diff --git a/.clang-format b/.clang-format index b01602a2b9..18b16e0de0 100644 --- a/.clang-format +++ b/.clang-format @@ -16,1130 +16,9 @@ PointerAlignment: Right # of a comment block to protect comments as # per STYLE.md CommentPragmas: '(^ IWYU pragma:|^\*$|^-$)' -# OpenSSL uses typedefs extensively. Tell clang-format about them. -TypeNames: - - "ACCESS_DESCRIPTION" - - "ADDED_OBJ" - - "ADMISSIONS" - - "ADMISSION_SYNTAX" - - "AES_KEY" - - "APP_HTTP_TLS_INFO" - - "ARGS" - - "ARIA_c128" - - "ARIA_KEY" - - "ARIA_u128" - - "ASIdentifierChoice" - - "ASIdentifiers" - - "ASIdOrRange" - - "ASIdOrRanges" - - "ASN1_ADB" - - "ASN1_ADB_TABLE" - - "ASN1_AUX" - - "ASN1_aux_cb" - - "ASN1_aux_const_cb" - - "ASN1_BIT_STRING" - - "ASN1_BMPSTRING" - - "ASN1_BOOLEAN" - - "ASN1_ENCODING" - - "ASN1_ENUMERATED" - - "ASN1_ex_d2i" - - "ASN1_ex_d2i_ex" - - "ASN1_ex_free_func" - - "ASN1_ex_i2d" - - "ASN1_ex_new_ex_func" - - "ASN1_ex_new_func" - - "ASN1_ex_print_func" - - "ASN1_EXTERN_FUNCS" - - "ASN1_GENERALIZEDTIME" - - "ASN1_GENERALSTRING" - - "ASN1_IA5STRING" - - "ASN1_INTEGER" - - "ASN1_ITEM" - - "ASN1_ITEM_EXP" - - "ASN1_NULL" - - "ASN1_OBJECT" - - "ASN1_OCTET_STRING" - - "ASN1_PCTX" - - "ASN1_primitive_c2i" - - "ASN1_PRIMITIVE_FUNCS" - - "ASN1_primitive_i2c" - - "ASN1_primitive_print" - - "ASN1_PRINTABLESTRING" - - "ASN1_PRINT_ARG" - - "asn1_ps_func" - - "ASN1_SCTX" - - "ASN1_SEQUENCE_ANY" - - "ASN1_STREAM_ARG" - - "ASN1_STRING" - - "ASN1_STRING_TABLE" - - "ASN1_T61STRING" - - "ASN1_TEMPLATE" - - "ASN1_TIME" - - "ASN1_TLC" - - "ASN1_TYPE" - - "ASN1_UNIVERSALSTRING" - - "ASN1_UTCTIME" - - "ASN1_UTF8STRING" - - "ASN1_VALUE" - - "ASN1_VISIBLESTRING" - - "ASRange" - - "ASYNC_callback_fn" - - "async_ctx" - - "async_fibre" - - "ASYNC_JOB" - - "async_pool" - - "ASYNC_stack_alloc_fn" - - "ASYNC_stack_free_fn" - - "ASYNC_WAIT_CTX" - - "AUTHORITY_INFO_ACCESS" - - "AUTHORITY_KEYID" - - "BASIC_CONSTRAINTS" - - "BF_KEY" - - "BF_LONG" - - "BIGNUM" - - "BIO" - - "BIO_ADDR" - - "BIO_ADDRINFO" - - "BIO_callback_fn" - - "BIO_callback_fn_ex" - - "BIO_dgram_sctp_notification_handler_fn" - - "BIO_F_BUFFER_CTX" - - "bio_info_cb" - - "BIO_info_cb" - - "BIO_METHOD" - - "BIO_MMSG_CB_ARGS" - - "BIO_MSG" - - "BIO_POLL_DESCRIPTOR" - - "BIT_STRING_BITNAME" - - "BLAKE2B_CTX" - - "BLAKE2B_PARAM" - - "BLAKE2S_CTX" - - "BLAKE2S_PARAM" - - "block128_f" - - "BN_BLINDING" - - "BN_CTX" - - "BN_GENCB" - - "BN_MONT_CTX" - - "BN_RECP_CTX" - - "BN_ULLONG" - - "BN_ULONG" - - "BUF_MEM" - - "BY_DIR_ENTRY" - - "BY_DIR_HASH" - - "c448_bool_t" - - "c448_dsword_t" - - "c448_dword_t" - - "c448_error_t" - - "c448_sword_t" - - "c448_word_t" - - "CA_DB" - - "CAMELLIA_KEY" - - "CAST_KEY" - - "CAST_LONG" - - "cbc128_f" - - "CCM128_CONTEXT" - - "ccm128_f" - - "CERT" - - "CERTIFICATEPOLICIES" - - "CERT_PKEY" - - "cfq_free_cb" - - "CIPH_DIGEST" - - "CLIENTHELLO_MSG" - - "CMAC_CTX" - - "CMS_AuthenticatedData" - - "CMS_AuthEnvelopedData" - - "CMS_CertificateChoices" - - "CMS_CompressedData" - - "CMS_ContentInfo" - - "CMS_CTX" - - "CMS_DigestedData" - - "CMS_EncapsulatedContentInfo" - - "CMS_EncryptedContentInfo" - - "CMS_EncryptedData" - - "CMS_EnvelopedData" - - "CMS_IssuerAndSerialNumber" - - "CMS_KEKIdentifier" - - "CMS_KEKRecipientInfo" - - "CMS_KEMRecipientInfo" - - "CMS_KeyAgreeRecipientIdentifier" - - "CMS_KeyAgreeRecipientInfo" - - "CMS_KeyTransRecipientInfo" - - "CMS_OriginatorIdentifierOrKey" - - "CMS_OriginatorInfo" - - "CMS_OriginatorPublicKey" - - "CMS_OtherCertificateFormat" - - "CMS_OtherKeyAttribute" - - "CMS_OtherRecipientInfo" - - "CMS_OtherRevocationInfoFormat" - - "CMS_PasswordRecipientInfo" - - "CMS_Receipt" - - "CMS_ReceiptRequest" - - "CMS_ReceiptsFrom" - - "CMS_RecipientEncryptedKey" - - "CMS_RecipientIdentifier" - - "CMS_RecipientInfo" - - "CMS_RecipientKeyIdentifier" - - "CMS_RevocationInfoChoice" - - "CMS_SignedData" - - "CMS_SignerIdentifier" - - "CMS_SignerInfo" - - "COMP_CTX" - - "COMP_METHOD" - - "CONF" - - "conf_finish_func" - - "CONF_IMODULE" - - "conf_init_func" - - "CONF_METHOD" - - "CONF_MODULE" - - "confunc_f" - - "CON_FUNC_RETURN" - - "CONF_VALUE" - - "const_ASN1_VALUE" - - "const_DES_cblock" - - "CRL_DIST_POINTS" - - "CRYPTO_CONDVAR" - - "CRYPTO_dynlock" - - "CRYPTO_EX_DATA" - - "CRYPTO_EX_dup" - - "CRYPTO_EX_free" - - "CRYPTO_EX_new" - - "CRYPTO_free_fn" - - "CRYPTO_malloc_fn" - - "CRYPTO_MUTEX" - - "CRYPTO_ONCE" - - "CRYPTO_RCU_LOCK" - - "CRYPTO_realloc_fn" - - "CRYPTO_REF_COUNT" - - "CRYPTO_RWLOCK" - - "CRYPTO_THREAD" - - "CRYPTO_THREAD_ID" - - "CRYPTO_THREADID" - - "CRYPTO_THREAD_LOCAL" - - "CRYPTO_THREAD_LOCAL_KEY_ID" - - "CRYPTO_THREAD_RETVAL" - - "CRYPTO_THREAD_ROUTINE" - - "CRYPTO_THREAD_ROUTINE_CB" - - "CTLOG" - - "ct_log_entry_type_t" - - "CTLOG_STORE" - - "CT_POLICY_EVAL_CTX" - - "ctr128_f" - - "curve448_point_t" - - "curve448_precomputed_s" - - "curve448_scalar_t" - - "custom_ext_add_cb" - - "custom_ext_free_cb" - - "custom_ext_method" - - "custom_ext_methods" - - "custom_ext_parse_cb" - - "d2i_of_void" - - "danetls_record" - - "DB_ATTR" - - "DES_cblock" - - "DES_key_schedule" - - "DES_LONG" - - "DH" - - "DH_METHOD" - - "DH_NAMED_GROUP" - - "DISPLAY_COLUMNS" - - "DIST_POINT" - - "DIST_POINT_NAME" - - "do_server_cb" - - "DOWNGRADE" - - "DRBG_STATUS" - - "DSA" - - "DSA_METHOD" - - "DSA_SIG" - - "DSO" - - "DSO_FUNC_TYPE" - - "DSO_MERGER_FUNC" - - "DSO_METHOD" - - "DSO_NAME_CONVERTER_FUNC" - - "dsword_t" - - "DTLS1_STATE" - - "DTLS_BITMAP" - - "DTLS_RECORD_LAYER" - - "DTLS_RLAYER_RECORD_DATA" - - "DTLS_timer_cb" - - "dword_t" - - "dynamic_bind_engine" - - "dynamic_fns" - - "dynamic_MEM_fns" - - "dynamic_v_check_fn" - - "dyn_MEM_free_fn" - - "dyn_MEM_malloc_fn" - - "dyn_MEM_realloc_fn" - - "ecb128_f" - - "EC_builtin_curve" - - "ECDH_VINFO" - - "ECDSA_SIG" - - "EC_GROUP" - - "EC_KEY" - - "EC_KEY_METHOD" - - "EC_METHOD" - - "ECPARAMETERS" - - "ECPKPARAMETERS" - - "EC_POINT" - - "EC_PRE_COMP" - - "ECX_KEY" - - "ecx_key_op_t" - - "ECX_KEY_TYPE" - - "EDIPARTYNAME" - - "ENDPOINT" - - "ENGINE" - - "ENGINE_CIPHERS_PTR" - - "ENGINE_CMD_DEFN" - - "ENGINE_CTRL_FUNC_PTR" - - "ENGINE_DIGESTS_PTR" - - "ENGINE_GEN_FUNC_PTR" - - "ENGINE_GEN_INT_FUNC_PTR" - - "ENGINE_LOAD_KEY_PTR" - - "ENGINE_PKEY_ASN1_METHS_PTR" - - "ENGINE_PKEY_METHS_PTR" - - "ENGINE_SSL_CLIENT_CERT_PTR" - - "ENUMERATED_NAMES" - - "ERR_STATE" - - "ERR_STRING_DATA" - - "ESS_CERT_ID" - - "ESS_CERT_ID_V2" - - "ESS_ISSUER_SERIAL" - - "ESS_SIGNING_CERT" - - "ESS_SIGNING_CERT_V2" - - "EVP_ASYM_CIPHER" - - "EVP_CIPHER" - - "evp_cipher_aead_asn1_params" - - "EVP_CIPHER_CTX" - - "EVP_CIPHER_INFO" - - "EVP_CTRL_TLS1_1_MULTIBLOCK_PARAM" - - "EVP_ENCODE_CTX" - - "EVP_KDF" - - "EVP_KDF_CTX" - - "EVP_KEM" - - "EVP_KEYEXCH" - - "EVP_KEYMGMT" - - "EVP_MAC" - - "EVP_MAC_CTX" - - "EVP_MD" - - "EVP_MD_CTX" - - "EVP_PBE_CTL" - - "EVP_PBE_KEYGEN" - - "EVP_PBE_KEYGEN_EX" - - "EVP_PKEY" - - "EVP_PKEY_ASN1_METHOD" - - "EVP_PKEY_CTX" - - "EVP_PKEY_gen_cb" - - "EVP_PKEY_METHOD" - - "EVP_RAND" - - "EVP_RAND_CTX" - - "EVP_SIGNATURE" - - "EVP_SKEY" - - "EVP_SKEYMGMT" - - "EX_CALLBACK" - - "EX_CALLBACKS" - - "EXTENDED_KEY_USAGE" - - "EXT_RETURN" - - "FFC_OSSL_PARAMS" - - "FFC_PARAMS" - - "FIPS_DEFERRED_TEST" - - "FUNCTION" - - "FUNC_TYPE" - - "GCM128_CONTEXT" - - "gcm_ghash_fn" - - "gcm_gmult_fn" - - "gcm_init_fn" - - "GENERAL_NAME" - - "GENERAL_NAMES" - - "GENERAL_SUBTREE" - - "GEN_SESSION_CB" - - "gf" - - "gf_s" - - "HMAC_CTX" - - "hm_fragment" - - "hsword_t" - - "HT" - - "HT_CONFIG" - - "HT_KEY" - - "HT_VALUE" - - "HT_VALUE_LIST" - - "i2d_of_void" - - "i64" - - "IDEA_INT" - - "IDEA_KEY_SCHEDULE" - - "INFOPAIR" - - "int128_t" - - "int16_t" - - "int32_t" - - "int64_t" - - "int8_t" - - "int_dhx942_dh" - - "IPAddrBlocks" - - "IPAddressChoice" - - "IPAddressFamily" - - "IPAddressOrRange" - - "IPAddressOrRanges" - - "IPAddressRange" - - "ISSUER_SIGN_TOOL" - - "ISSUING_DIST_POINT" - - "KDF_DATA" - - "KECCAK1600_CTX" - - "KEY_TABLE_TYPE" - - "ktls_crypto_info_t" - - "LM_OTS_PARAMS" - - "LM_OTS_SIG" - - "LMS_KEY" - - "LMS_PARAMS" - - "LMS_PUB_KEY" - - "LMS_SIG" - - "locale_t" - - "MAC_KEY" - - "mask_t" - - "MATRIX" - - "MD2_CTX" - - "MD2_INT" - - "MD4_CTX" - - "MD4_LONG" - - "MD5_CTX" - - "MD5_LONG" - - "MD5_SHA1_CTX" - - "MDC2_CTX" - - "MEM" - - "MIME_HEADER" - - "MIME_PARAM" - - "ML_COMMON_CODEC" - - "ML_COMMON_PKCS8_FMT" - - "ML_COMMON_PKCS8_FMT_PREF" - - "ML_COMMON_SPKI_FMT" - - "ML_DSA_KEY" - - "ML_DSA_PARAMS" - - "ML_DSA_SIG" - - "ML_KEM_KEY" - - "ML_KEM_VINFO" - - "MLX_KEY" - - "MSG_FLOW_STATE" - - "MSG_PROCESS_RETURN" - - "NAME_CONSTRAINTS" - - "NAME_FUNCS" - - "NAMING_AUTHORITY" - - "NETSCAPE_CERT_SEQUENCE" - - "NETSCAPE_SPKAC" - - "NETSCAPE_SPKI" - - "nid_triple" - - "niels_s" - - "niels_t" - - "NISTP224_PRE_COMP" - - "NISTP256_PRE_COMP" - - "NISTP384_PRE_COMP" - - "NISTP521_PRE_COMP" - - "NISTZ256_PRE_COMP" - - "NOTICEREF" - - "OBJ_NAME" - - "OCB128_CONTEXT" - - "ocb128_f" - - "OCB_BLOCK" - - "OCSP_BASICRESP" - - "OCSP_CERTID" - - "OCSP_CERTSTATUS" - - "OCSP_CRLID" - - "OCSP_ONEREQ" - - "OCSP_REQ_CTX" - - "OCSP_REQINFO" - - "OCSP_REQUEST" - - "OCSP_RESPBYTES" - - "OCSP_RESPDATA" - - "OCSP_RESPID" - - "OCSP_RESPONSE" - - "OCSP_REVOKEDINFO" - - "OCSP_SERVICELOC" - - "OCSP_SIGNATURE" - - "OCSP_SINGLERESP" - - "OP_CACHE_ELEM" - - "OPENSSL_BLOCK" - - "OPENSSL_CORE_CTX" - - "OPENSSL_CSTRING" - - "OPENSSL_DIR_CTX" - - "OPENSSL_INIT_SETTINGS" - - "OPENSSL_LHASH" - - "OPENSSL_LH_COMPFUNC" - - "OPENSSL_LH_COMPFUNCTHUNK" - - "OPENSSL_LH_DOALL_FUNC" - - "OPENSSL_LH_DOALL_FUNCARG" - - "OPENSSL_LH_DOALL_FUNCARG_THUNK" - - "OPENSSL_LH_DOALL_FUNC_THUNK" - - "OPENSSL_LH_HASHFUNC" - - "OPENSSL_LH_HASHFUNCTHUNK" - - "OPENSSL_LH_NODE" - - "OPENSSL_PSTRING" - - "OPENSSL_SA" - - "OPENSSL_sk_compfunc" - - "OPENSSL_sk_copyfunc" - - "OPENSSL_sk_freefunc" - - "OPENSSL_sk_freefunc_thunk" - - "OPENSSL_STACK" - - "OPENSSL_STRING" - - "OPTIONS" - - "OPT_PAIR" - - "OSSL_AA_DIST_POINT" - - "OSSL_ACKM" - - "OSSL_ACKM_PROBE_INFO" - - "OSSL_ACKM_RX_PKT" - - "OSSL_ACKM_TX_PKT" - - "OSSL_ALGORITHM" - - "OSSL_ALGORITHM_CAPABLE" - - "OSSL_ALLOWED_ATTRIBUTES_CHOICE" - - "OSSL_ALLOWED_ATTRIBUTES_ITEM" - - "OSSL_ALLOWED_ATTRIBUTES_SYNTAX" - - "OSSL_ATAV" - - "OSSL_ATTRIBUTE_DESCRIPTOR" - - "OSSL_ATTRIBUTE_MAPPING" - - "OSSL_ATTRIBUTE_MAPPINGS" - - "OSSL_ATTRIBUTES_SYNTAX" - - "OSSL_ATTRIBUTE_TYPE_MAPPING" - - "OSSL_ATTRIBUTE_VALUE_MAPPING" - - "OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX" - - "OSSL_BASIC_ATTR_CONSTRAINTS" - - "OSSL_CALLBACK" - - "OSSL_CC_ACK_INFO" - - "OSSL_CC_DATA" - - "OSSL_CC_ECN_INFO" - - "OSSL_CC_LOSS_INFO" - - "OSSL_CC_METHOD" - - "ossl_cmp_allow_unprotected_cb_t" - - "OSSL_CMP_ATAV" - - "OSSL_CMP_ATAVS" - - "OSSL_CMP_CAKEYUPDANNCONTENT" - - "OSSL_CMP_certConf_cb_t" - - "OSSL_CMP_CERTCONFIRMCONTENT" - - "OSSL_CMP_CERTIFIEDKEYPAIR" - - "OSSL_CMP_CERTORENCCERT" - - "OSSL_CMP_CERTREPMESSAGE" - - "OSSL_CMP_CERTREQTEMPLATE" - - "OSSL_CMP_CERTRESPONSE" - - "OSSL_CMP_CERTSTATUS" - - "OSSL_CMP_CHALLENGE" - - "OSSL_CMP_CRLANNCONTENT" - - "OSSL_CMP_CRLSOURCE" - - "OSSL_CMP_CRLSTATUS" - - "OSSL_CMP_CTX" - - "OSSL_CMP_ERRORMSGCONTENT" - - "OSSL_CMP_GENMSGCONTENT" - - "OSSL_CMP_GENREPCONTENT" - - "OSSL_CMP_ITAV" - - "OSSL_CMP_KEYRECREPCONTENT" - - "OSSL_CMP_log_cb_t" - - "OSSL_CMP_MSG" - - "OSSL_CMP_MSGS" - - "OSSL_CMP_PKIBODY" - - "OSSL_CMP_PKIFAILUREINFO" - - "OSSL_CMP_PKIFREETEXT" - - "OSSL_CMP_PKIHEADER" - - "OSSL_CMP_PKISI" - - "OSSL_CMP_PKISTATUS" - - "OSSL_CMP_POLLREP" - - "OSSL_CMP_POLLREPCONTENT" - - "OSSL_CMP_POLLREQ" - - "OSSL_CMP_POLLREQCONTENT" - - "OSSL_CMP_POPODECKEYCHALLCONTENT" - - "OSSL_CMP_POPODECKEYRESPCONTENT" - - "OSSL_CMP_PROTECTEDPART" - - "OSSL_CMP_REVANNCONTENT" - - "OSSL_CMP_REVDETAILS" - - "OSSL_CMP_REVREPCONTENT" - - "OSSL_CMP_REVREQCONTENT" - - "OSSL_CMP_ROOTCAKEYUPDATE" - - "OSSL_CMP_severity" - - "OSSL_CMP_SRV_certConf_cb_t" - - "OSSL_CMP_SRV_cert_request_cb_t" - - "OSSL_CMP_SRV_clean_transaction_cb_t" - - "OSSL_CMP_SRV_CTX" - - "OSSL_CMP_SRV_delayed_delivery_cb_t" - - "OSSL_CMP_SRV_error_cb_t" - - "OSSL_CMP_SRV_genm_cb_t" - - "OSSL_CMP_SRV_pollReq_cb_t" - - "OSSL_CMP_SRV_rr_cb_t" - - "OSSL_CMP_transfer_cb_t" - - "OSSL_COMP_CERT" - - "OSSL_CORE_BIO" - - "OSSL_CORE_HANDLE" - - "OSSL_CRMF_ATTRIBUTETYPEANDVALUE" - - "OSSL_CRMF_CERTID" - - "OSSL_CRMF_CERTREQUEST" - - "OSSL_CRMF_CERTTEMPLATE" - - "OSSL_CRMF_ENCKEYWITHID" - - "OSSL_CRMF_ENCKEYWITHID_IDENTIFIER" - - "OSSL_CRMF_ENCRYPTEDKEY" - - "OSSL_CRMF_ENCRYPTEDVALUE" - - "OSSL_CRMF_MSG" - - "OSSL_CRMF_MSGS" - - "OSSL_CRMF_OPTIONALVALIDITY" - - "OSSL_CRMF_PBMPARAMETER" - - "OSSL_CRMF_PKIPUBLICATIONINFO" - - "OSSL_CRMF_PKMACVALUE" - - "OSSL_CRMF_POPO" - - "OSSL_CRMF_POPOPRIVKEY" - - "OSSL_CRMF_POPOSIGNINGKEY" - - "OSSL_CRMF_POPOSIGNINGKEYINPUT" - - "OSSL_CRMF_POPOSIGNINGKEYINPUT_AUTHINFO" - - "OSSL_CRMF_PRIVATEKEYINFO" - - "OSSL_CRMF_PUBINFOS" - - "OSSL_CRMF_SINGLEPUBINFO" - - "OSSL_DAY_TIME" - - "OSSL_DAY_TIME_BAND" - - "OSSL_DECODER" - - "OSSL_DECODER_CLEANUP" - - "OSSL_DECODER_CONSTRUCT" - - "OSSL_DECODER_CTX" - - "OSSL_DECODER_INSTANCE" - - "OSSL_DISPATCH" - - "OSSL_ENCODER" - - "OSSL_ENCODER_CLEANUP" - - "OSSL_ENCODER_CONSTRUCT" - - "OSSL_ENCODER_CTX" - - "OSSL_ENCODER_INSTANCE" - - "OSSL_EX_DATA_GLOBAL" - - "ossl_finish_mutate_cb" - - "OSSL_FIPS_IND" - - "OSSL_FIPS_IND_CHECK_CB" - - "OSSL_FUNC" - - "OSSL_HANDSHAKE_STATE" - - "OSSL_HASH" - - "OSSL_HPKE_AEAD_INFO" - - "OSSL_HPKE_CTX" - - "OSSL_HPKE_KDF_INFO" - - "OSSL_HPKE_KEM_INFO" - - "OSSL_HPKE_SUITE" - - "OSSL_HTTP_bio_cb_t" - - "OSSL_HTTP_REQ_CTX" - - "OSSL_i2d_of_void_ctx" - - "OSSL_IETF_ATTR_SYNTAX" - - "OSSL_IETF_ATTR_SYNTAX_VALUE" - - "OSSL_INDICATOR_CALLBACK" - - "OSSL_INFO_SYNTAX" - - "OSSL_INFO_SYNTAX_POINTER" - - "OSSL_INOUT_CALLBACK" - - "ossl_intmax_t" - - "OSSL_ISSUER_SERIAL" - - "OSSL_ITEM" - - "OSSL_JSON_ENC" - - "OSSL_LIB_CTX" - - "OSSL_LIB_CTX_THREADS" - - "OSSL_METHOD_CONSTRUCT_METHOD" - - "OSSL_METHOD_STORE" - - "ossl_msg_cb" - - "ossl_mutate_packet_cb" - - "OSSL_NAMED_DAY" - - "OSSL_NAMEMAP" - - "OSSL_OBJECT_DIGEST_INFO" - - "OSSL_PARAM" - - "OSSL_PARAM_ALIGNED_BLOCK" - - "OSSL_PARAM_BLD" - - "OSSL_PASSPHRASE_CALLBACK" - - "OSSL_PQUEUE" - - "OSSL_PRIVILEGE_POLICY_ID" - - "OSSL_PROPERTY_DEFINITION" - - "OSSL_PROPERTY_IDX" - - "OSSL_PROPERTY_LIST" - - "OSSL_PROPERTY_OPER" - - "OSSL_PROPERTY_TYPE" - - "OSSL_PROVIDER" - - "OSSL_PROVIDER_INFO" - - "OSSL_provider_init_fn" - - "OSSL_QRL_ENC_LEVEL" - - "OSSL_QRL_ENC_LEVEL_SET" - - "OSSL_QRX" - - "OSSL_QRX_ARGS" - - "ossl_qrx_key_update_cb" - - "ossl_qrx_late_validation_cb" - - "OSSL_QRX_PKT" - - "OSSL_QTX" - - "OSSL_QTX_ARGS" - - "OSSL_QTX_IOVEC" - - "OSSL_QTX_PKT" - - "OSSL_QUIC_ACK_RANGE" - - "ossl_quic_demux_cb_fn" - - "OSSL_QUIC_FRAME_ACK" - - "OSSL_QUIC_FRAME_CONN_CLOSE" - - "OSSL_QUIC_FRAME_CRYPTO" - - "OSSL_QUIC_FRAME_NEW_CONN_ID" - - "OSSL_QUIC_FRAME_RESET_STREAM" - - "OSSL_QUIC_FRAME_STOP_SENDING" - - "OSSL_QUIC_FRAME_STREAM" - - "ossl_quic_initial_token_free_fn" - - "OSSL_QUIC_TLS_CALLBACKS" - - "OSSL_QUIC_TX_PACKETISER" - - "OSSL_QUIC_TX_PACKETISER_ARGS" - - "OSSL_RECORD_LAYER" - - "OSSL_RECORD_METHOD" - - "OSSL_RECORD_TEMPLATE" - - "OSSL_ROLE_SPEC_CERT_ID" - - "OSSL_ROLE_SPEC_CERT_ID_SYNTAX" - - "OSSL_RTT_INFO" - - "OSSL_SELF_TEST" - - "OSSL_SLH_ADRS_FUNC_copy" - - "OSSL_SLH_ADRS_FUNC_copy_keypair_address" - - "OSSL_SLH_ADRS_FUNC_set_chain_address" - - "OSSL_SLH_ADRS_FUNC_set_hash_address" - - "OSSL_SLH_ADRS_FUNC_set_keypair_address" - - "OSSL_SLH_ADRS_FUNC_set_layer_address" - - "OSSL_SLH_ADRS_FUNC_set_tree_address" - - "OSSL_SLH_ADRS_FUNC_set_tree_height" - - "OSSL_SLH_ADRS_FUNC_set_tree_index" - - "OSSL_SLH_ADRS_FUNC_set_type_and_clear" - - "OSSL_SLH_ADRS_FUNC_zero" - - "OSSL_SLH_HASHFUNC_F" - - "OSSL_SLH_HASHFUNC_H" - - "OSSL_SLH_HASHFUNC_H_MSG" - - "OSSL_SLH_HASHFUNC_PRF" - - "OSSL_SLH_HASHFUNC_PRF_MSG" - - "OSSL_SLH_HASHFUNC_T" - - "ossl_ssize_t" - - "OSSL_STATEM" - - "ossl_statem_finish_mutate_handshake_cb" - - "ossl_statem_mutate_handshake_cb" - - "OSSL_STATM" - - "OSSL_STORE_attach_fn" - - "OSSL_STORE_close_fn" - - "OSSL_STORE_ctrl_fn" - - "OSSL_STORE_CTX" - - "OSSL_STORE_eof_fn" - - "OSSL_STORE_error_fn" - - "OSSL_STORE_expect_fn" - - "OSSL_STORE_find_fn" - - "OSSL_STORE_INFO" - - "OSSL_STORE_LOADER" - - "OSSL_STORE_LOADER_CTX" - - "OSSL_STORE_load_fn" - - "OSSL_STORE_open_ex_fn" - - "OSSL_STORE_open_fn" - - "OSSL_STORE_post_process_info_fn" - - "OSSL_STORE_SEARCH" - - "OSSL_TARGET" - - "OSSL_TARGET_CERT" - - "OSSL_TARGETING_INFORMATION" - - "OSSL_TARGETS" - - "OSSL_thread_stop_handler_fn" - - "OSSL_TIME" - - "OSSL_TIME_PERIOD" - - "OSSL_TIME_SPEC" - - "OSSL_TIME_SPEC_ABSOLUTE" - - "OSSL_TIME_SPEC_DAY" - - "OSSL_TIME_SPEC_MONTH" - - "OSSL_TIME_SPEC_TIME" - - "OSSL_TIME_SPEC_WEEKS" - - "OSSL_TIME_SPEC_X_DAY_OF" - - "OSSL_trace_cb" - - "ossl_uintmax_t" - - "OSSL_USER_NOTICE_SYNTAX" - - "OTHERNAME" - - "PACKET" - - "PBE2PARAM" - - "PBEPARAM" - - "PBKDF2PARAM" - - "PBMAC1PARAM" - - "pem_password_cb" - - "pitem" - - "piterator" - - "PKCS12" - - "PKCS12_BAGS" - - "PKCS12_create_cb" - - "PKCS12_MAC_DATA" - - "PKCS12_SAFEBAG" - - "PKCS7" - - "PKCS7_CTX" - - "PKCS7_DIGEST" - - "PKCS7_ENC_CONTENT" - - "PKCS7_ENCRYPT" - - "PKCS7_ENVELOPE" - - "PKCS7_ISSUER_AND_SERIAL" - - "PKCS7_RECIP_INFO" - - "PKCS7_SIGNED" - - "PKCS7_SIGN_ENVELOPE" - - "PKCS7_SIGNER_INFO" - - "PKCS8_PRIV_KEY_INFO" - - "PKEY_USAGE_PERIOD" - - "pniels_t" - - "point_conversion_form_t" - - "POLICY_CONSTRAINTS" - - "POLICYINFO" - - "POLICY_MAPPING" - - "POLICY_MAPPINGS" - - "POLICYQUALINFO" - - "POLY" - - "POLY1305" - - "poly1305_blocks_f" - - "poly1305_emit_f" - - "pqueue" - - "prime_t" - - "PROFESSION_INFO" - - "PROFESSION_INFOS" - - "PROV_AES_CCM_CTX" - - "PROV_AES_CTX" - - "PROV_AES_GCM_CTX" - - "PROV_AES_GCM_SIV_CTX" - - "PROV_AES_HMAC_SHA1_CTX" - - "PROV_AES_HMAC_SHA1_ETM_CTX" - - "PROV_AES_HMAC_SHA256_CTX" - - "PROV_AES_HMAC_SHA256_ETM_CTX" - - "PROV_AES_HMAC_SHA512_ETM_CTX" - - "PROV_AES_HMAC_SHA_CTX" - - "PROV_AES_HMAC_SHA_ETM_CTX" - - "PROV_AES_OCB_CTX" - - "PROV_AES_SIV_CTX" - - "PROV_AES_XTS_CTX" - - "PROV_ARIA_CCM_CTX" - - "PROV_ARIA_CTX" - - "PROV_ARIA_GCM_CTX" - - "PROV_BLOWFISH_CTX" - - "PROV_CAMELLIA_CTX" - - "PROV_CAST_CTX" - - "PROV_CCM_CTX" - - "PROV_CCM_HW" - - "PROV_CHACHA20_CTX" - - "PROV_CHACHA20_POLY1305_CTX" - - "PROV_CIPHER" - - "PROV_CIPHER_CTX" - - "PROV_CIPHER_HW" - - "PROV_CIPHER_HW_AES_GCM_SIV" - - "PROV_CIPHER_HW_AES_HMAC_SHA" - - "PROV_CIPHER_HW_AES_HMAC_SHA_ETM" - - "PROV_CIPHER_HW_AES_SIV" - - "PROV_CIPHER_HW_CHACHA20" - - "PROV_CIPHER_HW_CHACHA20_POLY1305" - - "PROV_CIPHER_HW_FN" - - "PROV_CIPHER_HW_RC4_HMAC_MD5" - - "PROV_CTX" - - "PROV_DES_CTX" - - "PROV_DIGEST" - - "PROV_DRBG" - - "PROV_DRBG_HMAC" - - "PROV_GCM_CTX" - - "PROV_GCM_HW" - - "PROV_IDEA_CTX" - - "PROV_RC2_CTX" - - "PROV_RC4_CTX" - - "PROV_RC4_HMAC_MD5_CTX" - - "PROV_RC5_CTX" - - "PROV_SEED_CTX" - - "PROV_SHA3_METHOD" - - "PROV_SKEY" - - "PROV_SM4_CCM_CTX" - - "PROV_SM4_CTX" - - "PROV_SM4_GCM_CTX" - - "PROV_SM4_XTS_CTX" - - "PROV_TDES_CTX" - - "PROXY_CERT_INFO_EXTENSION" - - "PROXY_POLICY" - - "PW_CB_DATA" - - "QLOG" - - "QLOG_TRACE_INFO" - - "QUIC_CFQ" - - "QUIC_CFQ_ITEM" - - "QUIC_CHANNEL" - - "QUIC_CHANNEL_ARGS" - - "QUIC_CONNECTION" - - "QUIC_CONN_ID" - - "QUIC_DEMUX" - - "QUIC_DOMAIN" - - "QUIC_ENGINE" - - "QUIC_ENGINE_ARGS" - - "QUIC_FIFD" - - "QUIC_HDR_PROTECTOR" - - "QUIC_LCIDM" - - "QUIC_LISTENER" - - "QUIC_OBJ" - - "QUIC_PKT_HDR" - - "QUIC_PKT_HDR_PTRS" - - "QUIC_PN" - - "QUIC_PORT" - - "QUIC_PORT_ARGS" - - "QUIC_PREFERRED_ADDR" - - "QUIC_RCIDM" - - "QUIC_REACTOR" - - "QUIC_REACTOR_WAIT_CTX" - - "QUIC_REACTOR_WAIT_SLOT" - - "QUIC_RSTREAM" - - "QUIC_RXFC" - - "QUIC_SRT_ELEM" - - "QUIC_SRT_GEN" - - "QUIC_SRTM" - - "QUIC_SSTREAM" - - "QUIC_STATELESS_RESET_TOKEN" - - "QUIC_STREAM" - - "QUIC_STREAM_ITER" - - "QUIC_STREAM_LIST_NODE" - - "QUIC_STREAM_MAP" - - "QUIC_TERMINATE_CAUSE" - - "QUIC_THREAD_ASSIST" - - "QUIC_TICK_RESULT" - - "QUIC_TLS" - - "QUIC_TLS_ARGS" - - "QUIC_TOKEN" - - "QUIC_TSERVER" - - "QUIC_TSERVER_ARGS" - - "QUIC_TXFC" - - "QUIC_TXPIM" - - "QUIC_TXPIM_CHUNK" - - "QUIC_TXPIM_PKT" - - "QUIC_TXP_STATUS" - - "QUIC_URXE" - - "QUIC_URXE_LIST" - - "QUIC_XSO" - - "RAND_METHOD" - - "RAND_POOL" - - "RAW_EXTENSION" - - "RC2_INT" - - "RC2_KEY" - - "RC4_KEY" - - "RC5_32_INT" - - "RC5_32_KEY" - - "rcu_cb_fn" - - "READ_STATE" - - "RECORD_LAYER" - - "RIO_NOTIFIER" - - "RIO_POLL_BUILDER" - - "RIPEMD160_CTX" - - "RIPEMD160_LONG" - - "RSA" - - "RSA_ACVP_TEST" - - "RSA_METHOD" - - "RSA_OAEP_PARAMS" - - "RSA_PRIME_INFO" - - "RSA_PSS_PARAMS" - - "RSA_PSS_PARAMS_30" - - "S390X_KMAC_PARAMS" - - "S390X_KMA_PARAMS" - - "S390X_KM_XTS_PARAMS" - - "SCRYPT_PARAMS" - - "SCT" - - "SCT_CTX" - - "sct_source_t" - - "sct_validation_status_t" - - "sct_version_t" - - "SEED_KEY_SCHEDULE" - - "seed_word" - - "SELF_TEST_POST_PARAMS" - - "SFRAME_LIST" - - "sframe_list_write_at_cb" - - "SHA256_CTX" - - "sha3_absorb_fn" - - "sha3_final_fn" - - "sha3_squeeze_fn" - - "SHA512_CTX" - - "SHA_CTX" - - "SHA_LONG" - - "SHA_LONG64" - - "SIGALG_LOOKUP" - - "SIPHASH" - - "SIV128_CONTEXT" - - "SIV_BLOCK" - - "SLH_ADRS_FUNC" - - "SLH_DSA_HASH_CTX" - - "SLH_DSA_KEY" - - "SLH_DSA_PARAMS" - - "SLH_HASH_FUNC" - - "SM3_CTX" - - "SM3_WORD" - - "SM4_KEY" - - "socklen_t" - - "SRP_ARG" - - "SRP_CTX" - - "SRP_gN" - - "SRP_gN_cache" - - "srpsrvparm" - - "SRP_user_pwd" - - "SRP_VBASE" - - "SRTP_PROTECTION_PROFILE" - - "SSL" - - "SSL3_ENC_METHOD" - - "SSL_allow_early_data_cb_fn" - - "SSL_async_callback_fn" - - "SSL_CERT_LOOKUP" - - "SSL_CIPHER" - - "SSL_client_hello_cb_fn" - - "SSL_COMP" - - "SSL_CONF_CMD" - - "SSL_CONF_CTX" - - "SSL_CONN_CLOSE_INFO" - - "SSL_CONNECTION" - - "ssl_crock_st" - - "ssl_ct_validation_cb" - - "SSL_CTX" - - "SSL_CTX_alpn_select_cb_func" - - "SSL_CTX_decrypt_session_ticket_fn" - - "SSL_CTX_EXT_SECURE" - - "SSL_CTX_generate_session_ticket_fn" - - "SSL_CTX_keylog_cb_func" - - "SSL_CTX_npn_advertised_cb_func" - - "SSL_CTX_npn_select_cb_func" - - "SSL_custom_ext_add_cb_ex" - - "SSL_custom_ext_free_cb_ex" - - "SSL_custom_ext_parse_cb_ex" - - "SSL_DANE" - - "SSL_EARLY_DATA_STATE" - - "SSL_EXCERT" - - "SSL_HMAC" - - "SSL_MAC_BUF" - - "SSL_METHOD" - - "SSL_new_pending_conn_cb_fn" - - "SSL_PHA_STATE" - - "SSL_POLL_ITEM" - - "SSL_psk_client_cb_func" - - "SSL_psk_find_session_cb_func" - - "SSL_psk_server_cb_func" - - "SSL_psk_use_session_cb_func" - - "SSL_SESSION" - - "SSL_SHUTDOWN_EX_ARGS" - - "SSL_STREAM_RESET_ARGS" - - "SSL_TICKET_RETURN" - - "SSL_TICKET_STATUS" - - "SSL_TOKEN_STORE" - - "SSL_verify_cb" - - "STACK_OF" - - "STACK_OF_X509_NAME_ENTRY" - - "STREAM_FRAME" - - "STRINT_PAIR" - - "sword_t" - - "SXNET" - - "SXNETID" - - "testdsa" - - "TLS_BUFFER" - - "TLSEXT_INDEX" - - "TLS_FEATURE" - - "TLS_GROUP_INFO" - - "TLS_RECORD" - - "TLS_RL_RECORD" - - "tls_session_secret_cb_fn" - - "TLS_SESSION_TICKET_EXT" - - "tls_session_ticket_ext_cb_fn" - - "TLS_SIGALG_INFO" - - "TLS_SIGALGS" - - "TS_ACCURACY" - - "TS_extension_cb" - - "TS_MSG_IMPRINT" - - "TS_REQ" - - "TS_RESP" - - "TS_RESP_CTX" - - "TS_serial_cb" - - "TS_STATUS_INFO" - - "TS_time_cb" - - "TS_TST_INFO" - - "TS_VERIFY_CTX" - - "TTY_STRUCT" - - "TXT_DB" - - "u128" - - "u16" - - "u32" - - "u64" - - "u8" - - "UI" - - "UI_METHOD" - - "uint128_t" - - "uint16_t" - - "uint32_t" - - "uint64_t" - - "uint8_t" - - "uintptr_t" - - "UINT_RANGE" - - "UINT_SET" - - "UINT_SET_ITEM" - - "UI_STRING" - - "UNICODE_CONSTANTS" - - "USERNOTICE" - - "VECTOR" - - "VERIFY_CB_ARGS" - - "WHIRLPOOL_CTX" - - "word_t" - - "WORK_STATE" - - "WPACKET" - - "WPACKET_SUB" - - "WRITE_STATE" - - "WRITE_TRAN" - - "X509" - - "X509_ACERT" - - "X509_ACERT_INFO" - - "X509_ACERT_ISSUER" - - "X509_ACERT_ISSUER_V2FORM" - - "X509_ALGOR" - - "X509_ALGORS" - - "X509_ATTRIBUTE" - - "X509_CERT_AUX" - - "X509_CINF" - - "X509_CRL" - - "X509_CRL_INFO" - - "X509_CRL_METHOD" - - "X509_EXTENSION" - - "X509_EXTENSIONS" - - "X509_HOLDER" - - "X509_INFO" - - "X509_LOOKUP" - - "X509_LOOKUP_ctrl_ex_fn" - - "X509_LOOKUP_ctrl_fn" - - "X509_LOOKUP_get_by_alias_fn" - - "X509_LOOKUP_get_by_fingerprint_fn" - - "X509_LOOKUP_get_by_issuer_serial_fn" - - "X509_LOOKUP_get_by_subject_ex_fn" - - "X509_LOOKUP_get_by_subject_fn" - - "X509_LOOKUP_METHOD" - - "X509_LOOKUP_TYPE" - - "X509_NAME" - - "X509_NAME_ENTRY" - - "X509_OBJECT" - - "X509_PKEY" - - "X509_POLICY_CACHE" - - "X509_POLICY_DATA" - - "X509_POLICY_LEVEL" - - "X509_POLICY_NODE" - - "X509_POLICY_TREE" - - "X509_PUBKEY" - - "X509_PURPOSE" - - "X509_REQ" - - "X509_REQ_INFO" - - "X509_REVOKED" - - "X509_SIG" - - "X509_SIG_INFO" - - "X509_STORE" - - "X509_STORE_CTX" - - "X509_STORE_CTX_cert_crl_fn" - - "X509_STORE_CTX_check_crl_fn" - - "X509_STORE_CTX_check_issued_fn" - - "X509_STORE_CTX_check_policy_fn" - - "X509_STORE_CTX_check_revocation_fn" - - "X509_STORE_CTX_cleanup_fn" - - "X509_STORE_CTX_get_crl_fn" - - "X509_STORE_CTX_get_issuer_fn" - - "X509_STORE_CTX_verify_cb" - - "X509_STORE_CTX_verify_fn" - - "X509_TRUST" - - "X509V3_CONF_METHOD" - - "X509V3_CTX" - - "X509V3_EXT_D2I" - - "X509V3_EXT_FREE" - - "X509V3_EXT_I2D" - - "X509V3_EXT_I2R" - - "X509V3_EXT_I2S" - - "X509V3_EXT_METHOD" - - "X509V3_EXT_NEW" - - "X509V3_EXT_R2I" - - "X509V3_EXT_S2I" - - "X509V3_EXT_V2I" - - "X509_VAL" - - "X509_VERIFY_PARAM" - - "XTS128_CONTEXT" - # The following types are macros, and need to remain that way, unfortunately - - "HASH_CTX" - - "HASH_LONG" - - "MD32_REG_T" # OpenSSL uses macros extensively. Tell clang-format about them. TypenameMacros: ['LHASH_OF', 'STACK_OF'] StatementMacros: - - "BLOCK_CIPHER_aead" - - "BLOCK_CIPHER_generic" - - "BLOCK_CIPHER_custom" - - "BLOCK_CIPHER_def_cbc" - - "BLOCK_CIPHER_def_cfb" - - "BLOCK_CIPHER_def_ofb" - - "BLOCK_CIPHER_def_ecb" - - "BLOCK_CIPHER_defs" - - "BLOCK_CIPHER_generic_pack" - "DECLARE_AES_EVP" - "DECLARE_ASN1_ALLOC_FUNCTIONS" - "DECLARE_ASN1_ALLOC_FUNCTIONS_attr" @@ -1271,7 +150,6 @@ StatementMacros: - "IMPLEMENT_DIGEST" - "IMPLEMENT_digest_functions" - "IMPLEMENT_digest_functions_with_settable_ctx" - - "IMPLEMENT_digest_functions_with_serialize" - "IMPLEMENT_dtls1_meth_func" - "IMPLEMENT_DYNAMIC_BIND_FN" - "IMPLEMENT_DYNAMIC_CHECK_FN" @@ -1365,21 +243,7 @@ StatementMacros: - "ASN1_SEQUENCE_END_enc" - "ASN1_SEQUENCE_END_name" - "ASN1_SEQUENCE_END_ref" - - "make_dh" - - "make_dh_bn" - - "static_ASN1_CHOICE_END" - - "static_ASN1_CHOICE_END_name" - - "static_ASN1_CHOICE_END_selector" - - "static_ASN1_NDEF_SEQUENCE_END" - "static_ASN1_SEQUENCE_END" - - "static_ASN1_SEQUENCE_END_cb" - - "static_ASN1_SEQUENCE_END_name" - - "static_ASN1_SEQUENCE_END_ref" - - "PROV_CIPHER_HW_aes_mode" - - "PROV_CIPHER_HW_aria_mode" - - "PROV_CIPHER_HW_camellia_mode" - - "PROV_CIPHER_HW_des_mode" - - "PROV_CIPHER_HW_sm4_mode" # This isn't quite right, but it causes clang-format to do a slightly better # job formatting this macro. - "ASN1_EX_TEMPLATE_TYPE" diff --git a/.codespellrc b/.codespellrc index df3d676843..8103b70a7e 100644 --- a/.codespellrc +++ b/.codespellrc @@ -14,7 +14,6 @@ ignore-words-list = ADDAD, addin, adin, - ADn, AFAIR, afile, afterAll, @@ -75,7 +74,6 @@ ignore-words-list = configury, consumation, couldn, - couter, crasher, crashers, crate, @@ -132,7 +130,6 @@ ignore-words-list = Gost, GOST, Hart, - hashin, hasTable, hel, hist, @@ -335,7 +332,6 @@ skip = *.asc, *.bin, *.crt, - *.csr, *.css.map, *.eps, *.fr.utf-8, @@ -445,7 +441,6 @@ skip = CREDITS, CREDITS.TXT, DONATIONS, - external/*, jquery.js, jquery.min.map, localization*-[a-z][a-z]_[a-zA-Z][a-zA-Z].*, diff --git a/.ctags.d/exclude.ctags b/.ctags.d/exclude.ctags index 310a7ada24..c932464e6d 100644 --- a/.ctags.d/exclude.ctags +++ b/.ctags.d/exclude.ctags @@ -1,5 +1,5 @@ # -# Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -10,3 +10,4 @@ # List file names or patterns you want ctags to ignore. --exclude=.ctags.d --exclude=test +--exclude=check-format-test-positives.c diff --git a/.github/PULL_REQUEST_TEMPLATE.md b/.github/PULL_REQUEST_TEMPLATE.md index 3fb7a45961..85cfb3741c 100644 --- a/.github/PULL_REQUEST_TEMPLATE.md +++ b/.github/PULL_REQUEST_TEMPLATE.md @@ -3,11 +3,7 @@ Thank you for your pull request. Please review these requirements: Contributors guide: https://github.com/openssl/openssl/blob/master/CONTRIBUTING.md -Include a clear description of the issue or feature above this comment if not already provided. This should briefly outline the issue or feature being addressed, along with any relevant implementation details. For performance improvements, include benchmark results as well. - -Please always add meaningful commit messages. Commit message titles (the first line of each commit message which should be separated by an empty line from the rest of the message) should be kept to 50-70 characters if possible. Further details and Fixes #issue number annotations should be placed in the commit message body (i.e, after the empty line). - -Pull requests and commits should be self-contained, allowing readers to understand what changed and why without needing to reference related issues or having prior knowledge. Individual commit messages should include all relevant details to ensure future contributors can easily follow the git history. Clearly explain what is changing and why, and feel free to include detailed (long) descriptions when beneficial to understanding. +Other than that, provide a description above this comment if there isn't one already If this fixes a GitHub issue, make sure to have a line saying 'Fixes #XXXX' (without quotes) in the commit message. --> diff --git a/.github/ci-deps.json b/.github/ci-deps.json deleted file mode 100644 index f075460ff0..0000000000 --- a/.github/ci-deps.json +++ /dev/null @@ -1,5 +0,0 @@ -{ - "jom-1.1.7.exe": "8435dbf96eb9ee65395d46d04dc3af2ff6b2618aefbc7964eeede9be669e8bd6", - "nasm-3.01-installer-x64.exe": "7881e9febc8b6558581041019b7890f109bef0694d93ed82c9589794c7b5a600", - "nasm-3.01-installer-x86.exe": "2e3041dd2abe36cb7e9938057c3cf090dd2eac42d3280957359f87c4d83b9ed0" -} diff --git a/.github/workflows/aarch64-more-cross-compiles.yml b/.github/workflows/aarch64-more-cross-compiles.yml deleted file mode 100644 index 13fdef3925..0000000000 --- a/.github/workflows/aarch64-more-cross-compiles.yml +++ /dev/null @@ -1,202 +0,0 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -name: Cross Compile for AArch64 Extensions - -on: - pull_request: - types: [opened, reopened, edited, synchronize] - push: - schedule: - - cron: '05 03 * * *' - workflow_dispatch: - -permissions: - contents: read - -jobs: - cross-compilation-aarch64: - # pull request title contains 'aarch64' - # pull request title contains 'arm64' - # pull request body contains '[aarch64 ci]' - # push event commit message contains '[aarch64 ci]' - # cron job - # manual dispatch - if: contains(github.event.pull_request.title, 'aarch64') || contains(github.event.pull_request.title, 'AArch64') || contains(github.event.pull_request.title, 'arm64') || contains(github.event.pull_request.body, '[aarch64 ci]') || contains(github.event.head_commit.message, '[aarch64 ci]') || (github.event_name == 'schedule' && github.repository == 'openssl/openssl') || github.event_name == 'workflow_dispatch' - strategy: - fail-fast: false - matrix: - # The platform matrix specifies: - # arch: the architecture to build for, this defines the tool-chain - # prefix {arch}- and the Debian compiler package gcc-{arch} - # name. - # libs: the Debian package for the necessary link/runtime libraries. - # target: the OpenSSL configuration target to use, this is passed - # directly to the config command line. - # fips: set to "no" to disable building FIPS, leave unset to - # build the FIPS provider. - # tests: omit this to run all the tests using QEMU, set it to "none" - # to never run the tests, otherwise its value is passed to - # the "make test" command to allow selective disabling of - # tests. - # qemucpu: optional; string that describes CPU properties. - # The string will be used to set the QEMU_CPU variable. - # opensslcapsname: optional; string that describes the postfix of the - # OpenSSL environment variable that defines CPU - # capabilities. E.g. "foo" will result in an - # environment variable with the name OPENSSL_foo. - # opensslcaps: optional; if opensslcapsname (see above) is set, then - # this string will be used as content for the OpenSSL - # capabilities variable. - # capslabel: label used for artifacts. - platform: [ - { - # Baseline Armv8 crypto extensions: - # include/crypto/aes_platform.h - # providers/implementations/ciphers/cipher_aes_hw_armv8.inc - # crypto/sha/asm/sha1-armv8.pl - # crypto/aes/asm/aes-sha256-armv8.pl - arch: aarch64-linux-gnu, - libs: libc6-dev-arm64-cross, - target: linux-aarch64, - fips: no, - qemucpu: max, - opensslcapsname: armcap, # OPENSSL_armcap - opensslcaps: "0x1d", - capslabel: armv8-crypto - }, { - # PMULL-enabled AES-GCM / GHASH: - # include/crypto/aes_platform.h - # crypto/modes/asm/aes-gcm-armv8_64.pl - # crypto/modes/asm/ghashv8-armx.pl - arch: aarch64-linux-gnu, - libs: libc6-dev-arm64-cross, - target: linux-aarch64, - fips: no, - qemucpu: max, - opensslcapsname: armcap, # OPENSSL_armcap - opensslcaps: "0x3d", - capslabel: armv8-pmull - }, { - # SHA512 extension: - # crypto/aes/asm/aes-sha512-armv8.pl - arch: aarch64-linux-gnu, - libs: libc6-dev-arm64-cross, - target: linux-aarch64, - fips: no, - qemucpu: max, - opensslcapsname: armcap, # OPENSSL_armcap - opensslcaps: "0x7d", - capslabel: armv8-sha512 - }, { - # SHA3-accelerated path. Since OPENSSL_armcap short-circuits runtime - # detection, include the derived "worth using" and unroll bits too: - # crypto/sha/sha3.c - # providers/implementations/digests/sha3_prov.c - # providers/implementations/ciphers/cipher_aes_gcm_hw_armv8.inc - # providers/implementations/ciphers/cipher_aes_hw_armv8.inc - arch: aarch64-linux-gnu, - libs: libc6-dev-arm64-cross, - target: linux-aarch64, - fips: no, - qemucpu: max, - opensslcapsname: armcap, # OPENSSL_armcap - opensslcaps: "0x1987d", - capslabel: armv8-sha3 - }, { - # SVE2 Poly1305 path. OPENSSL_armcap requires the derived - # ARMV9_SVE2_POLY1305 bit to be set explicitly when capability - # probing is overridden: - # crypto/poly1305/asm/poly1305-armv8.pl - # crypto/chacha/asm/chacha-armv8-sve.pl - arch: aarch64-linux-gnu, - libs: libc6-dev-arm64-cross, - target: linux-aarch64, - fips: no, - qemucpu: max, - opensslcapsname: armcap, # OPENSSL_armcap - opensslcaps: "0x2601d", - capslabel: armv9-sve2-poly1305 - } - ] - runs-on: ubuntu-latest - steps: - - name: install packages - run: | - sudo apt-get update - sudo apt-get -yq --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install \ - gcc-${{ matrix.platform.arch }} \ - ${{ matrix.platform.libs }} - - uses: actions/checkout@v6 - with: - persist-credentials: false - - name: checkout fuzz/corpora submodule - run: git submodule update --init --depth 1 fuzz/corpora - - - name: config with FIPS - if: matrix.platform.fips != 'no' - run: | - ./config --banner=Configured --strict-warnings enable-fips enable-lms \ - --cross-compile-prefix=${{ matrix.platform.arch }}- \ - ${{ matrix.platform.target }} - - name: config without FIPS - if: matrix.platform.fips == 'no' - run: | - ./config --banner=Configured --strict-warnings enable-lms \ - --cross-compile-prefix=${{ matrix.platform.arch }}- \ - ${{ matrix.platform.target }} - - name: config dump - run: ./configdata.pm --dump - - - name: make - run: make -s -j4 - - - name: install qemu - if: matrix.platform.tests != 'none' - run: sudo apt-get -yq --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install qemu-user - - - name: Set QEMU environment - if: matrix.platform.qemucpu != '' - run: echo "QEMU_CPU=${{ matrix.platform.qemucpu }}" >> $GITHUB_ENV - - - name: Set OpenSSL caps environment - if: matrix.platform.opensslcapsname != '' - run: echo "OPENSSL_${{ matrix.platform.opensslcapsname }}=\ - ${{ matrix.platform.opensslcaps }}" >> $GITHUB_ENV - - - name: get cpu info - run: cat /proc/cpuinfo - - - name: get openssl cpu info - if: matrix.platform.tests != 'none' - run: QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }} ./util/opensslwrap.sh info -cpusettings - - - name: make all tests - if: github.event_name == 'push' && matrix.platform.tests == '' - run: | - .github/workflows/make-test \ - TESTS="-test_afalg" \ - QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }} - - name: make some tests - if: github.event_name == 'push' && matrix.platform.tests != 'none' && matrix.platform.tests != '' - run: | - .github/workflows/make-test \ - TESTS="${{ matrix.platform.tests }} -test_afalg" \ - QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }} - - name: make evp tests - if: github.event_name == 'pull_request' && matrix.platform.tests != 'none' - run: | - .github/workflows/make-test \ - TESTS="test_evp*" \ - QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }} - - name: save artifacts - if: success() || failure() - uses: actions/upload-artifact@v5 - with: - name: "cross-compiles-aarch64@${{ matrix.platform.capslabel }}" - path: artifacts.tar.gz - if-no-files-found: ignore diff --git a/.github/workflows/avx512-sde.yml b/.github/workflows/avx512-sde.yml deleted file mode 100644 index 1b94df9922..0000000000 --- a/.github/workflows/avx512-sde.yml +++ /dev/null @@ -1,167 +0,0 @@ -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# Copyright (c) 2026 Intel Corporation. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -# Run AVX512-specific tests under Intel SDE. -# -# GitHub Actions runners currently do not have AVX512 hardware. -# Intel SDE emulates AVX512 instructions and spoofs CPUID, -# so AVX512 code paths are exercised. -# -# To update Intel SDE: find the new mirror ID and file date from -# https://www.intel.com/content/www/us/en/download/684897 -# and update the three env vars below. - -name: AVX512 tests via Intel SDE - -on: - schedule: - - cron: '30 02 * * *' - workflow_dispatch: - -permissions: - contents: read - -env: - SDE_VERSION: 10.8.0 - SDE_DATE: 2026-03-15 - SDE_MIRROR_ID: 915934 - -jobs: - linux: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v6 - with: - persist-credentials: false - - - name: install NASM - run: sudo apt-get install -y nasm - - - name: install Intel SDE - run: | - SDE_URL="https://downloadmirror.intel.com/${SDE_MIRROR_ID}/sde-external-${SDE_VERSION}-${SDE_DATE}-lin.tar.xz" - SDE_SHA256="50b320cd226acef7a491f5b321fc1be3c3c7984f9e27a456e64894b5b0979dd3" - curl -fsSL -o /tmp/sde.tar.xz "$SDE_URL" - echo "$SDE_SHA256 /tmp/sde.tar.xz" | sha256sum -c - - mkdir /tmp/sde - tar -xf /tmp/sde.tar.xz -C /tmp/sde/ - sudo mv /tmp/sde/sde-external-${SDE_VERSION}-${SDE_DATE}-lin /opt/sde - echo "/opt/sde" >> "$GITHUB_PATH" - - - name: config - run: | - ./config --banner=Configured --strict-warnings no-shared enable-fips - - - name: build - run: make -j4 - - - name: show CPU and OpenSSL build info - run: | - cat /proc/cpuinfo | grep -m1 "model name" - sde64 -icx -- ./apps/openssl version -c - - - name: ml_dsa_internal_test (AVX512 via SDE) - run: sde64 -icx -- ./test/ml_dsa_internal_test - - - name: sha3_x4_internal_test (AVX512 via SDE) - run: sde64 -icx -- ./test/sha3_x4_internal_test - - - name: fipsinstall (FIPS KAT via SDE) - run: sde64 -icx -- ./apps/openssl fipsinstall -module ./providers/fips.so -out /tmp/fipsmodule.cnf -provider_name fips - - windows: - runs-on: windows-2022 - env: - VCVARS: C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat - steps: - - uses: actions/checkout@v6 - with: - persist-credentials: false - - - name: install nasm - if: github.repository == 'openssl/openssl' - run: | - $installer = "nasm-3.01-installer-x64.exe" - Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/$installer" -OutFile $installer - $expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).$installer - $actual = (Get-FileHash $installer -Algorithm SHA256).Hash - if ($actual -ne $expected) { throw "SHA256 mismatch for $installer (expected $expected, got $actual)" } - Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait - "C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install nasm (forks) - if: github.repository != 'openssl/openssl' - run: | - $installer = "nasm-3.01-installer-x64.exe" - Invoke-WebRequest -Uri "https://www.nasm.us/pub/nasm/releasebuilds/3.01/win64/$installer" -OutFile $installer - Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait - "C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - - name: install jom - if: github.repository == 'openssl/openssl' - run: | - mkdir C:\jom - Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe - $expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe' - $actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash - if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" } - "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install jom (forks) - if: github.repository != 'openssl/openssl' - run: | - mkdir C:\jom - Invoke-WebRequest -Uri "https://download.qt.io/official_releases/jom/jom_1_1_7.zip" -OutFile C:\jom\jom.zip - Expand-Archive -Path C:\jom\jom.zip -DestinationPath C:\jom - "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - - name: install Intel SDE - run: | - $url = "https://downloadmirror.intel.com/$env:SDE_MIRROR_ID/sde-external-$env:SDE_VERSION-$env:SDE_DATE-win.tar.xz" - $expected = "176F87C80EB42BB91B73E1428F4A0FD067DF322F901F9B4359B20B86B92C2BAE" - curl.exe -fsSL -o sde-win.tar.xz $url - $actual = (Get-FileHash sde-win.tar.xz -Algorithm SHA256).Hash - if ($actual -ne $expected) { throw "SDE SHA256 mismatch: got $actual" } - & "C:\Program Files\7-Zip\7z.exe" x sde-win.tar.xz -so | & "C:\Program Files\7-Zip\7z.exe" x -si -ttar -o"C:\sde" - $sdeRoot = "C:\sde\sde-external-$env:SDE_VERSION-$env:SDE_DATE-win" - if (-not (Test-Path "$sdeRoot\sde.exe")) { throw "sde.exe not found in $sdeRoot" } - "$sdeRoot" | Out-File -FilePath $env:GITHUB_PATH -Append - - - name: prepare build directory - run: mkdir _build - - - name: config - working-directory: _build - shell: cmd - run: | - call "%VCVARS%" - perl ..\Configure --banner=Configured --strict-warnings no-shared enable-fips no-makedepend - - - name: build - working-directory: _build - shell: cmd - run: | - call "%VCVARS%" - jom /j4 /S - - - name: show CPU and OpenSSL build info - working-directory: _build - run: sde -icx -- apps\openssl.exe version -c - - - name: ml_dsa_internal_test (AVX512 via SDE) - working-directory: _build - shell: cmd - run: sde -icx -- test\ml_dsa_internal_test.exe - - - name: sha3_x4_internal_test (AVX512 via SDE) - working-directory: _build - shell: cmd - run: sde -icx -- test\sha3_x4_internal_test.exe - - - name: fipsinstall (FIPS KAT via SDE) - working-directory: _build - shell: cmd - run: sde -icx -- apps\openssl.exe fipsinstall -module providers\fips.dll -out fipsmodule.cnf -provider_name fips diff --git a/.github/workflows/backport.yml b/.github/workflows/backport.yml index 86a53a2aba..8a128bb3ab 100644 --- a/.github/workflows/backport.yml +++ b/.github/workflows/backport.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -19,9 +19,6 @@ jobs: matrix: release: [ { - branch: '4.0', - cppflags: '' - }, { branch: '3.6', cppflags: '' }, { @@ -30,6 +27,12 @@ jobs: }, { branch: '3.4', cppflags: 'CPPFLAGS=-ansi' + }, { + branch: '3.3', + cppflags: 'CPPFLAGS=-ansi', + }, { + branch: '3.2', + cppflags: 'CPPFLAGS=-ansi' }, { branch: '3.0', cppflags: 'CPPFLAGS=-ansi' @@ -37,7 +40,7 @@ jobs: ] runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 if: ${{ contains(join(github.event.pull_request.labels.*.name,','),matrix.release.branch) }} with: ref: ${{ github.event.pull_request.head.sha }} @@ -52,7 +55,7 @@ jobs: git config user.name "OpenSSL Machine" git config user.email "openssl-machine@openssl.org" echo Cherry-picking $REFSTART..$REFEND - git cherry-pick $REFSTART..$REFEND || { git diff | head -n1000; exit 1; } + git cherry-pick $REFSTART..$REFEND - name: config if: ${{ contains(join(github.event.pull_request.labels.*.name,','),matrix.release.branch) }} run: ${{ matrix.release.cppflags }} ./config --strict-warnings --banner=Configured no-asm enable-fips --strict-warnings -D_DEFAULT_SOURCE && perl configdata.pm --dump diff --git a/.github/workflows/check-news-changes.yml b/.github/workflows/check-news-changes.yml deleted file mode 100644 index 484b3ee522..0000000000 --- a/.github/workflows/check-news-changes.yml +++ /dev/null @@ -1,105 +0,0 @@ -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -name: "Scan to check for NEWS/CHANGES suggestions" - -on: pull_request -env: - NEED_NEWS_CHANGES: "no" - SKIP_NEWS_CHECK: "no" - PR_NUMBER: ${{ github.event.number }} - GH_TOKEN: ${{ github.token }} -permissions: {} - -jobs: - scan_for_news_changes: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v6 - with: - persist-credentials: false - fetch-depth: 0 - - name: "Check if we have the label to skip this test" - run: | - SKIP_TEST=$(gh pr view $PR_NUMBER --json labels --jq '.labels[] | select(.name == "no_news_changes_needed") | .name') - if [ -n "$SKIP_TEST" ]; then - echo "SKIP_NEWS_CHECK=yes" >> $GITHUB_ENV - fi - - - name: "Check if we already have a NEWS/CHANGES entry" - if: ${{ env.SKIP_NEWS_CHECK == 'no' }} - run: | - git diff --name-only ${{ github.event.pull_request.base.sha }}..${{ github.event.pull_request.head.sha }} > ./names.txt - echo "changed files between ${{ github.event.pull_request.base.sha }} and ${{ github.event.pull_request.head.sha }}" - cat ./names.txt - set +e - grep -q "NEWS\.md" names.txt - if [ $? -eq 0 ]; then - echo "FOUND_NEWS_CHANGES_ADDITION=yes" >> $GITHUB_ENV - else - grep -q "CHANGES\.md" names.txt - if [ $? -eq 0 ]; then - echo "FOUND_NEWS_CHANGES_ADDITION=yes" >> $GITHUB_ENV - else - echo "FOUND_NEWS_CHANGES_ADDITION=no" >> $GITHUB_ENV - fi - fi - - name: "Check if this PR affects a CVE" - if: ${{ env.FOUND_NEWS_CHANGES_ADDITION == 'no' && env.SKIP_NEWS_CHECK == 'no' }} - run: | - git log ${{ github.event.pull_request.base.sha }}..${{ github.event.pull_request.head.sha }} > ./log.txt - set +e - grep -q "CVE-" ./log.txt - if [ $? -eq 0 ]; then - echo "Changes in this PR reference a CVE" - echo "NEED_NEWS_CHANGES=yes" >> $GITHUB_ENV - fi - - name: "Check if this PR impacts a public API" - if: ${{ env.FOUND_NEWS_CHANGES_ADDITION == 'no' && env.SKIP_NEWS_CHECK == 'no' }} - run: | - set +e - git diff --name-only ${{ github.event.pull_request.base.sha }}..${{ github.event.pull_request.head.sha }} > ./names.txt - echo "changed files between ${{ github.event.pull_request.base.sha }} and ${{ github.event.pull_request.head.sha }}" - cat ./names.txt - grep -q "include/openssl" ./names.txt - if [ $? -eq 0 ]; then - echo "Changes in this PR may impact public APIS's" - echo "NEED_NEWS_CHANGES=yes" >> $GITHUB_ENV - fi - - name: "Check if this is a feature branch merge" - if: ${{ env.FOUND_NEWS_CHANGES_ADDITION == 'no' && env.SKIP_NEWS_CHECK == 'no' }} - run: | - set +e - echo ${{ github.head_ref }} | grep -q "feature" - if [ $? -eq 0 ]; then - echo "Feature branch found" - echo "NEED_NEWS_CHANGES=yes" >> $GITHUB_ENV - fi - - name: "Check if configuration options have changed" - if: ${{ env.FOUND_NEWS_CHANGES_ADDITION == 'no' && env.SKIP_NEWS_CHECK == 'no' }} - run: | - git checkout ${{ github.event.pull_request.base.sha }} - set +e - ./Configure --help > ./before.txt 2>&1 - git checkout ${{ github.event.pull_request.head.sha }} - ./Configure --help > ./after.txt 2>&1 - set -e - CONF_CHANGE=$(diff ./before.txt ./after.txt | wc -l) - if [ $CONF_CHANGE -ne 0 ]; then - echo "Configuration options changes" - echo "NEED_NEWS_CHANGES=yes" >> $GITHUB_ENV - fi - - name: "Report Results" - if: ${{ env.SKIP_NEWS_CHECK == 'no' }} - run: | - if [ "${{ env.NEED_NEWS_CHANGES }}" == "yes" ]; then - echo "Suggest that you add a NEWS/CHANGES entry for this PR" - echo "Alternatively, quiet this suggestion by applying the no_news_changes_needed label" - exit 1 - fi - - diff --git a/.github/workflows/ci-doc-changes.yml b/.github/workflows/ci-doc-changes.yml deleted file mode 100644 index 08919fc323..0000000000 --- a/.github/workflows/ci-doc-changes.yml +++ /dev/null @@ -1,125 +0,0 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -name: Documentation and Installability CI - -on: [pull_request, push] - -permissions: - contents: read - -env: - OSSL_RUN_CI_TESTS: 1 - -jobs: - check_docs: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v6 - with: - persist-credentials: false - - name: config - run: ./config --strict-warnings --banner=Configured enable-fips && perl configdata.pm --dump - - name: make build_generated - run: make -s build_generated - - name: make doc-nits - run: make doc-nits - - name: make help - run: make help - - name: make md-nits - run: | - sudo gem install mdl - make md-nits - - # out-of-source-and-install checks multiple things at the same time: - # - That building, testing and installing works from an out-of-source - # build tree - # - That building, testing and installing works with a read-only source - # tree - out-of-readonly-source-and-install-ubuntu: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v6 - with: - path: ./source - persist-credentials: false - - name: checkout fuzz/corpora submodule - run: git submodule update --init --depth 1 fuzz/corpora - working-directory: ./source - - name: make source read-only - run: chmod -R a-w ./source - - name: create build and install directories - run: | - mkdir ./build - mkdir ./install - - name: config - run: | - ../source/config --banner=Configured enable-demos enable-h3demo enable-fips enable-lms enable-quic enable-acvp-tests --strict-warnings --prefix=$(cd ../install; pwd) - perl configdata.pm --dump - working-directory: ./build - - name: make - run: make -s -j4 - working-directory: ./build - - name: get cpu info - run: | - cat /proc/cpuinfo - ./util/opensslwrap.sh version -c - working-directory: ./build - - name: make test - run: ../source/.github/workflows/make-test - working-directory: ./build - - name: save artifacts - if: success() || failure() - uses: actions/upload-artifact@v5 - with: - name: "ci@out-of-readonly-source-and-install-ubuntu" - path: build/artifacts.tar.gz - - name: make install - run: make install - working-directory: ./build - - out-of-readonly-source-and-install-macos: - runs-on: macos-15 - steps: - - uses: actions/checkout@v6 - with: - path: ./source - persist-credentials: false - - name: checkout fuzz/corpora submodule - run: git submodule update --init --depth 1 fuzz/corpora - working-directory: ./source - - name: make source read-only - run: chmod -R a-w ./source - - name: create build and install directories - run: | - mkdir ./build - mkdir ./install - - name: config - run: | - ../source/config --banner=Configured enable-fips enable-lms enable-demos enable-h3demo enable-quic enable-acvp-tests --strict-warnings --prefix=$(cd ../install; pwd) - perl configdata.pm --dump - working-directory: ./build - - name: make - run: make -s -j4 - working-directory: ./build - - name: get cpu info - run: | - sysctl machdep.cpu - ./util/opensslwrap.sh version -c - working-directory: ./build - - name: make test - run: ../source/.github/workflows/make-test - working-directory: ./build - - name: save artifacts - if: success() || failure() - uses: actions/upload-artifact@v5 - with: - name: "ci@out-of-readonly-source-and-install-macos-15" - path: build/artifacts.tar.gz - - name: make install - run: make install - working-directory: ./build diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index a80ea66b29..d4712c262e 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -7,25 +7,7 @@ name: GitHub CI -on: - pull_request: - paths-ignore: - - 'doc/**' - - '*.md' - - '*.pod' - - 'README*' - - 'funding.json' - - 'LICENSE.txt' - - 'VERSION.dat' - push: - paths-ignore: - - 'doc/**' - - '*.md' - - '*.pod' - - 'README*' - - 'funding.json' - - 'LICENSE.txt' - - 'VERSION.dat' +on: [pull_request, push] # for some reason, this does not work: # variables: @@ -50,7 +32,7 @@ jobs: run: | sudo apt-get update sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install unifdef - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: fetch-depth: 0 persist-credentials: false @@ -63,13 +45,32 @@ jobs: - name: git diff run: git diff --exit-code + check_docs: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v5 + with: + persist-credentials: false + - name: config + run: ./config --strict-warnings --banner=Configured enable-fips && perl configdata.pm --dump + - name: make build_generated + run: make -s build_generated + - name: make doc-nits + run: make doc-nits + - name: make help + run: make help + - name: make md-nits + run: | + sudo gem install mdl + make md-nits + # This checks that we use ANSI C language syntax and semantics. # We are not as strict with libraries, but rather adapt to what's # expected to be available in a certain version of each platform. check-c99: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: config @@ -80,21 +81,19 @@ jobs: basic_gcc: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule run: git submodule update --init --depth 1 fuzz/corpora - name: localegen run: sudo locale-gen tr_TR.UTF-8 - - name: cmocka - run: sudo apt-get -y install libcmocka-dev - name: fipsvendor # Make one fips build use a customized FIPS vendor run: echo "FIPS_VENDOR=CI" >> VERSION.dat - name: config # enable-quic is on by default, but we leave it here to check we're testing the explicit enable somewhere - run: CC=gcc ./config --strict-warnings --banner=Configured enable-demos enable-h3demo enable-ec_explicit_curves enable-sslkeylog enable-fips enable-quic enable-lms enable-unit-tests && perl configdata.pm --dump + run: CC=gcc ./config --strict-warnings --banner=Configured enable-demos enable-h3demo enable-sslkeylog enable-fips enable-quic enable-lms && perl configdata.pm --dump - name: make run: make -s -j4 - name: get cpu info @@ -116,7 +115,7 @@ jobs: basic_clang: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -141,11 +140,11 @@ jobs: linux-arm64: runs-on: ubuntu-24.04-arm steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: config - run: ./config --strict-warnings enable-demos enable-fips enable-lms enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace + run: ./config --strict-warnings enable-demos enable-fips enable-lms enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace - name: config dump run: ./configdata.pm --dump - name: make @@ -163,35 +162,10 @@ jobs: name: "ci@linux-arm64" path: artifacts.tar.gz - gcc-min-version: - runs-on: ubuntu-latest - container: - image: docker.io/gcc:9 - timeout-minutes: 90 - strategy: - fail-fast: false - steps: - - uses: actions/checkout@v6 - with: - persist-credentials: false - - name: config - run: ./config --strict-warnings --banner=Configured enable-fips && perl configdata.pm --dump - - name: make - run: make -s -j4 - - name: print gcc version - run: | - gcc --version - - name: get cpu info - run: | - cat /proc/cpuinfo - ./util/opensslwrap.sh version -c - - name: make test - run: .github/workflows/make-test - linux-x86: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: run container @@ -204,7 +178,7 @@ jobs: - name: config run: | podman exec -t $CONTAINER_ID sh -c \ - "./config --strict-warnings linux-x86 enable-demos enable-fips enable-lms enable-md2 enable-rc5 enable-trace" + "./config --strict-warnings linux-x86 enable-demos enable-fips enable-lms enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace" - name: config dump run: | podman exec -t $CONTAINER_ID sh -c \ @@ -232,7 +206,7 @@ jobs: freebsd-x86_64: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: config @@ -243,7 +217,7 @@ jobs: shutdown_vm: false run: | sudo pkg install -y gcc perl5 - ./config --strict-warnings enable-fips enable-lms enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace + ./config --strict-warnings enable-fips enable-lms enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace - name: config dump uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0 with: @@ -276,7 +250,7 @@ jobs: minimal: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -301,7 +275,7 @@ jobs: no-deprecated: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -326,7 +300,7 @@ jobs: no-shared-ubuntu: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -351,7 +325,7 @@ jobs: no-shared-macos: runs-on: macos-14 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -376,7 +350,7 @@ jobs: non-caching: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -405,7 +379,7 @@ jobs: address_ub_sanitizer: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -415,7 +389,7 @@ jobs: sudo cat /proc/sys/vm/mmap_rnd_bits sudo sysctl -w vm.mmap_rnd_bits=28 - name: config - run: ./config --strict-warnings --banner=Configured --debug enable-demos enable-h3demo enable-asan enable-ec_explicit_curves enable-ubsan enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-fips enable-lms && perl configdata.pm --dump + run: ./config --strict-warnings --banner=Configured --debug enable-demos enable-h3demo enable-asan enable-ubsan enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-fips enable-lms && perl configdata.pm --dump - name: make run: make -s -j4 - name: get cpu info @@ -434,7 +408,7 @@ jobs: fuzz_tests: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -444,7 +418,7 @@ jobs: sudo cat /proc/sys/vm/mmap_rnd_bits sudo sysctl -w vm.mmap_rnd_bits=28 - name: config - run: ./config --strict-warnings --banner=Configured --debug -DPEDANTIC -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION enable-asan enable-ec_explicit_curves enable-ubsan enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-weak-ssl-ciphers enable-nextprotoneg && perl configdata.pm --dump + run: ./config --strict-warnings --banner=Configured --debug -DPEDANTIC -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION enable-asan enable-ubsan enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-weak-ssl-ciphers enable-ssl3 enable-ssl3-method enable-nextprotoneg && perl configdata.pm --dump - name: make run: make -s -j4 - name: get cpu info @@ -461,44 +435,10 @@ jobs: path: artifacts.tar.gz if-no-files-found: ignore - fuzz_tests_mfail: - runs-on: ubuntu-latest - timeout-minutes: 30 - steps: - - uses: actions/checkout@v6 - with: - persist-credentials: false - - name: checkout fuzz/corpora submodule - run: git submodule update --init --depth 1 fuzz/corpora - - name: Adjust ASLR for sanitizer - run: sudo sysctl -w vm.mmap_rnd_bits=28 - - name: config - run: | - ./config --strict-warnings --banner=Configured --debug \ - -DPEDANTIC -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION \ - enable-asan enable-ec_explicit_curves enable-ubsan \ - enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 \ - enable-weak-ssl-ciphers enable-nextprotoneg - perl configdata.pm --dump - - name: make - run: make -s -j4 - - name: make test (fuzz with mfail) - env: - OSSL_FUZZ_TEST_BUDGET: 1200 - OSSL_FUZZ_TEST_JOBS: 4 - run: .github/workflows/make-test OPENSSL_TEST_RAND_ORDER=0 TESTS="test_fuzz*" - - name: save artifacts - if: success() || failure() - uses: actions/upload-artifact@v5 - with: - name: "ci@fuzz_tests_mfail" - path: artifacts.tar.gz - if-no-files-found: ignore - memory_sanitizer: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -509,7 +449,7 @@ jobs: sudo sysctl -w vm.mmap_rnd_bits=28 - name: config # --debug -O1 is to produce a debug build that runs in a reasonable amount of time - run: CC=clang ./config --strict-warnings --banner=Configured --debug no-shared -O1 -fsanitize=memory -DOSSL_SANITIZE_MEMORY -fno-optimize-sibling-calls enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-ec_explicit_curves enable-fips enable-lms no-slh-dsa && perl configdata.pm --dump + run: CC=clang ./config --strict-warnings --banner=Configured --debug no-shared -O1 -fsanitize=memory -DOSSL_SANITIZE_MEMORY -fno-optimize-sibling-calls enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-fips enable-lms no-slh-dsa && perl configdata.pm --dump - name: make run: make -s -j4 - name: get cpu info @@ -528,7 +468,7 @@ jobs: threads_sanitizer: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -557,7 +497,7 @@ jobs: enable_non-default_options: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -584,7 +524,7 @@ jobs: full_featured: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -598,7 +538,7 @@ jobs: - name: install extra config support run: sudo apt-get -y install libsctp-dev abigail-tools libzstd-dev zstd - name: config - run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo enable-ec_explicit_curves enable-ktls enable-fips enable-lms enable-egd enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-sctp enable-weak-ssl-ciphers enable-trace enable-zlib enable-zstd && perl configdata.pm --dump + run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo enable-ktls enable-fips enable-lms enable-egd enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-sctp enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers enable-trace enable-zlib enable-zstd && perl configdata.pm --dump - name: make run: make -s -j4 - name: get cpu info @@ -617,7 +557,7 @@ jobs: no-legacy: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -642,13 +582,13 @@ jobs: legacy: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule run: git submodule update --init --depth 1 fuzz/corpora - name: config - run: ./config --strict-warnings --banner=Configured --debug enable-demos enable-h3demo no-shared enable-crypto-mdebug enable-rc5 enable-md2 enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-ec_explicit_curves no-fips && perl configdata.pm --dump + run: ./config --strict-warnings --banner=Configured --debug enable-demos enable-h3demo no-shared enable-crypto-mdebug enable-rc5 enable-md2 enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-fips && perl configdata.pm --dump - name: make run: make -s -j4 - name: get cpu info @@ -664,10 +604,99 @@ jobs: name: "ci@legacy" path: artifacts.tar.gz + # out-of-source-and-install checks multiple things at the same time: + # - That building, testing and installing works from an out-of-source + # build tree + # - That building, testing and installing works with a read-only source + # tree + out-of-readonly-source-and-install-ubuntu: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v5 + with: + path: ./source + persist-credentials: false + - name: checkout fuzz/corpora submodule + run: git submodule update --init --depth 1 fuzz/corpora + working-directory: ./source + - name: make source read-only + run: chmod -R a-w ./source + - name: create build and install directories + run: | + mkdir ./build + mkdir ./install + - name: config + run: | + ../source/config --banner=Configured enable-demos enable-h3demo enable-fips enable-lms enable-quic enable-acvp-tests --strict-warnings --prefix=$(cd ../install; pwd) + perl configdata.pm --dump + working-directory: ./build + - name: make + run: make -s -j4 + working-directory: ./build + - name: get cpu info + run: | + cat /proc/cpuinfo + ./util/opensslwrap.sh version -c + working-directory: ./build + - name: make test + run: ../source/.github/workflows/make-test + working-directory: ./build + - name: save artifacts + if: success() || failure() + uses: actions/upload-artifact@v5 + with: + name: "ci@out-of-readonly-source-and-install-ubuntu" + path: build/artifacts.tar.gz + - name: make install + run: make install + working-directory: ./build + + out-of-readonly-source-and-install-macos: + runs-on: macos-15 + steps: + - uses: actions/checkout@v5 + with: + path: ./source + persist-credentials: false + - name: checkout fuzz/corpora submodule + run: git submodule update --init --depth 1 fuzz/corpora + working-directory: ./source + - name: make source read-only + run: chmod -R a-w ./source + - name: create build and install directories + run: | + mkdir ./build + mkdir ./install + - name: config + run: | + ../source/config --banner=Configured enable-fips enable-lms enable-demos enable-h3demo enable-quic enable-acvp-tests --strict-warnings --prefix=$(cd ../install; pwd) + perl configdata.pm --dump + working-directory: ./build + - name: make + run: make -s -j4 + working-directory: ./build + - name: get cpu info + run: | + sysctl machdep.cpu + ./util/opensslwrap.sh version -c + working-directory: ./build + - name: make test + run: ../source/.github/workflows/make-test + working-directory: ./build + - name: save artifacts + if: success() || failure() + uses: actions/upload-artifact@v5 + with: + name: "ci@out-of-readonly-source-and-install-macos-15" + path: build/artifacts.tar.gz + - name: make install + run: make install + working-directory: ./build + external-tests-misc: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: submodules: recursive persist-credentials: false @@ -675,10 +704,14 @@ jobs: run: | sudo apt-get update sudo apt-get -yq install bison gettext keyutils ldap-utils libldap2-dev libkeyutils-dev python3 python3-paste python3-pyrad slapd tcsh python3-virtualenv virtualenv python3-kdcproxy gdb libtls-dev wget gpg + - name: install cpanm and Test2::V0 for gost_engine testing + uses: perl-actions/install-with-cpanm@10d60f00b4073f484fc29d45bfbe2f776397ab3d # v1.7 + with: + install: Test2::V0 - name: setup hostname workaround run: sudo hostname localhost - name: config - run: ./config --strict-warnings --banner=Configured --debug enable-rc5 enable-md2 enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-external-tests no-fips && perl configdata.pm --dump + run: ./config --strict-warnings --banner=Configured --debug enable-rc5 enable-md2 enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-external-tests no-fips && perl configdata.pm --dump - name: make run: make -s -j4 - uses: dtolnay/rust-toolchain@0f44b27771c32bda9f458f75a1e241b09791b331 @@ -688,9 +721,8 @@ jobs: run: | cat /proc/cpuinfo ./util/opensslwrap.sh version -c - - name: test failure when selecting non-existing test case - run: | - ! make test TESTS="test_external_gost_engine" + - name: test external gost-engine + run: make test TESTS="test_external_gost_engine" - name: test external krb5 run: make test TESTS="test_external_krb5" - name: test external tlsfuzzer @@ -708,7 +740,7 @@ jobs: external-tests-oqs-provider: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: submodules: recursive persist-credentials: false @@ -729,13 +761,13 @@ jobs: steps: - name: package installs run: | - dnf install -y perl-FindBin perl-IPC-Cmd perl-File-Compare perl-File-Copy perl-Test-Simple perl-Test-Harness python3 make g++ perl git meson opensc expect kryoptic xxd - - uses: actions/checkout@v6 + dnf install -y perl-FindBin perl-IPC-Cmd perl-File-Compare perl-File-Copy perl-Test-Simple perl-Test-Harness python3 make g++ perl git meson opensc expect kryoptic + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora and pkcs11-provider submodule run: | - git config --global --add safe.directory "$GITHUB_WORKSPACE" + git config --global --add safe.directory /__w/openssl/openssl git submodule update --init --depth 1 fuzz/corpora git submodule update --init --depth 1 pkcs11-provider - name: config @@ -761,7 +793,7 @@ jobs: PYTHON: - 3.9 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: submodules: recursive persist-credentials: false @@ -786,50 +818,3 @@ jobs: ./util/opensslwrap.sh version -c - name: test external pyca run: make test TESTS="test_external_pyca" VERBOSE=1 - - external-test-bssl: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v6 - with: - persist-credentials: false - - name: Configure OpenSSL - run: ./config enable-external-tests - - name: Build OpenSSL - run: make -s -j4 - - name: Clone BoringSSL 0.20260211.0 - run: git clone --depth 1 --branch 0.20260211.0 https://boringssl.googlesource.com/boringssl - - name: Configure and Build BoringSSL - run: | - cd boringssl - mkdir build - cd build - cmake -DCMAKE_INSTALL_PREFIX=../../boringssl/.local .. - make -s -j4 - make install - cd ../.. - - name: Test ECH with BoringSSL - run: make test TESTS='test_external_ech_bssl' V=1 - - external-test-nss: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v6 - with: - persist-credentials: false - - name: Configure OpenSSL - run: ./config enable-external-tests - - name: Build OpenSSL - run: make -s -j4 - - name: Clone and Build NSS - run: | - mkdir nss - cd nss - git clone --depth 1 --branch NSS_3_112_3_RTM https://github.com/nss-dev/nss.git - hg clone https://hg.mozilla.org/projects/nspr -r NSPR_4_36_BRANCH - cd nss - USE_64=1 make nss_build_all - USE_64=1 make install - cd ../.. - - name: Test ECH with NSS - run: make test TESTS='test_external_ech_nss' V=1 diff --git a/.github/workflows/compiler-zoo.yml b/.github/workflows/compiler-zoo.yml index 6422733a43..77f1496ac1 100644 --- a/.github/workflows/compiler-zoo.yml +++ b/.github/workflows/compiler-zoo.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -24,7 +24,7 @@ jobs: run: | sudo apt-get update sudo apt-get -y install ${{ matrix.gcc }} - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -37,7 +37,7 @@ jobs: - name: config dump run: ./configdata.pm --dump - name: make - run: make -s -j4 + run: make -s -j - name: get cpu info run: | cat /proc/cpuinfo @@ -49,7 +49,7 @@ jobs: strategy: fail-fast: false matrix: - clang: [clang-11, clang-12, clang-13, clang-14, clang-15, clang-16, clang-17, clang-18, clang-19, clang-20, clang-21] + clang: [clang-11, clang-12, clang-13, clang-14, clang-15, clang-16, clang-17, clang-18, clang-19, clang-20] runs-on: ubuntu-22.04 steps: - name: install packages @@ -60,7 +60,7 @@ jobs: echo "deb http://apt.llvm.org/jammy/ llvm-toolchain-jammy-$VERSION main" | sudo tee -a /etc/apt/sources.list sudo apt-get update || true sudo apt-get -y install ${{ matrix.clang }} - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -73,7 +73,7 @@ jobs: - name: config dump run: ./configdata.pm --dump - name: make - run: make -s -j4 + run: make -s -j - name: get cpu info run: | cat /proc/cpuinfo diff --git a/.github/workflows/coveralls.yml b/.github/workflows/coveralls.yml index 34075a3566..c219577991 100644 --- a/.github/workflows/coveralls.yml +++ b/.github/workflows/coveralls.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -46,23 +46,29 @@ jobs: else MATRIX=$(cat << EOF [{ - "branch": "master", - "extra_config": "enable-fips enable-tfo enable-lms enable-crypto-mdebug enable-unit-tests" - }, { - "branch": "openssl-4.0", - "extra_config": "enable-fips enable-tfo enable-lms enable-crypto-mdebug" - },{ "branch": "openssl-3.6", - "extra_config": "no-afalgeng enable-fips enable-tfo enable-lms" + "extra_config": "no-afalgeng enable-fips enable-tfo" },{ "branch": "openssl-3.5", "extra_config": "no-afalgeng enable-fips enable-tfo" },{ "branch": "openssl-3.4", "extra_config": "no-afalgeng enable-fips enable-tfo" + }, { + "branch": "openssl-3.3", + "extra_config": "no-afalgeng enable-fips enable-tfo" + }, { + "branch": "openssl-3.2", + "extra_config": "no-afalgeng enable-fips enable-tfo" + }, { + "branch": "openssl-3.1", + "extra_config": "no-afalgeng enable-fips" }, { "branch": "openssl-3.0", "extra_config": "no-afalgeng enable-fips" + }, { + "branch": "master", + "extra_config": "enable-fips enable-tfo enable-lms enable-crypto-mdebug enable-allocfail-tests" }] EOF ) @@ -81,7 +87,7 @@ jobs: branches: ${{ fromJSON(needs.define-matrix.outputs.branches) }} runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: submodules: recursive ref: ${{ matrix.branches.branch }} @@ -93,7 +99,7 @@ jobs: run: | sudo apt-get update sudo apt-get -yq install lcov - sudo apt-get -yq install bison gettext keyutils ldap-utils libcmocka-dev libldap2-dev libkeyutils-dev python3 python3-paste python3-pyrad slapd tcsh python3-virtualenv virtualenv python3-kdcproxy + sudo apt-get -yq install bison gettext keyutils ldap-utils libldap2-dev libkeyutils-dev python3 python3-paste python3-pyrad slapd tcsh python3-virtualenv virtualenv python3-kdcproxy - name: install Test2::V0 for gost_engine testing uses: perl-actions/install-with-cpanm@10d60f00b4073f484fc29d45bfbe2f776397ab3d #v1.7 with: @@ -101,7 +107,7 @@ jobs: - name: setup hostname workaround run: sudo hostname localhost - name: config - run: CC=gcc ./config --debug --coverage ${{ matrix.branches.extra_config }} no-asm enable-rc5 enable-md2 enable-nextprotoneg enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-buildtest-c++ enable-ssl-trace enable-trace + run: CC=gcc ./config --debug --coverage ${{ matrix.branches.extra_config }} no-asm enable-rc5 enable-md2 enable-ssl3 enable-nextprotoneg enable-ssl3-method enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-buildtest-c++ enable-ssl-trace enable-trace - name: config dump run: ./configdata.pm --dump - name: make diff --git a/.github/workflows/cross-compiles.yml b/.github/workflows/cross-compiles.yml index d0f5ff8284..b0f8d362ec 100644 --- a/.github/workflows/cross-compiles.yml +++ b/.github/workflows/cross-compiles.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -7,35 +7,13 @@ name: Cross Compile -on: - pull_request: - paths-ignore: - - 'doc/**' - - '*.md' - - '*.pod' - - 'README*' - - 'funding.json' - - 'LICENSE.txt' - - 'VERSION.dat' - push: - paths-ignore: - - 'doc/**' - - '*.md' - - '*.pod' - - 'README*' - - 'funding.json' - - 'LICENSE.txt' - - 'VERSION.dat' +on: [pull_request, push] permissions: contents: read jobs: cross-compilation: - # Run the full test suite on push, and on pull requests labelled with - # 'extended tests'. Other pull requests only run the EVP tests. - env: - EXTENDED: ${{ github.event_name == 'push' || contains(github.event.pull_request.labels.*.name, 'extended tests') }} strategy: fail-fast: false matrix: @@ -190,7 +168,7 @@ jobs: sudo apt-get -yq --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install \ gcc-${{ matrix.platform.arch }} \ ${{ matrix.platform.libs }} - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -233,19 +211,19 @@ jobs: cat /proc/cpuinfo QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }} ./util/opensslwrap.sh version -c - name: make all tests - if: env.EXTENDED == 'true' && matrix.platform.tests == '' + if: github.event_name == 'push' && matrix.platform.tests == '' run: | .github/workflows/make-test \ TESTS="-test_afalg" \ QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }} - name: make some tests - if: env.EXTENDED == 'true' && matrix.platform.tests != 'none' && matrix.platform.tests != '' + if: github.event_name == 'push' && matrix.platform.tests != 'none' && matrix.platform.tests != '' run: | .github/workflows/make-test \ TESTS="${{ matrix.platform.tests }} -test_afalg" \ QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }} - name: make evp tests - if: env.EXTENDED != 'true' && matrix.platform.tests != 'none' + if: github.event_name == 'pull_request' && matrix.platform.tests != 'none' run: | .github/workflows/make-test \ TESTS="test_evp*" \ diff --git a/.github/workflows/ct-validation-daily.yml b/.github/workflows/ct-validation-daily.yml deleted file mode 100644 index 18d8911fcb..0000000000 --- a/.github/workflows/ct-validation-daily.yml +++ /dev/null @@ -1,110 +0,0 @@ -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -name: Constant-time validation (daily) -# Verifies that several algorithms needing constant-time execution do not -# branch on secret data. -# -# The library is built with enable-ct-validation, which defines -# OPENSSL_CONSTANT_TIME_VALIDATION and causes secret regions to be marked -# as "uninitialised" from Valgrind memcheck's perspective. The tests are -# then run via "make test" with OSSL_VALGRIND_CT=yes, which makes -# OpenSSL::Test::test() wrap every test binary with: -# -# valgrind --tool=memcheck --track-origins=yes --error-exitcode=1 -# -# The wrapper chain (util/wrap.pl -> util/shlib_wrap.sh) is preserved, so -# LD_LIBRARY_PATH is set correctly for shared-library builds. Any -# control-flow branch or memory index that depends on secret data causes -# valgrind to exit with code 1, which propagates back through the test -# harness and fails the job. -# -# See include/internal/constant_time.h for the CONSTTIME_SECRET / -# CONSTTIME_DECLASSIFY macro documentation. -# -# Architecture note: Valgrind's memcheck supports x86_64, aarch64, s390x, -# and ppc64 well. GitHub Actions provides hosted runners for x86_64 -# (ubuntu-latest) and aarch64 (ubuntu-24.04-arm); we test both here. -# s390x and ppc64 runners are not available in the public GitHub Actions -# fleet, so they are not included. -# -# Package note: on Debian/Ubuntu the valgrind package bundles the C headers -# (valgrind/memcheck.h) — no separate -dev package is required. On Fedora -# the headers are in valgrind-devel; see Configure for the full list. - -on: - schedule: - - cron: '45 03 * * *' - workflow_dispatch: - -permissions: - contents: read - -jobs: - ct-validation: - if: github.repository == 'openssl/openssl' - strategy: - fail-fast: false - matrix: - # Constant-timeness is a property of the generated machine code, which - # the compiler derives differently per architecture. Therefore we verify - # both the assembly and C implementations on every architecture we can - # run Valgrind on. - include: - # Default builds use assembler implementations (when available) - - name: linux-x86_64 - runs-on: ubuntu-latest - config_extra: "" - - name: linux-aarch64 - runs-on: ubuntu-24.04-arm - config_extra: "" - - # no-asm builds always use C implementations - - name: linux-x86_64-no-asm - runs-on: ubuntu-latest - config_extra: no-asm - - name: linux-aarch64-no-asm - runs-on: ubuntu-24.04-arm - config_extra: no-asm - - name: CT validation (${{ matrix.name }}) - runs-on: ${{ matrix.runs-on }} - - steps: - - uses: actions/checkout@v6 - with: - persist-credentials: false - - - name: Install valgrind - # On Debian/Ubuntu the main 'valgrind' package includes - # /usr/include/valgrind/memcheck.h — no separate -dev package needed. - run: | - sudo apt-get -y update - sudo apt-get -y install valgrind - - - name: Configure with CT validation enabled - run: | - ./Configure enable-ct-validation ${{ matrix.config_extra }} - ./configdata.pm --dump - - - name: Build - run: make -j$(nproc) - - - name: Run CT validation under Valgrind - # OSSL_VALGRIND_CT=yes causes OpenSSL::Test::test() to wrap each - # test binary with valgrind --track-origins=yes --error-exitcode=1. - # util/wrap.pl -> util/shlib_wrap.sh sets LD_LIBRARY_PATH first, so - # the shared libraries are found correctly. - # - # Algorithms covered: - # - memcmp: test_crypto_memcmp - # - ML-KEM: test_internal_ml_kem - # - ML-DSA: test_internal_ml_dsa - run: | - make TESTS="test_internal_ml_kem test_internal_ml_dsa test_crypto_memcmp" \ - OSSL_VALGRIND_CT=yes \ - test diff --git a/.github/workflows/fips-checksums.yml b/.github/workflows/fips-checksums.yml index 5fd96b3159..67e7cd13a9 100644 --- a/.github/workflows/fips-checksums.yml +++ b/.github/workflows/fips-checksums.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -6,16 +6,7 @@ # https://www.openssl.org/source/license.html name: FIPS Check and ABIDIFF -on: - pull_request: - paths-ignore: - - 'doc/**' - - '*.md' - - '*.pod' - - 'README*' - - 'funding.json' - - 'LICENSE.txt' - - 'VERSION.dat' +on: [pull_request] permissions: contents: read @@ -35,7 +26,7 @@ jobs: mkdir ./build mkdir ./source mkdir ./artifact - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: repository: ${{ github.event.pull_request.base.repo.full_name }} ref: ${{ github.event.pull_request.base.ref }} @@ -53,7 +44,7 @@ jobs: - name: make fips-checksums pristine run: make fips-checksums working-directory: ./build-pristine - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: path: source persist-credentials: false @@ -88,7 +79,7 @@ jobs: compute-abidiff: runs-on: ubuntu-latest env: - BUILD_OPTS: -g --strict-warnings enable-ktls enable-fips enable-egd enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-sctp enable-trace enable-zlib enable-zstd + BUILD_OPTS: -g --strict-warnings enable-ktls enable-fips enable-egd enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-sctp enable-ssl3 enable-ssl3-method enable-trace enable-zlib enable-zstd steps: - name: create build dirs run: | @@ -99,7 +90,7 @@ jobs: mkdir ./artifact - name: install extra config support run: sudo apt-get -y install libsctp-dev abigail-tools libzstd-dev zstd - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: repository: ${{ github.event.pull_request.base.repo.full_name }} ref: ${{ github.event.pull_request.base.ref }} @@ -111,7 +102,7 @@ jobs: - name: make pristine run: make -s -j4 working-directory: ./build-pristine - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: path: source persist-credentials: false diff --git a/.github/workflows/fuzz-checker.yml b/.github/workflows/fuzz-checker.yml index 3f7f864976..184fd7b739 100644 --- a/.github/workflows/fuzz-checker.yml +++ b/.github/workflows/fuzz-checker.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -35,7 +35,7 @@ jobs: name: libFuzzer+, config: enable-fuzz-libfuzzer enable-asan enable-ubsan -fno-sanitize=function -fsanitize-coverage=trace-cmp -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION, libs: --with-fuzzer-lib=/usr/lib/llvm-18/lib/libFuzzer.a --with-fuzzer-include=/usr/include/clang/18/include/fuzzer, - extra: enable-fips enable-lms enable-ec_nistp_64_gcc_128 -fno-sanitize=alignment enable-tls1_3 enable-weak-ssl-ciphers enable-rc5 enable-md2 enable-nextprotoneg, + extra: enable-fips enable-lms enable-ec_nistp_64_gcc_128 -fno-sanitize=alignment enable-tls1_3 enable-weak-ssl-ciphers enable-rc5 enable-md2 enable-ssl3 enable-ssl3-method enable-nextprotoneg, install: libfuzzer-18-dev, cc: clang-18, linker: clang++-18, @@ -52,7 +52,7 @@ jobs: run: | sudo cat /proc/sys/vm/mmap_rnd_bits sudo sysctl -w vm.mmap_rnd_bits=28 - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false diff --git a/.github/workflows/interop-tests.yml b/.github/workflows/interop-tests.yml index 65e273f0e0..f764a29322 100644 --- a/.github/workflows/interop-tests.yml +++ b/.github/workflows/interop-tests.yml @@ -16,7 +16,7 @@ jobs: if: github.repository == 'openssl/openssl' runs-on: ubuntu-22.04 container: - image: docker.io/fedora:43 + image: docker.io/fedora:40 options: --sysctl net.ipv6.conf.lo.disable_ipv6=0 timeout-minutes: 90 strategy: @@ -26,31 +26,29 @@ jobs: env: COMPONENT: ${{ matrix.COMPONENT }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: Display environment run: export - name : Install needed tools run: | - dnf -y install perl gcc make \ - rpmdevtools dnf-utils \ - tmt-all beakerlib \ - crypto-policies-scripts + dnf -y install perl gcc rpmdevtools dnf-utils make tmt-all beakerlib \ + fips-mode-setup crypto-policies-scripts - name: install interop tests run: | cd ${GITHUB_WORKSPACE} - git clone --branch=openssl-v0.2 --depth=1 https://gitlab.com/redhat-crypto/tests/interop.git + git clone --branch=openssl-v0.1 --depth=1 https://gitlab.com/redhat-crypto/tests/interop.git - name: build openssl as an rpm run: | mkdir -p /build/SPECS && cd /build && echo -e "%_topdir /build\n%_lto_cflags %{nil}" >~/.rpmmacros && rpmdev-setuptree cd /build && cp ${GITHUB_WORKSPACE}/interop/openssl/openssl.spec SPECS/ && \ cd SPECS/ && source ${GITHUB_WORKSPACE}/VERSION.dat && \ - sed -i "s/SOVERSION/$SHLIB_VERSION/" openssl.spec && \ - sed -i "s/^Version: .*\$/Version: $MAJOR.$MINOR.$PATCH/" openssl.spec + sed -i "s/soversion 3/soversion $SHLIB_VERSION/;s/^Version: .*\$/Version: $MAJOR.$MINOR.$PATCH/" openssl.spec && \ + sed -i 's/^Release: .*$/Release: dev/' openssl.spec yum-builddep -y /build/SPECS/openssl.spec # just for sure nothing is missing mkdir -p /build/SOURCES - tar --transform "s/^__w\/openssl\/openssl/openssl-$MAJOR.$MINOR.$PATCH/" -czf /build/SOURCES/openssl-$MAJOR.$MINOR.$PATCH.tar.gz "$GITHUB_WORKSPACE" + tar --transform "s/^__w\/openssl\/openssl/openssl-$MAJOR.$MINOR.$PATCH/" -czf /build/SOURCES/openssl-$MAJOR.$MINOR.$PATCH.tar.gz /__w/openssl/openssl/ rpmbuild -bb /build/SPECS/openssl.spec rpm -i --force /build/RPMS/x86_64/openssl-* cp ${GITHUB_WORKSPACE}/interop/openssl/openssl.cnf /etc/pki/tls/openssl.cnf @@ -68,10 +66,11 @@ jobs: matrix: branch: [ { openssl: 'master', openssh: 'openssl-master', openssl_config: 'no-docs'}, - { openssl: 'openssl-4.0', openssh: 'openssl-4.0', openssl_config: 'no-docs'}, { openssl: 'openssl-3.6', openssh: 'openssl-3.6', openssl_config: 'no-docs'}, { openssl: 'openssl-3.5', openssh: 'openssl-3.5', openssl_config: 'no-docs'}, { openssl: 'openssl-3.4', openssh: 'openssl-3.4', openssl_config: 'no-docs'}, + { openssl: 'openssl-3.3', openssh: 'openssl-3.3', openssl_config: 'no-docs'}, + { openssl: 'openssl-3.2', openssh: 'openssl-3.2', openssl_config: 'no-docs'}, { openssl: 'openssl-3.0', openssh: 'openssl-3.0', openssl_config: ''} ] runs-on: ubuntu-latest @@ -80,24 +79,28 @@ jobs: TEST_SSH_UNSAFE_PERMISSIONS: 1 TEST_SSH_HOSTBASED_AUTH: yes steps: - - name: install dependencies + - uses: actions/checkout@v5 + with: + persist-credentials: false + ref: ${{ matrix.branch.openssl }} + fetch-depth: 1 + - name: config + run: ./config --banner=Configured -fPIC --prefix=/opt/openssl ${{ matrix.openssl_config }} shared -Wl,-rpath,/opt/openssl/lib64 && perl configdata.pm --dump + - name: make + run: | + make -s -j4 + make -s -j4 install_sw + - name: install dependencies of openssh run: | sudo apt-get update sudo apt-get -yq install autoconf zlib1g-dev - - uses: actions/checkout@v6 - with: - persist-credentials: false - repository: openssh/openssh-portable - fetch-depth: 1 - - name: setup ci - run: sh ./.github/setup_ci.sh ${{ matrix.branch.openssh }} ubuntu-latest - - name: autoreconf - run: autoreconf - - name: configure - run: sh ./.github/configure.sh ${{ matrix.branch.openssh }} - - name: make + - name: run openssh run: | + git clone --branch master --depth 1 https://github.com/openssh/openssh-portable.git + cd openssh-portable + sh ./.github/setup_ci.sh ${{ matrix.branch.openssh }} ubuntu-latest + autoreconf + sh ./.github/configure.sh ${{ matrix.branch.openssh }} make clean make -s -j4 - - name: run tests - run: sh ./.github/run_test.sh + sh ./.github/run_test.sh diff --git a/.github/workflows/make-release.yml b/.github/workflows/make-release.yml new file mode 100644 index 0000000000..eb74f5d160 --- /dev/null +++ b/.github/workflows/make-release.yml @@ -0,0 +1,48 @@ +# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. +# +# Licensed under the Apache License 2.0 (the "License"). You may not use +# this file except in compliance with the License. You can obtain a copy +# in the file LICENSE in the source distribution or at +# https://www.openssl.org/source/license.html + +name: "Make release" + +on: + push: + tags: + - "openssl-*" + +permissions: {} + +jobs: + release: + runs-on: "releaser" + steps: + - name: "Checkout" + uses: "actions/checkout@v5" + with: + fetch-depth: 1 + ref: ${{ github.ref_name }} + github-server-url: "https://github.openssl.org/" + repository: "openssl/openssl" + token: ${{ secrets.GHE_TOKEN }} + path: ${{ github.ref_name }} + persist-credentials: false + - name: "Prepare assets" + env: + SIGNING_KEY_UID: ${{ vars.signing_key_uid }} + run: | + cd "$GITHUB_REF_NAME" + ./util/mktar.sh + mkdir -p assets && mv "$GITHUB_REF_NAME.tar.gz" assets/ && cd assets + openssl sha1 -r "$GITHUB_REF_NAME.tar.gz" > "$GITHUB_REF_NAME.tar.gz.sha1" + openssl sha256 -r "$GITHUB_REF_NAME.tar.gz" > "$GITHUB_REF_NAME.tar.gz.sha256" + gpg -u "$SIGNING_KEY_UID" -o "$GITHUB_REF_NAME.tar.gz.asc" -sba "$GITHUB_REF_NAME.tar.gz" + - name: "Create release" + env: + GITHUB_TOKEN: ${{ secrets.GH_TOKEN }} + run: | + VERSION=$(echo "$GITHUB_REF_NAME" | cut -d "-" -f 2-) + PRE_RELEASE=$([[ "$GITHUB_REF_NAME" =~ alpha|beta ]] && echo "-p" || echo "") + NOTES=$(curl -s "https://api.openssl.org/release-metadata/news/?version=$VERSION&capture_title=False") + gh release create "$GITHUB_REF_NAME" $PRE_RELEASE -t "OpenSSL $VERSION" -d --notes "$NOTES" -R "$GITHUB_REPOSITORY" "$GITHUB_REF_NAME/assets/"* diff --git a/.github/workflows/make-test b/.github/workflows/make-test index c38d0de343..239fcfb4ae 100755 --- a/.github/workflows/make-test +++ b/.github/workflows/make-test @@ -19,7 +19,7 @@ export OSSL_CI_ARTIFACTS_PATH="$(cd "$OSSL_CI_ARTIFACTS_PATH"; pwd)" # Run the tests. This might fail, but we need to capture artifacts anyway. set +e -make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16} "$@" +make test HARNESS_JOBS=${HARNESS_JOBS:-4} "$@" RESULT=$? set -e diff --git a/.github/workflows/os-zoo.yml b/.github/workflows/os-zoo.yml index 1d8351b590..ebcf1fc2df 100644 --- a/.github/workflows/os-zoo.yml +++ b/.github/workflows/os-zoo.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -36,7 +36,7 @@ jobs: steps: - name: install packages run: apk --no-cache add build-base perl linux-headers ${{ matrix.cc }} - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: config @@ -52,7 +52,7 @@ jobs: cat /proc/cpuinfo ./util/opensslwrap.sh version -c - name: make test - run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16} + run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} linux: if: github.repository == 'openssl/openssl' @@ -88,7 +88,7 @@ jobs: runs-on: ubuntu-latest container: ${{ matrix.zoo.image }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: install packages @@ -104,7 +104,7 @@ jobs: cat /proc/cpuinfo ./util/opensslwrap.sh version -c - name: make test - run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16} + run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} macos: if: github.repository == 'openssl/openssl' @@ -114,7 +114,7 @@ jobs: os: [macos-14, macos-15, macos-15-intel] runs-on: ${{ matrix.os }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -130,7 +130,7 @@ jobs: sysctl machdep.cpu ./util/opensslwrap.sh version -c - name: make test - run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16} + run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} windows: if: github.repository == 'openssl/openssl' @@ -141,31 +141,18 @@ jobs: - os: windows-2022 vcvars: C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat - os: windows-2025 - vcvars: C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat + vcvars: C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat runs-on: ${{ matrix.platform.os }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule run: git submodule update --init --depth 1 fuzz/corpora - name: install nasm run: | - $installer = "nasm-3.01-installer-x64.exe" - Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/$installer" -OutFile $installer - $expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).$installer - $actual = (Get-FileHash $installer -Algorithm SHA256).Hash - if ($actual -ne $expected) { throw "SHA256 mismatch for $installer (expected $expected, got $actual)" } - Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait + choco install nasm "C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install jom - run: | - mkdir C:\jom - Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe - $expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe' - $actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash - if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" } - "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - name: prepare the build directory run: mkdir _build - name: config @@ -180,7 +167,7 @@ jobs: shell: cmd run: | call "${{ matrix.platform.vcvars }}" - jom /j4 /S + nmake /S - name: download coreinfo run: | mkdir _build\coreinfo @@ -196,16 +183,16 @@ jobs: shell: cmd run: | call "${{ matrix.platform.vcvars }}" - jom test VERBOSE_FAILURE=yes HARNESS_JOBS=4 LHASH_WORKERS=16 + nmake test VERBOSE_FAILURE=yes HARNESS_JOBS=4 linux-arm64: runs-on: ubuntu-24.04-arm steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: config - run: ./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace + run: ./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace - name: config dump run: ./configdata.pm --dump - name: make @@ -213,12 +200,12 @@ jobs: - name: get cpu info run: ./util/opensslwrap.sh version -c - name: make test - run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16} + run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} linux-x86: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: run container @@ -231,7 +218,7 @@ jobs: - name: config run: | podman exec -t $CONTAINER_ID sh -c \ - "./config --strict-warnings linux-x86 enable-demos enable-fips enable-lms enable-md2 enable-rc5 enable-trace" + "./config --strict-warnings linux-x86 enable-demos enable-fips enable-lms enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace" - name: config dump run: | podman exec -t $CONTAINER_ID sh -c \ @@ -260,11 +247,11 @@ jobs: runs-on: linux-ppc64le if: github.repository == 'openssl/openssl' steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: config - run: ./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace + run: ./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace - name: config dump run: ./configdata.pm --dump - name: make @@ -274,17 +261,17 @@ jobs: cat /proc/cpuinfo ./util/opensslwrap.sh version -c - name: make test - run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16} + run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} linux-s390x: runs-on: linux-s390x if: github.repository == 'openssl/openssl' steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: config - run: ./config --strict-warnings enable-fips enable-md2 enable-rc5 enable-trace + run: ./config --strict-warnings enable-fips enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace - name: config dump run: ./configdata.pm --dump - name: make @@ -294,17 +281,17 @@ jobs: cat /proc/cpuinfo ./util/opensslwrap.sh version -c - name: make test - run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16} + run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} linux-riscv64: runs-on: linux-riscv64 if: github.repository == 'openssl/openssl' steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: config - run: ./config enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace + run: ./config enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace - name: config dump run: ./configdata.pm --dump - name: make @@ -314,13 +301,13 @@ jobs: - name: make test env: OPENSSL_riscvcap: RV64GC_ZBA_ZBB_ZBC_ZBS_ZKT_V - run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16} + run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} freebsd-x86_64: runs-on: ubuntu-latest if: github.repository == 'openssl/openssl' steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: config @@ -331,7 +318,7 @@ jobs: shutdown_vm: false run: | sudo pkg install -y gcc perl5 - ./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace + ./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace - name: config dump uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0 with: @@ -354,45 +341,3 @@ jobs: run: | ./util/opensslwrap.sh version -c .github/workflows/make-test - - openbsd-x86_64: - runs-on: ubuntu-latest - if: github.repository == 'openssl/openssl' - steps: - - uses: actions/checkout@v6 - - name: config - uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0 - with: - operating_system: openbsd - architecture: x86-64 - version: '7.7' - shutdown_vm: false - run: | - ./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace - - name: config dump - uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0 - with: - operating_system: openbsd - architecture: x86-64 - version: '7.7' - shutdown_vm: false - run: | - ./configdata.pm --dump - - name: make - uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0 - with: - operating_system: openbsd - architecture: x86-64 - version: '7.7' - shutdown_vm: false - run: | - make -j4 - - name: make test - uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0 - with: - operating_system: openbsd - architecture: x86-64 - version: '7.7' - run: | - ./util/opensslwrap.sh version -c - .github/workflows/make-test diff --git a/.github/workflows/oss-fuzz.yml b/.github/workflows/oss-fuzz.yml index 33af299a84..aeb904b507 100644 --- a/.github/workflows/oss-fuzz.yml +++ b/.github/workflows/oss-fuzz.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -15,7 +15,6 @@ permissions: jobs: Fuzzing: - if: github.event_name != 'schedule' || github.repository == 'openssl/openssl' runs-on: ubuntu-latest steps: - name: Clear unnecessary files diff --git a/.github/workflows/perl-minimal-checker.yml b/.github/workflows/perl-minimal-checker.yml index 2606add5fb..c15b0f944d 100644 --- a/.github/workflows/perl-minimal-checker.yml +++ b/.github/workflows/perl-minimal-checker.yml @@ -1,4 +1,4 @@ -# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -7,25 +7,7 @@ # Jobs run per pull request submission name: Perl-minimal-checker CI -on: - pull_request: - paths-ignore: - - 'doc/**' - - '*.md' - - '*.pod' - - 'README*' - - 'funding.json' - - 'LICENSE.txt' - - 'VERSION.dat' - push: - paths-ignore: - - 'doc/**' - - '*.md' - - '*.pod' - - 'README*' - - 'funding.json' - - 'LICENSE.txt' - - 'VERSION.dat' +on: [pull_request, push] permissions: contents: read @@ -55,7 +37,7 @@ jobs: make -j$(nproc) && make install perl -MTest::More -e 'print "$Test::More::VERSION\n"' popd - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: Build openssl diff --git a/.github/workflows/prov-compat-label.yml b/.github/workflows/prov-compat-label.yml index 94334da8e5..4fa4759c3d 100644 --- a/.github/workflows/prov-compat-label.yml +++ b/.github/workflows/prov-compat-label.yml @@ -1,4 +1,4 @@ -# Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -10,22 +10,13 @@ name: Provider compatibility for PRs -on: - pull_request: - paths-ignore: - - 'doc/**' - - '*.md' - - '*.pod' - - 'README*' - - 'funding.json' - - 'LICENSE.txt' - - 'VERSION.dat' +on: [pull_request] permissions: contents: read env: - opts: enable-rc5 enable-md2 enable-weak-ssl-ciphers enable-zlib + opts: enable-rc5 enable-md2 enable-ssl3 enable-weak-ssl-ciphers enable-zlib jobs: fips-releases: @@ -118,43 +109,36 @@ jobs: name: '', dir: PR, tgz: PR.tar.gz, - extra_config: "enable-lms enable-tls-deprecated-ec", }, { name: openssl-3.0, dir: branch-3.0, tgz: branch-3.0.tar.gz, - extra_config: "", + }, { + name: openssl-3.3, + dir: branch-3.3, + tgz: branch-3.3.tar.gz, }, { name: openssl-3.4, dir: branch-3.4, tgz: branch-3.4.tar.gz, - extra_config: "", }, { name: openssl-3.5, dir: branch-3.5, tgz: branch-3.5.tar.gz, - extra_config: "", }, { name: openssl-3.6, dir: branch-3.6, tgz: branch-3.6.tar.gz, - extra_config: "enable-lms", - }, { - name: openssl-4.0, - dir: branch-4.0, - tgz: branch-4.0.tar.gz, - extra_config: "enable-lms enable-tls-deprecated-ec", }, { name: master, dir: branch-master, tgz: branch-master.tar.gz, - extra_config: "enable-lms enable-tls-deprecated-ec", }, ] runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: path: ${{ matrix.branch.dir }} repository: openssl/openssl @@ -165,7 +149,7 @@ jobs: - name: config branch run: | - ./config --banner=Configured enable-shared enable-fips ${{ env.opts }} ${{ matrix.branch.extra_config }} + ./config --banner=Configured enable-shared enable-fips ${{ env.opts }} working-directory: ${{ matrix.branch.dir }} - name: config dump current run: ./configdata.pm --dump @@ -214,20 +198,20 @@ jobs: # Note that releases are not used as a test environment for # later providers. Problems in these situations ought to be # caught by cross branch testing before the release. - tree_a: [ branch-4.0, branch-3.6, branch-3.5, branch-3.4, branch-3.0, + tree_a: [ branch-3.6, branch-3.5, branch-3.4, branch-3.3, branch-3.0, openssl-3.0.0, openssl-3.0.8, openssl-3.0.9, openssl-3.1.2 ] tree_b: [ PR ] include: - tree_a: PR tree_b: branch-master - - tree_a: PR - tree_b: branch-4.0 - tree_a: PR tree_b: branch-3.6 - tree_a: PR tree_b: branch-3.5 - tree_a: PR tree_b: branch-3.4 + - tree_a: PR + tree_b: branch-3.3 - tree_a: PR tree_b: branch-3.0 steps: diff --git a/.github/workflows/provider-compatibility.yml b/.github/workflows/provider-compatibility.yml index 806a61ad61..290c2751ad 100644 --- a/.github/workflows/provider-compatibility.yml +++ b/.github/workflows/provider-compatibility.yml @@ -1,4 +1,4 @@ -# Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -24,7 +24,7 @@ permissions: contents: read env: - opts: enable-rc5 enable-md2 enable-weak-ssl-ciphers enable-zlib + opts: enable-rc5 enable-md2 enable-ssl3 enable-weak-ssl-ciphers enable-zlib jobs: fips-releases: @@ -119,6 +119,11 @@ jobs: dir: branch-3.0, tgz: branch-3.0.tar.gz, extra_config: "", + }, { + name: openssl-3.3, + dir: branch-3.3, + tgz: branch-3.3.tar.gz, + extra_config: "", }, { name: openssl-3.4, dir: branch-3.4, @@ -134,22 +139,17 @@ jobs: dir: branch-3.6, tgz: branch-3.6.tar.gz, extra_config: "enable-lms", - }, { - name: openssl-4.0, - dir: branch-4.0, - tgz: branch-4.0.tar.gz, - extra_config: "enable-lms enable-tls-deprecated-ec", }, { name: master, dir: branch-master, tgz: branch-master.tar.gz, - extra_config: "enable-lms enable-tls-deprecated-ec", + extra_config: "enable-lms", }, ] runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: path: ${{ matrix.branch.dir }} repository: openssl/openssl @@ -213,10 +213,10 @@ jobs: # Note that releases are not used as a test environment for # later providers. Problems in these situations ought to be # caught by cross branch testing before the release. - tree_a: [ branch-master, branch-4.0, branch-3.6, branch-3.5, branch-3.4, + tree_a: [ branch-master, branch-3.6, branch-3.5, branch-3.4, branch-3.3, branch-3.0, openssl-3.0.0, openssl-3.0.8, openssl-3.0.9, openssl-3.1.2 ] - tree_b: [ branch-master, branch-4.0, branch-3.6, branch-3.5, branch-3.4, + tree_b: [ branch-master, branch-3.6, branch-3.5, branch-3.4, branch-3.3, branch-3.0 ] steps: - name: early exit checks diff --git a/.github/workflows/riscv-more-cross-compiles.yml b/.github/workflows/riscv-more-cross-compiles.yml index 069495e0f6..1747f56a38 100644 --- a/.github/workflows/riscv-more-cross-compiles.yml +++ b/.github/workflows/riscv-more-cross-compiles.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -10,14 +10,6 @@ name: Cross Compile for RISC-V Extensions on: pull_request: types: [opened, reopened, edited, synchronize] - paths-ignore: - - 'doc/**' - - '*.md' - - '*.pod' - - 'README*' - - 'funding.json' - - 'LICENSE.txt' - - 'VERSION.dat' push: schedule: - cron: '35 02 * * *' @@ -60,9 +52,6 @@ jobs: # opensslcaps: optional; if opensslcapsname (see above) is set, then # this string will be used as content for the OpenSSL # capabilities variable. - # capscheck: optional; ERE pattern passed to grep -E to assert that - # "openssl info -cpusettings" output contains expected - # capabilities when using the hwprobe detection path. # ppa: Launchpad PPA repository to download packages from. platform: [ # Scalar Crypto @@ -172,28 +161,6 @@ jobs: qemucpu: "rv64,zba=true,zbb=true,zbc=true,zbs=true,zbkb=true,zbkc=true,zbkx=true,zknd=true,zkne=true,zknh=true,zksed=true,zksh=true,zkr=true,zkt=true,v=true,vlen=128,zvbb=true,zvbc=true,zvkb=true,zvkg=true,zvkned=true,zvknha=true,zvknhb=true,zvksed=true,zvksh=true", opensslcapsname: riscvcap, # OPENSSL_riscvcap opensslcaps: "rv64gc_zba_zbb_zbc_zbs_zbkb_zbkc_zbkx_zknd_zkne_zknh_zksed_zksh_zkr_zkt_v_zvbb_zvbc_zvkb_zvkg_zvkned_zvknha_zvknhb_zvksed_zvksh" - }, { - # RV64GC with all currently OpenSSL-supported extensions, with zvl256 - # crypto/sha/asm/sha512-riscv64-zvkb-zvknhb.pl - # crypto/sm3/asm/sm3-riscv64-zvksh.pl - arch: riscv64-linux-gnu, - libs: libc6-dev-riscv64-cross, - target: linux64-riscv64, - fips: no, - qemucpu: "rv64,zba=true,zbb=true,zbc=true,zbs=true,zbkb=true,zbkc=true,zbkx=true,zknd=true,zkne=true,zknh=true,zksed=true,zksh=true,zkr=true,zkt=true,v=true,vlen=256,zvbb=true,zvbc=true,zvkb=true,zvkg=true,zvkned=true,zvknha=true,zvknhb=true,zvksed=true,zvksh=true", - opensslcapsname: riscvcap, # OPENSSL_riscvcap - opensslcaps: "rv64gc_zba_zbb_zbc_zbs_zbkb_zbkc_zbkx_zknd_zkne_zknh_zksed_zksh_zkr_zkt_v_zvbb_zvbc_zvkb_zvkg_zvkned_zvknha_zvknhb_zvksed_zvksh_zvl256" - }, { - # RV64GC with all currently OpenSSL-supported extensions, with zvl512 - # crypto/sha/asm/sha512-riscv64-zvkb-zvknhb.pl - # crypto/sm3/asm/sm3-riscv64-zvksh.pl - arch: riscv64-linux-gnu, - libs: libc6-dev-riscv64-cross, - target: linux64-riscv64, - fips: no, - qemucpu: "rv64,zba=true,zbb=true,zbc=true,zbs=true,zbkb=true,zbkc=true,zbkx=true,zknd=true,zkne=true,zknh=true,zksed=true,zksh=true,zkr=true,zkt=true,v=true,vlen=512,zvbb=true,zvbc=true,zvkb=true,zvkg=true,zvkned=true,zvknha=true,zvknhb=true,zvksed=true,zvksh=true", - opensslcapsname: riscvcap, # OPENSSL_riscvcap - opensslcaps: "rv64gc_zba_zbb_zbc_zbs_zbkb_zbkc_zbkx_zknd_zkne_zknh_zksed_zksh_zkr_zkt_v_zvbb_zvbc_zvkb_zvkg_zvkned_zvknha_zvknhb_zvksed_zvksh_zvl512" }, { # Inline asm # zbb/zbkb: @@ -213,35 +180,6 @@ jobs: qemucpu: "rv64,zbb=true,zbkb=true,zknh=true,zksh=true", opensslcapsname: riscvcap, # OPENSSL_riscvcap opensslcaps: "rv64gc_inlineasm" # for uploading artifact - }, { - # hwprobe path: RV64GC without V, no OPENSSL_riscvcap override. - # Forces the hwprobe_to_cap() code path (skipped when OPENSSL_riscvcap is set). - # V is absent so AT_HWCAP V bit is clear (VECTOR_CAPABLE=false). - # The rv64 CPU model includes ZBB/ZBC/ZBS/ZBKB by default. - arch: riscv64-linux-gnu, - libs: libc6-dev-riscv64-cross, - target: linux64-riscv64, - fips: no, - qemucpu: "rv64,zbb=true,zbc=true,zbs=true,zbkb=true,v=false", - # No opensslcapsname: hwprobe is used for capability detection. - opensslcaps: "rv64gc_novector_hwprobe", - # ZBB must be detected - capscheck: "_ZBB", - }, { - # hwprobe path: RV64GC + V + ZVKNED (vlen=128), no OPENSSL_riscvcap override. - # Forces the hwprobe_to_cap() code path (skipped when OPENSSL_riscvcap is set). - # V is present so AT_HWCAP V bit is set (VECTOR_CAPABLE=true). - arch: riscv64-linux-gnu, - libs: libc6-dev-riscv64-cross, - target: linux64-riscv64, - fips: no, - qemucpu: "rv64,v=true,vlen=128,zvkned=true", - # No opensslcapsname: hwprobe is used for capability detection. - opensslcaps: "rv64gc_v_zvkned_hwprobe", - # V must be detected. ZVKNED is not reported by QEMU 8.2.2 (ubuntu-latest) - # via hwprobe despite being set in QEMU_CPU; tighten once CI moves to a - # newer QEMU that reports all Zvk* extensions via hwprobe. - capscheck: "_V", } ] runs-on: ubuntu-latest @@ -256,7 +194,7 @@ jobs: sudo apt-get -yq --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install \ gcc-${{ matrix.platform.arch }} \ ${{ matrix.platform.libs }} - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -300,13 +238,6 @@ jobs: if: matrix.platform.tests != 'none' run: QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }} ./util/opensslwrap.sh info -cpusettings - - name: check detected capabilities - if: matrix.platform.capscheck != '' - run: | - QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }} \ - ./util/opensslwrap.sh info -cpusettings | \ - grep -qE "${{ matrix.platform.capscheck }}" - - name: make all tests if: github.event_name == 'push' && matrix.platform.tests == '' run: | diff --git a/.github/workflows/run-checker-ci.yml b/.github/workflows/run-checker-ci.yml index 89186ff03c..93157f50e5 100644 --- a/.github/workflows/run-checker-ci.yml +++ b/.github/workflows/run-checker-ci.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -7,25 +7,7 @@ # Jobs run per pull request submission name: Run-checker CI -on: - pull_request: - paths-ignore: - - 'doc/**' - - '*.md' - - '*.pod' - - 'README*' - - 'funding.json' - - 'LICENSE.txt' - - 'VERSION.dat' - push: - paths-ignore: - - 'doc/**' - - '*.md' - - '*.pod' - - 'README*' - - 'funding.json' - - 'LICENSE.txt' - - 'VERSION.dat' +on: [pull_request, push] permissions: contents: read @@ -59,12 +41,12 @@ jobs: no-tls1_2, no-tls1_3, enable-trace enable-fips, - no-quic, - -DOPENSSL_USE_IPV6=0 + no-ui, + no-quic ] runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule diff --git a/.github/workflows/run-checker-daily.yml b/.github/workflows/run-checker-daily.yml index 3d3688abca..9d347b16bf 100644 --- a/.github/workflows/run-checker-daily.yml +++ b/.github/workflows/run-checker-daily.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -30,6 +30,7 @@ jobs: no-asan, no-asm, no-async, + no-atexit, no-autoalginit, no-autoerrinit, no-autoload-config, @@ -44,6 +45,7 @@ jobs: no-cmac, no-comp, enable-crypto-mdebug, + enable-crypto-mdebug-backtrace, no-ct, enable-demos, no-deprecated, @@ -54,6 +56,8 @@ jobs: no-dtls1_2, no-dtls1_2-method, no-dtls1-method, + no-ecdh, + no-ecdsa, enable-ec_nistp_64_gcc_128, enable-egd, # enable-external-tests, # Requires extra setup @@ -65,13 +69,10 @@ jobs: # enable-fuzz-libfuzzer, # Requires extra setup no-gost, enable-h3demo, + enable-heartbeats, enable-hqinterop, - no-hmac-drbg-kdf, no-hw, no-idea, - no-ikev2kdf, - no-kbkdf, - no-krb5kdf, enable-lms, no-makedepend, enable-md2, @@ -85,7 +86,6 @@ jobs: no-poly1305, no-posix-io, no-psk, - no-pvkkdf, no-rc2, enable-rc5, no-rdrand, @@ -101,14 +101,12 @@ jobs: no-sm2-precomp, no-sm3, no-sm4, - no-snmpkdf, no-sock, - no-srtpkdf, no-sse2, - no-sshkdf, - no-sskdf, no-ssl, no-ssl-trace, + enable-ssl3, + enable-ssl3-method, enable-sslkeylog, no-shared, no-tests, @@ -125,8 +123,6 @@ jobs: no-uplink, no-weak-ssl-ciphers, no-whirlpool, - no-x942kdf, - no-x963kdf, enable-zlib-dynamic, -DOPENSSL_PEDANTIC_ZEROIZATION, -DOPENSSL_PEDANTIC_ZEROIZATION enable-fips, @@ -136,7 +132,7 @@ jobs: ] runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -158,7 +154,7 @@ jobs: if: github.repository == 'openssl/openssl' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -205,7 +201,7 @@ jobs: sudo apt-get update sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install brotli libbrotli1 libbrotli-dev - name: checkout openssl - uses: actions/checkout@v6 + uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -230,7 +226,7 @@ jobs: sudo apt-get update sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install zstd libzstd1 libzstd-dev - name: checkout openssl - uses: actions/checkout@v6 + uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -256,7 +252,7 @@ jobs: sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install brotli libbrotli1 libbrotli-dev sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install zstd libzstd1 libzstd-dev - name: checkout openssl - uses: actions/checkout@v6 + uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -277,7 +273,7 @@ jobs: runs-on: ubuntu-latest steps: - name: checkout openssl - uses: actions/checkout@v6 + uses: actions/checkout@v5 with: persist-credentials: false - name: Adjust ASLR for sanitizer @@ -306,7 +302,7 @@ jobs: sudo apt-get update sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install brotli libbrotli1 libbrotli-dev - name: checkout openssl - uses: actions/checkout@v6 + uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -335,7 +331,7 @@ jobs: sudo apt-get update sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install zstd libzstd1 libzstd-dev - name: checkout openssl - uses: actions/checkout@v6 + uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -362,7 +358,7 @@ jobs: os: [ubuntu-latest, macos-15, macos-15-intel] runs-on: ${{matrix.os}} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -380,7 +376,7 @@ jobs: if: github.repository == 'openssl/openssl' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -400,7 +396,7 @@ jobs: if: github.repository == 'openssl/openssl' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -424,7 +420,7 @@ jobs: bn_debug: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: config diff --git a/.github/workflows/run-checker-merge.yml b/.github/workflows/run-checker-merge.yml index 4342d97bb6..1a3a12c3e3 100644 --- a/.github/workflows/run-checker-merge.yml +++ b/.github/workflows/run-checker-merge.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -31,7 +31,6 @@ jobs: no-srp, no-srtp, no-ts, - no-ui, no-integrity-only-ciphers, enable-weak-ssl-ciphers, enable-zlib, @@ -43,7 +42,7 @@ jobs: run: | sudo cat /proc/sys/vm/mmap_rnd_bits sudo sysctl -w vm.mmap_rnd_bits=28 - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule @@ -65,11 +64,11 @@ jobs: runs-on: ubuntu-latest steps: - name: checkout openssl - uses: actions/checkout@v6 + uses: actions/checkout@v5 with: persist-credentials: false - name: checkout jitter - uses: actions/checkout@v6 + uses: actions/checkout@v5 with: repository: smuellerDD/jitterentropy-library ref: v3.5.0 @@ -93,7 +92,7 @@ jobs: threads_sanitizer_atomic_fallback: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule diff --git a/.github/workflows/run_quic_interop.yml b/.github/workflows/run_quic_interop.yml index f7fca6f373..383658edd4 100644 --- a/.github/workflows/run_quic_interop.yml +++ b/.github/workflows/run_quic_interop.yml @@ -18,7 +18,7 @@ jobs: if: ${{ github.repository == 'openssl/openssl' && !inputs.only_interop }} runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: "log in to quay.io" @@ -36,7 +36,7 @@ jobs: if: ${{ github.repository == 'openssl/openssl' && !inputs.only_interop }} runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: repository: microsoft/msquic ref: main @@ -71,7 +71,7 @@ jobs: tests: retry fail-fast: false steps: &client_steps - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: repository: 'quic-interop/quic-interop-runner' fetch-depth: 0 @@ -98,8 +98,8 @@ jobs: "msquic-openssl": { image: "quay.io/openssl-ci/msquic-openssl" , url: "https://github.com/microsoft/msquic" , role: "both" - }}' ./implementations_quic.json > ./implementations.tmp - mv ./implementations.tmp implementations_quic.json + }}' ./implementations.json > ./implementations.tmp + mv ./implementations.tmp implementations.json - name: Set up docker uses: docker/setup-docker-action@efe9e3891a4f7307e689f2100b33a155b900a608 # v4.5.0 with: @@ -129,7 +129,7 @@ jobs: tests: amplificationlimit fail-fast: false steps: &server_steps - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: repository: 'quic-interop/quic-interop-runner' fetch-depth: 0 @@ -156,8 +156,8 @@ jobs: "msquic-openssl": { image: "quay.io/openssl-ci/msquic-openssl" , url: "https://github.com/microsoft/msquic" , role: "both" - }}' ./implementations_quic.json > ./implementations.tmp - mv ./implementations.tmp implementations_quic.json + }}' ./implementations.json > ./implementations.tmp + mv ./implementations.tmp implementations.json - name: Set up docker uses: docker/setup-docker-action@efe9e3891a4f7307e689f2100b33a155b900a608 # v4.5.0 with: diff --git a/.github/workflows/static-analysis-on-prem.yml b/.github/workflows/static-analysis-on-prem.yml index 46781b66b6..0dc82eb427 100644 --- a/.github/workflows/static-analysis-on-prem.yml +++ b/.github/workflows/static-analysis-on-prem.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -27,11 +27,11 @@ jobs: run: | echo ${{ secrets.COVERITY_AUTH_KEY }} | base64 -d > /auth_key_file.txt chmod 0600 /auth_key_file.txt - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: Config - run: CC=gcc ./config --strict-warnings --banner=Configured --debug enable-lms enable-fips enable-rc5 enable-md2 enable-nextprotoneg enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-shared enable-buildtest-c++ enable-external-tests -DPEDANTIC + run: CC=gcc ./config --strict-warnings --banner=Configured --debug enable-lms enable-fips enable-rc5 enable-md2 enable-ssl3 enable-nextprotoneg enable-ssl3-method enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-shared enable-buildtest-c++ enable-external-tests -DPEDANTIC - name: Config dump run: ./configdata.pm --dump - name: Make diff --git a/.github/workflows/static-analysis.yml b/.github/workflows/static-analysis.yml index de052d4a5c..3ee2769a13 100644 --- a/.github/workflows/static-analysis.yml +++ b/.github/workflows/static-analysis.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -21,7 +21,7 @@ jobs: if: github.repository == 'openssl/openssl' runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: tool download @@ -30,7 +30,7 @@ jobs: --post-data "token=${{ secrets.COVERITY_TOKEN }}&project=openssl%2Fopenssl" \ --progress=dot:giga -O coverity_tool.tgz - name: config - run: CC=gcc ./config --strict-warnings --banner=Configured --debug enable-lms enable-fips enable-rc5 enable-md2 enable-nextprotoneg enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-shared enable-buildtest-c++ enable-external-tests -DPEDANTIC + run: CC=gcc ./config --strict-warnings --banner=Configured --debug enable-lms enable-fips enable-rc5 enable-md2 enable-ssl3 enable-nextprotoneg enable-ssl3-method enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-shared enable-buildtest-c++ enable-external-tests -DPEDANTIC - name: config dump run: ./configdata.pm --dump - name: tool install diff --git a/.github/workflows/style-checks.yml b/.github/workflows/style-checks.yml index f4d251681d..9d216ca898 100644 --- a/.github/workflows/style-checks.yml +++ b/.github/workflows/style-checks.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -7,22 +7,13 @@ name: Coding style validation -on: - pull_request: - paths-ignore: - - 'doc/**' - - '*.md' - - '*.pod' - - 'README*' - - 'funding.json' - - 'LICENSE.txt' - - 'VERSION.dat' +on: [pull_request] jobs: check-style: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 - uses: actions/setup-python@v6 - name: "Get changed files" env: diff --git a/.github/workflows/valgrind-daily.yml b/.github/workflows/valgrind-daily.yml deleted file mode 100644 index ac5f7e052e..0000000000 --- a/.github/workflows/valgrind-daily.yml +++ /dev/null @@ -1,66 +0,0 @@ -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -name: Test valgrind suppression file -# Jobs run daily - -on: - schedule: - - cron: '30 02 * * *' - workflow_dispatch: - -permissions: - contents: read - -jobs: - check-valgrind-suppressions: - runs-on: ubuntu-latest - steps: - - uses: actions/checkout@v6 - with: - persist-credentials: false - - name: Install valgrind - run: | - sudo apt-get -y update - sudo apt-get -y install valgrind - - name: Get parse suppressions script - run: | - wget https://raw.githubusercontent.com/coqui-ai/STT/refs/tags/v1.4.0/parse_valgrind_suppressions.sh - echo "7414fcb9405f8bd1632442a0b66ffb35457994c6b8b49b2aa91530cf9a7ff645 ./parse_valgrind_suppressions.sh" > ./valgrind_suppressions.sha256 - sha256sum -c ./valgrind_suppressions.sha256 - chmod 755 ./parse_valgrind_suppressions.sh - - name: Configure - run: | - ./Configure -DOPENSSL_VALGRIND_TEST - ./configdata.pm --dump - - name: Make - run: | - make -j - - name: Make test - run: | - # The quic radix and multistream test times out under valgrind in ci - make TESTS="-test_quic_radix -test_quic_multistream" OSSL_USE_VALGRIND=yes test - - name: Check for leaks - run: | - set +e - NUM_LOGS=$(find . -name 'valgrind.log.*' | wc -l) - echo "Found $NUM_LOGS valgrind logs" - if [ $NUM_LOGS == 0 ]; then - echo "No logs found!" - exit 1 - fi - for i in $(find . -name 'valgrind.log.*'); do - ./parse_valgrind_suppressions.sh $i >> ./new_suppressions.txt - done - NEW_SUPPRESSION_LINES=$(cat ./new_suppressions.txt | wc -l) - if [ $NEW_SUPPRESSION_LINES != 0 ]; then - echo "New Suppressions Found that need to be addressed!" - cat ./new_suppressions.txt - exit 1 - fi - echo "No new suppressions found" - exit 0 diff --git a/.github/workflows/windows.yml b/.github/workflows/windows.yml index eb8649f741..55eac915cc 100644 --- a/.github/workflows/windows.yml +++ b/.github/workflows/windows.yml @@ -1,4 +1,4 @@ -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -7,26 +7,7 @@ name: Windows GitHub CI -on: - pull_request: - paths-ignore: - - 'doc/**' - - '*.md' - - '*.pod' - - 'README*' - - 'funding.json' - - 'LICENSE.txt' - - 'VERSION.dat' - push: - paths-ignore: - - 'doc/**' - - '*.md' - - '*.pod' - - 'README*' - - 'funding.json' - - 'LICENSE.txt' - - 'VERSION.dat' - +on: [pull_request, push] permissions: contents: read @@ -44,51 +25,22 @@ jobs: - arch: amd64 os: windows-2025 config: enable-lms enable-fips no-thread-pool no-quic - vcvars: C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat + vcvars: C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat - arch: x86 os: windows-2022 config: no-fips enable-lms vcvars: C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars32.bat runs-on: ${{ matrix.platform.os }} steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule run: git submodule update --init --depth 1 fuzz/corpora - name: install nasm - if: github.repository == 'openssl/openssl' run: | - $installer = "nasm-3.01-installer-${{ matrix.platform.arch == 'x86' && 'x86' || 'x64' }}.exe" - Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/$installer" -OutFile $installer - $expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).$installer - $actual = (Get-FileHash $installer -Algorithm SHA256).Hash - if ($actual -ne $expected) { throw "SHA256 mismatch for $installer (expected $expected, got $actual)" } - Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait + choco install nasm ${{ matrix.platform.arch == 'x86' && '--x86' || '' }} "C:\Program Files${{ matrix.platform.arch == 'x86' && ' (x86)' || '' }}\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install nasm (forks) - if: github.repository != 'openssl/openssl' - run: | - $installer = "nasm-3.01-installer-${{ matrix.platform.arch == 'x86' && 'x86' || 'x64' }}.exe" - Invoke-WebRequest -Uri "https://www.nasm.us/pub/nasm/releasebuilds/3.01/win${{ matrix.platform.arch == 'x86' && '32' || '64' }}/$installer" -OutFile $installer - Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait - "C:\Program Files${{ matrix.platform.arch == 'x86' && ' (x86)' || '' }}\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install jom - if: github.repository == 'openssl/openssl' - run: | - mkdir C:\jom - Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe - $expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe' - $actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash - if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" } - "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install jom (forks) - if: github.repository != 'openssl/openssl' - run: | - mkdir C:\jom - Invoke-WebRequest -Uri "https://download.qt.io/official_releases/jom/jom_1_1_7.zip" -OutFile C:\jom\jom.zip - Expand-Archive -Path C:\jom\jom.zip -DestinationPath C:\jom - "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - name: prepare the build directory run: mkdir _build - name: config @@ -103,7 +55,7 @@ jobs: shell: cmd run: | call "${{ matrix.platform.vcvars }}" - jom /j4 /S + nmake /S - name: download coreinfo run: | mkdir _build\coreinfo @@ -115,7 +67,6 @@ jobs: apps/openssl.exe version -v | %{($_ -split '\s+')[1]} apps/openssl.exe version -v | %{($_ -split '\s+')[1] -replace '([0-9]+\.[0-9]+)(\..*)','$1'} echo "OSSL_VERSION=$(apps/openssl.exe version -v | %{($_ -split '\s+')[1] -replace '([0-9]+\.[0-9]+)(\..*)','$1'})" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append - echo "OSSL_MAJOR=$(apps/openssl.exe version -v | %{($_ -split '\s+')[1] -replace '([0-9]+)\.[0-9]+(\..*)','$1'})" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append - name: Set registry keys working-directory: _build run: | @@ -132,16 +83,13 @@ jobs: ./apps/openssl.exe version -c - name: Check platform symbol usage working-directory: _build - shell: cmd - run: | - call "${{ matrix.platform.vcvars }}" - perl ../util/checkplatformsyms.pl ../util/platform_symbols/windows-symbols.txt libcrypto-%OSSL_MAJOR%${{ matrix.platform.arch == 'amd64' && '-x64' || '' }}.dll ./libssl-%OSSL_MAJOR%${{ matrix.platform.arch == 'amd64' && '-x64' || '' }}.dll + run: perl ../util/checkplatformsyms.pl ../util/platform_symbols/windows-symbols.txt libcrypto-3-x64.dll ./libssl-3-x64.dll - name: test working-directory: _build shell: cmd run: | call "${{ matrix.platform.vcvars }}" - jom test VERBOSE_FAILURE=yes TESTS=-test_fuzz* HARNESS_JOBS=4 + nmake test VERBOSE_FAILURE=yes TESTS=-test_fuzz* HARNESS_JOBS=4 - name: install # Run on 64 bit only as 32 bit is slow enough already if: ${{ matrix.platform.arch == 'amd64' }} @@ -150,47 +98,31 @@ jobs: run: | call "${{ matrix.platform.vcvars }}" mkdir _dest - jom /j4 install DESTDIR=_dest + nmake install DESTDIR=_dest plain: runs-on: windows-2022 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule run: git submodule update --init --depth 1 fuzz/corpora - name: prepare the build directory run: mkdir _build - - name: install jom - if: github.repository == 'openssl/openssl' - run: | - mkdir C:\jom - Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe - $expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe' - $actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash - if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" } - "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install jom (forks) - if: github.repository != 'openssl/openssl' - run: | - mkdir C:\jom - Invoke-WebRequest -Uri "https://download.qt.io/official_releases/jom/jom_1_1_7.zip" -OutFile C:\jom\jom.zip - Expand-Archive -Path C:\jom\jom.zip -DestinationPath C:\jom - "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - name: config working-directory: _build shell: cmd run: | call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat" - perl ..\Configure --banner=Configured --strict-warnings enable-demos no-makedepend no-shared no-fips enable-md2 enable-rc5 enable-weak-ssl-ciphers enable-trace enable-crypto-mdebug -DOSSL_WINCTX=openssl VC-WIN64A-masm + perl ..\Configure --banner=Configured --strict-warnings enable-demos no-makedepend no-shared no-fips enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers enable-trace enable-crypto-mdebug -DOSSL_WINCTX=openssl VC-WIN64A-masm perl configdata.pm --dump - name: build working-directory: _build shell: cmd run: | call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat" - jom /j4 /S + nmake /S - name: download coreinfo run: | mkdir _build\coreinfo @@ -209,85 +141,16 @@ jobs: call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat" nmake test VERBOSE_FAILURE=yes HARNESS_JOBS=4 - unit-tests: - runs-on: windows-2022 - steps: - - uses: actions/checkout@v6 - with: - persist-credentials: false - - name: checkout fuzz/corpora submodule - run: git submodule update --init --depth 1 fuzz/corpora - - name: install jom - if: github.repository == 'openssl/openssl' - run: | - mkdir C:\jom - Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe - $expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe' - $actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash - if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" } - "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install jom (forks) - if: github.repository != 'openssl/openssl' - run: | - mkdir C:\jom - Invoke-WebRequest -Uri "https://download.qt.io/official_releases/jom/jom_1_1_7.zip" -OutFile C:\jom\jom.zip - Expand-Archive -Path C:\jom\jom.zip -DestinationPath C:\jom - "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install cmocka and detours via vcpkg - shell: pwsh - run: | - & "$env:VCPKG_INSTALLATION_ROOT\vcpkg.exe" install cmocka:x64-windows-static-md detours:x64-windows-static-md - "VCPKG_INST=$env:VCPKG_INSTALLATION_ROOT\installed\x64-windows-static-md" | Out-File -FilePath $env:GITHUB_ENV -Append - - name: prepare the build directory - run: mkdir _build - - name: config - working-directory: _build - shell: cmd - run: | - call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat" - perl ..\Configure VC-WIN64A --banner=Configured --strict-warnings no-makedepend no-asm enable-unit-tests ^ - --with-cmocka-include=%VCPKG_INST%\include --with-cmocka-lib=%VCPKG_INST%\lib ^ - --with-detours-include=%VCPKG_INST%\include --with-detours-lib=%VCPKG_INST%\lib - perl configdata.pm --dump - - name: build - working-directory: _build - shell: cmd - run: | - call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat" - jom /j4 /S - - name: test - working-directory: _build - shell: cmd - run: | - call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat" - jom test VERBOSE=1 TESTS=test_unit - minimal: runs-on: windows-2022 steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule run: git submodule update --init --depth 1 fuzz/corpora - name: prepare the build directory run: mkdir _build - - name: install jom - if: github.repository == 'openssl/openssl' - run: | - mkdir C:\jom - Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe - $expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe' - $actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash - if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" } - "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install jom (forks) - if: github.repository != 'openssl/openssl' - run: | - mkdir C:\jom - Invoke-WebRequest -Uri "https://download.qt.io/official_releases/jom/jom_1_1_7.zip" -OutFile C:\jom\jom.zip - Expand-Archive -Path C:\jom\jom.zip -DestinationPath C:\jom - "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - name: config working-directory: _build shell: cmd @@ -300,7 +163,7 @@ jobs: shell: cmd run: | call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat" - jom /j4 /S + nmake - name: download coreinfo run: | mkdir _build\coreinfo @@ -317,7 +180,7 @@ jobs: shell: cmd run: | call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat" - jom test VERBOSE_FAILURE=yes TESTS=-test_fuzz* HARNESS_JOBS=4 + nmake test VERBOSE_FAILURE=yes TESTS=-test_fuzz* HARNESS_JOBS=4 cygwin: # Run a job for each of the specified target architectures: @@ -339,7 +202,7 @@ jobs: MAKE_PARAMS: -j 4 steps: # Checkout before cygwin can mess with PATH... - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - uses: cygwin/cygwin-install-action@f2009323764960f80959895c7bc3bb30210afe4d #v6 @@ -353,89 +216,7 @@ jobs: # - name: Clone repo # run: bash -c "pwd && git clone --branch ${{ github.ref_name }} --depth 1 https://github.com/${{ github.repository }}.git" - name: Full build - shell: bash - run: | - gcc --version - ./config ${{ matrix.platform.config }} - make $MAKE_PARAMS + run: bash -c "gcc --version && ./config ${{ matrix.platform.config }} && make $MAKE_PARAMS" # Disable testing for now. TBD: Need local cygwin installation to debug . # - name: Run openssl tests # run: bash -c "cd openssl && make V=1 test" - - mingw64: - strategy: - matrix: - platform: - - arch: mingw64 - target: x86_64 - # Avoid MINGW bug in headers. Remove when CI is upgraded. - config: enable-demos -Wno-array-bounds - - arch: mingw - target: i686 - config: -Wno-array-bounds -Wno-stringop-overflow - runs-on: ubuntu-latest - env: - CC: ${{ matrix.platform.target }}-w64-mingw32-gcc - CXX: ${{ matrix.platform.target }}-w64-mingw32-g++ - AR: ${{ matrix.platform.target }}-w64-mingw32-ar - RANLIB: ${{ matrix.platform.target }}-w64-mingw32-ranlib - RC: ${{ matrix.platform.target }}-w64-mingw32-windres - steps: - - uses: actions/checkout@v6 - with: - persist-credentials: false - - name: install MINGW64 - run: sudo apt-get install -y mingw-w64 - - name: config - run: ./config ${{ matrix.platform.arch }} --strict-warnings --banner=Configured ${{ matrix.platform.config }} - - name: make - run: make -j4 -s - - msys2-mingw64: - strategy: - matrix: - platform: - - arch: UCRT64 - cc: gcc - pkgs: mingw-w64-ucrt-x86_64-gcc - config: mingw64 enable-demos - - arch: CLANG64 - cc: clang - pkgs: mingw-w64-clang-x86_64-clang - config: mingw64 - runs-on: windows-latest - env: - CC: ${{ matrix.platform.cc }} - MSYSTEM: ${{ matrix.platform.arch }} - CHERE_INVOKING: 'yes' - steps: - - uses: actions/checkout@v6 - with: - persist-credentials: false - - name: install MSYS2 - run: | - $url = 'https://github.com/msys2/msys2-installer/releases/download/nightly-x86_64/msys2-base-x86_64-latest.sfx.exe' - (New-Object System.Net.WebClient).DownloadFile($url, 'msys2.exe') - # Remove preinstalled MSYS2 - if (Test-Path C:\msys64) { Remove-Item -Recurse -Force C:\msys64 } - .\msys2.exe -y -oC:\ - Remove-Item msys2.exe - - - name: update MSYS2 - run: | - C:\msys64\usr\bin\bash.exe -lc ' ' - # Update core and then normal update - C:\msys64\usr\bin\bash.exe -lc 'pacman --noconfirm -Syuu' - C:\msys64\usr\bin\bash.exe -lc 'pacman --noconfirm -Syuu' - - - name: install dependencies - run: C:\msys64\usr\bin\bash.exe -lc 'pacman --noconfirm -S --needed perl git make ${{ matrix.platform.pkgs }}' - - - name: config - run: C:\msys64\usr\bin\bash.exe -lc './config --strict-warnings --banner=Configured ${{ matrix.platform.config }}' - - - name: make - run: C:\msys64\usr\bin\bash.exe -lc 'make -j4 -s' -# Tests are broken for now -# - name: test -# run: C:\msys64\usr\bin\bash.exe -lc 'make test' diff --git a/.github/workflows/windows_comp.yml b/.github/workflows/windows_comp.yml index 349ed24b89..87ab5ba321 100644 --- a/.github/workflows/windows_comp.yml +++ b/.github/workflows/windows_comp.yml @@ -1,4 +1,4 @@ -# Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -23,44 +23,15 @@ jobs: zstd: runs-on: windows-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule run: git submodule update --init --depth 1 fuzz/corpora - name: install nasm - if: github.repository == 'openssl/openssl' run: | - $installer = "nasm-3.01-installer-x64.exe" - Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/$installer" -OutFile $installer - $expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).$installer - $actual = (Get-FileHash $installer -Algorithm SHA256).Hash - if ($actual -ne $expected) { throw "SHA256 mismatch for $installer (expected $expected, got $actual)" } - Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait + choco install nasm "C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install nasm (forks) - if: github.repository != 'openssl/openssl' - run: | - $installer = "nasm-3.01-installer-x64.exe" - Invoke-WebRequest -Uri "https://www.nasm.us/pub/nasm/releasebuilds/3.01/win64/$installer" -OutFile $installer - Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait - "C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install jom - if: github.repository == 'openssl/openssl' - run: | - mkdir C:\jom - Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe - $expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe' - $actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash - if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" } - "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install jom (forks) - if: github.repository != 'openssl/openssl' - run: | - mkdir C:\jom - Invoke-WebRequest -Uri "https://download.qt.io/official_releases/jom/jom_1_1_7.zip" -OutFile C:\jom\jom.zip - Expand-Archive -Path C:\jom\jom.zip -DestinationPath C:\jom - "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - name: prepare the build directory run: mkdir _build - name: Get zstd @@ -71,15 +42,15 @@ jobs: working-directory: _build shell: cmd run: | - call "C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat" + call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat" perl ..\Configure --strict-warnings enable-comp enable-zstd --with-zstd-include=C:\vcpkg\packages\zstd_x64-windows\include --with-zstd-lib=C:\vcpkg\packages\zstd_x64-windows\lib\zstd.lib no-makedepend -DOSSL_WINCTX=openssl VC-WIN64A perl configdata.pm --dump - name: build working-directory: _build shell: cmd run: | - call "C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat" - jom /j4 /S + call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat" + nmake - name: Gather openssl version info working-directory: _build run: | @@ -105,54 +76,28 @@ jobs: 7z.exe x coreinfo/Coreinfo.zip ./Coreinfo64.exe -accepteula -f ./apps/openssl.exe version -c + - name: Check platform symbol usage + run: | + perl ./util/checkplatformsyms.pl ./util/platform_symbols/windows-symbols.txt libcrypto-3-x64.dll ./libssl-3-x64.dll - name: test working-directory: _build shell: cmd run: | - call "C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat" - jom test VERBOSE_FAILURE=yes TESTS="-test_fuzz* -test_fipsload" HARNESS_JOBS=4 + call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat" + nmake test VERBOSE_FAILURE=yes TESTS="-test_fuzz* -test_fipsload" HARNESS_JOBS=4 brotli: runs-on: windows-latest steps: - - uses: actions/checkout@v6 + - uses: actions/checkout@v5 with: persist-credentials: false - name: checkout fuzz/corpora submodule run: git submodule update --init --depth 1 fuzz/corpora - name: install nasm - if: github.repository == 'openssl/openssl' run: | - $installer = "nasm-3.01-installer-x64.exe" - Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/$installer" -OutFile $installer - $expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).$installer - $actual = (Get-FileHash $installer -Algorithm SHA256).Hash - if ($actual -ne $expected) { throw "SHA256 mismatch for $installer (expected $expected, got $actual)" } - Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait + choco install nasm "C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install nasm (forks) - if: github.repository != 'openssl/openssl' - run: | - $installer = "nasm-3.01-installer-x64.exe" - Invoke-WebRequest -Uri "https://www.nasm.us/pub/nasm/releasebuilds/3.01/win64/$installer" -OutFile $installer - Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait - "C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install jom - if: github.repository == 'openssl/openssl' - run: | - mkdir C:\jom - Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe - $expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe' - $actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash - if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" } - "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - - name: install jom (forks) - if: github.repository != 'openssl/openssl' - run: | - mkdir C:\jom - Invoke-WebRequest -Uri "https://download.qt.io/official_releases/jom/jom_1_1_7.zip" -OutFile C:\jom\jom.zip - Expand-Archive -Path C:\jom\jom.zip -DestinationPath C:\jom - "C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append - name: prepare the build directory run: mkdir _build - name: Get brotli @@ -163,15 +108,15 @@ jobs: working-directory: _build shell: cmd run: | - call "C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat" + call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat" perl ..\Configure --strict-warnings enable-comp enable-brotli --with-brotli-include=C:\vcpkg\packages\brotli_x64-windows\include --with-brotli-lib=C:\vcpkg\packages\brotli_x64-windows\lib no-makedepend -DOSSL_WINCTX=openssl VC-WIN64A perl configdata.pm --dump - name: build working-directory: _build shell: cmd run: | - call "C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat" - jom /j4 /S + call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat" + nmake - name: Gather openssl version info working-directory: _build run: | @@ -201,5 +146,5 @@ jobs: working-directory: _build shell: cmd run: | - call "C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat" - jom test VERBOSE_FAILURE=yes TESTS="-test_fuzz* -test_fipsload" HARNESS_JOBS=4 + call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat" + nmake test VERBOSE_FAILURE=yes TESTS="-test_fuzz* -test_fipsload" HARNESS_JOBS=4 diff --git a/.gitignore b/.gitignore index 2c221ee7bd..129335aa44 100644 --- a/.gitignore +++ b/.gitignore @@ -59,8 +59,6 @@ /include/openssl/x509_vfy.h /include/openssl/core_names.h -/apps/include/configuration.h - # Auto generated parameter name files /crypto/params_idx.c @@ -88,7 +86,6 @@ providers/common/include/prov/der_wrap.h providers/common/include/prov/der_sm2.h providers/common/include/prov/der_ml_dsa.h providers/common/include/prov/der_hkdf.h -providers/fips/fipsparams.inc providers/implementations/asymciphers/rsa_enc.inc providers/implementations/asymciphers/sm2_enc.inc providers/implementations/exchange/dh_exch.inc @@ -104,7 +101,6 @@ providers/implementations/encode_decode/encode_key2ms.inc providers/implementations/kdfs/argon2.inc providers/implementations/kdfs/hkdf.inc providers/implementations/kdfs/hmacdrbg_kdf.inc -providers/implementations/kdfs/ikev2kdf.inc providers/implementations/kdfs/kbkdf.inc providers/implementations/kdfs/krb5kdf.inc providers/implementations/kdfs/pbkdf1.inc @@ -112,13 +108,10 @@ providers/implementations/kdfs/pbkdf2.inc providers/implementations/kdfs/pkcs12kdf.inc providers/implementations/kdfs/pvkkdf.inc providers/implementations/kdfs/scrypt.inc -providers/implementations/kdfs/snmpkdf.inc -providers/implementations/kdfs/srtpkdf.inc providers/implementations/kdfs/sshkdf.inc providers/implementations/kdfs/sskdf.inc providers/implementations/kdfs/tls1_prf.inc providers/implementations/kdfs/x942kdf.inc -providers/implementations/kdfs/x963kdf.inc providers/implementations/kem/ec_kem.inc providers/implementations/kem/ecx_kem.inc providers/implementations/kem/ml_kem_kem.inc @@ -139,7 +132,6 @@ providers/implementations/keymgmt/mlx_kmgmt.inc providers/implementations/keymgmt/slh_dsa_kmgmt.inc providers/implementations/keymgmt/template_kmgmt.inc providers/implementations/signature/eddsa_sig.inc -providers/implementations/signature/mac_legacy_sig.inc providers/implementations/signature/ml_dsa_sig.inc providers/implementations/signature/rsa_sig.inc providers/implementations/signature/slh_dsa_sig.inc @@ -167,10 +159,7 @@ providers/implementations/ciphers/cipher_sm4_xts.inc providers/implementations/digests/blake2_prov.inc providers/implementations/digests/digestcommon.inc providers/implementations/digests/mdc2_prov.inc -providers/implementations/digests/sha2_prov.inc providers/implementations/digests/sha3_prov.inc -providers/implementations/digests/ml_dsa_mu_prov.inc -providers/implementations/digests/cshake_prov.inc providers/implementations/include/prov/blake2_params.inc providers/implementations/macs/cmac_prov.inc providers/implementations/macs/gmac_prov.inc @@ -200,7 +189,6 @@ providers/implementations/rands/test_rng.inc /test/gost2814789t /test/ssltest_old /test/*test -/test/*memfail /test/fips_aesavs /test/fips_desmovs /test/fips_dhvs @@ -311,6 +299,8 @@ providers/implementations/rands/test_rng.inc # Misc auto generated files /doc/man7/openssl_user_macros.pod +/tools/c_rehash +/tools/c_rehash.pl /util/shlib_wrap.sh /util/wrap.pl /tags @@ -431,11 +421,3 @@ doc-nits # LSP (Language Server Protocol) support .cache/ compile_commands.json - -# coverage files -*.gcda -*.gcno -lcov.info -run_tests -depend - diff --git a/.pre-commit-config.yaml b/.pre-commit-config.yaml index aab58f03a3..2565246b2a 100644 --- a/.pre-commit-config.yaml +++ b/.pre-commit-config.yaml @@ -11,9 +11,3 @@ repos: types_or: [] files: '\.c\.in$|\.h\.in$|\.c$|\.h$' args: ["--style=file"] - exclude: | - (?x)^( - crypto/objects/obj_dat.h| - crypto/objects/obj_xref.h| - include/openssl/obj_mac.h - )$ diff --git a/CHANGES.md b/CHANGES.md index 8d507e4f32..8a04fadc9c 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -27,1777 +27,70 @@ OpenSSL Releases - [OpenSSL 1.0.0](#openssl-100) - [OpenSSL 0.9.x](#openssl-09x) ------------ - -### Changes between 4.0 and 4.1 [xx XXX xxxx] - - * Fixed TLS 1.3 external PSK connections being wrongly rejected when - the client sets a non-empty session ID context. - - *Viktor Dukhovni* - - * Fixed a TLS 1.3 server with no session ID context to accept external PSK - connections and to stop issuing unusable session tickets. - - *Viktor Dukhovni* - - * Added AVX512 optimized SHAKE x4 operations for ML-DSA on `x86_64`. - - *Marcel Cornu and Tomasz Kantecki* - - * EC key point format simplification. - - The point conversion form (compressed, uncompressed, or hybrid) - is now a single value on the `EC_GROUP` and round-trips - unchanged through import and export of `EC_KEY` objects. - - Freshly generated keys have their public point encoded in - uncompressed form. A `point-format` supplied at key generation - time via `OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT` is - validated (an invalid value is rejected) but otherwise ignored - on the generated key. EC parameter generation continues to - honour the requested form on the group's generator; imported - keys keep their form. - - The `ec_point_formats` extension no longer affects TLS 1.2 - X.509 certificate selection or acceptance. OpenSSL now - accepts an EC certificate in any point form it can decode, - and sends any EC certificate it has regardless of point form. - TLS 1.3 disregards the extension entirely. - - The RFC 4492/8422 section 5.1.2 requirement that the peer's - point-format list contain "uncompressed" is now enforced on - both sides (previously client-only), and only when an ECC - TLS 1.2 ciphersuite is negotiated -- a missing "uncompressed" - is ignored under TLS 1.3 or with a non-ECC cipher. - - *Viktor Dukhovni* - - * Added unit tests setup activated via `enable-unit-tests` option. This works - only on platforms with ld `--wrap` support (Linux, BSD). - - *Jakub Zelenka* - - * Deprecated the `enable-unit-test` configure option and the - `SSL_test_functions()` function. Both will be removed in OpenSSL 5.0. - - *Jakub Zelenka* - - * Added -testmode option for `s_time` app. - - *Jakub Zelenka* - - * Added support for Ed25519 and Ed448 certificates in DTLS 1.2. Previously, - these certificate types were only supported in TLS 1.2 and TLS 1.3. - - *Adriano Sela Aviles* - - * SubjectPublicKeyInfo blobs whose AlgorithmIdentifier uses id-RSAES-OAEP - (`NID_rsaesOaep`, 1.2.840.113549.1.1.7) with a plain RSAPublicKey body - are now decoded as RSA keys. This is required for interoperability - with TPM 1.2 Endorsement Key certificates per TCG Credential Profiles - V1.2 section 3.2.7. The OAEP AlgorithmIdentifier parameters are not - interpreted. - - *Craig Lorentzen* - - * Do not issue TLS1.3 session tickets if the server has explicitly disabled - them via `SSL_OP_NO_TICKET` and also turned off the session cache with - `SSL_SESS_CACHE_OFF`. Both conditions together indicate a clear intent to - suppress resumption, so sending NewSessionTicket messages would be wasteful - and misleading. TLS1.3 client that does not send the `psk_key_exchange_modes` - extension, or that sends it together with [RFC 9149] parameters such as - `new_session_count = 0` or `resumption_count = 0`, is effectively signaling - no interest in session tickets and session resumption. - - *Daniel Kubec* - - * Added test framework for testing function memory allocation failures. - - *Jakub Zelenka* - - * Windows-on-Itanium (VC-WIN64I) support was dropped - the Itanium - architecture has been discontinued and the platform is no longer - supported or tested. - - *Bob Beck* - - * Windows CE support was dropped - Windows CE has been unsupported since - 2018 and does not have a modern C99 toolchain. - - *Bob Beck* - - * Improved DTLS handshake robustness under UDP reordering by buffering and - replaying early ChangeCipherSpec (CCS) records at the expected state. - - *Tong Li* - - * Header files in OpenSSL are being changed to reflect modern development - practices - Include files should all be guarded for inclusion by a define - and must be self contained, meaning they include all dependencies they need - to compile on their own. Headers have been changed to include guards and - to include the dependencies they require. Doing this will help the - future use of more modern tooling. - - *Bob Beck* - - * `ASN1_STRING_set()` and `ASN1_STRING_length()` have been - deprecated. The replacement functions `ASN1_STRING_set_data()` or - `ASN1_STRING_set_string()`, and `ASN1_STRING_length_ex()` should be - used in their place. This prepares the ASN1_STRING type to support - modern size_t length values in the future. - - *Bob Beck* - - * `EVP_CIPHER_CTX_get_num()` and `EVP_CIPHER_CTX_set_num()' have been deprecated. - - Refer to ossl-migration-guide(7) for more info. - - *Shane Lontis* - - * The functions `ASN1_BIT_STRING_name_print()`, `ASN1_BIT_STRING_num_asc(), - and `ASN1_BIT_STRING_set_asc()`, have been deprecated. Refer to the manual - pages for more information. - - *Bob Beck* - - * The API functions `CRYPTO_atomic_load_ptr`, `CRYPTO_atomic_store_ptr`, and - `CRYPTO_atomic_cmp_exch_ptr` have been added to libcrypto. - - *Neil Horman* - - * The `openssl pkeyutl` command now uses memory-mapped I/O when reading - raw input from a file for oneshot sign/verify operations (such as Ed25519, - Ed448, and ML-DSA) on platforms that support it (Unix-like). The - `openssl dgst` command uses the same approach for one-shot sign/verify - when the input is from a file, removing the previous 16 MB limit for - file-based input. This improves performance and supports large files - without doubling memory use. Other platforms and stdin input continue to - use the existing buffer-based path. - - *John Claus* - -* 'X509_check_host()', 'X509_check_email()', 'X509_check_ip()', and 'X509_check_ip_asc()' - have been deprecated. Applications should migrate to setting a reference identifier - to check using 'X509_VERIFY_PARAM_set1_host()', 'X509_VERIFY_PARAM_set1_email()', or - X509_VERIFY_PARAM_set1_ip_asc()', and using 'X509_verify_cert()'. - - *Bob Beck* - - * The API function `ASN1_STRING_new_not_owned` has been added to the - libcrypto. It provides the ability to construct an ASN1_STRING with data - for which ownership is not taken by the created ASN1_STRING object. - - *Bob Beck* - - * Fixed X.509 verification of certificate chains that use DSA signatures - with SHA-384 or SHA-512 by registering `dsa_with_SHA384` and - `dsa_with_SHA512` in the signature-algorithm cross-reference table. - - *John Claus* - - * Added AVX2 optimized ML-DSA NTT operations on `x86_64`. - - *Marcel Cornu and Tomasz Kantecki* - - * Changed the output of the -disabled option for the list command. - Displaying disabled features, protocols, and algorithms, in relevant sections. - Disabled features are now generated at configuration time. - - *Paul Louvel* - - * Added `CTLOG_STORE_add0_log()` to add individual CT logs to a `CTLOG_STORE`. - - *Tim Perry* - - * Dropped `no-ecdsa` and `no-ecdh` options from `Configure` as these options - did not really disable the implementations. Use `no-ec` to disable the - elliptic curve support. - - *Tomáš Mráz* - - * Added `EVP_EC_affine2oct()` that converts the affine coordinates of an - EC point to an octet string conforming to Sec. 2.3.4 of the SECG SEC 1 - ("Elliptic Curve Cryptography") standard. - - *Igor Ustinov* - - * Made more QUIC transport parameters configurable via the - `SSL_get_value_uint`/`SSL_set_value_uint` functions. Now also configurable: - `max_udp_payload_size`, `initial_max_data`, - `initial_max_stream_data_bidi_local`, `initial_max_stream_data_uni`, - `ack_delay_exponent`, `max_ack_delay`. - - *Nikolas Gauder* - - * Add new verification error `X509_V_ERR_DUPLICATE_EXTENSION` with descriptive - message for certificates containing duplicate X.509 extensions, which are - explicitly prohibited by [RFC 5280]. - - *Daniel Kubec* - - * Added `OSSL_CMP_OPT_NONMATCHED_ERROR_NONCES` option for `OSSL_CMP_CTX` and - a corresponding `-nonmatched_error_nonces` option for the `openssl cmp` command. - - This work was sponsored by Siemens AG. - - *David von Oheimb* - - * Added support for RFC 8701 GREASE (Generate Random Extensions And Sustain - Extensibility). When `SSL_OP_GREASE` is set, the TLS client injects - reserved GREASE values into cipher suites, supported versions, supported - groups, signature algorithms, key share, and extensions in the ClientHello - to prevent ecosystem ossification. The `openssl s_client` command gains a - `-grease` option to enable this. - - *William McCormack* - - * The undocumented public functions `UTF8_putc()` and `UTF8_getc()` - were deprecated, and their functionality moved internal to the - library. No public replacement is planned. - - *Bob Beck* - - * Added IKEV2 KDF (EVP_KDF-IKEV2KDF) implementation. - - *Helen Zhang* - - * Deprecated `ASN1_BIT_STRING_set()` in favour of `ASN1_BIT_STRING_set1()`. - - *Norbert Pócs* - - * Added optimized ML-DSA NTT operations on `s390x` - (or other architectures with 128 bit vector registers). - - *Timo Keller* - - * Added `EVP_KDF_CTX_get0_kdf()` and `EVP_KDF_CTX_get1_kdf()` functions - as a replacement for the now deprecated `EVP_KDF_CTX_kdf()`. - - *Leon Timmermans* - - * Add `FIPS_mode()` as a convenience define to - `EVP_default_properties_is_fips_enabled(NULL)`, which is - shorthand to check whether the `fips=yes` property is currently enabled - in the default library context. - - *Dimitri John Ledkov* - OpenSSL 4.0 ----------- -### Changes between 4.0.1 and 4.0.2 [xx XXX XXXX] - - * Add client-side validation for TLS 1.3 session ticket lifetimes. - - In accordance with [RFC 8446 Section 4.6.1](https://datatracker.ietf.org/doc/html/rfc8446#section-4.6.1), - TLS 1.3 clients must not cache session tickets - for longer than 7 days (604800 seconds). - When processing a new session ticket message with a - `ticket_lifetime_hint` value greater than 7 days, - the client now caps the lifetime to the - maximum permitted value of 7 days (604800 seconds). - - *Abel Thomas* - -### Changes between 4.0.0 and 4.0.1 [9 Jun 2026] - - * Fixed heap use-after-free in `PKCS7_verify()`. - - Severity: High - - Issue summary: A specially crafted PKCS#7 or S/MIME signed message could - trigger a use-after-free during PKCS#7 signature verification. - - Impact summary: A use-after-free may result in process crashes, heap - corruption, or, potentially, remote code execution. - - Reported by: Thai Duong (Calif.io in collaboration with Claude - and Anthropic Research). - - ([CVE-2026-45447]) - - *Igor Ustinov* - - * Fixed CMS `AuthEnvelopedData` processing may accept forged messages. - - Severity: Moderate - - Issue Summary: Cryptographic Message Services (CMS) processing fails - to perform sufficient input validation on the cipher and tag length fields - of `AuthEnvelopedData` containers, leading to various potential compromises. - - Impact Summary: Attackers making use of these vulnerabilities may achieve - key-equivalent functionality for a given CMS recipient and/or bypass - integrity validation for a given message. - - Reported by: Asim Viladi Oglu Manizada, Alex Gaynor (Anthropic), - Ying Dong, and Haiyang Huang. - - ([CVE-2026-34182]) - - *Neil Horman* - - * Fixed unbounded memory growth in the QUIC `PATH_CHALLENGE` handler. - - Severity: Moderate - - Issue summary: Remote peer may exhaust heap memory of the QUIC server - or client by flooding it with packets containing `PATH_CHALLENGE` frames. - - Impact summary: A malicious remote peer can cause an unbounded memory - allocation which can lead to an abnormal termination of the application - acting as a QUIC client or server and a Denial of Service. - - Reported by: Abhinav Agarwal. - - ([CVE-2026-34183]) - - *Abhinav Agarwal and Alexandr Nedvedicky* - - * Fixed double-free when checking OCSP stapled response. - - Severity: Moderate - - Issue summary: A malicious server can exploit TLS OCSP stapling by delivering - a crafted response through the `status_request` extension, triggering - a double-free in the client's certificate verification path. - - Impact summary: Successful exploitation allows an attacker to corrupt heap - memory via a double-free, potentially leading to a Denial of Service - or possibly an attacker controlled code execution or other undefined - behavior. - - Reported by: Wang Kenaz (University of Illinois), - Guido Vranken (Aisle Research), and Aaron Grattafiori (Nvidia). - - ([CVE-2026-35188]) - - *Daniel Kubec* - - * Fixed NULL pointer dereference in QUIC server initial packet handling. - - Severity: Moderate - - Issue summary: Receiving a QUIC initial packet with an invalid token - may trigger a NULL pointer dereference in the OpenSSL QUIC server - with address validation disabled. - - Impact summary: NULL pointer dereference typically causes abnormal - termination of the affected QUIC server process and a Denial of Service. - - Reported by: Sunwoo Lee (KENTECH), Hyuk Lim (KENTECH), - and Seunghyun Yoon (KENTECH). - - ([CVE-2026-42764]) - - *Sunwoo Lee (KENTECH), Hyuk Lim (KENTECH), and Seunghyun Yoon (KENTECH)* - - * Fixed AES-OCB IV ignored on `EVP_Cipher()` path. - - Severity: Moderate - - Issue summary: When an application drives an AES-OCB context through - the public `EVP_Cipher()` one-shot interface, the application-supplied - initialisation vector (IV) is silently discarded. - - Impact summary: Every message encrypted under the same key uses the same - effective nonce regardless of the IV supplied by the caller, resulting - in `(key, nonce)` reuse and loss of confidentiality. If the same code path - is used to compute the authentication tag, the tag depends only - on the `(key, IV)` pair and not on the plaintext or ciphertext, allowing - universal forgery of arbitrary ciphertext from a single captured message. - - Reported by: Alex Gaynor (Anthropic). - - ([CVE-2026-45445]) - - *Viktor Dukhovni* - - * Fixed possible heap buffer overflow in ASN.1 multibyte string conversion. - - Severity: Low - - Issue summary: A signed integer overflow when sizing the destination - buffer for Unicode output in `ASN1_mbstring_ncopy()` can lead to a heap - buffer overflow. - - Impact summary: A heap buffer overflow may lead to a crash or possibly - attacker controlled code execution or other undefined behaviour. - - Reported by: Zehua Qiao and Jinwen He. - - ([CVE-2026-7383]) - - *Viktor Dukhovni* - - * Fixed out-of-bounds read in CMS password-based decryption. - - Severity: Low - - Issue summary: When CMS password-based decryption ([RFC 3211]/PWRI key - unwrap) processes attacker-supplied CMS data, an attacker-chosen stream-mode - KEK cipher can trigger a heap out-of-bounds read in `kek_unwrap_key()`. - - Impact summary: A heap buffer over-read may trigger a crash, which leads - to Denial of Service for an application if the input buffer ends at a memory - page boundary and the following page is unmapped. There is no information - disclosure, as the over-read bytes are not revealed to the attacker. - - Reported by: Bhabani Sankar Das and Haruki Oyama (Waseda University). - - ([CVE-2026-9076]) - - *Nikola Pajkovský* - - * Fixed heap buffer over-read in ASN.1 content parsing. - - Severity: Low - - Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive - element whose content exceeds 2 gigabytes in length may cause a heap buffer - over-read on 64-bit Unix and Unix-like platforms. - - Impact summary: The heap buffer over-read may crash the application (Denial - of Service) or to load into the decoded ASN.1 object contents of memory - beyond the end of the input buffer. More typically, such ASN.1 elements - would instead be truncated. - - Reported by: Frank Buss. - - ([CVE-2026-34180]) - - *Viktor Dukhovni* - - * Fixed PKCS#12 files with PBMAC1 are accepted with short HMAC keys. - - Severity: Low - - Issue Summary: The PKCS#12 file processing fails to perform sufficient input - validation for files that use Password-Based Message Authentication Code 1 - (PBMAC1) integrity mechanism allowing a certificate and private key forgery. - - Impact Summary: An attacker impersonating a user can cause a service reading - PKCS#12 files to accept forged certificates and private keys with a 1 in 256 - probability. - - Reported by: Pavol ŽáÄik (Red Hat) and Alex Gaynor (Anthropic). - - ([CVE-2026-34181]) - - *Alicja Kario (Red Hat)* - - * Fixed NULL dereference in certificate verification with OCSP Checking. - - Severity: Low - - Issue summary: When a partial-chain certificate verification is enabled - together with OCSP response checking for the whole chain, a NULL dereference - will happen if the verified chain does not have a self-signed trusted anchor, - crashing the process. - - Impact summary: A NULL pointer dereference can trigger a crash which leads - to a Denial of Service for an application. - - Reported by: Joshua Rogers (Aisle Research). - - ([CVE-2026-42765]) - - *Joshua Rogers (Aisle Research) and Daniel Kubec* - - * Fixed possible NULL dereference in password-dased CMS decryption. - - Severity: Low - - Issue summary: A specially crafted password-encrypted CMS message - could trigger a NULL pointer dereference during CMS decryption. - - Impact summary: This NULL pointer dereference could lead to an application - crash and a Denial of Service. - - Reported by: Mayank Jangid, Kushal Khemka, Hari Priandana, - Bhabani Sankar Das, and Qifan Zhang (Palo Alto Networks). - - ([CVE-2026-42766]) - - *Igor Ustinov* - - * Fixed NULL pointer dereference in CRMF `EncryptedValue` decryption. - - Severity: Low - - Issue summary: An attacker-controlled CMP (Certificate Management Protocol) - server could trigger a NULL pointer dereference in a CMP client application. - - Impact summary: A NULL pointer dereference could cause a crash - of the application and a Denial of Service. - - Reported by: Zhanpeng Liu (Tencent Xuanwu Lab), - Guannan Wang (Tencent Xuanwu Lab), and Guancheng Li (Tencent Xuanwu Lab). - - ([CVE-2026-42767]) - - *Igor Ustinov* - - * Fixed multi-`RecipientInfo` Bleichenbacher Oracle in `CMS_decrypt()` - and `PKCS7_decrypt()`. - - Severity: Low - - Issue summary: The `CMS_decrypt()` and `PKCS7_decrypt()` functions - are vulnerable to Bleichenbacher-style attack when an attacker is able - to provide CMS or S/MIME messages and observe the error code - and/or decryption output. - - Impact summary: The Bleichenbacher-style attack allows an attacker to use - the victim's vulnerable application as a way to decrypt or sign messages - with the victim's private RSA key. - - Reported by: Alex Gaynor (Anthropic). - - ([CVE-2026-42768]) - - *Dmitry Belyavskiy (Red Hat) and Alicja Kario (Red Hat)* - - * Fixed trust anchor substitution via `cert`/`issuer` typo in CMP - `rootCaKeyUpdate`. - - Severity: Low - - Issue Summary: An error in the callback used to verify the certificate - provided in a Root CA key update Certificate Management Protocol (CMP) - message response rendered the certificate validation ineffectual, - which could lead to escalation of credentials from the Registration - Authority (RA) level to the root Certification Authority (root CA) level. - - Impact Summary: The Registration Authority could replace the root CA - certificate for the CMP clients with an arbitrary root CA certificate. - - Reported by: Alex Gaynor (Anthropic). - - ([CVE-2026-42769]) - - *Alex Gaynor (Anthropic) and Bob Beck* - - * Fixed FFC-DH peer validation uses attacker-supplied `q`. - - Severity: Low - - Issue summary: When `EVP_PKEY_derive_set_peer()` is called with a DHX (X9.42) - peer key, the peer key is not properly checked for the subgroup membership. - - Impact summary: A malicious peer which presents an X9.42 key carrying - the victim's `p` and `g` parameters, a forged `q = r` (a small prime factor - of the cofactor `(p − 1)/q_local`), and a public value `Y` of order `r` can - recover the victim's private key after a small number of key exchange - attempts. - - Reported by: Alex Gaynor (Anthropic). - - ([CVE-2026-42770]) - - *Alex Gaynor (Anthropic), Viktor Dukhovni, and Norbert Pócs* - - * Fixed possible out of bounds read in `X509_VERIFY_PARAM_set1_email()`. - - Severity: Low - - Issue summary: When `X509_VERIFY_PARAM_set1_email()` is called - by an application to validate a crafted e-mail address, such as during - S/MIME message validation, an out of bounds read can happen. - - Impact summary: This out of bounds read will not directly exfiltrate - the data read to the attacker, so, the most likely result is a crash - and a Denial of Service. - - Reported by: TrendAI Zero Day Initiative. - - ([CVE-2026-42771]) - - *Bob Beck* - - * Fixed incorrect tag processing for empty messages in AES-GCM-SIV - and AES-SIV modes. - - Severity: Low - - Issue summary: The implementations of AES-SIV ([RFC 5297]) and AES-GCM-SIV - ([RFC 8452]) mishandle the authentication of AAD (Additional Authenticated - Data) with an empty ciphertext, allowing forgery of such messages. - - Impact summary: An attacker can forge empty messages with arbitrary AAD - to the victim's application using these ciphers. - - Reported by: Alex Gaynor (Anthropic). - - ([CVE-2026-45446]) - - *Dmitry Belyavskiy (Red Hat)* - - * Fixed a regression introduced in 4.0.0 that led to a `openssl pkey` - command crash when it was invoked to encrypt a private key with password - being provided interactively. - - - *Viktor Dukhovni* - - * Fixed a regression introduced in 4.0.0 that led to `openssl s_client -adv` - command prematurely terminating a session when reading input of 16384 bytes - in one `read()` call. - - - *Eugene Syromiatnikov* - - * Fixed TLS 1.3 server not sending `NewSessionTicket` message - after ciphersuite mismatch. - - - *Daniel Kubec* - - * Implemented validation of the minimal length of PSK identity - being of at least one byte long, as required per [RFC 8446]. - - - *Matt Caswell* - - * Fixed usage of stale application buffer pointer by kTLS implementation - after incomplete writes when `SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER` is set, - that led to invalid memory reads and sending of incorrect data. - - - *Ilya Maximets* - -### Changes between 3.6 and 4.0.0 [14 Apr 2026] - - * Added `-expected-rpks` option to the `openssl s_client` - and `openssl s_server` commands. This makes it possible to specify - one or more public keys expected from the remote peer that are then used - to authenticate the connection. - - - *Viktor Dukhovni* - - * Added `-hmac-env` and `-hmac-stdin` options to `openssl dgst` command. - - - *Igor Ustinov* - - * Added LMS support for signature verification to `openssl pkeyutl` command. - To enable this, LMS `SubjectPublicKeyInfo` encoder and decoders were - added, and the LMS keymanager and signature code were updated. - - - *Shane Lontis* - - * Added new `SSL_get0_sigalg()` and `SSL_get0_shared_sigalg()` functions - to report the TLS signature algorithm name and codepoint for the peer - advertised and shared algorithms respectively. These supersede the existing - `SSL_get_sigalgs()` and `SSL_get_shared_sigalgs()` functions, which are only - a good fit for TLS 1.2. The names reported are the IANA names, - and are expected to consistently match the names expected - in `SignatureAlgorithms` configuration settings, see `SSL_CONF_cmd(3)` - for details. Previously reported names were not always directly usable - for configurations, and were mostly OpenSSL-specific aliases that rarely - matched the official IANA codepoint names. - - There is an associated change in how signature algorithms are reported by the - `openssl s_client` and `openssl s_server` commands. They now use - the new functions and report the IANA registered names of each signature - scheme. Example new output: - - Signature Algorithms: mldsa65:mldsa87:mldsa44:ecdsa_secp256r1_sha256:ecdsa_secp384r1_sha384:ecdsa_secp521r1_sha512:ed25519:ed448:ecdsa_brainpoolP256r1tls13_sha256:ecdsa_brainpoolP384r1tls13_sha384:ecdsa_brainpoolP512r1tls13_sha512:rsa_pss_pss_sha256:rsa_pss_pss_sha384:rsa_pss_pss_sha512:rsa_pss_rsae_sha256:rsa_pss_rsae_sha384:rsa_pss_rsae_sha512:rsa_pkcs1_sha256:rsa_pkcs1_sha384:rsa_pkcs1_sha512:ecdsa_sha224:rsa_pkcs1_sha224:dsa_sha224:dsa_sha256:dsa_sha384:dsa_sha512 - - - - *Viktor Dukhovni* - - * Implemented client-side predicted keyshare floating. When a tuple loses - the last element that was tagged for transmission of a predicted client - keyshare (by default `*X25519MLKEM768` and `*X25519` in their respective - tuples), either because the group is not enabled at compile-time, or - because it is removed by configuration (e.g. `DEFAULT:-`), if - the tuple remains non-empty, the keyshare is inherited by the first (i.e. - most preferred) remaining element of the tuple. - - - *Viktor Dukhovni* - - * Implemented `OSSL_STORE` support for `EVP_SKEY` objects, that includes - addition of new `-skeyuri` and `-storepass` options to `openssl enc` - command, addition of a new `-skeys` option to `openssl storeutl` command, - addition of `OSSL_STORE_INFO_SKEY` `OSS_STORE` object type and the relevant - `OSSL_STORE_INFO_get0_SKEY()`, `OSSL_STORE_INFO_get1_SKEY()`, - and `OSSL_STORE_INFO_new_SKEY()` APIs. - - - *Dmitry Belyavskiy* - - * Added support for [RFC 8998], signature algorithm `sm2sig_sm3`, key exchange - group `curveSM2`, and [tls-hybrid-sm2-mlkem] post-quantum group - `curveSM2MLKEM768`. - - Verification of SM2-signed certificates required changing the default - *distinguishing identifier* from empty to the constant ASCII string - "1234567812345678". An explicit empty distinguishing identifier value may - need to be used to verify or create signatures that are compatible with - versions of OpenSSL prior to 4.0. With the command-line tools an empty - value can be specified with the use of either the **-pkeyopt** - (`openssl-pkeyutl(1)`) or **-sigopt** (`openssl-dgst(1)`) option with a - value of "distid:". - - - *Viktor Dukhovni* - - * Added support for TLS 1.3 SM cipher suites `TLS_SM4_GCM_SM3` - and `TLS_SM4_CCM_SM3` from [RFC 8998]. - - - *Milan Brož* - - * Added cSHAKE function support as per [SP 800-185]. - - - *Shane Lontis* - - * Added "ML-DSA-MU" digest algorithm support. - - - *Shane Lontis* - - * Added SNMP KDF (`EVP_KDF_SNMPKDF`) to `EVP_KDF`. - - - *Barry Fussell and Helen Zhang* - - * Added SRTP KDF (`EVP_KDF_SRTPKDF`) to `EVP_KDF`. - - - *Barry Fussell and Helen Zhang* - - * Implemented [RFC 7919], adding support for negotiated FFDHE key exchange - in TLS 1.2. - - - *Joachim Vandersmissen* (with additional support from *Viktor Dukhovni*) - - * Added AKID verification checks when `X509_V_FLAG_X509_STRICT` is set. - Raise `X509_V_ERR_MISSING_AUTHORITY_KEY_IDENTIFIER` when AKID is not present. - Raise `X509_V_ERR_EMPTY_AUTHORITY_KEY_IDENTIFIER` when AKID has no attributes. - Raise `X509_V_ERR_AKID_ISSUER_SERIAL_NOT_PAIRED` when `authorityCertIssuer` - and `authorityCertSerialNumber` fields are not paired. - - - *Daniel Kubec* - - * Implemented [RFC 9849], adding support for Encrypted Client Hello (ECH). - See `doc/design/ech-api.md` for details. - - - - - - - - - - - *Stephen Farrell* (with much support from *Matt Caswell* and *Tomáš Mráz*) - - * Implemented display of CPU capabilities in `openssl version -c` output - on POWER and SPARC platforms, added `OPENSSL_ppccap(3)` manual page. - - - - - *Bernd Edlinger, Nia Alarie, and George Wilson* - - * Added `OSSL_ESS_check_signing_certs_ex()` function. - This API call is an extension to `OSSL_ESS_check_signing_certs()` that adds - the ability to specify a library context and property query when fetching - algorithms to validate a given certificate. - - - *Neil Horman* - - * Added `OPENSSL_sk_set_cmp_thunks()` function to allow for proper typecasting - during comparison of elements in a `STACK_OF` structure. - - - *Neil Horman* - - * Added `OSSL_PARAM_clear_free` function that allows cleansing `PARAM`s that - contain sensitive information, and switched to its use where it is suitable. - - - *Simo Source* - - * Added `ASN1_BIT_STRING_get_length()` function, that returns the number - of octets and the number of unused bits in an `ASN1_BIT_STRING` object. - - - *Bob Beck* - - * Added `ASN1_BIT_STRING_set1()` function to set a bit string to a value, - including the length in bytes and the number of unused bits. Internally, - `ASN1_BIT_STRING_set_bit()` has also been modified to keep the number - of unused bits correct when changing an `ASN1_BIT_STRING`. - - - *Bob Beck* - - * Added `PACKET_msg_start()` function, that allows obtaining start - of a `PACKET` buffer. - - - *Matt Caswell* - - * Added `SSL_add1_dnsname()`, `SSL_set1_dnsname()`, `SSL_add1_ipaddr()`, - and `SSL_set1_ipaddr()` functions as a replacement for `SSL_add1_host()` - and `SSL_set1_host()` that are deprecated now. The new replacement API - functions was added to support checking multiple names against a certificate - with `X509_VERIFY_PARAM`. See `X509_VERIFY_PARAM_set_flags(3)` for full - details. - - - *Bob Beck* - - * Added `SSL_listen_ex()` function, that, together with added ability to create - "blank" SSL objects using `OSSL_QUIC_method()`, allows implementing polling - of inbound connections in QUIC in a fashion similar to DTLS. - - - *Neil Horman* - - * Added `SSL_CTX_get0_alpn_protos()` and `SSL_get0_alpn_protos()` functions. - - - *Daniel Kubec* - - * Added `SSL_CTX_is_server()` function, that is similar to `SSL_is_server()`, - but takes `SSL_CTX` object as an argument. - - - *Igor Ustinov* - - * Added `EVP_MD_CTX_serialize()`/`EVP_MD_CTX_deserialize()` functions. - These functions allow to export the internal state of a Digest and re-import - it later to continue a computation from a specific checkpoint. Only SHA-2 - and the SHA-3 family (Keccak, SHAKE, SHA-3) of functions currently support - this functionality. - - - *Simo Sorce* - - * Added `BIO_set_send_flags()` function that allows setting flags passed to - `send()`, `sendto()`, and `sendmsg()`. The main intention is to allow - setting the `MSG_NOSIGNAL` flag to avoid a crash on receiving the `SIGPIPE` - signal. - - - *Igor Ustinov* - - * Added `X509v3_delete_extension()` function, that extends - `X509v3_delete_ext()` by deallocating the extension stack if it becomes - empty, as a convenience wrapper useful for optional X.509 extensions. - - - *Viktor Dukhovni* - - * Added ability to specify ML-KEM and ML-DSA encoding formats on a per-key - basis, by setting `output-formats` `EVP_PKEY` encoding parameter - appropriately via `OSSL_ENCODER_CTX_set_params(3)`. - - - *Viktor Dukhovni* - - * Added documentation for `BIO` flags and related functions. - - - *Igor Ustinov* - - * FIPS self tests can now be deferred and run as needed when installing - the FIPS module with the `-defer_tests` option of the `openssl fipsinstall` - command. - - - *Simo Sorce* - - * Lower bounds checks are now enforced when using `PKCS5_PBKDF2_HMAC` API - with FIPS provider. - - When using the FIPS provider via the `PKCS5_PBKDF2_HMAC` API, - password protected encrypted files will now have lower bounds - checks (minimum iteration count, minimum password length, salt - size and derived key lengths) enforced by default. Prior to - upgrading to this version, users may want to check if their - password protected key–stores are encrypted using short passwords, - salts, low iteration counts for PBKDF or weaker ciphers. To - upgrade to the new defaults one can decrypt the keys with a - previous OpenSSL version or the default provider, and then - re-encrypt them with the newer OpenSSL (using the FIPS provider), - thus upgrading to longer password, salt length and AES-256 CBC. - - - *Dimitri John Ledkov* - - * Added support for using either static or dynamic VC runtime linkage - on Windows. Using the `enable-static-vcruntime` configuration option, - OpenSSL can now be configured to use the static or dynamic `vcruntime.dll` - linkage. The multithreaded or single threaded static VC runtime is selected - based on the `enable-threads` option. - - - *Neil Horman* - - * Added configure options to disable KDF algorithms for `hmac-drbg-kdf`, - `kbkdf`, `krb5kdf`, `pvkkdf`, `snmpkdf`, `sskdf`, `sshkdf`, `x942kdf`, - and `x963kdf`. - - - *Shane Lontis* - - * Removed configure options can now only be disabled. You may continue - to use `disable-` syntax, which will remain supported. Using - `enable-` for a removed feature is no longer permitted. - - - *Andrew Dinh* - - * Added restrictions on the maximum number of TLS `key_share`s (16) - that a server will pay attention to, as well as the maximum number - of supported `group`s (128) and `sig_alg`s (128). Any sent beyond - these limits are ignored, in order to avoid clients sending excessively - long lists in these extensions. - - - *Matt Caswell* - - * Removed specialised built-in logic for adding the SKID and AKID extensions - from `openssl x509`, `openssl req`, and `openssl ca` commands, - these extensions are handled through configuration files and command-line - options just like any other extension. See their documentation and also - `x509v3_config(5)` for additional details. - - Updated the syntax of the `subjectKeyIdentifier` (SKID) and - `authorityKeyIdentifier` (AKID) extensions, introducing the `nonss` qualifier - for the `keyid` and `issuer` keywords. - - The x509 "mini-CA" now attempts to find extension settings in the default - configuration file even if neither the `-extfile` nor the `-extensions` - option is explicitly specified. Failure to open the default configuration - is silently ignored. - - The settings in the stock OpenSSL 4.0 configuration file arrange for - addition of the requisite SKID and AKID extensions. Other configuration - files may need to be adjusted if desired. - - - *Viktor Dukhovni* - - * Enabled Server verification by default in `s_server` - when the `-verify_return_error` option is enabled. - - - *Ryan Hooper* +### Changes between 3.6 and 4.0 [xx XXX xxxx] * Removed extra leading '00:' when printing key data such as an RSA modulus in hexadecimal format where the first (most significant) byte is >= 0x80. This had been added artificially to resemble ASN.1 DER encoding internals. Fixing this also makes sure that key output always has the expected length. - *David von Oheimb* - * Standardized the width of hexadecimal dumps to 24 bytes for signatures - (to stay within the 80 characters limit) and 16 bytes for everything else. - + * Standardized the width of hexadecimal dumps to 24 bytes for signatures (to + stay within the 80 characters limit) and 16 bytes for everything else. *Beat Bolli* - * Updated the default group list to append `SecP256r1MKEM768` and - `curveSM2MLKEM768` to the first tuple in that order after `*X25519MLKEM768`. - Also inserted a penultimate tuple with `curveSM2` (just before the `FFDHE` - groups). - + * The deprecated function ASN1_STRING_data has been removed. - *Viktor Dukhovni* + *Bob Beck* - * Consolidated processing of SM2 and EdDSA signatures with essentially - identical code for ECDSA in the `openssl speed` command. The output format - has changed slightly to report the EC curve name rather than its bit size. - + * various function parameters have been constified, + in particular for X509-related functions. - *Viktor Dukhovni* + *David von Oheimb* - * CRLs with a malformed Issuing Distribution Point extensions are now rejected. - - - *Daniel Kubec* - - * CRLs with malformed `CRL Number` or `Delta CRL Indicator` extensions - are now rejected. - - - *Daniel Kubec* - - * Fixed CRLs with invalid `ASN1_TIME` in `invalidityDate` extensions, - where verification incorrectly succeeded. Enforced proper handling - of `ASN1_TIME` validation results so that any CRL containing invalid - time fields is rejected immediately, preventing the error from propagating - to verification. - - - *Daniel Kubec* - - * CRLs with a `Certificate Issuer` extension in a certificate revocation entry - are now rejected, unless the `Indirect` flag is set to `TRUE` - in the `Issuing Distribution Point` extension of the CRL. - - - *Daniel Kubec* - - * `SSL_get_error()` no longer depends on the state of the error stack, - so it is no longer necessary to empty the error queue before the - TLS/SSL I/O operations. - + * Added `-hmac-env` and `-hmac-stdin` options to openssl-dgst. *Igor Ustinov* - * `ASN1_STRING` has been made opaque. + * Enabled Server verification by default in `s_server` when option + verify_return_error is enabled. - Access to values from `ASN1_STRING` and related types should be done with the - appropriate accessor functions. The various `ASN1_STRING_FLAG` values have - been made private. - + *Ryan Hooper* - *Bob Beck* - - * `OPENSSL_cleanup()` now runs in a global destructor, or not at all - by default: `OPENSSL_cleanup()` will no longer by default free global - objects when run from an application. Instead it sets a flag for a global - destructor to do this after the process exits, and after subordinate - libraries using OpenSSL have run their destructors. If destructor support - is not available, `OPENSSL_cleanup()` will do nothing, leaving the global - objects to be cleaned up by the operating system. - - - *Bob Beck* - - * Added `OSSL_CMP_OPT_PERMIT_TA_IN_EXTRACERTS_FOR_IR` option for `OSSL_CMP_CTX` - and a corresponding `-ta_in_ip_extracert` option for the `openssl cmp` command. - - This work was sponsored by Siemens AG. - - *David von Oheimb* - - * `X509_ALGOR_set_md()` function now returns a value indicating success - or failure. - - - *David von Oheimb* - - * Changed `BIO_snprintf()` implementation to use `snprintf()` provided - by system's libc (instead of relying on internal implementation), - making it bug-for-bug compatible with it. - - - *Alexandr Nedvedicky* - - * Added `X509_check_certificate_times()` function, as well as - the `` interface from BoringSSL/LibreSSL, that replace - now deprecated `X509_cmp_time()`, `X509_cmp_current_time()`, - and `X509_cmp_timeframe()`. See `X509_check_certificate_times(3)` - for details. - - - - - *Bob Beck* - - * `const`-corrected `time_t` arguments for `X509_cmp_time()`, - `X509_time_adj()`, and `X509_time_adj_ex()`. - - - *Frederik Wedel-Heinen* - - * Made `X509_ATTRIBUTE` accessor functions `const`-correct. The functions - `X509_ATTRIBUTE_get0_object()`, `X509_ATTRIBUTE_get0_type()`, and - `X509_ATTRIBUTE_get0_data()` now accept `const X509_ATTRIBUTE *` and - return `const` pointers. Related PKCS#12 functions `PKCS12_get_attr_gen()`, - `PKCS12_get_attr()`, and `PKCS8_get_attr()` have also been updated to - return `const ASN1_TYPE *`. - - - *kovan* - - * Made `X509_PUBKEY` accessor functions `const`-correct. - - - *Bob Beck* - - * `const`-corrected various function return values, particularly in `X509` - and related areas, and when functions were returning non-`const` objects - owned by a `const` parameter. - - - - *Bob Beck* - - * Many functions accepting `X509 *` arguments, or returning values - from a `const` `X509 *` have been changed to take/return `const` - arguments. The most visible changes are places where pointer values - are returned from a `const` `X509 *` object. In many places where - these were non `const` values being returned from a `const` object, - these pointer values have now been made `const`. The goal of this - change is to enable future improvements in X.509 certificate - handling. For full details see the relevant section in - `ossl-migration-guide(7)`. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - *Bob Beck* - - * `const`-corrected various function parameters, in particular - for `X509`-related functions. - - - *David von Oheimb* - - * `const`-corrected various `X509`-related functions: `X509_get_pathlen()`, - `X509_check_ca()`, `X509_check_purpose()`, `X509_get_proxy_pathlen()`, - `X509_get_extension_flags()`, `X509_get_key_usage()`, - `X509_get_extended_key_usage()`, `X509_get0_subject_key_id()`, - `X509_get0_authority_key_id()`, `X509_get0_authority_issuer()`, - `X509_get0_authority_serial()`, `X509_get0_distinguishing_id()`. - - - *Bob Beck* - - * Removed needless `const` qualifiers from scalar type arguments in the public - APIs, mostly for AES and Camellia. - - - *David von Oheimb* - - * Fixed a bug that allowed TLS 1.2 ciphers to be added to the TLS 1.3 - `ciphersuites` list, and for that list to contain duplicates. - Cipher configuration strings for both TLS 1.2 and 1.3 are now - case-insensitive. - - - *Viktor Dukhovni* - - * Deprecated `ASN1_OBJECT_new()` function. - Refer to `ossl-migration-guide(7)` for more info. - - - *Frederik Wedel-Heinen* - - * Deprecated `X509_NAME_get_text_by_NID()` and `X509_NAME_get_text_by_OBJ()` - functions, and documented them as such. - - - *Bob Beck* - - * Removed the `SSL_TXT_FIPS` option. This was a remnant of the old FIPS - canister and wasn't used anymore. - - - *Dr Paul Dale* - - * Removed `OPENSSL_atexit()` function. - - - *Bob Beck* - - * Removed critical extension enforcement for `EXFLAG_BCONS_CRITICAL`, - `EXFLAG_AKID_CRITICAL`, `EXFLAG_SKID_CRITICAL`, and `EXFLAG_SAN_CRITICAL`, - as it was incorrect. These checks were intended as CA requirements - to prevent misinterpretation by verifiers that don't support certain - extensions. However, since we do support these extensions, - there is no requirement for them to be marked as critical. Enforcing - that on `X509_V_FLAG_X509_STRICT` was a mistake. - + * Fixed CRLs with invalid ASN1_TIME in invalidityDate extensions, + where verification incorrectly succeeded. Enforced proper + handling of ASN1_TIME validation results so that any CRL + containing invalid time fields is rejected immediately, + preventing the error from propagating to verification. *Daniel Kubec* - * Removed support for an SSLv2 Client Hello. When a client wanted to support - both SSLv2 and higher versions like SSLv3 or even TLSv1, it needed to - send an SSLv2 Client Hello. SSLv2 support itself was removed - in OpenSSL 1.1.0, but there was still compatibility code for clients sending - an SSLv2 Client Hello. Since we no longer support SSLv2 Client Hello, - `SSL_client_hello_isv2()` is now deprecated and always returns 0. - + * Reject CRLs with a Certificate Issuer extension in a certificate revocation + entry unless the Indirect flag is set to TRUE in the IDP extension of the CRL. - *Kurt Roeckx* + *Daniel Kubec* - * Removed support for SSLv3. SSLv3 has been deprecated since 2015, and OpenSSL - had it disabled by default since version 1.1.0 (2016). - + * ENGINE support was removed. The `no-engine` build option and the + `OPENSSL_NO_ENGINE` macro is always present. + Applications using `ENGINE_` functions unguarded with `OPENSSL_NO_ENGINE` + can be built by defining a macro `OPENSSL_ENGINE_STUBS`, however all these + functions will return error when called. Provider API should be used to + replace ENGINEs functionality. - *Kurt Roeckx* + *Milan Broz*, *Neil Horman*, *Norbert Pocs* - * Support of deprecated elliptic curves in TLS according to [RFC 8422] was - disabled at compile-time by default. To enable it, use the - `enable-tls-deprecated-ec` configuration option. - + * Added SNMP KDF (EVP_KDF_SNMPKDF) to EVP_KDF - *Dmitry Belyavskiy* - - * Support of explicit EC curves was disabled by default, an error will occur - if an explicit EC curve doesn't match any known one. A new configuration - option, `enable-ec_explicit_curves`, is added. - - - *Dmitry Belyavskiy* - - * Removed `c_rehash` script tool. Use `openssl rehash` instead. - - - *Norbert Pócs* - - * `libcrypto` no longer cleans up globally allocated data via `atexit()`. - This data is cleaned up automatically by the OS. Some memory leak detectors - may report spurious allocated and reachable memory at application exit. - To avoid such spurious leak detection reports the application may call - `OPENSSL_cleanup()` before the process exits. - - - *Alexandr Nedvedicky* - - * Removed the `crypto-mdebug-backtrace` configuration option entirely. - The option has been a no-op since OpenSSL 1.0.2. - - - *Neil Horman* - - * Removed the deprecated function `ASN1_STRING_data()`. - - - *Bob Beck* - - * Removed the `ASN1_STRING_FLAG_X509_TIME` define. - - - *Bob Beck* - - * Dropped `darwin-i386{,-cc}` and `darwin-ppc{,64}{,-cc}` targets - from Configurations. - - - - *Daniel Kubec and Eugene Syromiatnikov* - - * Removed support for engines. The `no-engine` build option - and the `OPENSSL_NO_ENGINE` macro are always present. Applications that use - `ENGINE_` functions without `OPENSSL_NO_ENGINE` guards can be built - by defining a macro `OPENSSL_ENGINE_STUBS`; however, all these functions - will return error when called. Provider API should be used to replace - engine functionality. - - - *Milan Brož*, *Neil Horman*, *Norbert Pócs* - - * Removed deprecated support for custom `EVP_CIPHER`, `EVP_MD`, `EVP_PKEY`, - and `EVP_PKEY_ASN1` methods (`EVP_CIPHER_meth_*`, `EVP_MD_meth_*`, - `EVP_PKEY_meth_*`, and `EVP_PKEY_asn1_*` function families, respectively). - - - - - - - *Matt Caswell* - - * Removed deprecated fixed SSL/TLS version methods - (`{SSLv3,{D,}TLSv1{,_1,_2}}{,_client,_server}_method()` functions), - the migrating application should use `TLS_method()`, `TLS_client_method()`, - and `TLS_server_method()` functions instead. - - - *Frederik Wedel-Heinen* - - * Removed `BIO_f_reliable()` implementation without replacement. - It was broken since 3.0 release without any complaints. - - - *Tomáš Mráz* - - * Removed deprecated functions `ERR_get_state()`, `ERR_remove_state()` - and `ERR_remove_thread_state()`, as well as the `ERR_FLAG_MARK`, - `ERR_FLAG_CLEAR` and `ERR_NUM_ERRORS` macros. The `ERR_STATE` object is now - always opaque. - - - *Tomáš Mráz* - - * Removed the deprecated `msie-hack` option from the `openssl ca` command. - - - *Bob Beck* + *Barry Fussell and Helen Zhang* OpenSSL 3.6 ----------- -### Changes between 3.6.1 and 3.6.2 [7 Apr 2026] - - * Fixed incorrect failure handling in RSA KEM RSASVE encapsulation. - - Severity: Moderate - - Issue summary: Applications using RSASVE key encapsulation to establish - a secret encryption key can send contents of an uninitialized memory buffer - to a malicious peer. - - Impact summary: The uninitialized buffer might contain sensitive data - from the previous execution of the application process which leads - to sensitive data leakage to an attacker. - - Reported by: Simo Sorce (Red Hat). - - ([CVE-2026-31790]) - - *Nikola Pajkovsky* - - * Fixed loss of key agreement group tuple structure when the `DEFAULT` keyword - is used in the server-side configuration of the key-agreement group list. - - Severity: Low - - Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected - preferred key exchange group when its key exchange group configuration - includes the default by using the 'DEFAULT' keyword. - - Impact summary: A less preferred key exchange may be used even when a more - preferred group is supported by both client and server, if the group - was not included among the client's initial predicated keyshares. - This will sometimes be the case with the new hybrid post-quantum groups, - if the client chooses to defer their use until specifically requested by - the server. - - - * Fixed out-of-bounds read in AES-CFB-128 on x86-64 CPUs with AVX-512 support. - - Severity: Low - - Issue summary: Applications using AES-CFB128 encryption or decryption on - systems with AVX-512 and VAES support can trigger an out-of-bounds read - of up to 15 bytes when processing partial cipher blocks. - - Impact summary: This out-of-bounds read may trigger a crash which leads to - Denial of Service for an application if the input buffer ends at a memory - page boundary and the following page is unmapped. There is no information - disclosure as the over-read bytes are not written to output. - - Reported by: Stanislav Fort (Aisle Research), Pavel Kohout (Aisle Research), - and Alex Gaynor (Anthropic). - - ([CVE-2026-28386]) - - *Stanislav Fort, Pavel Kohout, and Alex Gaynor* - - * Fixed potential use-after-free in DANE client code. - - Severity: Low - - Issue summary: An uncommon configuration of clients performing DANE - TLSA-based server authentication, when paired with uncommon server DANE TLSA - records, may result in a use-after-free and/or double-free on the client - side. - - Impact summary: A use after free can have a range of potential consequences - such as the corruption of valid data, crashes, or execution of arbitrary - code. - - Reported by: Igor Morgenstern (Aisle Research). - - ([CVE-2026-28387]) - - *Viktor Dukhovni* - - * Fixed NULL pointer dereference when processing a delta CRL. - - Severity: Low - - Issue summary: When a delta CRL that contains a Delta CRL Indicator extension - is processed, a NULL pointer dereference might happen if the required CRL - Number extension is missing. - - Impact summary: A NULL pointer dereference can trigger a crash which - leads to a Denial of Service for an application. - - Reported by: Igor Morgenstern (Aisle Research). - - ([CVE-2026-28388]) - - *Igor Morgenstern* - - * Fixed possible NULL dereference when processing CMS KeyAgreeRecipientInfo. - - Severity: Low - - Issue summary: During processing of a crafted CMS EnvelopedData message - with KeyAgreeRecipientInfo a NULL pointer dereference can happen. - - Impact summary: Applications that process attacker-controlled CMS data may - crash before authentication or cryptographic operations occur resulting in - Denial of Service. - - Reported by: Nathan Sportsman (Praetorian), Daniel Rhea, - Jaeho Nam (Seoul National University), Muhammad Daffa, - Zhanpeng Liu (Tencent Xuanwu Lab), Guannan Wang (Tencent Xuanwu Lab), - Guancheng Li (Tencent Xuanwu Lab), and Joshua Rogers. - - ([CVE-2026-28389]) - - *Neil Horman* - - * Fixed possible NULL dereference when processing CMS - KeyTransportRecipientInfo. - - Severity: Low - - Issue summary: During processing of a crafted CMS EnvelopedData message - with KeyTransportRecipientInfo a NULL pointer dereference can happen. - - Impact summary: Applications that process attacker-controlled CMS data may - crash before authentication or cryptographic operations occur resulting in - Denial of Service. - - Reported by: Muhammad Daffa, Zhanpeng Liu (Tencent Xuanwu Lab), - Guannan Wang (Tencent Xuanwu Lab), Guancheng Li (Tencent Xuanwu Lab), - Joshua Rogers, and Chanho Kim. - - ([CVE-2026-28390]) - - *Neil Horman* - - * Fixed heap buffer overflow in hexadecimal conversion. - - Severity: Low - - Issue summary: Converting an excessively large OCTET STRING value to - a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. - - Impact summary: A heap buffer overflow may lead to a crash or possibly - an attacker controlled code execution or other undefined behavior. - - Reported by: Quoc Tran (Xint.io - US Team). - - ([CVE-2026-31789]) - - *Igor Ustinov* - - * Fixed usage of `openssl s_client -connect HOST -proxy PROXY` with `HOST` - containing a raw IPv6 address. - - - *Peter Zhang* - - * Fixed broken detection of plantext HTTP over TLS. - - - *Matt Caswell* - - * Fixed performance regressions introduced in 3.6 caused by the lack - of usage of CPU-capability-specific optimisations with non-EVP APIs, - as the capability detection was no longer performed during library load. - - - *Bob Beck* - -### Changes between 3.6.0 and 3.6.1 [27 Jan 2026] - - * Fixed Improper validation of PBMAC1 parameters in PKCS#12 MAC verification. - - Severity: Moderate - - Issue summary: PBMAC1 parameters in PKCS#12 files are missing validation - which can trigger a stack-based buffer overflow, invalid pointer or NULL - pointer dereference during MAC verification. - - Impact summary: The stack buffer overflow or NULL pointer dereference may - cause a crash leading to Denial of Service for an application that parses - untrusted PKCS#12 files. The buffer overflow may also potentially enable - code execution depending on platform mitigations. - - Reported by: Stanislav Fort (Aisle Research) and Petr Å imeÄek (Aisle - Research) and Hamza (Metadust) - - ([CVE-2025-11187]) - - *Tomáš Mráz* - - * Fixed Stack buffer overflow in CMS `AuthEnvelopedData` parsing. - - Severity: High - - Issue summary: Parsing CMS `AuthEnvelopedData` message with maliciously - crafted AEAD parameters can trigger a stack buffer overflow. - - Impact summary: A stack buffer overflow may lead to a crash, causing Denial - of Service, or potentially remote code execution. - - Reported by: Stanislav Fort (Aisle Research) - - ([CVE-2025-15467]) - - *Igor Ustinov* - - * Fixed NULL dereference in `SSL_CIPHER_find()` function on unknown cipher ID. - - Severity: Low - - Issue summary: If an application using the `SSL_CIPHER_find()` function - in a QUIC protocol client or server receives an unknown cipher suite from - the peer, a NULL dereference occurs. - - Impact summary: A NULL pointer dereference leads to abnormal termination - of the running process causing Denial of Service. - - Reported by: Stanislav Fort (Aisle Research) - - ([CVE-2025-15468]) - - *Stanislav Fort* - - * Fixed `openssl dgst` one-shot codepath silently truncates inputs >16 MiB. - - Severity: Low - - Issue summary: The `openssl dgst` command-line tool silently truncates input - data to 16 MiB when using one-shot signing algorithms and reports success - instead of an error. - - Impact summary: A user signing or verifying files larger than 16 MiB with - one-shot algorithms (such as Ed25519, Ed448, or ML-DSA) may believe the - entire file is authenticated while trailing data beyond 16 MiB remains - unauthenticated. - - Reported by: Stanislav Fort (Aisle Research) - - ([CVE-2025-15469]) - - *Viktor Dukhovni* - - * Fixed TLS 1.3 `CompressedCertificate` excessive memory allocation. - - Severity: Low - - Issue summary: A TLS 1.3 connection using certificate compression can be - forced to allocate a large buffer before decompression without checking - against the configured certificate size limit. - - Impact summary: An attacker can cause per-connection memory allocations - of up to approximately 22 MiB and extra CPU work, potentially leading - to service degradation or resource exhaustion (Denial of Service). - - Reported by: Tomas Dulka (Aisle Research) and Stanislav Fort (Aisle - Research) - - ([CVE-2025-66199]) - - *Tomas Dulka and Stanislav Fort* - - * Fixed Heap out-of-bounds write in `BIO_f_linebuffer` on short writes. - - Severity: Low - - Issue summary: Writing large, newline-free data into a BIO chain using the - line-buffering filter where the next BIO performs short writes can trigger - a heap-based out-of-bounds write. - - Impact summary: This out-of-bounds write can cause memory corruption - which typically results in a crash, leading to Denial of Service for - an application. - - Reported by: Petr Simecek (Aisle Research) and Stanislav Fort (Aisle - Research) - - ([CVE-2025-68160]) - - *Stanislav Fort and Neil Horman* - - * Fixed Unauthenticated/unencrypted trailing bytes with low-level OCB - function calls. - - Severity: Low - - Issue summary: When using the low-level OCB API directly with AES-NI or - other hardware-accelerated code paths, inputs whose length is not a multiple - of 16 bytes can leave the final partial block unencrypted and - unauthenticated. - - Impact summary: The trailing 1-15 bytes of a message may be exposed in - cleartext on encryption and are not covered by the authentication tag, - allowing an attacker to read or tamper with those bytes without detection. - - Reported by: Stanislav Fort (Aisle Research) - - ([CVE-2025-69418]) - - *Stanislav Fort* - - * Fixed Out of bounds write in `PKCS12_get_friendlyname()` UTF-8 conversion. - - Severity: Low - - Issue summary: Calling `PKCS12_get_friendlyname()` function on a maliciously - crafted PKCS#12 file with a `BMPString` (UTF-16BE) friendly name containing - non-ASCII BMP code point can trigger a one byte write before the allocated - buffer. - - Impact summary: The out-of-bounds write can cause a memory corruption - which can have various consequences including a Denial of Service. - - Reported by: Stanislav Fort (Aisle Research) - - ([CVE-2025-69419]) - - *Norbert Pócs* - - * Fixed Missing `ASN1_TYPE` validation in `TS_RESP_verify_response()` function. - - Severity: Low - - Issue summary: A type confusion vulnerability exists in the TimeStamp - Response verification code where an `ASN1_TYPE` union member is accessed - without first validating the type, causing an invalid or NULL pointer - dereference when processing a malformed `TimeStamp` Response file. - - Impact summary: An application calling `TS_RESP_verify_response()` - with a malformed TimeStamp Response can be caused to dereference an invalid - or NULL pointer when reading, resulting in a Denial of Service. - - Reported by: Luigino Camastra (Aisle Research) - - ([CVE-2025-69420]) - - *Bob Beck* - - * Fixed NULL Pointer Dereference in `PKCS12_item_decrypt_d2i_ex()` function. - - Severity: Low - - Issue summary: Processing a malformed PKCS#12 file can trigger a NULL - pointer dereference in the `PKCS12_item_decrypt_d2i_ex()` function. - - Impact summary: A NULL pointer dereference can trigger a crash which leads - to Denial of Service for an application processing PKCS#12 files. - - Reported by: Luigino Camastra (Aisle Research) - - ([CVE-2025-69421]) - - *Luigino Camastra* - - * Fixed Missing `ASN1_TYPE` validation in PKCS#12 parsing. - - Severity: Low - - Issue summary: An invalid or NULL pointer dereference can happen in - an application processing a malformed PKCS#12 file. - - Impact summary: An application processing a malformed PKCS#12 file can be - caused to dereference an invalid or NULL pointer on memory read, resulting - in a Denial of Service. - - Reported by: Luigino Camastra (Aisle Research) - - ([CVE-2026-22795]) - - *Bob Beck* - - * Fixed `ASN1_TYPE` Type Confusion in the `PKCS7_digest_from_attributes()` - function. - - Severity: Low - - Issue summary: A type confusion vulnerability exists in the signature - verification of signed PKCS#7 data where an `ASN1_TYPE` union member - is accessed without first validating the type, causing an invalid or NULL - pointer dereference when processing malformed PKCS#7 data. - - Impact summary: An application performing signature verification of PKCS#7 - data or calling directly the `PKCS7_digest_from_attributes()` function can be - caused to dereference an invalid or NULL pointer when reading, resulting in - a Denial of Service. - - Reported by: Luigino Camastra (Aisle Research) - - ([CVE-2026-22796]) - - *Bob Beck* - - * RISC-V capabilities string format has changed to include the base - architecture and the vector length for the V extension. - - - *Bernd Edlinger* - - * Fixed a regression in `X509_V_FLAG_CRL_CHECK_ALL` flag handling by restoring - its pre-3.6.0 behaviour of being ignored when `X509_V_FLAG_CRL_CHECK` flag - is not set, and no longer implying the latter flag instead. - - - *Carter Thaxton* - - * Fixed a regression that caused generation of empty stapled OCSP responses - when at least one certificate in the certificate chain had a stapled OCSP - response present, causing handshake failures for OpenSSL 3.6.0 servers - with various client implementations, including GnuTLS and BoringSSL. - - - *Martin Rauch* - - * Fixed exit code of `openssl x509` command with `-checkend` option in use. - - - *Stefan Rieche* - - * Fixed incorrect acceptance of some malformed ECDSA signatures on s390x. - - - *Holger Dengler* - - * Source code has been reformatted with `clang-format`. - - - *Bob Beck* - - * Reverted a change in behaviour of the single stapled OCSP response API - with respect to the ownership of the OCSP response object that caused - a memory leak. - - - *Remi Gacogne and Tomáš Mráz* - ### Changes between 3.5 and 3.6.0 [1 Oct 2025] * Added support for `EVP_SKEY` opaque symmetric key objects to the key @@ -2046,10 +339,10 @@ OpenSSL 3.5 *Stanislav Fort and Tomáš Mráz* - * Fix Out-of-bounds read in HTTP client `no_proxy` handling + * Fix Out-of-bounds read in HTTP client no_proxy handling Issue summary: An application using the OpenSSL HTTP client API functions - may trigger an out-of-bounds read if the `no_proxy` environment variable is + may trigger an out-of-bounds read if the "no_proxy" environment variable is set and the host portion of the authority component of the HTTP URL is an IPv6 address. @@ -2150,10 +443,10 @@ OpenSSL 3.5 *Tomas Mraz* - * Aligned the behaviour of TLS and DTLS in the event of a `no_renegotiation` + * Aligned the behaviour of TLS and DTLS in the event of a no_renegotiation alert being received. Older versions of OpenSSL failed with DTLS if a - `no_renegotiation` alert was received. All versions of OpenSSL do this for TLS. - From 3.2 a bug was exposed that meant that DTLS ignored `no_rengotiation`. We + no_renegotiation alert was received. All versions of OpenSSL do this for TLS. + From 3.2 a bug was exposed that meant that DTLS ignored no_rengotiation. We have now restored the original behaviour and brought DTLS back into line with TLS. @@ -4175,7 +2468,7 @@ breaking changes, and mappings for the large list of deprecated functions. * Fixed a bug in the function `OCSP_basic_verify` that verifies the signer certificate on an OCSP response. The bug caused the function in the case - where the (non-default) flag OCSP_NOCHECKS is used to return a positive + where the (non-default) flag OCSP_NOCHECKS is used to return a postivie response (meaning a successful verification) even in the case where the response signing certificate fails to verify. @@ -5207,7 +3500,7 @@ breaking changes, and mappings for the large list of deprecated functions. *Richard Levitte* - * Fixed an overflow bug in the x86_64 Montgomery squaring procedure + * Fixed an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very @@ -19973,7 +18266,7 @@ s-cbc 3624.96k 5258.21k 5530.91k 5624.30k 5628.26k The new configuration file reading functions are: NCONF_new, NCONF_free, NCONF_load, NCONF_load_fp, NCONF_load_bio, - NCONF_get_section, NCONF_get_string, NCONF_get_number + NCONF_get_section, NCONF_get_string, NCONF_get_numbre NCONF_default, NCONF_WIN32 @@ -23353,255 +21646,206 @@ ndif -[CMVP]: https://csrc.nist.gov/projects/cryptographic-module-validation-program -[CVE-2002-0655]: https://openssl-library.org/news/vulnerabilities/#CVE-2002-0655 -[CVE-2002-0656]: https://openssl-library.org/news/vulnerabilities/#CVE-2002-0656 -[CVE-2002-0657]: https://openssl-library.org/news/vulnerabilities/#CVE-2002-0657 -[CVE-2002-0659]: https://openssl-library.org/news/vulnerabilities/#CVE-2002-0659 -[CVE-2003-0078]: https://openssl-library.org/news/vulnerabilities/#CVE-2003-0078 -[CVE-2003-0543]: https://openssl-library.org/news/vulnerabilities/#CVE-2003-0543 -[CVE-2003-0544]: https://openssl-library.org/news/vulnerabilities/#CVE-2003-0544 -[CVE-2003-0545]: https://openssl-library.org/news/vulnerabilities/#CVE-2003-0545 -[CVE-2003-0851]: https://openssl-library.org/news/vulnerabilities/#CVE-2003-0851 -[CVE-2004-0079]: https://openssl-library.org/news/vulnerabilities/#CVE-2004-0079 -[CVE-2004-0112]: https://openssl-library.org/news/vulnerabilities/#CVE-2004-0112 -[CVE-2005-2969]: https://openssl-library.org/news/vulnerabilities/#CVE-2005-2969 -[CVE-2006-2937]: https://openssl-library.org/news/vulnerabilities/#CVE-2006-2937 -[CVE-2006-2940]: https://openssl-library.org/news/vulnerabilities/#CVE-2006-2940 -[CVE-2006-3738]: https://openssl-library.org/news/vulnerabilities/#CVE-2006-3738 -[CVE-2006-4339]: https://openssl-library.org/news/vulnerabilities/#CVE-2006-4339 -[CVE-2006-4343]: https://openssl-library.org/news/vulnerabilities/#CVE-2006-4343 -[CVE-2007-4995]: https://openssl-library.org/news/vulnerabilities/#CVE-2007-4995 -[CVE-2007-5135]: https://openssl-library.org/news/vulnerabilities/#CVE-2007-5135 -[CVE-2008-0891]: https://openssl-library.org/news/vulnerabilities/#CVE-2008-0891 -[CVE-2008-1672]: https://openssl-library.org/news/vulnerabilities/#CVE-2008-1672 -[CVE-2008-1678]: https://openssl-library.org/news/vulnerabilities/#CVE-2008-1678 -[CVE-2008-5077]: https://openssl-library.org/news/vulnerabilities/#CVE-2008-5077 -[CVE-2009-0590]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-0590 -[CVE-2009-0591]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-0591 -[CVE-2009-0789]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-0789 -[CVE-2009-1377]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-1377 -[CVE-2009-1378]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-1378 -[CVE-2009-1379]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-1379 -[CVE-2009-1386]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-1386 -[CVE-2009-3245]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-3245 -[CVE-2009-3555]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-3555 -[CVE-2009-4355]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-4355 -[CVE-2010-0433]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-0433 -[CVE-2010-0740]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-0740 -[CVE-2010-1633]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-1633 -[CVE-2010-3864]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-3864 -[CVE-2010-4180]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-4180 -[CVE-2010-4252]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-4252 -[CVE-2011-0014]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-0014 -[CVE-2011-3207]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-3207 -[CVE-2011-3210]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-3210 -[CVE-2011-4108]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-4108 -[CVE-2011-4109]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-4109 -[CVE-2011-4576]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-4576 -[CVE-2011-4577]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-4577 -[CVE-2011-4619]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-4619 -[CVE-2012-0027]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-0027 -[CVE-2012-0050]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-0050 -[CVE-2012-0884]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-0884 -[CVE-2012-2110]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-2110 -[CVE-2012-2333]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-2333 -[CVE-2012-2686]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-2686 -[CVE-2013-0166]: https://openssl-library.org/news/vulnerabilities/#CVE-2013-0166 -[CVE-2013-0169]: https://openssl-library.org/news/vulnerabilities/#CVE-2013-0169 -[CVE-2013-4353]: https://openssl-library.org/news/vulnerabilities/#CVE-2013-4353 -[CVE-2013-6450]: https://openssl-library.org/news/vulnerabilities/#CVE-2013-6450 -[CVE-2014-0076]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0076 -[CVE-2014-0160]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0160 -[CVE-2014-0195]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0195 -[CVE-2014-0221]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0221 -[CVE-2014-0224]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0224 -[CVE-2014-3470]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3470 -[CVE-2014-3505]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3505 -[CVE-2014-3506]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3506 -[CVE-2014-3507]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3507 -[CVE-2014-3508]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3508 -[CVE-2014-3509]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3509 -[CVE-2014-3510]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3510 -[CVE-2014-3511]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3511 -[CVE-2014-3512]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3512 -[CVE-2014-3513]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3513 -[CVE-2014-3566]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3566 -[CVE-2014-3567]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3567 -[CVE-2014-3568]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3568 -[CVE-2014-3569]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3569 -[CVE-2014-3570]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3570 -[CVE-2014-3571]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3571 -[CVE-2014-3572]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3572 -[CVE-2014-5139]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-5139 -[CVE-2014-8275]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-8275 -[CVE-2015-0204]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0204 -[CVE-2015-0205]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0205 -[CVE-2015-0206]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0206 -[CVE-2015-0207]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0207 -[CVE-2015-0208]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0208 -[CVE-2015-0209]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0209 -[CVE-2015-0285]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0285 -[CVE-2015-0286]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0286 -[CVE-2015-0287]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0287 -[CVE-2015-0288]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0288 -[CVE-2015-0289]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0289 -[CVE-2015-0290]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0290 -[CVE-2015-0291]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0291 -[CVE-2015-0293]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0293 -[CVE-2015-1787]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1787 -[CVE-2015-1788]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1788 -[CVE-2015-1789]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1789 -[CVE-2015-1790]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1790 -[CVE-2015-1791]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1791 -[CVE-2015-1792]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1792 -[CVE-2015-1793]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1793 -[CVE-2015-3193]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-3193 -[CVE-2015-3194]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-3194 -[CVE-2015-3195]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-3195 -[CVE-2015-3196]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-3196 -[CVE-2015-3197]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-3197 -[CVE-2016-0701]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0701 -[CVE-2016-0702]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0702 -[CVE-2016-0705]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0705 -[CVE-2016-0797]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0797 -[CVE-2016-0798]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0798 -[CVE-2016-0799]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0799 -[CVE-2016-0800]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0800 -[CVE-2016-2105]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2105 -[CVE-2016-2106]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2106 -[CVE-2016-2107]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2107 -[CVE-2016-2109]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2109 -[CVE-2016-2176]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2176 -[CVE-2016-2177]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2177 -[CVE-2016-2178]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2178 -[CVE-2016-2179]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2179 -[CVE-2016-2180]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2180 -[CVE-2016-2181]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2181 -[CVE-2016-2182]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2182 -[CVE-2016-2183]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2183 -[CVE-2016-6302]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6302 -[CVE-2016-6303]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6303 -[CVE-2016-6304]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6304 -[CVE-2016-6305]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6305 -[CVE-2016-6306]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6306 -[CVE-2016-6307]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6307 -[CVE-2016-6308]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6308 -[CVE-2016-6309]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6309 -[CVE-2016-7052]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-7052 -[CVE-2016-7053]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-7053 -[CVE-2016-7054]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-7054 -[CVE-2016-7055]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-7055 -[CVE-2017-3730]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3730 -[CVE-2017-3731]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3731 -[CVE-2017-3732]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3732 -[CVE-2017-3733]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3733 -[CVE-2017-3735]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3735 -[CVE-2017-3736]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3736 -[CVE-2017-3737]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3737 -[CVE-2017-3738]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3738 -[CVE-2018-0732]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0732 -[CVE-2018-0733]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0733 -[CVE-2018-0734]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0734 -[CVE-2018-0735]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0735 -[CVE-2018-0737]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0737 -[CVE-2018-0739]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0739 -[CVE-2018-5407]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-5407 -[CVE-2019-1543]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1543 -[CVE-2019-1547]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1547 -[CVE-2019-1549]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1549 -[CVE-2019-1551]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1551 -[CVE-2019-1552]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1552 -[CVE-2019-1559]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1559 -[CVE-2019-1563]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1563 -[CVE-2020-1967]: https://openssl-library.org/news/vulnerabilities/#CVE-2020-1967 -[CVE-2020-1971]: https://openssl-library.org/news/vulnerabilities/#CVE-2020-1971 -[CVE-2022-2097]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-2097 -[CVE-2022-2274]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-2274 -[CVE-2022-3996]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-3996 -[CVE-2022-4203]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-4203 -[CVE-2022-4304]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-4304 -[CVE-2022-4450]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-4450 -[CVE-2023-0215]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0215 -[CVE-2023-0216]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0216 -[CVE-2023-0217]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0217 -[CVE-2023-0286]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0286 -[CVE-2023-0401]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0401 -[CVE-2023-0464]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0464 -[CVE-2023-0465]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0465 -[CVE-2023-0466]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0466 -[CVE-2023-1255]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-1255 -[CVE-2023-2650]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-2650 -[CVE-2023-2975]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-2975 -[CVE-2023-3446]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-3446 -[CVE-2023-3817]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-3817 -[CVE-2023-4807]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-4807 -[CVE-2023-5363]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-5363 -[CVE-2023-5678]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-5678 -[CVE-2023-6129]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-6129 -[CVE-2023-6237]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-6237 -[CVE-2024-0727]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-0727 -[CVE-2024-2511]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-2511 -[CVE-2024-4603]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-4603 -[CVE-2024-4741]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-4741 -[CVE-2024-5535]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-5535 -[CVE-2024-6119]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-6119 -[CVE-2024-9143]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-9143 -[CVE-2024-13176]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-13176 -[CVE-2025-4575]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-4575 -[CVE-2025-9230]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-9230 -[CVE-2025-9231]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-9231 -[CVE-2025-9232]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-9232 -[CVE-2025-11187]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-11187 -[CVE-2025-15467]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-15467 -[CVE-2025-15468]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-15468 -[CVE-2025-15469]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-15469 -[CVE-2025-66199]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-66199 -[CVE-2025-68160]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-68160 -[CVE-2025-69418]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-69418 -[CVE-2025-69419]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-69419 -[CVE-2025-69420]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-69420 -[CVE-2025-69421]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-69421 -[CVE-2026-2673]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-2673 -[CVE-2026-7383]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-7383 -[CVE-2026-9076]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-9076 -[CVE-2026-22795]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-22795 -[CVE-2026-22796]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-22796 -[CVE-2026-28386]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-28386 -[CVE-2026-28387]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-28387 -[CVE-2026-28388]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-28388 -[CVE-2026-28389]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-28389 -[CVE-2026-28390]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-28390 -[CVE-2026-31789]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-31789 -[CVE-2026-31790]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-31790 -[CVE-2026-34180]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34180 -[CVE-2026-34181]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34181 -[CVE-2026-34182]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34182 -[CVE-2026-34183]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34183 -[CVE-2026-35188]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-35188 -[CVE-2026-42764]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42764 -[CVE-2026-42765]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42765 -[CVE-2026-42766]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42766 -[CVE-2026-42767]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42767 -[CVE-2026-42768]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42768 -[CVE-2026-42769]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42769 -[CVE-2026-42770]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42770 -[CVE-2026-42771]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42771 -[CVE-2026-45445]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-45445 -[CVE-2026-45446]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-45446 -[CVE-2026-45447]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-45447 -[ESV]: https://csrc.nist.gov/Projects/cryptographic-module-validation-program/entropy-validations +[CVE-2025-9232]: https://www.openssl.org/news/vulnerabilities.html#CVE-2025-9232 +[CVE-2025-9231]: https://www.openssl.org/news/vulnerabilities.html#CVE-2025-9231 +[CVE-2025-9230]: https://www.openssl.org/news/vulnerabilities.html#CVE-2025-9230 +[CVE-2025-4575]: https://www.openssl.org/news/vulnerabilities.html#CVE-2025-4575 +[CVE-2024-13176]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-13176 +[CVE-2024-9143]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-9143 +[CVE-2024-6119]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-6119 +[CVE-2024-5535]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-5535 +[CVE-2024-4741]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-4741 +[CVE-2024-4603]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-4603 +[CVE-2024-2511]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-2511 +[CVE-2024-0727]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-0727 +[CVE-2023-6237]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-6237 +[CVE-2023-6129]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-6129 +[CVE-2023-5678]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-5678 +[CVE-2023-5363]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-5363 +[CVE-2023-4807]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-4807 +[CVE-2023-3817]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-3817 +[CVE-2023-3446]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-3446 +[CVE-2023-2975]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-2975 [RFC 2578 (STD 58), section 3.5]: https://datatracker.ietf.org/doc/html/rfc2578#section-3.5 -[RFC 3211]: https://datatracker.ietf.org/doc/html/rfc3211 -[RFC 5297]: https://datatracker.ietf.org/doc/html/rfc5297 -[RFC 7919]: https://datatracker.ietf.org/doc/html/rfc7919 -[RFC 8422]: https://datatracker.ietf.org/doc/html/rfc8422 -[RFC 8446]: https://datatracker.ietf.org/doc/html/rfc8446 -[RFC 8452]: https://datatracker.ietf.org/doc/html/rfc8452 -[RFC 8998]: https://datatracker.ietf.org/doc/html/rfc8998#name-iana-considerations -[RFC 9149]: https://datatracker.ietf.org/doc/html/rfc9149 -[RFC 9849]: https://datatracker.ietf.org/doc/html/rfc9849 +[CVE-2023-2650]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-2650 +[CVE-2023-1255]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-1255 +[CVE-2023-0466]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0466 +[CVE-2023-0465]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0465 +[CVE-2023-0464]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0464 +[CVE-2023-0401]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0401 +[CVE-2023-0286]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0286 +[CVE-2023-0217]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0217 +[CVE-2023-0216]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0216 +[CVE-2023-0215]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0215 +[CVE-2022-4450]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-4450 +[CVE-2022-4304]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-4304 +[CVE-2022-4203]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-4203 +[CVE-2022-3996]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-3996 +[CVE-2022-2274]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-2274 +[CVE-2022-2097]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-2097 +[CVE-2020-1971]: https://www.openssl.org/news/vulnerabilities.html#CVE-2020-1971 +[CVE-2020-1967]: https://www.openssl.org/news/vulnerabilities.html#CVE-2020-1967 +[CVE-2019-1563]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1563 +[CVE-2019-1559]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1559 +[CVE-2019-1552]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1552 +[CVE-2019-1551]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1551 +[CVE-2019-1549]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1549 +[CVE-2019-1547]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1547 +[CVE-2019-1543]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1543 +[CVE-2018-5407]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-5407 +[CVE-2018-0739]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0739 +[CVE-2018-0737]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0737 +[CVE-2018-0735]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0735 +[CVE-2018-0734]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0734 +[CVE-2018-0733]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0733 +[CVE-2018-0732]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0732 +[CVE-2017-3738]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3738 +[CVE-2017-3737]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3737 +[CVE-2017-3736]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3736 +[CVE-2017-3735]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3735 +[CVE-2017-3733]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3733 +[CVE-2017-3732]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3732 +[CVE-2017-3731]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3731 +[CVE-2017-3730]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3730 +[CVE-2016-7055]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-7055 +[CVE-2016-7054]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-7054 +[CVE-2016-7053]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-7053 +[CVE-2016-7052]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-7052 +[CVE-2016-6309]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6309 +[CVE-2016-6308]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6308 +[CVE-2016-6307]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6307 +[CVE-2016-6306]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6306 +[CVE-2016-6305]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6305 +[CVE-2016-6304]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6304 +[CVE-2016-6303]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6303 +[CVE-2016-6302]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6302 +[CVE-2016-2183]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2183 +[CVE-2016-2182]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2182 +[CVE-2016-2181]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2181 +[CVE-2016-2180]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2180 +[CVE-2016-2179]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2179 +[CVE-2016-2178]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2178 +[CVE-2016-2177]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2177 +[CVE-2016-2176]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2176 +[CVE-2016-2109]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2109 +[CVE-2016-2107]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2107 +[CVE-2016-2106]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2106 +[CVE-2016-2105]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2105 +[CVE-2016-0800]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0800 +[CVE-2016-0799]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0799 +[CVE-2016-0798]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0798 +[CVE-2016-0797]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0797 +[CVE-2016-0705]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0705 +[CVE-2016-0702]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0702 +[CVE-2016-0701]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0701 +[CVE-2015-3197]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-3197 +[CVE-2015-3196]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-3196 +[CVE-2015-3195]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-3195 +[CVE-2015-3194]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-3194 +[CVE-2015-3193]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-3193 +[CVE-2015-1793]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1793 +[CVE-2015-1792]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1792 +[CVE-2015-1791]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1791 +[CVE-2015-1790]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1790 +[CVE-2015-1789]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1789 +[CVE-2015-1788]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1788 +[CVE-2015-1787]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1787 +[CVE-2015-0293]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0293 +[CVE-2015-0291]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0291 +[CVE-2015-0290]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0290 +[CVE-2015-0289]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0289 +[CVE-2015-0288]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0288 +[CVE-2015-0287]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0287 +[CVE-2015-0286]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0286 +[CVE-2015-0285]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0285 +[CVE-2015-0209]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0209 +[CVE-2015-0208]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0208 +[CVE-2015-0207]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0207 +[CVE-2015-0206]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0206 +[CVE-2015-0205]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0205 +[CVE-2015-0204]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0204 +[CVE-2014-8275]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-8275 +[CVE-2014-5139]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-5139 +[CVE-2014-3572]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3572 +[CVE-2014-3571]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3571 +[CVE-2014-3570]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3570 +[CVE-2014-3569]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3569 +[CVE-2014-3568]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3568 +[CVE-2014-3567]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3567 +[CVE-2014-3566]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3566 +[CVE-2014-3513]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3513 +[CVE-2014-3512]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3512 +[CVE-2014-3511]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3511 +[CVE-2014-3510]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3510 +[CVE-2014-3509]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3509 +[CVE-2014-3508]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3508 +[CVE-2014-3507]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3507 +[CVE-2014-3506]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3506 +[CVE-2014-3505]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3505 +[CVE-2014-3470]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3470 +[CVE-2014-0224]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0224 +[CVE-2014-0221]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0221 +[CVE-2014-0195]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0195 +[CVE-2014-0160]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0160 +[CVE-2014-0076]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0076 +[CVE-2013-6450]: https://www.openssl.org/news/vulnerabilities.html#CVE-2013-6450 +[CVE-2013-4353]: https://www.openssl.org/news/vulnerabilities.html#CVE-2013-4353 +[CVE-2013-0169]: https://www.openssl.org/news/vulnerabilities.html#CVE-2013-0169 +[CVE-2013-0166]: https://www.openssl.org/news/vulnerabilities.html#CVE-2013-0166 +[CVE-2012-2686]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-2686 +[CVE-2012-2333]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-2333 +[CVE-2012-2110]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-2110 +[CVE-2012-0884]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-0884 +[CVE-2012-0050]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-0050 +[CVE-2012-0027]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-0027 +[CVE-2011-4619]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-4619 +[CVE-2011-4577]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-4577 +[CVE-2011-4576]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-4576 +[CVE-2011-4109]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-4109 +[CVE-2011-4108]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-4108 +[CVE-2011-3210]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-3210 +[CVE-2011-3207]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-3207 +[CVE-2011-0014]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-0014 +[CVE-2010-4252]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-4252 +[CVE-2010-4180]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-4180 +[CVE-2010-3864]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-3864 +[CVE-2010-1633]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-1633 +[CVE-2010-0740]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-0740 +[CVE-2010-0433]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-0433 +[CVE-2009-4355]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-4355 +[CVE-2009-3555]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-3555 +[CVE-2009-3245]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-3245 +[CVE-2009-1386]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-1386 +[CVE-2009-1379]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-1379 +[CVE-2009-1378]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-1378 +[CVE-2009-1377]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-1377 +[CVE-2009-0789]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-0789 +[CVE-2009-0591]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-0591 +[CVE-2009-0590]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-0590 +[CVE-2008-5077]: https://www.openssl.org/news/vulnerabilities.html#CVE-2008-5077 +[CVE-2008-1678]: https://www.openssl.org/news/vulnerabilities.html#CVE-2008-1678 +[CVE-2008-1672]: https://www.openssl.org/news/vulnerabilities.html#CVE-2008-1672 +[CVE-2008-0891]: https://www.openssl.org/news/vulnerabilities.html#CVE-2008-0891 +[CVE-2007-5135]: https://www.openssl.org/news/vulnerabilities.html#CVE-2007-5135 +[CVE-2007-4995]: https://www.openssl.org/news/vulnerabilities.html#CVE-2007-4995 +[CVE-2006-4343]: https://www.openssl.org/news/vulnerabilities.html#CVE-2006-4343 +[CVE-2006-4339]: https://www.openssl.org/news/vulnerabilities.html#CVE-2006-4339 +[CVE-2006-3738]: https://www.openssl.org/news/vulnerabilities.html#CVE-2006-3738 +[CVE-2006-2940]: https://www.openssl.org/news/vulnerabilities.html#CVE-2006-2940 +[CVE-2006-2937]: https://www.openssl.org/news/vulnerabilities.html#CVE-2006-2937 +[CVE-2005-2969]: https://www.openssl.org/news/vulnerabilities.html#CVE-2005-2969 +[CVE-2004-0112]: https://www.openssl.org/news/vulnerabilities.html#CVE-2004-0112 +[CVE-2004-0079]: https://www.openssl.org/news/vulnerabilities.html#CVE-2004-0079 +[CVE-2003-0851]: https://www.openssl.org/news/vulnerabilities.html#CVE-2003-0851 +[CVE-2003-0545]: https://www.openssl.org/news/vulnerabilities.html#CVE-2003-0545 +[CVE-2003-0544]: https://www.openssl.org/news/vulnerabilities.html#CVE-2003-0544 +[CVE-2003-0543]: https://www.openssl.org/news/vulnerabilities.html#CVE-2003-0543 +[CVE-2003-0078]: https://www.openssl.org/news/vulnerabilities.html#CVE-2003-0078 +[CVE-2002-0659]: https://www.openssl.org/news/vulnerabilities.html#CVE-2002-0659 +[CVE-2002-0657]: https://www.openssl.org/news/vulnerabilities.html#CVE-2002-0657 +[CVE-2002-0656]: https://www.openssl.org/news/vulnerabilities.html#CVE-2002-0656 +[CVE-2002-0655]: https://www.openssl.org/news/vulnerabilities.html#CVE-2002-0655 +[CMVP]: https://csrc.nist.gov/projects/cryptographic-module-validation-program +[ESV]: https://csrc.nist.gov/Projects/cryptographic-module-validation-program/entropy-validations [SP 800-132]: https://csrc.nist.gov/pubs/sp/800/132/final -[SP 800-185]: https://csrc.nist.gov/pubs/sp/800/185/final [SP 800-208]: https://csrc.nist.gov/pubs/sp/800/208/final -[tls-hybrid-sm2-mlkem]: https://datatracker.ietf.org/doc/html/draft-yang-tls-hybrid-sm2-mlkem-03#name-iana-considerations diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 8101e47114..09416095e6 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -27,28 +27,6 @@ communication before submitting many pull requests. In addition, contributors should personally evaluate potential patches generated by automated tools. -Provide a clear description of the issue or feature being addressed, -including any relevant implementation details and, for performance -improvements, benchmark results. - -Pull requests and commits should be self-contained, enabling readers to -understand what changed and why without needing to reference related -issues or having prior knowledge. Commit messages should include all -relevant details to help future contributors follow the git history, -with clear explanations of what is changing and why. Long descriptions -are encouraged if they aid understanding. Commit message titles (their -first line) should be kept to 50-70 characters if possible. - -Pull Requests (PR's) go through multiple phases before they are merged. In the -first phase the label 'approval: review pending' is added. Once you receive 2 or -more approvals from [Committers] the label is changed to 'approval: done' and -24 hours after this the label changes to 'approval: ready to merge'. At some time -after this your PR will be merged and the PR is closed. Reviewers may ask you to -make changes at any phase before the Pull Request is merged, and any changes -(that are not just a rebase) will require re-approval. - -[Committers]: https://openssl-library.org/about/committers/index.html - To make it easier to review and accept your pull request, please follow these guidelines: @@ -80,37 +58,7 @@ guidelines: git push -f [ []] ``` - 2. Similarly, if a non-trivial portion of a contribution was created - using an AI tool, you must declare which agent and model were used. - This is done by adding `Assisted-by: {agent}:{model}` below the commit - message: - - ``` - One-line summary of change with AI-generated portions - - Assisted-by: Claude:claude-sonnet-4-6 - ``` - - Multiple Assisted-by trailers can be included if multiple tools were used: - - ``` - Assisted-by: Claude:claude-sonnet-4-6 - Assisted-by: ChatGPT:gpt-4o - Assisted-by: GitHub Copilot:gpt-4.1 - ``` - - You will need to have signed a v1.1 or later CLA in order to - include AI-generated content in your contribution. CLAs signed - after June 2026 will have the requisite clauses. - - Consult the [OpenSSL AI Code and Documentation Contribution - Policy] if an AI model assisted with the creation of your - contribution. - - [OpenSSL AI Code and Documentation Contribution - Policy]: - - 3. All source files should start with the following text (with + 2. All source files should start with the following text (with appropriate comment characters at the start of each line and the year(s) updated): @@ -123,37 +71,33 @@ guidelines: https://www.openssl.org/source/license.html ``` - 4. Patches should be as current as possible; expect to have to rebase + 3. Patches should be as current as possible; expect to have to rebase often. We do not accept merge commits, you will have to remove them (usually by rebasing) before it will be acceptable. - 5. Code provided should follow our [coding style](STYLE.md) and - [documentation policy](DOCUMENTATION.md) and compile without warnings when - using a --strict-warnings configuration. - - Consistent formatting is enforced by using `clang-format` with configuration - stored in [.clang-format](.clang-format). OpenSSL uses `WebKit` style. - You can configure git pre-commit to automatically reformat your code with - [.pre-commit-config.yaml](.pre-commit-config.yaml) configuration. - There is also a [Perl tool](util/reformat-patches.sh) to help with - reformatting existing patches. - + 4. Code provided should follow our [coding style] and [documentation policy] + and compile without warnings. + There is a [Perl tool](util/check-format.pl) that helps + finding code formatting mistakes and other coding style nits. Where `gcc` or `clang` is available, you should use the `--strict-warnings` `Configure` option. OpenSSL compiles on many varied platforms: try to ensure you only use portable features. Clean builds via GitHub Actions are required. They are started automatically whenever a PR is created or updated by committers. - 6. When at all possible, code contributions should include tests. These can + [coding style]: https://openssl-library.org/policies/technical/coding-style/ + [documentation policy]: https://openssl-library.org/policies/technical/documentation-policy/ + + 5. When at all possible, code contributions should include tests. These can either be added to an existing test, or completely new. Please see [test/README.md](test/README.md) for information on the test framework. - 7. New features or changed functionality must include + 6. New features or changed functionality must include documentation. Please look at the `.pod` files in `doc/man[1357]` for examples of our style. Run `make doc-nits` to make sure that your documentation changes are clean. - 8. For user visible changes (API changes, behaviour changes, ...), + 7. For user visible changes (API changes, behaviour changes, ...), consider adding a note in [CHANGES.md](CHANGES.md). This could be a summarising description of the change, and could explain the grander details. @@ -164,37 +108,5 @@ guidelines: with a specific release without having to sift through the higher noise ratio in git-log. - 9. Guidelines on how to integrate error output of new crypto library modules + 8. Guidelines on how to integrate error output of new crypto library modules can be found in [crypto/err/README.md](crypto/err/README.md). - -10. Once your Pull Request gets to the stage of being reviewed fixup commits - should be used where possible. Fixup commits are squashed when the PR is - finally merged. Fixup commits are done in the following way: - - ``` - - # Add one or more updated files that needed changes - git add - - # Do a fixup commit - # is the id of a previous commit that you want to fix up. - git commit --fixup - - # Do a non forced push - git push - ``` - - To view commit-id's use: - - ``` - git log - ``` - -11. If a Pull Request addresses an [issue](https://github.com/openssl/openssl/issues/) - the commit should include the line: - - ``` - Fixes: LINK - ``` - - where LINK is the https link to the issue in github. diff --git a/Configurations/00-base-templates.conf b/Configurations/00-base-templates.conf index 09295bf846..86287c3a25 100644 --- a/Configurations/00-base-templates.conf +++ b/Configurations/00-base-templates.conf @@ -47,7 +47,7 @@ my %targets=( defines => sub { - my @defs = (); + my @defs = ( 'OPENSSL_BUILDING_OPENSSL' ); push @defs, "BROTLI" unless $disabled{brotli}; push @defs, "BROTLI_SHARED" unless $disabled{"brotli-dynamic"}; push @defs, "ZLIB" unless $disabled{zlib}; diff --git a/Configurations/10-main.conf b/Configurations/10-main.conf index 9c7261c3f2..92b3923e40 100644 --- a/Configurations/10-main.conf +++ b/Configurations/10-main.conf @@ -5,8 +5,7 @@ my $vc_win64a_info = {}; sub vc_win64a_info { unless (%$vc_win64a_info) { - # Minimum NASM version is 2.09 otherwise SHA3 might be miscompiled - if (`nasm -v 2>NUL` =~ /NASM version ([0-9]+)\.([0-9]+)/ && ($1 > 2 || ($1 == 2 && $2 >= 9))) { + if (`nasm -v 2>NUL` =~ /NASM version ([0-9]+\.[0-9]+)/ && $1 >= 2.0) { $vc_win64a_info = { AS => "nasm", ASFLAGS => "-g", asflags => "-Ox -f win64 -DNEAR", @@ -61,6 +60,70 @@ sub vc_win32_info { return $vc_win32_info; } +my $vc_wince_info = {}; +sub vc_wince_info { + unless (%$vc_wince_info) { + # sanity check + $die->('%OSVERSION% is not defined') if (!defined(env('OSVERSION'))); + $die->('%PLATFORM% is not defined') if (!defined(env('PLATFORM'))); + $die->('%TARGETCPU% is not defined') if (!defined(env('TARGETCPU'))); + + # + # Idea behind this is to mimic flags set by eVC++ IDE... + # + my $wcevers = env('OSVERSION'); # WCENNN + my $wcevernum; + my $wceverdotnum; + if ($wcevers =~ /^WCE([1-9])([0-9]{2})$/) { + $wcevernum = "$1$2"; + $wceverdotnum = "$1.$2"; + } else { + $die->('%OSVERSION% value is insane'); + $wcevernum = "{unknown}"; + $wceverdotnum = "{unknown}"; + } + my $wcecdefs = "-D_WIN32_WCE=$wcevernum -DUNDER_CE=$wcevernum"; # -D_WIN32_WCE=NNN + my $wcelflag = "/subsystem:windowsce,$wceverdotnum"; # ...,N.NN + + my $wceplatf = env('PLATFORM'); + + $wceplatf =~ tr/a-z0-9 /A-Z0-9_/; + $wcecdefs .= " -DWCE_PLATFORM_$wceplatf"; + + my $wcetgt = env('TARGETCPU'); # just shorter name... + SWITCH: for($wcetgt) { + /^X86/ && do { $wcecdefs.=" -Dx86 -D_X86_ -D_i386_ -Di_386_"; + $wcelflag.=" /machine:X86"; last; }; + /^ARMV4[IT]/ && do { $wcecdefs.=" -DARM -D_ARM_ -D$wcetgt"; + $wcecdefs.=" -DTHUMB -D_THUMB_" if($wcetgt=~/T$/); + $wcecdefs.=" -QRarch4T -QRinterwork-return"; + $wcelflag.=" /machine:THUMB"; last; }; + /^ARM/ && do { $wcecdefs.=" -DARM -D_ARM_ -D$wcetgt"; + $wcelflag.=" /machine:ARM"; last; }; + /^MIPSIV/ && do { $wcecdefs.=" -DMIPS -D_MIPS_ -DR4000 -D$wcetgt"; + $wcecdefs.=" -D_MIPS64 -QMmips4 -QMn32"; + $wcelflag.=" /machine:MIPSFPU"; last; }; + /^MIPS16/ && do { $wcecdefs.=" -DMIPS -D_MIPS_ -DR4000 -D$wcetgt"; + $wcecdefs.=" -DMIPSII -QMmips16"; + $wcelflag.=" /machine:MIPS16"; last; }; + /^MIPSII/ && do { $wcecdefs.=" -DMIPS -D_MIPS_ -DR4000 -D$wcetgt"; + $wcecdefs.=" -QMmips2"; + $wcelflag.=" /machine:MIPS"; last; }; + /^R4[0-9]{3}/ && do { $wcecdefs.=" -DMIPS -D_MIPS_ -DR4000"; + $wcelflag.=" /machine:MIPS"; last; }; + /^SH[0-9]/ && do { $wcecdefs.=" -D$wcetgt -D_${wcetgt}_ -DSHx"; + $wcecdefs.=" -Qsh4" if ($wcetgt =~ /^SH4/); + $wcelflag.=" /machine:$wcetgt"; last; }; + { $wcecdefs.=" -D$wcetgt -D_${wcetgt}_"; + $wcelflag.=" /machine:$wcetgt"; last; }; + } + + $vc_wince_info = { cppflags => $wcecdefs, + lflags => $wcelflag }; + } + return $vc_wince_info; +} + # Helper functions for the VMS configs my $vms_info = {}; sub vms_info { @@ -623,6 +686,7 @@ my %targets = ( release => "-O3"), cflags => threads("-pthread"), cxxflags => combine("-std=c++11", threads("-pthread")), + lib_cppflags => "-DOPENSSL_USE_NODELETE", ex_libs => add("-ldl", threads("-pthread")), bn_ops => "BN_LLONG RC4_CHAR", thread_scheme => "pthreads", @@ -906,6 +970,7 @@ my %targets = ( perlasm_scheme => 'void', }, "linux64-sparcv9" => { + # GCC 3.1 is a requirement inherit_from => [ "linux-generic64" ], cflags => add("-m64 -mcpu=ultrasparc"), cxxflags => add("-m64 -mcpu=ultrasparc"), @@ -1434,7 +1499,7 @@ my %targets = ( #### Visual C targets # -# Win64 target, WIN64A denotes AMD64 +# Win64 targets, WIN64I denotes IA-64/Itanium and WIN64A - AMD64 # # Note about /wd4090, disable warning C4090. This warning returns false # positives in some situations. Disabling it altogether masks both @@ -1476,10 +1541,10 @@ my %targets = ( "UNICODE", "_UNICODE", "_CRT_SECURE_NO_DEPRECATE", "_WINSOCK_DEPRECATED_NO_WARNINGS"), - lib_cflags => add("/Z7"), + lib_cflags => add("/Zi /Fdossl_static.pdb"), lib_defines => add("L_ENDIAN"), - dso_cflags => "/Z7", - bin_cflags => "/Z7", + dso_cflags => "/Zi /Fddso.pdb", + bin_cflags => "/Zi /Fdapp.pdb", # def_flag made to empty string so a .def file gets generated shared_defflag => '', shared_ldflag => "/dll", @@ -1501,11 +1566,11 @@ my %targets = ( cflags => add(picker(default => '/Gs0 /GF /Gy', debug => sub { - ($disabled{shared} ? "" : ($disabled{"static-vcruntime"} ? "/MDd" : ($disabled{threads} ? "" : "/MTd"))); + ($disabled{shared} ? "" : "/MDd"); }, release => sub { - ($disabled{shared} ? "" : ($disabled{"static-vcruntime"} ? "/MD": ($disabled{threads} ? "" : "/MT"))); + ($disabled{shared} ? "" : "/MD"); })), defines => add(picker(default => [], # works as type cast debug => [ "DEBUG", "_DEBUG" ])), @@ -1542,6 +1607,17 @@ my %targets = ( }), bn_ops => add("SIXTY_FOUR_BIT"), }, + "VC-WIN64I" => { + inherit_from => [ "VC-WIN64-common" ], + AS => "ias", + ASFLAGS => "-d debug", + asoutflag => "-o ", + sys_id => "WIN64I", + uplink_arch => 'ia64', + asm_arch => 'ia64', + perlasm_scheme => "ias", + multilib => "-ia64", + }, "VC-WIN64A" => { inherit_from => [ "VC-WIN64-common" ], AS => sub { vc_win64a_info()->{AS} }, @@ -1569,6 +1645,53 @@ my %targets = ( # some installation path heuristics in windows-makefile.tmpl... build_scheme => add("VC-WOW", { separator => undef }), }, + "VC-CE" => { + inherit_from => [ "VC-common" ], + CFLAGS => add(picker(debug => "/Od", + release => "/O1i")), + CPPDEFINES => picker(debug => [ "DEBUG", "_DEBUG" ]), + LDFLAGS => add("/nologo /opt:ref"), + cflags => + combine('/GF /Gy', + sub { vc_wince_info()->{cflags}; }, + sub { `cl 2>&1` =~ /Version ([0-9]+)\./ && $1>=14 + ? ($disabled{shared} ? " /MT" : " /MD") + : " /MC"; }), + cppflags => sub { vc_wince_info()->{cppflags}; }, + lib_defines => add("NO_CHMOD", "OPENSSL_SMALL_FOOTPRINT"), + lib_cppflags => sub { vc_wince_info()->{cppflags}; }, + includes => + add(combine(sub { defined(env('WCECOMPAT')) + ? '$(WCECOMPAT)/include' : (); }, + sub { defined(env('PORTSDK_LIBPATH')) + ? '$(PORTSDK_LIBPATH)/../../include' + : (); })), + lflags => add(combine(sub { vc_wince_info()->{lflags}; }, + sub { defined(env('PORTSDK_LIBPATH')) + ? "/entry:mainCRTstartup" : (); })), + sys_id => "WINCE", + bn_ops => add("BN_LLONG"), + ex_libs => add(sub { + my @ex_libs = (); + push @ex_libs, 'ws2.lib' unless $disabled{sock}; + push @ex_libs, 'crypt32.lib'; + if (defined(env('WCECOMPAT'))) { + my $x = '$(WCECOMPAT)/lib'; + if (-f "$x/env('TARGETCPU')/wcecompatex.lib") { + $x .= '/$(TARGETCPU)/wcecompatex.lib'; + } else { + $x .= '/wcecompatex.lib'; + } + push @ex_libs, $x; + } + push @ex_libs, '$(PORTSDK_LIBPATH)/portlib.lib' + if (defined(env('PORTSDK_LIBPATH'))); + push @ex_libs, '/nodefaultlib coredll.lib corelibc.lib' + if (env('TARGETCPU') =~ /^X86|^ARMV4[IT]/); + return join(" ", @ex_libs); + }), + }, + #### MinGW "mingw-common" => { inherit_from => [ 'BASE_unix' ], @@ -1580,7 +1703,7 @@ my %targets = ( cppflags => combine("-DUNICODE -D_UNICODE -DWIN32_LEAN_AND_MEAN", threads("-D_MT")), lib_cppflags => "-DL_ENDIAN", - ex_libs => add("-lws2_32 -lgdi32 -lcrypt32 -lbcrypt"), + ex_libs => add("-lws2_32 -lgdi32 -lcrypt32"), thread_scheme => "winthreads", dso_scheme => "win32", shared_target => "mingw-shared", @@ -1733,6 +1856,45 @@ my %targets = ( shared_cflag => "-fPIC", shared_extension => ".\$(SHLIB_VERSION_NUMBER).dylib", }, + # Option "freeze" such as -std=gnu9x can't negatively interfere + # with future defaults for below two targets, because MacOS X + # for PPC has no future, it was discontinued by vendor in 2009. + "darwin8-ppc-cc" => { + inherit_from => [ "darwin-ppc" ], + disable => [ "async" ] + }, + "darwin-ppc-cc" => { inherit_from => [ "darwin-ppc" ] }, # Historic alias + "darwin-ppc" => { + inherit_from => [ "darwin-common" ], + cflags => add("-arch ppc -std=gnu9x -Wa,-force_cpusubtype_ALL"), + lib_cppflags => add("-DB_ENDIAN"), + shared_cflag => add("-fno-common"), + asm_arch => 'ppc32', + perlasm_scheme => "osx32", + }, + "darwin8-ppc64-cc" => { + inherit_from => [ "darwin64-ppc" ], + disable => [ "async" ] + }, + "darwin64-ppc-cc" => { inherit_from => [ "darwin64-ppc" ] }, # Historic alias + "darwin64-ppc" => { + inherit_from => [ "darwin-common" ], + cflags => add("-arch ppc64 -std=gnu9x"), + lib_cppflags => add("-DB_ENDIAN"), + bn_ops => "SIXTY_FOUR_BIT_LONG RC4_CHAR", + asm_arch => 'ppc64', + perlasm_scheme => "osx64", + }, + "darwin-i386-cc" => { inherit_from => [ "darwin-i386" ] }, # Historic alias + "darwin-i386" => { + inherit_from => [ "darwin-common" ], + CFLAGS => add(picker(release => "-fomit-frame-pointer")), + cflags => add("-arch i386"), + lib_cppflags => add("-DL_ENDIAN"), + bn_ops => "BN_LLONG RC4_INT", + asm_arch => 'x86', + perlasm_scheme => "macosx", + }, "darwin64-x86_64-cc" => { inherit_from => [ "darwin64-x86_64" ] }, # Historic alias "darwin64-x86_64" => { inherit_from => [ "darwin-common" ], @@ -1850,7 +2012,8 @@ my %targets = ( ? "/WARNINGS=DISABLE=(".join(",",@warnings).")" : (); }), cflag_incfirst => '/FIRST_INCLUDE=', lib_defines => - add("_XOPEN_SOURCE", "_XOPEN_SOURCE_EXTENDED=1", + add("OPENSSL_USE_NODELETE", + "_XOPEN_SOURCE", "_XOPEN_SOURCE_EXTENDED=1", sub { return vms_info()->{def_zlib} ? "LIBZ=\"\"\"".vms_info()->{def_zlib}."\"\"\"" : (); diff --git a/Configurations/50-nonstop.conf b/Configurations/50-nonstop.conf index 633d5ed6a0..24ab6009fc 100644 --- a/Configurations/50-nonstop.conf +++ b/Configurations/50-nonstop.conf @@ -22,6 +22,7 @@ ex_libs => add('-lrld'), enable => ['egd'], # Not currently inherited + disable => ['atexit'], dso_scheme => 'DLFCN', sys_id => 'TANDEM', }, @@ -190,7 +191,7 @@ 'nonstop-archenv-x86_64-oss', 'nonstop-ilp32', 'nonstop-efloat-x86_64' ], - disable => ['threads'], + disable => ['threads','atexit'], }, 'nonstop-nsx_put' => { inherit_from => [ 'nonstop-common', @@ -200,6 +201,7 @@ 'nonstop-model-put' ], multilib => '-put', multibin => '-put', + disable => ['atexit'], }, 'nonstop-nsx_64' => { inherit_from => [ 'nonstop-common', @@ -208,7 +210,7 @@ 'nonstop-efloat-x86_64' ], multilib => '64', multibin => '64', - disable => ['threads'], + disable => ['threads','atexit'], }, 'nonstop-nsx_64_put' => { inherit_from => [ 'nonstop-common', @@ -218,6 +220,7 @@ 'nonstop-model-put' ], multilib => '64-put', multibin => '64-put', + disable => ['atexit'], }, 'nonstop-nsx_64_klt' => { inherit_from => [ 'nonstop-common', @@ -227,18 +230,19 @@ 'nonstop-model-klt' ], multilib => '64-klt', multibin => '64-klt', + disable => ['atexit'], }, 'nonstop-nsx_g' => { inherit_from => [ 'nonstop-common', 'nonstop-archenv-x86_64-guardian', 'nonstop-ilp32', 'nonstop-nfloat-x86_64' ], - disable => ['threads'], + disable => ['threads','atexit'], }, 'nonstop-nsx_g_tandem' => { inherit_from => [ 'nonstop-common', 'nonstop-archenv-x86_64-guardian', 'nonstop-ilp32', 'nonstop-tfloat-x86_64' ], - disable => ['threads'], + disable => ['threads','atexit'], }, 'nonstop-nsv' => { inherit_from => [ 'nonstop-nsx' ], @@ -248,7 +252,7 @@ 'nonstop-archenv-itanium-oss', 'nonstop-ilp32', 'nonstop-efloat-itanium' ], - disable => ['threads'], + disable => ['threads','atexit'], }, 'nonstop-nse_put' => { inherit_from => [ 'nonstop-common', @@ -258,6 +262,7 @@ 'nonstop-model-put' ], multilib => '-put', multibin => '-put', + disable => ['atexit'], }, 'nonstop-nse_64' => { inherit_from => [ 'nonstop-common', @@ -266,7 +271,7 @@ 'nonstop-efloat-itanium' ], multilib => '64', multibin => '64', - disable => ['threads'], + disable => ['threads','atexit'], }, 'nonstop-nse_64_put' => { inherit_from => [ 'nonstop-common', @@ -276,4 +281,5 @@ 'nonstop-model-put' ], multilib => '64-put', multibin => '64-put', + disable => ['atexit'], }, diff --git a/Configurations/README.md b/Configurations/README.md index b07e758296..83bcc96062 100644 --- a/Configurations/README.md +++ b/Configurations/README.md @@ -502,7 +502,7 @@ The build-file template is processed with the perl module Text::Template, using `{-` and `-}` as delimiters that enclose the perl code fragments that generate configuration-dependent content. Those perl fragments have access to all the hash variables from -configdata.pm. +configdata.pem. The build-file template is expected to define at least the following perl functions in a perl code fragment enclosed with `{-` and `-}`. diff --git a/Configurations/unix-Makefile.tmpl b/Configurations/unix-Makefile.tmpl index 3f9d04b6d0..b6a7810766 100644 --- a/Configurations/unix-Makefile.tmpl +++ b/Configurations/unix-Makefile.tmpl @@ -11,7 +11,6 @@ our $makedepcmd = platform->makedepcmd(); sub windowsdll { $config{target} =~ /^(?:Cygwin|mingw)/ } - sub run_on_windows { $^O =~ /^(?:cygwin|msys|MSWin32)/ } # Shared AIX support is special. We put libcrypto[64].so.ver into # libcrypto.a and use libcrypto_a.a as static one, unless using @@ -73,7 +72,6 @@ OPTIONS={- $config{options} -} CONFIGURE_ARGS=({- join(", ",quotify_l(@{$config{perlargv}})) -}) SRCDIR={- $config{sourcedir} -} BLDDIR={- $config{builddir} -} -RESULT_D=$(BLDDIR)/test-runs FIPSKEY={- $config{FIPSKEY} -} VERSION={- "$config{full_version}" -} @@ -504,9 +502,6 @@ BIN_LDFLAGS={- join(' ', $target{bin_lflags} || (), '$(CNF_LDFLAGS)', '$(LDFLAGS)') -} BIN_EX_LIBS=$(CNF_EX_LIBS) $(EX_LIBS) -CMOCKA_LIBS={- $config{cmocka_libs} // '' -} -DETOURS_LIBS={- $config{detours_libs} // '' -} - # CPPFLAGS_Q is used for one thing only: to build up buildinf.h CPPFLAGS_Q={- $cppflags1 =~ s|([\\"])|\\$1|g; $cppflags2 =~ s|([\\"])|\\$1|g; @@ -604,12 +599,6 @@ list-tests: ## List available tests that can be invoked via "make test TESTS=depext() -}' \! -name '.*' \! -type d -exec $(RM) {} \; + -find . -name '*{- platform->objext() -}' \! -name '.*' \! -type d -exec $(RM) {} \; $(RM) core $(RM) tags TAGS doc-nits md-nits - $(RM) -r $(RESULT_D) + $(RM) -r test/test-runs $(RM) providers/fips*.new - # Remove the generated dependency files, object files, and symlinks - # in a single pass, avoid descending into submodules. - -find . \( -path './cloudflare-quiche' \ - -o -path './fuzz/corpora' \ - -o -path './gost-engine' \ - -o -path './krb5' \ - -o -path './oqs-provider' \ - -o -path './pkcs11-provider' \ - -o -path './pyca-cryptography' \ - -o -path './python-ecdsa' \ - -o -path './tlsfuzzer' \ - -o -path './tlslite-ng' \ - -o -path './wycheproof' \) \ - -prune \ - -o \! -type d \ - \( -name '*{- platform->depext() -}' \ - -o -name '*{- platform->objext() -}' \ - -o -type l \) \ - \! -name '.*' \ - -exec $(RM) '{}' + + -find . -type l \! -name '.*' \! -wholename './pkcs11-provider/*' -exec $(RM) {} \; -distclean: clean cov-clean ## Clean and remove the configuration +distclean: clean ## Clean and remove the configuration $(RM) include/openssl/configuration.h $(RM) configdata.pm $(RM) Makefile @@ -907,7 +879,6 @@ uninstall_dev: uninstall_runtime_libs done -$(RMDIR) "$(DESTDIR)$(PKGCONFIGDIR)" -$(RMDIR) "$(DESTDIR)$(CMAKECONFIGDIR)" - -$(RMDIR) "$(DESTDIR)$(libdir)/cmake" -$(RMDIR) "$(DESTDIR)$(libdir)" _install_modules_deps: install_runtime_libs build_modules @@ -1209,18 +1180,10 @@ lint: ## Evaluate C code via "splint" echo splint -DLINT -posixlib -preproc -D__gnuc_va_list=void \ -I. -Iinclude -Iapps/include $(CRYPTOHEADERS) $(SSLHEADERS) $(SRCS) ) -CLANG_FORMAT_DIFF = clang-format-diff - -.PHONY: check-format check-clang-format-diff-cmd -check-clang-format-diff-cmd: - @if ! command -v "$(CLANG_FORMAT_DIFF)" >/dev/null; then \ - echo "Unable to find ${CLANG_FORMAT_DIFF}";\ - echo "Please set the CLANG_FORMAT_DIFF variable to your clang-format-diff command";\ - exit 1;\ - fi - -check-format: check-clang-format-diff-cmd ## Evaluate C code according to OpenSSL coding standards - ( cd $(SRCDIR); git diff -U0 --no-prefix --no-color | $(CLANG_FORMAT_DIFF) ) +.PHONY: check-format +check-format: ## Evaluate C code according to OpenSSL coding standards + ( cd $(SRCDIR); $(PERL) util/check-format.pl \ + $(SRCS) \$(CRYPTOHEADERS) $(SSLHEADERS) ) generate_apps: ( cd $(SRCDIR); $(PERL) VMS/VMSify-conf.pl \ @@ -1317,14 +1280,11 @@ providers/fips.module.sources.new: configdata.pm for x in crypto/bn/asm/*.pl crypto/bn/asm/*.S \ crypto/aes/asm/*.pl crypto/aes/asm/*.S \ crypto/ec/asm/*.pl \ - crypto/ml_dsa/asm/*.pl \ - crypto/ml_kem/asm/*.pl \ crypto/modes/asm/*.pl \ crypto/sha/asm/*.pl \ - crypto/slh_dsa/asm/*.pl \ crypto/*cpuid.pl crypto/*cpuid.S \ crypto/*cap.c; do \ - test -e "$$x" && echo "$$x"; \ + echo "$$x"; \ done \ ) | grep -v sm2p256 | sort | uniq > providers/fips.module.sources.new rm -rf sources-tmp @@ -1347,8 +1307,7 @@ errors: include/openssl/dtls1.h include/openssl/srtp.h include/openssl/quic.h - include/openssl/sslerr_legacy.h - include/openssl/ech.h); + include/openssl/sslerr_legacy.h ); my @cryptoheaders_tmpl = qw( include/internal/dso.h include/internal/o_dir.h @@ -1583,24 +1542,12 @@ EOF my $section = $1; my $name = uc basename($args{src}, ".$section"); my $pod = $gen0; - - if ($config{manpage_format} eq "mdoc") { - return <<"EOF"; -$args{src}: $pod - pod2mdoc -n $name -s $section\$(MANSUFFIX) \\ - -d \$(RELEASE_DATE) \\ - $pod >\$\@ -EOF - } elsif ($config{manpage_format} eq "roff") { - return <<"EOF"; + return <<"EOF"; $args{src}: $pod pod2man --name=$name --section=$section\$(MANSUFFIX) --center=OpenSSL \\ --date=\$(RELEASE_DATE) --release=\$(VERSION) \\ $pod >\$\@ EOF - } else { - die "Unhandled manpage format: $config{manpage_format}"; - } } elsif (platform->isdef($args{src})) { # # Linker script-ish generator @@ -1911,27 +1858,13 @@ $import: $full EOF } } - if (!run_on_windows()) { - $recipe .= <<"EOF"; + $recipe .= <<"EOF"; $full: $fulldeps \$(CC) \$(LIB_CFLAGS) $linkflags\$(LIB_LDFLAGS)$shared_soname$shared_imp \\ -o $full$shared_def \\ $fullobjs \\ $linklibs \$(LIB_EX_LIBS) EOF - } else { - $recipe .= <<"EOF"; -$full: $fulldeps - \$(file >\$@.lst, \\ - $fullobjs \\ - ) - \$(CC) \$(LIB_CFLAGS) $linkflags\$(LIB_LDFLAGS)$shared_soname$shared_imp \\ - -o $full$shared_def \\ - @\$@.lst \\ - $linklibs \$(LIB_EX_LIBS) - rm -f \$@.lst -EOF - } if (windowsdll()) { $recipe .= <<"EOF"; rm -f apps/$full @@ -2036,15 +1969,6 @@ EOF push @linkdirs, $d unless grep { $d eq $_ } @linkdirs; } } - my $wrapflags = ''; - if (defined $unified_info{wraps}->{$args{bin}}) { - $wrapflags = ' ' . join(' ', - map { "-Wl,--wrap=$_" } - @{$unified_info{wraps}->{$args{bin}}}); - } - my $utlibs = $unified_info{unit_test_libs}->{$args{bin}}; - $utlibs = $utlibs ne '' ? ' ' . $utlibs : '' if defined $utlibs; - $utlibs //= ''; my $linkflags = join("", map { $_." " } @linkdirs); my $linklibs = join("", map { $_." " } @linklibs); my $cmd = '$(CC)'; @@ -2062,10 +1986,10 @@ EOF return <<"EOF"; $bin: $deps rm -f $bin - \$\${LDCMD:-$cmd} $cmdflags $linkflags\$(BIN_LDFLAGS)$wrapflags \\ + \$\${LDCMD:-$cmd} $cmdflags $linkflags\$(BIN_LDFLAGS) \\ -o $bin \\ $objs \\ - $linklibs\$(BIN_EX_LIBS)$utlibs + $linklibs\$(BIN_EX_LIBS) EOF } sub in2script { diff --git a/Configurations/windows-makefile.tmpl b/Configurations/windows-makefile.tmpl index a7f2b6652b..498d33369c 100644 --- a/Configurations/windows-makefile.tmpl +++ b/Configurations/windows-makefile.tmpl @@ -38,7 +38,6 @@ PLATFORM={- $config{target} -} SRCDIR={- $config{sourcedir} -} BLDDIR={- $config{builddir} -} -RESULT_D=$(BLDDIR)\test-runs FIPSKEY={- $config{FIPSKEY} -} VERSION={- "$config{full_version}" -} @@ -209,7 +208,7 @@ OPENSSLDIR_dir={- canonpath($openssldir_dir) -} LIBDIR={- our $libdir = $config{libdir} || "lib"; file_name_is_absolute($libdir) ? "" : $libdir -} MODULESDIR_dev={- use File::Spec::Functions qw(:DEFAULT splitpath catpath); - our $modulesprefix = file_name_is_absolute($libdir) ? $libdir : catdir($prefix,$libdir); + our $modulesprefix = catdir($prefix,$libdir); our ($modulesprefix_dev, $modulesprefix_dir, $modulesprefix_file) = splitpath($modulesprefix, 1); @@ -380,9 +379,6 @@ BIN_LDFLAGS={- join(' ', $target{bin_lflags} || (), '$(CNF_LDFLAGS)', '$(LDFLAGS)') -} BIN_EX_LIBS=$(CNF_EX_LIBS) $(EX_LIBS) -CMOCKA_LIBS={- $config{cmocka_libs} // '' -} -DETOURS_LIBS={- $config{detours_libs} // '' -} - # CPPFLAGS_Q is used for one thing only: to build up buildinf.h CPPFLAGS_Q={- $cppflags1 =~ s|([\\"])|\\$1|g; $cppflags2 =~ s|([\\"])|\\$1|g; @@ -453,22 +449,22 @@ uninstall: {- "uninstall_docs" if !$disabled{docs}; -} uninstall_sw {- $disabled libclean: "$(PERL)" -e "map { m/(.*)\.dll$$/; unlink glob """{.,apps,test,fuzz}/$$1.*"""; } @ARGV" $(SHLIBS) - -del /Q /F $(LIBS) libcrypto.* libssl.* + -del /Q /F $(LIBS) libcrypto.* libssl.* ossl_static.pdb clean: libclean - {- join("\n\t", map { "-if exist $_ del /Q /F $_" } @HTMLDOCS1) || "\@rem" -} - {- join("\n\t", map { "-if exist $_ del /Q /F $_" } @HTMLDOCS3) || "\@rem" -} - {- join("\n\t", map { "-if exist $_ del /Q /F $_" } @HTMLDOCS5) || "\@rem" -} - {- join("\n\t", map { "-if exist $_ del /Q /F $_" } @HTMLDOCS7) || "\@rem" -} - {- join("\n\t", map { "-if exist $_ del /Q /F $_" } @PROGRAMS) || "\@rem" -} - {- join("\n\t", map { "-if exist $_ del /Q /F $_" } @MODULES) || "\@rem" -} - {- join("\n\t", map { "-if exist $_ del /Q /F $_" } @SCRIPTS) || "\@rem" -} - {- join("\n\t", map { "-if exist $_ del /Q /F $_" } @GENERATED_MANDATORY) || "\@rem" -} - {- join("\n\t", map { "-if exist $_ del /Q /F $_" } @GENERATED) || "\@rem" -} + {- join("\n\t", map { "-del /Q /F $_" } @HTMLDOCS1) || "\@rem" -} + {- join("\n\t", map { "-del /Q /F $_" } @HTMLDOCS3) || "\@rem" -} + {- join("\n\t", map { "-del /Q /F $_" } @HTMLDOCS5) || "\@rem" -} + {- join("\n\t", map { "-del /Q /F $_" } @HTMLDOCS7) || "\@rem" -} + {- join("\n\t", map { "-del /Q /F $_" } @PROGRAMS) || "\@rem" -} + {- join("\n\t", map { "-del /Q /F $_" } @MODULES) || "\@rem" -} + {- join("\n\t", map { "-del /Q /F $_" } @SCRIPTS) || "\@rem" -} + {- join("\n\t", map { "-del /Q /F $_" } @GENERATED_MANDATORY) || "\@rem" -} + {- join("\n\t", map { "-del /Q /F $_" } @GENERATED) || "\@rem" -} -del /Q /S /F *.d *.obj *.pdb *.ilk *.manifest -del /Q /S /F apps\*.lib apps\*.rc apps\*.res apps\*.exp -del /Q /S /F test\*.exp - -@if exist "$(RESULT_D)" rd /Q /S "$(RESULT_D)" + -rd /Q /S test\test-runs distclean: clean -del /Q /F include\openssl\configuration.h @@ -548,6 +544,8 @@ install_dev: install_runtime_libs "$(INSTALLTOP)\include\openssl" @"$(PERL)" "$(SRCDIR)\util\mkdir-p.pl" "$(libdir)" @"$(PERL)" "$(SRCDIR)\util\copy.pl" $(INSTALL_LIBS) "$(libdir)" + @if "$(SHLIBS)"=="" \ + "$(PERL)" "$(SRCDIR)\util\copy.pl" ossl_static.pdb "$(libdir)" @"$(PERL)" "$(SRCDIR)\util\mkdir-p.pl" "$(CMAKECONFIGDIR)" @"$(PERL)" "$(SRCDIR)\util\copy.pl" $(INSTALL_EXPORTERS_CMAKE) "$(CMAKECONFIGDIR)" @@ -586,10 +584,10 @@ install_programs: install_runtime_libs build_inst_programs @if not "$(INSTALL_PROGRAMS)"=="" \ "$(PERL)" "$(SRCDIR)\util\copy.pl" $(INSTALL_PROGRAMS) \ "$(INSTALLTOP)\bin" - @if not "$(INSTALL_PROGRAMPDBS)"=="" \ + @if not "$(INSTALL_PROGRAMS)"=="" \ "$(PERL)" "$(SRCDIR)\util\copy.pl" $(INSTALL_PROGRAMPDBS) \ "$(INSTALLTOP)\bin" - @if not "$(BIN_SCRIPTS)"=="" \ + @if not "$(INSTALL_PROGRAMS)"=="" \ "$(PERL)" "$(SRCDIR)\util\copy.pl" $(BIN_SCRIPTS) \ "$(INSTALLTOP)\bin" @@ -1004,14 +1002,11 @@ EOF my $ress = join($target{ld_resp_delim}, @ress); my $linklibs = join("", map { "$_$target{ld_resp_delim}" } @deps); my $deps = join(" ", @objs, @ress, @deps); - my $utlibs = $unified_info{unit_test_libs}->{$args{bin}}; - $utlibs = (defined $utlibs && $utlibs ne '') - ? "$utlibs$target{ld_resp_delim}" : ''; return <<"EOF"; $bin: $deps IF EXIST $bin.manifest DEL /F /Q $bin.manifest \$(LD) \$(LDFLAGS) \$(BIN_LDFLAGS) @<< -$objs$target{ld_resp_delim}\$(LDOUTFLAG)$bin$target{ldpostoutflag}$target{ld_resp_delim}$utlibs$linklibs\$(BIN_EX_LIBS)$target{ldresflag}$target{ldresflag}$ress +$objs$target{ld_resp_delim}\$(LDOUTFLAG)$bin$target{ldpostoutflag}$target{ld_resp_delim}$linklibs\$(BIN_EX_LIBS)$target{ldresflag}$target{ldresflag}$ress << IF EXIST $bin.manifest \\ \$(MT) \$(MTFLAGS) \$(MTINFLAG)$bin.manifest \$(MTOUTFLAG)$bin diff --git a/Configure b/Configure index 75f1f6b67b..a73f464fd7 100755 --- a/Configure +++ b/Configure @@ -1,6 +1,6 @@ #! /usr/bin/env perl # -*- mode: perl; -*- -# Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -27,7 +27,7 @@ use OpenSSL::config; my $orig_death_handler = $SIG{__DIE__}; $SIG{__DIE__} = \&death_handler; -my $usage="Usage: Configure [no- ...] [enable- ...] [-Dxxx] [-lxxx] [-Lxxx] [-fxxx] [-Kxxx] [no-hw-xxx|no-hw] [[no-]threads] [[no-]thread-pool] [[no-]default-thread-pool] [[no-]shared] [[no-]zlib|zlib-dynamic] [no-asm] [no-egd] [sctp] [386] [--prefix=DIR] [--openssldir=OPENSSLDIR] [--with-xxx[=vvv]] [--config=FILE] [--manpage-format={roff,mdoc}] [--help] os/compiler[:flags]\n"; +my $usage="Usage: Configure [no- ...] [enable- ...] [-Dxxx] [-lxxx] [-Lxxx] [-fxxx] [-Kxxx] [no-hw-xxx|no-hw] [[no-]threads] [[no-]thread-pool] [[no-]default-thread-pool] [[no-]shared] [[no-]zlib|zlib-dynamic] [no-asm] [no-egd] [sctp] [386] [--prefix=DIR] [--openssldir=OPENSSLDIR] [--with-xxx[=vvv]] [--config=FILE] [--help] os/compiler[:flags]\n"; my $banner = <<"EOF"; @@ -171,17 +171,16 @@ my @gcc_devteam_warn = qw( -Wextra -Wno-unused-parameter -Wno-missing-field-initializers + -Wno-unterminated-string-initialization -Wswitch -Wsign-compare -Wshadow -Wformat - -Wtype-limits + -Wno-type-limits -Wundef -Werror -Wmissing-prototypes -Wstrict-prototypes - -Wpointer-arith - -Wfloat-conversion ); # These are used in addition to $gcc_devteam_warn when the compiler is clang. @@ -222,9 +221,16 @@ our $BSDthreads="-pthread -D_THREAD_SAFE -D_REENTRANT"; # # API compatibility name to version number mapping. # - -# This table expresses when API additions or changes can occur my $apitable = { + # This table expresses when API additions or changes can occur. + # The numbering used changes from 3.0 and on because we updated + # (solidified) our version numbering scheme at that point. + + # From 3.0 and on, we internalise the given version number in decimal + # as MAJOR * 10000 + MINOR * 100 + 0 + "3.0.0" => 30000, + "3.0" => 30000, + # Note that before 3.0, we didn't have the same version number scheme. # Still, the numbering we use here covers what we need. "1.1.1" => 10101, @@ -235,19 +241,6 @@ my $apitable = { "0.9.8" => 908, }; -# From 3.0 and on, we internalise the given version number in decimal -# as MAJOR * 10000 + MINOR * 100 + 0 -my @post30_versions = ([3, 0], [3, 1], [3, 2], [3, 3], [3, 4], [3, 5], [3, 6], - [4, 0], [4, 1], - ); - -# The numbering used changes from 3.0 and on because we updated -# (solidified) our version numbering scheme at that point. -foreach (@post30_versions) { - my ($x, $y) = @{$_}; - $apitable->{"$x.$y.0"} = $apitable->{"$x.$y"} = $x * 10000 + $y * 100; -} - # For OpenSSL::config::get_platform my %guess_opts = (); @@ -295,7 +288,6 @@ my $dofile = abs2rel(catfile($srcdir, "util/dofile.pl")); my $local_config_envname = 'OPENSSL_LOCAL_CONFIG_DIR'; -$config{manpage_format} = "roff"; $config{sourcedir} = abs2rel($srcdir, $blddir); $config{builddir} = abs2rel($blddir, $blddir); # echo -n 'holy hand grenade of antioch' | openssl sha256 @@ -421,120 +413,61 @@ my $auto_threads=1; # enable threads automatically? true by default my $default_ranlib; # Known TLS and DTLS protocols -my @tls = qw(tls1 tls1_1 tls1_2 tls1_3); +my @tls = qw(ssl3 tls1 tls1_1 tls1_2 tls1_3); my @dtls = qw(dtls1 dtls1_2); # Explicitly known options that are possible to disable. They can # be regexps, and will be used like this: /^no-${option}$/ # For developers: keep it sorted alphabetically -my @disablables_protocols = ( - "cmp", - "dtls", - "http", - "ocsp", - "ktls", - "tls", - "tls-deprecated-ec", - "quic", - "sctp", - "srp", - "srtp" -); - -foreach my $proto ((@tls, @dtls)) - { - push(@disablables_protocols, $proto); - push(@disablables_protocols, "$proto-method") unless $proto eq "tls1_3"; - } - -my @disablables_algorithms = ( - "argon2", - "aria", - "bf", - "blake2", - "brotli", - "camellia", - "cast", - "chacha", - "cmac", - "cms", - "comp", - "des", - "dh", - "dsa", - "hmac-drbg-kdf", - "ec", - "ec2m", - "ecx", - "kbkdf", - "krb5kdf", - "gost", - "idea", - "ikev2kdf", - "md2", - "md4", - "md5", - "mdc2", - "ml-dsa", - "ml-kem", - "lms", - "ocb", - "poly1305", - "psk", - "pvkkdf", - "rc2", - "rc4", - "rc5", - "rmd160", - "scrypt", - "seed", - "siphash", - "slh-dsa", - "siv", - "snmpkdf", - "sm2", - "sm3", - "sm4", - "srtpkdf", - "sshkdf", - "sskdf", - "x942kdf", - "x963kdf", - "whirlpool", - "zlib", - "zstd", -); - -my @disablables_features = ( +my @disablables = ( "acvp-tests", "apps", + "argon2", + "aria", "asan", "asm", "async", + "atexit", "autoalginit", "autoerrinit", "autoload-config", + "bf", + "blake2", + "brotli", "brotli-dynamic", "buildtest-c++", "bulk", "cached-fetch", - "dgram", + "camellia", "winstore", + "cast", + "chacha", + "cmac", + "cmp", + "cms", + "comp", "crypto-mdebug", "allocfail-tests", "ct", - "ct-validation", "default-thread-pool", "demos", "h3demo", "hqinterop", "deprecated", + "des", + "dgram", + "dh", "docs", + "dsa", "dso", - "ech", - "ec_explicit_curves", + "dtls", + "ec", + "ec2m", "ec_nistp_64_gcc_128", + "ecdh", + "ecdsa", + "ecx", "egd", "err", "external-tests", @@ -545,48 +478,84 @@ my @disablables_features = ( "fips-jitter", "fuzz-afl", "fuzz-libfuzzer", + "gost", + "http", + "idea", "integrity-only-ciphers", "jitter", + "ktls", "legacy", + "lms", "makedepend", + "md2", + "md4", + "mdc2", + "ml-dsa", + "ml-kem", "module", "msan", "multiblock", "nextprotoneg", + "ocb", + "ocsp", "pic", "pie", "pinshared", + "poly1305", "posix-io", + "psk", + "quic", "unstable-qlog", + "rc2", + "rc4", + "rc5", "rdrand", "rfc3779", + "rmd160", + "scrypt", + "sctp", "secure-memory", + "seed", "shared", + "siphash", + "siv", + "slh-dsa", + "sm2", "sm2-precomp", + "sm3", + "sm4", "sock", + "srp", + "srtp", "sse2", + "ssl", "ssl-trace", - "static-vcruntime", "stdio", "sslkeylog", "tests", "tfo", "thread-pool", "threads", + "tls", + "tls-deprecated-ec", "trace", "ts", "ubsan", "ui-console", "unit-test", - "unit-tests", "uplink", "weak-ssl-ciphers", + "whirlpool", + "zlib", "zlib-dynamic", + "zstd", "zstd-dynamic", - -); - -my @disablables = sort (@disablables_protocols,@disablables_algorithms,@disablables_features); + ); +foreach my $proto ((@tls, @dtls)) + { + push(@disablables, $proto); + push(@disablables, "$proto-method") unless $proto eq "tls1_3"; + } # Internal disablables, for aliasing purposes. They serve no special # purpose here, but allow scripts to get to know them through configdata.pm, @@ -597,7 +566,6 @@ my @disablables_int = qw( ); my %deprecated_disablables = ( - "atexit" => undef, "engine" => undef, "static-engine" => undef, "dynamic-engine" => undef, @@ -608,20 +576,17 @@ my %deprecated_disablables = ( "padlockeng" => undef, "ssl2" => undef, "buf-freelists" => undef, + "crypto-mdebug-backtrace" => undef, "hw" => undef, "hw-padlock" => undef, "ripemd" => "rmd160", "ui" => "ui-console", "heartbeats" => undef, - "ssl" => undef, - "ssl3" => undef, - "ssl3-method" => undef, ); # All of the following are disabled by default: our %disabled = ( # "what" => "comment" - "atexit" => "default", "fips" => "default", "fips-jitter" => "default", "asan" => "default", @@ -630,11 +595,10 @@ our %disabled = ( # "what" => "comment" "buildtest-c++" => "default", "crypto-mdebug" => "default", "allocfail-tests" => "default", - "ct-validation" => "default", + "crypto-mdebug-backtrace" => "default", "demos" => "default", "h3demo" => "default", "hqinterop" => "default", - "ec_explicit_curves" => "default", "ec_nistp_64_gcc_128" => "default", "egd" => "default", "engine" => "default", @@ -649,14 +613,13 @@ our %disabled = ( # "what" => "comment" "msan" => "default", "rc5" => "default", "sctp" => "default", + "ssl3" => "default", + "ssl3-method" => "default", "sslkeylog" => "default", - "static-vcruntime" => "default", "tfo" => "default", - "tls-deprecated-ec" => "default", "trace" => "default", "ubsan" => "default", "unit-test" => "default", - "unit-tests" => "default", "weak-ssl-ciphers" => "default", "zlib" => "default", "zlib-dynamic" => "default", @@ -668,32 +631,32 @@ our %disabled = ( # "what" => "comment" my @disable_cascades = ( # "what" => [ "cascade", ... ] "bulk" => [ "shared", "dso", - "argon2", "aria", "async", "autoload-config", + "argon2", "aria", "async", "atexit", "autoload-config", "blake2", "bf", "camellia", "cast", "chacha", "cmac", "cms", "cmp", "comp", "ct", "des", "dgram", "dh", "dsa", - "ec", "ech", - "filenames", "hmac-drbg-kdf", - "idea", "ikev2kdf", "kbkdf", "krb5kdf", "ktls", "lms", + "ec", + "filenames", + "idea", "ktls", "lms", "md4", "ml-dsa", "ml-kem", "multiblock", "nextprotoneg", "ocsp", "ocb", "poly1305", "psk", - "pvkkdf", "rc2", "rc4", "rmd160", + "rc2", "rc4", "rmd160", "scrypt", "seed", "siphash", "siv", - "slh-dsa", "sm3", "sm4", "snmpkdf", - "srp", "srtp", "srtpkdf", "sshkdf", "sskdf", - "ssl-trace", + "slh-dsa", "sm3", "sm4", "srp", + "srtp", "ssl3-method", "ssl-trace", "tfo", "ts", "ui-console", "whirlpool", - "x942kdf", "x963kdf", "fips-securitychecks" ], sub { $config{processor} eq "386" } => [ "sse2" ], + "ssl" => [ "ssl3" ], + "ssl3-method" => [ "ssl3" ], "zlib" => [ "zlib-dynamic" ], "brotli" => [ "brotli-dynamic" ], "zstd" => [ "zstd-dynamic" ], "des" => [ "mdc2" ], "deprecated" => [ "tls-deprecated-ec" ], - "ec" => [ qw(ec2m ec_explicit_curves sm2 gost ecx tls-deprecated-ec) ], + "ec" => [ qw(ec2m ecdsa ecdh sm2 gost ecx tls-deprecated-ec) ], "dgram" => [ "dtls", "quic", "sctp" ], "sock" => [ "dgram", "tfo" ], "dtls" => [ @dtls ], @@ -706,7 +669,7 @@ my @disable_cascades = ( "tls1_3" => [ "quic" ], "quic" => [ "unstable-qlog" ], - "crypto-mdebug" => [ "allocfail-tests" ], + "crypto-mdebug" => [ "crypto-mdebug-backtrace", "allocfail-tests" ], "module" => [ "fips" ], @@ -726,7 +689,7 @@ my @disable_cascades = ( "stdio" => [ "apps", "egd" ], "apps" => [ "tests" ], - "tests" => [ "external-tests", "unit-tests" ], + "tests" => [ "external-tests" ], "comp" => [ "zlib", "brotli", "zstd" ], "sm3" => [ "sm2" ], sub { !$disabled{"unit-test"} } => [ "heartbeats" ], @@ -861,11 +824,6 @@ $config{ex_libs} = [ env('__CNF_LDLIBS') || () ]; $config{openssl_api_defines}=[]; $config{openssl_sys_defines}=[]; $config{openssl_feature_defines}=[]; - -$config{openssl_disabled_protocols}=[]; -$config{openssl_disabled_algorithms}=[]; -$config{openssl_disabled_features}=[]; - $config{options}=""; $config{build_type} = "release"; my $target=""; @@ -926,14 +884,6 @@ while (@argvcopy) $unsupported_options{$_} = 1; next; } - - # Do not allow users to enable removed features - if (/^enable-(.+)$/ && exists $deprecated_disablables{$word} - && $deprecated_disablables{$word} eq undef) - { - $unsupported_options{$_} = 1; - next; - } } if (/^no-(.+)$/ || /^disable-(.+)$/) { @@ -953,6 +903,11 @@ while (@argvcopy) } $disabled{"dtls"} = "option(dtls)"; } + elsif ($1 eq "ssl") + { + # Last one of its kind + $disabled{"ssl3"} = "option(ssl)"; + } elsif ($1 eq "tls") { # XXX: Tests will fail if all SSL/TLS @@ -1045,10 +1000,6 @@ while (@argvcopy) { $config{build_type} = "release"; } - elsif (/^--manpage-format=(mdoc|roff)$/) - { - $config{manpage_format}="$1"; - } elsif (/^--pgo$/) { $config{build_type} = "pgo"; @@ -1122,22 +1073,6 @@ while (@argvcopy) { $withargs{fuzzer_include}=$1; } - elsif (/^--with-cmocka-lib=(.*)$/) - { - $withargs{cmocka_lib}=$1; - } - elsif (/^--with-cmocka-include=(.*)$/) - { - $withargs{cmocka_include}=$1; - } - elsif (/^--with-detours-lib=(.*)$/) - { - $withargs{detours_lib}=$1; - } - elsif (/^--with-detours-include=(.*)$/) - { - $withargs{detours_include}=$1; - } elsif (/^--with-rand-seed=(.*)$/) { foreach my $x (split(m|,|, $1)) @@ -1421,7 +1356,8 @@ at runtime in openssl.cnf or configured at build time with -DOPENSSL_DEFAULT_SEED_SRC. Please read the 'Note on random number generation' section in the -INSTALL.md instructions for more details. +INSTALL.md instructions and the RAND_DRBG(7) manual page for more +details. ============================== WARNING =============================== _____ @@ -1650,12 +1586,12 @@ unless ($disabled{threads}) { } } -# Find out if clang's sanitizers have been enabled with -fsanitize (or -# /fsanitize for VC targets) flags and ensure that the corresponding %disabled -# elements area removed to reflect that the sanitizers are indeed enabled. +# Find out if clang's sanitizers have been enabled with -fsanitize +# flags and ensure that the corresponding %disabled elements area +# removed to reflect that the sanitizers are indeed enabled. my %detected_sanitizers = (); -foreach (grep { /^[-\/]fsanitize=/ } @{$config{CFLAGS} || []}) { - (my $checks = $_) =~ s|^[-/]fsanitize=||; +foreach (grep /^-fsanitize=/, @{$config{CFLAGS} || []}) { + (my $checks = $_) =~ s/^-fsanitize=//; foreach (split /,/, $checks) { my $d = { address => 'asan', undefined => 'ubsan', @@ -1690,17 +1626,11 @@ if (($target{shared_target} // '') eq "") } unless ($disabled{asan} || defined $detected_sanitizers{asan}) { - push @{$config{cflags}}, - $config{target} =~ /^VC-/ ? "/fsanitize=address" : "-fsanitize=address"; + push @{$config{cflags}}, "-fsanitize=address"; } -my %predefined_C = compiler_predefined($config{CROSS_COMPILE}.$config{CC}); - unless ($disabled{ubsan} || defined $detected_sanitizers{ubsan}) { push @{$config{cflags}}, "-fsanitize=undefined", "-fno-sanitize-recover=all", "-DPEDANTIC"; - if ($predefined_C{__clang__}) { - push @{$config{cflags}}, "-fno-sanitize=function"; - } } unless ($disabled{msan} || defined $detected_sanitizers{msan}) { @@ -1709,50 +1639,8 @@ unless ($disabled{msan} || defined $detected_sanitizers{msan}) { unless ($disabled{"fuzz-libfuzzer"} && $disabled{"fuzz-afl"} && $disabled{asan} && $disabled{ubsan} && $disabled{msan}) { - unless ($config{target} =~ /^VC-/) { - push @{$config{cflags}}, "-fno-omit-frame-pointer", "-g"; - push @{$config{cxxflags}}, "-fno-omit-frame-pointer", "-g" if $config{CXX}; - } -} - -# Valgrind-based constant-time validation: marks secret data as "undefined" -# to Valgrind's memcheck tool, so that any control flow or memory indexing -# that depends on secret data is flagged as an error. Requires valgrind -# headers at build time and running the tests under valgrind at test time. -# Use |make TESTS="test_internal_ml_kem test_internal_ml_dsa" test| under -# valgrind after building with this option. -# -# Package names for the required valgrind headers: -# Debian/Ubuntu : valgrind (headers bundled in the main package) -# Fedora/RHEL : valgrind-devel -# Alpine : valgrind-dev -# Arch Linux : valgrind -unless ($disabled{"ct-validation"}) { - # Probe for so that we give a clear error here - # rather than a cryptic compile failure inside constant_time.h later. - my $cc = ($config{CROSS_COMPILE} // "").$config{CC}; - my $probe_src = "ct_valgrind_probe_$$.c"; - my $probe_obj = "ct_valgrind_probe_$$.o"; - open(my $fh, ">", $probe_src) - or die "Cannot write probe file '$probe_src': $!"; - print $fh "#include \n"; - close($fh); - my $probe_ok = (system("$cc -c -o $probe_obj $probe_src 2>/dev/null") == 0); - unlink($probe_src, $probe_obj); - if (!$probe_ok) { - die < at build time, -***** but the header was not found by '$cc'. -***** -***** Install the appropriate package and re-run Configure: -***** Debian/Ubuntu : sudo apt-get install valgrind -***** Fedora/RHEL : sudo dnf install valgrind-devel -***** Alpine : sudo apk add valgrind-dev -***** Arch Linux : sudo pacman -S valgrind -EOT - } - push @{$config{openssl_feature_defines}}, "OPENSSL_CONSTANT_TIME_VALIDATION"; + push @{$config{cflags}}, "-fno-omit-frame-pointer", "-g"; + push @{$config{cxxflags}}, "-fno-omit-frame-pointer", "-g" if $config{CXX}; } # # Platform fix-ups @@ -1780,6 +1668,7 @@ if ($target{sys_id} ne "") push @{$config{openssl_sys_defines}}, "OPENSSL_SYS_$target{sys_id}"; } +my %predefined_C = compiler_predefined($config{CROSS_COMPILE}.$config{CC}); my %predefined_CXX = $config{CXX} ? compiler_predefined($config{CROSS_COMPILE}.$config{CXX}) : (); @@ -1940,29 +1829,6 @@ unless ($disabled{winstore}) { push @{$config{openssl_other_defines}}, "OPENSSL_NO_KTLS" if ($disabled{ktls}); -# Keywords accepted in a build.info UNIT_TEST[] link set. -my @unit_test_keywords = qw(cmocka detours); - -unless ($disabled{"unit-tests"}) { - if ($target =~ /^linux/ || $target =~ /^BSD/) { - $config{cmocka_includes} = - $withargs{cmocka_include} ? [$withargs{cmocka_include}] : []; - $config{cmocka_libs} = $withargs{cmocka_lib} - ? "-L$withargs{cmocka_lib} -lcmocka" : "-lcmocka"; - } elsif ($target =~ /^VC-/) { - $config{cmocka_includes} = - $withargs{cmocka_include} ? [$withargs{cmocka_include}] : []; - $config{cmocka_libs} = $withargs{cmocka_lib} - ? "/LIBPATH:$withargs{cmocka_lib} cmocka.lib" : "cmocka.lib"; - $config{detours_includes} = - $withargs{detours_include} ? [$withargs{detours_include}] : []; - $config{detours_libs} = $withargs{detours_lib} - ? "/LIBPATH:$withargs{detours_lib} detours.lib" : "detours.lib"; - } else { - disable('no-unit-test-support', 'unit-tests'); - } -} - # Get the extra flags used when building shared libraries and modules. We # do this late because some of them depend on %disabled. @@ -2043,20 +1909,6 @@ foreach my $what (sort keys %disabled) { my $macro = $disabled_info{$what}->{macro} = "OPENSSL_NO_$WHAT"; push @{$config{openssl_feature_defines}}, $macro; - my @rules = ( - [ \@disablables_protocols, 'openssl_disabled_protocols' ], - [ \@disablables_algorithms, 'openssl_disabled_algorithms' ], - [ \@disablables_features, 'openssl_disabled_features' ], - ); - - for my $r (@rules) { - my ($list, $target) = @$r; - - if (grep { $what eq $_ } @$list) { - push @{$config{$target}}, uc $what; - } - } - $skipdir{"crypto/$skipdir"} = $what unless $what eq 'async' || $what eq 'err' || $what eq 'dso' || $what eq 'http'; } @@ -2187,8 +2039,6 @@ if ($builder eq "unified") { my %includes = (); my %defines = (); my %depends = (); - my %unit_tests = (); - my %wraps = (); my %generate = (); my %imagedocs = (); my %htmldocs = (); @@ -2444,16 +2294,6 @@ if ($builder eq "unified") { \$attributes{depends}, $+{ATTRIBS}, tokenize($expand_variables->($+{VALUE}))) if !@skip || $skip[$#skip] > 0; }, - qr/^\s* UNIT_TEST ${index_re} \s* = \s* ${value_re} \s* $/x - => sub { $push_to->(\%unit_tests, $expand_variables->($+{INDEX}), - undef, undef, - tokenize($expand_variables->($+{VALUE}))) - if !@skip || $skip[$#skip] > 0; }, - qr/^\s* WRAP ${index_re} \s* = \s* ${value_re} \s* $/x - => sub { $push_to->(\%wraps, $expand_variables->($+{INDEX}), - undef, undef, - tokenize($expand_variables->($+{VALUE}))) - if !@skip || $skip[$#skip] > 0; }, qr/^\s* GENERATE ${index_re} ${attribs_re} \s* = \s* ${value_re} \s* $/x => sub { $push_to->(\%generate, $expand_variables->($+{INDEX}), \$attributes{generate}, $+{ATTRIBS}, @@ -2740,27 +2580,6 @@ if ($builder eq "unified") { } } - foreach my $dest (keys %wraps) { - my $ddest = cleanfile($buildd, $dest, $blddir); - foreach my $fn (@{$wraps{$dest}}) { - push @{$unified_info{wraps}->{$ddest}}, $fn; - } - } - - foreach my $dest (keys %unit_tests) { - my $ddest = cleanfile($buildd, $dest, $blddir); - foreach my $kw (@{$unit_tests{$dest}}) { - die "***** Unknown keyword '$kw' in UNIT_TEST[$dest] at $sourced/$f\n" - unless grep { $_ eq $kw } @unit_test_keywords; - } - $unified_info{unit_tests}->{$ddest} = - [ @{$unit_tests{$dest}} ]; - } - # WRAP implies cmocka unless an explicit UNIT_TEST set was given - foreach my $dest (keys %{$unified_info{wraps} // {}}) { - $unified_info{unit_tests}->{$dest} //= [ "cmocka" ]; - } - foreach my $section (keys %imagedocs) { foreach (@{$imagedocs{$section}}) { my $imagedocs = cleanfile($buildd, $_, $blddir); @@ -3093,28 +2912,6 @@ EOF } } -# Attach cmocka (and, on Windows, Detours) include paths to unit tests, -# based on each test's UNIT_TEST[] link set. -if (!$disabled{"unit-tests"}) { - while (my ($dest, $libs) = each %{$unified_info{unit_tests} // {}}) { - my %want = map { $_ => 1 } @$libs; - push @{$unified_info{includes}->{$dest}}, @{$config{cmocka_includes}} - if $want{cmocka} && @{$config{cmocka_includes} // []}; - push @{$unified_info{includes}->{$dest}}, @{$config{detours_includes}} - if $want{detours} && @{$config{detours_includes} // []}; - } -} - -if (!$disabled{"unit-tests"}) { - foreach my $dest (sort keys %{$unified_info{unit_tests} // {}}) { - my %want = map { $_ => 1 } @{$unified_info{unit_tests}->{$dest}}; - my @resolved; - push @resolved, '$(CMOCKA_LIBS)' if $want{cmocka} && $config{cmocka_libs}; - push @resolved, '$(DETOURS_LIBS)' if $want{detours} && $config{detours_libs}; - $unified_info{unit_test_libs}->{$dest} = join(' ', @resolved); - } -} - # For the schemes that need it, we provide the old *_obj configs # from the *_asm_obj ones foreach (grep /_(asm|aux)_src$/, keys %target) { diff --git a/DOCUMENTATION.md b/DOCUMENTATION.md deleted file mode 100644 index 05bbb8564c..0000000000 --- a/DOCUMENTATION.md +++ /dev/null @@ -1,194 +0,0 @@ -OpenSSL Documentation Policy -============================ - -This document describes the code documentation and commenting requirements -for the OpenSSL project. - -The project's documentation is about making the libraries and tools more -accessible to our users and making the code more maintainable. This policy -applies to new submissions; existing code does not uniformly conform to it -and will be brought up to standard gradually. - -Any non-trivial change to existing code must bring the affected code into -conformance with this policy as part of the same change. In particular, -renaming or relocating functions, changes to public APIs, and any change -that would render an existing POD page or in-source comment inaccurate -require the corresponding documentation to be updated. This includes -adding documentation that was previously absent where the change brings -the affected code within the scope of this policy. - -The form and style of code comments themselves -- comment markers, layout, -the use of `/**` and `/*-` blocks, doxygen markup, the structure of the -sample multi-line comment, and similar -- are described in -[STYLE.md](STYLE.md). This file describes what *must* be documented and -where; [STYLE.md](STYLE.md) describes how code comments look. - -Command line commands and arguments ------------------------------------ - -All new commands, as well as new or modified arguments to existing -commands, must be documented in the `doc/man1` directory. This -documentation is in POD format. - -Public symbols in the libraries -------------------------------- - -All new public symbols must be documented in a POD manual page in the -`doc/man3` directory. This includes types, macros, and functions. - -The allowed exceptions are: - -- guard macros preventing a header file being included twice -- new symbols generated automatically via `make update` (errors, objects, etc.) - -Each public function's declaration in its public header must carry a -doxygen comment block. The block's `@see` must include the function's -own manual page (`name(3)`) and may include additional manual pages -that a caller needs to use the function correctly. The doxygen block -is a navigation aid pointing to the canonical reference documentation -in the corresponding POD file; see [STYLE.md](STYLE.md) for the -doxygen form. - -Overviews, conventions, et al ------------------------------ - -Where additional user-facing information is required, it should be -included in the `doc/man7` section. This includes, but is not limited to: - -- algorithm descriptions and parameters -- architectural and subsystem overviews -- user guides and tutorials -- conventions and reference material (environment variables, glossary, - threading rules, file format conventions) - -Internal functions, structures, globals and macros --------------------------------------------------- - -Internal functions, structures, globals and macros are non-public -items declared in any header that is not part of the public API. -These include items declared in: - -- `include/internal/` (shared across subsystems); -- `include/crypto/` (cryptographic internals); -- per-directory local headers (for example, `crypto/asn1/asn1_local.h`) - shared between source files in a single subdirectory. - -These should all be documented at the declaration site -- that is, -in the header that declares them -- using a doxygen-style comment -block. For functions, this places the comment at the prototype, -where editor tooling (clangd and similar) can surface it to readers -at every call site. The comment should describe the purpose and, -for functions, the input and output arguments and the return value. -See [STYLE.md](STYLE.md) for the doxygen conventions used by OpenSSL. - -For *trivial* items, where their operation is obvious from their -implementation, the documentation requirement is not mandated. The -following are generally representative of trivial items, however it is -quite possible for any of these to be non-trivial in specific instances -and therefore require documentation: - -- `OSSL_DISPATCH` tables -- upref functions -- free functions -- simple getter/setter functions -- wrappers for other functions (a function that calls a more recent - `_ex` variant or a group of functions that call a common internal - routine) - -For structures, each of the fields should be commented stating its -purpose. Again, a *trivial* exception applies where the purpose is -obvious. Some representative examples: - -- `OSSL_LIB_CTX *ctx;` where there is only one library context referenced - in the structure. -- `struct *next;` in a linked list implementation. -- `CRYPTO_REF_COUNT refcnt;` - -File-local items ----------------- - -These are functions, structures, globals, and macros that are local -to a single C file: `static` functions, file-scope variables, -structures, and macros defined inside a `.c` file with no declaration -in any header. - -These should all be documented at the point of definition. Follow the -same rules and exceptions as for internal items above. In some cases -slightly more leniency with respect to *trivial* can be tolerated. - -Code comments -------------- - -The form, style, and content guidance for code comments are described in -[STYLE.md](STYLE.md). Comments are required at the points described in -the internal and static sections above, subject to the *trivial* -exception, and at the additional points described in -[STYLE.md](STYLE.md). - -Assembly code -------------- - -Assembly code should include a good description of the algorithm and -approach being used. This should be followed by a performance comparison -and then the assembly code itself. The assembly code should be well -commented, but it is not necessary to comment every line. A comment -describing each block of code suffices. - -For pure-assembly modules (`.s` files and the perlasm scripts that -generate them), comments use the native syntax of the assembler or -generator (typically `#`). Doxygen-style markup does not apply here; -the algorithm description, performance comparison, and per-block -comments described above are still required. - -For assembly that appears inline inside a C file (within an `asm()` -statement, for example), the surrounding C function is documented -with doxygen-style C comments as for any other C code; see -[STYLE.md](STYLE.md). Comments inside the `asm()` body itself use -plain C `/* */` comments. - -There are no *trivial* exceptions for assembly code. - -Configure options ------------------ - -New options added to the configuration scripts must be documented in the -[INSTALL.md](INSTALL.md) file. - -Changes and news ----------------- - -Significant modifications should be documented in the -[CHANGES.md](CHANGES.md) file. - -Very significant features and changes should be documented in the -[NEWS.md](NEWS.md) file. - -In both cases, the added note should be short and to the point, and -should be written for users of the library, focusing on impact rather -than implementation details. - -Automated sanity checking -------------------------- - -The `make doc-nits` command should be run before submitting a pull -request and any problems it locates must be addressed. - -Language --------- - -The language used for documentation shall be *British English*. - -In general the language, abbreviations, layout and formatting should also -correspond to the -[LDP](https://openssl-library.org/policies/general/glossary/#ldp) -guidelines. - -Common sense ------------- - -Comments and documentation are to improve readability and comprehension. -Where the code is obvious, there is no need to include a comment. -However, common sense applies: always err in favour of including more -comments than less or none. Code that you have just written that is -*obvious* will not necessarily be to someone else two years later. See -[STYLE.md](STYLE.md) for the form and content of code comments. diff --git a/doc/HOWTO/adding-functions.md b/HACKING.md similarity index 80% rename from doc/HOWTO/adding-functions.md rename to HACKING.md index 704089a246..b58f08a2dc 100644 --- a/doc/HOWTO/adding-functions.md +++ b/HACKING.md @@ -1,5 +1,5 @@ -ADDING FUNCTIONS to OPENSSL -=========================== +MODIFYING OPENSSL SOURCE +======================== This document describes the way to add custom modifications to OpenSSL sources. @@ -58,7 +58,7 @@ public function - as defined above - is added, these files must be updated. To make such an update, please do the following: - ./Configure --strict-warnings [your-options] + ./Configure -Werror --strict-warnings [your-options] make update If you plan to submit the changes you made to OpenSSL (see @@ -67,19 +67,14 @@ If you plan to submit the changes you made to OpenSSL (see make doc-nits -`make update` ensures that your functions declarations are added to -`util/libcrypto.num` or `util/libssl.num`. -It also generates files related to OIDs (in the `crypto/objects/` folder) -and error messages. - -More details are at - [doc/HOWTO/documenting-functions-macros.md](Documenting Functions and Macros) +Do note that `make update` also generates files related to OIDs (in the +`crypto/objects/` folder) and errors messages. If a git merge error occurs in one of these generated files, then the generated files need to be removed and regenerated using `make update`. -To aid in this process, the generated files should be committed separately +To aid in this process, the generated files can be committed separately so they can be removed easily by reverting that commit. -[doc/internal/man7/build.info.pod]: ../doc/internal/man7/build.info.pod -[Configurations/unix-Makefile.tmpl]: ../../Configurations/unix-Makefile.tmpl -[CONTRIBUTING.md]: ../../CONTRIBUTING.md +[doc/internal/man7/build.info.pod]: ./doc/internal/man7/build.info.pod +[Configurations/unix-Makefile.tmpl]: ./Configurations/unix-Makefile.tmpl +[CONTRIBUTING.md]: ./CONTRIBUTING.md diff --git a/HOWTO.md b/HOWTO.md deleted file mode 100644 index 8ee3be5e05..0000000000 --- a/HOWTO.md +++ /dev/null @@ -1,8 +0,0 @@ -MODIFYING OPENSSL SOURCE -======================== - -This is a collection of pointers to parts of the documentation that will help -people doing modifications. - -* [doc/HOWTO/adding-functions.md](Adding new Functions) -* [doc/HOWTO/documenting-functions-macros.md](Documenting Functions and Macros) diff --git a/INSTALL.md b/INSTALL.md index 5d132b49f0..414c08d366 100644 --- a/INSTALL.md +++ b/INSTALL.md @@ -169,11 +169,13 @@ issue the following commands to build OpenSSL. $ nmake test As mentioned in the [Choices](#choices) section, you need to pick one -of the Configure targets in the first command. +of the four Configure targets in the first command. Most likely you will be using the `VC-WIN64A`/`VC-WIN64A-HYBRIDCRT` target for 64bit Windows binaries (AMD64) or `VC-WIN32`/`VC-WIN32-HYBRIDCRT` for 32bit Windows binaries (X86). +The other two options are `VC-WIN64I` (Intel IA64, Itanium) and +`VC-CE` (Windows CE) are rather uncommon nowadays. Installing OpenSSL ------------------ @@ -426,22 +428,6 @@ The names of the libraries are: * brotlidec.lib * brotlienc.lib -### with-cmocka-include - - --with-cmocka-include=DIR - -The directory for the location of the cmocka include file. This option is only -necessary if [enable-unit-tests](#enable-unit-tests) is used and the include -file is not already on the system include path. - -### with-cmocka-lib - - --with-cmocka-lib=DIR - -The directory containing the cmocka library. This option is only necessary if -[enable-unit-tests](#enable-unit-tests) is used and the library is not already -on the system library path. - ### with-zlib-include --with-zlib-include=DIR @@ -598,15 +584,6 @@ In the following list, always the non-default variant is documented: if feature `xxxx` is disabled by default then `enable-xxxx` is documented and if feature `xxxx` is enabled by default then `no-xxxx` is documented. -### enable-static-vcruntime - -Build binaries that do not require that VC runtimes are installed - -This option will produce binaries that are "self contained", that do not -depend upon VC runtime libraries being installed, so can be used on any -computer running MS Windows. Without this option, the build will produce -binaries that rely on the VC runtimes being installed and available. - ### enable-ktls Build with Kernel TLS support. @@ -657,10 +634,9 @@ Do not build support for async operations. Do not use `atexit()` in libcrypto builds. -Before version 4.0, OpenSSL used to set `atexit()` handler for cleaning up -global data, and this option allowed to disable that functionality. `atexit()` -handler setup was removed in OpenSSL 4.0, so `no-atexit` option is retained -for compatibility reasons only, always present, and does nothing. +`atexit()` has varied semantics between platforms and can cause SIGSEGV in some +circumstances. This option disables the atexit registration of OPENSSL_cleanup. +By default, NonStop configurations use `no-atexit`. ### no-autoalginit @@ -753,6 +729,10 @@ the zlib or `zlib-dynamic` options are also chosen. This now only enables the `failed-malloc` feature. +### enable-crypto-mdebug-backtrace + +This is a no-op; the project uses the compiler's address/leak sanitizer instead. + ### enable-allocfail-tests This option enables testing that leverages the use of the crypto-mdebug feature @@ -781,22 +761,20 @@ Don't build and install documentation, i.e. manual pages in various forms. Don't build support for loading Dynamic Shared Objects (DSO) -### enable-tls-deprecated-ec +### no-ec -Enable legacy TLS EC groups that were deprecated in RFC8422. These are the +Don't build support for Elliptic Curves. + +### no-ec2m + +Don't build support for binary Elliptic Curves + +### no-tls-deprecated-ec + +Disable legacy TLS EC groups that were deprecated in RFC8422. These are the Koblitz curves, B, B, B, B, and the binary Elliptic curves that would also be disabled by C. -### enable-ec_expicit_curves - -Enable support for explictitly specified elliptic curves not matching the -well-known ones. Until this option is on, such curves can't be instantiated -from ASN.1 formats. - -### no-ech - -Don't build support for Encrypted Client Hello (ECH) extension. - ### enable-ec_nistp_64_gcc_128 Enable support for optimised implementations of some commonly used NIST @@ -832,12 +810,6 @@ external test suites are currently supported: See the file [test/README-external.md](test/README-external.md) for further details. -### enable-unit-tests - -Enable building and running unit tests. - -This works only on platforms supporting ld `--wrap` option like Linux and BSD. - ### no-filenames Don't compile in filename and line number information (e.g. for errors and @@ -889,13 +861,6 @@ Note that if this feature is enabled then GOST ciphersuites are only available if the GOST algorithms are also available through loading an externally supplied engine. -### no-engine, no-static-engine, no-dynamic-engine - -The `no-engine` option is always present. These options are deprecated and do -nothing, and are retained for backwards compatibility only. The ENGINE API was -deprecated in OpenSSL 3.0 and removed in OpenSSL 4.0, so applications should -transition to using providers instead. - ### no-http Disable HTTP support. @@ -906,10 +871,26 @@ Don't build the legacy provider. Disabling this also disables the legacy algorithms: MD2 (already disabled by default). +### enable-lms + +Enable Leighton-Micali Signatures (LMS) support. +Support is currently limited to verification only as per +[SP 800-208](https://csrc.nist.gov/pubs/sp/800/208/final). + ### no-makedepend Don't generate dependencies. +### no-ml-dsa + +Disable Module-Lattice-Based Digital Signature Standard (ML-DSA) support. +ML-DSA is based on CRYSTALS-DILITHIUM. See [FIPS 204]. + +### no-ml-kem + +Disable Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM) +support. ML-KEM is based on CRYSTALS-KYBER. See [FIPS 203]. + ### no-module Don't build any dynamically loadable modules. @@ -940,17 +921,17 @@ Build with support for Position Independent Execution. Don't pin the shared libraries. -By default, on supported platforms (such as Linux and GNU Hurd), OpenSSL -is built with linker options (e.g., `-Wl,-znodelete`) that prevent the -operating system from unloading the libcrypto and libssl shared libraries -from memory, even if the application explicitly unloads them using -`dlclose()`. On platforms that do not support these options, this feature -is disabled by default. +By default OpenSSL will attempt to stay in memory until the process exits. +This is so that libcrypto and libssl can be properly cleaned up automatically +via an `atexit()` handler. The handler is registered by libcrypto and cleans +up both libraries. On some platforms the `atexit()` handler will run on unload of +libcrypto (if it has been dynamically loaded) rather than at process exit. -This option prevents the addition of those linker flags, allowing the -shared libraries to be completely unloaded from the process address space. -This is useful for applications that dynamically load and unload OpenSSL -plugins to conserve memory. +This option can be used to stop OpenSSL from attempting to stay in memory until the +process exits. This could lead to crashes if either libcrypto or libssl have +already been unloaded at the point that the atexit handler is invoked, e.g. on a +platform which calls `atexit()` on unload of the library, and libssl is unloaded +before libcrypto then a crash is likely to happen. Note that shared library pinning is not automatically disabled for static builds, i.e., `no-shared` does not imply `no-pinshared`. This may come as a surprise when @@ -958,6 +939,10 @@ linking libcrypto statically into a shared third-party library, because in this case the shared library will be pinned. To prevent this behaviour, you need to configure the static build using `no-shared` and `no-pinshared` together. +Applications can suppress running of the `atexit()` handler at run time by +using the `OPENSSL_INIT_NO_ATEXIT` option to `OPENSSL_init_crypto()`. +See the man page for it for further details. + ### no-posix-io Don't use POSIX IO capabilities. @@ -985,6 +970,11 @@ Do not create shared libraries, only static ones. See [Notes on shared libraries](#notes-on-shared-libraries) below. +### no-slh-dsa + +Disable Stateless Hash Based Digital Signature Standard support. +(SLH-DSA is based on SPHINCS+. See [FIPS 205]) + ### no-sm2-precomp Disable using the SM2 precomputed table on aarch64 to make the library smaller. @@ -1115,12 +1105,10 @@ The User Interface console method enables text based console prompts. ### enable-unit-test -Enable exposing SSL_test_functions for overwriting ssl_init_wbio_buffer. +Enable additional unit test APIs. This should not typically be used in production deployments. -This option is deprecated and will be removed in OpenSSL 5.0. - ### no-uplink Don't build support for UPLINK interface. @@ -1177,8 +1165,8 @@ Don't build support for negotiating the specified SSL/TLS protocol. If `no-tls` is selected then all of `tls1`, `tls1_1`, `tls1_2` and `tls1_3` are disabled. -Similarly `no-dtls` will disable `dtls1` and `dtls1_2`. -`no-ssl` and `no-ssl3` are deprecated and do nothing. +Similarly `no-dtls` will disable `dtls1` and `dtls1_2`. The `no-ssl` option is +synonymous with `no-ssl3`. Note this only affects version negotiation. OpenSSL will still provide the methods for applications to explicitly select the individual protocol versions. @@ -1194,37 +1182,28 @@ Analogous to `no-{protocol}` but in addition do not build the methods for applications to explicitly select individual protocol versions. Note that there is no `no-tls1_3-method` option because there is no application method for TLSv1.3. -`no-ssl3` is deprecated and does nothing. Using individual protocol methods directly is deprecated. Applications should use `TLS_method()` instead. ### enable-{algorithm} - enable-{md2|rc5|lms} + enable-{md2|rc5} Build with support for the specified algorithm. -The `lms` algorithm support is currently limited to verification only as per -[SP 800-208](https://csrc.nist.gov/pubs/sp/800/208/final). - ### no-{algorithm} no-{aria|bf|blake2|camellia|cast|chacha|cmac| - des|dh|dsa| - ec|ec2m|ecdh|ecdsa|hmac-drbg-kdf|idea|ikev2kdf|kbkdf|krb5kdf| - md4|mdc2| - ml-dsa|ml-kem| - ocb|poly1305|pvkkdf|rc2|rc4|rmd160|scrypt| - seed|siphash|siv|slh-dsa|sm2|sm3|sm4|snmpkdf|srtpkdf|sshkdf|sskdf| - x942kdf|x963kdf|whirlpool} + des|dh|dsa|ecdh|ecdsa|idea|md4|mdc2|ml-dsa| + ml-kem|ocb|poly1305|rc2|rc4|rmd160|scrypt| + seed|siphash|siv|sm2|sm3|sm4|whirlpool} Build without support for the specified algorithm. The `ripemd` algorithm is deprecated and if used is synonymous with `rmd160`. -Compiler-specific options -------------------------- +### Compiler-specific options -Dxxx, -Ixxx, -Wp, -lxxx, -Lxxx, -Wl, -rpath, -R, -framework, -static @@ -1255,17 +1234,7 @@ encoding. Take note of the [Environment Variables](#environment-variables) documentation below and how these flags interact with those variables. -Miscellaneous options ---------------------- - -### --manpage-format - -Specify a specific output manpage format. The supported output types are mandoc -and *roff. The *roff output format is the default for legacy and portability -reasons. - -Environment Variables ---------------------- +### Environment Variables VAR=value @@ -1342,18 +1311,10 @@ If `CC` is set, it is advisable to also set `CXX` to ensure both the C and C++ compiler are in the same "family". This becomes relevant with `enable-external-tests` and `enable-buildtest-c++`. -Reconfigure ------------ +### Reconfigure -### Make targets - - `$ make reconf` - -or - - `$ make reconfigure` - -### Description + reconf + reconfigure Reconfigure from earlier data. @@ -1971,8 +1932,9 @@ on Cygwin, shared libraries are named `cygcrypto-1.1.dll` and `cygssl-1.1.dll` with import libraries `libcrypto.dll.a` and `libssl.dll.a`. On Windows build with MSVC or using MingW, shared libraries are named -`libcrypto-1_1.dll` and `libssl-1_1.dll` for 32-bit Windows, and -`libcrypto-1_1-x64.dll` and `libssl-1_1-x64.dll` for 64-bit x86_64 Windows. +`libcrypto-1_1.dll` and `libssl-1_1.dll` for 32-bit Windows, +`libcrypto-1_1-x64.dll` and `libssl-1_1-x64.dll` for 64-bit x86_64 Windows, +and `libcrypto-1_1-ia64.dll` and `libssl-1_1-ia64.dll` for IA64 Windows. With MSVC, the import libraries are named `libcrypto.lib` and `libssl.lib`, while with MingW, they are named `libcrypto.dll.a` and `libssl.dll.a`. diff --git a/NEWS.md b/NEWS.md index 239f195de0..3944e99cf0 100644 --- a/NEWS.md +++ b/NEWS.md @@ -7,7 +7,6 @@ release. For more details please read the CHANGES file. OpenSSL Releases ---------------- - - [OpenSSL 4.1](#openssl-41) - [OpenSSL 4.0](#openssl-40) - [OpenSSL 3.6](#openssl-36) - [OpenSSL 3.5](#openssl-35) @@ -23,280 +22,18 @@ OpenSSL Releases - [OpenSSL 1.0.0](#openssl-100) - [OpenSSL 0.9.x](#openssl-09x) -OpenSSL 4.1 ------------ - -### Major changes between OpenSSL 4.0 and OpenSSL 4.1 [under development] - - * API calls `CRYPTO_atomic_load_ptr`, `CRYPTO_atomic_store_ptr`, and - `CRYPTO_atomic_cmp_exch_ptr` have been added. - - * Fixed verification of DSA certificates signed with SHA-384 or SHA-512. - OpenSSL 4.0 ----------- -### Major changes between OpenSSL 4.0.0 and OpenSSL 4.0.1 [9 Jun 2026] +### Major changes between OpenSSL 3.6 and OpenSSL 4.0 [under development] -OpenSSL 4.0.1 is a security patch release. The most severe CVE fixed -in this release is High. - -This release incorporates the following bug fixes and mitigations: - - * Fixed heap use-after-free in `PKCS7_verify()`. - ([CVE-2026-45447]) - - * Fixed CMS `AuthEnvelopedData` processing may accept forged messages. - ([CVE-2026-34182]) - - * Fixed unbounded memory growth in the QUIC `PATH_CHALLENGE` handler. - ([CVE-2026-34183]) - - * Fixed double-free when checking OCSP stapled response. - ([CVE-2026-35188]) - - * Fixed NULL pointer dereference in QUIC server initial packet handling. - ([CVE-2026-42764]) - - * Fixed AES-OCB IV ignored on `EVP_Cipher()` path. - ([CVE-2026-45445]) - - * Fixed possible heap buffer overflow in ASN.1 multibyte string conversion. - ([CVE-2026-7383]) - - * Fixed out-of-bounds read in CMS password-based decryption. - ([CVE-2026-9076]) - - * Fixed heap buffer over-read in ASN.1 content parsing. - ([CVE-2026-34180]) - - * Fixed PKCS#12 files with PBMAC1 are accepted with short HMAC keys. - ([CVE-2026-34181]) - - * Fixed NULL dereference in certificate verification with OCSP Checking. - ([CVE-2026-42765]) - - * Fixed possible NULL dereference in password-dased CMS decryption. - ([CVE-2026-42766]) - - * Fixed NULL pointer dereference in CRMF `EncryptedValue` decryption. - ([CVE-2026-42767]) - - * Fixed multi-`RecipientInfo` Bleichenbacher Oracle in `CMS_decrypt()` - and `PKCS7_decrypt()`. - ([CVE-2026-42768]) - - * Fixed trust anchor substitution via `cert`/`issuer` typo in CMP - `rootCaKeyUpdate`. - ([CVE-2026-42769]) - - * Fixed FFC-DH peer validation uses attacker-supplied `q`. - ([CVE-2026-42770]) - - * Fixed possible out of bounds read in `X509_VERIFY_PARAM_set1_email()`. - ([CVE-2026-42771]) - - * Fixed incorrect tag processing for empty messages in AES-GCM-SIV - and AES-SIV modes. - ([CVE-2026-45446]) - - * Fixed a regression introduced in 4.0.0 that led to a `openssl pkey` - command crash when it was invoked to encrypt a private key with password - being provided interactively. - - * Fixed a regression introduced in 4.0.0 that led to `openssl s_client -adv` - command prematurely terminating a session when reading input of 16384 bytes - in one `read()` call. - -### Major changes between OpenSSL 3.6 and OpenSSL 4.0.0 [14 Apr 2026] - -OpenSSL 4.0.0 is a feature release adding significant new functionality -to OpenSSL. - -This release incorporates the following potentially significant or incompatible -changes: - - * Removed extra leading '00:' when printing key data such as an RSA modulus - in hexadecimal format where the first (most significant) byte is >= 0x80. - - * Standardized the width of hexadecimal dumps to 24 bytes for signatures - (to stay within the 80 characters limit) and 16 bytes for everything else. - - * Lower bounds checks are now enforced when using `PKCS5_PBKDF2_HMAC` API - with FIPS provider. - - * Added AKID verification checks when `X509_V_FLAG_X509_STRICT` is set. - - * Augmented CRL verification process with several additional checks. - - * `libcrypto` no longer cleans up globally allocated data via `atexit()`. - - * `BIO_snprintf()` now uses `snprintf()` provided by libc instead of internal - implementation. - - * `OPENSSL_cleanup()` now runs in a global destructor, or not at all - by default. - - * `ASN1_STRING` has been made opaque. - - * Signatures of numerous API functions, including those that are related - to X509 processing, are changed to include `const` qualifiers for argument - and return types, where suitable. - - * Deprecated `X509_cmp_time()`, `X509_cmp_current_time()`, - and `X509_cmp_timeframe()` in favor of `X509_check_certificate_times()`. - - * Removed support for the SSLv2 Client Hello. - - * Removed support for SSLv3. SSLv3 has been deprecated since 2015, - and OpenSSL had it disabled by default since version 1.1.0 (2016). - - * Removed support for engines. The `no-engine` build option - and the `OPENSSL_NO_ENGINE` macro are always present. - - * Support of deprecated elliptic curves in TLS according to [RFC 8422] was - disabled at compile-time by default. To enable it, use the - `enable-tls-deprecated-ec` configuration option. - - * Support of explicit EC curves was disabled at compile-time by default. - To enable it, use the `enable-ec_explicit_curves` configuration option. - - * Removed `c_rehash` script tool. Use `openssl rehash` instead. - - * Removed the deprecated `msie-hack` option from the `openssl ca` command. - - * Removed `BIO_f_reliable()` implementation without replacement. - It was broken since 3.0 release without any complaints. - - * Removed deprecated support for custom `EVP_CIPHER`, `EVP_MD`, `EVP_PKEY`, - and `EVP_PKEY_ASN1` methods. - - * Removed deprecated fixed SSL/TLS version method functions. - - * Removed deprecated functions `ERR_get_state()`, `ERR_remove_state()` - and `ERR_remove_thread_state()`. The `ERR_STATE` object is now always - opaque. - - * Dropped `darwin-i386{,-cc}` and `darwin-ppc{,64}{,-cc}` targets - from Configurations. - -This release adds the following new features: - - * Support for Encrypted Client Hello (ECH, [RFC 9849]). - See `doc/designs/ech-api.md` for details. - - * Support for [RFC 8998], signature algorithm `sm2sig_sm3`, key exchange - group `curveSM2`, and [tls-hybrid-sm2-mlkem] post-quantum group - `curveSM2MLKEM768`. - - * cSHAKE function support as per [SP 800-185]. - - * "ML-DSA-MU" digest algorithm support. - - * Support for SNMP KDF and SRTP KDF. - - * FIPS self tests can now be deferred and run as needed when installing - the FIPS module with the `-defer_tests` option of the `openssl fipsinstall` - command. - - * Support for using either static or dynamic VC runtime linkage - on Windows. - - * Support for negotiated FFDHE key exchange in TLS 1.2 in accordance - with [RFC 7919]. + * ENGINE support was removed. The `no-engine` build option and the + `OPENSSL_NO_ENGINE` macro is always present. OpenSSL 3.6 ----------- -### Major changes between OpenSSL 3.6.1 and OpenSSL 3.6.2 [7 Apr 2026] - -OpenSSL 3.6.2 is a security patch release. The most severe CVE fixed in this -release is Moderate. - -This release incorporates the following bug fixes and mitigations: - - * Fixed incorrect failure handling in RSA KEM RSASVE encapsulation. - ([CVE-2026-31790]) - - * Fixed loss of key agreement group tuple structure when the `DEFAULT` keyword - is used in the server-side configuration of the key-agreement group list. - ([CVE-2026-2673]) - - * Fixed out-of-bounds read in AES-CFB-128 on x86-64 CPUs with AVX-512 support. - ([CVE-2026-28386]) - - * Fixed potential use-after-free in DANE client code. - ([CVE-2026-28387]) - - * Fixed NULL pointer dereference when processing a delta CRL. - ([CVE-2026-28388]) - - * Fixed possible NULL dereference when processing CMS KeyAgreeRecipientInfo. - ([CVE-2026-28389]) - - * Fixed possible NULL dereference when processing CMS - KeyTransportRecipientInfo. - ([CVE-2026-28390]) - - * Fixed heap buffer overflow in hexadecimal conversion. - ([CVE-2026-31789]) - -### Major changes between OpenSSL 3.6.0 and OpenSSL 3.6.1 [27 Jan 2026] - -OpenSSL 3.6.1 is a security patch release. The most severe CVE fixed in this -release is High. - -This release incorporates the following bug fixes and mitigations: - - * Fixed Improper validation of PBMAC1 parameters in PKCS#12 MAC verification. - ([CVE-2025-11187]) - - * Fixed Stack buffer overflow in CMS `AuthEnvelopedData` parsing. - ([CVE-2025-15467]) - - * Fixed NULL dereference in `SSL_CIPHER_find()` function on unknown cipher ID. - ([CVE-2025-15468]) - - * Fixed `openssl dgst` one-shot codepath silently truncates inputs >16 MiB. - ([CVE-2025-15469]) - - * Fixed TLS 1.3 `CompressedCertificate` excessive memory allocation. - ([CVE-2025-66199]) - - * Fixed Heap out-of-bounds write in `BIO_f_linebuffer` on short writes. - ([CVE-2025-68160]) - - * Fixed Unauthenticated/unencrypted trailing bytes with low-level OCB - function calls. - ([CVE-2025-69418]) - - * Fixed Out of bounds write in `PKCS12_get_friendlyname()` UTF-8 conversion. - ([CVE-2025-69419]) - - * Fixed Missing `ASN1_TYPE` validation in `TS_RESP_verify_response()` - function. - ([CVE-2025-69420]) - - * Fixed NULL Pointer Dereference in `PKCS12_item_decrypt_d2i_ex()` function. - ([CVE-2025-69421]) - - * Fixed Missing `ASN1_TYPE` validation in PKCS#12 parsing. - ([CVE-2026-22795]) - - * Fixed `ASN1_TYPE` Type Confusion in the `PKCS7_digest_from_attributes()` - function. - ([CVE-2026-22796]) - - * Fixed a regression in `X509_V_FLAG_CRL_CHECK_ALL` flag handling by - restoring its pre-3.6.0 behaviour. - - * Fixed a regression in handling stapled OCSP responses causing handshake - failures for OpenSSL 3.6.0 servers with various client implementations. - -### Major changes between OpenSSL 3.5 and OpenSSL 3.6.0 [1 Oct 2025] - -OpenSSL 3.6.0 is a feature release adding significant new functionality -to OpenSSL. +### Major changes between OpenSSL 3.5 and OpenSSL 3.6 [under development] This release incorporates the following potentially significant or incompatible changes: @@ -1015,7 +752,7 @@ OpenSSL 1.1.1 ### Major changes between OpenSSL 1.1.1d and OpenSSL 1.1.1e [17 Mar 2020] - * Fixed an overflow bug in the x86_64 Montgomery squaring procedure + * Fixed an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli ([CVE-2019-1551]) ### Major changes between OpenSSL 1.1.1c and OpenSSL 1.1.1d [10 Sep 2019] @@ -2245,233 +1982,190 @@ OpenSSL 0.9.x * Support for various new platforms -[CHANGES.md]: ./CHANGES.md -[CMVP]: https://csrc.nist.gov/projects/cryptographic-module-validation-program -[CVE-2005-2969]: https://openssl-library.org/news/vulnerabilities/#CVE-2005-2969 -[CVE-2006-2937]: https://openssl-library.org/news/vulnerabilities/#CVE-2006-2937 -[CVE-2006-2940]: https://openssl-library.org/news/vulnerabilities/#CVE-2006-2940 -[CVE-2006-3737]: https://openssl-library.org/news/vulnerabilities/#CVE-2006-3737 -[CVE-2006-4339]: https://openssl-library.org/news/vulnerabilities/#CVE-2006-4339 -[CVE-2006-4343]: https://openssl-library.org/news/vulnerabilities/#CVE-2006-4343 -[CVE-2008-5077]: https://openssl-library.org/news/vulnerabilities/#CVE-2008-5077 -[CVE-2009-0590]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-0590 -[CVE-2009-0591]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-0591 -[CVE-2009-0789]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-0789 -[CVE-2009-3555]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-3555 -[CVE-2010-0433]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-0433 -[CVE-2010-0740]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-0740 -[CVE-2010-1633]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-1633 -[CVE-2010-2939]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-2939 -[CVE-2010-3864]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-3864 -[CVE-2010-4180]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-4180 -[CVE-2010-4252]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-4252 -[CVE-2010-5298]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-5298 -[CVE-2011-0014]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-0014 -[CVE-2011-3207]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-3207 -[CVE-2011-3210]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-3210 -[CVE-2011-4108]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-4108 -[CVE-2011-4576]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-4576 -[CVE-2011-4577]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-4577 -[CVE-2011-4619]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-4619 -[CVE-2012-0027]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-0027 -[CVE-2012-0050]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-0050 -[CVE-2012-0884]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-0884 -[CVE-2012-2110]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-2110 -[CVE-2012-2333]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-2333 -[CVE-2012-2686]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-2686 -[CVE-2013-0166]: https://openssl-library.org/news/vulnerabilities/#CVE-2013-0166 -[CVE-2013-0169]: https://openssl-library.org/news/vulnerabilities/#CVE-2013-0169 -[CVE-2013-4353]: https://openssl-library.org/news/vulnerabilities/#CVE-2013-4353 -[CVE-2013-6449]: https://openssl-library.org/news/vulnerabilities/#CVE-2013-6449 -[CVE-2013-6450]: https://openssl-library.org/news/vulnerabilities/#CVE-2013-6450 -[CVE-2014-0076]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0076 -[CVE-2014-0160]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0160 -[CVE-2014-0195]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0195 -[CVE-2014-0198]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0198 -[CVE-2014-0221]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0221 -[CVE-2014-0224]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0224 -[CVE-2014-3470]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3470 -[CVE-2014-3505]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3505 -[CVE-2014-3506]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3506 -[CVE-2014-3507]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3507 -[CVE-2014-3508]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3508 -[CVE-2014-3509]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3509 -[CVE-2014-3510]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3510 -[CVE-2014-3511]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3511 -[CVE-2014-3512]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3512 -[CVE-2014-3513]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3513 -[CVE-2014-3566]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3566 -[CVE-2014-3567]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3567 -[CVE-2014-3568]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3568 -[CVE-2014-3569]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3569 -[CVE-2014-3570]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3570 -[CVE-2014-3571]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3571 -[CVE-2014-3572]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3572 -[CVE-2014-5139]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-5139 -[CVE-2014-8275]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-8275 -[CVE-2015-0204]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0204 -[CVE-2015-0205]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0205 -[CVE-2015-0206]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0206 -[CVE-2015-0207]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0207 -[CVE-2015-0208]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0208 -[CVE-2015-0209]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0209 -[CVE-2015-0285]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0285 -[CVE-2015-0286]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0286 -[CVE-2015-0287]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0287 -[CVE-2015-0288]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0288 -[CVE-2015-0289]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0289 -[CVE-2015-0290]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0290 -[CVE-2015-0291]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0291 -[CVE-2015-0293]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0293 -[CVE-2015-1787]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1787 -[CVE-2015-1788]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1788 -[CVE-2015-1789]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1789 -[CVE-2015-1790]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1790 -[CVE-2015-1791]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1791 -[CVE-2015-1792]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1792 -[CVE-2015-1793]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1793 -[CVE-2015-3193]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-3193 -[CVE-2015-3194]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-3194 -[CVE-2015-3195]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-3195 -[CVE-2015-3196]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-3196 -[CVE-2015-3197]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-3197 -[CVE-2016-0701]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0701 -[CVE-2016-0702]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0702 -[CVE-2016-0705]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0705 -[CVE-2016-0797]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0797 -[CVE-2016-0798]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0798 -[CVE-2016-0799]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0799 -[CVE-2016-0800]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0800 -[CVE-2016-2105]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2105 -[CVE-2016-2106]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2106 -[CVE-2016-2107]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2107 -[CVE-2016-2109]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2109 -[CVE-2016-2176]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2176 -[CVE-2016-2177]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2177 -[CVE-2016-2178]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2178 -[CVE-2016-2179]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2179 -[CVE-2016-2180]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2180 -[CVE-2016-2181]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2181 -[CVE-2016-2182]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2182 -[CVE-2016-2183]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2183 -[CVE-2016-6302]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6302 -[CVE-2016-6303]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6303 -[CVE-2016-6304]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6304 -[CVE-2016-6305]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6305 -[CVE-2016-6306]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6306 -[CVE-2016-6307]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6307 -[CVE-2016-6308]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6308 -[CVE-2016-6309]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6309 -[CVE-2016-7052]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-7052 -[CVE-2016-7053]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-7053 -[CVE-2016-7054]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-7054 -[CVE-2016-7055]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-7055 -[CVE-2017-3730]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3730 -[CVE-2017-3731]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3731 -[CVE-2017-3732]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3732 -[CVE-2017-3733]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3733 -[CVE-2017-3735]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3735 -[CVE-2017-3736]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3736 -[CVE-2017-3737]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3737 -[CVE-2017-3738]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3738 -[CVE-2018-0732]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0732 -[CVE-2018-0733]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0733 -[CVE-2018-0734]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0734 -[CVE-2018-0735]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0735 -[CVE-2018-0737]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0737 -[CVE-2018-0739]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0739 -[CVE-2018-5407]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-5407 -[CVE-2019-1543]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1543 -[CVE-2019-1547]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1547 -[CVE-2019-1549]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1549 -[CVE-2019-1551]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1551 -[CVE-2019-1552]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1552 -[CVE-2019-1559]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1559 -[CVE-2019-1563]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1563 -[CVE-2020-1967]: https://openssl-library.org/news/vulnerabilities/#CVE-2020-1967 -[CVE-2020-1971]: https://openssl-library.org/news/vulnerabilities/#CVE-2020-1971 -[CVE-2022-2097]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-2097 -[CVE-2022-2274]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-2274 -[CVE-2022-3996]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-3996 -[CVE-2022-4203]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-4203 -[CVE-2022-4304]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-4304 -[CVE-2022-4450]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-4450 -[CVE-2023-0215]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0215 -[CVE-2023-0216]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0216 -[CVE-2023-0217]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0217 -[CVE-2023-0286]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0286 -[CVE-2023-0401]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0401 -[CVE-2023-0464]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0464 -[CVE-2023-0465]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0465 -[CVE-2023-0466]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0466 -[CVE-2023-1255]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-1255 -[CVE-2023-2650]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-2650 -[CVE-2023-2975]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-2975 -[CVE-2023-3446]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-3446 -[CVE-2023-3817]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-3817 -[CVE-2023-4807]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-4807 -[CVE-2023-5363]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-5363 -[CVE-2023-5678]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-5678 -[CVE-2023-6129]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-6129 -[CVE-2023-6237]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-6237 -[CVE-2024-0727]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-0727 -[CVE-2024-2511]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-2511 -[CVE-2024-4603]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-4603 -[CVE-2024-4741]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-4741 -[CVE-2024-5535]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-5535 -[CVE-2024-6119]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-6119 -[CVE-2024-9143]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-9143 -[CVE-2024-13176]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-13176 -[CVE-2025-4575]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-4575 -[CVE-2025-9230]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-9230 -[CVE-2025-9231]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-9231 -[CVE-2025-9232]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-9232 -[CVE-2025-11187]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-11187 -[CVE-2025-15467]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-15467 -[CVE-2025-15468]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-15468 -[CVE-2025-15469]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-15469 -[CVE-2025-66199]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-66199 -[CVE-2025-68160]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-68160 -[CVE-2025-69418]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-69418 -[CVE-2025-69419]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-69419 -[CVE-2025-69420]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-69420 -[CVE-2025-69421]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-69421 -[CVE-2026-2673]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-2673 -[CVE-2026-7383]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-7383 -[CVE-2026-9076]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-9076 -[CVE-2026-22795]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-22795 -[CVE-2026-22796]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-22796 -[CVE-2026-28386]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-28386 -[CVE-2026-28387]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-28387 -[CVE-2026-28388]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-28388 -[CVE-2026-28389]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-28389 -[CVE-2026-28390]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-28390 -[CVE-2026-31789]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-31789 -[CVE-2026-31790]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-31790 -[CVE-2026-34180]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34180 -[CVE-2026-34181]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34181 -[CVE-2026-34182]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34182 -[CVE-2026-34183]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34183 -[CVE-2026-35188]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-35188 -[CVE-2026-42764]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42764 -[CVE-2026-42765]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42765 -[CVE-2026-42766]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42766 -[CVE-2026-42767]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42767 -[CVE-2026-42768]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42768 -[CVE-2026-42769]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42769 -[CVE-2026-42770]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42770 -[CVE-2026-42771]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42771 -[CVE-2026-45445]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-45445 -[CVE-2026-45446]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-45446 -[CVE-2026-45447]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-45447 -[ESV]: https://csrc.nist.gov/Projects/cryptographic-module-validation-program/entropy-validations +[CVE-2025-9232]: https://www.openssl.org/news/vulnerabilities.html#CVE-2025-9232 +[CVE-2025-9231]: https://www.openssl.org/news/vulnerabilities.html#CVE-2025-9231 +[CVE-2025-9230]: https://www.openssl.org/news/vulnerabilities.html#CVE-2025-9230 +[CVE-2025-4575]: https://www.openssl.org/news/vulnerabilities.html#CVE-2025-4575 +[CVE-2024-13176]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-13176 +[CVE-2024-9143]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-9143 +[CVE-2024-6119]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-6119 +[CVE-2024-5535]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-5535 +[CVE-2024-4741]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-4741 +[CVE-2024-4603]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-4603 +[CVE-2024-2511]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-2511 +[CVE-2024-0727]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-0727 +[CVE-2023-6237]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-6237 +[CVE-2023-6129]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-6129 +[CVE-2023-5678]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-5678 +[CVE-2023-5363]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-5363 +[CVE-2023-4807]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-4807 +[CVE-2023-3817]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-3817 +[CVE-2023-3446]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-3446 +[CVE-2023-2975]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-2975 +[CVE-2023-2650]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-2650 +[CVE-2023-1255]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-1255 +[CVE-2023-0466]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0466 +[CVE-2023-0465]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0465 +[CVE-2023-0464]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0464 +[CVE-2023-0401]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0401 +[CVE-2023-0286]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0286 +[CVE-2023-0217]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0217 +[CVE-2023-0216]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0216 +[CVE-2023-0215]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0215 +[CVE-2022-4450]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-4450 +[CVE-2022-4304]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-4304 +[CVE-2022-4203]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-4203 +[CVE-2022-3996]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-3996 +[CVE-2022-2274]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-2274 +[CVE-2022-2097]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-2097 +[CVE-2020-1971]: https://www.openssl.org/news/vulnerabilities.html#CVE-2020-1971 +[CVE-2020-1967]: https://www.openssl.org/news/vulnerabilities.html#CVE-2020-1967 +[CVE-2019-1563]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1563 +[CVE-2019-1559]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1559 +[CVE-2019-1552]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1552 +[CVE-2019-1551]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1551 +[CVE-2019-1549]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1549 +[CVE-2019-1547]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1547 +[CVE-2019-1543]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1543 +[CVE-2018-5407]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-5407 +[CVE-2018-0739]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0739 +[CVE-2018-0737]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0737 +[CVE-2018-0735]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0735 +[CVE-2018-0734]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0734 +[CVE-2018-0733]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0733 +[CVE-2018-0732]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0732 +[CVE-2017-3738]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3738 +[CVE-2017-3737]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3737 +[CVE-2017-3736]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3736 +[CVE-2017-3735]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3735 +[CVE-2017-3733]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3733 +[CVE-2017-3732]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3732 +[CVE-2017-3731]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3731 +[CVE-2017-3730]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3730 +[CVE-2016-7055]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-7055 +[CVE-2016-7054]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-7054 +[CVE-2016-7053]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-7053 +[CVE-2016-7052]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-7052 +[CVE-2016-6309]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6309 +[CVE-2016-6308]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6308 +[CVE-2016-6307]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6307 +[CVE-2016-6306]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6306 +[CVE-2016-6305]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6305 +[CVE-2016-6304]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6304 +[CVE-2016-6303]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6303 +[CVE-2016-6302]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6302 +[CVE-2016-2183]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2183 +[CVE-2016-2182]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2182 +[CVE-2016-2181]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2181 +[CVE-2016-2180]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2180 +[CVE-2016-2179]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2179 +[CVE-2016-2178]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2178 +[CVE-2016-2177]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2177 +[CVE-2016-2176]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2176 +[CVE-2016-2109]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2109 +[CVE-2016-2107]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2107 +[CVE-2016-2106]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2106 +[CVE-2016-2105]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2105 +[CVE-2016-0800]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0800 +[CVE-2016-0799]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0799 +[CVE-2016-0798]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0798 +[CVE-2016-0797]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0797 +[CVE-2016-0705]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0705 +[CVE-2016-0702]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0702 +[CVE-2016-0701]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0701 +[CVE-2015-3197]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-3197 +[CVE-2015-3196]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-3196 +[CVE-2015-3195]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-3195 +[CVE-2015-3194]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-3194 +[CVE-2015-3193]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-3193 +[CVE-2015-1793]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1793 +[CVE-2015-1792]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1792 +[CVE-2015-1791]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1791 +[CVE-2015-1790]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1790 +[CVE-2015-1789]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1789 +[CVE-2015-1788]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1788 +[CVE-2015-1787]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1787 +[CVE-2015-0293]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0293 +[CVE-2015-0291]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0291 +[CVE-2015-0290]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0290 +[CVE-2015-0289]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0289 +[CVE-2015-0288]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0288 +[CVE-2015-0287]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0287 +[CVE-2015-0286]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0286 +[CVE-2015-0285]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0285 +[CVE-2015-0209]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0209 +[CVE-2015-0208]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0208 +[CVE-2015-0207]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0207 +[CVE-2015-0206]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0206 +[CVE-2015-0205]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0205 +[CVE-2015-0204]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0204 +[CVE-2014-8275]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-8275 +[CVE-2014-5139]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-5139 +[CVE-2014-3572]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3572 +[CVE-2014-3571]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3571 +[CVE-2014-3570]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3570 +[CVE-2014-3569]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3569 +[CVE-2014-3568]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3568 +[CVE-2014-3567]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3567 +[CVE-2014-3566]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3566 +[CVE-2014-3513]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3513 +[CVE-2014-3512]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3512 +[CVE-2014-3511]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3511 +[CVE-2014-3510]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3510 +[CVE-2014-3509]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3509 +[CVE-2014-3508]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3508 +[CVE-2014-3507]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3507 +[CVE-2014-3506]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3506 +[CVE-2014-3505]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3505 +[CVE-2014-3470]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3470 +[CVE-2014-0224]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0224 +[CVE-2014-0221]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0221 +[CVE-2014-0198]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0198 +[CVE-2014-0195]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0195 +[CVE-2014-0160]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0160 +[CVE-2014-0076]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0076 +[CVE-2013-6450]: https://www.openssl.org/news/vulnerabilities.html#CVE-2013-6450 +[CVE-2013-6449]: https://www.openssl.org/news/vulnerabilities.html#CVE-2013-6449 +[CVE-2013-4353]: https://www.openssl.org/news/vulnerabilities.html#CVE-2013-4353 +[CVE-2013-0169]: https://www.openssl.org/news/vulnerabilities.html#CVE-2013-0169 +[CVE-2013-0166]: https://www.openssl.org/news/vulnerabilities.html#CVE-2013-0166 +[CVE-2012-2686]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-2686 +[CVE-2012-2333]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-2333 +[CVE-2012-2110]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-2110 +[CVE-2012-0884]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-0884 +[CVE-2012-0050]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-0050 +[CVE-2012-0027]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-0027 +[CVE-2011-4619]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-4619 +[CVE-2011-4577]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-4577 +[CVE-2011-4576]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-4576 +[CVE-2011-4108]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-4108 +[CVE-2011-3210]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-3210 +[CVE-2011-3207]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-3207 +[CVE-2011-0014]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-0014 +[CVE-2010-5298]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-5298 +[CVE-2010-4252]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-4252 +[CVE-2010-4180]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-4180 +[CVE-2010-3864]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-3864 +[CVE-2010-2939]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-2939 +[CVE-2010-1633]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-1633 +[CVE-2010-0740]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-0740 +[CVE-2010-0433]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-0433 +[CVE-2009-3555]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-3555 +[CVE-2009-0789]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-0789 +[CVE-2009-0591]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-0591 +[CVE-2009-0590]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-0590 +[CVE-2008-5077]: https://www.openssl.org/news/vulnerabilities.html#CVE-2008-5077 +[CVE-2006-4343]: https://www.openssl.org/news/vulnerabilities.html#CVE-2006-4343 +[CVE-2006-4339]: https://www.openssl.org/news/vulnerabilities.html#CVE-2006-4339 +[CVE-2006-3737]: https://www.openssl.org/news/vulnerabilities.html#CVE-2006-3737 +[CVE-2006-2940]: https://www.openssl.org/news/vulnerabilities.html#CVE-2006-2940 +[CVE-2006-2937]: https://www.openssl.org/news/vulnerabilities.html#CVE-2006-2937 +[CVE-2005-2969]: https://www.openssl.org/news/vulnerabilities.html#CVE-2005-2969 [OpenSSL Guide]: https://docs.openssl.org/master/man7/ossl-guide-introduction +[CHANGES.md]: ./CHANGES.md [README-QUIC.md]: ./README-QUIC.md -[RFC 7919]: https://datatracker.ietf.org/doc/html/rfc7919 -[RFC 8422]: https://datatracker.ietf.org/doc/html/rfc8422 -[RFC 8998]: https://datatracker.ietf.org/doc/html/rfc8998#name-iana-considerations -[RFC 9849]: https://datatracker.ietf.org/doc/html/rfc9849 -[SP 800-185]: https://csrc.nist.gov/pubs/sp/800/185/final -[SP 800-208]: https://csrc.nist.gov/pubs/sp/800/208/final [issue tracker]: https://github.com/openssl/openssl/issues +[CMVP]: https://csrc.nist.gov/projects/cryptographic-module-validation-program +[ESV]: https://csrc.nist.gov/Projects/cryptographic-module-validation-program/entropy-validations +[SP 800-208]: https://csrc.nist.gov/pubs/sp/800/208/final [jitterentropy-library]: https://github.com/smuellerDD/jitterentropy-library diff --git a/NOTES-C99.md b/NOTES-C99.md index 59bf502daf..47b153a88d 100644 --- a/NOTES-C99.md +++ b/NOTES-C99.md @@ -32,18 +32,4 @@ The list of C-99 features we don't support in OpenSSL project follows: { char s[n]; /* variable size array */ ... - } ``` - -Exit status macros (`EXIT_SUCCESS`, `EXIT_FAILURE`) ---------------------------------------------------- - -These macros from `` represent *process* exit status. Do not use -them as return values from internal APIs (any function that is not `main()`). -Use them only as the return value from `main()` or as the argument to -`exit(3)` (or equivalent, such as `_exit()`). - -Elsewhere, be consistent with the rest of the codebase: return a positive -value for success (often `1`), and `0` or a non-positive value for failure, -or `bool` when that improves clarity. See -. diff --git a/NOTES-NONSTOP.md b/NOTES-NONSTOP.md index b41758da20..a2d485132d 100644 --- a/NOTES-NONSTOP.md +++ b/NOTES-NONSTOP.md @@ -55,6 +55,26 @@ option to `./Configure`. TNS/E has moved to a limited support state, so fixes for this platform will not be guaranteed in future. +Linking and Loading Considerations +---------------------------------- + +Because of how the NonStop Common Runtime Environment (CRE) works, there are +restrictions on how programs can link and load with OpenSSL libraries. +On current NonStop platforms, programs cannot both statically link OpenSSL +libraries and dynamically load OpenSSL shared libraries concurrently. If this +is done, there is a high probability of encountering a SIGSEGV condition +relating to `atexit()` processing when a shared library is unloaded and when +the program terminates. This limitation applies to all OpenSSL shared library +components. + +A control has been added as of 3.3.x to disable calls to `atexit()` within the +`libcrypto` builds (specifically in `crypto/init.c`). This switch can be +controlled using `disable-atexit` or `enable-atexit`, and is disabled by default +for NonStop builds. If you need to have `atexit()` functionality, set +`enabled-atexit` when configuring OpenSSL to enable the `atexit()` call to +register `OPENSSL_cleanup()` automatically. Preferably, you can explicitly call +`OPENSSL_cleanup()` from your application. + Secure Memory ------------- @@ -167,7 +187,7 @@ the following variables. The following set of compiler defines are required: ### Optional Build Variables DBGFLAG="--debug" - CIPHENABLES="enable-weak-ssl-ciphers enable-rc4" + CIPHENABLES="enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers enable-rc4" ### Internal Known TNS/X to TNS/E Cross Compile Variables diff --git a/NOTES-VALGRIND.md b/NOTES-VALGRIND.md index cd82d01fdc..96f0df1d19 100644 --- a/NOTES-VALGRIND.md +++ b/NOTES-VALGRIND.md @@ -70,76 +70,3 @@ with the `VERBOSE` or `VF` or `VFP` options to gather additional information. $ make test VERBOSE=1 TESTS=test_test EXE_SHELL="$(/bin/pwd)/util/wrap.pl \ valgrind --error-exitcode=1 --leak-check=full -q" OPENSSL_ia32cap=":0" - -Still reachable memory -====================== - -OpenSSL 4.0 no longer arms `OPENSSL_cleanup()` function as an `atexit(3)` -handler. So, unless the application explicitly calls `OPENSSL_cleanup()`, valgrind and -similar memory leak detectors may report `still reachable` memory blocks -as memory leaks. An example of a valgrind report reads as follows: - - # valgrind ./pkeyread -f pem -k dh 8 - ==280439== Memcheck, a memory error detector - ==280439== Copyright (C) 2002-2024, and GNU GPL'd, by Julian Seward et al. - ==280439== Using Valgrind-3.24.0 and LibVEX; rerun with -h for copyright info - ==280439== Command: ./pkeyread -f pem -k dh 8 - ==280439== - Average time per pem(dh) call: 506329.113924us - ==280439== - ==280439== HEAP SUMMARY: - ==280439== in use at exit: 239,521 bytes in 4,137 blocks - ==280439== total heap usage: 21,841 allocs, 17,704 frees, 4,089,104 bytes allocated - ==280439== - ==280439== LEAK SUMMARY: - ==280439== definitely lost: 0 bytes in 0 blocks - ==280439== indirectly lost: 0 bytes in 0 blocks - ==280439== possibly lost: 0 bytes in 0 blocks - ==280439== still reachable: 239,521 bytes in 4,137 blocks - ==280439== suppressed: 0 bytes in 0 blocks - ==280439== Rerun with --leak-check=full to see details of leaked memory - ==280439== - ==280439== For lists of detected and suppressed errors, rerun with: -s - ==280439== ERROR SUMMARY: 0 errors from 0 contexts (suppressed: 0 from 0) - -The valgrind output above reports there are 239,521 of reachable memory -when process exits. That memory is not regarded as a true memory leak -as the OS will reclaim that memory on process exit, rendering calls to libc -`free()` within `OPENSSL_cleanup()` useless. Also calling `OPENSSL_cleanup()` -is discouraged when libcrypto is being linked with process to satisfy more -than one dependency paths. If it is the case then calling `OPENSSL_cleanup()` -may lead to spurious application crashes during exit. - -If memory leaks caused by _still reachable memory_ are still an issue, -then preferred way is to suppress those reports using the suppression -file [1] instead of changing exiting code by adding a call to `OPENSSL_cleanup()`. -The suppression file for OpenSSL is shipped within the OpenSSL sources and -can be found at`$OPENSSL_SRCS/util/valgrind.suppressions` where `OPENSSL_SRCS` -is an environment variable containing path to the OpenSSL source -tree. To use it, just add `--suppressions` option to the valgrind command: -`valgrind --suppressions="$OPENSSL_SRCS/util/valgrind.suppression" ...` -For `pkeyread` the command and output reads as follows: - - # valgrind --suppressions=$OPENSSL_SRCS/util/valgrind.suppression ./pkeyread -f pem -k dh 8 - ==280896== Memcheck, a memory error detector - ==280896== Copyright (C) 2002-2024, and GNU GPL'd, by Julian Seward et al. - ==280896== Using Valgrind-3.24.0 and LibVEX; rerun with -h for copyright info - ==280896== Command: ./pkeyread -f pem -k dh 8 - ==280896== - Average time per pem(dh) call: 476190.476190us - ==280896== - ==280896== HEAP SUMMARY: - ==280896== in use at exit: 239,521 bytes in 4,137 blocks - ==280896== total heap usage: 22,816 allocs, 18,679 frees, 4,325,714 bytes allocated - ==280896== - ==280896== LEAK SUMMARY: - ==280896== definitely lost: 0 bytes in 0 blocks - ==280896== indirectly lost: 0 bytes in 0 blocks - ==280896== possibly lost: 0 bytes in 0 blocks - ==280896== still reachable: 0 bytes in 0 blocks - ==280896== suppressed: 239,521 bytes in 4,137 blocks - ==280896== - ==280896== For lists of detected and suppressed errors, rerun with: -s - ==280896== ERROR SUMMARY: 0 errors from 0 contexts (suppressed: 0 from 0) - -[1] diff --git a/NOTES-WINDOWS.md b/NOTES-WINDOWS.md index 76371e529d..20748b5365 100644 --- a/NOTES-WINDOWS.md +++ b/NOTES-WINDOWS.md @@ -7,8 +7,6 @@ Notes for Windows platforms - [Native builds using MinGW](#native-builds-using-mingw) - [Linking native applications](#linking-native-applications) - [Hosted builds using Cygwin](#hosted-builds-using-cygwin) - - [Hosted builds using Windows Subsystem for Linux (WSL)]( - #hosted-builds-using-windows-subsystem-for-linux-wsl) There are various options to build and run OpenSSL on the Windows platforms. @@ -25,7 +23,7 @@ or "Hosted" OpenSSL relies on an external POSIX compatibility layer for building (using GNU/Unix shell, compiler, and tools) and at run time. -For this option, you can use Cygwin or the Windows Subsystem for Linux (WSL). +For this option, you can use Cygwin. Native builds using Visual C++ ============================== @@ -94,13 +92,6 @@ Quick start dependency feature can speed up build times by up to 50%: `perl Configure no-makedepend` - b. If you want the OpenSSL binaries to be "self contained", usable on any - computer running MS Windows, use 'perl Configure enable-static-vcruntime'. - Otherwise, build will produce binaries that depend on the VC runtime - libraries being installed and available, and will not work on computers - that do not have them. (This option adds 1 MB to the total size of the - two dll's.) - 6. `nmake` 7. `nmake test` @@ -296,71 +287,3 @@ NOTE: `make test` and normal file operations may fail in directories mounted as text (i.e. `mount -t c:\somewhere /home`) due to Cygwin stripping of carriage returns. To avoid this, ensure that a binary mount is used, e.g. `mount -b c:\somewhere /home`. - -Hosted builds using Windows Subsystem for Linux (WSL) -====================================================== - -WSL provides a Linux-compatible environment directly on Windows, allowing -OpenSSL to be built using standard GNU/Unix tools. The resulting OpenSSL -runs within the WSL environment and relies on the WSL compatibility layer -at run time. - - 1. Install WSL and a Linux distribution (e.g. Ubuntu), see - - - 2. Ensure your distribution is up to date: - - sudo apt update && sudo apt upgrade - - 3. Install the required build dependencies. On Debian/Ubuntu-based - distributions: - - sudo apt install build-essential perl make - - 4. Optionally install the NASM assembler for optimised assembly routines: - - sudo apt install nasm - - 5. Run the WSL shell (e.g. Ubuntu) from the Start menu or by running - `wsl` from a Windows command prompt - - 6. From the root of the OpenSSL source directory, configure the build: - - ./Configure - - or specify a prefix and openssldir explicitly: - - ./Configure --prefix=/usr/local/ssl --openssldir=/usr/local/ssl - - 7. Build, test, and install: - - make - make test - make install - -Apart from the setup steps above, follow the Unix / Linux instructions -in INSTALL.md and the shared library path guidance in NOTES-UNIX.md. - -NOTE: The OpenSSL source tree should reside on the Linux filesystem -(e.g. under `~/`) rather than on a mounted Windows path such as -`/mnt/c/`. Building from a mounted Windows path can result in -significantly slower build times and occasional failures due to -filesystem permission and interoperability differences between NTFS -and the Linux layer. If your source is on the Windows filesystem, -copy it into the WSL home directory first: - - cp -r /mnt/c/path/to/openssl ~/openssl - -NOTE: If you do build from a mounted Windows path (e.g. /mnt/c/), be aware -that Windows line endings (CRLF) in source or script files can cause -configure and build scripts to fail. In this case, run dos2unix on the -affected files before building: - - dos2unix Configure # removes all \r (carriage return) characters - dos2unix config # does the same, but for the config script - dos2unix *.sh # runs dos2unix on all shell scripts in the directory, - # ensuring every .sh file has correct Unix line endings - -dos2unix can be installed via: - - sudo apt install dos2unix diff --git a/README-FIPS.md b/README-FIPS.md index 4e3e20cf4d..160234518d 100644 --- a/README-FIPS.md +++ b/README-FIPS.md @@ -109,19 +109,19 @@ which versions are FIPS validated. For this example we use OpenSSL 3.1.2. Download and build the latest release of OpenSSL ------------------------------------------------ -We use OpenSSL 3.6.0 here, (but you could also use the latest 3.6.X) +We use OpenSSL 3.5.0 here, (but you could also use the latest 3.5.X) - $ wget https://www.openssl.org/source/openssl-3.6.0.tar.gz - $ tar -xf openssl-3.6.0.tar.gz - $ cd openssl-3.6.0 + $ wget https://www.openssl.org/source/openssl-3.5.0.tar.gz + $ tar -xf openssl-3.5.0.tar.gz + $ cd openssl-3.5.0 $ ./Configure enable-fips $ make Use the OpenSSL FIPS provider for testing ----------------------------------------- -We do this by replacing the artifact for the OpenSSL 3.6.0 FIPS provider. -Note that the OpenSSL 3.6.0 FIPS provider has not been validated +We do this by replacing the artifact for the OpenSSL 3.5.0 FIPS provider. +Note that the OpenSSL 3.5.0 FIPS provider has not been validated so it must not be used for FIPS purposes. $ cp ../openssl-3.1.2/providers/fips.so providers/. @@ -147,7 +147,7 @@ Copy the FIPS provider artifacts (`fips.so` & `fipsmodule.cnf`) to known locatio Check that the correct FIPS provider is being used -------------------------------------------------- - $ cd ../openssl-3.6.0 + $ cd ../openssl-3.5.0 $./util/wrap.pl -fips apps/openssl list -provider-path providers \ -provider fips -providers @@ -155,7 +155,7 @@ Check that the correct FIPS provider is being used Providers: base name: OpenSSL Base Provider - version: 3.6.0 + version: 3.5.0 status: active fips name: OpenSSL FIPS Provider diff --git a/README.md b/README.md index fcefc19923..1d84f5ab1b 100644 --- a/README.md +++ b/README.md @@ -49,7 +49,7 @@ The OpenSSL toolkit includes: basis of the TLS implementation, but can also be used independently. - **openssl** - the OpenSSL command line tool, a Swiss Army knife for cryptographic tasks, + the OpenSSL command line tool, a swiss army knife for cryptographic tasks, testing and analyzing. It can be used for - creation of key parameters - creation of X.509 certificates, CSRs and CRLs @@ -150,10 +150,10 @@ The manual pages for the master branch and all current stable releases are available online. - [OpenSSL master](https://docs.openssl.org/master/) -- [OpenSSL 4.0](https://docs.openssl.org/4.0/) -- [OpenSSL 3.6](https://docs.openssl.org/3.6/) - [OpenSSL 3.5](https://docs.openssl.org/3.5/) - [OpenSSL 3.4](https://docs.openssl.org/3.4/) +- [OpenSSL 3.3](https://docs.openssl.org/3.3/) +- [OpenSSL 3.2](https://docs.openssl.org/3.2/) - [OpenSSL 3.0](https://docs.openssl.org/3.0/) Demos @@ -198,7 +198,7 @@ attempting to develop or distribute cryptographic code. Copyright ========= -Copyright (c) 1998-2026 The OpenSSL Project Authors +Copyright (c) 1998-2025 The OpenSSL Project Authors Copyright (c) 1995-1998 Eric A. Young, Tim J. Hudson diff --git a/STYLE.md b/STYLE.md deleted file mode 100644 index 2bedc42a5a..0000000000 --- a/STYLE.md +++ /dev/null @@ -1,1133 +0,0 @@ -OpenSSL Style Guide -=================== - -Applicability -------------- - -New code in OpenSSL is expected to follow the conventions in this -guide. Existing code does not uniformly comply and is being brought -up to standard gradually; non-trivial changes to existing code -should bring the affected area into compliance. - -When bringing an area into compliance as part of a larger change, -do so in a separate commit -- typically one that lands first, so -that the substantive change then operates on already-compliant -code. Combining a compliance sweep with a behaviour change in one -commit makes the diff hard to review and hard to revert. - -Do not bring code into compliance as part of a bug fix. Make the -minimal change that fixes the bug. This holds for any bug fix, and -especially for one that may be backported to a stable release -branch -- and at the time of the fix you often cannot know whether -it will be. Mixing compliance changes into a fix complicates -backporting and makes the change larger than it needs to be. Leave -any compliance work for a separate change. - -The language is C99 (ISO/IEC 9899:1999). More modern C versions -are not yet supported on every platform OpenSSL targets and -should be avoided. - -Formatting ----------- - -OpenSSL follows the -[WebKit coding style for C code](https://webkit.org/code-style-guidelines/). -In cases where the WebKit guide gives different rules for C and C++, -OpenSSL uses the C variant. - -Whitespace, indentation, brace placement, line wrapping, alignment and -the other mechanical aspects of formatting are enforced by `clang-format` -using the [`.clang-format`](.clang-format) file at the top of this -repository. The configuration is the WebKit C style with a small set -of OpenSSL-specific customisations (notably the list of project -typedefs, the `STACK_OF` / `LHASH_OF` type macros, and the list of -statement-shaped macros). - -Run `clang-format` on your changes before submitting; the output of -`clang-format` is deemed correct. See -[CONTRIBUTING.md](CONTRIBUTING.md) for the tooling (`.pre-commit-config.yaml`, -the `util/reformat-patches.sh` helper, and editor integrations). - -In rare situations it may be necessary to disable `clang-format` on a -piece of code. This may be done with paired comments: - -```c -/* clang-format off */ -I am doing something nasty here. -Reviewers should be triggered. -/* clang-format on */ -``` - -This should be used sparingly, and should not be used if there is any -other way to do what you are doing. - -Multi-line comment blocks have an additional clang-format opt-out -via the `/**` and `/*-` markers; see [Comments](#comments). - -Naming ------- - -### Functions and variables - -A name describes what the identifier holds or what it does. -Match the name to its role: a variable holding an `X509 *` is -typically `cert`; one holding an `X509_STORE_CTX *` is typically -`ctx`; a function that counts the number of active users is -called `count_active_users()`, not `cntusr()`. Use whole words -when there is no established short form, and reuse the same -name across the codebase for the same concept rather than -inventing synonyms. - -Names use lowercase with underscores (snake_case). For public -functions, snake_case applies to the portion of the name after -the uppercase subsystem prefix (see below). Do not begin a -name with an underscore; identifiers starting with an -underscore are reserved by the C standard in various contexts -and can collide with toolchain or system identifiers. - -For variables, OpenSSL has well-established short forms that -are fine to use without further qualification: `ctx`, `ptr`, -`len`, `buf`, `cert`, `key`, `pkey`, `ret`, `tmp`, and similar. -Use these in preference to longer forms; do not coin a new -variant when one of these already covers the meaning. Use the -suffix `_count` for a number of items, `_len` for a byte length, -and `_size` for a size in bytes; do not invent variants like -`num_X`, `X_length`, or `X_bytes` when one of these already -applies. - -A variable that mirrors notation from a standard, RFC, paper, -or other authoritative specification being implemented may use -whatever name the spec uses (for example, `n`, `e`, `d` for RSA -parameters, or `salt` and `info` for HKDF). Document the spec -citation and which variables come from it in the function or -file doxygen comment; see [Doxygen comments](#doxygen-comments) -for the form. - -Outside spec-mirroring, single letters are appropriate only as -loop counters (`i`, `j`, `k`). - -For functions, OpenSSL names follow a `PREFIX_[OBJECT_]action()` -shape: an uppercase subsystem prefix; then, where the function -operates on a particular object or context, that object -- usually -the uppercase or mixed-case type name; then the action, in -lowercase with underscores. Where the prefix already identifies -the object, or the function is a general subsystem utility, there -is no separate object element. -Examples: `EVP_KDF_CTX_get0_kdf` (prefix `EVP`, object `KDF_CTX`, -action `get0_kdf`), `EVP_PKEY_sign`, `OSSL_CMP_validate_msg`, -`SSL_CTX_set_verify`; and, with no object element, `BIO_eof` and -`CRYPTO_malloc`. - -This shape is aspirational and describes the direction for new -code. Much of the existing API predates it and carries years of -naming baggage, so it does not uniformly conform. Do not rename -existing public functions to fit it -- that breaks the API. - -Public (API) functions use the uppercase subsystem prefix. -Internal functions use the lowercase `ossl_` prefix unless they -are static (i.e., local to the source file); static functions -need no prefix. - -Functions that return a pointer disclose ownership of the -returned value via a `0` or `1` suffix on the name: - -- `get0_X()` returns a non-owning pointer. -- `get1_X()` returns an owning pointer; the caller is the new - owner, of either a fresh allocation or an up-ref. - -The same convention applies in reverse for setters and -pushers that take a pointer: - -- `set0_X(obj, p)` and `push0_X(coll, p)` transfer ownership - of `p` to `obj` or `coll`. -- `set1_X(obj, p)` and `push1_X(coll, p)` leave ownership - with the caller; the callee stores a copy or up-ref. - -Use these forms rather than a bare `get_` / `set_` / `push_` -whenever a pointer crosses the API boundary. - -A function extended from an existing form takes an `_ex` -suffix (`_ex2` for a second extension, `_ex3` for a third, -and so on). See [Extending existing functions](#extending-existing-functions) -for when to add an extended form and how to handle the -parameter list. - -### Typedefs - -OpenSSL uses typedefs extensively. Struct typedefs are named in -`ALL_CAPS_WITH_UNDERSCORES`, with a subsystem prefix, and the -underlying struct tag is the lowercase form of the typedef name -suffixed `_st`: - -```c -typedef struct evp_pkey_st EVP_PKEY; -``` - -For more examples, look in ``. - -When a typedef'd enum is used (see [Structs and typedefs](#structs-and-typedefs) -below for the policy on enums), the enum type name is lowercase -and the values are uppercase. - -Function-pointer and callback typedefs use one of two -suffixes: - -- `_cb` for typedefs that are user-supplied callbacks - (`X509_STORE_CTX_verify_cb`, `pem_password_cb`). -- `_fn` for function pointers in an internal interface or - dispatch table (`OSSL_provider_init_fn`, - `X509_STORE_CTX_verify_fn`). - -When introducing a new type, consider that a bare or generic -name may collide with system or third-party headers; OpenSSL -has historically used unprefixed names like `X509` and these -now collide with Windows headers in places. Prefix new type -names (for example `EVP_PKEY`, `OSSL_PARAM`) to avoid this. - -### Macros and enum labels - -Macros and labels in enums should be named in -`ALL_CAPS_WITH_UNDERSCORES`. This convention helps distinguish -macros from functions and variables. - -```c -#define OPENSSL_MAGIC_FOO 0x12345 -``` - -Error reason codes follow a `SUBSYSTEM_R_REASON` pattern, -where `_R_` is the infix marking the macro as an error reason: -`X509_R_INVALID_TRUST`, `SSL_R_NO_SHARED_CIPHER`, -`ERR_R_MALLOC_FAILURE`. - -Feature-disable macros follow `OPENSSL_NO_` -- for -example, `OPENSSL_NO_SOCK` (no socket support), -`OPENSSL_NO_RSA` (no RSA), `OPENSSL_NO_DEPRECATED__` -(no APIs deprecated as of that version). When defined, the -corresponding feature's headers and implementations are -conditionally compiled out. - -Comments --------- - -This section describes the form and style of code comments. -[DOCUMENTATION.md](DOCUMENTATION.md) is the companion document that -describes the policy: when a comment is required, the *trivial* -exception, and the per-field commenting requirement on structures. - -Use the classic `/* ... */` comment markers. Do not use `// ...` -markers. - -Comments should describe *what* the code does and *why*. Do not -parrot the effect of each statement; well-written code is its own -description of *how*. As the complexity of the code increases, the -size and detail of comments should also increase. Err in favour of -more comments rather than fewer: code that is *obvious* to you -today will not necessarily be obvious to someone else two years -later. - -### Multi-line comment blocks - -The preferred style for long (multi-line) comments is: - -```c -/*- - * This is the preferred style for multi-line - * comments in the OpenSSL source code. - * Please use it consistently. - * - * Description: A column of asterisks on the left side, - * with beginning and ending almost-blank lines. - */ -``` - -Both `/*-` and `/**` are recognised by the `CommentPragmas` setting -in [`.clang-format`](.clang-format) and cause the block to be left -exactly as written. Use `/*-` for plain prose comments whose layout -you want to preserve, and `/**` for doxygen blocks (see below). - -### TODO and FIXME markers - -Use `/* TODO: */` to mark work that should be -done later. Use `/* FIXME: */` to mark a known -incorrectness, hack, or workaround that needs to be addressed. If -a marker is worth adding, the underlying work is worth tracking: -ensure a GitHub issue is opened for it and include the issue's -full URL in the marker (e.g., `/* TODO: -(https://github.com/openssl/openssl/issues/1234) */`). Use the URL -form because OpenSSL has issue trackers in multiple repositories. - -### Doxygen comments - -OpenSSL code uses doxygen-style comments on functions, data -structures, and macros to make the source easier to navigate and to -translate into reference documentation. The internal-function, -struct-field, and other in-source documentation requirements set out -in [DOCUMENTATION.md](DOCUMENTATION.md) must be satisfied with -doxygen-style comments using the conventions described below. - -Use the `@` form of doxygen markers (`@brief`, `@param`, `@returns`, -`@file`, `@def`, `@struct`, and so on). Do not use the `\` form -(`\brief`, `\param`, etc.). - -For the full set of recognised tags and their semantics, see the -Doxygen manual: the [commands list](https://www.doxygen.nl/manual/commands.html) -is the practical reference for what you can write inside a doxygen -block; the chapter on -[documenting the code](https://www.doxygen.nl/manual/docblocks.html) -explains the block forms and where comments attach. - -The following sample illustrates the convention: - -```c -/** - * @file doxysample.c - * This is a brief file description that you may add. - * Subsequent lines contain more detailed information about what you - * will find defined in this file. It is not currently required that - * you add a file description, but it is available if you like. - */ - -/** - * @def MAX(x, y) - * Document a macro that returns the maximum of two inputs. - * @param x integer input value - * @param y integer input value - * @returns the maximum of x and y - */ -#define MAX(x, y) ((x) > (y) ? (x) : (y)) - -/** - * @struct foo_st - * @brief Description of the foo_st struct. - * Optional more detailed description here. - */ -typedef struct foo_st { - int a; /**< Describe the a field here */ - char b; /**< Describe the b field here */ -} FOO; - -/** - * @brief Describe the function ossl_add briefly. - * Add a more detailed description here, like sums two inputs and - * returns the result. - * @param a input integer to add - * @param b input integer to add - * @returns the sum of a and b - */ -int ossl_add(int a, int b); -``` - -#### Spec-mirroring variables - -When a function uses variable names taken from a specification -(see [Functions and variables](#functions-and-variables) in the -Naming section), the doxygen block cites the spec and identifies -each spec-derived variable: - -```c -/** - * @brief Transmogrify Calvin into Hobbes per RFC 31337 section 1.2.3. - * - * Variable naming follows the spec: - * - Calvin: input to be transmogrified - * - Hobbes: transmogrified output (caller-allocated) - * - * @param Calvin pointer to the input bytes to transmogrify - * @param Calvin_len the number of bytes available at Calvin - * @param Hobbes pointer to the caller-allocated output buffer - * @param Hobbes_len the number of bytes available at Hobbes - * @returns 1 on success, 0 on failure - * @see https://www.example.org/rfc/rfc31337.html#section-1.2.3 - * @see https://calvinandhobbes.fandom.com/wiki/Transmogrifier - */ -int ossl_transmogrify(const uint8_t *Calvin, size_t Calvin_len, - uint8_t *Hobbes, size_t Hobbes_len); -``` - -#### Public functions: link the manual page - -Every public function declaration in a public header must carry a -doxygen block that includes an `@see` referencing the function's -manual page in the standard `name(3)` form. This in-source comment -is a navigation aid; the canonical reference documentation lives in -the POD file under `doc/man3/` (see [DOCUMENTATION.md](DOCUMENTATION.md)). - -The cross-reference is to the function name, not the POD file -name; the build emits a man-page entry per function name, so -`man X509_verify_cert` resolves regardless of which POD file -currently documents it. - -```c -/** - * @brief One-line summary of what the function does. - * @see X509_verify_cert(3) - */ -int X509_verify_cert(X509_STORE_CTX *ctx); -``` - -Additional `@see` entries may be added for any manual page a caller -needs in order to use the function correctly, such as pages -documenting argument types, the flag families that affect the -function's behaviour, or closely related functions. List them -comma-separated on a single `@see`, matching the form used in POD's -`SEE ALSO` section: - -```c -/** - * @brief One-line summary of what the function does. - * @see X509_verify_cert(3), X509_STORE_CTX_new(3), - * X509_VERIFY_PARAM_set_flags(3) - */ -int X509_verify_cert(X509_STORE_CTX *ctx); -``` - -The doxygen comment should not duplicate the POD content. Two -copies of "what this function does" inevitably diverge; the POD is -the source of truth. Keep the doxygen block to a short summary and -the `@see` references. - -Structs and typedefs --------------------- - -See [Typedefs](#typedefs) under Naming for naming conventions. - -Typedef'd enums are used much less often than struct typedefs; -consider not using a typedef for an enum at all. A typedef'd -enum hides the integer-ness of the type from the caller, which -makes the implementation-defined underlying type easier to -forget. - -Enum arguments to public functions are not permitted. C's `enum` -underlying type is implementation-defined, and adding values to -an enum can change its ABI; use `int` and document the allowed -values instead. - -OpenSSL has historically made all struct definitions public, which -caused problems with maintaining binary compatibility and adding -features. New structs are opaque and expose only pointers in the -API; the struct definition is placed in a local header file that -is not exported. Legacy structs that are still part of the public -ABI are exempt; do not add new public struct definitions. - -In practice, the opaque pattern is to forward-declare the typedef -in the public header (`typedef struct foo_st FOO;`, with no struct -body) and place the `struct foo_st { ... };` definition in a local -header that is not exported. Callers see only the pointer type. - -Bitfield layout is implementation-defined and varies across -compilers and ABIs. Where that layout is observable -- in structs -that are part of the public ABI or that mirror a wire or file -format -- avoid bitfields and use explicit shifts and masks on a -regular integer instead. - -Flexible array members (C99 trailing `[]`) are permitted and -preferred over the older `[1]` "struct hack" for variable-length -trailing data. Remember that `sizeof(struct)` does not include the -flexible member; allocate the trailing data explicitly when the -struct is created. - -C99 designated initializers (`{ .field = value }`) are encouraged -for struct initialisation, particularly where they make the field -assignments self-documenting. - -A trailing comma in an initializer list is a layout hint to -`clang-format`: with it the list is kept one element per line; -without it the formatter may pack the list onto fewer lines. -Most of the time you do not want a trailing comma; omit it -unless you specifically want to lock the one-per-line layout -(for example, in a multi-row table of values). - -Integers --------- - -Prefer explicitly-sized integers over generic C ones where the -size matters. To represent a byte use `uint8_t`, not -`unsigned char`; for a two-byte field, `uint16_t` rather than -`unsigned short`. - -Avoid `long` and `long long` specifically. `long` is 32 bits on -64-bit Windows and 64 bits on 64-bit Linux; using it for "at -least 32 bits" produces code that works inconsistently across -platforms. Use `int32_t`, `int64_t`, `size_t`, or another -`` type as appropriate. - -Sizes are `size_t`. When converting to or from `int` for legacy -reasons, check for overflow and underflow. - -Add an integer literal suffix when the literal participates in a -shift or appears in an expression involving a wider type -- -without a suffix the literal is `int`. Use `U` for unsigned -semantics (`1U << 31`) and the `UINT8_C` through `UINT64_C` -macros from `` for explicit widths (`UINT32_C(1) << 31`, -`UINT64_C(1) << 63`). Avoid `UL` and `ULL`, for the same reason -as `long` / `long long`: their widths vary by platform. - -Bit shifts should be performed on unsigned operands. -Left-shifting a signed value is undefined behaviour when the -operand is negative or when the result reaches the sign bit; -right-shifting a signed negative value is implementation-defined. -Combined with the literal-suffix rule above, shifts of constants -typically take the form `UINT32_C(1) << n` or `(uint32_t)x << n`. - -In structs that are retained across the lifetime of a connection, -new integer fields whose value range is known should use a smaller -integer type (`uint8_t`, `uint16_t`) where doing so is -straightforward. This reduces per-connection memory in server -processes. Do not make code significantly more complex to achieve -it, and continue to bounds-check at the struct boundary. - -This narrowing should not propagate to local variables or function -parameters; those use the conventional integer types so callers -are not forced to deal with narrow types. - -Do not retroactively narrow existing integer fields in legacy -structs; this risks ABI breakage. - -When doing arithmetic, account for overflow. - -Use `int` with `0` / `1` for boolean values, both in public API -and internal code. Do not introduce `` for new code; -the public API convention is `int`, and using `bool` internally -just to convert to `int` at the API boundary adds friction -without enough benefit. - -Except in platform-specific code, do not use `ssize_t`; MSVC lacks -it. Use `size_t` and signal errors out-of-band (see -[Return values in new code](#return-values-in-new-code)). - -Preprocessor directives ------------------------ - -Headers use traditional include guards in the `#if defined()` -form rather than `#pragma once`, which is non-standard: - -```c -#if !defined(OPENSSL_FOO_H) -#define OPENSSL_FOO_H - -/* ... header contents ... */ - -#endif /* defined(OPENSSL_FOO_H) */ -``` - -Prefer `#if defined(FOO)` and `#if !defined(FOO)` to `#ifdef` and -`#ifndef`. This allows logical operations when conditional -compilation is dependent on more than one variable, without -nesting multiple blocks. - -All `#endif` blocks must have a comment matching their `#if`: - -```c -#if defined(OPENSSL_LINUX) && (!defined(OPENSSL_NO_HOOBLA) || !defined(OPENSSL_BULA)) -... -#endif /* defined(OPENSSL_LINUX) && (!defined(OPENSSL_NO_HOOBLA) || !defined(OPENSSL_BULA)) */ -``` - -Minimise the footprint of conditional compilation in source -code: the more conditional code is concentrated and confined, -the easier the unconditional flow is to read. - -Concentrate conditional compilation rather than dispersing it. -Do not duplicate the same OS-dispatch ladder across the -codebase: - -```c -#if defined(OPENSSL_OS_FOO) || defined(OPENSSL_OS_BAR) - stuff the way foo or bar does it; -#elif defined(OPENSSL_OS_BLAH) || defined(OPENSSL_OS_WOOF) - stuff the way blah or woof does it; -#endif /* defined(OPENSSL_OS_FOO) || defined(OPENSSL_OS_BAR) */ -``` - -For OS-dependent code in particular, put the directives inside -a single function that wraps the OS-dependent work, so callers -see a clean interface. When the OS-dependent implementations -are large, put them in separate files (`stuff_foo.c`, -`stuff_blah.c`) implementing a common function and select the -appropriate file via the build process; this lets non-mainstream -platforms add an implementation file without patching shared -code. - -When a feature can be compiled out, prefer to provide a no-op -stub implementation of its functions in the disabled case -rather than wrapping every call site in `#if`. Callers then -invoke the functions unconditionally and the compiler discards -the stubs: - -```c -#if defined(OPENSSL_NO_FOO) -static ossl_inline int ossl_foo_init(void) { return 1; } -static ossl_inline void ossl_foo_cleanup(void) { } -#else -int ossl_foo_init(void); -void ossl_foo_cleanup(void); -#endif /* defined(OPENSSL_NO_FOO) */ -``` - -Macros and enums ----------------- - -**Just use a function, not a macro.** OpenSSL has historically -used macros heavily to avoid function-call overhead, but modern -compilers inline well; the trade-offs that justified that pattern -no longer apply. Where a macro is genuinely unavoidable, the -rules below apply. - -For the naming convention used for macros and enum labels, see the -[Macros and enum labels](#macros-and-enum-labels) subsection of -Naming above. - -Enums are preferred when defining several related constants. -Enum arguments to public functions are not permitted, because -C's `enum` underlying type is implementation-defined and adding -values can change ABI; see -[Structs and typedefs](#structs-and-typedefs) for the rule and -the canonical alternative (use `int` and document the allowed -values). - -Where the constants need a fixed underlying width (for ABI or -wire-format reasons), use `#define` or `static const` with an -explicit-width type from `` instead, since enum width -is implementation-defined. - -### Avoid complex macros - -Avoid complex or clever macros: they are hard to read, debug, and -maintain. Do not nest macros calling other macros. - -### Avoid function-like macros - -Prefer functions over function-like macros. Do not optimise for -function-call overhead without first measuring with a function -implementation; if the function is hot enough to need inlining, -mark it `ossl_inline` rather than converting it to a macro. - -### Macro parenthesisation - -Always parenthesise arguments in function-like macros to prevent -operator-precedence issues during expansion. Enclose the entire -macro definition in parentheses if it expands to an expression, so -the expansion evaluates correctly inside larger expressions. For -example: - -```c -#define BOB(blah) ((blah) + 42 - 23) -``` - -### Multi-statement macros - -Enclose multi-statement macros in a `do { } while (0)` block. Do -not include a semicolon at the end, and do not use bare braces -(which fail when followed by `else`). For example: - -```c -/* This is bad. */ -#define KERMIT(x) muppet((x)); frog((x)); green((x)) -if (something) - KERMIT(bob); -else /* This now breaks. */ - -/* This is also bad, because now you have to omit the semicolon. */ -#define KERMIT(x) { muppet((x)); frog((x)); green((x)) } -if (something) - KERMIT(bob) /* No semicolon. */ -else - -/* This works. */ -#define KERMIT(x) do { muppet((x)); frog((x)); green((x)) } while (0) -if (something) - KERMIT(bob); -else - -/* - * But just use a function -- now we know that x is an integer that - * has something to do with frogginess and we gain some type safety. - */ -static void kermit(int frogginess) -{ - muppet(frogginess); - frog(frogginess); - green(frogginess); -} -if (something) - kermit(bob); -else -``` - -### Do not include files as multi-line macros - -Do not put code in a file and include it inline: - -```c - ... - printf("Yolo\n"); -#include "./abagfullofcode.inc" - printf("That was fun\n"); - ... -``` - -Either make a function out of the code and call it, or put the code -in place. - -### Be careful with macro arguments that have side effects - -Be careful when writing a function-like macro that could be called -with arguments that have side effects. Because a macro may expand an -argument more than once, a side-effecting argument (`n++`, a function -call, a volatile access) can then be evaluated more than once, with -unexpected results: - -```c -#define SQUARE(x) ((x) * (x)) - -int n = 1; -int result = SQUARE(n++); /* expands to ((n++) * (n++)) -- evaluates twice */ -``` - -Where it can reasonably be avoided, prefer a form that expands each -argument exactly once -- a function, or an `ossl_inline` function -for a fixed type. If there is any doubt that your function-like -macro could be called with arguments that have side effects, treat -that as a sign to follow the advice in -[Avoid function-like macros](#avoid-function-like-macros) and make -it a real function. Some macros cannot avoid it: a type-generic macro -such as `MAX` must name each operand and so evaluates it more than -once. When that is unavoidable, say so at the definition and avoid -passing side-effecting expressions at the call site. - -### Avoid macros that depend on magic names - -Do not write macros that rely on a particular variable name being -in scope at the call site: - -```c -#define FOO(val) bar(index, (val)) /* requires `index' to exist */ -``` - -This is confusing to the reader and prone to breakage from -seemingly innocent changes. - -### Avoid macros that expand to l-values - -Do not write a macro that expands to something assignable: - -```c -#define FIELD(p) (((struct foo *)(p))->field) - -FIELD(x) = y; /* legal C, but the macro hides the assignment */ -``` - -Use an accessor function or expose the field directly through a -typed pointer. - -### Avoid macros that affect control flow - -Do not write macros that `return`, `goto`, `break`, or `continue` -out of their expansion. Such macros hide control flow from a -reader at the call site, who sees what looks like a function -call but which may exit the surrounding function or jump out of -a loop: - -```c -#define RETURN_IF_NULL(p) do { if ((p) == NULL) return -1; } while (0) - -int ossl_frobnicate(void *p) -{ - RETURN_IF_NULL(p); /* may return from ossl_frobnicate() -- not visible at the call site */ - /* ... */ -} -``` - -### Avoid `#` and `##` in new code - -The stringification (`#`) and token-pasting (`##`) operators are -forbidden in new code. Existing macros that use them (notably the -`DECLARE_*` and `IMPLEMENT_*` macro families) are not retroactively -changed; new code should achieve the same effect through -functions. - -### Use variadic macros sparingly - -Variadic macros (`__VA_ARGS__`) are permitted but should be used -sparingly: prefer a function or a small set of helper functions -where possible. They are harder to reason about and debug than -functions, and the rules around zero variadic arguments and -`__VA_ARGS__` forwarding are subtle. - -Functions ---------- - -A function should do one thing and be short enough that a -reader can hold its behaviour in their head while reading it. -Length follows from complexity, not the other way around: a -long but flat function (for example, a single switch dispatching -to many cases) is fine; a short function with three levels of -nested control flow is not. - -When complexity grows, factor out helpers with descriptive -names. A large number of local variables is a signal that this -factoring is overdue; consider splitting before reaching for a -comment to explain the variables. Performance-critical helpers -can be marked `inline`; see -[Avoid function-like macros](#avoid-function-like-macros) for -why this is preferable to a macro. - -In function prototypes, include parameter names alongside their -types. C does not require this, but it carries useful information -for the reader; the name in the prototype should match the name -in the definition. - -### Functions with no arguments - -A function that takes no arguments must declare so explicitly -with `void` in its parameter list: `int f(void);`, not -`int f();`. The latter declares the parameter list as -unspecified and prevents the compiler from checking calls. - -### Internal linkage - -Functions that are local to a single source file are declared -`static`. Static functions need no `ossl_` prefix (see -[Naming](#functions-and-variables) above) and do not appear in -the symbol table of the resulting object file. - -### Parameter ordering - -In OpenSSL's API style, a context parameter (an `SSL_CTX *`, -`EVP_PKEY_CTX *`, `OSSL_LIB_CTX *`, or similar) is the first -parameter. The order of the remaining parameters is at the -function's discretion but should be consistent with similar -functions in the same subsystem. - -### `const`-correctness - -Pointer parameters that are not modified by the function should -be declared `const`; likewise, pointer return values that the -caller must not modify should be declared `const`. The -return-side rule pairs with the `get0_X()` ownership convention: -a non-owning pointer is typically a read-only view, while an -owning pointer returned by `get1_X()` is non-`const` because the -caller controls it. The `const` qualifier documents the contract, -allows callers to pass or receive `const`-qualified data without -casts, and lets the compiler catch accidental modification. - -### Return values in legacy code - -Historically, functions in OpenSSL can return values of many different -kinds, and one of the most common is a value indicating whether the -function succeeded or failed. Usually this is: - -- `1`: success -- `0`: failure - -Other patterns appear in legacy code: - -- `-1` indicates a serious error (internal error or memory - allocation failure), and in some subsystems (BIO, SSL, etc.) - means "should retry" -- `>= 1` indicates success with the value carrying additional - information; `<= 0` indicates failure with the value indicating - the reason - -Functions that return a computed value (not a success/failure -indicator) are exempt. - -**Read the existing return-value contract carefully before -modifying legacy code.** OpenSSL's legacy return-value -conventions are not uniform -- a function may use values, -overloadings, or semantics outside the patterns above -- and -bugs have been introduced into OpenSSL when contributors -assumed a function followed a familiar pattern when it did not. -The contract is part of the API, not just a stylistic choice. - -### Return values in new code - -For new code, functions should return `int` with `1` on success -and `0` on error. Do not overload the return value to both -signal success/failure and output an integer. For example: - -```c -/** - * @brief ossl_snuffle_thingamabob snuffles a thingamabob from bytes of input. - * If a valid thingamabob is snuffled, the result is stored in - * *out_thingamabob. On failure a snuffling error code is stored - * in *out_err. - * @param input pointer to the bytes to snuffle - * @param input_len the number of bytes available to snuffle from input - * @param out_err pointer to an integer to store an error code - * @param out_thingamabob pointer to a thingamabob to store the output - * @returns 1 if a thingamabob was snuffled and stored, 0 otherwise. - */ -int ossl_snuffle_thingamabob(const uint8_t *input, size_t input_len, - int *out_err, thingamabob *out_thingamabob); -``` - -If a function outputs a single pointer and no other values, -return the pointer directly, with `NULL` on error. - -### Checking function arguments - -A public function must verify that its arguments are sensible -and return its documented failure value if they are not. -Typical checks include: - -- non-optional pointer arguments are not NULL; -- numeric arguments are within their expected ranges. - -Public-API callers are outside the OpenSSL development envelope. -The contract cannot be enforced through code review, so a NULL -non-optional pointer or an out-of-range integer is a possibility -that must be handled defensively at the boundary. Failing with a -documented error code on the error stack is preferable to a -SIGSEGV in the calling application's process. - -For NULL pointer arguments, the canonical pattern is: - -```c -if (arg == NULL) { - ERR_raise(ERR_LIB_, ERR_R_PASSED_NULL_PARAMETER); - return 0; -} -``` - -Use the function's documented failure value in place of `0` -where it differs (`NULL` for pointer-returning functions, `-1` -for functions that may return `-1`, and so on). - -Internal functions must not repeat these checks. Their callers -are us; the contract is enforceable in code review, and a NULL -or out-of-range argument is a programmer error of the same -character as the impossibilities discussed under -[Assertions](#assertions). A runtime check at an internal call -site is dead on any correct execution, and the untested branch -is itself attack surface. Use `assert()` instead where you want -to document an internal invariant. - -### Extending existing functions - -When an existing public function needs additional parameters, -keep the original and add a new function with the same name plus -an `_ex` suffix (`RAND_bytes_ex` extends `RAND_bytes`). Further -extensions use `_ex2`, `_ex3`, and so on. - -The extended function preserves the existing parameters in their -existing order. New parameters may be inserted at any position -(they do not have to be at the end); parameters that are no -longer needed may be removed. - -### Centralised exiting of functions - -When a function exits from multiple locations and some common -work (such as cleanup) has to be done at every exit, use `goto` -to a single exit label. Return directly when there is no cleanup -to do. The rationale: - -- a single exit point is easier to read and follow; -- it reduces excessive control structures and nesting; -- it avoids errors caused by failing to update multiple exit - points when the code changes; -- it lets the compiler avoid emitting redundant cleanup code. - -For example: - -```c -int ossl_do_thing(const uint8_t *in, size_t in_len) -{ - int ret = 0; - uint8_t *buf = OPENSSL_malloc(in_len); - - if (buf == NULL) - return 0; - - if (!ossl_step1(in, in_len, buf)) - goto out; - if (!ossl_step2(buf, in_len)) - goto out; - - ret = 1; -out: - OPENSSL_free(buf); - return ret; -} -``` - -Error reporting ---------------- - -OpenSSL surfaces errors through a per-thread error stack; see -`ERR_raise(3)` for the calls and `include/openssl/err.h` for the -available reason codes. This section describes the conventions -for using them. - -Raise at the leaf. The function that detects the failure pushes -the error; intermediate wrappers that propagate the failure -value must not re-raise. Re-raising on each frame floods the -stack with duplicates and obscures the originating condition. - -Use the `ERR_LIB_` corresponding to the function's -home directory (`ERR_LIB_X509` in code under `crypto/x509/`, and -so on). Use a cross-library reason (`ERR_R_PASSED_NULL_PARAMETER`, -`ERR_R_MALLOC_FAILURE`, `ERR_R_INTERNAL_ERROR`, and others) for -portable failure modes; use a `SUBSYSTEM_R_REASON` -(`X509_R_INVALID_TRUST`, etc.) for domain-specific ones. - -Do not call `ERR_clear_error` at function entry; the error stack -belongs to the caller, who may have pushed errors before -invoking you that they intend to inspect. - -Use `ERR_set_mark` / `ERR_pop_to_mark` to suppress error-stack -pollution from operations expected to fail sometimes (a -speculative parse, a capability probe), leaving earlier errors -intact. - -Allocating memory ------------------ - -Use the `OPENSSL_malloc` family for general allocation; see -`OPENSSL_malloc(3)` for the full set of calls. Do not mix these -with the C standard library's `malloc()` / `free()` family; -allocations made with one set must be released with the matching -set, and OpenSSL can be built with custom allocator hooks that -the C library does not know about. - -For arrays, use `OPENSSL_malloc_array()` and -`OPENSSL_realloc_array()`, which take the element size and -element count separately and check for integer overflow. - -Memory holding sensitive material (key bytes, plaintext, -internal state of cryptographic primitives) must be cleansed -before release. `OPENSSL_clear_free()` combines cleansing and -freeing; `OPENSSL_cleanse()` wipes without freeing. For -long-lived sensitive data, use the `OPENSSL_secure_malloc()` -family (`OPENSSL_secure_malloc(3)`), which allocates from a -separate non-pageable secure heap, and release with -`OPENSSL_secure_clear_free()`. - -An API that owns internal state requires both an initialisation -function to set it up and a completion function to release it. -This is the standard constructor/destructor pair for opaque -types; see [Structs and typedefs](#structs-and-typedefs). - -Processor-specific code ------------------------ - -The only reason for processor-specific code in OpenSSL is -performance. Every processor-specific path must have a -platform-neutral pure-C implementation as a fallback, because -not every target architecture or build configuration enables -the processor-specific path. OpenSSL selects between -implementations at runtime via the CPU-capability detection in -`OPENSSL_cpuid_setup` and the `OPENSSL_*` capability flags; -processor-specific code must integrate with this dispatch. - -Cryptographic primitives operating on secret data must execute -in time independent of those secrets. Avoid secret-dependent -branches, secret-indexed memory accesses, and variable-time -arithmetic (such as variable-time multiplication or division) -on words derived from secrets. Hand-coded asm is sometimes used -specifically to force a particular sequence of constant-time -operations that a compiler might otherwise rewrite. - -Short processor-specific operations are typically written as -inline assembly. Use a `static inline` function when the asm -constraints permit it. When the asm requires a compile-time -constant operand (an `i` constraint), use a statement-expression -macro instead, because a function parameter does not satisfy the -immediate-constant constraint. When `asm()` has side effects the -compiler cannot see, mark it `volatile`; do not mark `volatile` -unnecessarily as that limits optimisation. - -When writing a single inline assembly statement containing -multiple instructions, put each instruction on a separate line -in a separate quoted string, and end each string except the -last with `\n\t` to properly indent the next instruction in the -assembly output: - -```c -asm("magic %reg1, #42\n\t" - "more_magic %reg2, %reg3" - : /* outputs */ : /* inputs */ : /* clobbers */); -``` - -Large, non-trivial assembly functions go in pure assembly -modules, with corresponding C prototypes. The preferred way to -generate these is *perlasm*: a Perl script that generates a -`.s` file. Perlasm allows symbolic names for variables -(registers and stack-allocated locals) that are independent of -the specific assembler, and supports multiple ABIs and -assemblers from a single source by adhering to its coding -rules. See `crypto/perlasm/x86_64-xlate.pl` for an example. - -Compiler intrinsics are permitted but used sparingly. They are -appropriate for self-contained SIMD acceleration where the -intrinsic vocabulary is well-supported across our target -compilers and the code does not need to span multiple ABIs -- -`crypto/evp/enc_b64_avx2.c` (AVX2 base64) is an example. -Intrinsics are not appropriate for cryptographic primitives -where constant-time execution is required (the compiler may -reorder, branch, or otherwise alter the timing), or where an -existing perlasm implementation already covers the multi-ABI -case. - -Assertions ----------- - -Assertions check programmer errors -- invariants, preconditions, and -postconditions that must hold in any correctly-functioning build. -They are not for runtime conditions such as allocation failure, I/O -errors, or malformed input from callers; those are errors the -surrounding code must handle and propagate. - -OpenSSL provides three assertion forms, which differ in their -behaviour depending on whether `NDEBUG` is defined (release) or not -(debug): - -| Form | Failure (debug) | Failure (release) | Success | -|---|---|---|---| -| `assert(e)` | abort | `e` not evaluated | no effect | -| `ossl_assert(e)` | abort | returns 0 | returns 1 | -| `OPENSSL_assert(e)` | abort | abort | no effect | - -Choosing between these forms is a trade-off, not a default. Each -form pays a cost somewhere: - -- `OPENSSL_assert()` terminates the host process when an invariant - fails, which is hostile to applications that link against - OpenSSL. -- `ossl_assert()` returns failure in release builds so the host - process survives, but the caller must then handle a failure for - a condition that, by definition, cannot occur in correct code. - That handling code is dead on any correct execution and cannot - be exercised by ordinary tests; untested branches accumulate - their own bugs and become part of the attack surface. -- `assert()` is silently dropped in release builds, so an invariant - violation in production passes through to downstream code that - may then operate on inconsistent state. - -Use `ossl_assert()` when the surrounding function already returns -success/failure and the recovery path collapses naturally into the -function's existing error path: push an internal error and return -the function's failure value. The recovery code is then colocated -with tested error handling and is not a structurally new branch: - -```c -if (!ossl_assert(invariant_holds)) { - ERR_raise(ERR_LIB_..., ERR_R_INTERNAL_ERROR); - return 0; -} -``` - -Use `assert()` for impossible cases in internal code -- typically -`switch` defaults, unreachable branches in helpers, and invariants -local to a function whose contract makes the violation strictly -impossible. The release-build behaviour ("do nothing") is the -right choice here, because the alternative is untested recovery -code for a case that cannot occur, and that code is itself a -hazard. The assertion expression must be free of side effects, -because `assert()` does not evaluate it in release builds. - -Use `OPENSSL_assert()` only when continued execution would be more -dangerous than termination -- typically when global library state -is irrecoverably corrupted -- or in applications, test programs, -and fuzzers where termination on a failed check is desired. -`OPENSSL_assert()` aborts in all builds, including production. diff --git a/VERSION.dat b/VERSION.dat index d3538fb9e7..def9fedb1c 100644 --- a/VERSION.dat +++ b/VERSION.dat @@ -1,5 +1,5 @@ MAJOR=4 -MINOR=1 +MINOR=0 PATCH=0 PRE_RELEASE_TAG=dev BUILD_METADATA= diff --git a/VMS/VMSify-conf.pl b/VMS/VMSify-conf.pl index bc7392fde3..a3844e505c 100644 --- a/VMS/VMSify-conf.pl +++ b/VMS/VMSify-conf.pl @@ -10,7 +10,7 @@ use strict; use warnings; -my @directory_vars = ( "dir", "certs", "new_certs_dir" ); +my @directory_vars = ( "dir", "certs", "crl_dir", "new_certs_dir" ); my @file_vars = ( "database", "certificate", "serial", "crlnumber", "crl", "private_key", "RANDFILE" ); while() { diff --git a/VMS/openssl_utils.com.in b/VMS/openssl_utils.com.in index 4369711a21..900d0462c5 100644 --- a/VMS/openssl_utils.com.in +++ b/VMS/openssl_utils.com.in @@ -5,3 +5,10 @@ $ v := {- sprintf "%02d", split(/\./, $config{version}) -} $ $ OPENSSL'v' :== $OSSL$EXE:OPENSSL'v' $ OPENSSL :== $OSSL$EXE:OPENSSL'v' +$ +$ IF F$TYPE(PERL) .EQS. "STRING" +$ THEN +$ C_REHASH :== 'PERL' OSSL$EXE:c_rehash.pl +$ ELSE +$ WRITE SYS$ERROR "NOTE: no perl => no C_REHASH" +$ ENDIF diff --git a/apps/asn1parse.c b/apps/asn1parse.c index b8449762fe..fbd9d7c334 100644 --- a/apps/asn1parse.c +++ b/apps/asn1parse.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -82,9 +82,8 @@ int asn1parse_main(int argc, char **argv) const unsigned char *ctmpbuf; int indent = 0, noout = 0, dump = 0, informat = FORMAT_PEM; int offset = 0, ret = 1, i, j; - long num; - size_t tmplen; - const unsigned char *tmpbuf; + long num, tmplen; + unsigned char *tmpbuf; unsigned int length = 0; OPTION_CHOICE o; const ASN1_ITEM *it = NULL; @@ -193,7 +192,7 @@ int asn1parse_main(int argc, char **argv) goto end; if (genconf == NULL && genstr == NULL && informat == FORMAT_PEM) { if (PEM_read_bio(in, &name, &header, &str, &num) != 1) { - BIO_puts(bio_err, "Error reading PEM file\n"); + BIO_printf(bio_err, "Error reading PEM file\n"); ERR_print_errors(bio_err); goto end; } @@ -242,12 +241,12 @@ int asn1parse_main(int argc, char **argv) if (sk_OPENSSL_STRING_num(osk)) { tmpbuf = str; - tmplen = (size_t)num; + tmplen = num; for (i = 0; i < sk_OPENSSL_STRING_num(osk); i++) { ASN1_TYPE *atmp; int typ; j = strtol(sk_OPENSSL_STRING_value(osk, i), NULL, 0); - if (j <= 0 || (size_t)j >= tmplen) { + if (j <= 0 || j >= tmplen) { BIO_printf(bio_err, "'%s' is out of range\n", sk_OPENSSL_STRING_value(osk, i)); continue; @@ -256,10 +255,10 @@ int asn1parse_main(int argc, char **argv) tmplen -= j; atmp = at; ctmpbuf = tmpbuf; - at = d2i_ASN1_TYPE(NULL, &ctmpbuf, (long)tmplen); + at = d2i_ASN1_TYPE(NULL, &ctmpbuf, tmplen); ASN1_TYPE_free(atmp); if (!at) { - BIO_puts(bio_err, "Error parsing structure\n"); + BIO_printf(bio_err, "Error parsing structure\n"); ERR_print_errors(bio_err); goto end; } @@ -272,21 +271,15 @@ int asn1parse_main(int argc, char **argv) goto end; } /* hmm... this is a little evil but it works */ - tmpbuf = ASN1_STRING_get0_data(at->value.asn1_string); - tmplen = ASN1_STRING_length_ex(at->value.asn1_string); - if (tmplen > INT_MAX) { - BIO_puts(bio_err, "ASN.1 string length exceeds INT_MAX\n"); - ERR_print_errors(bio_err); - goto end; - } + tmpbuf = at->value.asn1_string->data; + tmplen = at->value.asn1_string->length; } - /* XXX casts away const */ - str = (unsigned char *)tmpbuf; - num = (int)tmplen; + str = tmpbuf; + num = tmplen; } if (offset < 0 || offset >= num) { - BIO_puts(bio_err, "Error: offset out of range\n"); + BIO_printf(bio_err, "Error: offset out of range\n"); goto end; } @@ -296,7 +289,7 @@ int asn1parse_main(int argc, char **argv) length = (unsigned int)num; if (derout != NULL) { if (BIO_write(derout, str + offset, length) != (int)length) { - BIO_puts(bio_err, "Error writing output\n"); + BIO_printf(bio_err, "Error writing output\n"); ERR_print_errors(bio_err); goto end; } diff --git a/apps/build.info b/apps/build.info index 5b550b836e..976a24d71b 100644 --- a/apps/build.info +++ b/apps/build.info @@ -18,7 +18,6 @@ $OPENSSLSRC=\ pkcs8.c pkey.c pkeyparam.c pkeyutl.c prime.c rand.c req.c \ s_client.c s_server.c s_time.c sess_id.c skeyutl.c smime.c speed.c \ spkac.c verify.c version.c x509.c rehash.c storeutl.c \ - ech.c \ list.c info.c fipsinstall.c pkcs12.c IF[{- !$disabled{'ec'} -}] $OPENSSLSRC=$OPENSSLSRC ec.c ecparam.c diff --git a/apps/ca.c b/apps/ca.c index 8f98bc9a6a..07d8ef23b9 100644 --- a/apps/ca.c +++ b/apps/ca.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -25,8 +25,6 @@ #include #include -#include - #ifndef W_OK #ifdef OPENSSL_SYS_VMS #include @@ -72,6 +70,7 @@ #define ENV_POLICY "policy" #define ENV_EXTENSIONS "x509_extensions" #define ENV_CRLEXT "crl_extensions" +#define ENV_MSIE_HACK "msie_hack" #define ENV_NAMEOPT "name_opt" #define ENV_CERTOPT "cert_opt" #define ENV_EXTCOPY "copy_extensions" @@ -142,6 +141,7 @@ static void write_new_certificate(BIO *bp, X509 *x, int output_der, int notext); static CONF *extfile_conf = NULL; static int preserve = 0; +static int msie_hack = 0; typedef enum OPTION_choice { OPT_COMMON, @@ -176,6 +176,7 @@ typedef enum OPTION_choice { OPT_PRESERVEDN, OPT_NOEMAILDN, OPT_GENCRL, + OPT_MSIE_HACK, OPT_CRL_LASTUPDATE, OPT_CRL_NEXTUPDATE, OPT_CRLDAYS, @@ -220,6 +221,8 @@ const OPTIONS ca_options[] = { { "dateopt", OPT_DATEOPT, 's', "Datetime format used for printing. (rfc_822/iso_8601). Default is rfc_822." }, { "notext", OPT_NOTEXT, '-', "Do not print the generated certificate" }, { "batch", OPT_BATCH, '-', "Don't ask questions" }, + { "msie_hack", OPT_MSIE_HACK, '-', + "msie modifications to handle all Universal Strings" }, { "ss_cert", OPT_SS_CERT, '<', "File contains a self signed cert to sign" }, { "spkac", OPT_SPKAC, '<', "File contains DN and signed public key and challenge" }, @@ -408,7 +411,7 @@ int ca_main(int argc, char **argv) enddate = opt_arg(); break; case OPT_DAYS: - days = opt_int_arg(); + days = atoi(opt_arg()); break; case OPT_MD: dgst = opt_arg(); @@ -477,6 +480,9 @@ int ca_main(int argc, char **argv) case OPT_GENCRL: gencrl = 1; break; + case OPT_MSIE_HACK: + msie_hack = 1; + break; case OPT_CRL_LASTUPDATE: crl_lastupdate = opt_arg(); break; @@ -617,7 +623,7 @@ end_of_options: if (passin == NULL) { free_passin = 1; if (!app_passwd(passinarg, NULL, &passin, NULL)) { - BIO_puts(bio_err, "Error getting password\n"); + BIO_printf(bio_err, "Error getting password\n"); goto end; } } @@ -639,7 +645,7 @@ end_of_options: goto end; if (!X509_check_private_key(x509, pkey)) { - BIO_puts(bio_err, + BIO_printf(bio_err, "CA certificate and CA private key do not match\n"); goto end; } @@ -650,6 +656,9 @@ end_of_options: f = app_conf_try_string(conf, BASE_SECTION, ENV_PRESERVE); if (f != NULL && (*f == 'y' || *f == 'Y')) preserve = 1; + f = app_conf_try_string(conf, BASE_SECTION, ENV_MSIE_HACK); + if (f != NULL && (*f == 'y' || *f == 'Y')) + msie_hack = 1; f = app_conf_try_string(conf, section, ENV_NAMEOPT); if (f != NULL) { @@ -683,7 +692,7 @@ end_of_options: outdir = NCONF_get_string(conf, section, ENV_NEW_CERTS_DIR); if (outdir == NULL) { - BIO_puts(bio_err, + BIO_printf(bio_err, "there needs to be defined a directory for new certificate to be placed in\n"); goto end; } @@ -756,7 +765,7 @@ end_of_options: TXT_DB_write(bio_out, db->db); BIO_printf(bio_err, "%d entries loaded from the database\n", sk_OPENSSL_PSTRING_num(db->db->data)); - BIO_puts(bio_err, "generating index\n"); + BIO_printf(bio_err, "generating index\n"); } if (index_index(db) <= 0) @@ -770,11 +779,11 @@ end_of_options: i = do_updatedb(db, NULL); if (i == -1) { - BIO_puts(bio_err, "Malloc failure\n"); + BIO_printf(bio_err, "Malloc failure\n"); goto end; } else if (i == 0) { if (verbose) - BIO_puts(bio_err, "No entries found to mark expired\n"); + BIO_printf(bio_err, "No entries found to mark expired\n"); } else { if (!save_index(dbfile, "new", db)) goto end; @@ -871,8 +880,11 @@ end_of_options: X509V3_CTX ctx; X509V3_set_ctx_test(&ctx); - if (!do_EXT_add_nconf(extfile_conf, extfile_conf, &ctx, NULL, - "Error checking certificate extensions from extfile section %s\n", extensions)) { + X509V3_set_nconf(&ctx, extfile_conf); + if (!X509V3_EXT_add_nconf(extfile_conf, &ctx, extensions, NULL)) { + BIO_printf(bio_err, + "Error checking certificate extensions from extfile section %s\n", + extensions); ret = 1; goto end; } @@ -888,8 +900,11 @@ end_of_options: X509V3_CTX ctx; X509V3_set_ctx_test(&ctx); - if (!do_EXT_add_nconf(conf, conf, &ctx, NULL, - "Error checking certificate extension config section %s\n", extensions)) { + X509V3_set_nconf(&ctx, conf); + if (!X509V3_EXT_add_nconf(conf, &ctx, extensions, NULL)) { + BIO_printf(bio_err, + "Error checking certificate extension config section %s\n", + extensions); ret = 1; goto end; } @@ -905,27 +920,27 @@ end_of_options: days = 0; } if (enddate == NULL && days == 0) { - BIO_puts(bio_err, "cannot lookup how many days to certify for\n"); + BIO_printf(bio_err, "cannot lookup how many days to certify for\n"); goto end; } if (days != 0 && enddate != NULL) - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: -enddate or -not_after option overriding -days option\n"); if (rand_ser) { if ((serial = BN_new()) == NULL || !rand_serial(serial, NULL)) { - BIO_puts(bio_err, "error generating serial number\n"); + BIO_printf(bio_err, "error generating serial number\n"); goto end; } } else { serial = load_serial(serialfile, NULL, create_ser, NULL); if (serial == NULL) { - BIO_puts(bio_err, "error while loading serial number\n"); + BIO_printf(bio_err, "error while loading serial number\n"); goto end; } if (verbose) { if (BN_is_zero(serial)) { - BIO_puts(bio_err, "next serial number is 00\n"); + BIO_printf(bio_err, "next serial number is 00\n"); } else { if ((f = BN_bn2hex(serial)) == NULL) goto end; @@ -941,7 +956,7 @@ end_of_options: } if ((cert_sk = sk_X509_new_null()) == NULL) { - BIO_puts(bio_err, "Memory allocation failure\n"); + BIO_printf(bio_err, "Memory allocation failure\n"); goto end; } if (spkac_file != NULL) { @@ -955,11 +970,11 @@ end_of_options: goto end; if (j > 0) { total_done++; - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); if (!BN_add_word(serial, 1)) goto end; if (!sk_X509_push(cert_sk, x)) { - BIO_puts(bio_err, "Memory allocation failure\n"); + BIO_printf(bio_err, "Memory allocation failure\n"); goto end; } } @@ -976,11 +991,11 @@ end_of_options: goto end; if (j > 0) { total_done++; - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); if (!BN_add_word(serial, 1)) goto end; if (!sk_X509_push(cert_sk, x)) { - BIO_puts(bio_err, "Memory allocation failure\n"); + BIO_printf(bio_err, "Memory allocation failure\n"); goto end; } } @@ -996,11 +1011,11 @@ end_of_options: goto end; if (j > 0) { total_done++; - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); if (!BN_add_word(serial, 1)) goto end; if (!sk_X509_push(cert_sk, x)) { - BIO_puts(bio_err, "Memory allocation failure\n"); + BIO_printf(bio_err, "Memory allocation failure\n"); goto end; } } @@ -1017,13 +1032,13 @@ end_of_options: goto end; if (j > 0) { total_done++; - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); if (!BN_add_word(serial, 1)) { X509_free(x); goto end; } if (!sk_X509_push(cert_sk, x)) { - BIO_puts(bio_err, "Memory allocation failure\n"); + BIO_printf(bio_err, "Memory allocation failure\n"); X509_free(x); goto end; } @@ -1042,12 +1057,12 @@ end_of_options: (void)BIO_flush(bio_err); tmp[0] = '\0'; if (fgets(tmp, sizeof(tmp), stdin) == NULL) { - BIO_puts(bio_err, "CERTIFICATION CANCELED: I/O error\n"); + BIO_printf(bio_err, "CERTIFICATION CANCELED: I/O error\n"); ret = 0; goto end; } if (tmp[0] != 'y' && tmp[0] != 'Y') { - BIO_puts(bio_err, "CERTIFICATION CANCELED\n"); + BIO_printf(bio_err, "CERTIFICATION CANCELED\n"); ret = 0; goto end; } @@ -1070,26 +1085,26 @@ end_of_options: #endif if (verbose) - BIO_puts(bio_err, "writing new certificates\n"); + BIO_printf(bio_err, "writing new certificates\n"); for (i = 0; i < sk_X509_num(cert_sk); i++) { BIO *Cout = NULL; X509 *xi = sk_X509_value(cert_sk, i); const ASN1_INTEGER *serialNumber = X509_get0_serialNumber(xi); const unsigned char *psn = ASN1_STRING_get0_data(serialNumber); - const size_t snl = ASN1_STRING_length_ex(serialNumber); - const size_t filen_len = 2 * (snl > 0 ? snl : 1) + sizeof(".pem"); + const int snl = ASN1_STRING_length(serialNumber); + const int filen_len = 2 * (snl > 0 ? snl : 1) + sizeof(".pem"); char *n = new_cert + outdirlen; if (outdirlen + filen_len > PATH_MAX) { - BIO_puts(bio_err, "certificate file name too long\n"); + BIO_printf(bio_err, "certificate file name too long\n"); goto end; } if (snl > 0) { static const char HEX_DIGITS[] = "0123456789ABCDEF"; - for (j = 0; (size_t)j < snl; j++, psn++) { + for (j = 0; j < snl; j++, psn++) { *n++ = HEX_DIGITS[*psn >> 4]; *n++ = HEX_DIGITS[*psn & 0x0F]; } @@ -1131,7 +1146,7 @@ end_of_options: if (!rotate_index(dbfile, "new", "old")) goto end; - BIO_puts(bio_err, "Database updated\n"); + BIO_printf(bio_err, "Database updated\n"); } } @@ -1146,8 +1161,10 @@ end_of_options: X509V3_CTX ctx; X509V3_set_ctx_test(&ctx); - if (!do_EXT_add_nconf(conf, conf, &ctx, NULL, - "Error checking CRL extension section %s\n", crl_ext)) { + X509V3_set_nconf(&ctx, conf); + if (!X509V3_EXT_add_nconf(conf, &ctx, crl_ext, NULL)) { + BIO_printf(bio_err, + "Error checking CRL extension section %s\n", crl_ext); ret = 1; goto end; } @@ -1157,7 +1174,7 @@ end_of_options: if (crlnumberfile != NULL) { if ((crlnumber = load_serial(crlnumberfile, NULL, 0, NULL)) == NULL) { - BIO_puts(bio_err, "error while loading CRL number\n"); + BIO_printf(bio_err, "error while loading CRL number\n"); goto end; } } @@ -1171,13 +1188,13 @@ end_of_options: crlhours = 0; } if ((crl_nextupdate == NULL) && (crldays == 0) && (crlhours == 0) && (crlsec == 0)) { - BIO_puts(bio_err, + BIO_printf(bio_err, "cannot lookup how long until the next CRL is issued\n"); goto end; } if (verbose) - BIO_puts(bio_err, "making CRL\n"); + BIO_printf(bio_err, "making CRL\n"); if ((crl = X509_CRL_new_ex(app_get0_libctx(), app_get0_propq())) == NULL) goto end; if (!X509_CRL_set_issuer_name(crl, X509_get_subject_name(x509))) @@ -1226,7 +1243,7 @@ end_of_options: /* we now have a CRL */ if (verbose) - BIO_puts(bio_err, "signing CRL\n"); + BIO_printf(bio_err, "signing CRL\n"); /* Add any extensions asked for */ @@ -1236,11 +1253,12 @@ end_of_options: X509V3_set_ctx(&crlctx, x509, NULL, NULL, crl, 0); X509V3_set_nconf(&crlctx, conf); - if (crl_ext != NULL && !X509V3_EXT_CRL_add_nconf(conf, &crlctx, crl_ext, crl)) { - BIO_printf(bio_err, - "Error adding CRL extensions from section %s\n", crl_ext); - goto end; - } + if (crl_ext != NULL) + if (!X509V3_EXT_CRL_add_nconf(conf, &crlctx, crl_ext, crl)) { + BIO_printf(bio_err, + "Error adding CRL extensions from section %s\n", crl_ext); + goto end; + } if (crlnumberfile != NULL) { tmpser = BN_to_ASN1_INTEGER(crlnumber, NULL); if (!tmpser) @@ -1283,7 +1301,7 @@ end_of_options: /*****************************************************************/ if (dorevoke) { if (infile == NULL) { - BIO_puts(bio_err, "no input files\n"); + BIO_printf(bio_err, "no input files\n"); goto end; } else { X509 *revcert; @@ -1305,7 +1323,7 @@ end_of_options: if (!rotate_index(dbfile, "new", "old")) goto end; - BIO_puts(bio_err, "Database updated\n"); + BIO_printf(bio_err, "Database updated\n"); } } ret = 0; @@ -1363,31 +1381,31 @@ static int certify(X509 **xret, const char *infile, int informat, if (req == NULL) goto end; if ((pktmp = X509_REQ_get0_pubkey(req)) == NULL) { - BIO_puts(bio_err, "Error unpacking public key\n"); + BIO_printf(bio_err, "Error unpacking public key\n"); goto end; } if (verbose) X509_REQ_print_ex(bio_err, req, nameopt, X509_FLAG_COMPAT); - BIO_puts(bio_err, "Check that the request matches the signature\n"); + BIO_printf(bio_err, "Check that the request matches the signature\n"); ok = 0; if (selfsign && !X509_REQ_check_private_key(req, pkey)) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Certificate request and CA private key do not match\n"); goto end; } i = do_X509_REQ_verify(req, pktmp, vfyopts); if (i < 0) { - BIO_puts(bio_err, "Signature verification problems...\n"); + BIO_printf(bio_err, "Signature verification problems...\n"); goto end; } if (i == 0) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Signature did not match the certificate request\n"); goto end; } - BIO_puts(bio_err, "Signature ok\n"); + BIO_printf(bio_err, "Signature ok\n"); ok = do_body(xret, pkey, x509, dgst, sigopts, policy, db, serial, subj, chtype, multirdn, email_dn, startdate, enddate, days, batch, @@ -1424,24 +1442,24 @@ static int certify_cert(X509 **xret, const char *infile, int certformat, if (verbose) X509_print(bio_err, template_cert); - BIO_puts(bio_err, "Check that the request matches the signature\n"); + BIO_printf(bio_err, "Check that the request matches the signature\n"); if ((pktmp = X509_get0_pubkey(template_cert)) == NULL) { - BIO_puts(bio_err, "error unpacking public key\n"); + BIO_printf(bio_err, "error unpacking public key\n"); goto end; } i = do_X509_verify(template_cert, pktmp, vfyopts); if (i < 0) { ok = 0; - BIO_puts(bio_err, "Signature verification problems....\n"); + BIO_printf(bio_err, "Signature verification problems....\n"); goto end; } if (i == 0) { ok = 0; - BIO_puts(bio_err, "Signature did not match the certificate\n"); + BIO_printf(bio_err, "Signature did not match the certificate\n"); goto end; } else { - BIO_puts(bio_err, "Signature ok\n"); + BIO_printf(bio_err, "Signature ok\n"); } if ((rreq = X509_to_X509_REQ(template_cert, NULL, NULL)) == NULL) @@ -1470,10 +1488,10 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, const X509_NAME *name = NULL; X509_NAME *CAname = NULL, *subject = NULL; const ASN1_TIME *tm; - const ASN1_STRING *str, *str2; - const ASN1_OBJECT *obj; + ASN1_STRING *str, *str2; + ASN1_OBJECT *obj; X509 *ret = NULL; - const X509_NAME_ENTRY *ne, *tne; + X509_NAME_ENTRY *ne, *tne; EVP_PKEY *pktmp; int ok = -1, i, j, last, nid; const char *p; @@ -1489,49 +1507,52 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, if (subj) { X509_NAME *n = parse_name(subj, chtype, multirdn, "subject"); - int ok_local; if (!n) goto end; - - ok_local = X509_REQ_set_subject_name(req, n); + X509_REQ_set_subject_name(req, n); X509_NAME_free(n); - if (ok_local == 0) - goto end; } if (default_op) - BIO_puts(bio_err, "The Subject's Distinguished Name is as follows\n"); + BIO_printf(bio_err, "The Subject's Distinguished Name is as follows\n"); name = X509_REQ_get_subject_name(req); for (i = 0; i < X509_NAME_entry_count(name); i++) { - int type; ne = X509_NAME_get_entry(name, i); str = X509_NAME_ENTRY_get_data(ne); obj = X509_NAME_ENTRY_get_object(ne); nid = OBJ_obj2nid(obj); - type = ASN1_STRING_type(str); + + if (msie_hack) { + /* assume all type should be strings */ + + if (str->type == V_ASN1_UNIVERSALSTRING) + ASN1_UNIVERSALSTRING_to_string(str); + + if (str->type == V_ASN1_IA5STRING && nid != NID_pkcs9_emailAddress) + str->type = V_ASN1_T61STRING; + + if (nid == NID_pkcs9_emailAddress + && str->type == V_ASN1_PRINTABLESTRING) + str->type = V_ASN1_IA5STRING; + } /* If no EMAIL is wanted in the subject */ if (nid == NID_pkcs9_emailAddress && !email_dn) continue; /* check some things */ - if (nid == NID_pkcs9_emailAddress && type != V_ASN1_IA5STRING) { - BIO_puts(bio_err, + if (nid == NID_pkcs9_emailAddress && str->type != V_ASN1_IA5STRING) { + BIO_printf(bio_err, "\nemailAddress type needs to be of type IA5STRING\n"); goto end; } - if (type != V_ASN1_BMPSTRING && type != V_ASN1_UTF8STRING) { - size_t tmp = ASN1_STRING_length_ex(str); - if (tmp > INT_MAX) - goto end; - j = ASN1_PRINTABLE_type(ASN1_STRING_get0_data(str), (int)tmp); - if ((j == V_ASN1_T61STRING && type != V_ASN1_T61STRING) - || (j == V_ASN1_IA5STRING && type == V_ASN1_PRINTABLESTRING)) { - BIO_puts(bio_err, - "\nThe string contains characters that are illegal for the" - " ASN.1 type\n"); + if (str->type != V_ASN1_BMPSTRING && str->type != V_ASN1_UTF8STRING) { + j = ASN1_PRINTABLE_type(str->data, str->length); + if ((j == V_ASN1_T61STRING && str->type != V_ASN1_T61STRING) || (j == V_ASN1_IA5STRING && str->type == V_ASN1_PRINTABLESTRING)) { + BIO_printf(bio_err, + "\nThe string contains characters that are illegal for the ASN.1 type\n"); goto end; } } @@ -1542,7 +1563,7 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, /* Ok, now we check the 'policy' stuff. */ if ((subject = X509_NAME_new()) == NULL) { - BIO_puts(bio_err, "Memory allocation failure\n"); + BIO_printf(bio_err, "Memory allocation failure\n"); goto end; } @@ -1567,7 +1588,7 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, last = -1; for (;;) { - const X509_NAME_ENTRY *push = NULL; + X509_NAME_ENTRY *push = NULL; /* lookup the object in the supplied name list */ j = X509_NAME_get_index_by_OBJ(name, obj, last); @@ -1627,8 +1648,8 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, "The %s field is different between\n" "CA certificate (%s) and the request (%s)\n", cv->name, - ((str2 == NULL) ? "NULL" : (char *)ASN1_STRING_get0_data(str2)), - ((str == NULL) ? "NULL" : (char *)ASN1_STRING_get0_data(str))); + ((str2 == NULL) ? "NULL" : (char *)str2->data), + ((str == NULL) ? "NULL" : (char *)str->data)); goto end; } } else { @@ -1640,7 +1661,7 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, if (push != NULL) { if (!X509_NAME_add_entry(subject, push, -1, 0)) { - BIO_puts(bio_err, "Memory allocation failure\n"); + BIO_printf(bio_err, "Memory allocation failure\n"); goto end; } } @@ -1659,7 +1680,7 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, /* We are now totally happy, lets make and sign the certificate */ if (verbose) - BIO_puts(bio_err, + BIO_printf(bio_err, "Everything appears to be ok, creating and signing the certificate\n"); if ((ret = X509_new_ex(app_get0_libctx(), app_get0_propq())) == NULL) @@ -1703,7 +1724,7 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, if (!X509V3_set_issuer_pkey(&ext_ctx, pkey)) goto end; if (!cert_matches_key(ret, pkey)) - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: Signature key and public key of cert do not match\n"); } @@ -1711,24 +1732,34 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, if (ext_sect) { if (extfile_conf != NULL) { if (verbose) - BIO_puts(bio_err, "Extra configuration file found\n"); + BIO_printf(bio_err, "Extra configuration file found\n"); /* Use the extfile_conf configuration db LHASH */ + X509V3_set_nconf(&ext_ctx, extfile_conf); + /* Adds exts contained in the configuration file */ - if (!do_EXT_add_nconf(extfile_conf, extfile_conf, &ext_ctx, ret, - "Error adding certificate extensions from extfile section %s\n", ext_sect)) + if (!X509V3_EXT_add_nconf(extfile_conf, &ext_ctx, ext_sect, ret)) { + BIO_printf(bio_err, + "Error adding certificate extensions from extfile section %s\n", + ext_sect); goto end; + } if (verbose) - BIO_puts(bio_err, + BIO_printf(bio_err, "Successfully added extensions from file.\n"); } else if (ext_sect) { /* We found extensions to be set from config file */ - if (!do_EXT_add_nconf(lconf, lconf, &ext_ctx, ret, - "Error adding certificate extensions from config section %s\n", ext_sect)) + X509V3_set_nconf(&ext_ctx, lconf); + + if (!X509V3_EXT_add_nconf(lconf, &ext_ctx, ext_sect, ret)) { + BIO_printf(bio_err, + "Error adding certificate extensions from config section %s\n", + ext_sect); goto end; + } if (verbose) - BIO_puts(bio_err, + BIO_printf(bio_err, "Successfully added extensions from config\n"); } } @@ -1736,12 +1767,12 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, /* Copy extensions from request (if any) */ if (!copy_extensions(ret, req, ext_copy)) { - BIO_puts(bio_err, "ERROR: adding extensions from request\n"); + BIO_printf(bio_err, "ERROR: adding extensions from request\n"); goto end; } if (verbose) - BIO_puts(bio_err, + BIO_printf(bio_err, "The subject name appears to be ok, checking database for clashes\n"); /* Build the correct Subject if no e-mail is wanted in the subject. */ @@ -1754,7 +1785,7 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, * because this retains its structure. */ if ((dn_subject = X509_NAME_dup(subject)) == NULL) { - BIO_puts(bio_err, "Memory allocation failure\n"); + BIO_printf(bio_err, "Memory allocation failure\n"); goto end; } i = -1; @@ -1775,7 +1806,7 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, row[DB_name] = X509_NAME_oneline(X509_get_subject_name(ret), NULL, 0); if (row[DB_name] == NULL) { - BIO_puts(bio_err, "Memory allocation failure\n"); + BIO_printf(bio_err, "Memory allocation failure\n"); goto end; } @@ -1784,7 +1815,7 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, else row[DB_serial] = BN_bn2hex(serial); if (row[DB_serial] == NULL) { - BIO_puts(bio_err, "Memory allocation failure\n"); + BIO_printf(bio_err, "Memory allocation failure\n"); goto end; } @@ -1797,7 +1828,7 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, OPENSSL_free(row[DB_name]); row[DB_name] = OPENSSL_strdup(row[DB_serial]); if (row[DB_name] == NULL) { - BIO_puts(bio_err, "Memory allocation failure\n"); + BIO_printf(bio_err, "Memory allocation failure\n"); goto end; } } @@ -1818,13 +1849,13 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, BIO_printf(bio_err, "ERROR:Serial number %s has already been issued,\n", row[DB_serial]); - BIO_puts(bio_err, + BIO_printf(bio_err, " check the database/serial_file for corruption\n"); } } if (rrow != NULL) { - BIO_puts(bio_err, "The matching entry has the following details\n"); + BIO_printf(bio_err, "The matching entry has the following details\n"); if (rrow[DB_type][0] == DB_TYPE_EXP) p = "Expired"; else if (rrow[DB_type][0] == DB_TYPE_REV) @@ -1861,7 +1892,7 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, } if (!default_op) { - BIO_puts(bio_err, "Certificate Details:\n"); + BIO_printf(bio_err, "Certificate Details:\n"); /* * Never print signature details because signature not present */ @@ -1869,25 +1900,25 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, X509_print_ex(bio_err, ret, nameopt, certopt); } - BIO_puts(bio_err, "Certificate is to be certified until "); + BIO_printf(bio_err, "Certificate is to be certified until "); ASN1_TIME_print_ex(bio_err, X509_get0_notAfter(ret), dateopt); if (days) BIO_printf(bio_err, " (%ld days)", days); - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); if (!batch) { - BIO_puts(bio_err, "Sign the certificate? [y/n]:"); + BIO_printf(bio_err, "Sign the certificate? [y/n]:"); (void)BIO_flush(bio_err); buf[0] = '\0'; if (fgets(buf, sizeof(buf), stdin) == NULL) { - BIO_puts(bio_err, + BIO_printf(bio_err, "CERTIFICATE WILL NOT BE CERTIFIED: I/O error\n"); ok = 0; goto end; } if (!(buf[0] == 'y' || buf[0] == 'Y')) { - BIO_puts(bio_err, "CERTIFICATE WILL NOT BE CERTIFIED\n"); + BIO_printf(bio_err, "CERTIFICATE WILL NOT BE CERTIFIED\n"); ok = 0; goto end; } @@ -1903,14 +1934,14 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, /* We now just add it to the database as DB_TYPE_VAL('V') */ row[DB_type] = OPENSSL_strdup("V"); tm = X509_get0_notAfter(ret); - row[DB_exp_date] = app_malloc(ASN1_STRING_length_ex(tm) + 1, "row expdate"); - memcpy(row[DB_exp_date], ASN1_STRING_get0_data(tm), ASN1_STRING_length_ex(tm)); - row[DB_exp_date][ASN1_STRING_length_ex(tm)] = '\0'; + row[DB_exp_date] = app_malloc(tm->length + 1, "row expdate"); + memcpy(row[DB_exp_date], tm->data, tm->length); + row[DB_exp_date][tm->length] = '\0'; row[DB_rev_date] = NULL; row[DB_file] = OPENSSL_strdup("unknown"); if ((row[DB_type] == NULL) || (row[DB_file] == NULL) || (row[DB_name] == NULL)) { - BIO_puts(bio_err, "Memory allocation failure\n"); + BIO_printf(bio_err, "Memory allocation failure\n"); goto end; } @@ -1920,9 +1951,8 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, irow[DB_NUMBER] = NULL; if (!TXT_DB_insert(db->db, irow)) { - BIO_printf(bio_err, "failed to update database\n" - "TXT_DB error number %ld\n", - db->db->error); + BIO_printf(bio_err, "failed to update database\n"); + BIO_printf(bio_err, "TXT_DB error number %ld\n", db->db->error); goto end; } irow = NULL; @@ -2009,9 +2039,7 @@ static int certify_spkac(X509 **xret, const char *infile, EVP_PKEY *pkey, /* * Build up the subject name set. */ - n = X509_NAME_new(); - if (n == NULL) - goto end; + n = X509_REQ_get_subject_name(req); for (i = 0;; i++) { if (sk_CONF_VALUE_num(sk) <= i) @@ -2035,7 +2063,7 @@ static int certify_spkac(X509 **xret, const char *infile, EVP_PKEY *pkey, if (strcmp(type, "SPKAC") == 0) { spki = NETSCAPE_SPKI_b64_decode(cv->value, -1); if (spki == NULL) { - BIO_puts(bio_err, + BIO_printf(bio_err, "unable to load Netscape SPKAC structure\n"); goto end; } @@ -2053,28 +2081,25 @@ static int certify_spkac(X509 **xret, const char *infile, EVP_PKEY *pkey, goto end; } - if (!X509_REQ_set_subject_name(req, n)) - goto end; - /* * Now extract the key from the SPKI structure. */ - BIO_puts(bio_err, "Check that the SPKAC request matches the signature\n"); + BIO_printf(bio_err, "Check that the SPKAC request matches the signature\n"); if ((pktmp = NETSCAPE_SPKI_get_pubkey(spki)) == NULL) { - BIO_puts(bio_err, "error unpacking SPKAC public key\n"); + BIO_printf(bio_err, "error unpacking SPKAC public key\n"); goto end; } j = NETSCAPE_SPKI_verify(spki, pktmp); if (j <= 0) { EVP_PKEY_free(pktmp); - BIO_puts(bio_err, + BIO_printf(bio_err, "signature verification failed on SPKAC public key\n"); goto end; } - BIO_puts(bio_err, "Signature ok\n"); + BIO_printf(bio_err, "Signature ok\n"); X509_REQ_set_pubkey(req, pktmp); EVP_PKEY_free(pktmp); @@ -2084,7 +2109,6 @@ static int certify_spkac(X509 **xret, const char *infile, EVP_PKEY *pkey, ext_copy, 0, dateopt); end: X509_REQ_free(req); - X509_NAME_free(n); CONF_free(parms); NETSCAPE_SPKI_free(spki); X509_NAME_ENTRY_free(ne); @@ -2123,7 +2147,7 @@ static int do_revoke(X509 *x509, CA_DB *db, REVINFO_TYPE rev_type, row[DB_name] = OPENSSL_strdup(row[DB_serial]); } if ((row[DB_name] == NULL) || (row[DB_serial] == NULL)) { - BIO_puts(bio_err, "Memory allocation failure\n"); + BIO_printf(bio_err, "Memory allocation failure\n"); goto end; } /* @@ -2139,14 +2163,14 @@ static int do_revoke(X509 *x509, CA_DB *db, REVINFO_TYPE rev_type, /* We now just add it to the database as DB_TYPE_REV('V') */ row[DB_type] = OPENSSL_strdup("V"); tm = X509_get0_notAfter(x509); - row[DB_exp_date] = app_malloc(ASN1_STRING_length_ex(tm) + 1, "row exp_data"); - memcpy(row[DB_exp_date], ASN1_STRING_get0_data(tm), ASN1_STRING_length_ex(tm)); - row[DB_exp_date][ASN1_STRING_length_ex(tm)] = '\0'; + row[DB_exp_date] = app_malloc(tm->length + 1, "row exp_data"); + memcpy(row[DB_exp_date], tm->data, tm->length); + row[DB_exp_date][tm->length] = '\0'; row[DB_rev_date] = NULL; row[DB_file] = OPENSSL_strdup("unknown"); if (row[DB_type] == NULL || row[DB_file] == NULL) { - BIO_puts(bio_err, "Memory allocation failure\n"); + BIO_printf(bio_err, "Memory allocation failure\n"); goto end; } @@ -2156,9 +2180,8 @@ static int do_revoke(X509 *x509, CA_DB *db, REVINFO_TYPE rev_type, irow[DB_NUMBER] = NULL; if (!TXT_DB_insert(db->db, irow)) { - BIO_printf(bio_err, "failed to update database\n" - "TXT_DB error number %ld\n", - db->db->error); + BIO_printf(bio_err, "failed to update database\n"); + BIO_printf(bio_err, "TXT_DB error number %ld\n", db->db->error); OPENSSL_free(irow); goto end; } @@ -2190,7 +2213,7 @@ static int do_revoke(X509 *x509, CA_DB *db, REVINFO_TYPE rev_type, BIO_printf(bio_err, "Revoking Certificate %s.\n", rrow[DB_serial]); rev_str = make_revocation_str(rev_type, value); if (!rev_str) { - BIO_puts(bio_err, "Error in revocation arguments\n"); + BIO_printf(bio_err, "Error in revocation arguments\n"); goto end; } rrow[DB_type][0] = DB_TYPE_REV; @@ -2271,7 +2294,7 @@ end: return ok; } -int do_updatedb(CA_DB *db, const time_t *now) +int do_updatedb(CA_DB *db, time_t *now) { ASN1_TIME *a_tm = NULL; int i, cnt = 0; @@ -2352,7 +2375,7 @@ static char *make_revocation_str(REVINFO_TYPE rev_type, const char *rev_arg) const char *reason = NULL, *other = NULL; ASN1_OBJECT *otmp; ASN1_UTCTIME *revtm = NULL; - size_t i; + int i; switch (rev_type) { case REV_NONE: @@ -2409,15 +2432,15 @@ static char *make_revocation_str(REVINFO_TYPE rev_type, const char *rev_arg) if (!revtm) return NULL; - i = ASN1_STRING_length_ex(revtm) + 1; + i = revtm->length + 1; if (reason) - i += strlen(reason) + 1; + i += (int)(strlen(reason) + 1); if (other) - i += strlen(other) + 1; + i += (int)(strlen(other) + 1); str = app_malloc(i, "revocation reason"); - OPENSSL_strlcpy(str, (const char *)ASN1_STRING_get0_data(revtm), i); + OPENSSL_strlcpy(str, (char *)revtm->data, i); if (reason) { OPENSSL_strlcat(str, ",", i); OPENSSL_strlcat(str, reason, i); @@ -2494,7 +2517,7 @@ static int old_entry_print(const ASN1_OBJECT *obj, const ASN1_STRING *str) { char buf[25], *pbuf; const char *p; - size_t j; + int j; j = i2a_ASN1_OBJECT(bio_err, obj); pbuf = buf; @@ -2504,30 +2527,30 @@ static int old_entry_print(const ASN1_OBJECT *obj, const ASN1_STRING *str) *(pbuf++) = '\0'; BIO_puts(bio_err, buf); - if (ASN1_STRING_type(str) == V_ASN1_PRINTABLESTRING) - BIO_puts(bio_err, "PRINTABLE:'"); - else if (ASN1_STRING_type(str) == V_ASN1_T61STRING) - BIO_puts(bio_err, "T61STRING:'"); - else if (ASN1_STRING_type(str) == V_ASN1_IA5STRING) - BIO_puts(bio_err, "IA5STRING:'"); - else if (ASN1_STRING_type(str) == V_ASN1_UNIVERSALSTRING) - BIO_puts(bio_err, "UNIVERSALSTRING:'"); + if (str->type == V_ASN1_PRINTABLESTRING) + BIO_printf(bio_err, "PRINTABLE:'"); + else if (str->type == V_ASN1_T61STRING) + BIO_printf(bio_err, "T61STRING:'"); + else if (str->type == V_ASN1_IA5STRING) + BIO_printf(bio_err, "IA5STRING:'"); + else if (str->type == V_ASN1_UNIVERSALSTRING) + BIO_printf(bio_err, "UNIVERSALSTRING:'"); else - BIO_printf(bio_err, "ASN.1 %2d:'", ASN1_STRING_type(str)); + BIO_printf(bio_err, "ASN.1 %2d:'", str->type); - p = (const char *)ASN1_STRING_get0_data(str); - for (j = ASN1_STRING_length_ex(str); j > 0; j--) { + p = (const char *)str->data; + for (j = str->length; j > 0; j--) { if ((*p >= ' ') && (*p <= '~')) BIO_printf(bio_err, "%c", *p); else if (*p & 0x80) BIO_printf(bio_err, "\\0x%02X", *p); else if ((unsigned char)*p == 0xf7) - BIO_puts(bio_err, "^?"); + BIO_printf(bio_err, "^?"); else BIO_printf(bio_err, "^%c", *p + '@'); p++; } - BIO_puts(bio_err, "'\n"); + BIO_printf(bio_err, "'\n"); return 1; } @@ -2544,7 +2567,7 @@ int unpack_revinfo(ASN1_TIME **prevtm, int *preason, ASN1_OBJECT **phold, tmp = OPENSSL_strdup(str); if (!tmp) { - BIO_puts(bio_err, "memory allocation failure\n"); + BIO_printf(bio_err, "memory allocation failure\n"); goto end; } @@ -2566,7 +2589,7 @@ int unpack_revinfo(ASN1_TIME **prevtm, int *preason, ASN1_OBJECT **phold, if (prevtm) { *prevtm = ASN1_UTCTIME_new(); if (*prevtm == NULL) { - BIO_puts(bio_err, "memory allocation failure\n"); + BIO_printf(bio_err, "memory allocation failure\n"); goto end; } if (!ASN1_UTCTIME_set_string(*prevtm, rtime_str)) { @@ -2590,7 +2613,7 @@ int unpack_revinfo(ASN1_TIME **prevtm, int *preason, ASN1_OBJECT **phold, reason_code = OCSP_REVOKED_STATUS_REMOVEFROMCRL; } else if (reason_code == 8) { /* Hold instruction */ if (!arg_str) { - BIO_puts(bio_err, "missing hold instruction\n"); + BIO_printf(bio_err, "missing hold instruction\n"); goto end; } reason_code = OCSP_REVOKED_STATUS_CERTIFICATEHOLD; @@ -2606,12 +2629,12 @@ int unpack_revinfo(ASN1_TIME **prevtm, int *preason, ASN1_OBJECT **phold, ASN1_OBJECT_free(hold); } else if ((reason_code == 9) || (reason_code == 10)) { if (!arg_str) { - BIO_puts(bio_err, "missing compromised time\n"); + BIO_printf(bio_err, "missing compromised time\n"); goto end; } comp_time = ASN1_GENERALIZEDTIME_new(); if (comp_time == NULL) { - BIO_puts(bio_err, "memory allocation failure\n"); + BIO_printf(bio_err, "memory allocation failure\n"); goto end; } if (!ASN1_GENERALIZEDTIME_set_string(comp_time, arg_str)) { diff --git a/apps/ciphers.c b/apps/ciphers.c index 4dbdd41f8a..dc52b9f912 100644 --- a/apps/ciphers.c +++ b/apps/ciphers.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2022 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -20,6 +20,7 @@ typedef enum OPTION_choice { OPT_COMMON, OPT_STDNAME, OPT_CONVERT, + OPT_SSL3, OPT_TLS1, OPT_TLS1_1, OPT_TLS1_2, @@ -47,6 +48,9 @@ const OPTIONS ciphers_options[] = { OPT_SECTION("Cipher specification"), { "s", OPT_S, '-', "Only supported ciphers" }, +#ifndef OPENSSL_NO_SSL3 + { "ssl3", OPT_SSL3, '-', "Ciphers compatible with SSL3" }, +#endif #ifndef OPENSSL_NO_TLS1 { "tls1", OPT_TLS1, '-', "Ciphers compatible with TLS1" }, #endif @@ -131,6 +135,10 @@ int ciphers_main(int argc, char **argv) case OPT_CONVERT: convert = opt_arg(); break; + case OPT_SSL3: + min_version = SSL3_VERSION; + max_version = SSL3_VERSION; + break; case OPT_TLS1: min_version = TLS1_VERSION; max_version = TLS1_VERSION; @@ -199,13 +207,13 @@ int ciphers_main(int argc, char **argv) #endif if (ciphersuites != NULL && !SSL_CTX_set_ciphersuites(ctx, ciphersuites)) { - BIO_puts(bio_err, "Error setting TLSv1.3 ciphersuites\n"); + BIO_printf(bio_err, "Error setting TLSv1.3 ciphersuites\n"); goto err; } if (ciphers != NULL) { if (!SSL_CTX_set_cipher_list(ctx, ciphers)) { - BIO_puts(bio_err, "Error in cipher list\n"); + BIO_printf(bio_err, "Error in cipher list\n"); goto err; } } @@ -229,10 +237,10 @@ int ciphers_main(int argc, char **argv) if (p == NULL) break; if (i != 0) - BIO_puts(bio_out, ":"); - BIO_puts(bio_out, p); + BIO_printf(bio_out, ":"); + BIO_printf(bio_out, "%s", p); } - BIO_puts(bio_out, "\n"); + BIO_printf(bio_out, "\n"); } else { for (i = 0; i < sk_SSL_CIPHER_num(sk); i++) { diff --git a/apps/cmp.c b/apps/cmp.c index abe6de5cb9..990112b64d 100644 --- a/apps/cmp.c +++ b/apps/cmp.c @@ -1,5 +1,5 @@ /* - * Copyright 2007-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright Nokia 2007-2019 * Copyright Siemens AG 2015-2019 * @@ -87,7 +87,6 @@ static char *opt_srvcert = NULL; static char *opt_expect_sender = NULL; static int opt_ignore_keyusage = 0; static int opt_unprotected_errors = 0; -static int opt_nonmatched_error_nonces = 0; static int opt_ta_in_ip_extracerts = 0; static int opt_no_cache_extracerts = 0; static char *opt_srvcertout = NULL; @@ -283,7 +282,6 @@ typedef enum OPTION_choice { OPT_EXPECT_SENDER, OPT_IGNORE_KEYUSAGE, OPT_UNPROTECTED_ERRORS, - OPT_NONMATCHED_ERROR_NONCES, OPT_TA_IN_IP_EXTRACERTS, OPT_NO_CACHE_EXTRACERTS, OPT_SRVCERTOUT, @@ -474,13 +472,13 @@ const OPTIONS cmp_options[] = { "NOTE: -server, -proxy, and -no_proxy not supported due to no-sock/no-http build" }, #else { "server", OPT_SERVER, 's', - "[http[s]://]host[:port][/path] of CMP server to use. Default port 80 or 443." }, + "[http[s]://]address[:port][/path] of CMP server. Default port 80 or 443." }, { OPT_MORE_STR, 0, 0, - "host may be a DNS name or an IP address; path can be overridden by -path" }, + "address may be a DNS name or an IP address; path can be overridden by -path" }, { "proxy", OPT_PROXY, 's', - "[http[s]://]host[:port][/path] of HTTP(S) proxy to use; path is ignored" }, + "[http[s]://]address[:port][/path] of HTTP(S) proxy to use; path is ignored" }, { "no_proxy", OPT_NO_PROXY, 's', - "List of servers not to use HTTP(S) proxy for" }, + "List of addresses of servers not to use HTTP(S) proxy for" }, { OPT_MORE_STR, 0, 0, "Default from environment variable 'no_proxy', else 'NO_PROXY', else none" }, #endif @@ -513,8 +511,6 @@ const OPTIONS cmp_options[] = { "certificate responses (ip/cp/kup), revocation responses (rp), and PKIConf" }, { OPT_MORE_STR, 0, 0, "WARNING: This setting leads to behavior allowing violation of RFC 9810" }, - { "nonmatched_error_nonces", OPT_NONMATCHED_ERROR_NONCES, '-', - "Accept missing or non-matching transactionID or recipNonce in error messages" }, { "ta_in_ip_extracerts", OPT_TA_IN_IP_EXTRACERTS, '-', "Permit using self-issued certificates from the extraCerts in an IP message" }, { OPT_MORE_STR, 0, 0, @@ -538,9 +534,9 @@ const OPTIONS cmp_options[] = { { "oldwithnew", OPT_OLDWITHNEW, 's', "File to save OldWithNew cert received in genp of type rootCaKeyUpdate" }, { "crlcert", OPT_CRLCERT, 's', - "certificate to take CRL source data from in genm of type crlStatusList" }, + "certificate to request a CRL for in genm of type crlStatusList" }, { "oldcrl", OPT_OLDCRL, 's', - "CRL to obtain an update for in genm of type crlStatusList" }, + "CRL to request update for in genm of type crlStatusList" }, { "crlout", OPT_CRLOUT, 's', "File to save new CRL received in genp of type 'crls'" }, @@ -588,7 +584,7 @@ const OPTIONS cmp_options[] = { "NOTE: -tls_used and all other TLS options not supported due to no-sock/no-http build" }, #else { "tls_used", OPT_TLS_USED, '-', - "Require using TLS for HTTP (also when other TLS options are not set)" }, + "Enable using TLS (also when other TLS options are not set)" }, { "tls_cert", OPT_TLS_CERT, 's', "Client's TLS certificate. May include chain to be provided to TLS server" }, { "tls_key", OPT_TLS_KEY, 's', @@ -601,7 +597,7 @@ const OPTIONS cmp_options[] = { "Trusted certificates to use for verifying the TLS server certificate;" }, { OPT_MORE_STR, 0, 0, "this implies hostname validation" }, { "tls_host", OPT_TLS_HOST, 's', - "Host name/address (rather than -server) to verify in TLS server cert" }, + "Address to be checked (rather than -server) during TLS hostname validation" }, #endif OPT_SECTION("Client-side debugging"), @@ -739,7 +735,6 @@ static varref cmp_vars[] = { /* must be in same order as enumerated above! */ { &opt_trusted }, { &opt_untrusted }, { &opt_srvcert }, { &opt_expect_sender }, { (char **)&opt_ignore_keyusage }, { (char **)&opt_unprotected_errors }, - { (char **)&opt_nonmatched_error_nonces }, { (char **)&opt_ta_in_ip_extracerts }, { (char **)&opt_no_cache_extracerts }, { &opt_srvcertout }, { &opt_extracertsout }, { &opt_cacertsout }, @@ -838,39 +833,27 @@ static int set_verbosity(int level) return 1; } -static EVP_PKEY *load_pubkey_pwd(const char *uri, int format, const char *source, const char *desc) -{ - char *pass = get_passwd(source, desc); - EVP_PKEY *pkey = load_pubkey(uri, format, 0, pass, desc); - - clear_free(pass); - return pkey; -} - static EVP_PKEY *load_key_pwd(const char *uri, int format, - const char *source, const char *desc) + const char *pass, const char *desc) { - char *pass = get_passwd(source, desc); - EVP_PKEY *pkey = load_key(uri, format, 0, pass, desc); + char *pass_string = get_passwd(pass, desc); + EVP_PKEY *pkey = load_key(uri, format, 0, pass_string, desc); - clear_free(pass); + clear_free(pass_string); return pkey; } -static X509 *load_cert_pwd(const char *uri, const char *source, const char *desc) +static X509 *load_cert_pwd(const char *uri, const char *pass, const char *desc) { - char *pass = get_passwd(source, desc); - X509 *cert = load_cert_pass(uri, FORMAT_UNDEF, 0, pass, desc); + X509 *cert; + char *pass_string = get_passwd(pass, desc); - clear_free(pass); + cert = load_cert_pass(uri, FORMAT_UNDEF, 0, pass_string, desc); + clear_free(pass_string); return cert; } -/* - * Set expected hostname/IP address and clears any email address in the given ts. - * If the host is NULL, host name/address verification is disabled. - * It is interpreted as an IP address when possible, otherwise as a domain name. - */ +/* set expected hostname/IP addr and clears the email addr in the given ts */ static int truststore_set_host_etc(X509_STORE *ts, const char *host) { X509_VERIFY_PARAM *ts_vpm = X509_STORE_get0_param(ts); @@ -880,14 +863,10 @@ static int truststore_set_host_etc(X509_STORE *ts, const char *host) || !X509_VERIFY_PARAM_set1_ip(ts_vpm, NULL, 0) || !X509_VERIFY_PARAM_set1_email(ts_vpm, NULL, 0)) return 0; - if (host == NULL) - return 1; - X509_VERIFY_PARAM_set_hostflags(ts_vpm, X509_CHECK_FLAG_ALWAYS_CHECK_SUBJECT | X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS); - return host_is_ip_address(host) - ? X509_VERIFY_PARAM_set1_ip_asc(ts_vpm, host) - : X509_VERIFY_PARAM_set1_host(ts_vpm, host, 0); + return (host != NULL && X509_VERIFY_PARAM_set1_ip_asc(ts_vpm, host)) + || X509_VERIFY_PARAM_set1_host(ts_vpm, host, 0); } /* write OSSL_CMP_MSG DER-encoded to the specified file name item */ @@ -900,14 +879,14 @@ static int write_PKIMESSAGE(const OSSL_CMP_MSG *msg, char **filenames) return 0; } if (*filenames == NULL) { - CMP_warn("Too few file names provided for writing PKIMessage"); - return 1; + CMP_err("not enough file names provided for writing PKIMessage"); + return 0; } file = *filenames; *filenames = next_item(file); if (OSSL_CMP_MSG_write(file, msg) < 0) { - CMP_err1("Cannot write PKIMessage to file '%s'", file); + CMP_err1("cannot write PKIMessage to file '%s'", file); return 0; } return 1; @@ -924,7 +903,7 @@ static OSSL_CMP_MSG *read_PKIMESSAGE(const char *desc, char **filenames) return NULL; } if (*filenames == NULL) { - CMP_err("Too few file names provided for reading PKIMessage"); + CMP_err("not enough file names provided for reading PKIMessage"); return NULL; } @@ -933,7 +912,7 @@ static OSSL_CMP_MSG *read_PKIMESSAGE(const char *desc, char **filenames) ret = OSSL_CMP_MSG_read(file, app_get0_libctx(), app_get0_propq()); if (ret == NULL) - CMP_err1("Cannot read PKIMessage from file '%s'", file); + CMP_err1("cannot read PKIMessage from file '%s'", file); else CMP_info2("%s %s", desc, file); return ret; @@ -955,7 +934,7 @@ static OSSL_CMP_MSG *read_write_req_resp(OSSL_CMP_CTX *ctx, if (opt_reqout_only != NULL) { if (OSSL_CMP_MSG_write(opt_reqout_only, req) < 0) - CMP_err1("Cannot write request PKIMessage to file '%s'", + CMP_err1("cannot write request PKIMessage to file '%s'", opt_reqout_only); else reqout_only_done = 1; @@ -987,20 +966,19 @@ static OSSL_CMP_MSG *read_write_req_resp(OSSL_CMP_CTX *ctx, res = read_PKIMESSAGE("actually using", &opt_rspin); } else { const OSSL_CMP_MSG *actual_req = req_new != NULL ? req_new : req; - const char *const msg = "Too few -rspin filename arguments; resorting to"; if (opt_use_mock_srv) { if (rspin_in_use) - CMP_warn1("%s using mock server", msg); + CMP_warn("too few -rspin filename arguments; resorting to using mock server"); res = OSSL_CMP_CTX_server_perform(ctx, actual_req); } else { #if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP) if (opt_server == NULL) { - CMP_err("Missing -server or -use_mock_srv option, or too few -rspin filename arguments"); + CMP_err("missing -server or -use_mock_srv option, or too few -rspin filename arguments"); goto err; } if (rspin_in_use) - CMP_warn1("%s contacting server", msg); + CMP_warn("too few -rspin filename arguments; resorting to contacting server"); res = OSSL_CMP_MSG_http_perform(ctx, actual_req); #else CMP_err("-server not supported on no-sock/no-http build; missing -use_mock_srv option or too few -rspin filename arguments"); @@ -1048,7 +1026,7 @@ static int set_name(const char *str, return 0; if (!(*set_fn)(ctx, n)) { X509_NAME_free(n); - CMP_err("Out of memory"); + CMP_err("out of memory"); return 0; } X509_NAME_free(n); @@ -1082,12 +1060,12 @@ static int set_gennames(OSSL_CMP_CTX *ctx, char *names, const char *desc) (void)ERR_pop_to_mark(); if (n == NULL) { - CMP_err2("Bad syntax of %s '%s'", desc, names); + CMP_err2("bad syntax of %s '%s'", desc, names); return 0; } if (!OSSL_CMP_CTX_push1_subjectAltName(ctx, n)) { GENERAL_NAME_free(n); - CMP_err("Out of memory"); + CMP_err("out of memory"); return 0; } GENERAL_NAME_free(n); @@ -1129,22 +1107,6 @@ static int setup_cert(void *ctx, const char *file, const char *pass, return ok; } -typedef int (*add_X509_fn_srv_t)(OSSL_CMP_SRV_CTX *ctx, X509 *cert); -static int setup_cert_srv(OSSL_CMP_SRV_CTX *ctx, const char *file, const char *pass, - const char *desc, add_X509_fn_srv_t set1_fn) -{ - X509 *cert; - int ok; - - if (file == NULL) - return 1; - if ((cert = load_cert_pwd(file, pass, desc)) == NULL) - return 0; - ok = (*set1_fn)(ctx, cert); - X509_free(cert); - return ok; -} - typedef int (*add_X509_stack_fn_t)(void *ctx, const STACK_OF(X509) *certs); static int setup_certs(char *files, const char *desc, void *ctx, add_X509_stack_fn_t set1_fn) @@ -1161,22 +1123,6 @@ static int setup_certs(char *files, const char *desc, void *ctx, return ok; } -typedef int (*add_X509_stack_fn_srv_t)(OSSL_CMP_SRV_CTX *ctx, STACK_OF(X509) *certs); -static int setup_certs_srv(char *files, const char *desc, OSSL_CMP_SRV_CTX *ctx, - add_X509_stack_fn_srv_t set1_fn) -{ - STACK_OF(X509) *certs; - int ok; - - if (files == NULL) - return 1; - if ((certs = load_certs_multifile(files, opt_otherpass, desc, vpm)) == NULL) - return 0; - ok = (*set1_fn)(ctx, certs); - OSSL_STACK_OF_X509_free(certs); - return ok; -} - static int setup_mock_crlout(void *ctx, const char *file, const char *desc) { X509_CRL *crl; @@ -1210,11 +1156,11 @@ static int transform_opts(void) } else if (!strcmp(opt_cmd_s, "genm")) { opt_cmd = CMP_GENM; } else { - CMP_err1("Unknown cmp command '%s'", opt_cmd_s); + CMP_err1("unknown cmp command '%s'", opt_cmd_s); return 0; } } else { - CMP_err("No cmp command to execute"); + CMP_err("no cmp command to execute"); return 0; } @@ -1222,7 +1168,7 @@ static int transform_opts(void) if (opt_keyform_s != NULL && !opt_format(opt_keyform_s, FORMAT_OPTIONS, &opt_keyform)) { - CMP_err("Unknown option given for key loading format"); + CMP_err("unknown option given for key loading format"); return 0; } @@ -1230,12 +1176,12 @@ static int transform_opts(void) if (opt_certform_s != NULL && !opt_format(opt_certform_s, OPT_FMT_PEMDER, &opt_certform)) { - CMP_err("Unknown option given for certificate storing format"); + CMP_err("unknown option given for certificate storing format"); return 0; } if (opt_crlform_s != NULL && !opt_format(opt_crlform_s, OPT_FMT_PEMDER, &opt_crlform)) { - CMP_err("Unknown option given for CRL storing format"); + CMP_err("unknown option given for CRL storing format"); return 0; } @@ -1255,7 +1201,7 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(void) if (opt_srv_ref == NULL) { if (opt_srv_cert == NULL) { /* opt_srv_cert should determine the sender */ - CMP_err("Must give -srv_ref for mock server if no -srv_cert given"); + CMP_err("must give -srv_ref for mock server if no -srv_cert given"); goto err; } } else { @@ -1277,7 +1223,7 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(void) goto err; } } else if (opt_srv_cert == NULL) { - CMP_err("Server credentials (-srv_secret or -srv_cert) must be given if -use_mock_srv or -port is used"); + CMP_err("server credentials (-srv_secret or -srv_cert) must be given if -use_mock_srv or -port is used"); goto err; } else { CMP_warn("server will not be able to handle PBM-protected requests since -srv_secret is not given"); @@ -1285,7 +1231,7 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(void) if (opt_srv_secret == NULL && ((opt_srv_cert == NULL) != (opt_srv_key == NULL))) { - CMP_err("Must give both -srv_cert and -srv_key options or neither"); + CMP_err("must give both -srv_cert and -srv_key options or neither"); goto err; } if (!setup_cert(ctx, opt_srv_cert, opt_srv_keypass, @@ -1320,16 +1266,16 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(void) (add_X509_stack_fn_t)OSSL_CMP_CTX_set1_untrusted)) goto err; - if (!setup_cert_srv(srv_ctx, opt_ref_cert, opt_otherpass, + if (!setup_cert(srv_ctx, opt_ref_cert, opt_otherpass, "reference cert to be expected by the mock server", - ossl_cmp_mock_srv_set1_refCert)) + (add_X509_fn_t)ossl_cmp_mock_srv_set1_refCert)) goto err; if (opt_rsp_cert == NULL) { CMP_warn("no -rsp_cert given for mock server"); } else { - if (!setup_cert_srv(srv_ctx, opt_rsp_cert, opt_rsp_keypass, + if (!setup_cert(srv_ctx, opt_rsp_cert, opt_rsp_keypass, "cert the mock server returns on certificate requests", - ossl_cmp_mock_srv_set1_certOut)) + (add_X509_fn_t)ossl_cmp_mock_srv_set1_certOut)) goto err; } if (opt_rsp_key != NULL) { @@ -1349,22 +1295,22 @@ static OSSL_CMP_SRV_CTX *setup_srv_ctx(void) if (!setup_mock_crlout(srv_ctx, opt_rsp_crl, "CRL to be returned by the mock server")) goto err; - if (!setup_certs_srv(opt_rsp_extracerts, + if (!setup_certs(opt_rsp_extracerts, "CMP extra certificates for mock server", srv_ctx, - ossl_cmp_mock_srv_set1_chainOut)) + (add_X509_stack_fn_t)ossl_cmp_mock_srv_set1_chainOut)) goto err; - if (!setup_certs_srv(opt_rsp_capubs, "caPubs for mock server", srv_ctx, - ossl_cmp_mock_srv_set1_caPubsOut)) + if (!setup_certs(opt_rsp_capubs, "caPubs for mock server", srv_ctx, + (add_X509_stack_fn_t)ossl_cmp_mock_srv_set1_caPubsOut)) goto err; - if (!setup_cert_srv(srv_ctx, opt_rsp_newwithnew, opt_otherpass, + if (!setup_cert(srv_ctx, opt_rsp_newwithnew, opt_otherpass, "NewWithNew cert the mock server returns in rootCaKeyUpdate", - ossl_cmp_mock_srv_set1_newWithNew) - || !setup_cert_srv(srv_ctx, opt_rsp_newwithold, opt_otherpass, + (add_X509_fn_t)ossl_cmp_mock_srv_set1_newWithNew) + || !setup_cert(srv_ctx, opt_rsp_newwithold, opt_otherpass, "NewWithOld cert the mock server returns in rootCaKeyUpdate", - ossl_cmp_mock_srv_set1_newWithOld) - || !setup_cert_srv(srv_ctx, opt_rsp_oldwithnew, opt_otherpass, + (add_X509_fn_t)ossl_cmp_mock_srv_set1_newWithOld) + || !setup_cert(srv_ctx, opt_rsp_oldwithnew, opt_otherpass, "OldWithNew cert the mock server returns in rootCaKeyUpdate", - ossl_cmp_mock_srv_set1_oldWithNew)) + (add_X509_fn_t)ossl_cmp_mock_srv_set1_oldWithNew)) goto err; (void)ossl_cmp_mock_srv_set_pollCount(srv_ctx, opt_poll_count); (void)ossl_cmp_mock_srv_set_checkAfterTime(srv_ctx, opt_check_after); @@ -1454,8 +1400,6 @@ static int setup_verification_ctx(OSSL_CMP_CTX *ctx) if (opt_unprotected_errors) (void)OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_UNPROTECTED_ERRORS, 1); - if (opt_nonmatched_error_nonces) - (void)OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_NONMATCHED_ERROR_NONCES, 1); if (opt_ta_in_ip_extracerts) { (void)OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_PERMIT_TA_IN_EXTRACERTS_FOR_IR, 1); CMP_warn("permitting non-authenticated trust anchors in IP extracerts according to 3GPP TS 33.310"); @@ -1472,10 +1416,7 @@ static int setup_verification_ctx(OSSL_CMP_CTX *ctx) out_vpm = X509_STORE_get0_param(out_trusted); X509_VERIFY_PARAM_clear_flags(out_vpm, X509_V_FLAG_USE_CHECK_TIME); - if (!OSSL_CMP_CTX_set_certConf_cb_arg(ctx, out_trusted)) { - X509_STORE_free(out_trusted); - return 0; - } + (void)OSSL_CMP_CTX_set_certConf_cb_arg(ctx, out_trusted); } if (opt_disable_confirm) @@ -1533,7 +1474,7 @@ static SSL_CTX *setup_ssl_ctx(OSSL_CMP_CTX *ctx, const char *host) * the chain to be provided with the TLS client cert to the TLS server. */ if (!ok || !SSL_CTX_set0_chain(ssl_ctx, certs)) { - CMP_err1("Unable to use client TLS certificate file '%s'", + CMP_err1("unable to use client TLS certificate file '%s'", opt_tls_cert); OSSL_STACK_OF_X509_free(certs); goto err; @@ -1541,7 +1482,7 @@ static SSL_CTX *setup_ssl_ctx(OSSL_CMP_CTX *ctx, const char *host) for (i = 0; i < sk_X509_num(untrusted); i++) { cert = sk_X509_value(untrusted, i); if (!SSL_CTX_add1_chain_cert(ssl_ctx, cert)) { - CMP_err("Could not add untrusted cert to TLS client cert chain"); + CMP_err("could not add untrusted cert to TLS client cert chain"); goto err; } } @@ -1560,10 +1501,10 @@ static SSL_CTX *setup_ssl_ctx(OSSL_CMP_CTX *ctx, const char *host) | X509_V_FLAG_PARTIAL_CHAIN | X509_V_FLAG_POLICY_CHECK)); } - CMP_debug("Trying to build cert chain for own TLS cert"); + CMP_debug("trying to build cert chain for own TLS cert"); if (SSL_CTX_build_cert_chain(ssl_ctx, SSL_BUILD_CHAIN_FLAG_UNTRUSTED | SSL_BUILD_CHAIN_FLAG_NO_ROOT)) { - CMP_debug("Success building cert chain for own TLS cert"); + CMP_debug("success building cert chain for own TLS cert"); } else { OSSL_CMP_CTX_print_errors(ctx); CMP_warn("could not build cert chain for own TLS cert"); @@ -1591,7 +1532,7 @@ static SSL_CTX *setup_ssl_ctx(OSSL_CMP_CTX *ctx, const char *host) } sk_X509_free(tls_extra); if (res == 0) { - BIO_puts(bio_err, "error: unable to add TLS extra certs\n"); + BIO_printf(bio_err, "error: unable to add TLS extra certs\n"); goto err; } } @@ -1615,7 +1556,7 @@ static SSL_CTX *setup_ssl_ctx(OSSL_CMP_CTX *ctx, const char *host) goto err; } if (SSL_CTX_use_PrivateKey(ssl_ctx, pkey) <= 0) { - CMP_err1("Unable to use TLS client private key '%s'", opt_tls_key); + CMP_err1("unable to use TLS client private key '%s'", opt_tls_key); EVP_PKEY_free(pkey); pkey = NULL; /* otherwise, for some reason double free! */ goto err; @@ -1630,7 +1571,8 @@ static SSL_CTX *setup_ssl_ctx(OSSL_CMP_CTX *ctx, const char *host) * If we did this before checking our own TLS cert * the expected hostname would mislead the check. */ - if (!truststore_set_host_etc(trust_store, host)) + if (!truststore_set_host_etc(trust_store, + opt_tls_host != NULL ? opt_tls_host : host)) goto err; } return ssl_ctx; @@ -1648,7 +1590,7 @@ err: static int setup_protection_ctx(OSSL_CMP_CTX *ctx) { if (!opt_unprotected_requests && opt_secret == NULL && opt_key == NULL) { - CMP_err("Must give -key or -secret unless -unprotected_requests is used"); + CMP_err("must give -key or -secret unless -unprotected_requests is used"); return 0; } @@ -1658,7 +1600,7 @@ static int setup_protection_ctx(OSSL_CMP_CTX *ctx) return 0; } if (opt_secret == NULL && ((opt_cert == NULL) != (opt_key == NULL))) { - CMP_err("Must give both -cert and -key options or neither"); + CMP_err("must give both -cert and -key options or neither"); return 0; } if (opt_secret != NULL) { @@ -1709,7 +1651,7 @@ static int setup_protection_ctx(OSSL_CMP_CTX *ctx) ok = OSSL_CMP_CTX_set1_cert(ctx, cert); X509_free(cert); if (!ok) { - CMP_err("Out of memory"); + CMP_err("out of memory"); } else { if (opt_own_trusted != NULL) { own_trusted = load_trusted(opt_own_trusted, 0, @@ -1738,12 +1680,12 @@ static int setup_protection_ctx(OSSL_CMP_CTX *ctx) int digest = OBJ_ln2nid(opt_digest); if (digest == NID_undef) { - CMP_err1("Digest algorithm name not recognized: '%s'", opt_digest); + CMP_err1("digest algorithm name not recognized: '%s'", opt_digest); return 0; } if (!OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_DIGEST_ALGNID, digest) || !OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_OWF_ALGNID, digest)) { - CMP_err1("Digest algorithm name not supported: '%s'", opt_digest); + CMP_err1("digest algorithm name not supported: '%s'", opt_digest); return 0; } } @@ -1765,7 +1707,8 @@ static int set_fallback_pubkey(OSSL_CMP_CTX *ctx) char *file = opt_reqin, *end = file, bak; OSSL_CMP_MSG *req; const X509_PUBKEY *pubkey; - EVP_PKEY *pkey, *pkey1; + EVP_PKEY *pkey; + EVP_PKEY *pkey1; int res = 0; /* temporarily separate first file name in opt_reqin */ @@ -1777,18 +1720,21 @@ static int set_fallback_pubkey(OSSL_CMP_CTX *ctx) *end = bak; if (req == NULL) { - CMP_err1("Failed to load ir/cr/kur file '%s' attempting to get fallback public key", file); + CMP_err1("failed to load ir/cr/kur file '%s' attempting to get fallback public key", + file); return 0; } if ((pubkey = OSSL_CMP_MSG_get0_certreq_publickey(req)) == NULL || (pkey = X509_PUBKEY_get0(pubkey)) == NULL) { - CMP_err1("Failed to get fallback public key from ir/cr/kur file '%s'", file); + CMP_err1("failed to get fallback public key from ir/cr/kur file '%s'", + file); goto err; } pkey1 = EVP_PKEY_dup(pkey); - if (pkey1 == NULL || !OSSL_CMP_CTX_set0_newPkey(ctx, 0 /* priv */, pkey1)) { + if (pkey == NULL || !OSSL_CMP_CTX_set0_newPkey(ctx, 0 /* priv */, pkey1)) { EVP_PKEY_free(pkey1); - CMP_err1("Failed to set fallback public key obtained from ir/cr/kur file '%s'", file); + CMP_err1("failed to get fallback public key obtained from ir/cr/kur file '%s'", + file); goto err; } res = 1; @@ -1819,7 +1765,7 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx) if (opt_cmd == CMP_IR || opt_cmd == CMP_CR || opt_cmd == CMP_KUR) { if (opt_reqin == NULL && opt_newkey == NULL && !opt_centralkeygen && opt_key == NULL && opt_csr == NULL && opt_oldcert == NULL) { - CMP_err("Missing -newkey (or -key) to be certified and no -csr, -oldcert, -cert, or -reqin option given, which could provide fallback public key." + CMP_err("missing -newkey (or -key) to be certified and no -csr, -oldcert, -cert, or -reqin option given, which could provide fallback public key." " Neither central key generation is requested."); return 0; } @@ -1842,14 +1788,14 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx) && opt_popo != OSSL_CRMF_POPO_NONE && opt_popo != OSSL_CRMF_POPO_RAVERIFIED) { if (opt_csr != NULL) { - CMP_err1("No -newkey option given with private key for POPO, -csr option provides just public key%s", + CMP_err1("no -newkey option given with private key for POPO, -csr option provides just public key%s", opt_key == NULL ? "" : ", and -key option superseded by -csr"); if (opt_reqin != NULL) CMP_info("since -reqin is used, may use -popo -1 or -popo 0 to disable the needless generation of a POPO"); return 0; } if (opt_key == NULL) { - CMP_err("Missing -newkey (or -key) option for key to be certified and for POPO"); + CMP_err("missing -newkey (or -key) option for key to be certified and for POPO"); return 0; } } @@ -1905,21 +1851,21 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx) char *ref_cert = opt_oldcert != NULL ? opt_oldcert : opt_cert; if (ref_cert == NULL && opt_csr == NULL) { - CMP_err("Missing -oldcert for certificate to be updated and no -csr given"); + CMP_err("missing -oldcert for certificate to be updated and no -csr given"); return 0; } if (opt_subject != NULL) - CMP_warn2("Given -subject '%s' overrides the subject of '%s' for KUR", + CMP_warn2("given -subject '%s' overrides the subject of '%s' for KUR", opt_subject, ref_cert != NULL ? ref_cert : opt_csr); } if (opt_cmd == CMP_RR) { if (opt_issuer == NULL && opt_serial == NULL) { if (opt_oldcert == NULL && opt_csr == NULL) { - CMP_err("Missing -oldcert or -issuer and -serial for certificate to be revoked and no -csr given"); + CMP_err("missing -oldcert or -issuer and -serial for certificate to be revoked and no -csr given"); return 0; } if (opt_oldcert != NULL && opt_csr != NULL) - CMP_warn("Ignoring -csr since certificate to be revoked is given"); + CMP_warn("ignoring -csr since certificate to be revoked is given"); } else { #define OSSL_CMP_RR_MSG "since -issuer and -serial is given for command 'rr'" if (opt_issuer == NULL || opt_serial == NULL) { @@ -1935,12 +1881,12 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx) ASN1_INTEGER *sno; if ((sno = s2i_ASN1_INTEGER(NULL, opt_serial)) == NULL) { - CMP_err1("Cannot read serial number: '%s'", opt_serial); + CMP_err1("cannot read serial number: '%s'", opt_serial); return 0; } if (!OSSL_CMP_CTX_set1_serialNumber(ctx, sno)) { ASN1_INTEGER_free(sno); - CMP_err("Out of memory"); + CMP_err("out of memory"); return 0; } ASN1_INTEGER_free(sno); @@ -1953,13 +1899,13 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx) CMP_warn("Ignoring -serial for command other than 'rr'"); } if (opt_cmd == CMP_P10CR && opt_csr == NULL) { - CMP_err("Missing PKCS#10 CSR for p10cr"); + CMP_err("missing PKCS#10 CSR for p10cr"); return 0; } if (opt_recipient == NULL && opt_srvcert == NULL && opt_issuer == NULL && opt_oldcert == NULL && opt_cert == NULL) - CMP_warn("Missing -recipient, -srvcert, -issuer, -oldcert or -cert; recipient for any requests not covered by -reqin will be set to \"NULL-DN\""); + CMP_warn("missing -recipient, -srvcert, -issuer, -oldcert or -cert; recipient for any requests not covered by -reqin will be set to \"NULL-DN\""); if (opt_cmd == CMP_P10CR || opt_cmd == CMP_RR || opt_cmd == CMP_GENM) { const char *msg = "option is ignored for 'p10cr', 'rr', and 'genm' commands"; @@ -1972,8 +1918,8 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx) CMP_warn1("-days %s", msg); if (opt_popo != OSSL_CRMF_POPO_NONE - 1) CMP_warn1("-popo %s", msg); - if (opt_cmd != CMP_P10CR && opt_out_trusted != NULL) - CMP_warn("-out_trusted is ignored for 'rr' and 'genm' commands"); + if (opt_out_trusted != NULL) + CMP_warn1("-out_trusted %s", msg); } else if (opt_newkey != NULL) { const char *file = opt_newkey; const int format = opt_keyform; @@ -1991,7 +1937,7 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx) desc = opt_csr == NULL ? "fallback public key for cert to be enrolled" : "public key for checking cert resulting from p10cr"; - pkey = load_pubkey_pwd(file, format, pass, desc); + pkey = load_pubkey(file, format, 0, pass, desc); priv = 0; } @@ -2007,13 +1953,14 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx) } if (opt_days > 0 - && !OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_VALIDITY_DAYS, opt_days)) { - CMP_err("Could not set requested cert validity period"); + && !OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_VALIDITY_DAYS, + opt_days)) { + CMP_err("could not set requested cert validity period"); return 0; } if (opt_policies != NULL && opt_policy_oids != NULL) { - CMP_err("Cannot have policies both via -policies and via -policy_oids"); + CMP_err("cannot have policies both via -policies and via -policy_oids"); return 0; } @@ -2035,12 +1982,14 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx) X509V3_set_nconf(&ext_ctx, conf); if (opt_reqexts != NULL && !X509V3_EXT_add_nconf_sk(conf, &ext_ctx, opt_reqexts, &exts)) { - CMP_err1("Cannot load certificate request extension section '%s'", opt_reqexts); + CMP_err1("cannot load certificate request extension section '%s'", + opt_reqexts); goto exts_err; } if (opt_policies != NULL && !X509V3_EXT_add_nconf_sk(conf, &ext_ctx, opt_policies, &exts)) { - CMP_err1("Cannot load policy cert request extension section '%s'", opt_policies); + CMP_err1("cannot load policy cert request extension section '%s'", + opt_policies); goto exts_err; } OSSL_CMP_CTX_set0_reqExtensions(ctx, exts); @@ -2049,7 +1998,7 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx) /* After here, must not goto oom/exts_err */ if (OSSL_CMP_CTX_reqExtensions_have_SAN(ctx) && opt_sans != NULL) { - CMP_err("Cannot have Subject Alternative Names both via -reqexts and via -sans"); + CMP_err("cannot have Subject Alternative Names both via -reqexts and via -sans"); return 0; } if (!set_gennames(ctx, opt_sans, "Subject Alternative Name")) @@ -2087,7 +2036,7 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx) pinfo->policyid = policy; if (!OSSL_CMP_CTX_push0_policy(ctx, pinfo)) { - CMP_err1("Cannot add policy with OID '%s'", opt_policy_oids); + CMP_err1("cannot add policy with OID '%s'", opt_policy_oids); POLICYINFO_free(pinfo); return 0; } @@ -2096,13 +2045,6 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx) if (opt_popo >= OSSL_CRMF_POPO_NONE) (void)OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_POPO_METHOD, opt_popo); - if (opt_cmd != CMP_RR) { - if (opt_revreason != CRL_REASON_NONE) - CMP_warn("-revreason option is ignored for commands other than 'rr'"); - if (opt_cmd != CMP_KUR && opt_oldcert != NULL) - CMP_warn("-oldcert option used only as reference cert"); - } - if (opt_oldcert != NULL) { if (opt_cmd == CMP_GENM) { CMP_warn("-oldcert option is ignored for 'genm' command"); @@ -2120,7 +2062,7 @@ static int setup_request_ctx(OSSL_CMP_CTX *ctx) return 1; oom: - CMP_err("Out of memory"); + CMP_err("out of memory"); exts_err: sk_X509_EXTENSION_pop_free(exts, X509_EXTENSION_free); X509_REQ_free(csr); @@ -2140,7 +2082,7 @@ static int add_certProfile(OSSL_CMP_CTX *ctx, const char *name) return 0; if ((utf8string = ASN1_UTF8STRING_new()) == NULL) goto err; - if (!ASN1_STRING_set_string(utf8string, name)) { + if (!ASN1_STRING_set(utf8string, name, (int)strlen(name))) { ASN1_STRING_free(utf8string); goto err; } @@ -2215,7 +2157,7 @@ static int handle_opt_geninfo(OSSL_CMP_CTX *ctx) else *end++ = '\0'; if ((text = ASN1_UTF8STRING_new()) == NULL - || !ASN1_STRING_set_string(text, ptr)) + || !ASN1_STRING_set(text, ptr, -1)) goto oom; ptr = end; ASN1_TYPE_set(type, V_ASN1_UTF8STRING, text); @@ -2242,7 +2184,7 @@ static int handle_opt_geninfo(OSSL_CMP_CTX *ctx) return 1; oom: - CMP_err("Out of memory"); + CMP_err("out of memory"); err: ASN1_OBJECT_free(obj); ASN1_TYPE_free(type); @@ -2274,25 +2216,26 @@ static int setup_client_ctx(OSSL_CMP_CTX *ctx) if (!opt_use_mock_srv && opt_rspin == NULL) { /* note: -port is not given */ #if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP) if (opt_server == NULL && opt_reqout_only == NULL) { - CMP_err("Missing -server or -use_mock_srv or -rspin option"); + CMP_err("missing -server or -use_mock_srv or -rspin option"); goto err; } #else - CMP_err("Missing -use_mock_srv or -rspin option; -server option is not supported due to no-sock build"); + CMP_err("missing -use_mock_srv or -rspin option; -server option is not supported due to no-sock build"); goto err; #endif } #if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP) if (opt_server == NULL) { if (opt_proxy != NULL) - CMP_warn("Ignoring -proxy option since -server is not given"); + CMP_warn("ignoring -proxy option since -server is not given"); if (opt_no_proxy != NULL) - CMP_warn("Ignoring -no_proxy option since -server is not given"); + CMP_warn("ignoring -no_proxy option since -server is not given"); goto set_path; } if (!OSSL_HTTP_parse_url(opt_server, &use_ssl, NULL /* user */, - &host, &port, &portnum, &path, NULL /* q */, NULL /* frag */)) { - CMP_err1("Cannot parse -server URL: %s", opt_server); + &host, &port, &portnum, + &path, NULL /* q */, NULL /* frag */)) { + CMP_err1("cannot parse -server URL: %s", opt_server); goto err; } if (use_ssl && !opt_tls_used) { @@ -2338,7 +2281,7 @@ set_path: strncat(id_buf, opt_infotype_s, sizeof(id_buf) - strlen(id_buf) - 1); if ((opt_infotype = OBJ_sn2nid(id_buf)) == NID_undef) { - CMP_err("Unknown OID name in -infotype option"); + CMP_err("unknown OID name in -infotype option"); goto err; } } @@ -2363,7 +2306,7 @@ set_path: CMP_warn1("-keyspec %s", msg); } else { if (opt_template == NULL) - CMP_err("Missing -template option for genm with infotype certReqTemplate"); + CMP_err("missing -template option for genm with infotype certReqTemplate"); } if (!setup_verification_ctx(ctx)) @@ -2403,10 +2346,10 @@ set_path: if (opt_tls_cert != NULL || opt_tls_key != NULL || opt_tls_keypass != NULL) { if (opt_tls_key == NULL) { - CMP_err("Missing -tls_key option"); + CMP_err("missing -tls_key option"); goto err; } else if (opt_tls_cert == NULL) { - CMP_err("Missing -tls_cert option"); + CMP_err("missing -tls_cert option"); goto err; } } @@ -2415,9 +2358,9 @@ set_path: goto err; APP_HTTP_TLS_INFO_free(OSSL_CMP_CTX_get_http_cb_arg(ctx)); (void)OSSL_CMP_CTX_set_http_cb_arg(ctx, info); - info->ssl_ctx = setup_ssl_ctx(ctx, opt_tls_host != NULL ? opt_tls_host : host); + info->ssl_ctx = setup_ssl_ctx(ctx, host); info->server = host; - host = NULL; /* ownership has been transferred to info structure */ + host = NULL; /* prevent deallocation */ if ((info->port = OPENSSL_strdup(server_port)) == NULL) goto err; /* workaround for callback design flaw, see #17088: */ @@ -2447,11 +2390,9 @@ set_path: goto err; /* not printing earlier, to minimize confusion in case setup fails before */ - if (opt_reqout_only != NULL) - CMP_info("Will not contact any server"); - else - CMP_info3("Will contact %s%s%s ", server_buf, proxy_buf, - opt_rspin == NULL ? "" : " only if -rspin argument does not give enough filenames"); + if (opt_reqout_only == NULL) + CMP_info3("will contact %s%s%s ", server_buf, proxy_buf, + opt_rspin == NULL ? "" : " only if -rspin argument gives too few filenames"); ret = 1; @@ -2461,7 +2402,7 @@ err: OPENSSL_free(path); return ret; oom: - CMP_err("Out of memory"); + CMP_err("out of memory"); goto err; } @@ -2514,13 +2455,14 @@ static int save_free_certs(STACK_OF(X509) *certs, if (file == NULL) goto end; if (certs != NULL) - CMP_info3("Received %d %s certificate(s), saving to file '%s'", n, desc, file); + CMP_info3("received %d %s certificate(s), saving to file '%s'", + n, desc, file); if (n > 1 && opt_certform != FORMAT_PEM) - CMP_warn("Saving more than one certificate in non-PEM format"); + CMP_warn("saving more than one certificate in non-PEM format"); if ((bio = BIO_new(BIO_s_file())) == NULL || !BIO_write_filename(bio, (char *)file)) { - CMP_err3("Could not open file '%s' for %s %s certificate(s)", + CMP_err3("could not open file '%s' for %s %s certificate(s)", file, certs == NULL ? "deleting" : "writing", desc); n = -1; goto end; @@ -2528,7 +2470,7 @@ static int save_free_certs(STACK_OF(X509) *certs, for (i = 0; i < n; i++) { if (!write_cert(bio, sk_X509_value(certs, i))) { - CMP_err2("Cannot write %s certificate to file '%s'", desc, file); + CMP_err2("cannot write %s certificate to file '%s'", desc, file); n = -1; goto end; } @@ -2549,16 +2491,17 @@ static int save_crl(X509_CRL *crl, if (file == NULL) return 1; if (crl != NULL) - CMP_info2("Received %s, saving to file '%s'", desc, file); + CMP_info2("received %s, saving to file '%s'", desc, file); if ((bio = BIO_new(BIO_s_file())) == NULL || !BIO_write_filename(bio, (char *)file)) { - CMP_err2("Could not open file '%s' for writing %s", file, desc); + CMP_err2("could not open file '%s' for writing %s", + file, desc); goto end; } if (!write_crl(bio, crl)) { - CMP_err2("Cannot write %s to file '%s'", desc, file); + CMP_err2("cannot write %s to file '%s'", desc, file); goto end; } res = 1; @@ -2613,15 +2556,18 @@ static int save_template(const char *file, const OSSL_CRMF_CERTTEMPLATE *tmpl) BIO *bio = BIO_new_file(file, "wb"); if (bio == NULL) { - CMP_err1("Error saving certTemplate from genp: cannot open file %s", file); + CMP_err1("error saving certTemplate from genp: cannot open file %s", + file); return 0; } - if (!ASN1_i2d_bio_of(OSSL_CRMF_CERTTEMPLATE, i2d_OSSL_CRMF_CERTTEMPLATE, bio, tmpl)) { - CMP_err1("Error saving certTemplate from genp: cannot write file %s", file); + if (!ASN1_i2d_bio_of(OSSL_CRMF_CERTTEMPLATE, i2d_OSSL_CRMF_CERTTEMPLATE, + bio, tmpl)) { + CMP_err1("error saving certTemplate from genp: cannot write file %s", + file); BIO_free(bio); return 0; } else { - CMP_info1("Stored certTemplate from genp to file '%s'", file); + CMP_info1("stored certTemplate from genp to file '%s'", file); } BIO_free(bio); return 1; @@ -2632,16 +2578,16 @@ static int save_keyspec(const char *file, const OSSL_CMP_ATAVS *keyspec) BIO *bio = BIO_new_file(file, "wb"); if (bio == NULL) { - CMP_err1("Error saving keySpec from genp: cannot open file %s", file); + CMP_err1("error saving keySpec from genp: cannot open file %s", file); return 0; } if (!ASN1_i2d_bio_of(OSSL_CMP_ATAVS, i2d_OSSL_CMP_ATAVS, bio, keyspec)) { - CMP_err1("Error saving keySpec from genp: cannot write file %s", file); + CMP_err1("error saving keySpec from genp: cannot write file %s", file); BIO_free(bio); return 0; } else { - CMP_info1("Stored keySpec from genp to file '%s'", file); + CMP_info1("stored keySpec from genp to file '%s'", file); } BIO_free(bio); return 1; @@ -2674,12 +2620,12 @@ static int print_itavs(const STACK_OF(OSSL_CMP_ITAV) *itavs) char name[80]; if (itav == NULL) { - CMP_err1("Could not get ITAV #%d from genp", i); + CMP_err1("could not get ITAV #%d from genp", i); ret = 0; continue; } if (i2t_ASN1_OBJECT(name, sizeof(name), type) <= 0) { - CMP_err1("Error parsing type of ITAV #%d from genp", i); + CMP_err1("error parsing type of ITAV #%d from genp", i); ret = 0; } else { CMP_info2("ITAV #%d from genp infoType=%s", i, name); @@ -2707,7 +2653,7 @@ static const char *prev_item(const char *opt, const char *end) } len = end - beg; if (len > SECTION_NAME_MAX) { - CMP_warn3("Using only first %d characters of section name starting with \"%.*s\"", + CMP_warn3("using only first %d characters of section name starting with \"%.*s\"", SECTION_NAME_MAX, SECTION_NAME_MAX, beg); len = SECTION_NAME_MAX; } @@ -2828,7 +2774,8 @@ static int read_config(void) } break; default: - CMP_err2("Internal: unsupported type '%c' for option '%s'", opt->valtype, opt->name); + CMP_err2("internal: unsupported type '%c' for option '%s'", + opt->valtype, opt->name); return 0; break; } @@ -2854,7 +2801,8 @@ static int read_config(void) if (provider_option ? !opt_provider(opt_next()) : !opt_verify(opt_next(), vpm)) { - CMP_err2("For option '%s' in config file section '%s'", opt->name, opt_section); + CMP_err2("for option '%s' in config file section '%s'", + opt->name, opt_section); return 0; } } @@ -3028,9 +2976,6 @@ static int get_opts(int argc, char **argv) case OPT_UNPROTECTED_ERRORS: opt_unprotected_errors = 1; break; - case OPT_NONMATCHED_ERROR_NONCES: - opt_nonmatched_error_nonces = 1; - break; case OPT_TA_IN_IP_EXTRACERTS: opt_ta_in_ip_extracerts = 1; break; @@ -3130,7 +3075,7 @@ static int get_opts(int argc, char **argv) opt_popo = opt_int_arg(); if (opt_popo < OSSL_CRMF_POPO_NONE || opt_popo > OSSL_CRMF_POPO_KEYENC) { - CMP_err("Invalid popo spec. Valid values are -1 .. 2"); + CMP_err("invalid popo spec. Valid values are -1 .. 2"); goto opthelp; } break; @@ -3160,7 +3105,7 @@ static int get_opts(int argc, char **argv) if (opt_revreason < CRL_REASON_NONE || opt_revreason > CRL_REASON_AA_COMPROMISE || opt_revreason == 7) { - CMP_err("Invalid revreason. Valid values are -1 .. 6, 8 .. 10"); + CMP_err("invalid revreason. Valid values are -1 .. 6, 8 .. 10"); goto opthelp; } break; @@ -3364,7 +3309,8 @@ static int cmp_server(OSSL_CMP_CTX *srv_cmp_ctx) if (req != NULL) { if (strcmp(path, "") != 0 && strcmp(path, "pkix/") != 0) { (void)http_server_send_status(prog, cbio, 404, "Not Found"); - CMP_err1("Expecting empty path or 'pkix/' but got '%s'", path); + CMP_err1("expecting empty path or 'pkix/' but got '%s'", + path); OPENSSL_free(path); OSSL_CMP_MSG_free(req); goto next; @@ -3436,19 +3382,13 @@ static void print_keyspec(OSSL_CMP_ATAVS *keySpec) int paramtype; const void *param; - /* NULL check to prevent dereferencing a NULL pointer when print_keyspec is called */ - if (alg == NULL) { - BIO_puts(mem, "Key algorithm: \n"); - break; - } - X509_ALGOR_get0(&oid, ¶mtype, ¶m, alg); - BIO_puts(mem, "Key algorithm: "); + BIO_printf(mem, "Key algorithm: "); i2a_ASN1_OBJECT(mem, oid); if (paramtype == V_ASN1_UNDEF || alg->parameter == NULL) { - BIO_puts(mem, "\n"); + BIO_printf(mem, "\n"); } else { - BIO_puts(mem, " - "); + BIO_printf(mem, " - "); ASN1_item_print(mem, (ASN1_VALUE *)alg, 0, ASN1_ITEM_rptr(X509_ALGOR), NULL); } @@ -3517,7 +3457,7 @@ static int do_genm(OSSL_CMP_CTX *ctx) /* could check authorization of sender/origin at this point */ if (cacerts == NULL) { - CMP_warn("No CA certificates provided by server"); + CMP_warn("no CA certificates provided by server"); } else if (save_free_certs(cacerts, opt_cacertsout, "CA") < 0) { CMP_err1("Failed to store CA certificates from genp in %s", opt_cacertsout); @@ -3549,9 +3489,9 @@ static int do_genm(OSSL_CMP_CTX *ctx) /* At this point might check authorization of response sender/origin */ if (newwithnew == NULL) - CMP_info("No root CA certificate update available"); + CMP_info("no root CA certificate update available"); else if (oldwithold == NULL && oldwithnew != NULL) - CMP_warn("OldWithNew certificate received in genp for verifying oldWithOld, but oldWithOld was not provided"); + CMP_warn("oldWithNew certificate received in genp for verifying oldWithOld, but oldWithOld was not provided"); if (save_cert_or_delete(newwithnew, opt_newwithnew, "NewWithNew cert from genp") @@ -3607,7 +3547,7 @@ static int do_genm(OSSL_CMP_CTX *ctx) goto end_crlupd; if (crl == NULL) - CMP_info("No CRL update available"); + CMP_info("no CRL update available"); if (!save_crl_or_delete(crl, opt_crlout, desc)) goto end_crlupd; @@ -3628,7 +3568,7 @@ static int do_genm(OSSL_CMP_CTX *ctx) return 0; if (certTemplate == NULL) { - CMP_warn("No certificate request template available"); + CMP_warn("no certificate request template available"); if (!delete_file(opt_template, "certTemplate from genp")) return 0; if (opt_keyspec != NULL @@ -3642,7 +3582,7 @@ static int do_genm(OSSL_CMP_CTX *ctx) print_keyspec(keySpec); if (opt_keyspec != NULL) { if (keySpec == NULL) { - CMP_warn("No key specifications available"); + CMP_warn("no key specifications available"); if (!delete_file(opt_keyspec, "keySpec from genp")) goto tmpl_end; } else if (!save_keyspec(opt_keyspec, keySpec)) { @@ -3671,10 +3611,7 @@ static int do_genm(OSSL_CMP_CTX *ctx) } } - itavs = OSSL_CMP_exec_GENM_ses(ctx); - if (reqout_only_done && OSSL_CMP_CTX_get_status(ctx) == OSSL_CMP_PKISTATUS_trans) - return 1; /* not checking response as we did not send request */ - if (itavs != NULL) { + if ((itavs = OSSL_CMP_exec_GENM_ses(ctx)) != NULL) { int res = print_itavs(itavs); sk_OSSL_CMP_ITAV_pop_free(itavs, OSSL_CMP_ITAV_free); @@ -3728,7 +3665,7 @@ int cmp_main(int argc, char **argv) vpm = X509_VERIFY_PARAM_new(); if (vpm == NULL) { - CMP_err("Out of memory"); + CMP_err("out of memory"); goto err; } @@ -3737,7 +3674,7 @@ int cmp_main(int argc, char **argv) if (configfile != NULL && configfile[0] != '\0' /* non-empty string */ && (configfile != default_config_file || access(configfile, F_OK) != -1)) { - CMP_info2("Using section(s) '%s' of OpenSSL configuration file '%s'", + CMP_info2("using section(s) '%s' of OpenSSL configuration file '%s'", opt_section, configfile); conf = app_load_config(configfile); if (conf == NULL) { @@ -3745,7 +3682,7 @@ int cmp_main(int argc, char **argv) } else { if (strcmp(opt_section, CMP_SECTION) == 0) { /* default */ if (!NCONF_get_section(conf, opt_section)) - CMP_info2("No [%s] section found in config file '%s';" + CMP_info2("no [%s] section found in config file '%s';" " will thus use just [default] and unnamed section if present", opt_section, configfile); } else { @@ -3753,7 +3690,8 @@ int cmp_main(int argc, char **argv) while ((end = prev_item(opt_section, end)) != NULL) { if (!NCONF_get_section(conf, opt_item)) { - CMP_err2("No [%s] section found in config file '%s'", opt_item, configfile); + CMP_err2("no [%s] section found in config file '%s'", + opt_item, configfile); goto err; } } @@ -3763,7 +3701,7 @@ int cmp_main(int argc, char **argv) ret = -1; if (ret <= 0) { if (ret == -1) - BIO_puts(bio_err, "Use -help for summary.\n"); + BIO_printf(bio_err, "Use -help for summary.\n"); goto err; } } @@ -3787,7 +3725,7 @@ int cmp_main(int argc, char **argv) OSSL_CMP_CTX_set_log_verbosity(cmp_ctx, opt_verbosity); if (!OSSL_CMP_CTX_set_log_cb(cmp_ctx, print_to_bio_out)) { - CMP_err1("Cannot set up error reporting and logging for %s", prog); + CMP_err1("cannot set up error reporting and logging for %s", prog); goto err; } @@ -3796,9 +3734,9 @@ int cmp_main(int argc, char **argv) && opt_tls_extra == NULL && opt_tls_trusted == NULL && opt_tls_host == NULL) { if (opt_tls_used) - CMP_warn("-tls_used is active without any other TLS options"); + CMP_warn("-tls_used given without any other TLS options"); } else if (!opt_tls_used) { - CMP_warn("Ignoring TLS options(s) since -tls_used is not active"); + CMP_warn("ignoring TLS options(s) since -tls_used is not given"); } if (opt_port != NULL) { if (opt_tls_used) { @@ -3820,11 +3758,11 @@ int cmp_main(int argc, char **argv) } if (opt_server != NULL && opt_use_mock_srv) { - CMP_err("Cannot use both -server and -use_mock_srv options"); + CMP_err("cannot use both -server and -use_mock_srv options"); goto err; } if ((opt_server == NULL || opt_use_mock_srv) && opt_tls_used) { - CMP_warn("Ignoring -tls_used option since -server is not given or -use_mock_srv is given"); + CMP_warn("ignoring -tls_used option since -server is not given or -use_mock_srv is given"); opt_tls_used = 0; } @@ -3833,7 +3771,8 @@ int cmp_main(int argc, char **argv) if (opt_ignore_keyusage) (void)OSSL_CMP_CTX_set_option(cmp_ctx, OSSL_CMP_OPT_IGNORE_KEYUSAGE, 1); if (opt_no_cache_extracerts) - (void)OSSL_CMP_CTX_set_option(cmp_ctx, OSSL_CMP_OPT_NO_CACHE_EXTRACERTS, 1); + (void)OSSL_CMP_CTX_set_option(cmp_ctx, OSSL_CMP_OPT_NO_CACHE_EXTRACERTS, + 1); if (opt_reqout_only == NULL && (opt_use_mock_srv #if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP) @@ -3849,14 +3788,10 @@ int cmp_main(int argc, char **argv) srv_cmp_ctx = OSSL_CMP_SRV_CTX_get0_cmp_ctx(srv_ctx); if (!OSSL_CMP_CTX_set_log_cb(srv_cmp_ctx, print_to_bio_err)) { - CMP_err1("Cannot set up server-side error reporting and logging for %s", prog); + CMP_err1("cannot set up error reporting and logging for %s", prog); goto err; } OSSL_CMP_CTX_set_log_verbosity(srv_cmp_ctx, opt_verbosity); - if (opt_ignore_keyusage) - (void)OSSL_CMP_CTX_set_option(srv_cmp_ctx, OSSL_CMP_OPT_IGNORE_KEYUSAGE, 1); - if (opt_no_cache_extracerts) - (void)OSSL_CMP_CTX_set_option(srv_cmp_ctx, OSSL_CMP_OPT_NO_CACHE_EXTRACERTS, 1); #if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP) if (opt_port != NULL) { /* act as very basic CMP HTTP server only */ @@ -3876,20 +3811,11 @@ int cmp_main(int argc, char **argv) CMP_err("the -reqout_only client option does not combine with -port implying server behavior"); goto err; } - if (opt_server != NULL) { + if (opt_server != NULL) CMP_warn1("-server %s", msg); - opt_server = NULL; - } #endif - if (opt_path != NULL) { - CMP_warn1("-path %s", msg); - opt_path = NULL; - } - - if (opt_use_mock_srv) { + if (opt_use_mock_srv) CMP_warn1("-use_mock_srv %s", msg); - opt_use_mock_srv = 0; - } if (opt_reqout != NULL) CMP_warn1("-reqout %s", msg); if (opt_rspin != NULL) @@ -3898,21 +3824,17 @@ int cmp_main(int argc, char **argv) CMP_warn1("-rspout %s", msg); opt_reqout = opt_reqout_only; } -#if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP) - if (opt_server == NULL && !opt_use_mock_srv && opt_port == NULL) - CMP_info("Will not contact any server"); -#endif if (opt_rspin != NULL) { #if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP) if (opt_server != NULL) - CMP_warn("-server option etc. are not used if enough filenames given for -rspin"); + CMP_warn("-server option is not used if enough filenames given for -rspin"); #endif if (opt_use_mock_srv) CMP_warn("-use_mock_srv option is not used if enough filenames given for -rspin"); } if (!setup_client_ctx(cmp_ctx)) { - CMP_err("Cannot set up CMP context"); + CMP_err("cannot set up CMP context"); goto err; } for (i = 0; i < opt_repeat; i++) { @@ -4004,7 +3926,7 @@ int cmp_main(int argc, char **argv) cipher = EVP_CIPHER_fetch(app_get0_libctx(), SN_aes_256_cbc, app_get0_propq()); } - CMP_info1("Saving centrally generated key to file '%s'", opt_newkeyout); + CMP_info1("saving centrally generated key to file '%s'", opt_newkeyout); if (PEM_write_bio_PrivateKey(out, new_key, cipher, NULL, 0, NULL, (void *)pass_string) <= 0) @@ -4048,7 +3970,11 @@ err: /* cannot free info already here, as it may be used indirectly by: */ OSSL_CMP_CTX_free(cmp_ctx); #if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP) - APP_HTTP_TLS_INFO_free(info); + if (info != NULL) { + OPENSSL_free((char *)info->server); + OPENSSL_free((char *)info->port); + APP_HTTP_TLS_INFO_free(info); + } #endif } X509_VERIFY_PARAM_free(vpm); diff --git a/apps/cms.c b/apps/cms.c index 5e32ab55af..df13876b23 100644 --- a/apps/cms.c +++ b/apps/cms.c @@ -1,5 +1,5 @@ /* - * Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2008-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -284,9 +284,9 @@ const OPTIONS cms_options[] = { { "cades", OPT_DUP, '-', "Check signingCertificate (CAdES-BES)" }, { "verify_retcode", OPT_VERIFY_RETCODE, '-', "Exit non-zero on verification failure" }, - { "CAfile", OPT_CAFILE, '<', "File in PEM format with trusted CA certs" }, - { "CApath", OPT_CAPATH, '/', "Dir with trusted CA cert files in PEM format" }, - { "CAstore", OPT_CASTORE, ':', "URI of store with trusted CA certs" }, + { "CAfile", OPT_CAFILE, '<', "Trusted certificates file" }, + { "CApath", OPT_CAPATH, '/', "Trusted certificates directory" }, + { "CAstore", OPT_CASTORE, ':', "Trusted certificates store URI" }, { "no-CAfile", OPT_NOCAFILE, '-', "Do not load the default certificates file" }, { "no-CApath", OPT_NOCAPATH, '-', @@ -323,7 +323,7 @@ static CMS_ContentInfo *load_content_info(int informat, BIO *in, int flags, ret = CMS_ContentInfo_new_ex(app_get0_libctx(), app_get0_propq()); if (ret == NULL) { - BIO_puts(bio_err, "Error allocating CMS_contentinfo\n"); + BIO_printf(bio_err, "Error allocating CMS_contentinfo\n"); return NULL; } switch (informat) { @@ -791,7 +791,7 @@ int cms_main(int argc, char **argv) keyidx += sk_OPENSSL_STRING_num(skkeys); } if (keyidx < 0) { - BIO_puts(bio_err, "No key specified\n"); + BIO_printf(bio_err, "No key specified\n"); goto opthelp; } if (key_param == NULL || key_param->idx != keyidx) { @@ -908,7 +908,7 @@ int cms_main(int argc, char **argv) goto end; } if (sksigners == NULL) { - BIO_puts(bio_err, "No signer certificate specified\n"); + BIO_printf(bio_err, "No signer certificate specified\n"); goto opthelp; } signerfile = NULL; @@ -916,23 +916,23 @@ int cms_main(int argc, char **argv) } else if (operation == SMIME_DECRYPT) { if (recipfile == NULL && keyfile == NULL && secret_key == NULL && pwri_pass == NULL) { - BIO_puts(bio_err, + BIO_printf(bio_err, "No recipient certificate or key specified\n"); goto opthelp; } } else if (operation == SMIME_ENCRYPT) { if (*argv == NULL && secret_key == NULL && pwri_pass == NULL && sk_X509_num(encerts) <= 0) { - BIO_puts(bio_err, "No recipient(s) certificate(s) specified\n"); + BIO_printf(bio_err, "No recipient(s) certificate(s) specified\n"); goto opthelp; } } else if (!operation) { - BIO_puts(bio_err, "No operation option (-encrypt|-decrypt|-sign|-verify|...) specified.\n"); + BIO_printf(bio_err, "No operation option (-encrypt|-decrypt|-sign|-verify|...) specified.\n"); goto opthelp; } if (!app_passwd(passinarg, NULL, &passin, NULL)) { - BIO_puts(bio_err, "Error getting password\n"); + BIO_printf(bio_err, "Error getting password\n"); goto end; } @@ -940,19 +940,19 @@ int cms_main(int argc, char **argv) if ((operation & SMIME_SIGNERS) == 0) { if ((flags & CMS_DETACHED) == 0) - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: -nodetach option is ignored for non-signing operation\n"); flags &= ~CMS_DETACHED; } if ((operation & SMIME_IP) == 0 && contfile != NULL) - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: -contfile option is ignored for the given operation\n"); if (operation != SMIME_ENCRYPT && *argv != NULL) - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: recipient certificate file parameters ignored for operation other than -encrypt\n"); if (operation != SMIME_ENCRYPT && recip_first != NULL) - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: -recip_kdf and -recip_ukm parameters ignored for operation other than -encrypt\n"); if ((flags & CMS_BINARY) != 0) { @@ -970,7 +970,7 @@ int cms_main(int argc, char **argv) if (!cipher) cipher = (EVP_CIPHER *)EVP_aes_256_cbc(); if (secret_key && !secret_keyid) { - BIO_puts(bio_err, "No secret key id\n"); + BIO_printf(bio_err, "No secret key id\n"); goto end; } @@ -1025,20 +1025,20 @@ int cms_main(int argc, char **argv) if (digesthex != NULL) { if (operation != SMIME_SIGN) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Cannot use -digest for non-signing operation\n"); goto end; } if (infile != NULL || (flags & CMS_DETACHED) == 0 || (flags & CMS_STREAM) != 0) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Cannot use -digest when -in, -nodetach or streaming is used\n"); goto end; } digestbin = OPENSSL_hexstr2buf(digesthex, &digestlen); if (digestbin == NULL) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Invalid hex value after -digest\n"); goto end; } @@ -1213,7 +1213,7 @@ int cms_main(int argc, char **argv) if (originator != NULL && ERR_GET_REASON(ERR_peek_error()) == CMS_R_ERROR_UNSUPPORTED_STATIC_KEY_AGREEMENT) { - BIO_puts(bio_err, "Cannot use originator for encryption\n"); + BIO_printf(bio_err, "Cannot use originator for encryption\n"); goto end; } goto end; @@ -1327,7 +1327,7 @@ int cms_main(int argc, char **argv) } if (cms == NULL) { - BIO_puts(bio_err, "Error creating CMS structure\n"); + BIO_printf(bio_err, "Error creating CMS structure\n"); goto end; } @@ -1360,7 +1360,7 @@ int cms_main(int argc, char **argv) } if (!CMS_decrypt(cms, NULL, NULL, indata, out, flags)) { - BIO_puts(bio_err, "Error decrypting CMS structure\n"); + BIO_printf(bio_err, "Error decrypting CMS structure\n"); goto end; } } else if (operation == SMIME_DATA_OUT) { @@ -1371,9 +1371,9 @@ int cms_main(int argc, char **argv) goto end; } else if (operation == SMIME_DIGEST_VERIFY) { if (CMS_digest_verify(cms, indata, out, flags) > 0) { - BIO_puts(bio_err, "Verification successful\n"); + BIO_printf(bio_err, "Verification successful\n"); } else { - BIO_puts(bio_err, "Verification failure\n"); + BIO_printf(bio_err, "Verification failure\n"); goto end; } } else if (operation == SMIME_ENCRYPTED_DECRYPT) { @@ -1407,9 +1407,9 @@ int cms_main(int argc, char **argv) } else if (operation == SMIME_VERIFY_RECEIPT) { if (CMS_verify_receipt(rcms, cms, other, store, flags) > 0) { - BIO_puts(bio_err, "Verification successful\n"); + BIO_printf(bio_err, "Verification successful\n"); } else { - BIO_puts(bio_err, "Verification failure\n"); + BIO_printf(bio_err, "Verification failure\n"); goto end; } } else { @@ -1445,11 +1445,11 @@ int cms_main(int argc, char **argv) } else if (outformat == FORMAT_ASN1) { ret = i2d_CMS_bio_stream(out, cms, in, flags); } else { - BIO_puts(bio_err, "Bad output format for CMS file\n"); + BIO_printf(bio_err, "Bad output format for CMS file\n"); goto end; } if (ret <= 0) { - BIO_puts(bio_err, "Error writing CMS output\n"); + BIO_printf(bio_err, "Error writing CMS output\n"); ret = 6; goto end; } @@ -1580,15 +1580,13 @@ static void receipt_request_print(CMS_ContentInfo *cms) ERR_print_errors(bio_err); } else { const char *id; - size_t idlen; + int idlen; CMS_ReceiptRequest_get0_values(rr, &scid, &allorfirst, &rlist, &rto); BIO_puts(bio_err, " Signed Content ID:\n"); - idlen = ASN1_STRING_length_ex(scid); - if (idlen > INT_MAX) - idlen = INT_MAX; + idlen = ASN1_STRING_length(scid); id = (const char *)ASN1_STRING_get0_data(scid); - BIO_dump_indent(bio_err, id, (int)idlen, 4); + BIO_dump_indent(bio_err, id, idlen, 4); BIO_puts(bio_err, " Receipts From"); if (rlist != NULL) { BIO_puts(bio_err, " List:\n"); diff --git a/apps/configutl.c b/apps/configutl.c index d1bee103e3..e564ce06d3 100644 --- a/apps/configutl.c +++ b/apps/configutl.c @@ -1,5 +1,5 @@ /* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -28,20 +28,20 @@ static void print_escaped_value(BIO *out, const char *value) case '#': case '\\': case '$': - BIO_puts(out, "\\"); + BIO_printf(out, "\\"); BIO_write(out, p, 1); break; case '\n': - BIO_puts(out, "\\n"); + BIO_printf(out, "%s", "\\n"); break; case '\r': - BIO_puts(out, "\\r"); + BIO_printf(out, "%s", "\\r"); break; case '\b': - BIO_puts(out, "\\b"); + BIO_printf(out, "%s", "\\b"); break; case '\t': - BIO_puts(out, "\\t"); + BIO_printf(out, "%s", "\\t"); break; case ' ': if (p == value || p[1] == '\0') { @@ -56,7 +56,7 @@ static void print_escaped_value(BIO *out, const char *value) * more trouble than adding the quotes just around the * first and last leading and trailing space. */ - BIO_puts(out, "\" \""); + BIO_printf(out, "%s", "\" \""); break; } /* FALLTHROUGH */ @@ -80,7 +80,7 @@ static void print_section(BIO *out, const CONF *cnf, OPENSSL_CSTRING section_nam BIO_printf(out, "%s = ", value->name); print_escaped_value(out, value->value); - BIO_puts(out, "\n"); + BIO_printf(out, "\n"); } } diff --git a/apps/crl.c b/apps/crl.c index ba0f323a6b..3c0987b98e 100644 --- a/apps/crl.c +++ b/apps/crl.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -84,9 +84,9 @@ const OPTIONS crl_options[] = { { "gendelta", OPT_GENDELTA, '<', "Other CRL to compare/diff to the Input one" }, OPT_SECTION("Certificate"), - { "CAfile", OPT_CAFILE, '<', "File in PEM format with trusted CA certs" }, - { "CApath", OPT_CAPATH, '/', "Dir with trusted CA cert files in PEM format" }, - { "CAstore", OPT_CASTORE, ':', "URI of store with trusted CA certs" }, + { "CApath", OPT_CAPATH, '/', "Verify CRL using certificates in dir" }, + { "CAfile", OPT_CAFILE, '<', "Verify CRL using certificates in file name" }, + { "CAstore", OPT_CASTORE, ':', "Verify CRL using certificates in store URI" }, { "no-CAfile", OPT_NOCAFILE, '-', "Do not load the default certificates file" }, { "no-CApath", OPT_NOCAPATH, '-', @@ -252,20 +252,20 @@ int crl_main(int argc, char **argv) goto end; ctx = X509_STORE_CTX_new(); if (ctx == NULL || !X509_STORE_CTX_init(ctx, store, NULL, NULL)) { - BIO_puts(bio_err, "Error initialising X509 store\n"); + BIO_printf(bio_err, "Error initialising X509 store\n"); goto end; } xobj = X509_STORE_CTX_get_obj_by_subject(ctx, X509_LU_X509, X509_CRL_get_issuer(x)); if (xobj == NULL) { - BIO_puts(bio_err, "Error getting CRL issuer certificate\n"); + BIO_printf(bio_err, "Error getting CRL issuer certificate\n"); goto end; } pkey = X509_get_pubkey(X509_OBJECT_get0_X509(xobj)); X509_OBJECT_free(xobj); if (pkey == NULL) { - BIO_puts(bio_err, "Error getting CRL issuer public key\n"); + BIO_printf(bio_err, "Error getting CRL issuer public key\n"); goto end; } i = X509_CRL_verify(x, pkey); @@ -273,10 +273,11 @@ int crl_main(int argc, char **argv) if (i < 0) goto end; if (i == 0) { - BIO_puts(bio_err, "verify failure\n"); + BIO_printf(bio_err, "verify failure\n"); goto end; - } else - BIO_puts(bio_err, "verify OK\n"); + } else { + BIO_printf(bio_err, "verify OK\n"); + } } if (crldiff != NULL) { @@ -309,11 +310,7 @@ int crl_main(int argc, char **argv) const ASN1_BIT_STRING *sig; X509_CRL_get0_signature(x, &sig, NULL); - /* XXX Casts away const, because it mutates the value! */ - if (!corrupt_signature((ASN1_BIT_STRING *)sig)) { - BIO_puts(bio_err, "Error corrupting signature\n"); - goto end; - } + corrupt_signature(sig); } if (num) { @@ -325,7 +322,7 @@ int crl_main(int argc, char **argv) ASN1_INTEGER *crlnum; crlnum = X509_CRL_get_ext_d2i(x, NID_crl_number, NULL, NULL); - BIO_puts(bio_out, "crlNumber="); + BIO_printf(bio_out, "crlNumber="); if (crlnum) { BIO_puts(bio_out, "0x"); i2a_ASN1_INTEGER(bio_out, crlnum); @@ -333,7 +330,7 @@ int crl_main(int argc, char **argv) } else { BIO_puts(bio_out, ""); } - BIO_puts(bio_out, "\n"); + BIO_printf(bio_out, "\n"); } if (hash == i) { int ok; @@ -341,7 +338,7 @@ int crl_main(int argc, char **argv) app_get0_propq(), &ok); if (num > 1) - BIO_puts(bio_out, "issuer name hash="); + BIO_printf(bio_out, "issuer name hash="); if (ok) { BIO_printf(bio_out, "%08lx\n", hash_value); } else { @@ -352,23 +349,23 @@ int crl_main(int argc, char **argv) #ifndef OPENSSL_NO_MD5 if (hash_old == i) { if (num > 1) - BIO_puts(bio_out, "issuer name old hash="); + BIO_printf(bio_out, "issuer name old hash="); BIO_printf(bio_out, "%08lx\n", X509_NAME_hash_old(X509_CRL_get_issuer(x))); } #endif if (lastupdate == i) { - BIO_puts(bio_out, "lastUpdate="); + BIO_printf(bio_out, "lastUpdate="); ASN1_TIME_print_ex(bio_out, X509_CRL_get0_lastUpdate(x), dateopt); - BIO_puts(bio_out, "\n"); + BIO_printf(bio_out, "\n"); } if (nextupdate == i) { - BIO_puts(bio_out, "nextUpdate="); + BIO_printf(bio_out, "nextUpdate="); if (X509_CRL_get0_nextUpdate(x)) ASN1_TIME_print_ex(bio_out, X509_CRL_get0_nextUpdate(x), dateopt); else - BIO_puts(bio_out, "NONE"); - BIO_puts(bio_out, "\n"); + BIO_printf(bio_out, "NONE"); + BIO_printf(bio_out, "\n"); } if (fingerprint == i) { int j; @@ -376,7 +373,7 @@ int crl_main(int argc, char **argv) unsigned char md[EVP_MAX_MD_SIZE]; if (!X509_CRL_digest(x, digest, md, &n)) { - BIO_puts(bio_err, "out of memory\n"); + BIO_printf(bio_err, "out of memory\n"); goto end; } BIO_printf(bio_out, "%s Fingerprint=", @@ -404,7 +401,7 @@ int crl_main(int argc, char **argv) else i = PEM_write_bio_X509_CRL(out, x); if (!i) { - BIO_puts(bio_err, "unable to write CRL\n"); + BIO_printf(bio_err, "unable to write CRL\n"); goto end; } ret = 0; diff --git a/apps/crl2pkcs7.c b/apps/crl2pkcs7.c index 8b61a37e45..72d385250a 100644 --- a/apps/crl2pkcs7.c +++ b/apps/crl2pkcs7.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -121,7 +121,7 @@ int crl2pkcs7_main(int argc, char **argv) else if (informat == FORMAT_PEM) crl = PEM_read_bio_X509_CRL(in, NULL, NULL, NULL); if (crl == NULL) { - BIO_puts(bio_err, "unable to load CRL\n"); + BIO_printf(bio_err, "unable to load CRL\n"); ERR_print_errors(bio_err); goto end; } @@ -156,7 +156,7 @@ int crl2pkcs7_main(int argc, char **argv) for (i = 0; i < sk_OPENSSL_STRING_num(certflst); i++) { certfile = sk_OPENSSL_STRING_value(certflst, i); if (add_certs_from_file(cert_stack, certfile) < 0) { - BIO_puts(bio_err, "error loading certificates\n"); + BIO_printf(bio_err, "error loading certificates\n"); ERR_print_errors(bio_err); goto end; } @@ -172,7 +172,7 @@ int crl2pkcs7_main(int argc, char **argv) else if (outformat == FORMAT_PEM) i = PEM_write_bio_PKCS7(out, p7); if (!i) { - BIO_puts(bio_err, "unable to write pkcs7 object\n"); + BIO_printf(bio_err, "unable to write pkcs7 object\n"); ERR_print_errors(bio_err); goto end; } diff --git a/apps/dgst.c b/apps/dgst.c index 9185307cda..8bc8e4c2c5 100644 --- a/apps/dgst.c +++ b/apps/dgst.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -7,10 +7,10 @@ * https://www.openssl.org/source/license.html */ -#include "apps.h" #include #include #include +#include "apps.h" #include "progs.h" #include #include @@ -20,7 +20,6 @@ #include #include #include -#include #undef BUFSIZE #define BUFSIZE 1024 * 8 @@ -134,7 +133,7 @@ int dgst_main(int argc, char **argv) int oneshot_sign = 0; buf = app_malloc(BUFSIZE, "I/O buffer"); - md = EVP_MD_fetch(app_get0_libctx(), argv[0], app_get0_propq()); + md = (EVP_MD *)EVP_get_digestbyname(argv[0]); if (md != NULL) digestname = argv[0]; @@ -152,12 +151,12 @@ int dgst_main(int argc, char **argv) ret = EXIT_SUCCESS; goto end; case OPT_LIST: - BIO_puts(bio_out, "Supported digests:\n"); + BIO_printf(bio_out, "Supported digests:\n"); dec.bio = bio_out; dec.n = 0; OBJ_NAME_do_all_sorted(OBJ_NAME_TYPE_MD_METH, show_digests, &dec); - BIO_puts(bio_out, "\n"); + BIO_printf(bio_out, "\n"); ret = EXIT_SUCCESS; goto end; case OPT_C: @@ -201,7 +200,7 @@ int dgst_main(int argc, char **argv) out_bin = 1; break; case OPT_XOFLEN: - xoflen = opt_int_arg(); + xoflen = atoi(opt_arg()); break; case OPT_DEBUG: debug = 1; @@ -283,7 +282,7 @@ int dgst_main(int argc, char **argv) } if (do_verify && sigfile == NULL) { - BIO_puts(bio_err, + BIO_printf(bio_err, "No signature to verify: use the -signature option\n"); goto end; } @@ -300,7 +299,7 @@ int dgst_main(int argc, char **argv) } if (!app_passwd(passinarg, NULL, &passin, NULL)) { - BIO_puts(bio_err, "Error getting password\n"); + BIO_printf(bio_err, "Error getting password\n"); goto end; } @@ -316,7 +315,7 @@ int dgst_main(int argc, char **argv) goto end; if ((!(mac_name == NULL) + !(keyfile == NULL) + !(hmac_key == NULL)) > 1) { - BIO_puts(bio_err, "MAC and signing key cannot both be specified\n"); + BIO_printf(bio_err, "MAC and signing key cannot both be specified\n"); goto end; } @@ -388,7 +387,7 @@ int dgst_main(int argc, char **argv) if (oneshot_sign) { mctx = signctx; } else if (BIO_get_md_ctx(bmd, &mctx) <= 0) { - BIO_puts(bio_err, "Error getting context\n"); + BIO_printf(bio_err, "Error getting context\n"); goto end; } if (do_verify) @@ -400,7 +399,7 @@ int dgst_main(int argc, char **argv) app_get0_libctx(), app_get0_propq(), sigkey, NULL); if (res == 0) { - BIO_puts(bio_err, "Error setting context\n"); + BIO_printf(bio_err, "Error setting context\n"); goto end; } if (sigopts != NULL) { @@ -420,17 +419,17 @@ int dgst_main(int argc, char **argv) EVP_MD_CTX *mctx = NULL; if (oneshot_sign) { - BIO_puts(bio_err, "Oneshot algorithms don't use a digest\n"); + BIO_printf(bio_err, "Oneshot algorithms don't use a digest\n"); goto end; } if (BIO_get_md_ctx(bmd, &mctx) <= 0) { - BIO_puts(bio_err, "Error getting context\n"); + BIO_printf(bio_err, "Error getting context\n"); goto end; } if (md == NULL) md = (EVP_MD *)EVP_sha256(); if (!EVP_DigestInit_ex(mctx, md, NULL)) { - BIO_puts(bio_err, "Error setting digest\n"); + BIO_printf(bio_err, "Error setting digest\n"); goto end; } } @@ -465,7 +464,7 @@ int dgst_main(int argc, char **argv) } if (xoflen > 0) { if (!EVP_MD_xof(md)) { - BIO_puts(bio_err, "Length can only be specified for XOF\n"); + BIO_printf(bio_err, "Length can only be specified for XOF\n"); goto end; } /* @@ -474,7 +473,7 @@ int dgst_main(int argc, char **argv) * and verify_final methods. */ if (sigkey != NULL) { - BIO_puts(bio_err, "Signing key cannot be specified for XOF\n"); + BIO_printf(bio_err, "Signing key cannot be specified for XOF\n"); goto end; } } @@ -483,14 +482,10 @@ int dgst_main(int argc, char **argv) BIO_set_fp(in, stdin, BIO_NOCLOSE); if (oneshot_sign) ret = do_fp_oneshot_sign(out, signctx, in, separator, out_bin, - sigkey, sigbuf, siglen, NULL, NULL) - ? EXIT_SUCCESS - : EXIT_FAILURE; + sigkey, sigbuf, siglen, NULL, "stdin"); else ret = do_fp(out, buf, inp, separator, out_bin, xoflen, - sigkey, sigbuf, siglen, NULL, md_name, "stdin") - ? EXIT_SUCCESS - : EXIT_FAILURE; + sigkey, sigbuf, siglen, NULL, md_name, "stdin"); } else { const char *sig_name = NULL; @@ -506,12 +501,12 @@ int dgst_main(int argc, char **argv) continue; } else { if (oneshot_sign) { - if (!do_fp_oneshot_sign(out, signctx, in, separator, out_bin, + if (do_fp_oneshot_sign(out, signctx, in, separator, out_bin, sigkey, sigbuf, siglen, sig_name, argv[i])) ret = EXIT_FAILURE; } else { - if (!do_fp(out, buf, inp, separator, out_bin, xoflen, + if (do_fp(out, buf, inp, separator, out_bin, xoflen, sigkey, sigbuf, siglen, sig_name, md_name, argv[i])) ret = EXIT_FAILURE; } @@ -552,15 +547,17 @@ static void show_digests(const OBJ_NAME *name, void *arg) /* Filter out message digests that we cannot use */ md = EVP_MD_fetch(app_get0_libctx(), name->name, app_get0_propq()); - if (md == NULL) - return; + if (md == NULL) { + if (EVP_get_digestbyname(name->name) == NULL) + return; + } BIO_printf(dec->bio, "-%-25s", name->name); if (++dec->n == 3) { - BIO_puts(dec->bio, "\n"); + BIO_printf(dec->bio, "\n"); dec->n = 0; } else { - BIO_puts(dec->bio, " "); + BIO_printf(dec->bio, " "); } EVP_MD_free(md); @@ -636,34 +633,30 @@ static void print_out(BIO *out, unsigned char *buf, size_t len, } for (i = 0; i < (int)len; i++) { if (sep && (i != 0)) - BIO_puts(out, ":"); + BIO_printf(out, ":"); BIO_printf(out, "%02x", buf[i]); } - BIO_puts(out, "\n"); + BIO_printf(out, "\n"); } } static void print_verify_result(BIO *out, int i) { if (i > 0) - BIO_puts(out, "Verified OK\n"); + BIO_printf(out, "Verified OK\n"); else if (i == 0) - BIO_puts(out, "Verification failure\n"); + BIO_printf(out, "Verification failure\n"); else - BIO_puts(bio_err, "Error verifying data\n"); + BIO_printf(bio_err, "Error verifying data\n"); } -/* - * Returns 1 on success, 0 on failure. Do not use EXIT_SUCCESS / EXIT_FAILURE - * here; reserve those for main() and exit(3) (issue #30562). - */ int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout, int xoflen, EVP_PKEY *key, unsigned char *sigin, int siglen, const char *sig_name, const char *md_name, const char *file) { size_t len = BUFSIZE; - int i, ret = 0; + int i, ret = EXIT_FAILURE; unsigned char *allocated_buf = NULL; while (BIO_pending(bp) || !BIO_eof(bp)) { @@ -681,7 +674,7 @@ int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout, int xoflen i = EVP_DigestVerifyFinal(ctx, sigin, (unsigned int)siglen); print_verify_result(out, i); if (i > 0) - ret = 1; + ret = EXIT_SUCCESS; goto end; } if (key != NULL) { @@ -690,7 +683,7 @@ int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout, int xoflen BIO_get_md_ctx(bp, &ctx); if (!EVP_DigestSignFinal(ctx, NULL, &tmplen)) { - BIO_puts(bio_err, "Error getting maximum length of signed data\n"); + BIO_printf(bio_err, "Error getting maximum length of signed data\n"); goto end; } if (tmplen > BUFSIZE) { @@ -699,7 +692,7 @@ int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout, int xoflen buf = allocated_buf; } if (!EVP_DigestSignFinal(ctx, buf, &len)) { - BIO_puts(bio_err, "Error signing data\n"); + BIO_printf(bio_err, "Error signing data\n"); goto end; } } else if (xoflen > 0) { @@ -714,7 +707,7 @@ int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout, int xoflen BIO_get_md_ctx(bp, &ctx); if (!EVP_DigestFinalXOF(ctx, buf, len)) { - BIO_puts(bio_err, "Error Digesting Data\n"); + BIO_printf(bio_err, "Error Digesting Data\n"); goto end; } } else { @@ -723,7 +716,7 @@ int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout, int xoflen goto end; } print_out(out, buf, len, sep, binout, sig_name, md_name, file); - ret = 1; + ret = EXIT_SUCCESS; end: if (allocated_buf != NULL) OPENSSL_clear_free(allocated_buf, len); @@ -731,87 +724,54 @@ end: return ret; } -/* - * Perform one-shot verify or sign on a contiguous data buffer. - * Returns 0 on failure, 1 on success. - */ -static int do_oneshot_verify_sign(EVP_MD_CTX *ctx, BIO *out, - unsigned char *sigin, int siglen, EVP_PKEY *key, - const unsigned char *data, size_t len, - int sep, int binout, const char *sig_name, const char *file) -{ - int res; - size_t siglen_out = 0; - unsigned char *sig = NULL; - - if (sigin != NULL) { - res = EVP_DigestVerify(ctx, sigin, siglen, data, len); - print_verify_result(out, res); - return res > 0; - } - if (key != NULL) { - if (EVP_DigestSign(ctx, NULL, &siglen_out, data, len) != 1) { - BIO_puts(bio_err, "Error getting maximum length of signed data\n"); - return 0; - } - sig = app_malloc(siglen_out, "Signature buffer"); - if (EVP_DigestSign(ctx, sig, &siglen_out, data, len) != 1) { - BIO_puts(bio_err, "Error signing data\n"); - OPENSSL_free(sig); - return 0; - } - print_out(out, sig, siglen_out, sep, binout, sig_name, NULL, file); - OPENSSL_free(sig); - return 1; - } - BIO_puts(bio_err, "key must be set for one-shot algorithms\n"); - return 0; -} - /* * Some new algorithms only support one shot operations. * For these we need to buffer all input and then do the sign on the * total buffered input. These algorithms set a NULL digest name which is * then used inside EVP_DigestVerify() and EVP_DigestSign(). - * Returns 1 on success, 0 on failure. Do not use EXIT_SUCCESS / EXIT_FAILURE - * here; reserve those for main() and exit(3) (issue #30562). */ static int do_fp_oneshot_sign(BIO *out, EVP_MD_CTX *ctx, BIO *in, int sep, int binout, EVP_PKEY *key, unsigned char *sigin, int siglen, const char *sig_name, const char *file) { - int ret = 0; - size_t buflen = 0; - size_t maxlen = 16 * 1024 * 1024; - uint8_t *buf = NULL; + int res, ret = EXIT_FAILURE; + size_t len = 0; + int buflen = 0; + int maxlen = 16 * 1024 * 1024; + uint8_t *buf = NULL, *sig = NULL; -#if defined(OPENSSL_SYS_UNIX) && defined(_POSIX_MAPPED_FILES) && _POSIX_MAPPED_FILES > 0 - if (file != NULL) { - const unsigned char *data = NULL; - size_t filesize = 0; - int r = app_mmap_file(file, bio_err, (size_t)-1, &data, &filesize); - - if (r == 1) { - ret = do_oneshot_verify_sign(ctx, out, sigin, siglen, key, data, - filesize, sep, binout, sig_name, file); - munmap((void *)data, filesize); - return ret; + buflen = bio_to_mem(&buf, maxlen, in); + if (buflen <= 0) { + BIO_printf(bio_err, "Read error in %s\n", file); + return ret; + } + if (sigin != NULL) { + res = EVP_DigestVerify(ctx, sigin, siglen, buf, buflen); + print_verify_result(out, res); + if (res > 0) + ret = EXIT_SUCCESS; + goto end; + } + if (key != NULL) { + if (EVP_DigestSign(ctx, NULL, &len, buf, buflen) != 1) { + BIO_printf(bio_err, "Error getting maximum length of signed data\n"); + goto end; } - if (r == -1) - return 0; /* error already printed */ - /* r == 0: empty file, fall through to buffer path */ + sig = app_malloc(len, "Signature buffer"); + if (EVP_DigestSign(ctx, sig, &len, buf, buflen) != 1) { + BIO_printf(bio_err, "Error signing data\n"); + goto end; + } + print_out(out, sig, len, sep, binout, sig_name, NULL, file); + ret = EXIT_SUCCESS; + } else { + BIO_printf(bio_err, "key must be set for one-shot algorithms\n"); + goto end; } -#endif - { - const char *display_file = file != NULL ? file : "stdin"; - - if (!bio_to_mem(&buf, &buflen, maxlen, in)) - return 0; - ret = do_oneshot_verify_sign(ctx, out, sigin, siglen, key, buf, buflen, - sep, binout, sig_name, display_file); - OPENSSL_clear_free(buf, buflen); - } +end: + OPENSSL_free(sig); + OPENSSL_clear_free(buf, buflen); return ret; } diff --git a/apps/dhparam.c b/apps/dhparam.c index 3c78ac377b..dc6648aa92 100644 --- a/apps/dhparam.c +++ b/apps/dhparam.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -178,7 +178,7 @@ int dhparam_main(int argc, char **argv) num = DEFBITS; if (dsaparam && g) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Error, generator may not be chosen for DSA parameters\n"); goto end; } @@ -218,16 +218,16 @@ int dhparam_main(int argc, char **argv) if (dsaparam) { if (EVP_PKEY_CTX_set_dsa_paramgen_bits(ctx, num) <= 0) { - BIO_puts(bio_err, "Error, unable to set DSA prime length\n"); + BIO_printf(bio_err, "Error, unable to set DSA prime length\n"); goto end; } } else { if (EVP_PKEY_CTX_set_dh_paramgen_prime_len(ctx, num) <= 0) { - BIO_puts(bio_err, "Error, unable to set DH prime length\n"); + BIO_printf(bio_err, "Error, unable to set DH prime length\n"); goto end; } if (EVP_PKEY_CTX_set_dh_paramgen_generator(ctx, g) <= 0) { - BIO_puts(bio_err, "Error, unable to set generator\n"); + BIO_printf(bio_err, "Error, unable to set generator\n"); goto end; } } @@ -301,13 +301,13 @@ int dhparam_main(int argc, char **argv) OSSL_DECODER_CTX_free(decoderctx); } while (!done); if (tmppkey == NULL) { - BIO_puts(bio_err, "Error, unable to load parameters\n"); + BIO_printf(bio_err, "Error, unable to load parameters\n"); goto end; } if (dsaparam) { if (!EVP_PKEY_is_a(tmppkey, "DSA")) { - BIO_puts(bio_err, "Error, unable to load DSA parameters\n"); + BIO_printf(bio_err, "Error, unable to load DSA parameters\n"); goto end; } pkey = dsa_to_dh(tmppkey); @@ -316,7 +316,7 @@ int dhparam_main(int argc, char **argv) } else { if (!EVP_PKEY_is_a(tmppkey, "DH") && !EVP_PKEY_is_a(tmppkey, "DHX")) { - BIO_puts(bio_err, "Error, unable to load DH parameters\n"); + BIO_printf(bio_err, "Error, unable to load DH parameters\n"); goto end; } pkey = tmppkey; @@ -334,14 +334,14 @@ int dhparam_main(int argc, char **argv) if (check) { ctx = EVP_PKEY_CTX_new_from_pkey(app_get0_libctx(), pkey, app_get0_propq()); if (ctx == NULL) { - BIO_puts(bio_err, "Error, failed to check DH parameters\n"); + BIO_printf(bio_err, "Error, failed to check DH parameters\n"); goto end; } if (EVP_PKEY_param_check(ctx) <= 0) { - BIO_puts(bio_err, "Error, invalid parameters generated\n"); + BIO_printf(bio_err, "Error, invalid parameters generated\n"); goto end; } - BIO_puts(bio_err, "DH parameters appear to be ok.\n"); + BIO_printf(bio_err, "DH parameters appear to be ok.\n"); } if (!noout) { @@ -354,7 +354,7 @@ int dhparam_main(int argc, char **argv) if (ectx == NULL || !OSSL_ENCODER_to_bio(ectx, out)) { OSSL_ENCODER_CTX_free(ectx); - BIO_puts(bio_err, "Error, unable to write DH parameters\n"); + BIO_printf(bio_err, "Error, unable to write DH parameters\n"); goto end; } OSSL_ENCODER_CTX_free(ectx); @@ -387,7 +387,7 @@ static EVP_PKEY *dsa_to_dh(EVP_PKEY *dh) if (!EVP_PKEY_get_bn_param(dh, OSSL_PKEY_PARAM_FFC_P, &bn_p) || !EVP_PKEY_get_bn_param(dh, OSSL_PKEY_PARAM_FFC_Q, &bn_q) || !EVP_PKEY_get_bn_param(dh, OSSL_PKEY_PARAM_FFC_G, &bn_g)) { - BIO_puts(bio_err, "Error, failed to set DH parameters\n"); + BIO_printf(bio_err, "Error, failed to set DH parameters\n"); goto err; } @@ -399,7 +399,7 @@ static EVP_PKEY *dsa_to_dh(EVP_PKEY *dh) || !OSSL_PARAM_BLD_push_BN(tmpl, OSSL_PKEY_PARAM_FFC_G, bn_g) || (params = OSSL_PARAM_BLD_to_param(tmpl)) == NULL) { - BIO_puts(bio_err, "Error, failed to set DH parameters\n"); + BIO_printf(bio_err, "Error, failed to set DH parameters\n"); goto err; } @@ -407,7 +407,7 @@ static EVP_PKEY *dsa_to_dh(EVP_PKEY *dh) if (ctx == NULL || EVP_PKEY_fromdata_init(ctx) <= 0 || EVP_PKEY_fromdata(ctx, &pkey, EVP_PKEY_KEY_PARAMETERS, params) <= 0) { - BIO_puts(bio_err, "Error, failed to set DH parameters\n"); + BIO_printf(bio_err, "Error, failed to set DH parameters\n"); goto err; } diff --git a/apps/dsa.c b/apps/dsa.c index 95a1b432cc..ac7172f41d 100644 --- a/apps/dsa.c +++ b/apps/dsa.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -174,23 +174,23 @@ int dsa_main(int argc, char **argv) private = !pubin && (!pubout || text); if (!app_passwd(passinarg, passoutarg, &passin, &passout)) { - BIO_puts(bio_err, "Error getting passwords\n"); + BIO_printf(bio_err, "Error getting passwords\n"); goto end; } - BIO_puts(bio_err, "read DSA key\n"); + BIO_printf(bio_err, "read DSA key\n"); if (pubin) pkey = load_pubkey(infile, informat, 1, passin, "public key"); else pkey = load_key(infile, informat, 1, passin, "private key"); if (pkey == NULL) { - BIO_puts(bio_err, "unable to load Key\n"); + BIO_printf(bio_err, "unable to load Key\n"); ERR_print_errors(bio_err); goto end; } if (!EVP_PKEY_is_a(pkey, "DSA")) { - BIO_puts(bio_err, "Not a DSA key\n"); + BIO_printf(bio_err, "Not a DSA key\n"); goto end; } @@ -215,9 +215,9 @@ int dsa_main(int argc, char **argv) ERR_print_errors(bio_err); goto end; } - BIO_puts(out, "Public Key="); + BIO_printf(out, "Public Key="); BN_print(out, pub_key); - BIO_puts(out, "\n"); + BIO_printf(out, "\n"); BN_free(pub_key); } @@ -225,7 +225,7 @@ int dsa_main(int argc, char **argv) ret = 0; goto end; } - BIO_puts(bio_err, "writing DSA key\n"); + BIO_printf(bio_err, "writing DSA key\n"); if (outformat == FORMAT_ASN1) { output_type = "DER"; } else if (outformat == FORMAT_PEM) { @@ -234,12 +234,12 @@ int dsa_main(int argc, char **argv) output_type = "MSBLOB"; } else if (outformat == FORMAT_PVK) { if (pubin) { - BIO_puts(bio_err, "PVK form impossible with public key input\n"); + BIO_printf(bio_err, "PVK form impossible with public key input\n"); goto end; } output_type = "PVK"; } else { - BIO_puts(bio_err, "bad output format specified for outfile\n"); + BIO_printf(bio_err, "bad output format specified for outfile\n"); goto end; } @@ -287,13 +287,13 @@ int dsa_main(int argc, char **argv) params[0] = OSSL_PARAM_construct_int("encrypt-level", &pvk_encr); if (!OSSL_ENCODER_CTX_set_params(ectx, params)) { - BIO_puts(bio_err, "invalid PVK encryption level\n"); + BIO_printf(bio_err, "invalid PVK encryption level\n"); goto end; } } if (!OSSL_ENCODER_to_bio(ectx, out)) { - BIO_puts(bio_err, "unable to write key\n"); + BIO_printf(bio_err, "unable to write key\n"); goto end; } ret = 0; diff --git a/apps/dsaparam.c b/apps/dsaparam.c index 8b07e5efea..cec9b7af4d 100644 --- a/apps/dsaparam.c +++ b/apps/dsaparam.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -153,7 +153,7 @@ int dsaparam_main(int argc, char **argv) ctx = EVP_PKEY_CTX_new_from_name(app_get0_libctx(), "DSA", app_get0_propq()); if (ctx == NULL) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Error, DSA parameter generation context allocation failed\n"); goto end; } @@ -167,23 +167,23 @@ int dsaparam_main(int argc, char **argv) EVP_PKEY_CTX_set_app_data(ctx, bio_err); if (verbose) { EVP_PKEY_CTX_set_cb(ctx, progress_cb); - BIO_printf(bio_err, "Generating DSA parameters, %d bit long prime\n" - "This could take some time\n", + BIO_printf(bio_err, "Generating DSA parameters, %d bit long prime\n", num); + BIO_printf(bio_err, "This could take some time\n"); } if (EVP_PKEY_paramgen_init(ctx) <= 0) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Error, DSA key generation paramgen init failed\n"); goto end; } if (EVP_PKEY_CTX_set_dsa_paramgen_bits(ctx, num) <= 0) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Error, DSA key generation setting bit length failed\n"); goto end; } if (numqbits > 0) { if (EVP_PKEY_CTX_set_dsa_paramgen_q_bits(ctx, numqbits) <= 0) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Error, DSA key generation setting subprime bit length failed\n"); goto end; } @@ -214,7 +214,7 @@ int dsaparam_main(int argc, char **argv) else i = PEM_write_bio_Parameters(out, params); if (!i) { - BIO_puts(bio_err, "Error, unable to write DSA parameters\n"); + BIO_printf(bio_err, "Error, unable to write DSA parameters\n"); goto end; } } @@ -228,7 +228,7 @@ int dsaparam_main(int argc, char **argv) goto end; } if (EVP_PKEY_keygen_init(ctx) <= 0) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Error, unable to initialise for key generation\n"); goto end; } diff --git a/apps/ec.c b/apps/ec.c index 8ed452a153..a5abc34ac3 100644 --- a/apps/ec.c +++ b/apps/ec.c @@ -1,5 +1,5 @@ /* - * Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2002-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -54,7 +54,7 @@ const OPTIONS ec_options[] = { { "check", OPT_CHECK, '-', "check key consistency" }, { "", OPT_CIPHER, '-', "Any supported cipher" }, { "param_enc", OPT_PARAM_ENC, 's', - "Selects between named_curve and explicit EC parameter encoding" }, + "Specifies the way the ec parameters are encoded" }, { "conv_form", OPT_CONV_FORM, 's', "Specifies the point conversion form " }, OPT_SECTION("Output"), @@ -172,7 +172,7 @@ int ec_main(int argc, char **argv) private = !pubin && (text || (!param_out && !pubout)); if (!app_passwd(passinarg, passoutarg, &passin, &passout)) { - BIO_puts(bio_err, "Error getting passwords\n"); + BIO_printf(bio_err, "Error getting passwords\n"); goto end; } @@ -182,7 +182,7 @@ int ec_main(int argc, char **argv) eckey = load_key(infile, informat, 1, passin, "private key"); if (eckey == NULL) { - BIO_puts(bio_err, "unable to load Key\n"); + BIO_printf(bio_err, "unable to load Key\n"); goto end; } @@ -194,25 +194,25 @@ int ec_main(int argc, char **argv) && !EVP_PKEY_set_utf8_string_param( eckey, OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT, point_format)) { - BIO_puts(bio_err, "unable to set point conversion format\n"); + BIO_printf(bio_err, "unable to set point conversion format\n"); goto end; } if (asn1_encoding != NULL && !EVP_PKEY_set_utf8_string_param( eckey, OSSL_PKEY_PARAM_EC_ENCODING, asn1_encoding)) { - BIO_puts(bio_err, "unable to set asn1 encoding format\n"); + BIO_printf(bio_err, "unable to set asn1 encoding format\n"); goto end; } if (no_public) { if (!EVP_PKEY_set_int_param(eckey, OSSL_PKEY_PARAM_EC_INCLUDE_PUBLIC, 0)) { - BIO_puts(bio_err, "unable to disable public key encoding\n"); + BIO_printf(bio_err, "unable to disable public key encoding\n"); goto end; } } else { if (!EVP_PKEY_set_int_param(eckey, OSSL_PKEY_PARAM_EC_INCLUDE_PUBLIC, 1)) { - BIO_puts(bio_err, "unable to enable public key encoding\n"); + BIO_printf(bio_err, "unable to enable public key encoding\n"); goto end; } } @@ -221,7 +221,7 @@ int ec_main(int argc, char **argv) assert(pubin || private); if ((pubin && EVP_PKEY_print_public(out, eckey, 0, NULL) <= 0) || (!pubin && EVP_PKEY_print_private(out, eckey, 0, NULL) <= 0)) { - BIO_puts(bio_err, "unable to print EC key\n"); + BIO_printf(bio_err, "unable to print EC key\n"); goto end; } } @@ -229,13 +229,13 @@ int ec_main(int argc, char **argv) if (check) { pctx = EVP_PKEY_CTX_new_from_pkey(NULL, eckey, NULL); if (pctx == NULL) { - BIO_puts(bio_err, "unable to check EC key\n"); + BIO_printf(bio_err, "unable to check EC key\n"); goto end; } if (EVP_PKEY_check(pctx) <= 0) - BIO_puts(bio_err, "EC Key Invalid!\n"); + BIO_printf(bio_err, "EC Key Invalid!\n"); else - BIO_puts(bio_err, "EC Key valid.\n"); + BIO_printf(bio_err, "EC Key valid.\n"); ERR_print_errors(bio_err); } @@ -269,7 +269,7 @@ int ec_main(int argc, char **argv) strlen(passout)); } if (!OSSL_ENCODER_to_bio(ectx, out)) { - BIO_puts(bio_err, "unable to write EC key\n"); + BIO_printf(bio_err, "unable to write EC key\n"); goto end; } } diff --git a/apps/ech.c b/apps/ech.c deleted file mode 100644 index fd037a3817..0000000000 --- a/apps/ech.c +++ /dev/null @@ -1,283 +0,0 @@ -/* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include -#include -#include "apps.h" -#include "progs.h" -#include -#include -#include -#include -#include -#include -#include -#include - -#include -#include - -#ifndef OPENSSL_NO_ECH - -#define OSSL_ECH_KEYGEN_MODE 0 /* default: generate a key pair/ECHConfig */ -#define OSSL_ECH_SELPRINT_MODE 1 /* we can print/down-select ECHConfigList */ -#define OSSL_ECH_MAXINFILES 5 /* we'll only take this many inputs */ - -typedef enum OPTION_choice { - /* standard openssl options */ - OPT_ERR = -1, - OPT_EOF = 0, - OPT_HELP, - OPT_VERBOSE, - OPT_TEXT, - OPT_OUT, - OPT_IN, - /* ECHConfig specifics */ - OPT_PUBLICNAME, - OPT_ECHVERSION, - OPT_MAXNAMELENGTH, - OPT_HPKESUITE, - OPT_SELECT -} OPTION_CHOICE; - -const OPTIONS ech_options[] = { - OPT_SECTION("General options"), - { "help", OPT_HELP, '-', "Display this summary" }, - { "verbose", OPT_VERBOSE, '-', "Provide additional output" }, - { "text", OPT_TEXT, '-', "Provide human-readable output" }, - OPT_SECTION("Key generation"), - { "out", OPT_OUT, '>', - "Private key and/or ECHConfig [default: echconfig.pem]" }, - { "public_name", OPT_PUBLICNAME, 's', "public_name value" }, - { "max_name_len", OPT_MAXNAMELENGTH, 'n', - "Maximum host name length value [default: 0]" }, - { "suite", OPT_HPKESUITE, 's', "HPKE ciphersuite: e.g. \"0x20,1,3\"" }, - { "ech_version", OPT_ECHVERSION, 'n', - "ECHConfig version [default: 0xff0d (13)]" }, - OPT_SECTION("ECH PEM file downselect/display"), - { "in", OPT_IN, '<', "An ECH PEM file" }, - { "select", OPT_SELECT, 'n', "Downselect to the numbered ECH config" }, - { NULL } -}; - -/** - * @brief map version string like 0xff01 or 65291 to uint16_t - * @param arg is the version string, from command line - * @return is the uint16_t value (with zero for error cases) - */ -static uint16_t verstr2us(char *arg) -{ - long lv = strtol(arg, NULL, 0); - uint16_t rv = 0; - - if (lv < 0xffff && lv > 0) - rv = (uint16_t)lv; - return rv; -} - -int ech_main(int argc, char **argv) -{ - char *prog = NULL; - OPTION_CHOICE o; - int i, rv = 1, verbose = 0, text = 0, outsupp = 0; - int select = OSSL_ECHSTORE_ALL, numinfiles = 0; - char *outfile = NULL, *infile = NULL; - char *infiles[OSSL_ECH_MAXINFILES] = { NULL }; - char *public_name = NULL, *suitestr = NULL; - uint16_t ech_version = OSSL_ECH_CURRENT_VERSION; - uint8_t max_name_length = 0; - OSSL_HPKE_SUITE hpke_suite = OSSL_HPKE_SUITE_DEFAULT; - int mode = OSSL_ECH_KEYGEN_MODE; /* key generation */ - OSSL_ECHSTORE *es = NULL; - BIO *ecf = NULL; - - prog = opt_init(argc, argv, ech_options); - while ((o = opt_next()) != OPT_EOF) { - switch (o) { - case OPT_EOF: - case OPT_ERR: - BIO_printf(bio_err, "%s: Use -help for summary.\n", prog); - goto end; - case OPT_HELP: - opt_help(ech_options); - rv = 0; - goto end; - case OPT_VERBOSE: - verbose = 1; - break; - case OPT_TEXT: - text = 1; - break; - case OPT_SELECT: - mode = OSSL_ECH_SELPRINT_MODE; - select = strtol(opt_arg(), NULL, 10); - break; - case OPT_OUT: - outfile = opt_arg(); - outsupp = 1; - break; - case OPT_IN: - mode = OSSL_ECH_SELPRINT_MODE; - infile = opt_arg(); - if (numinfiles >= OSSL_ECH_MAXINFILES) { - BIO_printf(bio_err, "too many input files, only %d allowed\n", - OSSL_ECH_MAXINFILES); - goto opthelp; - } - infiles[numinfiles] = infile; - numinfiles++; - break; - case OPT_PUBLICNAME: - public_name = opt_arg(); - break; - case OPT_ECHVERSION: - ech_version = verstr2us(opt_arg()); - break; - case OPT_MAXNAMELENGTH: { - long tmp = strtol(opt_arg(), NULL, 10); - - if (tmp < 0 || tmp > OSSL_ECH_MAX_MAXNAMELEN) { - BIO_printf(bio_err, - "max name length out of range [0,%d] (%ld)\n", - OSSL_ECH_MAX_MAXNAMELEN, tmp); - goto opthelp; - } else { - max_name_length = (uint8_t)tmp; - } - } break; - case OPT_HPKESUITE: - suitestr = opt_arg(); - break; - } - } - argc = opt_num_rest(); - argv = opt_rest(); - if (argc != 0) { - BIO_printf(bio_err, "%s: Unknown parameter %s\n", prog, argv[0]); - goto opthelp; - } - /* Check ECH-specific inputs */ - switch (ech_version) { - case OSSL_ECH_RFC9849_VERSION: /* fall through */ - case 13: - ech_version = OSSL_ECH_RFC9849_VERSION; - break; - default: - BIO_printf(bio_err, "Un-supported version (0x%04x)\n", ech_version); - goto end; - } - if (suitestr != NULL) { - if (OSSL_HPKE_str2suite(suitestr, &hpke_suite) != 1) { - BIO_printf(bio_err, "Bad OSSL_HPKE_SUITE (%s)\n", suitestr); - ERR_print_errors(bio_err); - goto end; - } - } - /* Set default if needed */ - if (outfile == NULL) - outfile = "echconfig.pem"; - es = OSSL_ECHSTORE_new(NULL, NULL); - if (es == NULL) - goto end; - if (mode == OSSL_ECH_KEYGEN_MODE) { - if (public_name == NULL) { - BIO_printf(bio_err, "public_name required\n"); - goto end; - } - if (verbose) - BIO_printf(bio_err, "Calling OSSL_ECHSTORE_new_config\n"); - if ((ecf = bio_open_owner(outfile, FORMAT_PEM, 1)) == NULL - || OSSL_ECHSTORE_new_config(es, ech_version, max_name_length, - public_name, hpke_suite) - != 1 - || OSSL_ECHSTORE_write_pem(es, 0, ecf) != 1) { - BIO_printf(bio_err, "OSSL_ECHSTORE_new_config error\n"); - goto end; - } - if (verbose) - BIO_printf(bio_err, "OSSL_ECHSTORE_new_config success\n"); - rv = 0; - } - if (mode == OSSL_ECH_SELPRINT_MODE) { - if (numinfiles == 0) - goto opthelp; - for (i = 0; i != numinfiles; i++) { - if ((ecf = BIO_new_file(infiles[i], "r")) == NULL - || OSSL_ECHSTORE_read_pem(es, ecf, OSSL_ECH_FOR_RETRY) != 1) { - BIO_printf(bio_err, "OSSL_ECHSTORE_read_pem error: %s\n", - infiles[i]); - goto end; - } - BIO_free(ecf); - ecf = NULL; - } - if (verbose) - BIO_printf(bio_err, "Success reading %d files\n", numinfiles); - if (outsupp == 1) { - /* write result to that, with downselection if required */ - if (verbose) - BIO_printf(bio_err, "Will write to %s\n", outfile); - if (verbose && select != OSSL_ECHSTORE_ALL) - BIO_printf(bio_err, "Selected entry: %d\n", select); - if ((ecf = BIO_new_file(outfile, "w")) == NULL - || OSSL_ECHSTORE_write_pem(es, select, ecf) != 1) { - BIO_printf(bio_err, "OSSL_ECHSTORE_write_pem error: %s\n", - outfile); - goto end; - } - if (verbose) - BIO_printf(bio_err, "Success writing to %s\n", outfile); - } - rv = 0; - } - if (text) { - int oi_ind, oi_cnt = 0; - - if (OSSL_ECHSTORE_num_entries(es, &oi_cnt) != 1) - goto end; - if (verbose) - BIO_printf(bio_err, "Printing %d ECHConfig values\n", oi_cnt); - for (oi_ind = 0; oi_ind != oi_cnt; oi_ind++) { - time_t secs = 0; - char *pn = NULL, *ec = NULL; - int has_priv, for_retry; - - if (OSSL_ECHSTORE_get1_info(es, oi_ind, &secs, &pn, &ec, - &has_priv, &for_retry) - != 1) { - OPENSSL_free(pn); /* just in case */ - OPENSSL_free(ec); - goto end; - } - BIO_printf(bio_err, "ECH entry: %d public_name: %s age: %lld%s%s\n", - oi_ind, pn, (long long)secs, - has_priv ? " (has private key)" : "", - for_retry ? " (will be sent in retry-configs)" : ""); - BIO_printf(bio_err, "\t%s\n", ec); - OPENSSL_free(pn); - OPENSSL_free(ec); - } - if (verbose) - BIO_printf(bio_err, "Success printing %d ECHConfigList\n", oi_cnt); - rv = 0; - } -end: - OSSL_ECHSTORE_free(es); - BIO_free_all(ecf); - return rv; -opthelp: - BIO_printf(bio_err, "%s: Use -help for summary.\n", prog); - BIO_printf(bio_err, "\tup to %d -in instances allowed\n", OSSL_ECH_MAXINFILES); - OSSL_ECHSTORE_free(es); - BIO_free_all(ecf); - return rv; -} - -#endif diff --git a/apps/ecparam.c b/apps/ecparam.c index aece2cb81d..27f8039e3b 100644 --- a/apps/ecparam.c +++ b/apps/ecparam.c @@ -1,5 +1,5 @@ /* - * Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2002-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -57,7 +57,7 @@ const OPTIONS ecparam_options[] = { { "text", OPT_TEXT, '-', "Print the ec parameters in text form" }, { "noout", OPT_NOOUT, '-', "Do not print the ec parameter" }, { "param_enc", OPT_PARAM_ENC, 's', - "Selects between named_curve and explicit EC parameter encoding" }, + "Specifies the way the ec parameters are encoded" }, OPT_SECTION("Parameter"), { "check", OPT_CHECK, '-', "Validate the ec parameters" }, @@ -91,7 +91,8 @@ static int list_builtin_curves(BIO *out) if (sname == NULL) sname = ""; - BIO_printf(out, " %-10s: %s\n", sname, comment); + BIO_printf(out, " %-10s: ", sname); + BIO_printf(out, "%s\n", comment); } OPENSSL_free(curves); return 1; @@ -209,11 +210,11 @@ int ecparam_main(int argc, char **argv) OSSL_PARAM *p = params; if (strcmp(curve_name, "secp192r1") == 0) { - BIO_puts(bio_err, + BIO_printf(bio_err, "using curve name prime192v1 instead of secp192r1\n"); curve_name = SN_X9_62_prime192v1; } else if (strcmp(curve_name, "secp256r1") == 0) { - BIO_puts(bio_err, + BIO_printf(bio_err, "using curve name prime256v1 instead of secp256r1\n"); curve_name = SN_X9_62_prime256v1; } @@ -238,7 +239,7 @@ int ecparam_main(int argc, char **argv) || EVP_PKEY_keygen_init(gctx_params) <= 0 || EVP_PKEY_CTX_set_params(gctx_params, params) <= 0 || EVP_PKEY_keygen(gctx_params, ¶ms_key) <= 0) { - BIO_puts(bio_err, "unable to generate key\n"); + BIO_printf(bio_err, "unable to generate key\n"); goto end; } } else { @@ -257,14 +258,14 @@ int ecparam_main(int argc, char **argv) && !EVP_PKEY_set_utf8_string_param( params_key, OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT, point_format)) { - BIO_puts(bio_err, "unable to set point conversion format\n"); + BIO_printf(bio_err, "unable to set point conversion format\n"); goto end; } if (asn1_encoding != NULL && !EVP_PKEY_set_utf8_string_param( params_key, OSSL_PKEY_PARAM_EC_ENCODING, asn1_encoding)) { - BIO_puts(bio_err, "unable to set asn1 encoding format\n"); + BIO_printf(bio_err, "unable to set asn1 encoding format\n"); goto end; } } @@ -272,7 +273,7 @@ int ecparam_main(int argc, char **argv) if (no_seed && !EVP_PKEY_set_octet_string_param(params_key, OSSL_PKEY_PARAM_EC_SEED, NULL, 0)) { - BIO_puts(bio_err, "unable to clear seed\n"); + BIO_printf(bio_err, "unable to clear seed\n"); goto end; } @@ -282,27 +283,27 @@ int ecparam_main(int argc, char **argv) if (text && EVP_PKEY_print_params(out, params_key, 0, NULL) <= 0) { - BIO_puts(bio_err, "unable to print params\n"); + BIO_printf(bio_err, "unable to print params\n"); goto end; } if (check || check_named) { - BIO_puts(bio_err, "checking elliptic curve parameters: "); + BIO_printf(bio_err, "checking elliptic curve parameters: "); if (check_named && !EVP_PKEY_set_utf8_string_param(params_key, OSSL_PKEY_PARAM_EC_GROUP_CHECK_TYPE, OSSL_PKEY_EC_GROUP_CHECK_NAMED)) { - BIO_puts(bio_err, "unable to set check_type\n"); + BIO_printf(bio_err, "unable to set check_type\n"); goto end; } pctx = EVP_PKEY_CTX_new_from_pkey(app_get0_libctx(), params_key, app_get0_propq()); if (pctx == NULL || EVP_PKEY_param_check(pctx) <= 0) { - BIO_puts(bio_err, "failed\n"); + BIO_printf(bio_err, "failed\n"); goto end; } - BIO_puts(bio_err, "ok\n"); + BIO_printf(bio_err, "ok\n"); } if (outformat == FORMAT_ASN1 && genkey) @@ -313,7 +314,7 @@ int ecparam_main(int argc, char **argv) params_key, OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS, outformat == FORMAT_ASN1 ? "DER" : "PEM", NULL, NULL); if (!OSSL_ENCODER_to_bio(ectx_params, out)) { - BIO_puts(bio_err, "unable to write elliptic curve parameters\n"); + BIO_printf(bio_err, "unable to write elliptic curve parameters\n"); goto end; } } @@ -331,7 +332,7 @@ int ecparam_main(int argc, char **argv) app_get0_propq()); if (EVP_PKEY_keygen_init(gctx_key) <= 0 || EVP_PKEY_keygen(gctx_key, &key) <= 0) { - BIO_puts(bio_err, "unable to generate key\n"); + BIO_printf(bio_err, "unable to generate key\n"); goto end; } assert(private); @@ -339,8 +340,8 @@ int ecparam_main(int argc, char **argv) key, OSSL_KEYMGMT_SELECT_ALL, outformat == FORMAT_ASN1 ? "DER" : "PEM", NULL, NULL); if (!OSSL_ENCODER_to_bio(ectx_key, out)) { - BIO_puts(bio_err, "unable to write elliptic " - "curve parameters\n"); + BIO_printf(bio_err, "unable to write elliptic " + "curve parameters\n"); goto end; } } diff --git a/apps/enc.c b/apps/enc.c index 3d06a6ef03..1c47cbd80c 100644 --- a/apps/enc.c +++ b/apps/enc.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -24,7 +24,6 @@ #include #endif #include -#include #undef SIZE #undef BSIZE @@ -115,7 +114,7 @@ const OPTIONS enc_options[] = { { "S", OPT_UPPER_S, 's', "Salt, in hex" }, { "iv", OPT_IV, 's', "IV in hex" }, { "md", OPT_MD, 's', "Use specified digest to create a key from the passphrase" }, - { "k", OPT_K, 's', "Passphrase (Deprecated)" }, + { "k", OPT_K, 's', "Passphrase (Deprecated" }, { "kfile", OPT_KFILE, '<', "Read passphrase from file (Deprecated)" }, { "pass", OPT_PASS, 's', "Passphrase source" }, { "iter", OPT_ITER, 'p', @@ -143,15 +142,15 @@ const OPTIONS enc_options[] = { }; static EVP_SKEY *skey_from_params(const EVP_CIPHER *cipher, const char *skeymgmt, - STACK_OF(OPENSSL_STRING) *opts) + STACK_OF(OPENSSL_STRING) *opts) { EVP_SKEY *skey = NULL; EVP_SKEYMGMT *mgmt = NULL; OSSL_PARAM *params = NULL; mgmt = EVP_SKEYMGMT_fetch(app_get0_libctx(), - skeymgmt != NULL ? skeymgmt : EVP_CIPHER_name(cipher), - app_get0_propq()); + skeymgmt != NULL ? skeymgmt : EVP_CIPHER_name(cipher), + app_get0_propq()); if (mgmt == NULL) return NULL; @@ -162,8 +161,8 @@ static EVP_SKEY *skey_from_params(const EVP_CIPHER *cipher, const char *skeymgmt } skey = EVP_SKEY_import(app_get0_libctx(), EVP_SKEYMGMT_get0_name(mgmt), - app_get0_propq(), OSSL_SKEYMGMT_SELECT_ALL, params); - app_params_free(params); + app_get0_propq(), OSSL_SKEYMGMT_SELECT_ALL, params); + OSSL_PARAM_free(params); EVP_SKEYMGMT_free(mgmt); return skey; @@ -244,12 +243,12 @@ int enc_main(int argc, char **argv) ret = 0; goto end; case OPT_LIST: - BIO_puts(bio_out, "Supported ciphers:\n"); + BIO_printf(bio_out, "Supported ciphers:\n"); dec.bio = bio_out; dec.n = 0; OBJ_NAME_do_all_sorted(OBJ_NAME_TYPE_CIPHER_METH, show_ciphers, &dec); - BIO_puts(bio_out, "\n"); + BIO_printf(bio_out, "\n"); ret = 0; goto end; case OPT_E: @@ -425,7 +424,7 @@ int enc_main(int argc, char **argv) if (base64 && bsize < 80) bsize = 80; if (verbose) - BIO_printf(bio_out, "bufsize=%d\n", bsize); + BIO_printf(bio_err, "bufsize=%d\n", bsize); #ifndef OPENSSL_NO_ZLIB if (do_zlib) @@ -448,7 +447,7 @@ int enc_main(int argc, char **argv) if (infile == NULL) { if (!streamable && printkey != 2) { /* if just print key and exit, it's ok */ - BIO_puts(bio_err, "Unstreamable cipher mode\n"); + BIO_printf(bio_err, "Unstreamable cipher mode\n"); goto end; } in = dup_bio_in(informat); @@ -460,7 +459,7 @@ int enc_main(int argc, char **argv) if (str == NULL && passarg != NULL) { if (!app_passwd(passarg, NULL, &pass, NULL)) { - BIO_puts(bio_err, "Error getting password\n"); + BIO_printf(bio_err, "Error getting password\n"); goto end; } str = pass; @@ -487,13 +486,13 @@ int enc_main(int argc, char **argv) break; } if (i < 0) { - BIO_puts(bio_err, "bad password read\n"); + BIO_printf(bio_err, "bad password read\n"); goto end; } } } else { #endif - BIO_puts(bio_err, "password required\n"); + BIO_printf(bio_err, "password required\n"); goto end; } } @@ -584,13 +583,13 @@ int enc_main(int argc, char **argv) sptr = NULL; } else { if (hsalt != NULL && !set_hex(hsalt, salt, saltlen)) { - BIO_puts(bio_err, "invalid hex salt value\n"); + BIO_printf(bio_err, "invalid hex salt value\n"); goto end; } if (enc) { /* encryption */ if (hsalt == NULL) { if (RAND_bytes(salt, saltlen) <= 0) { - BIO_puts(bio_err, "RAND_bytes failed\n"); + BIO_printf(bio_err, "RAND_bytes failed\n"); goto end; } /* @@ -605,25 +604,25 @@ int enc_main(int argc, char **argv) (char *)salt, saltlen) != saltlen)) { - BIO_puts(bio_err, "error writing output file\n"); + BIO_printf(bio_err, "error writing output file\n"); goto end; } } } else { /* decryption */ if (hsalt == NULL) { if (BIO_read(rbio, mbuf, sizeof(mbuf)) != sizeof(mbuf)) { - BIO_puts(bio_err, "error reading input file\n"); + BIO_printf(bio_err, "error reading input file\n"); goto end; } if (memcmp(mbuf, magic, sizeof(mbuf)) == 0) { /* file IS salted */ if (BIO_read(rbio, salt, saltlen) != saltlen) { - BIO_puts(bio_err, "error reading input file\n"); + BIO_printf(bio_err, "error reading input file\n"); goto end; } } else { /* file is NOT salted, NO salt available */ - BIO_puts(bio_err, "bad magic number\n"); + BIO_printf(bio_err, "bad magic number\n"); goto end; } } @@ -644,7 +643,7 @@ int enc_main(int argc, char **argv) if (!PKCS5_PBKDF2_HMAC(str, (int)str_len, sptr, islen, iter, dgst, iklen + ivlen, tmpkeyiv)) { - BIO_puts(bio_err, "PKCS5_PBKDF2_HMAC failed\n"); + BIO_printf(bio_err, "PKCS5_PBKDF2_HMAC failed\n"); goto end; } /* split and move data back to global buffer */ @@ -652,13 +651,13 @@ int enc_main(int argc, char **argv) memcpy(iv, tmpkeyiv + iklen, ivlen); rawkey_set = 1; } else { - BIO_puts(bio_err, "*** WARNING : " - "deprecated key derivation used.\n" - "Using -iter or -pbkdf2 would be better.\n"); + BIO_printf(bio_err, "*** WARNING : " + "deprecated key derivation used.\n" + "Using -iter or -pbkdf2 would be better.\n"); if (!EVP_BytesToKey(cipher, dgst, sptr, (unsigned char *)str, (int)str_len, 1, key, iv)) { - BIO_puts(bio_err, "EVP_BytesToKey failed\n"); + BIO_printf(bio_err, "EVP_BytesToKey failed\n"); goto end; } rawkey_set = 1; @@ -676,9 +675,9 @@ int enc_main(int argc, char **argv) int siz = EVP_CIPHER_get_iv_length(cipher); if (siz == 0) { - BIO_puts(bio_err, "warning: iv not used by this cipher\n"); + BIO_printf(bio_err, "warning: iv not used by this cipher\n"); } else if (!set_hex(hiv, iv, siz)) { - BIO_puts(bio_err, "invalid hex iv value\n"); + BIO_printf(bio_err, "invalid hex iv value\n"); goto end; } } @@ -689,12 +688,12 @@ int enc_main(int argc, char **argv) * No IV was explicitly set and no IV was generated. * Hence the IV is undefined, making correct decryption impossible. */ - BIO_puts(bio_err, "iv undefined\n"); + BIO_printf(bio_err, "iv undefined\n"); goto end; } if (hkey != NULL) { if (!set_hex(hkey, key, EVP_CIPHER_get_key_length(cipher))) { - BIO_puts(bio_err, "invalid hex key value\n"); + BIO_printf(bio_err, "invalid hex key value\n"); goto end; } /* wiping secret data as we no longer need it */ @@ -707,7 +706,7 @@ int enc_main(int argc, char **argv) * or an opaque symmetric key. We do not allow both options simultaneously. */ if (rawkey_set > 0 && (skeyopts != NULL || skeyuri != NULL)) { - BIO_puts(bio_err, "Either a raw key or the skeyopt/skeyuri args must be used.\n"); + BIO_printf(bio_err, "Either a raw key or the skeyopt/skeyuri args must be used.\n"); goto end; } @@ -736,7 +735,7 @@ int enc_main(int argc, char **argv) char *storepass = NULL; if (!app_passwd(storepassarg, NULL, &storepass, NULL)) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Error getting store password from 'storepass' argument\n"); } @@ -750,7 +749,7 @@ int enc_main(int argc, char **argv) skey = skey_from_params(cipher, skeymgmt, skeyopts); if (skey == NULL) { BIO_printf(bio_err, "Error creating opaque key object for skeymgmt %s\n", - skeymgmt ? skeymgmt : EVP_CIPHER_name(cipher)); + skeymgmt ? skeymgmt : EVP_CIPHER_name(cipher)); goto end; } } @@ -807,11 +806,11 @@ int enc_main(int argc, char **argv) if (inl <= 0) break; if (!streamable && !BIO_eof(rbio)) { /* do not output data */ - BIO_puts(bio_err, "Unstreamable cipher mode\n"); + BIO_printf(bio_err, "Unstreamable cipher mode\n"); goto end; } if (BIO_write(wbio, (char *)buff, inl) != inl) { - BIO_puts(bio_err, "error writing output file\n"); + BIO_printf(bio_err, "error writing output file\n"); goto end; } if (!streamable) @@ -819,17 +818,16 @@ int enc_main(int argc, char **argv) } if (!BIO_flush(wbio)) { if (enc) - BIO_puts(bio_err, "bad encrypt\n"); + BIO_printf(bio_err, "bad encrypt\n"); else - BIO_puts(bio_err, "bad decrypt\n"); + BIO_printf(bio_err, "bad decrypt\n"); goto end; } ret = 0; if (verbose) { - BIO_printf(bio_err, "bytes read : %8" PRIu64 "\n" - "bytes written: %8" PRIu64 "\n", - BIO_number_read(in), BIO_number_written(out)); + BIO_printf(bio_err, "bytes read : %8ju\n", BIO_number_read(in)); + BIO_printf(bio_err, "bytes written: %8ju\n", BIO_number_written(out)); } end: ERR_print_errors(bio_err); @@ -855,29 +853,25 @@ end: static void show_ciphers(const OBJ_NAME *name, void *arg) { struct doall_enc_ciphers *dec = (struct doall_enc_ciphers *)arg; - EVP_CIPHER *cipher; + const EVP_CIPHER *cipher; if (!islower((unsigned char)*name->name)) return; /* Filter out ciphers that we cannot use */ - cipher = EVP_CIPHER_fetch(app_get0_libctx(), name->name, app_get0_propq()); + cipher = EVP_get_cipherbyname(name->name); if (cipher == NULL || (EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_AEAD_CIPHER) != 0 || (EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_ENC_THEN_MAC) != 0 - || EVP_CIPHER_get_mode(cipher) == EVP_CIPH_XTS_MODE) { - EVP_CIPHER_free(cipher); + || EVP_CIPHER_get_mode(cipher) == EVP_CIPH_XTS_MODE) return; - } BIO_printf(dec->bio, "-%-25s", name->name); if (++dec->n == 3) { - BIO_puts(dec->bio, "\n"); + BIO_printf(dec->bio, "\n"); dec->n = 0; } else - BIO_puts(dec->bio, " "); - - EVP_CIPHER_free(cipher); + BIO_printf(dec->bio, " "); } static int set_hex(const char *in, unsigned char *out, int size) @@ -888,17 +882,17 @@ static int set_hex(const char *in, unsigned char *out, int size) i = size * 2; n = (int)strlen(in); if (n > i) { - BIO_puts(bio_err, "hex string is too long, ignoring excess\n"); + BIO_printf(bio_err, "hex string is too long, ignoring excess\n"); n = i; /* ignore exceeding part */ } else if (n < i) { - BIO_puts(bio_err, "hex string is too short, padding with zero bytes to length\n"); + BIO_printf(bio_err, "hex string is too short, padding with zero bytes to length\n"); } memset(out, 0, size); for (i = 0; i < n; i++) { j = (unsigned char)*in++; if (!isxdigit(j)) { - BIO_puts(bio_err, "non-hex digit\n"); + BIO_printf(bio_err, "non-hex digit\n"); return 0; } j = (unsigned char)OPENSSL_hexchar2int(j); diff --git a/apps/fipsinstall.c b/apps/fipsinstall.c index b9b66e42b7..ea54a00cff 100644 --- a/apps/fipsinstall.c +++ b/apps/fipsinstall.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -77,8 +77,7 @@ typedef enum OPTION_choice { OPT_NO_PBKDF2_LOWER_BOUND_CHECK, OPT_ECDH_COFACTOR_CHECK, OPT_SELF_TEST_ONLOAD, - OPT_SELF_TEST_ONINSTALL, - OPT_DEFER_TESTS + OPT_SELF_TEST_ONINSTALL } OPTION_CHOICE; const OPTIONS fipsinstall_options[] = { @@ -151,7 +150,6 @@ const OPTIONS fipsinstall_options[] = { "Disable lower bound check for PBKDF2" }, { "ecdh_cofactor_check", OPT_ECDH_COFACTOR_CHECK, '-', "Enable Cofactor check for ECDH" }, - { "defer_tests", OPT_DEFER_TESTS, '-', "Enables test deferral" }, OPT_SECTION("Input"), { "in", OPT_IN, '<', "Input config file, used when verifying" }, @@ -199,7 +197,6 @@ typedef struct { unsigned int x942kdf_key_check : 1; unsigned int pbkdf2_lower_bound_check : 1; unsigned int ecdh_cofactor_check : 1; - unsigned int defer_tests : 1; } FIPS_OPTS; /* Pedantic FIPS compliance */ @@ -234,7 +231,6 @@ static const FIPS_OPTS pedantic_opts = { 1, /* x942kdf_key_check */ 1, /* pbkdf2_lower_bound_check */ 1, /* ecdh_cofactor_check */ - 0, /* defer_tests */ }; /* Default FIPS settings for backward compatibility */ @@ -269,7 +265,6 @@ static FIPS_OPTS fips_opts = { 0, /* x942kdf_key_check */ 1, /* pbkdf2_lower_bound_check */ 0, /* ecdh_cofactor_check */ - 0, /* defer_tests */ }; static int check_non_pedantic_fips(int pedantic, const char *name) @@ -314,7 +309,7 @@ static int load_fips_prov_and_run_self_test(const char *prov_name, prov = OSSL_PROVIDER_load(NULL, prov_name); if (prov == NULL) { - BIO_puts(bio_err, "Failed to load FIPS module\n"); + BIO_printf(bio_err, "Failed to load FIPS module\n"); goto end; } if (!quiet) { @@ -326,7 +321,7 @@ static int load_fips_prov_and_run_self_test(const char *prov_name, &build, sizeof(build)); *p = OSSL_PARAM_construct_end(); if (!OSSL_PROVIDER_get_params(prov, params)) { - BIO_puts(bio_err, "Failed to query FIPS module parameters\n"); + BIO_printf(bio_err, "Failed to query FIPS module parameters\n"); goto end; } if (OSSL_PARAM_modified(params)) @@ -340,7 +335,7 @@ static int load_fips_prov_and_run_self_test(const char *prov_name, &vers, sizeof(vers)); *p = OSSL_PARAM_construct_end(); if (!OSSL_PROVIDER_get_params(prov, params)) { - BIO_puts(bio_err, "Failed to query FIPS module parameters\n"); + BIO_printf(bio_err, "Failed to query FIPS module parameters\n"); goto end; } } @@ -368,13 +363,11 @@ static int print_mac(BIO *bio, const char *label, const unsigned char *mac, static int write_config_header(BIO *out, const char *prov_name, const char *section) { - return (BIO_printf(out, "openssl_conf = openssl_init\n\n" - "[openssl_init]\n" - "providers = provider_section\n\n" - "[provider_section]\n" - "%s = %s\n\n", - prov_name, section) - > 0); + return BIO_printf(out, "openssl_conf = openssl_init\n\n") + && BIO_printf(out, "[openssl_init]\n") + && BIO_printf(out, "providers = provider_section\n\n") + && BIO_printf(out, "[provider_section]\n") + && BIO_printf(out, "%s = %s\n\n", prov_name, section); } /* @@ -393,75 +386,109 @@ static int write_config_fips_section(BIO *out, const char *section, { int ret = 0; - if (BIO_printf(out, "[%s]\n" - "activate = 1\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n" - "%s = %s\n", - section, - OSSL_PROV_FIPS_PARAM_INSTALL_VERSION, VERSION_VAL, - OSSL_PROV_FIPS_PARAM_CONDITIONAL_ERRORS, opts->conditional_errors ? "1" : "0", - OSSL_PROV_PARAM_SECURITY_CHECKS, opts->security_checks ? "1" : "0", - OSSL_PROV_PARAM_HMAC_KEY_CHECK, opts->hmac_key_check ? "1" : "0", - OSSL_PROV_PARAM_KMAC_KEY_CHECK, opts->kmac_key_check ? "1" : "0", - OSSL_PROV_PARAM_TLS1_PRF_EMS_CHECK, opts->tls_prf_ems_check ? "1" : "0", - OSSL_PROV_PARAM_NO_SHORT_MAC, opts->no_short_mac ? "1" : "0", - OSSL_PROV_PARAM_DRBG_TRUNC_DIGEST, opts->drgb_no_trunc_dgst ? "1" : "0", - OSSL_PROV_PARAM_SIGNATURE_DIGEST_CHECK, opts->signature_digest_check ? "1" : "0", - OSSL_PROV_PARAM_HKDF_DIGEST_CHECK, opts->hkdf_digest_check ? "1" : "0", - OSSL_PROV_PARAM_TLS13_KDF_DIGEST_CHECK, opts->tls13_kdf_digest_check ? "1" : "0", - OSSL_PROV_PARAM_TLS1_PRF_DIGEST_CHECK, opts->tls1_prf_digest_check ? "1" : "0", - OSSL_PROV_PARAM_SSHKDF_DIGEST_CHECK, opts->sshkdf_digest_check ? "1" : "0", - OSSL_PROV_PARAM_SSKDF_DIGEST_CHECK, opts->sskdf_digest_check ? "1" : "0", - OSSL_PROV_PARAM_X963KDF_DIGEST_CHECK, opts->x963kdf_digest_check ? "1" : "0", - OSSL_PROV_PARAM_DSA_SIGN_DISABLED, opts->dsa_sign_disabled ? "1" : "0", - OSSL_PROV_PARAM_TDES_ENCRYPT_DISABLED, opts->tdes_encrypt_disabled ? "1" : "0", - OSSL_PROV_PARAM_RSA_PKCS15_PAD_DISABLED, opts->rsa_pkcs15_padding_disabled ? "1" : "0", - OSSL_PROV_PARAM_RSA_PSS_SALTLEN_CHECK, opts->rsa_pss_saltlen_check ? "1" : "0", - OSSL_PROV_PARAM_RSA_SIGN_X931_PAD_DISABLED, opts->sign_x931_padding_disabled ? "1" : "0", - OSSL_PROV_PARAM_HKDF_KEY_CHECK, opts->hkdf_key_check ? "1" : "0", - OSSL_PROV_PARAM_KBKDF_KEY_CHECK, opts->kbkdf_key_check ? "1" : "0", - OSSL_PROV_PARAM_TLS13_KDF_KEY_CHECK, opts->tls13_kdf_key_check ? "1" : "0", - OSSL_PROV_PARAM_TLS1_PRF_KEY_CHECK, opts->tls1_prf_key_check ? "1" : "0", - OSSL_PROV_PARAM_SSHKDF_KEY_CHECK, opts->sshkdf_key_check ? "1" : "0", - OSSL_PROV_PARAM_SSKDF_KEY_CHECK, opts->sskdf_key_check ? "1" : "0", - OSSL_PROV_PARAM_X963KDF_KEY_CHECK, opts->x963kdf_key_check ? "1" : "0", - OSSL_PROV_PARAM_X942KDF_KEY_CHECK, opts->x942kdf_key_check ? "1" : "0", - OSSL_PROV_PARAM_PBKDF2_LOWER_BOUND_CHECK, opts->pbkdf2_lower_bound_check ? "1" : "0", - OSSL_PROV_PARAM_ECDH_COFACTOR_CHECK, opts->ecdh_cofactor_check ? "1" : "0") + if (BIO_printf(out, "[%s]\n", section) <= 0 + || BIO_printf(out, "activate = 1\n") <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_FIPS_PARAM_INSTALL_VERSION, + VERSION_VAL) + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_FIPS_PARAM_CONDITIONAL_ERRORS, + opts->conditional_errors ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_SECURITY_CHECKS, + opts->security_checks ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_HMAC_KEY_CHECK, + opts->hmac_key_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_KMAC_KEY_CHECK, + opts->kmac_key_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_TLS1_PRF_EMS_CHECK, + opts->tls_prf_ems_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_NO_SHORT_MAC, + opts->no_short_mac ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_DRBG_TRUNC_DIGEST, + opts->drgb_no_trunc_dgst ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_SIGNATURE_DIGEST_CHECK, + opts->signature_digest_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_HKDF_DIGEST_CHECK, + opts->hkdf_digest_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", + OSSL_PROV_PARAM_TLS13_KDF_DIGEST_CHECK, + opts->tls13_kdf_digest_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", + OSSL_PROV_PARAM_TLS1_PRF_DIGEST_CHECK, + opts->tls1_prf_digest_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", + OSSL_PROV_PARAM_SSHKDF_DIGEST_CHECK, + opts->sshkdf_digest_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_SSKDF_DIGEST_CHECK, + opts->sskdf_digest_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", + OSSL_PROV_PARAM_X963KDF_DIGEST_CHECK, + opts->x963kdf_digest_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_DSA_SIGN_DISABLED, + opts->dsa_sign_disabled ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_TDES_ENCRYPT_DISABLED, + opts->tdes_encrypt_disabled ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", + OSSL_PROV_PARAM_RSA_PKCS15_PAD_DISABLED, + opts->rsa_pkcs15_padding_disabled ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", + OSSL_PROV_PARAM_RSA_PSS_SALTLEN_CHECK, + opts->rsa_pss_saltlen_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", + OSSL_PROV_PARAM_RSA_SIGN_X931_PAD_DISABLED, + opts->sign_x931_padding_disabled ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_HKDF_KEY_CHECK, + opts->hkdf_key_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_KBKDF_KEY_CHECK, + opts->kbkdf_key_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", + OSSL_PROV_PARAM_TLS13_KDF_KEY_CHECK, + opts->tls13_kdf_key_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_TLS1_PRF_KEY_CHECK, + opts->tls1_prf_key_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_SSHKDF_KEY_CHECK, + opts->sshkdf_key_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_SSKDF_KEY_CHECK, + opts->sskdf_key_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_X963KDF_KEY_CHECK, + opts->x963kdf_key_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_X942KDF_KEY_CHECK, + opts->x942kdf_key_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", + OSSL_PROV_PARAM_PBKDF2_LOWER_BOUND_CHECK, + opts->pbkdf2_lower_bound_check ? "1" : "0") + <= 0 + || BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_ECDH_COFACTOR_CHECK, + opts->ecdh_cofactor_check ? "1" : "0") <= 0 || !print_mac(out, OSSL_PROV_FIPS_PARAM_MODULE_MAC, module_mac, - module_mac_len) - || BIO_printf(out, "%s = %s\n", OSSL_PROV_FIPS_PARAM_DEFER_TESTS, - opts->defer_tests ? "1" : "0") - <= 0) + module_mac_len)) goto end; if (install_mac != NULL @@ -545,37 +572,37 @@ static int verify_config(const char *infile, const char *section, s = NCONF_get_string(conf, section, OSSL_PROV_FIPS_PARAM_INSTALL_VERSION); if (s == NULL || strcmp(s, VERSION_VAL) != 0) { - BIO_puts(bio_err, "version not found\n"); + BIO_printf(bio_err, "version not found\n"); goto end; } s = NCONF_get_string(conf, section, OSSL_PROV_FIPS_PARAM_MODULE_MAC); if (s == NULL) { - BIO_puts(bio_err, "Module integrity MAC not found\n"); + BIO_printf(bio_err, "Module integrity MAC not found\n"); goto end; } buf1 = OPENSSL_hexstr2buf(s, &len); if (buf1 == NULL || (size_t)len != module_mac_len || memcmp(module_mac, buf1, module_mac_len) != 0) { - BIO_puts(bio_err, "Module integrity mismatch\n"); + BIO_printf(bio_err, "Module integrity mismatch\n"); goto end; } if (install_mac != NULL && install_mac_len > 0) { s = NCONF_get_string(conf, section, OSSL_PROV_FIPS_PARAM_INSTALL_STATUS); if (s == NULL || strcmp(s, INSTALL_STATUS_VAL) != 0) { - BIO_puts(bio_err, "install status not found\n"); + BIO_printf(bio_err, "install status not found\n"); goto end; } s = NCONF_get_string(conf, section, OSSL_PROV_FIPS_PARAM_INSTALL_MAC); if (s == NULL) { - BIO_puts(bio_err, "Install indicator MAC not found\n"); + BIO_printf(bio_err, "Install indicator MAC not found\n"); goto end; } buf2 = OPENSSL_hexstr2buf(s, &len); if (buf2 == NULL || (size_t)len != install_mac_len || memcmp(install_mac, buf2, install_mac_len) != 0) { - BIO_puts(bio_err, "Install indicator status mismatch\n"); + BIO_printf(bio_err, "Install indicator status mismatch\n"); goto end; } } @@ -775,9 +802,6 @@ int fipsinstall_main(int argc, char **argv) set_selftest_onload_option = 1; fips_opts.self_test_onload = 0; break; - case OPT_DEFER_TESTS: - fips_opts.defer_tests = 1; - break; } } @@ -826,7 +850,7 @@ int fipsinstall_main(int argc, char **argv) module_bio = bio_open_default(module_fname, 'r', FORMAT_BINARY); if (module_bio == NULL) { - BIO_puts(bio_err, "Failed to open module file\n"); + BIO_printf(bio_err, "Failed to open module file\n"); goto end; } @@ -842,7 +866,7 @@ int fipsinstall_main(int argc, char **argv) ctx = EVP_MAC_CTX_new(mac); if (ctx == NULL) { - BIO_puts(bio_err, "Unable to create MAC CTX for module check\n"); + BIO_printf(bio_err, "Unable to create MAC CTX for module check\n"); goto end; } @@ -854,7 +878,7 @@ int fipsinstall_main(int argc, char **argv) goto end; if (!EVP_MAC_CTX_set_params(ctx, params)) { - BIO_puts(bio_err, "MAC parameter error\n"); + BIO_printf(bio_err, "MAC parameter error\n"); ERR_print_errors(bio_err); ok = 0; } @@ -865,7 +889,7 @@ int fipsinstall_main(int argc, char **argv) ctx2 = EVP_MAC_CTX_dup(ctx); if (ctx2 == NULL) { - BIO_puts(bio_err, "Unable to create MAC CTX for install indicator\n"); + BIO_printf(bio_err, "Unable to create MAC CTX for install indicator\n"); goto end; } @@ -876,7 +900,7 @@ int fipsinstall_main(int argc, char **argv) mem_bio = BIO_new_mem_buf((const void *)INSTALL_STATUS_VAL, (int)strlen(INSTALL_STATUS_VAL)); if (mem_bio == NULL) { - BIO_puts(bio_err, "Unable to create memory BIO\n"); + BIO_printf(bio_err, "Unable to create memory BIO\n"); goto end; } if (!do_mac(ctx2, read_buffer, mem_bio, install_mac, &install_mac_len)) @@ -889,7 +913,7 @@ int fipsinstall_main(int argc, char **argv) install_mac, install_mac_len)) goto end; if (!quiet) - BIO_puts(bio_err, "VERIFY PASSED\n"); + BIO_printf(bio_err, "VERIFY PASSED\n"); } else { conf = generate_config_and_load(prov_name, section_name, module_mac, module_mac_len, &fips_opts); @@ -912,7 +936,7 @@ int fipsinstall_main(int argc, char **argv) fout = out_fname == NULL ? dup_bio_out(FORMAT_TEXT) : bio_open_default(out_fname, 'w', FORMAT_TEXT); if (fout == NULL) { - BIO_puts(bio_err, "Failed to open file\n"); + BIO_printf(bio_err, "Failed to open file\n"); goto end; } @@ -921,7 +945,7 @@ int fipsinstall_main(int argc, char **argv) install_mac, install_mac_len)) goto end; if (!quiet) - BIO_puts(bio_err, "INSTALL PASSED\n"); + BIO_printf(bio_err, "INSTALL PASSED\n"); } ret = 0; diff --git a/apps/gendsa.c b/apps/gendsa.c index 43f9194f5e..bc0f5e5ba1 100644 --- a/apps/gendsa.c +++ b/apps/gendsa.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -117,7 +117,7 @@ int gendsa_main(int argc, char **argv) private = 1; if (!app_passwd(NULL, passoutarg, NULL, &passout)) { - BIO_puts(bio_err, "Error getting password\n"); + BIO_printf(bio_err, "Error getting password\n"); goto end; } @@ -136,13 +136,13 @@ int gendsa_main(int argc, char **argv) ctx = EVP_PKEY_CTX_new_from_pkey(app_get0_libctx(), pkey, app_get0_propq()); if (ctx == NULL) { - BIO_puts(bio_err, "unable to create PKEY context\n"); + BIO_printf(bio_err, "unable to create PKEY context\n"); goto end; } EVP_PKEY_free(pkey); pkey = NULL; if (EVP_PKEY_keygen_init(ctx) <= 0) { - BIO_puts(bio_err, "unable to set up for key generation\n"); + BIO_printf(bio_err, "unable to set up for key generation\n"); goto end; } pkey = app_keygen(ctx, "DSA", nbits, verbose); @@ -151,7 +151,7 @@ int gendsa_main(int argc, char **argv) assert(private); if (!PEM_write_bio_PrivateKey(out, pkey, enc, NULL, 0, NULL, passout)) { - BIO_puts(bio_err, "unable to output generated key\n"); + BIO_printf(bio_err, "unable to output generated key\n"); goto end; } ret = 0; diff --git a/apps/genpkey.c b/apps/genpkey.c index a6d1786d56..19fc788b23 100644 --- a/apps/genpkey.c +++ b/apps/genpkey.c @@ -1,5 +1,5 @@ /* - * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -22,7 +22,6 @@ static int init_keygen_file(EVP_PKEY_CTX **pctx, const char *file, typedef enum OPTION_choice { OPT_COMMON, OPT_OUTFORM, - OPT_ENCOPT, OPT_OUT, OPT_PASS, OPT_PARAMFILE, @@ -54,7 +53,6 @@ const OPTIONS genpkey_options[] = { { "out", OPT_OUT, '>', "Output (private key) file" }, { "outpubkey", OPT_OUTPUBKEY, '>', "Output public key file" }, { "outform", OPT_OUTFORM, 'F', "output format (DER or PEM)" }, - { "encopt", OPT_ENCOPT, 's', "Private key encoder parameter" }, { "pass", OPT_PASS, 's', "Output file pass phrase source" }, { "genparam", OPT_GENPARAM, '-', "Generate parameters, not key" }, { "text", OPT_TEXT, '-', "Print the private key in text" }, @@ -108,7 +106,7 @@ static void show_gen_pkeyopt(const char *algname, OSSL_LIB_CTX *libctx, const ch if (params == NULL) goto cleanup; - BIO_puts(bio_err, "\nThe possible -pkeyopt arguments are:\n"); + BIO_printf(bio_err, "\nThe possible -pkeyopt arguments are:\n"); for (i = 0; params[i].key != NULL; ++i) { const char *name = param_datatype_2name(params[i].data_type, &ishex); @@ -132,7 +130,6 @@ int genpkey_main(int argc, char **argv) OPTION_CHOICE o; int outformat = FORMAT_PEM, text = 0, ret = 1, rv, do_param = 0; int private = 0, i; - STACK_OF(OPENSSL_STRING) *encopt = NULL; OSSL_LIB_CTX *libctx = app_get0_libctx(); STACK_OF(OPENSSL_STRING) *keyopt = NULL; @@ -157,12 +154,6 @@ int genpkey_main(int argc, char **argv) if (!opt_format(opt_arg(), OPT_FMT_PEMDER, &outformat)) goto opthelp; break; - case OPT_ENCOPT: - if (encopt == NULL) - encopt = sk_OPENSSL_STRING_new_null(); - if (!sk_OPENSSL_STRING_push(encopt, opt_arg())) - goto end; - break; case OPT_OUT: outfile = opt_arg(); break; @@ -245,7 +236,7 @@ int genpkey_main(int argc, char **argv) if (!opt_cipher(ciphername, &cipher)) goto opthelp; if (ciphername != NULL && do_param == 1) { - BIO_puts(bio_err, "Cannot use cipher with -genparam option\n"); + BIO_printf(bio_err, "Cannot use cipher with -genparam option\n"); goto opthelp; } @@ -281,16 +272,16 @@ int genpkey_main(int argc, char **argv) rv = PEM_write_bio_Parameters(mem_out, pkey); } else if (outformat == FORMAT_PEM) { assert(private); - rv = encode_private_key(mem_out, "PEM", pkey, encopt, cipher, pass); + rv = PEM_write_bio_PrivateKey(mem_out, pkey, cipher, NULL, 0, NULL, pass); if (rv > 0 && mem_outpubkey != NULL) rv = PEM_write_bio_PUBKEY(mem_outpubkey, pkey); } else if (outformat == FORMAT_ASN1) { assert(private); - rv = encode_private_key(mem_out, "DER", pkey, encopt, cipher, pass); + rv = i2d_PrivateKey_bio(mem_out, pkey); if (rv > 0 && mem_outpubkey != NULL) rv = i2d_PUBKEY_bio(mem_outpubkey, pkey); } else { - BIO_puts(bio_err, "Bad format specified for key\n"); + BIO_printf(bio_err, "Bad format specified for key\n"); goto end; } @@ -331,7 +322,6 @@ end: outfile, strerror(errno)); } } - sk_OPENSSL_STRING_free(encopt); EVP_PKEY_free(pkey); EVP_PKEY_CTX_free(ctx); EVP_CIPHER_free(cipher); diff --git a/apps/genrsa.c b/apps/genrsa.c index 9187fa9ce0..1412d3cf34 100644 --- a/apps/genrsa.c +++ b/apps/genrsa.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -171,7 +171,7 @@ int genrsa_main(int argc, char **argv) if (!opt_cipher(ciphername, &enc)) goto end; if (!app_passwd(NULL, passoutarg, NULL, &passout)) { - BIO_puts(bio_err, "Error getting password\n"); + BIO_printf(bio_err, "Error getting password\n"); goto end; } @@ -188,19 +188,19 @@ int genrsa_main(int argc, char **argv) EVP_PKEY_CTX_set_app_data(ctx, bio_err); if (EVP_PKEY_CTX_set_rsa_keygen_bits(ctx, num) <= 0) { - BIO_puts(bio_err, "Error setting RSA length\n"); + BIO_printf(bio_err, "Error setting RSA length\n"); goto end; } if (!BN_set_word(bn, f4)) { - BIO_puts(bio_err, "Error allocating RSA public exponent\n"); + BIO_printf(bio_err, "Error allocating RSA public exponent\n"); goto end; } if (EVP_PKEY_CTX_set1_rsa_keygen_pubexp(ctx, bn) <= 0) { - BIO_puts(bio_err, "Error setting RSA public exponent\n"); + BIO_printf(bio_err, "Error setting RSA public exponent\n"); goto end; } if (EVP_PKEY_CTX_set_rsa_keygen_primes(ctx, primes) <= 0) { - BIO_puts(bio_err, "Error setting number of primes\n"); + BIO_printf(bio_err, "Error setting number of primes\n"); goto end; } pkey = app_keygen(ctx, "RSA", num, verbose); @@ -213,7 +213,7 @@ int genrsa_main(int argc, char **argv) /* Every RSA key has an 'e' */ EVP_PKEY_get_bn_param(pkey, "e", &e); if (e == NULL) { - BIO_puts(bio_err, "Error cannot access RSA e\n"); + BIO_printf(bio_err, "Error cannot access RSA e\n"); goto end; } hexe = BN_bn2hex(e); diff --git a/apps/include/app_params.h b/apps/include/app_params.h index 5c8d22ced9..20caf737d4 100644 --- a/apps/include/app_params.h +++ b/apps/include/app_params.h @@ -7,12 +7,7 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_APPS_INCLUDE_APP_PARAMS_H) -#define OSSL_APPS_INCLUDE_APP_PARAMS_H - #include int print_param_types(const char *thing, const OSSL_PARAM *pdefs, int indent); void print_param_value(const OSSL_PARAM *p, int indent); - -#endif /* !defined(OSSL_APPS_INCLUDE_APP_PARAMS_H) */ diff --git a/apps/include/apps.h b/apps/include/apps.h index 80bd775ffb..2113669f5d 100644 --- a/apps/include/apps.h +++ b/apps/include/apps.h @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -10,16 +10,6 @@ #ifndef OSSL_APPS_H #define OSSL_APPS_H -#if defined(__linux__) || defined(__sun__) || defined(__hpux) -/* - * Allow open() and stat() to work with files larger than 2GB on 32-bit - * systems. See crypto/o_fopen.c and crypto/bio/bss_file.c. - */ -#ifndef _FILE_OFFSET_BITS -#define _FILE_OFFSET_BITS 64 -#endif -#endif - #include "internal/common.h" /* for HAS_PREFIX */ #include "internal/nelem.h" #include @@ -32,19 +22,6 @@ #endif #include -#if defined(OPENSSL_SYS_UNIX) && defined(_POSIX_MAPPED_FILES) && _POSIX_MAPPED_FILES > 0 -#include -#include -/* - * Map a file read-only into memory. Returns 1 on success (*out_data and - * *out_size set; caller must munmap when done), 0 when file size is 0 (no - * error, caller may use buffer path), or -1 on error (message printed to - * bio_err). known_size: (size_t)-1 = stat to get size; 0 = do not map - * (return 0); > 0 = use this size (caller obtained it from stat of same path). - */ -int app_mmap_file(const char *path, BIO *err_bio, size_t known_size, - const unsigned char **out_data, size_t *out_size); -#endif #include #include #include @@ -101,7 +78,7 @@ void wait_for_async(SSL *s); int has_stdin_waiting(void); #endif -int corrupt_signature(ASN1_STRING *signature); +void corrupt_signature(const ASN1_STRING *signature); /* Helpers for setting X509v3 certificate fields notBefore and notAfter */ int check_cert_time_string(const char *time, const char *desc); @@ -125,10 +102,6 @@ int wrap_password_callback(char *buf, int bufsiz, int verify, void *cb_data); int progress_cb(EVP_PKEY_CTX *ctx); void dump_cert_text(BIO *out, X509 *x); -int encode_private_key( - BIO *out, const char *output_type, const EVP_PKEY *pkey, - const STACK_OF(OPENSSL_STRING) *encopt, const EVP_CIPHER *cipher, - const char *pass); void print_name(BIO *out, const char *title, const X509_NAME *nm); void print_bignum_var(BIO *, const BIGNUM *, const char *, int, unsigned char *); @@ -168,10 +141,11 @@ char *process_additional_mac_key_arguments(const char *arg); char *get_str_from_file(const char *filename); int load_cert_certs(const char *uri, X509 **pcert, STACK_OF(X509) **pcerts, - int exclude_http, const char *pass, const char *desc, X509_VERIFY_PARAM *vpm); -STACK_OF(X509) *load_certs_multifile(char *files, const char *source, + int exclude_http, const char *pass, const char *desc, + X509_VERIFY_PARAM *vpm); +STACK_OF(X509) *load_certs_multifile(char *files, const char *pass, const char *desc, X509_VERIFY_PARAM *vpm); -X509_STORE *load_certstore(char *input, const char *source, const char *desc, +X509_STORE *load_certstore(char *input, const char *pass, const char *desc, X509_VERIFY_PARAM *vpm); int load_certs(const char *uri, int maybe_stdin, STACK_OF(X509) **certs, const char *pass, const char *desc); @@ -186,7 +160,6 @@ int load_key_certs_crls(const char *uri, int format, int maybe_stdin, EVP_SKEY **pskey); EVP_SKEY *load_skey(const char *uri, int format, int maybe_stdin, const char *pass, int quiet); -int load_rpk_file(SSL *ssl, const char *file); X509_STORE *setup_verify(const char *CAfile, int noCAfile, const char *CApath, int noCApath, const char *CAstore, int noCAstore); @@ -243,7 +216,7 @@ typedef struct ca_db_st { #endif } CA_DB; -extern int do_updatedb(CA_DB *db, const time_t *now); +extern int do_updatedb(CA_DB *db, time_t *now); void app_bail_out(char *fmt, ...); /** @@ -291,7 +264,7 @@ int parse_yesno(const char *str, int def); X509_NAME *parse_name(const char *str, int chtype, int multirdn, const char *desc); void policies_print(X509_STORE_CTX *ctx); -int bio_to_mem(unsigned char **out, size_t *outlen, size_t maxlen, BIO *in); +int bio_to_mem(unsigned char **out, int maxlen, BIO *in); int pkey_ctrl_string(EVP_PKEY_CTX *ctx, const char *value); int x509_ctrl_string(X509 *x, const char *value); int x509_req_ctrl_string(X509_REQ *x, const char *value); @@ -299,10 +272,6 @@ int init_gen_str(EVP_PKEY_CTX **pctx, const char *algname, int do_param, OSSL_LIB_CTX *libctx, const char *propq); int cert_matches_key(const X509 *cert, const EVP_PKEY *pkey); -int do_EXT_add_nconf(CONF *conf1, CONF *conf2, X509V3_CTX *ctx, - X509 *cert, const char *msg, const char *sect); -int do_EXT_REQ_add_nconf(CONF *conf1, CONF *conf2, X509V3_CTX *ctx, - X509_REQ *req, const char *msg, const char *sect); int do_X509_sign(X509 *x, int force_v1, EVP_PKEY *pkey, const char *md, STACK_OF(OPENSSL_STRING) *sigopts, X509V3_CTX *ext_ctx); int do_X509_verify(X509 *x, EVP_PKEY *pkey, STACK_OF(OPENSSL_STRING) *vfyopts); @@ -317,14 +286,12 @@ extern char *psk_key; unsigned char *next_protos_parse(size_t *outlen, const char *in); -int check_cert_might_be_valid(BIO *bio, BIO *bio_err, X509 *x, +int check_cert_attributes(BIO *bio, X509 *x, const char *checkhost, const char *checkemail, - const char *checkip); + const char *checkip, int print); void store_setup_crl_download(X509_STORE *st); -int host_is_ip_address(const char *host); - typedef struct app_http_tls_info_st { const char *server; const char *port; diff --git a/apps/include/apps_ui.h b/apps/include/apps_ui.h index 66caca98ae..ea41c092f4 100644 --- a/apps/include/apps_ui.h +++ b/apps/include/apps_ui.h @@ -10,9 +10,6 @@ #ifndef OSSL_APPS_UI_H #define OSSL_APPS_UI_H -#include -#include - #define PW_MIN_LENGTH 4 typedef struct pw_cb_data { const void *password; diff --git a/apps/include/cmp_mock_srv.h b/apps/include/cmp_mock_srv.h index d05f99ea04..215b95b744 100644 --- a/apps/include/cmp_mock_srv.h +++ b/apps/include/cmp_mock_srv.h @@ -19,8 +19,6 @@ OSSL_CMP_SRV_CTX *ossl_cmp_mock_srv_new(OSSL_LIB_CTX *libctx, const char *propq); void ossl_cmp_mock_srv_free(OSSL_CMP_SRV_CTX *srv_ctx); -OSSL_CMP_MSG *ossl_cmp_mock_server_perform(OSSL_CMP_CTX *ctx, - const OSSL_CMP_MSG *req); int ossl_cmp_mock_srv_set1_refCert(OSSL_CMP_SRV_CTX *srv_ctx, X509 *cert); int ossl_cmp_mock_srv_set1_certOut(OSSL_CMP_SRV_CTX *srv_ctx, X509 *cert); @@ -36,7 +34,6 @@ int ossl_cmp_mock_srv_set1_oldWithNew(OSSL_CMP_SRV_CTX *srv_ctx, X509 *cert); int ossl_cmp_mock_srv_set_statusInfo(OSSL_CMP_SRV_CTX *srv_ctx, int status, int fail_info, const char *text); int ossl_cmp_mock_srv_set_sendError(OSSL_CMP_SRV_CTX *srv_ctx, int bodytype); -int ossl_cmp_mock_srv_set_useBadProtection(OSSL_CMP_SRV_CTX *srv_ctx, int bodytype); int ossl_cmp_mock_srv_set_pollCount(OSSL_CMP_SRV_CTX *srv_ctx, int count); int ossl_cmp_mock_srv_set_checkAfterTime(OSSL_CMP_SRV_CTX *srv_ctx, int sec); diff --git a/apps/include/configuration.h.in b/apps/include/configuration.h.in deleted file mode 100644 index 71b6ff434e..0000000000 --- a/apps/include/configuration.h.in +++ /dev/null @@ -1,44 +0,0 @@ -/* - * {- join("\n * ", @autowarntext) -} - * - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#ifndef APPS_CONFIGURATION_H -#define APPS_CONFIGURATION_H - -/* clang-format off */ -{- - my $generate_openssl_disable_array = sub { - my ($key) = @_; - my $data = $config{$key}; - my $res = "static const char * const ${key}[] = {\n"; - - $res .= "\t\"\",\n"; - - if ($data && @$data) { - - foreach (@$data) { - $res .= "\t\"$_\",\n"; - } - } - - $res .= "};\n"; - - return $res; - }; - - $OUT .= $generate_openssl_disable_array->('openssl_disabled_protocols'); - $OUT .= "\n"; - $OUT .= $generate_openssl_disable_array->('openssl_disabled_algorithms'); - $OUT .= "\n"; - $OUT .= $generate_openssl_disable_array->('openssl_disabled_features'); --} -/* clang-format on */ - -#endif diff --git a/apps/include/ec_common.h b/apps/include/ec_common.h index ac160e507f..f5711657a2 100644 --- a/apps/include/ec_common.h +++ b/apps/include/ec_common.h @@ -7,12 +7,7 @@ * https://www.openssl.org/source/license.html */ -#if !defined(APPS_INCLUDE_EC_COMMON_H) -#define APPS_INCLUDE_EC_COMMON_H - #ifndef OPENSSL_NO_EC -#include - static const char *point_format_options[] = { "uncompressed", "compressed", @@ -26,5 +21,3 @@ static const char *asn1_encoding_options[] = { NULL }; #endif - -#endif /* !defined(APPS_INCLUDE_EC_COMMON_H) */ diff --git a/apps/include/names.h b/apps/include/names.h index c2a8c41dd7..bf47459ade 100644 --- a/apps/include/names.h +++ b/apps/include/names.h @@ -7,12 +7,7 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_APPS_INCLUDE_NAMES_H) -#define OSSL_APPS_INCLUDE_NAMES_H - -#include #include -#include /* Standard comparing function for names */ int name_cmp(const char *const *a, const char *const *b); @@ -20,5 +15,3 @@ int name_cmp(const char *const *a, const char *const *b); void collect_names(const char *name, void *vdata); /* Sorts and prints a stack of names to |out| */ void print_names(BIO *out, STACK_OF(OPENSSL_CSTRING) *names); - -#endif /* !defined(OSSL_APPS_INCLUDE_NAMES_H) */ diff --git a/apps/include/opt.h b/apps/include/opt.h index 6b22f89ada..a2facb0252 100644 --- a/apps/include/opt.h +++ b/apps/include/opt.h @@ -39,9 +39,9 @@ { "purpose", OPT_V_PURPOSE, 's', \ "certificate chain purpose" }, \ { "verify_name", OPT_V_VERIFY_NAME, 's', "verification policy name" }, \ - { "verify_depth", OPT_V_VERIFY_DEPTH, 'N', \ + { "verify_depth", OPT_V_VERIFY_DEPTH, 'n', \ "chain depth limit" }, \ - { "auth_level", OPT_V_VERIFY_AUTH_LEVEL, 'N', \ + { "auth_level", OPT_V_VERIFY_AUTH_LEVEL, 'n', \ "chain authentication security level" }, \ { "attime", OPT_V_ATTIME, 'M', "verification epoch time" }, \ { "verify_hostname", OPT_V_VERIFY_HOSTNAME, 's', \ @@ -341,9 +341,8 @@ typedef struct options_st { * value type: * * '-' no value (also the value zero) - * 'n' any number (type 'int') - * 'p' positive number (type 'int', value > 0) - * 'N' is a non-negative number (type 'int', value >= 0) + * 'n' number (type 'int') + * 'p' positive number (type 'int') * 'u' unsigned number (type 'unsigned long') * 'l' number (type 'unsigned long') * 'M' number (type 'intmax_t') @@ -357,7 +356,7 @@ typedef struct options_st { * 'A' any ASN1, der/pem/b64 format [OPT_FMT_ASN1] * 'c' pem/der/smime format [OPT_FMT_PDS] * - * The 'l', 'n', 'N' and 'u' value types include the values zero, + * The 'l', 'n' and 'u' value types include the values zero, * the 'p' value type does not. */ int valtype; diff --git a/apps/include/s_apps.h b/apps/include/s_apps.h index c46f6327e9..c6a9a890c2 100644 --- a/apps/include/s_apps.h +++ b/apps/include/s_apps.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_APPS_INCLUDE_S_APPS_H) -#define OSSL_APPS_INCLUDE_S_APPS_H - #include #include @@ -113,8 +110,5 @@ typedef struct srpsrvparm_st { int set_up_srp_verifier_file(SSL_CTX *ctx, srpsrvparm *srp_callback_parm, char *srpuserseed, char *srp_verifier_file); -void cleanup_srp(srpsrvparm *srp_callback_parm); void lookup_srp_user(srpsrvparm *srp_callback_parm, BIO *bio_s_out); #endif /* OPENSSL_NO_SRP */ - -#endif /* !defined(OSSL_APPS_INCLUDE_S_APPS_H) */ diff --git a/apps/kdf.c b/apps/kdf.c index 7eaa1a19de..dae13c8fcf 100644 --- a/apps/kdf.c +++ b/apps/kdf.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -39,7 +39,7 @@ const OPTIONS kdf_options[] = { { "digest", OPT_DIGEST, 's', "Digest" }, { "mac", OPT_MAC, 's', "MAC" }, { OPT_MORE_STR, 1, '-', "See 'Supported Controls' in the EVP_KDF_ docs\n" }, - { "keylen", OPT_KEYLEN, 'p', "The size of the output derived key" }, + { "keylen", OPT_KEYLEN, 's', "The size of the output derived key" }, OPT_SECTION("Output"), { "out", OPT_OUT, '>', "Output to filename rather than stdout" }, @@ -101,7 +101,7 @@ int kdf_main(int argc, char **argv) out_bin = 1; break; case OPT_KEYLEN: - dkm_len = opt_int_arg(); + dkm_len = atoi(opt_arg()); break; case OPT_OUT: outfile = opt_arg(); @@ -162,7 +162,7 @@ int kdf_main(int argc, char **argv) goto err; if (!EVP_KDF_CTX_set_params(ctx, params)) { - BIO_puts(bio_err, "KDF parameter error\n"); + BIO_printf(bio_err, "KDF parameter error\n"); ERR_print_errors(bio_err); ok = 0; } @@ -176,7 +176,7 @@ int kdf_main(int argc, char **argv) goto err; if (dkm_len <= 0) { - BIO_puts(bio_err, "Derived key length is mandatory!\n"); + BIO_printf(bio_err, "Invalid derived key length.\n"); goto err; } dkm_bytes = app_malloc(dkm_len, "out buffer"); @@ -184,7 +184,7 @@ int kdf_main(int argc, char **argv) goto err; if (!EVP_KDF_derive(ctx, dkm_bytes, dkm_len, NULL)) { - BIO_puts(bio_err, "EVP_KDF_derive failed\n"); + BIO_printf(bio_err, "EVP_KDF_derive failed\n"); goto err; } @@ -193,7 +193,7 @@ int kdf_main(int argc, char **argv) } else { hexout = OPENSSL_buf2hexstr(dkm_bytes, dkm_len); if (hexout == NULL) { - BIO_puts(bio_err, "Memory allocation failure\n"); + BIO_printf(bio_err, "Memory allocation failure\n"); goto err; } BIO_printf(out, "%s\n\n", hexout); diff --git a/apps/lib/app_params.c b/apps/lib/app_params.c index cb569bb0c9..cfd48ebc35 100644 --- a/apps/lib/app_params.c +++ b/apps/lib/app_params.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -56,7 +56,7 @@ static int describe_param_type(char *buf, size_t bufsz, const OSSL_PARAM *param) bufsz -= printed_len; } if (show_type_number) { - printed_len = BIO_snprintf(buf, bufsz, " [%u]", param->data_type); + printed_len = BIO_snprintf(buf, bufsz, " [%d]", param->data_type); if (printed_len > 0) { buf += printed_len; bufsz -= printed_len; @@ -158,13 +158,13 @@ void print_param_value(const OSSL_PARAM *p, int indent) if (OSSL_PARAM_get_uint64(p, &u)) BIO_printf(bio_out, "%llu\n", (unsigned long long int)u); else - BIO_puts(bio_out, "error getting value\n"); + BIO_printf(bio_out, "error getting value\n"); break; case OSSL_PARAM_INTEGER: if (OSSL_PARAM_get_int64(p, &i)) BIO_printf(bio_out, "%lld\n", (long long int)i); else - BIO_puts(bio_out, "error getting value\n"); + BIO_printf(bio_out, "error getting value\n"); break; case OSSL_PARAM_UTF8_PTR: print_param_utf8((const char **)p->data, p->return_size); diff --git a/apps/lib/app_provider.c b/apps/lib/app_provider.c index a245349d13..6986ab4c10 100644 --- a/apps/lib/app_provider.c +++ b/apps/lib/app_provider.c @@ -47,7 +47,6 @@ int app_provider_load(OSSL_LIB_CTX *libctx, const char *provider_name) app_providers = sk_OSSL_PROVIDER_new_null(); if (app_providers == NULL || !sk_OSSL_PROVIDER_push(app_providers, prov)) { - OSSL_PROVIDER_unload(prov); app_providers_cleanup(); return 0; } diff --git a/apps/lib/app_rand.c b/apps/lib/app_rand.c index 7d50feeb77..061211a0b6 100644 --- a/apps/lib/app_rand.c +++ b/apps/lib/app_rand.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -84,7 +84,7 @@ int app_RAND_write(void) if (save_rand_file == NULL) return 1; if (RAND_write_file(save_rand_file) == -1) { - BIO_puts(bio_err, "Cannot write random bytes:\n"); + BIO_printf(bio_err, "Cannot write random bytes:\n"); ERR_print_errors(bio_err); ret = 0; } diff --git a/apps/lib/app_x509.c b/apps/lib/app_x509.c index b396dbef94..11cb3fa342 100644 --- a/apps/lib/app_x509.c +++ b/apps/lib/app_x509.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -25,7 +25,7 @@ static ASN1_OCTET_STRING *mk_octet_string(void *value, size_t value_n) ASN1_OCTET_STRING *v = ASN1_OCTET_STRING_new(); if (v == NULL) { - BIO_puts(bio_err, "error: allocation failed\n"); + BIO_printf(bio_err, "error: allocation failed\n"); } else if (!ASN1_OCTET_STRING_set(v, value, (int)value_n)) { ASN1_OCTET_STRING_free(v); v = NULL; @@ -42,7 +42,7 @@ static int x509_ctrl(void *object, int cmd, void *value, size_t value_n) ASN1_OCTET_STRING *v = mk_octet_string(value, value_n); if (v == NULL) { - BIO_puts(bio_err, + BIO_printf(bio_err, "error: setting distinguishing ID in certificate failed\n"); return 0; } @@ -65,7 +65,7 @@ static int x509_req_ctrl(void *object, int cmd, void *value, size_t value_n) ASN1_OCTET_STRING *v = mk_octet_string(value, value_n); if (v == NULL) { - BIO_puts(bio_err, + BIO_printf(bio_err, "error: setting distinguishing ID in certificate signing request failed\n"); return 0; } diff --git a/apps/lib/apps.c b/apps/lib/apps.c index b44e4b2bef..77c70586ec 100644 --- a/apps/lib/apps.c +++ b/apps/lib/apps.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -39,13 +39,10 @@ #include #include #include -#include -#include #include "s_apps.h" #include "apps.h" #include "internal/sockets.h" /* for openssl_fdset() */ -#include "internal/numbers.h" /* for LONG_MAX */ #include "internal/e_os.h" #ifdef _WIN32 @@ -87,22 +84,6 @@ int app_init(long mesgwin) } #endif -static int maybe_printf(BIO *bio, const char *format, ...) -{ - va_list args; - int ret = 0; - - if (bio != NULL) { - va_start(args, format); - - ret = BIO_vprintf(bio, format, args); - - va_end(args); - } - - return ret; -} - int ctx_set_verify_locations(SSL_CTX *ctx, const char *CAfile, int noCAfile, const char *CApath, int noCApath, @@ -180,7 +161,7 @@ char *get_passwd(const char *pass, const char *desc) if (!app_passwd(pass, NULL, &result, NULL)) BIO_printf(bio_err, "Error getting password for %s\n", desc); if (pass != NULL && result == NULL) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Trying plain input string (better precede with 'pass:')\n"); result = OPENSSL_strdup(pass); if (result == NULL) @@ -203,13 +184,8 @@ int app_passwd(const char *arg1, const char *arg2, char **pass1, char **pass2) } if (arg2 != NULL) { *pass2 = app_get_pass(arg2, same ? 2 : 0); - if (*pass2 == NULL) { - if (pass1 != NULL) { - clear_free(*pass1); - *pass1 = NULL; - } + if (*pass2 == NULL) return 0; - } } else if (pass2 != NULL) { *pass2 = NULL; } @@ -266,7 +242,7 @@ static char *app_get_pass(const char *arg, int keepbio) if (btmp == NULL) { BIO_free_all(pwdbio); pwdbio = NULL; - BIO_puts(bio_err, "Out of memory\n"); + BIO_printf(bio_err, "Out of memory\n"); return NULL; } pwdbio = BIO_push(btmp, pwdbio); @@ -275,20 +251,20 @@ static char *app_get_pass(const char *arg, int keepbio) unbuffer(stdin); pwdbio = dup_bio_in(FORMAT_TEXT); if (pwdbio == NULL) { - BIO_puts(bio_err, "Can't open BIO for stdin\n"); + BIO_printf(bio_err, "Can't open BIO for stdin\n"); return NULL; } } else { /* argument syntax error; do not reveal too much about arg */ - const char *arg_ptr = strchr(arg, ':'); - if (arg_ptr == NULL || arg_ptr - arg > PASS_SOURCE_SIZE_MAX) + tmp = strchr(arg, ':'); + if (tmp == NULL || tmp - arg > PASS_SOURCE_SIZE_MAX) BIO_printf(bio_err, "Invalid password argument, missing ':' within the first %d chars\n", PASS_SOURCE_SIZE_MAX + 1); else BIO_printf(bio_err, "Invalid password argument, starting with \"%.*s\"\n", - (int)(arg_ptr - arg + 1), arg); + (int)(tmp - arg + 1), arg); return NULL; } } @@ -298,7 +274,7 @@ static char *app_get_pass(const char *arg, int keepbio) pwdbio = NULL; } if (i <= 0) { - BIO_puts(bio_err, "Error reading password from BIO\n"); + BIO_printf(bio_err, "Error reading password from BIO\n"); return NULL; } tmp = strchr(tpass, '\n'); @@ -354,7 +330,7 @@ CONF *app_load_config_bio(BIO *in, const char *filename) if (filename != NULL) BIO_printf(bio_err, "config file \"%s\"\n", filename); else - BIO_puts(bio_err, "config input"); + BIO_printf(bio_err, "config input"); NCONF_free(conf); return NULL; @@ -364,7 +340,7 @@ CONF *app_load_config_verbose(const char *filename, int verbose) { if (verbose) { if (*filename == '\0') - BIO_puts(bio_err, "No configuration used\n"); + BIO_printf(bio_err, "No configuration used\n"); else BIO_printf(bio_err, "Using configuration from %s\n", filename); } @@ -398,7 +374,7 @@ int app_load_modules(const CONF *config) return 1; if (CONF_modules_load(config, NULL, 0) <= 0) { - BIO_puts(bio_err, "Error configuring OpenSSL modules\n"); + BIO_printf(bio_err, "Error configuring OpenSSL modules\n"); ERR_print_errors(bio_err); NCONF_free(to_free); return 0; @@ -606,46 +582,20 @@ EVP_PKEY *load_keyparams_suppress(const char *uri, int format, int maybe_stdin, int suppress_decode_errors) { EVP_PKEY *params = NULL; - OSSL_DECODER_CTX *dctx = NULL; - BIO *file_bio = BIO_new_file(uri, "rb"); - OSSL_LIB_CTX *libctx = app_get0_libctx(); - const char *propq = app_get0_propq(); if (desc == NULL) desc = "key parameters"; - /* - * Use the store lookup path for anything that is not DER/ASN1 format - * Or if we are unable to opens the uri as a file. - */ - if (format != FORMAT_ASN1 || file_bio == NULL) { - (void)load_key_certs_crls(uri, format, maybe_stdin, NULL, desc, - suppress_decode_errors, - NULL, NULL, ¶ms, NULL, NULL, NULL, NULL, NULL); - if (params != NULL && keytype != NULL && !EVP_PKEY_is_a(params, keytype)) { - ERR_print_errors(bio_err); - BIO_printf(bio_err, - "Unable to load %s from %s (unexpected parameters type)\n", - desc, uri); - EVP_PKEY_free(params); - params = NULL; - } - } else { - dctx = OSSL_DECODER_CTX_new_for_pkey(¶ms, NULL, NULL, keytype, - OSSL_KEYMGMT_SELECT_ALL_PARAMETERS, - libctx, propq); - if (dctx == NULL) { - ERR_print_errors(bio_err); - BIO_printf(bio_err, "Unable to allocate decoder context\n"); - } else { - if (!OSSL_DECODER_from_bio(dctx, file_bio)) { - ERR_print_errors(bio_err); - BIO_printf(bio_err, "Unable to decode file %s\n", uri); - } - } + (void)load_key_certs_crls(uri, format, maybe_stdin, NULL, desc, + suppress_decode_errors, + NULL, NULL, ¶ms, NULL, NULL, NULL, NULL, NULL); + if (params != NULL && keytype != NULL && !EVP_PKEY_is_a(params, keytype)) { + ERR_print_errors(bio_err); + BIO_printf(bio_err, + "Unable to load %s from %s (unexpected parameters type)\n", + desc, uri); + EVP_PKEY_free(params); + params = NULL; } - - BIO_free(file_bio); - OSSL_DECODER_CTX_free(dctx); return params; } @@ -656,12 +606,12 @@ EVP_PKEY *load_keyparams(const char *uri, int format, int maybe_stdin, } EVP_SKEY *load_skey(const char *uri, int format, int may_stdin, - const char *pass, int quiet) + const char *pass, int quiet) { EVP_SKEY *skey = NULL; (void)load_key_certs_crls(uri, format, may_stdin, pass, NULL, 0, - NULL, NULL, NULL, NULL, NULL, NULL, NULL, &skey); + NULL, NULL, NULL, NULL, NULL, NULL, NULL, &skey); return skey; } @@ -697,19 +647,16 @@ void *app_malloc_array(size_t n, size_t sz, const char *what) return vp; } -char *next_item(char *opt) /* in list separated by comma and/or spaces */ +char *next_item(char *opt) /* in list separated by comma and/or space */ { /* advance to separator (comma or whitespace), if any */ - while (*opt != '\0' && *opt != ',' && !isspace(_UC(*opt))) + while (*opt != ',' && !isspace(_UC(*opt)) && *opt != '\0') opt++; if (*opt != '\0') { - int found_comma = *opt == ','; - /* terminate current item */ *opt++ = '\0'; - /* skip over any further separators, but only one comma */ - while ((!found_comma && (found_comma = (*opt == ','))) - || isspace(_UC(*opt))) + /* skip over any whitespace after separator */ + while (isspace(_UC(*opt))) opt++; } return *opt == '\0' ? NULL : opt; /* NULL indicates end of input */ @@ -727,12 +674,18 @@ static void warn_cert_msg(const char *uri, X509 *cert, const char *msg) static void warn_cert(const char *uri, X509 *cert, int warn_EE, X509_VERIFY_PARAM *vpm) { - int error; uint32_t ex_flags = X509_get_extension_flags(cert); + /* + * This should not be used as as example for how to verify + * certificates. This treats an invalid not before or an invalid + * not after time in the certificate as infinitely valid, which + * you don't want outside of a toy testing function like this. + */ + int res = X509_cmp_timeframe(vpm, X509_get0_notBefore(cert), + X509_get0_notAfter(cert)); - if (!X509_check_certificate_times(vpm, cert, &error)) - warn_cert_msg(uri, cert, X509_verify_cert_error_string(error)); - + if (res != 0) + warn_cert_msg(uri, cert, res > 0 ? "has expired" : "not yet valid"); if (warn_EE && (ex_flags & EXFLAG_V1) == 0 && (ex_flags & EXFLAG_CA) == 0) warn_cert_msg(uri, cert, "is not a CA cert"); } @@ -774,10 +727,9 @@ int load_cert_certs(const char *uri, return ret; } -STACK_OF(X509) *load_certs_multifile(char *files, const char *source, +STACK_OF(X509) *load_certs_multifile(char *files, const char *pass, const char *desc, X509_VERIFY_PARAM *vpm) { - char *pass = get_passwd(source, desc); STACK_OF(X509) *certs = NULL; STACK_OF(X509) *result = sk_X509_new_null(); @@ -798,13 +750,11 @@ STACK_OF(X509) *load_certs_multifile(char *files, const char *source, certs = NULL; files = next; } - clear_free(pass); return result; oom: - BIO_puts(bio_err, "out of memory\n"); + BIO_printf(bio_err, "out of memory\n"); err: - clear_free(pass); OSSL_STACK_OF_X509_free(certs); OSSL_STACK_OF_X509_free(result); return NULL; @@ -832,10 +782,9 @@ static X509_STORE *sk_X509_to_store(X509_STORE *store /* may be NULL */, * Create cert store structure with certificates read from given file(s). * Returns pointer to created X509_STORE on success, NULL on error. */ -X509_STORE *load_certstore(char *input, const char *source, const char *desc, +X509_STORE *load_certstore(char *input, const char *pass, const char *desc, X509_VERIFY_PARAM *vpm) { - char *pass = get_passwd(source, desc); X509_STORE *store = NULL; STACK_OF(X509) *certs = NULL; @@ -845,19 +794,15 @@ X509_STORE *load_certstore(char *input, const char *source, const char *desc, if (!load_cert_certs(input, NULL, &certs, 1, pass, desc, vpm)) { X509_STORE_free(store); - store = NULL; - goto end; + return NULL; } ok = (store = sk_X509_to_store(store, certs)) != NULL; OSSL_STACK_OF_X509_free(certs); certs = NULL; if (!ok) - goto end; + return NULL; input = next; } - -end: - clear_free(pass); return store; } @@ -943,7 +888,7 @@ int load_key_certs_crls(const char *uri, int format, int maybe_stdin, X509_CRL **pcrl, STACK_OF(X509_CRL) **pcrls, EVP_SKEY **pskey) { - PW_CB_DATA uidata = { pass, uri }; + PW_CB_DATA uidata; OSSL_STORE_CTX *ctx = NULL; OSSL_LIB_CTX *libctx = app_get0_libctx(); const char *propq = app_get0_propq(); @@ -978,7 +923,7 @@ int load_key_certs_crls(const char *uri, int format, int maybe_stdin, if (pcerts != NULL) { if (*pcerts == NULL && (*pcerts = sk_X509_new_null()) == NULL) { if (!quiet) - BIO_puts(bio_err, "Out of memory loading"); + BIO_printf(bio_err, "Out of memory loading"); goto end; } /* @@ -992,7 +937,7 @@ int load_key_certs_crls(const char *uri, int format, int maybe_stdin, if (pcrls != NULL) { if (*pcrls == NULL && (*pcrls = sk_X509_CRL_new_null()) == NULL) { if (!quiet) - BIO_puts(bio_err, "Out of memory loading"); + BIO_printf(bio_err, "Out of memory loading"); goto end; } /* @@ -1003,6 +948,9 @@ int load_key_certs_crls(const char *uri, int format, int maybe_stdin, SET_EXPECT(OSSL_STORE_INFO_CRL); } + uidata.password = pass; + uidata.prompt_info = uri; + if ((input_type = format2string(format)) != NULL) { itp[0] = OSSL_PARAM_construct_utf8_string(OSSL_STORE_PARAM_INPUT_TYPE, (char *)input_type, 0); @@ -1015,7 +963,7 @@ int load_key_certs_crls(const char *uri, int format, int maybe_stdin, if (!maybe_stdin) { if (!quiet) - BIO_puts(bio_err, "No filename or uri specified for loading\n"); + BIO_printf(bio_err, "No filename or uri specified for loading\n"); goto end; } uri = ""; @@ -1033,14 +981,14 @@ int load_key_certs_crls(const char *uri, int format, int maybe_stdin, } if (ctx == NULL) { if (!quiet) - BIO_puts(bio_err, "Could not open file or uri for loading"); + BIO_printf(bio_err, "Could not open file or uri for loading"); goto end; } /* expect == 0 means here multiple types of credentials are to be loaded */ if (expect > 0 && !OSSL_STORE_expect(ctx, expect)) { if (!quiet) - BIO_puts(bio_err, "Internal error trying to load"); + BIO_printf(bio_err, "Internal error trying to load"); goto end; } @@ -1100,12 +1048,9 @@ int load_key_certs_crls(const char *uri, int format, int maybe_stdin, if (ok) pcert = NULL; } else if (pcerts != NULL) { - X509 *cert = OSSL_STORE_INFO_get1_CERT(info); - - ok = cert != NULL - && X509_add_cert(*pcerts, cert, X509_ADD_FLAG_DEFAULT); - if (!ok) - X509_free(cert); + ok = X509_add_cert(*pcerts, + OSSL_STORE_INFO_get1_CERT(info), + X509_ADD_FLAG_DEFAULT); } ncerts += ok; break; @@ -1115,11 +1060,7 @@ int load_key_certs_crls(const char *uri, int format, int maybe_stdin, if (ok) pcrl = NULL; } else if (pcrls != NULL) { - X509_CRL *crl = OSSL_STORE_INFO_get1_CRL(info); - - ok = crl != NULL && sk_X509_CRL_push(*pcrls, crl); - if (!ok) - X509_CRL_free(crl); + ok = sk_X509_CRL_push(*pcrls, OSSL_STORE_INFO_get1_CRL(info)); } ncrls += ok; break; @@ -1139,7 +1080,7 @@ int load_key_certs_crls(const char *uri, int format, int maybe_stdin, if (!ok) { failed = OSSL_STORE_INFO_type_string(type); if (!quiet) - BIO_puts(bio_err, "Error reading"); + BIO_printf(bio_err, "Error reading"); break; } } @@ -1157,7 +1098,7 @@ end: pskey = NULL; failed = FAIL_NAME; if (failed != NULL && !quiet) - BIO_puts(bio_err, "Could not find or decode"); + BIO_printf(bio_err, "Could not find"); } if (failed != NULL && !quiet) { @@ -1179,7 +1120,7 @@ end: ERR_pop_to_mark(); ERR_set_mark(); } - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); ERR_print_errors(bio_err); ERR_clear_last_mark(); } else { @@ -1220,112 +1161,6 @@ end: return 1; } -int load_rpk_file(SSL *ssl, const char *file) -{ - BIO *in = BIO_new_file(file, "r"); - char *name = NULL; - char *header = NULL; - unsigned char *buf = NULL; - long buflen; - int ret = 1; - int found = 0; - - if (in == NULL) - return ret; - - ERR_set_mark(); - while (ret != 0) { - PKCS8_PRIV_KEY_INFO *p8; - EVP_PKEY *pkey = NULL; - X509 *cert = NULL; - const unsigned char *p; - int pkey_type = NID_undef; - X509 *(*d2i)(X509 **, const unsigned char **, long); - - OPENSSL_free(name); - OPENSSL_free(header); - OPENSSL_free(buf); - name = header = NULL; - buf = NULL; - - if (!PEM_read_bio(in, &name, &header, &buf, &buflen)) { - if (ERR_GET_REASON(ERR_peek_last_error()) != PEM_R_NO_START_LINE) - ret = 0; - break; - } - p = buf; - -#define WHEN_PEM_X509(name, f) \ - ((d2i = f), \ - (strcmp((name), PEM_STRING_X509) == 0 \ - || strcmp((name), PEM_STRING_X509_OLD) == 0)) - -#define WHEN_PEM_X509_AUX(name, f) \ - ((d2i = f), \ - (strcmp((name), PEM_STRING_X509_TRUSTED) == 0)) - -#define WHEN_PKEY_TYPE(name, str, type) \ - ((pkey_type = type), (strcmp((name), str) == 0)) - - if (strcmp(name, PEM_STRING_PUBLIC) == 0) { - pkey = d2i_PUBKEY(NULL, &p, buflen); - if (p - buf != buflen || pkey == NULL) { - BIO_printf(bio_err, "Error reading %s in %s\n", name, file); - ret = 0; - } else if (!SSL_add_expected_rpk(ssl, pkey)) { - BIO_printf(bio_err, "Error adding RPK from %s in %s\n", name, file); - ret = 0; - } else { - found = 1; - } - EVP_PKEY_free(pkey); - } else if (WHEN_PEM_X509(name, d2i_X509) - || WHEN_PEM_X509_AUX(name, d2i_X509_AUX)) { - cert = d2i(NULL, &p, buflen); - if (p - buf != buflen || cert == NULL) { - BIO_printf(bio_err, "Error reading %s in %s\n", name, file); - ret = 0; - } else if ((pkey = X509_get0_pubkey(cert)) == NULL - || !SSL_add_expected_rpk(ssl, pkey)) { - BIO_printf(bio_err, "Error adding RPK from %s in %s\n", name, file); - ret = 0; - } else { - found = 1; - } - X509_free(cert); - } else if (WHEN_PKEY_TYPE(name, PEM_STRING_PKCS8INF, NID_undef) == 0 - || WHEN_PKEY_TYPE(name, PEM_STRING_RSA, EVP_PKEY_RSA) - || WHEN_PKEY_TYPE(name, PEM_STRING_ECPRIVATEKEY, EVP_PKEY_EC) - || WHEN_PKEY_TYPE(name, PEM_STRING_DSA, EVP_PKEY_DSA)) { - if (pkey_type != NID_undef) { - pkey = d2i_PrivateKey(pkey_type, 0, &p, buflen); - } else { - if ((p8 = d2i_PKCS8_PRIV_KEY_INFO(NULL, &p, buflen)) != NULL) { - pkey = EVP_PKCS82PKEY(p8); - PKCS8_PRIV_KEY_INFO_free(p8); - } - } - if (p - buf != buflen || pkey == NULL) { - BIO_printf(bio_err, "Error reading %s in %s\n", name, file); - ret = 0; - } else if (!SSL_add_expected_rpk(ssl, pkey)) { - BIO_printf(bio_err, "Error adding RPK from %s in %s\n", name, file); - ret = 0; - } else { - found = 1; - } - EVP_PKEY_free(pkey); - } - } - - OPENSSL_free(name); - OPENSSL_free(header); - OPENSSL_free(buf); - ERR_pop_to_mark(); - BIO_free(in); - return found && ret; -} - #define X509V3_EXT_UNKNOWN_MASK (0xfL << 16) #define X509V3_EXT_DEFAULT 0 /* Return error for unknown exts */ #define X509V3_EXT_ERROR_UNKNOWN (1L << 16) /* Print error for unknown exts */ @@ -1437,8 +1272,8 @@ int copy_extensions(X509 *x, X509_REQ *req, int copy_type) exts = X509_REQ_get_extensions(req); for (i = 0; i < sk_X509_EXTENSION_num(exts); i++) { - const X509_EXTENSION *ext = sk_X509_EXTENSION_value(exts, i); - const ASN1_OBJECT *obj = X509_EXTENSION_get_object(ext); + X509_EXTENSION *ext = sk_X509_EXTENSION_value(exts, i); + ASN1_OBJECT *obj = X509_EXTENSION_get_object(ext); int idx = X509_get_ext_by_OBJ(x, obj, -1); /* Does extension exist in target? */ @@ -1528,7 +1363,8 @@ void print_name(BIO *out, const char *title, const X509_NAME *nm) } if (lflags == XN_FLAG_COMPAT) { buf = X509_NAME_oneline(nm, 0, 0); - BIO_printf(out, "%s\n", buf); + BIO_puts(out, buf); + BIO_puts(out, "\n"); OPENSSL_free(buf); } else { if (mline) @@ -1543,7 +1379,7 @@ void print_bignum_var(BIO *out, const BIGNUM *in, const char *var, { BIO_printf(out, " static unsigned char %s_%d[] = {", var, len); if (BN_is_zero(in)) { - BIO_puts(out, "\n 0x00"); + BIO_printf(out, "\n 0x00"); } else { int i, l; @@ -1556,7 +1392,7 @@ void print_bignum_var(BIO *out, const BIGNUM *in, const char *var, BIO_printf(out, "0x%02X", buffer[i]); } } - BIO_puts(out, "\n };\n"); + BIO_printf(out, "\n };\n"); } void print_array(BIO *out, const char *title, int len, const unsigned char *d) @@ -1566,13 +1402,13 @@ void print_array(BIO *out, const char *title, int len, const unsigned char *d) BIO_printf(out, "unsigned char %s[%d] = {", title, len); for (i = 0; i < len; i++) { if ((i % 10) == 0) - BIO_puts(out, "\n "); + BIO_printf(out, "\n "); if (i < len - 1) BIO_printf(out, "0x%02X, ", d[i]); else BIO_printf(out, "0x%02X", d[i]); } - BIO_puts(out, "\n};\n"); + BIO_printf(out, "\n};\n"); } X509_STORE *setup_verify(const char *CAfile, int noCAfile, @@ -1708,7 +1544,7 @@ BIGNUM *load_serial(const char *serialfile, int *exists, int create, ERR_clear_error(); ret = BN_new(); if (ret == NULL) { - BIO_puts(bio_err, "Out of memory\n"); + BIO_printf(bio_err, "Out of memory\n"); } else if (!rand_serial(ret, ai)) { BIO_printf(bio_err, "Error creating random number to store in %s\n", serialfile); @@ -1723,7 +1559,7 @@ BIGNUM *load_serial(const char *serialfile, int *exists, int create, } ret = ASN1_INTEGER_to_BN(ai, NULL); if (ret == NULL) { - BIO_puts(bio_err, "Error converting number from bin to BIGNUM\n"); + BIO_printf(bio_err, "Error converting number from bin to BIGNUM\n"); goto err; } } @@ -1754,7 +1590,7 @@ int save_serial(const char *serialfile, const char *suffix, else j = strlen(serialfile) + strlen(suffix) + 1; if (j >= BSIZE) { - BIO_puts(bio_err, "File name too long\n"); + BIO_printf(bio_err, "File name too long\n"); goto err; } @@ -1773,7 +1609,7 @@ int save_serial(const char *serialfile, const char *suffix, } if ((ai = BN_to_ASN1_INTEGER(serial, NULL)) == NULL) { - BIO_puts(bio_err, "error converting serial to ASN.1 format\n"); + BIO_printf(bio_err, "error converting serial to ASN.1 format\n"); goto err; } i2a_ASN1_INTEGER(out, ai); @@ -1802,7 +1638,7 @@ int rotate_serial(const char *serialfile, const char *new_suffix, if (i > j) j = i; if (j + 1 >= BSIZE) { - BIO_puts(bio_err, "File name too long\n"); + BIO_printf(bio_err, "File name too long\n"); goto err; } #ifndef OPENSSL_SYS_VMS @@ -1876,18 +1712,11 @@ CA_DB *load_index(const char *dbfile, DB_ATTR *db_attr) goto err; #ifndef OPENSSL_NO_POSIX_IO - if (BIO_get_fp(in, &dbfp) > 0 && dbfp != NULL) { - if (fstat(fileno(dbfp), &dbst) == -1) { - ERR_raise_data(ERR_LIB_SYS, errno, - "calling fstat(%s)", dbfile); - goto err; - } - } else { - if (stat(dbfile, &dbst) == -1) { - ERR_raise_data(ERR_LIB_SYS, errno, - "calling stat(%s)", dbfile); - goto err; - } + BIO_get_fp(in, &dbfp); + if (fstat(fileno(dbfp), &dbst) == -1) { + ERR_raise_data(ERR_LIB_SYS, errno, + "calling fstat(%s)", dbfile); + goto err; } #endif @@ -1917,14 +1746,8 @@ CA_DB *load_index(const char *dbfile, DB_ATTR *db_attr) } retdb->dbfname = OPENSSL_strdup(dbfile); - if (retdb->dbfname == NULL) { - TXT_DB_free(retdb->db); - retdb->db = NULL; - OPENSSL_free(retdb); - retdb = NULL; - ERR_raise_data(ERR_LIB_SYS, errno, "Out of memory while copying filename: %s", dbfile); + if (retdb->dbfname == NULL) goto err; - } #ifndef OPENSSL_NO_POSIX_IO retdb->dbst = dbst; @@ -1974,7 +1797,7 @@ int save_index(const char *dbfile, const char *suffix, CA_DB *db) j = (int)(strlen(dbfile) + strlen(suffix)); if (j + 6 >= BSIZE) { - BIO_puts(bio_err, "File name too long\n"); + BIO_printf(bio_err, "File name too long\n"); goto err; } #ifndef OPENSSL_SYS_VMS @@ -2024,7 +1847,7 @@ int rotate_index(const char *dbfile, const char *new_suffix, if (i > j) j = i; if (j + 6 >= BSIZE) { - BIO_puts(bio_err, "File name too long\n"); + BIO_printf(bio_err, "File name too long\n"); goto err; } #ifndef OPENSSL_SYS_VMS @@ -2224,111 +2047,46 @@ err: } /* - * Read whole contents of a BIO into an allocated memory buffer. - * The return value is one on success, zero on error. - * If `maxlen` is non-zero, at most `maxlen` bytes are returned, or else, if - * the input is longer than `maxlen`, an error is returned. - * If `maxlen` is zero, the limit is effectively `SIZE_MAX`. + * Read whole contents of a BIO into an allocated memory buffer and return + * it. */ -int bio_to_mem(unsigned char **out, size_t *outlen, size_t maxlen, BIO *in) + +int bio_to_mem(unsigned char **out, int maxlen, BIO *in) { - unsigned char tbuf[4096]; BIO *mem; - BUF_MEM *bufm; - size_t sz = 0; - int len; + int len, ret; + unsigned char tbuf[1024]; mem = BIO_new(BIO_s_mem()); if (mem == NULL) - return 0; + return -1; for (;;) { - if ((len = BIO_read(in, tbuf, 4096)) == 0) - break; - if (len < 0 - || BIO_write(mem, tbuf, len) != len - || sz > SIZE_MAX - len - || ((sz += len) > maxlen && maxlen != 0)) { + if ((maxlen != -1) && maxlen < 1024) + len = maxlen; + else + len = 1024; + len = BIO_read(in, tbuf, len); + if (len < 0) { BIO_free(mem); - return 0; + return -1; } - } + if (len == 0) + break; + if (BIO_write(mem, tbuf, len) != len) { + BIO_free(mem); + return -1; + } + if (maxlen != -1) + maxlen -= len; - /* So BIO_free orphans BUF_MEM */ - (void)BIO_set_close(mem, BIO_NOCLOSE); - BIO_get_mem_ptr(mem, &bufm); + if (maxlen == 0) + break; + } + ret = BIO_get_mem_data(mem, (char **)out); + BIO_set_flags(mem, BIO_FLAGS_MEM_RDONLY); BIO_free(mem); - *out = (unsigned char *)bufm->data; - *outlen = bufm->length; - /* Tell BUF_MEM to orphan data */ - bufm->data = NULL; - BUF_MEM_free(bufm); - return 1; -} - -#if defined(OPENSSL_SYS_UNIX) && defined(_POSIX_MAPPED_FILES) && _POSIX_MAPPED_FILES > 0 -int app_mmap_file(const char *path, BIO *err_bio, size_t known_size, - const unsigned char **out_data, size_t *out_size) -{ - struct stat st; - size_t filesize; - int fd; - int ret = -1; - void *p; - - *out_data = NULL; - *out_size = 0; - - if (known_size == 0) - return 0; - - fd = open(path, O_RDONLY); - if (fd < 0) { - BIO_puts(err_bio, "Error opening file for memory mapping\n"); - return -1; - } - - if (known_size == (size_t)-1) { - if (fstat(fd, &st) != 0 || st.st_size < 0) { - BIO_printf(err_bio, "Error: failed to get size of file '%s'\n", path); - goto err; - } - if (!S_ISREG(st.st_mode)) { - /* - * mmap() is only for regular files. Directories and other non-regular - * paths can report st_size == 0; do not treat those like empty files - * and fall back to the buffer path in callers. - */ - BIO_puts(err_bio, "Error: failed to use memory-mapped file\n"); - goto err; - } - filesize = (size_t)st.st_size; - if ((off_t)filesize != st.st_size) { - BIO_puts(err_bio, "Error: failed to convert file size, likely too big\n"); - goto err; - } - if (filesize == 0) { - ret = 0; - goto err; - } - } else { - filesize = known_size; - } - - p = mmap(NULL, filesize, PROT_READ, MAP_PRIVATE, fd, 0); - (void)close(fd); - if (p == MAP_FAILED) { - BIO_puts(err_bio, "Error: failed to use memory-mapped file\n"); - return -1; - } - *out_data = (const unsigned char *)p; - *out_size = filesize; - return 1; - -err: - close(fd); return ret; } -#endif int pkey_ctrl_string(EVP_PKEY_CTX *ctx, const char *value) { @@ -2351,69 +2109,6 @@ err: return rv; } -static int -encoder_ctrl_string(OSSL_ENCODER_CTX *ctx, const char *value) -{ - int rv = 0; - char *stmp, *vtmp = NULL; - - stmp = OPENSSL_strdup(value); - if (stmp == NULL) - return -1; - vtmp = strchr(stmp, ':'); - if (vtmp == NULL) { - BIO_printf(bio_err, - "Missing encoder option value: %s\n", value); - goto end; - } - - *vtmp = 0; - vtmp++; - rv = OSSL_ENCODER_CTX_ctrl_string(ctx, stmp, vtmp); - -end: - OPENSSL_free(stmp); - return rv; -} - -int encode_private_key(BIO *out, const char *output_type, const EVP_PKEY *pkey, - const STACK_OF(OPENSSL_STRING) *encopt, - const EVP_CIPHER *cipher, const char *pass) -{ - int ret = 0; - OSSL_ENCODER_CTX *ectx = OSSL_ENCODER_CTX_new_for_pkey(pkey, EVP_PKEY_PRIVATE_KEY, - output_type, "PrivateKeyInfo", NULL); - - if (ectx == NULL) - return 0; - - if (cipher != NULL) { - if (!OSSL_ENCODER_CTX_set_cipher(ectx, EVP_CIPHER_get0_name(cipher), NULL)) - goto end; - OSSL_ENCODER_CTX_set_passphrase_ui(ectx, get_ui_method(), NULL); - if (pass != NULL - && !OSSL_ENCODER_CTX_set_passphrase(ectx, - (const unsigned char *)pass, strlen(pass))) - goto end; - } - - if (encopt != NULL) { - int i, n = sk_OPENSSL_STRING_num(encopt); - - for (i = 0; i < n; ++i) { - const char *opt = sk_OPENSSL_STRING_value(encopt, i); - - if (encoder_ctrl_string(ectx, opt) <= 0) - goto end; - } - } - - ret = OSSL_ENCODER_to_bio(ectx, out); -end: - OSSL_ENCODER_CTX_free(ectx); - return ret; -} - static void nodes_print(const char *name, STACK_OF(X509_POLICY_NODE) *nodes) { X509_POLICY_NODE *node; @@ -2503,132 +2198,42 @@ unsigned char *next_protos_parse(size_t *outlen, const char *in) return out; } -int check_cert_might_be_valid(BIO *bio, BIO *b_err, X509 *x, const char *checkhost, - const char *checkemail, const char *checkip) +int check_cert_attributes(BIO *bio, X509 *x, const char *checkhost, + const char *checkemail, const char *checkip, + int print) { - int ret = 0; - int error; - X509_STORE_CTX *ctx = NULL; - X509_STORE *store = NULL; - X509_VERIFY_PARAM *vpm = NULL; + int valid_host = 0; + int valid_mail = 0; + int valid_ip = 0; + int ret = 1; - if (x == NULL) { - maybe_printf(b_err, "Internal error, NULL certificate\n"); - goto err; + if (x == NULL) + return 0; + + if (checkhost != NULL) { + valid_host = X509_check_host(x, checkhost, 0, 0, NULL); + if (print) + BIO_printf(bio, "Hostname %s does%s match certificate\n", + checkhost, valid_host == 1 ? "" : " NOT"); + ret = ret && valid_host > 0; } - if ((store = X509_STORE_new()) == NULL) { - maybe_printf(b_err, "Malloc failed or internal error\n"); - goto err; + if (checkemail != NULL) { + valid_mail = X509_check_email(x, checkemail, 0, 0); + if (print) + BIO_printf(bio, "Email %s does%s match certificate\n", + checkemail, valid_mail ? "" : " NOT"); + ret = ret && valid_mail > 0; } - if (!X509_STORE_add_cert(store, x)) { - maybe_printf(b_err, "Malloc failed or internal error\n"); - goto err; + if (checkip != NULL) { + valid_ip = X509_check_ip_asc(x, checkip, 0); + if (print) + BIO_printf(bio, "IP %s does%s match certificate\n", + checkip, valid_ip ? "" : " NOT"); + ret = ret && valid_ip > 0; } - if ((vpm = X509_STORE_get0_param(store)) == NULL) { - maybe_printf(b_err, "Malloc failed or internal error\n"); - goto err; - } - - if ((ctx = X509_STORE_CTX_new()) == NULL) { - maybe_printf(b_err, "Malloc failed or internal error\n"); - goto err; - } - - /* - * As this is "might verify": - * - * We don't care about the verification time. - * We are trusting ourselves. - * We are very liberal in what we allow. - * - * Needless to say these flags should normally not be used in a - * for real verification. - */ - X509_VERIFY_PARAM_set_flags(vpm, X509_V_FLAG_NO_CHECK_TIME); - X509_VERIFY_PARAM_set_flags(vpm, X509_V_FLAG_PARTIAL_CHAIN); - X509_VERIFY_PARAM_set_flags(vpm, X509_V_FLAG_IGNORE_CRITICAL); - X509_VERIFY_PARAM_set_flags(vpm, X509_V_FLAG_ALLOW_PROXY_CERTS); - X509_VERIFY_PARAM_set_trust(vpm, X509_TRUST_OK_ANY_EKU); - - if (!X509_VERIFY_PARAM_set1_ip_asc(vpm, checkip)) { - maybe_printf(b_err, "Invalid IP address: %s\n", checkip); - goto err; - } - - if (!X509_VERIFY_PARAM_set1_host(vpm, checkhost, 0)) { - maybe_printf(b_err, "Invalid host name: %s\n", checkhost); - goto err; - } - - if (!X509_VERIFY_PARAM_set1_email(vpm, checkemail, 0)) { - maybe_printf(b_err, "Invalid email address: %s\n", checkemail); - goto err; - } - - if (!X509_VERIFY_PARAM_set1_ip_asc(vpm, checkip)) { - maybe_printf(b_err, "Invalid IP address: %s\n", checkip); - goto err; - } - - if (!X509_STORE_CTX_init(ctx, store, x, NULL)) { - maybe_printf(b_err, "Malloc failed or internal error\n"); - goto err; - } - - /* We might be verifying for ANY purpose ... */ - if (!X509_STORE_CTX_set_purpose(ctx, X509_PURPOSE_ANY)) { - maybe_printf(b_err, "Malloc failed or internal error\n"); - goto err; - } - - ret = X509_verify_cert(ctx); - error = X509_STORE_CTX_get_error(ctx); - if (!ret) { - - maybe_printf(bio, "Certificate may not verify: error %s\n", - X509_verify_cert_error_string(error)); - - if (checkhost != NULL && error == X509_V_ERR_HOSTNAME_MISMATCH) - maybe_printf(bio, "Hostname %s does NOT match certificate\n", - checkhost); - else if (checkemail != NULL && error == X509_V_ERR_EMAIL_MISMATCH) - maybe_printf(bio, "Email %s does NOT match certificate\n", - checkemail); - else if (checkip != NULL && error == X509_V_ERR_IP_ADDRESS_MISMATCH) - maybe_printf(bio, "IP %s does NOT match certificate\n", - checkip); - else { - /* Originally, we only cared about the above failures */ - /* - * Suppress trust rejection errors, we don't care, because - * we don't really know what this might be used for if - * this was for real. - */ - if (error == X509_V_ERR_CERT_REJECTED) { - maybe_printf(bio, "Ignoring certificate rejection error\n"); - ret = 1; - } - } - } else { - if (checkhost != NULL) - maybe_printf(bio, "Hostname %s does match certificate\n", - checkhost); - if (checkemail != NULL) - maybe_printf(bio, "Email %s does match certificate\n", - checkemail); - if (checkip != NULL) - maybe_printf(bio, "IP %s does match certificate\n", - checkip); - } - X509_STORE_CTX_cleanup(ctx); - -err: - ERR_print_errors(b_err); - X509_STORE_free(store); - X509_STORE_CTX_free(ctx); return ret; } @@ -2715,24 +2320,32 @@ static int do_sign_init(EVP_MD_CTX *ctx, EVP_PKEY *pkey, && do_pkey_ctx_init(pkctx, sigopts); } -int do_EXT_add_nconf(CONF *conf1, CONF *conf2, X509V3_CTX *ctx, - X509 *cert, const char *msg, const char *sect) +static int adapt_keyid_ext(X509 *cert, X509V3_CTX *ext_ctx, + const char *name, const char *value, int add_default) { - X509V3_set_nconf(ctx, conf1); - if (X509V3_EXT_add_nconf(conf2, ctx, sect != NULL ? sect : "default", cert)) - return 1; - BIO_printf(bio_err, msg, sect); - return 0; -} + const STACK_OF(X509_EXTENSION) *exts = X509_get0_extensions(cert); + X509_EXTENSION *new_ext = X509V3_EXT_nconf(NULL, ext_ctx, name, value); + int idx, rv = 0; -int do_EXT_REQ_add_nconf(CONF *conf1, CONF *conf2, X509V3_CTX *ctx, - X509_REQ *req, const char *msg, const char *sect) -{ - X509V3_set_nconf(ctx, conf1); - if (X509V3_EXT_REQ_add_nconf(conf2, ctx, sect, req)) - return 1; - BIO_printf(bio_err, msg, sect); - return 0; + if (new_ext == NULL) + return rv; + + idx = X509v3_get_ext_by_OBJ(exts, X509_EXTENSION_get_object(new_ext), -1); + if (idx >= 0) { + X509_EXTENSION *found_ext = X509v3_get_ext(exts, idx); + ASN1_OCTET_STRING *encoded = X509_EXTENSION_get_data(found_ext); + int disabled = ASN1_STRING_length(encoded) <= 2; /* indicating "none" */ + + if (disabled) { + X509_delete_ext(cert, idx); + X509_EXTENSION_free(found_ext); + } /* else keep existing key identifier, which might be outdated */ + rv = 1; + } else { + rv = !add_default || X509_add_ext(cert, new_ext, -1); + } + X509_EXTENSION_free(new_ext); + return rv; } int cert_matches_key(const X509 *cert, const EVP_PKEY *pkey) @@ -2749,14 +2362,32 @@ int cert_matches_key(const X509 *cert, const EVP_PKEY *pkey) int do_X509_sign(X509 *cert, int force_v1, EVP_PKEY *pkey, const char *md, STACK_OF(OPENSSL_STRING) *sigopts, X509V3_CTX *ext_ctx) { - EVP_MD_CTX *mctx; + EVP_MD_CTX *mctx = EVP_MD_CTX_new(); + int self_sign; int rv = 0; - if (!force_v1 && !X509_set_version(cert, X509_VERSION_3)) - return 0; - if ((mctx = EVP_MD_CTX_new()) != NULL - && do_sign_init(mctx, pkey, md, sigopts) > 0) + if (!force_v1) { + if (!X509_set_version(cert, X509_VERSION_3)) + goto end; + + /* + * Add default SKID before AKID such that AKID can make use of it + * in case the certificate is self-signed + */ + /* Prevent X509_V_ERR_MISSING_SUBJECT_KEY_IDENTIFIER */ + if (!adapt_keyid_ext(cert, ext_ctx, "subjectKeyIdentifier", "hash", 1)) + goto end; + /* Prevent X509_V_ERR_MISSING_AUTHORITY_KEY_IDENTIFIER */ + self_sign = cert_matches_key(cert, pkey); + if (!adapt_keyid_ext(cert, ext_ctx, "authorityKeyIdentifier", + "keyid, issuer", !self_sign)) + goto end; + } + /* May add further measures for ensuring RFC 5280 compliance, see #19805 */ + + if (mctx != NULL && do_sign_init(mctx, pkey, md, sigopts) > 0) rv = (X509_sign_ctx(cert, mctx) > 0); +end: EVP_MD_CTX_free(mctx); return rv; } @@ -2833,7 +2464,7 @@ static const char *get_dp_url(DIST_POINT *dp) for (i = 0; i < sk_GENERAL_NAME_num(gens); i++) { gen = sk_GENERAL_NAME_value(gens, i); uri = GENERAL_NAME_get0_value(gen, >ype); - if (gtype == GEN_URI && ASN1_STRING_length_ex(uri) > 6) { + if (gtype == GEN_URI && ASN1_STRING_length(uri) > 6) { const char *uptr = (const char *)ASN1_STRING_get0_data(uri); if (IS_HTTP(uptr)) /* can/should not use HTTPS here */ @@ -2871,7 +2502,7 @@ static X509_CRL *load_crl_crldp(STACK_OF(DIST_POINT) *crldp) static STACK_OF(X509_CRL) *crls_http_cb(const X509_STORE_CTX *ctx, const X509_NAME *nm) { - const X509 *x; + X509 *x; STACK_OF(X509_CRL) *crls = NULL; X509_CRL *crl; STACK_OF(DIST_POINT) *crldp; @@ -2899,7 +2530,7 @@ static STACK_OF(X509_CRL) *crls_http_cb(const X509_STORE_CTX *ctx, error: X509_CRL_free(crl); - sk_X509_CRL_pop_free(crls, X509_CRL_free); + sk_X509_CRL_free(crls); return NULL; } @@ -2908,34 +2539,6 @@ void store_setup_crl_download(X509_STORE *st) X509_STORE_set_lookup_crls_cb(st, crls_http_cb); } -int host_is_ip_address(const char *host) -{ -#ifndef INET6_ADDRSTRLEN /* not defined on OPENSSL_NO_SOCK */ -#define INET6_ADDRSTRLEN 46 -#endif - char stripped_host_ipv6[INET6_ADDRSTRLEN + 1]; - ASN1_OCTET_STRING *str; - int ret; - - if (host == NULL) - return 0; - - if (host[0] == '[') { /* OSSL_parse_url() returns IPv6 addresses enclosed in [ and ] */ - size_t len = strlen(++host); - if (len == 0 || len > sizeof(stripped_host_ipv6) || host[--len] != ']') - return 0; - strncpy(stripped_host_ipv6, host, sizeof(stripped_host_ipv6)); - stripped_host_ipv6[len] = '\0'; - host = stripped_host_ipv6; - } - ERR_set_mark(); - str = a2i_IPADDRESS(host); - ret = str != NULL; - ERR_pop_to_mark(); - ASN1_OCTET_STRING_free(str); - return ret; -} - #if !defined(OPENSSL_NO_SOCK) && !defined(OPENSSL_NO_HTTP) static const char *tls_error_hint(void) { @@ -2985,12 +2588,15 @@ BIO *app_http_tls_cb(BIO *bio, void *arg, int connect, int detail) { APP_HTTP_TLS_INFO *info = (APP_HTTP_TLS_INFO *)arg; SSL_CTX *ssl_ctx = info->ssl_ctx; - BIO *sbio = NULL; if (ssl_ctx == NULL) /* not using TLS */ return bio; if (connect) { SSL *ssl; + BIO *sbio = NULL; + X509_STORE *ts = SSL_CTX_get_cert_store(ssl_ctx); + X509_VERIFY_PARAM *vpm = X509_STORE_get0_param(ts); + const char *host = vpm == NULL ? NULL : X509_VERIFY_PARAM_get0_host(vpm, 0 /* first hostname */); /* adapt after fixing callback design flaw, see #17088 */ if ((info->use_proxy @@ -3000,35 +2606,27 @@ BIO *app_http_tls_cb(BIO *bio, void *arg, int connect, int detail) || (sbio = BIO_new(BIO_f_ssl())) == NULL) { return NULL; } - if ((ssl = SSL_new(ssl_ctx)) == NULL) - goto err; + if ((ssl = SSL_new(ssl_ctx)) == NULL) { + BIO_free(sbio); + return NULL; + } + + if (vpm != NULL) + SSL_set_tlsext_host_name(ssl, host /* may be NULL */); SSL_set_connect_state(ssl); - if (BIO_set_ssl(sbio, ssl, BIO_CLOSE) <= 0) { - SSL_free(ssl); - goto err; - } - if (!host_is_ip_address(info->server)) { - if (!SSL_set_tlsext_host_name(ssl, info->server)) /* set SNI */ - goto err; - } + BIO_set_ssl(sbio, ssl, BIO_CLOSE); bio = BIO_push(sbio, bio); } else { /* disconnect from TLS */ bio = http_tls_shutdown(bio); } return bio; - -err: - BIO_free(sbio); - return NULL; } void APP_HTTP_TLS_INFO_free(APP_HTTP_TLS_INFO *info) { if (info != NULL) { - OPENSSL_free((char *)info->server); - OPENSSL_free((char *)info->port); SSL_CTX_free(info->ssl_ctx); OPENSSL_free(info); } @@ -3151,10 +2749,14 @@ static int WIN32_rename(const char *from, const char *to) if (tfrom == NULL) goto err; tto = tfrom + flen; +#if !defined(_WIN32_WCE) || _WIN32_WCE >= 101 if (!MultiByteToWideChar(CP_ACP, 0, from, (int)flen, (WCHAR *)tfrom, (int)flen)) +#endif for (i = 0; i < flen; i++) tfrom[i] = (TCHAR)from[i]; +#if !defined(_WIN32_WCE) || _WIN32_WCE >= 101 if (!MultiByteToWideChar(CP_ACP, 0, to, (int)tlen, (WCHAR *)tto, (int)tlen)) +#endif for (i = 0; i < tlen; i++) tto[i] = (TCHAR)to[i]; } @@ -3213,8 +2815,8 @@ double app_tminterval(int stop, int usertime) SYSTEMTIME systime; if (usertime && warning) { - BIO_puts(bio_err, "To get meaningful results, run " - "this program on idle system.\n"); + BIO_printf(bio_err, "To get meaningful results, run " + "this program on idle system.\n"); warning = 0; } GetSystemTime(&systime); @@ -3251,8 +2853,8 @@ double app_tminterval(int stop, int usertime) static int warning = 1; if (usertime && warning) { - BIO_puts(bio_err, "To get meaningful results, run " - "this program on idle system.\n"); + BIO_printf(bio_err, "To get meaningful results, run " + "this program on idle system.\n"); warning = 0; } #ifdef CLOCK_REALTIME @@ -3715,23 +3317,12 @@ int has_stdin_waiting(void) } #endif -/* - * Corrupt a signature by modifying final byte - * (mutates signature) - */ -int corrupt_signature(ASN1_STRING *signature) +/* Corrupt a signature by modifying final byte */ +void corrupt_signature(const ASN1_STRING *signature) { - const unsigned char *valid = ASN1_STRING_get0_data(signature); - size_t length = ASN1_STRING_length_ex(signature); - unsigned char *s = OPENSSL_memdup(valid, length); + unsigned char *s = signature->data; - if (s == NULL) - return 0; - - s[length - 1] ^= 0x1; - - ASN1_STRING_set0(signature, s, (int)length); - return 1; + s[signature->length - 1] ^= 0x1; } int check_cert_time_string(const char *time, const char *desc) @@ -3754,12 +3345,12 @@ int set_cert_times(X509 *x, const char *startdate, const char *enddate, return 0; if (startdate == NULL || strcmp(startdate, "today") == 0) { if (X509_gmtime_adj(X509_getm_notBefore(x), 0) == NULL) { - BIO_puts(bio_err, "Error setting notBefore certificate field\n"); + BIO_printf(bio_err, "Error setting notBefore certificate field\n"); return 0; } } else { if (!ASN1_TIME_set_string_X509(X509_getm_notBefore(x), startdate)) { - BIO_puts(bio_err, "Error setting notBefore certificate field\n"); + BIO_printf(bio_err, "Error setting notBefore certificate field\n"); return 0; } } @@ -3769,11 +3360,11 @@ int set_cert_times(X509 *x, const char *startdate, const char *enddate, } if (enddate == NULL) { if (X509_time_adj_ex(X509_getm_notAfter(x), days, 0, NULL) == NULL) { - BIO_puts(bio_err, "Error setting notAfter certificate field\n"); + BIO_printf(bio_err, "Error setting notAfter certificate field\n"); return 0; } } else if (!ASN1_TIME_set_string_X509(X509_getm_notAfter(x), enddate)) { - BIO_puts(bio_err, "Error setting notAfter certificate field\n"); + BIO_printf(bio_err, "Error setting notAfter certificate field\n"); return 0; } if (ASN1_TIME_compare(X509_get0_notAfter(x), X509_get0_notBefore(x)) < 0) { @@ -3905,11 +3496,11 @@ EVP_PKEY *app_keygen(EVP_PKEY_CTX *ctx, const char *alg, int bits, int verbose) if (bits > 0) BIO_printf(bio_err, " with %d bits\n", bits); else - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); } if (!RAND_status()) - BIO_puts(bio_err, "Warning: generating random key material may take a long time\n" - "if the system has a poor entropy source\n"); + BIO_printf(bio_err, "Warning: generating random key material may take a long time\n" + "if the system has a poor entropy source\n"); if (EVP_PKEY_keygen(ctx, &res) <= 0) BIO_printf(bio_err, "%s: Error generating %s key\n", opt_getprog(), alg != NULL ? alg : "asymmetric"); @@ -3921,8 +3512,8 @@ EVP_PKEY *app_paramgen(EVP_PKEY_CTX *ctx, const char *alg) EVP_PKEY *res = NULL; if (!RAND_status()) - BIO_puts(bio_err, "Warning: generating random key parameters may take a long time\n" - "if the system has a poor entropy source\n"); + BIO_printf(bio_err, "Warning: generating random key parameters may take a long time\n" + "if the system has a poor entropy source\n"); if (EVP_PKEY_paramgen(ctx, &res) <= 0) BIO_printf(bio_err, "%s: Generating %s key parameters failed\n", opt_getprog(), alg != NULL ? alg : "asymmetric"); @@ -4075,7 +3666,6 @@ char *get_str_from_file(const char *filename) bio = NULL; if (n <= 0) { BIO_printf(bio_err, "Error reading from %s\n", filename); - OPENSSL_clear_free(buf, MAX_KEY_SIZE); return NULL; } tmp = strchr(buf, '\n'); diff --git a/apps/lib/apps_ui.c b/apps/lib/apps_ui.c index 6388dae617..ecfa25e076 100644 --- a/apps/lib/apps_ui.c +++ b/apps/lib/apps_ui.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -171,7 +171,7 @@ int password_callback(char *buf, int bufsiz, int verify, PW_CB_DATA *cb_data) prompt_info = cb_data->prompt_info; prompt = UI_construct_prompt(ui, "pass phrase", prompt_info); if (prompt == NULL) { - BIO_puts(bio_err, "Out of memory\n"); + BIO_printf(bio_err, "Out of memory\n"); UI_free(ui); return 0; } @@ -200,13 +200,13 @@ int password_callback(char *buf, int bufsiz, int verify, PW_CB_DATA *cb_data) if (ok >= 0) res = (int)strlen(buf); if (ok == -1) { - BIO_puts(bio_err, "User interface error\n"); + BIO_printf(bio_err, "User interface error\n"); ERR_print_errors(bio_err); OPENSSL_cleanse(buf, (unsigned int)bufsiz); res = 0; } if (ok == -2) { - BIO_puts(bio_err, "aborted!\n"); + BIO_printf(bio_err, "aborted!\n"); OPENSSL_cleanse(buf, (unsigned int)bufsiz); res = 0; } diff --git a/apps/lib/cmp_mock_srv.c b/apps/lib/cmp_mock_srv.c index 825a2b6709..bf8b06c390 100644 --- a/apps/lib/cmp_mock_srv.c +++ b/apps/lib/cmp_mock_srv.c @@ -1,5 +1,5 @@ /* - * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2018-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright Siemens AG 2018-2020 * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -10,7 +10,6 @@ #include "apps.h" #include "cmp_mock_srv.h" -#include "../../crypto/cmp/cmp_local.h" /* for access to msg->protection */ #include #include @@ -29,7 +28,6 @@ typedef struct { X509 *oldWithNew; /* to return in oldWithNew of rootKeyUpdate */ OSSL_CMP_PKISI *statusOut; /* status for ip/cp/kup/rp msg unless polling */ int sendError; /* send error response on given request type */ - int useBadProtection; /* use bad protection on given response type */ OSSL_CMP_MSG *req; /* original request message during polling */ int pollCount; /* number of polls before actual cert response */ int curr_pollCount; /* number of polls so far for current request */ @@ -61,7 +59,6 @@ static mock_srv_ctx *mock_srv_ctx_new(void) goto err; ctx->sendError = -1; - ctx->useBadProtection = -1; /* all other elements are initialized to 0 or NULL, respectively */ return ctx; @@ -190,19 +187,6 @@ int ossl_cmp_mock_srv_set_sendError(OSSL_CMP_SRV_CTX *srv_ctx, int bodytype) return 1; } -int ossl_cmp_mock_srv_set_useBadProtection(OSSL_CMP_SRV_CTX *srv_ctx, int bodytype) -{ - mock_srv_ctx *ctx = OSSL_CMP_SRV_CTX_get0_custom_ctx(srv_ctx); - - if (ctx == NULL) { - ERR_raise(ERR_LIB_CMP, CMP_R_NULL_ARGUMENT); - return 0; - } - /* might check bodytype, but this would require exporting all body types */ - ctx->useBadProtection = bodytype; - return 1; -} - int ossl_cmp_mock_srv_set_pollCount(OSSL_CMP_SRV_CTX *srv_ctx, int count) { mock_srv_ctx *ctx = OSSL_CMP_SRV_CTX_get0_custom_ctx(srv_ctx); @@ -345,7 +329,6 @@ static OSSL_CMP_PKISI *process_cert_request(OSSL_CMP_SRV_CTX *srv_ctx, STACK_OF(ASN1_UTF8STRING) *strs; ASN1_UTF8STRING *str; const char *data; - size_t len; if (OBJ_obj2nid(obj) == NID_id_it_certProfile) { if (!OSSL_CMP_ITAV_get0_certProfile(itav, &strs)) @@ -360,8 +343,7 @@ static OSSL_CMP_PKISI *process_cert_request(OSSL_CMP_SRV_CTX *srv_ctx, ERR_raise(ERR_LIB_CMP, ERR_R_PASSED_INVALID_ARGUMENT); return NULL; } - if (((len = ASN1_STRING_length_ex(str)) != sizeof("profile1") - 1) - || memcmp(data, "profile1", len) != 0) { + if (strcmp(data, "profile1") != 0) { ERR_raise(ERR_LIB_CMP, CMP_R_UNEXPECTED_CERTPROFILE); return NULL; } @@ -609,7 +591,6 @@ static int process_genm(OSSL_CMP_SRV_CTX *srv_ctx, if (rsp != NULL && sk_OSSL_CMP_ITAV_push(*out, rsp)) return 1; sk_OSSL_CMP_ITAV_free(*out); - OSSL_CMP_ITAV_free(rsp); return 0; } @@ -633,10 +614,10 @@ static void process_error(OSSL_CMP_SRV_CTX *srv_ctx, const OSSL_CMP_MSG *error, return; } - BIO_puts(bio_err, "mock server received error:\n"); + BIO_printf(bio_err, "mock server received error:\n"); if (statusInfo == NULL) { - BIO_puts(bio_err, "pkiStatusInfo absent\n"); + BIO_printf(bio_err, "pkiStatusInfo absent\n"); } else { sibuf = OSSL_CMP_snprint_PKIStatusInfo(statusInfo, buf, sizeof(buf)); BIO_printf(bio_err, "pkiStatusInfo: %s\n", @@ -644,22 +625,22 @@ static void process_error(OSSL_CMP_SRV_CTX *srv_ctx, const OSSL_CMP_MSG *error, } if (errorCode == NULL) - BIO_puts(bio_err, "errorCode absent\n"); + BIO_printf(bio_err, "errorCode absent\n"); else BIO_printf(bio_err, "errorCode: %ld\n", ASN1_INTEGER_get(errorCode)); if (sk_ASN1_UTF8STRING_num(errorDetails) <= 0) { - BIO_puts(bio_err, "errorDetails absent\n"); + BIO_printf(bio_err, "errorDetails absent\n"); } else { - BIO_puts(bio_err, "errorDetails: "); + BIO_printf(bio_err, "errorDetails: "); for (i = 0; i < sk_ASN1_UTF8STRING_num(errorDetails); i++) { if (i > 0) - BIO_puts(bio_err, ", "); + BIO_printf(bio_err, ", "); ASN1_STRING_print_ex(bio_err, sk_ASN1_UTF8STRING_value(errorDetails, i), ASN1_STRFLGS_ESC_QUOTE); } - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); } } @@ -731,25 +712,6 @@ static int process_pollReq(OSSL_CMP_SRV_CTX *srv_ctx, return 1; } -OSSL_CMP_MSG *ossl_cmp_mock_server_perform(OSSL_CMP_CTX *ctx, - const OSSL_CMP_MSG *req) -{ - OSSL_CMP_SRV_CTX *srv_ctx = OSSL_CMP_CTX_get_transfer_cb_arg(ctx); - OSSL_CMP_MSG *rsp = OSSL_CMP_CTX_server_perform(ctx, req); - - if (srv_ctx != NULL && rsp != NULL) { - mock_srv_ctx *mock_ctx = OSSL_CMP_SRV_CTX_get0_custom_ctx(srv_ctx); - - if (mock_ctx != NULL && OSSL_CMP_MSG_get_bodytype(rsp) == mock_ctx->useBadProtection) { - ASN1_BIT_STRING *prot = rsp->protection; - - if (prot != NULL && prot->length != 0 && prot->data != NULL) - prot->data[0] ^= 0x80; /* flip most significant bit of the first byte */ - } - } - return rsp; -} - OSSL_CMP_SRV_CTX *ossl_cmp_mock_srv_new(OSSL_LIB_CTX *libctx, const char *propq) { OSSL_CMP_SRV_CTX *srv_ctx = OSSL_CMP_SRV_CTX_new(libctx, propq); diff --git a/apps/lib/log.c b/apps/lib/log.c index 8ed7a3bc2b..d686cfbdf2 100644 --- a/apps/lib/log.c +++ b/apps/lib/log.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -53,7 +53,7 @@ static void log_with_prefix(const char *prog, const char *fmt, va_list ap) (void)BIO_set_prefix(pre, prefix); bio = BIO_push(pre, bio_err); (void)BIO_vprintf(bio, fmt, ap); - (void)BIO_puts(bio, "\n"); + (void)BIO_printf(bio, "\n"); (void)BIO_flush(bio); (void)BIO_pop(pre); BIO_free(pre); @@ -92,7 +92,7 @@ void trace_log_message(int category, #else (void)BIO_vprintf(out, fmt, ap); #endif - (void)BIO_puts(out, "\n"); + (void)BIO_printf(out, "\n"); OSSL_trace_end(category, out); } if (verbosity < level) { diff --git a/apps/lib/names.c b/apps/lib/names.c index dbce9a1b0c..24a146819b 100644 --- a/apps/lib/names.c +++ b/apps/lib/names.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -33,14 +33,14 @@ void print_names(BIO *out, STACK_OF(OPENSSL_CSTRING) *names) sk_OPENSSL_CSTRING_sort(names); if (i > 1) - BIO_puts(out, "{ "); + BIO_printf(out, "{ "); for (j = 0; j < i; j++) { const char *name = sk_OPENSSL_CSTRING_value(names, j); if (j > 0) - BIO_puts(out, ", "); + BIO_printf(out, ", "); BIO_printf(out, "%s", name); } if (i > 1) - BIO_puts(out, " }"); + BIO_printf(out, " }"); } diff --git a/apps/lib/opt.c b/apps/lib/opt.c index d139346cc2..8c3b3a9e25 100644 --- a/apps/lib/opt.c +++ b/apps/lib/opt.c @@ -688,7 +688,7 @@ int opt_ulong(const char *value, unsigned long *result) l = strtoul(value, &endptr, 0); if (*endptr || endptr == value - || (l == ULONG_MAX && errno == ERANGE) + || ((l == ULONG_MAX) && errno == ERANGE) || (l == 0 && errno != 0)) { opt_number_error(value); errno = oerrno; @@ -765,12 +765,12 @@ int opt_verify(int opt, X509_VERIFY_PARAM *vpm) X509_VERIFY_PARAM_set1(vpm, vtmp); break; case OPT_V_VERIFY_DEPTH: - i = opt_int_arg(); + i = atoi(opt_arg()); if (i >= 0) X509_VERIFY_PARAM_set_depth(vpm, i); break; case OPT_V_VERIFY_AUTH_LEVEL: - i = opt_int_arg(); + i = atoi(opt_arg()); if (i >= 0) X509_VERIFY_PARAM_set_auth_level(vpm, i); break; @@ -1236,7 +1236,9 @@ int opt_isdir(const char *name) if (len_0 > MAX_PATH) return -1; +#if !defined(_WIN32_WCE) || _WIN32_WCE >= 101 if (!MultiByteToWideChar(CP_ACP, 0, name, (int)len_0, tempname, MAX_PATH)) +#endif for (i = 0; i < len_0; i++) tempname[i] = (WCHAR)name[i]; diff --git a/apps/lib/s_cb.c b/apps/lib/s_cb.c index f83ffd7236..016adb5043 100644 --- a/apps/lib/s_cb.c +++ b/apps/lib/s_cb.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -47,7 +47,7 @@ static const char *lookup(int val, const STRINT_PAIR *list, const char *def) int verify_callback(int ok, X509_STORE_CTX *ctx) { - const X509 *err_cert; + X509 *err_cert; int err, depth; err_cert = X509_STORE_CTX_get_current_cert(ctx); @@ -89,17 +89,17 @@ int verify_callback(int ok, X509_STORE_CTX *ctx) case X509_V_ERR_CERT_NOT_YET_VALID: case X509_V_ERR_ERROR_IN_CERT_NOT_BEFORE_FIELD: if (err_cert != NULL) { - BIO_puts(bio_err, "notBefore="); + BIO_printf(bio_err, "notBefore="); ASN1_TIME_print(bio_err, X509_get0_notBefore(err_cert)); - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); } break; case X509_V_ERR_CERT_HAS_EXPIRED: case X509_V_ERR_ERROR_IN_CERT_NOT_AFTER_FIELD: if (err_cert != NULL) { - BIO_puts(bio_err, "notAfter="); + BIO_printf(bio_err, "notAfter="); ASN1_TIME_print(bio_err, X509_get0_notAfter(err_cert)); - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); } break; case X509_V_ERR_NO_EXPLICIT_POLICY: @@ -148,7 +148,7 @@ int set_cert_stuff(SSL_CTX *ctx, char *cert_file, char *key_file) * context */ if (!SSL_CTX_check_private_key(ctx)) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Private key does not match the certificate public key\n"); return 0; } @@ -164,13 +164,13 @@ int set_cert_key_stuff(SSL_CTX *ctx, X509 *cert, EVP_PKEY *key, if (cert == NULL) return 1; if (SSL_CTX_use_certificate(ctx, cert) <= 0) { - BIO_puts(bio_err, "error setting certificate\n"); + BIO_printf(bio_err, "error setting certificate\n"); ERR_print_errors(bio_err); return 0; } if (SSL_CTX_use_PrivateKey(ctx, key) <= 0) { - BIO_puts(bio_err, "error setting private key\n"); + BIO_printf(bio_err, "error setting private key\n"); ERR_print_errors(bio_err); return 0; } @@ -179,17 +179,17 @@ int set_cert_key_stuff(SSL_CTX *ctx, X509 *cert, EVP_PKEY *key, * Now we know that a key and cert have been set against the SSL context */ if (!SSL_CTX_check_private_key(ctx)) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Private key does not match the certificate public key\n"); return 0; } if (chain && !SSL_CTX_set1_chain(ctx, chain)) { - BIO_puts(bio_err, "error setting certificate chain\n"); + BIO_printf(bio_err, "error setting certificate chain\n"); ERR_print_errors(bio_err); return 0; } if (build_chain && !SSL_CTX_build_cert_chain(ctx, chflags)) { - BIO_puts(bio_err, "error building certificate chain\n"); + BIO_printf(bio_err, "error building certificate chain\n"); ERR_print_errors(bio_err); return 0; } @@ -274,9 +274,9 @@ static int do_print_sigalgs(BIO *out, SSL *s, int shared) client = SSL_is_server(s) ? 0 : 1; if (shared) - nsig = SSL_get0_shared_sigalg(s, -1, NULL, NULL); + nsig = SSL_get_shared_sigalgs(s, 0, NULL, NULL, NULL, NULL, NULL); else - nsig = SSL_get0_sigalg(s, -1, NULL, NULL); + nsig = SSL_get_sigalgs(s, -1, NULL, NULL, NULL, NULL, NULL); if (nsig == 0) return 1; @@ -287,19 +287,45 @@ static int do_print_sigalgs(BIO *out, SSL *s, int shared) BIO_puts(out, "Requested "); BIO_puts(out, "Signature Algorithms: "); for (i = 0; i < nsig; i++) { - const char *name = NULL; - unsigned int codepoint; - + int hash_nid, sign_nid; + unsigned char rhash, rsign; + const char *sstr = NULL; if (shared) - SSL_get0_shared_sigalg(s, i, &codepoint, &name); + SSL_get_shared_sigalgs(s, i, &sign_nid, &hash_nid, NULL, + &rsign, &rhash); else - SSL_get0_sigalg(s, i, &codepoint, &name); - if (i > 0) + SSL_get_sigalgs(s, i, &sign_nid, &hash_nid, NULL, &rsign, &rhash); + if (i) BIO_puts(out, ":"); - if (name != NULL) - BIO_puts(out, name); + switch (rsign | rhash << 8) { + case 0x0809: + BIO_puts(out, "rsa_pss_pss_sha256"); + continue; + case 0x080a: + BIO_puts(out, "rsa_pss_pss_sha384"); + continue; + case 0x080b: + BIO_puts(out, "rsa_pss_pss_sha512"); + continue; + case 0x081a: + BIO_puts(out, "ecdsa_brainpoolP256r1_sha256"); + continue; + case 0x081b: + BIO_puts(out, "ecdsa_brainpoolP384r1_sha384"); + continue; + case 0x081c: + BIO_puts(out, "ecdsa_brainpoolP512r1_sha512"); + continue; + } + sstr = get_sigtype(sign_nid); + if (sstr) + BIO_printf(out, "%s", sstr); else - BIO_printf(out, "0x%04X", codepoint); + BIO_printf(out, "0x%02X", (int)rsign); + if (hash_nid != NID_undef) + BIO_printf(out, "+%s", OBJ_nid2sn(hash_nid)); + else if (sstr == NULL) + BIO_printf(out, "+0x%02X", (int)rhash); } BIO_puts(out, "\n"); return 1; @@ -373,11 +399,7 @@ int ssl_print_groups(BIO *out, SSL *s, int noshared) if (i) BIO_puts(out, ":"); nid = groups[i]; - const char *name = SSL_group_to_name(s, nid); - if (name == NULL) - BIO_printf(out, "NID %d", nid); - else - BIO_puts(out, name); + BIO_printf(out, "%s", SSL_group_to_name(s, nid)); } OPENSSL_free(groups); if (noshared) { @@ -390,11 +412,7 @@ int ssl_print_groups(BIO *out, SSL *s, int noshared) if (i) BIO_puts(out, ":"); nid = SSL_get_shared_group(s, i); - const char *name = SSL_group_to_name(s, nid); - if (name == NULL) - BIO_printf(out, "%d", nid); - else - BIO_puts(out, name); + BIO_printf(out, "%s", SSL_group_to_name(s, nid)); } if (ngroups == 0) BIO_puts(out, "NONE"); @@ -409,15 +427,9 @@ int ssl_print_tmp_key(BIO *out, SSL *s) EVP_PKEY *key; if (!SSL_get_peer_tmp_key(s, &key)) { - if (SSL_version(s) == TLS1_3_VERSION) { - int nid = SSL_get_negotiated_group(s); - const char *name = SSL_group_to_name(s, nid); - - if (name == NULL) - BIO_printf(out, "Negotiated TLS1.3 group NID: %d\n", nid); - else - BIO_printf(out, "Negotiated TLS1.3 group: %s\n", name); - } + if (SSL_version(s) == TLS1_3_VERSION) + BIO_printf(out, "Negotiated TLS1.3 group: %s\n", + SSL_group_to_name(s, SSL_get_negotiated_group(s))); return 1; } @@ -459,7 +471,7 @@ long bio_dump_callback(BIO *bio, int cmd, const char *argp, size_t len, int argi, long argl, int ret, size_t *processed) { BIO *out; - const BIO_MMSG_CB_ARGS *mmsgargs; + BIO_MMSG_CB_ARGS *mmsgargs; size_t i; out = (BIO *)BIO_get_callback_arg(bio); @@ -490,14 +502,14 @@ long bio_dump_callback(BIO *bio, int cmd, const char *argp, size_t len, break; case (BIO_CB_RECVMMSG | BIO_CB_RETURN): - mmsgargs = (const BIO_MMSG_CB_ARGS *)argp; + mmsgargs = (BIO_MMSG_CB_ARGS *)argp; if (ret > 0) { for (i = 0; i < *(mmsgargs->msgs_processed); i++) { BIO_MSG *msg = (BIO_MSG *)((char *)mmsgargs->msg + (i * mmsgargs->stride)); BIO_printf(out, "read from %p [%p] (%zu bytes => %zu (0x%zX))\n", - (void *)bio, msg->data, msg->data_len, + (void *)bio, (void *)msg->data, msg->data_len, msg->data_len, msg->data_len); if (msg->data_len <= INT_MAX) BIO_dump(out, msg->data, (int)msg->data_len); @@ -506,19 +518,19 @@ long bio_dump_callback(BIO *bio, int cmd, const char *argp, size_t len, BIO_MSG *msg = mmsgargs->msg; BIO_printf(out, "read from %p [%p] (%zu bytes => %d)\n", - (void *)bio, msg->data, msg->data_len, ret); + (void *)bio, (void *)msg->data, msg->data_len, ret); } break; case (BIO_CB_SENDMMSG | BIO_CB_RETURN): - mmsgargs = (const BIO_MMSG_CB_ARGS *)argp; + mmsgargs = (BIO_MMSG_CB_ARGS *)argp; if (ret > 0) { for (i = 0; i < *(mmsgargs->msgs_processed); i++) { BIO_MSG *msg = (BIO_MSG *)((char *)mmsgargs->msg + (i * mmsgargs->stride)); BIO_printf(out, "write to %p [%p] (%zu bytes => %zu (0x%zX))\n", - (void *)bio, msg->data, msg->data_len, + (void *)bio, (void *)msg->data, msg->data_len, msg->data_len, msg->data_len); if (msg->data_len <= INT_MAX) BIO_dump(out, msg->data, (int)msg->data_len); @@ -527,7 +539,7 @@ long bio_dump_callback(BIO *bio, int cmd, const char *argp, size_t len, BIO_MSG *msg = mmsgargs->msg; BIO_printf(out, "write to %p [%p] (%zu bytes => %d)\n", - (void *)bio, msg->data, msg->data_len, ret); + (void *)bio, (void *)msg->data, msg->data_len, ret); } break; @@ -571,12 +583,12 @@ void apps_ssl_info_callback(const SSL *s, int where, int ret) } static STRINT_PAIR ssl_versions[] = { + { "SSL 3.0", SSL3_VERSION }, { "TLS 1.0", TLS1_VERSION }, { "TLS 1.1", TLS1_1_VERSION }, { "TLS 1.2", TLS1_2_VERSION }, { "TLS 1.3", TLS1_3_VERSION }, { "DTLS 1.0", DTLS1_VERSION }, - { "DTLS 1.2", DTLS1_2_VERSION }, { "DTLS 1.0 (bad)", DTLS1_BAD_VER }, { NULL } }; @@ -654,10 +666,7 @@ void msg_cb(int write_p, int version, int content_type, const void *buf, const char *str_version, *str_content_type = "", *str_details1 = "", *str_details2 = ""; const unsigned char *bp = buf; - if (version == TLS1_VERSION || version == TLS1_1_VERSION - || version == TLS1_2_VERSION || version == TLS1_3_VERSION - || version == DTLS1_VERSION || version == DTLS1_2_VERSION - || version == DTLS1_BAD_VER) { + if (version == SSL3_VERSION || version == TLS1_VERSION || version == TLS1_1_VERSION || version == TLS1_2_VERSION || version == TLS1_3_VERSION || version == DTLS1_VERSION || version == DTLS1_BAD_VER) { str_version = lookup(version, ssl_versions, "???"); switch (content_type) { case SSL3_RT_CHANGE_CIPHER_SPEC: @@ -708,23 +717,23 @@ void msg_cb(int write_p, int version, int content_type, const void *buf, str_version = tmpbuf; } - BIO_printf(bio, "%s %s%s [length %04zx]%s%s\n", str_write_p, str_version, - str_content_type, len, str_details1, + BIO_printf(bio, "%s %s%s [length %04lx]%s%s\n", str_write_p, str_version, + str_content_type, (unsigned long)len, str_details1, str_details2); if (len > 0) { size_t num, i; - BIO_puts(bio, " "); + BIO_printf(bio, " "); num = len; for (i = 0; i < num; i++) { if (i % 16 == 0 && i > 0) - BIO_puts(bio, "\n "); + BIO_printf(bio, "\n "); BIO_printf(bio, " %02x", ((const unsigned char *)buf)[i]); } if (i < len) - BIO_puts(bio, " ..."); - BIO_puts(bio, "\n"); + BIO_printf(bio, " ..."); + BIO_printf(bio, "\n"); } (void)BIO_flush(bio); } @@ -772,15 +781,11 @@ static const STRINT_PAIR tlsext_types[] = { { "certificate authorities", TLSEXT_TYPE_certificate_authorities }, { "post handshake auth", TLSEXT_TYPE_post_handshake_auth }, { "early_data", TLSEXT_TYPE_early_data }, -#ifndef OPENSSL_NO_ECH - { "encrypted ClientHello (draft-13)", TLSEXT_TYPE_ech }, - { "outer exts", TLSEXT_TYPE_outer_extensions }, -#endif { NULL } }; +/* from rfc8446 4.2.3. + gost (https://tools.ietf.org/id/draft-smyshlyaev-tls12-gost-suites-04.html) */ static STRINT_PAIR signature_tls13_scheme_list[] = { - /* RFC 8446 4.2.3 */ { "rsa_pkcs1_sha1", 0x0201 /* TLSEXT_SIGALG_rsa_pkcs1_sha1 */ }, { "ecdsa_sha1", 0x0203 /* TLSEXT_SIGALG_ecdsa_sha1 */ }, /* {"rsa_pkcs1_sha224", 0x0301 TLSEXT_SIGALG_rsa_pkcs1_sha224}, not in rfc8446 */ @@ -799,59 +804,9 @@ static STRINT_PAIR signature_tls13_scheme_list[] = { { "rsa_pss_pss_sha256", 0x0809 /* TLSEXT_SIGALG_rsa_pss_pss_sha256 */ }, { "rsa_pss_pss_sha384", 0x080a /* TLSEXT_SIGALG_rsa_pss_pss_sha384 */ }, { "rsa_pss_pss_sha512", 0x080b /* TLSEXT_SIGALG_rsa_pss_pss_sha512 */ }, - - /* RFC 8734 */ - { "ecdsa_brainpoolP256r1tls13_sha256", 0x81a }, - { "ecdsa_brainpoolP256r1tls13_sha384", 0x81b }, - { "ecdsa_brainpoolP256r1tls13_sha512", 0x81c }, - - /* RFC 8998 */ - { "sm2sig_sm3", 0x0708 /* TLSEXT_SIGALG_sm2sig_sm3 */ }, - - /* RFC 9367 */ - { "gostr34102012_256a", 0x709 }, - { "gostr34102012_256b", 0x70a }, - { "gostr34102012_256c", 0x70b }, - { "gostr34102012_256d", 0x70c }, - { "gostr34102012_512a", 0x70d }, - { "gostr34102012_512b", 0x70e }, - { "gostr34102012_512c", 0x70f }, - - /* RFC 9963 */ - { "rsa_pkcs1_sha256_legacy", 0x0420 }, - { "rsa_pkcs1_sha384_legacy", 0x0520 }, - { "rsa_pkcs1_sha512_legacy", 0x0620 }, - - /* IBS (https://datatracker.ietf.org/doc/html/draft-wang-tls-raw-public-key-with-ibc-02) */ - { "eccsi_sha256", 0x0704 }, - { "iso_ibs1", 0x0705 }, - { "iso_ibs2", 0x0706 }, - { "iso_chinese_ibs", 0x0707 }, - - /* ML-DSA (https://datatracker.ietf.org/doc/html/draft-ietf-tls-mldsa-00) */ - { "mldsa44", 0x0904 }, - { "mldsa65", 0x0905 }, - { "mldsa87", 0x0906 }, - - /* SLH-DSA (https://datatracker.ietf.org/doc/html/draft-reddy-tls-slhdsa-01) */ - { "slhdsa_sha2_128s", 0x0911 }, - { "slhdsa_sha2_128f", 0x0912 }, - { "slhdsa_sha2_192s", 0x0913 }, - { "slhdsa_sha2_192f", 0x0914 }, - { "slhdsa_sha2_256s", 0x0915 }, - { "slhdsa_sha2_256f", 0x0916 }, - { "slhdsa_shake_128s", 0x0917 }, - { "slhdsa_shake_128f", 0x0918 }, - { "slhdsa_shake_192s", 0x0919 }, - { "slhdsa_shake_192f", 0x091a }, - { "slhdsa_shake_256s", 0x091b }, - { "slhdsa_shake_256f", 0x091c }, - - /* GOST (https://tools.ietf.org/id/draft-smyshlyaev-tls12-gost-suites-04.html) */ { "gostr34102001", 0xeded /* TLSEXT_SIGALG_gostr34102001_gostr3411 */ }, { "gostr34102012_256", 0xeeee /* TLSEXT_SIGALG_gostr34102012_256_gostr34112012_256 */ }, { "gostr34102012_512", 0xefef /* TLSEXT_SIGALG_gostr34102012_512_gostr34112012_512 */ }, - { NULL } }; @@ -901,7 +856,7 @@ int generate_stateless_cookie_callback(SSL *ssl, unsigned char *cookie, /* Initialize a random secret */ if (!cookie_initialized) { if (RAND_bytes(cookie_secret, COOKIE_SECRET_LENGTH) <= 0) { - BIO_puts(bio_err, "error setting random cookie secret\n"); + BIO_printf(bio_err, "error setting random cookie secret\n"); return 0; } cookie_initialized = 1; @@ -910,7 +865,7 @@ int generate_stateless_cookie_callback(SSL *ssl, unsigned char *cookie, if (SSL_is_dtls(ssl)) { lpeer = peer = BIO_ADDR_new(); if (peer == NULL) { - BIO_puts(bio_err, "memory full\n"); + BIO_printf(bio_err, "memory full\n"); return 0; } @@ -922,7 +877,7 @@ int generate_stateless_cookie_callback(SSL *ssl, unsigned char *cookie, /* Create buffer with peer's address and port */ if (!BIO_ADDR_rawaddress(peer, NULL, &length)) { - BIO_puts(bio_err, "Failed getting peer address\n"); + BIO_printf(bio_err, "Failed getting peer address\n"); BIO_ADDR_free(lpeer); return 0; } @@ -939,7 +894,7 @@ int generate_stateless_cookie_callback(SSL *ssl, unsigned char *cookie, cookie_secret, COOKIE_SECRET_LENGTH, buffer, length, cookie, DTLS1_COOKIE_LENGTH, cookie_len) == NULL) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Error calculating HMAC-SHA1 of buffer with secret\n"); goto end; } @@ -1029,11 +984,11 @@ static void print_chain_flags(SSL *s, int flags) BIO_printf(bio_err, "\t%s: %s\n", pp->name, (flags & pp->retval) ? "OK" : "NOT OK"); - BIO_puts(bio_err, "\tSuite B: "); + BIO_printf(bio_err, "\tSuite B: "); if (SSL_set_cert_flags(s, 0) & SSL_CERT_FLAG_SUITEB_128_LOS) BIO_puts(bio_err, flags & CERT_PKEY_SUITEB ? "OK\n" : "NOT OK\n"); else - BIO_puts(bio_err, "not tested\n"); + BIO_printf(bio_err, "not tested\n"); } /* @@ -1155,7 +1110,7 @@ int load_excert(SSL_EXCERT **pexc) } for (; exc; exc = exc->next) { if (exc->certfile == NULL) { - BIO_puts(bio_err, "Missing filename\n"); + BIO_printf(bio_err, "Missing filename\n"); return 0; } exc->cert = load_cert(exc->certfile, exc->certform, @@ -1310,7 +1265,7 @@ void print_verify_detail(SSL *s, BIO *bio) if (verify_err == X509_V_OK) { const char *peername = SSL_get0_peername(s); - BIO_puts(bio, "Verification: OK\n"); + BIO_printf(bio, "Verification: OK\n"); if (peername != NULL) BIO_printf(bio, "Verified peername: %s\n", peername); } else { @@ -1348,7 +1303,7 @@ void print_verify_detail(SSL *s, BIO *bio) : "matched the EE", mdpth); else - BIO_puts(bio, "matched the peer raw public key\n"); + BIO_printf(bio, "matched the peer raw public key\n"); OPENSSL_free(hexdata); } } @@ -1359,7 +1314,6 @@ void print_ssl_summary(SSL *s) const SSL_CIPHER *c; X509 *peer = SSL_get0_peer_certificate(s); EVP_PKEY *peer_rpk = SSL_get0_peer_rpk(s); - const char *local_sigalg = NULL; int nid; BIO_printf(bio_err, "Protocol version: %s\n", SSL_get_version(s)); @@ -1367,9 +1321,6 @@ void print_ssl_summary(SSL *s) c = SSL_get_current_cipher(s); BIO_printf(bio_err, "Ciphersuite: %s\n", SSL_CIPHER_get_name(c)); do_print_sigalgs(bio_err, s, 0); - if (SSL_get0_signature_name(s, &local_sigalg) > 0 - && local_sigalg != NULL) - BIO_printf(bio_err, "Own signature type: %s\n", local_sigalg); if (peer != NULL) { BIO_puts(bio_err, "Peer certificate: "); X509_NAME_print_ex(bio_err, X509_get_subject_name(peer), @@ -1381,7 +1332,7 @@ void print_ssl_summary(SSL *s) BIO_printf(bio_err, "Signature type: %s\n", sigalg); print_verify_detail(s, bio_err); } else if (peer_rpk != NULL) { - BIO_puts(bio_err, "Peer used raw public key\n"); + BIO_printf(bio_err, "Peer used raw public key\n"); if (SSL_get0_peer_signature_name(s, &sigalg)) BIO_printf(bio_err, "Signature type: %s\n", sigalg); print_verify_detail(s, bio_err); @@ -1459,18 +1410,12 @@ int ssl_load_stores(SSL_CTX *ctx, vfy = X509_STORE_new(); if (vfy == NULL) goto err; - if (vfyCAfile != NULL && !X509_STORE_load_file(vfy, vfyCAfile)) { - BIO_printf(bio_err, "Error loading trusted peer verification cert file %s\n", vfyCAfile); + if (vfyCAfile != NULL && !X509_STORE_load_file(vfy, vfyCAfile)) goto err; - } - if (vfyCApath != NULL && !X509_STORE_load_path(vfy, vfyCApath)) { - BIO_printf(bio_err, "Error adding trusted peer verification certs directory %s\n", vfyCApath); + if (vfyCApath != NULL && !X509_STORE_load_path(vfy, vfyCApath)) goto err; - } - if (vfyCAstore != NULL && !X509_STORE_load_store(vfy, vfyCAstore)) { - BIO_printf(bio_err, "Error adding trusted peer verification cert store file %s\n", vfyCAstore); + if (vfyCAstore != NULL && !X509_STORE_load_store(vfy, vfyCAstore)) goto err; - } add_crls_store(vfy, crls); if (SSL_CTX_set1_verify_cert_store(ctx, vfy) == 0) goto err; @@ -1481,18 +1426,12 @@ int ssl_load_stores(SSL_CTX *ctx, ch = X509_STORE_new(); if (ch == NULL) goto err; - if (chCAfile != NULL && !X509_STORE_load_file(ch, chCAfile)) { - BIO_printf(bio_err, "Error loading trusted chain building cert file %s\n", chCAfile); + if (chCAfile != NULL && !X509_STORE_load_file(ch, chCAfile)) goto err; - } - if (chCApath != NULL && !X509_STORE_load_path(ch, chCApath)) { - BIO_printf(bio_err, "Error adddng trusted chain building cert directory %s\n", chCApath); + if (chCApath != NULL && !X509_STORE_load_path(ch, chCApath)) goto err; - } - if (chCAstore != NULL && !X509_STORE_load_store(ch, chCAstore)) { - BIO_printf(bio_err, "Error adddng trusted chain building cert store file %s\n", chCAstore); + if (chCAstore != NULL && !X509_STORE_load_store(ch, chCAstore)) goto err; - } if (SSL_CTX_set1_chain_cert_store(ctx, ch) == 0) goto err; } @@ -1528,7 +1467,10 @@ static STRINT_PAIR callback_types[] = { { "Signature Algorithm mask", SSL_SECOP_SIGALG_MASK }, { "Certificate chain EE key", SSL_SECOP_EE_KEY }, { "Certificate chain CA key", SSL_SECOP_CA_KEY }, + { "Peer Chain EE key", SSL_SECOP_PEER_EE_KEY }, + { "Peer Chain CA key", SSL_SECOP_PEER_CA_KEY }, { "Certificate chain CA digest", SSL_SECOP_CA_MD }, + { "Peer chain CA digest", SSL_SECOP_PEER_CA_MD }, { "SSL compression", SSL_SECOP_COMPRESSION }, { "Session ticket", SSL_SECOP_TICKET }, { NULL } @@ -1562,6 +1504,7 @@ static int security_callback_debug(const SSL *s, const SSL_CTX *ctx, show_nm = 0; break; case SSL_SECOP_CA_MD: + case SSL_SECOP_PEER_CA_MD: cert_md = 1; break; case SSL_SECOP_SIGALG_SUPPORTED: @@ -1655,7 +1598,7 @@ void ssl_ctx_security_debug(SSL_CTX *ctx, int verbose) static void keylog_callback(const SSL *ssl, const char *line) { if (bio_keylog == NULL) { - BIO_puts(bio_err, "Keylog callback is invoked without valid file!\n"); + BIO_printf(bio_err, "Keylog callback is invoked without valid file!\n"); return; } @@ -1724,7 +1667,7 @@ void ssl_print_secure_renegotiation_notes(BIO *bio, SSL *s) BIO_printf(bio, "Secure Renegotiation IS%s supported\n", SSL_get_secure_renegotiation_support(s) ? "" : " NOT"); } else { - BIO_puts(bio, "This TLS version forbids renegotiation.\n"); + BIO_printf(bio, "This TLS version forbids renegotiation.\n"); } } diff --git a/apps/lib/s_socket.c b/apps/lib/s_socket.c index d8e67d6430..976728a423 100644 --- a/apps/lib/s_socket.c +++ b/apps/lib/s_socket.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -156,7 +156,7 @@ int init_client(int *sock, const char *host, const char *port, if (tmpbio == NULL) { BIO_closesocket(*sock); *sock = INVALID_SOCKET; - continue; + goto out; } BIO_free(tmpbio); } @@ -176,7 +176,7 @@ int init_client(int *sock, const char *host, const char *port, /* Save the address */ if (tfo || !doconn) { if (ba_ret == NULL) { - BIO_puts(bio_err, "Internal error\n"); + BIO_printf(bio_err, "Internal error\n"); BIO_closesocket(*sock); *sock = INVALID_SOCKET; goto out; @@ -248,7 +248,7 @@ int report_server_accept(BIO *out, int asock, int with_address, int with_pid) { int success = 1; - if (BIO_puts(out, "ACCEPT") <= 0) + if (BIO_printf(out, "ACCEPT") <= 0) return 0; if (with_address) { char *hostname, *service; @@ -263,13 +263,13 @@ int report_server_accept(BIO *out, int asock, int with_address, int with_pid) hostname, service) > 0; else - (void)BIO_puts(out, "unknown:error\n"); + (void)BIO_printf(out, "unknown:error\n"); OPENSSL_free(hostname); OPENSSL_free(service); } if (with_pid) success *= BIO_printf(out, " PID=%d", getpid()) > 0; - success *= BIO_puts(out, "\n") > 0; + success *= BIO_printf(out, "\n") > 0; (void)BIO_flush(out); return success; @@ -380,7 +380,6 @@ int do_server(int *accept_sock, const char *host, const char *port, BIO *tmpbio = BIO_new_dgram_sctp(asock, BIO_NOCLOSE); if (tmpbio == NULL) { - BIO_ADDRINFO_free(res); BIO_closesocket(asock); ERR_print_errors(bio_err); goto end; diff --git a/apps/lib/tlssrp_depr.c b/apps/lib/tlssrp_depr.c index eb9f3a1814..058f47b90f 100644 --- a/apps/lib/tlssrp_depr.c +++ b/apps/lib/tlssrp_depr.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved. * Copyright 2005 Nokia. All rights reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -65,12 +65,12 @@ static int ssl_srp_verify_param_cb(SSL *s, void *arg) if (((N = SSL_get_srp_N(s)) == NULL) || ((g = SSL_get_srp_g(s)) == NULL)) return 0; if (srp_arg->debug || srp_arg->msg || srp_arg->amp == 1) { - BIO_puts(bio_err, "SRP parameters:\n" - "\tN="); + BIO_printf(bio_err, "SRP parameters:\n"); + BIO_printf(bio_err, "\tN="); BN_print(bio_err, N); - BIO_puts(bio_err, "\n\tg="); + BIO_printf(bio_err, "\n\tg="); BN_print(bio_err, g); - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); } if (SRP_check_known_gN_param(g, N)) @@ -78,7 +78,7 @@ static int ssl_srp_verify_param_cb(SSL *s, void *arg) if (srp_arg->amp == 1) { if (srp_arg->debug) - BIO_puts(bio_err, + BIO_printf(bio_err, "SRP param N and g are not known params, going to check deeper.\n"); /* @@ -89,7 +89,7 @@ static int ssl_srp_verify_param_cb(SSL *s, void *arg) if (BN_num_bits(g) <= BN_BITS && srp_Verify_N_and_g(N, g)) return 1; } - BIO_puts(bio_err, "SRP param N and g rejected.\n"); + BIO_printf(bio_err, "SRP param N and g rejected.\n"); return 0; } @@ -105,7 +105,7 @@ static char *ssl_give_srp_client_pwd_cb(SSL *s, void *arg) cb_tmp.password = (char *)srp_arg->srppassin; cb_tmp.prompt_info = "SRP user"; if ((l = password_callback(pass, PWD_STRLEN, 0, &cb_tmp)) < 0) { - BIO_puts(bio_err, "Can't read Password\n"); + BIO_printf(bio_err, "Can't read Password\n"); OPENSSL_free(pass); return NULL; } @@ -118,7 +118,7 @@ int set_up_srp_arg(SSL_CTX *ctx, SRP_ARG *srp_arg, int srp_lateuser, int c_msg, int c_debug) { if (!srp_lateuser && !SSL_CTX_set_srp_username(ctx, srp_arg->srplogin)) { - BIO_puts(bio_err, "Unable to set SRP username\n"); + BIO_printf(bio_err, "Unable to set SRP username\n"); return 0; } srp_arg->msg = c_msg; @@ -194,7 +194,7 @@ int set_up_srp_verifier_file(SSL_CTX *ctx, srpsrvparm *srp_callback_parm, srp_callback_parm->login = NULL; if (srp_callback_parm->vb == NULL) { - BIO_puts(bio_err, "Failed to initialize SRP verifier file\n"); + BIO_printf(bio_err, "Failed to initialize SRP verifier file\n"); return 0; } if ((ret = SRP_VBASE_init(srp_callback_parm->vb, @@ -203,8 +203,6 @@ int set_up_srp_verifier_file(SSL_CTX *ctx, srpsrvparm *srp_callback_parm, BIO_printf(bio_err, "Cannot initialize SRP verifier file \"%s\":ret=%d\n", srp_verifier_file, ret); - SRP_VBASE_free(srp_callback_parm->vb); - srp_callback_parm->vb = NULL; return 0; } SSL_CTX_set_verify(ctx, SSL_VERIFY_NONE, verify_callback); @@ -224,13 +222,5 @@ void lookup_srp_user(srpsrvparm *srp_callback_parm, BIO *bio_s_out) BIO_printf(bio_s_out, "LOOKUP done %s\n", srp_callback_parm->user->info); else - BIO_puts(bio_s_out, "LOOKUP not successful\n"); -} - -void cleanup_srp(srpsrvparm *srp_callback_parm) -{ - SRP_user_pwd_free(srp_callback_parm->user); - srp_callback_parm->user = NULL; - SRP_VBASE_free(srp_callback_parm->vb); - srp_callback_parm->vb = NULL; + BIO_printf(bio_s_out, "LOOKUP not successful\n"); } diff --git a/apps/lib/vms_term_sock.c b/apps/lib/vms_term_sock.c index e60d7f0a1b..faceb05d01 100644 --- a/apps/lib/vms_term_sock.c +++ b/apps/lib/vms_term_sock.c @@ -495,7 +495,7 @@ static int CreateSocketPair(int SocketFamily, SocketPair[0] = SockDesc2; SocketPair[1] = socket_fd(TcpDeviceChan); - return 0; + return (0); } /*----------------------------------------------------------------------------*/ diff --git a/apps/lib/win32_init.c b/apps/lib/win32_init.c index 37a1f3ec22..ff05730414 100644 --- a/apps/lib/win32_init.c +++ b/apps/lib/win32_init.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -10,7 +10,7 @@ #include #include #include -#include "platform.h" +#include #if defined(CP_UTF8) diff --git a/apps/list.c b/apps/list.c index a9a55fadee..e4825ae3b1 100644 --- a/apps/list.c +++ b/apps/list.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -8,8 +8,6 @@ */ /* We need to use some deprecated APIs */ -#include "internal/nelem.h" -#include "openssl/bio.h" #define OPENSSL_SUPPRESS_DEPRECATED #include "internal/e_os.h" @@ -33,7 +31,6 @@ #include "progs.h" #include "opt.h" #include "names.h" -#include "configuration.h" static int verbose = 0; static const char *select_name = NULL; @@ -55,21 +52,6 @@ static const char *select_name = NULL; TYPE##_free(impl); \ return 1; \ } - -#define OPENSSL_HAS_DISABLED(name) (OSSL_NELEM(openssl_disabled_##name) > 1) - -#define OPENSSL_PRINT_DISABLED(bio, name, str) \ - do { \ - if (OPENSSL_HAS_DISABLED(name)) { \ - BIO_puts((bio), "Disabled " str "(s):\n"); \ - for (size_t i = 1; i < OSSL_NELEM(openssl_disabled_##name); i++) { \ - BIO_printf((bio), "\t- %s\n", openssl_disabled_##name[i]); \ - } \ - } else { \ - BIO_puts((bio), "No disabled " str "s.\n"); \ - } \ - } while (0); - IS_FETCHABLE(cipher, EVP_CIPHER) IS_FETCHABLE(digest, EVP_MD) IS_FETCHABLE(mac, EVP_MAC) @@ -133,7 +115,7 @@ static void list_ciphers(const char *prefix) int i; if (ciphers == NULL) { - BIO_puts(bio_err, "ERROR: Memory allocation\n"); + BIO_printf(bio_err, "ERROR: Memory allocation\n"); return; } #ifndef OPENSSL_NO_DEPRECATED_3_0 @@ -155,7 +137,7 @@ static void list_ciphers(const char *prefix) names = sk_OPENSSL_CSTRING_new(name_cmp); if (names != NULL && EVP_CIPHER_names_do_all(c, collect_names, names)) { - BIO_puts(bio_out, " "); + BIO_printf(bio_out, " "); print_names(bio_out, names); BIO_printf(bio_out, " @ %s\n", @@ -218,7 +200,7 @@ static void list_digests(const char *prefix) int i; if (digests == NULL) { - BIO_puts(bio_err, "ERROR: Memory allocation\n"); + BIO_printf(bio_err, "ERROR: Memory allocation\n"); return; } #ifndef OPENSSL_NO_DEPRECATED_3_0 @@ -240,7 +222,7 @@ static void list_digests(const char *prefix) names = sk_OPENSSL_CSTRING_new(name_cmp); if (names != NULL && EVP_MD_names_do_all(m, collect_names, names)) { - BIO_puts(bio_out, " "); + BIO_printf(bio_out, " "); print_names(bio_out, names); BIO_printf(bio_out, " @ %s\n", @@ -286,10 +268,10 @@ static void list_macs(void) int i; if (macs == NULL) { - BIO_puts(bio_err, "ERROR: Memory allocation\n"); + BIO_printf(bio_err, "ERROR: Memory allocation\n"); return; } - BIO_puts(bio_out, "Provided MACs:\n"); + BIO_printf(bio_out, "Provided MACs:\n"); EVP_MAC_do_all_provided(app_get0_libctx(), collect_macs, macs); sk_EVP_MAC_sort(macs); for (i = 0; i < sk_EVP_MAC_num(macs); i++) { @@ -301,7 +283,7 @@ static void list_macs(void) names = sk_OPENSSL_CSTRING_new(name_cmp); if (names != NULL && EVP_MAC_names_do_all(m, collect_names, names)) { - BIO_puts(bio_out, " "); + BIO_printf(bio_out, " "); print_names(bio_out, names); BIO_printf(bio_out, " @ %s\n", @@ -351,10 +333,10 @@ static void list_kdfs(void) int i; if (kdfs == NULL) { - BIO_puts(bio_err, "ERROR: Memory allocation\n"); + BIO_printf(bio_err, "ERROR: Memory allocation\n"); return; } - BIO_puts(bio_out, "Provided KDFs and PDFs:\n"); + BIO_printf(bio_out, "Provided KDFs and PDFs:\n"); EVP_KDF_do_all_provided(app_get0_libctx(), collect_kdfs, kdfs); sk_EVP_KDF_sort(kdfs); for (i = 0; i < sk_EVP_KDF_num(kdfs); i++) { @@ -366,7 +348,7 @@ static void list_kdfs(void) names = sk_OPENSSL_CSTRING_new(name_cmp); if (names != NULL && EVP_KDF_names_do_all(k, collect_names, names)) { - BIO_puts(bio_out, " "); + BIO_printf(bio_out, " "); print_names(bio_out, names); BIO_printf(bio_out, " @ %s\n", @@ -422,10 +404,10 @@ static void list_random_generators(void) int i; if (rands == NULL) { - BIO_puts(bio_err, "ERROR: Memory allocation\n"); + BIO_printf(bio_err, "ERROR: Memory allocation\n"); return; } - BIO_puts(bio_out, "Provided RNGs and seed sources:\n"); + BIO_printf(bio_out, "Provided RNGs and seed sources:\n"); EVP_RAND_do_all_provided(app_get0_libctx(), collect_rands, rands); sk_EVP_RAND_sort(rands); for (i = 0; i < sk_EVP_RAND_num(rands); i++) { @@ -434,7 +416,8 @@ static void list_random_generators(void) if (select_name != NULL && OPENSSL_strcasecmp(EVP_RAND_get0_name(m), select_name) != 0) continue; - BIO_printf(bio_out, " %s @ %s\n", EVP_RAND_get0_name(m), + BIO_printf(bio_out, " %s", EVP_RAND_get0_name(m)); + BIO_printf(bio_out, " @ %s\n", OSSL_PROVIDER_get0_name(EVP_RAND_get0_provider(m))); if (verbose) { @@ -466,7 +449,8 @@ static void display_random(const char *name, EVP_RAND_CTX *drbg) if (drbg != NULL) { rand = EVP_RAND_CTX_get0_rand(drbg); - BIO_printf(bio_out, " %s @ %s\n", EVP_RAND_get0_name(rand), + BIO_printf(bio_out, " %s", EVP_RAND_get0_name(rand)); + BIO_printf(bio_out, " @ %s\n", OSSL_PROVIDER_get0_name(EVP_RAND_get0_provider(rand))); switch (EVP_RAND_get_state(drbg)) { @@ -548,10 +532,10 @@ static void list_encoders(void) encoders = sk_OSSL_ENCODER_new(encoder_cmp); if (encoders == NULL) { - BIO_puts(bio_err, "ERROR: Memory allocation\n"); + BIO_printf(bio_err, "ERROR: Memory allocation\n"); return; } - BIO_puts(bio_out, "Provided ENCODERs:\n"); + BIO_printf(bio_out, "Provided ENCODERs:\n"); OSSL_ENCODER_do_all_provided(app_get0_libctx(), collect_encoders, encoders); sk_OSSL_ENCODER_sort(encoders); @@ -565,7 +549,7 @@ static void list_encoders(void) names = sk_OPENSSL_CSTRING_new(name_cmp); if (names != NULL && OSSL_ENCODER_names_do_all(k, collect_names, names)) { - BIO_puts(bio_out, " "); + BIO_printf(bio_out, " "); print_names(bio_out, names); BIO_printf(bio_out, " @ %s (%s)\n", @@ -614,10 +598,10 @@ static void list_decoders(void) decoders = sk_OSSL_DECODER_new(decoder_cmp); if (decoders == NULL) { - BIO_puts(bio_err, "ERROR: Memory allocation\n"); + BIO_printf(bio_err, "ERROR: Memory allocation\n"); return; } - BIO_puts(bio_out, "Provided DECODERs:\n"); + BIO_printf(bio_out, "Provided DECODERs:\n"); OSSL_DECODER_do_all_provided(app_get0_libctx(), collect_decoders, decoders); sk_OSSL_DECODER_sort(decoders); @@ -631,7 +615,7 @@ static void list_decoders(void) names = sk_OPENSSL_CSTRING_new(name_cmp); if (names != NULL && OSSL_DECODER_names_do_all(k, collect_names, names)) { - BIO_puts(bio_out, " "); + BIO_printf(bio_out, " "); print_names(bio_out, names); BIO_printf(bio_out, " @ %s (%s)\n", @@ -690,14 +674,14 @@ static void list_keymanagers(void) if (names != NULL && EVP_KEYMGMT_names_do_all(k, collect_names, names)) { const char *desc = EVP_KEYMGMT_get0_description(k); - BIO_puts(bio_out, " Name: "); + BIO_printf(bio_out, " Name: "); if (desc != NULL) - BIO_puts(bio_out, desc); + BIO_printf(bio_out, "%s", desc); else - BIO_puts(bio_out, sk_OPENSSL_CSTRING_value(names, 0)); - BIO_puts(bio_out, "\n" - " Type: Provider Algorithm\n" - " IDs: "); + BIO_printf(bio_out, "%s", sk_OPENSSL_CSTRING_value(names, 0)); + BIO_printf(bio_out, "\n"); + BIO_printf(bio_out, " Type: Provider Algorithm\n"); + BIO_printf(bio_out, " IDs: "); print_names(bio_out, names); BIO_printf(bio_out, " @ %s\n", OSSL_PROVIDER_get0_name(EVP_KEYMGMT_get0_provider(k))); @@ -753,14 +737,14 @@ static void list_skeymanagers(void) if (names != NULL && EVP_SKEYMGMT_names_do_all(k, collect_names, names)) { const char *desc = EVP_SKEYMGMT_get0_description(k); - BIO_puts(bio_out, " Name: "); + BIO_printf(bio_out, " Name: "); if (desc != NULL) - BIO_puts(bio_out, desc); + BIO_printf(bio_out, "%s", desc); else - BIO_puts(bio_out, sk_OPENSSL_CSTRING_value(names, 0)); - BIO_puts(bio_out, "\n"); - BIO_puts(bio_out, " Type: Provider Algorithm\n"); - BIO_puts(bio_out, " IDs: "); + BIO_printf(bio_out, "%s", sk_OPENSSL_CSTRING_value(names, 0)); + BIO_printf(bio_out, "\n"); + BIO_printf(bio_out, " Type: Provider Algorithm\n"); + BIO_printf(bio_out, " IDs: "); print_names(bio_out, names); BIO_printf(bio_out, " @ %s\n", OSSL_PROVIDER_get0_name(EVP_SKEYMGMT_get0_provider(k))); @@ -807,7 +791,7 @@ static void list_signatures(void) names = sk_OPENSSL_CSTRING_new(name_cmp); if (names != NULL && EVP_SIGNATURE_names_do_all(k, collect_names, names)) { count++; - BIO_puts(bio_out, " "); + BIO_printf(bio_out, " "); print_names(bio_out, names); BIO_printf(bio_out, " @ %s\n", @@ -828,7 +812,7 @@ static void list_signatures(void) } sk_EVP_SIGNATURE_pop_free(sig_stack, EVP_SIGNATURE_free); if (count == 0) - BIO_puts(bio_out, " -\n"); + BIO_printf(bio_out, " -\n"); } static int list_provider_tls_sigalgs(const OSSL_PARAM params[], void *data) @@ -839,8 +823,8 @@ static int list_provider_tls_sigalgs(const OSSL_PARAM params[], void *data) p = OSSL_PARAM_locate_const(params, OSSL_CAPABILITY_TLS_SIGALG_IANA_NAME); if (p != NULL && p->data_type == OSSL_PARAM_UTF8_STRING) { if (*((int *)data) > 0) - BIO_puts(bio_out, ":"); - BIO_puts(bio_out, (p->data != NULL) ? (char *)(p->data) : "(null)"); + BIO_printf(bio_out, ":"); + BIO_printf(bio_out, "%s", (char *)(p->data)); /* mark presence of a provider-based sigalg */ *((int *)data) = 2; } @@ -865,20 +849,20 @@ static void list_tls_groups(int version, int all) int i, num; if ((groups = sk_OPENSSL_CSTRING_new_null()) == NULL) { - BIO_puts(bio_err, "ERROR: Memory allocation\n"); + BIO_printf(bio_err, "ERROR: Memory allocation\n"); return; } if ((ctx = SSL_CTX_new(TLS_method())) == NULL) { - BIO_puts(bio_err, "ERROR: Memory allocation\n"); + BIO_printf(bio_err, "ERROR: Memory allocation\n"); goto err; } if (!SSL_CTX_set_min_proto_version(ctx, version) || !SSL_CTX_set_max_proto_version(ctx, version)) { - BIO_puts(bio_err, "ERROR: setting TLS protocol version\n"); + BIO_printf(bio_err, "ERROR: setting TLS protocol version\n"); goto err; } if (!SSL_CTX_get0_implemented_groups(ctx, all, groups)) { - BIO_puts(bio_err, "ERROR: getting implemented TLS group list\n"); + BIO_printf(bio_err, "ERROR: getting implemented TLS group list\n"); goto err; } num = sk_OPENSSL_CSTRING_num(groups); @@ -900,19 +884,19 @@ static void list_tls_signatures(void) if (builtin_sigalgs != NULL) { if (builtin_sigalgs[0] != 0) { - BIO_puts(bio_out, builtin_sigalgs); + BIO_printf(bio_out, "%s", builtin_sigalgs); tls_sigalg_listed = 1; } OPENSSL_free(builtin_sigalgs); } if (!OSSL_PROVIDER_do_all(NULL, list_tls_sigalg_caps, &tls_sigalg_listed)) - BIO_puts(bio_err, + BIO_printf(bio_err, "ERROR: could not list all provider signature algorithms\n"); if (tls_sigalg_listed < 2) BIO_printf(bio_out, "\nNo TLS sig algs registered by currently active providers"); - BIO_puts(bio_out, "\n"); + BIO_printf(bio_out, "\n"); } DEFINE_STACK_OF(EVP_KEM) @@ -951,7 +935,7 @@ static void list_kems(void) names = sk_OPENSSL_CSTRING_new(name_cmp); if (names != NULL && EVP_KEM_names_do_all(k, collect_names, names)) { count++; - BIO_puts(bio_out, " "); + BIO_printf(bio_out, " "); print_names(bio_out, names); BIO_printf(bio_out, " @ %s\n", @@ -972,7 +956,7 @@ static void list_kems(void) } sk_EVP_KEM_pop_free(kem_stack, EVP_KEM_free); if (count == 0) - BIO_puts(bio_out, " -\n"); + BIO_printf(bio_out, " -\n"); } DEFINE_STACK_OF(EVP_ASYM_CIPHER) @@ -1013,7 +997,7 @@ static void list_asymciphers(void) if (names != NULL && EVP_ASYM_CIPHER_names_do_all(k, collect_names, names)) { count++; - BIO_puts(bio_out, " "); + BIO_printf(bio_out, " "); print_names(bio_out, names); BIO_printf(bio_out, " @ %s\n", @@ -1034,7 +1018,7 @@ static void list_asymciphers(void) } sk_EVP_ASYM_CIPHER_pop_free(asymciph_stack, EVP_ASYM_CIPHER_free); if (count == 0) - BIO_puts(bio_out, " -\n"); + BIO_printf(bio_out, " -\n"); } DEFINE_STACK_OF(EVP_KEYEXCH) @@ -1073,7 +1057,7 @@ static void list_keyexchanges(void) names = sk_OPENSSL_CSTRING_new(name_cmp); if (names != NULL && EVP_KEYEXCH_names_do_all(k, collect_names, names)) { count++; - BIO_puts(bio_out, " "); + BIO_printf(bio_out, " "); print_names(bio_out, names); BIO_printf(bio_out, " @ %s\n", @@ -1094,7 +1078,7 @@ static void list_keyexchanges(void) } sk_EVP_KEYEXCH_pop_free(kex_stack, EVP_KEYEXCH_free); if (count == 0) - BIO_puts(bio_out, " -\n"); + BIO_printf(bio_out, " -\n"); } static void list_objects(void) @@ -1131,7 +1115,7 @@ static void list_objects(void) if (n > oid_size) { oid_buf = OPENSSL_realloc(oid_buf, n + 1); if (oid_buf == NULL) { - BIO_puts(bio_err, "ERROR: Memory allocation\n"); + BIO_printf(bio_err, "ERROR: Memory allocation\n"); break; /* Error */ } oid_size = n + 1; @@ -1178,7 +1162,7 @@ static void list_options_for_command(const char *command) BIO_printf(bio_out, "%s %c\n", o->name, c == '\0' ? '-' : c); } /* Always output the -- marker since it is sometimes documented. */ - BIO_puts(bio_out, "- -\n"); + BIO_printf(bio_out, "- -\n"); } static int is_md_available(const char *name) @@ -1244,32 +1228,77 @@ static void list_type(FUNC_TYPE ft, int one) BIO_printf(bio_out, "%s\n", fp->name); } else { if (i % dc.columns == 0 && i > 0) - BIO_puts(bio_out, "\n"); + BIO_printf(bio_out, "\n"); BIO_printf(bio_out, "%-*s", dc.width, fp->name); i++; } } if (!one) - BIO_puts(bio_out, "\n\n"); + BIO_printf(bio_out, "\n\n"); } static void list_pkey(void) { - BIO_puts(bio_out, "Provided:\n" - " Key Managers:\n"); +#ifndef OPENSSL_NO_DEPRECATED_3_0 + int i; + + if (select_name == NULL && include_legacy()) { + BIO_printf(bio_out, "Legacy:\n"); + for (i = 0; i < EVP_PKEY_asn1_get_count(); i++) { + const EVP_PKEY_ASN1_METHOD *ameth; + int pkey_id, pkey_base_id, pkey_flags; + const char *pinfo, *pem_str; + ameth = EVP_PKEY_asn1_get0(i); + EVP_PKEY_asn1_get0_info(&pkey_id, &pkey_base_id, &pkey_flags, + &pinfo, &pem_str, ameth); + if (pkey_flags & ASN1_PKEY_ALIAS) { + BIO_printf(bio_out, " Name: %s\n", OBJ_nid2ln(pkey_id)); + BIO_printf(bio_out, "\tAlias for: %s\n", + OBJ_nid2ln(pkey_base_id)); + } else { + BIO_printf(bio_out, " Name: %s\n", pinfo); + BIO_printf(bio_out, "\tType: %s Algorithm\n", + pkey_flags & ASN1_PKEY_DYNAMIC ? "External" : "Builtin"); + BIO_printf(bio_out, "\tOID: %s\n", OBJ_nid2ln(pkey_id)); + if (pem_str == NULL) + pem_str = "(none)"; + BIO_printf(bio_out, "\tPEM string: %s\n", pem_str); + } + } + } +#endif + BIO_printf(bio_out, "Provided:\n"); + BIO_printf(bio_out, " Key Managers:\n"); list_keymanagers(); } static void list_pkey_meth(void) { - BIO_puts(bio_out, "Provided:\n" - " Encryption:\n"); +#ifndef OPENSSL_NO_DEPRECATED_3_0 + size_t i; + size_t meth_count = EVP_PKEY_meth_get_count(); + + if (select_name == NULL && include_legacy()) { + BIO_printf(bio_out, "Legacy:\n"); + for (i = 0; i < meth_count; i++) { + const EVP_PKEY_METHOD *pmeth = EVP_PKEY_meth_get0(i); + int pkey_id, pkey_flags; + + EVP_PKEY_meth_get0_info(&pkey_id, &pkey_flags, pmeth); + BIO_printf(bio_out, " %s\n", OBJ_nid2ln(pkey_id)); + BIO_printf(bio_out, "\tType: %s Algorithm\n", + pkey_flags & ASN1_PKEY_DYNAMIC ? "External" : "Builtin"); + } + } +#endif + BIO_printf(bio_out, "Provided:\n"); + BIO_printf(bio_out, " Encryption:\n"); list_asymciphers(); - BIO_puts(bio_out, " Key Exchange:\n"); + BIO_printf(bio_out, " Key Exchange:\n"); list_keyexchanges(); - BIO_puts(bio_out, " Signatures:\n"); + BIO_printf(bio_out, " Signatures:\n"); list_signatures(); - BIO_puts(bio_out, " Key encapsulation:\n"); + BIO_printf(bio_out, " Key encapsulation:\n"); list_kems(); } @@ -1296,10 +1325,10 @@ static void list_store_loaders(void) int i; if (stores == NULL) { - BIO_puts(bio_err, "ERROR: Memory allocation\n"); + BIO_printf(bio_err, "ERROR: Memory allocation\n"); return; } - BIO_puts(bio_out, "Provided STORE LOADERs:\n"); + BIO_printf(bio_out, "Provided STORE LOADERs:\n"); OSSL_STORE_LOADER_do_all_provided(app_get0_libctx(), collect_store_loaders, stores); sk_OSSL_STORE_LOADER_sort(stores); @@ -1312,7 +1341,7 @@ static void list_store_loaders(void) names = sk_OPENSSL_CSTRING_new(name_cmp); if (names != NULL && OSSL_STORE_LOADER_names_do_all(l, collect_names, names)) { - BIO_puts(bio_out, " "); + BIO_printf(bio_out, " "); print_names(bio_out, names); BIO_printf(bio_out, " @ %s\n", @@ -1359,17 +1388,17 @@ static void list_provider_info(void) int i; if (providers == NULL) { - BIO_puts(bio_err, "ERROR: Memory allocation\n"); + BIO_printf(bio_err, "ERROR: Memory allocation\n"); return; } if (OSSL_PROVIDER_do_all(NULL, &collect_providers, providers) != 1) { sk_OSSL_PROVIDER_free(providers); - BIO_puts(bio_err, "ERROR: Memory allocation\n"); + BIO_printf(bio_err, "ERROR: Memory allocation\n"); return; } - BIO_puts(bio_out, "Providers:\n"); + BIO_printf(bio_out, "Providers:\n"); sk_OSSL_PROVIDER_sort(providers); for (i = 0; i < sk_OSSL_PROVIDER_num(providers); i++) { const OSSL_PROVIDER *prov = sk_OSSL_PROVIDER_value(providers, i); @@ -1412,9 +1441,154 @@ static void list_provider_info(void) static void list_disabled(void) { - OPENSSL_PRINT_DISABLED(bio_out, protocols, "protocol"); - OPENSSL_PRINT_DISABLED(bio_out, algorithms, "algorithm"); - OPENSSL_PRINT_DISABLED(bio_out, features, "feature"); + BIO_puts(bio_out, "Disabled algorithms:\n"); +#ifdef OPENSSL_NO_ARGON2 + BIO_puts(bio_out, "ARGON2\n"); +#endif +#ifdef OPENSSL_NO_ARIA + BIO_puts(bio_out, "ARIA\n"); +#endif +#ifdef OPENSSL_NO_BF + BIO_puts(bio_out, "BF\n"); +#endif +#ifdef OPENSSL_NO_BLAKE2 + BIO_puts(bio_out, "BLAKE2\n"); +#endif +#ifdef OPENSSL_NO_CAMELLIA + BIO_puts(bio_out, "CAMELLIA\n"); +#endif +#ifdef OPENSSL_NO_CAST + BIO_puts(bio_out, "CAST\n"); +#endif +#ifdef OPENSSL_NO_CMAC + BIO_puts(bio_out, "CMAC\n"); +#endif +#ifdef OPENSSL_NO_CMS + BIO_puts(bio_out, "CMS\n"); +#endif +#ifdef OPENSSL_NO_COMP + BIO_puts(bio_out, "COMP\n"); +#endif +#ifdef OPENSSL_NO_DES + BIO_puts(bio_out, "DES\n"); +#endif +#ifdef OPENSSL_NO_DGRAM + BIO_puts(bio_out, "DGRAM\n"); +#endif +#ifdef OPENSSL_NO_DH + BIO_puts(bio_out, "DH\n"); +#endif +#ifdef OPENSSL_NO_DSA + BIO_puts(bio_out, "DSA\n"); +#endif +#if defined(OPENSSL_NO_DTLS) + BIO_puts(bio_out, "DTLS\n"); +#endif +#if defined(OPENSSL_NO_DTLS1) + BIO_puts(bio_out, "DTLS1\n"); +#endif +#if defined(OPENSSL_NO_DTLS1_2) + BIO_puts(bio_out, "DTLS1_2\n"); +#endif +#ifdef OPENSSL_NO_EC + BIO_puts(bio_out, "EC\n"); +#endif +#ifdef OPENSSL_NO_ECX + BIO_puts(bio_out, "ECX\n"); +#endif +#ifdef OPENSSL_NO_EC2M + BIO_puts(bio_out, "EC2M\n"); +#endif +#ifdef OPENSSL_NO_GOST + BIO_puts(bio_out, "GOST\n"); +#endif +#ifdef OPENSSL_NO_IDEA + BIO_puts(bio_out, "IDEA\n"); +#endif +#ifdef OPENSSL_NO_MD2 + BIO_puts(bio_out, "MD2\n"); +#endif +#ifdef OPENSSL_NO_MD4 + BIO_puts(bio_out, "MD4\n"); +#endif +#ifdef OPENSSL_NO_MD5 + BIO_puts(bio_out, "MD5\n"); +#endif +#ifdef OPENSSL_NO_MDC2 + BIO_puts(bio_out, "MDC2\n"); +#endif +#ifdef OPENSSL_NO_OCB + BIO_puts(bio_out, "OCB\n"); +#endif +#ifdef OPENSSL_NO_OCSP + BIO_puts(bio_out, "OCSP\n"); +#endif +#ifdef OPENSSL_NO_PSK + BIO_puts(bio_out, "PSK\n"); +#endif +#ifdef OPENSSL_NO_RC2 + BIO_puts(bio_out, "RC2\n"); +#endif +#ifdef OPENSSL_NO_RC4 + BIO_puts(bio_out, "RC4\n"); +#endif +#ifdef OPENSSL_NO_RC5 + BIO_puts(bio_out, "RC5\n"); +#endif +#ifdef OPENSSL_NO_RMD160 + BIO_puts(bio_out, "RMD160\n"); +#endif +#ifdef OPENSSL_NO_SCRYPT + BIO_puts(bio_out, "SCRYPT\n"); +#endif +#ifdef OPENSSL_NO_SCTP + BIO_puts(bio_out, "SCTP\n"); +#endif +#ifdef OPENSSL_NO_SEED + BIO_puts(bio_out, "SEED\n"); +#endif +#ifdef OPENSSL_NO_SM2 + BIO_puts(bio_out, "SM2\n"); +#endif +#ifdef OPENSSL_NO_SM3 + BIO_puts(bio_out, "SM3\n"); +#endif +#ifdef OPENSSL_NO_SM4 + BIO_puts(bio_out, "SM4\n"); +#endif +#ifdef OPENSSL_NO_SOCK + BIO_puts(bio_out, "SOCK\n"); +#endif +#ifdef OPENSSL_NO_SRP + BIO_puts(bio_out, "SRP\n"); +#endif +#ifdef OPENSSL_NO_SRTP + BIO_puts(bio_out, "SRTP\n"); +#endif +#ifdef OPENSSL_NO_SSL3 + BIO_puts(bio_out, "SSL3\n"); +#endif +#ifdef OPENSSL_NO_TLS1 + BIO_puts(bio_out, "TLS1\n"); +#endif +#ifdef OPENSSL_NO_TLS1_1 + BIO_puts(bio_out, "TLS1_1\n"); +#endif +#ifdef OPENSSL_NO_TLS1_2 + BIO_puts(bio_out, "TLS1_2\n"); +#endif +#ifdef OPENSSL_NO_WHIRLPOOL + BIO_puts(bio_out, "WHIRLPOOL\n"); +#endif +#ifdef OPENSSL_NO_ZLIB + BIO_puts(bio_out, "ZLIB\n"); +#endif +#ifdef OPENSSL_NO_BROTLI + BIO_puts(bio_out, "BROTLI\n"); +#endif +#ifdef OPENSSL_NO_ZSTD + BIO_puts(bio_out, "ZSTD\n"); +#endif } /* Unified enum for help and list commands. */ @@ -1530,7 +1704,7 @@ const OPTIONS list_options[] = { #endif { "providers", OPT_PROVIDER_INFO, '-', "List of provider information" }, - { "disabled", OPT_DISABLED, '-', "List of disabled features, algorithms, and protocols." }, + { "disabled", OPT_DISABLED, '-', "List of disabled features" }, { "options", OPT_OPTIONS, 's', "List options for specified command" }, { "objects", OPT_OBJECTS, '-', @@ -1717,12 +1891,12 @@ int list_main(int argc, char **argv) if (!opt_check_rest_arg(NULL)) goto opthelp; -#define MAYBE_ADD_NL(cmd) \ - do { \ - if (print_newline++) { \ - BIO_puts(bio_out, "\n"); \ - } \ - cmd; \ +#define MAYBE_ADD_NL(cmd) \ + do { \ + if (print_newline++) { \ + BIO_printf(bio_out, "\n"); \ + } \ + cmd; \ } while (0) if (todo.commands) @@ -1730,31 +1904,31 @@ int list_main(int argc, char **argv) if (todo.all_algorithms) { MAYBE_ADD_NL({}); - BIO_puts(bio_out, "Digests:\n"); + BIO_printf(bio_out, "Digests:\n"); list_digests(" "); - BIO_puts(bio_out, "\nSymmetric Ciphers:\n"); + BIO_printf(bio_out, "\nSymmetric Ciphers:\n"); list_ciphers(" "); - BIO_puts(bio_out, "\n"); + BIO_printf(bio_out, "\n"); list_kdfs(); - BIO_puts(bio_out, "\n"); + BIO_printf(bio_out, "\n"); list_macs(); - BIO_puts(bio_out, "\nProvided Asymmetric Encryption:\n"); + BIO_printf(bio_out, "\nProvided Asymmetric Encryption:\n"); list_asymciphers(); - BIO_puts(bio_out, "\nProvided Key Exchange:\n"); + BIO_printf(bio_out, "\nProvided Key Exchange:\n"); list_keyexchanges(); - BIO_puts(bio_out, "\nProvided Signatures:\n"); + BIO_printf(bio_out, "\nProvided Signatures:\n"); list_signatures(); - BIO_puts(bio_out, "\nProvided Key encapsulation:\n"); + BIO_printf(bio_out, "\nProvided Key encapsulation:\n"); list_kems(); - BIO_puts(bio_out, "\nProvided Key managers:\n"); + BIO_printf(bio_out, "\nProvided Key managers:\n"); list_keymanagers(); - BIO_puts(bio_out, "\n"); + BIO_printf(bio_out, "\n"); list_encoders(); - BIO_puts(bio_out, "\n"); + BIO_printf(bio_out, "\n"); list_decoders(); - BIO_puts(bio_out, "\n"); + BIO_printf(bio_out, "\n"); list_store_loaders(); } if (todo.random_instances) diff --git a/apps/mac.c b/apps/mac.c index 61044eb633..d67c573054 100644 --- a/apps/mac.c +++ b/apps/mac.c @@ -1,5 +1,5 @@ /* - * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2018-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -172,7 +172,7 @@ int mac_main(int argc, char **argv) goto err; if (!EVP_MAC_CTX_set_params(ctx, params)) { - BIO_puts(bio_err, "MAC parameter error\n"); + BIO_printf(bio_err, "MAC parameter error\n"); ERR_print_errors(bio_err); ok = 0; } @@ -190,7 +190,7 @@ int mac_main(int argc, char **argv) goto err; if (!EVP_MAC_init(ctx, NULL, 0, NULL)) { - BIO_puts(bio_err, "EVP_MAC_Init failed\n"); + BIO_printf(bio_err, "EVP_MAC_Init failed\n"); goto err; } @@ -204,22 +204,22 @@ int mac_main(int argc, char **argv) if (i == 0) break; if (!EVP_MAC_update(ctx, buf, i)) { - BIO_puts(bio_err, "EVP_MAC_update failed\n"); + BIO_printf(bio_err, "EVP_MAC_update failed\n"); goto err; } } if (!EVP_MAC_final(ctx, NULL, &len, 0)) { - BIO_puts(bio_err, "EVP_MAC_final failed\n"); + BIO_printf(bio_err, "EVP_MAC_final failed\n"); goto err; } if (len > BUFSIZE) { - BIO_puts(bio_err, "output len is too large\n"); + BIO_printf(bio_err, "output len is too large\n"); goto err; } if (!EVP_MAC_final(ctx, buf, &len, BUFSIZE)) { - BIO_puts(bio_err, "EVP_MAC_final failed\n"); + BIO_printf(bio_err, "EVP_MAC_final failed\n"); goto err; } @@ -229,7 +229,7 @@ int mac_main(int argc, char **argv) for (i = 0; i < (int)len; ++i) BIO_printf(out, "%02X", buf[i]); if (outfile == NULL) - BIO_puts(out, "\n"); + BIO_printf(out, "\n"); } ret = 0; diff --git a/apps/ocsp.c b/apps/ocsp.c index 59d33e90f2..9c55fecd4f 100644 --- a/apps/ocsp.c +++ b/apps/ocsp.c @@ -1,5 +1,5 @@ /* - * Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2001-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -74,7 +74,7 @@ static int do_responder(OCSP_REQUEST **preq, BIO **pcbio, BIO *acbio, static int send_ocsp_response(BIO *cbio, const OCSP_RESPONSE *resp); static char *prog; -#ifndef OPENSSL_NO_POSIX_IO +#ifdef HTTP_DAEMON static int index_changed(CA_DB *); #endif @@ -152,9 +152,9 @@ const OPTIONS ocsp_options[] = { { "help", OPT_HELP, '-', "Display this summary" }, { "ignore_err", OPT_IGNORE_ERR, '-', "Ignore error on OCSP request or response and continue running" }, - { "CAfile", OPT_CAFILE, '<', "File in PEM format with trusted CA certs" }, - { "CApath", OPT_CAPATH, '/', "Dir with trusted CA cert files in PEM format" }, - { "CAstore", OPT_CASTORE, ':', "URI of store with trusted CA certs" }, + { "CAfile", OPT_CAFILE, '<', "Trusted certificates file" }, + { "CApath", OPT_CAPATH, '<', "Trusted certificates directory" }, + { "CAstore", OPT_CASTORE, ':', "Trusted certificates store URI" }, { "no-CAfile", OPT_NOCAFILE, '-', "Do not load the default certificates file" }, { "no-CApath", OPT_NOCAPATH, '-', @@ -319,7 +319,7 @@ int ocsp_main(int argc, char **argv) break; case OPT_TIMEOUT: #ifndef OPENSSL_NO_SOCK - req_timeout = opt_int_arg(); + req_timeout = atoi(opt_arg()); #endif break; case OPT_URL: @@ -515,7 +515,7 @@ int ocsp_main(int argc, char **argv) accept_count = opt_int_arg(); break; case OPT_NDAYS: - ndays = opt_int_arg(); + ndays = atoi(opt_arg()); break; case OPT_RSIGNER: rsignfile = opt_arg(); @@ -543,7 +543,7 @@ int ocsp_main(int argc, char **argv) header = opt_arg(); value = strchr(header, '='); if (value == NULL) { - BIO_puts(bio_err, "Missing = in header key=value\n"); + BIO_printf(bio_err, "Missing = in header key=value\n"); goto opthelp; } *value++ = '\0'; @@ -567,7 +567,7 @@ int ocsp_main(int argc, char **argv) break; case OPT_MULTI: #ifdef HTTP_DAEMON - n_responders = opt_int_arg(); + n_responders = atoi(opt_arg()); #endif break; case OPT_PROV_CASES: @@ -607,7 +607,7 @@ int ocsp_main(int argc, char **argv) req = d2i_OCSP_REQUEST_bio(derbio, NULL); BIO_free(derbio); if (req == NULL) { - BIO_puts(bio_err, "Error reading OCSP request\n"); + BIO_printf(bio_err, "Error reading OCSP request\n"); goto end; } } @@ -618,7 +618,7 @@ int ocsp_main(int argc, char **argv) if (acbio == NULL) goto end; #else - BIO_puts(bio_err, "Cannot act as server - sockets not supported\n"); + BIO_printf(bio_err, "Cannot act as server - sockets not supported\n"); goto end; #endif } @@ -628,7 +628,7 @@ int ocsp_main(int argc, char **argv) rkeyfile = rsignfile; rsigner = load_cert(rsignfile, FORMAT_UNDEF, "responder certificate"); if (rsigner == NULL) { - BIO_puts(bio_err, "Error loading responder certificate\n"); + BIO_printf(bio_err, "Error loading responder certificate\n"); goto end; } if (!load_certs(rca_filename, 0, &rca_certs, NULL, "CA certificates")) @@ -639,7 +639,7 @@ int ocsp_main(int argc, char **argv) goto end; } if (!app_passwd(passinarg, NULL, &passin, NULL)) { - BIO_puts(bio_err, "Error getting password\n"); + BIO_printf(bio_err, "Error getting password\n"); goto end; } rkey = load_key(rkeyfile, FORMAT_UNDEF, 0, passin, @@ -650,7 +650,7 @@ int ocsp_main(int argc, char **argv) if (ridx_filename != NULL && (rkey == NULL || rsigner == NULL || rca_certs == NULL)) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Responder mode requires certificate, key, and CA.\n"); goto end; } @@ -680,7 +680,7 @@ int ocsp_main(int argc, char **argv) redo_accept: if (acbio != NULL) { -#ifndef OPENSSL_NO_POSIX_IO +#ifdef HTTP_DAEMON if (index_changed(rdb)) { CA_DB *newrdb = load_index(ridx_filename, NULL); @@ -715,7 +715,7 @@ redo_accept: if (req == NULL && (signfile != NULL || reqout != NULL || host != NULL || add_nonce || ridx_filename != NULL)) { - BIO_puts(bio_err, "Need an OCSP request for this operation!\n"); + BIO_printf(bio_err, "Need an OCSP request for this operation!\n"); goto end; } @@ -729,7 +729,7 @@ redo_accept: keyfile = signfile; signer = load_cert(signfile, FORMAT_UNDEF, "signer certificate"); if (signer == NULL) { - BIO_puts(bio_err, "Error loading signer certificate\n"); + BIO_printf(bio_err, "Error loading signer certificate\n"); goto end; } if (sign_certfile != NULL) { @@ -744,7 +744,7 @@ redo_accept: if (!OCSP_request_sign(req, signer, key, NULL, sign_other, sign_flags)) { - BIO_puts(bio_err, "Error signing OCSP request\n"); + BIO_printf(bio_err, "Error signing OCSP request\n"); goto end; } } @@ -779,7 +779,7 @@ redo_accept: if (resp == NULL) goto end; #else - BIO_puts(bio_err, + BIO_printf(bio_err, "Error creating connect BIO - sockets not supported\n"); goto end; #endif @@ -790,7 +790,7 @@ redo_accept: resp = d2i_OCSP_RESPONSE_bio(derbio, NULL); BIO_free(derbio); if (resp == NULL) { - BIO_puts(bio_err, "Error reading OCSP response\n"); + BIO_printf(bio_err, "Error reading OCSP response\n"); goto end; } } else { @@ -857,7 +857,7 @@ done_resp: bs = OCSP_response_get1_basic(resp); if (bs == NULL) { - BIO_puts(bio_err, "Error parsing response\n"); + BIO_printf(bio_err, "Error parsing response\n"); goto end; } @@ -866,9 +866,9 @@ done_resp: if (!noverify) { if (req != NULL && ((i = OCSP_check_nonce(req, bs)) <= 0)) { if (i == -1) - BIO_puts(bio_err, "WARNING: no nonce in response\n"); + BIO_printf(bio_err, "WARNING: no nonce in response\n"); else { - BIO_puts(bio_err, "Nonce Verify error\n"); + BIO_printf(bio_err, "Nonce Verify error\n"); ret = 1; goto end; } @@ -876,16 +876,16 @@ done_resp: i = OCSP_basic_verify(bs, verify_other, store, verify_flags); if (i <= 0 && issuers) { - i = OCSP_basic_verify(bs, issuers, store, verify_flags); + i = OCSP_basic_verify(bs, issuers, store, OCSP_TRUSTOTHER); if (i > 0) ERR_clear_error(); } if (i <= 0) { - BIO_puts(bio_err, "Response Verify Failure\n"); + BIO_printf(bio_err, "Response Verify Failure\n"); ERR_print_errors(bio_err); ret = 1; } else { - BIO_puts(bio_err, "Response verify OK\n"); + BIO_printf(bio_err, "Response verify OK\n"); } } @@ -926,7 +926,7 @@ end: return ret; } -#ifndef OPENSSL_NO_POSIX_IO +#ifdef HTTP_DAEMON static int index_changed(CA_DB *rdb) { @@ -937,11 +937,7 @@ static int index_changed(CA_DB *rdb) || rdb->dbst.st_ctime != sb.st_ctime || rdb->dbst.st_ino != sb.st_ino || rdb->dbst.st_dev != sb.st_dev) { -#ifdef HTTP_DAEMON syslog(LOG_INFO, "index file changed, reloading"); -#else - BIO_printf(bio_err, "%s: index file changed, reloading\n", prog); -#endif return 1; } } @@ -957,7 +953,7 @@ static int add_ocsp_cert(OCSP_REQUEST **req, X509 *cert, OCSP_CERTID *id = NULL; if (issuer == NULL) { - BIO_puts(bio_err, "No issuer certificate specified\n"); + BIO_printf(bio_err, "No issuer certificate specified\n"); return 0; } if (*req == NULL) @@ -975,7 +971,7 @@ static int add_ocsp_cert(OCSP_REQUEST **req, X509 *cert, err: OCSP_CERTID_free(id); - BIO_puts(bio_err, "Error Creating OCSP request\n"); + BIO_printf(bio_err, "Error Creating OCSP request\n"); return 0; } @@ -985,11 +981,11 @@ static int add_ocsp_serial(OCSP_REQUEST **req, char *serial, { OCSP_CERTID *id = NULL; const X509_NAME *iname; - const ASN1_BIT_STRING *ikey; + ASN1_BIT_STRING *ikey; ASN1_INTEGER *sno; if (issuer == NULL) { - BIO_puts(bio_err, "No issuer certificate specified\n"); + BIO_printf(bio_err, "No issuer certificate specified\n"); return 0; } if (*req == NULL) @@ -1015,7 +1011,7 @@ static int add_ocsp_serial(OCSP_REQUEST **req, char *serial, err: OCSP_CERTID_free(id); - BIO_puts(bio_err, "Error Creating OCSP request\n"); + BIO_printf(bio_err, "Error Creating OCSP request\n"); return 0; } @@ -1056,10 +1052,9 @@ static int print_ocsp_summary(BIO *out, OCSP_BASICRESP *bs, OCSP_REQUEST *req, BIO_puts(out, "WARNING: Status times invalid.\n"); ERR_print_errors(out); } - BIO_printf(out, "%s\n" - "\tThis Update: ", - OCSP_cert_status_str(status)); + BIO_printf(out, "%s\n", OCSP_cert_status_str(status)); + BIO_puts(out, "\tThis Update: "); ASN1_GENERALIZEDTIME_print(out, thisupd); BIO_puts(out, "\n"); @@ -1121,7 +1116,7 @@ static void make_ocsp_response(BIO *err, OCSP_RESPONSE **resp, OCSP_REQUEST *req int jj; int found = 0; ASN1_OBJECT *cert_id_md_oid; - EVP_MD *cert_id_md; + const EVP_MD *cert_id_md; OCSP_CERTID *cid_resp_md = NULL; one = OCSP_request_onereq_get0(req, i); @@ -1129,8 +1124,7 @@ static void make_ocsp_response(BIO *err, OCSP_RESPONSE **resp, OCSP_REQUEST *req OCSP_id_get0_info(NULL, &cert_id_md_oid, NULL, NULL, cid); - cert_id_md = EVP_MD_fetch(app_get0_libctx(), OBJ_nid2sn(OBJ_obj2nid(cert_id_md_oid)), - app_get0_propq()); + cert_id_md = EVP_get_digestbyobj(cert_id_md_oid); if (cert_id_md == NULL) { *resp = OCSP_response_create(OCSP_RESPONSE_STATUS_INTERNALERROR, NULL); @@ -1140,13 +1134,6 @@ static void make_ocsp_response(BIO *err, OCSP_RESPONSE **resp, OCSP_REQUEST *req X509 *ca_cert = sk_X509_value(ca, jj); OCSP_CERTID *ca_id = OCSP_cert_to_id(cert_id_md, NULL, ca_cert); - if (ca_id == NULL) { - *resp = OCSP_response_create(OCSP_RESPONSE_STATUS_INTERNALERROR, - NULL); - EVP_MD_free(cert_id_md); - goto end; - } - if (OCSP_id_issuer_cmp(ca_id, cid) == 0) { found = 1; if (resp_md != NULL) @@ -1154,7 +1141,6 @@ static void make_ocsp_response(BIO *err, OCSP_RESPONSE **resp, OCSP_REQUEST *req } OCSP_CERTID_free(ca_id); } - EVP_MD_free(cert_id_md); OCSP_id_get0_info(NULL, NULL, NULL, &serial, cid); inf = lookup_serial(db, serial); @@ -1230,9 +1216,7 @@ static void make_ocsp_response(BIO *err, OCSP_RESPONSE **resp, OCSP_REQUEST *req if (badsig) { const ASN1_OCTET_STRING *sig = OCSP_resp_get0_signature(bs); - /* XXX Casts away const, because it mutates the value! */ - if (!corrupt_signature((ASN1_STRING *)sig)) - goto end; + corrupt_signature(sig); } *resp = OCSP_response_create(OCSP_RESPONSE_STATUS_SUCCESSFUL, bs); @@ -1276,7 +1260,7 @@ static int do_responder(OCSP_REQUEST **preq, BIO **pcbio, BIO *acbio, NULL /* found_keep_alive */, prog, 1 /* accept_get */, timeout); #else - BIO_puts(bio_err, + BIO_printf(bio_err, "Error getting OCSP request - sockets not supported\n"); *preq = NULL; return 0; @@ -1292,7 +1276,7 @@ static int send_ocsp_response(BIO *cbio, const OCSP_RESPONSE *resp) ASN1_ITEM_rptr(OCSP_RESPONSE), (const ASN1_VALUE *)resp); #else - BIO_puts(bio_err, + BIO_printf(bio_err, "Error sending OCSP response - sockets not supported\n"); return 0; #endif @@ -1311,7 +1295,7 @@ OCSP_RESPONSE *process_responder(OCSP_REQUEST *req, const char *host, if (use_ssl == 1) { ctx = SSL_CTX_new(TLS_client_method()); if (ctx == NULL) { - BIO_puts(bio_err, "Error creating SSL context.\n"); + BIO_printf(bio_err, "Error creating SSL context.\n"); goto end; } } @@ -1324,7 +1308,7 @@ OCSP_RESPONSE *process_responder(OCSP_REQUEST *req, const char *host, req_timeout, ASN1_ITEM_rptr(OCSP_RESPONSE)); if (resp == NULL) - BIO_puts(bio_err, "Error querying OCSP responder\n"); + BIO_printf(bio_err, "Error querying OCSP responder\n"); end: SSL_CTX_free(ctx); diff --git a/apps/openssl-vms.cnf b/apps/openssl-vms.cnf index cc465c420e..9c02c1c7ec 100644 --- a/apps/openssl-vms.cnf +++ b/apps/openssl-vms.cnf @@ -23,22 +23,12 @@ config_diagnostics = 1 # oid_file = $ENV::HOME/.oid oid_section = new_oids -# When present, The `extensions` setting of the default configuration file is -# used by the `openssl-x509(1)` "mini-CA" as a list of extensions to add to -# each newly signed certificate. See the descriptions of the `-extfile` and -# `-extensions` options for details in the documentation. -# -# The below setting arranges for `openssl-x509(1)` to add -# subjectKeyIdentifier and authorityKeyIdentifier extensions by default. -# -extensions = default_skid_akid - -[ default_skid_akid ] -# Always a subjectKeyIdentifier -subjectKeyIdentifier = hash -# Only if the certificate is not self-signed, with the issuer+serial only as a -# fallback if no issuer keyid is available. -authorityKeyIdentifier = keyid:nonss,issuer:nonss +# To use this configuration file with the "-extfile" option of the +# "openssl x509" utility, name here the section containing the +# X.509v3 extensions to use: +# extensions = +# (Alternatively, use a configuration file that has only +# X.509v3 extensions in its main [= default] section.) [ new_oids ] # We can add new OIDs in here for use by 'ca', 'req' and 'ts'. @@ -91,6 +81,7 @@ default_ca = CA_default # The default ca section dir = sys\$disk:[.demoCA # Where everything is kept certs = $dir.certs] # Where the issued certs are kept +crl_dir = $dir.crl] # Where the issued crl are kept database = $dir]index.txt # database index file. #unique_subject = no # Set to 'no' to allow creation of # several certs with same subject. @@ -222,7 +213,7 @@ basicConstraints=CA:FALSE # PKIX recommendations harmless if included in all certificates. subjectKeyIdentifier=hash -authorityKeyIdentifier=keyid:nonss,issuer:nonss +authorityKeyIdentifier=keyid,issuer # This stuff is for subjectAltName and issuerAltname. # Import the email address. @@ -245,11 +236,16 @@ basicConstraints = CA:FALSE keyUsage = nonRepudiation, digitalSignature, keyEncipherment [ v3_ca ] + + # Extensions for a typical CA + # PKIX recommendation. + subjectKeyIdentifier=hash -authorityKeyIdentifier=keyid:nonss,issuer:nonss + +authorityKeyIdentifier=keyid:always,issuer basicConstraints = critical,CA:true @@ -290,8 +286,7 @@ basicConstraints=CA:FALSE # PKIX recommendations harmless if included in all certificates. subjectKeyIdentifier=hash -# The issuer of a proxy certificate should have SKID. -authorityKeyIdentifier=keyid:always +authorityKeyIdentifier=keyid,issuer # This stuff is for subjectAltName and issuerAltname. # Import the email address. diff --git a/apps/openssl.c b/apps/openssl.c index 4df297e3c4..61623086f7 100644 --- a/apps/openssl.c +++ b/apps/openssl.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -21,15 +21,6 @@ #include #include #include - -#if defined __has_include -/* Any compiler you're going to run valgrind on has this */ -#if __has_include() -#include -#define OPENSSL_VALGRIND_H_INCLUDED -#endif -#endif /* defined(__has_include) */ - /* Needed to get the other O_xxx flags. */ #ifdef OPENSSL_SYS_VMS #include @@ -60,7 +51,7 @@ static void warn_deprecated(const FUNCTION *fp) BIO_printf(bio_err, "The command %s is deprecated.", fp->name); if (strcmp(fp->deprecated_alternative, DEPRECATED_NO_ALTERNATIVE) != 0) BIO_printf(bio_err, " Use '%s' instead.", fp->deprecated_alternative); - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); } static int apps_startup(void) @@ -116,7 +107,7 @@ static size_t internal_trace_cb(const char *buf, size_t cnt, switch (cmd) { case OSSL_TRACE_CTRL_BEGIN: if (trace_data->ingroup) { - BIO_puts(bio_err, "ERROR: tracing already started\n"); + BIO_printf(bio_err, "ERROR: tracing already started\n"); return 0; } trace_data->ingroup = 1; @@ -131,7 +122,7 @@ static size_t internal_trace_cb(const char *buf, size_t cnt, break; case OSSL_TRACE_CTRL_WRITE: if (!trace_data->ingroup) { - BIO_puts(bio_err, "ERROR: writing when tracing not started\n"); + BIO_printf(bio_err, "ERROR: writing when tracing not started\n"); return 0; } if (cnt > INT_MAX) @@ -141,7 +132,7 @@ static size_t internal_trace_cb(const char *buf, size_t cnt, break; case OSSL_TRACE_CTRL_END: if (!trace_data->ingroup) { - BIO_puts(bio_err, "ERROR: finishing when tracing not started\n"); + BIO_printf(bio_err, "ERROR: finishing when tracing not started\n"); return 0; } trace_data->ingroup = 0; @@ -381,32 +372,6 @@ end: #ifndef OPENSSL_NO_SECURE_MEMORY CRYPTO_secure_malloc_done(); #endif - -#if defined(OPENSSL_VALGRIND_TEST) -#if defined(OPENSSL_VALGRIND_H_INCLUDED) -#if defined(RUNNING_ON_VALGRIND) - /* - * Enable special behaviour if we are compiled with - * OPENSSL_VALGRIND_TEST defined. - * - * Somewhat paradoxically, we do *NOT* want to clean up normally - * when running our tests using valgrind in order to test the - * suppression file which we will ship with the distribution. We - * set the OSSL_USE_VALGRIND environment variable for this - * purpose, but we only want to dodge cleanup when running under - * valgrind, *and* that environment variable is set. If you run - * this under valgrind without that environment variable set, it - * will still call OPENSSL_cleanup normally. - * - */ - if (RUNNING_ON_VALGRIND && getenv("OSSL_USE_VALGRIND") != NULL) - EXIT(ret); -#endif /* defined(RUNNING_ON_VALGRIND) */ -#else -#error "OPENSSL_VALGRIND_TEST is defined, but could not be included!" -#endif /* defined(OPENSSL_VALGRIND_H_INCLUDED) */ -#endif /* defined(OPENSSL_VALGRIND_TEST) */ - OPENSSL_cleanup(); EXIT(ret); } @@ -469,26 +434,26 @@ int help_main(int argc, char **argv) for (fp = functions; fp->name != NULL; fp++) { nl = 0; if (i++ % dc.columns == 0) { - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); nl = 1; } if (fp->type != tp) { tp = fp->type; if (!nl) - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); if (tp == FT_md) { i = 1; - BIO_puts(bio_err, + BIO_printf(bio_err, "\nMessage Digest commands (see the `dgst' command for more details)\n"); } else if (tp == FT_cipher) { i = 1; - BIO_puts(bio_err, + BIO_printf(bio_err, "\nCipher commands (see the `enc' command for more details)\n"); } } BIO_printf(bio_err, "%-*s", dc.width, fp->name); } - BIO_puts(bio_err, "\n\n"); + BIO_printf(bio_err, "\n\n"); return 0; } @@ -502,18 +467,11 @@ static int do_cmd(LHASH_OF(FUNCTION) *prog, int argc, char *argv[]) f.name = argv[0]; fp = lh_FUNCTION_retrieve(prog, &f); if (fp == NULL) { - EVP_MD *md = NULL; - EVP_CIPHER *cipher = NULL; - - if ((md = EVP_MD_fetch(app_get0_libctx(), argv[0], app_get0_propq())) != NULL) { - EVP_MD_free(md); - md = NULL; + if (EVP_get_digestbyname(argv[0])) { f.type = FT_md; f.func = dgst_main; fp = &f; - } else if ((cipher = EVP_CIPHER_fetch(app_get0_libctx(), argv[0], app_get0_propq())) != NULL) { - EVP_CIPHER_free(cipher); - cipher = NULL; + } else if (EVP_get_cipherbyname(argv[0])) { f.type = FT_cipher; f.func = enc_main; fp = &f; diff --git a/apps/openssl.cnf b/apps/openssl.cnf index 03429af34a..4db6a549b1 100644 --- a/apps/openssl.cnf +++ b/apps/openssl.cnf @@ -23,22 +23,12 @@ config_diagnostics = 1 # oid_file = $ENV::HOME/.oid oid_section = new_oids -# When present, The `extensions` setting of the default configuration file is -# used by the `openssl-x509(1)` "mini-CA" as a list of extensions to add to -# each newly signed certificate. See the descriptions of the `-extfile` and -# `-extensions` options for details in the documentation. -# -# The below setting arranges for `openssl-x509(1)` to add -# subjectKeyIdentifier and authorityKeyIdentifier extensions by default. -# -extensions = default_skid_akid - -[ default_skid_akid ] -# Always a subjectKeyIdentifier -subjectKeyIdentifier = hash -# Only if the certificate is not self-signed, with the issuer+serial only as a -# fallback if no issuer keyid is available. -authorityKeyIdentifier = keyid:nonss,issuer:nonss +# To use this configuration file with the "-extfile" option of the +# "openssl x509" utility, name here the section containing the +# X.509v3 extensions to use: +# extensions = +# (Alternatively, use a configuration file that has only +# X.509v3 extensions in its main [= default] section.) [ new_oids ] # We can add new OIDs in here for use by 'ca', 'req' and 'ts'. @@ -91,6 +81,7 @@ default_ca = CA_default # The default ca section dir = ./demoCA # Where everything is kept certs = $dir/certs # Where the issued certs are kept +crl_dir = $dir/crl # Where the issued crl are kept database = $dir/index.txt # database index file. #unique_subject = no # Set to 'no' to allow creation of # several certs with same subject. @@ -222,7 +213,7 @@ basicConstraints=CA:FALSE # PKIX recommendations harmless if included in all certificates. subjectKeyIdentifier=hash -authorityKeyIdentifier=keyid:nonss,issuer:nonss +authorityKeyIdentifier=keyid,issuer # This stuff is for subjectAltName and issuerAltname. # Import the email address. @@ -245,11 +236,16 @@ basicConstraints = CA:FALSE keyUsage = nonRepudiation, digitalSignature, keyEncipherment [ v3_ca ] + + # Extensions for a typical CA + # PKIX recommendation. + subjectKeyIdentifier=hash -authorityKeyIdentifier=keyid:nonss,issuer:nonss + +authorityKeyIdentifier=keyid:always,issuer basicConstraints = critical,CA:true @@ -290,8 +286,7 @@ basicConstraints=CA:FALSE # PKIX recommendations harmless if included in all certificates. subjectKeyIdentifier=hash -# The issuer of a proxy certificate should have SKID. -authorityKeyIdentifier=keyid:always +authorityKeyIdentifier=keyid,issuer # This stuff is for subjectAltName and issuerAltname. # Import the email address. diff --git a/apps/passwd.c b/apps/passwd.c index 1750f12f76..338e0135ba 100644 --- a/apps/passwd.c +++ b/apps/passwd.c @@ -1,5 +1,5 @@ /* - * Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -196,6 +196,7 @@ int passwd_main(int argc, char **argv) } /* All remaining arguments are the password text */ + argc = opt_num_rest(); argv = opt_rest(); if (*argv != NULL) { if (pw_source_defined) @@ -256,7 +257,7 @@ int passwd_main(int argc, char **argv) passwds[0] = passwd_malloc; } else { #endif - BIO_puts(bio_err, "password required\n"); + BIO_printf(bio_err, "password required\n"); goto end; } } diff --git a/apps/pkcs12.c b/apps/pkcs12.c index e37aefc7a3..65ce120b40 100644 --- a/apps/pkcs12.c +++ b/apps/pkcs12.c @@ -1,5 +1,5 @@ /* - * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -51,7 +51,7 @@ int dump_certs_pkeys_bag(BIO *out, const PKCS12_SAFEBAG *bags, void print_attribute(BIO *out, const ASN1_TYPE *av); int print_attribs(BIO *out, const STACK_OF(X509_ATTRIBUTE) *attrlst, const char *name); -static void hex_print(BIO *out, const unsigned char *buf, int len); +void hex_prin(BIO *out, unsigned char *buf, int len); static int alg_print(const X509_ALGOR *alg); int cert_load(BIO *in, STACK_OF(X509) *sk); static int set_pbe(int *ppbe, const char *str); @@ -157,9 +157,9 @@ const OPTIONS pkcs12_options[] = { { OPT_MORE_STR, 0, 0, "which is the 1st cert from -in matching the private key (if given)" }, { "untrusted", OPT_UNTRUSTED, '<', "Untrusted certificates for chain building" }, - { "CAfile", OPT_CAFILE, '<', "File in PEM format with trusted CA certs" }, - { "CApath", OPT_CAPATH, '/', "Dir with trusted CA cert files in PEM format" }, - { "CAstore", OPT_CASTORE, ':', "URI of store with trusted CA certs" }, + { "CAfile", OPT_CAFILE, '<', "PEM-format file of CA's" }, + { "CApath", OPT_CAPATH, '/', "PEM-format directory of CA's" }, + { "CAstore", OPT_CASTORE, ':', "URI to store of CA's" }, { "no-CAfile", OPT_NOCAFILE, '-', "Do not load the default certificates file" }, { "no-CApath", OPT_NOCAPATH, '-', @@ -513,7 +513,7 @@ int pkcs12_main(int argc, char **argv) private = 1; if (!app_passwd(passcertsarg, NULL, &passcerts, NULL)) { - BIO_puts(bio_err, "Error getting certificate file password\n"); + BIO_printf(bio_err, "Error getting certificate file password\n"); goto end; } @@ -525,7 +525,7 @@ int pkcs12_main(int argc, char **argv) } if (!app_passwd(passinarg, passoutarg, &passin, &passout)) { - BIO_puts(bio_err, "Error getting passwords\n"); + BIO_printf(bio_err, "Error getting passwords\n"); goto end; } @@ -541,9 +541,9 @@ int pkcs12_main(int argc, char **argv) noprompt = 1; if (twopass) { if (export_pkcs12) - BIO_puts(bio_err, "Option -twopass cannot be used with -passout or -password\n"); + BIO_printf(bio_err, "Option -twopass cannot be used with -passout or -password\n"); else - BIO_puts(bio_err, "Option -twopass cannot be used with -passin or -password\n"); + BIO_printf(bio_err, "Option -twopass cannot be used with -passin or -password\n"); goto end; } } else { @@ -557,12 +557,12 @@ int pkcs12_main(int argc, char **argv) #ifndef OPENSSL_NO_UI_CONSOLE if (EVP_read_pw_string( macpass, sizeof(macpass), "Enter MAC Password:", export_pkcs12)) { - BIO_puts(bio_err, "Can't read Password\n"); + BIO_printf(bio_err, "Can't read Password\n"); goto end; } } else { #endif - BIO_puts(bio_err, "Unsupported option -twopass\n"); + BIO_printf(bio_err, "Unsupported option -twopass\n"); goto end; } } @@ -578,13 +578,13 @@ int pkcs12_main(int argc, char **argv) ASN1_OBJECT *obj = NULL; if ((options & (NOCERTS | NOKEYS)) == (NOCERTS | NOKEYS)) { - BIO_puts(bio_err, "Nothing to export due to -noout or -nocerts and -nokeys\n"); + BIO_printf(bio_err, "Nothing to export due to -noout or -nocerts and -nokeys\n"); goto export_end; } if ((options & NOCERTS) != 0) { chain = 0; - BIO_puts(bio_err, "Warning: -chain option ignored with -nocerts\n"); + BIO_printf(bio_err, "Warning: -chain option ignored with -nocerts\n"); } if (!(options & NOKEYS)) { @@ -647,7 +647,7 @@ int pkcs12_main(int argc, char **argv) ee_cert_tmp = sk_X509_value(certs, 0); if (ee_cert_tmp == NULL) { - BIO_puts(bio_err, + BIO_printf(bio_err, "No end entity certificate to check with -chain\n"); goto export_end; } @@ -704,12 +704,12 @@ int pkcs12_main(int argc, char **argv) #ifndef OPENSSL_NO_UI_CONSOLE if (EVP_read_pw_string(pass, sizeof(pass), "Enter Export Password:", 1)) { - BIO_puts(bio_err, "Can't read Password\n"); + BIO_printf(bio_err, "Can't read Password\n"); goto export_end; } } else { #endif - BIO_puts(bio_err, "Password required\n"); + BIO_printf(bio_err, "Password required\n"); goto export_end; } } @@ -742,13 +742,14 @@ int pkcs12_main(int argc, char **argv) if (!PKCS12_set_pbmac1_pbkdf2(p12, mpass, -1, NULL, macsaltlen, maciter, macmd, pbmac1_pbkdf2_md)) { - BIO_puts(bio_err, "Error creating PBMAC1\n"); + BIO_printf(bio_err, "Error creating PBMAC1\n"); goto export_end; } } else { if (!PKCS12_set_mac(p12, mpass, -1, NULL, macsaltlen, maciter, macmd)) { - BIO_puts(bio_err, "Error creating PKCS12 MAC; no PKCS12KDF support?\n" - "Use -nomac or -pbmac1_pbkdf2 if PKCS12KDF support not available\n"); + BIO_printf(bio_err, "Error creating PKCS12 MAC; no PKCS12KDF support?\n"); + BIO_printf(bio_err, + "Use -nomac or -pbmac1_pbkdf2 if PKCS12KDF support not available\n"); goto export_end; } } @@ -794,12 +795,12 @@ int pkcs12_main(int argc, char **argv) #ifndef OPENSSL_NO_UI_CONSOLE if (EVP_read_pw_string(pass, sizeof(pass), "Enter Import Password:", 0)) { - BIO_puts(bio_err, "Can't read Password\n"); + BIO_printf(bio_err, "Can't read Password\n"); goto end; } } else { #endif - BIO_puts(bio_err, "Password required\n"); + BIO_printf(bio_err, "Password required\n"); goto end; } } @@ -824,7 +825,7 @@ int pkcs12_main(int argc, char **argv) PBKDF2PARAM *pbkdf2_param = PBMAC1_get1_pbkdf2_param(macalgid); if (pbkdf2_param == NULL) { - BIO_puts(bio_err, ", Unsupported KDF or params for PBMAC1\n"); + BIO_printf(bio_err, ", Unsupported KDF or params for PBMAC1\n"); } else { const ASN1_OBJECT *prfobj; int prfnid; @@ -833,7 +834,7 @@ int pkcs12_main(int argc, char **argv) ASN1_INTEGER_get(pbkdf2_param->iter)); BIO_printf(bio_err, "Key length: %ld, Salt length: %d\n", ASN1_INTEGER_get(pbkdf2_param->keylength), - (int)ASN1_STRING_length_ex(pbkdf2_param->salt->value.octet_string)); + ASN1_STRING_length(pbkdf2_param->salt->value.octet_string)); if (pbkdf2_param->prf == NULL) { prfnid = NID_hmacWithSHA1; } else { @@ -847,8 +848,8 @@ int pkcs12_main(int argc, char **argv) BIO_printf(bio_err, ", Iteration %ld\n", tmaciter != NULL ? ASN1_INTEGER_get(tmaciter) : 1L); BIO_printf(bio_err, "MAC length: %ld, salt length: %ld\n", - tmac != NULL ? (long)ASN1_STRING_length_ex(tmac) : 0L, - tsalt != NULL ? (long)ASN1_STRING_length_ex(tsalt) : 0L); + tmac != NULL ? ASN1_STRING_length(tmac) : 0L, + tsalt != NULL ? ASN1_STRING_length(tsalt) : 0L); } } @@ -859,7 +860,7 @@ int pkcs12_main(int argc, char **argv) PKCS12_get0_mac(NULL, &macalgid, NULL, NULL, p12); if (macalgid == NULL) { - BIO_puts(bio_err, "Warning: MAC is absent!\n"); + BIO_printf(bio_err, "Warning: MAC is absent!\n"); goto dump; } @@ -871,8 +872,8 @@ int pkcs12_main(int argc, char **argv) pkcs12kdf = EVP_KDF_fetch(app_get0_libctx(), "PKCS12KDF", app_get0_propq()); if (pkcs12kdf == NULL) { - BIO_puts(bio_err, "Error verifying PKCS12 MAC; no PKCS12KDF support.\n"); - BIO_puts(bio_err, "Use -nomacver if MAC verification is not required.\n"); + BIO_printf(bio_err, "Error verifying PKCS12 MAC; no PKCS12KDF support.\n"); + BIO_printf(bio_err, "Use -nomacver if MAC verification is not required.\n"); goto end; } EVP_KDF_free(pkcs12kdf); @@ -895,7 +896,7 @@ int pkcs12_main(int argc, char **argv) if (ERR_GET_LIB(err) == ERR_LIB_PKCS12 && ERR_GET_REASON(err) == PKCS12_R_MAC_ABSENT) { - BIO_puts(bio_err, "Warning: MAC is absent!\n"); + BIO_printf(bio_err, "Warning: MAC is absent!\n"); goto dump; } @@ -903,20 +904,13 @@ int pkcs12_main(int argc, char **argv) if (utmp == NULL) goto end; badpass = OPENSSL_uni2utf8(utmp, utmplen); - if (badpass == NULL) { - BIO_printf(bio_err, "Verbatim password did not match, and fallback conversion to UTF-8 failed\n" - "The password entered or the input encoding may be wrong\n"); - OPENSSL_free(utmp); - goto end; - } OPENSSL_free(utmp); - if (strcmp(mpass, badpass) == 0 || !PKCS12_verify_mac(p12, badpass, -1)) { - if (ERR_peek_error() == 0) - BIO_puts(bio_err, "Mac verify error: invalid password?\n"); + if (!PKCS12_verify_mac(p12, badpass, -1)) { + BIO_printf(bio_err, "Mac verify error: invalid password?\n"); ERR_print_errors(bio_err); goto end; } else { - BIO_puts(bio_err, "Warning: using broken algorithm\n"); + BIO_printf(bio_err, "Warning: using broken algorithm\n"); if (!twopass) cpass = badpass; } @@ -931,7 +925,7 @@ dump: goto end; if (!dump_certs_keys_p12(out, p12, cpass, -1, options, passout, enc)) { - BIO_puts(bio_err, "Error outputting keys and certificates\n"); + BIO_printf(bio_err, "Error outputting keys and certificates\n"); ERR_print_errors(bio_err); goto end; } @@ -992,12 +986,12 @@ int dump_certs_keys_p12(BIO *out, const PKCS12 *p12, const char *pass, if (bagnid == NID_pkcs7_data) { bags = PKCS12_unpack_p7data(p7); if (options & INFO) - BIO_puts(bio_err, "PKCS7 Data\n"); + BIO_printf(bio_err, "PKCS7 Data\n"); } else if (bagnid == NID_pkcs7_encrypted) { if (options & INFO) { - BIO_puts(bio_err, "PKCS7 Encrypted data: "); + BIO_printf(bio_err, "PKCS7 Encrypted data: "); if (p7->d.encrypted == NULL) { - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); } else { alg_print(p7->d.encrypted->enc_data->algorithm); } @@ -1052,7 +1046,7 @@ int dump_certs_pkeys_bag(BIO *out, const PKCS12_SAFEBAG *bag, switch (PKCS12_SAFEBAG_get_nid(bag)) { case NID_keyBag: if (options & INFO) - BIO_puts(bio_err, "Key bag\n"); + BIO_printf(bio_err, "Key bag\n"); if (options & NOKEYS) return 1; print_attribs(out, attrs, "Bag Attributes"); @@ -1069,7 +1063,7 @@ int dump_certs_pkeys_bag(BIO *out, const PKCS12_SAFEBAG *bag, const X509_SIG *tp8; const X509_ALGOR *tp8alg; - BIO_puts(bio_err, "Shrouded Keybag: "); + BIO_printf(bio_err, "Shrouded Keybag: "); tp8 = PKCS12_SAFEBAG_get0_pkcs8(bag); X509_SIG_get0(tp8, &tp8alg, NULL); alg_print(tp8alg); @@ -1091,7 +1085,7 @@ int dump_certs_pkeys_bag(BIO *out, const PKCS12_SAFEBAG *bag, case NID_certBag: if (options & INFO) - BIO_puts(bio_err, "Certificate bag\n"); + BIO_printf(bio_err, "Certificate bag\n"); if (options & NOCERTS) return 1; if (PKCS12_SAFEBAG_get0_attr(bag, NID_localKeyID)) { @@ -1111,25 +1105,25 @@ int dump_certs_pkeys_bag(BIO *out, const PKCS12_SAFEBAG *bag, case NID_secretBag: if (options & INFO) - BIO_puts(bio_err, "Secret bag\n"); + BIO_printf(bio_err, "Secret bag\n"); print_attribs(out, attrs, "Bag Attributes"); - BIO_puts(bio_err, "Bag Type: "); + BIO_printf(bio_err, "Bag Type: "); i2a_ASN1_OBJECT(bio_err, PKCS12_SAFEBAG_get0_bag_type(bag)); - BIO_puts(bio_err, "\nBag Value: "); + BIO_printf(bio_err, "\nBag Value: "); print_attribute(out, PKCS12_SAFEBAG_get0_bag_obj(bag)); return 1; case NID_safeContentsBag: if (options & INFO) - BIO_puts(bio_err, "Safe Contents bag\n"); + BIO_printf(bio_err, "Safe Contents bag\n"); print_attribs(out, attrs, "Bag Attributes"); return dump_certs_pkeys_bags(out, PKCS12_SAFEBAG_get0_safes(bag), pass, passlen, options, pempass, enc); default: - BIO_puts(bio_err, "Warning unsupported bag type: "); + BIO_printf(bio_err, "Warning unsupported bag type: "); i2a_ASN1_OBJECT(bio_err, PKCS12_SAFEBAG_get0_type(bag)); - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); return 1; } return ret; @@ -1177,8 +1171,7 @@ static int alg_print(const X509_ALGOR *alg) pbenid = OBJ_obj2nid(aoid); - const char *ln = OBJ_nid2ln(pbenid); - BIO_puts(bio_err, (ln != NULL) ? ln : "(null)"); + BIO_printf(bio_err, "%s", OBJ_nid2ln(pbenid)); /* * If PBE algorithm is PBES2 decode algorithm parameters @@ -1231,7 +1224,7 @@ static int alg_print(const X509_ALGOR *alg) } BIO_printf(bio_err, ", Salt length: %d, Cost(N): %ld, " "Block size(r): %ld, Parallelism(p): %ld", - (int)ASN1_STRING_length_ex(kdf->salt), + ASN1_STRING_length(kdf->salt), ASN1_INTEGER_get(kdf->costParameter), ASN1_INTEGER_get(kdf->blockSize), ASN1_INTEGER_get(kdf->parallelizationParameter)); @@ -1281,27 +1274,27 @@ void print_attribute(BIO *out, const ASN1_TYPE *av) switch (av->type) { case V_ASN1_BMPSTRING: - value = OPENSSL_uni2asc(ASN1_STRING_get0_data(av->value.bmpstring), - (int)ASN1_STRING_length_ex(av->value.bmpstring)); + value = OPENSSL_uni2asc(av->value.bmpstring->data, + av->value.bmpstring->length); BIO_printf(out, "%s\n", value); OPENSSL_free(value); break; case V_ASN1_UTF8STRING: - BIO_printf(out, "%.*s\n", (int)ASN1_STRING_length_ex(av->value.utf8string), - ASN1_STRING_get0_data(av->value.utf8string)); + BIO_printf(out, "%.*s\n", av->value.utf8string->length, + av->value.utf8string->data); break; case V_ASN1_OCTET_STRING: - hex_print(out, ASN1_STRING_get0_data(av->value.octet_string), - (int)ASN1_STRING_length_ex(av->value.octet_string)); - BIO_puts(out, "\n"); + hex_prin(out, av->value.octet_string->data, + av->value.octet_string->length); + BIO_printf(out, "\n"); break; case V_ASN1_BIT_STRING: - hex_print(out, ASN1_STRING_get0_data(av->value.bit_string), - (int)ASN1_STRING_length_ex(av->value.bit_string)); - BIO_puts(out, "\n"); + hex_prin(out, av->value.bit_string->data, + av->value.bit_string->length); + BIO_printf(out, "\n"); break; case V_ASN1_OBJECT: @@ -1309,7 +1302,8 @@ void print_attribute(BIO *out, const ASN1_TYPE *av) if (!ln) ln = ""; OBJ_obj2txt(objbuf, sizeof(objbuf), av->value.object, 1); - BIO_printf(out, "%s (%s)\n", ln, objbuf); + BIO_printf(out, "%s (%s)", ln, objbuf); + BIO_printf(out, "\n"); break; default: @@ -1324,7 +1318,7 @@ int print_attribs(BIO *out, const STACK_OF(X509_ATTRIBUTE) *attrlst, const char *name) { X509_ATTRIBUTE *attr; - const ASN1_TYPE *av; + ASN1_TYPE *av; int i, j, attr_nid; if (!attrlst) { BIO_printf(out, "%s: \n", name); @@ -1336,14 +1330,14 @@ int print_attribs(BIO *out, const STACK_OF(X509_ATTRIBUTE) *attrlst, } BIO_printf(out, "%s\n", name); for (i = 0; i < sk_X509_ATTRIBUTE_num(attrlst); i++) { - const ASN1_OBJECT *attr_obj; + ASN1_OBJECT *attr_obj; attr = sk_X509_ATTRIBUTE_value(attrlst, i); attr_obj = X509_ATTRIBUTE_get0_object(attr); attr_nid = OBJ_obj2nid(attr_obj); - BIO_puts(out, " "); + BIO_printf(out, " "); if (attr_nid == NID_undef) { i2a_ASN1_OBJECT(out, attr_obj); - BIO_puts(out, ": "); + BIO_printf(out, ": "); } else { BIO_printf(out, "%s: ", OBJ_nid2ln(attr_nid)); } @@ -1354,13 +1348,13 @@ int print_attribs(BIO *out, const STACK_OF(X509_ATTRIBUTE) *attrlst, print_attribute(out, av); } } else { - BIO_puts(out, "\n"); + BIO_printf(out, "\n"); } } return 1; } -static void hex_print(BIO *out, const unsigned char *buf, int len) +void hex_prin(BIO *out, unsigned char *buf, int len) { int i; for (i = 0; i < len; i++) diff --git a/apps/pkcs7.c b/apps/pkcs7.c index ce652cbe76..33d84098be 100644 --- a/apps/pkcs7.c +++ b/apps/pkcs7.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2022 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -125,7 +125,7 @@ int pkcs7_main(int argc, char **argv) p7 = PKCS7_new_ex(libctx, app_get0_propq()); if (p7 == NULL) { - BIO_puts(bio_err, "unable to allocate PKCS7 object\n"); + BIO_printf(bio_err, "unable to allocate PKCS7 object\n"); ERR_print_errors(bio_err); goto end; } @@ -135,7 +135,7 @@ int pkcs7_main(int argc, char **argv) else p7i = PEM_read_bio_PKCS7(in, &p7, NULL, NULL); if (p7i == NULL) { - BIO_puts(bio_err, "unable to load PKCS7 object\n"); + BIO_printf(bio_err, "unable to load PKCS7 object\n"); ERR_print_errors(bio_err); goto end; } @@ -209,7 +209,7 @@ int pkcs7_main(int argc, char **argv) i = PEM_write_bio_PKCS7(out, p7); if (!i) { - BIO_puts(bio_err, "unable to write pkcs7 object\n"); + BIO_printf(bio_err, "unable to write pkcs7 object\n"); ERR_print_errors(bio_err); goto end; } diff --git a/apps/pkcs8.c b/apps/pkcs8.c index e792bedfeb..4d73f30c2f 100644 --- a/apps/pkcs8.c +++ b/apps/pkcs8.c @@ -1,5 +1,5 @@ /* - * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -223,7 +223,7 @@ int pkcs8_main(int argc, char **argv) } if (!app_passwd(passinarg, passoutarg, &passin, &passout)) { - BIO_puts(bio_err, "Error getting passwords\n"); + BIO_printf(bio_err, "Error getting passwords\n"); goto end; } @@ -240,7 +240,7 @@ int pkcs8_main(int argc, char **argv) if (pkey == NULL) goto end; if ((p8inf = EVP_PKEY2PKCS8(pkey)) == NULL) { - BIO_puts(bio_err, "Error converting key\n"); + BIO_printf(bio_err, "Error converting key\n"); ERR_print_errors(bio_err); goto end; } @@ -253,7 +253,7 @@ int pkcs8_main(int argc, char **argv) } else if (outformat == FORMAT_ASN1) { i2d_PKCS8_PRIV_KEY_INFO_bio(out, p8inf); } else { - BIO_puts(bio_err, "Bad format specified for key\n"); + BIO_printf(bio_err, "Bad format specified for key\n"); goto end; } } else { @@ -271,7 +271,7 @@ int pkcs8_main(int argc, char **argv) pbe = PKCS5_pbe_set(pbe_nid, iter, NULL, saltlen); } if (pbe == NULL) { - BIO_puts(bio_err, "Error setting PBE algorithm\n"); + BIO_printf(bio_err, "Error setting PBE algorithm\n"); ERR_print_errors(bio_err); goto end; } @@ -287,13 +287,13 @@ int pkcs8_main(int argc, char **argv) } } else { #endif - BIO_puts(bio_err, "Password required\n"); + BIO_printf(bio_err, "Password required\n"); goto end; } p8 = PKCS8_set0_pbe(p8pass, (int)strlen(p8pass), p8inf, pbe); if (p8 == NULL) { X509_ALGOR_free(pbe); - BIO_puts(bio_err, "Error encrypting key\n"); + BIO_printf(bio_err, "Error encrypting key\n"); ERR_print_errors(bio_err); goto end; } @@ -303,7 +303,7 @@ int pkcs8_main(int argc, char **argv) else if (outformat == FORMAT_ASN1) i2d_PKCS8_bio(out, p8); else { - BIO_puts(bio_err, "Bad format specified for key\n"); + BIO_printf(bio_err, "Bad format specified for key\n"); goto end; } } @@ -318,7 +318,7 @@ int pkcs8_main(int argc, char **argv) } else if (informat == FORMAT_ASN1) { p8inf = d2i_PKCS8_PRIV_KEY_INFO_bio(in, NULL); } else { - BIO_puts(bio_err, "Bad format specified for key\n"); + BIO_printf(bio_err, "Bad format specified for key\n"); goto end; } } else { @@ -327,12 +327,12 @@ int pkcs8_main(int argc, char **argv) } else if (informat == FORMAT_ASN1) { p8 = d2i_PKCS8_bio(in, NULL); } else { - BIO_puts(bio_err, "Bad format specified for key\n"); + BIO_printf(bio_err, "Bad format specified for key\n"); goto end; } if (p8 == NULL) { - BIO_puts(bio_err, "Error reading key\n"); + BIO_printf(bio_err, "Error reading key\n"); ERR_print_errors(bio_err); goto end; } @@ -342,25 +342,25 @@ int pkcs8_main(int argc, char **argv) #ifndef OPENSSL_NO_UI_CONSOLE p8pass = pass; if (EVP_read_pw_string(pass, sizeof(pass), "Enter Password:", 0)) { - BIO_puts(bio_err, "Can't read Password\n"); + BIO_printf(bio_err, "Can't read Password\n"); goto end; } } else { #endif - BIO_puts(bio_err, "Password required\n"); + BIO_printf(bio_err, "Password required\n"); goto end; } p8inf = PKCS8_decrypt(p8, p8pass, (int)strlen(p8pass)); } if (p8inf == NULL) { - BIO_puts(bio_err, "Error decrypting key\n"); + BIO_printf(bio_err, "Error decrypting key\n"); ERR_print_errors(bio_err); goto end; } if ((pkey = EVP_PKCS82PKEY(p8inf)) == NULL) { - BIO_puts(bio_err, "Error converting key\n"); + BIO_printf(bio_err, "Error converting key\n"); ERR_print_errors(bio_err); goto end; } @@ -378,7 +378,7 @@ int pkcs8_main(int argc, char **argv) } else if (outformat == FORMAT_ASN1) { i2d_PrivateKey_bio(out, pkey); } else { - BIO_puts(bio_err, "Bad format specified for key\n"); + BIO_printf(bio_err, "Bad format specified for key\n"); goto end; } ret = 0; diff --git a/apps/pkey.c b/apps/pkey.c index 868e411820..13160f9d8a 100644 --- a/apps/pkey.c +++ b/apps/pkey.c @@ -1,5 +1,5 @@ /* - * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -14,7 +14,6 @@ #include "ec_common.h" #include #include -#include #include #include @@ -22,7 +21,6 @@ typedef enum OPTION_choice { OPT_COMMON, OPT_INFORM, OPT_OUTFORM, - OPT_ENCOPT, OPT_PASSIN, OPT_PASSOUT, OPT_IN, @@ -59,7 +57,6 @@ const OPTIONS pkey_options[] = { OPT_SECTION("Output"), { "out", OPT_OUT, '>', "Output file for encoded and/or text output" }, { "outform", OPT_OUTFORM, 'F', "Output encoding format (DER or PEM)" }, - { "encopt", OPT_ENCOPT, 's', "Private key encoder parameter" }, { "", OPT_CIPHER, '-', "Any supported cipher to be used for encryption" }, { "passout", OPT_PASSOUT, 's', "Output PEM file pass phrase source" }, { "traditional", OPT_TRADITIONAL, '-', @@ -72,7 +69,7 @@ const OPTIONS pkey_options[] = { { "ec_conv_form", OPT_EC_CONV_FORM, 's', "Specifies the EC point conversion form in the encoding" }, { "ec_param_enc", OPT_EC_PARAM_ENC, 's', - "Selects between named_curve and explicit EC parameter encoding" }, + "Specifies the way the EC parameters are encoded" }, { NULL } }; @@ -89,7 +86,6 @@ int pkey_main(int argc, char **argv) int informat = FORMAT_UNDEF, outformat = FORMAT_PEM; int pubin = 0, pubout = 0, text_pub = 0, text = 0, noout = 0, ret = 1; int private = 0, traditional = 0, check = 0, pub_check = 0; - STACK_OF(OPENSSL_STRING) *encopt = NULL; #ifndef OPENSSL_NO_EC char *asn1_encoding = NULL; char *point_format = NULL; @@ -116,12 +112,6 @@ int pkey_main(int argc, char **argv) if (!opt_format(opt_arg(), OPT_FMT_PEMDER, &outformat)) goto opthelp; break; - case OPT_ENCOPT: - if (encopt == NULL) - encopt = sk_OPENSSL_STRING_new_null(); - if (!sk_OPENSSL_STRING_push(encopt, opt_arg())) - goto end; - break; case OPT_PASSIN: passinarg = opt_arg(); break; @@ -191,10 +181,10 @@ int pkey_main(int argc, char **argv) goto opthelp; if (text && text_pub) - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: The -text option is ignored with -text_pub\n"); if (traditional && (noout || pubout)) - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: -traditional is ignored with no private key output\n"); /* -pubout and -text is the same as -text_pub */ @@ -209,28 +199,17 @@ int pkey_main(int argc, char **argv) goto opthelp; if (cipher == NULL) { if (passoutarg != NULL) - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: The -passout option is ignored without a cipher option\n"); - } else if (noout) { - EVP_CIPHER_free(cipher); - cipher = NULL; } else { - switch (outformat) { - case FORMAT_PEM: - break; - case FORMAT_ASN1: - if (!traditional) - break; - /* FALLTHROUGH */ - default: - BIO_puts(bio_err, - "Error: Cipher options are supported only in PEM " - "and non-traditional DER output forms\n"); + if (noout || outformat != FORMAT_PEM) { + BIO_printf(bio_err, + "Error: Cipher options are supported only for PEM output\n"); goto end; } } if (!app_passwd(passinarg, passoutarg, &passin, &passout)) { - BIO_puts(bio_err, "Error getting passwords\n"); + BIO_printf(bio_err, "Error getting passwords\n"); goto end; } @@ -280,13 +259,13 @@ int pkey_main(int argc, char **argv) r = EVP_PKEY_public_check(ctx); if (r == 1) { - BIO_puts(out, "Key is valid\n"); + BIO_printf(out, "Key is valid\n"); } else { /* * Note: at least for RSA keys if this function returns * -1, there will be no error reasons. */ - BIO_puts(bio_err, "Key is invalid\n"); + BIO_printf(bio_err, "Key is invalid\n"); ERR_print_errors(bio_err); goto end; } @@ -305,13 +284,14 @@ int pkey_main(int argc, char **argv) passout)) goto end; } else { - if (!encode_private_key(out, "PEM", pkey, encopt, cipher, passout)) + if (!PEM_write_bio_PrivateKey(out, pkey, cipher, + NULL, 0, NULL, passout)) goto end; } } } else if (outformat == FORMAT_ASN1) { if (text || text_pub) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Error: Text output cannot be combined with DER output\n"); goto end; } @@ -324,12 +304,13 @@ int pkey_main(int argc, char **argv) if (!i2d_PrivateKey_bio(out, pkey)) goto end; } else { - if (!encode_private_key(out, "DER", pkey, encopt, cipher, passout)) + if (!i2d_PKCS8PrivateKey_bio(out, pkey, NULL, NULL, 0, + NULL, NULL)) goto end; } } } else { - BIO_puts(bio_err, "Bad format specified for key\n"); + BIO_printf(bio_err, "Bad format specified for key\n"); goto end; } } @@ -348,7 +329,6 @@ int pkey_main(int argc, char **argv) end: if (ret != 0) ERR_print_errors(bio_err); - sk_OPENSSL_STRING_free(encopt); EVP_PKEY_CTX_free(ctx); EVP_PKEY_free(pkey); EVP_CIPHER_free(cipher); diff --git a/apps/pkeyparam.c b/apps/pkeyparam.c index 5aff95dae1..624ab91cf0 100644 --- a/apps/pkeyparam.c +++ b/apps/pkeyparam.c @@ -1,5 +1,5 @@ /* - * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2006-2021 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -96,7 +96,7 @@ int pkeyparam_main(int argc, char **argv) pkey = PEM_read_bio_Parameters_ex(in, NULL, app_get0_libctx(), app_get0_propq()); if (pkey == NULL) { - BIO_puts(bio_err, "Error reading parameters\n"); + BIO_printf(bio_err, "Error reading parameters\n"); ERR_print_errors(bio_err); goto end; } @@ -115,13 +115,13 @@ int pkeyparam_main(int argc, char **argv) r = EVP_PKEY_param_check(ctx); if (r == 1) { - BIO_puts(out, "Parameters are valid\n"); + BIO_printf(out, "Parameters are valid\n"); } else { /* * Note: at least for RSA keys if this function returns * -1, there will be no error reasons. */ - BIO_puts(bio_err, "Parameters are invalid\n"); + BIO_printf(bio_err, "Parameters are invalid\n"); ERR_print_errors(bio_err); goto end; } diff --git a/apps/pkeyutl.c b/apps/pkeyutl.c index 5f9c3284f0..59b061b7d9 100644 --- a/apps/pkeyutl.c +++ b/apps/pkeyutl.c @@ -1,5 +1,5 @@ /* - * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -9,7 +9,6 @@ #include "apps.h" #include "progs.h" -#include #include #include #include @@ -38,8 +37,8 @@ static int do_keyop(EVP_PKEY_CTX *ctx, int pkey_op, unsigned char *secret, size_t *psecretlen); static int do_raw_keyop(int pkey_op, EVP_MD_CTX *mctx, - EVP_PKEY *pkey, BIO *in, const char *infile, - size_t filesize, unsigned char *sig, size_t siglen, + EVP_PKEY *pkey, BIO *in, + int filesize, unsigned char *sig, int siglen, unsigned char **out, size_t *poutlen); static int only_nomd(EVP_PKEY *pkey) @@ -149,7 +148,7 @@ int pkeyutl_main(int argc, char **argv) char hexdump = 0, asn1parse = 0, rev = 0, *prog; unsigned char *buf_in = NULL, *buf_out = NULL, *sig = NULL, *secret = NULL; OPTION_CHOICE o; - size_t buf_inlen = 0, siglen = 0; + int buf_inlen = 0, siglen = -1; int keyform = FORMAT_UNDEF, peerform = FORMAT_UNDEF; int keysize = -1, pkey_op = EVP_PKEY_OP_SIGN, key_type = KEY_PRIVKEY; int ret = 1, rv = -1; @@ -163,7 +162,7 @@ int pkeyutl_main(int argc, char **argv) int rawin = 0; EVP_MD_CTX *mctx = NULL; EVP_MD *md = NULL; - size_t filesize = (size_t)-1; /* (size_t)-1 means unknown */ + int filesize = -1; OSSL_LIB_CTX *libctx = app_get0_libctx(); prog = opt_init(argc, argv, pkeyutl_options); @@ -266,7 +265,7 @@ int pkeyutl_main(int argc, char **argv) kdfalg = opt_arg(); break; case OPT_KDFLEN: - kdflen = opt_int_arg(); + kdflen = atoi(opt_arg()); break; case OPT_REV: rev = 1; @@ -358,7 +357,7 @@ int pkeyutl_main(int argc, char **argv) if (rawin) { if ((mctx = EVP_MD_CTX_new()) == NULL) { - BIO_puts(bio_err, "Error: out of memory\n"); + BIO_printf(bio_err, "Error: out of memory\n"); goto end; } } @@ -455,11 +454,8 @@ int pkeyutl_main(int argc, char **argv) if (infile != NULL) { struct stat st; - if (stat(infile, &st) == 0 && st.st_size >= 0) { - filesize = (size_t)st.st_size; - if ((off_t)filesize != st.st_size) - filesize = (size_t)-1; - } + if (stat(infile, &st) == 0 && st.st_size <= INT_MAX) + filesize = (int)st.st_size; } if (in == NULL) goto end; @@ -483,8 +479,8 @@ int pkeyutl_main(int argc, char **argv) if (pkey_op == EVP_PKEY_OP_ENCAPSULATE || pkey_op == EVP_PKEY_OP_DECAPSULATE) { if (secoutfile == NULL && pkey_op == EVP_PKEY_OP_ENCAPSULATE) { - BIO_puts(bio_err, "KEM-based shared-secret derivation requires " - "the '-secret ' option\n"); + BIO_printf(bio_err, "KEM-based shared-secret derivation requires " + "the '-secret ' option\n"); goto end; } /* For backwards compatibility, default decap secrets to the output */ @@ -495,31 +491,31 @@ int pkeyutl_main(int argc, char **argv) if (sigfile != NULL) { BIO *sigbio = BIO_new_file(sigfile, "rb"); - size_t maxsiglen = 16 * 1024 * 1024; if (sigbio == NULL) { BIO_printf(bio_err, "Can't open signature file %s\n", sigfile); goto end; } - if (!bio_to_mem(&sig, &siglen, maxsiglen, sigbio)) { - BIO_free(sigbio); - BIO_puts(bio_err, "Error reading signature data\n"); + siglen = bio_to_mem(&sig, keysize * 10, sigbio); + BIO_free(sigbio); + if (siglen < 0) { + BIO_printf(bio_err, "Error reading signature data\n"); goto end; } - BIO_free(sigbio); } /* Raw input data is handled elsewhere */ if (in != NULL && !rawin) { /* Read the input data */ - if (!bio_to_mem(&buf_in, &buf_inlen, 0, in)) { - BIO_puts(bio_err, "Error reading input Data\n"); + buf_inlen = bio_to_mem(&buf_in, -1, in); + if (buf_inlen < 0) { + BIO_printf(bio_err, "Error reading input Data\n"); goto end; } if (rev) { size_t i; unsigned char ctmp; - size_t l = buf_inlen; + size_t l = (size_t)buf_inlen; for (i = 0; i < l / 2; i++) { ctmp = buf_in[i]; @@ -534,8 +530,7 @@ int pkeyutl_main(int argc, char **argv) && (pkey_op == EVP_PKEY_OP_SIGN || pkey_op == EVP_PKEY_OP_VERIFY)) { if (buf_inlen > EVP_MAX_MD_SIZE) { BIO_printf(bio_err, - "Error: The non-raw input data length %zd is too long - " - "max supported hashed size is %d\n", + "Error: The non-raw input data length %d is too long - max supported hashed size is %d\n", buf_inlen, EVP_MAX_MD_SIZE); goto end; } @@ -543,10 +538,11 @@ int pkeyutl_main(int argc, char **argv) if (pkey_op == EVP_PKEY_OP_VERIFY) { if (rawin) { - rv = do_raw_keyop(pkey_op, mctx, pkey, in, infile, filesize, sig, siglen, + rv = do_raw_keyop(pkey_op, mctx, pkey, in, filesize, sig, siglen, NULL, 0); } else { - rv = EVP_PKEY_verify(ctx, sig, siglen, buf_in, buf_inlen); + rv = EVP_PKEY_verify(ctx, sig, (size_t)siglen, + buf_in, (size_t)buf_inlen); } if (rv == 1) { BIO_puts(out, "Signature Verified Successfully\n"); @@ -558,7 +554,7 @@ int pkeyutl_main(int argc, char **argv) } if (rawin) { /* rawin allocates the buffer in do_raw_keyop() */ - rv = do_raw_keyop(pkey_op, mctx, pkey, in, infile, filesize, NULL, 0, + rv = do_raw_keyop(pkey_op, mctx, pkey, in, filesize, NULL, 0, &buf_out, &buf_outlen); } else { if (kdflen != 0) { @@ -566,7 +562,7 @@ int pkeyutl_main(int argc, char **argv) rv = 1; } else { rv = do_keyop(ctx, pkey_op, NULL, &buf_outlen, - buf_in, buf_inlen, NULL, &secretlen); + buf_in, (size_t)buf_inlen, NULL, &secretlen); } if (rv > 0 && (secretlen > 0 || (pkey_op != EVP_PKEY_OP_ENCAPSULATE && pkey_op != EVP_PKEY_OP_DECAPSULATE)) @@ -577,7 +573,7 @@ int pkeyutl_main(int argc, char **argv) secret = app_malloc(secretlen, "secret output"); rv = do_keyop(ctx, pkey_op, buf_out, &buf_outlen, - buf_in, buf_inlen, secret, &secretlen); + buf_in, (size_t)buf_inlen, secret, &secretlen); } } if (rv <= 0) { @@ -633,11 +629,11 @@ static EVP_PKEY *get_pkey(const char *kdfalg, if (((pkey_op == EVP_PKEY_OP_SIGN) || (pkey_op == EVP_PKEY_OP_DECRYPT) || (pkey_op == EVP_PKEY_OP_DERIVE)) && (key_type != KEY_PRIVKEY && kdfalg == NULL)) { - BIO_puts(bio_err, "A private key is needed for this operation\n"); + BIO_printf(bio_err, "A private key is needed for this operation\n"); return NULL; } if (!app_passwd(passinarg, NULL, &passin, NULL)) { - BIO_puts(bio_err, "Error getting password\n"); + BIO_printf(bio_err, "Error getting password\n"); return NULL; } switch (key_type) { @@ -825,8 +821,8 @@ static int do_keyop(EVP_PKEY_CTX *ctx, int pkey_op, #define TBUF_MAXSIZE 2048 static int do_raw_keyop(int pkey_op, EVP_MD_CTX *mctx, - EVP_PKEY *pkey, BIO *in, const char *infile, - size_t filesize, unsigned char *sig, size_t siglen, + EVP_PKEY *pkey, BIO *in, + int filesize, unsigned char *sig, int siglen, unsigned char **out, size_t *poutlen) { int rv = 0; @@ -836,72 +832,31 @@ static int do_raw_keyop(int pkey_op, EVP_MD_CTX *mctx, /* Some algorithms only support oneshot digests */ if (only_nomd(pkey)) { - if (filesize == (size_t)-1) { + if (filesize < 0) { BIO_printf(bio_err, - "Error: unable to determine size of file '%s' for oneshot operation\n", - infile); + "Error: unable to determine file size for oneshot operation\n"); goto end; } -#if defined(OPENSSL_SYS_UNIX) && defined(_POSIX_MAPPED_FILES) && _POSIX_MAPPED_FILES > 0 - if (infile != NULL) { - struct stat st; - - if (stat(infile, &st) == 0 && !S_ISREG(st.st_mode)) { - BIO_puts(bio_err, "Error: failed to use memory-mapped file\n"); - goto end; - } - } - if (filesize > 0 && infile != NULL) { - const unsigned char *data = NULL; - size_t mapped_size = 0; - - if (app_mmap_file(infile, bio_err, filesize, &data, &mapped_size) == 1) { - switch (pkey_op) { - case EVP_PKEY_OP_VERIFY: - rv = EVP_DigestVerify(mctx, sig, siglen, data, mapped_size); - break; - case EVP_PKEY_OP_SIGN: - rv = EVP_DigestSign(mctx, NULL, poutlen, data, mapped_size); - if (rv == 1 && out != NULL) { - *out = app_malloc(*poutlen, "buffer output"); - rv = EVP_DigestSign(mctx, *out, poutlen, data, mapped_size); - } - break; - default: - break; - } - munmap((void *)data, mapped_size); - } - /* Success or mmap failure: do not fall back to buffer path */ - goto end; - } -#endif - if (filesize > INT_MAX) { - BIO_puts(bio_err, - "Error: file too large for oneshot operation without memory mapping\n"); - goto end; - } - if (filesize > 0) - mbuf = app_malloc(filesize, "oneshot sign/verify buffer"); + mbuf = app_malloc(filesize, "oneshot sign/verify buffer"); switch (pkey_op) { case EVP_PKEY_OP_VERIFY: - buf_len = BIO_read(in, mbuf, (int)filesize); - if (buf_len < 0 || (size_t)buf_len != filesize) { - BIO_puts(bio_err, "Error reading raw input data\n"); + buf_len = BIO_read(in, mbuf, filesize); + if (buf_len != filesize) { + BIO_printf(bio_err, "Error reading raw input data\n"); goto end; } - rv = EVP_DigestVerify(mctx, sig, siglen, mbuf, filesize); + rv = EVP_DigestVerify(mctx, sig, (size_t)siglen, mbuf, buf_len); break; case EVP_PKEY_OP_SIGN: - buf_len = BIO_read(in, mbuf, (int)filesize); - if (buf_len < 0 || (size_t)buf_len != filesize) { - BIO_puts(bio_err, "Error reading raw input data\n"); + buf_len = BIO_read(in, mbuf, filesize); + if (buf_len != filesize) { + BIO_printf(bio_err, "Error reading raw input data\n"); goto end; } - rv = EVP_DigestSign(mctx, NULL, poutlen, mbuf, filesize); + rv = EVP_DigestSign(mctx, NULL, poutlen, mbuf, buf_len); if (rv == 1 && out != NULL) { *out = app_malloc(*poutlen, "buffer output"); - rv = EVP_DigestSign(mctx, *out, poutlen, mbuf, filesize); + rv = EVP_DigestSign(mctx, *out, poutlen, mbuf, buf_len); } break; } @@ -915,16 +870,16 @@ static int do_raw_keyop(int pkey_op, EVP_MD_CTX *mctx, if (buf_len == 0) break; if (buf_len < 0) { - BIO_puts(bio_err, "Error reading raw input data\n"); + BIO_printf(bio_err, "Error reading raw input data\n"); goto end; } rv = EVP_DigestVerifyUpdate(mctx, tbuf, (size_t)buf_len); if (rv != 1) { - BIO_puts(bio_err, "Error verifying raw input data\n"); + BIO_printf(bio_err, "Error verifying raw input data\n"); goto end; } } - rv = EVP_DigestVerifyFinal(mctx, sig, siglen); + rv = EVP_DigestVerifyFinal(mctx, sig, (size_t)siglen); break; case EVP_PKEY_OP_SIGN: for (;;) { @@ -932,12 +887,12 @@ static int do_raw_keyop(int pkey_op, EVP_MD_CTX *mctx, if (buf_len == 0) break; if (buf_len < 0) { - BIO_puts(bio_err, "Error reading raw input data\n"); + BIO_printf(bio_err, "Error reading raw input data\n"); goto end; } rv = EVP_DigestSignUpdate(mctx, tbuf, (size_t)buf_len); if (rv != 1) { - BIO_puts(bio_err, "Error signing raw input data\n"); + BIO_printf(bio_err, "Error signing raw input data\n"); goto end; } } diff --git a/apps/prime.c b/apps/prime.c index f4572e1afb..ffb7648384 100644 --- a/apps/prime.c +++ b/apps/prime.c @@ -1,5 +1,5 @@ /* - * Copyright 2004-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2004-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -67,7 +67,7 @@ static void process_num(const char *s, const int is_hex) r = BN_check_prime(bn, NULL, NULL); BN_free(bn); if (r < 0) { - BIO_puts(bio_err, "Error checking prime\n"); + BIO_printf(bio_err, "Error checking prime\n"); return; } @@ -125,7 +125,7 @@ int prime_main(int argc, char **argv) generate = 1; break; case OPT_BITS: - bits = opt_int_arg(); + bits = atoi(opt_arg()); break; case OPT_SAFE: safe = 1; @@ -150,7 +150,7 @@ int prime_main(int argc, char **argv) argc = opt_num_rest(); argv = opt_rest(); if (!generate && argc == 0) { - BIO_puts(bio_err, "Missing number (s) to check\n"); + BIO_printf(bio_err, "Missing number (s) to check\n"); goto opthelp; } @@ -158,21 +158,21 @@ int prime_main(int argc, char **argv) char *s; if (!bits) { - BIO_puts(bio_err, "Specify the number of bits.\n"); + BIO_printf(bio_err, "Specify the number of bits.\n"); goto end; } bn = BN_new(); if (bn == NULL) { - BIO_puts(bio_err, "Out of memory.\n"); + BIO_printf(bio_err, "Out of memory.\n"); goto end; } if (!BN_generate_prime_ex(bn, bits, safe, NULL, NULL, NULL)) { - BIO_puts(bio_err, "Failed to generate prime.\n"); + BIO_printf(bio_err, "Failed to generate prime.\n"); goto end; } s = hex ? BN_bn2hex(bn) : BN_bn2dec(bn); if (s == NULL) { - BIO_puts(bio_err, "Out of memory.\n"); + BIO_printf(bio_err, "Out of memory.\n"); goto end; } BIO_printf(bio_out, "%s\n", s); diff --git a/apps/progs.pl b/apps/progs.pl index 01789b9058..7abc483a9b 100644 --- a/apps/progs.pl +++ b/apps/progs.pl @@ -60,9 +60,6 @@ if ($opt eq '-H') { * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_APPS_PROGS_H) -#define OSSL_APPS_PROGS_H - #include "function.h" EOF @@ -77,7 +74,6 @@ EOF } print "\n"; print "extern FUNCTION functions[];\n"; - print "\n#endif /* !defined(OSSL_APPS_PROGS_H) */\n"; } if ($opt eq '-C') { diff --git a/apps/rand.c b/apps/rand.c index 3b1647d9b1..a4fb7ecde0 100644 --- a/apps/rand.c +++ b/apps/rand.c @@ -1,5 +1,5 @@ /* - * Copyright 1998-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1998-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -23,7 +23,6 @@ typedef enum OPTION_choice { OPT_OUT, OPT_BASE64, OPT_HEX, - OPT_NO_NEWLINE, OPT_R_ENUM, OPT_PROV_ENUM } OPTION_CHOICE; @@ -38,7 +37,6 @@ const OPTIONS rand_options[] = { { "out", OPT_OUT, '>', "Output file" }, { "base64", OPT_BASE64, '-', "Base64 encode output" }, { "hex", OPT_HEX, '-', "Hex encode output" }, - { "n", OPT_NO_NEWLINE, '-', "Do not output the trailing newline" }, OPT_R_OPTIONS, OPT_PROV_OPTIONS, @@ -53,7 +51,7 @@ int rand_main(int argc, char **argv) BIO *out = NULL; char *outfile = NULL, *prog; OPTION_CHOICE o; - int format = FORMAT_BINARY, r, i, ret = 1, newline = 1; + int format = FORMAT_BINARY, r, i, ret = 1; size_t buflen = (1 << 16); /* max rand chunk size is 2^16 bytes */ long num = -1; uint64_t scaled_num = 0; @@ -84,9 +82,6 @@ int rand_main(int argc, char **argv) case OPT_HEX: format = FORMAT_TEXT; break; - case OPT_NO_NEWLINE: - newline = 0; - break; case OPT_PROV_CASES: if (!opt_provider(o)) goto end; @@ -164,13 +159,13 @@ int rand_main(int argc, char **argv) if (shift != 0) { /* check for overflow */ if ((UINT64_MAX >> shift) < (size_t)num) { - BIO_printf(bio_err, "%ld bytes with suffix overflows\n", + BIO_printf(bio_err, "%lu bytes with suffix overflows\n", num); goto opthelp; } scaled_num = num << shift; if (scaled_num > (UINT64_MAX >> 3)) { - BIO_puts(bio_err, "Request exceeds max allowed output\n"); + BIO_printf(bio_err, "Request exceeds max allowed output\n"); goto opthelp; } } else { @@ -213,7 +208,7 @@ int rand_main(int argc, char **argv) } scaled_num -= chunk; } - if (newline && format == FORMAT_TEXT) + if (format == FORMAT_TEXT) BIO_puts(out, "\n"); if (BIO_flush(out) <= 0) goto end; diff --git a/apps/rehash.c b/apps/rehash.c index 93e757faa9..e2083fa76b 100644 --- a/apps/rehash.c +++ b/apps/rehash.c @@ -1,5 +1,5 @@ /* - * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2013-2014 Timo Teräs * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -168,7 +168,7 @@ static int add_entry(enum Type type, unsigned int hash, const char *filename, if (ep->filename == NULL) { OPENSSL_free(ep); ep = NULL; - BIO_puts(bio_err, "out of memory\n"); + BIO_printf(bio_err, "out of memory\n"); return 1; } if (bp->last_entry) @@ -235,12 +235,12 @@ static int handle_symlink(const char *filename, const char *fullpath) static int do_file(const char *filename, const char *fullpath, enum Hash h) { STACK_OF(X509_INFO) *inf = NULL; - X509_INFO *x = NULL, *tmp; + X509_INFO *x; const X509_NAME *name = NULL; BIO *b; const char *ext; unsigned char digest[EVP_MAX_MD_SIZE]; - int type, j, num = 0, errs = 0; + int type, errs = 0; size_t i; /* Does it end with a recognized extension? */ @@ -265,42 +265,34 @@ static int do_file(const char *filename, const char *fullpath, enum Hash h) if (inf == NULL) goto end; - /* Count the number of certs and CRLs and make x point to the last X509_INFO */ - for (j = 0; j < sk_X509_INFO_num(inf); j++) { - tmp = sk_X509_INFO_value(inf, j); - if (tmp->x509 != NULL) { - x = tmp; - num++; - } - if (tmp->crl != NULL) { - x = tmp; - num++; - } - } - if (num != 1) { + if (sk_X509_INFO_num(inf) != 1) { BIO_printf(bio_err, "%s: warning: skipping %s, " - "it does not contain exactly one certificate or CRL in PEM format\n", + "it does not contain exactly one certificate or CRL\n", opt_getprog(), filename); /* This is not an error. */ goto end; } + x = sk_X509_INFO_value(inf, 0); if (x->x509 != NULL) { type = TYPE_CERT; name = X509_get_subject_name(x->x509); if (!X509_digest(x->x509, evpmd, digest, NULL)) { - BIO_puts(bio_err, "out of memory\n"); + BIO_printf(bio_err, "out of memory\n"); + ++errs; + goto end; + } + } else if (x->crl != NULL) { + type = TYPE_CRL; + name = X509_CRL_get_issuer(x->crl); + if (!X509_CRL_digest(x->crl, evpmd, digest, NULL)) { + BIO_printf(bio_err, "out of memory\n"); ++errs; goto end; } } else { - type = TYPE_CRL; - name = X509_CRL_get_issuer(x->crl); - if (!X509_CRL_digest(x->crl, evpmd, digest, NULL)) { - BIO_puts(bio_err, "out of memory\n"); - ++errs; - goto end; - } + ++errs; + goto end; } if (name != NULL) { if (h == HASH_NEW || h == HASH_BOTH) { @@ -558,6 +550,7 @@ int rehash_main(int argc, char **argv) } /* Optional arguments are directories to scan. */ + argc = opt_num_rest(); argv = opt_rest(); evpmd = EVP_sha1(); @@ -595,7 +588,7 @@ const OPTIONS rehash_options[] = { int rehash_main(int argc, char **argv) { - BIO_puts(bio_err, "Not available\n"); + BIO_printf(bio_err, "Not available; use c_rehash script\n"); return 1; } diff --git a/apps/req.c b/apps/req.c index 83ac38ef86..f95fa013bd 100644 --- a/apps/req.c +++ b/apps/req.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -48,7 +48,7 @@ #define UNSET_DAYS -2 /* -1 may be used for testing expiration checks */ #define EXT_COPY_UNSET -1 -static int make_REQ(X509_REQ *req, EVP_PKEY *pkey, const X509_NAME *fsubj, +static int make_REQ(X509_REQ *req, EVP_PKEY *pkey, X509_NAME *fsubj, int mutlirdn, int attribs, unsigned long chtype); static int prompt_info(X509_REQ *req, STACK_OF(CONF_VALUE) *dn_sk, const char *dn_sect, @@ -240,7 +240,7 @@ static int duplicated(LHASH_OF(OPENSSL_STRING) *addexts, char *kv) while (isspace(_UC(*kv))) kv++; if ((p = strchr(kv, '=')) == NULL) { - BIO_puts(bio_err, "Parse error on -addext: missing '='\n"); + BIO_printf(bio_err, "Parse error on -addext: missing '='\n"); return -2; } off = p - kv; @@ -252,7 +252,7 @@ static int duplicated(LHASH_OF(OPENSSL_STRING) *addexts, char *kv) if (!isspace(_UC(p[-1]))) break; if (p == kv) { - BIO_puts(bio_err, "Parse error on -addext: missing key\n"); + BIO_printf(bio_err, "Parse error on -addext: missing key\n"); OPENSSL_free(kv); return -2; } @@ -292,7 +292,7 @@ int req_main(int argc, char **argv) char *passin = NULL, *passout = NULL; char *nofree_passin = NULL, *nofree_passout = NULL; char *subj = NULL; - const X509_NAME *fsubj = NULL; + X509_NAME *fsubj = NULL; char *template = default_config_file, *keyout = NULL; const char *keyalg = NULL; OPTION_CHOICE o; @@ -454,7 +454,7 @@ int req_main(int argc, char **argv) not_after = opt_arg(); break; case OPT_DAYS: - days = opt_int_arg(); + days = atoi(opt_arg()); if (days <= UNSET_DAYS) { BIO_printf(bio_err, "%s: -days parameter arg must be >= -1\n", prog); @@ -463,7 +463,7 @@ int req_main(int argc, char **argv) break; case OPT_SET_SERIAL: if (serial != NULL) { - BIO_puts(bio_err, "Serial number supplied twice\n"); + BIO_printf(bio_err, "Serial number supplied twice\n"); goto opthelp; } serial = s2i_ASN1_INTEGER(NULL, opt_arg()); @@ -531,24 +531,24 @@ int req_main(int argc, char **argv) if (!gen_x509) { if (days != UNSET_DAYS) - BIO_puts(bio_err, "Warning: Ignoring -days without -x509; not generating a certificate\n"); + BIO_printf(bio_err, "Warning: Ignoring -days without -x509; not generating a certificate\n"); if (not_before != NULL) - BIO_puts(bio_err, "Warning: Ignoring -not_before without -x509; not generating a certificate\n"); + BIO_printf(bio_err, "Warning: Ignoring -not_before without -x509; not generating a certificate\n"); if (not_after != NULL) - BIO_puts(bio_err, "Warning: Ignoring -not_after without -x509; not generating a certificate\n"); + BIO_printf(bio_err, "Warning: Ignoring -not_after without -x509; not generating a certificate\n"); if (ext_copy == EXT_COPY_NONE) - BIO_puts(bio_err, "Warning: Ignoring -copy_extensions 'none' when -x509 is not given\n"); + BIO_printf(bio_err, "Warning: Ignoring -copy_extensions 'none' when -x509 is not given\n"); } if (infile == NULL) { if (gen_x509) newreq = 1; else if (!newreq && isatty(fileno_stdin())) - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: Will read cert request from stdin since no -in option is given\n"); } if (!app_passwd(passargin, passargout, &passin, &passout)) { - BIO_puts(bio_err, "Error getting passwords\n"); + BIO_printf(bio_err, "Error getting passwords\n"); goto end; } @@ -556,7 +556,7 @@ int req_main(int argc, char **argv) goto end; if (addext_bio != NULL) { if (verbose) - BIO_puts(bio_err, + BIO_printf(bio_err, "Using additional configuration from -addext options\n"); if ((addext_conf = app_load_config_bio(addext_bio, NULL)) == NULL) goto end; @@ -593,7 +593,7 @@ int req_main(int argc, char **argv) digest = p; } - if (extsect == NULL && !x509v1) + if (extsect == NULL) extsect = app_conf_try_string(req_conf, section, gen_x509 ? V3_EXTENSIONS : REQ_EXTENSIONS); if (extsect != NULL) { @@ -601,21 +601,24 @@ int req_main(int argc, char **argv) X509V3_CTX ctx; X509V3_set_ctx_test(&ctx); - if (!do_EXT_add_nconf(req_conf, req_conf, &ctx, NULL, - !gen_x509 - ? "Error checking request extension section %s\n" - : "Error checking x509 extension section %s\n", - extsect)) + X509V3_set_nconf(&ctx, req_conf); + if (!X509V3_EXT_add_nconf(req_conf, &ctx, extsect, NULL)) { + BIO_printf(bio_err, + "Error checking %s extension section %s\n", + gen_x509 ? "x509" : "request", extsect); goto end; + } } if (addext_conf != NULL) { /* Check syntax of command line extensions */ X509V3_CTX ctx; X509V3_set_ctx_test(&ctx); - if (!do_EXT_add_nconf(req_conf, addext_conf, &ctx, NULL, - "Error checking x509 extensions defined via -addext\n", NULL)) + X509V3_set_nconf(&ctx, req_conf); + if (!X509V3_EXT_add_nconf(addext_conf, &ctx, "default", NULL)) { + BIO_printf(bio_err, "Error checking extensions defined using -addext\n"); goto end; + } } if (passin == NULL) @@ -643,7 +646,7 @@ int req_main(int argc, char **argv) app_RAND_load_conf(req_conf, section); } if (keyalg != NULL && pkey != NULL) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: Not generating key via given -newkey option since -key is given\n"); /* Better throw an error in this case */ } @@ -710,13 +713,13 @@ int req_main(int argc, char **argv) if (pkey != NULL && (keyfile == NULL || keyout != NULL)) { if (verbose) { - BIO_puts(bio_out, "Writing private key to "); + BIO_printf(bio_err, "Writing private key to "); if (keyout == NULL) - BIO_puts(bio_out, "stdout\n"); + BIO_printf(bio_err, "stdout\n"); else - BIO_printf(bio_out, "'%s'\n", keyout); + BIO_printf(bio_err, "'%s'\n", keyout); } - out = bio_open_owner(keyout, outformat, 1); + out = bio_open_owner(keyout, outformat, newreq); if (out == NULL) goto end; @@ -741,7 +744,7 @@ int req_main(int argc, char **argv) } BIO_free_all(out); out = NULL; - BIO_puts(bio_err, "-----\n"); + BIO_printf(bio_err, "-----\n"); } /* @@ -754,14 +757,14 @@ int req_main(int argc, char **argv) if (!newreq) { if (keyfile != NULL) - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: Not placing -key in cert or request since request is used\n"); req = load_csr_autofmt(infile /* if NULL, reads from stdin */, informat, vfyopts, "X509 request"); if (req == NULL) goto end; } else if (infile != NULL) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: Ignoring -in option since -new or -newkey or -precert is given\n"); /* Better throw an error in this case, as done in the x509 app */ } @@ -770,7 +773,7 @@ int req_main(int argc, char **argv) CAkeyfile = CAfile; if (CAkeyfile != NULL) { if (CAfile == NULL) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: Ignoring -CAkey option since no -CA option is given\n"); } else { if ((CAkey = load_key(CAkeyfile, FORMAT_UNDEF, @@ -788,15 +791,15 @@ int req_main(int argc, char **argv) == NULL) goto end; if (!X509_check_private_key(CAcert, CAkey)) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Issuer CA certificate and key do not match\n"); goto end; } } if (newreq || gen_x509) { if (CAcert == NULL && pkey == NULL) { - BIO_puts(bio_err, "Must provide a signature key using -key or" - " provide -CA / -CAkey\n"); + BIO_printf(bio_err, "Must provide a signature key using -key or" + " provide -CA / -CAkey\n"); goto end; } @@ -807,7 +810,7 @@ int req_main(int argc, char **argv) } if (!make_REQ(req, pkey, fsubj, multirdn, !gen_x509, chtype)) { - BIO_puts(bio_err, "Error making certificate request\n"); + BIO_printf(bio_err, "Error making certificate request\n"); goto end; } /* Note that -x509 can take over -key and -subj option values. */ @@ -816,12 +819,11 @@ int req_main(int argc, char **argv) EVP_PKEY *pub_key = X509_REQ_get0_pubkey(req); EVP_PKEY *issuer_key = CAcert != NULL ? CAkey : pkey; X509V3_CTX ext_ctx; + X509_NAME *issuer = CAcert != NULL ? X509_get_subject_name(CAcert) : X509_REQ_get_subject_name(req); + X509_NAME *n_subj = fsubj != NULL ? fsubj : X509_REQ_get_subject_name(req); - const X509_NAME *n_subj = fsubj != NULL ? fsubj : X509_REQ_get_subject_name(req); - const X509_NAME *issuer = CAcert != NULL ? X509_get_subject_name(CAcert) - : X509_REQ_get_subject_name(req); if (CAcert != NULL && keyfile != NULL) - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: Not using -key or -newkey for signing since -CA option is given\n"); if ((new_x509 = X509_new_ex(app_get0_libctx(), @@ -842,7 +844,7 @@ int req_main(int argc, char **argv) if (days == UNSET_DAYS) days = DEFAULT_DAYS; else if (not_after != NULL) - BIO_puts(bio_err, "Warning: -not_after option overriding -days option\n"); + BIO_printf(bio_err, "Warning: -not_after option overriding -days option\n"); if (!set_cert_times(new_x509, not_before, not_after, days, 1)) goto end; if (!X509_set_subject_name(new_x509, n_subj)) @@ -851,41 +853,45 @@ int req_main(int argc, char **argv) goto end; if (ext_copy == EXT_COPY_UNSET) { if (infile != NULL) - BIO_puts(bio_err, "Warning: No -copy_extensions given; ignoring any extensions in the request\n"); + BIO_printf(bio_err, "Warning: No -copy_extensions given; ignoring any extensions in the request\n"); } else if (!copy_extensions(new_x509, req, ext_copy)) { - BIO_puts(bio_err, "Error copying extensions from request\n"); + BIO_printf(bio_err, "Error copying extensions from request\n"); goto end; } /* Set up V3 context struct */ X509V3_set_ctx(&ext_ctx, CAcert != NULL ? CAcert : new_x509, new_x509, NULL, NULL, X509V3_CTX_REPLACE); - /* prepare fallback for AKID, but only if issuer cert == new_x509 */ if (CAcert == NULL) { if (!X509V3_set_issuer_pkey(&ext_ctx, issuer_key)) goto end; if (!cert_matches_key(new_x509, issuer_key)) - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: Signature key and public key of cert do not match\n"); } + X509V3_set_nconf(&ext_ctx, req_conf); /* Add extensions */ if (extsect != NULL - && !do_EXT_add_nconf(req_conf, req_conf, &ext_ctx, new_x509, - "Error adding x509 extensions from section %s\n", extsect)) + && !X509V3_EXT_add_nconf(req_conf, &ext_ctx, extsect, new_x509)) { + BIO_printf(bio_err, "Error adding x509 extensions from section %s\n", + extsect); goto end; + } if (addext_conf != NULL - && !do_EXT_add_nconf(addext_conf, addext_conf, &ext_ctx, new_x509, - "Error adding x509 extensions defined via -addext\n", NULL)) + && !X509V3_EXT_add_nconf(addext_conf, &ext_ctx, "default", + new_x509)) { + BIO_printf(bio_err, "Error adding x509 extensions defined via -addext\n"); goto end; + } /* If a pre-cert was requested, we need to add a poison extension */ if (precert) { if (X509_add1_ext_i2d(new_x509, NID_ct_precert_poison, NULL, 1, 0) != 1) { - BIO_puts(bio_err, "Error adding poison extension\n"); + BIO_printf(bio_err, "Error adding poison extension\n"); goto end; } } @@ -898,21 +904,26 @@ int req_main(int argc, char **argv) X509V3_CTX ext_ctx; if (precert) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Warning: Ignoring -precert flag since no cert is produced\n"); } /* Set up V3 context struct */ X509V3_set_ctx(&ext_ctx, NULL, NULL, req, NULL, X509V3_CTX_REPLACE); + X509V3_set_nconf(&ext_ctx, req_conf); /* Add extensions */ if (extsect != NULL - && !do_EXT_REQ_add_nconf(req_conf, req_conf, &ext_ctx, req, - "Error adding request extensions from section %s\n", extsect)) + && !X509V3_EXT_REQ_add_nconf(req_conf, &ext_ctx, extsect, req)) { + BIO_printf(bio_err, "Error adding request extensions from section %s\n", + extsect); goto end; + } if (addext_conf != NULL - && !do_EXT_REQ_add_nconf(req_conf, addext_conf, &ext_ctx, req, - "Error adding request extensions defined via -addext\n", "default")) + && !X509V3_EXT_REQ_add_nconf(addext_conf, &ext_ctx, "default", + req)) { + BIO_printf(bio_err, "Error adding request extensions defined via -addext\n"); goto end; + } i = do_X509_REQ_sign(req, pkey, digest, sigopts); if (!i) goto end; @@ -921,12 +932,12 @@ int req_main(int argc, char **argv) if (subj != NULL && !newreq && !gen_x509) { if (verbose) { - BIO_puts(out, "Modifying subject of certificate request\n"); + BIO_printf(out, "Modifying subject of certificate request\n"); print_name(out, "Old subject=", X509_REQ_get_subject_name(req)); } if (!X509_REQ_set_subject_name(req, fsubj)) { - BIO_puts(bio_err, "Error modifying subject of certificate request\n"); + BIO_printf(bio_err, "Error modifying subject of certificate request\n"); goto end; } @@ -949,10 +960,10 @@ int req_main(int argc, char **argv) if (i < 0) goto end; if (i == 0) { - BIO_puts(bio_err, "Certificate request self-signature verify failure\n"); + BIO_printf(bio_err, "Certificate request self-signature verify failure\n"); goto end; } else /* i > 0 */ { - BIO_puts(bio_out, "Certificate request self-signature verify OK\n"); + BIO_printf(bio_out, "Certificate request self-signature verify OK\n"); } } @@ -971,7 +982,7 @@ int req_main(int argc, char **argv) EVP_PKEY *tpubkey = X509_REQ_get0_pubkey(req); if (tpubkey == NULL) { - BIO_puts(bio_err, "Error getting public key\n"); + BIO_printf(bio_err, "Error getting public key\n"); goto end; } PEM_write_bio_PUBKEY(out, tpubkey); @@ -985,9 +996,9 @@ int req_main(int argc, char **argv) if (ret == 0) { if (gen_x509) - BIO_puts(bio_err, "Error printing certificate\n"); + BIO_printf(bio_err, "Error printing certificate\n"); else - BIO_puts(bio_err, "Error printing certificate request\n"); + BIO_printf(bio_err, "Error printing certificate request\n"); goto end; } } @@ -1029,7 +1040,7 @@ int req_main(int argc, char **argv) else i = PEM_write_bio_X509_REQ(out, req); if (!i) { - BIO_puts(bio_err, "Unable to write certificate request\n"); + BIO_printf(bio_err, "Unable to write certificate request\n"); goto end; } } @@ -1039,7 +1050,7 @@ int req_main(int argc, char **argv) else i = PEM_write_bio_X509(out, new_x509); if (!i) { - BIO_puts(bio_err, "Unable to write X509 certificate\n"); + BIO_printf(bio_err, "Unable to write X509 certificate\n"); goto end; } } @@ -1061,7 +1072,7 @@ end: lh_OPENSSL_STRING_free(addexts); OPENSSL_free(keyalgstr); X509_REQ_free(req); - X509_NAME_free((X509_NAME *)fsubj); + X509_NAME_free(fsubj); X509_free(new_x509); X509_free(CAcert); EVP_PKEY_free(CAkey); @@ -1073,7 +1084,7 @@ end: return ret; } -static int make_REQ(X509_REQ *req, EVP_PKEY *pkey, const X509_NAME *fsubj, +static int make_REQ(X509_REQ *req, EVP_PKEY *pkey, X509_NAME *fsubj, int multirdn, int attribs, unsigned long chtype) { int ret = 0, i; @@ -1138,25 +1149,21 @@ static int prompt_info(X509_REQ *req, char *type, *value; const char *def; CONF_VALUE *v; - X509_NAME *subj; - int ret = 0; - - if ((subj = X509_NAME_new()) == NULL) - goto err; + X509_NAME *subj = X509_REQ_get_subject_name(req); if (!batch) { - BIO_puts(bio_err, + BIO_printf(bio_err, "You are about to be asked to enter information that will be incorporated\n"); - BIO_puts(bio_err, "into your certificate request.\n"); - BIO_puts(bio_err, + BIO_printf(bio_err, "into your certificate request.\n"); + BIO_printf(bio_err, "What you are about to enter is what is called a Distinguished Name or a DN.\n"); - BIO_puts(bio_err, + BIO_printf(bio_err, "There are quite a few fields but you can leave some blank\n"); - BIO_puts(bio_err, + BIO_printf(bio_err, "For some fields there will be a default value,\n"); - BIO_puts(bio_err, + BIO_printf(bio_err, "If you enter '.', the field will be left blank.\n"); - BIO_puts(bio_err, "-----\n"); + BIO_printf(bio_err, "-----\n"); } if (sk_CONF_VALUE_num(dn_sk)) { @@ -1193,44 +1200,40 @@ static int prompt_info(X509_REQ *req, if ((nid = OBJ_txt2nid(type)) == NID_undef) goto start; if (!join(buf, sizeof(buf), v->name, "_default", "Name")) - goto err; + return 0; if ((def = app_conf_try_string(req_conf, dn_sect, buf)) == NULL) def = ""; if (!join(buf, sizeof(buf), v->name, "_value", "Name")) - goto err; + return 0; if ((value = app_conf_try_string(req_conf, dn_sect, buf)) == NULL) value = NULL; if (!join(buf, sizeof(buf), v->name, "_min", "Name")) - goto err; + return 0; if (!app_conf_try_number(req_conf, dn_sect, buf, &n_min)) n_min = -1; if (!join(buf, sizeof(buf), v->name, "_max", "Name")) - goto err; + return 0; if (!app_conf_try_number(req_conf, dn_sect, buf, &n_max)) n_max = -1; if (!add_DN_object(subj, v->value, def, value, nid, n_min, n_max, chtype, mval)) - goto err; + return 0; } if (X509_NAME_entry_count(subj) == 0) { - BIO_puts(bio_err, "Error: No objects specified in config file\n"); - goto err; - } - - if (X509_REQ_set_subject_name(req, subj) == 0) { - BIO_printf(bio_err, "Error: Can't set subject name\n"); - goto err; + BIO_printf(bio_err, "Error: No objects specified in config file\n"); + return 0; } if (attribs) { if ((attr_sk != NULL) && (sk_CONF_VALUE_num(attr_sk) > 0) && (!batch)) { - BIO_puts(bio_err, - "\nPlease enter the following 'extra' attributes\n" + BIO_printf(bio_err, + "\nPlease enter the following 'extra' attributes\n"); + BIO_printf(bio_err, "to be sent with your certificate request\n"); } @@ -1253,34 +1256,31 @@ static int prompt_info(X509_REQ *req, def = ""; if (!join(buf, sizeof(buf), type, "_value", "Name")) - goto err; + return 0; value = app_conf_try_string(req_conf, attr_sect, buf); if (!join(buf, sizeof(buf), type, "_min", "Name")) - goto err; + return 0; if (!app_conf_try_number(req_conf, attr_sect, buf, &n_min)) n_min = -1; if (!join(buf, sizeof(buf), type, "_max", "Name")) - goto err; + return 0; if (!app_conf_try_number(req_conf, attr_sect, buf, &n_max)) n_max = -1; + if (!add_attribute_object(req, v->value, def, value, nid, n_min, n_max, chtype)) - goto err; + return 0; } } } else { - BIO_puts(bio_err, "No template, please set one up.\n"); - goto err; + BIO_printf(bio_err, "No template, please set one up.\n"); + return 0; } - ret = 1; - -err: - X509_NAME_free(subj); - return ret; + return 1; } static int auto_info(X509_REQ *req, STACK_OF(CONF_VALUE) *dn_sk, @@ -1292,10 +1292,8 @@ static int auto_info(X509_REQ *req, STACK_OF(CONF_VALUE) *dn_sk, char *type; CONF_VALUE *v; X509_NAME *subj; - int ret = 0; - if ((subj = X509_NAME_new()) == NULL) - goto err; + subj = X509_REQ_get_subject_name(req); for (i = 0; i < sk_CONF_VALUE_num(dn_sk); i++) { int mval; @@ -1333,11 +1331,11 @@ static int auto_info(X509_REQ *req, STACK_OF(CONF_VALUE) *dn_sk, if (!X509_NAME_add_entry_by_txt(subj, type, chtype, (unsigned char *)v->value, -1, -1, mval)) - goto err; + return 0; } if (!X509_NAME_entry_count(subj)) { - BIO_puts(bio_err, "Error: No objects specified in config file\n"); + BIO_printf(bio_err, "Error: No objects specified in config file\n"); return 0; } if (attribs) { @@ -1345,20 +1343,10 @@ static int auto_info(X509_REQ *req, STACK_OF(CONF_VALUE) *dn_sk, v = sk_CONF_VALUE_value(attr_sk, i); if (!X509_REQ_add1_attr_by_txt(req, v->name, chtype, (unsigned char *)v->value, -1)) - goto err; + return 0; } } - - if (X509_REQ_set_subject_name(req, subj) == 0) { - BIO_printf(bio_err, "Error: Can't set subject name\n"); - goto err; - } - - ret = 1; - -err: - X509_NAME_free(subj); - return ret; + return 1; } static int add_DN_object(X509_NAME *n, char *text, const char *def, @@ -1396,7 +1384,7 @@ static int add_attribute_object(X509_REQ *req, char *text, const char *def, if (!X509_REQ_add1_attr_by_NID(req, nid, chtype, (unsigned char *)buf, -1)) { - BIO_puts(bio_err, "Error adding attribute\n"); + BIO_printf(bio_err, "Error adding attribute\n"); ret = 0; } @@ -1440,7 +1428,7 @@ start: i = (int)strlen(buf); if (buf[i - 1] != '\n') { - BIO_puts(bio_err, "Missing newline at end of input\n"); + BIO_printf(bio_err, "Missing newline at end of input\n"); return 0; } buf[--i] = '\0'; @@ -1604,7 +1592,7 @@ static EVP_PKEY_CTX *set_keygen_ctx(const char *gstr, *pkeytype = OPENSSL_strdup(keytype); if (*pkeytype == NULL) { - BIO_puts(bio_err, "Out of memory\n"); + BIO_printf(bio_err, "Out of memory\n"); EVP_PKEY_free(param); return NULL; } @@ -1614,7 +1602,7 @@ static EVP_PKEY_CTX *set_keygen_ctx(const char *gstr, if (param != NULL) { if (!EVP_PKEY_is_a(param, *pkeytype)) { - BIO_puts(bio_err, "Key type does not match parameters\n"); + BIO_printf(bio_err, "Key type does not match parameters\n"); EVP_PKEY_free(param); return NULL; } diff --git a/apps/rsa.c b/apps/rsa.c index c6eea728b4..6cdffd1eae 100644 --- a/apps/rsa.c +++ b/apps/rsa.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -233,11 +233,11 @@ int rsa_main(int argc, char **argv) private = (text && !pubin) || (!pubout && !noout); if (!app_passwd(passinarg, passoutarg, &passin, &passout)) { - BIO_puts(bio_err, "Error getting passwords\n"); + BIO_printf(bio_err, "Error getting passwords\n"); goto end; } if (check && pubin) { - BIO_puts(bio_err, "Only private keys can be checked\n"); + BIO_printf(bio_err, "Only private keys can be checked\n"); goto end; } @@ -263,7 +263,7 @@ int rsa_main(int argc, char **argv) goto end; } if (!EVP_PKEY_is_a(pkey, "RSA") && !EVP_PKEY_is_a(pkey, "RSA-PSS")) { - BIO_puts(bio_err, "Not an RSA key\n"); + BIO_printf(bio_err, "Not an RSA key\n"); goto end; } @@ -286,9 +286,9 @@ int rsa_main(int argc, char **argv) /* Every RSA key has an 'n' */ EVP_PKEY_get_bn_param(pkey, "n", &n); - BIO_puts(out, "Modulus="); + BIO_printf(out, "Modulus="); BN_print(out, n); - BIO_puts(out, "\n"); + BIO_printf(out, "\n"); BN_free(n); } @@ -297,7 +297,7 @@ int rsa_main(int argc, char **argv) pctx = EVP_PKEY_CTX_new_from_pkey(NULL, pkey, NULL); if (pctx == NULL) { - BIO_puts(bio_err, "RSA unable to create PKEY context\n"); + BIO_printf(bio_err, "RSA unable to create PKEY context\n"); ERR_print_errors(bio_err); goto end; } @@ -305,9 +305,9 @@ int rsa_main(int argc, char **argv) EVP_PKEY_CTX_free(pctx); if (r == 1) { - BIO_puts(out, "RSA key ok\n"); + BIO_printf(out, "RSA key ok\n"); } else if (r == 0) { - BIO_puts(bio_err, "RSA key not ok\n"); + BIO_printf(bio_err, "RSA key not ok\n"); ERR_print_errors(bio_err); } else if (r < 0) { ERR_print_errors(bio_err); @@ -319,7 +319,7 @@ int rsa_main(int argc, char **argv) ret = 0; goto end; } - BIO_puts(bio_err, "writing RSA key\n"); + BIO_printf(bio_err, "writing RSA key\n"); /* Choose output type for the format */ if (outformat == FORMAT_ASN1) { @@ -330,12 +330,12 @@ int rsa_main(int argc, char **argv) output_type = "MSBLOB"; } else if (outformat == FORMAT_PVK) { if (pubin) { - BIO_puts(bio_err, "PVK form impossible with public key input\n"); + BIO_printf(bio_err, "PVK form impossible with public key input\n"); goto end; } output_type = "PVK"; } else { - BIO_puts(bio_err, "bad output format specified for outfile\n"); + BIO_printf(bio_err, "bad output format specified for outfile\n"); goto end; } @@ -397,13 +397,13 @@ int rsa_main(int argc, char **argv) params[0] = OSSL_PARAM_construct_int("encrypt-level", &pvk_encr); if (!OSSL_ENCODER_CTX_set_params(ectx, params)) { - BIO_puts(bio_err, "invalid PVK encryption level\n"); + BIO_printf(bio_err, "invalid PVK encryption level\n"); goto end; } } if (!OSSL_ENCODER_to_bio(ectx, out)) { - BIO_puts(bio_err, "unable to write key\n"); + BIO_printf(bio_err, "unable to write key\n"); ERR_print_errors(bio_err); goto end; } diff --git a/apps/rsautl.c b/apps/rsautl.c index 8bbce5c83a..e54b1812f2 100644 --- a/apps/rsautl.c +++ b/apps/rsautl.c @@ -1,5 +1,5 @@ /* - * Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -184,12 +184,12 @@ int rsautl_main(int argc, char **argv) goto end; if (need_priv && (key_type != KEY_PRIVKEY)) { - BIO_puts(bio_err, "A private key is needed for this operation\n"); + BIO_printf(bio_err, "A private key is needed for this operation\n"); goto end; } if (!app_passwd(passinarg, NULL, &passin, NULL)) { - BIO_puts(bio_err, "Error getting password\n"); + BIO_printf(bio_err, "Error getting password\n"); goto end; } @@ -230,7 +230,7 @@ int rsautl_main(int argc, char **argv) /* Read the input data */ rv = BIO_read(in, rsa_in, keysize * 2); if (rv < 0) { - BIO_puts(bio_err, "Error reading input Data\n"); + BIO_printf(bio_err, "Error reading input Data\n"); goto end; } rsa_inlen = rv; @@ -274,7 +274,7 @@ int rsautl_main(int argc, char **argv) } if (!rv) { - BIO_puts(bio_err, "RSA operation error\n"); + BIO_printf(bio_err, "RSA operation error\n"); ERR_print_errors(bio_err); goto end; } diff --git a/apps/s_client.c b/apps/s_client.c index 65aff3eb42..55e8b02256 100644 --- a/apps/s_client.c +++ b/apps/s_client.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright 2005 Nokia. All rights reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -9,7 +9,6 @@ */ #include "internal/e_os.h" -#include #include #include #include @@ -108,14 +107,6 @@ static int keymatexportlen = 20; static BIO *bio_c_out = NULL; static int c_quiet = 0; static char *sess_out = NULL; -#ifndef OPENSSL_NO_ECH -static char *ech_config_list = NULL, *ech_grease_suite = NULL; -static const char *sni_outer_name = NULL; -static int ech_grease = 0, ech_ignore_cid = 0; -static int ech_select = OSSL_ECHSTORE_ALL; -static int ech_grease_type = OSSL_ECH_CURRENT_VERSION; -static int ech_no_outer_sni = 0; -#endif static SSL_SESSION *psksess = NULL; static void print_stuff(BIO *berr, SSL *con, int full); @@ -158,11 +149,11 @@ static unsigned int psk_client_cb(SSL *ssl, const char *hint, char *identity, unsigned char *key; if (c_debug) - BIO_puts(bio_c_out, "psk_client_cb\n"); + BIO_printf(bio_c_out, "psk_client_cb\n"); if (!hint) { /* no ServerKeyExchange message */ if (c_debug) - BIO_puts(bio_c_out, + BIO_printf(bio_c_out, "NULL received PSK identity hint, continuing anyway\n"); } else if (c_debug) { BIO_printf(bio_c_out, "Received PSK identity hint '%s'\n", hint); @@ -187,7 +178,7 @@ static unsigned int psk_client_cb(SSL *ssl, const char *hint, char *identity, } if (max_psk_len > INT_MAX || key_len > (long)max_psk_len) { BIO_printf(bio_err, - "psk buffer of callback is too small (%u) for key (%ld)\n", + "psk buffer of callback is too small (%d) for key (%ld)\n", max_psk_len, key_len); OPENSSL_free(key); return 0; @@ -202,7 +193,7 @@ static unsigned int psk_client_cb(SSL *ssl, const char *hint, char *identity, return key_len; out_err: if (c_debug) - BIO_puts(bio_err, "Error in PSK client callback\n"); + BIO_printf(bio_err, "Error in PSK client callback\n"); return 0; } #endif @@ -234,7 +225,7 @@ static int psk_use_session_cb(SSL *s, const EVP_MD *md, /* We default to SHA-256 */ cipher = SSL_CIPHER_find(s, tls13_aes128gcmsha256_id); if (cipher == NULL) { - BIO_puts(bio_err, "Error finding suitable ciphersuite\n"); + BIO_printf(bio_err, "Error finding suitable ciphersuite\n"); OPENSSL_free(key); return 0; } @@ -286,7 +277,7 @@ static int ssl_servername_cb(SSL *s, int *ad, void *arg) if (SSL_get_servername_type(s) != -1) p->ack = !SSL_session_reused(s) && hn != NULL; else - BIO_puts(bio_err, "Can't use SSL_get_servername\n"); + BIO_printf(bio_err, "Can't use SSL_get_servername\n"); return SSL_TLSEXT_ERR_OK; } @@ -310,7 +301,7 @@ static int next_proto_cb(SSL *s, unsigned char **out, unsigned char *outlen, if (!c_quiet) { /* We can assume that |in| is syntactically valid. */ unsigned i; - BIO_puts(bio_c_out, "Protocols advertised by server: "); + BIO_printf(bio_c_out, "Protocols advertised by server: "); for (i = 0; i < inlen;) { if (i) BIO_write(bio_c_out, ", ", 2); @@ -341,7 +332,7 @@ static int serverinfo_cli_parse_cb(SSL *s, unsigned int ext_type, ext_buf[3] = (unsigned char)(inlen); memcpy(ext_buf + 4, in, inlen); - BIO_snprintf(pem_name, sizeof(pem_name), "SERVERINFO FOR EXTENSION %u", + BIO_snprintf(pem_name, sizeof(pem_name), "SERVERINFO FOR EXTENSION %d", ext_type); PEM_write_bio(bio_c_out, pem_name, "", ext_buf, (long)(4 + inlen)); return 1; @@ -355,22 +346,15 @@ static ossl_ssize_t hexdecode(const char **inptr, void *result) { unsigned char **out = (unsigned char **)result; const char *in = *inptr; - size_t retlen = strlen(in) / 2; - unsigned char *ret = NULL, *cp; + unsigned char *ret = app_malloc(strlen(in) / 2, "hexdecode"); + unsigned char *cp = ret; uint8_t byte; int nibble = 0; - if (retlen > 0) { - if ((ret = app_malloc(retlen, "hexdecode")) == NULL) - return -1; - } else if (*in == '\0') { - *out = NULL; - return 0; - } else { + if (ret == NULL) return -1; - } - for (cp = ret, byte = 0; *in; ++in) { + for (byte = 0; *in; ++in) { int x; if (isspace(_UC(*in))) @@ -441,7 +425,9 @@ static int tlsa_import_rr(SSL *con, const char *rrdata) { &selector, "selector", checked_uint8 }, { &mtype, "mtype", checked_uint8 }, { &data, "data", hexdecode }, - { NULL, NULL, NULL }, + { + NULL, + } }; struct tlsa_field *f; int ret; @@ -544,6 +530,7 @@ typedef enum OPTION_choice { OPT_SRP_LATEUSER, OPT_SRP_MOREGROUPS, #endif + OPT_SSL3, OPT_SSL_CONFIG, OPT_TLS1_3, OPT_TLS1_2, @@ -599,7 +586,6 @@ typedef enum OPTION_choice { OPT_S_ENUM, OPT_IGNORE_UNEXPECTED_EOF, OPT_FALLBACKSCSV, - OPT_GREASE, OPT_NOCMDS, OPT_ADV, OPT_PROXY, @@ -616,20 +602,8 @@ typedef enum OPTION_choice { OPT_ENABLE_PHA, OPT_ENABLE_SERVER_RPK, OPT_ENABLE_CLIENT_RPK, - OPT_EXPECTED_RPK, OPT_SCTP_LABEL_BUG, OPT_KTLS, -#ifndef OPENSSL_NO_ECH - OPT_ECHCONFIGLIST, - OPT_SNIOUTER, - OPT_ALPN_OUTER, - OPT_ECH_SELECT, - OPT_ECH_IGNORE_CONFIG_ID, - OPT_ECH_GREASE, - OPT_ECH_GREASE_SUITE, - OPT_ECH_GREASE_TYPE, - OPT_ECH_NO_OUTER_SNI, -#endif OPT_R_ENUM, OPT_PROV_ENUM } OPTION_CHOICE; @@ -673,7 +647,6 @@ const OPTIONS s_client_options[] = { { "read_buf", OPT_READ_BUF, 'p', "Default read buffer size to be used for connections" }, { "fallback_scsv", OPT_FALLBACKSCSV, '-', "Send the fallback SCSV" }, - { "grease", OPT_GREASE, '-', "Send GREASE values in ClientHello (RFC 8701)" }, OPT_SECTION("Identity"), { "cert", OPT_CERT, '<', "Client certificate file to use" }, @@ -685,11 +658,11 @@ const OPTIONS s_client_options[] = { { "key", OPT_KEY, 's', "Private key file to use; default: -cert file" }, { "keyform", OPT_KEYFORM, 'f', "Key format (DER/PEM)" }, { "pass", OPT_PASS, 's', "Private key and cert file pass phrase source" }, - { "verify", OPT_VERIFY, 'p', "Turn on peer certificate verification, set depth" }, + { "verify", OPT_VERIFY, 'p', "Turn on peer certificate verification" }, { "nameopt", OPT_NAMEOPT, 's', "Certificate subject/issuer name printing options" }, - { "CAfile", OPT_CAFILE, '<', "File in PEM format with trusted CA certs" }, - { "CApath", OPT_CAPATH, '/', "Dir with trusted CA cert files in PEM format" }, - { "CAstore", OPT_CASTORE, ':', "URI of store with trusted CA certs" }, + { "CApath", OPT_CAPATH, '/', "PEM format directory of CA's" }, + { "CAfile", OPT_CAFILE, '<', "PEM format file of CA's" }, + { "CAstore", OPT_CASTORE, ':', "URI to store of CA's" }, { "no-CAfile", OPT_NOCAFILE, '-', "Do not load the default certificates file" }, { "no-CApath", OPT_NOCAPATH, '-', @@ -698,8 +671,6 @@ const OPTIONS s_client_options[] = { "Do not load certificates from the default certificates store" }, { "requestCAfile", OPT_REQCAFILE, '<', "PEM format file of CA names to send to the server" }, - { "expected-rpks", OPT_EXPECTED_RPK, '<', - "PEM file with expected server public key(s)" }, #if defined(TCP_FASTOPEN) && !defined(OPENSSL_NO_TFO) { "tfo", OPT_TFO, '-', "Connect using TCP Fast Open" }, #endif @@ -789,6 +760,9 @@ const OPTIONS s_client_options[] = { { "nbio", OPT_NBIO, '-', "Use non-blocking IO" }, OPT_SECTION("Protocol and version"), +#ifndef OPENSSL_NO_SSL3 + { "ssl3", OPT_SSL3, '-', "Just use SSLv3" }, +#endif #ifndef OPENSSL_NO_TLS1 { "tls1", OPT_TLS1, '-', "Just use TLSv1" }, #endif @@ -830,27 +804,6 @@ const OPTIONS s_client_options[] = { { "use_srtp", OPT_USE_SRTP, 's', "Offer SRTP key management with a colon-separated profile list" }, #endif - -#ifndef OPENSSL_NO_ECH - { "ech_config_list", OPT_ECHCONFIGLIST, 's', - "Set ECHConfigList, value is base64-encoded ECHConfigList" }, - { "ech_outer_alpn", OPT_ALPN_OUTER, 's', - "Specify outer ALPN value, when using ECH (comma-separated list)" }, - { "ech_outer_sni", OPT_SNIOUTER, 's', - "The name to put in the outer CH when overriding the server's choice" }, - { "ech_no_outer_sni", OPT_ECH_NO_OUTER_SNI, '-', - "Do not send the server name (SNI) extension in the outer ClientHello" }, - { "ech_select", OPT_ECH_SELECT, 'n', - "Select one ECHConfig from the set provided via -ech_config_list" }, - { "ech_grease", OPT_ECH_GREASE, '-', - "Send GREASE values when not really using ECH" }, - { "ech_grease_suite", OPT_ECH_GREASE_SUITE, 's', - "Use this HPKE suite for GREASE values when not really using ECH" }, - { "ech_grease_type", OPT_ECH_GREASE_TYPE, 'n', - "Use this TLS extension type for GREASE values when not really using ECH" }, - { "ech_ignore_cid", OPT_ECH_IGNORE_CONFIG_ID, '-', - "Ignore the server-chosen ECH config ID and send a random value" }, -#endif #ifndef OPENSSL_NO_SRP { "srpuser", OPT_SRPUSER, 's', "(deprecated) SRP authentication for 'user'" }, { "srppass", OPT_SRPPASS, 's', "(deprecated) Password for 'user'" }, @@ -875,21 +828,17 @@ const OPTIONS s_client_options[] = { "Close connection on verification error" }, { "verify_quiet", OPT_VERIFY_QUIET, '-', "Restrict verify output to errors" }, { "chainCAfile", OPT_CHAINCAFILE, '<', - "File in PEM format with trusted CA certs to build own cert chain" }, + "CA file for certificate chain (PEM format)" }, { "chainCApath", OPT_CHAINCAPATH, '/', - "Dir with trusted CA cert files in PEM format to build own cert chain" }, + "Use dir as certificate store path to build CA certificate chain" }, { "chainCAstore", OPT_CHAINCASTORE, ':', - "URI of trusted CA cert store to build own cert chain" }, - { OPT_MORE_STR, 0, 0, - "NOTE: these override -CApath, -CAfile, and -CAstore for client chain building" }, + "CA store URI for certificate chain" }, { "verifyCAfile", OPT_VERIFYCAFILE, '<', - "File in PEM format with trusted CA certs for server cert verification" }, + "CA file for certificate verification (PEM format)" }, { "verifyCApath", OPT_VERIFYCAPATH, '/', - "Dir with trusted CA cert files in PEM format for server cert verification" }, + "Use dir as certificate store path to verify CA certificate" }, { "verifyCAstore", OPT_VERIFYCASTORE, ':', - "URI of trusted CA cert store for server cert verification" }, - { OPT_MORE_STR, 0, 0, - "NOTE: these override -CApath, -CAfile, and -CAstore for server cert verification" }, + "CA store URI for certificate verification" }, OPT_X_OPTIONS, OPT_PROV_OPTIONS, @@ -939,7 +888,7 @@ static const OPT_PAIR services[] = { #define IS_UNIX_FLAG(o) (o == OPT_UNIX) #define IS_PROT_FLAG(o) \ - (o == OPT_TLS1 || o == OPT_TLS1_1 || o == OPT_TLS1_2 \ + (o == OPT_SSL3 || o == OPT_TLS1 || o == OPT_TLS1_1 || o == OPT_TLS1_2 \ || o == OPT_TLS1_3 || o == OPT_DTLS || o == OPT_DTLS1 || o == OPT_DTLS1_2 \ || o == OPT_QUIC) @@ -971,10 +920,10 @@ static int new_session_cb(SSL *s, SSL_SESSION *sess) * arrival of the NewSessionTicket for TLSv1.3. */ if (SSL_version(s) == TLS1_3_VERSION) { - BIO_puts(bio_c_out, + BIO_printf(bio_c_out, "---\nPost-Handshake New Session Ticket arrived:\n"); SSL_SESSION_print(bio_c_out, sess); - BIO_puts(bio_c_out, "---\n"); + BIO_printf(bio_c_out, "---\n"); } /* @@ -996,7 +945,6 @@ int s_client_main(int argc, char **argv) SSL_EXCERT *exc = NULL; SSL_CONF_CTX *cctx = NULL; STACK_OF(OPENSSL_STRING) *ssl_args = NULL; - STACK_OF(OPENSSL_STRING) *rpk_files = NULL; char *dane_tlsa_domain = NULL; STACK_OF(OPENSSL_STRING) *dane_tlsa_rrset = NULL; int dane_ee_no_name = 0; @@ -1038,7 +986,6 @@ int s_client_main(int argc, char **argv) #endif int read_buf_len = 0; int fallback_scsv = 0; - int grease = 0; OPTION_CHOICE o; #ifndef OPENSSL_NO_DTLS int enable_timeouts = 0; @@ -1047,15 +994,10 @@ int s_client_main(int argc, char **argv) #if defined(OPENSSL_SYS_WINDOWS) || defined(OPENSSL_SYS_MSDOS) struct timeval tv; #endif - char *servername = NULL; + const char *servername = NULL; char *sname_alloc = NULL; int noservername = 0; const char *alpn_in = NULL; -#ifndef OPENSSL_NO_ECH - const char *alpn_outer_in = NULL; - int rv = 0; - OSSL_ECHSTORE *es = NULL; -#endif tlsextctx tlsextcbp = { NULL, 0 }; const char *ssl_config = NULL; #define MAX_SI_TYPES 100 @@ -1155,13 +1097,13 @@ int s_client_main(int argc, char **argv) } if (IS_PROT_FLAG(o) && ++prot_opt > 1) { - BIO_puts(bio_err, "Cannot supply multiple protocol flags\n"); + BIO_printf(bio_err, "Cannot supply multiple protocol flags\n"); goto end; } if (IS_NO_PROT_FLAG(o)) no_prot_opt++; if (prot_opt == 1 && no_prot_opt) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Cannot supply both a protocol flag and '-no_'\n"); goto end; } @@ -1226,7 +1168,7 @@ int s_client_main(int argc, char **argv) break; case OPT_VERIFY: verify = SSL_VERIFY_PEER; - verify_args.depth = opt_int_arg(); + verify_args.depth = atoi(opt_arg()); if (!c_quiet) BIO_printf(bio_err, "verify depth is %d\n", verify_args.depth); break; @@ -1407,7 +1349,7 @@ int s_client_main(int argc, char **argv) min_version = TLS1_VERSION; break; case OPT_SRP_STRENGTH: - srp_arg.strength = opt_int_arg(); + srp_arg.strength = atoi(opt_arg()); BIO_printf(bio_err, "SRP minimal length for N is %d\n", srp_arg.strength); if (min_version < TLS1_VERSION) @@ -1427,6 +1369,15 @@ int s_client_main(int argc, char **argv) case OPT_SSL_CONFIG: ssl_config = opt_arg(); break; + case OPT_SSL3: + min_version = SSL3_VERSION; + max_version = SSL3_VERSION; + socket_type = SOCK_STREAM; +#ifndef OPENSSL_NO_DTLS + isdtls = 0; +#endif + isquic = 0; + break; case OPT_TLS1_3: min_version = TLS1_3_VERSION; max_version = TLS1_3_VERSION; @@ -1526,9 +1477,6 @@ int s_client_main(int argc, char **argv) case OPT_FALLBACKSCSV: fallback_scsv = 1; break; - case OPT_GREASE: - grease = 1; - break; case OPT_KEYFORM: if (!opt_format(opt_arg(), OPT_FMT_ANY, &key_format)) goto opthelp; @@ -1642,41 +1590,6 @@ int s_client_main(int argc, char **argv) case OPT_SERVERNAME: servername = opt_arg(); break; -#ifndef OPENSSL_NO_ECH - case OPT_ECHCONFIGLIST: - ech_config_list = opt_arg(); - break; - case OPT_ALPN_OUTER: - alpn_outer_in = opt_arg(); - break; - case OPT_SNIOUTER: - sni_outer_name = opt_arg(); - break; - case OPT_ECH_SELECT: - ech_select = opt_int_arg(); - break; - case OPT_ECH_GREASE: - ech_grease = 1; - break; - case OPT_ECH_GREASE_SUITE: - ech_grease_suite = opt_arg(); - break; - case OPT_ECH_GREASE_TYPE: - ech_grease_type = opt_int_arg(); - if (ech_grease_type != (ech_grease_type & 0xFFFF)) { - BIO_printf(bio_err, - "%s: invalid GREASE ECH type 0x%8x\n permitted values are 0-FFFF", - prog, ech_grease_type); - goto opthelp; - } - break; - case OPT_ECH_IGNORE_CONFIG_ID: - ech_ignore_cid = 1; - break; - case OPT_ECH_NO_OUTER_SNI: - ech_no_outer_sni = 1; - break; -#endif case OPT_NOSERVERNAME: noservername = 1; break; @@ -1689,13 +1602,13 @@ int s_client_main(int argc, char **argv) keymatexportlabel = opt_arg(); break; case OPT_KEYMATEXPORTLEN: - keymatexportlen = opt_int_arg(); + keymatexportlen = atoi(opt_arg()); break; case OPT_ASYNC: async = 1; break; case OPT_MAXFRAGLEN: - len = opt_int_arg(); + len = atoi(opt_arg()); switch (len) { case 512: maxfraglen = TLSEXT_max_fragment_length_512; @@ -1711,22 +1624,22 @@ int s_client_main(int argc, char **argv) break; default: BIO_printf(bio_err, - "%s: Max Fragment Len %d is out of permitted values", + "%s: Max Fragment Len %u is out of permitted values", prog, len); goto opthelp; } break; case OPT_MAX_SEND_FRAG: - max_send_fragment = opt_int_arg(); + max_send_fragment = atoi(opt_arg()); break; case OPT_SPLIT_SEND_FRAG: - split_send_fragment = opt_int_arg(); + split_send_fragment = atoi(opt_arg()); break; case OPT_MAX_PIPELINES: - max_pipelines = opt_int_arg(); + max_pipelines = atoi(opt_arg()); break; case OPT_READ_BUF: - read_buf_len = opt_int_arg(); + read_buf_len = atoi(opt_arg()); break; case OPT_KEYLOG_FILE: keylog_file = opt_arg(); @@ -1748,13 +1661,6 @@ int s_client_main(int argc, char **argv) case OPT_ENABLE_CLIENT_RPK: enable_client_rpk = 1; break; - case OPT_EXPECTED_RPK: - if ((rpk_files == NULL - && (rpk_files = sk_OPENSSL_STRING_new_null()) == NULL) - || !sk_OPENSSL_STRING_push(rpk_files, opt_arg())) - goto end; - enable_server_rpk = 1; - break; } } @@ -1796,20 +1702,10 @@ int s_client_main(int argc, char **argv) goto opthelp; } } -#ifndef OPENSSL_NO_ECH - if ((alpn_outer_in != NULL || sni_outer_name != NULL - || ech_no_outer_sni == 1) - && ech_config_list == NULL) { - BIO_printf(bio_err, "%s: Can't use -ech_outer_sni nor " - "-ech_outer_alpn nor -no_ech_outer_sni without " - "-ech_config_list\n", - prog); - goto opthelp; - } -#endif + #ifndef OPENSSL_NO_NEXTPROTONEG if (min_version == TLS1_3_VERSION && next_proto_neg_in != NULL) { - BIO_puts(bio_err, "Cannot supply -nextprotoneg with TLSv1.3\n"); + BIO_printf(bio_err, "Cannot supply -nextprotoneg with TLSv1.3\n"); goto opthelp; } #endif @@ -1888,7 +1784,7 @@ int s_client_main(int argc, char **argv) #ifdef AF_UNIX if (socket_family == AF_UNIX && socket_type != SOCK_STREAM) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Can't use unix sockets and datagrams together\n"); goto end; } @@ -1897,7 +1793,7 @@ int s_client_main(int argc, char **argv) #ifndef OPENSSL_NO_SCTP if (protocol == IPPROTO_SCTP) { if (socket_type != SOCK_DGRAM) { - BIO_puts(bio_err, "Can't use -sctp without DTLS\n"); + BIO_printf(bio_err, "Can't use -sctp without DTLS\n"); goto end; } /* SCTP is unusual. It uses DTLS over a SOCK_STREAM protocol */ @@ -1910,7 +1806,7 @@ int s_client_main(int argc, char **argv) if (next_proto_neg_in) { next_proto.data = next_protos_parse(&next_proto.len, next_proto_neg_in); if (next_proto.data == NULL) { - BIO_puts(bio_err, "Error parsing -nextprotoneg argument\n"); + BIO_printf(bio_err, "Error parsing -nextprotoneg argument\n"); goto end; } } else @@ -1918,17 +1814,17 @@ int s_client_main(int argc, char **argv) #endif if (!app_passwd(passarg, NULL, &pass, NULL)) { - BIO_puts(bio_err, "Error getting private key password\n"); + BIO_printf(bio_err, "Error getting private key password\n"); goto end; } if (!app_passwd(proxypassarg, NULL, &proxypass, NULL)) { - BIO_puts(bio_err, "Error getting proxy password\n"); + BIO_printf(bio_err, "Error getting proxy password\n"); goto end; } if (proxypass != NULL && proxyuser == NULL) { - BIO_puts(bio_err, "Error: Must specify proxy_user with proxy_pass\n"); + BIO_printf(bio_err, "Error: Must specify proxy_user with proxy_pass\n"); goto end; } @@ -1976,7 +1872,7 @@ int s_client_main(int argc, char **argv) if (c_msg && bio_c_msg == NULL) { bio_c_msg = dup_bio_out(FORMAT_TEXT); if (bio_c_msg == NULL) { - BIO_puts(bio_err, "Out of memory\n"); + BIO_printf(bio_err, "Out of memory\n"); goto end; } } @@ -1985,13 +1881,13 @@ int s_client_main(int argc, char **argv) } if (bio_c_out == NULL) { - BIO_puts(bio_err, "Unable to create BIO\n"); + BIO_printf(bio_err, "Unable to create BIO\n"); goto end; } } #ifndef OPENSSL_NO_SRP if (!app_passwd(srppass, NULL, &srp_arg.srppassin, NULL)) { - BIO_puts(bio_err, "Error getting password\n"); + BIO_printf(bio_err, "Error getting password\n"); goto end; } #endif @@ -2035,15 +1931,8 @@ int s_client_main(int argc, char **argv) SSL_CTX_set_options(ctx, SSL_OP_ENABLE_KTLS); #endif -#ifndef OPENSSL_NO_ECH - if (ech_grease != 0) - SSL_CTX_set_options(ctx, SSL_OP_ECH_GREASE); - if (ech_ignore_cid != 0) - SSL_CTX_set_options(ctx, SSL_OP_ECH_IGNORE_CID); -#endif - if (vpmtouched && !SSL_CTX_set1_param(ctx, vpm)) { - BIO_puts(bio_err, "Error setting verify params\n"); + BIO_printf(bio_err, "Error setting verify params\n"); goto end; } @@ -2089,7 +1978,7 @@ int s_client_main(int argc, char **argv) vfyCApath, vfyCAfile, vfyCAstore, chCApath, chCAfile, chCAstore, crls, crl_download)) { - BIO_puts(bio_err, "Error loading store locations for server cert verification and client cert chain building\n"); + BIO_printf(bio_err, "Error loading store locations\n"); goto end; } if (ReqCAfile != NULL) { @@ -2097,7 +1986,7 @@ int s_client_main(int argc, char **argv) if (nm == NULL || !SSL_add_file_cert_subjects_to_stack(nm, ReqCAfile)) { sk_X509_NAME_pop_free(nm, X509_NAME_free); - BIO_puts(bio_err, "Error loading CA names\n"); + BIO_printf(bio_err, "Error loading CA names\n"); goto end; } SSL_CTX_set0_CA_list(ctx, nm); @@ -2106,7 +1995,7 @@ int s_client_main(int argc, char **argv) #ifndef OPENSSL_NO_PSK if (psk_key != NULL) { if (c_debug) - BIO_puts(bio_c_out, "PSK key given, setting client callback\n"); + BIO_printf(bio_c_out, "PSK key given, setting client callback\n"); SSL_CTX_set_psk_client_callback(ctx, psk_client_cb); } #endif @@ -2131,7 +2020,7 @@ int s_client_main(int argc, char **argv) if (srtp_profiles != NULL) { /* Returns 0 on success! */ if (SSL_CTX_set_tlsext_use_srtp(ctx, srtp_profiles) != 0) { - BIO_puts(bio_err, "Error setting SRTP profile\n"); + BIO_printf(bio_err, "Error setting SRTP profile\n"); goto end; } } @@ -2149,12 +2038,12 @@ int s_client_main(int argc, char **argv) unsigned char *alpn = next_protos_parse(&alpn_len, alpn_in); if (alpn == NULL) { - BIO_puts(bio_err, "Error parsing -alpn argument\n"); + BIO_printf(bio_err, "Error parsing -alpn argument\n"); goto end; } /* Returns 0 on success! */ if (SSL_CTX_set_alpn_protos(ctx, alpn, (unsigned int)alpn_len) != 0) { - BIO_puts(bio_err, "Error setting ALPN\n"); + BIO_printf(bio_err, "Error setting ALPN\n"); goto end; } OPENSSL_free(alpn); @@ -2197,10 +2086,8 @@ int s_client_main(int argc, char **argv) SSL_CTX_set_verify(ctx, verify, verify_callback); if (!ctx_set_verify_locations(ctx, CAfile, noCAfile, CApath, noCApath, - CAstore, noCAstore)) { - BIO_puts(bio_err, "Error setting default locations for trusted certificates\n"); + CAstore, noCAstore)) goto end; - } ssl_ctx_add_crls(ctx, crls, crl_download); @@ -2220,12 +2107,9 @@ int s_client_main(int argc, char **argv) if (dane_tlsa_domain != NULL) { if (SSL_CTX_dane_enable(ctx) <= 0) { - BIO_printf(bio_err, "%s: Error enabling DANE TLSA authentication.\n", prog); - goto end; - } - } else if (rpk_files != NULL) { - if (SSL_CTX_dane_enable(ctx) <= 0) { - BIO_printf(bio_err, "%s: Error enabling RPK verification\n", prog); + BIO_printf(bio_err, + "%s: Error enabling DANE TLSA authentication.\n", + prog); goto end; } } @@ -2241,27 +2125,6 @@ int s_client_main(int argc, char **argv) if (set_keylog_file(ctx, keylog_file)) goto end; -#ifndef OPENSSL_NO_ECH - if (alpn_outer_in != NULL) { - size_t alpn_outer_len; - unsigned char *alpn_outer = NULL; - - alpn_outer = next_protos_parse(&alpn_outer_len, alpn_outer_in); - if (alpn_outer == NULL) { - BIO_printf(bio_err, "Error parsing -ech_outer_alpn argument\n"); - goto end; - } - if (SSL_CTX_ech_set1_outer_alpn_protos(ctx, alpn_outer, - alpn_outer_len) - != 1) { - BIO_printf(bio_err, "Error setting ALPN-OUTER\n"); - OPENSSL_free(alpn_outer); - goto end; - } - OPENSSL_free(alpn_outer); - } -#endif - con = SSL_new(ctx); if (con == NULL) goto end; @@ -2269,35 +2132,17 @@ int s_client_main(int argc, char **argv) if (enable_pha) SSL_set_post_handshake_auth(con, 1); - if (enable_client_rpk - && !SSL_set1_client_cert_type(con, cert_type_rpk, sizeof(cert_type_rpk))) { - BIO_puts(bio_err, "Error setting client certificate types\n"); - goto end; - } - if (enable_server_rpk - && !SSL_set1_server_cert_type(con, cert_type_rpk, sizeof(cert_type_rpk))) { - BIO_puts(bio_err, "Error setting server certificate types\n"); - goto end; - } - -#ifndef OPENSSL_NO_ECH - if (ech_grease_suite != NULL) { - if (SSL_ech_set1_grease_suite(con, ech_grease_suite) != 1) { - ERR_print_errors(bio_err); + if (enable_client_rpk) + if (!SSL_set1_client_cert_type(con, cert_type_rpk, sizeof(cert_type_rpk))) { + BIO_printf(bio_err, "Error setting client certificate types\n"); + goto end; + } + if (enable_server_rpk) { + if (!SSL_set1_server_cert_type(con, cert_type_rpk, sizeof(cert_type_rpk))) { + BIO_printf(bio_err, "Error setting server certificate types\n"); goto end; } } - /* no point in setting to our default */ - if (ech_grease_type != OSSL_ECH_CURRENT_VERSION) { - BIO_printf(bio_err, "Setting GREASE ECH type 0x%4x\n", ech_grease_type); - if (SSL_ech_set_grease_type(con, ech_grease_type) != 1) { - BIO_printf(bio_err, "Can't set GREASE ECH type 0x%4x\n", - ech_grease_type); - ERR_print_errors(bio_err); - goto end; - } - } -#endif if (sess_in != NULL) { SSL_SESSION *sess; @@ -2313,8 +2158,7 @@ int s_client_main(int argc, char **argv) goto end; } if (!SSL_set_session(con, sess)) { - SSL_SESSION_free(sess); - BIO_puts(bio_err, "Can't set session\n"); + BIO_printf(bio_err, "Can't set session\n"); goto end; } @@ -2323,8 +2167,6 @@ int s_client_main(int argc, char **argv) if (fallback_scsv) SSL_set_mode(con, SSL_MODE_SEND_FALLBACK_SCSV); - if (grease) - SSL_set_options(con, SSL_OP_GREASE); if (!noservername && (servername != NULL || dane_tlsa_domain == NULL)) { if (servername == NULL) { @@ -2332,57 +2174,11 @@ int s_client_main(int argc, char **argv) servername = (host == NULL) ? "localhost" : host; } if (servername != NULL && !SSL_set_tlsext_host_name(con, servername)) { - BIO_puts(bio_err, "Unable to set TLS servername extension.\n"); + BIO_printf(bio_err, "Unable to set TLS servername extension.\n"); goto end; } } -#ifndef OPENSSL_NO_ECH - if (ech_config_list != NULL) { - if (SSL_set1_ech_config_list(con, (unsigned char *)ech_config_list, - strlen(ech_config_list)) - != 1) { - BIO_printf(bio_err, "%s: error setting ECHConfigList.\n", prog); - goto end; - } - if (ech_no_outer_sni == 1) { - if (sni_outer_name != NULL) { - BIO_printf(bio_err, "%s: can't set -ech_no_outer_sni and " - "-ech_outer_sni together.\n", - prog); - goto end; - } - if (SSL_ech_set1_outer_server_name(con, NULL, 1) != 1) { - BIO_printf(bio_err, "%s: setting no ECH outer name failed.\n", - prog); - ERR_print_errors(bio_err); - goto end; - } - } - if (sni_outer_name != NULL) { - rv = SSL_ech_set1_outer_server_name(con, sni_outer_name, 0); - if (rv != 1) { - BIO_printf(bio_err, "%s: setting ECH outer name to %s failed.\n", - prog, sni_outer_name); - ERR_print_errors(bio_err); - goto end; - } - } - } - if (ech_select != OSSL_ECHSTORE_ALL) { - if ((es = SSL_get1_echstore(con)) == NULL - || OSSL_ECHSTORE_downselect(es, ech_select) != 1 - || SSL_set1_echstore(con, es) != 1) { - BIO_printf(bio_err, "%s: ECH downselect to (%d) failed.\n", - prog, ech_select); - ERR_print_errors(bio_err); - goto end; - } - OSSL_ECHSTORE_free(es); - es = NULL; - } -#endif - if (dane_tlsa_domain != NULL) { if (SSL_dane_enable(con, dane_tlsa_domain) <= 0) { BIO_printf(bio_err, "%s: Error enabling DANE TLSA " @@ -2390,39 +2186,26 @@ int s_client_main(int argc, char **argv) prog); goto end; } - if (dane_tlsa_rrset != NULL) { - if (tlsa_import_rrset(con, dane_tlsa_rrset) <= 0) { - BIO_printf(bio_err, "%s: Failed to import any TLSA " - "records.\n", - prog); - goto end; - } - } else if (rpk_files == NULL) { + if (dane_tlsa_rrset == NULL) { BIO_printf(bio_err, "%s: DANE TLSA authentication requires at " - "least one -dane_tlsa_rrdata option, or else " - "at least one -expected_rpks option.\n", + "least one -dane_tlsa_rrdata option.\n", + prog); + goto end; + } + if (tlsa_import_rrset(con, dane_tlsa_rrset) <= 0) { + BIO_printf(bio_err, "%s: Failed to import any TLSA " + "records.\n", prog); goto end; } if (dane_ee_no_name) SSL_dane_set_flags(con, DANE_FLAG_NO_DANE_EE_NAMECHECKS); - } else if (rpk_files == NULL && dane_tlsa_rrset != NULL) { + } else if (dane_tlsa_rrset != NULL) { BIO_printf(bio_err, "%s: DANE TLSA authentication requires the " "-dane_tlsa_domain option.\n", prog); goto end; } - - if (rpk_files != NULL) { - if (dane_tlsa_domain == NULL - && !SSL_dane_enable(con, noservername ? NULL : servername)) { - BIO_puts(bio_err, "Error enabling server RPK verification\n"); - goto end; - } - for (i = 0; i < sk_OPENSSL_STRING_num(rpk_files); ++i) - if (!load_rpk_file(con, sk_OPENSSL_STRING_value(rpk_files, i))) - goto end; - } #ifndef OPENSSL_NO_DTLS if (isdtls && tfo) { BIO_printf(bio_err, "%s: DTLS does not support the -tfo option\n", prog); @@ -2441,7 +2224,7 @@ int s_client_main(int argc, char **argv) #endif if (tfo) - BIO_puts(bio_c_out, "Connecting via TFO\n"); + BIO_printf(bio_c_out, "Connecting via TFO\n"); re_start: /* peer_addr might be set from previous connections */ BIO_ADDR_free(peer_addr); @@ -2465,7 +2248,7 @@ re_start: if (c_nbio) { if (isquic && !SSL_set_blocking_mode(con, 0)) goto end; - BIO_puts(bio_c_out, "Turned on non blocking io\n"); + BIO_printf(bio_c_out, "Turned on non blocking io\n"); } } #ifndef OPENSSL_NO_DTLS @@ -2480,7 +2263,7 @@ re_start: sbio = BIO_new_dgram(sock, BIO_NOCLOSE); if (sbio == NULL || (peer_info.addr = BIO_ADDR_new()) == NULL) { - BIO_puts(bio_err, "memory allocation failure\n"); + BIO_printf(bio_err, "memory allocation failure\n"); BIO_free(sbio); BIO_closesocket(sock); goto end; @@ -2517,7 +2300,7 @@ re_start: } SSL_set_options(con, SSL_OP_NO_QUERY_MTU); if (!DTLS_set_link_mtu(con, socket_mtu)) { - BIO_puts(bio_err, "Failed to set MTU\n"); + BIO_printf(bio_err, "Failed to set MTU\n"); BIO_free(sbio); goto shut; } @@ -2531,7 +2314,7 @@ re_start: if (isquic) { sbio = BIO_new_dgram(sock, BIO_NOCLOSE); if (!SSL_set1_initial_peer_addr(con, peer_addr)) { - BIO_puts(bio_err, "Failed to set the initial peer address\n"); + BIO_printf(bio_err, "Failed to set the initial peer address\n"); goto shut; } } else @@ -2539,7 +2322,7 @@ re_start: sbio = BIO_new_socket(sock, BIO_NOCLOSE); if (sbio == NULL) { - BIO_puts(bio_err, "Unable to create BIO\n"); + BIO_printf(bio_err, "Unable to create BIO\n"); BIO_closesocket(sock); goto end; } @@ -2555,7 +2338,7 @@ re_start: test = BIO_new(BIO_f_nbio_test()); if (test == NULL) { - BIO_puts(bio_err, "Unable to create BIO\n"); + BIO_printf(bio_err, "Unable to create BIO\n"); BIO_free(sbio); goto shut; } @@ -2635,7 +2418,7 @@ re_start: BIO *fbio = BIO_new(BIO_f_buffer()); if (fbio == NULL) { - BIO_puts(bio_err, "Unable to create BIO\n"); + BIO_printf(bio_err, "Unable to create BIO\n"); goto shut; } BIO_push(fbio, sbio); @@ -2663,18 +2446,18 @@ re_start: BIO_pop(fbio); BIO_free(fbio); if (!foundit) - BIO_puts(bio_err, + BIO_printf(bio_err, "Didn't find STARTTLS in server response," " trying anyway...\n"); - BIO_puts(sbio, "STARTTLS\r\n"); + BIO_printf(sbio, "STARTTLS\r\n"); BIO_read(sbio, sbuf, BUFSIZZ); } break; case PROTO_POP3: { BIO_read(sbio, mbuf, BUFSIZZ); - BIO_puts(sbio, "STLS\r\n"); + BIO_printf(sbio, "STLS\r\n"); mbuf_len = BIO_read(sbio, sbuf, BUFSIZZ); if (mbuf_len < 0) { - BIO_puts(bio_err, "BIO_read failed\n"); + BIO_printf(bio_err, "BIO_read failed\n"); goto end; } } break; @@ -2683,7 +2466,7 @@ re_start: BIO *fbio = BIO_new(BIO_f_buffer()); if (fbio == NULL) { - BIO_puts(bio_err, "Unable to create BIO\n"); + BIO_printf(bio_err, "Unable to create BIO\n"); goto shut; } BIO_push(fbio, sbio); @@ -2711,7 +2494,7 @@ re_start: BIO *fbio = BIO_new(BIO_f_buffer()); if (fbio == NULL) { - BIO_puts(bio_err, "Unable to create BIO\n"); + BIO_printf(bio_err, "Unable to create BIO\n"); goto shut; } BIO_push(fbio, sbio); @@ -2733,7 +2516,7 @@ re_start: "xmlns='jabber:%s' to='%s' version='1.0'>", starttls_proto == PROTO_XMPP ? "client" : "server", protohost ? protohost : host); - seen = BIO_read(sbio, mbuf, BUFSIZZ - 1); + seen = BIO_read(sbio, mbuf, BUFSIZZ); if (seen < 0) { BIO_printf(bio_err, "BIO_read failed\n"); goto end; @@ -2742,18 +2525,18 @@ re_start: while (!strstr(mbuf, ""); - seen = BIO_read(sbio, sbuf, BUFSIZZ - 1); + seen = BIO_read(sbio, sbuf, BUFSIZZ); if (seen < 0) { - BIO_puts(bio_err, "BIO_read failed\n"); + BIO_printf(bio_err, "BIO_read failed\n"); goto shut; } sbuf[seen] = '\0'; @@ -2794,7 +2577,7 @@ re_start: BIO *fbio = BIO_new(BIO_f_buffer()); if (fbio == NULL) { - BIO_puts(bio_err, "Unable to create BIO\n"); + BIO_printf(bio_err, "Unable to create BIO\n"); goto end; } BIO_push(fbio, sbio); @@ -2873,10 +2656,10 @@ re_start: int bytes = 0; int ssl_flg = 0x800; int pos; - unsigned char *packet = (unsigned char *)sbuf; + const unsigned char *packet = (const unsigned char *)sbuf; /* Receiving Initial Handshake packet. */ - bytes = BIO_read(sbio, packet, BUFSIZZ); + bytes = BIO_read(sbio, (void *)packet, BUFSIZZ); if (bytes < 0) { BIO_printf(bio_err, "BIO_read failed\n"); goto shut; @@ -2907,21 +2690,21 @@ re_start: /* make sure we have at least 15 bytes left in the packet */ if (pos + 15 > bytes) { - BIO_puts(bio_err, + BIO_printf(bio_err, "MySQL server handshake packet is broken.\n"); goto shut; } pos += 12; /* skip over conn id[4] + SALT[8] */ if (packet[pos++] != '\0') { /* verify filler */ - BIO_puts(bio_err, + BIO_printf(bio_err, "MySQL packet is broken.\n"); goto shut; } /* capability flags[2] */ if (!((packet[pos] + (packet[pos + 1] << 8)) & ssl_flg)) { - BIO_puts(bio_err, "MySQL server does not support SSL.\n"); + BIO_printf(bio_err, "MySQL server does not support SSL.\n"); goto shut; } @@ -2950,13 +2733,13 @@ re_start: BIO *fbio = BIO_new(BIO_f_buffer()); if (fbio == NULL) { - BIO_puts(bio_err, "Unable to create BIO\n"); + BIO_printf(bio_err, "Unable to create BIO\n"); goto end; } BIO_push(fbio, sbio); BIO_gets(fbio, mbuf, BUFSIZZ); /* STARTTLS command requires CAPABILITIES... */ - BIO_puts(fbio, "CAPABILITIES\r\n"); + BIO_printf(fbio, "CAPABILITIES\r\n"); (void)BIO_flush(fbio); BIO_gets(fbio, mbuf, BUFSIZZ); /* no point in trying to parse the CAPABILITIES response if there is none */ @@ -2972,13 +2755,13 @@ re_start: BIO_pop(fbio); BIO_free(fbio); if (!foundit) - BIO_puts(bio_err, + BIO_printf(bio_err, "Didn't find STARTTLS in server response," " trying anyway...\n"); - BIO_puts(sbio, "STARTTLS\r\n"); - mbuf_len = BIO_read(sbio, mbuf, BUFSIZZ - 1); + BIO_printf(sbio, "STARTTLS\r\n"); + mbuf_len = BIO_read(sbio, mbuf, BUFSIZZ); if (mbuf_len < 0) { - BIO_puts(bio_err, "BIO_read failed\n"); + BIO_printf(bio_err, "BIO_read failed\n"); goto end; } mbuf[mbuf_len] = '\0'; @@ -2992,7 +2775,7 @@ re_start: BIO *fbio = BIO_new(BIO_f_buffer()); if (fbio == NULL) { - BIO_puts(bio_err, "Unable to create BIO\n"); + BIO_printf(bio_err, "Unable to create BIO\n"); goto end; } BIO_push(fbio, sbio); @@ -3013,13 +2796,13 @@ re_start: BIO_pop(fbio); BIO_free(fbio); if (!foundit) - BIO_puts(bio_err, + BIO_printf(bio_err, "Didn't find STARTTLS in server response," " trying anyway...\n"); - BIO_puts(sbio, "STARTTLS\r\n"); - mbuf_len = BIO_read(sbio, mbuf, BUFSIZZ - 1); + BIO_printf(sbio, "STARTTLS\r\n"); + mbuf_len = BIO_read(sbio, mbuf, BUFSIZZ); if (mbuf_len < 0) { - BIO_puts(bio_err, "BIO_read failed\n"); + BIO_printf(bio_err, "BIO_read failed\n"); goto end; } mbuf[mbuf_len] = '\0'; @@ -3029,9 +2812,11 @@ re_start: } /* * According to RFC 5804 § 2.2, response codes are case- - * insensitive. + * insensitive, make it uppercase but preserve the response. */ - if (OPENSSL_strncasecmp(mbuf, "OK", 2) != 0) { + strncpy(sbuf, mbuf, 2); + make_uppercase(sbuf); + if (!HAS_PREFIX(sbuf, "OK")) { BIO_printf(bio_err, "STARTTLS not supported: %s", mbuf); goto shut; } @@ -3049,7 +2834,6 @@ re_start: ASN1_TYPE *atyp = NULL; BIO *ldapbio = BIO_new(BIO_s_mem()); CONF *cnf = NCONF_new(NULL); - size_t ssl_request_len; if (ldapbio == NULL || cnf == NULL) { BIO_free(ldapbio); @@ -3061,7 +2845,7 @@ re_start: BIO_free(ldapbio); NCONF_free(cnf); if (errline <= 0) { - BIO_puts(bio_err, "NCONF_load_bio failed\n"); + BIO_printf(bio_err, "NCONF_load_bio failed\n"); goto end; } else { BIO_printf(bio_err, "Error on line %ld\n", errline); @@ -3072,39 +2856,31 @@ re_start: genstr = NCONF_get_string(cnf, "default", "asn1"); if (genstr == NULL) { NCONF_free(cnf); - BIO_puts(bio_err, "NCONF_get_string failed\n"); + BIO_printf(bio_err, "NCONF_get_string failed\n"); goto end; } atyp = ASN1_generate_nconf(genstr, cnf); - if (atyp == NULL || atyp->type != V_ASN1_SEQUENCE) { + if (atyp == NULL) { NCONF_free(cnf); - ASN1_TYPE_free(atyp); - BIO_puts(bio_err, "ASN1_generate_nconf failed\n"); - goto end; - } - ssl_request_len = ASN1_STRING_length_ex(atyp->value.sequence); - if (ssl_request_len > INT_MAX) { - NCONF_free(cnf); - ASN1_TYPE_free(atyp); - BIO_puts(bio_err, "generated NCONF size is too large\n"); + BIO_printf(bio_err, "ASN1_generate_nconf failed\n"); goto end; } NCONF_free(cnf); /* Send SSLRequest packet */ - BIO_write(sbio, ASN1_STRING_get0_data(atyp->value.sequence), - (int)ssl_request_len); + BIO_write(sbio, atyp->value.sequence->data, + atyp->value.sequence->length); (void)BIO_flush(sbio); ASN1_TYPE_free(atyp); mbuf_len = BIO_read(sbio, mbuf, BUFSIZZ); if (mbuf_len < 0) { - BIO_puts(bio_err, "BIO_read failed\n"); + BIO_printf(bio_err, "BIO_read failed\n"); goto end; } result = ldap_ExtendedResponse_parse(mbuf, mbuf_len); if (result < 0) { - BIO_puts(bio_err, "ldap_ExtendedResponse_parse failed\n"); + BIO_printf(bio_err, "ldap_ExtendedResponse_parse failed\n"); goto shut; } else if (result > 0) { BIO_printf(bio_err, "STARTTLS failed, LDAP Result Code: %i\n", @@ -3125,7 +2901,7 @@ re_start: int finish = 0; if (edfile == NULL) { - BIO_puts(bio_err, "Cannot open early data file\n"); + BIO_printf(bio_err, "Cannot open early data file\n"); goto shut; } @@ -3141,7 +2917,7 @@ re_start: /* Just keep trying - busy waiting */ continue; default: - BIO_puts(bio_err, "Error writing early data\n"); + BIO_printf(bio_err, "Error writing early data\n"); BIO_free(edfile); goto shut; } @@ -3189,7 +2965,7 @@ re_start: if (reconnect) { reconnect--; - BIO_puts(bio_c_out, + BIO_printf(bio_c_out, "drop connection and then reconnect\n"); do_ssl_shutdown(con); SSL_set_connect_state(con); @@ -3203,7 +2979,7 @@ re_start: do { switch (user_data_process(&user_data, &cbuf_len, &cbuf_off)) { default: - BIO_puts(bio_err, "ERROR\n"); + BIO_printf(bio_err, "ERROR\n"); /* fall through */ case USER_DATA_PROCESS_SHUT: ret = 0; @@ -3316,7 +3092,7 @@ re_start: if (isdtls && !FD_ISSET(SSL_get_fd(con), &readfds) && !FD_ISSET(SSL_get_fd(con), &writefds)) - BIO_puts(bio_err, "TIMEOUT occurred\n"); + BIO_printf(bio_err, "TIMEOUT occurred\n"); } if (!ssl_pending @@ -3340,28 +3116,28 @@ re_start: } break; case SSL_ERROR_WANT_WRITE: - BIO_puts(bio_c_out, "write W BLOCK\n"); + BIO_printf(bio_c_out, "write W BLOCK\n"); write_ssl = 1; read_tty = 0; break; case SSL_ERROR_WANT_ASYNC: - BIO_puts(bio_c_out, "write A BLOCK\n"); + BIO_printf(bio_c_out, "write A BLOCK\n"); wait_for_async(con); write_ssl = 1; read_tty = 0; break; case SSL_ERROR_WANT_READ: - BIO_puts(bio_c_out, "write R BLOCK\n"); + BIO_printf(bio_c_out, "write R BLOCK\n"); write_tty = 0; read_ssl = 1; write_ssl = 0; break; case SSL_ERROR_WANT_X509_LOOKUP: - BIO_puts(bio_c_out, "write X BLOCK\n"); + BIO_printf(bio_c_out, "write X BLOCK\n"); break; case SSL_ERROR_ZERO_RETURN: if (cbuf_len != 0) { - BIO_puts(bio_c_out, "shutdown\n"); + BIO_printf(bio_c_out, "shutdown\n"); ret = 0; goto shut; } else { @@ -3402,7 +3178,7 @@ re_start: i = raw_write_stdout(&(sbuf[sbuf_off]), sbuf_len); if (i <= 0) { - BIO_puts(bio_c_out, "DONE\n"); + BIO_printf(bio_c_out, "DONE\n"); ret = 0; goto shut; } @@ -3428,7 +3204,7 @@ re_start: write_tty = 1; break; case SSL_ERROR_WANT_ASYNC: - BIO_puts(bio_c_out, "read A BLOCK\n"); + BIO_printf(bio_c_out, "read A BLOCK\n"); wait_for_async(con); write_tty = 0; read_ssl = 1; @@ -3436,19 +3212,19 @@ re_start: write_ssl = 1; break; case SSL_ERROR_WANT_WRITE: - BIO_puts(bio_c_out, "read W BLOCK\n"); + BIO_printf(bio_c_out, "read W BLOCK\n"); write_ssl = 1; read_tty = 0; break; case SSL_ERROR_WANT_READ: - BIO_puts(bio_c_out, "read R BLOCK\n"); + BIO_printf(bio_c_out, "read R BLOCK\n"); write_tty = 0; read_ssl = 1; if ((read_tty == 0) && (write_ssl == 0)) write_ssl = 1; break; case SSL_ERROR_WANT_X509_LOOKUP: - BIO_puts(bio_c_out, "read X BLOCK\n"); + BIO_printf(bio_c_out, "read X BLOCK\n"); break; case SSL_ERROR_SYSCALL: ret = get_last_socket_error(); @@ -3458,7 +3234,7 @@ re_start: BIO_printf(bio_err, "read:errno=%d\n", ret); goto shut; case SSL_ERROR_ZERO_RETURN: - BIO_puts(bio_c_out, "closed\n"); + BIO_printf(bio_c_out, "closed\n"); ret = 0; goto shut; case SSL_ERROR_WANT_ASYNC_JOB: @@ -3484,7 +3260,7 @@ re_start: if (crlf) { int j, lf_num; - i = raw_read_stdin(cbuf, (BUFSIZZ - 1) / 2); + i = raw_read_stdin(cbuf, BUFSIZZ / 2); lf_num = 0; /* both loops are skipped when i <= 0 */ for (j = 0; j < i; j++) @@ -3500,14 +3276,14 @@ re_start: } assert(lf_num == 0); } else - i = raw_read_stdin(cbuf, BUFSIZZ - 1); + i = raw_read_stdin(cbuf, BUFSIZZ); #if !defined(OPENSSL_SYS_WINDOWS) && !defined(OPENSSL_SYS_MSDOS) if (i == 0) at_eof = 1; #endif if (!c_ign_eof && i <= 0) { - BIO_puts(bio_err, "DONE\n"); + BIO_printf(bio_err, "DONE\n"); ret = 0; goto shut; } @@ -3528,32 +3304,29 @@ shut: print_stuff(bio_c_out, con, full_log); do_ssl_shutdown(con); - /* The following half-close/drain workaround is TCP-specific. */ - if (!isdtls && !isquic) { - /* - * If we ended with an alert being sent, but still with data in the - * network buffer to be read, then calling BIO_closesocket() will - * result in a TCP-RST being sent. On some platforms (notably - * Windows) then this will result in the peer immediately abandoning - * the connection including any buffered alert data before it has - * had a chance to be read. Shutting down the sending side first, - * and then closing the socket sends TCP-FIN first followed by - * TCP-RST. This seems to allow the peer to read the alert data. - */ - shutdown(SSL_get_fd(con), 1); /* SHUT_WR */ - /* - * We just said we have nothing else to say, but it doesn't mean that - * the other side has nothing. It's even recommended to consume incoming - * data. [In testing context this ensures that alerts are passed on...] - */ - timeout.tv_sec = 0; - timeout.tv_usec = 500000; /* some extreme round-trip */ - do { - FD_ZERO(&readfds); - openssl_fdset(sock, &readfds); - } while (select(sock + 1, &readfds, NULL, NULL, &timeout) > 0 - && BIO_read(sbio, sbuf, BUFSIZZ) > 0); - } + /* + * If we ended with an alert being sent, but still with data in the + * network buffer to be read, then calling BIO_closesocket() will + * result in a TCP-RST being sent. On some platforms (notably + * Windows) then this will result in the peer immediately abandoning + * the connection including any buffered alert data before it has + * had a chance to be read. Shutting down the sending side first, + * and then closing the socket sends TCP-FIN first followed by + * TCP-RST. This seems to allow the peer to read the alert data. + */ + shutdown(SSL_get_fd(con), 1); /* SHUT_WR */ + /* + * We just said we have nothing else to say, but it doesn't mean that + * the other side has nothing. It's even recommended to consume incoming + * data. [In testing context this ensures that alerts are passed on...] + */ + timeout.tv_sec = 0; + timeout.tv_usec = 500000; /* some extreme round-trip */ + do { + FD_ZERO(&readfds); + openssl_fdset(sock, &readfds); + } while (select(sock + 1, &readfds, NULL, NULL, &timeout) > 0 + && BIO_read(sbio, sbuf, BUFSIZZ) > 0); BIO_closesocket(SSL_get_fd(con)); end: @@ -3591,7 +3364,6 @@ end: X509_VERIFY_PARAM_free(vpm); ssl_excert_free(exc); sk_OPENSSL_STRING_free(ssl_args); - sk_OPENSSL_STRING_free(rpk_files); sk_OPENSSL_STRING_free(dane_tlsa_rrset); SSL_CONF_CTX_free(cctx); OPENSSL_clear_free(cbuf, BUFSIZZ); @@ -3602,9 +3374,6 @@ end: bio_c_out = NULL; BIO_free(bio_c_msg); bio_c_msg = NULL; -#ifndef OPENSSL_NO_ECH - OSSL_ECHSTORE_free(es); -#endif return ret; } @@ -3647,105 +3416,6 @@ static void print_cert_key_info(BIO *bio, X509 *cert) OPENSSL_free(curve); } -#ifndef OPENSSL_NO_ECH -static void print_ech_retry_configs(BIO *bio, SSL *s) -{ - int ind, cnt = 0, has_priv, for_retry; - OSSL_ECHSTORE *es = NULL; - time_t secs = 0; - char *pn = NULL, *ec = NULL; - size_t rtlen = 0; - unsigned char *rtval = NULL; - BIO *biom = NULL; - - if (SSL_ech_get1_retry_config(s, &rtval, &rtlen) != 1) { - BIO_puts(bio, "ECH: Error getting retry-configs\n"); - return; - } - /* - * print nicely, note that any non-supported versions - * sent by server will have been filtered out by now - */ - if (rtlen > INT_MAX - || (biom = BIO_new(BIO_s_mem())) == NULL - || BIO_write(biom, rtval, (int)rtlen) <= 0 - || (es = OSSL_ECHSTORE_new(NULL, NULL)) == NULL - || OSSL_ECHSTORE_read_echconfiglist(es, biom) != 1) { - BIO_puts(bio, "ECH: Error loading retry-configs\n"); - goto end; - } - if (OSSL_ECHSTORE_num_entries(es, &cnt) != 1) - goto end; - BIO_printf(bio, "ECH: Got %d retry-configs\n", cnt); - for (ind = 0; ind != cnt; ind++) { - if (OSSL_ECHSTORE_get1_info(es, ind, &secs, &pn, &ec, - &has_priv, &for_retry) - != 1) { - BIO_printf(bio, "ECH: Error getting retry-config %d.\n", ind); - goto end; - } - BIO_printf(bio, "ECH: entry: %d public_name: %s age: %lld%s\n", - ind, pn, (long long)secs, - has_priv ? " (has private key)" : ""); - BIO_printf(bio, "ECH: \t%s\n", ec); - OPENSSL_free(pn); - pn = NULL; - OPENSSL_free(ec); - ec = NULL; - } -end: - BIO_free_all(biom); - OPENSSL_free(rtval); - OPENSSL_free(pn); - OPENSSL_free(ec); - OSSL_ECHSTORE_free(es); - return; -} - -/* outcomes marked as "odd" shouldn't happen in s_client */ -static void print_ech_status(BIO *bio, SSL *s, int estat) -{ - switch (estat) { - case SSL_ECH_STATUS_NOT_TRIED: - BIO_printf(bio, "ECH: not tried: %d\n", estat); - break; - case SSL_ECH_STATUS_FAILED: - BIO_printf(bio, "ECH: tried but failed: %d\n", estat); - break; - case SSL_ECH_STATUS_FAILED_ECH: - BIO_printf(bio, "ECH: failed+retry-configs: %d\n", estat); - break; - case SSL_ECH_STATUS_SUCCESS: - BIO_printf(bio, "ECH: success: %d\n", estat); - break; - case SSL_ECH_STATUS_GREASE_ECH: - BIO_printf(bio, "ECH: GREASE+retry-configs: %d\n", estat); - break; - case SSL_ECH_STATUS_BACKEND: - BIO_printf(bio, "ECH: BACKEND: %d\n", estat); - break; - case SSL_ECH_STATUS_GREASE: - BIO_printf(bio, "ECH: GREASE: %d\n", estat); - break; - case SSL_ECH_STATUS_BAD_CALL: - BIO_printf(bio, "ECH: BAD CALL: %d\n", estat); - break; - case SSL_ECH_STATUS_BAD_NAME: - BIO_printf(bio, "ECH: BAD NAME: %d\n", estat); - break; - case SSL_ECH_STATUS_NOT_CONFIGURED: - BIO_printf(bio, "ECH: NOT CONFIGURED: %d\n", estat); - break; - case SSL_ECH_STATUS_FAILED_ECH_BAD_NAME: - BIO_printf(bio, "ECH: failed+retry-configs: %d\n", estat); - break; - default: - BIO_printf(bio, "ECH: unexpected status: %d\n", estat); - } - return; -} -#endif - static void print_stuff(BIO *bio, SSL *s, int full) { X509 *peer = NULL; @@ -3760,10 +3430,6 @@ static void print_stuff(BIO *bio, SSL *s, int full) #ifndef OPENSSL_NO_CT const SSL_CTX *ctx = SSL_get_SSL_CTX(s); #endif -#ifndef OPENSSL_NO_ECH - char *inner = NULL, *outer = NULL; - int estat = 0; -#endif if (full) { int got_a_chain = 0; @@ -3772,19 +3438,20 @@ static void print_stuff(BIO *bio, SSL *s, int full) if (sk != NULL) { got_a_chain = 1; - BIO_puts(bio, "---\nCertificate chain\n"); + BIO_printf(bio, "---\nCertificate chain\n"); for (i = 0; i < sk_X509_num(sk); i++) { X509 *chain_cert = sk_X509_value(sk, i); BIO_printf(bio, "%2d s:", i); X509_NAME_print_ex(bio, X509_get_subject_name(chain_cert), 0, get_nameopt()); - BIO_puts(bio, "\n i:"); + BIO_puts(bio, "\n"); + BIO_printf(bio, " i:"); X509_NAME_print_ex(bio, X509_get_issuer_name(chain_cert), 0, get_nameopt()); BIO_puts(bio, "\n"); print_cert_key_info(bio, chain_cert); - BIO_puts(bio, " v:NotBefore: "); + BIO_printf(bio, " v:NotBefore: "); ASN1_TIME_print(bio, X509_get0_notBefore(chain_cert)); - BIO_puts(bio, "; NotAfter: "); + BIO_printf(bio, "; NotAfter: "); ASN1_TIME_print(bio, X509_get0_notAfter(chain_cert)); BIO_puts(bio, "\n"); if (c_showcerts) @@ -3792,32 +3459,32 @@ static void print_stuff(BIO *bio, SSL *s, int full) } } - BIO_puts(bio, "---\n"); + BIO_printf(bio, "---\n"); peer = SSL_get0_peer_certificate(s); if (peer != NULL) { - BIO_puts(bio, "Server certificate\n"); + BIO_printf(bio, "Server certificate\n"); /* Redundant if we showed the whole chain */ if (!(c_showcerts && got_a_chain)) PEM_write_bio_X509(bio, peer); dump_cert_text(bio, peer); } else { - BIO_puts(bio, "no peer certificate available\n"); + BIO_printf(bio, "no peer certificate available\n"); } /* Only display RPK information if configured */ if (SSL_get_negotiated_client_cert_type(s) == TLSEXT_cert_type_rpk) - BIO_puts(bio, "Client-to-server raw public key negotiated\n"); + BIO_printf(bio, "Client-to-server raw public key negotiated\n"); if (SSL_get_negotiated_server_cert_type(s) == TLSEXT_cert_type_rpk) - BIO_puts(bio, "Server-to-client raw public key negotiated\n"); + BIO_printf(bio, "Server-to-client raw public key negotiated\n"); if (enable_server_rpk) { EVP_PKEY *peer_rpk = SSL_get0_peer_rpk(s); if (peer_rpk != NULL) { - BIO_puts(bio, "Server raw public key\n"); + BIO_printf(bio, "Server raw public key\n"); EVP_PKEY_print_public(bio, peer_rpk, 2, NULL); } else { - BIO_puts(bio, "no peer rpk available\n"); + BIO_printf(bio, "no peer rpk available\n"); } } @@ -3844,7 +3511,7 @@ static void print_stuff(BIO *bio, SSL *s, int full) if (sct_count > 0) { const CTLOG_STORE *log_store = SSL_CTX_get0_ctlog_store(ctx); - BIO_puts(bio, "---\n"); + BIO_printf(bio, "---\n"); for (i = 0; i < sct_count; ++i) { SCT *sct = sk_SCT_value(scts, i); @@ -3852,16 +3519,16 @@ static void print_stuff(BIO *bio, SSL *s, int full) SCT_validation_status_string(sct)); SCT_print(sct, bio, 0, log_store); if (i < sct_count - 1) - BIO_puts(bio, "\n---\n"); + BIO_printf(bio, "\n---\n"); } - BIO_puts(bio, "\n"); + BIO_printf(bio, "\n"); } } #endif BIO_printf(bio, - "---\nSSL handshake has read %" PRIu64 " bytes " - "and written %" PRIu64 " bytes\n", + "---\nSSL handshake has read %ju bytes " + "and written %ju bytes\n", BIO_number_read(SSL_get_rbio(s)), BIO_number_written(SSL_get_wbio(s))); } @@ -3884,16 +3551,16 @@ static void print_stuff(BIO *bio, SSL *s, int full) #ifndef OPENSSL_NO_COMP comp = SSL_get_current_compression(s); expansion = SSL_get_current_expansion(s); - BIO_printf(bio, "Compression: %s\n" - "Expansion: %s\n", - comp ? SSL_COMP_get_name(comp) : "NONE", + BIO_printf(bio, "Compression: %s\n", + comp ? SSL_COMP_get_name(comp) : "NONE"); + BIO_printf(bio, "Expansion: %s\n", expansion ? SSL_COMP_get_name(expansion) : "NONE"); #endif #ifndef OPENSSL_NO_KTLS if (BIO_get_ktls_send(SSL_get_wbio(s))) - BIO_puts(bio_err, "Using Kernel TLS for sending\n"); + BIO_printf(bio_err, "Using Kernel TLS for sending\n"); if (BIO_get_ktls_recv(SSL_get_rbio(s))) - BIO_puts(bio_err, "Using Kernel TLS for receiving\n"); + BIO_printf(bio_err, "Using Kernel TLS for receiving\n"); #endif if (OSSL_TRACE_ENABLED(TLS)) { @@ -3925,11 +3592,11 @@ static void print_stuff(BIO *bio, SSL *s, int full) unsigned int proto_len; SSL_get0_alpn_selected(s, &proto, &proto_len); if (proto_len > 0) { - BIO_puts(bio, "ALPN protocol: "); + BIO_printf(bio, "ALPN protocol: "); BIO_write(bio, proto, proto_len); BIO_write(bio, "\n", 1); } else - BIO_puts(bio, "No ALPN negotiated\n"); + BIO_printf(bio, "No ALPN negotiated\n"); } #ifndef OPENSSL_NO_SRTP @@ -3945,15 +3612,15 @@ static void print_stuff(BIO *bio, SSL *s, int full) if (istls13) { switch (SSL_get_early_data_status(s)) { case SSL_EARLY_DATA_NOT_SENT: - BIO_puts(bio, "Early data was not sent\n"); + BIO_printf(bio, "Early data was not sent\n"); break; case SSL_EARLY_DATA_REJECTED: - BIO_puts(bio, "Early data was rejected\n"); + BIO_printf(bio, "Early data was rejected\n"); break; case SSL_EARLY_DATA_ACCEPTED: - BIO_puts(bio, "Early data was accepted\n"); + BIO_printf(bio, "Early data was accepted\n"); break; } @@ -3971,11 +3638,9 @@ static void print_stuff(BIO *bio, SSL *s, int full) } if (SSL_get_session(s) != NULL && keymatexportlabel != NULL) { - BIO_printf(bio, "Keying material exporter:\n" - " Label: '%s'\n" - " Length: %i bytes\n", - keymatexportlabel, - keymatexportlen); + BIO_printf(bio, "Keying material exporter:\n"); + BIO_printf(bio, " Label: '%s'\n", keymatexportlabel); + BIO_printf(bio, " Length: %i bytes\n", keymatexportlen); exportedkeymat = app_malloc(keymatexportlen, "export key"); if (SSL_export_keying_material(s, exportedkeymat, keymatexportlen, @@ -3983,31 +3648,16 @@ static void print_stuff(BIO *bio, SSL *s, int full) strlen(keymatexportlabel), NULL, 0, 0) <= 0) { - BIO_puts(bio, " Error\n"); + BIO_printf(bio, " Error\n"); } else { - BIO_puts(bio, " Keying material: "); + BIO_printf(bio, " Keying material: "); for (i = 0; i < keymatexportlen; i++) BIO_printf(bio, "%02X", exportedkeymat[i]); - BIO_puts(bio, "\n"); + BIO_printf(bio, "\n"); } OPENSSL_free(exportedkeymat); } - BIO_puts(bio, "---\n"); -#ifndef OPENSSL_NO_ECH - estat = SSL_ech_get1_status(s, &inner, &outer); - print_ech_status(bio, s, estat); - if (estat == SSL_ECH_STATUS_SUCCESS) { - BIO_printf(bio, "ECH: inner: %s\n", inner == NULL ? "" : inner); - BIO_printf(bio, "ECH: outer: %s\n", outer == NULL ? "" : outer); - } - if (estat == SSL_ECH_STATUS_FAILED_ECH - || estat == SSL_ECH_STATUS_FAILED_ECH_BAD_NAME) - print_ech_retry_configs(bio, s); - OPENSSL_free(inner); - OPENSSL_free(outer); - BIO_puts(bio, "---\n"); -#endif - + BIO_printf(bio, "---\n"); /* flush, or debugging output gets mixed with http response */ (void)BIO_flush(bio); } @@ -4046,7 +3696,7 @@ static int ocsp_resp_cb(SSL *s, void *arg) rsp = d2i_OCSP_RESPONSE(NULL, &p, len); if (rsp == NULL) { BIO_puts(arg, "OCSP response parse error\n"); - BIO_dump_indent(arg, p, len, 4); + BIO_dump_indent(arg, (char *)p, len, 4); return 0; } print_ocsp_response(arg, rsp); @@ -4108,7 +3758,7 @@ static int ldap_ExtendedResponse_parse(const char *buf, long rem) /* pull SEQUENCE */ inf = ASN1_get_object(&cur, &len, &tag, &xclass, rem); if (inf != V_ASN1_CONSTRUCTED || tag != V_ASN1_SEQUENCE || (rem = (long)(end - cur), len > rem)) { - BIO_puts(bio_err, "Unexpected LDAP response\n"); + BIO_printf(bio_err, "Unexpected LDAP response\n"); goto end; } @@ -4117,7 +3767,7 @@ static int ldap_ExtendedResponse_parse(const char *buf, long rem) /* pull MessageID */ inf = ASN1_get_object(&cur, &len, &tag, &xclass, rem); if (inf != V_ASN1_UNIVERSAL || tag != V_ASN1_INTEGER || (rem = (long)(end - cur), len > rem)) { - BIO_puts(bio_err, "No MessageID\n"); + BIO_printf(bio_err, "No MessageID\n"); goto end; } @@ -4127,7 +3777,7 @@ static int ldap_ExtendedResponse_parse(const char *buf, long rem) rem = (long)(end - cur); inf = ASN1_get_object(&cur, &len, &tag, &xclass, rem); if (inf != V_ASN1_CONSTRUCTED || xclass != V_ASN1_APPLICATION || tag != 24) { - BIO_puts(bio_err, "Not ExtendedResponse\n"); + BIO_printf(bio_err, "Not ExtendedResponse\n"); goto end; } @@ -4135,7 +3785,7 @@ static int ldap_ExtendedResponse_parse(const char *buf, long rem) rem = (long)(end - cur); inf = ASN1_get_object(&cur, &len, &tag, &xclass, rem); if (inf != V_ASN1_UNIVERSAL || tag != V_ASN1_ENUMERATED || len == 0 || (rem = (long)(end - cur), len > rem)) { - BIO_puts(bio_err, "Not LDAPResult\n"); + BIO_printf(bio_err, "Not LDAPResult\n"); goto end; } @@ -4229,11 +3879,7 @@ static void user_data_init(struct user_data_st *user_data, SSL *con, char *buf, static int user_data_add(struct user_data_st *user_data, size_t i) { - /* - * We must allow one byte for a NUL terminator so i must be less than - * bufmax - */ - if (user_data->buflen != 0 || i >= user_data->bufmax) + if (user_data->buflen != 0 || i > user_data->bufmax) return 0; user_data->buflen = i; @@ -4254,39 +3900,39 @@ static int user_data_execute(struct user_data_st *user_data, int cmd, char *arg) switch (cmd) { case USER_COMMAND_HELP: /* This only ever occurs in advanced mode, so just emit advanced help */ - BIO_puts(bio_err, "Enter text to send to the peer followed by \n" - "To issue a command insert {cmd} or {cmd:arg} anywhere in the text\n" - "Entering {{ will send { to the peer\n" - "The following commands are available\n" - " {help}: Get this help text\n" - " {quit}: Close the connection to the peer\n" - " {reconnect}: Reconnect to the peer\n"); + BIO_printf(bio_err, "Enter text to send to the peer followed by \n"); + BIO_printf(bio_err, "To issue a command insert {cmd} or {cmd:arg} anywhere in the text\n"); + BIO_printf(bio_err, "Entering {{ will send { to the peer\n"); + BIO_printf(bio_err, "The following commands are available\n"); + BIO_printf(bio_err, " {help}: Get this help text\n"); + BIO_printf(bio_err, " {quit}: Close the connection to the peer\n"); + BIO_printf(bio_err, " {reconnect}: Reconnect to the peer\n"); if (SSL_is_quic(user_data->con)) { - BIO_puts(bio_err, " {fin}: Send FIN on the stream. No further writing is possible\n"); + BIO_printf(bio_err, " {fin}: Send FIN on the stream. No further writing is possible\n"); } else if (SSL_version(user_data->con) == TLS1_3_VERSION) { - BIO_puts(bio_err, " {keyup:req|noreq}: Send a Key Update message\n" - " Arguments:\n" - " req = peer update requested (default)\n" - " noreq = peer update not requested\n"); + BIO_printf(bio_err, " {keyup:req|noreq}: Send a Key Update message\n"); + BIO_printf(bio_err, " Arguments:\n"); + BIO_printf(bio_err, " req = peer update requested (default)\n"); + BIO_printf(bio_err, " noreq = peer update not requested\n"); } else { - BIO_puts(bio_err, " {reneg}: Attempt to renegotiate\n"); + BIO_printf(bio_err, " {reneg}: Attempt to renegotiate\n"); } - BIO_puts(bio_err, "\n"); + BIO_printf(bio_err, "\n"); return USER_DATA_PROCESS_NO_DATA; case USER_COMMAND_QUIT: - BIO_puts(bio_err, "DONE\n"); + BIO_printf(bio_err, "DONE\n"); return USER_DATA_PROCESS_SHUT; case USER_COMMAND_RECONNECT: - BIO_puts(bio_err, "RECONNECTING\n"); + BIO_printf(bio_err, "RECONNECTING\n"); do_ssl_shutdown(user_data->con); SSL_set_connect_state(user_data->con); BIO_closesocket(SSL_get_fd(user_data->con)); return USER_DATA_PROCESS_RESTART; case USER_COMMAND_RENEGOTIATE: - BIO_puts(bio_err, "RENEGOTIATING\n"); + BIO_printf(bio_err, "RENEGOTIATING\n"); if (!SSL_renegotiate(user_data->con)) break; return USER_DATA_PROCESS_CONTINUE; @@ -4300,7 +3946,7 @@ static int user_data_execute(struct user_data_st *user_data, int cmd, char *arg) updatetype = SSL_KEY_UPDATE_NOT_REQUESTED; else return USER_DATA_PROCESS_BAD_ARGUMENT; - BIO_puts(bio_err, "KEYUPDATE\n"); + BIO_printf(bio_err, "KEYUPDATE\n"); if (!SSL_key_update(user_data->con, updatetype)) break; return USER_DATA_PROCESS_CONTINUE; @@ -4316,7 +3962,7 @@ static int user_data_execute(struct user_data_st *user_data, int cmd, char *arg) break; } - BIO_puts(bio_err, "ERROR\n"); + BIO_printf(bio_err, "ERROR\n"); return USER_DATA_PROCESS_SHUT; } diff --git a/apps/s_server.c b/apps/s_server.c index 4d99e5442b..dd5431ca30 100644 --- a/apps/s_server.c +++ b/apps/s_server.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * Copyright 2005 Nokia. All rights reserved. * @@ -19,9 +19,6 @@ /* Included before async.h to avoid some warnings */ #include #endif -#if !defined(OPENSSL_NO_ECH) && !defined(PATH_MAX) -#define PATH_MAX 4096 -#endif #include #include @@ -29,27 +26,6 @@ #include #include "internal/sockets.h" /* for openssl_fdset() */ -#ifndef OPENSSL_NO_ECH -/* to use tracing, if configured and requested */ -#ifndef OPENSSL_NO_SSL_TRACE -#include -#endif -/* sockaddr stuff */ -#if defined(_WIN32) -#include -#include -#include -#else -#include -#include -#include -#include -#endif -/* for timing in some TRACE statements */ -#include -#include "internal/o_dir.h" /* for OPENSSL_DIR_read */ -#endif - #ifndef OPENSSL_NO_SOCK /* @@ -83,11 +59,6 @@ typedef unsigned int u_int; #include "internal/sockets.h" #include "internal/statem.h" -#ifndef OPENSSL_NO_ECH -/* needed for X509_check_host in some CI builds "no-http" */ -#include -#endif - static int not_resumable_sess_cb(SSL *s, int is_forward_secure); static int sv_body(int s, int stype, int prot, unsigned char *context); static int www_body(int s, int stype, int prot, unsigned char *context); @@ -101,10 +72,6 @@ static void init_session_cache_ctx(SSL_CTX *sctx); static void free_sessions(void); static void print_connection_info(SSL *con); -#ifndef OPENSSL_NO_ECH -static unsigned int ech_print_cb(SSL *s, const char *str); -#endif - static const int bufsize = 16 * 1024; static int accept_socket = -1; @@ -116,7 +83,6 @@ static int s_nbio_test = 0; static int s_crlf = 0; static SSL_CTX *ctx = NULL; static SSL_CTX *ctx2 = NULL; -static STACK_OF(OPENSSL_STRING) *rpk_files = NULL; static int www = 0; static BIO *bio_s_out = NULL; @@ -170,7 +136,7 @@ static unsigned int psk_server_cb(SSL *ssl, const char *identity, unsigned char *key; if (s_debug) - BIO_puts(bio_s_out, "psk_server_cb\n"); + BIO_printf(bio_s_out, "psk_server_cb\n"); if (!SSL_is_dtls(ssl) && SSL_version(ssl) >= TLS1_3_VERSION) { /* @@ -183,12 +149,12 @@ static unsigned int psk_server_cb(SSL *ssl, const char *identity, } if (identity == NULL) { - BIO_puts(bio_err, "Error: client did not send PSK identity\n"); + BIO_printf(bio_err, "Error: client did not send PSK identity\n"); goto out_err; } if (s_debug) - BIO_printf(bio_s_out, "identity_len=%zu identity=%s\n", - strlen(identity), identity); + BIO_printf(bio_s_out, "identity_len=%d identity=%s\n", + (int)strlen(identity), identity); /* here we could lookup the given identity e.g. from a database */ if (strcmp(identity, psk_identity) != 0) { @@ -197,7 +163,7 @@ static unsigned int psk_server_cb(SSL *ssl, const char *identity, identity, psk_identity); } else { if (s_debug) - BIO_puts(bio_s_out, "PSK client identity found\n"); + BIO_printf(bio_s_out, "PSK client identity found\n"); } /* convert the PSK key to binary */ @@ -209,7 +175,7 @@ static unsigned int psk_server_cb(SSL *ssl, const char *identity, } if (key_len > (int)max_psk_len) { BIO_printf(bio_err, - "psk buffer of callback is too small (%u) for key (%ld)\n", + "psk buffer of callback is too small (%d) for key (%ld)\n", max_psk_len, key_len); OPENSSL_free(key); return 0; @@ -223,7 +189,7 @@ static unsigned int psk_server_cb(SSL *ssl, const char *identity, return key_len; out_err: if (s_debug) - BIO_puts(bio_err, "Error in PSK server callback\n"); + BIO_printf(bio_err, "Error in PSK server callback\n"); (void)BIO_flush(bio_err); (void)BIO_flush(bio_s_out); return 0; @@ -262,7 +228,7 @@ static int psk_find_session_cb(SSL *ssl, const unsigned char *identity, /* We default to SHA256 */ cipher = SSL_CIPHER_find(ssl, tls13_aes128gcmsha256_id); if (cipher == NULL) { - BIO_puts(bio_err, "Error finding suitable ciphersuite\n"); + BIO_printf(bio_err, "Error finding suitable ciphersuite\n"); OPENSSL_free(key); return 0; } @@ -455,206 +421,8 @@ typedef struct tlsextctx_st { char *servername; BIO *biodebug; int extension_error; - X509 *scert; /* ECH needs 2nd cert for testing */ } tlsextctx; -#ifndef OPENSSL_NO_ECH -static unsigned int ech_print_cb(SSL *s, const char *str) -{ - if (str != NULL) - BIO_printf(bio_s_out, "ECH Server callback printing:\n%s\n", str); - return 1; -} - -/* - * The server has possibly 2 TLS server names basically in ctx and ctx2. So we - * need to check if any client-supplied SNI in the inner/outer matches either - * and serve whichever is appropriate. X509_check_host is the way to do that, - * given an X509* pointer. - * - * We default to the "main" ctx if the client-supplied SNI does not match the - * ctx2 certificate. We don't fail if the client-supplied SNI matches neither, - * but just continue with the "main" ctx. If the client-supplied SNI matches - * both ctx and ctx2, then we'll switch to ctx2 anyway - we don't try for a - * "best" match in that case. - * - * Note that since we attempt ECH decryption whenever configured to do that, - * the only way to get the "outer" SNI is via SSL_ech_get1_status. - */ - -/* apparently 26 is all we need, but round it up to 32 to be on the safe side */ -#define ECH_TIME_STR_LEN 32 - -static int ssl_ech_servername_cb(SSL *s, int *ad, void *arg) -{ - tlsextctx *p = (tlsextctx *)arg; - time_t now = time(0); /* For a bit of basic logging */ - int sockfd = 0, res = 0, echrv = 0; - size_t srv = 0; - struct sockaddr_storage ss; - socklen_t salen = sizeof(ss); - struct sockaddr *sa; - char clientip[INET6_ADDRSTRLEN], lstr[ECH_TIME_STR_LEN]; - const char *servername = NULL; - char *inner_sni = NULL, *outer_sni = NULL; - struct tm local; -#if !defined(OPENSSL_SYS_WINDOWS) - struct tm *local_p = NULL; -#else - errno_t grv; -#endif - -#if !defined(OPENSSL_SYS_WINDOWS) - local_p = gmtime_r(&now, &local); - if (local_p != &local) { - strcpy(lstr, "sometime"); - } else { - srv = strftime(lstr, ECH_TIME_STR_LEN, "%c", &local); - if (srv == 0) - strcpy(lstr, "sometime"); - } -#else - grv = gmtime_s(&local, &now); - if (grv != 0) { - strcpy(lstr, "sometime"); - } else { - srv = strftime(lstr, ECH_TIME_STR_LEN, "%c", &local); - if (srv == 0) - strcpy(lstr, "sometime"); - } -#endif - memset(clientip, 0, INET6_ADDRSTRLEN); - strncpy(clientip, "unknown", INET6_ADDRSTRLEN); - memset(&ss, 0, salen); - sa = (struct sockaddr *)&ss; - res = BIO_get_fd(SSL_get_wbio(s), &sockfd); - if (res != -1) { -#if !defined(_WIN32) - res = getpeername(sockfd, sa, &salen); -#else - res = getpeername(sockfd, sa, (int *)&salen); -#endif - if (res == 0) - res = getnameinfo(sa, salen, clientip, INET6_ADDRSTRLEN, - 0, 0, NI_NUMERICHOST); - } - /* Name that matches "main" ctx */ - servername = SSL_get_servername(s, TLSEXT_NAMETYPE_host_name); - echrv = SSL_ech_get1_status(s, &inner_sni, &outer_sni); - if (p->biodebug != NULL) { - /* spit out basic logging */ - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: connection from %s at %s\n", - clientip, lstr); - /* Client supplied SNI from inner and outer */ - switch (echrv) { - case SSL_ECH_STATUS_BACKEND: - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: ECH backend got inner ECH\n"); - break; - case SSL_ECH_STATUS_NOT_CONFIGURED: - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: ECH not configured\n"); - break; - case SSL_ECH_STATUS_GREASE: - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: attempt we think is GREASE\n"); - break; - case SSL_ECH_STATUS_NOT_TRIED: - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: not attempted\n"); - break; - case SSL_ECH_STATUS_FAILED: - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: tried but failed\n"); - break; - case SSL_ECH_STATUS_BAD_CALL: - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: bad input to API\n"); - break; - case SSL_ECH_STATUS_BAD_NAME: - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: worked but bad name\n"); - break; - case SSL_ECH_STATUS_SUCCESS: - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: success: outer %s, inner: %s\n", - (outer_sni == NULL ? "none" : outer_sni), - (inner_sni == NULL ? "none" : inner_sni)); - break; - default: - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: Error getting ECH status\n"); - break; - } - } - OPENSSL_free(inner_sni); - OPENSSL_free(outer_sni); - if (servername != NULL && p->biodebug != NULL) { - const char *cp = servername; - unsigned char uc; - - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: Hostname in TLS extension: \""); - while ((uc = *cp++) != 0) - BIO_printf(p->biodebug, - isascii(uc) && isprint(uc) ? "%c" : "\\x%02x", uc); - BIO_printf(p->biodebug, "\"\n"); - if (p->servername != NULL) - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: ctx servername: %s\n", - p->servername); - else - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: ctx servername is NULL\n"); - if (p->scert == NULL) - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: No 2nd cert! That's bad.\n"); - } - if (p->servername == NULL) - return SSL_TLSEXT_ERR_NOACK; - if (p->scert == NULL) - return SSL_TLSEXT_ERR_NOACK; - if (echrv == SSL_ECH_STATUS_SUCCESS && servername != NULL) { - if (ctx2 != NULL) { - int check_host = check_cert_might_be_valid(p->biodebug, - p->biodebug, p->scert, servername, NULL, NULL); - - if (check_host == 1) { - if (p->biodebug != NULL) - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: Switching context.\n"); - SSL_set_SSL_CTX(s, ctx2); - } else { - if (p->biodebug != NULL) - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: Not switching context " - "- no name match (%d).\n", - check_host); - if (OPENSSL_strcasecmp(servername, p->servername) != 0) - return p->extension_error; - } - } - } else { - if (p->biodebug != NULL) - BIO_printf(p->biodebug, - "ssl_ech_servername_cb: Not switching context " - "- no ECH SUCCESS\n"); - if (servername != NULL) { - if (OPENSSL_strcasecmp(servername, p->servername)) - return p->extension_error; - if (ctx2 != NULL) { - BIO_puts(p->biodebug, "Switching server context.\n"); - SSL_set_SSL_CTX(s, ctx2); - } - } - } - return SSL_TLSEXT_ERR_OK; -} -/* Below is the "original" ssl_servername_cb, before ECH */ - -#else - static int ssl_servername_cb(SSL *s, int *ad, void *arg) { tlsextctx *p = (tlsextctx *)arg; @@ -664,11 +432,11 @@ static int ssl_servername_cb(SSL *s, int *ad, void *arg) const char *cp = servername; unsigned char uc; - BIO_puts(p->biodebug, "Hostname in TLS extension: \""); + BIO_printf(p->biodebug, "Hostname in TLS extension: \""); while ((uc = *cp++) != 0) BIO_printf(p->biodebug, (((uc) & ~127) == 0) && isprint(uc) ? "%c" : "\\x%02x", uc); - BIO_puts(p->biodebug, "\"\n"); + BIO_printf(p->biodebug, "\"\n"); } if (p->servername == NULL) @@ -678,15 +446,13 @@ static int ssl_servername_cb(SSL *s, int *ad, void *arg) if (OPENSSL_strcasecmp(servername, p->servername)) return p->extension_error; if (ctx2 != NULL) { - BIO_puts(p->biodebug, "Switching server context.\n"); + BIO_printf(p->biodebug, "Switching server context.\n"); SSL_set_SSL_CTX(s, ctx2); } } return SSL_TLSEXT_ERR_OK; } -#endif - /* Structure passed to cert status callback */ typedef struct tlsextstatusctx_st { int timeout; @@ -723,7 +489,7 @@ static int get_ocsp_resp_from_responder_single(SSL *s, X509 *x, int use_ssl; STACK_OF(OPENSSL_STRING) *aia = NULL; X509 *cert; - const X509_NAME *iname; + X509_NAME *iname; STACK_OF(X509) *chain = NULL; SSL_CTX *ssl_ctx; X509_STORE_CTX *inctx = NULL; @@ -1081,8 +847,8 @@ static int cert_status_cb(SSL *s, void *arg) } if (srctx->verbose) { - BIO_printf(bio_err, "cert_status: ocsp response sent:\n" - "cert_status: number of responses: %d\n", + BIO_puts(bio_err, "cert_status: ocsp response sent:\n"); + BIO_printf(bio_err, "cert_status: number of responses: %d\n", sk_OCSP_RESPONSE_num(sk_resp)); for (i = 0; i < sk_OCSP_RESPONSE_num(sk_resp); i++) { resp = sk_OCSP_RESPONSE_value(sk_resp, i); @@ -1140,7 +906,7 @@ static int alpn_cb(SSL *s, const unsigned char **out, unsigned char *outlen, /* We can assume that |in| is syntactically valid. */ unsigned int i; - BIO_puts(bio_s_out, "ALPN protocols advertised by the client: "); + BIO_printf(bio_s_out, "ALPN protocols advertised by the client: "); for (i = 0; i < inlen;) { if (i) BIO_write(bio_s_out, ", ", 2); @@ -1156,7 +922,7 @@ static int alpn_cb(SSL *s, const unsigned char **out, unsigned char *outlen, return SSL_TLSEXT_ERR_ALERT_FATAL; if (!s_quiet) { - BIO_puts(bio_s_out, "ALPN protocols selected: "); + BIO_printf(bio_s_out, "ALPN protocols selected: "); BIO_write(bio_s_out, *out, *outlen); BIO_write(bio_s_out, "\n", 1); } @@ -1259,6 +1025,7 @@ typedef enum OPTION_choice { OPT_SPLIT_SEND_FRAG, OPT_MAX_PIPELINES, OPT_READ_BUF, + OPT_SSL3, OPT_TLS1_3, OPT_TLS1_2, OPT_TLS1_1, @@ -1299,14 +1066,6 @@ typedef enum OPTION_choice { OPT_CERT_COMP, OPT_ENABLE_SERVER_RPK, OPT_ENABLE_CLIENT_RPK, - OPT_EXPECTED_RPK, -#ifndef OPENSSL_NO_ECH - OPT_ECH_PEM, - OPT_ECH_DIR, - OPT_ECH_NORETRY, - OPT_ECH_TRIALDECRYPT, - OPT_ECH_GREASE_RT, -#endif OPT_R_ENUM, OPT_S_ENUM, OPT_V_ENUM, @@ -1340,9 +1099,9 @@ const OPTIONS s_server_options[] = { OPT_SECTION("Identity"), { "context", OPT_CONTEXT, 's', "Set session ID context" }, - { "CAfile", OPT_CAFILE, '<', "File in PEM format with trusted CA certs" }, - { "CApath", OPT_CAPATH, '/', "Dir with trusted CA cert files in PEM format" }, - { "CAstore", OPT_CASTORE, ':', "URI of store with trusted CA certs" }, + { "CAfile", OPT_CAFILE, '<', "PEM format file of CA's" }, + { "CApath", OPT_CAPATH, '/', "PEM format directory of CA's" }, + { "CAstore", OPT_CASTORE, ':', "URI to store of CA's" }, { "no-CAfile", OPT_NOCAFILE, '-', "Do not load the default certificates file" }, { "no-CApath", OPT_NOCAPATH, '-', @@ -1350,9 +1109,9 @@ const OPTIONS s_server_options[] = { { "no-CAstore", OPT_NOCASTORE, '-', "Do not load certificates from the default certificates store URI" }, { "nocert", OPT_NOCERT, '-', "Don't use any certificates (Anon-DH)" }, - { "verify", OPT_VERIFY, 'p', "Turn on peer certificate verification, set depth" }, - { "Verify", OPT_UPPER_V_VERIFY, 'p', - "Turn on peer certificate verification, must have a cert, set depth" }, + { "verify", OPT_VERIFY, 'n', "Turn on peer certificate verification" }, + { "Verify", OPT_UPPER_V_VERIFY, 'n', + "Turn on peer certificate verification, must have a cert" }, { "nameopt", OPT_NAMEOPT, 's', "Certificate subject/issuer name printing options" }, { "cert", OPT_CERT, '<', "Server certificate file to use; default " TEST_CERT }, { "cert2", OPT_CERT2, '<', @@ -1409,23 +1168,17 @@ const OPTIONS s_server_options[] = { { "crl_download", OPT_CRL_DOWNLOAD, '-', "Download CRLs from distribution points in certificate CDP entries" }, { "chainCAfile", OPT_CHAINCAFILE, '<', - "File in PEM format with trusted CA certs to build own cert chain" }, + "CA file for certificate chain (PEM format)" }, { "chainCApath", OPT_CHAINCAPATH, '/', - "Dir with trusted CA cert files in PEM format to build own cert chain" }, + "use dir as certificate store path to build CA certificate chain" }, { "chainCAstore", OPT_CHAINCASTORE, ':', - "URI of trusted CA cert store to build own cert chain" }, - { OPT_MORE_STR, 0, 0, - "NOTE: these override -CApath, -CAfile, and -CAstore for server chain building" }, + "use URI as certificate store to build CA certificate chain" }, { "verifyCAfile", OPT_VERIFYCAFILE, '<', - "File in PEM format with trusted CA certs for client cert verification" }, + "CA file for certificate verification (PEM format)" }, { "verifyCApath", OPT_VERIFYCAPATH, '/', - "Dir with trusted CA cert files in PEM format for client cert verification" }, + "use dir as certificate store path to verify CA certificate" }, { "verifyCAstore", OPT_VERIFYCASTORE, ':', - "URI of trusted CA cert store for client cert verification" }, - { OPT_MORE_STR, 0, 0, - "NOTE: these override -CApath, -CAfile, and -CAstore for client cert verification" }, - { "expected-rpks", OPT_EXPECTED_RPK, '<', - "PEM file with expected client public key(s)" }, + "use URI as certificate store to verify CA certificate" }, { "no_cache", OPT_NO_CACHE, '-', "Disable session cache" }, { "ext_cache", OPT_EXT_CACHE, '-', "Disable internal cache, set up and use external cache" }, @@ -1447,7 +1200,7 @@ const OPTIONS s_server_options[] = { "Provide certificate status response(s) if requested, for the whole chain" }, { "status_verbose", OPT_STATUS_VERBOSE, '-', "Print more output in certificate status callback" }, - { "status_timeout", OPT_STATUS_TIMEOUT, 'N', + { "status_timeout", OPT_STATUS_TIMEOUT, 'n', "Status request responder timeout" }, { "status_url", OPT_STATUS_URL, 's', "Status request fallback URL" }, { "proxy", OPT_PROXY, 's', @@ -1504,9 +1257,9 @@ const OPTIONS s_server_options[] = { #endif OPT_SECTION("Protocol and version"), - { "max_early_data", OPT_MAX_EARLY, 'N', + { "max_early_data", OPT_MAX_EARLY, 'n', "The maximum number of bytes of early data as advertised in tickets" }, - { "recv_max_early_data", OPT_RECV_MAX_EARLY, 'N', + { "recv_max_early_data", OPT_RECV_MAX_EARLY, 'n', "The maximum number of bytes of early data (hard limit)" }, { "early_data", OPT_EARLY_DATA, '-', "Attempt to read early data" }, { "num_tickets", OPT_S_NUM_TICKETS, 'n', @@ -1517,6 +1270,9 @@ const OPTIONS s_server_options[] = { { "no_ca_names", OPT_NOCANAMES, '-', "Disable TLS Extension CA Names" }, { "stateless", OPT_STATELESS, '-', "Require TLSv1.3 cookies" }, +#ifndef OPENSSL_NO_SSL3 + { "ssl3", OPT_SSL3, '-', "Just talk SSLv3" }, +#endif #ifndef OPENSSL_NO_TLS1 { "tls1", OPT_TLS1, '-', "Just talk TLSv1" }, #endif @@ -1555,19 +1311,6 @@ const OPTIONS s_server_options[] = { #endif { "alpn", OPT_ALPN, 's', "Set the advertised protocols for the ALPN extension (comma-separated list)" }, - -#ifndef OPENSSL_NO_ECH - { "ech_key", OPT_ECH_PEM, 's', "Load ECH PEM-formatted key pair" }, - { "ech_dir", OPT_ECH_DIR, 's', "Load ECH key pairs (for retries) " - "from the specified directory" }, - { "ech_noretry_dir", OPT_ECH_NORETRY, 's', "Load ECH key pairs (not " - "for retry) from the specified directory" }, - { "ech_trialdecrypt", OPT_ECH_TRIALDECRYPT, '-', - "Do trial decryption even if ECH record_digest matching fails" }, - { "ech_greaseretries", OPT_ECH_GREASE_RT, '-', - "Set server to GREASE retry_config values" }, -#endif - #ifndef OPENSSL_NO_KTLS { "ktls", OPT_KTLS, '-', "Enable Kernel TLS for sending and receiving" }, { "sendfile", OPT_SENDFILE, '-', "Use sendfile to response file with -WWW" }, @@ -1583,86 +1326,8 @@ const OPTIONS s_server_options[] = { { NULL } }; -#ifndef OPENSSL_NO_ECH -static int ech_load_dir(SSL_CTX *lctx, const char *thedir, - int for_retry, int *nloaded) -{ - size_t elen = strlen(thedir); - OPENSSL_DIR_CTX *d = NULL; - const char *thisfile = NULL; - OSSL_ECHSTORE *es = NULL; - BIO *in = NULL; - int loaded = 0; - int ret = 0; - - /* - * If you change the output to bio_s_out here you may - * also need to change test/recipes/82-test_ech_client_server.t - * as that test checks the server's stdout to decide if the - * server started ok or not. Text sent to stderr won't affect - * that test. - */ - if ((elen + 7) >= PATH_MAX) { /* too long, go away */ - BIO_printf(bio_err, "'%s' too long - exiting\n", thedir); - return 0; - } - if (app_isdir(thedir) <= 0) { /* if not a directory, ignore it */ - BIO_printf(bio_err, "'%s' not a directory - exiting\n", thedir); - return 0; - } - if ((es = SSL_CTX_get1_echstore(lctx)) == NULL - && (es = OSSL_ECHSTORE_new(app_get0_libctx(), - app_get0_propq())) - == NULL) { - BIO_puts(bio_err, "ECH: Internal error\n"); - return 0; - } - while ((thisfile = OPENSSL_DIR_read(&d, thedir))) { - char filepath[PATH_MAX]; - int r; - -#ifdef OPENSSL_SYS_VMS - r = BIO_snprintf(filepath, sizeof(filepath), "%s%s", thedir, thisfile); -#else - r = BIO_snprintf(filepath, sizeof(filepath), "%s/%s", thedir, thisfile); -#endif - if (app_isdir(filepath) > 0) { - if (s_debug) - BIO_printf(bio_err, "Skipping directory: %s\n", filepath); - continue; - } - if (r < 0 - || (in = BIO_new_file(filepath, "r")) == NULL - || OSSL_ECHSTORE_read_pem(es, in, for_retry) != 1) { - BIO_printf(bio_err, "Failed reading from: %s\n", filepath); - continue; - } - BIO_free_all(in); - if (bio_s_out != NULL) - BIO_printf(bio_s_out, "Added ECH key pair from: %s\n", thisfile); - loaded++; - } - OPENSSL_DIR_end(&d); - - if (SSL_CTX_set1_echstore(lctx, es) != 1) { - BIO_puts(bio_err, "ECH: Internal error\n"); - goto end; - } - if (bio_s_out != NULL) - BIO_printf(bio_s_out, "Added %d ECH key pairs from: %s\n", - loaded, thedir); - *nloaded = loaded; - ret = 1; - -end: - OSSL_ECHSTORE_free(es); - - return ret; -} -#endif - -#define IS_PROT_FLAG(o) \ - (o == OPT_TLS1 || o == OPT_TLS1_1 || o == OPT_TLS1_2 \ +#define IS_PROT_FLAG(o) \ + (o == OPT_SSL3 || o == OPT_TLS1 || o == OPT_TLS1_1 || o == OPT_TLS1_2 \ || o == OPT_TLS1_3 || o == OPT_DTLS || o == OPT_DTLS1 || o == OPT_DTLS1_2) int s_server_main(int argc, char *argv[]) @@ -1702,7 +1367,7 @@ int s_server_main(int argc, char *argv[]) OPTION_CHOICE o; EVP_PKEY *s_key2 = NULL; X509 *s_cert2 = NULL; - tlsextctx tlsextcbp = { NULL, NULL, SSL_TLSEXT_ERR_ALERT_WARNING, NULL }; + tlsextctx tlsextcbp = { NULL, NULL, SSL_TLSEXT_ERR_ALERT_WARNING }; const char *ssl_config = NULL; int read_buf_len = 0; #ifndef OPENSSL_NO_NEXTPROTONEG @@ -1740,14 +1405,6 @@ int s_server_main(int argc, char *argv[]) int max_early_data = -1, recv_max_early_data = -1; char *psksessf = NULL; int no_ca_names = 0; -#ifndef OPENSSL_NO_ECH - char *echkeyfile = NULL; - char *echkeydir = NULL; - char *echnoretrydir = NULL; - int ech_files_loaded = 0; - int echtrialdecrypt = 0; /* trial decryption off by default */ - int echgrease_rc = 0; /* retry_config GREASEing off by default */ -#endif #ifndef OPENSSL_NO_SCTP int sctp_label_bug = 0; #endif @@ -1786,13 +1443,13 @@ int s_server_main(int argc, char *argv[]) prog = opt_init(argc, argv, s_server_options); while ((o = opt_next()) != OPT_EOF) { if (IS_PROT_FLAG(o) && ++prot_opt > 1) { - BIO_puts(bio_err, "Cannot supply multiple protocol flags\n"); + BIO_printf(bio_err, "Cannot supply multiple protocol flags\n"); goto end; } if (IS_NO_PROT_FLAG(o)) no_prot_opt++; if (prot_opt == 1 && no_prot_opt) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Cannot supply both a protocol flag and '-no_'\n"); goto end; } @@ -1889,13 +1546,13 @@ int s_server_main(int argc, char *argv[]) break; case OPT_VERIFY: s_server_verify = SSL_VERIFY_PEER | SSL_VERIFY_CLIENT_ONCE; - verify_args.depth = opt_int_arg(); + verify_args.depth = atoi(opt_arg()); if (!s_quiet) BIO_printf(bio_err, "verify depth is %d\n", verify_args.depth); break; case OPT_UPPER_V_VERIFY: s_server_verify = SSL_VERIFY_PEER | SSL_VERIFY_FAIL_IF_NO_PEER_CERT | SSL_VERIFY_CLIENT_ONCE; - verify_args.depth = opt_int_arg(); + verify_args.depth = atoi(opt_arg()); if (!s_quiet) BIO_printf(bio_err, "verify depth is %d, must return a certificate\n", @@ -2079,7 +1736,7 @@ int s_server_main(int argc, char *argv[]) case OPT_STATUS_TIMEOUT: #ifndef OPENSSL_NO_OCSP s_tlsextstatus = 1; - tlscstatp.timeout = opt_int_arg(); + tlscstatp.timeout = atoi(opt_arg()); #endif break; case OPT_PROXY: @@ -2098,7 +1755,7 @@ int s_server_main(int argc, char *argv[]) if (!OSSL_HTTP_parse_url(opt_arg(), &tlscstatp.use_ssl, NULL, &tlscstatp.host, &tlscstatp.port, NULL, &tlscstatp.path, NULL, NULL)) { - BIO_puts(bio_err, "Error parsing -status_url argument\n"); + BIO_printf(bio_err, "Error parsing -status_url argument\n"); goto end; } #endif @@ -2199,6 +1856,10 @@ int s_server_main(int argc, char *argv[]) case OPT_SSL_CONFIG: ssl_config = opt_arg(); break; + case OPT_SSL3: + min_version = SSL3_VERSION; + max_version = SSL3_VERSION; + break; case OPT_TLS1_3: min_version = TLS1_3_VERSION; max_version = TLS1_3_VERSION; @@ -2305,37 +1966,37 @@ int s_server_main(int argc, char *argv[]) keymatexportlabel = opt_arg(); break; case OPT_KEYMATEXPORTLEN: - keymatexportlen = opt_int_arg(); + keymatexportlen = atoi(opt_arg()); break; case OPT_ASYNC: async = 1; break; case OPT_MAX_SEND_FRAG: - max_send_fragment = opt_int_arg(); + max_send_fragment = atoi(opt_arg()); break; case OPT_SPLIT_SEND_FRAG: - split_send_fragment = opt_int_arg(); + split_send_fragment = atoi(opt_arg()); break; case OPT_MAX_PIPELINES: - max_pipelines = opt_int_arg(); + max_pipelines = atoi(opt_arg()); break; case OPT_READ_BUF: - read_buf_len = opt_int_arg(); + read_buf_len = atoi(opt_arg()); break; case OPT_KEYLOG_FILE: keylog_file = opt_arg(); break; case OPT_MAX_EARLY: - max_early_data = opt_int_arg(); + max_early_data = atoi(opt_arg()); if (max_early_data < 0) { - BIO_puts(bio_err, "Invalid value for max_early_data\n"); + BIO_printf(bio_err, "Invalid value for max_early_data\n"); goto end; } break; case OPT_RECV_MAX_EARLY: - recv_max_early_data = opt_int_arg(); + recv_max_early_data = atoi(opt_arg()); if (recv_max_early_data < 0) { - BIO_puts(bio_err, "Invalid value for recv_max_early_data\n"); + BIO_printf(bio_err, "Invalid value for recv_max_early_data\n"); goto end; } break; @@ -2347,23 +2008,6 @@ int s_server_main(int argc, char *argv[]) case OPT_HTTP_SERVER_BINMODE: http_server_binmode = 1; break; -#ifndef OPENSSL_NO_ECH - case OPT_ECH_PEM: - echkeyfile = opt_arg(); - break; - case OPT_ECH_DIR: - echkeydir = opt_arg(); - break; - case OPT_ECH_NORETRY: - echnoretrydir = opt_arg(); - break; - case OPT_ECH_TRIALDECRYPT: - echtrialdecrypt = 1; - break; - case OPT_ECH_GREASE_RT: - echgrease_rc = 1; - break; -#endif case OPT_NOCANAMES: no_ca_names = 1; break; @@ -2397,13 +2041,6 @@ int s_server_main(int argc, char *argv[]) case OPT_ENABLE_CLIENT_RPK: enable_client_rpk = 1; break; - case OPT_EXPECTED_RPK: - if ((rpk_files == NULL - && (rpk_files = sk_OPENSSL_STRING_new_null()) == NULL) - || !sk_OPENSSL_STRING_push(rpk_files, opt_arg())) - goto end; - enable_client_rpk = 1; - break; } } @@ -2416,46 +2053,46 @@ int s_server_main(int argc, char *argv[]) #ifndef OPENSSL_NO_NEXTPROTONEG if (min_version == TLS1_3_VERSION && next_proto_neg_in != NULL) { - BIO_puts(bio_err, "Cannot supply -nextprotoneg with TLSv1.3\n"); + BIO_printf(bio_err, "Cannot supply -nextprotoneg with TLSv1.3\n"); goto opthelp; } #endif #ifndef OPENSSL_NO_DTLS if (www && socket_type == SOCK_DGRAM) { - BIO_puts(bio_err, "Can't use -HTTP, -www or -WWW with DTLS\n"); + BIO_printf(bio_err, "Can't use -HTTP, -www or -WWW with DTLS\n"); goto end; } if (dtlslisten && socket_type != SOCK_DGRAM) { - BIO_puts(bio_err, "Can only use -listen with DTLS\n"); + BIO_printf(bio_err, "Can only use -listen with DTLS\n"); goto end; } if (rev && socket_type == SOCK_DGRAM) { - BIO_puts(bio_err, "Can't use -rev with DTLS\n"); + BIO_printf(bio_err, "Can't use -rev with DTLS\n"); goto end; } #endif if (tfo && socket_type != SOCK_STREAM) { - BIO_puts(bio_err, "Can only use -tfo with TLS\n"); + BIO_printf(bio_err, "Can only use -tfo with TLS\n"); goto end; } if (stateless && socket_type != SOCK_STREAM) { - BIO_puts(bio_err, "Can only use --stateless with TLS\n"); + BIO_printf(bio_err, "Can only use --stateless with TLS\n"); goto end; } #ifdef AF_UNIX if (socket_family == AF_UNIX && socket_type != SOCK_STREAM) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Can't use unix sockets and datagrams together\n"); goto end; } #endif if (early_data && rev) { - BIO_puts(bio_err, + BIO_printf(bio_err, "Can't use -early_data in combination with -rev\n"); goto end; } @@ -2463,7 +2100,7 @@ int s_server_main(int argc, char *argv[]) #ifndef OPENSSL_NO_SCTP if (protocol == IPPROTO_SCTP) { if (socket_type != SOCK_DGRAM) { - BIO_puts(bio_err, "Can't use -sctp without DTLS\n"); + BIO_printf(bio_err, "Can't use -sctp without DTLS\n"); goto end; } /* SCTP is unusual. It uses DTLS over a SOCK_STREAM protocol */ @@ -2473,23 +2110,23 @@ int s_server_main(int argc, char *argv[]) #ifndef OPENSSL_NO_KTLS if (use_zc_sendfile && !use_sendfile) { - BIO_puts(bio_err, "Warning: -zerocopy_sendfile depends on -sendfile, enabling -sendfile now.\n"); + BIO_printf(bio_out, "Warning: -zerocopy_sendfile depends on -sendfile, enabling -sendfile now.\n"); use_sendfile = 1; } if (use_sendfile && enable_ktls == 0) { - BIO_puts(bio_err, "Warning: -sendfile depends on -ktls, enabling -ktls now.\n"); + BIO_printf(bio_out, "Warning: -sendfile depends on -ktls, enabling -ktls now.\n"); enable_ktls = 1; } if (use_sendfile && www <= 1) { - BIO_puts(bio_err, "Can't use -sendfile without -WWW or -HTTP\n"); + BIO_printf(bio_err, "Can't use -sendfile without -WWW or -HTTP\n"); goto end; } #endif if (!app_passwd(passarg, dpassarg, &pass, &dpass)) { - BIO_puts(bio_err, "Error getting password\n"); + BIO_printf(bio_err, "Error getting password\n"); goto end; } @@ -2530,9 +2167,6 @@ int s_server_main(int argc, char *argv[]) if (s_cert2 == NULL) goto end; -#ifndef OPENSSL_NO_ECH - tlsextcbp.scert = s_cert2; -#endif } } #if !defined(OPENSSL_NO_NEXTPROTONEG) @@ -2593,7 +2227,7 @@ int s_server_main(int argc, char *argv[]) if (s_msg && bio_s_msg == NULL) { bio_s_msg = dup_bio_out(FORMAT_TEXT); if (bio_s_msg == NULL) { - BIO_puts(bio_err, "Out of memory\n"); + BIO_printf(bio_err, "Out of memory\n"); goto end; } } @@ -2650,10 +2284,10 @@ int s_server_main(int argc, char *argv[]) if (session_id_prefix) { if (strlen(session_id_prefix) >= 32) - BIO_puts(bio_err, + BIO_printf(bio_err, "warning: id_prefix is too long, only one new session will be possible\n"); if (!SSL_CTX_set_generate_session_id(ctx, generate_session_id)) { - BIO_puts(bio_err, "error setting 'id_prefix'\n"); + BIO_printf(bio_err, "error setting 'id_prefix'\n"); ERR_print_errors(bio_err); goto end; } @@ -2715,7 +2349,7 @@ int s_server_main(int argc, char *argv[]) if (srtp_profiles != NULL) { /* Returns 0 on success! */ if (SSL_CTX_set_tlsext_use_srtp(ctx, srtp_profiles) != 0) { - BIO_puts(bio_err, "Error setting SRTP profile\n"); + BIO_printf(bio_err, "Error setting SRTP profile\n"); ERR_print_errors(bio_err); goto end; } @@ -2728,7 +2362,7 @@ int s_server_main(int argc, char *argv[]) goto end; } if (vpmtouched && !SSL_CTX_set1_param(ctx, vpm)) { - BIO_puts(bio_err, "Error setting verify params\n"); + BIO_printf(bio_err, "Error setting verify params\n"); ERR_print_errors(bio_err); goto end; } @@ -2739,90 +2373,31 @@ int s_server_main(int argc, char *argv[]) vfyCApath, vfyCAfile, vfyCAstore, chCApath, chCAfile, chCAstore, crls, crl_download)) { - BIO_puts(bio_err, "Error loading store locations\n"); + BIO_printf(bio_err, "Error loading store locations\n"); ERR_print_errors(bio_err); goto end; } -#ifndef OPENSSL_NO_ECH - if (echtrialdecrypt != 0) - SSL_CTX_set_options(ctx, SSL_OP_ECH_TRIALDECRYPT); - if (echgrease_rc != 0) - SSL_CTX_set_options(ctx, SSL_OP_ECH_GREASE_RETRY_CONFIG); - if (echkeyfile != NULL) { - OSSL_ECHSTORE *es = NULL; - BIO *in = NULL; - - if ((in = BIO_new_file(echkeyfile, "r")) == NULL - || (es = OSSL_ECHSTORE_new(app_get0_libctx(), - app_get0_propq())) - == NULL - || OSSL_ECHSTORE_read_pem(es, in, OSSL_ECH_FOR_RETRY) != 1 - || SSL_CTX_set1_echstore(ctx, es) != 1) { - BIO_printf(bio_err, "Failed reading: %s\n", echkeyfile); - OSSL_ECHSTORE_free(es); - BIO_free_all(in); - goto end; - } - OSSL_ECHSTORE_free(es); - BIO_free_all(in); - if (bio_s_out != NULL) - BIO_printf(bio_s_out, "Added ECH key pair from: %s\n", echkeyfile); - ech_files_loaded++; - } - if (echkeydir != NULL) { - int nloaded = 0; - - if (ech_load_dir(ctx, echkeydir, OSSL_ECH_FOR_RETRY, &nloaded) != 1) { - BIO_printf(bio_err, "error loading from %s\n", echkeydir); - goto end; - } - ech_files_loaded += nloaded; - } - if (echnoretrydir != NULL) { - int nloaded = 0; - - if (ech_load_dir(ctx, echnoretrydir, OSSL_ECH_NO_RETRY, - &nloaded) - != 1) { - BIO_printf(bio_err, "error loading from %s\n", echnoretrydir); - goto end; - } - ech_files_loaded += nloaded; - } - if ((echkeyfile != NULL || echkeydir != NULL || echnoretrydir != NULL) - && bio_s_out != NULL) { - BIO_printf(bio_s_out, "Loaded %d ECH key pairs in total\n", - ech_files_loaded); - } -#endif - if (s_cert2) { ctx2 = SSL_CTX_new_ex(app_get0_libctx(), app_get0_propq(), meth); if (ctx2 == NULL) { ERR_print_errors(bio_err); goto end; } -#ifndef OPENSSL_NO_ECH - if (echtrialdecrypt != 0) - SSL_CTX_set_options(ctx2, SSL_OP_ECH_TRIALDECRYPT); - if (echgrease_rc != 0) - SSL_CTX_set_options(ctx, SSL_OP_ECH_GREASE_RETRY_CONFIG); -#endif } if (ctx2 != NULL) { - BIO_puts(bio_s_out, "Setting secondary ctx parameters\n"); + BIO_printf(bio_s_out, "Setting secondary ctx parameters\n"); if (sdebug) ssl_ctx_security_debug(ctx2, sdebug); if (session_id_prefix) { if (strlen(session_id_prefix) >= 32) - BIO_puts(bio_err, + BIO_printf(bio_err, "warning: id_prefix is too long, only one new session will be possible\n"); if (!SSL_CTX_set_generate_session_id(ctx2, generate_session_id)) { - BIO_puts(bio_err, "error setting 'id_prefix'\n"); + BIO_printf(bio_err, "error setting 'id_prefix'\n"); ERR_print_errors(bio_err); goto end; } @@ -2850,7 +2425,7 @@ int s_server_main(int argc, char *argv[]) goto end; } if (vpmtouched && !SSL_CTX_set1_param(ctx2, vpm)) { - BIO_puts(bio_err, "Error setting verify params\n"); + BIO_printf(bio_err, "Error setting verify params\n"); ERR_print_errors(bio_err); goto end; } @@ -2867,13 +2442,6 @@ int s_server_main(int argc, char *argv[]) if (alpn_ctx.data) SSL_CTX_set_alpn_select_cb(ctx, alpn_cb, &alpn_ctx); - /* - * If we have a 2nd context to which we might switch, then set - * the same alpn callback for that too. - */ - if (s_cert2 != NULL && alpn_ctx.data != NULL) - SSL_CTX_set_alpn_select_cb(ctx2, alpn_cb, &alpn_ctx); - if (!no_dhe) { EVP_PKEY *dhpkey = NULL; @@ -2884,9 +2452,9 @@ int s_server_main(int argc, char *argv[]) "DH parameters", 1); if (dhpkey != NULL) { - BIO_puts(bio_s_out, "Setting temp DH parameters\n"); + BIO_printf(bio_s_out, "Setting temp DH parameters\n"); } else { - BIO_puts(bio_s_out, "Using default temp DH parameters\n"); + BIO_printf(bio_s_out, "Using default temp DH parameters\n"); } (void)BIO_flush(bio_s_out); @@ -2919,7 +2487,7 @@ int s_server_main(int argc, char *argv[]) "DH parameters", 1); if (dhpkey2 != NULL) { - BIO_puts(bio_s_out, "Setting temp DH parameters\n"); + BIO_printf(bio_s_out, "Setting temp DH parameters\n"); (void)BIO_flush(bio_s_out); EVP_PKEY_free(dhpkey); @@ -2948,21 +2516,9 @@ int s_server_main(int argc, char *argv[]) goto end; } -#ifndef OPENSSL_NO_ECH - /* - * Giving the same chain to the 2nd key pair works for our tests. - * It would be better to supply s_chain_file2 as a new CLA in case - * the paths are very different but as that's not needed for tests, - * I didn't do it. - */ - if (ctx2 != NULL - && !set_cert_key_stuff(ctx2, s_cert2, s_key2, s_chain, build_chain)) - goto end; -#else if (ctx2 != NULL && !set_cert_key_stuff(ctx2, s_cert2, s_key2, NULL, build_chain)) goto end; -#endif if (s_dcert != NULL) { if (!set_cert_key_stuff(ctx, s_dcert, s_dkey, s_dchain, build_chain)) @@ -2980,16 +2536,16 @@ int s_server_main(int argc, char *argv[]) #ifndef OPENSSL_NO_PSK if (psk_key != NULL) { if (s_debug) - BIO_puts(bio_s_out, "PSK key given, setting server callback\n"); + BIO_printf(bio_s_out, "PSK key given, setting server callback\n"); SSL_CTX_set_psk_server_callback(ctx, psk_server_cb); } if (psk_identity_hint != NULL) { if (min_version == TLS1_3_VERSION) { - BIO_puts(bio_s_out, "PSK warning: there is NO identity hint in TLSv1.3\n"); + BIO_printf(bio_s_out, "PSK warning: there is NO identity hint in TLSv1.3\n"); } else { if (!SSL_CTX_use_psk_identity_hint(ctx, psk_identity_hint)) { - BIO_puts(bio_err, "error setting PSK identity hint to context\n"); + BIO_printf(bio_err, "error setting PSK identity hint to context\n"); ERR_print_errors(bio_err); goto end; } @@ -3020,7 +2576,7 @@ int s_server_main(int argc, char *argv[]) if (!SSL_CTX_set_session_id_context(ctx, (void *)&s_server_session_id_context, sizeof(s_server_session_id_context))) { - BIO_puts(bio_err, "error setting session id context\n"); + BIO_printf(bio_err, "error setting session id context\n"); ERR_print_errors(bio_err); goto end; } @@ -3038,24 +2594,15 @@ int s_server_main(int argc, char *argv[]) if (!SSL_CTX_set_session_id_context(ctx2, (void *)&s_server_session_id_context, sizeof(s_server_session_id_context))) { - BIO_puts(bio_err, "error setting session id context\n"); + BIO_printf(bio_err, "error setting session id context\n"); ERR_print_errors(bio_err); goto end; } tlsextcbp.biodebug = bio_s_out; -#ifndef OPENSSL_NO_ECH - SSL_CTX_set_tlsext_servername_callback(ctx2, ssl_ech_servername_cb); - SSL_CTX_set_tlsext_servername_arg(ctx2, &tlsextcbp); - SSL_CTX_set_tlsext_servername_callback(ctx, ssl_ech_servername_cb); - SSL_CTX_set_tlsext_servername_arg(ctx, &tlsextcbp); - SSL_CTX_ech_set_callback(ctx2, ech_print_cb); - SSL_CTX_ech_set_callback(ctx, ech_print_cb); -#else SSL_CTX_set_tlsext_servername_callback(ctx2, ssl_servername_cb); SSL_CTX_set_tlsext_servername_arg(ctx2, &tlsextcbp); SSL_CTX_set_tlsext_servername_callback(ctx, ssl_servername_cb); SSL_CTX_set_tlsext_servername_arg(ctx, &tlsextcbp); -#endif } #ifndef OPENSSL_NO_SRP @@ -3083,11 +2630,6 @@ int s_server_main(int argc, char *argv[]) #endif if (set_keylog_file(ctx, keylog_file)) goto end; -#ifndef OPENSSL_NO_ECH - /* not really an ECH issue but needed */ - if (ctx2 != NULL && set_keylog_file(ctx2, keylog_file)) - goto end; -#endif if (max_early_data >= 0) SSL_CTX_set_max_early_data(ctx, max_early_data); @@ -3095,26 +2637,22 @@ int s_server_main(int argc, char *argv[]) SSL_CTX_set_recv_max_early_data(ctx, recv_max_early_data); if (cert_comp) { - BIO_puts(bio_s_out, "Compressing certificates\n"); + BIO_printf(bio_s_out, "Compressing certificates\n"); if (!SSL_CTX_compress_certs(ctx, 0)) - BIO_puts(bio_s_out, "Error compressing certs on ctx\n"); + BIO_printf(bio_s_out, "Error compressing certs on ctx\n"); if (ctx2 != NULL && !SSL_CTX_compress_certs(ctx2, 0)) - BIO_puts(bio_s_out, "Error compressing certs on ctx2\n"); - } - if (enable_server_rpk - && !SSL_CTX_set1_server_cert_type(ctx, cert_type_rpk, sizeof(cert_type_rpk))) { - BIO_puts(bio_err, "Error setting server certificate types\n"); - goto end; - } - if (enable_client_rpk - && !SSL_CTX_set1_client_cert_type(ctx, cert_type_rpk, sizeof(cert_type_rpk))) { - BIO_puts(bio_err, "Error setting client certificate types\n"); - goto end; - } - if (rpk_files != NULL && SSL_CTX_dane_enable(ctx) <= 0) { - BIO_puts(bio_err, "Error enabling RPK verification\n"); - goto end; + BIO_printf(bio_s_out, "Error compressing certs on ctx2\n"); } + if (enable_server_rpk) + if (!SSL_CTX_set1_server_cert_type(ctx, cert_type_rpk, sizeof(cert_type_rpk))) { + BIO_printf(bio_s_out, "Error setting server certificate types\n"); + goto end; + } + if (enable_client_rpk) + if (!SSL_CTX_set1_client_cert_type(ctx, cert_type_rpk, sizeof(cert_type_rpk))) { + BIO_printf(bio_s_out, "Error setting server certificate types\n"); + goto end; + } if (rev) server_cb = rev_body; @@ -3128,16 +2666,13 @@ int s_server_main(int argc, char *argv[]) unlink(host); #endif if (tfo) - BIO_puts(bio_s_out, "Listening for TFO\n"); + BIO_printf(bio_s_out, "Listening for TFO\n"); do_server(&accept_socket, host, port, socket_family, socket_type, protocol, server_cb, context, naccept, bio_s_out, tfo); print_stats(bio_s_out, ctx); ret = 0; end: SSL_CTX_free(ctx); -#ifndef OPENSSL_NO_SRP - cleanup_srp(&srp_callback_parm); -#endif SSL_SESSION_free(psksess); set_keylog_file(NULL, NULL); X509_free(s_cert); @@ -3166,7 +2701,6 @@ end: OPENSSL_free(alpn_ctx.data); ssl_excert_free(exc); sk_OPENSSL_STRING_free(ssl_args); - sk_OPENSSL_STRING_free(rpk_files); SSL_CONF_CTX_free(cctx); BIO_free(bio_s_out); bio_s_out = NULL; @@ -3180,29 +2714,28 @@ end: static void print_stats(BIO *bio, SSL_CTX *ssl_ctx) { - BIO_printf(bio, "%4ld items in the session cache\n" - "%4ld client connects (SSL_connect())\n" - "%4ld client renegotiates (SSL_connect())\n" - "%4ld client connects that finished\n" - "%4ld server accepts (SSL_accept())\n" - "%4ld server renegotiates (SSL_accept())\n" - "%4ld server accepts that finished\n" - "%4ld session cache hits\n" - "%4ld session cache misses\n" - "%4ld session cache timeouts\n" - "%4ld callback cache hits\n" - "%4ld cache full overflows (%ld allowed)\n", - SSL_CTX_sess_number(ssl_ctx), - SSL_CTX_sess_connect(ssl_ctx), - SSL_CTX_sess_connect_renegotiate(ssl_ctx), - SSL_CTX_sess_connect_good(ssl_ctx), - SSL_CTX_sess_accept(ssl_ctx), - SSL_CTX_sess_accept_renegotiate(ssl_ctx), - SSL_CTX_sess_accept_good(ssl_ctx), - SSL_CTX_sess_hits(ssl_ctx), - SSL_CTX_sess_misses(ssl_ctx), - SSL_CTX_sess_timeouts(ssl_ctx), - SSL_CTX_sess_cb_hits(ssl_ctx), + BIO_printf(bio, "%4ld items in the session cache\n", + SSL_CTX_sess_number(ssl_ctx)); + BIO_printf(bio, "%4ld client connects (SSL_connect())\n", + SSL_CTX_sess_connect(ssl_ctx)); + BIO_printf(bio, "%4ld client renegotiates (SSL_connect())\n", + SSL_CTX_sess_connect_renegotiate(ssl_ctx)); + BIO_printf(bio, "%4ld client connects that finished\n", + SSL_CTX_sess_connect_good(ssl_ctx)); + BIO_printf(bio, "%4ld server accepts (SSL_accept())\n", + SSL_CTX_sess_accept(ssl_ctx)); + BIO_printf(bio, "%4ld server renegotiates (SSL_accept())\n", + SSL_CTX_sess_accept_renegotiate(ssl_ctx)); + BIO_printf(bio, "%4ld server accepts that finished\n", + SSL_CTX_sess_accept_good(ssl_ctx)); + BIO_printf(bio, "%4ld session cache hits\n", SSL_CTX_sess_hits(ssl_ctx)); + BIO_printf(bio, "%4ld session cache misses\n", + SSL_CTX_sess_misses(ssl_ctx)); + BIO_printf(bio, "%4ld session cache timeouts\n", + SSL_CTX_sess_timeouts(ssl_ctx)); + BIO_printf(bio, "%4ld callback cache hits\n", + SSL_CTX_sess_cb_hits(ssl_ctx)); + BIO_printf(bio, "%4ld cache full overflows (%ld allowed)\n", SSL_CTX_sess_cache_full(ssl_ctx), SSL_CTX_sess_get_cache_size(ssl_ctx)); } @@ -3231,19 +2764,6 @@ static long int count_reads_callback(BIO *bio, int cmd, const char *argp, size_t return ret; } -static int rpk_enable(SSL *con) -{ - if (!SSL_dane_enable(con, NULL)) - return 0; - for (int i = 0; i < sk_OPENSSL_STRING_num(rpk_files); ++i) { - const char *file = sk_OPENSSL_STRING_value(rpk_files, i); - - if (!load_rpk_file(con, file)) - return 0; - } - return 1; -} - static int sv_body(int s, int stype, int prot, unsigned char *context) { char *buf = NULL; @@ -3270,7 +2790,7 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) if (!BIO_socket_nbio(s, 1)) ERR_print_errors(bio_err); else if (!s_quiet) - BIO_puts(bio_err, "Turned on non blocking io\n"); + BIO_printf(bio_err, "Turned on non blocking io\n"); } con = SSL_new(ctx); @@ -3287,23 +2807,16 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) if (context != NULL && !SSL_set_session_id_context(con, context, (unsigned int)strlen((char *)context))) { - BIO_puts(bio_err, "Error setting session id context\n"); + BIO_printf(bio_err, "Error setting session id context\n"); ret = -1; goto err; } if (!SSL_clear(con)) { - BIO_puts(bio_err, "Error clearing SSL connection\n"); + BIO_printf(bio_err, "Error clearing SSL connection\n"); ret = -1; goto err; } - - if (rpk_files != NULL && !rpk_enable(con)) { - BIO_puts(bio_err, "Error enabling client RPK verification\n"); - ret = -1; - goto err; - } - #ifndef OPENSSL_NO_DTLS if (isdtls) { #ifndef OPENSSL_NO_SCTP @@ -3313,7 +2826,7 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) #endif sbio = BIO_new_dgram(s, BIO_NOCLOSE); if (sbio == NULL) { - BIO_puts(bio_err, "Unable to create BIO\n"); + BIO_printf(bio_err, "Unable to create BIO\n"); ERR_print_errors(bio_err); goto err; } @@ -3338,7 +2851,7 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) } SSL_set_options(con, SSL_OP_NO_QUERY_MTU); if (!DTLS_set_link_mtu(con, socket_mtu)) { - BIO_puts(bio_err, "Failed to set MTU\n"); + BIO_printf(bio_err, "Failed to set MTU\n"); ret = -1; BIO_free(sbio); goto err; @@ -3357,7 +2870,7 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) sbio = BIO_new_socket(s, BIO_NOCLOSE); if (sbio == NULL) { - BIO_puts(bio_err, "Unable to create BIO\n"); + BIO_printf(bio_err, "Unable to create BIO\n"); ERR_print_errors(bio_err); goto err; } @@ -3367,7 +2880,7 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) test = BIO_new(BIO_f_nbio_test()); if (test == NULL) { - BIO_puts(bio_err, "Unable to create BIO\n"); + BIO_printf(bio_err, "Unable to create BIO\n"); ret = -1; BIO_free(sbio); goto err; @@ -3412,14 +2925,14 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) /* Just keep trying - busy waiting */ continue; default: - BIO_puts(bio_err, "Error reading early data\n"); + BIO_printf(bio_err, "Error reading early data\n"); ERR_print_errors(bio_err); goto err; } } if (readbytes > 0) { if (write_header) { - BIO_puts(bio_s_out, "Early data received:\n"); + BIO_printf(bio_s_out, "Early data received:\n"); write_header = 0; } raw_write_stdout(buf, (unsigned int)readbytes); @@ -3428,11 +2941,11 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) } if (write_header) { if (SSL_get_early_data_status(con) == SSL_EARLY_DATA_NOT_SENT) - BIO_puts(bio_s_out, "No early data received\n"); + BIO_printf(bio_s_out, "No early data received\n"); else - BIO_puts(bio_s_out, "Early data was rejected\n"); + BIO_printf(bio_s_out, "Early data was rejected\n"); } else { - BIO_puts(bio_s_out, "\nEnd of early data\n"); + BIO_printf(bio_s_out, "\nEnd of early data\n"); } if (SSL_is_init_finished(con)) print_connection_info(con); @@ -3487,7 +3000,7 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) i = select(width, (void *)&readfds, NULL, NULL, timeoutp); if ((SSL_is_dtls(con)) && DTLSv1_handle_timeout(con) > 0) - BIO_puts(bio_err, "TIMEOUT occurred\n"); + BIO_printf(bio_err, "TIMEOUT occurred\n"); if (i <= 0) continue; @@ -3522,7 +3035,7 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) if (!s_quiet && !s_brief) { if ((i <= 0) || (buf[0] == 'Q')) { - BIO_puts(bio_s_out, "DONE\n"); + BIO_printf(bio_s_out, "DONE\n"); (void)BIO_flush(bio_s_out); BIO_closesocket(s); close_accept_socket(); @@ -3530,7 +3043,7 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) goto err; } if ((i <= 0) || (buf[0] == 'q')) { - BIO_puts(bio_s_out, "DONE\n"); + BIO_printf(bio_s_out, "DONE\n"); (void)BIO_flush(bio_s_out); if (SSL_version(con) != DTLS1_VERSION) BIO_closesocket(s); @@ -3590,7 +3103,7 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) k = SSL_write(con, &(buf[l]), (unsigned int)i); #ifndef OPENSSL_NO_SRP while (SSL_get_error(con, k) == SSL_ERROR_WANT_X509_LOOKUP) { - BIO_puts(bio_s_out, "LOOKUP renego during write\n"); + BIO_printf(bio_s_out, "LOOKUP renego during write\n"); lookup_srp_user(&srp_callback_parm, bio_s_out); @@ -3601,14 +3114,14 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) case SSL_ERROR_NONE: break; case SSL_ERROR_WANT_ASYNC: - BIO_puts(bio_s_out, "Write BLOCK (Async)\n"); + BIO_printf(bio_s_out, "Write BLOCK (Async)\n"); (void)BIO_flush(bio_s_out); wait_for_async(con); break; case SSL_ERROR_WANT_WRITE: case SSL_ERROR_WANT_READ: case SSL_ERROR_WANT_X509_LOOKUP: - BIO_puts(bio_s_out, "Write BLOCK\n"); + BIO_printf(bio_s_out, "Write BLOCK\n"); (void)BIO_flush(bio_s_out); break; case SSL_ERROR_WANT_ASYNC_JOB: @@ -3617,14 +3130,14 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) */ case SSL_ERROR_SYSCALL: case SSL_ERROR_SSL: - BIO_puts(bio_s_out, "ERROR\n"); + BIO_printf(bio_s_out, "ERROR\n"); (void)BIO_flush(bio_s_out); ERR_print_errors(bio_err); ret = 1; goto err; /* break; */ case SSL_ERROR_ZERO_RETURN: - BIO_puts(bio_s_out, "DONE\n"); + BIO_printf(bio_s_out, "DONE\n"); (void)BIO_flush(bio_s_out); ret = 1; goto err; @@ -3676,7 +3189,7 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) i = SSL_read(con, (char *)buf, bufsize); #ifndef OPENSSL_NO_SRP while (SSL_get_error(con, i) == SSL_ERROR_WANT_X509_LOOKUP) { - BIO_puts(bio_s_out, "LOOKUP renego during read\n"); + BIO_printf(bio_s_out, "LOOKUP renego during read\n"); lookup_srp_user(&srp_callback_parm, bio_s_out); @@ -3694,13 +3207,13 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) goto again; break; case SSL_ERROR_WANT_ASYNC: - BIO_puts(bio_s_out, "Read BLOCK (Async)\n"); + BIO_printf(bio_s_out, "Read BLOCK (Async)\n"); (void)BIO_flush(bio_s_out); wait_for_async(con); break; case SSL_ERROR_WANT_WRITE: case SSL_ERROR_WANT_READ: - BIO_puts(bio_s_out, "Read BLOCK\n"); + BIO_printf(bio_s_out, "Read BLOCK\n"); (void)BIO_flush(bio_s_out); break; case SSL_ERROR_WANT_ASYNC_JOB: @@ -3709,13 +3222,13 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) */ case SSL_ERROR_SYSCALL: case SSL_ERROR_SSL: - BIO_puts(bio_s_out, "ERROR\n"); + BIO_printf(bio_s_out, "ERROR\n"); (void)BIO_flush(bio_s_out); ERR_print_errors(bio_err); ret = 1; goto err; case SSL_ERROR_ZERO_RETURN: - BIO_puts(bio_s_out, "DONE\n"); + BIO_printf(bio_s_out, "DONE\n"); (void)BIO_flush(bio_s_out); ret = 1; goto err; @@ -3725,18 +3238,18 @@ static int sv_body(int s, int stype, int prot, unsigned char *context) } err: if (con != NULL) { - BIO_puts(bio_s_out, "shutting down SSL\n"); + BIO_printf(bio_s_out, "shutting down SSL\n"); do_ssl_shutdown(con); SSL_free(con); } - BIO_puts(bio_s_out, "CONNECTION CLOSED\n"); + BIO_printf(bio_s_out, "CONNECTION CLOSED\n"); OPENSSL_clear_free(buf, bufsize); return ret; } static void close_accept_socket(void) { - BIO_puts(bio_err, "shutdown accept socket\n"); + BIO_printf(bio_err, "shutdown accept socket\n"); if (accept_socket >= 0) { BIO_closesocket(accept_socket); } @@ -3763,7 +3276,7 @@ static int init_ssl_connection(SSL *con) if (dtlslisten) { if ((client = BIO_ADDR_new()) == NULL) { - BIO_puts(bio_err, "ERROR - memory\n"); + BIO_printf(bio_err, "ERROR - memory\n"); return 0; } i = DTLSv1_listen(con, client); @@ -3781,7 +3294,7 @@ static int init_ssl_connection(SSL *con) } if (!wbio || BIO_connect(fd, client, 0) == 0) { - BIO_puts(bio_err, "ERROR - unable to connect\n"); + BIO_printf(bio_err, "ERROR - unable to connect\n"); BIO_ADDR_free(client); return 0; } @@ -3807,7 +3320,7 @@ static int init_ssl_connection(SSL *con) while (i <= 0 && SSL_get_error(con, i) == SSL_ERROR_WANT_X509_LOOKUP && SSL_get_state(con) == TLS_ST_SR_CLNT_HELLO) { - BIO_puts(bio_err, + BIO_printf(bio_err, "LOOKUP from certificate callback during accept\n"); i = SSL_accept(con); if (i <= 0) @@ -3835,11 +3348,11 @@ static int init_ssl_connection(SSL *con) if (i <= 0) { if (((dtlslisten || stateless) && i == 0) || (!dtlslisten && !stateless && retry)) { - BIO_puts(bio_s_out, "DELAY\n"); + BIO_printf(bio_s_out, "DELAY\n"); return 1; } - BIO_puts(bio_err, "ERROR\n"); + BIO_printf(bio_err, "ERROR\n"); verify_err = SSL_get_verify_result(con); if (verify_err != X509_V_OK) { @@ -3874,21 +3387,21 @@ static void print_connection_info(SSL *con) peer = SSL_get0_peer_certificate(con); if (peer != NULL) { - BIO_puts(bio_s_out, "Client certificate\n"); + BIO_printf(bio_s_out, "Client certificate\n"); PEM_write_bio_X509(bio_s_out, peer); dump_cert_text(bio_s_out, peer); peer = NULL; } /* Only display RPK information if configured */ if (SSL_get_negotiated_server_cert_type(con) == TLSEXT_cert_type_rpk) - BIO_puts(bio_s_out, "Server-to-client raw public key negotiated\n"); + BIO_printf(bio_s_out, "Server-to-client raw public key negotiated\n"); if (SSL_get_negotiated_client_cert_type(con) == TLSEXT_cert_type_rpk) - BIO_puts(bio_s_out, "Client-to-server raw public key negotiated\n"); + BIO_printf(bio_s_out, "Client-to-server raw public key negotiated\n"); if (enable_client_rpk) { EVP_PKEY *client_rpk = SSL_get0_peer_rpk(con); if (client_rpk != NULL) { - BIO_puts(bio_s_out, "Client raw public key\n"); + BIO_printf(bio_s_out, "Client raw public key\n"); EVP_PKEY_print_public(bio_s_out, client_rpk, 2, NULL); } } @@ -3907,9 +3420,9 @@ static void print_connection_info(SSL *con) #if !defined(OPENSSL_NO_NEXTPROTONEG) SSL_get0_next_proto_negotiated(con, &next_proto_neg, &next_proto_neg_len); if (next_proto_neg) { - BIO_puts(bio_s_out, "NEXTPROTO is "); + BIO_printf(bio_s_out, "NEXTPROTO is "); BIO_write(bio_s_out, next_proto_neg, next_proto_neg_len); - BIO_puts(bio_s_out, "\n"); + BIO_printf(bio_s_out, "\n"); } #endif #ifndef OPENSSL_NO_SRTP @@ -3923,19 +3436,17 @@ static void print_connection_info(SSL *con) } #endif if (SSL_session_reused(con)) - BIO_puts(bio_s_out, "Reused session-id\n"); + BIO_printf(bio_s_out, "Reused session-id\n"); ssl_print_secure_renegotiation_notes(bio_s_out, con); if ((SSL_get_options(con) & SSL_OP_NO_RENEGOTIATION)) - BIO_puts(bio_s_out, "Renegotiation is DISABLED\n"); + BIO_printf(bio_s_out, "Renegotiation is DISABLED\n"); - if (keymatexportlabel != NULL && keymatexportlen > 0) { - BIO_printf(bio_s_out, "Keying material exporter:\n" - " Label: '%s'\n" - " Length: %i bytes\n", - keymatexportlabel, - keymatexportlen); + if (keymatexportlabel != NULL) { + BIO_printf(bio_s_out, "Keying material exporter:\n"); + BIO_printf(bio_s_out, " Label: '%s'\n", keymatexportlabel); + BIO_printf(bio_s_out, " Length: %i bytes\n", keymatexportlen); exportedkeymat = app_malloc(keymatexportlen, "export key"); if (SSL_export_keying_material(con, exportedkeymat, keymatexportlen, @@ -3943,20 +3454,20 @@ static void print_connection_info(SSL *con) strlen(keymatexportlabel), NULL, 0, 0) <= 0) { - BIO_puts(bio_s_out, " Error\n"); + BIO_printf(bio_s_out, " Error\n"); } else { - BIO_puts(bio_s_out, " Keying material: "); + BIO_printf(bio_s_out, " Keying material: "); for (i = 0; i < keymatexportlen; i++) BIO_printf(bio_s_out, "%02X", exportedkeymat[i]); - BIO_puts(bio_s_out, "\n"); + BIO_printf(bio_s_out, "\n"); } OPENSSL_free(exportedkeymat); } #ifndef OPENSSL_NO_KTLS if (BIO_get_ktls_send(SSL_get_wbio(con))) - BIO_puts(bio_err, "Using Kernel TLS for sending\n"); + BIO_printf(bio_err, "Using Kernel TLS for sending\n"); if (BIO_get_ktls_recv(SSL_get_rbio(con))) - BIO_puts(bio_err, "Using Kernel TLS for receiving\n"); + BIO_printf(bio_err, "Using Kernel TLS for receiving\n"); #endif (void)BIO_flush(bio_s_out); @@ -3996,7 +3507,7 @@ static int www_body(int s, int stype, int prot, unsigned char *context) if (!BIO_socket_nbio(s, 1)) ERR_print_errors(bio_err); else if (!s_quiet) - BIO_puts(bio_err, "Turned on non blocking io\n"); + BIO_printf(bio_err, "Turned on non blocking io\n"); } /* lets make the output buffer a reasonable size */ @@ -4018,12 +3529,6 @@ static int www_body(int s, int stype, int prot, unsigned char *context) goto err; } - if (rpk_files != NULL && !rpk_enable(con)) { - BIO_puts(bio_err, "Error enabling client RPK verification\n"); - SSL_free(con); - goto err; - } - sbio = BIO_new_socket(s, BIO_NOCLOSE); if (sbio == NULL) { SSL_free(con); @@ -4094,7 +3599,7 @@ static int www_body(int s, int stype, int prot, unsigned char *context) /* Just keep trying - busy waiting */ continue; default: - BIO_puts(bio_err, "Error reading early data\n"); + BIO_printf(bio_err, "Error reading early data\n"); ERR_print_errors(bio_err); goto err; } @@ -4112,11 +3617,11 @@ static int www_body(int s, int stype, int prot, unsigned char *context) ERR_print_errors(bio_err); goto err; } else { - BIO_puts(bio_s_out, "read R BLOCK\n"); + BIO_printf(bio_s_out, "read R BLOCK\n"); #ifndef OPENSSL_NO_SRP if (BIO_should_io_special(io) && BIO_get_retry_reason(io) == BIO_RR_SSL_X509_LOOKUP) { - BIO_puts(bio_s_out, "LOOKUP renego during read\n"); + BIO_printf(bio_s_out, "LOOKUP renego during read\n"); lookup_srp_user(&srp_callback_parm, bio_s_out); @@ -4137,10 +3642,6 @@ static int www_body(int s, int stype, int prot, unsigned char *context) X509 *peer = NULL; STACK_OF(SSL_CIPHER) *sk; static const char *space = " "; -#ifndef OPENSSL_NO_ECH - char *ech_inner = NULL, *ech_outer = NULL; - int echrv = 0; -#endif if (www == 1 && HAS_PREFIX(buf, "GET /reneg")) { if (HAS_PREFIX(buf, "GET /renegcert")) @@ -4162,7 +3663,7 @@ static int www_body(int s, int stype, int prot, unsigned char *context) openssl_fdset(s, &readfds); i = select(width, (void *)&readfds, NULL, NULL, NULL); if (i <= 0 || !FD_ISSET(s, &readfds)) { - BIO_puts(bio_s_out, + BIO_printf(bio_s_out, "Error waiting for client response\n"); ERR_print_errors(bio_err); goto err; @@ -4177,9 +3678,9 @@ static int www_body(int s, int stype, int prot, unsigned char *context) } BIO_puts(io, - "HTTP/1.0 200 ok\r\nContent-type: text/html\r\n\r\n" - "\n" - "
\n");
+                "HTTP/1.0 200 ok\r\nContent-type: text/html\r\n\r\n");
+            BIO_puts(io, "\n");
+            BIO_puts(io, "
\n");
             /* BIO_puts(io, OpenSSL_version(OPENSSL_VERSION)); */
             BIO_puts(io, "\n");
             for (i = 0; i < local_argc; i++) {
@@ -4204,86 +3705,12 @@ static int www_body(int s, int stype, int prot, unsigned char *context)
             }
             BIO_puts(io, "\n");
 
-#ifndef OPENSSL_NO_ECH
-            /* Customise output a bit to show ECH info at top */
-            BIO_puts(io, "

OpenSSL with ECH

\n"); - BIO_puts(io, "

\n"); - echrv = SSL_ech_get1_status(con, &ech_inner, &ech_outer); - switch (echrv) { - case SSL_ECH_STATUS_NOT_TRIED: - BIO_puts(io, "ECH not attempted\n"); - break; - case SSL_ECH_STATUS_FAILED: - BIO_puts(io, "ECH tried but failed\n"); - break; - case SSL_ECH_STATUS_FAILED_ECH: - BIO_puts(io, "ECH tried but we got ECH which is weird\n"); - break; - case SSL_ECH_STATUS_BAD_NAME: - BIO_puts(io, "ECH worked but bad name\n"); - break; - case SSL_ECH_STATUS_BACKEND: - BIO_printf(io, "ECH acting as backend\n"); - break; - case SSL_ECH_STATUS_NOT_CONFIGURED: - BIO_printf(io, "ECH not configured\n"); - break; - case SSL_ECH_STATUS_GREASE: - BIO_printf(io, "ECH attempt we interpret as GREASE\n"); - break; - case SSL_ECH_STATUS_GREASE_ECH: - BIO_printf(io, "ECH attempt we interpret as GREASE, + ECH\n"); - break; - case SSL_ECH_STATUS_BAD_CALL: - BIO_printf(io, "ECH bad input to API\n"); - break; - case SSL_ECH_STATUS_SUCCESS: - BIO_printf(io, "ECH success: outer sni: %s, inner sni: %s\n", - (ech_outer == NULL ? "none" : ech_outer), - (ech_inner == NULL ? "none" : ech_inner)); - break; - default: - BIO_printf(io, " Error getting ECH status\n"); - break; - } - BIO_puts(io, "

\n"); - BIO_puts(io, "

TLS Session details

\n"); - BIO_puts(io, "
\n");
-            /*
-             * also dump session info to server stdout for debugging
-             */
-            SSL_SESSION_print(bio_s_out, SSL_get_session(con));
-            BIO_puts(io, "
\n");
-            BIO_puts(io, "\n");
-            for (i = 0; i < local_argc; i++) {
-                const char *myp;
-
-                for (myp = local_argv[i]; *myp; myp++)
-                    switch (*myp) {
-                    case '<':
-                        BIO_puts(io, "<");
-                        break;
-                    case '>':
-                        BIO_puts(io, ">");
-                        break;
-                    case '&':
-                        BIO_puts(io, "&");
-                        break;
-                    default:
-                        BIO_write(io, myp, 1);
-                        break;
-                    }
-                BIO_write(io, " ", 1);
-            }
-            BIO_puts(io, "\n");
-#endif
-
             ssl_print_secure_renegotiation_notes(io, con);
 
             /*
              * The following is evil and should not really be done
              */
-            BIO_puts(io, "Ciphers supported in s_server binary\n");
+            BIO_printf(io, "Ciphers supported in s_server binary\n");
             sk = SSL_get_ciphers(con);
             j = sk_SSL_CIPHER_num(sk);
             for (i = 0; i < j; i++) {
@@ -4296,7 +3723,7 @@ static int www_body(int s, int stype, int prot, unsigned char *context)
             BIO_puts(io, "\n");
             p = SSL_get_shared_ciphers(con, buf, bufsize);
             if (p != NULL) {
-                BIO_puts(io,
+                BIO_printf(io,
                     "---\nCiphers common between both SSL end points:\n");
                 j = i = 0;
                 while (*p) {
@@ -4323,12 +3750,12 @@ static int www_body(int s, int stype, int prot, unsigned char *context)
             BIO_printf(io, "%s, Cipher is %s\n",
                 SSL_CIPHER_get_version(c), SSL_CIPHER_get_name(c));
             SSL_SESSION_print(io, SSL_get_session(con));
-            BIO_puts(io, "---\n");
+            BIO_printf(io, "---\n");
             print_stats(io, SSL_get_SSL_CTX(con));
-            BIO_puts(io, "---\n");
+            BIO_printf(io, "---\n");
             peer = SSL_get0_peer_certificate(con);
             if (peer != NULL) {
-                BIO_puts(io, "Client certificate\n");
+                BIO_printf(io, "Client certificate\n");
                 X509_print(io, peer);
                 PEM_write_bio_X509(io, peer);
                 peer = NULL;
@@ -4371,30 +3798,35 @@ static int www_body(int s, int stype, int prot, unsigned char *context)
                                               * component */
 
             if (*e == '\0') {
-                BIO_printf(io, "%s'%s' is an invalid file name\r\n", text, p);
+                BIO_puts(io, text);
+                BIO_printf(io, "'%s' is an invalid file name\r\n", p);
                 break;
             }
             *e = '\0';
 
             if (dot) {
-                BIO_printf(io, "%s'%s' contains '..' or ':'\r\n", text, p);
+                BIO_puts(io, text);
+                BIO_printf(io, "'%s' contains '..' or ':'\r\n", p);
                 break;
             }
 
             if (*p == '/' || *p == '\\') {
-                BIO_printf(io, "%s'%s' is an invalid path\r\n", text, p);
+                BIO_puts(io, text);
+                BIO_printf(io, "'%s' is an invalid path\r\n", p);
                 break;
             }
 
             /* if a directory, do the index thang */
             if (app_isdir(p) > 0) {
-                BIO_printf(io, "%s'%s' is a directory\r\n", text, p);
+                BIO_puts(io, text);
+                BIO_printf(io, "'%s' is a directory\r\n", p);
                 break;
             }
 
             opmode = (http_server_binmode == 1) ? "rb" : "r";
             if ((file = BIO_new_file(p, opmode)) == NULL) {
-                BIO_printf(io, "%sError opening '%s' mode='%s'\r\n", text, p, opmode);
+                BIO_puts(io, text);
+                BIO_printf(io, "Error opening '%s' mode='%s'\r\n", p, opmode);
                 ERR_print_errors(io);
                 break;
             }
@@ -4414,7 +3846,7 @@ static int www_body(int s, int stype, int prot, unsigned char *context)
             /* send the file */
 #ifndef OPENSSL_NO_KTLS
             if (use_sendfile_for_req && !BIO_get_ktls_send(SSL_get_wbio(con))) {
-                BIO_puts(bio_err, "Warning: sendfile requested but KTLS is not available\n");
+                BIO_printf(bio_err, "Warning: sendfile requested but KTLS is not available\n");
                 use_sendfile_for_req = 0;
             }
             if (use_sendfile_for_req) {
@@ -4469,7 +3901,7 @@ static int www_body(int s, int stype, int prot, unsigned char *context)
                                 && !SSL_waiting_for_async(con)) {
                                 goto write_error;
                             } else {
-                                BIO_puts(bio_s_out, "rwrite W BLOCK\n");
+                                BIO_printf(bio_s_out, "rwrite W BLOCK\n");
                             }
                         } else {
                             j += k;
@@ -4541,13 +3973,6 @@ static int rev_body(int s, int stype, int prot, unsigned char *context)
         goto err;
     }
 
-    if (rpk_files != NULL && !rpk_enable(con)) {
-        BIO_puts(bio_err, "Error enabling client RPK verification\n");
-        ERR_print_errors(bio_err);
-        SSL_free(con);
-        goto err;
-    }
-
     sbio = BIO_new_socket(s, BIO_NOCLOSE);
     if (sbio == NULL) {
         SSL_free(con);
@@ -4596,7 +4021,7 @@ static int rev_body(int s, int stype, int prot, unsigned char *context)
 #ifndef OPENSSL_NO_SRP
         if (BIO_should_io_special(io)
             && BIO_get_retry_reason(io) == BIO_RR_SSL_X509_LOOKUP) {
-            BIO_puts(bio_s_out, "LOOKUP renego during accept\n");
+            BIO_printf(bio_s_out, "LOOKUP renego during accept\n");
 
             lookup_srp_user(&srp_callback_parm, bio_s_out);
 
@@ -4604,7 +4029,7 @@ static int rev_body(int s, int stype, int prot, unsigned char *context)
         }
 #endif
     }
-    BIO_puts(bio_err, "CONNECTION ESTABLISHED\n");
+    BIO_printf(bio_err, "CONNECTION ESTABLISHED\n");
     print_ssl_summary(con);
 
     for (;;) {
@@ -4615,11 +4040,11 @@ static int rev_body(int s, int stype, int prot, unsigned char *context)
                     ERR_print_errors(bio_err);
                 goto err;
             } else {
-                BIO_puts(bio_s_out, "read R BLOCK\n");
+                BIO_printf(bio_s_out, "read R BLOCK\n");
 #ifndef OPENSSL_NO_SRP
                 if (BIO_should_io_special(io)
                     && BIO_get_retry_reason(io) == BIO_RR_SSL_X509_LOOKUP) {
-                    BIO_puts(bio_s_out, "LOOKUP renego during read\n");
+                    BIO_printf(bio_s_out, "LOOKUP renego during read\n");
 
                     lookup_srp_user(&srp_callback_parm, bio_s_out);
 
@@ -4631,7 +4056,7 @@ static int rev_body(int s, int stype, int prot, unsigned char *context)
             }
         } else if (i == 0) { /* end of input */
             ret = 1;
-            BIO_puts(bio_err, "CONNECTION CLOSED\n");
+            BIO_printf(bio_err, "CONNECTION CLOSED\n");
             goto end;
         } else {
             char *p = buf + i - 1;
@@ -4641,7 +4066,7 @@ static int rev_body(int s, int stype, int prot, unsigned char *context)
             }
             if (!s_ign_eof && i == 5 && HAS_PREFIX(buf, "CLOSE")) {
                 ret = 1;
-                BIO_puts(bio_err, "CONNECTION CLOSED\n");
+                BIO_printf(bio_err, "CONNECTION CLOSED\n");
                 goto end;
             }
             BUF_reverse((unsigned char *)buf, NULL, i);
@@ -4717,8 +4142,8 @@ static int add_session(SSL *ssl, SSL_SESSION *session)
 
     SSL_SESSION_get_id(session, &sess->idlen);
     sess->derlen = i2d_SSL_SESSION(session, NULL);
-    if (sess->derlen <= 0) {
-        BIO_puts(bio_err, "Error encoding session\n");
+    if (sess->derlen < 0) {
+        BIO_printf(bio_err, "Error encoding session\n");
         OPENSSL_free(sess);
         return 0;
     }
@@ -4726,7 +4151,7 @@ static int add_session(SSL *ssl, SSL_SESSION *session)
     sess->id = OPENSSL_memdup(SSL_SESSION_get_id(session, NULL), sess->idlen);
     sess->der = app_malloc(sess->derlen, "get session buffer");
     if (!sess->id) {
-        BIO_puts(bio_err, "Out of memory adding to external cache\n");
+        BIO_printf(bio_err, "Out of memory adding to external cache\n");
         OPENSSL_free(sess->id);
         OPENSSL_free(sess->der);
         OPENSSL_free(sess);
@@ -4736,7 +4161,7 @@ static int add_session(SSL *ssl, SSL_SESSION *session)
 
     /* Assume it still works. */
     if (i2d_SSL_SESSION(session, &p) != sess->derlen) {
-        BIO_puts(bio_err, "Unexpected session encoding length\n");
+        BIO_printf(bio_err, "Unexpected session encoding length\n");
         OPENSSL_free(sess->id);
         OPENSSL_free(sess->der);
         OPENSSL_free(sess);
@@ -4745,7 +4170,7 @@ static int add_session(SSL *ssl, SSL_SESSION *session)
 
     sess->next = first;
     first = sess;
-    BIO_puts(bio_err, "New session added to external cache\n");
+    BIO_printf(bio_err, "New session added to external cache\n");
     return 0;
 }
 
@@ -4757,12 +4182,12 @@ static SSL_SESSION *get_session(SSL *ssl, const unsigned char *id, int idlen,
     for (sess = first; sess; sess = sess->next) {
         if (idlen == (int)sess->idlen && !memcmp(sess->id, id, idlen)) {
             const unsigned char *p = sess->der;
-            BIO_puts(bio_err, "Lookup session: cache hit\n");
+            BIO_printf(bio_err, "Lookup session: cache hit\n");
             return d2i_SSL_SESSION_ex(NULL, &p, sess->derlen, app_get0_libctx(),
                 app_get0_propq());
         }
     }
-    BIO_puts(bio_err, "Lookup session: cache miss\n");
+    BIO_printf(bio_err, "Lookup session: cache miss\n");
     return NULL;
 }
 
diff --git a/apps/s_time.c b/apps/s_time.c
index d68418445c..e52f456838 100644
--- a/apps/s_time.c
+++ b/apps/s_time.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -61,19 +61,18 @@ typedef enum OPTION_choice {
     OPT_BUGS,
     OPT_VERIFY,
     OPT_TIME,
+    OPT_SSL3,
     OPT_WWW,
     OPT_TLS1,
     OPT_TLS1_1,
     OPT_TLS1_2,
     OPT_TLS1_3,
-    OPT_TESTMODE,
     OPT_PROV_ENUM
 } OPTION_CHOICE;
 
 const OPTIONS s_time_options[] = {
     OPT_SECTION("General"),
     { "help", OPT_HELP, '-', "Display this summary" },
-    { "testmode", OPT_TESTMODE, '-', "Run the s_time command in test mode" },
 
     OPT_SECTION("Connection"),
     { "connect", OPT_CONNECT, 's',
@@ -84,6 +83,9 @@ const OPTIONS s_time_options[] = {
     { "cipher", OPT_CIPHER, 's', "TLSv1.2 and below cipher list to be used" },
     { "ciphersuites", OPT_CIPHERSUITES, 's',
         "Specify TLSv1.3 ciphersuites to be used" },
+#ifndef OPENSSL_NO_SSL3
+    { "ssl3", OPT_SSL3, '-', "Just use SSLv3" },
+#endif
 #ifndef OPENSSL_NO_TLS1
     { "tls1", OPT_TLS1, '-', "Just use TLSv1.0" },
 #endif
@@ -105,10 +107,10 @@ const OPTIONS s_time_options[] = {
     { "nameopt", OPT_NAMEOPT, 's', "Certificate subject/issuer name printing options" },
     { "cert", OPT_CERT, '<', "Cert file to use, PEM format assumed" },
     { "key", OPT_KEY, '<', "File with key, PEM; default is -cert file" },
-    { "cafile", OPT_CAFILE, '<', "Deprecated alias of -CAfile" },
-    { "CAfile", OPT_CAFILE, '<', "File in PEM format with trusted CA certs" },
-    { "CApath", OPT_CAPATH, '/', "Dir with trusted CA cert files in PEM format" },
-    { "CAstore", OPT_CASTORE, ':', "URI of store with trusted CA certs" },
+    { "cafile", OPT_CAFILE, '<', "PEM format file of CA's" },
+    { "CAfile", OPT_CAFILE, '<', "PEM format file of CA's" },
+    { "CApath", OPT_CAPATH, '/', "PEM format directory of CA's" },
+    { "CAstore", OPT_CASTORE, ':', "URI to store of CA's" },
     { "no-CAfile", OPT_NOCAFILE, '-',
         "Do not load the default certificates file" },
     { "no-CApath", OPT_NOCAPATH, '-',
@@ -144,7 +146,7 @@ int s_time_main(int argc, char **argv)
     long bytes_read = 0, finishtime = 0;
     OPTION_CHOICE o;
     int min_version = 0, max_version = 0, ver, buf_len, fd;
-    int want_verify = 0, testmode = 0;
+    int want_verify = 0;
     size_t buf_size;
 
     meth = TLS_client_method();
@@ -224,6 +226,10 @@ int s_time_main(int argc, char **argv)
                 goto end;
             }
             break;
+        case OPT_SSL3:
+            min_version = SSL3_VERSION;
+            max_version = SSL3_VERSION;
+            break;
         case OPT_TLS1:
             min_version = TLS1_VERSION;
             max_version = TLS1_VERSION;
@@ -240,9 +246,6 @@ int s_time_main(int argc, char **argv)
             min_version = TLS1_3_VERSION;
             max_version = TLS1_3_VERSION;
             break;
-        case OPT_TESTMODE:
-            testmode = 1;
-            break;
         case OPT_PROV_CASES:
             if (!opt_provider(o))
                 goto end;
@@ -291,8 +294,7 @@ int s_time_main(int argc, char **argv)
 
     if (!(perform & 1))
         goto next;
-    if (!testmode)
-        printf("Collecting connection statistics for %d seconds\n", maxtime);
+    printf("Collecting connection statistics for %d seconds\n", maxtime);
 
     /* Loop and time how long it takes to make connections */
 
@@ -300,7 +302,7 @@ int s_time_main(int argc, char **argv)
     finishtime = (long)time(NULL) + maxtime;
     tm_Time_F(START);
     for (;;) {
-        if (testmode ? nConn >= 1 : finishtime < (long)time(NULL))
+        if (finishtime < (long)time(NULL))
             break;
 
         if ((scon = doConnection(NULL, host, ctx)) == NULL)
@@ -324,6 +326,8 @@ int s_time_main(int argc, char **argv)
             ver = SSL_version(scon);
             if (ver == TLS1_VERSION)
                 ver = 't';
+            else if (ver == SSL3_VERSION)
+                ver = '3';
             else
                 ver = '*';
         }
@@ -350,12 +354,11 @@ next:
         ret = 0;
         goto end;
     }
-    if (!testmode)
-        printf("\n\nNow timing with session id reuse.\n");
+    printf("\n\nNow timing with session id reuse.\n");
 
     /* Get an SSL object so we can reuse the session id */
     if ((scon = doConnection(NULL, host, ctx)) == NULL) {
-        BIO_puts(bio_err, "Unable to get connection\n");
+        BIO_printf(bio_err, "Unable to get connection\n");
         goto end;
     }
 
@@ -375,13 +378,12 @@ next:
 
     finishtime = (long)time(NULL) + maxtime;
 
-    if (!testmode)
-        printf("starting\n");
+    printf("starting\n");
     bytes_read = 0;
     tm_Time_F(START);
 
     for (;;) {
-        if (testmode ? nConn >= 2 : finishtime < (long)time(NULL))
+        if (finishtime < (long)time(NULL))
             break;
 
         if ((doConnection(scon, host, ctx)) == NULL)
@@ -406,6 +408,8 @@ next:
             ver = SSL_version(scon);
             if (ver == TLS1_VERSION)
                 ver = 't';
+            else if (ver == SSL3_VERSION)
+                ver = '3';
             else
                 ver = '*';
         }
@@ -474,7 +478,7 @@ static SSL *doConnection(SSL *scon, const char *host, SSL_CTX *ctx)
     /* ok, lets connect */
     i = SSL_connect(serverCon);
     if (i <= 0) {
-        BIO_puts(bio_err, "ERROR\n");
+        BIO_printf(bio_err, "ERROR\n");
         if (verify_args.error != X509_V_OK)
             BIO_printf(bio_err, "verify error:%s\n",
                 X509_verify_cert_error_string(verify_args.error));
diff --git a/apps/sess_id.c b/apps/sess_id.c
index 0d3d35a3bc..130670d1de 100644
--- a/apps/sess_id.c
+++ b/apps/sess_id.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -116,12 +116,12 @@ int sess_id_main(int argc, char **argv)
     if (context != NULL) {
         size_t ctx_len = strlen(context);
         if (ctx_len > SSL_MAX_SID_CTX_LENGTH) {
-            BIO_puts(bio_err, "Context too long\n");
+            BIO_printf(bio_err, "Context too long\n");
             goto end;
         }
         if (!SSL_SESSION_set1_id_context(x, (unsigned char *)context,
                 (unsigned int)ctx_len)) {
-            BIO_puts(bio_err, "Error setting id context\n");
+            BIO_printf(bio_err, "Error setting id context\n");
             goto end;
         }
     }
@@ -151,11 +151,11 @@ int sess_id_main(int argc, char **argv)
         } else if (outformat == FORMAT_NSS) {
             i = SSL_SESSION_print_keylog(out, x);
         } else {
-            BIO_puts(bio_err, "bad output format specified for outfile\n");
+            BIO_printf(bio_err, "bad output format specified for outfile\n");
             goto end;
         }
         if (!i) {
-            BIO_puts(bio_err, "unable to write SSL_SESSION\n");
+            BIO_printf(bio_err, "unable to write SSL_SESSION\n");
             goto end;
         }
     } else if (!noout && (peer != NULL)) { /* just print the certificate */
@@ -164,11 +164,11 @@ int sess_id_main(int argc, char **argv)
         } else if (outformat == FORMAT_PEM) {
             i = PEM_write_bio_X509(out, peer);
         } else {
-            BIO_puts(bio_err, "bad output format specified for outfile\n");
+            BIO_printf(bio_err, "bad output format specified for outfile\n");
             goto end;
         }
         if (!i) {
-            BIO_puts(bio_err, "unable to write X509\n");
+            BIO_printf(bio_err, "unable to write X509\n");
             goto end;
         }
     }
@@ -192,7 +192,7 @@ static SSL_SESSION *load_sess_id(char *infile, int format)
     else
         x = PEM_read_bio_SSL_SESSION(in, NULL, NULL, NULL);
     if (x == NULL) {
-        BIO_puts(bio_err, "unable to load SSL_SESSION\n");
+        BIO_printf(bio_err, "unable to load SSL_SESSION\n");
         ERR_print_errors(bio_err);
         goto end;
     }
diff --git a/apps/skeyutl.c b/apps/skeyutl.c
index 46461781ff..2404a8e8aa 100644
--- a/apps/skeyutl.c
+++ b/apps/skeyutl.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -88,7 +88,7 @@ int skeyutl_main(int argc, char **argv)
         goto opthelp;
 
     if (cipher == NULL && skeymgmt == NULL) {
-        BIO_puts(bio_err, "Either -skeymgmt -or -cipher option should be specified\n");
+        BIO_printf(bio_err, "Either -skeymgmt -or -cipher option should be specified\n");
         goto end;
     }
 
@@ -106,7 +106,7 @@ int skeyutl_main(int argc, char **argv)
         skey = EVP_SKEY_generate(app_get0_libctx(),
             skeymgmt ? skeymgmt : EVP_CIPHER_name(cipher),
             app_get0_propq(), params);
-        app_params_free(params);
+        OSSL_PARAM_free(params);
         if (skey == NULL) {
             BIO_printf(bio_err, "Error creating opaque key for skeymgmt %s\n",
                 skeymgmt ? skeymgmt : EVP_CIPHER_name(cipher));
@@ -114,17 +114,15 @@ int skeyutl_main(int argc, char **argv)
         } else {
             const char *key_name = EVP_SKEY_get0_key_id(skey);
 
-            BIO_printf(bio_out, "An opaque key identified by %s is created\n"
-                                "Provider: %s\n"
-                                "Key management: %s\n",
-                key_name ? key_name : "",
-                EVP_SKEY_get0_provider_name(skey),
-                EVP_SKEY_get0_skeymgmt_name(skey));
+            BIO_printf(bio_out, "An opaque key identified by %s is created\n",
+                key_name ? key_name : "");
+            BIO_printf(bio_out, "Provider: %s\n", EVP_SKEY_get0_provider_name(skey));
+            BIO_printf(bio_out, "Key management: %s\n", EVP_SKEY_get0_skeymgmt_name(skey));
             ret = 0;
         }
         goto end;
     } else {
-        BIO_puts(bio_err, "Key generation is the only supported operation as of now\n");
+        BIO_printf(bio_err, "Key generation is the only supported operation as of now\n");
     }
 
 end:
diff --git a/apps/smime.c b/apps/smime.c
index 7f639ebd5b..458056c04d 100644
--- a/apps/smime.c
+++ b/apps/smime.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -141,9 +141,9 @@ const OPTIONS smime_options[] = {
     { "nosmimecap", OPT_NOSMIMECAP, '-', "Omit the SMIMECapabilities attribute" },
 
     OPT_SECTION("Certificate chain"),
-    { "CAfile", OPT_CAFILE, '<', "File in PEM format with trusted CA certs" },
-    { "CApath", OPT_CAPATH, '/', "Dir with trusted CA cert files in PEM format" },
-    { "CAstore", OPT_CASTORE, ':', "URI of store with trusted CA certs" },
+    { "CApath", OPT_CAPATH, '/', "Trusted certificates directory" },
+    { "CAfile", OPT_CAFILE, '<', "Trusted certificates file" },
+    { "CAstore", OPT_CASTORE, ':', "Trusted certificates store URI" },
     { "no-CAfile", OPT_NOCAFILE, '-',
         "Do not load the default certificates file" },
     { "no-CApath", OPT_NOCAPATH, '-',
@@ -463,26 +463,26 @@ int smime_main(int argc, char **argv)
                 goto end;
         }
         if (sksigners == NULL) {
-            BIO_puts(bio_err, "No signer certificate specified\n");
+            BIO_printf(bio_err, "No signer certificate specified\n");
             goto opthelp;
         }
         signerfile = NULL;
         keyfile = NULL;
     } else if (operation == SMIME_DECRYPT) {
         if (recipfile == NULL && keyfile == NULL) {
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "No recipient certificate or key specified\n");
             goto opthelp;
         }
     } else if (operation == SMIME_ENCRYPT) {
         if (argc == 0) {
-            BIO_puts(bio_err, "No recipient(s) certificate(s) specified\n");
+            BIO_printf(bio_err, "No recipient(s) certificate(s) specified\n");
             goto opthelp;
         }
     }
 
     if (!app_passwd(passinarg, NULL, &passin, NULL)) {
-        BIO_puts(bio_err, "Error getting password\n");
+        BIO_printf(bio_err, "Error getting password\n");
         goto end;
     }
 
@@ -560,7 +560,7 @@ int smime_main(int argc, char **argv)
 
         p7 = PKCS7_new_ex(libctx, app_get0_propq());
         if (p7 == NULL) {
-            BIO_puts(bio_err, "Error allocating PKCS7 object\n");
+            BIO_printf(bio_err, "Error allocating PKCS7 object\n");
             goto end;
         }
         if (informat == FORMAT_SMIME) {
@@ -570,12 +570,12 @@ int smime_main(int argc, char **argv)
         } else if (informat == FORMAT_ASN1) {
             p7_in = d2i_PKCS7_bio(in, &p7);
         } else {
-            BIO_puts(bio_err, "Bad input format for PKCS#7 file\n");
+            BIO_printf(bio_err, "Bad input format for PKCS#7 file\n");
             goto end;
         }
 
         if (p7_in == NULL) {
-            BIO_puts(bio_err, "Error reading S/MIME message\n");
+            BIO_printf(bio_err, "Error reading S/MIME message\n");
             goto end;
         }
         if (contfile != NULL) {
@@ -658,22 +658,22 @@ int smime_main(int argc, char **argv)
     }
 
     if (p7 == NULL) {
-        BIO_puts(bio_err, "Error creating PKCS#7 structure\n");
+        BIO_printf(bio_err, "Error creating PKCS#7 structure\n");
         goto end;
     }
 
     ret = 4;
     if (operation == SMIME_DECRYPT) {
         if (!PKCS7_decrypt(p7, key, recip, out, flags)) {
-            BIO_puts(bio_err, "Error decrypting PKCS#7 structure\n");
+            BIO_printf(bio_err, "Error decrypting PKCS#7 structure\n");
             goto end;
         }
     } else if (operation == SMIME_VERIFY) {
         STACK_OF(X509) *signers;
         if (PKCS7_verify(p7, other, store, indata, out, flags))
-            BIO_puts(bio_err, "Verification successful\n");
+            BIO_printf(bio_err, "Verification successful\n");
         else {
-            BIO_puts(bio_err, "Verification failure\n");
+            BIO_printf(bio_err, "Verification failure\n");
             goto end;
         }
         signers = PKCS7_get0_signers(p7, other, flags);
@@ -702,11 +702,11 @@ int smime_main(int argc, char **argv)
         } else if (outformat == FORMAT_ASN1) {
             rv = i2d_PKCS7_bio_stream(out, p7, in, flags);
         } else {
-            BIO_puts(bio_err, "Bad output format for PKCS#7 file\n");
+            BIO_printf(bio_err, "Bad output format for PKCS#7 file\n");
             goto end;
         }
         if (rv == 0) {
-            BIO_puts(bio_err, "Error writing output\n");
+            BIO_printf(bio_err, "Error writing output\n");
             ret = 3;
             goto end;
         }
diff --git a/apps/speed.c b/apps/speed.c
index b1732744d3..bd1a0da705 100644
--- a/apps/speed.c
+++ b/apps/speed.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
@@ -16,6 +16,8 @@
 #define DSA_SECONDS PKEY_SECONDS
 #define ECDSA_SECONDS PKEY_SECONDS
 #define ECDH_SECONDS PKEY_SECONDS
+#define EdDSA_SECONDS PKEY_SECONDS
+#define SM2_SECONDS PKEY_SECONDS
 #define FFDH_SECONDS PKEY_SECONDS
 #define KEM_SECONDS PKEY_SECONDS
 #define SIG_SECONDS PKEY_SECONDS
@@ -41,7 +43,6 @@
 #include 
 #include 
 #include 
-#include 
 #include 
 #if !defined(OPENSSL_SYS_MSDOS)
 #include 
@@ -106,6 +107,8 @@ typedef struct openssl_speed_sec_st {
     int dsa;
     int ecdsa;
     int ecdh;
+    int eddsa;
+    int sm2;
     int ffdh;
     int kem;
     int sig;
@@ -217,9 +220,6 @@ static int opt_found(const char *name, unsigned int *result,
 {
     unsigned int idx;
 
-    if (*name == '\0')
-        return 0;
-
     for (idx = 0; idx < nbelem; ++idx, pairs++)
         if (strcmp(name, pairs->name) == 0) {
             *result = pairs->retval;
@@ -478,26 +478,10 @@ enum ec_curves_t {
     R_EC_BRP384T1,
     R_EC_BRP512R1,
     R_EC_BRP512T1,
-    ECBASE_NUM,
-#ifndef OPENSSL_NO_ECX
-    R_Ed25519 = ECBASE_NUM,
-    R_Ed448,
-    R_X25519,
-    R_X448,
-    ECX_NUM,
-#else
-    ECX_NUM = ECBASE_NUM,
-#endif
-#ifndef OPENSSL_NO_SM2
-    R_SM2 = ECX_NUM,
-    R_curveSM2,
-    EC_NUM,
-#else
-    EC_NUM = ECX_NUM,
-#endif
+    ECDSA_NUM
 };
 /* list of ecdsa curves */
-static const OPT_PAIR ecdsa_choices[EC_NUM] = {
+static const OPT_PAIR ecdsa_choices[ECDSA_NUM] = {
     { "ecdsap160", R_EC_P160 },
     { "ecdsap192", R_EC_P192 },
     { "ecdsap224", R_EC_P224 },
@@ -521,16 +505,15 @@ static const OPT_PAIR ecdsa_choices[EC_NUM] = {
     { "ecdsabrp384r1", R_EC_BRP384R1 },
     { "ecdsabrp384t1", R_EC_BRP384T1 },
     { "ecdsabrp512r1", R_EC_BRP512R1 },
-    { "ecdsabrp512t1", R_EC_BRP512T1 },
+    { "ecdsabrp512t1", R_EC_BRP512T1 }
+};
+enum {
 #ifndef OPENSSL_NO_ECX
-    { "ed25519", R_Ed25519 },
-    { "ed448", R_Ed448 },
-    { "", -1 },
-    { "", -1 },
-#endif
-#ifndef OPENSSL_NO_SM2
-    { "sm2", R_SM2 },
-    { "", -1 },
+    R_EC_X25519 = ECDSA_NUM,
+    R_EC_X448,
+    EC_NUM
+#else
+    EC_NUM = ECDSA_NUM
 #endif
 };
 /* list of ecdh curves, extension of |ecdsa_choices| list above */
@@ -560,19 +543,36 @@ static const OPT_PAIR ecdh_choices[EC_NUM] = {
     { "ecdhbrp512r1", R_EC_BRP512R1 },
     { "ecdhbrp512t1", R_EC_BRP512T1 },
 #ifndef OPENSSL_NO_ECX
-    { "", -1 },
-    { "", -1 },
-    { "ecdhx25519", R_X25519 },
-    { "ecdhx448", R_X448 },
-#endif
-#ifndef OPENSSL_NO_SM2
-    { "", -1 },
-    { "curveSM2", R_curveSM2 },
+    { "ecdhx25519", R_EC_X25519 },
+    { "ecdhx448", R_EC_X448 }
 #endif
 };
 
 static double ecdh_results[EC_NUM][1]; /* 1 op: derivation */
-static double ecdsa_results[EC_NUM][2]; /* 2 ops: sign then verify */
+static double ecdsa_results[ECDSA_NUM][2]; /* 2 ops: sign then verify */
+
+#ifndef OPENSSL_NO_ECX
+enum { R_EC_Ed25519,
+    R_EC_Ed448,
+    EdDSA_NUM };
+static const OPT_PAIR eddsa_choices[EdDSA_NUM] = {
+    { "ed25519", R_EC_Ed25519 },
+    { "ed448", R_EC_Ed448 }
+
+};
+static double eddsa_results[EdDSA_NUM][2]; /* 2 ops: sign then verify */
+#endif /* OPENSSL_NO_ECX */
+
+#ifndef OPENSSL_NO_SM2
+enum { R_EC_CURVESM2,
+    SM2_NUM };
+static const OPT_PAIR sm2_choices[SM2_NUM] = {
+    { "curveSM2", R_EC_CURVESM2 }
+};
+#define SM2_ID "TLSv1.3+GM+Cipher+Suite"
+#define SM2_ID_LEN sizeof("TLSv1.3+GM+Cipher+Suite") - 1
+static double sm2_results[SM2_NUM][2]; /* 2 ops: sign then verify */
+#endif /* OPENSSL_NO_SM2 */
 
 #define MAX_KEM_NUM 111
 static size_t kems_algs_len = 0;
@@ -615,12 +615,18 @@ typedef struct loopargs_st {
     EVP_PKEY_CTX *dsa_sign_ctx[DSA_NUM];
     EVP_PKEY_CTX *dsa_verify_ctx[DSA_NUM];
 #endif
-    const char *curve_name[EC_NUM];
+    EVP_PKEY_CTX *ecdsa_sign_ctx[ECDSA_NUM];
+    EVP_PKEY_CTX *ecdsa_verify_ctx[ECDSA_NUM];
     EVP_PKEY_CTX *ecdh_ctx[EC_NUM];
-    EVP_PKEY_CTX *pk_sign_ctx[EC_NUM];
-    EVP_PKEY_CTX *pk_verify_ctx[EC_NUM];
-    EVP_MD_CTX *md_sign_ctx[EC_NUM];
-    EVP_MD_CTX *md_verify_ctx[EC_NUM];
+#ifndef OPENSSL_NO_ECX
+    EVP_MD_CTX *eddsa_ctx[EdDSA_NUM];
+    EVP_MD_CTX *eddsa_ctx2[EdDSA_NUM];
+#endif /* OPENSSL_NO_ECX */
+#ifndef OPENSSL_NO_SM2
+    EVP_MD_CTX *sm2_ctx[SM2_NUM];
+    EVP_MD_CTX *sm2_vfy_ctx[SM2_NUM];
+    EVP_PKEY *sm2_pkey[SM2_NUM];
+#endif
     unsigned char *secret_a;
     unsigned char *secret_b;
     size_t outlen[EC_NUM];
@@ -974,7 +980,7 @@ static int EVP_Update_loop(void *args)
         rc = EVP_EncryptFinal_ex(ctx, buf, &outl);
 
     if (rc == 0)
-        BIO_puts(bio_err, "Error finalizing cipher loop\n");
+        BIO_printf(bio_err, "Error finalizing cipher loop\n");
     return count;
 }
 
@@ -999,7 +1005,7 @@ static int EVP_Update_loop_aead_enc(void *args)
         if (mode_op != EVP_CIPH_SIV_MODE) {
             if (!EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_IVLEN,
                     sizeof(aead_iv), NULL)) {
-                BIO_puts(bio_err, "\nFailed to set iv length\n");
+                BIO_printf(bio_err, "\nFailed to set iv length\n");
                 dofail();
                 exit(1);
             }
@@ -1010,13 +1016,13 @@ static int EVP_Update_loop_aead_enc(void *args)
             && mode_op != EVP_CIPH_GCM_SIV_MODE) {
             if (!EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG,
                     TAG_LEN, NULL)) {
-                BIO_puts(bio_err, "\nFailed to set tag length\n");
+                BIO_printf(bio_err, "\nFailed to set tag length\n");
                 dofail();
                 exit(1);
             }
         }
         if (!EVP_CipherInit_ex(ctx, NULL, NULL, key, aead_iv, -1)) {
-            BIO_puts(bio_err, "\nFailed to set key and iv\n");
+            BIO_printf(bio_err, "\nFailed to set key and iv\n");
             dofail();
             exit(1);
         }
@@ -1024,20 +1030,20 @@ static int EVP_Update_loop_aead_enc(void *args)
         if (mode_op == EVP_CIPH_CCM_MODE) {
             if (!EVP_EncryptUpdate(ctx, NULL, &outl,
                     NULL, lengths[testnum])) {
-                BIO_puts(bio_err, "\nCouldn't set input text length\n");
+                BIO_printf(bio_err, "\nCouldn't set input text length\n");
                 dofail();
                 exit(1);
             }
         }
         if (aead) {
             if (!EVP_EncryptUpdate(ctx, NULL, &outl, aad, sizeof(aad))) {
-                BIO_puts(bio_err, "\nCouldn't insert AAD when encrypting\n");
+                BIO_printf(bio_err, "\nCouldn't insert AAD when encrypting\n");
                 dofail();
                 exit(1);
             }
         }
         if (!EVP_EncryptUpdate(ctx, buf, &outl, buf, lengths[testnum])) {
-            BIO_puts(bio_err, "\nFailed to encrypt the data\n");
+            BIO_printf(bio_err, "\nFailed to encrypt the data\n");
             dofail();
             exit(1);
         }
@@ -1071,7 +1077,7 @@ static int EVP_Update_loop_aead_dec(void *args)
         if (mode_op != EVP_CIPH_SIV_MODE) {
             if (!EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_IVLEN,
                     sizeof(aead_iv), NULL)) {
-                BIO_puts(bio_err, "\nFailed to set iv length\n");
+                BIO_printf(bio_err, "\nFailed to set iv length\n");
                 dofail();
                 exit(1);
             }
@@ -1083,20 +1089,20 @@ static int EVP_Update_loop_aead_dec(void *args)
             && mode_op != EVP_CIPH_GCM_SIV_MODE) {
             if (!EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG,
                     TAG_LEN, NULL)) {
-                BIO_puts(bio_err, "\nFailed to set tag length\n");
+                BIO_printf(bio_err, "\nFailed to set tag length\n");
                 dofail();
                 exit(1);
             }
         }
         if (!EVP_CipherInit_ex(ctx, NULL, NULL, key, aead_iv, -1)) {
-            BIO_puts(bio_err, "\nFailed to set key and iv\n");
+            BIO_printf(bio_err, "\nFailed to set key and iv\n");
             dofail();
             exit(1);
         }
         /* Set iv before decryption (Doesn't apply to SIV mode) */
         if (mode_op != EVP_CIPH_SIV_MODE) {
             if (!EVP_DecryptInit_ex(ctx, NULL, NULL, NULL, aead_iv)) {
-                BIO_puts(bio_err, "\nFailed to set iv\n");
+                BIO_printf(bio_err, "\nFailed to set iv\n");
                 dofail();
                 exit(1);
             }
@@ -1105,7 +1111,7 @@ static int EVP_Update_loop_aead_dec(void *args)
 
         if (!EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG,
                 TAG_LEN, tag)) {
-            BIO_puts(bio_err, "\nFailed to set tag\n");
+            BIO_printf(bio_err, "\nFailed to set tag\n");
             dofail();
             exit(1);
         }
@@ -1113,20 +1119,20 @@ static int EVP_Update_loop_aead_dec(void *args)
         if (mode_op == EVP_CIPH_CCM_MODE) {
             if (!EVP_DecryptUpdate(ctx, NULL, &outl,
                     NULL, lengths[testnum])) {
-                BIO_puts(bio_err, "\nCouldn't set cipher text length\n");
+                BIO_printf(bio_err, "\nCouldn't set cipher text length\n");
                 dofail();
                 exit(1);
             }
         }
         if (aead) {
             if (!EVP_DecryptUpdate(ctx, NULL, &outl, aad, sizeof(aad))) {
-                BIO_puts(bio_err, "\nCouldn't insert AAD when decrypting\n");
+                BIO_printf(bio_err, "\nCouldn't insert AAD when decrypting\n");
                 dofail();
                 exit(1);
             }
         }
         if (!EVP_DecryptUpdate(ctx, outbuf, &outl, buf, lengths[testnum])) {
-            BIO_puts(bio_err, "\nFailed to decrypt the data\n");
+            BIO_printf(bio_err, "\nFailed to decrypt the data\n");
             dofail();
             exit(1);
         }
@@ -1149,7 +1155,7 @@ static int RSA_sign_loop(void *args)
         *rsa_num = tempargs->buflen;
         ret = EVP_PKEY_sign(rsa_sign_ctx[testnum], buf2, rsa_num, buf, 36);
         if (ret <= 0) {
-            BIO_puts(bio_err, "RSA sign failure\n");
+            BIO_printf(bio_err, "RSA sign failure\n");
             dofail();
             count = -1;
             break;
@@ -1170,7 +1176,7 @@ static int RSA_verify_loop(void *args)
     for (count = 0; COND(rsa_c[testnum][1]); count++) {
         ret = EVP_PKEY_verify(rsa_verify_ctx[testnum], buf2, rsa_num, buf, 36);
         if (ret <= 0) {
-            BIO_puts(bio_err, "RSA verify failure\n");
+            BIO_printf(bio_err, "RSA verify failure\n");
             dofail();
             count = -1;
             break;
@@ -1192,7 +1198,7 @@ static int RSA_encrypt_loop(void *args)
         *rsa_num = tempargs->buflen;
         ret = EVP_PKEY_encrypt(rsa_encrypt_ctx[testnum], buf2, rsa_num, buf, 36);
         if (ret <= 0) {
-            BIO_puts(bio_err, "RSA encrypt failure\n");
+            BIO_printf(bio_err, "RSA encrypt failure\n");
             dofail();
             count = -1;
             break;
@@ -1214,7 +1220,7 @@ static int RSA_decrypt_loop(void *args)
         rsa_num = tempargs->buflen;
         ret = EVP_PKEY_decrypt(rsa_decrypt_ctx[testnum], buf, &rsa_num, buf2, tempargs->encsize);
         if (ret <= 0) {
-            BIO_puts(bio_err, "RSA decrypt failure\n");
+            BIO_printf(bio_err, "RSA decrypt failure\n");
             dofail();
             count = -1;
             break;
@@ -1256,7 +1262,7 @@ static int DSA_sign_loop(void *args)
         *dsa_num = tempargs->buflen;
         ret = EVP_PKEY_sign(dsa_sign_ctx[testnum], buf2, dsa_num, buf, 20);
         if (ret <= 0) {
-            BIO_puts(bio_err, "DSA sign failure\n");
+            BIO_printf(bio_err, "DSA sign failure\n");
             dofail();
             count = -1;
             break;
@@ -1277,7 +1283,7 @@ static int DSA_verify_loop(void *args)
     for (count = 0; COND(dsa_c[testnum][1]); count++) {
         ret = EVP_PKEY_verify(dsa_verify_ctx[testnum], buf2, dsa_num, buf, 20);
         if (ret <= 0) {
-            BIO_puts(bio_err, "DSA verify failure\n");
+            BIO_printf(bio_err, "DSA verify failure\n");
             dofail();
             count = -1;
             break;
@@ -1292,21 +1298,15 @@ static int ECDSA_sign_loop(void *args)
     loopargs_t *tempargs = *(loopargs_t **)args;
     unsigned char *buf = tempargs->buf;
     unsigned char *buf2 = tempargs->buf2;
-    size_t *sigsize = &tempargs->sigsize;
-    EVP_PKEY_CTX *pctx = tempargs->pk_sign_ctx[testnum];
-    EVP_MD_CTX *mctx = tempargs->md_sign_ctx[testnum];
-    const char *curve_name = tempargs->curve_name[testnum];
+    size_t *ecdsa_num = &tempargs->sigsize;
+    EVP_PKEY_CTX **ecdsa_sign_ctx = tempargs->ecdsa_sign_ctx;
     int ret, count;
 
     for (count = 0; COND(ecdsa_c[testnum][0]); count++) {
-        *sigsize = tempargs->buflen;
-        if (pctx != NULL)
-            ret = EVP_PKEY_sign(pctx, buf2, sigsize, buf, 20);
-        else
-            ret = EVP_DigestSignInit_ex(mctx, NULL, NULL, NULL, NULL, NULL, NULL)
-                && EVP_DigestSign(mctx, buf2, sigsize, buf, 20);
+        *ecdsa_num = tempargs->buflen;
+        ret = EVP_PKEY_sign(ecdsa_sign_ctx[testnum], buf2, ecdsa_num, buf, 20);
         if (ret <= 0) {
-            BIO_printf(bio_err, "%s sign failure\n", curve_name);
+            BIO_printf(bio_err, "ECDSA sign failure\n");
             dofail();
             count = -1;
             break;
@@ -1320,20 +1320,15 @@ static int ECDSA_verify_loop(void *args)
     loopargs_t *tempargs = *(loopargs_t **)args;
     unsigned char *buf = tempargs->buf;
     unsigned char *buf2 = tempargs->buf2;
-    size_t sigsize = tempargs->sigsize;
-    EVP_PKEY_CTX *pctx = tempargs->pk_verify_ctx[testnum];
-    EVP_MD_CTX *mctx = tempargs->md_verify_ctx[testnum];
-    const char *curve_name = tempargs->curve_name[testnum];
+    size_t ecdsa_num = tempargs->sigsize;
+    EVP_PKEY_CTX **ecdsa_verify_ctx = tempargs->ecdsa_verify_ctx;
     int ret, count;
 
     for (count = 0; COND(ecdsa_c[testnum][1]); count++) {
-        if (pctx != NULL)
-            ret = EVP_PKEY_verify(pctx, buf2, sigsize, buf, 20);
-        else
-            ret = EVP_DigestVerifyInit_ex(mctx, NULL, NULL, NULL, NULL, NULL, NULL)
-                && EVP_DigestVerify(mctx, buf2, sigsize, buf, 20);
+        ret = EVP_PKEY_verify(ecdsa_verify_ctx[testnum], buf2, ecdsa_num,
+            buf, 20);
         if (ret <= 0) {
-            BIO_printf(bio_err, "%s verify failure\n", curve_name);
+            BIO_printf(bio_err, "ECDSA verify failure\n");
             dofail();
             count = -1;
             break;
@@ -1358,6 +1353,132 @@ static int ECDH_EVP_derive_key_loop(void *args)
     return count;
 }
 
+#ifndef OPENSSL_NO_ECX
+static int EdDSA_sign_loop(void *args)
+{
+    loopargs_t *tempargs = *(loopargs_t **)args;
+    unsigned char *buf = tempargs->buf;
+    EVP_MD_CTX **edctx = tempargs->eddsa_ctx;
+    unsigned char *eddsasig = tempargs->buf2;
+    size_t *eddsasigsize = &tempargs->sigsize;
+    int ret, count;
+
+    for (count = 0; COND(eddsa_c[testnum][0]); count++) {
+        ret = EVP_DigestSignInit(edctx[testnum], NULL, NULL, NULL, NULL);
+        if (ret == 0) {
+            BIO_printf(bio_err, "EdDSA sign init failure\n");
+            dofail();
+            count = -1;
+            break;
+        }
+        ret = EVP_DigestSign(edctx[testnum], eddsasig, eddsasigsize, buf, 20);
+        if (ret == 0) {
+            BIO_printf(bio_err, "EdDSA sign failure\n");
+            dofail();
+            count = -1;
+            break;
+        }
+    }
+    return count;
+}
+
+static int EdDSA_verify_loop(void *args)
+{
+    loopargs_t *tempargs = *(loopargs_t **)args;
+    unsigned char *buf = tempargs->buf;
+    EVP_MD_CTX **edctx = tempargs->eddsa_ctx2;
+    unsigned char *eddsasig = tempargs->buf2;
+    size_t eddsasigsize = tempargs->sigsize;
+    int ret, count;
+
+    for (count = 0; COND(eddsa_c[testnum][1]); count++) {
+        ret = EVP_DigestVerifyInit(edctx[testnum], NULL, NULL, NULL, NULL);
+        if (ret == 0) {
+            BIO_printf(bio_err, "EdDSA verify init failure\n");
+            dofail();
+            count = -1;
+            break;
+        }
+        ret = EVP_DigestVerify(edctx[testnum], eddsasig, eddsasigsize, buf, 20);
+        if (ret != 1) {
+            BIO_printf(bio_err, "EdDSA verify failure\n");
+            dofail();
+            count = -1;
+            break;
+        }
+    }
+    return count;
+}
+#endif /* OPENSSL_NO_ECX */
+
+#ifndef OPENSSL_NO_SM2
+static int SM2_sign_loop(void *args)
+{
+    loopargs_t *tempargs = *(loopargs_t **)args;
+    unsigned char *buf = tempargs->buf;
+    EVP_MD_CTX **sm2ctx = tempargs->sm2_ctx;
+    unsigned char *sm2sig = tempargs->buf2;
+    size_t sm2sigsize;
+    int ret, count;
+    EVP_PKEY **sm2_pkey = tempargs->sm2_pkey;
+    const size_t max_size = EVP_PKEY_get_size(sm2_pkey[testnum]);
+
+    for (count = 0; COND(sm2_c[testnum][0]); count++) {
+        sm2sigsize = max_size;
+
+        if (!EVP_DigestSignInit(sm2ctx[testnum], NULL, EVP_sm3(),
+                NULL, sm2_pkey[testnum])) {
+            BIO_printf(bio_err, "SM2 init sign failure\n");
+            dofail();
+            count = -1;
+            break;
+        }
+        ret = EVP_DigestSign(sm2ctx[testnum], sm2sig, &sm2sigsize,
+            buf, 20);
+        if (ret == 0) {
+            BIO_printf(bio_err, "SM2 sign failure\n");
+            dofail();
+            count = -1;
+            break;
+        }
+        /* update the latest returned size and always use the fixed buffer size */
+        tempargs->sigsize = sm2sigsize;
+    }
+
+    return count;
+}
+
+static int SM2_verify_loop(void *args)
+{
+    loopargs_t *tempargs = *(loopargs_t **)args;
+    unsigned char *buf = tempargs->buf;
+    EVP_MD_CTX **sm2ctx = tempargs->sm2_vfy_ctx;
+    unsigned char *sm2sig = tempargs->buf2;
+    size_t sm2sigsize = tempargs->sigsize;
+    int ret, count;
+    EVP_PKEY **sm2_pkey = tempargs->sm2_pkey;
+
+    for (count = 0; COND(sm2_c[testnum][1]); count++) {
+        if (!EVP_DigestVerifyInit(sm2ctx[testnum], NULL, EVP_sm3(),
+                NULL, sm2_pkey[testnum])) {
+            BIO_printf(bio_err, "SM2 verify init failure\n");
+            dofail();
+            count = -1;
+            break;
+        }
+        ret = EVP_DigestVerify(sm2ctx[testnum], sm2sig, sm2sigsize,
+            buf, 20);
+        if (ret != 1) {
+            BIO_printf(bio_err, "SM2 verify failure\n");
+            dofail();
+            count = -1;
+            break;
+        }
+    }
+    return count;
+}
+#endif /* OPENSSL_NO_SM2 */
+
 static int KEM_keygen_loop(void *args)
 {
     loopargs_t *tempargs = *(loopargs_t **)args;
@@ -1486,7 +1607,7 @@ static int check_block_size(EVP_CIPHER_CTX *ctx, int length)
     int blocksize = EVP_CIPHER_CTX_get_block_size(ctx);
 
     if (ciph == NULL || blocksize <= 0) {
-        BIO_puts(bio_err, "\nInvalid cipher!\n");
+        BIO_printf(bio_err, "\nInvalid cipher!\n");
         return 0;
     }
     if (length % blocksize != 0) {
@@ -1532,7 +1653,7 @@ static int run_benchmark(int async_jobs,
             break;
         case ASYNC_NO_JOBS:
         case ASYNC_ERR:
-            BIO_puts(bio_err, "Failure in the job\n");
+            BIO_printf(bio_err, "Failure in the job\n");
             dofail();
             error = 1;
             break;
@@ -1555,7 +1676,7 @@ static int run_benchmark(int async_jobs,
 
             if (!ASYNC_WAIT_CTX_get_all_fds(loopargs[i].wait_ctx, NULL, &num_job_fds)
                 || num_job_fds > 1) {
-                BIO_puts(bio_err, "Too many fds in ASYNC_WAIT_CTX\n");
+                BIO_printf(bio_err, "Too many fds in ASYNC_WAIT_CTX\n");
                 dofail();
                 error = 1;
                 break;
@@ -1582,7 +1703,7 @@ static int run_benchmark(int async_jobs,
             continue;
 
         if (select_result == -1) {
-            BIO_puts(bio_err, "Failure in the select\n");
+            BIO_printf(bio_err, "Failure in the select\n");
             dofail();
             error = 1;
             break;
@@ -1598,7 +1719,7 @@ static int run_benchmark(int async_jobs,
 
             if (!ASYNC_WAIT_CTX_get_all_fds(loopargs[i].wait_ctx, NULL, &num_job_fds)
                 || num_job_fds > 1) {
-                BIO_puts(bio_err, "Too many fds in ASYNC_WAIT_CTX\n");
+                BIO_printf(bio_err, "Too many fds in ASYNC_WAIT_CTX\n");
                 dofail();
                 error = 1;
                 break;
@@ -1636,7 +1757,7 @@ static int run_benchmark(int async_jobs,
             case ASYNC_ERR:
                 --num_inprogress;
                 loopargs[i].inprogress_job = NULL;
-                BIO_puts(bio_err, "Failure in the job\n");
+                BIO_printf(bio_err, "Failure in the job\n");
                 dofail();
                 error = 1;
                 break;
@@ -1648,33 +1769,79 @@ static int run_benchmark(int async_jobs,
 }
 
 typedef struct ec_curve_st {
-    const char *algor;
-    char *group_name;
-    size_t group_name_size;
-    int mdsig;
+    const char *name;
+    unsigned int nid;
     unsigned int bits;
+    size_t sigsize; /* only used for EdDSA curves */
 } EC_CURVE;
 
-#define EC_CURVE_NAME(c) ((c).group_name ? (c).group_name : (c).algor)
-
 static EVP_PKEY *get_ecdsa(const EC_CURVE *curve)
 {
     EVP_PKEY_CTX *kctx = NULL;
     EVP_PKEY *key = NULL;
-    OSSL_PARAM param[] = {
-        OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_GROUP_NAME, NULL, 0),
-        OSSL_PARAM_END,
-    };
 
-    param[0].data = curve->group_name;
-    param[0].data_size = curve->group_name_size;
+    /* Ensure that the error queue is empty */
+    if (ERR_peek_error()) {
+        BIO_printf(bio_err,
+            "WARNING: the error queue contains previous unhandled errors.\n");
+        dofail();
+    }
 
-    /* Create the context for parameter generation */
-    if ((kctx = EVP_PKEY_CTX_new_from_name(NULL, curve->algor, NULL)) == NULL
+    /*
+     * Let's try to create a ctx directly from the NID: this works for
+     * curves like Curve25519 that are not implemented through the low
+     * level EC interface.
+     * If this fails we try creating a EVP_PKEY_EC generic param ctx,
+     * then we set the curve by NID before deriving the actual keygen
+     * ctx for that specific curve.
+     */
+    kctx = EVP_PKEY_CTX_new_id(curve->nid, NULL);
+    if (kctx == NULL) {
+        EVP_PKEY_CTX *pctx = NULL;
+        EVP_PKEY *params = NULL;
+        /*
+         * If we reach this code EVP_PKEY_CTX_new_id() failed and a
+         * "int_ctx_new:unsupported algorithm" error was added to the
+         * error queue.
+         * We remove it from the error queue as we are handling it.
+         */
+        unsigned long error = ERR_peek_error();
+
+        if (error == ERR_peek_last_error() /* oldest and latest errors match */
+            /* check that the error origin matches */
+            && ERR_GET_LIB(error) == ERR_LIB_EVP
+            && (ERR_GET_REASON(error) == EVP_R_UNSUPPORTED_ALGORITHM
+                || ERR_GET_REASON(error) == ERR_R_UNSUPPORTED))
+            ERR_get_error(); /* pop error from queue */
+        if (ERR_peek_error()) {
+            BIO_printf(bio_err,
+                "Unhandled error in the error queue during EC key setup.\n");
+            dofail();
+            return NULL;
+        }
+
+        /* Create the context for parameter generation */
+        if ((pctx = EVP_PKEY_CTX_new_from_name(NULL, "EC", NULL)) == NULL
+            || EVP_PKEY_paramgen_init(pctx) <= 0
+            || EVP_PKEY_CTX_set_ec_paramgen_curve_nid(pctx,
+                   curve->nid)
+                <= 0
+            || EVP_PKEY_paramgen(pctx, ¶ms) <= 0) {
+            BIO_printf(bio_err, "EC params init failure.\n");
+            dofail();
+            EVP_PKEY_CTX_free(pctx);
+            return NULL;
+        }
+        EVP_PKEY_CTX_free(pctx);
+
+        /* Create the context for the key generation */
+        kctx = EVP_PKEY_CTX_new(params, NULL);
+        EVP_PKEY_free(params);
+    }
+    if (kctx == NULL
         || EVP_PKEY_keygen_init(kctx) <= 0
-        || (param[0].data_size > 0 && !EVP_PKEY_CTX_set_params(kctx, param))
         || EVP_PKEY_keygen(kctx, &key) <= 0) {
-        BIO_printf(bio_err, "%s key generation failure.\n", curve->group_name);
+        BIO_printf(bio_err, "EC key generation failure.\n");
         dofail();
         key = NULL;
     }
@@ -1728,8 +1895,6 @@ static void collect_kem(EVP_KEM *kem, void *stack)
 static int kem_locate(const char *algo, unsigned int *idx)
 {
     unsigned int i;
-    EVP_KEM *kem;
-    const char *canonical_name;
 
     for (i = 0; i < kems_algs_len; i++) {
         if (strcmp(kems_algname[i], algo) == 0) {
@@ -1737,20 +1902,6 @@ static int kem_locate(const char *algo, unsigned int *idx)
             return 1;
         }
     }
-    ERR_set_mark();
-    kem = EVP_KEM_fetch(app_get0_libctx(), algo, app_get0_propq());
-    ERR_pop_to_mark();
-    if (kem != NULL) {
-        canonical_name = EVP_KEM_get0_name(kem);
-        for (i = 0; i < kems_algs_len; i++) {
-            if (strcmp(kems_algname[i], canonical_name) == 0) {
-                *idx = i;
-                EVP_KEM_free(kem);
-                return 1;
-            }
-        }
-        EVP_KEM_free(kem);
-    }
     return 0;
 }
 
@@ -1776,8 +1927,6 @@ static void collect_signatures(EVP_SIGNATURE *sig, void *stack)
 static int sig_locate(const char *algo, unsigned int *idx)
 {
     unsigned int i;
-    EVP_SIGNATURE *sig;
-    const char *canonical_name;
 
     for (i = 0; i < sigs_algs_len; i++) {
         if (strcmp(sigs_algname[i], algo) == 0) {
@@ -1785,20 +1934,6 @@ static int sig_locate(const char *algo, unsigned int *idx)
             return 1;
         }
     }
-    ERR_set_mark();
-    sig = EVP_SIGNATURE_fetch(app_get0_libctx(), algo, app_get0_propq());
-    ERR_pop_to_mark();
-    if (sig != NULL) {
-        canonical_name = EVP_SIGNATURE_get0_name(sig);
-        for (i = 0; i < sigs_algs_len; i++) {
-            if (strcmp(sigs_algname[i], canonical_name) == 0) {
-                *idx = i;
-                EVP_SIGNATURE_free(sig);
-                return 1;
-            }
-        }
-        EVP_SIGNATURE_free(sig);
-    }
     return 0;
 }
 
@@ -1840,16 +1975,11 @@ int speed_main(int argc, char **argv)
     int multi = 0;
 #endif
     long op_count = 1;
-    openssl_speed_sec_t seconds = {
-        SECONDS,
-        RSA_SECONDS,
-        DSA_SECONDS,
-        ECDSA_SECONDS,
-        ECDH_SECONDS,
-        FFDH_SECONDS,
-        KEM_SECONDS,
-        SIG_SECONDS,
-    };
+    openssl_speed_sec_t seconds = { SECONDS, RSA_SECONDS, DSA_SECONDS,
+        ECDSA_SECONDS, ECDH_SECONDS,
+        EdDSA_SECONDS, SM2_SECONDS,
+        FFDH_SECONDS, KEM_SECONDS,
+        SIG_SECONDS };
 
     static const unsigned char key32[32] = {
         0x12, 0x34, 0x56, 0x78, 0x9a, 0xbc, 0xde, 0xf0,
@@ -1904,47 +2034,58 @@ int speed_main(int argc, char **argv)
      * the following arrays and increase the |ecdh_choices| and |ecdsa_choices|
      * lists accordingly.
      */
-#define STRSZ(lit) (lit), (sizeof(lit))
     static const EC_CURVE ec_curves[EC_NUM] = {
         /* Prime Curves */
-        { "EC", STRSZ("secp160r1"), 0, 160 },
-        { "EC", STRSZ("prime192v1"), 0, 192 },
-        { "EC", STRSZ("secp224r1"), 0, 224 },
-        { "EC", STRSZ("prime256v1"), 0, 256 },
-        { "EC", STRSZ("secp384r1"), 0, 384 },
-        { "EC", STRSZ("secp521r1"), 0, 521 },
+        { "secp160r1", NID_secp160r1, 160 },
+        { "nistp192", NID_X9_62_prime192v1, 192 },
+        { "nistp224", NID_secp224r1, 224 },
+        { "nistp256", NID_X9_62_prime256v1, 256 },
+        { "nistp384", NID_secp384r1, 384 },
+        { "nistp521", NID_secp521r1, 521 },
 #ifndef OPENSSL_NO_EC2M
         /* Binary Curves */
-        { "EC", STRSZ("sect163k1"), 0, 163 },
-        { "EC", STRSZ("sect233k1"), 0, 233 },
-        { "EC", STRSZ("sect283k1"), 0, 283 },
-        { "EC", STRSZ("sect409k1"), 0, 409 },
-        { "EC", STRSZ("sect571k1"), 0, 571 },
-        { "EC", STRSZ("sect163r2"), 0, 163 },
-        { "EC", STRSZ("sect233r1"), 0, 233 },
-        { "EC", STRSZ("sect283r1"), 0, 283 },
-        { "EC", STRSZ("sect409r1"), 0, 409 },
-        { "EC", STRSZ("sect571r1"), 0, 571 },
+        { "nistk163", NID_sect163k1, 163 },
+        { "nistk233", NID_sect233k1, 233 },
+        { "nistk283", NID_sect283k1, 283 },
+        { "nistk409", NID_sect409k1, 409 },
+        { "nistk571", NID_sect571k1, 571 },
+        { "nistb163", NID_sect163r2, 163 },
+        { "nistb233", NID_sect233r1, 233 },
+        { "nistb283", NID_sect283r1, 283 },
+        { "nistb409", NID_sect409r1, 409 },
+        { "nistb571", NID_sect571r1, 571 },
 #endif
-        { "EC", STRSZ("brainpoolP256r1"), 0, 256 },
-        { "EC", STRSZ("brainpoolP256t1"), 0, 256 },
-        { "EC", STRSZ("brainpoolP384r1"), 0, 384 },
-        { "EC", STRSZ("brainpoolP384t1"), 0, 384 },
-        { "EC", STRSZ("brainpoolP512r1"), 0, 512 },
-        { "EC", STRSZ("brainpoolP512t1"), 0, 512 },
+        { "brainpoolP256r1", NID_brainpoolP256r1, 256 },
+        { "brainpoolP256t1", NID_brainpoolP256t1, 256 },
+        { "brainpoolP384r1", NID_brainpoolP384r1, 384 },
+        { "brainpoolP384t1", NID_brainpoolP384t1, 384 },
+        { "brainpoolP512r1", NID_brainpoolP512r1, 512 },
+        { "brainpoolP512t1", NID_brainpoolP512t1, 512 },
 #ifndef OPENSSL_NO_ECX
-        { "Ed25519", NULL, 0, 1, 253 },
-        { "Ed448", NULL, 0, 1, 456 },
-        { "X25519", NULL, 0, -1, 253 },
-        { "X448", NULL, 0, -1, 448 },
-#endif
-#ifndef OPENSSL_NO_SM2
-        { "SM2", STRSZ("SM2"), 1, 256 },
-        { "curveSM2", STRSZ("SM2"), -1, 256 },
+        /* Other and ECDH only ones */
+        { "X25519", NID_X25519, 253 },
+        { "X448", NID_X448, 448 }
 #endif
     };
-    uint8_t ecdsa_doit[EC_NUM] = { 0 };
+#ifndef OPENSSL_NO_ECX
+    static const EC_CURVE ed_curves[EdDSA_NUM] = {
+        /* EdDSA */
+        { "Ed25519", NID_ED25519, 253, 64 },
+        { "Ed448", NID_ED448, 456, 114 }
+    };
+#endif /* OPENSSL_NO_ECX */
+#ifndef OPENSSL_NO_SM2
+    static const EC_CURVE sm2_curves[SM2_NUM] = {
+        /* SM2 */
+        { "CurveSM2", NID_sm2, 256 }
+    };
+    uint8_t sm2_doit[SM2_NUM] = { 0 };
+#endif
+    uint8_t ecdsa_doit[ECDSA_NUM] = { 0 };
     uint8_t ecdh_doit[EC_NUM] = { 0 };
+#ifndef OPENSSL_NO_ECX
+    uint8_t eddsa_doit[EdDSA_NUM] = { 0 };
+#endif /* OPENSSL_NO_ECX */
 
     uint8_t kems_doit[MAX_KEM_NUM] = { 0 };
     uint8_t sigs_doit[MAX_SIG_NUM] = { 0 };
@@ -1952,6 +2093,23 @@ int speed_main(int argc, char **argv)
     uint8_t do_kems = 0;
     uint8_t do_sigs = 0;
 
+    /* checks declared curves against choices list. */
+#ifndef OPENSSL_NO_ECX
+    OPENSSL_assert(ed_curves[EdDSA_NUM - 1].nid == NID_ED448);
+    OPENSSL_assert(strcmp(eddsa_choices[EdDSA_NUM - 1].name, "ed448") == 0);
+
+    OPENSSL_assert(ec_curves[EC_NUM - 1].nid == NID_X448);
+    OPENSSL_assert(strcmp(ecdh_choices[EC_NUM - 1].name, "ecdhx448") == 0);
+
+    OPENSSL_assert(ec_curves[ECDSA_NUM - 1].nid == NID_brainpoolP512t1);
+    OPENSSL_assert(strcmp(ecdsa_choices[ECDSA_NUM - 1].name, "ecdsabrp512t1") == 0);
+#endif /* OPENSSL_NO_ECX */
+
+#ifndef OPENSSL_NO_SM2
+    OPENSSL_assert(sm2_curves[SM2_NUM - 1].nid == NID_sm2);
+    OPENSSL_assert(strcmp(sm2_choices[SM2_NUM - 1].name, "curveSM2") == 0);
+#endif
+
     prog = opt_init(argc, argv, speed_options);
     while ((o = opt_next()) != OPT_EOF) {
         switch (o) {
@@ -2073,8 +2231,9 @@ int speed_main(int argc, char **argv)
             break;
         case OPT_SECONDS:
             seconds.sym = seconds.rsa = seconds.dsa = seconds.ecdsa
-                = seconds.ecdh = seconds.ffdh = seconds.kem
-                = seconds.sig = opt_int_arg();
+                = seconds.ecdh = seconds.eddsa
+                = seconds.sm2 = seconds.ffdh
+                = seconds.kem = seconds.sig = opt_int_arg();
             break;
         case OPT_BYTES:
             lengths_single = opt_int_arg();
@@ -2116,7 +2275,7 @@ int speed_main(int argc, char **argv)
 
         if (strcmp(EVP_KEM_get0_name(kem), "RSA") == 0) {
             if (kems_algs_len + OSSL_NELEM(rsa_choices) >= MAX_KEM_NUM) {
-                BIO_puts(bio_err,
+                BIO_printf(bio_err,
                     "Too many KEMs registered. Change MAX_KEM_NUM.\n");
                 goto end;
             }
@@ -2126,7 +2285,7 @@ int speed_main(int argc, char **argv)
             }
         } else if (strcmp(EVP_KEM_get0_name(kem), "EC") == 0) {
             if (kems_algs_len + 3 >= MAX_KEM_NUM) {
-                BIO_puts(bio_err,
+                BIO_printf(bio_err,
                     "Too many KEMs registered. Change MAX_KEM_NUM.\n");
                 goto end;
             }
@@ -2138,7 +2297,7 @@ int speed_main(int argc, char **argv)
             kems_algname[kems_algs_len++] = OPENSSL_strdup("ECP-521");
         } else {
             if (kems_algs_len + 1 >= MAX_KEM_NUM) {
-                BIO_puts(bio_err,
+                BIO_printf(bio_err,
                     "Too many KEMs registered. Change MAX_KEM_NUM.\n");
                 goto end;
             }
@@ -2161,7 +2320,7 @@ int speed_main(int argc, char **argv)
 
         if (strcmp(sig_name, "RSA") == 0) {
             if (sigs_algs_len + OSSL_NELEM(rsa_choices) >= MAX_SIG_NUM) {
-                BIO_puts(bio_err,
+                BIO_printf(bio_err,
                     "Too many signatures registered. Change MAX_SIG_NUM.\n");
                 goto end;
             }
@@ -2173,7 +2332,7 @@ int speed_main(int argc, char **argv)
 #ifndef OPENSSL_NO_DSA
         else if (strcmp(sig_name, "DSA") == 0) {
             if (sigs_algs_len + DSA_NUM >= MAX_SIG_NUM) {
-                BIO_puts(bio_err,
+                BIO_printf(bio_err,
                     "Too many signatures registered. Change MAX_SIG_NUM.\n");
                 goto end;
             }
@@ -2184,18 +2343,9 @@ int speed_main(int argc, char **argv)
         }
 #endif /* OPENSSL_NO_DSA */
         /* skipping these algs as tested elsewhere - and b/o setup is a pain */
-        else if (strncmp(sig_name, "RSA", 3)
-            && strncmp(sig_name, "DSA", 3)
-            && strncmp(sig_name, "ED25519", 7)
-            && strncmp(sig_name, "ED448", 5)
-            && strncmp(sig_name, "ECDSA", 5)
-            && strcmp(sig_name, "HMAC")
-            && strcmp(sig_name, "SIPHASH")
-            && strcmp(sig_name, "POLY1305")
-            && strcmp(sig_name, "CMAC")
-            && strcmp(sig_name, "SM2")) { /* skip alg */
+        else if (strncmp(sig_name, "RSA", 3) && strncmp(sig_name, "DSA", 3) && strncmp(sig_name, "ED25519", 7) && strncmp(sig_name, "ED448", 5) && strncmp(sig_name, "ECDSA", 5) && strcmp(sig_name, "HMAC") && strcmp(sig_name, "SIPHASH") && strcmp(sig_name, "POLY1305") && strcmp(sig_name, "CMAC") && strcmp(sig_name, "SM2")) { /* skip alg */
             if (sigs_algs_len + 1 >= MAX_SIG_NUM) {
-                BIO_puts(bio_err,
+                BIO_printf(bio_err,
                     "Too many signatures registered. Change MAX_SIG_NUM.\n");
                 goto end;
             }
@@ -2276,37 +2426,46 @@ int speed_main(int argc, char **argv)
             doit[D_CBC_128_CML] = doit[D_CBC_192_CML] = doit[D_CBC_256_CML] = 1;
             algo_found = 1;
         }
-        if (strcmp(algo, "ecdsa") == 0) {
-            memset(ecdsa_doit, 1, sizeof(ecdsa_doit));
-            algo_found = 1;
+        if (HAS_PREFIX(algo, "ecdsa")) {
+            if (algo[sizeof("ecdsa") - 1] == '\0') {
+                memset(ecdsa_doit, 1, sizeof(ecdsa_doit));
+                algo_found = 1;
+            }
+            if (opt_found(algo, ecdsa_choices, &i)) {
+                ecdsa_doit[i] = 2;
+                algo_found = 1;
+            }
         }
-        if (strcmp(algo, "ecdh") == 0) {
-            memset(ecdh_doit, 1, sizeof(ecdh_doit));
-            algo_found = 1;
-        }
-        for (i = 0; i < EC_NUM; i++) {
-            /* Negative values are ECDH-only curves */
-            if (ec_curves[i].mdsig < 0)
-                ecdsa_doit[i] = 0;
-            /* Positive values are signature-only curves */
-            if (ec_curves[i].mdsig > 0)
-                ecdh_doit[i] = 0;
-        }
-        if (opt_found(algo, ecdsa_choices, &i)) {
-            ecdsa_doit[i] = 2;
-            algo_found = 1;
+        if (HAS_PREFIX(algo, "ecdh")) {
+            if (algo[sizeof("ecdh") - 1] == '\0') {
+                memset(ecdh_doit, 1, sizeof(ecdh_doit));
+                algo_found = 1;
+            }
+            if (opt_found(algo, ecdh_choices, &i)) {
+                ecdh_doit[i] = 2;
+                algo_found = 1;
+            }
         }
 #ifndef OPENSSL_NO_ECX
         if (strcmp(algo, "eddsa") == 0) {
+            memset(eddsa_doit, 1, sizeof(eddsa_doit));
+            algo_found = 1;
+        }
+        if (opt_found(algo, eddsa_choices, &i)) {
+            eddsa_doit[i] = 2;
             algo_found = 1;
-            ecdsa_doit[R_Ed25519] = 2;
-            ecdsa_doit[R_Ed448] = 2;
         }
 #endif /* OPENSSL_NO_ECX */
-        if (opt_found(algo, ecdh_choices, &i)) {
-            ecdh_doit[i] = 2;
+#ifndef OPENSSL_NO_SM2
+        if (strcmp(algo, "sm2") == 0) {
+            memset(sm2_doit, 1, sizeof(sm2_doit));
             algo_found = 1;
         }
+        if (opt_found(algo, sm2_choices, &i)) {
+            sm2_doit[i] = 2;
+            algo_found = 1;
+        }
+#endif
         if (kem_locate(algo, &idx)) {
             kems_doit[idx]++;
             do_kems = 1;
@@ -2335,7 +2494,7 @@ int speed_main(int argc, char **argv)
     /* Sanity checks */
     if (aead) {
         if (evp_cipher == NULL) {
-            BIO_puts(bio_err, "-aead can be used only with an AEAD cipher\n");
+            BIO_printf(bio_err, "-aead can be used only with an AEAD cipher\n");
             goto end;
         } else if (!(EVP_CIPHER_get_flags(evp_cipher) & EVP_CIPH_FLAG_AEAD_CIPHER)) {
             BIO_printf(bio_err, "%s is not an AEAD cipher\n",
@@ -2367,15 +2526,15 @@ int speed_main(int argc, char **argv)
     }
     if (multiblock) {
         if (evp_cipher == NULL) {
-            BIO_puts(bio_err, "-mb can be used only with a multi-block"
-                              " capable cipher\n");
+            BIO_printf(bio_err, "-mb can be used only with a multi-block"
+                                " capable cipher\n");
             goto end;
         } else if (!(EVP_CIPHER_get_flags(evp_cipher) & EVP_CIPH_FLAG_TLS1_1_MULTIBLOCK)) {
             BIO_printf(bio_err, "%s is not a multi-block capable\n",
                 EVP_CIPHER_get0_name(evp_cipher));
             goto end;
         } else if (async_jobs > 0) {
-            BIO_puts(bio_err, "Async mode is not supported with -mb");
+            BIO_printf(bio_err, "Async mode is not supported with -mb");
             goto end;
         }
     }
@@ -2384,7 +2543,7 @@ int speed_main(int argc, char **argv)
     if (async_jobs > 0) {
         async_init = ASYNC_init_thread(async_jobs, async_jobs);
         if (!async_init) {
-            BIO_puts(bio_err, "Error creating the ASYNC job pool\n");
+            BIO_printf(bio_err, "Error creating the ASYNC job pool\n");
             goto end;
         }
     }
@@ -2397,7 +2556,7 @@ int speed_main(int argc, char **argv)
     if (buflen < 36) /* size of random vector in RSA benchmark */
         buflen = 36;
     if (INT_MAX - (MAX_MISALIGNMENT + 1) < buflen) {
-        BIO_puts(bio_err, "Error: buffer size too large\n");
+        BIO_printf(bio_err, "Error: buffer size too large\n");
         goto end;
     }
     buflen += MAX_MISALIGNMENT + 1;
@@ -2405,7 +2564,7 @@ int speed_main(int argc, char **argv)
         if (async_jobs > 0) {
             loopargs[i].wait_ctx = ASYNC_WAIT_CTX_new();
             if (loopargs[i].wait_ctx == NULL) {
-                BIO_puts(bio_err, "Error creating the ASYNC_WAIT_CTX\n");
+                BIO_printf(bio_err, "Error creating the ASYNC_WAIT_CTX\n");
                 goto end;
             }
         }
@@ -2486,7 +2645,11 @@ int speed_main(int argc, char **argv)
 #ifndef OPENSSL_NO_ECX
         memset(ecdsa_doit, 1, sizeof(ecdsa_doit));
         memset(ecdh_doit, 1, sizeof(ecdh_doit));
+        memset(eddsa_doit, 1, sizeof(eddsa_doit));
 #endif /* OPENSSL_NO_ECX */
+#ifndef OPENSSL_NO_SM2
+        memset(sm2_doit, 1, sizeof(sm2_doit));
+#endif
         memset(kems_doit, 1, sizeof(kems_doit));
         do_kems = 1;
         memset(sigs_doit, 1, sizeof(sigs_doit));
@@ -2497,7 +2660,7 @@ int speed_main(int argc, char **argv)
             pr_header++;
 
     if (usertime == 0 && !mr)
-        BIO_puts(bio_err,
+        BIO_printf(bio_err,
             "You have chosen to measure elapsed time "
             "instead of user CPU time.\n");
 
@@ -2855,7 +3018,7 @@ int speed_main(int argc, char **argv)
                 for (k = 0; k < loopargs_len; k++) {
                     loopargs[k].ctx = EVP_CIPHER_CTX_new();
                     if (loopargs[k].ctx == NULL) {
-                        BIO_puts(bio_err, "\nEVP_CIPHER_CTX_new failure\n");
+                        BIO_printf(bio_err, "\nEVP_CIPHER_CTX_new failure\n");
                         exit(1);
                     }
 
@@ -2867,7 +3030,7 @@ int speed_main(int argc, char **argv)
                      */
                     if (!EVP_CipherInit_ex(loopargs[k].ctx, evp_cipher, NULL,
                             NULL, NULL, ae_mode ? 1 : !decrypt)) {
-                        BIO_puts(bio_err, "\nCouldn't init the context\n");
+                        BIO_printf(bio_err, "\nCouldn't init the context\n");
                         dofail();
                         exit(1);
                     }
@@ -2882,7 +3045,7 @@ int speed_main(int argc, char **argv)
                     if (!ae_mode) {
                         if (!EVP_CipherInit_ex(loopargs[k].ctx, NULL, NULL,
                                 loopargs[k].key, iv, -1)) {
-                            BIO_puts(bio_err, "\nFailed to set the key\n");
+                            BIO_printf(bio_err, "\nFailed to set the key\n");
                             dofail();
                             exit(1);
                         }
@@ -2897,7 +3060,7 @@ int speed_main(int argc, char **argv)
                             if (!EVP_CIPHER_CTX_ctrl(loopargs[k].ctx,
                                     EVP_CTRL_AEAD_SET_IVLEN,
                                     sizeof(aead_iv), NULL)) {
-                                BIO_puts(bio_err, "\nFailed to set iv length\n");
+                                BIO_printf(bio_err, "\nFailed to set iv length\n");
                                 dofail();
                                 exit(1);
                             }
@@ -2909,7 +3072,7 @@ int speed_main(int argc, char **argv)
                             if (!EVP_CIPHER_CTX_ctrl(loopargs[k].ctx,
                                     EVP_CTRL_AEAD_SET_TAG,
                                     TAG_LEN, NULL)) {
-                                BIO_puts(bio_err,
+                                BIO_printf(bio_err,
                                     "\nFailed to set tag length\n");
                                 dofail();
                                 exit(1);
@@ -2917,7 +3080,7 @@ int speed_main(int argc, char **argv)
                         }
                         if (!EVP_CipherInit_ex(loopargs[k].ctx, NULL, NULL,
                                 loopargs[k].key, aead_iv, -1)) {
-                            BIO_puts(bio_err, "\nFailed to set the key\n");
+                            BIO_printf(bio_err, "\nFailed to set the key\n");
                             dofail();
                             exit(1);
                         }
@@ -2926,7 +3089,7 @@ int speed_main(int argc, char **argv)
                             if (!EVP_EncryptUpdate(loopargs[k].ctx, NULL,
                                     &outlen, NULL,
                                     lengths[testnum])) {
-                                BIO_puts(bio_err,
+                                BIO_printf(bio_err,
                                     "\nCouldn't set input text length\n");
                                 dofail();
                                 exit(1);
@@ -2935,7 +3098,7 @@ int speed_main(int argc, char **argv)
                         if (aead) {
                             if (!EVP_EncryptUpdate(loopargs[k].ctx, NULL,
                                     &outlen, aad, sizeof(aad))) {
-                                BIO_puts(bio_err,
+                                BIO_printf(bio_err,
                                     "\nCouldn't insert AAD when encrypting\n");
                                 dofail();
                                 exit(1);
@@ -2944,24 +3107,23 @@ int speed_main(int argc, char **argv)
                         if (!EVP_EncryptUpdate(loopargs[k].ctx, loopargs[k].buf,
                                 &outlen, loopargs[k].buf,
                                 lengths[testnum])) {
-                            BIO_puts(bio_err,
-                                "\nFailed to encrypt the data\n");
+                            BIO_printf(bio_err,
+                                "\nFailed to to encrypt the data\n");
                             dofail();
                             exit(1);
                         }
 
                         if (!EVP_EncryptFinal_ex(loopargs[k].ctx,
                                 loopargs[k].buf, &outlen)) {
-                            BIO_puts(bio_err,
+                            BIO_printf(bio_err,
                                 "\nFailed finalize the encryption\n");
                             dofail();
                             exit(1);
                         }
 
-                        if (EVP_CIPHER_CTX_ctrl(loopargs[k].ctx, EVP_CTRL_AEAD_GET_TAG,
-                                TAG_LEN, &loopargs[k].tag)
-                            <= 0) {
-                            BIO_puts(bio_err, "\nFailed to get the tag\n");
+                        if (!EVP_CIPHER_CTX_ctrl(loopargs[k].ctx, EVP_CTRL_AEAD_GET_TAG,
+                                TAG_LEN, &loopargs[k].tag)) {
+                            BIO_printf(bio_err, "\nFailed to get the tag\n");
                             dofail();
                             exit(1);
                         }
@@ -2969,7 +3131,7 @@ int speed_main(int argc, char **argv)
                         EVP_CIPHER_CTX_free(loopargs[k].ctx);
                         loopargs[k].ctx = EVP_CIPHER_CTX_new();
                         if (loopargs[k].ctx == NULL) {
-                            BIO_puts(bio_err,
+                            BIO_printf(bio_err,
                                 "\nEVP_CIPHER_CTX_new failure\n");
                             exit(1);
                         }
@@ -3026,7 +3188,7 @@ int speed_main(int argc, char **argv)
         keylen = EVP_CIPHER_get_key_length(cipher);
         EVP_CIPHER_free(cipher);
         if (keylen <= 0 || keylen > (int)sizeof(key32)) {
-            BIO_puts(bio_err, "\nRequested CMAC cipher with unsupported key length.\n");
+            BIO_printf(bio_err, "\nRequested CMAC cipher with unsupported key length.\n");
             goto end;
         }
         evp_cmac_name = app_malloc(len, "CMAC name");
@@ -3141,7 +3303,7 @@ int speed_main(int argc, char **argv)
                 st = 0;
         }
         if (!st) {
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "RSA sign setup failure.  No RSA sign will be done.\n");
             dofail();
             op_count = 1;
@@ -3153,7 +3315,8 @@ int speed_main(int argc, char **argv)
             count = run_benchmark(async_jobs, RSA_sign_loop, loopargs);
             d = Time_F(STOP);
             BIO_printf(bio_err,
-                mr ? "+R1:%ld:%d:%.2f\n" : "%ld %u bits private RSA sign ops in %.2fs\n",
+                mr ? "+R1:%ld:%d:%.2f\n"
+                   : "%ld %u bits private RSA sign ops in %.2fs\n",
                 count, rsa_keys[testnum].bits, d);
             rsa_results[testnum][0] = (double)count / d;
             op_count = count;
@@ -3172,7 +3335,7 @@ int speed_main(int argc, char **argv)
                 st = 0;
         }
         if (!st) {
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "RSA verify setup failure.  No RSA verify will be done.\n");
             dofail();
             rsa_doit[testnum] = 0;
@@ -3183,7 +3346,8 @@ int speed_main(int argc, char **argv)
             count = run_benchmark(async_jobs, RSA_verify_loop, loopargs);
             d = Time_F(STOP);
             BIO_printf(bio_err,
-                mr ? "+R2:%ld:%d:%.2f\n" : "%ld %u bits public RSA verify ops in %.2fs\n",
+                mr ? "+R2:%ld:%d:%.2f\n"
+                   : "%ld %u bits public RSA verify ops in %.2fs\n",
                 count, rsa_keys[testnum].bits, d);
             rsa_results[testnum][1] = (double)count / d;
         }
@@ -3201,7 +3365,7 @@ int speed_main(int argc, char **argv)
                 st = 0;
         }
         if (!st) {
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "RSA encrypt setup failure.  No RSA encrypt will be done.\n");
             dofail();
             op_count = 1;
@@ -3213,7 +3377,8 @@ int speed_main(int argc, char **argv)
             count = run_benchmark(async_jobs, RSA_encrypt_loop, loopargs);
             d = Time_F(STOP);
             BIO_printf(bio_err,
-                mr ? "+R3:%ld:%d:%.2f\n" : "%ld %u bits public RSA encrypt ops in %.2fs\n",
+                mr ? "+R3:%ld:%d:%.2f\n"
+                   : "%ld %u bits public RSA encrypt ops in %.2fs\n",
                 count, rsa_keys[testnum].bits, d);
             rsa_results[testnum][2] = (double)count / d;
             op_count = count;
@@ -3233,7 +3398,7 @@ int speed_main(int argc, char **argv)
                 st = 0;
         }
         if (!st) {
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "RSA decrypt setup failure.  No RSA decrypt will be done.\n");
             dofail();
             op_count = 1;
@@ -3245,7 +3410,8 @@ int speed_main(int argc, char **argv)
             count = run_benchmark(async_jobs, RSA_decrypt_loop, loopargs);
             d = Time_F(STOP);
             BIO_printf(bio_err,
-                mr ? "+R4:%ld:%d:%.2f\n" : "%ld %u bits private RSA decrypt ops in %.2fs\n",
+                mr ? "+R4:%ld:%d:%.2f\n"
+                   : "%ld %u bits private RSA decrypt ops in %.2fs\n",
                 count, rsa_keys[testnum].bits, d);
             rsa_results[testnum][3] = (double)count / d;
             op_count = count;
@@ -3282,7 +3448,7 @@ int speed_main(int argc, char **argv)
                 st = 0;
         }
         if (!st) {
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "DSA sign setup failure.  No DSA sign will be done.\n");
             dofail();
             op_count = 1;
@@ -3293,7 +3459,8 @@ int speed_main(int argc, char **argv)
             count = run_benchmark(async_jobs, DSA_sign_loop, loopargs);
             d = Time_F(STOP);
             BIO_printf(bio_err,
-                mr ? "+R5:%ld:%u:%.2f\n" : "%ld %u bits DSA sign ops in %.2fs\n",
+                mr ? "+R5:%ld:%u:%.2f\n"
+                   : "%ld %u bits DSA sign ops in %.2fs\n",
                 count, dsa_bits[testnum], d);
             dsa_results[testnum][0] = (double)count / d;
             op_count = count;
@@ -3312,7 +3479,7 @@ int speed_main(int argc, char **argv)
                 st = 0;
         }
         if (!st) {
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "DSA verify setup failure.  No DSA verify will be done.\n");
             dofail();
             dsa_doit[testnum] = 0;
@@ -3323,7 +3490,8 @@ int speed_main(int argc, char **argv)
             count = run_benchmark(async_jobs, DSA_verify_loop, loopargs);
             d = Time_F(STOP);
             BIO_printf(bio_err,
-                mr ? "+R6:%ld:%u:%.2f\n" : "%ld %u bits DSA verify ops in %.2fs\n",
+                mr ? "+R6:%ld:%u:%.2f\n"
+                   : "%ld %u bits DSA verify ops in %.2fs\n",
                 count, dsa_bits[testnum], d);
             dsa_results[testnum][1] = (double)count / d;
         }
@@ -3336,110 +3504,74 @@ int speed_main(int argc, char **argv)
     }
 #endif /* OPENSSL_NO_DSA */
 
-    for (testnum = 0; testnum < EC_NUM; testnum++) {
-        EVP_PKEY *pkey = NULL;
+    for (testnum = 0; testnum < ECDSA_NUM; testnum++) {
+        EVP_PKEY *ecdsa_key = NULL;
         int st;
-        int mdsig = ec_curves[testnum].mdsig > 0;
 
         if (!ecdsa_doit[testnum])
             continue;
 
-        st = (pkey = get_ecdsa(&ec_curves[testnum])) != NULL;
+        st = (ecdsa_key = get_ecdsa(&ec_curves[testnum])) != NULL;
 
         for (i = 0; st && i < loopargs_len; i++) {
+            loopargs[i].ecdsa_sign_ctx[testnum] = EVP_PKEY_CTX_new(ecdsa_key,
+                NULL);
             loopargs[i].sigsize = loopargs[i].buflen;
-            loopargs[i].curve_name[testnum] = EC_CURVE_NAME(ec_curves[testnum]);
-            if (!mdsig) {
-                EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new(pkey, NULL);
-
-                if ((loopargs[i].pk_sign_ctx[testnum] = pctx) == NULL
-                    || EVP_PKEY_sign_init(pctx) <= 0
-                    || EVP_PKEY_sign(pctx, loopargs[i].buf2,
-                           &loopargs[i].sigsize, loopargs[i].buf, 20)
-                        <= 0)
-                    st = 0;
-            } else {
-                OSSL_PARAM params[2] = {
-                    OSSL_PARAM_uint(OSSL_SIGNATURE_PARAM_TLS_VERSION, NULL),
-                    OSSL_PARAM_END,
-                };
-                EVP_MD_CTX *mctx = EVP_MD_CTX_new();
-                int v = TLS1_3_VERSION;
-
-                /*
-                 * Emulate TLS signature code, the TLS version is needed for
-                 * SM2 to infer the correct "distinguishing identifier".
-                 */
-                params[0].data = &v;
-                if ((loopargs[i].md_sign_ctx[testnum] = mctx) == NULL
-                    || !EVP_DigestSignInit_ex(mctx, NULL, NULL, NULL, NULL, pkey, params))
-                    st = 0;
-            }
+            if (loopargs[i].ecdsa_sign_ctx[testnum] == NULL
+                || EVP_PKEY_sign_init(loopargs[i].ecdsa_sign_ctx[testnum]) <= 0
+                || EVP_PKEY_sign(loopargs[i].ecdsa_sign_ctx[testnum],
+                       loopargs[i].buf2,
+                       &loopargs[i].sigsize,
+                       loopargs[i].buf, 20)
+                    <= 0)
+                st = 0;
         }
         if (!st) {
             BIO_printf(bio_err,
-                "%s sign setup failure.  No %s signing will be done.\n",
-                EC_CURVE_NAME(ec_curves[testnum]),
-                EC_CURVE_NAME(ec_curves[testnum]));
+                "ECDSA sign setup failure.  No ECDSA sign will be done.\n");
             dofail();
             op_count = 1;
         } else {
-            pkey_print_message("sign", EC_CURVE_NAME(ec_curves[testnum]),
+            pkey_print_message("sign", "ecdsa",
                 ec_curves[testnum].bits, seconds.ecdsa);
             Time_F(START);
             count = run_benchmark(async_jobs, ECDSA_sign_loop, loopargs);
             d = Time_F(STOP);
             BIO_printf(bio_err,
-                mr ? "+R7:%ld:%s:%.2f\n" : "%ld %s sign ops in %.2fs\n",
-                count, EC_CURVE_NAME(ec_curves[testnum]), d);
+                mr ? "+R7:%ld:%u:%.2f\n"
+                   : "%ld %u bits ECDSA sign ops in %.2fs\n",
+                count, ec_curves[testnum].bits, d);
             ecdsa_results[testnum][0] = (double)count / d;
             op_count = count;
         }
 
         for (i = 0; st && i < loopargs_len; i++) {
-            if (!mdsig) {
-                EVP_PKEY_CTX *pctx = EVP_PKEY_CTX_new(pkey, NULL);
-
-                if ((loopargs[i].pk_verify_ctx[testnum] = pctx) == NULL
-                    || EVP_PKEY_verify_init(pctx) <= 0
-                    || EVP_PKEY_verify(pctx, loopargs[i].buf2,
-                           loopargs[i].sigsize, loopargs[i].buf, 20)
-                        <= 0)
-                    st = 0;
-            } else {
-                OSSL_PARAM params[2] = {
-                    OSSL_PARAM_uint(OSSL_SIGNATURE_PARAM_TLS_VERSION, NULL),
-                    OSSL_PARAM_END,
-                };
-                EVP_MD_CTX *mctx = EVP_MD_CTX_new();
-                int v = TLS1_3_VERSION;
-
-                /*
-                 * Emulate TLS signature code, the TLS version is needed for
-                 * SM2 to infer the correct "distinguishing identifier".
-                 */
-                params[0].data = &v;
-                if ((loopargs[i].md_verify_ctx[testnum] = mctx) == NULL
-                    || !EVP_DigestVerifyInit_ex(mctx, NULL, NULL, NULL, NULL, pkey, params))
-                    st = 0;
-            }
+            loopargs[i].ecdsa_verify_ctx[testnum] = EVP_PKEY_CTX_new(ecdsa_key,
+                NULL);
+            if (loopargs[i].ecdsa_verify_ctx[testnum] == NULL
+                || EVP_PKEY_verify_init(loopargs[i].ecdsa_verify_ctx[testnum]) <= 0
+                || EVP_PKEY_verify(loopargs[i].ecdsa_verify_ctx[testnum],
+                       loopargs[i].buf2,
+                       loopargs[i].sigsize,
+                       loopargs[i].buf, 20)
+                    <= 0)
+                st = 0;
         }
         if (!st) {
             BIO_printf(bio_err,
-                "%s verify setup failure.  No %s verification will be done.\n",
-                EC_CURVE_NAME(ec_curves[testnum]),
-                EC_CURVE_NAME(ec_curves[testnum]));
+                "ECDSA verify setup failure.  No ECDSA verify will be done.\n");
             dofail();
             ecdsa_doit[testnum] = 0;
         } else {
-            pkey_print_message("verify", EC_CURVE_NAME(ec_curves[testnum]),
+            pkey_print_message("verify", "ecdsa",
                 ec_curves[testnum].bits, seconds.ecdsa);
             Time_F(START);
             count = run_benchmark(async_jobs, ECDSA_verify_loop, loopargs);
             d = Time_F(STOP);
             BIO_printf(bio_err,
-                mr ? "+R8:%ld:%s:%.2f\n" : "%ld %s verify ops in %.2fs\n",
-                count, EC_CURVE_NAME(ec_curves[testnum]), d);
+                mr ? "+R8:%ld:%u:%.2f\n"
+                   : "%ld %u bits ECDSA verify ops in %.2fs\n",
+                count, ec_curves[testnum].bits, d);
             ecdsa_results[testnum][1] = (double)count / d;
         }
 
@@ -3447,7 +3579,7 @@ int speed_main(int argc, char **argv)
             /* if longer than 10s, don't do any more */
             stop_it(ecdsa_doit, testnum);
         }
-        EVP_PKEY_free(pkey);
+        EVP_PKEY_free(ecdsa_key);
     }
 
     for (testnum = 0; testnum < EC_NUM; testnum++) {
@@ -3473,7 +3605,7 @@ int speed_main(int argc, char **argv)
                 || outlen == 0 /* ensure outlen is a valid size */
                 || outlen > MAX_ECDH_SIZE /* avoid buffer overflow */) {
                 ecdh_checks = 0;
-                BIO_puts(bio_err, "ECDH key generation failure.\n");
+                BIO_printf(bio_err, "ECDH key generation failure.\n");
                 dofail();
                 op_count = 1;
                 break;
@@ -3493,7 +3625,7 @@ int speed_main(int argc, char **argv)
                 || EVP_PKEY_derive(test_ctx, loopargs[i].secret_b, &test_outlen) <= 0 /* compute b*A */
                 || test_outlen != outlen /* compare output length */) {
                 ecdh_checks = 0;
-                BIO_puts(bio_err, "ECDH computation failure.\n");
+                BIO_printf(bio_err, "ECDH computation failure.\n");
                 dofail();
                 op_count = 1;
                 break;
@@ -3503,7 +3635,7 @@ int speed_main(int argc, char **argv)
             if (CRYPTO_memcmp(loopargs[i].secret_a,
                     loopargs[i].secret_b, outlen)) {
                 ecdh_checks = 0;
-                BIO_puts(bio_err, "ECDH computations don't match.\n");
+                BIO_printf(bio_err, "ECDH computations don't match.\n");
                 dofail();
                 op_count = 1;
                 break;
@@ -3518,14 +3650,14 @@ int speed_main(int argc, char **argv)
             test_ctx = NULL;
         }
         if (ecdh_checks != 0) {
-            pkey_print_message("", EC_CURVE_NAME(ec_curves[testnum]),
+            pkey_print_message("", "ecdh",
                 ec_curves[testnum].bits, seconds.ecdh);
             Time_F(START);
             count = run_benchmark(async_jobs, ECDH_EVP_derive_key_loop, loopargs);
             d = Time_F(STOP);
             BIO_printf(bio_err,
-                mr ? "+R9:%ld:%s:%.2f\n" : "%ld %s ops in %.2fs\n",
-                count, EC_CURVE_NAME(ec_curves[testnum]), d);
+                mr ? "+R9:%ld:%d:%.2f\n" : "%ld %u-bits ECDH ops in %.2fs\n", count,
+                ec_curves[testnum].bits, d);
             ecdh_results[testnum][0] = (double)count / d;
             op_count = count;
         }
@@ -3536,6 +3668,254 @@ int speed_main(int argc, char **argv)
         }
     }
 
+#ifndef OPENSSL_NO_ECX
+    for (testnum = 0; testnum < EdDSA_NUM; testnum++) {
+        int st = 1;
+        EVP_PKEY *ed_pkey = NULL;
+        EVP_PKEY_CTX *ed_pctx = NULL;
+
+        if (!eddsa_doit[testnum])
+            continue; /* Ignore Curve */
+        for (i = 0; i < loopargs_len; i++) {
+            loopargs[i].eddsa_ctx[testnum] = EVP_MD_CTX_new();
+            if (loopargs[i].eddsa_ctx[testnum] == NULL) {
+                st = 0;
+                break;
+            }
+            loopargs[i].eddsa_ctx2[testnum] = EVP_MD_CTX_new();
+            if (loopargs[i].eddsa_ctx2[testnum] == NULL) {
+                st = 0;
+                break;
+            }
+
+            if ((ed_pctx = EVP_PKEY_CTX_new_id(ed_curves[testnum].nid,
+                     NULL))
+                    == NULL
+                || EVP_PKEY_keygen_init(ed_pctx) <= 0
+                || EVP_PKEY_keygen(ed_pctx, &ed_pkey) <= 0) {
+                st = 0;
+                EVP_PKEY_CTX_free(ed_pctx);
+                break;
+            }
+            EVP_PKEY_CTX_free(ed_pctx);
+
+            if (!EVP_DigestSignInit(loopargs[i].eddsa_ctx[testnum], NULL, NULL,
+                    NULL, ed_pkey)) {
+                st = 0;
+                EVP_PKEY_free(ed_pkey);
+                break;
+            }
+            if (!EVP_DigestVerifyInit(loopargs[i].eddsa_ctx2[testnum], NULL,
+                    NULL, NULL, ed_pkey)) {
+                st = 0;
+                EVP_PKEY_free(ed_pkey);
+                break;
+            }
+
+            EVP_PKEY_free(ed_pkey);
+            ed_pkey = NULL;
+        }
+        if (st == 0) {
+            BIO_printf(bio_err, "EdDSA failure.\n");
+            dofail();
+            op_count = 1;
+        } else {
+            for (i = 0; i < loopargs_len; i++) {
+                /* Perform EdDSA signature test */
+                loopargs[i].sigsize = ed_curves[testnum].sigsize;
+                st = EVP_DigestSign(loopargs[i].eddsa_ctx[testnum],
+                    loopargs[i].buf2, &loopargs[i].sigsize,
+                    loopargs[i].buf, 20);
+                if (st == 0)
+                    break;
+            }
+            if (st == 0) {
+                BIO_printf(bio_err,
+                    "EdDSA sign failure.  No EdDSA sign will be done.\n");
+                dofail();
+                op_count = 1;
+            } else {
+                pkey_print_message("sign", ed_curves[testnum].name,
+                    ed_curves[testnum].bits, seconds.eddsa);
+                Time_F(START);
+                count = run_benchmark(async_jobs, EdDSA_sign_loop, loopargs);
+                d = Time_F(STOP);
+
+                BIO_printf(bio_err,
+                    mr ? "+R10:%ld:%u:%s:%.2f\n" : "%ld %u bits %s sign ops in %.2fs \n",
+                    count, ed_curves[testnum].bits,
+                    ed_curves[testnum].name, d);
+                eddsa_results[testnum][0] = (double)count / d;
+                op_count = count;
+            }
+            /* Perform EdDSA verification test */
+            for (i = 0; i < loopargs_len; i++) {
+                st = EVP_DigestVerify(loopargs[i].eddsa_ctx2[testnum],
+                    loopargs[i].buf2, loopargs[i].sigsize,
+                    loopargs[i].buf, 20);
+                if (st != 1)
+                    break;
+            }
+            if (st != 1) {
+                BIO_printf(bio_err,
+                    "EdDSA verify failure.  No EdDSA verify will be done.\n");
+                dofail();
+                eddsa_doit[testnum] = 0;
+            } else {
+                pkey_print_message("verify", ed_curves[testnum].name,
+                    ed_curves[testnum].bits, seconds.eddsa);
+                Time_F(START);
+                count = run_benchmark(async_jobs, EdDSA_verify_loop, loopargs);
+                d = Time_F(STOP);
+                BIO_printf(bio_err,
+                    mr ? "+R11:%ld:%u:%s:%.2f\n"
+                       : "%ld %u bits %s verify ops in %.2fs\n",
+                    count, ed_curves[testnum].bits,
+                    ed_curves[testnum].name, d);
+                eddsa_results[testnum][1] = (double)count / d;
+            }
+
+            if (op_count <= 1) {
+                /* if longer than 10s, don't do any more */
+                stop_it(eddsa_doit, testnum);
+            }
+        }
+    }
+#endif /* OPENSSL_NO_ECX */
+
+#ifndef OPENSSL_NO_SM2
+    for (testnum = 0; testnum < SM2_NUM; testnum++) {
+        int st = 1;
+        EVP_PKEY *sm2_pkey = NULL;
+
+        if (!sm2_doit[testnum])
+            continue; /* Ignore Curve */
+        /* Init signing and verification */
+        for (i = 0; i < loopargs_len; i++) {
+            EVP_PKEY_CTX *sm2_pctx = NULL;
+            EVP_PKEY_CTX *sm2_vfy_pctx = NULL;
+            EVP_PKEY_CTX *pctx = NULL;
+            st = 0;
+
+            loopargs[i].sm2_ctx[testnum] = EVP_MD_CTX_new();
+            loopargs[i].sm2_vfy_ctx[testnum] = EVP_MD_CTX_new();
+            if (loopargs[i].sm2_ctx[testnum] == NULL
+                || loopargs[i].sm2_vfy_ctx[testnum] == NULL)
+                break;
+
+            sm2_pkey = NULL;
+
+            st = !((pctx = EVP_PKEY_CTX_new_id(EVP_PKEY_SM2, NULL)) == NULL
+                || EVP_PKEY_keygen_init(pctx) <= 0
+                || EVP_PKEY_CTX_set_ec_paramgen_curve_nid(pctx,
+                       sm2_curves[testnum].nid)
+                    <= 0
+                || EVP_PKEY_keygen(pctx, &sm2_pkey) <= 0);
+            EVP_PKEY_CTX_free(pctx);
+            if (st == 0)
+                break;
+
+            st = 0; /* set back to zero */
+            /* attach it sooner to rely on main final cleanup */
+            loopargs[i].sm2_pkey[testnum] = sm2_pkey;
+            loopargs[i].sigsize = EVP_PKEY_get_size(sm2_pkey);
+
+            sm2_pctx = EVP_PKEY_CTX_new(sm2_pkey, NULL);
+            sm2_vfy_pctx = EVP_PKEY_CTX_new(sm2_pkey, NULL);
+            if (sm2_pctx == NULL || sm2_vfy_pctx == NULL) {
+                EVP_PKEY_CTX_free(sm2_vfy_pctx);
+                break;
+            }
+
+            /* attach them directly to respective ctx */
+            EVP_MD_CTX_set_pkey_ctx(loopargs[i].sm2_ctx[testnum], sm2_pctx);
+            EVP_MD_CTX_set_pkey_ctx(loopargs[i].sm2_vfy_ctx[testnum], sm2_vfy_pctx);
+
+            /*
+             * No need to allow user to set an explicit ID here, just use
+             * the one defined in the 'draft-yang-tls-tl13-sm-suites' I-D.
+             */
+            if (EVP_PKEY_CTX_set1_id(sm2_pctx, SM2_ID, SM2_ID_LEN) != 1
+                || EVP_PKEY_CTX_set1_id(sm2_vfy_pctx, SM2_ID, SM2_ID_LEN) != 1)
+                break;
+
+            if (!EVP_DigestSignInit(loopargs[i].sm2_ctx[testnum], NULL,
+                    EVP_sm3(), NULL, sm2_pkey))
+                break;
+            if (!EVP_DigestVerifyInit(loopargs[i].sm2_vfy_ctx[testnum], NULL,
+                    EVP_sm3(), NULL, sm2_pkey))
+                break;
+            st = 1; /* mark loop as succeeded */
+        }
+        if (st == 0) {
+            BIO_printf(bio_err, "SM2 init failure.\n");
+            dofail();
+            op_count = 1;
+        } else {
+            for (i = 0; i < loopargs_len; i++) {
+                /* Perform SM2 signature test */
+                st = EVP_DigestSign(loopargs[i].sm2_ctx[testnum],
+                    loopargs[i].buf2, &loopargs[i].sigsize,
+                    loopargs[i].buf, 20);
+                if (st == 0)
+                    break;
+            }
+            if (st == 0) {
+                BIO_printf(bio_err,
+                    "SM2 sign failure.  No SM2 sign will be done.\n");
+                dofail();
+                op_count = 1;
+            } else {
+                pkey_print_message("sign", sm2_curves[testnum].name,
+                    sm2_curves[testnum].bits, seconds.sm2);
+                Time_F(START);
+                count = run_benchmark(async_jobs, SM2_sign_loop, loopargs);
+                d = Time_F(STOP);
+
+                BIO_printf(bio_err,
+                    mr ? "+R12:%ld:%u:%s:%.2f\n" : "%ld %u bits %s sign ops in %.2fs \n",
+                    count, sm2_curves[testnum].bits,
+                    sm2_curves[testnum].name, d);
+                sm2_results[testnum][0] = (double)count / d;
+                op_count = count;
+            }
+
+            /* Perform SM2 verification test */
+            for (i = 0; i < loopargs_len; i++) {
+                st = EVP_DigestVerify(loopargs[i].sm2_vfy_ctx[testnum],
+                    loopargs[i].buf2, loopargs[i].sigsize,
+                    loopargs[i].buf, 20);
+                if (st != 1)
+                    break;
+            }
+            if (st != 1) {
+                BIO_printf(bio_err,
+                    "SM2 verify failure.  No SM2 verify will be done.\n");
+                dofail();
+                sm2_doit[testnum] = 0;
+            } else {
+                pkey_print_message("verify", sm2_curves[testnum].name,
+                    sm2_curves[testnum].bits, seconds.sm2);
+                Time_F(START);
+                count = run_benchmark(async_jobs, SM2_verify_loop, loopargs);
+                d = Time_F(STOP);
+                BIO_printf(bio_err,
+                    mr ? "+R13:%ld:%u:%s:%.2f\n"
+                       : "%ld %u bits %s verify ops in %.2fs\n",
+                    count, sm2_curves[testnum].bits,
+                    sm2_curves[testnum].name, d);
+                sm2_results[testnum][1] = (double)count / d;
+            }
+
+            if (op_count <= 1) {
+                /* if longer than 10s, don't do any more */
+                for (testnum++; testnum < SM2_NUM; testnum++)
+                    sm2_doit[testnum] = 0;
+            }
+        }
+    }
+#endif /* OPENSSL_NO_SM2 */
+
 #ifndef OPENSSL_NO_DH
     for (testnum = 0; testnum < FFDH_NUM; testnum++) {
         int ffdh_checks = 1;
@@ -3553,14 +3933,14 @@ int speed_main(int argc, char **argv)
 
             /* Ensure that the error queue is empty */
             if (ERR_peek_error()) {
-                BIO_puts(bio_err,
+                BIO_printf(bio_err,
                     "WARNING: the error queue contains previous unhandled errors.\n");
                 dofail();
             }
 
             pkey_A = EVP_PKEY_new();
             if (!pkey_A) {
-                BIO_puts(bio_err, "Error while initialising EVP_PKEY (out of memory?).\n");
+                BIO_printf(bio_err, "Error while initialising EVP_PKEY (out of memory?).\n");
                 dofail();
                 op_count = 1;
                 ffdh_checks = 0;
@@ -3568,7 +3948,7 @@ int speed_main(int argc, char **argv)
             }
             pkey_B = EVP_PKEY_new();
             if (!pkey_B) {
-                BIO_puts(bio_err, "Error while initialising EVP_PKEY (out of memory?).\n");
+                BIO_printf(bio_err, "Error while initialising EVP_PKEY (out of memory?).\n");
                 dofail();
                 op_count = 1;
                 ffdh_checks = 0;
@@ -3577,7 +3957,7 @@ int speed_main(int argc, char **argv)
 
             ffdh_ctx = EVP_PKEY_CTX_new_id(EVP_PKEY_DH, NULL);
             if (!ffdh_ctx) {
-                BIO_puts(bio_err, "Error while allocating EVP_PKEY_CTX.\n");
+                BIO_printf(bio_err, "Error while allocating EVP_PKEY_CTX.\n");
                 dofail();
                 op_count = 1;
                 ffdh_checks = 0;
@@ -3585,14 +3965,14 @@ int speed_main(int argc, char **argv)
             }
 
             if (EVP_PKEY_keygen_init(ffdh_ctx) <= 0) {
-                BIO_puts(bio_err, "Error while initialising EVP_PKEY_CTX.\n");
+                BIO_printf(bio_err, "Error while initialising EVP_PKEY_CTX.\n");
                 dofail();
                 op_count = 1;
                 ffdh_checks = 0;
                 break;
             }
             if (EVP_PKEY_CTX_set_dh_nid(ffdh_ctx, ffdh_params[testnum].nid) <= 0) {
-                BIO_puts(bio_err, "Error setting DH key size for keygen.\n");
+                BIO_printf(bio_err, "Error setting DH key size for keygen.\n");
                 dofail();
                 op_count = 1;
                 ffdh_checks = 0;
@@ -3600,7 +3980,7 @@ int speed_main(int argc, char **argv)
             }
 
             if (EVP_PKEY_keygen(ffdh_ctx, &pkey_A) <= 0 || EVP_PKEY_keygen(ffdh_ctx, &pkey_B) <= 0) {
-                BIO_puts(bio_err, "FFDH key generation failure.\n");
+                BIO_printf(bio_err, "FFDH key generation failure.\n");
                 dofail();
                 op_count = 1;
                 ffdh_checks = 0;
@@ -3616,35 +3996,35 @@ int speed_main(int argc, char **argv)
              */
             ffdh_ctx = EVP_PKEY_CTX_new(pkey_A, NULL);
             if (ffdh_ctx == NULL) {
-                BIO_puts(bio_err, "Error while allocating EVP_PKEY_CTX.\n");
+                BIO_printf(bio_err, "Error while allocating EVP_PKEY_CTX.\n");
                 dofail();
                 op_count = 1;
                 ffdh_checks = 0;
                 break;
             }
             if (EVP_PKEY_derive_init(ffdh_ctx) <= 0) {
-                BIO_puts(bio_err, "FFDH derivation context init failure.\n");
+                BIO_printf(bio_err, "FFDH derivation context init failure.\n");
                 dofail();
                 op_count = 1;
                 ffdh_checks = 0;
                 break;
             }
             if (EVP_PKEY_derive_set_peer(ffdh_ctx, pkey_B) <= 0) {
-                BIO_puts(bio_err, "Assigning peer key for derivation failed.\n");
+                BIO_printf(bio_err, "Assigning peer key for derivation failed.\n");
                 dofail();
                 op_count = 1;
                 ffdh_checks = 0;
                 break;
             }
             if (EVP_PKEY_derive(ffdh_ctx, NULL, &secret_size) <= 0) {
-                BIO_puts(bio_err, "Checking size of shared secret failed.\n");
+                BIO_printf(bio_err, "Checking size of shared secret failed.\n");
                 dofail();
                 op_count = 1;
                 ffdh_checks = 0;
                 break;
             }
             if (secret_size > MAX_FFDH_SIZE) {
-                BIO_puts(bio_err, "Assertion failure: shared secret too large.\n");
+                BIO_printf(bio_err, "Assertion failure: shared secret too large.\n");
                 op_count = 1;
                 ffdh_checks = 0;
                 break;
@@ -3653,7 +4033,7 @@ int speed_main(int argc, char **argv)
                     loopargs[i].secret_ff_a,
                     &secret_size)
                 <= 0) {
-                BIO_puts(bio_err, "Shared secret derive failure.\n");
+                BIO_printf(bio_err, "Shared secret derive failure.\n");
                 dofail();
                 op_count = 1;
                 ffdh_checks = 0;
@@ -3662,14 +4042,14 @@ int speed_main(int argc, char **argv)
             /* Now check from side B */
             test_ctx = EVP_PKEY_CTX_new(pkey_B, NULL);
             if (!test_ctx) {
-                BIO_puts(bio_err, "Error while allocating EVP_PKEY_CTX.\n");
+                BIO_printf(bio_err, "Error while allocating EVP_PKEY_CTX.\n");
                 dofail();
                 op_count = 1;
                 ffdh_checks = 0;
                 break;
             }
             if (EVP_PKEY_derive_init(test_ctx) <= 0 || EVP_PKEY_derive_set_peer(test_ctx, pkey_A) <= 0 || EVP_PKEY_derive(test_ctx, NULL, &test_out) <= 0 || EVP_PKEY_derive(test_ctx, loopargs[i].secret_ff_b, &test_out) <= 0 || test_out != secret_size) {
-                BIO_puts(bio_err, "FFDH computation failure.\n");
+                BIO_printf(bio_err, "FFDH computation failure.\n");
                 op_count = 1;
                 ffdh_checks = 0;
                 break;
@@ -3678,7 +4058,7 @@ int speed_main(int argc, char **argv)
             /* compare the computed secrets */
             if (CRYPTO_memcmp(loopargs[i].secret_ff_a,
                     loopargs[i].secret_ff_b, secret_size)) {
-                BIO_puts(bio_err, "FFDH computations don't match.\n");
+                BIO_printf(bio_err, "FFDH computations don't match.\n");
                 dofail();
                 op_count = 1;
                 ffdh_checks = 0;
@@ -3752,7 +4132,7 @@ int speed_main(int argc, char **argv)
                 kem_type = 0;
 
             if (ERR_peek_error()) {
-                BIO_puts(bio_err,
+                BIO_printf(bio_err,
                     "WARNING: the error queue contains previous unhandled errors.\n");
                 dofail();
             }
@@ -3781,7 +4161,7 @@ int speed_main(int argc, char **argv)
                 goto kem_err_break;
             }
             if (EVP_PKEY_keygen(kem_gen_ctx, &pkey) <= 0) {
-                BIO_puts(bio_err, "Error while generating KEM EVP_PKEY.\n");
+                BIO_printf(bio_err, "Error while generating KEM EVP_PKEY.\n");
                 goto kem_err_break;
             }
             /* Now prepare encaps data structs */
@@ -3875,8 +4255,8 @@ int speed_main(int argc, char **argv)
             count = run_benchmark(async_jobs, KEM_keygen_loop, loopargs);
             d = Time_F(STOP);
             BIO_printf(bio_err,
-                mr ? "+R15:%ld:%s:%.2f\n" : "%ld %s KEM keygen ops in %.2fs\n",
-                count, kem_name, d);
+                mr ? "+R15:%ld:%s:%.2f\n" : "%ld %s KEM keygen ops in %.2fs\n", count,
+                kem_name, d);
             kems_results[testnum][0] = (double)count / d;
             op_count = count;
             kskey_print_message(kem_name, "encaps", seconds.kem);
@@ -3884,8 +4264,8 @@ int speed_main(int argc, char **argv)
             count = run_benchmark(async_jobs, KEM_encaps_loop, loopargs);
             d = Time_F(STOP);
             BIO_printf(bio_err,
-                mr ? "+R16:%ld:%s:%.2f\n" : "%ld %s KEM encaps ops in %.2fs\n",
-                count, kem_name, d);
+                mr ? "+R16:%ld:%s:%.2f\n" : "%ld %s KEM encaps ops in %.2fs\n", count,
+                kem_name, d);
             kems_results[testnum][1] = (double)count / d;
             op_count = count;
             kskey_print_message(kem_name, "decaps", seconds.kem);
@@ -3893,8 +4273,8 @@ int speed_main(int argc, char **argv)
             count = run_benchmark(async_jobs, KEM_decaps_loop, loopargs);
             d = Time_F(STOP);
             BIO_printf(bio_err,
-                mr ? "+R17:%ld:%s:%.2f\n" : "%ld %s KEM decaps ops in %.2fs\n",
-                count, kem_name, d);
+                mr ? "+R17:%ld:%s:%.2f\n" : "%ld %s KEM decaps ops in %.2fs\n", count,
+                kem_name, d);
             kems_results[testnum][2] = (double)count / d;
             op_count = count;
         }
@@ -3932,7 +4312,7 @@ int speed_main(int argc, char **argv)
             memset(md, 0, SHA256_DIGEST_LENGTH);
 
             if (ERR_peek_error()) {
-                BIO_puts(bio_err,
+                BIO_printf(bio_err,
                     "WARNING: the error queue contains previous unhandled errors.\n");
                 dofail();
             }
@@ -4086,8 +4466,8 @@ int speed_main(int argc, char **argv)
             count = run_benchmark(async_jobs, SIG_keygen_loop, loopargs);
             d = Time_F(STOP);
             BIO_printf(bio_err,
-                mr ? "+R18:%ld:%s:%.2f\n" : "%ld %s signature keygen ops in %.2fs\n",
-                count, sig_name, d);
+                mr ? "+R18:%ld:%s:%.2f\n" : "%ld %s signature keygen ops in %.2fs\n", count,
+                sig_name, d);
             sigs_results[testnum][0] = (double)count / d;
             op_count = count;
             kskey_print_message(sig_name, "signs", seconds.sig);
@@ -4095,8 +4475,8 @@ int speed_main(int argc, char **argv)
             count = run_benchmark(async_jobs, SIG_sign_loop, loopargs);
             d = Time_F(STOP);
             BIO_printf(bio_err,
-                mr ? "+R19:%ld:%s:%.2f\n" : "%ld %s signature sign ops in %.2fs\n",
-                count, sig_name, d);
+                mr ? "+R19:%ld:%s:%.2f\n" : "%ld %s signature sign ops in %.2fs\n", count,
+                sig_name, d);
             sigs_results[testnum][1] = (double)count / d;
             op_count = count;
 
@@ -4105,8 +4485,8 @@ int speed_main(int argc, char **argv)
             count = run_benchmark(async_jobs, SIG_verify_loop, loopargs);
             d = Time_F(STOP);
             BIO_printf(bio_err,
-                mr ? "+R20:%ld:%s:%.2f\n" : "%ld %s signature verify ops in %.2fs\n",
-                count, sig_name, d);
+                mr ? "+R20:%ld:%s:%.2f\n" : "%ld %s signature verify ops in %.2fs\n", count,
+                sig_name, d);
             sigs_results[testnum][2] = (double)count / d;
             op_count = count;
         }
@@ -4214,8 +4594,8 @@ show_res:
                 k, ec_curves[k].bits,
                 ecdsa_results[k][0], ecdsa_results[k][1]);
         else
-            printf("%4u bits EC (%s) %8.4fs %8.4fs %8.1f %8.1f\n",
-                ec_curves[k].bits, EC_CURVE_NAME(ec_curves[k]),
+            printf("%4u bits ecdsa (%s) %8.4fs %8.4fs %8.1f %8.1f\n",
+                ec_curves[k].bits, ec_curves[k].name,
                 1.0 / ecdsa_results[k][0], 1.0 / ecdsa_results[k][1],
                 ecdsa_results[k][0], ecdsa_results[k][1]);
     }
@@ -4235,10 +4615,53 @@ show_res:
 
         else
             printf("%4u bits ecdh (%s) %8.4fs %8.1f\n",
-                ec_curves[k].bits, EC_CURVE_NAME(ec_curves[k]),
+                ec_curves[k].bits, ec_curves[k].name,
                 1.0 / ecdh_results[k][0], ecdh_results[k][0]);
     }
 
+#ifndef OPENSSL_NO_ECX
+    testnum = 1;
+    for (k = 0; k < OSSL_NELEM(eddsa_doit); k++) {
+        if (!eddsa_doit[k])
+            continue;
+        if (testnum && !mr) {
+            printf("%30ssign    verify    sign/s verify/s\n", " ");
+            testnum = 0;
+        }
+
+        if (mr)
+            printf("+F6:%u:%u:%s:%f:%f\n",
+                k, ed_curves[k].bits, ed_curves[k].name,
+                eddsa_results[k][0], eddsa_results[k][1]);
+        else
+            printf("%4u bits EdDSA (%s) %8.4fs %8.4fs %8.1f %8.1f\n",
+                ed_curves[k].bits, ed_curves[k].name,
+                1.0 / eddsa_results[k][0], 1.0 / eddsa_results[k][1],
+                eddsa_results[k][0], eddsa_results[k][1]);
+    }
+#endif /* OPENSSL_NO_ECX */
+
+#ifndef OPENSSL_NO_SM2
+    testnum = 1;
+    for (k = 0; k < OSSL_NELEM(sm2_doit); k++) {
+        if (!sm2_doit[k])
+            continue;
+        if (testnum && !mr) {
+            printf("%30ssign    verify    sign/s verify/s\n", " ");
+            testnum = 0;
+        }
+
+        if (mr)
+            printf("+F7:%u:%u:%s:%f:%f\n",
+                k, sm2_curves[k].bits, sm2_curves[k].name,
+                sm2_results[k][0], sm2_results[k][1]);
+        else
+            printf("%4u bits SM2 (%s) %8.4fs %8.4fs %8.1f %8.1f\n",
+                sm2_curves[k].bits, sm2_curves[k].name,
+                1.0 / sm2_results[k][0], 1.0 / sm2_results[k][1],
+                sm2_results[k][0], sm2_results[k][1]);
+    }
+#endif
 #ifndef OPENSSL_NO_DH
     testnum = 1;
     for (k = 0; k < FFDH_NUM; k++) {
@@ -4249,7 +4672,7 @@ show_res:
             testnum = 0;
         }
         if (mr)
-            printf("+F7:%u:%u:%f:%f\n",
+            printf("+F8:%u:%u:%f:%f\n",
                 k, ffdh_params[k].bits,
                 ffdh_results[k][0], 1.0 / ffdh_results[k][0]);
 
@@ -4271,7 +4694,7 @@ show_res:
             testnum = 0;
         }
         if (mr)
-            printf("+F8:%u:%f:%f:%f\n",
+            printf("+F9:%u:%f:%f:%f\n",
                 k, kems_results[k][0], kems_results[k][1],
                 kems_results[k][2]);
         else
@@ -4293,7 +4716,7 @@ show_res:
             testnum = 0;
         }
         if (mr)
-            printf("+F9:%u:%f:%f:%f\n",
+            printf("+F10:%u:%f:%f:%f\n",
                 k, sigs_results[k][0], sigs_results[k][1],
                 sigs_results[k][2]);
         else
@@ -4332,12 +4755,36 @@ end:
             EVP_PKEY_CTX_free(loopargs[i].dsa_verify_ctx[k]);
         }
 #endif
-        for (k = 0; k < EC_NUM; k++) {
-            EVP_PKEY_CTX_free(loopargs[i].pk_sign_ctx[k]);
-            EVP_PKEY_CTX_free(loopargs[i].pk_verify_ctx[k]);
+        for (k = 0; k < ECDSA_NUM; k++) {
+            EVP_PKEY_CTX_free(loopargs[i].ecdsa_sign_ctx[k]);
+            EVP_PKEY_CTX_free(loopargs[i].ecdsa_verify_ctx[k]);
         }
         for (k = 0; k < EC_NUM; k++)
             EVP_PKEY_CTX_free(loopargs[i].ecdh_ctx[k]);
+#ifndef OPENSSL_NO_ECX
+        for (k = 0; k < EdDSA_NUM; k++) {
+            EVP_MD_CTX_free(loopargs[i].eddsa_ctx[k]);
+            EVP_MD_CTX_free(loopargs[i].eddsa_ctx2[k]);
+        }
+#endif /* OPENSSL_NO_ECX */
+#ifndef OPENSSL_NO_SM2
+        for (k = 0; k < SM2_NUM; k++) {
+            EVP_PKEY_CTX *pctx = NULL;
+
+            /* free signing ctx */
+            if (loopargs[i].sm2_ctx[k] != NULL
+                && (pctx = EVP_MD_CTX_get_pkey_ctx(loopargs[i].sm2_ctx[k])) != NULL)
+                EVP_PKEY_CTX_free(pctx);
+            EVP_MD_CTX_free(loopargs[i].sm2_ctx[k]);
+            /* free verification ctx */
+            if (loopargs[i].sm2_vfy_ctx[k] != NULL
+                && (pctx = EVP_MD_CTX_get_pkey_ctx(loopargs[i].sm2_vfy_ctx[k])) != NULL)
+                EVP_PKEY_CTX_free(pctx);
+            EVP_MD_CTX_free(loopargs[i].sm2_vfy_ctx[k]);
+            /* free pkey */
+            EVP_PKEY_free(loopargs[i].sm2_pkey[k]);
+        }
+#endif
         for (k = 0; k < kems_algs_len; k++) {
             EVP_PKEY_CTX_free(loopargs[i].kem_gen_ctx[k]);
             EVP_PKEY_CTX_free(loopargs[i].kem_encaps_ctx[k]);
@@ -4384,7 +4831,8 @@ end:
 static void print_message(const char *s, int length, int tm)
 {
     BIO_printf(bio_err,
-        mr ? "+DT:%s:%d:%d\n" : "Doing %s ops for %ds on %d size blocks: ",
+        mr ? "+DT:%s:%d:%d\n"
+           : "Doing %s ops for %ds on %d size blocks: ",
         s, tm, length);
     (void)BIO_flush(bio_err);
     run = 1;
@@ -4395,7 +4843,8 @@ static void pkey_print_message(const char *str, const char *str2, unsigned int b
     int tm)
 {
     BIO_printf(bio_err,
-        mr ? "+DTP:%d:%s:%s:%d\n" : "Doing %u bits %s %s ops for %ds: ",
+        mr ? "+DTP:%d:%s:%s:%d\n"
+           : "Doing %u bits %s %s ops for %ds: ",
         bits, str, str2, tm);
     (void)BIO_flush(bio_err);
     run = 1;
@@ -4405,7 +4854,8 @@ static void pkey_print_message(const char *str, const char *str2, unsigned int b
 static void kskey_print_message(const char *str, const char *str2, int tm)
 {
     BIO_printf(bio_err,
-        mr ? "+DTP:%s:%s:%d\n" : "Doing %s %s ops for %ds: ",
+        mr ? "+DTP:%s:%s:%d\n"
+           : "Doing %s %s ops for %ds: ",
         str, str2, tm);
     (void)BIO_flush(bio_err);
     run = 1;
@@ -4420,7 +4870,8 @@ static void print_result(int alg, int run_no, int count, double time_used)
         return;
     }
     BIO_printf(bio_err,
-        mr ? "+R:%d:%s:%f\n" : "%d %s ops in %.2fs\n",
+        mr ? "+R:%d:%s:%f\n"
+           : "%d %s ops in %.2fs\n",
         count, names[alg], time_used);
     results[alg][run_no] = ((double)count) / time_used * lengths[run_no];
 }
@@ -4478,7 +4929,7 @@ static int do_multi(int multi, int size_num)
     fds = app_malloc_array(multi, sizeof(*fds), "fd buffer for do_multi");
     for (n = 0; n < multi; ++n) {
         if (pipe(fd) == -1) {
-            BIO_puts(bio_err, "pipe failure\n");
+            BIO_printf(bio_err, "pipe failure\n");
             exit(1);
         }
         fflush(stdout);
@@ -4490,7 +4941,7 @@ static int do_multi(int multi, int size_num)
             close(fd[0]);
             close(1);
             if (dup(fd[1]) == -1) {
-                BIO_puts(bio_err, "dup failed\n");
+                BIO_printf(bio_err, "dup failed\n");
                 exit(1);
             }
             close(fd[1]);
@@ -4587,8 +5038,36 @@ static int do_multi(int multi, int size_num)
                     d = atof(sstrsep(&p, sep));
                     ecdh_results[k][0] += d;
                 }
-#ifndef OPENSSL_NO_DH
+#ifndef OPENSSL_NO_ECX
+            } else if (CHECK_AND_SKIP_PREFIX(p, "+F6:")) {
+                tk = sstrsep(&p, sep);
+                if (strtoint(tk, 0, OSSL_NELEM(eddsa_results), &k)) {
+                    sstrsep(&p, sep);
+                    sstrsep(&p, sep);
+
+                    d = atof(sstrsep(&p, sep));
+                    eddsa_results[k][0] += d;
+
+                    d = atof(sstrsep(&p, sep));
+                    eddsa_results[k][1] += d;
+                }
+#endif /* OPENSSL_NO_ECX */
+#ifndef OPENSSL_NO_SM2
             } else if (CHECK_AND_SKIP_PREFIX(p, "+F7:")) {
+                tk = sstrsep(&p, sep);
+                if (strtoint(tk, 0, OSSL_NELEM(sm2_results), &k)) {
+                    sstrsep(&p, sep);
+                    sstrsep(&p, sep);
+
+                    d = atof(sstrsep(&p, sep));
+                    sm2_results[k][0] += d;
+
+                    d = atof(sstrsep(&p, sep));
+                    sm2_results[k][1] += d;
+                }
+#endif /* OPENSSL_NO_SM2 */
+#ifndef OPENSSL_NO_DH
+            } else if (CHECK_AND_SKIP_PREFIX(p, "+F8:")) {
                 tk = sstrsep(&p, sep);
                 if (strtoint(tk, 0, OSSL_NELEM(ffdh_results), &k)) {
                     sstrsep(&p, sep);
@@ -4597,7 +5076,7 @@ static int do_multi(int multi, int size_num)
                     ffdh_results[k][0] += d;
                 }
 #endif /* OPENSSL_NO_DH */
-            } else if (CHECK_AND_SKIP_PREFIX(p, "+F8:")) {
+            } else if (CHECK_AND_SKIP_PREFIX(p, "+F9:")) {
                 tk = sstrsep(&p, sep);
                 if (strtoint(tk, 0, OSSL_NELEM(kems_results), &k)) {
                     d = atof(sstrsep(&p, sep));
@@ -4609,7 +5088,7 @@ static int do_multi(int multi, int size_num)
                     d = atof(sstrsep(&p, sep));
                     kems_results[k][2] += d;
                 }
-            } else if (CHECK_AND_SKIP_PREFIX(p, "+F9:")) {
+            } else if (CHECK_AND_SKIP_PREFIX(p, "+F10:")) {
                 tk = sstrsep(&p, sep);
                 if (strtoint(tk, 0, OSSL_NELEM(sigs_results), &k)) {
                     d = atof(sstrsep(&p, sep));
@@ -4633,7 +5112,7 @@ static int do_multi(int multi, int size_num)
     for (n = 0; n < multi; ++n) {
         while (wait(&status) == -1)
             if (errno != EINTR) {
-                BIO_printf(bio_err, "Waiting for child failed with 0x%x\n",
+                BIO_printf(bio_err, "Waitng for child failed with 0x%x\n",
                     errno);
                 return 1;
             }
@@ -4736,7 +5215,7 @@ static void multiblock_speed(const EVP_CIPHER *evp_cipher, int lengths_single,
         d = Time_F(STOP);
         BIO_printf(bio_err, mr ? "+R:%d:%s:%f\n" : "%d %s ops in %.2fs\n", count, "evp", d);
         if ((ciph_success <= 0) && (mr == 0))
-            BIO_puts(bio_err, "Error performing cipher op\n");
+            BIO_printf(bio_err, "Error performing cipher op\n");
         results[D_EVP][j] = ((double)count) / d * mblengths[j];
     }
 
diff --git a/apps/spkac.c b/apps/spkac.c
index 27b2392bb9..d2cb68086a 100644
--- a/apps/spkac.c
+++ b/apps/spkac.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -139,7 +139,7 @@ int spkac_main(int argc, char **argv)
         goto opthelp;
 
     if (!app_passwd(passinarg, NULL, &passin, NULL)) {
-        BIO_puts(bio_err, "Error getting password\n");
+        BIO_printf(bio_err, "Error getting password\n");
         goto end;
     }
 
@@ -155,16 +155,16 @@ int spkac_main(int argc, char **argv)
         if (spki == NULL)
             goto end;
         if (challenge != NULL
-            && !ASN1_STRING_set_string(spki->spkac->challenge,
-                challenge))
+            && !ASN1_STRING_set(spki->spkac->challenge,
+                challenge, (int)strlen(challenge)))
             goto end;
         if (!NETSCAPE_SPKI_set_pubkey(spki, pkey)) {
-            BIO_puts(bio_err, "Error setting public key\n");
+            BIO_printf(bio_err, "Error setting public key\n");
             goto end;
         }
         i = NETSCAPE_SPKI_sign(spki, pkey, md);
         if (i <= 0) {
-            BIO_puts(bio_err, "Error signing SPKAC\n");
+            BIO_printf(bio_err, "Error signing SPKAC\n");
             goto end;
         }
         spkstr = NETSCAPE_SPKI_b64_encode(spki);
@@ -196,7 +196,7 @@ int spkac_main(int argc, char **argv)
     spki = NETSCAPE_SPKI_b64_decode(spkstr, -1);
 
     if (spki == NULL) {
-        BIO_puts(bio_err, "Error loading SPKAC\n");
+        BIO_printf(bio_err, "Error loading SPKAC\n");
         ERR_print_errors(bio_err);
         goto end;
     }
@@ -211,9 +211,9 @@ int spkac_main(int argc, char **argv)
     if (verify) {
         i = NETSCAPE_SPKI_verify(spki, pkey);
         if (i > 0) {
-            BIO_puts(bio_err, "Signature OK\n");
+            BIO_printf(bio_err, "Signature OK\n");
         } else {
-            BIO_puts(bio_err, "Signature Failure\n");
+            BIO_printf(bio_err, "Signature Failure\n");
             ERR_print_errors(bio_err);
             goto end;
         }
diff --git a/apps/srp.c b/apps/srp.c
index 2ae7b9e957..554f129ff7 100644
--- a/apps/srp.c
+++ b/apps/srp.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2004-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2004-2021 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright (c) 2004, EdelKey Project. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
@@ -101,7 +101,7 @@ static int update_index(CA_DB *db, char **row)
     irow[DB_NUMBER] = NULL;
 
     if (!TXT_DB_insert(db->db, irow)) {
-        BIO_puts(bio_err, "failed to update srpvfile\n");
+        BIO_printf(bio_err, "failed to update srpvfile\n");
         BIO_printf(bio_err, "TXT_DB error number %ld\n", db->db->error);
         OPENSSL_free(irow);
         return 0;
@@ -144,7 +144,7 @@ static char *srp_verify_user(const char *user, const char *srp_verifier,
         if ((gNid = SRP_create_verifier(user, password, &srp_usersalt,
                  &verifier, N, g))
             == NULL) {
-            BIO_puts(bio_err, "Internal error validating SRP verifier\n");
+            BIO_printf(bio_err, "Internal error validating SRP verifier\n");
         } else {
             if (strcmp(verifier, srp_verifier))
                 gNid = NULL;
@@ -176,7 +176,7 @@ static char *srp_create_user(char *user, char **srp_verifier,
         if ((gNid = SRP_create_verifier(user, password, &salt,
                  srp_verifier, N, g))
             == NULL) {
-            BIO_puts(bio_err, "Internal error creating SRP verifier\n");
+            BIO_printf(bio_err, "Internal error creating SRP verifier\n");
         } else {
             *srp_usersalt = salt;
         }
@@ -316,30 +316,30 @@ int srp_main(int argc, char **argv)
         goto end;
 
     if (srpvfile != NULL && configfile != NULL) {
-        BIO_puts(bio_err,
+        BIO_printf(bio_err,
             "-srpvfile and -configfile cannot be specified together.\n");
         goto end;
     }
     if (mode == OPT_ERR) {
-        BIO_puts(bio_err,
+        BIO_printf(bio_err,
             "Exactly one of the options -add, -delete, -modify -list must be specified.\n");
         goto opthelp;
     }
     if (mode == OPT_DELETE || mode == OPT_MODIFY || mode == OPT_ADD) {
         if (argc == 0) {
-            BIO_puts(bio_err, "Need at least one user.\n");
+            BIO_printf(bio_err, "Need at least one user.\n");
             goto opthelp;
         }
         user = *argv++;
     }
     if ((passinarg != NULL || passoutarg != NULL) && argc != 1) {
-        BIO_puts(bio_err,
+        BIO_printf(bio_err,
             "-passin, -passout arguments only valid with one user.\n");
         goto opthelp;
     }
 
     if (!app_passwd(passinarg, passoutarg, &passin, &passout)) {
-        BIO_puts(bio_err, "Error getting passwords\n");
+        BIO_printf(bio_err, "Error getting passwords\n");
         goto end;
     }
 
@@ -401,7 +401,7 @@ int srp_main(int argc, char **argv)
     }
 
     if (verbose)
-        BIO_puts(bio_err, "Database initialised\n");
+        BIO_printf(bio_err, "Database initialised\n");
 
     if (gNindex >= 0) {
         gNrow = sk_OPENSSL_PSTRING_value(db->db->data, gNindex);
@@ -411,12 +411,12 @@ int srp_main(int argc, char **argv)
         goto end;
     } else {
         if (verbose)
-            BIO_puts(bio_err, "Database has no g N information.\n");
+            BIO_printf(bio_err, "Database has no g N information.\n");
         gNrow = NULL;
     }
 
     if (verbose > 1)
-        BIO_puts(bio_err, "Starting user processing\n");
+        BIO_printf(bio_err, "Starting user processing\n");
 
     while (mode == OPT_LIST || user != NULL) {
         int userindex = -1;
@@ -428,7 +428,7 @@ int srp_main(int argc, char **argv)
 
         if (mode == OPT_LIST) {
             if (user == NULL) {
-                BIO_puts(bio_err, "List all users\n");
+                BIO_printf(bio_err, "List all users\n");
 
                 for (i = 0; i < sk_OPENSSL_PSTRING_num(db->db->data); i++)
                     print_user(db, i, 1);
@@ -578,7 +578,7 @@ int srp_main(int argc, char **argv)
     }
 
     if (verbose)
-        BIO_puts(bio_err, "User procession done.\n");
+        BIO_printf(bio_err, "User procession done.\n");
 
     if (doupdatedb) {
         /* Lets check some fields */
@@ -592,17 +592,17 @@ int srp_main(int argc, char **argv)
         }
 
         if (verbose)
-            BIO_puts(bio_err, "Trying to update srpvfile.\n");
+            BIO_printf(bio_err, "Trying to update srpvfile.\n");
         if (!save_index(srpvfile, "new", db))
             goto end;
 
         if (verbose)
-            BIO_puts(bio_err, "Temporary srpvfile created.\n");
+            BIO_printf(bio_err, "Temporary srpvfile created.\n");
         if (!rotate_index(srpvfile, "new", "old"))
             goto end;
 
         if (verbose)
-            BIO_puts(bio_err, "srpvfile updated.\n");
+            BIO_printf(bio_err, "srpvfile updated.\n");
     }
 
     ret = (errors != 0);
diff --git a/apps/storeutl.c b/apps/storeutl.c
index 5f2727808e..387cf54522 100644
--- a/apps/storeutl.c
+++ b/apps/storeutl.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -310,7 +310,7 @@ int storeutl_main(int argc, char *argv[])
     }
 
     if (!app_passwd(passinarg, NULL, &passin, NULL)) {
-        BIO_puts(bio_err, "Error getting passwords\n");
+        BIO_printf(bio_err, "Error getting passwords\n");
         goto end;
     }
     pw_cb_data.password = passin;
@@ -403,10 +403,10 @@ static int process(const char *uri, const UI_METHOD *uimeth, PW_CB_DATA *uidata,
             if (OSSL_STORE_eof(store_ctx))
                 break;
 
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "ERROR: OSSL_STORE_load() returned NULL without "
                 "eof or error indications\n");
-            BIO_puts(bio_err, "       This is an error in the loader\n");
+            BIO_printf(bio_err, "       This is an error in the loader\n");
             ERR_print_errors(bio_err);
             ret++;
             break;
@@ -484,7 +484,7 @@ static int process(const char *uri, const UI_METHOD *uimeth, PW_CB_DATA *uidata,
             /* Currently there is no universal API allowing to print smth, so no output */
             break;
         default:
-            BIO_puts(bio_err, "!!! Unknown code\n");
+            BIO_printf(bio_err, "!!! Unknown code\n");
             ret++;
             break;
         }
diff --git a/apps/testdsa.h b/apps/testdsa.h
index 48ff31309f..e8d04bb31e 100644
--- a/apps/testdsa.h
+++ b/apps/testdsa.h
@@ -7,60 +7,280 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_APPS_TESTDSA_H)
-#define OSSL_APPS_TESTDSA_H
-
-#include 
-#include 
-#include 
 #include 
 
 /* used by speed.c */
 EVP_PKEY *get_dsa(int);
 
 static unsigned char dsa512_priv[] = {
-    0x65, 0xe5, 0xc7, 0x38, 0x60, 0x24, 0xb5, 0x89, 0xd4, 0x9c,
-    0xeb, 0x4c, 0x9c, 0x1d, 0x7a, 0x22, 0xbd, 0xd1, 0xc2, 0xd2
+    0x65,
+    0xe5,
+    0xc7,
+    0x38,
+    0x60,
+    0x24,
+    0xb5,
+    0x89,
+    0xd4,
+    0x9c,
+    0xeb,
+    0x4c,
+    0x9c,
+    0x1d,
+    0x7a,
+    0x22,
+    0xbd,
+    0xd1,
+    0xc2,
+    0xd2,
 };
 
 static unsigned char dsa512_pub[] = {
-    0x00, 0x95, 0xa7, 0x0d, 0xec, 0x93, 0x68, 0xba, 0x5f, 0xf7,
-    0x5f, 0x07, 0xf2, 0x3b, 0xad, 0x6b, 0x01, 0xdc, 0xbe, 0xec,
-    0xde, 0x04, 0x7a, 0x3a, 0x27, 0xb3, 0xec, 0x49, 0xfd, 0x08,
-    0x43, 0x3d, 0x7e, 0xa8, 0x2c, 0x5e, 0x7b, 0xbb, 0xfc, 0xf4,
-    0x6e, 0xeb, 0x6c, 0xb0, 0x6e, 0xf8, 0x02, 0x12, 0x8c, 0x38,
-    0x5d, 0x83, 0x56, 0x7d, 0xee, 0x53, 0x05, 0x3e, 0x24, 0x84,
-    0xbe, 0xba, 0x0a, 0x6b, 0xc8
+    0x00,
+    0x95,
+    0xa7,
+    0x0d,
+    0xec,
+    0x93,
+    0x68,
+    0xba,
+    0x5f,
+    0xf7,
+    0x5f,
+    0x07,
+    0xf2,
+    0x3b,
+    0xad,
+    0x6b,
+    0x01,
+    0xdc,
+    0xbe,
+    0xec,
+    0xde,
+    0x04,
+    0x7a,
+    0x3a,
+    0x27,
+    0xb3,
+    0xec,
+    0x49,
+    0xfd,
+    0x08,
+    0x43,
+    0x3d,
+    0x7e,
+    0xa8,
+    0x2c,
+    0x5e,
+    0x7b,
+    0xbb,
+    0xfc,
+    0xf4,
+    0x6e,
+    0xeb,
+    0x6c,
+    0xb0,
+    0x6e,
+    0xf8,
+    0x02,
+    0x12,
+    0x8c,
+    0x38,
+    0x5d,
+    0x83,
+    0x56,
+    0x7d,
+    0xee,
+    0x53,
+    0x05,
+    0x3e,
+    0x24,
+    0x84,
+    0xbe,
+    0xba,
+    0x0a,
+    0x6b,
+    0xc8,
 };
 
 static unsigned char dsa512_p[] = {
-    0x9D, 0x1B, 0x69, 0x8E, 0x26, 0xDB, 0xF2, 0x2B, 0x11, 0x70,
-    0x19, 0x86, 0xF6, 0x19, 0xC8, 0xF8, 0x19, 0xF2, 0x18, 0x53,
-    0x94, 0x46, 0x06, 0xD0, 0x62, 0x50, 0x33, 0x4B, 0x02, 0x3C,
-    0x52, 0x30, 0x03, 0x8B, 0x3B, 0xF9, 0x5F, 0xD1, 0x24, 0x06,
-    0x4F, 0x7B, 0x4C, 0xBA, 0xAA, 0x40, 0x9B, 0xFD, 0x96, 0xE4,
-    0x37, 0x33, 0xBB, 0x2D, 0x5A, 0xD7, 0x5A, 0x11, 0x40, 0x66,
-    0xA2, 0x76, 0x7D, 0x31
+    0x9D,
+    0x1B,
+    0x69,
+    0x8E,
+    0x26,
+    0xDB,
+    0xF2,
+    0x2B,
+    0x11,
+    0x70,
+    0x19,
+    0x86,
+    0xF6,
+    0x19,
+    0xC8,
+    0xF8,
+    0x19,
+    0xF2,
+    0x18,
+    0x53,
+    0x94,
+    0x46,
+    0x06,
+    0xD0,
+    0x62,
+    0x50,
+    0x33,
+    0x4B,
+    0x02,
+    0x3C,
+    0x52,
+    0x30,
+    0x03,
+    0x8B,
+    0x3B,
+    0xF9,
+    0x5F,
+    0xD1,
+    0x24,
+    0x06,
+    0x4F,
+    0x7B,
+    0x4C,
+    0xBA,
+    0xAA,
+    0x40,
+    0x9B,
+    0xFD,
+    0x96,
+    0xE4,
+    0x37,
+    0x33,
+    0xBB,
+    0x2D,
+    0x5A,
+    0xD7,
+    0x5A,
+    0x11,
+    0x40,
+    0x66,
+    0xA2,
+    0x76,
+    0x7D,
+    0x31,
 };
 
 static unsigned char dsa512_q[] = {
-    0xFB, 0x53, 0xEF, 0x50, 0xB4, 0x40, 0x92, 0x31, 0x56, 0x86,
-    0x53, 0x7A, 0xE8, 0x8B, 0x22, 0x9A, 0x49, 0xFB, 0x71, 0x8F
+    0xFB,
+    0x53,
+    0xEF,
+    0x50,
+    0xB4,
+    0x40,
+    0x92,
+    0x31,
+    0x56,
+    0x86,
+    0x53,
+    0x7A,
+    0xE8,
+    0x8B,
+    0x22,
+    0x9A,
+    0x49,
+    0xFB,
+    0x71,
+    0x8F,
 };
 
 static unsigned char dsa512_g[] = {
-    0x83, 0x3E, 0x88, 0xE5, 0xC5, 0x89, 0x73, 0xCE, 0x3B, 0x6C,
-    0x01, 0x49, 0xBF, 0xB3, 0xC7, 0x9F, 0x0A, 0xEA, 0x44, 0x91,
-    0xE5, 0x30, 0xAA, 0xD9, 0xBE, 0x5B, 0x5F, 0xB7, 0x10, 0xD7,
-    0x89, 0xB7, 0x8E, 0x74, 0xFB, 0xCF, 0x29, 0x1E, 0xEB, 0xA8,
-    0x2C, 0x54, 0x51, 0xB8, 0x10, 0xDE, 0xA0, 0xCE, 0x2F, 0xCC,
-    0x24, 0x6B, 0x90, 0x77, 0xDE, 0xA2, 0x68, 0xA6, 0x52, 0x12,
-    0xA2, 0x03, 0x9D, 0x20
+    0x83,
+    0x3E,
+    0x88,
+    0xE5,
+    0xC5,
+    0x89,
+    0x73,
+    0xCE,
+    0x3B,
+    0x6C,
+    0x01,
+    0x49,
+    0xBF,
+    0xB3,
+    0xC7,
+    0x9F,
+    0x0A,
+    0xEA,
+    0x44,
+    0x91,
+    0xE5,
+    0x30,
+    0xAA,
+    0xD9,
+    0xBE,
+    0x5B,
+    0x5F,
+    0xB7,
+    0x10,
+    0xD7,
+    0x89,
+    0xB7,
+    0x8E,
+    0x74,
+    0xFB,
+    0xCF,
+    0x29,
+    0x1E,
+    0xEB,
+    0xA8,
+    0x2C,
+    0x54,
+    0x51,
+    0xB8,
+    0x10,
+    0xDE,
+    0xA0,
+    0xCE,
+    0x2F,
+    0xCC,
+    0x24,
+    0x6B,
+    0x90,
+    0x77,
+    0xDE,
+    0xA2,
+    0x68,
+    0xA6,
+    0x52,
+    0x12,
+    0xA2,
+    0x03,
+    0x9D,
+    0x20,
 };
 
 static unsigned char dsa1024_priv[] = {
-    0x7d, 0x21, 0xda, 0xbb, 0x62, 0x15, 0x47, 0x36, 0x07, 0x67,
-    0x12, 0xe8, 0x8c, 0xaa, 0x1c, 0xcd, 0x38, 0x12, 0x61, 0x18
+    0x7d,
+    0x21,
+    0xda,
+    0xbb,
+    0x62,
+    0x15,
+    0x47,
+    0x36,
+    0x07,
+    0x67,
+    0x12,
+    0xe8,
+    0x8c,
+    0xaa,
+    0x1c,
+    0xcd,
+    0x38,
+    0x12,
+    0x61,
+    0x18,
 };
 
 static unsigned char dsa1024_pub[] = {
@@ -78,137 +298,1111 @@ static unsigned char dsa1024_pub[] = {
 };
 
 static unsigned char dsa1024_p[] = {
-    0xA7, 0x3F, 0x6E, 0x85, 0xBF, 0x41, 0x6A, 0x29, 0x7D, 0xF0,
-    0x9F, 0x47, 0x19, 0x30, 0x90, 0x9A, 0x09, 0x1D, 0xDA, 0x6A,
-    0x33, 0x1E, 0xC5, 0x3D, 0x86, 0x96, 0xB3, 0x15, 0xE0, 0x53,
-    0x2E, 0x8F, 0xE0, 0x59, 0x82, 0x73, 0x90, 0x3E, 0x75, 0x31,
-    0x99, 0x47, 0x7A, 0x52, 0xFB, 0x85, 0xE4, 0xD9, 0xA6, 0x7B,
-    0x38, 0x9B, 0x68, 0x8A, 0x84, 0x9B, 0x87, 0xC6, 0x1E, 0xB5,
-    0x7E, 0x86, 0x4B, 0x53, 0x5B, 0x59, 0xCF, 0x71, 0x65, 0x19,
-    0x88, 0x6E, 0xCE, 0x66, 0xAE, 0x6B, 0x88, 0x36, 0xFB, 0xEC,
-    0x28, 0xDC, 0xC2, 0xD7, 0xA5, 0xBB, 0xE5, 0x2C, 0x39, 0x26,
-    0x4B, 0xDA, 0x9A, 0x70, 0x18, 0x95, 0x37, 0x95, 0x10, 0x56,
-    0x23, 0xF6, 0x15, 0xED, 0xBA, 0x04, 0x5E, 0xDE, 0x39, 0x4F,
-    0xFD, 0xB7, 0x43, 0x1F, 0xB5, 0xA4, 0x65, 0x6F, 0xCD, 0x80,
-    0x11, 0xE4, 0x70, 0x95, 0x5B, 0x50, 0xCD, 0x49
+    0xA7,
+    0x3F,
+    0x6E,
+    0x85,
+    0xBF,
+    0x41,
+    0x6A,
+    0x29,
+    0x7D,
+    0xF0,
+    0x9F,
+    0x47,
+    0x19,
+    0x30,
+    0x90,
+    0x9A,
+    0x09,
+    0x1D,
+    0xDA,
+    0x6A,
+    0x33,
+    0x1E,
+    0xC5,
+    0x3D,
+    0x86,
+    0x96,
+    0xB3,
+    0x15,
+    0xE0,
+    0x53,
+    0x2E,
+    0x8F,
+    0xE0,
+    0x59,
+    0x82,
+    0x73,
+    0x90,
+    0x3E,
+    0x75,
+    0x31,
+    0x99,
+    0x47,
+    0x7A,
+    0x52,
+    0xFB,
+    0x85,
+    0xE4,
+    0xD9,
+    0xA6,
+    0x7B,
+    0x38,
+    0x9B,
+    0x68,
+    0x8A,
+    0x84,
+    0x9B,
+    0x87,
+    0xC6,
+    0x1E,
+    0xB5,
+    0x7E,
+    0x86,
+    0x4B,
+    0x53,
+    0x5B,
+    0x59,
+    0xCF,
+    0x71,
+    0x65,
+    0x19,
+    0x88,
+    0x6E,
+    0xCE,
+    0x66,
+    0xAE,
+    0x6B,
+    0x88,
+    0x36,
+    0xFB,
+    0xEC,
+    0x28,
+    0xDC,
+    0xC2,
+    0xD7,
+    0xA5,
+    0xBB,
+    0xE5,
+    0x2C,
+    0x39,
+    0x26,
+    0x4B,
+    0xDA,
+    0x9A,
+    0x70,
+    0x18,
+    0x95,
+    0x37,
+    0x95,
+    0x10,
+    0x56,
+    0x23,
+    0xF6,
+    0x15,
+    0xED,
+    0xBA,
+    0x04,
+    0x5E,
+    0xDE,
+    0x39,
+    0x4F,
+    0xFD,
+    0xB7,
+    0x43,
+    0x1F,
+    0xB5,
+    0xA4,
+    0x65,
+    0x6F,
+    0xCD,
+    0x80,
+    0x11,
+    0xE4,
+    0x70,
+    0x95,
+    0x5B,
+    0x50,
+    0xCD,
+    0x49,
 };
 
 static unsigned char dsa1024_q[] = {
-    0xF7, 0x07, 0x31, 0xED, 0xFA, 0x6C, 0x06, 0x03, 0xD5, 0x85,
-    0x8A, 0x1C, 0xAC, 0x9C, 0x65, 0xE7, 0x50, 0x66, 0x65, 0x6F
+    0xF7,
+    0x07,
+    0x31,
+    0xED,
+    0xFA,
+    0x6C,
+    0x06,
+    0x03,
+    0xD5,
+    0x85,
+    0x8A,
+    0x1C,
+    0xAC,
+    0x9C,
+    0x65,
+    0xE7,
+    0x50,
+    0x66,
+    0x65,
+    0x6F,
 };
 
 static unsigned char dsa1024_g[] = {
-    0x4D, 0xDF, 0x4C, 0x03, 0xA6, 0x91, 0x8A, 0xF5, 0x19, 0x6F,
-    0x50, 0x46, 0x25, 0x99, 0xE5, 0x68, 0x6F, 0x30, 0xE3, 0x69,
-    0xE1, 0xE5, 0xB3, 0x5D, 0x98, 0xBB, 0x28, 0x86, 0x48, 0xFC,
-    0xDE, 0x99, 0x04, 0x3F, 0x5F, 0x88, 0x0C, 0x9C, 0x73, 0x24,
-    0x0D, 0x20, 0x5D, 0xB9, 0x2A, 0x9A, 0x3F, 0x18, 0x96, 0x27,
-    0xE4, 0x62, 0x87, 0xC1, 0x7B, 0x74, 0x62, 0x53, 0xFC, 0x61,
-    0x27, 0xA8, 0x7A, 0x91, 0x09, 0x9D, 0xB6, 0xF1, 0x4D, 0x9C,
-    0x54, 0x0F, 0x58, 0x06, 0xEE, 0x49, 0x74, 0x07, 0xCE, 0x55,
-    0x7E, 0x23, 0xCE, 0x16, 0xF6, 0xCA, 0xDC, 0x5A, 0x61, 0x01,
-    0x7E, 0xC9, 0x71, 0xB5, 0x4D, 0xF6, 0xDC, 0x34, 0x29, 0x87,
-    0x68, 0xF6, 0x5E, 0x20, 0x93, 0xB3, 0xDB, 0xF5, 0xE4, 0x09,
-    0x6C, 0x41, 0x17, 0x95, 0x92, 0xEB, 0x01, 0xB5, 0x73, 0xA5,
-    0x6A, 0x7E, 0xD8, 0x32, 0xED, 0x0E, 0x02, 0xB8
+    0x4D,
+    0xDF,
+    0x4C,
+    0x03,
+    0xA6,
+    0x91,
+    0x8A,
+    0xF5,
+    0x19,
+    0x6F,
+    0x50,
+    0x46,
+    0x25,
+    0x99,
+    0xE5,
+    0x68,
+    0x6F,
+    0x30,
+    0xE3,
+    0x69,
+    0xE1,
+    0xE5,
+    0xB3,
+    0x5D,
+    0x98,
+    0xBB,
+    0x28,
+    0x86,
+    0x48,
+    0xFC,
+    0xDE,
+    0x99,
+    0x04,
+    0x3F,
+    0x5F,
+    0x88,
+    0x0C,
+    0x9C,
+    0x73,
+    0x24,
+    0x0D,
+    0x20,
+    0x5D,
+    0xB9,
+    0x2A,
+    0x9A,
+    0x3F,
+    0x18,
+    0x96,
+    0x27,
+    0xE4,
+    0x62,
+    0x87,
+    0xC1,
+    0x7B,
+    0x74,
+    0x62,
+    0x53,
+    0xFC,
+    0x61,
+    0x27,
+    0xA8,
+    0x7A,
+    0x91,
+    0x09,
+    0x9D,
+    0xB6,
+    0xF1,
+    0x4D,
+    0x9C,
+    0x54,
+    0x0F,
+    0x58,
+    0x06,
+    0xEE,
+    0x49,
+    0x74,
+    0x07,
+    0xCE,
+    0x55,
+    0x7E,
+    0x23,
+    0xCE,
+    0x16,
+    0xF6,
+    0xCA,
+    0xDC,
+    0x5A,
+    0x61,
+    0x01,
+    0x7E,
+    0xC9,
+    0x71,
+    0xB5,
+    0x4D,
+    0xF6,
+    0xDC,
+    0x34,
+    0x29,
+    0x87,
+    0x68,
+    0xF6,
+    0x5E,
+    0x20,
+    0x93,
+    0xB3,
+    0xDB,
+    0xF5,
+    0xE4,
+    0x09,
+    0x6C,
+    0x41,
+    0x17,
+    0x95,
+    0x92,
+    0xEB,
+    0x01,
+    0xB5,
+    0x73,
+    0xA5,
+    0x6A,
+    0x7E,
+    0xD8,
+    0x32,
+    0xED,
+    0x0E,
+    0x02,
+    0xB8,
 };
 
 static unsigned char dsa2048_priv[] = {
-    0x32, 0x67, 0x92, 0xf6, 0xc4, 0xe2, 0xe2, 0xe8, 0xa0, 0x8b,
-    0x6b, 0x45, 0x0c, 0x8a, 0x76, 0xb0, 0xee, 0xcf, 0x91, 0xa7
+    0x32,
+    0x67,
+    0x92,
+    0xf6,
+    0xc4,
+    0xe2,
+    0xe2,
+    0xe8,
+    0xa0,
+    0x8b,
+    0x6b,
+    0x45,
+    0x0c,
+    0x8a,
+    0x76,
+    0xb0,
+    0xee,
+    0xcf,
+    0x91,
+    0xa7,
 };
 
 static unsigned char dsa2048_pub[] = {
-    0x17, 0x8f, 0xa8, 0x11, 0x84, 0x92, 0xec, 0x83, 0x47, 0xc7,
-    0x6a, 0xb0, 0x92, 0xaf, 0x5a, 0x20, 0x37, 0xa3, 0x64, 0x79,
-    0xd2, 0xd0, 0x3d, 0xcd, 0xe0, 0x61, 0x88, 0x88, 0x21, 0xcc,
-    0x74, 0x5d, 0xce, 0x4c, 0x51, 0x47, 0xf0, 0xc5, 0x5c, 0x4c,
-    0x82, 0x7a, 0xaf, 0x72, 0xad, 0xb9, 0xe0, 0x53, 0xf2, 0x78,
-    0xb7, 0xf0, 0xb5, 0x48, 0x7f, 0x8a, 0x3a, 0x18, 0xd1, 0x9f,
-    0x8b, 0x7d, 0xa5, 0x47, 0xb7, 0x95, 0xab, 0x98, 0xf8, 0x7b,
-    0x74, 0x50, 0x56, 0x8e, 0x57, 0xf0, 0xee, 0xf5, 0xb7, 0xba,
-    0xab, 0x85, 0x86, 0xf9, 0x2b, 0xef, 0x41, 0x56, 0xa0, 0xa4,
-    0x9f, 0xb7, 0x38, 0x00, 0x46, 0x0a, 0xa6, 0xf1, 0xfc, 0x1f,
-    0xd8, 0x4e, 0x85, 0x44, 0x92, 0x43, 0x21, 0x5d, 0x6e, 0xcc,
-    0xc2, 0xcb, 0x26, 0x31, 0x0d, 0x21, 0xc4, 0xbd, 0x8d, 0x24,
-    0xbc, 0xd9, 0x18, 0x19, 0xd7, 0xdc, 0xf1, 0xe7, 0x93, 0x50,
-    0x48, 0x03, 0x2c, 0xae, 0x2e, 0xe7, 0x49, 0x88, 0x5f, 0x93,
-    0x57, 0x27, 0x99, 0x36, 0xb4, 0x20, 0xab, 0xfc, 0xa7, 0x2b,
-    0xf2, 0xd9, 0x98, 0xd7, 0xd4, 0x34, 0x9d, 0x96, 0x50, 0x58,
-    0x9a, 0xea, 0x54, 0xf3, 0xee, 0xf5, 0x63, 0x14, 0xee, 0x85,
-    0x83, 0x74, 0x76, 0xe1, 0x52, 0x95, 0xc3, 0xf7, 0xeb, 0x04,
-    0x04, 0x7b, 0xa7, 0x28, 0x1b, 0xcc, 0xea, 0x4a, 0x4e, 0x84,
-    0xda, 0xd8, 0x9c, 0x79, 0xd8, 0x9b, 0x66, 0x89, 0x2f, 0xcf,
-    0xac, 0xd7, 0x79, 0xf9, 0xa9, 0xd8, 0x45, 0x13, 0x78, 0xb9,
-    0x00, 0x14, 0xc9, 0x7e, 0x22, 0x51, 0x86, 0x67, 0xb0, 0x9f,
-    0x26, 0x11, 0x23, 0xc8, 0x38, 0xd7, 0x70, 0x1d, 0x15, 0x8e,
-    0x4d, 0x4f, 0x95, 0x97, 0x40, 0xa1, 0xc2, 0x7e, 0x01, 0x18,
-    0x72, 0xf4, 0x10, 0xe6, 0x8d, 0x52, 0x16, 0x7f, 0xf2, 0xc9,
-    0xf8, 0x33, 0x8b, 0x33, 0xb7, 0xce
+    0x17,
+    0x8f,
+    0xa8,
+    0x11,
+    0x84,
+    0x92,
+    0xec,
+    0x83,
+    0x47,
+    0xc7,
+    0x6a,
+    0xb0,
+    0x92,
+    0xaf,
+    0x5a,
+    0x20,
+    0x37,
+    0xa3,
+    0x64,
+    0x79,
+    0xd2,
+    0xd0,
+    0x3d,
+    0xcd,
+    0xe0,
+    0x61,
+    0x88,
+    0x88,
+    0x21,
+    0xcc,
+    0x74,
+    0x5d,
+    0xce,
+    0x4c,
+    0x51,
+    0x47,
+    0xf0,
+    0xc5,
+    0x5c,
+    0x4c,
+    0x82,
+    0x7a,
+    0xaf,
+    0x72,
+    0xad,
+    0xb9,
+    0xe0,
+    0x53,
+    0xf2,
+    0x78,
+    0xb7,
+    0xf0,
+    0xb5,
+    0x48,
+    0x7f,
+    0x8a,
+    0x3a,
+    0x18,
+    0xd1,
+    0x9f,
+    0x8b,
+    0x7d,
+    0xa5,
+    0x47,
+    0xb7,
+    0x95,
+    0xab,
+    0x98,
+    0xf8,
+    0x7b,
+    0x74,
+    0x50,
+    0x56,
+    0x8e,
+    0x57,
+    0xf0,
+    0xee,
+    0xf5,
+    0xb7,
+    0xba,
+    0xab,
+    0x85,
+    0x86,
+    0xf9,
+    0x2b,
+    0xef,
+    0x41,
+    0x56,
+    0xa0,
+    0xa4,
+    0x9f,
+    0xb7,
+    0x38,
+    0x00,
+    0x46,
+    0x0a,
+    0xa6,
+    0xf1,
+    0xfc,
+    0x1f,
+    0xd8,
+    0x4e,
+    0x85,
+    0x44,
+    0x92,
+    0x43,
+    0x21,
+    0x5d,
+    0x6e,
+    0xcc,
+    0xc2,
+    0xcb,
+    0x26,
+    0x31,
+    0x0d,
+    0x21,
+    0xc4,
+    0xbd,
+    0x8d,
+    0x24,
+    0xbc,
+    0xd9,
+    0x18,
+    0x19,
+    0xd7,
+    0xdc,
+    0xf1,
+    0xe7,
+    0x93,
+    0x50,
+    0x48,
+    0x03,
+    0x2c,
+    0xae,
+    0x2e,
+    0xe7,
+    0x49,
+    0x88,
+    0x5f,
+    0x93,
+    0x57,
+    0x27,
+    0x99,
+    0x36,
+    0xb4,
+    0x20,
+    0xab,
+    0xfc,
+    0xa7,
+    0x2b,
+    0xf2,
+    0xd9,
+    0x98,
+    0xd7,
+    0xd4,
+    0x34,
+    0x9d,
+    0x96,
+    0x50,
+    0x58,
+    0x9a,
+    0xea,
+    0x54,
+    0xf3,
+    0xee,
+    0xf5,
+    0x63,
+    0x14,
+    0xee,
+    0x85,
+    0x83,
+    0x74,
+    0x76,
+    0xe1,
+    0x52,
+    0x95,
+    0xc3,
+    0xf7,
+    0xeb,
+    0x04,
+    0x04,
+    0x7b,
+    0xa7,
+    0x28,
+    0x1b,
+    0xcc,
+    0xea,
+    0x4a,
+    0x4e,
+    0x84,
+    0xda,
+    0xd8,
+    0x9c,
+    0x79,
+    0xd8,
+    0x9b,
+    0x66,
+    0x89,
+    0x2f,
+    0xcf,
+    0xac,
+    0xd7,
+    0x79,
+    0xf9,
+    0xa9,
+    0xd8,
+    0x45,
+    0x13,
+    0x78,
+    0xb9,
+    0x00,
+    0x14,
+    0xc9,
+    0x7e,
+    0x22,
+    0x51,
+    0x86,
+    0x67,
+    0xb0,
+    0x9f,
+    0x26,
+    0x11,
+    0x23,
+    0xc8,
+    0x38,
+    0xd7,
+    0x70,
+    0x1d,
+    0x15,
+    0x8e,
+    0x4d,
+    0x4f,
+    0x95,
+    0x97,
+    0x40,
+    0xa1,
+    0xc2,
+    0x7e,
+    0x01,
+    0x18,
+    0x72,
+    0xf4,
+    0x10,
+    0xe6,
+    0x8d,
+    0x52,
+    0x16,
+    0x7f,
+    0xf2,
+    0xc9,
+    0xf8,
+    0x33,
+    0x8b,
+    0x33,
+    0xb7,
+    0xce,
 };
 
 static unsigned char dsa2048_p[] = {
-    0xA0, 0x25, 0xFA, 0xAD, 0xF4, 0x8E, 0xB9, 0xE5, 0x99, 0xF3,
-    0x5D, 0x6F, 0x4F, 0x83, 0x34, 0xE2, 0x7E, 0xCF, 0x6F, 0xBF,
-    0x30, 0xAF, 0x6F, 0x81, 0xEB, 0xF8, 0xC4, 0x13, 0xD9, 0xA0,
-    0x5D, 0x8B, 0x5C, 0x8E, 0xDC, 0xC2, 0x1D, 0x0B, 0x41, 0x32,
-    0xB0, 0x1F, 0xFE, 0xEF, 0x0C, 0xC2, 0xA2, 0x7E, 0x68, 0x5C,
-    0x28, 0x21, 0xE9, 0xF5, 0xB1, 0x58, 0x12, 0x63, 0x4C, 0x19,
-    0x4E, 0xFF, 0x02, 0x4B, 0x92, 0xED, 0xD2, 0x07, 0x11, 0x4D,
-    0x8C, 0x58, 0x16, 0x5C, 0x55, 0x8E, 0xAD, 0xA3, 0x67, 0x7D,
-    0xB9, 0x86, 0x6E, 0x0B, 0xE6, 0x54, 0x6F, 0x40, 0xAE, 0x0E,
-    0x67, 0x4C, 0xF9, 0x12, 0x5B, 0x3C, 0x08, 0x7A, 0xF7, 0xFC,
-    0x67, 0x86, 0x69, 0xE7, 0x0A, 0x94, 0x40, 0xBF, 0x8B, 0x76,
-    0xFE, 0x26, 0xD1, 0xF2, 0xA1, 0x1A, 0x84, 0xA1, 0x43, 0x56,
-    0x28, 0xBC, 0x9A, 0x5F, 0xD7, 0x3B, 0x69, 0x89, 0x8A, 0x36,
-    0x2C, 0x51, 0xDF, 0x12, 0x77, 0x2F, 0x57, 0x7B, 0xA0, 0xAA,
-    0xDD, 0x7F, 0xA1, 0x62, 0x3B, 0x40, 0x7B, 0x68, 0x1A, 0x8F,
-    0x0D, 0x38, 0xBB, 0x21, 0x5D, 0x18, 0xFC, 0x0F, 0x46, 0xF7,
-    0xA3, 0xB0, 0x1D, 0x23, 0xC3, 0xD2, 0xC7, 0x72, 0x51, 0x18,
-    0xDF, 0x46, 0x95, 0x79, 0xD9, 0xBD, 0xB5, 0x19, 0x02, 0x2C,
-    0x87, 0xDC, 0xE7, 0x57, 0x82, 0x7E, 0xF1, 0x8B, 0x06, 0x3D,
-    0x00, 0xA5, 0x7B, 0x6B, 0x26, 0x27, 0x91, 0x0F, 0x6A, 0x77,
-    0xE4, 0xD5, 0x04, 0xE4, 0x12, 0x2C, 0x42, 0xFF, 0xD2, 0x88,
-    0xBB, 0xD3, 0x92, 0xA0, 0xF9, 0xC8, 0x51, 0x64, 0x14, 0x5C,
-    0xD8, 0xF9, 0x6C, 0x47, 0x82, 0xB4, 0x1C, 0x7F, 0x09, 0xB8,
-    0xF0, 0x25, 0x83, 0x1D, 0x3F, 0x3F, 0x05, 0xB3, 0x21, 0x0A,
-    0x5D, 0xA7, 0xD8, 0x54, 0xC3, 0x65, 0x7D, 0xC3, 0xB0, 0x1D,
-    0xBF, 0xAE, 0xF8, 0x68, 0xCF, 0x9B
+    0xA0,
+    0x25,
+    0xFA,
+    0xAD,
+    0xF4,
+    0x8E,
+    0xB9,
+    0xE5,
+    0x99,
+    0xF3,
+    0x5D,
+    0x6F,
+    0x4F,
+    0x83,
+    0x34,
+    0xE2,
+    0x7E,
+    0xCF,
+    0x6F,
+    0xBF,
+    0x30,
+    0xAF,
+    0x6F,
+    0x81,
+    0xEB,
+    0xF8,
+    0xC4,
+    0x13,
+    0xD9,
+    0xA0,
+    0x5D,
+    0x8B,
+    0x5C,
+    0x8E,
+    0xDC,
+    0xC2,
+    0x1D,
+    0x0B,
+    0x41,
+    0x32,
+    0xB0,
+    0x1F,
+    0xFE,
+    0xEF,
+    0x0C,
+    0xC2,
+    0xA2,
+    0x7E,
+    0x68,
+    0x5C,
+    0x28,
+    0x21,
+    0xE9,
+    0xF5,
+    0xB1,
+    0x58,
+    0x12,
+    0x63,
+    0x4C,
+    0x19,
+    0x4E,
+    0xFF,
+    0x02,
+    0x4B,
+    0x92,
+    0xED,
+    0xD2,
+    0x07,
+    0x11,
+    0x4D,
+    0x8C,
+    0x58,
+    0x16,
+    0x5C,
+    0x55,
+    0x8E,
+    0xAD,
+    0xA3,
+    0x67,
+    0x7D,
+    0xB9,
+    0x86,
+    0x6E,
+    0x0B,
+    0xE6,
+    0x54,
+    0x6F,
+    0x40,
+    0xAE,
+    0x0E,
+    0x67,
+    0x4C,
+    0xF9,
+    0x12,
+    0x5B,
+    0x3C,
+    0x08,
+    0x7A,
+    0xF7,
+    0xFC,
+    0x67,
+    0x86,
+    0x69,
+    0xE7,
+    0x0A,
+    0x94,
+    0x40,
+    0xBF,
+    0x8B,
+    0x76,
+    0xFE,
+    0x26,
+    0xD1,
+    0xF2,
+    0xA1,
+    0x1A,
+    0x84,
+    0xA1,
+    0x43,
+    0x56,
+    0x28,
+    0xBC,
+    0x9A,
+    0x5F,
+    0xD7,
+    0x3B,
+    0x69,
+    0x89,
+    0x8A,
+    0x36,
+    0x2C,
+    0x51,
+    0xDF,
+    0x12,
+    0x77,
+    0x2F,
+    0x57,
+    0x7B,
+    0xA0,
+    0xAA,
+    0xDD,
+    0x7F,
+    0xA1,
+    0x62,
+    0x3B,
+    0x40,
+    0x7B,
+    0x68,
+    0x1A,
+    0x8F,
+    0x0D,
+    0x38,
+    0xBB,
+    0x21,
+    0x5D,
+    0x18,
+    0xFC,
+    0x0F,
+    0x46,
+    0xF7,
+    0xA3,
+    0xB0,
+    0x1D,
+    0x23,
+    0xC3,
+    0xD2,
+    0xC7,
+    0x72,
+    0x51,
+    0x18,
+    0xDF,
+    0x46,
+    0x95,
+    0x79,
+    0xD9,
+    0xBD,
+    0xB5,
+    0x19,
+    0x02,
+    0x2C,
+    0x87,
+    0xDC,
+    0xE7,
+    0x57,
+    0x82,
+    0x7E,
+    0xF1,
+    0x8B,
+    0x06,
+    0x3D,
+    0x00,
+    0xA5,
+    0x7B,
+    0x6B,
+    0x26,
+    0x27,
+    0x91,
+    0x0F,
+    0x6A,
+    0x77,
+    0xE4,
+    0xD5,
+    0x04,
+    0xE4,
+    0x12,
+    0x2C,
+    0x42,
+    0xFF,
+    0xD2,
+    0x88,
+    0xBB,
+    0xD3,
+    0x92,
+    0xA0,
+    0xF9,
+    0xC8,
+    0x51,
+    0x64,
+    0x14,
+    0x5C,
+    0xD8,
+    0xF9,
+    0x6C,
+    0x47,
+    0x82,
+    0xB4,
+    0x1C,
+    0x7F,
+    0x09,
+    0xB8,
+    0xF0,
+    0x25,
+    0x83,
+    0x1D,
+    0x3F,
+    0x3F,
+    0x05,
+    0xB3,
+    0x21,
+    0x0A,
+    0x5D,
+    0xA7,
+    0xD8,
+    0x54,
+    0xC3,
+    0x65,
+    0x7D,
+    0xC3,
+    0xB0,
+    0x1D,
+    0xBF,
+    0xAE,
+    0xF8,
+    0x68,
+    0xCF,
+    0x9B,
 };
 
 static unsigned char dsa2048_q[] = {
-    0x97, 0xE7, 0x33, 0x4D, 0xD3, 0x94, 0x3E, 0x0B, 0xDB, 0x62,
-    0x74, 0xC6, 0xA1, 0x08, 0xDD, 0x19, 0xA3, 0x75, 0x17, 0x1B
+    0x97,
+    0xE7,
+    0x33,
+    0x4D,
+    0xD3,
+    0x94,
+    0x3E,
+    0x0B,
+    0xDB,
+    0x62,
+    0x74,
+    0xC6,
+    0xA1,
+    0x08,
+    0xDD,
+    0x19,
+    0xA3,
+    0x75,
+    0x17,
+    0x1B,
 };
 
 static unsigned char dsa2048_g[] = {
-    0x2C, 0x78, 0x16, 0x59, 0x34, 0x63, 0xF4, 0xF3, 0x92, 0xFC,
-    0xB5, 0xA5, 0x4F, 0x13, 0xDE, 0x2F, 0x1C, 0xA4, 0x3C, 0xAE,
-    0xAD, 0x38, 0x3F, 0x7E, 0x90, 0xBF, 0x96, 0xA6, 0xAE, 0x25,
-    0x90, 0x72, 0xF5, 0x8E, 0x80, 0x0C, 0x39, 0x1C, 0xD9, 0xEC,
-    0xBA, 0x90, 0x5B, 0x3A, 0xE8, 0x58, 0x6C, 0x9E, 0x30, 0x42,
-    0x37, 0x02, 0x31, 0x82, 0xBC, 0x6A, 0xDF, 0x6A, 0x09, 0x29,
-    0xE3, 0xC0, 0x46, 0xD1, 0xCB, 0x85, 0xEC, 0x0C, 0x30, 0x5E,
-    0xEA, 0xC8, 0x39, 0x8E, 0x22, 0x9F, 0x22, 0x10, 0xD2, 0x34,
-    0x61, 0x68, 0x37, 0x3D, 0x2E, 0x4A, 0x5B, 0x9A, 0xF5, 0xC1,
-    0x48, 0xC6, 0xF6, 0xDC, 0x63, 0x1A, 0xD3, 0x96, 0x64, 0xBA,
-    0x34, 0xC9, 0xD1, 0xA0, 0xD1, 0xAE, 0x6C, 0x2F, 0x48, 0x17,
-    0x93, 0x14, 0x43, 0xED, 0xF0, 0x21, 0x30, 0x19, 0xC3, 0x1B,
-    0x5F, 0xDE, 0xA3, 0xF0, 0x70, 0x78, 0x18, 0xE1, 0xA8, 0xE4,
-    0xEE, 0x2E, 0x00, 0xA5, 0xE4, 0xB3, 0x17, 0xC8, 0x0C, 0x7D,
-    0x6E, 0x42, 0xDC, 0xB7, 0x46, 0x00, 0x36, 0x4D, 0xD4, 0x46,
-    0xAA, 0x3D, 0x3C, 0x46, 0x89, 0x40, 0xBF, 0x1D, 0x84, 0x77,
-    0x0A, 0x75, 0xF3, 0x87, 0x1D, 0x08, 0x4C, 0xA6, 0xD1, 0xA9,
-    0x1C, 0x1E, 0x12, 0x1E, 0xE1, 0xC7, 0x30, 0x28, 0x76, 0xA5,
-    0x7F, 0x6C, 0x85, 0x96, 0x2B, 0x6F, 0xDB, 0x80, 0x66, 0x26,
-    0xAE, 0xF5, 0x93, 0xC7, 0x8E, 0xAE, 0x9A, 0xED, 0xE4, 0xCA,
-    0x04, 0xEA, 0x3B, 0x72, 0xEF, 0xDC, 0x87, 0xED, 0x0D, 0xA5,
-    0x4C, 0x4A, 0xDD, 0x71, 0x22, 0x64, 0x59, 0x69, 0x4E, 0x8E,
-    0xBF, 0x43, 0xDC, 0xAB, 0x8E, 0x66, 0xBB, 0x01, 0xB6, 0xF4,
-    0xE7, 0xFD, 0xD2, 0xAD, 0x9F, 0x36, 0xC1, 0xA0, 0x29, 0x99,
-    0xD1, 0x96, 0x70, 0x59, 0x06, 0x78, 0x35, 0xBD, 0x65, 0x55,
-    0x52, 0x9E, 0xF8, 0xB2, 0xE5, 0x38
+    0x2C,
+    0x78,
+    0x16,
+    0x59,
+    0x34,
+    0x63,
+    0xF4,
+    0xF3,
+    0x92,
+    0xFC,
+    0xB5,
+    0xA5,
+    0x4F,
+    0x13,
+    0xDE,
+    0x2F,
+    0x1C,
+    0xA4,
+    0x3C,
+    0xAE,
+    0xAD,
+    0x38,
+    0x3F,
+    0x7E,
+    0x90,
+    0xBF,
+    0x96,
+    0xA6,
+    0xAE,
+    0x25,
+    0x90,
+    0x72,
+    0xF5,
+    0x8E,
+    0x80,
+    0x0C,
+    0x39,
+    0x1C,
+    0xD9,
+    0xEC,
+    0xBA,
+    0x90,
+    0x5B,
+    0x3A,
+    0xE8,
+    0x58,
+    0x6C,
+    0x9E,
+    0x30,
+    0x42,
+    0x37,
+    0x02,
+    0x31,
+    0x82,
+    0xBC,
+    0x6A,
+    0xDF,
+    0x6A,
+    0x09,
+    0x29,
+    0xE3,
+    0xC0,
+    0x46,
+    0xD1,
+    0xCB,
+    0x85,
+    0xEC,
+    0x0C,
+    0x30,
+    0x5E,
+    0xEA,
+    0xC8,
+    0x39,
+    0x8E,
+    0x22,
+    0x9F,
+    0x22,
+    0x10,
+    0xD2,
+    0x34,
+    0x61,
+    0x68,
+    0x37,
+    0x3D,
+    0x2E,
+    0x4A,
+    0x5B,
+    0x9A,
+    0xF5,
+    0xC1,
+    0x48,
+    0xC6,
+    0xF6,
+    0xDC,
+    0x63,
+    0x1A,
+    0xD3,
+    0x96,
+    0x64,
+    0xBA,
+    0x34,
+    0xC9,
+    0xD1,
+    0xA0,
+    0xD1,
+    0xAE,
+    0x6C,
+    0x2F,
+    0x48,
+    0x17,
+    0x93,
+    0x14,
+    0x43,
+    0xED,
+    0xF0,
+    0x21,
+    0x30,
+    0x19,
+    0xC3,
+    0x1B,
+    0x5F,
+    0xDE,
+    0xA3,
+    0xF0,
+    0x70,
+    0x78,
+    0x18,
+    0xE1,
+    0xA8,
+    0xE4,
+    0xEE,
+    0x2E,
+    0x00,
+    0xA5,
+    0xE4,
+    0xB3,
+    0x17,
+    0xC8,
+    0x0C,
+    0x7D,
+    0x6E,
+    0x42,
+    0xDC,
+    0xB7,
+    0x46,
+    0x00,
+    0x36,
+    0x4D,
+    0xD4,
+    0x46,
+    0xAA,
+    0x3D,
+    0x3C,
+    0x46,
+    0x89,
+    0x40,
+    0xBF,
+    0x1D,
+    0x84,
+    0x77,
+    0x0A,
+    0x75,
+    0xF3,
+    0x87,
+    0x1D,
+    0x08,
+    0x4C,
+    0xA6,
+    0xD1,
+    0xA9,
+    0x1C,
+    0x1E,
+    0x12,
+    0x1E,
+    0xE1,
+    0xC7,
+    0x30,
+    0x28,
+    0x76,
+    0xA5,
+    0x7F,
+    0x6C,
+    0x85,
+    0x96,
+    0x2B,
+    0x6F,
+    0xDB,
+    0x80,
+    0x66,
+    0x26,
+    0xAE,
+    0xF5,
+    0x93,
+    0xC7,
+    0x8E,
+    0xAE,
+    0x9A,
+    0xED,
+    0xE4,
+    0xCA,
+    0x04,
+    0xEA,
+    0x3B,
+    0x72,
+    0xEF,
+    0xDC,
+    0x87,
+    0xED,
+    0x0D,
+    0xA5,
+    0x4C,
+    0x4A,
+    0xDD,
+    0x71,
+    0x22,
+    0x64,
+    0x59,
+    0x69,
+    0x4E,
+    0x8E,
+    0xBF,
+    0x43,
+    0xDC,
+    0xAB,
+    0x8E,
+    0x66,
+    0xBB,
+    0x01,
+    0xB6,
+    0xF4,
+    0xE7,
+    0xFD,
+    0xD2,
+    0xAD,
+    0x9F,
+    0x36,
+    0xC1,
+    0xA0,
+    0x29,
+    0x99,
+    0xD1,
+    0x96,
+    0x70,
+    0x59,
+    0x06,
+    0x78,
+    0x35,
+    0xBD,
+    0x65,
+    0x55,
+    0x52,
+    0x9E,
+    0xF8,
+    0xB2,
+    0xE5,
+    0x38,
 };
 
 typedef struct testdsa_st {
@@ -303,5 +1497,3 @@ err:
     EVP_PKEY_CTX_free(pctx);
     return pkey;
 }
-
-#endif /* !defined(OSSL_APPS_TESTDSA_H) */
diff --git a/apps/testrsa.h b/apps/testrsa.h
index 0a9d5dda37..db9221e8aa 100644
--- a/apps/testrsa.h
+++ b/apps/testrsa.h
@@ -7,229 +7,2130 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_APPS_TESTRSA_H)
-#define OSSL_APPS_TESTRSA_H
-
 static unsigned char test512[] = {
-    0x30, 0x82, 0x01, 0x3a, 0x02, 0x01, 0x00, 0x02, 0x41, 0x00,
-    0xd6, 0x33, 0xb9, 0xc8, 0xfb, 0x4f, 0x3c, 0x7d, 0xc0, 0x01,
-    0x86, 0xd0, 0xe7, 0xa0, 0x55, 0xf2, 0x95, 0x93, 0xcc, 0x4f,
-    0xb7, 0x5b, 0x67, 0x5b, 0x94, 0x68, 0xc9, 0x34, 0x15, 0xde,
-    0xa5, 0x2e, 0x1c, 0x33, 0xc2, 0x6e, 0xfc, 0x34, 0x5e, 0x71,
-    0x13, 0xb7, 0xd6, 0xee, 0xd8, 0xa5, 0x65, 0x05, 0x72, 0x87,
-    0xa8, 0xb0, 0x77, 0xfe, 0x57, 0xf5, 0xfc, 0x5f, 0x55, 0x83,
-    0x87, 0xdd, 0x57, 0x49, 0x02, 0x03, 0x01, 0x00, 0x01, 0x02,
-    0x41, 0x00, 0xa7, 0xf7, 0x91, 0xc5, 0x0f, 0x84, 0x57, 0xdc,
-    0x07, 0xf7, 0x6a, 0x7f, 0x60, 0x52, 0xb3, 0x72, 0xf1, 0x66,
-    0x1f, 0x7d, 0x97, 0x3b, 0x9e, 0xb6, 0x0a, 0x8f, 0x8c, 0xcf,
-    0x42, 0x23, 0x00, 0x04, 0xd4, 0x28, 0x0e, 0x1c, 0x90, 0xc4,
-    0x11, 0x25, 0x25, 0xa5, 0x93, 0xa5, 0x2f, 0x70, 0x02, 0xdf,
-    0x81, 0x9c, 0x49, 0x03, 0xa0, 0xf8, 0x6d, 0x54, 0x2e, 0x26,
-    0xde, 0xaa, 0x85, 0x59, 0xa8, 0x31, 0x02, 0x21, 0x00, 0xeb,
-    0x47, 0xd7, 0x3b, 0xf6, 0xc3, 0xdd, 0x5a, 0x46, 0xc5, 0xb9,
-    0x2b, 0x9a, 0xa0, 0x09, 0x8f, 0xa6, 0xfb, 0xf3, 0x78, 0x7a,
-    0x33, 0x70, 0x9d, 0x0f, 0x42, 0x6b, 0x13, 0x68, 0x24, 0xd3,
-    0x15, 0x02, 0x21, 0x00, 0xe9, 0x10, 0xb0, 0xb3, 0x0d, 0xe2,
-    0x82, 0x68, 0x77, 0x8a, 0x6e, 0x7c, 0xda, 0xbc, 0x3e, 0x53,
-    0x83, 0xfb, 0xd6, 0x22, 0xe7, 0xb5, 0xae, 0x6e, 0x80, 0xda,
-    0x00, 0x55, 0x97, 0xc1, 0xd0, 0x65, 0x02, 0x20, 0x4c, 0xf8,
-    0x73, 0xb1, 0x6a, 0x49, 0x29, 0x61, 0x1f, 0x46, 0x10, 0x0d,
-    0xf3, 0xc7, 0xe7, 0x58, 0xd7, 0x88, 0x15, 0x5e, 0x94, 0x9b,
-    0xbf, 0x7b, 0xa2, 0x42, 0x58, 0x45, 0x41, 0x0c, 0xcb, 0x01,
-    0x02, 0x20, 0x12, 0x11, 0xba, 0x31, 0x57, 0x9d, 0x3d, 0x11,
-    0x0e, 0x5b, 0x8c, 0x2f, 0x5f, 0xe2, 0x02, 0x4f, 0x05, 0x47,
-    0x8c, 0x15, 0x8e, 0xb3, 0x56, 0x3f, 0xb8, 0xfb, 0xad, 0xd4,
-    0xf4, 0xfc, 0x10, 0xc5, 0x02, 0x20, 0x18, 0xa1, 0x29, 0x99,
-    0x5b, 0xd9, 0xc8, 0xd4, 0xfc, 0x49, 0x7a, 0x2a, 0x21, 0x2c,
-    0x49, 0xe4, 0x4f, 0xeb, 0xef, 0x51, 0xf1, 0xab, 0x6d, 0xfb,
-    0x4b, 0x14, 0xe9, 0x4b, 0x52, 0xb5, 0x82, 0x2c
+    0x30,
+    0x82,
+    0x01,
+    0x3a,
+    0x02,
+    0x01,
+    0x00,
+    0x02,
+    0x41,
+    0x00,
+    0xd6,
+    0x33,
+    0xb9,
+    0xc8,
+    0xfb,
+    0x4f,
+    0x3c,
+    0x7d,
+    0xc0,
+    0x01,
+    0x86,
+    0xd0,
+    0xe7,
+    0xa0,
+    0x55,
+    0xf2,
+    0x95,
+    0x93,
+    0xcc,
+    0x4f,
+    0xb7,
+    0x5b,
+    0x67,
+    0x5b,
+    0x94,
+    0x68,
+    0xc9,
+    0x34,
+    0x15,
+    0xde,
+    0xa5,
+    0x2e,
+    0x1c,
+    0x33,
+    0xc2,
+    0x6e,
+    0xfc,
+    0x34,
+    0x5e,
+    0x71,
+    0x13,
+    0xb7,
+    0xd6,
+    0xee,
+    0xd8,
+    0xa5,
+    0x65,
+    0x05,
+    0x72,
+    0x87,
+    0xa8,
+    0xb0,
+    0x77,
+    0xfe,
+    0x57,
+    0xf5,
+    0xfc,
+    0x5f,
+    0x55,
+    0x83,
+    0x87,
+    0xdd,
+    0x57,
+    0x49,
+    0x02,
+    0x03,
+    0x01,
+    0x00,
+    0x01,
+    0x02,
+    0x41,
+    0x00,
+    0xa7,
+    0xf7,
+    0x91,
+    0xc5,
+    0x0f,
+    0x84,
+    0x57,
+    0xdc,
+    0x07,
+    0xf7,
+    0x6a,
+    0x7f,
+    0x60,
+    0x52,
+    0xb3,
+    0x72,
+    0xf1,
+    0x66,
+    0x1f,
+    0x7d,
+    0x97,
+    0x3b,
+    0x9e,
+    0xb6,
+    0x0a,
+    0x8f,
+    0x8c,
+    0xcf,
+    0x42,
+    0x23,
+    0x00,
+    0x04,
+    0xd4,
+    0x28,
+    0x0e,
+    0x1c,
+    0x90,
+    0xc4,
+    0x11,
+    0x25,
+    0x25,
+    0xa5,
+    0x93,
+    0xa5,
+    0x2f,
+    0x70,
+    0x02,
+    0xdf,
+    0x81,
+    0x9c,
+    0x49,
+    0x03,
+    0xa0,
+    0xf8,
+    0x6d,
+    0x54,
+    0x2e,
+    0x26,
+    0xde,
+    0xaa,
+    0x85,
+    0x59,
+    0xa8,
+    0x31,
+    0x02,
+    0x21,
+    0x00,
+    0xeb,
+    0x47,
+    0xd7,
+    0x3b,
+    0xf6,
+    0xc3,
+    0xdd,
+    0x5a,
+    0x46,
+    0xc5,
+    0xb9,
+    0x2b,
+    0x9a,
+    0xa0,
+    0x09,
+    0x8f,
+    0xa6,
+    0xfb,
+    0xf3,
+    0x78,
+    0x7a,
+    0x33,
+    0x70,
+    0x9d,
+    0x0f,
+    0x42,
+    0x6b,
+    0x13,
+    0x68,
+    0x24,
+    0xd3,
+    0x15,
+    0x02,
+    0x21,
+    0x00,
+    0xe9,
+    0x10,
+    0xb0,
+    0xb3,
+    0x0d,
+    0xe2,
+    0x82,
+    0x68,
+    0x77,
+    0x8a,
+    0x6e,
+    0x7c,
+    0xda,
+    0xbc,
+    0x3e,
+    0x53,
+    0x83,
+    0xfb,
+    0xd6,
+    0x22,
+    0xe7,
+    0xb5,
+    0xae,
+    0x6e,
+    0x80,
+    0xda,
+    0x00,
+    0x55,
+    0x97,
+    0xc1,
+    0xd0,
+    0x65,
+    0x02,
+    0x20,
+    0x4c,
+    0xf8,
+    0x73,
+    0xb1,
+    0x6a,
+    0x49,
+    0x29,
+    0x61,
+    0x1f,
+    0x46,
+    0x10,
+    0x0d,
+    0xf3,
+    0xc7,
+    0xe7,
+    0x58,
+    0xd7,
+    0x88,
+    0x15,
+    0x5e,
+    0x94,
+    0x9b,
+    0xbf,
+    0x7b,
+    0xa2,
+    0x42,
+    0x58,
+    0x45,
+    0x41,
+    0x0c,
+    0xcb,
+    0x01,
+    0x02,
+    0x20,
+    0x12,
+    0x11,
+    0xba,
+    0x31,
+    0x57,
+    0x9d,
+    0x3d,
+    0x11,
+    0x0e,
+    0x5b,
+    0x8c,
+    0x2f,
+    0x5f,
+    0xe2,
+    0x02,
+    0x4f,
+    0x05,
+    0x47,
+    0x8c,
+    0x15,
+    0x8e,
+    0xb3,
+    0x56,
+    0x3f,
+    0xb8,
+    0xfb,
+    0xad,
+    0xd4,
+    0xf4,
+    0xfc,
+    0x10,
+    0xc5,
+    0x02,
+    0x20,
+    0x18,
+    0xa1,
+    0x29,
+    0x99,
+    0x5b,
+    0xd9,
+    0xc8,
+    0xd4,
+    0xfc,
+    0x49,
+    0x7a,
+    0x2a,
+    0x21,
+    0x2c,
+    0x49,
+    0xe4,
+    0x4f,
+    0xeb,
+    0xef,
+    0x51,
+    0xf1,
+    0xab,
+    0x6d,
+    0xfb,
+    0x4b,
+    0x14,
+    0xe9,
+    0x4b,
+    0x52,
+    0xb5,
+    0x82,
+    0x2c,
 };
 
 static unsigned char test1024[] = {
-    0x30, 0x82, 0x02, 0x5c, 0x02, 0x01, 0x00, 0x02, 0x81, 0x81,
-    0x00, 0xdc, 0x98, 0x43, 0xe8, 0x3d, 0x43, 0x5b, 0xe4, 0x05,
-    0xcd, 0xd0, 0xa9, 0x3e, 0xcb, 0x83, 0x75, 0xf6, 0xb5, 0xa5,
-    0x9f, 0x6b, 0xe9, 0x34, 0x41, 0x29, 0x18, 0xfa, 0x6a, 0x55,
-    0x4d, 0x70, 0xfc, 0xec, 0xae, 0x87, 0x38, 0x0a, 0x20, 0xa9,
-    0xc0, 0x45, 0x77, 0x6e, 0x57, 0x60, 0x57, 0xf4, 0xed, 0x96,
-    0x22, 0xcb, 0x8f, 0xe1, 0x33, 0x3a, 0x17, 0x1f, 0xed, 0x37,
-    0xa5, 0x6f, 0xeb, 0xa6, 0xbc, 0x12, 0x80, 0x1d, 0x53, 0xbd,
-    0x70, 0xeb, 0x21, 0x76, 0x3e, 0xc9, 0x2f, 0x1a, 0x45, 0x24,
-    0x82, 0xff, 0xcd, 0x59, 0x32, 0x06, 0x2e, 0x12, 0x3b, 0x23,
-    0x78, 0xed, 0x12, 0x3d, 0xe0, 0x8d, 0xf9, 0x67, 0x4f, 0x37,
-    0x4e, 0x47, 0x02, 0x4c, 0x2d, 0xc0, 0x4f, 0x1f, 0xb3, 0x94,
-    0xe1, 0x41, 0x2e, 0x2d, 0x90, 0x10, 0xfc, 0x82, 0x91, 0x8b,
-    0x0f, 0x22, 0xd4, 0xf2, 0xfc, 0x2c, 0xab, 0x53, 0x55, 0x02,
-    0x03, 0x01, 0x00, 0x01, 0x02, 0x81, 0x80, 0x2b, 0xcc, 0x3f,
-    0x8f, 0x58, 0xba, 0x8b, 0x00, 0x16, 0xf6, 0xea, 0x3a, 0xf0,
-    0x30, 0xd0, 0x05, 0x17, 0xda, 0xb0, 0xeb, 0x9a, 0x2d, 0x4f,
-    0x26, 0xb0, 0xd6, 0x38, 0xc1, 0xeb, 0xf5, 0xd8, 0x3d, 0x1f,
-    0x70, 0xf7, 0x7f, 0xf4, 0xe2, 0xcf, 0x51, 0x51, 0x79, 0x88,
-    0xfa, 0xe8, 0x32, 0x0e, 0x7b, 0x2d, 0x97, 0xf2, 0xfa, 0xba,
-    0x27, 0xc5, 0x9c, 0xd9, 0xc5, 0xeb, 0x8a, 0x79, 0x52, 0x3c,
-    0x64, 0x34, 0x7d, 0xc2, 0xcf, 0x28, 0xc7, 0x4e, 0xd5, 0x43,
-    0x0b, 0xd1, 0xa6, 0xca, 0x6d, 0x03, 0x2d, 0x72, 0x23, 0xbc,
-    0x6d, 0x05, 0xfa, 0x16, 0x09, 0x2f, 0x2e, 0x5c, 0xb6, 0xee,
-    0x74, 0xdd, 0xd2, 0x48, 0x8e, 0x36, 0x0c, 0x06, 0x3d, 0x4d,
-    0xe5, 0x10, 0x82, 0xeb, 0x6a, 0xf3, 0x4b, 0x9f, 0xd6, 0xed,
-    0x11, 0xb1, 0x6e, 0xec, 0xf4, 0xfe, 0x8e, 0x75, 0x94, 0x20,
-    0x2f, 0xcb, 0xac, 0x46, 0xf1, 0x02, 0x41, 0x00, 0xf9, 0x8c,
-    0xa3, 0x85, 0xb1, 0xdd, 0x29, 0xaf, 0x65, 0xc1, 0x33, 0xf3,
-    0x95, 0xc5, 0x52, 0x68, 0x0b, 0xd4, 0xf1, 0xe5, 0x0e, 0x02,
-    0x9f, 0x4f, 0xfa, 0x77, 0xdc, 0x46, 0x9e, 0xc7, 0xa6, 0xe4,
-    0x16, 0x29, 0xda, 0xb0, 0x07, 0xcf, 0x5b, 0xa9, 0x12, 0x8a,
-    0xdd, 0x63, 0x0a, 0xde, 0x2e, 0x8c, 0x66, 0x8b, 0x8c, 0xdc,
-    0x19, 0xa3, 0x7e, 0xf4, 0x3b, 0xd0, 0x1a, 0x8c, 0xa4, 0xc2,
-    0xe1, 0xd3, 0x02, 0x41, 0x00, 0xe2, 0x4c, 0x05, 0xf2, 0x04,
-    0x86, 0x4e, 0x61, 0x43, 0xdb, 0xb0, 0xb9, 0x96, 0x86, 0x52,
-    0x2c, 0xca, 0x8d, 0x7b, 0xab, 0x0b, 0x13, 0x0d, 0x7e, 0x38,
-    0x5b, 0xe2, 0x2e, 0x7b, 0x0e, 0xe7, 0x19, 0x99, 0x38, 0xe7,
-    0xf2, 0x21, 0xbd, 0x85, 0x85, 0xe3, 0xfd, 0x28, 0x77, 0x20,
-    0x31, 0x71, 0x2c, 0xd0, 0xff, 0xfb, 0x2e, 0xaf, 0x85, 0xb4,
-    0x86, 0xca, 0xf3, 0xbb, 0xca, 0xaa, 0x0f, 0x95, 0x37, 0x02,
-    0x40, 0x0e, 0x41, 0x9a, 0x95, 0xe8, 0xb3, 0x59, 0xce, 0x4b,
-    0x61, 0xde, 0x35, 0xec, 0x38, 0x79, 0x9c, 0xb8, 0x10, 0x52,
-    0x41, 0x63, 0xab, 0x82, 0xae, 0x6f, 0x00, 0xa9, 0xf4, 0xde,
-    0xdd, 0x49, 0x0b, 0x7e, 0xb8, 0xa5, 0x65, 0xa9, 0x0c, 0x8f,
-    0x8f, 0xf9, 0x1f, 0x35, 0xc6, 0x92, 0xb8, 0x5e, 0xb0, 0x66,
-    0xab, 0x52, 0x40, 0xc0, 0xb6, 0x36, 0x6a, 0x7d, 0x80, 0x46,
-    0x04, 0x02, 0xe5, 0x9f, 0x41, 0x02, 0x41, 0x00, 0xc0, 0xad,
-    0xcc, 0x4e, 0x21, 0xee, 0x1d, 0x24, 0x91, 0xfb, 0xa7, 0x80,
-    0x8d, 0x9a, 0xb6, 0xb3, 0x2e, 0x8f, 0xc2, 0xe1, 0x82, 0xdf,
-    0x69, 0x18, 0xb4, 0x71, 0xff, 0xa6, 0x65, 0xde, 0xed, 0x84,
-    0x8d, 0x42, 0xb7, 0xb3, 0x21, 0x69, 0x56, 0x1c, 0x07, 0x60,
-    0x51, 0x29, 0x04, 0xff, 0x34, 0x06, 0xdd, 0xb9, 0x67, 0x2c,
-    0x7c, 0x04, 0x93, 0x0e, 0x46, 0x15, 0xbb, 0x2a, 0xb7, 0x1b,
-    0xe7, 0x87, 0x02, 0x40, 0x78, 0xda, 0x5d, 0x07, 0x51, 0x0c,
-    0x16, 0x7a, 0x9f, 0x29, 0x20, 0x84, 0x0d, 0x42, 0xfa, 0xd7,
-    0x00, 0xd8, 0x77, 0x7e, 0xb0, 0xb0, 0x6b, 0xd6, 0x5b, 0x53,
-    0xb8, 0x9b, 0x7a, 0xcd, 0xc7, 0x2b, 0xb8, 0x6a, 0x63, 0xa9,
-    0xfb, 0x6f, 0xa4, 0x72, 0xbf, 0x4c, 0x5d, 0x00, 0x14, 0xba,
-    0xfa, 0x59, 0x88, 0xed, 0xe4, 0xe0, 0x8c, 0xa2, 0xec, 0x14,
-    0x7e, 0x2d, 0xe2, 0xf0, 0x46, 0x49, 0x95, 0x45
+    0x30,
+    0x82,
+    0x02,
+    0x5c,
+    0x02,
+    0x01,
+    0x00,
+    0x02,
+    0x81,
+    0x81,
+    0x00,
+    0xdc,
+    0x98,
+    0x43,
+    0xe8,
+    0x3d,
+    0x43,
+    0x5b,
+    0xe4,
+    0x05,
+    0xcd,
+    0xd0,
+    0xa9,
+    0x3e,
+    0xcb,
+    0x83,
+    0x75,
+    0xf6,
+    0xb5,
+    0xa5,
+    0x9f,
+    0x6b,
+    0xe9,
+    0x34,
+    0x41,
+    0x29,
+    0x18,
+    0xfa,
+    0x6a,
+    0x55,
+    0x4d,
+    0x70,
+    0xfc,
+    0xec,
+    0xae,
+    0x87,
+    0x38,
+    0x0a,
+    0x20,
+    0xa9,
+    0xc0,
+    0x45,
+    0x77,
+    0x6e,
+    0x57,
+    0x60,
+    0x57,
+    0xf4,
+    0xed,
+    0x96,
+    0x22,
+    0xcb,
+    0x8f,
+    0xe1,
+    0x33,
+    0x3a,
+    0x17,
+    0x1f,
+    0xed,
+    0x37,
+    0xa5,
+    0x6f,
+    0xeb,
+    0xa6,
+    0xbc,
+    0x12,
+    0x80,
+    0x1d,
+    0x53,
+    0xbd,
+    0x70,
+    0xeb,
+    0x21,
+    0x76,
+    0x3e,
+    0xc9,
+    0x2f,
+    0x1a,
+    0x45,
+    0x24,
+    0x82,
+    0xff,
+    0xcd,
+    0x59,
+    0x32,
+    0x06,
+    0x2e,
+    0x12,
+    0x3b,
+    0x23,
+    0x78,
+    0xed,
+    0x12,
+    0x3d,
+    0xe0,
+    0x8d,
+    0xf9,
+    0x67,
+    0x4f,
+    0x37,
+    0x4e,
+    0x47,
+    0x02,
+    0x4c,
+    0x2d,
+    0xc0,
+    0x4f,
+    0x1f,
+    0xb3,
+    0x94,
+    0xe1,
+    0x41,
+    0x2e,
+    0x2d,
+    0x90,
+    0x10,
+    0xfc,
+    0x82,
+    0x91,
+    0x8b,
+    0x0f,
+    0x22,
+    0xd4,
+    0xf2,
+    0xfc,
+    0x2c,
+    0xab,
+    0x53,
+    0x55,
+    0x02,
+    0x03,
+    0x01,
+    0x00,
+    0x01,
+    0x02,
+    0x81,
+    0x80,
+    0x2b,
+    0xcc,
+    0x3f,
+    0x8f,
+    0x58,
+    0xba,
+    0x8b,
+    0x00,
+    0x16,
+    0xf6,
+    0xea,
+    0x3a,
+    0xf0,
+    0x30,
+    0xd0,
+    0x05,
+    0x17,
+    0xda,
+    0xb0,
+    0xeb,
+    0x9a,
+    0x2d,
+    0x4f,
+    0x26,
+    0xb0,
+    0xd6,
+    0x38,
+    0xc1,
+    0xeb,
+    0xf5,
+    0xd8,
+    0x3d,
+    0x1f,
+    0x70,
+    0xf7,
+    0x7f,
+    0xf4,
+    0xe2,
+    0xcf,
+    0x51,
+    0x51,
+    0x79,
+    0x88,
+    0xfa,
+    0xe8,
+    0x32,
+    0x0e,
+    0x7b,
+    0x2d,
+    0x97,
+    0xf2,
+    0xfa,
+    0xba,
+    0x27,
+    0xc5,
+    0x9c,
+    0xd9,
+    0xc5,
+    0xeb,
+    0x8a,
+    0x79,
+    0x52,
+    0x3c,
+    0x64,
+    0x34,
+    0x7d,
+    0xc2,
+    0xcf,
+    0x28,
+    0xc7,
+    0x4e,
+    0xd5,
+    0x43,
+    0x0b,
+    0xd1,
+    0xa6,
+    0xca,
+    0x6d,
+    0x03,
+    0x2d,
+    0x72,
+    0x23,
+    0xbc,
+    0x6d,
+    0x05,
+    0xfa,
+    0x16,
+    0x09,
+    0x2f,
+    0x2e,
+    0x5c,
+    0xb6,
+    0xee,
+    0x74,
+    0xdd,
+    0xd2,
+    0x48,
+    0x8e,
+    0x36,
+    0x0c,
+    0x06,
+    0x3d,
+    0x4d,
+    0xe5,
+    0x10,
+    0x82,
+    0xeb,
+    0x6a,
+    0xf3,
+    0x4b,
+    0x9f,
+    0xd6,
+    0xed,
+    0x11,
+    0xb1,
+    0x6e,
+    0xec,
+    0xf4,
+    0xfe,
+    0x8e,
+    0x75,
+    0x94,
+    0x20,
+    0x2f,
+    0xcb,
+    0xac,
+    0x46,
+    0xf1,
+    0x02,
+    0x41,
+    0x00,
+    0xf9,
+    0x8c,
+    0xa3,
+    0x85,
+    0xb1,
+    0xdd,
+    0x29,
+    0xaf,
+    0x65,
+    0xc1,
+    0x33,
+    0xf3,
+    0x95,
+    0xc5,
+    0x52,
+    0x68,
+    0x0b,
+    0xd4,
+    0xf1,
+    0xe5,
+    0x0e,
+    0x02,
+    0x9f,
+    0x4f,
+    0xfa,
+    0x77,
+    0xdc,
+    0x46,
+    0x9e,
+    0xc7,
+    0xa6,
+    0xe4,
+    0x16,
+    0x29,
+    0xda,
+    0xb0,
+    0x07,
+    0xcf,
+    0x5b,
+    0xa9,
+    0x12,
+    0x8a,
+    0xdd,
+    0x63,
+    0x0a,
+    0xde,
+    0x2e,
+    0x8c,
+    0x66,
+    0x8b,
+    0x8c,
+    0xdc,
+    0x19,
+    0xa3,
+    0x7e,
+    0xf4,
+    0x3b,
+    0xd0,
+    0x1a,
+    0x8c,
+    0xa4,
+    0xc2,
+    0xe1,
+    0xd3,
+    0x02,
+    0x41,
+    0x00,
+    0xe2,
+    0x4c,
+    0x05,
+    0xf2,
+    0x04,
+    0x86,
+    0x4e,
+    0x61,
+    0x43,
+    0xdb,
+    0xb0,
+    0xb9,
+    0x96,
+    0x86,
+    0x52,
+    0x2c,
+    0xca,
+    0x8d,
+    0x7b,
+    0xab,
+    0x0b,
+    0x13,
+    0x0d,
+    0x7e,
+    0x38,
+    0x5b,
+    0xe2,
+    0x2e,
+    0x7b,
+    0x0e,
+    0xe7,
+    0x19,
+    0x99,
+    0x38,
+    0xe7,
+    0xf2,
+    0x21,
+    0xbd,
+    0x85,
+    0x85,
+    0xe3,
+    0xfd,
+    0x28,
+    0x77,
+    0x20,
+    0x31,
+    0x71,
+    0x2c,
+    0xd0,
+    0xff,
+    0xfb,
+    0x2e,
+    0xaf,
+    0x85,
+    0xb4,
+    0x86,
+    0xca,
+    0xf3,
+    0xbb,
+    0xca,
+    0xaa,
+    0x0f,
+    0x95,
+    0x37,
+    0x02,
+    0x40,
+    0x0e,
+    0x41,
+    0x9a,
+    0x95,
+    0xe8,
+    0xb3,
+    0x59,
+    0xce,
+    0x4b,
+    0x61,
+    0xde,
+    0x35,
+    0xec,
+    0x38,
+    0x79,
+    0x9c,
+    0xb8,
+    0x10,
+    0x52,
+    0x41,
+    0x63,
+    0xab,
+    0x82,
+    0xae,
+    0x6f,
+    0x00,
+    0xa9,
+    0xf4,
+    0xde,
+    0xdd,
+    0x49,
+    0x0b,
+    0x7e,
+    0xb8,
+    0xa5,
+    0x65,
+    0xa9,
+    0x0c,
+    0x8f,
+    0x8f,
+    0xf9,
+    0x1f,
+    0x35,
+    0xc6,
+    0x92,
+    0xb8,
+    0x5e,
+    0xb0,
+    0x66,
+    0xab,
+    0x52,
+    0x40,
+    0xc0,
+    0xb6,
+    0x36,
+    0x6a,
+    0x7d,
+    0x80,
+    0x46,
+    0x04,
+    0x02,
+    0xe5,
+    0x9f,
+    0x41,
+    0x02,
+    0x41,
+    0x00,
+    0xc0,
+    0xad,
+    0xcc,
+    0x4e,
+    0x21,
+    0xee,
+    0x1d,
+    0x24,
+    0x91,
+    0xfb,
+    0xa7,
+    0x80,
+    0x8d,
+    0x9a,
+    0xb6,
+    0xb3,
+    0x2e,
+    0x8f,
+    0xc2,
+    0xe1,
+    0x82,
+    0xdf,
+    0x69,
+    0x18,
+    0xb4,
+    0x71,
+    0xff,
+    0xa6,
+    0x65,
+    0xde,
+    0xed,
+    0x84,
+    0x8d,
+    0x42,
+    0xb7,
+    0xb3,
+    0x21,
+    0x69,
+    0x56,
+    0x1c,
+    0x07,
+    0x60,
+    0x51,
+    0x29,
+    0x04,
+    0xff,
+    0x34,
+    0x06,
+    0xdd,
+    0xb9,
+    0x67,
+    0x2c,
+    0x7c,
+    0x04,
+    0x93,
+    0x0e,
+    0x46,
+    0x15,
+    0xbb,
+    0x2a,
+    0xb7,
+    0x1b,
+    0xe7,
+    0x87,
+    0x02,
+    0x40,
+    0x78,
+    0xda,
+    0x5d,
+    0x07,
+    0x51,
+    0x0c,
+    0x16,
+    0x7a,
+    0x9f,
+    0x29,
+    0x20,
+    0x84,
+    0x0d,
+    0x42,
+    0xfa,
+    0xd7,
+    0x00,
+    0xd8,
+    0x77,
+    0x7e,
+    0xb0,
+    0xb0,
+    0x6b,
+    0xd6,
+    0x5b,
+    0x53,
+    0xb8,
+    0x9b,
+    0x7a,
+    0xcd,
+    0xc7,
+    0x2b,
+    0xb8,
+    0x6a,
+    0x63,
+    0xa9,
+    0xfb,
+    0x6f,
+    0xa4,
+    0x72,
+    0xbf,
+    0x4c,
+    0x5d,
+    0x00,
+    0x14,
+    0xba,
+    0xfa,
+    0x59,
+    0x88,
+    0xed,
+    0xe4,
+    0xe0,
+    0x8c,
+    0xa2,
+    0xec,
+    0x14,
+    0x7e,
+    0x2d,
+    0xe2,
+    0xf0,
+    0x46,
+    0x49,
+    0x95,
+    0x45,
 };
 
 static unsigned char test2048[] = {
-    0x30, 0x82, 0x04, 0xa3, 0x02, 0x01, 0x00, 0x02, 0x82, 0x01,
-    0x01, 0x00, 0xc0, 0xc0, 0xce, 0x3e, 0x3c, 0x53, 0x67, 0x3f,
-    0x4f, 0xc5, 0x2f, 0xa4, 0xc2, 0x5a, 0x2f, 0x58, 0xfd, 0x27,
-    0x52, 0x6a, 0xe8, 0xcf, 0x4a, 0x73, 0x47, 0x8d, 0x25, 0x0f,
-    0x5f, 0x03, 0x26, 0x78, 0xef, 0xf0, 0x22, 0x12, 0xd3, 0xde,
-    0x47, 0xb2, 0x1c, 0x0b, 0x38, 0x63, 0x1a, 0x6c, 0x85, 0x7a,
-    0x80, 0xc6, 0x8f, 0xa0, 0x41, 0xaf, 0x62, 0xc4, 0x67, 0x32,
-    0x88, 0xf8, 0xa6, 0x9c, 0xf5, 0x23, 0x1d, 0xe4, 0xac, 0x3f,
-    0x29, 0xf9, 0xec, 0xe1, 0x8b, 0x26, 0x03, 0x2c, 0xb2, 0xab,
-    0xf3, 0x7d, 0xb5, 0xca, 0x49, 0xc0, 0x8f, 0x1c, 0xdf, 0x33,
-    0x3a, 0x60, 0xda, 0x3c, 0xb0, 0x16, 0xf8, 0xa9, 0x12, 0x8f,
-    0x64, 0xac, 0x23, 0x0c, 0x69, 0x64, 0x97, 0x5d, 0x99, 0xd4,
-    0x09, 0x83, 0x9b, 0x61, 0xd3, 0xac, 0xf0, 0xde, 0xdd, 0x5e,
-    0x9f, 0x44, 0x94, 0xdb, 0x3a, 0x4d, 0x97, 0xe8, 0x52, 0x29,
-    0xf7, 0xdb, 0x94, 0x07, 0x45, 0x90, 0x78, 0x1e, 0x31, 0x0b,
-    0x80, 0xf7, 0x57, 0xad, 0x1c, 0x79, 0xc5, 0xcb, 0x32, 0xb0,
-    0xce, 0xcd, 0x74, 0xb3, 0xe2, 0x94, 0xc5, 0x78, 0x2f, 0x34,
-    0x1a, 0x45, 0xf7, 0x8c, 0x52, 0xa5, 0xbc, 0x8d, 0xec, 0xd1,
-    0x2f, 0x31, 0x3b, 0xf0, 0x49, 0x59, 0x5e, 0x88, 0x9d, 0x15,
-    0x92, 0x35, 0x32, 0xc1, 0xe7, 0x61, 0xec, 0x50, 0x48, 0x7c,
-    0xba, 0x05, 0xf9, 0xf8, 0xf8, 0xa7, 0x8c, 0x83, 0xe8, 0x66,
-    0x5b, 0xeb, 0xfe, 0xd8, 0x4f, 0xdd, 0x6d, 0x36, 0xc0, 0xb2,
-    0x90, 0x0f, 0xb8, 0x52, 0xf9, 0x04, 0x9b, 0x40, 0x2c, 0x27,
-    0xd6, 0x36, 0x8e, 0xc2, 0x1b, 0x44, 0xf3, 0x92, 0xd5, 0x15,
-    0x9e, 0x9a, 0xbc, 0xf3, 0x7d, 0x03, 0xd7, 0x02, 0x14, 0x20,
-    0xe9, 0x10, 0x92, 0xfd, 0xf9, 0xfc, 0x8f, 0xe5, 0x18, 0xe1,
-    0x95, 0xcc, 0x9e, 0x60, 0xa6, 0xfa, 0x38, 0x4d, 0x02, 0x03,
-    0x01, 0x00, 0x01, 0x02, 0x82, 0x01, 0x00, 0x00, 0xc3, 0xc3,
-    0x0d, 0xb4, 0x27, 0x90, 0x8d, 0x4b, 0xbf, 0xb8, 0x84, 0xaa,
-    0xd0, 0xb8, 0xc7, 0x5d, 0x99, 0xbe, 0x55, 0xf6, 0x3e, 0x7c,
-    0x49, 0x20, 0xcb, 0x8a, 0x8e, 0x19, 0x0e, 0x66, 0x24, 0xac,
-    0xaf, 0x03, 0x33, 0x97, 0xeb, 0x95, 0xd5, 0x3b, 0x0f, 0x40,
-    0x56, 0x04, 0x50, 0xd1, 0xe6, 0xbe, 0x84, 0x0b, 0x25, 0xd3,
-    0x9c, 0xe2, 0x83, 0x6c, 0xf5, 0x62, 0x5d, 0xba, 0x2b, 0x7d,
-    0x3d, 0x7a, 0x6c, 0xe1, 0xd2, 0x0e, 0x54, 0x93, 0x80, 0x01,
-    0x91, 0x51, 0x09, 0xe8, 0x5b, 0x8e, 0x47, 0xbd, 0x64, 0xe4,
-    0x0e, 0x03, 0x83, 0x55, 0xcf, 0x5a, 0x37, 0xf0, 0x25, 0xb5,
-    0x7d, 0x21, 0xd7, 0x69, 0xdf, 0x6f, 0xc2, 0xcf, 0x10, 0xc9,
-    0x8a, 0x40, 0x9f, 0x7a, 0x70, 0xc0, 0xe8, 0xe8, 0xc0, 0xe6,
-    0x9a, 0x15, 0x0a, 0x8d, 0x4e, 0x46, 0xcb, 0x7a, 0xdb, 0xb3,
-    0xcb, 0x83, 0x02, 0xc4, 0xf0, 0xab, 0xeb, 0x02, 0x01, 0x0e,
-    0x23, 0xfc, 0x1d, 0xc4, 0xbd, 0xd4, 0xaa, 0x5d, 0x31, 0x46,
-    0x99, 0xce, 0x9e, 0xf8, 0x04, 0x75, 0x10, 0x67, 0xc4, 0x53,
-    0x47, 0x44, 0xfa, 0xc2, 0x25, 0x73, 0x7e, 0xd0, 0x8e, 0x59,
-    0xd1, 0xb2, 0x5a, 0xf4, 0xc7, 0x18, 0x92, 0x2f, 0x39, 0xab,
-    0xcd, 0xa3, 0xb5, 0xc2, 0xb9, 0xc7, 0xb9, 0x1b, 0x9f, 0x48,
-    0xfa, 0x13, 0xc6, 0x98, 0x4d, 0xca, 0x84, 0x9c, 0x06, 0xca,
-    0xe7, 0x89, 0x01, 0x04, 0xc4, 0x6c, 0xfd, 0x29, 0x59, 0x35,
-    0xe7, 0xf3, 0xdd, 0xce, 0x64, 0x59, 0xbf, 0x21, 0x13, 0xa9,
-    0x9f, 0x0e, 0xc5, 0xff, 0xbd, 0x33, 0x00, 0xec, 0xac, 0x6b,
-    0x11, 0xef, 0x51, 0x5e, 0xad, 0x07, 0x15, 0xde, 0xb8, 0x5f,
-    0xc6, 0xb9, 0xa3, 0x22, 0x65, 0x46, 0x83, 0x14, 0xdf, 0xd0,
-    0xf1, 0x44, 0x8a, 0xe1, 0x9c, 0x23, 0x33, 0xb4, 0x97, 0x33,
-    0xe6, 0x6b, 0x81, 0x02, 0x81, 0x81, 0x00, 0xec, 0x12, 0xa7,
-    0x59, 0x74, 0x6a, 0xde, 0x3e, 0xad, 0xd8, 0x36, 0x80, 0x50,
-    0xa2, 0xd5, 0x21, 0x81, 0x07, 0xf1, 0xd0, 0x91, 0xf2, 0x6c,
-    0x12, 0x2f, 0x9d, 0x1a, 0x26, 0xf8, 0x30, 0x65, 0xdf, 0xe8,
-    0xc0, 0x9b, 0x6a, 0x30, 0x98, 0x82, 0x87, 0xec, 0xa2, 0x56,
-    0x87, 0x62, 0x6f, 0xe7, 0x9f, 0xf6, 0x56, 0xe6, 0x71, 0x8f,
-    0x49, 0x86, 0x93, 0x5a, 0x4d, 0x34, 0x58, 0xfe, 0xd9, 0x04,
-    0x13, 0xaf, 0x79, 0xb7, 0xad, 0x11, 0xd1, 0x30, 0x9a, 0x14,
-    0x06, 0xa0, 0xfa, 0xb7, 0x55, 0xdc, 0x6c, 0x5a, 0x4c, 0x2c,
-    0x59, 0x56, 0xf6, 0xe8, 0x9d, 0xaf, 0x0a, 0x78, 0x99, 0x06,
-    0x06, 0x9e, 0xe7, 0x9c, 0x51, 0x55, 0x43, 0xfc, 0x3b, 0x6c,
-    0x0b, 0xbf, 0x2d, 0x41, 0xa7, 0xaf, 0xb7, 0xe0, 0xe8, 0x28,
-    0x18, 0xb4, 0x13, 0xd1, 0xe6, 0x97, 0xd0, 0x9f, 0x6a, 0x80,
-    0xca, 0xdd, 0x1a, 0x7e, 0x15, 0x02, 0x81, 0x81, 0x00, 0xd1,
-    0x06, 0x0c, 0x1f, 0xe3, 0xd0, 0xab, 0xd6, 0xca, 0x7c, 0xbc,
-    0x7d, 0x13, 0x35, 0xce, 0x27, 0xcd, 0xd8, 0x49, 0x51, 0x63,
-    0x64, 0x0f, 0xca, 0x06, 0x12, 0xfc, 0x07, 0x3e, 0xaf, 0x61,
-    0x6d, 0xe2, 0x53, 0x39, 0x27, 0xae, 0xc3, 0x11, 0x9e, 0x94,
-    0x01, 0x4f, 0xe3, 0xf3, 0x67, 0xf9, 0x77, 0xf9, 0xe7, 0x95,
-    0x3a, 0x6f, 0xe2, 0x20, 0x73, 0x3e, 0xa4, 0x7a, 0x28, 0xd4,
-    0x61, 0x97, 0xf6, 0x17, 0xa0, 0x23, 0x10, 0x2b, 0xce, 0x84,
-    0x57, 0x7e, 0x25, 0x1f, 0xf4, 0xa8, 0x54, 0xd2, 0x65, 0x94,
-    0xcc, 0x95, 0x0a, 0xab, 0x30, 0xc1, 0x59, 0x1f, 0x61, 0x8e,
-    0xb9, 0x6b, 0xd7, 0x4e, 0xb9, 0x83, 0x43, 0x79, 0x85, 0x11,
-    0xbc, 0x0f, 0xae, 0x25, 0x20, 0x05, 0xbc, 0xd2, 0x48, 0xa1,
-    0x68, 0x09, 0x84, 0xf6, 0x12, 0x9a, 0x66, 0xb9, 0x2b, 0xbb,
-    0x76, 0x03, 0x17, 0x46, 0x4e, 0x97, 0x59, 0x02, 0x81, 0x80,
-    0x09, 0x4c, 0xfa, 0xd6, 0xe5, 0x65, 0x48, 0x78, 0x43, 0xb5,
-    0x1f, 0x00, 0x93, 0x2c, 0xb7, 0x24, 0xe8, 0xc6, 0x7d, 0x5a,
-    0x70, 0x45, 0x92, 0xc8, 0x6c, 0xa3, 0xcd, 0xe1, 0xf7, 0x29,
-    0x40, 0xfa, 0x3f, 0x5b, 0x47, 0x44, 0x39, 0xc1, 0xe8, 0x72,
-    0x9e, 0x7a, 0x0e, 0xda, 0xaa, 0xa0, 0x2a, 0x09, 0xfd, 0x54,
-    0x93, 0x23, 0xaa, 0x37, 0x85, 0x5b, 0xcc, 0xd4, 0xf9, 0xd8,
-    0xff, 0xc1, 0x61, 0x0d, 0xbd, 0x7e, 0x18, 0x24, 0x73, 0x6d,
-    0x40, 0x72, 0xf1, 0x93, 0x09, 0x48, 0x97, 0x6c, 0x84, 0x90,
-    0xa8, 0x46, 0x14, 0x01, 0x39, 0x11, 0xe5, 0x3c, 0x41, 0x27,
-    0x32, 0x75, 0x24, 0xed, 0xa1, 0xd9, 0x12, 0x29, 0x8a, 0x28,
-    0x71, 0x89, 0x8d, 0xca, 0x30, 0xb0, 0x01, 0xc4, 0x2f, 0x82,
-    0x19, 0x14, 0x4c, 0x70, 0x1c, 0xb8, 0x23, 0x2e, 0xe8, 0x90,
-    0x49, 0x97, 0x92, 0x97, 0x6b, 0x7a, 0x9d, 0xb9, 0x02, 0x81,
-    0x80, 0x0f, 0x0e, 0xa1, 0x76, 0xf6, 0xa1, 0x44, 0x8f, 0xaf,
-    0x7c, 0x76, 0xd3, 0x87, 0xbb, 0xbb, 0x83, 0x10, 0x88, 0x01,
-    0x18, 0x14, 0xd1, 0xd3, 0x75, 0x59, 0x24, 0xaa, 0xf5, 0x16,
-    0xa5, 0xe9, 0x9d, 0xd1, 0xcc, 0xee, 0xf4, 0x15, 0xd9, 0xc5,
-    0x7e, 0x27, 0xe9, 0x44, 0x49, 0x06, 0x72, 0xb9, 0xfc, 0xd3,
-    0x8a, 0xc4, 0x2c, 0x36, 0x7d, 0x12, 0x9b, 0x5a, 0xaa, 0xdc,
-    0x85, 0xee, 0x6e, 0xad, 0x54, 0xb3, 0xf4, 0xfc, 0x31, 0xa1,
-    0x06, 0x3a, 0x70, 0x57, 0x0c, 0xf3, 0x95, 0x5b, 0x3e, 0xe8,
-    0xfd, 0x1a, 0x4f, 0xf6, 0x78, 0x93, 0x46, 0x6a, 0xd7, 0x31,
-    0xb4, 0x84, 0x64, 0x85, 0x09, 0x38, 0x89, 0x92, 0x94, 0x1c,
-    0xbf, 0xe2, 0x3c, 0x2a, 0xe0, 0xff, 0x99, 0xa3, 0xf0, 0x2b,
-    0x31, 0xc2, 0x36, 0xcd, 0x60, 0xbf, 0x9d, 0x2d, 0x74, 0x32,
-    0xe8, 0x9c, 0x93, 0x6e, 0xbb, 0x91, 0x7b, 0xfd, 0xd9, 0x02,
-    0x81, 0x81, 0x00, 0xa2, 0x71, 0x25, 0x38, 0xeb, 0x2a, 0xe9,
-    0x37, 0xcd, 0xfe, 0x44, 0xce, 0x90, 0x3f, 0x52, 0x87, 0x84,
-    0x52, 0x1b, 0xae, 0x8d, 0x22, 0x94, 0xce, 0x38, 0xe6, 0x04,
-    0x88, 0x76, 0x85, 0x9a, 0xd3, 0x14, 0x09, 0xe5, 0x69, 0x9a,
-    0xff, 0x58, 0x92, 0x02, 0x6a, 0x7d, 0x7c, 0x1e, 0x2c, 0xfd,
-    0xa8, 0xca, 0x32, 0x14, 0x4f, 0x0d, 0x84, 0x0d, 0x37, 0x43,
-    0xbf, 0xe4, 0x5d, 0x12, 0xc8, 0x24, 0x91, 0x27, 0x8d, 0x46,
-    0xd9, 0x54, 0x53, 0xe7, 0x62, 0x71, 0xa8, 0x2b, 0x71, 0x41,
-    0x8d, 0x75, 0xf8, 0x3a, 0xa0, 0x61, 0x29, 0x46, 0xa6, 0xe5,
-    0x82, 0xfa, 0x3a, 0xd9, 0x08, 0xfa, 0xfc, 0x63, 0xfd, 0x6b,
-    0x30, 0xbc, 0xf4, 0x4e, 0x9e, 0x8c, 0x25, 0x0c, 0xb6, 0x55,
-    0xe7, 0x3c, 0xd4, 0x4e, 0x0b, 0xfd, 0x8b, 0xc3, 0x0e, 0x1d,
-    0x9c, 0x44, 0x57, 0x8f, 0x1f, 0x86, 0xf7, 0xd5, 0x1b, 0xe4,
-    0x95
+    0x30,
+    0x82,
+    0x04,
+    0xa3,
+    0x02,
+    0x01,
+    0x00,
+    0x02,
+    0x82,
+    0x01,
+    0x01,
+    0x00,
+    0xc0,
+    0xc0,
+    0xce,
+    0x3e,
+    0x3c,
+    0x53,
+    0x67,
+    0x3f,
+    0x4f,
+    0xc5,
+    0x2f,
+    0xa4,
+    0xc2,
+    0x5a,
+    0x2f,
+    0x58,
+    0xfd,
+    0x27,
+    0x52,
+    0x6a,
+    0xe8,
+    0xcf,
+    0x4a,
+    0x73,
+    0x47,
+    0x8d,
+    0x25,
+    0x0f,
+    0x5f,
+    0x03,
+    0x26,
+    0x78,
+    0xef,
+    0xf0,
+    0x22,
+    0x12,
+    0xd3,
+    0xde,
+    0x47,
+    0xb2,
+    0x1c,
+    0x0b,
+    0x38,
+    0x63,
+    0x1a,
+    0x6c,
+    0x85,
+    0x7a,
+    0x80,
+    0xc6,
+    0x8f,
+    0xa0,
+    0x41,
+    0xaf,
+    0x62,
+    0xc4,
+    0x67,
+    0x32,
+    0x88,
+    0xf8,
+    0xa6,
+    0x9c,
+    0xf5,
+    0x23,
+    0x1d,
+    0xe4,
+    0xac,
+    0x3f,
+    0x29,
+    0xf9,
+    0xec,
+    0xe1,
+    0x8b,
+    0x26,
+    0x03,
+    0x2c,
+    0xb2,
+    0xab,
+    0xf3,
+    0x7d,
+    0xb5,
+    0xca,
+    0x49,
+    0xc0,
+    0x8f,
+    0x1c,
+    0xdf,
+    0x33,
+    0x3a,
+    0x60,
+    0xda,
+    0x3c,
+    0xb0,
+    0x16,
+    0xf8,
+    0xa9,
+    0x12,
+    0x8f,
+    0x64,
+    0xac,
+    0x23,
+    0x0c,
+    0x69,
+    0x64,
+    0x97,
+    0x5d,
+    0x99,
+    0xd4,
+    0x09,
+    0x83,
+    0x9b,
+    0x61,
+    0xd3,
+    0xac,
+    0xf0,
+    0xde,
+    0xdd,
+    0x5e,
+    0x9f,
+    0x44,
+    0x94,
+    0xdb,
+    0x3a,
+    0x4d,
+    0x97,
+    0xe8,
+    0x52,
+    0x29,
+    0xf7,
+    0xdb,
+    0x94,
+    0x07,
+    0x45,
+    0x90,
+    0x78,
+    0x1e,
+    0x31,
+    0x0b,
+    0x80,
+    0xf7,
+    0x57,
+    0xad,
+    0x1c,
+    0x79,
+    0xc5,
+    0xcb,
+    0x32,
+    0xb0,
+    0xce,
+    0xcd,
+    0x74,
+    0xb3,
+    0xe2,
+    0x94,
+    0xc5,
+    0x78,
+    0x2f,
+    0x34,
+    0x1a,
+    0x45,
+    0xf7,
+    0x8c,
+    0x52,
+    0xa5,
+    0xbc,
+    0x8d,
+    0xec,
+    0xd1,
+    0x2f,
+    0x31,
+    0x3b,
+    0xf0,
+    0x49,
+    0x59,
+    0x5e,
+    0x88,
+    0x9d,
+    0x15,
+    0x92,
+    0x35,
+    0x32,
+    0xc1,
+    0xe7,
+    0x61,
+    0xec,
+    0x50,
+    0x48,
+    0x7c,
+    0xba,
+    0x05,
+    0xf9,
+    0xf8,
+    0xf8,
+    0xa7,
+    0x8c,
+    0x83,
+    0xe8,
+    0x66,
+    0x5b,
+    0xeb,
+    0xfe,
+    0xd8,
+    0x4f,
+    0xdd,
+    0x6d,
+    0x36,
+    0xc0,
+    0xb2,
+    0x90,
+    0x0f,
+    0xb8,
+    0x52,
+    0xf9,
+    0x04,
+    0x9b,
+    0x40,
+    0x2c,
+    0x27,
+    0xd6,
+    0x36,
+    0x8e,
+    0xc2,
+    0x1b,
+    0x44,
+    0xf3,
+    0x92,
+    0xd5,
+    0x15,
+    0x9e,
+    0x9a,
+    0xbc,
+    0xf3,
+    0x7d,
+    0x03,
+    0xd7,
+    0x02,
+    0x14,
+    0x20,
+    0xe9,
+    0x10,
+    0x92,
+    0xfd,
+    0xf9,
+    0xfc,
+    0x8f,
+    0xe5,
+    0x18,
+    0xe1,
+    0x95,
+    0xcc,
+    0x9e,
+    0x60,
+    0xa6,
+    0xfa,
+    0x38,
+    0x4d,
+    0x02,
+    0x03,
+    0x01,
+    0x00,
+    0x01,
+    0x02,
+    0x82,
+    0x01,
+    0x00,
+    0x00,
+    0xc3,
+    0xc3,
+    0x0d,
+    0xb4,
+    0x27,
+    0x90,
+    0x8d,
+    0x4b,
+    0xbf,
+    0xb8,
+    0x84,
+    0xaa,
+    0xd0,
+    0xb8,
+    0xc7,
+    0x5d,
+    0x99,
+    0xbe,
+    0x55,
+    0xf6,
+    0x3e,
+    0x7c,
+    0x49,
+    0x20,
+    0xcb,
+    0x8a,
+    0x8e,
+    0x19,
+    0x0e,
+    0x66,
+    0x24,
+    0xac,
+    0xaf,
+    0x03,
+    0x33,
+    0x97,
+    0xeb,
+    0x95,
+    0xd5,
+    0x3b,
+    0x0f,
+    0x40,
+    0x56,
+    0x04,
+    0x50,
+    0xd1,
+    0xe6,
+    0xbe,
+    0x84,
+    0x0b,
+    0x25,
+    0xd3,
+    0x9c,
+    0xe2,
+    0x83,
+    0x6c,
+    0xf5,
+    0x62,
+    0x5d,
+    0xba,
+    0x2b,
+    0x7d,
+    0x3d,
+    0x7a,
+    0x6c,
+    0xe1,
+    0xd2,
+    0x0e,
+    0x54,
+    0x93,
+    0x80,
+    0x01,
+    0x91,
+    0x51,
+    0x09,
+    0xe8,
+    0x5b,
+    0x8e,
+    0x47,
+    0xbd,
+    0x64,
+    0xe4,
+    0x0e,
+    0x03,
+    0x83,
+    0x55,
+    0xcf,
+    0x5a,
+    0x37,
+    0xf0,
+    0x25,
+    0xb5,
+    0x7d,
+    0x21,
+    0xd7,
+    0x69,
+    0xdf,
+    0x6f,
+    0xc2,
+    0xcf,
+    0x10,
+    0xc9,
+    0x8a,
+    0x40,
+    0x9f,
+    0x7a,
+    0x70,
+    0xc0,
+    0xe8,
+    0xe8,
+    0xc0,
+    0xe6,
+    0x9a,
+    0x15,
+    0x0a,
+    0x8d,
+    0x4e,
+    0x46,
+    0xcb,
+    0x7a,
+    0xdb,
+    0xb3,
+    0xcb,
+    0x83,
+    0x02,
+    0xc4,
+    0xf0,
+    0xab,
+    0xeb,
+    0x02,
+    0x01,
+    0x0e,
+    0x23,
+    0xfc,
+    0x1d,
+    0xc4,
+    0xbd,
+    0xd4,
+    0xaa,
+    0x5d,
+    0x31,
+    0x46,
+    0x99,
+    0xce,
+    0x9e,
+    0xf8,
+    0x04,
+    0x75,
+    0x10,
+    0x67,
+    0xc4,
+    0x53,
+    0x47,
+    0x44,
+    0xfa,
+    0xc2,
+    0x25,
+    0x73,
+    0x7e,
+    0xd0,
+    0x8e,
+    0x59,
+    0xd1,
+    0xb2,
+    0x5a,
+    0xf4,
+    0xc7,
+    0x18,
+    0x92,
+    0x2f,
+    0x39,
+    0xab,
+    0xcd,
+    0xa3,
+    0xb5,
+    0xc2,
+    0xb9,
+    0xc7,
+    0xb9,
+    0x1b,
+    0x9f,
+    0x48,
+    0xfa,
+    0x13,
+    0xc6,
+    0x98,
+    0x4d,
+    0xca,
+    0x84,
+    0x9c,
+    0x06,
+    0xca,
+    0xe7,
+    0x89,
+    0x01,
+    0x04,
+    0xc4,
+    0x6c,
+    0xfd,
+    0x29,
+    0x59,
+    0x35,
+    0xe7,
+    0xf3,
+    0xdd,
+    0xce,
+    0x64,
+    0x59,
+    0xbf,
+    0x21,
+    0x13,
+    0xa9,
+    0x9f,
+    0x0e,
+    0xc5,
+    0xff,
+    0xbd,
+    0x33,
+    0x00,
+    0xec,
+    0xac,
+    0x6b,
+    0x11,
+    0xef,
+    0x51,
+    0x5e,
+    0xad,
+    0x07,
+    0x15,
+    0xde,
+    0xb8,
+    0x5f,
+    0xc6,
+    0xb9,
+    0xa3,
+    0x22,
+    0x65,
+    0x46,
+    0x83,
+    0x14,
+    0xdf,
+    0xd0,
+    0xf1,
+    0x44,
+    0x8a,
+    0xe1,
+    0x9c,
+    0x23,
+    0x33,
+    0xb4,
+    0x97,
+    0x33,
+    0xe6,
+    0x6b,
+    0x81,
+    0x02,
+    0x81,
+    0x81,
+    0x00,
+    0xec,
+    0x12,
+    0xa7,
+    0x59,
+    0x74,
+    0x6a,
+    0xde,
+    0x3e,
+    0xad,
+    0xd8,
+    0x36,
+    0x80,
+    0x50,
+    0xa2,
+    0xd5,
+    0x21,
+    0x81,
+    0x07,
+    0xf1,
+    0xd0,
+    0x91,
+    0xf2,
+    0x6c,
+    0x12,
+    0x2f,
+    0x9d,
+    0x1a,
+    0x26,
+    0xf8,
+    0x30,
+    0x65,
+    0xdf,
+    0xe8,
+    0xc0,
+    0x9b,
+    0x6a,
+    0x30,
+    0x98,
+    0x82,
+    0x87,
+    0xec,
+    0xa2,
+    0x56,
+    0x87,
+    0x62,
+    0x6f,
+    0xe7,
+    0x9f,
+    0xf6,
+    0x56,
+    0xe6,
+    0x71,
+    0x8f,
+    0x49,
+    0x86,
+    0x93,
+    0x5a,
+    0x4d,
+    0x34,
+    0x58,
+    0xfe,
+    0xd9,
+    0x04,
+    0x13,
+    0xaf,
+    0x79,
+    0xb7,
+    0xad,
+    0x11,
+    0xd1,
+    0x30,
+    0x9a,
+    0x14,
+    0x06,
+    0xa0,
+    0xfa,
+    0xb7,
+    0x55,
+    0xdc,
+    0x6c,
+    0x5a,
+    0x4c,
+    0x2c,
+    0x59,
+    0x56,
+    0xf6,
+    0xe8,
+    0x9d,
+    0xaf,
+    0x0a,
+    0x78,
+    0x99,
+    0x06,
+    0x06,
+    0x9e,
+    0xe7,
+    0x9c,
+    0x51,
+    0x55,
+    0x43,
+    0xfc,
+    0x3b,
+    0x6c,
+    0x0b,
+    0xbf,
+    0x2d,
+    0x41,
+    0xa7,
+    0xaf,
+    0xb7,
+    0xe0,
+    0xe8,
+    0x28,
+    0x18,
+    0xb4,
+    0x13,
+    0xd1,
+    0xe6,
+    0x97,
+    0xd0,
+    0x9f,
+    0x6a,
+    0x80,
+    0xca,
+    0xdd,
+    0x1a,
+    0x7e,
+    0x15,
+    0x02,
+    0x81,
+    0x81,
+    0x00,
+    0xd1,
+    0x06,
+    0x0c,
+    0x1f,
+    0xe3,
+    0xd0,
+    0xab,
+    0xd6,
+    0xca,
+    0x7c,
+    0xbc,
+    0x7d,
+    0x13,
+    0x35,
+    0xce,
+    0x27,
+    0xcd,
+    0xd8,
+    0x49,
+    0x51,
+    0x63,
+    0x64,
+    0x0f,
+    0xca,
+    0x06,
+    0x12,
+    0xfc,
+    0x07,
+    0x3e,
+    0xaf,
+    0x61,
+    0x6d,
+    0xe2,
+    0x53,
+    0x39,
+    0x27,
+    0xae,
+    0xc3,
+    0x11,
+    0x9e,
+    0x94,
+    0x01,
+    0x4f,
+    0xe3,
+    0xf3,
+    0x67,
+    0xf9,
+    0x77,
+    0xf9,
+    0xe7,
+    0x95,
+    0x3a,
+    0x6f,
+    0xe2,
+    0x20,
+    0x73,
+    0x3e,
+    0xa4,
+    0x7a,
+    0x28,
+    0xd4,
+    0x61,
+    0x97,
+    0xf6,
+    0x17,
+    0xa0,
+    0x23,
+    0x10,
+    0x2b,
+    0xce,
+    0x84,
+    0x57,
+    0x7e,
+    0x25,
+    0x1f,
+    0xf4,
+    0xa8,
+    0x54,
+    0xd2,
+    0x65,
+    0x94,
+    0xcc,
+    0x95,
+    0x0a,
+    0xab,
+    0x30,
+    0xc1,
+    0x59,
+    0x1f,
+    0x61,
+    0x8e,
+    0xb9,
+    0x6b,
+    0xd7,
+    0x4e,
+    0xb9,
+    0x83,
+    0x43,
+    0x79,
+    0x85,
+    0x11,
+    0xbc,
+    0x0f,
+    0xae,
+    0x25,
+    0x20,
+    0x05,
+    0xbc,
+    0xd2,
+    0x48,
+    0xa1,
+    0x68,
+    0x09,
+    0x84,
+    0xf6,
+    0x12,
+    0x9a,
+    0x66,
+    0xb9,
+    0x2b,
+    0xbb,
+    0x76,
+    0x03,
+    0x17,
+    0x46,
+    0x4e,
+    0x97,
+    0x59,
+    0x02,
+    0x81,
+    0x80,
+    0x09,
+    0x4c,
+    0xfa,
+    0xd6,
+    0xe5,
+    0x65,
+    0x48,
+    0x78,
+    0x43,
+    0xb5,
+    0x1f,
+    0x00,
+    0x93,
+    0x2c,
+    0xb7,
+    0x24,
+    0xe8,
+    0xc6,
+    0x7d,
+    0x5a,
+    0x70,
+    0x45,
+    0x92,
+    0xc8,
+    0x6c,
+    0xa3,
+    0xcd,
+    0xe1,
+    0xf7,
+    0x29,
+    0x40,
+    0xfa,
+    0x3f,
+    0x5b,
+    0x47,
+    0x44,
+    0x39,
+    0xc1,
+    0xe8,
+    0x72,
+    0x9e,
+    0x7a,
+    0x0e,
+    0xda,
+    0xaa,
+    0xa0,
+    0x2a,
+    0x09,
+    0xfd,
+    0x54,
+    0x93,
+    0x23,
+    0xaa,
+    0x37,
+    0x85,
+    0x5b,
+    0xcc,
+    0xd4,
+    0xf9,
+    0xd8,
+    0xff,
+    0xc1,
+    0x61,
+    0x0d,
+    0xbd,
+    0x7e,
+    0x18,
+    0x24,
+    0x73,
+    0x6d,
+    0x40,
+    0x72,
+    0xf1,
+    0x93,
+    0x09,
+    0x48,
+    0x97,
+    0x6c,
+    0x84,
+    0x90,
+    0xa8,
+    0x46,
+    0x14,
+    0x01,
+    0x39,
+    0x11,
+    0xe5,
+    0x3c,
+    0x41,
+    0x27,
+    0x32,
+    0x75,
+    0x24,
+    0xed,
+    0xa1,
+    0xd9,
+    0x12,
+    0x29,
+    0x8a,
+    0x28,
+    0x71,
+    0x89,
+    0x8d,
+    0xca,
+    0x30,
+    0xb0,
+    0x01,
+    0xc4,
+    0x2f,
+    0x82,
+    0x19,
+    0x14,
+    0x4c,
+    0x70,
+    0x1c,
+    0xb8,
+    0x23,
+    0x2e,
+    0xe8,
+    0x90,
+    0x49,
+    0x97,
+    0x92,
+    0x97,
+    0x6b,
+    0x7a,
+    0x9d,
+    0xb9,
+    0x02,
+    0x81,
+    0x80,
+    0x0f,
+    0x0e,
+    0xa1,
+    0x76,
+    0xf6,
+    0xa1,
+    0x44,
+    0x8f,
+    0xaf,
+    0x7c,
+    0x76,
+    0xd3,
+    0x87,
+    0xbb,
+    0xbb,
+    0x83,
+    0x10,
+    0x88,
+    0x01,
+    0x18,
+    0x14,
+    0xd1,
+    0xd3,
+    0x75,
+    0x59,
+    0x24,
+    0xaa,
+    0xf5,
+    0x16,
+    0xa5,
+    0xe9,
+    0x9d,
+    0xd1,
+    0xcc,
+    0xee,
+    0xf4,
+    0x15,
+    0xd9,
+    0xc5,
+    0x7e,
+    0x27,
+    0xe9,
+    0x44,
+    0x49,
+    0x06,
+    0x72,
+    0xb9,
+    0xfc,
+    0xd3,
+    0x8a,
+    0xc4,
+    0x2c,
+    0x36,
+    0x7d,
+    0x12,
+    0x9b,
+    0x5a,
+    0xaa,
+    0xdc,
+    0x85,
+    0xee,
+    0x6e,
+    0xad,
+    0x54,
+    0xb3,
+    0xf4,
+    0xfc,
+    0x31,
+    0xa1,
+    0x06,
+    0x3a,
+    0x70,
+    0x57,
+    0x0c,
+    0xf3,
+    0x95,
+    0x5b,
+    0x3e,
+    0xe8,
+    0xfd,
+    0x1a,
+    0x4f,
+    0xf6,
+    0x78,
+    0x93,
+    0x46,
+    0x6a,
+    0xd7,
+    0x31,
+    0xb4,
+    0x84,
+    0x64,
+    0x85,
+    0x09,
+    0x38,
+    0x89,
+    0x92,
+    0x94,
+    0x1c,
+    0xbf,
+    0xe2,
+    0x3c,
+    0x2a,
+    0xe0,
+    0xff,
+    0x99,
+    0xa3,
+    0xf0,
+    0x2b,
+    0x31,
+    0xc2,
+    0x36,
+    0xcd,
+    0x60,
+    0xbf,
+    0x9d,
+    0x2d,
+    0x74,
+    0x32,
+    0xe8,
+    0x9c,
+    0x93,
+    0x6e,
+    0xbb,
+    0x91,
+    0x7b,
+    0xfd,
+    0xd9,
+    0x02,
+    0x81,
+    0x81,
+    0x00,
+    0xa2,
+    0x71,
+    0x25,
+    0x38,
+    0xeb,
+    0x2a,
+    0xe9,
+    0x37,
+    0xcd,
+    0xfe,
+    0x44,
+    0xce,
+    0x90,
+    0x3f,
+    0x52,
+    0x87,
+    0x84,
+    0x52,
+    0x1b,
+    0xae,
+    0x8d,
+    0x22,
+    0x94,
+    0xce,
+    0x38,
+    0xe6,
+    0x04,
+    0x88,
+    0x76,
+    0x85,
+    0x9a,
+    0xd3,
+    0x14,
+    0x09,
+    0xe5,
+    0x69,
+    0x9a,
+    0xff,
+    0x58,
+    0x92,
+    0x02,
+    0x6a,
+    0x7d,
+    0x7c,
+    0x1e,
+    0x2c,
+    0xfd,
+    0xa8,
+    0xca,
+    0x32,
+    0x14,
+    0x4f,
+    0x0d,
+    0x84,
+    0x0d,
+    0x37,
+    0x43,
+    0xbf,
+    0xe4,
+    0x5d,
+    0x12,
+    0xc8,
+    0x24,
+    0x91,
+    0x27,
+    0x8d,
+    0x46,
+    0xd9,
+    0x54,
+    0x53,
+    0xe7,
+    0x62,
+    0x71,
+    0xa8,
+    0x2b,
+    0x71,
+    0x41,
+    0x8d,
+    0x75,
+    0xf8,
+    0x3a,
+    0xa0,
+    0x61,
+    0x29,
+    0x46,
+    0xa6,
+    0xe5,
+    0x82,
+    0xfa,
+    0x3a,
+    0xd9,
+    0x08,
+    0xfa,
+    0xfc,
+    0x63,
+    0xfd,
+    0x6b,
+    0x30,
+    0xbc,
+    0xf4,
+    0x4e,
+    0x9e,
+    0x8c,
+    0x25,
+    0x0c,
+    0xb6,
+    0x55,
+    0xe7,
+    0x3c,
+    0xd4,
+    0x4e,
+    0x0b,
+    0xfd,
+    0x8b,
+    0xc3,
+    0x0e,
+    0x1d,
+    0x9c,
+    0x44,
+    0x57,
+    0x8f,
+    0x1f,
+    0x86,
+    0xf7,
+    0xd5,
+    0x1b,
+    0xe4,
+    0x95,
 };
 
 static unsigned char test3072[] = {
@@ -413,241 +2314,2355 @@ static unsigned char test3072[] = {
 };
 
 static unsigned char test4096[] = {
-    0x30, 0x82, 0x09, 0x29, 0x02, 0x01, 0x00, 0x02, 0x82, 0x02,
-    0x01, 0x00, 0xc0, 0x71, 0xac, 0x1a, 0x13, 0x88, 0x82, 0x43,
-    0x3b, 0x51, 0x57, 0x71, 0x8d, 0xb6, 0x2b, 0x82, 0x65, 0x21,
-    0x53, 0x5f, 0x28, 0x29, 0x4f, 0x8d, 0x7c, 0x8a, 0xb9, 0x44,
-    0xb3, 0x28, 0x41, 0x4f, 0xd3, 0xfa, 0x6a, 0xf8, 0xb9, 0x28,
-    0x50, 0x39, 0x67, 0x53, 0x2c, 0x3c, 0xd7, 0xcb, 0x96, 0x41,
-    0x40, 0x32, 0xbb, 0xeb, 0x70, 0xae, 0x1f, 0xb0, 0x65, 0xf7,
-    0x3a, 0xd9, 0x22, 0xfd, 0x10, 0xae, 0xbd, 0x02, 0xe2, 0xdd,
-    0xf3, 0xc2, 0x79, 0x3c, 0xc6, 0xfc, 0x75, 0xbb, 0xaf, 0x4e,
-    0x3a, 0x36, 0xc2, 0x4f, 0xea, 0x25, 0xdf, 0x13, 0x16, 0x4b,
-    0x20, 0xfe, 0x4b, 0x69, 0x16, 0xc4, 0x7f, 0x1a, 0x43, 0xa6,
-    0x17, 0x1b, 0xb9, 0x0a, 0xf3, 0x09, 0x86, 0x28, 0x89, 0xcf,
-    0x2c, 0xd0, 0xd4, 0x81, 0xaf, 0xc6, 0x6d, 0xe6, 0x21, 0x8d,
-    0xee, 0xef, 0xea, 0xdc, 0xb7, 0xc6, 0x3b, 0x63, 0x9f, 0x0e,
-    0xad, 0x89, 0x78, 0x23, 0x18, 0xbf, 0x70, 0x7e, 0x84, 0xe0,
-    0x37, 0xec, 0xdb, 0x8e, 0x9c, 0x3e, 0x6a, 0x19, 0xcc, 0x99,
-    0x72, 0xe6, 0xb5, 0x7d, 0x6d, 0xfa, 0xe5, 0xd3, 0xe4, 0x90,
-    0xb5, 0xb2, 0xb2, 0x12, 0x70, 0x4e, 0xca, 0xf8, 0x10, 0xf8,
-    0xa3, 0x14, 0xc2, 0x48, 0x19, 0xeb, 0x60, 0x99, 0xbb, 0x2a,
-    0x1f, 0xb1, 0x7a, 0xb1, 0x3d, 0x24, 0xfb, 0xa0, 0x29, 0xda,
-    0xbd, 0x1b, 0xd7, 0xa4, 0xbf, 0xef, 0x60, 0x2d, 0x22, 0xca,
-    0x65, 0x98, 0xf1, 0xc4, 0xe1, 0xc9, 0x02, 0x6b, 0x16, 0x28,
-    0x2f, 0xa1, 0xaa, 0x79, 0x00, 0xda, 0xdc, 0x7c, 0x43, 0xf7,
-    0x42, 0x3c, 0xa0, 0xef, 0x68, 0xf7, 0xdf, 0xb9, 0x69, 0xfb,
-    0x8e, 0x01, 0xed, 0x01, 0x42, 0xb5, 0x4e, 0x57, 0xa6, 0x26,
-    0xb8, 0xd0, 0x7b, 0x56, 0x6d, 0x03, 0xc6, 0x40, 0x8c, 0x8c,
-    0x2a, 0x55, 0xd7, 0x9c, 0x35, 0x00, 0x94, 0x93, 0xec, 0x03,
-    0xeb, 0x22, 0xef, 0x77, 0xbb, 0x79, 0x13, 0x3f, 0x15, 0xa1,
-    0x8f, 0xca, 0xdf, 0xfd, 0xd3, 0xb8, 0xe1, 0xd4, 0xcc, 0x09,
-    0x3f, 0x3c, 0x2c, 0xdb, 0xd1, 0x49, 0x7f, 0x38, 0x07, 0x83,
-    0x6d, 0xeb, 0x08, 0x66, 0xe9, 0x06, 0x44, 0x12, 0xac, 0x95,
-    0x22, 0x90, 0x23, 0x67, 0xd4, 0x08, 0xcc, 0xf4, 0xb7, 0xdc,
-    0xcc, 0x87, 0xd4, 0xac, 0x69, 0x35, 0x4c, 0xb5, 0x39, 0x36,
-    0xcd, 0xa4, 0xd2, 0x95, 0xca, 0x0d, 0xc5, 0xda, 0xc2, 0xc5,
-    0x22, 0x32, 0x28, 0x08, 0xe3, 0xd2, 0x8b, 0x38, 0x30, 0xdc,
-    0x8c, 0x75, 0x4f, 0x6a, 0xec, 0x7a, 0xac, 0x16, 0x3e, 0xa8,
-    0xd4, 0x6a, 0x45, 0xe1, 0xa8, 0x4f, 0x2e, 0x80, 0x34, 0xaa,
-    0x54, 0x1b, 0x02, 0x95, 0x7d, 0x8a, 0x6d, 0xcc, 0x79, 0xca,
-    0xf2, 0xa4, 0x2e, 0x8d, 0xfb, 0xfe, 0x15, 0x51, 0x10, 0x0e,
-    0x4d, 0x88, 0xb1, 0xc7, 0xf4, 0x79, 0xdb, 0xf0, 0xb4, 0x56,
-    0x44, 0x37, 0xca, 0x5a, 0xc1, 0x8c, 0x48, 0xac, 0xae, 0x48,
-    0x80, 0x83, 0x01, 0x3f, 0xde, 0xd9, 0xd3, 0x2c, 0x51, 0x46,
-    0xb1, 0x41, 0xb6, 0xc6, 0x91, 0x72, 0xf9, 0x83, 0x55, 0x1b,
-    0x8c, 0xba, 0xf3, 0x73, 0xe5, 0x2c, 0x74, 0x50, 0x3a, 0xbe,
-    0xc5, 0x2f, 0xa7, 0xb2, 0x6d, 0x8c, 0x9e, 0x13, 0x77, 0xa3,
-    0x13, 0xcd, 0x6d, 0x8c, 0x45, 0xe1, 0xfc, 0x0b, 0xb7, 0x69,
-    0xe9, 0x27, 0xbc, 0x65, 0xc3, 0xfa, 0x9b, 0xd0, 0xef, 0xfe,
-    0xe8, 0x1f, 0xb3, 0x5e, 0x34, 0xf4, 0x8c, 0xea, 0xfc, 0xd3,
-    0x81, 0xbf, 0x3d, 0x30, 0xb2, 0xb4, 0x01, 0xe8, 0x43, 0x0f,
-    0xba, 0x02, 0x23, 0x42, 0x76, 0x82, 0x31, 0x73, 0x91, 0xed,
-    0x07, 0x46, 0x61, 0x0d, 0x39, 0x83, 0x40, 0xce, 0x7a, 0xd4,
-    0xdb, 0x80, 0x2c, 0x1f, 0x0d, 0xd1, 0x34, 0xd4, 0x92, 0xe3,
-    0xd4, 0xf1, 0xc2, 0x01, 0x02, 0x03, 0x01, 0x00, 0x01, 0x02,
-    0x82, 0x02, 0x01, 0x00, 0x97, 0x6c, 0xda, 0x6e, 0xea, 0x4f,
-    0xcf, 0xaf, 0xf7, 0x4c, 0xd9, 0xf1, 0x90, 0x00, 0x77, 0xdb,
-    0xf2, 0x97, 0x76, 0x72, 0xb9, 0xb7, 0x47, 0xd1, 0x9c, 0xdd,
-    0xcb, 0x4a, 0x33, 0x6e, 0xc9, 0x75, 0x76, 0xe6, 0xe4, 0xa5,
-    0x31, 0x8c, 0x77, 0x13, 0xb4, 0x29, 0xcd, 0xf5, 0x52, 0x17,
-    0xef, 0xf3, 0x08, 0x00, 0xe3, 0xbd, 0x2e, 0xbc, 0xd4, 0x52,
-    0x88, 0xe9, 0x30, 0x75, 0x0b, 0x02, 0xf5, 0xcd, 0x89, 0x0c,
-    0x6c, 0x57, 0x19, 0x27, 0x3d, 0x1e, 0x85, 0xb4, 0xc1, 0x2f,
-    0x1d, 0x92, 0x00, 0x5c, 0x76, 0x29, 0x4b, 0xa4, 0xe1, 0x12,
-    0xb3, 0xc8, 0x09, 0xfe, 0x0e, 0x78, 0x72, 0x61, 0xcb, 0x61,
-    0x6f, 0x39, 0x91, 0x95, 0x4e, 0xd5, 0x3e, 0xc7, 0x8f, 0xb8,
-    0xf6, 0x36, 0xfe, 0x9c, 0x93, 0x9a, 0x38, 0x25, 0x7a, 0xf4,
-    0x4a, 0x12, 0xd4, 0xa0, 0x13, 0xbd, 0xf9, 0x1d, 0x12, 0x3e,
-    0x21, 0x39, 0xfb, 0x72, 0xe0, 0x05, 0x3d, 0xc3, 0xe5, 0x50,
-    0xa8, 0x5d, 0x85, 0xa3, 0xea, 0x5f, 0x1c, 0xb2, 0x3f, 0xea,
-    0x6d, 0x03, 0x91, 0x55, 0xd8, 0x19, 0x0a, 0x21, 0x12, 0x16,
-    0xd9, 0x12, 0xc4, 0xe6, 0x07, 0x18, 0x5b, 0x26, 0xa4, 0xae,
-    0xed, 0x2b, 0xb7, 0xa6, 0xed, 0xf8, 0xad, 0xec, 0x77, 0xe6,
-    0x7f, 0x4f, 0x76, 0x00, 0xc0, 0xfa, 0x15, 0x92, 0xb4, 0x2c,
-    0x22, 0xc2, 0xeb, 0x6a, 0xad, 0x14, 0x05, 0xb2, 0xe5, 0x8a,
-    0x9e, 0x85, 0x83, 0xcc, 0x04, 0xf1, 0x56, 0x78, 0x44, 0x5e,
-    0xde, 0xe0, 0x60, 0x1a, 0x65, 0x79, 0x31, 0x23, 0x05, 0xbb,
-    0x01, 0xff, 0xdd, 0x2e, 0xb7, 0xb3, 0xaa, 0x74, 0xe0, 0xa5,
-    0x94, 0xaf, 0x4b, 0xde, 0x58, 0x0f, 0x55, 0xde, 0x33, 0xf6,
-    0xe3, 0xd6, 0x34, 0x36, 0x57, 0xd6, 0x79, 0x91, 0x2e, 0xbe,
-    0x3b, 0xd9, 0x4e, 0xb6, 0x9d, 0x21, 0x5c, 0xd3, 0x48, 0x14,
-    0x7f, 0x4a, 0xc4, 0x60, 0xa9, 0x29, 0xf8, 0x53, 0x7f, 0x88,
-    0x11, 0x2d, 0xb5, 0xc5, 0x2d, 0x6f, 0xee, 0x85, 0x0b, 0xf7,
-    0x8d, 0x9a, 0xbe, 0xb0, 0x42, 0xf2, 0x2e, 0x71, 0xaf, 0x19,
-    0x31, 0x6d, 0xec, 0xcd, 0x6f, 0x2b, 0x23, 0xdf, 0xb4, 0x40,
-    0xaf, 0x2c, 0x0a, 0xc3, 0x1b, 0x7d, 0x7d, 0x03, 0x1d, 0x4b,
-    0xf3, 0xb5, 0xe0, 0x85, 0xd8, 0xdf, 0x91, 0x6b, 0x0a, 0x69,
-    0xf7, 0xf2, 0x69, 0x66, 0x5b, 0xf1, 0xcf, 0x46, 0x7d, 0xe9,
-    0x70, 0xfa, 0x6d, 0x7e, 0x75, 0x4e, 0xa9, 0x77, 0xe6, 0x8c,
-    0x02, 0xf7, 0x14, 0x4d, 0xa5, 0x41, 0x8f, 0x3f, 0xc1, 0x62,
-    0x1e, 0x71, 0x5e, 0x38, 0xb4, 0xd6, 0xe6, 0xe1, 0x4b, 0xc2,
-    0x2c, 0x30, 0x83, 0x81, 0x6f, 0x49, 0x2e, 0x96, 0xe6, 0xc9,
-    0x9a, 0xf7, 0x5d, 0x09, 0xa0, 0x55, 0x02, 0xa5, 0x3a, 0x25,
-    0x23, 0xd0, 0x92, 0xc3, 0xa3, 0xe3, 0x0e, 0x12, 0x2f, 0x4d,
-    0xef, 0xf3, 0x55, 0x5a, 0xbe, 0xe6, 0x19, 0x86, 0x31, 0xab,
-    0x75, 0x9a, 0xd3, 0xf0, 0x2c, 0xc5, 0x41, 0x92, 0xd9, 0x1f,
-    0x5f, 0x11, 0x8c, 0x75, 0x1c, 0x63, 0xd0, 0x02, 0x80, 0x2c,
-    0x68, 0xcb, 0x93, 0xfb, 0x51, 0x73, 0x49, 0xb4, 0x60, 0xda,
-    0xe2, 0x26, 0xaf, 0xa9, 0x46, 0x12, 0xb8, 0xec, 0x50, 0xdd,
-    0x12, 0x06, 0x5f, 0xce, 0x59, 0xe6, 0xf6, 0x1c, 0xe0, 0x54,
-    0x10, 0xad, 0xf6, 0xcd, 0x98, 0xcc, 0x0f, 0xfb, 0xcb, 0x41,
-    0x14, 0x9d, 0xed, 0xe4, 0xb4, 0x74, 0x5f, 0x09, 0x60, 0xc7,
-    0x12, 0xf6, 0x7b, 0x3c, 0x8f, 0xa7, 0x20, 0xbc, 0xe4, 0xb1,
-    0xef, 0xeb, 0xa4, 0x93, 0xc5, 0x06, 0xca, 0x9a, 0x27, 0x9d,
-    0x87, 0xf3, 0xde, 0xca, 0xe5, 0xe7, 0xf6, 0x1c, 0x01, 0x65,
-    0x5b, 0xfb, 0x19, 0x79, 0x6e, 0x08, 0x26, 0xc5, 0xc8, 0x28,
-    0x0e, 0xb6, 0x3b, 0x07, 0x08, 0xc1, 0x02, 0x82, 0x01, 0x01,
-    0x00, 0xe8, 0x1c, 0x73, 0xa6, 0xb8, 0xe0, 0x0e, 0x6d, 0x8d,
-    0x1b, 0xb9, 0x53, 0xed, 0x58, 0x94, 0xe6, 0x1d, 0x60, 0x14,
-    0x5c, 0x76, 0x43, 0xc4, 0x58, 0x19, 0xc4, 0x24, 0xe8, 0xbc,
-    0x1b, 0x3b, 0x0b, 0x13, 0x24, 0x45, 0x54, 0x0e, 0xcc, 0x37,
-    0xf0, 0xe0, 0x63, 0x7d, 0xc3, 0xf7, 0xfb, 0x81, 0x74, 0x81,
-    0xc4, 0x0f, 0x1a, 0x21, 0x48, 0xaf, 0xce, 0xc1, 0xc4, 0x94,
-    0x18, 0x06, 0x44, 0x8d, 0xd3, 0xd2, 0x22, 0x2d, 0x2d, 0x3e,
-    0x5a, 0x31, 0xdc, 0x95, 0x8e, 0xf4, 0x41, 0xfc, 0x58, 0xc9,
-    0x40, 0x92, 0x17, 0x5f, 0xe3, 0xda, 0xac, 0x9e, 0x3f, 0x1c,
-    0x2a, 0x6b, 0x58, 0x5f, 0x48, 0x78, 0x20, 0xb1, 0xaf, 0x24,
-    0x9b, 0x3c, 0x20, 0x8b, 0x93, 0x25, 0x9e, 0xe6, 0x6b, 0xbc,
-    0x13, 0x42, 0x14, 0x6c, 0x36, 0x31, 0xff, 0x7a, 0xd1, 0xc1,
-    0x1a, 0x26, 0x14, 0x7f, 0xa9, 0x76, 0xa7, 0x0c, 0xf8, 0xcc,
-    0xed, 0x07, 0x6a, 0xd2, 0xdf, 0x62, 0xee, 0x0a, 0x7c, 0x84,
-    0xcb, 0x49, 0x90, 0xb2, 0x03, 0x0d, 0xa2, 0x82, 0x06, 0x77,
-    0xf1, 0xcd, 0x67, 0xf2, 0x47, 0x21, 0x02, 0x3f, 0x43, 0x21,
-    0xf0, 0x46, 0x30, 0x62, 0x51, 0x72, 0xb1, 0xe7, 0x48, 0xc6,
-    0x67, 0x12, 0xcd, 0x9e, 0xd6, 0x15, 0xe5, 0x21, 0xed, 0xfa,
-    0x8f, 0x30, 0xa6, 0x41, 0xfe, 0xb6, 0xfa, 0x8f, 0x34, 0x14,
-    0x19, 0xe8, 0x11, 0xf7, 0xa5, 0x77, 0x3e, 0xb7, 0xf9, 0x39,
-    0x07, 0x8c, 0x67, 0x2a, 0xab, 0x7b, 0x08, 0xf8, 0xb0, 0x06,
-    0xa8, 0xea, 0x2f, 0x8f, 0xfa, 0xcc, 0xcc, 0x40, 0xce, 0xf3,
-    0x70, 0x4f, 0x3f, 0x7f, 0xe2, 0x0c, 0xea, 0x76, 0x4a, 0x35,
-    0x4e, 0x47, 0xad, 0x2b, 0xa7, 0x97, 0x5d, 0x74, 0x43, 0x97,
-    0x90, 0xd2, 0xfb, 0xd9, 0xf9, 0x96, 0x01, 0x33, 0x05, 0xed,
-    0x7b, 0x03, 0x05, 0xad, 0xf8, 0x49, 0x03, 0x02, 0x82, 0x01,
-    0x01, 0x00, 0xd4, 0x40, 0x17, 0x66, 0x10, 0x92, 0x95, 0xc8,
-    0xec, 0x62, 0xa9, 0x7a, 0xcb, 0x93, 0x8e, 0xe6, 0x53, 0xd4,
-    0x80, 0x48, 0x27, 0x4b, 0x41, 0xce, 0x61, 0xdf, 0xbf, 0x94,
-    0xa4, 0x3d, 0x71, 0x03, 0x0b, 0xed, 0x25, 0x71, 0x98, 0xa4,
-    0xd6, 0xd5, 0x4a, 0x57, 0xf5, 0x6c, 0x1b, 0xda, 0x21, 0x7d,
-    0x35, 0x45, 0xb3, 0xf3, 0x6a, 0xd9, 0xd3, 0x43, 0xe8, 0x5c,
-    0x54, 0x1c, 0x83, 0x1b, 0xb4, 0x5f, 0xf2, 0x97, 0x24, 0x2e,
-    0xdc, 0x40, 0xde, 0x92, 0x23, 0x59, 0x8e, 0xbc, 0xd2, 0xa1,
-    0xf2, 0xe0, 0x4c, 0xdd, 0x0b, 0xd1, 0xe7, 0xae, 0x65, 0xbc,
-    0xb5, 0xf5, 0x5b, 0x98, 0xe9, 0xd7, 0xc2, 0xb7, 0x0e, 0x55,
-    0x71, 0x0e, 0x3c, 0x0a, 0x24, 0x6b, 0xa6, 0xe6, 0x14, 0x61,
-    0x11, 0xfd, 0x33, 0x42, 0x99, 0x2b, 0x84, 0x77, 0x74, 0x92,
-    0x91, 0xf5, 0x79, 0x79, 0xcf, 0xad, 0x8e, 0x04, 0xef, 0x80,
-    0x1e, 0x57, 0xf4, 0x14, 0xf5, 0x35, 0x09, 0x74, 0xb2, 0x13,
-    0x71, 0x58, 0x6b, 0xea, 0x32, 0x5d, 0xf3, 0xd3, 0x76, 0x48,
-    0x39, 0x10, 0x23, 0x84, 0x9d, 0xbe, 0x92, 0x77, 0x4a, 0xed,
-    0x70, 0x3e, 0x1a, 0xa2, 0x6c, 0xb3, 0x81, 0x00, 0xc3, 0xc9,
-    0xe4, 0x52, 0xc8, 0x24, 0x88, 0x0c, 0x41, 0xad, 0x87, 0x5a,
-    0xea, 0xa3, 0x7a, 0x85, 0x1c, 0x5e, 0x31, 0x7f, 0xc3, 0x35,
-    0xc6, 0xfa, 0x10, 0xc8, 0x75, 0x10, 0xc4, 0x96, 0x99, 0xe7,
-    0xfe, 0x01, 0xb4, 0x74, 0xdb, 0xb4, 0x11, 0xc3, 0xc8, 0x8c,
-    0xf6, 0xf7, 0x3b, 0x66, 0x50, 0xfc, 0xdb, 0xeb, 0xca, 0x47,
-    0x85, 0x89, 0xe1, 0x65, 0xd9, 0x62, 0x34, 0x3c, 0x70, 0xd8,
-    0x2e, 0xb4, 0x2f, 0x65, 0x3c, 0x4a, 0xa6, 0x2a, 0xe7, 0xc7,
-    0xd8, 0x41, 0x8f, 0x8a, 0x43, 0xbf, 0x42, 0xf2, 0x4d, 0xbc,
-    0xfc, 0x9e, 0x27, 0x95, 0xfb, 0x75, 0xff, 0xab, 0x02, 0x82,
-    0x01, 0x00, 0x41, 0x2f, 0x44, 0x57, 0x6d, 0x12, 0x17, 0x5b,
-    0x32, 0xc6, 0xb7, 0x6c, 0x57, 0x7a, 0x8a, 0x0e, 0x79, 0xef,
-    0x72, 0xa8, 0x68, 0xda, 0x2d, 0x38, 0xe4, 0xbb, 0x8d, 0xf6,
-    0x02, 0x65, 0xcf, 0x56, 0x13, 0xe1, 0x1a, 0xcb, 0x39, 0x80,
-    0xa6, 0xb1, 0x32, 0x03, 0x1e, 0xdd, 0xbb, 0x35, 0xd9, 0xac,
-    0x43, 0x89, 0x31, 0x08, 0x90, 0x92, 0x5e, 0x35, 0x3d, 0x7b,
-    0x9c, 0x6f, 0x86, 0xcb, 0x17, 0xdd, 0x85, 0xe4, 0xed, 0x35,
-    0x08, 0x8e, 0xc1, 0xf4, 0x05, 0xd8, 0x68, 0xc6, 0x63, 0x3c,
-    0xf7, 0xff, 0xf7, 0x47, 0x33, 0x39, 0xc5, 0x3e, 0xb7, 0x0e,
-    0x58, 0x35, 0x9d, 0x81, 0xea, 0xf8, 0x6a, 0x2c, 0x1c, 0x5a,
-    0x68, 0x78, 0x64, 0x11, 0x6b, 0xc1, 0x3e, 0x4e, 0x7a, 0xbd,
-    0x84, 0xcb, 0x0f, 0xc2, 0xb6, 0x85, 0x1d, 0xd3, 0x76, 0xc5,
-    0x93, 0x6a, 0x69, 0x89, 0x56, 0x34, 0xdc, 0x4a, 0x9b, 0xbc,
-    0xff, 0xa8, 0x0d, 0x6e, 0x35, 0x9c, 0x60, 0xa7, 0x23, 0x30,
-    0xc7, 0x06, 0x64, 0x39, 0x8b, 0x94, 0x89, 0xee, 0xba, 0x7f,
-    0x60, 0x8d, 0xfa, 0xb6, 0x97, 0x76, 0xdc, 0x51, 0x4a, 0x3c,
-    0xeb, 0x3a, 0x14, 0x2c, 0x20, 0x60, 0x69, 0x4a, 0x86, 0xfe,
-    0x8c, 0x21, 0x84, 0x49, 0x54, 0xb3, 0x20, 0xe1, 0x01, 0x7f,
-    0x58, 0xdf, 0x7f, 0xb5, 0x21, 0x51, 0x8c, 0x47, 0x9f, 0x91,
-    0xeb, 0x97, 0x3e, 0xf2, 0x54, 0xcf, 0x16, 0x46, 0xf9, 0xd9,
-    0xb6, 0xe7, 0x64, 0xc9, 0xd0, 0x54, 0xea, 0x2f, 0xa1, 0xcf,
-    0xa5, 0x7f, 0x28, 0x8d, 0x84, 0xec, 0xd5, 0x39, 0x03, 0x76,
-    0x5b, 0x2d, 0x8e, 0x43, 0xf2, 0x01, 0x24, 0xc9, 0x6f, 0xc0,
-    0xf5, 0x69, 0x6f, 0x7d, 0xb5, 0x85, 0xd2, 0x5f, 0x7f, 0x78,
-    0x40, 0x07, 0x7f, 0x09, 0x15, 0xb5, 0x1f, 0x28, 0x65, 0x10,
-    0xe4, 0x19, 0xa8, 0xc6, 0x9e, 0x8d, 0xdc, 0xcb, 0x02, 0x82,
-    0x01, 0x00, 0x13, 0x01, 0xee, 0x56, 0x80, 0x93, 0x70, 0x00,
-    0x7f, 0x52, 0xd2, 0x94, 0xa1, 0x98, 0x84, 0x4a, 0x92, 0x25,
-    0x4c, 0x9b, 0xa9, 0x91, 0x2e, 0xc2, 0x79, 0xb7, 0x5c, 0xe3,
-    0xc5, 0xd5, 0x8e, 0xc2, 0x54, 0x16, 0x17, 0xad, 0x55, 0x9b,
-    0x25, 0x76, 0x12, 0x63, 0x50, 0x22, 0x2f, 0x58, 0x58, 0x79,
-    0x6b, 0x04, 0xe3, 0xf9, 0x9f, 0x8f, 0x04, 0x41, 0x67, 0x94,
-    0xa5, 0x1f, 0xac, 0x8a, 0x15, 0x9c, 0x26, 0x10, 0x6c, 0xf8,
-    0x19, 0x57, 0x61, 0xd7, 0x3a, 0x7d, 0x31, 0xb0, 0x2d, 0x38,
-    0xbd, 0x94, 0x62, 0xad, 0xc4, 0xfa, 0x36, 0x42, 0x42, 0xf0,
-    0x24, 0x67, 0x65, 0x9d, 0x8b, 0x0b, 0x7c, 0x6f, 0x82, 0x44,
-    0x1a, 0x8c, 0xc8, 0xc9, 0xab, 0xbb, 0x4c, 0x45, 0xfc, 0x7b,
-    0x38, 0xee, 0x30, 0xe1, 0xfc, 0xef, 0x8d, 0xbc, 0x58, 0xdf,
-    0x2b, 0x5d, 0x0d, 0x54, 0xe0, 0x49, 0x4d, 0x97, 0x99, 0x8f,
-    0x22, 0xa8, 0x83, 0xbe, 0x40, 0xbb, 0x50, 0x2e, 0x78, 0x28,
-    0x0f, 0x95, 0x78, 0x8c, 0x8f, 0x98, 0x24, 0x56, 0xc2, 0x97,
-    0xf3, 0x2c, 0x43, 0xd2, 0x03, 0x82, 0x66, 0x81, 0x72, 0x5f,
-    0x53, 0x16, 0xec, 0xb1, 0xb1, 0x04, 0x5e, 0x40, 0x20, 0x48,
-    0x7b, 0x3f, 0x02, 0x97, 0x6a, 0xeb, 0x96, 0x12, 0x21, 0x35,
-    0xfe, 0x1f, 0x47, 0xc0, 0x95, 0xea, 0xc5, 0x8a, 0x08, 0x84,
-    0x4f, 0x5e, 0x63, 0x94, 0x60, 0x0f, 0x71, 0x5b, 0x7f, 0x4a,
-    0xec, 0x4f, 0x60, 0xc6, 0xba, 0x4a, 0x24, 0xf1, 0x20, 0x8b,
-    0xa7, 0x2e, 0x3a, 0xce, 0x8d, 0xe0, 0x27, 0x1d, 0xb5, 0x8e,
-    0xb4, 0x21, 0xc5, 0xe2, 0xa6, 0x16, 0x0a, 0x51, 0x83, 0x55,
-    0x88, 0xd1, 0x30, 0x11, 0x63, 0xd5, 0xd7, 0x8d, 0xae, 0x16,
-    0x12, 0x82, 0xc4, 0x85, 0x00, 0x4e, 0x27, 0x83, 0xa5, 0x7c,
-    0x90, 0x2e, 0xe5, 0xa2, 0xa3, 0xd3, 0x4c, 0x63, 0x02, 0x82,
-    0x01, 0x01, 0x00, 0x86, 0x08, 0x98, 0x98, 0xa5, 0x00, 0x05,
-    0x39, 0x77, 0xd9, 0x66, 0xb3, 0xcf, 0xca, 0xa0, 0x71, 0xb3,
-    0x50, 0xce, 0x3d, 0xb1, 0x93, 0x95, 0x35, 0xc4, 0xd4, 0x2e,
-    0x90, 0xdf, 0x0f, 0xfc, 0x60, 0xc1, 0x94, 0x68, 0x61, 0x43,
-    0xca, 0x9a, 0x23, 0x4a, 0x1e, 0x45, 0x72, 0x99, 0xb5, 0x1e,
-    0x61, 0x8d, 0x77, 0x0f, 0xa0, 0xbb, 0xd7, 0x77, 0xb4, 0x2a,
-    0x15, 0x11, 0x88, 0x2d, 0xb3, 0x56, 0x61, 0x5e, 0x6a, 0xed,
-    0xa4, 0x46, 0x4a, 0x3f, 0x50, 0x11, 0xd6, 0xba, 0xb6, 0xd7,
-    0x95, 0x65, 0x53, 0xc3, 0xa1, 0x8f, 0xe0, 0xa3, 0xf5, 0x1c,
-    0xfd, 0xaf, 0x6e, 0x43, 0xd7, 0x17, 0xa7, 0xd3, 0x81, 0x1b,
-    0xa4, 0xdf, 0xe0, 0x97, 0x8a, 0x46, 0x03, 0xd3, 0x46, 0x0e,
-    0x83, 0x48, 0x4e, 0xd2, 0x02, 0xcb, 0xc0, 0xad, 0x79, 0x95,
-    0x8c, 0x96, 0xba, 0x40, 0x34, 0x11, 0x71, 0x5e, 0xe9, 0x11,
-    0xf9, 0xc5, 0x4a, 0x5e, 0x91, 0x9d, 0xf5, 0x92, 0x4f, 0xeb,
-    0xc6, 0x70, 0x02, 0x2d, 0x3d, 0x04, 0xaa, 0xe9, 0x3a, 0x8e,
-    0xd5, 0xa8, 0xad, 0xf7, 0xce, 0x0d, 0x16, 0xb2, 0xec, 0x0a,
-    0x9c, 0xf5, 0x94, 0x39, 0xb9, 0x8a, 0xfc, 0x1e, 0xf9, 0xcc,
-    0xf2, 0x5f, 0x21, 0x31, 0x74, 0x72, 0x6b, 0x64, 0xae, 0x35,
-    0x61, 0x8d, 0x0d, 0xcb, 0xe7, 0xda, 0x39, 0xca, 0xf3, 0x21,
-    0x66, 0x0b, 0x95, 0xd7, 0x0a, 0x7c, 0xca, 0xa1, 0xa9, 0x5a,
-    0xe8, 0xac, 0xe0, 0x71, 0x54, 0xaf, 0x28, 0xcf, 0xd5, 0x70,
-    0x89, 0xe0, 0xf3, 0x9e, 0x43, 0x6c, 0x8d, 0x7b, 0x99, 0x01,
-    0x68, 0x4d, 0xa1, 0x45, 0x46, 0x0c, 0x43, 0xbc, 0xcc, 0x2c,
-    0xdd, 0xc5, 0x46, 0xc8, 0x4e, 0x0e, 0xbe, 0xed, 0xb9, 0x26,
-    0xab, 0x2e, 0xdb, 0xeb, 0x8f, 0xff, 0xdb, 0xb0, 0xc6, 0x55,
-    0xaf, 0xf8, 0x2a, 0x91, 0x9d, 0x50, 0x44, 0x21, 0x17
+    0x30,
+    0x82,
+    0x09,
+    0x29,
+    0x02,
+    0x01,
+    0x00,
+    0x02,
+    0x82,
+    0x02,
+    0x01,
+    0x00,
+    0xc0,
+    0x71,
+    0xac,
+    0x1a,
+    0x13,
+    0x88,
+    0x82,
+    0x43,
+    0x3b,
+    0x51,
+    0x57,
+    0x71,
+    0x8d,
+    0xb6,
+    0x2b,
+    0x82,
+    0x65,
+    0x21,
+    0x53,
+    0x5f,
+    0x28,
+    0x29,
+    0x4f,
+    0x8d,
+    0x7c,
+    0x8a,
+    0xb9,
+    0x44,
+    0xb3,
+    0x28,
+    0x41,
+    0x4f,
+    0xd3,
+    0xfa,
+    0x6a,
+    0xf8,
+    0xb9,
+    0x28,
+    0x50,
+    0x39,
+    0x67,
+    0x53,
+    0x2c,
+    0x3c,
+    0xd7,
+    0xcb,
+    0x96,
+    0x41,
+    0x40,
+    0x32,
+    0xbb,
+    0xeb,
+    0x70,
+    0xae,
+    0x1f,
+    0xb0,
+    0x65,
+    0xf7,
+    0x3a,
+    0xd9,
+    0x22,
+    0xfd,
+    0x10,
+    0xae,
+    0xbd,
+    0x02,
+    0xe2,
+    0xdd,
+    0xf3,
+    0xc2,
+    0x79,
+    0x3c,
+    0xc6,
+    0xfc,
+    0x75,
+    0xbb,
+    0xaf,
+    0x4e,
+    0x3a,
+    0x36,
+    0xc2,
+    0x4f,
+    0xea,
+    0x25,
+    0xdf,
+    0x13,
+    0x16,
+    0x4b,
+    0x20,
+    0xfe,
+    0x4b,
+    0x69,
+    0x16,
+    0xc4,
+    0x7f,
+    0x1a,
+    0x43,
+    0xa6,
+    0x17,
+    0x1b,
+    0xb9,
+    0x0a,
+    0xf3,
+    0x09,
+    0x86,
+    0x28,
+    0x89,
+    0xcf,
+    0x2c,
+    0xd0,
+    0xd4,
+    0x81,
+    0xaf,
+    0xc6,
+    0x6d,
+    0xe6,
+    0x21,
+    0x8d,
+    0xee,
+    0xef,
+    0xea,
+    0xdc,
+    0xb7,
+    0xc6,
+    0x3b,
+    0x63,
+    0x9f,
+    0x0e,
+    0xad,
+    0x89,
+    0x78,
+    0x23,
+    0x18,
+    0xbf,
+    0x70,
+    0x7e,
+    0x84,
+    0xe0,
+    0x37,
+    0xec,
+    0xdb,
+    0x8e,
+    0x9c,
+    0x3e,
+    0x6a,
+    0x19,
+    0xcc,
+    0x99,
+    0x72,
+    0xe6,
+    0xb5,
+    0x7d,
+    0x6d,
+    0xfa,
+    0xe5,
+    0xd3,
+    0xe4,
+    0x90,
+    0xb5,
+    0xb2,
+    0xb2,
+    0x12,
+    0x70,
+    0x4e,
+    0xca,
+    0xf8,
+    0x10,
+    0xf8,
+    0xa3,
+    0x14,
+    0xc2,
+    0x48,
+    0x19,
+    0xeb,
+    0x60,
+    0x99,
+    0xbb,
+    0x2a,
+    0x1f,
+    0xb1,
+    0x7a,
+    0xb1,
+    0x3d,
+    0x24,
+    0xfb,
+    0xa0,
+    0x29,
+    0xda,
+    0xbd,
+    0x1b,
+    0xd7,
+    0xa4,
+    0xbf,
+    0xef,
+    0x60,
+    0x2d,
+    0x22,
+    0xca,
+    0x65,
+    0x98,
+    0xf1,
+    0xc4,
+    0xe1,
+    0xc9,
+    0x02,
+    0x6b,
+    0x16,
+    0x28,
+    0x2f,
+    0xa1,
+    0xaa,
+    0x79,
+    0x00,
+    0xda,
+    0xdc,
+    0x7c,
+    0x43,
+    0xf7,
+    0x42,
+    0x3c,
+    0xa0,
+    0xef,
+    0x68,
+    0xf7,
+    0xdf,
+    0xb9,
+    0x69,
+    0xfb,
+    0x8e,
+    0x01,
+    0xed,
+    0x01,
+    0x42,
+    0xb5,
+    0x4e,
+    0x57,
+    0xa6,
+    0x26,
+    0xb8,
+    0xd0,
+    0x7b,
+    0x56,
+    0x6d,
+    0x03,
+    0xc6,
+    0x40,
+    0x8c,
+    0x8c,
+    0x2a,
+    0x55,
+    0xd7,
+    0x9c,
+    0x35,
+    0x00,
+    0x94,
+    0x93,
+    0xec,
+    0x03,
+    0xeb,
+    0x22,
+    0xef,
+    0x77,
+    0xbb,
+    0x79,
+    0x13,
+    0x3f,
+    0x15,
+    0xa1,
+    0x8f,
+    0xca,
+    0xdf,
+    0xfd,
+    0xd3,
+    0xb8,
+    0xe1,
+    0xd4,
+    0xcc,
+    0x09,
+    0x3f,
+    0x3c,
+    0x2c,
+    0xdb,
+    0xd1,
+    0x49,
+    0x7f,
+    0x38,
+    0x07,
+    0x83,
+    0x6d,
+    0xeb,
+    0x08,
+    0x66,
+    0xe9,
+    0x06,
+    0x44,
+    0x12,
+    0xac,
+    0x95,
+    0x22,
+    0x90,
+    0x23,
+    0x67,
+    0xd4,
+    0x08,
+    0xcc,
+    0xf4,
+    0xb7,
+    0xdc,
+    0xcc,
+    0x87,
+    0xd4,
+    0xac,
+    0x69,
+    0x35,
+    0x4c,
+    0xb5,
+    0x39,
+    0x36,
+    0xcd,
+    0xa4,
+    0xd2,
+    0x95,
+    0xca,
+    0x0d,
+    0xc5,
+    0xda,
+    0xc2,
+    0xc5,
+    0x22,
+    0x32,
+    0x28,
+    0x08,
+    0xe3,
+    0xd2,
+    0x8b,
+    0x38,
+    0x30,
+    0xdc,
+    0x8c,
+    0x75,
+    0x4f,
+    0x6a,
+    0xec,
+    0x7a,
+    0xac,
+    0x16,
+    0x3e,
+    0xa8,
+    0xd4,
+    0x6a,
+    0x45,
+    0xe1,
+    0xa8,
+    0x4f,
+    0x2e,
+    0x80,
+    0x34,
+    0xaa,
+    0x54,
+    0x1b,
+    0x02,
+    0x95,
+    0x7d,
+    0x8a,
+    0x6d,
+    0xcc,
+    0x79,
+    0xca,
+    0xf2,
+    0xa4,
+    0x2e,
+    0x8d,
+    0xfb,
+    0xfe,
+    0x15,
+    0x51,
+    0x10,
+    0x0e,
+    0x4d,
+    0x88,
+    0xb1,
+    0xc7,
+    0xf4,
+    0x79,
+    0xdb,
+    0xf0,
+    0xb4,
+    0x56,
+    0x44,
+    0x37,
+    0xca,
+    0x5a,
+    0xc1,
+    0x8c,
+    0x48,
+    0xac,
+    0xae,
+    0x48,
+    0x80,
+    0x83,
+    0x01,
+    0x3f,
+    0xde,
+    0xd9,
+    0xd3,
+    0x2c,
+    0x51,
+    0x46,
+    0xb1,
+    0x41,
+    0xb6,
+    0xc6,
+    0x91,
+    0x72,
+    0xf9,
+    0x83,
+    0x55,
+    0x1b,
+    0x8c,
+    0xba,
+    0xf3,
+    0x73,
+    0xe5,
+    0x2c,
+    0x74,
+    0x50,
+    0x3a,
+    0xbe,
+    0xc5,
+    0x2f,
+    0xa7,
+    0xb2,
+    0x6d,
+    0x8c,
+    0x9e,
+    0x13,
+    0x77,
+    0xa3,
+    0x13,
+    0xcd,
+    0x6d,
+    0x8c,
+    0x45,
+    0xe1,
+    0xfc,
+    0x0b,
+    0xb7,
+    0x69,
+    0xe9,
+    0x27,
+    0xbc,
+    0x65,
+    0xc3,
+    0xfa,
+    0x9b,
+    0xd0,
+    0xef,
+    0xfe,
+    0xe8,
+    0x1f,
+    0xb3,
+    0x5e,
+    0x34,
+    0xf4,
+    0x8c,
+    0xea,
+    0xfc,
+    0xd3,
+    0x81,
+    0xbf,
+    0x3d,
+    0x30,
+    0xb2,
+    0xb4,
+    0x01,
+    0xe8,
+    0x43,
+    0x0f,
+    0xba,
+    0x02,
+    0x23,
+    0x42,
+    0x76,
+    0x82,
+    0x31,
+    0x73,
+    0x91,
+    0xed,
+    0x07,
+    0x46,
+    0x61,
+    0x0d,
+    0x39,
+    0x83,
+    0x40,
+    0xce,
+    0x7a,
+    0xd4,
+    0xdb,
+    0x80,
+    0x2c,
+    0x1f,
+    0x0d,
+    0xd1,
+    0x34,
+    0xd4,
+    0x92,
+    0xe3,
+    0xd4,
+    0xf1,
+    0xc2,
+    0x01,
+    0x02,
+    0x03,
+    0x01,
+    0x00,
+    0x01,
+    0x02,
+    0x82,
+    0x02,
+    0x01,
+    0x00,
+    0x97,
+    0x6c,
+    0xda,
+    0x6e,
+    0xea,
+    0x4f,
+    0xcf,
+    0xaf,
+    0xf7,
+    0x4c,
+    0xd9,
+    0xf1,
+    0x90,
+    0x00,
+    0x77,
+    0xdb,
+    0xf2,
+    0x97,
+    0x76,
+    0x72,
+    0xb9,
+    0xb7,
+    0x47,
+    0xd1,
+    0x9c,
+    0xdd,
+    0xcb,
+    0x4a,
+    0x33,
+    0x6e,
+    0xc9,
+    0x75,
+    0x76,
+    0xe6,
+    0xe4,
+    0xa5,
+    0x31,
+    0x8c,
+    0x77,
+    0x13,
+    0xb4,
+    0x29,
+    0xcd,
+    0xf5,
+    0x52,
+    0x17,
+    0xef,
+    0xf3,
+    0x08,
+    0x00,
+    0xe3,
+    0xbd,
+    0x2e,
+    0xbc,
+    0xd4,
+    0x52,
+    0x88,
+    0xe9,
+    0x30,
+    0x75,
+    0x0b,
+    0x02,
+    0xf5,
+    0xcd,
+    0x89,
+    0x0c,
+    0x6c,
+    0x57,
+    0x19,
+    0x27,
+    0x3d,
+    0x1e,
+    0x85,
+    0xb4,
+    0xc1,
+    0x2f,
+    0x1d,
+    0x92,
+    0x00,
+    0x5c,
+    0x76,
+    0x29,
+    0x4b,
+    0xa4,
+    0xe1,
+    0x12,
+    0xb3,
+    0xc8,
+    0x09,
+    0xfe,
+    0x0e,
+    0x78,
+    0x72,
+    0x61,
+    0xcb,
+    0x61,
+    0x6f,
+    0x39,
+    0x91,
+    0x95,
+    0x4e,
+    0xd5,
+    0x3e,
+    0xc7,
+    0x8f,
+    0xb8,
+    0xf6,
+    0x36,
+    0xfe,
+    0x9c,
+    0x93,
+    0x9a,
+    0x38,
+    0x25,
+    0x7a,
+    0xf4,
+    0x4a,
+    0x12,
+    0xd4,
+    0xa0,
+    0x13,
+    0xbd,
+    0xf9,
+    0x1d,
+    0x12,
+    0x3e,
+    0x21,
+    0x39,
+    0xfb,
+    0x72,
+    0xe0,
+    0x05,
+    0x3d,
+    0xc3,
+    0xe5,
+    0x50,
+    0xa8,
+    0x5d,
+    0x85,
+    0xa3,
+    0xea,
+    0x5f,
+    0x1c,
+    0xb2,
+    0x3f,
+    0xea,
+    0x6d,
+    0x03,
+    0x91,
+    0x55,
+    0xd8,
+    0x19,
+    0x0a,
+    0x21,
+    0x12,
+    0x16,
+    0xd9,
+    0x12,
+    0xc4,
+    0xe6,
+    0x07,
+    0x18,
+    0x5b,
+    0x26,
+    0xa4,
+    0xae,
+    0xed,
+    0x2b,
+    0xb7,
+    0xa6,
+    0xed,
+    0xf8,
+    0xad,
+    0xec,
+    0x77,
+    0xe6,
+    0x7f,
+    0x4f,
+    0x76,
+    0x00,
+    0xc0,
+    0xfa,
+    0x15,
+    0x92,
+    0xb4,
+    0x2c,
+    0x22,
+    0xc2,
+    0xeb,
+    0x6a,
+    0xad,
+    0x14,
+    0x05,
+    0xb2,
+    0xe5,
+    0x8a,
+    0x9e,
+    0x85,
+    0x83,
+    0xcc,
+    0x04,
+    0xf1,
+    0x56,
+    0x78,
+    0x44,
+    0x5e,
+    0xde,
+    0xe0,
+    0x60,
+    0x1a,
+    0x65,
+    0x79,
+    0x31,
+    0x23,
+    0x05,
+    0xbb,
+    0x01,
+    0xff,
+    0xdd,
+    0x2e,
+    0xb7,
+    0xb3,
+    0xaa,
+    0x74,
+    0xe0,
+    0xa5,
+    0x94,
+    0xaf,
+    0x4b,
+    0xde,
+    0x58,
+    0x0f,
+    0x55,
+    0xde,
+    0x33,
+    0xf6,
+    0xe3,
+    0xd6,
+    0x34,
+    0x36,
+    0x57,
+    0xd6,
+    0x79,
+    0x91,
+    0x2e,
+    0xbe,
+    0x3b,
+    0xd9,
+    0x4e,
+    0xb6,
+    0x9d,
+    0x21,
+    0x5c,
+    0xd3,
+    0x48,
+    0x14,
+    0x7f,
+    0x4a,
+    0xc4,
+    0x60,
+    0xa9,
+    0x29,
+    0xf8,
+    0x53,
+    0x7f,
+    0x88,
+    0x11,
+    0x2d,
+    0xb5,
+    0xc5,
+    0x2d,
+    0x6f,
+    0xee,
+    0x85,
+    0x0b,
+    0xf7,
+    0x8d,
+    0x9a,
+    0xbe,
+    0xb0,
+    0x42,
+    0xf2,
+    0x2e,
+    0x71,
+    0xaf,
+    0x19,
+    0x31,
+    0x6d,
+    0xec,
+    0xcd,
+    0x6f,
+    0x2b,
+    0x23,
+    0xdf,
+    0xb4,
+    0x40,
+    0xaf,
+    0x2c,
+    0x0a,
+    0xc3,
+    0x1b,
+    0x7d,
+    0x7d,
+    0x03,
+    0x1d,
+    0x4b,
+    0xf3,
+    0xb5,
+    0xe0,
+    0x85,
+    0xd8,
+    0xdf,
+    0x91,
+    0x6b,
+    0x0a,
+    0x69,
+    0xf7,
+    0xf2,
+    0x69,
+    0x66,
+    0x5b,
+    0xf1,
+    0xcf,
+    0x46,
+    0x7d,
+    0xe9,
+    0x70,
+    0xfa,
+    0x6d,
+    0x7e,
+    0x75,
+    0x4e,
+    0xa9,
+    0x77,
+    0xe6,
+    0x8c,
+    0x02,
+    0xf7,
+    0x14,
+    0x4d,
+    0xa5,
+    0x41,
+    0x8f,
+    0x3f,
+    0xc1,
+    0x62,
+    0x1e,
+    0x71,
+    0x5e,
+    0x38,
+    0xb4,
+    0xd6,
+    0xe6,
+    0xe1,
+    0x4b,
+    0xc2,
+    0x2c,
+    0x30,
+    0x83,
+    0x81,
+    0x6f,
+    0x49,
+    0x2e,
+    0x96,
+    0xe6,
+    0xc9,
+    0x9a,
+    0xf7,
+    0x5d,
+    0x09,
+    0xa0,
+    0x55,
+    0x02,
+    0xa5,
+    0x3a,
+    0x25,
+    0x23,
+    0xd0,
+    0x92,
+    0xc3,
+    0xa3,
+    0xe3,
+    0x0e,
+    0x12,
+    0x2f,
+    0x4d,
+    0xef,
+    0xf3,
+    0x55,
+    0x5a,
+    0xbe,
+    0xe6,
+    0x19,
+    0x86,
+    0x31,
+    0xab,
+    0x75,
+    0x9a,
+    0xd3,
+    0xf0,
+    0x2c,
+    0xc5,
+    0x41,
+    0x92,
+    0xd9,
+    0x1f,
+    0x5f,
+    0x11,
+    0x8c,
+    0x75,
+    0x1c,
+    0x63,
+    0xd0,
+    0x02,
+    0x80,
+    0x2c,
+    0x68,
+    0xcb,
+    0x93,
+    0xfb,
+    0x51,
+    0x73,
+    0x49,
+    0xb4,
+    0x60,
+    0xda,
+    0xe2,
+    0x26,
+    0xaf,
+    0xa9,
+    0x46,
+    0x12,
+    0xb8,
+    0xec,
+    0x50,
+    0xdd,
+    0x12,
+    0x06,
+    0x5f,
+    0xce,
+    0x59,
+    0xe6,
+    0xf6,
+    0x1c,
+    0xe0,
+    0x54,
+    0x10,
+    0xad,
+    0xf6,
+    0xcd,
+    0x98,
+    0xcc,
+    0x0f,
+    0xfb,
+    0xcb,
+    0x41,
+    0x14,
+    0x9d,
+    0xed,
+    0xe4,
+    0xb4,
+    0x74,
+    0x5f,
+    0x09,
+    0x60,
+    0xc7,
+    0x12,
+    0xf6,
+    0x7b,
+    0x3c,
+    0x8f,
+    0xa7,
+    0x20,
+    0xbc,
+    0xe4,
+    0xb1,
+    0xef,
+    0xeb,
+    0xa4,
+    0x93,
+    0xc5,
+    0x06,
+    0xca,
+    0x9a,
+    0x27,
+    0x9d,
+    0x87,
+    0xf3,
+    0xde,
+    0xca,
+    0xe5,
+    0xe7,
+    0xf6,
+    0x1c,
+    0x01,
+    0x65,
+    0x5b,
+    0xfb,
+    0x19,
+    0x79,
+    0x6e,
+    0x08,
+    0x26,
+    0xc5,
+    0xc8,
+    0x28,
+    0x0e,
+    0xb6,
+    0x3b,
+    0x07,
+    0x08,
+    0xc1,
+    0x02,
+    0x82,
+    0x01,
+    0x01,
+    0x00,
+    0xe8,
+    0x1c,
+    0x73,
+    0xa6,
+    0xb8,
+    0xe0,
+    0x0e,
+    0x6d,
+    0x8d,
+    0x1b,
+    0xb9,
+    0x53,
+    0xed,
+    0x58,
+    0x94,
+    0xe6,
+    0x1d,
+    0x60,
+    0x14,
+    0x5c,
+    0x76,
+    0x43,
+    0xc4,
+    0x58,
+    0x19,
+    0xc4,
+    0x24,
+    0xe8,
+    0xbc,
+    0x1b,
+    0x3b,
+    0x0b,
+    0x13,
+    0x24,
+    0x45,
+    0x54,
+    0x0e,
+    0xcc,
+    0x37,
+    0xf0,
+    0xe0,
+    0x63,
+    0x7d,
+    0xc3,
+    0xf7,
+    0xfb,
+    0x81,
+    0x74,
+    0x81,
+    0xc4,
+    0x0f,
+    0x1a,
+    0x21,
+    0x48,
+    0xaf,
+    0xce,
+    0xc1,
+    0xc4,
+    0x94,
+    0x18,
+    0x06,
+    0x44,
+    0x8d,
+    0xd3,
+    0xd2,
+    0x22,
+    0x2d,
+    0x2d,
+    0x3e,
+    0x5a,
+    0x31,
+    0xdc,
+    0x95,
+    0x8e,
+    0xf4,
+    0x41,
+    0xfc,
+    0x58,
+    0xc9,
+    0x40,
+    0x92,
+    0x17,
+    0x5f,
+    0xe3,
+    0xda,
+    0xac,
+    0x9e,
+    0x3f,
+    0x1c,
+    0x2a,
+    0x6b,
+    0x58,
+    0x5f,
+    0x48,
+    0x78,
+    0x20,
+    0xb1,
+    0xaf,
+    0x24,
+    0x9b,
+    0x3c,
+    0x20,
+    0x8b,
+    0x93,
+    0x25,
+    0x9e,
+    0xe6,
+    0x6b,
+    0xbc,
+    0x13,
+    0x42,
+    0x14,
+    0x6c,
+    0x36,
+    0x31,
+    0xff,
+    0x7a,
+    0xd1,
+    0xc1,
+    0x1a,
+    0x26,
+    0x14,
+    0x7f,
+    0xa9,
+    0x76,
+    0xa7,
+    0x0c,
+    0xf8,
+    0xcc,
+    0xed,
+    0x07,
+    0x6a,
+    0xd2,
+    0xdf,
+    0x62,
+    0xee,
+    0x0a,
+    0x7c,
+    0x84,
+    0xcb,
+    0x49,
+    0x90,
+    0xb2,
+    0x03,
+    0x0d,
+    0xa2,
+    0x82,
+    0x06,
+    0x77,
+    0xf1,
+    0xcd,
+    0x67,
+    0xf2,
+    0x47,
+    0x21,
+    0x02,
+    0x3f,
+    0x43,
+    0x21,
+    0xf0,
+    0x46,
+    0x30,
+    0x62,
+    0x51,
+    0x72,
+    0xb1,
+    0xe7,
+    0x48,
+    0xc6,
+    0x67,
+    0x12,
+    0xcd,
+    0x9e,
+    0xd6,
+    0x15,
+    0xe5,
+    0x21,
+    0xed,
+    0xfa,
+    0x8f,
+    0x30,
+    0xa6,
+    0x41,
+    0xfe,
+    0xb6,
+    0xfa,
+    0x8f,
+    0x34,
+    0x14,
+    0x19,
+    0xe8,
+    0x11,
+    0xf7,
+    0xa5,
+    0x77,
+    0x3e,
+    0xb7,
+    0xf9,
+    0x39,
+    0x07,
+    0x8c,
+    0x67,
+    0x2a,
+    0xab,
+    0x7b,
+    0x08,
+    0xf8,
+    0xb0,
+    0x06,
+    0xa8,
+    0xea,
+    0x2f,
+    0x8f,
+    0xfa,
+    0xcc,
+    0xcc,
+    0x40,
+    0xce,
+    0xf3,
+    0x70,
+    0x4f,
+    0x3f,
+    0x7f,
+    0xe2,
+    0x0c,
+    0xea,
+    0x76,
+    0x4a,
+    0x35,
+    0x4e,
+    0x47,
+    0xad,
+    0x2b,
+    0xa7,
+    0x97,
+    0x5d,
+    0x74,
+    0x43,
+    0x97,
+    0x90,
+    0xd2,
+    0xfb,
+    0xd9,
+    0xf9,
+    0x96,
+    0x01,
+    0x33,
+    0x05,
+    0xed,
+    0x7b,
+    0x03,
+    0x05,
+    0xad,
+    0xf8,
+    0x49,
+    0x03,
+    0x02,
+    0x82,
+    0x01,
+    0x01,
+    0x00,
+    0xd4,
+    0x40,
+    0x17,
+    0x66,
+    0x10,
+    0x92,
+    0x95,
+    0xc8,
+    0xec,
+    0x62,
+    0xa9,
+    0x7a,
+    0xcb,
+    0x93,
+    0x8e,
+    0xe6,
+    0x53,
+    0xd4,
+    0x80,
+    0x48,
+    0x27,
+    0x4b,
+    0x41,
+    0xce,
+    0x61,
+    0xdf,
+    0xbf,
+    0x94,
+    0xa4,
+    0x3d,
+    0x71,
+    0x03,
+    0x0b,
+    0xed,
+    0x25,
+    0x71,
+    0x98,
+    0xa4,
+    0xd6,
+    0xd5,
+    0x4a,
+    0x57,
+    0xf5,
+    0x6c,
+    0x1b,
+    0xda,
+    0x21,
+    0x7d,
+    0x35,
+    0x45,
+    0xb3,
+    0xf3,
+    0x6a,
+    0xd9,
+    0xd3,
+    0x43,
+    0xe8,
+    0x5c,
+    0x54,
+    0x1c,
+    0x83,
+    0x1b,
+    0xb4,
+    0x5f,
+    0xf2,
+    0x97,
+    0x24,
+    0x2e,
+    0xdc,
+    0x40,
+    0xde,
+    0x92,
+    0x23,
+    0x59,
+    0x8e,
+    0xbc,
+    0xd2,
+    0xa1,
+    0xf2,
+    0xe0,
+    0x4c,
+    0xdd,
+    0x0b,
+    0xd1,
+    0xe7,
+    0xae,
+    0x65,
+    0xbc,
+    0xb5,
+    0xf5,
+    0x5b,
+    0x98,
+    0xe9,
+    0xd7,
+    0xc2,
+    0xb7,
+    0x0e,
+    0x55,
+    0x71,
+    0x0e,
+    0x3c,
+    0x0a,
+    0x24,
+    0x6b,
+    0xa6,
+    0xe6,
+    0x14,
+    0x61,
+    0x11,
+    0xfd,
+    0x33,
+    0x42,
+    0x99,
+    0x2b,
+    0x84,
+    0x77,
+    0x74,
+    0x92,
+    0x91,
+    0xf5,
+    0x79,
+    0x79,
+    0xcf,
+    0xad,
+    0x8e,
+    0x04,
+    0xef,
+    0x80,
+    0x1e,
+    0x57,
+    0xf4,
+    0x14,
+    0xf5,
+    0x35,
+    0x09,
+    0x74,
+    0xb2,
+    0x13,
+    0x71,
+    0x58,
+    0x6b,
+    0xea,
+    0x32,
+    0x5d,
+    0xf3,
+    0xd3,
+    0x76,
+    0x48,
+    0x39,
+    0x10,
+    0x23,
+    0x84,
+    0x9d,
+    0xbe,
+    0x92,
+    0x77,
+    0x4a,
+    0xed,
+    0x70,
+    0x3e,
+    0x1a,
+    0xa2,
+    0x6c,
+    0xb3,
+    0x81,
+    0x00,
+    0xc3,
+    0xc9,
+    0xe4,
+    0x52,
+    0xc8,
+    0x24,
+    0x88,
+    0x0c,
+    0x41,
+    0xad,
+    0x87,
+    0x5a,
+    0xea,
+    0xa3,
+    0x7a,
+    0x85,
+    0x1c,
+    0x5e,
+    0x31,
+    0x7f,
+    0xc3,
+    0x35,
+    0xc6,
+    0xfa,
+    0x10,
+    0xc8,
+    0x75,
+    0x10,
+    0xc4,
+    0x96,
+    0x99,
+    0xe7,
+    0xfe,
+    0x01,
+    0xb4,
+    0x74,
+    0xdb,
+    0xb4,
+    0x11,
+    0xc3,
+    0xc8,
+    0x8c,
+    0xf6,
+    0xf7,
+    0x3b,
+    0x66,
+    0x50,
+    0xfc,
+    0xdb,
+    0xeb,
+    0xca,
+    0x47,
+    0x85,
+    0x89,
+    0xe1,
+    0x65,
+    0xd9,
+    0x62,
+    0x34,
+    0x3c,
+    0x70,
+    0xd8,
+    0x2e,
+    0xb4,
+    0x2f,
+    0x65,
+    0x3c,
+    0x4a,
+    0xa6,
+    0x2a,
+    0xe7,
+    0xc7,
+    0xd8,
+    0x41,
+    0x8f,
+    0x8a,
+    0x43,
+    0xbf,
+    0x42,
+    0xf2,
+    0x4d,
+    0xbc,
+    0xfc,
+    0x9e,
+    0x27,
+    0x95,
+    0xfb,
+    0x75,
+    0xff,
+    0xab,
+    0x02,
+    0x82,
+    0x01,
+    0x00,
+    0x41,
+    0x2f,
+    0x44,
+    0x57,
+    0x6d,
+    0x12,
+    0x17,
+    0x5b,
+    0x32,
+    0xc6,
+    0xb7,
+    0x6c,
+    0x57,
+    0x7a,
+    0x8a,
+    0x0e,
+    0x79,
+    0xef,
+    0x72,
+    0xa8,
+    0x68,
+    0xda,
+    0x2d,
+    0x38,
+    0xe4,
+    0xbb,
+    0x8d,
+    0xf6,
+    0x02,
+    0x65,
+    0xcf,
+    0x56,
+    0x13,
+    0xe1,
+    0x1a,
+    0xcb,
+    0x39,
+    0x80,
+    0xa6,
+    0xb1,
+    0x32,
+    0x03,
+    0x1e,
+    0xdd,
+    0xbb,
+    0x35,
+    0xd9,
+    0xac,
+    0x43,
+    0x89,
+    0x31,
+    0x08,
+    0x90,
+    0x92,
+    0x5e,
+    0x35,
+    0x3d,
+    0x7b,
+    0x9c,
+    0x6f,
+    0x86,
+    0xcb,
+    0x17,
+    0xdd,
+    0x85,
+    0xe4,
+    0xed,
+    0x35,
+    0x08,
+    0x8e,
+    0xc1,
+    0xf4,
+    0x05,
+    0xd8,
+    0x68,
+    0xc6,
+    0x63,
+    0x3c,
+    0xf7,
+    0xff,
+    0xf7,
+    0x47,
+    0x33,
+    0x39,
+    0xc5,
+    0x3e,
+    0xb7,
+    0x0e,
+    0x58,
+    0x35,
+    0x9d,
+    0x81,
+    0xea,
+    0xf8,
+    0x6a,
+    0x2c,
+    0x1c,
+    0x5a,
+    0x68,
+    0x78,
+    0x64,
+    0x11,
+    0x6b,
+    0xc1,
+    0x3e,
+    0x4e,
+    0x7a,
+    0xbd,
+    0x84,
+    0xcb,
+    0x0f,
+    0xc2,
+    0xb6,
+    0x85,
+    0x1d,
+    0xd3,
+    0x76,
+    0xc5,
+    0x93,
+    0x6a,
+    0x69,
+    0x89,
+    0x56,
+    0x34,
+    0xdc,
+    0x4a,
+    0x9b,
+    0xbc,
+    0xff,
+    0xa8,
+    0x0d,
+    0x6e,
+    0x35,
+    0x9c,
+    0x60,
+    0xa7,
+    0x23,
+    0x30,
+    0xc7,
+    0x06,
+    0x64,
+    0x39,
+    0x8b,
+    0x94,
+    0x89,
+    0xee,
+    0xba,
+    0x7f,
+    0x60,
+    0x8d,
+    0xfa,
+    0xb6,
+    0x97,
+    0x76,
+    0xdc,
+    0x51,
+    0x4a,
+    0x3c,
+    0xeb,
+    0x3a,
+    0x14,
+    0x2c,
+    0x20,
+    0x60,
+    0x69,
+    0x4a,
+    0x86,
+    0xfe,
+    0x8c,
+    0x21,
+    0x84,
+    0x49,
+    0x54,
+    0xb3,
+    0x20,
+    0xe1,
+    0x01,
+    0x7f,
+    0x58,
+    0xdf,
+    0x7f,
+    0xb5,
+    0x21,
+    0x51,
+    0x8c,
+    0x47,
+    0x9f,
+    0x91,
+    0xeb,
+    0x97,
+    0x3e,
+    0xf2,
+    0x54,
+    0xcf,
+    0x16,
+    0x46,
+    0xf9,
+    0xd9,
+    0xb6,
+    0xe7,
+    0x64,
+    0xc9,
+    0xd0,
+    0x54,
+    0xea,
+    0x2f,
+    0xa1,
+    0xcf,
+    0xa5,
+    0x7f,
+    0x28,
+    0x8d,
+    0x84,
+    0xec,
+    0xd5,
+    0x39,
+    0x03,
+    0x76,
+    0x5b,
+    0x2d,
+    0x8e,
+    0x43,
+    0xf2,
+    0x01,
+    0x24,
+    0xc9,
+    0x6f,
+    0xc0,
+    0xf5,
+    0x69,
+    0x6f,
+    0x7d,
+    0xb5,
+    0x85,
+    0xd2,
+    0x5f,
+    0x7f,
+    0x78,
+    0x40,
+    0x07,
+    0x7f,
+    0x09,
+    0x15,
+    0xb5,
+    0x1f,
+    0x28,
+    0x65,
+    0x10,
+    0xe4,
+    0x19,
+    0xa8,
+    0xc6,
+    0x9e,
+    0x8d,
+    0xdc,
+    0xcb,
+    0x02,
+    0x82,
+    0x01,
+    0x00,
+    0x13,
+    0x01,
+    0xee,
+    0x56,
+    0x80,
+    0x93,
+    0x70,
+    0x00,
+    0x7f,
+    0x52,
+    0xd2,
+    0x94,
+    0xa1,
+    0x98,
+    0x84,
+    0x4a,
+    0x92,
+    0x25,
+    0x4c,
+    0x9b,
+    0xa9,
+    0x91,
+    0x2e,
+    0xc2,
+    0x79,
+    0xb7,
+    0x5c,
+    0xe3,
+    0xc5,
+    0xd5,
+    0x8e,
+    0xc2,
+    0x54,
+    0x16,
+    0x17,
+    0xad,
+    0x55,
+    0x9b,
+    0x25,
+    0x76,
+    0x12,
+    0x63,
+    0x50,
+    0x22,
+    0x2f,
+    0x58,
+    0x58,
+    0x79,
+    0x6b,
+    0x04,
+    0xe3,
+    0xf9,
+    0x9f,
+    0x8f,
+    0x04,
+    0x41,
+    0x67,
+    0x94,
+    0xa5,
+    0x1f,
+    0xac,
+    0x8a,
+    0x15,
+    0x9c,
+    0x26,
+    0x10,
+    0x6c,
+    0xf8,
+    0x19,
+    0x57,
+    0x61,
+    0xd7,
+    0x3a,
+    0x7d,
+    0x31,
+    0xb0,
+    0x2d,
+    0x38,
+    0xbd,
+    0x94,
+    0x62,
+    0xad,
+    0xc4,
+    0xfa,
+    0x36,
+    0x42,
+    0x42,
+    0xf0,
+    0x24,
+    0x67,
+    0x65,
+    0x9d,
+    0x8b,
+    0x0b,
+    0x7c,
+    0x6f,
+    0x82,
+    0x44,
+    0x1a,
+    0x8c,
+    0xc8,
+    0xc9,
+    0xab,
+    0xbb,
+    0x4c,
+    0x45,
+    0xfc,
+    0x7b,
+    0x38,
+    0xee,
+    0x30,
+    0xe1,
+    0xfc,
+    0xef,
+    0x8d,
+    0xbc,
+    0x58,
+    0xdf,
+    0x2b,
+    0x5d,
+    0x0d,
+    0x54,
+    0xe0,
+    0x49,
+    0x4d,
+    0x97,
+    0x99,
+    0x8f,
+    0x22,
+    0xa8,
+    0x83,
+    0xbe,
+    0x40,
+    0xbb,
+    0x50,
+    0x2e,
+    0x78,
+    0x28,
+    0x0f,
+    0x95,
+    0x78,
+    0x8c,
+    0x8f,
+    0x98,
+    0x24,
+    0x56,
+    0xc2,
+    0x97,
+    0xf3,
+    0x2c,
+    0x43,
+    0xd2,
+    0x03,
+    0x82,
+    0x66,
+    0x81,
+    0x72,
+    0x5f,
+    0x53,
+    0x16,
+    0xec,
+    0xb1,
+    0xb1,
+    0x04,
+    0x5e,
+    0x40,
+    0x20,
+    0x48,
+    0x7b,
+    0x3f,
+    0x02,
+    0x97,
+    0x6a,
+    0xeb,
+    0x96,
+    0x12,
+    0x21,
+    0x35,
+    0xfe,
+    0x1f,
+    0x47,
+    0xc0,
+    0x95,
+    0xea,
+    0xc5,
+    0x8a,
+    0x08,
+    0x84,
+    0x4f,
+    0x5e,
+    0x63,
+    0x94,
+    0x60,
+    0x0f,
+    0x71,
+    0x5b,
+    0x7f,
+    0x4a,
+    0xec,
+    0x4f,
+    0x60,
+    0xc6,
+    0xba,
+    0x4a,
+    0x24,
+    0xf1,
+    0x20,
+    0x8b,
+    0xa7,
+    0x2e,
+    0x3a,
+    0xce,
+    0x8d,
+    0xe0,
+    0x27,
+    0x1d,
+    0xb5,
+    0x8e,
+    0xb4,
+    0x21,
+    0xc5,
+    0xe2,
+    0xa6,
+    0x16,
+    0x0a,
+    0x51,
+    0x83,
+    0x55,
+    0x88,
+    0xd1,
+    0x30,
+    0x11,
+    0x63,
+    0xd5,
+    0xd7,
+    0x8d,
+    0xae,
+    0x16,
+    0x12,
+    0x82,
+    0xc4,
+    0x85,
+    0x00,
+    0x4e,
+    0x27,
+    0x83,
+    0xa5,
+    0x7c,
+    0x90,
+    0x2e,
+    0xe5,
+    0xa2,
+    0xa3,
+    0xd3,
+    0x4c,
+    0x63,
+    0x02,
+    0x82,
+    0x01,
+    0x01,
+    0x00,
+    0x86,
+    0x08,
+    0x98,
+    0x98,
+    0xa5,
+    0x00,
+    0x05,
+    0x39,
+    0x77,
+    0xd9,
+    0x66,
+    0xb3,
+    0xcf,
+    0xca,
+    0xa0,
+    0x71,
+    0xb3,
+    0x50,
+    0xce,
+    0x3d,
+    0xb1,
+    0x93,
+    0x95,
+    0x35,
+    0xc4,
+    0xd4,
+    0x2e,
+    0x90,
+    0xdf,
+    0x0f,
+    0xfc,
+    0x60,
+    0xc1,
+    0x94,
+    0x68,
+    0x61,
+    0x43,
+    0xca,
+    0x9a,
+    0x23,
+    0x4a,
+    0x1e,
+    0x45,
+    0x72,
+    0x99,
+    0xb5,
+    0x1e,
+    0x61,
+    0x8d,
+    0x77,
+    0x0f,
+    0xa0,
+    0xbb,
+    0xd7,
+    0x77,
+    0xb4,
+    0x2a,
+    0x15,
+    0x11,
+    0x88,
+    0x2d,
+    0xb3,
+    0x56,
+    0x61,
+    0x5e,
+    0x6a,
+    0xed,
+    0xa4,
+    0x46,
+    0x4a,
+    0x3f,
+    0x50,
+    0x11,
+    0xd6,
+    0xba,
+    0xb6,
+    0xd7,
+    0x95,
+    0x65,
+    0x53,
+    0xc3,
+    0xa1,
+    0x8f,
+    0xe0,
+    0xa3,
+    0xf5,
+    0x1c,
+    0xfd,
+    0xaf,
+    0x6e,
+    0x43,
+    0xd7,
+    0x17,
+    0xa7,
+    0xd3,
+    0x81,
+    0x1b,
+    0xa4,
+    0xdf,
+    0xe0,
+    0x97,
+    0x8a,
+    0x46,
+    0x03,
+    0xd3,
+    0x46,
+    0x0e,
+    0x83,
+    0x48,
+    0x4e,
+    0xd2,
+    0x02,
+    0xcb,
+    0xc0,
+    0xad,
+    0x79,
+    0x95,
+    0x8c,
+    0x96,
+    0xba,
+    0x40,
+    0x34,
+    0x11,
+    0x71,
+    0x5e,
+    0xe9,
+    0x11,
+    0xf9,
+    0xc5,
+    0x4a,
+    0x5e,
+    0x91,
+    0x9d,
+    0xf5,
+    0x92,
+    0x4f,
+    0xeb,
+    0xc6,
+    0x70,
+    0x02,
+    0x2d,
+    0x3d,
+    0x04,
+    0xaa,
+    0xe9,
+    0x3a,
+    0x8e,
+    0xd5,
+    0xa8,
+    0xad,
+    0xf7,
+    0xce,
+    0x0d,
+    0x16,
+    0xb2,
+    0xec,
+    0x0a,
+    0x9c,
+    0xf5,
+    0x94,
+    0x39,
+    0xb9,
+    0x8a,
+    0xfc,
+    0x1e,
+    0xf9,
+    0xcc,
+    0xf2,
+    0x5f,
+    0x21,
+    0x31,
+    0x74,
+    0x72,
+    0x6b,
+    0x64,
+    0xae,
+    0x35,
+    0x61,
+    0x8d,
+    0x0d,
+    0xcb,
+    0xe7,
+    0xda,
+    0x39,
+    0xca,
+    0xf3,
+    0x21,
+    0x66,
+    0x0b,
+    0x95,
+    0xd7,
+    0x0a,
+    0x7c,
+    0xca,
+    0xa1,
+    0xa9,
+    0x5a,
+    0xe8,
+    0xac,
+    0xe0,
+    0x71,
+    0x54,
+    0xaf,
+    0x28,
+    0xcf,
+    0xd5,
+    0x70,
+    0x89,
+    0xe0,
+    0xf3,
+    0x9e,
+    0x43,
+    0x6c,
+    0x8d,
+    0x7b,
+    0x99,
+    0x01,
+    0x68,
+    0x4d,
+    0xa1,
+    0x45,
+    0x46,
+    0x0c,
+    0x43,
+    0xbc,
+    0xcc,
+    0x2c,
+    0xdd,
+    0xc5,
+    0x46,
+    0xc8,
+    0x4e,
+    0x0e,
+    0xbe,
+    0xed,
+    0xb9,
+    0x26,
+    0xab,
+    0x2e,
+    0xdb,
+    0xeb,
+    0x8f,
+    0xff,
+    0xdb,
+    0xb0,
+    0xc6,
+    0x55,
+    0xaf,
+    0xf8,
+    0x2a,
+    0x91,
+    0x9d,
+    0x50,
+    0x44,
+    0x21,
+    0x17,
 };
 
 static unsigned char test7680[] = {
@@ -1961,5 +5976,3 @@ static unsigned char test15360[] = {
     0x91, 0x29, 0x6e, 0x08, 0x37, 0xd6, 0xaa, 0xd2, 0xf8, 0x4f,
     0x5e, 0x00, 0x16, 0x52
 };
-
-#endif /* !defined(OSSL_APPS_TESTRSA_H) */
diff --git a/apps/ts.c b/apps/ts.c
index 2049eb9331..ef2c717966 100644
--- a/apps/ts.c
+++ b/apps/ts.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -114,9 +114,9 @@ const OPTIONS ts_options[] = {
     { "inkey", OPT_INKEY, 's', "File with private key for reply" },
     { "signer", OPT_SIGNER, 's', "Signer certificate file" },
     { "chain", OPT_CHAIN, '<', "File with signer CA chain" },
-    { "CAfile", OPT_CAFILE, '<', "File in PEM format with trusted CA certs" },
-    { "CApath", OPT_CAPATH, '/', "Dir with trusted CA cert files in PEM format" },
-    { "CAstore", OPT_CASTORE, ':', "URI of store with trusted CA certs" },
+    { "CAfile", OPT_CAFILE, '<', "File with trusted CA certs" },
+    { "CApath", OPT_CAPATH, '/', "Path to trusted CA files" },
+    { "CAstore", OPT_CASTORE, ':', "URI to trusted CA store" },
     { "untrusted", OPT_UNTRUSTED, '<', "Extra untrusted certs" },
     { "token_in", OPT_TOKEN_IN, '-', "Input is a PKCS#7 file" },
     { "token_out", OPT_TOKEN_OUT, '-', "Output is a PKCS#7 file" },
@@ -311,12 +311,10 @@ int ts_main(int argc, char **argv)
     if (!app_RAND_load())
         goto end;
 
-    if (digestname == NULL)
-        digestname = "sha256";
     if (!opt_md(digestname, &md))
         goto opthelp;
     if (mode == OPT_REPLY && passin && !app_passwd(passin, NULL, &password, NULL)) {
-        BIO_puts(bio_err, "Error getting password.\n");
+        BIO_printf(bio_err, "Error getting password.\n");
         goto end;
     }
 
@@ -339,7 +337,7 @@ int ts_main(int argc, char **argv)
         if ((in != NULL) && (queryfile != NULL))
             goto opthelp;
         if (in == NULL) {
-            if (conf == NULL || token_in != 0 || queryfile == NULL)
+            if ((conf == NULL) || (token_in != 0))
                 goto opthelp;
         }
         ret = !reply_command(conf, section, queryfile,
@@ -464,6 +462,8 @@ static TS_REQ *create_query(BIO *data_bio, const char *digest, const EVP_MD *md,
     ASN1_OBJECT *policy_obj = NULL;
     ASN1_INTEGER *nonce_asn1 = NULL;
 
+    if (md == NULL && (md = EVP_get_digestbyname("sha256")) == NULL)
+        goto err;
     if ((ts_req = TS_REQ_new()) == NULL)
         goto err;
     if (!TS_REQ_set_version(ts_req, 1))
@@ -503,7 +503,7 @@ err:
     if (!ret) {
         TS_REQ_free(ts_req);
         ts_req = NULL;
-        BIO_puts(bio_err, "could not create query\n");
+        BIO_printf(bio_err, "could not create query\n");
         ERR_print_errors(bio_err);
     }
     TS_MSG_IMPRINT_free(msg_imprint);
@@ -567,33 +567,30 @@ err:
 static ASN1_INTEGER *create_nonce(int bits)
 {
     unsigned char buf[20];
-    ASN1_INTEGER *ret = NULL;
     ASN1_INTEGER *nonce = NULL;
     int len = (bits - 1) / 8 + 1;
+    int i;
 
     if (len > (int)sizeof(buf))
         goto err;
+    if (RAND_bytes(buf, len) <= 0)
+        goto err;
 
-    /* Make a random nonce with a non-zero first byte */
-    do {
-        if (RAND_bytes(buf, len) <= 0)
-            goto err;
-    } while (!buf[0]);
-
+    /* Find the first non-zero byte and creating ASN1_INTEGER object. */
+    for (i = 0; i < len && !buf[i]; ++i)
+        continue;
     if ((nonce = ASN1_INTEGER_new()) == NULL)
         goto err;
-
-    if (!ASN1_STRING_set_data(nonce, buf, len))
-        goto err;
-
-    ret = nonce;
-    nonce = NULL;
+    OPENSSL_free(nonce->data);
+    nonce->length = len - i;
+    nonce->data = app_malloc(nonce->length + 1, "nonce buffer");
+    memcpy(nonce->data, buf + i, nonce->length);
+    return nonce;
 
 err:
-    if (ret == NULL)
-        BIO_puts(bio_err, "could not create nonce\n");
+    BIO_printf(bio_err, "could not create nonce\n");
     ASN1_INTEGER_free(nonce);
-    return ret;
+    return NULL;
 }
 
 /*
@@ -626,9 +623,9 @@ static int reply_command(CONF *conf, const char *section,
         response = create_response(conf, section, queryfile,
             passin, inkey, md, signer, chain, policy);
         if (response != NULL)
-            BIO_puts(bio_err, "Response has been generated.\n");
+            BIO_printf(bio_err, "Response has been generated.\n");
         else
-            BIO_puts(bio_err, "Response is not generated.\n");
+            BIO_printf(bio_err, "Response is not generated.\n");
     }
     if (response == NULL)
         goto end;
@@ -939,7 +936,7 @@ static TS_VERIFY_CTX *create_verify_ctx(const char *data, const char *digest,
             unsigned char *hexstr = OPENSSL_hexstr2buf(digest, &imprint_len);
             f |= TS_VFY_IMPRINT;
             if (!TS_VERIFY_CTX_set0_imprint(ctx, hexstr, imprint_len)) {
-                BIO_puts(bio_err, "invalid digest string\n");
+                BIO_printf(bio_err, "invalid digest string\n");
                 goto err;
             }
         }
@@ -991,14 +988,14 @@ static X509_STORE *create_cert_store(const char *CApath, const char *CAfile,
 
     cert_ctx = X509_STORE_new();
     if (cert_ctx == NULL) {
-        BIO_puts(bio_err, "memory allocation failure\n");
+        BIO_printf(bio_err, "memory allocation failure\n");
         return NULL;
     }
     X509_STORE_set_verify_cb(cert_ctx, verify_cb);
     if (CApath != NULL) {
         lookup = X509_STORE_add_lookup(cert_ctx, X509_LOOKUP_hash_dir());
         if (lookup == NULL) {
-            BIO_puts(bio_err, "memory allocation failure\n");
+            BIO_printf(bio_err, "memory allocation failure\n");
             goto err;
         }
         if (X509_LOOKUP_add_dir(lookup, CApath, X509_FILETYPE_PEM) <= 0) {
@@ -1010,7 +1007,7 @@ static X509_STORE *create_cert_store(const char *CApath, const char *CAfile,
     if (CAfile != NULL) {
         lookup = X509_STORE_add_lookup(cert_ctx, X509_LOOKUP_file());
         if (lookup == NULL) {
-            BIO_puts(bio_err, "memory allocation failure\n");
+            BIO_printf(bio_err, "memory allocation failure\n");
             goto err;
         }
         if (X509_LOOKUP_load_file_ex(lookup, CAfile, X509_FILETYPE_PEM, libctx,
@@ -1024,7 +1021,7 @@ static X509_STORE *create_cert_store(const char *CApath, const char *CAfile,
     if (CAstore != NULL) {
         lookup = X509_STORE_add_lookup(cert_ctx, X509_LOOKUP_store());
         if (lookup == NULL) {
-            BIO_puts(bio_err, "memory allocation failure\n");
+            BIO_printf(bio_err, "memory allocation failure\n");
             goto err;
         }
         if (X509_LOOKUP_add_store_ex(lookup, CAstore, libctx, propq) <= 0) {
diff --git a/apps/verify.c b/apps/verify.c
index d16ccbaac0..c1d50ba4b7 100644
--- a/apps/verify.c
+++ b/apps/verify.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2022 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -56,9 +56,9 @@ const OPTIONS verify_options[] = {
 
     OPT_SECTION("Certificate chain"),
     { "trusted", OPT_TRUSTED, '<', "A file of trusted certificates" },
-    { "CAfile", OPT_CAFILE, '<', "File in PEM format with trusted CA certs" },
-    { "CApath", OPT_CAPATH, '/', "Dir with trusted CA cert files in PEM format" },
-    { "CAstore", OPT_CASTORE, ':', "URI of store with trusted CA certs" },
+    { "CAfile", OPT_CAFILE, '<', "A file of trusted certificates" },
+    { "CApath", OPT_CAPATH, '/', "A directory of files with trusted certificates" },
+    { "CAstore", OPT_CASTORE, ':', "URI to a store of trusted certificates" },
     { "no-CAfile", OPT_NOCAFILE, '-',
         "Do not load the default trusted certificates file" },
     { "no-CApath", OPT_NOCAPATH, '-',
@@ -108,7 +108,7 @@ int verify_main(int argc, char **argv)
             goto end;
         case OPT_HELP:
             opt_help(verify_options);
-            BIO_puts(bio_err, "\nRecognized certificate chain purposes:\n");
+            BIO_printf(bio_err, "\nRecognized certificate chain purposes:\n");
             for (i = 0; i < X509_PURPOSE_get_count(); i++) {
                 X509_PURPOSE *ptmp = X509_PURPOSE_get0(i);
 
@@ -117,7 +117,7 @@ int verify_main(int argc, char **argv)
                     X509_PURPOSE_get0_name(ptmp));
             }
 
-            BIO_puts(bio_err, "Recognized certificate policy names:\n");
+            BIO_printf(bio_err, "Recognized certificate policy names:\n");
             for (i = 0; i < X509_VERIFY_PARAM_get_count(); i++) {
                 const X509_VERIFY_PARAM *vptmp = X509_VERIFY_PARAM_get0(i);
 
@@ -299,7 +299,7 @@ static int check(X509_STORE *ctx, const char *file,
 
             chain = X509_STORE_CTX_get1_chain(csc);
             num_untrusted = X509_STORE_CTX_get_num_untrusted(csc);
-            BIO_puts(bio_out, "Chain:\n");
+            BIO_printf(bio_out, "Chain:\n");
             for (j = 0; j < sk_X509_num(chain); j++) {
                 X509 *cert = sk_X509_value(chain, j);
                 BIO_printf(bio_out, "depth=%d: ", j);
@@ -307,8 +307,8 @@ static int check(X509_STORE *ctx, const char *file,
                     X509_get_subject_name(cert),
                     0, get_nameopt());
                 if (j < num_untrusted)
-                    BIO_puts(bio_out, " (untrusted)");
-                BIO_puts(bio_out, "\n");
+                    BIO_printf(bio_out, " (untrusted)");
+                BIO_printf(bio_out, "\n");
             }
             OSSL_STACK_OF_X509_free(chain);
         }
@@ -330,14 +330,14 @@ end:
 static int cb(int ok, X509_STORE_CTX *ctx)
 {
     int cert_error = X509_STORE_CTX_get_error(ctx);
-    const X509 *current_cert = X509_STORE_CTX_get_current_cert(ctx);
+    X509 *current_cert = X509_STORE_CTX_get_current_cert(ctx);
 
     if (!ok) {
         if (current_cert != NULL) {
             X509_NAME_print_ex(bio_err,
                 X509_get_subject_name(current_cert),
                 0, get_nameopt());
-            BIO_puts(bio_err, "\n");
+            BIO_printf(bio_err, "\n");
         }
         BIO_printf(bio_err, "%serror %d at %d depth lookup: %s\n",
             X509_STORE_CTX_get0_parent_ctx(ctx) ? "[CRL path] " : "",
diff --git a/apps/x509.c b/apps/x509.c
index 867961e61d..41e9204087 100644
--- a/apps/x509.c
+++ b/apps/x509.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -197,7 +197,7 @@ const OPTIONS x509_options[] = {
         "[CC]YYMMDDHHMMSSZ value for notBefore certificate field" },
     { "not_after", OPT_NOT_AFTER, 's',
         "[CC]YYMMDDHHMMSSZ value for notAfter certificate field, overrides -days" },
-    { "days", OPT_DAYS, 'p',
+    { "days", OPT_DAYS, 'n',
         "Number of days until newly generated certificate expires - default 30" },
     { "preserve_dates", OPT_PRESERVE_DATES, '-',
         "Preserve existing validity dates" },
@@ -274,7 +274,7 @@ static X509_REQ *x509_to_req(X509 *cert, int ext_copy, const char *names)
         goto err;
     for (i = 0; i < n; i++) {
         X509_EXTENSION *ex = sk_X509_EXTENSION_value(cert_exts, i);
-        const ASN1_OBJECT *obj = X509_EXTENSION_get_object(ex);
+        ASN1_OBJECT *obj = X509_EXTENSION_get_object(ex);
 
         if (OBJ_cmp(obj, skid) != 0 && OBJ_cmp(obj, akid) != 0
             && !sk_X509_EXTENSION_push(exts, ex))
@@ -284,7 +284,7 @@ static X509_REQ *x509_to_req(X509 *cert, int ext_copy, const char *names)
     if (sk_X509_EXTENSION_num(exts) > 0) {
         if (ext_copy != EXT_COPY_UNSET && ext_copy != EXT_COPY_NONE
             && !X509_REQ_add_extensions(req, exts)) {
-            BIO_puts(bio_err, "Error copying extensions from certificate\n");
+            BIO_printf(bio_err, "Error copying extensions from certificate\n");
             goto err;
         }
     }
@@ -303,7 +303,7 @@ static int self_signed(X509_STORE *ctx, X509 *cert)
     int ret = 0;
 
     if (xsc == NULL || !X509_STORE_CTX_init(xsc, ctx, cert, NULL)) {
-        BIO_puts(bio_err, "Error initialising X509 store\n");
+        BIO_printf(bio_err, "Error initialising X509 store\n");
     } else {
         X509_STORE_CTX_set_flags(xsc, X509_V_FLAG_CHECK_SS_SIGNATURE);
         ret = X509_verify_cert(xsc) > 0;
@@ -312,68 +312,17 @@ static int self_signed(X509_STORE *ctx, X509 *cert)
     return ret;
 }
 
-static int add_object(STACK_OF(ASN1_OBJECT) **sk, const char *name,
-    const char *desc, const char *prog)
-{
-    ASN1_OBJECT *obj = NULL;
-
-    if (*sk == NULL && (*sk = sk_ASN1_OBJECT_new_null()) == NULL)
-        return 0;
-    if ((obj = OBJ_txt2obj(name, 0)) == NULL) {
-        BIO_printf(bio_err, "%s: Unknown %s object value: %s\n", prog, desc, name);
-        return 0;
-    }
-    if (sk_ASN1_OBJECT_push(*sk, obj) != 0)
-        return 1;
-
-    ASN1_OBJECT_free(obj);
-    return 0;
-}
-
-static CONF *load_ext_conf(const char *file, const char *sect, int quiet)
-{
-    BIO *bio = NULL;
-    CONF *conf;
-
-    if (file == NULL)
-        file = default_config_file;
-    if (file != NULL && *file != '\0')
-        bio = bio_open_default_quiet(file, 'r', FORMAT_TEXT);
-    else if (!quiet) {
-        BIO_puts(bio_err, "The -extfile option, or else the default "
-                          "configuration filename must be nonempty");
-        return NULL;
-    }
-
-    if (bio == NULL) {
-        if (!quiet)
-            BIO_printf(bio_err, "Error opening: %s\n", file);
-        return NULL;
-    }
-
-    conf = NCONF_new_ex(app_get0_libctx(), NULL);
-    if (conf != NULL && NCONF_load_bio(conf, bio, NULL) <= 0) {
-        NCONF_free(conf);
-        conf = NULL;
-    }
-    BIO_free(bio);
-    if (conf != NULL)
-        return conf;
-    if (!quiet)
-        BIO_printf(bio_err, "Error loading configuration from: %s\n", file);
-    return conf;
-}
-
 int x509_main(int argc, char **argv)
 {
     ASN1_INTEGER *sno = NULL;
+    ASN1_OBJECT *objtmp = NULL;
     BIO *out = NULL;
     CONF *extconf = NULL;
     int ext_copy = EXT_COPY_UNSET;
     X509V3_CTX ext_ctx;
     EVP_PKEY *privkey = NULL, *CAkey = NULL, *pubkey = NULL;
     EVP_PKEY *pkey;
-    int newcert = 0, newout = 0;
+    int newcert = 0;
     char *issu = NULL, *subj = NULL, *digest = NULL;
     X509_NAME *fissu = NULL, *fsubj = NULL;
     const unsigned long chtype = MBSTRING_ASC;
@@ -492,7 +441,7 @@ int x509_main(int argc, char **argv)
             not_after = opt_arg();
             break;
         case OPT_DAYS:
-            days = opt_int_arg();
+            days = atoi(opt_arg());
             if (days <= UNSET_DAYS) {
                 BIO_printf(bio_err, "%s: -days parameter arg must be >= -1\n",
                     prog);
@@ -531,7 +480,7 @@ int x509_main(int argc, char **argv)
             break;
         case OPT_SET_SERIAL:
             if (sno != NULL) {
-                BIO_puts(bio_err, "Serial number supplied twice\n");
+                BIO_printf(bio_err, "Serial number supplied twice\n");
                 goto opthelp;
             }
             if ((sno = s2i_ASN1_INTEGER(NULL, opt_arg())) == NULL)
@@ -550,13 +499,27 @@ int x509_main(int argc, char **argv)
             subj = opt_arg();
             break;
         case OPT_ADDTRUST:
-            if (!add_object(&trust, opt_arg(), "trust", prog))
-                goto end;
+            if (trust == NULL && (trust = sk_ASN1_OBJECT_new_null()) == NULL)
+                goto err;
+            if ((objtmp = OBJ_txt2obj(opt_arg(), 0)) == NULL) {
+                BIO_printf(bio_err, "%s: Invalid trust object value %s\n",
+                    prog, opt_arg());
+                goto opthelp;
+            }
+            if (!sk_ASN1_OBJECT_push(trust, objtmp))
+                goto err;
             trustout = 1;
             break;
         case OPT_ADDREJECT:
-            if (!add_object(&reject, opt_arg(), "reject", prog))
-                goto end;
+            if (reject == NULL && (reject = sk_ASN1_OBJECT_new_null()) == NULL)
+                goto err;
+            if ((objtmp = OBJ_txt2obj(opt_arg(), 0)) == NULL) {
+                BIO_printf(bio_err, "%s: Invalid reject object value %s\n",
+                    prog, opt_arg());
+                goto opthelp;
+            }
+            if (!sk_ASN1_OBJECT_push(reject, objtmp))
+                goto err;
             trustout = 1;
             break;
         case OPT_SETALIAS:
@@ -713,48 +676,25 @@ int x509_main(int argc, char **argv)
     if (!opt_check_md(digest))
         goto opthelp;
 
-    if (reqfile || newcert || privkey != NULL || CAfile != NULL)
-        newout = 1;
-    else if (sno != NULL
-        || not_before != NULL
-        || not_after != NULL
-        || days != UNSET_DAYS
-        || preserve_dates
-        || issu != NULL
-        || subj != NULL
-        || pubkeyfile != NULL
-        || clrext
-        || extfile != NULL
-        || extsect != NULL
-        || sigopts != NULL) {
-        BIO_printf(bio_err,
-            "The %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s, %s and %s "
-            "options are only valid when signing a new certificate\n",
-            "set_serial", "not_before", "not_after", "days",
-            "preserve_dates", "set_issuer", "set_subject", "subj",
-            "force_pubkey", "clrext", "extfile", "extensions", "sigopt");
-        goto err;
-    }
-
     if (preserve_dates && not_before != NULL) {
-        BIO_puts(bio_err, "Cannot use -preserve_dates with -not_before option\n");
+        BIO_printf(bio_err, "Cannot use -preserve_dates with -not_before option\n");
         goto err;
     }
     if (preserve_dates && not_after != NULL) {
-        BIO_puts(bio_err, "Cannot use -preserve_dates with -not_after option\n");
+        BIO_printf(bio_err, "Cannot use -preserve_dates with -not_after option\n");
         goto err;
     }
     if (preserve_dates && days != UNSET_DAYS) {
-        BIO_puts(bio_err, "Cannot use -preserve_dates with -days option\n");
+        BIO_printf(bio_err, "Cannot use -preserve_dates with -days option\n");
         goto err;
     }
     if (days == UNSET_DAYS)
         days = DEFAULT_DAYS;
     else if (not_after != NULL)
-        BIO_puts(bio_err, "Warning: -not_after option overriding -days option\n");
+        BIO_printf(bio_err, "Warning: -not_after option overriding -days option\n");
 
     if (!app_passwd(passinarg, NULL, &passin, NULL)) {
-        BIO_puts(bio_err, "Error getting password\n");
+        BIO_printf(bio_err, "Error getting password\n");
         goto err;
     }
 
@@ -763,11 +703,11 @@ int x509_main(int argc, char **argv)
         goto err;
 
     if (newcert && infile != NULL) {
-        BIO_puts(bio_err, "The -in option cannot be used with -new\n");
+        BIO_printf(bio_err, "The -in option cannot be used with -new\n");
         goto err;
     }
     if (newcert && reqfile) {
-        BIO_puts(bio_err, "The -req option cannot be used with -new\n");
+        BIO_printf(bio_err, "The -req option cannot be used with -new\n");
         goto err;
     }
     if (privkeyfile != NULL) {
@@ -784,12 +724,12 @@ int x509_main(int argc, char **argv)
 
     if (newcert) {
         if (subj == NULL) {
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "The -new option requires a subject to be set using -subj\n");
             goto err;
         }
         if (privkeyfile == NULL && pubkeyfile == NULL) {
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "The -new option requires using the -key or -force_pubkey option\n");
             goto err;
         }
@@ -805,11 +745,11 @@ int x509_main(int argc, char **argv)
         CAkeyfile = CAfile;
     if (CAfile != NULL) {
         if (privkeyfile != NULL) {
-            BIO_puts(bio_err, "Cannot use both -key/-signkey and -CA option\n");
+            BIO_printf(bio_err, "Cannot use both -key/-signkey and -CA option\n");
             goto err;
         }
     } else {
-#define WARN_NO_CA(opt) BIO_puts(bio_err, \
+#define WARN_NO_CA(opt) BIO_printf(bio_err, \
     "Warning: ignoring " opt " option since -CA option is not given\n");
         if (CAkeyfile != NULL)
             WARN_NO_CA("-CAkey");
@@ -823,39 +763,37 @@ int x509_main(int argc, char **argv)
             WARN_NO_CA("-CAcreateserial");
     }
 
-    /*
-     * Failure to find or process the default config file is silent, when no
-     * `-extensions` was specified.  Otherwise, the requested extensions
-     * section must be present.
-     */
-    int confquiet = extsect == NULL && extfile == NULL;
-    if (newout)
-        extconf = load_ext_conf(extfile, extsect, confquiet);
-
-    if (extconf != NULL) {
+    if (extfile == NULL) {
+        if (extsect != NULL)
+            BIO_printf(bio_err,
+                "Warning: ignoring -extensions option without -extfile\n");
+    } else {
         X509V3_CTX ctx2;
 
+        if ((extconf = app_load_config(extfile)) == NULL)
+            goto err;
         if (extsect == NULL) {
             extsect = app_conf_try_string(extconf, "default", "extensions");
-            if (extfile != NULL && extsect == NULL)
+            if (extsect == NULL)
                 extsect = "default";
         }
         X509V3_set_ctx_test(&ctx2);
-        if (!do_EXT_add_nconf(extconf, extconf, &ctx2, NULL,
-                "Error checking extension section %s\n", extsect))
+        X509V3_set_nconf(&ctx2, extconf);
+        if (!X509V3_EXT_add_nconf(extconf, &ctx2, extsect, NULL)) {
+            BIO_printf(bio_err,
+                "Error checking extension section %s\n", extsect);
             goto err;
-    } else if (newout && !confquiet) {
-        goto err;
+        }
     }
 
     if (multi && (reqfile || newcert)) {
-        BIO_puts(bio_err, "Error: -multi cannot be used with -req or -new\n");
+        BIO_printf(bio_err, "Error: -multi cannot be used with -req or -new\n");
         goto err;
     }
 
     if (reqfile) {
         if (infile == NULL && isatty(fileno_stdin()))
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "Warning: Reading cert request from stdin since no -in option is given\n");
         req = load_csr_autofmt(infile, informat, vfyopts,
             "certificate request input");
@@ -863,28 +801,28 @@ int x509_main(int argc, char **argv)
             goto err;
 
         if ((pkey = X509_REQ_get0_pubkey(req)) == NULL) {
-            BIO_puts(bio_err, "Error unpacking public key from CSR\n");
+            BIO_printf(bio_err, "Error unpacking public key from CSR\n");
             goto err;
         }
         i = do_X509_REQ_verify(req, pkey, vfyopts);
         if (i <= 0) {
-            BIO_puts(bio_err, i < 0 ? "Error while verifying certificate request self-signature\n" : "Certificate request self-signature did not match the contents\n");
+            BIO_printf(bio_err, i < 0 ? "Error while verifying certificate request self-signature\n" : "Certificate request self-signature did not match the contents\n");
             goto err;
         }
-        BIO_puts(bio_err, "Certificate request self-signature ok\n");
+        BIO_printf(bio_err, "Certificate request self-signature ok\n");
 
         print_name(bio_err, "subject=", X509_REQ_get_subject_name(req));
     } else if (!x509toreq && ext_copy != EXT_COPY_UNSET) {
-        BIO_puts(bio_err, "Warning: ignoring -copy_extensions since neither -x509toreq nor -req is given\n");
+        BIO_printf(bio_err, "Warning: ignoring -copy_extensions since neither -x509toreq nor -req is given\n");
     }
 
     if (reqfile || newcert) {
         if (preserve_dates)
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "Warning: ignoring -preserve_dates option with -req or -new\n");
         preserve_dates = 0;
         if (privkeyfile == NULL && CAkeyfile == NULL) {
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "We need a private key to sign with, use -key or -CAkey or -CA with private key\n");
             goto err;
         }
@@ -897,16 +835,16 @@ int x509_main(int argc, char **argv)
         }
         if (req != NULL && ext_copy != EXT_COPY_UNSET) {
             if (clrext && ext_copy != EXT_COPY_NONE) {
-                BIO_puts(bio_err, "Must not use -clrext together with -copy_extensions\n");
+                BIO_printf(bio_err, "Must not use -clrext together with -copy_extensions\n");
                 goto err;
             } else if (!copy_extensions(x, req, ext_copy)) {
-                BIO_puts(bio_err, "Error copying extensions from request\n");
+                BIO_printf(bio_err, "Error copying extensions from request\n");
                 goto err;
             }
         }
     } else {
         if (infile == NULL && isatty(fileno_stdin()))
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "Warning: Reading certificate(s) from stdin since no -in or -new option is given\n");
         if (multi) {
             certs = sk_X509_new_null();
@@ -964,9 +902,9 @@ cert_loop:
     }
 
     if (clrext && ext_names != NULL)
-        BIO_puts(bio_err, "Warning: Ignoring -ext since -clrext is given\n");
+        BIO_printf(bio_err, "Warning: Ignoring -ext since -clrext is given\n");
     for (i = X509_get_ext_count(x) - 1; i >= 0; i--) {
-        const X509_EXTENSION *ex = X509_get_ext(x, i);
+        X509_EXTENSION *ex = X509_get_ext(x, i);
         const char *sn = OBJ_nid2sn(OBJ_obj2nid(X509_EXTENSION_get_object(ex)));
 
         if (clrext || (ext_names != NULL && strstr(ext_names, sn) == NULL))
@@ -984,7 +922,7 @@ cert_loop:
             goto err;
     } else {
         if (privkey != NULL && !cert_matches_key(x, privkey))
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "Warning: Signature key and public key of cert do not match\n");
     }
 
@@ -1010,34 +948,40 @@ cert_loop:
             goto err;
     }
     if (extconf != NULL && !x509toreq) {
-        if (!do_EXT_add_nconf(extconf, extconf, &ext_ctx, x,
-                "Error adding extensions from section %s\n", extsect))
+        X509V3_set_nconf(&ext_ctx, extconf);
+        if (!X509V3_EXT_add_nconf(extconf, &ext_ctx, extsect, x)) {
+            BIO_printf(bio_err,
+                "Error adding extensions from section %s\n", extsect);
             goto err;
+        }
     }
 
     /* At this point the contents of the certificate x have been finished. */
 
     pkey = X509_get0_pubkey(x);
     if ((print_pubkey != 0 || modulus != 0) && pkey == NULL) {
-        BIO_puts(bio_err, "Error getting public key\n");
+        BIO_printf(bio_err, "Error getting public key\n");
         goto err;
     }
 
     if (x509toreq) { /* also works in conjunction with -req */
         if (privkey == NULL) {
-            BIO_puts(bio_err, "Must specify request signing key using -key\n");
+            BIO_printf(bio_err, "Must specify request signing key using -key\n");
             goto err;
         }
         if (clrext && ext_copy != EXT_COPY_NONE) {
-            BIO_puts(bio_err, "Must not use -clrext together with -copy_extensions\n");
+            BIO_printf(bio_err, "Must not use -clrext together with -copy_extensions\n");
             goto err;
         }
         if ((rq = x509_to_req(x, ext_copy, ext_names)) == NULL)
             goto err;
         if (extconf != NULL) {
-            if (!do_EXT_REQ_add_nconf(extconf, extconf, &ext_ctx, rq,
-                    "Error adding request extensions from section %s\n", extsect))
+            X509V3_set_nconf(&ext_ctx, extconf);
+            if (!X509V3_EXT_REQ_add_nconf(extconf, &ext_ctx, extsect, rq)) {
+                BIO_printf(bio_err,
+                    "Error adding request extensions from section %s\n", extsect);
                 goto err;
+            }
         }
         if (!do_X509_REQ_sign(rq, privkey, digest, sigopts))
             goto err;
@@ -1049,7 +993,7 @@ cert_loop:
                 i = PEM_write_bio_X509_REQ(out, rq);
             }
             if (!i) {
-                BIO_puts(bio_err,
+                BIO_printf(bio_err,
                     "Unable to write certificate request\n");
                 goto err;
             }
@@ -1061,7 +1005,7 @@ cert_loop:
             == NULL)
             goto err;
         if (!X509_check_private_key(xca, CAkey)) {
-            BIO_puts(bio_err,
+            BIO_printf(bio_err,
                 "CA certificate and CA private key do not match\n");
             goto err;
         }
@@ -1076,9 +1020,7 @@ cert_loop:
         const ASN1_BIT_STRING *signature;
 
         X509_get0_signature(&signature, NULL, x);
-        /* XXX Casts away const, because it mutates the value! */
-        if (!corrupt_signature(((ASN1_STRING *)signature)))
-            goto err;
+        corrupt_signature(signature);
     }
 
     /* Process print options in the given order, as indicated by index i */
@@ -1088,9 +1030,9 @@ cert_loop:
         } else if (i == subject) {
             print_name(out, "subject=", X509_get_subject_name(x));
         } else if (i == serial) {
-            BIO_puts(out, "serial=");
+            BIO_printf(out, "serial=");
             i2a_ASN1_INTEGER(out, X509_get0_serialNumber(x));
-            BIO_puts(out, "\n");
+            BIO_printf(out, "\n");
         } else if (i == next_serial) {
             ASN1_INTEGER *ser;
             BIGNUM *bnser = ASN1_INTEGER_to_BN(X509_get0_serialNumber(x), NULL);
@@ -1113,7 +1055,7 @@ cert_loop:
                 BIO_printf(out, "%s\n", sk_OPENSSL_STRING_value(emlst, j));
             X509_email_free(emlst);
         } else if (i == aliasout) {
-            const unsigned char *alstr = X509_alias_get0(x, NULL);
+            unsigned char *alstr = X509_alias_get0(x, NULL);
 
             if (alstr)
                 BIO_printf(out, "%s\n", alstr);
@@ -1132,11 +1074,11 @@ cert_loop:
             BIO_printf(out, "%08lx\n", X509_issuer_name_hash_old(x));
 #endif
         } else if (i == pprint) {
-            BIO_puts(out, "Certificate purposes:\n");
+            BIO_printf(out, "Certificate purposes:\n");
             for (j = 0; j < X509_PURPOSE_get_count(); j++)
                 purpose_print(out, x, X509_PURPOSE_get0(j));
         } else if (i == modulus) {
-            BIO_puts(out, "Modulus=");
+            BIO_printf(out, "Modulus=");
             if (EVP_PKEY_is_a(pkey, "RSA") || EVP_PKEY_is_a(pkey, "RSA-PSS")) {
                 BIGNUM *n = NULL;
 
@@ -1152,9 +1094,9 @@ cert_loop:
                 BN_print(out, dsapub);
                 BN_free(dsapub);
             } else {
-                BIO_puts(out, "No modulus for this public key type");
+                BIO_printf(out, "No modulus for this public key type");
             }
-            BIO_puts(out, "\n");
+            BIO_printf(out, "\n");
         } else if (i == print_pubkey) {
             PEM_write_bio_PUBKEY(out, pkey);
         } else if (i == text) {
@@ -1180,13 +1122,13 @@ cert_loop:
             if ((fdig = EVP_MD_fetch(app_get0_libctx(), fdigname,
                      app_get0_propq()))
                 == NULL) {
-                BIO_puts(bio_err, "Unknown digest\n");
+                BIO_printf(bio_err, "Unknown digest\n");
                 goto err;
             }
             digres = X509_digest(x, fdig, md, &n);
             EVP_MD_free(fdig);
             if (!digres) {
-                BIO_puts(bio_err, "Out of memory\n");
+                BIO_printf(bio_err, "Out of memory\n");
                 goto err;
             }
 
@@ -1201,40 +1143,26 @@ cert_loop:
     }
 
     if (checkend) {
-        X509_VERIFY_PARAM *vpm;
         time_t tcheck = time(NULL) + checkoffset;
-        int expired = 0;
-        int error;
+        int expired = X509_cmp_time(X509_get0_notAfter(x), &tcheck) < 0;
 
-        if ((vpm = X509_VERIFY_PARAM_new()) == NULL) {
-            BIO_puts(out, "Malloc failed\n");
-            goto end_cert_loop;
-        }
-        X509_VERIFY_PARAM_set_flags(vpm, X509_V_FLAG_USE_CHECK_TIME);
-        X509_VERIFY_PARAM_set_time(vpm, tcheck);
+        if (expired)
+            BIO_printf(out, "Certificate will expire\n");
+        else
+            BIO_printf(out, "Certificate will not expire\n");
 
-        if (!X509_check_certificate_times(vpm, x, &error)) {
-            if (error == X509_V_ERR_CERT_HAS_EXPIRED) {
-                BIO_puts(out, "Certificate will expire\n");
-                expired = 1;
-            }
-        } else {
-            BIO_puts(out, "Certificate will not expire\n");
-        }
         if (multi && k > 0)
             ret |= expired;
         else
             ret = expired;
 
-        X509_VERIFY_PARAM_free(vpm);
         if (multi && k < sk_X509_num(certs) - 1)
             goto end_cert_loop;
         else
             goto end;
     }
 
-    if (!check_cert_might_be_valid(out, bio_err, x, checkhost, checkemail,
-            checkip))
+    if (!check_cert_attributes(out, x, checkhost, checkemail, checkip, 1))
         goto err;
 
     if (noout || nocert) {
@@ -1250,11 +1178,11 @@ cert_loop:
         else
             i = PEM_write_bio_X509(out, x);
     } else {
-        BIO_puts(bio_err, "Bad output format specified for outfile\n");
+        BIO_printf(bio_err, "Bad output format specified for outfile\n");
         goto err;
     }
     if (!i) {
-        BIO_puts(bio_err, "Unable to write certificate\n");
+        BIO_printf(bio_err, "Unable to write certificate\n");
         goto err;
     }
 
@@ -1318,7 +1246,7 @@ static ASN1_INTEGER *x509_load_serial(const char *CAfile,
         goto end;
 
     if (!BN_add_word(serial, 1)) {
-        BIO_puts(bio_err, "Serial number increment failure\n");
+        BIO_printf(bio_err, "Serial number increment failure\n");
         goto end;
     }
 
@@ -1336,7 +1264,7 @@ end:
 static int callb(int ok, X509_STORE_CTX *ctx)
 {
     int err;
-    const X509 *err_cert;
+    X509 *err_cert;
 
     /*
      * It is ok to use a self-signed certificate. This case will catch both
@@ -1369,9 +1297,9 @@ static int purpose_print(BIO *bio, X509 *cert, X509_PURPOSE *pt)
         idret = X509_check_purpose(cert, id, i);
         BIO_printf(bio, "%s%s : ", pname, i ? " CA" : "");
         if (idret == 1)
-            BIO_puts(bio, "Yes\n");
+            BIO_printf(bio, "Yes\n");
         else if (idret == 0)
-            BIO_puts(bio, "No\n");
+            BIO_printf(bio, "No\n");
         else
             BIO_printf(bio, "Yes (WARNING code=%d)\n", idret);
     }
@@ -1410,14 +1338,14 @@ static int print_x509v3_exts(BIO *bio, X509 *x, const char *ext_names)
     const STACK_OF(X509_EXTENSION) *exts = NULL;
     STACK_OF(X509_EXTENSION) *exts2 = NULL;
     X509_EXTENSION *ext = NULL;
-    const ASN1_OBJECT *obj;
+    ASN1_OBJECT *obj;
     int i, j, ret = 0, num, nn = 0;
     const char *sn, **names = NULL;
     char *tmp_ext_names = NULL;
 
     exts = X509_get0_extensions(x);
     if ((num = sk_X509_EXTENSION_num(exts)) <= 0) {
-        BIO_puts(bio_err, "No extensions in certificate\n");
+        BIO_printf(bio_err, "No extensions in certificate\n");
         ret = 1;
         goto end;
     }
diff --git a/build.info b/build.info
index d7982a9553..f2d6da6c8b 100644
--- a/build.info
+++ b/build.info
@@ -1,7 +1,7 @@
 # Note that some of these directories are filtered in Configure.  Look for
 # %skipdir there for further explanations.
 
-SUBDIRS=crypto ssl apps util fuzz providers doc
+SUBDIRS=crypto ssl apps util tools fuzz providers doc
 IF[{- !$disabled{tests} -}]
   SUBDIRS=test
 ENDIF
@@ -60,7 +60,6 @@ DEPEND[]=include/openssl/asn1.h \
          providers/implementations/kdfs/argon2.inc \
          providers/implementations/kdfs/hkdf.inc \
          providers/implementations/kdfs/hmacdrbg_kdf.inc \
-         providers/implementations/kdfs/ikev2kdf.inc \
          providers/implementations/kdfs/kbkdf.inc \
          providers/implementations/kdfs/krb5kdf.inc \
          providers/implementations/kdfs/pbkdf1.inc \
@@ -69,12 +68,10 @@ DEPEND[]=include/openssl/asn1.h \
          providers/implementations/kdfs/pvkkdf.inc \
          providers/implementations/kdfs/scrypt.inc \
          providers/implementations/kdfs/snmpkdf.inc \
-         providers/implementations/kdfs/srtpkdf.inc \
          providers/implementations/kdfs/sshkdf.inc \
          providers/implementations/kdfs/sskdf.inc \
          providers/implementations/kdfs/tls1_prf.inc \
          providers/implementations/kdfs/x942kdf.inc \
-         providers/implementations/kdfs/x963kdf.inc \
          providers/implementations/kem/ec_kem.inc \
          providers/implementations/kem/ecx_kem.inc \
          providers/implementations/kem/ml_kem_kem.inc \
@@ -92,7 +89,6 @@ DEPEND[]=include/openssl/asn1.h \
          providers/implementations/signature/dsa_sig.inc \
          providers/implementations/signature/ecdsa_sig.inc \
          providers/implementations/signature/eddsa_sig.inc \
-         providers/implementations/signature/mac_legacy_sig.inc \
          providers/implementations/signature/ml_dsa_sig.inc \
          providers/implementations/signature/rsa_sig.inc \
          providers/implementations/signature/slh_dsa_sig.inc \
@@ -119,10 +115,7 @@ DEPEND[]=include/openssl/asn1.h \
          providers/implementations/digests/blake2_prov.inc \
          providers/implementations/digests/digestcommon.inc \
          providers/implementations/digests/mdc2_prov.inc \
-         providers/implementations/digests/sha2_prov.inc \
          providers/implementations/digests/sha3_prov.inc \
-         providers/implementations/digests/ml_dsa_mu_prov.inc \
-         providers/implementations/digests/cshake_prov.inc \
          providers/implementations/include/prov/blake2_params.inc \
          providers/implementations/macs/cmac_prov.inc \
          providers/implementations/macs/gmac_prov.inc \
@@ -185,7 +178,6 @@ DEPEND[providers/implementations/asymciphers/rsa_enc.inc \
        providers/implementations/kdfs/argon2.inc \
        providers/implementations/kdfs/hkdf.inc \
        providers/implementations/kdfs/hmacdrbg_kdf.inc \
-       providers/implementations/kdfs/ikev2kdf.inc \
        providers/implementations/kdfs/kbkdf.inc \
        providers/implementations/kdfs/krb5kdf.inc \
        providers/implementations/kdfs/pbkdf1.inc \
@@ -194,12 +186,10 @@ DEPEND[providers/implementations/asymciphers/rsa_enc.inc \
        providers/implementations/kdfs/pvkkdf.inc \
        providers/implementations/kdfs/scrypt.inc \
        providers/implementations/kdfs/snmpkdf.inc \
-       providers/implementations/kdfs/srtpkdf.inc \
        providers/implementations/kdfs/sshkdf.inc \
        providers/implementations/kdfs/sskdf.inc \
        providers/implementations/kdfs/tls1_prf.inc \
        providers/implementations/kdfs/x942kdf.inc \
-       providers/implementations/kdfs/x963kdf.inc \
        providers/implementations/kem/ec_kem.inc \
        providers/implementations/kem/ecx_kem.inc \
        providers/implementations/kem/ml_kem_kem.inc \
@@ -217,7 +207,6 @@ DEPEND[providers/implementations/asymciphers/rsa_enc.inc \
        providers/implementations/signature/dsa_sig.inc \
        providers/implementations/signature/ecdsa_sig.inc \
        providers/implementations/signature/eddsa_sig.inc \
-       providers/implementations/signature/mac_legacy_sig.inc \
        providers/implementations/signature/ml_dsa_sig.inc \
        providers/implementations/signature/rsa_sig.inc \
        providers/implementations/signature/slh_dsa_sig.inc \
@@ -242,12 +231,9 @@ DEPEND[providers/implementations/asymciphers/rsa_enc.inc \
        providers/implementations/ciphers/cipher_rc4_hmac_md5.inc \
        providers/implementations/ciphers/cipher_sm4_xts.inc \
        providers/implementations/digests/blake2_prov.inc \
-       providers/implementations/digests/ml_dsa_mu_prov.inc \
        providers/implementations/digests/digestcommon.inc \
        providers/implementations/digests/mdc2_prov.inc \
-       providers/implementations/digests/sha2_prov.inc \
        providers/implementations/digests/sha3_prov.inc \
-       providers/implementations/digests/cshake_prov.inc \
        providers/implementations/include/prov/blake2_params.inc \
        providers/implementations/macs/cmac_prov.inc \
        providers/implementations/macs/gmac_prov.inc \
@@ -263,7 +249,6 @@ DEPEND[providers/implementations/asymciphers/rsa_enc.inc \
        providers/implementations/rands/seed_src_jitter.inc \
        providers/implementations/rands/test_rng.inc \
        include/openssl/core_names.h]=util/perl|OpenSSL/paramnames.pm
-
 GENERATE[providers/implementations/asymciphers/rsa_enc.inc]=\
     providers/implementations/asymciphers/rsa_enc.inc.in
 GENERATE[providers/implementations/asymciphers/sm2_enc.inc]=\
@@ -294,8 +279,6 @@ GENERATE[providers/implementations/kdfs/hkdf.inc]=\
     providers/implementations/kdfs/hkdf.inc.in
 GENERATE[providers/implementations/kdfs/hmacdrbg_kdf.inc]=\
     providers/implementations/kdfs/hmacdrbg_kdf.inc.in
-GENERATE[providers/implementations/kdfs/ikev2kdf.inc]=\
-    providers/implementations/kdfs/ikev2kdf.inc.in
 GENERATE[providers/implementations/kdfs/kbkdf.inc]=\
     providers/implementations/kdfs/kbkdf.inc.in
 GENERATE[providers/implementations/kdfs/krb5kdf.inc]=\
@@ -312,8 +295,6 @@ GENERATE[providers/implementations/kdfs/scrypt.inc]=\
     providers/implementations/kdfs/scrypt.inc.in
 GENERATE[providers/implementations/kdfs/snmpkdf.inc]=\
     providers/implementations/kdfs/snmpkdf.inc.in
-GENERATE[providers/implementations/kdfs/srtpkdf.inc]=\
-    providers/implementations/kdfs/srtpkdf.inc.in
 GENERATE[providers/implementations/kdfs/sshkdf.inc]=\
     providers/implementations/kdfs/sshkdf.inc.in
 GENERATE[providers/implementations/kdfs/sskdf.inc]=\
@@ -322,8 +303,6 @@ GENERATE[providers/implementations/kdfs/tls1_prf.inc]=\
     providers/implementations/kdfs/tls1_prf.inc.in
 GENERATE[providers/implementations/kdfs/x942kdf.inc]=\
     providers/implementations/kdfs/x942kdf.inc.in
-GENERATE[providers/implementations/kdfs/x963kdf.inc]=\
-    providers/implementations/kdfs/x963kdf.inc.in
 GENERATE[providers/implementations/kem/ec_kem.inc]=\
     providers/implementations/kem/ec_kem.inc.in
 GENERATE[providers/implementations/kem/ecx_kem.inc]=\
@@ -358,8 +337,6 @@ GENERATE[providers/implementations/signature/ecdsa_sig.inc]=\
     providers/implementations/signature/ecdsa_sig.inc.in
 GENERATE[providers/implementations/signature/eddsa_sig.inc]=\
     providers/implementations/signature/eddsa_sig.inc.in
-GENERATE[providers/implementations/signature/mac_legacy_sig.inc]=\
-    providers/implementations/signature/mac_legacy_sig.inc.in
 GENERATE[providers/implementations/signature/ml_dsa_sig.inc]=\
     providers/implementations/signature/ml_dsa_sig.inc.in
 GENERATE[providers/implementations/signature/rsa_sig.inc]=\
@@ -412,16 +389,10 @@ GENERATE[providers/implementations/digests/digestcommon.inc]=\
     providers/implementations/digests/digestcommon.inc.in
 GENERATE[providers/implementations/digests/mdc2_prov.inc]=\
     providers/implementations/digests/mdc2_prov.inc.in
-GENERATE[providers/implementations/digests/sha2_prov.inc]=\
-    providers/implementations/digests/sha2_prov.inc.in
 GENERATE[providers/implementations/digests/sha3_prov.inc]=\
     providers/implementations/digests/sha3_prov.inc.in
-GENERATE[providers/implementations/digests/cshake_prov.inc]=\
-    providers/implementations/digests/cshake_prov.inc.in
 GENERATE[providers/implementations/include/prov/blake2_params.inc]=\
     providers/implementations/include/prov/blake2_params.inc.in
-GENERATE[providers/implementations/digests/ml_dsa_mu_prov.inc]=\
-    providers/implementations/digests/ml_dsa_mu_prov.inc.in
 GENERATE[providers/implementations/macs/cmac_prov.inc]=\
     providers/implementations/macs/cmac_prov.inc.in
 GENERATE[providers/implementations/macs/gmac_prov.inc]=\
@@ -468,10 +439,12 @@ IF[{- $config{target} =~ /^(?:Cygwin|mingw|VC-|BC-)/ -}]
   SHARED_SOURCE[libssl]=libssl.rc
 ENDIF
 
-# These files set the build directory up for CMake inclusion.
-# To achieve this, their variables are taken from builddata.pm.
-# These files are not installed; you will find the installable
-# versions in the 'exporters' directory.
+# This file sets the build directory up for CMake inclusion
+# Note: This generation of OpenSSLConfig[Version].cmake is used
+# for building openssl locally, and so the build variables are 
+# taken from builddata.pm rather than installdata.pm.  For exportable
+# versions of these generated files, you'll find them in the exporters
+# directory
 GENERATE[OpenSSLConfig.cmake]=exporters/cmake/OpenSSLConfig.cmake.in
 DEPEND[OpenSSLConfig.cmake]=builddata.pm
 GENERATE[OpenSSLConfigVersion.cmake]=exporters/cmake/OpenSSLConfigVersion.cmake.in
@@ -479,10 +452,7 @@ DEPEND[OpenSSLConfigVersion.cmake]=builddata.pm
 DEPEND[OpenSSLConfigVersion.cmake]=OpenSSLConfig.cmake
 DEPEND[""]=OpenSSLConfigVersion.cmake
 
-# These files set the build directory up for pkg-config use.
-# To achieve this, their variables are taken from builddata.pm.
-# These files are not installed; you will find the installable
-# versions in the 'exporters' directory.
+# This file sets the build directory up for pkg-config
 GENERATE[libcrypto.pc]=exporters/pkg-config/libcrypto.pc.in
 DEPEND[libcrypto.pc]=builddata.pm
 GENERATE[libssl.pc]=exporters/pkg-config/libssl.pc.in
@@ -492,7 +462,6 @@ DEPEND[openssl.pc]=builddata.pm
 DEPEND[openssl.pc]=libcrypto.pc libssl.pc
 
 GENERATE[builddata.pm]=util/mkinstallvars.pl \
-    COMMENT="This file should be used when building against this OpenSSL build, and should never be installed" \
     PREFIX=. BINDIR=apps APPLINKDIR=ms \
     LIBDIR= INCLUDEDIR=include "INCLUDEDIR=$(SRCDIR)/include" \
     MODULESDIR=providers \
diff --git a/configdata.pm.in b/configdata.pm.in
index a21fe686d9..fea6004d6c 100644
--- a/configdata.pm.in
+++ b/configdata.pm.in
@@ -151,75 +151,55 @@ _____
             or die "Trying to rename $buildfile.new to $buildfile: $!";
         print 'Created ',$buildfile,"\n";
 
-        my $create_configuration = sub {
-          my ($configuration_file, $configuration_file_in) = @_;
-
-          open CONFIGURATION, ">${configuration_file}.new"
-              or die "Trying to create ${configuration_file_in}.new: $!";
-          $tmpl = OpenSSL::Template->new(TYPE => 'FILE',
-                                        SOURCE => $configuration_file_in);
-          $tmpl->fill_in(FILENAME => $_,
-                        OUTPUT => \*CONFIGURATION,
-                        HASH => \%gendata,
-                        PREPEND => $prepend,
-                        # To ensure that global variables and functions
-                        # defined in one template stick around for the
-                        # next, making them combinable
-                        PACKAGE => 'OpenSSL::safe')
-              or die $OpenSSL::Template::ERROR;
-          close CONFIGURATION;
-        };
-
-        my $update_configuration = sub {
-          # When using stat() on Windows, we can get it to perform better by
-          # avoid some data.  This doesn't affect the mtime field, so we're not
-          # losing anything...
-          ${^WIN32_SLOPPY_STAT} = 1;
-
-          my ($configuration_file, $configuration_file_in) = @_;
-          my $update_configuration_file = 0;
-
-          if (-f $configuration_file) {
-              my $configuration_file_mtime = (stat($configuration_file))[9];
-              my $configuration_file_in_mtime = (stat($configuration_file_in))[9];
-
-              # If configuration.h.in was updated after the last configuration.h,
-              # or if configuration.h.new differs configuration.h, we update
-              # configuration.h
-              if ($configuration_file_mtime < $configuration_file_in_mtime
-                  || compare_text("${configuration_file}.new", $configuration_file) != 0) {
-                  $update_configuration_file = 1;
-              } else {
-                  # If nothing has changed, let's just drop the new one and
-                  # pretend like nothing happened
-                  unlink "${configuration_file}.new"
-              }
-          } else {
-              $update_configuration_file = 1;
-          }
-
-          if ($update_configuration_file) {
-              rename("${configuration_file}.new", $configuration_file)
-                  or die "Trying to rename ${configuration_file}.new to $configuration_file: $!";
-              print 'Created ',$configuration_file,"\n";
-          }
-        };
-
         my $configuration_h =
             catfile('include', 'openssl', 'configuration.h');
         my $configuration_h_in =
             catfile($config{sourcedir}, 'include', 'openssl', 'configuration.h.in');
+        open CONFIGURATION_H, ">${configuration_h}.new"
+            or die "Trying to create ${configuration_h}.new: $!";
+        $tmpl = OpenSSL::Template->new(TYPE => 'FILE',
+                                       SOURCE => $configuration_h_in);
+        $tmpl->fill_in(FILENAME => $_,
+                       OUTPUT => \*CONFIGURATION_H,
+                       HASH => \%gendata,
+                       PREPEND => $prepend,
+                       # To ensure that global variables and functions
+                       # defined in one template stick around for the
+                       # next, making them combinable
+                       PACKAGE => 'OpenSSL::safe')
+            or die $OpenSSL::Template::ERROR;
+        close CONFIGURATION_H;
 
-        my $apps_configuration_h =
-            catfile('apps', 'include', 'configuration.h');
-        my $apps_configuration_h_in =
-            catfile($config{sourcedir}, 'apps', 'include', 'configuration.h.in');
+        # When using stat() on Windows, we can get it to perform better by
+        # avoid some data.  This doesn't affect the mtime field, so we're not
+        # losing anything...
+        ${^WIN32_SLOPPY_STAT} = 1;
 
-        $create_configuration->($configuration_h, $configuration_h_in);
-        $update_configuration->($configuration_h, $configuration_h_in);
+        my $update_configuration_h = 0;
+        if (-f $configuration_h) {
+            my $configuration_h_mtime = (stat($configuration_h))[9];
+            my $configuration_h_in_mtime = (stat($configuration_h_in))[9];
 
-        $create_configuration->($apps_configuration_h, $apps_configuration_h_in);
-        $update_configuration->($apps_configuration_h, $apps_configuration_h_in);
+            # If configuration.h.in was updated after the last configuration.h,
+            # or if configuration.h.new differs configuration.h, we update
+            # configuration.h
+            if ($configuration_h_mtime < $configuration_h_in_mtime
+                || compare_text("${configuration_h}.new", $configuration_h) != 0) {
+                $update_configuration_h = 1;
+            } else {
+                # If nothing has changed, let's just drop the new one and
+                # pretend like nothing happened
+                unlink "${configuration_h}.new"
+            }
+        } else {
+            $update_configuration_h = 1;
+        }
+
+        if ($update_configuration_h) {
+            rename("${configuration_h}.new", $configuration_h)
+                or die "Trying to rename ${configuration_h}.new to $configuration_h: $!";
+            print 'Created ',$configuration_h,"\n";
+        }
 
         exit(0);
     }
@@ -505,4 +485,3 @@ Verbose output.
 =cut
 
 EOF
-#define PRINT_ENABLED(type)
diff --git a/crypto/LPdir_win.c b/crypto/LPdir_win.c
index 425a7962d0..bc5cec35d9 100644
--- a/crypto/LPdir_win.c
+++ b/crypto/LPdir_win.c
@@ -36,13 +36,25 @@
  * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
  */
 
+#include 
 #include 
-#include "internal/e_os.h"
 #include "internal/numbers.h"
 #ifndef LPDIR_H
 #include "LPdir.h"
 #endif
 
+/*
+ * We're most likely overcautious here, but let's reserve for broken WinCE
+ * headers and explicitly opt for UNICODE call. Keep in mind that our WinCE
+ * builds are compiled with -DUNICODE [as well as -D_UNICODE].
+ */
+#if defined(LP_SYS_WINCE) && !defined(FindFirstFile)
+#define FindFirstFile FindFirstFileW
+#endif
+#if defined(LP_SYS_WINCE) && !defined(FindNextFile)
+#define FindNextFile FindNextFileW
+#endif
+
 #ifndef NAME_MAX
 #define NAME_MAX 255
 #endif
diff --git a/crypto/LPdir_wince.c b/crypto/LPdir_wince.c
new file mode 100644
index 0000000000..e4c883dcef
--- /dev/null
+++ b/crypto/LPdir_wince.c
@@ -0,0 +1,46 @@
+/*
+ * Copyright 2004-2016 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+/*
+ * This file is dual-licensed and is also available under the following
+ * terms:
+ *
+ * Copyright (c) 2004, Richard Levitte 
+ * All rights reserved.
+ *
+ * Redistribution and use in source and binary forms, with or without
+ * modification, are permitted provided that the following conditions
+ * are met:
+ * 1. Redistributions of source code must retain the above copyright
+ *    notice, this list of conditions and the following disclaimer.
+ * 2. Redistributions in binary form must reproduce the above copyright
+ *    notice, this list of conditions and the following disclaimer in the
+ *    documentation and/or other materials provided with the distribution.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
+ * ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
+ * LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR
+ * A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT
+ * OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
+ * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
+ * LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
+ * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
+ * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
+ * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+
+#define LP_SYS_WINCE
+/*
+ * We might want to define LP_MULTIBYTE_AVAILABLE here.  It's currently under
+ * investigation what the exact conditions would be
+ */
+/* clang-format off */
+#include "LPdir_win.c"
+/* clang-format on */
diff --git a/crypto/aes/aes_cfb.c b/crypto/aes/aes_cfb.c
index 3026208a0b..e6a184a19f 100644
--- a/crypto/aes/aes_cfb.c
+++ b/crypto/aes/aes_cfb.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -24,7 +24,7 @@
 
 void AES_cfb128_encrypt(const unsigned char *in, unsigned char *out,
     size_t length, const AES_KEY *key,
-    unsigned char *ivec, int *num, int enc)
+    unsigned char *ivec, int *num, const int enc)
 {
 
     CRYPTO_cfb128_encrypt(in, out, length, key, ivec, num, enc,
@@ -34,7 +34,7 @@ void AES_cfb128_encrypt(const unsigned char *in, unsigned char *out,
 /* N.B. This expects the input to be packed, MS bit first */
 void AES_cfb1_encrypt(const unsigned char *in, unsigned char *out,
     size_t length, const AES_KEY *key,
-    unsigned char *ivec, int *num, int enc)
+    unsigned char *ivec, int *num, const int enc)
 {
     CRYPTO_cfb128_1_encrypt(in, out, length, key, ivec, num, enc,
         (block128_f)AES_encrypt);
@@ -42,7 +42,7 @@ void AES_cfb1_encrypt(const unsigned char *in, unsigned char *out,
 
 void AES_cfb8_encrypt(const unsigned char *in, unsigned char *out,
     size_t length, const AES_KEY *key,
-    unsigned char *ivec, int *num, int enc)
+    unsigned char *ivec, int *num, const int enc)
 {
     CRYPTO_cfb128_8_encrypt(in, out, length, key, ivec, num, enc,
         (block128_f)AES_encrypt);
diff --git a/crypto/aes/aes_core.c b/crypto/aes/aes_core.c
index 66577ba39a..b376e7e47d 100644
--- a/crypto/aes/aes_core.c
+++ b/crypto/aes/aes_core.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2002-2022 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -62,17 +62,17 @@
 
 typedef union {
     unsigned char b[8];
-    uint32_t w[2];
-    uint64_t d;
+    u32 w[2];
+    u64 d;
 } uni;
 
 /*
  * Compute w := (w * x) mod (x^8 + x^4 + x^3 + x^1 + 1)
  * Therefore the name "xtime".
  */
-static void XtimeWord(uint32_t *w)
+static void XtimeWord(u32 *w)
 {
-    uint32_t a, b;
+    u32 a, b;
 
     a = *w;
     b = a & 0x80808080u;
@@ -83,9 +83,9 @@ static void XtimeWord(uint32_t *w)
     *w = b;
 }
 
-static void XtimeLong(uint64_t *w)
+static void XtimeLong(u64 *w)
 {
-    uint64_t a, b;
+    u64 a, b;
 
     a = *w;
     b = a & U64(0x8080808080808080);
@@ -142,9 +142,9 @@ static void XtimeLong(uint64_t *w)
  *   return [b0,b1];
  * The non-linear multiplies (*) can be done in parallel at no extra cost.
  */
-static void SubWord(uint32_t *w)
+static void SubWord(u32 *w)
 {
-    uint32_t x, y, a1, a2, a3, a4, a5, a6;
+    u32 x, y, a1, a2, a3, a4, a5, a6;
 
     x = *w;
     y = ((x & 0xFEFEFEFEu) >> 1) | ((x & 0x01010101u) << 7);
@@ -190,7 +190,7 @@ static void SubWord(uint32_t *w)
     a2 = a3;
     a2 ^= (a3 & 0x0C0C0C0Cu) >> 2;
     a4 = a3 & a2;
-    a4 ^= (a4 & 0x0A0A0A0Au) >> 1;
+    a4 ^= (a4 & 0x0A0A0A0A0Au) >> 1;
     a4 ^= (((a3 << 1) & a2) ^ ((a2 << 1) & a3)) & 0x0A0A0A0Au;
     a5 = a4 & 0x08080808u;
     a5 |= a5 >> 1;
@@ -233,9 +233,9 @@ static void SubWord(uint32_t *w)
     *w = x;
 }
 
-static void SubLong(uint64_t *w)
+static void SubLong(u64 *w)
 {
-    uint64_t x, y, a1, a2, a3, a4, a5, a6;
+    u64 x, y, a1, a2, a3, a4, a5, a6;
 
     x = *w;
     y = ((x & U64(0xFEFEFEFEFEFEFEFE)) >> 1) | ((x & U64(0x0101010101010101)) << 7);
@@ -327,9 +327,9 @@ static void SubLong(uint64_t *w)
 /*
  * This computes w := (S^-1 * (w + c))^-1
  */
-static void InvSubLong(uint64_t *w)
+static void InvSubLong(u64 *w)
 {
-    uint64_t x, y, a1, a2, a3, a4, a5, a6;
+    u64 x, y, a1, a2, a3, a4, a5, a6;
 
     x = *w;
     x ^= U64(0x6363636363636363);
@@ -422,7 +422,7 @@ static void InvSubLong(uint64_t *w)
     *w = x;
 }
 
-static void ShiftRows(uint64_t *state)
+static void ShiftRows(u64 *state)
 {
     unsigned char s[4];
     unsigned char *s0;
@@ -441,7 +441,7 @@ static void ShiftRows(uint64_t *state)
     }
 }
 
-static void InvShiftRows(uint64_t *state)
+static void InvShiftRows(u64 *state)
 {
     unsigned char s[4];
     unsigned char *s0;
@@ -460,7 +460,7 @@ static void InvShiftRows(uint64_t *state)
     }
 }
 
-static void MixColumns(uint64_t *state)
+static void MixColumns(u64 *state)
 {
     uni s1;
     uni s;
@@ -488,7 +488,7 @@ static void MixColumns(uint64_t *state)
     }
 }
 
-static void InvMixColumns(uint64_t *state)
+static void InvMixColumns(u64 *state)
 {
     uni s1;
     uni s;
@@ -524,16 +524,16 @@ static void InvMixColumns(uint64_t *state)
     }
 }
 
-static void AddRoundKey(uint64_t *state, const uint64_t *w)
+static void AddRoundKey(u64 *state, const u64 *w)
 {
     state[0] ^= w[0];
     state[1] ^= w[1];
 }
 
 static void Cipher(const unsigned char *in, unsigned char *out,
-    const uint64_t *w, int nr)
+    const u64 *w, int nr)
 {
-    uint64_t state[2];
+    u64 state[2];
     int i;
 
     memcpy(state, in, 16);
@@ -557,10 +557,10 @@ static void Cipher(const unsigned char *in, unsigned char *out,
 }
 
 static void InvCipher(const unsigned char *in, unsigned char *out,
-    const uint64_t *w, int nr)
+    const u64 *w, int nr)
 
 {
-    uint64_t state[2];
+    u64 state[2];
     int i;
 
     memcpy(state, in, 16);
@@ -583,7 +583,7 @@ static void InvCipher(const unsigned char *in, unsigned char *out,
     memcpy(out, state, 16);
 }
 
-static void RotWord(uint32_t *x)
+static void RotWord(u32 *x)
 {
     unsigned char *w0;
     unsigned char tmp;
@@ -596,12 +596,12 @@ static void RotWord(uint32_t *x)
     w0[3] = tmp;
 }
 
-static void KeyExpansion(const unsigned char *key, uint64_t *w,
+static void KeyExpansion(const unsigned char *key, u64 *w,
     int nr, int nk)
 {
-    uint32_t rcon;
+    u32 rcon;
     uni prev;
-    uint32_t temp;
+    u32 temp;
     int i, n;
 
     memcpy(w, key, nk * 4);
@@ -628,17 +628,17 @@ static void KeyExpansion(const unsigned char *key, uint64_t *w,
 /**
  * Expand the cipher key into the encryption key schedule.
  */
-int AES_set_encrypt_key(const unsigned char *userKey, int bits,
+int AES_set_encrypt_key(const unsigned char *userKey, const int bits,
     AES_KEY *key)
 {
-    uint64_t *rk;
+    u64 *rk;
 
     if (!userKey || !key)
         return -1;
     if (bits != 128 && bits != 192 && bits != 256)
         return -2;
 
-    rk = (uint64_t *)key->rd_key;
+    rk = (u64 *)key->rd_key;
 
     if (bits == 128)
         key->rounds = 10;
@@ -654,7 +654,7 @@ int AES_set_encrypt_key(const unsigned char *userKey, int bits,
 /**
  * Expand the cipher key into the decryption key schedule.
  */
-int AES_set_decrypt_key(const unsigned char *userKey, int bits,
+int AES_set_decrypt_key(const unsigned char *userKey, const int bits,
     AES_KEY *key)
 {
     return AES_set_encrypt_key(userKey, bits, key);
@@ -667,10 +667,10 @@ int AES_set_decrypt_key(const unsigned char *userKey, int bits,
 void AES_encrypt(const unsigned char *in, unsigned char *out,
     const AES_KEY *key)
 {
-    const uint64_t *rk;
+    const u64 *rk;
 
     assert(in && out && key);
-    rk = (uint64_t *)key->rd_key;
+    rk = (u64 *)key->rd_key;
 
     Cipher(in, out, rk, key->rounds);
 }
@@ -682,10 +682,10 @@ void AES_encrypt(const unsigned char *in, unsigned char *out,
 void AES_decrypt(const unsigned char *in, unsigned char *out,
     const AES_KEY *key)
 {
-    const uint64_t *rk;
+    const u64 *rk;
 
     assert(in && out && key);
-    rk = (uint64_t *)key->rd_key;
+    rk = (u64 *)key->rd_key;
 
     InvCipher(in, out, rk, key->rounds);
 }
@@ -703,586 +703,2352 @@ Td3[x] = Si[x].[09, 0d, 0b, 0e];
 Td4[x] = Si[x].[01];
 */
 
-static const uint32_t Te0[256] = {
-    0xc66363a5U, 0xf87c7c84U, 0xee777799U, 0xf67b7b8dU,
-    0xfff2f20dU, 0xd66b6bbdU, 0xde6f6fb1U, 0x91c5c554U,
-    0x60303050U, 0x02010103U, 0xce6767a9U, 0x562b2b7dU,
-    0xe7fefe19U, 0xb5d7d762U, 0x4dababe6U, 0xec76769aU,
-    0x8fcaca45U, 0x1f82829dU, 0x89c9c940U, 0xfa7d7d87U,
-    0xeffafa15U, 0xb25959ebU, 0x8e4747c9U, 0xfbf0f00bU,
-    0x41adadecU, 0xb3d4d467U, 0x5fa2a2fdU, 0x45afafeaU,
-    0x239c9cbfU, 0x53a4a4f7U, 0xe4727296U, 0x9bc0c05bU,
-    0x75b7b7c2U, 0xe1fdfd1cU, 0x3d9393aeU, 0x4c26266aU,
-    0x6c36365aU, 0x7e3f3f41U, 0xf5f7f702U, 0x83cccc4fU,
-    0x6834345cU, 0x51a5a5f4U, 0xd1e5e534U, 0xf9f1f108U,
-    0xe2717193U, 0xabd8d873U, 0x62313153U, 0x2a15153fU,
-    0x0804040cU, 0x95c7c752U, 0x46232365U, 0x9dc3c35eU,
-    0x30181828U, 0x379696a1U, 0x0a05050fU, 0x2f9a9ab5U,
-    0x0e070709U, 0x24121236U, 0x1b80809bU, 0xdfe2e23dU,
-    0xcdebeb26U, 0x4e272769U, 0x7fb2b2cdU, 0xea75759fU,
-    0x1209091bU, 0x1d83839eU, 0x582c2c74U, 0x341a1a2eU,
-    0x361b1b2dU, 0xdc6e6eb2U, 0xb45a5aeeU, 0x5ba0a0fbU,
-    0xa45252f6U, 0x763b3b4dU, 0xb7d6d661U, 0x7db3b3ceU,
-    0x5229297bU, 0xdde3e33eU, 0x5e2f2f71U, 0x13848497U,
-    0xa65353f5U, 0xb9d1d168U, 0x00000000U, 0xc1eded2cU,
-    0x40202060U, 0xe3fcfc1fU, 0x79b1b1c8U, 0xb65b5bedU,
-    0xd46a6abeU, 0x8dcbcb46U, 0x67bebed9U, 0x7239394bU,
-    0x944a4adeU, 0x984c4cd4U, 0xb05858e8U, 0x85cfcf4aU,
-    0xbbd0d06bU, 0xc5efef2aU, 0x4faaaae5U, 0xedfbfb16U,
-    0x864343c5U, 0x9a4d4dd7U, 0x66333355U, 0x11858594U,
-    0x8a4545cfU, 0xe9f9f910U, 0x04020206U, 0xfe7f7f81U,
-    0xa05050f0U, 0x783c3c44U, 0x259f9fbaU, 0x4ba8a8e3U,
-    0xa25151f3U, 0x5da3a3feU, 0x804040c0U, 0x058f8f8aU,
-    0x3f9292adU, 0x219d9dbcU, 0x70383848U, 0xf1f5f504U,
-    0x63bcbcdfU, 0x77b6b6c1U, 0xafdada75U, 0x42212163U,
-    0x20101030U, 0xe5ffff1aU, 0xfdf3f30eU, 0xbfd2d26dU,
-    0x81cdcd4cU, 0x180c0c14U, 0x26131335U, 0xc3ecec2fU,
-    0xbe5f5fe1U, 0x359797a2U, 0x884444ccU, 0x2e171739U,
-    0x93c4c457U, 0x55a7a7f2U, 0xfc7e7e82U, 0x7a3d3d47U,
-    0xc86464acU, 0xba5d5de7U, 0x3219192bU, 0xe6737395U,
-    0xc06060a0U, 0x19818198U, 0x9e4f4fd1U, 0xa3dcdc7fU,
-    0x44222266U, 0x542a2a7eU, 0x3b9090abU, 0x0b888883U,
-    0x8c4646caU, 0xc7eeee29U, 0x6bb8b8d3U, 0x2814143cU,
-    0xa7dede79U, 0xbc5e5ee2U, 0x160b0b1dU, 0xaddbdb76U,
-    0xdbe0e03bU, 0x64323256U, 0x743a3a4eU, 0x140a0a1eU,
-    0x924949dbU, 0x0c06060aU, 0x4824246cU, 0xb85c5ce4U,
-    0x9fc2c25dU, 0xbdd3d36eU, 0x43acacefU, 0xc46262a6U,
-    0x399191a8U, 0x319595a4U, 0xd3e4e437U, 0xf279798bU,
-    0xd5e7e732U, 0x8bc8c843U, 0x6e373759U, 0xda6d6db7U,
-    0x018d8d8cU, 0xb1d5d564U, 0x9c4e4ed2U, 0x49a9a9e0U,
-    0xd86c6cb4U, 0xac5656faU, 0xf3f4f407U, 0xcfeaea25U,
-    0xca6565afU, 0xf47a7a8eU, 0x47aeaee9U, 0x10080818U,
-    0x6fbabad5U, 0xf0787888U, 0x4a25256fU, 0x5c2e2e72U,
-    0x381c1c24U, 0x57a6a6f1U, 0x73b4b4c7U, 0x97c6c651U,
-    0xcbe8e823U, 0xa1dddd7cU, 0xe874749cU, 0x3e1f1f21U,
-    0x964b4bddU, 0x61bdbddcU, 0x0d8b8b86U, 0x0f8a8a85U,
-    0xe0707090U, 0x7c3e3e42U, 0x71b5b5c4U, 0xcc6666aaU,
-    0x904848d8U, 0x06030305U, 0xf7f6f601U, 0x1c0e0e12U,
-    0xc26161a3U, 0x6a35355fU, 0xae5757f9U, 0x69b9b9d0U,
-    0x17868691U, 0x99c1c158U, 0x3a1d1d27U, 0x279e9eb9U,
-    0xd9e1e138U, 0xebf8f813U, 0x2b9898b3U, 0x22111133U,
-    0xd26969bbU, 0xa9d9d970U, 0x078e8e89U, 0x339494a7U,
-    0x2d9b9bb6U, 0x3c1e1e22U, 0x15878792U, 0xc9e9e920U,
-    0x87cece49U, 0xaa5555ffU, 0x50282878U, 0xa5dfdf7aU,
-    0x038c8c8fU, 0x59a1a1f8U, 0x09898980U, 0x1a0d0d17U,
-    0x65bfbfdaU, 0xd7e6e631U, 0x844242c6U, 0xd06868b8U,
-    0x824141c3U, 0x299999b0U, 0x5a2d2d77U, 0x1e0f0f11U,
-    0x7bb0b0cbU, 0xa85454fcU, 0x6dbbbbd6U, 0x2c16163aU
+static const u32 Te0[256] = {
+    0xc66363a5U,
+    0xf87c7c84U,
+    0xee777799U,
+    0xf67b7b8dU,
+    0xfff2f20dU,
+    0xd66b6bbdU,
+    0xde6f6fb1U,
+    0x91c5c554U,
+    0x60303050U,
+    0x02010103U,
+    0xce6767a9U,
+    0x562b2b7dU,
+    0xe7fefe19U,
+    0xb5d7d762U,
+    0x4dababe6U,
+    0xec76769aU,
+    0x8fcaca45U,
+    0x1f82829dU,
+    0x89c9c940U,
+    0xfa7d7d87U,
+    0xeffafa15U,
+    0xb25959ebU,
+    0x8e4747c9U,
+    0xfbf0f00bU,
+    0x41adadecU,
+    0xb3d4d467U,
+    0x5fa2a2fdU,
+    0x45afafeaU,
+    0x239c9cbfU,
+    0x53a4a4f7U,
+    0xe4727296U,
+    0x9bc0c05bU,
+    0x75b7b7c2U,
+    0xe1fdfd1cU,
+    0x3d9393aeU,
+    0x4c26266aU,
+    0x6c36365aU,
+    0x7e3f3f41U,
+    0xf5f7f702U,
+    0x83cccc4fU,
+    0x6834345cU,
+    0x51a5a5f4U,
+    0xd1e5e534U,
+    0xf9f1f108U,
+    0xe2717193U,
+    0xabd8d873U,
+    0x62313153U,
+    0x2a15153fU,
+    0x0804040cU,
+    0x95c7c752U,
+    0x46232365U,
+    0x9dc3c35eU,
+    0x30181828U,
+    0x379696a1U,
+    0x0a05050fU,
+    0x2f9a9ab5U,
+    0x0e070709U,
+    0x24121236U,
+    0x1b80809bU,
+    0xdfe2e23dU,
+    0xcdebeb26U,
+    0x4e272769U,
+    0x7fb2b2cdU,
+    0xea75759fU,
+    0x1209091bU,
+    0x1d83839eU,
+    0x582c2c74U,
+    0x341a1a2eU,
+    0x361b1b2dU,
+    0xdc6e6eb2U,
+    0xb45a5aeeU,
+    0x5ba0a0fbU,
+    0xa45252f6U,
+    0x763b3b4dU,
+    0xb7d6d661U,
+    0x7db3b3ceU,
+    0x5229297bU,
+    0xdde3e33eU,
+    0x5e2f2f71U,
+    0x13848497U,
+    0xa65353f5U,
+    0xb9d1d168U,
+    0x00000000U,
+    0xc1eded2cU,
+    0x40202060U,
+    0xe3fcfc1fU,
+    0x79b1b1c8U,
+    0xb65b5bedU,
+    0xd46a6abeU,
+    0x8dcbcb46U,
+    0x67bebed9U,
+    0x7239394bU,
+    0x944a4adeU,
+    0x984c4cd4U,
+    0xb05858e8U,
+    0x85cfcf4aU,
+    0xbbd0d06bU,
+    0xc5efef2aU,
+    0x4faaaae5U,
+    0xedfbfb16U,
+    0x864343c5U,
+    0x9a4d4dd7U,
+    0x66333355U,
+    0x11858594U,
+    0x8a4545cfU,
+    0xe9f9f910U,
+    0x04020206U,
+    0xfe7f7f81U,
+    0xa05050f0U,
+    0x783c3c44U,
+    0x259f9fbaU,
+    0x4ba8a8e3U,
+    0xa25151f3U,
+    0x5da3a3feU,
+    0x804040c0U,
+    0x058f8f8aU,
+    0x3f9292adU,
+    0x219d9dbcU,
+    0x70383848U,
+    0xf1f5f504U,
+    0x63bcbcdfU,
+    0x77b6b6c1U,
+    0xafdada75U,
+    0x42212163U,
+    0x20101030U,
+    0xe5ffff1aU,
+    0xfdf3f30eU,
+    0xbfd2d26dU,
+    0x81cdcd4cU,
+    0x180c0c14U,
+    0x26131335U,
+    0xc3ecec2fU,
+    0xbe5f5fe1U,
+    0x359797a2U,
+    0x884444ccU,
+    0x2e171739U,
+    0x93c4c457U,
+    0x55a7a7f2U,
+    0xfc7e7e82U,
+    0x7a3d3d47U,
+    0xc86464acU,
+    0xba5d5de7U,
+    0x3219192bU,
+    0xe6737395U,
+    0xc06060a0U,
+    0x19818198U,
+    0x9e4f4fd1U,
+    0xa3dcdc7fU,
+    0x44222266U,
+    0x542a2a7eU,
+    0x3b9090abU,
+    0x0b888883U,
+    0x8c4646caU,
+    0xc7eeee29U,
+    0x6bb8b8d3U,
+    0x2814143cU,
+    0xa7dede79U,
+    0xbc5e5ee2U,
+    0x160b0b1dU,
+    0xaddbdb76U,
+    0xdbe0e03bU,
+    0x64323256U,
+    0x743a3a4eU,
+    0x140a0a1eU,
+    0x924949dbU,
+    0x0c06060aU,
+    0x4824246cU,
+    0xb85c5ce4U,
+    0x9fc2c25dU,
+    0xbdd3d36eU,
+    0x43acacefU,
+    0xc46262a6U,
+    0x399191a8U,
+    0x319595a4U,
+    0xd3e4e437U,
+    0xf279798bU,
+    0xd5e7e732U,
+    0x8bc8c843U,
+    0x6e373759U,
+    0xda6d6db7U,
+    0x018d8d8cU,
+    0xb1d5d564U,
+    0x9c4e4ed2U,
+    0x49a9a9e0U,
+    0xd86c6cb4U,
+    0xac5656faU,
+    0xf3f4f407U,
+    0xcfeaea25U,
+    0xca6565afU,
+    0xf47a7a8eU,
+    0x47aeaee9U,
+    0x10080818U,
+    0x6fbabad5U,
+    0xf0787888U,
+    0x4a25256fU,
+    0x5c2e2e72U,
+    0x381c1c24U,
+    0x57a6a6f1U,
+    0x73b4b4c7U,
+    0x97c6c651U,
+    0xcbe8e823U,
+    0xa1dddd7cU,
+    0xe874749cU,
+    0x3e1f1f21U,
+    0x964b4bddU,
+    0x61bdbddcU,
+    0x0d8b8b86U,
+    0x0f8a8a85U,
+    0xe0707090U,
+    0x7c3e3e42U,
+    0x71b5b5c4U,
+    0xcc6666aaU,
+    0x904848d8U,
+    0x06030305U,
+    0xf7f6f601U,
+    0x1c0e0e12U,
+    0xc26161a3U,
+    0x6a35355fU,
+    0xae5757f9U,
+    0x69b9b9d0U,
+    0x17868691U,
+    0x99c1c158U,
+    0x3a1d1d27U,
+    0x279e9eb9U,
+    0xd9e1e138U,
+    0xebf8f813U,
+    0x2b9898b3U,
+    0x22111133U,
+    0xd26969bbU,
+    0xa9d9d970U,
+    0x078e8e89U,
+    0x339494a7U,
+    0x2d9b9bb6U,
+    0x3c1e1e22U,
+    0x15878792U,
+    0xc9e9e920U,
+    0x87cece49U,
+    0xaa5555ffU,
+    0x50282878U,
+    0xa5dfdf7aU,
+    0x038c8c8fU,
+    0x59a1a1f8U,
+    0x09898980U,
+    0x1a0d0d17U,
+    0x65bfbfdaU,
+    0xd7e6e631U,
+    0x844242c6U,
+    0xd06868b8U,
+    0x824141c3U,
+    0x299999b0U,
+    0x5a2d2d77U,
+    0x1e0f0f11U,
+    0x7bb0b0cbU,
+    0xa85454fcU,
+    0x6dbbbbd6U,
+    0x2c16163aU,
 };
-static const uint32_t Te1[256] = {
-    0xa5c66363U, 0x84f87c7cU, 0x99ee7777U, 0x8df67b7bU,
-    0x0dfff2f2U, 0xbdd66b6bU, 0xb1de6f6fU, 0x5491c5c5U,
-    0x50603030U, 0x03020101U, 0xa9ce6767U, 0x7d562b2bU,
-    0x19e7fefeU, 0x62b5d7d7U, 0xe64dababU, 0x9aec7676U,
-    0x458fcacaU, 0x9d1f8282U, 0x4089c9c9U, 0x87fa7d7dU,
-    0x15effafaU, 0xebb25959U, 0xc98e4747U, 0x0bfbf0f0U,
-    0xec41adadU, 0x67b3d4d4U, 0xfd5fa2a2U, 0xea45afafU,
-    0xbf239c9cU, 0xf753a4a4U, 0x96e47272U, 0x5b9bc0c0U,
-    0xc275b7b7U, 0x1ce1fdfdU, 0xae3d9393U, 0x6a4c2626U,
-    0x5a6c3636U, 0x417e3f3fU, 0x02f5f7f7U, 0x4f83ccccU,
-    0x5c683434U, 0xf451a5a5U, 0x34d1e5e5U, 0x08f9f1f1U,
-    0x93e27171U, 0x73abd8d8U, 0x53623131U, 0x3f2a1515U,
-    0x0c080404U, 0x5295c7c7U, 0x65462323U, 0x5e9dc3c3U,
-    0x28301818U, 0xa1379696U, 0x0f0a0505U, 0xb52f9a9aU,
-    0x090e0707U, 0x36241212U, 0x9b1b8080U, 0x3ddfe2e2U,
-    0x26cdebebU, 0x694e2727U, 0xcd7fb2b2U, 0x9fea7575U,
-    0x1b120909U, 0x9e1d8383U, 0x74582c2cU, 0x2e341a1aU,
-    0x2d361b1bU, 0xb2dc6e6eU, 0xeeb45a5aU, 0xfb5ba0a0U,
-    0xf6a45252U, 0x4d763b3bU, 0x61b7d6d6U, 0xce7db3b3U,
-    0x7b522929U, 0x3edde3e3U, 0x715e2f2fU, 0x97138484U,
-    0xf5a65353U, 0x68b9d1d1U, 0x00000000U, 0x2cc1ededU,
-    0x60402020U, 0x1fe3fcfcU, 0xc879b1b1U, 0xedb65b5bU,
-    0xbed46a6aU, 0x468dcbcbU, 0xd967bebeU, 0x4b723939U,
-    0xde944a4aU, 0xd4984c4cU, 0xe8b05858U, 0x4a85cfcfU,
-    0x6bbbd0d0U, 0x2ac5efefU, 0xe54faaaaU, 0x16edfbfbU,
-    0xc5864343U, 0xd79a4d4dU, 0x55663333U, 0x94118585U,
-    0xcf8a4545U, 0x10e9f9f9U, 0x06040202U, 0x81fe7f7fU,
-    0xf0a05050U, 0x44783c3cU, 0xba259f9fU, 0xe34ba8a8U,
-    0xf3a25151U, 0xfe5da3a3U, 0xc0804040U, 0x8a058f8fU,
-    0xad3f9292U, 0xbc219d9dU, 0x48703838U, 0x04f1f5f5U,
-    0xdf63bcbcU, 0xc177b6b6U, 0x75afdadaU, 0x63422121U,
-    0x30201010U, 0x1ae5ffffU, 0x0efdf3f3U, 0x6dbfd2d2U,
-    0x4c81cdcdU, 0x14180c0cU, 0x35261313U, 0x2fc3ececU,
-    0xe1be5f5fU, 0xa2359797U, 0xcc884444U, 0x392e1717U,
-    0x5793c4c4U, 0xf255a7a7U, 0x82fc7e7eU, 0x477a3d3dU,
-    0xacc86464U, 0xe7ba5d5dU, 0x2b321919U, 0x95e67373U,
-    0xa0c06060U, 0x98198181U, 0xd19e4f4fU, 0x7fa3dcdcU,
-    0x66442222U, 0x7e542a2aU, 0xab3b9090U, 0x830b8888U,
-    0xca8c4646U, 0x29c7eeeeU, 0xd36bb8b8U, 0x3c281414U,
-    0x79a7dedeU, 0xe2bc5e5eU, 0x1d160b0bU, 0x76addbdbU,
-    0x3bdbe0e0U, 0x56643232U, 0x4e743a3aU, 0x1e140a0aU,
-    0xdb924949U, 0x0a0c0606U, 0x6c482424U, 0xe4b85c5cU,
-    0x5d9fc2c2U, 0x6ebdd3d3U, 0xef43acacU, 0xa6c46262U,
-    0xa8399191U, 0xa4319595U, 0x37d3e4e4U, 0x8bf27979U,
-    0x32d5e7e7U, 0x438bc8c8U, 0x596e3737U, 0xb7da6d6dU,
-    0x8c018d8dU, 0x64b1d5d5U, 0xd29c4e4eU, 0xe049a9a9U,
-    0xb4d86c6cU, 0xfaac5656U, 0x07f3f4f4U, 0x25cfeaeaU,
-    0xafca6565U, 0x8ef47a7aU, 0xe947aeaeU, 0x18100808U,
-    0xd56fbabaU, 0x88f07878U, 0x6f4a2525U, 0x725c2e2eU,
-    0x24381c1cU, 0xf157a6a6U, 0xc773b4b4U, 0x5197c6c6U,
-    0x23cbe8e8U, 0x7ca1ddddU, 0x9ce87474U, 0x213e1f1fU,
-    0xdd964b4bU, 0xdc61bdbdU, 0x860d8b8bU, 0x850f8a8aU,
-    0x90e07070U, 0x427c3e3eU, 0xc471b5b5U, 0xaacc6666U,
-    0xd8904848U, 0x05060303U, 0x01f7f6f6U, 0x121c0e0eU,
-    0xa3c26161U, 0x5f6a3535U, 0xf9ae5757U, 0xd069b9b9U,
-    0x91178686U, 0x5899c1c1U, 0x273a1d1dU, 0xb9279e9eU,
-    0x38d9e1e1U, 0x13ebf8f8U, 0xb32b9898U, 0x33221111U,
-    0xbbd26969U, 0x70a9d9d9U, 0x89078e8eU, 0xa7339494U,
-    0xb62d9b9bU, 0x223c1e1eU, 0x92158787U, 0x20c9e9e9U,
-    0x4987ceceU, 0xffaa5555U, 0x78502828U, 0x7aa5dfdfU,
-    0x8f038c8cU, 0xf859a1a1U, 0x80098989U, 0x171a0d0dU,
-    0xda65bfbfU, 0x31d7e6e6U, 0xc6844242U, 0xb8d06868U,
-    0xc3824141U, 0xb0299999U, 0x775a2d2dU, 0x111e0f0fU,
-    0xcb7bb0b0U, 0xfca85454U, 0xd66dbbbbU, 0x3a2c1616U
+static const u32 Te1[256] = {
+    0xa5c66363U,
+    0x84f87c7cU,
+    0x99ee7777U,
+    0x8df67b7bU,
+    0x0dfff2f2U,
+    0xbdd66b6bU,
+    0xb1de6f6fU,
+    0x5491c5c5U,
+    0x50603030U,
+    0x03020101U,
+    0xa9ce6767U,
+    0x7d562b2bU,
+    0x19e7fefeU,
+    0x62b5d7d7U,
+    0xe64dababU,
+    0x9aec7676U,
+    0x458fcacaU,
+    0x9d1f8282U,
+    0x4089c9c9U,
+    0x87fa7d7dU,
+    0x15effafaU,
+    0xebb25959U,
+    0xc98e4747U,
+    0x0bfbf0f0U,
+    0xec41adadU,
+    0x67b3d4d4U,
+    0xfd5fa2a2U,
+    0xea45afafU,
+    0xbf239c9cU,
+    0xf753a4a4U,
+    0x96e47272U,
+    0x5b9bc0c0U,
+    0xc275b7b7U,
+    0x1ce1fdfdU,
+    0xae3d9393U,
+    0x6a4c2626U,
+    0x5a6c3636U,
+    0x417e3f3fU,
+    0x02f5f7f7U,
+    0x4f83ccccU,
+    0x5c683434U,
+    0xf451a5a5U,
+    0x34d1e5e5U,
+    0x08f9f1f1U,
+    0x93e27171U,
+    0x73abd8d8U,
+    0x53623131U,
+    0x3f2a1515U,
+    0x0c080404U,
+    0x5295c7c7U,
+    0x65462323U,
+    0x5e9dc3c3U,
+    0x28301818U,
+    0xa1379696U,
+    0x0f0a0505U,
+    0xb52f9a9aU,
+    0x090e0707U,
+    0x36241212U,
+    0x9b1b8080U,
+    0x3ddfe2e2U,
+    0x26cdebebU,
+    0x694e2727U,
+    0xcd7fb2b2U,
+    0x9fea7575U,
+    0x1b120909U,
+    0x9e1d8383U,
+    0x74582c2cU,
+    0x2e341a1aU,
+    0x2d361b1bU,
+    0xb2dc6e6eU,
+    0xeeb45a5aU,
+    0xfb5ba0a0U,
+    0xf6a45252U,
+    0x4d763b3bU,
+    0x61b7d6d6U,
+    0xce7db3b3U,
+    0x7b522929U,
+    0x3edde3e3U,
+    0x715e2f2fU,
+    0x97138484U,
+    0xf5a65353U,
+    0x68b9d1d1U,
+    0x00000000U,
+    0x2cc1ededU,
+    0x60402020U,
+    0x1fe3fcfcU,
+    0xc879b1b1U,
+    0xedb65b5bU,
+    0xbed46a6aU,
+    0x468dcbcbU,
+    0xd967bebeU,
+    0x4b723939U,
+    0xde944a4aU,
+    0xd4984c4cU,
+    0xe8b05858U,
+    0x4a85cfcfU,
+    0x6bbbd0d0U,
+    0x2ac5efefU,
+    0xe54faaaaU,
+    0x16edfbfbU,
+    0xc5864343U,
+    0xd79a4d4dU,
+    0x55663333U,
+    0x94118585U,
+    0xcf8a4545U,
+    0x10e9f9f9U,
+    0x06040202U,
+    0x81fe7f7fU,
+    0xf0a05050U,
+    0x44783c3cU,
+    0xba259f9fU,
+    0xe34ba8a8U,
+    0xf3a25151U,
+    0xfe5da3a3U,
+    0xc0804040U,
+    0x8a058f8fU,
+    0xad3f9292U,
+    0xbc219d9dU,
+    0x48703838U,
+    0x04f1f5f5U,
+    0xdf63bcbcU,
+    0xc177b6b6U,
+    0x75afdadaU,
+    0x63422121U,
+    0x30201010U,
+    0x1ae5ffffU,
+    0x0efdf3f3U,
+    0x6dbfd2d2U,
+    0x4c81cdcdU,
+    0x14180c0cU,
+    0x35261313U,
+    0x2fc3ececU,
+    0xe1be5f5fU,
+    0xa2359797U,
+    0xcc884444U,
+    0x392e1717U,
+    0x5793c4c4U,
+    0xf255a7a7U,
+    0x82fc7e7eU,
+    0x477a3d3dU,
+    0xacc86464U,
+    0xe7ba5d5dU,
+    0x2b321919U,
+    0x95e67373U,
+    0xa0c06060U,
+    0x98198181U,
+    0xd19e4f4fU,
+    0x7fa3dcdcU,
+    0x66442222U,
+    0x7e542a2aU,
+    0xab3b9090U,
+    0x830b8888U,
+    0xca8c4646U,
+    0x29c7eeeeU,
+    0xd36bb8b8U,
+    0x3c281414U,
+    0x79a7dedeU,
+    0xe2bc5e5eU,
+    0x1d160b0bU,
+    0x76addbdbU,
+    0x3bdbe0e0U,
+    0x56643232U,
+    0x4e743a3aU,
+    0x1e140a0aU,
+    0xdb924949U,
+    0x0a0c0606U,
+    0x6c482424U,
+    0xe4b85c5cU,
+    0x5d9fc2c2U,
+    0x6ebdd3d3U,
+    0xef43acacU,
+    0xa6c46262U,
+    0xa8399191U,
+    0xa4319595U,
+    0x37d3e4e4U,
+    0x8bf27979U,
+    0x32d5e7e7U,
+    0x438bc8c8U,
+    0x596e3737U,
+    0xb7da6d6dU,
+    0x8c018d8dU,
+    0x64b1d5d5U,
+    0xd29c4e4eU,
+    0xe049a9a9U,
+    0xb4d86c6cU,
+    0xfaac5656U,
+    0x07f3f4f4U,
+    0x25cfeaeaU,
+    0xafca6565U,
+    0x8ef47a7aU,
+    0xe947aeaeU,
+    0x18100808U,
+    0xd56fbabaU,
+    0x88f07878U,
+    0x6f4a2525U,
+    0x725c2e2eU,
+    0x24381c1cU,
+    0xf157a6a6U,
+    0xc773b4b4U,
+    0x5197c6c6U,
+    0x23cbe8e8U,
+    0x7ca1ddddU,
+    0x9ce87474U,
+    0x213e1f1fU,
+    0xdd964b4bU,
+    0xdc61bdbdU,
+    0x860d8b8bU,
+    0x850f8a8aU,
+    0x90e07070U,
+    0x427c3e3eU,
+    0xc471b5b5U,
+    0xaacc6666U,
+    0xd8904848U,
+    0x05060303U,
+    0x01f7f6f6U,
+    0x121c0e0eU,
+    0xa3c26161U,
+    0x5f6a3535U,
+    0xf9ae5757U,
+    0xd069b9b9U,
+    0x91178686U,
+    0x5899c1c1U,
+    0x273a1d1dU,
+    0xb9279e9eU,
+    0x38d9e1e1U,
+    0x13ebf8f8U,
+    0xb32b9898U,
+    0x33221111U,
+    0xbbd26969U,
+    0x70a9d9d9U,
+    0x89078e8eU,
+    0xa7339494U,
+    0xb62d9b9bU,
+    0x223c1e1eU,
+    0x92158787U,
+    0x20c9e9e9U,
+    0x4987ceceU,
+    0xffaa5555U,
+    0x78502828U,
+    0x7aa5dfdfU,
+    0x8f038c8cU,
+    0xf859a1a1U,
+    0x80098989U,
+    0x171a0d0dU,
+    0xda65bfbfU,
+    0x31d7e6e6U,
+    0xc6844242U,
+    0xb8d06868U,
+    0xc3824141U,
+    0xb0299999U,
+    0x775a2d2dU,
+    0x111e0f0fU,
+    0xcb7bb0b0U,
+    0xfca85454U,
+    0xd66dbbbbU,
+    0x3a2c1616U,
 };
-static const uint32_t Te2[256] = {
-    0x63a5c663U, 0x7c84f87cU, 0x7799ee77U, 0x7b8df67bU,
-    0xf20dfff2U, 0x6bbdd66bU, 0x6fb1de6fU, 0xc55491c5U,
-    0x30506030U, 0x01030201U, 0x67a9ce67U, 0x2b7d562bU,
-    0xfe19e7feU, 0xd762b5d7U, 0xabe64dabU, 0x769aec76U,
-    0xca458fcaU, 0x829d1f82U, 0xc94089c9U, 0x7d87fa7dU,
-    0xfa15effaU, 0x59ebb259U, 0x47c98e47U, 0xf00bfbf0U,
-    0xadec41adU, 0xd467b3d4U, 0xa2fd5fa2U, 0xafea45afU,
-    0x9cbf239cU, 0xa4f753a4U, 0x7296e472U, 0xc05b9bc0U,
-    0xb7c275b7U, 0xfd1ce1fdU, 0x93ae3d93U, 0x266a4c26U,
-    0x365a6c36U, 0x3f417e3fU, 0xf702f5f7U, 0xcc4f83ccU,
-    0x345c6834U, 0xa5f451a5U, 0xe534d1e5U, 0xf108f9f1U,
-    0x7193e271U, 0xd873abd8U, 0x31536231U, 0x153f2a15U,
-    0x040c0804U, 0xc75295c7U, 0x23654623U, 0xc35e9dc3U,
-    0x18283018U, 0x96a13796U, 0x050f0a05U, 0x9ab52f9aU,
-    0x07090e07U, 0x12362412U, 0x809b1b80U, 0xe23ddfe2U,
-    0xeb26cdebU, 0x27694e27U, 0xb2cd7fb2U, 0x759fea75U,
-    0x091b1209U, 0x839e1d83U, 0x2c74582cU, 0x1a2e341aU,
-    0x1b2d361bU, 0x6eb2dc6eU, 0x5aeeb45aU, 0xa0fb5ba0U,
-    0x52f6a452U, 0x3b4d763bU, 0xd661b7d6U, 0xb3ce7db3U,
-    0x297b5229U, 0xe33edde3U, 0x2f715e2fU, 0x84971384U,
-    0x53f5a653U, 0xd168b9d1U, 0x00000000U, 0xed2cc1edU,
-    0x20604020U, 0xfc1fe3fcU, 0xb1c879b1U, 0x5bedb65bU,
-    0x6abed46aU, 0xcb468dcbU, 0xbed967beU, 0x394b7239U,
-    0x4ade944aU, 0x4cd4984cU, 0x58e8b058U, 0xcf4a85cfU,
-    0xd06bbbd0U, 0xef2ac5efU, 0xaae54faaU, 0xfb16edfbU,
-    0x43c58643U, 0x4dd79a4dU, 0x33556633U, 0x85941185U,
-    0x45cf8a45U, 0xf910e9f9U, 0x02060402U, 0x7f81fe7fU,
-    0x50f0a050U, 0x3c44783cU, 0x9fba259fU, 0xa8e34ba8U,
-    0x51f3a251U, 0xa3fe5da3U, 0x40c08040U, 0x8f8a058fU,
-    0x92ad3f92U, 0x9dbc219dU, 0x38487038U, 0xf504f1f5U,
-    0xbcdf63bcU, 0xb6c177b6U, 0xda75afdaU, 0x21634221U,
-    0x10302010U, 0xff1ae5ffU, 0xf30efdf3U, 0xd26dbfd2U,
-    0xcd4c81cdU, 0x0c14180cU, 0x13352613U, 0xec2fc3ecU,
-    0x5fe1be5fU, 0x97a23597U, 0x44cc8844U, 0x17392e17U,
-    0xc45793c4U, 0xa7f255a7U, 0x7e82fc7eU, 0x3d477a3dU,
-    0x64acc864U, 0x5de7ba5dU, 0x192b3219U, 0x7395e673U,
-    0x60a0c060U, 0x81981981U, 0x4fd19e4fU, 0xdc7fa3dcU,
-    0x22664422U, 0x2a7e542aU, 0x90ab3b90U, 0x88830b88U,
-    0x46ca8c46U, 0xee29c7eeU, 0xb8d36bb8U, 0x143c2814U,
-    0xde79a7deU, 0x5ee2bc5eU, 0x0b1d160bU, 0xdb76addbU,
-    0xe03bdbe0U, 0x32566432U, 0x3a4e743aU, 0x0a1e140aU,
-    0x49db9249U, 0x060a0c06U, 0x246c4824U, 0x5ce4b85cU,
-    0xc25d9fc2U, 0xd36ebdd3U, 0xacef43acU, 0x62a6c462U,
-    0x91a83991U, 0x95a43195U, 0xe437d3e4U, 0x798bf279U,
-    0xe732d5e7U, 0xc8438bc8U, 0x37596e37U, 0x6db7da6dU,
-    0x8d8c018dU, 0xd564b1d5U, 0x4ed29c4eU, 0xa9e049a9U,
-    0x6cb4d86cU, 0x56faac56U, 0xf407f3f4U, 0xea25cfeaU,
-    0x65afca65U, 0x7a8ef47aU, 0xaee947aeU, 0x08181008U,
-    0xbad56fbaU, 0x7888f078U, 0x256f4a25U, 0x2e725c2eU,
-    0x1c24381cU, 0xa6f157a6U, 0xb4c773b4U, 0xc65197c6U,
-    0xe823cbe8U, 0xdd7ca1ddU, 0x749ce874U, 0x1f213e1fU,
-    0x4bdd964bU, 0xbddc61bdU, 0x8b860d8bU, 0x8a850f8aU,
-    0x7090e070U, 0x3e427c3eU, 0xb5c471b5U, 0x66aacc66U,
-    0x48d89048U, 0x03050603U, 0xf601f7f6U, 0x0e121c0eU,
-    0x61a3c261U, 0x355f6a35U, 0x57f9ae57U, 0xb9d069b9U,
-    0x86911786U, 0xc15899c1U, 0x1d273a1dU, 0x9eb9279eU,
-    0xe138d9e1U, 0xf813ebf8U, 0x98b32b98U, 0x11332211U,
-    0x69bbd269U, 0xd970a9d9U, 0x8e89078eU, 0x94a73394U,
-    0x9bb62d9bU, 0x1e223c1eU, 0x87921587U, 0xe920c9e9U,
-    0xce4987ceU, 0x55ffaa55U, 0x28785028U, 0xdf7aa5dfU,
-    0x8c8f038cU, 0xa1f859a1U, 0x89800989U, 0x0d171a0dU,
-    0xbfda65bfU, 0xe631d7e6U, 0x42c68442U, 0x68b8d068U,
-    0x41c38241U, 0x99b02999U, 0x2d775a2dU, 0x0f111e0fU,
-    0xb0cb7bb0U, 0x54fca854U, 0xbbd66dbbU, 0x163a2c16U
+static const u32 Te2[256] = {
+    0x63a5c663U,
+    0x7c84f87cU,
+    0x7799ee77U,
+    0x7b8df67bU,
+    0xf20dfff2U,
+    0x6bbdd66bU,
+    0x6fb1de6fU,
+    0xc55491c5U,
+    0x30506030U,
+    0x01030201U,
+    0x67a9ce67U,
+    0x2b7d562bU,
+    0xfe19e7feU,
+    0xd762b5d7U,
+    0xabe64dabU,
+    0x769aec76U,
+    0xca458fcaU,
+    0x829d1f82U,
+    0xc94089c9U,
+    0x7d87fa7dU,
+    0xfa15effaU,
+    0x59ebb259U,
+    0x47c98e47U,
+    0xf00bfbf0U,
+    0xadec41adU,
+    0xd467b3d4U,
+    0xa2fd5fa2U,
+    0xafea45afU,
+    0x9cbf239cU,
+    0xa4f753a4U,
+    0x7296e472U,
+    0xc05b9bc0U,
+    0xb7c275b7U,
+    0xfd1ce1fdU,
+    0x93ae3d93U,
+    0x266a4c26U,
+    0x365a6c36U,
+    0x3f417e3fU,
+    0xf702f5f7U,
+    0xcc4f83ccU,
+    0x345c6834U,
+    0xa5f451a5U,
+    0xe534d1e5U,
+    0xf108f9f1U,
+    0x7193e271U,
+    0xd873abd8U,
+    0x31536231U,
+    0x153f2a15U,
+    0x040c0804U,
+    0xc75295c7U,
+    0x23654623U,
+    0xc35e9dc3U,
+    0x18283018U,
+    0x96a13796U,
+    0x050f0a05U,
+    0x9ab52f9aU,
+    0x07090e07U,
+    0x12362412U,
+    0x809b1b80U,
+    0xe23ddfe2U,
+    0xeb26cdebU,
+    0x27694e27U,
+    0xb2cd7fb2U,
+    0x759fea75U,
+    0x091b1209U,
+    0x839e1d83U,
+    0x2c74582cU,
+    0x1a2e341aU,
+    0x1b2d361bU,
+    0x6eb2dc6eU,
+    0x5aeeb45aU,
+    0xa0fb5ba0U,
+    0x52f6a452U,
+    0x3b4d763bU,
+    0xd661b7d6U,
+    0xb3ce7db3U,
+    0x297b5229U,
+    0xe33edde3U,
+    0x2f715e2fU,
+    0x84971384U,
+    0x53f5a653U,
+    0xd168b9d1U,
+    0x00000000U,
+    0xed2cc1edU,
+    0x20604020U,
+    0xfc1fe3fcU,
+    0xb1c879b1U,
+    0x5bedb65bU,
+    0x6abed46aU,
+    0xcb468dcbU,
+    0xbed967beU,
+    0x394b7239U,
+    0x4ade944aU,
+    0x4cd4984cU,
+    0x58e8b058U,
+    0xcf4a85cfU,
+    0xd06bbbd0U,
+    0xef2ac5efU,
+    0xaae54faaU,
+    0xfb16edfbU,
+    0x43c58643U,
+    0x4dd79a4dU,
+    0x33556633U,
+    0x85941185U,
+    0x45cf8a45U,
+    0xf910e9f9U,
+    0x02060402U,
+    0x7f81fe7fU,
+    0x50f0a050U,
+    0x3c44783cU,
+    0x9fba259fU,
+    0xa8e34ba8U,
+    0x51f3a251U,
+    0xa3fe5da3U,
+    0x40c08040U,
+    0x8f8a058fU,
+    0x92ad3f92U,
+    0x9dbc219dU,
+    0x38487038U,
+    0xf504f1f5U,
+    0xbcdf63bcU,
+    0xb6c177b6U,
+    0xda75afdaU,
+    0x21634221U,
+    0x10302010U,
+    0xff1ae5ffU,
+    0xf30efdf3U,
+    0xd26dbfd2U,
+    0xcd4c81cdU,
+    0x0c14180cU,
+    0x13352613U,
+    0xec2fc3ecU,
+    0x5fe1be5fU,
+    0x97a23597U,
+    0x44cc8844U,
+    0x17392e17U,
+    0xc45793c4U,
+    0xa7f255a7U,
+    0x7e82fc7eU,
+    0x3d477a3dU,
+    0x64acc864U,
+    0x5de7ba5dU,
+    0x192b3219U,
+    0x7395e673U,
+    0x60a0c060U,
+    0x81981981U,
+    0x4fd19e4fU,
+    0xdc7fa3dcU,
+    0x22664422U,
+    0x2a7e542aU,
+    0x90ab3b90U,
+    0x88830b88U,
+    0x46ca8c46U,
+    0xee29c7eeU,
+    0xb8d36bb8U,
+    0x143c2814U,
+    0xde79a7deU,
+    0x5ee2bc5eU,
+    0x0b1d160bU,
+    0xdb76addbU,
+    0xe03bdbe0U,
+    0x32566432U,
+    0x3a4e743aU,
+    0x0a1e140aU,
+    0x49db9249U,
+    0x060a0c06U,
+    0x246c4824U,
+    0x5ce4b85cU,
+    0xc25d9fc2U,
+    0xd36ebdd3U,
+    0xacef43acU,
+    0x62a6c462U,
+    0x91a83991U,
+    0x95a43195U,
+    0xe437d3e4U,
+    0x798bf279U,
+    0xe732d5e7U,
+    0xc8438bc8U,
+    0x37596e37U,
+    0x6db7da6dU,
+    0x8d8c018dU,
+    0xd564b1d5U,
+    0x4ed29c4eU,
+    0xa9e049a9U,
+    0x6cb4d86cU,
+    0x56faac56U,
+    0xf407f3f4U,
+    0xea25cfeaU,
+    0x65afca65U,
+    0x7a8ef47aU,
+    0xaee947aeU,
+    0x08181008U,
+    0xbad56fbaU,
+    0x7888f078U,
+    0x256f4a25U,
+    0x2e725c2eU,
+    0x1c24381cU,
+    0xa6f157a6U,
+    0xb4c773b4U,
+    0xc65197c6U,
+    0xe823cbe8U,
+    0xdd7ca1ddU,
+    0x749ce874U,
+    0x1f213e1fU,
+    0x4bdd964bU,
+    0xbddc61bdU,
+    0x8b860d8bU,
+    0x8a850f8aU,
+    0x7090e070U,
+    0x3e427c3eU,
+    0xb5c471b5U,
+    0x66aacc66U,
+    0x48d89048U,
+    0x03050603U,
+    0xf601f7f6U,
+    0x0e121c0eU,
+    0x61a3c261U,
+    0x355f6a35U,
+    0x57f9ae57U,
+    0xb9d069b9U,
+    0x86911786U,
+    0xc15899c1U,
+    0x1d273a1dU,
+    0x9eb9279eU,
+    0xe138d9e1U,
+    0xf813ebf8U,
+    0x98b32b98U,
+    0x11332211U,
+    0x69bbd269U,
+    0xd970a9d9U,
+    0x8e89078eU,
+    0x94a73394U,
+    0x9bb62d9bU,
+    0x1e223c1eU,
+    0x87921587U,
+    0xe920c9e9U,
+    0xce4987ceU,
+    0x55ffaa55U,
+    0x28785028U,
+    0xdf7aa5dfU,
+    0x8c8f038cU,
+    0xa1f859a1U,
+    0x89800989U,
+    0x0d171a0dU,
+    0xbfda65bfU,
+    0xe631d7e6U,
+    0x42c68442U,
+    0x68b8d068U,
+    0x41c38241U,
+    0x99b02999U,
+    0x2d775a2dU,
+    0x0f111e0fU,
+    0xb0cb7bb0U,
+    0x54fca854U,
+    0xbbd66dbbU,
+    0x163a2c16U,
 };
-static const uint32_t Te3[256] = {
-    0x6363a5c6U, 0x7c7c84f8U, 0x777799eeU, 0x7b7b8df6U,
-    0xf2f20dffU, 0x6b6bbdd6U, 0x6f6fb1deU, 0xc5c55491U,
-    0x30305060U, 0x01010302U, 0x6767a9ceU, 0x2b2b7d56U,
-    0xfefe19e7U, 0xd7d762b5U, 0xababe64dU, 0x76769aecU,
-    0xcaca458fU, 0x82829d1fU, 0xc9c94089U, 0x7d7d87faU,
-    0xfafa15efU, 0x5959ebb2U, 0x4747c98eU, 0xf0f00bfbU,
-    0xadadec41U, 0xd4d467b3U, 0xa2a2fd5fU, 0xafafea45U,
-    0x9c9cbf23U, 0xa4a4f753U, 0x727296e4U, 0xc0c05b9bU,
-    0xb7b7c275U, 0xfdfd1ce1U, 0x9393ae3dU, 0x26266a4cU,
-    0x36365a6cU, 0x3f3f417eU, 0xf7f702f5U, 0xcccc4f83U,
-    0x34345c68U, 0xa5a5f451U, 0xe5e534d1U, 0xf1f108f9U,
-    0x717193e2U, 0xd8d873abU, 0x31315362U, 0x15153f2aU,
-    0x04040c08U, 0xc7c75295U, 0x23236546U, 0xc3c35e9dU,
-    0x18182830U, 0x9696a137U, 0x05050f0aU, 0x9a9ab52fU,
-    0x0707090eU, 0x12123624U, 0x80809b1bU, 0xe2e23ddfU,
-    0xebeb26cdU, 0x2727694eU, 0xb2b2cd7fU, 0x75759feaU,
-    0x09091b12U, 0x83839e1dU, 0x2c2c7458U, 0x1a1a2e34U,
-    0x1b1b2d36U, 0x6e6eb2dcU, 0x5a5aeeb4U, 0xa0a0fb5bU,
-    0x5252f6a4U, 0x3b3b4d76U, 0xd6d661b7U, 0xb3b3ce7dU,
-    0x29297b52U, 0xe3e33eddU, 0x2f2f715eU, 0x84849713U,
-    0x5353f5a6U, 0xd1d168b9U, 0x00000000U, 0xeded2cc1U,
-    0x20206040U, 0xfcfc1fe3U, 0xb1b1c879U, 0x5b5bedb6U,
-    0x6a6abed4U, 0xcbcb468dU, 0xbebed967U, 0x39394b72U,
-    0x4a4ade94U, 0x4c4cd498U, 0x5858e8b0U, 0xcfcf4a85U,
-    0xd0d06bbbU, 0xefef2ac5U, 0xaaaae54fU, 0xfbfb16edU,
-    0x4343c586U, 0x4d4dd79aU, 0x33335566U, 0x85859411U,
-    0x4545cf8aU, 0xf9f910e9U, 0x02020604U, 0x7f7f81feU,
-    0x5050f0a0U, 0x3c3c4478U, 0x9f9fba25U, 0xa8a8e34bU,
-    0x5151f3a2U, 0xa3a3fe5dU, 0x4040c080U, 0x8f8f8a05U,
-    0x9292ad3fU, 0x9d9dbc21U, 0x38384870U, 0xf5f504f1U,
-    0xbcbcdf63U, 0xb6b6c177U, 0xdada75afU, 0x21216342U,
-    0x10103020U, 0xffff1ae5U, 0xf3f30efdU, 0xd2d26dbfU,
-    0xcdcd4c81U, 0x0c0c1418U, 0x13133526U, 0xecec2fc3U,
-    0x5f5fe1beU, 0x9797a235U, 0x4444cc88U, 0x1717392eU,
-    0xc4c45793U, 0xa7a7f255U, 0x7e7e82fcU, 0x3d3d477aU,
-    0x6464acc8U, 0x5d5de7baU, 0x19192b32U, 0x737395e6U,
-    0x6060a0c0U, 0x81819819U, 0x4f4fd19eU, 0xdcdc7fa3U,
-    0x22226644U, 0x2a2a7e54U, 0x9090ab3bU, 0x8888830bU,
-    0x4646ca8cU, 0xeeee29c7U, 0xb8b8d36bU, 0x14143c28U,
-    0xdede79a7U, 0x5e5ee2bcU, 0x0b0b1d16U, 0xdbdb76adU,
-    0xe0e03bdbU, 0x32325664U, 0x3a3a4e74U, 0x0a0a1e14U,
-    0x4949db92U, 0x06060a0cU, 0x24246c48U, 0x5c5ce4b8U,
-    0xc2c25d9fU, 0xd3d36ebdU, 0xacacef43U, 0x6262a6c4U,
-    0x9191a839U, 0x9595a431U, 0xe4e437d3U, 0x79798bf2U,
-    0xe7e732d5U, 0xc8c8438bU, 0x3737596eU, 0x6d6db7daU,
-    0x8d8d8c01U, 0xd5d564b1U, 0x4e4ed29cU, 0xa9a9e049U,
-    0x6c6cb4d8U, 0x5656faacU, 0xf4f407f3U, 0xeaea25cfU,
-    0x6565afcaU, 0x7a7a8ef4U, 0xaeaee947U, 0x08081810U,
-    0xbabad56fU, 0x787888f0U, 0x25256f4aU, 0x2e2e725cU,
-    0x1c1c2438U, 0xa6a6f157U, 0xb4b4c773U, 0xc6c65197U,
-    0xe8e823cbU, 0xdddd7ca1U, 0x74749ce8U, 0x1f1f213eU,
-    0x4b4bdd96U, 0xbdbddc61U, 0x8b8b860dU, 0x8a8a850fU,
-    0x707090e0U, 0x3e3e427cU, 0xb5b5c471U, 0x6666aaccU,
-    0x4848d890U, 0x03030506U, 0xf6f601f7U, 0x0e0e121cU,
-    0x6161a3c2U, 0x35355f6aU, 0x5757f9aeU, 0xb9b9d069U,
-    0x86869117U, 0xc1c15899U, 0x1d1d273aU, 0x9e9eb927U,
-    0xe1e138d9U, 0xf8f813ebU, 0x9898b32bU, 0x11113322U,
-    0x6969bbd2U, 0xd9d970a9U, 0x8e8e8907U, 0x9494a733U,
-    0x9b9bb62dU, 0x1e1e223cU, 0x87879215U, 0xe9e920c9U,
-    0xcece4987U, 0x5555ffaaU, 0x28287850U, 0xdfdf7aa5U,
-    0x8c8c8f03U, 0xa1a1f859U, 0x89898009U, 0x0d0d171aU,
-    0xbfbfda65U, 0xe6e631d7U, 0x4242c684U, 0x6868b8d0U,
-    0x4141c382U, 0x9999b029U, 0x2d2d775aU, 0x0f0f111eU,
-    0xb0b0cb7bU, 0x5454fca8U, 0xbbbbd66dU, 0x16163a2cU
+static const u32 Te3[256] = {
+    0x6363a5c6U,
+    0x7c7c84f8U,
+    0x777799eeU,
+    0x7b7b8df6U,
+    0xf2f20dffU,
+    0x6b6bbdd6U,
+    0x6f6fb1deU,
+    0xc5c55491U,
+    0x30305060U,
+    0x01010302U,
+    0x6767a9ceU,
+    0x2b2b7d56U,
+    0xfefe19e7U,
+    0xd7d762b5U,
+    0xababe64dU,
+    0x76769aecU,
+    0xcaca458fU,
+    0x82829d1fU,
+    0xc9c94089U,
+    0x7d7d87faU,
+    0xfafa15efU,
+    0x5959ebb2U,
+    0x4747c98eU,
+    0xf0f00bfbU,
+    0xadadec41U,
+    0xd4d467b3U,
+    0xa2a2fd5fU,
+    0xafafea45U,
+    0x9c9cbf23U,
+    0xa4a4f753U,
+    0x727296e4U,
+    0xc0c05b9bU,
+    0xb7b7c275U,
+    0xfdfd1ce1U,
+    0x9393ae3dU,
+    0x26266a4cU,
+    0x36365a6cU,
+    0x3f3f417eU,
+    0xf7f702f5U,
+    0xcccc4f83U,
+    0x34345c68U,
+    0xa5a5f451U,
+    0xe5e534d1U,
+    0xf1f108f9U,
+    0x717193e2U,
+    0xd8d873abU,
+    0x31315362U,
+    0x15153f2aU,
+    0x04040c08U,
+    0xc7c75295U,
+    0x23236546U,
+    0xc3c35e9dU,
+    0x18182830U,
+    0x9696a137U,
+    0x05050f0aU,
+    0x9a9ab52fU,
+    0x0707090eU,
+    0x12123624U,
+    0x80809b1bU,
+    0xe2e23ddfU,
+    0xebeb26cdU,
+    0x2727694eU,
+    0xb2b2cd7fU,
+    0x75759feaU,
+    0x09091b12U,
+    0x83839e1dU,
+    0x2c2c7458U,
+    0x1a1a2e34U,
+    0x1b1b2d36U,
+    0x6e6eb2dcU,
+    0x5a5aeeb4U,
+    0xa0a0fb5bU,
+    0x5252f6a4U,
+    0x3b3b4d76U,
+    0xd6d661b7U,
+    0xb3b3ce7dU,
+    0x29297b52U,
+    0xe3e33eddU,
+    0x2f2f715eU,
+    0x84849713U,
+    0x5353f5a6U,
+    0xd1d168b9U,
+    0x00000000U,
+    0xeded2cc1U,
+    0x20206040U,
+    0xfcfc1fe3U,
+    0xb1b1c879U,
+    0x5b5bedb6U,
+    0x6a6abed4U,
+    0xcbcb468dU,
+    0xbebed967U,
+    0x39394b72U,
+    0x4a4ade94U,
+    0x4c4cd498U,
+    0x5858e8b0U,
+    0xcfcf4a85U,
+    0xd0d06bbbU,
+    0xefef2ac5U,
+    0xaaaae54fU,
+    0xfbfb16edU,
+    0x4343c586U,
+    0x4d4dd79aU,
+    0x33335566U,
+    0x85859411U,
+    0x4545cf8aU,
+    0xf9f910e9U,
+    0x02020604U,
+    0x7f7f81feU,
+    0x5050f0a0U,
+    0x3c3c4478U,
+    0x9f9fba25U,
+    0xa8a8e34bU,
+    0x5151f3a2U,
+    0xa3a3fe5dU,
+    0x4040c080U,
+    0x8f8f8a05U,
+    0x9292ad3fU,
+    0x9d9dbc21U,
+    0x38384870U,
+    0xf5f504f1U,
+    0xbcbcdf63U,
+    0xb6b6c177U,
+    0xdada75afU,
+    0x21216342U,
+    0x10103020U,
+    0xffff1ae5U,
+    0xf3f30efdU,
+    0xd2d26dbfU,
+    0xcdcd4c81U,
+    0x0c0c1418U,
+    0x13133526U,
+    0xecec2fc3U,
+    0x5f5fe1beU,
+    0x9797a235U,
+    0x4444cc88U,
+    0x1717392eU,
+    0xc4c45793U,
+    0xa7a7f255U,
+    0x7e7e82fcU,
+    0x3d3d477aU,
+    0x6464acc8U,
+    0x5d5de7baU,
+    0x19192b32U,
+    0x737395e6U,
+    0x6060a0c0U,
+    0x81819819U,
+    0x4f4fd19eU,
+    0xdcdc7fa3U,
+    0x22226644U,
+    0x2a2a7e54U,
+    0x9090ab3bU,
+    0x8888830bU,
+    0x4646ca8cU,
+    0xeeee29c7U,
+    0xb8b8d36bU,
+    0x14143c28U,
+    0xdede79a7U,
+    0x5e5ee2bcU,
+    0x0b0b1d16U,
+    0xdbdb76adU,
+    0xe0e03bdbU,
+    0x32325664U,
+    0x3a3a4e74U,
+    0x0a0a1e14U,
+    0x4949db92U,
+    0x06060a0cU,
+    0x24246c48U,
+    0x5c5ce4b8U,
+    0xc2c25d9fU,
+    0xd3d36ebdU,
+    0xacacef43U,
+    0x6262a6c4U,
+    0x9191a839U,
+    0x9595a431U,
+    0xe4e437d3U,
+    0x79798bf2U,
+    0xe7e732d5U,
+    0xc8c8438bU,
+    0x3737596eU,
+    0x6d6db7daU,
+    0x8d8d8c01U,
+    0xd5d564b1U,
+    0x4e4ed29cU,
+    0xa9a9e049U,
+    0x6c6cb4d8U,
+    0x5656faacU,
+    0xf4f407f3U,
+    0xeaea25cfU,
+    0x6565afcaU,
+    0x7a7a8ef4U,
+    0xaeaee947U,
+    0x08081810U,
+    0xbabad56fU,
+    0x787888f0U,
+    0x25256f4aU,
+    0x2e2e725cU,
+    0x1c1c2438U,
+    0xa6a6f157U,
+    0xb4b4c773U,
+    0xc6c65197U,
+    0xe8e823cbU,
+    0xdddd7ca1U,
+    0x74749ce8U,
+    0x1f1f213eU,
+    0x4b4bdd96U,
+    0xbdbddc61U,
+    0x8b8b860dU,
+    0x8a8a850fU,
+    0x707090e0U,
+    0x3e3e427cU,
+    0xb5b5c471U,
+    0x6666aaccU,
+    0x4848d890U,
+    0x03030506U,
+    0xf6f601f7U,
+    0x0e0e121cU,
+    0x6161a3c2U,
+    0x35355f6aU,
+    0x5757f9aeU,
+    0xb9b9d069U,
+    0x86869117U,
+    0xc1c15899U,
+    0x1d1d273aU,
+    0x9e9eb927U,
+    0xe1e138d9U,
+    0xf8f813ebU,
+    0x9898b32bU,
+    0x11113322U,
+    0x6969bbd2U,
+    0xd9d970a9U,
+    0x8e8e8907U,
+    0x9494a733U,
+    0x9b9bb62dU,
+    0x1e1e223cU,
+    0x87879215U,
+    0xe9e920c9U,
+    0xcece4987U,
+    0x5555ffaaU,
+    0x28287850U,
+    0xdfdf7aa5U,
+    0x8c8c8f03U,
+    0xa1a1f859U,
+    0x89898009U,
+    0x0d0d171aU,
+    0xbfbfda65U,
+    0xe6e631d7U,
+    0x4242c684U,
+    0x6868b8d0U,
+    0x4141c382U,
+    0x9999b029U,
+    0x2d2d775aU,
+    0x0f0f111eU,
+    0xb0b0cb7bU,
+    0x5454fca8U,
+    0xbbbbd66dU,
+    0x16163a2cU,
 };
 
-static const uint32_t Td0[256] = {
-    0x51f4a750U, 0x7e416553U, 0x1a17a4c3U, 0x3a275e96U,
-    0x3bab6bcbU, 0x1f9d45f1U, 0xacfa58abU, 0x4be30393U,
-    0x2030fa55U, 0xad766df6U, 0x88cc7691U, 0xf5024c25U,
-    0x4fe5d7fcU, 0xc52acbd7U, 0x26354480U, 0xb562a38fU,
-    0xdeb15a49U, 0x25ba1b67U, 0x45ea0e98U, 0x5dfec0e1U,
-    0xc32f7502U, 0x814cf012U, 0x8d4697a3U, 0x6bd3f9c6U,
-    0x038f5fe7U, 0x15929c95U, 0xbf6d7aebU, 0x955259daU,
-    0xd4be832dU, 0x587421d3U, 0x49e06929U, 0x8ec9c844U,
-    0x75c2896aU, 0xf48e7978U, 0x99583e6bU, 0x27b971ddU,
-    0xbee14fb6U, 0xf088ad17U, 0xc920ac66U, 0x7dce3ab4U,
-    0x63df4a18U, 0xe51a3182U, 0x97513360U, 0x62537f45U,
-    0xb16477e0U, 0xbb6bae84U, 0xfe81a01cU, 0xf9082b94U,
-    0x70486858U, 0x8f45fd19U, 0x94de6c87U, 0x527bf8b7U,
-    0xab73d323U, 0x724b02e2U, 0xe31f8f57U, 0x6655ab2aU,
-    0xb2eb2807U, 0x2fb5c203U, 0x86c57b9aU, 0xd33708a5U,
-    0x302887f2U, 0x23bfa5b2U, 0x02036abaU, 0xed16825cU,
-    0x8acf1c2bU, 0xa779b492U, 0xf307f2f0U, 0x4e69e2a1U,
-    0x65daf4cdU, 0x0605bed5U, 0xd134621fU, 0xc4a6fe8aU,
-    0x342e539dU, 0xa2f355a0U, 0x058ae132U, 0xa4f6eb75U,
-    0x0b83ec39U, 0x4060efaaU, 0x5e719f06U, 0xbd6e1051U,
-    0x3e218af9U, 0x96dd063dU, 0xdd3e05aeU, 0x4de6bd46U,
-    0x91548db5U, 0x71c45d05U, 0x0406d46fU, 0x605015ffU,
-    0x1998fb24U, 0xd6bde997U, 0x894043ccU, 0x67d99e77U,
-    0xb0e842bdU, 0x07898b88U, 0xe7195b38U, 0x79c8eedbU,
-    0xa17c0a47U, 0x7c420fe9U, 0xf8841ec9U, 0x00000000U,
-    0x09808683U, 0x322bed48U, 0x1e1170acU, 0x6c5a724eU,
-    0xfd0efffbU, 0x0f853856U, 0x3daed51eU, 0x362d3927U,
-    0x0a0fd964U, 0x685ca621U, 0x9b5b54d1U, 0x24362e3aU,
-    0x0c0a67b1U, 0x9357e70fU, 0xb4ee96d2U, 0x1b9b919eU,
-    0x80c0c54fU, 0x61dc20a2U, 0x5a774b69U, 0x1c121a16U,
-    0xe293ba0aU, 0xc0a02ae5U, 0x3c22e043U, 0x121b171dU,
-    0x0e090d0bU, 0xf28bc7adU, 0x2db6a8b9U, 0x141ea9c8U,
-    0x57f11985U, 0xaf75074cU, 0xee99ddbbU, 0xa37f60fdU,
-    0xf701269fU, 0x5c72f5bcU, 0x44663bc5U, 0x5bfb7e34U,
-    0x8b432976U, 0xcb23c6dcU, 0xb6edfc68U, 0xb8e4f163U,
-    0xd731dccaU, 0x42638510U, 0x13972240U, 0x84c61120U,
-    0x854a247dU, 0xd2bb3df8U, 0xaef93211U, 0xc729a16dU,
-    0x1d9e2f4bU, 0xdcb230f3U, 0x0d8652ecU, 0x77c1e3d0U,
-    0x2bb3166cU, 0xa970b999U, 0x119448faU, 0x47e96422U,
-    0xa8fc8cc4U, 0xa0f03f1aU, 0x567d2cd8U, 0x223390efU,
-    0x87494ec7U, 0xd938d1c1U, 0x8ccaa2feU, 0x98d40b36U,
-    0xa6f581cfU, 0xa57ade28U, 0xdab78e26U, 0x3fadbfa4U,
-    0x2c3a9de4U, 0x5078920dU, 0x6a5fcc9bU, 0x547e4662U,
-    0xf68d13c2U, 0x90d8b8e8U, 0x2e39f75eU, 0x82c3aff5U,
-    0x9f5d80beU, 0x69d0937cU, 0x6fd52da9U, 0xcf2512b3U,
-    0xc8ac993bU, 0x10187da7U, 0xe89c636eU, 0xdb3bbb7bU,
-    0xcd267809U, 0x6e5918f4U, 0xec9ab701U, 0x834f9aa8U,
-    0xe6956e65U, 0xaaffe67eU, 0x21bccf08U, 0xef15e8e6U,
-    0xbae79bd9U, 0x4a6f36ceU, 0xea9f09d4U, 0x29b07cd6U,
-    0x31a4b2afU, 0x2a3f2331U, 0xc6a59430U, 0x35a266c0U,
-    0x744ebc37U, 0xfc82caa6U, 0xe090d0b0U, 0x33a7d815U,
-    0xf104984aU, 0x41ecdaf7U, 0x7fcd500eU, 0x1791f62fU,
-    0x764dd68dU, 0x43efb04dU, 0xccaa4d54U, 0xe49604dfU,
-    0x9ed1b5e3U, 0x4c6a881bU, 0xc12c1fb8U, 0x4665517fU,
-    0x9d5eea04U, 0x018c355dU, 0xfa877473U, 0xfb0b412eU,
-    0xb3671d5aU, 0x92dbd252U, 0xe9105633U, 0x6dd64713U,
-    0x9ad7618cU, 0x37a10c7aU, 0x59f8148eU, 0xeb133c89U,
-    0xcea927eeU, 0xb761c935U, 0xe11ce5edU, 0x7a47b13cU,
-    0x9cd2df59U, 0x55f2733fU, 0x1814ce79U, 0x73c737bfU,
-    0x53f7cdeaU, 0x5ffdaa5bU, 0xdf3d6f14U, 0x7844db86U,
-    0xcaaff381U, 0xb968c43eU, 0x3824342cU, 0xc2a3405fU,
-    0x161dc372U, 0xbce2250cU, 0x283c498bU, 0xff0d9541U,
-    0x39a80171U, 0x080cb3deU, 0xd8b4e49cU, 0x6456c190U,
-    0x7bcb8461U, 0xd532b670U, 0x486c5c74U, 0xd0b85742U
+static const u32 Td0[256] = {
+    0x51f4a750U,
+    0x7e416553U,
+    0x1a17a4c3U,
+    0x3a275e96U,
+    0x3bab6bcbU,
+    0x1f9d45f1U,
+    0xacfa58abU,
+    0x4be30393U,
+    0x2030fa55U,
+    0xad766df6U,
+    0x88cc7691U,
+    0xf5024c25U,
+    0x4fe5d7fcU,
+    0xc52acbd7U,
+    0x26354480U,
+    0xb562a38fU,
+    0xdeb15a49U,
+    0x25ba1b67U,
+    0x45ea0e98U,
+    0x5dfec0e1U,
+    0xc32f7502U,
+    0x814cf012U,
+    0x8d4697a3U,
+    0x6bd3f9c6U,
+    0x038f5fe7U,
+    0x15929c95U,
+    0xbf6d7aebU,
+    0x955259daU,
+    0xd4be832dU,
+    0x587421d3U,
+    0x49e06929U,
+    0x8ec9c844U,
+    0x75c2896aU,
+    0xf48e7978U,
+    0x99583e6bU,
+    0x27b971ddU,
+    0xbee14fb6U,
+    0xf088ad17U,
+    0xc920ac66U,
+    0x7dce3ab4U,
+    0x63df4a18U,
+    0xe51a3182U,
+    0x97513360U,
+    0x62537f45U,
+    0xb16477e0U,
+    0xbb6bae84U,
+    0xfe81a01cU,
+    0xf9082b94U,
+    0x70486858U,
+    0x8f45fd19U,
+    0x94de6c87U,
+    0x527bf8b7U,
+    0xab73d323U,
+    0x724b02e2U,
+    0xe31f8f57U,
+    0x6655ab2aU,
+    0xb2eb2807U,
+    0x2fb5c203U,
+    0x86c57b9aU,
+    0xd33708a5U,
+    0x302887f2U,
+    0x23bfa5b2U,
+    0x02036abaU,
+    0xed16825cU,
+    0x8acf1c2bU,
+    0xa779b492U,
+    0xf307f2f0U,
+    0x4e69e2a1U,
+    0x65daf4cdU,
+    0x0605bed5U,
+    0xd134621fU,
+    0xc4a6fe8aU,
+    0x342e539dU,
+    0xa2f355a0U,
+    0x058ae132U,
+    0xa4f6eb75U,
+    0x0b83ec39U,
+    0x4060efaaU,
+    0x5e719f06U,
+    0xbd6e1051U,
+    0x3e218af9U,
+    0x96dd063dU,
+    0xdd3e05aeU,
+    0x4de6bd46U,
+    0x91548db5U,
+    0x71c45d05U,
+    0x0406d46fU,
+    0x605015ffU,
+    0x1998fb24U,
+    0xd6bde997U,
+    0x894043ccU,
+    0x67d99e77U,
+    0xb0e842bdU,
+    0x07898b88U,
+    0xe7195b38U,
+    0x79c8eedbU,
+    0xa17c0a47U,
+    0x7c420fe9U,
+    0xf8841ec9U,
+    0x00000000U,
+    0x09808683U,
+    0x322bed48U,
+    0x1e1170acU,
+    0x6c5a724eU,
+    0xfd0efffbU,
+    0x0f853856U,
+    0x3daed51eU,
+    0x362d3927U,
+    0x0a0fd964U,
+    0x685ca621U,
+    0x9b5b54d1U,
+    0x24362e3aU,
+    0x0c0a67b1U,
+    0x9357e70fU,
+    0xb4ee96d2U,
+    0x1b9b919eU,
+    0x80c0c54fU,
+    0x61dc20a2U,
+    0x5a774b69U,
+    0x1c121a16U,
+    0xe293ba0aU,
+    0xc0a02ae5U,
+    0x3c22e043U,
+    0x121b171dU,
+    0x0e090d0bU,
+    0xf28bc7adU,
+    0x2db6a8b9U,
+    0x141ea9c8U,
+    0x57f11985U,
+    0xaf75074cU,
+    0xee99ddbbU,
+    0xa37f60fdU,
+    0xf701269fU,
+    0x5c72f5bcU,
+    0x44663bc5U,
+    0x5bfb7e34U,
+    0x8b432976U,
+    0xcb23c6dcU,
+    0xb6edfc68U,
+    0xb8e4f163U,
+    0xd731dccaU,
+    0x42638510U,
+    0x13972240U,
+    0x84c61120U,
+    0x854a247dU,
+    0xd2bb3df8U,
+    0xaef93211U,
+    0xc729a16dU,
+    0x1d9e2f4bU,
+    0xdcb230f3U,
+    0x0d8652ecU,
+    0x77c1e3d0U,
+    0x2bb3166cU,
+    0xa970b999U,
+    0x119448faU,
+    0x47e96422U,
+    0xa8fc8cc4U,
+    0xa0f03f1aU,
+    0x567d2cd8U,
+    0x223390efU,
+    0x87494ec7U,
+    0xd938d1c1U,
+    0x8ccaa2feU,
+    0x98d40b36U,
+    0xa6f581cfU,
+    0xa57ade28U,
+    0xdab78e26U,
+    0x3fadbfa4U,
+    0x2c3a9de4U,
+    0x5078920dU,
+    0x6a5fcc9bU,
+    0x547e4662U,
+    0xf68d13c2U,
+    0x90d8b8e8U,
+    0x2e39f75eU,
+    0x82c3aff5U,
+    0x9f5d80beU,
+    0x69d0937cU,
+    0x6fd52da9U,
+    0xcf2512b3U,
+    0xc8ac993bU,
+    0x10187da7U,
+    0xe89c636eU,
+    0xdb3bbb7bU,
+    0xcd267809U,
+    0x6e5918f4U,
+    0xec9ab701U,
+    0x834f9aa8U,
+    0xe6956e65U,
+    0xaaffe67eU,
+    0x21bccf08U,
+    0xef15e8e6U,
+    0xbae79bd9U,
+    0x4a6f36ceU,
+    0xea9f09d4U,
+    0x29b07cd6U,
+    0x31a4b2afU,
+    0x2a3f2331U,
+    0xc6a59430U,
+    0x35a266c0U,
+    0x744ebc37U,
+    0xfc82caa6U,
+    0xe090d0b0U,
+    0x33a7d815U,
+    0xf104984aU,
+    0x41ecdaf7U,
+    0x7fcd500eU,
+    0x1791f62fU,
+    0x764dd68dU,
+    0x43efb04dU,
+    0xccaa4d54U,
+    0xe49604dfU,
+    0x9ed1b5e3U,
+    0x4c6a881bU,
+    0xc12c1fb8U,
+    0x4665517fU,
+    0x9d5eea04U,
+    0x018c355dU,
+    0xfa877473U,
+    0xfb0b412eU,
+    0xb3671d5aU,
+    0x92dbd252U,
+    0xe9105633U,
+    0x6dd64713U,
+    0x9ad7618cU,
+    0x37a10c7aU,
+    0x59f8148eU,
+    0xeb133c89U,
+    0xcea927eeU,
+    0xb761c935U,
+    0xe11ce5edU,
+    0x7a47b13cU,
+    0x9cd2df59U,
+    0x55f2733fU,
+    0x1814ce79U,
+    0x73c737bfU,
+    0x53f7cdeaU,
+    0x5ffdaa5bU,
+    0xdf3d6f14U,
+    0x7844db86U,
+    0xcaaff381U,
+    0xb968c43eU,
+    0x3824342cU,
+    0xc2a3405fU,
+    0x161dc372U,
+    0xbce2250cU,
+    0x283c498bU,
+    0xff0d9541U,
+    0x39a80171U,
+    0x080cb3deU,
+    0xd8b4e49cU,
+    0x6456c190U,
+    0x7bcb8461U,
+    0xd532b670U,
+    0x486c5c74U,
+    0xd0b85742U,
 };
-static const uint32_t Td1[256] = {
-    0x5051f4a7U, 0x537e4165U, 0xc31a17a4U, 0x963a275eU,
-    0xcb3bab6bU, 0xf11f9d45U, 0xabacfa58U, 0x934be303U,
-    0x552030faU, 0xf6ad766dU, 0x9188cc76U, 0x25f5024cU,
-    0xfc4fe5d7U, 0xd7c52acbU, 0x80263544U, 0x8fb562a3U,
-    0x49deb15aU, 0x6725ba1bU, 0x9845ea0eU, 0xe15dfec0U,
-    0x02c32f75U, 0x12814cf0U, 0xa38d4697U, 0xc66bd3f9U,
-    0xe7038f5fU, 0x9515929cU, 0xebbf6d7aU, 0xda955259U,
-    0x2dd4be83U, 0xd3587421U, 0x2949e069U, 0x448ec9c8U,
-    0x6a75c289U, 0x78f48e79U, 0x6b99583eU, 0xdd27b971U,
-    0xb6bee14fU, 0x17f088adU, 0x66c920acU, 0xb47dce3aU,
-    0x1863df4aU, 0x82e51a31U, 0x60975133U, 0x4562537fU,
-    0xe0b16477U, 0x84bb6baeU, 0x1cfe81a0U, 0x94f9082bU,
-    0x58704868U, 0x198f45fdU, 0x8794de6cU, 0xb7527bf8U,
-    0x23ab73d3U, 0xe2724b02U, 0x57e31f8fU, 0x2a6655abU,
-    0x07b2eb28U, 0x032fb5c2U, 0x9a86c57bU, 0xa5d33708U,
-    0xf2302887U, 0xb223bfa5U, 0xba02036aU, 0x5ced1682U,
-    0x2b8acf1cU, 0x92a779b4U, 0xf0f307f2U, 0xa14e69e2U,
-    0xcd65daf4U, 0xd50605beU, 0x1fd13462U, 0x8ac4a6feU,
-    0x9d342e53U, 0xa0a2f355U, 0x32058ae1U, 0x75a4f6ebU,
-    0x390b83ecU, 0xaa4060efU, 0x065e719fU, 0x51bd6e10U,
-    0xf93e218aU, 0x3d96dd06U, 0xaedd3e05U, 0x464de6bdU,
-    0xb591548dU, 0x0571c45dU, 0x6f0406d4U, 0xff605015U,
-    0x241998fbU, 0x97d6bde9U, 0xcc894043U, 0x7767d99eU,
-    0xbdb0e842U, 0x8807898bU, 0x38e7195bU, 0xdb79c8eeU,
-    0x47a17c0aU, 0xe97c420fU, 0xc9f8841eU, 0x00000000U,
-    0x83098086U, 0x48322bedU, 0xac1e1170U, 0x4e6c5a72U,
-    0xfbfd0effU, 0x560f8538U, 0x1e3daed5U, 0x27362d39U,
-    0x640a0fd9U, 0x21685ca6U, 0xd19b5b54U, 0x3a24362eU,
-    0xb10c0a67U, 0x0f9357e7U, 0xd2b4ee96U, 0x9e1b9b91U,
-    0x4f80c0c5U, 0xa261dc20U, 0x695a774bU, 0x161c121aU,
-    0x0ae293baU, 0xe5c0a02aU, 0x433c22e0U, 0x1d121b17U,
-    0x0b0e090dU, 0xadf28bc7U, 0xb92db6a8U, 0xc8141ea9U,
-    0x8557f119U, 0x4caf7507U, 0xbbee99ddU, 0xfda37f60U,
-    0x9ff70126U, 0xbc5c72f5U, 0xc544663bU, 0x345bfb7eU,
-    0x768b4329U, 0xdccb23c6U, 0x68b6edfcU, 0x63b8e4f1U,
-    0xcad731dcU, 0x10426385U, 0x40139722U, 0x2084c611U,
-    0x7d854a24U, 0xf8d2bb3dU, 0x11aef932U, 0x6dc729a1U,
-    0x4b1d9e2fU, 0xf3dcb230U, 0xec0d8652U, 0xd077c1e3U,
-    0x6c2bb316U, 0x99a970b9U, 0xfa119448U, 0x2247e964U,
-    0xc4a8fc8cU, 0x1aa0f03fU, 0xd8567d2cU, 0xef223390U,
-    0xc787494eU, 0xc1d938d1U, 0xfe8ccaa2U, 0x3698d40bU,
-    0xcfa6f581U, 0x28a57adeU, 0x26dab78eU, 0xa43fadbfU,
-    0xe42c3a9dU, 0x0d507892U, 0x9b6a5fccU, 0x62547e46U,
-    0xc2f68d13U, 0xe890d8b8U, 0x5e2e39f7U, 0xf582c3afU,
-    0xbe9f5d80U, 0x7c69d093U, 0xa96fd52dU, 0xb3cf2512U,
-    0x3bc8ac99U, 0xa710187dU, 0x6ee89c63U, 0x7bdb3bbbU,
-    0x09cd2678U, 0xf46e5918U, 0x01ec9ab7U, 0xa8834f9aU,
-    0x65e6956eU, 0x7eaaffe6U, 0x0821bccfU, 0xe6ef15e8U,
-    0xd9bae79bU, 0xce4a6f36U, 0xd4ea9f09U, 0xd629b07cU,
-    0xaf31a4b2U, 0x312a3f23U, 0x30c6a594U, 0xc035a266U,
-    0x37744ebcU, 0xa6fc82caU, 0xb0e090d0U, 0x1533a7d8U,
-    0x4af10498U, 0xf741ecdaU, 0x0e7fcd50U, 0x2f1791f6U,
-    0x8d764dd6U, 0x4d43efb0U, 0x54ccaa4dU, 0xdfe49604U,
-    0xe39ed1b5U, 0x1b4c6a88U, 0xb8c12c1fU, 0x7f466551U,
-    0x049d5eeaU, 0x5d018c35U, 0x73fa8774U, 0x2efb0b41U,
-    0x5ab3671dU, 0x5292dbd2U, 0x33e91056U, 0x136dd647U,
-    0x8c9ad761U, 0x7a37a10cU, 0x8e59f814U, 0x89eb133cU,
-    0xeecea927U, 0x35b761c9U, 0xede11ce5U, 0x3c7a47b1U,
-    0x599cd2dfU, 0x3f55f273U, 0x791814ceU, 0xbf73c737U,
-    0xea53f7cdU, 0x5b5ffdaaU, 0x14df3d6fU, 0x867844dbU,
-    0x81caaff3U, 0x3eb968c4U, 0x2c382434U, 0x5fc2a340U,
-    0x72161dc3U, 0x0cbce225U, 0x8b283c49U, 0x41ff0d95U,
-    0x7139a801U, 0xde080cb3U, 0x9cd8b4e4U, 0x906456c1U,
-    0x617bcb84U, 0x70d532b6U, 0x74486c5cU, 0x42d0b857U
+static const u32 Td1[256] = {
+    0x5051f4a7U,
+    0x537e4165U,
+    0xc31a17a4U,
+    0x963a275eU,
+    0xcb3bab6bU,
+    0xf11f9d45U,
+    0xabacfa58U,
+    0x934be303U,
+    0x552030faU,
+    0xf6ad766dU,
+    0x9188cc76U,
+    0x25f5024cU,
+    0xfc4fe5d7U,
+    0xd7c52acbU,
+    0x80263544U,
+    0x8fb562a3U,
+    0x49deb15aU,
+    0x6725ba1bU,
+    0x9845ea0eU,
+    0xe15dfec0U,
+    0x02c32f75U,
+    0x12814cf0U,
+    0xa38d4697U,
+    0xc66bd3f9U,
+    0xe7038f5fU,
+    0x9515929cU,
+    0xebbf6d7aU,
+    0xda955259U,
+    0x2dd4be83U,
+    0xd3587421U,
+    0x2949e069U,
+    0x448ec9c8U,
+    0x6a75c289U,
+    0x78f48e79U,
+    0x6b99583eU,
+    0xdd27b971U,
+    0xb6bee14fU,
+    0x17f088adU,
+    0x66c920acU,
+    0xb47dce3aU,
+    0x1863df4aU,
+    0x82e51a31U,
+    0x60975133U,
+    0x4562537fU,
+    0xe0b16477U,
+    0x84bb6baeU,
+    0x1cfe81a0U,
+    0x94f9082bU,
+    0x58704868U,
+    0x198f45fdU,
+    0x8794de6cU,
+    0xb7527bf8U,
+    0x23ab73d3U,
+    0xe2724b02U,
+    0x57e31f8fU,
+    0x2a6655abU,
+    0x07b2eb28U,
+    0x032fb5c2U,
+    0x9a86c57bU,
+    0xa5d33708U,
+    0xf2302887U,
+    0xb223bfa5U,
+    0xba02036aU,
+    0x5ced1682U,
+    0x2b8acf1cU,
+    0x92a779b4U,
+    0xf0f307f2U,
+    0xa14e69e2U,
+    0xcd65daf4U,
+    0xd50605beU,
+    0x1fd13462U,
+    0x8ac4a6feU,
+    0x9d342e53U,
+    0xa0a2f355U,
+    0x32058ae1U,
+    0x75a4f6ebU,
+    0x390b83ecU,
+    0xaa4060efU,
+    0x065e719fU,
+    0x51bd6e10U,
+    0xf93e218aU,
+    0x3d96dd06U,
+    0xaedd3e05U,
+    0x464de6bdU,
+    0xb591548dU,
+    0x0571c45dU,
+    0x6f0406d4U,
+    0xff605015U,
+    0x241998fbU,
+    0x97d6bde9U,
+    0xcc894043U,
+    0x7767d99eU,
+    0xbdb0e842U,
+    0x8807898bU,
+    0x38e7195bU,
+    0xdb79c8eeU,
+    0x47a17c0aU,
+    0xe97c420fU,
+    0xc9f8841eU,
+    0x00000000U,
+    0x83098086U,
+    0x48322bedU,
+    0xac1e1170U,
+    0x4e6c5a72U,
+    0xfbfd0effU,
+    0x560f8538U,
+    0x1e3daed5U,
+    0x27362d39U,
+    0x640a0fd9U,
+    0x21685ca6U,
+    0xd19b5b54U,
+    0x3a24362eU,
+    0xb10c0a67U,
+    0x0f9357e7U,
+    0xd2b4ee96U,
+    0x9e1b9b91U,
+    0x4f80c0c5U,
+    0xa261dc20U,
+    0x695a774bU,
+    0x161c121aU,
+    0x0ae293baU,
+    0xe5c0a02aU,
+    0x433c22e0U,
+    0x1d121b17U,
+    0x0b0e090dU,
+    0xadf28bc7U,
+    0xb92db6a8U,
+    0xc8141ea9U,
+    0x8557f119U,
+    0x4caf7507U,
+    0xbbee99ddU,
+    0xfda37f60U,
+    0x9ff70126U,
+    0xbc5c72f5U,
+    0xc544663bU,
+    0x345bfb7eU,
+    0x768b4329U,
+    0xdccb23c6U,
+    0x68b6edfcU,
+    0x63b8e4f1U,
+    0xcad731dcU,
+    0x10426385U,
+    0x40139722U,
+    0x2084c611U,
+    0x7d854a24U,
+    0xf8d2bb3dU,
+    0x11aef932U,
+    0x6dc729a1U,
+    0x4b1d9e2fU,
+    0xf3dcb230U,
+    0xec0d8652U,
+    0xd077c1e3U,
+    0x6c2bb316U,
+    0x99a970b9U,
+    0xfa119448U,
+    0x2247e964U,
+    0xc4a8fc8cU,
+    0x1aa0f03fU,
+    0xd8567d2cU,
+    0xef223390U,
+    0xc787494eU,
+    0xc1d938d1U,
+    0xfe8ccaa2U,
+    0x3698d40bU,
+    0xcfa6f581U,
+    0x28a57adeU,
+    0x26dab78eU,
+    0xa43fadbfU,
+    0xe42c3a9dU,
+    0x0d507892U,
+    0x9b6a5fccU,
+    0x62547e46U,
+    0xc2f68d13U,
+    0xe890d8b8U,
+    0x5e2e39f7U,
+    0xf582c3afU,
+    0xbe9f5d80U,
+    0x7c69d093U,
+    0xa96fd52dU,
+    0xb3cf2512U,
+    0x3bc8ac99U,
+    0xa710187dU,
+    0x6ee89c63U,
+    0x7bdb3bbbU,
+    0x09cd2678U,
+    0xf46e5918U,
+    0x01ec9ab7U,
+    0xa8834f9aU,
+    0x65e6956eU,
+    0x7eaaffe6U,
+    0x0821bccfU,
+    0xe6ef15e8U,
+    0xd9bae79bU,
+    0xce4a6f36U,
+    0xd4ea9f09U,
+    0xd629b07cU,
+    0xaf31a4b2U,
+    0x312a3f23U,
+    0x30c6a594U,
+    0xc035a266U,
+    0x37744ebcU,
+    0xa6fc82caU,
+    0xb0e090d0U,
+    0x1533a7d8U,
+    0x4af10498U,
+    0xf741ecdaU,
+    0x0e7fcd50U,
+    0x2f1791f6U,
+    0x8d764dd6U,
+    0x4d43efb0U,
+    0x54ccaa4dU,
+    0xdfe49604U,
+    0xe39ed1b5U,
+    0x1b4c6a88U,
+    0xb8c12c1fU,
+    0x7f466551U,
+    0x049d5eeaU,
+    0x5d018c35U,
+    0x73fa8774U,
+    0x2efb0b41U,
+    0x5ab3671dU,
+    0x5292dbd2U,
+    0x33e91056U,
+    0x136dd647U,
+    0x8c9ad761U,
+    0x7a37a10cU,
+    0x8e59f814U,
+    0x89eb133cU,
+    0xeecea927U,
+    0x35b761c9U,
+    0xede11ce5U,
+    0x3c7a47b1U,
+    0x599cd2dfU,
+    0x3f55f273U,
+    0x791814ceU,
+    0xbf73c737U,
+    0xea53f7cdU,
+    0x5b5ffdaaU,
+    0x14df3d6fU,
+    0x867844dbU,
+    0x81caaff3U,
+    0x3eb968c4U,
+    0x2c382434U,
+    0x5fc2a340U,
+    0x72161dc3U,
+    0x0cbce225U,
+    0x8b283c49U,
+    0x41ff0d95U,
+    0x7139a801U,
+    0xde080cb3U,
+    0x9cd8b4e4U,
+    0x906456c1U,
+    0x617bcb84U,
+    0x70d532b6U,
+    0x74486c5cU,
+    0x42d0b857U,
 };
-static const uint32_t Td2[256] = {
-    0xa75051f4U, 0x65537e41U, 0xa4c31a17U, 0x5e963a27U,
-    0x6bcb3babU, 0x45f11f9dU, 0x58abacfaU, 0x03934be3U,
-    0xfa552030U, 0x6df6ad76U, 0x769188ccU, 0x4c25f502U,
-    0xd7fc4fe5U, 0xcbd7c52aU, 0x44802635U, 0xa38fb562U,
-    0x5a49deb1U, 0x1b6725baU, 0x0e9845eaU, 0xc0e15dfeU,
-    0x7502c32fU, 0xf012814cU, 0x97a38d46U, 0xf9c66bd3U,
-    0x5fe7038fU, 0x9c951592U, 0x7aebbf6dU, 0x59da9552U,
-    0x832dd4beU, 0x21d35874U, 0x692949e0U, 0xc8448ec9U,
-    0x896a75c2U, 0x7978f48eU, 0x3e6b9958U, 0x71dd27b9U,
-    0x4fb6bee1U, 0xad17f088U, 0xac66c920U, 0x3ab47dceU,
-    0x4a1863dfU, 0x3182e51aU, 0x33609751U, 0x7f456253U,
-    0x77e0b164U, 0xae84bb6bU, 0xa01cfe81U, 0x2b94f908U,
-    0x68587048U, 0xfd198f45U, 0x6c8794deU, 0xf8b7527bU,
-    0xd323ab73U, 0x02e2724bU, 0x8f57e31fU, 0xab2a6655U,
-    0x2807b2ebU, 0xc2032fb5U, 0x7b9a86c5U, 0x08a5d337U,
-    0x87f23028U, 0xa5b223bfU, 0x6aba0203U, 0x825ced16U,
-    0x1c2b8acfU, 0xb492a779U, 0xf2f0f307U, 0xe2a14e69U,
-    0xf4cd65daU, 0xbed50605U, 0x621fd134U, 0xfe8ac4a6U,
-    0x539d342eU, 0x55a0a2f3U, 0xe132058aU, 0xeb75a4f6U,
-    0xec390b83U, 0xefaa4060U, 0x9f065e71U, 0x1051bd6eU,
-    0x8af93e21U, 0x063d96ddU, 0x05aedd3eU, 0xbd464de6U,
-    0x8db59154U, 0x5d0571c4U, 0xd46f0406U, 0x15ff6050U,
-    0xfb241998U, 0xe997d6bdU, 0x43cc8940U, 0x9e7767d9U,
-    0x42bdb0e8U, 0x8b880789U, 0x5b38e719U, 0xeedb79c8U,
-    0x0a47a17cU, 0x0fe97c42U, 0x1ec9f884U, 0x00000000U,
-    0x86830980U, 0xed48322bU, 0x70ac1e11U, 0x724e6c5aU,
-    0xfffbfd0eU, 0x38560f85U, 0xd51e3daeU, 0x3927362dU,
-    0xd9640a0fU, 0xa621685cU, 0x54d19b5bU, 0x2e3a2436U,
-    0x67b10c0aU, 0xe70f9357U, 0x96d2b4eeU, 0x919e1b9bU,
-    0xc54f80c0U, 0x20a261dcU, 0x4b695a77U, 0x1a161c12U,
-    0xba0ae293U, 0x2ae5c0a0U, 0xe0433c22U, 0x171d121bU,
-    0x0d0b0e09U, 0xc7adf28bU, 0xa8b92db6U, 0xa9c8141eU,
-    0x198557f1U, 0x074caf75U, 0xddbbee99U, 0x60fda37fU,
-    0x269ff701U, 0xf5bc5c72U, 0x3bc54466U, 0x7e345bfbU,
-    0x29768b43U, 0xc6dccb23U, 0xfc68b6edU, 0xf163b8e4U,
-    0xdccad731U, 0x85104263U, 0x22401397U, 0x112084c6U,
-    0x247d854aU, 0x3df8d2bbU, 0x3211aef9U, 0xa16dc729U,
-    0x2f4b1d9eU, 0x30f3dcb2U, 0x52ec0d86U, 0xe3d077c1U,
-    0x166c2bb3U, 0xb999a970U, 0x48fa1194U, 0x642247e9U,
-    0x8cc4a8fcU, 0x3f1aa0f0U, 0x2cd8567dU, 0x90ef2233U,
-    0x4ec78749U, 0xd1c1d938U, 0xa2fe8ccaU, 0x0b3698d4U,
-    0x81cfa6f5U, 0xde28a57aU, 0x8e26dab7U, 0xbfa43fadU,
-    0x9de42c3aU, 0x920d5078U, 0xcc9b6a5fU, 0x4662547eU,
-    0x13c2f68dU, 0xb8e890d8U, 0xf75e2e39U, 0xaff582c3U,
-    0x80be9f5dU, 0x937c69d0U, 0x2da96fd5U, 0x12b3cf25U,
-    0x993bc8acU, 0x7da71018U, 0x636ee89cU, 0xbb7bdb3bU,
-    0x7809cd26U, 0x18f46e59U, 0xb701ec9aU, 0x9aa8834fU,
-    0x6e65e695U, 0xe67eaaffU, 0xcf0821bcU, 0xe8e6ef15U,
-    0x9bd9bae7U, 0x36ce4a6fU, 0x09d4ea9fU, 0x7cd629b0U,
-    0xb2af31a4U, 0x23312a3fU, 0x9430c6a5U, 0x66c035a2U,
-    0xbc37744eU, 0xcaa6fc82U, 0xd0b0e090U, 0xd81533a7U,
-    0x984af104U, 0xdaf741ecU, 0x500e7fcdU, 0xf62f1791U,
-    0xd68d764dU, 0xb04d43efU, 0x4d54ccaaU, 0x04dfe496U,
-    0xb5e39ed1U, 0x881b4c6aU, 0x1fb8c12cU, 0x517f4665U,
-    0xea049d5eU, 0x355d018cU, 0x7473fa87U, 0x412efb0bU,
-    0x1d5ab367U, 0xd25292dbU, 0x5633e910U, 0x47136dd6U,
-    0x618c9ad7U, 0x0c7a37a1U, 0x148e59f8U, 0x3c89eb13U,
-    0x27eecea9U, 0xc935b761U, 0xe5ede11cU, 0xb13c7a47U,
-    0xdf599cd2U, 0x733f55f2U, 0xce791814U, 0x37bf73c7U,
-    0xcdea53f7U, 0xaa5b5ffdU, 0x6f14df3dU, 0xdb867844U,
-    0xf381caafU, 0xc43eb968U, 0x342c3824U, 0x405fc2a3U,
-    0xc372161dU, 0x250cbce2U, 0x498b283cU, 0x9541ff0dU,
-    0x017139a8U, 0xb3de080cU, 0xe49cd8b4U, 0xc1906456U,
-    0x84617bcbU, 0xb670d532U, 0x5c74486cU, 0x5742d0b8U
+static const u32 Td2[256] = {
+    0xa75051f4U,
+    0x65537e41U,
+    0xa4c31a17U,
+    0x5e963a27U,
+    0x6bcb3babU,
+    0x45f11f9dU,
+    0x58abacfaU,
+    0x03934be3U,
+    0xfa552030U,
+    0x6df6ad76U,
+    0x769188ccU,
+    0x4c25f502U,
+    0xd7fc4fe5U,
+    0xcbd7c52aU,
+    0x44802635U,
+    0xa38fb562U,
+    0x5a49deb1U,
+    0x1b6725baU,
+    0x0e9845eaU,
+    0xc0e15dfeU,
+    0x7502c32fU,
+    0xf012814cU,
+    0x97a38d46U,
+    0xf9c66bd3U,
+    0x5fe7038fU,
+    0x9c951592U,
+    0x7aebbf6dU,
+    0x59da9552U,
+    0x832dd4beU,
+    0x21d35874U,
+    0x692949e0U,
+    0xc8448ec9U,
+    0x896a75c2U,
+    0x7978f48eU,
+    0x3e6b9958U,
+    0x71dd27b9U,
+    0x4fb6bee1U,
+    0xad17f088U,
+    0xac66c920U,
+    0x3ab47dceU,
+    0x4a1863dfU,
+    0x3182e51aU,
+    0x33609751U,
+    0x7f456253U,
+    0x77e0b164U,
+    0xae84bb6bU,
+    0xa01cfe81U,
+    0x2b94f908U,
+    0x68587048U,
+    0xfd198f45U,
+    0x6c8794deU,
+    0xf8b7527bU,
+    0xd323ab73U,
+    0x02e2724bU,
+    0x8f57e31fU,
+    0xab2a6655U,
+    0x2807b2ebU,
+    0xc2032fb5U,
+    0x7b9a86c5U,
+    0x08a5d337U,
+    0x87f23028U,
+    0xa5b223bfU,
+    0x6aba0203U,
+    0x825ced16U,
+    0x1c2b8acfU,
+    0xb492a779U,
+    0xf2f0f307U,
+    0xe2a14e69U,
+    0xf4cd65daU,
+    0xbed50605U,
+    0x621fd134U,
+    0xfe8ac4a6U,
+    0x539d342eU,
+    0x55a0a2f3U,
+    0xe132058aU,
+    0xeb75a4f6U,
+    0xec390b83U,
+    0xefaa4060U,
+    0x9f065e71U,
+    0x1051bd6eU,
+    0x8af93e21U,
+    0x063d96ddU,
+    0x05aedd3eU,
+    0xbd464de6U,
+    0x8db59154U,
+    0x5d0571c4U,
+    0xd46f0406U,
+    0x15ff6050U,
+    0xfb241998U,
+    0xe997d6bdU,
+    0x43cc8940U,
+    0x9e7767d9U,
+    0x42bdb0e8U,
+    0x8b880789U,
+    0x5b38e719U,
+    0xeedb79c8U,
+    0x0a47a17cU,
+    0x0fe97c42U,
+    0x1ec9f884U,
+    0x00000000U,
+    0x86830980U,
+    0xed48322bU,
+    0x70ac1e11U,
+    0x724e6c5aU,
+    0xfffbfd0eU,
+    0x38560f85U,
+    0xd51e3daeU,
+    0x3927362dU,
+    0xd9640a0fU,
+    0xa621685cU,
+    0x54d19b5bU,
+    0x2e3a2436U,
+    0x67b10c0aU,
+    0xe70f9357U,
+    0x96d2b4eeU,
+    0x919e1b9bU,
+    0xc54f80c0U,
+    0x20a261dcU,
+    0x4b695a77U,
+    0x1a161c12U,
+    0xba0ae293U,
+    0x2ae5c0a0U,
+    0xe0433c22U,
+    0x171d121bU,
+    0x0d0b0e09U,
+    0xc7adf28bU,
+    0xa8b92db6U,
+    0xa9c8141eU,
+    0x198557f1U,
+    0x074caf75U,
+    0xddbbee99U,
+    0x60fda37fU,
+    0x269ff701U,
+    0xf5bc5c72U,
+    0x3bc54466U,
+    0x7e345bfbU,
+    0x29768b43U,
+    0xc6dccb23U,
+    0xfc68b6edU,
+    0xf163b8e4U,
+    0xdccad731U,
+    0x85104263U,
+    0x22401397U,
+    0x112084c6U,
+    0x247d854aU,
+    0x3df8d2bbU,
+    0x3211aef9U,
+    0xa16dc729U,
+    0x2f4b1d9eU,
+    0x30f3dcb2U,
+    0x52ec0d86U,
+    0xe3d077c1U,
+    0x166c2bb3U,
+    0xb999a970U,
+    0x48fa1194U,
+    0x642247e9U,
+    0x8cc4a8fcU,
+    0x3f1aa0f0U,
+    0x2cd8567dU,
+    0x90ef2233U,
+    0x4ec78749U,
+    0xd1c1d938U,
+    0xa2fe8ccaU,
+    0x0b3698d4U,
+    0x81cfa6f5U,
+    0xde28a57aU,
+    0x8e26dab7U,
+    0xbfa43fadU,
+    0x9de42c3aU,
+    0x920d5078U,
+    0xcc9b6a5fU,
+    0x4662547eU,
+    0x13c2f68dU,
+    0xb8e890d8U,
+    0xf75e2e39U,
+    0xaff582c3U,
+    0x80be9f5dU,
+    0x937c69d0U,
+    0x2da96fd5U,
+    0x12b3cf25U,
+    0x993bc8acU,
+    0x7da71018U,
+    0x636ee89cU,
+    0xbb7bdb3bU,
+    0x7809cd26U,
+    0x18f46e59U,
+    0xb701ec9aU,
+    0x9aa8834fU,
+    0x6e65e695U,
+    0xe67eaaffU,
+    0xcf0821bcU,
+    0xe8e6ef15U,
+    0x9bd9bae7U,
+    0x36ce4a6fU,
+    0x09d4ea9fU,
+    0x7cd629b0U,
+    0xb2af31a4U,
+    0x23312a3fU,
+    0x9430c6a5U,
+    0x66c035a2U,
+    0xbc37744eU,
+    0xcaa6fc82U,
+    0xd0b0e090U,
+    0xd81533a7U,
+    0x984af104U,
+    0xdaf741ecU,
+    0x500e7fcdU,
+    0xf62f1791U,
+    0xd68d764dU,
+    0xb04d43efU,
+    0x4d54ccaaU,
+    0x04dfe496U,
+    0xb5e39ed1U,
+    0x881b4c6aU,
+    0x1fb8c12cU,
+    0x517f4665U,
+    0xea049d5eU,
+    0x355d018cU,
+    0x7473fa87U,
+    0x412efb0bU,
+    0x1d5ab367U,
+    0xd25292dbU,
+    0x5633e910U,
+    0x47136dd6U,
+    0x618c9ad7U,
+    0x0c7a37a1U,
+    0x148e59f8U,
+    0x3c89eb13U,
+    0x27eecea9U,
+    0xc935b761U,
+    0xe5ede11cU,
+    0xb13c7a47U,
+    0xdf599cd2U,
+    0x733f55f2U,
+    0xce791814U,
+    0x37bf73c7U,
+    0xcdea53f7U,
+    0xaa5b5ffdU,
+    0x6f14df3dU,
+    0xdb867844U,
+    0xf381caafU,
+    0xc43eb968U,
+    0x342c3824U,
+    0x405fc2a3U,
+    0xc372161dU,
+    0x250cbce2U,
+    0x498b283cU,
+    0x9541ff0dU,
+    0x017139a8U,
+    0xb3de080cU,
+    0xe49cd8b4U,
+    0xc1906456U,
+    0x84617bcbU,
+    0xb670d532U,
+    0x5c74486cU,
+    0x5742d0b8U,
 };
-static const uint32_t Td3[256] = {
-    0xf4a75051U, 0x4165537eU, 0x17a4c31aU, 0x275e963aU,
-    0xab6bcb3bU, 0x9d45f11fU, 0xfa58abacU, 0xe303934bU,
-    0x30fa5520U, 0x766df6adU, 0xcc769188U, 0x024c25f5U,
-    0xe5d7fc4fU, 0x2acbd7c5U, 0x35448026U, 0x62a38fb5U,
-    0xb15a49deU, 0xba1b6725U, 0xea0e9845U, 0xfec0e15dU,
-    0x2f7502c3U, 0x4cf01281U, 0x4697a38dU, 0xd3f9c66bU,
-    0x8f5fe703U, 0x929c9515U, 0x6d7aebbfU, 0x5259da95U,
-    0xbe832dd4U, 0x7421d358U, 0xe0692949U, 0xc9c8448eU,
-    0xc2896a75U, 0x8e7978f4U, 0x583e6b99U, 0xb971dd27U,
-    0xe14fb6beU, 0x88ad17f0U, 0x20ac66c9U, 0xce3ab47dU,
-    0xdf4a1863U, 0x1a3182e5U, 0x51336097U, 0x537f4562U,
-    0x6477e0b1U, 0x6bae84bbU, 0x81a01cfeU, 0x082b94f9U,
-    0x48685870U, 0x45fd198fU, 0xde6c8794U, 0x7bf8b752U,
-    0x73d323abU, 0x4b02e272U, 0x1f8f57e3U, 0x55ab2a66U,
-    0xeb2807b2U, 0xb5c2032fU, 0xc57b9a86U, 0x3708a5d3U,
-    0x2887f230U, 0xbfa5b223U, 0x036aba02U, 0x16825cedU,
-    0xcf1c2b8aU, 0x79b492a7U, 0x07f2f0f3U, 0x69e2a14eU,
-    0xdaf4cd65U, 0x05bed506U, 0x34621fd1U, 0xa6fe8ac4U,
-    0x2e539d34U, 0xf355a0a2U, 0x8ae13205U, 0xf6eb75a4U,
-    0x83ec390bU, 0x60efaa40U, 0x719f065eU, 0x6e1051bdU,
-    0x218af93eU, 0xdd063d96U, 0x3e05aeddU, 0xe6bd464dU,
-    0x548db591U, 0xc45d0571U, 0x06d46f04U, 0x5015ff60U,
-    0x98fb2419U, 0xbde997d6U, 0x4043cc89U, 0xd99e7767U,
-    0xe842bdb0U, 0x898b8807U, 0x195b38e7U, 0xc8eedb79U,
-    0x7c0a47a1U, 0x420fe97cU, 0x841ec9f8U, 0x00000000U,
-    0x80868309U, 0x2bed4832U, 0x1170ac1eU, 0x5a724e6cU,
-    0x0efffbfdU, 0x8538560fU, 0xaed51e3dU, 0x2d392736U,
-    0x0fd9640aU, 0x5ca62168U, 0x5b54d19bU, 0x362e3a24U,
-    0x0a67b10cU, 0x57e70f93U, 0xee96d2b4U, 0x9b919e1bU,
-    0xc0c54f80U, 0xdc20a261U, 0x774b695aU, 0x121a161cU,
-    0x93ba0ae2U, 0xa02ae5c0U, 0x22e0433cU, 0x1b171d12U,
-    0x090d0b0eU, 0x8bc7adf2U, 0xb6a8b92dU, 0x1ea9c814U,
-    0xf1198557U, 0x75074cafU, 0x99ddbbeeU, 0x7f60fda3U,
-    0x01269ff7U, 0x72f5bc5cU, 0x663bc544U, 0xfb7e345bU,
-    0x4329768bU, 0x23c6dccbU, 0xedfc68b6U, 0xe4f163b8U,
-    0x31dccad7U, 0x63851042U, 0x97224013U, 0xc6112084U,
-    0x4a247d85U, 0xbb3df8d2U, 0xf93211aeU, 0x29a16dc7U,
-    0x9e2f4b1dU, 0xb230f3dcU, 0x8652ec0dU, 0xc1e3d077U,
-    0xb3166c2bU, 0x70b999a9U, 0x9448fa11U, 0xe9642247U,
-    0xfc8cc4a8U, 0xf03f1aa0U, 0x7d2cd856U, 0x3390ef22U,
-    0x494ec787U, 0x38d1c1d9U, 0xcaa2fe8cU, 0xd40b3698U,
-    0xf581cfa6U, 0x7ade28a5U, 0xb78e26daU, 0xadbfa43fU,
-    0x3a9de42cU, 0x78920d50U, 0x5fcc9b6aU, 0x7e466254U,
-    0x8d13c2f6U, 0xd8b8e890U, 0x39f75e2eU, 0xc3aff582U,
-    0x5d80be9fU, 0xd0937c69U, 0xd52da96fU, 0x2512b3cfU,
-    0xac993bc8U, 0x187da710U, 0x9c636ee8U, 0x3bbb7bdbU,
-    0x267809cdU, 0x5918f46eU, 0x9ab701ecU, 0x4f9aa883U,
-    0x956e65e6U, 0xffe67eaaU, 0xbccf0821U, 0x15e8e6efU,
-    0xe79bd9baU, 0x6f36ce4aU, 0x9f09d4eaU, 0xb07cd629U,
-    0xa4b2af31U, 0x3f23312aU, 0xa59430c6U, 0xa266c035U,
-    0x4ebc3774U, 0x82caa6fcU, 0x90d0b0e0U, 0xa7d81533U,
-    0x04984af1U, 0xecdaf741U, 0xcd500e7fU, 0x91f62f17U,
-    0x4dd68d76U, 0xefb04d43U, 0xaa4d54ccU, 0x9604dfe4U,
-    0xd1b5e39eU, 0x6a881b4cU, 0x2c1fb8c1U, 0x65517f46U,
-    0x5eea049dU, 0x8c355d01U, 0x877473faU, 0x0b412efbU,
-    0x671d5ab3U, 0xdbd25292U, 0x105633e9U, 0xd647136dU,
-    0xd7618c9aU, 0xa10c7a37U, 0xf8148e59U, 0x133c89ebU,
-    0xa927eeceU, 0x61c935b7U, 0x1ce5ede1U, 0x47b13c7aU,
-    0xd2df599cU, 0xf2733f55U, 0x14ce7918U, 0xc737bf73U,
-    0xf7cdea53U, 0xfdaa5b5fU, 0x3d6f14dfU, 0x44db8678U,
-    0xaff381caU, 0x68c43eb9U, 0x24342c38U, 0xa3405fc2U,
-    0x1dc37216U, 0xe2250cbcU, 0x3c498b28U, 0x0d9541ffU,
-    0xa8017139U, 0x0cb3de08U, 0xb4e49cd8U, 0x56c19064U,
-    0xcb84617bU, 0x32b670d5U, 0x6c5c7448U, 0xb85742d0U
+static const u32 Td3[256] = {
+    0xf4a75051U,
+    0x4165537eU,
+    0x17a4c31aU,
+    0x275e963aU,
+    0xab6bcb3bU,
+    0x9d45f11fU,
+    0xfa58abacU,
+    0xe303934bU,
+    0x30fa5520U,
+    0x766df6adU,
+    0xcc769188U,
+    0x024c25f5U,
+    0xe5d7fc4fU,
+    0x2acbd7c5U,
+    0x35448026U,
+    0x62a38fb5U,
+    0xb15a49deU,
+    0xba1b6725U,
+    0xea0e9845U,
+    0xfec0e15dU,
+    0x2f7502c3U,
+    0x4cf01281U,
+    0x4697a38dU,
+    0xd3f9c66bU,
+    0x8f5fe703U,
+    0x929c9515U,
+    0x6d7aebbfU,
+    0x5259da95U,
+    0xbe832dd4U,
+    0x7421d358U,
+    0xe0692949U,
+    0xc9c8448eU,
+    0xc2896a75U,
+    0x8e7978f4U,
+    0x583e6b99U,
+    0xb971dd27U,
+    0xe14fb6beU,
+    0x88ad17f0U,
+    0x20ac66c9U,
+    0xce3ab47dU,
+    0xdf4a1863U,
+    0x1a3182e5U,
+    0x51336097U,
+    0x537f4562U,
+    0x6477e0b1U,
+    0x6bae84bbU,
+    0x81a01cfeU,
+    0x082b94f9U,
+    0x48685870U,
+    0x45fd198fU,
+    0xde6c8794U,
+    0x7bf8b752U,
+    0x73d323abU,
+    0x4b02e272U,
+    0x1f8f57e3U,
+    0x55ab2a66U,
+    0xeb2807b2U,
+    0xb5c2032fU,
+    0xc57b9a86U,
+    0x3708a5d3U,
+    0x2887f230U,
+    0xbfa5b223U,
+    0x036aba02U,
+    0x16825cedU,
+    0xcf1c2b8aU,
+    0x79b492a7U,
+    0x07f2f0f3U,
+    0x69e2a14eU,
+    0xdaf4cd65U,
+    0x05bed506U,
+    0x34621fd1U,
+    0xa6fe8ac4U,
+    0x2e539d34U,
+    0xf355a0a2U,
+    0x8ae13205U,
+    0xf6eb75a4U,
+    0x83ec390bU,
+    0x60efaa40U,
+    0x719f065eU,
+    0x6e1051bdU,
+    0x218af93eU,
+    0xdd063d96U,
+    0x3e05aeddU,
+    0xe6bd464dU,
+    0x548db591U,
+    0xc45d0571U,
+    0x06d46f04U,
+    0x5015ff60U,
+    0x98fb2419U,
+    0xbde997d6U,
+    0x4043cc89U,
+    0xd99e7767U,
+    0xe842bdb0U,
+    0x898b8807U,
+    0x195b38e7U,
+    0xc8eedb79U,
+    0x7c0a47a1U,
+    0x420fe97cU,
+    0x841ec9f8U,
+    0x00000000U,
+    0x80868309U,
+    0x2bed4832U,
+    0x1170ac1eU,
+    0x5a724e6cU,
+    0x0efffbfdU,
+    0x8538560fU,
+    0xaed51e3dU,
+    0x2d392736U,
+    0x0fd9640aU,
+    0x5ca62168U,
+    0x5b54d19bU,
+    0x362e3a24U,
+    0x0a67b10cU,
+    0x57e70f93U,
+    0xee96d2b4U,
+    0x9b919e1bU,
+    0xc0c54f80U,
+    0xdc20a261U,
+    0x774b695aU,
+    0x121a161cU,
+    0x93ba0ae2U,
+    0xa02ae5c0U,
+    0x22e0433cU,
+    0x1b171d12U,
+    0x090d0b0eU,
+    0x8bc7adf2U,
+    0xb6a8b92dU,
+    0x1ea9c814U,
+    0xf1198557U,
+    0x75074cafU,
+    0x99ddbbeeU,
+    0x7f60fda3U,
+    0x01269ff7U,
+    0x72f5bc5cU,
+    0x663bc544U,
+    0xfb7e345bU,
+    0x4329768bU,
+    0x23c6dccbU,
+    0xedfc68b6U,
+    0xe4f163b8U,
+    0x31dccad7U,
+    0x63851042U,
+    0x97224013U,
+    0xc6112084U,
+    0x4a247d85U,
+    0xbb3df8d2U,
+    0xf93211aeU,
+    0x29a16dc7U,
+    0x9e2f4b1dU,
+    0xb230f3dcU,
+    0x8652ec0dU,
+    0xc1e3d077U,
+    0xb3166c2bU,
+    0x70b999a9U,
+    0x9448fa11U,
+    0xe9642247U,
+    0xfc8cc4a8U,
+    0xf03f1aa0U,
+    0x7d2cd856U,
+    0x3390ef22U,
+    0x494ec787U,
+    0x38d1c1d9U,
+    0xcaa2fe8cU,
+    0xd40b3698U,
+    0xf581cfa6U,
+    0x7ade28a5U,
+    0xb78e26daU,
+    0xadbfa43fU,
+    0x3a9de42cU,
+    0x78920d50U,
+    0x5fcc9b6aU,
+    0x7e466254U,
+    0x8d13c2f6U,
+    0xd8b8e890U,
+    0x39f75e2eU,
+    0xc3aff582U,
+    0x5d80be9fU,
+    0xd0937c69U,
+    0xd52da96fU,
+    0x2512b3cfU,
+    0xac993bc8U,
+    0x187da710U,
+    0x9c636ee8U,
+    0x3bbb7bdbU,
+    0x267809cdU,
+    0x5918f46eU,
+    0x9ab701ecU,
+    0x4f9aa883U,
+    0x956e65e6U,
+    0xffe67eaaU,
+    0xbccf0821U,
+    0x15e8e6efU,
+    0xe79bd9baU,
+    0x6f36ce4aU,
+    0x9f09d4eaU,
+    0xb07cd629U,
+    0xa4b2af31U,
+    0x3f23312aU,
+    0xa59430c6U,
+    0xa266c035U,
+    0x4ebc3774U,
+    0x82caa6fcU,
+    0x90d0b0e0U,
+    0xa7d81533U,
+    0x04984af1U,
+    0xecdaf741U,
+    0xcd500e7fU,
+    0x91f62f17U,
+    0x4dd68d76U,
+    0xefb04d43U,
+    0xaa4d54ccU,
+    0x9604dfe4U,
+    0xd1b5e39eU,
+    0x6a881b4cU,
+    0x2c1fb8c1U,
+    0x65517f46U,
+    0x5eea049dU,
+    0x8c355d01U,
+    0x877473faU,
+    0x0b412efbU,
+    0x671d5ab3U,
+    0xdbd25292U,
+    0x105633e9U,
+    0xd647136dU,
+    0xd7618c9aU,
+    0xa10c7a37U,
+    0xf8148e59U,
+    0x133c89ebU,
+    0xa927eeceU,
+    0x61c935b7U,
+    0x1ce5ede1U,
+    0x47b13c7aU,
+    0xd2df599cU,
+    0xf2733f55U,
+    0x14ce7918U,
+    0xc737bf73U,
+    0xf7cdea53U,
+    0xfdaa5b5fU,
+    0x3d6f14dfU,
+    0x44db8678U,
+    0xaff381caU,
+    0x68c43eb9U,
+    0x24342c38U,
+    0xa3405fc2U,
+    0x1dc37216U,
+    0xe2250cbcU,
+    0x3c498b28U,
+    0x0d9541ffU,
+    0xa8017139U,
+    0x0cb3de08U,
+    0xb4e49cd8U,
+    0x56c19064U,
+    0xcb84617bU,
+    0x32b670d5U,
+    0x6c5c7448U,
+    0xb85742d0U,
 };
-static const uint8_t Td4[256] = {
-    0x52U, 0x09U, 0x6aU, 0xd5U, 0x30U, 0x36U, 0xa5U, 0x38U,
-    0xbfU, 0x40U, 0xa3U, 0x9eU, 0x81U, 0xf3U, 0xd7U, 0xfbU,
-    0x7cU, 0xe3U, 0x39U, 0x82U, 0x9bU, 0x2fU, 0xffU, 0x87U,
-    0x34U, 0x8eU, 0x43U, 0x44U, 0xc4U, 0xdeU, 0xe9U, 0xcbU,
-    0x54U, 0x7bU, 0x94U, 0x32U, 0xa6U, 0xc2U, 0x23U, 0x3dU,
-    0xeeU, 0x4cU, 0x95U, 0x0bU, 0x42U, 0xfaU, 0xc3U, 0x4eU,
-    0x08U, 0x2eU, 0xa1U, 0x66U, 0x28U, 0xd9U, 0x24U, 0xb2U,
-    0x76U, 0x5bU, 0xa2U, 0x49U, 0x6dU, 0x8bU, 0xd1U, 0x25U,
-    0x72U, 0xf8U, 0xf6U, 0x64U, 0x86U, 0x68U, 0x98U, 0x16U,
-    0xd4U, 0xa4U, 0x5cU, 0xccU, 0x5dU, 0x65U, 0xb6U, 0x92U,
-    0x6cU, 0x70U, 0x48U, 0x50U, 0xfdU, 0xedU, 0xb9U, 0xdaU,
-    0x5eU, 0x15U, 0x46U, 0x57U, 0xa7U, 0x8dU, 0x9dU, 0x84U,
-    0x90U, 0xd8U, 0xabU, 0x00U, 0x8cU, 0xbcU, 0xd3U, 0x0aU,
-    0xf7U, 0xe4U, 0x58U, 0x05U, 0xb8U, 0xb3U, 0x45U, 0x06U,
-    0xd0U, 0x2cU, 0x1eU, 0x8fU, 0xcaU, 0x3fU, 0x0fU, 0x02U,
-    0xc1U, 0xafU, 0xbdU, 0x03U, 0x01U, 0x13U, 0x8aU, 0x6bU,
-    0x3aU, 0x91U, 0x11U, 0x41U, 0x4fU, 0x67U, 0xdcU, 0xeaU,
-    0x97U, 0xf2U, 0xcfU, 0xceU, 0xf0U, 0xb4U, 0xe6U, 0x73U,
-    0x96U, 0xacU, 0x74U, 0x22U, 0xe7U, 0xadU, 0x35U, 0x85U,
-    0xe2U, 0xf9U, 0x37U, 0xe8U, 0x1cU, 0x75U, 0xdfU, 0x6eU,
-    0x47U, 0xf1U, 0x1aU, 0x71U, 0x1dU, 0x29U, 0xc5U, 0x89U,
-    0x6fU, 0xb7U, 0x62U, 0x0eU, 0xaaU, 0x18U, 0xbeU, 0x1bU,
-    0xfcU, 0x56U, 0x3eU, 0x4bU, 0xc6U, 0xd2U, 0x79U, 0x20U,
-    0x9aU, 0xdbU, 0xc0U, 0xfeU, 0x78U, 0xcdU, 0x5aU, 0xf4U,
-    0x1fU, 0xddU, 0xa8U, 0x33U, 0x88U, 0x07U, 0xc7U, 0x31U,
-    0xb1U, 0x12U, 0x10U, 0x59U, 0x27U, 0x80U, 0xecU, 0x5fU,
-    0x60U, 0x51U, 0x7fU, 0xa9U, 0x19U, 0xb5U, 0x4aU, 0x0dU,
-    0x2dU, 0xe5U, 0x7aU, 0x9fU, 0x93U, 0xc9U, 0x9cU, 0xefU,
-    0xa0U, 0xe0U, 0x3bU, 0x4dU, 0xaeU, 0x2aU, 0xf5U, 0xb0U,
-    0xc8U, 0xebU, 0xbbU, 0x3cU, 0x83U, 0x53U, 0x99U, 0x61U,
-    0x17U, 0x2bU, 0x04U, 0x7eU, 0xbaU, 0x77U, 0xd6U, 0x26U,
-    0xe1U, 0x69U, 0x14U, 0x63U, 0x55U, 0x21U, 0x0cU, 0x7dU
+static const u8 Td4[256] = {
+    0x52U,
+    0x09U,
+    0x6aU,
+    0xd5U,
+    0x30U,
+    0x36U,
+    0xa5U,
+    0x38U,
+    0xbfU,
+    0x40U,
+    0xa3U,
+    0x9eU,
+    0x81U,
+    0xf3U,
+    0xd7U,
+    0xfbU,
+    0x7cU,
+    0xe3U,
+    0x39U,
+    0x82U,
+    0x9bU,
+    0x2fU,
+    0xffU,
+    0x87U,
+    0x34U,
+    0x8eU,
+    0x43U,
+    0x44U,
+    0xc4U,
+    0xdeU,
+    0xe9U,
+    0xcbU,
+    0x54U,
+    0x7bU,
+    0x94U,
+    0x32U,
+    0xa6U,
+    0xc2U,
+    0x23U,
+    0x3dU,
+    0xeeU,
+    0x4cU,
+    0x95U,
+    0x0bU,
+    0x42U,
+    0xfaU,
+    0xc3U,
+    0x4eU,
+    0x08U,
+    0x2eU,
+    0xa1U,
+    0x66U,
+    0x28U,
+    0xd9U,
+    0x24U,
+    0xb2U,
+    0x76U,
+    0x5bU,
+    0xa2U,
+    0x49U,
+    0x6dU,
+    0x8bU,
+    0xd1U,
+    0x25U,
+    0x72U,
+    0xf8U,
+    0xf6U,
+    0x64U,
+    0x86U,
+    0x68U,
+    0x98U,
+    0x16U,
+    0xd4U,
+    0xa4U,
+    0x5cU,
+    0xccU,
+    0x5dU,
+    0x65U,
+    0xb6U,
+    0x92U,
+    0x6cU,
+    0x70U,
+    0x48U,
+    0x50U,
+    0xfdU,
+    0xedU,
+    0xb9U,
+    0xdaU,
+    0x5eU,
+    0x15U,
+    0x46U,
+    0x57U,
+    0xa7U,
+    0x8dU,
+    0x9dU,
+    0x84U,
+    0x90U,
+    0xd8U,
+    0xabU,
+    0x00U,
+    0x8cU,
+    0xbcU,
+    0xd3U,
+    0x0aU,
+    0xf7U,
+    0xe4U,
+    0x58U,
+    0x05U,
+    0xb8U,
+    0xb3U,
+    0x45U,
+    0x06U,
+    0xd0U,
+    0x2cU,
+    0x1eU,
+    0x8fU,
+    0xcaU,
+    0x3fU,
+    0x0fU,
+    0x02U,
+    0xc1U,
+    0xafU,
+    0xbdU,
+    0x03U,
+    0x01U,
+    0x13U,
+    0x8aU,
+    0x6bU,
+    0x3aU,
+    0x91U,
+    0x11U,
+    0x41U,
+    0x4fU,
+    0x67U,
+    0xdcU,
+    0xeaU,
+    0x97U,
+    0xf2U,
+    0xcfU,
+    0xceU,
+    0xf0U,
+    0xb4U,
+    0xe6U,
+    0x73U,
+    0x96U,
+    0xacU,
+    0x74U,
+    0x22U,
+    0xe7U,
+    0xadU,
+    0x35U,
+    0x85U,
+    0xe2U,
+    0xf9U,
+    0x37U,
+    0xe8U,
+    0x1cU,
+    0x75U,
+    0xdfU,
+    0x6eU,
+    0x47U,
+    0xf1U,
+    0x1aU,
+    0x71U,
+    0x1dU,
+    0x29U,
+    0xc5U,
+    0x89U,
+    0x6fU,
+    0xb7U,
+    0x62U,
+    0x0eU,
+    0xaaU,
+    0x18U,
+    0xbeU,
+    0x1bU,
+    0xfcU,
+    0x56U,
+    0x3eU,
+    0x4bU,
+    0xc6U,
+    0xd2U,
+    0x79U,
+    0x20U,
+    0x9aU,
+    0xdbU,
+    0xc0U,
+    0xfeU,
+    0x78U,
+    0xcdU,
+    0x5aU,
+    0xf4U,
+    0x1fU,
+    0xddU,
+    0xa8U,
+    0x33U,
+    0x88U,
+    0x07U,
+    0xc7U,
+    0x31U,
+    0xb1U,
+    0x12U,
+    0x10U,
+    0x59U,
+    0x27U,
+    0x80U,
+    0xecU,
+    0x5fU,
+    0x60U,
+    0x51U,
+    0x7fU,
+    0xa9U,
+    0x19U,
+    0xb5U,
+    0x4aU,
+    0x0dU,
+    0x2dU,
+    0xe5U,
+    0x7aU,
+    0x9fU,
+    0x93U,
+    0xc9U,
+    0x9cU,
+    0xefU,
+    0xa0U,
+    0xe0U,
+    0x3bU,
+    0x4dU,
+    0xaeU,
+    0x2aU,
+    0xf5U,
+    0xb0U,
+    0xc8U,
+    0xebU,
+    0xbbU,
+    0x3cU,
+    0x83U,
+    0x53U,
+    0x99U,
+    0x61U,
+    0x17U,
+    0x2bU,
+    0x04U,
+    0x7eU,
+    0xbaU,
+    0x77U,
+    0xd6U,
+    0x26U,
+    0xe1U,
+    0x69U,
+    0x14U,
+    0x63U,
+    0x55U,
+    0x21U,
+    0x0cU,
+    0x7dU,
 };
-static const uint32_t rcon[] = {
-    0x01000000, 0x02000000, 0x04000000, 0x08000000,
-    0x10000000, 0x20000000, 0x40000000, 0x80000000,
-    0x1B000000, 0x36000000
-    /* for 128-bit blocks, Rijndael never uses more than 10 rcon values */
+static const u32 rcon[] = {
+    0x01000000,
+    0x02000000,
+    0x04000000,
+    0x08000000,
+    0x10000000,
+    0x20000000,
+    0x40000000,
+    0x80000000,
+    0x1B000000,
+    0x36000000, /* for 128-bit blocks, Rijndael never uses more than 10 rcon values */
 };
 
 /**
  * Expand the cipher key into the encryption key schedule.
  */
-int AES_set_encrypt_key(const unsigned char *userKey, int bits,
+int AES_set_encrypt_key(const unsigned char *userKey, const int bits,
     AES_KEY *key)
 {
 
-    uint32_t *rk;
+    u32 *rk;
     int i = 0;
-    uint32_t temp;
+    u32 temp;
 
     if (!userKey || !key)
         return -1;
@@ -1359,13 +3125,13 @@ int AES_set_encrypt_key(const unsigned char *userKey, int bits,
 /**
  * Expand the cipher key into the decryption key schedule.
  */
-int AES_set_decrypt_key(const unsigned char *userKey, int bits,
+int AES_set_decrypt_key(const unsigned char *userKey, const int bits,
     AES_KEY *key)
 {
 
-    uint32_t *rk;
+    u32 *rk;
     int i, j, status;
-    uint32_t temp;
+    u32 temp;
 
     /* first, start with an encryption schedule */
     status = AES_set_encrypt_key(userKey, bits, key);
@@ -1408,8 +3174,8 @@ void AES_encrypt(const unsigned char *in, unsigned char *out,
     const AES_KEY *key)
 {
 
-    const uint32_t *rk;
-    uint32_t s0, s1, s2, s3, t0, t1, t2, t3;
+    const u32 *rk;
+    u32 s0, s1, s2, s3, t0, t1, t2, t3;
 #ifndef FULL_UNROLL
     int r;
 #endif /* ?FULL_UNROLL */
@@ -1540,8 +3306,8 @@ void AES_decrypt(const unsigned char *in, unsigned char *out,
     const AES_KEY *key)
 {
 
-    const uint32_t *rk;
-    uint32_t s0, s1, s2, s3, t0, t1, t2, t3;
+    const u32 *rk;
+    u32 s0, s1, s2, s3, t0, t1, t2, t3;
 #ifndef FULL_UNROLL
     int r;
 #endif /* ?FULL_UNROLL */
@@ -1654,19 +3420,19 @@ void AES_decrypt(const unsigned char *in, unsigned char *out,
      * apply last round and
      * map cipher state to byte array block:
      */
-    s0 = ((uint32_t)Td4[(t0 >> 24)] << 24) ^ ((uint32_t)Td4[(t3 >> 16) & 0xff] << 16) ^ ((uint32_t)Td4[(t2 >> 8) & 0xff] << 8) ^ ((uint32_t)Td4[(t1) & 0xff]) ^ rk[0];
+    s0 = ((u32)Td4[(t0 >> 24)] << 24) ^ ((u32)Td4[(t3 >> 16) & 0xff] << 16) ^ ((u32)Td4[(t2 >> 8) & 0xff] << 8) ^ ((u32)Td4[(t1) & 0xff]) ^ rk[0];
     PUTU32(out, s0);
-    s1 = ((uint32_t)Td4[(t1 >> 24)] << 24) ^ ((uint32_t)Td4[(t0 >> 16) & 0xff] << 16) ^ ((uint32_t)Td4[(t3 >> 8) & 0xff] << 8) ^ ((uint32_t)Td4[(t2) & 0xff]) ^ rk[1];
+    s1 = ((u32)Td4[(t1 >> 24)] << 24) ^ ((u32)Td4[(t0 >> 16) & 0xff] << 16) ^ ((u32)Td4[(t3 >> 8) & 0xff] << 8) ^ ((u32)Td4[(t2) & 0xff]) ^ rk[1];
     PUTU32(out + 4, s1);
-    s2 = ((uint32_t)Td4[(t2 >> 24)] << 24) ^ ((uint32_t)Td4[(t1 >> 16) & 0xff] << 16) ^ ((uint32_t)Td4[(t0 >> 8) & 0xff] << 8) ^ ((uint32_t)Td4[(t3) & 0xff]) ^ rk[2];
+    s2 = ((u32)Td4[(t2 >> 24)] << 24) ^ ((u32)Td4[(t1 >> 16) & 0xff] << 16) ^ ((u32)Td4[(t0 >> 8) & 0xff] << 8) ^ ((u32)Td4[(t3) & 0xff]) ^ rk[2];
     PUTU32(out + 8, s2);
-    s3 = ((uint32_t)Td4[(t3 >> 24)] << 24) ^ ((uint32_t)Td4[(t2 >> 16) & 0xff] << 16) ^ ((uint32_t)Td4[(t1 >> 8) & 0xff] << 8) ^ ((uint32_t)Td4[(t0) & 0xff]) ^ rk[3];
+    s3 = ((u32)Td4[(t3 >> 24)] << 24) ^ ((u32)Td4[(t2 >> 16) & 0xff] << 16) ^ ((u32)Td4[(t1 >> 8) & 0xff] << 8) ^ ((u32)Td4[(t0) & 0xff]) ^ rk[3];
     PUTU32(out + 12, s3);
 }
 
 #else /* AES_ASM */
 
-static const uint8_t Te4[256] = {
+static const u8 Te4[256] = {
     0x63U, 0x7cU, 0x77U, 0x7bU, 0xf2U, 0x6bU, 0x6fU, 0xc5U,
     0x30U, 0x01U, 0x67U, 0x2bU, 0xfeU, 0xd7U, 0xabU, 0x76U,
     0xcaU, 0x82U, 0xc9U, 0x7dU, 0xfaU, 0x59U, 0x47U, 0xf0U,
@@ -1700,22 +3466,28 @@ static const uint8_t Te4[256] = {
     0x8cU, 0xa1U, 0x89U, 0x0dU, 0xbfU, 0xe6U, 0x42U, 0x68U,
     0x41U, 0x99U, 0x2dU, 0x0fU, 0xb0U, 0x54U, 0xbbU, 0x16U
 };
-static const uint32_t rcon[] = {
-    0x01000000, 0x02000000, 0x04000000, 0x08000000,
-    0x10000000, 0x20000000, 0x40000000, 0x80000000,
-    0x1B000000, 0x36000000
-    /* for 128-bit blocks, Rijndael never uses more than 10 rcon values */
+static const u32 rcon[] = {
+    0x01000000,
+    0x02000000,
+    0x04000000,
+    0x08000000,
+    0x10000000,
+    0x20000000,
+    0x40000000,
+    0x80000000,
+    0x1B000000,
+    0x36000000, /* for 128-bit blocks, Rijndael never uses more than 10 rcon values */
 };
 
 /**
  * Expand the cipher key into the encryption key schedule.
  */
-int AES_set_encrypt_key(const unsigned char *userKey, int bits,
+int AES_set_encrypt_key(const unsigned char *userKey, const int bits,
     AES_KEY *key)
 {
-    uint32_t *rk;
+    u32 *rk;
     int i = 0;
-    uint32_t temp;
+    u32 temp;
 
     if (!userKey || !key)
         return -1;
@@ -1738,7 +3510,7 @@ int AES_set_encrypt_key(const unsigned char *userKey, int bits,
     if (bits == 128) {
         while (1) {
             temp = rk[3];
-            rk[4] = rk[0] ^ ((uint32_t)Te4[(temp >> 16) & 0xff] << 24) ^ ((uint32_t)Te4[(temp >> 8) & 0xff] << 16) ^ ((uint32_t)Te4[(temp) & 0xff] << 8) ^ ((uint32_t)Te4[(temp >> 24)]) ^ rcon[i];
+            rk[4] = rk[0] ^ ((u32)Te4[(temp >> 16) & 0xff] << 24) ^ ((u32)Te4[(temp >> 8) & 0xff] << 16) ^ ((u32)Te4[(temp) & 0xff] << 8) ^ ((u32)Te4[(temp >> 24)]) ^ rcon[i];
             rk[5] = rk[1] ^ rk[4];
             rk[6] = rk[2] ^ rk[5];
             rk[7] = rk[3] ^ rk[6];
@@ -1753,7 +3525,7 @@ int AES_set_encrypt_key(const unsigned char *userKey, int bits,
     if (bits == 192) {
         while (1) {
             temp = rk[5];
-            rk[6] = rk[0] ^ ((uint32_t)Te4[(temp >> 16) & 0xff] << 24) ^ ((uint32_t)Te4[(temp >> 8) & 0xff] << 16) ^ ((uint32_t)Te4[(temp) & 0xff] << 8) ^ ((uint32_t)Te4[(temp >> 24)]) ^ rcon[i];
+            rk[6] = rk[0] ^ ((u32)Te4[(temp >> 16) & 0xff] << 24) ^ ((u32)Te4[(temp >> 8) & 0xff] << 16) ^ ((u32)Te4[(temp) & 0xff] << 8) ^ ((u32)Te4[(temp >> 24)]) ^ rcon[i];
             rk[7] = rk[1] ^ rk[6];
             rk[8] = rk[2] ^ rk[7];
             rk[9] = rk[3] ^ rk[8];
@@ -1770,7 +3542,7 @@ int AES_set_encrypt_key(const unsigned char *userKey, int bits,
     if (bits == 256) {
         while (1) {
             temp = rk[7];
-            rk[8] = rk[0] ^ ((uint32_t)Te4[(temp >> 16) & 0xff] << 24) ^ ((uint32_t)Te4[(temp >> 8) & 0xff] << 16) ^ ((uint32_t)Te4[(temp) & 0xff] << 8) ^ ((uint32_t)Te4[(temp >> 24)]) ^ rcon[i];
+            rk[8] = rk[0] ^ ((u32)Te4[(temp >> 16) & 0xff] << 24) ^ ((u32)Te4[(temp >> 8) & 0xff] << 16) ^ ((u32)Te4[(temp) & 0xff] << 8) ^ ((u32)Te4[(temp >> 24)]) ^ rcon[i];
             rk[9] = rk[1] ^ rk[8];
             rk[10] = rk[2] ^ rk[9];
             rk[11] = rk[3] ^ rk[10];
@@ -1778,7 +3550,7 @@ int AES_set_encrypt_key(const unsigned char *userKey, int bits,
                 return 0;
             }
             temp = rk[11];
-            rk[12] = rk[4] ^ ((uint32_t)Te4[(temp >> 24)] << 24) ^ ((uint32_t)Te4[(temp >> 16) & 0xff] << 16) ^ ((uint32_t)Te4[(temp >> 8) & 0xff] << 8) ^ ((uint32_t)Te4[(temp) & 0xff]);
+            rk[12] = rk[4] ^ ((u32)Te4[(temp >> 24)] << 24) ^ ((u32)Te4[(temp >> 16) & 0xff] << 16) ^ ((u32)Te4[(temp >> 8) & 0xff] << 8) ^ ((u32)Te4[(temp) & 0xff]);
             rk[13] = rk[5] ^ rk[12];
             rk[14] = rk[6] ^ rk[13];
             rk[15] = rk[7] ^ rk[14];
@@ -1792,13 +3564,13 @@ int AES_set_encrypt_key(const unsigned char *userKey, int bits,
 /**
  * Expand the cipher key into the decryption key schedule.
  */
-int AES_set_decrypt_key(const unsigned char *userKey, int bits,
+int AES_set_decrypt_key(const unsigned char *userKey, const int bits,
     AES_KEY *key)
 {
 
-    uint32_t *rk;
+    u32 *rk;
     int i, j, status;
-    uint32_t temp;
+    u32 temp;
 
     /* first, start with an encryption schedule */
     status = AES_set_encrypt_key(userKey, bits, key);
@@ -1826,7 +3598,7 @@ int AES_set_decrypt_key(const unsigned char *userKey, int bits,
     for (i = 1; i < (key->rounds); i++) {
         rk += 4;
         for (j = 0; j < 4; j++) {
-            uint32_t tp1, tp2, tp4, tp8, tp9, tpb, tpd, tpe, m;
+            u32 tp1, tp2, tp4, tp8, tp9, tpb, tpd, tpe, m;
 
             tp1 = rk[j];
             m = tp1 & 0x80808080;
diff --git a/crypto/aes/aes_ige.c b/crypto/aes/aes_ige.c
index 93f7ffd456..0308f3f225 100644
--- a/crypto/aes/aes_ige.c
+++ b/crypto/aes/aes_ige.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -47,7 +47,7 @@ typedef struct {
 /*  Use of this function is deprecated. */
 void AES_ige_encrypt(const unsigned char *in, unsigned char *out,
     size_t length, const AES_KEY *key,
-    unsigned char *ivec, int enc)
+    unsigned char *ivec, const int enc)
 {
     size_t n;
     size_t len = length / AES_BLOCK_SIZE;
@@ -180,7 +180,7 @@ void AES_ige_encrypt(const unsigned char *in, unsigned char *out,
 void AES_bi_ige_encrypt(const unsigned char *in, unsigned char *out,
     size_t length, const AES_KEY *key,
     const AES_KEY *key2, const unsigned char *ivec,
-    int enc)
+    const int enc)
 {
     size_t n;
     size_t len = length;
diff --git a/crypto/aes/aes_local.h b/crypto/aes/aes_local.h
index 38c37537fc..71f9f5c648 100644
--- a/crypto/aes/aes_local.h
+++ b/crypto/aes/aes_local.h
@@ -17,22 +17,31 @@
 
 #if defined(_MSC_VER) && (defined(_M_IX86) || defined(_M_AMD64) || defined(_M_X64))
 #define SWAP(x) (_lrotl(x, 8) & 0x00ff00ff | _lrotr(x, 8) & 0xff00ff00)
-#define GETU32(p) SWAP(*((uint32_t *)(p)))
-#define PUTU32(ct, st)                    \
-    {                                     \
-        *((uint32_t *)(ct)) = SWAP((st)); \
+#define GETU32(p) SWAP(*((u32 *)(p)))
+#define PUTU32(ct, st)               \
+    {                                \
+        *((u32 *)(ct)) = SWAP((st)); \
     }
 #else
-#define GETU32(pt) (((uint32_t)(pt)[0] << 24) ^ ((uint32_t)(pt)[1] << 16) ^ ((uint32_t)(pt)[2] << 8) ^ ((uint32_t)(pt)[3]))
-#define PUTU32(ct, st)                   \
-    {                                    \
-        (ct)[0] = (uint8_t)((st) >> 24); \
-        (ct)[1] = (uint8_t)((st) >> 16); \
-        (ct)[2] = (uint8_t)((st) >> 8);  \
-        (ct)[3] = (uint8_t)(st);         \
+#define GETU32(pt) (((u32)(pt)[0] << 24) ^ ((u32)(pt)[1] << 16) ^ ((u32)(pt)[2] << 8) ^ ((u32)(pt)[3]))
+#define PUTU32(ct, st)              \
+    {                               \
+        (ct)[0] = (u8)((st) >> 24); \
+        (ct)[1] = (u8)((st) >> 16); \
+        (ct)[2] = (u8)((st) >> 8);  \
+        (ct)[3] = (u8)(st);         \
     }
 #endif
 
+typedef uint64_t u64;
+#ifdef AES_LONG
+typedef unsigned long u32;
+#else
+typedef unsigned int u32;
+#endif
+typedef unsigned short u16;
+typedef unsigned char u8;
+
 #define MAXKC (256 / 32)
 #define MAXKB (256 / 8)
 #define MAXNR 14
diff --git a/crypto/aes/aes_x86core.c b/crypto/aes/aes_x86core.c
new file mode 100644
index 0000000000..0fa994871b
--- /dev/null
+++ b/crypto/aes/aes_x86core.c
@@ -0,0 +1,867 @@
+/*
+ * Copyright 2006-2016 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+/*
+ * This is experimental x86[_64] derivative. It assumes little-endian
+ * byte order and expects CPU to sustain unaligned memory references.
+ * It is used as playground for cache-time attack mitigations and
+ * serves as reference C implementation for x86[_64] as well as some
+ * other assembly modules.
+ */
+
+/**
+ * rijndael-alg-fst.c
+ *
+ * @version 3.0 (December 2000)
+ *
+ * Optimised ANSI C code for the Rijndael cipher (now AES)
+ *
+ * @author Vincent Rijmen
+ * @author Antoon Bosselaers
+ * @author Paulo Barreto
+ *
+ * This code is hereby placed in the public domain.
+ *
+ * THIS SOFTWARE IS PROVIDED BY THE AUTHORS ''AS IS'' AND ANY EXPRESS
+ * OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
+ * WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
+ * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHORS OR CONTRIBUTORS BE
+ * LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
+ * CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
+ * SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR
+ * BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
+ * WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE
+ * OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE,
+ * EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+
+#include 
+
+#include 
+#include 
+#include "aes_local.h"
+
+/*
+ * These two parameters control which table, 256-byte or 2KB, is
+ * referenced in outer and respectively inner rounds.
+ */
+#define AES_COMPACT_IN_OUTER_ROUNDS
+#ifdef AES_COMPACT_IN_OUTER_ROUNDS
+/* AES_COMPACT_IN_OUTER_ROUNDS costs ~30% in performance, while
+ * adding AES_COMPACT_IN_INNER_ROUNDS reduces benchmark *further*
+ * by factor of ~2. */
+#undef AES_COMPACT_IN_INNER_ROUNDS
+#endif
+
+#if 1
+static void prefetch256(const void *table)
+{
+    volatile unsigned long *t = (void *)table, ret;
+    unsigned long sum;
+    int i;
+
+    /* 32 is common least cache-line size */
+    for (sum = 0, i = 0; i < 256 / sizeof(t[0]); i += 32 / sizeof(t[0]))
+        sum ^= t[i];
+
+    ret = sum;
+}
+#else
+#define prefetch256(t)
+#endif
+
+#undef GETU32
+#define GETU32(p) (*((u32 *)(p)))
+
+#if (defined(_WIN32) || defined(_WIN64)) && !defined(__MINGW32__)
+#define U64(C) C##UI64
+#elif defined(__arch64__)
+#define U64(C) C##UL
+#else
+#define U64(C) C##ULL
+#endif
+
+#undef ROTATE
+#if defined(_MSC_VER)
+#define ROTATE(a, n) _lrotl(a, n)
+#elif defined(__ICC)
+#define ROTATE(a, n) _rotl(a, n)
+#elif defined(__GNUC__) && __GNUC__ >= 2
+#if defined(__i386) || defined(__i386__) || defined(__x86_64) || defined(__x86_64__)
+#define ROTATE(a, n) ({        \
+    register unsigned int ret; \
+    asm(                       \
+        "roll %1,%0"           \
+        : "=r"(ret)            \
+        : "I"(n), "0"(a)       \
+        : "cc");               \
+    ret;                       \
+})
+#endif
+#endif
+/*-
+Te [x] = S [x].[02, 01, 01, 03, 02, 01, 01, 03];
+Te0[x] = S [x].[02, 01, 01, 03];
+Te1[x] = S [x].[03, 02, 01, 01];
+Te2[x] = S [x].[01, 03, 02, 01];
+Te3[x] = S [x].[01, 01, 03, 02];
+*/
+#define Te0 (u32)((u64 *)((u8 *)Te + 0))
+#define Te1 (u32)((u64 *)((u8 *)Te + 3))
+#define Te2 (u32)((u64 *)((u8 *)Te + 2))
+#define Te3 (u32)((u64 *)((u8 *)Te + 1))
+/*-
+Td [x] = Si[x].[0e, 09, 0d, 0b, 0e, 09, 0d, 0b];
+Td0[x] = Si[x].[0e, 09, 0d, 0b];
+Td1[x] = Si[x].[0b, 0e, 09, 0d];
+Td2[x] = Si[x].[0d, 0b, 0e, 09];
+Td3[x] = Si[x].[09, 0d, 0b, 0e];
+Td4[x] = Si[x].[01];
+*/
+#define Td0 (u32)((u64 *)((u8 *)Td + 0))
+#define Td1 (u32)((u64 *)((u8 *)Td + 3))
+#define Td2 (u32)((u64 *)((u8 *)Td + 2))
+#define Td3 (u32)((u64 *)((u8 *)Td + 1))
+
+static const u64 Te[256] = {
+    U64(0xa56363c6a56363c6), U64(0x847c7cf8847c7cf8),
+    U64(0x997777ee997777ee), U64(0x8d7b7bf68d7b7bf6),
+    U64(0x0df2f2ff0df2f2ff), U64(0xbd6b6bd6bd6b6bd6),
+    U64(0xb16f6fdeb16f6fde), U64(0x54c5c59154c5c591),
+    U64(0x5030306050303060), U64(0x0301010203010102),
+    U64(0xa96767cea96767ce), U64(0x7d2b2b567d2b2b56),
+    U64(0x19fefee719fefee7), U64(0x62d7d7b562d7d7b5),
+    U64(0xe6abab4de6abab4d), U64(0x9a7676ec9a7676ec),
+    U64(0x45caca8f45caca8f), U64(0x9d82821f9d82821f),
+    U64(0x40c9c98940c9c989), U64(0x877d7dfa877d7dfa),
+    U64(0x15fafaef15fafaef), U64(0xeb5959b2eb5959b2),
+    U64(0xc947478ec947478e), U64(0x0bf0f0fb0bf0f0fb),
+    U64(0xecadad41ecadad41), U64(0x67d4d4b367d4d4b3),
+    U64(0xfda2a25ffda2a25f), U64(0xeaafaf45eaafaf45),
+    U64(0xbf9c9c23bf9c9c23), U64(0xf7a4a453f7a4a453),
+    U64(0x967272e4967272e4), U64(0x5bc0c09b5bc0c09b),
+    U64(0xc2b7b775c2b7b775), U64(0x1cfdfde11cfdfde1),
+    U64(0xae93933dae93933d), U64(0x6a26264c6a26264c),
+    U64(0x5a36366c5a36366c), U64(0x413f3f7e413f3f7e),
+    U64(0x02f7f7f502f7f7f5), U64(0x4fcccc834fcccc83),
+    U64(0x5c3434685c343468), U64(0xf4a5a551f4a5a551),
+    U64(0x34e5e5d134e5e5d1), U64(0x08f1f1f908f1f1f9),
+    U64(0x937171e2937171e2), U64(0x73d8d8ab73d8d8ab),
+    U64(0x5331316253313162), U64(0x3f15152a3f15152a),
+    U64(0x0c0404080c040408), U64(0x52c7c79552c7c795),
+    U64(0x6523234665232346), U64(0x5ec3c39d5ec3c39d),
+    U64(0x2818183028181830), U64(0xa1969637a1969637),
+    U64(0x0f05050a0f05050a), U64(0xb59a9a2fb59a9a2f),
+    U64(0x0907070e0907070e), U64(0x3612122436121224),
+    U64(0x9b80801b9b80801b), U64(0x3de2e2df3de2e2df),
+    U64(0x26ebebcd26ebebcd), U64(0x6927274e6927274e),
+    U64(0xcdb2b27fcdb2b27f), U64(0x9f7575ea9f7575ea),
+    U64(0x1b0909121b090912), U64(0x9e83831d9e83831d),
+    U64(0x742c2c58742c2c58), U64(0x2e1a1a342e1a1a34),
+    U64(0x2d1b1b362d1b1b36), U64(0xb26e6edcb26e6edc),
+    U64(0xee5a5ab4ee5a5ab4), U64(0xfba0a05bfba0a05b),
+    U64(0xf65252a4f65252a4), U64(0x4d3b3b764d3b3b76),
+    U64(0x61d6d6b761d6d6b7), U64(0xceb3b37dceb3b37d),
+    U64(0x7b2929527b292952), U64(0x3ee3e3dd3ee3e3dd),
+    U64(0x712f2f5e712f2f5e), U64(0x9784841397848413),
+    U64(0xf55353a6f55353a6), U64(0x68d1d1b968d1d1b9),
+    U64(0x0000000000000000), U64(0x2cededc12cededc1),
+    U64(0x6020204060202040), U64(0x1ffcfce31ffcfce3),
+    U64(0xc8b1b179c8b1b179), U64(0xed5b5bb6ed5b5bb6),
+    U64(0xbe6a6ad4be6a6ad4), U64(0x46cbcb8d46cbcb8d),
+    U64(0xd9bebe67d9bebe67), U64(0x4b3939724b393972),
+    U64(0xde4a4a94de4a4a94), U64(0xd44c4c98d44c4c98),
+    U64(0xe85858b0e85858b0), U64(0x4acfcf854acfcf85),
+    U64(0x6bd0d0bb6bd0d0bb), U64(0x2aefefc52aefefc5),
+    U64(0xe5aaaa4fe5aaaa4f), U64(0x16fbfbed16fbfbed),
+    U64(0xc5434386c5434386), U64(0xd74d4d9ad74d4d9a),
+    U64(0x5533336655333366), U64(0x9485851194858511),
+    U64(0xcf45458acf45458a), U64(0x10f9f9e910f9f9e9),
+    U64(0x0602020406020204), U64(0x817f7ffe817f7ffe),
+    U64(0xf05050a0f05050a0), U64(0x443c3c78443c3c78),
+    U64(0xba9f9f25ba9f9f25), U64(0xe3a8a84be3a8a84b),
+    U64(0xf35151a2f35151a2), U64(0xfea3a35dfea3a35d),
+    U64(0xc0404080c0404080), U64(0x8a8f8f058a8f8f05),
+    U64(0xad92923fad92923f), U64(0xbc9d9d21bc9d9d21),
+    U64(0x4838387048383870), U64(0x04f5f5f104f5f5f1),
+    U64(0xdfbcbc63dfbcbc63), U64(0xc1b6b677c1b6b677),
+    U64(0x75dadaaf75dadaaf), U64(0x6321214263212142),
+    U64(0x3010102030101020), U64(0x1affffe51affffe5),
+    U64(0x0ef3f3fd0ef3f3fd), U64(0x6dd2d2bf6dd2d2bf),
+    U64(0x4ccdcd814ccdcd81), U64(0x140c0c18140c0c18),
+    U64(0x3513132635131326), U64(0x2fececc32fececc3),
+    U64(0xe15f5fbee15f5fbe), U64(0xa2979735a2979735),
+    U64(0xcc444488cc444488), U64(0x3917172e3917172e),
+    U64(0x57c4c49357c4c493), U64(0xf2a7a755f2a7a755),
+    U64(0x827e7efc827e7efc), U64(0x473d3d7a473d3d7a),
+    U64(0xac6464c8ac6464c8), U64(0xe75d5dbae75d5dba),
+    U64(0x2b1919322b191932), U64(0x957373e6957373e6),
+    U64(0xa06060c0a06060c0), U64(0x9881811998818119),
+    U64(0xd14f4f9ed14f4f9e), U64(0x7fdcdca37fdcdca3),
+    U64(0x6622224466222244), U64(0x7e2a2a547e2a2a54),
+    U64(0xab90903bab90903b), U64(0x8388880b8388880b),
+    U64(0xca46468cca46468c), U64(0x29eeeec729eeeec7),
+    U64(0xd3b8b86bd3b8b86b), U64(0x3c1414283c141428),
+    U64(0x79dedea779dedea7), U64(0xe25e5ebce25e5ebc),
+    U64(0x1d0b0b161d0b0b16), U64(0x76dbdbad76dbdbad),
+    U64(0x3be0e0db3be0e0db), U64(0x5632326456323264),
+    U64(0x4e3a3a744e3a3a74), U64(0x1e0a0a141e0a0a14),
+    U64(0xdb494992db494992), U64(0x0a06060c0a06060c),
+    U64(0x6c2424486c242448), U64(0xe45c5cb8e45c5cb8),
+    U64(0x5dc2c29f5dc2c29f), U64(0x6ed3d3bd6ed3d3bd),
+    U64(0xefacac43efacac43), U64(0xa66262c4a66262c4),
+    U64(0xa8919139a8919139), U64(0xa4959531a4959531),
+    U64(0x37e4e4d337e4e4d3), U64(0x8b7979f28b7979f2),
+    U64(0x32e7e7d532e7e7d5), U64(0x43c8c88b43c8c88b),
+    U64(0x5937376e5937376e), U64(0xb76d6ddab76d6dda),
+    U64(0x8c8d8d018c8d8d01), U64(0x64d5d5b164d5d5b1),
+    U64(0xd24e4e9cd24e4e9c), U64(0xe0a9a949e0a9a949),
+    U64(0xb46c6cd8b46c6cd8), U64(0xfa5656acfa5656ac),
+    U64(0x07f4f4f307f4f4f3), U64(0x25eaeacf25eaeacf),
+    U64(0xaf6565caaf6565ca), U64(0x8e7a7af48e7a7af4),
+    U64(0xe9aeae47e9aeae47), U64(0x1808081018080810),
+    U64(0xd5baba6fd5baba6f), U64(0x887878f0887878f0),
+    U64(0x6f25254a6f25254a), U64(0x722e2e5c722e2e5c),
+    U64(0x241c1c38241c1c38), U64(0xf1a6a657f1a6a657),
+    U64(0xc7b4b473c7b4b473), U64(0x51c6c69751c6c697),
+    U64(0x23e8e8cb23e8e8cb), U64(0x7cdddda17cdddda1),
+    U64(0x9c7474e89c7474e8), U64(0x211f1f3e211f1f3e),
+    U64(0xdd4b4b96dd4b4b96), U64(0xdcbdbd61dcbdbd61),
+    U64(0x868b8b0d868b8b0d), U64(0x858a8a0f858a8a0f),
+    U64(0x907070e0907070e0), U64(0x423e3e7c423e3e7c),
+    U64(0xc4b5b571c4b5b571), U64(0xaa6666ccaa6666cc),
+    U64(0xd8484890d8484890), U64(0x0503030605030306),
+    U64(0x01f6f6f701f6f6f7), U64(0x120e0e1c120e0e1c),
+    U64(0xa36161c2a36161c2), U64(0x5f35356a5f35356a),
+    U64(0xf95757aef95757ae), U64(0xd0b9b969d0b9b969),
+    U64(0x9186861791868617), U64(0x58c1c19958c1c199),
+    U64(0x271d1d3a271d1d3a), U64(0xb99e9e27b99e9e27),
+    U64(0x38e1e1d938e1e1d9), U64(0x13f8f8eb13f8f8eb),
+    U64(0xb398982bb398982b), U64(0x3311112233111122),
+    U64(0xbb6969d2bb6969d2), U64(0x70d9d9a970d9d9a9),
+    U64(0x898e8e07898e8e07), U64(0xa7949433a7949433),
+    U64(0xb69b9b2db69b9b2d), U64(0x221e1e3c221e1e3c),
+    U64(0x9287871592878715), U64(0x20e9e9c920e9e9c9),
+    U64(0x49cece8749cece87), U64(0xff5555aaff5555aa),
+    U64(0x7828285078282850), U64(0x7adfdfa57adfdfa5),
+    U64(0x8f8c8c038f8c8c03), U64(0xf8a1a159f8a1a159),
+    U64(0x8089890980898909), U64(0x170d0d1a170d0d1a),
+    U64(0xdabfbf65dabfbf65), U64(0x31e6e6d731e6e6d7),
+    U64(0xc6424284c6424284), U64(0xb86868d0b86868d0),
+    U64(0xc3414182c3414182), U64(0xb0999929b0999929),
+    U64(0x772d2d5a772d2d5a), U64(0x110f0f1e110f0f1e),
+    U64(0xcbb0b07bcbb0b07b), U64(0xfc5454a8fc5454a8),
+    U64(0xd6bbbb6dd6bbbb6d), U64(0x3a16162c3a16162c)
+};
+
+static const u8 Te4[256] = {
+    0x63U, 0x7cU, 0x77U, 0x7bU, 0xf2U, 0x6bU, 0x6fU, 0xc5U,
+    0x30U, 0x01U, 0x67U, 0x2bU, 0xfeU, 0xd7U, 0xabU, 0x76U,
+    0xcaU, 0x82U, 0xc9U, 0x7dU, 0xfaU, 0x59U, 0x47U, 0xf0U,
+    0xadU, 0xd4U, 0xa2U, 0xafU, 0x9cU, 0xa4U, 0x72U, 0xc0U,
+    0xb7U, 0xfdU, 0x93U, 0x26U, 0x36U, 0x3fU, 0xf7U, 0xccU,
+    0x34U, 0xa5U, 0xe5U, 0xf1U, 0x71U, 0xd8U, 0x31U, 0x15U,
+    0x04U, 0xc7U, 0x23U, 0xc3U, 0x18U, 0x96U, 0x05U, 0x9aU,
+    0x07U, 0x12U, 0x80U, 0xe2U, 0xebU, 0x27U, 0xb2U, 0x75U,
+    0x09U, 0x83U, 0x2cU, 0x1aU, 0x1bU, 0x6eU, 0x5aU, 0xa0U,
+    0x52U, 0x3bU, 0xd6U, 0xb3U, 0x29U, 0xe3U, 0x2fU, 0x84U,
+    0x53U, 0xd1U, 0x00U, 0xedU, 0x20U, 0xfcU, 0xb1U, 0x5bU,
+    0x6aU, 0xcbU, 0xbeU, 0x39U, 0x4aU, 0x4cU, 0x58U, 0xcfU,
+    0xd0U, 0xefU, 0xaaU, 0xfbU, 0x43U, 0x4dU, 0x33U, 0x85U,
+    0x45U, 0xf9U, 0x02U, 0x7fU, 0x50U, 0x3cU, 0x9fU, 0xa8U,
+    0x51U, 0xa3U, 0x40U, 0x8fU, 0x92U, 0x9dU, 0x38U, 0xf5U,
+    0xbcU, 0xb6U, 0xdaU, 0x21U, 0x10U, 0xffU, 0xf3U, 0xd2U,
+    0xcdU, 0x0cU, 0x13U, 0xecU, 0x5fU, 0x97U, 0x44U, 0x17U,
+    0xc4U, 0xa7U, 0x7eU, 0x3dU, 0x64U, 0x5dU, 0x19U, 0x73U,
+    0x60U, 0x81U, 0x4fU, 0xdcU, 0x22U, 0x2aU, 0x90U, 0x88U,
+    0x46U, 0xeeU, 0xb8U, 0x14U, 0xdeU, 0x5eU, 0x0bU, 0xdbU,
+    0xe0U, 0x32U, 0x3aU, 0x0aU, 0x49U, 0x06U, 0x24U, 0x5cU,
+    0xc2U, 0xd3U, 0xacU, 0x62U, 0x91U, 0x95U, 0xe4U, 0x79U,
+    0xe7U, 0xc8U, 0x37U, 0x6dU, 0x8dU, 0xd5U, 0x4eU, 0xa9U,
+    0x6cU, 0x56U, 0xf4U, 0xeaU, 0x65U, 0x7aU, 0xaeU, 0x08U,
+    0xbaU, 0x78U, 0x25U, 0x2eU, 0x1cU, 0xa6U, 0xb4U, 0xc6U,
+    0xe8U, 0xddU, 0x74U, 0x1fU, 0x4bU, 0xbdU, 0x8bU, 0x8aU,
+    0x70U, 0x3eU, 0xb5U, 0x66U, 0x48U, 0x03U, 0xf6U, 0x0eU,
+    0x61U, 0x35U, 0x57U, 0xb9U, 0x86U, 0xc1U, 0x1dU, 0x9eU,
+    0xe1U, 0xf8U, 0x98U, 0x11U, 0x69U, 0xd9U, 0x8eU, 0x94U,
+    0x9bU, 0x1eU, 0x87U, 0xe9U, 0xceU, 0x55U, 0x28U, 0xdfU,
+    0x8cU, 0xa1U, 0x89U, 0x0dU, 0xbfU, 0xe6U, 0x42U, 0x68U,
+    0x41U, 0x99U, 0x2dU, 0x0fU, 0xb0U, 0x54U, 0xbbU, 0x16U
+};
+
+static const u64 Td[256] = {
+    U64(0x50a7f45150a7f451), U64(0x5365417e5365417e),
+    U64(0xc3a4171ac3a4171a), U64(0x965e273a965e273a),
+    U64(0xcb6bab3bcb6bab3b), U64(0xf1459d1ff1459d1f),
+    U64(0xab58faacab58faac), U64(0x9303e34b9303e34b),
+    U64(0x55fa302055fa3020), U64(0xf66d76adf66d76ad),
+    U64(0x9176cc889176cc88), U64(0x254c02f5254c02f5),
+    U64(0xfcd7e54ffcd7e54f), U64(0xd7cb2ac5d7cb2ac5),
+    U64(0x8044352680443526), U64(0x8fa362b58fa362b5),
+    U64(0x495ab1de495ab1de), U64(0x671bba25671bba25),
+    U64(0x980eea45980eea45), U64(0xe1c0fe5de1c0fe5d),
+    U64(0x02752fc302752fc3), U64(0x12f04c8112f04c81),
+    U64(0xa397468da397468d), U64(0xc6f9d36bc6f9d36b),
+    U64(0xe75f8f03e75f8f03), U64(0x959c9215959c9215),
+    U64(0xeb7a6dbfeb7a6dbf), U64(0xda595295da595295),
+    U64(0x2d83bed42d83bed4), U64(0xd3217458d3217458),
+    U64(0x2969e0492969e049), U64(0x44c8c98e44c8c98e),
+    U64(0x6a89c2756a89c275), U64(0x78798ef478798ef4),
+    U64(0x6b3e58996b3e5899), U64(0xdd71b927dd71b927),
+    U64(0xb64fe1beb64fe1be), U64(0x17ad88f017ad88f0),
+    U64(0x66ac20c966ac20c9), U64(0xb43ace7db43ace7d),
+    U64(0x184adf63184adf63), U64(0x82311ae582311ae5),
+    U64(0x6033519760335197), U64(0x457f5362457f5362),
+    U64(0xe07764b1e07764b1), U64(0x84ae6bbb84ae6bbb),
+    U64(0x1ca081fe1ca081fe), U64(0x942b08f9942b08f9),
+    U64(0x5868487058684870), U64(0x19fd458f19fd458f),
+    U64(0x876cde94876cde94), U64(0xb7f87b52b7f87b52),
+    U64(0x23d373ab23d373ab), U64(0xe2024b72e2024b72),
+    U64(0x578f1fe3578f1fe3), U64(0x2aab55662aab5566),
+    U64(0x0728ebb20728ebb2), U64(0x03c2b52f03c2b52f),
+    U64(0x9a7bc5869a7bc586), U64(0xa50837d3a50837d3),
+    U64(0xf2872830f2872830), U64(0xb2a5bf23b2a5bf23),
+    U64(0xba6a0302ba6a0302), U64(0x5c8216ed5c8216ed),
+    U64(0x2b1ccf8a2b1ccf8a), U64(0x92b479a792b479a7),
+    U64(0xf0f207f3f0f207f3), U64(0xa1e2694ea1e2694e),
+    U64(0xcdf4da65cdf4da65), U64(0xd5be0506d5be0506),
+    U64(0x1f6234d11f6234d1), U64(0x8afea6c48afea6c4),
+    U64(0x9d532e349d532e34), U64(0xa055f3a2a055f3a2),
+    U64(0x32e18a0532e18a05), U64(0x75ebf6a475ebf6a4),
+    U64(0x39ec830b39ec830b), U64(0xaaef6040aaef6040),
+    U64(0x069f715e069f715e), U64(0x51106ebd51106ebd),
+    U64(0xf98a213ef98a213e), U64(0x3d06dd963d06dd96),
+    U64(0xae053eddae053edd), U64(0x46bde64d46bde64d),
+    U64(0xb58d5491b58d5491), U64(0x055dc471055dc471),
+    U64(0x6fd406046fd40604), U64(0xff155060ff155060),
+    U64(0x24fb981924fb9819), U64(0x97e9bdd697e9bdd6),
+    U64(0xcc434089cc434089), U64(0x779ed967779ed967),
+    U64(0xbd42e8b0bd42e8b0), U64(0x888b8907888b8907),
+    U64(0x385b19e7385b19e7), U64(0xdbeec879dbeec879),
+    U64(0x470a7ca1470a7ca1), U64(0xe90f427ce90f427c),
+    U64(0xc91e84f8c91e84f8), U64(0x0000000000000000),
+    U64(0x8386800983868009), U64(0x48ed2b3248ed2b32),
+    U64(0xac70111eac70111e), U64(0x4e725a6c4e725a6c),
+    U64(0xfbff0efdfbff0efd), U64(0x5638850f5638850f),
+    U64(0x1ed5ae3d1ed5ae3d), U64(0x27392d3627392d36),
+    U64(0x64d90f0a64d90f0a), U64(0x21a65c6821a65c68),
+    U64(0xd1545b9bd1545b9b), U64(0x3a2e36243a2e3624),
+    U64(0xb1670a0cb1670a0c), U64(0x0fe757930fe75793),
+    U64(0xd296eeb4d296eeb4), U64(0x9e919b1b9e919b1b),
+    U64(0x4fc5c0804fc5c080), U64(0xa220dc61a220dc61),
+    U64(0x694b775a694b775a), U64(0x161a121c161a121c),
+    U64(0x0aba93e20aba93e2), U64(0xe52aa0c0e52aa0c0),
+    U64(0x43e0223c43e0223c), U64(0x1d171b121d171b12),
+    U64(0x0b0d090e0b0d090e), U64(0xadc78bf2adc78bf2),
+    U64(0xb9a8b62db9a8b62d), U64(0xc8a91e14c8a91e14),
+    U64(0x8519f1578519f157), U64(0x4c0775af4c0775af),
+    U64(0xbbdd99eebbdd99ee), U64(0xfd607fa3fd607fa3),
+    U64(0x9f2601f79f2601f7), U64(0xbcf5725cbcf5725c),
+    U64(0xc53b6644c53b6644), U64(0x347efb5b347efb5b),
+    U64(0x7629438b7629438b), U64(0xdcc623cbdcc623cb),
+    U64(0x68fcedb668fcedb6), U64(0x63f1e4b863f1e4b8),
+    U64(0xcadc31d7cadc31d7), U64(0x1085634210856342),
+    U64(0x4022971340229713), U64(0x2011c6842011c684),
+    U64(0x7d244a857d244a85), U64(0xf83dbbd2f83dbbd2),
+    U64(0x1132f9ae1132f9ae), U64(0x6da129c76da129c7),
+    U64(0x4b2f9e1d4b2f9e1d), U64(0xf330b2dcf330b2dc),
+    U64(0xec52860dec52860d), U64(0xd0e3c177d0e3c177),
+    U64(0x6c16b32b6c16b32b), U64(0x99b970a999b970a9),
+    U64(0xfa489411fa489411), U64(0x2264e9472264e947),
+    U64(0xc48cfca8c48cfca8), U64(0x1a3ff0a01a3ff0a0),
+    U64(0xd82c7d56d82c7d56), U64(0xef903322ef903322),
+    U64(0xc74e4987c74e4987), U64(0xc1d138d9c1d138d9),
+    U64(0xfea2ca8cfea2ca8c), U64(0x360bd498360bd498),
+    U64(0xcf81f5a6cf81f5a6), U64(0x28de7aa528de7aa5),
+    U64(0x268eb7da268eb7da), U64(0xa4bfad3fa4bfad3f),
+    U64(0xe49d3a2ce49d3a2c), U64(0x0d9278500d927850),
+    U64(0x9bcc5f6a9bcc5f6a), U64(0x62467e5462467e54),
+    U64(0xc2138df6c2138df6), U64(0xe8b8d890e8b8d890),
+    U64(0x5ef7392e5ef7392e), U64(0xf5afc382f5afc382),
+    U64(0xbe805d9fbe805d9f), U64(0x7c93d0697c93d069),
+    U64(0xa92dd56fa92dd56f), U64(0xb31225cfb31225cf),
+    U64(0x3b99acc83b99acc8), U64(0xa77d1810a77d1810),
+    U64(0x6e639ce86e639ce8), U64(0x7bbb3bdb7bbb3bdb),
+    U64(0x097826cd097826cd), U64(0xf418596ef418596e),
+    U64(0x01b79aec01b79aec), U64(0xa89a4f83a89a4f83),
+    U64(0x656e95e6656e95e6), U64(0x7ee6ffaa7ee6ffaa),
+    U64(0x08cfbc2108cfbc21), U64(0xe6e815efe6e815ef),
+    U64(0xd99be7bad99be7ba), U64(0xce366f4ace366f4a),
+    U64(0xd4099fead4099fea), U64(0xd67cb029d67cb029),
+    U64(0xafb2a431afb2a431), U64(0x31233f2a31233f2a),
+    U64(0x3094a5c63094a5c6), U64(0xc066a235c066a235),
+    U64(0x37bc4e7437bc4e74), U64(0xa6ca82fca6ca82fc),
+    U64(0xb0d090e0b0d090e0), U64(0x15d8a73315d8a733),
+    U64(0x4a9804f14a9804f1), U64(0xf7daec41f7daec41),
+    U64(0x0e50cd7f0e50cd7f), U64(0x2ff691172ff69117),
+    U64(0x8dd64d768dd64d76), U64(0x4db0ef434db0ef43),
+    U64(0x544daacc544daacc), U64(0xdf0496e4df0496e4),
+    U64(0xe3b5d19ee3b5d19e), U64(0x1b886a4c1b886a4c),
+    U64(0xb81f2cc1b81f2cc1), U64(0x7f5165467f516546),
+    U64(0x04ea5e9d04ea5e9d), U64(0x5d358c015d358c01),
+    U64(0x737487fa737487fa), U64(0x2e410bfb2e410bfb),
+    U64(0x5a1d67b35a1d67b3), U64(0x52d2db9252d2db92),
+    U64(0x335610e9335610e9), U64(0x1347d66d1347d66d),
+    U64(0x8c61d79a8c61d79a), U64(0x7a0ca1377a0ca137),
+    U64(0x8e14f8598e14f859), U64(0x893c13eb893c13eb),
+    U64(0xee27a9ceee27a9ce), U64(0x35c961b735c961b7),
+    U64(0xede51ce1ede51ce1), U64(0x3cb1477a3cb1477a),
+    U64(0x59dfd29c59dfd29c), U64(0x3f73f2553f73f255),
+    U64(0x79ce141879ce1418), U64(0xbf37c773bf37c773),
+    U64(0xeacdf753eacdf753), U64(0x5baafd5f5baafd5f),
+    U64(0x146f3ddf146f3ddf), U64(0x86db447886db4478),
+    U64(0x81f3afca81f3afca), U64(0x3ec468b93ec468b9),
+    U64(0x2c3424382c342438), U64(0x5f40a3c25f40a3c2),
+    U64(0x72c31d1672c31d16), U64(0x0c25e2bc0c25e2bc),
+    U64(0x8b493c288b493c28), U64(0x41950dff41950dff),
+    U64(0x7101a8397101a839), U64(0xdeb30c08deb30c08),
+    U64(0x9ce4b4d89ce4b4d8), U64(0x90c1566490c15664),
+    U64(0x6184cb7b6184cb7b), U64(0x70b632d570b632d5),
+    U64(0x745c6c48745c6c48), U64(0x4257b8d04257b8d0)
+};
+static const u8 Td4[256] = {
+    0x52U, 0x09U, 0x6aU, 0xd5U, 0x30U, 0x36U, 0xa5U, 0x38U,
+    0xbfU, 0x40U, 0xa3U, 0x9eU, 0x81U, 0xf3U, 0xd7U, 0xfbU,
+    0x7cU, 0xe3U, 0x39U, 0x82U, 0x9bU, 0x2fU, 0xffU, 0x87U,
+    0x34U, 0x8eU, 0x43U, 0x44U, 0xc4U, 0xdeU, 0xe9U, 0xcbU,
+    0x54U, 0x7bU, 0x94U, 0x32U, 0xa6U, 0xc2U, 0x23U, 0x3dU,
+    0xeeU, 0x4cU, 0x95U, 0x0bU, 0x42U, 0xfaU, 0xc3U, 0x4eU,
+    0x08U, 0x2eU, 0xa1U, 0x66U, 0x28U, 0xd9U, 0x24U, 0xb2U,
+    0x76U, 0x5bU, 0xa2U, 0x49U, 0x6dU, 0x8bU, 0xd1U, 0x25U,
+    0x72U, 0xf8U, 0xf6U, 0x64U, 0x86U, 0x68U, 0x98U, 0x16U,
+    0xd4U, 0xa4U, 0x5cU, 0xccU, 0x5dU, 0x65U, 0xb6U, 0x92U,
+    0x6cU, 0x70U, 0x48U, 0x50U, 0xfdU, 0xedU, 0xb9U, 0xdaU,
+    0x5eU, 0x15U, 0x46U, 0x57U, 0xa7U, 0x8dU, 0x9dU, 0x84U,
+    0x90U, 0xd8U, 0xabU, 0x00U, 0x8cU, 0xbcU, 0xd3U, 0x0aU,
+    0xf7U, 0xe4U, 0x58U, 0x05U, 0xb8U, 0xb3U, 0x45U, 0x06U,
+    0xd0U, 0x2cU, 0x1eU, 0x8fU, 0xcaU, 0x3fU, 0x0fU, 0x02U,
+    0xc1U, 0xafU, 0xbdU, 0x03U, 0x01U, 0x13U, 0x8aU, 0x6bU,
+    0x3aU, 0x91U, 0x11U, 0x41U, 0x4fU, 0x67U, 0xdcU, 0xeaU,
+    0x97U, 0xf2U, 0xcfU, 0xceU, 0xf0U, 0xb4U, 0xe6U, 0x73U,
+    0x96U, 0xacU, 0x74U, 0x22U, 0xe7U, 0xadU, 0x35U, 0x85U,
+    0xe2U, 0xf9U, 0x37U, 0xe8U, 0x1cU, 0x75U, 0xdfU, 0x6eU,
+    0x47U, 0xf1U, 0x1aU, 0x71U, 0x1dU, 0x29U, 0xc5U, 0x89U,
+    0x6fU, 0xb7U, 0x62U, 0x0eU, 0xaaU, 0x18U, 0xbeU, 0x1bU,
+    0xfcU, 0x56U, 0x3eU, 0x4bU, 0xc6U, 0xd2U, 0x79U, 0x20U,
+    0x9aU, 0xdbU, 0xc0U, 0xfeU, 0x78U, 0xcdU, 0x5aU, 0xf4U,
+    0x1fU, 0xddU, 0xa8U, 0x33U, 0x88U, 0x07U, 0xc7U, 0x31U,
+    0xb1U, 0x12U, 0x10U, 0x59U, 0x27U, 0x80U, 0xecU, 0x5fU,
+    0x60U, 0x51U, 0x7fU, 0xa9U, 0x19U, 0xb5U, 0x4aU, 0x0dU,
+    0x2dU, 0xe5U, 0x7aU, 0x9fU, 0x93U, 0xc9U, 0x9cU, 0xefU,
+    0xa0U, 0xe0U, 0x3bU, 0x4dU, 0xaeU, 0x2aU, 0xf5U, 0xb0U,
+    0xc8U, 0xebU, 0xbbU, 0x3cU, 0x83U, 0x53U, 0x99U, 0x61U,
+    0x17U, 0x2bU, 0x04U, 0x7eU, 0xbaU, 0x77U, 0xd6U, 0x26U,
+    0xe1U, 0x69U, 0x14U, 0x63U, 0x55U, 0x21U, 0x0cU, 0x7dU
+};
+
+static const u32 rcon[] = {
+    0x00000001U,
+    0x00000002U,
+    0x00000004U,
+    0x00000008U,
+    0x00000010U,
+    0x00000020U,
+    0x00000040U,
+    0x00000080U,
+    0x0000001bU,
+    0x00000036U, /* for 128-bit blocks, Rijndael never uses more than 10 rcon values */
+};
+
+/**
+ * Expand the cipher key into the encryption key schedule.
+ */
+int AES_set_encrypt_key(const unsigned char *userKey, const int bits,
+    AES_KEY *key)
+{
+
+    u32 *rk;
+    int i = 0;
+    u32 temp;
+
+    if (!userKey || !key)
+        return -1;
+    if (bits != 128 && bits != 192 && bits != 256)
+        return -2;
+
+    rk = key->rd_key;
+
+    if (bits == 128)
+        key->rounds = 10;
+    else if (bits == 192)
+        key->rounds = 12;
+    else
+        key->rounds = 14;
+
+    rk[0] = GETU32(userKey);
+    rk[1] = GETU32(userKey + 4);
+    rk[2] = GETU32(userKey + 8);
+    rk[3] = GETU32(userKey + 12);
+    if (bits == 128) {
+        while (1) {
+            temp = rk[3];
+            rk[4] = rk[0] ^ ((u32)Te4[(temp >> 8) & 0xff]) ^ ((u32)Te4[(temp >> 16) & 0xff] << 8) ^ ((u32)Te4[(temp >> 24)] << 16) ^ ((u32)Te4[(temp) & 0xff] << 24) ^ rcon[i];
+            rk[5] = rk[1] ^ rk[4];
+            rk[6] = rk[2] ^ rk[5];
+            rk[7] = rk[3] ^ rk[6];
+            if (++i == 10) {
+                return 0;
+            }
+            rk += 4;
+        }
+    }
+    rk[4] = GETU32(userKey + 16);
+    rk[5] = GETU32(userKey + 20);
+    if (bits == 192) {
+        while (1) {
+            temp = rk[5];
+            rk[6] = rk[0] ^ ((u32)Te4[(temp >> 8) & 0xff]) ^ ((u32)Te4[(temp >> 16) & 0xff] << 8) ^ ((u32)Te4[(temp >> 24)] << 16) ^ ((u32)Te4[(temp) & 0xff] << 24) ^ rcon[i];
+            rk[7] = rk[1] ^ rk[6];
+            rk[8] = rk[2] ^ rk[7];
+            rk[9] = rk[3] ^ rk[8];
+            if (++i == 8) {
+                return 0;
+            }
+            rk[10] = rk[4] ^ rk[9];
+            rk[11] = rk[5] ^ rk[10];
+            rk += 6;
+        }
+    }
+    rk[6] = GETU32(userKey + 24);
+    rk[7] = GETU32(userKey + 28);
+    if (bits == 256) {
+        while (1) {
+            temp = rk[7];
+            rk[8] = rk[0] ^ ((u32)Te4[(temp >> 8) & 0xff]) ^ ((u32)Te4[(temp >> 16) & 0xff] << 8) ^ ((u32)Te4[(temp >> 24)] << 16) ^ ((u32)Te4[(temp) & 0xff] << 24) ^ rcon[i];
+            rk[9] = rk[1] ^ rk[8];
+            rk[10] = rk[2] ^ rk[9];
+            rk[11] = rk[3] ^ rk[10];
+            if (++i == 7) {
+                return 0;
+            }
+            temp = rk[11];
+            rk[12] = rk[4] ^ ((u32)Te4[(temp) & 0xff]) ^ ((u32)Te4[(temp >> 8) & 0xff] << 8) ^ ((u32)Te4[(temp >> 16) & 0xff] << 16) ^ ((u32)Te4[(temp >> 24)] << 24);
+            rk[13] = rk[5] ^ rk[12];
+            rk[14] = rk[6] ^ rk[13];
+            rk[15] = rk[7] ^ rk[14];
+
+            rk += 8;
+        }
+    }
+    return 0;
+}
+
+/**
+ * Expand the cipher key into the decryption key schedule.
+ */
+int AES_set_decrypt_key(const unsigned char *userKey, const int bits,
+    AES_KEY *key)
+{
+
+    u32 *rk;
+    int i, j, status;
+    u32 temp;
+
+    /* first, start with an encryption schedule */
+    status = AES_set_encrypt_key(userKey, bits, key);
+    if (status < 0)
+        return status;
+
+    rk = key->rd_key;
+
+    /* invert the order of the round keys: */
+    for (i = 0, j = 4 * (key->rounds); i < j; i += 4, j -= 4) {
+        temp = rk[i];
+        rk[i] = rk[j];
+        rk[j] = temp;
+        temp = rk[i + 1];
+        rk[i + 1] = rk[j + 1];
+        rk[j + 1] = temp;
+        temp = rk[i + 2];
+        rk[i + 2] = rk[j + 2];
+        rk[j + 2] = temp;
+        temp = rk[i + 3];
+        rk[i + 3] = rk[j + 3];
+        rk[j + 3] = temp;
+    }
+    /* apply the inverse MixColumn transform to all round keys but the first and the last: */
+    for (i = 1; i < (key->rounds); i++) {
+        rk += 4;
+#if 1
+        for (j = 0; j < 4; j++) {
+            u32 tp1, tp2, tp4, tp8, tp9, tpb, tpd, tpe, m;
+
+            tp1 = rk[j];
+            m = tp1 & 0x80808080;
+            tp2 = ((tp1 & 0x7f7f7f7f) << 1) ^ ((m - (m >> 7)) & 0x1b1b1b1b);
+            m = tp2 & 0x80808080;
+            tp4 = ((tp2 & 0x7f7f7f7f) << 1) ^ ((m - (m >> 7)) & 0x1b1b1b1b);
+            m = tp4 & 0x80808080;
+            tp8 = ((tp4 & 0x7f7f7f7f) << 1) ^ ((m - (m >> 7)) & 0x1b1b1b1b);
+            tp9 = tp8 ^ tp1;
+            tpb = tp9 ^ tp2;
+            tpd = tp9 ^ tp4;
+            tpe = tp8 ^ tp4 ^ tp2;
+#if defined(ROTATE)
+            rk[j] = tpe ^ ROTATE(tpd, 16) ^ ROTATE(tp9, 8) ^ ROTATE(tpb, 24);
+#else
+            rk[j] = tpe ^ (tpd >> 16) ^ (tpd << 16) ^ (tp9 >> 24) ^ (tp9 << 8) ^ (tpb >> 8) ^ (tpb << 24);
+#endif
+        }
+#else
+        rk[0] = Td0[Te2[(rk[0]) & 0xff] & 0xff] ^ Td1[Te2[(rk[0] >> 8) & 0xff] & 0xff] ^ Td2[Te2[(rk[0] >> 16) & 0xff] & 0xff] ^ Td3[Te2[(rk[0] >> 24)] & 0xff];
+        rk[1] = Td0[Te2[(rk[1]) & 0xff] & 0xff] ^ Td1[Te2[(rk[1] >> 8) & 0xff] & 0xff] ^ Td2[Te2[(rk[1] >> 16) & 0xff] & 0xff] ^ Td3[Te2[(rk[1] >> 24)] & 0xff];
+        rk[2] = Td0[Te2[(rk[2]) & 0xff] & 0xff] ^ Td1[Te2[(rk[2] >> 8) & 0xff] & 0xff] ^ Td2[Te2[(rk[2] >> 16) & 0xff] & 0xff] ^ Td3[Te2[(rk[2] >> 24)] & 0xff];
+        rk[3] = Td0[Te2[(rk[3]) & 0xff] & 0xff] ^ Td1[Te2[(rk[3] >> 8) & 0xff] & 0xff] ^ Td2[Te2[(rk[3] >> 16) & 0xff] & 0xff] ^ Td3[Te2[(rk[3] >> 24)] & 0xff];
+#endif
+    }
+    return 0;
+}
+
+/*
+ * Encrypt a single block
+ * in and out can overlap
+ */
+void AES_encrypt(const unsigned char *in, unsigned char *out,
+    const AES_KEY *key)
+{
+
+    const u32 *rk;
+    u32 s0, s1, s2, s3, t[4];
+    int r;
+
+    assert(in && out && key);
+    rk = key->rd_key;
+
+    /*
+     * map byte array block to cipher state
+     * and add initial round key:
+     */
+    s0 = GETU32(in) ^ rk[0];
+    s1 = GETU32(in + 4) ^ rk[1];
+    s2 = GETU32(in + 8) ^ rk[2];
+    s3 = GETU32(in + 12) ^ rk[3];
+
+#if defined(AES_COMPACT_IN_OUTER_ROUNDS)
+    prefetch256(Te4);
+
+    t[0] = (u32)Te4[(s0) & 0xff] ^ (u32)Te4[(s1 >> 8) & 0xff] << 8 ^ (u32)Te4[(s2 >> 16) & 0xff] << 16 ^ (u32)Te4[(s3 >> 24)] << 24;
+    t[1] = (u32)Te4[(s1) & 0xff] ^ (u32)Te4[(s2 >> 8) & 0xff] << 8 ^ (u32)Te4[(s3 >> 16) & 0xff] << 16 ^ (u32)Te4[(s0 >> 24)] << 24;
+    t[2] = (u32)Te4[(s2) & 0xff] ^ (u32)Te4[(s3 >> 8) & 0xff] << 8 ^ (u32)Te4[(s0 >> 16) & 0xff] << 16 ^ (u32)Te4[(s1 >> 24)] << 24;
+    t[3] = (u32)Te4[(s3) & 0xff] ^ (u32)Te4[(s0 >> 8) & 0xff] << 8 ^ (u32)Te4[(s1 >> 16) & 0xff] << 16 ^ (u32)Te4[(s2 >> 24)] << 24;
+
+    /* now do the linear transform using words */
+    {
+        int i;
+        u32 r0, r1, r2;
+
+        for (i = 0; i < 4; i++) {
+            r0 = t[i];
+            r1 = r0 & 0x80808080;
+            r2 = ((r0 & 0x7f7f7f7f) << 1) ^ ((r1 - (r1 >> 7)) & 0x1b1b1b1b);
+#if defined(ROTATE)
+            t[i] = r2 ^ ROTATE(r2, 24) ^ ROTATE(r0, 24) ^ ROTATE(r0, 16) ^ ROTATE(r0, 8);
+#else
+            t[i] = r2 ^ ((r2 ^ r0) << 24) ^ ((r2 ^ r0) >> 8) ^ (r0 << 16) ^ (r0 >> 16) ^ (r0 << 8) ^ (r0 >> 24);
+#endif
+            t[i] ^= rk[4 + i];
+        }
+    }
+#else
+    t[0] = Te0[(s0) & 0xff] ^ Te1[(s1 >> 8) & 0xff] ^ Te2[(s2 >> 16) & 0xff] ^ Te3[(s3 >> 24)] ^ rk[4];
+    t[1] = Te0[(s1) & 0xff] ^ Te1[(s2 >> 8) & 0xff] ^ Te2[(s3 >> 16) & 0xff] ^ Te3[(s0 >> 24)] ^ rk[5];
+    t[2] = Te0[(s2) & 0xff] ^ Te1[(s3 >> 8) & 0xff] ^ Te2[(s0 >> 16) & 0xff] ^ Te3[(s1 >> 24)] ^ rk[6];
+    t[3] = Te0[(s3) & 0xff] ^ Te1[(s0 >> 8) & 0xff] ^ Te2[(s1 >> 16) & 0xff] ^ Te3[(s2 >> 24)] ^ rk[7];
+#endif
+    s0 = t[0];
+    s1 = t[1];
+    s2 = t[2];
+    s3 = t[3];
+
+    /*
+     * Nr - 2 full rounds:
+     */
+    for (rk += 8, r = key->rounds - 2; r > 0; rk += 4, r--) {
+#if defined(AES_COMPACT_IN_INNER_ROUNDS)
+        t[0] = (u32)Te4[(s0) & 0xff] ^ (u32)Te4[(s1 >> 8) & 0xff] << 8 ^ (u32)Te4[(s2 >> 16) & 0xff] << 16 ^ (u32)Te4[(s3 >> 24)] << 24;
+        t[1] = (u32)Te4[(s1) & 0xff] ^ (u32)Te4[(s2 >> 8) & 0xff] << 8 ^ (u32)Te4[(s3 >> 16) & 0xff] << 16 ^ (u32)Te4[(s0 >> 24)] << 24;
+        t[2] = (u32)Te4[(s2) & 0xff] ^ (u32)Te4[(s3 >> 8) & 0xff] << 8 ^ (u32)Te4[(s0 >> 16) & 0xff] << 16 ^ (u32)Te4[(s1 >> 24)] << 24;
+        t[3] = (u32)Te4[(s3) & 0xff] ^ (u32)Te4[(s0 >> 8) & 0xff] << 8 ^ (u32)Te4[(s1 >> 16) & 0xff] << 16 ^ (u32)Te4[(s2 >> 24)] << 24;
+
+        /* now do the linear transform using words */
+        {
+            int i;
+            u32 r0, r1, r2;
+
+            for (i = 0; i < 4; i++) {
+                r0 = t[i];
+                r1 = r0 & 0x80808080;
+                r2 = ((r0 & 0x7f7f7f7f) << 1) ^ ((r1 - (r1 >> 7)) & 0x1b1b1b1b);
+#if defined(ROTATE)
+                t[i] = r2 ^ ROTATE(r2, 24) ^ ROTATE(r0, 24) ^ ROTATE(r0, 16) ^ ROTATE(r0, 8);
+#else
+                t[i] = r2 ^ ((r2 ^ r0) << 24) ^ ((r2 ^ r0) >> 8) ^ (r0 << 16) ^ (r0 >> 16) ^ (r0 << 8) ^ (r0 >> 24);
+#endif
+                t[i] ^= rk[i];
+            }
+        }
+#else
+        t[0] = Te0[(s0) & 0xff] ^ Te1[(s1 >> 8) & 0xff] ^ Te2[(s2 >> 16) & 0xff] ^ Te3[(s3 >> 24)] ^ rk[0];
+        t[1] = Te0[(s1) & 0xff] ^ Te1[(s2 >> 8) & 0xff] ^ Te2[(s3 >> 16) & 0xff] ^ Te3[(s0 >> 24)] ^ rk[1];
+        t[2] = Te0[(s2) & 0xff] ^ Te1[(s3 >> 8) & 0xff] ^ Te2[(s0 >> 16) & 0xff] ^ Te3[(s1 >> 24)] ^ rk[2];
+        t[3] = Te0[(s3) & 0xff] ^ Te1[(s0 >> 8) & 0xff] ^ Te2[(s1 >> 16) & 0xff] ^ Te3[(s2 >> 24)] ^ rk[3];
+#endif
+        s0 = t[0];
+        s1 = t[1];
+        s2 = t[2];
+        s3 = t[3];
+    }
+    /*
+     * apply last round and
+     * map cipher state to byte array block:
+     */
+#if defined(AES_COMPACT_IN_OUTER_ROUNDS)
+    prefetch256(Te4);
+
+    *(u32 *)(out + 0) = (u32)Te4[(s0) & 0xff] ^ (u32)Te4[(s1 >> 8) & 0xff] << 8 ^ (u32)Te4[(s2 >> 16) & 0xff] << 16 ^ (u32)Te4[(s3 >> 24)] << 24 ^ rk[0];
+    *(u32 *)(out + 4) = (u32)Te4[(s1) & 0xff] ^ (u32)Te4[(s2 >> 8) & 0xff] << 8 ^ (u32)Te4[(s3 >> 16) & 0xff] << 16 ^ (u32)Te4[(s0 >> 24)] << 24 ^ rk[1];
+    *(u32 *)(out + 8) = (u32)Te4[(s2) & 0xff] ^ (u32)Te4[(s3 >> 8) & 0xff] << 8 ^ (u32)Te4[(s0 >> 16) & 0xff] << 16 ^ (u32)Te4[(s1 >> 24)] << 24 ^ rk[2];
+    *(u32 *)(out + 12) = (u32)Te4[(s3) & 0xff] ^ (u32)Te4[(s0 >> 8) & 0xff] << 8 ^ (u32)Te4[(s1 >> 16) & 0xff] << 16 ^ (u32)Te4[(s2 >> 24)] << 24 ^ rk[3];
+#else
+    *(u32 *)(out + 0) = (Te2[(s0) & 0xff] & 0x000000ffU) ^ (Te3[(s1 >> 8) & 0xff] & 0x0000ff00U) ^ (Te0[(s2 >> 16) & 0xff] & 0x00ff0000U) ^ (Te1[(s3 >> 24)] & 0xff000000U) ^ rk[0];
+    *(u32 *)(out + 4) = (Te2[(s1) & 0xff] & 0x000000ffU) ^ (Te3[(s2 >> 8) & 0xff] & 0x0000ff00U) ^ (Te0[(s3 >> 16) & 0xff] & 0x00ff0000U) ^ (Te1[(s0 >> 24)] & 0xff000000U) ^ rk[1];
+    *(u32 *)(out + 8) = (Te2[(s2) & 0xff] & 0x000000ffU) ^ (Te3[(s3 >> 8) & 0xff] & 0x0000ff00U) ^ (Te0[(s0 >> 16) & 0xff] & 0x00ff0000U) ^ (Te1[(s1 >> 24)] & 0xff000000U) ^ rk[2];
+    *(u32 *)(out + 12) = (Te2[(s3) & 0xff] & 0x000000ffU) ^ (Te3[(s0 >> 8) & 0xff] & 0x0000ff00U) ^ (Te0[(s1 >> 16) & 0xff] & 0x00ff0000U) ^ (Te1[(s2 >> 24)] & 0xff000000U) ^ rk[3];
+#endif
+}
+
+/*
+ * Decrypt a single block
+ * in and out can overlap
+ */
+void AES_decrypt(const unsigned char *in, unsigned char *out,
+    const AES_KEY *key)
+{
+
+    const u32 *rk;
+    u32 s0, s1, s2, s3, t[4];
+    int r;
+
+    assert(in && out && key);
+    rk = key->rd_key;
+
+    /*
+     * map byte array block to cipher state
+     * and add initial round key:
+     */
+    s0 = GETU32(in) ^ rk[0];
+    s1 = GETU32(in + 4) ^ rk[1];
+    s2 = GETU32(in + 8) ^ rk[2];
+    s3 = GETU32(in + 12) ^ rk[3];
+
+#if defined(AES_COMPACT_IN_OUTER_ROUNDS)
+    prefetch256(Td4);
+
+    t[0] = (u32)Td4[(s0) & 0xff] ^ (u32)Td4[(s3 >> 8) & 0xff] << 8 ^ (u32)Td4[(s2 >> 16) & 0xff] << 16 ^ (u32)Td4[(s1 >> 24)] << 24;
+    t[1] = (u32)Td4[(s1) & 0xff] ^ (u32)Td4[(s0 >> 8) & 0xff] << 8 ^ (u32)Td4[(s3 >> 16) & 0xff] << 16 ^ (u32)Td4[(s2 >> 24)] << 24;
+    t[2] = (u32)Td4[(s2) & 0xff] ^ (u32)Td4[(s1 >> 8) & 0xff] << 8 ^ (u32)Td4[(s0 >> 16) & 0xff] << 16 ^ (u32)Td4[(s3 >> 24)] << 24;
+    t[3] = (u32)Td4[(s3) & 0xff] ^ (u32)Td4[(s2 >> 8) & 0xff] << 8 ^ (u32)Td4[(s1 >> 16) & 0xff] << 16 ^ (u32)Td4[(s0 >> 24)] << 24;
+
+    /* now do the linear transform using words */
+    {
+        int i;
+        u32 tp1, tp2, tp4, tp8, tp9, tpb, tpd, tpe, m;
+
+        for (i = 0; i < 4; i++) {
+            tp1 = t[i];
+            m = tp1 & 0x80808080;
+            tp2 = ((tp1 & 0x7f7f7f7f) << 1) ^ ((m - (m >> 7)) & 0x1b1b1b1b);
+            m = tp2 & 0x80808080;
+            tp4 = ((tp2 & 0x7f7f7f7f) << 1) ^ ((m - (m >> 7)) & 0x1b1b1b1b);
+            m = tp4 & 0x80808080;
+            tp8 = ((tp4 & 0x7f7f7f7f) << 1) ^ ((m - (m >> 7)) & 0x1b1b1b1b);
+            tp9 = tp8 ^ tp1;
+            tpb = tp9 ^ tp2;
+            tpd = tp9 ^ tp4;
+            tpe = tp8 ^ tp4 ^ tp2;
+#if defined(ROTATE)
+            t[i] = tpe ^ ROTATE(tpd, 16) ^ ROTATE(tp9, 8) ^ ROTATE(tpb, 24);
+#else
+            t[i] = tpe ^ (tpd >> 16) ^ (tpd << 16) ^ (tp9 >> 24) ^ (tp9 << 8) ^ (tpb >> 8) ^ (tpb << 24);
+#endif
+            t[i] ^= rk[4 + i];
+        }
+    }
+#else
+    t[0] = Td0[(s0) & 0xff] ^ Td1[(s3 >> 8) & 0xff] ^ Td2[(s2 >> 16) & 0xff] ^ Td3[(s1 >> 24)] ^ rk[4];
+    t[1] = Td0[(s1) & 0xff] ^ Td1[(s0 >> 8) & 0xff] ^ Td2[(s3 >> 16) & 0xff] ^ Td3[(s2 >> 24)] ^ rk[5];
+    t[2] = Td0[(s2) & 0xff] ^ Td1[(s1 >> 8) & 0xff] ^ Td2[(s0 >> 16) & 0xff] ^ Td3[(s3 >> 24)] ^ rk[6];
+    t[3] = Td0[(s3) & 0xff] ^ Td1[(s2 >> 8) & 0xff] ^ Td2[(s1 >> 16) & 0xff] ^ Td3[(s0 >> 24)] ^ rk[7];
+#endif
+    s0 = t[0];
+    s1 = t[1];
+    s2 = t[2];
+    s3 = t[3];
+
+    /*
+     * Nr - 2 full rounds:
+     */
+    for (rk += 8, r = key->rounds - 2; r > 0; rk += 4, r--) {
+#if defined(AES_COMPACT_IN_INNER_ROUNDS)
+        t[0] = (u32)Td4[(s0) & 0xff] ^ (u32)Td4[(s3 >> 8) & 0xff] << 8 ^ (u32)Td4[(s2 >> 16) & 0xff] << 16 ^ (u32)Td4[(s1 >> 24)] << 24;
+        t[1] = (u32)Td4[(s1) & 0xff] ^ (u32)Td4[(s0 >> 8) & 0xff] << 8 ^ (u32)Td4[(s3 >> 16) & 0xff] << 16 ^ (u32)Td4[(s2 >> 24)] << 24;
+        t[2] = (u32)Td4[(s2) & 0xff] ^ (u32)Td4[(s1 >> 8) & 0xff] << 8 ^ (u32)Td4[(s0 >> 16) & 0xff] << 16 ^ (u32)Td4[(s3 >> 24)] << 24;
+        t[3] = (u32)Td4[(s3) & 0xff] ^ (u32)Td4[(s2 >> 8) & 0xff] << 8 ^ (u32)Td4[(s1 >> 16) & 0xff] << 16 ^ (u32)Td4[(s0 >> 24)] << 24;
+
+        /* now do the linear transform using words */
+        {
+            int i;
+            u32 tp1, tp2, tp4, tp8, tp9, tpb, tpd, tpe, m;
+
+            for (i = 0; i < 4; i++) {
+                tp1 = t[i];
+                m = tp1 & 0x80808080;
+                tp2 = ((tp1 & 0x7f7f7f7f) << 1) ^ ((m - (m >> 7)) & 0x1b1b1b1b);
+                m = tp2 & 0x80808080;
+                tp4 = ((tp2 & 0x7f7f7f7f) << 1) ^ ((m - (m >> 7)) & 0x1b1b1b1b);
+                m = tp4 & 0x80808080;
+                tp8 = ((tp4 & 0x7f7f7f7f) << 1) ^ ((m - (m >> 7)) & 0x1b1b1b1b);
+                tp9 = tp8 ^ tp1;
+                tpb = tp9 ^ tp2;
+                tpd = tp9 ^ tp4;
+                tpe = tp8 ^ tp4 ^ tp2;
+#if defined(ROTATE)
+                t[i] = tpe ^ ROTATE(tpd, 16) ^ ROTATE(tp9, 8) ^ ROTATE(tpb, 24);
+#else
+                t[i] = tpe ^ (tpd >> 16) ^ (tpd << 16) ^ (tp9 >> 24) ^ (tp9 << 8) ^ (tpb >> 8) ^ (tpb << 24);
+#endif
+                t[i] ^= rk[i];
+            }
+        }
+#else
+        t[0] = Td0[(s0) & 0xff] ^ Td1[(s3 >> 8) & 0xff] ^ Td2[(s2 >> 16) & 0xff] ^ Td3[(s1 >> 24)] ^ rk[0];
+        t[1] = Td0[(s1) & 0xff] ^ Td1[(s0 >> 8) & 0xff] ^ Td2[(s3 >> 16) & 0xff] ^ Td3[(s2 >> 24)] ^ rk[1];
+        t[2] = Td0[(s2) & 0xff] ^ Td1[(s1 >> 8) & 0xff] ^ Td2[(s0 >> 16) & 0xff] ^ Td3[(s3 >> 24)] ^ rk[2];
+        t[3] = Td0[(s3) & 0xff] ^ Td1[(s2 >> 8) & 0xff] ^ Td2[(s1 >> 16) & 0xff] ^ Td3[(s0 >> 24)] ^ rk[3];
+#endif
+        s0 = t[0];
+        s1 = t[1];
+        s2 = t[2];
+        s3 = t[3];
+    }
+    /*
+     * apply last round and
+     * map cipher state to byte array block:
+     */
+    prefetch256(Td4);
+
+    *(u32 *)(out + 0) = ((u32)Td4[(s0) & 0xff]) ^ ((u32)Td4[(s3 >> 8) & 0xff] << 8) ^ ((u32)Td4[(s2 >> 16) & 0xff] << 16) ^ ((u32)Td4[(s1 >> 24)] << 24) ^ rk[0];
+    *(u32 *)(out + 4) = ((u32)Td4[(s1) & 0xff]) ^ ((u32)Td4[(s0 >> 8) & 0xff] << 8) ^ ((u32)Td4[(s3 >> 16) & 0xff] << 16) ^ ((u32)Td4[(s2 >> 24)] << 24) ^ rk[1];
+    *(u32 *)(out + 8) = ((u32)Td4[(s2) & 0xff]) ^ ((u32)Td4[(s1 >> 8) & 0xff] << 8) ^ ((u32)Td4[(s0 >> 16) & 0xff] << 16) ^ ((u32)Td4[(s3 >> 24)] << 24) ^ rk[2];
+    *(u32 *)(out + 12) = ((u32)Td4[(s3) & 0xff]) ^ ((u32)Td4[(s2 >> 8) & 0xff] << 8) ^ ((u32)Td4[(s1 >> 16) & 0xff] << 16) ^ ((u32)Td4[(s0 >> 24)] << 24) ^ rk[3];
+}
diff --git a/crypto/aes/asm/aes-586.pl b/crypto/aes/asm/aes-586.pl
index 6f2bad2a81..541f7f8d11 100755
--- a/crypto/aes/asm/aes-586.pl
+++ b/crypto/aes/asm/aes-586.pl
@@ -1,5 +1,5 @@
 #! /usr/bin/env perl
-# Copyright 2004-2026 The OpenSSL Project Authors. All Rights Reserved.
+# Copyright 2004-2025 The OpenSSL Project Authors. All Rights Reserved.
 #
 # Licensed under the Apache License 2.0 (the "License").  You may not use
 # this file except in compliance with the License.  You can obtain a copy
@@ -2022,7 +2022,7 @@ sub declast()
 
 # void AES_cbc_encrypt (const void char *inp, unsigned char *out,
 #			size_t length, const AES_KEY *key,
-#			unsigned char *ivp, int enc);
+#			unsigned char *ivp,const int enc);
 {
 # stack frame layout
 #             -4(%esp)		# return address	 0(%esp)
@@ -2870,7 +2870,8 @@ sub enckey()
     &set_label("exit");
 &function_end("_x86_AES_set_encrypt_key");
 
-# int AES_set_encrypt_key(const unsigned char *userKey, int bits, AES_KEY *key)
+# int AES_set_encrypt_key(const unsigned char *userKey, const int bits,
+#                        AES_KEY *key)
 &function_begin_B("AES_set_encrypt_key");
 	&call	("_x86_AES_set_encrypt_key");
 	&ret	();
@@ -2931,7 +2932,8 @@ sub deckey()
 	&mov	(&DWP(4*$i,$key),$tp1);
 }
 
-# int AES_set_decrypt_key(const unsigned char *userKey, int bits, AES_KEY *key)
+# int AES_set_decrypt_key(const unsigned char *userKey, const int bits,
+#                        AES_KEY *key)
 &function_begin_B("AES_set_decrypt_key");
 	&call	("_x86_AES_set_encrypt_key");
 	&cmp	("eax",0);
diff --git a/crypto/aes/asm/aes-armv4.pl b/crypto/aes/asm/aes-armv4.pl
index 641e45144e..162eb5ce36 100644
--- a/crypto/aes/asm/aes-armv4.pl
+++ b/crypto/aes/asm/aes-armv4.pl
@@ -73,7 +73,7 @@ $rounds="r12";
 
 $code=<<___;
 #ifndef __KERNEL__
-# include "arch/arm_arch.h"
+# include "arm_arch.h"
 #else
 # define __ARM_ARCH__ __LINUX_ARM_ARCH__
 #endif
diff --git a/crypto/aes/asm/aes-cfb-avx512.pl b/crypto/aes/asm/aes-cfb-avx512.pl
index d9e1815ee6..8136f16e55 100644
--- a/crypto/aes/asm/aes-cfb-avx512.pl
+++ b/crypto/aes/asm/aes-cfb-avx512.pl
@@ -49,13 +49,6 @@ if (!$avx512vaes && `$ENV{CC} -v 2>&1`
     }
 }
 
-if (!$avx512vaes && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-    =~ /#define __clang_major__.([0-9]+)/) {
-    if ($1) {
-        $avx512vaes = ($1>=11); #icx started with clang 11
-    }
-}
-
 open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\""
     or die "can't call $xlate: $!";
 *STDOUT=*OUT;
@@ -506,8 +499,8 @@ $code.=<<___;
     and \$0x0F,%al                   # wrap-around $num in a 16-byte block
 
     leaq ($num,$ivp),%r11            # process $left iv bytes
-    vmovdqu8 (%r11),%xmm0{%k1}{z}
-    vmovdqu8 ($inp),%xmm1{%k1}{z}    # process $left input bytes
+    vmovdqu8 (%r11),%xmm0
+    vmovdqu8 ($inp),%xmm1            # process $left input bytes
     vpxor %xmm0,%xmm1,%xmm2          # CipherFeedBack XOR
     vmovdqu8 %xmm2,($out){%k1}       # write $left output bytes
     vmovdqu8 %xmm2,(%r11){%k1}       # blend $left output bytes into iv
@@ -760,8 +753,8 @@ $code.=<<___;
     and \$0x0F,%al                    # wrap-around in a 16-byte block
 
     leaq ($num,$ivp),%r11             # process $left iv bytes
-    vmovdqu8 (%r11),%xmm0{%k1}{z}
-    vmovdqu8 ($inp),%xmm1{%k1}{z}     # process $left input bytes
+    vmovdqu8 (%r11),%xmm0
+    vmovdqu8 ($inp),%xmm1             # process $left input bytes
     vpxor %xmm0,%xmm1,%xmm2           # CipherFeedBack XOR
     vmovdqu8 %xmm2,($out){%k1}        # write $left output bytes
     vmovdqu8 %xmm1,(%r11){%k1}        # blend $left input bytes into iv
diff --git a/crypto/aes/asm/aes-mips.pl b/crypto/aes/asm/aes-mips.pl
index 28ca4d028b..6a37c1ce3f 100644
--- a/crypto/aes/asm/aes-mips.pl
+++ b/crypto/aes/asm/aes-mips.pl
@@ -107,7 +107,7 @@ my ($MSB,$LSB)=(0,3);	# automatically converted to little-endian
 $output and open STDOUT,">$output";
 
 $code.=<<___;
-#include "arch/mips_arch.h"
+#include "mips_arch.h"
 
 .text
 #if !defined(__mips_eabi) && (!defined(__vxworks) || defined(__pic__))
diff --git a/crypto/aes/asm/aes-riscv32-zkn.pl b/crypto/aes/asm/aes-riscv32-zkn.pl
index b57e10c485..6fac451846 100644
--- a/crypto/aes/asm/aes-riscv32-zkn.pl
+++ b/crypto/aes/asm/aes-riscv32-zkn.pl
@@ -704,6 +704,11 @@ sub AES_set_common {
     my ($ke128, $ke192, $ke256) = @_;
     my $ret = '';
 $ret .= <<___;
+    bnez    $UKEY,1f        # if (!userKey || !key) return -1;
+    bnez    $KEYP,1f
+    li      a0,-1
+    ret
+1:
     # Determine number of rounds from key size in bits
     li      $T0,128
     bne     $BITS,$T0,1f
diff --git a/crypto/aes/asm/aes-riscv64-zkn.pl b/crypto/aes/asm/aes-riscv64-zkn.pl
index 34f71b2185..0e8a1540c4 100644
--- a/crypto/aes/asm/aes-riscv64-zkn.pl
+++ b/crypto/aes/asm/aes-riscv64-zkn.pl
@@ -392,6 +392,11 @@ sub AES_set_common {
     my ($ke128, $ke192, $ke256) = @_;
     my $ret = '';
 $ret .= <<___;
+    bnez    $UKEY,1f        # if (!userKey || !key) return -1;
+    bnez    $KEYP,1f
+    li      a0,-1
+    ret
+1:
     # Determine number of rounds from key size in bits
     li      $T0,128
     bne     $BITS,$T0,1f
diff --git a/crypto/aes/asm/aes-riscv64-zvbb-zvkg-zvkned.pl b/crypto/aes/asm/aes-riscv64-zvbb-zvkg-zvkned.pl
index 7365a36976..5fb2cc33f3 100644
--- a/crypto/aes/asm/aes-riscv64-zvbb-zvkg-zvkned.pl
+++ b/crypto/aes/asm/aes-riscv64-zvbb-zvkg-zvkned.pl
@@ -2,7 +2,7 @@
 # This file is dual-licensed, meaning that you can use it under your
 # choice of either of the following two licenses:
 #
-# Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved.
+# Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.
 #
 # Licensed under the Apache License 2.0 (the "License"). You can obtain
 # a copy in the file LICENSE in the source distribution or at
@@ -633,7 +633,7 @@ aes_xts_dec_128:
     @{[aes_128_dec]}
     @{[vxor_vv $V24, $V24, $V28]}
 
-    # store last block plaintext
+    # store second to last block plaintext
     @{[vse32_v $V24, $OUTPUT]}
 
     ret
@@ -697,7 +697,7 @@ aes_xts_dec_256:
     @{[aes_256_dec]}
     @{[vxor_vv $V24, $V24, $V28]}
 
-    # store last block plaintext
+    # store second to last block plaintext
     @{[vse32_v $V24, $OUTPUT]}
 
     ret
diff --git a/crypto/aes/asm/aes-riscv64-zvkned.pl b/crypto/aes/asm/aes-riscv64-zvkned.pl
index 45c2efde07..cac1d194cc 100644
--- a/crypto/aes/asm/aes-riscv64-zvkned.pl
+++ b/crypto/aes/asm/aes-riscv64-zvkned.pl
@@ -210,6 +210,88 @@ ___
     return $code;
 }
 
+# aes-128 decryption with round keys v1-v11
+sub aes_128_decrypt_6 {
+    my $code=<<___;
+    @{[vaesz_vs $V24, $V11]}   # with round key w[40,43]
+    @{[vaesz_vs $V25, $V11]}   # with round key w[40,43]
+    @{[vaesz_vs $V26, $V11]}   # with round key w[40,43]
+    @{[vaesz_vs $V27, $V11]}   # with round key w[40,43]
+    @{[vaesz_vs $V28, $V11]}   # with round key w[40,43]
+    @{[vaesz_vs $V29, $V11]}   # with round key w[40,43]
+    @{[vaesdm_vs $V24, $V10]}  # with round key w[36,39]
+    @{[vaesdm_vs $V25, $V10]}  # with round key w[36,39]
+    @{[vaesdm_vs $V26, $V10]}  # with round key w[36,39]
+    @{[vaesdm_vs $V27, $V10]}  # with round key w[36,39]
+    @{[vaesdm_vs $V28, $V10]}  # with round key w[36,39]
+    @{[vaesdm_vs $V29, $V10]}  # with round key w[36,39]
+    @{[vaesdm_vs $V24, $V9]}   # with round key w[32,35]
+    @{[vaesdm_vs $V25, $V9]}   # with round key w[32,35]
+    @{[vaesdm_vs $V26, $V9]}   # with round key w[32,35]
+    @{[vaesdm_vs $V27, $V9]}   # with round key w[32,35]
+    @{[vaesdm_vs $V28, $V9]}   # with round key w[32,35]
+    @{[vaesdm_vs $V29, $V9]}   # with round key w[32,35]
+
+    @{[vaesdm_vs $V24, $V8]}   # with round key w[28,31]
+    @{[vaesdm_vs $V25, $V8]}   # with round key w[28,31]
+    @{[vaesdm_vs $V26, $V8]}   # with round key w[28,31]
+    @{[vaesdm_vs $V27, $V8]}   # with round key w[28,31]
+    @{[vaesdm_vs $V28, $V8]}   # with round key w[28,31]
+    @{[vaesdm_vs $V29, $V8]}   # with round key w[28,31]
+
+    @{[vaesdm_vs $V24, $V7]}   # with round key w[24,27]
+    @{[vaesdm_vs $V25, $V7]}   # with round key w[24,27]
+    @{[vaesdm_vs $V26, $V7]}   # with round key w[24,27]
+    @{[vaesdm_vs $V27, $V7]}   # with round key w[24,27]
+    @{[vaesdm_vs $V28, $V7]}   # with round key w[24,27]
+    @{[vaesdm_vs $V29, $V7]}   # with round key w[24,27]
+
+    @{[vaesdm_vs $V24, $V6]}   # with round key w[20,23]
+    @{[vaesdm_vs $V25, $V6]}   # with round key w[20,23]
+    @{[vaesdm_vs $V26, $V6]}   # with round key w[20,23]
+    @{[vaesdm_vs $V27, $V6]}   # with round key w[20,23]
+    @{[vaesdm_vs $V28, $V6]}   # with round key w[20,23]
+    @{[vaesdm_vs $V29, $V6]}   # with round key w[20,23]
+    
+    @{[vaesdm_vs $V24, $V5]}   # with round key w[16,19]
+    @{[vaesdm_vs $V25, $V5]}   # with round key w[16,19]
+    @{[vaesdm_vs $V26, $V5]}   # with round key w[16,19]
+    @{[vaesdm_vs $V27, $V5]}   # with round key w[16,19]
+    @{[vaesdm_vs $V28, $V5]}   # with round key w[16,19]
+    @{[vaesdm_vs $V29, $V5]}   # with round key w[16,19]
+
+    @{[vaesdm_vs $V24, $V4]}   # with round key w[12,15]
+    @{[vaesdm_vs $V25, $V4]}   # with round key w[12,15]
+    @{[vaesdm_vs $V26, $V4]}   # with round key w[12,15]
+    @{[vaesdm_vs $V27, $V4]}   # with round key w[12,15]
+    @{[vaesdm_vs $V28, $V4]}   # with round key w[12,15]
+    @{[vaesdm_vs $V29, $V4]}   # with round key w[12,15]
+
+    @{[vaesdm_vs $V24, $V3]}   # with round key w[ 8,11]
+    @{[vaesdm_vs $V25, $V3]}   # with round key w[ 8,11]
+    @{[vaesdm_vs $V26, $V3]}   # with round key w[ 8,11]
+    @{[vaesdm_vs $V27, $V3]}   # with round key w[ 8,11]
+    @{[vaesdm_vs $V28, $V3]}   # with round key w[ 8,11]
+    @{[vaesdm_vs $V29, $V3]}   # with round key w[ 8,11]
+
+    @{[vaesdm_vs $V24, $V2]}   # with round key w[ 4, 7]
+    @{[vaesdm_vs $V25, $V2]}   # with round key w[ 4, 7]
+    @{[vaesdm_vs $V26, $V2]}   # with round key w[ 4, 7]
+    @{[vaesdm_vs $V27, $V2]}   # with round key w[ 4, 7]
+    @{[vaesdm_vs $V28, $V2]}   # with round key w[ 4, 7]
+    @{[vaesdm_vs $V29, $V2]}   # with round key w[ 4, 7]
+
+    @{[vaesdf_vs $V24, $V1]}   # with round key w[ 0, 3]
+    @{[vaesdf_vs $V25, $V1]}   # with round key w[ 0, 3]
+    @{[vaesdf_vs $V26, $V1]}   # with round key w[ 0, 3]
+    @{[vaesdf_vs $V27, $V1]}   # with round key w[ 0, 3]
+    @{[vaesdf_vs $V28, $V1]}   # with round key w[ 0, 3]
+    @{[vaesdf_vs $V29, $V1]}   # with round key w[ 0, 3]
+___
+
+    return $code;
+}
+
 # aes-192 encryption with round keys v1-v13
 sub aes_192_encrypt {
     my $code=<<___;
@@ -475,161 +557,16 @@ ___
 $code .= <<___;
 .p2align 3
 L_cbc_dec_128:
-    @{[vsetivli "zero", 4, "e32", "m1", "ta", "ma"]}
+    # Load all 11 round keys to v1-v11 registers.
+    @{[aes_128_load_key $KEYP]}
+
     # Load IV.
     @{[vle32_v $V16, $IVP]}
 
-.Lcbc_dec_loop:
-    li $T0, 10
-    addi $KEYP, $KEYP, 160
-    @{[vle32_v $V11, $KEYP]}
-    addi $KEYP, $KEYP, -16
-    @{[vle32_v $V10, $KEYP]}
-    li $T1, 64
-    bgeu $LEN, $T1, .Lcbc_check_64
-
-    @{[vle32_v $V24, $INP]}
-    @{[vmv_v_v $V17, $V24]}
-    j 2f
-
-1:
-    li $T0, 10
-    addi $KEYP, $KEYP, 160
-    @{[vle32_v $V11, $KEYP]}
-    addi $KEYP, $KEYP, -16
-    @{[vle32_v $V10, $KEYP]}
-    @{[vle32_v $V24, $INP]}
-    @{[vmv_v_v $V17, $V24]}
-    addi $OUTP, $OUTP, 16
-
-2:
-    # AES body
-    @{[vaesz_vs $V24, $V11]}   # with round key w[40,43]
-    addi $T0, $T0, -2
+    li $T1, 96
 3:
-    addi $KEYP, $KEYP, -16
-    @{[vle32_v $V11, $KEYP]}
-    @{[vaesdm_vs $V24, $V10]}  # with round key w[36,39]
-    addi $KEYP, $KEYP, -16
-    @{[vle32_v $V10, $KEYP]}
-    @{[vaesdm_vs $V24, $V11]}   # with round key w[32,35]
-    addi $T0, $T0, -2
-    bnez $T0, 3b
-    addi $KEYP, $KEYP, -16
-    @{[vle32_v $V11, $KEYP]}
-    @{[vaesdm_vs $V24, $V10]}   # with round key w[ 4, 7]
-    @{[vaesdf_vs $V24, $V11]}   # with round key w[ 0, 3]
+    blt $LEN, $T1, L_small 
 
-    @{[vxor_vv $V24, $V24, $V16]}
-    @{[vse32_v $V24, $OUTP]}
-    @{[vmv_v_v $V16, $V17]}
-
-    addi $LEN, $LEN, -16
-    addi $INP, $INP, 16
-
-    bnez $LEN, 1b
-
-    @{[vse32_v $V16, $IVP]}
-
-    ret
-
-# =====================================================
-# If data 128bytes > length ≥ 64 bytes, process in batches of 4 blocks:
-# 4-block CBC decryption process:
-#   1. Load 4 ciphertext blocks
-#   2. Back up the ciphertext blocks
-#   3. Decrypt each data block
-#   4. Reload ciphertext blocks into registers v17-v20 for XOR
-#   5. XOR with previous ciphertext block (CBC chain)
-#   6. Update IV and store plaintext
-# If the data length is less than 64 bytes, process it block by block using the Lcbc_dec_loop function
-# =====================================================
-.Lcbc_check_64:
-    li $T1, 128
-    bgeu $LEN, $T1, .Lcbc_check_128
-
-    @{[vle32_v $V24, $INP]}
-    addi $INP, $INP, 16
-    @{[vle32_v $V25, $INP]}
-    addi $INP, $INP, 16
-    @{[vle32_v $V26, $INP]}
-    addi $INP, $INP, 16
-    @{[vle32_v $V27, $INP]}
-    @{[vle32_v $V20, $INP]}
-    addi $INP, $INP, -16
-    @{[vle32_v $V19, $INP]}
-
-    @{[vaesz_vs $V24, $V11]}   # with round key w[40,43]
-    @{[vaesz_vs $V25, $V11]}   # with round key w[40,43]
-    @{[vaesz_vs $V26, $V11]}   # with round key w[40,43]
-    @{[vaesz_vs $V27, $V11]}   # with round key w[40,43]
-    addi $T0, $T0, -2
-4:
-    addi $KEYP, $KEYP, -16
-    @{[vle32_v $V11, $KEYP]}
-    @{[vaesdm_vs $V24, $V10]}  # with round key w[36,39]
-    @{[vaesdm_vs $V25, $V10]}  # with round key w[36,39]
-    @{[vaesdm_vs $V26, $V10]}  # with round key w[36,39]
-    @{[vaesdm_vs $V27, $V10]}  # with round key w[36,39]
-    addi $KEYP, $KEYP, -16
-    @{[vle32_v $V10, $KEYP]}
-    @{[vaesdm_vs $V24, $V11]}   # with round key w[32,35]
-    @{[vaesdm_vs $V25, $V11]}   # with round key w[32,35]
-    @{[vaesdm_vs $V26, $V11]}   # with round key w[32,35]
-    @{[vaesdm_vs $V27, $V11]}   # with round key w[32,35]
-    addi $T0, $T0, -2
-    bnez $T0, 4b
-    addi $KEYP, $KEYP, -16
-    @{[vle32_v $V11, $KEYP]}
-    addi $INP, $INP, -16
-    @{[vle32_v $V18, $INP]}
-    addi $INP, $INP, -16
-    @{[vle32_v $V17, $INP]}
-
-    @{[vaesdm_vs $V24, $V10]}   # with round key w[ 4, 7]
-    @{[vaesdm_vs $V25, $V10]}   # with round key w[ 4, 7]
-    @{[vaesdm_vs $V26, $V10]}   # with round key w[ 4, 7]
-    @{[vaesdm_vs $V27, $V10]}   # with round key w[ 4, 7]
-
-    @{[vaesdf_vs $V24, $V11]}   # with round key w[ 0, 3]
-    @{[vaesdf_vs $V25, $V11]}   # with round key w[ 0, 3]
-    @{[vaesdf_vs $V26, $V11]}   # with round key w[ 0, 3]
-    @{[vaesdf_vs $V27, $V11]}   # with round key w[ 0, 3]
-
-    @{[vxor_vv $V24, $V24, $V16]}
-    @{[vxor_vv $V25, $V25, $V17]}
-    @{[vxor_vv $V26, $V26, $V18]}
-    @{[vxor_vv $V27, $V27, $V19]}
-
-    @{[vse32_v $V24, $OUTP]}
-    addi $OUTP, $OUTP, 16
-    @{[vse32_v $V25, $OUTP]}
-    addi $OUTP, $OUTP, 16
-    @{[vse32_v $V26, $OUTP]}
-    addi $OUTP, $OUTP, 16
-    @{[vse32_v $V27, $OUTP]}
-    addi $OUTP, $OUTP, 16
-
-    @{[vmv_v_v $V16, $V20]}
-
-    addi $LEN, $LEN, -64
-    addi $INP, $INP, 64
-    bnez $LEN, .Lcbc_dec_loop
-    @{[vse32_v $V16, $IVP]}
-
-    ret
-
-# =====================================================
-# If data length ≥ 128 bytes, process 8 blocks in batch:
-# 8-block CBC decryption pipeline:
-#   1. Load 8 ciphertext blocks
-#   2. Back up the ciphertext blocks
-#   3. Decrypt each data block
-#   4. Reload ciphertext blocks into registers v17-v23 and v15 for XOR
-#   5. XOR with previous ciphertext block (CBC chain)
-#   6. Update IV and store plaintext
-# =====================================================
-.Lcbc_check_128:
     @{[vle32_v $V24, $INP]}
     addi $INP, $INP, 16
     @{[vle32_v $V25, $INP]}
@@ -642,108 +579,67 @@ L_cbc_dec_128:
     addi $INP, $INP, 16
     @{[vle32_v $V29, $INP]}
     addi $INP, $INP, 16
-    @{[vle32_v $V30, $INP]}
-    addi $INP, $INP, 16
-    @{[vle32_v $V31, $INP]}
-    @{[vle32_v $V15, $INP]}
-    addi $INP, $INP, -16
-    @{[vle32_v $V23, $INP]}
+    @{[vmv_v_v $V17, $V24]}  
+    @{[vmv_v_v $V18, $V25]}
+    @{[vmv_v_v $V19, $V26]} 
+    @{[vmv_v_v $V20, $V27]} 
+    @{[vmv_v_v $V21, $V28]} 
+    @{[vmv_v_v $V22, $V29]}  
 
-    @{[vaesz_vs $V24, $V11]}   # with round key w[40,43]
-    @{[vaesz_vs $V25, $V11]}   # with round key w[40,43]
-    @{[vaesz_vs $V26, $V11]}   # with round key w[40,43]
-    @{[vaesz_vs $V27, $V11]}   # with round key w[40,43]
-    @{[vaesz_vs $V28, $V11]}   # with round key w[40,43]
-    @{[vaesz_vs $V29, $V11]}   # with round key w[40,43]
-    @{[vaesz_vs $V30, $V11]}   # with round key w[40,43]
-    @{[vaesz_vs $V31, $V11]}   # with round key w[40,43]
-    addi $INP, $INP, -16
-    @{[vle32_v $V22, $INP]}
-    addi $INP, $INP, -16
-    @{[vle32_v $V21, $INP]}
-    addi $T0, $T0, -2
-4:
-    addi $KEYP, $KEYP, -16
-    @{[vle32_v $V11, $KEYP]}
-    @{[vaesdm_vs $V24, $V10]}  # with round key w[36,39]
-    @{[vaesdm_vs $V25, $V10]}  # with round key w[36,39]
-    @{[vaesdm_vs $V26, $V10]}  # with round key w[36,39]
-    @{[vaesdm_vs $V27, $V10]}  # with round key w[36,39]
-    @{[vaesdm_vs $V28, $V10]}  # with round key w[36,39]
-    @{[vaesdm_vs $V29, $V10]}  # with round key w[36,39]
-    @{[vaesdm_vs $V30, $V10]}  # with round key w[36,39]
-    @{[vaesdm_vs $V31, $V10]}  # with round key w[36,39]
-    addi $KEYP, $KEYP, -16
-    @{[vle32_v $V10, $KEYP]}
-    @{[vaesdm_vs $V24, $V11]}   # with round key w[32,35]
-    @{[vaesdm_vs $V25, $V11]}   # with round key w[32,35]
-    @{[vaesdm_vs $V26, $V11]}   # with round key w[32,35]
-    @{[vaesdm_vs $V27, $V11]}   # with round key w[32,35]
-    @{[vaesdm_vs $V28, $V11]}   # with round key w[32,35]
-    @{[vaesdm_vs $V29, $V11]}   # with round key w[32,35]
-    @{[vaesdm_vs $V30, $V11]}   # with round key w[32,35]
-    @{[vaesdm_vs $V31, $V11]}   # with round key w[32,35]
-    addi $T0, $T0, -2
-    bnez $T0, 4b
-    addi $KEYP, $KEYP, -16
-    @{[vle32_v $V11, $KEYP]}
-    addi $INP, $INP, -16
-    @{[vle32_v $V20, $INP]}
-    addi $INP, $INP, -16
-    @{[vle32_v $V19, $INP]}
-    addi $INP, $INP, -16
-    @{[vle32_v $V18, $INP]}
-    addi $INP, $INP, -16
-    @{[vle32_v $V17, $INP]}
-    @{[vaesdm_vs $V24, $V10]}   # with round key w[ 4, 7]
-    @{[vaesdm_vs $V25, $V10]}   # with round key w[ 4, 7]
-    @{[vaesdm_vs $V26, $V10]}   # with round key w[ 4, 7]
-    @{[vaesdm_vs $V27, $V10]}   # with round key w[ 4, 7]
-    @{[vaesdm_vs $V28, $V10]}   # with round key w[ 4, 7]
-    @{[vaesdm_vs $V29, $V10]}   # with round key w[ 4, 7]
-    @{[vaesdm_vs $V30, $V10]}   # with round key w[ 4, 7]
-    @{[vaesdm_vs $V31, $V10]}   # with round key w[ 4, 7]
+    @{[aes_128_decrypt_6]} 
 
-    @{[vaesdf_vs $V24, $V11]}   # with round key w[ 0, 3]
-    @{[vaesdf_vs $V25, $V11]}   # with round key w[ 0, 3]
-    @{[vaesdf_vs $V26, $V11]}   # with round key w[ 0, 3]
-    @{[vaesdf_vs $V27, $V11]}   # with round key w[ 0, 3]
-    @{[vaesdf_vs $V28, $V11]}   # with round key w[ 0, 3]
-    @{[vaesdf_vs $V29, $V11]}   # with round key w[ 0, 3]
-    @{[vaesdf_vs $V30, $V11]}   # with round key w[ 0, 3]
-    @{[vaesdf_vs $V31, $V11]}   # with round key w[ 0, 3]
-
-    @{[vxor_vv $V24, $V24, $V16]}
+    @{[vxor_vv $V24, $V24, $V16]}  
     @{[vxor_vv $V25, $V25, $V17]}
     @{[vxor_vv $V26, $V26, $V18]}
     @{[vxor_vv $V27, $V27, $V19]}
     @{[vxor_vv $V28, $V28, $V20]}
     @{[vxor_vv $V29, $V29, $V21]}
-    @{[vxor_vv $V30, $V30, $V22]}
-    @{[vxor_vv $V31, $V31, $V23]}
 
     @{[vse32_v $V24, $OUTP]}
-    addi $OUTP, $OUTP, 16
+    addi $OUTP, $OUTP, 16 
     @{[vse32_v $V25, $OUTP]}
-    addi $OUTP, $OUTP, 16
+    addi $OUTP, $OUTP, 16      
     @{[vse32_v $V26, $OUTP]}
     addi $OUTP, $OUTP, 16
     @{[vse32_v $V27, $OUTP]}
-    addi $OUTP, $OUTP, 16
+    addi $OUTP, $OUTP, 16   
     @{[vse32_v $V28, $OUTP]}
     addi $OUTP, $OUTP, 16
     @{[vse32_v $V29, $OUTP]}
     addi $OUTP, $OUTP, 16
-    @{[vse32_v $V30, $OUTP]}
-    addi $OUTP, $OUTP, 16
-    @{[vse32_v $V31, $OUTP]}
+
+    @{[vmv_v_v $V16, $V22]}  
+
+    addi $LEN, $LEN, -96       
+    
+    bnez $LEN, 3b 
+    @{[vse32_v $V16, $IVP]} 
+
+    ret
+
+L_small:
+    @{[vle32_v $V24, $INP]}
+    @{[vmv_v_v $V17, $V24]}
+    j 2f
+
+1:
+    @{[vle32_v $V24, $INP]}
+    @{[vmv_v_v $V17, $V24]}
     addi $OUTP, $OUTP, 16
 
-    @{[vmv_v_v $V16, $V15]}
+2:
+    # AES body
+    @{[aes_128_decrypt]}
+
+    @{[vxor_vv $V24, $V24, $V16]}
+    @{[vse32_v $V24, $OUTP]}
+    @{[vmv_v_v $V16, $V17]}
+
+    addi $LEN, $LEN, -16
+    addi $INP, $INP, 16
+
+    bnez $LEN, 1b
 
-    addi $LEN, $LEN, -128
-    addi $INP, $INP, 128
-    bnez $LEN, .Lcbc_dec_loop
     @{[vse32_v $V16, $IVP]}
 
     ret
@@ -1069,6 +965,9 @@ $code .= <<___;
 .globl rv64i_zvkned_set_encrypt_key
 .type rv64i_zvkned_set_encrypt_key,\@function
 rv64i_zvkned_set_encrypt_key:
+    beqz $UKEY, L_fail_m1
+    beqz $KEYP, L_fail_m1
+
     # Get proper routine for key size
     li $T0, 256
     beq $BITS, $T0, L_set_key_256
@@ -1085,6 +984,9 @@ $code .= <<___;
 .globl rv64i_zvkned_set_decrypt_key
 .type rv64i_zvkned_set_decrypt_key,\@function
 rv64i_zvkned_set_decrypt_key:
+    beqz $UKEY, L_fail_m1
+    beqz $KEYP, L_fail_m1
+
     # Get proper routine for key size
     li $T0, 256
     beq $BITS, $T0, L_set_key_256
@@ -1591,6 +1493,11 @@ ___
 }
 
 $code .= <<___;
+L_fail_m1:
+    li a0, -1
+    ret
+.size L_fail_m1,.-L_fail_m1
+
 L_fail_m2:
     li a0, -2
     ret
diff --git a/crypto/aes/asm/aes-riscv64.pl b/crypto/aes/asm/aes-riscv64.pl
index 9c864dc6d8..525eba4b46 100644
--- a/crypto/aes/asm/aes-riscv64.pl
+++ b/crypto/aes/asm/aes-riscv64.pl
@@ -773,13 +773,11 @@ AES_set_encrypt_key:
 ___
 $code .= save_regs();
 $code .= <<___;
-    beqz    $UKEY,1f    # if (!userKey || !key) return -1;
-    beqz    $KEYP,1f
-    j       2f
-1:
+    bnez    $UKEY,1f    # if (!userKey || !key) return -1;
+    bnez    $KEYP,1f
     li      a0,-1
     ret
-2:
+1:
     la      $RCON,AES_rcon
     la      $TBL,AES_Te0
     li      $T8,128
diff --git a/crypto/aes/asm/aes-s390x.pl b/crypto/aes/asm/aes-s390x.pl
index 66529ad732..073829cda4 100644
--- a/crypto/aes/asm/aes-s390x.pl
+++ b/crypto/aes/asm/aes-s390x.pl
@@ -131,7 +131,7 @@ sub _data_word()
 }
 
 $code=<<___;
-#include "arch/s390x_arch.h"
+#include "s390x_arch.h"
 
 .text
 
diff --git a/crypto/aes/asm/aes-sha1-armv8.pl b/crypto/aes/asm/aes-sha1-armv8.pl
index 8f121274e9..eb6e16698a 100644
--- a/crypto/aes/asm/aes-sha1-armv8.pl
+++ b/crypto/aes/asm/aes-sha1-armv8.pl
@@ -30,7 +30,7 @@ open OUT,"| \"$^X\" $xlate $flavour \"$output\""
 *STDOUT=*OUT;
 
 $code=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 /* These are offsets into the CIPH_DIGEST struct */
 #define CIPHER_KEY	0
@@ -226,7 +226,6 @@ $code.=<<___;
 	.word	0xca62c1d6, 0xca62c1d6, 0xca62c1d6, 0xca62c1d6
 .text
 
-.align	4
 asm_aescbc_sha1_hmac:
 	AARCH64_VALID_CALL_TARGET
 	/* protect registers */
@@ -2396,7 +2395,6 @@ $code.=<<___;
 
 .global asm_sha1_hmac_aescbc_dec
 .type	asm_sha1_hmac_aescbc_dec,%function
-.align 4
 
 asm_sha1_hmac_aescbc_dec:
 	AARCH64_VALID_CALL_TARGET
diff --git a/crypto/aes/asm/aes-sha256-armv8.pl b/crypto/aes/asm/aes-sha256-armv8.pl
index 9e403c3abf..085319eace 100644
--- a/crypto/aes/asm/aes-sha256-armv8.pl
+++ b/crypto/aes/asm/aes-sha256-armv8.pl
@@ -30,7 +30,7 @@ open OUT,"| \"$^X\" $xlate $flavour \"$output\""
 *STDOUT=*OUT;
 
 $code=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 /* These are offsets into the CIPH_DIGEST struct */
 #define CIPHER_KEY	0
@@ -2555,7 +2555,6 @@ $code.=<<___;
 
 .global	asm_sha256_hmac_aescbc_dec
 .type	asm_sha256_hmac_aescbc_dec,%function
-.align  4
 
 asm_sha256_hmac_aescbc_dec:
 	AARCH64_VALID_CALL_TARGET
@@ -4656,4 +4655,4 @@ if ($flavour =~ /64/) {
 	}
 }
 
-close STDOUT or die "error closing STDOUT: $!";
+close STDOUT or die "error closing STDOUT: $!";
\ No newline at end of file
diff --git a/crypto/aes/asm/aes-sha512-armv8.pl b/crypto/aes/asm/aes-sha512-armv8.pl
index bae8f31c44..3582bcfeef 100644
--- a/crypto/aes/asm/aes-sha512-armv8.pl
+++ b/crypto/aes/asm/aes-sha512-armv8.pl
@@ -22,7 +22,7 @@ open OUT,"| \"$^X\" $xlate $flavour \"$output\""
 *STDOUT=*OUT;
 
 $code=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 /* These are offsets into the CIPH_DIGEST struct */
 #define CIPHER_KEY	0
diff --git a/crypto/aes/asm/aes-sparcv9.pl b/crypto/aes/asm/aes-sparcv9.pl
index 9fbe7c7a74..2a6fa6c96e 100755
--- a/crypto/aes/asm/aes-sparcv9.pl
+++ b/crypto/aes/asm/aes-sparcv9.pl
@@ -85,7 +85,7 @@ $code.=<<___;
 #ifndef __ASSEMBLER__
 # define __ASSEMBLER__ 1
 #endif
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 #ifdef  __arch64__
 .register	%g2,#scratch
diff --git a/crypto/aes/asm/aes-x86_64.pl b/crypto/aes/asm/aes-x86_64.pl
index b899560319..4127cbb98b 100755
--- a/crypto/aes/asm/aes-x86_64.pl
+++ b/crypto/aes/asm/aes-x86_64.pl
@@ -1,5 +1,5 @@
 #! /usr/bin/env perl
-# Copyright 2005-2026 The OpenSSL Project Authors. All Rights Reserved.
+# Copyright 2005-2025 The OpenSSL Project Authors. All Rights Reserved.
 #
 # Licensed under the Apache License 2.0 (the "License").  You may not use
 # this file except in compliance with the License.  You can obtain a copy
@@ -1337,7 +1337,8 @@ $code.=<<___;
 ___
 }
 
-# int AES_set_encrypt_key(const unsigned char *userKey, int bits, AES_KEY *key)
+# int AES_set_encrypt_key(const unsigned char *userKey, const int bits,
+#                        AES_KEY *key)
 $code.=<<___;
 .globl	AES_set_encrypt_key
 .type	AES_set_encrypt_key,\@function,3
@@ -1617,7 +1618,8 @@ $code.=<<___;
 ___
 }
 
-# int AES_set_decrypt_key(const unsigned char *userKey, int bits, AES_KEY *key)
+# int AES_set_decrypt_key(const unsigned char *userKey, const int bits,
+#                        AES_KEY *key)
 $code.=<<___;
 .globl	AES_set_decrypt_key
 .type	AES_set_decrypt_key,\@function,3
@@ -1713,7 +1715,7 @@ ___
 
 # void AES_cbc_encrypt (const void char *inp, unsigned char *out,
 #			size_t length, const AES_KEY *key,
-#			unsigned char *ivp, int enc);
+#			unsigned char *ivp,const int enc);
 {
 # stack frame layout
 # -8(%rsp)		return address
diff --git a/crypto/aes/asm/aesfx-sparcv9.pl b/crypto/aes/asm/aesfx-sparcv9.pl
index d19efa2f92..34d1fff3d8 100644
--- a/crypto/aes/asm/aesfx-sparcv9.pl
+++ b/crypto/aes/asm/aesfx-sparcv9.pl
@@ -42,7 +42,7 @@ $code.=<<___;
 #ifndef __ASSEMBLER__
 # define __ASSEMBLER__ 1
 #endif
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 #define LOCALS (STACK_BIAS+STACK_FRAME)
 
@@ -479,16 +479,11 @@ aes_fx_cbc_encrypt:
 	ldd		[$end + 24], %f12
 
 	movrz		$len, 0, $inc
-
-	brz,pn		$len, .Lcbc_enc_skip_load
-	nop
-
 	fmovd		$intail, $in0
 	ldd		[$inp - 8], $in1	! load next input block
 	ldda		[$inp]0x82, $intail	! non-faulting load
 	add		$inp, $inc, $inp	! inp+=16
 
-.Lcbc_enc_skip_load:
 	fmovd		%f0, %f4
 	faesencx	%f2, %f6, %f0
 	faesencx	%f4, %f8, %f2
@@ -699,16 +694,11 @@ aes_fx_cbc_encrypt:
 	fmovd		$in1, $iv1
 
 	movrz		$len, 0, $inc
-
-	brz,pn		$len, .Lcbc_dec_skip_load
-	nop
-
 	fmovd		$intail, $in0
 	ldd		[$inp - 8], $in1	! load next input block
 	ldda		[$inp]0x82, $intail	! non-faulting load
 	add		$inp, $inc, $inp	! inp+=16
 
-.Lcbc_dec_skip_load:
 	fmovd		%f0, %f4
 	faesdecx	%f2, %f10, %f0
 	faesdecx	%f4, %f12, %f2
@@ -963,16 +953,11 @@ aes_fx_ctr32_encrypt_blocks:
 	fxor		$in1, $rllo, %f8
 
 	movrz		$len, 0, $inc
-
-	brz,pn		$len, .Lctr32_enc_skip_load
-	nop
-
 	fmovd		$intail, $in0
 	ldd		[$inp - 8], $in1	! load next input block
 	ldda		[$inp]0x82, $intail	! non-faulting load
 	add		$inp, $inc, $inp	! inp+=16
 
-.Lctr32_enc_skip_load:
 	fmovd		%f0, %f4
 	faesencx	%f2, %f10, %f0
 	faesencx	%f4, %f12, %f2
diff --git a/crypto/aes/asm/aesni-mb-x86_64.pl b/crypto/aes/asm/aesni-mb-x86_64.pl
index 154f1bc70f..852c484727 100644
--- a/crypto/aes/asm/aesni-mb-x86_64.pl
+++ b/crypto/aes/asm/aesni-mb-x86_64.pl
@@ -80,13 +80,6 @@ if (!$avx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([0
 	$avx = ($2>=3.0) + ($2>3.0);
 }
 
-if (!$avx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$avx = ($1>=11); #icx started with clang 11
-	}
-}
-
 open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\""
     or die "can't call $xlate: $!";
 *STDOUT=*OUT;
diff --git a/crypto/aes/asm/aesni-sha1-x86_64.pl b/crypto/aes/asm/aesni-sha1-x86_64.pl
index 003c0e9716..e7c218f097 100644
--- a/crypto/aes/asm/aesni-sha1-x86_64.pl
+++ b/crypto/aes/asm/aesni-sha1-x86_64.pl
@@ -111,9 +111,6 @@ $avx=1 if (!$avx && $win64 && ($flavour =~ /masm/ || $ENV{ASM} =~ /ml64/) &&
 	   $1>=10);
 $avx=1 if (!$avx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([0-9]+\.[0-9]+)/ && $2>=3.0);
 
-$avx=1 if (!$avx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__` =~ /#define __clang_major__.([0-9]+)/ &&
-	   $1>=11); #icx started with clang 11
-
 $shaext=1;	### set to zero if compiling for 1.0.1
 
 $stitched_decrypt=0;
diff --git a/crypto/aes/asm/aesni-sha256-x86_64.pl b/crypto/aes/asm/aesni-sha256-x86_64.pl
index aecd6e7b40..da39d483c2 100644
--- a/crypto/aes/asm/aesni-sha256-x86_64.pl
+++ b/crypto/aes/asm/aesni-sha256-x86_64.pl
@@ -75,13 +75,6 @@ if (!$avx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([0
 	$avx = ($2>=3.0) + ($2>3.0);
 }
 
-if (!$avx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$avx = ($1>=11); #icx started with clang 11
-	}
-}
-
 $shaext=$avx;	### set to zero if compiling for 1.0.1
 $avx=1		if (!$shaext && $avx);
 
diff --git a/crypto/aes/asm/aesni-xts-avx512.pl b/crypto/aes/asm/aesni-xts-avx512.pl
index 16f2bbe789..d89564112e 100644
--- a/crypto/aes/asm/aesni-xts-avx512.pl
+++ b/crypto/aes/asm/aesni-xts-avx512.pl
@@ -59,13 +59,6 @@ if (!$avx512vaes && `$ENV{CC} -v 2>&1`
     }
 }
 
-if (!$avx512vaes && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-    =~ /#define __clang_major__.([0-9]+)/) {
-    if ($1) {
-        $avx512vaes = ($1>=11); #icx started with clang 11
-    }
-}
-
 open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\""
     or die "can't call $xlate: $!";
 *STDOUT=*OUT;
diff --git a/crypto/aes/asm/aest4-sparcv9.pl b/crypto/aes/asm/aest4-sparcv9.pl
index d867db183b..c04b5f3cda 100644
--- a/crypto/aes/asm/aest4-sparcv9.pl
+++ b/crypto/aes/asm/aest4-sparcv9.pl
@@ -94,7 +94,7 @@ $code.=<<___;
 #ifndef __ASSEMBLER__
 # define __ASSEMBLER__ 1
 #endif
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 #ifdef	__arch64__
 .register	%g2,#scratch
diff --git a/crypto/aes/asm/aesv8-armx.pl b/crypto/aes/asm/aesv8-armx.pl
index a9e272a91c..82e60d788e 100755
--- a/crypto/aes/asm/aesv8-armx.pl
+++ b/crypto/aes/asm/aesv8-armx.pl
@@ -75,7 +75,7 @@ $prefix="aes_v8";
 $_byte = ($flavour =~ /win/ ? "DCB" : ".byte");
 
 $code=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 #if __ARM_MAX_ARCH__>=7
 ___
diff --git a/crypto/aes/asm/bsaes-armv7.pl b/crypto/aes/asm/bsaes-armv7.pl
index ff9c2fa3b9..edc01265f7 100644
--- a/crypto/aes/asm/bsaes-armv7.pl
+++ b/crypto/aes/asm/bsaes-armv7.pl
@@ -706,7 +706,7 @@ ___
 
 $code.=<<___;
 #ifndef __KERNEL__
-# include "arch/arm_arch.h"
+# include "arm_arch.h"
 
 # define VFP_ABI_PUSH	vstmdb	sp!,{d8-d15}
 # define VFP_ABI_POP	vldmia	sp!,{d8-d15}
diff --git a/crypto/aes/asm/bsaes-armv8.pl b/crypto/aes/asm/bsaes-armv8.pl
index fa64865ba6..912538622b 100644
--- a/crypto/aes/asm/bsaes-armv8.pl
+++ b/crypto/aes/asm/bsaes-armv8.pl
@@ -56,7 +56,7 @@ __END__
 // up in Perl, and it is presented as pure assembly.
 
 
-#include "arch/arm_arch.h"
+#include "crypto/arm_arch.h"
 
 .text
 
diff --git a/crypto/aes/asm/vpaes-armv8.pl b/crypto/aes/asm/vpaes-armv8.pl
index e9bf163cac..a8cc8c3f78 100755
--- a/crypto/aes/asm/vpaes-armv8.pl
+++ b/crypto/aes/asm/vpaes-armv8.pl
@@ -53,7 +53,7 @@ open OUT,"| \"$^X\" $xlate $flavour \"$output\""
 *STDOUT=*OUT;
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 .rodata
 
@@ -1254,6 +1254,48 @@ vpaes_ecb_encrypt:
 	AARCH64_VALIDATE_LINK_REGISTER
 	ret
 .size	vpaes_ecb_encrypt,.-vpaes_ecb_encrypt
+
+.globl	vpaes_ecb_decrypt
+.type	vpaes_ecb_decrypt,%function
+.align	4
+vpaes_ecb_decrypt:
+	AARCH64_SIGN_LINK_REGISTER
+	stp	x29,x30,[sp,#-16]!
+	add	x29,sp,#0
+	stp	d8,d9,[sp,#-16]!	// ABI spec says so
+	stp	d10,d11,[sp,#-16]!
+	stp	d12,d13,[sp,#-16]!
+	stp	d14,d15,[sp,#-16]!
+
+	mov	x17, $len
+	mov	x2,  $key
+	bl	_vpaes_decrypt_preheat
+	tst	x17, #16
+	b.eq	.Lecb_dec_loop
+
+	ld1	{v7.16b}, [$inp],#16
+	bl	_vpaes_encrypt_core
+	st1	{v0.16b}, [$out],#16
+	subs	x17, x17, #16
+	b.ls	.Lecb_dec_done
+
+.align	4
+.Lecb_dec_loop:
+	ld1	{v14.16b,v15.16b}, [$inp], #32
+	bl	_vpaes_decrypt_2x
+	st1	{v0.16b,v1.16b}, [$out], #32
+	subs	x17, x17, #32
+	b.hi	.Lecb_dec_loop
+
+.Lecb_dec_done:
+	ldp	d14,d15,[sp],#16
+	ldp	d12,d13,[sp],#16
+	ldp	d10,d11,[sp],#16
+	ldp	d8,d9,[sp],#16
+	ldp	x29,x30,[sp],#16
+	AARCH64_VALIDATE_LINK_REGISTER
+	ret
+.size	vpaes_ecb_decrypt,.-vpaes_ecb_decrypt
 ___
 }	}
 print $code;
diff --git a/crypto/arm64cpuid.pl b/crypto/arm64cpuid.pl
index d90289b6a9..f38a64bc6b 100755
--- a/crypto/arm64cpuid.pl
+++ b/crypto/arm64cpuid.pl
@@ -22,7 +22,7 @@ open OUT,"| \"$^X\" $xlate $flavour \"$output\""
 *STDOUT=*OUT;
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 .text
 .arch	armv8-a+crypto
diff --git a/include/arch/arm_arch.h b/crypto/arm_arch.h
similarity index 97%
rename from include/arch/arm_arch.h
rename to crypto/arm_arch.h
index 5bc61c22e1..1cf41ff5b5 100644
--- a/include/arch/arm_arch.h
+++ b/crypto/arm_arch.h
@@ -1,5 +1,5 @@
 /*
- * Copyright 2011-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2011-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -100,7 +100,6 @@ extern unsigned int OPENSSL_armv8_rsa_neonized;
 #define ARM_CPU_IMP_APPLE 0x61
 #define ARM_CPU_IMP_MICROSOFT 0x6D
 #define ARM_CPU_IMP_AMPERE 0xC0
-#define ARM_CPU_IMP_NVIDIA 0x4E
 
 #define ARM_CPU_PART_CORTEX_A72 0xD08
 #define ARM_CPU_PART_N1 0xD0C
@@ -114,8 +113,6 @@ extern unsigned int OPENSSL_armv8_rsa_neonized;
 
 #define QCOM_CPU_PART_ORYON_X1 0x001
 
-#define NVIDIA_CPU_PART_OLYMPUS 0x010
-
 #define APPLE_CPU_PART_M1_ICESTORM 0x022
 #define APPLE_CPU_PART_M1_FIRESTORM 0x023
 #define APPLE_CPU_PART_M1_ICESTORM_PRO 0x024
@@ -195,9 +192,7 @@ extern unsigned int OPENSSL_armv8_rsa_neonized;
 #endif
 
 #if GNU_PROPERTY_AARCH64_POINTER_AUTH != 0 || GNU_PROPERTY_AARCH64_BTI != 0
-/* clang-format off */
-.pushsection .note.gnu.property, "a";
-/* clang-format on */
+.pushsection.note.gnu.property, "a";
 .balign 8;
 .long 4;
 .long 0x10;
diff --git a/crypto/armcap.c b/crypto/armcap.c
index f4f6b0d7f9..d8ad9ce012 100644
--- a/crypto/armcap.c
+++ b/crypto/armcap.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2011-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2011-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -19,11 +19,11 @@
 #endif
 #include "internal/cryptlib.h"
 #ifdef _WIN32
-#include "internal/e_os.h"
+#include 
 #else
 #include 
 #endif
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 #ifdef __aarch64__
 #include 
 #endif
@@ -69,10 +69,6 @@ uint32_t OPENSSL_rdtsc(void)
 
 /* First determine if getauxval() is available (OSSL_IMPLEMENT_GETAUXVAL) */
 
-#if defined(__GNUC__)
-void OPENSSL_cpuid_setup(void) __attribute__((constructor));
-#endif
-
 #if defined(__GLIBC__) && defined(__GLIBC_PREREQ)
 #if __GLIBC_PREREQ(2, 16)
 #include 
@@ -415,52 +411,15 @@ void OPENSSL_cpuid_setup(void)
     if (OPENSSL_armcap_P & ARMV8_CPUID)
         OPENSSL_arm_midr = _armv8_cpuid_probe();
 
-    if ((OPENSSL_armcap_P & ARMV7_NEON)
-        && (MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_CORTEX_A72)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_N1)))
+    if ((MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_CORTEX_A72) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_N1)) && (OPENSSL_armcap_P & ARMV7_NEON)) {
         OPENSSL_armv8_rsa_neonized = 1;
-
-    if ((OPENSSL_armcap_P & ARMV8_SHA3)
-        && (MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V1)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_N2)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_QCOMM, QCOM_CPU_PART_ORYON_X1)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_MICROSOFT, MICROSOFT_CPU_PART_COBALT_100)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V2)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_N3)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V3_AE)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V3)
-            || MIDR_IMPLEMENTER(OPENSSL_arm_midr) == ARM_CPU_IMP_AMPERE
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_NVIDIA, NVIDIA_CPU_PART_OLYMPUS)))
+    }
+    if ((MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V1) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_N2) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_QCOMM, QCOM_CPU_PART_ORYON_X1) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_MICROSOFT, MICROSOFT_CPU_PART_COBALT_100) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V2) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_N3) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V3_AE) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V3) || MIDR_IMPLEMENTER(OPENSSL_arm_midr) == ARM_CPU_IMP_AMPERE) && (OPENSSL_armcap_P & ARMV8_SHA3))
         OPENSSL_armcap_P |= ARMV8_UNROLL8_EOR3;
-
-    if ((OPENSSL_armcap_P & ARMV8_SHA3)
-        && (MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V1)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V2)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V3_AE)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V3)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_N2)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_N3)
-            || MIDR_IMPLEMENTER(OPENSSL_arm_midr) == ARM_CPU_IMP_AMPERE
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_NVIDIA, NVIDIA_CPU_PART_OLYMPUS)))
+    if ((MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V1) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V2) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V3_AE) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_V3) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_N2) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_ARM, ARM_CPU_PART_N3) || MIDR_IMPLEMENTER(OPENSSL_arm_midr) == ARM_CPU_IMP_AMPERE) && (OPENSSL_armcap_P & ARMV8_SHA3))
         OPENSSL_armcap_P |= ARMV8_UNROLL12_EOR3;
-
-    if ((OPENSSL_armcap_P & ARMV8_SHA3)
-        && (MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M1_FIRESTORM)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M1_ICESTORM)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M1_FIRESTORM_PRO)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M1_ICESTORM_PRO)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M1_FIRESTORM_MAX)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M1_ICESTORM_MAX)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M2_AVALANCHE)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M2_BLIZZARD)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M2_AVALANCHE_PRO)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M2_BLIZZARD_PRO)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M2_AVALANCHE_MAX)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M2_BLIZZARD_MAX)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_QCOMM, QCOM_CPU_PART_ORYON_X1)
-            || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_NVIDIA, NVIDIA_CPU_PART_OLYMPUS)))
+    if ((MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M1_FIRESTORM) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M1_ICESTORM) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M1_FIRESTORM_PRO) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M1_ICESTORM_PRO) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M1_FIRESTORM_MAX) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M1_ICESTORM_MAX) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M2_AVALANCHE) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M2_BLIZZARD) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M2_AVALANCHE_PRO) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M2_BLIZZARD_PRO) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M2_AVALANCHE_MAX) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_APPLE, APPLE_CPU_PART_M2_BLIZZARD_MAX) || MIDR_IS_CPU_MODEL(OPENSSL_arm_midr, ARM_CPU_IMP_QCOMM, QCOM_CPU_PART_ORYON_X1)) && (OPENSSL_armcap_P & ARMV8_SHA3))
         OPENSSL_armcap_P |= ARMV8_HAVE_SHA3_AND_WORTH_USING;
-
     if (OPENSSL_armcap_P & ARMV9_SVE2) {
         uint64_t vl_bytes = _armv8_sve_get_vl_bytes();
 
diff --git a/crypto/armv4cpuid.pl b/crypto/armv4cpuid.pl
index 0d2b590ad3..e7273b3390 100644
--- a/crypto/armv4cpuid.pl
+++ b/crypto/armv4cpuid.pl
@@ -22,7 +22,7 @@ open OUT,"| \"$^X\" $xlate $flavour \"$output\""
 *STDOUT=*OUT;
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 #if defined(__thumb2__) && !defined(__APPLE__)
 .syntax	unified
@@ -73,7 +73,6 @@ OPENSSL_atomic_add:
 
 .global	OPENSSL_cleanse
 .type	OPENSSL_cleanse,%function
-.align	5
 OPENSSL_cleanse:
 	eor	ip,ip,ip
 	cmp	r1,#7
@@ -113,7 +112,7 @@ OPENSSL_cleanse:
 
 .global	CRYPTO_memcmp
 .type	CRYPTO_memcmp,%function
-.align	5
+.align	4
 CRYPTO_memcmp:
 	eor	ip,ip,ip
 	cmp	r2,#0
@@ -155,7 +154,6 @@ _armv7_neon_probe:
 
 .global	_armv7_tick
 .type	_armv7_tick,%function
-.align	5
 _armv7_tick:
 #ifdef	__APPLE__
 	mrrc	p15,0,r0,r1,c14		@ CNTPCT
@@ -167,7 +165,6 @@ _armv7_tick:
 
 .global	_armv8_aes_probe
 .type	_armv8_aes_probe,%function
-.align	5
 _armv8_aes_probe:
 #if defined(__thumb2__) && !defined(__APPLE__)
 	.byte	0xb0,0xff,0x00,0x03	@ aese.8	q0,q0
@@ -179,7 +176,6 @@ _armv8_aes_probe:
 
 .global	_armv8_sha1_probe
 .type	_armv8_sha1_probe,%function
-.align	5
 _armv8_sha1_probe:
 #if defined(__thumb2__) && !defined(__APPLE__)
 	.byte	0x00,0xef,0x40,0x0c	@ sha1c.32	q0,q0,q0
@@ -191,7 +187,6 @@ _armv8_sha1_probe:
 
 .global	_armv8_sha256_probe
 .type	_armv8_sha256_probe,%function
-.align	5
 _armv8_sha256_probe:
 #if defined(__thumb2__) && !defined(__APPLE__)
 	.byte	0x00,0xff,0x40,0x0c	@ sha256h.32	q0,q0,q0
@@ -202,7 +197,6 @@ _armv8_sha256_probe:
 .size	_armv8_sha256_probe,.-_armv8_sha256_probe
 .global	_armv8_pmull_probe
 .type	_armv8_pmull_probe,%function
-.align	5
 _armv8_pmull_probe:
 #if defined(__thumb2__) && !defined(__APPLE__)
 	.byte	0xa0,0xef,0x00,0x0e	@ vmull.p64	q0,d0,d0
@@ -215,7 +209,6 @@ _armv8_pmull_probe:
 
 .global	OPENSSL_instrument_bus
 .type	OPENSSL_instrument_bus,%function
-.align	5
 OPENSSL_instrument_bus:
 	eor	r0,r0,r0
 #if __ARM_ARCH__>=5
@@ -229,7 +222,6 @@ OPENSSL_instrument_bus:
 
 .global	OPENSSL_instrument_bus2
 .type	OPENSSL_instrument_bus2,%function
-.align	5
 OPENSSL_instrument_bus2:
 	eor	r0,r0,r0
 #if __ARM_ARCH__>=5
diff --git a/crypto/asn1/a_bitstr.c b/crypto/asn1/a_bitstr.c
index fdefb80e26..223efc2bb1 100644
--- a/crypto/asn1/a_bitstr.c
+++ b/crypto/asn1/a_bitstr.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -13,33 +13,60 @@
 #include 
 #include "asn1_local.h"
 
-#include 
-
-#ifndef OPENSSL_NO_DEPRECATED_4_1
 int ASN1_BIT_STRING_set(ASN1_BIT_STRING *x, unsigned char *d, int len)
 {
-    return ossl_asn1_string_set_internal(x, d, len, /*add_nul_byte=*/0);
+    return ASN1_STRING_set(x, d, len);
 }
-#endif
 
-int ossl_i2c_ASN1_BIT_STRING(const ASN1_BIT_STRING *a, unsigned char **pp)
+int ossl_i2c_ASN1_BIT_STRING(ASN1_BIT_STRING *a, unsigned char **pp)
 {
-    int ret = 0, bits = 0, len;
+    int ret, j, bits, len;
     unsigned char *p, *d;
 
     if (a == NULL)
-        goto err;
+        return 0;
 
     len = a->length;
 
-    if (len > INT_MAX - 1)
-        goto err;
+    if (len > 0) {
+        if (a->flags & ASN1_STRING_FLAG_BITS_LEFT) {
+            bits = (int)a->flags & 0x07;
+        } else {
+            for (; len > 0; len--) {
+                if (a->data[len - 1])
+                    break;
+            }
 
-    if ((len > 0) && (a->flags & ASN1_STRING_FLAG_BITS_LEFT))
-        bits = (int)a->flags & 0x07;
+            if (len == 0) {
+                bits = 0;
+            } else {
+                j = a->data[len - 1];
+                if (j & 0x01)
+                    bits = 0;
+                else if (j & 0x02)
+                    bits = 1;
+                else if (j & 0x04)
+                    bits = 2;
+                else if (j & 0x08)
+                    bits = 3;
+                else if (j & 0x10)
+                    bits = 4;
+                else if (j & 0x20)
+                    bits = 5;
+                else if (j & 0x40)
+                    bits = 6;
+                else if (j & 0x80)
+                    bits = 7;
+                else
+                    bits = 0; /* should not happen */
+            }
+        }
+    } else
+        bits = 0;
 
+    ret = 1 + len;
     if (pp == NULL)
-        goto done;
+        return ret;
 
     p = *pp;
 
@@ -51,11 +78,6 @@ int ossl_i2c_ASN1_BIT_STRING(const ASN1_BIT_STRING *a, unsigned char **pp)
         p[-1] &= (0xff << bits);
     }
     *pp = p;
-
-done:
-    ret = len + 1;
-
-err:
     return ret;
 }
 
@@ -93,7 +115,7 @@ ASN1_BIT_STRING *ossl_c2i_ASN1_BIT_STRING(ASN1_BIT_STRING **a,
      * We do this to preserve the settings.  If we modify the settings, via
      * the _set_bit function, we will recalculate on output
      */
-    ossl_asn1_bit_string_set_unused_bits(ret, i);
+    ossl_asn1_string_set_bits_left(ret, i);
 
     if (len-- > 1) { /* using one because of the bits left byte */
         s = OPENSSL_malloc((int)len);
@@ -154,24 +176,8 @@ int ASN1_BIT_STRING_set_bit(ASN1_BIT_STRING *a, int n, int value)
         a->length = w + 1;
     }
     a->data[w] = ((a->data[w]) & iv) | v;
-
     while ((a->length > 0) && (a->data[a->length - 1] == 0))
         a->length--;
-
-    if (a->length > 0) {
-        uint8_t u8 = a->data[a->length - 1];
-        uint8_t unused_bits = 7;
-
-        /* Only keep least significant bit; count trailing zeroes. */
-        u8 &= 0x100 - u8;
-        if ((u8 & 0x0f) != 0)
-            unused_bits -= 4;
-        if ((u8 & 0x33) != 0)
-            unused_bits -= 2;
-        if ((u8 & 0x55) != 0)
-            unused_bits -= 1;
-        ossl_asn1_bit_string_set_unused_bits(a, unused_bits);
-    }
     return 1;
 }
 
@@ -214,61 +220,3 @@ int ASN1_BIT_STRING_check(const ASN1_BIT_STRING *a,
     }
     return ok;
 }
-
-int ASN1_BIT_STRING_get_length(const ASN1_BIT_STRING *abs, size_t *out_length,
-    int *out_unused_bits)
-{
-    size_t length;
-    int unused_bits;
-
-    if (abs == NULL || abs->type != V_ASN1_BIT_STRING)
-        return 0;
-
-    if (out_length == NULL || out_unused_bits == NULL)
-        return 0;
-
-    length = abs->length;
-    unused_bits = 0;
-
-    if ((abs->flags & ASN1_STRING_FLAG_BITS_LEFT) != 0)
-        unused_bits = abs->flags & 0x07;
-
-    if (length == 0 && unused_bits != 0)
-        return 0;
-
-    if (unused_bits != 0) {
-        unsigned char mask = (1 << unused_bits) - 1;
-        if ((abs->data[length - 1] & mask) != 0)
-            return 0;
-    }
-
-    *out_length = length;
-    *out_unused_bits = unused_bits;
-
-    return 1;
-}
-
-int ASN1_BIT_STRING_set1(ASN1_BIT_STRING *abs, const uint8_t *data, size_t length,
-    int unused_bits)
-{
-    if (abs == NULL)
-        return 0;
-
-    if (length > INT_MAX || unused_bits < 0 || unused_bits > 7)
-        return 0;
-
-    if (length == 0 && unused_bits != 0)
-        return 0;
-
-    if (length > 0 && (data[length - 1] & ((1 << unused_bits) - 1)) != 0)
-        return 0;
-
-    if (!ossl_asn1_string_set_internal(abs, data, (int)length, /*add_nul_byte=*/0))
-        return 0;
-
-    abs->type = V_ASN1_BIT_STRING;
-
-    ossl_asn1_bit_string_set_unused_bits(abs, unused_bits);
-
-    return 1;
-}
diff --git a/crypto/asn1/a_d2i_fp.c b/crypto/asn1/a_d2i_fp.c
index 41491b92a1..4204743cd2 100644
--- a/crypto/asn1/a_d2i_fp.c
+++ b/crypto/asn1/a_d2i_fp.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -104,7 +104,7 @@ void *ASN1_item_d2i_fp(const ASN1_ITEM *it, FILE *in, void *x)
 }
 #endif
 
-#define HEADER_SIZE 2
+#define HEADER_SIZE 8
 #define ASN1_CHUNK_INITIAL_SIZE (16 * 1024)
 int asn1_d2i_read_bio(BIO *in, BUF_MEM **pb)
 {
@@ -140,21 +140,8 @@ int asn1_d2i_read_bio(BIO *in, BUF_MEM **pb)
             }
             i = BIO_read(in, &(b->data[len]), (int)want);
 
-            if (i <= 0) {
-                /*
-                 * A read error (i < 0), an EOF in the middle of an object
-                 * (diff != 0, some bytes already buffered), or an EOF while
-                 * still inside an indefinite-length constructed value awaiting
-                 * its end-of-contents octets (eos != 0) all mean the input is
-                 * truncated.  Only a clean EOF at a top-level object boundary
-                 * (i == 0, diff == 0, eos == 0) is the normal end of input:
-                 * fail without queuing an error so that callers looping over
-                 * concatenated DER values (e.g. the libcrypto d2i_*_bio()
-                 * consumers in CPython's ssl module) terminate cleanly instead
-                 * of seeing a spurious ASN1_R_NOT_ENOUGH_DATA.
-                 */
-                if (i < 0 || diff != 0 || eos != 0)
-                    ERR_raise(ERR_LIB_ASN1, ASN1_R_NOT_ENOUGH_DATA);
+            if (i <= 0 && diff == 0) {
+                ERR_raise(ERR_LIB_ASN1, ASN1_R_NOT_ENOUGH_DATA);
                 goto err;
             }
 
@@ -170,64 +157,11 @@ int asn1_d2i_read_bio(BIO *in, BUF_MEM **pb)
         }
         /* else data already loaded */
 
-        /* make sure there is enough data for a complete header */
         p = (unsigned char *)&(b->data[off]);
         q = p;
         diff = len - off;
-        if (diff < 2) {
-            /* Failed sanity check */
-            ERR_raise(ERR_LIB_ASN1, ASN1_R_NOT_ENOUGH_DATA);
+        if (diff == 0)
             goto err;
-        }
-
-        diff--;
-        if ((*(q++) & V_ASN1_PRIMITIVE_TAG) == V_ASN1_PRIMITIVE_TAG) {
-            unsigned int i = 0;
-            /* Multi-byte tag.  See if we have the whole thing yet */
-            do {
-                if (i > 4) {
-                    /* The tag value must fit into int */
-                    ERR_raise(ERR_LIB_ASN1, ASN1_R_HEADER_TOO_LONG);
-                    goto err;
-                }
-                ++i;
-                diff--;
-            } while (diff > 0 && *(q++) & 0x80);
-
-            if (diff == 0) {
-                /*
-                 * End of current data, will need at least 1 more byte for
-                 * length.  2 if the tag is still incomplete
-                 */
-                want = q - p + 2;
-                if (*q & 0x80) {
-                    want++;
-                }
-                continue;
-            }
-        }
-
-        /* Check the length.  This should also work for indefinite length */
-        diff--;
-        if (*q & 0x80) {
-            unsigned int i = *q & 0x7f;
-
-            if (i > sizeof(long)) {
-                ERR_raise(ERR_LIB_ASN1, ASN1_R_TOO_LONG);
-                goto err;
-            }
-            if (i > diff) {
-                want = q - p + i + 1;
-                continue;
-            }
-        }
-
-        /*
-         * We have a complete header now, assuming we didn't hit EOF. Parse the
-         * tag and length
-         */
-        q = p;
-        diff = len - off;
         inf = ASN1_get_object(&q, &slen, &tag, &xclass, (int)diff);
         if (inf & 0x80) {
             unsigned long e;
diff --git a/crypto/asn1/a_int.c b/crypto/asn1/a_int.c
index 10db6b6a3c..de39a54cdb 100644
--- a/crypto/asn1/a_int.c
+++ b/crypto/asn1/a_int.c
@@ -316,7 +316,7 @@ ASN1_INTEGER *ossl_c2i_ASN1_INTEGER(ASN1_INTEGER **a, const unsigned char **pp,
     } else
         ret = *a;
 
-    if (ASN1_STRING_set_data(ret, NULL, r) == 0) {
+    if (r > INT_MAX || ASN1_STRING_set(ret, NULL, (int)r) == 0) {
         ERR_raise(ERR_LIB_ASN1, ERR_R_ASN1_LIB);
         goto err;
     }
@@ -371,7 +371,7 @@ static int asn1_string_set_int64(ASN1_STRING *a, int64_t r, int itype)
         off = asn1_put_uint64(tbuf, r);
         a->type &= ~V_ASN1_NEG;
     }
-    return ASN1_STRING_set_data(a, tbuf + off, (sizeof(tbuf) - off));
+    return ASN1_STRING_set(a, tbuf + off, (int)(sizeof(tbuf) - off));
 }
 
 static int asn1_string_get_uint64(uint64_t *pr, const ASN1_STRING *a,
@@ -399,7 +399,7 @@ static int asn1_string_set_uint64(ASN1_STRING *a, uint64_t r, int itype)
 
     a->type = itype;
     off = asn1_put_uint64(tbuf, r);
-    return ASN1_STRING_set_data(a, tbuf + off, (sizeof(tbuf) - off));
+    return ASN1_STRING_set(a, tbuf + off, (int)(sizeof(tbuf) - off));
 }
 
 /*
@@ -441,17 +441,11 @@ ASN1_INTEGER *d2i_ASN1_UINTEGER(ASN1_INTEGER **a, const unsigned char **pp,
         i = ASN1_R_ILLEGAL_NEGATIVE_VALUE;
         goto err;
     }
-#if INT_MAX < LONG_MAX
-    if (len > INT_MAX - 1) {
-        i = ASN1_R_TOO_LARGE;
-        goto err;
-    }
-#endif
     /*
      * We must OPENSSL_malloc stuff, even for 0 bytes otherwise it signifies
      * a missing NULL parameter.
      */
-    s = OPENSSL_malloc(len == 0 ? 1 : (size_t)len);
+    s = OPENSSL_malloc((int)len + 1);
     if (s == NULL)
         goto err;
     ret->type = V_ASN1_INTEGER;
@@ -460,11 +454,11 @@ ASN1_INTEGER *d2i_ASN1_UINTEGER(ASN1_INTEGER **a, const unsigned char **pp,
             p++;
             len--;
         }
-        memcpy(s, p, (size_t)len);
+        memcpy(s, p, (int)len);
         p += len;
     }
 
-    ASN1_STRING_set0(ret, s, (int)len); /* len <= INT_MAX checked above */
+    ASN1_STRING_set0(ret, s, (int)len);
     if (a != NULL)
         (*a) = ret;
     *pp = p;
@@ -503,7 +497,7 @@ static ASN1_STRING *bn_to_asn1_string(const BIGNUM *bn, ASN1_STRING *ai,
     if (len == 0)
         len = 1;
 
-    if (ASN1_STRING_set_data(ret, NULL, len) == 0) {
+    if (ASN1_STRING_set(ret, NULL, len) == 0) {
         ERR_raise(ERR_LIB_ASN1, ERR_R_ASN1_LIB);
         goto err;
     }
diff --git a/crypto/asn1/a_mbstr.c b/crypto/asn1/a_mbstr.c
index e70fe92db5..b7a5284fa5 100644
--- a/crypto/asn1/a_mbstr.c
+++ b/crypto/asn1/a_mbstr.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -12,20 +12,17 @@
 #include "internal/cryptlib.h"
 #include "internal/unicode.h"
 #include 
-#include 
-
-#include 
 
 static int traverse_string(const unsigned char *p, int len, int inform,
-    int (*rfunc)(uint32_t value, void *in),
+    int (*rfunc)(unsigned long value, void *in),
     void *arg);
-static int in_utf8(uint32_t value, void *arg);
-static int out_utf8(uint32_t value, void *arg);
-static int type_str(uint32_t value, void *arg);
-static int cpy_asc(uint32_t value, void *arg);
-static int cpy_bmp(uint32_t value, void *arg);
-static int cpy_univ(uint32_t value, void *arg);
-static int cpy_utf8(uint32_t value, void *arg);
+static int in_utf8(unsigned long value, void *arg);
+static int out_utf8(unsigned long value, void *arg);
+static int type_str(unsigned long value, void *arg);
+static int cpy_asc(unsigned long value, void *arg);
+static int cpy_bmp(unsigned long value, void *arg);
+static int cpy_univ(unsigned long value, void *arg);
+static int cpy_utf8(unsigned long value, void *arg);
 
 /*
  * These functions take a string in UTF8, ASCII or multibyte form and a mask
@@ -43,7 +40,7 @@ int ASN1_mbstring_copy(ASN1_STRING **out, const unsigned char *in, int len,
 }
 
 int ASN1_mbstring_ncopy(ASN1_STRING **out, const unsigned char *in, int len,
-    int inform, unsigned long mask_in,
+    int inform, unsigned long mask,
     long minsize, long maxsize)
 {
     int str_type;
@@ -53,8 +50,7 @@ int ASN1_mbstring_ncopy(ASN1_STRING **out, const unsigned char *in, int len,
     ASN1_STRING *dest;
     unsigned char *p;
     int nchar;
-    uint32_t mask = (uint32_t)mask_in;
-    int (*cpyfunc)(uint32_t, void *) = NULL;
+    int (*cpyfunc)(unsigned long, void *) = NULL;
     if (len == -1) {
         size_t len_s = strlen((const char *)in);
 
@@ -69,9 +65,6 @@ int ASN1_mbstring_ncopy(ASN1_STRING **out, const unsigned char *in, int len,
     if (len < 0) {
         ERR_raise(ERR_LIB_ASN1, ERR_R_PASSED_INVALID_ARGUMENT);
         return -1;
-    } else if (len >= INT_MAX) {
-        ERR_raise(ERR_LIB_ASN1, ASN1_R_STRING_TOO_LONG);
-        return -1;
     }
 
     /* First do a string check and work out the number of characters */
@@ -130,10 +123,7 @@ int ASN1_mbstring_ncopy(ASN1_STRING **out, const unsigned char *in, int len,
         return -1;
     }
 
-    /*
-     * Now work out output format and string type.
-     * These checks should be in sync with the checks in type_str.
-     */
+    /* Now work out output format and string type */
     outform = MBSTRING_ASC;
     if (mask & B_ASN1_NUMERICSTRING)
         str_type = V_ASN1_NUMERICSTRING;
@@ -171,7 +161,7 @@ int ASN1_mbstring_ncopy(ASN1_STRING **out, const unsigned char *in, int len,
     }
     /* If both the same type just copy across */
     if (inform == outform) {
-        if (!ASN1_STRING_set_data(dest, in, len)) {
+        if (!ASN1_STRING_set(dest, in, len)) {
             if (free_out) {
                 ASN1_STRING_free(dest);
                 *out = NULL;
@@ -190,41 +180,18 @@ int ASN1_mbstring_ncopy(ASN1_STRING **out, const unsigned char *in, int len,
         break;
 
     case MBSTRING_BMP:
-        if (nchar > INT_MAX / 2) {
-            ERR_raise(ERR_LIB_ASN1, ASN1_R_STRING_TOO_LONG);
-            if (free_out) {
-                ASN1_STRING_free(dest);
-                *out = NULL;
-            }
-            return -1;
-        }
         outlen = nchar << 1;
         cpyfunc = cpy_bmp;
         break;
 
     case MBSTRING_UNIV:
-        if (nchar > INT_MAX / 4) {
-            ERR_raise(ERR_LIB_ASN1, ASN1_R_STRING_TOO_LONG);
-            if (free_out) {
-                ASN1_STRING_free(dest);
-                *out = NULL;
-            }
-            return -1;
-        }
         outlen = nchar << 2;
         cpyfunc = cpy_univ;
         break;
 
     case MBSTRING_UTF8:
         outlen = 0;
-        ret = traverse_string(in, len, inform, out_utf8, &outlen);
-        if (ret < 0) { /* error already raised in out_utf8() */
-            if (free_out) {
-                ASN1_STRING_free(dest);
-                *out = NULL;
-            }
-            return -1;
-        }
+        traverse_string(in, len, inform, out_utf8, &outlen);
         cpyfunc = cpy_utf8;
         break;
     }
@@ -248,25 +215,27 @@ int ASN1_mbstring_ncopy(ASN1_STRING **out, const unsigned char *in, int len,
  */
 
 static int traverse_string(const unsigned char *p, int len, int inform,
-    int (*rfunc)(uint32_t value, void *in),
+    int (*rfunc)(unsigned long value, void *in),
     void *arg)
 {
-    uint32_t value;
+    unsigned long value;
     int ret;
     while (len) {
         if (inform == MBSTRING_ASC) {
             value = *p++;
             len--;
         } else if (inform == MBSTRING_BMP) {
-            uint16_t tmp;
-            p = OPENSSL_load_u16_be(&tmp, p);
-            value = tmp;
+            value = *p++ << 8;
+            value |= *p++;
             len -= 2;
         } else if (inform == MBSTRING_UNIV) {
-            p = OPENSSL_load_u32_be(&value, p);
+            value = ((unsigned long)*p++) << 24;
+            value |= ((unsigned long)*p++) << 16;
+            value |= *p++ << 8;
+            value |= *p++;
             len -= 4;
         } else {
-            ret = ossl_utf8_getc_internal(p, len, &value);
+            ret = UTF8_getc(p, len, &value);
             if (ret < 0)
                 return -1;
             len -= ret;
@@ -285,7 +254,7 @@ static int traverse_string(const unsigned char *p, int len, int inform,
 
 /* Just count number of characters */
 
-static int in_utf8(uint32_t value, void *arg)
+static int in_utf8(unsigned long value, void *arg)
 {
     int *nchar;
 
@@ -298,20 +267,14 @@ static int in_utf8(uint32_t value, void *arg)
 
 /* Determine size of output as a UTF8 String */
 
-static int out_utf8(uint32_t value, void *arg)
+static int out_utf8(unsigned long value, void *arg)
 {
     int *outlen, len;
 
-    len = ossl_utf8_putc_internal(NULL, -1, value);
-    if (len <= 0) {
-        ERR_raise(ERR_LIB_ASN1, ASN1_R_INVALID_UTF8STRING);
+    len = UTF8_putc(NULL, -1, value);
+    if (len <= 0)
         return len;
-    }
     outlen = arg;
-    if (*outlen >= INT_MAX - len) {
-        ERR_raise(ERR_LIB_ASN1, ASN1_R_STRING_TOO_LONG);
-        return -1;
-    }
     *outlen += len;
     return 1;
 }
@@ -321,31 +284,11 @@ static int out_utf8(uint32_t value, void *arg)
  * "mask".
  */
 
-static int type_str(uint32_t value, void *arg)
+static int type_str(unsigned long value, void *arg)
 {
-    uint32_t usable_types = *((uint32_t *)arg);
-    uint32_t types = usable_types;
+    unsigned long types = *((unsigned long *)arg);
     const int native = value > INT_MAX ? INT_MAX : ossl_fromascii(value);
 
-    /*
-     * Clear out all the types which are not checked later. If any of those
-     * is present in the mask, then the UTF8 type will be added and checked
-     * below.
-     */
-    types &= B_ASN1_NUMERICSTRING | B_ASN1_PRINTABLESTRING
-        | B_ASN1_IA5STRING | B_ASN1_T61STRING | B_ASN1_BMPSTRING
-        | B_ASN1_UNIVERSALSTRING | B_ASN1_UTF8STRING;
-
-    /*
-     * If any other types were in the input mask, they're effectively treated
-     * as UTF8
-     */
-    if (types != usable_types)
-        types |= B_ASN1_UTF8STRING;
-
-    /*
-     * These checks should be in sync with ASN1_mbstring_ncopy.
-     */
     if ((types & B_ASN1_NUMERICSTRING) && !(ossl_isdigit(native) || native == ' '))
         types &= ~B_ASN1_NUMERICSTRING;
     if ((types & B_ASN1_PRINTABLESTRING) && !ossl_isasn1print(native))
@@ -360,13 +303,13 @@ static int type_str(uint32_t value, void *arg)
         types &= ~B_ASN1_UTF8STRING;
     if (!types)
         return -1;
-    *((uint32_t *)arg) = types;
+    *((unsigned long *)arg) = types;
     return 1;
 }
 
 /* Copy one byte per character ASCII like strings */
 
-static int cpy_asc(uint32_t value, void *arg)
+static int cpy_asc(unsigned long value, void *arg)
 {
     unsigned char **p, *q;
     p = arg;
@@ -378,7 +321,7 @@ static int cpy_asc(uint32_t value, void *arg)
 
 /* Copy two byte per character BMPStrings */
 
-static int cpy_bmp(uint32_t value, void *arg)
+static int cpy_bmp(unsigned long value, void *arg)
 {
     unsigned char **p, *q;
     p = arg;
@@ -391,7 +334,7 @@ static int cpy_bmp(uint32_t value, void *arg)
 
 /* Copy four byte per character UniversalStrings */
 
-static int cpy_univ(uint32_t value, void *arg)
+static int cpy_univ(unsigned long value, void *arg)
 {
     unsigned char **p, *q;
     p = arg;
@@ -406,15 +349,13 @@ static int cpy_univ(uint32_t value, void *arg)
 
 /* Copy to a UTF8String */
 
-static int cpy_utf8(uint32_t value, void *arg)
+static int cpy_utf8(unsigned long value, void *arg)
 {
     unsigned char **p;
     int ret;
     p = arg;
     /* We already know there is enough room so pass 0xff as the length */
-    ret = ossl_utf8_putc_internal(*p, 0xff, value);
-    if (ret < 0)
-        return ret;
+    ret = UTF8_putc(*p, 0xff, value);
     *p += ret;
     return 1;
 }
diff --git a/crypto/asn1/a_object.c b/crypto/asn1/a_object.c
index 126636dfd5..4860308821 100644
--- a/crypto/asn1/a_object.c
+++ b/crypto/asn1/a_object.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -50,8 +50,7 @@ int i2d_ASN1_OBJECT(const ASN1_OBJECT *a, unsigned char **pp)
 
 int a2d_ASN1_OBJECT(unsigned char *out, int olen, const char *buf, int num)
 {
-    int i, first, len = 0, use_bn;
-    char c;
+    int i, first, len = 0, c, use_bn;
     char ftmp[24], *tmp = ftmp;
     int tmpsize = sizeof(ftmp);
     const char *p;
@@ -293,7 +292,7 @@ ASN1_OBJECT *ossl_c2i_ASN1_OBJECT(ASN1_OBJECT **a, const unsigned char **pp,
     }
 
     if ((a == NULL) || ((*a) == NULL) || !((*a)->flags & ASN1_OBJECT_FLAG_DYNAMIC)) {
-        if ((ret = ossl_asn1_object_new()) == NULL)
+        if ((ret = ASN1_OBJECT_new()) == NULL)
             return NULL;
     } else {
         ret = (*a);
@@ -338,14 +337,7 @@ err:
     return NULL;
 }
 
-#ifndef OPENSSL_NO_DEPRECATED_4_0
 ASN1_OBJECT *ASN1_OBJECT_new(void)
-{
-    return NULL;
-}
-#endif /* OPENSSL_NO_DEPRECATED_4_0 */
-
-ASN1_OBJECT *ossl_asn1_object_new(void)
 {
     ASN1_OBJECT *ret;
 
diff --git a/crypto/asn1/a_octet.c b/crypto/asn1/a_octet.c
index 99df7539a1..4efb8ec517 100644
--- a/crypto/asn1/a_octet.c
+++ b/crypto/asn1/a_octet.c
@@ -25,11 +25,5 @@ int ASN1_OCTET_STRING_cmp(const ASN1_OCTET_STRING *a,
 int ASN1_OCTET_STRING_set(ASN1_OCTET_STRING *x, const unsigned char *d,
     int len)
 {
-    if (len < -1) {
-        ERR_raise(ERR_LIB_ASN1, ASN1_R_TOO_SMALL);
-        return 0;
-    }
-    if (len == -1)
-        return ASN1_STRING_set_string(x, (const char *)d);
-    return ASN1_STRING_set_data(x, d, len);
+    return ASN1_STRING_set(x, d, len);
 }
diff --git a/crypto/asn1/a_print.c b/crypto/asn1/a_print.c
index 774d6b1383..54e5042591 100644
--- a/crypto/asn1/a_print.c
+++ b/crypto/asn1/a_print.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -12,8 +12,6 @@
 #include "internal/cryptlib.h"
 #include 
 
-#include 
-
 int ASN1_PRINTABLE_type(const unsigned char *s, int len)
 {
     int c;
diff --git a/crypto/asn1/a_sign.c b/crypto/asn1/a_sign.c
index 58d58f81ff..7659cf8703 100644
--- a/crypto/asn1/a_sign.c
+++ b/crypto/asn1/a_sign.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -100,7 +100,7 @@ int ASN1_sign(i2d_of_void *i2d, X509_ALGOR *algor1, X509_ALGOR *algor2,
      * In the interests of compatibility, I'll make sure that the bit string
      * has a 'not-used bits' value of 0
      */
-    ossl_asn1_bit_string_set_unused_bits(signature, 0);
+    ossl_asn1_string_set_bits_left(signature, 0);
 err:
     EVP_MD_CTX_free(ctx);
     OPENSSL_clear_free((char *)buf_in, inll);
@@ -143,27 +143,11 @@ err:
     return rv;
 }
 
-static int replace_algor_contents_from_DER(X509_ALGOR *algor, const unsigned char *aid, size_t len)
-{
-    /* as a workaround for d2i_*() freeing its first argument, using NULL instead: */
-    X509_ALGOR *alg = d2i_X509_ALGOR(NULL, &aid, (long)len);
-    int ret;
-
-    if (alg == NULL) {
-        ERR_raise(ERR_LIB_ASN1, ASN1_R_DECODE_ERROR);
-        return 0;
-    }
-    ret = X509_ALGOR_copy(algor, alg);
-    X509_ALGOR_free(alg);
-    return ret;
-}
-
 int ASN1_item_sign_ctx(const ASN1_ITEM *it, X509_ALGOR *algor1,
     X509_ALGOR *algor2, ASN1_BIT_STRING *signature,
     const void *data, EVP_MD_CTX *ctx)
 {
     const EVP_MD *md;
-    EVP_PKEY_CTX *pctx;
     EVP_PKEY *pkey;
     unsigned char *buf_in = NULL, *buf_out = NULL;
     size_t inl = 0, outl = 0, outll = 0;
@@ -171,14 +155,7 @@ int ASN1_item_sign_ctx(const ASN1_ITEM *it, X509_ALGOR *algor1,
     int rv, pkey_id;
 
     md = EVP_MD_CTX_get0_md(ctx);
-    pctx = EVP_MD_CTX_get_pkey_ctx(ctx);
-
-    if (pctx == NULL) {
-        ERR_raise(ERR_LIB_ASN1, ASN1_R_CONTEXT_NOT_INITIALISED);
-        goto err;
-    }
-
-    pkey = EVP_PKEY_CTX_get0_pkey(pctx);
+    pkey = EVP_PKEY_CTX_get0_pkey(EVP_MD_CTX_get_pkey_ctx(ctx));
 
     if (pkey == NULL) {
         ERR_raise(ERR_LIB_ASN1, ASN1_R_CONTEXT_NOT_INITIALISED);
@@ -186,11 +163,13 @@ int ASN1_item_sign_ctx(const ASN1_ITEM *it, X509_ALGOR *algor1,
     }
 
     if (pkey->ameth == NULL) {
+        EVP_PKEY_CTX *pctx = EVP_MD_CTX_get_pkey_ctx(ctx);
         OSSL_PARAM params[2];
         unsigned char aid[128];
         size_t aid_len = 0;
 
-        if (!EVP_PKEY_CTX_IS_SIGNATURE_OP(pctx)) {
+        if (pctx == NULL
+            || !EVP_PKEY_CTX_IS_SIGNATURE_OP(pctx)) {
             ERR_raise(ERR_LIB_ASN1, ASN1_R_CONTEXT_NOT_INITIALISED);
             goto err;
         }
@@ -207,10 +186,23 @@ int ASN1_item_sign_ctx(const ASN1_ITEM *it, X509_ALGOR *algor1,
             goto err;
         }
 
-        if (algor1 != NULL && !replace_algor_contents_from_DER(algor1, aid, aid_len))
-            goto err;
-        if (algor2 != NULL && !replace_algor_contents_from_DER(algor2, aid, aid_len))
-            goto err;
+        if (algor1 != NULL) {
+            const unsigned char *pp = aid;
+
+            if (d2i_X509_ALGOR(&algor1, &pp, (long)aid_len) == NULL) {
+                ERR_raise(ERR_LIB_ASN1, ERR_R_INTERNAL_ERROR);
+                goto err;
+            }
+        }
+
+        if (algor2 != NULL) {
+            const unsigned char *pp = aid;
+
+            if (d2i_X509_ALGOR(&algor2, &pp, (long)aid_len) == NULL) {
+                ERR_raise(ERR_LIB_ASN1, ERR_R_INTERNAL_ERROR);
+                goto err;
+            }
+        }
 
         rv = 3;
     } else if (pkey->ameth->item_sign) {
@@ -288,7 +280,7 @@ int ASN1_item_sign_ctx(const ASN1_ITEM *it, X509_ALGOR *algor1,
      * In the interests of compatibility, I'll make sure that the bit string
      * has a 'not-used bits' value of 0
      */
-    ossl_asn1_bit_string_set_unused_bits(signature, 0);
+    ossl_asn1_string_set_bits_left(signature, 0);
 err:
     OPENSSL_clear_free((char *)buf_in, inl);
     OPENSSL_clear_free((char *)buf_out, outll);
diff --git a/crypto/asn1/a_strex.c b/crypto/asn1/a_strex.c
index 4315355632..17f7372026 100644
--- a/crypto/asn1/a_strex.c
+++ b/crypto/asn1/a_strex.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -11,14 +11,10 @@
 #include 
 #include "internal/cryptlib.h"
 #include "internal/sizes.h"
-#include "internal/unicode.h"
-#include "internal/safe_math.h"
 #include "crypto/asn1.h"
-#include 
 #include 
 #include 
 #include 
-#include 
 
 #include "charmap.h"
 
@@ -32,8 +28,6 @@
 
 #define ESC_FLAGS (ASN1_STRFLGS_ESC_2253 | ASN1_STRFLGS_ESC_2254 | ASN1_STRFLGS_ESC_QUOTE | ASN1_STRFLGS_ESC_CTRL | ASN1_STRFLGS_ESC_MSB)
 
-OSSL_SAFE_MATH_SIGNED(int, int)
-
 /*
  * Three IO functions for sending data to memory, a BIO and a FILE
  * pointer.
@@ -62,27 +56,27 @@ typedef int char_io(void *arg, const void *buf, int len);
 
 /*
  * This function handles display of strings, one character at a time. It is
- * passed a uint32_t for each character because it could come from 2 or
+ * passed an unsigned long for each character because it could come from 2 or
  * even 4 byte forms.
  */
 
-static int do_esc_char(uint32_t c, unsigned short flags, char *do_quotes,
+static int do_esc_char(unsigned long c, unsigned short flags, char *do_quotes,
     char_io *io_ch, void *arg)
 {
     unsigned short chflgs;
     unsigned char chtmp;
     char tmphex[HEX_SIZE(long) + 3];
 
-    if (c > UNICODE_MAX)
+    if (c > 0xffffffffL)
         return -1;
     if (c > 0xffff) {
-        BIO_snprintf(tmphex, sizeof(tmphex), "\\W%08" PRIX32, c);
+        BIO_snprintf(tmphex, sizeof(tmphex), "\\W%08lX", c);
         if (!io_ch(arg, tmphex, 10))
             return -1;
         return 10;
     }
     if (c > 0xff) {
-        BIO_snprintf(tmphex, sizeof(tmphex), "\\U%04" PRIX32, c);
+        BIO_snprintf(tmphex, sizeof(tmphex), "\\U%04lX", c);
         if (!io_ch(arg, tmphex, 6))
             return -1;
         return 6;
@@ -136,19 +130,15 @@ static int do_esc_char(uint32_t c, unsigned short flags, char *do_quotes,
  * appropriate.
  */
 
-static int do_buf(const unsigned char *buf, int buflen,
+static int do_buf(unsigned char *buf, int buflen,
     int type, unsigned short flags, char *quotes, char_io *io_ch,
     void *arg)
 {
     int i, outlen, len, charwidth;
     unsigned short orflags;
-    const unsigned char *p, *q;
-    uint32_t c;
+    unsigned char *p, *q;
+    unsigned long c;
 
-    if (buflen < 0)
-        return -1;
-    if (buflen == 0)
-        return 0;
     p = buf;
     q = buf + buflen;
     outlen = 0;
@@ -172,8 +162,6 @@ static int do_buf(const unsigned char *buf, int buflen,
     }
 
     while (p != q) {
-        uint16_t tmp;
-
         if (p == buf && flags & ASN1_STRFLGS_ESC_2253)
             orflags = CHARTYPE_FIRST_ESC_2253;
         else
@@ -181,12 +169,15 @@ static int do_buf(const unsigned char *buf, int buflen,
 
         switch (charwidth) {
         case 4:
-            p = OPENSSL_load_u32_be(&c, p);
+            c = ((unsigned long)*p++) << 24;
+            c |= ((unsigned long)*p++) << 16;
+            c |= ((unsigned long)*p++) << 8;
+            c |= *p++;
             break;
 
         case 2:
-            p = OPENSSL_load_u16_be(&tmp, p);
-            c = tmp;
+            c = ((unsigned long)*p++) << 8;
+            c |= *p++;
             break;
 
         case 1:
@@ -194,7 +185,7 @@ static int do_buf(const unsigned char *buf, int buflen,
             break;
 
         case 0:
-            i = ossl_utf8_getc_internal(p, buflen, &c);
+            i = UTF8_getc(p, buflen, &c);
             if (i < 0)
                 return -1; /* Invalid UTF8String */
             buflen -= i;
@@ -207,10 +198,8 @@ static int do_buf(const unsigned char *buf, int buflen,
             orflags = CHARTYPE_LAST_ESC_2253;
         if (type & BUF_TYPE_CONVUTF8) {
             unsigned char utfbuf[6];
-            int utflen = ossl_utf8_putc_internal(utfbuf, sizeof(utfbuf), c);
-
-            if (utflen < 0)
-                return -1; /* error happened with UTF8 */
+            int utflen;
+            utflen = UTF8_putc(utfbuf, sizeof(utfbuf), c);
             for (i = 0; i < utflen; i++) {
                 /*
                  * We don't need to worry about setting orflags correctly
@@ -243,10 +232,6 @@ static int do_hex_dump(char_io *io_ch, void *arg, unsigned char *buf,
     unsigned char *p, *q;
     char hextmp[2];
 
-    if (buflen < 0)
-        return -1;
-    if (buflen == 0)
-        return 0;
     if (arg) {
         p = buf;
         q = buf + buflen;
@@ -435,13 +420,12 @@ static int do_name_ex(char_io *io_ch, void *arg, const X509_NAME *n,
 {
     int i, prev = -1, orflags, cnt;
     int fn_opt, fn_nid;
-    const ASN1_OBJECT *fn;
+    ASN1_OBJECT *fn;
     const ASN1_STRING *val;
     const X509_NAME_ENTRY *ent;
     char objtmp[80];
     const char *objbuf;
     int outlen, len;
-    int err = 0;
     char *sep_dn, *sep_mv, *sep_eq;
     int sep_dn_len, sep_mv_len, sep_eq_len;
     if (indent < 0)
@@ -505,20 +489,14 @@ static int do_name_ex(char_io *io_ch, void *arg, const X509_NAME *n,
             if (prev == X509_NAME_ENTRY_set(ent)) {
                 if (!io_ch(arg, sep_mv, sep_mv_len))
                     return -1;
-                outlen = safe_add_int(outlen, sep_mv_len, &err);
-                if (err != 0)
-                    return -1;
+                outlen += sep_mv_len;
             } else {
                 if (!io_ch(arg, sep_dn, sep_dn_len))
                     return -1;
-                outlen = safe_add_int(outlen, sep_dn_len, &err);
-                if (err != 0)
-                    return -1;
+                outlen += sep_dn_len;
                 if (!do_indent(io_ch, arg, indent))
                     return -1;
-                outlen = safe_add_int(outlen, indent, &err);
-                if (err != 0)
-                    return -1;
+                outlen += indent;
             }
         }
         prev = X509_NAME_ENTRY_set(ent);
@@ -549,18 +527,11 @@ static int do_name_ex(char_io *io_ch, void *arg, const X509_NAME *n,
             if ((objlen < fld_len) && (flags & XN_FLAG_FN_ALIGN)) {
                 if (!do_indent(io_ch, arg, fld_len - objlen))
                     return -1;
-                outlen = safe_add_int(outlen, fld_len - objlen, &err);
-                if (err != 0)
-                    return -1;
+                outlen += fld_len - objlen;
             }
             if (!io_ch(arg, sep_eq, sep_eq_len))
                 return -1;
-            outlen = safe_add_int(outlen, objlen, &err);
-            if (err != 0)
-                return -1;
-            outlen = safe_add_int(outlen, sep_eq_len, &err);
-            if (err != 0)
-                return -1;
+            outlen += objlen + sep_eq_len;
         }
         /*
          * If the field name is unknown then fix up the DER dump flag. We
@@ -575,9 +546,7 @@ static int do_name_ex(char_io *io_ch, void *arg, const X509_NAME *n,
         len = do_print_ex(io_ch, arg, flags | orflags, val);
         if (len < 0)
             return -1;
-        outlen = safe_add_int(outlen, len, &err);
-        if (err != 0)
-            return -1;
+        outlen += len;
     }
     return outlen;
 }
diff --git a/crypto/asn1/a_strnid.c b/crypto/asn1/a_strnid.c
index 54117d50ee..889587133c 100644
--- a/crypto/asn1/a_strnid.c
+++ b/crypto/asn1/a_strnid.c
@@ -11,7 +11,6 @@
 #include "internal/cryptlib.h"
 #include 
 #include 
-#include "tbl_standard.h"
 
 static STACK_OF(ASN1_STRING_TABLE) *stable = NULL;
 static void st_free(ASN1_STRING_TABLE *tbl);
@@ -108,6 +107,8 @@ ASN1_STRING *ASN1_STRING_set_by_NID(ASN1_STRING **out,
  * Now the tables and helper functions for the string table:
  */
 
+#include "tbl_standard.h"
+
 static int sk_table_cmp(const ASN1_STRING_TABLE *const *a,
     const ASN1_STRING_TABLE *const *b)
 {
diff --git a/crypto/asn1/a_time.c b/crypto/asn1/a_time.c
index 341bd5142d..51536eb630 100644
--- a/crypto/asn1/a_time.c
+++ b/crypto/asn1/a_time.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -79,20 +79,33 @@ int ossl_asn1_time_to_tm(struct tm *tm, const ASN1_TIME *d)
     static const int max[9] = { 99, 99, 12, 31, 23, 59, 59, 12, 59 };
     static const int mdays[12] = { 31, 28, 31, 30, 31, 30, 31, 31, 30, 31, 30, 31 };
     char *a;
-    int n, i, i2, l, o, min_l, end = 6, btz = 5, md;
+    int n, i, i2, l, o, min_l, strict = 0, end = 6, btz = 5, md;
     struct tm tmp;
 #if defined(CHARSET_EBCDIC)
     const char upper_z = 0x5A, num_zero = 0x30, period = 0x2E, minus = 0x2D, plus = 0x2B;
 #else
     const char upper_z = 'Z', num_zero = '0', period = '.', minus = '-', plus = '+';
 #endif
-
+    /*
+     * ASN1_STRING_FLAG_X509_TIME is used to enforce RFC 5280
+     * time string format, in which:
+     *
+     * 1. "seconds" is a 'MUST'
+     * 2. "Zulu" timezone is a 'MUST'
+     * 3. "+|-" is not allowed to indicate a timezone
+     */
     if (d->type == V_ASN1_UTCTIME) {
         min_l = 13;
+        if (d->flags & ASN1_STRING_FLAG_X509_TIME) {
+            strict = 1;
+        }
     } else if (d->type == V_ASN1_GENERALIZEDTIME) {
         end = 7;
         btz = 6;
         min_l = 15;
+        if (d->flags & ASN1_STRING_FLAG_X509_TIME) {
+            strict = 1;
+        }
     } else {
         return 0;
     }
@@ -111,7 +124,7 @@ int ossl_asn1_time_to_tm(struct tm *tm, const ASN1_TIME *d)
     if (l < min_l)
         goto err;
     for (i = 0; i < end; i++) {
-        if ((i == btz) && ((a[o] == upper_z) || (a[o] == plus) || (a[o] == minus))) {
+        if (!strict && (i == btz) && ((a[o] == upper_z) || (a[o] == plus) || (a[o] == minus))) {
             i++;
             break;
         }
@@ -177,6 +190,9 @@ int ossl_asn1_time_to_tm(struct tm *tm, const ASN1_TIME *d)
      * digits.
      */
     if (d->type == V_ASN1_GENERALIZEDTIME && a[o] == period) {
+        if (strict)
+            /* RFC 5280 forbids fractional seconds */
+            goto err;
         if (++o == l)
             goto err;
         i = o;
@@ -197,7 +213,7 @@ int ossl_asn1_time_to_tm(struct tm *tm, const ASN1_TIME *d)
      */
     if (a[o] == upper_z) {
         o++;
-    } else if (((a[o] == plus) || (a[o] == minus))) {
+    } else if (!strict && ((a[o] == plus) || (a[o] == minus))) {
         int offsign = a[o] == minus ? 1 : -1;
         int offset = 0;
 
@@ -233,7 +249,7 @@ int ossl_asn1_time_to_tm(struct tm *tm, const ASN1_TIME *d)
         if (offset && !OPENSSL_gmtime_adj(&tmp, 0, offset * offsign))
             goto err;
     } else {
-        /* not Z, or not +/- */
+        /* not Z, or not +/- in non-strict mode */
         goto err;
     }
     if (o == l) {
@@ -271,7 +287,7 @@ ASN1_TIME *ossl_asn1_time_from_tm(ASN1_TIME *s, struct tm *ts, int type)
     if (tmps == NULL)
         return NULL;
 
-    if (!ASN1_STRING_set_data(tmps, NULL, len))
+    if (!ASN1_STRING_set(tmps, NULL, len))
         goto err;
 
     tmps->type = type;
@@ -369,53 +385,62 @@ int ASN1_TIME_set_string_X509(ASN1_TIME *s, const char *str)
 {
     ASN1_TIME t;
     struct tm tm;
+    int rv = 0;
     size_t len;
 
-    /* RFC 5280 4.1.2.5: Valid RFC5280 times must be either length 13 or 15. */
-    len = strlen(str);
-    switch (len) {
-    case 13:
-        t.type = V_ASN1_UTCTIME;
-        break;
-    case 15:
-        t.type = V_ASN1_GENERALIZEDTIME;
-        break;
-    default:
-        return 0;
-    }
-
-    /* RFC 5280 4.1.2.5 Valid RFC5280 times must end in 'Z'. */
-    if (str[len - 1] != 0x5A)
-        return 0;
-
+    if ((len = strlen(str)) >= INT_MAX)
+        goto out;
     t.length = (int)len;
     t.data = (unsigned char *)str;
+    t.flags = ASN1_STRING_FLAG_X509_TIME;
 
-    /*
-     * RFC 5280 Section 4.1.2.5 The following function is permissive
-     * and allows time zone offsets and time zones not Z, etc. As we
-     * have already failed and excluded anything not the correct length
-     * for the type, and anything not ending in a 'Z', Our time may
-     * not be any of these other cases, and still parse as a time.
-     */
-    if (!ossl_asn1_time_to_tm(&tm, &t))
-        return 0;
+    t.type = V_ASN1_UTCTIME;
 
-    if (s != NULL) {
-        /*
-         * Unlike every other type of nonconforming to RFC5280 time
-         * string, which causes this function to fail, a 15 character
-         * input string that ends up being in the UTC time range is not
-         * rejected. Instead, two digits of the year is removed from
-         * start of the input string so the result is a UTC time.
-         */
-        if (is_utc(tm.tm_year) && len == 15)
-            return ASN1_TIME_set_string(s, str + 2);
-
-        return ASN1_TIME_set_string(s, str);
+    if (!ASN1_TIME_check(&t)) {
+        t.type = V_ASN1_GENERALIZEDTIME;
+        if (!ASN1_TIME_check(&t))
+            goto out;
     }
 
-    return 1;
+    /*
+     * Per RFC 5280 (section 4.1.2.5.), the valid input time
+     * strings should be encoded with the following rules:
+     *
+     * 1. UTC: YYMMDDHHMMSSZ, if YY < 50 (20YY) --> UTC: YYMMDDHHMMSSZ
+     * 2. UTC: YYMMDDHHMMSSZ, if YY >= 50 (19YY) --> UTC: YYMMDDHHMMSSZ
+     * 3. G'd: YYYYMMDDHHMMSSZ, if YYYY >= 2050 --> G'd: YYYYMMDDHHMMSSZ
+     * 4. G'd: YYYYMMDDHHMMSSZ, if YYYY < 2050 --> UTC: YYMMDDHHMMSSZ
+     *
+     * Only strings of the 4th rule should be reformatted, but since a
+     * UTC can only present [1950, 2050), so if the given time string
+     * is less than 1950 (e.g. 19230419000000Z), we do nothing...
+     */
+
+    if (s != NULL && t.type == V_ASN1_GENERALIZEDTIME) {
+        if (!ossl_asn1_time_to_tm(&tm, &t))
+            goto out;
+        if (is_utc(tm.tm_year)) {
+            t.length -= 2;
+            /*
+             * it's OK to let original t.data go since that's assigned
+             * to a piece of memory allocated outside of this function.
+             * new t.data would be freed after ASN1_STRING_copy is done.
+             */
+            t.data = OPENSSL_zalloc(t.length + 1);
+            if (t.data == NULL)
+                goto out;
+            memcpy(t.data, str + 2, t.length);
+            t.type = V_ASN1_UTCTIME;
+        }
+    }
+
+    if (s == NULL || ASN1_STRING_copy((ASN1_STRING *)s, (ASN1_STRING *)&t))
+        rv = 1;
+
+    if (t.data != (unsigned char *)str)
+        OPENSSL_free(t.data);
+out:
+    return rv;
 }
 
 int ASN1_TIME_to_tm(const ASN1_TIME *s, struct tm *tm)
diff --git a/crypto/asn1/a_utf8.c b/crypto/asn1/a_utf8.c
index 76f5ccbda4..fb5999fa7f 100644
--- a/crypto/asn1/a_utf8.c
+++ b/crypto/asn1/a_utf8.c
@@ -11,7 +11,6 @@
 #include "internal/cryptlib.h"
 #include "internal/unicode.h"
 #include 
-#include 
 
 /* UTF8 utilities */
 
@@ -26,10 +25,10 @@
  * -4 = character encoded incorrectly (not minimal length).
  */
 
-int ossl_utf8_getc_internal(const unsigned char *str, int len, uint32_t *val)
+int UTF8_getc(const unsigned char *str, int len, unsigned long *val)
 {
     const unsigned char *p;
-    uint32_t value;
+    unsigned long value;
     int ret;
     if (len <= 0)
         return 0;
@@ -83,21 +82,6 @@ int ossl_utf8_getc_internal(const unsigned char *str, int len, uint32_t *val)
     return ret;
 }
 
-#if !defined(OPENSSL_NO_DEPRECATED_4_1)
-int UTF8_getc(const unsigned char *str, int len, unsigned long *val)
-{
-    uint32_t value = 0;
-    int ret;
-
-    ret = ossl_utf8_getc_internal(str, len, &value);
-
-    if (ret)
-        *val = (unsigned long)value;
-
-    return ret;
-}
-#endif /* !defined(OPENSSL_NO_DEPRECATED_4_1) */
-
 /*
  * This takes a character 'value' and writes the UTF8 encoded value in 'str'
  * where 'str' is a buffer containing 'len' characters. Returns the number of
@@ -106,7 +90,7 @@ int UTF8_getc(const unsigned char *str, int len, unsigned long *val)
  * characters. It will need at most 4 characters.
  */
 
-int ossl_utf8_putc_internal(unsigned char *str, int len, uint32_t value)
+int UTF8_putc(unsigned char *str, int len, unsigned long value)
 {
     if (!str)
         len = 4; /* Maximum we will need */
@@ -151,10 +135,3 @@ int ossl_utf8_putc_internal(unsigned char *str, int len, uint32_t value)
     }
     return -2;
 }
-
-#if !defined(OPENSSL_NO_DEPRECATED_4_1)
-int UTF8_putc(unsigned char *str, int len, unsigned long value)
-{
-    return ossl_utf8_putc_internal(str, len, (uint32_t)value);
-}
-#endif
diff --git a/crypto/asn1/a_verify.c b/crypto/asn1/a_verify.c
index 5dae9e9c75..55f86ee83f 100644
--- a/crypto/asn1/a_verify.c
+++ b/crypto/asn1/a_verify.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -28,7 +28,7 @@ int ASN1_verify(i2d_of_void *i2d, X509_ALGOR *a, ASN1_BIT_STRING *signature,
     char *data, EVP_PKEY *pkey)
 {
     EVP_MD_CTX *ctx = EVP_MD_CTX_new();
-    EVP_MD *type = NULL;
+    const EVP_MD *type;
     unsigned char *p, *buf_in = NULL;
     int ret = -1, i, inl;
 
@@ -37,7 +37,7 @@ int ASN1_verify(i2d_of_void *i2d, X509_ALGOR *a, ASN1_BIT_STRING *signature,
         goto err;
     }
     i = OBJ_obj2nid(a->algorithm);
-    type = EVP_MD_fetch(NULL, OBJ_nid2sn(i), NULL);
+    type = EVP_get_digestbyname(OBJ_nid2sn(i));
     if (type == NULL) {
         ERR_raise(ERR_LIB_ASN1, ASN1_R_UNKNOWN_MESSAGE_DIGEST_ALGORITHM);
         goto err;
@@ -79,33 +79,46 @@ int ASN1_verify(i2d_of_void *i2d, X509_ALGOR *a, ASN1_BIT_STRING *signature,
     }
     ret = 1;
 err:
-    EVP_MD_free(type);
     EVP_MD_CTX_free(ctx);
     return ret;
 }
 
 #endif
 
-static int item_verify(const ASN1_ITEM *it, const X509_ALGOR *alg,
+int ASN1_item_verify(const ASN1_ITEM *it, const X509_ALGOR *alg,
     const ASN1_BIT_STRING *signature, const void *data,
-    EVP_MD_CTX *ctx, OSSL_LIB_CTX *libctx, const char *propq)
+    EVP_PKEY *pkey)
+{
+    return ASN1_item_verify_ex(it, alg, signature, data, NULL, pkey, NULL, NULL);
+}
+
+int ASN1_item_verify_ex(const ASN1_ITEM *it, const X509_ALGOR *alg,
+    const ASN1_BIT_STRING *signature, const void *data,
+    const ASN1_OCTET_STRING *id, EVP_PKEY *pkey,
+    OSSL_LIB_CTX *libctx, const char *propq)
+{
+    EVP_MD_CTX *ctx;
+    int rv = -1;
+
+    if ((ctx = evp_md_ctx_new_ex(pkey, id, libctx, propq)) != NULL) {
+        rv = ASN1_item_verify_ctx(it, alg, signature, data, ctx);
+        EVP_PKEY_CTX_free(EVP_MD_CTX_get_pkey_ctx(ctx));
+        EVP_MD_CTX_free(ctx);
+    }
+    return rv;
+}
+
+int ASN1_item_verify_ctx(const ASN1_ITEM *it, const X509_ALGOR *alg,
+    const ASN1_BIT_STRING *signature, const void *data,
+    EVP_MD_CTX *ctx)
 {
-    EVP_PKEY_CTX *pctx;
     EVP_PKEY *pkey;
-    EVP_MD *type = NULL;
     unsigned char *buf_in = NULL;
     int ret = -1, inl = 0;
     int mdnid, pknid;
     size_t inll = 0;
 
-    pctx = EVP_MD_CTX_get_pkey_ctx(ctx);
-
-    if (pctx == NULL) {
-        ERR_raise(ERR_LIB_ASN1, ASN1_R_CONTEXT_NOT_INITIALISED);
-        return -1;
-    }
-
-    pkey = EVP_PKEY_CTX_get0_pkey(pctx);
+    pkey = EVP_PKEY_CTX_get0_pkey(EVP_MD_CTX_get_pkey_ctx(ctx));
 
     if (pkey == NULL) {
         ERR_raise(ERR_LIB_ASN1, ERR_R_PASSED_NULL_PARAMETER);
@@ -140,6 +153,8 @@ static int item_verify(const ASN1_ITEM *it, const X509_ALGOR *alg,
         if (ret <= 1)
             goto err;
     } else {
+        const EVP_MD *type = NULL;
+
         /*
          * We don't yet have the ability for providers to be able to handle
          * X509_ALGOR style parameters. Fortunately the only one that needs this
@@ -164,7 +179,7 @@ static int item_verify(const ASN1_ITEM *it, const X509_ALGOR *alg,
             }
 
             if (mdnid != NID_undef) {
-                type = EVP_MD_fetch(libctx, OBJ_nid2sn(mdnid), propq);
+                type = EVP_get_digestbynid(mdnid);
                 if (type == NULL) {
                     ERR_raise_data(ERR_LIB_ASN1,
                         ASN1_R_UNKNOWN_MESSAGE_DIGEST_ALGORITHM,
@@ -206,37 +221,6 @@ static int item_verify(const ASN1_ITEM *it, const X509_ALGOR *alg,
     }
     ret = 1;
 err:
-    EVP_MD_free(type);
     OPENSSL_clear_free(buf_in, inll);
     return ret;
 }
-
-int ASN1_item_verify(const ASN1_ITEM *it, const X509_ALGOR *alg,
-    const ASN1_BIT_STRING *signature, const void *data,
-    EVP_PKEY *pkey)
-{
-    return ASN1_item_verify_ex(it, alg, signature, data, NULL, pkey, NULL, NULL);
-}
-
-int ASN1_item_verify_ex(const ASN1_ITEM *it, const X509_ALGOR *alg,
-    const ASN1_BIT_STRING *signature, const void *data,
-    const ASN1_OCTET_STRING *id, EVP_PKEY *pkey,
-    OSSL_LIB_CTX *libctx, const char *propq)
-{
-    EVP_MD_CTX *ctx;
-    int rv = -1;
-
-    if ((ctx = evp_md_ctx_new_ex(pkey, id, libctx, propq)) != NULL) {
-        rv = item_verify(it, alg, signature, data, ctx, libctx, propq);
-        EVP_PKEY_CTX_free(EVP_MD_CTX_get_pkey_ctx(ctx));
-        EVP_MD_CTX_free(ctx);
-    }
-    return rv;
-}
-
-int ASN1_item_verify_ctx(const ASN1_ITEM *it, const X509_ALGOR *alg,
-    const ASN1_BIT_STRING *signature, const void *data,
-    EVP_MD_CTX *ctx)
-{
-    return item_verify(it, alg, signature, data, ctx, NULL, NULL);
-}
diff --git a/crypto/asn1/ameth_lib.c b/crypto/asn1/ameth_lib.c
index a015203583..de63ea96bd 100644
--- a/crypto/asn1/ameth_lib.c
+++ b/crypto/asn1/ameth_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,6 +7,11 @@
  * https://www.openssl.org/source/license.html
  */
 
+/*
+ * We need to use some EVP_PKEY_asn1 deprecated APIs
+ */
+#include "internal/deprecated.h"
+
 #include "internal/cryptlib.h"
 #include 
 #include 
@@ -17,6 +22,7 @@
 #include "standard_methods.h"
 
 typedef int sk_cmp_fn_type(const char *const *a, const char *const *b);
+static STACK_OF(EVP_PKEY_ASN1_METHOD) *app_methods = NULL;
 
 DECLARE_OBJ_BSEARCH_CMP_FN(const EVP_PKEY_ASN1_METHOD *,
     const EVP_PKEY_ASN1_METHOD *, ameth);
@@ -30,20 +36,23 @@ static int ameth_cmp(const EVP_PKEY_ASN1_METHOD *const *a,
 IMPLEMENT_OBJ_BSEARCH_CMP_FN(const EVP_PKEY_ASN1_METHOD *,
     const EVP_PKEY_ASN1_METHOD *, ameth);
 
-int evp_pkey_asn1_get_count(void)
+int EVP_PKEY_asn1_get_count(void)
 {
     int num = OSSL_NELEM(standard_methods);
+    if (app_methods)
+        num += sk_EVP_PKEY_ASN1_METHOD_num(app_methods);
     return num;
 }
 
-const EVP_PKEY_ASN1_METHOD *evp_pkey_asn1_get0(int idx)
+const EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_get0(int idx)
 {
     int num = OSSL_NELEM(standard_methods);
-
-    if (idx < 0 || idx >= num)
+    if (idx < 0)
         return NULL;
-
-    return standard_methods[idx];
+    if (idx < num)
+        return standard_methods[idx];
+    idx -= num;
+    return sk_EVP_PKEY_ASN1_METHOD_value(app_methods, idx);
 }
 
 static const EVP_PKEY_ASN1_METHOD *pkey_asn1_find(int type)
@@ -52,6 +61,12 @@ static const EVP_PKEY_ASN1_METHOD *pkey_asn1_find(int type)
     const EVP_PKEY_ASN1_METHOD *t = &tmp, **ret;
 
     tmp.pkey_id = type;
+    if (app_methods) {
+        int idx;
+        idx = sk_EVP_PKEY_ASN1_METHOD_find(app_methods, &tmp);
+        if (idx >= 0)
+            return sk_EVP_PKEY_ASN1_METHOD_value(app_methods, idx);
+    }
     ret = OBJ_bsearch_ameth(&t, standard_methods, OSSL_NELEM(standard_methods));
     if (ret == NULL || *ret == NULL)
         return NULL;
@@ -63,7 +78,7 @@ static const EVP_PKEY_ASN1_METHOD *pkey_asn1_find(int type)
  * `type`. If pe is not NULL, the function will set *pe to NULL to indicate no
  * engine is used.
  */
-const EVP_PKEY_ASN1_METHOD *evp_pkey_asn1_find(int type)
+const EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_find(ENGINE **pe, int type)
 {
     const EVP_PKEY_ASN1_METHOD *t;
 
@@ -73,18 +88,25 @@ const EVP_PKEY_ASN1_METHOD *evp_pkey_asn1_find(int type)
             break;
         type = t->pkey_base_id;
     }
+    if (pe) {
+        *pe = NULL;
+    }
     return t;
 }
 
-const EVP_PKEY_ASN1_METHOD *evp_pkey_asn1_find_str(const char *str, int len)
+const EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_find_str(ENGINE **pe,
+    const char *str, int len)
 {
     int i;
     const EVP_PKEY_ASN1_METHOD *ameth = NULL;
 
     if (len == -1)
         len = (int)strlen(str);
-    for (i = evp_pkey_asn1_get_count(); i-- > 0;) {
-        ameth = evp_pkey_asn1_get0(i);
+    if (pe) {
+        *pe = NULL;
+    }
+    for (i = EVP_PKEY_asn1_get_count(); i-- > 0;) {
+        ameth = EVP_PKEY_asn1_get0(i);
         if (ameth->pkey_flags & ASN1_PKEY_ALIAS)
             continue;
         if ((int)strlen(ameth->pem_str) == len
@@ -94,7 +116,62 @@ const EVP_PKEY_ASN1_METHOD *evp_pkey_asn1_find_str(const char *str, int len)
     return NULL;
 }
 
-int evp_pkey_asn1_get0_info(int *ppkey_id, int *ppkey_base_id,
+int EVP_PKEY_asn1_add0(const EVP_PKEY_ASN1_METHOD *ameth)
+{
+    EVP_PKEY_ASN1_METHOD tmp = {
+        0,
+    };
+
+    /*
+     * One of the following must be true:
+     *
+     * pem_str == NULL AND ASN1_PKEY_ALIAS is set
+     * pem_str != NULL AND ASN1_PKEY_ALIAS is clear
+     *
+     * Anything else is an error and may lead to a corrupt ASN1 method table
+     */
+    if (!((ameth->pem_str == NULL
+              && (ameth->pkey_flags & ASN1_PKEY_ALIAS) != 0)
+            || (ameth->pem_str != NULL
+                && (ameth->pkey_flags & ASN1_PKEY_ALIAS) == 0))) {
+        ERR_raise(ERR_LIB_EVP, ERR_R_PASSED_INVALID_ARGUMENT);
+        return 0;
+    }
+
+    if (app_methods == NULL) {
+        app_methods = sk_EVP_PKEY_ASN1_METHOD_new(ameth_cmp);
+        if (app_methods == NULL)
+            return 0;
+    }
+
+    tmp.pkey_id = ameth->pkey_id;
+    if (sk_EVP_PKEY_ASN1_METHOD_find(app_methods, &tmp) >= 0) {
+        ERR_raise(ERR_LIB_EVP,
+            EVP_R_PKEY_APPLICATION_ASN1_METHOD_ALREADY_REGISTERED);
+        return 0;
+    }
+
+    if (!sk_EVP_PKEY_ASN1_METHOD_push(app_methods, ameth))
+        return 0;
+    sk_EVP_PKEY_ASN1_METHOD_sort(app_methods);
+    return 1;
+}
+
+int EVP_PKEY_asn1_add_alias(int to, int from)
+{
+    EVP_PKEY_ASN1_METHOD *ameth;
+    ameth = EVP_PKEY_asn1_new(from, ASN1_PKEY_ALIAS, NULL, NULL);
+    if (ameth == NULL)
+        return 0;
+    ameth->pkey_base_id = to;
+    if (!EVP_PKEY_asn1_add0(ameth)) {
+        EVP_PKEY_asn1_free(ameth);
+        return 0;
+    }
+    return 1;
+}
+
+int EVP_PKEY_asn1_get0_info(int *ppkey_id, int *ppkey_base_id,
     int *ppkey_flags, const char **pinfo,
     const char **ppem_str,
     const EVP_PKEY_ASN1_METHOD *ameth)
@@ -114,7 +191,223 @@ int evp_pkey_asn1_get0_info(int *ppkey_id, int *ppkey_base_id,
     return 1;
 }
 
-const EVP_PKEY_ASN1_METHOD *evp_pkey_get0_asn1(const EVP_PKEY *pkey)
+const EVP_PKEY_ASN1_METHOD *EVP_PKEY_get0_asn1(const EVP_PKEY *pkey)
 {
     return pkey->ameth;
 }
+
+EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_new(int id, int flags,
+    const char *pem_str, const char *info)
+{
+    EVP_PKEY_ASN1_METHOD *ameth = OPENSSL_zalloc(sizeof(*ameth));
+
+    if (ameth == NULL)
+        return NULL;
+
+    ameth->pkey_id = id;
+    ameth->pkey_base_id = id;
+    ameth->pkey_flags = flags | ASN1_PKEY_DYNAMIC;
+
+    if (info) {
+        ameth->info = OPENSSL_strdup(info);
+        if (ameth->info == NULL)
+            goto err;
+    }
+
+    if (pem_str) {
+        ameth->pem_str = OPENSSL_strdup(pem_str);
+        if (ameth->pem_str == NULL)
+            goto err;
+    }
+
+    return ameth;
+
+err:
+    EVP_PKEY_asn1_free(ameth);
+    return NULL;
+}
+
+void EVP_PKEY_asn1_copy(EVP_PKEY_ASN1_METHOD *dst,
+    const EVP_PKEY_ASN1_METHOD *src)
+{
+    int pkey_id = dst->pkey_id;
+    int pkey_base_id = dst->pkey_base_id;
+    unsigned long pkey_flags = dst->pkey_flags;
+    char *pem_str = dst->pem_str;
+    char *info = dst->info;
+
+    *dst = *src;
+
+    /* We only copy the function pointers so restore the other values */
+    dst->pkey_id = pkey_id;
+    dst->pkey_base_id = pkey_base_id;
+    dst->pkey_flags = pkey_flags;
+    dst->pem_str = pem_str;
+    dst->info = info;
+}
+
+void EVP_PKEY_asn1_free(EVP_PKEY_ASN1_METHOD *ameth)
+{
+    if (ameth && (ameth->pkey_flags & ASN1_PKEY_DYNAMIC)) {
+        OPENSSL_free(ameth->pem_str);
+        OPENSSL_free(ameth->info);
+        OPENSSL_free(ameth);
+    }
+}
+
+void EVP_PKEY_asn1_set_public(EVP_PKEY_ASN1_METHOD *ameth,
+    int (*pub_decode)(EVP_PKEY *pk,
+        const X509_PUBKEY *pub),
+    int (*pub_encode)(X509_PUBKEY *pub,
+        const EVP_PKEY *pk),
+    int (*pub_cmp)(const EVP_PKEY *a,
+        const EVP_PKEY *b),
+    int (*pub_print)(BIO *out,
+        const EVP_PKEY *pkey,
+        int indent, ASN1_PCTX *pctx),
+    int (*pkey_size)(const EVP_PKEY *pk),
+    int (*pkey_bits)(const EVP_PKEY *pk))
+{
+    ameth->pub_decode = pub_decode;
+    ameth->pub_encode = pub_encode;
+    ameth->pub_cmp = pub_cmp;
+    ameth->pub_print = pub_print;
+    ameth->pkey_size = pkey_size;
+    ameth->pkey_bits = pkey_bits;
+}
+
+void EVP_PKEY_asn1_set_private(EVP_PKEY_ASN1_METHOD *ameth,
+    int (*priv_decode)(EVP_PKEY *pk,
+        const PKCS8_PRIV_KEY_INFO
+            *p8inf),
+    int (*priv_encode)(PKCS8_PRIV_KEY_INFO *p8,
+        const EVP_PKEY *pk),
+    int (*priv_print)(BIO *out,
+        const EVP_PKEY *pkey,
+        int indent,
+        ASN1_PCTX *pctx))
+{
+    ameth->priv_decode = priv_decode;
+    ameth->priv_encode = priv_encode;
+    ameth->priv_print = priv_print;
+}
+
+void EVP_PKEY_asn1_set_param(EVP_PKEY_ASN1_METHOD *ameth,
+    int (*param_decode)(EVP_PKEY *pkey,
+        const unsigned char **pder,
+        int derlen),
+    int (*param_encode)(const EVP_PKEY *pkey,
+        unsigned char **pder),
+    int (*param_missing)(const EVP_PKEY *pk),
+    int (*param_copy)(EVP_PKEY *to,
+        const EVP_PKEY *from),
+    int (*param_cmp)(const EVP_PKEY *a,
+        const EVP_PKEY *b),
+    int (*param_print)(BIO *out,
+        const EVP_PKEY *pkey,
+        int indent, ASN1_PCTX *pctx))
+{
+    ameth->param_decode = param_decode;
+    ameth->param_encode = param_encode;
+    ameth->param_missing = param_missing;
+    ameth->param_copy = param_copy;
+    ameth->param_cmp = param_cmp;
+    ameth->param_print = param_print;
+}
+
+void EVP_PKEY_asn1_set_free(EVP_PKEY_ASN1_METHOD *ameth,
+    void (*pkey_free)(EVP_PKEY *pkey))
+{
+    ameth->pkey_free = pkey_free;
+}
+
+void EVP_PKEY_asn1_set_ctrl(EVP_PKEY_ASN1_METHOD *ameth,
+    int (*pkey_ctrl)(EVP_PKEY *pkey, int op,
+        long arg1, void *arg2))
+{
+    ameth->pkey_ctrl = pkey_ctrl;
+}
+
+void EVP_PKEY_asn1_set_security_bits(EVP_PKEY_ASN1_METHOD *ameth,
+    int (*pkey_security_bits)(const EVP_PKEY
+            *pk))
+{
+    ameth->pkey_security_bits = pkey_security_bits;
+}
+
+void EVP_PKEY_asn1_set_item(EVP_PKEY_ASN1_METHOD *ameth,
+    int (*item_verify)(EVP_MD_CTX *ctx,
+        const ASN1_ITEM *it,
+        const void *data,
+        const X509_ALGOR *a,
+        const ASN1_BIT_STRING *sig,
+        EVP_PKEY *pkey),
+    int (*item_sign)(EVP_MD_CTX *ctx,
+        const ASN1_ITEM *it,
+        const void *data,
+        X509_ALGOR *alg1,
+        X509_ALGOR *alg2,
+        ASN1_BIT_STRING *sig))
+{
+    ameth->item_sign = item_sign;
+    ameth->item_verify = item_verify;
+}
+
+void EVP_PKEY_asn1_set_siginf(EVP_PKEY_ASN1_METHOD *ameth,
+    int (*siginf_set)(X509_SIG_INFO *siginf,
+        const X509_ALGOR *alg,
+        const ASN1_STRING *sig))
+{
+    ameth->siginf_set = siginf_set;
+}
+
+void EVP_PKEY_asn1_set_check(EVP_PKEY_ASN1_METHOD *ameth,
+    int (*pkey_check)(const EVP_PKEY *pk))
+{
+    ameth->pkey_check = pkey_check;
+}
+
+void EVP_PKEY_asn1_set_public_check(EVP_PKEY_ASN1_METHOD *ameth,
+    int (*pkey_pub_check)(const EVP_PKEY *pk))
+{
+    ameth->pkey_public_check = pkey_pub_check;
+}
+
+void EVP_PKEY_asn1_set_param_check(EVP_PKEY_ASN1_METHOD *ameth,
+    int (*pkey_param_check)(const EVP_PKEY *pk))
+{
+    ameth->pkey_param_check = pkey_param_check;
+}
+
+void EVP_PKEY_asn1_set_set_priv_key(EVP_PKEY_ASN1_METHOD *ameth,
+    int (*set_priv_key)(EVP_PKEY *pk,
+        const unsigned char
+            *priv,
+        size_t len))
+{
+    ameth->set_priv_key = set_priv_key;
+}
+
+void EVP_PKEY_asn1_set_set_pub_key(EVP_PKEY_ASN1_METHOD *ameth,
+    int (*set_pub_key)(EVP_PKEY *pk,
+        const unsigned char *pub,
+        size_t len))
+{
+    ameth->set_pub_key = set_pub_key;
+}
+
+void EVP_PKEY_asn1_set_get_priv_key(EVP_PKEY_ASN1_METHOD *ameth,
+    int (*get_priv_key)(const EVP_PKEY *pk,
+        unsigned char *priv,
+        size_t *len))
+{
+    ameth->get_priv_key = get_priv_key;
+}
+
+void EVP_PKEY_asn1_set_get_pub_key(EVP_PKEY_ASN1_METHOD *ameth,
+    int (*get_pub_key)(const EVP_PKEY *pk,
+        unsigned char *pub,
+        size_t *len))
+{
+    ameth->get_pub_key = get_pub_key;
+}
diff --git a/crypto/asn1/asn1_gen.c b/crypto/asn1/asn1_gen.c
index 6fbf581b49..4561b227b1 100644
--- a/crypto/asn1/asn1_gen.c
+++ b/crypto/asn1/asn1_gen.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2002-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -149,8 +149,6 @@ static ASN1_TYPE *generate_v3(const char *str, X509V3_CTX *cnf, int depth,
     cpy_len = i2d_ASN1_TYPE(ret, &orig_der);
     ASN1_TYPE_free(ret);
     ret = NULL;
-    if (orig_der == NULL)
-        return NULL;
     /* Set point to start copying for modified encoding */
     cpy_start = orig_der;
 
@@ -651,7 +649,7 @@ static ASN1_TYPE *asn1_str2type(const char *str, int format, int utype)
             ERR_raise(ERR_LIB_ASN1, ERR_R_ASN1_LIB);
             goto bad_str;
         }
-        if (!ASN1_STRING_set_string(atmp->value.asn1_string, str)) {
+        if (!ASN1_STRING_set(atmp->value.asn1_string, str, -1)) {
             ERR_raise(ERR_LIB_ASN1, ERR_R_ASN1_LIB);
             goto bad_str;
         }
@@ -706,7 +704,7 @@ static ASN1_TYPE *asn1_str2type(const char *str, int format, int utype)
             atmp->value.asn1_string->length = rdlen;
             atmp->value.asn1_string->type = utype;
         } else if (format == ASN1_GEN_FORMAT_ASCII) {
-            if (!ASN1_STRING_set_string(atmp->value.asn1_string, str)) {
+            if (!ASN1_STRING_set(atmp->value.asn1_string, str, -1)) {
                 ERR_raise(ERR_LIB_ASN1, ERR_R_ASN1_LIB);
                 goto bad_str;
             }
@@ -724,7 +722,7 @@ static ASN1_TYPE *asn1_str2type(const char *str, int format, int utype)
         }
 
         if ((utype == V_ASN1_BIT_STRING) && no_unused)
-            ossl_asn1_bit_string_set_unused_bits(atmp->value.asn1_string, 0);
+            ossl_asn1_string_set_bits_left(atmp->value.asn1_string, 0);
 
         break;
 
diff --git a/crypto/asn1/asn1_item_list.c b/crypto/asn1/asn1_item_list.c
index b01fb738ac..2b57694e33 100644
--- a/crypto/asn1/asn1_item_list.c
+++ b/crypto/asn1/asn1_item_list.c
@@ -23,180 +23,7 @@
 #include 
 #include 
 
-static ASN1_ITEM_EXP *asn1_item_list[] = {
-
-    ASN1_ITEM_ref(ACCESS_DESCRIPTION),
-#ifndef OPENSSL_NO_RFC3779
-    ASN1_ITEM_ref(ASIdOrRange),
-    ASN1_ITEM_ref(ASIdentifierChoice),
-    ASN1_ITEM_ref(ASIdentifiers),
-#endif
-    ASN1_ITEM_ref(ASN1_ANY),
-    ASN1_ITEM_ref(ASN1_BIT_STRING),
-    ASN1_ITEM_ref(ASN1_BMPSTRING),
-    ASN1_ITEM_ref(ASN1_BOOLEAN),
-    ASN1_ITEM_ref(ASN1_ENUMERATED),
-    ASN1_ITEM_ref(ASN1_FBOOLEAN),
-    ASN1_ITEM_ref(ASN1_GENERALIZEDTIME),
-    ASN1_ITEM_ref(ASN1_GENERALSTRING),
-    ASN1_ITEM_ref(ASN1_IA5STRING),
-    ASN1_ITEM_ref(ASN1_INTEGER),
-    ASN1_ITEM_ref(ASN1_NULL),
-    ASN1_ITEM_ref(ASN1_OBJECT),
-    ASN1_ITEM_ref(ASN1_OCTET_STRING_NDEF),
-    ASN1_ITEM_ref(ASN1_OCTET_STRING),
-    ASN1_ITEM_ref(ASN1_PRINTABLESTRING),
-    ASN1_ITEM_ref(ASN1_PRINTABLE),
-    ASN1_ITEM_ref(ASN1_SEQUENCE_ANY),
-    ASN1_ITEM_ref(ASN1_SEQUENCE),
-    ASN1_ITEM_ref(ASN1_SET_ANY),
-    ASN1_ITEM_ref(ASN1_T61STRING),
-    ASN1_ITEM_ref(ASN1_TBOOLEAN),
-    ASN1_ITEM_ref(ASN1_TIME),
-    ASN1_ITEM_ref(ASN1_UNIVERSALSTRING),
-    ASN1_ITEM_ref(ASN1_UTCTIME),
-    ASN1_ITEM_ref(ASN1_UTF8STRING),
-    ASN1_ITEM_ref(ASN1_VISIBLESTRING),
-#ifndef OPENSSL_NO_RFC3779
-    ASN1_ITEM_ref(ASRange),
-#endif
-    ASN1_ITEM_ref(AUTHORITY_INFO_ACCESS),
-    ASN1_ITEM_ref(AUTHORITY_KEYID),
-    ASN1_ITEM_ref(BASIC_CONSTRAINTS),
-    ASN1_ITEM_ref(BIGNUM),
-    ASN1_ITEM_ref(CBIGNUM),
-    ASN1_ITEM_ref(CERTIFICATEPOLICIES),
-#ifndef OPENSSL_NO_CMS
-    ASN1_ITEM_ref(CMS_ContentInfo),
-    ASN1_ITEM_ref(CMS_EnvelopedData),
-    ASN1_ITEM_ref(CMS_ReceiptRequest),
-#endif
-    ASN1_ITEM_ref(CRL_DIST_POINTS),
-#ifndef OPENSSL_NO_DH
-    ASN1_ITEM_ref(DHparams),
-#endif
-    ASN1_ITEM_ref(DIRECTORYSTRING),
-    ASN1_ITEM_ref(DISPLAYTEXT),
-    ASN1_ITEM_ref(DIST_POINT_NAME),
-    ASN1_ITEM_ref(DIST_POINT),
-#ifndef OPENSSL_NO_EC
-#ifndef OPENSSL_NO_DEPRECATED_3_0
-    ASN1_ITEM_ref(ECPARAMETERS),
-    ASN1_ITEM_ref(ECPKPARAMETERS),
-#endif
-#endif
-    ASN1_ITEM_ref(EDIPARTYNAME),
-    ASN1_ITEM_ref(EXTENDED_KEY_USAGE),
-    ASN1_ITEM_ref(GENERAL_NAMES),
-    ASN1_ITEM_ref(GENERAL_NAME),
-    ASN1_ITEM_ref(GENERAL_SUBTREE),
-#ifndef OPENSSL_NO_RFC3779
-    ASN1_ITEM_ref(IPAddressChoice),
-    ASN1_ITEM_ref(IPAddressFamily),
-    ASN1_ITEM_ref(IPAddressOrRange),
-    ASN1_ITEM_ref(IPAddressRange),
-#endif
-    ASN1_ITEM_ref(ISSUING_DIST_POINT),
-#ifndef OPENSSL_NO_DEPRECATED_3_0
-    ASN1_ITEM_ref(LONG),
-#endif
-    ASN1_ITEM_ref(NAME_CONSTRAINTS),
-    ASN1_ITEM_ref(NETSCAPE_CERT_SEQUENCE),
-    ASN1_ITEM_ref(NETSCAPE_SPKAC),
-    ASN1_ITEM_ref(NETSCAPE_SPKI),
-    ASN1_ITEM_ref(NOTICEREF),
-#ifndef OPENSSL_NO_OCSP
-    ASN1_ITEM_ref(OCSP_BASICRESP),
-    ASN1_ITEM_ref(OCSP_CERTID),
-    ASN1_ITEM_ref(OCSP_CERTSTATUS),
-    ASN1_ITEM_ref(OCSP_CRLID),
-    ASN1_ITEM_ref(OCSP_ONEREQ),
-    ASN1_ITEM_ref(OCSP_REQINFO),
-    ASN1_ITEM_ref(OCSP_REQUEST),
-    ASN1_ITEM_ref(OCSP_RESPBYTES),
-    ASN1_ITEM_ref(OCSP_RESPDATA),
-    ASN1_ITEM_ref(OCSP_RESPID),
-    ASN1_ITEM_ref(OCSP_RESPONSE),
-    ASN1_ITEM_ref(OCSP_REVOKEDINFO),
-    ASN1_ITEM_ref(OCSP_SERVICELOC),
-    ASN1_ITEM_ref(OCSP_SIGNATURE),
-    ASN1_ITEM_ref(OCSP_SINGLERESP),
-#endif
-    ASN1_ITEM_ref(OTHERNAME),
-    ASN1_ITEM_ref(PBE2PARAM),
-    ASN1_ITEM_ref(PBEPARAM),
-    ASN1_ITEM_ref(PBKDF2PARAM),
-    ASN1_ITEM_ref(PKCS12_AUTHSAFES),
-    ASN1_ITEM_ref(PKCS12_BAGS),
-    ASN1_ITEM_ref(PKCS12_MAC_DATA),
-    ASN1_ITEM_ref(PKCS12_SAFEBAGS),
-    ASN1_ITEM_ref(PKCS12_SAFEBAG),
-    ASN1_ITEM_ref(PKCS12),
-    ASN1_ITEM_ref(PKCS7_ATTR_SIGN),
-    ASN1_ITEM_ref(PKCS7_ATTR_VERIFY),
-    ASN1_ITEM_ref(PKCS7_DIGEST),
-    ASN1_ITEM_ref(PKCS7_ENCRYPT),
-    ASN1_ITEM_ref(PKCS7_ENC_CONTENT),
-    ASN1_ITEM_ref(PKCS7_ENVELOPE),
-    ASN1_ITEM_ref(PKCS7_ISSUER_AND_SERIAL),
-    ASN1_ITEM_ref(PKCS7_RECIP_INFO),
-    ASN1_ITEM_ref(PKCS7_SIGNED),
-    ASN1_ITEM_ref(PKCS7_SIGNER_INFO),
-    ASN1_ITEM_ref(PKCS7_SIGN_ENVELOPE),
-    ASN1_ITEM_ref(PKCS7),
-    ASN1_ITEM_ref(PKCS8_PRIV_KEY_INFO),
-    ASN1_ITEM_ref(PKEY_USAGE_PERIOD),
-    ASN1_ITEM_ref(POLICYINFO),
-    ASN1_ITEM_ref(POLICYQUALINFO),
-    ASN1_ITEM_ref(POLICY_CONSTRAINTS),
-    ASN1_ITEM_ref(POLICY_MAPPINGS),
-    ASN1_ITEM_ref(POLICY_MAPPING),
-    ASN1_ITEM_ref(PROXY_CERT_INFO_EXTENSION),
-    ASN1_ITEM_ref(PROXY_POLICY),
-#ifndef OPENSSL_NO_DEPRECATED_3_0
-    ASN1_ITEM_ref(RSAPrivateKey),
-    ASN1_ITEM_ref(RSAPublicKey),
-    ASN1_ITEM_ref(RSA_OAEP_PARAMS),
-    ASN1_ITEM_ref(RSA_PSS_PARAMS),
-#endif
-#ifndef OPENSSL_NO_SCRYPT
-    ASN1_ITEM_ref(SCRYPT_PARAMS),
-#endif
-    ASN1_ITEM_ref(SXNETID),
-    ASN1_ITEM_ref(SXNET),
-    ASN1_ITEM_ref(ISSUER_SIGN_TOOL),
-    ASN1_ITEM_ref(USERNOTICE),
-    ASN1_ITEM_ref(X509_ACERT),
-    ASN1_ITEM_ref(X509_ALGORS),
-    ASN1_ITEM_ref(X509_ALGOR),
-    ASN1_ITEM_ref(X509_ATTRIBUTE),
-    ASN1_ITEM_ref(X509_CERT_AUX),
-    ASN1_ITEM_ref(X509_CINF),
-    ASN1_ITEM_ref(X509_CRL_INFO),
-    ASN1_ITEM_ref(X509_CRL),
-    ASN1_ITEM_ref(X509_EXTENSIONS),
-    ASN1_ITEM_ref(X509_EXTENSION),
-    ASN1_ITEM_ref(X509_NAME_ENTRY),
-    ASN1_ITEM_ref(X509_NAME),
-    ASN1_ITEM_ref(X509_PUBKEY),
-    ASN1_ITEM_ref(X509_REQ_INFO),
-    ASN1_ITEM_ref(X509_REQ),
-    ASN1_ITEM_ref(X509_REVOKED),
-    ASN1_ITEM_ref(X509_SIG),
-    ASN1_ITEM_ref(X509_VAL),
-    ASN1_ITEM_ref(X509),
-#ifndef OPENSSL_NO_DEPRECATED_3_0
-    ASN1_ITEM_ref(ZLONG),
-#endif
-    ASN1_ITEM_ref(INT32),
-    ASN1_ITEM_ref(UINT32),
-    ASN1_ITEM_ref(ZINT32),
-    ASN1_ITEM_ref(ZUINT32),
-    ASN1_ITEM_ref(INT64),
-    ASN1_ITEM_ref(UINT64),
-    ASN1_ITEM_ref(ZINT64),
-    ASN1_ITEM_ref(ZUINT64),
-};
+#include "asn1_item_list.h"
 
 const ASN1_ITEM *ASN1_ITEM_lookup(const char *name)
 {
diff --git a/crypto/asn1/asn1_item_list.h b/crypto/asn1/asn1_item_list.h
new file mode 100644
index 0000000000..f26954ecb7
--- /dev/null
+++ b/crypto/asn1/asn1_item_list.h
@@ -0,0 +1,183 @@
+/*
+ * Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+static ASN1_ITEM_EXP *asn1_item_list[] = {
+
+    ASN1_ITEM_ref(ACCESS_DESCRIPTION),
+#ifndef OPENSSL_NO_RFC3779
+    ASN1_ITEM_ref(ASIdOrRange),
+    ASN1_ITEM_ref(ASIdentifierChoice),
+    ASN1_ITEM_ref(ASIdentifiers),
+#endif
+    ASN1_ITEM_ref(ASN1_ANY),
+    ASN1_ITEM_ref(ASN1_BIT_STRING),
+    ASN1_ITEM_ref(ASN1_BMPSTRING),
+    ASN1_ITEM_ref(ASN1_BOOLEAN),
+    ASN1_ITEM_ref(ASN1_ENUMERATED),
+    ASN1_ITEM_ref(ASN1_FBOOLEAN),
+    ASN1_ITEM_ref(ASN1_GENERALIZEDTIME),
+    ASN1_ITEM_ref(ASN1_GENERALSTRING),
+    ASN1_ITEM_ref(ASN1_IA5STRING),
+    ASN1_ITEM_ref(ASN1_INTEGER),
+    ASN1_ITEM_ref(ASN1_NULL),
+    ASN1_ITEM_ref(ASN1_OBJECT),
+    ASN1_ITEM_ref(ASN1_OCTET_STRING_NDEF),
+    ASN1_ITEM_ref(ASN1_OCTET_STRING),
+    ASN1_ITEM_ref(ASN1_PRINTABLESTRING),
+    ASN1_ITEM_ref(ASN1_PRINTABLE),
+    ASN1_ITEM_ref(ASN1_SEQUENCE_ANY),
+    ASN1_ITEM_ref(ASN1_SEQUENCE),
+    ASN1_ITEM_ref(ASN1_SET_ANY),
+    ASN1_ITEM_ref(ASN1_T61STRING),
+    ASN1_ITEM_ref(ASN1_TBOOLEAN),
+    ASN1_ITEM_ref(ASN1_TIME),
+    ASN1_ITEM_ref(ASN1_UNIVERSALSTRING),
+    ASN1_ITEM_ref(ASN1_UTCTIME),
+    ASN1_ITEM_ref(ASN1_UTF8STRING),
+    ASN1_ITEM_ref(ASN1_VISIBLESTRING),
+#ifndef OPENSSL_NO_RFC3779
+    ASN1_ITEM_ref(ASRange),
+#endif
+    ASN1_ITEM_ref(AUTHORITY_INFO_ACCESS),
+    ASN1_ITEM_ref(AUTHORITY_KEYID),
+    ASN1_ITEM_ref(BASIC_CONSTRAINTS),
+    ASN1_ITEM_ref(BIGNUM),
+    ASN1_ITEM_ref(CBIGNUM),
+    ASN1_ITEM_ref(CERTIFICATEPOLICIES),
+#ifndef OPENSSL_NO_CMS
+    ASN1_ITEM_ref(CMS_ContentInfo),
+    ASN1_ITEM_ref(CMS_EnvelopedData),
+    ASN1_ITEM_ref(CMS_ReceiptRequest),
+#endif
+    ASN1_ITEM_ref(CRL_DIST_POINTS),
+#ifndef OPENSSL_NO_DH
+    ASN1_ITEM_ref(DHparams),
+#endif
+    ASN1_ITEM_ref(DIRECTORYSTRING),
+    ASN1_ITEM_ref(DISPLAYTEXT),
+    ASN1_ITEM_ref(DIST_POINT_NAME),
+    ASN1_ITEM_ref(DIST_POINT),
+#ifndef OPENSSL_NO_EC
+#ifndef OPENSSL_NO_DEPRECATED_3_0
+    ASN1_ITEM_ref(ECPARAMETERS),
+    ASN1_ITEM_ref(ECPKPARAMETERS),
+#endif
+#endif
+    ASN1_ITEM_ref(EDIPARTYNAME),
+    ASN1_ITEM_ref(EXTENDED_KEY_USAGE),
+    ASN1_ITEM_ref(GENERAL_NAMES),
+    ASN1_ITEM_ref(GENERAL_NAME),
+    ASN1_ITEM_ref(GENERAL_SUBTREE),
+#ifndef OPENSSL_NO_RFC3779
+    ASN1_ITEM_ref(IPAddressChoice),
+    ASN1_ITEM_ref(IPAddressFamily),
+    ASN1_ITEM_ref(IPAddressOrRange),
+    ASN1_ITEM_ref(IPAddressRange),
+#endif
+    ASN1_ITEM_ref(ISSUING_DIST_POINT),
+#ifndef OPENSSL_NO_DEPRECATED_3_0
+    ASN1_ITEM_ref(LONG),
+#endif
+    ASN1_ITEM_ref(NAME_CONSTRAINTS),
+    ASN1_ITEM_ref(NETSCAPE_CERT_SEQUENCE),
+    ASN1_ITEM_ref(NETSCAPE_SPKAC),
+    ASN1_ITEM_ref(NETSCAPE_SPKI),
+    ASN1_ITEM_ref(NOTICEREF),
+#ifndef OPENSSL_NO_OCSP
+    ASN1_ITEM_ref(OCSP_BASICRESP),
+    ASN1_ITEM_ref(OCSP_CERTID),
+    ASN1_ITEM_ref(OCSP_CERTSTATUS),
+    ASN1_ITEM_ref(OCSP_CRLID),
+    ASN1_ITEM_ref(OCSP_ONEREQ),
+    ASN1_ITEM_ref(OCSP_REQINFO),
+    ASN1_ITEM_ref(OCSP_REQUEST),
+    ASN1_ITEM_ref(OCSP_RESPBYTES),
+    ASN1_ITEM_ref(OCSP_RESPDATA),
+    ASN1_ITEM_ref(OCSP_RESPID),
+    ASN1_ITEM_ref(OCSP_RESPONSE),
+    ASN1_ITEM_ref(OCSP_REVOKEDINFO),
+    ASN1_ITEM_ref(OCSP_SERVICELOC),
+    ASN1_ITEM_ref(OCSP_SIGNATURE),
+    ASN1_ITEM_ref(OCSP_SINGLERESP),
+#endif
+    ASN1_ITEM_ref(OTHERNAME),
+    ASN1_ITEM_ref(PBE2PARAM),
+    ASN1_ITEM_ref(PBEPARAM),
+    ASN1_ITEM_ref(PBKDF2PARAM),
+    ASN1_ITEM_ref(PKCS12_AUTHSAFES),
+    ASN1_ITEM_ref(PKCS12_BAGS),
+    ASN1_ITEM_ref(PKCS12_MAC_DATA),
+    ASN1_ITEM_ref(PKCS12_SAFEBAGS),
+    ASN1_ITEM_ref(PKCS12_SAFEBAG),
+    ASN1_ITEM_ref(PKCS12),
+    ASN1_ITEM_ref(PKCS7_ATTR_SIGN),
+    ASN1_ITEM_ref(PKCS7_ATTR_VERIFY),
+    ASN1_ITEM_ref(PKCS7_DIGEST),
+    ASN1_ITEM_ref(PKCS7_ENCRYPT),
+    ASN1_ITEM_ref(PKCS7_ENC_CONTENT),
+    ASN1_ITEM_ref(PKCS7_ENVELOPE),
+    ASN1_ITEM_ref(PKCS7_ISSUER_AND_SERIAL),
+    ASN1_ITEM_ref(PKCS7_RECIP_INFO),
+    ASN1_ITEM_ref(PKCS7_SIGNED),
+    ASN1_ITEM_ref(PKCS7_SIGNER_INFO),
+    ASN1_ITEM_ref(PKCS7_SIGN_ENVELOPE),
+    ASN1_ITEM_ref(PKCS7),
+    ASN1_ITEM_ref(PKCS8_PRIV_KEY_INFO),
+    ASN1_ITEM_ref(PKEY_USAGE_PERIOD),
+    ASN1_ITEM_ref(POLICYINFO),
+    ASN1_ITEM_ref(POLICYQUALINFO),
+    ASN1_ITEM_ref(POLICY_CONSTRAINTS),
+    ASN1_ITEM_ref(POLICY_MAPPINGS),
+    ASN1_ITEM_ref(POLICY_MAPPING),
+    ASN1_ITEM_ref(PROXY_CERT_INFO_EXTENSION),
+    ASN1_ITEM_ref(PROXY_POLICY),
+#ifndef OPENSSL_NO_DEPRECATED_3_0
+    ASN1_ITEM_ref(RSAPrivateKey),
+    ASN1_ITEM_ref(RSAPublicKey),
+    ASN1_ITEM_ref(RSA_OAEP_PARAMS),
+    ASN1_ITEM_ref(RSA_PSS_PARAMS),
+#endif
+#ifndef OPENSSL_NO_SCRYPT
+    ASN1_ITEM_ref(SCRYPT_PARAMS),
+#endif
+    ASN1_ITEM_ref(SXNETID),
+    ASN1_ITEM_ref(SXNET),
+    ASN1_ITEM_ref(ISSUER_SIGN_TOOL),
+    ASN1_ITEM_ref(USERNOTICE),
+    ASN1_ITEM_ref(X509_ACERT),
+    ASN1_ITEM_ref(X509_ALGORS),
+    ASN1_ITEM_ref(X509_ALGOR),
+    ASN1_ITEM_ref(X509_ATTRIBUTE),
+    ASN1_ITEM_ref(X509_CERT_AUX),
+    ASN1_ITEM_ref(X509_CINF),
+    ASN1_ITEM_ref(X509_CRL_INFO),
+    ASN1_ITEM_ref(X509_CRL),
+    ASN1_ITEM_ref(X509_EXTENSIONS),
+    ASN1_ITEM_ref(X509_EXTENSION),
+    ASN1_ITEM_ref(X509_NAME_ENTRY),
+    ASN1_ITEM_ref(X509_NAME),
+    ASN1_ITEM_ref(X509_PUBKEY),
+    ASN1_ITEM_ref(X509_REQ_INFO),
+    ASN1_ITEM_ref(X509_REQ),
+    ASN1_ITEM_ref(X509_REVOKED),
+    ASN1_ITEM_ref(X509_SIG),
+    ASN1_ITEM_ref(X509_VAL),
+    ASN1_ITEM_ref(X509),
+#ifndef OPENSSL_NO_DEPRECATED_3_0
+    ASN1_ITEM_ref(ZLONG),
+#endif
+    ASN1_ITEM_ref(INT32),
+    ASN1_ITEM_ref(UINT32),
+    ASN1_ITEM_ref(ZINT32),
+    ASN1_ITEM_ref(ZUINT32),
+    ASN1_ITEM_ref(INT64),
+    ASN1_ITEM_ref(UINT64),
+    ASN1_ITEM_ref(ZINT64),
+    ASN1_ITEM_ref(ZUINT64),
+};
diff --git a/crypto/asn1/asn1_lib.c b/crypto/asn1/asn1_lib.c
index 4b9e720bad..892b984353 100644
--- a/crypto/asn1/asn1_lib.c
+++ b/crypto/asn1/asn1_lib.c
@@ -129,7 +129,7 @@ static int asn1_get_length(const unsigned char **pp, int *inf, long *rl,
         *inf = 0;
         i = *p & 0x7f;
         if (*p++ & 0x80) {
-            if (max < i)
+            if (max < i + 1)
                 return 0;
             /* Skip leading zeroes */
             while (i > 0 && *p == 0) {
@@ -248,15 +248,9 @@ int ASN1_object_size(int constructed, int length, int tag)
     return ret + length;
 }
 
-void ossl_asn1_bit_string_clear_unused_bits(ASN1_STRING *str)
+void ossl_asn1_string_set_bits_left(ASN1_STRING *str, unsigned int num)
 {
     str->flags &= ~0x07;
-    str->flags &= ~ASN1_STRING_FLAG_BITS_LEFT;
-}
-
-void ossl_asn1_bit_string_set_unused_bits(ASN1_STRING *str, unsigned int num)
-{
-    ossl_asn1_bit_string_clear_unused_bits(str);
     str->flags |= ASN1_STRING_FLAG_BITS_LEFT | (num & 0x07);
 }
 
@@ -265,8 +259,7 @@ int ASN1_STRING_copy(ASN1_STRING *dst, const ASN1_STRING *str)
     if (str == NULL)
         return 0;
     dst->type = str->type;
-    if (!ossl_asn1_string_set_internal(dst, str->data, str->length,
-            /*add_nul_byte=*/0))
+    if (!ASN1_STRING_set(dst, str->data, str->length))
         return 0;
     /* Copy flags but preserve embed value */
     dst->flags &= ASN1_STRING_FLAG_EMBED;
@@ -290,117 +283,66 @@ ASN1_STRING *ASN1_STRING_dup(const ASN1_STRING *str)
     return ret;
 }
 
-int ossl_asn1_string_set_internal(ASN1_STRING *str, const uint8_t *data,
-    int len_in, int add_nul_byte)
+int ASN1_STRING_set(ASN1_STRING *str, const void *_data, int len_in)
 {
-    size_t len, alloc_len;
+    unsigned char *c;
+    const char *data = _data;
+    size_t len;
 
-#ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
-    /*
-     * Force no NUL byte for callers that are requesting it
-     * 0 length object data will be NULL
-     */
-    add_nul_byte = 0;
-#endif
-    if (len_in < -1) {
-        ERR_raise(ERR_LIB_ASN1, ASN1_R_TOO_SMALL);
-        return 0;
-    }
-    if (len_in == -1) {
+    if (len_in < 0) {
         if (data == NULL)
             return 0;
-        len = strlen((const char *)data);
+        len = strlen(data);
     } else {
         len = (size_t)len_in;
     }
     /*
-     * Add one to the length to allow for adding an a '\0' terminator
-     * "even though this isn't strictly necessary".
+     * Verify that the length fits within an integer for assignment to
+     * str->length below.  The additional 1 is subtracted to allow for the
+     * '\0' terminator even though this isn't strictly necessary.
      */
-    alloc_len = add_nul_byte ? len + 1 : len;
-
-    if (alloc_len > INT_MAX) {
+    if (len > INT_MAX - 1) {
         ERR_raise(ERR_LIB_ASN1, ASN1_R_TOO_LARGE);
         return 0;
     }
-
-    if ((str->flags & ASN1_STRING_FLAG_DATA_NOT_OWNED)) {
-        str->data = NULL;
-        str->length = 0;
-        str->flags &= ~ASN1_STRING_FLAG_DATA_NOT_OWNED;
-    }
-
-    /* Ensure copying a 0 length data field is defined. */
-    if (alloc_len == 0) {
-        OPENSSL_free(str->data);
-        str->data = NULL;
-        str->length = 0;
-        return 1;
-    }
-
-    if ((size_t)str->length != alloc_len) {
-        uint8_t *c;
-        c = OPENSSL_realloc(str->length == 0 ? NULL : str->data, alloc_len);
-        if (c == NULL)
+    if ((size_t)str->length <= len || str->data == NULL) {
+        c = str->data;
+#ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
+        /* No NUL terminator in fuzzing builds */
+        str->data = OPENSSL_realloc(c, len != 0 ? len : 1);
+#else
+        str->data = OPENSSL_realloc(c, len + 1);
+#endif
+        if (str->data == NULL) {
+            str->data = c;
             return 0;
-        str->data = c;
-    }
-    /* length never includes the added \0 byte */
-    str->length = (int)len;
-
-    if (data != NULL && str->data != NULL) {
-        memcpy(str->data, data, len);
-        if (add_nul_byte) {
-            /*
-             * Add a '\0' terminator. This should not be necessary - but we add it as
-             * a safety precaution
-             */
-            str->data[len] = '\0';
         }
     }
-    ossl_asn1_bit_string_clear_unused_bits(str);
-
+    str->length = (int)len;
+    if (data != NULL) {
+        memcpy(str->data, data, len);
+#ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
+        /* Set the unused byte to something non NUL and printable. */
+        if (len == 0)
+            str->data[len] = '~';
+#else
+        /*
+         * Add a NUL terminator. This should not be necessary - but we add it as
+         * a safety precaution
+         */
+        str->data[len] = '\0';
+#endif
+    }
     return 1;
 }
 
-#ifndef OPENSSL_NO_DEPRECATED_4_1
-int ASN1_STRING_set(ASN1_STRING *str, const void *_data, int len_in)
-{
-    return ossl_asn1_string_set_internal(str, (const uint8_t *)_data, len_in,
-        /*add_nul_byte=*/1);
-}
-#endif
-
 void ASN1_STRING_set0(ASN1_STRING *str, void *data, int len)
 {
-    if (!(str->flags & ASN1_STRING_FLAG_DATA_NOT_OWNED)) {
-        OPENSSL_clear_free(str->data, str->length);
-    }
-    str->flags &= ~ASN1_STRING_FLAG_DATA_NOT_OWNED;
+    OPENSSL_free(str->data);
     str->data = data;
     str->length = len;
 }
 
-int ASN1_STRING_set_data(ASN1_STRING *str, const uint8_t *data, size_t len_in)
-{
-    if (str->type == V_ASN1_BIT_STRING) {
-        ERR_raise(ERR_LIB_ASN1, ASN1_R_ILLEGAL_BITSTRING_FORMAT);
-        return 0;
-    }
-    /* This will go away once ASN1_STRING can size_t internally */
-    if (len_in > INT_MAX) {
-        ERR_raise(ERR_LIB_ASN1, ASN1_R_TOO_LARGE);
-        return 0;
-    }
-    return ossl_asn1_string_set_internal(str, data, (int)len_in, /*add_nul_byte=*/0);
-}
-
-int ASN1_STRING_set_string(ASN1_STRING *str, const char *c_string)
-{
-    return ASN1_STRING_set_data(str, (const uint8_t *)c_string,
-        strlen(c_string));
-}
-
 ASN1_STRING *ASN1_STRING_new(void)
 {
     return ASN1_STRING_type_new(V_ASN1_OCTET_STRING);
@@ -417,75 +359,30 @@ ASN1_STRING *ASN1_STRING_type_new(int type)
     return ret;
 }
 
-ASN1_STRING *ASN1_STRING_new_not_owned(int type, const uint8_t *data,
-    size_t length)
-{
-    ASN1_STRING *ret;
-
-    if (type == V_ASN1_BIT_STRING)
-        return NULL;
-
-    if (data == NULL || length == 0)
-        return NULL;
-
-    if (length > INT_MAX)
-        return NULL;
-
-    ret = OPENSSL_zalloc(sizeof(*ret));
-    if (ret == NULL)
-        return NULL;
-
-    ret->type = type;
-    ret->data = (unsigned char *)data;
-    ret->length = (int)length;
-    ret->flags |= ASN1_STRING_FLAG_DATA_NOT_OWNED;
-
-    return ret;
-}
-
-void ossl_asn1_string_free_internal(ASN1_STRING *a, int clear, int embed)
+void ossl_asn1_string_embed_free(ASN1_STRING *a, int embed)
 {
     if (a == NULL)
         return;
-
-    if ((a->flags & ASN1_STRING_FLAG_DATA_NOT_OWNED)) {
-        a->data = NULL;
-        a->length = 0;
-        a->flags &= ~ASN1_STRING_FLAG_DATA_NOT_OWNED;
-    }
-
-    if (!(a->flags & ASN1_STRING_FLAG_NDEF)) {
-        if (clear)
-            OPENSSL_clear_free(a->data, a->length);
-        else
-            OPENSSL_free(a->data);
-    }
-    /*
-     * TODO(beck): Add an assert here to verify that the embed arg is
-     * always set to match the flag, and then get rid of the arg.
-     */
-    if (!embed && !(a->flags & ASN1_STRING_FLAG_EMBED)) {
-        if (clear)
-            OPENSSL_clear_free(a, sizeof(*a));
-        else
-            OPENSSL_free(a);
-    }
+    if (!(a->flags & ASN1_STRING_FLAG_NDEF))
+        OPENSSL_free(a->data);
+    if (embed == 0)
+        OPENSSL_free(a);
 }
 
 void ASN1_STRING_free(ASN1_STRING *a)
 {
     if (a == NULL)
         return;
-
-    ossl_asn1_string_free_internal(a, 0, a->flags & ASN1_STRING_FLAG_EMBED);
+    ossl_asn1_string_embed_free(a, a->flags & ASN1_STRING_FLAG_EMBED);
 }
 
 void ASN1_STRING_clear_free(ASN1_STRING *a)
 {
     if (a == NULL)
         return;
-
-    ossl_asn1_string_free_internal(a, 1, a->flags & ASN1_STRING_FLAG_EMBED);
+    if (a->data && !(a->flags & ASN1_STRING_FLAG_NDEF))
+        OPENSSL_cleanse(a->data, a->length);
+    ASN1_STRING_free(a);
 }
 
 int ASN1_STRING_cmp(const ASN1_STRING *a, const ASN1_STRING *b)
@@ -505,17 +402,10 @@ int ASN1_STRING_cmp(const ASN1_STRING *a, const ASN1_STRING *b)
     }
 }
 
-#ifndef OPENSSL_NO_DEPRECATED_4_1
 int ASN1_STRING_length(const ASN1_STRING *x)
 {
     return x->length;
 }
-#endif
-
-size_t ASN1_STRING_length_ex(const ASN1_STRING *x)
-{
-    return (size_t)x->length;
-}
 
 #ifndef OPENSSL_NO_DEPRECATED_3_0
 void ASN1_STRING_length_set(ASN1_STRING *x, int len)
@@ -552,7 +442,7 @@ char *ossl_sk_ASN1_UTF8STRING2text(STACK_OF(ASN1_UTF8STRING) *text,
         current = sk_ASN1_UTF8STRING_value(text, i);
         if (i > 0)
             length += sep_len;
-        length += ASN1_STRING_length_ex(current);
+        length += ASN1_STRING_length(current);
         if (max_len != 0 && length > max_len)
             return NULL;
     }
@@ -562,7 +452,7 @@ char *ossl_sk_ASN1_UTF8STRING2text(STACK_OF(ASN1_UTF8STRING) *text,
     p = result;
     for (i = 0; i < sk_ASN1_UTF8STRING_num(text); i++) {
         current = sk_ASN1_UTF8STRING_value(text, i);
-        length = ASN1_STRING_length_ex(current);
+        length = ASN1_STRING_length(current);
         if (i > 0 && sep_len > 0) {
             strncpy(p, sep, sep_len + 1); /* using + 1 to silence gcc warning */
             p += sep_len;
diff --git a/crypto/asn1/asn1_local.h b/crypto/asn1/asn1_local.h
index 6f3ee7983c..7796603dd4 100644
--- a/crypto/asn1/asn1_local.h
+++ b/crypto/asn1/asn1_local.h
@@ -1,5 +1,5 @@
 /*
- * Copyright 2005-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2005-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -9,10 +9,6 @@
 
 /* Internal ASN1 structures and functions: not for application use */
 
-#if !defined(OSSL_LIBCRYPTO_ASN1_ASN1_LOCAL_H)
-#define OSSL_LIBCRYPTO_ASN1_ASN1_LOCAL_H
-
-#include 
 #include "crypto/asn1.h"
 
 typedef const ASN1_VALUE const_ASN1_VALUE;
@@ -51,7 +47,7 @@ DEFINE_STACK_OF(MIME_PARAM)
 typedef struct mime_header_st MIME_HEADER;
 DEFINE_STACK_OF(MIME_HEADER)
 
-void ossl_asn1_string_free_internal(ASN1_STRING *a, int clear, int embed);
+void ossl_asn1_string_embed_free(ASN1_STRING *a, int embed);
 
 int ossl_asn1_get_choice_selector(ASN1_VALUE **pval, const ASN1_ITEM *it);
 int ossl_asn1_get_choice_selector_const(const ASN1_VALUE **pval,
@@ -67,8 +63,6 @@ const ASN1_TEMPLATE *ossl_asn1_do_adb(const ASN1_VALUE *val,
     const ASN1_TEMPLATE *tt,
     int nullerr);
 
-ASN1_OBJECT *ossl_asn1_object_new(void);
-
 int ossl_asn1_do_lock(ASN1_VALUE **pval, int op, const ASN1_ITEM *it);
 
 void ossl_asn1_enc_init(ASN1_VALUE **pval, const ASN1_ITEM *it);
@@ -84,7 +78,7 @@ void ossl_asn1_template_free(ASN1_VALUE **pval, const ASN1_TEMPLATE *tt);
 
 ASN1_OBJECT *ossl_c2i_ASN1_OBJECT(ASN1_OBJECT **a, const unsigned char **pp,
     long length);
-int ossl_i2c_ASN1_BIT_STRING(const ASN1_BIT_STRING *a, unsigned char **pp);
+int ossl_i2c_ASN1_BIT_STRING(ASN1_BIT_STRING *a, unsigned char **pp);
 ASN1_BIT_STRING *ossl_c2i_ASN1_BIT_STRING(ASN1_BIT_STRING **a,
     const unsigned char **pp, long length);
 int ossl_i2c_ASN1_INTEGER(ASN1_INTEGER *a, unsigned char **pp);
@@ -100,9 +94,3 @@ int ossl_asn1_item_ex_new_intern(ASN1_VALUE **pval, const ASN1_ITEM *it,
     OSSL_LIB_CTX *libctx, const char *propq);
 int ossl_asn1_time_time_t_to_tm(const time_t *time, struct tm *out_tm);
 int ossl_asn1_time_tm_to_time_t(const struct tm *tm, time_t *out);
-int ossl_asn1_call_aux_cb(const ASN1_AUX *aux, int operation,
-    const ASN1_VALUE **in, const ASN1_ITEM *it, void *exarg);
-int ossl_asn1_string_set_internal(ASN1_STRING *str, const uint8_t *data,
-    int len_in, int add_nul_byte);
-
-#endif /* !defined(OSSL_LIBCRYPTO_ASN1_ASN1_LOCAL_H) */
diff --git a/crypto/asn1/asn1_parse.c b/crypto/asn1/asn1_parse.c
index 27d09dc9fe..9b7e2a7939 100644
--- a/crypto/asn1/asn1_parse.c
+++ b/crypto/asn1/asn1_parse.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -17,8 +17,6 @@
 #define ASN1_PARSE_MAXDEPTH 128
 #endif
 
-#include 
-
 static int asn1_parse2(BIO *bp, const unsigned char **pp, long length,
     int offset, int depth, int indent, int dump);
 static int asn1_print_info(BIO *bp, long offset, int depth, int hl, long len,
diff --git a/crypto/asn1/asn_mime.c b/crypto/asn1/asn_mime.c
index af79f27bda..eff6f89fb6 100644
--- a/crypto/asn1/asn_mime.c
+++ b/crypto/asn1/asn_mime.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2008-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -157,6 +157,7 @@ static ASN1_VALUE *b64_read_asn1(BIO *bio, const ASN1_ITEM *it, ASN1_VALUE **x,
 
 static int asn1_write_micalg(BIO *out, STACK_OF(X509_ALGOR) *mdalgs)
 {
+    const EVP_MD *md;
     int i, have_unknown = 0, write_comma, ret = 0, md_nid;
     have_unknown = 0;
     write_comma = 0;
@@ -178,6 +179,21 @@ static int asn1_write_micalg(BIO *out, STACK_OF(X509_ALGOR) *mdalgs)
             continue;
         }
 
+        md = EVP_get_digestbynid(md_nid);
+        if (md && md->md_ctrl) {
+            int rv;
+            char *micstr;
+            rv = md->md_ctrl(NULL, EVP_MD_CTRL_MICALG, 0, &micstr);
+            if (rv > 0) {
+                rv = BIO_puts(out, micstr);
+                OPENSSL_free(micstr);
+                if (rv < 0)
+                    goto err;
+                continue;
+            }
+            if (rv != -2)
+                goto err;
+        }
         switch (md_nid) {
         case NID_sha1:
             if (BIO_puts(out, "sha1") < 0)
@@ -660,8 +676,10 @@ static int multi_split(BIO *bio, int flags, const char *bound, STACK_OF(BIO) **r
                     return 0;
                 BIO_set_mem_eof_return(bpart, 0);
             }
-            if (!sk_BIO_push(parts, bpart))
-                goto err;
+            if (!sk_BIO_push(parts, bpart)) {
+                BIO_free(bpart);
+                return 0;
+            }
             return 1;
         } else if (part != 0) {
             /* Strip (possibly CR +) LF from linebuf */
@@ -669,8 +687,10 @@ static int multi_split(BIO *bio, int flags, const char *bound, STACK_OF(BIO) **r
             if (first) {
                 first = 0;
                 if (bpart)
-                    if (!sk_BIO_push(parts, bpart))
-                        goto err;
+                    if (!sk_BIO_push(parts, bpart)) {
+                        BIO_free(bpart);
+                        return 0;
+                    }
                 bpart = BIO_new(BIO_s_mem());
                 if (bpart == NULL)
                     return 0;
@@ -684,18 +704,17 @@ static int multi_split(BIO *bio, int flags, const char *bound, STACK_OF(BIO) **r
 #endif
                     || (flags & SMIME_CRLFEOL) != 0) {
                     if (BIO_puts(bpart, "\r\n") < 0)
-                        goto err;
+                        return 0;
                 } else {
                     if (BIO_puts(bpart, "\n") < 0)
-                        goto err;
+                        return 0;
                 }
             }
             eol = next_eol;
             if (len > 0 && BIO_write(bpart, linebuf, len) != len)
-                goto err;
+                return 0;
         }
     }
-err:
     BIO_free(bpart);
     return 0;
 }
diff --git a/crypto/asn1/asn_pack.c b/crypto/asn1/asn_pack.c
index 3084993a34..e8b93030a2 100644
--- a/crypto/asn1/asn_pack.c
+++ b/crypto/asn1/asn_pack.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -11,8 +11,6 @@
 #include "internal/cryptlib.h"
 #include 
 
-#include 
-
 /* ASN1 packing and unpacking functions */
 
 ASN1_STRING *ASN1_item_pack(void *obj, const ASN1_ITEM *it, ASN1_STRING **oct)
diff --git a/crypto/asn1/bio_asn1.c b/crypto/asn1/bio_asn1.c
index 547faa5165..610d767d43 100644
--- a/crypto/asn1/bio_asn1.c
+++ b/crypto/asn1/bio_asn1.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -252,16 +252,11 @@ static int asn1_bio_flush_ex(BIO *b, BIO_ASN1_BUF_CTX *ctx,
     asn1_ps_func *cleanup, asn1_bio_state_t next)
 {
     int ret;
-    BIO *next_bio = BIO_next(b);
 
     if (ctx->ex_len <= 0)
         return 1;
-    if (next_bio == NULL)
-        return 0;
     for (;;) {
-        ret = BIO_write(next_bio, ctx->ex_buf + ctx->ex_pos, ctx->ex_len);
-        BIO_clear_retry_flags(b);
-        BIO_copy_next_retry(b);
+        ret = BIO_write(BIO_next(b), ctx->ex_buf + ctx->ex_pos, ctx->ex_len);
         if (ret <= 0)
             break;
         ctx->ex_len -= ret;
@@ -296,14 +291,10 @@ static int asn1_bio_setup_ex(BIO *b, BIO_ASN1_BUF_CTX *ctx,
 
 static int asn1_bio_read(BIO *b, char *in, int inl)
 {
-    int ret = 0;
     BIO *next = BIO_next(b);
     if (next == NULL)
         return 0;
-    ret = BIO_read(next, in, inl);
-    BIO_clear_retry_flags(b);
-    BIO_copy_next_retry(b);
-    return ret;
+    return BIO_read(next, in, inl);
 }
 
 static int asn1_bio_puts(BIO *b, const char *str)
@@ -318,14 +309,10 @@ static int asn1_bio_puts(BIO *b, const char *str)
 
 static int asn1_bio_gets(BIO *b, char *str, int size)
 {
-    int ret = 0;
     BIO *next = BIO_next(b);
     if (next == NULL)
         return 0;
-    ret = BIO_gets(next, str, size);
-    BIO_clear_retry_flags(b);
-    BIO_copy_next_retry(b);
-    return ret;
+    return BIO_gets(next, str, size);
 }
 
 static long asn1_bio_callback_ctrl(BIO *b, int cmd, BIO_info_cb *fp)
@@ -381,14 +368,6 @@ static long asn1_bio_ctrl(BIO *b, int cmd, long arg1, void *arg2)
         *(void **)arg2 = ctx->ex_arg;
         break;
 
-    case BIO_C_DO_STATE_MACHINE:
-        if (next == NULL)
-            return 0;
-        BIO_clear_retry_flags(b);
-        ret = BIO_ctrl(next, cmd, arg1, arg2);
-        BIO_copy_next_retry(b);
-        break;
-
     case BIO_CTRL_FLUSH:
         if (next == NULL)
             return 0;
@@ -407,24 +386,13 @@ static long asn1_bio_ctrl(BIO *b, int cmd, long arg1, void *arg2)
                 return ret;
         }
 
-        BIO_clear_retry_flags(b);
-        if (ctx->state == ASN1_STATE_DONE) {
-            ret = BIO_ctrl(next, cmd, arg1, arg2);
-            BIO_copy_next_retry(b);
-            return ret;
-        } else {
+        if (ctx->state == ASN1_STATE_DONE)
+            return BIO_ctrl(next, cmd, arg1, arg2);
+        else {
+            BIO_clear_retry_flags(b);
             return 0;
         }
 
-    case BIO_CTRL_EOF:
-        /*
-         * If there is no next BIO, BIO_read() returns 0, which means EOF.
-         * BIO_eof() should return 1 in this case.
-         */
-        if (next == NULL)
-            return 1;
-        return BIO_ctrl(next, cmd, arg1, arg2);
-
     default:
         if (next == NULL)
             return 0;
diff --git a/crypto/asn1/charmap.h b/crypto/asn1/charmap.h
index ca99f05b32..ac1eb076cc 100644
--- a/crypto/asn1/charmap.h
+++ b/crypto/asn1/charmap.h
@@ -2,7 +2,7 @@
  * WARNING: do not edit!
  * Generated by crypto/asn1/charmap.pl
  *
- * Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -10,10 +10,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_ASN1_CHARMAP_H)
-#define OSSL_LIBCRYPTO_ASN1_CHARMAP_H
-
-/* clang-format off */
 #define CHARTYPE_HOST_ANY 4096
 #define CHARTYPE_HOST_DOT 8192
 #define CHARTYPE_HOST_HYPHEN 16384
@@ -36,6 +32,3 @@ static const unsigned short char_type[] = {
     4112, 4112, 4112, 4112, 4112, 4112, 4112, 4112, 4112, 4112, 4112, 4112,
     4112, 4112, 4112,    0,    0,    0,    0,    2
 };
-/* clang-format on */
-
-#endif /* !defined(OSSL_LIBCRYPTO_ASN1_CHARMAP_H) */
diff --git a/crypto/asn1/charmap.pl b/crypto/asn1/charmap.pl
index 53add52825..78053dee15 100644
--- a/crypto/asn1/charmap.pl
+++ b/crypto/asn1/charmap.pl
@@ -101,10 +101,6 @@ print <type != V_ASN1_OCTET_STRING) || (a->value.octet_string == NULL)) {
@@ -42,13 +41,7 @@ int ASN1_TYPE_get_octetstring(const ASN1_TYPE *a, unsigned char *data, int max_l
         return -1;
     }
     p = ASN1_STRING_get0_data(a->value.octet_string);
-    tmp = ASN1_STRING_length_ex(a->value.octet_string);
-    if (tmp > INT_MAX) {
-        ERR_raise(ERR_LIB_ASN1, ASN1_R_TOO_LARGE);
-        return -1;
-    }
-    ret = (int)tmp;
-
+    ret = ASN1_STRING_length(a->value.octet_string);
     if (ret < max_len)
         num = ret;
     else
@@ -67,28 +60,14 @@ static ossl_inline void asn1_type_init_oct(ASN1_OCTET_STRING *oct,
     oct->flags = 0;
 }
 
-/*
- * This function copies 'anum' to 'num' and the data of 'oct' to 'data'.
- * If the length of 'data' > 'max_len', copies only the first 'max_len'
- * bytes, but returns the full length of 'oct'; this allows distinguishing
- * whether all the data was copied.
- */
 static int asn1_type_get_int_oct(ASN1_OCTET_STRING *oct, int32_t anum,
     long *num, unsigned char *data, int max_len)
 {
-    int ret, n;
-    size_t tmp;
+    int ret = ASN1_STRING_length(oct), n;
 
     if (num != NULL)
         *num = anum;
 
-    tmp = ASN1_STRING_length_ex(oct);
-
-    if (tmp > INT_MAX)
-        tmp = INT_MAX;
-
-    ret = (int)tmp;
-
     if (max_len > ret)
         n = ret;
     else
@@ -110,7 +89,7 @@ ASN1_SEQUENCE(asn1_int_oct) = {
     ASN1_SIMPLE(asn1_int_oct, oct, ASN1_OCTET_STRING)
 } static_ASN1_SEQUENCE_END(asn1_int_oct)
 
-DECLARE_ASN1_ITEM(asn1_int_oct)
+    DECLARE_ASN1_ITEM(asn1_int_oct)
 
 int ASN1_TYPE_set_int_octetstring(ASN1_TYPE *a, long num, unsigned char *data,
     int len)
@@ -127,13 +106,6 @@ int ASN1_TYPE_set_int_octetstring(ASN1_TYPE *a, long num, unsigned char *data,
     return 0;
 }
 
-/*
- * This function decodes an int-octet sequence and copies the integer to 'num'
- * and the data of octet to 'data'.
- * If the length of 'data' > 'max_len', copies only the first 'max_len'
- * bytes, but returns the full length of 'oct'; this allows distinguishing
- * whether all the data was copied.
- */
 int ASN1_TYPE_get_int_octetstring(const ASN1_TYPE *a, long *num,
     unsigned char *data, int max_len)
 {
@@ -173,7 +145,7 @@ ASN1_SEQUENCE(asn1_oct_int) = {
     ASN1_EMBED(asn1_oct_int, num, INT32)
 } static_ASN1_SEQUENCE_END(asn1_oct_int)
 
-DECLARE_ASN1_ITEM(asn1_oct_int)
+    DECLARE_ASN1_ITEM(asn1_oct_int)
 
 int ossl_asn1_type_set_octetstring_int(ASN1_TYPE *a, long num,
     unsigned char *data, int len)
@@ -190,13 +162,6 @@ int ossl_asn1_type_set_octetstring_int(ASN1_TYPE *a, long num,
     return 0;
 }
 
-/*
- * This function decodes an octet-int sequence and copies the data of octet
- * to 'data' and the integer to 'num'.
- * If the length of 'data' > 'max_len', copies only the first 'max_len'
- * bytes, but returns the full length of 'oct'; this allows distinguishing
- * whether all the data was copied.
- */
 int ossl_asn1_type_get_octetstring_int(const ASN1_TYPE *a, long *num,
     unsigned char *data, int max_len)
 {
diff --git a/crypto/asn1/f_int.c b/crypto/asn1/f_int.c
index c6d8bfd034..b1fd3f9467 100644
--- a/crypto/asn1/f_int.c
+++ b/crypto/asn1/f_int.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -13,8 +13,6 @@
 #include 
 #include 
 
-#include 
-
 int i2a_ASN1_INTEGER(BIO *bp, const ASN1_INTEGER *a)
 {
     int i, n = 0;
diff --git a/crypto/asn1/f_string.c b/crypto/asn1/f_string.c
index 3b96f91cfc..9fb34f495e 100644
--- a/crypto/asn1/f_string.c
+++ b/crypto/asn1/f_string.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -13,8 +13,6 @@
 #include 
 #include 
 
-#include 
-
 int i2a_ASN1_STRING(BIO *bp, const ASN1_STRING *a, int type)
 {
     int i, n = 0;
diff --git a/crypto/asn1/n_pkey.c b/crypto/asn1/n_pkey.c
index a8ce8ccc46..7b70d6c7a0 100644
--- a/crypto/asn1/n_pkey.c
+++ b/crypto/asn1/n_pkey.c
@@ -52,6 +52,6 @@ ASN1_SEQUENCE(NETSCAPE_PKEY) = {
     ASN1_SIMPLE(NETSCAPE_PKEY, private_key, ASN1_OCTET_STRING)
 } static_ASN1_SEQUENCE_END(NETSCAPE_PKEY)
 
-DECLARE_ASN1_FUNCTIONS(NETSCAPE_PKEY)
+    DECLARE_ASN1_FUNCTIONS(NETSCAPE_PKEY)
 DECLARE_ASN1_ENCODE_FUNCTIONS_name(NETSCAPE_PKEY, NETSCAPE_PKEY)
 IMPLEMENT_ASN1_FUNCTIONS(NETSCAPE_PKEY)
diff --git a/crypto/asn1/p5_scrypt.c b/crypto/asn1/p5_scrypt.c
index 9e1b537b9f..14c672bcb4 100644
--- a/crypto/asn1/p5_scrypt.c
+++ b/crypto/asn1/p5_scrypt.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -17,8 +17,6 @@
 #include 
 #include "crypto/evp.h"
 
-#include 
-
 #ifndef OPENSSL_NO_SCRYPT
 /* PKCS#5 scrypt password based encryption structures */
 
@@ -46,7 +44,7 @@ X509_ALGOR *PKCS5_pbe2_set_scrypt(const EVP_CIPHER *cipher,
     uint64_t p)
 {
     X509_ALGOR *scheme = NULL, *ret = NULL;
-    int alg_nid, ivlen;
+    int alg_nid;
     size_t keylen = 0;
     EVP_CIPHER_CTX *ctx = NULL;
     unsigned char iv[EVP_MAX_IV_LENGTH];
@@ -85,11 +83,10 @@ X509_ALGOR *PKCS5_pbe2_set_scrypt(const EVP_CIPHER *cipher,
     }
 
     /* Create random IV */
-    ivlen = EVP_CIPHER_get_iv_length(cipher);
-    if (ivlen > 0) {
+    if (EVP_CIPHER_get_iv_length(cipher)) {
         if (aiv)
-            memcpy(iv, aiv, ivlen);
-        else if (RAND_bytes(iv, ivlen) <= 0)
+            memcpy(iv, aiv, EVP_CIPHER_get_iv_length(cipher));
+        else if (RAND_bytes(iv, EVP_CIPHER_get_iv_length(cipher)) <= 0)
             goto err;
     }
 
@@ -173,7 +170,7 @@ static X509_ALGOR *pkcs5_scrypt_set(const unsigned char *salt, int saltlen,
         saltlen = PKCS5_DEFAULT_PBE2_SALT_LEN;
 
     /* This will either copy salt or grow the buffer */
-    if (ASN1_STRING_set_data(sparam->salt, salt, saltlen) == 0) {
+    if (ASN1_STRING_set(sparam->salt, salt, saltlen) == 0) {
         ERR_raise(ERR_LIB_ASN1, ERR_R_ASN1_LIB);
         goto err;
     }
diff --git a/crypto/asn1/p8_pkey.c b/crypto/asn1/p8_pkey.c
index 77f03e82ef..143f503dea 100644
--- a/crypto/asn1/p8_pkey.c
+++ b/crypto/asn1/p8_pkey.c
@@ -72,13 +72,11 @@ int PKCS8_pkey_get0(const ASN1_OBJECT **ppkalg,
     const unsigned char **pk, int *ppklen,
     const X509_ALGOR **pa, const PKCS8_PRIV_KEY_INFO *p8)
 {
-    if (ASN1_STRING_length_ex(p8->pkey) > INT_MAX)
-        return 0;
     if (ppkalg)
         *ppkalg = p8->pkeyalg->algorithm;
     if (pk) {
         *pk = ASN1_STRING_get0_data(p8->pkey);
-        *ppklen = (int)ASN1_STRING_length_ex(p8->pkey);
+        *ppklen = ASN1_STRING_length(p8->pkey);
     }
     if (pa)
         *pa = p8->pkeyalg;
diff --git a/crypto/asn1/standard_methods.h b/crypto/asn1/standard_methods.h
index b5f038969b..8b3d068de7 100644
--- a/crypto/asn1/standard_methods.h
+++ b/crypto/asn1/standard_methods.h
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,13 +7,7 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_CRYPTO_ASN1_STANDARD_METHODS_H)
-#define OSSL_CRYPTO_ASN1_STANDARD_METHODS_H
-
-#include 
-
-#include 
-
+#ifndef OPENSSL_NO_DEPRECATED_3_6
 /*
  * This table MUST be kept in ascending order of the NID each method
  * represents (corresponding to the pkey_id field) as OBJ_bsearch
@@ -48,4 +42,4 @@ static const EVP_PKEY_ASN1_METHOD *const standard_methods[] = {
     &ossl_sm2_asn1_meth,
 #endif
 };
-#endif /* !defined(OSSL_CRYPTO_ASN1_STANDARD_METHODS_H) */
+#endif
diff --git a/crypto/asn1/t_bitst.c b/crypto/asn1/t_bitst.c
index 4d691b304c..bee3f78543 100644
--- a/crypto/asn1/t_bitst.c
+++ b/crypto/asn1/t_bitst.c
@@ -12,8 +12,6 @@
 #include 
 #include 
 
-#if !defined(OPENSSL_NO_DEPRECATED_4_1)
-OSSL_BEGIN_ALLOW_DEPRECATED
 int ASN1_BIT_STRING_name_print(BIO *out, ASN1_BIT_STRING *bs,
     BIT_STRING_BITNAME *tbl, int indent)
 {
@@ -21,8 +19,7 @@ int ASN1_BIT_STRING_name_print(BIO *out, ASN1_BIT_STRING *bs,
     char first = 1;
     int last_seen_bit = -1;
 
-    if (BIO_printf(out, "%*s", indent, "") < 0)
-        return 0;
+    BIO_printf(out, "%*s", indent, "");
     for (bnam = tbl; bnam->lname; bnam++) {
         /*
          * Skip duplicate entries for the same bit in the BIT_STRING_BITNAME
@@ -35,15 +32,12 @@ int ASN1_BIT_STRING_name_print(BIO *out, ASN1_BIT_STRING *bs,
 
         if (ASN1_BIT_STRING_get_bit(bs, bnam->bitnum)) {
             if (!first)
-                if (BIO_puts(out, ", ") < 1)
-                    return 0;
-            if (BIO_puts(out, bnam->lname) < 1)
-                return 0;
+                BIO_puts(out, ", ");
+            BIO_puts(out, bnam->lname);
             first = 0;
         }
     }
-    if (BIO_puts(out, "\n") < 1)
-        return 0;
+    BIO_puts(out, "\n");
     return 1;
 }
 
@@ -71,5 +65,3 @@ int ASN1_BIT_STRING_num_asc(const char *name, BIT_STRING_BITNAME *tbl)
     }
     return -1;
 }
-OSSL_END_ALLOW_DEPRECATED
-#endif /* !defined(OPENSSL_NO_DEPRECATED_4_1) */
diff --git a/crypto/asn1/t_spki.c b/crypto/asn1/t_spki.c
index d313f102df..ab5fca73bc 100644
--- a/crypto/asn1/t_spki.c
+++ b/crypto/asn1/t_spki.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,8 +15,6 @@
 #include 
 #include 
 
-#include 
-
 /* Print out an SPKI */
 
 int NETSCAPE_SPKI_print(BIO *out, const NETSCAPE_SPKI *spki)
diff --git a/crypto/asn1/tasn_dec.c b/crypto/asn1/tasn_dec.c
index 911eb42be7..70ea5f0879 100644
--- a/crypto/asn1/tasn_dec.c
+++ b/crypto/asn1/tasn_dec.c
@@ -54,7 +54,7 @@ static int asn1_d2i_ex_primitive(ASN1_VALUE **pval,
     const ASN1_ITEM *it,
     int tag, int aclass, char opt,
     ASN1_TLC *ctx);
-static int asn1_ex_c2i(ASN1_VALUE **pval, const unsigned char *cont, long len,
+static int asn1_ex_c2i(ASN1_VALUE **pval, const unsigned char *cont, int len,
     int utype, char *free_cont, const ASN1_ITEM *it);
 
 /* Table to convert tags to bit values, used for MSTRING type */
@@ -855,24 +855,19 @@ err:
 
 /* Translate ASN1 content octets into a structure */
 
-static int asn1_ex_c2i(ASN1_VALUE **pval, const unsigned char *cont, long len,
+static int asn1_ex_c2i(ASN1_VALUE **pval, const unsigned char *cont, int len,
     int utype, char *free_cont, const ASN1_ITEM *it)
 {
     ASN1_VALUE **opval = NULL;
     ASN1_STRING *stmp;
     ASN1_TYPE *typ = NULL;
     int ret = 0;
-    int ilen = (int)len;
     const ASN1_PRIMITIVE_FUNCS *pf;
     ASN1_INTEGER **tint;
     pf = it->funcs;
 
-    if (pf && pf->prim_c2i) {
-        if (len == (long)ilen)
-            return pf->prim_c2i(pval, cont, ilen, utype, free_cont, it);
-        ERR_raise(ERR_LIB_ASN1, ASN1_R_TOO_LONG);
-        return 0;
-    }
+    if (pf && pf->prim_c2i)
+        return pf->prim_c2i(pval, cont, len, utype, free_cont, it);
     /* If ANY type clear type and set pointer to internal value */
     if (it->utype == V_ASN1_ANY) {
         if (*pval == NULL) {
@@ -890,8 +885,7 @@ static int asn1_ex_c2i(ASN1_VALUE **pval, const unsigned char *cont, long len,
     }
     switch (utype) {
     case V_ASN1_OBJECT:
-        if (len != (long)ilen
-            || !ossl_c2i_ASN1_OBJECT((ASN1_OBJECT **)pval, &cont, ilen))
+        if (!ossl_c2i_ASN1_OBJECT((ASN1_OBJECT **)pval, &cont, len))
             goto err;
         break;
 
@@ -946,10 +940,6 @@ static int asn1_ex_c2i(ASN1_VALUE **pval, const unsigned char *cont, long len,
     case V_ASN1_SET:
     case V_ASN1_SEQUENCE:
     default:
-        if (len != (long)ilen) {
-            ERR_raise(ERR_LIB_ASN1, ASN1_R_TOO_LONG);
-            goto err;
-        }
         if (utype == V_ASN1_BMPSTRING && (len & 1)) {
             ERR_raise(ERR_LIB_ASN1, ASN1_R_BMPSTRING_IS_WRONG_LENGTH);
             goto err;
@@ -980,10 +970,10 @@ static int asn1_ex_c2i(ASN1_VALUE **pval, const unsigned char *cont, long len,
         }
         /* If we've already allocated a buffer use it */
         if (*free_cont) {
-            ASN1_STRING_set0(stmp, (unsigned char *)cont /* UGLY CAST! */, ilen);
+            ASN1_STRING_set0(stmp, (unsigned char *)cont /* UGLY CAST! */, len);
             *free_cont = 0;
         } else {
-            if (!ASN1_STRING_set_data(stmp, cont, len)) {
+            if (!ASN1_STRING_set(stmp, cont, len)) {
                 ERR_raise(ERR_LIB_ASN1, ERR_R_ASN1_LIB);
                 ASN1_STRING_free(stmp);
                 *pval = NULL;
diff --git a/crypto/asn1/tasn_enc.c b/crypto/asn1/tasn_enc.c
index e489e29a0c..8dea9f3653 100644
--- a/crypto/asn1/tasn_enc.c
+++ b/crypto/asn1/tasn_enc.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -85,10 +85,16 @@ int ASN1_item_ex_i2d(const ASN1_VALUE **pval, unsigned char **out,
     int i, seqcontlen, seqlen, ndef = 1;
     const ASN1_EXTERN_FUNCS *ef;
     const ASN1_AUX *aux = it->funcs;
+    ASN1_aux_const_cb *asn1_cb = NULL;
 
     if ((it->itype != ASN1_ITYPE_PRIMITIVE) && *pval == NULL)
         return 0;
 
+    if (aux != NULL) {
+        asn1_cb = ((aux->flags & ASN1_AFLG_CONST_CB) != 0) ? aux->asn1_const_cb
+                                                           : (ASN1_aux_const_cb *)aux->asn1_cb; /* backward compatibility */
+    }
+
     switch (it->itype) {
 
     case ASN1_ITYPE_PRIMITIVE:
@@ -117,7 +123,7 @@ int ASN1_item_ex_i2d(const ASN1_VALUE **pval, unsigned char **out,
             ERR_raise(ERR_LIB_ASN1, ASN1_R_BAD_TEMPLATE);
             return -1;
         }
-        if (!ossl_asn1_call_aux_cb(aux, ASN1_OP_I2D_PRE, pval, it, NULL))
+        if (asn1_cb && !asn1_cb(ASN1_OP_I2D_PRE, pval, it, NULL))
             return 0;
         i = ossl_asn1_get_choice_selector_const(pval, it);
         if ((i >= 0) && (i < it->tcount)) {
@@ -128,7 +134,7 @@ int ASN1_item_ex_i2d(const ASN1_VALUE **pval, unsigned char **out,
             return asn1_template_ex_i2d(pchval, out, chtt, -1, aclass);
         }
         /* Fixme: error condition if selector out of range */
-        if (!ossl_asn1_call_aux_cb(aux, ASN1_OP_I2D_POST, pval, it, NULL))
+        if (asn1_cb && !asn1_cb(ASN1_OP_I2D_POST, pval, it, NULL))
             return 0;
         break;
 
@@ -160,7 +166,7 @@ int ASN1_item_ex_i2d(const ASN1_VALUE **pval, unsigned char **out,
             aclass = (aclass & ~ASN1_TFLG_TAG_CLASS)
                 | V_ASN1_UNIVERSAL;
         }
-        if (!ossl_asn1_call_aux_cb(aux, ASN1_OP_I2D_PRE, pval, it, NULL))
+        if (asn1_cb && !asn1_cb(ASN1_OP_I2D_PRE, pval, it, NULL))
             return 0;
         /* First work out sequence content length */
         for (i = 0, tt = it->templates; i < it->tcount; tt++, i++) {
@@ -194,7 +200,7 @@ int ASN1_item_ex_i2d(const ASN1_VALUE **pval, unsigned char **out,
         }
         if (ndef == 2)
             ASN1_put_eoc(out);
-        if (!ossl_asn1_call_aux_cb(aux, ASN1_OP_I2D_POST, pval, it, NULL))
+        if (asn1_cb && !asn1_cb(ASN1_OP_I2D_POST, pval, it, NULL))
             return 0;
         return seqlen;
 
@@ -584,7 +590,7 @@ static int asn1_ex_i2c(const ASN1_VALUE **pval, unsigned char *cout, int *putype
         break;
 
     case V_ASN1_BIT_STRING:
-        return ossl_i2c_ASN1_BIT_STRING((const ASN1_BIT_STRING *)*pval,
+        return ossl_i2c_ASN1_BIT_STRING((ASN1_BIT_STRING *)*pval,
             cout ? &cout : NULL);
 
     case V_ASN1_INTEGER:
diff --git a/crypto/asn1/tasn_fre.c b/crypto/asn1/tasn_fre.c
index df24111578..f8068832ab 100644
--- a/crypto/asn1/tasn_fre.c
+++ b/crypto/asn1/tasn_fre.c
@@ -205,7 +205,7 @@ void ossl_asn1_primitive_free(ASN1_VALUE **pval, const ASN1_ITEM *it, int embed)
         break;
 
     default:
-        ossl_asn1_string_free_internal((ASN1_STRING *)*pval, 0, embed);
+        ossl_asn1_string_embed_free((ASN1_STRING *)*pval, embed);
         break;
     }
     *pval = NULL;
diff --git a/crypto/asn1/tasn_prn.c b/crypto/asn1/tasn_prn.c
index 72922c6530..080b5623e4 100644
--- a/crypto/asn1/tasn_prn.c
+++ b/crypto/asn1/tasn_prn.c
@@ -138,12 +138,15 @@ static int asn1_item_print_ctx(BIO *out, const ASN1_VALUE **fld, int indent,
     const ASN1_EXTERN_FUNCS *ef;
     const ASN1_VALUE **tmpfld;
     const ASN1_AUX *aux = it->funcs;
+    ASN1_aux_const_cb *asn1_cb = NULL;
     ASN1_PRINT_ARG parg;
     int i;
     if (aux != NULL) {
         parg.out = out;
         parg.indent = indent;
         parg.pctx = pctx;
+        asn1_cb = ((aux->flags & ASN1_AFLG_CONST_CB) != 0) ? aux->asn1_const_cb
+                                                           : (ASN1_aux_const_cb *)aux->asn1_cb; /* backward compatibility */
     }
 
     if (((it->itype != ASN1_ITYPE_PRIMITIVE)
@@ -217,11 +220,13 @@ static int asn1_item_print_ctx(BIO *out, const ASN1_VALUE **fld, int indent,
             }
         }
 
-        i = ossl_asn1_call_aux_cb(aux, ASN1_OP_PRINT_PRE, fld, it, &parg);
-        if (i == 0)
-            return 0;
-        if (i == 2)
-            return 1;
+        if (asn1_cb) {
+            i = asn1_cb(ASN1_OP_PRINT_PRE, fld, it, &parg);
+            if (i == 0)
+                return 0;
+            if (i == 2)
+                return 1;
+        }
 
         /* Print each field entry */
         for (i = 0, tt = it->templates; i < it->tcount; i++, tt++) {
@@ -239,9 +244,11 @@ static int asn1_item_print_ctx(BIO *out, const ASN1_VALUE **fld, int indent,
                 return 0;
         }
 
-        i = ossl_asn1_call_aux_cb(aux, ASN1_OP_PRINT_POST, fld, it, &parg);
-        if (i == 0)
-            return 0;
+        if (asn1_cb) {
+            i = asn1_cb(ASN1_OP_PRINT_POST, fld, it, &parg);
+            if (i == 0)
+                return 0;
+        }
         break;
 
     default:
diff --git a/crypto/asn1/tasn_typ.c b/crypto/asn1/tasn_typ.c
index 20d17fc914..0e25b75b9f 100644
--- a/crypto/asn1/tasn_typ.c
+++ b/crypto/asn1/tasn_typ.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -11,8 +11,6 @@
 #include 
 #include 
 
-#include 
-
 /* Declarations for string types */
 
 #define IMPLEMENT_ASN1_STRING_FUNCTIONS(sname)                 \
diff --git a/crypto/asn1/tasn_utl.c b/crypto/asn1/tasn_utl.c
index a4ab762960..5e82a10fbd 100644
--- a/crypto/asn1/tasn_utl.c
+++ b/crypto/asn1/tasn_utl.c
@@ -288,19 +288,3 @@ err:
         ERR_raise(ERR_LIB_ASN1, ASN1_R_UNSUPPORTED_ANY_DEFINED_BY_TYPE);
     return NULL;
 }
-
-int ossl_asn1_call_aux_cb(const ASN1_AUX *aux, int operation,
-    const ASN1_VALUE **in, const ASN1_ITEM *it, void *exarg)
-{
-    if (aux == NULL)
-        return 1;
-
-    if ((aux->flags & ASN1_AFLG_CONST_CB) != 0) {
-        if (aux->asn1_const_cb != NULL)
-            return aux->asn1_const_cb(operation, in, it, exarg);
-    } else if (aux->asn1_cb != NULL) {
-        return aux->asn1_cb(operation, (ASN1_VALUE **)in, it, exarg);
-    }
-
-    return 1;
-}
diff --git a/crypto/asn1/tbl_standard.h b/crypto/asn1/tbl_standard.h
index 41af74e27a..da9c299bed 100644
--- a/crypto/asn1/tbl_standard.h
+++ b/crypto/asn1/tbl_standard.h
@@ -7,14 +7,8 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_ASN1_TBL_STANDARD_H)
-#define OSSL_LIBCRYPTO_ASN1_TBL_STANDARD_H
-
 /* size limits: this stuff is taken straight from RFC3280 */
 
-#include 
-#include 
-
 #define ub_name 32768
 #define ub_common_name 64
 #define ub_locality_name 128
@@ -65,5 +59,3 @@ static const ASN1_STRING_TABLE tbl_standard[] = {
     { NID_dnsName, 0, -1, B_ASN1_UTF8STRING, STABLE_NO_MASK },
     { NID_id_on_SmtpUTF8Mailbox, 1, ub_email_address, B_ASN1_UTF8STRING, STABLE_NO_MASK }
 };
-
-#endif /* !defined(OSSL_LIBCRYPTO_ASN1_TBL_STANDARD_H) */
diff --git a/crypto/asn1/x_algor.c b/crypto/asn1/x_algor.c
index 5050adb8f1..f8faf7209b 100644
--- a/crypto/asn1/x_algor.c
+++ b/crypto/asn1/x_algor.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1998-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1998-2022 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -85,14 +85,12 @@ void X509_ALGOR_get0(const ASN1_OBJECT **paobj, int *pptype,
 }
 
 /* Set up an X509_ALGOR DigestAlgorithmIdentifier from an EVP_MD */
-int X509_ALGOR_set_md(X509_ALGOR *alg, const EVP_MD *md)
+void X509_ALGOR_set_md(X509_ALGOR *alg, const EVP_MD *md)
 {
     int type = md->flags & EVP_MD_FLAG_DIGALGID_ABSENT ? V_ASN1_UNDEF
                                                        : V_ASN1_NULL;
-    int md_type = EVP_MD_type(md);
 
-    ASN1_OBJECT *obj = (md_type == NID_undef) ? OBJ_txt2obj(EVP_MD_get0_name(md), 0) : OBJ_nid2obj(md_type);
-    return X509_ALGOR_set0(alg, obj, type, NULL);
+    (void)X509_ALGOR_set0(alg, OBJ_nid2obj(EVP_MD_get_type(md)), type, NULL);
 }
 
 int X509_ALGOR_cmp(const X509_ALGOR *a, const X509_ALGOR *b)
@@ -150,10 +148,7 @@ int ossl_x509_algor_new_from_md(X509_ALGOR **palg, const EVP_MD *md)
         return 1;
     if ((alg = X509_ALGOR_new()) == NULL)
         return 0;
-    if (!X509_ALGOR_set_md(alg, md)) {
-        X509_ALGOR_free(alg);
-        return 0;
-    }
+    X509_ALGOR_set_md(alg, md);
     *palg = alg;
     return 1;
 }
diff --git a/crypto/asn1/x_bignum.c b/crypto/asn1/x_bignum.c
index aff286a563..efa2ade30f 100644
--- a/crypto/asn1/x_bignum.c
+++ b/crypto/asn1/x_bignum.c
@@ -114,21 +114,13 @@ static int bn_i2c(const ASN1_VALUE **pval, unsigned char *cont, int *putype,
 static int bn_c2i(ASN1_VALUE **pval, const unsigned char *cont, int len,
     int utype, char *free_cont, const ASN1_ITEM *it)
 {
-    int allocated = 0;
     BIGNUM *bn;
 
-    /* Reject encodings that imply a negative number. */
-    if (len == 0 || (*cont & 0x80) != 0) {
-        ERR_raise(ERR_LIB_ASN1, ASN1_R_INVALID_VALUE);
-        return 0;
-    }
-
-    if (*pval == NULL && (allocated = bn_new(pval, it)) == 0)
+    if (*pval == NULL && !bn_new(pval, it))
         return 0;
     bn = (BIGNUM *)*pval;
     if (!BN_bin2bn(cont, len, bn)) {
-        if (allocated != 0)
-            bn_free(pval, it);
+        bn_free(pval, it);
         return 0;
     }
     return 1;
@@ -137,19 +129,15 @@ static int bn_c2i(ASN1_VALUE **pval, const unsigned char *cont, int len,
 static int bn_secure_c2i(ASN1_VALUE **pval, const unsigned char *cont, int len,
     int utype, char *free_cont, const ASN1_ITEM *it)
 {
-    int ret, allocated = 0;
+    int ret;
     BIGNUM *bn;
 
-    if (*pval == NULL && (allocated = bn_secure_new(pval, it)) == 0)
+    if (*pval == NULL && !bn_secure_new(pval, it))
         return 0;
 
     ret = bn_c2i(pval, cont, len, utype, free_cont, it);
-    if (!ret) {
-        if (allocated != 0)
-            bn_free(pval, it);
-
+    if (!ret)
         return 0;
-    }
 
     /* Set constant-time flag for all secure BIGNUMS */
     bn = (BIGNUM *)*pval;
diff --git a/crypto/asn1/x_int64.c b/crypto/asn1/x_int64.c
index 9f2a3aedc2..f7cd7cbd95 100644
--- a/crypto/asn1/x_int64.c
+++ b/crypto/asn1/x_int64.c
@@ -8,7 +8,6 @@
  */
 
 #include 
-#include 
 #include "internal/cryptlib.h"
 #include "internal/numbers.h"
 #include 
@@ -114,8 +113,8 @@ static int uint64_print(BIO *out, const ASN1_VALUE **pval, const ASN1_ITEM *it,
     int indent, const ASN1_PCTX *pctx)
 {
     if ((it->size & INTxx_FLAG_SIGNED) == INTxx_FLAG_SIGNED)
-        return BIO_printf(out, "%" PRId64 "\n", **(int64_t **)pval);
-    return BIO_printf(out, "%" PRIu64 "\n", **(uint64_t **)pval);
+        return BIO_printf(out, "%jd\n", **(int64_t **)pval);
+    return BIO_printf(out, "%ju\n", **(uint64_t **)pval);
 }
 
 /* 32-bit variants */
diff --git a/crypto/async/arch/async_null.h b/crypto/async/arch/async_null.h
new file mode 100644
index 0000000000..6be0b96f9e
--- /dev/null
+++ b/crypto/async/arch/async_null.h
@@ -0,0 +1,31 @@
+/*
+ * Copyright 2015-2022 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+#include 
+
+/*
+ * If we haven't managed to detect any other async architecture then we default
+ * to NULL.
+ */
+#ifndef ASYNC_ARCH
+#define ASYNC_NULL
+#define ASYNC_ARCH
+
+typedef struct async_fibre_st {
+    int dummy;
+} async_fibre;
+
+#define async_fibre_swapcontext(o, n, r) 0
+#define async_fibre_makecontext(c) 0
+#define async_fibre_free(f)
+#define async_fibre_init_dispatcher(f)
+#define async_local_init() 1
+#define async_local_deinit()
+
+#endif
diff --git a/crypto/async/arch/async_posix.h b/crypto/async/arch/async_posix.h
new file mode 100644
index 0000000000..449ca27d22
--- /dev/null
+++ b/crypto/async/arch/async_posix.h
@@ -0,0 +1,97 @@
+/*
+ * Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+#ifndef OSSL_CRYPTO_ASYNC_POSIX_H
+#define OSSL_CRYPTO_ASYNC_POSIX_H
+#include 
+
+#if defined(OPENSSL_SYS_UNIX)                                 \
+    && defined(OPENSSL_THREADS) && !defined(OPENSSL_NO_ASYNC) \
+    && !defined(__ANDROID__) && !defined(__OpenBSD__)         \
+    && !defined(OPENSSL_SYS_TANDEM)
+
+#include 
+
+#if _POSIX_VERSION >= 200112L \
+    && (_POSIX_VERSION < 200809L || defined(__GLIBC__) || defined(__FreeBSD__))
+
+#include 
+
+#define ASYNC_POSIX
+#define ASYNC_ARCH
+
+#if defined(__CET__) || defined(__ia64__)
+/*
+ * When Intel CET is enabled, makecontext will create a different
+ * shadow stack for each context.  async_fibre_swapcontext cannot
+ * use _longjmp.  It must call swapcontext to swap shadow stack as
+ * well as normal stack.
+ * On IA64 the register stack engine is not saved across setjmp/longjmp. Here
+ * swapcontext() performs correctly.
+ */
+#define USE_SWAPCONTEXT
+#endif
+#if defined(__aarch64__) && defined(__clang__) \
+    && defined(__ARM_FEATURE_BTI_DEFAULT) && __ARM_FEATURE_BTI_DEFAULT == 1
+/*
+ * setjmp/longjmp don't currently work with BTI on all libc implementations
+ * when compiled by clang. This is because clang doesn't put a BTI after the
+ * call to setjmp where it returns the second time. This then fails on libc
+ * implementations - notably glibc - which use an indirect jump to there.
+ * So use the swapcontext implementation, which does work.
+ * See https://github.com/llvm/llvm-project/issues/48888.
+ */
+#define USE_SWAPCONTEXT
+#endif
+#if defined(OPENSSL_SYS_TANDEM)
+#include 
+#else
+#include 
+#endif
+#ifndef USE_SWAPCONTEXT
+#include 
+#endif
+
+typedef struct async_fibre_st {
+    ucontext_t fibre;
+#ifndef USE_SWAPCONTEXT
+    jmp_buf env;
+    int env_init;
+#endif
+} async_fibre;
+
+int async_local_init(void);
+void async_local_deinit(void);
+
+static ossl_inline int async_fibre_swapcontext(async_fibre *o, async_fibre *n, int r)
+{
+#ifdef USE_SWAPCONTEXT
+    swapcontext(&o->fibre, &n->fibre);
+#else
+    o->env_init = 1;
+
+    if (!r || !_setjmp(o->env)) {
+        if (n->env_init)
+            _longjmp(n->env, 1);
+        else
+            setcontext(&n->fibre);
+    }
+#endif
+
+    return 1;
+}
+
+#define async_fibre_init_dispatcher(d)
+
+int async_fibre_makecontext(async_fibre *fibre);
+void async_fibre_free(async_fibre *fibre);
+
+#endif
+#endif
+#endif /* OSSL_CRYPTO_ASYNC_POSIX_H */
diff --git a/crypto/async/arch/async_win.c b/crypto/async/arch/async_win.c
index 2ca4ed6a93..849da5c3c4 100644
--- a/crypto/async/arch/async_win.c
+++ b/crypto/async/arch/async_win.c
@@ -12,7 +12,7 @@
 
 #ifdef ASYNC_WIN
 
-#include "internal/e_os.h"
+#include 
 #include "internal/cryptlib.h"
 
 int ASYNC_is_capable(void)
diff --git a/crypto/async/arch/async_win.h b/crypto/async/arch/async_win.h
new file mode 100644
index 0000000000..ef134f53ab
--- /dev/null
+++ b/crypto/async/arch/async_win.h
@@ -0,0 +1,46 @@
+/*
+ * Copyright 2015-2022 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+/*
+ * This is the same detection used in cryptlib to set up the thread local
+ * storage that we depend on, so just copy that
+ */
+#if defined(_WIN32) && !defined(OPENSSL_NO_ASYNC)
+#include 
+#define ASYNC_WIN
+#define ASYNC_ARCH
+
+#include 
+#include "internal/cryptlib.h"
+
+typedef struct async_fibre_st {
+    LPVOID fibre;
+    int converted;
+} async_fibre;
+
+#define async_fibre_swapcontext(o, n, r) \
+    (SwitchToFiber((n)->fibre), 1)
+
+#if defined(_WIN32_WINNT) && _WIN32_WINNT >= 0x600
+#define async_fibre_makecontext(c)                             \
+    ((c)->fibre = CreateFiberEx(0, 0, FIBER_FLAG_FLOAT_SWITCH, \
+         async_start_func_win, 0))
+#else
+#define async_fibre_makecontext(c) \
+    ((c)->fibre = CreateFiber(0, async_start_func_win, 0))
+#endif
+
+#define async_fibre_free(f) (DeleteFiber((f)->fibre))
+#define async_local_init() 1
+#define async_local_deinit()
+
+int async_fibre_init_dispatcher(async_fibre *fibre);
+VOID CALLBACK async_start_func_win(PVOID unused);
+
+#endif
diff --git a/crypto/async/async.c b/crypto/async/async.c
index 4585390342..ff55ef77ba 100644
--- a/crypto/async/async.c
+++ b/crypto/async/async.c
@@ -255,8 +255,7 @@ int ASYNC_start_job(ASYNC_JOB **job, ASYNC_WAIT_CTX *wctx, int *ret,
         if ((ctx->currjob = async_get_pool_job()) == NULL)
             return ASYNC_NO_JOBS;
 
-        /* Check for size > 0 to avoid malloc(0) */
-        if (args != NULL && size > 0) {
+        if (args != NULL) {
             ctx->currjob->funcargs = OPENSSL_malloc(size);
             if (ctx->currjob->funcargs == NULL) {
                 async_release_job(ctx->currjob);
diff --git a/crypto/async/async_local.h b/crypto/async/async_local.h
index f10a6745f8..9690adbb1e 100644
--- a/crypto/async/async_local.h
+++ b/crypto/async/async_local.h
@@ -11,150 +11,24 @@
  * Must do this before including any header files, because on MacOS/X 
  * includes  which includes 
  */
-#if !defined(OSSL_LIBCRYPTO_ASYNC_ASYNC_LOCAL_H)
-#define OSSL_LIBCRYPTO_ASYNC_ASYNC_LOCAL_H
-
 #if defined(__APPLE__) && defined(__MACH__) && !defined(_XOPEN_SOURCE)
 #define _XOPEN_SOURCE /* Otherwise incomplete ucontext_t structure */
 #pragma GCC diagnostic ignored "-Wdeprecated-declarations"
 #endif
 
+#if defined(_WIN32)
+#include 
+#endif
+
+#include "crypto/async.h"
 #include 
-#include 
-#include 
 
 typedef struct async_ctx_st async_ctx;
 typedef struct async_pool_st async_pool;
 
-#if defined(_WIN32)
-#define ASYNC_WIN
-#define ASYNC_ARCH
-
-#include "internal/cryptlib.h"
-
-typedef struct async_fibre_st {
-    LPVOID fibre;
-    int converted;
-} async_fibre;
-
-#define async_fibre_swapcontext(o, n, r) \
-    (SwitchToFiber((n)->fibre), 1)
-
-#if defined(_WIN32_WINNT) && _WIN32_WINNT >= 0x600
-#define async_fibre_makecontext(c)                             \
-    ((c)->fibre = CreateFiberEx(0, 0, FIBER_FLAG_FLOAT_SWITCH, \
-         async_start_func_win, 0))
-#else
-#define async_fibre_makecontext(c) \
-    ((c)->fibre = CreateFiber(0, async_start_func_win, 0))
-#endif
-
-#define async_fibre_free(f) (DeleteFiber((f)->fibre))
-#define async_local_init() 1
-#define async_local_deinit()
-
-int async_fibre_init_dispatcher(async_fibre *fibre);
-VOID CALLBACK async_start_func_win(PVOID unused);
-
-#elif defined(OPENSSL_SYS_UNIX)                               \
-    && defined(OPENSSL_THREADS) && !defined(OPENSSL_NO_ASYNC) \
-    && !defined(__ANDROID__) && !defined(__OpenBSD__)         \
-    && !defined(OPENSSL_SYS_TANDEM)
-
-#include 
-
-#if _POSIX_VERSION >= 200112L \
-    && (_POSIX_VERSION < 200809L || defined(__GLIBC__) || defined(__FreeBSD__))
-
-#include 
-
-#define ASYNC_POSIX
-#define ASYNC_ARCH
-
-#if defined(__CET__) || defined(__ia64__)
-/*
- * When Intel CET is enabled, makecontext will create a different
- * shadow stack for each context.  async_fibre_swapcontext cannot
- * use _longjmp.  It must call swapcontext to swap shadow stack as
- * well as normal stack.
- * On IA64 the register stack engine is not saved across setjmp/longjmp. Here
- * swapcontext() performs correctly.
- */
-#define USE_SWAPCONTEXT
-#endif
-#if defined(__aarch64__) && defined(__clang__) \
-    && defined(__ARM_FEATURE_BTI_DEFAULT) && __ARM_FEATURE_BTI_DEFAULT == 1
-/*
- * setjmp/longjmp don't currently work with BTI on all libc implementations
- * when compiled by clang. This is because clang doesn't put a BTI after the
- * call to setjmp where it returns the second time. This then fails on libc
- * implementations - notably glibc - which use an indirect jump to there.
- * So use the swapcontext implementation, which does work.
- * See https://github.com/llvm/llvm-project/issues/48888.
- */
-#define USE_SWAPCONTEXT
-#endif
-#include 
-#ifndef USE_SWAPCONTEXT
-#include 
-#endif
-
-typedef struct async_fibre_st {
-    ucontext_t fibre;
-#ifndef USE_SWAPCONTEXT
-    jmp_buf env;
-    int env_init;
-#endif
-} async_fibre;
-
-int async_local_init(void);
-void async_local_deinit(void);
-
-static ossl_inline int async_fibre_swapcontext(async_fibre *o, async_fibre *n, int r)
-{
-#ifdef USE_SWAPCONTEXT
-    swapcontext(&o->fibre, &n->fibre);
-#else
-    o->env_init = 1;
-
-    if (!r || !_setjmp(o->env)) {
-        if (n->env_init)
-            _longjmp(n->env, 1);
-        else
-            setcontext(&n->fibre);
-    }
-#endif
-
-    return 1;
-}
-
-#define async_fibre_init_dispatcher(d)
-
-int async_fibre_makecontext(async_fibre *fibre);
-void async_fibre_free(async_fibre *fibre);
-
-#endif
-#endif /* UNIX */
-
-#ifndef ASYNC_ARCH
-#define ASYNC_NULL
-#define ASYNC_ARCH
-
-typedef struct async_fibre_st {
-    int dummy;
-} async_fibre;
-
-#define async_fibre_swapcontext(o, n, r) 0
-#define async_fibre_makecontext(c) 0
-#define async_fibre_free(f)
-#define async_fibre_init_dispatcher(f)
-#define async_local_init() 1
-#define async_local_deinit()
-#endif
-
-/* needs to be included after windows.h */
-#include 
-#include "crypto/async.h"
+#include "arch/async_win.h"
+#include "arch/async_posix.h"
+#include "arch/async_null.h"
 
 struct async_ctx_st {
     async_fibre dispatcher;
@@ -204,5 +78,3 @@ void async_start_func(void);
 async_ctx *async_get_ctx(void);
 
 void async_wait_ctx_reset_counts(ASYNC_WAIT_CTX *ctx);
-
-#endif /* !defined(OSSL_LIBCRYPTO_ASYNC_ASYNC_LOCAL_H) */
diff --git a/crypto/bf/bf_cfb64.c b/crypto/bf/bf_cfb64.c
index cec20b9158..e380972dbd 100644
--- a/crypto/bf/bf_cfb64.c
+++ b/crypto/bf/bf_cfb64.c
@@ -27,7 +27,7 @@ void BF_cfb64_encrypt(const unsigned char *in, unsigned char *out,
     unsigned char *ivec, int *num, int encrypt)
 {
     register BF_LONG v0, v1, t;
-    register int n = *num & 0x07;
+    register int n = *num;
     register long l = length;
     BF_LONG ti[2];
     unsigned char *iv, c, cc;
diff --git a/crypto/bf/bf_local.h b/crypto/bf/bf_local.h
index c9c6d53f9e..8634a57ceb 100644
--- a/crypto/bf/bf_local.h
+++ b/crypto/bf/bf_local.h
@@ -9,9 +9,82 @@
 
 #ifndef OSSL_CRYPTO_BF_LOCAL_H
 #define OSSL_CRYPTO_BF_LOCAL_H
-
 #include 
-#include "internal/common.h"
+
+/* NOTE - c is not incremented as per n2l */
+#define n2ln(c, l1, l2, n)                           \
+    {                                                \
+        c += n;                                      \
+        l1 = l2 = 0;                                 \
+        switch (n) {                                 \
+        case 8:                                      \
+            l2 = ((unsigned long)(*(--(c))));        \
+        /* fall through */                           \
+        case 7:                                      \
+            l2 |= ((unsigned long)(*(--(c)))) << 8;  \
+        /* fall through */                           \
+        case 6:                                      \
+            l2 |= ((unsigned long)(*(--(c)))) << 16; \
+        /* fall through */                           \
+        case 5:                                      \
+            l2 |= ((unsigned long)(*(--(c)))) << 24; \
+        /* fall through */                           \
+        case 4:                                      \
+            l1 = ((unsigned long)(*(--(c))));        \
+        /* fall through */                           \
+        case 3:                                      \
+            l1 |= ((unsigned long)(*(--(c)))) << 8;  \
+        /* fall through */                           \
+        case 2:                                      \
+            l1 |= ((unsigned long)(*(--(c)))) << 16; \
+        /* fall through */                           \
+        case 1:                                      \
+            l1 |= ((unsigned long)(*(--(c)))) << 24; \
+        }                                            \
+    }
+
+/* NOTE - c is not incremented as per l2n */
+#define l2nn(l1, l2, c, n)                                   \
+    {                                                        \
+        c += n;                                              \
+        switch (n) {                                         \
+        case 8:                                              \
+            *(--(c)) = (unsigned char)(((l2)) & 0xff);       \
+        /* fall through */                                   \
+        case 7:                                              \
+            *(--(c)) = (unsigned char)(((l2) >> 8) & 0xff);  \
+        /* fall through */                                   \
+        case 6:                                              \
+            *(--(c)) = (unsigned char)(((l2) >> 16) & 0xff); \
+        /* fall through */                                   \
+        case 5:                                              \
+            *(--(c)) = (unsigned char)(((l2) >> 24) & 0xff); \
+        /* fall through */                                   \
+        case 4:                                              \
+            *(--(c)) = (unsigned char)(((l1)) & 0xff);       \
+        /* fall through */                                   \
+        case 3:                                              \
+            *(--(c)) = (unsigned char)(((l1) >> 8) & 0xff);  \
+        /* fall through */                                   \
+        case 2:                                              \
+            *(--(c)) = (unsigned char)(((l1) >> 16) & 0xff); \
+        /* fall through */                                   \
+        case 1:                                              \
+            *(--(c)) = (unsigned char)(((l1) >> 24) & 0xff); \
+        }                                                    \
+    }
+
+#undef n2l
+#define n2l(c, l) (l = ((unsigned long)(*((c)++))) << 24L, \
+    l |= ((unsigned long)(*((c)++))) << 16L,               \
+    l |= ((unsigned long)(*((c)++))) << 8L,                \
+    l |= ((unsigned long)(*((c)++))))
+
+#undef l2n
+#define l2n(l, c) (*((c)++) = (unsigned char)(((l) >> 24L) & 0xff), \
+    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff),                \
+    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff),                 \
+    *((c)++) = (unsigned char)(((l)) & 0xff))
 
 /*
  * This is actually a big endian algorithm, the most significant byte is used
diff --git a/crypto/bf/bf_ofb64.c b/crypto/bf/bf_ofb64.c
index dbd60d1853..5c9193add1 100644
--- a/crypto/bf/bf_ofb64.c
+++ b/crypto/bf/bf_ofb64.c
@@ -26,7 +26,7 @@ void BF_ofb64_encrypt(const unsigned char *in, unsigned char *out,
     unsigned char *ivec, int *num)
 {
     register BF_LONG v0, v1, t;
-    register int n = *num & 0x07;
+    register int n = *num;
     register long l = length;
     unsigned char d[8];
     register char *dp;
diff --git a/crypto/bf/bf_pi.h b/crypto/bf/bf_pi.h
index 1419a5cf4a..ffb3b3e9b3 100644
--- a/crypto/bf/bf_pi.h
+++ b/crypto/bf/bf_pi.h
@@ -7,11 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_BF_BF_PI_H)
-#define OSSL_LIBCRYPTO_BF_BF_PI_H
-
-#include 
-
 static const BF_KEY bf_init = {
     { 0x243f6a88L, 0x85a308d3L, 0x13198a2eL, 0x03707344L,
         0xa4093822L, 0x299f31d0L, 0x082efa98L, 0xec4e6c89L,
@@ -1045,5 +1040,3 @@ static const BF_KEY bf_init = {
         0x3ac372e6L,
     }
 };
-
-#endif /* !defined(OSSL_LIBCRYPTO_BF_BF_PI_H) */
diff --git a/crypto/bio/bf_buff.c b/crypto/bio/bf_buff.c
index c7d4c34f50..3926d1552b 100644
--- a/crypto/bio/bf_buff.c
+++ b/crypto/bio/bf_buff.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -256,12 +256,6 @@ static long buffer_ctrl(BIO *b, int cmd, long num, void *ptr)
     case BIO_CTRL_EOF:
         if (ctx->ibuf_len > 0)
             return 0;
-        /*
-         * If there is no next BIO, BIO_read() returns 0, which means EOF,
-         * BIO_eof() should return 1 in this case.
-         */
-        if (b->next_bio == NULL)
-            return 1;
         ret = BIO_ctrl(b->next_bio, cmd, num, ptr);
         break;
     case BIO_CTRL_INFO:
diff --git a/crypto/bio/bf_lbuf.c b/crypto/bio/bf_lbuf.c
index 6514f08337..1dfcac8f2e 100644
--- a/crypto/bio/bf_lbuf.c
+++ b/crypto/bio/bf_lbuf.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -187,34 +187,14 @@ static int linebuffer_write(BIO *b, const char *in, int inl)
     } while (foundnl && inl > 0);
     /*
      * We've written as much as we can.  The rest of the input buffer, if
-     * any, is text that doesn't end with a NL and therefore we need to try
-     * free up some space in our obuf so we can make forward progress.
+     * any, is text that doesn't and with a NL and therefore needs to be
+     * saved for the next trip.
      */
-    while (inl > 0) {
-        size_t avail = (size_t)ctx->obuf_size - (size_t)ctx->obuf_len;
-        size_t to_copy;
-
-        if (avail == 0) {
-            /* Flush buffered data to make room */
-            i = BIO_write(b->next_bio, ctx->obuf, ctx->obuf_len);
-            if (i <= 0) {
-                BIO_copy_next_retry(b);
-                return num > 0 ? num : i;
-            }
-            if (i < ctx->obuf_len)
-                memmove(ctx->obuf, ctx->obuf + i, ctx->obuf_len - i);
-            ctx->obuf_len -= i;
-            continue;
-        }
-
-        to_copy = inl > (int)avail ? avail : (size_t)inl;
-        memcpy(&(ctx->obuf[ctx->obuf_len]), in, to_copy);
-        ctx->obuf_len += (int)to_copy;
-        in += to_copy;
-        inl -= (int)to_copy;
-        num += (int)to_copy;
+    if (inl > 0) {
+        memcpy(&(ctx->obuf[ctx->obuf_len]), in, inl);
+        ctx->obuf_len += inl;
+        num += inl;
     }
-
     return num;
 }
 
@@ -307,15 +287,6 @@ static long linebuffer_ctrl(BIO *b, int cmd, long num, void *ptr)
         if (BIO_set_write_buffer_size(dbio, ctx->obuf_size) <= 0)
             ret = 0;
         break;
-    case BIO_CTRL_EOF:
-        /*
-         * If there is no next BIO, BIO_read() returns 0, which means EOF.
-         * BIO_eof() should return 1 in this case.
-         */
-        if (b->next_bio == NULL)
-            return 1;
-        ret = BIO_ctrl(b->next_bio, cmd, num, ptr);
-        break;
     default:
         if (b->next_bio == NULL)
             return 0;
@@ -334,14 +305,9 @@ static long linebuffer_callback_ctrl(BIO *b, int cmd, BIO_info_cb *fp)
 
 static int linebuffer_gets(BIO *b, char *buf, int size)
 {
-    int ret = 0;
-
     if (b->next_bio == NULL)
         return 0;
-    ret = BIO_gets(b->next_bio, buf, size);
-    BIO_clear_retry_flags(b);
-    BIO_copy_next_retry(b);
-    return ret;
+    return BIO_gets(b->next_bio, buf, size);
 }
 
 static int linebuffer_puts(BIO *b, const char *str)
diff --git a/crypto/bio/bf_nbio.c b/crypto/bio/bf_nbio.c
index 52d3bbec77..01138729b0 100644
--- a/crypto/bio/bf_nbio.c
+++ b/crypto/bio/bf_nbio.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -149,14 +149,9 @@ static long nbiof_ctrl(BIO *b, int cmd, long num, void *ptr)
 {
     long ret;
 
-    /*
-     * If there is no next BIO, BIO_read() returns 0, which means EOF.
-     * BIO_eof() should return 1 in this case.
-     */
     if (b->next_bio == NULL)
-        return cmd == BIO_CTRL_EOF;
+        return 0;
     switch (cmd) {
-    case BIO_CTRL_FLUSH:
     case BIO_C_DO_STATE_MACHINE:
         BIO_clear_retry_flags(b);
         ret = BIO_ctrl(b->next_bio, cmd, num, ptr);
@@ -181,22 +176,14 @@ static long nbiof_callback_ctrl(BIO *b, int cmd, BIO_info_cb *fp)
 
 static int nbiof_gets(BIO *bp, char *buf, int size)
 {
-    int ret = 0;
     if (bp->next_bio == NULL)
         return 0;
-    ret = BIO_gets(bp->next_bio, buf, size);
-    BIO_clear_retry_flags(bp);
-    BIO_copy_next_retry(bp);
-    return ret;
+    return BIO_gets(bp->next_bio, buf, size);
 }
 
 static int nbiof_puts(BIO *bp, const char *str)
 {
-    int ret = 0;
     if (bp->next_bio == NULL)
         return 0;
-    ret = BIO_puts(bp->next_bio, str);
-    BIO_clear_retry_flags(bp);
-    BIO_copy_next_retry(bp);
-    return ret;
+    return BIO_puts(bp->next_bio, str);
 }
diff --git a/crypto/bio/bf_null.c b/crypto/bio/bf_null.c
index 8c13a7bb63..7add76a4ca 100644
--- a/crypto/bio/bf_null.c
+++ b/crypto/bio/bf_null.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -74,14 +74,9 @@ static long nullf_ctrl(BIO *b, int cmd, long num, void *ptr)
 {
     long ret;
 
-    /*
-     * If there is no next BIO, BIO_read() returns 0, which means EOF.
-     * BIO_eof() should return 1 in this case.
-     */
     if (b->next_bio == NULL)
-        return cmd == BIO_CTRL_EOF;
+        return 0;
     switch (cmd) {
-    case BIO_CTRL_FLUSH:
     case BIO_C_DO_STATE_MACHINE:
         BIO_clear_retry_flags(b);
         ret = BIO_ctrl(b->next_bio, cmd, num, ptr);
@@ -105,24 +100,14 @@ static long nullf_callback_ctrl(BIO *b, int cmd, BIO_info_cb *fp)
 
 static int nullf_gets(BIO *bp, char *buf, int size)
 {
-    int ret = 0;
-
     if (bp->next_bio == NULL)
         return 0;
-    ret = BIO_gets(bp->next_bio, buf, size);
-    BIO_clear_retry_flags(bp);
-    BIO_copy_next_retry(bp);
-    return ret;
+    return BIO_gets(bp->next_bio, buf, size);
 }
 
 static int nullf_puts(BIO *bp, const char *str)
 {
-    int ret = 0;
-
     if (bp->next_bio == NULL)
         return 0;
-    ret = BIO_puts(bp->next_bio, str);
-    BIO_clear_retry_flags(bp);
-    BIO_copy_next_retry(bp);
-    return ret;
+    return BIO_puts(bp->next_bio, str);
 }
diff --git a/crypto/bio/bio_lib.c b/crypto/bio/bio_lib.c
index 6066cc0d8c..f89316b59f 100644
--- a/crypto/bio/bio_lib.c
+++ b/crypto/bio/bio_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -116,22 +116,24 @@ BIO *BIO_new(const BIO_METHOD *method)
     return BIO_new_ex(NULL, method);
 }
 
-static int BIO_free_int(BIO *a, int *ret)
+int BIO_free(BIO *a)
 {
+    int ret;
 
     if (a == NULL)
         return 0;
 
-    if (CRYPTO_DOWN_REF(&a->references, ret) <= 0)
+    if (CRYPTO_DOWN_REF(&a->references, &ret) <= 0)
         return 0;
 
-    REF_PRINT_COUNT("BIO", *ret, a);
-    if (*ret > 0)
+    REF_PRINT_COUNT("BIO", ret, a);
+    if (ret > 0)
         return 1;
-    REF_ASSERT_ISNT(*ret < 0);
+    REF_ASSERT_ISNT(ret < 0);
 
     if (HAS_CALLBACK(a)) {
-        if ((int)bio_call_callback(a, BIO_CB_FREE, NULL, 0, 0, 0L, 1L, NULL) <= 0)
+        ret = (int)bio_call_callback(a, BIO_CB_FREE, NULL, 0, 0, 0L, 1L, NULL);
+        if (ret <= 0)
             return 0;
     }
 
@@ -147,13 +149,6 @@ static int BIO_free_int(BIO *a, int *ret)
     return 1;
 }
 
-int BIO_free(BIO *b)
-{
-    int ref;
-
-    return BIO_free_int(b, &ref);
-}
-
 void BIO_set_data(BIO *a, void *ptr)
 {
     a->ptr = ptr;
@@ -193,7 +188,7 @@ int BIO_up_ref(BIO *a)
 {
     int i;
 
-    if (!CRYPTO_UP_REF(&a->references, &i))
+    if (CRYPTO_UP_REF(&a->references, &i) <= 0)
         return 0;
 
     REF_PRINT_COUNT("BIO", i, a);
@@ -216,11 +211,6 @@ void BIO_set_flags(BIO *b, int flags)
     b->flags |= flags;
 }
 
-long BIO_set_send_flags(BIO *b, int flags)
-{
-    return BIO_ctrl(b, BIO_C_SET_SEND_FLAGS, (long)flags, NULL);
-}
-
 #ifndef OPENSSL_NO_DEPRECATED_3_0
 BIO_callback_fn BIO_get_callback(const BIO *b)
 {
@@ -264,14 +254,10 @@ int BIO_method_type(const BIO *b)
 }
 
 /*
- * Internal BIO read function. Attempts to read dlen bytes from BIO b and
- * places them in data. If any bytes were successfully read, then the number
- * of bytes read is stored in readbytes.
- * For compatibility with the old-style BIO_read() API, the function uses a
- * return-value convention where a positive value indicates success,
- * 0 indicates end-of-file, and a negative value indicates an error
- * (including retryable errors).
- * It also returns 0 if dlen==0.
+ * This is essentially the same as BIO_read_ex() except that it allows
+ * 0 or a negative value to indicate failure (retryable or not) in the return.
+ * This is for compatibility with the old style BIO_read(), where existing code
+ * may make assumptions about the return value that it might get.
  */
 static int bio_read_intern(BIO *b, void *data, size_t dlen, size_t *readbytes)
 {
@@ -299,13 +285,6 @@ static int bio_read_intern(BIO *b, void *data, size_t dlen, size_t *readbytes)
     if (ret > 0)
         b->num_read += (uint64_t)*readbytes;
 
-    /*
-     * If method->bread() returned 0 when dlen>0, it can be either EOF or
-     * an error, and we should distinguish them
-     */
-    if (ret == 0 && dlen > 0 && BIO_eof(b) == 0)
-        ret = -1;
-
     if (HAS_CALLBACK(b))
         ret = (int)bio_call_callback(b, BIO_CB_READ | BIO_CB_RETURN, data,
             dlen, 0, 0L, ret, readbytes);
@@ -324,10 +303,8 @@ int BIO_read(BIO *b, void *data, int dlen)
     size_t readbytes;
     int ret;
 
-    if (dlen < 0) {
-        ERR_raise(ERR_LIB_BIO, ERR_R_PASSED_INVALID_ARGUMENT);
-        return -1;
-    }
+    if (dlen < 0)
+        return 0;
 
     ret = bio_read_intern(b, data, (size_t)dlen, &readbytes);
 
@@ -452,7 +429,7 @@ int BIO_sendmmsg(BIO *b, BIO_MSG *msg,
 
     if (HAS_CALLBACK(b))
         ret = (size_t)bio_call_callback(b, BIO_CB_SENDMMSG | BIO_CB_RETURN,
-            (void *)&args, ret, 0, 0, (long)ret, msgs_processed);
+            (void *)&args, ret, 0, 0, (long)ret, NULL);
 
     return ret > 0;
 }
@@ -499,7 +476,7 @@ int BIO_recvmmsg(BIO *b, BIO_MSG *msg,
 
     if (HAS_CALLBACK(b))
         ret = (size_t)bio_call_callback(b, BIO_CB_RECVMMSG | BIO_CB_RETURN,
-            (void *)&args, ret, 0, 0, (long)ret, msgs_processed);
+            (void *)&args, ret, 0, 0, (long)ret, NULL);
 
     return ret > 0;
 }
@@ -702,13 +679,6 @@ long BIO_ctrl(BIO *b, int cmd, long larg, void *parg)
     return ret;
 }
 
-int BIO_eof(BIO *b)
-{
-    if ((b->flags & BIO_FLAGS_AUTO_EOF) != 0)
-        return 1;
-    return (int)BIO_ctrl(b, BIO_CTRL_EOF, 0, NULL);
-}
-
 long BIO_callback_ctrl(BIO *b, int cmd, BIO_info_cb *fp)
 {
     long ret;
@@ -879,11 +849,11 @@ void BIO_free_all(BIO *bio)
 
     while (bio != NULL) {
         b = bio;
+        CRYPTO_GET_REF(&b->references, &ref);
         bio = bio->next_bio;
-        ref = 0;
-        BIO_free_int(b, &ref);
-        /* Since ref count > 0, don't free anyone else. */
-        if (ref > 0)
+        BIO_free(b);
+        /* Since ref count > 1, don't free anyone else. */
+        if (ref > 1)
             break;
     }
 }
diff --git a/crypto/bio/bio_local.h b/crypto/bio/bio_local.h
index 87227e4f8f..60fb944928 100644
--- a/crypto/bio/bio_local.h
+++ b/crypto/bio/bio_local.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_BIO_BIO_LOCAL_H)
-#define OSSL_LIBCRYPTO_BIO_BIO_LOCAL_H
-
 #include "internal/e_os.h"
 #include "internal/sockets.h"
 #include "internal/bio_addr.h"
@@ -74,7 +71,6 @@ struct bio_addrinfo_st {
 #include "internal/cryptlib.h"
 #include "internal/bio.h"
 #include "internal/refcount.h"
-#include "internal/time.h"
 
 typedef struct bio_f_buffer_ctx_struct {
     /*-
@@ -123,87 +119,6 @@ struct bio_st {
 };
 
 #ifndef OPENSSL_NO_SOCK
-
-typedef struct bio_connect_st {
-    int state;
-    int connect_family;
-    int connect_sock_type;
-    char *param_hostname;
-    char *param_service;
-    int connect_mode;
-#ifndef OPENSSL_NO_KTLS
-    unsigned char record_type;
-#endif
-    int tfo_first;
-
-    BIO_ADDRINFO *addr_first;
-    const BIO_ADDRINFO *addr_iter;
-    /*
-     * int socket; this will be kept in bio->num so that it is compatible
-     * with the bss_sock bio
-     */
-    /*
-     * called when the connection is initially made callback(BIO,state,ret);
-     * The callback should return 'ret'.  state is for compatibility with the
-     * ssl info_callback
-     */
-    BIO_info_cb *info_callback;
-    /*
-     * Used when connect_sock_type is SOCK_DGRAM. Owned by us; we forward
-     * read/write(mmsg) calls to this if present.
-     */
-    BIO *dgram_bio;
-} BIO_CONNECT;
-
-typedef struct bio_accept_st {
-    int state;
-    int accept_family;
-    int bind_mode; /* Socket mode for BIO_listen */
-    int accepted_mode; /* Socket mode for BIO_accept (set on accepted sock) */
-    char *param_addr;
-    char *param_serv;
-
-    int accept_sock;
-
-    BIO_ADDRINFO *addr_first;
-    const BIO_ADDRINFO *addr_iter;
-    BIO_ADDR cache_accepting_addr; /* Useful if we asked for port 0 */
-    char *cache_accepting_name, *cache_accepting_serv;
-    BIO_ADDR cache_peer_addr;
-    char *cache_peer_name, *cache_peer_serv;
-
-    BIO *bio_chain;
-} BIO_ACCEPT;
-
-#ifndef OPENSSL_NO_DGRAM
-typedef struct bio_dgram_data_st {
-    BIO_ADDR peer;
-    BIO_ADDR local_addr;
-    unsigned int connected;
-    unsigned int _errno;
-    unsigned int mtu;
-    OSSL_TIME next_timeout;
-    OSSL_TIME socket_timeout;
-    unsigned int peekmode;
-    char local_addr_enabled;
-} bio_dgram_data;
-#endif
-
-#define BIO_CONN_S_BEFORE 1
-#define BIO_CONN_S_GET_ADDR 2
-#define BIO_CONN_S_CREATE_SOCKET 3
-#define BIO_CONN_S_CONNECT 4
-#define BIO_CONN_S_OK 5
-#define BIO_CONN_S_BLOCKED_CONNECT 6
-#define BIO_CONN_S_CONNECT_ERROR 7
-
-#define BIO_ACPT_S_BEFORE 1
-#define BIO_ACPT_S_GET_ADDR 2
-#define BIO_ACPT_S_CREATE_SOCKET 3
-#define BIO_ACPT_S_LISTEN 4
-#define BIO_ACPT_S_ACCEPT 5
-#define BIO_ACPT_S_OK 6
-
 #ifdef OPENSSL_SYS_VMS
 typedef unsigned int socklen_t;
 #endif
@@ -263,5 +178,3 @@ void bio_sock_cleanup_int(void);
 #endif
 
 #endif
-
-#endif /* !defined(OSSL_LIBCRYPTO_BIO_BIO_LOCAL_H) */
diff --git a/crypto/bio/bio_meth.c b/crypto/bio/bio_meth.c
index e97e51a720..0cab60491e 100644
--- a/crypto/bio/bio_meth.c
+++ b/crypto/bio/bio_meth.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -121,25 +121,12 @@ int bread_conv(BIO *bio, char *data, size_t datal, size_t *readbytes)
 {
     int ret;
 
-    if (datal == 0) {
-        *readbytes = 0;
-        return 1;
-    }
-
     if (datal > INT_MAX)
         datal = INT_MAX;
 
     ret = bio->method->bread_old(bio, data, (int)datal);
 
-    bio->flags &= ~BIO_FLAGS_AUTO_EOF;
-    if (ret == 0) {
-        if (BIO_ctrl(bio, BIO_CTRL_EOF, 0, NULL) == 0)
-            bio->flags |= BIO_FLAGS_AUTO_EOF;
-        *readbytes = 0;
-        return 0;
-    }
-
-    if (ret < 0) {
+    if (ret <= 0) {
         *readbytes = 0;
         return ret;
     }
diff --git a/crypto/bio/bio_print.c b/crypto/bio/bio_print.c
index 5366587a2a..2a78cd6373 100644
--- a/crypto/bio/bio_print.c
+++ b/crypto/bio/bio_print.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -28,7 +28,7 @@ int BIO_printf(BIO *bio, const char *format, ...)
     return ret;
 }
 
-#if defined(_MSC_VER) && _MSC_VER < 1900
+#if defined(_WIN32)
 /*
  * _MSC_VER described here:
  * https://learn.microsoft.com/en-us/cpp/overview/compiler-versions?view=msvc-170
@@ -70,9 +70,7 @@ static int msvc_bio_vprintf(BIO *bio, const char *format, va_list args)
 
     return ret;
 }
-#endif
 
-#ifdef _MSC_VER
 /*
  * This function is for unit test on windows only when built with Visual Studio
  */
@@ -87,12 +85,13 @@ int ossl_BIO_snprintf_msvc(char *buf, size_t n, const char *format, ...)
 
     return ret;
 }
+
 #endif
 
 int BIO_vprintf(BIO *bio, const char *format, va_list args)
 {
     va_list cp_args;
-#if !defined(_MSC_VER) || _MSC_VER >= 1900
+#if !defined(_MSC_VER) || _MSC_VER > 1900
     int sz;
 #endif
     int ret = -1;
@@ -111,7 +110,7 @@ int BIO_vprintf(BIO *bio, const char *format, va_list args)
      */
     sz = vsnprintf(buf, sizeof(buf), format, args);
     if (sz >= 0) {
-        if ((size_t)sz >= sizeof(buf)) {
+        if ((size_t)sz > sizeof(buf)) {
             sz += 1;
             abuf = (char *)OPENSSL_malloc(sz);
             if (abuf == NULL) {
diff --git a/crypto/bio/bio_sock.c b/crypto/bio/bio_sock.c
index 44e8f622ae..5b793b9af1 100644
--- a/crypto/bio/bio_sock.c
+++ b/crypto/bio/bio_sock.c
@@ -437,7 +437,7 @@ int BIO_socket_wait(int fd, int for_read, time_t max_time)
     time_t now;
 
 #ifdef _WIN32
-    if (fd == INVALID_SOCKET)
+    if ((SOCKET)fd == INVALID_SOCKET)
 #else
     if (fd < 0 || fd >= FD_SETSIZE)
 #endif
diff --git a/crypto/bio/bss_acpt.c b/crypto/bio/bss_acpt.c
index c9cdba041a..80e62df825 100644
--- a/crypto/bio/bss_acpt.c
+++ b/crypto/bio/bss_acpt.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,6 +15,26 @@
 
 #ifndef OPENSSL_NO_SOCK
 
+typedef struct bio_accept_st {
+    int state;
+    int accept_family;
+    int bind_mode; /* Socket mode for BIO_listen */
+    int accepted_mode; /* Socket mode for BIO_accept (set on accepted sock) */
+    char *param_addr;
+    char *param_serv;
+
+    int accept_sock;
+
+    BIO_ADDRINFO *addr_first;
+    const BIO_ADDRINFO *addr_iter;
+    BIO_ADDR cache_accepting_addr; /* Useful if we asked for port 0 */
+    char *cache_accepting_name, *cache_accepting_serv;
+    BIO_ADDR cache_peer_addr;
+    char *cache_peer_name, *cache_peer_serv;
+
+    BIO *bio_chain;
+} BIO_ACCEPT;
+
 static int acpt_write(BIO *h, const char *buf, int num);
 static int acpt_read(BIO *h, char *buf, int size);
 static int acpt_puts(BIO *h, const char *str);
@@ -26,6 +46,13 @@ static void acpt_close_socket(BIO *data);
 static BIO_ACCEPT *BIO_ACCEPT_new(void);
 static void BIO_ACCEPT_free(BIO_ACCEPT *a);
 
+#define ACPT_S_BEFORE 1
+#define ACPT_S_GET_ADDR 2
+#define ACPT_S_CREATE_SOCKET 3
+#define ACPT_S_LISTEN 4
+#define ACPT_S_ACCEPT 5
+#define ACPT_S_OK 6
+
 static const BIO_METHOD methods_acceptp = {
     BIO_TYPE_ACCEPT,
     "socket accept",
@@ -56,7 +83,7 @@ static int acpt_new(BIO *bi)
     if ((ba = BIO_ACCEPT_new()) == NULL)
         return 0;
     bi->ptr = (char *)ba;
-    ba->state = BIO_ACPT_S_BEFORE;
+    ba->state = ACPT_S_BEFORE;
     bi->shutdown = 1;
     return 1;
 }
@@ -125,7 +152,7 @@ static int acpt_state(BIO *b, BIO_ACCEPT *c)
 
     for (;;) {
         switch (c->state) {
-        case BIO_ACPT_S_BEFORE:
+        case ACPT_S_BEFORE:
             if (c->param_addr == NULL && c->param_serv == NULL) {
                 ERR_raise_data(ERR_LIB_BIO,
                     BIO_R_NO_ACCEPT_ADDR_OR_SERVICE_SPECIFIED,
@@ -147,10 +174,10 @@ static int acpt_state(BIO *b, BIO_ACCEPT *c)
             OPENSSL_free(c->cache_peer_serv);
             c->cache_peer_serv = NULL;
 
-            c->state = BIO_ACPT_S_GET_ADDR;
+            c->state = ACPT_S_GET_ADDR;
             break;
 
-        case BIO_ACPT_S_GET_ADDR: {
+        case ACPT_S_GET_ADDR: {
             int family = AF_UNSPEC;
             switch (c->accept_family) {
             case BIO_FAMILY_IPV6:
@@ -186,10 +213,10 @@ static int acpt_state(BIO *b, BIO_ACCEPT *c)
                 goto exit_loop;
             }
             c->addr_iter = c->addr_first;
-            c->state = BIO_ACPT_S_CREATE_SOCKET;
+            c->state = ACPT_S_CREATE_SOCKET;
             break;
 
-        case BIO_ACPT_S_CREATE_SOCKET:
+        case ACPT_S_CREATE_SOCKET:
             ERR_set_mark();
             s = BIO_socket(BIO_ADDRINFO_family(c->addr_iter),
                 BIO_ADDRINFO_socktype(c->addr_iter),
@@ -211,11 +238,11 @@ static int acpt_state(BIO *b, BIO_ACCEPT *c)
             }
             c->accept_sock = s;
             b->num = s;
-            c->state = BIO_ACPT_S_LISTEN;
+            c->state = ACPT_S_LISTEN;
             s = -1;
             break;
 
-        case BIO_ACPT_S_LISTEN: {
+        case ACPT_S_LISTEN: {
             if (!BIO_listen(c->accept_sock,
                     BIO_ADDRINFO_address(c->addr_iter),
                     c->bind_mode)) {
@@ -239,19 +266,16 @@ static int acpt_state(BIO *b, BIO_ACCEPT *c)
                 }
             }
 
-            /* Free old values before assigning new ones to prevent memory leak */
-            OPENSSL_free(c->cache_accepting_name);
-            OPENSSL_free(c->cache_accepting_serv);
             c->cache_accepting_name = BIO_ADDR_hostname_string(&c->cache_accepting_addr, 1);
             c->cache_accepting_serv = BIO_ADDR_service_string(&c->cache_accepting_addr, 1);
-            c->state = BIO_ACPT_S_ACCEPT;
+            c->state = ACPT_S_ACCEPT;
             s = -1;
             ret = 1;
             goto end;
 
-        case BIO_ACPT_S_ACCEPT:
+        case ACPT_S_ACCEPT:
             if (b->next_bio != NULL) {
-                c->state = BIO_ACPT_S_OK;
+                c->state = ACPT_S_OK;
                 break;
             }
             BIO_clear_retry_flags(b);
@@ -307,14 +331,14 @@ static int acpt_state(BIO *b, BIO_ACCEPT *c)
 
             c->cache_peer_name = BIO_ADDR_hostname_string(&c->cache_peer_addr, 1);
             c->cache_peer_serv = BIO_ADDR_service_string(&c->cache_peer_addr, 1);
-            c->state = BIO_ACPT_S_OK;
+            c->state = ACPT_S_OK;
             bio = NULL;
             ret = 1;
             goto end;
 
-        case BIO_ACPT_S_OK:
+        case ACPT_S_OK:
             if (b->next_bio == NULL) {
-                c->state = BIO_ACPT_S_ACCEPT;
+                c->state = ACPT_S_ACCEPT;
                 break;
             }
             ret = 1;
@@ -385,11 +409,10 @@ static long acpt_ctrl(BIO *b, int cmd, long num, void *ptr)
     switch (cmd) {
     case BIO_CTRL_RESET:
         ret = 0;
-        data->state = BIO_ACPT_S_BEFORE;
+        data->state = ACPT_S_BEFORE;
         acpt_close_socket(b);
         BIO_ADDRINFO_free(data->addr_first);
         data->addr_first = NULL;
-        data->addr_iter = NULL;
         b->flags = 0;
         break;
     case BIO_C_DO_STATE_MACHINE:
@@ -447,7 +470,7 @@ static long acpt_ctrl(BIO *b, int cmd, long num, void *ptr)
     case BIO_C_SET_FD:
         b->num = *((int *)ptr);
         data->accept_sock = b->num;
-        data->state = BIO_ACPT_S_ACCEPT;
+        data->state = ACPT_S_ACCEPT;
         b->shutdown = (int)num;
         b->init = 1;
         break;
diff --git a/crypto/bio/bss_bio.c b/crypto/bio/bss_bio.c
index 8f7c0fcb3d..5470777f95 100644
--- a/crypto/bio/bss_bio.c
+++ b/crypto/bio/bss_bio.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -112,9 +112,6 @@ static int bio_read(BIO *bio, char *buf, int size_)
     size_t rest;
     struct bio_bio_st *b, *peer_b;
 
-    if (buf == NULL || size_ <= 0)
-        return 0;
-
     BIO_clear_retry_flags(bio);
 
     if (!bio->init)
@@ -129,6 +126,9 @@ static int bio_read(BIO *bio, char *buf, int size_)
 
     peer_b->request = 0; /* will be set in "retry_read" situation */
 
+    if (buf == NULL || size == 0)
+        return 0;
+
     if (peer_b->len == 0) {
         if (peer_b->closed)
             return 0; /* writer has closed, and no data is left */
diff --git a/crypto/bio/bss_conn.c b/crypto/bio/bss_conn.c
index c4355392e4..0d52e8e05f 100644
--- a/crypto/bio/bss_conn.c
+++ b/crypto/bio/bss_conn.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -16,6 +16,37 @@
 
 #ifndef OPENSSL_NO_SOCK
 
+typedef struct bio_connect_st {
+    int state;
+    int connect_family;
+    int connect_sock_type;
+    char *param_hostname;
+    char *param_service;
+    int connect_mode;
+#ifndef OPENSSL_NO_KTLS
+    unsigned char record_type;
+#endif
+    int tfo_first;
+
+    BIO_ADDRINFO *addr_first;
+    const BIO_ADDRINFO *addr_iter;
+    /*
+     * int socket; this will be kept in bio->num so that it is compatible
+     * with the bss_sock bio
+     */
+    /*
+     * called when the connection is initially made callback(BIO,state,ret);
+     * The callback should return 'ret'.  state is for compatibility with the
+     * ssl info_callback
+     */
+    BIO_info_cb *info_callback;
+    /*
+     * Used when connect_sock_type is SOCK_DGRAM. Owned by us; we forward
+     * read/write(mmsg) calls to this if present.
+     */
+    BIO *dgram_bio;
+} BIO_CONNECT;
+
 static int conn_write(BIO *h, const char *buf, int num);
 static int conn_read(BIO *h, char *buf, int size);
 static int conn_puts(BIO *h, const char *str);
@@ -34,6 +65,14 @@ static void conn_close_socket(BIO *data);
 static BIO_CONNECT *BIO_CONNECT_new(void);
 static void BIO_CONNECT_free(BIO_CONNECT *a);
 
+#define BIO_CONN_S_BEFORE 1
+#define BIO_CONN_S_GET_ADDR 2
+#define BIO_CONN_S_CREATE_SOCKET 3
+#define BIO_CONN_S_CONNECT 4
+#define BIO_CONN_S_OK 5
+#define BIO_CONN_S_BLOCKED_CONNECT 6
+#define BIO_CONN_S_CONNECT_ERROR 7
+
 static const BIO_METHOD methods_connectp = {
     BIO_TYPE_CONNECT,
     "socket connect",
@@ -334,9 +373,8 @@ static int conn_read(BIO *b, char *out, int outl)
         return ret;
     }
 
-    if (out != NULL && outl > 0) {
+    if (out != NULL) {
         clear_socket_error();
-        b->flags &= ~BIO_FLAGS_IN_EOF;
 #ifndef OPENSSL_NO_KTLS
         if (BIO_get_ktls_recv(b))
             ret = ktls_read_record(b->num, out, outl);
@@ -376,7 +414,7 @@ static int conn_write(BIO *b, const char *in, int inl)
     clear_socket_error();
 #ifndef OPENSSL_NO_KTLS
     if (BIO_should_ktls_ctrl_msg_flag(b)) {
-        ret = ktls_send_ctrl_message(b->num, data->record_type, in, inl, 0);
+        ret = ktls_send_ctrl_message(b->num, data->record_type, in, inl);
         if (ret >= 0) {
             ret = inl;
             BIO_clear_ktls_ctrl_msg_flag(b);
@@ -422,7 +460,6 @@ static long conn_ctrl(BIO *b, int cmd, long num, void *ptr)
         conn_close_socket(b);
         BIO_ADDRINFO_free(data->addr_first);
         data->addr_first = NULL;
-        data->addr_iter = NULL;
         b->flags = 0;
         break;
     case BIO_C_DO_STATE_MACHINE:
@@ -739,7 +776,6 @@ int conn_gets(BIO *bio, char *buf, int size)
     }
 
     clear_socket_error();
-    bio->flags &= ~BIO_FLAGS_IN_EOF;
     while (size-- > 1) {
 #ifndef OPENSSL_NO_KTLS
         if (BIO_get_ktls_recv(bio))
diff --git a/crypto/bio/bss_dgram.c b/crypto/bio/bss_dgram.c
index 1d98239511..1f62ecf844 100644
--- a/crypto/bio/bss_dgram.c
+++ b/crypto/bio/bss_dgram.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2005-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2005-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -14,6 +14,7 @@
 #include 
 #include 
 
+#include "internal/time.h"
 #include "bio_local.h"
 #ifndef OPENSSL_NO_DGRAM
 
@@ -67,8 +68,8 @@
 #undef NO_RECVMMSG
 #define NO_RECVMMSG
 #endif
-#if defined(_AIX)
-/* AIX header files don't properly expose sendmmsg/recvmmsg declarations */
+#if defined(_AIX) && !defined(_AIX72)
+/* AIX >= 7.2 provides sendmmsg() and recvmmsg(). */
 #undef NO_RECVMMSG
 #define NO_RECVMMSG
 #endif
@@ -212,7 +213,21 @@ static const BIO_METHOD methods_dgramp_sctp = {
     NULL, /* sendmmsg */
     NULL, /* recvmmsg */
 };
+#endif
 
+typedef struct bio_dgram_data_st {
+    BIO_ADDR peer;
+    BIO_ADDR local_addr;
+    unsigned int connected;
+    unsigned int _errno;
+    unsigned int mtu;
+    OSSL_TIME next_timeout;
+    OSSL_TIME socket_timeout;
+    unsigned int peekmode;
+    char local_addr_enabled;
+} bio_dgram_data;
+
+#ifndef OPENSSL_NO_SCTP
 typedef struct bio_dgram_sctp_save_message_st {
     BIO *bio;
     char *data;
@@ -412,7 +427,7 @@ static int dgram_read(BIO *b, char *out, int outl)
     BIO_ADDR peer;
     socklen_t len = sizeof(peer);
 
-    if (out != NULL && outl > 0) {
+    if (out != NULL) {
         clear_socket_error();
         BIO_ADDR_clear(&peer);
         dgram_adjust_rcv_timeout(b);
@@ -946,7 +961,7 @@ static long dgram_ctrl(BIO *b, int cmd, long num, void *ptr)
                 ERR_raise_data(ERR_LIB_SYS, get_last_socket_error(),
                     "calling setsockopt()");
 
-#elif defined(OPENSSL_SYS_LINUX) && defined(IPV6_MTU_DISCOVER) && defined(IPV6_PMTUDISC_PROBE)
+#elif defined(OPENSSL_SYS_LINUX) && defined(IPV6_MTU_DISCOVER)
             sockopt_val = num ? IPV6_PMTUDISC_PROBE : IPV6_PMTUDISC_DONT;
             if ((ret = setsockopt(b->num, IPPROTO_IPV6, IPV6_MTU_DISCOVER,
                      &sockopt_val, sizeof(sockopt_val)))
@@ -1332,7 +1347,7 @@ static int dgram_sendmmsg(BIO *b, BIO_MSG *msg, size_t stride,
     size_t i;
     struct mmsghdr mh[BIO_MAX_MSGS_PER_CALL];
     struct iovec iov[BIO_MAX_MSGS_PER_CALL];
-    unsigned char control[BIO_MAX_MSGS_PER_CALL][BIO_CMSG_ALLOC_LEN] = { { 0 } };
+    unsigned char control[BIO_MAX_MSGS_PER_CALL][BIO_CMSG_ALLOC_LEN];
     int have_local_enabled = data->local_addr_enabled;
 #elif M_METHOD == M_METHOD_RECVMSG
     int sysflags;
@@ -1340,7 +1355,7 @@ static int dgram_sendmmsg(BIO *b, BIO_MSG *msg, size_t stride,
     ossl_ssize_t l;
     struct msghdr mh;
     struct iovec iov;
-    unsigned char control[BIO_CMSG_ALLOC_LEN] = { 0 };
+    unsigned char control[BIO_CMSG_ALLOC_LEN];
     int have_local_enabled = data->local_addr_enabled;
 #elif M_METHOD == M_METHOD_WSARECVMSG
     bio_dgram_data *data = (bio_dgram_data *)b->ptr;
@@ -1348,7 +1363,7 @@ static int dgram_sendmmsg(BIO *b, BIO_MSG *msg, size_t stride,
     WSAMSG wmsg;
     WSABUF wbuf;
     DWORD num_bytes_sent = 0;
-    unsigned char control[BIO_CMSG_ALLOC_LEN] = { 0 };
+    unsigned char control[BIO_CMSG_ALLOC_LEN];
 #endif
 #if M_METHOD == M_METHOD_RECVFROM || M_METHOD == M_METHOD_WSARECVMSG
     int sysflags;
diff --git a/crypto/bio/bss_dgram_pair.c b/crypto/bio/bss_dgram_pair.c
index d0136b4afc..bd9b7b892c 100644
--- a/crypto/bio/bss_dgram_pair.c
+++ b/crypto/bio/bss_dgram_pair.c
@@ -305,7 +305,6 @@ static int dgram_mem_init(BIO *bio)
     b = bio->ptr;
 
     if (ring_buf_init(&b->rbuf, b->req_buf_len) == 0) {
-        dgram_pair_free(bio);
         ERR_raise(ERR_LIB_BIO, ERR_R_BIO_LIB);
         return 0;
     }
diff --git a/crypto/bio/bss_fd.c b/crypto/bio/bss_fd.c
index 910da5e8b6..eb0119d63c 100644
--- a/crypto/bio/bss_fd.c
+++ b/crypto/bio/bss_fd.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -114,9 +114,8 @@ static int fd_read(BIO *b, char *out, int outl)
 {
     int ret = 0;
 
-    if (out != NULL && outl > 0) {
+    if (out != NULL) {
         clear_sys_error();
-        b->flags &= ~BIO_FLAGS_IN_EOF;
         ret = (int)UP_read(b->num, out, outl);
         BIO_clear_retry_flags(b);
         if (ret <= 0) {
diff --git a/crypto/bio/bss_file.c b/crypto/bio/bss_file.c
index 7aed585342..5d9300e74e 100644
--- a/crypto/bio/bss_file.c
+++ b/crypto/bio/bss_file.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -57,18 +57,12 @@ static const BIO_METHOD methods_filep = {
 BIO *BIO_new_file(const char *filename, const char *mode)
 {
     BIO *ret;
-    FILE *file;
+    FILE *file = openssl_fopen(filename, mode);
     int fp_flags = BIO_CLOSE;
 
     if (strchr(mode, 'b') == NULL)
         fp_flags |= BIO_FP_TEXT;
 
-    if (filename == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return NULL;
-    }
-
-    file = openssl_fopen(filename, mode);
     if (file == NULL) {
         ERR_raise_data(ERR_LIB_SYS, get_last_sys_error(),
             "calling fopen(%s, %s)",
@@ -143,7 +137,7 @@ static int file_read(BIO *b, char *out, int outl)
 {
     int ret = 0;
 
-    if (b->init != 0 && out != NULL && outl > 0) {
+    if (b->init && (out != NULL)) {
         if (b->flags & BIO_FLAGS_UPLINK_INTERNAL)
             ret = (int)UP_fread(out, 1, outl, b->ptr);
         else
@@ -163,16 +157,23 @@ static int file_read(BIO *b, char *out, int outl)
 
 static int file_write(BIO *b, const char *in, int inl)
 {
-    size_t ret = 0;
+    int ret = 0;
 
-    if (inl < INT_MAX && inl >= 0 && b->init && (in != NULL)) {
+    if (b->init && (in != NULL)) {
         if (b->flags & BIO_FLAGS_UPLINK_INTERNAL)
-            ret = (int)UP_fwrite(in, 1, (size_t)inl, b->ptr);
+            ret = (int)UP_fwrite(in, inl, 1, b->ptr);
         else
-            ret = fwrite(in, 1, (size_t)inl, (FILE *)b->ptr);
+            ret = (int)fwrite(in, inl, 1, (FILE *)b->ptr);
+        if (ret)
+            ret = inl;
+        /* ret=fwrite(in,1,(int)inl,(FILE *)b->ptr); */
+        /*
+         * according to Tim Hudson , the commented out
+         * version above can cause 'inl' write calls under some stupid stdio
+         * implementations (VMS)
+         */
     }
-
-    return (int)ret;
+    return ret;
 }
 
 static long file_ctrl(BIO *b, int cmd, long num, void *ptr)
@@ -192,44 +193,17 @@ static long file_ctrl(BIO *b, int cmd, long num, void *ptr)
             ret = (long)fseek(fp, num, 0);
         break;
     case BIO_CTRL_EOF:
-        /*
-         * NOTE feof returns 0 if we're not in an eof condition
-         * and a non-zero value if we are (i.e. any non-zero value
-         * so we map the 0:non-0 return value here to 0:1 with a
-         * double negation
-         */
         if (b->flags & BIO_FLAGS_UPLINK_INTERNAL)
-            ret = !!(long)UP_feof(fp);
+            ret = (long)UP_feof(fp);
         else
-            ret = !!(long)feof(fp);
-#if defined(OPENSSL_SYS_WINDOWS)
-        /*
-         * Windows gives us an extra issue to contend with.
-         * In windows feof may return 0 if it is passed an invalid
-         * stream.  In this event, feof sets errno to EINVAL.
-         * Check for that here, and set ret to -EINVAL if its the case.
-         */
-        if (ret == 0 && errno == EINVAL)
-            ret = -EINVAL;
-#endif
+            ret = (long)feof(fp);
         break;
     case BIO_C_FILE_TELL:
     case BIO_CTRL_INFO:
         if (b->flags & BIO_FLAGS_UPLINK_INTERNAL)
             ret = UP_ftell(b->ptr);
-        else {
-#if defined(OPENSSL_SYS_WINDOWS)
-            /*
-             * On Windows, for non-seekable files (stdin), ftell() is undefined.
-             */
-            if (GetFileType((HANDLE)_get_osfhandle(_fileno(fp))) != FILE_TYPE_DISK)
-                ret = -1;
-            else
-                ret = ftell(fp);
-#else
+        else
             ret = ftell(fp);
-#endif
-        }
         break;
     case BIO_C_SET_FILE_PTR:
         file_free(b);
@@ -309,11 +283,6 @@ static long file_ctrl(BIO *b, int cmd, long num, void *ptr)
         if (!(num & BIO_FP_TEXT))
             OPENSSL_strlcat(p, "b", sizeof(p));
 #endif
-        if (ptr == NULL) {
-            ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-            ret = 0;
-            break;
-        }
         fp = openssl_fopen(ptr, p);
         if (fp == NULL) {
             ERR_raise_data(ERR_LIB_SYS, get_last_sys_error(),
@@ -332,13 +301,7 @@ static long file_ctrl(BIO *b, int cmd, long num, void *ptr)
         /* the ptr parameter is actually a FILE ** in this case. */
         if (ptr != NULL) {
             fpp = (FILE **)ptr;
-            if (BIO_FLAGS_UPLINK_INTERNAL == 0
-                || b->flags & BIO_FLAGS_UPLINK_INTERNAL) {
-                *fpp = (FILE *)b->ptr;
-            } else { /* avoid returning internal FILE * to the app */
-                *fpp = NULL;
-                ret = 0;
-            }
+            *fpp = (FILE *)b->ptr;
         }
         break;
     case BIO_CTRL_GET_CLOSE:
diff --git a/crypto/bio/bss_log.c b/crypto/bio/bss_log.c
index 2928ae5c41..8f8e180468 100644
--- a/crypto/bio/bss_log.c
+++ b/crypto/bio/bss_log.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -22,7 +22,8 @@
 #include "bio_local.h"
 #include "internal/cryptlib.h"
 
-#if defined(OPENSSL_SYS_WIN32)
+#if defined(OPENSSL_SYS_WINCE)
+#elif defined(OPENSSL_SYS_WIN32)
 #elif defined(__wasi__)
 #define NO_SYSLOG
 #elif defined(OPENSSL_SYS_VMS)
@@ -90,10 +91,10 @@ static const BIO_METHOD methods_slg = {
     "syslog",
     bwrite_conv,
     slg_write,
-    NULL, /* slg_read          */
-    NULL, /* slg_read_old      */
+    NULL, /* slg_write_old,    */
+    NULL, /* slg_read,         */
     slg_puts,
-    NULL, /* slg_gets          */
+    NULL,
     slg_ctrl,
     slg_new,
     slg_free,
diff --git a/crypto/bio/bss_mem.c b/crypto/bio/bss_mem.c
index b39f186d9d..7d817fecd0 100644
--- a/crypto/bio/bss_mem.c
+++ b/crypto/bio/bss_mem.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -125,7 +125,6 @@ static int mem_init(BIO *bi, unsigned long flags)
     bi->shutdown = 1;
     bi->init = 1;
     bi->num = -1;
-    bi->flags |= BIO_FLAGS_MEM_LEGACY_EOF;
     bi->ptr = (char *)bb;
     return 1;
 }
@@ -289,14 +288,10 @@ static long mem_ctrl(BIO *b, int cmd, long num, void *ptr)
             ret = -1;
         break;
     case BIO_CTRL_EOF:
-        if (b->num == 0 || (b->flags & BIO_FLAGS_MEM_LEGACY_EOF) != 0)
-            ret = (long)(bm->length == 0);
-        else
-            ret = 0;
+        ret = (long)(bm->length == 0);
         break;
     case BIO_C_SET_BUF_MEM_EOF_RETURN:
         b->num = (int)num;
-        b->flags &= ~BIO_FLAGS_MEM_LEGACY_EOF;
         break;
     case BIO_CTRL_INFO:
         ret = (long)bm->length;
diff --git a/crypto/bio/bss_sock.c b/crypto/bio/bss_sock.c
index ef25ccada5..11a8ce200c 100644
--- a/crypto/bio/bss_sock.c
+++ b/crypto/bio/bss_sock.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -34,7 +34,6 @@ struct bss_sock_st {
 #ifndef OPENSSL_NO_KTLS
     unsigned char ktls_record_type;
 #endif
-    int sflags;
 };
 
 static int sock_write(BIO *h, const char *buf, int num);
@@ -107,9 +106,8 @@ static int sock_read(BIO *b, char *out, int outl)
 {
     int ret = 0;
 
-    if (out != NULL && outl > 0) {
+    if (out != NULL) {
         clear_socket_error();
-        b->flags &= ~BIO_FLAGS_IN_EOF;
 #ifndef OPENSSL_NO_KTLS
         if (BIO_get_ktls_recv(b))
             ret = ktls_read_record(b->num, out, outl);
@@ -118,10 +116,10 @@ static int sock_read(BIO *b, char *out, int outl)
             ret = readsocket(b->num, out, outl);
         BIO_clear_retry_flags(b);
         if (ret <= 0) {
-            if (ret == 0)
-                b->flags |= BIO_FLAGS_IN_EOF;
-            else if (BIO_sock_should_retry(ret))
+            if (BIO_sock_should_retry(ret))
                 BIO_set_retry_read(b);
+            else if (ret == 0)
+                b->flags |= BIO_FLAGS_IN_EOF;
         }
     }
     return ret;
@@ -130,13 +128,15 @@ static int sock_read(BIO *b, char *out, int outl)
 static int sock_write(BIO *b, const char *in, int inl)
 {
     int ret = 0;
+#if !defined(OPENSSL_NO_KTLS) || defined(OSSL_TFO_SENDTO)
     struct bss_sock_st *data = (struct bss_sock_st *)b->ptr;
+#endif
 
     clear_socket_error();
 #ifndef OPENSSL_NO_KTLS
     if (BIO_should_ktls_ctrl_msg_flag(b)) {
         unsigned char record_type = data->ktls_record_type;
-        ret = ktls_send_ctrl_message(b->num, record_type, in, inl, data->sflags);
+        ret = ktls_send_ctrl_message(b->num, record_type, in, inl);
         if (ret >= 0) {
             ret = inl;
             BIO_clear_ktls_ctrl_msg_flag(b);
@@ -145,14 +145,15 @@ static int sock_write(BIO *b, const char *in, int inl)
 #endif
 #if defined(OSSL_TFO_SENDTO)
         if (data->tfo_first) {
+        struct bss_sock_st *data = (struct bss_sock_st *)b->ptr;
         socklen_t peerlen = BIO_ADDR_sockaddr_size(&data->tfo_peer);
 
-        ret = sendto(b->num, in, inl, OSSL_TFO_SENDTO | data->sflags,
+        ret = sendto(b->num, in, inl, OSSL_TFO_SENDTO,
             BIO_ADDR_sockaddr(&data->tfo_peer), peerlen);
         data->tfo_first = 0;
     } else
 #endif
-        ret = writesocket_ex(b->num, in, inl, data->sflags);
+        ret = writesocket(b->num, in, inl);
     BIO_clear_retry_flags(b);
     if (ret <= 0) {
         if (BIO_sock_should_retry(ret))
@@ -263,20 +264,6 @@ static long sock_ctrl(BIO *b, int cmd, long num, void *ptr)
             ret = 0;
         }
         break;
-    case BIO_C_SET_SEND_FLAGS:
-        if (num > INT_MAX || num < INT_MIN) {
-            ERR_raise(ERR_LIB_BIO, BIO_R_INVALID_ARGUMENT);
-            return 0;
-        }
-#if defined(OPENSSL_SYS_VXWORKS) || defined(OPENSSL_SYS_TANDEM)
-        if (num != 0) {
-            ERR_raise(ERR_LIB_BIO, BIO_R_INVALID_ARGUMENT);
-            return 0;
-        }
-#endif
-        data->sflags = (int)num;
-        ret = 1;
-        break;
     default:
         ret = 0;
         break;
@@ -322,9 +309,6 @@ int BIO_sock_non_fatal_error(int err)
         || err == EINTR
 #if !defined(__DJGPP__) && !defined(OPENSSL_SYS_TANDEM)
         || err == EPROTO
-#endif
-#ifdef __FreeBSD__
-        || err == EBUSY
 #endif
         || err == EINPROGRESS
         || err == EALREADY;
diff --git a/crypto/bn/asm/armv4-gf2m.pl b/crypto/bn/asm/armv4-gf2m.pl
index f722804b2f..7375e3970a 100644
--- a/crypto/bn/asm/armv4-gf2m.pl
+++ b/crypto/bn/asm/armv4-gf2m.pl
@@ -37,7 +37,7 @@
 # Câmara, D.; Gouvêa, C. P. L.; López, J. & Dahab, R.: Fast Software
 # Polynomial Multiplication on ARM Processors using the NEON Engine.
 #
-# https://conradoplg.modp.net/files/2010/12/mocrysen13.pdf
+# http://conradoplg.cryptoland.net/files/2010/12/mocrysen13.pdf
 
 # $output is the last argument if it looks like a file (it has an extension)
 # $flavour is the first argument if it doesn't look like a file
@@ -57,7 +57,7 @@ if ($flavour && $flavour ne "void") {
 }
 
 $code=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 #if defined(__thumb2__)
 .syntax	unified
diff --git a/crypto/bn/asm/armv4-mont.pl b/crypto/bn/asm/armv4-mont.pl
index 9429440e87..ad474e3899 100644
--- a/crypto/bn/asm/armv4-mont.pl
+++ b/crypto/bn/asm/armv4-mont.pl
@@ -97,7 +97,7 @@ $_n0="$num,#14*4";
 $_num="$num,#15*4";	$_bpend=$_num;
 
 $code=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 #if defined(__thumb2__)
 .syntax	unified
diff --git a/crypto/bn/asm/armv8-mont.pl b/crypto/bn/asm/armv8-mont.pl
index 9f0495f270..f1692caae7 100755
--- a/crypto/bn/asm/armv8-mont.pl
+++ b/crypto/bn/asm/armv8-mont.pl
@@ -67,7 +67,7 @@ $n0="x4";	# const BN_ULONG *n0,
 $num="x5";	# int num);
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 #ifndef	__KERNEL__
 .extern OPENSSL_armv8_rsa_neonized
 .hidden OPENSSL_armv8_rsa_neonized
@@ -780,7 +780,7 @@ __bn_sqr8x_mont:
 	umulh	$t2,$a4,$a0
 	stp	$acc0,$acc1,[$tp],#8*2	// t[0..1]
 	adc	$acc0,xzr,xzr		// t[8]
-	adds	$acc2,$acc2,$t3		// t[2]+hi(a[1]*a[0])
+	adds	$acc2,$acc2,$t3		// t[2]+lo(a[1]*a[0])
 	umulh	$t3,$a5,$a0
 	adcs	$acc3,$acc3,$t0
 	umulh	$t0,$a6,$a0
diff --git a/crypto/bn/asm/mips-mont.pl b/crypto/bn/asm/mips-mont.pl
index b26989271f..b3740b7527 100644
--- a/crypto/bn/asm/mips-mont.pl
+++ b/crypto/bn/asm/mips-mont.pl
@@ -124,7 +124,7 @@ $m1=$s11;
 $FRAMESIZE=14;
 
 $code=<<___;
-#include "arch/mips_arch.h"
+#include "mips_arch.h"
 
 .text
 
diff --git a/crypto/bn/asm/mips.pl b/crypto/bn/asm/mips.pl
index 0e7046ac48..3240a3e398 100644
--- a/crypto/bn/asm/mips.pl
+++ b/crypto/bn/asm/mips.pl
@@ -111,7 +111,7 @@ $gp=$v1 if ($flavour =~ /nubi/i);
 $minus4=$v1;
 
 $code.=<<___;
-#include "arch/mips_arch.h"
+#include "mips_arch.h"
 
 #if defined(_MIPS_ARCH_MIPS64R6)
 # define ddivu(rs,rt)
diff --git a/crypto/bn/asm/riscv64-mont.pl b/crypto/bn/asm/riscv64-mont.pl
index f9db3c11eb..b512dcfd01 100644
--- a/crypto/bn/asm/riscv64-mont.pl
+++ b/crypto/bn/asm/riscv64-mont.pl
@@ -57,7 +57,7 @@ $output and open STDOUT,">$output";
             $stack_offset -= 8;
             $ret.="    sd      $_,$stack_offset(sp)\n";
         }
-        return $ret;
+	    return $ret;
     }
     sub load_regs {
         my $ret = '';
@@ -70,7 +70,7 @@ $output and open STDOUT,">$output";
             $stack_offset -= 8;
             $ret.="    ld      $_,$stack_offset(sp)\n";
         }
-        $ret.="    addi    sp,sp,$stack_reservation\n";
+	    $ret.="    addi    sp,sp,$stack_reservation\n";
         return $ret;
     }
     sub clear_regs {
@@ -84,12 +84,12 @@ $output and open STDOUT,">$output";
 
 # Function arguments
 #      RISC-V    ABI
-# $rp   x10     a0  # BN_ULONG *rp
-# $ap   x11     a1  # const BN_ULONG *ap
-# $bp   x12     a2  # const BN_ULONG *bp
-# $np   x13     a3  # const BN_ULONG *np
-# $n0   x14     a4  # const BN_ULONG *n0
-# $num  x15     a5  # int num
+# $rp	x10	     a0  # BN_ULONG *rp
+# $ap	x11	     a1  # const BN_ULONG *ap
+# $bp	x12	     a2  # const BN_ULONG *bp
+# $np	x13	     a3  # const BN_ULONG *np
+# $n0	x14      a4  # const BN_ULONG *n0
+# $num	x15      a5  # int num
 my ($rp,$ap,$bp,$np,$n0,$num) = use_regs(10,11,12,13,14,15);
 
 # Return address and Frame pointer
@@ -100,40 +100,37 @@ my ($ra,$fp) = use_regs(1,8);
 
 # Temporary variable allocation
 #      RISC-V    ABI
-# $lo0  x5     t0    the sum of partial products of a and b
-# $hi0  x6     t1    the high word of partial product of a and b + Carry
-# $aj   x7     t2    ap[j]
-# $m0   x28    t3    bp[i]
-# $alo  x29    t4    the low word of partial product
-# $ahi  x30    t5    the high word of partial product
-# $lo1  x31    t6    partial product + reduction term
-# $hi1  x18    s2    the high word of reduction term + Carry
-# $nj   x19    s3    np[j],modulus
-# $m1   x20    s4    montgomery reduction coefficient
-# $nlo  x21    s5    the low word of reduction term
-# $nhi  x22    s6    the high word of reduction term
-# $ovf  x23    s7    highest carry bit,overflow flag
-# $i    x24    s8    outer loop index
-# $j    x25    s9    inner loop index
-# $tp   x26    s10   temporary result storage
-# $tj   x27    s11   tp[j],temporary result value
-# $temp x9     s1
+# $lo0	x5	     t0    the sum of partial products of a and b
+# $hi0	x6	     t1    the high word of partial product of a and b + Carry
+# $aj	x7	     t2    ap[j]
+# $m0	x28	     t3    bp[i]
+# $alo	x29	     t4    the low word of partial product
+# $ahi	x30      t5    the high word of partial product
+# $lo1	x31	     t6    partial product + reduction term
+# $hi1	x18	     s2    the high word of reduction term + Carry
+# $nj	x19	     s3    np[j],modulus
+# $m1	x20	     s4    montgomery reduction coefficient
+# $nlo	x21	     s5    the low word of reduction term
+# $nhi	x22	     s6    the high word of reduction term
+# $ovf	x23	     s7    highest carry bit,overflow flag
+# $i	x24	     s8    outer loop index
+# $j	x25	     s9    inner loop index
+# $tp	x26	     s10   temporary result storage
+# $tj	x27	     s11   tp[j],temporary result value
+# $temp x9       s1
 my ($lo0,$hi0,$aj,$m0,$alo,$ahi,$lo1,$hi1,$nj,$m1,$nlo,$nhi,$ovf,$i,$j,$tp,$tj,$temp) = use_regs(5..7,28..31,18..27,9);
 
 # Carry variable
 # $carry1 x16      a6
 # $carry2 x17      a7
-my ($carry1,$carry2,$numtst) = use_regs(16,17,17);
+my ($carry1,$carry2) = use_regs(16,17);
 
 my $code .= <<___;
 .text
 .balign 32
 .globl bn_mul_mont
-.type bn_mul_mont,\@function
+.type   bn_mul_mont,\@function
 bn_mul_mont:
-    andi  $numtst, $num, 7
-    beqz  $numtst, bn_sqr8x_mont
-.Lmul_mont:
 ___
 
 $code .= save_regs();
@@ -142,24 +139,25 @@ $code .= <<___;
     mv $fp, sp
 ___
 
-$code .= <<___;
+$code .= <<___;	
     ld $m0, 0($bp)    # bp[0]
     addi $bp, $bp,8
     ld $hi0, 0($ap)    # ap[0]
-    slli $num, $num, 3
-    sub $tp, sp, $num
     ld $aj, 8($ap)    # ap[1]
     addi $ap, $ap, 16
     ld $n0, 0($n0)    # n0,precomputed modular inverse
-    andi $tp, $tp, -16    # address alignment
     ld $hi1, 0($np)    # np[0]
-    mv sp, $tp    # alloca
     ld $nj, 8($np)    # np[1]
     addi $np, $np, 16
 
+    slli $num, $num, 3
+    sub $tp, sp, $num
+    andi $tp, $tp, -16    # address alignment
+    mv sp, $tp    # alloca
+
+    addi $j, $num, -16    # $j=(num-2)*8
 
     mul $lo0, $hi0, $m0    # ap[0]*bp[0]
-    addi $j, $num, -16    # $j=(num-2)*8
     mulhu $hi0, $hi0, $m0
     mul $alo, $aj, $m0    # ap[1]*bp[0]
     mulhu $ahi, $aj, $m0
@@ -168,12 +166,12 @@ $code .= <<___;
     # montgomery optimization: np[0]*m1 ensures (np[0]*m1+lo0) has zero lower bits
     # only carry status needed, not full lo1 result
     # eliminates mul/adds instructions → Saves cycles & power
-    # mul $lo1, $hi1, $m1   // np[0]*m1
+    # mul $lo1, $hi1, $m1		// np[0]*m1
     # adds $lo1, $lo1, $lo0   // discarded
     mulhu $hi1, $hi1, $m1
     snez $carry1, $lo0
-    mul $nlo, $nj, $m1    # np[1]*m1
     add $hi1, $hi1, $carry1
+    mul $nlo, $nj, $m1    # np[1]*m1
     mulhu $nhi, $nj, $m1
     beqz $j, .L1st_last_entry
 
@@ -193,43 +191,46 @@ $code .= <<___;
     # compute the sum of reduction term
     add $lo1, $nlo, $hi1    # {np[j-1]*m1,low}+{np[j-2]*m1,high}, j ranges from 2 to num-1
     sltu $carry1, $lo1, $nlo
-    mul $alo, $aj, $m0    # ap[j]*bp[0], j ranges from 2 to num-1
     add $hi1, $nhi, $carry1    # {np[j-1]*m1,high}+C_lo1, j ranges from 2 to num-1
-    mulhu $ahi, $aj, $m0
+
     # partial product + reduction term
-    add $lo1, $lo1, $lo0
-    sltu $carry1, $lo1, $lo0
-    mul $nlo, $nj, $m1    # np[j]*m1, j ranges from 2 to num-1
+    add $temp, $lo1, $lo0
+    sltu $carry1, $temp, $lo1
+    mv $lo1, $temp
     add $hi1, $hi1, $carry1
-    mulhu $nhi, $nj, $m1
+
     sd $lo1, 0($tp)    # tp[j-2], j ranges from 2 to num-1
     addi $tp, $tp, 8
 
+    mul $alo, $aj, $m0    # ap[j]*bp[0], j ranges from 2 to num-1
+    mulhu $ahi, $aj, $m0
+    mul $nlo, $nj, $m1    # np[j]*m1, j ranges from 2 to num-1
+    mulhu $nhi, $nj, $m1
     bnez $j, .L1st
 
 .L1st_last_entry:
     # last partial product
     add $lo0, $alo, $hi0    # {ap[j]*bp[0],low}+{ap[j-1]*bp[0],high}, j is num-1
     sltu $carry1, $lo0, $alo
-    sub $ap, $ap, $num    # rewind $ap
     add $hi0, $ahi, $carry1    # {ap[j]*bp[0],high}+C_lo0, j is num-1
 
+    sub $ap, $ap, $num    # rewind $ap
+    sub $np, $np, $num    # rewind $np
+
     # last reduction term
     add $lo1, $nlo, $hi1    # {np[j]*m1,low}+{np[j-1]*m1,high}, j is num-1
     sltu $carry1, $lo1, $nlo
-    sub $np, $np, $num    # rewind $np
     add $hi1, $nhi, $carry1    # {np[j]*m1,high}+C_lo1, j is num-1
 
     # last partial product + last reduction term
     add $lo1, $lo1, $lo0
     sltu $carry1, $lo1, $lo0
 
-    add $hi1, $hi1, $hi0
-    sltu $carry2, $hi1, $hi0
-    add $hi1, $hi1, $carry1
-    sltu $ovf, $hi1, $carry1
+    add $temp, $hi1, $hi0
+    sltu $carry2, $temp, $hi1
+    add $hi1, $temp, $carry1
+    sltu $ovf, $hi1, $temp
     or $carry1, $carry2, $ovf    # carry2 and ovf are mutually exclusive, both cannot be 1 simultaneously
-
     mv $ovf, $carry1    # upmost overflow bit
 
     addi $i, $num, -8    # $i=(num-1)*8
@@ -247,16 +248,18 @@ $code .= <<___;
     addi $tp, sp, 8    # tp[1]
 
     mul $lo0, $hi0, $m0    # ap[0]*bp[i], i ranges from 1 to num-1
-    addi $j, $num,-16    # $j=(num-2)*8
     mulhu $hi0, $hi0, $m0
+
+    addi $j, $num,-16    # $j=(num-2)*8
     ld $hi1, 0($np)
     ld $nj, 8($np)
     addi $np, $np, 16
 
     mul $alo, $aj, $m0    # ap[1]*bp[i], i ranges from 1 to num-1
+    mulhu $ahi, $aj, $m0
+
     add $lo0, $lo0, $tj    # ap[0]*bp[i] + last_tp[0] , i ranges from 1 to num-1
     sltu $carry1, $lo0, $tj
-    mulhu $ahi, $aj, $m0
     add $hi0, $hi0, $carry1    # $hi0 will not overflow
 
     # compute the modular reduction coefficient
@@ -264,6 +267,8 @@ $code .= <<___;
 
     addi $i, $i, -8    # $i--, $i ranges from (num-1)*8 to 0
 
+    # mul $lo1, $hi1, $m1	 # discarded
+    # adds	$lo1, $lo1, $lo0   # discarded
     mulhu $hi1, $hi1, $m1
     snez $carry1, $lo0
     mul $nlo, $nj, $m1    # np[1]*m1
@@ -294,19 +299,21 @@ $code .= <<___;
     ld $nj, 0($np)
     addi $np, $np, 8
 
-    mul $alo, $aj, $m0    # ap[j]*bp[i], j ranges from 2 to num-1, i ranges from 1 to num-1
     # partial product + reduction term
     add $lo0, $lo0, $tj
     sltu $carry1, $lo0, $tj
-    mulhu $ahi, $aj, $m0
     add $hi0, $hi0, $carry1
 
-    mul $nlo, $nj, $m1    # np[j]*m1, j ranges from 2 to num-1
     add $lo1, $lo1, $lo0
     sltu $carry1, $lo1, $lo0
-    mulhu $nhi, $nj, $m1
+
     sd $lo1, -16($tp)    # tp[j-2], j ranges from 2 to num-1
 
+    mul $alo, $aj, $m0    # ap[j]*bp[i], j ranges from 2 to num-1, i ranges from 1 to num-1
+    mulhu $ahi, $aj, $m0
+    mul $nlo, $nj, $m1    # np[j]*m1, j ranges from 2 to num-1
+    mulhu $nhi, $nj, $m1
+
     bnez $j, .Linner
 
 .Linner_last_entry:
@@ -317,21 +324,19 @@ $code .= <<___;
     # last partial product
     add $lo0, $alo, $hi0    # {ap[j]*bp[i],low}+{ap[j-1]*bp[i],high}, j is num-1, i ranges from 1 to num-1
     sltu $carry1, $lo0, $alo
-    sub $ap, $ap, $num    # rewind $ap
     add $hi0, $ahi, $carry1    # {ap[j]*bp[i],high}+C_lo0, j is num-1, i ranges from 1 to num-1
 
+    sub $ap, $ap, $num    # rewind $ap
+    sub	$np, $np, $num    # rewind $np
+
     # last reduction term
     add $lo1, $nlo, $hi1    # {np[j]*m1,low}+{np[j-1]*m1,high}, j is num-1
     sltu $carry1, $lo1, $nlo
-
-    sub $np, $np, $num    # rewind $np
-
-    add $hi1, $nhi, $ovf
-    sltu $carry2, $hi1, $ovf
-    add $hi1, $hi1, $carry1    # {np[j]*m1,high}+C_lo1, j is num-1
-    sltu $ovf, $hi1, $carry1
+    add $temp, $nhi, $ovf
+    sltu $carry2, $temp, $nhi
+    add $hi1, $temp, $carry1    # {np[j]*m1,high}+C_lo1, j is num-1
+    sltu $ovf, $hi1, $temp
     or $carry1, $carry2, $ovf
-
     mv $ovf, $carry1    # update the upmost overflow bit
 
     # last partial product + last reduction term
@@ -341,11 +346,10 @@ $code .= <<___;
 
     add $lo1, $lo1, $lo0
     sltu $carry1, $lo1, $lo0
-
-    add $hi1, $hi1, $hi0
-    sltu $carry2, $hi1, $hi0
-    add $hi1, $hi1, $carry1
-    sltu $carry1, $hi1, $carry1
+    add $temp, $hi1, $hi0
+    sltu $carry2, $temp, $hi1
+    add $hi1, $temp, $carry1
+    sltu $carry1, $hi1, $temp
     or $carry1, $carry2, $carry1
 
     add $ovf, $ovf, $carry1    # upmost overflow bit
@@ -359,16 +363,18 @@ $code .= <<___;
     ld $nj, 0($np)    # np[0]
     addi $np, $np, 8
     addi $j, $num, -8    # $j=(num-1)*8 and clear borrow
-
-    li $carry1,0   # Custom, no borrow, C=0 (normal case, with borrow C=1)
+    sltu $carry1, $num, 8
+    xori $carry1, $carry1, 1
     mv $ap, $rp
 .Lsub:
     # tp[j]-np[j], j ranges from 0 to num-2, set carry flag
+    xori $carry1, $carry1,1
     sub $temp, $tj, $nj
     sltu $carry2, $tj, $temp
     sub $aj, $temp, $carry1
     sltu $carry1, $temp, $aj
     or $carry1, $carry2, $carry1
+    xori $carry1, $carry1, 1
 
     ld $tj, 0($tp)    # tp[j], j ranges from 1 to num-1
     addi $tp, $tp, 8
@@ -381,15 +387,21 @@ $code .= <<___;
     bnez $j, .Lsub
 
     # process the last word, tp[j]-np[j], j is num-1
+    xori $carry1, $carry1,1
     sub $temp, $tj, $nj
     sltu $carry2, $tj, $temp
     sub $aj, $temp, $carry1
     sltu $carry1, $temp, $aj
     or $carry1, $carry2, $carry1
+    xori $carry1, $carry1, 1
 
     # whether there is a borrow
-    sub $temp, $ovf, $carry1
-    sltu $carry1, $ovf, $temp
+    xori $carry1, $carry1, 1
+    sub $temp, $ovf, zero
+    sltu $carry2, $ovf, $temp
+    sub $ovf, $temp, $carry1
+    sltu $carry1, $temp, $ovf
+    or $carry1, $carry2, $carry1
     xori $carry1, $carry1, 1
 
     sd $aj, 0($ap)    # rp[j], j is num-1
@@ -402,6 +414,7 @@ $code .= <<___;
     addi $rp, $rp, 8
     addi $num, $num, -8    # num--
     nop
+
 .Lcond_copy:
     addi $num,$num, -8    # num--
     # conditionally selects value based on borrow flag:
@@ -440,1440 +453,8 @@ $code .= load_regs();
 
 $code .= <<___;
     ret
-.size bn_mul_mont,.-bn_mul_mont
+.size	bn_mul_mont,.-bn_mul_mont
 ___
 
-{
-# Following is RISCV64 adaptation of __bn_sqr8x_mont from armv8-mont module.
-
-# Return address and Frame pointer
-#      RISC-V    ABI
-# $ra   x1       ra
-# $fp   x8       s0
-my ($ra,$fp) = use_regs(1,8);
-
-# Temporary variable allocation
-#      RISC-V    ABI
-# $a0   x5     t0
-# $a1   x6     t1
-# $a2   x7     t2
-# $a3   x28    t3
-# $a4   x9     s1
-# $a5   x18    s2
-# $a6   x19    s3
-# $a7   x20    s4
-my ($a0,$a1,$a2,$a3,$a4,$a5,$a6,$a7) = use_regs(5,6,7,28,9,18,19,20);
-
-# $t0   x16     a6
-# $t1   x17     a7
-# $t2   x29     t4
-# $t3   x30     t5
-my ($t0,$t1,$t2,$t3) = use_regs(16,17,29,30);
-
-# $acc0 x21    s5
-# $acc1 x22    s6
-# $acc2 x23    s7
-# $acc3 x24    s8
-# $acc4 x25    s9
-# $acc5 x31    t6
-# $acc6 x27    s11
-# $acc7 x26    s10
-my ($acc0,$acc1,$acc2,$acc3,$acc4,$acc5,$acc6,$acc7) = use_regs(21,22,23,24,25,31,27,26);
-
-# $temp   x14    a4
-# $carry1 x15    a5
-# $carry2 x10    a0
-# $carry  x1     ra
-my ($temp, $carry1, $carry2, $carry) = use_regs(14,15,10,1);
-
-# $tp     x12    a2
-# $na0    x1     ra
-my ($tp,$na0) = use_regs(12,1);
-
-# Stack variables
-# rp       fp+96
-# np       fp+104
-# num      fp+112
-# n0       fp+120
-# ra       fp+128
-# cnt      fp+136
-# ap_end   fp+144
-# np_end   fp+152
-# topmost  fp+160
-
-# My_function
-sub adds {
-    # Simulate ARM 'adds':add with carry flag set
-    # (1) Final sum: dst = src1 + b, no input carry
-    # (2) Output carry, if src1 + b overflowed, carry = 1. src1 + b < b ? carry1=1 : carry1=0
-    my ($dst, $src1, $b) = @_;
-    my $code=<<___;
-    add $dst, $src1, $b
-    sltu $carry1, $dst, $b
-___
-    return $code;
-}
-
-sub adcs {
-    # Simulate ARM 'adcs': add with input carry and set output carry
-    # (1) Temp sum. dst = src1 + b, ignore input carry
-    # (2) Temp1 carry. if src1 + b overflowed, carry2 = 1. src1 + b < b ? carry2=1 : carry2=0
-    # (3) Final sum: dst += carry1 (input carry)
-    # (4) Temp2 carry. if adding input carry overflowed, carry1 = 1. dst + carry1 < carry1 ? carry1=1 : carry1=0
-    # (5) Final carry. carry1(carry_out) = carry2 | carry1
-    my ($dst, $src1, $b) = @_;
-    my $code=<<___;
-    add $dst, $src1, $b
-    sltu $carry2, $dst, $b
-    add $dst, $dst, $carry1
-    sltu $carry1, $dst, $carry1
-    or $carry1, $carry2, $carry1
-___
-    return $code;
-}
-
-sub adc {
-    # (1) Simulate ARM 'adc': add with input carry1, no flags
-    # (2) Temp sum: dst = src1 + b, ignore input carry
-    # (3) Final sum: dst += carry1 (input carry), ignore output carry
-    my ($dst, $src1, $b) = @_;
-    my $code=<<___;
-    add $dst,$src1,$b
-    add $dst,$dst,$carry1
-___
-    return $code;
-}
-
-sub extr {
-    # Simulate ARM 'extr': extract high bit and shift
-    # (1) carry2 = b >> 63 (extract highest bit of b)
-    # (2) dst = src1 << 1 (shift src1 left by 1, dst = src1*2)
-    # (3) dst |= carry2 (combine: insert b's high bit as dst's LSB, dst= carry2 + src1*2 )
-    my ($dst, $src1, $b) = @_;
-    my $code=<<___;
-    srli $carry2, $b, 63
-    slli $dst, $src1, 1
-    or   $dst, $dst, $carry2
-___
-    return $code;
-}
-
-sub subs{
-    # Simulate ARM 'subs': subtract with borrow flag set.
-    # (1) dst = src1 - b
-    # (2) if src1 < dst, set borrow flag,carry1 = 1
-    my ($dst, $src1, $b) = @_;
-    my $code=<<___;
-    sub $dst, $src1, $b
-    sltu $carry1, $src1, $dst
-___
-    return $code;
-}
-
-sub sbcs{
-    # Simulate ARM 'sbcs': subtract with input borrow (carry1) and set output borrow.
-    # (1) temp = src1 - b
-    # (2) if src1 < temp, set borrow flag, carry2 = 1
-    # (3) dst = temp - carry1 (borrow_in)
-    # (4) if temp < dst, set borrow flag, carry1 = 1
-    # (5) carry1 (borrow_out) = carry2 | carry1
-    my ($dst, $src1, $b) = @_;
-    my $code=<<___;
-    sub $temp, $src1, $b
-    sltu $carry2, $src1, $temp
-    sub $dst, $temp, $carry1
-    sltu $carry1, $temp, $dst
-    or $carry1, $carry2, $carry1
-___
-    return $code;
-}
-
-sub csel{
-    # Simulate ARM 'csel': conditional select based on carry
-    # Assumes carry1 is input condition, 1 if true/select b, 0 if false/select src1.
-    # dst = (carry1 == 0) ? src1 : b
-    # Uses bitwise ops for branchless execution
-    # (1) Normalize carry1: carry1 !=0 ? carry1 = 1 : carry1 = 0
-    # (2) Create mask: carry1 = 0 - carry1; yields -1 (all 1s) if 1 (true), 0 if false carry1 = -carry1 (0 or -1 mask)
-    # (3) Compute diff: dst = src1 ^ b (bitwise XOR highlights differing bits)
-    # (4) Mask diff: dst = diff & mask; yields diff if -1 (true), 0 if 0 (false)
-    # (5) Select: dst = src1 ^ dst; yields b if dst=diff (true), src1 if dst=0 (false)
-    my ($dst, $src1, $b) = @_;
-    my $code=<<___;
-    snez $carry1, $carry1
-    sub $carry1, zero, $carry1
-    xor $dst, $src1, $b
-    and $dst, $dst, $carry1
-    xor $dst, $src1, $dst
-___
-    return $code;
-}
-
-## store
-sub sd_rp{
-    my ($src1,$dst) = @_;
-    my $code=<<___;
-    sd $src1,96($dst)
-___
-    return $code;
-}
-
-sub sd_np{
-    my ($src1,$dst) = @_;
-    my $code=<<___;
-    sd $src1,104($dst)
-___
-    return $code;
-}
-
-sub sd_num{
-    my ($src1,$dst) = @_;
-    my $code=<<___;
-    sd $src1,112($dst)
-___
-    return $code;
-}
-
-sub sd_n0{
-    my ($src1,$dst) = @_;
-    my $code=<<___;
-    sd $src1,120($dst)
-___
-    return $code;
-}
-
-sub sd_ra{
-    my ($src1,$dst) = @_;
-    my $code=<<___;
-    sd $src1,128($dst)
-___
-    return $code;
-}
-
-sub sd_cnt{
-    my ($src1,$dst) = @_;
-    my $code=<<___;
-    sd $src1,136($dst)
-___
-    return $code;
-}
-
-sub sd_apend{
-    my ($src1,$dst) = @_;
-    my $code=<<___;
-    sd $src1,144($dst)
-___
-    return $code;
-}
-
-sub sd_npend{
-    my ($src1,$dst) = @_;
-    my $code=<<___;
-    sd $src1,152($dst)
-___
-    return $code;
-}
-
-sub sd_topmost{
-    my ($src1,$dst) = @_;
-    my $code=<<___;
-    sd $src1,160($dst)
-___
-    return $code;
-}
-
-## load
-sub ld_rp{
-    my ($dst,$src1) = @_;
-    my $code=<<___;
-    ld $dst,96($src1)
-___
-    return $code;
-}
-
-sub ld_np{
-    my ($dst,$src1) = @_;
-    my $code=<<___;
-    ld $dst,104($src1)
-___
-    return $code;
-}
-
-sub ld_num{
-    my ($dst,$src1) = @_;
-    my $code=<<___;
-    ld $dst,112($src1)
-___
-    return $code;
-}
-
-sub ld_n0{
-    my ($dst,$src1) = @_;
-    my $code=<<___;
-    ld $dst,120($src1)
-___
-    return $code;
-}
-
-sub ld_ra{
-    my ($dst,$src1) = @_;
-    my $code=<<___;
-    ld $dst,128($src1)
-___
-    return $code;
-}
-
-sub ld_cnt{
-    my ($dst,$src1) = @_;
-    my $code=<<___;
-    ld $dst,136($src1)
-___
-    return $code;
-}
-
-sub ld_apend{
-    my ($dst,$src1) = @_;
-    my $code=<<___;
-    ld $dst,144($src1)
-___
-    return $code;
-}
-
-sub ld_npend{
-    my ($dst,$src1) = @_;
-    my $code=<<___;
-    ld $dst,152($src1)
-___
-    return $code;
-}
-
-sub ld_topmost{
-    my ($dst,$src1) = @_;
-    my $code=<<___;
-    ld $dst,160($src1)
-___
-    return $code;
-}
-
-$code.=<<___;
-.type   bn_sqr8x_mont,%function
-.balign 32
-bn_sqr8x_mont:
-    # If ap != bp, -> normal multiplication, jump to .Lmul_mont
-    # If ap == bp, -> continue with optimized sqr8x path
-    bne $ap,$bp, .Lmul_mont
-___
-$code .= <<___;
-    addi    sp,sp,-168
-    sd      s0,88(sp)
-    sd      s1,80(sp)
-    sd      s2,72(sp)
-    sd      s3,64(sp)
-    sd      s4,56(sp)
-    sd      s5,48(sp)
-    sd      s6,40(sp)
-    sd      s7,32(sp)
-    sd      s8,24(sp)
-    sd      s9,16(sp)
-    sd      s11,8(sp)
-    sd      s10,0(sp)
-    mv $fp, sp
-___
-$code .= <<___;
-.Lsqr8x_mont:
-    ld $a0, 0($ap)    # load a[0-7]
-    ld $a1, 8($ap)
-    ld $a2, 16($ap)
-    ld $a3, 24($ap)
-    ld $a4, 32($ap)
-    ld $a5, 40($ap)
-    ld $a6, 48($ap)
-    ld $a7, 56($ap)
-
-    slli $t0, $num, 4
-    sub $tp, sp, $t0    # alloca sp-num*16
-    slli $num, $num, 3
-    ld $n0, 0($n0)    # n0, precomputed modular inverse
-    mv sp, $tp    # alloca
-
-    # Save temporary values to stack to release registers for subsequent operations
-    addi $t1,$num,-64    # number of bytes remaining to be zeroed
-    @{[sd_cnt $t1,$fp]}    # offload cnt
-    @{[sd_rp $rp,$fp]}    # offload rp
-    @{[sd_np $np,$fp]}    # offload np
-    @{[sd_num $num,$fp]}    # offload num
-    @{[sd_n0 $n0,$fp]}    # offload n0
-    @{[sd_ra $ra,$fp]}    # offload ra
-
-    j .Lsqr8x_zero_start
-
-
-    # Clear tp buffer to store partial products
-    # Zero 128 bytes per iteration until cache cleared
-.Lsqr8x_zero:
-    addi $carry2,$carry2,-64    # cnt=cnt-64
-    @{[sd_cnt $carry2,$fp]}
-
-    sd zero, 0($tp)
-    sd zero, 8($tp)
-    sd zero, 16($tp)
-    sd zero, 24($tp)
-    sd zero, 32($tp)
-    sd zero, 40($tp)
-    sd zero, 48($tp)
-    sd zero, 56($tp)
-
-.Lsqr8x_zero_start:
-    sd zero, 64($tp)
-    sd zero, 72($tp)
-    sd zero, 80($tp)
-    sd zero, 88($tp)
-    sd zero, 96($tp)
-    sd zero, 104($tp)
-    sd zero, 112($tp)
-    sd zero, 120($tp)
-    addi $tp,$tp,128
-
-    @{[ld_cnt $carry2,$fp]}
-    bnez $carry2,.Lsqr8x_zero    # cnt != 0 -> Lsqr8x_zero
-
-    @{[ld_num $temp,$fp]}
-    add $temp,$ap,$temp    # ap_end = ap + num
-    @{[sd_apend $temp,$fp]} # offload ap_end, the last element of ap
-    addi $ap,$ap,64    # ap += 64, skip initial 8 64-bit words
-    mv $acc0, zero
-    mv $acc1, zero
-    mv $acc2, zero
-    mv $acc3, zero
-    mv $acc4, zero
-    mv $acc5, zero
-    mv $acc6, zero
-    mv $acc7, zero
-    mv $tp,sp    # points to buffer start
-
-    # Multiply everything but a[i]*a[i]
-.balign 16
-.Lsqr8x_outer_loop:
-    # Compute cross products: a[j] * a[i] for all < j
-    #                                                 a[1]a[0]  (i)
-    #                                             a[2]a[0]
-    #                                         a[3]a[0]
-    #                                     a[4]a[0]
-    #                                 a[5]a[0]
-    #                             a[6]a[0]
-    #                         a[7]a[0]
-    #                                         a[2]a[1]  (ii)
-    #                                     a[3]a[1]
-    #                                 a[4]a[1]
-    #                             a[5]a[1]
-    #                         a[6]a[1]
-    #                     a[7]a[1]
-    #                                 a[3]a[2]  (iii)
-    #                             a[4]a[2]
-    #                         a[5]a[2]
-    #                     a[6]a[2]
-    #                 a[7]a[2]
-    #                         a[4]a[3]  (iv)
-    #                     a[5]a[3]
-    #                 a[6]a[3]
-    #             a[7]a[3]
-    #                 a[5]a[4]  (v)
-    #             a[6]a[4]
-    #         a[7]a[4]
-    #         a[6]a[5]  (vi)
-    #     a[7]a[5]
-    # a[7]a[6]  (vii)
-    mul $t0,$a1,$a0    # lo(a[1..7]*a[0])  (i)
-    mul $t1,$a2,$a0
-    mul $t2,$a3,$a0
-    mul $t3,$a4,$a0
-
-    @{[adds $acc1, $acc1, $t0]}    # t[1]+lo(a[1]*a[0])
-    mul $t0,$a5,$a0
-    @{[adcs $acc2, $acc2, $t1]}    # t[2]+lo(a[2]*a[0])
-    mul $t1,$a6,$a0
-    @{[adcs $acc3, $acc3, $t2]}    # t[3]+lo(a[3]*a[0])
-    mul $t2,$a7,$a0
-    @{[adcs $acc4, $acc4, $t3]}    # t[4]+lo(a[4]*a[0])
-
-    mulhu $t3,$a1,$a0    # hi(a[1..7]*a[0])
-    @{[adcs $acc5, $acc5, $t0]}    # t[5]+lo(a[5]*a[0])
-    mulhu $t0,$a2,$a0
-    @{[adcs $acc6, $acc6, $t1]}    # t[6]+lo(a[6]*a[0])
-    mulhu $t1,$a3,$a0
-    @{[adcs $acc7, $acc7, $t2]}    # t[7]+lo(a[7]*a[0])
-    mulhu $t2,$a4,$a0
-    sd $acc0, 0($tp)    # offload acc0, store t[0]
-    add $acc0,zero,$carry1    # t[8]=0+c_pre{t[7]+lo(a[7]*a[0])}
-    sd $acc1, 8($tp)    # offload acc1, store t[1]
-    addi $tp,$tp,16    # tp=tp+16,advance buffer pointer by 16 bytes
-
-    @{[adds $acc2, $acc2, $t3]}    # t[2]+hi(a[1]*a[0])
-    mulhu $t3,$a5,$a0
-    @{[adcs $acc3, $acc3, $t0]}    # t[3]+hi(a[2]*a[0])
-    mulhu $t0,$a6,$a0
-    @{[adcs $acc4, $acc4, $t1]}    # t[4]+hi(a[3]*a[0])
-    mulhu $t1,$a7,$a0
-    @{[adcs $acc5, $acc5, $t2]}    # t[5]+hi(a[4]*a[0])
-
-    mul $t2,$a2,$a1    # lo(a[2..7]*a[1])  (ii)
-    @{[adcs $acc6, $acc6, $t3]}    # t[6]+hi(a[5]*a[0])
-    mul $t3,$a3,$a1
-    @{[adcs $acc7, $acc7, $t0]}    # t[7]+hi(a[6]*a[0])
-    mul $t0,$a4,$a1
-    @{[adc $acc0, $acc0, $t1]}    # t[8]+hi(a[7]*a[0])
-    mul $t1,$a5,$a1
-
-    @{[adds $acc3, $acc3, $t2]}    # t[3]+ lo(a[2]*a[1])
-    mul $t2,$a6,$a1
-    @{[adcs $acc4, $acc4, $t3]}    # t[4]+ lo(a[3]*a[1])
-    mul $t3,$a7,$a1
-    @{[adcs $acc5, $acc5, $t0]}    # t[5]+ lo(a[4]*a[1])
-    mulhu $t0,$a2,$a1    # hi(a[2..7]*a[1])
-    @{[adcs $acc6,$acc6, $t1]}    # t[6]+ lo(a[5]*a[1])
-    mulhu $t1,$a3,$a1
-    @{[adcs $acc7, $acc7, $t2]}    # t[7]+ lo(a[6]*a[1])
-    mulhu $t2,$a4,$a1
-    @{[adcs $acc0, $acc0, $t3]}    # t[8]+ lo(a[7]*a[1])
-    mulhu $t3,$a5,$a1
-    sd $acc2,0($tp)    # offload acc2, store t[2]
-    add $acc1,zero,$carry1    # t[9]=0+c_pre{t[8]+ lo(a[7]*a[1])}
-    sd $acc3,8($tp)    # offload acc3, store t[3]
-    addi $tp,$tp,16    # tp=tp+16,advance buffer pointer by 16 bytes
-
-    @{[adds $acc4, $acc4, $t0]}    # t[4]+ hi(a[2]*a[1])
-    mulhu $t0,$a6,$a1
-    @{[adcs $acc5, $acc5, $t1]}    # t[5]+ hi(a[3]*a[1])
-    mulhu $t1,$a7,$a1
-    @{[adcs $acc6, $acc6, $t2]}    # t[6]+ hi(a[4]*a[1])
-    mul $t2,$a3,$a2    # lo(a[3..7]*a[2])  (iii)
-    @{[adcs $acc7, $acc7, $t3]}    # t[7]+ hi(a[5]*a[1])
-    mul $t3,$a4,$a2
-    @{[adcs $acc0, $acc0, $t0]}    # t[8]+ hi(a[6]*a[1])
-    mul $t0,$a5,$a2
-    @{[adc  $acc1, $acc1, $t1]}    # t[9]+ hi(a[7]*a[1])
-    mul $t1,$a6,$a2
-    @{[adds $acc5, $acc5, $t2]}    # t[5]+ lo(a[3]*a[2])
-    mul $t2,$a7,$a2
-    @{[adcs $acc6, $acc6, $t3]}    # t[6]+ lo(a[4]*a[2])
-    mulhu $t3,$a3,$a2    # hi(a[3..7]*a[2])
-    @{[adcs $acc7, $acc7, $t0]}    # t[7]+ lo(a[5]*a[2])
-    mulhu $t0,$a4,$a2
-    @{[adcs $acc0, $acc0, $t1]}    # t[8]+ lo(a[6]*a[2])
-    mulhu $t1,$a5,$a2
-    @{[adcs $acc1, $acc1, $t2]}    # t[9]+ lo(a[7]*a[2])
-    mulhu $t2,$a6,$a2
-    sd $acc4,0($tp)    # offload acc4, store t[4]
-    add $acc2,zero,$carry1    # t[10]=0+c_pre{t[9]+ lo(a[7]*a[2])}
-    sd $acc5,8($tp)    # offload acc5, store t[5]
-    addi $tp,$tp,16    # tp=tp+16,advance buffer pointer by 16 bytes
-
-    @{[adds $acc6, $acc6, $t3]}    # t[6]+ hi(a[3]*a[2])
-    mulhu $t3,$a7,$a2
-    @{[adcs $acc7, $acc7, $t0]}    # t[7]+ hi(a4]*a[2])
-    mul $t0,$a4,$a3  # lo(a[4..7]*a[3])  (iv)
-    @{[adcs $acc0, $acc0, $t1]}    # t[8]+ hi(a5]*a[2])
-    mul $t1,$a5,$a3
-    @{[adcs $acc1, $acc1, $t2]}    # t[9]+ hi(a6]*a[2])
-    mul $t2,$a6,$a3
-    @{[adc  $acc2, $acc2, $t3]}    # t[10]+ hi(a7]*a[2])
-    mul $t3,$a7,$a3
-
-    @{[adds $acc7, $acc7, $t0]}    # t[7]+ lo(a[4]*a[3])
-    mulhu $t0,$a4,$a3   # hi(a[4..7]*a[3])
-    @{[adcs $acc0, $acc0, $t1]}    # t[8]+ lo(a[5]*a[3])
-    mulhu $t1,$a5,$a3
-    @{[adcs $acc1, $acc1, $t2]}    # t[9]+ lo(a[6]*a[3])
-    mulhu $t2,$a6,$a3
-    @{[adcs $acc2, $acc2, $t3]}    # t[10]+ lo(a[7]*a[3])
-    mulhu $t3,$a7,$a3
-    sd $acc6,0($tp)    # offload acc6, store t[6]
-    add $acc3,zero,$carry1    # t[11]=0+c_pre{t[10]+ lo(a[7]*a[3])}
-    sd $acc7,8($tp)    # offload acc7, store t[7]
-    addi $tp,$tp,16    # tp=tp+16, advance buffer pointer by 16 bytes
-
-    @{[adds $acc0, $acc0, $t0]}    # t[8]+ hi(a[4]*a[3])
-    mul $t0,$a5,$a4    # lo(a[5..7]*a[4])  (v)
-    @{[adcs $acc1, $acc1, $t1]}    # t[9]+ hi(a[5]*a[3])
-    mul $t1,$a6,$a4
-    @{[adcs $acc2, $acc2, $t2]}    # t[10]+ hi(a[6]*a[3])
-    mul $t2,$a7,$a4
-    @{[adc  $acc3, $acc3, $t3]}    # t[11]+ hi(a[7]*a[3])
-
-    mulhu $t3,$a5,$a4    # hi(a[5..7]*a[4])
-    @{[adds $acc1, $acc1, $t0]}    # t[9]+ lo(a[5]*a[4])
-    mulhu $t0,$a6,$a4
-    @{[adcs $acc2, $acc2, $t1]}    # t[10]+ lo(a[6]*a[4])
-    mulhu $t1,$a7,$a4
-    @{[adcs $acc3, $acc3, $t2]}    # t[11]+ lo(a[7]*a[4])
-    mul $t2,$a6,$a5    # lo(a[6..7]*a[5])  (vi)
-    add $acc4,zero,$carry1    # t[12]=0+c_pre{t[11]+ lo(a[7]*a[4])}
-
-    @{[adds $acc2, $acc2, $t3]}    # t[10]+ hi(a[5]*a[4])
-    mul $t3,$a7,$a5
-    @{[adcs $acc3, $acc3, $t0]}    # t[11]+ hi(a[6]*a[4])
-    mulhu $t0,$a6,$a5    # hi(a[6..7]*a[5])
-    @{[adc $acc4, $acc4, $t1]}    # t[12]+ hi(a[7]*a[4])
-    mulhu $t1,$a7,$a5
-
-    @{[adds $acc3, $acc3, $t2]}    # t[11]+ lo(a[6]*a[5])
-    mul $t2,$a7,$a6    # lo(a[7]*a[6])  (vii)
-    @{[adcs $acc4,$acc4, $t3]}    # t[12]+ lo(a[7]*a[5])
-    mulhu $t3,$a7,$a6    # hi(a[7]*a[6])
-    add $acc5,zero,$carry1    # t[13] =0+c_pre{t[12]+lo(a[7]*a[5])}
-
-    @{[adds $acc4, $acc4, $t0]}    # t[12]+ hi(a[6]*a[5])
-
-    @{[ld_apend $temp,$fp]} # load ap_end
-    sub $temp,$temp,$ap    # cnt = ap_end-ap, done yet?
-    @{[sd_cnt $temp,$fp]}
-
-    @{[adc $acc5, $acc5, $t1]}    # t[13]+ hi(a[7]*a[5])
-
-    @{[adds $acc5, $acc5, $t2]}     # t[13]+ lo(a[7]*a[6])
-    @{[ld_num $temp,$fp]}
-    @{[ld_apend $carry2,$fp]}
-    sub $t0, $carry2, $temp    # rewinded ap
-    add $acc6,zero,$carry1    # t[14]=0+c_pre{t[13]+ lo(a[7]*a[6])}
-    add $acc6,$acc6,$t3    # t[14] + hi(a[7]*a[6])
-
-    # Check if we have processed all elements of a:
-    # If no remaining elements, jump to next step Lsqr8x_outer_break
-    # Otherwise, load previous partial product from temp buffer,
-    # add new a product, and continue inner loop .Lsqr8x_mul.
-    @{[ld_cnt $temp,$fp]}  # load cnt, cnt = ap_end-ap
-    beqz $temp, .Lsqr8x_outer_break
-
-    mv $temp,$a0    # a0->temp,reuse register'temp'
-    # loads next batch of data from temporary buffer
-    ld $a0,0($tp)
-    ld $a1,8($tp)
-    ld $a2,16($tp)
-    ld $a3,24($tp)
-    ld $a4,32($tp)
-    ld $a5,40($tp)
-    ld $a6,48($tp)
-    ld $a7,56($tp)
-
-    # accumulate new data
-    @{[adds $acc0, $acc0, $a0]}    # t[8]~t[14]...
-    ld $a0,0($ap)    # load new data, a[8..15]...
-    @{[adcs $acc1, $acc1, $a1]}
-    ld $a1,8($ap)
-    @{[adcs $acc2, $acc2, $a2]}
-    ld $a2,16($ap)
-    @{[adcs $acc3, $acc3, $a3]}
-    ld $a3,24($ap)
-    @{[adcs $acc4, $acc4, $a4]}
-    ld $a4,32($ap)
-    @{[adcs $acc5, $acc5, $a5]}
-    ld $a5,40($ap)
-    @{[adcs $acc6, $acc6, $a6]}
-    ld $a6,48($ap)
-
-    mv $np,$ap    # ap->np,reuse register'np',a[8]
-    @{[adcs $acc7, "zero", $a7]}    # t[7]...
-    ld $a7,56($ap)
-    add $ap,$ap,64    # move pointer forward by 64 bits (8 bytes),a[16]
-
-    li $carry2,-64    # cnt=-64, set loop count
-    @{[sd_cnt $carry2,$fp]}
-
-    # Compute cross products: (current 8 elements) x (remaining a)
-    # Accumulate results in RAX (accumulator)
-    #
-    #                                                         a[8]a[0]
-    #                                                     a[9]a[0]
-    #                                                 a[a]a[0]
-    #                                             a[b]a[0]
-    #                                         a[c]a[0]
-    #                                     a[d]a[0]
-    #                                 a[e]a[0]
-    #                             a[f]a[0]
-    #                                                     a[8]a[1]
-    #                         a[f]a[1]........................
-    #                                                 a[8]a[2]
-    #                     a[f]a[2]........................
-    #                                             a[8]a[3]
-    #                 a[f]a[3]........................
-    #                                         a[8]a[4]
-    #             a[f]a[4]........................
-    #                                     a[8]a[5]
-    #         a[f]a[5]........................
-    #                                 a[8]a[6]
-    #     a[f]a[6]........................
-    #                             a[8]a[7]
-    # a[f]a[7]........................
- .Lsqr8x_mul:
-    mul $t0,$a0,$temp    # lo(a[i+8..i+15]*a[i]),..,lo(a[i+8..i+15]*a[i+7])
-    add $carry,zero,$carry1    # carry bit
-    mul $t1,$a1,$temp
-
-    @{[ld_cnt $carry2,$fp]}
-    add $carry2,$carry2,8    # cnt=cnt+8
-    @{[sd_cnt $carry2,$fp]}
-
-    mul $t2,$a2,$temp
-    mul $t3,$a3,$temp
-    @{[adds $acc0,$acc0,$t0]}
-    mul $t0,$a4,$temp
-    @{[adcs $acc1,$acc1,$t1]}
-    mul $t1,$a5,$temp
-    @{[adcs $acc2,$acc2,$t2]}
-    mul $t2,$a6,$temp
-    @{[adcs $acc3, $acc3, $t3]}
-    mul $t3,$a7,$temp
-    @{[adcs $acc4, $acc4, $t0]}
-    mulhu $t0,$a0,$temp    # hi(a[i+8..i+15]*a[i]),..,lo(a[i+8..i+15]*a[i+7])
-    @{[adcs $acc5, $acc5, $t1]}
-    mulhu $t1,$a1,$temp
-    @{[adcs $acc6, $acc6, $t2]}
-    mulhu $t2,$a2,$temp
-    @{[adcs $acc7, $acc7, $t3]}
-    mulhu $t3,$a3,$temp
-    add $carry,$carry,$carry1
-    sd $acc0,0($tp)
-    addi $tp,$tp,8    # move pointer forward by 8 bits (1 bytes)
-
-    @{[adds $acc0, $acc1, $t0]}
-    mulhu $t0,$a4,$temp
-    @{[adcs $acc1, $acc2, $t1]}
-    mulhu $t1,$a5,$temp
-    @{[adcs $acc2, $acc3, $t2]}
-    mulhu $t2,$a6,$temp
-    @{[adcs $acc3, $acc4, $t3]}
-    mulhu $t3,$a7,$temp
-
-    @{[ld_cnt $carry2,$fp]}
-    add $carry2,$np,$carry2    # carry2 = np + cnt
-    ld $temp,0($carry2)    # a[i+1],..,a[i+7],i=0
-    @{[adcs $acc4, $acc5, $t0]}
-    @{[adcs $acc5, $acc6, $t1]}
-    @{[adcs $acc6, $acc7, $t2]}
-    @{[adcs $acc7, $carry, $t3]}
-
-    # Process current 8 elements:
-    #  - If not finished: continue inner loop, .Lsqr8x_mul
-    #  - If finished: check remaining a elements
-    #     - If none: break out,jump to .Lsqr8x_break
-    #     - Else: load new data and restart inner loop, .Lsqr8x_mul
-    @{[ld_cnt $carry2,$fp]}
-    bnez $carry2,.Lsqr8x_mul
-
-    @{[ld_apend $carry2,$fp]}
-    beq $ap, $carry2, .Lsqr8x_break    # done yet?
-
-    # loads next batch of data from temporary buffer
-    ld $a0,0($tp)
-    ld $a1,8($tp)
-    ld $a2,16($tp)
-    ld $a3,24($tp)
-    ld $a4,32($tp)
-    ld $a5,40($tp)
-    ld $a6,48($tp)
-    ld $a7,56($tp)
-
-    # accumulate new data
-    # load new data, a[16..23]...
-    @{[adds $acc0, $acc0, $a0]}
-    ld $a0,0($ap)
-    ld $temp, -64($np)    # return to start of current 8 elements, a[0]ã€a[8]...
-    @{[adcs $acc1, $acc1, $a1]}
-    ld $a1,8($ap)
-    @{[adcs $acc2, $acc2, $a2]}
-    ld $a2,16($ap)
-    @{[adcs $acc3, $acc3, $a3]}
-    ld $a3,24($ap)
-    @{[adcs $acc4, $acc4, $a4]}
-    ld $a4,32($ap)
-    @{[adcs $acc5, $acc5, $a5]}
-    ld $a5,40($ap)
-    @{[adcs $acc6, $acc6, $a6]}
-    ld $a6,48($ap)
-    li $carry2,-64    # set loop count, cnt=-64, 8 times
-    @{[sd_cnt $carry2,$fp]}
-    @{[adcs $acc7, $acc7, $a7]}
-    ld $a7,56($ap)
-    add $ap,$ap,64    # move pointer forward by 64 bytes, a[24]...
-    j .Lsqr8x_mul
-
-    # Outer iteration completion:
-    #    - Fetch next data chunk for upcoming iteration
-    #    - Determine if this is the final iteration
-    #    - Update pointer positions and buffer offsets
-.balign 16
-.Lsqr8x_break:
-    ld $a0,0($np)
-    ld $a1,8($np)
-    add $ap,$np,64
-    ld $a2,16($np)
-    ld $a3,24($np)
-    @{[ld_apend $carry2,$fp]}
-    sub $t0,$carry2,$ap    # is it last iteration?
-    ld $a4,32($np)
-    ld $a5,40($np)
-    sub $t1,$tp,$t0
-    ld $a6,48($np)
-    ld $a7,56($np)
-    beqz $t0, .Lsqr8x_outer_loop
-
-    sd $acc0,0($tp)
-    sd $acc1,8($tp)
-    ld $acc0,0($t1)
-    ld $acc1,8($t1)
-    sd $acc2,16($tp)
-    sd $acc3,24($tp)
-    ld $acc2,16($t1)
-    ld $acc3,24($t1)
-    sd $acc4,32($tp)
-    sd $acc5,40($tp)
-    ld $acc4,32($t1)
-    ld $acc5,40($t1)
-    sd $acc6,48($tp)
-    sd $acc7,56($tp)
-    mv $tp,$t1
-    ld $acc6,48($t1)
-    ld $acc7,56($t1)
-
-    j .Lsqr8x_outer_loop
-    # Squaring algorithm:
-    # 1.Reload input
-    # 2.Compute diagonal squares, a[n-1]*a[n-1]|...|a[0]*a[0]
-    # 3.Cross terms x 2: first via lsl#1, rest via extr chain (128-bit << 1)
-    # 4.Merge diagonal + cross terms x 2
-.balign 16
-.Lsqr8x_outer_break:
-    ld $a1,0($t0)    # recall that $t0 is &a[0], load a[0 1 2 3]
-    ld $a3,8($t0)
-    ld $t1,8(sp)    # load previously computed cross product term from buffer
-    ld $t2,16(sp)
-    ld $a5,16($t0)
-    ld $a7,24($t0)
-
-    add $ap,$t0,32    # a[4]
-    ld $t3,24(sp)
-    sd $acc0,0($tp)
-    ld $t0,32(sp)
-    sd $acc1,8($tp)
-
-    mul $acc0,$a1,$a1    # lo(a[0]*a[0])
-    sd $acc2,16($tp)
-    sd $acc3,24($tp)
-    mulhu $a1,$a1,$a1    # hi(a[0]*a[0])
-    sd $acc4,32($tp)
-    sd $acc5,40($tp)
-    mul $a2,$a3,$a3    # lo(a[1]*a[1])
-    sd $acc6,48($tp)
-    sd $acc7,56($tp)
-    mv $tp,sp
-    mulhu $a3,$a3,$a3    # hi(a[1]*a[1])
-
-    slli $carry2,$t1,1    # cross terms x 2
-    @{[adds $acc1, $a1, $carry2]}    # (t1 << 1) + hi(a[0]*a[0])
-    @{[extr $t1, $t2, $t1]}    # t1 = (t2 << 1) + high(t1), cross term multiplied by 2
-
-    @{[ld_num $carry2,$fp]}
-    addi $carry2,$carry2,-32    # set loop count, cnt=num-32
-    @{[sd_cnt $carry2,$fp]}
-
-    # Loop processing 4 diagonal elements per iteration:
-    #  - Compute a[i]*a[i] for 4 elements
-    #  - Accumulate left-shifted cross product terms
-.Lsqr4x_shift_n_add:
-    @{[adcs $acc2, $a2, $t1]}    # t1+ lo(a[1]*a[1])
-    @{[extr $t2, $t3, $t2]}    # t2 = (t3 << 1) + high(t2), cross term multiplied by 2
-
-    @{[ld_cnt $carry2,$fp]}
-    addi $carry2,$carry2,-32    # cnt=cnt-32
-    @{[sd_cnt $carry2,$fp]}
-
-    @{[adcs $acc3, $a3, $t2]}    # t2+ hi(a[1]*a[1])
-    ld $t1,40($tp)
-    ld $t2,48($tp)
-    mul $a4,$a5,$a5    # lo(a[2]*a[2])
-    ld $a1,0($ap)    # a[4 5]
-    ld $a3,8($ap)
-    addi $ap,$ap,16
-    mulhu $a5,$a5,$a5    # hi(a[2]*a[2])
-    @{[extr $t3, $t0, $t3]}    # t3 = (t0 << 1) + high(t3), cross term multiplied by 2
-    sd $acc0,0($tp)
-    sd $acc1,8($tp)
-    mul $a6,$a7,$a7    # lo(a[3]*a[3])
-    mulhu $a7,$a7,$a7    # hi(a[3]*a[3])
-    @{[adcs $acc4, $a4, $t3]}    # t3 + lo(a[2]*a[2])
-    @{[extr $t0, $t1, $t0]}    # t0 = (t1 << 1) + high(t0), cross term multiplied by 2
-    sd $acc2,16($tp)
-    sd $acc3,24($tp)
-    @{[adcs $acc5, $a5, $t0]}    # t0 + hi(a[2]*a[2])
-    ld $t3,56($tp)
-    ld $t0,64($tp)
-    @{[extr $t1, $t2, $t1]}    # t1 = (t2 << 1) + high(t1), cross term multiplied by 2
-    @{[adcs $acc6, $a6, $t1]}    # t1 + lo(a[3]*a[3])
-    @{[extr $t2, $t3, $t2]}    # t2 = (t3 << 1) + high(t2), cross term multiplied by 2
-    @{[adcs $acc7, $a7, $t2]}    # t2 + hi(a[3]*a[3])
-    ld $t1,72($tp)
-    ld $t2,80($tp)
-    mul $a0,$a1,$a1    # lo(a[4]*a[4])
-    ld $a5,0($ap)    # a[6 7]
-    ld $a7,8($ap)
-    addi $ap,$ap,16    # move forward by two elements
-    mulhu $a1,$a1,$a1    # hi(a[4]*a[4])
-    sd $acc4,32($tp)
-    sd $acc5,40($tp)
-    mul $a2,$a3,$a3    # lo(a[5]*a[5])
-    mulhu $a3,$a3,$a3    # hi(a[5]*a[5])
-    @{[extr $t3, $t0, $t3]}    # t3 = (t0 << 1) + high(t3), cross term multiplied by 2
-    sd $acc6,48($tp)
-    sd $acc7,56($tp)
-    addi $tp,$tp,64
-    @{[adcs $acc0, $a0, $t3]}    # t3 + lo(a[4]*a[4])
-    @{[extr $t0, $t1, $t0]}    # t0 = (t1 << 1) + high(t0), cross term multiplied by 2
-    @{[adcs $acc1, $a1, $t0]}    # t0 + hi(a[4]*a[4])
-    ld $t3,24($tp)
-    ld $t0,32($tp)
-    @{[extr $t1, $t2, $t1]}    # t1 = (t2 << 1) + high(t1), cross term multiplied by 2
-
-    @{[ld_cnt $carry2,$fp]}
-    bnez $carry2,.Lsqr4x_shift_n_add    # if cnt!=0, jump to .Lsqr4x_shift_n_add
-___
-my ($np,$np_temp) = use_regs(11,13);
-$code.=<<___;
-    # Tail element handling for square computation
-    @{[ld_np $np,$fp]}    # load np, N
-    @{[ld_n0 $n0,$fp]} # load n0, n0`
-    @{[adcs $acc2, $a2, $t1]}    # t1 + lo(a[n-3]*a[n-3])
-    @{[extr $t2, $t3, $t2]}    # t2 = (t3 << 1) + high(t2), cross term multiplied by 2
-    @{[adcs $acc3, $a3, $t2]}    # t2 + hi(a[n-3]*a[n-3])
-    ld $t1,40($tp)
-    ld $t2,48($tp)
-    mul $a4,$a5,$a5    # lo(a[n-2]*a[n-2])
-    mulhu $a5,$a5,$a5    # hi(a[n-2]*a[n-2])
-    sd $acc0,0($tp)
-    sd $acc1,8($tp)
-    mul $a6,$a7,$a7    # lo(a[n-1]*a[n-1])
-    mulhu $a7,$a7,$a7    # hi(a[n-1]*a[n-1])
-    sd $acc2,16($tp)
-    sd $acc3,24($tp)
-    @{[extr $t3, $t0, $t3]}    # t3 = (t0 << 1) + high(t3), cross term multiplied by 2
-    @{[adcs $acc4, $a4, $t3]}    # t3 + lo(a[n-2]*a[n-2])
-    @{[extr $t0, $t1, $t0]}    # t0 = (t1 << 1) + high(t0), cross term multiplied by 2
-    ld $acc0,0(sp)
-    ld $acc1,8(sp)
-    @{[adcs $acc5, $a5, $t0]}    # t0 + hi(a[n-2]*a[n-2])
-    @{[extr $t1, $t2, $t1]}    # t1 = (t2 << 1) + high(t1), cross term multiplied by 2
-    ld $a0,0($np)    # load N[0..7]
-    ld $a1,8($np)
-    @{[adcs $acc6, $a6, $t1]}    # t1 + lo(a[n-1]*a[n-1])
-    @{[extr $t2, "zero", $t2]}    # t2 = high(t2)
-    ld $a2,16($np)
-    ld $a3,24($np)
-    @{[adc $acc7, $a7, $t2]}     # t2 + hi(a[n-1]*a[n-1])
-    ld $a4,32($np)
-    ld $a5,40($np)
-
-    # Reduce by 512 bits per iteration
-    mul $na0,$n0,$acc0    # t[0]*n0, the modular reduction coefficient
-    ld $a6,48($np)
-    ld $a7,56($np)
-    @{[ld_num $carry2,$fp]}
-    add $carry2,$np,$carry2    # np_end=np+num
-    @{[sd_npend $carry2,$fp]}
-    ld $acc2,16(sp)
-    ld $acc3,24(sp)
-    sd $acc4,32($tp)
-    sd $acc5,40($tp)
-    ld $acc4,32(sp)
-    ld $acc5,40(sp)
-    sd $acc6,48($tp)
-    sd $acc7,56($tp)
-    ld $acc6,48(sp)
-    ld $acc7,56(sp)
-    add $np,$np,64    # move pointer forward by 64 bytes, 8 elements
-    mv $tp,sp
-    li $carry2,0
-    @{[sd_topmost $carry2,$fp]} # initial topmost carry as 0
-    li $carry2,8    # set loop count, cnt=8
-    @{[sd_cnt $carry2,$fp]}
-
-    # Montgomery reduction, t = t + m * N / 2^64
-    # m = t[i] * n0 mod 2^64
-    # single-round reduction process:Lsqr8x_reduction ——>Lsqr8x_tail->Lsqr8x_tail_break
-    #                                                 |__Lsqr8x8_post_condition
-    # after one round of reduction completes,
-    # process the current m[i..i+7]*N+t until
-    # all tp in the buffer have been reduced
- .Lsqr8x_reduction:
-    # mul $t0,$a0,$na0    # discarded
-    mul $t1,$a1,$na0    # lo(n[1-7])*lo(t[0]*n0)
-
-    @{[ld_cnt $carry2,$fp]}
-    addi $carry2,$carry2,-1    # cnt=cnt-1
-    @{[sd_cnt $carry2,$fp]}
-
-    mul $t2,$a2,$na0
-    sd $na0,0($tp)    # put aside "na0=t[0]*n0" for tail processing
-    addi $tp,$tp,8    # tp=tp+8
-    mul $t3,$a3,$na0
-
-    # low64 partial product + reduction term
-    snez $carry1, $acc0        # only carry status needed, not full lo1 result
-    mul $t0,$a4,$na0
-    @{[adcs $acc0, $acc1, $t1]}
-    mul $t1,$a5,$na0
-    @{[adcs $acc1, $acc2, $t2]}
-    mul $t2,$a6,$na0
-    @{[adcs $acc2, $acc3, $t3]}
-    mul $t3,$a7,$na0
-    @{[adcs $acc3, $acc4, $t0]}
-    mulhu $t0,$a0,$na0    # hi(n[0-7])*lo(t[0]*n0)
-    @{[adcs $acc4, $acc5, $t1]}
-    mulhu $t1,$a1,$na0
-    @{[adcs $acc5, $acc6, $t2]}
-    mulhu $t2,$a2,$na0
-    @{[adcs $acc6, $acc7, $t3]}
-    mulhu $t3,$a3,$na0
-    add $acc7,zero,$carry1
-
-    # high64 partial product + reduction term
-    @{[adds $acc0, $acc0, $t0]}
-    mulhu $t0,$a4,$na0
-    @{[adcs $acc1, $acc1, $t1]}
-    mulhu $t1,$a5,$na0
-    @{[adcs $acc2, $acc2, $t2]}
-    mulhu $t2,$a6,$na0
-    @{[adcs $acc3, $acc3, $t3]}
-    mulhu $t3,$a7,$na0
-    mul $na0,$n0,$acc0    # next na0
-    @{[adcs $acc4, $acc4, $t0]}
-    @{[adcs $acc5, $acc5, $t1]}
-    @{[adcs $acc6, $acc6, $t2]}
-    @{[adc  $acc7, $acc7, $t3]}
-
-    @{[ld_cnt $carry2,$fp]}
-    bnez $carry2,.Lsqr8x_reduction    # 8 iteration done?
-
-    ld $t0,0($tp)
-    ld $t1,8($tp)
-    ld $t2,16($tp)
-    ld $t3,24($tp)
-    mv $np_temp,$tp
-    @{[ld_npend $carry2,$fp]}
-    sub $carry2,$carry2,$np    # cnt=np_end-np, done yet?
-    @{[sd_cnt $carry2,$fp]}
-
-    @{[adds $acc0, $acc0, $t0]}
-    @{[adcs $acc1, $acc1, $t1]}
-    ld $t0,32($tp)
-    ld $t1,40($tp)
-    @{[adcs $acc2, $acc2, $t2]}
-    @{[adcs $acc3, $acc3, $t3]}
-    ld $t2,48($tp)
-    ld $t3,56($tp)
-    @{[adcs $acc4, $acc4, $t0]}
-    @{[adcs $acc5, $acc5, $t1]}
-    @{[adcs $acc6, $acc6, $t2]}
-    @{[adcs $acc7, $acc7, $t3]}
-
-    # check whether N has finished iteration.
-    # If completed, proceed to the special scenario '8' for processing;
-    # otherwise, continue with the reduction Lsqr8x_tail.
-    @{[ld_cnt $carry2,$fp]}
-    beqz $carry2,.Lsqr8x8_post_condition
-
-    ld $n0,-64($tp)    # load the previous na0
-    ld $a0,0($np)    # load next N[0..7]
-    ld $a1,8($np)
-    ld $a2,16($np)
-    ld $a3,24($np)
-    ld $a4,32($np)
-    ld $a5,40($np)
-    li $carry2,-64
-    @{[sd_cnt $carry2,$fp]}  # set loop cnt,cnt=-64
-    ld $a6,48($np)
-    ld $a7,56($np)
-    add $np,$np,64    # move pointer forward by next 8 elements
-
-.Lsqr8x_tail:
-    mul $t0,$a0,$n0
-    add $carry,zero,$carry1    # carry bit, modulo-scheduled
-    mul $t1,$a1,$n0
-
-    @{[ld_cnt $carry2,$fp]}
-    addi $carry2,$carry2,8    # cnt=cnt+8
-    @{[sd_cnt $carry2,$fp]}
-
-    mul $t2,$a2,$n0
-    mul $t3,$a3,$n0
-    # low64 partial product + reduction term
-    @{[adds $acc0, $acc0, $t0]}
-    mul $t0,$a4,$n0
-    @{[adcs $acc1, $acc1, $t1]}
-    mul $t1,$a5,$n0
-    @{[adcs $acc2, $acc2, $t2]}
-    mul $t2,$a6,$n0
-    @{[adcs $acc3, $acc3, $t3]}
-    mul $t3,$a7,$n0
-    @{[adcs $acc4, $acc4, $t0]}
-    mulhu $t0,$a0,$n0
-    @{[adcs $acc5, $acc5, $t1]}
-    mulhu $t1,$a1,$n0
-    @{[adcs $acc6, $acc6, $t2]}
-    mulhu $t2,$a2,$n0
-    @{[adcs $acc7, $acc7, $t3]}
-    mulhu $t3,$a3,$n0
-    add $carry,$carry,$carry1
-    sd $acc0,0($tp)
-    addi $tp,$tp,8    # move pointer forward by next 8 elements
-
-    # high64 partial product + reduction term
-    @{[adds $acc0, $acc1, $t0]}
-    mulhu $t0,$a4,$n0
-    @{[adcs $acc1, $acc2, $t1]}
-    mulhu $t1,$a5,$n0
-    @{[adcs $acc2, $acc3, $t2]}
-    mulhu $t2,$a6,$n0
-    @{[adcs $acc3, $acc4, $t3]}
-    mulhu $t3,$a7,$n0
-
-    @{[ld_cnt $carry2,$fp]}
-    add $carry2,$np_temp,$carry2
-    ld $n0,0($carry2)    # next n0, ld 0(np_temp+cnt)
-
-    @{[adcs $acc4, $acc5, $t0]}
-    @{[adcs $acc5, $acc6, $t1]}
-    @{[adcs $acc6, $acc7, $t2]}
-    @{[adcs $acc7, $carry, $t3]}
-    @{[ld_cnt $carry2,$fp]}
-    bnez $carry2,.Lsqr8x_tail    # 8 iteration done?
-
-    ld $a0,0($tp)
-    ld $a1,8($tp)
-    @{[ld_npend $carry2,$fp]}
-    sub $carry2,$carry2,$np    # done yet? cnt=np_end-np
-    @{[sd_cnt $carry2,$fp]}
-
-    @{[ld_npend $t0,$fp]}
-    @{[ld_num $t1,$fp]}
-    sub $t2, $t0, $t1    # rewinded np, t2=np_end-num
-    ld $a2,16($tp)
-    ld $a3,24($tp)
-    ld $a4,32($tp)
-    ld $a5,40($tp)
-    ld $a6,48($tp)
-    ld $a7,56($tp)
-
-    @{[ld_cnt $carry2,$fp]}
-    beqz $carry2,.Lsqr8x_tail_break    # exit loop when np=np_end
-
-    ld $n0,-64($np_temp)    # load the previous n0 value
-    @{[adds $acc0, $acc0, $a0]}
-    @{[adcs $acc1, $acc1, $a1]}
-    ld $a0,0($np)    # next N[0..7]
-    ld $a1,8($np)
-    @{[adcs $acc2, $acc2, $a2]}
-    @{[adcs $acc3, $acc3, $a3]}
-    ld $a2,16($np)
-    ld $a3,24($np)
-    @{[adcs $acc4, $acc4, $a4]}
-    @{[adcs $acc5, $acc5, $a5]}
-    ld $a4,32($np)
-    ld $a5,40($np)
-    @{[adcs $acc6, $acc6, $a6]}
-
-    li $carry2,-64    # set loop cnt,cnt=-64
-    @{[sd_cnt $carry2,$fp]}
-
-    @{[adcs $acc7, $acc7, $a7]}
-    ld $a6,48($np)
-    ld $a7,56($np)
-    add $np,$np,64
-    j .Lsqr8x_tail
-
-.balign 16
-.Lsqr8x_tail_break:
-    @{[ld_n0 $n0,$fp]}    # load n0
-    addi $carry2,$tp,64    # cnt=cnt+64
-    @{[sd_cnt $carry2,$fp]}
-    @{[ld_topmost $carry2,$fp]} # load topmost
-
-    snez $carry1, $carry2    # "move" topmost carry to carry bit
-    @{[adcs $t0, $acc0, $a0]}
-    @{[adcs $t1, $acc1, $a1]}
-    ld $acc0,0($np_temp)    # load the current t[0..7] from tp
-    ld $acc1,8($np_temp)
-    @{[adcs $acc2, $acc2, $a2]}
-    ld $a0,0($t2)    # recall that $t2 is &n[0], initialize, load N[0..7]
-    ld $a1,8($t2)
-    @{[adcs $acc3, $acc3, $a3]}
-    ld $a2,16($t2)
-    ld $a3,24($t2)
-    @{[adcs $acc4, $acc4, $a4]}
-    @{[adcs $acc5, $acc5, $a5]}
-    ld $a4,32($t2)
-    ld $a5,40($t2)
-    @{[adcs $acc6, $acc6, $a6]}
-    @{[adcs $acc7, $acc7, $a7]}
-    ld $a6,48($t2)
-    ld $a7,56($t2)
-    addi $np,$t2,64    # np=np+64, move pointer forward by next 8 elements
-
-    @{[ld_topmost $carry2,$fp]}
-    add $carry2,zero,$carry1    # topmost carry
-    @{[sd_topmost $carry2,$fp]} # offload topmost
-
-    mul $na0,$n0,$acc0    # na0=n0*t[0]
-    sd $t0,0($tp)
-    sd $t1,8($tp)
-    sd $acc2,16($tp)
-    sd $acc3,24($tp)
-    ld $acc2,16($np_temp)
-    ld $acc3,24($np_temp)
-    sd $acc4,32($tp)
-    sd $acc5,40($tp)
-    ld $acc4,32($np_temp)
-    ld $acc5,40($np_temp)
-    @{[ld_cnt $t1,$fp]}    # load cnt, t1<-cnt
-    sd $acc6,48($tp)
-    sd $acc7,56($tp)
-    mv $tp,$np_temp    # update tp<-np_temp
-    ld $acc6,48($np_temp)
-    ld $acc7,56($np_temp)
-    li $carry2,8    #  set loop cnt, cnt=8
-    @{[sd_cnt $carry2,$fp]}
-    bne $t1,$fp, .Lsqr8x_reduction    # if t1!=fp,jump to the next round of reduction and
-                                      # continue with the reduction of the next set of na0.
-
-    @{[sd_n0 $n0,$fp]}    # offload n0
-    @{[ld_rp $carry,$fp]}
-    add $tp,$tp,64
-    @{[subs  $t0, $acc0, $a0]}
-    @{[sbcs  $t1, $acc1, $a1]}
-    @{[ld_num $t2,$fp]}
-    addi $t3,$t2,-64    # cnt=num-64
-    @{[sd_cnt $t3,$fp]}
-    mv $carry2,$carry    # ap_end=rp, rp copy
-    @{[sd_apend $carry2,$fp]}
-
-    # conditional subtraction, compute T-N
-    # If T < N (borrow occurs), set t = T;
-    # If T >= N (no borrow), set t = T-N
-    # Process 8 elements per loop iteration.
-.Lsqr8x_sub:
-    @{[sbcs  $t2, $acc2, $a2]}    # t=t-N
-    ld $a0,0($np)
-    ld $a1,8($np)
-    @{[sbcs  $t3, $acc3, $a3]}
-    sd $t0,0($carry)    # sd result
-    sd $t1,8($carry)
-    @{[sbcs  $t0, $acc4, $a4]}
-    ld $a2,16($np)
-    ld $a3,24($np)
-    @{[sbcs  $t1, $acc5, $a5]}
-    sd $t2,16($carry)
-    sd $t3,24($carry)
-    @{[sbcs  $t2, $acc6, $a6]}
-    ld $a4,32($np)
-    ld $a5,40($np)
-    @{[sbcs  $t3, $acc7, $a7]}
-    ld $a6,48($np)
-    ld $a7,56($np)
-    add $np,$np,64
-    ld $acc0,0($tp)    # ld t[0..7]
-    ld $acc1,8($tp)
-
-    @{[ld_cnt $carry2,$fp]}
-    addi $carry2,$carry2,-64    # cnt=cnt-64
-    @{[sd_cnt $carry2,$fp]}
-
-    ld $acc2,16($tp)
-    ld $acc3,24($tp)
-    ld $acc4,32($tp)
-    ld $acc5,40($tp)
-    ld $acc6,48($tp)
-    ld $acc7,56($tp)
-    add $tp,$tp,64    # move pointer forward by next 8 elements
-    sd $t0,32($carry)
-    sd $t1,40($carry)
-    @{[sbcs  $t0, $acc0, $a0]}
-    sd $t2,48($carry)
-    sd $t3,56($carry)
-    add $carry,$carry,64
-    @{[sbcs  $t1, $acc1, $a1]}
-
-    @{[ld_cnt $carry2,$fp]}
-    bnez $carry2,.Lsqr8x_sub    # # if cnt!=0, jump to Lsqr8x_sub
-
-    @{[sbcs  $t2, $acc2, $a2]}
-    mv $tp,sp
-    @{[ld_num $carry2,$fp]}
-    add $ap,sp,$carry2    # ap=sp-num
-
-    @{[ld_apend $carry2,$fp]}
-    ld $a0,0($carry2)    # ld 0(ap_end)
-    ld $a1,8($carry2)
-
-    @{[sbcs  $t3, $acc3, $a3]}
-    sd $t0,0($carry)
-    sd $t1,8($carry)
-    @{[sbcs  $t0, $acc4, $a4]}
-    @{[ld_apend $carry2,$fp]}
-    ld $a2,16($carry2)
-    ld $a3,24($carry2)
-    @{[sbcs  $t1, $acc5, $a5]}
-    sd $t2,16($carry)
-    sd $t3,24($carry)
-    @{[sbcs  $t2, $acc6, $a6]}
-    ld $acc0,0($ap)
-    ld $acc1,8($ap)
-    @{[sbcs  $t3, $acc7, $a7]}
-    ld $acc2,16($ap)
-    ld $acc3,24($ap)
-
-    @{[ld_topmost $temp,$fp]}
-    sub $carry2, $temp, $carry1    # did it borrow?
-    sltu $carry1, $temp, $carry2
-    xori $carry1, $carry1, 1
-
-    sd $t0,32($carry)
-    sd $t1,40($carry)
-    sd $t2,48($carry)
-    sd $t3,56($carry)
-
-    @{[ld_num $carry2,$fp]}
-    addi $carry2,$carry2,-32    # cnt=num-32
-    @{[sd_cnt $carry2,$fp]}
-    @{[ld_ra $ra,$fp]}    # offload ra
-
-
-    # The csel conditional instruction selects the result based on the borrow flag.
-    # If there is a borrow (C=0), select the original value acc
-    # If there is no borrow (C=1), select the subtracted value a
-    # Process 4 elements per loop iteration.
-.Lsqr4x_cond_copy:
-    @{[ld_cnt $carry2,$fp]}
-    addi $carry2,$carry2,-32    # cnt=cnt_pre-32=num-32-32
-    @{[sd_cnt $carry2,$fp]}
-
-    @{[csel  $t0, $acc0, $a0]}    # when pre_borrow occurs, t0 = acc0
-    sd zero,0($tp)
-    sd zero,8($tp)
-    @{[csel  $t1, $acc1, $a1]}
-    @{[ld_apend $carry2,$fp]}
-    ld $a0,32($carry2)
-    ld $a1,40($carry2)
-    ld $acc0,32($ap)
-    ld $acc1,40($ap)
-    @{[csel  $t2, $acc2, $a2]}
-    sd zero,16($tp)
-    sd zero,24($tp)
-    add $tp,$tp,32
-    @{[csel  $t3, $acc3, $a3]}
-    ld $a2,48($carry2)
-    ld $a3,56($carry2)
-    ld $acc2,48($ap)
-    ld $acc3,56($ap)
-    add $ap,$ap,32
-    sd $t0,0($carry2)
-    sd $t1,8($carry2)
-    sd $t2,16($carry2)
-    sd $t3,24($carry2)
-    add $carry2,$carry2,32    # ap_end=ap_end+32
-    @{[sd_apend $carry2,$fp]}
-    sd zero,0($ap)
-    sd zero,8($ap)
-    sd zero,16($ap)
-    sd zero,24($ap)
-
-    @{[ld_cnt $carry2,$fp]}
-    bnez $carry2,.Lsqr4x_cond_copy    # if cnt!=0, jump to Lsqr4x_cond_copy
-
-    @{[csel  $t0, $acc0, $a0]}
-    sd zero,0($tp)
-    sd zero,8($tp)
-    @{[csel  $t1, $acc1, $a1]}
-    sd zero,16($tp)
-    sd zero,24($tp)
-    @{[csel  $t2, $acc2, $a2]}
-    @{[csel  $t3, $acc3, $a3]}
-    @{[ld_apend $carry2,$fp]}
-    sd $t0,0($carry2)
-    sd $t1,8($carry2)
-    sd $t2,16($carry2)
-    sd $t3,24($carry2)
-    j .Lsqr8x_done
-
-# process special case for 8-word boundary
-.balign 16
-.Lsqr8x8_post_condition:
-    add $carry,zero,$carry1
-    @{[subs  $a0, $acc0, $a0]}    # acc0-7,carry hold result, a0-7 hold modulus
-    @{[ld_rp $ap,$fp]}    # pull rp
-    @{[sbcs  $a1, $acc1, $a1]}
-    sd zero,0(sp)
-    sd zero,8(sp)
-    @{[sbcs  $a2, $acc2, $a2]}
-    sd zero,16(sp)
-    sd zero,24(sp)
-    @{[sbcs  $a3, $acc3, $a3]}
-    sd zero,32(sp)
-    sd zero,40(sp)
-    @{[sbcs  $a4, $acc4, $a4]}
-    sd zero,48(sp)
-    sd zero,56(sp)
-    @{[sbcs  $a5, $acc5, $a5]}
-    sd zero,64(sp)
-    sd zero,72(sp)
-    @{[sbcs  $a6, $acc6, $a6]}
-    sd zero,80(sp)
-    sd zero,88(sp)
-    @{[sbcs  $a7, $acc7, $a7]}
-    sd zero,96(sp)
-    sd zero,104(sp)
-    @{[sbcs  $carry, $carry, "zero"]}    # did it borrow?
-    xori $carry1, $carry1, 1
-    sd zero,112(sp)
-    sd zero,120(sp)
-
-    # a0-7 hold result-modulus
-    @{[csel  $a0, $acc0, $a0]}
-    @{[csel  $a1, $acc1, $a1]}
-    @{[csel  $a2, $acc2, $a2]}
-    @{[csel  $a3, $acc3, $a3]}
-    sd $a0,0($ap)
-    sd $a1,8($ap)
-    @{[csel  $a4, $acc4, $a4]}
-    @{[csel  $a5, $acc5, $a5]}
-    sd $a2,16($ap)
-    sd $a3,24($ap)
-    @{[csel  $a6, $acc6, $a6]}
-    @{[csel  $a7, $acc7, $a7]}
-    sd $a4,32($ap)
-    sd $a5,40($ap)
-    sd $a6,48($ap)
-    sd $a7,56($ap)
-
-    @{[ld_ra $ra,$fp]}    # pull ra return address
-.Lsqr8x_done:
-    mv sp, $fp
-    li $rp, 1
-___
-$code .= <<___;
-    ld      s0,88(sp)
-    ld      s1,80(sp)
-    ld      s2,72(sp)
-    ld      s3,64(sp)
-    ld      s4,56(sp)
-    ld      s5,48(sp)
-    ld      s6,40(sp)
-    ld      s7,32(sp)
-    ld      s8,24(sp)
-    ld      s9,16(sp)
-    ld      s11,8(sp)
-    ld      s10,0(sp)
-    addi    sp,sp,168
-    ret
-.size bn_sqr8x_mont,.-bn_sqr8x_mont
-___
-}
 print $code;
 close STDOUT or die "error closing STDOUT: $!";
diff --git a/crypto/bn/asm/rsaz-2k-avx512.pl b/crypto/bn/asm/rsaz-2k-avx512.pl
index 7e1db31e22..27f2e9b4b9 100644
--- a/crypto/bn/asm/rsaz-2k-avx512.pl
+++ b/crypto/bn/asm/rsaz-2k-avx512.pl
@@ -64,13 +64,6 @@ if (!$avx512ifma && `$ENV{CC} -v 2>&1`
     }
 }
 
-if (!$avx512ifma && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-    =~ /#define __clang_major__.([0-9]+)/) {
-    if ($1) {
-        $avx512ifma = ($1>=11); #icx started with clang 11
-    }
-}
-
 open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\""
     or die "can't call $xlate: $!";
 *STDOUT=*OUT;
diff --git a/crypto/bn/asm/rsaz-2k-avxifma.pl b/crypto/bn/asm/rsaz-2k-avxifma.pl
index 652d659442..ea45d2051a 100644
--- a/crypto/bn/asm/rsaz-2k-avxifma.pl
+++ b/crypto/bn/asm/rsaz-2k-avxifma.pl
@@ -39,13 +39,6 @@ if (!$avxifma && `$ENV{CC} -v 2>&1`
     $avxifma = ($ver>=16.0);
 }
 
-if (!$avxifma && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-    =~ /#define __clang_major__.([0-9]+)/) {
-    if ($1) {
-        $avxifma = ($1>=16);
-    }
-}
-
 if ($win64 && ($flavour =~ /nasm/ || $ENV{ASM} =~ /nasm/) &&
        `nasm -v 2>&1` =~ /NASM version ([0-9]+)\.([0-9]+)(?:\.([0-9]+))?(rc[0-9]+)?/) {
     my $ver = $1 + $2/100.0 + $3/10000.0; # 3.1.0->3.01, 3.10.1->3.1001
@@ -369,23 +362,6 @@ ossl_rsaz_amm52x20_x1_avxifma256:
 .cfi_push   %r14
     push    %r15
 .cfi_push   %r15
-___
-$code.=<<___ if ($win64);
-    push      %rsi                          # save non-volatile registers
-    push      %rdi
-    lea       -168(%rsp), %rsp              # 16*10 + (8 bytes to get correct 16-byte SIMD alignment)
-    vmovapd   %xmm6, `16*0`(%rsp)
-    vmovapd   %xmm7, `16*1`(%rsp)
-    vmovapd   %xmm8, `16*2`(%rsp)
-    vmovapd   %xmm9, `16*3`(%rsp)
-    vmovapd   %xmm10, `16*4`(%rsp)
-    vmovapd   %xmm11, `16*5`(%rsp)
-    vmovapd   %xmm12, `16*6`(%rsp)
-    vmovapd   %xmm13, `16*7`(%rsp)
-    vmovapd   %xmm14, `16*8`(%rsp)
-    vmovapd   %xmm15, `16*9`(%rsp)
-___
-$code.=<<___;
 .Lossl_rsaz_amm52x20_x1_avxifma256_body:
 
     # Zeroing accumulators
@@ -425,23 +401,6 @@ $code.=<<___;
     vmovdqu   $R2_0,  `4*32`($res)
 
     vzeroupper
-___
-$code.=<<___ if ($win64);
-    vmovapd `16*0`(%rsp), %xmm6
-    vmovapd `16*1`(%rsp), %xmm7
-    vmovapd `16*2`(%rsp), %xmm8
-    vmovapd `16*3`(%rsp), %xmm9
-    vmovapd `16*4`(%rsp), %xmm10
-    vmovapd `16*5`(%rsp), %xmm11
-    vmovapd `16*6`(%rsp), %xmm12
-    vmovapd `16*7`(%rsp), %xmm13
-    vmovapd `16*8`(%rsp), %xmm14
-    vmovapd `16*9`(%rsp), %xmm15
-    lea     168(%rsp), %rsp
-    pop     %rdi
-    pop     %rsi
-___
-$code.=<<___;
     mov  0(%rsp),%r15
 .cfi_restore    %r15
     mov  8(%rsp),%r14
@@ -594,23 +553,6 @@ ossl_rsaz_amm52x20_x2_avxifma256:
 .cfi_push   %r14
     push    %r15
 .cfi_push   %r15
-___
-$code.=<<___ if ($win64);
-    push    %rsi                            # save non-volatile registers
-    push    %rdi
-    lea     -168(%rsp), %rsp                # 16*10 + (8 bytes to get correct 16-byte SIMD alignment)
-    vmovapd %xmm6, `16*0`(%rsp)
-    vmovapd %xmm7, `16*1`(%rsp)
-    vmovapd %xmm8, `16*2`(%rsp)
-    vmovapd %xmm9, `16*3`(%rsp)
-    vmovapd %xmm10, `16*4`(%rsp)
-    vmovapd %xmm11, `16*5`(%rsp)
-    vmovapd %xmm12, `16*6`(%rsp)
-    vmovapd %xmm13, `16*7`(%rsp)
-    vmovapd %xmm14, `16*8`(%rsp)
-    vmovapd %xmm15, `16*9`(%rsp)
-___
-$code.=<<___;
 .Lossl_rsaz_amm52x20_x2_avxifma256_body:
 
     # Zeroing accumulators
@@ -662,23 +604,6 @@ $code.=<<___;
     vmovdqu   $R2_1,  `9*32`($res)
 
     vzeroupper
-___
-$code.=<<___ if ($win64);
-    vmovapd `16*0`(%rsp), %xmm6
-    vmovapd `16*1`(%rsp), %xmm7
-    vmovapd `16*2`(%rsp), %xmm8
-    vmovapd `16*3`(%rsp), %xmm9
-    vmovapd `16*4`(%rsp), %xmm10
-    vmovapd `16*5`(%rsp), %xmm11
-    vmovapd `16*6`(%rsp), %xmm12
-    vmovapd `16*7`(%rsp), %xmm13
-    vmovapd `16*8`(%rsp), %xmm14
-    vmovapd `16*9`(%rsp), %xmm15
-    lea     168(%rsp), %rsp
-    pop     %rdi
-    pop     %rsi
-___
-$code.=<<___;
     mov  0(%rsp),%r15
 .cfi_restore    %r15
     mov  8(%rsp),%r14
@@ -738,23 +663,6 @@ $code.=<<___;
 ossl_extract_multiplier_2x20_win5_avx:
 .cfi_startproc
     endbranch
-___
-$code.=<<___ if ($win64);
-    push      %rsi                          # save non-volatile registers
-    push      %rdi
-    lea       -168(%rsp), %rsp              # 16*10 + (8 bytes to get correct 16-byte SIMD alignment)
-    vmovapd   %xmm6, `16*0`(%rsp)
-    vmovapd   %xmm7, `16*1`(%rsp)
-    vmovapd   %xmm8, `16*2`(%rsp)
-    vmovapd   %xmm9, `16*3`(%rsp)
-    vmovapd   %xmm10, `16*4`(%rsp)
-    vmovapd   %xmm11, `16*5`(%rsp)
-    vmovapd   %xmm12, `16*6`(%rsp)
-    vmovapd   %xmm13, `16*7`(%rsp)
-    vmovapd   %xmm14, `16*8`(%rsp)
-    vmovapd   %xmm15, `16*9`(%rsp)
-___
-$code.=<<___;
     vmovapd   .Lones(%rip), $ones         # broadcast ones
     vmovq $red_tbl_idx1, $tmp_xmm
     vpbroadcastq    $tmp_xmm, $idx1
@@ -800,24 +708,6 @@ ___
 foreach (0..9) {
     $code.="vmovdqu   $t[$_], `${_}*32`($out) \n";
 }
-$code.=<<___;
-    vzeroupper
-___
-$code.=<<___ if ($win64);
-    vmovapd `16*0`(%rsp), %xmm6
-    vmovapd `16*1`(%rsp), %xmm7
-    vmovapd `16*2`(%rsp), %xmm8
-    vmovapd `16*3`(%rsp), %xmm9
-    vmovapd `16*4`(%rsp), %xmm10
-    vmovapd `16*5`(%rsp), %xmm11
-    vmovapd `16*6`(%rsp), %xmm12
-    vmovapd `16*7`(%rsp), %xmm13
-    vmovapd `16*8`(%rsp), %xmm14
-    vmovapd `16*9`(%rsp), %xmm15
-    lea     168(%rsp), %rsp
-    pop     %rdi
-    pop     %rsi
-___
 $code.=<<___;
     ret
 .cfi_endproc
diff --git a/crypto/bn/asm/rsaz-3k-avx512.pl b/crypto/bn/asm/rsaz-3k-avx512.pl
index 403e09099f..b2ed3e8ca7 100644
--- a/crypto/bn/asm/rsaz-3k-avx512.pl
+++ b/crypto/bn/asm/rsaz-3k-avx512.pl
@@ -63,13 +63,6 @@ if (!$avx512ifma && `$ENV{CC} -v 2>&1`
     }
 }
 
-if (!$avx512ifma && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-    =~ /#define __clang_major__.([0-9]+)/) {
-    if ($1) {
-        $avx512ifma = ($1>=11); #icx started with clang 11
-    }
-}
-
 open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\""
     or die "can't call $xlate: $!";
 *STDOUT=*OUT;
diff --git a/crypto/bn/asm/rsaz-3k-avxifma.pl b/crypto/bn/asm/rsaz-3k-avxifma.pl
index 9141e552bd..a19cb5aaa3 100644
--- a/crypto/bn/asm/rsaz-3k-avxifma.pl
+++ b/crypto/bn/asm/rsaz-3k-avxifma.pl
@@ -38,13 +38,6 @@ if (!$avxifma && `$ENV{CC} -v 2>&1`
     $avxifma = ($ver>=16.0);
 }
 
-if (!$avxifma && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-    =~ /#define __clang_major__.([0-9]+)/) {
-    if ($1) {
-        $avxifma = ($1>=16);
-    }
-}
-
 if ($win64 && ($flavour =~ /nasm/ || $ENV{ASM} =~ /nasm/) &&
        `nasm -v 2>&1` =~ /NASM version ([2-9]\.[0-9]+)(?:\.([0-9]+))?(rc[0-9]+)?/) {
     $avxifma = ($1>2.16) + ($1==2.16 && ((!defined($2) && !defined($3)) || (defined($2))));
@@ -94,6 +87,8 @@ my ($res,$a,$b,$m,$k0) = @_6_args_universal_ABI;
 my $mask52     = "%rax";
 my $acc0_0     = "%r9";
 my $acc0_0_low = "%r9d";
+my $acc0_1     = "%r15";
+my $acc0_1_low = "%r15d";
 my $b_ptr      = "%r11";
 
 my $iter = "%ebx";
@@ -746,7 +741,7 @@ $code.=<<___;
     vmovdqu   $R3_0,  `6*32`($res)
     vmovdqu   $R3_0h, `7*32`($res)
 
-    xorl    $acc0_0_low, $acc0_0_low
+    xorl    $acc0_1_low, $acc0_1_low
 
     lea    16($b_ptr), $b_ptr
     movq    \$0xfffffffffffff, $mask52       # 52-bit mask
@@ -862,23 +857,6 @@ $code.=<<___;
 ossl_extract_multiplier_2x30_win5_avx:
 .cfi_startproc
     endbranch
-___
-$code.=<<___ if ($win64);
-    push      %rsi                          # save non-volatile registers
-    push      %rdi
-    lea       -168(%rsp), %rsp              # 16*10 + (8 bytes to get correct 16-byte SIMD alignment)
-    vmovapd   %xmm6, `16*0`(%rsp)
-    vmovapd   %xmm7, `16*1`(%rsp)
-    vmovapd   %xmm8, `16*2`(%rsp)
-    vmovapd   %xmm9, `16*3`(%rsp)
-    vmovapd   %xmm10, `16*4`(%rsp)
-    vmovapd   %xmm11, `16*5`(%rsp)
-    vmovapd   %xmm12, `16*6`(%rsp)
-    vmovapd   %xmm13, `16*7`(%rsp)
-    vmovapd   %xmm14, `16*8`(%rsp)
-    vmovapd   %xmm15, `16*9`(%rsp)
-___
-$code.=<<___;
     vmovapd   .Lones(%rip), $ones         # broadcast ones
     vmovq    $red_tbl_idx1, $tmp_xmm
     vpbroadcastq    $tmp_xmm, $idx1
@@ -952,24 +930,6 @@ foreach (8..15) {
     $code.="vmovdqu   $t[$_], `${_}*32`($out) \n";
 }
 
-$code.=<<___;
-    vzeroupper
-___
-$code.=<<___ if ($win64);
-    vmovapd `16*0`(%rsp), %xmm6
-    vmovapd `16*1`(%rsp), %xmm7
-    vmovapd `16*2`(%rsp), %xmm8
-    vmovapd `16*3`(%rsp), %xmm9
-    vmovapd `16*4`(%rsp), %xmm10
-    vmovapd `16*5`(%rsp), %xmm11
-    vmovapd `16*6`(%rsp), %xmm12
-    vmovapd `16*7`(%rsp), %xmm13
-    vmovapd `16*8`(%rsp), %xmm14
-    vmovapd `16*9`(%rsp), %xmm15
-    lea     168(%rsp), %rsp
-    pop     %rdi
-    pop     %rsi
-___
 
 $code.=<<___;
 
diff --git a/crypto/bn/asm/rsaz-4k-avx512.pl b/crypto/bn/asm/rsaz-4k-avx512.pl
index f41c1c60df..b76ab5904c 100644
--- a/crypto/bn/asm/rsaz-4k-avx512.pl
+++ b/crypto/bn/asm/rsaz-4k-avx512.pl
@@ -63,13 +63,6 @@ if (!$avx512ifma && `$ENV{CC} -v 2>&1`
     }
 }
 
-if (!$avx512ifma && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-    =~ /#define __clang_major__.([0-9]+)/) {
-    if ($1) {
-        $avx512ifma = ($1>=11); #icx started with clang 11
-    }
-}
-
 open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\""
     or die "can't call $xlate: $!";
 *STDOUT=*OUT;
diff --git a/crypto/bn/asm/rsaz-4k-avxifma.pl b/crypto/bn/asm/rsaz-4k-avxifma.pl
index 2f7b036e5d..f15e2d7411 100644
--- a/crypto/bn/asm/rsaz-4k-avxifma.pl
+++ b/crypto/bn/asm/rsaz-4k-avxifma.pl
@@ -38,13 +38,6 @@ if (!$avxifma && `$ENV{CC} -v 2>&1`
     $avxifma = ($ver>=16.0);
 }
 
-if (!$avxifma && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-    =~ /#define __clang_major__.([0-9]+)/) {
-    if ($1) {
-        $avxifma = ($1>=16);
-    }
-}
-
 if ($win64 && ($flavour =~ /nasm/ || $ENV{ASM} =~ /nasm/) &&
        `nasm -v 2>&1` =~ /NASM version ([2-9]\.[0-9]+)(?:\.([0-9]+))?(rc[0-9]+)?/) {
     $avxifma = ($1>2.16) + ($1==2.16 && ((!defined($2) && !defined($3)) || (defined($2))));
@@ -91,6 +84,8 @@ my ($res,$a,$b,$m,$k0) = @_6_args_universal_ABI;
 my $mask52     = "%rax";
 my $acc0_0     = "%r9";
 my $acc0_0_low = "%r9d";
+my $acc0_1     = "%r15";
+my $acc0_1_low = "%r15d";
 my $b_ptr      = "%r11";
 
 my $iter = "%ebx";
@@ -839,7 +834,7 @@ $code.=<<___;
     vmovdqu   $R4_0,  `8*32`($res)
     vmovdqu   $R4_0h, `9*32`($res)
 
-    xorl    $acc0_0_low, $acc0_0_low
+    xorl    $acc0_1_low, $acc0_1_low
 
     movq    \$0xfffffffffffff, $mask52
 
@@ -980,23 +975,6 @@ $code.=<<___;
 ossl_extract_multiplier_2x40_win5_avx:
 .cfi_startproc
     endbranch
-___
-$code.=<<___ if ($win64);
-    push      %rsi                          # save non-volatile registers
-    push      %rdi
-    lea       -168(%rsp), %rsp              # 16*10 + (8 bytes to get correct 16-byte SIMD alignment)
-    vmovapd   %xmm6, `16*0`(%rsp)
-    vmovapd   %xmm7, `16*1`(%rsp)
-    vmovapd   %xmm8, `16*2`(%rsp)
-    vmovapd   %xmm9, `16*3`(%rsp)
-    vmovapd   %xmm10, `16*4`(%rsp)
-    vmovapd   %xmm11, `16*5`(%rsp)
-    vmovapd   %xmm12, `16*6`(%rsp)
-    vmovapd   %xmm13, `16*7`(%rsp)
-    vmovapd   %xmm14, `16*8`(%rsp)
-    vmovapd   %xmm15, `16*9`(%rsp)
-___
-$code.=<<___;
     vmovapd   .Lones(%rip), $ones         # broadcast ones
     vmovq $red_tbl_idx1, $tmp_xmm
     vpbroadcastq    $tmp_xmm, $idx1
@@ -1023,24 +1001,6 @@ $code.="movq    %r10, $red_tbl \n";
 foreach (0..9) {
     $code.="vmovdqu   $t[$_], `(10+$_)*32`($out) \n";
 }
-$code.=<<___;
-    vzeroupper
-___
-$code.=<<___ if ($win64);
-    vmovapd `16*0`(%rsp), %xmm6
-    vmovapd `16*1`(%rsp), %xmm7
-    vmovapd `16*2`(%rsp), %xmm8
-    vmovapd `16*3`(%rsp), %xmm9
-    vmovapd `16*4`(%rsp), %xmm10
-    vmovapd `16*5`(%rsp), %xmm11
-    vmovapd `16*6`(%rsp), %xmm12
-    vmovapd `16*7`(%rsp), %xmm13
-    vmovapd `16*8`(%rsp), %xmm14
-    vmovapd `16*9`(%rsp), %xmm15
-    lea     168(%rsp), %rsp
-    pop     %rdi
-    pop     %rsi
-___
 $code.=<<___;
 
     ret
diff --git a/crypto/bn/asm/rsaz-avx2.pl b/crypto/bn/asm/rsaz-avx2.pl
index 239ffb7e2b..30ba4e0b58 100755
--- a/crypto/bn/asm/rsaz-avx2.pl
+++ b/crypto/bn/asm/rsaz-avx2.pl
@@ -73,14 +73,6 @@ if (!$avx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|based on LLVM) ([0-9
 	$addx = ($ver>=3.03);
 }
 
-if (!$avx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$addx = ($1>=11); #icx started with clang 11
-		$avx = ($1>=11);
-	}
-}
-
 open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\""
     or die "can't call $xlate: $!";
 *STDOUT = *OUT;
diff --git a/crypto/bn/asm/rsaz-x86_64.pl b/crypto/bn/asm/rsaz-x86_64.pl
index ea6f3f2ac6..ebb4762b63 100755
--- a/crypto/bn/asm/rsaz-x86_64.pl
+++ b/crypto/bn/asm/rsaz-x86_64.pl
@@ -90,13 +90,6 @@ if (!$addx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([
 	$addx = ($ver>=3.03);
 }
 
-if (!$addx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$addx = ($1>=11); #icx started with clang 11
-	}
-}
-
 ($out, $inp, $mod) = ("%rdi", "%rsi", "%rbp");	# common internal API
 {
 my ($out,$inp,$mod,$n0,$times) = ("%rdi","%rsi","%rdx","%rcx","%r8d");
diff --git a/crypto/bn/asm/sparct4-mont.pl b/crypto/bn/asm/sparct4-mont.pl
index 1d2747c4ca..8a3bedc9af 100755
--- a/crypto/bn/asm/sparct4-mont.pl
+++ b/crypto/bn/asm/sparct4-mont.pl
@@ -89,7 +89,7 @@ $code.=<<___;
 #ifndef __ASSEMBLER__
 # define __ASSEMBLER__ 1
 #endif
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 #ifdef	__arch64__
 .register	%g2,#scratch
diff --git a/crypto/bn/asm/sparcv9-gf2m.pl b/crypto/bn/asm/sparcv9-gf2m.pl
index 2cd0498aa1..7beee807f4 100644
--- a/crypto/bn/asm/sparcv9-gf2m.pl
+++ b/crypto/bn/asm/sparcv9-gf2m.pl
@@ -41,7 +41,7 @@ $code.=<<___;
 #ifndef __ASSEMBLER__
 # define __ASSEMBLER__ 1
 #endif
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 #ifdef __arch64__
 .register	%g2,#scratch
diff --git a/crypto/bn/asm/sparcv9-mont.pl b/crypto/bn/asm/sparcv9-mont.pl
index 4578f523a6..a7624df99f 100644
--- a/crypto/bn/asm/sparcv9-mont.pl
+++ b/crypto/bn/asm/sparcv9-mont.pl
@@ -1,5 +1,5 @@
 #! /usr/bin/env perl
-# Copyright 2005-2026 The OpenSSL Project Authors. All Rights Reserved.
+# Copyright 2005-2025 The OpenSSL Project Authors. All Rights Reserved.
 #
 # Licensed under the Apache License 2.0 (the "License").  You may not use
 # this file except in compliance with the License.  You can obtain a copy
@@ -86,7 +86,7 @@ $code=<<___;
 #ifndef __ASSEMBLER__
 # define __ASSEMBLER__ 1
 #endif
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 .section	".text",#alloc,#execinstr
 
@@ -394,11 +394,11 @@ $code.=<<___;
 
 	mulx	$car1,$mul1,$car1
 	mulx	$npj,$mul1,$acc1
-	add	$tmp1,$car0,$car0
 	add	$tmp0,$car1,$car1
 	and	$car0,$mask,$acc0
 	ld	[$np+8],$npj			! np[2]
 	srlx	$car1,32,$car1
+	add	$tmp1,$car1,$car1
 	srlx	$car0,32,$car0
 	add	$acc0,$car1,$car1
 	and	$car0,1,$sbit
diff --git a/crypto/bn/asm/sparcv9a-mont.pl b/crypto/bn/asm/sparcv9a-mont.pl
index 81fc807625..f60854e95f 100755
--- a/crypto/bn/asm/sparcv9a-mont.pl
+++ b/crypto/bn/asm/sparcv9a-mont.pl
@@ -129,7 +129,7 @@ $code=<<___;
 #ifndef __ASSEMBLER__
 # define __ASSEMBLER__ 1
 #endif
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 .section	".text",#alloc,#execinstr
 
diff --git a/crypto/bn/asm/vis3-mont.pl b/crypto/bn/asm/vis3-mont.pl
index 65a6c23e3c..5f8304c0ea 100644
--- a/crypto/bn/asm/vis3-mont.pl
+++ b/crypto/bn/asm/vis3-mont.pl
@@ -34,7 +34,7 @@ $code.=<<___;
 #ifndef __ASSEMBLER__
 # define __ASSEMBLER__ 1
 #endif
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 #ifdef	__arch64__
 .register	%g2,#scratch
diff --git a/crypto/bn/asm/x86_64-gcc.c b/crypto/bn/asm/x86_64-gcc.c
index 03299a7b72..7edb77806e 100644
--- a/crypto/bn/asm/x86_64-gcc.c
+++ b/crypto/bn/asm/x86_64-gcc.c
@@ -8,7 +8,7 @@
  */
 
 #include "../bn_local.h"
-#if !defined(__GNUC__)
+#if !(defined(__GNUC__) && __GNUC__ >= 2)
 /* clang-format off */
 # include "../bn_asm.c"         /* kind of dirty hack for Sun Studio */
 /* clang-format on */
diff --git a/crypto/bn/asm/x86_64-mont.pl b/crypto/bn/asm/x86_64-mont.pl
index 3b3bd747e5..78c006126f 100755
--- a/crypto/bn/asm/x86_64-mont.pl
+++ b/crypto/bn/asm/x86_64-mont.pl
@@ -82,13 +82,6 @@ if (!$addx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([
 	$addx = ($ver>=3.03);
 }
 
-if (!$addx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$addx = ($1>=11); #icx started with clang 11
-	}
-}
-
 # int bn_mul_mont(
 $rp="%rdi";	# BN_ULONG *rp,
 $ap="%rsi";	# const BN_ULONG *ap,
diff --git a/crypto/bn/asm/x86_64-mont5.pl b/crypto/bn/asm/x86_64-mont5.pl
index 95d34e0b50..6b40f789b3 100755
--- a/crypto/bn/asm/x86_64-mont5.pl
+++ b/crypto/bn/asm/x86_64-mont5.pl
@@ -69,13 +69,6 @@ if (!$addx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([
 	$addx = ($ver>=3.03);
 }
 
-if (!$addx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$addx = ($1>=11); #icx started with clang 11
-	}
-}
-
 # int bn_mul_mont_gather5(
 $rp="%rdi";	# BN_ULONG *rp,
 $ap="%rsi";	# const BN_ULONG *ap,
diff --git a/crypto/bn/bn_add.c b/crypto/bn/bn_add.c
index 24151d0e13..88d77c534f 100644
--- a/crypto/bn/bn_add.c
+++ b/crypto/bn/bn_add.c
@@ -97,8 +97,6 @@ int BN_uadd(BIGNUM *r, const BIGNUM *a, const BIGNUM *b)
         return 0;
 
     r->top = max;
-    if (max == 0)
-        goto end;
 
     ap = a->d;
     bp = b->d;
@@ -118,7 +116,6 @@ int BN_uadd(BIGNUM *r, const BIGNUM *a, const BIGNUM *b)
     *rp = carry;
     r->top += (int)carry;
 
-end:
     r->neg = 0;
     bn_check_top(r);
     return 1;
@@ -146,9 +143,6 @@ int BN_usub(BIGNUM *r, const BIGNUM *a, const BIGNUM *b)
     if (bn_wexpand(r, max) == NULL)
         return 0;
 
-    if (max == 0)
-        goto end;
-
     ap = a->d;
     bp = b->d;
     rp = r->d;
@@ -168,7 +162,6 @@ int BN_usub(BIGNUM *r, const BIGNUM *a, const BIGNUM *b)
     while (max && *--rp == 0)
         max--;
 
-end:
     r->top = max;
     r->neg = 0;
     bn_pollute(r);
diff --git a/crypto/bn/bn_asm.c b/crypto/bn/bn_asm.c
index e667702143..0a77f1b070 100644
--- a/crypto/bn/bn_asm.c
+++ b/crypto/bn/bn_asm.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -429,7 +429,7 @@ BN_ULONG bn_sub_words(BN_ULONG *r, const BN_ULONG *a, const BN_ULONG *b,
     return c;
 }
 
-#ifndef OPENSSL_SMALL_FOOTPRINT
+#if defined(BN_MUL_COMBA) && !defined(OPENSSL_SMALL_FOOTPRINT)
 
 /* mul_add_c(a,b,c0,c1,c2)  -- c+=a*b for three word number c=(c2,c1,c0) */
 /* mul_add_c2(a,b,c0,c1,c2) -- c+=2*a*b for three word number c=(c2,c1,c0) */
@@ -991,7 +991,7 @@ int bn_mul_mont(BN_ULONG *rp, const BN_ULONG *ap, const BN_ULONG *bp,
 #endif /* OPENSSL_BN_ASM_MONT */
 #endif
 
-#else /* OPENSSL_SMALL_FOOTPRINT */
+#else /* !BN_MUL_COMBA */
 
 /* hmm... is it faster just to do a multiply? */
 void bn_sqr_comba4(BN_ULONG *r, const BN_ULONG *a)
@@ -1078,4 +1078,4 @@ int bn_mul_mont(BN_ULONG *rp, const BN_ULONG *ap, const BN_ULONG *bp,
 #endif /* OPENSSL_BN_ASM_MONT */
 #endif
 
-#endif /* !OPENSSL_SMALL_FOOTPRINT */
+#endif /* !BN_MUL_COMBA */
diff --git a/crypto/bn/bn_const.c b/crypto/bn/bn_const.c
index 1dfdbf6ac0..974868feca 100644
--- a/crypto/bn/bn_const.c
+++ b/crypto/bn/bn_const.c
@@ -24,16 +24,102 @@
 BIGNUM *BN_get_rfc2409_prime_768(BIGNUM *bn)
 {
     static const unsigned char RFC2409_PRIME_768[] = {
-        0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xC9, 0x0F,
-        0xDA, 0xA2, 0x21, 0x68, 0xC2, 0x34, 0xC4, 0xC6, 0x62, 0x8B,
-        0x80, 0xDC, 0x1C, 0xD1, 0x29, 0x02, 0x4E, 0x08, 0x8A, 0x67,
-        0xCC, 0x74, 0x02, 0x0B, 0xBE, 0xA6, 0x3B, 0x13, 0x9B, 0x22,
-        0x51, 0x4A, 0x08, 0x79, 0x8E, 0x34, 0x04, 0xDD, 0xEF, 0x95,
-        0x19, 0xB3, 0xCD, 0x3A, 0x43, 0x1B, 0x30, 0x2B, 0x0A, 0x6D,
-        0xF2, 0x5F, 0x14, 0x37, 0x4F, 0xE1, 0x35, 0x6D, 0x6D, 0x51,
-        0xC2, 0x45, 0xE4, 0x85, 0xB5, 0x76, 0x62, 0x5E, 0x7E, 0xC6,
-        0xF4, 0x4C, 0x42, 0xE9, 0xA6, 0x3A, 0x36, 0x20, 0xFF, 0xFF,
-        0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xC9,
+        0x0F,
+        0xDA,
+        0xA2,
+        0x21,
+        0x68,
+        0xC2,
+        0x34,
+        0xC4,
+        0xC6,
+        0x62,
+        0x8B,
+        0x80,
+        0xDC,
+        0x1C,
+        0xD1,
+        0x29,
+        0x02,
+        0x4E,
+        0x08,
+        0x8A,
+        0x67,
+        0xCC,
+        0x74,
+        0x02,
+        0x0B,
+        0xBE,
+        0xA6,
+        0x3B,
+        0x13,
+        0x9B,
+        0x22,
+        0x51,
+        0x4A,
+        0x08,
+        0x79,
+        0x8E,
+        0x34,
+        0x04,
+        0xDD,
+        0xEF,
+        0x95,
+        0x19,
+        0xB3,
+        0xCD,
+        0x3A,
+        0x43,
+        0x1B,
+        0x30,
+        0x2B,
+        0x0A,
+        0x6D,
+        0xF2,
+        0x5F,
+        0x14,
+        0x37,
+        0x4F,
+        0xE1,
+        0x35,
+        0x6D,
+        0x6D,
+        0x51,
+        0xC2,
+        0x45,
+        0xE4,
+        0x85,
+        0xB5,
+        0x76,
+        0x62,
+        0x5E,
+        0x7E,
+        0xC6,
+        0xF4,
+        0x4C,
+        0x42,
+        0xE9,
+        0xA6,
+        0x3A,
+        0x36,
+        0x20,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
     };
     return BN_bin2bn(RFC2409_PRIME_768, sizeof(RFC2409_PRIME_768), bn);
 }
@@ -50,19 +136,134 @@ BIGNUM *BN_get_rfc2409_prime_768(BIGNUM *bn)
 BIGNUM *BN_get_rfc2409_prime_1024(BIGNUM *bn)
 {
     static const unsigned char RFC2409_PRIME_1024[] = {
-        0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xC9, 0x0F,
-        0xDA, 0xA2, 0x21, 0x68, 0xC2, 0x34, 0xC4, 0xC6, 0x62, 0x8B,
-        0x80, 0xDC, 0x1C, 0xD1, 0x29, 0x02, 0x4E, 0x08, 0x8A, 0x67,
-        0xCC, 0x74, 0x02, 0x0B, 0xBE, 0xA6, 0x3B, 0x13, 0x9B, 0x22,
-        0x51, 0x4A, 0x08, 0x79, 0x8E, 0x34, 0x04, 0xDD, 0xEF, 0x95,
-        0x19, 0xB3, 0xCD, 0x3A, 0x43, 0x1B, 0x30, 0x2B, 0x0A, 0x6D,
-        0xF2, 0x5F, 0x14, 0x37, 0x4F, 0xE1, 0x35, 0x6D, 0x6D, 0x51,
-        0xC2, 0x45, 0xE4, 0x85, 0xB5, 0x76, 0x62, 0x5E, 0x7E, 0xC6,
-        0xF4, 0x4C, 0x42, 0xE9, 0xA6, 0x37, 0xED, 0x6B, 0x0B, 0xFF,
-        0x5C, 0xB6, 0xF4, 0x06, 0xB7, 0xED, 0xEE, 0x38, 0x6B, 0xFB,
-        0x5A, 0x89, 0x9F, 0xA5, 0xAE, 0x9F, 0x24, 0x11, 0x7C, 0x4B,
-        0x1F, 0xE6, 0x49, 0x28, 0x66, 0x51, 0xEC, 0xE6, 0x53, 0x81,
-        0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xC9,
+        0x0F,
+        0xDA,
+        0xA2,
+        0x21,
+        0x68,
+        0xC2,
+        0x34,
+        0xC4,
+        0xC6,
+        0x62,
+        0x8B,
+        0x80,
+        0xDC,
+        0x1C,
+        0xD1,
+        0x29,
+        0x02,
+        0x4E,
+        0x08,
+        0x8A,
+        0x67,
+        0xCC,
+        0x74,
+        0x02,
+        0x0B,
+        0xBE,
+        0xA6,
+        0x3B,
+        0x13,
+        0x9B,
+        0x22,
+        0x51,
+        0x4A,
+        0x08,
+        0x79,
+        0x8E,
+        0x34,
+        0x04,
+        0xDD,
+        0xEF,
+        0x95,
+        0x19,
+        0xB3,
+        0xCD,
+        0x3A,
+        0x43,
+        0x1B,
+        0x30,
+        0x2B,
+        0x0A,
+        0x6D,
+        0xF2,
+        0x5F,
+        0x14,
+        0x37,
+        0x4F,
+        0xE1,
+        0x35,
+        0x6D,
+        0x6D,
+        0x51,
+        0xC2,
+        0x45,
+        0xE4,
+        0x85,
+        0xB5,
+        0x76,
+        0x62,
+        0x5E,
+        0x7E,
+        0xC6,
+        0xF4,
+        0x4C,
+        0x42,
+        0xE9,
+        0xA6,
+        0x37,
+        0xED,
+        0x6B,
+        0x0B,
+        0xFF,
+        0x5C,
+        0xB6,
+        0xF4,
+        0x06,
+        0xB7,
+        0xED,
+        0xEE,
+        0x38,
+        0x6B,
+        0xFB,
+        0x5A,
+        0x89,
+        0x9F,
+        0xA5,
+        0xAE,
+        0x9F,
+        0x24,
+        0x11,
+        0x7C,
+        0x4B,
+        0x1F,
+        0xE6,
+        0x49,
+        0x28,
+        0x66,
+        0x51,
+        0xEC,
+        0xE6,
+        0x53,
+        0x81,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
+        0xFF,
     };
     return BN_bin2bn(RFC2409_PRIME_1024, sizeof(RFC2409_PRIME_1024), bn);
 }
diff --git a/crypto/bn/bn_dh.c b/crypto/bn/bn_dh.c
index 1630be9191..542c33d6a8 100644
--- a/crypto/bn/bn_dh.c
+++ b/crypto/bn/bn_dh.c
@@ -14,7 +14,7 @@
 #include "crypto/bn_dh.h"
 
 #if BN_BITS2 == 64
-#define BN_DEF(lo, hi) (BN_ULONG)hi << 32 | lo
+#define BN_DEF(lo, hi) (BN_ULONG) hi << 32 | lo
 #else
 #define BN_DEF(lo, hi) lo, hi
 #endif
@@ -1387,37 +1387,37 @@ const BIGNUM ossl_bignum_const_2 = {
 };
 
 make_dh_bn(dh1024_160_p)
-make_dh_bn(dh1024_160_q)
-make_dh_bn(dh1024_160_g)
-make_dh_bn(dh2048_224_p)
-make_dh_bn(dh2048_224_q)
-make_dh_bn(dh2048_224_g)
-make_dh_bn(dh2048_256_p)
-make_dh_bn(dh2048_256_q)
-make_dh_bn(dh2048_256_g)
+    make_dh_bn(dh1024_160_q)
+        make_dh_bn(dh1024_160_g)
+            make_dh_bn(dh2048_224_p)
+                make_dh_bn(dh2048_224_q)
+                    make_dh_bn(dh2048_224_g)
+                        make_dh_bn(dh2048_256_p)
+                            make_dh_bn(dh2048_256_q)
+                                make_dh_bn(dh2048_256_g)
 
-make_dh_bn(ffdhe2048_p)
-make_dh_bn(ffdhe2048_q)
-make_dh_bn(ffdhe3072_p)
-make_dh_bn(ffdhe3072_q)
-make_dh_bn(ffdhe4096_p)
-make_dh_bn(ffdhe4096_q)
-make_dh_bn(ffdhe6144_p)
-make_dh_bn(ffdhe6144_q)
-make_dh_bn(ffdhe8192_p)
-make_dh_bn(ffdhe8192_q)
+                                    make_dh_bn(ffdhe2048_p)
+                                        make_dh_bn(ffdhe2048_q)
+                                            make_dh_bn(ffdhe3072_p)
+                                                make_dh_bn(ffdhe3072_q)
+                                                    make_dh_bn(ffdhe4096_p)
+                                                        make_dh_bn(ffdhe4096_q)
+                                                            make_dh_bn(ffdhe6144_p)
+                                                                make_dh_bn(ffdhe6144_q)
+                                                                    make_dh_bn(ffdhe8192_p)
+                                                                        make_dh_bn(ffdhe8192_q)
 
 #ifndef FIPS_MODULE
-make_dh_bn(modp_1536_p)
-make_dh_bn(modp_1536_q)
+                                                                            make_dh_bn(modp_1536_p)
+                                                                                make_dh_bn(modp_1536_q)
 #endif
-make_dh_bn(modp_2048_p)
-make_dh_bn(modp_2048_q)
-make_dh_bn(modp_3072_p)
-make_dh_bn(modp_3072_q)
-make_dh_bn(modp_4096_p)
-make_dh_bn(modp_4096_q)
-make_dh_bn(modp_6144_p)
-make_dh_bn(modp_6144_q)
-make_dh_bn(modp_8192_p)
-make_dh_bn(modp_8192_q)
+                                                                                    make_dh_bn(modp_2048_p)
+                                                                                        make_dh_bn(modp_2048_q)
+                                                                                            make_dh_bn(modp_3072_p)
+                                                                                                make_dh_bn(modp_3072_q)
+                                                                                                    make_dh_bn(modp_4096_p)
+                                                                                                        make_dh_bn(modp_4096_q)
+                                                                                                            make_dh_bn(modp_6144_p)
+                                                                                                                make_dh_bn(modp_6144_q)
+                                                                                                                    make_dh_bn(modp_8192_p)
+                                                                                                                        make_dh_bn(modp_8192_q)
diff --git a/crypto/bn/bn_div.c b/crypto/bn/bn_div.c
index a731b2d37d..fc61d70a9d 100644
--- a/crypto/bn/bn_div.c
+++ b/crypto/bn/bn_div.c
@@ -160,7 +160,7 @@ static int bn_left_align(BIGNUM *num)
 
 #if !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM) \
     && !defined(PEDANTIC) && !defined(BN_DIV3W)
-#if defined(__GNUC__)
+#if defined(__GNUC__) && __GNUC__ >= 2
 #if defined(__i386) || defined(__i386__)
 /*-
  * There were two reasons for implementing this template:
@@ -288,7 +288,7 @@ int bn_div_fixed_top(BIGNUM *dv, BIGNUM *rm, const BIGNUM *num,
         goto err;
 
     /* First we normalise the numbers */
-    if (BN_copy(sdiv, divisor) == NULL)
+    if (!BN_copy(sdiv, divisor))
         goto err;
     norm_shift = bn_left_align(sdiv);
     sdiv->neg = 0;
diff --git a/crypto/bn/bn_exp.c b/crypto/bn/bn_exp.c
index c3bd5e7b5d..a44b2d3712 100644
--- a/crypto/bn/bn_exp.c
+++ b/crypto/bn/bn_exp.c
@@ -29,7 +29,7 @@
 
 #undef SPARC_T4_MONT
 #if defined(OPENSSL_BN_ASM_MONT) && (defined(__sparc__) || defined(__sparc))
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 #define SPARC_T4_MONT
 #endif
 
@@ -206,7 +206,7 @@ int BN_mod_exp_recp(BIGNUM *r, const BIGNUM *a, const BIGNUM *p,
 
     if (m->neg) {
         /* ignore sign of 'm' */
-        if (BN_copy(aa, m) == NULL)
+        if (!BN_copy(aa, m))
             goto err;
         aa->neg = 0;
         if (BN_RECP_CTX_set(&recp, aa, ctx) <= 0)
@@ -772,16 +772,16 @@ int bn_mod_exp_mont_fixed_top(BIGNUM *rr, const BIGNUM *a, const BIGNUM *p,
         typedef int (*bn_pwr5_mont_f)(BN_ULONG *tp, const BN_ULONG *np,
             const BN_ULONG *n0, const void *table,
             int power, int bits);
-        int bn_pwr5_mont_t4_8(BN_ULONG *tp, const BN_ULONG *np,
+        int bn_pwr5_mont_t4_8(BN_ULONG * tp, const BN_ULONG *np,
             const BN_ULONG *n0, const void *table,
             int power, int bits);
-        int bn_pwr5_mont_t4_16(BN_ULONG *tp, const BN_ULONG *np,
+        int bn_pwr5_mont_t4_16(BN_ULONG * tp, const BN_ULONG *np,
             const BN_ULONG *n0, const void *table,
             int power, int bits);
-        int bn_pwr5_mont_t4_24(BN_ULONG *tp, const BN_ULONG *np,
+        int bn_pwr5_mont_t4_24(BN_ULONG * tp, const BN_ULONG *np,
             const BN_ULONG *n0, const void *table,
             int power, int bits);
-        int bn_pwr5_mont_t4_32(BN_ULONG *tp, const BN_ULONG *np,
+        int bn_pwr5_mont_t4_32(BN_ULONG * tp, const BN_ULONG *np,
             const BN_ULONG *n0, const void *table,
             int power, int bits);
         static const bn_pwr5_mont_f pwr5_funcs[4] = {
@@ -793,15 +793,15 @@ int bn_mod_exp_mont_fixed_top(BIGNUM *rr, const BIGNUM *a, const BIGNUM *p,
         typedef int (*bn_mul_mont_f)(BN_ULONG *rp, const BN_ULONG *ap,
             const void *bp, const BN_ULONG *np,
             const BN_ULONG *n0);
-        int bn_mul_mont_t4_8(BN_ULONG *rp, const BN_ULONG *ap, const void *bp,
+        int bn_mul_mont_t4_8(BN_ULONG * rp, const BN_ULONG *ap, const void *bp,
             const BN_ULONG *np, const BN_ULONG *n0);
-        int bn_mul_mont_t4_16(BN_ULONG *rp, const BN_ULONG *ap,
+        int bn_mul_mont_t4_16(BN_ULONG * rp, const BN_ULONG *ap,
             const void *bp, const BN_ULONG *np,
             const BN_ULONG *n0);
-        int bn_mul_mont_t4_24(BN_ULONG *rp, const BN_ULONG *ap,
+        int bn_mul_mont_t4_24(BN_ULONG * rp, const BN_ULONG *ap,
             const void *bp, const BN_ULONG *np,
             const BN_ULONG *n0);
-        int bn_mul_mont_t4_32(BN_ULONG *rp, const BN_ULONG *ap,
+        int bn_mul_mont_t4_32(BN_ULONG * rp, const BN_ULONG *ap,
             const void *bp, const BN_ULONG *np,
             const BN_ULONG *n0);
         static const bn_mul_mont_f mul_funcs[4] = {
@@ -810,20 +810,20 @@ int bn_mod_exp_mont_fixed_top(BIGNUM *rr, const BIGNUM *a, const BIGNUM *p,
         };
         bn_mul_mont_f mul_worker = mul_funcs[top / 16 - 1];
 
-        void bn_mul_mont_vis3(BN_ULONG *rp, const BN_ULONG *ap,
+        void bn_mul_mont_vis3(BN_ULONG * rp, const BN_ULONG *ap,
             const void *bp, const BN_ULONG *np,
             const BN_ULONG *n0, int num);
-        void bn_mul_mont_t4(BN_ULONG *rp, const BN_ULONG *ap,
+        void bn_mul_mont_t4(BN_ULONG * rp, const BN_ULONG *ap,
             const void *bp, const BN_ULONG *np,
             const BN_ULONG *n0, int num);
-        void bn_mul_mont_gather5_t4(BN_ULONG *rp, const BN_ULONG *ap,
+        void bn_mul_mont_gather5_t4(BN_ULONG * rp, const BN_ULONG *ap,
             const void *table, const BN_ULONG *np,
             const BN_ULONG *n0, int num, int power);
         void bn_flip_n_scatter5_t4(const BN_ULONG *inp, size_t num,
             void *table, size_t power);
-        void bn_gather5_t4(BN_ULONG *out, size_t num,
+        void bn_gather5_t4(BN_ULONG * out, size_t num,
             void *table, size_t power);
-        void bn_flip_t4(BN_ULONG *dst, BN_ULONG *src, size_t num);
+        void bn_flip_t4(BN_ULONG * dst, BN_ULONG * src, size_t num);
 
         BN_ULONG *np = mont->N.d, *n0 = mont->n0;
         int stride = 5 * (6 - (top / 16 - 1)); /* multiple of 5, but less
@@ -923,13 +923,13 @@ int bn_mod_exp_mont_fixed_top(BIGNUM *rr, const BIGNUM *a, const BIGNUM *p,
          * Given those inputs, |bn_mul_mont| may not give reduced
          * output, but it will still produce "almost" reduced output.
          */
-        void bn_mul_mont_gather5(BN_ULONG *rp, const BN_ULONG *ap,
+        void bn_mul_mont_gather5(BN_ULONG * rp, const BN_ULONG *ap,
             const void *table, const BN_ULONG *np,
             const BN_ULONG *n0, int num, int power);
         void bn_scatter5(const BN_ULONG *inp, size_t num,
             void *table, size_t power);
-        void bn_gather5(BN_ULONG *out, size_t num, void *table, size_t power);
-        void bn_power5(BN_ULONG *rp, const BN_ULONG *ap,
+        void bn_gather5(BN_ULONG * out, size_t num, void *table, size_t power);
+        void bn_power5(BN_ULONG * rp, const BN_ULONG *ap,
             const void *table, const BN_ULONG *np,
             const BN_ULONG *n0, int num, int power);
         int bn_get_bits5(const BN_ULONG *ap, int off);
diff --git a/crypto/bn/bn_gcd.c b/crypto/bn/bn_gcd.c
index 42d02ef123..59865f9728 100644
--- a/crypto/bn/bn_gcd.c
+++ b/crypto/bn/bn_gcd.c
@@ -167,7 +167,7 @@ static ossl_inline BIGNUM *bn_mod_inverse_no_branch(BIGNUM *in,
     if (BN_is_one(A)) {
         /* Y*a == 1  (mod |n|) */
         if (!Y->neg && BN_ucmp(Y, n) < 0) {
-            if (BN_copy(R, Y) == NULL)
+            if (!BN_copy(R, Y))
                 goto err;
         } else {
             if (!BN_nnmod(R, Y, n, ctx))
@@ -456,7 +456,7 @@ BIGNUM *int_bn_mod_inverse(BIGNUM *in,
                     if (!BN_lshift(tmp, X, 2))
                         goto err;
                 } else if (D->top == 1) {
-                    if (BN_copy(tmp, X) == NULL)
+                    if (!BN_copy(tmp, X))
                         goto err;
                     if (!BN_mul_word(tmp, D->d[0]))
                         goto err;
@@ -492,7 +492,7 @@ BIGNUM *int_bn_mod_inverse(BIGNUM *in,
     if (BN_is_one(A)) {
         /* Y*a == 1  (mod |n|) */
         if (!Y->neg && BN_ucmp(Y, n) < 0) {
-            if (BN_copy(R, Y) == NULL)
+            if (!BN_copy(R, Y))
                 goto err;
         } else {
             if (!BN_nnmod(R, Y, n, ctx))
diff --git a/crypto/bn/bn_gf2m.c b/crypto/bn/bn_gf2m.c
index 81a7fda5b3..7ca6587fb4 100644
--- a/crypto/bn/bn_gf2m.c
+++ b/crypto/bn/bn_gf2m.c
@@ -568,7 +568,7 @@ static int BN_GF2m_mod_inv_vartime(BIGNUM *r, const BIGNUM *a,
     if (BN_is_zero(u))
         goto err;
 
-    if (BN_copy(v, p) == NULL)
+    if (!BN_copy(v, p))
         goto err;
 #if 0
     if (!BN_one(b))
@@ -696,7 +696,7 @@ static int BN_GF2m_mod_inv_vartime(BIGNUM *r, const BIGNUM *a,
     }
 #endif
 
-    if (BN_copy(r, b) == NULL)
+    if (!BN_copy(r, b))
         goto err;
     bn_check_top(r);
     ret = 1;
@@ -881,7 +881,7 @@ int BN_GF2m_mod_exp_arr(BIGNUM *r, const BIGNUM *a, const BIGNUM *b,
                 goto err;
         }
     }
-    if (BN_copy(r, u) == NULL)
+    if (!BN_copy(r, u))
         goto err;
     bn_check_top(r);
     ret = 1;
@@ -1020,7 +1020,7 @@ int BN_GF2m_mod_solve_quad_arr(BIGNUM *r, const BIGNUM *a_, const int p[],
 
     if (p[0] & 0x1) { /* m is odd */
         /* compute half-trace of a */
-        if (BN_copy(z, a) == NULL)
+        if (!BN_copy(z, a))
             goto err;
         for (j = 1; j <= (p[0] - 1) / 2; j++) {
             if (!BN_GF2m_mod_sqr_arr(z, z, p, ctx))
@@ -1045,7 +1045,7 @@ int BN_GF2m_mod_solve_quad_arr(BIGNUM *r, const BIGNUM *a_, const int p[],
             if (!BN_GF2m_mod_arr(rho, rho, p))
                 goto err;
             BN_zero(z);
-            if (BN_copy(w, rho) == NULL)
+            if (!BN_copy(w, rho))
                 goto err;
             for (j = 1; j <= p[0] - 1; j++) {
                 if (!BN_GF2m_mod_sqr_arr(z, z, p, ctx))
@@ -1076,7 +1076,7 @@ int BN_GF2m_mod_solve_quad_arr(BIGNUM *r, const BIGNUM *a_, const int p[],
         goto err;
     }
 
-    if (BN_copy(r, z) == NULL)
+    if (!BN_copy(r, z))
         goto err;
     bn_check_top(r);
 
diff --git a/crypto/bn/bn_kron.c b/crypto/bn/bn_kron.c
index b2dda11cc2..b24bdd1c07 100644
--- a/crypto/bn/bn_kron.c
+++ b/crypto/bn/bn_kron.c
@@ -38,10 +38,10 @@ int BN_kronecker(const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx)
     if (B == NULL)
         goto end;
 
-    err = (BN_copy(A, a) == NULL);
+    err = !BN_copy(A, a);
     if (err)
         goto end;
-    err = (BN_copy(B, b) == NULL);
+    err = !BN_copy(B, b);
     if (err)
         goto end;
 
diff --git a/crypto/bn/bn_lib.c b/crypto/bn/bn_lib.c
index a63e2b9154..618c59cb69 100644
--- a/crypto/bn/bn_lib.c
+++ b/crypto/bn/bn_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -89,6 +89,15 @@ const BIGNUM *BN_value_one(void)
     return &const_one;
 }
 
+/*
+ * Old Visual Studio ARM compiler miscompiles BN_num_bits_word()
+ * https://mta.openssl.org/pipermail/openssl-users/2018-August/008465.html
+ */
+#if defined(_MSC_VER) && defined(_ARM_) && defined(_WIN32_WCE) \
+    && _MSC_VER >= 1400 && _MSC_VER < 1501
+#define MS_BROKEN_BN_num_bits_word
+#pragma optimize("", off)
+#endif
 int BN_num_bits_word(BN_ULONG l)
 {
     BN_ULONG x, mask;
@@ -133,6 +142,9 @@ int BN_num_bits_word(BN_ULONG l)
 
     return bits;
 }
+#ifdef MS_BROKEN_BN_num_bits_word
+#pragma optimize("", on)
+#endif
 
 /*
  * This function still leaks `a->dmax`: it's caller's responsibility to
@@ -310,7 +322,7 @@ BIGNUM *BN_dup(const BIGNUM *a)
     t = BN_get_flags(a, BN_FLG_SECURE) ? BN_secure_new() : BN_new();
     if (t == NULL)
         return NULL;
-    if (BN_copy(t, a) == NULL) {
+    if (!BN_copy(t, a)) {
         BN_free(t);
         return NULL;
     }
@@ -696,37 +708,19 @@ int BN_ucmp(const BIGNUM *a, const BIGNUM *b)
     int i;
     BN_ULONG t1, t2, *ap, *bp;
 
-    /*
-     * As it is a public API function, we should handle NULL parameters in
-     * some way. The function can’t return an error, so let’s define that NULL
-     * is less than any BIGNUM.
-     */
-    if (!ossl_assert(a != NULL && b != NULL))
-        return (b == NULL) - (a == NULL);
-
     ap = a->d;
     bp = b->d;
 
     if (BN_get_flags(a, BN_FLG_CONSTTIME)
-        || BN_get_flags(b, BN_FLG_CONSTTIME)) {
+        && a->top == b->top) {
         int res = 0;
-        int min_top = a->top < b->top ? a->top : b->top;
 
-        for (i = 0; i < min_top; i++) {
+        for (i = 0; i < b->top; i++) {
             res = constant_time_select_int((int)constant_time_lt_bn(ap[i], bp[i]),
                 -1, res);
             res = constant_time_select_int((int)constant_time_lt_bn(bp[i], ap[i]),
                 1, res);
         }
-
-        for (i = min_top; i < a->top; ++i)
-            res = constant_time_select_int((int)constant_time_is_zero_bn(ap[i]),
-                res, 1);
-
-        for (i = min_top; i < b->top; ++i)
-            res = constant_time_select_int((int)constant_time_is_zero_bn(bp[i]),
-                res, -1);
-
         return res;
     }
 
diff --git a/crypto/bn/bn_local.h b/crypto/bn/bn_local.h
index 4602cdcaba..e73cba1733 100644
--- a/crypto/bn/bn_local.h
+++ b/crypto/bn/bn_local.h
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -52,6 +52,12 @@
 #define BN_SOFT_LIMIT (4096 / BN_BYTES)
 #endif
 
+#ifndef OPENSSL_SMALL_FOOTPRINT
+#define BN_MUL_COMBA
+#define BN_SQR_COMBA
+#define BN_RECURSION
+#endif
+
 /*
  * This next option uses the C libraries (2 word)/(1 word) function. If it is
  * not defined, I use my C version (which is slower). The reason for this
@@ -72,7 +78,7 @@
  * 64-bit processor with LP64 ABI
  */
 #ifdef SIXTY_FOUR_BIT_LONG
-typedef unsigned long long BN_ULLONG;
+#define BN_ULLONG unsigned long long
 #define BN_BITS4 32
 #define BN_MASK2 (0xffffffffffffffffL)
 #define BN_MASK2l (0xffffffffL)
@@ -104,9 +110,9 @@ typedef unsigned long long BN_ULLONG;
 #ifdef THIRTY_TWO_BIT
 #ifdef BN_LLONG
 #if defined(_WIN32) && !defined(__GNUC__)
-typedef unsigned __int64 BN_ULLONG;
+#define BN_ULLONG unsigned __int64
 #else
-typedef unsigned long long BN_ULLONG;
+#define BN_ULLONG unsigned long long
 #endif
 #endif
 #define BN_BITS4 16
@@ -379,8 +385,8 @@ struct bn_gencb_st {
 #elif defined(__alpha) && (defined(SIXTY_FOUR_BIT_LONG) || defined(SIXTY_FOUR_BIT))
 #if defined(__DECC)
 #include 
-#define BN_UMULT_HIGH(a, b) (BN_ULONG)asm("umulh %a0,%a1,%v0", (a), (b))
-#elif defined(__GNUC__)
+#define BN_UMULT_HIGH(a, b) (BN_ULONG) asm("umulh %a0,%a1,%v0", (a), (b))
+#elif defined(__GNUC__) && __GNUC__ >= 2
 #define BN_UMULT_HIGH(a, b) ({     \
         register BN_ULONG ret;          \
         asm ("umulh     %1,%2,%0"       \
@@ -389,7 +395,7 @@ struct bn_gencb_st {
         ret; })
 #endif /* compiler */
 #elif defined(_ARCH_PPC64) && defined(SIXTY_FOUR_BIT_LONG)
-#if defined(__GNUC__)
+#if defined(__GNUC__) && __GNUC__ >= 2
 #define BN_UMULT_HIGH(a, b) ({     \
         register BN_ULONG ret;          \
         asm ("mulhdu    %0,%1,%2"       \
@@ -398,7 +404,7 @@ struct bn_gencb_st {
         ret; })
 #endif /* compiler */
 #elif (defined(__x86_64) || defined(__x86_64__)) && (defined(SIXTY_FOUR_BIT_LONG) || defined(SIXTY_FOUR_BIT))
-#if defined(__GNUC__)
+#if defined(__GNUC__) && __GNUC__ >= 2
 #define BN_UMULT_HIGH(a, b) ({     \
         register BN_ULONG ret,discard;  \
         asm ("mulq      %3"             \
@@ -422,7 +428,7 @@ unsigned __int64 _umul128(unsigned __int64 a, unsigned __int64 b,
 #define BN_UMULT_LOHI(low, high, a, b) ((low) = _umul128((a), (b), &(high)))
 #endif
 #elif defined(__mips) && (defined(SIXTY_FOUR_BIT) || defined(SIXTY_FOUR_BIT_LONG))
-#if defined(__GNUC__)
+#if defined(__GNUC__) && __GNUC__ >= 2
 #define BN_UMULT_HIGH(a, b) ({       \
         register BN_ULONG ret;          \
         asm ("dmultu    %1,%2"          \
@@ -435,7 +441,7 @@ unsigned __int64 _umul128(unsigned __int64 a, unsigned __int64 b,
         : "r"(a), "r"(b));
 #endif
 #elif defined(__aarch64__) && defined(SIXTY_FOUR_BIT_LONG)
-#if defined(__GNUC__)
+#if defined(__GNUC__) && __GNUC__ >= 2
 #define BN_UMULT_HIGH(a, b) ({     \
         register BN_ULONG ret;          \
         asm ("umulh     %0,%1,%2"       \
diff --git a/crypto/bn/bn_mod.c b/crypto/bn/bn_mod.c
index 703072bbf2..ae08729545 100644
--- a/crypto/bn/bn_mod.c
+++ b/crypto/bn/bn_mod.c
@@ -11,24 +11,24 @@
 #include "internal/nelem.h"
 #include "bn_local.h"
 
-int BN_nnmod(BIGNUM *r, const BIGNUM *a, const BIGNUM *m, BN_CTX *ctx)
+int BN_nnmod(BIGNUM *r, const BIGNUM *m, const BIGNUM *d, BN_CTX *ctx)
 {
     /*
-     * like BN_mod, but returns non-negative remainder (i.e., 0 <= r < |m|
+     * like BN_mod, but returns non-negative remainder (i.e., 0 <= r < |d|
      * always holds)
      */
 
-    if (r == m) {
+    if (r == d) {
         ERR_raise(ERR_LIB_BN, ERR_R_PASSED_INVALID_ARGUMENT);
         return 0;
     }
 
-    if (!(BN_mod(r, a, m, ctx)))
+    if (!(BN_mod(r, m, d, ctx)))
         return 0;
     if (!r->neg)
         return 1;
-    /* now   -|m| < r < 0,  so we have to set  r := r + |m| */
-    return (m->neg ? BN_sub : BN_add)(r, r, m);
+    /* now   -|d| < r < 0,  so we have to set  r := r + |d| */
+    return (d->neg ? BN_sub : BN_add)(r, r, d);
 }
 
 int BN_mod_add(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, const BIGNUM *m,
diff --git a/crypto/bn/bn_mont.c b/crypto/bn/bn_mont.c
index 0bdfce3c48..384e64c3f8 100644
--- a/crypto/bn/bn_mont.c
+++ b/crypto/bn/bn_mont.c
@@ -8,9 +8,10 @@
  */
 
 /*
- * Details about Montgomery multiplication algorithms can be found in
- * https://www.microsoft.com/en-us/research/wp-content/uploads/1996/01/j37acmon.pdf
- * and https://cetinkayakoc.net/docs/r01.pdf
+ * Details about Montgomery multiplication algorithms can be found at
+ * http://security.ece.orst.edu/publications.html, e.g.
+ * http://security.ece.orst.edu/koc/papers/j37acmon.pdf and
+ * sections 3.8 and 4.2 in http://security.ece.orst.edu/koc/papers/r01rsasw.pdf
  */
 
 #include "internal/cryptlib.h"
@@ -191,7 +192,7 @@ int bn_from_mont_fixed_top(BIGNUM *ret, const BIGNUM *a, BN_MONT_CTX *mont,
     if (t2 == NULL)
         goto err;
 
-    if (BN_copy(t1, a) == NULL)
+    if (!BN_copy(t1, a))
         goto err;
     BN_mask_bits(t1, mont->ri);
 
@@ -269,7 +270,7 @@ int BN_MONT_CTX_set(BN_MONT_CTX *mont, const BIGNUM *mod, BN_CTX *ctx)
     if ((Ri = BN_CTX_get(ctx)) == NULL)
         goto err;
     R = &(mont->RR); /* grab RR as a temp */
-    if (BN_copy(&(mont->N), mod) == NULL)
+    if (!BN_copy(&(mont->N), mod))
         goto err; /* Set N */
     if (BN_get_flags(mod, BN_FLG_CONSTTIME) != 0)
         BN_set_flags(&(mont->N), BN_FLG_CONSTTIME);
@@ -410,11 +411,11 @@ BN_MONT_CTX *BN_MONT_CTX_copy(BN_MONT_CTX *to, BN_MONT_CTX *from)
     if (to == from)
         return to;
 
-    if (BN_copy(&(to->RR), &(from->RR)) == NULL)
+    if (!BN_copy(&(to->RR), &(from->RR)))
         return NULL;
-    if (BN_copy(&(to->N), &(from->N)) == NULL)
+    if (!BN_copy(&(to->N), &(from->N)))
         return NULL;
-    if (BN_copy(&(to->Ni), &(from->Ni)) == NULL)
+    if (!BN_copy(&(to->Ni), &(from->Ni)))
         return NULL;
     to->ri = from->ri;
     to->n0[0] = from->n0[0];
diff --git a/crypto/bn/bn_mul.c b/crypto/bn/bn_mul.c
index aefc335923..ff4bf2ca25 100644
--- a/crypto/bn/bn_mul.c
+++ b/crypto/bn/bn_mul.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2018 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -154,7 +154,7 @@ BN_ULONG bn_sub_part_words(BN_ULONG *r,
 }
 #endif
 
-#ifndef OPENSSL_SMALL_FOOTPRINT
+#ifdef BN_RECURSION
 /*
  * Karatsuba recursive multiplication algorithm (cf. Knuth, The Art of
  * Computer Programming, Vol. 2)
@@ -180,6 +180,13 @@ void bn_mul_recursive(BN_ULONG *r, BN_ULONG *a, BN_ULONG *b, int n2,
     unsigned int neg, zero;
     BN_ULONG ln, lo, *p;
 
+#ifdef BN_MUL_COMBA
+#if 0
+    if (n2 == 4) {
+        bn_mul_comba4(r, a, b);
+        return;
+    }
+#endif
     /*
      * Only call bn_mul_comba 8 if n2 == 8 and the two arrays are complete
      * [steve]
@@ -188,7 +195,7 @@ void bn_mul_recursive(BN_ULONG *r, BN_ULONG *a, BN_ULONG *b, int n2,
         bn_mul_comba8(r, a, b);
         return;
     }
-
+#endif /* BN_MUL_COMBA */
     /* Else do normal multiply */
     if (n2 < BN_MUL_RECURSIVE_SIZE_NORMAL) {
         bn_mul_normal(r, a, n2 + dna, b, n2 + dnb);
@@ -233,6 +240,7 @@ void bn_mul_recursive(BN_ULONG *r, BN_ULONG *a, BN_ULONG *b, int n2,
         break;
     }
 
+#ifdef BN_MUL_COMBA
     if (n == 4 && dna == 0 && dnb == 0) { /* XXX: bn_mul_comba4 could take
                                            * extra args to do this well */
         if (!zero)
@@ -252,7 +260,9 @@ void bn_mul_recursive(BN_ULONG *r, BN_ULONG *a, BN_ULONG *b, int n2,
 
         bn_mul_comba8(r, a, b);
         bn_mul_comba8(&(r[n2]), &(a[n]), &(b[n]));
-    } else {
+    } else
+#endif /* BN_MUL_COMBA */
+    {
         p = &(t[n2 * 2]);
         if (!zero)
             bn_mul_recursive(&(t[n2]), t, &(t[n]), n, 0, 0, p);
@@ -482,7 +492,7 @@ void bn_mul_low_recursive(BN_ULONG *r, BN_ULONG *a, BN_ULONG *b, int n2,
         bn_add_words(&(r[n]), &(r[n]), &(t[n]), n);
     }
 }
-#endif /* OPENSSL_SMALL_FOOTPRINT */
+#endif /* BN_RECURSION */
 
 int BN_mul(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx)
 {
@@ -499,8 +509,10 @@ int bn_mul_fixed_top(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx)
     int ret = 0;
     int top, al, bl;
     BIGNUM *rr;
-#if !defined(OPENSSL_SMALL_FOOTPRINT)
+#if defined(BN_MUL_COMBA) || defined(BN_RECURSION)
     int i;
+#endif
+#ifdef BN_RECURSION
     BIGNUM *t = NULL;
     int j = 0, k;
 #endif
@@ -525,9 +537,10 @@ int bn_mul_fixed_top(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx)
     } else
         rr = r;
 
-#if !defined(OPENSSL_SMALL_FOOTPRINT)
+#if defined(BN_MUL_COMBA) || defined(BN_RECURSION)
     i = al - bl;
-
+#endif
+#ifdef BN_MUL_COMBA
     if (i == 0) {
 #if 0
         if (al == 4) {
@@ -546,7 +559,8 @@ int bn_mul_fixed_top(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx)
             goto end;
         }
     }
-
+#endif /* BN_MUL_COMBA */
+#ifdef BN_RECURSION
     if ((al >= BN_MULL_SIZE_NORMAL) && (bl >= BN_MULL_SIZE_NORMAL)) {
         if (i >= -1 && i <= 1) {
             /*
@@ -584,13 +598,13 @@ int bn_mul_fixed_top(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, BN_CTX *ctx)
             goto end;
         }
     }
-#endif /* OPENSSL_SMALL_FOOTPRINT */
+#endif /* BN_RECURSION */
     if (bn_wexpand(rr, top) == NULL)
         goto err;
     rr->top = top;
     bn_mul_normal(rr->d, a->d, al, b->d, bl);
 
-#if !defined(OPENSSL_SMALL_FOOTPRINT)
+#if defined(BN_MUL_COMBA) || defined(BN_RECURSION)
 end:
 #endif
     rr->neg = a->neg ^ b->neg;
diff --git a/crypto/bn/bn_nist.c b/crypto/bn/bn_nist.c
index b820ef7486..aa084996e4 100644
--- a/crypto/bn/bn_nist.c
+++ b/crypto/bn/bn_nist.c
@@ -281,8 +281,8 @@ static void nist_cp_bn(BN_ULONG *dst, const BN_ULONG *src, int top)
 }
 
 #if BN_BITS2 == 64
-#define bn_cp_64(to, n, from, m) ((to)[n] = ((m) >= 0) ? ((from)[m]) : 0)
-#define bn_64_set_0(to, n) (to)[n] = (BN_ULONG)0
+#define bn_cp_64(to, n, from, m) (to)[n] = (m >= 0) ? ((from)[m]) : 0;
+#define bn_64_set_0(to, n) (to)[n] = (BN_ULONG)0;
 /*
  * two following macros are implemented under assumption that they
  * are called in a sequence with *ascending* n, i.e. as they are...
@@ -309,7 +309,7 @@ static void nist_cp_bn(BN_ULONG *dst, const BN_ULONG *src, int top)
         bn_32_set_0(to, (n) * 2);     \
         bn_32_set_0(to, (n) * 2 + 1); \
     }
-#define bn_cp_32(to, n, from, m) ((to)[n] = ((m) >= 0) ? ((from)[m]) : 0)
+#define bn_cp_32(to, n, from, m) (to)[n] = (m >= 0) ? ((from)[m]) : 0;
 #define bn_32_set_0(to, n) (to)[n] = (BN_ULONG)0;
 #if defined(_WIN32) && !defined(__GNUC__)
 #define NIST_INT64 __int64
@@ -340,11 +340,11 @@ static ossl_inline void store_lo32(void *ptr, NIST_INT64 val)
 }
 #endif /* NIST_INT64 */
 
-#define nist_set_192(to, from, a1, a2, a3) \
-    {                                      \
-        bn_cp_64(to, 0, from, (a3) - 3);   \
-        bn_cp_64(to, 1, from, (a2) - 3);   \
-        bn_cp_64(to, 2, from, (a1) - 3);   \
+#define nist_set_192(to, from, a1, a2, a3)      \
+    {                                           \
+        bn_cp_64(to, 0, from, (a3) - 3)         \
+            bn_cp_64(to, 1, from, (a2) - 3)     \
+                bn_cp_64(to, 2, from, (a1) - 3) \
     }
 
 int BN_nist_mod_192(BIGNUM *r, const BIGNUM *a, const BIGNUM *field,
@@ -471,15 +471,15 @@ int BN_nist_mod_192(BIGNUM *r, const BIGNUM *a, const BIGNUM *field,
 typedef BN_ULONG (*bn_addsub_f)(BN_ULONG *, const BN_ULONG *,
     const BN_ULONG *, int);
 
-#define nist_set_224(to, from, a1, a2, a3, a4, a5, a6, a7) \
-    {                                                      \
-        bn_cp_32(to, 0, from, (a7) - 7);                   \
-        bn_cp_32(to, 1, from, (a6) - 7);                   \
-        bn_cp_32(to, 2, from, (a5) - 7);                   \
-        bn_cp_32(to, 3, from, (a4) - 7);                   \
-        bn_cp_32(to, 4, from, (a3) - 7);                   \
-        bn_cp_32(to, 5, from, (a2) - 7);                   \
-        bn_cp_32(to, 6, from, (a1) - 7);                   \
+#define nist_set_224(to, from, a1, a2, a3, a4, a5, a6, a7)      \
+    {                                                           \
+        bn_cp_32(to, 0, from, (a7) - 7)                         \
+            bn_cp_32(to, 1, from, (a6) - 7)                     \
+                bn_cp_32(to, 2, from, (a5) - 7)                 \
+                    bn_cp_32(to, 3, from, (a4) - 7)             \
+                        bn_cp_32(to, 4, from, (a3) - 7)         \
+                            bn_cp_32(to, 5, from, (a2) - 7)     \
+                                bn_cp_32(to, 6, from, (a1) - 7) \
     }
 
 int BN_nist_mod_224(BIGNUM *r, const BIGNUM *a, const BIGNUM *field,
@@ -585,6 +585,9 @@ int BN_nist_mod_224(BIGNUM *r, const BIGNUM *a, const BIGNUM *field,
         rp[6] = (unsigned int)acc;
 
         carry = (int)(acc >> 32);
+#if BN_BITS2 == 64
+        rp[7] = carry;
+#endif
     }
 #else
     {
@@ -636,16 +639,16 @@ int BN_nist_mod_224(BIGNUM *r, const BIGNUM *a, const BIGNUM *field,
     return 1;
 }
 
-#define nist_set_256(to, from, a1, a2, a3, a4, a5, a6, a7, a8) \
-    {                                                          \
-        bn_cp_32(to, 0, from, (a8) - 8);                       \
-        bn_cp_32(to, 1, from, (a7) - 8);                       \
-        bn_cp_32(to, 2, from, (a6) - 8);                       \
-        bn_cp_32(to, 3, from, (a5) - 8);                       \
-        bn_cp_32(to, 4, from, (a4) - 8);                       \
-        bn_cp_32(to, 5, from, (a3) - 8);                       \
-        bn_cp_32(to, 6, from, (a2) - 8);                       \
-        bn_cp_32(to, 7, from, (a1) - 8);                       \
+#define nist_set_256(to, from, a1, a2, a3, a4, a5, a6, a7, a8)      \
+    {                                                               \
+        bn_cp_32(to, 0, from, (a8) - 8)                             \
+            bn_cp_32(to, 1, from, (a7) - 8)                         \
+                bn_cp_32(to, 2, from, (a6) - 8)                     \
+                    bn_cp_32(to, 3, from, (a5) - 8)                 \
+                        bn_cp_32(to, 4, from, (a4) - 8)             \
+                            bn_cp_32(to, 5, from, (a3) - 8)         \
+                                bn_cp_32(to, 6, from, (a2) - 8)     \
+                                    bn_cp_32(to, 7, from, (a1) - 8) \
     }
 
 int BN_nist_mod_256(BIGNUM *r, const BIGNUM *a, const BIGNUM *field,
@@ -865,20 +868,20 @@ int BN_nist_mod_256(BIGNUM *r, const BIGNUM *a, const BIGNUM *field,
     return 1;
 }
 
-#define nist_set_384(to, from, a1, a2, a3, a4, a5, a6, a7, a8, a9, a10, a11, a12) \
-    {                                                                             \
-        bn_cp_32(to, 0, from, (a12) - 12);                                        \
-        bn_cp_32(to, 1, from, (a11) - 12);                                        \
-        bn_cp_32(to, 2, from, (a10) - 12);                                        \
-        bn_cp_32(to, 3, from, (a9) - 12);                                         \
-        bn_cp_32(to, 4, from, (a8) - 12);                                         \
-        bn_cp_32(to, 5, from, (a7) - 12);                                         \
-        bn_cp_32(to, 6, from, (a6) - 12);                                         \
-        bn_cp_32(to, 7, from, (a5) - 12);                                         \
-        bn_cp_32(to, 8, from, (a4) - 12);                                         \
-        bn_cp_32(to, 9, from, (a3) - 12);                                         \
-        bn_cp_32(to, 10, from, (a2) - 12);                                        \
-        bn_cp_32(to, 11, from, (a1) - 12);                                        \
+#define nist_set_384(to, from, a1, a2, a3, a4, a5, a6, a7, a8, a9, a10, a11, a12)     \
+    {                                                                                 \
+        bn_cp_32(to, 0, from, (a12) - 12)                                             \
+            bn_cp_32(to, 1, from, (a11) - 12)                                         \
+                bn_cp_32(to, 2, from, (a10) - 12)                                     \
+                    bn_cp_32(to, 3, from, (a9) - 12)                                  \
+                        bn_cp_32(to, 4, from, (a8) - 12)                              \
+                            bn_cp_32(to, 5, from, (a7) - 12)                          \
+                                bn_cp_32(to, 6, from, (a6) - 12)                      \
+                                    bn_cp_32(to, 7, from, (a5) - 12)                  \
+                                        bn_cp_32(to, 8, from, (a4) - 12)              \
+                                            bn_cp_32(to, 9, from, (a3) - 12)          \
+                                                bn_cp_32(to, 10, from, (a2) - 12)     \
+                                                    bn_cp_32(to, 11, from, (a1) - 12) \
     }
 
 int BN_nist_mod_384(BIGNUM *r, const BIGNUM *a, const BIGNUM *field,
diff --git a/crypto/bn/bn_ppc.c b/crypto/bn/bn_ppc.c
index f7e2568ab7..049ffa50da 100644
--- a/crypto/bn/bn_ppc.c
+++ b/crypto/bn/bn_ppc.c
@@ -9,20 +9,20 @@
 
 #include 
 #include 
-#include "arch/ppc_arch.h"
+#include "crypto/ppc_arch.h"
 #include "bn_local.h"
 
 int bn_mul_mont(BN_ULONG *rp, const BN_ULONG *ap, const BN_ULONG *bp,
     const BN_ULONG *np, const BN_ULONG *n0, int num)
 {
-    int bn_mul_mont_int(BN_ULONG *rp, const BN_ULONG *ap, const BN_ULONG *bp,
+    int bn_mul_mont_int(BN_ULONG * rp, const BN_ULONG *ap, const BN_ULONG *bp,
         const BN_ULONG *np, const BN_ULONG *n0, int num);
-    int bn_mul4x_mont_int(BN_ULONG *rp, const BN_ULONG *ap, const BN_ULONG *bp,
+    int bn_mul4x_mont_int(BN_ULONG * rp, const BN_ULONG *ap, const BN_ULONG *bp,
         const BN_ULONG *np, const BN_ULONG *n0, int num);
-    int bn_mul_mont_fixed_n6(BN_ULONG *rp, const BN_ULONG *ap,
+    int bn_mul_mont_fixed_n6(BN_ULONG * rp, const BN_ULONG *ap,
         const BN_ULONG *bp, const BN_ULONG *np,
         const BN_ULONG *n0, int num);
-    int bn_mul_mont_300_fixed_n6(BN_ULONG *rp, const BN_ULONG *ap,
+    int bn_mul_mont_300_fixed_n6(BN_ULONG * rp, const BN_ULONG *ap,
         const BN_ULONG *bp, const BN_ULONG *np,
         const BN_ULONG *n0, int num);
 
diff --git a/crypto/bn/bn_prime.c b/crypto/bn/bn_prime.c
index 33a9fc8d67..6e911b4cbf 100644
--- a/crypto/bn/bn_prime.c
+++ b/crypto/bn/bn_prime.c
@@ -30,7 +30,7 @@ static int bn_is_prime_int(const BIGNUM *w, int checks, BN_CTX *ctx,
 #define square(x) ((BN_ULONG)(x) * (BN_ULONG)(x))
 
 #if BN_BITS2 == 64
-#define BN_DEF(lo, hi) (BN_ULONG)hi << 32 | lo
+#define BN_DEF(lo, hi) (BN_ULONG) hi << 32 | lo
 #else
 #define BN_DEF(lo, hi) lo, hi
 #endif
@@ -420,7 +420,7 @@ int ossl_bn_miller_rabin_is_prime(const BIGNUM *w, int iterations, BN_CTX *ctx,
         /* (Step 4.7) for j = 1 to a-1 */
         for (j = 1; j < a; ++j) {
             /* (Step 4.7.1 - 4.7.2) x = z. z = x^2 mod w */
-            if (BN_copy(x, z) == NULL || !BN_mod_mul(z, x, x, w, ctx))
+            if (!BN_copy(x, z) || !BN_mod_mul(z, x, x, w, ctx))
                 goto err;
             /* (Step 4.7.3) */
             if (BN_cmp(z, w1) == 0)
@@ -431,13 +431,13 @@ int ossl_bn_miller_rabin_is_prime(const BIGNUM *w, int iterations, BN_CTX *ctx,
         }
         /* At this point z = b^((w-1)/2) mod w */
         /* (Steps 4.8 - 4.9) x = z, z = x^2 mod w */
-        if (BN_copy(x, z) == NULL || !BN_mod_mul(z, x, x, w, ctx))
+        if (!BN_copy(x, z) || !BN_mod_mul(z, x, x, w, ctx))
             goto err;
         /* (Step 4.10) */
         if (BN_is_one(z))
             goto composite;
         /* (Step 4.11) x = b^(w-1) mod w */
-        if (BN_copy(x, z) == NULL)
+        if (!BN_copy(x, z))
             goto err;
     composite:
         if (enhanced) {
diff --git a/crypto/bn/bn_prime.h b/crypto/bn/bn_prime.h
index 4038d99b6a..8a859ac02e 100644
--- a/crypto/bn/bn_prime.h
+++ b/crypto/bn/bn_prime.h
@@ -2,7 +2,7 @@
  * WARNING: do not edit!
  * Generated by crypto/bn/bn_prime.pl
  *
- * Copyright 1998-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1998-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -10,10 +10,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_BN_BN_PRIME_H)
-#define OSSL_LIBCRYPTO_BN_BN_PRIME_H
-
-/* clang-format off */
 typedef unsigned short prime_t;
 # define NUMPRIMES 2048
 
@@ -275,6 +271,3 @@ static const prime_t primes[2048] = {
     17707, 17713, 17729, 17737, 17747, 17749, 17761, 17783,
     17789, 17791, 17807, 17827, 17837, 17839, 17851, 17863,
 };
-/* clang-format on */
-
-#endif /* !defined(OSSL_LIBCRYPTO_BN_BN_PRIME_H) */
diff --git a/crypto/bn/bn_prime.pl b/crypto/bn/bn_prime.pl
index 3d9722d008..a7a764627b 100644
--- a/crypto/bn/bn_prime.pl
+++ b/crypto/bn/bn_prime.pl
@@ -25,10 +25,6 @@ print <<"EOF";
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_BN_BN_PRIME_H)
-#define OSSL_LIBCRYPTO_BN_BN_PRIME_H
-
-/* clang-format off */
 EOF
 
 
@@ -54,5 +50,3 @@ for (my $i = 0; $i <= $#primes; $i++) {
     printf " %5d,", $primes[$i];
 }
 print "\n};\n";
-print "/* clang-format on */\n";
-print "\n#endif /* !defined(OSSL_LIBCRYPTO_BN_BN_PRIME_H) */\n"
diff --git a/crypto/bn/bn_recp.c b/crypto/bn/bn_recp.c
index ab546ce9eb..26fb737e25 100644
--- a/crypto/bn/bn_recp.c
+++ b/crypto/bn/bn_recp.c
@@ -42,7 +42,7 @@ void BN_RECP_CTX_free(BN_RECP_CTX *recp)
 
 int BN_RECP_CTX_set(BN_RECP_CTX *recp, const BIGNUM *d, BN_CTX *ctx)
 {
-    if (BN_is_zero(d) || BN_copy(&(recp->N), d) == NULL)
+    if (BN_is_zero(d) || !BN_copy(&(recp->N), d))
         return 0;
     BN_zero(&(recp->Nr));
     recp->num_bits = BN_num_bits(d);
@@ -95,7 +95,7 @@ int BN_div_recp(BIGNUM *dv, BIGNUM *rem, const BIGNUM *m,
 
     if (BN_ucmp(m, &(recp->N)) < 0) {
         BN_zero(d);
-        if (BN_copy(r, m) == NULL) {
+        if (!BN_copy(r, m)) {
             BN_CTX_end(ctx);
             return 0;
         }
diff --git a/crypto/bn/bn_rsa_fips186_5.c b/crypto/bn/bn_rsa_fips186_5.c
index 635f013f73..d483ba3ae5 100644
--- a/crypto/bn/bn_rsa_fips186_5.c
+++ b/crypto/bn/bn_rsa_fips186_5.c
@@ -29,7 +29,7 @@
 #include "internal/nelem.h"
 
 #if BN_BITS2 == 64
-#define BN_DEF(lo, hi) (BN_ULONG)hi << 32 | lo
+#define BN_DEF(lo, hi) (BN_ULONG) hi << 32 | lo
 #else
 #define BN_DEF(lo, hi) lo, hi
 #endif
diff --git a/crypto/bn/bn_s390x.c b/crypto/bn/bn_s390x.c
index 4e7aba35f6..599f4eba58 100644
--- a/crypto/bn/bn_s390x.c
+++ b/crypto/bn/bn_s390x.c
@@ -8,7 +8,7 @@
  */
 
 #include "crypto/bn.h"
-#include "arch/s390x_arch.h"
+#include "crypto/s390x_arch.h"
 
 #ifdef S390X_MOD_EXP
 
@@ -20,20 +20,16 @@
 #include 
 #include 
 
-/*
- * Returns 1 for success, 0 for failure, and -1 to tell the caller to use the
- * SW-fallback.
- */
 static int s390x_mod_exp_hw(BIGNUM *r, const BIGNUM *a, const BIGNUM *p,
     const BIGNUM *m)
 {
     struct ica_rsa_modexpo me;
     unsigned char *buffer;
     size_t size;
-    int res = -1;
+    int res = 0;
 
     if (OPENSSL_s390xcex == -1 || OPENSSL_s390xcex_nodev)
-        return -1;
+        return 0;
     size = BN_num_bytes(m);
     buffer = OPENSSL_calloc(size, 4);
     if (buffer == NULL)
@@ -46,15 +42,11 @@ static int s390x_mod_exp_hw(BIGNUM *r, const BIGNUM *a, const BIGNUM *p,
     me.n_modulus = buffer + 3 * size;
     if (BN_bn2binpad(a, me.inputdata, size) == -1
         || BN_bn2binpad(p, me.b_key, size) == -1
-        || BN_bn2binpad(m, me.n_modulus, size) == -1) {
-        res = 0;
+        || BN_bn2binpad(m, me.n_modulus, size) == -1)
         goto dealloc;
-    }
     if (ioctl(OPENSSL_s390xcex, ICARSAMODEXPO, &me) != -1) {
         if (BN_bin2bn(me.outputdata, size, r) != NULL)
             res = 1;
-        else
-            res = 0;
     } else if (errno == EBADF || errno == ENOTTY) {
         /*
          * In this cases, someone (e.g. a sandbox) closed the fd.
@@ -79,34 +71,27 @@ dealloc:
 int s390x_mod_exp(BIGNUM *r, const BIGNUM *a, const BIGNUM *p,
     const BIGNUM *m, BN_CTX *ctx, BN_MONT_CTX *m_ctx)
 {
-    int rc;
-
-    rc = s390x_mod_exp_hw(r, a, p, m);
-    if (rc < 0)
-        return BN_mod_exp_mont(r, a, p, m, ctx, m_ctx);
-    return rc;
+    if (s390x_mod_exp_hw(r, a, p, m) == 1)
+        return 1;
+    return BN_mod_exp_mont(r, a, p, m, ctx, m_ctx);
 }
 
-/*
- * Returns 1 for success, 0 for failure, and -1 to tell the caller to use the
- * SW-fallback.
- */
 int s390x_crt(BIGNUM *r, const BIGNUM *i, const BIGNUM *p, const BIGNUM *q,
     const BIGNUM *dmp, const BIGNUM *dmq, const BIGNUM *iqmp)
 {
     struct ica_rsa_modexpo_crt crt;
     unsigned char *buffer, *part;
     size_t size, plen, qlen;
-    int res = -1;
+    int res = 0;
 
     if (OPENSSL_s390xcex == -1 || OPENSSL_s390xcex_nodev)
-        return -1;
+        return 0;
     /*-
      * Hardware-accelerated CRT can only deal with p>q.  Fall back to
      * software in the (hopefully rare) other cases.
      */
     if (BN_ucmp(p, q) != 1)
-        return -1;
+        return 0;
     plen = BN_num_bytes(p);
     qlen = BN_num_bytes(q);
     size = (plen > qlen ? plen : qlen);
@@ -134,15 +119,11 @@ int s390x_crt(BIGNUM *r, const BIGNUM *i, const BIGNUM *p, const BIGNUM *q,
         || BN_bn2binpad(q, crt.nq_prime, size) == -1
         || BN_bn2binpad(dmp, crt.bp_key, size + 8) == -1
         || BN_bn2binpad(dmq, crt.bq_key, size) == -1
-        || BN_bn2binpad(iqmp, crt.u_mult_inv, size + 8) == -1) {
-        res = 0;
+        || BN_bn2binpad(iqmp, crt.u_mult_inv, size + 8) == -1)
         goto dealloc;
-    }
     if (ioctl(OPENSSL_s390xcex, ICARSACRT, &crt) != -1) {
         if (BN_bin2bn(crt.outputdata, crt.outputdatalength, r) != NULL)
             res = 1;
-        else
-            res = 0;
     } else if (errno == EBADF || errno == ENOTTY) {
         /*
          * In this cases, someone (e.g. a sandbox) closed the fd.
diff --git a/crypto/bn/bn_sparc.c b/crypto/bn/bn_sparc.c
index 1dedbdf26f..a236e42dfa 100644
--- a/crypto/bn/bn_sparc.c
+++ b/crypto/bn/bn_sparc.c
@@ -10,17 +10,17 @@
 #include 
 #include 
 #include "internal/cryptlib.h"
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 #include "bn_local.h" /* for definition of bn_mul_mont */
 
 int bn_mul_mont(BN_ULONG *rp, const BN_ULONG *ap, const BN_ULONG *bp,
     const BN_ULONG *np, const BN_ULONG *n0, int num)
 {
-    int bn_mul_mont_vis3(BN_ULONG *rp, const BN_ULONG *ap, const BN_ULONG *bp,
+    int bn_mul_mont_vis3(BN_ULONG * rp, const BN_ULONG *ap, const BN_ULONG *bp,
         const BN_ULONG *np, const BN_ULONG *n0, int num);
-    int bn_mul_mont_fpu(BN_ULONG *rp, const BN_ULONG *ap, const BN_ULONG *bp,
+    int bn_mul_mont_fpu(BN_ULONG * rp, const BN_ULONG *ap, const BN_ULONG *bp,
         const BN_ULONG *np, const BN_ULONG *n0, int num);
-    int bn_mul_mont_int(BN_ULONG *rp, const BN_ULONG *ap, const BN_ULONG *bp,
+    int bn_mul_mont_int(BN_ULONG * rp, const BN_ULONG *ap, const BN_ULONG *bp,
         const BN_ULONG *np, const BN_ULONG *n0, int num);
 
     if (!(num & 1) && num >= 6) {
@@ -29,16 +29,16 @@ int bn_mul_mont(BN_ULONG *rp, const BN_ULONG *ap, const BN_ULONG *bp,
                 const BN_ULONG *bp,
                 const BN_ULONG *np,
                 const BN_ULONG *n0);
-            int bn_mul_mont_t4_8(BN_ULONG *rp, const BN_ULONG *ap,
+            int bn_mul_mont_t4_8(BN_ULONG * rp, const BN_ULONG *ap,
                 const BN_ULONG *bp, const BN_ULONG *np,
                 const BN_ULONG *n0);
-            int bn_mul_mont_t4_16(BN_ULONG *rp, const BN_ULONG *ap,
+            int bn_mul_mont_t4_16(BN_ULONG * rp, const BN_ULONG *ap,
                 const BN_ULONG *bp, const BN_ULONG *np,
                 const BN_ULONG *n0);
-            int bn_mul_mont_t4_24(BN_ULONG *rp, const BN_ULONG *ap,
+            int bn_mul_mont_t4_24(BN_ULONG * rp, const BN_ULONG *ap,
                 const BN_ULONG *bp, const BN_ULONG *np,
                 const BN_ULONG *n0);
-            int bn_mul_mont_t4_32(BN_ULONG *rp, const BN_ULONG *ap,
+            int bn_mul_mont_t4_32(BN_ULONG * rp, const BN_ULONG *ap,
                 const BN_ULONG *bp, const BN_ULONG *np,
                 const BN_ULONG *n0);
             static const bn_mul_mont_f funcs[4] = {
diff --git a/crypto/bn/bn_sqr.c b/crypto/bn/bn_sqr.c
index 807577bae5..34b33a30a3 100644
--- a/crypto/bn/bn_sqr.c
+++ b/crypto/bn/bn_sqr.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2018 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -50,25 +50,21 @@ int bn_sqr_fixed_top(BIGNUM *r, const BIGNUM *a, BN_CTX *ctx)
         goto err;
 
     if (al == 4) {
-#ifdef OPENSSL_SMALL_FOOTPRINT
+#ifndef BN_SQR_COMBA
         BN_ULONG t[8];
         bn_sqr_normal(rr->d, a->d, 4, t);
 #else
         bn_sqr_comba4(rr->d, a->d);
 #endif
     } else if (al == 8) {
-#ifdef OPENSSL_SMALL_FOOTPRINT
+#ifndef BN_SQR_COMBA
         BN_ULONG t[16];
         bn_sqr_normal(rr->d, a->d, 8, t);
 #else
         bn_sqr_comba8(rr->d, a->d);
 #endif
     } else {
-#ifdef OPENSSL_SMALL_FOOTPRINT
-        if (bn_wexpand(tmp, max) == NULL)
-            goto err;
-        bn_sqr_normal(rr->d, a->d, al, tmp->d);
-#else
+#if defined(BN_RECURSION)
         if (al < BN_SQR_RECURSIVE_SIZE_NORMAL) {
             BN_ULONG t[BN_SQR_RECURSIVE_SIZE_NORMAL * 2];
             bn_sqr_normal(rr->d, a->d, al, t);
@@ -88,6 +84,10 @@ int bn_sqr_fixed_top(BIGNUM *r, const BIGNUM *a, BN_CTX *ctx)
                 bn_sqr_normal(rr->d, a->d, al, tmp->d);
             }
         }
+#else
+        if (bn_wexpand(tmp, max) == NULL)
+            goto err;
+        bn_sqr_normal(rr->d, a->d, al, tmp->d);
 #endif
     }
 
@@ -141,7 +141,7 @@ void bn_sqr_normal(BN_ULONG *r, const BN_ULONG *a, int n, BN_ULONG *tmp)
     bn_add_words(r, r, tmp, max);
 }
 
-#ifndef OPENSSL_SMALL_FOOTPRINT
+#ifdef BN_RECURSION
 /*-
  * r is 2*n words in size,
  * a and b are both n words in size.    (There's not actually a 'b' here ...)
@@ -160,10 +160,18 @@ void bn_sqr_recursive(BN_ULONG *r, const BN_ULONG *a, int n2, BN_ULONG *t)
     BN_ULONG ln, lo, *p;
 
     if (n2 == 4) {
+#ifndef BN_SQR_COMBA
+        bn_sqr_normal(r, a, 4, t);
+#else
         bn_sqr_comba4(r, a);
+#endif
         return;
     } else if (n2 == 8) {
+#ifndef BN_SQR_COMBA
+        bn_sqr_normal(r, a, 8, t);
+#else
         bn_sqr_comba8(r, a);
+#endif
         return;
     }
     if (n2 < BN_SQR_RECURSIVE_SIZE_NORMAL) {
diff --git a/crypto/bn/bn_sqrt.c b/crypto/bn/bn_sqrt.c
index 2f2d9e446f..4b4bc7d5d1 100644
--- a/crypto/bn/bn_sqrt.c
+++ b/crypto/bn/bn_sqrt.c
@@ -160,7 +160,7 @@ BIGNUM *BN_mod_sqrt(BIGNUM *in, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx)
         if (!BN_mod_mul(x, x, t, p, ctx))
             goto end;
 
-        if (BN_copy(ret, x) == NULL)
+        if (!BN_copy(ret, x))
             goto end;
         err = 0;
         goto vrfy;
@@ -170,7 +170,7 @@ BIGNUM *BN_mod_sqrt(BIGNUM *in, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx)
      * e > 2, so we really have to use the Tonelli/Shanks algorithm. First,
      * find some y that is not a square.
      */
-    if (BN_copy(q, p) == NULL)
+    if (!BN_copy(q, p))
         goto end; /* use 'q' as temp */
     q->neg = 0;
     i = 2;
@@ -297,7 +297,7 @@ BIGNUM *BN_mod_sqrt(BIGNUM *in, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx)
          */
 
         if (BN_is_one(b)) {
-            if (BN_copy(ret, x) == NULL)
+            if (!BN_copy(ret, x))
                 goto end;
             err = 0;
             goto vrfy;
@@ -323,7 +323,7 @@ BIGNUM *BN_mod_sqrt(BIGNUM *in, const BIGNUM *a, const BIGNUM *p, BN_CTX *ctx)
         }
 
         /* t := y^2^(e - i - 1) */
-        if (BN_copy(t, y) == NULL)
+        if (!BN_copy(t, y))
             goto end;
         for (j = e - i - 1; j > 0; j--) {
             if (!BN_mod_sqr(t, t, p, ctx))
diff --git a/crypto/bn/bn_x931p.c b/crypto/bn/bn_x931p.c
index 67d0431cc5..2a86f7391b 100644
--- a/crypto/bn/bn_x931p.c
+++ b/crypto/bn/bn_x931p.c
@@ -24,7 +24,7 @@ static int bn_x931_derive_pi(BIGNUM *pi, const BIGNUM *Xpi, BN_CTX *ctx,
     BN_GENCB *cb)
 {
     int i = 0, is_prime;
-    if (BN_copy(pi, Xpi) == NULL)
+    if (!BN_copy(pi, Xpi))
         return 0;
     if (!BN_is_odd(pi) && !BN_add_word(pi, 1))
         return 0;
@@ -121,7 +121,7 @@ int BN_X931_derive_prime_ex(BIGNUM *p, BIGNUM *p1, BIGNUM *p2,
     for (;;) {
         int i = 1;
         BN_GENCB_call(cb, 0, i++);
-        if (BN_copy(pm1, p) == NULL)
+        if (!BN_copy(pm1, p))
             goto err;
         if (!BN_sub_word(pm1, 1))
             goto err;
diff --git a/crypto/bsearch.c b/crypto/bsearch.c
index 201bc6e5f3..192ccbeb91 100644
--- a/crypto/bsearch.c
+++ b/crypto/bsearch.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -10,10 +10,8 @@
 #include 
 #include "internal/cryptlib.h"
 
-typedef int (*cmpthunk_fn)(const void *, const void *);
 const void *ossl_bsearch(const void *key, const void *base, int num,
     int size, int (*cmp)(const void *, const void *),
-    int (*cmp_thunk)(cmpthunk_fn real_cmp_fn, const void *, const void *),
     int flags)
 {
     const char *base_ = base;
@@ -25,12 +23,9 @@ const void *ossl_bsearch(const void *key, const void *base, int num,
     l = 0;
     h = num;
     while (l < h) {
-        i = l + (h - l) / 2;
+        i = (l + h) / 2;
         p = &(base_[i * size]);
-        if (cmp_thunk != NULL)
-            c = cmp_thunk((cmpthunk_fn)cmp, key, (const void *)p);
-        else
-            c = cmp(key, p);
+        c = (*cmp)(key, p);
         if (c < 0)
             h = i;
         else if (c > 0)
@@ -41,16 +36,8 @@ const void *ossl_bsearch(const void *key, const void *base, int num,
     if (c != 0 && !(flags & OSSL_BSEARCH_VALUE_ON_NOMATCH))
         p = NULL;
     else if (c == 0 && (flags & OSSL_BSEARCH_FIRST_VALUE_ON_MATCH)) {
-        while (i > 0) {
-            if (cmp_thunk != NULL) {
-                if (cmp_thunk((cmpthunk_fn)cmp, key, (const void *)&(base_[(i - 1) * size])))
-                    break;
-            } else {
-                if (cmp(key, &(base_[(i - 1) * size])))
-                    break;
-            }
+        while (i > 0 && (*cmp)(key, &(base_[(i - 1) * size])) == 0)
             i--;
-        }
         p = &(base_[i * size]);
     }
     return p;
diff --git a/crypto/build.info b/crypto/build.info
index 4e9068407c..a6801047c8 100644
--- a/crypto/build.info
+++ b/crypto/build.info
@@ -16,6 +16,7 @@ IF[{- !$disabled{uplink} -}]
   $UPLINKSRC_common=../ms/uplink.c
   $UPLINKSRC_x86=$UPLINKSRC_common uplink-x86.S
   $UPLINKSRC_x86_64=$UPLINKSRC_common uplink-x86_64.s
+  $UPLINKSRC_ia64=$UPLINKSRC_common uplink-ia64.s
 
   IF[$UPLINKSRC_{- $target{uplink_arch} -}]
     $UPLINKSRC=$UPLINKSRC_{- $target{uplink_arch} -}
@@ -66,6 +67,7 @@ ENDIF
 # provider module that uses it.  ctype.c is included here because the CPUID
 # uses functions from there to parse magic environment variables.
 $CPUID_COMMON=$CPUIDASM cpuid.c ctype.c
+INCLUDE[cpuid.o]=..
 
 SOURCE[../libcrypto]=$CPUID_COMMON
 DEFINE[../libcrypto]=$CPUIDDEF
@@ -117,6 +119,7 @@ GENERATE[buildinf.h]=../util/mkbuildinf.pl "$(CC) $(LIB_CFLAGS) $(CPPFLAGS_Q)" "
 
 GENERATE[uplink-x86.S]=../ms/uplink-x86.pl
 GENERATE[uplink-x86_64.s]=../ms/uplink-x86_64.pl
+GENERATE[uplink-ia64.s]=../ms/uplink-ia64.pl
 
 GENERATE[x86cpuid.S]=x86cpuid.pl
 DEPEND[x86cpuid.s]=perlasm/x86asm.pl
diff --git a/crypto/camellia/asm/cmll-x86.pl b/crypto/camellia/asm/cmll-x86.pl
index 4db2911b07..195d4cd54b 100644
--- a/crypto/camellia/asm/cmll-x86.pl
+++ b/crypto/camellia/asm/cmll-x86.pl
@@ -1,5 +1,5 @@
 #! /usr/bin/env perl
-# Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved.
+# Copyright 2008-2025 The OpenSSL Project Authors. All Rights Reserved.
 #
 # Licensed under the Apache License 2.0 (the "License").  You may not use
 # this file except in compliance with the License.  You can obtain a copy
@@ -549,7 +549,7 @@ my $bias=int(@T[0])?shift(@T):0;
 }
 
 # void Camellia_Ekeygen(
-#		int keyBitLength,
+#		const int keyBitLength,
 #		const Byte *rawKey,
 #		KEY_TABLE_TYPE keyTable)
 &function_begin("Camellia_Ekeygen");
@@ -807,7 +807,7 @@ for ($i=0;$i<256;$i++) { &data_word(&S0222($i),&S3033($i)); }
 
 # void Camellia_cbc_encrypt (const void char *inp, unsigned char *out,
 #			size_t length, const CAMELLIA_KEY *key,
-#			unsigned char *ivp, int enc);
+#			unsigned char *ivp,const int enc);
 {
 # stack frame layout
 #             -4(%esp)		# return address	 0(%esp)
diff --git a/crypto/camellia/asm/cmllt4-sparcv9.pl b/crypto/camellia/asm/cmllt4-sparcv9.pl
index c1299397e3..86e38d65c4 100644
--- a/crypto/camellia/asm/cmllt4-sparcv9.pl
+++ b/crypto/camellia/asm/cmllt4-sparcv9.pl
@@ -69,7 +69,7 @@ $code=<<___;
 #ifndef __ASSEMBLER__
 # define __ASSEMBLER__ 1
 #endif
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 .text
 
diff --git a/crypto/camellia/camellia.c b/crypto/camellia/camellia.c
index 8841baa7a5..cd9521a019 100644
--- a/crypto/camellia/camellia.c
+++ b/crypto/camellia/camellia.c
@@ -53,15 +53,15 @@
 #define RightRotate(x, s) (((x) >> (s)) + ((x) << (32 - s)))
 #define LeftRotate(x, s) (((x) << (s)) + ((x) >> (32 - s)))
 
-#define GETU32(p) (((uint32_t)(p)[0] << 24) ^ ((uint32_t)(p)[1] << 16) ^ ((uint32_t)(p)[2] << 8) ^ ((uint32_t)(p)[3]))
-#define PUTU32(p, v) ((p)[0] = (uint8_t)((v) >> 24), (p)[1] = (uint8_t)((v) >> 16), (p)[2] = (uint8_t)((v) >> 8), (p)[3] = (uint8_t)(v))
+#define GETU32(p) (((u32)(p)[0] << 24) ^ ((u32)(p)[1] << 16) ^ ((u32)(p)[2] << 8) ^ ((u32)(p)[3]))
+#define PUTU32(p, v) ((p)[0] = (u8)((v) >> 24), (p)[1] = (u8)((v) >> 16), (p)[2] = (u8)((v) >> 8), (p)[3] = (u8)(v))
 
 /* S-box data */
 #define SBOX1_1110 Camellia_SBOX[0]
 #define SBOX4_4404 Camellia_SBOX[1]
 #define SBOX2_0222 Camellia_SBOX[2]
 #define SBOX3_3033 Camellia_SBOX[3]
-static const uint32_t Camellia_SBOX[][256] = {
+static const u32 Camellia_SBOX[][256] = {
     { 0x70707000, 0x82828200, 0x2c2c2c00, 0xececec00, 0xb3b3b300, 0x27272700,
         0xc0c0c000, 0xe5e5e500, 0xe4e4e400, 0x85858500, 0x57575700, 0x35353500,
         0xeaeaea00, 0x0c0c0c00, 0xaeaeae00, 0x41414100, 0x23232300, 0xefefef00,
@@ -237,7 +237,7 @@ static const uint32_t Camellia_SBOX[][256] = {
 };
 
 /* Key generation constants */
-static const uint32_t SIGMA[] = {
+static const u32 SIGMA[] = {
     0xa09e667f, 0x3bcc908b, 0xb67ae858, 0x4caa73b2, 0xc6ef372f, 0xe94f82be,
     0x54ff53a5, 0xf1d36f1c, 0x10e527fa, 0xde682d1d, 0xb05688c2, 0xb3e6c1fd
 };
@@ -252,7 +252,7 @@ static const uint32_t SIGMA[] = {
  */
 #define Camellia_Feistel(_s0, _s1, _s2, _s3, _key) \
     do {                                           \
-        register uint32_t _t0, _t1, _t2, _t3;      \
+        register u32 _t0, _t1, _t2, _t3;           \
                                                    \
         _t0 = _s0 ^ (_key)[0];                     \
         _t3 = SBOX4_4404[_t0 & 0xff];              \
@@ -278,16 +278,16 @@ static const uint32_t SIGMA[] = {
  */
 #define RotLeft128(_s0, _s1, _s2, _s3, _n)      \
     do {                                        \
-        uint32_t _t0 = _s0 >> (32 - _n);        \
+        u32 _t0 = _s0 >> (32 - _n);             \
         _s0 = (_s0 << _n) | (_s1 >> (32 - _n)); \
         _s1 = (_s1 << _n) | (_s2 >> (32 - _n)); \
         _s2 = (_s2 << _n) | (_s3 >> (32 - _n)); \
         _s3 = (_s3 << _n) | _t0;                \
     } while (0)
 
-int Camellia_Ekeygen(int keyBitLength, const uint8_t *rawKey, KEY_TABLE_TYPE k)
+int Camellia_Ekeygen(int keyBitLength, const u8 *rawKey, KEY_TABLE_TYPE k)
 {
-    register uint32_t s0, s1, s2, s3;
+    register u32 s0, s1, s2, s3;
 
     k[0] = s0 = GETU32(rawKey);
     k[1] = s1 = GETU32(rawKey + 4);
@@ -402,12 +402,12 @@ int Camellia_Ekeygen(int keyBitLength, const uint8_t *rawKey, KEY_TABLE_TYPE k)
      */
 }
 
-void Camellia_EncryptBlock_Rounds(int grandRounds, const uint8_t plaintext[],
+void Camellia_EncryptBlock_Rounds(int grandRounds, const u8 plaintext[],
     const KEY_TABLE_TYPE keyTable,
-    uint8_t ciphertext[])
+    u8 ciphertext[])
 {
-    register uint32_t s0, s1, s2, s3;
-    const uint32_t *k = keyTable, *kend = keyTable + grandRounds * 16;
+    register u32 s0, s1, s2, s3;
+    const u32 *k = keyTable, *kend = keyTable + grandRounds * 16;
 
     s0 = GETU32(plaintext) ^ k[0];
     s1 = GETU32(plaintext + 4) ^ k[1];
@@ -448,19 +448,19 @@ void Camellia_EncryptBlock_Rounds(int grandRounds, const uint8_t plaintext[],
     PUTU32(ciphertext + 12, s1);
 }
 
-void Camellia_EncryptBlock(int keyBitLength, const uint8_t plaintext[],
-    const KEY_TABLE_TYPE keyTable, uint8_t ciphertext[])
+void Camellia_EncryptBlock(int keyBitLength, const u8 plaintext[],
+    const KEY_TABLE_TYPE keyTable, u8 ciphertext[])
 {
     Camellia_EncryptBlock_Rounds(keyBitLength == 128 ? 3 : 4,
         plaintext, keyTable, ciphertext);
 }
 
-void Camellia_DecryptBlock_Rounds(int grandRounds, const uint8_t ciphertext[],
+void Camellia_DecryptBlock_Rounds(int grandRounds, const u8 ciphertext[],
     const KEY_TABLE_TYPE keyTable,
-    uint8_t plaintext[])
+    u8 plaintext[])
 {
-    uint32_t s0, s1, s2, s3;
-    const uint32_t *k = keyTable + grandRounds * 16, *kend = keyTable + 4;
+    u32 s0, s1, s2, s3;
+    const u32 *k = keyTable + grandRounds * 16, *kend = keyTable + 4;
 
     s0 = GETU32(ciphertext) ^ k[0];
     s1 = GETU32(ciphertext + 4) ^ k[1];
@@ -501,8 +501,8 @@ void Camellia_DecryptBlock_Rounds(int grandRounds, const uint8_t ciphertext[],
     PUTU32(plaintext + 12, s1);
 }
 
-void Camellia_DecryptBlock(int keyBitLength, const uint8_t ciphertext[],
-    const KEY_TABLE_TYPE keyTable, uint8_t plaintext[])
+void Camellia_DecryptBlock(int keyBitLength, const u8 ciphertext[],
+    const KEY_TABLE_TYPE keyTable, u8 plaintext[])
 {
     Camellia_DecryptBlock_Rounds(keyBitLength == 128 ? 3 : 4,
         ciphertext, keyTable, plaintext);
diff --git a/crypto/camellia/cmll_cbc.c b/crypto/camellia/cmll_cbc.c
index 42324a3d86..51d8310b48 100644
--- a/crypto/camellia/cmll_cbc.c
+++ b/crypto/camellia/cmll_cbc.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -18,7 +18,7 @@
 
 void Camellia_cbc_encrypt(const unsigned char *in, unsigned char *out,
     size_t len, const CAMELLIA_KEY *key,
-    unsigned char *ivec, int enc)
+    unsigned char *ivec, const int enc)
 {
 
     if (enc)
diff --git a/crypto/camellia/cmll_cfb.c b/crypto/camellia/cmll_cfb.c
index 693ff1a6ec..ea4ab67512 100644
--- a/crypto/camellia/cmll_cfb.c
+++ b/crypto/camellia/cmll_cfb.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -24,7 +24,7 @@
 
 void Camellia_cfb128_encrypt(const unsigned char *in, unsigned char *out,
     size_t length, const CAMELLIA_KEY *key,
-    unsigned char *ivec, int *num, int enc)
+    unsigned char *ivec, int *num, const int enc)
 {
 
     CRYPTO_cfb128_encrypt(in, out, length, key, ivec, num, enc,
@@ -34,7 +34,7 @@ void Camellia_cfb128_encrypt(const unsigned char *in, unsigned char *out,
 /* N.B. This expects the input to be packed, MS bit first */
 void Camellia_cfb1_encrypt(const unsigned char *in, unsigned char *out,
     size_t length, const CAMELLIA_KEY *key,
-    unsigned char *ivec, int *num, int enc)
+    unsigned char *ivec, int *num, const int enc)
 {
     CRYPTO_cfb128_1_encrypt(in, out, length, key, ivec, num, enc,
         (block128_f)Camellia_encrypt);
@@ -42,7 +42,7 @@ void Camellia_cfb1_encrypt(const unsigned char *in, unsigned char *out,
 
 void Camellia_cfb8_encrypt(const unsigned char *in, unsigned char *out,
     size_t length, const CAMELLIA_KEY *key,
-    unsigned char *ivec, int *num, int enc)
+    unsigned char *ivec, int *num, const int enc)
 {
     CRYPTO_cfb128_8_encrypt(in, out, length, key, ivec, num, enc,
         (block128_f)Camellia_encrypt);
diff --git a/crypto/camellia/cmll_ecb.c b/crypto/camellia/cmll_ecb.c
index 2b2a02629b..fddf7c7837 100644
--- a/crypto/camellia/cmll_ecb.c
+++ b/crypto/camellia/cmll_ecb.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -17,7 +17,7 @@
 #include "cmll_local.h"
 
 void Camellia_ecb_encrypt(const unsigned char *in, unsigned char *out,
-    const CAMELLIA_KEY *key, int enc)
+    const CAMELLIA_KEY *key, const int enc)
 {
     if (CAMELLIA_ENCRYPT == enc)
         Camellia_encrypt(in, out, key);
diff --git a/crypto/camellia/cmll_local.h b/crypto/camellia/cmll_local.h
index 45b8dc0e2d..f585994ff9 100644
--- a/crypto/camellia/cmll_local.h
+++ b/crypto/camellia/cmll_local.h
@@ -25,19 +25,19 @@
 #ifndef OSSL_CRYPTO_CAMELLIA_CMLL_LOCAL_H
 #define OSSL_CRYPTO_CAMELLIA_CMLL_LOCAL_H
 
-#include 
-#include 
+typedef unsigned int u32;
+typedef unsigned char u8;
 
-int Camellia_Ekeygen(int keyBitLength, const uint8_t *rawKey,
+int Camellia_Ekeygen(int keyBitLength, const u8 *rawKey,
     KEY_TABLE_TYPE keyTable);
-void Camellia_EncryptBlock_Rounds(int grandRounds, const uint8_t plaintext[],
+void Camellia_EncryptBlock_Rounds(int grandRounds, const u8 plaintext[],
     const KEY_TABLE_TYPE keyTable,
-    uint8_t ciphertext[]);
-void Camellia_DecryptBlock_Rounds(int grandRounds, const uint8_t ciphertext[],
+    u8 ciphertext[]);
+void Camellia_DecryptBlock_Rounds(int grandRounds, const u8 ciphertext[],
     const KEY_TABLE_TYPE keyTable,
-    uint8_t plaintext[]);
-void Camellia_EncryptBlock(int keyBitLength, const uint8_t plaintext[],
-    const KEY_TABLE_TYPE keyTable, uint8_t ciphertext[]);
-void Camellia_DecryptBlock(int keyBitLength, const uint8_t ciphertext[],
-    const KEY_TABLE_TYPE keyTable, uint8_t plaintext[]);
+    u8 plaintext[]);
+void Camellia_EncryptBlock(int keyBitLength, const u8 plaintext[],
+    const KEY_TABLE_TYPE keyTable, u8 ciphertext[]);
+void Camellia_DecryptBlock(int keyBitLength, const u8 ciphertext[],
+    const KEY_TABLE_TYPE keyTable, u8 plaintext[]);
 #endif /* #ifndef OSSL_CRYPTO_CAMELLIA_CMLL_LOCAL_H */
diff --git a/crypto/camellia/cmll_misc.c b/crypto/camellia/cmll_misc.c
index 3b89fa2d83..30db3a380c 100644
--- a/crypto/camellia/cmll_misc.c
+++ b/crypto/camellia/cmll_misc.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -17,7 +17,7 @@
 #include 
 #include "cmll_local.h"
 
-int Camellia_set_key(const unsigned char *userKey, int bits,
+int Camellia_set_key(const unsigned char *userKey, const int bits,
     CAMELLIA_KEY *key)
 {
     if (!userKey || !key)
diff --git a/crypto/cast/c_cfb64.c b/crypto/cast/c_cfb64.c
index 477762005f..4170f77a78 100644
--- a/crypto/cast/c_cfb64.c
+++ b/crypto/cast/c_cfb64.c
@@ -27,7 +27,7 @@ void CAST_cfb64_encrypt(const unsigned char *in, unsigned char *out,
     unsigned char *ivec, int *num, int enc)
 {
     register CAST_LONG v0, v1, t;
-    register int n = *num & 0x07;
+    register int n = *num;
     register long l = length;
     CAST_LONG ti[2];
     unsigned char *iv, c, cc;
diff --git a/crypto/cast/c_ofb64.c b/crypto/cast/c_ofb64.c
index c130f9183f..431446ab5f 100644
--- a/crypto/cast/c_ofb64.c
+++ b/crypto/cast/c_ofb64.c
@@ -26,7 +26,7 @@ void CAST_ofb64_encrypt(const unsigned char *in, unsigned char *out,
     unsigned char *ivec, int *num)
 {
     register CAST_LONG v0, v1, t;
-    register int n = *num & 0x07;
+    register int n = *num;
     register long l = length;
     unsigned char d[8];
     register char *dp;
diff --git a/crypto/cast/cast_local.h b/crypto/cast/cast_local.h
index e18a8eee7c..f24b8bccdc 100644
--- a/crypto/cast/cast_local.h
+++ b/crypto/cast/cast_local.h
@@ -6,17 +6,86 @@
  * in the file LICENSE in the source distribution or at
  * https://www.openssl.org/source/license.html
  */
-#if !defined(OSSL_LIBCRYPTO_CAST_CAST_LOCAL_H)
-#define OSSL_LIBCRYPTO_CAST_CAST_LOCAL_H
-
-#include 
-
-#include "internal/common.h"
 
 #ifdef OPENSSL_SYS_WIN32
 #include 
 #endif
 
+/* NOTE - c is not incremented as per n2l */
+#define n2ln(c, l1, l2, n)                           \
+    {                                                \
+        c += n;                                      \
+        l1 = l2 = 0;                                 \
+        switch (n) {                                 \
+        case 8:                                      \
+            l2 = ((unsigned long)(*(--(c))));        \
+        /* fall through */                           \
+        case 7:                                      \
+            l2 |= ((unsigned long)(*(--(c)))) << 8;  \
+        /* fall through */                           \
+        case 6:                                      \
+            l2 |= ((unsigned long)(*(--(c)))) << 16; \
+        /* fall through */                           \
+        case 5:                                      \
+            l2 |= ((unsigned long)(*(--(c)))) << 24; \
+        /* fall through */                           \
+        case 4:                                      \
+            l1 = ((unsigned long)(*(--(c))));        \
+        /* fall through */                           \
+        case 3:                                      \
+            l1 |= ((unsigned long)(*(--(c)))) << 8;  \
+        /* fall through */                           \
+        case 2:                                      \
+            l1 |= ((unsigned long)(*(--(c)))) << 16; \
+        /* fall through */                           \
+        case 1:                                      \
+            l1 |= ((unsigned long)(*(--(c)))) << 24; \
+        }                                            \
+    }
+
+/* NOTE - c is not incremented as per l2n */
+#define l2nn(l1, l2, c, n)                                   \
+    {                                                        \
+        c += n;                                              \
+        switch (n) {                                         \
+        case 8:                                              \
+            *(--(c)) = (unsigned char)(((l2)) & 0xff);       \
+        /* fall through */                                   \
+        case 7:                                              \
+            *(--(c)) = (unsigned char)(((l2) >> 8) & 0xff);  \
+        /* fall through */                                   \
+        case 6:                                              \
+            *(--(c)) = (unsigned char)(((l2) >> 16) & 0xff); \
+        /* fall through */                                   \
+        case 5:                                              \
+            *(--(c)) = (unsigned char)(((l2) >> 24) & 0xff); \
+        /* fall through */                                   \
+        case 4:                                              \
+            *(--(c)) = (unsigned char)(((l1)) & 0xff);       \
+        /* fall through */                                   \
+        case 3:                                              \
+            *(--(c)) = (unsigned char)(((l1) >> 8) & 0xff);  \
+        /* fall through */                                   \
+        case 2:                                              \
+            *(--(c)) = (unsigned char)(((l1) >> 16) & 0xff); \
+        /* fall through */                                   \
+        case 1:                                              \
+            *(--(c)) = (unsigned char)(((l1) >> 24) & 0xff); \
+        }                                                    \
+    }
+
+#undef n2l
+#define n2l(c, l) (l = ((unsigned long)(*((c)++))) << 24L, \
+    l |= ((unsigned long)(*((c)++))) << 16L,               \
+    l |= ((unsigned long)(*((c)++))) << 8L,                \
+    l |= ((unsigned long)(*((c)++))))
+
+#undef l2n
+#define l2n(l, c) (*((c)++) = (unsigned char)(((l) >> 24L) & 0xff), \
+    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff),                \
+    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff),                 \
+    *((c)++) = (unsigned char)(((l)) & 0xff))
+
 #if defined(OPENSSL_SYS_WIN32) && defined(_MSC_VER)
 #define ROTL(a, n) (_lrotl(a, n))
 #else
@@ -97,5 +166,3 @@ extern const CAST_LONG CAST_S_table4[256];
 extern const CAST_LONG CAST_S_table5[256];
 extern const CAST_LONG CAST_S_table6[256];
 extern const CAST_LONG CAST_S_table7[256];
-
-#endif /* !defined(OSSL_LIBCRYPTO_CAST_CAST_LOCAL_H) */
diff --git a/crypto/cast/cast_s.h b/crypto/cast/cast_s.h
index eb4159d615..345b4dd731 100644
--- a/crypto/cast/cast_s.h
+++ b/crypto/cast/cast_s.h
@@ -7,289 +7,2074 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_CAST_CAST_S_H)
-#define OSSL_LIBCRYPTO_CAST_CAST_S_H
-
-#include 
-
 const CAST_LONG CAST_S_table0[256] = {
-    0x30fb40d4, 0x9fa0ff0b, 0x6beccd2f, 0x3f258c7a, 0x1e213f2f, 0x9c004dd3, 0x6003e540, 0xcf9fc949,
-    0xbfd4af27, 0x88bbbdb5, 0xe2034090, 0x98d09675, 0x6e63a0e0, 0x15c361d2, 0xc2e7661d, 0x22d4ff8e,
-    0x28683b6f, 0xc07fd059, 0xff2379c8, 0x775f50e2, 0x43c340d3, 0xdf2f8656, 0x887ca41a, 0xa2d2bd2d,
-    0xa1c9e0d6, 0x346c4819, 0x61b76d87, 0x22540f2f, 0x2abe32e1, 0xaa54166b, 0x22568e3a, 0xa2d341d0,
-    0x66db40c8, 0xa784392f, 0x004dff2f, 0x2db9d2de, 0x97943fac, 0x4a97c1d8, 0x527644b7, 0xb5f437a7,
-    0xb82cbaef, 0xd751d159, 0x6ff7f0ed, 0x5a097a1f, 0x827b68d0, 0x90ecf52e, 0x22b0c054, 0xbc8e5935,
-    0x4b6d2f7f, 0x50bb64a2, 0xd2664910, 0xbee5812d, 0xb7332290, 0xe93b159f, 0xb48ee411, 0x4bff345d,
-    0xfd45c240, 0xad31973f, 0xc4f6d02e, 0x55fc8165, 0xd5b1caad, 0xa1ac2dae, 0xa2d4b76d, 0xc19b0c50,
-    0x882240f2, 0x0c6e4f38, 0xa4e4bfd7, 0x4f5ba272, 0x564c1d2f, 0xc59c5319, 0xb949e354, 0xb04669fe,
-    0xb1b6ab8a, 0xc71358dd, 0x6385c545, 0x110f935d, 0x57538ad5, 0x6a390493, 0xe63d37e0, 0x2a54f6b3,
-    0x3a787d5f, 0x6276a0b5, 0x19a6fcdf, 0x7a42206a, 0x29f9d4d5, 0xf61b1891, 0xbb72275e, 0xaa508167,
-    0x38901091, 0xc6b505eb, 0x84c7cb8c, 0x2ad75a0f, 0x874a1427, 0xa2d1936b, 0x2ad286af, 0xaa56d291,
-    0xd7894360, 0x425c750d, 0x93b39e26, 0x187184c9, 0x6c00b32d, 0x73e2bb14, 0xa0bebc3c, 0x54623779,
-    0x64459eab, 0x3f328b82, 0x7718cf82, 0x59a2cea6, 0x04ee002e, 0x89fe78e6, 0x3fab0950, 0x325ff6c2,
-    0x81383f05, 0x6963c5c8, 0x76cb5ad6, 0xd49974c9, 0xca180dcf, 0x380782d5, 0xc7fa5cf6, 0x8ac31511,
-    0x35e79e13, 0x47da91d0, 0xf40f9086, 0xa7e2419e, 0x31366241, 0x051ef495, 0xaa573b04, 0x4a805d8d,
-    0x548300d0, 0x00322a3c, 0xbf64cddf, 0xba57a68e, 0x75c6372b, 0x50afd341, 0xa7c13275, 0x915a0bf5,
-    0x6b54bfab, 0x2b0b1426, 0xab4cc9d7, 0x449ccd82, 0xf7fbf265, 0xab85c5f3, 0x1b55db94, 0xaad4e324,
-    0xcfa4bd3f, 0x2deaa3e2, 0x9e204d02, 0xc8bd25ac, 0xeadf55b3, 0xd5bd9e98, 0xe31231b2, 0x2ad5ad6c,
-    0x954329de, 0xadbe4528, 0xd8710f69, 0xaa51c90f, 0xaa786bf6, 0x22513f1e, 0xaa51a79b, 0x2ad344cc,
-    0x7b5a41f0, 0xd37cfbad, 0x1b069505, 0x41ece491, 0xb4c332e6, 0x032268d4, 0xc9600acc, 0xce387e6d,
-    0xbf6bb16c, 0x6a70fb78, 0x0d03d9c9, 0xd4df39de, 0xe01063da, 0x4736f464, 0x5ad328d8, 0xb347cc96,
-    0x75bb0fc3, 0x98511bfb, 0x4ffbcc35, 0xb58bcf6a, 0xe11f0abc, 0xbfc5fe4a, 0xa70aec10, 0xac39570a,
-    0x3f04442f, 0x6188b153, 0xe0397a2e, 0x5727cb79, 0x9ceb418f, 0x1cacd68d, 0x2ad37c96, 0x0175cb9d,
-    0xc69dff09, 0xc75b65f0, 0xd9db40d8, 0xec0e7779, 0x4744ead4, 0xb11c3274, 0xdd24cb9e, 0x7e1c54bd,
-    0xf01144f9, 0xd2240eb1, 0x9675b3fd, 0xa3ac3755, 0xd47c27af, 0x51c85f4d, 0x56907596, 0xa5bb15e6,
-    0x580304f0, 0xca042cf1, 0x011a37ea, 0x8dbfaadb, 0x35ba3e4a, 0x3526ffa0, 0xc37b4d09, 0xbc306ed9,
-    0x98a52666, 0x5648f725, 0xff5e569d, 0x0ced63d0, 0x7c63b2cf, 0x700b45e1, 0xd5ea50f1, 0x85a92872,
-    0xaf1fbda7, 0xd4234870, 0xa7870bf3, 0x2d3b4d79, 0x42e04198, 0x0cd0ede7, 0x26470db8, 0xf881814c,
-    0x474d6ad7, 0x7c0c5e5c, 0xd1231959, 0x381b7298, 0xf5d2f4db, 0xab838653, 0x6e2f1e23, 0x83719c9e,
-    0xbd91e046, 0x9a56456e, 0xdc39200c, 0x20c8c571, 0x962bda1c, 0xe1e696ff, 0xb141ab08, 0x7cca89b9,
-    0x1a69e783, 0x02cc4843, 0xa2f7c579, 0x429ef47d, 0x427b169c, 0x5ac9f049, 0xdd8f0f00, 0x5c8165bf
+    0x30fb40d4,
+    0x9fa0ff0b,
+    0x6beccd2f,
+    0x3f258c7a,
+    0x1e213f2f,
+    0x9c004dd3,
+    0x6003e540,
+    0xcf9fc949,
+    0xbfd4af27,
+    0x88bbbdb5,
+    0xe2034090,
+    0x98d09675,
+    0x6e63a0e0,
+    0x15c361d2,
+    0xc2e7661d,
+    0x22d4ff8e,
+    0x28683b6f,
+    0xc07fd059,
+    0xff2379c8,
+    0x775f50e2,
+    0x43c340d3,
+    0xdf2f8656,
+    0x887ca41a,
+    0xa2d2bd2d,
+    0xa1c9e0d6,
+    0x346c4819,
+    0x61b76d87,
+    0x22540f2f,
+    0x2abe32e1,
+    0xaa54166b,
+    0x22568e3a,
+    0xa2d341d0,
+    0x66db40c8,
+    0xa784392f,
+    0x004dff2f,
+    0x2db9d2de,
+    0x97943fac,
+    0x4a97c1d8,
+    0x527644b7,
+    0xb5f437a7,
+    0xb82cbaef,
+    0xd751d159,
+    0x6ff7f0ed,
+    0x5a097a1f,
+    0x827b68d0,
+    0x90ecf52e,
+    0x22b0c054,
+    0xbc8e5935,
+    0x4b6d2f7f,
+    0x50bb64a2,
+    0xd2664910,
+    0xbee5812d,
+    0xb7332290,
+    0xe93b159f,
+    0xb48ee411,
+    0x4bff345d,
+    0xfd45c240,
+    0xad31973f,
+    0xc4f6d02e,
+    0x55fc8165,
+    0xd5b1caad,
+    0xa1ac2dae,
+    0xa2d4b76d,
+    0xc19b0c50,
+    0x882240f2,
+    0x0c6e4f38,
+    0xa4e4bfd7,
+    0x4f5ba272,
+    0x564c1d2f,
+    0xc59c5319,
+    0xb949e354,
+    0xb04669fe,
+    0xb1b6ab8a,
+    0xc71358dd,
+    0x6385c545,
+    0x110f935d,
+    0x57538ad5,
+    0x6a390493,
+    0xe63d37e0,
+    0x2a54f6b3,
+    0x3a787d5f,
+    0x6276a0b5,
+    0x19a6fcdf,
+    0x7a42206a,
+    0x29f9d4d5,
+    0xf61b1891,
+    0xbb72275e,
+    0xaa508167,
+    0x38901091,
+    0xc6b505eb,
+    0x84c7cb8c,
+    0x2ad75a0f,
+    0x874a1427,
+    0xa2d1936b,
+    0x2ad286af,
+    0xaa56d291,
+    0xd7894360,
+    0x425c750d,
+    0x93b39e26,
+    0x187184c9,
+    0x6c00b32d,
+    0x73e2bb14,
+    0xa0bebc3c,
+    0x54623779,
+    0x64459eab,
+    0x3f328b82,
+    0x7718cf82,
+    0x59a2cea6,
+    0x04ee002e,
+    0x89fe78e6,
+    0x3fab0950,
+    0x325ff6c2,
+    0x81383f05,
+    0x6963c5c8,
+    0x76cb5ad6,
+    0xd49974c9,
+    0xca180dcf,
+    0x380782d5,
+    0xc7fa5cf6,
+    0x8ac31511,
+    0x35e79e13,
+    0x47da91d0,
+    0xf40f9086,
+    0xa7e2419e,
+    0x31366241,
+    0x051ef495,
+    0xaa573b04,
+    0x4a805d8d,
+    0x548300d0,
+    0x00322a3c,
+    0xbf64cddf,
+    0xba57a68e,
+    0x75c6372b,
+    0x50afd341,
+    0xa7c13275,
+    0x915a0bf5,
+    0x6b54bfab,
+    0x2b0b1426,
+    0xab4cc9d7,
+    0x449ccd82,
+    0xf7fbf265,
+    0xab85c5f3,
+    0x1b55db94,
+    0xaad4e324,
+    0xcfa4bd3f,
+    0x2deaa3e2,
+    0x9e204d02,
+    0xc8bd25ac,
+    0xeadf55b3,
+    0xd5bd9e98,
+    0xe31231b2,
+    0x2ad5ad6c,
+    0x954329de,
+    0xadbe4528,
+    0xd8710f69,
+    0xaa51c90f,
+    0xaa786bf6,
+    0x22513f1e,
+    0xaa51a79b,
+    0x2ad344cc,
+    0x7b5a41f0,
+    0xd37cfbad,
+    0x1b069505,
+    0x41ece491,
+    0xb4c332e6,
+    0x032268d4,
+    0xc9600acc,
+    0xce387e6d,
+    0xbf6bb16c,
+    0x6a70fb78,
+    0x0d03d9c9,
+    0xd4df39de,
+    0xe01063da,
+    0x4736f464,
+    0x5ad328d8,
+    0xb347cc96,
+    0x75bb0fc3,
+    0x98511bfb,
+    0x4ffbcc35,
+    0xb58bcf6a,
+    0xe11f0abc,
+    0xbfc5fe4a,
+    0xa70aec10,
+    0xac39570a,
+    0x3f04442f,
+    0x6188b153,
+    0xe0397a2e,
+    0x5727cb79,
+    0x9ceb418f,
+    0x1cacd68d,
+    0x2ad37c96,
+    0x0175cb9d,
+    0xc69dff09,
+    0xc75b65f0,
+    0xd9db40d8,
+    0xec0e7779,
+    0x4744ead4,
+    0xb11c3274,
+    0xdd24cb9e,
+    0x7e1c54bd,
+    0xf01144f9,
+    0xd2240eb1,
+    0x9675b3fd,
+    0xa3ac3755,
+    0xd47c27af,
+    0x51c85f4d,
+    0x56907596,
+    0xa5bb15e6,
+    0x580304f0,
+    0xca042cf1,
+    0x011a37ea,
+    0x8dbfaadb,
+    0x35ba3e4a,
+    0x3526ffa0,
+    0xc37b4d09,
+    0xbc306ed9,
+    0x98a52666,
+    0x5648f725,
+    0xff5e569d,
+    0x0ced63d0,
+    0x7c63b2cf,
+    0x700b45e1,
+    0xd5ea50f1,
+    0x85a92872,
+    0xaf1fbda7,
+    0xd4234870,
+    0xa7870bf3,
+    0x2d3b4d79,
+    0x42e04198,
+    0x0cd0ede7,
+    0x26470db8,
+    0xf881814c,
+    0x474d6ad7,
+    0x7c0c5e5c,
+    0xd1231959,
+    0x381b7298,
+    0xf5d2f4db,
+    0xab838653,
+    0x6e2f1e23,
+    0x83719c9e,
+    0xbd91e046,
+    0x9a56456e,
+    0xdc39200c,
+    0x20c8c571,
+    0x962bda1c,
+    0xe1e696ff,
+    0xb141ab08,
+    0x7cca89b9,
+    0x1a69e783,
+    0x02cc4843,
+    0xa2f7c579,
+    0x429ef47d,
+    0x427b169c,
+    0x5ac9f049,
+    0xdd8f0f00,
+    0x5c8165bf,
 };
 
 const CAST_LONG CAST_S_table1[256] = {
-    0x1f201094, 0xef0ba75b, 0x69e3cf7e, 0x393f4380, 0xfe61cf7a, 0xeec5207a, 0x55889c94, 0x72fc0651,
-    0xada7ef79, 0x4e1d7235, 0xd55a63ce, 0xde0436ba, 0x99c430ef, 0x5f0c0794, 0x18dcdb7d, 0xa1d6eff3,
-    0xa0b52f7b, 0x59e83605, 0xee15b094, 0xe9ffd909, 0xdc440086, 0xef944459, 0xba83ccb3, 0xe0c3cdfb,
-    0xd1da4181, 0x3b092ab1, 0xf997f1c1, 0xa5e6cf7b, 0x01420ddb, 0xe4e7ef5b, 0x25a1ff41, 0xe180f806,
-    0x1fc41080, 0x179bee7a, 0xd37ac6a9, 0xfe5830a4, 0x98de8b7f, 0x77e83f4e, 0x79929269, 0x24fa9f7b,
-    0xe113c85b, 0xacc40083, 0xd7503525, 0xf7ea615f, 0x62143154, 0x0d554b63, 0x5d681121, 0xc866c359,
-    0x3d63cf73, 0xcee234c0, 0xd4d87e87, 0x5c672b21, 0x071f6181, 0x39f7627f, 0x361e3084, 0xe4eb573b,
-    0x602f64a4, 0xd63acd9c, 0x1bbc4635, 0x9e81032d, 0x2701f50c, 0x99847ab4, 0xa0e3df79, 0xba6cf38c,
-    0x10843094, 0x2537a95e, 0xf46f6ffe, 0xa1ff3b1f, 0x208cfb6a, 0x8f458c74, 0xd9e0a227, 0x4ec73a34,
-    0xfc884f69, 0x3e4de8df, 0xef0e0088, 0x3559648d, 0x8a45388c, 0x1d804366, 0x721d9bfd, 0xa58684bb,
-    0xe8256333, 0x844e8212, 0x128d8098, 0xfed33fb4, 0xce280ae1, 0x27e19ba5, 0xd5a6c252, 0xe49754bd,
-    0xc5d655dd, 0xeb667064, 0x77840b4d, 0xa1b6a801, 0x84db26a9, 0xe0b56714, 0x21f043b7, 0xe5d05860,
-    0x54f03084, 0x066ff472, 0xa31aa153, 0xdadc4755, 0xb5625dbf, 0x68561be6, 0x83ca6b94, 0x2d6ed23b,
-    0xeccf01db, 0xa6d3d0ba, 0xb6803d5c, 0xaf77a709, 0x33b4a34c, 0x397bc8d6, 0x5ee22b95, 0x5f0e5304,
-    0x81ed6f61, 0x20e74364, 0xb45e1378, 0xde18639b, 0x881ca122, 0xb96726d1, 0x8049a7e8, 0x22b7da7b,
-    0x5e552d25, 0x5272d237, 0x79d2951c, 0xc60d894c, 0x488cb402, 0x1ba4fe5b, 0xa4b09f6b, 0x1ca815cf,
-    0xa20c3005, 0x8871df63, 0xb9de2fcb, 0x0cc6c9e9, 0x0beeff53, 0xe3214517, 0xb4542835, 0x9f63293c,
-    0xee41e729, 0x6e1d2d7c, 0x50045286, 0x1e6685f3, 0xf33401c6, 0x30a22c95, 0x31a70850, 0x60930f13,
-    0x73f98417, 0xa1269859, 0xec645c44, 0x52c877a9, 0xcdff33a6, 0xa02b1741, 0x7cbad9a2, 0x2180036f,
-    0x50d99c08, 0xcb3f4861, 0xc26bd765, 0x64a3f6ab, 0x80342676, 0x25a75e7b, 0xe4e6d1fc, 0x20c710e6,
-    0xcdf0b680, 0x17844d3b, 0x31eef84d, 0x7e0824e4, 0x2ccb49eb, 0x846a3bae, 0x8ff77888, 0xee5d60f6,
-    0x7af75673, 0x2fdd5cdb, 0xa11631c1, 0x30f66f43, 0xb3faec54, 0x157fd7fa, 0xef8579cc, 0xd152de58,
-    0xdb2ffd5e, 0x8f32ce19, 0x306af97a, 0x02f03ef8, 0x99319ad5, 0xc242fa0f, 0xa7e3ebb0, 0xc68e4906,
-    0xb8da230c, 0x80823028, 0xdcdef3c8, 0xd35fb171, 0x088a1bc8, 0xbec0c560, 0x61a3c9e8, 0xbca8f54d,
-    0xc72feffa, 0x22822e99, 0x82c570b4, 0xd8d94e89, 0x8b1c34bc, 0x301e16e6, 0x273be979, 0xb0ffeaa6,
-    0x61d9b8c6, 0x00b24869, 0xb7ffce3f, 0x08dc283b, 0x43daf65a, 0xf7e19798, 0x7619b72f, 0x8f1c9ba4,
-    0xdc8637a0, 0x16a7d3b1, 0x9fc393b7, 0xa7136eeb, 0xc6bcc63e, 0x1a513742, 0xef6828bc, 0x520365d6,
-    0x2d6a77ab, 0x3527ed4b, 0x821fd216, 0x095c6e2e, 0xdb92f2fb, 0x5eea29cb, 0x145892f5, 0x91584f7f,
-    0x5483697b, 0x2667a8cc, 0x85196048, 0x8c4bacea, 0x833860d4, 0x0d23e0f9, 0x6c387e8a, 0x0ae6d249,
-    0xb284600c, 0xd835731d, 0xdcb1c647, 0xac4c56ea, 0x3ebd81b3, 0x230eabb0, 0x6438bc87, 0xf0b5b1fa,
-    0x8f5ea2b3, 0xfc184642, 0x0a036b7a, 0x4fb089bd, 0x649da589, 0xa345415e, 0x5c038323, 0x3e5d3bb9,
-    0x43d79572, 0x7e6dd07c, 0x06dfdf1e, 0x6c6cc4ef, 0x7160a539, 0x73bfbe70, 0x83877605, 0x4523ecf1
+    0x1f201094,
+    0xef0ba75b,
+    0x69e3cf7e,
+    0x393f4380,
+    0xfe61cf7a,
+    0xeec5207a,
+    0x55889c94,
+    0x72fc0651,
+    0xada7ef79,
+    0x4e1d7235,
+    0xd55a63ce,
+    0xde0436ba,
+    0x99c430ef,
+    0x5f0c0794,
+    0x18dcdb7d,
+    0xa1d6eff3,
+    0xa0b52f7b,
+    0x59e83605,
+    0xee15b094,
+    0xe9ffd909,
+    0xdc440086,
+    0xef944459,
+    0xba83ccb3,
+    0xe0c3cdfb,
+    0xd1da4181,
+    0x3b092ab1,
+    0xf997f1c1,
+    0xa5e6cf7b,
+    0x01420ddb,
+    0xe4e7ef5b,
+    0x25a1ff41,
+    0xe180f806,
+    0x1fc41080,
+    0x179bee7a,
+    0xd37ac6a9,
+    0xfe5830a4,
+    0x98de8b7f,
+    0x77e83f4e,
+    0x79929269,
+    0x24fa9f7b,
+    0xe113c85b,
+    0xacc40083,
+    0xd7503525,
+    0xf7ea615f,
+    0x62143154,
+    0x0d554b63,
+    0x5d681121,
+    0xc866c359,
+    0x3d63cf73,
+    0xcee234c0,
+    0xd4d87e87,
+    0x5c672b21,
+    0x071f6181,
+    0x39f7627f,
+    0x361e3084,
+    0xe4eb573b,
+    0x602f64a4,
+    0xd63acd9c,
+    0x1bbc4635,
+    0x9e81032d,
+    0x2701f50c,
+    0x99847ab4,
+    0xa0e3df79,
+    0xba6cf38c,
+    0x10843094,
+    0x2537a95e,
+    0xf46f6ffe,
+    0xa1ff3b1f,
+    0x208cfb6a,
+    0x8f458c74,
+    0xd9e0a227,
+    0x4ec73a34,
+    0xfc884f69,
+    0x3e4de8df,
+    0xef0e0088,
+    0x3559648d,
+    0x8a45388c,
+    0x1d804366,
+    0x721d9bfd,
+    0xa58684bb,
+    0xe8256333,
+    0x844e8212,
+    0x128d8098,
+    0xfed33fb4,
+    0xce280ae1,
+    0x27e19ba5,
+    0xd5a6c252,
+    0xe49754bd,
+    0xc5d655dd,
+    0xeb667064,
+    0x77840b4d,
+    0xa1b6a801,
+    0x84db26a9,
+    0xe0b56714,
+    0x21f043b7,
+    0xe5d05860,
+    0x54f03084,
+    0x066ff472,
+    0xa31aa153,
+    0xdadc4755,
+    0xb5625dbf,
+    0x68561be6,
+    0x83ca6b94,
+    0x2d6ed23b,
+    0xeccf01db,
+    0xa6d3d0ba,
+    0xb6803d5c,
+    0xaf77a709,
+    0x33b4a34c,
+    0x397bc8d6,
+    0x5ee22b95,
+    0x5f0e5304,
+    0x81ed6f61,
+    0x20e74364,
+    0xb45e1378,
+    0xde18639b,
+    0x881ca122,
+    0xb96726d1,
+    0x8049a7e8,
+    0x22b7da7b,
+    0x5e552d25,
+    0x5272d237,
+    0x79d2951c,
+    0xc60d894c,
+    0x488cb402,
+    0x1ba4fe5b,
+    0xa4b09f6b,
+    0x1ca815cf,
+    0xa20c3005,
+    0x8871df63,
+    0xb9de2fcb,
+    0x0cc6c9e9,
+    0x0beeff53,
+    0xe3214517,
+    0xb4542835,
+    0x9f63293c,
+    0xee41e729,
+    0x6e1d2d7c,
+    0x50045286,
+    0x1e6685f3,
+    0xf33401c6,
+    0x30a22c95,
+    0x31a70850,
+    0x60930f13,
+    0x73f98417,
+    0xa1269859,
+    0xec645c44,
+    0x52c877a9,
+    0xcdff33a6,
+    0xa02b1741,
+    0x7cbad9a2,
+    0x2180036f,
+    0x50d99c08,
+    0xcb3f4861,
+    0xc26bd765,
+    0x64a3f6ab,
+    0x80342676,
+    0x25a75e7b,
+    0xe4e6d1fc,
+    0x20c710e6,
+    0xcdf0b680,
+    0x17844d3b,
+    0x31eef84d,
+    0x7e0824e4,
+    0x2ccb49eb,
+    0x846a3bae,
+    0x8ff77888,
+    0xee5d60f6,
+    0x7af75673,
+    0x2fdd5cdb,
+    0xa11631c1,
+    0x30f66f43,
+    0xb3faec54,
+    0x157fd7fa,
+    0xef8579cc,
+    0xd152de58,
+    0xdb2ffd5e,
+    0x8f32ce19,
+    0x306af97a,
+    0x02f03ef8,
+    0x99319ad5,
+    0xc242fa0f,
+    0xa7e3ebb0,
+    0xc68e4906,
+    0xb8da230c,
+    0x80823028,
+    0xdcdef3c8,
+    0xd35fb171,
+    0x088a1bc8,
+    0xbec0c560,
+    0x61a3c9e8,
+    0xbca8f54d,
+    0xc72feffa,
+    0x22822e99,
+    0x82c570b4,
+    0xd8d94e89,
+    0x8b1c34bc,
+    0x301e16e6,
+    0x273be979,
+    0xb0ffeaa6,
+    0x61d9b8c6,
+    0x00b24869,
+    0xb7ffce3f,
+    0x08dc283b,
+    0x43daf65a,
+    0xf7e19798,
+    0x7619b72f,
+    0x8f1c9ba4,
+    0xdc8637a0,
+    0x16a7d3b1,
+    0x9fc393b7,
+    0xa7136eeb,
+    0xc6bcc63e,
+    0x1a513742,
+    0xef6828bc,
+    0x520365d6,
+    0x2d6a77ab,
+    0x3527ed4b,
+    0x821fd216,
+    0x095c6e2e,
+    0xdb92f2fb,
+    0x5eea29cb,
+    0x145892f5,
+    0x91584f7f,
+    0x5483697b,
+    0x2667a8cc,
+    0x85196048,
+    0x8c4bacea,
+    0x833860d4,
+    0x0d23e0f9,
+    0x6c387e8a,
+    0x0ae6d249,
+    0xb284600c,
+    0xd835731d,
+    0xdcb1c647,
+    0xac4c56ea,
+    0x3ebd81b3,
+    0x230eabb0,
+    0x6438bc87,
+    0xf0b5b1fa,
+    0x8f5ea2b3,
+    0xfc184642,
+    0x0a036b7a,
+    0x4fb089bd,
+    0x649da589,
+    0xa345415e,
+    0x5c038323,
+    0x3e5d3bb9,
+    0x43d79572,
+    0x7e6dd07c,
+    0x06dfdf1e,
+    0x6c6cc4ef,
+    0x7160a539,
+    0x73bfbe70,
+    0x83877605,
+    0x4523ecf1,
 };
 
 const CAST_LONG CAST_S_table2[256] = {
-    0x8defc240, 0x25fa5d9f, 0xeb903dbf, 0xe810c907, 0x47607fff, 0x369fe44b, 0x8c1fc644, 0xaececa90,
-    0xbeb1f9bf, 0xeefbcaea, 0xe8cf1950, 0x51df07ae, 0x920e8806, 0xf0ad0548, 0xe13c8d83, 0x927010d5,
-    0x11107d9f, 0x07647db9, 0xb2e3e4d4, 0x3d4f285e, 0xb9afa820, 0xfade82e0, 0xa067268b, 0x8272792e,
-    0x553fb2c0, 0x489ae22b, 0xd4ef9794, 0x125e3fbc, 0x21fffcee, 0x825b1bfd, 0x9255c5ed, 0x1257a240,
-    0x4e1a8302, 0xbae07fff, 0x528246e7, 0x8e57140e, 0x3373f7bf, 0x8c9f8188, 0xa6fc4ee8, 0xc982b5a5,
-    0xa8c01db7, 0x579fc264, 0x67094f31, 0xf2bd3f5f, 0x40fff7c1, 0x1fb78dfc, 0x8e6bd2c1, 0x437be59b,
-    0x99b03dbf, 0xb5dbc64b, 0x638dc0e6, 0x55819d99, 0xa197c81c, 0x4a012d6e, 0xc5884a28, 0xccc36f71,
-    0xb843c213, 0x6c0743f1, 0x8309893c, 0x0feddd5f, 0x2f7fe850, 0xd7c07f7e, 0x02507fbf, 0x5afb9a04,
-    0xa747d2d0, 0x1651192e, 0xaf70bf3e, 0x58c31380, 0x5f98302e, 0x727cc3c4, 0x0a0fb402, 0x0f7fef82,
-    0x8c96fdad, 0x5d2c2aae, 0x8ee99a49, 0x50da88b8, 0x8427f4a0, 0x1eac5790, 0x796fb449, 0x8252dc15,
-    0xefbd7d9b, 0xa672597d, 0xada840d8, 0x45f54504, 0xfa5d7403, 0xe83ec305, 0x4f91751a, 0x925669c2,
-    0x23efe941, 0xa903f12e, 0x60270df2, 0x0276e4b6, 0x94fd6574, 0x927985b2, 0x8276dbcb, 0x02778176,
-    0xf8af918d, 0x4e48f79e, 0x8f616ddf, 0xe29d840e, 0x842f7d83, 0x340ce5c8, 0x96bbb682, 0x93b4b148,
-    0xef303cab, 0x984faf28, 0x779faf9b, 0x92dc560d, 0x224d1e20, 0x8437aa88, 0x7d29dc96, 0x2756d3dc,
-    0x8b907cee, 0xb51fd240, 0xe7c07ce3, 0xe566b4a1, 0xc3e9615e, 0x3cf8209d, 0x6094d1e3, 0xcd9ca341,
-    0x5c76460e, 0x00ea983b, 0xd4d67881, 0xfd47572c, 0xf76cedd9, 0xbda8229c, 0x127dadaa, 0x438a074e,
-    0x1f97c090, 0x081bdb8a, 0x93a07ebe, 0xb938ca15, 0x97b03cff, 0x3dc2c0f8, 0x8d1ab2ec, 0x64380e51,
-    0x68cc7bfb, 0xd90f2788, 0x12490181, 0x5de5ffd4, 0xdd7ef86a, 0x76a2e214, 0xb9a40368, 0x925d958f,
-    0x4b39fffa, 0xba39aee9, 0xa4ffd30b, 0xfaf7933b, 0x6d498623, 0x193cbcfa, 0x27627545, 0x825cf47a,
-    0x61bd8ba0, 0xd11e42d1, 0xcead04f4, 0x127ea392, 0x10428db7, 0x8272a972, 0x9270c4a8, 0x127de50b,
-    0x285ba1c8, 0x3c62f44f, 0x35c0eaa5, 0xe805d231, 0x428929fb, 0xb4fcdf82, 0x4fb66a53, 0x0e7dc15b,
-    0x1f081fab, 0x108618ae, 0xfcfd086d, 0xf9ff2889, 0x694bcc11, 0x236a5cae, 0x12deca4d, 0x2c3f8cc5,
-    0xd2d02dfe, 0xf8ef5896, 0xe4cf52da, 0x95155b67, 0x494a488c, 0xb9b6a80c, 0x5c8f82bc, 0x89d36b45,
-    0x3a609437, 0xec00c9a9, 0x44715253, 0x0a874b49, 0xd773bc40, 0x7c34671c, 0x02717ef6, 0x4feb5536,
-    0xa2d02fff, 0xd2bf60c4, 0xd43f03c0, 0x50b4ef6d, 0x07478cd1, 0x006e1888, 0xa2e53f55, 0xb9e6d4bc,
-    0xa2048016, 0x97573833, 0xd7207d67, 0xde0f8f3d, 0x72f87b33, 0xabcc4f33, 0x7688c55d, 0x7b00a6b0,
-    0x947b0001, 0x570075d2, 0xf9bb88f8, 0x8942019e, 0x4264a5ff, 0x856302e0, 0x72dbd92b, 0xee971b69,
-    0x6ea22fde, 0x5f08ae2b, 0xaf7a616d, 0xe5c98767, 0xcf1febd2, 0x61efc8c2, 0xf1ac2571, 0xcc8239c2,
-    0x67214cb8, 0xb1e583d1, 0xb7dc3e62, 0x7f10bdce, 0xf90a5c38, 0x0ff0443d, 0x606e6dc6, 0x60543a49,
-    0x5727c148, 0x2be98a1d, 0x8ab41738, 0x20e1be24, 0xaf96da0f, 0x68458425, 0x99833be5, 0x600d457d,
-    0x282f9350, 0x8334b362, 0xd91d1120, 0x2b6d8da0, 0x642b1e31, 0x9c305a00, 0x52bce688, 0x1b03588a,
-    0xf7baefd5, 0x4142ed9c, 0xa4315c11, 0x83323ec5, 0xdfef4636, 0xa133c501, 0xe9d3531c, 0xee353783
+    0x8defc240,
+    0x25fa5d9f,
+    0xeb903dbf,
+    0xe810c907,
+    0x47607fff,
+    0x369fe44b,
+    0x8c1fc644,
+    0xaececa90,
+    0xbeb1f9bf,
+    0xeefbcaea,
+    0xe8cf1950,
+    0x51df07ae,
+    0x920e8806,
+    0xf0ad0548,
+    0xe13c8d83,
+    0x927010d5,
+    0x11107d9f,
+    0x07647db9,
+    0xb2e3e4d4,
+    0x3d4f285e,
+    0xb9afa820,
+    0xfade82e0,
+    0xa067268b,
+    0x8272792e,
+    0x553fb2c0,
+    0x489ae22b,
+    0xd4ef9794,
+    0x125e3fbc,
+    0x21fffcee,
+    0x825b1bfd,
+    0x9255c5ed,
+    0x1257a240,
+    0x4e1a8302,
+    0xbae07fff,
+    0x528246e7,
+    0x8e57140e,
+    0x3373f7bf,
+    0x8c9f8188,
+    0xa6fc4ee8,
+    0xc982b5a5,
+    0xa8c01db7,
+    0x579fc264,
+    0x67094f31,
+    0xf2bd3f5f,
+    0x40fff7c1,
+    0x1fb78dfc,
+    0x8e6bd2c1,
+    0x437be59b,
+    0x99b03dbf,
+    0xb5dbc64b,
+    0x638dc0e6,
+    0x55819d99,
+    0xa197c81c,
+    0x4a012d6e,
+    0xc5884a28,
+    0xccc36f71,
+    0xb843c213,
+    0x6c0743f1,
+    0x8309893c,
+    0x0feddd5f,
+    0x2f7fe850,
+    0xd7c07f7e,
+    0x02507fbf,
+    0x5afb9a04,
+    0xa747d2d0,
+    0x1651192e,
+    0xaf70bf3e,
+    0x58c31380,
+    0x5f98302e,
+    0x727cc3c4,
+    0x0a0fb402,
+    0x0f7fef82,
+    0x8c96fdad,
+    0x5d2c2aae,
+    0x8ee99a49,
+    0x50da88b8,
+    0x8427f4a0,
+    0x1eac5790,
+    0x796fb449,
+    0x8252dc15,
+    0xefbd7d9b,
+    0xa672597d,
+    0xada840d8,
+    0x45f54504,
+    0xfa5d7403,
+    0xe83ec305,
+    0x4f91751a,
+    0x925669c2,
+    0x23efe941,
+    0xa903f12e,
+    0x60270df2,
+    0x0276e4b6,
+    0x94fd6574,
+    0x927985b2,
+    0x8276dbcb,
+    0x02778176,
+    0xf8af918d,
+    0x4e48f79e,
+    0x8f616ddf,
+    0xe29d840e,
+    0x842f7d83,
+    0x340ce5c8,
+    0x96bbb682,
+    0x93b4b148,
+    0xef303cab,
+    0x984faf28,
+    0x779faf9b,
+    0x92dc560d,
+    0x224d1e20,
+    0x8437aa88,
+    0x7d29dc96,
+    0x2756d3dc,
+    0x8b907cee,
+    0xb51fd240,
+    0xe7c07ce3,
+    0xe566b4a1,
+    0xc3e9615e,
+    0x3cf8209d,
+    0x6094d1e3,
+    0xcd9ca341,
+    0x5c76460e,
+    0x00ea983b,
+    0xd4d67881,
+    0xfd47572c,
+    0xf76cedd9,
+    0xbda8229c,
+    0x127dadaa,
+    0x438a074e,
+    0x1f97c090,
+    0x081bdb8a,
+    0x93a07ebe,
+    0xb938ca15,
+    0x97b03cff,
+    0x3dc2c0f8,
+    0x8d1ab2ec,
+    0x64380e51,
+    0x68cc7bfb,
+    0xd90f2788,
+    0x12490181,
+    0x5de5ffd4,
+    0xdd7ef86a,
+    0x76a2e214,
+    0xb9a40368,
+    0x925d958f,
+    0x4b39fffa,
+    0xba39aee9,
+    0xa4ffd30b,
+    0xfaf7933b,
+    0x6d498623,
+    0x193cbcfa,
+    0x27627545,
+    0x825cf47a,
+    0x61bd8ba0,
+    0xd11e42d1,
+    0xcead04f4,
+    0x127ea392,
+    0x10428db7,
+    0x8272a972,
+    0x9270c4a8,
+    0x127de50b,
+    0x285ba1c8,
+    0x3c62f44f,
+    0x35c0eaa5,
+    0xe805d231,
+    0x428929fb,
+    0xb4fcdf82,
+    0x4fb66a53,
+    0x0e7dc15b,
+    0x1f081fab,
+    0x108618ae,
+    0xfcfd086d,
+    0xf9ff2889,
+    0x694bcc11,
+    0x236a5cae,
+    0x12deca4d,
+    0x2c3f8cc5,
+    0xd2d02dfe,
+    0xf8ef5896,
+    0xe4cf52da,
+    0x95155b67,
+    0x494a488c,
+    0xb9b6a80c,
+    0x5c8f82bc,
+    0x89d36b45,
+    0x3a609437,
+    0xec00c9a9,
+    0x44715253,
+    0x0a874b49,
+    0xd773bc40,
+    0x7c34671c,
+    0x02717ef6,
+    0x4feb5536,
+    0xa2d02fff,
+    0xd2bf60c4,
+    0xd43f03c0,
+    0x50b4ef6d,
+    0x07478cd1,
+    0x006e1888,
+    0xa2e53f55,
+    0xb9e6d4bc,
+    0xa2048016,
+    0x97573833,
+    0xd7207d67,
+    0xde0f8f3d,
+    0x72f87b33,
+    0xabcc4f33,
+    0x7688c55d,
+    0x7b00a6b0,
+    0x947b0001,
+    0x570075d2,
+    0xf9bb88f8,
+    0x8942019e,
+    0x4264a5ff,
+    0x856302e0,
+    0x72dbd92b,
+    0xee971b69,
+    0x6ea22fde,
+    0x5f08ae2b,
+    0xaf7a616d,
+    0xe5c98767,
+    0xcf1febd2,
+    0x61efc8c2,
+    0xf1ac2571,
+    0xcc8239c2,
+    0x67214cb8,
+    0xb1e583d1,
+    0xb7dc3e62,
+    0x7f10bdce,
+    0xf90a5c38,
+    0x0ff0443d,
+    0x606e6dc6,
+    0x60543a49,
+    0x5727c148,
+    0x2be98a1d,
+    0x8ab41738,
+    0x20e1be24,
+    0xaf96da0f,
+    0x68458425,
+    0x99833be5,
+    0x600d457d,
+    0x282f9350,
+    0x8334b362,
+    0xd91d1120,
+    0x2b6d8da0,
+    0x642b1e31,
+    0x9c305a00,
+    0x52bce688,
+    0x1b03588a,
+    0xf7baefd5,
+    0x4142ed9c,
+    0xa4315c11,
+    0x83323ec5,
+    0xdfef4636,
+    0xa133c501,
+    0xe9d3531c,
+    0xee353783,
 };
 
 const CAST_LONG CAST_S_table3[256] = {
-    0x9db30420, 0x1fb6e9de, 0xa7be7bef, 0xd273a298, 0x4a4f7bdb, 0x64ad8c57, 0x85510443, 0xfa020ed1,
-    0x7e287aff, 0xe60fb663, 0x095f35a1, 0x79ebf120, 0xfd059d43, 0x6497b7b1, 0xf3641f63, 0x241e4adf,
-    0x28147f5f, 0x4fa2b8cd, 0xc9430040, 0x0cc32220, 0xfdd30b30, 0xc0a5374f, 0x1d2d00d9, 0x24147b15,
-    0xee4d111a, 0x0fca5167, 0x71ff904c, 0x2d195ffe, 0x1a05645f, 0x0c13fefe, 0x081b08ca, 0x05170121,
-    0x80530100, 0xe83e5efe, 0xac9af4f8, 0x7fe72701, 0xd2b8ee5f, 0x06df4261, 0xbb9e9b8a, 0x7293ea25,
-    0xce84ffdf, 0xf5718801, 0x3dd64b04, 0xa26f263b, 0x7ed48400, 0x547eebe6, 0x446d4ca0, 0x6cf3d6f5,
-    0x2649abdf, 0xaea0c7f5, 0x36338cc1, 0x503f7e93, 0xd3772061, 0x11b638e1, 0x72500e03, 0xf80eb2bb,
-    0xabe0502e, 0xec8d77de, 0x57971e81, 0xe14f6746, 0xc9335400, 0x6920318f, 0x081dbb99, 0xffc304a5,
-    0x4d351805, 0x7f3d5ce3, 0xa6c866c6, 0x5d5bcca9, 0xdaec6fea, 0x9f926f91, 0x9f46222f, 0x3991467d,
-    0xa5bf6d8e, 0x1143c44f, 0x43958302, 0xd0214eeb, 0x022083b8, 0x3fb6180c, 0x18f8931e, 0x281658e6,
-    0x26486e3e, 0x8bd78a70, 0x7477e4c1, 0xb506e07c, 0xf32d0a25, 0x79098b02, 0xe4eabb81, 0x28123b23,
-    0x69dead38, 0x1574ca16, 0xdf871b62, 0x211c40b7, 0xa51a9ef9, 0x0014377b, 0x041e8ac8, 0x09114003,
-    0xbd59e4d2, 0xe3d156d5, 0x4fe876d5, 0x2f91a340, 0x557be8de, 0x00eae4a7, 0x0ce5c2ec, 0x4db4bba6,
-    0xe756bdff, 0xdd3369ac, 0xec17b035, 0x06572327, 0x99afc8b0, 0x56c8c391, 0x6b65811c, 0x5e146119,
-    0x6e85cb75, 0xbe07c002, 0xc2325577, 0x893ff4ec, 0x5bbfc92d, 0xd0ec3b25, 0xb7801ab7, 0x8d6d3b24,
-    0x20c763ef, 0xc366a5fc, 0x9c382880, 0x0ace3205, 0xaac9548a, 0xeca1d7c7, 0x041afa32, 0x1d16625a,
-    0x6701902c, 0x9b757a54, 0x31d477f7, 0x9126b031, 0x36cc6fdb, 0xc70b8b46, 0xd9e66a48, 0x56e55a79,
-    0x026a4ceb, 0x52437eff, 0x2f8f76b4, 0x0df980a5, 0x8674cde3, 0xedda04eb, 0x17a9be04, 0x2c18f4df,
-    0xb7747f9d, 0xab2af7b4, 0xefc34d20, 0x2e096b7c, 0x1741a254, 0xe5b6a035, 0x213d42f6, 0x2c1c7c26,
-    0x61c2f50f, 0x6552daf9, 0xd2c231f8, 0x25130f69, 0xd8167fa2, 0x0418f2c8, 0x001a96a6, 0x0d1526ab,
-    0x63315c21, 0x5e0a72ec, 0x49bafefd, 0x187908d9, 0x8d0dbd86, 0x311170a7, 0x3e9b640c, 0xcc3e10d7,
-    0xd5cad3b6, 0x0caec388, 0xf73001e1, 0x6c728aff, 0x71eae2a1, 0x1f9af36e, 0xcfcbd12f, 0xc1de8417,
-    0xac07be6b, 0xcb44a1d8, 0x8b9b0f56, 0x013988c3, 0xb1c52fca, 0xb4be31cd, 0xd8782806, 0x12a3a4e2,
-    0x6f7de532, 0x58fd7eb6, 0xd01ee900, 0x24adffc2, 0xf4990fc5, 0x9711aac5, 0x001d7b95, 0x82e5e7d2,
-    0x109873f6, 0x00613096, 0xc32d9521, 0xada121ff, 0x29908415, 0x7fbb977f, 0xaf9eb3db, 0x29c9ed2a,
-    0x5ce2a465, 0xa730f32c, 0xd0aa3fe8, 0x8a5cc091, 0xd49e2ce7, 0x0ce454a9, 0xd60acd86, 0x015f1919,
-    0x77079103, 0xdea03af6, 0x78a8565e, 0xdee356df, 0x21f05cbe, 0x8b75e387, 0xb3c50651, 0xb8a5c3ef,
-    0xd8eeb6d2, 0xe523be77, 0xc2154529, 0x2f69efdf, 0xafe67afb, 0xf470c4b2, 0xf3e0eb5b, 0xd6cc9876,
-    0x39e4460c, 0x1fda8538, 0x1987832f, 0xca007367, 0xa99144f8, 0x296b299e, 0x492fc295, 0x9266beab,
-    0xb5676e69, 0x9bd3ddda, 0xdf7e052f, 0xdb25701c, 0x1b5e51ee, 0xf65324e6, 0x6afce36c, 0x0316cc04,
-    0x8644213e, 0xb7dc59d0, 0x7965291f, 0xccd6fd43, 0x41823979, 0x932bcdf6, 0xb657c34d, 0x4edfd282,
-    0x7ae5290c, 0x3cb9536b, 0x851e20fe, 0x9833557e, 0x13ecf0b0, 0xd3ffb372, 0x3f85c5c1, 0x0aef7ed2
+    0x9db30420,
+    0x1fb6e9de,
+    0xa7be7bef,
+    0xd273a298,
+    0x4a4f7bdb,
+    0x64ad8c57,
+    0x85510443,
+    0xfa020ed1,
+    0x7e287aff,
+    0xe60fb663,
+    0x095f35a1,
+    0x79ebf120,
+    0xfd059d43,
+    0x6497b7b1,
+    0xf3641f63,
+    0x241e4adf,
+    0x28147f5f,
+    0x4fa2b8cd,
+    0xc9430040,
+    0x0cc32220,
+    0xfdd30b30,
+    0xc0a5374f,
+    0x1d2d00d9,
+    0x24147b15,
+    0xee4d111a,
+    0x0fca5167,
+    0x71ff904c,
+    0x2d195ffe,
+    0x1a05645f,
+    0x0c13fefe,
+    0x081b08ca,
+    0x05170121,
+    0x80530100,
+    0xe83e5efe,
+    0xac9af4f8,
+    0x7fe72701,
+    0xd2b8ee5f,
+    0x06df4261,
+    0xbb9e9b8a,
+    0x7293ea25,
+    0xce84ffdf,
+    0xf5718801,
+    0x3dd64b04,
+    0xa26f263b,
+    0x7ed48400,
+    0x547eebe6,
+    0x446d4ca0,
+    0x6cf3d6f5,
+    0x2649abdf,
+    0xaea0c7f5,
+    0x36338cc1,
+    0x503f7e93,
+    0xd3772061,
+    0x11b638e1,
+    0x72500e03,
+    0xf80eb2bb,
+    0xabe0502e,
+    0xec8d77de,
+    0x57971e81,
+    0xe14f6746,
+    0xc9335400,
+    0x6920318f,
+    0x081dbb99,
+    0xffc304a5,
+    0x4d351805,
+    0x7f3d5ce3,
+    0xa6c866c6,
+    0x5d5bcca9,
+    0xdaec6fea,
+    0x9f926f91,
+    0x9f46222f,
+    0x3991467d,
+    0xa5bf6d8e,
+    0x1143c44f,
+    0x43958302,
+    0xd0214eeb,
+    0x022083b8,
+    0x3fb6180c,
+    0x18f8931e,
+    0x281658e6,
+    0x26486e3e,
+    0x8bd78a70,
+    0x7477e4c1,
+    0xb506e07c,
+    0xf32d0a25,
+    0x79098b02,
+    0xe4eabb81,
+    0x28123b23,
+    0x69dead38,
+    0x1574ca16,
+    0xdf871b62,
+    0x211c40b7,
+    0xa51a9ef9,
+    0x0014377b,
+    0x041e8ac8,
+    0x09114003,
+    0xbd59e4d2,
+    0xe3d156d5,
+    0x4fe876d5,
+    0x2f91a340,
+    0x557be8de,
+    0x00eae4a7,
+    0x0ce5c2ec,
+    0x4db4bba6,
+    0xe756bdff,
+    0xdd3369ac,
+    0xec17b035,
+    0x06572327,
+    0x99afc8b0,
+    0x56c8c391,
+    0x6b65811c,
+    0x5e146119,
+    0x6e85cb75,
+    0xbe07c002,
+    0xc2325577,
+    0x893ff4ec,
+    0x5bbfc92d,
+    0xd0ec3b25,
+    0xb7801ab7,
+    0x8d6d3b24,
+    0x20c763ef,
+    0xc366a5fc,
+    0x9c382880,
+    0x0ace3205,
+    0xaac9548a,
+    0xeca1d7c7,
+    0x041afa32,
+    0x1d16625a,
+    0x6701902c,
+    0x9b757a54,
+    0x31d477f7,
+    0x9126b031,
+    0x36cc6fdb,
+    0xc70b8b46,
+    0xd9e66a48,
+    0x56e55a79,
+    0x026a4ceb,
+    0x52437eff,
+    0x2f8f76b4,
+    0x0df980a5,
+    0x8674cde3,
+    0xedda04eb,
+    0x17a9be04,
+    0x2c18f4df,
+    0xb7747f9d,
+    0xab2af7b4,
+    0xefc34d20,
+    0x2e096b7c,
+    0x1741a254,
+    0xe5b6a035,
+    0x213d42f6,
+    0x2c1c7c26,
+    0x61c2f50f,
+    0x6552daf9,
+    0xd2c231f8,
+    0x25130f69,
+    0xd8167fa2,
+    0x0418f2c8,
+    0x001a96a6,
+    0x0d1526ab,
+    0x63315c21,
+    0x5e0a72ec,
+    0x49bafefd,
+    0x187908d9,
+    0x8d0dbd86,
+    0x311170a7,
+    0x3e9b640c,
+    0xcc3e10d7,
+    0xd5cad3b6,
+    0x0caec388,
+    0xf73001e1,
+    0x6c728aff,
+    0x71eae2a1,
+    0x1f9af36e,
+    0xcfcbd12f,
+    0xc1de8417,
+    0xac07be6b,
+    0xcb44a1d8,
+    0x8b9b0f56,
+    0x013988c3,
+    0xb1c52fca,
+    0xb4be31cd,
+    0xd8782806,
+    0x12a3a4e2,
+    0x6f7de532,
+    0x58fd7eb6,
+    0xd01ee900,
+    0x24adffc2,
+    0xf4990fc5,
+    0x9711aac5,
+    0x001d7b95,
+    0x82e5e7d2,
+    0x109873f6,
+    0x00613096,
+    0xc32d9521,
+    0xada121ff,
+    0x29908415,
+    0x7fbb977f,
+    0xaf9eb3db,
+    0x29c9ed2a,
+    0x5ce2a465,
+    0xa730f32c,
+    0xd0aa3fe8,
+    0x8a5cc091,
+    0xd49e2ce7,
+    0x0ce454a9,
+    0xd60acd86,
+    0x015f1919,
+    0x77079103,
+    0xdea03af6,
+    0x78a8565e,
+    0xdee356df,
+    0x21f05cbe,
+    0x8b75e387,
+    0xb3c50651,
+    0xb8a5c3ef,
+    0xd8eeb6d2,
+    0xe523be77,
+    0xc2154529,
+    0x2f69efdf,
+    0xafe67afb,
+    0xf470c4b2,
+    0xf3e0eb5b,
+    0xd6cc9876,
+    0x39e4460c,
+    0x1fda8538,
+    0x1987832f,
+    0xca007367,
+    0xa99144f8,
+    0x296b299e,
+    0x492fc295,
+    0x9266beab,
+    0xb5676e69,
+    0x9bd3ddda,
+    0xdf7e052f,
+    0xdb25701c,
+    0x1b5e51ee,
+    0xf65324e6,
+    0x6afce36c,
+    0x0316cc04,
+    0x8644213e,
+    0xb7dc59d0,
+    0x7965291f,
+    0xccd6fd43,
+    0x41823979,
+    0x932bcdf6,
+    0xb657c34d,
+    0x4edfd282,
+    0x7ae5290c,
+    0x3cb9536b,
+    0x851e20fe,
+    0x9833557e,
+    0x13ecf0b0,
+    0xd3ffb372,
+    0x3f85c5c1,
+    0x0aef7ed2,
 };
 
 const CAST_LONG CAST_S_table4[256] = {
-    0x7ec90c04, 0x2c6e74b9, 0x9b0e66df, 0xa6337911, 0xb86a7fff, 0x1dd358f5, 0x44dd9d44, 0x1731167f,
-    0x08fbf1fa, 0xe7f511cc, 0xd2051b00, 0x735aba00, 0x2ab722d8, 0x386381cb, 0xacf6243a, 0x69befd7a,
-    0xe6a2e77f, 0xf0c720cd, 0xc4494816, 0xccf5c180, 0x38851640, 0x15b0a848, 0xe68b18cb, 0x4caadeff,
-    0x5f480a01, 0x0412b2aa, 0x259814fc, 0x41d0efe2, 0x4e40b48d, 0x248eb6fb, 0x8dba1cfe, 0x41a99b02,
-    0x1a550a04, 0xba8f65cb, 0x7251f4e7, 0x95a51725, 0xc106ecd7, 0x97a5980a, 0xc539b9aa, 0x4d79fe6a,
-    0xf2f3f763, 0x68af8040, 0xed0c9e56, 0x11b4958b, 0xe1eb5a88, 0x8709e6b0, 0xd7e07156, 0x4e29fea7,
-    0x6366e52d, 0x02d1c000, 0xc4ac8e05, 0x9377f571, 0x0c05372a, 0x578535f2, 0x2261be02, 0xd642a0c9,
-    0xdf13a280, 0x74b55bd2, 0x682199c0, 0xd421e5ec, 0x53fb3ce8, 0xc8adedb3, 0x28a87fc9, 0x3d959981,
-    0x5c1ff900, 0xfe38d399, 0x0c4eff0b, 0x062407ea, 0xaa2f4fb1, 0x4fb96976, 0x90c79505, 0xb0a8a774,
-    0xef55a1ff, 0xe59ca2c2, 0xa6b62d27, 0xe66a4263, 0xdf65001f, 0x0ec50966, 0xdfdd55bc, 0x29de0655,
-    0x911e739a, 0x17af8975, 0x32c7911c, 0x89f89468, 0x0d01e980, 0x524755f4, 0x03b63cc9, 0x0cc844b2,
-    0xbcf3f0aa, 0x87ac36e9, 0xe53a7426, 0x01b3d82b, 0x1a9e7449, 0x64ee2d7e, 0xcddbb1da, 0x01c94910,
-    0xb868bf80, 0x0d26f3fd, 0x9342ede7, 0x04a5c284, 0x636737b6, 0x50f5b616, 0xf24766e3, 0x8eca36c1,
-    0x136e05db, 0xfef18391, 0xfb887a37, 0xd6e7f7d4, 0xc7fb7dc9, 0x3063fcdf, 0xb6f589de, 0xec2941da,
-    0x26e46695, 0xb7566419, 0xf654efc5, 0xd08d58b7, 0x48925401, 0xc1bacb7f, 0xe5ff550f, 0xb6083049,
-    0x5bb5d0e8, 0x87d72e5a, 0xab6a6ee1, 0x223a66ce, 0xc62bf3cd, 0x9e0885f9, 0x68cb3e47, 0x086c010f,
-    0xa21de820, 0xd18b69de, 0xf3f65777, 0xfa02c3f6, 0x407edac3, 0xcbb3d550, 0x1793084d, 0xb0d70eba,
-    0x0ab378d5, 0xd951fb0c, 0xded7da56, 0x4124bbe4, 0x94ca0b56, 0x0f5755d1, 0xe0e1e56e, 0x6184b5be,
-    0x580a249f, 0x94f74bc0, 0xe327888e, 0x9f7b5561, 0xc3dc0280, 0x05687715, 0x646c6bd7, 0x44904db3,
-    0x66b4f0a3, 0xc0f1648a, 0x697ed5af, 0x49e92ff6, 0x309e374f, 0x2cb6356a, 0x85808573, 0x4991f840,
-    0x76f0ae02, 0x083be84d, 0x28421c9a, 0x44489406, 0x736e4cb8, 0xc1092910, 0x8bc95fc6, 0x7d869cf4,
-    0x134f616f, 0x2e77118d, 0xb31b2be1, 0xaa90b472, 0x3ca5d717, 0x7d161bba, 0x9cad9010, 0xaf462ba2,
-    0x9fe459d2, 0x45d34559, 0xd9f2da13, 0xdbc65487, 0xf3e4f94e, 0x176d486f, 0x097c13ea, 0x631da5c7,
-    0x445f7382, 0x175683f4, 0xcdc66a97, 0x70be0288, 0xb3cdcf72, 0x6e5dd2f3, 0x20936079, 0x459b80a5,
-    0xbe60e2db, 0xa9c23101, 0xeba5315c, 0x224e42f2, 0x1c5c1572, 0xf6721b2c, 0x1ad2fff3, 0x8c25404e,
-    0x324ed72f, 0x4067b7fd, 0x0523138e, 0x5ca3bc78, 0xdc0fd66e, 0x75922283, 0x784d6b17, 0x58ebb16e,
-    0x44094f85, 0x3f481d87, 0xfcfeae7b, 0x77b5ff76, 0x8c2302bf, 0xaaf47556, 0x5f46b02a, 0x2b092801,
-    0x3d38f5f7, 0x0ca81f36, 0x52af4a8a, 0x66d5e7c0, 0xdf3b0874, 0x95055110, 0x1b5ad7a8, 0xf61ed5ad,
-    0x6cf6e479, 0x20758184, 0xd0cefa65, 0x88f7be58, 0x4a046826, 0x0ff6f8f3, 0xa09c7f70, 0x5346aba0,
-    0x5ce96c28, 0xe176eda3, 0x6bac307f, 0x376829d2, 0x85360fa9, 0x17e3fe2a, 0x24b79767, 0xf5a96b20,
-    0xd6cd2595, 0x68ff1ebf, 0x7555442c, 0xf19f06be, 0xf9e0659a, 0xeeb9491d, 0x34010718, 0xbb30cab8,
-    0xe822fe15, 0x88570983, 0x750e6249, 0xda627e55, 0x5e76ffa8, 0xb1534546, 0x6d47de08, 0xefe9e7d4
+    0x7ec90c04,
+    0x2c6e74b9,
+    0x9b0e66df,
+    0xa6337911,
+    0xb86a7fff,
+    0x1dd358f5,
+    0x44dd9d44,
+    0x1731167f,
+    0x08fbf1fa,
+    0xe7f511cc,
+    0xd2051b00,
+    0x735aba00,
+    0x2ab722d8,
+    0x386381cb,
+    0xacf6243a,
+    0x69befd7a,
+    0xe6a2e77f,
+    0xf0c720cd,
+    0xc4494816,
+    0xccf5c180,
+    0x38851640,
+    0x15b0a848,
+    0xe68b18cb,
+    0x4caadeff,
+    0x5f480a01,
+    0x0412b2aa,
+    0x259814fc,
+    0x41d0efe2,
+    0x4e40b48d,
+    0x248eb6fb,
+    0x8dba1cfe,
+    0x41a99b02,
+    0x1a550a04,
+    0xba8f65cb,
+    0x7251f4e7,
+    0x95a51725,
+    0xc106ecd7,
+    0x97a5980a,
+    0xc539b9aa,
+    0x4d79fe6a,
+    0xf2f3f763,
+    0x68af8040,
+    0xed0c9e56,
+    0x11b4958b,
+    0xe1eb5a88,
+    0x8709e6b0,
+    0xd7e07156,
+    0x4e29fea7,
+    0x6366e52d,
+    0x02d1c000,
+    0xc4ac8e05,
+    0x9377f571,
+    0x0c05372a,
+    0x578535f2,
+    0x2261be02,
+    0xd642a0c9,
+    0xdf13a280,
+    0x74b55bd2,
+    0x682199c0,
+    0xd421e5ec,
+    0x53fb3ce8,
+    0xc8adedb3,
+    0x28a87fc9,
+    0x3d959981,
+    0x5c1ff900,
+    0xfe38d399,
+    0x0c4eff0b,
+    0x062407ea,
+    0xaa2f4fb1,
+    0x4fb96976,
+    0x90c79505,
+    0xb0a8a774,
+    0xef55a1ff,
+    0xe59ca2c2,
+    0xa6b62d27,
+    0xe66a4263,
+    0xdf65001f,
+    0x0ec50966,
+    0xdfdd55bc,
+    0x29de0655,
+    0x911e739a,
+    0x17af8975,
+    0x32c7911c,
+    0x89f89468,
+    0x0d01e980,
+    0x524755f4,
+    0x03b63cc9,
+    0x0cc844b2,
+    0xbcf3f0aa,
+    0x87ac36e9,
+    0xe53a7426,
+    0x01b3d82b,
+    0x1a9e7449,
+    0x64ee2d7e,
+    0xcddbb1da,
+    0x01c94910,
+    0xb868bf80,
+    0x0d26f3fd,
+    0x9342ede7,
+    0x04a5c284,
+    0x636737b6,
+    0x50f5b616,
+    0xf24766e3,
+    0x8eca36c1,
+    0x136e05db,
+    0xfef18391,
+    0xfb887a37,
+    0xd6e7f7d4,
+    0xc7fb7dc9,
+    0x3063fcdf,
+    0xb6f589de,
+    0xec2941da,
+    0x26e46695,
+    0xb7566419,
+    0xf654efc5,
+    0xd08d58b7,
+    0x48925401,
+    0xc1bacb7f,
+    0xe5ff550f,
+    0xb6083049,
+    0x5bb5d0e8,
+    0x87d72e5a,
+    0xab6a6ee1,
+    0x223a66ce,
+    0xc62bf3cd,
+    0x9e0885f9,
+    0x68cb3e47,
+    0x086c010f,
+    0xa21de820,
+    0xd18b69de,
+    0xf3f65777,
+    0xfa02c3f6,
+    0x407edac3,
+    0xcbb3d550,
+    0x1793084d,
+    0xb0d70eba,
+    0x0ab378d5,
+    0xd951fb0c,
+    0xded7da56,
+    0x4124bbe4,
+    0x94ca0b56,
+    0x0f5755d1,
+    0xe0e1e56e,
+    0x6184b5be,
+    0x580a249f,
+    0x94f74bc0,
+    0xe327888e,
+    0x9f7b5561,
+    0xc3dc0280,
+    0x05687715,
+    0x646c6bd7,
+    0x44904db3,
+    0x66b4f0a3,
+    0xc0f1648a,
+    0x697ed5af,
+    0x49e92ff6,
+    0x309e374f,
+    0x2cb6356a,
+    0x85808573,
+    0x4991f840,
+    0x76f0ae02,
+    0x083be84d,
+    0x28421c9a,
+    0x44489406,
+    0x736e4cb8,
+    0xc1092910,
+    0x8bc95fc6,
+    0x7d869cf4,
+    0x134f616f,
+    0x2e77118d,
+    0xb31b2be1,
+    0xaa90b472,
+    0x3ca5d717,
+    0x7d161bba,
+    0x9cad9010,
+    0xaf462ba2,
+    0x9fe459d2,
+    0x45d34559,
+    0xd9f2da13,
+    0xdbc65487,
+    0xf3e4f94e,
+    0x176d486f,
+    0x097c13ea,
+    0x631da5c7,
+    0x445f7382,
+    0x175683f4,
+    0xcdc66a97,
+    0x70be0288,
+    0xb3cdcf72,
+    0x6e5dd2f3,
+    0x20936079,
+    0x459b80a5,
+    0xbe60e2db,
+    0xa9c23101,
+    0xeba5315c,
+    0x224e42f2,
+    0x1c5c1572,
+    0xf6721b2c,
+    0x1ad2fff3,
+    0x8c25404e,
+    0x324ed72f,
+    0x4067b7fd,
+    0x0523138e,
+    0x5ca3bc78,
+    0xdc0fd66e,
+    0x75922283,
+    0x784d6b17,
+    0x58ebb16e,
+    0x44094f85,
+    0x3f481d87,
+    0xfcfeae7b,
+    0x77b5ff76,
+    0x8c2302bf,
+    0xaaf47556,
+    0x5f46b02a,
+    0x2b092801,
+    0x3d38f5f7,
+    0x0ca81f36,
+    0x52af4a8a,
+    0x66d5e7c0,
+    0xdf3b0874,
+    0x95055110,
+    0x1b5ad7a8,
+    0xf61ed5ad,
+    0x6cf6e479,
+    0x20758184,
+    0xd0cefa65,
+    0x88f7be58,
+    0x4a046826,
+    0x0ff6f8f3,
+    0xa09c7f70,
+    0x5346aba0,
+    0x5ce96c28,
+    0xe176eda3,
+    0x6bac307f,
+    0x376829d2,
+    0x85360fa9,
+    0x17e3fe2a,
+    0x24b79767,
+    0xf5a96b20,
+    0xd6cd2595,
+    0x68ff1ebf,
+    0x7555442c,
+    0xf19f06be,
+    0xf9e0659a,
+    0xeeb9491d,
+    0x34010718,
+    0xbb30cab8,
+    0xe822fe15,
+    0x88570983,
+    0x750e6249,
+    0xda627e55,
+    0x5e76ffa8,
+    0xb1534546,
+    0x6d47de08,
+    0xefe9e7d4,
 };
 
 const CAST_LONG CAST_S_table5[256] = {
-    0xf6fa8f9d, 0x2cac6ce1, 0x4ca34867, 0xe2337f7c, 0x95db08e7, 0x016843b4, 0xeced5cbc, 0x325553ac,
-    0xbf9f0960, 0xdfa1e2ed, 0x83f0579d, 0x63ed86b9, 0x1ab6a6b8, 0xde5ebe39, 0xf38ff732, 0x8989b138,
-    0x33f14961, 0xc01937bd, 0xf506c6da, 0xe4625e7e, 0xa308ea99, 0x4e23e33c, 0x79cbd7cc, 0x48a14367,
-    0xa3149619, 0xfec94bd5, 0xa114174a, 0xeaa01866, 0xa084db2d, 0x09a8486f, 0xa888614a, 0x2900af98,
-    0x01665991, 0xe1992863, 0xc8f30c60, 0x2e78ef3c, 0xd0d51932, 0xcf0fec14, 0xf7ca07d2, 0xd0a82072,
-    0xfd41197e, 0x9305a6b0, 0xe86be3da, 0x74bed3cd, 0x372da53c, 0x4c7f4448, 0xdab5d440, 0x6dba0ec3,
-    0x083919a7, 0x9fbaeed9, 0x49dbcfb0, 0x4e670c53, 0x5c3d9c01, 0x64bdb941, 0x2c0e636a, 0xba7dd9cd,
-    0xea6f7388, 0xe70bc762, 0x35f29adb, 0x5c4cdd8d, 0xf0d48d8c, 0xb88153e2, 0x08a19866, 0x1ae2eac8,
-    0x284caf89, 0xaa928223, 0x9334be53, 0x3b3a21bf, 0x16434be3, 0x9aea3906, 0xefe8c36e, 0xf890cdd9,
-    0x80226dae, 0xc340a4a3, 0xdf7e9c09, 0xa694a807, 0x5b7c5ecc, 0x221db3a6, 0x9a69a02f, 0x68818a54,
-    0xceb2296f, 0x53c0843a, 0xfe893655, 0x25bfe68a, 0xb4628abc, 0xcf222ebf, 0x25ac6f48, 0xa9a99387,
-    0x53bddb65, 0xe76ffbe7, 0xe967fd78, 0x0ba93563, 0x8e342bc1, 0xe8a11be9, 0x4980740d, 0xc8087dfc,
-    0x8de4bf99, 0xa11101a0, 0x7fd37975, 0xda5a26c0, 0xe81f994f, 0x9528cd89, 0xfd339fed, 0xb87834bf,
-    0x5f04456d, 0x22258698, 0xc9c4c83b, 0x2dc156be, 0x4f628daa, 0x57f55ec5, 0xe2220abe, 0xd2916ebf,
-    0x4ec75b95, 0x24f2c3c0, 0x42d15d99, 0xcd0d7fa0, 0x7b6e27ff, 0xa8dc8af0, 0x7345c106, 0xf41e232f,
-    0x35162386, 0xe6ea8926, 0x3333b094, 0x157ec6f2, 0x372b74af, 0x692573e4, 0xe9a9d848, 0xf3160289,
-    0x3a62ef1d, 0xa787e238, 0xf3a5f676, 0x74364853, 0x20951063, 0x4576698d, 0xb6fad407, 0x592af950,
-    0x36f73523, 0x4cfb6e87, 0x7da4cec0, 0x6c152daa, 0xcb0396a8, 0xc50dfe5d, 0xfcd707ab, 0x0921c42f,
-    0x89dff0bb, 0x5fe2be78, 0x448f4f33, 0x754613c9, 0x2b05d08d, 0x48b9d585, 0xdc049441, 0xc8098f9b,
-    0x7dede786, 0xc39a3373, 0x42410005, 0x6a091751, 0x0ef3c8a6, 0x890072d6, 0x28207682, 0xa9a9f7be,
-    0xbf32679d, 0xd45b5b75, 0xb353fd00, 0xcbb0e358, 0x830f220a, 0x1f8fb214, 0xd372cf08, 0xcc3c4a13,
-    0x8cf63166, 0x061c87be, 0x88c98f88, 0x6062e397, 0x47cf8e7a, 0xb6c85283, 0x3cc2acfb, 0x3fc06976,
-    0x4e8f0252, 0x64d8314d, 0xda3870e3, 0x1e665459, 0xc10908f0, 0x513021a5, 0x6c5b68b7, 0x822f8aa0,
-    0x3007cd3e, 0x74719eef, 0xdc872681, 0x073340d4, 0x7e432fd9, 0x0c5ec241, 0x8809286c, 0xf592d891,
-    0x08a930f6, 0x957ef305, 0xb7fbffbd, 0xc266e96f, 0x6fe4ac98, 0xb173ecc0, 0xbc60b42a, 0x953498da,
-    0xfba1ae12, 0x2d4bd736, 0x0f25faab, 0xa4f3fceb, 0xe2969123, 0x257f0c3d, 0x9348af49, 0x361400bc,
-    0xe8816f4a, 0x3814f200, 0xa3f94043, 0x9c7a54c2, 0xbc704f57, 0xda41e7f9, 0xc25ad33a, 0x54f4a084,
-    0xb17f5505, 0x59357cbe, 0xedbd15c8, 0x7f97c5ab, 0xba5ac7b5, 0xb6f6deaf, 0x3a479c3a, 0x5302da25,
-    0x653d7e6a, 0x54268d49, 0x51a477ea, 0x5017d55b, 0xd7d25d88, 0x44136c76, 0x0404a8c8, 0xb8e5a121,
-    0xb81a928a, 0x60ed5869, 0x97c55b96, 0xeaec991b, 0x29935913, 0x01fdb7f1, 0x088e8dfa, 0x9ab6f6f5,
-    0x3b4cbf9f, 0x4a5de3ab, 0xe6051d35, 0xa0e1d855, 0xd36b4cf1, 0xf544edeb, 0xb0e93524, 0xbebb8fbd,
-    0xa2d762cf, 0x49c92f54, 0x38b5f331, 0x7128a454, 0x48392905, 0xa65b1db8, 0x851c97bd, 0xd675cf2f
+    0xf6fa8f9d,
+    0x2cac6ce1,
+    0x4ca34867,
+    0xe2337f7c,
+    0x95db08e7,
+    0x016843b4,
+    0xeced5cbc,
+    0x325553ac,
+    0xbf9f0960,
+    0xdfa1e2ed,
+    0x83f0579d,
+    0x63ed86b9,
+    0x1ab6a6b8,
+    0xde5ebe39,
+    0xf38ff732,
+    0x8989b138,
+    0x33f14961,
+    0xc01937bd,
+    0xf506c6da,
+    0xe4625e7e,
+    0xa308ea99,
+    0x4e23e33c,
+    0x79cbd7cc,
+    0x48a14367,
+    0xa3149619,
+    0xfec94bd5,
+    0xa114174a,
+    0xeaa01866,
+    0xa084db2d,
+    0x09a8486f,
+    0xa888614a,
+    0x2900af98,
+    0x01665991,
+    0xe1992863,
+    0xc8f30c60,
+    0x2e78ef3c,
+    0xd0d51932,
+    0xcf0fec14,
+    0xf7ca07d2,
+    0xd0a82072,
+    0xfd41197e,
+    0x9305a6b0,
+    0xe86be3da,
+    0x74bed3cd,
+    0x372da53c,
+    0x4c7f4448,
+    0xdab5d440,
+    0x6dba0ec3,
+    0x083919a7,
+    0x9fbaeed9,
+    0x49dbcfb0,
+    0x4e670c53,
+    0x5c3d9c01,
+    0x64bdb941,
+    0x2c0e636a,
+    0xba7dd9cd,
+    0xea6f7388,
+    0xe70bc762,
+    0x35f29adb,
+    0x5c4cdd8d,
+    0xf0d48d8c,
+    0xb88153e2,
+    0x08a19866,
+    0x1ae2eac8,
+    0x284caf89,
+    0xaa928223,
+    0x9334be53,
+    0x3b3a21bf,
+    0x16434be3,
+    0x9aea3906,
+    0xefe8c36e,
+    0xf890cdd9,
+    0x80226dae,
+    0xc340a4a3,
+    0xdf7e9c09,
+    0xa694a807,
+    0x5b7c5ecc,
+    0x221db3a6,
+    0x9a69a02f,
+    0x68818a54,
+    0xceb2296f,
+    0x53c0843a,
+    0xfe893655,
+    0x25bfe68a,
+    0xb4628abc,
+    0xcf222ebf,
+    0x25ac6f48,
+    0xa9a99387,
+    0x53bddb65,
+    0xe76ffbe7,
+    0xe967fd78,
+    0x0ba93563,
+    0x8e342bc1,
+    0xe8a11be9,
+    0x4980740d,
+    0xc8087dfc,
+    0x8de4bf99,
+    0xa11101a0,
+    0x7fd37975,
+    0xda5a26c0,
+    0xe81f994f,
+    0x9528cd89,
+    0xfd339fed,
+    0xb87834bf,
+    0x5f04456d,
+    0x22258698,
+    0xc9c4c83b,
+    0x2dc156be,
+    0x4f628daa,
+    0x57f55ec5,
+    0xe2220abe,
+    0xd2916ebf,
+    0x4ec75b95,
+    0x24f2c3c0,
+    0x42d15d99,
+    0xcd0d7fa0,
+    0x7b6e27ff,
+    0xa8dc8af0,
+    0x7345c106,
+    0xf41e232f,
+    0x35162386,
+    0xe6ea8926,
+    0x3333b094,
+    0x157ec6f2,
+    0x372b74af,
+    0x692573e4,
+    0xe9a9d848,
+    0xf3160289,
+    0x3a62ef1d,
+    0xa787e238,
+    0xf3a5f676,
+    0x74364853,
+    0x20951063,
+    0x4576698d,
+    0xb6fad407,
+    0x592af950,
+    0x36f73523,
+    0x4cfb6e87,
+    0x7da4cec0,
+    0x6c152daa,
+    0xcb0396a8,
+    0xc50dfe5d,
+    0xfcd707ab,
+    0x0921c42f,
+    0x89dff0bb,
+    0x5fe2be78,
+    0x448f4f33,
+    0x754613c9,
+    0x2b05d08d,
+    0x48b9d585,
+    0xdc049441,
+    0xc8098f9b,
+    0x7dede786,
+    0xc39a3373,
+    0x42410005,
+    0x6a091751,
+    0x0ef3c8a6,
+    0x890072d6,
+    0x28207682,
+    0xa9a9f7be,
+    0xbf32679d,
+    0xd45b5b75,
+    0xb353fd00,
+    0xcbb0e358,
+    0x830f220a,
+    0x1f8fb214,
+    0xd372cf08,
+    0xcc3c4a13,
+    0x8cf63166,
+    0x061c87be,
+    0x88c98f88,
+    0x6062e397,
+    0x47cf8e7a,
+    0xb6c85283,
+    0x3cc2acfb,
+    0x3fc06976,
+    0x4e8f0252,
+    0x64d8314d,
+    0xda3870e3,
+    0x1e665459,
+    0xc10908f0,
+    0x513021a5,
+    0x6c5b68b7,
+    0x822f8aa0,
+    0x3007cd3e,
+    0x74719eef,
+    0xdc872681,
+    0x073340d4,
+    0x7e432fd9,
+    0x0c5ec241,
+    0x8809286c,
+    0xf592d891,
+    0x08a930f6,
+    0x957ef305,
+    0xb7fbffbd,
+    0xc266e96f,
+    0x6fe4ac98,
+    0xb173ecc0,
+    0xbc60b42a,
+    0x953498da,
+    0xfba1ae12,
+    0x2d4bd736,
+    0x0f25faab,
+    0xa4f3fceb,
+    0xe2969123,
+    0x257f0c3d,
+    0x9348af49,
+    0x361400bc,
+    0xe8816f4a,
+    0x3814f200,
+    0xa3f94043,
+    0x9c7a54c2,
+    0xbc704f57,
+    0xda41e7f9,
+    0xc25ad33a,
+    0x54f4a084,
+    0xb17f5505,
+    0x59357cbe,
+    0xedbd15c8,
+    0x7f97c5ab,
+    0xba5ac7b5,
+    0xb6f6deaf,
+    0x3a479c3a,
+    0x5302da25,
+    0x653d7e6a,
+    0x54268d49,
+    0x51a477ea,
+    0x5017d55b,
+    0xd7d25d88,
+    0x44136c76,
+    0x0404a8c8,
+    0xb8e5a121,
+    0xb81a928a,
+    0x60ed5869,
+    0x97c55b96,
+    0xeaec991b,
+    0x29935913,
+    0x01fdb7f1,
+    0x088e8dfa,
+    0x9ab6f6f5,
+    0x3b4cbf9f,
+    0x4a5de3ab,
+    0xe6051d35,
+    0xa0e1d855,
+    0xd36b4cf1,
+    0xf544edeb,
+    0xb0e93524,
+    0xbebb8fbd,
+    0xa2d762cf,
+    0x49c92f54,
+    0x38b5f331,
+    0x7128a454,
+    0x48392905,
+    0xa65b1db8,
+    0x851c97bd,
+    0xd675cf2f,
 };
 
 const CAST_LONG CAST_S_table6[256] = {
-    0x85e04019, 0x332bf567, 0x662dbfff, 0xcfc65693, 0x2a8d7f6f, 0xab9bc912, 0xde6008a1, 0x2028da1f,
-    0x0227bce7, 0x4d642916, 0x18fac300, 0x50f18b82, 0x2cb2cb11, 0xb232e75c, 0x4b3695f2, 0xb28707de,
-    0xa05fbcf6, 0xcd4181e9, 0xe150210c, 0xe24ef1bd, 0xb168c381, 0xfde4e789, 0x5c79b0d8, 0x1e8bfd43,
-    0x4d495001, 0x38be4341, 0x913cee1d, 0x92a79c3f, 0x089766be, 0xbaeeadf4, 0x1286becf, 0xb6eacb19,
-    0x2660c200, 0x7565bde4, 0x64241f7a, 0x8248dca9, 0xc3b3ad66, 0x28136086, 0x0bd8dfa8, 0x356d1cf2,
-    0x107789be, 0xb3b2e9ce, 0x0502aa8f, 0x0bc0351e, 0x166bf52a, 0xeb12ff82, 0xe3486911, 0xd34d7516,
-    0x4e7b3aff, 0x5f43671b, 0x9cf6e037, 0x4981ac83, 0x334266ce, 0x8c9341b7, 0xd0d854c0, 0xcb3a6c88,
-    0x47bc2829, 0x4725ba37, 0xa66ad22b, 0x7ad61f1e, 0x0c5cbafa, 0x4437f107, 0xb6e79962, 0x42d2d816,
-    0x0a961288, 0xe1a5c06e, 0x13749e67, 0x72fc081a, 0xb1d139f7, 0xf9583745, 0xcf19df58, 0xbec3f756,
-    0xc06eba30, 0x07211b24, 0x45c28829, 0xc95e317f, 0xbc8ec511, 0x38bc46e9, 0xc6e6fa14, 0xbae8584a,
-    0xad4ebc46, 0x468f508b, 0x7829435f, 0xf124183b, 0x821dba9f, 0xaff60ff4, 0xea2c4e6d, 0x16e39264,
-    0x92544a8b, 0x009b4fc3, 0xaba68ced, 0x9ac96f78, 0x06a5b79a, 0xb2856e6e, 0x1aec3ca9, 0xbe838688,
-    0x0e0804e9, 0x55f1be56, 0xe7e5363b, 0xb3a1f25d, 0xf7debb85, 0x61fe033c, 0x16746233, 0x3c034c28,
-    0xda6d0c74, 0x79aac56c, 0x3ce4e1ad, 0x51f0c802, 0x98f8f35a, 0x1626a49f, 0xeed82b29, 0x1d382fe3,
-    0x0c4fb99a, 0xbb325778, 0x3ec6d97b, 0x6e77a6a9, 0xcb658b5c, 0xd45230c7, 0x2bd1408b, 0x60c03eb7,
-    0xb9068d78, 0xa33754f4, 0xf430c87d, 0xc8a71302, 0xb96d8c32, 0xebd4e7be, 0xbe8b9d2d, 0x7979fb06,
-    0xe7225308, 0x8b75cf77, 0x11ef8da4, 0xe083c858, 0x8d6b786f, 0x5a6317a6, 0xfa5cf7a0, 0x5dda0033,
-    0xf28ebfb0, 0xf5b9c310, 0xa0eac280, 0x08b9767a, 0xa3d9d2b0, 0x79d34217, 0x021a718d, 0x9ac6336a,
-    0x2711fd60, 0x438050e3, 0x069908a8, 0x3d7fedc4, 0x826d2bef, 0x4eeb8476, 0x488dcf25, 0x36c9d566,
-    0x28e74e41, 0xc2610aca, 0x3d49a9cf, 0xbae3b9df, 0xb65f8de6, 0x92aeaf64, 0x3ac7d5e6, 0x9ea80509,
-    0xf22b017d, 0xa4173f70, 0xdd1e16c3, 0x15e0d7f9, 0x50b1b887, 0x2b9f4fd5, 0x625aba82, 0x6a017962,
-    0x2ec01b9c, 0x15488aa9, 0xd716e740, 0x40055a2c, 0x93d29a22, 0xe32dbf9a, 0x058745b9, 0x3453dc1e,
-    0xd699296e, 0x496cff6f, 0x1c9f4986, 0xdfe2ed07, 0xb87242d1, 0x19de7eae, 0x053e561a, 0x15ad6f8c,
-    0x66626c1c, 0x7154c24c, 0xea082b2a, 0x93eb2939, 0x17dcb0f0, 0x58d4f2ae, 0x9ea294fb, 0x52cf564c,
-    0x9883fe66, 0x2ec40581, 0x763953c3, 0x01d6692e, 0xd3a0c108, 0xa1e7160e, 0xe4f2dfa6, 0x693ed285,
-    0x74904698, 0x4c2b0edd, 0x4f757656, 0x5d393378, 0xa132234f, 0x3d321c5d, 0xc3f5e194, 0x4b269301,
-    0xc79f022f, 0x3c997e7e, 0x5e4f9504, 0x3ffafbbd, 0x76f7ad0e, 0x296693f4, 0x3d1fce6f, 0xc61e45be,
-    0xd3b5ab34, 0xf72bf9b7, 0x1b0434c0, 0x4e72b567, 0x5592a33d, 0xb5229301, 0xcfd2a87f, 0x60aeb767,
-    0x1814386b, 0x30bcc33d, 0x38a0c07d, 0xfd1606f2, 0xc363519b, 0x589dd390, 0x5479f8e6, 0x1cb8d647,
-    0x97fd61a9, 0xea7759f4, 0x2d57539d, 0x569a58cf, 0xe84e63ad, 0x462e1b78, 0x6580f87e, 0xf3817914,
-    0x91da55f4, 0x40a230f3, 0xd1988f35, 0xb6e318d2, 0x3ffa50bc, 0x3d40f021, 0xc3c0bdae, 0x4958c24c,
-    0x518f36b2, 0x84b1d370, 0x0fedce83, 0x878ddada, 0xf2a279c7, 0x94e01be8, 0x90716f4b, 0x954b8aa3
+    0x85e04019,
+    0x332bf567,
+    0x662dbfff,
+    0xcfc65693,
+    0x2a8d7f6f,
+    0xab9bc912,
+    0xde6008a1,
+    0x2028da1f,
+    0x0227bce7,
+    0x4d642916,
+    0x18fac300,
+    0x50f18b82,
+    0x2cb2cb11,
+    0xb232e75c,
+    0x4b3695f2,
+    0xb28707de,
+    0xa05fbcf6,
+    0xcd4181e9,
+    0xe150210c,
+    0xe24ef1bd,
+    0xb168c381,
+    0xfde4e789,
+    0x5c79b0d8,
+    0x1e8bfd43,
+    0x4d495001,
+    0x38be4341,
+    0x913cee1d,
+    0x92a79c3f,
+    0x089766be,
+    0xbaeeadf4,
+    0x1286becf,
+    0xb6eacb19,
+    0x2660c200,
+    0x7565bde4,
+    0x64241f7a,
+    0x8248dca9,
+    0xc3b3ad66,
+    0x28136086,
+    0x0bd8dfa8,
+    0x356d1cf2,
+    0x107789be,
+    0xb3b2e9ce,
+    0x0502aa8f,
+    0x0bc0351e,
+    0x166bf52a,
+    0xeb12ff82,
+    0xe3486911,
+    0xd34d7516,
+    0x4e7b3aff,
+    0x5f43671b,
+    0x9cf6e037,
+    0x4981ac83,
+    0x334266ce,
+    0x8c9341b7,
+    0xd0d854c0,
+    0xcb3a6c88,
+    0x47bc2829,
+    0x4725ba37,
+    0xa66ad22b,
+    0x7ad61f1e,
+    0x0c5cbafa,
+    0x4437f107,
+    0xb6e79962,
+    0x42d2d816,
+    0x0a961288,
+    0xe1a5c06e,
+    0x13749e67,
+    0x72fc081a,
+    0xb1d139f7,
+    0xf9583745,
+    0xcf19df58,
+    0xbec3f756,
+    0xc06eba30,
+    0x07211b24,
+    0x45c28829,
+    0xc95e317f,
+    0xbc8ec511,
+    0x38bc46e9,
+    0xc6e6fa14,
+    0xbae8584a,
+    0xad4ebc46,
+    0x468f508b,
+    0x7829435f,
+    0xf124183b,
+    0x821dba9f,
+    0xaff60ff4,
+    0xea2c4e6d,
+    0x16e39264,
+    0x92544a8b,
+    0x009b4fc3,
+    0xaba68ced,
+    0x9ac96f78,
+    0x06a5b79a,
+    0xb2856e6e,
+    0x1aec3ca9,
+    0xbe838688,
+    0x0e0804e9,
+    0x55f1be56,
+    0xe7e5363b,
+    0xb3a1f25d,
+    0xf7debb85,
+    0x61fe033c,
+    0x16746233,
+    0x3c034c28,
+    0xda6d0c74,
+    0x79aac56c,
+    0x3ce4e1ad,
+    0x51f0c802,
+    0x98f8f35a,
+    0x1626a49f,
+    0xeed82b29,
+    0x1d382fe3,
+    0x0c4fb99a,
+    0xbb325778,
+    0x3ec6d97b,
+    0x6e77a6a9,
+    0xcb658b5c,
+    0xd45230c7,
+    0x2bd1408b,
+    0x60c03eb7,
+    0xb9068d78,
+    0xa33754f4,
+    0xf430c87d,
+    0xc8a71302,
+    0xb96d8c32,
+    0xebd4e7be,
+    0xbe8b9d2d,
+    0x7979fb06,
+    0xe7225308,
+    0x8b75cf77,
+    0x11ef8da4,
+    0xe083c858,
+    0x8d6b786f,
+    0x5a6317a6,
+    0xfa5cf7a0,
+    0x5dda0033,
+    0xf28ebfb0,
+    0xf5b9c310,
+    0xa0eac280,
+    0x08b9767a,
+    0xa3d9d2b0,
+    0x79d34217,
+    0x021a718d,
+    0x9ac6336a,
+    0x2711fd60,
+    0x438050e3,
+    0x069908a8,
+    0x3d7fedc4,
+    0x826d2bef,
+    0x4eeb8476,
+    0x488dcf25,
+    0x36c9d566,
+    0x28e74e41,
+    0xc2610aca,
+    0x3d49a9cf,
+    0xbae3b9df,
+    0xb65f8de6,
+    0x92aeaf64,
+    0x3ac7d5e6,
+    0x9ea80509,
+    0xf22b017d,
+    0xa4173f70,
+    0xdd1e16c3,
+    0x15e0d7f9,
+    0x50b1b887,
+    0x2b9f4fd5,
+    0x625aba82,
+    0x6a017962,
+    0x2ec01b9c,
+    0x15488aa9,
+    0xd716e740,
+    0x40055a2c,
+    0x93d29a22,
+    0xe32dbf9a,
+    0x058745b9,
+    0x3453dc1e,
+    0xd699296e,
+    0x496cff6f,
+    0x1c9f4986,
+    0xdfe2ed07,
+    0xb87242d1,
+    0x19de7eae,
+    0x053e561a,
+    0x15ad6f8c,
+    0x66626c1c,
+    0x7154c24c,
+    0xea082b2a,
+    0x93eb2939,
+    0x17dcb0f0,
+    0x58d4f2ae,
+    0x9ea294fb,
+    0x52cf564c,
+    0x9883fe66,
+    0x2ec40581,
+    0x763953c3,
+    0x01d6692e,
+    0xd3a0c108,
+    0xa1e7160e,
+    0xe4f2dfa6,
+    0x693ed285,
+    0x74904698,
+    0x4c2b0edd,
+    0x4f757656,
+    0x5d393378,
+    0xa132234f,
+    0x3d321c5d,
+    0xc3f5e194,
+    0x4b269301,
+    0xc79f022f,
+    0x3c997e7e,
+    0x5e4f9504,
+    0x3ffafbbd,
+    0x76f7ad0e,
+    0x296693f4,
+    0x3d1fce6f,
+    0xc61e45be,
+    0xd3b5ab34,
+    0xf72bf9b7,
+    0x1b0434c0,
+    0x4e72b567,
+    0x5592a33d,
+    0xb5229301,
+    0xcfd2a87f,
+    0x60aeb767,
+    0x1814386b,
+    0x30bcc33d,
+    0x38a0c07d,
+    0xfd1606f2,
+    0xc363519b,
+    0x589dd390,
+    0x5479f8e6,
+    0x1cb8d647,
+    0x97fd61a9,
+    0xea7759f4,
+    0x2d57539d,
+    0x569a58cf,
+    0xe84e63ad,
+    0x462e1b78,
+    0x6580f87e,
+    0xf3817914,
+    0x91da55f4,
+    0x40a230f3,
+    0xd1988f35,
+    0xb6e318d2,
+    0x3ffa50bc,
+    0x3d40f021,
+    0xc3c0bdae,
+    0x4958c24c,
+    0x518f36b2,
+    0x84b1d370,
+    0x0fedce83,
+    0x878ddada,
+    0xf2a279c7,
+    0x94e01be8,
+    0x90716f4b,
+    0x954b8aa3,
 };
 
 const CAST_LONG CAST_S_table7[256] = {
-    0xe216300d, 0xbbddfffc, 0xa7ebdabd, 0x35648095, 0x7789f8b7, 0xe6c1121b, 0x0e241600, 0x052ce8b5,
-    0x11a9cfb0, 0xe5952f11, 0xece7990a, 0x9386d174, 0x2a42931c, 0x76e38111, 0xb12def3a, 0x37ddddfc,
-    0xde9adeb1, 0x0a0cc32c, 0xbe197029, 0x84a00940, 0xbb243a0f, 0xb4d137cf, 0xb44e79f0, 0x049eedfd,
-    0x0b15a15d, 0x480d3168, 0x8bbbde5a, 0x669ded42, 0xc7ece831, 0x3f8f95e7, 0x72df191b, 0x7580330d,
-    0x94074251, 0x5c7dcdfa, 0xabbe6d63, 0xaa402164, 0xb301d40a, 0x02e7d1ca, 0x53571dae, 0x7a3182a2,
-    0x12a8ddec, 0xfdaa335d, 0x176f43e8, 0x71fb46d4, 0x38129022, 0xce949ad4, 0xb84769ad, 0x965bd862,
-    0x82f3d055, 0x66fb9767, 0x15b80b4e, 0x1d5b47a0, 0x4cfde06f, 0xc28ec4b8, 0x57e8726e, 0x647a78fc,
-    0x99865d44, 0x608bd593, 0x6c200e03, 0x39dc5ff6, 0x5d0b00a3, 0xae63aff2, 0x7e8bd632, 0x70108c0c,
-    0xbbd35049, 0x2998df04, 0x980cf42a, 0x9b6df491, 0x9e7edd53, 0x06918548, 0x58cb7e07, 0x3b74ef2e,
-    0x522fffb1, 0xd24708cc, 0x1c7e27cd, 0xa4eb215b, 0x3cf1d2e2, 0x19b47a38, 0x424f7618, 0x35856039,
-    0x9d17dee7, 0x27eb35e6, 0xc9aff67b, 0x36baf5b8, 0x09c467cd, 0xc18910b1, 0xe11dbf7b, 0x06cd1af8,
-    0x7170c608, 0x2d5e3354, 0xd4de495a, 0x64c6d006, 0xbcc0c62c, 0x3dd00db3, 0x708f8f34, 0x77d51b42,
-    0x264f620f, 0x24b8d2bf, 0x15c1b79e, 0x46a52564, 0xf8d7e54e, 0x3e378160, 0x7895cda5, 0x859c15a5,
-    0xe6459788, 0xc37bc75f, 0xdb07ba0c, 0x0676a3ab, 0x7f229b1e, 0x31842e7b, 0x24259fd7, 0xf8bef472,
-    0x835ffcb8, 0x6df4c1f2, 0x96f5b195, 0xfd0af0fc, 0xb0fe134c, 0xe2506d3d, 0x4f9b12ea, 0xf215f225,
-    0xa223736f, 0x9fb4c428, 0x25d04979, 0x34c713f8, 0xc4618187, 0xea7a6e98, 0x7cd16efc, 0x1436876c,
-    0xf1544107, 0xbedeee14, 0x56e9af27, 0xa04aa441, 0x3cf7c899, 0x92ecbae6, 0xdd67016d, 0x151682eb,
-    0xa842eedf, 0xfdba60b4, 0xf1907b75, 0x20e3030f, 0x24d8c29e, 0xe139673b, 0xefa63fb8, 0x71873054,
-    0xb6f2cf3b, 0x9f326442, 0xcb15a4cc, 0xb01a4504, 0xf1e47d8d, 0x844a1be5, 0xbae7dfdc, 0x42cbda70,
-    0xcd7dae0a, 0x57e85b7a, 0xd53f5af6, 0x20cf4d8c, 0xcea4d428, 0x79d130a4, 0x3486ebfb, 0x33d3cddc,
-    0x77853b53, 0x37effcb5, 0xc5068778, 0xe580b3e6, 0x4e68b8f4, 0xc5c8b37e, 0x0d809ea2, 0x398feb7c,
-    0x132a4f94, 0x43b7950e, 0x2fee7d1c, 0x223613bd, 0xdd06caa2, 0x37df932b, 0xc4248289, 0xacf3ebc3,
-    0x5715f6b7, 0xef3478dd, 0xf267616f, 0xc148cbe4, 0x9052815e, 0x5e410fab, 0xb48a2465, 0x2eda7fa4,
-    0xe87b40e4, 0xe98ea084, 0x5889e9e1, 0xefd390fc, 0xdd07d35b, 0xdb485694, 0x38d7e5b2, 0x57720101,
-    0x730edebc, 0x5b643113, 0x94917e4f, 0x503c2fba, 0x646f1282, 0x7523d24a, 0xe0779695, 0xf9c17a8f,
-    0x7a5b2121, 0xd187b896, 0x29263a4d, 0xba510cdf, 0x81f47c9f, 0xad1163ed, 0xea7b5965, 0x1a00726e,
-    0x11403092, 0x00da6d77, 0x4a0cdd61, 0xad1f4603, 0x605bdfb0, 0x9eedc364, 0x22ebe6a8, 0xcee7d28a,
-    0xa0e736a0, 0x5564a6b9, 0x10853209, 0xc7eb8f37, 0x2de705ca, 0x8951570f, 0xdf09822b, 0xbd691a6c,
-    0xaa12e4f2, 0x87451c0f, 0xe0f6a27a, 0x3ada4819, 0x4cf1764f, 0x0d771c2b, 0x67cdb156, 0x350d8384,
-    0x5938fa0f, 0x42399ef3, 0x36997b07, 0x0e84093d, 0x4aa93e61, 0x8360d87b, 0x1fa98b0c, 0x1149382c,
-    0xe97625a5, 0x0614d1b7, 0x0e25244b, 0x0c768347, 0x589e8d82, 0x0d2059d1, 0xa466bb1e, 0xf8da0a82,
-    0x04f19130, 0xba6e4ec0, 0x99265164, 0x1ee7230d, 0x50b2ad80, 0xeaee6801, 0x8db2a283, 0xea8bf59e
+    0xe216300d,
+    0xbbddfffc,
+    0xa7ebdabd,
+    0x35648095,
+    0x7789f8b7,
+    0xe6c1121b,
+    0x0e241600,
+    0x052ce8b5,
+    0x11a9cfb0,
+    0xe5952f11,
+    0xece7990a,
+    0x9386d174,
+    0x2a42931c,
+    0x76e38111,
+    0xb12def3a,
+    0x37ddddfc,
+    0xde9adeb1,
+    0x0a0cc32c,
+    0xbe197029,
+    0x84a00940,
+    0xbb243a0f,
+    0xb4d137cf,
+    0xb44e79f0,
+    0x049eedfd,
+    0x0b15a15d,
+    0x480d3168,
+    0x8bbbde5a,
+    0x669ded42,
+    0xc7ece831,
+    0x3f8f95e7,
+    0x72df191b,
+    0x7580330d,
+    0x94074251,
+    0x5c7dcdfa,
+    0xabbe6d63,
+    0xaa402164,
+    0xb301d40a,
+    0x02e7d1ca,
+    0x53571dae,
+    0x7a3182a2,
+    0x12a8ddec,
+    0xfdaa335d,
+    0x176f43e8,
+    0x71fb46d4,
+    0x38129022,
+    0xce949ad4,
+    0xb84769ad,
+    0x965bd862,
+    0x82f3d055,
+    0x66fb9767,
+    0x15b80b4e,
+    0x1d5b47a0,
+    0x4cfde06f,
+    0xc28ec4b8,
+    0x57e8726e,
+    0x647a78fc,
+    0x99865d44,
+    0x608bd593,
+    0x6c200e03,
+    0x39dc5ff6,
+    0x5d0b00a3,
+    0xae63aff2,
+    0x7e8bd632,
+    0x70108c0c,
+    0xbbd35049,
+    0x2998df04,
+    0x980cf42a,
+    0x9b6df491,
+    0x9e7edd53,
+    0x06918548,
+    0x58cb7e07,
+    0x3b74ef2e,
+    0x522fffb1,
+    0xd24708cc,
+    0x1c7e27cd,
+    0xa4eb215b,
+    0x3cf1d2e2,
+    0x19b47a38,
+    0x424f7618,
+    0x35856039,
+    0x9d17dee7,
+    0x27eb35e6,
+    0xc9aff67b,
+    0x36baf5b8,
+    0x09c467cd,
+    0xc18910b1,
+    0xe11dbf7b,
+    0x06cd1af8,
+    0x7170c608,
+    0x2d5e3354,
+    0xd4de495a,
+    0x64c6d006,
+    0xbcc0c62c,
+    0x3dd00db3,
+    0x708f8f34,
+    0x77d51b42,
+    0x264f620f,
+    0x24b8d2bf,
+    0x15c1b79e,
+    0x46a52564,
+    0xf8d7e54e,
+    0x3e378160,
+    0x7895cda5,
+    0x859c15a5,
+    0xe6459788,
+    0xc37bc75f,
+    0xdb07ba0c,
+    0x0676a3ab,
+    0x7f229b1e,
+    0x31842e7b,
+    0x24259fd7,
+    0xf8bef472,
+    0x835ffcb8,
+    0x6df4c1f2,
+    0x96f5b195,
+    0xfd0af0fc,
+    0xb0fe134c,
+    0xe2506d3d,
+    0x4f9b12ea,
+    0xf215f225,
+    0xa223736f,
+    0x9fb4c428,
+    0x25d04979,
+    0x34c713f8,
+    0xc4618187,
+    0xea7a6e98,
+    0x7cd16efc,
+    0x1436876c,
+    0xf1544107,
+    0xbedeee14,
+    0x56e9af27,
+    0xa04aa441,
+    0x3cf7c899,
+    0x92ecbae6,
+    0xdd67016d,
+    0x151682eb,
+    0xa842eedf,
+    0xfdba60b4,
+    0xf1907b75,
+    0x20e3030f,
+    0x24d8c29e,
+    0xe139673b,
+    0xefa63fb8,
+    0x71873054,
+    0xb6f2cf3b,
+    0x9f326442,
+    0xcb15a4cc,
+    0xb01a4504,
+    0xf1e47d8d,
+    0x844a1be5,
+    0xbae7dfdc,
+    0x42cbda70,
+    0xcd7dae0a,
+    0x57e85b7a,
+    0xd53f5af6,
+    0x20cf4d8c,
+    0xcea4d428,
+    0x79d130a4,
+    0x3486ebfb,
+    0x33d3cddc,
+    0x77853b53,
+    0x37effcb5,
+    0xc5068778,
+    0xe580b3e6,
+    0x4e68b8f4,
+    0xc5c8b37e,
+    0x0d809ea2,
+    0x398feb7c,
+    0x132a4f94,
+    0x43b7950e,
+    0x2fee7d1c,
+    0x223613bd,
+    0xdd06caa2,
+    0x37df932b,
+    0xc4248289,
+    0xacf3ebc3,
+    0x5715f6b7,
+    0xef3478dd,
+    0xf267616f,
+    0xc148cbe4,
+    0x9052815e,
+    0x5e410fab,
+    0xb48a2465,
+    0x2eda7fa4,
+    0xe87b40e4,
+    0xe98ea084,
+    0x5889e9e1,
+    0xefd390fc,
+    0xdd07d35b,
+    0xdb485694,
+    0x38d7e5b2,
+    0x57720101,
+    0x730edebc,
+    0x5b643113,
+    0x94917e4f,
+    0x503c2fba,
+    0x646f1282,
+    0x7523d24a,
+    0xe0779695,
+    0xf9c17a8f,
+    0x7a5b2121,
+    0xd187b896,
+    0x29263a4d,
+    0xba510cdf,
+    0x81f47c9f,
+    0xad1163ed,
+    0xea7b5965,
+    0x1a00726e,
+    0x11403092,
+    0x00da6d77,
+    0x4a0cdd61,
+    0xad1f4603,
+    0x605bdfb0,
+    0x9eedc364,
+    0x22ebe6a8,
+    0xcee7d28a,
+    0xa0e736a0,
+    0x5564a6b9,
+    0x10853209,
+    0xc7eb8f37,
+    0x2de705ca,
+    0x8951570f,
+    0xdf09822b,
+    0xbd691a6c,
+    0xaa12e4f2,
+    0x87451c0f,
+    0xe0f6a27a,
+    0x3ada4819,
+    0x4cf1764f,
+    0x0d771c2b,
+    0x67cdb156,
+    0x350d8384,
+    0x5938fa0f,
+    0x42399ef3,
+    0x36997b07,
+    0x0e84093d,
+    0x4aa93e61,
+    0x8360d87b,
+    0x1fa98b0c,
+    0x1149382c,
+    0xe97625a5,
+    0x0614d1b7,
+    0x0e25244b,
+    0x0c768347,
+    0x589e8d82,
+    0x0d2059d1,
+    0xa466bb1e,
+    0xf8da0a82,
+    0x04f19130,
+    0xba6e4ec0,
+    0x99265164,
+    0x1ee7230d,
+    0x50b2ad80,
+    0xeaee6801,
+    0x8db2a283,
+    0xea8bf59e,
 };
-
-#endif /* !defined(OSSL_LIBCRYPTO_CAST_CAST_S_H) */
diff --git a/crypto/chacha/asm/chacha-armv4.pl b/crypto/chacha/asm/chacha-armv4.pl
index 24acb742b0..cb5441ad8b 100755
--- a/crypto/chacha/asm/chacha-armv4.pl
+++ b/crypto/chacha/asm/chacha-armv4.pl
@@ -171,7 +171,7 @@ my @ret;
 }
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 #if defined(__thumb2__) || defined(__clang__)
 .syntax	unified
diff --git a/crypto/chacha/asm/chacha-armv8-sve.pl b/crypto/chacha/asm/chacha-armv8-sve.pl
index df5232d621..40454c3322 100755
--- a/crypto/chacha/asm/chacha-armv8-sve.pl
+++ b/crypto/chacha/asm/chacha-armv8-sve.pl
@@ -724,7 +724,7 @@ ___
 	my ($sve2flag) = ("x7");
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 .arch   armv8-a
 
diff --git a/crypto/chacha/asm/chacha-armv8.pl b/crypto/chacha/asm/chacha-armv8.pl
index ccbc816136..f500bf1eb5 100755
--- a/crypto/chacha/asm/chacha-armv8.pl
+++ b/crypto/chacha/asm/chacha-armv8.pl
@@ -132,7 +132,7 @@ my ($a3,$b3,$c3,$d3)=map(($_&~3)+(($_+1)&3),($a2,$b2,$c2,$d2));
 }
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 #ifndef	__KERNEL__
 .extern	OPENSSL_armcap_P
 .hidden	OPENSSL_armcap_P
diff --git a/crypto/chacha/asm/chacha-loongarch64.pl b/crypto/chacha/asm/chacha-loongarch64.pl
index e78f668927..d608c909a6 100644
--- a/crypto/chacha/asm/chacha-loongarch64.pl
+++ b/crypto/chacha/asm/chacha-loongarch64.pl
@@ -12,10 +12,10 @@ use strict;
 my $code;
 
 # Here is the scalar register layout for LoongArch.
-my ($zero,$ra,$tp,$sp,$fp)=("\$zero", "\$ra", "\$tp", "\$sp", "\$fp");
-my ($a0,$a1,$a2,$a3,$a4,$a5,$a6,$a7)=map("\$a$_",(0..7));
-my ($t0,$t1,$t2,$t3,$t4,$t5,$t6,$t7,$t8)=map("\$t$_",(0..8));
-my ($s0,$s1,$s2,$s3,$s4,$s5,$s6,$s7,$s8)=map("\$s$_",(0..8));
+my ($zero,$ra,$tp,$sp,$fp)=map("\$r$_",(0..3,22));
+my ($a0,$a1,$a2,$a3,$a4,$a5,$a6,$a7)=map("\$r$_",(4..11));
+my ($t0,$t1,$t2,$t3,$t4,$t5,$t6,$t7,$t8,$x)=map("\$r$_",(12..21));
+my ($s0,$s1,$s2,$s3,$s4,$s5,$s6,$s7,$s8)=map("\$r$_",(23..31));
 
 # The saved floating-point registers in the LP64D ABI.  In LoongArch
 # with vector extension, the low 64 bits of a vector register alias with
@@ -46,7 +46,7 @@ open STDOUT,">$output";
 my ($out, $inp, $len, $key, $counter) = ($a0, $a1, $a2, $a3, $a4);
 
 $code .= <&1` =~ /((?:clang|LLVM) version|based on LLVM) ([0-9]+\.[0-9]+)/ &&
 		$2>=3.0);	# first version supporting AVX
 
-$ymm=1 if ($xmm && !$ymm &&
-		`$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__` =~ /#define __clang_major__.([0-9]+)/ &&
-		$1>=11); #icx started with clang 11
-
 $a="eax";
 ($b,$b_)=("ebx","ebp");
 ($c,$c_)=("ecx","esi");
diff --git a/crypto/chacha/asm/chacha-x86_64.pl b/crypto/chacha/asm/chacha-x86_64.pl
index ed54836dbf..9e5e1ba1e1 100755
--- a/crypto/chacha/asm/chacha-x86_64.pl
+++ b/crypto/chacha/asm/chacha-x86_64.pl
@@ -91,13 +91,6 @@ if (!$avx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([0
 	$avx = ($2>=3.0) + ($2>3.0);
 }
 
-if (!$avx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$avx = ($1>=11); #icx started with clang 11
-	}
-}
-
 open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\""
     or die "can't call $xlate: $!";
 *STDOUT=*OUT;
diff --git a/crypto/chacha/asm/chachap10-ppc.pl b/crypto/chacha/asm/chachap10-ppc.pl
index 10f8a57749..ef43a117ae 100755
--- a/crypto/chacha/asm/chachap10-ppc.pl
+++ b/crypto/chacha/asm/chachap10-ppc.pl
@@ -501,7 +501,7 @@ my ($xv8,$xv9,$xv10,$xv11,$xv12,$xv13,$xv14,$xv15,$xv16,$xv17) = map("v$_",(8..1
 my ($xv18,$xv19,$xv20,$xv21) = map("v$_",(18..21));
 my ($xv22,$xv23,$xv24,$xv25,$xv26) = map("v$_",(22..26));
 
-my $FRAME=$LOCALS+64+9*16+13*8+4*16;	# 8*16 for v24-v31 offload, 13*8 for f14-f26, 4*16 for v20-v23
+my $FRAME=$LOCALS+64+9*16;	# 8*16 is for v24-v31 offload
 
 sub VSX_lane_ROUND_8x {
 my ($a0,$b0,$c0,$d0,$a4,$b4,$c4,$d4)=@_;
@@ -665,28 +665,7 @@ $code.=<<___;
 	addi	r11,r11,32
 	stvx	v30,r10,$sp
 	stvx	v31,r11,$sp
-	stfd	f14,`$LOCALS+64+9*16+0*8`($sp)	# save FPR14-FPR26 (callee-saved per ELFv2 ABI)
-	stfd	f15,`$LOCALS+64+9*16+1*8`($sp)
-	stfd	f16,`$LOCALS+64+9*16+2*8`($sp)
-	stfd	f17,`$LOCALS+64+9*16+3*8`($sp)
-	stfd	f18,`$LOCALS+64+9*16+4*8`($sp)
-	stfd	f19,`$LOCALS+64+9*16+5*8`($sp)
-	stfd	f20,`$LOCALS+64+9*16+6*8`($sp)
-	stfd	f21,`$LOCALS+64+9*16+7*8`($sp)
-	stfd	f22,`$LOCALS+64+9*16+8*8`($sp)
-	stfd	f23,`$LOCALS+64+9*16+9*8`($sp)
-	stfd	f24,`$LOCALS+64+9*16+10*8`($sp)
-	stfd	f25,`$LOCALS+64+9*16+11*8`($sp)
-	be?stfd	f26,`$LOCALS+64+9*16+12*8`($sp)	# BE only
-	li	r10,`$LOCALS+64+9*16+13*8+15`
-	li	r11,`$LOCALS+64+9*16+13*8+31`
-	stvx	v20,r10,$sp			# save VMX v20-v23 (callee-saved per ELFv2 ABI)
-	addi	r10,r10,32
-	stvx	v21,r11,$sp
-	addi	r11,r11,32
-	stvx	v22,r10,$sp
-	stvx	v23,r11,$sp
-	stw	r12,`$LOCALS+64+9*16-4`($sp)		# save vrsave
+	stw	r12,`$FRAME-4`($sp)		# save vrsave
 	li	r12,-4096+63
 	$PUSH	r0, `$FRAME+$LRSAVE`($sp)
 	mtspr	256,r12				# preserve 29 AltiVec registers
@@ -1180,28 +1159,7 @@ $code.=<<___;
 	bne	Loop_outer_vsx_8x
 
 Ldone_vsx_8x:
-	lwz	r12,`$LOCALS+64+9*16-4`($sp)		# pull vrsave
-	lfd	f14,`$LOCALS+64+9*16+0*8`($sp)	# restore FPR14-FPR26 (callee-saved per ELFv2 ABI)
-	lfd	f15,`$LOCALS+64+9*16+1*8`($sp)
-	lfd	f16,`$LOCALS+64+9*16+2*8`($sp)
-	lfd	f17,`$LOCALS+64+9*16+3*8`($sp)
-	lfd	f18,`$LOCALS+64+9*16+4*8`($sp)
-	lfd	f19,`$LOCALS+64+9*16+5*8`($sp)
-	lfd	f20,`$LOCALS+64+9*16+6*8`($sp)
-	lfd	f21,`$LOCALS+64+9*16+7*8`($sp)
-	lfd	f22,`$LOCALS+64+9*16+8*8`($sp)
-	lfd	f23,`$LOCALS+64+9*16+9*8`($sp)
-	lfd	f24,`$LOCALS+64+9*16+10*8`($sp)
-	lfd	f25,`$LOCALS+64+9*16+11*8`($sp)
-	be?lfd	f26,`$LOCALS+64+9*16+12*8`($sp)	# BE only
-	li	r10,`$LOCALS+64+9*16+13*8+15`
-	li	r11,`$LOCALS+64+9*16+13*8+31`
-	lvx	v20,r10,$sp			# restore VMX v20-v23 (callee-saved per ELFv2 ABI)
-	addi	r10,r10,32
-	lvx	v21,r11,$sp
-	addi	r11,r11,32
-	lvx	v22,r10,$sp
-	lvx	v23,r11,$sp
+	lwz	r12,`$FRAME-4`($sp)		# pull vrsave
 	li	r10,`15+$LOCALS+64`
 	li	r11,`31+$LOCALS+64`
 	$POP	r0, `$FRAME+$LRSAVE`($sp)
diff --git a/crypto/chacha/chacha_enc.c b/crypto/chacha/chacha_enc.c
index c7c36b9c54..3cd4f0188d 100644
--- a/crypto/chacha/chacha_enc.c
+++ b/crypto/chacha/chacha_enc.c
@@ -9,33 +9,34 @@
 
 /* Adapted from the public domain code by D. Bernstein from SUPERCOP. */
 
-#include 
 #include 
 
 #include "internal/endian.h"
 #include "crypto/chacha.h"
 #include "crypto/ctype.h"
 
+typedef unsigned int u32;
+typedef unsigned char u8;
 typedef union {
-    uint32_t u[16];
-    uint8_t c[64];
+    u32 u[16];
+    u8 c[64];
 } chacha_buf;
 
 #define ROTATE(v, n) (((v) << (n)) | ((v) >> (32 - (n))))
 
 #ifndef PEDANTIC
-#if defined(__GNUC__) && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM)
+#if defined(__GNUC__) && __GNUC__ >= 2 && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM)
 #if defined(__riscv_zbb) || defined(__riscv_zbkb)
 #if __riscv_xlen == 64
 #undef ROTATE
-#define ROTATE(x, n) ({ uint32_t ret;                   \
+#define ROTATE(x, n) ({ u32 ret;                   \
                         asm ("roriw %0, %1, %2"        \
                         : "=r"(ret)                    \
                         : "r"(x), "i"(32 - (n))); ret; })
 #endif
 #if __riscv_xlen == 32
 #undef ROTATE
-#define ROTATE(x, n) ({ uint32_t ret;                   \
+#define ROTATE(x, n) ({ u32 ret;                   \
                         asm ("rori %0, %1, %2"         \
                         : "=r"(ret)                    \
                         : "r"(x), "i"(32 - (n))); ret; })
@@ -44,12 +45,12 @@ typedef union {
 #endif
 #endif
 
-#define U32TO8_LITTLE(p, v)          \
-    do {                             \
-        (p)[0] = (uint8_t)(v >> 0);  \
-        (p)[1] = (uint8_t)(v >> 8);  \
-        (p)[2] = (uint8_t)(v >> 16); \
-        (p)[3] = (uint8_t)(v >> 24); \
+#define U32TO8_LITTLE(p, v)     \
+    do {                        \
+        (p)[0] = (u8)(v >> 0);  \
+        (p)[1] = (u8)(v >> 8);  \
+        (p)[2] = (u8)(v >> 16); \
+        (p)[3] = (u8)(v >> 24); \
     } while (0)
 
 /* QUARTERROUND updates a, b, c, d with a ChaCha "quarter" round. */
@@ -61,9 +62,9 @@ typedef union {
 
 /* chacha_core performs 20 rounds of ChaCha on the input words in
  * |input| and writes the 64 output bytes to |output|. */
-static void chacha20_core(chacha_buf *output, const uint32_t input[16])
+static void chacha20_core(chacha_buf *output, const u32 input[16])
 {
-    uint32_t x[16];
+    u32 x[16];
     int i;
     DECLARE_IS_ENDIAN;
 
@@ -97,23 +98,23 @@ void ChaCha20_ctr32(unsigned char *out, const unsigned char *inp, size_t len,
     const unsigned int key[8], const unsigned int counter[4])
 #endif
 {
-    uint32_t input[16];
+    u32 input[16];
     chacha_buf buf;
     size_t todo, i;
 
     /* sigma constant "expand 32-byte k" in little-endian encoding */
-    input[0] = ((uint32_t)ossl_toascii('e')) | ((uint32_t)ossl_toascii('x') << 8)
-        | ((uint32_t)ossl_toascii('p') << 16)
-        | ((uint32_t)ossl_toascii('a') << 24);
-    input[1] = ((uint32_t)ossl_toascii('n')) | ((uint32_t)ossl_toascii('d') << 8)
-        | ((uint32_t)ossl_toascii(' ') << 16)
-        | ((uint32_t)ossl_toascii('3') << 24);
-    input[2] = ((uint32_t)ossl_toascii('2')) | ((uint32_t)ossl_toascii('-') << 8)
-        | ((uint32_t)ossl_toascii('b') << 16)
-        | ((uint32_t)ossl_toascii('y') << 24);
-    input[3] = ((uint32_t)ossl_toascii('t')) | ((uint32_t)ossl_toascii('e') << 8)
-        | ((uint32_t)ossl_toascii(' ') << 16)
-        | ((uint32_t)ossl_toascii('k') << 24);
+    input[0] = ((u32)ossl_toascii('e')) | ((u32)ossl_toascii('x') << 8)
+        | ((u32)ossl_toascii('p') << 16)
+        | ((u32)ossl_toascii('a') << 24);
+    input[1] = ((u32)ossl_toascii('n')) | ((u32)ossl_toascii('d') << 8)
+        | ((u32)ossl_toascii(' ') << 16)
+        | ((u32)ossl_toascii('3') << 24);
+    input[2] = ((u32)ossl_toascii('2')) | ((u32)ossl_toascii('-') << 8)
+        | ((u32)ossl_toascii('b') << 16)
+        | ((u32)ossl_toascii('y') << 24);
+    input[3] = ((u32)ossl_toascii('t')) | ((u32)ossl_toascii('e') << 8)
+        | ((u32)ossl_toascii(' ') << 16)
+        | ((u32)ossl_toascii('k') << 24);
 
     input[4] = key[0];
     input[5] = key[1];
diff --git a/crypto/chacha/chacha_ppc.c b/crypto/chacha/chacha_ppc.c
index d2e0a68baa..b36881a833 100644
--- a/crypto/chacha/chacha_ppc.c
+++ b/crypto/chacha/chacha_ppc.c
@@ -12,7 +12,7 @@
 
 #include 
 #include "crypto/chacha.h"
-#include "arch/ppc_arch.h"
+#include "crypto/ppc_arch.h"
 
 void ChaCha20_ctr32_int(unsigned char *out, const unsigned char *inp,
     size_t len, const unsigned int key[8],
diff --git a/crypto/chacha/chacha_riscv.c b/crypto/chacha/chacha_riscv.c
index e3e24c99fa..c9f17b35d8 100644
--- a/crypto/chacha/chacha_riscv.c
+++ b/crypto/chacha/chacha_riscv.c
@@ -38,7 +38,7 @@
 
 #include 
 #include "crypto/chacha.h"
-#include "arch/riscv_arch.h"
+#include "crypto/riscv_arch.h"
 
 void ChaCha20_ctr32_v_zbb_zvkb(unsigned char *out, const unsigned char *inp,
     size_t len, const unsigned int key[8],
diff --git a/crypto/cmp/cmp_client.c b/crypto/cmp/cmp_client.c
index 60c769af93..3e5973158d 100644
--- a/crypto/cmp/cmp_client.c
+++ b/crypto/cmp/cmp_client.c
@@ -10,7 +10,6 @@
  */
 
 #include "cmp_local.h"
-#include 
 
 #define IS_CREP(t) ((t) == OSSL_CMP_PKIBODY_IP || (t) == OSSL_CMP_PKIBODY_CP \
     || (t) == OSSL_CMP_PKIBODY_KUP)
@@ -141,7 +140,6 @@ static int send_receive_check(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *req,
     int time_left;
     OSSL_CMP_transfer_cb_t transfer_cb = ctx->transfer_cb;
 
-    ctx->status = OSSL_CMP_PKISTATUS_trans;
 #ifndef OPENSSL_NO_HTTP
     if (transfer_cb == NULL)
         transfer_cb = OSSL_CMP_MSG_http_perform;
@@ -168,7 +166,7 @@ static int send_receive_check(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *req,
     /* should print error queue since transfer_cb may call ERR_clear_error() */
     OSSL_CMP_CTX_print_errors(ctx);
 
-    if (ctx->server != NULL || ctx->transfer_cb != NULL)
+    if (ctx->server != NULL)
         ossl_cmp_log1(INFO, ctx, "sending %s", req_type_str);
 
     *rep = (*transfer_cb)(ctx, req);
@@ -182,7 +180,6 @@ static int send_receive_check(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *req,
         return 0;
     }
 
-    ctx->status = OSSL_CMP_PKISTATUS_checking_response;
     bt = OSSL_CMP_MSG_get_bodytype(*rep);
     /*
      * The body type in the 'bt' variable is not yet verified.
@@ -278,15 +275,11 @@ static int poll_for_response(OSSL_CMP_CTX *ctx, int sleep, int rid,
         "received 'waiting' PKIStatus, starting to poll for response");
     *rep = NULL;
     for (;;) {
-        int bak = ctx->status;
-
-        ctx->status = OSSL_CMP_PKISTATUS_request;
         if ((preq = ossl_cmp_pollReq_new(ctx, rid)) == NULL)
             goto err;
 
         if (!send_receive_check(ctx, preq, &prep, OSSL_CMP_PKIBODY_POLLREP))
             goto err;
-        ctx->status = bak;
 
         /* handle potential pollRep */
         if (OSSL_CMP_MSG_get_bodytype(prep) == OSSL_CMP_PKIBODY_POLLREP) {
@@ -310,7 +303,7 @@ static int poll_for_response(OSSL_CMP_CTX *ctx, int sleep, int rid,
             }
             if (check_after < 0 || (uint64_t)check_after > (sleep ? ULONG_MAX / 1000 : INT_MAX)) {
                 ERR_raise(ERR_LIB_CMP, CMP_R_CHECKAFTER_OUT_OF_RANGE);
-                if (BIO_snprintf(str, OSSL_CMP_PKISI_BUFLEN, "value = %" PRId64,
+                if (BIO_snprintf(str, OSSL_CMP_PKISI_BUFLEN, "value = %jd",
                         check_after)
                     >= 0)
                     ERR_add_error_data(1, str);
@@ -342,7 +335,6 @@ static int poll_for_response(OSSL_CMP_CTX *ctx, int sleep, int rid,
                 int64_t time_left = (int64_t)(ctx->end_time - exp - time(NULL));
 
                 if (time_left <= 0) {
-                    ctx->status = OSSL_CMP_PKISTATUS_trans;
                     ERR_raise(ERR_LIB_CMP, CMP_R_TOTAL_TIMEOUT);
                     goto err;
                 }
@@ -454,9 +446,7 @@ int ossl_cmp_exchange_certConf(OSSL_CMP_CTX *ctx, int certReqId,
     OSSL_CMP_MSG *certConf;
     OSSL_CMP_MSG *PKIconf = NULL;
     int res = 0;
-    int bak = ctx->status;
 
-    ctx->status = OSSL_CMP_PKISTATUS_request;
     /* OSSL_CMP_certConf_new() also checks if all necessary options are set */
     certConf = ossl_cmp_certConf_new(ctx, certReqId, fail_info, txt);
     if (certConf == NULL)
@@ -465,9 +455,6 @@ int ossl_cmp_exchange_certConf(OSSL_CMP_CTX *ctx, int certReqId,
     res = send_receive_also_delayed(ctx, certConf, &PKIconf,
         OSSL_CMP_PKIBODY_PKICONF);
 
-    if (res)
-        ctx->status = bak;
-
 err:
     OSSL_CMP_MSG_free(certConf);
     OSSL_CMP_MSG_free(PKIconf);
@@ -483,7 +470,6 @@ int ossl_cmp_exchange_error(OSSL_CMP_CTX *ctx, int status, int fail_info,
     OSSL_CMP_MSG *PKIconf = NULL;
     int res = 0;
 
-    ctx->status = OSSL_CMP_PKISTATUS_request;
     /* not overwriting ctx->status on error exchange */
     if ((si = OSSL_CMP_STATUSINFO_new(status, fail_info, txt)) == NULL)
         goto err;
@@ -493,7 +479,6 @@ int ossl_cmp_exchange_error(OSSL_CMP_CTX *ctx, int status, int fail_info,
 
     res = send_receive_also_delayed(ctx, error,
         &PKIconf, OSSL_CMP_PKIBODY_PKICONF);
-    ctx->status = OSSL_CMP_PKISTATUS_rejected_by_client;
 
 err:
     OSSL_CMP_MSG_free(error);
@@ -796,7 +781,7 @@ retry:
         ERR_raise_data(ERR_LIB_CMP, CMP_R_CERTIFICATE_NOT_ACCEPTED,
             "rejecting newly enrolled cert with subject: %s; %s",
             subj, txt);
-        ctx->status = OSSL_CMP_PKISTATUS_rejected_by_client;
+        ctx->status = OSSL_CMP_PKISTATUS_rejection;
         ret = 0;
     }
     OPENSSL_free(subj);
@@ -818,6 +803,7 @@ static int initial_certreq(OSSL_CMP_CTX *ctx,
     if ((req = ossl_cmp_certreq_new(ctx, req_type, crm)) == NULL)
         return 0;
 
+    ctx->status = OSSL_CMP_PKISTATUS_trans;
     res = send_receive_check(ctx, req, p_rep, rep_type);
     OSSL_CMP_MSG_free(req);
     return res;
@@ -923,6 +909,7 @@ int OSSL_CMP_exec_RR_ses(OSSL_CMP_CTX *ctx)
     if ((rr = ossl_cmp_rr_new(ctx)) == NULL)
         goto end;
 
+    ctx->status = OSSL_CMP_PKISTATUS_trans;
     if (!send_receive_also_delayed(ctx, rr, &rp, OSSL_CMP_PKIBODY_RP))
         goto end;
 
@@ -1042,6 +1029,7 @@ STACK_OF(OSSL_CMP_ITAV) *OSSL_CMP_exec_GENM_ses(OSSL_CMP_CTX *ctx)
     if ((genm = ossl_cmp_genm_new(ctx)) == NULL)
         goto err;
 
+    ctx->status = OSSL_CMP_PKISTATUS_trans;
     if (!send_receive_also_delayed(ctx, genm, &genp, OSSL_CMP_PKIBODY_GENP))
         goto err;
     ctx->status = OSSL_CMP_PKISTATUS_accepted;
diff --git a/crypto/cmp/cmp_ctx.c b/crypto/cmp/cmp_ctx.c
index da8277f5fe..979ce7fa97 100644
--- a/crypto/cmp/cmp_ctx.c
+++ b/crypto/cmp/cmp_ctx.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2007-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright Nokia 2007-2019
  * Copyright Siemens AG 2015-2019
  *
@@ -81,18 +81,11 @@ err:
 
 static int cmp_ctx_set_md(OSSL_CMP_CTX *ctx, EVP_MD **pmd, int nid)
 {
-    const char *name = OBJ_nid2sn(nid);
-    EVP_MD *md;
-
-    if (name == NULL) {
-        ERR_raise_data(ERR_LIB_CMP, CMP_R_UNKNOWN_ALGORITHM_ID, "nid=%d", nid);
-        return 0;
-    }
-    md = EVP_MD_fetch(ctx->libctx, name, ctx->propq);
+    EVP_MD *md = EVP_MD_fetch(ctx->libctx, OBJ_nid2sn(nid), ctx->propq);
     /* fetching in advance to be able to throw error early if unsupported */
 
     if (md == NULL) {
-        ERR_raise_data(ERR_LIB_CMP, CMP_R_UNSUPPORTED_ALGORITHM, "name=%s,nid=%d", name, nid);
+        ERR_raise(ERR_LIB_CMP, CMP_R_UNSUPPORTED_ALGORITHM);
         return 0;
     }
     EVP_MD_free(*pmd);
@@ -129,20 +122,11 @@ OSSL_CMP_CTX *OSSL_CMP_CTX_new(OSSL_LIB_CTX *libctx, const char *propq)
         goto err;
     }
 
-    /*
-     * https://www.rfc-editor.org/rfc/rfc9045.html#name-password-based-message-auth says:
-     * The salt SHOULD be at least 8 octets (64 bits) long.
-     */
     ctx->pbm_slen = 16;
     if (!cmp_ctx_set_md(ctx, &ctx->pbm_owf, NID_sha256))
         goto err;
-    ctx->pbm_itercnt = 1024;
+    ctx->pbm_itercnt = 500;
     ctx->pbm_mac = NID_hmac_sha1;
-    /*
-     * For maximal interoperability with existing deployments, by default using HMAC-SHA1
-     * as required in https://www.rfc-editor.org/rfc/rfc4211.html#section-4.4:
-     * All implementations MUST support SHA-1.
-     */
 
     if (!cmp_ctx_set_md(ctx, &ctx->digest, NID_sha256))
         goto err;
@@ -750,7 +734,7 @@ DEFINE_OSSL_set1_up_ref(OSSL_CMP_CTX, oldCert, X509)
      */
     DEFINE_OSSL_set0(ossl_cmp_ctx, newCert, X509)
 
-    /* Get successfully validated sender cert, if any, of current transaction */
+    /* Get successfully validated server cert, if any, of current transaction */
     DEFINE_OSSL_CMP_CTX_get0(validatedSrvCert, X509)
 
     /*
@@ -925,9 +909,6 @@ DEFINE_set1_ASN1_OCTET_STRING(OSSL_CMP_CTX, transactionID)
     case OSSL_CMP_OPT_UNPROTECTED_ERRORS:
         ctx->unprotectedErrors = val;
         break;
-    case OSSL_CMP_OPT_NONMATCHED_ERROR_NONCES:
-        ctx->nonmatchedErrorNonces = val;
-        break;
     case OSSL_CMP_OPT_NO_CACHE_EXTRACERTS:
         ctx->noCacheExtraCerts = val;
         break;
@@ -987,7 +968,7 @@ DEFINE_set1_ASN1_OCTET_STRING(OSSL_CMP_CTX, transactionID)
         ctx->revocationReason = val;
         break;
     default:
-        ERR_raise_data(ERR_LIB_CMP, CMP_R_INVALID_OPTION, "%d", opt);
+        ERR_raise(ERR_LIB_CMP, CMP_R_INVALID_OPTION);
         return 0;
     }
 
@@ -1016,8 +997,6 @@ int OSSL_CMP_CTX_get_option(const OSSL_CMP_CTX *ctx, int opt)
         return ctx->unprotectedSend;
     case OSSL_CMP_OPT_UNPROTECTED_ERRORS:
         return ctx->unprotectedErrors;
-    case OSSL_CMP_OPT_NONMATCHED_ERROR_NONCES:
-        return ctx->nonmatchedErrorNonces;
     case OSSL_CMP_OPT_NO_CACHE_EXTRACERTS:
         return ctx->noCacheExtraCerts;
     case OSSL_CMP_OPT_VALIDITY_DAYS:
@@ -1051,7 +1030,7 @@ int OSSL_CMP_CTX_get_option(const OSSL_CMP_CTX *ctx, int opt)
     case OSSL_CMP_OPT_REVOCATION_REASON:
         return ctx->revocationReason;
     default:
-        ERR_raise_data(ERR_LIB_CMP, CMP_R_INVALID_OPTION, "%d", opt);
+        ERR_raise(ERR_LIB_CMP, CMP_R_INVALID_OPTION);
         return -1;
     }
 }
diff --git a/crypto/cmp/cmp_genm.c b/crypto/cmp/cmp_genm.c
index 8e974297fd..1966be60ec 100644
--- a/crypto/cmp/cmp_genm.c
+++ b/crypto/cmp/cmp_genm.c
@@ -39,7 +39,7 @@ static int ossl_X509_check(OSSL_CMP_CTX *ctx, const char *source, X509 *cert,
     int ret, err;
     OSSL_CMP_severity level = vpm == NULL ? OSSL_CMP_LOG_WARNING : OSSL_CMP_LOG_ERR;
 
-    ret = X509_check_certificate_times(vpm, cert, &err);
+    ret = ossl_x509_check_certificate_times(vpm, cert, &err);
     if (!ret) {
         const char *msg;
 
@@ -112,8 +112,7 @@ static OSSL_CMP_ITAV *get_genm_itav(OSSL_CMP_CTX *ctx,
     req = NULL;
     itavs = OSSL_CMP_exec_GENM_ses(ctx);
     if (itavs == NULL) {
-        if (OSSL_CMP_CTX_get_status(ctx) != OSSL_CMP_PKISTATUS_request
-            && OSSL_CMP_CTX_get_status(ctx) != OSSL_CMP_PKISTATUS_rejection)
+        if (OSSL_CMP_CTX_get_status(ctx) != OSSL_CMP_PKISTATUS_request)
             ERR_raise_data(ERR_LIB_CMP, CMP_R_GETTING_GENP,
                 "with infoType %s", desc);
         return NULL;
@@ -133,7 +132,8 @@ static OSSL_CMP_ITAV *get_genm_itav(OSSL_CMP_CTX *ctx,
     for (i = 0; i < n; i++) {
         OSSL_CMP_ITAV *itav = sk_OSSL_CMP_ITAV_shift(itavs);
         ASN1_OBJECT *obj = OSSL_CMP_ITAV_get0_type(itav);
-        char name[128];
+        char name[128] = "genp contains InfoType '";
+        size_t offset = strlen(name);
 
         if (OBJ_obj2nid(obj) == expected) {
             for (i++; i < n; i++)
@@ -142,15 +142,13 @@ static OSSL_CMP_ITAV *get_genm_itav(OSSL_CMP_CTX *ctx,
             return itav;
         }
 
-        if (OBJ_obj2txt(name, sizeof(name), obj, 0) < 0)
-            name[0] = '\0';
-        ossl_cmp_log2(WARN, ctx,
-            "genp contains InfoType '%s' while expecting 'id-it-%s'",
-            name[0] == '\0' ? "" : name, desc);
+        if (OBJ_obj2txt(name + offset, (int)(sizeof(name) - offset), obj, 0) < 0)
+            strcat(name, "");
+        ossl_cmp_log2(WARN, ctx, "%s' while expecting 'id-it-%s'", name, desc);
         OSSL_CMP_ITAV_free(itav);
     }
     ERR_raise_data(ERR_LIB_CMP, CMP_R_INVALID_GENP,
-        "could not find any suitable ITAV for %s", desc);
+        "could not find any ITAV for %s", desc);
 
 err:
     sk_OSSL_CMP_ITAV_free(itavs);
@@ -223,7 +221,7 @@ static int selfsigned_verify_cb(int ok, X509_STORE_CTX *store_ctx)
         for (i = 0; i < sk_X509_num(trust); i++) {
             issuer = sk_X509_value(trust, i);
             if ((*check_issued)(store_ctx, cert, issuer)) {
-                if (X509_add_cert(chain, issuer, X509_ADD_FLAG_UP_REF))
+                if (X509_add_cert(chain, cert, X509_ADD_FLAG_UP_REF))
                     ok = 1;
                 break;
             }
@@ -256,7 +254,6 @@ static int verify_ss_cert(OSSL_LIB_CTX *libctx, const char *propq,
     if ((csc = X509_STORE_CTX_new_ex(libctx, propq)) == NULL
         || !X509_STORE_CTX_init(csc, ts, target, untrusted))
         goto err;
-    X509_STORE_CTX_set_flags(csc, X509_V_FLAG_CHECK_SS_SIGNATURE);
     X509_STORE_CTX_set_verify_cb(csc, selfsigned_verify_cb);
     ok = X509_verify_cert(csc) > 0;
 
@@ -275,8 +272,7 @@ verify_ss_cert_trans(OSSL_CMP_CTX *ctx, X509 *trusted /* may be NULL */,
     int res = 0;
 
     if (trusted != NULL) {
-        X509_VERIFY_PARAM *vpm = (ts == NULL) ? NULL
-                                              : X509_STORE_get0_param(ts);
+        X509_VERIFY_PARAM *vpm = X509_STORE_get0_param(ts);
 
         if ((ts = X509_STORE_new()) == NULL)
             return 0;
@@ -339,14 +335,11 @@ int OSSL_CMP_get1_rootCaKeyUpdate(OSSL_CMP_CTX *ctx,
         ERR_raise(ERR_LIB_CMP, CMP_R_INVALID_ROOTCAKEYUPDATE);
         goto end;
     }
-    if (my_oldWithNew != NULL) {
-        if (oldWithOld == NULL) {
-            ossl_cmp_log(WARN, ctx, "oldWithNew certificate received in genp for verifying oldWithOld, but oldWithOld was not provided");
-        } else if (!verify_ss_cert_trans(ctx, *newWithNew, my_oldWithNew,
-                       oldWithOld_copy, "oldWithOld")) {
-            ERR_raise(ERR_LIB_CMP, CMP_R_INVALID_ROOTCAKEYUPDATE);
-            goto end;
-        }
+    if (oldWithOld != NULL && my_oldWithNew != NULL
+        && !verify_ss_cert_trans(ctx, *newWithNew, my_oldWithNew,
+            oldWithOld_copy, "oldWithOld")) {
+        ERR_raise(ERR_LIB_CMP, CMP_R_INVALID_ROOTCAKEYUPDATE);
+        goto end;
     }
 
     if (!X509_up_ref(*newWithNew))
diff --git a/crypto/cmp/cmp_local.h b/crypto/cmp/cmp_local.h
index ac892f62bd..07475d6a43 100644
--- a/crypto/cmp/cmp_local.h
+++ b/crypto/cmp/cmp_local.h
@@ -1,5 +1,5 @@
 /*
- * Copyright 2007-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright Nokia 2007-2019
  * Copyright Siemens AG 2015-2019
  *
@@ -55,10 +55,9 @@ struct ossl_cmp_ctx_st {
      * certificate responses (ip/cp/kup), revocation responses (rp), and PKIConf
      */
     int unprotectedErrors;
-    int nonmatchedErrorNonces; /* accept missing/wrong transactionID or recipNonce in error msgs */
     int noCacheExtraCerts;
     X509 *srvCert; /* certificate used to identify the server */
-    X509 *validatedSrvCert; /* caches any already validated sender cert */
+    X509 *validatedSrvCert; /* caches any already validated server cert */
     X509_NAME *expected_sender; /* expected sender in header of response */
     X509_STORE *trusted; /* trust store maybe w CRLs and cert verify callback */
     STACK_OF(X509) *untrusted; /* untrusted (intermediate CA) certs */
@@ -819,7 +818,7 @@ int ossl_cmp_X509_STORE_add1_certs(X509_STORE *store, STACK_OF(X509) *certs,
     int only_self_issued);
 STACK_OF(X509) *ossl_cmp_X509_STORE_get1_certs(X509_STORE *store);
 int ossl_cmp_sk_ASN1_UTF8STRING_push_str(STACK_OF(ASN1_UTF8STRING) *sk,
-    const char *text, size_t len);
+    const char *text, int len);
 int ossl_cmp_asn1_octet_string_set1(ASN1_OCTET_STRING **tgt,
     const ASN1_OCTET_STRING *src);
 int ossl_cmp_asn1_octet_string_set1_bytes(ASN1_OCTET_STRING **tgt,
@@ -946,7 +945,7 @@ OSSL_CMP_MSG *ossl_cmp_certrep_new(OSSL_CMP_CTX *ctx, int bodytype,
     int certReqId, const OSSL_CMP_PKISI *si,
     X509 *cert, const EVP_PKEY *pkey,
     const X509 *encryption_recip,
-    const STACK_OF(X509) *chain, STACK_OF(X509) *caPubs,
+    STACK_OF(X509) *chain, STACK_OF(X509) *caPubs,
     int unprotectedErrors);
 OSSL_CMP_MSG *ossl_cmp_rr_new(OSSL_CMP_CTX *ctx);
 OSSL_CMP_MSG *ossl_cmp_rp_new(OSSL_CMP_CTX *ctx, const OSSL_CMP_PKISI *si,
diff --git a/crypto/cmp/cmp_msg.c b/crypto/cmp/cmp_msg.c
index abea670ce9..c72a7e09cd 100644
--- a/crypto/cmp/cmp_msg.c
+++ b/crypto/cmp/cmp_msg.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2007-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright Nokia 2007-2019
  * Copyright Siemens AG 2015-2019
  *
@@ -504,7 +504,7 @@ OSSL_CMP_MSG *ossl_cmp_certrep_new(OSSL_CMP_CTX *ctx, int bodytype,
     int certReqId, const OSSL_CMP_PKISI *si,
     X509 *cert, const EVP_PKEY *pkey,
     const X509 *encryption_recip,
-    const STACK_OF(X509) *chain, STACK_OF(X509) *caPubs,
+    STACK_OF(X509) *chain, STACK_OF(X509) *caPubs,
     int unprotectedErrors)
 {
     OSSL_CMP_MSG *msg = NULL;
@@ -824,13 +824,13 @@ OSSL_CMP_MSG *ossl_cmp_error_new(OSSL_CMP_CTX *ctx, const OSSL_CMP_PKISI *si,
             goto err;
         msg->body->value.error->errorDetails = ft;
         if (lib != NULL && *lib != '\0'
-            && !ossl_cmp_sk_ASN1_UTF8STRING_push_str(ft, lib, strlen(lib)))
+            && !ossl_cmp_sk_ASN1_UTF8STRING_push_str(ft, lib, -1))
             goto err;
         if (reason != NULL && *reason != '\0'
-            && !ossl_cmp_sk_ASN1_UTF8STRING_push_str(ft, reason, strlen(reason)))
+            && !ossl_cmp_sk_ASN1_UTF8STRING_push_str(ft, reason, -1))
             goto err;
         if (details != NULL
-            && !ossl_cmp_sk_ASN1_UTF8STRING_push_str(ft, details, strlen(details)))
+            && !ossl_cmp_sk_ASN1_UTF8STRING_push_str(ft, details, -1))
             goto err;
     }
 
diff --git a/crypto/cmp/cmp_protect.c b/crypto/cmp/cmp_protect.c
index c0dba8392d..651b3ff324 100644
--- a/crypto/cmp/cmp_protect.c
+++ b/crypto/cmp/cmp_protect.c
@@ -72,12 +72,8 @@ ASN1_BIT_STRING *ossl_cmp_calc_protection(const OSSL_CMP_CTX *ctx,
         prot_part_der_len = (size_t)len;
 
         pbm_str = (ASN1_STRING *)ppval;
-        pbm_str_uc = ASN1_STRING_get0_data(pbm_str);
-        if (ASN1_STRING_length_ex(pbm_str) > INT_MAX) {
-            ERR_raise(ERR_LIB_CMP, CMP_R_WRONG_ALGORITHM_OID);
-            goto end;
-        }
-        pbm = d2i_OSSL_CRMF_PBMPARAMETER(NULL, &pbm_str_uc, (long)ASN1_STRING_length_ex(pbm_str));
+        pbm_str_uc = pbm_str->data;
+        pbm = d2i_OSSL_CRMF_PBMPARAMETER(NULL, &pbm_str_uc, pbm_str->length);
         if (pbm == NULL) {
             ERR_raise(ERR_LIB_CMP, CMP_R_WRONG_ALGORITHM_OID);
             goto end;
@@ -85,14 +81,15 @@ ASN1_BIT_STRING *ossl_cmp_calc_protection(const OSSL_CMP_CTX *ctx,
 
         if (!OSSL_CRMF_pbm_new(ctx->libctx, ctx->propq,
                 pbm, prot_part_der, prot_part_der_len,
-                ASN1_STRING_get0_data(ctx->secretValue), ASN1_STRING_length_ex(ctx->secretValue),
+                ctx->secretValue->data, ctx->secretValue->length,
                 &protection, &sig_len))
             goto end;
 
         if (sig_len > INT_MAX || (prot = ASN1_BIT_STRING_new()) == NULL)
             goto end;
         /* OpenSSL by default encodes all bit strings as ASN.1 NamedBitList */
-        if (!ASN1_BIT_STRING_set1(prot, protection, (int)sig_len, 0)) {
+        ossl_asn1_string_set_bits_left(prot, 0);
+        if (!ASN1_BIT_STRING_set(prot, protection, (int)sig_len)) {
             ASN1_BIT_STRING_free(prot);
             prot = NULL;
         }
@@ -206,7 +203,7 @@ static X509_ALGOR *pbmac_algor(const OSSL_CMP_CTX *ctx)
         goto err;
     if ((pbm_der_len = i2d_OSSL_CRMF_PBMPARAMETER(pbm, &pbm_der)) < 0)
         goto err;
-    if (!ASN1_STRING_set_data(pbm_str, pbm_der, pbm_der_len))
+    if (!ASN1_STRING_set(pbm_str, pbm_der, pbm_der_len))
         goto err;
     alg = ossl_X509_ALGOR_from_nid(NID_id_PasswordBasedMAC,
         V_ASN1_SEQUENCE, pbm_str);
diff --git a/crypto/cmp/cmp_status.c b/crypto/cmp/cmp_status.c
index 063bbe808c..40e1ee671e 100644
--- a/crypto/cmp/cmp_status.c
+++ b/crypto/cmp/cmp_status.c
@@ -214,7 +214,7 @@ static char *snprint_PKIStatusInfo_parts(int status, int fail_info,
         for (i = 0; i < n_status_strings; i++) {
             text = sk_ASN1_UTF8STRING_value(status_strings, i);
             printed_chars = BIO_snprintf(write_ptr, bufsize, "\"%.*s\"%s",
-                (int)ASN1_STRING_length_ex(text),
+                ASN1_STRING_length(text),
                 ASN1_STRING_get0_data(text),
                 i < n_status_strings - 1 ? ", " : "");
             ADVANCE_BUFFER;
@@ -275,7 +275,7 @@ OSSL_CMP_PKISI *OSSL_CMP_STATUSINFO_new(int status, int fail_info,
 
     if (text != NULL) {
         if ((utf8_text = ASN1_UTF8STRING_new()) == NULL
-            || !ASN1_STRING_set_string(utf8_text, text))
+            || !ASN1_STRING_set(utf8_text, text, -1))
             goto err;
         if ((si->statusString = sk_ASN1_UTF8STRING_new_null()) == NULL)
             goto err;
diff --git a/crypto/cmp/cmp_util.c b/crypto/cmp/cmp_util.c
index f3a0c86d53..5c710addf2 100644
--- a/crypto/cmp/cmp_util.c
+++ b/crypto/cmp/cmp_util.c
@@ -219,7 +219,7 @@ int ossl_cmp_X509_STORE_add1_certs(X509_STORE *store, STACK_OF(X509) *certs,
 }
 
 int ossl_cmp_sk_ASN1_UTF8STRING_push_str(STACK_OF(ASN1_UTF8STRING) *sk,
-    const char *text, size_t len)
+    const char *text, int len)
 {
     ASN1_UTF8STRING *utf8string;
 
@@ -227,7 +227,7 @@ int ossl_cmp_sk_ASN1_UTF8STRING_push_str(STACK_OF(ASN1_UTF8STRING) *sk,
         return 0;
     if ((utf8string = ASN1_UTF8STRING_new()) == NULL)
         return 0;
-    if (!ASN1_STRING_set_data(utf8string, (const uint8_t *)text, len))
+    if (!ASN1_STRING_set(utf8string, text, len))
         goto err;
     if (!sk_ASN1_UTF8STRING_push(sk, utf8string))
         goto err;
diff --git a/crypto/cmp/cmp_vfy.c b/crypto/cmp/cmp_vfy.c
index 48014295e3..6d11c7ec0c 100644
--- a/crypto/cmp/cmp_vfy.c
+++ b/crypto/cmp/cmp_vfy.c
@@ -56,10 +56,8 @@ static int verify_signature(const OSSL_CMP_CTX *cmp_ctx,
 sig_err:
     res = ossl_x509_print_ex_brief(bio, cert, X509_FLAG_NO_EXTENSIONS);
     ERR_raise(ERR_LIB_CMP, CMP_R_ERROR_VALIDATING_SIGNATURE);
-    if (res) {
-        ERR_add_error_txt(NULL, "\n");
-        ERR_add_error_mem_bio(NULL, bio);
-    }
+    if (res)
+        ERR_add_error_mem_bio("\n", bio);
     res = 0;
 
 end:
@@ -267,7 +265,7 @@ static int cert_acceptable(const OSSL_CMP_CTX *ctx,
         return 0;
     }
 
-    if (!X509_check_certificate_times(vpm, cert, &err)) {
+    if (!ossl_x509_check_certificate_times(vpm, cert, &err)) {
         const char *message;
 
         switch (err) {
@@ -382,12 +380,13 @@ err:
     return valid;
 }
 
-/* checks protection of msg but not cert revocation nor cert chain */
 static int check_msg_given_cert(const OSSL_CMP_CTX *ctx, X509 *cert,
     const OSSL_CMP_MSG *msg)
 {
     return cert_acceptable(ctx, "previously validated", "sender cert",
-        cert, NULL, NULL, msg);
+               cert, NULL, NULL, msg)
+        && (check_cert_path(ctx, ctx->trusted, cert)
+            || check_cert_path_3gpp(ctx, msg, cert));
 }
 
 /*-
@@ -406,7 +405,7 @@ static int check_msg_with_certs(OSSL_CMP_CTX *ctx, const STACK_OF(X509) *certs,
     int i;
 
     if (sk_X509_num(certs) <= 0) {
-        ossl_cmp_log1(INFO, ctx, "no %s", desc);
+        ossl_cmp_log1(WARN, ctx, "no %s", desc);
         return 0;
     }
 
@@ -426,7 +425,7 @@ static int check_msg_with_certs(OSSL_CMP_CTX *ctx, const STACK_OF(X509) *certs,
         }
     }
     if (in_extraCerts && n_acceptable_certs == 0)
-        ossl_cmp_log1(WARN, ctx, "no acceptable %s", desc);
+        ossl_cmp_warn(ctx, "no acceptable cert in extraCerts");
     return 0;
 }
 
@@ -497,38 +496,34 @@ static int check_msg_find_cert(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg)
     (void)ERR_set_mark();
     ctx->log_cb = NULL; /* temporarily disable logging */
 
+    /*
+     * try first cached scrt, used successfully earlier in same transaction,
+     * for validating this and any further msgs where extraCerts may be left out
+     */
     if (scrt != NULL) {
-        /*-
-         * try first using cached message sender cert (in 'scrt' variable),
-         * which was used successfully earlier in the same transaction
-         * (assuming that the certificate itself was not revoked meanwhile and
-         *  is a good guess for use in validating also the current message)
-         */
         if (check_msg_given_cert(ctx, scrt, msg)) {
             ctx->log_cb = backup_log_cb;
             (void)ERR_pop_to_mark();
             return 1;
         }
         /* cached sender cert has shown to be no more successfully usable */
+        (void)ossl_cmp_ctx_set1_validatedSrvCert(ctx, NULL);
         /* re-do the above check (just) for adding diagnostic information */
         ossl_cmp_info(ctx,
             "trying to verify msg signature with previously validated cert");
-        ctx->log_cb = backup_log_cb;
         (void)check_msg_given_cert(ctx, scrt, msg);
-        ctx->log_cb = NULL;
-        (void)ossl_cmp_ctx_set1_validatedSrvCert(ctx, NULL); /* this invalidates scrt */
     }
 
     res = check_msg_all_certs(ctx, msg, 0 /* using ctx->trusted */)
         || check_msg_all_certs(ctx, msg, 1 /* 3gpp */);
-
-    ctx->log_cb = backup_log_cb; /* re-enable logging */
-    /* discard any previous diagnostic information on trying to use certs */
-    (void)ERR_pop_to_mark();
-
-    if (res)
+    ctx->log_cb = backup_log_cb;
+    if (res) {
+        /* discard any diagnostic information on trying to use certs */
+        (void)ERR_pop_to_mark();
         goto end;
+    }
     /* failed finding a sender cert that verifies the message signature */
+    (void)ERR_clear_last_mark();
 
     sname = X509_NAME_oneline(sender->d.directoryName, NULL, 0);
     skid_str = skid == NULL ? NULL : i2s_ASN1_OCTET_STRING(NULL, skid);
@@ -651,7 +646,7 @@ int OSSL_CMP_validate_msg(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg)
         scrt = ctx->srvCert;
         if (scrt == NULL) {
             if (ctx->trusted == NULL && ctx->secretValue != NULL) {
-                ossl_cmp_info(ctx, "no trust store nor pinned sender cert available for verifying signature-based CMP message protection");
+                ossl_cmp_info(ctx, "no trust store nor pinned server cert available for verifying signature-based CMP message protection");
                 ERR_raise(ERR_LIB_CMP, CMP_R_MISSING_TRUST_ANCHOR);
                 return 0;
             }
@@ -665,7 +660,7 @@ int OSSL_CMP_validate_msg(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg)
             /* use ctx->srvCert for signature check even if not acceptable */
             if (verify_signature(ctx, msg, scrt)) {
                 ossl_cmp_debug(ctx,
-                    "successfully validated signature-based CMP message protection using pinned sender cert");
+                    "successfully validated signature-based CMP message protection using pinned server cert");
                 return ossl_cmp_ctx_set1_validatedSrvCert(ctx, scrt);
             }
             ossl_cmp_warn(ctx, "CMP message signature verification failed");
@@ -676,35 +671,24 @@ int OSSL_CMP_validate_msg(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg)
     return 0;
 }
 
-static int check_transactionID_or_nonce(OSSL_CMP_CTX *ctx, const ASN1_OCTET_STRING *expected,
-    const ASN1_OCTET_STRING *actual, int bodytype, int reason)
+static int check_transactionID_or_nonce(ASN1_OCTET_STRING *expected,
+    ASN1_OCTET_STRING *actual, int reason)
 {
     if (expected != NULL
         && (actual == NULL || ASN1_OCTET_STRING_cmp(expected, actual) != 0)) {
 #ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
-        char *expected_str, *actual_str, *expected_msg, *actual_msg;
-        const int strict = bodytype != OSSL_CMP_PKIBODY_ERROR || !ctx->nonmatchedErrorNonces;
-        int res = 0;
+        char *expected_str, *actual_str;
 
-        if (reason == 0) /* at end of polling, overall check is not yet complete */
-            return res;
         expected_str = i2s_ASN1_OCTET_STRING(NULL, expected);
-        expected_msg = expected_str == NULL ? "?" : expected_str;
         actual_str = actual == NULL ? NULL : i2s_ASN1_OCTET_STRING(NULL, actual);
-        actual_msg = actual == NULL ? "(none)" : actual_str == NULL ? "?"
-                                                                    : actual_str;
-        if (strict) {
-            ERR_raise_data(ERR_LIB_CMP, reason, "expected = %s, actual = %s",
-                expected_msg, actual_msg);
-        } else {
-            ossl_cmp_log3(WARN, ctx, "ignoring missing or non-matching %s of error message, expected = %s, actual = %s",
-                reason == CMP_R_TRANSACTIONID_UNMATCHED ? "transactionID" : "recipNonce",
-                expected_msg, actual_msg);
-            res = 1;
-        }
+        ERR_raise_data(ERR_LIB_CMP, reason,
+            "expected = %s, actual = %s",
+            expected_str == NULL ? "?" : expected_str,
+            actual == NULL ? "(none)" : actual_str == NULL ? "?"
+                                                           : actual_str);
         OPENSSL_free(expected_str);
         OPENSSL_free(actual_str);
-        return res;
+        return 0;
 #endif
     }
     return 1;
@@ -735,13 +719,11 @@ int ossl_cmp_msg_check_update(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg,
 {
     OSSL_CMP_PKIHEADER *hdr;
     const X509_NAME *expected_sender;
-    int bodytype, end_of_polling;
     int num_untrusted, num_added, res;
 
     if (!ossl_assert(ctx != NULL && msg != NULL && msg->header != NULL))
         return 0;
     hdr = OSSL_CMP_MSG_get0_header(msg);
-    bodytype = OSSL_CMP_MSG_get_bodytype(msg);
 
     /* If expected_sender is given, validate sender name of received msg */
     expected_sender = ctx->expected_sender;
@@ -775,8 +757,6 @@ int ossl_cmp_msg_check_update(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg,
             return 0;
         }
     }
-
-    /* Ignoring recipient */
     /* Note: if recipient was NULL-DN it could be learned here if needed */
 
     num_added = sk_X509_num(msg->extraCerts);
@@ -838,7 +818,7 @@ int ossl_cmp_msg_check_update(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg,
 #endif
     }
 
-    if (bodytype < 0) {
+    if (OSSL_CMP_MSG_get_bodytype(msg) < 0) {
 #ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
         ERR_raise(ERR_LIB_CMP, CMP_R_PKIBODY_ERROR);
         return 0;
@@ -846,25 +826,30 @@ int ossl_cmp_msg_check_update(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg,
     }
 
     /* compare received transactionID with the expected one in previous msg */
-    if (!check_transactionID_or_nonce(ctx, ctx->transactionID, hdr->transactionID,
-            bodytype, CMP_R_TRANSACTIONID_UNMATCHED))
+    if (!check_transactionID_or_nonce(ctx->transactionID, hdr->transactionID,
+            CMP_R_TRANSACTIONID_UNMATCHED))
         return 0;
 
     /*
-     * Compare received nonce with the one we sent last.
-     * When we received the final response at the end of polling,
-     * we allow also the nonce that we sent earlier with the original request,
-     * as specified in RFC 9483 section 5.1.5.
+     * enable clearing irrelevant errors
+     * in attempts to validate recipient nonce in case of delayed delivery.
      */
-    end_of_polling = ctx->first_senderNonce != NULL && bodytype != OSSL_CMP_PKIBODY_POLLREP;
-    if (!check_transactionID_or_nonce(ctx, ctx->senderNonce, hdr->recipNonce,
-            bodytype, end_of_polling ? 0 : CMP_R_RECIPNONCE_UNMATCHED)) {
-        if (!end_of_polling
-            /* otherwise, compare received nonce with our sender nonce at poll start: */
-            || !check_transactionID_or_nonce(ctx, ctx->first_senderNonce, hdr->recipNonce,
-                bodytype, CMP_R_RECIPNONCE_UNMATCHED))
+    (void)ERR_set_mark();
+    /* compare received nonce with the one we sent */
+    if (!check_transactionID_or_nonce(ctx->senderNonce, hdr->recipNonce,
+            CMP_R_RECIPNONCE_UNMATCHED)) {
+        /* check if we are polling and received final response */
+        if (ctx->first_senderNonce == NULL
+            || OSSL_CMP_MSG_get_bodytype(msg) == OSSL_CMP_PKIBODY_POLLREP
+            /* compare received nonce with our sender nonce at poll start */
+            || !check_transactionID_or_nonce(ctx->first_senderNonce,
+                hdr->recipNonce,
+                CMP_R_RECIPNONCE_UNMATCHED)) {
+            (void)ERR_clear_last_mark();
             return 0;
+        }
     }
+    (void)ERR_pop_to_mark();
 
     /* if not yet present, learn transactionID */
     if (ctx->transactionID == NULL
@@ -886,7 +871,7 @@ int ossl_cmp_msg_check_update(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg,
          * the caPubs field may be directly trusted as a root CA
          * certificate by the initiator.'
          */
-        switch (bodytype) {
+        switch (OSSL_CMP_MSG_get_bodytype(msg)) {
         case OSSL_CMP_PKIBODY_IP:
         case OSSL_CMP_PKIBODY_CP:
         case OSSL_CMP_PKIBODY_KUP:
diff --git a/crypto/cms/cms_asn1.c b/crypto/cms/cms_asn1.c
index 96b125e930..22c809d716 100644
--- a/crypto/cms/cms_asn1.c
+++ b/crypto/cms/cms_asn1.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2008-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -13,8 +13,6 @@
 #include 
 #include "cms_local.h"
 
-#include 
-
 ASN1_SEQUENCE(CMS_IssuerAndSerialNumber) = {
     ASN1_SIMPLE(CMS_IssuerAndSerialNumber, issuer, X509_NAME),
     ASN1_SIMPLE(CMS_IssuerAndSerialNumber, serialNumber, ASN1_INTEGER)
@@ -25,7 +23,7 @@ ASN1_SEQUENCE(CMS_OtherCertificateFormat) = {
     ASN1_OPT(CMS_OtherCertificateFormat, otherCert, ASN1_ANY)
 } static_ASN1_SEQUENCE_END(CMS_OtherCertificateFormat)
 
-ASN1_CHOICE(CMS_CertificateChoices)
+    ASN1_CHOICE(CMS_CertificateChoices)
     = { ASN1_SIMPLE(CMS_CertificateChoices, d.certificate, X509), ASN1_IMP(CMS_CertificateChoices, d.extendedCertificate, ASN1_SEQUENCE, 0), ASN1_IMP(CMS_CertificateChoices, d.v1AttrCert, ASN1_SEQUENCE, 1), ASN1_IMP(CMS_CertificateChoices, d.v2AttrCert, ASN1_SEQUENCE, 2), ASN1_IMP(CMS_CertificateChoices, d.other, CMS_OtherCertificateFormat, 3) } ASN1_CHOICE_END(CMS_CertificateChoices)
 
 ASN1_CHOICE(CMS_SignerIdentifier) = {
@@ -33,11 +31,11 @@ ASN1_CHOICE(CMS_SignerIdentifier) = {
     ASN1_IMP(CMS_SignerIdentifier, d.subjectKeyIdentifier, ASN1_OCTET_STRING, 0)
 } static_ASN1_CHOICE_END(CMS_SignerIdentifier)
 
-ASN1_NDEF_SEQUENCE(CMS_EncapsulatedContentInfo)
+    ASN1_NDEF_SEQUENCE(CMS_EncapsulatedContentInfo)
     = { ASN1_SIMPLE(CMS_EncapsulatedContentInfo, eContentType, ASN1_OBJECT), ASN1_NDEF_EXP_OPT(CMS_EncapsulatedContentInfo, eContent, ASN1_OCTET_STRING_NDEF, 0) } static_ASN1_NDEF_SEQUENCE_END(CMS_EncapsulatedContentInfo)
 
-/* Minor tweak to operation: free up signer key, cert */
-static int cms_si_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it, void *exarg)
+    /* Minor tweak to operation: free up signer key, cert */
+    static int cms_si_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it, void *exarg)
 {
     if (operation == ASN1_OP_FREE_POST) {
         CMS_SignerInfo *si = (CMS_SignerInfo *)*pval;
@@ -64,7 +62,7 @@ ASN1_SEQUENCE(CMS_OtherRevocationInfoFormat) = {
     ASN1_OPT(CMS_OtherRevocationInfoFormat, otherRevInfo, ASN1_ANY)
 } static_ASN1_SEQUENCE_END(CMS_OtherRevocationInfoFormat)
 
-ASN1_CHOICE(CMS_RevocationInfoChoice)
+    ASN1_CHOICE(CMS_RevocationInfoChoice)
     = { ASN1_SIMPLE(CMS_RevocationInfoChoice, d.crl, X509_CRL), ASN1_IMP(CMS_RevocationInfoChoice, d.other, CMS_OtherRevocationInfoFormat, 1) } ASN1_CHOICE_END(CMS_RevocationInfoChoice)
 
 ASN1_NDEF_SEQUENCE(CMS_SignedData) = {
@@ -82,7 +80,7 @@ ASN1_SEQUENCE(CMS_OriginatorInfo) = {
     ASN1_IMP_SET_OF_OPT(CMS_OriginatorInfo, crls, CMS_RevocationInfoChoice, 1)
 } static_ASN1_SEQUENCE_END(CMS_OriginatorInfo)
 
-static int cms_ec_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it, void *exarg)
+    static int cms_ec_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it, void *exarg)
 {
     CMS_EncryptedContentInfo *ec = (CMS_EncryptedContentInfo *)*pval;
 
@@ -120,7 +118,7 @@ ASN1_CHOICE(CMS_KeyAgreeRecipientIdentifier) = {
     ASN1_IMP(CMS_KeyAgreeRecipientIdentifier, d.rKeyId, CMS_RecipientKeyIdentifier, 0)
 } static_ASN1_CHOICE_END(CMS_KeyAgreeRecipientIdentifier)
 
-static int cms_rek_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it, void *exarg)
+    static int cms_rek_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it, void *exarg)
 {
     CMS_RecipientEncryptedKey *rek = (CMS_RecipientEncryptedKey *)*pval;
     if (operation == ASN1_OP_FREE_POST) {
@@ -145,7 +143,7 @@ ASN1_CHOICE(CMS_OriginatorIdentifierOrKey) = {
     ASN1_IMP(CMS_OriginatorIdentifierOrKey, d.originatorKey, CMS_OriginatorPublicKey, 1)
 } static_ASN1_CHOICE_END(CMS_OriginatorIdentifierOrKey)
 
-static int cms_kari_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it, void *exarg)
+    static int cms_kari_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it, void *exarg)
 {
     CMS_KeyAgreeRecipientInfo *kari = (CMS_KeyAgreeRecipientInfo *)*pval;
     if (operation == ASN1_OP_NEW_POST) {
@@ -175,7 +173,7 @@ ASN1_SEQUENCE(CMS_KEKIdentifier) = {
     ASN1_OPT(CMS_KEKIdentifier, other, CMS_OtherKeyAttribute)
 } static_ASN1_SEQUENCE_END(CMS_KEKIdentifier)
 
-ASN1_SEQUENCE(CMS_KEKRecipientInfo)
+    ASN1_SEQUENCE(CMS_KEKRecipientInfo)
     = { ASN1_EMBED(CMS_KEKRecipientInfo, version, INT32), ASN1_SIMPLE(CMS_KEKRecipientInfo, kekid, CMS_KEKIdentifier), ASN1_SIMPLE(CMS_KEKRecipientInfo, keyEncryptionAlgorithm, X509_ALGOR), ASN1_SIMPLE(CMS_KEKRecipientInfo, encryptedKey, ASN1_OCTET_STRING) } ASN1_SEQUENCE_END(CMS_KEKRecipientInfo)
 
 ASN1_SEQUENCE(CMS_PasswordRecipientInfo) = {
@@ -306,9 +304,9 @@ ASN1_NDEF_SEQUENCE(CMS_AuthEnvelopedData) = {
     ASN1_IMP_OPT(CMS_AuthEnvelopedData, originatorInfo, CMS_OriginatorInfo, 0),
     ASN1_SET_OF(CMS_AuthEnvelopedData, recipientInfos, CMS_RecipientInfo),
     ASN1_SIMPLE(CMS_AuthEnvelopedData, authEncryptedContentInfo, CMS_EncryptedContentInfo),
-    ASN1_IMP_SET_OF_OPT(CMS_AuthEnvelopedData, authAttrs, X509_ATTRIBUTE, 1),
+    ASN1_IMP_SET_OF_OPT(CMS_AuthEnvelopedData, authAttrs, X509_ALGOR, 2),
     ASN1_SIMPLE(CMS_AuthEnvelopedData, mac, ASN1_OCTET_STRING),
-    ASN1_IMP_SET_OF_OPT(CMS_AuthEnvelopedData, unauthAttrs, X509_ATTRIBUTE, 2)
+    ASN1_IMP_SET_OF_OPT(CMS_AuthEnvelopedData, unauthAttrs, X509_ALGOR, 3)
 } ASN1_NDEF_SEQUENCE_END(CMS_AuthEnvelopedData)
 
 ASN1_NDEF_SEQUENCE(CMS_AuthenticatedData) = {
@@ -323,7 +321,7 @@ ASN1_NDEF_SEQUENCE(CMS_AuthenticatedData) = {
     ASN1_IMP_SET_OF_OPT(CMS_AuthenticatedData, unauthAttrs, X509_ALGOR, 3)
 } static_ASN1_NDEF_SEQUENCE_END(CMS_AuthenticatedData)
 
-ASN1_NDEF_SEQUENCE(CMS_CompressedData)
+    ASN1_NDEF_SEQUENCE(CMS_CompressedData)
     = {
           ASN1_EMBED(CMS_CompressedData, version, INT32),
           ASN1_SIMPLE(CMS_CompressedData, compressionAlgorithm, X509_ALGOR),
@@ -409,7 +407,7 @@ ASN1_CHOICE(CMS_ReceiptsFrom) = {
     ASN1_IMP_SEQUENCE_OF(CMS_ReceiptsFrom, d.receiptList, GENERAL_NAMES, 1)
 } static_ASN1_CHOICE_END(CMS_ReceiptsFrom)
 
-ASN1_SEQUENCE(CMS_ReceiptRequest)
+    ASN1_SEQUENCE(CMS_ReceiptRequest)
     = { ASN1_SIMPLE(CMS_ReceiptRequest, signedContentIdentifier, ASN1_OCTET_STRING), ASN1_SIMPLE(CMS_ReceiptRequest, receiptsFrom, CMS_ReceiptsFrom), ASN1_SEQUENCE_OF(CMS_ReceiptRequest, receiptsTo, GENERAL_NAMES) } ASN1_SEQUENCE_END(CMS_ReceiptRequest)
 
 ASN1_SEQUENCE(CMS_Receipt) = {
@@ -436,7 +434,7 @@ ASN1_SEQUENCE(CMS_SharedInfo) = {
     ASN1_EXP_OPT(CMS_SharedInfo, suppPubInfo, ASN1_OCTET_STRING, 2),
 } static_ASN1_SEQUENCE_END(CMS_SharedInfo)
 
-int CMS_SharedInfo_encode(unsigned char **pder, X509_ALGOR *kekalg, ASN1_OCTET_STRING *ukm, int keylen)
+    int CMS_SharedInfo_encode(unsigned char **pder, X509_ALGOR *kekalg, ASN1_OCTET_STRING *ukm, int keylen)
 {
     union {
         CMS_SharedInfo *pecsi;
@@ -482,7 +480,7 @@ ASN1_SEQUENCE(CMS_CMSORIforKEMOtherInfo) = {
     ASN1_EXP_OPT(CMS_CMSORIforKEMOtherInfo, ukm, ASN1_OCTET_STRING, 0),
 } static_ASN1_SEQUENCE_END(CMS_CMSORIforKEMOtherInfo)
 
-int CMS_CMSORIforKEMOtherInfo_encode(unsigned char **pder, X509_ALGOR *wrap, ASN1_OCTET_STRING *ukm, int keylen)
+    int CMS_CMSORIforKEMOtherInfo_encode(unsigned char **pder, X509_ALGOR *wrap, ASN1_OCTET_STRING *ukm, int keylen)
 {
     CMS_CMSORIforKEMOtherInfo kem_otherinfo;
 
diff --git a/crypto/cms/cms_att.c b/crypto/cms/cms_att.c
index 49894dce60..86852afda4 100644
--- a/crypto/cms/cms_att.c
+++ b/crypto/cms/cms_att.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2008-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -113,7 +113,7 @@ int CMS_signed_add1_attr_by_txt(CMS_SignerInfo *si,
     return 0;
 }
 
-const void *CMS_signed_get0_data_by_OBJ(const CMS_SignerInfo *si,
+void *CMS_signed_get0_data_by_OBJ(const CMS_SignerInfo *si,
     const ASN1_OBJECT *oid,
     int lastpos, int type)
 {
@@ -182,7 +182,7 @@ int CMS_unsigned_add1_attr_by_txt(CMS_SignerInfo *si,
     return 0;
 }
 
-const void *CMS_unsigned_get0_data_by_OBJ(CMS_SignerInfo *si, ASN1_OBJECT *oid,
+void *CMS_unsigned_get0_data_by_OBJ(CMS_SignerInfo *si, ASN1_OBJECT *oid,
     int lastpos, int type)
 {
     return X509at_get0_data_by_OBJ(si->unsignedAttrs, oid, lastpos, type);
diff --git a/crypto/cms/cms_dd.c b/crypto/cms/cms_dd.c
index e307460e44..aff9af63ca 100644
--- a/crypto/cms/cms_dd.c
+++ b/crypto/cms/cms_dd.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2008-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,8 +15,6 @@
 #include 
 #include "cms_local.h"
 
-#include 
-
 /* CMS DigestedData Utilities */
 
 CMS_ContentInfo *ossl_cms_DigestedData_create(const EVP_MD *md,
@@ -41,8 +39,7 @@ CMS_ContentInfo *ossl_cms_DigestedData_create(const EVP_MD *md,
     dd->version = 0;
     dd->encapContentInfo->eContentType = OBJ_nid2obj(NID_pkcs7_data);
 
-    if (!X509_ALGOR_set_md(dd->digestAlgorithm, md))
-        goto err;
+    X509_ALGOR_set_md(dd->digestAlgorithm, md);
 
     return cms;
 
@@ -92,7 +89,7 @@ int ossl_cms_DigestedData_do_final(const CMS_ContentInfo *cms, BIO *chain,
         else
             r = 1;
     } else {
-        if (!ASN1_STRING_set_data(dd->digest, md, mdlen))
+        if (!ASN1_STRING_set(dd->digest, md, mdlen))
             goto err;
         r = 1;
     }
diff --git a/crypto/cms/cms_dh.c b/crypto/cms/cms_dh.c
index 03cef7455a..a10df73b10 100644
--- a/crypto/cms/cms_dh.c
+++ b/crypto/cms/cms_dh.c
@@ -29,7 +29,7 @@ static int dh_cms_set_peerkey(EVP_PKEY_CTX *pctx,
     BIGNUM *bnpub = NULL;
     const unsigned char *p;
     unsigned char *buf = NULL;
-    size_t plen;
+    int plen;
 
     X509_ALGOR_get0(&aoid, &atype, &aval, alg);
     if (OBJ_obj2nid(aoid) != NID_dhpublicnumber)
@@ -43,33 +43,29 @@ static int dh_cms_set_peerkey(EVP_PKEY_CTX *pctx,
         goto err;
 
     /* Get public key */
-    plen = ASN1_STRING_length_ex(pubkey);
-    if (plen > INT_MAX)
-        goto err;
+    plen = ASN1_STRING_length(pubkey);
     p = ASN1_STRING_get0_data(pubkey);
     if (p == NULL || plen == 0)
         goto err;
 
-    if ((public_key = d2i_ASN1_INTEGER(NULL, &p, (int)plen)) == NULL)
+    if ((public_key = d2i_ASN1_INTEGER(NULL, &p, plen)) == NULL)
         goto err;
     /*
      * Pad to full p parameter size as that is checked by
      * EVP_PKEY_set1_encoded_public_key()
      */
     plen = EVP_PKEY_get_size(pk);
-    if (plen > INT_MAX)
-        goto err;
     if ((bnpub = ASN1_INTEGER_to_BN(public_key, NULL)) == NULL)
         goto err;
     if ((buf = OPENSSL_malloc(plen)) == NULL)
         goto err;
-    if (BN_bn2binpad(bnpub, buf, (int)plen) < 0)
+    if (BN_bn2binpad(bnpub, buf, plen) < 0)
         goto err;
 
     pkpeer = EVP_PKEY_new();
     if (pkpeer == NULL
         || !EVP_PKEY_copy_parameters(pkpeer, pk)
-        || EVP_PKEY_set1_encoded_public_key(pkpeer, buf, (int)plen) <= 0)
+        || EVP_PKEY_set1_encoded_public_key(pkpeer, buf, plen) <= 0)
         goto err;
 
     if (EVP_PKEY_derive_set_peer(pctx, pkpeer) > 0)
@@ -89,26 +85,20 @@ static int dh_cms_set_shared_info(EVP_PKEY_CTX *pctx, CMS_RecipientInfo *ri)
     ASN1_OCTET_STRING *ukm;
     const unsigned char *p;
     unsigned char *dukm = NULL;
-    size_t dukmlen = 0;
-    int keylen;
-    size_t plen;
+    int dukmlen = 0;
+    int keylen, plen;
     EVP_CIPHER *kekcipher = NULL;
     EVP_CIPHER_CTX *kekctx;
-    const ASN1_OBJECT *aoid;
-    const void *parameter = NULL;
-    int ptype = 0;
     char name[OSSL_MAX_NAME_SIZE];
 
     if (!CMS_RecipientInfo_kari_get0_alg(ri, &alg, &ukm))
         goto err;
 
-    X509_ALGOR_get0(&aoid, &ptype, ¶meter, alg);
-
     /*
      * For DH we only have one OID permissible. If ever any more get defined
      * we will need something cleverer.
      */
-    if (OBJ_obj2nid(aoid) != NID_id_smime_alg_ESDH) {
+    if (OBJ_obj2nid(alg->algorithm) != NID_id_smime_alg_ESDH) {
         ERR_raise(ERR_LIB_CMS, CMS_R_KDF_PARAMETER_ERROR);
         goto err;
     }
@@ -117,14 +107,12 @@ static int dh_cms_set_shared_info(EVP_PKEY_CTX *pctx, CMS_RecipientInfo *ri)
         || EVP_PKEY_CTX_set_dh_kdf_md(pctx, EVP_sha1()) <= 0)
         goto err;
 
-    if (ptype != V_ASN1_SEQUENCE)
+    if (alg->parameter->type != V_ASN1_SEQUENCE)
         goto err;
 
-    p = ASN1_STRING_get0_data(parameter);
-    plen = ASN1_STRING_length_ex(parameter);
-    if (plen > INT_MAX)
-        goto err;
-    kekalg = d2i_X509_ALGOR(NULL, &p, (int)plen);
+    p = alg->parameter->value.sequence->data;
+    plen = alg->parameter->value.sequence->length;
+    kekalg = d2i_X509_ALGOR(NULL, &p, plen);
     if (kekalg == NULL)
         goto err;
     kekctx = CMS_RecipientInfo_kari_get0_ctx(ri);
@@ -153,15 +141,13 @@ static int dh_cms_set_shared_info(EVP_PKEY_CTX *pctx, CMS_RecipientInfo *ri)
         goto err;
 
     if (ukm != NULL) {
-        dukmlen = ASN1_STRING_length_ex(ukm);
-        if (dukmlen > INT_MAX)
-            goto err;
-        dukm = OPENSSL_memdup(ASN1_STRING_get0_data(ukm), (int)dukmlen);
+        dukmlen = ASN1_STRING_length(ukm);
+        dukm = OPENSSL_memdup(ASN1_STRING_get0_data(ukm), dukmlen);
         if (dukm == NULL)
             goto err;
     }
 
-    if (EVP_PKEY_CTX_set0_dh_kdf_ukm(pctx, dukm, (int)dukmlen) <= 0)
+    if (EVP_PKEY_CTX_set0_dh_kdf_ukm(pctx, dukm, dukmlen) <= 0)
         goto err;
     dukm = NULL;
 
@@ -215,7 +201,7 @@ static int dh_cms_encrypt(CMS_RecipientInfo *ri)
     ASN1_OCTET_STRING *ukm;
     unsigned char *penc = NULL, *dukm = NULL;
     int penclen;
-    size_t dukmlen = 0;
+    int dukmlen = 0;
     int rv = 0;
     int kdf_type, wrap_nid;
     const EVP_MD *kdf_md;
@@ -249,7 +235,7 @@ static int dh_cms_encrypt(CMS_RecipientInfo *ri)
         if (penclen <= 0)
             goto err;
         ASN1_STRING_set0(pubkey, penc, penclen);
-        ossl_asn1_bit_string_set_unused_bits(pubkey, 0);
+        ossl_asn1_string_set_bits_left(pubkey, 0);
 
         penc = NULL;
         (void)X509_ALGOR_set0(talg, OBJ_nid2obj(NID_dhpublicnumber),
@@ -307,15 +293,13 @@ static int dh_cms_encrypt(CMS_RecipientInfo *ri)
         goto err;
 
     if (ukm != NULL) {
-        dukmlen = ASN1_STRING_length_ex(ukm);
-        if (dukmlen > INT_MAX)
-            goto err;
+        dukmlen = ASN1_STRING_length(ukm);
         dukm = OPENSSL_memdup(ASN1_STRING_get0_data(ukm), dukmlen);
         if (dukm == NULL)
             goto err;
     }
 
-    if (EVP_PKEY_CTX_set0_dh_kdf_ukm(pctx, dukm, (int)dukmlen) <= 0)
+    if (EVP_PKEY_CTX_set0_dh_kdf_ukm(pctx, dukm, dukmlen) <= 0)
         goto err;
     dukm = NULL;
 
diff --git a/crypto/cms/cms_ec.c b/crypto/cms/cms_ec.c
index 98ab266779..ff8adad616 100644
--- a/crypto/cms/cms_ec.c
+++ b/crypto/cms/cms_ec.c
@@ -79,7 +79,7 @@ static int ecdh_cms_set_peerkey(EVP_PKEY_CTX *pctx,
     int rv = 0;
     EVP_PKEY *pkpeer = NULL;
     const unsigned char *p;
-    size_t plen;
+    int plen;
 
     X509_ALGOR_get0(&aoid, &atype, &aval, alg);
     if (OBJ_obj2nid(aoid) != NID_X9_62_id_ecPublicKey)
@@ -106,14 +106,12 @@ static int ecdh_cms_set_peerkey(EVP_PKEY_CTX *pctx,
             goto err;
     }
     /* We have parameters now set public key */
-    plen = ASN1_STRING_length_ex(pubkey);
-    if (plen > INT_MAX)
-        goto err;
+    plen = ASN1_STRING_length(pubkey);
     p = ASN1_STRING_get0_data(pubkey);
     if (p == NULL || plen == 0)
         goto err;
 
-    if (EVP_PKEY_set1_encoded_public_key(pkpeer, p, (int)plen) <= 0)
+    if (EVP_PKEY_set1_encoded_public_key(pkpeer, p, plen) <= 0)
         goto err;
 
     if (EVP_PKEY_derive_set_peer(pctx, pkpeer) > 0)
@@ -165,34 +163,25 @@ static int ecdh_cms_set_shared_info(EVP_PKEY_CTX *pctx, CMS_RecipientInfo *ri)
     ASN1_OCTET_STRING *ukm;
     const unsigned char *p;
     unsigned char *der = NULL;
-    int keylen, plen_i;
-    size_t plen;
+    int plen, keylen;
     EVP_CIPHER *kekcipher = NULL;
     EVP_CIPHER_CTX *kekctx;
-    const ASN1_OBJECT *aoid = NULL;
-    int ptype = 0;
-    const void *parameter = NULL;
-
     char name[OSSL_MAX_NAME_SIZE];
 
     if (!CMS_RecipientInfo_kari_get0_alg(ri, &alg, &ukm))
         return 0;
 
-    X509_ALGOR_get0(&aoid, &ptype, ¶meter, alg);
-
-    if (!ecdh_cms_set_kdf_param(pctx, OBJ_obj2nid(aoid))) {
+    if (!ecdh_cms_set_kdf_param(pctx, OBJ_obj2nid(alg->algorithm))) {
         ERR_raise(ERR_LIB_CMS, CMS_R_KDF_PARAMETER_ERROR);
         return 0;
     }
 
-    if (ptype != V_ASN1_SEQUENCE)
+    if (alg->parameter->type != V_ASN1_SEQUENCE)
         return 0;
 
-    p = ASN1_STRING_get0_data(parameter);
-    plen = ASN1_STRING_length_ex(parameter);
-    if (plen > INT_MAX)
-        goto err;
-    kekalg = d2i_X509_ALGOR(NULL, &p, (int)plen);
+    p = alg->parameter->value.sequence->data;
+    plen = alg->parameter->value.sequence->length;
+    kekalg = d2i_X509_ALGOR(NULL, &p, plen);
     if (kekalg == NULL)
         goto err;
     kekctx = CMS_RecipientInfo_kari_get0_ctx(ri);
@@ -211,12 +200,12 @@ static int ecdh_cms_set_shared_info(EVP_PKEY_CTX *pctx, CMS_RecipientInfo *ri)
     if (EVP_PKEY_CTX_set_ecdh_kdf_outlen(pctx, keylen) <= 0)
         goto err;
 
-    plen_i = CMS_SharedInfo_encode(&der, kekalg, ukm, keylen);
+    plen = CMS_SharedInfo_encode(&der, kekalg, ukm, keylen);
 
-    if (plen_i <= 0)
+    if (plen <= 0)
         goto err;
 
-    if (EVP_PKEY_CTX_set0_ecdh_kdf_ukm(pctx, der, plen_i) <= 0)
+    if (EVP_PKEY_CTX_set0_ecdh_kdf_ukm(pctx, der, plen) <= 0)
         goto err;
     der = NULL;
 
@@ -293,7 +282,7 @@ static int ecdh_cms_encrypt(CMS_RecipientInfo *ri)
         if (enckeylen > INT_MAX || enckeylen == 0)
             goto err;
         ASN1_STRING_set0(pubkey, penc, (int)enckeylen);
-        ossl_asn1_bit_string_set_unused_bits(pubkey, 0);
+        ossl_asn1_string_set_bits_left(pubkey, 0);
 
         penc = NULL;
         (void)X509_ALGOR_set0(talg, OBJ_nid2obj(NID_X9_62_id_ecPublicKey),
diff --git a/crypto/cms/cms_enc.c b/crypto/cms/cms_enc.c
index 32133c6847..2b0ccd62a1 100644
--- a/crypto/cms/cms_enc.c
+++ b/crypto/cms/cms_enc.c
@@ -88,6 +88,10 @@ BIO *ossl_cms_EncryptedContent_init_bio(CMS_EncryptedContentInfo *ec,
         }
         /* Generate a random IV if we need one */
         ivlen = EVP_CIPHER_CTX_get_iv_length(ctx);
+        if (ivlen < 0) {
+            ERR_raise(ERR_LIB_CMS, ERR_R_EVP_LIB);
+            goto err;
+        }
 
         if (ivlen > 0) {
             if (RAND_bytes_ex(libctx, iv, ivlen, 0) <= 0)
@@ -105,15 +109,13 @@ BIO *ossl_cms_EncryptedContent_init_bio(CMS_EncryptedContentInfo *ec,
                 goto err;
             }
             piv = aparams.iv;
-
-            if (ec->taglen < 4 || ec->taglen > 16
-                || EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, (int)ec->taglen, ec->tag) <= 0) {
+            if (ec->taglen > 0
+                && EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG,
+                       (int)ec->taglen, ec->tag)
+                    <= 0) {
                 ERR_raise(ERR_LIB_CMS, CMS_R_CIPHER_AEAD_SET_TAG_ERROR);
                 goto err;
             }
-        } else if (auth) {
-            ERR_raise(ERR_LIB_CMS, CMS_R_UNSUPPORTED_CONTENT_ENCRYPTION_ALGORITHM);
-            goto err;
         }
     }
     len = EVP_CIPHER_CTX_get_key_length(ctx);
@@ -172,12 +174,7 @@ BIO *ossl_cms_EncryptedContent_init_bio(CMS_EncryptedContentInfo *ec,
             goto err;
         }
         if ((EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_AEAD_CIPHER)) {
-            if (ivlen > EVP_MAX_IV_LENGTH || ivlen < 0) {
-                ERR_raise(ERR_LIB_CMS, ERR_R_EVP_LIB);
-                goto err;
-            }
-            if (ivlen != 0)
-                memcpy(aparams.iv, piv, ivlen);
+            memcpy(aparams.iv, piv, ivlen);
             aparams.iv_len = ivlen;
             aparams.tag_len = EVP_CIPHER_CTX_get_tag_length(ctx);
             if (aparams.tag_len <= 0) {
diff --git a/crypto/cms/cms_env.c b/crypto/cms/cms_env.c
index c29e2019ee..2243820bb2 100644
--- a/crypto/cms/cms_env.c
+++ b/crypto/cms/cms_env.c
@@ -278,17 +278,12 @@ BIO *CMS_EnvelopedData_decrypt(CMS_EnvelopedData *env, BIO *detached_data,
     CMS_ContentInfo *ci;
     BIO *bio = NULL;
     int res = 0;
-    size_t secret_len = 0;
 
     if (env == NULL) {
         ERR_raise(ERR_LIB_CMS, ERR_R_PASSED_NULL_PARAMETER);
         return NULL;
     }
 
-    if (secret != NULL
-        && (secret_len = ASN1_STRING_length_ex(secret)) > INT_MAX)
-        return NULL;
-
     if ((ci = CMS_ContentInfo_new_ex(libctx, propq)) == NULL
         || (bio = BIO_new(BIO_s_mem())) == NULL)
         goto end;
@@ -296,7 +291,7 @@ BIO *CMS_EnvelopedData_decrypt(CMS_EnvelopedData *env, BIO *detached_data,
     ci->d.envelopedData = env;
     if (secret != NULL
         && CMS_decrypt_set1_password(ci, (unsigned char *)ASN1_STRING_get0_data(secret),
-               (int)secret_len)
+               ASN1_STRING_length(secret))
             != 1)
         goto end;
     res = CMS_decrypt(ci, secret == NULL ? pkey : NULL,
@@ -649,6 +644,13 @@ static int cms_RecipientInfo_ktri_decrypt(CMS_ContentInfo *cms,
     if (!ossl_cms_env_asn1_ctrl(ri, 1))
         goto err;
 
+    if (EVP_PKEY_is_a(pkey, "RSA"))
+        /* upper layer CMS code incorrectly assumes that a successful RSA
+         * decryption means that the key matches ciphertext (which never
+         * was the case, implicit rejection or not), so to make it work
+         * disable implicit rejection for RSA keys */
+        EVP_PKEY_CTX_ctrl_str(ktri->pctx, "rsa_pkcs1_implicit_rejection", "0");
+
     if (evp_pkey_decrypt_alloc(ktri->pctx, &ek, &eklen, fixlen,
             ktri->encryptedKey->data,
             ktri->encryptedKey->length)
@@ -1241,35 +1243,6 @@ BIO *ossl_cms_EnvelopedData_init_bio(CMS_ContentInfo *cms)
     return cms_EnvelopedData_Decryption_init_bio(cms);
 }
 
-/* The DER encoding of authAttrs, with the universal SET OF tag, is the AAD */
-static int cms_AuthEnvelopedData_set_aad(BIO *b,
-    STACK_OF(X509_ATTRIBUTE) *authAttrs)
-{
-    EVP_CIPHER_CTX *ctx;
-    unsigned char *aad = NULL;
-    int aadlen, outl, ok = 0;
-    const ASN1_ITEM *item;
-
-    if (!BIO_get_cipher_ctx(b, &ctx))
-        return 0;
-    item = EVP_CIPHER_CTX_is_encrypting(ctx)
-        ? ASN1_ITEM_rptr(CMS_Attributes_AadEncrypt)
-        : ASN1_ITEM_rptr(CMS_Attributes_AadDecrypt);
-    aadlen = ASN1_item_i2d((ASN1_VALUE *)authAttrs, &aad, item);
-    if (aadlen <= 0 || aad == NULL) {
-        ERR_raise(ERR_LIB_CMS, ERR_R_ASN1_LIB);
-        goto err;
-    }
-    if (EVP_CipherUpdate(ctx, NULL, &outl, aad, aadlen) <= 0) {
-        ERR_raise(ERR_LIB_CMS, CMS_R_CTRL_FAILURE);
-        goto err;
-    }
-    ok = 1;
-err:
-    OPENSSL_free(aad);
-    return ok;
-}
-
 BIO *ossl_cms_AuthEnvelopedData_init_bio(CMS_ContentInfo *cms)
 {
     CMS_EncryptedContentInfo *ec;
@@ -1286,16 +1259,9 @@ BIO *ossl_cms_AuthEnvelopedData_init_bio(CMS_ContentInfo *cms)
         ec->taglen = aenv->mac->length;
     }
     ret = ossl_cms_EncryptedContent_init_bio(ec, ossl_cms_get0_cmsctx(cms), 1);
-    if (ret == NULL)
-        return NULL;
 
-    /* authAttrs, if present, are the AEAD associated data */
-    if (aenv->authAttrs != NULL
-        && !cms_AuthEnvelopedData_set_aad(ret, aenv->authAttrs))
-        goto err;
-
-    /* If no cipher end of processing */
-    if (ec->cipher == NULL)
+    /* If error or no cipher end of processing */
+    if (ret == NULL || ec->cipher == NULL)
         return ret;
 
     /* Now encrypt content key according to each RecipientInfo type */
@@ -1514,6 +1480,19 @@ int ossl_cms_RecipientInfo_wrap_init(CMS_RecipientInfo *ri,
         ERR_raise(ERR_LIB_CMS, CMS_R_INVALID_KEY_LENGTH);
         return 0;
     }
+    if ((EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_GET_WRAP_CIPHER) != 0) {
+        ret = EVP_CIPHER_meth_get_ctrl(cipher)(NULL, EVP_CTRL_GET_WRAP_CIPHER,
+            0, &kekcipher);
+        if (ret <= 0)
+            return 0;
+
+        if (kekcipher != NULL) {
+            if (EVP_CIPHER_get_mode(kekcipher) != EVP_CIPH_WRAP_MODE)
+                return 0;
+            kekcipher_name = EVP_CIPHER_get0_name(kekcipher);
+            goto enc;
+        }
+    }
 
     /*
      * Pick a cipher based on content encryption cipher. If it is DES3 use
@@ -1530,7 +1509,7 @@ int ossl_cms_RecipientInfo_wrap_init(CMS_RecipientInfo *ri,
         kekcipher_name = SN_id_aes192_wrap;
     else
         kekcipher_name = SN_id_aes256_wrap;
-
+enc:
     fetched_kekcipher = EVP_CIPHER_fetch(ossl_cms_ctx_get0_libctx(cms_ctx),
         kekcipher_name,
         ossl_cms_ctx_get0_propq(cms_ctx));
diff --git a/crypto/cms/cms_ess.c b/crypto/cms/cms_ess.c
index bfe0ccbf3d..480e1c8b1d 100644
--- a/crypto/cms/cms_ess.c
+++ b/crypto/cms/cms_ess.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2008-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -25,7 +25,7 @@ IMPLEMENT_ASN1_FUNCTIONS(CMS_ReceiptRequest)
 
 int CMS_get1_ReceiptRequest(CMS_SignerInfo *si, CMS_ReceiptRequest **prr)
 {
-    const ASN1_STRING *str;
+    ASN1_STRING *str;
     CMS_ReceiptRequest *rr;
     ASN1_OBJECT *obj = OBJ_nid2obj(NID_id_smime_aa_receiptRequest);
 
@@ -52,7 +52,7 @@ int CMS_get1_ReceiptRequest(CMS_SignerInfo *si, CMS_ReceiptRequest **prr)
 static int ossl_cms_signerinfo_get_signing_cert(const CMS_SignerInfo *si,
     ESS_SIGNING_CERT **psc)
 {
-    const ASN1_STRING *str;
+    ASN1_STRING *str;
     ESS_SIGNING_CERT *sc;
     ASN1_OBJECT *obj = OBJ_nid2obj(NID_id_smime_aa_signingCertificate);
 
@@ -79,7 +79,7 @@ static int ossl_cms_signerinfo_get_signing_cert(const CMS_SignerInfo *si,
 static int ossl_cms_signerinfo_get_signing_cert_v2(const CMS_SignerInfo *si,
     ESS_SIGNING_CERT_V2 **psc)
 {
-    const ASN1_STRING *str;
+    ASN1_STRING *str;
     ESS_SIGNING_CERT_V2 *sc;
     ASN1_OBJECT *obj = OBJ_nid2obj(NID_id_smime_aa_signingCertificateV2);
 
@@ -106,10 +106,7 @@ int ossl_cms_check_signing_certs(const CMS_SignerInfo *si,
     ESS_SIGNING_CERT_V2 *ssv2 = NULL;
     int ret = ossl_cms_signerinfo_get_signing_cert(si, &ss) >= 0
         && ossl_cms_signerinfo_get_signing_cert_v2(si, &ssv2) >= 0
-        && OSSL_ESS_check_signing_certs_ex(ss, ssv2, chain,
-               ossl_cms_ctx_get0_libctx(si->cms_ctx),
-               ossl_cms_ctx_get0_propq(si->cms_ctx), 1)
-            > 0;
+        && OSSL_ESS_check_signing_certs(ss, ssv2, chain, 1) > 0;
 
     ESS_SIGNING_CERT_free(ss);
     ESS_SIGNING_CERT_V2_free(ssv2);
@@ -131,7 +128,7 @@ CMS_ReceiptRequest *CMS_ReceiptRequest_create0_ex(
     if (id)
         ASN1_STRING_set0(rr->signedContentIdentifier, id, idlen);
     else {
-        if (!ASN1_STRING_set_data(rr->signedContentIdentifier, NULL, 32)) {
+        if (!ASN1_STRING_set(rr->signedContentIdentifier, NULL, 32)) {
             ERR_raise(ERR_LIB_CMS, ERR_R_ASN1_LIB);
             goto err;
         }
@@ -260,9 +257,8 @@ int ossl_cms_Receipt_verify(CMS_ContentInfo *cms, CMS_ContentInfo *req_cms)
     CMS_Receipt *rct = NULL;
     STACK_OF(CMS_SignerInfo) *sis, *osis;
     CMS_SignerInfo *si, *osi = NULL;
-    const ASN1_OCTET_STRING *msig;
-    ASN1_OCTET_STRING **pcont;
-    const ASN1_OBJECT *octype;
+    ASN1_OCTET_STRING *msig, **pcont;
+    ASN1_OBJECT *octype;
     unsigned char dig[EVP_MAX_MD_SIZE];
     unsigned int diglen;
 
@@ -385,7 +381,7 @@ ASN1_OCTET_STRING *ossl_cms_encode_Receipt(CMS_SignerInfo *si)
 {
     CMS_Receipt rct;
     CMS_ReceiptRequest *rr = NULL;
-    const ASN1_OBJECT *ctype;
+    ASN1_OBJECT *ctype;
     ASN1_OCTET_STRING *os = NULL;
 
     /* Get original receipt request */
diff --git a/crypto/cms/cms_io.c b/crypto/cms/cms_io.c
index 9d2345d0db..14a758da5d 100644
--- a/crypto/cms/cms_io.c
+++ b/crypto/cms/cms_io.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2008-2022 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -14,8 +14,6 @@
 #include 
 #include "cms_local.h"
 
-#include 
-
 /* unfortunately cannot constify BIO_new_NDEF() due to this and PKCS7_stream() */
 int CMS_stream(unsigned char ***boundary, CMS_ContentInfo *cms)
 {
diff --git a/crypto/cms/cms_kemri.c b/crypto/cms/cms_kemri.c
index 3284ebc23a..d5900ecfc4 100644
--- a/crypto/cms/cms_kemri.c
+++ b/crypto/cms/cms_kemri.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -18,8 +18,6 @@
 #include "crypto/evp.h"
 #include "internal/sizes.h"
 
-#include 
-
 /* KEM Recipient Info (KEMRI) routines */
 
 int ossl_cms_RecipientInfo_kemri_get0_alg(CMS_RecipientInfo *ri,
@@ -85,7 +83,7 @@ int ossl_cms_RecipientInfo_kemri_init(CMS_RecipientInfo *ri, X509 *recip,
     CMS_OtherRecipientInfo *ori;
     CMS_KEMRecipientInfo *kemri;
     int idtype;
-    const X509_PUBKEY *x_pubkey;
+    X509_PUBKEY *x_pubkey;
     X509_ALGOR *x_alg;
 
     ri->d.ori = M_ASN1_new_of(CMS_OtherRecipientInfo);
@@ -388,7 +386,7 @@ int ossl_cms_RecipientInfo_kemri_decrypt(const CMS_ContentInfo *cms,
         goto err;
 
     kem_ct = ASN1_STRING_get0_data(kemri->kemct);
-    kem_ct_len = ASN1_STRING_length_ex(kemri->kemct);
+    kem_ct_len = ASN1_STRING_length(kemri->kemct);
 
     if (EVP_PKEY_decapsulate(kemri->pctx, NULL, &kem_secret_len, kem_ct, kem_ct_len) <= 0)
         return 0;
diff --git a/crypto/cms/cms_lib.c b/crypto/cms/cms_lib.c
index 82bf01df26..1454e4758b 100644
--- a/crypto/cms/cms_lib.c
+++ b/crypto/cms/cms_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2008-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -409,20 +409,28 @@ BIO *ossl_cms_DigestAlgorithm_init_bio(X509_ALGOR *digestAlgorithm,
 {
     BIO *mdbio = NULL;
     const ASN1_OBJECT *digestoid;
-    EVP_MD *digest = NULL;
+    const EVP_MD *digest = NULL;
+    EVP_MD *fetched_digest = NULL;
     char alg[OSSL_MAX_NAME_SIZE];
     size_t xof_len = 0;
 
     X509_ALGOR_get0(&digestoid, NULL, NULL, digestAlgorithm);
     OBJ_obj2txt(alg, sizeof(alg), digestoid, 0);
 
-    digest = EVP_MD_fetch(ossl_cms_ctx_get0_libctx(ctx), alg,
+    (void)ERR_set_mark();
+    fetched_digest = EVP_MD_fetch(ossl_cms_ctx_get0_libctx(ctx), alg,
         ossl_cms_ctx_get0_propq(ctx));
 
+    if (fetched_digest != NULL)
+        digest = fetched_digest;
+    else
+        digest = EVP_get_digestbyobj(digestoid);
     if (digest == NULL) {
+        (void)ERR_clear_last_mark();
         ERR_raise(ERR_LIB_CMS, CMS_R_UNKNOWN_DIGEST_ALGORITHM);
         goto err;
     }
+    (void)ERR_pop_to_mark();
 
     mdbio = BIO_new(BIO_f_md());
     if (mdbio == NULL || BIO_set_md(mdbio, digest) <= 0) {
@@ -447,10 +455,10 @@ BIO *ossl_cms_DigestAlgorithm_init_bio(X509_ALGOR *digestAlgorithm,
                 goto err;
         }
     }
-    EVP_MD_free(digest);
+    EVP_MD_free(fetched_digest);
     return mdbio;
 err:
-    EVP_MD_free(digest);
+    EVP_MD_free(fetched_digest);
     BIO_free(mdbio);
     return NULL;
 }
@@ -473,7 +481,7 @@ int ossl_cms_DigestAlgorithm_find_ctx(EVP_MD_CTX *mctx, BIO *chain,
             return 0;
         }
         BIO_get_md_ctx(chain, &mtmp);
-        if (EVP_MD_CTX_get_type(mtmp) == nid || OBJ_sn2nid(EVP_MD_CTX_get0_name(mtmp)) == nid
+        if (EVP_MD_CTX_get_type(mtmp) == nid
             /*
              * Workaround for broken implementations that use signature
              * algorithm OID instead of digest.
diff --git a/crypto/cms/cms_local.h b/crypto/cms/cms_local.h
index bfb0ca729b..24426d5747 100644
--- a/crypto/cms/cms_local.h
+++ b/crypto/cms/cms_local.h
@@ -1,5 +1,5 @@
 /*
- * Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2008-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -10,7 +10,6 @@
 #ifndef OSSL_CRYPTO_CMS_LOCAL_H
 #define OSSL_CRYPTO_CMS_LOCAL_H
 
-#include 
 #include 
 
 /*
@@ -36,7 +35,8 @@ typedef struct CMS_OriginatorPublicKey_st CMS_OriginatorPublicKey;
 typedef struct CMS_OriginatorIdentifierOrKey_st CMS_OriginatorIdentifierOrKey;
 typedef struct CMS_KeyAgreeRecipientInfo_st CMS_KeyAgreeRecipientInfo;
 typedef struct CMS_RecipientKeyIdentifier_st CMS_RecipientKeyIdentifier;
-typedef struct CMS_KeyAgreeRecipientIdentifier_st CMS_KeyAgreeRecipientIdentifier;
+typedef struct CMS_KeyAgreeRecipientIdentifier_st
+    CMS_KeyAgreeRecipientIdentifier;
 typedef struct CMS_KEKIdentifier_st CMS_KEKIdentifier;
 typedef struct CMS_KEKRecipientInfo_st CMS_KEKRecipientInfo;
 typedef struct CMS_PasswordRecipientInfo_st CMS_PasswordRecipientInfo;
@@ -390,7 +390,7 @@ struct CMS_ReceiptsFrom_st {
 
 struct CMS_Receipt_st {
     int32_t version;
-    const ASN1_OBJECT *contentType;
+    ASN1_OBJECT *contentType;
     ASN1_OCTET_STRING *signedContentIdentifier;
     ASN1_OCTET_STRING *originatorSignatureValue;
 };
@@ -401,9 +401,6 @@ DECLARE_ASN1_ITEM(CMS_EncryptedContentInfo)
 DECLARE_ASN1_ITEM(CMS_IssuerAndSerialNumber)
 DECLARE_ASN1_ITEM(CMS_Attributes_Sign)
 DECLARE_ASN1_ITEM(CMS_Attributes_Verify)
-/* The authAttrs AAD encoding matches the signed-attributes one */
-#define CMS_Attributes_AadEncrypt_it CMS_Attributes_Sign_it
-#define CMS_Attributes_AadDecrypt_it CMS_Attributes_Verify_it
 DECLARE_ASN1_ITEM(CMS_RecipientInfo)
 DECLARE_ASN1_ITEM(CMS_PasswordRecipientInfo)
 DECLARE_ASN1_ALLOC_FUNCTIONS(CMS_IssuerAndSerialNumber)
diff --git a/crypto/cms/cms_pwri.c b/crypto/cms/cms_pwri.c
index 2cdac56fcf..ac869a37f9 100644
--- a/crypto/cms/cms_pwri.c
+++ b/crypto/cms/cms_pwri.c
@@ -205,7 +205,7 @@ static int kek_unwrap_key(unsigned char *out, size_t *outlen,
     unsigned char *tmp;
     int outl, rv = 0;
 
-    if (blocklen < 4)
+    if (blocklen <= 0)
         return 0;
 
     if (inlen < 2 * (size_t)blocklen) {
@@ -368,11 +368,6 @@ int ossl_cms_RecipientInfo_pwri_crypt(const CMS_ContentInfo *cms,
 
     /* Finish password based key derivation to setup key in "ctx" */
 
-    if (algtmp == NULL) {
-        ERR_raise_data(ERR_LIB_CMS, CMS_R_INVALID_KEY_ENCRYPTION_PARAMETER,
-            "Missing KeyDerivationAlgorithm");
-        goto err;
-    }
     if (!EVP_PBE_CipherInit_ex(algtmp->algorithm,
             (char *)pwri->pass, (int)pwri->passlen,
             algtmp->parameter, kekctx, en_de,
diff --git a/crypto/cms/cms_rsa.c b/crypto/cms/cms_rsa.c
index 1b351f6cd1..9b12d90885 100644
--- a/crypto/cms/cms_rsa.c
+++ b/crypto/cms/cms_rsa.c
@@ -42,13 +42,10 @@ static int rsa_cms_decrypt(CMS_RecipientInfo *ri)
     X509_ALGOR *cmsalg;
     int nid;
     int rv = -1;
-    const unsigned char *label = NULL;
-    size_t labellen = 0;
+    unsigned char *label = NULL;
+    int labellen = 0;
     const EVP_MD *mgf1md = NULL, *md = NULL;
     RSA_OAEP_PARAMS *oaep;
-    const ASN1_OBJECT *aoid;
-    const void *parameter = NULL;
-    int ptype = 0;
 
     pkctx = CMS_RecipientInfo_get0_pkey_ctx(ri);
     if (pkctx == NULL)
@@ -78,21 +75,21 @@ static int rsa_cms_decrypt(CMS_RecipientInfo *ri)
         goto err;
 
     if (oaep->pSourceFunc != NULL) {
-        X509_ALGOR_get0(&aoid, &ptype, ¶meter, oaep->pSourceFunc);
+        X509_ALGOR *plab = oaep->pSourceFunc;
 
-        if (OBJ_obj2nid(aoid) != NID_pSpecified) {
+        if (OBJ_obj2nid(plab->algorithm) != NID_pSpecified) {
             ERR_raise(ERR_LIB_CMS, CMS_R_UNSUPPORTED_LABEL_SOURCE);
             goto err;
         }
-        if (ptype != V_ASN1_OCTET_STRING) {
+        if (plab->parameter->type != V_ASN1_OCTET_STRING) {
             ERR_raise(ERR_LIB_CMS, CMS_R_INVALID_LABEL);
             goto err;
         }
 
-        label = ASN1_STRING_get0_data(parameter);
-        labellen = ASN1_STRING_length_ex(parameter);
-        if (labellen > INT_MAX)
-            goto err;
+        label = plab->parameter->value.octet_string->data;
+        /* Stop label being freed when OAEP parameters are freed */
+        plab->parameter->value.octet_string->data = NULL;
+        labellen = plab->parameter->value.octet_string->length;
     }
 
     if (EVP_PKEY_CTX_set_rsa_padding(pkctx, RSA_PKCS1_OAEP_PADDING) <= 0)
@@ -101,16 +98,10 @@ static int rsa_cms_decrypt(CMS_RecipientInfo *ri)
         goto err;
     if (EVP_PKEY_CTX_set_rsa_mgf1_md(pkctx, mgf1md) <= 0)
         goto err;
-    if (label != NULL) {
-        unsigned char *dup_label = OPENSSL_memdup(label, labellen);
-
-        if (dup_label == NULL)
-            goto err;
-
-        if (EVP_PKEY_CTX_set0_rsa_oaep_label(pkctx, dup_label, (int)labellen) <= 0) {
-            OPENSSL_free(dup_label);
-            goto err;
-        }
+    if (label != NULL
+        && EVP_PKEY_CTX_set0_rsa_oaep_label(pkctx, label, labellen) <= 0) {
+        OPENSSL_free(label);
+        goto err;
     }
     /* Carry on */
     rv = 1;
diff --git a/crypto/cms/cms_sd.c b/crypto/cms/cms_sd.c
index 352f75a45c..8e60e6e559 100644
--- a/crypto/cms/cms_sd.c
+++ b/crypto/cms/cms_sd.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2008-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -141,7 +141,7 @@ static int cms_copy_messageDigest(CMS_ContentInfo *cms, CMS_SignerInfo *si)
 
     sinfos = CMS_get0_SignerInfos(cms);
     for (i = 0; i < sk_CMS_SignerInfo_num(sinfos); i++) {
-        const ASN1_OCTET_STRING *messageDigest;
+        ASN1_OCTET_STRING *messageDigest;
 
         sitmp = sk_CMS_SignerInfo_value(sinfos, i);
         if (sitmp == si)
@@ -304,7 +304,7 @@ static int ossl_cms_add1_signing_cert(CMS_SignerInfo *si,
 
     p = pp;
     i2d_ESS_SIGNING_CERT(sc, &p);
-    if (!(seq = ASN1_STRING_new()) || !ASN1_STRING_set_data(seq, pp, len)) {
+    if (!(seq = ASN1_STRING_new()) || !ASN1_STRING_set(seq, pp, len)) {
         ASN1_STRING_free(seq);
         OPENSSL_free(pp);
         return 0;
@@ -329,7 +329,7 @@ static int ossl_cms_add1_signing_cert_v2(CMS_SignerInfo *si,
 
     p = pp;
     i2d_ESS_SIGNING_CERT_V2(sc, &p);
-    if (!(seq = ASN1_STRING_new()) || !ASN1_STRING_set_data(seq, pp, len)) {
+    if (!(seq = ASN1_STRING_new()) || !ASN1_STRING_set(seq, pp, len)) {
         ASN1_STRING_free(seq);
         OPENSSL_free(pp);
         return 0;
@@ -372,7 +372,7 @@ static const struct {
     {
         "ED25519",
         NID_sha512,
-        1,
+        0,
         NID_sha512,
         1,
     }, /* RFC 8419 */
@@ -480,22 +480,17 @@ static const struct {
 static const char *cms_mdless_signing(EVP_PKEY *pkey)
 {
     unsigned int i;
-    int def_nid = NID_undef;
 
     for (i = 0; key2data[i].name != NULL; i++) {
         if (EVP_PKEY_is_a(pkey, key2data[i].name))
             return key2data[i].name;
     }
-    if (EVP_PKEY_get_default_digest_nid(pkey, &def_nid) <= 0) {
-        /* Key doesn't have default digest, it's mdless */
-        return EVP_PKEY_get0_type_name(pkey);
-    }
     return NULL;
 }
 
-static EVP_MD *ossl_cms_get_default_md(const CMS_CTX *ctx, EVP_PKEY *pk, int *md_a_must)
+static const EVP_MD *ossl_cms_get_default_md(EVP_PKEY *pk, int *md_a_must)
 {
-    EVP_MD *md = NULL;
+    const EVP_MD *md;
     unsigned int i;
     int def_nid = NID_undef;
 
@@ -514,28 +509,29 @@ static EVP_MD *ossl_cms_get_default_md(const CMS_CTX *ctx, EVP_PKEY *pk, int *md
             "pkey nid=%d", EVP_PKEY_get_id(pk));
         return NULL;
     }
-    md = EVP_MD_fetch(ossl_cms_ctx_get0_libctx(ctx), OBJ_nid2sn(def_nid), ossl_cms_ctx_get0_propq(ctx));
+    md = EVP_get_digestbynid(def_nid);
     if (md == NULL)
         ERR_raise_data(ERR_LIB_CMS, CMS_R_NO_DEFAULT_DIGEST,
             "default md nid=%d", def_nid);
     return md;
 }
 
-static EVP_MD *ossl_cms_get_noattr_md(const CMS_CTX *ctx, EVP_PKEY *pk, int *noattr_md_a_must)
+static const EVP_MD *ossl_cms_get_noattr_md(EVP_PKEY *pk, int *noattr_md_a_must)
 {
     unsigned int i;
 
     for (i = 0; key2data[i].name != NULL; i++) {
         if (EVP_PKEY_is_a(pk, key2data[i].name)) {
             *noattr_md_a_must = key2data[i].noattr_md_a_must;
-            return EVP_MD_fetch(ossl_cms_ctx_get0_libctx(ctx), OBJ_nid2sn(key2data[i].noattr_md_nid), ossl_cms_ctx_get0_propq(ctx));
+            return EVP_get_digestbynid(key2data[i].noattr_md_nid);
         }
     }
     return NULL;
 }
 
-static int ossl_cms_adjust_md(const CMS_CTX *ctx, EVP_PKEY *pk, const EVP_MD **md, EVP_MD **fetched_md, unsigned int flags)
+static int ossl_cms_adjust_md(EVP_PKEY *pk, const EVP_MD **md, unsigned int flags)
 {
+    const EVP_MD *tmp_md;
     int md_a_must = 0;
 
     while ((flags & CMS_NOATTR) != 0) {
@@ -546,26 +542,22 @@ static int ossl_cms_adjust_md(const CMS_CTX *ctx, EVP_PKEY *pk, const EVP_MD **m
          */
         int noattr_md_a_must = 0;
 
-        *fetched_md = ossl_cms_get_noattr_md(ctx, pk, &noattr_md_a_must);
-        if (*fetched_md == NULL)
+        tmp_md = ossl_cms_get_noattr_md(pk, &noattr_md_a_must);
+        if (tmp_md == NULL)
             break; /* key type not listed - use the default */
 
         if (noattr_md_a_must)
-            *md = *fetched_md;
+            *md = tmp_md;
         else if (*md == NULL)
-            *md = *fetched_md;
+            *md = tmp_md;
         return 1;
     }
 
-    if (*md != NULL)
-        (void)ERR_set_mark(); /* No error if no default md and user-supplied md is set */
-    *fetched_md = ossl_cms_get_default_md(ctx, pk, &md_a_must);
-    if (*md != NULL)
-        (void)ERR_pop_to_mark();
+    tmp_md = ossl_cms_get_default_md(pk, &md_a_must);
     if (md_a_must)
-        *md = *fetched_md;
+        *md = tmp_md;
     else if (*md == NULL)
-        *md = *fetched_md;
+        *md = tmp_md;
 
     if (*md == NULL) /* ED448 case */
         return 0;
@@ -577,7 +569,6 @@ CMS_SignerInfo *CMS_add1_signer(CMS_ContentInfo *cms,
     X509 *signer, EVP_PKEY *pk, const EVP_MD *md,
     unsigned int flags)
 {
-    EVP_MD *local_md = NULL;
     CMS_SignedData *sd;
     CMS_SignerInfo *si = NULL;
     X509_ALGOR *alg;
@@ -631,11 +622,10 @@ CMS_SignerInfo *CMS_add1_signer(CMS_ContentInfo *cms,
     if (!ossl_cms_set1_SignerIdentifier(si->sid, signer, type, ctx))
         goto err;
 
-    if (ossl_cms_adjust_md(ctx, pk, &md, &local_md, flags) != 1 && local_md != md)
+    if (ossl_cms_adjust_md(pk, &md, flags) != 1)
         goto err;
 
-    if (!X509_ALGOR_set_md(si->digestAlgorithm, md))
-        goto err;
+    X509_ALGOR_set_md(si->digestAlgorithm, md);
 
     /* See if digest is present in digestAlgorithms */
     for (i = 0; i < sk_X509_ALGOR_num(sd->digestAlgorithms); i++) {
@@ -649,9 +639,12 @@ CMS_SignerInfo *CMS_add1_signer(CMS_ContentInfo *cms,
             break;
     }
     if (i == sk_X509_ALGOR_num(sd->digestAlgorithms)) {
-        if ((alg = X509_ALGOR_new()) == NULL
-            || !X509_ALGOR_set_md(alg, md)
-            || !sk_X509_ALGOR_push(sd->digestAlgorithms, alg)) {
+        if ((alg = X509_ALGOR_new()) == NULL) {
+            ERR_raise(ERR_LIB_CMS, ERR_R_ASN1_LIB);
+            goto err;
+        }
+        X509_ALGOR_set_md(alg, md);
+        if (!sk_X509_ALGOR_push(sd->digestAlgorithms, alg)) {
             X509_ALGOR_free(alg);
             ERR_raise(ERR_LIB_CMS, ERR_R_CRYPTO_LIB);
             goto err;
@@ -763,11 +756,9 @@ CMS_SignerInfo *CMS_add1_signer(CMS_ContentInfo *cms,
         ERR_raise(ERR_LIB_CMS, ERR_R_CRYPTO_LIB);
         goto err;
     }
-    EVP_MD_free(local_md);
     return si;
 
 err:
-    EVP_MD_free(local_md);
     M_ASN1_free_of(si, CMS_SignerInfo);
     return NULL;
 }
@@ -882,7 +873,7 @@ int CMS_SignerInfo_cert_cmp(CMS_SignerInfo *si, X509 *cert)
     return ossl_cms_SignerIdentifier_cert_cmp(si->sid, cert);
 }
 
-int CMS_set1_signers_certs(CMS_ContentInfo *cms, const STACK_OF(X509) *scerts,
+int CMS_set1_signers_certs(CMS_ContentInfo *cms, STACK_OF(X509) *scerts,
     unsigned int flags)
 {
     CMS_SignedData *sd;
@@ -1398,7 +1389,7 @@ int CMS_SignerInfo_verify_content(CMS_SignerInfo *si, BIO *chain)
 
 int CMS_SignerInfo_verify_ex(CMS_SignerInfo *si, BIO *chain, BIO *data)
 {
-    const ASN1_OCTET_STRING *os = NULL;
+    ASN1_OCTET_STRING *os = NULL;
     EVP_MD_CTX *mctx = EVP_MD_CTX_new();
     EVP_PKEY_CTX *pkctx = NULL;
     int r = -1;
@@ -1500,9 +1491,8 @@ err:
 }
 
 BIO *CMS_SignedData_verify(CMS_SignedData *sd, BIO *detached_data,
-    const STACK_OF(X509) *scerts, X509_STORE *store,
-    const STACK_OF(X509) *extra,
-    const STACK_OF(X509_CRL) *crls,
+    STACK_OF(X509) *scerts, X509_STORE *store,
+    STACK_OF(X509) *extra, STACK_OF(X509_CRL) *crls,
     unsigned int flags,
     OSSL_LIB_CTX *libctx, const char *propq)
 {
diff --git a/crypto/cms/cms_smime.c b/crypto/cms/cms_smime.c
index 044cb2326f..fe631b27a2 100644
--- a/crypto/cms/cms_smime.c
+++ b/crypto/cms/cms_smime.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2008-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -36,7 +36,6 @@ static int cms_copy_content(BIO *out, BIO *in, unsigned int flags)
     unsigned char buf[4096];
     int r = 0, i;
     BIO *tmpout;
-    BIO *aeadbuf = NULL;
 
     tmpout = cms_get_text_bio(out, flags);
 
@@ -45,33 +44,6 @@ static int cms_copy_content(BIO *out, BIO *in, unsigned int flags)
         goto err;
     }
 
-    /*
-     * For AEAD content (AuthEnvelopedData) the integrity tag is only verified
-     * once all the ciphertext has been processed, by the
-     * BIO_get_cipher_status() call below. RFC 5083 requires that the plaintext
-     * is not released to the caller until that verification succeeds, so
-     * buffer it in memory and only forward it to the output BIO once the tag
-     * has been checked. When CMS_TEXT is set tmpout is already a memory BIO
-     * that is flushed only on success, so the extra buffering is not needed.
-     */
-    if (tmpout == out && BIO_method_type(in) == BIO_TYPE_CIPHER) {
-        EVP_CIPHER_CTX *ctx = NULL;
-
-        if (BIO_get_cipher_ctx(in, &ctx) > 0 && ctx != NULL
-            && (EVP_CIPHER_get_flags(EVP_CIPHER_CTX_get0_cipher(ctx))
-                   & EVP_CIPH_FLAG_AEAD_CIPHER)
-                != 0) {
-            aeadbuf = BIO_new(BIO_s_mem());
-            if (aeadbuf == NULL) {
-                ERR_raise(ERR_LIB_CMS, ERR_R_BIO_LIB);
-                goto err;
-            }
-            /* Return 0 (EOF) rather than a retryable -1 once drained. */
-            BIO_set_mem_eof_return(aeadbuf, 0);
-            tmpout = aeadbuf;
-        }
-    }
-
     /* Read all content through chain to process digest, decrypt etc */
     for (;;) {
         i = BIO_read(in, buf, sizeof(buf));
@@ -94,17 +66,6 @@ static int cms_copy_content(BIO *out, BIO *in, unsigned int flags)
             ERR_raise(ERR_LIB_CMS, CMS_R_SMIME_TEXT_ERROR);
             goto err;
         }
-    } else if (aeadbuf != NULL) {
-        /* Forward the AEAD BIO to out BIO as the tag has been verified. */
-        for (;;) {
-            i = BIO_read(aeadbuf, buf, sizeof(buf));
-            if (i < 0)
-                goto err;
-            if (i == 0)
-                break;
-            if (BIO_write(out, buf, i) != i)
-                goto err;
-        }
     }
 
     r = 1;
@@ -341,7 +302,7 @@ err:
 }
 
 /* This strongly overlaps with PKCS7_verify() */
-int CMS_verify(CMS_ContentInfo *cms, const STACK_OF(X509) *certs,
+int CMS_verify(CMS_ContentInfo *cms, STACK_OF(X509) *certs,
     X509_STORE *store, BIO *dcont, BIO *out, unsigned int flags)
 {
     CMS_SignerInfo *si;
@@ -513,10 +474,8 @@ err:
     } else {
         if (dcont && (tmpin == dcont))
             do_free_upto(cmsbio, dcont);
-        else if (cmsbio != NULL)
-            BIO_free_all(cmsbio);
         else
-            BIO_free(tmpin);
+            BIO_free_all(cmsbio);
     }
 
     if (out != tmpout)
@@ -535,7 +494,7 @@ err2:
 }
 
 int CMS_verify_receipt(CMS_ContentInfo *rcms, CMS_ContentInfo *ocms,
-    const STACK_OF(X509) *certs,
+    STACK_OF(X509) *certs,
     X509_STORE *store, unsigned int flags)
 {
     int r;
@@ -548,7 +507,7 @@ int CMS_verify_receipt(CMS_ContentInfo *rcms, CMS_ContentInfo *ocms,
 }
 
 CMS_ContentInfo *CMS_sign_ex(X509 *signcert, EVP_PKEY *pkey,
-    const STACK_OF(X509) *certs, BIO *data,
+    STACK_OF(X509) *certs, BIO *data,
     unsigned int flags, OSSL_LIB_CTX *libctx,
     const char *propq)
 {
@@ -595,15 +554,15 @@ err:
     return NULL;
 }
 
-CMS_ContentInfo *CMS_sign(X509 *signcert, EVP_PKEY *pkey,
-    const STACK_OF(X509) *certs, BIO *data, unsigned int flags)
+CMS_ContentInfo *CMS_sign(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs,
+    BIO *data, unsigned int flags)
 {
     return CMS_sign_ex(signcert, pkey, certs, data, flags, NULL, NULL);
 }
 
 CMS_ContentInfo *CMS_sign_receipt(CMS_SignerInfo *si,
     X509 *signcert, EVP_PKEY *pkey,
-    const STACK_OF(X509) *certs, unsigned int flags)
+    STACK_OF(X509) *certs, unsigned int flags)
 {
     CMS_SignerInfo *rct_si;
     CMS_ContentInfo *cms = NULL;
@@ -673,7 +632,7 @@ err:
     return NULL;
 }
 
-CMS_ContentInfo *CMS_encrypt_ex(const STACK_OF(X509) *certs, BIO *data,
+CMS_ContentInfo *CMS_encrypt_ex(STACK_OF(X509) *certs, BIO *data,
     const EVP_CIPHER *cipher, unsigned int flags,
     OSSL_LIB_CTX *libctx, const char *propq)
 {
@@ -710,7 +669,7 @@ err:
     return NULL;
 }
 
-CMS_ContentInfo *CMS_encrypt(const STACK_OF(X509) *certs, BIO *data,
+CMS_ContentInfo *CMS_encrypt(STACK_OF(X509) *certs, BIO *data,
     const EVP_CIPHER *cipher, unsigned int flags)
 {
     return CMS_encrypt_ex(certs, data, cipher, flags, NULL, NULL);
diff --git a/crypto/comp/c_brotli.c b/crypto/comp/c_brotli.c
index 9c99e066b7..d262ec6a4e 100644
--- a/crypto/comp/c_brotli.c
+++ b/crypto/comp/c_brotli.c
@@ -13,7 +13,6 @@
 #include 
 #include 
 #include 
-#include "internal/e_os.h"
 #include "internal/comp.h"
 #include 
 #include "crypto/cryptlib.h"
@@ -47,6 +46,10 @@ static void brotli_free(void *opaque, void *address)
  * work.  Therefore, all BROTLI routines are loaded at run time
  * and we do not link to a .LIB file when BROTLI_SHARED is set.
  */
+#if defined(OPENSSL_SYS_WINDOWS) || defined(OPENSSL_SYS_WIN32)
+#include 
+#endif
+
 #ifdef BROTLI_SHARED
 #include "internal/dso.h"
 
diff --git a/crypto/comp/c_zlib.c b/crypto/comp/c_zlib.c
index 4af4e30b64..602259c821 100644
--- a/crypto/comp/c_zlib.c
+++ b/crypto/comp/c_zlib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1998-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1998-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -11,7 +11,6 @@
 #include 
 #include 
 #include 
-#include "internal/e_os.h"
 #include "internal/comp.h"
 #include 
 #include "crypto/cryptlib.h"
@@ -65,6 +64,10 @@ static COMP_METHOD zlib_stateful_method = {
  * work.  Therefore, all ZLIB routines are loaded at run time
  * and we do not link to a .LIB file when ZLIB_SHARED is set.
  */
+#if defined(OPENSSL_SYS_WINDOWS) || defined(OPENSSL_SYS_WIN32)
+#include 
+#endif /* !(OPENSSL_SYS_WINDOWS || \
+        * OPENSSL_SYS_WIN32) */
 
 #ifdef ZLIB_SHARED
 #include "internal/dso.h"
@@ -281,7 +284,7 @@ DEFINE_RUN_ONCE_STATIC(ossl_comp_zlib_init)
     zlib_dso = DSO_load(NULL, LIBZ, NULL, 0);
     if (zlib_dso != NULL) {
         p_compress = (compress_ft)DSO_bind_func(zlib_dso, "compress");
-        p_uncompress = (uncompress_ft)DSO_bind_func(zlib_dso, "uncompress");
+        p_uncompress = (compress_ft)DSO_bind_func(zlib_dso, "uncompress");
         p_inflateEnd = (inflateEnd_ft)DSO_bind_func(zlib_dso, "inflateEnd");
         p_inflate = (inflate_ft)DSO_bind_func(zlib_dso, "inflate");
         p_inflateInit_ = (inflateInit__ft)DSO_bind_func(zlib_dso, "inflateInit_");
@@ -289,14 +292,14 @@ DEFINE_RUN_ONCE_STATIC(ossl_comp_zlib_init)
         p_deflate = (deflate_ft)DSO_bind_func(zlib_dso, "deflate");
         p_deflateInit_ = (deflateInit__ft)DSO_bind_func(zlib_dso, "deflateInit_");
         p_zError = (zError__ft)DSO_bind_func(zlib_dso, "zError");
-    }
 
-    if (p_compress == NULL || p_uncompress == NULL || p_inflateEnd == NULL
-        || p_inflate == NULL || p_inflateInit_ == NULL
-        || p_deflateEnd == NULL || p_deflate == NULL
-        || p_deflateInit_ == NULL || p_zError == NULL) {
-        ossl_comp_zlib_cleanup();
-        return 0;
+        if (p_compress == NULL || p_uncompress == NULL || p_inflateEnd == NULL
+            || p_inflate == NULL || p_inflateInit_ == NULL
+            || p_deflateEnd == NULL || p_deflate == NULL
+            || p_deflateInit_ == NULL || p_zError == NULL) {
+            ossl_comp_zlib_cleanup();
+            return 0;
+        }
     }
 #endif
     return 1;
diff --git a/crypto/comp/c_zstd.c b/crypto/comp/c_zstd.c
index c5c6cd6eef..a9c881f8f9 100644
--- a/crypto/comp/c_zstd.c
+++ b/crypto/comp/c_zstd.c
@@ -16,7 +16,6 @@
 #include 
 #include 
 #include 
-#include "internal/e_os.h"
 #include "internal/comp.h"
 #include 
 #include "crypto/cryptlib.h"
@@ -63,6 +62,16 @@ static ZSTD_customMem zstd_mem_funcs = {
 };
 #endif
 
+/*
+ * When OpenSSL is built on Windows, we do not want to require that
+ * the LIBZSTD.DLL be available in order for the OpenSSL DLLs to
+ * work.  Therefore, all ZSTD routines are loaded at run time
+ * and we do not link to a .LIB file when ZSTD_SHARED is set.
+ */
+#if defined(OPENSSL_SYS_WINDOWS) || defined(OPENSSL_SYS_WIN32)
+#include 
+#endif
+
 #ifdef ZSTD_SHARED
 #include "internal/dso.h"
 
diff --git a/crypto/comp/comp_local.h b/crypto/comp/comp_local.h
index bb9d4a0f79..fbc5ab318c 100644
--- a/crypto/comp/comp_local.h
+++ b/crypto/comp/comp_local.h
@@ -7,11 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_COMP_COMP_LOCAL_H)
-#define OSSL_LIBCRYPTO_COMP_COMP_LOCAL_H
-
-#include 
-
 struct comp_method_st {
     int type; /* NID for compression library */
     const char *name; /* A text string to identify the library */
@@ -33,5 +28,3 @@ struct comp_ctx_st {
     unsigned long expand_out;
     void *data;
 };
-
-#endif /* !defined(OSSL_LIBCRYPTO_COMP_COMP_LOCAL_H) */
diff --git a/crypto/conf/conf_def.h b/crypto/conf/conf_def.h
index 2fdc9d7d99..1f66a58e09 100644
--- a/crypto/conf/conf_def.h
+++ b/crypto/conf/conf_def.h
@@ -2,16 +2,13 @@
  * WARNING: do not edit!
  * Generated by crypto/conf/keysets.pl
  *
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
  * in the file LICENSE in the source distribution or at
  * https://www.openssl.org/source/license.html
  */
-#if !defined(OSSL_LIBCRYPTO_CONF_CONF_DEF_H)
-#define OSSL_LIBCRYPTO_CONF_CONF_DEF_H
 
-/* clang-format off */
 #define CONF_NUMBER       1
 #define CONF_UPPER        2
 #define CONF_LOWER        4
@@ -81,6 +78,3 @@ static const unsigned short CONF_type_win32[128] = {
     0x0004, 0x0004, 0x0004, 0x0000, 0x0200, 0x0000, 0x0200, 0x0000,
 };
 #endif
-/* clang-format on */
-
-#endif /* !defined(OSSL_LIBCRYPTO_CONF_CONF_DEF_H) */
diff --git a/crypto/conf/conf_lib.c b/crypto/conf/conf_lib.c
index c148a43490..6efd95283e 100644
--- a/crypto/conf/conf_lib.c
+++ b/crypto/conf/conf_lib.c
@@ -314,7 +314,7 @@ char *NCONF_get_string(const CONF *conf, const char *group, const char *name)
         return NULL;
     }
     ERR_raise_data(ERR_LIB_CONF, CONF_R_NO_VALUE,
-        "group=%s name=%s", group != NULL ? group : "", name);
+        "group=%s name=%s", group, name);
     return NULL;
 }
 
diff --git a/crypto/conf/conf_local.h b/crypto/conf/conf_local.h
index 1ecef7549a..f3b16f1138 100644
--- a/crypto/conf/conf_local.h
+++ b/crypto/conf/conf_local.h
@@ -7,10 +7,5 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_CONF_CONF_LOCAL_H)
-#define OSSL_LIBCRYPTO_CONF_CONF_LOCAL_H
-
 #include 
 void ossl_config_add_ssl_module(void);
-
-#endif /* !defined(OSSL_LIBCRYPTO_CONF_CONF_LOCAL_H) */
diff --git a/crypto/conf/conf_mod.c b/crypto/conf/conf_mod.c
index 9f55954bf9..998c0538e3 100644
--- a/crypto/conf/conf_mod.c
+++ b/crypto/conf/conf_mod.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2002-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -356,7 +356,7 @@ static CONF_MODULE *module_find(const char *name)
     CONF_MODULE *tmod;
     int i;
     size_t nchar;
-    const char *p;
+    char *p;
     STACK_OF(CONF_MODULE) *mods;
 
     p = strrchr(name, '.');
diff --git a/crypto/conf/keysets.pl b/crypto/conf/keysets.pl
index cb0ddc300a..7e83d80050 100644
--- a/crypto/conf/keysets.pl
+++ b/crypto/conf/keysets.pl
@@ -73,10 +73,7 @@ print <<"EOF";
  * in the file LICENSE in the source distribution or at
  * https://www.openssl.org/source/license.html
  */
-#if !defined(OSSL_LIBCRYPTO_CONF_CONF_DEF_H)
-#define OSSL_LIBCRYPTO_CONF_CONF_DEF_H
 
-/* clang-format off */
 #define CONF_NUMBER       $NUMBER
 #define CONF_UPPER        $UPPER
 #define CONF_LOWER        $LOWER
@@ -126,5 +123,3 @@ for ($i = 0; $i < 128; $i++) {
 }
 print "\n};\n";
 print "#endif\n";
-print "/* clang-format on */\n";
-print "\n#endif /* !defined(OSSL_LIBCRYPTO_CONF_CONF_DEF_H) */\n";
diff --git a/crypto/context.c b/crypto/context.c
index 66d7e42955..506ad84e2f 100644
--- a/crypto/context.c
+++ b/crypto/context.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -255,6 +255,12 @@ err:
 
 static void context_deinit_objs(OSSL_LIB_CTX *ctx)
 {
+    /* P2. We want evp_method_store to be cleaned up before the provider store */
+    if (ctx->evp_method_store != NULL) {
+        ossl_method_store_free(ctx->evp_method_store);
+        ctx->evp_method_store = NULL;
+    }
+
     /* P2. */
     if (ctx->drbg != NULL) {
         ossl_rand_ctx_free(ctx->drbg);
@@ -272,14 +278,14 @@ static void context_deinit_objs(OSSL_LIB_CTX *ctx)
      * P2. We want decoder_store/decoder_cache to be cleaned up before the
      * provider store
      */
-    if (ctx->decoder_cache != NULL) {
-        ossl_decoder_cache_free(ctx->decoder_cache);
-        ctx->decoder_cache = NULL;
-    }
     if (ctx->decoder_store != NULL) {
         ossl_method_store_free(ctx->decoder_store);
         ctx->decoder_store = NULL;
     }
+    if (ctx->decoder_cache != NULL) {
+        ossl_decoder_cache_free(ctx->decoder_cache);
+        ctx->decoder_cache = NULL;
+    }
 
     /* P2. We want encoder_store to be cleaned up before the provider store */
     if (ctx->encoder_store != NULL) {
@@ -300,12 +306,6 @@ static void context_deinit_objs(OSSL_LIB_CTX *ctx)
         ctx->provider_store = NULL;
     }
 
-    /* P2. We want evp_method_store to be cleaned up before the provider store */
-    if (ctx->evp_method_store != NULL) {
-        ossl_method_store_free(ctx->evp_method_store);
-        ctx->evp_method_store = NULL;
-    }
-
     /* Default priority. */
     if (ctx->property_string_data != NULL) {
         ossl_property_string_data_free(ctx->property_string_data);
@@ -406,24 +406,24 @@ static int context_deinit(OSSL_LIB_CTX *ctx)
 static OSSL_LIB_CTX default_context_int;
 
 static CRYPTO_ONCE default_context_init = CRYPTO_ONCE_STATIC_INIT;
-static CRYPTO_ONCE default_context_thread_key_init = CRYPTO_ONCE_STATIC_INIT;
 static CRYPTO_THREAD_LOCAL default_context_thread_local;
 static int default_context_inited = 0;
 
-DEFINE_RUN_ONCE_STATIC(default_context_do_thread_key_init)
-{
-    if (!CRYPTO_THREAD_init_local(&default_context_thread_local, NULL))
-        return 0;
-    return 1;
-}
-
 DEFINE_RUN_ONCE_STATIC(default_context_do_init)
 {
+    if (!CRYPTO_THREAD_init_local(&default_context_thread_local, NULL))
+        goto err;
+
     if (!context_init(&default_context_int))
-        return 0;
+        goto deinit_thread;
 
     default_context_inited = 1;
     return 1;
+
+deinit_thread:
+    CRYPTO_THREAD_cleanup_local(&default_context_thread_local);
+err:
+    return 0;
 }
 
 void ossl_lib_ctx_default_deinit(void)
@@ -437,23 +437,12 @@ void ossl_lib_ctx_default_deinit(void)
 
 static OSSL_LIB_CTX *get_thread_default_context(void)
 {
-    if (!RUN_ONCE(&default_context_thread_key_init, default_context_do_thread_key_init))
-        return NULL;
-
     if (!RUN_ONCE(&default_context_init, default_context_do_init))
         return NULL;
 
     return CRYPTO_THREAD_get_local(&default_context_thread_local);
 }
 
-static OSSL_LIB_CTX *check_thread_default_context(void)
-{
-    if (!RUN_ONCE(&default_context_thread_key_init, default_context_do_thread_key_init))
-        return NULL;
-
-    return CRYPTO_THREAD_get_local(&default_context_thread_local);
-}
-
 static OSSL_LIB_CTX *get_default_context(void)
 {
     OSSL_LIB_CTX *current_defctx = get_thread_default_context();
@@ -463,15 +452,6 @@ static OSSL_LIB_CTX *get_default_context(void)
     return current_defctx;
 }
 
-static OSSL_LIB_CTX *check_default_context(void)
-{
-    OSSL_LIB_CTX *current_defctx = check_thread_default_context();
-
-    if (current_defctx == NULL && default_context_inited)
-        current_defctx = &default_context_int;
-    return current_defctx;
-}
-
 static int set_default_context(OSSL_LIB_CTX *defctx)
 {
     if (defctx == &default_context_int)
@@ -481,6 +461,19 @@ static int set_default_context(OSSL_LIB_CTX *defctx)
 }
 #endif
 
+int OSSL_LIB_CTX_freeze(OSSL_LIB_CTX *ctx, const char *propq)
+{
+    OSSL_METHOD_STORE *store;
+
+    store = ossl_lib_ctx_get_data(ctx, OSSL_LIB_CTX_EVP_METHOD_STORE_INDEX);
+    if (store == NULL) {
+        ERR_raise(ERR_LIB_EVP, ERR_R_PASSED_INVALID_ARGUMENT);
+        return 0;
+    }
+
+    return ossl_method_store_freeze_cache(store, propq);
+}
+
 OSSL_LIB_CTX *OSSL_LIB_CTX_new(void)
 {
     OSSL_LIB_CTX *ctx = OPENSSL_zalloc(sizeof(*ctx));
@@ -534,7 +527,7 @@ int OSSL_LIB_CTX_load_config(OSSL_LIB_CTX *ctx, const char *config_file)
 
 void OSSL_LIB_CTX_free(OSSL_LIB_CTX *ctx)
 {
-    if (ctx == NULL || ossl_lib_ctx_is_default_nocreate(ctx))
+    if (ctx == NULL || ossl_lib_ctx_is_default(ctx))
         return;
 
 #ifndef FIPS_MODULE
@@ -548,9 +541,6 @@ void OSSL_LIB_CTX_free(OSSL_LIB_CTX *ctx)
 #ifndef FIPS_MODULE
 OSSL_LIB_CTX *OSSL_LIB_CTX_get0_global_default(void)
 {
-    if (!RUN_ONCE(&default_context_thread_key_init, default_context_do_thread_key_init))
-        return NULL;
-
     if (!RUN_ONCE(&default_context_init, default_context_do_init))
         return NULL;
 
@@ -598,15 +588,6 @@ int ossl_lib_ctx_is_default(OSSL_LIB_CTX *ctx)
     return 0;
 }
 
-int ossl_lib_ctx_is_default_nocreate(OSSL_LIB_CTX *ctx)
-{
-#ifndef FIPS_MODULE
-    if (ctx == NULL || ctx == check_default_context())
-        return 1;
-#endif
-    return 0;
-}
-
 int ossl_lib_ctx_is_global_default(OSSL_LIB_CTX *ctx)
 {
 #ifndef FIPS_MODULE
diff --git a/crypto/core_fetch.c b/crypto/core_fetch.c
index 3d09b384aa..ab8ec59bde 100644
--- a/crypto/core_fetch.c
+++ b/crypto/core_fetch.c
@@ -107,7 +107,7 @@ static void ossl_method_construct_this(OSSL_PROVIDER *provider,
     struct construct_data_st *data = cbdata;
     void *method = NULL;
 
-    if ((method = data->mcm->construct(algo, provider, data->mcm_data, no_store))
+    if ((method = data->mcm->construct(algo, provider, data->mcm_data))
         == NULL)
         return;
 
@@ -162,14 +162,16 @@ void *ossl_method_construct(OSSL_LIB_CTX *libctx, int operation_id,
         ossl_method_construct_postcondition,
         &cbdata);
 
-    /* If there is a temporary store, try there first */
-    if (cbdata.store != NULL)
-        method = mcm->get(cbdata.store, (const OSSL_PROVIDER **)provider_rw,
-            mcm_data);
+    if (mcm->get != NULL) {
+        /* If there is a temporary store, try there first */
+        if (cbdata.store != NULL)
+            method = mcm->get(cbdata.store, (const OSSL_PROVIDER **)provider_rw,
+                mcm_data);
 
-    /* If no method was found yet, try the global store */
-    if (method == NULL)
-        method = mcm->get(NULL, (const OSSL_PROVIDER **)provider_rw, mcm_data);
+        /* If no method was found yet, try the global store */
+        if (method == NULL)
+            method = mcm->get(NULL, (const OSSL_PROVIDER **)provider_rw, mcm_data);
+    }
 
     return method;
 }
diff --git a/crypto/core_namemap.c b/crypto/core_namemap.c
index 7ba228bdc0..822656eaef 100644
--- a/crypto/core_namemap.c
+++ b/crypto/core_namemap.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,18 +7,22 @@
  * https://www.openssl.org/source/license.html
  */
 
+/*
+ * For EVP_PKEY_asn1_get0_info(), EVP_PKEY_asn1_get_count() and
+ * EVP_PKEY_asn1_get0()
+ */
+#define OPENSSL_SUPPRESS_DEPRECATED
+
 #include "internal/namemap.h"
 #include "internal/tsan_assist.h"
 #include "internal/hashtable.h"
 #include "internal/sizes.h"
 #include "crypto/context.h"
-#include "crypto/evp.h"
 
 #define NAMEMAP_HT_BUCKETS 512
 
-#define NAMEMAP_NAME_LEN 64
 HT_START_KEY_DEFN(namenum_key)
-HT_DEF_KEY_FIELD_CHAR_ARRAY(name, NAMEMAP_NAME_LEN)
+HT_DEF_KEY_FIELD_CHAR_ARRAY(name, 64)
 HT_END_KEY_DEFN(NAMENUM_KEY)
 
 /*-
@@ -141,9 +145,28 @@ int ossl_namemap_doall_names(const OSSL_NAMEMAP *namemap, int number,
 
 int ossl_namemap_name2num(const OSSL_NAMEMAP *namemap, const char *name)
 {
-    if (name == NULL)
+    int number = 0;
+    HT_VALUE *val;
+    NAMENUM_KEY key;
+
+#ifndef FIPS_MODULE
+    if (namemap == NULL)
+        namemap = ossl_namemap_stored(NULL);
+#endif
+
+    if (namemap == NULL)
         return 0;
-    return ossl_namemap_name2num_n(namemap, name, strlen(name));
+
+    HT_INIT_KEY(&key);
+    HT_SET_KEY_STRING_CASE(&key, name, name);
+
+    val = ossl_ht_get(namemap->namenum_ht, TO_HT_KEY(&key));
+
+    if (val != NULL)
+        /* We store a (small) int directly instead of a pointer to it. */
+        number = (int)(intptr_t)val->value;
+
+    return number;
 }
 
 int ossl_namemap_name2num_n(const OSSL_NAMEMAP *namemap,
@@ -161,11 +184,8 @@ int ossl_namemap_name2num_n(const OSSL_NAMEMAP *namemap,
     if (namemap == NULL)
         return 0;
 
-    if (name_len > NAMEMAP_NAME_LEN)
-        name_len = NAMEMAP_NAME_LEN;
-
-    HT_INIT_RAW_KEY(&key);
-    HT_COPY_RAW_KEY_CASE(TO_HT_KEY(&key), name, name_len);
+    HT_INIT_KEY(&key);
+    HT_SET_KEY_STRING_CASE_N(&key, name, name, (int)name_len);
 
     val = ossl_ht_get(namemap->namenum_ht, TO_HT_KEY(&key));
 
@@ -256,9 +276,8 @@ static int namemap_add_name(OSSL_NAMEMAP *namemap, int number,
     /* Using tsan_store alone here is safe since we're under lock */
     tsan_store(&namemap->max_number, number);
 
-    HT_INIT_RAW_KEY(&key);
-    HT_COPY_RAW_KEY_CASE(TO_HT_KEY(&key), name, strlen(name));
-
+    HT_INIT_KEY(&key);
+    HT_SET_KEY_STRING_CASE(&key, name, name);
     val.value = (void *)(intptr_t)number;
     ret = ossl_ht_insert(namemap->namenum_ht, TO_HT_KEY(&key), &val, NULL);
     if (ret <= 0) {
@@ -427,7 +446,7 @@ static void get_legacy_pkey_meth_names(const EVP_PKEY_ASN1_METHOD *ameth,
     int nid = 0, base_nid = 0, flags = 0;
     const char *pem_name = NULL;
 
-    evp_pkey_asn1_get0_info(&nid, &base_nid, &flags, NULL, &pem_name, ameth);
+    EVP_PKEY_asn1_get0_info(&nid, &base_nid, &flags, NULL, &pem_name, ameth);
     if (nid != NID_undef) {
         if ((flags & ASN1_PKEY_ALIAS) == 0) {
             switch (nid) {
@@ -515,8 +534,8 @@ OSSL_NAMEMAP *ossl_namemap_stored(OSSL_LIB_CTX *libctx)
             int i, end;
 
             /* We also pilfer data from the legacy EVP_PKEY_ASN1_METHODs */
-            for (i = 0, end = evp_pkey_asn1_get_count(); i < end; i++)
-                get_legacy_pkey_meth_names(evp_pkey_asn1_get0(i), namemap);
+            for (i = 0, end = EVP_PKEY_asn1_get_count(); i < end; i++)
+                get_legacy_pkey_meth_names(EVP_PKEY_asn1_get0(i), namemap);
         }
 #endif
     }
diff --git a/crypto/cpuid.c b/crypto/cpuid.c
index 89d841bfd0..d659135919 100644
--- a/crypto/cpuid.c
+++ b/crypto/cpuid.c
@@ -193,10 +193,6 @@ void OPENSSL_cpuid_setup(void)
  * not volatile, but compilers do this in practice anyway.
  *
  * There are also assembler versions of this function.
- *
- * This C version and the per-architecture assembler versions are all verified
- * to be constant-time under enable-ct-validation for Valgrind-supported
- * architectures, currently x86_64 and aarch64.
  */
 #undef CRYPTO_memcmp
 int CRYPTO_memcmp(const void *in_a, const void *in_b, size_t len)
diff --git a/crypto/crmf/crmf_lib.c b/crypto/crmf/crmf_lib.c
index 5747ab1856..3792c2e83b 100644
--- a/crypto/crmf/crmf_lib.c
+++ b/crypto/crmf/crmf_lib.c
@@ -1,5 +1,5 @@
 /*-
- * Copyright 2007-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright Nokia 2007-2018
  * Copyright Siemens AG 2015-2019
  *
@@ -537,13 +537,13 @@ int OSSL_CRMF_MSGS_verify_popo(const OSSL_CRMF_MSGS *reqs,
     return 1;
 }
 
-int OSSL_CRMF_MSG_centralkeygen_requested(const OSSL_CRMF_MSG *crm, const X509_REQ *p10)
+int OSSL_CRMF_MSG_centralkeygen_requested(const OSSL_CRMF_MSG *crm, const X509_REQ *p10cr)
 {
     X509_PUBKEY *pubkey = NULL;
     const unsigned char *pk = NULL;
     int pklen, ret = 0;
 
-    if (crm == NULL && p10 == NULL) {
+    if (crm == NULL && p10cr == NULL) {
         ERR_raise(ERR_LIB_CRMF, CRMF_R_NULL_ARGUMENT);
         return -1;
     }
@@ -551,7 +551,7 @@ int OSSL_CRMF_MSG_centralkeygen_requested(const OSSL_CRMF_MSG *crm, const X509_R
     if (crm != NULL)
         pubkey = OSSL_CRMF_CERTTEMPLATE_get0_publicKey(OSSL_CRMF_MSG_get0_tmpl(crm));
     else
-        pubkey = p10->req_info.pubkey;
+        pubkey = p10cr->req_info.pubkey;
 
     if (pubkey == NULL
         || (X509_PUBKEY_get0_param(NULL, &pk, &pklen, NULL, pubkey)
@@ -762,7 +762,6 @@ unsigned char *OSSL_CRMF_ENCRYPTEDVALUE_decrypt(const OSSL_CRMF_ENCRYPTEDVALUE *
     EVP_CIPHER *cipher = NULL; /* used cipher */
     int cikeysize = 0; /* key size from cipher */
     unsigned char *iv = NULL; /* initial vector for symmetric encryption */
-    int iv_len; /* iv length */
     unsigned char *out = NULL; /* decryption output buffer */
     int n, ret = 0;
     EVP_PKEY_CTX *pkctx = NULL; /* private key context */
@@ -781,11 +780,16 @@ unsigned char *OSSL_CRMF_ENCRYPTEDVALUE_decrypt(const OSSL_CRMF_ENCRYPTEDVALUE *
 
     /* select symmetric cipher based on algorithm given in message */
     OBJ_obj2txt(name, sizeof(name), enc->symmAlg->algorithm, 0);
+    (void)ERR_set_mark();
     cipher = EVP_CIPHER_fetch(libctx, name, propq);
+    if (cipher == NULL)
+        cipher = (EVP_CIPHER *)EVP_get_cipherbyobj(enc->symmAlg->algorithm);
     if (cipher == NULL) {
+        (void)ERR_clear_last_mark();
         ERR_raise(ERR_LIB_CRMF, CRMF_R_UNSUPPORTED_CIPHER);
         goto end;
     }
+    (void)ERR_pop_to_mark();
 
     cikeysize = EVP_CIPHER_get_key_length(cipher);
     /* first the symmetric key needs to be decrypted */
@@ -812,12 +816,11 @@ unsigned char *OSSL_CRMF_ENCRYPTEDVALUE_decrypt(const OSSL_CRMF_ENCRYPTEDVALUE *
     } else {
         goto end;
     }
-    iv_len = EVP_CIPHER_get_iv_length(cipher);
-    if ((iv = OPENSSL_malloc(iv_len)) == NULL)
+    if ((iv = OPENSSL_malloc(EVP_CIPHER_get_iv_length(cipher))) == NULL)
         goto end;
-    if (enc->symmAlg->parameter == NULL
-        || ASN1_TYPE_get_octetstring(enc->symmAlg->parameter, iv, iv_len)
-            != iv_len) {
+    if (ASN1_TYPE_get_octetstring(enc->symmAlg->parameter, iv,
+            EVP_CIPHER_get_iv_length(cipher))
+        != EVP_CIPHER_get_iv_length(cipher)) {
         ERR_raise(ERR_LIB_CRMF, CRMF_R_MALFORMED_IV);
         goto end;
     }
@@ -850,7 +853,7 @@ end:
     return NULL;
 }
 
-/*-
+/*
  * Decrypts the certificate in the given encryptedValue using private key pkey.
  * This is needed for the indirect PoP method as in RFC 9810 section 5.2.8.3.2.
  *
@@ -880,7 +883,6 @@ end:
     OPENSSL_free(buf);
     return cert;
 }
-
 /*-
  * Decrypts the certificate in the given encryptedKey using private key pkey.
  * This is needed for the indirect PoP method as in RFC 9810 section 5.2.8.3.2.
diff --git a/crypto/crmf/crmf_pbm.c b/crypto/crmf/crmf_pbm.c
index 2825a6773a..7f326a0b6a 100644
--- a/crypto/crmf/crmf_pbm.c
+++ b/crypto/crmf/crmf_pbm.c
@@ -1,5 +1,5 @@
 /*-
- * Copyright 2007-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright Nokia 2007-2019
  * Copyright Siemens AG 2015-2019
  *
@@ -16,8 +16,6 @@
 #include "internal/sizes.h" /* for OSSL_MAX_NAME_SIZE */
 #include 
 
-#include 
-
 /*-
  * creates and initializes OSSL_CRMF_PBMPARAMETER (section 4.4)
  * |slen| SHOULD be at least 8 (16 is common)
diff --git a/crypto/cryptlib.c b/crypto/cryptlib.c
index 07b244cb35..7624574103 100644
--- a/crypto/cryptlib.c
+++ b/crypto/cryptlib.c
@@ -15,6 +15,13 @@
 #if defined(_WIN32) && !defined(OPENSSL_SYS_UEFI)
 #include 
 #include 
+#ifdef __WATCOMC__
+#if defined(_UNICODE) || defined(__UNICODE__)
+#define _vsntprintf _vsnwprintf
+#else
+#define _vsntprintf _vsnprintf
+#endif
+#endif
 #ifdef _MSC_VER
 #define alloca _alloca
 #endif
@@ -103,6 +110,8 @@ void OPENSSL_showfatal(const char *fmta, ...)
     /*
      * First check if it's a console application, in which case the
      * error message would be printed to standard error.
+     * Windows CE does not have a concept of a console application,
+     * so we need to guard the check.
      */
 #ifdef STD_ERROR_HANDLE
     HANDLE h;
@@ -251,7 +260,9 @@ void OPENSSL_die(const char *message, const char *file, int line)
     /*
      * Win32 abort() customarily shows a dialog, but we just did that...
      */
+#if !defined(_WIN32_WCE)
     raise(SIGABRT);
+#endif
     _exit(3);
 #endif
 }
diff --git a/crypto/ct/ct_b64.c b/crypto/ct/ct_b64.c
index ed84073503..a292a95627 100644
--- a/crypto/ct/ct_b64.c
+++ b/crypto/ct/ct_b64.c
@@ -84,7 +84,7 @@ SCT *SCT_new_from_base64(unsigned char version, const char *logid_base64,
 
     declen = ct_base64_decode(logid_base64, &dec);
     if (declen < 0) {
-        ERR_raise(ERR_LIB_CT, CT_R_BASE64_DECODE_ERROR);
+        ERR_raise(ERR_LIB_CT, X509_R_BASE64_DECODE_ERROR);
         goto err;
     }
     if (!SCT_set0_log_id(sct, dec, declen))
@@ -93,7 +93,7 @@ SCT *SCT_new_from_base64(unsigned char version, const char *logid_base64,
 
     declen = ct_base64_decode(extensions_base64, &dec);
     if (declen < 0) {
-        ERR_raise(ERR_LIB_CT, CT_R_BASE64_DECODE_ERROR);
+        ERR_raise(ERR_LIB_CT, X509_R_BASE64_DECODE_ERROR);
         goto err;
     }
     SCT_set0_extensions(sct, dec, declen);
@@ -101,7 +101,7 @@ SCT *SCT_new_from_base64(unsigned char version, const char *logid_base64,
 
     declen = ct_base64_decode(signature_base64, &dec);
     if (declen < 0) {
-        ERR_raise(ERR_LIB_CT, CT_R_BASE64_DECODE_ERROR);
+        ERR_raise(ERR_LIB_CT, X509_R_BASE64_DECODE_ERROR);
         goto err;
     }
 
diff --git a/crypto/ct/ct_local.h b/crypto/ct/ct_local.h
index 337dc272c3..d2f6c48cbd 100644
--- a/crypto/ct/ct_local.h
+++ b/crypto/ct/ct_local.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_CT_CT_LOCAL_H)
-#define OSSL_LIBCRYPTO_CT_CT_LOCAL_H
-
 #include 
 #include 
 #include 
@@ -17,8 +14,6 @@
 #include 
 #include 
 
-#include "internal/common.h"
-
 /*
  * From RFC6962: opaque SerializedSCT<1..2^16-1>; struct { SerializedSCT
  * sct_list <1..2^16-1>; } SignedCertificateTimestampList;
@@ -26,6 +21,39 @@
 #define MAX_SCT_SIZE 65535
 #define MAX_SCT_LIST_SIZE MAX_SCT_SIZE
 
+/*
+ * Macros to read and write integers in network-byte order.
+ */
+
+#define n2s(c, s) ((s = (((unsigned int)((c)[0])) << 8) | (((unsigned int)((c)[1])))), c += 2)
+
+#define s2n(s, c) ((c[0] = (unsigned char)(((s) >> 8) & 0xff), \
+                       c[1] = (unsigned char)(((s)) & 0xff)),  \
+    c += 2)
+
+#define l2n3(l, c) ((c[0] = (unsigned char)(((l) >> 16) & 0xff),   \
+                        c[1] = (unsigned char)(((l) >> 8) & 0xff), \
+                        c[2] = (unsigned char)(((l)) & 0xff)),     \
+    c += 3)
+
+#define n2l8(c, l) (l = ((uint64_t)(*((c)++))) << 56, \
+    l |= ((uint64_t)(*((c)++))) << 48,                \
+    l |= ((uint64_t)(*((c)++))) << 40,                \
+    l |= ((uint64_t)(*((c)++))) << 32,                \
+    l |= ((uint64_t)(*((c)++))) << 24,                \
+    l |= ((uint64_t)(*((c)++))) << 16,                \
+    l |= ((uint64_t)(*((c)++))) << 8,                 \
+    l |= ((uint64_t)(*((c)++))))
+
+#define l2n8(l, c) (*((c)++) = (unsigned char)(((l) >> 56) & 0xff), \
+    *((c)++) = (unsigned char)(((l) >> 48) & 0xff),                 \
+    *((c)++) = (unsigned char)(((l) >> 40) & 0xff),                 \
+    *((c)++) = (unsigned char)(((l) >> 32) & 0xff),                 \
+    *((c)++) = (unsigned char)(((l) >> 24) & 0xff),                 \
+    *((c)++) = (unsigned char)(((l) >> 16) & 0xff),                 \
+    *((c)++) = (unsigned char)(((l) >> 8) & 0xff),                  \
+    *((c)++) = (unsigned char)(((l)) & 0xff))
+
 /* Signed Certificate Timestamp */
 struct sct_st {
     sct_version_t version;
@@ -117,7 +145,7 @@ __owur int SCT_CTX_set1_cert(SCT_CTX *sctx, X509 *cert, X509 *presigner);
  * Issuer must not be NULL.
  * Returns 1 on success, 0 on failure.
  */
-__owur int SCT_CTX_set1_issuer(SCT_CTX *sctx, X509 *issuer);
+__owur int SCT_CTX_set1_issuer(SCT_CTX *sctx, const X509 *issuer);
 
 /*
  * Sets the public key of the issuer of the certificate that the SCT was created
@@ -125,13 +153,14 @@ __owur int SCT_CTX_set1_issuer(SCT_CTX *sctx, X509 *issuer);
  * The public key must not be NULL.
  * Returns 1 on success, 0 on failure.
  */
-__owur int SCT_CTX_set1_issuer_pubkey(SCT_CTX *sctx, const X509_PUBKEY *pubkey);
+__owur int SCT_CTX_set1_issuer_pubkey(SCT_CTX *sctx, X509_PUBKEY *pubkey);
 
 /*
  * Sets the public key of the CT log that the SCT is from.
  * Returns 1 on success, 0 on failure.
  */
 __owur int SCT_CTX_set1_pubkey(SCT_CTX *sctx, X509_PUBKEY *pubkey);
+
 /*
  * Sets the time to evaluate the SCT against, in milliseconds since the Unix
  * epoch. If the SCT's timestamp is after this time, it will be interpreted as
@@ -187,5 +216,3 @@ __owur int o2i_SCT_signature(SCT *sct, const unsigned char **in, size_t len);
  * Handlers for Certificate Transparency X509v3/OCSP extensions
  */
 extern const X509V3_EXT_METHOD ossl_v3_ct_scts[3];
-
-#endif /* !defined(OSSL_LIBCRYPTO_CT_CT_LOCAL_H) */
diff --git a/crypto/ct/ct_log.c b/crypto/ct/ct_log.c
index 6fad6a6bd4..b9990dc9a0 100644
--- a/crypto/ct/ct_log.c
+++ b/crypto/ct/ct_log.c
@@ -315,20 +315,6 @@ EVP_PKEY *CTLOG_get0_public_key(const CTLOG *log)
     return log->public_key;
 }
 
-int CTLOG_STORE_add0_log(CTLOG_STORE *store, CTLOG *log)
-{
-    if (store == NULL || log == NULL) {
-        ERR_raise(ERR_LIB_CT, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
-    if (!sk_CTLOG_push(store->logs, log)) {
-        ERR_raise(ERR_LIB_CT, ERR_R_CRYPTO_LIB);
-        return 0;
-    }
-    return 1;
-}
-
 /*
  * Given a log ID, finds the matching log.
  * Returns NULL if no match found.
diff --git a/crypto/ct/ct_oct.c b/crypto/ct/ct_oct.c
index 4f5fd8d027..770027741c 100644
--- a/crypto/ct/ct_oct.c
+++ b/crypto/ct/ct_oct.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -347,7 +347,7 @@ int i2o_SCT_LIST(const STACK_OF(SCT) *a, unsigned char **pp)
             if ((sct_len = i2o_SCT(sk_SCT_value(a, i), NULL)) == -1)
                 goto err;
         }
-        len2 += (size_t)sct_len + 2;
+        len2 += 2 + sct_len;
     }
 
     if (len2 > MAX_SCT_LIST_SIZE)
@@ -380,8 +380,8 @@ STACK_OF(SCT) *d2i_SCT_LIST(STACK_OF(SCT) **a, const unsigned char **pp,
     if (d2i_ASN1_OCTET_STRING(&oct, &p, len) == NULL)
         return NULL;
 
-    p = ASN1_STRING_get0_data(oct);
-    if ((sk = o2i_SCT_LIST(a, &p, ASN1_STRING_length_ex(oct))) != NULL)
+    p = oct->data;
+    if ((sk = o2i_SCT_LIST(a, &p, oct->length)) != NULL)
         *pp += len;
 
     ASN1_OCTET_STRING_free(oct);
@@ -390,20 +390,14 @@ STACK_OF(SCT) *d2i_SCT_LIST(STACK_OF(SCT) **a, const unsigned char **pp,
 
 int i2d_SCT_LIST(const STACK_OF(SCT) *a, unsigned char **out)
 {
-    ASN1_OCTET_STRING *oct;
-    unsigned char *data = NULL;
+    ASN1_OCTET_STRING oct;
     int len;
 
-    if ((len = i2o_SCT_LIST(a, &data)) == -1)
+    oct.data = NULL;
+    if ((oct.length = i2o_SCT_LIST(a, &oct.data)) == -1)
         return -1;
 
-    oct = ASN1_OCTET_STRING_new();
-    if (oct == NULL) {
-        OPENSSL_free(data);
-        return -1;
-    }
-    ASN1_STRING_set0(oct, data, len);
-    len = i2d_ASN1_OCTET_STRING(oct, out);
-    ASN1_OCTET_STRING_free(oct);
+    len = i2d_ASN1_OCTET_STRING(&oct, out);
+    OPENSSL_free(oct.data);
     return len;
 }
diff --git a/crypto/ct/ct_sct_ctx.c b/crypto/ct/ct_sct_ctx.c
index 80603b617f..af5be04eff 100644
--- a/crypto/ct/ct_sct_ctx.c
+++ b/crypto/ct/ct_sct_ctx.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2016-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -74,15 +74,11 @@ static int ct_x509_get_ext(X509 *cert, int nid, int *is_duplicated)
  */
 __owur static int ct_x509_cert_fixup(X509 *cert, X509 *presigner)
 {
-    int ret = 0;
     int preidx, certidx;
     int pre_akid_ext_is_dup, cert_akid_ext_is_dup;
-    X509_EXTENSION *new = NULL;
 
-    if (presigner == NULL) {
-        ret = 1;
-        goto done;
-    }
+    if (presigner == NULL)
+        return 1;
 
     preidx = ct_x509_get_ext(presigner, NID_authority_key_identifier,
         &pre_akid_ext_is_dup);
@@ -91,41 +87,32 @@ __owur static int ct_x509_cert_fixup(X509 *cert, X509 *presigner)
 
     /* An error occurred whilst searching for the extension */
     if (preidx < -1 || certidx < -1)
-        goto done;
+        return 0;
     /* Invalid certificate if they contain duplicate extensions */
     if (pre_akid_ext_is_dup || cert_akid_ext_is_dup)
-        goto done;
+        return 0;
     /* AKID must be present in both certificate or absent in both */
     if (preidx >= 0 && certidx == -1)
-        goto done;
+        return 0;
     if (preidx == -1 && certidx >= 0)
-        goto done;
+        return 0;
     /* Copy issuer name */
     if (!X509_set_issuer_name(cert, X509_get_issuer_name(presigner)))
-        goto done;
+        return 0;
     if (preidx != -1) {
         /* Retrieve and copy AKID encoding */
-        const X509_EXTENSION *preext = X509_get_ext(presigner, preidx);
-        const X509_EXTENSION *certext = X509_get_ext(cert, certidx);
-        const ASN1_OCTET_STRING *preextdata;
+        X509_EXTENSION *preext = X509_get_ext(presigner, preidx);
+        X509_EXTENSION *certext = X509_get_ext(cert, certidx);
+        ASN1_OCTET_STRING *preextdata;
 
         /* Should never happen */
         if (preext == NULL || certext == NULL)
-            goto done;
-        if ((new = X509_EXTENSION_dup(certext)) == NULL)
-            goto done;
+            return 0;
         preextdata = X509_EXTENSION_get_data(preext);
-        if (preextdata == NULL || !X509_EXTENSION_set_data(new, preextdata))
-            goto done;
-        X509_EXTENSION_free(X509_delete_ext(cert, certidx));
-        certext = NULL;
-        if (!X509_add_ext(cert, new, certidx))
-            goto done;
-        ret = 1;
+        if (preextdata == NULL || !X509_EXTENSION_set_data(certext, preextdata))
+            return 0;
     }
-done:
-    X509_EXTENSION_free(new);
-    return ret;
+    return 1;
 }
 
 int SCT_CTX_set1_cert(SCT_CTX *sctx, X509 *cert, X509 *presigner)
@@ -210,7 +197,7 @@ err:
     return 0;
 }
 
-__owur static int ct_public_key_hash(SCT_CTX *sctx, const X509_PUBKEY *pkey,
+__owur static int ct_public_key_hash(SCT_CTX *sctx, X509_PUBKEY *pkey,
     unsigned char **hash, size_t *hash_len)
 {
     int ret = 0;
@@ -254,12 +241,12 @@ err:
     return ret;
 }
 
-int SCT_CTX_set1_issuer(SCT_CTX *sctx, X509 *issuer)
+int SCT_CTX_set1_issuer(SCT_CTX *sctx, const X509 *issuer)
 {
     return SCT_CTX_set1_issuer_pubkey(sctx, X509_get_X509_PUBKEY(issuer));
 }
 
-int SCT_CTX_set1_issuer_pubkey(SCT_CTX *sctx, const X509_PUBKEY *pubkey)
+int SCT_CTX_set1_issuer_pubkey(SCT_CTX *sctx, X509_PUBKEY *pubkey)
 {
     return ct_public_key_hash(sctx, pubkey, &sctx->ihash, &sctx->ihashlen);
 }
diff --git a/crypto/ctype.c b/crypto/ctype.c
index 75192b11f4..686fe64165 100644
--- a/crypto/ctype.c
+++ b/crypto/ctype.c
@@ -226,7 +226,7 @@ static const unsigned short ctype_char_map[128] = {
 #ifdef CHARSET_EBCDIC
 int ossl_toascii(int c)
 {
-    if (c < -128 || c >= 256 || c == EOF)
+    if (c < -128 || c > 256 || c == EOF)
         return c;
     /*
      * Adjust negatively signed characters.
@@ -241,7 +241,7 @@ int ossl_toascii(int c)
 
 int ossl_fromascii(int c)
 {
-    if (c < -128 || c >= 256 || c == EOF)
+    if (c < -128 || c > 256 || c == EOF)
         return c;
     if (c < 0)
         c += 256;
diff --git a/crypto/des/asm/dest4-sparcv9.pl b/crypto/des/asm/dest4-sparcv9.pl
index 87a5a82742..afa15860f0 100644
--- a/crypto/des/asm/dest4-sparcv9.pl
+++ b/crypto/des/asm/dest4-sparcv9.pl
@@ -40,7 +40,7 @@ $code.=<<___;
 #ifndef __ASSEMBLER__
 # define __ASSEMBLER__ 1
 #endif
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 #ifdef	__arch64__
 .register       %g2,#scratch
diff --git a/crypto/des/cfb64ede.c b/crypto/des/cfb64ede.c
index 56aab27f0d..26613a05fe 100644
--- a/crypto/des/cfb64ede.c
+++ b/crypto/des/cfb64ede.c
@@ -28,7 +28,7 @@ void DES_ede3_cfb64_encrypt(const unsigned char *in, unsigned char *out,
 {
     register DES_LONG v0, v1;
     register long l = length;
-    register int n = *num & 0x07;
+    register int n = *num;
     DES_LONG ti[2];
     unsigned char *iv, c, cc;
 
diff --git a/crypto/des/cfb64enc.c b/crypto/des/cfb64enc.c
index b3abc12a25..3ddd6819e2 100644
--- a/crypto/des/cfb64enc.c
+++ b/crypto/des/cfb64enc.c
@@ -27,7 +27,7 @@ void DES_cfb64_encrypt(const unsigned char *in, unsigned char *out,
 {
     register DES_LONG v0, v1;
     register long l = length;
-    register int n = *num & 0x07;
+    register int n = *num;
     DES_LONG ti[2];
     unsigned char *iv, c, cc;
 
diff --git a/crypto/des/des_local.h b/crypto/des/des_local.h
index fa368c359c..8d08aca7e6 100644
--- a/crypto/des/des_local.h
+++ b/crypto/des/des_local.h
@@ -18,8 +18,6 @@
 
 #include 
 
-#include "internal/common.h"
-
 #ifdef OPENSSL_BUILD_SHLIBCRYPTO
 #undef OPENSSL_EXTERN
 #define OPENSSL_EXTERN OPENSSL_EXPORT
@@ -28,11 +26,84 @@
 #define ITERATIONS 16
 #define HALF_ITERATIONS 8
 
+#define c2l(c, l) (l = ((DES_LONG)(*((c)++))), \
+    l |= ((DES_LONG)(*((c)++))) << 8L,         \
+    l |= ((DES_LONG)(*((c)++))) << 16L,        \
+    l |= ((DES_LONG)(*((c)++))) << 24L)
+
+/* NOTE - c is not incremented as per c2l */
+#define c2ln(c, l1, l2, n)                       \
+    {                                            \
+        c += n;                                  \
+        l1 = l2 = 0;                             \
+        switch (n) {                             \
+        case 8:                                  \
+            l2 = ((DES_LONG)(*(--(c)))) << 24L;  \
+        /* fall through */                       \
+        case 7:                                  \
+            l2 |= ((DES_LONG)(*(--(c)))) << 16L; \
+        /* fall through */                       \
+        case 6:                                  \
+            l2 |= ((DES_LONG)(*(--(c)))) << 8L;  \
+        /* fall through */                       \
+        case 5:                                  \
+            l2 |= ((DES_LONG)(*(--(c))));        \
+        /* fall through */                       \
+        case 4:                                  \
+            l1 = ((DES_LONG)(*(--(c)))) << 24L;  \
+        /* fall through */                       \
+        case 3:                                  \
+            l1 |= ((DES_LONG)(*(--(c)))) << 16L; \
+        /* fall through */                       \
+        case 2:                                  \
+            l1 |= ((DES_LONG)(*(--(c)))) << 8L;  \
+        /* fall through */                       \
+        case 1:                                  \
+            l1 |= ((DES_LONG)(*(--(c))));        \
+        }                                        \
+    }
+
+#define l2c(l, c) (*((c)++) = (unsigned char)(((l)) & 0xff), \
+    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff),          \
+    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff),         \
+    *((c)++) = (unsigned char)(((l) >> 24L) & 0xff))
+
+/* NOTE - c is not incremented as per l2c */
+#define l2cn(l1, l2, c, n)                                    \
+    {                                                         \
+        c += n;                                               \
+        switch (n) {                                          \
+        case 8:                                               \
+            *(--(c)) = (unsigned char)(((l2) >> 24L) & 0xff); \
+        /* fall through */                                    \
+        case 7:                                               \
+            *(--(c)) = (unsigned char)(((l2) >> 16L) & 0xff); \
+        /* fall through */                                    \
+        case 6:                                               \
+            *(--(c)) = (unsigned char)(((l2) >> 8L) & 0xff);  \
+        /* fall through */                                    \
+        case 5:                                               \
+            *(--(c)) = (unsigned char)(((l2)) & 0xff);        \
+        /* fall through */                                    \
+        case 4:                                               \
+            *(--(c)) = (unsigned char)(((l1) >> 24L) & 0xff); \
+        /* fall through */                                    \
+        case 3:                                               \
+            *(--(c)) = (unsigned char)(((l1) >> 16L) & 0xff); \
+        /* fall through */                                    \
+        case 2:                                               \
+            *(--(c)) = (unsigned char)(((l1) >> 8L) & 0xff);  \
+        /* fall through */                                    \
+        case 1:                                               \
+            *(--(c)) = (unsigned char)(((l1)) & 0xff);        \
+        }                                                     \
+    }
+
 #if defined(_MSC_VER)
 #define ROTATE(a, n) (_lrotr(a, n))
 #elif defined(__ICC)
 #define ROTATE(a, n) (_rotr(a, n))
-#elif defined(__GNUC__) && !defined(__STRICT_ANSI__) && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM) && !defined(PEDANTIC)
+#elif defined(__GNUC__) && __GNUC__ >= 2 && !defined(__STRICT_ANSI__) && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM) && !defined(PEDANTIC)
 #if defined(__i386) || defined(__i386__) || defined(__x86_64) || defined(__x86_64__)
 #define ROTATE(a, n) ({        \
     register unsigned int ret; \
diff --git a/crypto/des/fcrypt.c b/crypto/des/fcrypt.c
index c01e1f960d..ebf5ce0ee0 100644
--- a/crypto/des/fcrypt.c
+++ b/crypto/des/fcrypt.c
@@ -32,19 +32,134 @@
  * implementations do.
  */
 static const unsigned char con_salt[128] = {
-    0xD2, 0xD3, 0xD4, 0xD5, 0xD6, 0xD7, 0xD8, 0xD9, 0xDA, 0xDB,
-    0xDC, 0xDD, 0xDE, 0xDF, 0xE0, 0xE1, 0xE2, 0xE3, 0xE4, 0xE5,
-    0xE6, 0xE7, 0xE8, 0xE9, 0xEA, 0xEB, 0xEC, 0xED, 0xEE, 0xEF,
-    0xF0, 0xF1, 0xF2, 0xF3, 0xF4, 0xF5, 0xF6, 0xF7, 0xF8, 0xF9,
-    0xFA, 0xFB, 0xFC, 0xFD, 0xFE, 0xFF, 0x00, 0x01, 0x02, 0x03,
-    0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0A, 0x0B, 0x05, 0x06,
-    0x07, 0x08, 0x09, 0x0A, 0x0B, 0x0C, 0x0D, 0x0E, 0x0F, 0x10,
-    0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17, 0x18, 0x19, 0x1A,
-    0x1B, 0x1C, 0x1D, 0x1E, 0x1F, 0x20, 0x21, 0x22, 0x23, 0x24,
-    0x25, 0x20, 0x21, 0x22, 0x23, 0x24, 0x25, 0x26, 0x27, 0x28,
-    0x29, 0x2A, 0x2B, 0x2C, 0x2D, 0x2E, 0x2F, 0x30, 0x31, 0x32,
-    0x33, 0x34, 0x35, 0x36, 0x37, 0x38, 0x39, 0x3A, 0x3B, 0x3C,
-    0x3D, 0x3E, 0x3F, 0x40, 0x41, 0x42, 0x43, 0x44
+    0xD2,
+    0xD3,
+    0xD4,
+    0xD5,
+    0xD6,
+    0xD7,
+    0xD8,
+    0xD9,
+    0xDA,
+    0xDB,
+    0xDC,
+    0xDD,
+    0xDE,
+    0xDF,
+    0xE0,
+    0xE1,
+    0xE2,
+    0xE3,
+    0xE4,
+    0xE5,
+    0xE6,
+    0xE7,
+    0xE8,
+    0xE9,
+    0xEA,
+    0xEB,
+    0xEC,
+    0xED,
+    0xEE,
+    0xEF,
+    0xF0,
+    0xF1,
+    0xF2,
+    0xF3,
+    0xF4,
+    0xF5,
+    0xF6,
+    0xF7,
+    0xF8,
+    0xF9,
+    0xFA,
+    0xFB,
+    0xFC,
+    0xFD,
+    0xFE,
+    0xFF,
+    0x00,
+    0x01,
+    0x02,
+    0x03,
+    0x04,
+    0x05,
+    0x06,
+    0x07,
+    0x08,
+    0x09,
+    0x0A,
+    0x0B,
+    0x05,
+    0x06,
+    0x07,
+    0x08,
+    0x09,
+    0x0A,
+    0x0B,
+    0x0C,
+    0x0D,
+    0x0E,
+    0x0F,
+    0x10,
+    0x11,
+    0x12,
+    0x13,
+    0x14,
+    0x15,
+    0x16,
+    0x17,
+    0x18,
+    0x19,
+    0x1A,
+    0x1B,
+    0x1C,
+    0x1D,
+    0x1E,
+    0x1F,
+    0x20,
+    0x21,
+    0x22,
+    0x23,
+    0x24,
+    0x25,
+    0x20,
+    0x21,
+    0x22,
+    0x23,
+    0x24,
+    0x25,
+    0x26,
+    0x27,
+    0x28,
+    0x29,
+    0x2A,
+    0x2B,
+    0x2C,
+    0x2D,
+    0x2E,
+    0x2F,
+    0x30,
+    0x31,
+    0x32,
+    0x33,
+    0x34,
+    0x35,
+    0x36,
+    0x37,
+    0x38,
+    0x39,
+    0x3A,
+    0x3B,
+    0x3C,
+    0x3D,
+    0x3E,
+    0x3F,
+    0x40,
+    0x41,
+    0x42,
+    0x43,
+    0x44,
 };
 
 static const unsigned char cov_2char[64] = {
diff --git a/crypto/des/ofb64ede.c b/crypto/des/ofb64ede.c
index 17236d2195..b0f9f0441c 100644
--- a/crypto/des/ofb64ede.c
+++ b/crypto/des/ofb64ede.c
@@ -26,7 +26,7 @@ void DES_ede3_ofb64_encrypt(register const unsigned char *in,
     DES_key_schedule *k3, DES_cblock *ivec, int *num)
 {
     register DES_LONG v0, v1;
-    register int n = *num & 0x07;
+    register int n = *num;
     register long l = length;
     DES_cblock d;
     register char *dp;
diff --git a/crypto/des/ofb64enc.c b/crypto/des/ofb64enc.c
index 1426407423..df4e2077e9 100644
--- a/crypto/des/ofb64enc.c
+++ b/crypto/des/ofb64enc.c
@@ -25,7 +25,7 @@ void DES_ofb64_encrypt(register const unsigned char *in,
     DES_key_schedule *schedule, DES_cblock *ivec, int *num)
 {
     register DES_LONG v0, v1, t;
-    register int n = *num & 0x07;
+    register int n = *num;
     register long l = length;
     DES_cblock d;
     register unsigned char *dp;
diff --git a/crypto/des/spr.h b/crypto/des/spr.h
index fe3e9d31e3..955fbc2989 100644
--- a/crypto/des/spr.h
+++ b/crypto/des/spr.h
@@ -7,11 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_DES_SPR_H)
-#define OSSL_LIBCRYPTO_DES_SPR_H
-
-#include 
-
 const DES_LONG DES_SPtrans[8][64] = {
     {
         /* nibble 0 */
@@ -550,5 +545,3 @@ const DES_LONG DES_SPtrans[8][64] = {
         0x00820080L,
     }
 };
-
-#endif /* !defined(OSSL_LIBCRYPTO_DES_SPR_H) */
diff --git a/crypto/dh/build.info b/crypto/dh/build.info
index 52f4de5fe7..b413567271 100644
--- a/crypto/dh/build.info
+++ b/crypto/dh/build.info
@@ -5,7 +5,7 @@ $COMMON=dh_lib.c dh_key.c dh_group_params.c dh_check.c dh_backend.c dh_gen.c \
 
 SOURCE[../../libcrypto]=$COMMON\
         dh_asn1.c dh_err.c \
-        dh_ameth.c dh_prn.c dh_rfc5114.c dh_meth.c
+        dh_ameth.c dh_pmeth.c dh_prn.c dh_rfc5114.c dh_meth.c
 IF[{- !$disabled{'deprecated-0.9.8'} -}]
   SOURCE[../../libcrypto]=dh_depr.c
 ENDIF
diff --git a/crypto/dh/dh_asn1.c b/crypto/dh/dh_asn1.c
index 29d987d3c2..6112d513a5 100644
--- a/crypto/dh/dh_asn1.c
+++ b/crypto/dh/dh_asn1.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -21,8 +21,6 @@
 #include 
 #include "crypto/dh.h"
 
-#include 
-
 /* Override the default free and new methods */
 static int dh_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it,
     void *exarg)
@@ -78,7 +76,7 @@ ASN1_SEQUENCE(DHvparams) = {
     ASN1_SIMPLE(int_dhvparams, counter, BIGNUM)
 } static_ASN1_SEQUENCE_END_name(int_dhvparams, DHvparams)
 
-ASN1_SEQUENCE(DHxparams)
+    ASN1_SEQUENCE(DHxparams)
     = {
           ASN1_SIMPLE(int_dhx942_dh, p, BIGNUM),
           ASN1_SIMPLE(int_dhx942_dh, g, BIGNUM),
@@ -87,7 +85,8 @@ ASN1_SEQUENCE(DHxparams)
           ASN1_OPT(int_dhx942_dh, vparams, DHvparams),
       } static_ASN1_SEQUENCE_END_name(int_dhx942_dh, DHxparams)
 
-int_dhx942_dh *d2i_int_dhx(int_dhx942_dh **a, const unsigned char **pp, long length);
+          int_dhx942_dh
+    * d2i_int_dhx(int_dhx942_dh * *a, const unsigned char **pp, long length);
 int i2d_int_dhx(const int_dhx942_dh *a, unsigned char **pp);
 
 IMPLEMENT_ASN1_ENCODE_FUNCTIONS_fname(int_dhx942_dh, DHxparams, int_dhx)
diff --git a/crypto/dh/dh_backend.c b/crypto/dh/dh_backend.c
index bb3824a4a0..4a3e2b2e42 100644
--- a/crypto/dh/dh_backend.c
+++ b/crypto/dh/dh_backend.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2020-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -22,12 +22,10 @@
 #include "crypto/dh.h"
 #include "dh_local.h"
 
-#include 
-
 /*
  * The intention with the "backend" source file is to offer backend functions
- * for legacy backends (EVP_PKEY_ASN1_METHOD) and provider implementations
- * alike.
+ * for legacy backends (EVP_PKEY_ASN1_METHOD and EVP_PKEY_METHOD) and provider
+ * implementations alike.
  */
 
 static int dh_ffc_params_fromdata(DH *dh, const OSSL_PARAM params[])
@@ -235,7 +233,7 @@ DH *ossl_dh_key_from_pkcs8(const PKCS8_PRIV_KEY_INFO *p8inf,
     goto done;
 
 decerr:
-    ERR_raise(ERR_LIB_DH, DH_R_DECODE_ERROR);
+    ERR_raise(ERR_LIB_DH, EVP_R_DECODE_ERROR);
 dherr:
     DH_free(dh);
     dh = NULL;
diff --git a/crypto/dh/dh_check.c b/crypto/dh/dh_check.c
index 96256f9283..3002609b68 100644
--- a/crypto/dh/dh_check.c
+++ b/crypto/dh/dh_check.c
@@ -74,14 +74,6 @@ int DH_check_params(const DH *dh, int *ret)
     BN_CTX *ctx = NULL;
 
     *ret = 0;
-    /*
-     * A DH with no modulus or generator cannot be checked.  Report
-     * the failure via |*ret| rather than dereferencing NULL below.
-     */
-    if (dh->params.p == NULL || dh->params.g == NULL) {
-        *ret = DH_NOT_SUITABLE_GENERATOR | DH_CHECK_P_NOT_PRIME;
-        return 1;
-    }
     ctx = BN_CTX_new_ex(dh->libctx);
     if (ctx == NULL)
         goto err;
@@ -158,11 +150,6 @@ int DH_check(const DH *dh, int *ret)
     int nid = DH_get_nid((DH *)dh);
 
     *ret = 0;
-    /* A DH with no modulus or generator cannot be checked. */
-    if (dh->params.p == NULL || dh->params.g == NULL) {
-        *ret = DH_NOT_SUITABLE_GENERATOR | DH_CHECK_P_NOT_PRIME;
-        return 1;
-    }
     if (nid != NID_undef)
         return 1;
 
@@ -263,15 +250,6 @@ int DH_check_pub_key_ex(const DH *dh, const BIGNUM *pub_key)
  */
 int DH_check_pub_key(const DH *dh, const BIGNUM *pub_key, int *ret)
 {
-    *ret = 0;
-    /*
-     * Without a modulus we cannot check anything; signal failure via
-     * |*ret| rather than crashing in BN_num_bits below.
-     */
-    if (dh->params.p == NULL) {
-        *ret = DH_CHECK_PUBKEY_INVALID;
-        return 1;
-    }
     /* Don't do any checks at all with an excessively large modulus */
     if (BN_num_bits(dh->params.p) > OPENSSL_DH_CHECK_MAX_MODULUS_BITS) {
         ERR_raise(ERR_LIB_DH, DH_R_MODULUS_TOO_LARGE);
diff --git a/crypto/dh/dh_lib.c b/crypto/dh/dh_lib.c
index 1934c71080..f959c0dd88 100644
--- a/crypto/dh/dh_lib.c
+++ b/crypto/dh/dh_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -142,7 +142,7 @@ int DH_up_ref(DH *r)
 {
     int i;
 
-    if (!CRYPTO_UP_REF(&r->references, &i))
+    if (CRYPTO_UP_REF(&r->references, &i) <= 0)
         return 0;
 
     REF_PRINT_COUNT("DH", i, r);
@@ -150,11 +150,6 @@ int DH_up_ref(DH *r)
     return ((i > 1) ? 1 : 0);
 }
 
-OSSL_LIB_CTX *ossl_dh_get0_libctx(const DH *dh)
-{
-    return dh->libctx;
-}
-
 void ossl_dh_set0_libctx(DH *d, OSSL_LIB_CTX *libctx)
 {
     d->libctx = libctx;
diff --git a/crypto/dh/dh_local.h b/crypto/dh/dh_local.h
index ea6c378a9d..177f055a67 100644
--- a/crypto/dh/dh_local.h
+++ b/crypto/dh/dh_local.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_DH_DH_LOCAL_H)
-#define OSSL_LIBCRYPTO_DH_DH_LOCAL_H
-
 #include 
 #include "internal/refcount.h"
 #include "internal/ffc.h"
@@ -60,5 +57,3 @@ struct dh_method {
     int (*generate_params)(DH *dh, int prime_len, int generator,
         BN_GENCB *cb);
 };
-
-#endif /* !defined(OSSL_LIBCRYPTO_DH_DH_LOCAL_H) */
diff --git a/crypto/dh/dh_pmeth.c b/crypto/dh/dh_pmeth.c
new file mode 100644
index 0000000000..673426b7f3
--- /dev/null
+++ b/crypto/dh/dh_pmeth.c
@@ -0,0 +1,535 @@
+/*
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+/*
+ * DH & DSA low level APIs are deprecated for public use, but still ok for
+ * internal use.
+ */
+#include "internal/deprecated.h"
+
+#include 
+#include "internal/cryptlib.h"
+#include 
+#include 
+#include 
+#include "dh_local.h"
+#include 
+#include 
+#include 
+#include "crypto/evp.h"
+
+/* DH pkey context structure */
+
+typedef struct {
+    /* Parameter gen parameters */
+    int prime_len;
+    int generator;
+    int paramgen_type;
+    int subprime_len;
+    int pad;
+    /* message digest used for parameter generation */
+    const EVP_MD *md;
+    int param_nid;
+    /* Keygen callback info */
+    int gentmp[2];
+    /* KDF (if any) to use for DH */
+    char kdf_type;
+    /* OID to use for KDF */
+    ASN1_OBJECT *kdf_oid;
+    /* Message digest to use for key derivation */
+    const EVP_MD *kdf_md;
+    /* User key material */
+    unsigned char *kdf_ukm;
+    size_t kdf_ukmlen;
+    /* KDF output length */
+    size_t kdf_outlen;
+} DH_PKEY_CTX;
+
+static int pkey_dh_init(EVP_PKEY_CTX *ctx)
+{
+    DH_PKEY_CTX *dctx;
+
+    if ((dctx = OPENSSL_zalloc(sizeof(*dctx))) == NULL)
+        return 0;
+    dctx->prime_len = 2048;
+    dctx->subprime_len = -1;
+    dctx->generator = 2;
+    dctx->kdf_type = EVP_PKEY_DH_KDF_NONE;
+
+    ctx->data = dctx;
+    ctx->keygen_info = dctx->gentmp;
+    ctx->keygen_info_count = 2;
+
+    return 1;
+}
+
+static void pkey_dh_cleanup(EVP_PKEY_CTX *ctx)
+{
+    DH_PKEY_CTX *dctx = ctx->data;
+
+    if (dctx != NULL) {
+        OPENSSL_free(dctx->kdf_ukm);
+        ASN1_OBJECT_free(dctx->kdf_oid);
+        OPENSSL_free(dctx);
+    }
+}
+
+static int pkey_dh_copy(EVP_PKEY_CTX *dst, const EVP_PKEY_CTX *src)
+{
+    DH_PKEY_CTX *dctx, *sctx;
+
+    if (!pkey_dh_init(dst))
+        return 0;
+    sctx = src->data;
+    dctx = dst->data;
+    dctx->prime_len = sctx->prime_len;
+    dctx->subprime_len = sctx->subprime_len;
+    dctx->generator = sctx->generator;
+    dctx->paramgen_type = sctx->paramgen_type;
+    dctx->pad = sctx->pad;
+    dctx->md = sctx->md;
+    dctx->param_nid = sctx->param_nid;
+
+    dctx->kdf_type = sctx->kdf_type;
+    dctx->kdf_oid = OBJ_dup(sctx->kdf_oid);
+    if (dctx->kdf_oid == NULL)
+        return 0;
+    dctx->kdf_md = sctx->kdf_md;
+    if (sctx->kdf_ukm != NULL) {
+        dctx->kdf_ukm = OPENSSL_memdup(sctx->kdf_ukm, sctx->kdf_ukmlen);
+        if (dctx->kdf_ukm == NULL)
+            return 0;
+        dctx->kdf_ukmlen = sctx->kdf_ukmlen;
+    }
+    dctx->kdf_outlen = sctx->kdf_outlen;
+    return 1;
+}
+
+static int pkey_dh_ctrl(EVP_PKEY_CTX *ctx, int type, int p1, void *p2)
+{
+    DH_PKEY_CTX *dctx = ctx->data;
+    switch (type) {
+    case EVP_PKEY_CTRL_DH_PARAMGEN_PRIME_LEN:
+        if (p1 < 256)
+            return -2;
+        dctx->prime_len = p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_DH_PARAMGEN_SUBPRIME_LEN:
+        if (dctx->paramgen_type == DH_PARAMGEN_TYPE_GENERATOR)
+            return -2;
+        dctx->subprime_len = p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_DH_PAD:
+        dctx->pad = p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_DH_PARAMGEN_GENERATOR:
+        if (dctx->paramgen_type != DH_PARAMGEN_TYPE_GENERATOR)
+            return -2;
+        dctx->generator = p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_DH_PARAMGEN_TYPE:
+#ifdef OPENSSL_NO_DSA
+        if (p1 != DH_PARAMGEN_TYPE_GENERATOR)
+            return -2;
+#else
+        if (p1 < 0 || p1 > 2)
+            return -2;
+#endif
+        dctx->paramgen_type = p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_DH_RFC5114:
+        if (p1 < 1 || p1 > 3 || dctx->param_nid != NID_undef)
+            return -2;
+        dctx->param_nid = p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_DH_NID:
+        if (p1 <= 0 || dctx->param_nid != NID_undef)
+            return -2;
+        dctx->param_nid = p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_PEER_KEY:
+        /* Default behaviour is OK */
+        return 1;
+
+    case EVP_PKEY_CTRL_DH_KDF_TYPE:
+        if (p1 == -2)
+            return dctx->kdf_type;
+        if (p1 != EVP_PKEY_DH_KDF_NONE && p1 != EVP_PKEY_DH_KDF_X9_42)
+            return -2;
+        dctx->kdf_type = p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_DH_KDF_MD:
+        dctx->kdf_md = p2;
+        return 1;
+
+    case EVP_PKEY_CTRL_GET_DH_KDF_MD:
+        *(const EVP_MD **)p2 = dctx->kdf_md;
+        return 1;
+
+    case EVP_PKEY_CTRL_DH_KDF_OUTLEN:
+        if (p1 <= 0)
+            return -2;
+        dctx->kdf_outlen = (size_t)p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_GET_DH_KDF_OUTLEN:
+        *(int *)p2 = (int)dctx->kdf_outlen;
+        return 1;
+
+    case EVP_PKEY_CTRL_DH_KDF_UKM:
+        OPENSSL_free(dctx->kdf_ukm);
+        dctx->kdf_ukm = p2;
+        if (p2)
+            dctx->kdf_ukmlen = p1;
+        else
+            dctx->kdf_ukmlen = 0;
+        return 1;
+
+    case EVP_PKEY_CTRL_GET_DH_KDF_UKM:
+        *(unsigned char **)p2 = dctx->kdf_ukm;
+        return (int)dctx->kdf_ukmlen;
+
+    case EVP_PKEY_CTRL_DH_KDF_OID:
+        ASN1_OBJECT_free(dctx->kdf_oid);
+        dctx->kdf_oid = p2;
+        return 1;
+
+    case EVP_PKEY_CTRL_GET_DH_KDF_OID:
+        *(ASN1_OBJECT **)p2 = dctx->kdf_oid;
+        return 1;
+
+    default:
+        return -2;
+    }
+}
+
+static int pkey_dh_ctrl_str(EVP_PKEY_CTX *ctx,
+    const char *type, const char *value)
+{
+    if (strcmp(type, "dh_paramgen_prime_len") == 0) {
+        int len;
+        len = atoi(value);
+        return EVP_PKEY_CTX_set_dh_paramgen_prime_len(ctx, len);
+    }
+    if (strcmp(type, "dh_rfc5114") == 0) {
+        DH_PKEY_CTX *dctx = ctx->data;
+        int id;
+
+        id = atoi(value);
+        if (id < 0 || id > 3)
+            return -2;
+        dctx->param_nid = id;
+        return 1;
+    }
+    if (strcmp(type, "dh_param") == 0) {
+        DH_PKEY_CTX *dctx = ctx->data;
+        int nid = OBJ_sn2nid(value);
+
+        if (nid == NID_undef) {
+            ERR_raise(ERR_LIB_DH, DH_R_INVALID_PARAMETER_NAME);
+            return -2;
+        }
+        dctx->param_nid = nid;
+        return 1;
+    }
+    if (strcmp(type, "dh_paramgen_generator") == 0) {
+        int len;
+        len = atoi(value);
+        return EVP_PKEY_CTX_set_dh_paramgen_generator(ctx, len);
+    }
+    if (strcmp(type, "dh_paramgen_subprime_len") == 0) {
+        int len;
+        len = atoi(value);
+        return EVP_PKEY_CTX_set_dh_paramgen_subprime_len(ctx, len);
+    }
+    if (strcmp(type, "dh_paramgen_type") == 0) {
+        int typ;
+        typ = atoi(value);
+        return EVP_PKEY_CTX_set_dh_paramgen_type(ctx, typ);
+    }
+    if (strcmp(type, "dh_pad") == 0) {
+        int pad;
+        pad = atoi(value);
+        return EVP_PKEY_CTX_set_dh_pad(ctx, pad);
+    }
+    return -2;
+}
+
+static DH *ffc_params_generate(OSSL_LIB_CTX *libctx, DH_PKEY_CTX *dctx,
+    BN_GENCB *pcb)
+{
+    DH *ret;
+    int rv = 0;
+    int res;
+    int prime_len = dctx->prime_len;
+    int subprime_len = dctx->subprime_len;
+
+    if (dctx->paramgen_type > DH_PARAMGEN_TYPE_FIPS_186_4)
+        return NULL;
+    ret = DH_new();
+    if (ret == NULL)
+        return NULL;
+
+    if (subprime_len == -1) {
+        if (prime_len >= 2048)
+            subprime_len = 256;
+        else
+            subprime_len = 160;
+    }
+
+    if (dctx->md != NULL)
+        ossl_ffc_set_digest(&ret->params, EVP_MD_get0_name(dctx->md), NULL);
+
+#ifndef FIPS_MODULE
+    if (dctx->paramgen_type == DH_PARAMGEN_TYPE_FIPS_186_2)
+        rv = ossl_ffc_params_FIPS186_2_generate(libctx, &ret->params,
+            FFC_PARAM_TYPE_DH,
+            prime_len, subprime_len, &res,
+            pcb);
+    else
+#endif
+        /* For FIPS we always use the DH_PARAMGEN_TYPE_FIPS_186_4 generator */
+        if (dctx->paramgen_type >= DH_PARAMGEN_TYPE_FIPS_186_2)
+            rv = ossl_ffc_params_FIPS186_4_generate(libctx, &ret->params,
+                FFC_PARAM_TYPE_DH,
+                prime_len, subprime_len, &res,
+                pcb);
+    if (rv <= 0) {
+        DH_free(ret);
+        return NULL;
+    }
+    return ret;
+}
+
+static int pkey_dh_paramgen(EVP_PKEY_CTX *ctx,
+    EVP_PKEY *pkey)
+{
+    DH *dh = NULL;
+    DH_PKEY_CTX *dctx = ctx->data;
+    BN_GENCB *pcb = NULL;
+    int ret;
+
+    /*
+     * Look for a safe prime group for key establishment. Which uses
+     * either RFC_3526 (modp_XXXX) or RFC_7919 (ffdheXXXX).
+     * RFC_5114 is also handled here for param_nid = (1..3)
+     */
+    if (dctx->param_nid != NID_undef) {
+        int type = dctx->param_nid <= 3 ? EVP_PKEY_DHX : EVP_PKEY_DH;
+
+        if ((dh = DH_new_by_nid(dctx->param_nid)) == NULL)
+            return 0;
+        EVP_PKEY_assign(pkey, type, dh);
+        return 1;
+    }
+
+    if (ctx->pkey_gencb != NULL) {
+        pcb = BN_GENCB_new();
+        if (pcb == NULL)
+            return 0;
+        evp_pkey_set_cb_translate(pcb, ctx);
+    }
+#ifdef FIPS_MODULE
+    dctx->paramgen_type = DH_PARAMGEN_TYPE_FIPS_186_4;
+#endif /* FIPS_MODULE */
+    if (dctx->paramgen_type >= DH_PARAMGEN_TYPE_FIPS_186_2) {
+        dh = ffc_params_generate(NULL, dctx, pcb);
+        BN_GENCB_free(pcb);
+        if (dh == NULL)
+            return 0;
+        EVP_PKEY_assign(pkey, EVP_PKEY_DHX, dh);
+        return 1;
+    }
+    dh = DH_new();
+    if (dh == NULL) {
+        BN_GENCB_free(pcb);
+        return 0;
+    }
+    ret = DH_generate_parameters_ex(dh,
+        dctx->prime_len, dctx->generator, pcb);
+    BN_GENCB_free(pcb);
+    if (ret)
+        EVP_PKEY_assign_DH(pkey, dh);
+    else
+        DH_free(dh);
+    return ret;
+}
+
+static int pkey_dh_keygen(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
+{
+    DH_PKEY_CTX *dctx = ctx->data;
+    DH *dh = NULL;
+
+    if (ctx->pkey == NULL && dctx->param_nid == NID_undef) {
+        ERR_raise(ERR_LIB_DH, DH_R_NO_PARAMETERS_SET);
+        return 0;
+    }
+    if (dctx->param_nid != NID_undef)
+        dh = DH_new_by_nid(dctx->param_nid);
+    else
+        dh = DH_new();
+    if (dh == NULL)
+        return 0;
+    EVP_PKEY_assign(pkey, ctx->pmeth->pkey_id, dh);
+    /* Note: if error return, pkey is freed by parent routine */
+    if (ctx->pkey != NULL && !EVP_PKEY_copy_parameters(pkey, ctx->pkey))
+        return 0;
+    return DH_generate_key((DH *)EVP_PKEY_get0_DH(pkey));
+}
+
+static int pkey_dh_derive(EVP_PKEY_CTX *ctx, unsigned char *key,
+    size_t *keylen)
+{
+    int ret;
+    DH *dh;
+    const DH *dhpub;
+    DH_PKEY_CTX *dctx = ctx->data;
+    BIGNUM *dhpubbn;
+
+    if (ctx->pkey == NULL || ctx->peerkey == NULL) {
+        ERR_raise(ERR_LIB_DH, DH_R_KEYS_NOT_SET);
+        return 0;
+    }
+    dh = (DH *)EVP_PKEY_get0_DH(ctx->pkey);
+    dhpub = EVP_PKEY_get0_DH(ctx->peerkey);
+    if (dhpub == NULL || dh == NULL) {
+        ERR_raise(ERR_LIB_DH, DH_R_KEYS_NOT_SET);
+        return 0;
+    }
+    dhpubbn = dhpub->pub_key;
+    if (dctx->kdf_type == EVP_PKEY_DH_KDF_NONE) {
+        if (key == NULL) {
+            *keylen = DH_size(dh);
+            return 1;
+        }
+        if (dctx->pad)
+            ret = DH_compute_key_padded(key, dhpubbn, dh);
+        else
+            ret = DH_compute_key(key, dhpubbn, dh);
+        if (ret <= 0)
+            return ret;
+        *keylen = ret;
+        return 1;
+    } else if (dctx->kdf_type == EVP_PKEY_DH_KDF_X9_42) {
+
+        unsigned char *Z = NULL;
+        int Zlen = 0;
+
+        if (!dctx->kdf_outlen || !dctx->kdf_oid)
+            return 0;
+        if (key == NULL) {
+            *keylen = dctx->kdf_outlen;
+            return 1;
+        }
+        if (*keylen != dctx->kdf_outlen)
+            return 0;
+        ret = 0;
+        if ((Zlen = DH_size(dh)) <= 0)
+            return 0;
+        if ((Z = OPENSSL_malloc(Zlen)) == NULL)
+            return 0;
+        if (DH_compute_key_padded(Z, dhpubbn, dh) <= 0)
+            goto err;
+        if (!DH_KDF_X9_42(key, *keylen, Z, Zlen, dctx->kdf_oid,
+                dctx->kdf_ukm, dctx->kdf_ukmlen, dctx->kdf_md))
+            goto err;
+        *keylen = dctx->kdf_outlen;
+        ret = 1;
+    err:
+        OPENSSL_clear_free(Z, Zlen);
+        return ret;
+    }
+    return 0;
+}
+
+static const EVP_PKEY_METHOD dh_pkey_meth = {
+    EVP_PKEY_DH,
+    0,
+    pkey_dh_init,
+    pkey_dh_copy,
+    pkey_dh_cleanup,
+
+    0,
+    pkey_dh_paramgen,
+
+    0,
+    pkey_dh_keygen,
+
+    0,
+    0,
+
+    0,
+    0,
+
+    0, 0,
+
+    0, 0, 0, 0,
+
+    0, 0,
+
+    0, 0,
+
+    0,
+    pkey_dh_derive,
+
+    pkey_dh_ctrl,
+    pkey_dh_ctrl_str
+};
+
+const EVP_PKEY_METHOD *ossl_dh_pkey_method(void)
+{
+    return &dh_pkey_meth;
+}
+
+static const EVP_PKEY_METHOD dhx_pkey_meth = {
+    EVP_PKEY_DHX,
+    0,
+    pkey_dh_init,
+    pkey_dh_copy,
+    pkey_dh_cleanup,
+
+    0,
+    pkey_dh_paramgen,
+
+    0,
+    pkey_dh_keygen,
+
+    0,
+    0,
+
+    0,
+    0,
+
+    0, 0,
+
+    0, 0, 0, 0,
+
+    0, 0,
+
+    0, 0,
+
+    0,
+    pkey_dh_derive,
+
+    pkey_dh_ctrl,
+    pkey_dh_ctrl_str
+};
+
+const EVP_PKEY_METHOD *ossl_dhx_pkey_method(void)
+{
+    return &dhx_pkey_meth;
+}
diff --git a/crypto/dh/dh_rfc5114.c b/crypto/dh/dh_rfc5114.c
index 7f88d569e0..366776ce4e 100644
--- a/crypto/dh/dh_rfc5114.c
+++ b/crypto/dh/dh_rfc5114.c
@@ -43,5 +43,5 @@
     }
 
 make_dh(1024_160)
-make_dh(2048_224)
-make_dh(2048_256)
+    make_dh(2048_224)
+        make_dh(2048_256)
diff --git a/crypto/dllmain.c b/crypto/dllmain.c
index 0ca19e63ec..78eee3f4c7 100644
--- a/crypto/dllmain.c
+++ b/crypto/dllmain.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -30,19 +30,13 @@ BOOL WINAPI DllMain(HINSTANCE hinstDLL, DWORD fdwReason, LPVOID lpvReserved)
 {
     switch (fdwReason) {
     case DLL_PROCESS_ATTACH:
-        OPENSSL_cpuid_setup();
         break;
     case DLL_THREAD_ATTACH:
         break;
     case DLL_THREAD_DETACH:
-#ifndef __CYGWIN__
         OPENSSL_thread_stop();
-#endif
         break;
     case DLL_PROCESS_DETACH:
-#if defined(OSSL_DLLMAIN_DESTRUCTOR)
-        ossl_cleanup_destructor();
-#endif /* defined(OSSL_DLLMAIN_DESTRUCTOR) */
         break;
     }
     return TRUE;
diff --git a/crypto/dsa/build.info b/crypto/dsa/build.info
index f38ad8d567..9a7d275c35 100644
--- a/crypto/dsa/build.info
+++ b/crypto/dsa/build.info
@@ -4,7 +4,7 @@ $COMMON=dsa_sign.c dsa_vrf.c dsa_lib.c dsa_ossl.c dsa_check.c \
         dsa_key.c dsa_backend.c dsa_gen.c
 
 SOURCE[../../libcrypto]=$COMMON\
-        dsa_asn1.c dsa_err.c dsa_ameth.c dsa_prn.c \
+        dsa_asn1.c dsa_err.c dsa_ameth.c dsa_pmeth.c dsa_prn.c \
         dsa_meth.c
 IF[{- !$disabled{'deprecated-0.9.8'} -}]
   SOURCE[../../libcrypto]=dsa_depr.c
diff --git a/crypto/dsa/dsa_asn1.c b/crypto/dsa/dsa_asn1.c
index 4cf5d66a63..3366610a9f 100644
--- a/crypto/dsa/dsa_asn1.c
+++ b/crypto/dsa/dsa_asn1.c
@@ -47,7 +47,7 @@ ASN1_SEQUENCE_cb(DSAPrivateKey, dsa_cb) = {
     ASN1_SIMPLE(DSA, priv_key, CBIGNUM)
 } static_ASN1_SEQUENCE_END_cb(DSA, DSAPrivateKey)
 
-IMPLEMENT_ASN1_ENCODE_FUNCTIONS_fname(DSA, DSAPrivateKey, DSAPrivateKey)
+    IMPLEMENT_ASN1_ENCODE_FUNCTIONS_fname(DSA, DSAPrivateKey, DSAPrivateKey)
 
 ASN1_SEQUENCE_cb(DSAparams, dsa_cb) = {
     ASN1_SIMPLE(DSA, params.p, BIGNUM),
@@ -55,7 +55,7 @@ ASN1_SEQUENCE_cb(DSAparams, dsa_cb) = {
     ASN1_SIMPLE(DSA, params.g, BIGNUM),
 } static_ASN1_SEQUENCE_END_cb(DSA, DSAparams)
 
-IMPLEMENT_ASN1_ENCODE_FUNCTIONS_fname(DSA, DSAparams, DSAparams)
+    IMPLEMENT_ASN1_ENCODE_FUNCTIONS_fname(DSA, DSAparams, DSAparams)
 
 ASN1_SEQUENCE_cb(DSAPublicKey, dsa_cb) = {
     ASN1_SIMPLE(DSA, pub_key, BIGNUM),
@@ -64,7 +64,7 @@ ASN1_SEQUENCE_cb(DSAPublicKey, dsa_cb) = {
     ASN1_SIMPLE(DSA, params.g, BIGNUM)
 } static_ASN1_SEQUENCE_END_cb(DSA, DSAPublicKey)
 
-IMPLEMENT_ASN1_ENCODE_FUNCTIONS_fname(DSA, DSAPublicKey, DSAPublicKey)
+    IMPLEMENT_ASN1_ENCODE_FUNCTIONS_fname(DSA, DSAPublicKey, DSAPublicKey)
 
 DSA *DSAparams_dup(const DSA *dsa)
 {
diff --git a/crypto/dsa/dsa_backend.c b/crypto/dsa/dsa_backend.c
index cab9b71301..e4c1c7bb01 100644
--- a/crypto/dsa/dsa_backend.c
+++ b/crypto/dsa/dsa_backend.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2020-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -21,12 +21,10 @@
 #include "crypto/dsa.h"
 #include "dsa_local.h"
 
-#include 
-
 /*
- * The intention with the "backend" source file is to offer backend functions
- * for legacy backends (EVP_PKEY_ASN1_METHOD) and provider implementations
- * alike.
+ * The intention with the "backend" source file is to offer backend support
+ * for legacy backends (EVP_PKEY_ASN1_METHOD and EVP_PKEY_METHOD) and provider
+ * implementations alike.
  */
 
 int ossl_dsa_key_fromdata(DSA *dsa, const OSSL_PARAM params[],
diff --git a/crypto/dsa/dsa_key.c b/crypto/dsa/dsa_key.c
index a07f866a21..aa69c3eea8 100644
--- a/crypto/dsa/dsa_key.c
+++ b/crypto/dsa/dsa_key.c
@@ -198,6 +198,7 @@ static int dsa_keygen(DSA *dsa)
         ok = dsa_keygen_pairwise_test(dsa, cb, cbarg)
             && dsa_keygen_knownanswer_test(dsa, ctx, cb, cbarg);
         if (!ok) {
+            ossl_set_error_state(OSSL_SELF_TEST_TYPE_PCT);
             BN_free(dsa->pub_key);
             BN_clear_free(dsa->priv_key);
             dsa->pub_key = NULL;
diff --git a/crypto/dsa/dsa_lib.c b/crypto/dsa/dsa_lib.c
index 5936b84098..01d5d8e3c1 100644
--- a/crypto/dsa/dsa_lib.c
+++ b/crypto/dsa/dsa_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -215,7 +215,7 @@ int DSA_up_ref(DSA *r)
 {
     int i;
 
-    if (!CRYPTO_UP_REF(&r->references, &i))
+    if (CRYPTO_UP_REF(&r->references, &i) <= 0)
         return 0;
 
     REF_PRINT_COUNT("DSA", i, r);
@@ -223,11 +223,6 @@ int DSA_up_ref(DSA *r)
     return ((i > 1) ? 1 : 0);
 }
 
-OSSL_LIB_CTX *ossl_dsa_get0_libctx(const DSA *d)
-{
-    return d->libctx;
-}
-
 void ossl_dsa_set0_libctx(DSA *d, OSSL_LIB_CTX *libctx)
 {
     d->libctx = libctx;
diff --git a/crypto/dsa/dsa_local.h b/crypto/dsa/dsa_local.h
index 566bcb0def..a744463c87 100644
--- a/crypto/dsa/dsa_local.h
+++ b/crypto/dsa/dsa_local.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_DSA_DSA_LOCAL_H)
-#define OSSL_LIBCRYPTO_DSA_DSA_LOCAL_H
-
 #include 
 #include "internal/refcount.h"
 #include "internal/ffc.h"
@@ -73,5 +70,3 @@ struct dsa_method {
 DSA_SIG *ossl_dsa_do_sign_int(const unsigned char *dgst, int dlen, DSA *dsa,
     unsigned int nonce_type, const char *digestname,
     OSSL_LIB_CTX *libctx, const char *propq);
-
-#endif /* !defined(OSSL_LIBCRYPTO_DSA_DSA_LOCAL_H) */
diff --git a/crypto/dsa/dsa_pmeth.c b/crypto/dsa/dsa_pmeth.c
new file mode 100644
index 0000000000..5f92f71a75
--- /dev/null
+++ b/crypto/dsa/dsa_pmeth.c
@@ -0,0 +1,294 @@
+/*
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+/*
+ * DSA low level APIs are deprecated for public use, but still ok for
+ * internal use.
+ */
+#include "internal/deprecated.h"
+
+#include 
+#include "internal/cryptlib.h"
+#include 
+#include 
+#include 
+#include 
+#include "crypto/evp.h"
+#include "dsa_local.h"
+
+/* DSA pkey context structure */
+
+typedef struct {
+    /* Parameter gen parameters */
+    int nbits; /* size of p in bits (default: 2048) */
+    int qbits; /* size of q in bits (default: 224) */
+    const EVP_MD *pmd; /* MD for parameter generation */
+    /* Keygen callback info */
+    int gentmp[2];
+    /* message digest */
+    const EVP_MD *md; /* MD for the signature */
+} DSA_PKEY_CTX;
+
+static int pkey_dsa_init(EVP_PKEY_CTX *ctx)
+{
+    DSA_PKEY_CTX *dctx = OPENSSL_malloc(sizeof(*dctx));
+
+    if (dctx == NULL)
+        return 0;
+    dctx->nbits = 2048;
+    dctx->qbits = 224;
+    dctx->pmd = NULL;
+    dctx->md = NULL;
+
+    ctx->data = dctx;
+    ctx->keygen_info = dctx->gentmp;
+    ctx->keygen_info_count = 2;
+
+    return 1;
+}
+
+static int pkey_dsa_copy(EVP_PKEY_CTX *dst, const EVP_PKEY_CTX *src)
+{
+    DSA_PKEY_CTX *dctx, *sctx;
+
+    if (!pkey_dsa_init(dst))
+        return 0;
+    sctx = src->data;
+    dctx = dst->data;
+    dctx->nbits = sctx->nbits;
+    dctx->qbits = sctx->qbits;
+    dctx->pmd = sctx->pmd;
+    dctx->md = sctx->md;
+    return 1;
+}
+
+static void pkey_dsa_cleanup(EVP_PKEY_CTX *ctx)
+{
+    DSA_PKEY_CTX *dctx = ctx->data;
+    OPENSSL_free(dctx);
+}
+
+static int pkey_dsa_sign(EVP_PKEY_CTX *ctx, unsigned char *sig,
+    size_t *siglen, const unsigned char *tbs,
+    size_t tbslen)
+{
+    int ret, md_size;
+    unsigned int sltmp;
+    DSA_PKEY_CTX *dctx = ctx->data;
+    /*
+     * Discard const. Its marked as const because this may be a cached copy of
+     * the "real" key. These calls don't make any modifications that need to
+     * be reflected back in the "original" key.
+     */
+    DSA *dsa = (DSA *)EVP_PKEY_get0_DSA(ctx->pkey);
+
+    if (dctx->md != NULL) {
+        md_size = EVP_MD_get_size(dctx->md);
+        if (md_size <= 0)
+            return 0;
+        if (tbslen != (size_t)md_size)
+            return 0;
+    }
+
+    ret = DSA_sign(0, tbs, (int)tbslen, sig, &sltmp, dsa);
+
+    if (ret <= 0)
+        return ret;
+    *siglen = sltmp;
+    return 1;
+}
+
+static int pkey_dsa_verify(EVP_PKEY_CTX *ctx,
+    const unsigned char *sig, size_t siglen,
+    const unsigned char *tbs, size_t tbslen)
+{
+    int ret, md_size;
+    DSA_PKEY_CTX *dctx = ctx->data;
+    /*
+     * Discard const. Its marked as const because this may be a cached copy of
+     * the "real" key. These calls don't make any modifications that need to
+     * be reflected back in the "original" key.
+     */
+    DSA *dsa = (DSA *)EVP_PKEY_get0_DSA(ctx->pkey);
+
+    if (dctx->md != NULL) {
+        md_size = EVP_MD_get_size(dctx->md);
+        if (md_size <= 0)
+            return 0;
+        if (tbslen != (size_t)md_size)
+            return 0;
+    }
+
+    ret = DSA_verify(0, tbs, (int)tbslen, sig, (int)siglen, dsa);
+
+    return ret;
+}
+
+static int pkey_dsa_ctrl(EVP_PKEY_CTX *ctx, int type, int p1, void *p2)
+{
+    DSA_PKEY_CTX *dctx = ctx->data;
+
+    switch (type) {
+    case EVP_PKEY_CTRL_DSA_PARAMGEN_BITS:
+        if (p1 < 256)
+            return -2;
+        dctx->nbits = p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_DSA_PARAMGEN_Q_BITS:
+        if (p1 != 160 && p1 != 224 && p1 && p1 != 256)
+            return -2;
+        dctx->qbits = p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_DSA_PARAMGEN_MD:
+        if (EVP_MD_get_type((const EVP_MD *)p2) != NID_sha1 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha224 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha256) {
+            ERR_raise(ERR_LIB_DSA, DSA_R_INVALID_DIGEST_TYPE);
+            return 0;
+        }
+        dctx->pmd = p2;
+        return 1;
+
+    case EVP_PKEY_CTRL_MD:
+        if (EVP_MD_get_type((const EVP_MD *)p2) != NID_sha1 && EVP_MD_get_type((const EVP_MD *)p2) != NID_dsa && EVP_MD_get_type((const EVP_MD *)p2) != NID_dsaWithSHA && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha224 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha256 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha384 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha512 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha3_224 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha3_256 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha3_384 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha3_512) {
+            ERR_raise(ERR_LIB_DSA, DSA_R_INVALID_DIGEST_TYPE);
+            return 0;
+        }
+        dctx->md = p2;
+        return 1;
+
+    case EVP_PKEY_CTRL_GET_MD:
+        *(const EVP_MD **)p2 = dctx->md;
+        return 1;
+
+    case EVP_PKEY_CTRL_DIGESTINIT:
+    case EVP_PKEY_CTRL_PKCS7_SIGN:
+    case EVP_PKEY_CTRL_CMS_SIGN:
+        return 1;
+
+    case EVP_PKEY_CTRL_PEER_KEY:
+        ERR_raise(ERR_LIB_DSA, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
+        return -2;
+    default:
+        return -2;
+    }
+}
+
+static int pkey_dsa_ctrl_str(EVP_PKEY_CTX *ctx,
+    const char *type, const char *value)
+{
+    if (strcmp(type, "dsa_paramgen_bits") == 0) {
+        int nbits;
+        nbits = atoi(value);
+        return EVP_PKEY_CTX_set_dsa_paramgen_bits(ctx, nbits);
+    }
+    if (strcmp(type, "dsa_paramgen_q_bits") == 0) {
+        int qbits = atoi(value);
+        return EVP_PKEY_CTX_set_dsa_paramgen_q_bits(ctx, qbits);
+    }
+    if (strcmp(type, "dsa_paramgen_md") == 0) {
+        const EVP_MD *md = EVP_get_digestbyname(value);
+
+        if (md == NULL) {
+            ERR_raise(ERR_LIB_DSA, DSA_R_INVALID_DIGEST_TYPE);
+            return 0;
+        }
+        return EVP_PKEY_CTX_set_dsa_paramgen_md(ctx, md);
+    }
+    return -2;
+}
+
+static int pkey_dsa_paramgen(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
+{
+    DSA *dsa = NULL;
+    DSA_PKEY_CTX *dctx = ctx->data;
+    BN_GENCB *pcb;
+    int ret, res;
+
+    if (ctx->pkey_gencb) {
+        pcb = BN_GENCB_new();
+        if (pcb == NULL)
+            return 0;
+        evp_pkey_set_cb_translate(pcb, ctx);
+    } else
+        pcb = NULL;
+    dsa = DSA_new();
+    if (dsa == NULL) {
+        BN_GENCB_free(pcb);
+        return 0;
+    }
+    if (dctx->md != NULL)
+        ossl_ffc_set_digest(&dsa->params, EVP_MD_get0_name(dctx->md), NULL);
+
+    ret = ossl_ffc_params_FIPS186_4_generate(NULL, &dsa->params,
+        FFC_PARAM_TYPE_DSA, dctx->nbits,
+        dctx->qbits, &res, pcb);
+    BN_GENCB_free(pcb);
+    if (ret > 0)
+        EVP_PKEY_assign_DSA(pkey, dsa);
+    else
+        DSA_free(dsa);
+    return ret;
+}
+
+static int pkey_dsa_keygen(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
+{
+    DSA *dsa = NULL;
+
+    if (ctx->pkey == NULL) {
+        ERR_raise(ERR_LIB_DSA, DSA_R_NO_PARAMETERS_SET);
+        return 0;
+    }
+    dsa = DSA_new();
+    if (dsa == NULL)
+        return 0;
+    EVP_PKEY_assign_DSA(pkey, dsa);
+    /* Note: if error return, pkey is freed by parent routine */
+    if (!EVP_PKEY_copy_parameters(pkey, ctx->pkey))
+        return 0;
+    return DSA_generate_key((DSA *)EVP_PKEY_get0_DSA(pkey));
+}
+
+static const EVP_PKEY_METHOD dsa_pkey_meth = {
+    EVP_PKEY_DSA,
+    EVP_PKEY_FLAG_AUTOARGLEN,
+    pkey_dsa_init,
+    pkey_dsa_copy,
+    pkey_dsa_cleanup,
+
+    0,
+    pkey_dsa_paramgen,
+
+    0,
+    pkey_dsa_keygen,
+
+    0,
+    pkey_dsa_sign,
+
+    0,
+    pkey_dsa_verify,
+
+    0, 0,
+
+    0, 0, 0, 0,
+
+    0, 0,
+
+    0, 0,
+
+    0, 0,
+
+    pkey_dsa_ctrl,
+    pkey_dsa_ctrl_str
+};
+
+const EVP_PKEY_METHOD *ossl_dsa_pkey_method(void)
+{
+    return &dsa_pkey_meth;
+}
diff --git a/crypto/dso/dso_lib.c b/crypto/dso/dso_lib.c
index 1366bea66d..6f51e4d35a 100644
--- a/crypto/dso/dso_lib.c
+++ b/crypto/dso/dso_lib.c
@@ -93,7 +93,7 @@ int DSO_up_ref(DSO *dso)
         return 0;
     }
 
-    if (!CRYPTO_UP_REF(&dso->references, &i))
+    if (CRYPTO_UP_REF(&dso->references, &i) <= 0)
         return 0;
 
     REF_PRINT_COUNT("DSO", i, dso);
diff --git a/crypto/dso/dso_local.h b/crypto/dso/dso_local.h
index 8318e3ab0c..f3ec802101 100644
--- a/crypto/dso/dso_local.h
+++ b/crypto/dso/dso_local.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_DSO_DSO_LOCAL_H)
-#define OSSL_LIBCRYPTO_DSO_DSO_LOCAL_H
-
 #include 
 #include "internal/cryptlib.h"
 #include "internal/dso.h"
@@ -107,5 +104,3 @@ struct dso_meth_st {
     /* Perform global symbol lookup, i.e. among *all* modules */
     void *(*globallookup)(const char *symname);
 };
-
-#endif /* !defined(OSSL_LIBCRYPTO_DSO_DSO_LOCAL_H) */
diff --git a/crypto/dso/dso_win32.c b/crypto/dso/dso_win32.c
index 6ac6727fda..908a3bbdc7 100644
--- a/crypto/dso/dso_win32.c
+++ b/crypto/dso/dso_win32.c
@@ -12,7 +12,48 @@
 
 #if defined(DSO_WIN32)
 
-#define GETPROCADDRESS(h, name, type) ((type)(void (*)(void))GetProcAddress((h), (name)))
+#ifdef _WIN32_WCE
+#if _WIN32_WCE < 300
+static FARPROC GetProcAddressA(HMODULE hModule, LPCSTR lpProcName)
+{
+    WCHAR lpProcNameW[64];
+    int i;
+
+    for (i = 0; lpProcName[i] && i < 64; i++)
+        lpProcNameW[i] = (WCHAR)lpProcName[i];
+    if (i == 64)
+        return NULL;
+    lpProcNameW[i] = 0;
+
+    return GetProcAddressW(hModule, lpProcNameW);
+}
+#endif
+#undef GetProcAddress
+#define GetProcAddress GetProcAddressA
+
+static HINSTANCE LoadLibraryA(LPCSTR lpLibFileName)
+{
+    WCHAR *fnamw;
+    size_t len_0 = strlen(lpLibFileName) + 1, i;
+
+#ifdef _MSC_VER
+    fnamw = (WCHAR *)_alloca(len_0 * sizeof(WCHAR));
+#else
+    fnamw = (WCHAR *)alloca(len_0 * sizeof(WCHAR));
+#endif
+    if (fnamw == NULL) {
+        SetLastError(ERROR_NOT_ENOUGH_MEMORY);
+        return NULL;
+    }
+#if defined(_WIN32_WCE) && _WIN32_WCE >= 101
+    if (!MultiByteToWideChar(CP_ACP, 0, lpLibFileName, len_0, fnamw, len_0))
+#endif
+        for (i = 0; i < len_0; i++)
+            fnamw[i] = (WCHAR)lpLibFileName[i];
+
+    return LoadLibraryW(fnamw);
+}
+#endif
 
 /* Part of the hack in "win32_load" ... */
 #define DSO_MAX_TRANSLATED_SIZE 256
@@ -136,7 +177,7 @@ static DSO_FUNC_TYPE win32_bind_func(DSO *dso, const char *symname)
         ERR_raise(ERR_LIB_DSO, DSO_R_NULL_HANDLE);
         return NULL;
     }
-    sym.f = GETPROCADDRESS(*ptr, symname, FARPROC);
+    sym.f = GetProcAddress(*ptr, symname);
     if (sym.p == NULL) {
         ERR_raise_data(ERR_LIB_DSO, DSO_R_SYM_FAILURE, "symname(%s)", symname);
         return NULL;
@@ -278,7 +319,7 @@ static char *win32_joiner(DSO *dso, const struct file_st *file_split)
         len++; /* 1 for ending \ */
     }
     len += file_split->dirlen;
-    if (file_split->dir) {
+    if (file_split->dir && file_split->file) {
         len++; /* 1 for ending \ */
     }
     len += file_split->filelen;
@@ -429,10 +470,14 @@ static const char *openssl_strnchr(const char *string, int c, size_t len)
 }
 
 #include 
+#ifdef _WIN32_WCE
+#define DLLNAME "TOOLHELP.DLL"
+#else
 #ifdef MODULEENTRY32
 #undef MODULEENTRY32 /* unmask the ASCII version! */
 #endif
 #define DLLNAME "KERNEL32.DLL"
+#endif
 
 typedef HANDLE(WINAPI *CREATETOOLHELP32SNAPSHOT)(DWORD, DWORD);
 typedef BOOL(WINAPI *CLOSETOOLHELP32SNAPSHOT)(HANDLE);
@@ -440,11 +485,12 @@ typedef BOOL(WINAPI *MODULE32)(HANDLE, MODULEENTRY32 *);
 
 static int win32_pathbyaddr(void *addr, char *path, int sz)
 {
-    HMODULE hModule = NULL;
-    const DWORD wpathSize = 32768; /* 32768 is the maximum possible path length on Windows */
-    WCHAR *wpath = NULL;
-    DWORD wlen, wsz;
-    int utf8len = -1;
+    HMODULE dll;
+    HANDLE hModuleSnap = INVALID_HANDLE_VALUE;
+    MODULEENTRY32 me32;
+    CREATETOOLHELP32SNAPSHOT create_snap;
+    CLOSETOOLHELP32SNAPSHOT close_snap;
+    MODULE32 module_first, module_next;
 
     if (addr == NULL) {
         union {
@@ -456,57 +502,89 @@ static int win32_pathbyaddr(void *addr, char *path, int sz)
         addr = t.p;
     }
 
-    if (!GetModuleHandleExW(
-            GET_MODULE_HANDLE_EX_FLAG_FROM_ADDRESS | GET_MODULE_HANDLE_EX_FLAG_UNCHANGED_REFCOUNT,
-            (LPCWSTR)addr, &hModule)) {
-        ERR_raise_data(ERR_LIB_DSO, DSO_R_SYM_FAILURE, "Unable to get module handle (%lu)\n",
-            GetLastError());
-        goto out;
+    dll = LoadLibrary(TEXT(DLLNAME));
+    if (dll == NULL) {
+        ERR_raise(ERR_LIB_DSO, DSO_R_UNSUPPORTED);
+        return -1;
     }
-    wpath = (WCHAR *)OPENSSL_malloc(wpathSize * sizeof(WCHAR));
-    if (wpath == NULL) {
-        ERR_raise_data(ERR_LIB_DSO, DSO_R_NULL_HANDLE, "Path allocation failure (%lu)\n",
-            GetLastError());
-        goto out;
-    }
-    wlen = GetModuleFileNameW(hModule, wpath, wpathSize);
-    if (wlen == 0 || GetLastError() == ERROR_INSUFFICIENT_BUFFER) {
-        ERR_raise_data(ERR_LIB_DSO, DSO_R_NAME_TRANSLATION_FAILED, "Module name fetch failed (%lu)\n",
-            GetLastError());
-        goto out;
+
+    create_snap = (CREATETOOLHELP32SNAPSHOT)
+        GetProcAddress(dll, "CreateToolhelp32Snapshot");
+    if (create_snap == NULL) {
+        FreeLibrary(dll);
+        ERR_raise(ERR_LIB_DSO, DSO_R_UNSUPPORTED);
+        return -1;
     }
+    /* We take the rest for granted... */
+#ifdef _WIN32_WCE
+    close_snap = (CLOSETOOLHELP32SNAPSHOT)
+        GetProcAddress(dll, "CloseToolhelp32Snapshot");
+#else
+    close_snap = (CLOSETOOLHELP32SNAPSHOT)CloseHandle;
+#endif
+    module_first = (MODULE32)GetProcAddress(dll, "Module32First");
+    module_next = (MODULE32)GetProcAddress(dll, "Module32Next");
 
     /*
-     * If we pass a size of 0 or less, invoke the size-query pattern,
-     * in which we do not actually copy the name to the path buffer,
-     * but return the size the path buffer needs to be for this object
+     * Take a snapshot of current process which includes
+     * list of all involved modules.
      */
-    if (sz <= 0) {
-        utf8len = (int)(wlen + 1);
-        goto out;
+    hModuleSnap = (*create_snap)(TH32CS_SNAPMODULE, 0);
+    if (hModuleSnap == INVALID_HANDLE_VALUE) {
+        FreeLibrary(dll);
+        ERR_raise(ERR_LIB_DSO, DSO_R_UNSUPPORTED);
+        return -1;
     }
 
-    /*
-     * Convert the wide path to UTF-8
-     */
-    wsz = (DWORD)sz;
-    utf8len = WideCharToMultiByte(CP_UTF8, 0, wpath, -1, NULL, 0, NULL, NULL);
-    if (utf8len <= 0 || (DWORD)utf8len > wsz) {
-        ERR_raise_data(ERR_LIB_DSO, DSO_R_NAME_TRANSLATION_FAILED, "UTF8 query failed (%lu)\n",
-            GetLastError());
-        goto out;
+    me32.dwSize = sizeof(me32);
+
+    if (!(*module_first)(hModuleSnap, &me32)) {
+        (*close_snap)(hModuleSnap);
+        FreeLibrary(dll);
+        ERR_raise(ERR_LIB_DSO, DSO_R_FAILURE);
+        return -1;
     }
 
-    if (WideCharToMultiByte(CP_UTF8, 0, wpath, -1, path, wsz, NULL, NULL) <= 0) {
-        ERR_raise_data(ERR_LIB_DSO, DSO_R_NAME_TRANSLATION_FAILED, "UTF8 translation failed (%lu)\n",
-            GetLastError());
-        goto out;
-    }
-out:
-    OPENSSL_free(wpath);
-    if (hModule != NULL)
-        CloseHandle(hModule);
-    return utf8len;
+    /* Enumerate the modules to find one which includes me. */
+    do {
+        if ((size_t)addr >= (size_t)me32.modBaseAddr && (size_t)addr < (size_t)(me32.modBaseAddr + me32.modBaseSize)) {
+            (*close_snap)(hModuleSnap);
+            FreeLibrary(dll);
+#ifdef _WIN32_WCE
+#if _WIN32_WCE >= 101
+            return WideCharToMultiByte(CP_ACP, 0, me32.szExePath, -1,
+                path, sz, NULL, NULL);
+#else
+            {
+                int i, len = (int)wcslen(me32.szExePath);
+                if (sz <= 0)
+                    return len + 1;
+                if (len >= sz)
+                    len = sz - 1;
+                for (i = 0; i < len; i++)
+                    path[i] = (char)me32.szExePath[i];
+                path[len++] = '\0';
+                return len;
+            }
+#endif
+#else
+            {
+                int len = (int)strlen(me32.szExePath);
+                if (sz <= 0)
+                    return len + 1;
+                if (len >= sz)
+                    len = sz - 1;
+                memcpy(path, me32.szExePath, len);
+                path[len++] = '\0';
+                return len;
+            }
+#endif
+        }
+    } while ((*module_next)(hModuleSnap, &me32));
+
+    (*close_snap)(hModuleSnap);
+    FreeLibrary(dll);
+    return 0;
 }
 
 static void *win32_globallookup(const char *name)
@@ -528,16 +606,22 @@ static void *win32_globallookup(const char *name)
         return NULL;
     }
 
-    create_snap = GETPROCADDRESS(dll, "CreateToolhelp32Snapshot", CREATETOOLHELP32SNAPSHOT);
+    create_snap = (CREATETOOLHELP32SNAPSHOT)
+        GetProcAddress(dll, "CreateToolhelp32Snapshot");
     if (create_snap == NULL) {
         FreeLibrary(dll);
         ERR_raise(ERR_LIB_DSO, DSO_R_UNSUPPORTED);
         return NULL;
     }
     /* We take the rest for granted... */
+#ifdef _WIN32_WCE
+    close_snap = (CLOSETOOLHELP32SNAPSHOT)
+        GetProcAddress(dll, "CloseToolhelp32Snapshot");
+#else
     close_snap = (CLOSETOOLHELP32SNAPSHOT)CloseHandle;
-    module_first = GETPROCADDRESS(dll, "Module32First", MODULE32);
-    module_next = GETPROCADDRESS(dll, "Module32Next", MODULE32);
+#endif
+    module_first = (MODULE32)GetProcAddress(dll, "Module32First");
+    module_next = (MODULE32)GetProcAddress(dll, "Module32Next");
 
     hModuleSnap = (*create_snap)(TH32CS_SNAPMODULE, 0);
     if (hModuleSnap == INVALID_HANDLE_VALUE) {
@@ -555,7 +639,7 @@ static void *win32_globallookup(const char *name)
     }
 
     do {
-        if ((ret.f = GETPROCADDRESS(me32.hModule, name, FARPROC))) {
+        if ((ret.f = GetProcAddress(me32.hModule, name))) {
             (*close_snap)(hModuleSnap);
             FreeLibrary(dll);
             return ret.p;
diff --git a/crypto/ec/asm/ecp_nistz256-armv4.pl b/crypto/ec/asm/ecp_nistz256-armv4.pl
index f00767e28b..77fd64c90a 100755
--- a/crypto/ec/asm/ecp_nistz256-armv4.pl
+++ b/crypto/ec/asm/ecp_nistz256-armv4.pl
@@ -51,7 +51,7 @@ if ($flavour && $flavour ne "void") {
 }
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 #if defined(__thumb2__)
 .syntax	unified
diff --git a/crypto/ec/asm/ecp_nistz256-armv8.pl b/crypto/ec/asm/ecp_nistz256-armv8.pl
index 9ecabca7a7..f84c6d49e7 100644
--- a/crypto/ec/asm/ecp_nistz256-armv8.pl
+++ b/crypto/ec/asm/ecp_nistz256-armv8.pl
@@ -53,7 +53,7 @@ my ($rp,$ap,$bp,$bi,$a0,$a1,$a2,$a3,$t0,$t1,$t2,$t3,$poly1,$poly3,
 my ($acc6,$acc7)=($ap,$bp);	# used in __ecp_nistz256_sqr_mont
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 .rodata
 ___
diff --git a/crypto/ec/asm/ecp_nistz256-sparcv9.pl b/crypto/ec/asm/ecp_nistz256-sparcv9.pl
index 0171420aaa..33f8ea2032 100755
--- a/crypto/ec/asm/ecp_nistz256-sparcv9.pl
+++ b/crypto/ec/asm/ecp_nistz256-sparcv9.pl
@@ -37,7 +37,7 @@ $code.=<<___;
 #ifndef __ASSEMBLER__
 # define __ASSEMBLER__ 1
 #endif
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 #define LOCALS	(STACK_BIAS+STACK_FRAME)
 #ifdef	__arch64__
diff --git a/crypto/ec/asm/ecp_nistz256-x86_64.pl b/crypto/ec/asm/ecp_nistz256-x86_64.pl
index f30811bc86..bfd767642a 100755
--- a/crypto/ec/asm/ecp_nistz256-x86_64.pl
+++ b/crypto/ec/asm/ecp_nistz256-x86_64.pl
@@ -80,14 +80,6 @@ if (!$addx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([
 	$addx = ($ver>=3.03);
 }
 
-if (!$addx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$avx = ($1>=11); #icx started with clang 11
-		$addx = ($1>=11);
-	}
-}
-
 $code.=<<___;
 .text
 .extern	OPENSSL_ia32cap_P
diff --git a/crypto/ec/asm/ecp_sm2p256-armv8.pl b/crypto/ec/asm/ecp_sm2p256-armv8.pl
index 34def77c6e..6db0b6d7aa 100644
--- a/crypto/ec/asm/ecp_sm2p256-armv8.pl
+++ b/crypto/ec/asm/ecp_sm2p256-armv8.pl
@@ -162,7 +162,7 @@ ___
 
 {
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 .arch  armv8-a
 .rodata
 
diff --git a/crypto/ec/asm/ecp_sm2p256-riscv64.pl b/crypto/ec/asm/ecp_sm2p256-riscv64.pl
index 40938e75c0..2a17e124dc 100644
--- a/crypto/ec/asm/ecp_sm2p256-riscv64.pl
+++ b/crypto/ec/asm/ecp_sm2p256-riscv64.pl
@@ -366,7 +366,7 @@ $code.=<<___;
 .type .Lord_div_2,\@object
 .Lord_div_2:
 .dword	0xa9ddfa049ceaa092,0xb901efb590e30295,0xffffffffffffffff,0x7fffffff7fffffff
-.previous
+
 
 // void bn_rshift1(BN_ULONG *a);
 .globl	bn_rshift1
diff --git a/crypto/ec/asm/x25519-x86_64.pl b/crypto/ec/asm/x25519-x86_64.pl
index d2fdd76948..a0771494b1 100755
--- a/crypto/ec/asm/x25519-x86_64.pl
+++ b/crypto/ec/asm/x25519-x86_64.pl
@@ -97,13 +97,6 @@ if (!$addx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([
 	$addx = ($ver>=3.03);
 }
 
-if (!$addx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$addx = ($1>=11); #icx started with clang 11
-	}
-}
-
 $code.=<<___;
 .text
 
diff --git a/crypto/ec/build.info b/crypto/ec/build.info
index 6fe0a31932..b6d1a9356e 100644
--- a/crypto/ec/build.info
+++ b/crypto/ec/build.info
@@ -93,7 +93,7 @@ IF[{- !$disabled{'ec_nistp_64_gcc_128'} -}]
   $COMMON=$COMMON ecp_nistp224.c ecp_nistp256.c ecp_nistp384.c ecp_nistp521.c ecp_nistputil.c
 ENDIF
 
-SOURCE[../../libcrypto]=$COMMON ec_ameth.c \
+SOURCE[../../libcrypto]=$COMMON ec_ameth.c ec_pmeth.c \
                         ec_err.c eck_prn.c \
                         ec_deprecated.c ec_print.c
 IF[{- !$disabled{'ecx'} -}]
diff --git a/crypto/ec/curve25519.c b/crypto/ec/curve25519.c
index 53c8bff5ed..c6886763ab 100644
--- a/crypto/ec/curve25519.c
+++ b/crypto/ec/curve25519.c
@@ -236,13 +236,6 @@ static void x25519_scalar_mulx(uint8_t out[32], const uint8_t scalar[32],
         fe64_sub(tmp1, x2, z2);
         fe64_add(x2, x2, z2);
         fe64_add(z2, x3, z3);
-        /* The original copy in x25519_scalar_mult_generic uses argument order
-         * fe_mul(z3, tmp0, x2), with the input arguments swapped.
-         *
-         * The assembly implementation of fe64_mul used here runs faster in
-         * parallel with its nearby instructions when an earlier-computable
-         * input (like tmp0) is passed as the 2nd input because it consumes
-         * the 2nd input at a faster rate than the 1st input. */
         fe64_mul(z3, x2, tmp0);
         fe64_mul(z2, z2, tmp1);
         fe64_sqr(tmp0, tmp1);
diff --git a/crypto/ec/curve448/arch_32/arch_intrinsics.inc b/crypto/ec/curve448/arch_32/arch_intrinsics.h
similarity index 94%
rename from crypto/ec/curve448/arch_32/arch_intrinsics.inc
rename to crypto/ec/curve448/arch_32/arch_intrinsics.h
index 78f5afc69f..6a2bf46a53 100644
--- a/crypto/ec/curve448/arch_32/arch_intrinsics.inc
+++ b/crypto/ec/curve448/arch_32/arch_intrinsics.h
@@ -10,8 +10,6 @@
  * Originally written by Mike Hamburg
  */
 
-/* IWYU pragma: private, include word.h */
-
 #ifndef OSSL_CRYPTO_EC_CURVE448_ARCH_32_INTRINSICS_H
 #define OSSL_CRYPTO_EC_CURVE448_ARCH_32_INTRINSICS_H
 
diff --git a/crypto/ec/curve448/arch_32/f_impl.h b/crypto/ec/curve448/arch_32/f_impl.h
new file mode 100644
index 0000000000..017844c11d
--- /dev/null
+++ b/crypto/ec/curve448/arch_32/f_impl.h
@@ -0,0 +1,64 @@
+/*
+ * Copyright 2017-2018 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2014-2016 Cryptography Research, Inc.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ *
+ * Originally written by Mike Hamburg
+ */
+
+#ifndef OSSL_CRYPTO_EC_CURVE448_ARCH_32_F_IMPL_H
+#define OSSL_CRYPTO_EC_CURVE448_ARCH_32_F_IMPL_H
+
+#define GF_HEADROOM 2
+#define LIMB(x) ((x) & ((1 << 28) - 1)), ((x) >> 28)
+#define FIELD_LITERAL(a, b, c, d, e, f, g, h)                                      \
+    {                                                                              \
+        {                                                                          \
+            LIMB(a), LIMB(b), LIMB(c), LIMB(d), LIMB(e), LIMB(f), LIMB(g), LIMB(h) \
+        }                                                                          \
+    }
+
+#define LIMB_PLACE_VALUE(i) 28
+
+void gf_add_RAW(gf out, const gf a, const gf b)
+{
+    unsigned int i;
+
+    for (i = 0; i < NLIMBS; i++)
+        out->limb[i] = a->limb[i] + b->limb[i];
+}
+
+void gf_sub_RAW(gf out, const gf a, const gf b)
+{
+    unsigned int i;
+
+    for (i = 0; i < NLIMBS; i++)
+        out->limb[i] = a->limb[i] - b->limb[i];
+}
+
+void gf_bias(gf a, int amt)
+{
+    unsigned int i;
+    uint32_t co1 = ((1 << 28) - 1) * amt, co2 = co1 - amt;
+
+    for (i = 0; i < NLIMBS; i++)
+        a->limb[i] += (i == NLIMBS / 2) ? co2 : co1;
+}
+
+void gf_weak_reduce(gf a)
+{
+    uint32_t mask = (1 << 28) - 1;
+    uint32_t tmp = a->limb[NLIMBS - 1] >> 28;
+    unsigned int i;
+
+    a->limb[NLIMBS / 2] += tmp;
+    for (i = NLIMBS - 1; i > 0; i--)
+        a->limb[i] = (a->limb[i] & mask) + (a->limb[i - 1] >> 28);
+    a->limb[0] = (a->limb[0] & mask) + tmp;
+}
+
+#endif /* OSSL_CRYPTO_EC_CURVE448_ARCH_32_F_IMPL_H */
diff --git a/crypto/ec/curve448/arch_64/arch_intrinsics.inc b/crypto/ec/curve448/arch_64/arch_intrinsics.h
similarity index 92%
rename from crypto/ec/curve448/arch_64/arch_intrinsics.inc
rename to crypto/ec/curve448/arch_64/arch_intrinsics.h
index 5dc906a241..09f0fdf34e 100644
--- a/crypto/ec/curve448/arch_64/arch_intrinsics.inc
+++ b/crypto/ec/curve448/arch_64/arch_intrinsics.h
@@ -10,13 +10,9 @@
  * Originally written by Mike Hamburg
  */
 
-/* IWYU pragma: private, include word.h */
-
 #ifndef OSSL_CRYPTO_EC_CURVE448_ARCH_64_INTRINSICS_H
 #define OSSL_CRYPTO_EC_CURVE448_ARCH_64_INTRINSICS_H
 
-#include 
-
 #include "internal/constant_time.h"
 
 #define ARCH_WORD_BITS 64
diff --git a/crypto/ec/curve448/arch_64/f_impl.h b/crypto/ec/curve448/arch_64/f_impl.h
new file mode 100644
index 0000000000..3e27820171
--- /dev/null
+++ b/crypto/ec/curve448/arch_64/f_impl.h
@@ -0,0 +1,63 @@
+/*
+ * Copyright 2017-2022 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2014-2016 Cryptography Research, Inc.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ *
+ * Originally written by Mike Hamburg
+ */
+
+#ifndef OSSL_CRYPTO_EC_CURVE448_ARCH_64_F_IMPL_H
+#define OSSL_CRYPTO_EC_CURVE448_ARCH_64_F_IMPL_H
+
+#define GF_HEADROOM 9999 /* Everything is reduced anyway */
+#define FIELD_LITERAL(a, b, c, d, e, f, g, h) \
+    {                                         \
+        {                                     \
+            a, b, c, d, e, f, g, h            \
+        }                                     \
+    }
+
+#define LIMB_PLACE_VALUE(i) 56
+
+void gf_add_RAW(gf out, const gf a, const gf b)
+{
+    unsigned int i;
+
+    for (i = 0; i < NLIMBS; i++)
+        out->limb[i] = a->limb[i] + b->limb[i];
+
+    gf_weak_reduce(out);
+}
+
+void gf_sub_RAW(gf out, const gf a, const gf b)
+{
+    uint64_t co1 = ((1ULL << 56) - 1) * 2, co2 = co1 - 2;
+    unsigned int i;
+
+    for (i = 0; i < NLIMBS; i++)
+        out->limb[i] = a->limb[i] - b->limb[i] + ((i == NLIMBS / 2) ? co2 : co1);
+
+    gf_weak_reduce(out);
+}
+
+void gf_bias(gf a, int amt)
+{
+}
+
+void gf_weak_reduce(gf a)
+{
+    uint64_t mask = (1ULL << 56) - 1;
+    uint64_t tmp = a->limb[NLIMBS - 1] >> 56;
+    unsigned int i;
+
+    a->limb[NLIMBS / 2] += tmp;
+    for (i = NLIMBS - 1; i > 0; i--)
+        a->limb[i] = (a->limb[i] & mask) + (a->limb[i - 1] >> 56);
+    a->limb[0] = (a->limb[0] & mask) + tmp;
+}
+
+#endif /* OSSL_CRYPTO_EC_CURVE448_ARCH_64_F_IMPL_H */
diff --git a/crypto/ec/curve448/curve448.c b/crypto/ec/curve448/curve448.c
index 29edb317f1..1a31f86355 100644
--- a/crypto/ec/curve448/curve448.c
+++ b/crypto/ec/curve448/curve448.c
@@ -502,7 +502,7 @@ struct smvt_control {
     int power, addend;
 };
 
-#if defined(__GNUC__)
+#if defined(__GNUC__) && (__GNUC__ > 3 || (__GNUC__ == 3 && __GNUC_MINOR__ > 3))
 #define NUMTRAILINGZEROS __builtin_ctz
 #else
 #define NUMTRAILINGZEROS numtrailingzeros
diff --git a/crypto/ec/curve448/ed448.h b/crypto/ec/curve448/ed448.h
index bb045fce87..1c94649557 100644
--- a/crypto/ec/curve448/ed448.h
+++ b/crypto/ec/curve448/ed448.h
@@ -13,8 +13,6 @@
 #ifndef OSSL_CRYPTO_EC_CURVE448_ED448_H
 #define OSSL_CRYPTO_EC_CURVE448_ED448_H
 
-#include 
-
 #include "point_448.h"
 
 /* Number of bytes in an EdDSA public key. */
@@ -32,6 +30,128 @@
 /* EdDSA decoding ratio. */
 #define C448_EDDSA_DECODE_RATIO (4 / 4)
 
+/*
+ * EdDSA key generation.  This function uses a different (non-Decaf) encoding.
+ *
+ * pubkey (out): The public key.
+ * privkey (in): The private key.
+ */
+c448_error_t
+ossl_c448_ed448_derive_public_key(
+    OSSL_LIB_CTX *ctx,
+    uint8_t pubkey[EDDSA_448_PUBLIC_BYTES],
+    const uint8_t privkey[EDDSA_448_PRIVATE_BYTES],
+    const char *propq);
+
+/*
+ * EdDSA signing.
+ *
+ * signature (out): The signature.
+ * privkey (in): The private key.
+ * pubkey (in):  The public key.
+ * message (in):  The message to sign.
+ * message_len (in):  The length of the message.
+ * prehashed (in):  Nonzero if the message is actually the hash of something
+ *                  you want to sign.
+ * context (in):  A "context" for this signature of up to 255 bytes.
+ * context_len (in):  Length of the context.
+ *
+ * For Ed25519, it is unsafe to use the same key for both prehashed and
+ * non-prehashed messages, at least without some very careful protocol-level
+ * disambiguation.  For Ed448 it is safe.
+ */
+c448_error_t
+ossl_c448_ed448_sign(OSSL_LIB_CTX *ctx,
+    uint8_t signature[EDDSA_448_SIGNATURE_BYTES],
+    const uint8_t privkey[EDDSA_448_PRIVATE_BYTES],
+    const uint8_t pubkey[EDDSA_448_PUBLIC_BYTES],
+    const uint8_t *message, size_t message_len,
+    uint8_t prehashed, const uint8_t *context,
+    size_t context_len,
+    const char *propq);
+
+/*
+ * EdDSA signing with prehash.
+ *
+ * signature (out): The signature.
+ * privkey (in): The private key.
+ * pubkey (in): The public key.
+ * hash (in): The hash of the message.  This object will not be modified by the
+ *            call.
+ * context (in): A "context" for this signature of up to 255 bytes.  Must be the
+ *               same as what was used for the prehash.
+ * context_len (in): Length of the context.
+ *
+ * For Ed25519, it is unsafe to use the same key for both prehashed and
+ * non-prehashed messages, at least without some very careful protocol-level
+ * disambiguation.  For Ed448 it is safe.
+ */
+c448_error_t
+ossl_c448_ed448_sign_prehash(OSSL_LIB_CTX *ctx,
+    uint8_t signature[EDDSA_448_SIGNATURE_BYTES],
+    const uint8_t privkey[EDDSA_448_PRIVATE_BYTES],
+    const uint8_t pubkey[EDDSA_448_PUBLIC_BYTES],
+    const uint8_t hash[64],
+    const uint8_t *context,
+    size_t context_len,
+    const char *propq);
+
+/*
+ * EdDSA signature verification.
+ *
+ * Uses the standard (i.e. less-strict) verification formula.
+ *
+ * signature (in): The signature.
+ * pubkey (in): The public key.
+ * message (in): The message to verify.
+ * message_len (in): The length of the message.
+ * prehashed (in): Nonzero if the message is actually the hash of something you
+ *                 want to verify.
+ * context (in): A "context" for this signature of up to 255 bytes.
+ * context_len (in): Length of the context.
+ *
+ * For Ed25519, it is unsafe to use the same key for both prehashed and
+ * non-prehashed messages, at least without some very careful protocol-level
+ * disambiguation.  For Ed448 it is safe.
+ */
+c448_error_t
+ossl_c448_ed448_verify(OSSL_LIB_CTX *ctx,
+    const uint8_t
+        signature[EDDSA_448_SIGNATURE_BYTES],
+    const uint8_t
+        pubkey[EDDSA_448_PUBLIC_BYTES],
+    const uint8_t *message, size_t message_len,
+    uint8_t prehashed, const uint8_t *context,
+    uint8_t context_len,
+    const char *propq);
+
+/*
+ * EdDSA signature verification.
+ *
+ * Uses the standard (i.e. less-strict) verification formula.
+ *
+ * signature (in): The signature.
+ * pubkey (in): The public key.
+ * hash (in): The hash of the message.  This object will not be modified by the
+ *            call.
+ * context (in): A "context" for this signature of up to 255 bytes.  Must be the
+ *               same as what was used for the prehash.
+ * context_len (in): Length of the context.
+ *
+ * For Ed25519, it is unsafe to use the same key for both prehashed and
+ * non-prehashed messages, at least without some very careful protocol-level
+ * disambiguation.  For Ed448 it is safe.
+ */
+c448_error_t
+ossl_c448_ed448_verify_prehash(
+    OSSL_LIB_CTX *ctx,
+    const uint8_t signature[EDDSA_448_SIGNATURE_BYTES],
+    const uint8_t pubkey[EDDSA_448_PUBLIC_BYTES],
+    const uint8_t hash[64],
+    const uint8_t *context,
+    uint8_t context_len,
+    const char *propq);
+
 /*
  * EdDSA point encoding.  Used internally, exposed externally.
  * Multiplies by C448_EDDSA_ENCODE_RATIO first.
@@ -73,4 +193,19 @@ ossl_curve448_point_decode_like_eddsa_and_mul_by_ratio(
     curve448_point_t p,
     const uint8_t enc[EDDSA_448_PUBLIC_BYTES]);
 
+/*
+ * EdDSA to ECDH private key conversion
+ * Using the appropriate hash function, hash the EdDSA private key
+ * and keep only the lower bytes to get the ECDH private key
+ *
+ * x (out): The ECDH private key as in RFC7748
+ * ed (in): The EdDSA private key
+ */
+c448_error_t
+ossl_c448_ed448_convert_private_key_to_x448(
+    OSSL_LIB_CTX *ctx,
+    uint8_t x[X448_PRIVATE_BYTES],
+    const uint8_t ed[EDDSA_448_PRIVATE_BYTES],
+    const char *propq);
+
 #endif /* OSSL_CRYPTO_EC_CURVE448_ED448_H */
diff --git a/crypto/ec/curve448/eddsa.c b/crypto/ec/curve448/eddsa.c
index 1c375413ab..f90ee2e82d 100644
--- a/crypto/ec/curve448/eddsa.c
+++ b/crypto/ec/curve448/eddsa.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2017-2024 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright 2015-2016 Cryptography Research, Inc.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
@@ -62,7 +62,7 @@ static c448_error_t hash_init_with_dom(OSSL_LIB_CTX *ctx, EVP_MD_CTX *hashctx,
     const char *propq)
 {
     /* ASCII: "SigEd448", in hex for EBCDIC compatibility */
-    static const char dom_s[] = "\x53\x69\x67\x45\x64\x34\x34\x38";
+    const char dom_s[] = "\x53\x69\x67\x45\x64\x34\x34\x38";
     uint8_t dom[2];
     EVP_MD *shake256 = NULL;
 
@@ -89,15 +89,22 @@ static c448_error_t hash_init_with_dom(OSSL_LIB_CTX *ctx, EVP_MD_CTX *hashctx,
     return C448_SUCCESS;
 }
 
-/*
- * EdDSA key generation.  This function uses a different (non-Decaf) encoding.
- *
- * pubkey (out): The public key.
- * privkey (in): The private key.
- * propq (in): The property query used to fetch SHAKE256.
- */
-static c448_error_t
-c448_ed448_derive_public_key(
+/* In this file because it uses the hash */
+c448_error_t
+ossl_c448_ed448_convert_private_key_to_x448(
+    OSSL_LIB_CTX *ctx,
+    uint8_t x[X448_PRIVATE_BYTES],
+    const uint8_t ed[EDDSA_448_PRIVATE_BYTES],
+    const char *propq)
+{
+    /* pass the private key through oneshot_hash function */
+    /* and keep the first X448_PRIVATE_BYTES bytes */
+    return oneshot_hash(ctx, x, X448_PRIVATE_BYTES, ed,
+        EDDSA_448_PRIVATE_BYTES, propq);
+}
+
+c448_error_t
+ossl_c448_ed448_derive_public_key(
     OSSL_LIB_CTX *ctx,
     uint8_t pubkey[EDDSA_448_PUBLIC_BYTES],
     const uint8_t privkey[EDDSA_448_PRIVATE_BYTES],
@@ -144,26 +151,8 @@ c448_ed448_derive_public_key(
     return C448_SUCCESS;
 }
 
-/*
- * EdDSA signing.
- *
- * signature (out): The signature.
- * privkey (in): The private key.
- * pubkey (in):  The public key.
- * message (in):  The message to sign.
- * message_len (in):  The length of the message.
- * prehashed (in):  Nonzero if the message is actually the hash of something
- *                  you want to sign.
- * context (in):  A "context" for this signature of up to 255 bytes.
- * context_len (in):  Length of the context.
- * propq (in):  The property query used to fetch SHAKE256.
- *
- * For Ed25519, it is unsafe to use the same key for both prehashed and
- * non-prehashed messages, at least without some very careful protocol-level
- * disambiguation.  For Ed448 it is safe.
- */
-static c448_error_t
-c448_ed448_sign(OSSL_LIB_CTX *ctx,
+c448_error_t
+ossl_c448_ed448_sign(OSSL_LIB_CTX *ctx,
     uint8_t signature[EDDSA_448_SIGNATURE_BYTES],
     const uint8_t privkey[EDDSA_448_PRIVATE_BYTES],
     const uint8_t pubkey[EDDSA_448_PUBLIC_BYTES],
@@ -270,6 +259,19 @@ err:
     return ret;
 }
 
+c448_error_t
+ossl_c448_ed448_sign_prehash(
+    OSSL_LIB_CTX *ctx,
+    uint8_t signature[EDDSA_448_SIGNATURE_BYTES],
+    const uint8_t privkey[EDDSA_448_PRIVATE_BYTES],
+    const uint8_t pubkey[EDDSA_448_PUBLIC_BYTES],
+    const uint8_t hash[64], const uint8_t *context,
+    size_t context_len, const char *propq)
+{
+    return ossl_c448_ed448_sign(ctx, signature, privkey, pubkey, hash, 64, 1,
+        context, context_len, propq);
+}
+
 static c448_error_t
 c448_ed448_pubkey_verify(const uint8_t *pub, size_t pub_len)
 {
@@ -281,27 +283,8 @@ c448_ed448_pubkey_verify(const uint8_t *pub, size_t pub_len)
     return ossl_curve448_point_decode_like_eddsa_and_mul_by_ratio(pk_point, pub);
 }
 
-/*
- * EdDSA signature verification.
- *
- * Uses the standard (i.e. less-strict) verification formula.
- *
- * signature (in): The signature.
- * pubkey (in): The public key.
- * message (in): The message to verify.
- * message_len (in): The length of the message.
- * prehashed (in): Nonzero if the message is actually the hash of something you
- *                 want to verify.
- * context (in): A "context" for this signature of up to 255 bytes.
- * context_len (in): Length of the context.
- * propq (in): The property query used to fetch SHAKE256.
- *
- * For Ed25519, it is unsafe to use the same key for both prehashed and
- * non-prehashed messages, at least without some very careful protocol-level
- * disambiguation.  For Ed448 it is safe.
- */
-static c448_error_t
-c448_ed448_verify(
+c448_error_t
+ossl_c448_ed448_verify(
     OSSL_LIB_CTX *ctx,
     const uint8_t signature[EDDSA_448_SIGNATURE_BYTES],
     const uint8_t pubkey[EDDSA_448_PUBLIC_BYTES],
@@ -382,13 +365,25 @@ c448_ed448_verify(
     return c448_succeed_if(ossl_curve448_point_eq(pk_point, r_point));
 }
 
+c448_error_t
+ossl_c448_ed448_verify_prehash(
+    OSSL_LIB_CTX *ctx,
+    const uint8_t signature[EDDSA_448_SIGNATURE_BYTES],
+    const uint8_t pubkey[EDDSA_448_PUBLIC_BYTES],
+    const uint8_t hash[64], const uint8_t *context,
+    uint8_t context_len, const char *propq)
+{
+    return ossl_c448_ed448_verify(ctx, signature, pubkey, hash, 64, 1, context,
+        context_len, propq);
+}
+
 int ossl_ed448_sign(OSSL_LIB_CTX *ctx, uint8_t *out_sig,
     const uint8_t *message, size_t message_len,
     const uint8_t public_key[57], const uint8_t private_key[57],
     const uint8_t *context, size_t context_len,
     const uint8_t phflag, const char *propq)
 {
-    return c448_ed448_sign(ctx, out_sig, private_key, public_key, message,
+    return ossl_c448_ed448_sign(ctx, out_sig, private_key, public_key, message,
                message_len, phflag, context, context_len,
                propq)
         == C448_SUCCESS;
@@ -410,7 +405,7 @@ int ossl_ed448_verify(OSSL_LIB_CTX *ctx,
     const uint8_t *context, size_t context_len,
     const uint8_t phflag, const char *propq)
 {
-    return c448_ed448_verify(ctx, signature, public_key, message,
+    return ossl_c448_ed448_verify(ctx, signature, public_key, message,
                message_len, phflag, context, (uint8_t)context_len,
                propq)
         == C448_SUCCESS;
@@ -419,7 +414,7 @@ int ossl_ed448_verify(OSSL_LIB_CTX *ctx,
 int ossl_ed448_public_from_private(OSSL_LIB_CTX *ctx, uint8_t out_public_key[57],
     const uint8_t private_key[57], const char *propq)
 {
-    return c448_ed448_derive_public_key(ctx, out_public_key, private_key,
+    return ossl_c448_ed448_derive_public_key(ctx, out_public_key, private_key,
                propq)
         == C448_SUCCESS;
 }
diff --git a/crypto/ec/curve448/field.h b/crypto/ec/curve448/field.h
index 850244ee55..5de942f042 100644
--- a/crypto/ec/curve448/field.h
+++ b/crypto/ec/curve448/field.h
@@ -66,107 +66,14 @@ void gf_serialize(uint8_t serial[SER_BYTES], const gf x, int with_highbit);
 mask_t gf_deserialize(gf x, const uint8_t serial[SER_BYTES], int with_hibit,
     uint8_t hi_nmask);
 
-/* clang-format off */
 #define LIMBPERM(i) (i)
 #if (ARCH_WORD_BITS == 32)
-#define GF_HEADROOM 2
-#define LIMB(x) ((x) & ((1 << 28) - 1)), ((x) >> 28)
-#define FIELD_LITERAL(a, b, c, d, e, f, g, h)                                      \
-    {                                                                              \
-        {                                                                          \
-            LIMB(a), LIMB(b), LIMB(c), LIMB(d), LIMB(e), LIMB(f), LIMB(g), LIMB(h) \
-        }                                                                          \
-    }
-
-#define LIMB_PLACE_VALUE(i) 28
-
-void gf_add_RAW(gf out, const gf a, const gf b)
-{
-    unsigned int i;
-
-    for (i = 0; i < NLIMBS; i++)
-        out->limb[i] = a->limb[i] + b->limb[i];
-}
-
-void gf_sub_RAW(gf out, const gf a, const gf b)
-{
-    unsigned int i;
-
-    for (i = 0; i < NLIMBS; i++)
-        out->limb[i] = a->limb[i] - b->limb[i];
-}
-
-void gf_bias(gf a, int amt)
-{
-    unsigned int i;
-    uint32_t co1 = ((1 << 28) - 1) * amt, co2 = co1 - amt;
-
-    for (i = 0; i < NLIMBS; i++)
-        a->limb[i] += (i == NLIMBS / 2) ? co2 : co1;
-}
-
-void gf_weak_reduce(gf a)
-{
-    uint32_t mask = (1 << 28) - 1;
-    uint32_t tmp = a->limb[NLIMBS - 1] >> 28;
-    unsigned int i;
-
-    a->limb[NLIMBS / 2] += tmp;
-    for (i = NLIMBS - 1; i > 0; i--)
-        a->limb[i] = (a->limb[i] & mask) + (a->limb[i - 1] >> 28);
-    a->limb[0] = (a->limb[0] & mask) + tmp;
-}
+#include "arch_32/f_impl.h" /* Bring in the inline implementations */
 #define LIMB_MASK(i) (((1) << LIMB_PLACE_VALUE(i)) - 1)
 #elif (ARCH_WORD_BITS == 64)
-#define GF_HEADROOM 9999 /* Everything is reduced anyway */
-#define FIELD_LITERAL(a, b, c, d, e, f, g, h) \
-    {                                         \
-        {                                     \
-            a, b, c, d, e, f, g, h            \
-        }                                     \
-    }
-
-#define LIMB_PLACE_VALUE(i) 56
-
-void gf_add_RAW(gf out, const gf a, const gf b)
-{
-    unsigned int i;
-
-    for (i = 0; i < NLIMBS; i++)
-        out->limb[i] = a->limb[i] + b->limb[i];
-
-    gf_weak_reduce(out);
-}
-
-void gf_sub_RAW(gf out, const gf a, const gf b)
-{
-    uint64_t co1 = ((1ULL << 56) - 1) * 2, co2 = co1 - 2;
-    unsigned int i;
-
-    for (i = 0; i < NLIMBS; i++)
-        out->limb[i] = a->limb[i] - b->limb[i] + ((i == NLIMBS / 2) ? co2 : co1);
-
-    gf_weak_reduce(out);
-}
-
-void gf_bias(gf a, int amt)
-{
-}
-
-void gf_weak_reduce(gf a)
-{
-    uint64_t mask = (1ULL << 56) - 1;
-    uint64_t tmp = a->limb[NLIMBS - 1] >> 56;
-    unsigned int i;
-
-    a->limb[NLIMBS / 2] += tmp;
-    for (i = NLIMBS - 1; i > 0; i--)
-        a->limb[i] = (a->limb[i] & mask) + (a->limb[i - 1] >> 56);
-    a->limb[0] = (a->limb[0] & mask) + tmp;
-}
+#include "arch_64/f_impl.h" /* Bring in the inline implementations */
 #define LIMB_MASK(i) (((1ULL) << LIMB_PLACE_VALUE(i)) - 1)
 #endif
-/* clang-format on */
 
 static const gf ZERO = { { { 0 } } }, ONE = { { { 1 } } };
 
diff --git a/crypto/ec/curve448/scalar.c b/crypto/ec/curve448/scalar.c
index 2308de6f63..191b0b4fd2 100644
--- a/crypto/ec/curve448/scalar.c
+++ b/crypto/ec/curve448/scalar.c
@@ -213,7 +213,6 @@ void ossl_curve448_scalar_halve(curve448_scalar_t out, const curve448_scalar_t a
     c448_dword_t chain = 0;
     unsigned int i;
 
-    mask = value_barrier_c448(mask);
     for (i = 0; i < C448_SCALAR_LIMBS; i++) {
         chain = (chain + a->limb[i]) + (sc_p->limb[i] & mask);
         out->limb[i] = (c448_word_t)chain;
diff --git a/crypto/ec/curve448/word.h b/crypto/ec/curve448/word.h
index 65ff1be12b..8137be6abb 100644
--- a/crypto/ec/curve448/word.h
+++ b/crypto/ec/curve448/word.h
@@ -18,12 +18,11 @@
 #include 
 #include 
 #include "curve448utils.h"
-#include "internal/constant_time.h"
 
 #ifdef INT128_MAX
-#include "arch_64/arch_intrinsics.inc"
+#include "arch_64/arch_intrinsics.h"
 #else
-#include "arch_32/arch_intrinsics.inc"
+#include "arch_32/arch_intrinsics.h"
 #endif
 
 #if (ARCH_WORD_BITS == 64)
@@ -54,12 +53,6 @@ typedef int64_t dsword_t;
 #error "For now we only support 32- and 64-bit architectures."
 #endif
 
-#if C448_WORD_BITS == 64
-#define value_barrier_c448(x) value_barrier_64(x)
-#elif C448_WORD_BITS == 32
-#define value_barrier_c448(x) value_barrier_32(x)
-#endif
-
 /*
  * The plan on booleans: The external interface uses c448_bool_t, but this
  * might be a different size than our particular arch's word_t (and thus
diff --git a/crypto/ec/ec2_smpl.c b/crypto/ec/ec2_smpl.c
index d8301ac6b7..17f814e4c9 100644
--- a/crypto/ec/ec2_smpl.c
+++ b/crypto/ec/ec2_smpl.c
@@ -74,11 +74,11 @@ void ossl_ec_GF2m_simple_group_clear_finish(EC_GROUP *group)
  */
 int ossl_ec_GF2m_simple_group_copy(EC_GROUP *dest, const EC_GROUP *src)
 {
-    if (BN_copy(dest->field, src->field) == NULL)
+    if (!BN_copy(dest->field, src->field))
         return 0;
-    if (BN_copy(dest->a, src->a) == NULL)
+    if (!BN_copy(dest->a, src->a))
         return 0;
-    if (BN_copy(dest->b, src->b) == NULL)
+    if (!BN_copy(dest->b, src->b))
         return 0;
     dest->poly[0] = src->poly[0];
     dest->poly[1] = src->poly[1];
@@ -103,7 +103,7 @@ int ossl_ec_GF2m_simple_group_set_curve(EC_GROUP *group,
     int ret = 0, i;
 
     /* group->field */
-    if (BN_copy(group->field, p) == NULL)
+    if (!BN_copy(group->field, p))
         goto err;
     i = BN_GF2m_poly2arr(group->field, group->poly, 6) - 1;
     if ((i != 5) && (i != 3)) {
@@ -142,17 +142,17 @@ int ossl_ec_GF2m_simple_group_get_curve(const EC_GROUP *group, BIGNUM *p,
     int ret = 0;
 
     if (p != NULL) {
-        if (BN_copy(p, group->field) == NULL)
+        if (!BN_copy(p, group->field))
             return 0;
     }
 
     if (a != NULL) {
-        if (BN_copy(a, group->a) == NULL)
+        if (!BN_copy(a, group->a))
             goto err;
     }
 
     if (b != NULL) {
-        if (BN_copy(b, group->b) == NULL)
+        if (!BN_copy(b, group->b))
             goto err;
     }
 
@@ -255,11 +255,11 @@ void ossl_ec_GF2m_simple_point_clear_finish(EC_POINT *point)
  */
 int ossl_ec_GF2m_simple_point_copy(EC_POINT *dest, const EC_POINT *src)
 {
-    if (BN_copy(dest->X, src->X) == NULL)
+    if (!BN_copy(dest->X, src->X))
         return 0;
-    if (BN_copy(dest->Y, src->Y) == NULL)
+    if (!BN_copy(dest->Y, src->Y))
         return 0;
-    if (BN_copy(dest->Z, src->Z) == NULL)
+    if (!BN_copy(dest->Z, src->Z))
         return 0;
     dest->Z_is_one = src->Z_is_one;
     dest->curve_name = src->curve_name;
@@ -295,13 +295,13 @@ int ossl_ec_GF2m_simple_point_set_affine_coordinates(const EC_GROUP *group,
         return 0;
     }
 
-    if (BN_copy(point->X, x) == NULL)
+    if (!BN_copy(point->X, x))
         goto err;
     BN_set_negative(point->X, 0);
-    if (BN_copy(point->Y, y) == NULL)
+    if (!BN_copy(point->Y, y))
         goto err;
     BN_set_negative(point->Y, 0);
-    if (BN_copy(point->Z, BN_value_one()) == NULL)
+    if (!BN_copy(point->Z, BN_value_one()))
         goto err;
     BN_set_negative(point->Z, 0);
     point->Z_is_one = 1;
@@ -332,12 +332,12 @@ int ossl_ec_GF2m_simple_point_get_affine_coordinates(const EC_GROUP *group,
         return 0;
     }
     if (x != NULL) {
-        if (BN_copy(x, point->X) == NULL)
+        if (!BN_copy(x, point->X))
             goto err;
         BN_set_negative(x, 0);
     }
     if (y != NULL) {
-        if (BN_copy(y, point->Y) == NULL)
+        if (!BN_copy(y, point->Y))
             goto err;
         BN_set_negative(y, 0);
     }
@@ -393,18 +393,18 @@ int ossl_ec_GF2m_simple_add(const EC_GROUP *group, EC_POINT *r,
         goto err;
 
     if (a->Z_is_one) {
-        if (BN_copy(x0, a->X) == NULL)
+        if (!BN_copy(x0, a->X))
             goto err;
-        if (BN_copy(y0, a->Y) == NULL)
+        if (!BN_copy(y0, a->Y))
             goto err;
     } else {
         if (!EC_POINT_get_affine_coordinates(group, a, x0, y0, ctx))
             goto err;
     }
     if (b->Z_is_one) {
-        if (BN_copy(x1, b->X) == NULL)
+        if (!BN_copy(x1, b->X))
             goto err;
-        if (BN_copy(y1, b->Y) == NULL)
+        if (!BN_copy(y1, b->Y))
             goto err;
     } else {
         if (!EC_POINT_get_affine_coordinates(group, b, x1, y1, ctx))
@@ -655,9 +655,9 @@ int ossl_ec_GF2m_simple_make_affine(const EC_GROUP *group, EC_POINT *point,
 
     if (!EC_POINT_get_affine_coordinates(group, point, x, y, ctx))
         goto err;
-    if (BN_copy(point->X, x) == NULL)
+    if (!BN_copy(point->X, x))
         goto err;
-    if (BN_copy(point->Y, y) == NULL)
+    if (!BN_copy(point->Y, y))
         goto err;
     if (!BN_one(point->Z))
         goto err;
diff --git a/crypto/ec/ec_ameth.c b/crypto/ec/ec_ameth.c
index a274f720f3..541d9936e5 100644
--- a/crypto/ec/ec_ameth.c
+++ b/crypto/ec/ec_ameth.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -214,7 +214,19 @@ static int ec_bits(const EVP_PKEY *pkey)
 
 static int ec_security_bits(const EVP_PKEY *pkey)
 {
-    return EC_GROUP_security_bits(EC_KEY_get0_group(pkey->pkey.ec));
+    int ecbits = ec_bits(pkey);
+
+    if (ecbits >= 512)
+        return 256;
+    if (ecbits >= 384)
+        return 192;
+    if (ecbits >= 256)
+        return 128;
+    if (ecbits >= 224)
+        return 112;
+    if (ecbits >= 160)
+        return 80;
+    return ecbits / 2;
 }
 
 static int ec_missing_parameters(const EVP_PKEY *pkey)
diff --git a/crypto/ec/ec_asn1.c b/crypto/ec/ec_asn1.c
index 835f759935..79acc6c6ad 100644
--- a/crypto/ec/ec_asn1.c
+++ b/crypto/ec/ec_asn1.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2002-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -105,7 +105,7 @@ ASN1_SEQUENCE(X9_62_PENTANOMIAL) = {
     ASN1_EMBED(X9_62_PENTANOMIAL, k3, INT32)
 } static_ASN1_SEQUENCE_END(X9_62_PENTANOMIAL)
 
-DECLARE_ASN1_ALLOC_FUNCTIONS(X9_62_PENTANOMIAL)
+    DECLARE_ASN1_ALLOC_FUNCTIONS(X9_62_PENTANOMIAL)
 IMPLEMENT_ASN1_ALLOC_FUNCTIONS(X9_62_PENTANOMIAL)
 
 ASN1_ADB_TEMPLATE(char_two_def) = ASN1_SIMPLE(X9_62_CHARACTERISTIC_TWO, p.other, ASN1_ANY);
@@ -122,7 +122,7 @@ ASN1_SEQUENCE(X9_62_CHARACTERISTIC_TWO) = {
     ASN1_ADB_OBJECT(X9_62_CHARACTERISTIC_TWO)
 } static_ASN1_SEQUENCE_END(X9_62_CHARACTERISTIC_TWO)
 
-DECLARE_ASN1_ALLOC_FUNCTIONS(X9_62_CHARACTERISTIC_TWO)
+    DECLARE_ASN1_ALLOC_FUNCTIONS(X9_62_CHARACTERISTIC_TWO)
 IMPLEMENT_ASN1_ALLOC_FUNCTIONS(X9_62_CHARACTERISTIC_TWO)
 
 ASN1_ADB_TEMPLATE(fieldID_def) = ASN1_SIMPLE(X9_62_FIELDID, p.other, ASN1_ANY);
@@ -137,10 +137,10 @@ ASN1_SEQUENCE(X9_62_FIELDID) = {
     ASN1_ADB_OBJECT(X9_62_FIELDID)
 } static_ASN1_SEQUENCE_END(X9_62_FIELDID)
 
-ASN1_SEQUENCE(X9_62_CURVE)
+    ASN1_SEQUENCE(X9_62_CURVE)
     = { ASN1_SIMPLE(X9_62_CURVE, a, ASN1_OCTET_STRING), ASN1_SIMPLE(X9_62_CURVE, b, ASN1_OCTET_STRING), ASN1_OPT(X9_62_CURVE, seed, ASN1_BIT_STRING) } static_ASN1_SEQUENCE_END(X9_62_CURVE)
 
-ASN1_SEQUENCE(ECPARAMETERS)
+        ASN1_SEQUENCE(ECPARAMETERS)
     = { ASN1_EMBED(ECPARAMETERS, version, INT32), ASN1_SIMPLE(ECPARAMETERS, fieldID, X9_62_FIELDID), ASN1_SIMPLE(ECPARAMETERS, curve, X9_62_CURVE), ASN1_SIMPLE(ECPARAMETERS, base, ASN1_OCTET_STRING), ASN1_SIMPLE(ECPARAMETERS, order, ASN1_INTEGER), ASN1_OPT(ECPARAMETERS, cofactor, ASN1_INTEGER) } ASN1_SEQUENCE_END(ECPARAMETERS)
 
 DECLARE_ASN1_ALLOC_FUNCTIONS(ECPARAMETERS)
@@ -163,7 +163,7 @@ ASN1_SEQUENCE(EC_PRIVATEKEY) = {
     ASN1_EXP_OPT(EC_PRIVATEKEY, publicKey, ASN1_BIT_STRING, 1)
 } static_ASN1_SEQUENCE_END(EC_PRIVATEKEY)
 
-DECLARE_ASN1_FUNCTIONS(EC_PRIVATEKEY)
+    DECLARE_ASN1_FUNCTIONS(EC_PRIVATEKEY)
 DECLARE_ASN1_ENCODE_FUNCTIONS_name(EC_PRIVATEKEY, EC_PRIVATEKEY)
 IMPLEMENT_ASN1_FUNCTIONS(EC_PRIVATEKEY)
 
@@ -348,8 +348,9 @@ static int ec_asn1_group2curve(const EC_GROUP *group, X9_62_CURVE *curve)
                 ERR_raise(ERR_LIB_EC, ERR_R_ASN1_LIB);
                 goto err;
             }
-        if (!ASN1_BIT_STRING_set1(curve->seed, group->seed,
-                (int)group->seed_len, 0)) {
+        ossl_asn1_string_set_bits_left(curve->seed, 0);
+        if (!ASN1_BIT_STRING_set(curve->seed, group->seed,
+                (int)group->seed_len)) {
             ERR_raise(ERR_LIB_EC, ERR_R_ASN1_LIB);
             goto err;
         }
@@ -887,14 +888,6 @@ EC_GROUP *d2i_ECPKParameters(EC_GROUP **a, const unsigned char **in, long len)
 
     if (params->type == ECPKPARAMETERS_TYPE_EXPLICIT)
         group->decoded_from_explicit_params = 1;
-#ifdef OPENSSL_NO_EC_EXPLICIT_CURVES
-    if (EC_GROUP_check_named_curve(group, 0, NULL) == NID_undef) {
-        EC_GROUP_free(group);
-        ECPKPARAMETERS_free(params);
-        ERR_raise(ERR_LIB_EC, EC_R_UNKNOWN_GROUP);
-        return NULL;
-    }
-#endif
 
     if (a) {
         EC_GROUP_free(*a);
@@ -955,21 +948,13 @@ EC_KEY *d2i_ECPrivateKey(EC_KEY **a, const unsigned char **in, long len)
         goto err;
     }
 
-#ifdef OPENSSL_NO_EC_EXPLICIT_CURVES
-    if (EC_GROUP_check_named_curve(ret->group, 0, NULL) == NID_undef) {
-        ERR_raise(ERR_LIB_EC, EC_R_UNKNOWN_GROUP);
-        goto err;
-    }
-#endif
-
     ret->version = priv_key->version;
 
     if (priv_key->privateKey) {
         ASN1_OCTET_STRING *pkey = priv_key->privateKey;
-        size_t pkey_len = ASN1_STRING_length_ex(pkey);
-        if (pkey_len > INT_MAX)
-            goto err;
-        if (EC_KEY_oct2priv(ret, ASN1_STRING_get0_data(pkey), (int)pkey_len) == 0)
+        if (EC_KEY_oct2priv(ret, ASN1_STRING_get0_data(pkey),
+                ASN1_STRING_length(pkey))
+            == 0)
             goto err;
     } else {
         ERR_raise(ERR_LIB_EC, EC_R_MISSING_PRIVATE_KEY);
@@ -988,13 +973,11 @@ EC_KEY *d2i_ECPrivateKey(EC_KEY **a, const unsigned char **in, long len)
 
     if (priv_key->publicKey) {
         const unsigned char *pub_oct;
-        size_t pub_oct_len;
+        int pub_oct_len;
 
         pub_oct = ASN1_STRING_get0_data(priv_key->publicKey);
-        pub_oct_len = ASN1_STRING_length_ex(priv_key->publicKey);
-        if (pub_oct_len > INT_MAX)
-            goto err;
-        if (!EC_KEY_oct2key(ret, pub_oct, (int)pub_oct_len, NULL)) {
+        pub_oct_len = ASN1_STRING_length(priv_key->publicKey);
+        if (!EC_KEY_oct2key(ret, pub_oct, pub_oct_len, NULL)) {
             ERR_raise(ERR_LIB_EC, ERR_R_EC_LIB);
             goto err;
         }
@@ -1066,14 +1049,14 @@ int i2d_ECPrivateKey(const EC_KEY *a, unsigned char **out)
             goto err;
         }
 
-        publen = EC_KEY_key2buf(a, EC_KEY_get_conv_form(a), &pub, NULL);
+        publen = EC_KEY_key2buf(a, a->conv_form, &pub, NULL);
 
         if (publen == 0 || publen > INT_MAX) {
             ERR_raise(ERR_LIB_EC, ERR_R_EC_LIB);
             goto err;
         }
 
-        ossl_asn1_bit_string_set_unused_bits(priv_key->publicKey, 0);
+        ossl_asn1_string_set_bits_left(priv_key->publicKey, 0);
         ASN1_STRING_set0(priv_key->publicKey, pub, (int)publen);
         pub = NULL;
     }
@@ -1087,7 +1070,7 @@ err:
     OPENSSL_clear_free(priv, privlen);
     OPENSSL_free(pub);
     EC_PRIVATEKEY_free(priv_key);
-    return ok ? ret : 0;
+    return (ok ? ret : 0);
 }
 
 int i2d_ECParameters(const EC_KEY *a, unsigned char **out)
@@ -1167,7 +1150,7 @@ int i2o_ECPublicKey(const EC_KEY *a, unsigned char **out)
     }
 
     buf_len = EC_POINT_point2oct(a->group, a->pub_key,
-        EC_KEY_get_conv_form(a), NULL, 0, NULL);
+        a->conv_form, NULL, 0, NULL);
 
     if (buf_len > INT_MAX) {
         ERR_raise(ERR_LIB_EC, ERR_R_PASSED_INVALID_ARGUMENT);
@@ -1182,7 +1165,7 @@ int i2o_ECPublicKey(const EC_KEY *a, unsigned char **out)
             return 0;
         new_buffer = 1;
     }
-    if (!EC_POINT_point2oct(a->group, a->pub_key, EC_KEY_get_conv_form(a),
+    if (!EC_POINT_point2oct(a->group, a->pub_key, a->conv_form,
             *out, buf_len, NULL)) {
         ERR_raise(ERR_LIB_EC, ERR_R_EC_LIB);
         if (new_buffer) {
diff --git a/crypto/ec/ec_backend.c b/crypto/ec/ec_backend.c
index 764ab7558b..2062711785 100644
--- a/crypto/ec/ec_backend.c
+++ b/crypto/ec/ec_backend.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -27,8 +27,6 @@
 #include "internal/nelem.h"
 #include "internal/param_build_set.h"
 
-#include 
-
 /* Mapping between a flag and a name */
 static const OSSL_ITEM encoding_nameid_map[] = {
     { OPENSSL_EC_EXPLICIT_CURVE, OSSL_PKEY_EC_ENCODING_EXPLICIT },
@@ -353,9 +351,9 @@ err:
 }
 
 /*
- * The intention with the "backend" source file is to offer backend functions
- * for legacy backends (EVP_PKEY_ASN1_METHOD) and provider implementations
- * alike.
+ * The intention with the "backend" source file is to offer backend support
+ * for legacy backends (EVP_PKEY_ASN1_METHOD and EVP_PKEY_METHOD) and provider
+ * implementations alike.
  */
 int ossl_ec_set_ecdh_cofactor_mode(EC_KEY *ec, int mode)
 {
@@ -485,15 +483,6 @@ int ossl_ec_key_fromdata(EC_KEY *ec, const OSSL_PARAM params[], int include_priv
         && !EC_KEY_set_public_key(ec, pub_point))
         goto err;
 
-    /* Fallback computation of public key if not provided */
-    if (priv_key != NULL && pub_point == NULL) {
-        if ((pub_point = EC_POINT_new(ecg)) == NULL
-            || !EC_KEY_set_public_key(ec, pub_point))
-            goto err;
-        if (!ossl_ec_key_simple_generate_public_key(ec))
-            goto err;
-    }
-
     ok = 1;
 
 err:
@@ -645,7 +634,7 @@ EC_KEY *ossl_ec_key_dup(const EC_KEY *src, int selection)
             /* no parameter-less keys allowed */
             goto err;
         ret->priv_key = BN_new();
-        if (ret->priv_key == NULL || BN_copy(ret->priv_key, src->priv_key) == NULL)
+        if (ret->priv_key == NULL || !BN_copy(ret->priv_key, src->priv_key))
             goto err;
         if (ret->group->meth->keycopy
             && ret->group->meth->keycopy(ret, src) == 0)
@@ -655,6 +644,7 @@ EC_KEY *ossl_ec_key_dup(const EC_KEY *src, int selection)
     /* copy the rest */
     if ((selection & OSSL_KEYMGMT_SELECT_OTHER_PARAMETERS) != 0) {
         ret->enc_flag = src->enc_flag;
+        ret->conv_form = src->conv_form;
     }
 
     ret->version = src->version;
diff --git a/crypto/ec/ec_check.c b/crypto/ec/ec_check.c
index 98cf12f36c..a112960021 100644
--- a/crypto/ec/ec_check.c
+++ b/crypto/ec/ec_check.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2002-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -50,7 +50,7 @@ int EC_GROUP_check(const EC_GROUP *group, BN_CTX *ctx)
      * ECC domain parameter validation.
      * See SP800-56A R3 5.5.2 "Assurances of Domain-Parameter Validity" Part 1b.
      */
-    return EC_GROUP_check_named_curve(group, 1, ctx) > 0 ? 1 : 0;
+    return EC_GROUP_check_named_curve(group, 1, ctx) >= 0 ? 1 : 0;
 #else
     int ret = 0;
     const BIGNUM *order;
diff --git a/crypto/ec/ec_curve.c b/crypto/ec/ec_curve.c
index 0fa1e7a6a6..c6845942c2 100644
--- a/crypto/ec/ec_curve.c
+++ b/crypto/ec/ec_curve.c
@@ -2495,38 +2495,208 @@ static const struct {
     unsigned char data[0 + 32 * 6];
 } _EC_sm2p256v1 = {
     { NID_X9_62_prime_field, 0, 32, 1 },
-    { /* no seed */
+    {
+        /* no seed */
 
         /* p */
-        0xff, 0xff, 0xff, 0xfe, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
-        0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
-        0x00, 0x00, 0x00, 0x00, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
-        0xff, 0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xfe,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0x00,
+        0x00,
+        0x00,
+        0x00,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
         /* a */
-        0xff, 0xff, 0xff, 0xfe, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
-        0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
-        0x00, 0x00, 0x00, 0x00, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
-        0xff, 0xfc,
+        0xff,
+        0xff,
+        0xff,
+        0xfe,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0x00,
+        0x00,
+        0x00,
+        0x00,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xfc,
         /* b */
-        0x28, 0xe9, 0xfa, 0x9e, 0x9d, 0x9f, 0x5e, 0x34, 0x4d, 0x5a,
-        0x9e, 0x4b, 0xcf, 0x65, 0x09, 0xa7, 0xf3, 0x97, 0x89, 0xf5,
-        0x15, 0xab, 0x8f, 0x92, 0xdd, 0xbc, 0xbd, 0x41, 0x4d, 0x94,
-        0x0e, 0x93,
+        0x28,
+        0xe9,
+        0xfa,
+        0x9e,
+        0x9d,
+        0x9f,
+        0x5e,
+        0x34,
+        0x4d,
+        0x5a,
+        0x9e,
+        0x4b,
+        0xcf,
+        0x65,
+        0x09,
+        0xa7,
+        0xf3,
+        0x97,
+        0x89,
+        0xf5,
+        0x15,
+        0xab,
+        0x8f,
+        0x92,
+        0xdd,
+        0xbc,
+        0xbd,
+        0x41,
+        0x4d,
+        0x94,
+        0x0e,
+        0x93,
         /* x */
-        0x32, 0xc4, 0xae, 0x2c, 0x1f, 0x19, 0x81, 0x19, 0x5f, 0x99,
-        0x04, 0x46, 0x6a, 0x39, 0xc9, 0x94, 0x8f, 0xe3, 0x0b, 0xbf,
-        0xf2, 0x66, 0x0b, 0xe1, 0x71, 0x5a, 0x45, 0x89, 0x33, 0x4c,
-        0x74, 0xc7,
+        0x32,
+        0xc4,
+        0xae,
+        0x2c,
+        0x1f,
+        0x19,
+        0x81,
+        0x19,
+        0x5f,
+        0x99,
+        0x04,
+        0x46,
+        0x6a,
+        0x39,
+        0xc9,
+        0x94,
+        0x8f,
+        0xe3,
+        0x0b,
+        0xbf,
+        0xf2,
+        0x66,
+        0x0b,
+        0xe1,
+        0x71,
+        0x5a,
+        0x45,
+        0x89,
+        0x33,
+        0x4c,
+        0x74,
+        0xc7,
         /* y */
-        0xbc, 0x37, 0x36, 0xa2, 0xf4, 0xf6, 0x77, 0x9c, 0x59, 0xbd,
-        0xce, 0xe3, 0x6b, 0x69, 0x21, 0x53, 0xd0, 0xa9, 0x87, 0x7c,
-        0xc6, 0x2a, 0x47, 0x40, 0x02, 0xdf, 0x32, 0xe5, 0x21, 0x39,
-        0xf0, 0xa0,
+        0xbc,
+        0x37,
+        0x36,
+        0xa2,
+        0xf4,
+        0xf6,
+        0x77,
+        0x9c,
+        0x59,
+        0xbd,
+        0xce,
+        0xe3,
+        0x6b,
+        0x69,
+        0x21,
+        0x53,
+        0xd0,
+        0xa9,
+        0x87,
+        0x7c,
+        0xc6,
+        0x2a,
+        0x47,
+        0x40,
+        0x02,
+        0xdf,
+        0x32,
+        0xe5,
+        0x21,
+        0x39,
+        0xf0,
+        0xa0,
         /* order */
-        0xff, 0xff, 0xff, 0xfe, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
-        0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x72, 0x03, 0xdf, 0x6b,
-        0x21, 0xc6, 0x05, 0x2b, 0x53, 0xbb, 0xf4, 0x09, 0x39, 0xd5,
-        0x41, 0x23 }
+        0xff,
+        0xff,
+        0xff,
+        0xfe,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0xff,
+        0x72,
+        0x03,
+        0xdf,
+        0x6b,
+        0x21,
+        0xc6,
+        0x05,
+        0x2b,
+        0x53,
+        0xbb,
+        0xf4,
+        0x09,
+        0x39,
+        0xd5,
+        0x41,
+        0x23,
+    }
 };
 #endif /* OPENSSL_NO_SM2 */
 
diff --git a/crypto/ec/ec_key.c b/crypto/ec/ec_key.c
index 4a84933bb6..a2a4a7401e 100644
--- a/crypto/ec/ec_key.c
+++ b/crypto/ec/ec_key.c
@@ -136,7 +136,7 @@ EC_KEY *EC_KEY_copy(EC_KEY *dest, const EC_KEY *src)
                 if (dest->priv_key == NULL)
                     return NULL;
             }
-            if (BN_copy(dest->priv_key, src->priv_key) == NULL)
+            if (!BN_copy(dest->priv_key, src->priv_key))
                 return NULL;
             if (src->group->meth->keycopy
                 && src->group->meth->keycopy(dest, src) == 0)
@@ -146,6 +146,7 @@ EC_KEY *EC_KEY_copy(EC_KEY *dest, const EC_KEY *src)
 
     /* copy the rest */
     dest->enc_flag = src->enc_flag;
+    dest->conv_form = src->conv_form;
     dest->version = src->version;
     dest->flags = src->flags;
 #ifndef FIPS_MODULE
@@ -175,7 +176,7 @@ int EC_KEY_up_ref(EC_KEY *r)
 {
     int i;
 
-    if (!CRYPTO_UP_REF(&r->references, &i))
+    if (CRYPTO_UP_REF(&r->references, &i) <= 0)
         return 0;
 
     REF_PRINT_COUNT("EC_KEY", i, r);
@@ -213,6 +214,56 @@ int ossl_ec_key_gen(EC_KEY *eckey)
     return ret;
 }
 
+/*
+ * Refer: FIPS 140-3 IG 10.3.A Additional Comment 1
+ * Perform a KAT by duplicating the public key generation.
+ *
+ * NOTE: This issue requires a background understanding, provided in a separate
+ * document; the current IG 10.3.A AC1 is insufficient regarding the PCT for
+ * the key agreement scenario.
+ *
+ * Currently IG 10.3.A requires PCT in the mode of use prior to use of the
+ * key pair, citing the PCT defined in the associated standard. For key
+ * agreement, the only PCT defined in SP 800-56A is that of Section 5.6.2.4:
+ * the comparison of the original public key to a newly calculated public key.
+ */
+static int ecdsa_keygen_knownanswer_test(EC_KEY *eckey, BN_CTX *ctx,
+    OSSL_CALLBACK *cb, void *cbarg)
+{
+    int len, ret = 0;
+    OSSL_SELF_TEST *st = NULL;
+    unsigned char bytes[512] = { 0 };
+    EC_POINT *pub_key2 = NULL;
+
+    st = OSSL_SELF_TEST_new(cb, cbarg);
+    if (st == NULL)
+        return 0;
+
+    OSSL_SELF_TEST_onbegin(st, OSSL_SELF_TEST_TYPE_PCT_KAT,
+        OSSL_SELF_TEST_DESC_PCT_ECDSA);
+
+    if ((pub_key2 = EC_POINT_new(eckey->group)) == NULL)
+        goto err;
+
+    /* pub_key = priv_key * G (where G is a point on the curve) */
+    if (!EC_POINT_mul(eckey->group, pub_key2, eckey->priv_key, NULL, NULL, ctx))
+        goto err;
+
+    if (BN_num_bytes(pub_key2->X) > (int)sizeof(bytes))
+        goto err;
+    len = BN_bn2bin(pub_key2->X, bytes);
+    if (OSSL_SELF_TEST_oncorrupt_byte(st, bytes)
+        && BN_bin2bn(bytes, len, pub_key2->X) == NULL)
+        goto err;
+    ret = !EC_POINT_cmp(eckey->group, eckey->pub_key, pub_key2, ctx);
+
+err:
+    OSSL_SELF_TEST_onend(st, ret);
+    OSSL_SELF_TEST_free(st);
+    EC_POINT_free(pub_key2);
+    return ret;
+}
+
 /*
  * ECC Key generation.
  * See SP800-56AR3 5.6.1.2.2 "Key Pair Generation by Testing Candidates"
@@ -309,11 +360,13 @@ static int ec_generate_key(EC_KEY *eckey, int pairwise_test)
         void *cbarg = NULL;
 
         OSSL_SELF_TEST_get_callback(eckey->libctx, &cb, &cbarg);
-        ok = ecdsa_keygen_pairwise_test(eckey, cb, cbarg);
+        ok = ecdsa_keygen_pairwise_test(eckey, cb, cbarg)
+            && ecdsa_keygen_knownanswer_test(eckey, ctx, cb, cbarg);
     }
 err:
     /* Step (9): If there is an error return an invalid keypair. */
     if (!ok) {
+        ossl_set_error_state(OSSL_SELF_TEST_TYPE_PCT);
         BN_clear(eckey->priv_key);
         if (eckey->pub_key != NULL)
             EC_POINT_set_to_infinity(group, eckey->pub_key);
@@ -831,13 +884,12 @@ void EC_KEY_set_enc_flags(EC_KEY *key, unsigned int flags)
 
 point_conversion_form_t EC_KEY_get_conv_form(const EC_KEY *key)
 {
-    return key->group != NULL
-        ? EC_GROUP_get_point_conversion_form(key->group)
-        : POINT_CONVERSION_UNCOMPRESSED;
+    return key->conv_form;
 }
 
 void EC_KEY_set_conv_form(EC_KEY *key, point_conversion_form_t cform)
 {
+    key->conv_form = cform;
     if (key->group != NULL)
         EC_GROUP_set_point_conversion_form(key->group, cform);
 }
@@ -908,10 +960,8 @@ int EC_KEY_oct2key(EC_KEY *key, const unsigned char *buf, size_t len,
      * EC_POINT_oct2point() has already performed sanity checking of
      * the buffer so we know it is valid.
      */
-    if ((key->group->meth->flags & EC_FLAGS_CUSTOM_CURVE) == 0) {
-        EC_GROUP_set_point_conversion_form(key->group,
-            (point_conversion_form_t)(buf[0] & ~0x01));
-    }
+    if ((key->group->meth->flags & EC_FLAGS_CUSTOM_CURVE) == 0)
+        key->conv_form = (point_conversion_form_t)(buf[0] & ~0x01);
     return 1;
 }
 
diff --git a/crypto/ec/ec_kmeth.c b/crypto/ec/ec_kmeth.c
index b27a40519d..b98bdd578e 100644
--- a/crypto/ec/ec_kmeth.c
+++ b/crypto/ec/ec_kmeth.c
@@ -90,6 +90,7 @@ EC_KEY *ossl_ec_key_new_method_int(OSSL_LIB_CTX *libctx, const char *propq)
 
     ret->meth = EC_KEY_get_default_method();
     ret->version = 1;
+    ret->conv_form = POINT_CONVERSION_UNCOMPRESSED;
 
 /* No ex_data inside the FIPS provider */
 #ifndef FIPS_MODULE
diff --git a/crypto/ec/ec_lib.c b/crypto/ec/ec_lib.c
index 51f0457f65..13dcd29b11 100644
--- a/crypto/ec/ec_lib.c
+++ b/crypto/ec/ec_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2001-2025 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
@@ -175,8 +175,6 @@ int EC_GROUP_copy(EC_GROUP *dest, const EC_GROUP *src)
     dest->libctx = src->libctx;
     dest->curve_name = src->curve_name;
 
-    EC_pre_comp_free(dest);
-
     /* Copy precomputed */
     dest->pre_comp_type = src->pre_comp_type;
     switch (src->pre_comp_type) {
@@ -242,9 +240,9 @@ int EC_GROUP_copy(EC_GROUP *dest, const EC_GROUP *src)
     }
 
     if ((src->meth->flags & EC_FLAGS_CUSTOM_CURVE) == 0) {
-        if (BN_copy(dest->order, src->order) == NULL)
+        if (!BN_copy(dest->order, src->order))
             return 0;
-        if (BN_copy(dest->cofactor, src->cofactor) == NULL)
+        if (!BN_copy(dest->cofactor, src->cofactor))
             return 0;
     }
 
@@ -348,7 +346,7 @@ static int ec_guess_cofactor(EC_GROUP *group)
         if (!BN_set_bit(q, BN_num_bits(group->field) - 1))
             goto err;
     } else {
-        if (BN_copy(q, group->field) == NULL)
+        if (!BN_copy(q, group->field))
             goto err;
     }
 
@@ -411,12 +409,12 @@ int EC_GROUP_set_generator(EC_GROUP *group, const EC_POINT *generator,
     if (!EC_POINT_copy(group->generator, generator))
         return 0;
 
-    if (BN_copy(group->order, order) == NULL)
+    if (!BN_copy(group->order, order))
         return 0;
 
     /* Either take the provided positive cofactor, or try to compute it */
     if (cofactor != NULL && !BN_is_zero(cofactor)) {
-        if (BN_copy(group->cofactor, cofactor) == NULL)
+        if (!BN_copy(group->cofactor, cofactor))
             return 0;
     } else if (!ec_guess_cofactor(group)) {
         BN_zero(group->cofactor);
@@ -451,7 +449,7 @@ int EC_GROUP_get_order(const EC_GROUP *group, BIGNUM *order, BN_CTX *ctx)
 {
     if (group->order == NULL)
         return 0;
-    if (BN_copy(order, group->order) == NULL)
+    if (!BN_copy(order, group->order))
         return 0;
 
     return !BN_is_zero(order);
@@ -467,39 +465,13 @@ int EC_GROUP_order_bits(const EC_GROUP *group)
     return group->meth->group_order_bits(group);
 }
 
-int EC_GROUP_security_bits(const EC_GROUP *group)
-{
-    int ecbits = group->meth->group_order_bits(group);
-
-    /*
-     * The following estimates are based on the values published in Table 2 of
-     * "NIST Special Publication 800-57 Part 1 Revision 4" at
-     * http://dx.doi.org/10.6028/NIST.SP.800-57pt1r4 .
-     *
-     * Note that the above reference explicitly categorizes algorithms in a
-     * discrete set of values {80, 112, 128, 192, 256}, and that it is relevant
-     * only for NIST approved Elliptic Curves, while OpenSSL applies the same
-     * logic also to other curves.
-     */
-    if (ecbits >= 512)
-        return 256;
-    if (ecbits >= 384)
-        return 192;
-    if (ecbits >= 256)
-        return 128;
-    if (ecbits >= 224)
-        return 112;
-    if (ecbits >= 160)
-        return 80;
-    return ecbits / 2;
-}
-
 int EC_GROUP_get_cofactor(const EC_GROUP *group, BIGNUM *cofactor,
     BN_CTX *ctx)
 {
+
     if (group->cofactor == NULL)
         return 0;
-    if (BN_copy(cofactor, group->cofactor) == NULL)
+    if (!BN_copy(cofactor, group->cofactor))
         return 0;
 
     return !BN_is_zero(group->cofactor);
@@ -930,9 +902,6 @@ int EC_POINT_get_affine_coordinates(const EC_GROUP *group,
     const EC_POINT *point, BIGNUM *x, BIGNUM *y,
     BN_CTX *ctx)
 {
-    BN_CTX *new_ctx = NULL;
-    int ret = 0;
-
     if (group->meth->point_get_affine_coordinates == NULL) {
         ERR_raise(ERR_LIB_EC, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
         return 0;
@@ -945,24 +914,7 @@ int EC_POINT_get_affine_coordinates(const EC_GROUP *group,
         ERR_raise(ERR_LIB_EC, EC_R_POINT_AT_INFINITY);
         return 0;
     }
-    if (point->Z_is_one) {
-        if (group->meth->field_decode != NULL) {
-            if (ctx == NULL && (ctx = new_ctx = BN_CTX_new_ex(group->libctx)) == NULL) {
-                ERR_raise(ERR_LIB_EC, ERR_R_INTERNAL_ERROR);
-                return 0;
-            }
-            if ((x != NULL && !group->meth->field_decode(group, x, point->X, ctx))
-                || (y != NULL && !group->meth->field_decode(group, y, point->Y, ctx)))
-                goto err;
-        } else if ((x != NULL && BN_copy(x, point->X) == NULL)
-            || (y != NULL && BN_copy(y, point->Y) == NULL))
-            goto err;
-        ret = 1;
-    } else
-        ret = group->meth->point_get_affine_coordinates(group, point, x, y, ctx);
-err:
-    BN_CTX_free(new_ctx);
-    return ret;
+    return group->meth->point_get_affine_coordinates(group, point, x, y, ctx);
 }
 
 #ifndef OPENSSL_NO_DEPRECATED_3_0
@@ -1599,9 +1551,7 @@ EC_GROUP *EC_GROUP_new_from_params(const OSSL_PARAM params[],
     int is_prime_field = 1;
     BN_CTX *bnctx = NULL;
     const unsigned char *buf = NULL;
-#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES
     int encoding_flag = -1;
-#endif
 #endif
 
     /* This is the simple named group case */
@@ -1731,8 +1681,7 @@ EC_GROUP *EC_GROUP_new_from_params(const OSSL_PARAM params[],
     /* generator base point */
     ptmp = OSSL_PARAM_locate_const(params, OSSL_PKEY_PARAM_EC_GENERATOR);
     if (ptmp == NULL
-        || ptmp->data_type != OSSL_PARAM_OCTET_STRING
-        || ptmp->data_size == 0) {
+        || ptmp->data_type != OSSL_PARAM_OCTET_STRING) {
         ERR_raise(ERR_LIB_EC, EC_R_INVALID_GENERATOR);
         goto err;
     }
@@ -1777,12 +1726,6 @@ EC_GROUP *EC_GROUP_new_from_params(const OSSL_PARAM params[],
         goto err;
     }
     if (named_group == group) {
-#ifdef OPENSSL_NO_EC_EXPLICIT_CURVES
-        if (EC_GROUP_check_named_curve(group, 0, NULL) == NID_undef) {
-            ERR_raise(ERR_LIB_EC, EC_R_UNKNOWN_GROUP);
-            goto err;
-        }
-#else
         /*
          * If we did not find a named group then the encoding should be explicit
          * if it was specified
@@ -1798,7 +1741,6 @@ EC_GROUP *EC_GROUP_new_from_params(const OSSL_PARAM params[],
             goto err;
         }
         EC_GROUP_set_asn1_flag(group, OPENSSL_EC_EXPLICIT_CURVE);
-#endif
     } else {
         EC_GROUP_free(group);
         group = named_group;
diff --git a/crypto/ec/ec_local.h b/crypto/ec/ec_local.h
index 0be3c5529e..c6a5753005 100644
--- a/crypto/ec/ec_local.h
+++ b/crypto/ec/ec_local.h
@@ -8,9 +8,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_EC_EC_LOCAL_H)
-#define OSSL_LIBCRYPTO_EC_EC_LOCAL_H
-
 #include 
 
 #include 
@@ -301,6 +298,7 @@ struct ec_key_st {
     EC_POINT *pub_key;
     BIGNUM *priv_key;
     unsigned int enc_flag;
+    point_conversion_form_t conv_form;
     CRYPTO_REF_COUNT references;
     int flags;
 #ifndef FIPS_MODULE
@@ -796,5 +794,3 @@ static ossl_inline int ec_point_ladder_post(const EC_GROUP *group,
 
     return 1;
 }
-
-#endif /* !defined(OSSL_LIBCRYPTO_EC_EC_LOCAL_H) */
diff --git a/crypto/ec/ec_mult.c b/crypto/ec/ec_mult.c
index f5c6ac7893..4b5e08ecae 100644
--- a/crypto/ec/ec_mult.c
+++ b/crypto/ec/ec_mult.c
@@ -72,8 +72,8 @@ static EC_PRE_COMP *ec_pre_comp_new(const EC_GROUP *group)
 EC_PRE_COMP *EC_ec_pre_comp_dup(EC_PRE_COMP *pre)
 {
     int i;
-    if (pre == NULL || !CRYPTO_UP_REF(&pre->references, &i))
-        return NULL;
+    if (pre != NULL)
+        CRYPTO_UP_REF(&pre->references, &i);
     return pre;
 }
 
@@ -213,7 +213,7 @@ int ossl_ec_scalar_mul_ladder(const EC_GROUP *group, EC_POINT *r,
         goto err;
     }
 
-    if (BN_copy(k, scalar) == NULL) {
+    if (!BN_copy(k, scalar)) {
         ERR_raise(ERR_LIB_EC, ERR_R_BN_LIB);
         goto err;
     }
diff --git a/crypto/ec/ec_pmeth.c b/crypto/ec/ec_pmeth.c
new file mode 100644
index 0000000000..b348832e38
--- /dev/null
+++ b/crypto/ec/ec_pmeth.c
@@ -0,0 +1,504 @@
+/*
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+/*
+ * ECDH and ECDSA low level APIs are deprecated for public use, but still ok
+ * for internal use.
+ */
+#include "internal/deprecated.h"
+
+#include 
+#include "internal/cryptlib.h"
+#include 
+#include 
+#include 
+#include "ec_local.h"
+#include 
+#include "crypto/evp.h"
+
+/* EC pkey context structure */
+
+typedef struct {
+    /* Key and paramgen group */
+    EC_GROUP *gen_group;
+    /* message digest */
+    const EVP_MD *md;
+    /* Duplicate key if custom cofactor needed */
+    EC_KEY *co_key;
+    /* Cofactor mode */
+    signed char cofactor_mode;
+    /* KDF (if any) to use for ECDH */
+    char kdf_type;
+    /* Message digest to use for key derivation */
+    const EVP_MD *kdf_md;
+    /* User key material */
+    unsigned char *kdf_ukm;
+    size_t kdf_ukmlen;
+    /* KDF output length */
+    size_t kdf_outlen;
+} EC_PKEY_CTX;
+
+static int pkey_ec_init(EVP_PKEY_CTX *ctx)
+{
+    EC_PKEY_CTX *dctx;
+
+    if ((dctx = OPENSSL_zalloc(sizeof(*dctx))) == NULL)
+        return 0;
+
+    dctx->cofactor_mode = -1;
+    dctx->kdf_type = EVP_PKEY_ECDH_KDF_NONE;
+    ctx->data = dctx;
+    return 1;
+}
+
+static int pkey_ec_copy(EVP_PKEY_CTX *dst, const EVP_PKEY_CTX *src)
+{
+    EC_PKEY_CTX *dctx, *sctx;
+    if (!pkey_ec_init(dst))
+        return 0;
+    sctx = src->data;
+    dctx = dst->data;
+    if (sctx->gen_group) {
+        dctx->gen_group = EC_GROUP_dup(sctx->gen_group);
+        if (!dctx->gen_group)
+            return 0;
+    }
+    dctx->md = sctx->md;
+
+    if (sctx->co_key) {
+        dctx->co_key = EC_KEY_dup(sctx->co_key);
+        if (!dctx->co_key)
+            return 0;
+    }
+    dctx->kdf_type = sctx->kdf_type;
+    dctx->kdf_md = sctx->kdf_md;
+    dctx->kdf_outlen = sctx->kdf_outlen;
+    if (sctx->kdf_ukm) {
+        dctx->kdf_ukm = OPENSSL_memdup(sctx->kdf_ukm, sctx->kdf_ukmlen);
+        if (!dctx->kdf_ukm)
+            return 0;
+    } else
+        dctx->kdf_ukm = NULL;
+    dctx->kdf_ukmlen = sctx->kdf_ukmlen;
+    return 1;
+}
+
+static void pkey_ec_cleanup(EVP_PKEY_CTX *ctx)
+{
+    EC_PKEY_CTX *dctx = ctx->data;
+    if (dctx != NULL) {
+        EC_GROUP_free(dctx->gen_group);
+        EC_KEY_free(dctx->co_key);
+        OPENSSL_free(dctx->kdf_ukm);
+        OPENSSL_free(dctx);
+        ctx->data = NULL;
+    }
+}
+
+static int pkey_ec_sign(EVP_PKEY_CTX *ctx, unsigned char *sig, size_t *siglen,
+    const unsigned char *tbs, size_t tbslen)
+{
+    int ret, type;
+    unsigned int sltmp;
+    EC_PKEY_CTX *dctx = ctx->data;
+    /*
+     * Discard const. Its marked as const because this may be a cached copy of
+     * the "real" key. These calls don't make any modifications that need to
+     * be reflected back in the "original" key.
+     */
+    EC_KEY *ec = (EC_KEY *)EVP_PKEY_get0_EC_KEY(ctx->pkey);
+    const int sig_sz = ECDSA_size(ec);
+
+    /* ensure cast to size_t is safe */
+    if (!ossl_assert(sig_sz > 0))
+        return 0;
+
+    if (sig == NULL) {
+        *siglen = (size_t)sig_sz;
+        return 1;
+    }
+
+    if (*siglen < (size_t)sig_sz) {
+        ERR_raise(ERR_LIB_EC, EC_R_BUFFER_TOO_SMALL);
+        return 0;
+    }
+
+    type = (dctx->md != NULL) ? EVP_MD_get_type(dctx->md) : NID_sha1;
+
+    ret = ECDSA_sign(type, tbs, (int)tbslen, sig, &sltmp, ec);
+
+    if (ret <= 0)
+        return ret;
+    *siglen = (size_t)sltmp;
+    return 1;
+}
+
+static int pkey_ec_verify(EVP_PKEY_CTX *ctx,
+    const unsigned char *sig, size_t siglen,
+    const unsigned char *tbs, size_t tbslen)
+{
+    int ret, type;
+    EC_PKEY_CTX *dctx = ctx->data;
+    /*
+     * Discard const. Its marked as const because this may be a cached copy of
+     * the "real" key. These calls don't make any modifications that need to
+     * be reflected back in the "original" key.
+     */
+    EC_KEY *ec = (EC_KEY *)EVP_PKEY_get0_EC_KEY(ctx->pkey);
+
+    if (dctx->md)
+        type = EVP_MD_get_type(dctx->md);
+    else
+        type = NID_sha1;
+
+    ret = ECDSA_verify(type, tbs, (int)tbslen, sig, (int)siglen, ec);
+
+    return ret;
+}
+
+#ifndef OPENSSL_NO_EC
+static int pkey_ec_derive(EVP_PKEY_CTX *ctx, unsigned char *key, size_t *keylen)
+{
+    int ret;
+    size_t outlen;
+    const EC_POINT *pubkey = NULL;
+    EC_KEY *eckey;
+    const EC_KEY *eckeypub;
+    EC_PKEY_CTX *dctx = ctx->data;
+
+    if (ctx->pkey == NULL || ctx->peerkey == NULL) {
+        ERR_raise(ERR_LIB_EC, EC_R_KEYS_NOT_SET);
+        return 0;
+    }
+    eckeypub = EVP_PKEY_get0_EC_KEY(ctx->peerkey);
+    if (eckeypub == NULL) {
+        ERR_raise(ERR_LIB_EC, EC_R_KEYS_NOT_SET);
+        return 0;
+    }
+
+    eckey = dctx->co_key ? dctx->co_key
+                         : (EC_KEY *)EVP_PKEY_get0_EC_KEY(ctx->pkey);
+
+    if (!key) {
+        const EC_GROUP *group;
+        group = EC_KEY_get0_group(eckey);
+
+        if (group == NULL)
+            return 0;
+        *keylen = (EC_GROUP_get_degree(group) + 7) / 8;
+        return 1;
+    }
+    pubkey = EC_KEY_get0_public_key(eckeypub);
+
+    /*
+     * NB: unlike PKCS#3 DH, if *outlen is less than maximum size this is not
+     * an error, the result is truncated.
+     */
+
+    outlen = *keylen;
+
+    ret = ECDH_compute_key(key, outlen, pubkey, eckey, 0);
+    if (ret <= 0)
+        return 0;
+    *keylen = ret;
+    return 1;
+}
+
+static int pkey_ec_kdf_derive(EVP_PKEY_CTX *ctx,
+    unsigned char *key, size_t *keylen)
+{
+    EC_PKEY_CTX *dctx = ctx->data;
+    unsigned char *ktmp = NULL;
+    size_t ktmplen;
+    int rv = 0;
+    if (dctx->kdf_type == EVP_PKEY_ECDH_KDF_NONE)
+        return pkey_ec_derive(ctx, key, keylen);
+    if (!key) {
+        *keylen = dctx->kdf_outlen;
+        return 1;
+    }
+    if (*keylen != dctx->kdf_outlen)
+        return 0;
+    if (!pkey_ec_derive(ctx, NULL, &ktmplen))
+        return 0;
+    if ((ktmp = OPENSSL_malloc(ktmplen)) == NULL)
+        return 0;
+    if (!pkey_ec_derive(ctx, ktmp, &ktmplen))
+        goto err;
+    /* Do KDF stuff */
+    if (!ossl_ecdh_kdf_X9_63(key, *keylen, ktmp, ktmplen,
+            dctx->kdf_ukm, dctx->kdf_ukmlen, dctx->kdf_md,
+            ctx->libctx, ctx->propquery))
+        goto err;
+    rv = 1;
+
+err:
+    OPENSSL_clear_free(ktmp, ktmplen);
+    return rv;
+}
+#endif
+
+static int pkey_ec_ctrl(EVP_PKEY_CTX *ctx, int type, int p1, void *p2)
+{
+    EC_PKEY_CTX *dctx = ctx->data;
+    EC_GROUP *group;
+    switch (type) {
+    case EVP_PKEY_CTRL_EC_PARAMGEN_CURVE_NID:
+        group = EC_GROUP_new_by_curve_name(p1);
+        if (group == NULL) {
+            ERR_raise(ERR_LIB_EC, EC_R_INVALID_CURVE);
+            return 0;
+        }
+        EC_GROUP_free(dctx->gen_group);
+        dctx->gen_group = group;
+        return 1;
+
+    case EVP_PKEY_CTRL_EC_PARAM_ENC:
+        if (!dctx->gen_group) {
+            ERR_raise(ERR_LIB_EC, EC_R_NO_PARAMETERS_SET);
+            return 0;
+        }
+        EC_GROUP_set_asn1_flag(dctx->gen_group, p1);
+        return 1;
+
+#ifndef OPENSSL_NO_EC
+    case EVP_PKEY_CTRL_EC_ECDH_COFACTOR:
+        if (p1 == -2) {
+            if (dctx->cofactor_mode != -1)
+                return dctx->cofactor_mode;
+            else {
+                const EC_KEY *ec_key = EVP_PKEY_get0_EC_KEY(ctx->pkey);
+                return EC_KEY_get_flags(ec_key) & EC_FLAG_COFACTOR_ECDH ? 1 : 0;
+            }
+        } else if (p1 < -1 || p1 > 1)
+            return -2;
+        dctx->cofactor_mode = p1;
+        if (p1 != -1) {
+            EC_KEY *ec_key = (EC_KEY *)EVP_PKEY_get0_EC_KEY(ctx->pkey);
+
+            /*
+             * We discarded the "const" above. This will only work if the key is
+             * a "real" legacy key, and not a cached copy of a provided key
+             */
+            if (evp_pkey_is_provided(ctx->pkey)) {
+                ERR_raise(ERR_LIB_EC, ERR_R_UNSUPPORTED);
+                return 0;
+            }
+            if (!ec_key->group)
+                return -2;
+            /* If cofactor is 1 cofactor mode does nothing */
+            if (BN_is_one(ec_key->group->cofactor))
+                return 1;
+            if (!dctx->co_key) {
+                dctx->co_key = EC_KEY_dup(ec_key);
+                if (!dctx->co_key)
+                    return 0;
+            }
+            if (p1)
+                EC_KEY_set_flags(dctx->co_key, EC_FLAG_COFACTOR_ECDH);
+            else
+                EC_KEY_clear_flags(dctx->co_key, EC_FLAG_COFACTOR_ECDH);
+        } else {
+            EC_KEY_free(dctx->co_key);
+            dctx->co_key = NULL;
+        }
+        return 1;
+#endif
+
+    case EVP_PKEY_CTRL_EC_KDF_TYPE:
+        if (p1 == -2)
+            return dctx->kdf_type;
+        if (p1 != EVP_PKEY_ECDH_KDF_NONE && p1 != EVP_PKEY_ECDH_KDF_X9_63)
+            return -2;
+        dctx->kdf_type = p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_EC_KDF_MD:
+        dctx->kdf_md = p2;
+        return 1;
+
+    case EVP_PKEY_CTRL_GET_EC_KDF_MD:
+        *(const EVP_MD **)p2 = dctx->kdf_md;
+        return 1;
+
+    case EVP_PKEY_CTRL_EC_KDF_OUTLEN:
+        if (p1 <= 0)
+            return -2;
+        dctx->kdf_outlen = (size_t)p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_GET_EC_KDF_OUTLEN:
+        *(int *)p2 = (int)dctx->kdf_outlen;
+        return 1;
+
+    case EVP_PKEY_CTRL_EC_KDF_UKM:
+        OPENSSL_free(dctx->kdf_ukm);
+        dctx->kdf_ukm = p2;
+        if (p2)
+            dctx->kdf_ukmlen = p1;
+        else
+            dctx->kdf_ukmlen = 0;
+        return 1;
+
+    case EVP_PKEY_CTRL_GET_EC_KDF_UKM:
+        *(unsigned char **)p2 = dctx->kdf_ukm;
+        return (int)dctx->kdf_ukmlen;
+
+    case EVP_PKEY_CTRL_MD:
+        if (EVP_MD_get_type((const EVP_MD *)p2) != NID_sha1 && EVP_MD_get_type((const EVP_MD *)p2) != NID_ecdsa_with_SHA1 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha224 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha256 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha384 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha512 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha3_224 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha3_256 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha3_384 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sha3_512 && EVP_MD_get_type((const EVP_MD *)p2) != NID_sm3) {
+            ERR_raise(ERR_LIB_EC, EC_R_INVALID_DIGEST_TYPE);
+            return 0;
+        }
+        dctx->md = p2;
+        return 1;
+
+    case EVP_PKEY_CTRL_GET_MD:
+        *(const EVP_MD **)p2 = dctx->md;
+        return 1;
+
+    case EVP_PKEY_CTRL_PEER_KEY:
+        /* Default behaviour is OK */
+    case EVP_PKEY_CTRL_DIGESTINIT:
+    case EVP_PKEY_CTRL_PKCS7_SIGN:
+    case EVP_PKEY_CTRL_CMS_SIGN:
+        return 1;
+
+    default:
+        return -2;
+    }
+}
+
+static int pkey_ec_ctrl_str(EVP_PKEY_CTX *ctx,
+    const char *type, const char *value)
+{
+    if (strcmp(type, "ec_paramgen_curve") == 0) {
+        int nid;
+        nid = EC_curve_nist2nid(value);
+        if (nid == NID_undef)
+            nid = OBJ_sn2nid(value);
+        if (nid == NID_undef)
+            nid = OBJ_ln2nid(value);
+        if (nid == NID_undef) {
+            ERR_raise(ERR_LIB_EC, EC_R_INVALID_CURVE);
+            return 0;
+        }
+        return EVP_PKEY_CTX_set_ec_paramgen_curve_nid(ctx, nid);
+    } else if (strcmp(type, "ec_param_enc") == 0) {
+        int param_enc;
+        if (strcmp(value, "explicit") == 0)
+            param_enc = 0;
+        else if (strcmp(value, "named_curve") == 0)
+            param_enc = OPENSSL_EC_NAMED_CURVE;
+        else
+            return -2;
+        return EVP_PKEY_CTX_set_ec_param_enc(ctx, param_enc);
+    } else if (strcmp(type, "ecdh_kdf_md") == 0) {
+        const EVP_MD *md;
+        if ((md = EVP_get_digestbyname(value)) == NULL) {
+            ERR_raise(ERR_LIB_EC, EC_R_INVALID_DIGEST);
+            return 0;
+        }
+        return EVP_PKEY_CTX_set_ecdh_kdf_md(ctx, md);
+    } else if (strcmp(type, "ecdh_cofactor_mode") == 0) {
+        int co_mode;
+        co_mode = atoi(value);
+        return EVP_PKEY_CTX_set_ecdh_cofactor_mode(ctx, co_mode);
+    }
+
+    return -2;
+}
+
+static int pkey_ec_paramgen(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
+{
+    EC_KEY *ec = NULL;
+    EC_PKEY_CTX *dctx = ctx->data;
+    int ret;
+
+    if (dctx->gen_group == NULL) {
+        ERR_raise(ERR_LIB_EC, EC_R_NO_PARAMETERS_SET);
+        return 0;
+    }
+    ec = EC_KEY_new();
+    if (ec == NULL)
+        return 0;
+    if (!(ret = EC_KEY_set_group(ec, dctx->gen_group))
+        || !ossl_assert(ret = EVP_PKEY_assign_EC_KEY(pkey, ec)))
+        EC_KEY_free(ec);
+    return ret;
+}
+
+static int pkey_ec_keygen(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
+{
+    EC_KEY *ec = NULL;
+    EC_PKEY_CTX *dctx = ctx->data;
+    int ret;
+
+    if (ctx->pkey == NULL && dctx->gen_group == NULL) {
+        ERR_raise(ERR_LIB_EC, EC_R_NO_PARAMETERS_SET);
+        return 0;
+    }
+    ec = EC_KEY_new();
+    if (ec == NULL)
+        return 0;
+    if (!ossl_assert(EVP_PKEY_assign_EC_KEY(pkey, ec))) {
+        EC_KEY_free(ec);
+        return 0;
+    }
+    /* Note: if error is returned, we count on caller to free pkey->pkey.ec */
+    if (ctx->pkey != NULL)
+        ret = EVP_PKEY_copy_parameters(pkey, ctx->pkey);
+    else
+        ret = EC_KEY_set_group(ec, dctx->gen_group);
+
+    return ret ? EC_KEY_generate_key(ec) : 0;
+}
+
+static const EVP_PKEY_METHOD ec_pkey_meth = {
+    EVP_PKEY_EC,
+    0,
+    pkey_ec_init,
+    pkey_ec_copy,
+    pkey_ec_cleanup,
+
+    0,
+    pkey_ec_paramgen,
+
+    0,
+    pkey_ec_keygen,
+
+    0,
+    pkey_ec_sign,
+
+    0,
+    pkey_ec_verify,
+
+    0, 0,
+
+    0, 0, 0, 0,
+
+    0,
+    0,
+
+    0,
+    0,
+
+    0,
+#ifndef OPENSSL_NO_EC
+    pkey_ec_kdf_derive,
+#else
+    0,
+#endif
+    pkey_ec_ctrl,
+    pkey_ec_ctrl_str
+};
+
+const EVP_PKEY_METHOD *ossl_ec_pkey_method(void)
+{
+    return &ec_pkey_meth;
+}
diff --git a/crypto/ec/ecp_mont.c b/crypto/ec/ecp_mont.c
index 5c289c10be..2ed4a6d6c4 100644
--- a/crypto/ec/ecp_mont.c
+++ b/crypto/ec/ecp_mont.c
@@ -294,7 +294,7 @@ int ossl_ec_GFp_mont_field_set_to_one(const EC_GROUP *group, BIGNUM *r,
         return 0;
     }
 
-    if (BN_copy(r, group->field_data2) == NULL)
+    if (!BN_copy(r, group->field_data2))
         return 0;
     return 1;
 }
diff --git a/crypto/ec/ecp_nistp224.c b/crypto/ec/ecp_nistp224.c
index 1a0952083c..449417414a 100644
--- a/crypto/ec/ecp_nistp224.c
+++ b/crypto/ec/ecp_nistp224.c
@@ -49,6 +49,9 @@
 #error "Your compiler doesn't appear to support 128-bit integer types"
 #endif
 
+typedef uint8_t u8;
+typedef uint64_t u64;
+
 /******************************************************************************/
 /*-
  * INTERNAL REPRESENTATION OF FIELD ELEMENTS
@@ -81,7 +84,7 @@ typedef widelimb widefelem[7];
  * group order size for the elliptic curve, and we also use this type for
  * scalars for point multiplication.
  */
-typedef uint8_t felem_bytearray[28];
+typedef u8 felem_bytearray[28];
 
 static const felem_bytearray nistp224_curve_params[5] = {
     { 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, /* p */
@@ -304,7 +307,7 @@ const EC_METHOD *EC_GFp_nistp224_method(void)
 /*
  * Helper functions to convert field elements to/from internal representation
  */
-static void bin28_to_felem(felem out, const uint8_t in[28])
+static void bin28_to_felem(felem out, const u8 in[28])
 {
     out[0] = *((const limb *)(in)) & 0x00ffffffffffffff;
     out[1] = (*((const limb_aX *)(in + 7))) & 0x00ffffffffffffff;
@@ -312,7 +315,7 @@ static void bin28_to_felem(felem out, const uint8_t in[28])
     out[3] = (*((const limb_aX *)(in + 20))) >> 8;
 }
 
-static void felem_to_bin28(uint8_t out[28], const felem in)
+static void felem_to_bin28(u8 out[28], const felem in)
 {
     unsigned i;
     for (i = 0; i < 7; ++i) {
@@ -1084,7 +1087,7 @@ static void point_add(felem x3, felem y3, felem z3,
  * copies it to out.
  * The pre_comp array argument should be size of |size| argument
  */
-static void select_point(const uint64_t idx, unsigned int size,
+static void select_point(const u64 idx, unsigned int size,
     const felem pre_comp[][3], felem out[3])
 {
     unsigned i, j;
@@ -1093,7 +1096,7 @@ static void select_point(const uint64_t idx, unsigned int size,
     memset(out, 0, sizeof(*out) * 3);
     for (i = 0; i < size; i++) {
         const limb *inlimbs = &pre_comp[i][0][0];
-        uint64_t mask = i ^ idx;
+        u64 mask = i ^ idx;
         mask |= mask >> 4;
         mask |= mask >> 2;
         mask |= mask >> 1;
@@ -1121,7 +1124,7 @@ static char get_bit(const felem_bytearray in, unsigned i)
  */
 static void batch_mul(felem x_out, felem y_out, felem z_out,
     const felem_bytearray scalars[],
-    const unsigned num_points, const uint8_t *g_scalar,
+    const unsigned num_points, const u8 *g_scalar,
     const int mixed, const felem pre_comp[][17][3],
     const felem g_pre_comp[2][16][3])
 {
@@ -1129,8 +1132,8 @@ static void batch_mul(felem x_out, felem y_out, felem z_out,
     unsigned num;
     unsigned gen_mul = (g_scalar != NULL);
     felem nq[3], tmp[4];
-    uint64_t bits;
-    uint8_t sign, digit;
+    u64 bits;
+    u8 sign, digit;
 
     /* set nq to the point at infinity */
     memset(nq, 0, sizeof(nq));
@@ -1234,8 +1237,8 @@ static NISTP224_PRE_COMP *nistp224_pre_comp_new(void)
 NISTP224_PRE_COMP *EC_nistp224_pre_comp_dup(NISTP224_PRE_COMP *p)
 {
     int i;
-    if (p == NULL || !CRYPTO_UP_REF(&p->references, &i))
-        return NULL;
+    if (p != NULL)
+        CRYPTO_UP_REF(&p->references, &i);
     return p;
 }
 
diff --git a/crypto/ec/ecp_nistp256.c b/crypto/ec/ecp_nistp256.c
index fba197a8c7..136406bbc7 100644
--- a/crypto/ec/ecp_nistp256.c
+++ b/crypto/ec/ecp_nistp256.c
@@ -50,13 +50,17 @@
 #error "Your compiler doesn't appear to support 128-bit integer types"
 #endif
 
+typedef uint8_t u8;
+typedef uint32_t u32;
+typedef uint64_t u64;
+
 /*
  * The underlying field. P256 operates over GF(2^256-2^224+2^192+2^96-1). We
  * can serialize an element of this field into 32 bytes. We call this an
  * felem_bytearray.
  */
 
-typedef uint8_t felem_bytearray[32];
+typedef u8 felem_bytearray[32];
 
 /*
  * These are the parameters of P256, taken from FIPS 186-3, page 86. These
@@ -111,36 +115,36 @@ static const felem_bytearray nistp256_curve_params[5] = {
 typedef uint128_t limb;
 typedef limb felem[NLIMBS];
 typedef limb longfelem[NLIMBS * 2];
-typedef uint64_t smallfelem[NLIMBS];
+typedef u64 smallfelem[NLIMBS];
 
 /* This is the value of the prime as four 64-bit words, little-endian. */
-static const uint64_t kPrime[4] = {
+static const u64 kPrime[4] = {
     0xfffffffffffffffful, 0xffffffff, 0, 0xffffffff00000001ul
 };
-static const uint64_t bottom63bits = 0x7ffffffffffffffful;
+static const u64 bottom63bits = 0x7ffffffffffffffful;
 
 /*
  * bin32_to_felem takes a little-endian byte array and converts it into felem
  * form. This assumes that the CPU is little-endian.
  */
-static void bin32_to_felem(felem out, const uint8_t in[32])
+static void bin32_to_felem(felem out, const u8 in[32])
 {
-    out[0] = *((uint64_t *)&in[0]);
-    out[1] = *((uint64_t *)&in[8]);
-    out[2] = *((uint64_t *)&in[16]);
-    out[3] = *((uint64_t *)&in[24]);
+    out[0] = *((u64 *)&in[0]);
+    out[1] = *((u64 *)&in[8]);
+    out[2] = *((u64 *)&in[16]);
+    out[3] = *((u64 *)&in[24]);
 }
 
 /*
  * smallfelem_to_bin32 takes a smallfelem and serializes into a little
  * endian, 32 byte array. This assumes that the CPU is little-endian.
  */
-static void smallfelem_to_bin32(uint8_t out[32], const smallfelem in)
+static void smallfelem_to_bin32(u8 out[32], const smallfelem in)
 {
-    *((uint64_t *)&out[0]) = in[0];
-    *((uint64_t *)&out[8]) = in[1];
-    *((uint64_t *)&out[16]) = in[2];
-    *((uint64_t *)&out[24]) = in[3];
+    *((u64 *)&out[0]) = in[0];
+    *((u64 *)&out[8]) = in[1];
+    *((u64 *)&out[16]) = in[2];
+    *((u64 *)&out[24]) = in[3];
 }
 
 /* BN_to_felem converts an OpenSSL BIGNUM into an felem */
@@ -218,7 +222,7 @@ static void felem_small_sum(felem out, const smallfelem in)
 }
 
 /* felem_scalar sets out = out * scalar */
-static void felem_scalar(felem out, const uint64_t scalar)
+static void felem_scalar(felem out, const u64 scalar)
 {
     out[0] *= scalar;
     out[1] *= scalar;
@@ -227,7 +231,7 @@ static void felem_scalar(felem out, const uint64_t scalar)
 }
 
 /* longfelem_scalar sets out = out * scalar */
-static void longfelem_scalar(longfelem out, const uint64_t scalar)
+static void longfelem_scalar(longfelem out, const u64 scalar)
 {
     out[0] *= scalar;
     out[1] *= scalar;
@@ -372,15 +376,15 @@ static const felem zero110 = { two64m0, two110p32m0, two64m46, two64m32 };
 static void felem_shrink(smallfelem out, const felem in)
 {
     felem tmp;
-    uint64_t a, b, mask;
-    uint64_t high, low;
-    static const uint64_t kPrime3Test = 0x7fffffff00000001ul; /* 2^63 - 2^32 + 1 */
+    u64 a, b, mask;
+    u64 high, low;
+    static const u64 kPrime3Test = 0x7fffffff00000001ul; /* 2^63 - 2^32 + 1 */
 
     /* Carry 2->3 */
-    tmp[3] = zero110[3] + in[3] + ((uint64_t)(in[2] >> 64));
+    tmp[3] = zero110[3] + in[3] + ((u64)(in[2] >> 64));
     /* tmp[3] < 2^110 */
 
-    tmp[2] = zero110[2] + (uint64_t)in[2];
+    tmp[2] = zero110[2] + (u64)in[2];
     tmp[0] = zero110[0] + in[0];
     tmp[1] = zero110[1] + in[1];
     /* tmp[0] < 2**110, tmp[1] < 2^111, tmp[2] < 2**65 */
@@ -390,7 +394,7 @@ static void felem_shrink(smallfelem out, const felem in)
      * tmp[3]. We don't update the other words till the end.
      */
     a = tmp[3] >> 64; /* a < 2^46 */
-    tmp[3] = (uint64_t)tmp[3];
+    tmp[3] = (u64)tmp[3];
     tmp[3] -= a;
     tmp[3] += ((limb)a) << 32;
     /* tmp[3] < 2^79 */
@@ -398,7 +402,7 @@ static void felem_shrink(smallfelem out, const felem in)
     b = a;
     a = tmp[3] >> 64; /* a < 2^15 */
     b += a; /* b < 2^46 + 2^15 < 2^47 */
-    tmp[3] = (uint64_t)tmp[3];
+    tmp[3] = (u64)tmp[3];
     tmp[3] -= a;
     tmp[3] += ((limb)a) << 32;
     /* tmp[3] < 2^64 + 2^47 */
@@ -414,7 +418,7 @@ static void felem_shrink(smallfelem out, const felem in)
      * In order to make space in tmp[3] for the carry from 2 -> 3, we
      * conditionally subtract kPrime if tmp[3] is large enough.
      */
-    high = (uint64_t)(tmp[3] >> 64);
+    high = (u64)(tmp[3] >> 64);
     /* As tmp[3] < 2^65, high is either 1 or 0 */
     high = 0 - high;
     /*-
@@ -422,7 +426,7 @@ static void felem_shrink(smallfelem out, const felem in)
      *   all ones   if the high word of tmp[3] is 1
      *   all zeros  if the high word of tmp[3] if 0
      */
-    low = (uint64_t)tmp[3];
+    low = (u64)tmp[3];
     mask = 0 - (low >> 63);
     /*-
      * mask is:
@@ -446,12 +450,12 @@ static void felem_shrink(smallfelem out, const felem in)
     tmp[3] -= mask & kPrime[3];
     /* tmp[3] < 2**64 - 2**32 + 1 */
 
-    tmp[1] += ((uint64_t)(tmp[0] >> 64));
-    tmp[0] = (uint64_t)tmp[0];
-    tmp[2] += ((uint64_t)(tmp[1] >> 64));
-    tmp[1] = (uint64_t)tmp[1];
-    tmp[3] += ((uint64_t)(tmp[2] >> 64));
-    tmp[2] = (uint64_t)tmp[2];
+    tmp[1] += ((u64)(tmp[0] >> 64));
+    tmp[0] = (u64)tmp[0];
+    tmp[2] += ((u64)(tmp[1] >> 64));
+    tmp[1] = (u64)tmp[1];
+    tmp[3] += ((u64)(tmp[2] >> 64));
+    tmp[2] = (u64)tmp[2];
     /* tmp[i] < 2^64 */
 
     out[0] = tmp[0];
@@ -479,7 +483,7 @@ static void smallfelem_expand(felem out, const smallfelem in)
 static void smallfelem_square(longfelem out, const smallfelem small)
 {
     limb a;
-    uint64_t high, low;
+    u64 high, low;
 
     a = ((uint128_t)small[0]) * small[0];
     low = a;
@@ -557,7 +561,7 @@ static void smallfelem_square(longfelem out, const smallfelem small)
  */
 static void felem_square(longfelem out, const felem in)
 {
-    uint64_t small[4];
+    u64 small[4];
     felem_shrink(small, in);
     smallfelem_square(out, small);
 }
@@ -574,7 +578,7 @@ static void smallfelem_mul(longfelem out, const smallfelem small1,
     const smallfelem small2)
 {
     limb a;
-    uint64_t high, low;
+    u64 high, low;
 
     a = ((uint128_t)small1[0]) * small2[0];
     low = a;
@@ -823,12 +827,12 @@ static void felem_reduce_zero105(felem out, const longfelem in)
  * subtract_u64 sets *result = *result - v and *carry to one if the
  * subtraction underflowed.
  */
-static void subtract_u64(uint64_t *result, uint64_t *carry, uint64_t v)
+static void subtract_u64(u64 *result, u64 *carry, u64 v)
 {
     uint128_t r = *result;
     r -= v;
     *carry = (r >> 64) & 1;
-    *result = (uint64_t)r;
+    *result = (u64)r;
 }
 
 /*
@@ -838,7 +842,7 @@ static void subtract_u64(uint64_t *result, uint64_t *carry, uint64_t v)
 static void felem_contract(smallfelem out, const felem in)
 {
     unsigned i;
-    uint64_t all_equal_so_far = 0, result = 0, carry;
+    u64 all_equal_so_far = 0, result = 0, carry;
 
     felem_shrink(out, in);
     /* small is minimal except that the value might be > p */
@@ -846,18 +850,18 @@ static void felem_contract(smallfelem out, const felem in)
     all_equal_so_far--;
     /*
      * We are doing a constant time test if out >= kPrime. We need to compare
-     * each uint64_t, from most-significant to least significant. For each one, if
+     * each u64, from most-significant to least significant. For each one, if
      * all words so far have been equal (m is all ones) then a non-equal
      * result is the answer. Otherwise we continue.
      */
     for (i = 3; i < 4; i--) {
-        uint64_t equal;
+        u64 equal;
         uint128_t a = ((uint128_t)kPrime[i]) - out[i];
         /*
          * if out[i] > kPrime[i] then a will underflow and the high 64-bits
          * will all be set.
          */
-        result |= all_equal_so_far & ((uint64_t)(a >> 64));
+        result |= all_equal_so_far & ((u64)(a >> 64));
 
         /*
          * if kPrime[i] == out[i] then |equal| will be all zeros and the
@@ -928,9 +932,9 @@ static void smallfelem_mul_contract(smallfelem out, const smallfelem in1,
 static limb smallfelem_is_zero(const smallfelem small)
 {
     limb result;
-    uint64_t is_p;
+    u64 is_p;
 
-    uint64_t is_zero = small[0] | small[1] | small[2] | small[3];
+    u64 is_zero = small[0] | small[1] | small[2] | small[3];
     is_zero--;
     is_zero &= is_zero << 32;
     is_zero &= is_zero << 16;
@@ -1205,7 +1209,7 @@ static void copy_conditional(felem out, const felem in, limb mask)
 static void copy_small_conditional(felem out, const smallfelem in, limb mask)
 {
     unsigned i;
-    const uint64_t mask64 = mask;
+    const u64 mask64 = mask;
     for (i = 0; i < NLIMBS; ++i) {
         out[i] = ((limb)(in[i] & mask64)) | (out[i] & ~mask);
     }
@@ -1624,17 +1628,17 @@ static const smallfelem gmul[2][16][3] = {
  * select_point selects the |idx|th point from a precomputation table and
  * copies it to out.
  */
-static void select_point(const uint64_t idx, unsigned int size,
+static void select_point(const u64 idx, unsigned int size,
     const smallfelem pre_comp[16][3], smallfelem out[3])
 {
     unsigned i, j;
-    uint64_t *outlimbs = &out[0][0];
+    u64 *outlimbs = &out[0][0];
 
     memset(out, 0, sizeof(*out) * 3);
 
     for (i = 0; i < size; i++) {
-        const uint64_t *inlimbs = (uint64_t *)&pre_comp[i][0][0];
-        uint64_t mask = i ^ idx;
+        const u64 *inlimbs = (u64 *)&pre_comp[i][0][0];
+        u64 mask = i ^ idx;
         mask |= mask >> 4;
         mask |= mask >> 2;
         mask |= mask >> 1;
@@ -1662,7 +1666,7 @@ static char get_bit(const felem_bytearray in, int i)
  */
 static void batch_mul(felem x_out, felem y_out, felem z_out,
     const felem_bytearray scalars[],
-    const unsigned num_points, const uint8_t *g_scalar,
+    const unsigned num_points, const u8 *g_scalar,
     const int mixed, const smallfelem pre_comp[][17][3],
     const smallfelem g_pre_comp[2][16][3])
 {
@@ -1670,8 +1674,8 @@ static void batch_mul(felem x_out, felem y_out, felem z_out,
     unsigned num, gen_mul = (g_scalar != NULL);
     felem nq[3], ftmp;
     smallfelem tmp[3];
-    uint64_t bits;
-    uint8_t sign, digit;
+    u64 bits;
+    u8 sign, digit;
 
     /* set nq to the point at infinity */
     memset(nq, 0, sizeof(nq));
@@ -1852,8 +1856,8 @@ static NISTP256_PRE_COMP *nistp256_pre_comp_new(void)
 NISTP256_PRE_COMP *EC_nistp256_pre_comp_dup(NISTP256_PRE_COMP *p)
 {
     int i;
-    if (p == NULL || !CRYPTO_UP_REF(&p->references, &i))
-        return NULL;
+    if (p != NULL)
+        CRYPTO_UP_REF(&p->references, &i);
     return p;
 }
 
diff --git a/crypto/ec/ecp_nistp384.c b/crypto/ec/ecp_nistp384.c
index 3d212dcc15..ce42edad05 100644
--- a/crypto/ec/ecp_nistp384.c
+++ b/crypto/ec/ecp_nistp384.c
@@ -41,13 +41,16 @@
 #error "Your compiler doesn't appear to support 128-bit integer types"
 #endif
 
+typedef uint8_t u8;
+typedef uint64_t u64;
+
 /*
  * The underlying field. P384 operates over GF(2^384-2^128-2^96+2^32-1). We
  * can serialize an element of this field into 48 bytes. We call this an
  * felem_bytearray.
  */
 
-typedef uint8_t felem_bytearray[48];
+typedef u8 felem_bytearray[48];
 
 /*
  * These are the parameters of P384, taken from FIPS 186-3, section D.1.2.4.
@@ -110,7 +113,7 @@ typedef widelimb widefelem[2 * NLIMBS - 1];
 static const limb bottom56bits = 0xffffffffffffff;
 
 /* Helper functions (de)serialising reduced field elements in little endian */
-static void bin48_to_felem(felem out, const uint8_t in[48])
+static void bin48_to_felem(felem out, const u8 in[48])
 {
     memset(out, 0, 56);
     out[0] = (*((limb *)&in[0])) & bottom56bits;
@@ -122,7 +125,7 @@ static void bin48_to_felem(felem out, const uint8_t in[48])
     memmove(&out[6], &in[42], 6);
 }
 
-static void felem_to_bin48(uint8_t out[48], const felem in)
+static void felem_to_bin48(u8 out[48], const felem in)
 {
     memset(out, 0, 48);
     (*((limb *)&out[0])) |= (in[0] & bottom56bits);
@@ -717,7 +720,7 @@ void p384_felem_square_reduce(felem out, const felem in);
 void p384_felem_mul_reduce(felem out, const felem in1, const felem in2);
 
 #if defined(_ARCH_PPC64)
-#include "arch/ppc_arch.h"
+#include "crypto/ppc_arch.h"
 #endif
 
 static void felem_select(void)
@@ -1401,7 +1404,7 @@ static char get_bit(const felem_bytearray in, int i)
  */
 static void batch_mul(felem x_out, felem y_out, felem z_out,
     const felem_bytearray scalars[],
-    const unsigned int num_points, const uint8_t *g_scalar,
+    const unsigned int num_points, const u8 *g_scalar,
     const int mixed, const felem pre_comp[][17][3],
     const felem g_pre_comp[16][3])
 {
@@ -1409,7 +1412,7 @@ static void batch_mul(felem x_out, felem y_out, felem z_out,
     unsigned int num, gen_mul = (g_scalar != NULL);
     felem nq[3], tmp[4];
     limb bits;
-    uint8_t sign, digit;
+    u8 sign, digit;
 
     /* set nq to the point at infinity */
     memset(nq, 0, sizeof(nq));
@@ -1576,8 +1579,8 @@ NISTP384_PRE_COMP *ossl_ec_nistp384_pre_comp_dup(NISTP384_PRE_COMP *p)
 {
     int i;
 
-    if (p == NULL || !CRYPTO_UP_REF(&p->references, &i))
-        return NULL;
+    if (p != NULL)
+        CRYPTO_UP_REF(&p->references, &i);
     return p;
 }
 
diff --git a/crypto/ec/ecp_nistp521.c b/crypto/ec/ecp_nistp521.c
index f7315f136c..3c088d9a5f 100644
--- a/crypto/ec/ecp_nistp521.c
+++ b/crypto/ec/ecp_nistp521.c
@@ -49,13 +49,16 @@
 #error "Your compiler doesn't appear to support 128-bit integer types"
 #endif
 
+typedef uint8_t u8;
+typedef uint64_t u64;
+
 /*
  * The underlying field. P521 operates over GF(2^521-1). We can serialize an
  * element of this field into 66 bytes where the most significant byte
  * contains only a single bit. We call this an felem_bytearray.
  */
 
-typedef uint8_t felem_bytearray[66];
+typedef u8 felem_bytearray[66];
 
 /*
  * These are the parameters of P521, taken from FIPS 186-3, section D.1.2.5.
@@ -137,7 +140,7 @@ static const limb bottom58bits = 0x3ffffffffffffff;
  * bin66_to_felem takes a little-endian byte array and converts it into felem
  * form. This assumes that the CPU is little-endian.
  */
-static void bin66_to_felem(felem out, const uint8_t in[66])
+static void bin66_to_felem(felem out, const u8 in[66])
 {
     out[0] = (*((limb *)&in[0])) & bottom58bits;
     out[1] = (*((limb_aX *)&in[7]) >> 2) & bottom58bits;
@@ -154,7 +157,7 @@ static void bin66_to_felem(felem out, const uint8_t in[66])
  * felem_to_bin66 takes an felem and serializes into a little endian, 66 byte
  * array. This assumes that the CPU is little-endian.
  */
-static void felem_to_bin66(uint8_t out[66], const felem in)
+static void felem_to_bin66(u8 out[66], const felem in)
 {
     memset(out, 0, 66);
     (*((limb *)&out[0])) = in[0];
@@ -518,7 +521,7 @@ static const limb bottom52bits = 0xfffffffffffff;
  */
 static void felem_reduce(felem out, const largefelem in)
 {
-    uint64_t overflow1, overflow2;
+    u64 overflow1, overflow2;
 
     out[0] = ((limb)in[0]) & bottom58bits;
     out[1] = ((limb)in[1]) & bottom58bits;
@@ -602,7 +605,7 @@ void p521_felem_square(largefelem out, const felem in);
 void p521_felem_mul(largefelem out, const felem in1, const felem in2);
 
 #if defined(_ARCH_PPC64)
-#include "arch/ppc_arch.h"
+#include "crypto/ppc_arch.h"
 #endif
 
 static void felem_select(void)
@@ -1494,7 +1497,7 @@ static char get_bit(const felem_bytearray in, int i)
  */
 static void batch_mul(felem x_out, felem y_out, felem z_out,
     const felem_bytearray scalars[],
-    const unsigned num_points, const uint8_t *g_scalar,
+    const unsigned num_points, const u8 *g_scalar,
     const int mixed, const felem pre_comp[][17][3],
     const felem g_pre_comp[16][3])
 {
@@ -1502,7 +1505,7 @@ static void batch_mul(felem x_out, felem y_out, felem z_out,
     unsigned num, gen_mul = (g_scalar != NULL);
     felem nq[3], tmp[4];
     limb bits;
-    uint8_t sign, digit;
+    u8 sign, digit;
 
     /* set nq to the point at infinity */
     memset(nq, 0, sizeof(nq));
@@ -1667,8 +1670,8 @@ static NISTP521_PRE_COMP *nistp521_pre_comp_new(void)
 NISTP521_PRE_COMP *EC_nistp521_pre_comp_dup(NISTP521_PRE_COMP *p)
 {
     int i;
-    if (p == NULL || !CRYPTO_UP_REF(&p->references, &i))
-        return NULL;
+    if (p != NULL)
+        CRYPTO_UP_REF(&p->references, &i);
     return p;
 }
 
diff --git a/crypto/ec/ecp_nistz256.c b/crypto/ec/ecp_nistz256.c
index df467b948f..9a2e864d22 100644
--- a/crypto/ec/ecp_nistz256.c
+++ b/crypto/ec/ecp_nistz256.c
@@ -39,6 +39,8 @@
 
 #define P256_LIMBS (256 / BN_BITS2)
 
+typedef unsigned short u16;
+
 typedef struct {
     BN_ULONG X[P256_LIMBS];
     BN_ULONG Y[P256_LIMBS];
@@ -1208,8 +1210,8 @@ static NISTZ256_PRE_COMP *ecp_nistz256_pre_comp_new(const EC_GROUP *group)
 NISTZ256_PRE_COMP *EC_nistz256_pre_comp_dup(NISTZ256_PRE_COMP *p)
 {
     int i;
-    if (p == NULL || !CRYPTO_UP_REF(&p->references, &i))
-        return NULL;
+    if (p != NULL)
+        CRYPTO_UP_REF(&p->references, &i);
     return p;
 }
 
@@ -1531,7 +1533,7 @@ static int ecp_nistz256group_full_init(EC_GROUP *group,
     }
     if (!EC_POINT_copy(group->generator, P))
         goto err;
-    if (BN_copy(group->order, order) == NULL)
+    if (!BN_copy(group->order, order))
         goto err;
     if (!BN_set_word(group->cofactor, 1))
         goto err;
diff --git a/crypto/ec/ecp_ppc.c b/crypto/ec/ecp_ppc.c
index 5fd27654fd..e038a07475 100644
--- a/crypto/ec/ecp_ppc.c
+++ b/crypto/ec/ecp_ppc.c
@@ -8,7 +8,7 @@
  */
 
 #include "internal/cryptlib.h"
-#include "arch/ppc_arch.h"
+#include "crypto/ppc_arch.h"
 #include "ec_local.h"
 
 void ecp_nistz256_mul_mont(unsigned long res[4], const unsigned long a[4],
diff --git a/crypto/ec/ecp_s390x_nistp.c b/crypto/ec/ecp_s390x_nistp.c
index c05f21c732..30754d4e75 100644
--- a/crypto/ec/ecp_s390x_nistp.c
+++ b/crypto/ec/ecp_s390x_nistp.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -18,7 +18,7 @@
 #include 
 #include 
 #include "ec_local.h"
-#include "arch/s390x_arch.h"
+#include "s390x_arch.h"
 
 /* Size of parameter blocks */
 #define S390X_SIZE_PARAM 4096
@@ -98,7 +98,9 @@ static int ec_GFp_s390x_nistp_mul(const EC_GROUP *group, EC_POINT *r,
 
         memset(¶m, 0, sizeof(param));
 
-        if (EC_POINT_get_affine_coordinates(group, point_ptr, x, y, ctx) != 1
+        if (group->meth->point_get_affine_coordinates(group, point_ptr,
+                x, y, ctx)
+                != 1
             || BN_bn2binpad(x, param + S390X_OFF_SRC_X(len), len) == -1
             || BN_bn2binpad(y, param + S390X_OFF_SRC_Y(len), len) == -1
             || BN_bn2binpad(scalar_ptr,
@@ -107,7 +109,9 @@ static int ec_GFp_s390x_nistp_mul(const EC_GROUP *group, EC_POINT *r,
             || s390x_pcc(fc, param) != 0
             || BN_bin2bn(param + S390X_OFF_RES_X(len), len, x) == NULL
             || BN_bin2bn(param + S390X_OFF_RES_Y(len), len, y) == NULL
-            || EC_POINT_set_affine_coordinates(group, r, x, y, ctx) != 1)
+            || group->meth->point_set_affine_coordinates(group, r,
+                   x, y, ctx)
+                != 1)
             goto ret;
 
         rc = 1;
@@ -123,8 +127,6 @@ ret:
     return rc;
 }
 
-#define MIN_ECDSA_SIGN_ORDERBITS 64
-
 static ECDSA_SIG *ecdsa_s390x_nistp_sign_sig(const unsigned char *dgst,
     int dgstlen,
     const BIGNUM *kinv,
@@ -139,36 +141,11 @@ static ECDSA_SIG *ecdsa_s390x_nistp_sign_sig(const unsigned char *dgst,
     const EC_GROUP *group;
     const BIGNUM *privkey;
     BN_CTX *bn_ctx = NULL;
-    const BIGNUM *order;
-#ifdef FIPS_MODULE
-    int order_bits;
-#endif
     int off;
 
-    if (dgstlen < 0) {
-        ERR_raise(ERR_LIB_EC, EC_R_INVALID_LENGTH);
-        return NULL;
-    }
-
-    if (eckey == NULL) {
-        ERR_raise(ERR_LIB_EC, EC_R_MISSING_PARAMETERS);
-        return NULL;
-    }
-
     group = EC_KEY_get0_group(eckey);
-    if (group == NULL) {
-        ERR_raise(ERR_LIB_EC, EC_R_MISSING_PARAMETERS);
-        return NULL;
-    }
-
-    order = EC_GROUP_get0_order(group);
-    if (order == NULL) {
-        ERR_raise(ERR_LIB_EC, EC_R_MISSING_PARAMETERS);
-        return NULL;
-    }
-
     privkey = EC_KEY_get0_private_key(eckey);
-    if (privkey == NULL) {
+    if (group == NULL || privkey == NULL) {
         ERR_raise(ERR_LIB_EC, EC_R_MISSING_PARAMETERS);
         return NULL;
     }
@@ -206,42 +183,6 @@ static ECDSA_SIG *ecdsa_s390x_nistp_sign_sig(const unsigned char *dgst,
             ERR_raise(ERR_LIB_EC, EC_R_INVALID_LENGTH);
             goto ret;
         }
-#ifdef FIPS_MODULE
-        /* get random value of k using OpenSSL's RNG */
-        bn_ctx = BN_CTX_secure_new_ex(ossl_ec_key_get_libctx(eckey));
-        if (bn_ctx == NULL)
-            goto ret;
-
-        /* Preallocate space */
-        order_bits = BN_num_bits(order);
-        /* Check the number of bits here so that an infinite loop is not possible */
-        if (order_bits < MIN_ECDSA_SIGN_ORDERBITS
-            || !BN_set_bit(k, order_bits))
-            goto ret;
-
-        do {
-            int res = 0;
-
-            if (dgst != NULL)
-                res = ossl_bn_gen_dsa_nonce_fixed_top(k, order, privkey,
-                    dgst, dgstlen, bn_ctx);
-            else
-                res = ossl_bn_priv_rand_range_fixed_top(k, order, 0, bn_ctx);
-
-            if (!res) {
-                ERR_raise(ERR_LIB_EC, EC_R_RANDOM_NUMBER_GENERATION_FAILED);
-                goto ret;
-            }
-        } while (ossl_bn_is_word_fixed_top(k, 0));
-
-        if (BN_bn2binpad(k, param + S390X_OFF_RN(len), len) == -1) {
-            ERR_raise(ERR_LIB_EC, EC_R_RANDOM_NUMBER_GENERATION_FAILED);
-            goto ret;
-        }
-
-        /* Turns KDSA internal nonce-generation off. */
-        fc |= S390X_KDSA_D;
-#else
         /*
          * Generate random k and copy to param block. RAND_priv_bytes_ex
          * is used instead of BN_priv_rand_range or BN_generate_dsa_nonce
@@ -254,7 +195,6 @@ static ECDSA_SIG *ecdsa_s390x_nistp_sign_sig(const unsigned char *dgst,
             ERR_raise(ERR_LIB_EC, EC_R_RANDOM_NUMBER_GENERATION_FAILED);
             goto ret;
         }
-#endif
     } else {
         bn_ctx = BN_CTX_secure_new_ex(ossl_ec_key_get_libctx(eckey));
         if (bn_ctx == NULL)
@@ -305,24 +245,9 @@ static int ecdsa_s390x_nistp_verify_sig(const unsigned char *dgst, int dgstlen,
     const EC_POINT *pubkey;
     int off;
 
-    if (dgstlen < 0) {
-        ERR_raise(ERR_LIB_EC, EC_R_INVALID_LENGTH);
-        return -1;
-    }
-
-    if (sig == NULL || eckey == NULL) {
-        ERR_raise(ERR_LIB_EC, EC_R_MISSING_PARAMETERS);
-        return -1;
-    }
-
     group = EC_KEY_get0_group(eckey);
-    if (group == NULL) {
-        ERR_raise(ERR_LIB_EC, EC_R_MISSING_PARAMETERS);
-        return -1;
-    }
-
     pubkey = EC_KEY_get0_public_key(eckey);
-    if (pubkey == NULL) {
+    if (eckey == NULL || group == NULL || pubkey == NULL || sig == NULL) {
         ERR_raise(ERR_LIB_EC, EC_R_MISSING_PARAMETERS);
         return -1;
     }
@@ -364,7 +289,9 @@ static int ecdsa_s390x_nistp_verify_sig(const unsigned char *dgst, int dgstlen,
         goto ret;
     }
 
-    if (EC_POINT_get_affine_coordinates(group, pubkey, x, y, ctx) != 1
+    if (group->meth->point_get_affine_coordinates(group, pubkey,
+            x, y, ctx)
+            != 1
         || BN_bn2binpad(x, param + S390X_OFF_X(len), len) == -1
         || BN_bn2binpad(y, param + S390X_OFF_Y(len), len) == -1) {
         ERR_raise(ERR_LIB_EC, ERR_R_BN_LIB);
diff --git a/crypto/ec/ecp_sm2p256.c b/crypto/ec/ecp_sm2p256.c
index 6a9e8c66d5..fef5e46d8e 100644
--- a/crypto/ec/ecp_sm2p256.c
+++ b/crypto/ec/ecp_sm2p256.c
@@ -46,7 +46,10 @@ ALIGN32 static const BN_ULONG def_xG[P256_LIMBS] = {
 };
 
 ALIGN32 static const BN_ULONG def_yG[P256_LIMBS] = {
-    0x02df32e52139f0a0, 0xd0a9877cc62a4740, 0x59bdcee36b692153, 0xbc3736a2f4f6779c
+    0x02df32e52139f0a0,
+    0xd0a9877cc62a4740,
+    0x59bdcee36b692153,
+    0xbc3736a2f4f6779c,
 };
 #endif
 
diff --git a/crypto/ec/ecp_smpl.c b/crypto/ec/ecp_smpl.c
index 7570693015..b37cc28216 100644
--- a/crypto/ec/ecp_smpl.c
+++ b/crypto/ec/ecp_smpl.c
@@ -126,11 +126,11 @@ void ossl_ec_GFp_simple_group_clear_finish(EC_GROUP *group)
 
 int ossl_ec_GFp_simple_group_copy(EC_GROUP *dest, const EC_GROUP *src)
 {
-    if (BN_copy(dest->field, src->field) == NULL)
+    if (!BN_copy(dest->field, src->field))
         return 0;
-    if (BN_copy(dest->a, src->a) == NULL)
+    if (!BN_copy(dest->a, src->a))
         return 0;
-    if (BN_copy(dest->b, src->b) == NULL)
+    if (!BN_copy(dest->b, src->b))
         return 0;
 
     dest->a_is_minus3 = src->a_is_minus3;
@@ -164,7 +164,7 @@ int ossl_ec_GFp_simple_group_set_curve(EC_GROUP *group,
         goto err;
 
     /* group->field */
-    if (BN_copy(group->field, p) == NULL)
+    if (!BN_copy(group->field, p))
         goto err;
     BN_set_negative(group->field, 0);
 
@@ -174,7 +174,7 @@ int ossl_ec_GFp_simple_group_set_curve(EC_GROUP *group,
     if (group->meth->field_encode != NULL) {
         if (!group->meth->field_encode(group, group->a, tmp_a, ctx))
             goto err;
-    } else if (BN_copy(group->a, tmp_a) == NULL)
+    } else if (!BN_copy(group->a, tmp_a))
         goto err;
 
     /* group->b */
@@ -204,7 +204,7 @@ int ossl_ec_GFp_simple_group_get_curve(const EC_GROUP *group, BIGNUM *p,
     BN_CTX *new_ctx = NULL;
 
     if (p != NULL) {
-        if (BN_copy(p, group->field) == NULL)
+        if (!BN_copy(p, group->field))
             return 0;
     }
 
@@ -225,11 +225,11 @@ int ossl_ec_GFp_simple_group_get_curve(const EC_GROUP *group, BIGNUM *p,
             }
         } else {
             if (a != NULL) {
-                if (BN_copy(a, group->a) == NULL)
+                if (!BN_copy(a, group->a))
                     goto err;
             }
             if (b != NULL) {
-                if (BN_copy(b, group->b) == NULL)
+                if (!BN_copy(b, group->b))
                     goto err;
             }
         }
@@ -277,9 +277,9 @@ int ossl_ec_GFp_simple_group_check_discriminant(const EC_GROUP *group,
         if (!group->meth->field_decode(group, b, group->b, ctx))
             goto err;
     } else {
-        if (BN_copy(a, group->a) == NULL)
+        if (!BN_copy(a, group->a))
             goto err;
-        if (BN_copy(b, group->b) == NULL)
+        if (!BN_copy(b, group->b))
             goto err;
     }
 
@@ -352,11 +352,11 @@ void ossl_ec_GFp_simple_point_clear_finish(EC_POINT *point)
 
 int ossl_ec_GFp_simple_point_copy(EC_POINT *dest, const EC_POINT *src)
 {
-    if (BN_copy(dest->X, src->X) == NULL)
+    if (!BN_copy(dest->X, src->X))
         return 0;
-    if (BN_copy(dest->Y, src->Y) == NULL)
+    if (!BN_copy(dest->Y, src->Y))
         return 0;
-    if (BN_copy(dest->Z, src->Z) == NULL)
+    if (!BN_copy(dest->Z, src->Z))
         return 0;
     dest->Z_is_one = src->Z_is_one;
     dest->curve_name = src->curve_name;
@@ -460,15 +460,15 @@ int ossl_ec_GFp_simple_get_Jprojective_coordinates_GFp(const EC_GROUP *group,
         }
     } else {
         if (x != NULL) {
-            if (BN_copy(x, point->X) == NULL)
+            if (!BN_copy(x, point->X))
                 goto err;
         }
         if (y != NULL) {
-            if (BN_copy(y, point->Y) == NULL)
+            if (!BN_copy(y, point->Y))
                 goto err;
         }
         if (z != NULL) {
-            if (BN_copy(z, point->Z) == NULL)
+            if (!BN_copy(z, point->Z))
                 goto err;
         }
     }
@@ -548,11 +548,11 @@ int ossl_ec_GFp_simple_point_get_affine_coordinates(const EC_GROUP *group,
             }
         } else {
             if (x != NULL) {
-                if (BN_copy(x, point->X) == NULL)
+                if (!BN_copy(x, point->X))
                     goto err;
             }
             if (y != NULL) {
-                if (BN_copy(y, point->Y) == NULL)
+                if (!BN_copy(y, point->Y))
                     goto err;
             }
         }
@@ -656,9 +656,9 @@ int ossl_ec_GFp_simple_add(const EC_GROUP *group, EC_POINT *r, const EC_POINT *a
 
     /* n1, n2 */
     if (b->Z_is_one) {
-        if (BN_copy(n1, a->X) == NULL)
+        if (!BN_copy(n1, a->X))
             goto end;
-        if (BN_copy(n2, a->Y) == NULL)
+        if (!BN_copy(n2, a->Y))
             goto end;
         /* n1 = X_a */
         /* n2 = Y_a */
@@ -678,9 +678,9 @@ int ossl_ec_GFp_simple_add(const EC_GROUP *group, EC_POINT *r, const EC_POINT *a
 
     /* n3, n4 */
     if (a->Z_is_one) {
-        if (BN_copy(n3, b->X) == NULL)
+        if (!BN_copy(n3, b->X))
             goto end;
-        if (BN_copy(n4, b->Y) == NULL)
+        if (!BN_copy(n4, b->Y))
             goto end;
         /* n3 = X_b */
         /* n4 = Y_b */
@@ -732,14 +732,14 @@ int ossl_ec_GFp_simple_add(const EC_GROUP *group, EC_POINT *r, const EC_POINT *a
 
     /* Z_r */
     if (a->Z_is_one && b->Z_is_one) {
-        if (BN_copy(r->Z, n5) == NULL)
+        if (!BN_copy(r->Z, n5))
             goto end;
     } else {
         if (a->Z_is_one) {
-            if (BN_copy(n0, b->Z) == NULL)
+            if (!BN_copy(n0, b->Z))
                 goto end;
         } else if (b->Z_is_one) {
-            if (BN_copy(n0, a->Z) == NULL)
+            if (!BN_copy(n0, a->Z))
                 goto end;
         } else {
             if (!field_mul(group, n0, a->Z, b->Z, ctx))
@@ -883,7 +883,7 @@ int ossl_ec_GFp_simple_dbl(const EC_GROUP *group, EC_POINT *r, const EC_POINT *a
 
     /* Z_r */
     if (a->Z_is_one) {
-        if (BN_copy(n0, a->Y) == NULL)
+        if (!BN_copy(n0, a->Y))
             goto err;
     } else {
         if (!field_mul(group, n0, a->Y, a->Z, ctx))
@@ -1241,7 +1241,7 @@ int ossl_ec_GFp_simple_points_make_affine(const EC_GROUP *group, size_t num,
      */
 
     if (!BN_is_zero(points[0]->Z)) {
-        if (BN_copy(prod_Z[0], points[0]->Z) == NULL)
+        if (!BN_copy(prod_Z[0], points[0]->Z))
             goto err;
     } else {
         if (group->meth->field_set_to_one != 0) {
@@ -1259,7 +1259,7 @@ int ossl_ec_GFp_simple_points_make_affine(const EC_GROUP *group, size_t num,
                     ctx))
                 goto err;
         } else {
-            if (BN_copy(prod_Z[i], prod_Z[i - 1]) == NULL)
+            if (!BN_copy(prod_Z[i], prod_Z[i - 1]))
                 goto err;
         }
     }
@@ -1303,14 +1303,14 @@ int ossl_ec_GFp_simple_points_make_affine(const EC_GROUP *group, size_t num,
             if (!group->meth->field_mul(group, tmp, tmp, points[i]->Z, ctx))
                 goto err;
             /* Replace points[i]->Z by its inverse. */
-            if (BN_copy(points[i]->Z, tmp_Z) == NULL)
+            if (!BN_copy(points[i]->Z, tmp_Z))
                 goto err;
         }
     }
 
     if (!BN_is_zero(points[0]->Z)) {
         /* Replace points[0]->Z by its inverse. */
-        if (BN_copy(points[0]->Z, tmp) == NULL)
+        if (!BN_copy(points[0]->Z, tmp))
             goto err;
     }
 
diff --git a/crypto/ec/ecx_backend.c b/crypto/ec/ecx_backend.c
index d95e8bb084..40daf30e1a 100644
--- a/crypto/ec/ecx_backend.c
+++ b/crypto/ec/ecx_backend.c
@@ -20,9 +20,9 @@
 #include "ecx_backend.h"
 
 /*
- * The intention with the "backend" source file is to offer backend functions
- * for legacy backends (EVP_PKEY_ASN1_METHOD) and provider implementations
- * alike.
+ * The intention with the "backend" source file is to offer backend support
+ * for legacy backends (EVP_PKEY_ASN1_METHOD and EVP_PKEY_METHOD) and provider
+ * implementations alike.
  */
 
 int ossl_ecx_public_from_private(ECX_KEY *key)
@@ -230,19 +230,15 @@ ECX_KEY *ossl_ecx_key_from_pkcs8(const PKCS8_PRIV_KEY_INFO *p8inf,
     const X509_ALGOR *palg;
 
     if (!PKCS8_pkey_get0(NULL, &p, &plen, &palg, p8inf))
-        goto err;
+        return 0;
 
     oct = d2i_ASN1_OCTET_STRING(NULL, &p, plen);
     if (oct == NULL) {
         p = NULL;
         plen = 0;
     } else {
-        size_t tmp;
         p = ASN1_STRING_get0_data(oct);
-        tmp = ASN1_STRING_length_ex(oct);
-        if (tmp > INT_MAX)
-            goto err;
-        plen = (int)tmp;
+        plen = ASN1_STRING_length(oct);
     }
 
     /*
@@ -251,7 +247,6 @@ ECX_KEY *ossl_ecx_key_from_pkcs8(const PKCS8_PRIV_KEY_INFO *p8inf,
      */
     ecx = ossl_ecx_key_op(palg, p, plen, EVP_PKEY_NONE, KEY_OP_PRIVATE,
         libctx, propq);
-err:
     ASN1_OCTET_STRING_free(oct);
     return ecx;
 }
diff --git a/crypto/ec/ecx_backend.h b/crypto/ec/ecx_backend.h
index c549178d9c..d3d889c3a5 100644
--- a/crypto/ec/ecx_backend.h
+++ b/crypto/ec/ecx_backend.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_EC_ECX_BACKEND_H)
-#define OSSL_LIBCRYPTO_EC_ECX_BACKEND_H
-
 #define ISX448(id) ((id) == EVP_PKEY_X448)
 #define IS25519(id) ((id) == EVP_PKEY_X25519 || (id) == EVP_PKEY_ED25519)
 #define KEYLENID(id) (IS25519(id) ? X25519_KEYLEN                        \
@@ -21,5 +18,3 @@
                  : ((id) == EVP_PKEY_X448 ? ECX_KEY_TYPE_X448       \
                                           : ECX_KEY_TYPE_ED448))
 #define KEYLEN(p) KEYLENID((p)->ameth->pkey_id)
-
-#endif /* !defined(OSSL_LIBCRYPTO_EC_ECX_BACKEND_H) */
diff --git a/crypto/ec/ecx_key.c b/crypto/ec/ecx_key.c
index 036e308e8b..2fed62c361 100644
--- a/crypto/ec/ecx_key.c
+++ b/crypto/ec/ecx_key.c
@@ -14,7 +14,7 @@
 #include "internal/common.h" /* for ossl_assert() */
 
 #ifdef S390X_EC_ASM
-#include "arch/s390x_arch.h"
+#include "s390x_arch.h"
 #endif
 
 ECX_KEY *ossl_ecx_key_new(OSSL_LIB_CTX *libctx, ECX_KEY_TYPE type, int haspubkey,
@@ -92,7 +92,7 @@ int ossl_ecx_key_up_ref(ECX_KEY *key)
 {
     int i;
 
-    if (!CRYPTO_UP_REF(&key->references, &i))
+    if (CRYPTO_UP_REF(&key->references, &i) <= 0)
         return 0;
 
     REF_PRINT_COUNT("ECX_KEY", i, key);
diff --git a/crypto/ec/ecx_meth.c b/crypto/ec/ecx_meth.c
index 52af1803f4..7642954187 100644
--- a/crypto/ec/ecx_meth.c
+++ b/crypto/ec/ecx_meth.c
@@ -709,3 +709,760 @@ const EVP_PKEY_ASN1_METHOD ossl_ed448_asn1_meth = {
 
     ecx_priv_decode_ex
 };
+
+static int pkey_ecx_keygen(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
+{
+    ECX_KEY *ecx = ossl_ecx_key_op(NULL, NULL, 0, ctx->pmeth->pkey_id,
+        KEY_OP_KEYGEN, NULL, NULL);
+
+    if (ecx != NULL) {
+        EVP_PKEY_assign(pkey, ctx->pmeth->pkey_id, ecx);
+        return 1;
+    }
+    return 0;
+}
+
+static int validate_ecx_derive(EVP_PKEY_CTX *ctx, unsigned char *key,
+    size_t *keylen,
+    const unsigned char **privkey,
+    const unsigned char **pubkey)
+{
+    const ECX_KEY *ecxkey, *peerkey;
+
+    if (ctx->pkey == NULL || ctx->peerkey == NULL) {
+        ERR_raise(ERR_LIB_EC, EC_R_KEYS_NOT_SET);
+        return 0;
+    }
+    ecxkey = evp_pkey_get_legacy(ctx->pkey);
+    peerkey = evp_pkey_get_legacy(ctx->peerkey);
+    if (ecxkey == NULL || ecxkey->privkey == NULL) {
+        ERR_raise(ERR_LIB_EC, EC_R_INVALID_PRIVATE_KEY);
+        return 0;
+    }
+    if (peerkey == NULL) {
+        ERR_raise(ERR_LIB_EC, EC_R_INVALID_PEER_KEY);
+        return 0;
+    }
+    *privkey = ecxkey->privkey;
+    *pubkey = peerkey->pubkey;
+
+    return 1;
+}
+
+static int pkey_ecx_derive25519(EVP_PKEY_CTX *ctx, unsigned char *key,
+    size_t *keylen)
+{
+    const unsigned char *privkey, *pubkey;
+
+    if (!validate_ecx_derive(ctx, key, keylen, &privkey, &pubkey)
+        || (key != NULL
+            && ossl_x25519(key, privkey, pubkey) == 0))
+        return 0;
+    *keylen = X25519_KEYLEN;
+    return 1;
+}
+
+static int pkey_ecx_derive448(EVP_PKEY_CTX *ctx, unsigned char *key,
+    size_t *keylen)
+{
+    const unsigned char *privkey, *pubkey;
+
+    if (!validate_ecx_derive(ctx, key, keylen, &privkey, &pubkey)
+        || (key != NULL
+            && ossl_x448(key, privkey, pubkey) == 0))
+        return 0;
+    *keylen = X448_KEYLEN;
+    return 1;
+}
+
+static int pkey_ecx_ctrl(EVP_PKEY_CTX *ctx, int type, int p1, void *p2)
+{
+    /* Only need to handle peer key for derivation */
+    if (type == EVP_PKEY_CTRL_PEER_KEY)
+        return 1;
+    return -2;
+}
+
+static const EVP_PKEY_METHOD ecx25519_pkey_meth = {
+    EVP_PKEY_X25519,
+    0, 0, 0, 0, 0, 0, 0,
+    pkey_ecx_keygen,
+    0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
+    pkey_ecx_derive25519,
+    pkey_ecx_ctrl,
+    0
+};
+
+static const EVP_PKEY_METHOD ecx448_pkey_meth = {
+    EVP_PKEY_X448,
+    0, 0, 0, 0, 0, 0, 0,
+    pkey_ecx_keygen,
+    0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
+    pkey_ecx_derive448,
+    pkey_ecx_ctrl,
+    0
+};
+
+static int pkey_ecd_digestsign25519(EVP_MD_CTX *ctx, unsigned char *sig,
+    size_t *siglen, const unsigned char *tbs,
+    size_t tbslen)
+{
+    const ECX_KEY *edkey = evp_pkey_get_legacy(EVP_MD_CTX_get_pkey_ctx(ctx)->pkey);
+
+    if (edkey == NULL) {
+        ERR_raise(ERR_LIB_EC, EC_R_INVALID_KEY);
+        return 0;
+    }
+
+    if (sig == NULL) {
+        *siglen = ED25519_SIGSIZE;
+        return 1;
+    }
+    if (*siglen < ED25519_SIGSIZE) {
+        ERR_raise(ERR_LIB_EC, EC_R_BUFFER_TOO_SMALL);
+        return 0;
+    }
+
+    if (ossl_ed25519_sign(sig, tbs, tbslen, edkey->pubkey, edkey->privkey,
+            0, 0, 0,
+            NULL, 0,
+            NULL, NULL)
+        == 0)
+        return 0;
+    *siglen = ED25519_SIGSIZE;
+    return 1;
+}
+
+static int pkey_ecd_digestsign448(EVP_MD_CTX *ctx, unsigned char *sig,
+    size_t *siglen, const unsigned char *tbs,
+    size_t tbslen)
+{
+    const ECX_KEY *edkey = evp_pkey_get_legacy(EVP_MD_CTX_get_pkey_ctx(ctx)->pkey);
+
+    if (edkey == NULL) {
+        ERR_raise(ERR_LIB_EC, EC_R_INVALID_KEY);
+        return 0;
+    }
+
+    if (sig == NULL) {
+        *siglen = ED448_SIGSIZE;
+        return 1;
+    }
+    if (*siglen < ED448_SIGSIZE) {
+        ERR_raise(ERR_LIB_EC, EC_R_BUFFER_TOO_SMALL);
+        return 0;
+    }
+
+    if (ossl_ed448_sign(edkey->libctx, sig, tbs, tbslen, edkey->pubkey,
+            edkey->privkey, NULL, 0, 0, edkey->propq)
+        == 0)
+        return 0;
+    *siglen = ED448_SIGSIZE;
+    return 1;
+}
+
+static int pkey_ecd_digestverify25519(EVP_MD_CTX *ctx, const unsigned char *sig,
+    size_t siglen, const unsigned char *tbs,
+    size_t tbslen)
+{
+    const ECX_KEY *edkey = evp_pkey_get_legacy(EVP_MD_CTX_get_pkey_ctx(ctx)->pkey);
+
+    if (edkey == NULL) {
+        ERR_raise(ERR_LIB_EC, EC_R_INVALID_KEY);
+        return 0;
+    }
+
+    if (siglen != ED25519_SIGSIZE)
+        return 0;
+
+    return ossl_ed25519_verify(tbs, tbslen, sig, edkey->pubkey,
+        0, 0, 0,
+        NULL, 0,
+        edkey->libctx, edkey->propq);
+}
+
+static int pkey_ecd_digestverify448(EVP_MD_CTX *ctx, const unsigned char *sig,
+    size_t siglen, const unsigned char *tbs,
+    size_t tbslen)
+{
+    const ECX_KEY *edkey = evp_pkey_get_legacy(EVP_MD_CTX_get_pkey_ctx(ctx)->pkey);
+
+    if (edkey == NULL) {
+        ERR_raise(ERR_LIB_EC, EC_R_INVALID_KEY);
+        return 0;
+    }
+
+    if (siglen != ED448_SIGSIZE)
+        return 0;
+
+    return ossl_ed448_verify(edkey->libctx, tbs, tbslen, sig, edkey->pubkey,
+        NULL, 0, 0, edkey->propq);
+}
+
+static int pkey_ecd_ctrl(EVP_PKEY_CTX *ctx, int type, int p1, void *p2)
+{
+    switch (type) {
+    case EVP_PKEY_CTRL_MD:
+        /* Only NULL allowed as digest */
+        if (p2 == NULL || (const EVP_MD *)p2 == EVP_md_null())
+            return 1;
+        ERR_raise(ERR_LIB_EC, EC_R_INVALID_DIGEST_TYPE);
+        return 0;
+
+    case EVP_PKEY_CTRL_DIGESTINIT:
+        return 1;
+    }
+    return -2;
+}
+
+static const EVP_PKEY_METHOD ed25519_pkey_meth = {
+    EVP_PKEY_ED25519, EVP_PKEY_FLAG_SIGCTX_CUSTOM,
+    0, 0, 0, 0, 0, 0,
+    pkey_ecx_keygen,
+    0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
+    pkey_ecd_ctrl,
+    0,
+    pkey_ecd_digestsign25519,
+    pkey_ecd_digestverify25519
+};
+
+static const EVP_PKEY_METHOD ed448_pkey_meth = {
+    EVP_PKEY_ED448, EVP_PKEY_FLAG_SIGCTX_CUSTOM,
+    0, 0, 0, 0, 0, 0,
+    pkey_ecx_keygen,
+    0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
+    pkey_ecd_ctrl,
+    0,
+    pkey_ecd_digestsign448,
+    pkey_ecd_digestverify448
+};
+
+#ifdef S390X_EC_ASM
+#include "s390x_arch.h"
+
+static int s390x_pkey_ecx_keygen25519(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
+{
+    static const unsigned char generator[] = {
+        0x09, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
+        0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
+        0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00
+    };
+    ECX_KEY *key = ossl_ecx_key_new(ctx->libctx, ECX_KEY_TYPE_X25519, 1,
+        ctx->propquery);
+    unsigned char *privkey = NULL, *pubkey;
+
+    if (key == NULL) {
+        ERR_raise(ERR_LIB_EC, ERR_R_EC_LIB);
+        goto err;
+    }
+
+    pubkey = key->pubkey;
+
+    privkey = ossl_ecx_key_allocate_privkey(key);
+    if (privkey == NULL) {
+        ERR_raise(ERR_LIB_EC, ERR_R_EC_LIB);
+        goto err;
+    }
+
+    if (RAND_priv_bytes_ex(ctx->libctx, privkey, X25519_KEYLEN, 0) <= 0)
+        goto err;
+
+    privkey[0] &= 248;
+    privkey[31] &= 127;
+    privkey[31] |= 64;
+
+    if (s390x_x25519_mul(pubkey, generator, privkey) != 1)
+        goto err;
+
+    EVP_PKEY_assign(pkey, ctx->pmeth->pkey_id, key);
+    return 1;
+err:
+    ossl_ecx_key_free(key);
+    return 0;
+}
+
+static int s390x_pkey_ecx_keygen448(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
+{
+    static const unsigned char generator[] = {
+        0x05, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
+        0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
+        0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
+        0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
+        0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00
+    };
+    ECX_KEY *key = ossl_ecx_key_new(ctx->libctx, ECX_KEY_TYPE_X448, 1,
+        ctx->propquery);
+    unsigned char *privkey = NULL, *pubkey;
+
+    if (key == NULL) {
+        ERR_raise(ERR_LIB_EC, ERR_R_EC_LIB);
+        goto err;
+    }
+
+    pubkey = key->pubkey;
+
+    privkey = ossl_ecx_key_allocate_privkey(key);
+    if (privkey == NULL) {
+        ERR_raise(ERR_LIB_EC, ERR_R_EC_LIB);
+        goto err;
+    }
+
+    if (RAND_priv_bytes_ex(ctx->libctx, privkey, X448_KEYLEN, 0) <= 0)
+        goto err;
+
+    privkey[0] &= 252;
+    privkey[55] |= 128;
+
+    if (s390x_x448_mul(pubkey, generator, privkey) != 1)
+        goto err;
+
+    EVP_PKEY_assign(pkey, ctx->pmeth->pkey_id, key);
+    return 1;
+err:
+    ossl_ecx_key_free(key);
+    return 0;
+}
+
+static int s390x_pkey_ecd_keygen25519(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
+{
+    static const unsigned char generator_x[] = {
+        0x1a, 0xd5, 0x25, 0x8f, 0x60, 0x2d, 0x56, 0xc9, 0xb2, 0xa7, 0x25, 0x95,
+        0x60, 0xc7, 0x2c, 0x69, 0x5c, 0xdc, 0xd6, 0xfd, 0x31, 0xe2, 0xa4, 0xc0,
+        0xfe, 0x53, 0x6e, 0xcd, 0xd3, 0x36, 0x69, 0x21
+    };
+    static const unsigned char generator_y[] = {
+        0x58,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+        0x66,
+    };
+    unsigned char x_dst[32], buff[SHA512_DIGEST_LENGTH];
+    ECX_KEY *key = ossl_ecx_key_new(ctx->libctx, ECX_KEY_TYPE_ED25519, 1,
+        ctx->propquery);
+    unsigned char *privkey = NULL, *pubkey;
+    unsigned int sz;
+    EVP_MD *md = NULL;
+    int rv;
+
+    if (key == NULL) {
+        ERR_raise(ERR_LIB_EC, ERR_R_EC_LIB);
+        goto err;
+    }
+
+    pubkey = key->pubkey;
+
+    privkey = ossl_ecx_key_allocate_privkey(key);
+    if (privkey == NULL) {
+        ERR_raise(ERR_LIB_EC, ERR_R_EC_LIB);
+        goto err;
+    }
+
+    if (RAND_priv_bytes_ex(ctx->libctx, privkey, ED25519_KEYLEN, 0) <= 0)
+        goto err;
+
+    md = EVP_MD_fetch(ctx->libctx, "SHA512", ctx->propquery);
+    if (md == NULL)
+        goto err;
+
+    rv = EVP_Digest(privkey, 32, buff, &sz, md, NULL);
+    EVP_MD_free(md);
+    if (!rv)
+        goto err;
+
+    buff[0] &= 248;
+    buff[31] &= 63;
+    buff[31] |= 64;
+
+    if (s390x_ed25519_mul(x_dst, pubkey,
+            generator_x, generator_y, buff)
+        != 1)
+        goto err;
+
+    pubkey[31] |= ((x_dst[0] & 0x01) << 7);
+
+    EVP_PKEY_assign(pkey, ctx->pmeth->pkey_id, key);
+    return 1;
+err:
+    ossl_ecx_key_free(key);
+    return 0;
+}
+
+static int s390x_pkey_ecd_keygen448(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
+{
+    static const unsigned char generator_x[] = {
+        0x5e, 0xc0, 0x0c, 0xc7, 0x2b, 0xa8, 0x26, 0x26, 0x8e, 0x93, 0x00, 0x8b,
+        0xe1, 0x80, 0x3b, 0x43, 0x11, 0x65, 0xb6, 0x2a, 0xf7, 0x1a, 0xae, 0x12,
+        0x64, 0xa4, 0xd3, 0xa3, 0x24, 0xe3, 0x6d, 0xea, 0x67, 0x17, 0x0f, 0x47,
+        0x70, 0x65, 0x14, 0x9e, 0xda, 0x36, 0xbf, 0x22, 0xa6, 0x15, 0x1d, 0x22,
+        0xed, 0x0d, 0xed, 0x6b, 0xc6, 0x70, 0x19, 0x4f, 0x00
+    };
+    static const unsigned char generator_y[] = {
+        0x14, 0xfa, 0x30, 0xf2, 0x5b, 0x79, 0x08, 0x98, 0xad, 0xc8, 0xd7, 0x4e,
+        0x2c, 0x13, 0xbd, 0xfd, 0xc4, 0x39, 0x7c, 0xe6, 0x1c, 0xff, 0xd3, 0x3a,
+        0xd7, 0xc2, 0xa0, 0x05, 0x1e, 0x9c, 0x78, 0x87, 0x40, 0x98, 0xa3, 0x6c,
+        0x73, 0x73, 0xea, 0x4b, 0x62, 0xc7, 0xc9, 0x56, 0x37, 0x20, 0x76, 0x88,
+        0x24, 0xbc, 0xb6, 0x6e, 0x71, 0x46, 0x3f, 0x69, 0x00
+    };
+    unsigned char x_dst[57], buff[114];
+    ECX_KEY *key = ossl_ecx_key_new(ctx->libctx, ECX_KEY_TYPE_ED448, 1,
+        ctx->propquery);
+    unsigned char *privkey = NULL, *pubkey;
+    EVP_MD_CTX *hashctx = NULL;
+    EVP_MD *md = NULL;
+    int rv;
+
+    if (key == NULL) {
+        ERR_raise(ERR_LIB_EC, ERR_R_EC_LIB);
+        goto err;
+    }
+
+    pubkey = key->pubkey;
+
+    privkey = ossl_ecx_key_allocate_privkey(key);
+    if (privkey == NULL) {
+        ERR_raise(ERR_LIB_EC, ERR_R_EC_LIB);
+        goto err;
+    }
+
+    if (RAND_priv_bytes_ex(ctx->libctx, privkey, ED448_KEYLEN, 0) <= 0)
+        goto err;
+
+    hashctx = EVP_MD_CTX_new();
+    if (hashctx == NULL)
+        goto err;
+
+    md = EVP_MD_fetch(ctx->libctx, "SHAKE256", ctx->propquery);
+    if (md == NULL)
+        goto err;
+
+    rv = EVP_DigestInit_ex(hashctx, md, NULL);
+    EVP_MD_free(md);
+    if (rv != 1)
+        goto err;
+
+    if (EVP_DigestUpdate(hashctx, privkey, 57) != 1)
+        goto err;
+    if (EVP_DigestFinalXOF(hashctx, buff, sizeof(buff)) != 1)
+        goto err;
+
+    buff[0] &= -4;
+    buff[55] |= 0x80;
+    buff[56] = 0;
+
+    if (s390x_ed448_mul(x_dst, pubkey,
+            generator_x, generator_y, buff)
+        != 1)
+        goto err;
+
+    pubkey[56] |= ((x_dst[0] & 0x01) << 7);
+
+    EVP_PKEY_assign(pkey, ctx->pmeth->pkey_id, key);
+    EVP_MD_CTX_free(hashctx);
+    return 1;
+err:
+    ossl_ecx_key_free(key);
+    EVP_MD_CTX_free(hashctx);
+    return 0;
+}
+
+static int s390x_pkey_ecx_derive25519(EVP_PKEY_CTX *ctx, unsigned char *key,
+    size_t *keylen)
+{
+    const unsigned char *privkey, *pubkey;
+
+    if (!validate_ecx_derive(ctx, key, keylen, &privkey, &pubkey)
+        || (key != NULL
+            && s390x_x25519_mul(key, privkey, pubkey) == 0))
+        return 0;
+    *keylen = X25519_KEYLEN;
+    return 1;
+}
+
+static int s390x_pkey_ecx_derive448(EVP_PKEY_CTX *ctx, unsigned char *key,
+    size_t *keylen)
+{
+    const unsigned char *privkey, *pubkey;
+
+    if (!validate_ecx_derive(ctx, key, keylen, &privkey, &pubkey)
+        || (key != NULL
+            && s390x_x448_mul(key, pubkey, privkey) == 0))
+        return 0;
+    *keylen = X448_KEYLEN;
+    return 1;
+}
+
+static int s390x_pkey_ecd_digestsign25519(EVP_MD_CTX *ctx,
+    unsigned char *sig, size_t *siglen,
+    const unsigned char *tbs,
+    size_t tbslen)
+{
+    union {
+        struct {
+            unsigned char sig[64];
+            unsigned char priv[32];
+        } ed25519;
+        unsigned long long buff[512];
+    } param;
+    const ECX_KEY *edkey = evp_pkey_get_legacy(EVP_MD_CTX_get_pkey_ctx(ctx)->pkey);
+    int rc;
+
+    if (edkey == NULL) {
+        ERR_raise(ERR_LIB_EC, EC_R_INVALID_KEY);
+        return 0;
+    }
+
+    if (sig == NULL) {
+        *siglen = ED25519_SIGSIZE;
+        return 1;
+    }
+
+    if (*siglen < ED25519_SIGSIZE) {
+        ERR_raise(ERR_LIB_EC, EC_R_BUFFER_TOO_SMALL);
+        return 0;
+    }
+
+    memset(¶m, 0, sizeof(param));
+    memcpy(param.ed25519.priv, edkey->privkey, sizeof(param.ed25519.priv));
+
+    rc = s390x_kdsa(S390X_EDDSA_SIGN_ED25519, ¶m.ed25519, tbs, tbslen);
+    OPENSSL_cleanse(param.ed25519.priv, sizeof(param.ed25519.priv));
+    if (rc != 0)
+        return 0;
+
+    s390x_flip_endian32(sig, param.ed25519.sig);
+    s390x_flip_endian32(sig + 32, param.ed25519.sig + 32);
+
+    *siglen = ED25519_SIGSIZE;
+    return 1;
+}
+
+static int s390x_pkey_ecd_digestsign448(EVP_MD_CTX *ctx,
+    unsigned char *sig, size_t *siglen,
+    const unsigned char *tbs,
+    size_t tbslen)
+{
+    union {
+        struct {
+            unsigned char sig[128];
+            unsigned char priv[64];
+        } ed448;
+        unsigned long long buff[512];
+    } param;
+    const ECX_KEY *edkey = evp_pkey_get_legacy(EVP_MD_CTX_get_pkey_ctx(ctx)->pkey);
+    int rc;
+
+    if (edkey == NULL) {
+        ERR_raise(ERR_LIB_EC, EC_R_INVALID_KEY);
+        return 0;
+    }
+
+    if (sig == NULL) {
+        *siglen = ED448_SIGSIZE;
+        return 1;
+    }
+
+    if (*siglen < ED448_SIGSIZE) {
+        ERR_raise(ERR_LIB_EC, EC_R_BUFFER_TOO_SMALL);
+        return 0;
+    }
+
+    memset(¶m, 0, sizeof(param));
+    memcpy(param.ed448.priv + 64 - 57, edkey->privkey, 57);
+
+    rc = s390x_kdsa(S390X_EDDSA_SIGN_ED448, ¶m.ed448, tbs, tbslen);
+    OPENSSL_cleanse(param.ed448.priv, sizeof(param.ed448.priv));
+    if (rc != 0)
+        return 0;
+
+    s390x_flip_endian64(param.ed448.sig, param.ed448.sig);
+    s390x_flip_endian64(param.ed448.sig + 64, param.ed448.sig + 64);
+    memcpy(sig, param.ed448.sig, 57);
+    memcpy(sig + 57, param.ed448.sig + 64, 57);
+
+    *siglen = ED448_SIGSIZE;
+    return 1;
+}
+
+static int s390x_pkey_ecd_digestverify25519(EVP_MD_CTX *ctx,
+    const unsigned char *sig,
+    size_t siglen,
+    const unsigned char *tbs,
+    size_t tbslen)
+{
+    union {
+        struct {
+            unsigned char sig[64];
+            unsigned char pub[32];
+        } ed25519;
+        unsigned long long buff[512];
+    } param;
+    const ECX_KEY *edkey = evp_pkey_get_legacy(EVP_MD_CTX_get_pkey_ctx(ctx)->pkey);
+
+    if (edkey == NULL) {
+        ERR_raise(ERR_LIB_EC, EC_R_INVALID_KEY);
+        return 0;
+    }
+
+    if (siglen != ED25519_SIGSIZE)
+        return 0;
+
+    memset(¶m, 0, sizeof(param));
+    s390x_flip_endian32(param.ed25519.sig, sig);
+    s390x_flip_endian32(param.ed25519.sig + 32, sig + 32);
+    s390x_flip_endian32(param.ed25519.pub, edkey->pubkey);
+
+    return s390x_kdsa(S390X_EDDSA_VERIFY_ED25519,
+               ¶m.ed25519, tbs, tbslen)
+            == 0
+        ? 1
+        : 0;
+}
+
+static int s390x_pkey_ecd_digestverify448(EVP_MD_CTX *ctx,
+    const unsigned char *sig,
+    size_t siglen,
+    const unsigned char *tbs,
+    size_t tbslen)
+{
+    union {
+        struct {
+            unsigned char sig[128];
+            unsigned char pub[64];
+        } ed448;
+        unsigned long long buff[512];
+    } param;
+    const ECX_KEY *edkey = evp_pkey_get_legacy(EVP_MD_CTX_get_pkey_ctx(ctx)->pkey);
+
+    if (edkey == NULL) {
+        ERR_raise(ERR_LIB_EC, EC_R_INVALID_KEY);
+        return 0;
+    }
+
+    if (siglen != ED448_SIGSIZE)
+        return 0;
+
+    memset(¶m, 0, sizeof(param));
+    memcpy(param.ed448.sig, sig, 57);
+    s390x_flip_endian64(param.ed448.sig, param.ed448.sig);
+    memcpy(param.ed448.sig + 64, sig + 57, 57);
+    s390x_flip_endian64(param.ed448.sig + 64, param.ed448.sig + 64);
+    memcpy(param.ed448.pub, edkey->pubkey, 57);
+    s390x_flip_endian64(param.ed448.pub, param.ed448.pub);
+
+    return s390x_kdsa(S390X_EDDSA_VERIFY_ED448,
+               ¶m.ed448, tbs, tbslen)
+            == 0
+        ? 1
+        : 0;
+}
+
+static const EVP_PKEY_METHOD ecx25519_s390x_pkey_meth = {
+    EVP_PKEY_X25519,
+    0, 0, 0, 0, 0, 0, 0,
+    s390x_pkey_ecx_keygen25519,
+    0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
+    s390x_pkey_ecx_derive25519,
+    pkey_ecx_ctrl,
+    0
+};
+
+static const EVP_PKEY_METHOD ecx448_s390x_pkey_meth = {
+    EVP_PKEY_X448,
+    0, 0, 0, 0, 0, 0, 0,
+    s390x_pkey_ecx_keygen448,
+    0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
+    s390x_pkey_ecx_derive448,
+    pkey_ecx_ctrl,
+    0
+};
+static const EVP_PKEY_METHOD ed25519_s390x_pkey_meth = {
+    EVP_PKEY_ED25519, EVP_PKEY_FLAG_SIGCTX_CUSTOM,
+    0, 0, 0, 0, 0, 0,
+    s390x_pkey_ecd_keygen25519,
+    0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
+    pkey_ecd_ctrl,
+    0,
+    s390x_pkey_ecd_digestsign25519,
+    s390x_pkey_ecd_digestverify25519
+};
+
+static const EVP_PKEY_METHOD ed448_s390x_pkey_meth = {
+    EVP_PKEY_ED448, EVP_PKEY_FLAG_SIGCTX_CUSTOM,
+    0, 0, 0, 0, 0, 0,
+    s390x_pkey_ecd_keygen448,
+    0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
+    pkey_ecd_ctrl,
+    0,
+    s390x_pkey_ecd_digestsign448,
+    s390x_pkey_ecd_digestverify448
+};
+#endif
+
+const EVP_PKEY_METHOD *ossl_ecx25519_pkey_method(void)
+{
+#ifdef S390X_EC_ASM
+    if (OPENSSL_s390xcap_P.pcc[1] & S390X_CAPBIT(S390X_SCALAR_MULTIPLY_X25519))
+        return &ecx25519_s390x_pkey_meth;
+#endif
+    return &ecx25519_pkey_meth;
+}
+
+const EVP_PKEY_METHOD *ossl_ecx448_pkey_method(void)
+{
+#ifdef S390X_EC_ASM
+    if (OPENSSL_s390xcap_P.pcc[1] & S390X_CAPBIT(S390X_SCALAR_MULTIPLY_X448))
+        return &ecx448_s390x_pkey_meth;
+#endif
+    return &ecx448_pkey_meth;
+}
+
+const EVP_PKEY_METHOD *ossl_ed25519_pkey_method(void)
+{
+#ifdef S390X_EC_ASM
+    if (OPENSSL_s390xcap_P.pcc[1] & S390X_CAPBIT(S390X_SCALAR_MULTIPLY_ED25519)
+        && OPENSSL_s390xcap_P.kdsa[0] & S390X_CAPBIT(S390X_EDDSA_SIGN_ED25519)
+        && OPENSSL_s390xcap_P.kdsa[0]
+            & S390X_CAPBIT(S390X_EDDSA_VERIFY_ED25519))
+        return &ed25519_s390x_pkey_meth;
+#endif
+    return &ed25519_pkey_meth;
+}
+
+const EVP_PKEY_METHOD *ossl_ed448_pkey_method(void)
+{
+#ifdef S390X_EC_ASM
+    if (OPENSSL_s390xcap_P.pcc[1] & S390X_CAPBIT(S390X_SCALAR_MULTIPLY_ED448)
+        && OPENSSL_s390xcap_P.kdsa[0] & S390X_CAPBIT(S390X_EDDSA_SIGN_ED448)
+        && OPENSSL_s390xcap_P.kdsa[0] & S390X_CAPBIT(S390X_EDDSA_VERIFY_ED448))
+        return &ed448_s390x_pkey_meth;
+#endif
+    return &ed448_pkey_meth;
+}
diff --git a/crypto/ec/ecx_s390x.c b/crypto/ec/ecx_s390x.c
index 5f0cad0fe3..4b9514084a 100644
--- a/crypto/ec/ecx_s390x.c
+++ b/crypto/ec/ecx_s390x.c
@@ -15,7 +15,7 @@
 #include "ec_local.h"
 #include "curve448/curve448_local.h"
 #include "ecx_backend.h"
-#include "arch/s390x_arch.h"
+#include "s390x_arch.h"
 #include "internal/constant_time.h"
 
 static void s390x_x25519_mod_p(unsigned char u[32])
diff --git a/crypto/encode_decode/decoder_lib.c b/crypto/encode_decode/decoder_lib.c
index 7be00d21a1..e827659c9a 100644
--- a/crypto/encode_decode/decoder_lib.c
+++ b/crypto/encode_decode/decoder_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -383,11 +383,10 @@ int ossl_decoder_ctx_add_decoder_inst(OSSL_DECODER_CTX *ctx,
         {
             BIO_printf(trc_out,
                 "(ctx %p) Added decoder instance %p for decoder %p\n"
-                "    %s with %s (%s)\n",
+                "    %s with %s\n",
                 (void *)ctx, (void *)di, (void *)di->decoder,
                 OSSL_DECODER_get0_name(di->decoder),
-                OSSL_DECODER_get0_properties(di->decoder),
-                OSSL_DECODER_get0_description(di->decoder));
+                OSSL_DECODER_get0_properties(di->decoder));
         }
         OSSL_TRACE_END(DECODER);
     }
@@ -472,11 +471,10 @@ static void collect_extra_decoder(OSSL_DECODER *decoder, void *arg)
         {
             BIO_printf(trc_out,
                 "(ctx %p) [%d] Checking out decoder %p:\n"
-                "    %s with %s (%s)\n",
+                "    %s with %s\n",
                 (void *)data->ctx, data->type_check, (void *)decoder,
                 OSSL_DECODER_get0_name(decoder),
-                OSSL_DECODER_get0_properties(decoder),
-                OSSL_DECODER_get0_description(decoder));
+                OSSL_DECODER_get0_properties(decoder));
         }
         OSSL_TRACE_END(DECODER);
 
@@ -986,10 +984,9 @@ static int decoder_process(const OSSL_PARAM params[], void *arg)
         OSSL_TRACE_BEGIN(DECODER)
         {
             BIO_printf(trc_out,
-                "(ctx %p) %s incoming from previous decoder (%p %s):\n"
+                "(ctx %p) %s incoming from previous decoder (%p):\n"
                 "    data type: %s, data structure: %s%s\n",
                 (void *)new_data.ctx, LEVEL, (void *)decoder,
-                OSSL_DECODER_get0_description(decoder),
                 data_type, trace_data_structure,
                 (trace_data_structure == data_structure
                         ? ""
@@ -1029,11 +1026,10 @@ static int decoder_process(const OSSL_PARAM params[], void *arg)
         {
             new_decoder_name = OSSL_DECODER_get0_name(new_decoder);
             BIO_printf(trc_out,
-                "(ctx %p) %s [%u] Considering decoder instance %p (decoder %p %s):\n"
+                "(ctx %p) %s [%u] Considering decoder instance %p (decoder %p):\n"
                 "    %s with %s\n",
                 (void *)new_data.ctx, LEVEL, (unsigned int)i,
                 (void *)new_decoder_inst, (void *)new_decoder,
-                OSSL_DECODER_get0_description(new_decoder),
                 new_decoder_name,
                 OSSL_DECODER_get0_properties(new_decoder));
         }
@@ -1067,10 +1063,9 @@ static int decoder_process(const OSSL_PARAM params[], void *arg)
             OSSL_TRACE_BEGIN(DECODER)
             {
                 BIO_printf(trc_out,
-                    "(ctx %p) %s [%u] the input type doesn't match the name of the previous decoder (%p %s), skipping...\n",
+                    "(ctx %p) %s [%u] the input type doesn't match the name of the previous decoder (%p), skipping...\n",
                     (void *)new_data.ctx, LEVEL, (unsigned int)i,
-                    (void *)decoder,
-                    OSSL_DECODER_get0_description(decoder));
+                    (void *)decoder);
             }
             OSSL_TRACE_END(DECODER);
             continue;
diff --git a/crypto/encode_decode/decoder_meth.c b/crypto/encode_decode/decoder_meth.c
index 632d20c996..466d910b67 100644
--- a/crypto/encode_decode/decoder_meth.c
+++ b/crypto/encode_decode/decoder_meth.c
@@ -26,7 +26,39 @@
 
 static void ossl_decoder_free(void *data)
 {
-    OSSL_DECODER *decoder = (OSSL_DECODER *)data;
+    OSSL_DECODER_free(data);
+}
+
+static int ossl_decoder_up_ref(void *data)
+{
+    return OSSL_DECODER_up_ref(data);
+}
+
+/* Simple method structure constructor and destructor */
+static OSSL_DECODER *ossl_decoder_new(void)
+{
+    OSSL_DECODER *decoder = NULL;
+
+    if ((decoder = OPENSSL_zalloc(sizeof(*decoder))) == NULL)
+        return NULL;
+    if (!CRYPTO_NEW_REF(&decoder->base.refcnt, 1)) {
+        OSSL_DECODER_free(decoder);
+        return NULL;
+    }
+
+    return decoder;
+}
+
+int OSSL_DECODER_up_ref(OSSL_DECODER *decoder)
+{
+    int ref = 0;
+
+    CRYPTO_UP_REF(&decoder->base.refcnt, &ref);
+    return 1;
+}
+
+void OSSL_DECODER_free(OSSL_DECODER *decoder)
+{
     int ref = 0;
 
     if (decoder == NULL)
@@ -42,58 +74,6 @@ static void ossl_decoder_free(void *data)
     OPENSSL_free(decoder);
 }
 
-static int ossl_decoder_up_ref(void *data)
-{
-    OSSL_DECODER *decoder = (OSSL_DECODER *)data;
-    int ref = 0;
-
-    return CRYPTO_UP_REF(&decoder->base.refcnt, &ref);
-}
-
-/* Simple method structure constructor and destructor */
-static OSSL_DECODER *ossl_decoder_new(void)
-{
-    OSSL_DECODER *decoder = NULL;
-
-    if ((decoder = OPENSSL_zalloc(sizeof(*decoder))) == NULL)
-        return NULL;
-    if (!CRYPTO_NEW_REF(&decoder->base.refcnt, 1)) {
-        ossl_decoder_free(decoder);
-        return NULL;
-    }
-
-    return decoder;
-}
-
-int OSSL_DECODER_up_ref(OSSL_DECODER *decoder)
-{
-#ifdef OPENSSL_NO_CACHED_FETCH
-    return ossl_decoder_up_ref(decoder);
-#else
-    /*
-     * DECODERS do something weird.  They manually build methods rather than
-     * attempt to fetch them from the method store or construct them through
-     * the ossl_generic_fetch mechanism.  As such they don't make use of the refcounting
-     * that we rely on in the method store, and so we always need to refcount them here
-     * We can identify them based on the fact that they never have a registered nid (i.e.
-     * its always zero)
-     */
-    if (decoder->base.id == 0 || decoder->base.no_store != 0)
-        return ossl_decoder_up_ref(decoder);
-    return 1;
-#endif
-}
-
-void OSSL_DECODER_free(OSSL_DECODER *decoder)
-{
-#ifdef OPENSSL_NO_CACHED_FETCH
-    ossl_decoder_free(decoder);
-#else
-    if (decoder != NULL && (decoder->base.id == 0 || decoder->base.no_store != 0))
-        ossl_decoder_free(decoder);
-#endif
-}
-
 /* Data to be passed through ossl_method_construct() */
 struct decoder_data_st {
     OSSL_LIB_CTX *libctx;
@@ -222,12 +202,12 @@ static int put_decoder_in_store(void *store, void *method,
 
     return ossl_method_store_add(store, prov, id, propdef, method,
         ossl_decoder_up_ref,
-        ossl_decoder_free);
+        ossl_decoder_free, NULL, NULL);
 }
 
 /* Create and populate a decoder method */
 void *ossl_decoder_from_algorithm(int id, const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, int no_store)
+    OSSL_PROVIDER *prov)
 {
     OSSL_DECODER *decoder = NULL;
     const OSSL_DISPATCH *fns = algodef->implementation;
@@ -236,16 +216,15 @@ void *ossl_decoder_from_algorithm(int id, const OSSL_ALGORITHM *algodef,
     if ((decoder = ossl_decoder_new()) == NULL)
         return NULL;
     decoder->base.id = id;
-    decoder->base.no_store = no_store;
     if ((decoder->base.name = ossl_algorithm_get1_first_name(algodef)) == NULL) {
-        ossl_decoder_free(decoder);
+        OSSL_DECODER_free(decoder);
         return NULL;
     }
     decoder->base.algodef = algodef;
     if ((decoder->base.parsed_propdef
             = ossl_parse_property(libctx, algodef->property_definition))
         == NULL) {
-        ossl_decoder_free(decoder);
+        OSSL_DECODER_free(decoder);
         return NULL;
     }
 
@@ -297,13 +276,13 @@ void *ossl_decoder_from_algorithm(int id, const OSSL_ALGORITHM *algodef,
     if (!((decoder->newctx == NULL && decoder->freectx == NULL)
             || (decoder->newctx != NULL && decoder->freectx != NULL))
         || decoder->decode == NULL) {
-        ossl_decoder_free(decoder);
+        OSSL_DECODER_free(decoder);
         ERR_raise(ERR_LIB_OSSL_DECODER, ERR_R_INVALID_PROVIDER_FUNCTIONS);
         return NULL;
     }
 
     if (prov != NULL && !ossl_provider_up_ref(prov)) {
-        ossl_decoder_free(decoder);
+        OSSL_DECODER_free(decoder);
         return NULL;
     }
 
@@ -317,7 +296,7 @@ void *ossl_decoder_from_algorithm(int id, const OSSL_ALGORITHM *algodef,
  * then call ossl_decoder_from_algorithm() with that identity number.
  */
 static void *construct_decoder(const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, void *data, int no_store)
+    OSSL_PROVIDER *prov, void *data)
 {
     /*
      * This function is only called if get_decoder_from_store() returned
@@ -333,7 +312,7 @@ static void *construct_decoder(const OSSL_ALGORITHM *algodef,
     void *method = NULL;
 
     if (id != 0)
-        method = ossl_decoder_from_algorithm(id, algodef, prov, no_store);
+        method = ossl_decoder_from_algorithm(id, algodef, prov);
 
     /*
      * Flag to indicate that there was actual construction errors.  This
@@ -349,7 +328,17 @@ static void *construct_decoder(const OSSL_ALGORITHM *algodef,
 /* Intermediary function to avoid ugly casts, used below */
 static void destruct_decoder(void *method, void *data)
 {
-    ossl_decoder_free(method);
+    OSSL_DECODER_free(method);
+}
+
+static int up_ref_decoder(void *method)
+{
+    return OSSL_DECODER_up_ref(method);
+}
+
+static void free_decoder(void *method)
+{
+    OSSL_DECODER_free(method);
 }
 
 /* Fetching support.  Can fetch by numeric identity or by name */
@@ -405,22 +394,9 @@ inner_ossl_decoder_fetch(struct decoder_data_st *methdata,
              */
             if (id == 0 && name != NULL)
                 id = ossl_namemap_name2num(namemap, name);
-            if (id != 0 && methdata->tmp_store == NULL) {
+            if (id != 0)
                 ossl_method_store_cache_set(store, prov, id, propq, method,
-                    ossl_decoder_up_ref, ossl_decoder_free);
-            } else {
-                /*
-                 * Like with EVP methods, if the provider requests no caching we need
-                 * to take an extra refcount here so that the tmp_stored decoder
-                 * lives beyond the freeing of that tmp_store
-                 */
-#ifndef OPENSSL_NO_CACHED_FETCH
-                if (!OSSL_DECODER_up_ref((OSSL_DECODER *)method)) {
-                    ossl_decoder_free(method);
-                    method = NULL;
-                }
-#endif
-            }
+                    up_ref_decoder, free_decoder, NULL, NULL);
         }
 
         /*
diff --git a/crypto/encode_decode/decoder_pkey.c b/crypto/encode_decode/decoder_pkey.c
index 047295b20b..2704ad2656 100644
--- a/crypto/encode_decode/decoder_pkey.c
+++ b/crypto/encode_decode/decoder_pkey.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -276,10 +276,9 @@ static int collect_decoder_keymgmt(EVP_KEYMGMT *keymgmt, OSSL_DECODER *decoder,
     OSSL_TRACE_BEGIN(DECODER)
     {
         BIO_printf(trc_out,
-            "(ctx %p) Checking out decoder %p (%s):\n"
+            "(ctx %p) Checking out decoder %p:\n"
             "    %s with %s\n",
             (void *)data->ctx, (void *)decoder,
-            OSSL_DECODER_get0_description(decoder),
             OSSL_DECODER_get0_name(decoder),
             OSSL_DECODER_get0_properties(decoder));
     }
@@ -338,10 +337,9 @@ static void collect_decoder(OSSL_DECODER *decoder, void *arg)
     OSSL_TRACE_BEGIN(DECODER)
     {
         BIO_printf(trc_out,
-            "(ctx %p) Checking out decoder %p (%s):\n"
+            "(ctx %p) Checking out decoder %p:\n"
             "    %s with %s\n",
             (void *)data->ctx, (void *)decoder,
-            OSSL_DECODER_get0_description(decoder),
             OSSL_DECODER_get0_name(decoder),
             OSSL_DECODER_get0_properties(decoder));
     }
@@ -419,13 +417,6 @@ static void collect_keymgmt(EVP_KEYMGMT *keymgmt, void *arg)
     if (!EVP_KEYMGMT_up_ref(keymgmt))
         return;
 
-    OSSL_TRACE_BEGIN(DECODER)
-    {
-        BIO_printf(trc_out,
-            "(Collecting KeyManager %s %s [id %d]:\n",
-            keymgmt->description, keymgmt->type_name, keymgmt->id);
-    }
-    OSSL_TRACE_END(DECODER);
     if (sk_EVP_KEYMGMT_push(data->keymgmts, keymgmt) <= 0) {
         EVP_KEYMGMT_free(keymgmt);
         data->error_occurred = 1;
diff --git a/crypto/encode_decode/encoder_err.c b/crypto/encode_decode/encoder_err.c
index 1def566f00..79b12f9c31 100644
--- a/crypto/encode_decode/encoder_err.c
+++ b/crypto/encode_decode/encoder_err.c
@@ -1,6 +1,6 @@
 /*
  * Generated by util/mkerr.pl DO NOT EDIT
- * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,16 +15,12 @@
 #ifndef OPENSSL_NO_ERR
 
 static const ERR_STRING_DATA OSSL_ENCODER_str_reasons[] = {
-    { ERR_PACK(ERR_LIB_OSSL_ENCODER, 0, OSSL_ENCODER_R_BAD_PARAMETER_VALUE),
-        "bad parameter value" },
     { ERR_PACK(ERR_LIB_OSSL_ENCODER, 0, OSSL_ENCODER_R_ENCODER_NOT_FOUND),
         "encoder not found" },
     { ERR_PACK(ERR_LIB_OSSL_ENCODER, 0, OSSL_ENCODER_R_INCORRECT_PROPERTY_QUERY),
         "incorrect property query" },
     { ERR_PACK(ERR_LIB_OSSL_ENCODER, 0, OSSL_ENCODER_R_MISSING_GET_PARAMS),
         "missing get params" },
-    { ERR_PACK(ERR_LIB_OSSL_ENCODER, 0, OSSL_ENCODER_R_UNKNOWN_PARAMETER_NAME),
-        "unknown parameter name" },
     { 0, NULL }
 };
 
diff --git a/crypto/encode_decode/encoder_local.h b/crypto/encode_decode/encoder_local.h
index 6ebbe1c513..a35c6174db 100644
--- a/crypto/encode_decode/encoder_local.h
+++ b/crypto/encode_decode/encoder_local.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_ENCODE_DECODE_ENCODER_LOCAL_H)
-#define OSSL_LIBCRYPTO_ENCODE_DECODE_ENCODER_LOCAL_H
-
 #include 
 #include 
 #include 
@@ -24,7 +21,6 @@
 struct ossl_endecode_base_st {
     OSSL_PROVIDER *prov;
     int id;
-    int no_store;
     char *name;
     const OSSL_ALGORITHM *algodef;
     OSSL_PROPERTY_LIST *parsed_propdef;
@@ -181,5 +177,3 @@ ossl_encoder_parsed_properties(const OSSL_ENCODER *encoder);
 
 int ossl_decoder_fast_is_a(OSSL_DECODER *decoder,
     const char *name, int *id_cache);
-
-#endif /* !defined(OSSL_LIBCRYPTO_ENCODE_DECODE_ENCODER_LOCAL_H) */
diff --git a/crypto/encode_decode/encoder_meth.c b/crypto/encode_decode/encoder_meth.c
index cb167004ab..c87935ba65 100644
--- a/crypto/encode_decode/encoder_meth.c
+++ b/crypto/encode_decode/encoder_meth.c
@@ -10,7 +10,6 @@
 #include 
 #include 
 #include 
-#include 
 #include 
 #include "internal/core.h"
 #include "internal/namemap.h"
@@ -27,28 +26,12 @@
 
 static void ossl_encoder_free(void *data)
 {
-    OSSL_ENCODER *encoder = (OSSL_ENCODER *)data;
-    int ref = 0;
-
-    if (encoder == NULL)
-        return;
-
-    CRYPTO_DOWN_REF(&encoder->base.refcnt, &ref);
-    if (ref > 0)
-        return;
-    OPENSSL_free(encoder->base.name);
-    ossl_property_free(encoder->base.parsed_propdef);
-    ossl_provider_free(encoder->base.prov);
-    CRYPTO_FREE_REF(&encoder->base.refcnt);
-    OPENSSL_free(encoder);
+    OSSL_ENCODER_free(data);
 }
 
 static int ossl_encoder_up_ref(void *data)
 {
-    OSSL_ENCODER *encoder = (OSSL_ENCODER *)data;
-    int ref = 0;
-
-    return CRYPTO_UP_REF(&encoder->base.refcnt, &ref);
+    return OSSL_ENCODER_up_ref(data);
 }
 
 /* Simple method structure constructor and destructor */
@@ -68,23 +51,27 @@ static OSSL_ENCODER *ossl_encoder_new(void)
 
 int OSSL_ENCODER_up_ref(OSSL_ENCODER *encoder)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    return ossl_encoder_up_ref(encoder);
-#else
-    if (encoder->base.no_store != 0)
-        return ossl_encoder_up_ref(encoder);
+    int ref = 0;
+
+    CRYPTO_UP_REF(&encoder->base.refcnt, &ref);
     return 1;
-#endif
 }
 
 void OSSL_ENCODER_free(OSSL_ENCODER *encoder)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    ossl_encoder_free(encoder);
-#else
-    if (encoder != NULL && (encoder->base.no_store != 0))
-        ossl_encoder_free(encoder);
-#endif
+    int ref = 0;
+
+    if (encoder == NULL)
+        return;
+
+    CRYPTO_DOWN_REF(&encoder->base.refcnt, &ref);
+    if (ref > 0)
+        return;
+    OPENSSL_free(encoder->base.name);
+    ossl_property_free(encoder->base.parsed_propdef);
+    ossl_provider_free(encoder->base.prov);
+    CRYPTO_FREE_REF(&encoder->base.refcnt);
+    OPENSSL_free(encoder);
 }
 
 /* Data to be passed through ossl_method_construct() */
@@ -215,12 +202,12 @@ static int put_encoder_in_store(void *store, void *method,
 
     return ossl_method_store_add(store, prov, id, propdef, method,
         ossl_encoder_up_ref,
-        ossl_encoder_free);
+        ossl_encoder_free, NULL, NULL);
 }
 
 /* Create and populate a encoder method */
 static void *encoder_from_algorithm(int id, const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, int no_store)
+    OSSL_PROVIDER *prov)
 {
     OSSL_ENCODER *encoder = NULL;
     const OSSL_DISPATCH *fns = algodef->implementation;
@@ -229,16 +216,15 @@ static void *encoder_from_algorithm(int id, const OSSL_ALGORITHM *algodef,
     if ((encoder = ossl_encoder_new()) == NULL)
         return NULL;
     encoder->base.id = id;
-    encoder->base.no_store = no_store;
     if ((encoder->base.name = ossl_algorithm_get1_first_name(algodef)) == NULL) {
-        ossl_encoder_free(encoder);
+        OSSL_ENCODER_free(encoder);
         return NULL;
     }
     encoder->base.algodef = algodef;
     if ((encoder->base.parsed_propdef
             = ossl_parse_property(libctx, algodef->property_definition))
         == NULL) {
-        ossl_encoder_free(encoder);
+        OSSL_ENCODER_free(encoder);
         return NULL;
     }
 
@@ -296,13 +282,13 @@ static void *encoder_from_algorithm(int id, const OSSL_ALGORITHM *algodef,
             || (encoder->import_object != NULL && encoder->free_object != NULL)
             || (encoder->import_object == NULL && encoder->free_object == NULL))
         || encoder->encode == NULL) {
-        ossl_encoder_free(encoder);
+        OSSL_ENCODER_free(encoder);
         ERR_raise(ERR_LIB_OSSL_ENCODER, ERR_R_INVALID_PROVIDER_FUNCTIONS);
         return NULL;
     }
 
     if (prov != NULL && !ossl_provider_up_ref(prov)) {
-        ossl_encoder_free(encoder);
+        OSSL_ENCODER_free(encoder);
         return NULL;
     }
 
@@ -316,7 +302,7 @@ static void *encoder_from_algorithm(int id, const OSSL_ALGORITHM *algodef,
  * then call encoder_from_algorithm() with that identity number.
  */
 static void *construct_encoder(const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, void *data, int no_store)
+    OSSL_PROVIDER *prov, void *data)
 {
     /*
      * This function is only called if get_encoder_from_store() returned
@@ -332,7 +318,7 @@ static void *construct_encoder(const OSSL_ALGORITHM *algodef,
     void *method = NULL;
 
     if (id != 0)
-        method = encoder_from_algorithm(id, algodef, prov, no_store);
+        method = encoder_from_algorithm(id, algodef, prov);
 
     /*
      * Flag to indicate that there was actual construction errors.  This
@@ -348,7 +334,17 @@ static void *construct_encoder(const OSSL_ALGORITHM *algodef,
 /* Intermediary function to avoid ugly casts, used below */
 static void destruct_encoder(void *method, void *data)
 {
-    ossl_encoder_free(method);
+    OSSL_ENCODER_free(method);
+}
+
+static int up_ref_encoder(void *method)
+{
+    return OSSL_ENCODER_up_ref(method);
+}
+
+static void free_encoder(void *method)
+{
+    OSSL_ENCODER_free(method);
 }
 
 /* Fetching support.  Can fetch by numeric identity or by name */
@@ -367,7 +363,7 @@ inner_ossl_encoder_fetch(struct encoder_data_st *methdata,
         return NULL;
     }
 
-    id = ossl_namemap_name2num(namemap, name);
+    id = name != NULL ? ossl_namemap_name2num(namemap, name) : 0;
 
     /*
      * If we haven't found the name yet, chances are that the algorithm to
@@ -404,19 +400,8 @@ inner_ossl_encoder_fetch(struct encoder_data_st *methdata,
              */
             if (id == 0)
                 id = ossl_namemap_name2num(namemap, name);
-            if (id != 0 && methdata->tmp_store == NULL) {
-                ossl_method_store_cache_set(store, prov, id, propq, method,
-                    ossl_encoder_up_ref, ossl_encoder_free);
-            } else {
-                /*
-                 * Like with EVP methods, if the provider requests no caching we need
-                 * to take an extra refcount here so that the tmp_stored encoder
-                 * lives beyond the freeing of that tmp_store
-                 */
-#ifndef OPENSSL_NO_CACHED_FETCH
-                OSSL_ENCODER_up_ref((OSSL_ENCODER *)method);
-#endif
-            }
+            ossl_method_store_cache_set(store, prov, id, propq, method,
+                up_ref_encoder, free_encoder, NULL, NULL);
         }
 
         /*
@@ -657,55 +642,6 @@ int OSSL_ENCODER_CTX_set_params(OSSL_ENCODER_CTX *ctx,
     return ok;
 }
 
-int OSSL_ENCODER_CTX_ctrl_string(OSSL_ENCODER_CTX *ctx,
-    const char *name, const char *value)
-{
-    const OSSL_PARAM *settable = NULL;
-    int i, n, ok = 0;
-
-    if (!ossl_assert(ctx != NULL)) {
-        ERR_raise(ERR_LIB_OSSL_ENCODER, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
-    if (ctx->encoder_insts == NULL)
-        return 1;
-
-    n = OSSL_ENCODER_CTX_get_num_encoders(ctx);
-    for (i = 0; i < n; i++) {
-        OSSL_ENCODER_INSTANCE *encoder_inst = sk_OSSL_ENCODER_INSTANCE_value(ctx->encoder_insts, i);
-        OSSL_ENCODER *encoder = OSSL_ENCODER_INSTANCE_get_encoder(encoder_inst);
-        void *encoderctx = OSSL_ENCODER_INSTANCE_get_encoder_ctx(encoder_inst);
-        OSSL_PARAM params[2] = { OSSL_PARAM_END, OSSL_PARAM_END };
-        int good = 0;
-
-        if (encoderctx == NULL || encoder->set_ctx_params == NULL)
-            continue;
-
-        settable = OSSL_ENCODER_settable_ctx_params(encoder);
-        if (settable == NULL)
-            continue;
-        if (!OSSL_PARAM_allocate_from_text(params, settable, name, value,
-                strlen(value), &good)) {
-            if (!good)
-                continue;
-            ERR_raise_data(ERR_LIB_OSSL_ENCODER, OSSL_ENCODER_R_BAD_PARAMETER_VALUE,
-                "bad encoder parameter value: %s:%s", name, value);
-            return 0;
-        }
-        good = encoder->set_ctx_params(encoderctx, params);
-        OPENSSL_free(params[0].data);
-        if (!good)
-            return 0;
-        ++ok;
-    }
-    if (!ok) {
-        ERR_raise_data(ERR_LIB_OSSL_ENCODER, OSSL_ENCODER_R_UNKNOWN_PARAMETER_NAME,
-            "unknown encoder parameter name: %s", name);
-    }
-    return ok;
-}
-
 void OSSL_ENCODER_CTX_free(OSSL_ENCODER_CTX *ctx)
 {
     if (ctx != NULL) {
diff --git a/crypto/err/err.c b/crypto/err/err.c
index bf637e1d45..e9920f00e3 100644
--- a/crypto/err/err.c
+++ b/crypto/err/err.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,6 +7,8 @@
  * https://www.openssl.org/source/license.html
  */
 
+#define OSSL_FORCE_ERR_STATE
+
 #include 
 #include 
 #include 
@@ -25,6 +27,9 @@
 #include "internal/e_os.h"
 #include "err_local.h"
 
+/* Forward declaration in case it's not published because of configuration */
+ERR_STATE *ERR_get_state(void);
+
 #ifndef OPENSSL_NO_ERR
 static int err_load_strings(const ERR_STRING_DATA *str);
 #endif
@@ -328,7 +333,7 @@ void ERR_clear_error(void)
     int i;
     ERR_STATE *es;
 
-    es = ossl_err_get_state_int(0);
+    es = ossl_err_get_state_int();
     if (es == NULL)
         return;
 
@@ -442,7 +447,7 @@ static unsigned long get_error_values(ERR_GET_ACTION g,
     ERR_STATE *es;
     unsigned long ret;
 
-    es = ossl_err_get_state_int(1);
+    es = ossl_err_get_state_int();
     if (es == NULL)
         return 0;
 
@@ -645,13 +650,22 @@ static void err_delete_thread_state(void *unused)
     OSSL_ERR_STATE_free(state);
 }
 
-ERR_STATE *ossl_err_get_state_int(int save_sys_error)
+#ifndef OPENSSL_NO_DEPRECATED_1_1_0
+void ERR_remove_thread_state(void *dummy)
+{
+}
+#endif
+
+#ifndef OPENSSL_NO_DEPRECATED_1_0_0
+void ERR_remove_state(unsigned long pid)
+{
+}
+#endif
+
+ERR_STATE *ossl_err_get_state_int(void)
 {
     ERR_STATE *state;
-    int saveerrno = 0;
-
-    if (save_sys_error)
-        saveerrno = get_last_sys_error();
+    int saveerrno = get_last_sys_error();
 
     if (!OPENSSL_init_crypto(OPENSSL_INIT_BASE_ONLY, NULL))
         return NULL;
@@ -686,11 +700,17 @@ ERR_STATE *ossl_err_get_state_int(int save_sys_error)
         OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CRYPTO_STRINGS, NULL);
     }
 
-    if (save_sys_error)
-        set_sys_error(saveerrno);
+    set_sys_error(saveerrno);
     return state;
 }
 
+#ifndef OPENSSL_NO_DEPRECATED_3_0
+ERR_STATE *ERR_get_state(void)
+{
+    return ossl_err_get_state_int();
+}
+#endif
+
 /*
  * err_shelve_state returns the current thread local error state
  * and freezes the error module until err_unshelve_state is called.
@@ -754,7 +774,7 @@ static int err_set_error_data_int(char *data, size_t size, int flags,
 {
     ERR_STATE *es;
 
-    es = ossl_err_get_state_int(1);
+    es = ossl_err_get_state_int();
     if (es == NULL)
         return 0;
 
@@ -800,7 +820,7 @@ void ERR_add_error_vdata(int num, va_list args)
     ERR_STATE *es;
 
     /* Get the current error data; if an allocated string get it. */
-    es = ossl_err_get_state_int(1);
+    es = ossl_err_get_state_int();
     if (es == NULL)
         return;
     i = es->top;
@@ -857,7 +877,7 @@ void err_clear_last_constant_time(int clear)
     ERR_STATE *es;
     int top;
 
-    es = ossl_err_get_state_int(0);
+    es = ossl_err_get_state_int();
     if (es == NULL)
         return;
 
diff --git a/crypto/err/err_all.c b/crypto/err/err_all.c
index 7761410f2d..be3d91280a 100644
--- a/crypto/err/err_all.c
+++ b/crypto/err/err_all.c
@@ -39,7 +39,6 @@
 #include "crypto/cmperr.h"
 #include "crypto/cterr.h"
 #include "crypto/asyncerr.h"
-#include "crypto/sm2err.h"
 #include "crypto/storeerr.h"
 #include "crypto/esserr.h"
 #include "internal/propertyerr.h"
@@ -101,9 +100,6 @@ int ossl_err_load_crypto_strings(void)
 #endif
         || ossl_err_load_ESS_strings() == 0
         || ossl_err_load_ASYNC_strings() == 0
-#ifndef OPENSSL_NO_SM2
-        || ossl_err_load_SM2_strings() == 0
-#endif
         || ossl_err_load_OSSL_STORE_strings() == 0
         || ossl_err_load_PROP_strings() == 0
         || ossl_err_load_PROV_strings() == 0
diff --git a/crypto/err/err_blocks.c b/crypto/err/err_blocks.c
index 90451ea880..a658df0576 100644
--- a/crypto/err/err_blocks.c
+++ b/crypto/err/err_blocks.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2019-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,6 +7,8 @@
  * https://www.openssl.org/source/license.html
  */
 
+#define OSSL_FORCE_ERR_STATE
+
 #include 
 #include 
 #include "err_local.h"
@@ -15,7 +17,7 @@ void ERR_new(void)
 {
     ERR_STATE *es;
 
-    es = ossl_err_get_state_int(1);
+    es = ossl_err_get_state_int();
     if (es == NULL)
         return;
 
@@ -28,7 +30,7 @@ void ERR_set_debug(const char *file, int line, const char *func)
 {
     ERR_STATE *es;
 
-    es = ossl_err_get_state_int(1);
+    es = ossl_err_get_state_int();
     if (es == NULL)
         return;
 
@@ -52,7 +54,7 @@ void ERR_vset_error(int lib, int reason, const char *fmt, va_list args)
     unsigned long flags = 0;
     size_t i;
 
-    es = ossl_err_get_state_int(1);
+    es = ossl_err_get_state_int();
     if (es == NULL)
         return;
     i = es->top;
diff --git a/crypto/err/err_local.h b/crypto/err/err_local.h
index 99aa5c7632..4d30059386 100644
--- a/crypto/err/err_local.h
+++ b/crypto/err/err_local.h
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,29 +7,9 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_ERR_ERR_LOCAL_H)
-#define OSSL_LIBCRYPTO_ERR_ERR_LOCAL_H
-
 #include 
 #include 
 #include 
-#include "internal/err.h"
-
-#define ERR_FLAG_MARK 0x01
-#define ERR_FLAG_CLEAR 0x02
-
-struct err_state_st {
-    int err_flags[ERR_NUM_ERRORS];
-    int err_marks[ERR_NUM_ERRORS];
-    unsigned long err_buffer[ERR_NUM_ERRORS];
-    char *err_data[ERR_NUM_ERRORS];
-    size_t err_data_size[ERR_NUM_ERRORS];
-    int err_data_flags[ERR_NUM_ERRORS];
-    char *err_file[ERR_NUM_ERRORS];
-    int err_line[ERR_NUM_ERRORS];
-    char *err_func[ERR_NUM_ERRORS];
-    int top, bottom;
-};
 
 static ossl_inline void err_get_slot(ERR_STATE *es)
 {
@@ -115,8 +95,6 @@ static ossl_inline void err_clear(ERR_STATE *es, size_t i, int deall)
     es->err_func[i] = NULL;
 }
 
-ERR_STATE *ossl_err_get_state_int(int save_sys_error);
+ERR_STATE *ossl_err_get_state_int(void);
 void ossl_err_string_int(unsigned long e, const char *func,
     char *buf, size_t len);
-
-#endif /* !defined(OSSL_LIBCRYPTO_ERR_ERR_LOCAL_H) */
diff --git a/crypto/err/err_mark.c b/crypto/err/err_mark.c
index 29aef24a12..33fa6b2127 100644
--- a/crypto/err/err_mark.c
+++ b/crypto/err/err_mark.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2003-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2003-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,6 +7,8 @@
  * https://www.openssl.org/source/license.html
  */
 
+#define OSSL_FORCE_ERR_STATE
+
 #include 
 #include "err_local.h"
 
@@ -14,7 +16,7 @@ int ERR_set_mark(void)
 {
     ERR_STATE *es;
 
-    es = ossl_err_get_state_int(0);
+    es = ossl_err_get_state_int();
     if (es == NULL)
         return 0;
 
@@ -28,7 +30,7 @@ int ERR_pop(void)
 {
     ERR_STATE *es;
 
-    es = ossl_err_get_state_int(0);
+    es = ossl_err_get_state_int();
     if (es == NULL || es->bottom == es->top)
         return 0;
 
@@ -41,7 +43,7 @@ int ERR_pop_to_mark(void)
 {
     ERR_STATE *es;
 
-    es = ossl_err_get_state_int(0);
+    es = ossl_err_get_state_int();
     if (es == NULL)
         return 0;
 
@@ -62,7 +64,7 @@ int ERR_count_to_mark(void)
     ERR_STATE *es;
     int count = 0, top;
 
-    es = ossl_err_get_state_int(1);
+    es = ossl_err_get_state_int();
     if (es == NULL)
         return 0;
 
@@ -81,7 +83,7 @@ int ERR_clear_last_mark(void)
     ERR_STATE *es;
     int top;
 
-    es = ossl_err_get_state_int(0);
+    es = ossl_err_get_state_int();
     if (es == NULL)
         return 0;
 
diff --git a/crypto/err/err_prn.c b/crypto/err/err_prn.c
index b4970da437..907cbc22ef 100644
--- a/crypto/err/err_prn.c
+++ b/crypto/err/err_prn.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,6 +7,8 @@
  * https://www.openssl.org/source/license.html
  */
 
+#define OSSL_FORCE_ERR_STATE
+
 #include 
 #include "internal/cryptlib.h"
 #include 
diff --git a/crypto/err/err_save.c b/crypto/err/err_save.c
index 62f5d752dc..ab58081fef 100644
--- a/crypto/err/err_save.c
+++ b/crypto/err/err_save.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,6 +7,8 @@
  * https://www.openssl.org/source/license.html
  */
 
+#define OSSL_FORCE_ERR_STATE
+
 #include 
 #include "err_local.h"
 
@@ -32,7 +34,7 @@ void OSSL_ERR_STATE_save(ERR_STATE *es)
     for (i = 0; i < ERR_NUM_ERRORS; i++)
         err_clear(es, i, 1);
 
-    thread_es = ossl_err_get_state_int(1);
+    thread_es = ossl_err_get_state_int();
     if (thread_es == NULL)
         return;
 
@@ -50,7 +52,7 @@ void OSSL_ERR_STATE_save_to_mark(ERR_STATE *es)
     if (es == NULL)
         return;
 
-    thread_es = ossl_err_get_state_int(1);
+    thread_es = ossl_err_get_state_int();
     if (thread_es == NULL) {
         for (i = 0; i < ERR_NUM_ERRORS; ++i)
             err_clear(es, i, 1);
@@ -116,7 +118,7 @@ void OSSL_ERR_STATE_restore(const ERR_STATE *es)
     if (es == NULL || es->bottom == es->top)
         return;
 
-    thread_es = ossl_err_get_state_int(0);
+    thread_es = ossl_err_get_state_int();
     if (thread_es == NULL)
         return;
 
diff --git a/crypto/err/openssl.ec b/crypto/err/openssl.ec
index 91aa11d1a6..a3fce49548 100644
--- a/crypto/err/openssl.ec
+++ b/crypto/err/openssl.ec
@@ -45,19 +45,19 @@ L OSSL_DECODER  include/openssl/decodererr.h    crypto/encode_decode/decoder_err
 L HTTP          include/openssl/httperr.h       crypto/http/http_err.c                  include/crypto/httperr.h
 
 # SSL/TLS alerts
-R SSL_R_TLS_ALERT_UNEXPECTED_MESSAGE            1010
-R SSL_R_TLS_ALERT_BAD_RECORD_MAC                1020
+R SSL_R_SSLV3_ALERT_UNEXPECTED_MESSAGE          1010
+R SSL_R_SSLV3_ALERT_BAD_RECORD_MAC              1020
 R SSL_R_TLSV1_ALERT_DECRYPTION_FAILED           1021
 R SSL_R_TLSV1_ALERT_RECORD_OVERFLOW             1022
-R SSL_R_TLS_ALERT_DECOMPRESSION_FAILURE         1030
-R SSL_R_TLS_ALERT_HANDSHAKE_FAILURE             1040
-R SSL_R_TLS_ALERT_NO_CERTIFICATE                1041
-R SSL_R_TLS_ALERT_BAD_CERTIFICATE               1042
-R SSL_R_TLS_ALERT_UNSUPPORTED_CERTIFICATE       1043
-R SSL_R_TLS_ALERT_CERTIFICATE_REVOKED           1044
-R SSL_R_TLS_ALERT_CERTIFICATE_EXPIRED           1045
-R SSL_R_TLS_ALERT_CERTIFICATE_UNKNOWN           1046
-R SSL_R_TLS_ALERT_ILLEGAL_PARAMETER             1047
+R SSL_R_SSLV3_ALERT_DECOMPRESSION_FAILURE       1030
+R SSL_R_SSLV3_ALERT_HANDSHAKE_FAILURE           1040
+R SSL_R_SSLV3_ALERT_NO_CERTIFICATE              1041
+R SSL_R_SSLV3_ALERT_BAD_CERTIFICATE             1042
+R SSL_R_SSLV3_ALERT_UNSUPPORTED_CERTIFICATE     1043
+R SSL_R_SSLV3_ALERT_CERTIFICATE_REVOKED         1044
+R SSL_R_SSLV3_ALERT_CERTIFICATE_EXPIRED         1045
+R SSL_R_SSLV3_ALERT_CERTIFICATE_UNKNOWN         1046
+R SSL_R_SSLV3_ALERT_ILLEGAL_PARAMETER           1047
 R SSL_R_TLSV1_ALERT_UNKNOWN_CA                  1048
 R SSL_R_TLSV1_ALERT_ACCESS_DENIED               1049
 R SSL_R_TLSV1_ALERT_DECODE_ERROR                1050
diff --git a/crypto/err/openssl.txt b/crypto/err/openssl.txt
index 8b6c912977..70e06a6a38 100644
--- a/crypto/err/openssl.txt
+++ b/crypto/err/openssl.txt
@@ -1,4 +1,4 @@
-# Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+# Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
 #
 # Licensed under the Apache License 2.0 (the "License").  You may not use
 # this file except in compliance with the License.  You can obtain a copy
@@ -700,7 +700,6 @@ EVP_R_CIPHER_NOT_GCM_MODE:184:cipher not gcm mode
 EVP_R_CIPHER_PARAMETER_ERROR:122:cipher parameter error
 EVP_R_COMMAND_NOT_SUPPORTED:147:command not supported
 EVP_R_CONFLICTING_ALGORITHM_NAME:201:conflicting algorithm name
-EVP_R_CONTEXT_FINALIZED:239:context finalized
 EVP_R_COPY_ERROR:173:copy error
 EVP_R_CTRL_NOT_IMPLEMENTED:132:ctrl not implemented
 EVP_R_CTRL_OPERATION_NOT_IMPLEMENTED:133:ctrl operation not implemented
@@ -820,7 +819,6 @@ EVP_R_XTS_DATA_UNIT_IS_TOO_LARGE:191:xts data unit is too large
 EVP_R_XTS_DUPLICATED_KEYS:192:xts duplicated keys
 HTTP_R_ASN1_LEN_EXCEEDS_MAX_RESP_LEN:108:asn1 len exceeds max resp len
 HTTP_R_CONNECT_FAILURE:100:connect failure
-HTTP_R_CONTENT_TYPE_MISMATCH:131:content type mismatch
 HTTP_R_ERROR_PARSING_ASN1_LENGTH:109:error parsing asn1 length
 HTTP_R_ERROR_PARSING_CONTENT_LENGTH:119:error parsing content length
 HTTP_R_ERROR_PARSING_URL:101:error parsing url
@@ -883,11 +881,9 @@ OCSP_R_UNSUPPORTED_REQUESTORNAME_TYPE:129:unsupported requestorname type
 OSSL_DECODER_R_COULD_NOT_DECODE_OBJECT:101:could not decode object
 OSSL_DECODER_R_DECODER_NOT_FOUND:102:decoder not found
 OSSL_DECODER_R_MISSING_GET_PARAMS:100:missing get params
-OSSL_ENCODER_R_BAD_PARAMETER_VALUE:103:bad parameter value
 OSSL_ENCODER_R_ENCODER_NOT_FOUND:101:encoder not found
 OSSL_ENCODER_R_INCORRECT_PROPERTY_QUERY:100:incorrect property query
 OSSL_ENCODER_R_MISSING_GET_PARAMS:102:missing get params
-OSSL_ENCODER_R_UNKNOWN_PARAMETER_NAME:104:unknown parameter name
 OSSL_STORE_R_AMBIGUOUS_CONTENT_TYPE:107:ambiguous content type
 OSSL_STORE_R_BAD_PASSWORD_READ:115:bad password read
 OSSL_STORE_R_ERROR_VERIFYING_PKCS12_MAC:113:error verifying pkcs12 mac
@@ -1064,7 +1060,6 @@ PROV_R_INIT_CALL_OUT_OF_ORDER:238:init call out of order
 PROV_R_INSUFFICIENT_DRBG_STRENGTH:181:insufficient drbg strength
 PROV_R_INVALID_AAD:108:invalid aad
 PROV_R_INVALID_AEAD:231:invalid aead
-PROV_R_INVALID_CIPHER:260:invalid cipher
 PROV_R_INVALID_CONFIG_DATA:211:invalid config data
 PROV_R_INVALID_CONSTANT_LENGTH:157:invalid constant length
 PROV_R_INVALID_CURVE:176:invalid curve
@@ -1075,28 +1070,21 @@ PROV_R_INVALID_DIGEST_LENGTH:166:invalid digest length
 PROV_R_INVALID_DIGEST_SIZE:218:invalid digest size
 PROV_R_INVALID_EDDSA_INSTANCE_FOR_ATTEMPTED_OPERATION:243:\
 	invalid eddsa instance for attempted operation
-PROV_R_INVALID_FUNCTION_NAME:258:invalid function name
-PROV_R_INVALID_INDEX_LENGTH:259:invalid index length
 PROV_R_INVALID_INPUT_LENGTH:230:invalid input length
 PROV_R_INVALID_ITERATION_COUNT:123:invalid iteration count
 PROV_R_INVALID_IV_LENGTH:109:invalid iv length
 PROV_R_INVALID_KDF:232:invalid kdf
-PROV_R_INVALID_KDR:256:invalid kdr
 PROV_R_INVALID_KEY:158:invalid key
 PROV_R_INVALID_KEY_LENGTH:105:invalid key length
-PROV_R_INVALID_LABEL:257:invalid label
 PROV_R_INVALID_MAC:151:invalid mac
 PROV_R_INVALID_MEMORY_SIZE:235:invalid memory size
 PROV_R_INVALID_MGF1_MD:167:invalid mgf1 md
 PROV_R_INVALID_MODE:125:invalid mode
-PROV_R_INVALID_NONCE_LENGTH:264:invalid nonce length
 PROV_R_INVALID_OUTPUT_LENGTH:217:invalid output length
 PROV_R_INVALID_PADDING_MODE:168:invalid padding mode
-PROV_R_INVALID_PARAMETERS_FOR_DKM:261:invalid parameters for dkm
 PROV_R_INVALID_PREHASHED_DIGEST_LENGTH:241:invalid prehashed digest length
 PROV_R_INVALID_PUBINFO:198:invalid pubinfo
 PROV_R_INVALID_SALT_LENGTH:112:invalid salt length
-PROV_R_INVALID_SECRET_LENGTH:265:invalid secret length
 PROV_R_INVALID_SEED_LENGTH:154:invalid seed length
 PROV_R_INVALID_SIGNATURE_SIZE:179:invalid signature size
 PROV_R_INVALID_STATE:212:invalid state
@@ -1106,7 +1094,6 @@ PROV_R_INVALID_THREAD_POOL_SIZE:234:invalid thread pool size
 PROV_R_INVALID_UKM_LENGTH:200:invalid ukm length
 PROV_R_INVALID_X931_DIGEST:170:invalid x931 digest
 PROV_R_IN_ERROR_STATE:192:in error state
-PROV_R_KEY_IMMUTABLE_ONCE_SET:266:key immutable once set
 PROV_R_KEY_SETUP_FAILED:101:key setup failed
 PROV_R_KEY_SIZE_TOO_SMALL:171:key size too small
 PROV_R_LENGTH_TOO_LARGE:202:length too large
@@ -1115,12 +1102,10 @@ PROV_R_MISSING_CEK_ALG:144:missing cek alg
 PROV_R_MISSING_CIPHER:155:missing cipher
 PROV_R_MISSING_CONFIG_DATA:213:missing config data
 PROV_R_MISSING_CONSTANT:156:missing constant
-PROV_R_MISSING_DKM:262:missing dkm
 PROV_R_MISSING_EID:255:missing eid
 PROV_R_MISSING_KEY:128:missing key
 PROV_R_MISSING_MAC:150:missing mac
 PROV_R_MISSING_MESSAGE_DIGEST:129:missing message digest
-PROV_R_MISSING_NONCE:263:missing nonce
 PROV_R_MISSING_OID:209:missing OID
 PROV_R_MISSING_PASS:130:missing pass
 PROV_R_MISSING_SALT:131:missing salt
@@ -1310,6 +1295,7 @@ RSA_R_RANDOMNESS_SOURCE_STRENGTH_INSUFFICIENT:180:\
 RSA_R_RSA_OPERATIONS_NOT_SUPPORTED:130:rsa operations not supported
 RSA_R_SLEN_CHECK_FAILED:136:salt length check failed
 RSA_R_SLEN_RECOVERY_FAILED:135:salt length recovery failed
+RSA_R_SSLV3_ROLLBACK_ATTACK:115:sslv3 rollback attack
 RSA_R_THE_ASN1_OBJECT_IDENTIFIER_IS_NOT_KNOWN_FOR_THIS_MD:116:\
 	the asn1 object identifier is not known for this md
 RSA_R_UNKNOWN_ALGORITHM_TYPE:117:unknown algorithm type
@@ -1355,7 +1341,6 @@ SSL_R_BAD_DH_VALUE:102:bad dh value
 SSL_R_BAD_DIGEST_LENGTH:111:bad digest length
 SSL_R_BAD_EARLY_DATA:233:bad early data
 SSL_R_BAD_ECC_CERT:304:bad ecc cert
-SSL_R_BAD_ECHCONFIG_EXTENSION:425:bad echconfig extension
 SSL_R_BAD_ECPOINT:306:bad ecpoint
 SSL_R_BAD_EXTENSION:110:bad extension
 SSL_R_BAD_HANDSHAKE_LENGTH:332:bad handshake length
@@ -1436,8 +1421,6 @@ SSL_R_DTLS_MESSAGE_TOO_BIG:334:dtls message too big
 SSL_R_DUPLICATE_COMPRESSION_ID:309:duplicate compression id
 SSL_R_ECC_CERT_NOT_FOR_SIGNING:318:ecc cert not for signing
 SSL_R_ECDH_REQUIRED_FOR_SUITEB_MODE:374:ecdh required for suiteb mode
-SSL_R_ECH_DECODE_ERROR:426:ech decode error
-SSL_R_ECH_REQUIRED:424:ech required
 SSL_R_EE_KEY_TOO_SMALL:399:ee key too small
 SSL_R_EMPTY_RAW_PUBLIC_KEY:349:empty raw public key
 SSL_R_EMPTY_SRTP_PROTECTION_PROFILE_LIST:354:empty srtp protection profile list
@@ -1601,6 +1584,23 @@ SSL_R_SRTP_COULD_NOT_ALLOCATE_PROFILES:362:srtp could not allocate profiles
 SSL_R_SRTP_PROTECTION_PROFILE_LIST_TOO_LONG:363:\
 	srtp protection profile list too long
 SSL_R_SRTP_UNKNOWN_PROTECTION_PROFILE:364:srtp unknown protection profile
+SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH:232:\
+	ssl3 ext invalid max fragment length
+SSL_R_SSL3_EXT_INVALID_SERVERNAME:319:ssl3 ext invalid servername
+SSL_R_SSL3_EXT_INVALID_SERVERNAME_TYPE:320:ssl3 ext invalid servername type
+SSL_R_SSL3_SESSION_ID_TOO_LONG:300:ssl3 session id too long
+SSL_R_SSLV3_ALERT_BAD_CERTIFICATE:1042:ssl/tls alert bad certificate
+SSL_R_SSLV3_ALERT_BAD_RECORD_MAC:1020:ssl/tls alert bad record mac
+SSL_R_SSLV3_ALERT_CERTIFICATE_EXPIRED:1045:ssl/tls alert certificate expired
+SSL_R_SSLV3_ALERT_CERTIFICATE_REVOKED:1044:ssl/tls alert certificate revoked
+SSL_R_SSLV3_ALERT_CERTIFICATE_UNKNOWN:1046:ssl/tls alert certificate unknown
+SSL_R_SSLV3_ALERT_DECOMPRESSION_FAILURE:1030:ssl/tls alert decompression failure
+SSL_R_SSLV3_ALERT_HANDSHAKE_FAILURE:1040:ssl/tls alert handshake failure
+SSL_R_SSLV3_ALERT_ILLEGAL_PARAMETER:1047:ssl/tls alert illegal parameter
+SSL_R_SSLV3_ALERT_NO_CERTIFICATE:1041:ssl/tls alert no certificate
+SSL_R_SSLV3_ALERT_UNEXPECTED_MESSAGE:1010:ssl/tls alert unexpected message
+SSL_R_SSLV3_ALERT_UNSUPPORTED_CERTIFICATE:1043:\
+	ssl/tls alert unsupported certificate
 SSL_R_SSL_COMMAND_SECTION_EMPTY:117:ssl command section empty
 SSL_R_SSL_COMMAND_SECTION_NOT_FOUND:125:ssl command section not found
 SSL_R_SSL_CTX_HAS_NO_DEFAULT_SSL_VERSION:228:ssl ctx has no default ssl version
@@ -1645,30 +1645,16 @@ SSL_R_TLSV1_BAD_CERTIFICATE_STATUS_RESPONSE:1113:\
 SSL_R_TLSV1_CERTIFICATE_UNOBTAINABLE:1111:tlsv1 certificate unobtainable
 SSL_R_TLSV1_UNRECOGNIZED_NAME:1112:tlsv1 unrecognized name
 SSL_R_TLSV1_UNSUPPORTED_EXTENSION:1110:tlsv1 unsupported extension
-SSL_R_TLS_ALERT_BAD_CERTIFICATE:1042:tls alert bad certificate
-SSL_R_TLS_ALERT_BAD_RECORD_MAC:1020:tls alert bad record mac
-SSL_R_TLS_ALERT_CERTIFICATE_EXPIRED:1045:tls alert certificate expired
-SSL_R_TLS_ALERT_CERTIFICATE_REVOKED:1044:tls alert certificate revoked
-SSL_R_TLS_ALERT_CERTIFICATE_UNKNOWN:1046:tls alert certificate unknown
-SSL_R_TLS_ALERT_DECOMPRESSION_FAILURE:1030:tls alert decompression failure
-SSL_R_TLS_ALERT_HANDSHAKE_FAILURE:1040:tls alert handshake failure
-SSL_R_TLS_ALERT_ILLEGAL_PARAMETER:1047:tls alert illegal parameter
-SSL_R_TLS_ALERT_NO_CERTIFICATE:1041:tls alert no certificate
-SSL_R_TLS_ALERT_UNEXPECTED_MESSAGE:1010:tls alert unexpected message
-SSL_R_TLS_ALERT_UNSUPPORTED_CERTIFICATE:1043:tls alert unsupported certificate
-SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH:232:\
-	tls ext invalid max fragment length
-SSL_R_TLS_EXT_INVALID_SERVERNAME:319:tls ext invalid servername
-SSL_R_TLS_EXT_INVALID_SERVERNAME_TYPE:320:tls ext invalid servername type
 SSL_R_TLS_ILLEGAL_EXPORTER_LABEL:367:tls illegal exporter label
 SSL_R_TLS_INVALID_ECPOINTFORMAT_LIST:157:tls invalid ecpointformat list
-SSL_R_TLS_SESSION_ID_TOO_LONG:300:tls session id too long
 SSL_R_TOO_MANY_KEY_UPDATES:132:too many key updates
 SSL_R_TOO_MANY_WARN_ALERTS:409:too many warn alerts
 SSL_R_TOO_MUCH_EARLY_DATA:164:too much early data
 SSL_R_UNABLE_TO_FIND_ECDH_PARAMETERS:314:unable to find ecdh parameters
 SSL_R_UNABLE_TO_FIND_PUBLIC_KEY_PARAMETERS:239:\
 	unable to find public key parameters
+SSL_R_UNABLE_TO_LOAD_SSL3_MD5_ROUTINES:242:unable to load ssl3 md5 routines
+SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES:243:unable to load ssl3 sha1 routines
 SSL_R_UNEXPECTED_CCS_MESSAGE:262:unexpected ccs message
 SSL_R_UNEXPECTED_END_OF_EARLY_DATA:178:unexpected end of early data
 SSL_R_UNEXPECTED_EOF_WHILE_READING:294:unexpected eof while reading
@@ -1850,7 +1836,6 @@ X509_R_CANT_CHECK_DH_KEY:114:can't check dh key
 X509_R_CERTIFICATE_VERIFICATION_FAILED:139:certificate verification failed
 X509_R_CERT_ALREADY_IN_HASH_TABLE:101:cert already in hash table
 X509_R_CRL_ALREADY_DELTA:127:crl already delta
-X509_R_CRL_SIGNATURE_ALGORITHM_MISMATCH:147:crl signature algorithm mismatch
 X509_R_CRL_VERIFY_FAILURE:131:crl verify failure
 X509_R_DUPLICATE_ATTRIBUTE:140:duplicate attribute
 X509_R_ERROR_GETTING_MD_BY_NID:141:error getting md by nid
@@ -1859,7 +1844,6 @@ X509_R_IDP_MISMATCH:128:idp mismatch
 X509_R_INVALID_ATTRIBUTES:138:invalid attributes
 X509_R_INVALID_DIRECTORY:113:invalid directory
 X509_R_INVALID_DISTPOINT:143:invalid distpoint
-X509_R_INVALID_EXTENSION:146:invalid extension
 X509_R_INVALID_FIELD_NAME:119:invalid field name
 X509_R_INVALID_TRUST:123:invalid trust
 X509_R_ISSUER_MISMATCH:129:issuer mismatch
diff --git a/crypto/ess/ess_asn1.c b/crypto/ess/ess_asn1.c
index 5a0978dfe0..297f2cead0 100644
--- a/crypto/ess/ess_asn1.c
+++ b/crypto/ess/ess_asn1.c
@@ -21,7 +21,7 @@ ASN1_SEQUENCE(ESS_ISSUER_SERIAL) = {
     ASN1_SIMPLE(ESS_ISSUER_SERIAL, serial, ASN1_INTEGER)
 } static_ASN1_SEQUENCE_END(ESS_ISSUER_SERIAL)
 
-IMPLEMENT_ASN1_FUNCTIONS(ESS_ISSUER_SERIAL)
+    IMPLEMENT_ASN1_FUNCTIONS(ESS_ISSUER_SERIAL)
 IMPLEMENT_ASN1_DUP_FUNCTION(ESS_ISSUER_SERIAL)
 
 ASN1_SEQUENCE(ESS_CERT_ID) = {
@@ -29,7 +29,7 @@ ASN1_SEQUENCE(ESS_CERT_ID) = {
     ASN1_OPT(ESS_CERT_ID, issuer_serial, ESS_ISSUER_SERIAL)
 } static_ASN1_SEQUENCE_END(ESS_CERT_ID)
 
-IMPLEMENT_ASN1_FUNCTIONS(ESS_CERT_ID)
+    IMPLEMENT_ASN1_FUNCTIONS(ESS_CERT_ID)
 IMPLEMENT_ASN1_DUP_FUNCTION(ESS_CERT_ID)
 
 ASN1_SEQUENCE(ESS_SIGNING_CERT) = {
@@ -46,7 +46,7 @@ ASN1_SEQUENCE(ESS_CERT_ID_V2) = {
     ASN1_OPT(ESS_CERT_ID_V2, issuer_serial, ESS_ISSUER_SERIAL)
 } static_ASN1_SEQUENCE_END(ESS_CERT_ID_V2)
 
-IMPLEMENT_ASN1_FUNCTIONS(ESS_CERT_ID_V2)
+    IMPLEMENT_ASN1_FUNCTIONS(ESS_CERT_ID_V2)
 IMPLEMENT_ASN1_DUP_FUNCTION(ESS_CERT_ID_V2)
 
 ASN1_SEQUENCE(ESS_SIGNING_CERT_V2) = {
diff --git a/crypto/ess/ess_lib.c b/crypto/ess/ess_lib.c
index 70efecae02..0486beffc4 100644
--- a/crypto/ess/ess_lib.c
+++ b/crypto/ess/ess_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -186,7 +186,12 @@ static ESS_CERT_ID_V2 *ESS_CERT_ID_V2_new_init(const EVP_MD *hash_alg,
 
     if (!EVP_MD_is_a(hash_alg, SN_sha256)) {
         alg = X509_ALGOR_new();
-        if (alg == NULL || !X509_ALGOR_set_md(alg, hash_alg) || alg->algorithm == NULL) {
+        if (alg == NULL) {
+            ERR_raise(ERR_LIB_ESS, ERR_R_ASN1_LIB);
+            goto err;
+        }
+        X509_ALGOR_set_md(alg, hash_alg);
+        if (alg->algorithm == NULL) {
             ERR_raise(ERR_LIB_ESS, ERR_R_ASN1_LIB);
             goto err;
         }
@@ -263,7 +268,7 @@ static int ess_issuer_serial_cmp(const ESS_ISSUER_SERIAL *is, const X509 *cert)
  * Return 0 on not found, -1 on error, else 1 + the position in |certs|.
  */
 static int find(const ESS_CERT_ID *cid, const ESS_CERT_ID_V2 *cid_v2,
-    int index, const STACK_OF(X509) *certs, OSSL_LIB_CTX *libctx, const char *propq)
+    int index, const STACK_OF(X509) *certs)
 {
     const X509 *cert;
     EVP_MD *md = NULL;
@@ -286,11 +291,18 @@ static int find(const ESS_CERT_ID *cid, const ESS_CERT_ID_V2 *cid_v2,
     else
         OBJ_obj2txt(name, sizeof(name), cid_v2->hash_alg->algorithm, 0);
 
-    md = EVP_MD_fetch(libctx, name, propq);
+    (void)ERR_set_mark();
+    md = EVP_MD_fetch(NULL, name, NULL);
+
+    if (md == NULL)
+        md = (EVP_MD *)EVP_get_digestbyname(name);
+
     if (md == NULL) {
+        (void)ERR_clear_last_mark();
         ERR_raise(ERR_LIB_ESS, ESS_R_ESS_DIGEST_ALG_UNKNOWN);
         goto end;
     }
+    (void)ERR_pop_to_mark();
 
     for (i = 0; i < sk_X509_num(certs); ++i) {
         cert = sk_X509_value(certs, i);
@@ -325,11 +337,9 @@ end:
     return ret;
 }
 
-int OSSL_ESS_check_signing_certs_ex(const ESS_SIGNING_CERT *ss,
+int OSSL_ESS_check_signing_certs(const ESS_SIGNING_CERT *ss,
     const ESS_SIGNING_CERT_V2 *ssv2,
     const STACK_OF(X509) *chain,
-    OSSL_LIB_CTX *libctx,
-    const char *propq,
     int require_signing_cert)
 {
     int n_v1 = ss == NULL ? -1 : sk_ESS_CERT_ID_num(ss->cert_ids);
@@ -346,23 +356,14 @@ int OSSL_ESS_check_signing_certs_ex(const ESS_SIGNING_CERT *ss,
     }
     /* If both ss and ssv2 exist, as required evaluate them independently. */
     for (i = 0; i < n_v1; i++) {
-        ret = find(sk_ESS_CERT_ID_value(ss->cert_ids, i), NULL, i, chain, libctx, propq);
+        ret = find(sk_ESS_CERT_ID_value(ss->cert_ids, i), NULL, i, chain);
         if (ret <= 0)
             return ret;
     }
     for (i = 0; i < n_v2; i++) {
-        ret = find(NULL, sk_ESS_CERT_ID_V2_value(ssv2->cert_ids, i), i, chain, libctx, propq);
+        ret = find(NULL, sk_ESS_CERT_ID_V2_value(ssv2->cert_ids, i), i, chain);
         if (ret <= 0)
             return ret;
     }
     return 1;
 }
-
-int OSSL_ESS_check_signing_certs(const ESS_SIGNING_CERT *ss,
-    const ESS_SIGNING_CERT_V2 *ssv2,
-    const STACK_OF(X509) *chain,
-    int require_signing_cert)
-{
-    return OSSL_ESS_check_signing_certs_ex(ss, ssv2, chain, NULL,
-        NULL, require_signing_cert);
-}
diff --git a/crypto/evp/asymcipher.c b/crypto/evp/asymcipher.c
index ec643bec9e..0860f1d8a6 100644
--- a/crypto/evp/asymcipher.c
+++ b/crypto/evp/asymcipher.c
@@ -17,28 +17,22 @@
 #include "crypto/evp.h"
 #include "evp_local.h"
 
-static void evp_asym_cipher_free(void *data)
+static void evp_asym_cipher_free_int(EVP_ASYM_CIPHER *cipher)
 {
-    EVP_ASYM_CIPHER *cipher = (EVP_ASYM_CIPHER *)data;
-    int i;
-
-    if (cipher == NULL)
-        return;
-    CRYPTO_DOWN_REF(&cipher->refcnt, &i);
-    if (i > 0)
-        return;
     OPENSSL_free(cipher->type_name);
     ossl_provider_free(cipher->prov);
     CRYPTO_FREE_REF(&cipher->refcnt);
     OPENSSL_free(cipher);
 }
 
+static void evp_asym_cipher_free(void *data)
+{
+    EVP_ASYM_CIPHER_free(data);
+}
+
 static int evp_asym_cipher_up_ref(void *data)
 {
-    EVP_ASYM_CIPHER *cipher = (EVP_ASYM_CIPHER *)data;
-    int ref = 0;
-
-    return CRYPTO_UP_REF(&cipher->refcnt, &ref);
+    return EVP_ASYM_CIPHER_up_ref(data);
 }
 
 static int evp_pkey_asym_cipher_init(EVP_PKEY_CTX *ctx, int operation,
@@ -64,7 +58,7 @@ static int evp_pkey_asym_cipher_init(EVP_PKEY_CTX *ctx, int operation,
     ERR_set_mark();
 
     if (evp_pkey_ctx_is_legacy(ctx))
-        goto err;
+        goto legacy;
 
     if (ctx->pkey == NULL) {
         ERR_clear_last_mark();
@@ -116,9 +110,7 @@ static int evp_pkey_asym_cipher_init(EVP_PKEY_CTX *ctx, int operation,
          * iteration we're on.
          */
         EVP_ASYM_CIPHER_free(cipher);
-        cipher = NULL;
         EVP_KEYMGMT_free(tmp_keymgmt);
-        tmp_keymgmt = NULL;
 
         switch (iter) {
         case 1:
@@ -132,7 +124,7 @@ static int evp_pkey_asym_cipher_init(EVP_PKEY_CTX *ctx, int operation,
             cipher = evp_asym_cipher_fetch_from_prov((OSSL_PROVIDER *)tmp_prov,
                 supported_ciph, ctx->propquery);
             if (cipher == NULL)
-                goto err;
+                goto legacy;
             break;
         }
         if (cipher == NULL)
@@ -160,7 +152,7 @@ static int evp_pkey_asym_cipher_init(EVP_PKEY_CTX *ctx, int operation,
 
     if (provkey == NULL) {
         EVP_ASYM_CIPHER_free(cipher);
-        goto err;
+        goto legacy;
     }
 
     ERR_pop_to_mark();
@@ -205,6 +197,35 @@ static int evp_pkey_asym_cipher_init(EVP_PKEY_CTX *ctx, int operation,
     EVP_KEYMGMT_free(tmp_keymgmt);
     return 1;
 
+legacy:
+    /*
+     * If we don't have the full support we need with provided methods,
+     * let's go see if legacy does.
+     */
+    ERR_pop_to_mark();
+    EVP_KEYMGMT_free(tmp_keymgmt);
+    tmp_keymgmt = NULL;
+
+    if (ctx->pmeth == NULL || ctx->pmeth->encrypt == NULL) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
+        return -2;
+    }
+    switch (ctx->operation) {
+    case EVP_PKEY_OP_ENCRYPT:
+        if (ctx->pmeth->encrypt_init == NULL)
+            return 1;
+        ret = ctx->pmeth->encrypt_init(ctx);
+        break;
+    case EVP_PKEY_OP_DECRYPT:
+        if (ctx->pmeth->decrypt_init == NULL)
+            return 1;
+        ret = ctx->pmeth->decrypt_init(ctx);
+        break;
+    default:
+        ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
+        ret = -1;
+    }
+
 err:
     if (ret <= 0) {
         evp_pkey_ctx_free_old_ops(ctx);
@@ -242,10 +263,9 @@ int EVP_PKEY_encrypt(EVP_PKEY_CTX *ctx,
         return -1;
     }
 
-    if (ctx->op.ciph.algctx == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
-        return -2;
-    }
+    if (ctx->op.ciph.algctx == NULL)
+        goto legacy;
+
     cipher = ctx->op.ciph.cipher;
     desc = cipher->description != NULL ? cipher->description : "";
     ERR_set_mark();
@@ -255,6 +275,13 @@ int EVP_PKEY_encrypt(EVP_PKEY_CTX *ctx,
             "%s encrypt:%s", cipher->type_name, desc);
     ERR_clear_last_mark();
     return ret;
+
+legacy:
+    if (ctx->pmeth == NULL || ctx->pmeth->encrypt == NULL) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
+        return -2;
+    }
+    M_check_autoarg(ctx, out, outlen, EVP_F_EVP_PKEY_ENCRYPT) return ctx->pmeth->encrypt(ctx, out, outlen, in, inlen);
 }
 
 int EVP_PKEY_decrypt_init(EVP_PKEY_CTX *ctx)
@@ -285,10 +312,8 @@ int EVP_PKEY_decrypt(EVP_PKEY_CTX *ctx,
         return -1;
     }
 
-    if (ctx->op.ciph.algctx == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
-        return -2;
-    }
+    if (ctx->op.ciph.algctx == NULL)
+        goto legacy;
 
     cipher = ctx->op.ciph.cipher;
     desc = cipher->description != NULL ? cipher->description : "";
@@ -300,6 +325,13 @@ int EVP_PKEY_decrypt(EVP_PKEY_CTX *ctx,
     ERR_clear_last_mark();
 
     return ret;
+
+legacy:
+    if (ctx->pmeth == NULL || ctx->pmeth->decrypt == NULL) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
+        return -2;
+    }
+    M_check_autoarg(ctx, out, outlen, EVP_F_EVP_PKEY_DECRYPT) return ctx->pmeth->decrypt(ctx, out, outlen, in, inlen);
 }
 
 /* decrypt to new buffer of dynamic size, checking any pre-determined size */
@@ -339,9 +371,50 @@ static EVP_ASYM_CIPHER *evp_asym_cipher_new(OSSL_PROVIDER *prov)
     return cipher;
 }
 
+static void *evp_asym_cipher_dup_frozen(void *vin)
+{
+    EVP_ASYM_CIPHER *in = vin;
+    EVP_ASYM_CIPHER *out;
+
+    out = OPENSSL_malloc(sizeof(*out));
+    if (out == NULL)
+        return NULL;
+    memcpy(out, in, sizeof(*out));
+    if (!CRYPTO_NEW_REF(&out->refcnt, 1))
+        goto err;
+    out->type_name = OPENSSL_strdup(in->type_name);
+    if (out->type_name == NULL)
+        goto err;
+    out->origin = EVP_ORIG_FROZEN;
+    if (out->prov == NULL || !ossl_provider_up_ref(out->prov)) {
+        OPENSSL_free(out->type_name);
+        goto err;
+    }
+    return out;
+
+err:
+    CRYPTO_FREE_REF(&out->refcnt);
+    OPENSSL_free(out);
+    return NULL;
+}
+
+static void evp_asym_cipher_frozen_free(void *vin)
+{
+    EVP_ASYM_CIPHER *rand = vin;
+    int ref = 0;
+
+    if (rand == NULL || rand->origin != EVP_ORIG_FROZEN)
+        return;
+
+    CRYPTO_DOWN_REF(&rand->refcnt, &ref);
+    if (ref > 0)
+        return;
+    evp_asym_cipher_free_int(rand);
+}
+
 static void *evp_asym_cipher_from_algorithm(int name_id,
     const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, int no_store)
+    OSSL_PROVIDER *prov)
 {
     const OSSL_DISPATCH *fns = algodef->implementation;
     EVP_ASYM_CIPHER *cipher = NULL;
@@ -354,7 +427,6 @@ static void *evp_asym_cipher_from_algorithm(int name_id,
     }
 
     cipher->name_id = name_id;
-    cipher->no_store = no_store;
     if ((cipher->type_name = ossl_algorithm_get1_first_name(algodef)) == NULL)
         goto err;
     cipher->description = algodef->algorithm_description;
@@ -453,29 +525,29 @@ static void *evp_asym_cipher_from_algorithm(int name_id,
 
     return cipher;
 err:
-    evp_asym_cipher_free(cipher);
+    EVP_ASYM_CIPHER_free(cipher);
     return NULL;
 }
 
 void EVP_ASYM_CIPHER_free(EVP_ASYM_CIPHER *cipher)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    evp_asym_cipher_free(cipher);
-#else
-    if (cipher != NULL && (cipher->no_store != 0))
-        evp_asym_cipher_free(cipher);
-#endif
+    int i;
+
+    if (cipher == NULL || cipher->origin != EVP_ORIG_DYNAMIC)
+        return;
+    CRYPTO_DOWN_REF(&cipher->refcnt, &i);
+    if (i > 0)
+        return;
+    evp_asym_cipher_free_int(cipher);
 }
 
 int EVP_ASYM_CIPHER_up_ref(EVP_ASYM_CIPHER *cipher)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    return evp_asym_cipher_up_ref(cipher);
-#else
-    if (cipher->no_store != 0)
-        return evp_asym_cipher_up_ref(cipher);
+    int ref = 0;
+
+    if (cipher->origin == EVP_ORIG_DYNAMIC)
+        CRYPTO_UP_REF(&cipher->refcnt, &ref);
     return 1;
-#endif
 }
 
 OSSL_PROVIDER *EVP_ASYM_CIPHER_get0_provider(const EVP_ASYM_CIPHER *cipher)
@@ -486,10 +558,26 @@ OSSL_PROVIDER *EVP_ASYM_CIPHER_get0_provider(const EVP_ASYM_CIPHER *cipher)
 EVP_ASYM_CIPHER *EVP_ASYM_CIPHER_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
     const char *properties)
 {
-    return evp_generic_fetch(ctx, OSSL_OP_ASYM_CIPHER, algorithm, properties,
+    return evp_generic_fetch(ctx,
+        OSSL_OP_ASYM_CIPHER,
+        algorithm,
+        properties,
         evp_asym_cipher_from_algorithm,
         evp_asym_cipher_up_ref,
-        evp_asym_cipher_free);
+        evp_asym_cipher_free,
+        evp_asym_cipher_dup_frozen,
+        evp_asym_cipher_frozen_free);
+}
+
+int evp_asym_cipher_fetch_all(OSSL_LIB_CTX *ctx)
+{
+    return evp_generic_fetch_all(ctx,
+        OSSL_OP_ASYM_CIPHER,
+        evp_asym_cipher_from_algorithm,
+        evp_asym_cipher_up_ref,
+        evp_asym_cipher_free,
+        evp_asym_cipher_dup_frozen,
+        evp_asym_cipher_frozen_free);
 }
 
 EVP_ASYM_CIPHER *evp_asym_cipher_fetch_from_prov(OSSL_PROVIDER *prov,
@@ -500,7 +588,9 @@ EVP_ASYM_CIPHER *evp_asym_cipher_fetch_from_prov(OSSL_PROVIDER *prov,
         algorithm, properties,
         evp_asym_cipher_from_algorithm,
         evp_asym_cipher_up_ref,
-        evp_asym_cipher_free);
+        evp_asym_cipher_free,
+        evp_asym_cipher_dup_frozen,
+        evp_asym_cipher_frozen_free);
 }
 
 int EVP_ASYM_CIPHER_is_a(const EVP_ASYM_CIPHER *cipher, const char *name)
@@ -528,12 +618,8 @@ void EVP_ASYM_CIPHER_do_all_provided(OSSL_LIB_CTX *libctx,
         void *arg),
     void *arg)
 {
-    struct EVP_ASYM_CIPHER_do_all_provided_thunk t;
-
-    t.fn = fn;
-    t.arg = arg;
     evp_generic_do_all(libctx, OSSL_OP_ASYM_CIPHER,
-        EVP_ASYM_CIPHER_do_all_provided_thunk, &t,
+        (void (*)(void *, void *))fn, arg,
         evp_asym_cipher_from_algorithm,
         evp_asym_cipher_up_ref,
         evp_asym_cipher_free);
diff --git a/crypto/evp/bio_b64.c b/crypto/evp/bio_b64.c
index 7f32d7a5d0..de95a57057 100644
--- a/crypto/evp/bio_b64.c
+++ b/crypto/evp/bio_b64.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -13,7 +13,6 @@
 #include 
 #include 
 #include "internal/bio.h"
-#include "crypto/evp.h"
 
 static int b64_write(BIO *h, const char *buf, int num);
 static int b64_read(BIO *h, char *buf, int size);
@@ -42,8 +41,6 @@ typedef struct b64_struct {
     EVP_ENCODE_CTX *base64;
     unsigned char buf[EVP_ENCODE_LENGTH(B64_BLOCK_SIZE) + 10];
     unsigned char tmp[B64_BLOCK_SIZE];
-    unsigned char *encoded_buf;
-    size_t encoded_buf_len;
 } BIO_B64_CTX;
 
 static const BIO_METHOD methods_b64 = {
@@ -75,8 +72,6 @@ static int b64_new(BIO *bi)
 
     ctx->cont = 1;
     ctx->start = 1;
-    ctx->encoded_buf = NULL;
-    ctx->encoded_buf_len = 0;
     ctx->base64 = EVP_ENCODE_CTX_new();
     if (ctx->base64 == NULL) {
         OPENSSL_free(ctx);
@@ -100,9 +95,6 @@ static int b64_free(BIO *a)
     if (ctx == NULL)
         return 0;
 
-    OPENSSL_free(ctx->encoded_buf);
-    ctx->encoded_buf = NULL;
-    ctx->encoded_buf_len = 0;
     EVP_ENCODE_CTX_free(ctx->base64);
     OPENSSL_free(ctx);
     BIO_set_data(a, NULL);
@@ -323,6 +315,7 @@ static int b64_read(BIO *b, char *out, int outl)
         outl -= i;
         out += i;
     }
+    /* BIO_clear_retry_flags(b); */
     BIO_copy_next_retry(b);
     return ret == 0 ? ret_code : ret;
 }
@@ -334,9 +327,6 @@ static int b64_write(BIO *b, const char *in, int inl)
     int i;
     BIO_B64_CTX *ctx;
     BIO *next;
-    size_t encoded_length;
-    unsigned char *encoded;
-    int n_bytes_enc;
 
     ctx = (BIO_B64_CTX *)BIO_get_data(b);
     next = BIO_next(b);
@@ -351,8 +341,6 @@ static int b64_write(BIO *b, const char *in, int inl)
         ctx->buf_off = 0;
         ctx->tmp_len = 0;
         EVP_EncodeInit(ctx->base64);
-        if (BIO_get_flags(b) & BIO_FLAGS_BASE64_NO_NL)
-            evp_encode_ctx_set_flags(ctx->base64, EVP_ENCODE_CTX_NO_NEWLINES);
     }
     if (!ossl_assert(ctx->buf_off < (int)sizeof(ctx->buf))) {
         ERR_raise(ERR_LIB_BIO, ERR_R_INTERNAL_ERROR);
@@ -391,38 +379,98 @@ static int b64_write(BIO *b, const char *in, int inl)
     if (in == NULL || inl <= 0)
         return 0;
 
-    encoded_length = EVP_ENCODE_LENGTH(inl);
+    while (inl > 0) {
+        n = inl > B64_BLOCK_SIZE ? B64_BLOCK_SIZE : inl;
 
-    if (encoded_length > SIZE_MAX / 2) {
-        ERR_raise(ERR_LIB_BIO, BIO_R_LENGTH_TOO_LONG);
-        return -1;
-    }
-
-    if (ctx->encoded_buf == NULL || encoded_length > ctx->encoded_buf_len) {
-        OPENSSL_free(ctx->encoded_buf);
-        ctx->encoded_buf = OPENSSL_malloc(encoded_length);
-        if (ctx->encoded_buf == NULL) {
-            ERR_raise(ERR_LIB_BIO, ERR_R_MALLOC_FAILURE);
-            return -1;
+        if ((BIO_get_flags(b) & BIO_FLAGS_BASE64_NO_NL) != 0) {
+            if (ctx->tmp_len > 0) {
+                if (!ossl_assert(ctx->tmp_len <= 3)) {
+                    ERR_raise(ERR_LIB_BIO, ERR_R_INTERNAL_ERROR);
+                    return ret == 0 ? -1 : ret;
+                }
+                n = 3 - ctx->tmp_len;
+                /*
+                 * There's a theoretical possibility for this
+                 */
+                if (n > inl)
+                    n = inl;
+                memcpy(&(ctx->tmp[ctx->tmp_len]), in, n);
+                ctx->tmp_len += n;
+                ret += n;
+                if (ctx->tmp_len < 3)
+                    break;
+                ctx->buf_len = EVP_EncodeBlock(ctx->buf, ctx->tmp, ctx->tmp_len);
+                if (!ossl_assert(ctx->buf_len <= (int)sizeof(ctx->buf))) {
+                    ERR_raise(ERR_LIB_BIO, ERR_R_INTERNAL_ERROR);
+                    return ret == 0 ? -1 : ret;
+                }
+                if (!ossl_assert(ctx->buf_len >= ctx->buf_off)) {
+                    ERR_raise(ERR_LIB_BIO, ERR_R_INTERNAL_ERROR);
+                    return ret == 0 ? -1 : ret;
+                }
+                /*
+                 * Since we're now done using the temporary buffer, the
+                 * length should be 0'd
+                 */
+                ctx->tmp_len = 0;
+            } else {
+                if (n < 3) {
+                    memcpy(ctx->tmp, in, n);
+                    ctx->tmp_len = n;
+                    ret += n;
+                    break;
+                }
+                n -= n % 3;
+                ctx->buf_len = EVP_EncodeBlock(ctx->buf, (unsigned char *)in, n);
+                if (!ossl_assert(ctx->buf_len <= (int)sizeof(ctx->buf))) {
+                    ERR_raise(ERR_LIB_BIO, ERR_R_INTERNAL_ERROR);
+                    return ret == 0 ? -1 : ret;
+                }
+                if (!ossl_assert(ctx->buf_len >= ctx->buf_off)) {
+                    ERR_raise(ERR_LIB_BIO, ERR_R_INTERNAL_ERROR);
+                    return ret == 0 ? -1 : ret;
+                }
+                ret += n;
+            }
+        } else {
+            if (!EVP_EncodeUpdate(ctx->base64, ctx->buf, &ctx->buf_len,
+                    (unsigned char *)in, n))
+                return ret == 0 ? -1 : ret;
+            if (!ossl_assert(ctx->buf_len <= (int)sizeof(ctx->buf))) {
+                ERR_raise(ERR_LIB_BIO, ERR_R_INTERNAL_ERROR);
+                return ret == 0 ? -1 : ret;
+            }
+            if (!ossl_assert(ctx->buf_len >= ctx->buf_off)) {
+                ERR_raise(ERR_LIB_BIO, ERR_R_INTERNAL_ERROR);
+                return ret == 0 ? -1 : ret;
+            }
+            ret += n;
         }
-        ctx->encoded_buf_len = encoded_length;
-    }
+        inl -= n;
+        in += n;
 
-    encoded = ctx->encoded_buf;
-
-    if (encoded == NULL) {
-        ERR_raise(ERR_LIB_BIO, ERR_R_MALLOC_FAILURE);
-        return -1;
+        ctx->buf_off = 0;
+        n = ctx->buf_len;
+        while (n > 0) {
+            i = BIO_write(next, &(ctx->buf[ctx->buf_off]), n);
+            if (i <= 0) {
+                BIO_copy_next_retry(b);
+                return ret == 0 ? i : ret;
+            }
+            n -= i;
+            ctx->buf_off += i;
+            if (!ossl_assert(ctx->buf_off <= (int)sizeof(ctx->buf))) {
+                ERR_raise(ERR_LIB_BIO, ERR_R_INTERNAL_ERROR);
+                return ret == 0 ? -1 : ret;
+            }
+            if (!ossl_assert(ctx->buf_len >= ctx->buf_off)) {
+                ERR_raise(ERR_LIB_BIO, ERR_R_INTERNAL_ERROR);
+                return ret == 0 ? -1 : ret;
+            }
+        }
+        ctx->buf_len = 0;
+        ctx->buf_off = 0;
     }
-    n_bytes_enc = 0;
-    if (!EVP_EncodeUpdate(ctx->base64, encoded, &n_bytes_enc,
-            (unsigned char *)in, inl)) {
-        return -1;
-    }
-    ret += inl;
-    i = BIO_write(next, encoded, n_bytes_enc);
-    if (i <= 0)
-        BIO_copy_next_retry(b);
     return ret;
 }
 
@@ -435,12 +483,8 @@ static long b64_ctrl(BIO *b, int cmd, long num, void *ptr)
 
     ctx = (BIO_B64_CTX *)BIO_get_data(b);
     next = BIO_next(b);
-    /*
-     * If there is no ctx or no next BIO, BIO_read() returns 0, which means EOF.
-     * BIO_eof() should return 1 in this case.
-     */
     if (ctx == NULL || next == NULL)
-        return cmd == BIO_CTRL_EOF;
+        return 0;
 
     switch (cmd) {
     case BIO_CTRL_RESET:
@@ -477,23 +521,29 @@ static long b64_ctrl(BIO *b, int cmd, long num, void *ptr)
             ret = BIO_ctrl(next, cmd, num, ptr);
         break;
     case BIO_CTRL_FLUSH:
-        if (ctx->encode == B64_ENCODE) {
-            /* do a final write */
-        again:
-            while (ctx->buf_len != ctx->buf_off) {
-                i = b64_write(b, NULL, 0);
-                if (i < 0)
-                    return i;
-            }
-            if (EVP_ENCODE_CTX_num(ctx->base64) != 0) {
+        /* do a final write */
+    again:
+        while (ctx->buf_len != ctx->buf_off) {
+            i = b64_write(b, NULL, 0);
+            if (i < 0)
+                return i;
+        }
+        if (BIO_get_flags(b) & BIO_FLAGS_BASE64_NO_NL) {
+            if (ctx->tmp_len != 0) {
+                ctx->buf_len = EVP_EncodeBlock(ctx->buf,
+                    ctx->tmp, ctx->tmp_len);
                 ctx->buf_off = 0;
-                EVP_EncodeFinal(ctx->base64, ctx->buf, &(ctx->buf_len));
-                /* push out the bytes */
+                ctx->tmp_len = 0;
                 goto again;
             }
+        } else if (ctx->encode != B64_NONE
+            && EVP_ENCODE_CTX_num(ctx->base64) != 0) {
+            ctx->buf_off = 0;
+            EVP_EncodeFinal(ctx->base64, ctx->buf, &(ctx->buf_len));
+            /* push out the bytes */
+            goto again;
         }
         /* Finally flush the underlying BIO */
-        BIO_clear_retry_flags(b);
         ret = BIO_ctrl(next, cmd, num, ptr);
         BIO_copy_next_retry(b);
         break;
diff --git a/crypto/evp/bio_enc.c b/crypto/evp/bio_enc.c
index a56bc3b9e6..fc319d6425 100644
--- a/crypto/evp/bio_enc.c
+++ b/crypto/evp/bio_enc.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -22,12 +22,7 @@ static long enc_ctrl(BIO *h, int cmd, long arg1, void *arg2);
 static int enc_new(BIO *h);
 static int enc_free(BIO *data);
 static long enc_callback_ctrl(BIO *h, int cmd, BIO_info_cb *fps);
-/*
- * ENC_BLOCK_SIZE has been sized to handle ciphers that do not support streaming.
- * i.e. For AES Key wrapping of larger PQ private keys the buffer needs to be
- * large enough to process the input/output in one EVP_CipherUpdate() call.
- */
-#define ENC_BLOCK_SIZE (1024 * 8)
+#define ENC_BLOCK_SIZE (1024 * 4)
 #define ENC_MIN_CHUNK (256)
 #define BUF_OFFSET (ENC_MIN_CHUNK + EVP_MAX_BLOCK_LENGTH)
 
@@ -311,12 +306,8 @@ static long enc_ctrl(BIO *b, int cmd, long num, void *ptr)
 
     ctx = BIO_get_data(b);
     next = BIO_next(b);
-    /*
-     * If there is no ctx, BIO_read() returns 0, which means EOF.
-     * BIO_eof() should return 1 in this case.
-     */
     if (ctx == NULL)
-        return cmd == BIO_CTRL_EOF;
+        return 0;
 
     switch (cmd) {
     case BIO_CTRL_RESET:
@@ -331,11 +322,7 @@ static long enc_ctrl(BIO *b, int cmd, long num, void *ptr)
         if (ctx->cont <= 0)
             ret = 1;
         else
-            /*
-             * If there is no next BIO, BIO_read() returns 0, which means EOF.
-             * BIO_eof() should return 1 in this case.
-             */
-            ret = (next == NULL) ? 1 : BIO_ctrl(next, cmd, num, ptr);
+            ret = BIO_ctrl(next, cmd, num, ptr);
         break;
     case BIO_CTRL_WPENDING:
         ret = ctx->buf_len - ctx->buf_off;
diff --git a/crypto/evp/bio_md.c b/crypto/evp/bio_md.c
index b003e47e12..a2d9afcf0e 100644
--- a/crypto/evp/bio_md.c
+++ b/crypto/evp/bio_md.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -167,22 +167,12 @@ static long md_ctrl(BIO *b, int cmd, long num, void *ptr)
         else
             ret = 0;
         break;
-    case BIO_CTRL_EOF:
-        /*
-         * If there is no ctx or no next BIO, BIO_read() returns 0, which means
-         * EOF, BIO_eof() should return 1 in this case.
-         */
-        if (ctx == NULL || next == NULL)
-            ret = 1;
-        else
-            ret = BIO_ctrl(next, cmd, num, ptr);
-        break;
-    case BIO_CTRL_FLUSH:
     case BIO_C_DO_STATE_MACHINE:
         BIO_clear_retry_flags(b);
         ret = BIO_ctrl(next, cmd, num, ptr);
         BIO_copy_next_retry(b);
         break;
+
     case BIO_C_SET_MD:
         md = ptr;
         ret = EVP_DigestInit_ex(ctx, md, NULL);
diff --git a/crypto/evp/bio_ok.c b/crypto/evp/bio_ok.c
new file mode 100644
index 0000000000..9b48c3c745
--- /dev/null
+++ b/crypto/evp/bio_ok.c
@@ -0,0 +1,606 @@
+/*
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+/*-
+        From: Arne Ansper
+
+        Why BIO_f_reliable?
+
+        I wrote function which took BIO* as argument, read data from it
+        and processed it. Then I wanted to store the input file in
+        encrypted form. OK I pushed BIO_f_cipher to the BIO stack
+        and everything was OK. BUT if user types wrong password
+        BIO_f_cipher outputs only garbage and my function crashes. Yes
+        I can and I should fix my function, but BIO_f_cipher is
+        easy way to add encryption support to many existing applications
+        and it's hard to debug and fix them all.
+
+        So I wanted another BIO which would catch the incorrect passwords and
+        file damages which cause garbage on BIO_f_cipher's output.
+
+        The easy way is to push the BIO_f_md and save the checksum at
+        the end of the file. However there are several problems with this
+        approach:
+
+        1) you must somehow separate checksum from actual data.
+        2) you need lot's of memory when reading the file, because you
+        must read to the end of the file and verify the checksum before
+        letting the application to read the data.
+
+        BIO_f_reliable tries to solve both problems, so that you can
+        read and write arbitrary long streams using only fixed amount
+        of memory.
+
+        BIO_f_reliable splits data stream into blocks. Each block is prefixed
+        with its length and suffixed with its digest. So you need only
+        several Kbytes of memory to buffer single block before verifying
+        its digest.
+
+        BIO_f_reliable goes further and adds several important capabilities:
+
+        1) the digest of the block is computed over the whole stream
+        -- so nobody can rearrange the blocks or remove or replace them.
+
+        2) to detect invalid passwords right at the start BIO_f_reliable
+        adds special prefix to the stream. In order to avoid known plain-text
+        attacks this prefix is generated as follows:
+
+                *) digest is initialized with random seed instead of
+                standardized one.
+                *) same seed is written to output
+                *) well-known text is then hashed and the output
+                of the digest is also written to output.
+
+        reader can now read the seed from stream, hash the same string
+        and then compare the digest output.
+
+        Bad things: BIO_f_reliable knows what's going on in EVP_Digest. I
+        initially wrote and tested this code on x86 machine and wrote the
+        digests out in machine-dependent order :( There are people using
+        this code and I cannot change this easily without making existing
+        data files unreadable.
+
+*/
+
+#include 
+#include 
+#include 
+#include "internal/cryptlib.h"
+#include 
+#include "internal/bio.h"
+#include 
+#include 
+#include "internal/endian.h"
+#include "internal/numbers.h" /* includes SIZE_MAX */
+#include "crypto/evp.h"
+
+static int ok_write(BIO *h, const char *buf, int num);
+static int ok_read(BIO *h, char *buf, int size);
+static long ok_ctrl(BIO *h, int cmd, long arg1, void *arg2);
+static int ok_new(BIO *h);
+static int ok_free(BIO *data);
+static long ok_callback_ctrl(BIO *h, int cmd, BIO_info_cb *fp);
+
+static __owur int sig_out(BIO *b);
+static __owur int sig_in(BIO *b);
+static __owur int block_out(BIO *b);
+static __owur int block_in(BIO *b);
+#define OK_BLOCK_SIZE (1024 * 4)
+#define OK_BLOCK_BLOCK 4
+#define IOBS (OK_BLOCK_SIZE + OK_BLOCK_BLOCK + 3 * EVP_MAX_MD_SIZE)
+#define WELLKNOWN "The quick brown fox jumped over the lazy dog's back."
+
+typedef struct ok_struct {
+    size_t buf_len;
+    size_t buf_off;
+    size_t buf_len_save;
+    size_t buf_off_save;
+    int cont; /* <= 0 when finished */
+    int finished;
+    EVP_MD_CTX *md;
+    int blockout; /* output block is ready */
+    int sigio; /* must process signature */
+    unsigned char buf[IOBS];
+} BIO_OK_CTX;
+
+static const BIO_METHOD methods_ok = {
+    BIO_TYPE_CIPHER,
+    "reliable",
+    bwrite_conv,
+    ok_write,
+    bread_conv,
+    ok_read,
+    NULL, /* ok_puts, */
+    NULL, /* ok_gets, */
+    ok_ctrl,
+    ok_new,
+    ok_free,
+    ok_callback_ctrl,
+};
+
+const BIO_METHOD *BIO_f_reliable(void)
+{
+    return &methods_ok;
+}
+
+static int ok_new(BIO *bi)
+{
+    BIO_OK_CTX *ctx;
+
+    if ((ctx = OPENSSL_zalloc(sizeof(*ctx))) == NULL)
+        return 0;
+
+    ctx->cont = 1;
+    ctx->sigio = 1;
+    ctx->md = EVP_MD_CTX_new();
+    if (ctx->md == NULL) {
+        OPENSSL_free(ctx);
+        return 0;
+    }
+    BIO_set_init(bi, 0);
+    BIO_set_data(bi, ctx);
+
+    return 1;
+}
+
+static int ok_free(BIO *a)
+{
+    BIO_OK_CTX *ctx;
+
+    if (a == NULL)
+        return 0;
+
+    ctx = BIO_get_data(a);
+
+    EVP_MD_CTX_free(ctx->md);
+    OPENSSL_clear_free(ctx, sizeof(BIO_OK_CTX));
+    BIO_set_data(a, NULL);
+    BIO_set_init(a, 0);
+
+    return 1;
+}
+
+static int ok_read(BIO *b, char *out, int outl)
+{
+    int ret = 0, i, n;
+    BIO_OK_CTX *ctx;
+    BIO *next;
+
+    if (out == NULL)
+        return 0;
+
+    ctx = BIO_get_data(b);
+    next = BIO_next(b);
+
+    if ((ctx == NULL) || (next == NULL) || (BIO_get_init(b) == 0))
+        return 0;
+
+    while (outl > 0) {
+
+        /* copy clean bytes to output buffer */
+        if (ctx->blockout) {
+            i = (int)(ctx->buf_len - ctx->buf_off);
+            if (i > outl)
+                i = outl;
+            memcpy(out, &(ctx->buf[ctx->buf_off]), i);
+            ret += i;
+            out += i;
+            outl -= i;
+            ctx->buf_off += i;
+
+            /* all clean bytes are out */
+            if (ctx->buf_len == ctx->buf_off) {
+                ctx->buf_off = 0;
+
+                /*
+                 * copy start of the next block into proper place
+                 */
+                if (ctx->buf_len_save > ctx->buf_off_save) {
+                    ctx->buf_len = ctx->buf_len_save - ctx->buf_off_save;
+                    memmove(ctx->buf, &(ctx->buf[ctx->buf_off_save]),
+                        ctx->buf_len);
+                } else {
+                    ctx->buf_len = 0;
+                }
+                ctx->blockout = 0;
+            }
+        }
+
+        /* output buffer full -- cancel */
+        if (outl == 0)
+            break;
+
+        /* no clean bytes in buffer -- fill it */
+        n = (int)(IOBS - ctx->buf_len);
+        i = BIO_read(next, &(ctx->buf[ctx->buf_len]), n);
+
+        if (i <= 0)
+            break; /* nothing new */
+
+        ctx->buf_len += i;
+
+        /* no signature yet -- check if we got one */
+        if (ctx->sigio == 1) {
+            if (!sig_in(b)) {
+                BIO_clear_retry_flags(b);
+                return 0;
+            }
+        }
+
+        /* signature ok -- check if we got block */
+        if (ctx->sigio == 0) {
+            if (!block_in(b)) {
+                BIO_clear_retry_flags(b);
+                return 0;
+            }
+        }
+
+        /* invalid block -- cancel */
+        if (ctx->cont <= 0)
+            break;
+    }
+
+    BIO_clear_retry_flags(b);
+    BIO_copy_next_retry(b);
+    return ret;
+}
+
+static int ok_write(BIO *b, const char *in, int inl)
+{
+    int ret = 0, n, i;
+    BIO_OK_CTX *ctx;
+    BIO *next;
+
+    if (inl <= 0)
+        return inl;
+
+    ctx = BIO_get_data(b);
+    next = BIO_next(b);
+    ret = inl;
+
+    if ((ctx == NULL) || (next == NULL) || (BIO_get_init(b) == 0))
+        return 0;
+
+    if (ctx->sigio && !sig_out(b))
+        return 0;
+
+    do {
+        BIO_clear_retry_flags(b);
+        n = (int)(ctx->buf_len - ctx->buf_off);
+        while (ctx->blockout && n > 0) {
+            i = BIO_write(next, &(ctx->buf[ctx->buf_off]), n);
+            if (i <= 0) {
+                BIO_copy_next_retry(b);
+                if (!BIO_should_retry(b))
+                    ctx->cont = 0;
+                return i;
+            }
+            ctx->buf_off += i;
+            n -= i;
+        }
+
+        /* at this point all pending data has been written */
+        ctx->blockout = 0;
+        if (ctx->buf_len == ctx->buf_off) {
+            ctx->buf_len = OK_BLOCK_BLOCK;
+            ctx->buf_off = 0;
+        }
+
+        if ((in == NULL) || (inl <= 0))
+            return 0;
+
+        n = (inl + ctx->buf_len > OK_BLOCK_SIZE + OK_BLOCK_BLOCK) ? (int)(OK_BLOCK_SIZE + OK_BLOCK_BLOCK - ctx->buf_len) : inl;
+
+        memcpy(&ctx->buf[ctx->buf_len], in, n);
+        ctx->buf_len += n;
+        inl -= n;
+        in += n;
+
+        if (ctx->buf_len >= OK_BLOCK_SIZE + OK_BLOCK_BLOCK) {
+            if (!block_out(b)) {
+                BIO_clear_retry_flags(b);
+                return 0;
+            }
+        }
+    } while (inl > 0);
+
+    BIO_clear_retry_flags(b);
+    BIO_copy_next_retry(b);
+    return ret;
+}
+
+static long ok_ctrl(BIO *b, int cmd, long num, void *ptr)
+{
+    BIO_OK_CTX *ctx;
+    EVP_MD *md;
+    const EVP_MD **ppmd;
+    long ret = 1;
+    int i;
+    BIO *next;
+
+    ctx = BIO_get_data(b);
+    next = BIO_next(b);
+
+    switch (cmd) {
+    case BIO_CTRL_RESET:
+        ctx->buf_len = 0;
+        ctx->buf_off = 0;
+        ctx->buf_len_save = 0;
+        ctx->buf_off_save = 0;
+        ctx->cont = 1;
+        ctx->finished = 0;
+        ctx->blockout = 0;
+        ctx->sigio = 1;
+        ret = BIO_ctrl(next, cmd, num, ptr);
+        break;
+    case BIO_CTRL_EOF: /* More to read */
+        if (ctx->cont <= 0)
+            ret = 1;
+        else
+            ret = BIO_ctrl(next, cmd, num, ptr);
+        break;
+    case BIO_CTRL_PENDING: /* More to read in buffer */
+    case BIO_CTRL_WPENDING: /* More to read in buffer */
+        ret = ctx->blockout ? (long)(ctx->buf_len - ctx->buf_off) : 0;
+        if (ret <= 0)
+            ret = BIO_ctrl(next, cmd, num, ptr);
+        break;
+    case BIO_CTRL_FLUSH:
+        /* do a final write */
+        if (ctx->blockout == 0)
+            if (!block_out(b))
+                return 0;
+
+        while (ctx->blockout) {
+            i = ok_write(b, NULL, 0);
+            if (i < 0) {
+                ret = i;
+                break;
+            }
+        }
+
+        ctx->finished = 1;
+        ctx->buf_off = ctx->buf_len = 0;
+        ctx->cont = (int)ret;
+
+        /* Finally flush the underlying BIO */
+        ret = BIO_ctrl(next, cmd, num, ptr);
+        BIO_copy_next_retry(b);
+        break;
+    case BIO_C_DO_STATE_MACHINE:
+        BIO_clear_retry_flags(b);
+        ret = BIO_ctrl(next, cmd, num, ptr);
+        BIO_copy_next_retry(b);
+        break;
+    case BIO_CTRL_INFO:
+        ret = (long)ctx->cont;
+        break;
+    case BIO_C_SET_MD:
+        md = ptr;
+        if (!EVP_DigestInit_ex(ctx->md, md, NULL))
+            return 0;
+        BIO_set_init(b, 1);
+        break;
+    case BIO_C_GET_MD:
+        if (BIO_get_init(b)) {
+            ppmd = ptr;
+            *ppmd = EVP_MD_CTX_get0_md(ctx->md);
+        } else
+            ret = 0;
+        break;
+    default:
+        ret = BIO_ctrl(next, cmd, num, ptr);
+        break;
+    }
+    return ret;
+}
+
+static long ok_callback_ctrl(BIO *b, int cmd, BIO_info_cb *fp)
+{
+    BIO *next;
+
+    next = BIO_next(b);
+
+    if (next == NULL)
+        return 0;
+
+    return BIO_callback_ctrl(next, cmd, fp);
+}
+
+static void longswap(void *_ptr, size_t len)
+{
+    DECLARE_IS_ENDIAN;
+
+    if (IS_LITTLE_ENDIAN) {
+        size_t i;
+        unsigned char *p = _ptr, c;
+
+        for (i = 0; i < len; i += 4) {
+            c = p[0], p[0] = p[3], p[3] = c;
+            c = p[1], p[1] = p[2], p[2] = c;
+        }
+    }
+}
+
+static int sig_out(BIO *b)
+{
+    BIO_OK_CTX *ctx;
+    EVP_MD_CTX *md;
+    const EVP_MD *digest;
+    int md_size;
+    void *md_data;
+
+    ctx = BIO_get_data(b);
+    md = ctx->md;
+    digest = EVP_MD_CTX_get0_md(md);
+    md_size = EVP_MD_get_size(digest);
+    md_data = EVP_MD_CTX_get0_md_data(md);
+
+    if (md_size <= 0)
+        goto berr;
+    if (ctx->buf_len + 2 * md_size > OK_BLOCK_SIZE)
+        return 1;
+
+    if (!EVP_DigestInit_ex(md, digest, NULL))
+        goto berr;
+    /*
+     * FIXME: there's absolutely no guarantee this makes any sense at all,
+     * particularly now EVP_MD_CTX has been restructured.
+     */
+    if (RAND_bytes(md_data, md_size) <= 0)
+        goto berr;
+    memcpy(&(ctx->buf[ctx->buf_len]), md_data, md_size);
+    longswap(&(ctx->buf[ctx->buf_len]), md_size);
+    ctx->buf_len += md_size;
+
+    if (!EVP_DigestUpdate(md, WELLKNOWN, strlen(WELLKNOWN)))
+        goto berr;
+    if (!EVP_DigestFinal_ex(md, &(ctx->buf[ctx->buf_len]), NULL))
+        goto berr;
+    ctx->buf_len += md_size;
+    ctx->blockout = 1;
+    ctx->sigio = 0;
+    return 1;
+berr:
+    BIO_clear_retry_flags(b);
+    return 0;
+}
+
+static int sig_in(BIO *b)
+{
+    BIO_OK_CTX *ctx;
+    EVP_MD_CTX *md;
+    unsigned char tmp[EVP_MAX_MD_SIZE];
+    int ret = 0;
+    const EVP_MD *digest;
+    int md_size;
+    void *md_data;
+
+    ctx = BIO_get_data(b);
+    if ((md = ctx->md) == NULL)
+        goto berr;
+    digest = EVP_MD_CTX_get0_md(md);
+    if ((md_size = EVP_MD_get_size(digest)) <= 0)
+        goto berr;
+    md_data = EVP_MD_CTX_get0_md_data(md);
+
+    if ((int)(ctx->buf_len - ctx->buf_off) < 2 * md_size)
+        return 1;
+
+    if (!EVP_DigestInit_ex(md, digest, NULL))
+        goto berr;
+    memcpy(md_data, &(ctx->buf[ctx->buf_off]), md_size);
+    longswap(md_data, md_size);
+    ctx->buf_off += md_size;
+
+    if (!EVP_DigestUpdate(md, WELLKNOWN, strlen(WELLKNOWN)))
+        goto berr;
+    if (!EVP_DigestFinal_ex(md, tmp, NULL))
+        goto berr;
+    ret = memcmp(&(ctx->buf[ctx->buf_off]), tmp, md_size) == 0;
+    ctx->buf_off += md_size;
+    if (ret == 1) {
+        ctx->sigio = 0;
+        if (ctx->buf_len != ctx->buf_off) {
+            memmove(ctx->buf, &(ctx->buf[ctx->buf_off]),
+                ctx->buf_len - ctx->buf_off);
+        }
+        ctx->buf_len -= ctx->buf_off;
+        ctx->buf_off = 0;
+    } else {
+        ctx->cont = 0;
+    }
+    return 1;
+berr:
+    BIO_clear_retry_flags(b);
+    return 0;
+}
+
+static int block_out(BIO *b)
+{
+    BIO_OK_CTX *ctx;
+    EVP_MD_CTX *md;
+    unsigned long tl;
+    const EVP_MD *digest;
+    int md_size;
+
+    ctx = BIO_get_data(b);
+    md = ctx->md;
+    digest = EVP_MD_CTX_get0_md(md);
+    md_size = EVP_MD_get_size(digest);
+    if (md_size <= 0)
+        goto berr;
+
+    tl = (unsigned long)(ctx->buf_len - OK_BLOCK_BLOCK);
+    ctx->buf[0] = (unsigned char)(tl >> 24);
+    ctx->buf[1] = (unsigned char)(tl >> 16);
+    ctx->buf[2] = (unsigned char)(tl >> 8);
+    ctx->buf[3] = (unsigned char)(tl);
+    if (!EVP_DigestUpdate(md,
+            (unsigned char *)&(ctx->buf[OK_BLOCK_BLOCK]), tl))
+        goto berr;
+    if (!EVP_DigestFinal_ex(md, &(ctx->buf[ctx->buf_len]), NULL))
+        goto berr;
+    ctx->buf_len += md_size;
+    ctx->blockout = 1;
+    return 1;
+berr:
+    BIO_clear_retry_flags(b);
+    return 0;
+}
+
+static int block_in(BIO *b)
+{
+    BIO_OK_CTX *ctx;
+    EVP_MD_CTX *md;
+    size_t tl = 0;
+    unsigned char tmp[EVP_MAX_MD_SIZE];
+    int md_size;
+
+    ctx = BIO_get_data(b);
+    md = ctx->md;
+    md_size = EVP_MD_get_size(EVP_MD_CTX_get0_md(md));
+    if (md_size <= 0)
+        goto berr;
+
+    assert(sizeof(tl) >= OK_BLOCK_BLOCK); /* always true */
+    tl = ((size_t)ctx->buf[0] << 24)
+        | ((size_t)ctx->buf[1] << 16)
+        | ((size_t)ctx->buf[2] << 8)
+        | ((size_t)ctx->buf[3]);
+
+    if (tl > OK_BLOCK_SIZE)
+        goto berr;
+
+    if (tl > SIZE_MAX - OK_BLOCK_BLOCK - (size_t)md_size)
+        goto berr;
+
+    if (ctx->buf_len < tl + OK_BLOCK_BLOCK + (size_t)md_size)
+        return 1;
+
+    if (!EVP_DigestUpdate(md,
+            (unsigned char *)&(ctx->buf[OK_BLOCK_BLOCK]), tl))
+        goto berr;
+    if (!EVP_DigestFinal_ex(md, tmp, NULL))
+        goto berr;
+    if (memcmp(&(ctx->buf[tl + OK_BLOCK_BLOCK]), tmp, (size_t)md_size) == 0) {
+        /* there might be parts from next block lurking around ! */
+        ctx->buf_off_save = tl + OK_BLOCK_BLOCK + md_size;
+        ctx->buf_len_save = ctx->buf_len;
+        ctx->buf_off = OK_BLOCK_BLOCK;
+        ctx->buf_len = tl + OK_BLOCK_BLOCK;
+        ctx->blockout = 1;
+    } else {
+        ctx->cont = 0;
+    }
+    return 1;
+berr:
+    BIO_clear_retry_flags(b);
+    return 0;
+}
diff --git a/crypto/evp/build.info b/crypto/evp/build.info
index 5897acd943..f46bbe8843 100644
--- a/crypto/evp/build.info
+++ b/crypto/evp/build.info
@@ -8,19 +8,17 @@ $COMMON=digest.c evp_enc.c evp_lib.c evp_fetch.c evp_utils.c \
 
 SOURCE[../../libcrypto]=$COMMON\
         encode.c evp_key.c evp_cnf.c \
-        enc_b64_scalar.c \
-        enc_b64_avx2.c \
         e_des.c e_bf.c e_idea.c e_des3.c \
         e_rc4.c e_aes.c names.c e_aria.c e_sm4.c \
         e_xcbc_d.c e_rc2.c e_cast.c e_rc5.c m_null.c \
         p_seal.c p_sign.c p_verify.c p_legacy.c \
         bio_md.c bio_b64.c bio_enc.c evp_err.c e_null.c \
-        c_allc.c c_alld.c \
+        c_allc.c c_alld.c bio_ok.c \
         evp_pkey.c evp_pbe.c p5_crpt.c p5_crpt2.c pbe_scrypt.c \
         e_aes_cbc_hmac_sha1.c e_aes_cbc_hmac_sha256.c e_rc4_hmac_md5.c \
         e_chacha20_poly1305.c \
         legacy_sha.c ctrl_params_translate.c \
-        m_sigver.c
+        cmeth_lib.c m_sigver.c
 
 # Diverse type specific ctrl functions.  They are kinda sorta legacy, kinda
 # sorta not.
diff --git a/crypto/evp/cmeth_lib.c b/crypto/evp/cmeth_lib.c
new file mode 100644
index 0000000000..5e71d0061c
--- /dev/null
+++ b/crypto/evp/cmeth_lib.c
@@ -0,0 +1,200 @@
+/*
+ * Copyright 2015-2023 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+/*
+ * EVP _meth_ APIs are deprecated for public use, but still ok for
+ * internal use.
+ */
+#include "internal/deprecated.h"
+
+#include 
+
+#include 
+#include "crypto/evp.h"
+#include "internal/provider.h"
+#include "evp_local.h"
+
+EVP_CIPHER *EVP_CIPHER_meth_new(int cipher_type, int block_size, int key_len)
+{
+    EVP_CIPHER *cipher = evp_cipher_new();
+
+    if (cipher != NULL) {
+        cipher->nid = cipher_type;
+        cipher->block_size = block_size;
+        cipher->key_len = key_len;
+        cipher->origin = EVP_ORIG_METH;
+    }
+    return cipher;
+}
+
+EVP_CIPHER *EVP_CIPHER_meth_dup(const EVP_CIPHER *cipher)
+{
+    EVP_CIPHER *to = NULL;
+
+    /*
+     * Non-legacy EVP_CIPHERs can't be duplicated like this.
+     * Use EVP_CIPHER_up_ref() instead.
+     */
+    if (cipher->prov != NULL)
+        return NULL;
+
+    if ((to = EVP_CIPHER_meth_new(cipher->nid, cipher->block_size,
+             cipher->key_len))
+        != NULL) {
+        CRYPTO_REF_COUNT refcnt = to->refcnt;
+
+        memcpy(to, cipher, sizeof(*to));
+        to->refcnt = refcnt;
+        to->origin = EVP_ORIG_METH;
+    }
+    return to;
+}
+
+void EVP_CIPHER_meth_free(EVP_CIPHER *cipher)
+{
+    if (cipher == NULL || cipher->origin != EVP_ORIG_METH)
+        return;
+
+    evp_cipher_free_int(cipher);
+}
+
+int EVP_CIPHER_meth_set_iv_length(EVP_CIPHER *cipher, int iv_len)
+{
+    if (cipher->iv_len != 0)
+        return 0;
+
+    cipher->iv_len = iv_len;
+    return 1;
+}
+
+int EVP_CIPHER_meth_set_flags(EVP_CIPHER *cipher, unsigned long flags)
+{
+    if (cipher->flags != 0)
+        return 0;
+
+    cipher->flags = flags;
+    return 1;
+}
+
+int EVP_CIPHER_meth_set_impl_ctx_size(EVP_CIPHER *cipher, int ctx_size)
+{
+    if (cipher->ctx_size != 0)
+        return 0;
+
+    cipher->ctx_size = ctx_size;
+    return 1;
+}
+
+int EVP_CIPHER_meth_set_init(EVP_CIPHER *cipher,
+    int (*init)(EVP_CIPHER_CTX *ctx,
+        const unsigned char *key,
+        const unsigned char *iv,
+        int enc))
+{
+    if (cipher->init != NULL)
+        return 0;
+
+    cipher->init = init;
+    return 1;
+}
+
+int EVP_CIPHER_meth_set_do_cipher(EVP_CIPHER *cipher,
+    int (*do_cipher)(EVP_CIPHER_CTX *ctx,
+        unsigned char *out,
+        const unsigned char *in,
+        size_t inl))
+{
+    if (cipher->do_cipher != NULL)
+        return 0;
+
+    cipher->do_cipher = do_cipher;
+    return 1;
+}
+
+int EVP_CIPHER_meth_set_cleanup(EVP_CIPHER *cipher,
+    int (*cleanup)(EVP_CIPHER_CTX *))
+{
+    if (cipher->cleanup != NULL)
+        return 0;
+
+    cipher->cleanup = cleanup;
+    return 1;
+}
+
+int EVP_CIPHER_meth_set_set_asn1_params(EVP_CIPHER *cipher,
+    int (*set_asn1_parameters)(EVP_CIPHER_CTX *,
+        ASN1_TYPE *))
+{
+    if (cipher->set_asn1_parameters != NULL)
+        return 0;
+
+    cipher->set_asn1_parameters = set_asn1_parameters;
+    return 1;
+}
+
+int EVP_CIPHER_meth_set_get_asn1_params(EVP_CIPHER *cipher,
+    int (*get_asn1_parameters)(EVP_CIPHER_CTX *,
+        ASN1_TYPE *))
+{
+    if (cipher->get_asn1_parameters != NULL)
+        return 0;
+
+    cipher->get_asn1_parameters = get_asn1_parameters;
+    return 1;
+}
+
+int EVP_CIPHER_meth_set_ctrl(EVP_CIPHER *cipher,
+    int (*ctrl)(EVP_CIPHER_CTX *, int type,
+        int arg, void *ptr))
+{
+    if (cipher->ctrl != NULL)
+        return 0;
+
+    cipher->ctrl = ctrl;
+    return 1;
+}
+
+int (*EVP_CIPHER_meth_get_init(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *ctx,
+    const unsigned char *key,
+    const unsigned char *iv,
+    int enc)
+{
+    return cipher->init;
+}
+int (*EVP_CIPHER_meth_get_do_cipher(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *ctx,
+    unsigned char *out,
+    const unsigned char *in,
+    size_t inl)
+{
+    return cipher->do_cipher;
+}
+
+int (*EVP_CIPHER_meth_get_cleanup(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *)
+{
+    return cipher->cleanup;
+}
+
+int (*EVP_CIPHER_meth_get_set_asn1_params(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *,
+    ASN1_TYPE *)
+{
+    return cipher->set_asn1_parameters;
+}
+
+int (*EVP_CIPHER_meth_get_get_asn1_params(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *,
+    ASN1_TYPE *)
+{
+    return cipher->get_asn1_parameters;
+}
+
+int (*EVP_CIPHER_meth_get_ctrl(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *,
+    int type, int arg,
+    void *ptr)
+{
+    return cipher->ctrl;
+}
diff --git a/crypto/evp/ctrl_params_translate.c b/crypto/evp/ctrl_params_translate.c
index c515c6cbbf..d4bbc6cf72 100644
--- a/crypto/evp/ctrl_params_translate.c
+++ b/crypto/evp/ctrl_params_translate.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -1833,36 +1833,6 @@ static int get_ec_decoded_from_explicit_params(enum state state,
     return get_payload_int(state, translation, ctx, val);
 }
 
-static int get_ec_field_degree(enum state state,
-    const struct translation_st *translation,
-    struct translation_ctx_st *ctx)
-{
-#ifndef OPENSSL_NO_EC
-    const EC_KEY *key;
-    const EC_GROUP *group;
-#endif
-    EVP_PKEY *pkey = ctx->p2;
-    int val = 0;
-
-    switch (EVP_PKEY_base_id(pkey)) {
-#ifndef OPENSSL_NO_EC
-    case EVP_PKEY_EC:
-        if ((key = EVP_PKEY_get0_EC_KEY(pkey)) == NULL
-            || (group = EC_KEY_get0_group(key)) == NULL) {
-            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY);
-            return 0;
-        }
-        val = EC_GROUP_get_degree(group);
-        break;
-#endif
-    default:
-        ERR_raise(ERR_LIB_EVP, EVP_R_UNSUPPORTED_KEY_TYPE);
-        return 0;
-    }
-
-    return get_payload_int(state, translation, ctx, val);
-}
-
 static int get_rsa_payload_n(enum state state,
     const struct translation_st *translation,
     struct translation_ctx_st *ctx)
@@ -2598,9 +2568,6 @@ static const struct translation_st evp_pkey_translations[] = {
     { OSSL_ACTION_GET, -1, -1, -1, 0, NULL, NULL,
         OSSL_PKEY_PARAM_EC_DECODED_FROM_EXPLICIT_PARAMS, OSSL_PARAM_INTEGER,
         get_ec_decoded_from_explicit_params },
-    { OSSL_ACTION_GET, -1, -1, -1, 0, NULL, NULL,
-        OSSL_PKEY_PARAM_EC_FIELD_DEGREE, OSSL_PARAM_INTEGER,
-        get_ec_field_degree },
 };
 
 static const struct translation_st *
@@ -2751,6 +2718,11 @@ int evp_pkey_ctx_ctrl_to_param(EVP_PKEY_CTX *pctx,
         return -2;
     }
 
+    if (pctx->pmeth != NULL
+        && pctx->pmeth->pkey_id != translation->keytype1
+        && pctx->pmeth->pkey_id != translation->keytype2)
+        return -1;
+
     if (translation->fixup_args != NULL)
         fixup = translation->fixup_args;
     ctx.action_type = translation->action_type;
@@ -2968,7 +2940,7 @@ static int evp_pkey_setget_params_to_ctrl(const EVP_PKEY *pkey,
          * on fixup_args to do the whole work.  Also, we currently only
          * support getting.
          */
-        if (translation == NULL
+        if (!ossl_assert(translation != NULL)
             || !ossl_assert(translation->action_type == OSSL_ACTION_GET)
             || !ossl_assert(translation->fixup_args != NULL)) {
             return -2;
diff --git a/crypto/evp/dh_ctrl.c b/crypto/evp/dh_ctrl.c
index 7d07d0d520..48f454cee2 100644
--- a/crypto/evp/dh_ctrl.c
+++ b/crypto/evp/dh_ctrl.c
@@ -25,8 +25,8 @@ static int dh_paramgen_check(EVP_PKEY_CTX *ctx)
     }
     /* If key type not DH return error */
     if (evp_pkey_ctx_is_legacy(ctx)
-        && ctx->legacy_keytype != EVP_PKEY_DH
-        && ctx->legacy_keytype != EVP_PKEY_DHX)
+        && ctx->pmeth->pkey_id != EVP_PKEY_DH
+        && ctx->pmeth->pkey_id != EVP_PKEY_DHX)
         return -1;
     return 1;
 }
@@ -40,8 +40,8 @@ static int dh_param_derive_check(EVP_PKEY_CTX *ctx)
     }
     /* If key type not DH return error */
     if (evp_pkey_ctx_is_legacy(ctx)
-        && ctx->legacy_keytype != EVP_PKEY_DH
-        && ctx->legacy_keytype != EVP_PKEY_DHX)
+        && ctx->pmeth->pkey_id != EVP_PKEY_DH
+        && ctx->pmeth->pkey_id != EVP_PKEY_DHX)
         return -1;
     return 1;
 }
diff --git a/crypto/evp/digest.c b/crypto/evp/digest.c
index db7121f0a4..5e5bd2523d 100644
--- a/crypto/evp/digest.c
+++ b/crypto/evp/digest.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -20,10 +20,22 @@
 #include "internal/common.h"
 #include "crypto/evp.h"
 #include "evp_local.h"
+#include "openssl/crypto.h"
 
-#include 
-
-static void evp_md_free(void *m);
+static void cleanup_old_md_data(EVP_MD_CTX *ctx, int force)
+{
+    if (ctx->digest != NULL) {
+        if (ctx->digest->cleanup != NULL
+            && !EVP_MD_CTX_test_flags(ctx, EVP_MD_CTX_FLAG_CLEANED))
+            ctx->digest->cleanup(ctx);
+        if (ctx->md_data != NULL && ctx->digest->ctx_size > 0
+            && (!EVP_MD_CTX_test_flags(ctx, EVP_MD_CTX_FLAG_REUSE)
+                || force)) {
+            OPENSSL_clear_free(ctx->md_data, ctx->digest->ctx_size);
+            ctx->md_data = NULL;
+        }
+    }
+}
 
 void evp_md_ctx_clear_digest(EVP_MD_CTX *ctx, int force, int keep_fetched)
 {
@@ -40,6 +52,7 @@ void evp_md_ctx_clear_digest(EVP_MD_CTX *ctx, int force, int keep_fetched)
      * Don't assume ctx->md_data was cleaned in EVP_Digest_Final, because
      * sometimes only copies of the context are ever finalised.
      */
+    cleanup_old_md_data(ctx, force);
     if (force)
         ctx->digest = NULL;
 
@@ -166,6 +179,27 @@ static int evp_md_init_internal(EVP_MD_CTX *ctx, const EVP_MD *type,
         type = ctx->digest;
     }
 
+    /*
+     * If there is EVP_MD_CTX_FLAG_NO_INIT set then we
+     * should use legacy handling for now.
+     */
+    if ((ctx->flags & EVP_MD_CTX_FLAG_NO_INIT) != 0
+        || (type != NULL && type->origin == EVP_ORIG_METH)
+        || (type == NULL && ctx->digest != NULL
+            && ctx->digest->origin == EVP_ORIG_METH)) {
+        /* If we were using provided hash before, cleanup algctx */
+        if (!evp_md_ctx_free_algctx(ctx))
+            return 0;
+        if (ctx->digest == ctx->fetched_digest)
+            ctx->digest = NULL;
+        EVP_MD_free(ctx->fetched_digest);
+        ctx->fetched_digest = NULL;
+        goto legacy;
+    }
+
+    cleanup_old_md_data(ctx, 1);
+
+    /* Start of non-legacy code below */
     if (ossl_likely(ctx->digest == type)) {
         if (ossl_unlikely(!ossl_assert(type->prov != NULL))) {
             ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
@@ -221,6 +255,35 @@ static int evp_md_init_internal(EVP_MD_CTX *ctx, const EVP_MD *type,
     }
 
     return ctx->digest->dinit(ctx->algctx, params);
+
+    /* Code below to be removed when legacy support is dropped. */
+legacy:
+
+    if (ctx->digest != type) {
+        cleanup_old_md_data(ctx, 1);
+
+        ctx->digest = type;
+        if (!(ctx->flags & EVP_MD_CTX_FLAG_NO_INIT) && type->ctx_size) {
+            ctx->update = type->update;
+            ctx->md_data = OPENSSL_zalloc(type->ctx_size);
+            if (ctx->md_data == NULL)
+                return 0;
+        }
+    }
+#ifndef FIPS_MODULE
+    if (ctx->pctx != NULL
+        && (!EVP_PKEY_CTX_IS_SIGNATURE_OP(ctx->pctx)
+            || ctx->pctx->op.sig.signature == NULL)) {
+        int r;
+        r = EVP_PKEY_CTX_ctrl(ctx->pctx, -1, EVP_PKEY_OP_TYPE_SIG,
+            EVP_PKEY_CTRL_DIGESTINIT, 0, ctx);
+        if (r <= 0 && (r != -2))
+            return 0;
+    }
+#endif
+    if (ctx->flags & EVP_MD_CTX_FLAG_NO_INIT)
+        return 1;
+    return ctx->digest->init(ctx);
 }
 
 int EVP_DigestInit_ex2(EVP_MD_CTX *ctx, const EVP_MD *type,
@@ -273,16 +336,20 @@ int EVP_DigestUpdate(EVP_MD_CTX *ctx, const void *data, size_t count)
         return 0;
     }
 
-    if (ctx->digest == NULL || ctx->digest->prov == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_UPDATE_ERROR);
-        return 0;
-    }
+    if (ctx->digest == NULL
+        || ctx->digest->prov == NULL
+        || ossl_unlikely((ctx->flags & EVP_MD_CTX_FLAG_NO_INIT) != 0))
+        goto legacy;
 
     if (ossl_unlikely(ctx->digest->dupdate == NULL)) {
         ERR_raise(ERR_LIB_EVP, EVP_R_UPDATE_ERROR);
         return 0;
     }
     return ctx->digest->dupdate(ctx->algctx, data, count);
+
+    /* Code below to be removed when legacy support is dropped. */
+legacy:
+    return ctx->update != NULL ? ctx->update(ctx, data, count) : 0;
 }
 
 /* The caller can assume that this removes any secret data from the context */
@@ -308,10 +375,8 @@ int EVP_DigestFinal_ex(EVP_MD_CTX *ctx, unsigned char *md, unsigned int *isize)
     if (ossl_unlikely(sz < 0))
         return 0;
     mdsize = sz;
-    if (ossl_unlikely(ctx->digest->prov == NULL)) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_FINAL_ERROR);
-        return 0;
-    }
+    if (ossl_unlikely(ctx->digest->prov == NULL))
+        goto legacy;
 
     if (ossl_unlikely(ctx->digest->dfinal == NULL)) {
         ERR_raise(ERR_LIB_EVP, EVP_R_FINAL_ERROR);
@@ -337,6 +402,19 @@ int EVP_DigestFinal_ex(EVP_MD_CTX *ctx, unsigned char *md, unsigned int *isize)
     }
 
     return ret;
+
+    /* Code below to be removed when legacy support is dropped. */
+legacy:
+    OPENSSL_assert(mdsize <= EVP_MAX_MD_SIZE);
+    ret = ctx->digest->final(ctx, md);
+    if (isize != NULL)
+        *isize = (unsigned int)mdsize;
+    if (ctx->digest->cleanup) {
+        ctx->digest->cleanup(ctx);
+        EVP_MD_CTX_set_flags(ctx, EVP_MD_CTX_FLAG_CLEANED);
+    }
+    OPENSSL_cleanse(ctx->md_data, ctx->digest->ctx_size);
+    return ret;
 }
 
 /* This is a one shot operation */
@@ -351,10 +429,8 @@ int EVP_DigestFinalXOF(EVP_MD_CTX *ctx, unsigned char *md, size_t size)
         return 0;
     }
 
-    if (ossl_unlikely(ctx->digest->prov == NULL)) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_FINAL_ERROR);
-        return 0;
-    }
+    if (ossl_unlikely(ctx->digest->prov == NULL))
+        goto legacy;
 
     if (ossl_unlikely(ctx->digest->dfinal == NULL)) {
         ERR_raise(ERR_LIB_EVP, EVP_R_FINAL_ERROR);
@@ -379,6 +455,22 @@ int EVP_DigestFinalXOF(EVP_MD_CTX *ctx, unsigned char *md, size_t size)
 
     ctx->flags |= EVP_MD_CTX_FLAG_FINALISED;
 
+    return ret;
+
+legacy:
+    if (EVP_MD_xof(ctx->digest)
+        && size <= INT_MAX
+        && ctx->digest->md_ctrl(ctx, EVP_MD_CTRL_XOF_LEN, (int)size, NULL)) {
+        ret = ctx->digest->final(ctx, md);
+        if (ctx->digest->cleanup != NULL) {
+            ctx->digest->cleanup(ctx);
+            EVP_MD_CTX_set_flags(ctx, EVP_MD_CTX_FLAG_CLEANED);
+        }
+        OPENSSL_cleanse(ctx->md_data, ctx->digest->ctx_size);
+    } else {
+        ERR_raise(ERR_LIB_EVP, EVP_R_NOT_XOF_OR_INVALID_LENGTH);
+    }
+
     return ret;
 }
 
@@ -403,57 +495,6 @@ int EVP_DigestSqueeze(EVP_MD_CTX *ctx, unsigned char *md, size_t size)
     return ctx->digest->dsqueeze(ctx->algctx, md, &size, size);
 }
 
-int EVP_MD_CTX_serialize(EVP_MD_CTX *ctx, unsigned char *out, size_t *outlen)
-{
-    if (ctx->digest == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_NULL_ALGORITHM);
-        return 0;
-    }
-
-    if (ctx->digest->prov == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_OPERATION);
-        return 0;
-    }
-
-    if (ctx->digest->serialize == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_METHOD_NOT_SUPPORTED);
-        return 0;
-    }
-
-    if (ossl_unlikely((ctx->flags & EVP_MD_CTX_FLAG_FINALISED) != 0)) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_CONTEXT_FINALIZED);
-        return 0;
-    }
-
-    return ctx->digest->serialize(ctx->algctx, out, outlen);
-}
-
-int EVP_MD_CTX_deserialize(EVP_MD_CTX *ctx, const unsigned char *in,
-    size_t inlen)
-{
-    if (ctx->digest == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_NULL_ALGORITHM);
-        return 0;
-    }
-
-    if (ctx->digest->prov == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_OPERATION);
-        return 0;
-    }
-
-    if (ctx->digest->deserialize == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_METHOD_NOT_SUPPORTED);
-        return 0;
-    }
-
-    if (ossl_unlikely((ctx->flags & EVP_MD_CTX_FLAG_FINALISED) != 0)) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_CONTEXT_FINALIZED);
-        return 0;
-    }
-
-    return ctx->digest->deserialize(ctx->algctx, in, inlen);
-}
-
 EVP_MD_CTX *EVP_MD_CTX_dup(const EVP_MD_CTX *in)
 {
     EVP_MD_CTX *out = EVP_MD_CTX_new();
@@ -474,6 +515,7 @@ int EVP_MD_CTX_copy(EVP_MD_CTX *out, const EVP_MD_CTX *in)
 int EVP_MD_CTX_copy_ex(EVP_MD_CTX *out, const EVP_MD_CTX *in)
 {
     int digest_change = 0;
+    unsigned char *tmp_buf;
 
     if (in == NULL) {
         ERR_raise(ERR_LIB_EVP, ERR_R_PASSED_NULL_PARAMETER);
@@ -489,20 +531,25 @@ int EVP_MD_CTX_copy_ex(EVP_MD_CTX *out, const EVP_MD_CTX *in)
         goto clone_pkey;
     }
 
-    if (in->digest->prov == NULL || in->digest->dupctx == NULL) {
+    if (in->digest->prov == NULL
+        || (in->flags & EVP_MD_CTX_FLAG_NO_INIT) != 0)
+        goto legacy;
+
+    if (in->digest->dupctx == NULL) {
         ERR_raise(ERR_LIB_EVP, EVP_R_NOT_ABLE_TO_COPY_CTX);
         return 0;
     }
 
-    if (out->digest == in->digest && in->digest->copyctx != NULL
-        && out->algctx != NULL && in->algctx != NULL) {
+    if (out->digest == in->digest && in->digest->copyctx != NULL) {
 
         in->digest->copyctx(out->algctx, in->algctx);
 
         EVP_PKEY_CTX_free(out->pctx);
         out->pctx = NULL;
+        cleanup_old_md_data(out, 0);
 
         out->flags = in->flags;
+        out->update = in->update;
     } else {
         evp_md_ctx_reset_ex(out, 1);
         digest_change = (out->fetched_digest != in->fetched_digest);
@@ -541,6 +588,55 @@ clone_pkey:
 #endif
 
     return 1;
+
+    /* Code below to be removed when legacy support is dropped. */
+legacy:
+
+    if (out->digest == in->digest) {
+        tmp_buf = out->md_data;
+        EVP_MD_CTX_set_flags(out, EVP_MD_CTX_FLAG_REUSE);
+    } else
+        tmp_buf = NULL;
+    EVP_MD_CTX_reset(out);
+    memcpy(out, in, sizeof(*out));
+
+    /* copied EVP_MD_CTX should free the copied EVP_PKEY_CTX */
+    EVP_MD_CTX_clear_flags(out, EVP_MD_CTX_FLAG_KEEP_PKEY_CTX);
+
+    /* Null these variables, since they are getting fixed up
+     * properly below.  Anything else may cause a memleak and/or
+     * double free if any of the memory allocations below fail
+     */
+    out->md_data = NULL;
+    out->pctx = NULL;
+
+    if (in->md_data && out->digest->ctx_size) {
+        if (tmp_buf)
+            out->md_data = tmp_buf;
+        else {
+            out->md_data = OPENSSL_malloc(out->digest->ctx_size);
+            if (out->md_data == NULL)
+                return 0;
+        }
+        memcpy(out->md_data, in->md_data, out->digest->ctx_size);
+    }
+
+    out->update = in->update;
+
+#ifndef FIPS_MODULE
+    if (in->pctx) {
+        out->pctx = EVP_PKEY_CTX_dup(in->pctx);
+        if (!out->pctx) {
+            EVP_MD_CTX_reset(out);
+            return 0;
+        }
+    }
+#endif
+
+    if (out->digest->copy)
+        return out->digest->copy(out, in);
+
+    return 1;
 }
 
 int EVP_Digest(const void *data, size_t count,
@@ -696,9 +792,8 @@ const OSSL_PARAM *EVP_MD_CTX_gettable_params(EVP_MD_CTX *ctx)
     if (ossl_unlikely(pctx != NULL)
         && (pctx->operation == EVP_PKEY_OP_VERIFYCTX
             || pctx->operation == EVP_PKEY_OP_SIGNCTX)
-        && pctx->op.sig.signature != NULL
-        && pctx->op.sig.signature->gettable_ctx_md_params != NULL
-        && pctx->op.sig.algctx != NULL)
+        && pctx->op.sig.algctx != NULL
+        && pctx->op.sig.signature->gettable_ctx_md_params != NULL)
         return pctx->op.sig.signature->gettable_ctx_md_params(
             pctx->op.sig.algctx);
 
@@ -722,10 +817,8 @@ int EVP_MD_CTX_ctrl(EVP_MD_CTX *ctx, int cmd, int p1, void *p2)
         return 0;
     }
 
-    if (ctx->digest != NULL && ctx->digest->prov == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_CTRL_NOT_IMPLEMENTED);
-        return 0;
-    }
+    if (ctx->digest != NULL && ctx->digest->prov == NULL)
+        goto legacy;
 
     switch (cmd) {
     case EVP_MD_CTRL_XOF_LEN:
@@ -749,7 +842,16 @@ int EVP_MD_CTX_ctrl(EVP_MD_CTX *ctx, int cmd, int p1, void *p2)
         ret = EVP_MD_CTX_set_params(ctx, params);
     else
         ret = EVP_MD_CTX_get_params(ctx, params);
+    goto conclude;
 
+    /* Code below to be removed when legacy support is dropped. */
+legacy:
+    if (ctx->digest->md_ctrl == NULL) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_CTRL_NOT_IMPLEMENTED);
+        return 0;
+    }
+
+    ret = ctx->digest->md_ctrl(ctx, cmd, p1, p2);
 conclude:
     if (ret <= 0)
         return 0;
@@ -832,7 +934,7 @@ static int evp_md_cache_constants(EVP_MD *md)
 
 static void *evp_md_from_algorithm(int name_id,
     const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, int no_store)
+    OSSL_PROVIDER *prov)
 {
     const OSSL_DISPATCH *fns = algodef->implementation;
     EVP_MD *md = NULL;
@@ -844,9 +946,6 @@ static void *evp_md_from_algorithm(int name_id,
         return NULL;
     }
 
-    if (no_store != 0)
-        md->flags |= EVP_MD_FLAG_NO_STORE;
-
 #ifndef FIPS_MODULE
     md->type = NID_undef;
     if (!evp_names_do_all(prov, name_id, set_legacy_nid, &md->type)
@@ -937,14 +1036,6 @@ static void *evp_md_from_algorithm(int name_id,
             if (md->copyctx == NULL)
                 md->copyctx = OSSL_FUNC_digest_copyctx(fns);
             break;
-        case OSSL_FUNC_DIGEST_SERIALIZE:
-            if (md->serialize == NULL)
-                md->serialize = OSSL_FUNC_digest_serialize(fns);
-            break;
-        case OSSL_FUNC_DIGEST_DESERIALIZE:
-            if (md->deserialize == NULL)
-                md->deserialize = OSSL_FUNC_digest_deserialize(fns);
-            break;
         }
     }
     if ((fncnt != 0 && fncnt != 5 && fncnt != 6)
@@ -971,23 +1062,95 @@ static void *evp_md_from_algorithm(int name_id,
     return md;
 
 err:
-    evp_md_free(md);
+    EVP_MD_free(md);
     return NULL;
 }
 
-static int evp_md_up_ref(void *m)
+static int evp_md_up_ref(void *md)
+{
+    return EVP_MD_up_ref(md);
+}
+
+static void evp_md_free(void *md)
+{
+    EVP_MD_free(md);
+}
+
+static void *evp_md_dup_frozen(void *vin)
+{
+    EVP_MD *in = vin;
+    EVP_MD *out;
+
+    out = OPENSSL_malloc(sizeof(*out));
+    if (out == NULL)
+        return NULL;
+    memcpy(out, in, sizeof(*out));
+    if (!CRYPTO_NEW_REF(&out->refcnt, 1))
+        goto err;
+    out->type_name = OPENSSL_strdup(in->type_name);
+    if (out->type_name == NULL)
+        goto err;
+    out->origin = EVP_ORIG_FROZEN;
+    if (!ossl_provider_up_ref(out->prov)) {
+        OPENSSL_free(out->type_name);
+        goto err;
+    }
+
+    return out;
+err:
+    CRYPTO_FREE_REF(&out->refcnt);
+    OPENSSL_free(out);
+    return NULL;
+}
+
+static void evp_md_frozen_free(EVP_MD *md)
+{
+    int i;
+
+    if (md == NULL || md->origin != EVP_ORIG_FROZEN)
+        return;
+
+    CRYPTO_DOWN_REF(&md->refcnt, &i);
+    if (i > 0)
+        return;
+    evp_md_free_int(md);
+}
+
+int evp_md_fetch_all(OSSL_LIB_CTX *ctx)
+{
+    int ret = evp_generic_fetch_all(ctx, OSSL_OP_DIGEST,
+        evp_md_from_algorithm,
+        evp_md_up_ref,
+        evp_md_free,
+        evp_md_dup_frozen,
+        (void (*)(void *))evp_md_frozen_free);
+    return ret;
+}
+
+EVP_MD *EVP_MD_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
+    const char *properties)
+{
+    EVP_MD *md = evp_generic_fetch(ctx, OSSL_OP_DIGEST, algorithm, properties,
+        evp_md_from_algorithm,
+        evp_md_up_ref,
+        evp_md_free,
+        evp_md_dup_frozen,
+        (void (*)(void *))evp_md_frozen_free);
+
+    return md;
+}
+
+int EVP_MD_up_ref(EVP_MD *md)
 {
-    EVP_MD *md = (EVP_MD *)m;
     int ref = 0;
 
     if (md->origin == EVP_ORIG_DYNAMIC)
-        return CRYPTO_UP_REF(&md->refcnt, &ref);
+        CRYPTO_UP_REF(&md->refcnt, &ref);
     return 1;
 }
 
-static void evp_md_free(void *m)
+void EVP_MD_free(EVP_MD *md)
 {
-    EVP_MD *md = (EVP_MD *)m;
     int i;
 
     if (md == NULL || md->origin != EVP_ORIG_DYNAMIC)
@@ -996,54 +1159,15 @@ static void evp_md_free(void *m)
     CRYPTO_DOWN_REF(&md->refcnt, &i);
     if (i > 0)
         return;
-
-    OPENSSL_free(md->type_name);
-    ossl_provider_free(md->prov);
-    CRYPTO_FREE_REF(&md->refcnt);
-    OPENSSL_free(md);
-}
-
-EVP_MD *EVP_MD_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
-    const char *properties)
-{
-    EVP_MD *md = evp_generic_fetch(ctx, OSSL_OP_DIGEST, algorithm, properties,
-        evp_md_from_algorithm, evp_md_up_ref, evp_md_free);
-
-    return md;
-}
-
-int EVP_MD_up_ref(EVP_MD *md)
-{
-#ifdef OPENSSL_NO_CACHED_FETCH
-    return evp_md_up_ref(md);
-#else
-    if (md->flags & EVP_MD_FLAG_NO_STORE)
-        return evp_md_up_ref(md);
-    return 1;
-#endif
-}
-
-void EVP_MD_free(EVP_MD *md)
-{
-#ifdef OPENSSL_NO_CACHED_FETCH
-    evp_md_free(md);
-#else
-    if (md != NULL && (md->flags & EVP_MD_FLAG_NO_STORE))
-        evp_md_free(md);
-    return;
-#endif
+    evp_md_free_int(md);
 }
 
 void EVP_MD_do_all_provided(OSSL_LIB_CTX *libctx,
     void (*fn)(EVP_MD *mac, void *arg),
     void *arg)
 {
-    struct EVP_MD_do_all_provided_thunk t;
-
-    t.fn = fn;
-    t.arg = arg;
     evp_generic_do_all(libctx, OSSL_OP_DIGEST,
-        EVP_MD_do_all_provided_thunk, &t,
+        (void (*)(void *, void *))fn, arg,
         evp_md_from_algorithm, evp_md_up_ref, evp_md_free);
 }
 
@@ -1055,7 +1179,9 @@ EVP_MD *evp_digest_fetch_from_prov(OSSL_PROVIDER *prov,
         algorithm, properties,
         evp_md_from_algorithm,
         evp_md_up_ref,
-        evp_md_free);
+        evp_md_free,
+        evp_md_dup_frozen,
+        (void (*)(void *))evp_md_frozen_free);
 }
 
 typedef struct {
diff --git a/crypto/evp/dsa_ctrl.c b/crypto/evp/dsa_ctrl.c
index 8490a1fe82..af1b055ee4 100644
--- a/crypto/evp/dsa_ctrl.c
+++ b/crypto/evp/dsa_ctrl.c
@@ -22,7 +22,7 @@ static int dsa_paramgen_check(EVP_PKEY_CTX *ctx)
         return -2;
     }
     /* If key type not DSA return error */
-    if (ctx->legacy_keytype != EVP_PKEY_DSA)
+    if (ctx->pmeth != NULL && ctx->pmeth->pkey_id != EVP_PKEY_DSA)
         return -1;
     return 1;
 }
diff --git a/crypto/evp/e_aes.c b/crypto/evp/e_aes.c
index 92773bb3a8..748df92baa 100644
--- a/crypto/evp/e_aes.c
+++ b/crypto/evp/e_aes.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2001-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,16 +7,2376 @@
  * https://www.openssl.org/source/license.html
  */
 
+/*
+ * This file uses the low-level AES functions (which are deprecated for
+ * non-internal use) in order to implement the EVP AES ciphers.
+ */
+#include "internal/deprecated.h"
+
+#include 
+#include 
+#include 
+#include 
+#include 
+#include 
+#include 
+#include 
+#include 
 #include "crypto/evp.h"
+#include "internal/cryptlib.h"
+#include "crypto/modes.h"
+#include "crypto/siv.h"
+#include "crypto/aes_platform.h"
+#include "evp_local.h"
+
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        AES_KEY ks;
+    } ks;
+    block128_f block;
+    union {
+        cbc128_f cbc;
+        ctr128_f ctr;
+    } stream;
+} EVP_AES_KEY;
+
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        AES_KEY ks;
+    } ks; /* AES key schedule to use */
+    int key_set; /* Set if key initialised */
+    int iv_set; /* Set if an iv is set */
+    GCM128_CONTEXT gcm;
+    unsigned char *iv; /* Temporary IV store */
+    int ivlen; /* IV length */
+    int taglen;
+    int iv_gen; /* It is OK to generate IVs */
+    int iv_gen_rand; /* No IV was specified, so generate a rand IV */
+    int tls_aad_len; /* TLS AAD length */
+    uint64_t tls_enc_records; /* Number of TLS records encrypted */
+    ctr128_f ctr;
+} EVP_AES_GCM_CTX;
+
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        AES_KEY ks;
+    } ks1, ks2; /* AES key schedules to use */
+    XTS128_CONTEXT xts;
+    void (*stream)(const unsigned char *in,
+        unsigned char *out, size_t length,
+        const AES_KEY *key1, const AES_KEY *key2,
+        const unsigned char iv[16]);
+} EVP_AES_XTS_CTX;
+
+#ifdef FIPS_MODULE
+static const int allow_insecure_decrypt = 0;
+#else
+static const int allow_insecure_decrypt = 1;
+#endif
+
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        AES_KEY ks;
+    } ks; /* AES key schedule to use */
+    int key_set; /* Set if key initialised */
+    int iv_set; /* Set if an iv is set */
+    int tag_set; /* Set if tag is valid */
+    int len_set; /* Set if message length set */
+    int L, M; /* L and M parameters from RFC3610 */
+    int tls_aad_len; /* TLS AAD length */
+    CCM128_CONTEXT ccm;
+    ccm128_f str;
+} EVP_AES_CCM_CTX;
+
+#ifndef OPENSSL_NO_OCB
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        AES_KEY ks;
+    } ksenc; /* AES key schedule to use for encryption */
+    union {
+        OSSL_UNION_ALIGN;
+        AES_KEY ks;
+    } ksdec; /* AES key schedule to use for decryption */
+    int key_set; /* Set if key initialised */
+    int iv_set; /* Set if an iv is set */
+    OCB128_CONTEXT ocb;
+    unsigned char *iv; /* Temporary IV store */
+    unsigned char tag[16];
+    unsigned char data_buf[16]; /* Store partial data blocks */
+    unsigned char aad_buf[16]; /* Store partial AAD blocks */
+    int data_buf_len;
+    int aad_buf_len;
+    int ivlen; /* IV length */
+    int taglen;
+} EVP_AES_OCB_CTX;
+#endif
+
+#define MAXBITCHUNK ((size_t)1 << (sizeof(size_t) * 8 - 4))
+
+/* increment counter (64-bit int) by 1 */
+static void ctr64_inc(unsigned char *counter)
+{
+    int n = 8;
+    unsigned char c;
+
+    do {
+        --n;
+        c = counter[n];
+        ++c;
+        counter[n] = c;
+        if (c)
+            return;
+    } while (n);
+}
+
+#if defined(AESNI_CAPABLE)
+#if defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)
+#define AES_GCM_ASM2(gctx) (gctx->gcm.block == (block128_f)aesni_encrypt && gctx->gcm.ghash == gcm_ghash_avx)
+#undef AES_GCM_ASM2 /* minor size optimization */
+#endif
+
+static int aesni_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    int ret, mode;
+    EVP_AES_KEY *dat = EVP_C_DATA(EVP_AES_KEY, ctx);
+    const int keylen = EVP_CIPHER_CTX_get_key_length(ctx) * 8;
+
+    if (keylen <= 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+        return 0;
+    }
+    mode = EVP_CIPHER_CTX_get_mode(ctx);
+    if ((mode == EVP_CIPH_ECB_MODE || mode == EVP_CIPH_CBC_MODE)
+        && !enc) {
+        ret = aesni_set_decrypt_key(key, keylen, &dat->ks.ks);
+        dat->block = (block128_f)aesni_decrypt;
+        dat->stream.cbc = mode == EVP_CIPH_CBC_MODE ? (cbc128_f)aesni_cbc_encrypt : NULL;
+    } else {
+        ret = aesni_set_encrypt_key(key, keylen, &dat->ks.ks);
+        dat->block = (block128_f)aesni_encrypt;
+        if (mode == EVP_CIPH_CBC_MODE)
+            dat->stream.cbc = (cbc128_f)aesni_cbc_encrypt;
+        else if (mode == EVP_CIPH_CTR_MODE)
+            dat->stream.ctr = (ctr128_f)aesni_ctr32_encrypt_blocks;
+        else
+            dat->stream.cbc = NULL;
+    }
+
+    if (ret < 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_AES_KEY_SETUP_FAILED);
+        return 0;
+    }
+
+    return 1;
+}
+
+static int aesni_cbc_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    aesni_cbc_encrypt(in, out, len, &EVP_C_DATA(EVP_AES_KEY, ctx)->ks.ks,
+        ctx->iv, EVP_CIPHER_CTX_is_encrypting(ctx));
+
+    return 1;
+}
+
+static int aesni_ecb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    size_t bl = EVP_CIPHER_CTX_get_block_size(ctx);
+
+    if (len < bl)
+        return 1;
+
+    aesni_ecb_encrypt(in, out, len, &EVP_C_DATA(EVP_AES_KEY, ctx)->ks.ks,
+        EVP_CIPHER_CTX_is_encrypting(ctx));
+
+    return 1;
+}
+
+#define aesni_ofb_cipher aes_ofb_cipher
+static int aesni_ofb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define aesni_cfb_cipher aes_cfb_cipher
+static int aesni_cfb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define aesni_cfb8_cipher aes_cfb8_cipher
+static int aesni_cfb8_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define aesni_cfb1_cipher aes_cfb1_cipher
+static int aesni_cfb1_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define aesni_ctr_cipher aes_ctr_cipher
+static int aesni_ctr_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+static int aesni_gcm_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    EVP_AES_GCM_CTX *gctx = EVP_C_DATA(EVP_AES_GCM_CTX, ctx);
+
+    if (iv == NULL && key == NULL)
+        return 1;
+
+    if (key) {
+        const int keylen = EVP_CIPHER_CTX_get_key_length(ctx) * 8;
+
+        if (keylen <= 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+            return 0;
+        }
+        aesni_set_encrypt_key(key, keylen, &gctx->ks.ks);
+        CRYPTO_gcm128_init(&gctx->gcm, &gctx->ks, (block128_f)aesni_encrypt);
+        gctx->ctr = (ctr128_f)aesni_ctr32_encrypt_blocks;
+        /*
+         * If we have an iv can set it directly, otherwise use saved IV.
+         */
+        if (iv == NULL && gctx->iv_set)
+            iv = gctx->iv;
+        if (iv) {
+            CRYPTO_gcm128_setiv(&gctx->gcm, iv, gctx->ivlen);
+            gctx->iv_set = 1;
+        }
+        gctx->key_set = 1;
+    } else {
+        /* If key set use IV, otherwise copy */
+        if (gctx->key_set)
+            CRYPTO_gcm128_setiv(&gctx->gcm, iv, gctx->ivlen);
+        else
+            memcpy(gctx->iv, iv, gctx->ivlen);
+        gctx->iv_set = 1;
+        gctx->iv_gen = 0;
+    }
+    return 1;
+}
+
+#define aesni_gcm_cipher aes_gcm_cipher
+static int aesni_gcm_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+static int aesni_xts_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    EVP_AES_XTS_CTX *xctx = EVP_C_DATA(EVP_AES_XTS_CTX, ctx);
+
+    if (iv == NULL && key == NULL)
+        return 1;
+
+    if (key) {
+        /* The key is two half length keys in reality */
+        const int keylen = EVP_CIPHER_CTX_get_key_length(ctx);
+        const int bytes = keylen / 2;
+        const int bits = bytes * 8;
+
+        if (keylen <= 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+            return 0;
+        }
+        /*
+         * Verify that the two keys are different.
+         *
+         * This addresses Rogaway's vulnerability.
+         * See comment in aes_xts_init_key() below.
+         */
+        if ((!allow_insecure_decrypt || enc)
+            && CRYPTO_memcmp(key, key + bytes, bytes) == 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_XTS_DUPLICATED_KEYS);
+            return 0;
+        }
+
+        /* key_len is two AES keys */
+        if (enc) {
+            aesni_set_encrypt_key(key, bits, &xctx->ks1.ks);
+            xctx->xts.block1 = (block128_f)aesni_encrypt;
+            xctx->stream = aesni_xts_encrypt;
+        } else {
+            aesni_set_decrypt_key(key, bits, &xctx->ks1.ks);
+            xctx->xts.block1 = (block128_f)aesni_decrypt;
+            xctx->stream = aesni_xts_decrypt;
+        }
+
+        aesni_set_encrypt_key(key + bytes, bits, &xctx->ks2.ks);
+        xctx->xts.block2 = (block128_f)aesni_encrypt;
+
+        xctx->xts.key1 = &xctx->ks1;
+    }
+
+    if (iv) {
+        xctx->xts.key2 = &xctx->ks2;
+        memcpy(ctx->iv, iv, 16);
+    }
+
+    return 1;
+}
+
+#define aesni_xts_cipher aes_xts_cipher
+static int aesni_xts_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+static int aesni_ccm_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    EVP_AES_CCM_CTX *cctx = EVP_C_DATA(EVP_AES_CCM_CTX, ctx);
+
+    if (iv == NULL && key == NULL)
+        return 1;
+
+    if (key != NULL) {
+        const int keylen = EVP_CIPHER_CTX_get_key_length(ctx) * 8;
+
+        if (keylen <= 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+            return 0;
+        }
+        aesni_set_encrypt_key(key, keylen, &cctx->ks.ks);
+        CRYPTO_ccm128_init(&cctx->ccm, cctx->M, cctx->L,
+            &cctx->ks, (block128_f)aesni_encrypt);
+        cctx->str = enc ? (ccm128_f)aesni_ccm64_encrypt_blocks : (ccm128_f)aesni_ccm64_decrypt_blocks;
+        cctx->key_set = 1;
+    }
+    if (iv) {
+        memcpy(ctx->iv, iv, 15 - cctx->L);
+        cctx->iv_set = 1;
+    }
+    return 1;
+}
+
+#define aesni_ccm_cipher aes_ccm_cipher
+static int aesni_ccm_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#ifndef OPENSSL_NO_OCB
+static int aesni_ocb_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    EVP_AES_OCB_CTX *octx = EVP_C_DATA(EVP_AES_OCB_CTX, ctx);
+
+    if (iv == NULL && key == NULL)
+        return 1;
+
+    if (key != NULL) {
+        const int keylen = EVP_CIPHER_CTX_get_key_length(ctx) * 8;
+
+        if (keylen <= 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+            return 0;
+        }
+        do {
+            /*
+             * We set both the encrypt and decrypt key here because decrypt
+             * needs both. We could possibly optimise to remove setting the
+             * decrypt for an encryption operation.
+             */
+            aesni_set_encrypt_key(key, keylen, &octx->ksenc.ks);
+            aesni_set_decrypt_key(key, keylen, &octx->ksdec.ks);
+            if (!CRYPTO_ocb128_init(&octx->ocb,
+                    &octx->ksenc.ks, &octx->ksdec.ks,
+                    (block128_f)aesni_encrypt,
+                    (block128_f)aesni_decrypt,
+                    enc ? aesni_ocb_encrypt
+                        : aesni_ocb_decrypt))
+                return 0;
+        } while (0);
+
+        /*
+         * If we have an iv we can set it directly, otherwise use saved IV.
+         */
+        if (iv == NULL && octx->iv_set)
+            iv = octx->iv;
+        if (iv) {
+            if (CRYPTO_ocb128_setiv(&octx->ocb, iv, octx->ivlen, octx->taglen)
+                != 1)
+                return 0;
+            octx->iv_set = 1;
+        }
+        octx->key_set = 1;
+    } else {
+        /* If key set use IV, otherwise copy */
+        if (octx->key_set)
+            CRYPTO_ocb128_setiv(&octx->ocb, iv, octx->ivlen, octx->taglen);
+        else
+            memcpy(octx->iv, iv, octx->ivlen);
+        octx->iv_set = 1;
+    }
+    return 1;
+}
+
+#define aesni_ocb_cipher aes_ocb_cipher
+static int aesni_ocb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+#endif /* OPENSSL_NO_OCB */
+
+#define BLOCK_CIPHER_generic(nid, keylen, blocksize, ivlen, nmode, mode, MODE, flags) \
+    static const EVP_CIPHER aesni_##keylen##_##mode = {                               \
+        nid##_##keylen##_##nmode, blocksize, keylen / 8, ivlen,                       \
+        flags | EVP_CIPH_##MODE##_MODE,                                               \
+        EVP_ORIG_GLOBAL,                                                              \
+        aesni_init_key,                                                               \
+        aesni_##mode##_cipher,                                                        \
+        NULL,                                                                         \
+        sizeof(EVP_AES_KEY),                                                          \
+        NULL, NULL, NULL, NULL                                                        \
+    };                                                                                \
+    static const EVP_CIPHER aes_##keylen##_##mode = {                                 \
+        nid##_##keylen##_##nmode, blocksize,                                          \
+        keylen / 8, ivlen,                                                            \
+        flags | EVP_CIPH_##MODE##_MODE,                                               \
+        EVP_ORIG_GLOBAL,                                                              \
+        aes_init_key,                                                                 \
+        aes_##mode##_cipher,                                                          \
+        NULL,                                                                         \
+        sizeof(EVP_AES_KEY),                                                          \
+        NULL, NULL, NULL, NULL                                                        \
+    };                                                                                \
+    const EVP_CIPHER *EVP_aes_##keylen##_##mode(void)                                 \
+    {                                                                                 \
+        return AESNI_CAPABLE ? &aesni_##keylen##_##mode : &aes_##keylen##_##mode;     \
+    }
+
+#define BLOCK_CIPHER_custom(nid, keylen, blocksize, ivlen, mode, MODE, flags)                                              \
+    static const EVP_CIPHER aesni_##keylen##_##mode = {                                                                    \
+        nid##_##keylen##_##mode, blocksize,                                                                                \
+        (EVP_CIPH_##MODE##_MODE == EVP_CIPH_XTS_MODE || EVP_CIPH_##MODE##_MODE == EVP_CIPH_SIV_MODE ? 2 : 1) * keylen / 8, \
+        ivlen,                                                                                                             \
+        flags | EVP_CIPH_##MODE##_MODE,                                                                                    \
+        EVP_ORIG_GLOBAL,                                                                                                   \
+        aesni_##mode##_init_key,                                                                                           \
+        aesni_##mode##_cipher,                                                                                             \
+        aes_##mode##_cleanup,                                                                                              \
+        sizeof(EVP_AES_##MODE##_CTX),                                                                                      \
+        NULL, NULL, aes_##mode##_ctrl, NULL                                                                                \
+    };                                                                                                                     \
+    static const EVP_CIPHER aes_##keylen##_##mode = {                                                                      \
+        nid##_##keylen##_##mode, blocksize,                                                                                \
+        (EVP_CIPH_##MODE##_MODE == EVP_CIPH_XTS_MODE || EVP_CIPH_##MODE##_MODE == EVP_CIPH_SIV_MODE ? 2 : 1) * keylen / 8, \
+        ivlen,                                                                                                             \
+        flags | EVP_CIPH_##MODE##_MODE,                                                                                    \
+        EVP_ORIG_GLOBAL,                                                                                                   \
+        aes_##mode##_init_key,                                                                                             \
+        aes_##mode##_cipher,                                                                                               \
+        aes_##mode##_cleanup,                                                                                              \
+        sizeof(EVP_AES_##MODE##_CTX),                                                                                      \
+        NULL, NULL, aes_##mode##_ctrl, NULL                                                                                \
+    };                                                                                                                     \
+    const EVP_CIPHER *EVP_aes_##keylen##_##mode(void)                                                                      \
+    {                                                                                                                      \
+        return AESNI_CAPABLE ? &aesni_##keylen##_##mode : &aes_##keylen##_##mode;                                          \
+    }
+
+#elif defined(SPARC_AES_CAPABLE)
+
+static int aes_t4_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    int ret, mode, bits;
+    EVP_AES_KEY *dat = EVP_C_DATA(EVP_AES_KEY, ctx);
+
+    mode = EVP_CIPHER_CTX_get_mode(ctx);
+    bits = EVP_CIPHER_CTX_get_key_length(ctx) * 8;
+    if (bits <= 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+        return 0;
+    }
+    if ((mode == EVP_CIPH_ECB_MODE || mode == EVP_CIPH_CBC_MODE)
+        && !enc) {
+        ret = 0;
+        aes_t4_set_decrypt_key(key, bits, &dat->ks.ks);
+        dat->block = (block128_f)aes_t4_decrypt;
+        switch (bits) {
+        case 128:
+            dat->stream.cbc = mode == EVP_CIPH_CBC_MODE ? (cbc128_f)aes128_t4_cbc_decrypt : NULL;
+            break;
+        case 192:
+            dat->stream.cbc = mode == EVP_CIPH_CBC_MODE ? (cbc128_f)aes192_t4_cbc_decrypt : NULL;
+            break;
+        case 256:
+            dat->stream.cbc = mode == EVP_CIPH_CBC_MODE ? (cbc128_f)aes256_t4_cbc_decrypt : NULL;
+            break;
+        default:
+            ret = -1;
+        }
+    } else {
+        ret = 0;
+        aes_t4_set_encrypt_key(key, bits, &dat->ks.ks);
+        dat->block = (block128_f)aes_t4_encrypt;
+        switch (bits) {
+        case 128:
+            if (mode == EVP_CIPH_CBC_MODE)
+                dat->stream.cbc = (cbc128_f)aes128_t4_cbc_encrypt;
+            else if (mode == EVP_CIPH_CTR_MODE)
+                dat->stream.ctr = (ctr128_f)aes128_t4_ctr32_encrypt;
+            else
+                dat->stream.cbc = NULL;
+            break;
+        case 192:
+            if (mode == EVP_CIPH_CBC_MODE)
+                dat->stream.cbc = (cbc128_f)aes192_t4_cbc_encrypt;
+            else if (mode == EVP_CIPH_CTR_MODE)
+                dat->stream.ctr = (ctr128_f)aes192_t4_ctr32_encrypt;
+            else
+                dat->stream.cbc = NULL;
+            break;
+        case 256:
+            if (mode == EVP_CIPH_CBC_MODE)
+                dat->stream.cbc = (cbc128_f)aes256_t4_cbc_encrypt;
+            else if (mode == EVP_CIPH_CTR_MODE)
+                dat->stream.ctr = (ctr128_f)aes256_t4_ctr32_encrypt;
+            else
+                dat->stream.cbc = NULL;
+            break;
+        default:
+            ret = -1;
+        }
+    }
+
+    if (ret < 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_AES_KEY_SETUP_FAILED);
+        return 0;
+    }
+
+    return 1;
+}
+
+#define aes_t4_cbc_cipher aes_cbc_cipher
+static int aes_t4_cbc_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define aes_t4_ecb_cipher aes_ecb_cipher
+static int aes_t4_ecb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define aes_t4_ofb_cipher aes_ofb_cipher
+static int aes_t4_ofb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define aes_t4_cfb_cipher aes_cfb_cipher
+static int aes_t4_cfb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define aes_t4_cfb8_cipher aes_cfb8_cipher
+static int aes_t4_cfb8_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define aes_t4_cfb1_cipher aes_cfb1_cipher
+static int aes_t4_cfb1_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define aes_t4_ctr_cipher aes_ctr_cipher
+static int aes_t4_ctr_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+static int aes_t4_gcm_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    EVP_AES_GCM_CTX *gctx = EVP_C_DATA(EVP_AES_GCM_CTX, ctx);
+
+    if (iv == NULL && key == NULL)
+        return 1;
+    if (key) {
+        const int bits = EVP_CIPHER_CTX_get_key_length(ctx) * 8;
+
+        if (bits <= 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+            return 0;
+        }
+        aes_t4_set_encrypt_key(key, bits, &gctx->ks.ks);
+        CRYPTO_gcm128_init(&gctx->gcm, &gctx->ks,
+            (block128_f)aes_t4_encrypt);
+        switch (bits) {
+        case 128:
+            gctx->ctr = (ctr128_f)aes128_t4_ctr32_encrypt;
+            break;
+        case 192:
+            gctx->ctr = (ctr128_f)aes192_t4_ctr32_encrypt;
+            break;
+        case 256:
+            gctx->ctr = (ctr128_f)aes256_t4_ctr32_encrypt;
+            break;
+        default:
+            return 0;
+        }
+        /*
+         * If we have an iv can set it directly, otherwise use saved IV.
+         */
+        if (iv == NULL && gctx->iv_set)
+            iv = gctx->iv;
+        if (iv) {
+            CRYPTO_gcm128_setiv(&gctx->gcm, iv, gctx->ivlen);
+            gctx->iv_set = 1;
+        }
+        gctx->key_set = 1;
+    } else {
+        /* If key set use IV, otherwise copy */
+        if (gctx->key_set)
+            CRYPTO_gcm128_setiv(&gctx->gcm, iv, gctx->ivlen);
+        else
+            memcpy(gctx->iv, iv, gctx->ivlen);
+        gctx->iv_set = 1;
+        gctx->iv_gen = 0;
+    }
+    return 1;
+}
+
+#define aes_t4_gcm_cipher aes_gcm_cipher
+static int aes_t4_gcm_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+static int aes_t4_xts_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    EVP_AES_XTS_CTX *xctx = EVP_C_DATA(EVP_AES_XTS_CTX, ctx);
+
+    if (!iv && !key)
+        return 1;
+
+    if (key) {
+        /* The key is two half length keys in reality */
+        const int keylen = EVP_CIPHER_CTX_get_key_length(ctx);
+        const int bytes = keylen / 2;
+        const int bits = bytes * 8;
+
+        if (keylen <= 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+            return 0;
+        }
+        /*
+         * Verify that the two keys are different.
+         *
+         * This addresses Rogaway's vulnerability.
+         * See comment in aes_xts_init_key() below.
+         */
+        if ((!allow_insecure_decrypt || enc)
+            && CRYPTO_memcmp(key, key + bytes, bytes) == 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_XTS_DUPLICATED_KEYS);
+            return 0;
+        }
+
+        xctx->stream = NULL;
+        /* key_len is two AES keys */
+        if (enc) {
+            aes_t4_set_encrypt_key(key, bits, &xctx->ks1.ks);
+            xctx->xts.block1 = (block128_f)aes_t4_encrypt;
+            switch (bits) {
+            case 128:
+                xctx->stream = aes128_t4_xts_encrypt;
+                break;
+            case 256:
+                xctx->stream = aes256_t4_xts_encrypt;
+                break;
+            default:
+                return 0;
+            }
+        } else {
+            aes_t4_set_decrypt_key(key, bits, &xctx->ks1.ks);
+            xctx->xts.block1 = (block128_f)aes_t4_decrypt;
+            switch (bits) {
+            case 128:
+                xctx->stream = aes128_t4_xts_decrypt;
+                break;
+            case 256:
+                xctx->stream = aes256_t4_xts_decrypt;
+                break;
+            default:
+                return 0;
+            }
+        }
+
+        aes_t4_set_encrypt_key(key + bytes, bits, &xctx->ks2.ks);
+        xctx->xts.block2 = (block128_f)aes_t4_encrypt;
+
+        xctx->xts.key1 = &xctx->ks1;
+    }
+
+    if (iv) {
+        xctx->xts.key2 = &xctx->ks2;
+        memcpy(ctx->iv, iv, 16);
+    }
+
+    return 1;
+}
+
+#define aes_t4_xts_cipher aes_xts_cipher
+static int aes_t4_xts_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+static int aes_t4_ccm_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    EVP_AES_CCM_CTX *cctx = EVP_C_DATA(EVP_AES_CCM_CTX, ctx);
+
+    if (iv == NULL && key == NULL)
+        return 1;
+
+    if (key != NULL) {
+        const int bits = EVP_CIPHER_CTX_get_key_length(ctx) * 8;
+
+        if (bits <= 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+            return 0;
+        }
+        aes_t4_set_encrypt_key(key, bits, &cctx->ks.ks);
+        CRYPTO_ccm128_init(&cctx->ccm, cctx->M, cctx->L,
+            &cctx->ks, (block128_f)aes_t4_encrypt);
+        cctx->str = NULL;
+        cctx->key_set = 1;
+    }
+    if (iv) {
+        memcpy(ctx->iv, iv, 15 - cctx->L);
+        cctx->iv_set = 1;
+    }
+    return 1;
+}
+
+#define aes_t4_ccm_cipher aes_ccm_cipher
+static int aes_t4_ccm_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#ifndef OPENSSL_NO_OCB
+static int aes_t4_ocb_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    EVP_AES_OCB_CTX *octx = EVP_C_DATA(EVP_AES_OCB_CTX, ctx);
+
+    if (iv == NULL && key == NULL)
+        return 1;
+
+    if (key != NULL) {
+        const int keylen = EVP_CIPHER_CTX_get_key_length(ctx) * 8;
+
+        if (keylen <= 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+            return 0;
+        }
+        do {
+            /*
+             * We set both the encrypt and decrypt key here because decrypt
+             * needs both. We could possibly optimise to remove setting the
+             * decrypt for an encryption operation.
+             */
+            aes_t4_set_encrypt_key(key, keylen, &octx->ksenc.ks);
+            aes_t4_set_decrypt_key(key, keylen, &octx->ksdec.ks);
+            if (!CRYPTO_ocb128_init(&octx->ocb,
+                    &octx->ksenc.ks, &octx->ksdec.ks,
+                    (block128_f)aes_t4_encrypt,
+                    (block128_f)aes_t4_decrypt,
+                    NULL))
+                return 0;
+        } while (0);
+
+        /*
+         * If we have an iv we can set it directly, otherwise use saved IV.
+         */
+        if (iv == NULL && octx->iv_set)
+            iv = octx->iv;
+        if (iv) {
+            if (CRYPTO_ocb128_setiv(&octx->ocb, iv, octx->ivlen, octx->taglen)
+                != 1)
+                return 0;
+            octx->iv_set = 1;
+        }
+        octx->key_set = 1;
+    } else {
+        /* If key set use IV, otherwise copy */
+        if (octx->key_set)
+            CRYPTO_ocb128_setiv(&octx->ocb, iv, octx->ivlen, octx->taglen);
+        else
+            memcpy(octx->iv, iv, octx->ivlen);
+        octx->iv_set = 1;
+    }
+    return 1;
+}
+
+#define aes_t4_ocb_cipher aes_ocb_cipher
+static int aes_t4_ocb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+#endif /* OPENSSL_NO_OCB */
+
+#ifndef OPENSSL_NO_SIV
+#define aes_t4_siv_init_key aes_siv_init_key
+#define aes_t4_siv_cipher aes_siv_cipher
+#endif /* OPENSSL_NO_SIV */
+
+#define BLOCK_CIPHER_generic(nid, keylen, blocksize, ivlen, nmode, mode, MODE, flags)  \
+    static const EVP_CIPHER aes_t4_##keylen##_##mode = {                               \
+        nid##_##keylen##_##nmode, blocksize, keylen / 8, ivlen,                        \
+        flags | EVP_CIPH_##MODE##_MODE,                                                \
+        EVP_ORIG_GLOBAL,                                                               \
+        aes_t4_init_key,                                                               \
+        aes_t4_##mode##_cipher,                                                        \
+        NULL,                                                                          \
+        sizeof(EVP_AES_KEY),                                                           \
+        NULL, NULL, NULL, NULL                                                         \
+    };                                                                                 \
+    static const EVP_CIPHER aes_##keylen##_##mode = {                                  \
+        nid##_##keylen##_##nmode, blocksize,                                           \
+        keylen / 8, ivlen,                                                             \
+        flags | EVP_CIPH_##MODE##_MODE,                                                \
+        EVP_ORIG_GLOBAL,                                                               \
+        aes_init_key,                                                                  \
+        aes_##mode##_cipher,                                                           \
+        NULL,                                                                          \
+        sizeof(EVP_AES_KEY),                                                           \
+        NULL, NULL, NULL, NULL                                                         \
+    };                                                                                 \
+    const EVP_CIPHER *EVP_aes_##keylen##_##mode(void)                                  \
+    {                                                                                  \
+        return SPARC_AES_CAPABLE ? &aes_t4_##keylen##_##mode : &aes_##keylen##_##mode; \
+    }
+
+#define BLOCK_CIPHER_custom(nid, keylen, blocksize, ivlen, mode, MODE, flags)                                              \
+    static const EVP_CIPHER aes_t4_##keylen##_##mode = {                                                                   \
+        nid##_##keylen##_##mode, blocksize,                                                                                \
+        (EVP_CIPH_##MODE##_MODE == EVP_CIPH_XTS_MODE || EVP_CIPH_##MODE##_MODE == EVP_CIPH_SIV_MODE ? 2 : 1) * keylen / 8, \
+        ivlen,                                                                                                             \
+        flags | EVP_CIPH_##MODE##_MODE,                                                                                    \
+        EVP_ORIG_GLOBAL,                                                                                                   \
+        aes_t4_##mode##_init_key,                                                                                          \
+        aes_t4_##mode##_cipher,                                                                                            \
+        aes_##mode##_cleanup,                                                                                              \
+        sizeof(EVP_AES_##MODE##_CTX),                                                                                      \
+        NULL, NULL, aes_##mode##_ctrl, NULL                                                                                \
+    };                                                                                                                     \
+    static const EVP_CIPHER aes_##keylen##_##mode = {                                                                      \
+        nid##_##keylen##_##mode, blocksize,                                                                                \
+        (EVP_CIPH_##MODE##_MODE == EVP_CIPH_XTS_MODE || EVP_CIPH_##MODE##_MODE == EVP_CIPH_SIV_MODE ? 2 : 1) * keylen / 8, \
+        ivlen,                                                                                                             \
+        flags | EVP_CIPH_##MODE##_MODE,                                                                                    \
+        EVP_ORIG_GLOBAL,                                                                                                   \
+        aes_##mode##_init_key,                                                                                             \
+        aes_##mode##_cipher,                                                                                               \
+        aes_##mode##_cleanup,                                                                                              \
+        sizeof(EVP_AES_##MODE##_CTX),                                                                                      \
+        NULL, NULL, aes_##mode##_ctrl, NULL                                                                                \
+    };                                                                                                                     \
+    const EVP_CIPHER *EVP_aes_##keylen##_##mode(void)                                                                      \
+    {                                                                                                                      \
+        return SPARC_AES_CAPABLE ? &aes_t4_##keylen##_##mode : &aes_##keylen##_##mode;                                     \
+    }
+
+#elif defined(S390X_aes_128_CAPABLE)
+/* IBM S390X support */
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        /*-
+         * KM-AES parameter block - begin
+         * (see z/Architecture Principles of Operation >= SA22-7832-06)
+         */
+        struct {
+            unsigned char k[32];
+        } param;
+        /* KM-AES parameter block - end */
+    } km;
+    unsigned int fc;
+} S390X_AES_ECB_CTX;
+
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        /*-
+         * KMO-AES parameter block - begin
+         * (see z/Architecture Principles of Operation >= SA22-7832-08)
+         */
+        struct {
+            unsigned char cv[16];
+            unsigned char k[32];
+        } param;
+        /* KMO-AES parameter block - end */
+    } kmo;
+    unsigned int fc;
+} S390X_AES_OFB_CTX;
+
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        /*-
+         * KMF-AES parameter block - begin
+         * (see z/Architecture Principles of Operation >= SA22-7832-08)
+         */
+        struct {
+            unsigned char cv[16];
+            unsigned char k[32];
+        } param;
+        /* KMF-AES parameter block - end */
+    } kmf;
+    unsigned int fc;
+} S390X_AES_CFB_CTX;
+
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        /*-
+         * KMA-GCM-AES parameter block - begin
+         * (see z/Architecture Principles of Operation >= SA22-7832-11)
+         */
+        struct {
+            unsigned char reserved[12];
+            union {
+                unsigned int w;
+                unsigned char b[4];
+            } cv;
+            union {
+                unsigned long long g[2];
+                unsigned char b[16];
+            } t;
+            unsigned char h[16];
+            unsigned long long taadl;
+            unsigned long long tpcl;
+            union {
+                unsigned long long g[2];
+                unsigned int w[4];
+            } j0;
+            unsigned char k[32];
+        } param;
+        /* KMA-GCM-AES parameter block - end */
+    } kma;
+    unsigned int fc;
+    int key_set;
+
+    unsigned char *iv;
+    int ivlen;
+    int iv_set;
+    int iv_gen;
+
+    int taglen;
+
+    unsigned char ares[16];
+    unsigned char mres[16];
+    unsigned char kres[16];
+    int areslen;
+    int mreslen;
+    int kreslen;
+
+    int tls_aad_len;
+    uint64_t tls_enc_records; /* Number of TLS records encrypted */
+} S390X_AES_GCM_CTX;
+
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        /*-
+         * Padding is chosen so that ccm.kmac_param.k overlaps with key.k and
+         * ccm.fc with key.k.rounds. Remember that on s390x, an AES_KEY's
+         * rounds field is used to store the function code and that the key
+         * schedule is not stored (if aes hardware support is detected).
+         */
+        struct {
+            unsigned char pad[16];
+            AES_KEY k;
+        } key;
+
+        struct {
+            /*-
+             * KMAC-AES parameter block - begin
+             * (see z/Architecture Principles of Operation >= SA22-7832-08)
+             */
+            struct {
+                union {
+                    unsigned long long g[2];
+                    unsigned char b[16];
+                } icv;
+                unsigned char k[32];
+            } kmac_param;
+            /* KMAC-AES parameter block - end */
+
+            union {
+                unsigned long long g[2];
+                unsigned char b[16];
+            } nonce;
+            union {
+                unsigned long long g[2];
+                unsigned char b[16];
+            } buf;
+
+            unsigned long long blocks;
+            int l;
+            int m;
+            int tls_aad_len;
+            int iv_set;
+            int tag_set;
+            int len_set;
+            int key_set;
+
+            unsigned char pad[140];
+            unsigned int fc;
+        } ccm;
+    } aes;
+} S390X_AES_CCM_CTX;
+
+#define s390x_aes_init_key aes_init_key
+static int s390x_aes_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc);
+
+#define S390X_AES_CBC_CTX EVP_AES_KEY
+
+#define s390x_aes_cbc_init_key aes_init_key
+
+#define s390x_aes_cbc_cipher aes_cbc_cipher
+static int s390x_aes_cbc_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+static int s390x_aes_ecb_init_key(EVP_CIPHER_CTX *ctx,
+    const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    S390X_AES_ECB_CTX *cctx = EVP_C_DATA(S390X_AES_ECB_CTX, ctx);
+    const int keylen = EVP_CIPHER_CTX_get_key_length(ctx);
+
+    if (keylen <= 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+        return 0;
+    }
+    cctx->fc = S390X_AES_FC(keylen);
+    if (!enc)
+        cctx->fc |= S390X_DECRYPT;
+
+    memcpy(cctx->km.param.k, key, keylen);
+    return 1;
+}
+
+static int s390x_aes_ecb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    S390X_AES_ECB_CTX *cctx = EVP_C_DATA(S390X_AES_ECB_CTX, ctx);
+
+    s390x_km(in, len, out, cctx->fc, &cctx->km.param);
+    return 1;
+}
+
+static int s390x_aes_ofb_init_key(EVP_CIPHER_CTX *ctx,
+    const unsigned char *key,
+    const unsigned char *ivec, int enc)
+{
+    S390X_AES_OFB_CTX *cctx = EVP_C_DATA(S390X_AES_OFB_CTX, ctx);
+    const unsigned char *iv = ctx->oiv;
+    const int keylen = EVP_CIPHER_CTX_get_key_length(ctx);
+    const int ivlen = EVP_CIPHER_CTX_get_iv_length(ctx);
+
+    if (keylen <= 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+        return 0;
+    }
+    if (ivlen <= 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_IV_LENGTH);
+        return 0;
+    }
+    memcpy(cctx->kmo.param.cv, iv, ivlen);
+    memcpy(cctx->kmo.param.k, key, keylen);
+    cctx->fc = S390X_AES_FC(keylen);
+    return 1;
+}
+
+static int s390x_aes_ofb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    S390X_AES_OFB_CTX *cctx = EVP_C_DATA(S390X_AES_OFB_CTX, ctx);
+    const int ivlen = EVP_CIPHER_CTX_get_iv_length(ctx);
+    unsigned char *iv = EVP_CIPHER_CTX_iv_noconst(ctx);
+    int n = ctx->num;
+    int rem;
+
+    memcpy(cctx->kmo.param.cv, iv, ivlen);
+    while (n && len) {
+        *out = *in ^ cctx->kmo.param.cv[n];
+        n = (n + 1) & 0xf;
+        --len;
+        ++in;
+        ++out;
+    }
+
+    rem = len & 0xf;
+
+    len &= ~(size_t)0xf;
+    if (len) {
+        s390x_kmo(in, len, out, cctx->fc, &cctx->kmo.param);
+
+        out += len;
+        in += len;
+    }
+
+    if (rem) {
+        s390x_km(cctx->kmo.param.cv, 16, cctx->kmo.param.cv, cctx->fc,
+            cctx->kmo.param.k);
+
+        while (rem--) {
+            out[n] = in[n] ^ cctx->kmo.param.cv[n];
+            ++n;
+        }
+    }
+
+    memcpy(iv, cctx->kmo.param.cv, ivlen);
+    ctx->num = n;
+    return 1;
+}
+
+static int s390x_aes_cfb_init_key(EVP_CIPHER_CTX *ctx,
+    const unsigned char *key,
+    const unsigned char *ivec, int enc)
+{
+    S390X_AES_CFB_CTX *cctx = EVP_C_DATA(S390X_AES_CFB_CTX, ctx);
+    const unsigned char *iv = ctx->oiv;
+    const int keylen = EVP_CIPHER_CTX_get_key_length(ctx);
+    const int ivlen = EVP_CIPHER_CTX_get_iv_length(ctx);
+
+    if (keylen <= 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+        return 0;
+    }
+    if (ivlen <= 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_IV_LENGTH);
+        return 0;
+    }
+    cctx->fc = S390X_AES_FC(keylen);
+    cctx->fc |= 16 << 24; /* 16 bytes cipher feedback */
+    if (!enc)
+        cctx->fc |= S390X_DECRYPT;
+
+    memcpy(cctx->kmf.param.cv, iv, ivlen);
+    memcpy(cctx->kmf.param.k, key, keylen);
+    return 1;
+}
+
+static int s390x_aes_cfb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    S390X_AES_CFB_CTX *cctx = EVP_C_DATA(S390X_AES_CFB_CTX, ctx);
+    const int keylen = EVP_CIPHER_CTX_get_key_length(ctx);
+    const int enc = EVP_CIPHER_CTX_is_encrypting(ctx);
+    const int ivlen = EVP_CIPHER_CTX_get_iv_length(ctx);
+    unsigned char *iv = EVP_CIPHER_CTX_iv_noconst(ctx);
+    int n = ctx->num;
+    int rem;
+    unsigned char tmp;
+
+    if (keylen <= 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+        return 0;
+    }
+    if (ivlen <= 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_IV_LENGTH);
+        return 0;
+    }
+    memcpy(cctx->kmf.param.cv, iv, ivlen);
+    while (n && len) {
+        tmp = *in;
+        *out = cctx->kmf.param.cv[n] ^ tmp;
+        cctx->kmf.param.cv[n] = enc ? *out : tmp;
+        n = (n + 1) & 0xf;
+        --len;
+        ++in;
+        ++out;
+    }
+
+    rem = len & 0xf;
+
+    len &= ~(size_t)0xf;
+    if (len) {
+        s390x_kmf(in, len, out, cctx->fc, &cctx->kmf.param);
+
+        out += len;
+        in += len;
+    }
+
+    if (rem) {
+        s390x_km(cctx->kmf.param.cv, 16, cctx->kmf.param.cv,
+            S390X_AES_FC(keylen), cctx->kmf.param.k);
+
+        while (rem--) {
+            tmp = in[n];
+            out[n] = cctx->kmf.param.cv[n] ^ tmp;
+            cctx->kmf.param.cv[n] = enc ? out[n] : tmp;
+            ++n;
+        }
+    }
+
+    memcpy(iv, cctx->kmf.param.cv, ivlen);
+    ctx->num = n;
+    return 1;
+}
+
+static int s390x_aes_cfb8_init_key(EVP_CIPHER_CTX *ctx,
+    const unsigned char *key,
+    const unsigned char *ivec, int enc)
+{
+    S390X_AES_CFB_CTX *cctx = EVP_C_DATA(S390X_AES_CFB_CTX, ctx);
+    const unsigned char *iv = ctx->oiv;
+    const int keylen = EVP_CIPHER_CTX_get_key_length(ctx);
+    const int ivlen = EVP_CIPHER_CTX_get_iv_length(ctx);
+
+    if (keylen <= 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+        return 0;
+    }
+    if (ivlen <= 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_IV_LENGTH);
+        return 0;
+    }
+    cctx->fc = S390X_AES_FC(keylen);
+    cctx->fc |= 1 << 24; /* 1 byte cipher feedback */
+    if (!enc)
+        cctx->fc |= S390X_DECRYPT;
+
+    memcpy(cctx->kmf.param.cv, iv, ivlen);
+    memcpy(cctx->kmf.param.k, key, keylen);
+    return 1;
+}
+
+static int s390x_aes_cfb8_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    S390X_AES_CFB_CTX *cctx = EVP_C_DATA(S390X_AES_CFB_CTX, ctx);
+    const int ivlen = EVP_CIPHER_CTX_get_iv_length(ctx);
+    unsigned char *iv = EVP_CIPHER_CTX_iv_noconst(ctx);
+
+    memcpy(cctx->kmf.param.cv, iv, ivlen);
+    s390x_kmf(in, len, out, cctx->fc, &cctx->kmf.param);
+    memcpy(iv, cctx->kmf.param.cv, ivlen);
+    return 1;
+}
+
+#define s390x_aes_cfb1_init_key aes_init_key
+
+#define s390x_aes_cfb1_cipher aes_cfb1_cipher
+static int s390x_aes_cfb1_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define S390X_AES_CTR_CTX EVP_AES_KEY
+
+#define s390x_aes_ctr_init_key aes_init_key
+
+#define s390x_aes_ctr_cipher aes_ctr_cipher
+static int s390x_aes_ctr_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+/* iv + padding length for iv lengths != 12 */
+#define S390X_gcm_ivpadlen(i) ((((i) + 15) >> 4 << 4) + 16)
+
+/*-
+ * Process additional authenticated data. Returns 0 on success. Code is
+ * big-endian.
+ */
+static int s390x_aes_gcm_aad(S390X_AES_GCM_CTX *ctx, const unsigned char *aad,
+    size_t len)
+{
+    unsigned long long alen;
+    int n, rem;
+
+    if (ctx->kma.param.tpcl)
+        return -2;
+
+    alen = ctx->kma.param.taadl + len;
+    if (alen > (U64(1) << 61) || (sizeof(len) == 8 && alen < len))
+        return -1;
+    ctx->kma.param.taadl = alen;
+
+    n = ctx->areslen;
+    if (n) {
+        while (n && len) {
+            ctx->ares[n] = *aad;
+            n = (n + 1) & 0xf;
+            ++aad;
+            --len;
+        }
+        /* ctx->ares contains a complete block if offset has wrapped around */
+        if (!n) {
+            s390x_kma(ctx->ares, 16, NULL, 0, NULL, ctx->fc, &ctx->kma.param);
+            ctx->fc |= S390X_KMA_HS;
+        }
+        ctx->areslen = n;
+    }
+
+    rem = len & 0xf;
+
+    len &= ~(size_t)0xf;
+    if (len) {
+        s390x_kma(aad, len, NULL, 0, NULL, ctx->fc, &ctx->kma.param);
+        aad += len;
+        ctx->fc |= S390X_KMA_HS;
+    }
+
+    if (rem) {
+        ctx->areslen = rem;
+
+        do {
+            --rem;
+            ctx->ares[rem] = aad[rem];
+        } while (rem);
+    }
+    return 0;
+}
+
+/*-
+ * En/de-crypt plain/cipher-text and authenticate ciphertext. Returns 0 for
+ * success. Code is big-endian.
+ */
+static int s390x_aes_gcm(S390X_AES_GCM_CTX *ctx, const unsigned char *in,
+    unsigned char *out, size_t len)
+{
+    const unsigned char *inptr;
+    unsigned long long mlen;
+    union {
+        unsigned int w[4];
+        unsigned char b[16];
+    } buf;
+    size_t inlen;
+    int n, rem, i;
+
+    mlen = ctx->kma.param.tpcl + len;
+    if (mlen > ((U64(1) << 36) - 32) || (sizeof(len) == 8 && mlen < len))
+        return -1;
+    ctx->kma.param.tpcl = mlen;
+
+    n = ctx->mreslen;
+    if (n) {
+        inptr = in;
+        inlen = len;
+        while (n && inlen) {
+            ctx->mres[n] = *inptr;
+            n = (n + 1) & 0xf;
+            ++inptr;
+            --inlen;
+        }
+        /* ctx->mres contains a complete block if offset has wrapped around */
+        if (!n) {
+            s390x_kma(ctx->ares, ctx->areslen, ctx->mres, 16, buf.b,
+                ctx->fc | S390X_KMA_LAAD, &ctx->kma.param);
+            ctx->fc |= S390X_KMA_HS;
+            ctx->areslen = 0;
+
+            /* previous call already encrypted/decrypted its remainder,
+             * see comment below */
+            n = ctx->mreslen;
+            while (n) {
+                *out = buf.b[n];
+                n = (n + 1) & 0xf;
+                ++out;
+                ++in;
+                --len;
+            }
+            ctx->mreslen = 0;
+        }
+    }
+
+    rem = len & 0xf;
+
+    len &= ~(size_t)0xf;
+    if (len) {
+        s390x_kma(ctx->ares, ctx->areslen, in, len, out,
+            ctx->fc | S390X_KMA_LAAD, &ctx->kma.param);
+        in += len;
+        out += len;
+        ctx->fc |= S390X_KMA_HS;
+        ctx->areslen = 0;
+    }
+
+    /*-
+     * If there is a remainder, it has to be saved such that it can be
+     * processed by kma later. However, we also have to do the for-now
+     * unauthenticated encryption/decryption part here and now...
+     */
+    if (rem) {
+        if (!ctx->mreslen) {
+            buf.w[0] = ctx->kma.param.j0.w[0];
+            buf.w[1] = ctx->kma.param.j0.w[1];
+            buf.w[2] = ctx->kma.param.j0.w[2];
+            buf.w[3] = ctx->kma.param.cv.w + 1;
+            s390x_km(buf.b, 16, ctx->kres, ctx->fc & 0x1f, &ctx->kma.param.k);
+        }
+
+        n = ctx->mreslen;
+        for (i = 0; i < rem; i++) {
+            ctx->mres[n + i] = in[i];
+            out[i] = in[i] ^ ctx->kres[n + i];
+        }
+
+        ctx->mreslen += rem;
+    }
+    return 0;
+}
+
+/*-
+ * Initialize context structure. Code is big-endian.
+ */
+static void s390x_aes_gcm_setiv(S390X_AES_GCM_CTX *ctx,
+    const unsigned char *iv)
+{
+    ctx->kma.param.t.g[0] = 0;
+    ctx->kma.param.t.g[1] = 0;
+    ctx->kma.param.tpcl = 0;
+    ctx->kma.param.taadl = 0;
+    ctx->mreslen = 0;
+    ctx->areslen = 0;
+    ctx->kreslen = 0;
+
+    if (ctx->ivlen == 12) {
+        memcpy(&ctx->kma.param.j0, iv, ctx->ivlen);
+        ctx->kma.param.j0.w[3] = 1;
+        ctx->kma.param.cv.w = 1;
+    } else {
+        /* ctx->iv has the right size and is already padded. */
+        memcpy(ctx->iv, iv, ctx->ivlen);
+        s390x_kma(ctx->iv, S390X_gcm_ivpadlen(ctx->ivlen), NULL, 0, NULL,
+            ctx->fc, &ctx->kma.param);
+        ctx->fc |= S390X_KMA_HS;
+
+        ctx->kma.param.j0.g[0] = ctx->kma.param.t.g[0];
+        ctx->kma.param.j0.g[1] = ctx->kma.param.t.g[1];
+        ctx->kma.param.cv.w = ctx->kma.param.j0.w[3];
+        ctx->kma.param.t.g[0] = 0;
+        ctx->kma.param.t.g[1] = 0;
+    }
+}
+
+/*-
+ * Performs various operations on the context structure depending on control
+ * type. Returns 1 for success, 0 for failure and -1 for unknown control type.
+ * Code is big-endian.
+ */
+static int s390x_aes_gcm_ctrl(EVP_CIPHER_CTX *c, int type, int arg, void *ptr)
+{
+    S390X_AES_GCM_CTX *gctx = EVP_C_DATA(S390X_AES_GCM_CTX, c);
+    S390X_AES_GCM_CTX *gctx_out;
+    EVP_CIPHER_CTX *out;
+    unsigned char *buf;
+    int ivlen, enc, len;
+
+    switch (type) {
+    case EVP_CTRL_INIT:
+        ivlen = EVP_CIPHER_get_iv_length(c->cipher);
+        gctx->key_set = 0;
+        gctx->iv_set = 0;
+        gctx->ivlen = ivlen;
+        gctx->iv = c->iv;
+        gctx->taglen = -1;
+        gctx->iv_gen = 0;
+        gctx->tls_aad_len = -1;
+        return 1;
+
+    case EVP_CTRL_GET_IVLEN:
+        *(int *)ptr = gctx->ivlen;
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_IVLEN:
+        if (arg <= 0)
+            return 0;
+
+        if (arg != 12) {
+            len = S390X_gcm_ivpadlen(arg);
+
+            /* Allocate memory for iv if needed. */
+            if (gctx->ivlen == 12 || len > S390X_gcm_ivpadlen(gctx->ivlen)) {
+                if (gctx->iv != c->iv)
+                    OPENSSL_free(gctx->iv);
+
+                if ((gctx->iv = OPENSSL_malloc(len)) == NULL)
+                    return 0;
+            }
+            /* Add padding. */
+            memset(gctx->iv + arg, 0, len - arg - 8);
+            *((unsigned long long *)(gctx->iv + len - 8)) = arg << 3;
+        }
+        gctx->ivlen = arg;
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_TAG:
+        buf = EVP_CIPHER_CTX_buf_noconst(c);
+        enc = EVP_CIPHER_CTX_is_encrypting(c);
+        if (arg <= 0 || arg > 16 || enc)
+            return 0;
+
+        memcpy(buf, ptr, arg);
+        gctx->taglen = arg;
+        return 1;
+
+    case EVP_CTRL_AEAD_GET_TAG:
+        enc = EVP_CIPHER_CTX_is_encrypting(c);
+        if (arg <= 0 || arg > 16 || !enc || gctx->taglen < 0)
+            return 0;
+
+        memcpy(ptr, gctx->kma.param.t.b, arg);
+        return 1;
+
+    case EVP_CTRL_GCM_SET_IV_FIXED:
+        /* Special case: -1 length restores whole iv */
+        if (arg == -1) {
+            memcpy(gctx->iv, ptr, gctx->ivlen);
+            gctx->iv_gen = 1;
+            return 1;
+        }
+        /*
+         * Fixed field must be at least 4 bytes and invocation field at least
+         * 8.
+         */
+        if ((arg < 4) || (gctx->ivlen - arg) < 8)
+            return 0;
+
+        if (arg)
+            memcpy(gctx->iv, ptr, arg);
+
+        enc = EVP_CIPHER_CTX_is_encrypting(c);
+        if (enc && RAND_bytes(gctx->iv + arg, gctx->ivlen - arg) <= 0)
+            return 0;
+
+        gctx->iv_gen = 1;
+        return 1;
+
+    case EVP_CTRL_GCM_IV_GEN:
+        if (gctx->iv_gen == 0 || gctx->key_set == 0)
+            return 0;
+
+        s390x_aes_gcm_setiv(gctx, gctx->iv);
+
+        if (arg <= 0 || arg > gctx->ivlen)
+            arg = gctx->ivlen;
+
+        memcpy(ptr, gctx->iv + gctx->ivlen - arg, arg);
+        /*
+         * Invocation field will be at least 8 bytes in size and so no need
+         * to check wrap around or increment more than last 8 bytes.
+         */
+        ctr64_inc(gctx->iv + gctx->ivlen - 8);
+        gctx->iv_set = 1;
+        return 1;
+
+    case EVP_CTRL_GCM_SET_IV_INV:
+        enc = EVP_CIPHER_CTX_is_encrypting(c);
+        if (gctx->iv_gen == 0 || gctx->key_set == 0 || enc)
+            return 0;
+
+        memcpy(gctx->iv + gctx->ivlen - arg, ptr, arg);
+        s390x_aes_gcm_setiv(gctx, gctx->iv);
+        gctx->iv_set = 1;
+        return 1;
+
+    case EVP_CTRL_AEAD_TLS1_AAD:
+        /* Save the aad for later use. */
+        if (arg != EVP_AEAD_TLS1_AAD_LEN)
+            return 0;
+
+        buf = EVP_CIPHER_CTX_buf_noconst(c);
+        memcpy(buf, ptr, arg);
+        gctx->tls_aad_len = arg;
+        gctx->tls_enc_records = 0;
+
+        len = buf[arg - 2] << 8 | buf[arg - 1];
+        /* Correct length for explicit iv. */
+        if (len < EVP_GCM_TLS_EXPLICIT_IV_LEN)
+            return 0;
+        len -= EVP_GCM_TLS_EXPLICIT_IV_LEN;
+
+        /* If decrypting correct for tag too. */
+        enc = EVP_CIPHER_CTX_is_encrypting(c);
+        if (!enc) {
+            if (len < EVP_GCM_TLS_TAG_LEN)
+                return 0;
+            len -= EVP_GCM_TLS_TAG_LEN;
+        }
+        buf[arg - 2] = len >> 8;
+        buf[arg - 1] = len & 0xff;
+        /* Extra padding: tag appended to record. */
+        return EVP_GCM_TLS_TAG_LEN;
+
+    case EVP_CTRL_COPY:
+        out = ptr;
+        gctx_out = EVP_C_DATA(S390X_AES_GCM_CTX, out);
+
+        if (gctx->iv == c->iv) {
+            gctx_out->iv = out->iv;
+        } else {
+            len = S390X_gcm_ivpadlen(gctx->ivlen);
+
+            if ((gctx_out->iv = OPENSSL_malloc(len)) == NULL)
+                return 0;
+
+            memcpy(gctx_out->iv, gctx->iv, len);
+        }
+        return 1;
+
+    default:
+        return -1;
+    }
+}
+
+/*-
+ * Set key and/or iv. Returns 1 on success. Otherwise 0 is returned.
+ */
+static int s390x_aes_gcm_init_key(EVP_CIPHER_CTX *ctx,
+    const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    S390X_AES_GCM_CTX *gctx = EVP_C_DATA(S390X_AES_GCM_CTX, ctx);
+    int keylen;
+
+    if (iv == NULL && key == NULL)
+        return 1;
+
+    if (key != NULL) {
+        keylen = EVP_CIPHER_CTX_get_key_length(ctx);
+        if (keylen <= 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+            return 0;
+        }
+
+        memcpy(&gctx->kma.param.k, key, keylen);
+
+        gctx->fc = S390X_AES_FC(keylen);
+        if (!enc)
+            gctx->fc |= S390X_DECRYPT;
+
+        if (iv == NULL && gctx->iv_set)
+            iv = gctx->iv;
+
+        if (iv != NULL) {
+            s390x_aes_gcm_setiv(gctx, iv);
+            gctx->iv_set = 1;
+        }
+        gctx->key_set = 1;
+    } else {
+        if (gctx->key_set)
+            s390x_aes_gcm_setiv(gctx, iv);
+        else
+            memcpy(gctx->iv, iv, gctx->ivlen);
+
+        gctx->iv_set = 1;
+        gctx->iv_gen = 0;
+    }
+    return 1;
+}
+
+/*-
+ * En/de-crypt and authenticate TLS packet. Returns the number of bytes written
+ * if successful. Otherwise -1 is returned. Code is big-endian.
+ */
+static int s390x_aes_gcm_tls_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    S390X_AES_GCM_CTX *gctx = EVP_C_DATA(S390X_AES_GCM_CTX, ctx);
+    const unsigned char *buf = EVP_CIPHER_CTX_buf_noconst(ctx);
+    const int enc = EVP_CIPHER_CTX_is_encrypting(ctx);
+    int rv = -1;
+
+    if (out != in || len < (EVP_GCM_TLS_EXPLICIT_IV_LEN + EVP_GCM_TLS_TAG_LEN))
+        return -1;
+
+    /*
+     * Check for too many keys as per FIPS 140-2 IG A.5 "Key/IV Pair Uniqueness
+     * Requirements from SP 800-38D".  The requirements is for one party to the
+     * communication to fail after 2^64 - 1 keys.  We do this on the encrypting
+     * side only.
+     */
+    if (enc && ++gctx->tls_enc_records == 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_TOO_MANY_RECORDS);
+        goto err;
+    }
+
+    if (EVP_CIPHER_CTX_ctrl(ctx, enc ? EVP_CTRL_GCM_IV_GEN : EVP_CTRL_GCM_SET_IV_INV,
+            EVP_GCM_TLS_EXPLICIT_IV_LEN, out)
+        <= 0)
+        goto err;
+
+    in += EVP_GCM_TLS_EXPLICIT_IV_LEN;
+    out += EVP_GCM_TLS_EXPLICIT_IV_LEN;
+    len -= EVP_GCM_TLS_EXPLICIT_IV_LEN + EVP_GCM_TLS_TAG_LEN;
+
+    gctx->kma.param.taadl = gctx->tls_aad_len << 3;
+    gctx->kma.param.tpcl = len << 3;
+    s390x_kma(buf, gctx->tls_aad_len, in, len, out,
+        gctx->fc | S390X_KMA_LAAD | S390X_KMA_LPC, &gctx->kma.param);
+
+    if (enc) {
+        memcpy(out + len, gctx->kma.param.t.b, EVP_GCM_TLS_TAG_LEN);
+        rv = len + EVP_GCM_TLS_EXPLICIT_IV_LEN + EVP_GCM_TLS_TAG_LEN;
+    } else {
+        if (CRYPTO_memcmp(gctx->kma.param.t.b, in + len,
+                EVP_GCM_TLS_TAG_LEN)) {
+            OPENSSL_cleanse(out, len);
+            goto err;
+        }
+        rv = len;
+    }
+err:
+    gctx->iv_set = 0;
+    gctx->tls_aad_len = -1;
+    return rv;
+}
+
+/*-
+ * Called from EVP layer to initialize context, process additional
+ * authenticated data, en/de-crypt plain/cipher-text and authenticate
+ * ciphertext or process a TLS packet, depending on context. Returns bytes
+ * written on success. Otherwise -1 is returned. Code is big-endian.
+ */
+static int s390x_aes_gcm_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    S390X_AES_GCM_CTX *gctx = EVP_C_DATA(S390X_AES_GCM_CTX, ctx);
+    unsigned char *buf, tmp[16];
+    int enc;
+
+    if (!gctx->key_set)
+        return -1;
+
+    if (gctx->tls_aad_len >= 0)
+        return s390x_aes_gcm_tls_cipher(ctx, out, in, len);
+
+    if (!gctx->iv_set)
+        return -1;
+
+    if (in != NULL) {
+        if (out == NULL) {
+            if (s390x_aes_gcm_aad(gctx, in, len))
+                return -1;
+        } else {
+            if (s390x_aes_gcm(gctx, in, out, len))
+                return -1;
+        }
+        return len;
+    } else {
+        gctx->kma.param.taadl <<= 3;
+        gctx->kma.param.tpcl <<= 3;
+        s390x_kma(gctx->ares, gctx->areslen, gctx->mres, gctx->mreslen, tmp,
+            gctx->fc | S390X_KMA_LAAD | S390X_KMA_LPC, &gctx->kma.param);
+        /* recall that we already did en-/decrypt gctx->mres
+         * and returned it to caller... */
+        OPENSSL_cleanse(tmp, gctx->mreslen);
+        gctx->iv_set = 0;
+
+        enc = EVP_CIPHER_CTX_is_encrypting(ctx);
+        if (enc) {
+            gctx->taglen = 16;
+        } else {
+            if (gctx->taglen < 0)
+                return -1;
+
+            buf = EVP_CIPHER_CTX_buf_noconst(ctx);
+            if (CRYPTO_memcmp(buf, gctx->kma.param.t.b, gctx->taglen))
+                return -1;
+        }
+        return 0;
+    }
+}
+
+static int s390x_aes_gcm_cleanup(EVP_CIPHER_CTX *c)
+{
+    S390X_AES_GCM_CTX *gctx = EVP_C_DATA(S390X_AES_GCM_CTX, c);
+
+    if (gctx == NULL)
+        return 0;
+
+    if (gctx->iv != c->iv)
+        OPENSSL_free(gctx->iv);
+
+    OPENSSL_cleanse(gctx, sizeof(*gctx));
+    return 1;
+}
+
+#define S390X_AES_XTS_CTX EVP_AES_XTS_CTX
+
+#define s390x_aes_xts_init_key aes_xts_init_key
+static int s390x_aes_xts_init_key(EVP_CIPHER_CTX *ctx,
+    const unsigned char *key,
+    const unsigned char *iv, int enc);
+#define s390x_aes_xts_cipher aes_xts_cipher
+static int s390x_aes_xts_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+#define s390x_aes_xts_ctrl aes_xts_ctrl
+static int s390x_aes_xts_ctrl(EVP_CIPHER_CTX *, int type, int arg, void *ptr);
+#define s390x_aes_xts_cleanup aes_xts_cleanup
+
+/*-
+ * Set nonce and length fields. Code is big-endian.
+ */
+static inline void s390x_aes_ccm_setiv(S390X_AES_CCM_CTX *ctx,
+    const unsigned char *nonce,
+    size_t mlen)
+{
+    ctx->aes.ccm.nonce.b[0] &= ~S390X_CCM_AAD_FLAG;
+    ctx->aes.ccm.nonce.g[1] = mlen;
+    memcpy(ctx->aes.ccm.nonce.b + 1, nonce, 15 - ctx->aes.ccm.l);
+}
+
+/*-
+ * Process additional authenticated data. Code is big-endian.
+ */
+static void s390x_aes_ccm_aad(S390X_AES_CCM_CTX *ctx, const unsigned char *aad,
+    size_t alen)
+{
+    unsigned char *ptr;
+    int i, rem;
+
+    if (!alen)
+        return;
+
+    ctx->aes.ccm.nonce.b[0] |= S390X_CCM_AAD_FLAG;
+
+    /* Suppress 'type-punned pointer dereference' warning. */
+    ptr = ctx->aes.ccm.buf.b;
+
+    if (alen < ((1 << 16) - (1 << 8))) {
+        *(uint16_t *)ptr = alen;
+        i = 2;
+    } else if (sizeof(alen) == 8
+        && alen >= (size_t)1 << (32 % (sizeof(alen) * 8))) {
+        *(uint16_t *)ptr = 0xffff;
+        *(uint64_t *)(ptr + 2) = alen;
+        i = 10;
+    } else {
+        *(uint16_t *)ptr = 0xfffe;
+        *(uint32_t *)(ptr + 2) = alen;
+        i = 6;
+    }
+
+    while (i < 16 && alen) {
+        ctx->aes.ccm.buf.b[i] = *aad;
+        ++aad;
+        --alen;
+        ++i;
+    }
+    while (i < 16) {
+        ctx->aes.ccm.buf.b[i] = 0;
+        ++i;
+    }
+
+    ctx->aes.ccm.kmac_param.icv.g[0] = 0;
+    ctx->aes.ccm.kmac_param.icv.g[1] = 0;
+    s390x_kmac(ctx->aes.ccm.nonce.b, 32, ctx->aes.ccm.fc,
+        &ctx->aes.ccm.kmac_param);
+    ctx->aes.ccm.blocks += 2;
+
+    rem = alen & 0xf;
+    alen &= ~(size_t)0xf;
+    if (alen) {
+        s390x_kmac(aad, alen, ctx->aes.ccm.fc, &ctx->aes.ccm.kmac_param);
+        ctx->aes.ccm.blocks += alen >> 4;
+        aad += alen;
+    }
+    if (rem) {
+        for (i = 0; i < rem; i++)
+            ctx->aes.ccm.kmac_param.icv.b[i] ^= aad[i];
+
+        s390x_km(ctx->aes.ccm.kmac_param.icv.b, 16,
+            ctx->aes.ccm.kmac_param.icv.b, ctx->aes.ccm.fc,
+            ctx->aes.ccm.kmac_param.k);
+        ctx->aes.ccm.blocks++;
+    }
+}
+
+/*-
+ * En/de-crypt plain/cipher-text. Compute tag from plaintext. Returns 0 for
+ * success.
+ */
+static int s390x_aes_ccm(S390X_AES_CCM_CTX *ctx, const unsigned char *in,
+    unsigned char *out, size_t len, int enc)
+{
+    size_t n, rem;
+    unsigned int i, l, num;
+    unsigned char flags;
+
+    flags = ctx->aes.ccm.nonce.b[0];
+    if (!(flags & S390X_CCM_AAD_FLAG)) {
+        s390x_km(ctx->aes.ccm.nonce.b, 16, ctx->aes.ccm.kmac_param.icv.b,
+            ctx->aes.ccm.fc, ctx->aes.ccm.kmac_param.k);
+        ctx->aes.ccm.blocks++;
+    }
+    l = flags & 0x7;
+    ctx->aes.ccm.nonce.b[0] = l;
+
+    /*-
+     * Reconstruct length from encoded length field
+     * and initialize it with counter value.
+     */
+    n = 0;
+    for (i = 15 - l; i < 15; i++) {
+        n |= ctx->aes.ccm.nonce.b[i];
+        ctx->aes.ccm.nonce.b[i] = 0;
+        n <<= 8;
+    }
+    n |= ctx->aes.ccm.nonce.b[15];
+    ctx->aes.ccm.nonce.b[15] = 1;
+
+    if (n != len)
+        return -1; /* length mismatch */
+
+    if (enc) {
+        /* Two operations per block plus one for tag encryption */
+        ctx->aes.ccm.blocks += (((len + 15) >> 4) << 1) + 1;
+        if (ctx->aes.ccm.blocks > (1ULL << 61))
+            return -2; /* too much data */
+    }
+
+    num = 0;
+    rem = len & 0xf;
+    len &= ~(size_t)0xf;
+
+    if (enc) {
+        /* mac-then-encrypt */
+        if (len)
+            s390x_kmac(in, len, ctx->aes.ccm.fc, &ctx->aes.ccm.kmac_param);
+        if (rem) {
+            for (i = 0; i < rem; i++)
+                ctx->aes.ccm.kmac_param.icv.b[i] ^= in[len + i];
+
+            s390x_km(ctx->aes.ccm.kmac_param.icv.b, 16,
+                ctx->aes.ccm.kmac_param.icv.b, ctx->aes.ccm.fc,
+                ctx->aes.ccm.kmac_param.k);
+        }
+
+        CRYPTO_ctr128_encrypt_ctr32(in, out, len + rem, &ctx->aes.key.k,
+            ctx->aes.ccm.nonce.b, ctx->aes.ccm.buf.b,
+            &num, (ctr128_f)AES_ctr32_encrypt);
+    } else {
+        /* decrypt-then-mac */
+        CRYPTO_ctr128_encrypt_ctr32(in, out, len + rem, &ctx->aes.key.k,
+            ctx->aes.ccm.nonce.b, ctx->aes.ccm.buf.b,
+            &num, (ctr128_f)AES_ctr32_encrypt);
+
+        if (len)
+            s390x_kmac(out, len, ctx->aes.ccm.fc, &ctx->aes.ccm.kmac_param);
+        if (rem) {
+            for (i = 0; i < rem; i++)
+                ctx->aes.ccm.kmac_param.icv.b[i] ^= out[len + i];
+
+            s390x_km(ctx->aes.ccm.kmac_param.icv.b, 16,
+                ctx->aes.ccm.kmac_param.icv.b, ctx->aes.ccm.fc,
+                ctx->aes.ccm.kmac_param.k);
+        }
+    }
+    /* encrypt tag */
+    for (i = 15 - l; i < 16; i++)
+        ctx->aes.ccm.nonce.b[i] = 0;
+
+    s390x_km(ctx->aes.ccm.nonce.b, 16, ctx->aes.ccm.buf.b, ctx->aes.ccm.fc,
+        ctx->aes.ccm.kmac_param.k);
+    ctx->aes.ccm.kmac_param.icv.g[0] ^= ctx->aes.ccm.buf.g[0];
+    ctx->aes.ccm.kmac_param.icv.g[1] ^= ctx->aes.ccm.buf.g[1];
+
+    ctx->aes.ccm.nonce.b[0] = flags; /* restore flags field */
+    return 0;
+}
+
+/*-
+ * En/de-crypt and authenticate TLS packet. Returns the number of bytes written
+ * if successful. Otherwise -1 is returned.
+ */
+static int s390x_aes_ccm_tls_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    S390X_AES_CCM_CTX *cctx = EVP_C_DATA(S390X_AES_CCM_CTX, ctx);
+    unsigned char *ivec = ctx->iv;
+    unsigned char *buf = EVP_CIPHER_CTX_buf_noconst(ctx);
+    const int enc = EVP_CIPHER_CTX_is_encrypting(ctx);
+
+    if (out != in
+        || len < (EVP_CCM_TLS_EXPLICIT_IV_LEN + (size_t)cctx->aes.ccm.m))
+        return -1;
+
+    if (enc) {
+        /* Set explicit iv (sequence number). */
+        memcpy(out, buf, EVP_CCM_TLS_EXPLICIT_IV_LEN);
+    }
+
+    len -= EVP_CCM_TLS_EXPLICIT_IV_LEN + cctx->aes.ccm.m;
+    /*-
+     * Get explicit iv (sequence number). We already have fixed iv
+     * (server/client_write_iv) here.
+     */
+    memcpy(ivec + EVP_CCM_TLS_FIXED_IV_LEN, in, EVP_CCM_TLS_EXPLICIT_IV_LEN);
+    s390x_aes_ccm_setiv(cctx, ivec, len);
+
+    /* Process aad (sequence number|type|version|length) */
+    s390x_aes_ccm_aad(cctx, buf, cctx->aes.ccm.tls_aad_len);
+
+    in += EVP_CCM_TLS_EXPLICIT_IV_LEN;
+    out += EVP_CCM_TLS_EXPLICIT_IV_LEN;
+
+    if (enc) {
+        if (s390x_aes_ccm(cctx, in, out, len, enc))
+            return -1;
+
+        memcpy(out + len, cctx->aes.ccm.kmac_param.icv.b, cctx->aes.ccm.m);
+        return len + EVP_CCM_TLS_EXPLICIT_IV_LEN + cctx->aes.ccm.m;
+    } else {
+        if (!s390x_aes_ccm(cctx, in, out, len, enc)) {
+            if (!CRYPTO_memcmp(cctx->aes.ccm.kmac_param.icv.b, in + len,
+                    cctx->aes.ccm.m))
+                return len;
+        }
+
+        OPENSSL_cleanse(out, len);
+        return -1;
+    }
+}
+
+/*-
+ * Set key and flag field and/or iv. Returns 1 if successful. Otherwise 0 is
+ * returned.
+ */
+static int s390x_aes_ccm_init_key(EVP_CIPHER_CTX *ctx,
+    const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    S390X_AES_CCM_CTX *cctx = EVP_C_DATA(S390X_AES_CCM_CTX, ctx);
+    int keylen;
+
+    if (iv == NULL && key == NULL)
+        return 1;
+
+    if (key != NULL) {
+        keylen = EVP_CIPHER_CTX_get_key_length(ctx);
+        if (keylen <= 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+            return 0;
+        }
+
+        cctx->aes.ccm.fc = S390X_AES_FC(keylen);
+        memcpy(cctx->aes.ccm.kmac_param.k, key, keylen);
+
+        /* Store encoded m and l. */
+        cctx->aes.ccm.nonce.b[0] = ((cctx->aes.ccm.l - 1) & 0x7)
+            | (((cctx->aes.ccm.m - 2) >> 1) & 0x7) << 3;
+        memset(cctx->aes.ccm.nonce.b + 1, 0,
+            sizeof(cctx->aes.ccm.nonce.b));
+        cctx->aes.ccm.blocks = 0;
+
+        cctx->aes.ccm.key_set = 1;
+    }
+
+    if (iv != NULL) {
+        memcpy(ctx->iv, iv, 15 - cctx->aes.ccm.l);
+
+        cctx->aes.ccm.iv_set = 1;
+    }
+
+    return 1;
+}
+
+/*-
+ * Called from EVP layer to initialize context, process additional
+ * authenticated data, en/de-crypt plain/cipher-text and authenticate
+ * plaintext or process a TLS packet, depending on context. Returns bytes
+ * written on success. Otherwise -1 is returned.
+ */
+static int s390x_aes_ccm_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    S390X_AES_CCM_CTX *cctx = EVP_C_DATA(S390X_AES_CCM_CTX, ctx);
+    const int enc = EVP_CIPHER_CTX_is_encrypting(ctx);
+    int rv;
+    unsigned char *buf;
+
+    if (!cctx->aes.ccm.key_set)
+        return -1;
+
+    if (cctx->aes.ccm.tls_aad_len >= 0)
+        return s390x_aes_ccm_tls_cipher(ctx, out, in, len);
+
+    /*-
+     * Final(): Does not return any data. Recall that ccm is mac-then-encrypt
+     * so integrity must be checked already at Update() i.e., before
+     * potentially corrupted data is output.
+     */
+    if (in == NULL && out != NULL)
+        return 0;
+
+    if (!cctx->aes.ccm.iv_set)
+        return -1;
+
+    if (out == NULL) {
+        /* Update(): Pass message length. */
+        if (in == NULL) {
+            s390x_aes_ccm_setiv(cctx, ctx->iv, len);
+
+            cctx->aes.ccm.len_set = 1;
+            return len;
+        }
+
+        /* Update(): Process aad. */
+        if (!cctx->aes.ccm.len_set && len)
+            return -1;
+
+        s390x_aes_ccm_aad(cctx, in, len);
+        return len;
+    }
+
+    /* The tag must be set before actually decrypting data */
+    if (!enc && !cctx->aes.ccm.tag_set)
+        return -1;
+
+    /* Update(): Process message. */
+
+    if (!cctx->aes.ccm.len_set) {
+        /*-
+         * In case message length was not previously set explicitly via
+         * Update(), set it now.
+         */
+        s390x_aes_ccm_setiv(cctx, ctx->iv, len);
+
+        cctx->aes.ccm.len_set = 1;
+    }
+
+    if (enc) {
+        if (s390x_aes_ccm(cctx, in, out, len, enc))
+            return -1;
+
+        cctx->aes.ccm.tag_set = 1;
+        return len;
+    } else {
+        rv = -1;
+
+        if (!s390x_aes_ccm(cctx, in, out, len, enc)) {
+            buf = EVP_CIPHER_CTX_buf_noconst(ctx);
+            if (!CRYPTO_memcmp(cctx->aes.ccm.kmac_param.icv.b, buf,
+                    cctx->aes.ccm.m))
+                rv = len;
+        }
+
+        if (rv == -1)
+            OPENSSL_cleanse(out, len);
+
+        cctx->aes.ccm.iv_set = 0;
+        cctx->aes.ccm.tag_set = 0;
+        cctx->aes.ccm.len_set = 0;
+        return rv;
+    }
+}
+
+/*-
+ * Performs various operations on the context structure depending on control
+ * type. Returns 1 for success, 0 for failure and -1 for unknown control type.
+ * Code is big-endian.
+ */
+static int s390x_aes_ccm_ctrl(EVP_CIPHER_CTX *c, int type, int arg, void *ptr)
+{
+    S390X_AES_CCM_CTX *cctx = EVP_C_DATA(S390X_AES_CCM_CTX, c);
+    unsigned char *buf;
+    int enc, len;
+
+    switch (type) {
+    case EVP_CTRL_INIT:
+        cctx->aes.ccm.key_set = 0;
+        cctx->aes.ccm.iv_set = 0;
+        cctx->aes.ccm.l = 8;
+        cctx->aes.ccm.m = 12;
+        cctx->aes.ccm.tag_set = 0;
+        cctx->aes.ccm.len_set = 0;
+        cctx->aes.ccm.tls_aad_len = -1;
+        return 1;
+
+    case EVP_CTRL_GET_IVLEN:
+        *(int *)ptr = 15 - cctx->aes.ccm.l;
+        return 1;
+
+    case EVP_CTRL_AEAD_TLS1_AAD:
+        if (arg != EVP_AEAD_TLS1_AAD_LEN)
+            return 0;
+
+        /* Save the aad for later use. */
+        buf = EVP_CIPHER_CTX_buf_noconst(c);
+        memcpy(buf, ptr, arg);
+        cctx->aes.ccm.tls_aad_len = arg;
+
+        len = buf[arg - 2] << 8 | buf[arg - 1];
+        if (len < EVP_CCM_TLS_EXPLICIT_IV_LEN)
+            return 0;
+
+        /* Correct length for explicit iv. */
+        len -= EVP_CCM_TLS_EXPLICIT_IV_LEN;
+
+        enc = EVP_CIPHER_CTX_is_encrypting(c);
+        if (!enc) {
+            if (len < cctx->aes.ccm.m)
+                return 0;
+
+            /* Correct length for tag. */
+            len -= cctx->aes.ccm.m;
+        }
+
+        buf[arg - 2] = len >> 8;
+        buf[arg - 1] = len & 0xff;
+
+        /* Extra padding: tag appended to record. */
+        return cctx->aes.ccm.m;
+
+    case EVP_CTRL_CCM_SET_IV_FIXED:
+        if (arg != EVP_CCM_TLS_FIXED_IV_LEN)
+            return 0;
+
+        /* Copy to first part of the iv. */
+        memcpy(c->iv, ptr, arg);
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_IVLEN:
+        arg = 15 - arg;
+        /* fall-through */
+
+    case EVP_CTRL_CCM_SET_L:
+        if (arg < 2 || arg > 8)
+            return 0;
+
+        cctx->aes.ccm.l = arg;
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_TAG:
+        if ((arg & 1) || arg < 4 || arg > 16)
+            return 0;
+
+        enc = EVP_CIPHER_CTX_is_encrypting(c);
+        if (enc && ptr)
+            return 0;
+
+        if (ptr) {
+            cctx->aes.ccm.tag_set = 1;
+            buf = EVP_CIPHER_CTX_buf_noconst(c);
+            memcpy(buf, ptr, arg);
+        }
+
+        cctx->aes.ccm.m = arg;
+        return 1;
+
+    case EVP_CTRL_AEAD_GET_TAG:
+        enc = EVP_CIPHER_CTX_is_encrypting(c);
+        if (!enc || !cctx->aes.ccm.tag_set)
+            return 0;
+
+        if (arg < cctx->aes.ccm.m)
+            return 0;
+
+        memcpy(ptr, cctx->aes.ccm.kmac_param.icv.b, cctx->aes.ccm.m);
+        cctx->aes.ccm.tag_set = 0;
+        cctx->aes.ccm.iv_set = 0;
+        cctx->aes.ccm.len_set = 0;
+        return 1;
+
+    case EVP_CTRL_COPY:
+        return 1;
+
+    default:
+        return -1;
+    }
+}
+
+#define s390x_aes_ccm_cleanup aes_ccm_cleanup
+
+#ifndef OPENSSL_NO_OCB
+#define S390X_AES_OCB_CTX EVP_AES_OCB_CTX
+
+#define s390x_aes_ocb_init_key aes_ocb_init_key
+static int s390x_aes_ocb_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc);
+#define s390x_aes_ocb_cipher aes_ocb_cipher
+static int s390x_aes_ocb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+#define s390x_aes_ocb_cleanup aes_ocb_cleanup
+static int s390x_aes_ocb_cleanup(EVP_CIPHER_CTX *);
+#define s390x_aes_ocb_ctrl aes_ocb_ctrl
+static int s390x_aes_ocb_ctrl(EVP_CIPHER_CTX *, int type, int arg, void *ptr);
+#endif
+
+#ifndef OPENSSL_NO_SIV
+#define S390X_AES_SIV_CTX EVP_AES_SIV_CTX
+
+#define s390x_aes_siv_init_key aes_siv_init_key
+#define s390x_aes_siv_cipher aes_siv_cipher
+#define s390x_aes_siv_cleanup aes_siv_cleanup
+#define s390x_aes_siv_ctrl aes_siv_ctrl
+#endif
+
+#define BLOCK_CIPHER_generic(nid, keylen, blocksize, ivlen, nmode, mode,                                      \
+    MODE, flags)                                                                                              \
+    static const EVP_CIPHER s390x_aes_##keylen##_##mode = {                                                   \
+        nid##_##keylen##_##nmode, blocksize,                                                                  \
+        keylen / 8,                                                                                           \
+        ivlen,                                                                                                \
+        flags | EVP_CIPH_##MODE##_MODE,                                                                       \
+        EVP_ORIG_GLOBAL,                                                                                      \
+        s390x_aes_##mode##_init_key,                                                                          \
+        s390x_aes_##mode##_cipher,                                                                            \
+        NULL,                                                                                                 \
+        sizeof(S390X_AES_##MODE##_CTX),                                                                       \
+        NULL,                                                                                                 \
+        NULL,                                                                                                 \
+        NULL,                                                                                                 \
+        NULL                                                                                                  \
+    };                                                                                                        \
+    static const EVP_CIPHER aes_##keylen##_##mode = {                                                         \
+        nid##_##keylen##_##nmode,                                                                             \
+        blocksize,                                                                                            \
+        keylen / 8,                                                                                           \
+        ivlen,                                                                                                \
+        flags | EVP_CIPH_##MODE##_MODE,                                                                       \
+        EVP_ORIG_GLOBAL,                                                                                      \
+        aes_init_key,                                                                                         \
+        aes_##mode##_cipher,                                                                                  \
+        NULL,                                                                                                 \
+        sizeof(EVP_AES_KEY),                                                                                  \
+        NULL,                                                                                                 \
+        NULL,                                                                                                 \
+        NULL,                                                                                                 \
+        NULL                                                                                                  \
+    };                                                                                                        \
+    const EVP_CIPHER *EVP_aes_##keylen##_##mode(void)                                                         \
+    {                                                                                                         \
+        return S390X_aes_##keylen##_##mode##_CAPABLE ? &s390x_aes_##keylen##_##mode : &aes_##keylen##_##mode; \
+    }
+
+#define BLOCK_CIPHER_custom(nid, keylen, blocksize, ivlen, mode, MODE, flags)                                              \
+    static const EVP_CIPHER s390x_aes_##keylen##_##mode = {                                                                \
+        nid##_##keylen##_##mode,                                                                                           \
+        blocksize,                                                                                                         \
+        (EVP_CIPH_##MODE##_MODE == EVP_CIPH_XTS_MODE || EVP_CIPH_##MODE##_MODE == EVP_CIPH_SIV_MODE ? 2 : 1) * keylen / 8, \
+        ivlen,                                                                                                             \
+        flags | EVP_CIPH_##MODE##_MODE,                                                                                    \
+        EVP_ORIG_GLOBAL,                                                                                                   \
+        s390x_aes_##mode##_init_key,                                                                                       \
+        s390x_aes_##mode##_cipher,                                                                                         \
+        s390x_aes_##mode##_cleanup,                                                                                        \
+        sizeof(S390X_AES_##MODE##_CTX),                                                                                    \
+        NULL,                                                                                                              \
+        NULL,                                                                                                              \
+        s390x_aes_##mode##_ctrl,                                                                                           \
+        NULL                                                                                                               \
+    };                                                                                                                     \
+    static const EVP_CIPHER aes_##keylen##_##mode = {                                                                      \
+        nid##_##keylen##_##mode, blocksize,                                                                                \
+        (EVP_CIPH_##MODE##_MODE == EVP_CIPH_XTS_MODE || EVP_CIPH_##MODE##_MODE == EVP_CIPH_SIV_MODE ? 2 : 1) * keylen / 8, \
+        ivlen,                                                                                                             \
+        flags | EVP_CIPH_##MODE##_MODE,                                                                                    \
+        EVP_ORIG_GLOBAL,                                                                                                   \
+        aes_##mode##_init_key,                                                                                             \
+        aes_##mode##_cipher,                                                                                               \
+        aes_##mode##_cleanup,                                                                                              \
+        sizeof(EVP_AES_##MODE##_CTX),                                                                                      \
+        NULL,                                                                                                              \
+        NULL,                                                                                                              \
+        aes_##mode##_ctrl,                                                                                                 \
+        NULL                                                                                                               \
+    };                                                                                                                     \
+    const EVP_CIPHER *EVP_aes_##keylen##_##mode(void)                                                                      \
+    {                                                                                                                      \
+        return S390X_aes_##keylen##_##mode##_CAPABLE ? &s390x_aes_##keylen##_##mode : &aes_##keylen##_##mode;              \
+    }
+
+#else
 
 #define BLOCK_CIPHER_generic(nid, keylen, blocksize, ivlen, nmode, mode, MODE, flags) \
     static const EVP_CIPHER aes_##keylen##_##mode = {                                 \
-        nid##_##keylen##_##nmode,                                                     \
-        blocksize,                                                                    \
-        keylen / 8,                                                                   \
-        ivlen,                                                                        \
+        nid##_##keylen##_##nmode, blocksize, keylen / 8, ivlen,                       \
         flags | EVP_CIPH_##MODE##_MODE,                                               \
         EVP_ORIG_GLOBAL,                                                              \
+        aes_init_key,                                                                 \
+        aes_##mode##_cipher,                                                          \
+        NULL,                                                                         \
+        sizeof(EVP_AES_KEY),                                                          \
+        NULL, NULL, NULL, NULL                                                        \
     };                                                                                \
     const EVP_CIPHER *EVP_aes_##keylen##_##mode(void)                                 \
     {                                                                                 \
@@ -25,30 +2385,802 @@
 
 #define BLOCK_CIPHER_custom(nid, keylen, blocksize, ivlen, mode, MODE, flags)                                              \
     static const EVP_CIPHER aes_##keylen##_##mode = {                                                                      \
-        nid##_##keylen##_##mode,                                                                                           \
-        blocksize,                                                                                                         \
+        nid##_##keylen##_##mode, blocksize,                                                                                \
         (EVP_CIPH_##MODE##_MODE == EVP_CIPH_XTS_MODE || EVP_CIPH_##MODE##_MODE == EVP_CIPH_SIV_MODE ? 2 : 1) * keylen / 8, \
         ivlen,                                                                                                             \
         flags | EVP_CIPH_##MODE##_MODE,                                                                                    \
         EVP_ORIG_GLOBAL,                                                                                                   \
+        aes_##mode##_init_key,                                                                                             \
+        aes_##mode##_cipher,                                                                                               \
+        aes_##mode##_cleanup,                                                                                              \
+        sizeof(EVP_AES_##MODE##_CTX),                                                                                      \
+        NULL, NULL, aes_##mode##_ctrl, NULL                                                                                \
     };                                                                                                                     \
     const EVP_CIPHER *EVP_aes_##keylen##_##mode(void)                                                                      \
     {                                                                                                                      \
         return &aes_##keylen##_##mode;                                                                                     \
     }
 
-#define BLOCK_CIPHER_generic_pack(nid, keylen, flags)                                              \
-    BLOCK_CIPHER_generic(nid, keylen, 16, 16, cbc, cbc, CBC, flags | EVP_CIPH_FLAG_DEFAULT_ASN1)   \
-    BLOCK_CIPHER_generic(nid, keylen, 16, 0, ecb, ecb, ECB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1)    \
-    BLOCK_CIPHER_generic(nid, keylen, 1, 16, ofb128, ofb, OFB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1) \
-    BLOCK_CIPHER_generic(nid, keylen, 1, 16, cfb128, cfb, CFB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1) \
-    BLOCK_CIPHER_generic(nid, keylen, 1, 16, cfb1, cfb1, CFB, flags)                               \
-    BLOCK_CIPHER_generic(nid, keylen, 1, 16, cfb8, cfb8, CFB, flags)                               \
-    BLOCK_CIPHER_generic(nid, keylen, 1, 16, ctr, ctr, CTR, flags)
+#endif
+
+#define BLOCK_CIPHER_generic_pack(nid, keylen, flags)                                                          \
+    BLOCK_CIPHER_generic(nid, keylen, 16, 16, cbc, cbc, CBC, flags | EVP_CIPH_FLAG_DEFAULT_ASN1)               \
+        BLOCK_CIPHER_generic(nid, keylen, 16, 0, ecb, ecb, ECB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1)            \
+            BLOCK_CIPHER_generic(nid, keylen, 1, 16, ofb128, ofb, OFB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1)     \
+                BLOCK_CIPHER_generic(nid, keylen, 1, 16, cfb128, cfb, CFB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1) \
+                    BLOCK_CIPHER_generic(nid, keylen, 1, 16, cfb1, cfb1, CFB, flags)                           \
+                        BLOCK_CIPHER_generic(nid, keylen, 1, 16, cfb8, cfb8, CFB, flags)                       \
+                            BLOCK_CIPHER_generic(nid, keylen, 1, 16, ctr, ctr, CTR, flags)
+
+static int aes_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    int ret, mode;
+    EVP_AES_KEY *dat = EVP_C_DATA(EVP_AES_KEY, ctx);
+    const int keylen = EVP_CIPHER_CTX_get_key_length(ctx) * 8;
+
+    if (keylen <= 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+        return 0;
+    }
+
+    mode = EVP_CIPHER_CTX_get_mode(ctx);
+    if ((mode == EVP_CIPH_ECB_MODE || mode == EVP_CIPH_CBC_MODE)
+        && !enc) {
+#ifdef HWAES_CAPABLE
+        if (HWAES_CAPABLE) {
+            ret = HWAES_set_decrypt_key(key, keylen, &dat->ks.ks);
+            dat->block = (block128_f)HWAES_decrypt;
+            dat->stream.cbc = NULL;
+#ifdef HWAES_cbc_encrypt
+            if (mode == EVP_CIPH_CBC_MODE)
+                dat->stream.cbc = (cbc128_f)HWAES_cbc_encrypt;
+#endif
+        } else
+#endif
+#ifdef BSAES_CAPABLE
+            if (BSAES_CAPABLE && mode == EVP_CIPH_CBC_MODE) {
+            ret = AES_set_decrypt_key(key, keylen, &dat->ks.ks);
+            dat->block = (block128_f)AES_decrypt;
+            dat->stream.cbc = (cbc128_f)ossl_bsaes_cbc_encrypt;
+        } else
+#endif
+#ifdef VPAES_CAPABLE
+            if (VPAES_CAPABLE) {
+            ret = vpaes_set_decrypt_key(key, keylen, &dat->ks.ks);
+            dat->block = (block128_f)vpaes_decrypt;
+            dat->stream.cbc = mode == EVP_CIPH_CBC_MODE ? (cbc128_f)vpaes_cbc_encrypt : NULL;
+        } else
+#endif
+        {
+            ret = AES_set_decrypt_key(key, keylen, &dat->ks.ks);
+            dat->block = (block128_f)AES_decrypt;
+            dat->stream.cbc = mode == EVP_CIPH_CBC_MODE ? (cbc128_f)AES_cbc_encrypt : NULL;
+        }
+    } else
+#ifdef HWAES_CAPABLE
+        if (HWAES_CAPABLE) {
+        ret = HWAES_set_encrypt_key(key, keylen, &dat->ks.ks);
+        dat->block = (block128_f)HWAES_encrypt;
+        dat->stream.cbc = NULL;
+#ifdef HWAES_cbc_encrypt
+        if (mode == EVP_CIPH_CBC_MODE)
+            dat->stream.cbc = (cbc128_f)HWAES_cbc_encrypt;
+        else
+#endif
+#ifdef HWAES_ctr32_encrypt_blocks
+            if (mode == EVP_CIPH_CTR_MODE)
+            dat->stream.ctr = (ctr128_f)HWAES_ctr32_encrypt_blocks;
+        else
+#endif
+            (void)0; /* terminate potentially open 'else' */
+    } else
+#endif
+#ifdef BSAES_CAPABLE
+        if (BSAES_CAPABLE && mode == EVP_CIPH_CTR_MODE) {
+        ret = AES_set_encrypt_key(key, keylen, &dat->ks.ks);
+        dat->block = (block128_f)AES_encrypt;
+        dat->stream.ctr = (ctr128_f)ossl_bsaes_ctr32_encrypt_blocks;
+    } else
+#endif
+#ifdef VPAES_CAPABLE
+        if (VPAES_CAPABLE) {
+        ret = vpaes_set_encrypt_key(key, keylen, &dat->ks.ks);
+        dat->block = (block128_f)vpaes_encrypt;
+        dat->stream.cbc = mode == EVP_CIPH_CBC_MODE ? (cbc128_f)vpaes_cbc_encrypt : NULL;
+    } else
+#endif
+    {
+        ret = AES_set_encrypt_key(key, keylen, &dat->ks.ks);
+        dat->block = (block128_f)AES_encrypt;
+        dat->stream.cbc = mode == EVP_CIPH_CBC_MODE ? (cbc128_f)AES_cbc_encrypt : NULL;
+#ifdef AES_CTR_ASM
+        if (mode == EVP_CIPH_CTR_MODE)
+            dat->stream.ctr = (ctr128_f)AES_ctr32_encrypt;
+#endif
+    }
+
+    if (ret < 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_AES_KEY_SETUP_FAILED);
+        return 0;
+    }
+
+    return 1;
+}
+
+static int aes_cbc_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_AES_KEY *dat = EVP_C_DATA(EVP_AES_KEY, ctx);
+
+    if (dat->stream.cbc)
+        (*dat->stream.cbc)(in, out, len, &dat->ks, ctx->iv,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+    else if (EVP_CIPHER_CTX_is_encrypting(ctx))
+        CRYPTO_cbc128_encrypt(in, out, len, &dat->ks, ctx->iv,
+            dat->block);
+    else
+        CRYPTO_cbc128_decrypt(in, out, len, &dat->ks,
+            ctx->iv, dat->block);
+
+    return 1;
+}
+
+static int aes_ecb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    size_t bl = EVP_CIPHER_CTX_get_block_size(ctx);
+    size_t i;
+    EVP_AES_KEY *dat = EVP_C_DATA(EVP_AES_KEY, ctx);
+
+    if (len < bl)
+        return 1;
+
+    for (i = 0, len -= bl; i <= len; i += bl)
+        (*dat->block)(in + i, out + i, &dat->ks);
+
+    return 1;
+}
+
+static int aes_ofb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_AES_KEY *dat = EVP_C_DATA(EVP_AES_KEY, ctx);
+
+    int num = EVP_CIPHER_CTX_get_num(ctx);
+    CRYPTO_ofb128_encrypt(in, out, len, &dat->ks,
+        ctx->iv, &num, dat->block);
+    EVP_CIPHER_CTX_set_num(ctx, num);
+    return 1;
+}
+
+static int aes_cfb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_AES_KEY *dat = EVP_C_DATA(EVP_AES_KEY, ctx);
+
+    int num = EVP_CIPHER_CTX_get_num(ctx);
+    CRYPTO_cfb128_encrypt(in, out, len, &dat->ks,
+        ctx->iv, &num,
+        EVP_CIPHER_CTX_is_encrypting(ctx), dat->block);
+    EVP_CIPHER_CTX_set_num(ctx, num);
+    return 1;
+}
+
+static int aes_cfb8_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_AES_KEY *dat = EVP_C_DATA(EVP_AES_KEY, ctx);
+
+    int num = EVP_CIPHER_CTX_get_num(ctx);
+    CRYPTO_cfb128_8_encrypt(in, out, len, &dat->ks,
+        ctx->iv, &num,
+        EVP_CIPHER_CTX_is_encrypting(ctx), dat->block);
+    EVP_CIPHER_CTX_set_num(ctx, num);
+    return 1;
+}
+
+static int aes_cfb1_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_AES_KEY *dat = EVP_C_DATA(EVP_AES_KEY, ctx);
+
+    if (EVP_CIPHER_CTX_test_flags(ctx, EVP_CIPH_FLAG_LENGTH_BITS)) {
+        int num = EVP_CIPHER_CTX_get_num(ctx);
+        CRYPTO_cfb128_1_encrypt(in, out, len, &dat->ks,
+            ctx->iv, &num,
+            EVP_CIPHER_CTX_is_encrypting(ctx), dat->block);
+        EVP_CIPHER_CTX_set_num(ctx, num);
+        return 1;
+    }
+
+    while (len >= MAXBITCHUNK) {
+        int num = EVP_CIPHER_CTX_get_num(ctx);
+        CRYPTO_cfb128_1_encrypt(in, out, MAXBITCHUNK * 8, &dat->ks,
+            ctx->iv, &num,
+            EVP_CIPHER_CTX_is_encrypting(ctx), dat->block);
+        EVP_CIPHER_CTX_set_num(ctx, num);
+        len -= MAXBITCHUNK;
+        out += MAXBITCHUNK;
+        in += MAXBITCHUNK;
+    }
+    if (len) {
+        int num = EVP_CIPHER_CTX_get_num(ctx);
+        CRYPTO_cfb128_1_encrypt(in, out, len * 8, &dat->ks,
+            ctx->iv, &num,
+            EVP_CIPHER_CTX_is_encrypting(ctx), dat->block);
+        EVP_CIPHER_CTX_set_num(ctx, num);
+    }
+
+    return 1;
+}
+
+static int aes_ctr_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    int n = EVP_CIPHER_CTX_get_num(ctx);
+    unsigned int num;
+    EVP_AES_KEY *dat = EVP_C_DATA(EVP_AES_KEY, ctx);
+
+    if (n < 0)
+        return 0;
+    num = (unsigned int)n;
+
+    if (dat->stream.ctr)
+        CRYPTO_ctr128_encrypt_ctr32(in, out, len, &dat->ks,
+            ctx->iv,
+            EVP_CIPHER_CTX_buf_noconst(ctx),
+            &num, dat->stream.ctr);
+    else
+        CRYPTO_ctr128_encrypt(in, out, len, &dat->ks,
+            ctx->iv,
+            EVP_CIPHER_CTX_buf_noconst(ctx), &num,
+            dat->block);
+    EVP_CIPHER_CTX_set_num(ctx, num);
+    return 1;
+}
 
 BLOCK_CIPHER_generic_pack(NID_aes, 128, 0)
-BLOCK_CIPHER_generic_pack(NID_aes, 192, 0)
-BLOCK_CIPHER_generic_pack(NID_aes, 256, 0)
+    BLOCK_CIPHER_generic_pack(NID_aes, 192, 0)
+        BLOCK_CIPHER_generic_pack(NID_aes, 256, 0)
+
+            static int aes_gcm_cleanup(EVP_CIPHER_CTX *c)
+{
+    EVP_AES_GCM_CTX *gctx = EVP_C_DATA(EVP_AES_GCM_CTX, c);
+    if (gctx == NULL)
+        return 0;
+    OPENSSL_cleanse(&gctx->gcm, sizeof(gctx->gcm));
+    if (gctx->iv != c->iv)
+        OPENSSL_free(gctx->iv);
+    return 1;
+}
+
+static int aes_gcm_ctrl(EVP_CIPHER_CTX *c, int type, int arg, void *ptr)
+{
+    EVP_AES_GCM_CTX *gctx = EVP_C_DATA(EVP_AES_GCM_CTX, c);
+    switch (type) {
+    case EVP_CTRL_INIT:
+        gctx->key_set = 0;
+        gctx->iv_set = 0;
+        gctx->ivlen = EVP_CIPHER_get_iv_length(c->cipher);
+        gctx->iv = c->iv;
+        gctx->taglen = -1;
+        gctx->iv_gen = 0;
+        gctx->tls_aad_len = -1;
+        return 1;
+
+    case EVP_CTRL_GET_IVLEN:
+        *(int *)ptr = gctx->ivlen;
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_IVLEN:
+        if (arg <= 0)
+            return 0;
+        /* Allocate memory for IV if needed */
+        if ((arg > EVP_MAX_IV_LENGTH) && (arg > gctx->ivlen)) {
+            if (gctx->iv != c->iv)
+                OPENSSL_free(gctx->iv);
+            if ((gctx->iv = OPENSSL_malloc(arg)) == NULL)
+                return 0;
+        }
+        gctx->ivlen = arg;
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_TAG:
+        if (arg <= 0 || arg > 16 || c->encrypt)
+            return 0;
+        memcpy(c->buf, ptr, arg);
+        gctx->taglen = arg;
+        return 1;
+
+    case EVP_CTRL_AEAD_GET_TAG:
+        if (arg <= 0 || arg > 16 || !c->encrypt
+            || gctx->taglen < 0)
+            return 0;
+        memcpy(ptr, c->buf, arg);
+        return 1;
+
+    case EVP_CTRL_GCM_SET_IV_FIXED:
+        /* Special case: -1 length restores whole IV */
+        if (arg == -1) {
+            memcpy(gctx->iv, ptr, gctx->ivlen);
+            gctx->iv_gen = 1;
+            return 1;
+        }
+        /*
+         * Fixed field must be at least 4 bytes and invocation field at least
+         * 8.
+         */
+        if ((arg < 4) || (gctx->ivlen - arg) < 8)
+            return 0;
+        if (arg)
+            memcpy(gctx->iv, ptr, arg);
+        if (c->encrypt && RAND_bytes(gctx->iv + arg, gctx->ivlen - arg) <= 0)
+            return 0;
+        gctx->iv_gen = 1;
+        return 1;
+
+    case EVP_CTRL_GCM_IV_GEN:
+        if (gctx->iv_gen == 0 || gctx->key_set == 0)
+            return 0;
+        CRYPTO_gcm128_setiv(&gctx->gcm, gctx->iv, gctx->ivlen);
+        if (arg <= 0 || arg > gctx->ivlen)
+            arg = gctx->ivlen;
+        memcpy(ptr, gctx->iv + gctx->ivlen - arg, arg);
+        /*
+         * Invocation field will be at least 8 bytes in size and so no need
+         * to check wrap around or increment more than last 8 bytes.
+         */
+        ctr64_inc(gctx->iv + gctx->ivlen - 8);
+        gctx->iv_set = 1;
+        return 1;
+
+    case EVP_CTRL_GCM_SET_IV_INV:
+        if (gctx->iv_gen == 0 || gctx->key_set == 0 || c->encrypt)
+            return 0;
+        memcpy(gctx->iv + gctx->ivlen - arg, ptr, arg);
+        CRYPTO_gcm128_setiv(&gctx->gcm, gctx->iv, gctx->ivlen);
+        gctx->iv_set = 1;
+        return 1;
+
+    case EVP_CTRL_AEAD_TLS1_AAD:
+        /* Save the AAD for later use */
+        if (arg != EVP_AEAD_TLS1_AAD_LEN)
+            return 0;
+        memcpy(c->buf, ptr, arg);
+        gctx->tls_aad_len = arg;
+        gctx->tls_enc_records = 0;
+        {
+            unsigned int len = c->buf[arg - 2] << 8 | c->buf[arg - 1];
+            /* Correct length for explicit IV */
+            if (len < EVP_GCM_TLS_EXPLICIT_IV_LEN)
+                return 0;
+            len -= EVP_GCM_TLS_EXPLICIT_IV_LEN;
+            /* If decrypting correct for tag too */
+            if (!c->encrypt) {
+                if (len < EVP_GCM_TLS_TAG_LEN)
+                    return 0;
+                len -= EVP_GCM_TLS_TAG_LEN;
+            }
+            c->buf[arg - 2] = len >> 8;
+            c->buf[arg - 1] = len & 0xff;
+        }
+        /* Extra padding: tag appended to record */
+        return EVP_GCM_TLS_TAG_LEN;
+
+    case EVP_CTRL_COPY: {
+        EVP_CIPHER_CTX *out = ptr;
+        EVP_AES_GCM_CTX *gctx_out = EVP_C_DATA(EVP_AES_GCM_CTX, out);
+        if (gctx->gcm.key) {
+            if (gctx->gcm.key != &gctx->ks)
+                return 0;
+            gctx_out->gcm.key = &gctx_out->ks;
+        }
+        if (gctx->iv == c->iv)
+            gctx_out->iv = out->iv;
+        else {
+            if ((gctx_out->iv = OPENSSL_malloc(gctx->ivlen)) == NULL)
+                return 0;
+            memcpy(gctx_out->iv, gctx->iv, gctx->ivlen);
+        }
+        return 1;
+    }
+
+    default:
+        return -1;
+    }
+}
+
+static int aes_gcm_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    EVP_AES_GCM_CTX *gctx = EVP_C_DATA(EVP_AES_GCM_CTX, ctx);
+
+    if (iv == NULL && key == NULL)
+        return 1;
+
+    if (key != NULL) {
+        const int keylen = EVP_CIPHER_CTX_get_key_length(ctx) * 8;
+
+        if (keylen <= 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+            return 0;
+        }
+        do {
+#ifdef HWAES_CAPABLE
+            if (HWAES_CAPABLE) {
+                HWAES_set_encrypt_key(key, keylen, &gctx->ks.ks);
+                CRYPTO_gcm128_init(&gctx->gcm, &gctx->ks,
+                    (block128_f)HWAES_encrypt);
+#ifdef HWAES_ctr32_encrypt_blocks
+                gctx->ctr = (ctr128_f)HWAES_ctr32_encrypt_blocks;
+#else
+                gctx->ctr = NULL;
+#endif
+                break;
+            } else
+#endif
+#ifdef BSAES_CAPABLE
+                if (BSAES_CAPABLE) {
+                AES_set_encrypt_key(key, keylen, &gctx->ks.ks);
+                CRYPTO_gcm128_init(&gctx->gcm, &gctx->ks,
+                    (block128_f)AES_encrypt);
+                gctx->ctr = (ctr128_f)ossl_bsaes_ctr32_encrypt_blocks;
+                break;
+            } else
+#endif
+#ifdef VPAES_CAPABLE
+                if (VPAES_CAPABLE) {
+                vpaes_set_encrypt_key(key, keylen, &gctx->ks.ks);
+                CRYPTO_gcm128_init(&gctx->gcm, &gctx->ks,
+                    (block128_f)vpaes_encrypt);
+                gctx->ctr = NULL;
+                break;
+            } else
+#endif
+                (void)0; /* terminate potentially open 'else' */
+
+            AES_set_encrypt_key(key, keylen, &gctx->ks.ks);
+            CRYPTO_gcm128_init(&gctx->gcm, &gctx->ks,
+                (block128_f)AES_encrypt);
+#ifdef AES_CTR_ASM
+            gctx->ctr = (ctr128_f)AES_ctr32_encrypt;
+#else
+            gctx->ctr = NULL;
+#endif
+        } while (0);
+
+        /*
+         * If we have an iv can set it directly, otherwise use saved IV.
+         */
+        if (iv == NULL && gctx->iv_set)
+            iv = gctx->iv;
+        if (iv) {
+            CRYPTO_gcm128_setiv(&gctx->gcm, iv, gctx->ivlen);
+            gctx->iv_set = 1;
+        }
+        gctx->key_set = 1;
+    } else {
+        /* If key set use IV, otherwise copy */
+        if (gctx->key_set)
+            CRYPTO_gcm128_setiv(&gctx->gcm, iv, gctx->ivlen);
+        else
+            memcpy(gctx->iv, iv, gctx->ivlen);
+        gctx->iv_set = 1;
+        gctx->iv_gen = 0;
+    }
+    return 1;
+}
+
+/*
+ * Handle TLS GCM packet format. This consists of the last portion of the IV
+ * followed by the payload and finally the tag. On encrypt generate IV,
+ * encrypt payload and write the tag. On verify retrieve IV, decrypt payload
+ * and verify tag.
+ */
+
+static int aes_gcm_tls_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_AES_GCM_CTX *gctx = EVP_C_DATA(EVP_AES_GCM_CTX, ctx);
+    int rv = -1;
+    /* Encrypt/decrypt must be performed in place */
+    if (out != in
+        || len < (EVP_GCM_TLS_EXPLICIT_IV_LEN + EVP_GCM_TLS_TAG_LEN))
+        return -1;
+
+    /*
+     * Check for too many keys as per FIPS 140-2 IG A.5 "Key/IV Pair Uniqueness
+     * Requirements from SP 800-38D".  The requirements is for one party to the
+     * communication to fail after 2^64 - 1 keys.  We do this on the encrypting
+     * side only.
+     */
+    if (EVP_CIPHER_CTX_is_encrypting(ctx) && ++gctx->tls_enc_records == 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_TOO_MANY_RECORDS);
+        goto err;
+    }
+
+    /*
+     * Set IV from start of buffer or generate IV and write to start of
+     * buffer.
+     */
+    if (EVP_CIPHER_CTX_ctrl(ctx,
+            EVP_CIPHER_CTX_is_encrypting(ctx) ? EVP_CTRL_GCM_IV_GEN : EVP_CTRL_GCM_SET_IV_INV,
+            EVP_GCM_TLS_EXPLICIT_IV_LEN, out)
+        <= 0)
+        goto err;
+    /* Use saved AAD */
+    if (CRYPTO_gcm128_aad(&gctx->gcm, EVP_CIPHER_CTX_buf_noconst(ctx),
+            gctx->tls_aad_len))
+        goto err;
+    /* Fix buffer and length to point to payload */
+    in += EVP_GCM_TLS_EXPLICIT_IV_LEN;
+    out += EVP_GCM_TLS_EXPLICIT_IV_LEN;
+    len -= EVP_GCM_TLS_EXPLICIT_IV_LEN + EVP_GCM_TLS_TAG_LEN;
+    if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+        /* Encrypt payload */
+        if (gctx->ctr) {
+            size_t bulk = 0;
+#if defined(AES_GCM_ASM)
+            if (len >= 32 && AES_GCM_ASM(gctx)) {
+                if (CRYPTO_gcm128_encrypt(&gctx->gcm, NULL, NULL, 0))
+                    return -1;
+
+                bulk = AES_gcm_encrypt(in, out, len,
+                    gctx->gcm.key,
+                    gctx->gcm.Yi.c, gctx->gcm.Xi.u);
+                gctx->gcm.len.u[1] += bulk;
+            }
+#endif
+            if (CRYPTO_gcm128_encrypt_ctr32(&gctx->gcm,
+                    in + bulk,
+                    out + bulk,
+                    len - bulk, gctx->ctr))
+                goto err;
+        } else {
+            size_t bulk = 0;
+#if defined(AES_GCM_ASM2)
+            if (len >= 32 && AES_GCM_ASM2(gctx)) {
+                if (CRYPTO_gcm128_encrypt(&gctx->gcm, NULL, NULL, 0))
+                    return -1;
+
+                bulk = AES_gcm_encrypt(in, out, len,
+                    gctx->gcm.key,
+                    gctx->gcm.Yi.c, gctx->gcm.Xi.u);
+                gctx->gcm.len.u[1] += bulk;
+            }
+#endif
+            if (CRYPTO_gcm128_encrypt(&gctx->gcm,
+                    in + bulk, out + bulk, len - bulk))
+                goto err;
+        }
+        out += len;
+        /* Finally write tag */
+        CRYPTO_gcm128_tag(&gctx->gcm, out, EVP_GCM_TLS_TAG_LEN);
+        rv = (int)(len + EVP_GCM_TLS_EXPLICIT_IV_LEN + EVP_GCM_TLS_TAG_LEN);
+    } else {
+        /* Decrypt */
+        if (gctx->ctr) {
+            size_t bulk = 0;
+#if defined(AES_GCM_ASM)
+            if (len >= 16 && AES_GCM_ASM(gctx)) {
+                if (CRYPTO_gcm128_decrypt(&gctx->gcm, NULL, NULL, 0))
+                    return -1;
+
+                bulk = AES_gcm_decrypt(in, out, len,
+                    gctx->gcm.key,
+                    gctx->gcm.Yi.c, gctx->gcm.Xi.u);
+                gctx->gcm.len.u[1] += bulk;
+            }
+#endif
+            if (CRYPTO_gcm128_decrypt_ctr32(&gctx->gcm,
+                    in + bulk,
+                    out + bulk,
+                    len - bulk, gctx->ctr))
+                goto err;
+        } else {
+            size_t bulk = 0;
+#if defined(AES_GCM_ASM2)
+            if (len >= 16 && AES_GCM_ASM2(gctx)) {
+                if (CRYPTO_gcm128_decrypt(&gctx->gcm, NULL, NULL, 0))
+                    return -1;
+
+                bulk = AES_gcm_decrypt(in, out, len,
+                    gctx->gcm.key,
+                    gctx->gcm.Yi.c, gctx->gcm.Xi.u);
+                gctx->gcm.len.u[1] += bulk;
+            }
+#endif
+            if (CRYPTO_gcm128_decrypt(&gctx->gcm,
+                    in + bulk, out + bulk, len - bulk))
+                goto err;
+        }
+        /* Retrieve tag */
+        CRYPTO_gcm128_tag(&gctx->gcm, EVP_CIPHER_CTX_buf_noconst(ctx),
+            EVP_GCM_TLS_TAG_LEN);
+        /* If tag mismatch wipe buffer */
+        if (CRYPTO_memcmp(EVP_CIPHER_CTX_buf_noconst(ctx), in + len,
+                EVP_GCM_TLS_TAG_LEN)) {
+            OPENSSL_cleanse(out, len);
+            goto err;
+        }
+        rv = (int)len;
+    }
+
+err:
+    gctx->iv_set = 0;
+    gctx->tls_aad_len = -1;
+    return rv;
+}
+
+#ifdef FIPS_MODULE
+/*
+ * See SP800-38D (GCM) Section 8 "Uniqueness requirement on IVS and keys"
+ *
+ * See also 8.2.2 RBG-based construction.
+ * Random construction consists of a free field (which can be NULL) and a
+ * random field which will use a DRBG that can return at least 96 bits of
+ * entropy strength. (The DRBG must be seeded by the FIPS module).
+ */
+static int aes_gcm_iv_generate(EVP_AES_GCM_CTX *gctx, int offset)
+{
+    int sz = gctx->ivlen - offset;
+
+    /* Must be at least 96 bits */
+    if (sz <= 0 || gctx->ivlen < 12)
+        return 0;
+
+    /* Use DRBG to generate random iv */
+    if (RAND_bytes(gctx->iv + offset, sz) <= 0)
+        return 0;
+    return 1;
+}
+#endif /* FIPS_MODULE */
+
+static int aes_gcm_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_AES_GCM_CTX *gctx = EVP_C_DATA(EVP_AES_GCM_CTX, ctx);
+
+    /* If not set up, return error */
+    if (!gctx->key_set)
+        return -1;
+
+    if (gctx->tls_aad_len >= 0)
+        return aes_gcm_tls_cipher(ctx, out, in, len);
+
+#ifdef FIPS_MODULE
+    /*
+     * FIPS requires generation of AES-GCM IV's inside the FIPS module.
+     * The IV can still be set externally (the security policy will state that
+     * this is not FIPS compliant). There are some applications
+     * where setting the IV externally is the only option available.
+     */
+    if (!gctx->iv_set) {
+        if (!EVP_CIPHER_CTX_is_encrypting(ctx) || !aes_gcm_iv_generate(gctx, 0))
+            return -1;
+        CRYPTO_gcm128_setiv(&gctx->gcm, gctx->iv, gctx->ivlen);
+        gctx->iv_set = 1;
+        gctx->iv_gen_rand = 1;
+    }
+#else
+    if (!gctx->iv_set)
+        return -1;
+#endif /* FIPS_MODULE */
+
+    if (in) {
+        if (out == NULL) {
+            if (CRYPTO_gcm128_aad(&gctx->gcm, in, len))
+                return -1;
+        } else if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+            if (gctx->ctr) {
+                size_t bulk = 0;
+#if defined(AES_GCM_ASM)
+                if (len >= 32 && AES_GCM_ASM(gctx)) {
+                    size_t res = (16 - gctx->gcm.mres) % 16;
+
+                    if (CRYPTO_gcm128_encrypt(&gctx->gcm, in, out, res))
+                        return -1;
+
+                    bulk = AES_gcm_encrypt(in + res,
+                        out + res, len - res,
+                        gctx->gcm.key, gctx->gcm.Yi.c,
+                        gctx->gcm.Xi.u);
+                    gctx->gcm.len.u[1] += bulk;
+                    bulk += res;
+                }
+#endif
+                if (CRYPTO_gcm128_encrypt_ctr32(&gctx->gcm,
+                        in + bulk,
+                        out + bulk,
+                        len - bulk, gctx->ctr))
+                    return -1;
+            } else {
+                size_t bulk = 0;
+#if defined(AES_GCM_ASM2)
+                if (len >= 32 && AES_GCM_ASM2(gctx)) {
+                    size_t res = (16 - gctx->gcm.mres) % 16;
+
+                    if (CRYPTO_gcm128_encrypt(&gctx->gcm, in, out, res))
+                        return -1;
+
+                    bulk = AES_gcm_encrypt(in + res,
+                        out + res, len - res,
+                        gctx->gcm.key, gctx->gcm.Yi.c,
+                        gctx->gcm.Xi.u);
+                    gctx->gcm.len.u[1] += bulk;
+                    bulk += res;
+                }
+#endif
+                if (CRYPTO_gcm128_encrypt(&gctx->gcm,
+                        in + bulk, out + bulk, len - bulk))
+                    return -1;
+            }
+        } else {
+            if (gctx->ctr) {
+                size_t bulk = 0;
+#if defined(AES_GCM_ASM)
+                if (len >= 16 && AES_GCM_ASM(gctx)) {
+                    size_t res = (16 - gctx->gcm.mres) % 16;
+
+                    if (CRYPTO_gcm128_decrypt(&gctx->gcm, in, out, res))
+                        return -1;
+
+                    bulk = AES_gcm_decrypt(in + res,
+                        out + res, len - res,
+                        gctx->gcm.key,
+                        gctx->gcm.Yi.c, gctx->gcm.Xi.u);
+                    gctx->gcm.len.u[1] += bulk;
+                    bulk += res;
+                }
+#endif
+                if (CRYPTO_gcm128_decrypt_ctr32(&gctx->gcm,
+                        in + bulk,
+                        out + bulk,
+                        len - bulk, gctx->ctr))
+                    return -1;
+            } else {
+                size_t bulk = 0;
+#if defined(AES_GCM_ASM2)
+                if (len >= 16 && AES_GCM_ASM2(gctx)) {
+                    size_t res = (16 - gctx->gcm.mres) % 16;
+
+                    if (CRYPTO_gcm128_decrypt(&gctx->gcm, in, out, res))
+                        return -1;
+
+                    bulk = AES_gcm_decrypt(in + res,
+                        out + res, len - res,
+                        gctx->gcm.key,
+                        gctx->gcm.Yi.c, gctx->gcm.Xi.u);
+                    gctx->gcm.len.u[1] += bulk;
+                    bulk += res;
+                }
+#endif
+                if (CRYPTO_gcm128_decrypt(&gctx->gcm,
+                        in + bulk, out + bulk, len - bulk))
+                    return -1;
+            }
+        }
+        return (int)len;
+    } else {
+        if (!EVP_CIPHER_CTX_is_encrypting(ctx)) {
+            if (gctx->taglen < 0)
+                return -1;
+            if (CRYPTO_gcm128_finish(&gctx->gcm,
+                    EVP_CIPHER_CTX_buf_noconst(ctx),
+                    gctx->taglen)
+                != 0)
+                return -1;
+            gctx->iv_set = 0;
+            return 0;
+        }
+        CRYPTO_gcm128_tag(&gctx->gcm, EVP_CIPHER_CTX_buf_noconst(ctx), 16);
+        gctx->taglen = 16;
+        /* Don't reuse the IV */
+        gctx->iv_set = 0;
+        return 0;
+    }
+}
 
 #define CUSTOM_FLAGS (EVP_CIPH_FLAG_DEFAULT_ASN1       \
     | EVP_CIPH_CUSTOM_IV | EVP_CIPH_FLAG_CUSTOM_CIPHER \
@@ -57,24 +3189,574 @@ BLOCK_CIPHER_generic_pack(NID_aes, 256, 0)
 
 BLOCK_CIPHER_custom(NID_aes, 128, 1, 12, gcm, GCM,
     EVP_CIPH_FLAG_AEAD_CIPHER | CUSTOM_FLAGS)
-BLOCK_CIPHER_custom(NID_aes, 192, 1, 12, gcm, GCM,
-    EVP_CIPH_FLAG_AEAD_CIPHER | CUSTOM_FLAGS)
-BLOCK_CIPHER_custom(NID_aes, 256, 1, 12, gcm, GCM,
-    EVP_CIPH_FLAG_AEAD_CIPHER | CUSTOM_FLAGS)
+    BLOCK_CIPHER_custom(NID_aes, 192, 1, 12, gcm, GCM,
+        EVP_CIPH_FLAG_AEAD_CIPHER | CUSTOM_FLAGS)
+        BLOCK_CIPHER_custom(NID_aes, 256, 1, 12, gcm, GCM,
+            EVP_CIPH_FLAG_AEAD_CIPHER | CUSTOM_FLAGS)
+
+            static int aes_xts_ctrl(EVP_CIPHER_CTX *c, int type, int arg, void *ptr)
+{
+    EVP_AES_XTS_CTX *xctx = EVP_C_DATA(EVP_AES_XTS_CTX, c);
+
+    if (type == EVP_CTRL_COPY) {
+        EVP_CIPHER_CTX *out = ptr;
+        EVP_AES_XTS_CTX *xctx_out = EVP_C_DATA(EVP_AES_XTS_CTX, out);
+
+        if (xctx->xts.key1) {
+            if (xctx->xts.key1 != &xctx->ks1)
+                return 0;
+            xctx_out->xts.key1 = &xctx_out->ks1;
+        }
+        if (xctx->xts.key2) {
+            if (xctx->xts.key2 != &xctx->ks2)
+                return 0;
+            xctx_out->xts.key2 = &xctx_out->ks2;
+        }
+        return 1;
+    } else if (type != EVP_CTRL_INIT)
+        return -1;
+    /* key1 and key2 are used as an indicator both key and IV are set */
+    xctx->xts.key1 = NULL;
+    xctx->xts.key2 = NULL;
+    return 1;
+}
+
+static int aes_xts_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    EVP_AES_XTS_CTX *xctx = EVP_C_DATA(EVP_AES_XTS_CTX, ctx);
+
+    if (iv == NULL && key == NULL)
+        return 1;
+
+    if (key != NULL) {
+        do {
+            /* The key is two half length keys in reality */
+            const int keylen = EVP_CIPHER_CTX_get_key_length(ctx);
+            const int bytes = keylen / 2;
+            const int bits = bytes * 8;
+
+            if (keylen <= 0) {
+                ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+                return 0;
+            }
+            /*
+             * Verify that the two keys are different.
+             *
+             * This addresses the vulnerability described in Rogaway's
+             * September 2004 paper:
+             *
+             *      "Efficient Instantiations of Tweakable Blockciphers and
+             *       Refinements to Modes OCB and PMAC".
+             *      (http://web.cs.ucdavis.edu/~rogaway/papers/offsets.pdf)
+             *
+             * FIPS 140-2 IG A.9 XTS-AES Key Generation Requirements states
+             * that:
+             *      "The check for Key_1 != Key_2 shall be done at any place
+             *       BEFORE using the keys in the XTS-AES algorithm to process
+             *       data with them."
+             */
+            if ((!allow_insecure_decrypt || enc)
+                && CRYPTO_memcmp(key, key + bytes, bytes) == 0) {
+                ERR_raise(ERR_LIB_EVP, EVP_R_XTS_DUPLICATED_KEYS);
+                return 0;
+            }
+
+#ifdef AES_XTS_ASM
+            xctx->stream = enc ? AES_xts_encrypt : AES_xts_decrypt;
+#else
+            xctx->stream = NULL;
+#endif
+            /* key_len is two AES keys */
+#ifdef HWAES_CAPABLE
+            if (HWAES_CAPABLE) {
+                if (enc) {
+                    HWAES_set_encrypt_key(key, bits, &xctx->ks1.ks);
+                    xctx->xts.block1 = (block128_f)HWAES_encrypt;
+#ifdef HWAES_xts_encrypt
+                    xctx->stream = HWAES_xts_encrypt;
+#endif
+                } else {
+                    HWAES_set_decrypt_key(key, bits, &xctx->ks1.ks);
+                    xctx->xts.block1 = (block128_f)HWAES_decrypt;
+#ifdef HWAES_xts_decrypt
+                    xctx->stream = HWAES_xts_decrypt;
+#endif
+                }
+
+                HWAES_set_encrypt_key(key + bytes, bits, &xctx->ks2.ks);
+                xctx->xts.block2 = (block128_f)HWAES_encrypt;
+
+                xctx->xts.key1 = &xctx->ks1;
+                break;
+            } else
+#endif
+#ifdef BSAES_CAPABLE
+                if (BSAES_CAPABLE)
+                xctx->stream = enc ? ossl_bsaes_xts_encrypt : ossl_bsaes_xts_decrypt;
+            else
+#endif
+#ifdef VPAES_CAPABLE
+                if (VPAES_CAPABLE) {
+                if (enc) {
+                    vpaes_set_encrypt_key(key, bits, &xctx->ks1.ks);
+                    xctx->xts.block1 = (block128_f)vpaes_encrypt;
+                } else {
+                    vpaes_set_decrypt_key(key, bits, &xctx->ks1.ks);
+                    xctx->xts.block1 = (block128_f)vpaes_decrypt;
+                }
+
+                vpaes_set_encrypt_key(key + bytes, bits, &xctx->ks2.ks);
+                xctx->xts.block2 = (block128_f)vpaes_encrypt;
+
+                xctx->xts.key1 = &xctx->ks1;
+                break;
+            } else
+#endif
+                (void)0; /* terminate potentially open 'else' */
+
+            if (enc) {
+                AES_set_encrypt_key(key, bits, &xctx->ks1.ks);
+                xctx->xts.block1 = (block128_f)AES_encrypt;
+            } else {
+                AES_set_decrypt_key(key, bits, &xctx->ks1.ks);
+                xctx->xts.block1 = (block128_f)AES_decrypt;
+            }
+
+            AES_set_encrypt_key(key + bytes, bits, &xctx->ks2.ks);
+            xctx->xts.block2 = (block128_f)AES_encrypt;
+
+            xctx->xts.key1 = &xctx->ks1;
+        } while (0);
+    }
+
+    if (iv) {
+        xctx->xts.key2 = &xctx->ks2;
+        memcpy(ctx->iv, iv, 16);
+    }
+
+    return 1;
+}
+
+static int aes_xts_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_AES_XTS_CTX *xctx = EVP_C_DATA(EVP_AES_XTS_CTX, ctx);
+
+    if (xctx->xts.key1 == NULL
+        || xctx->xts.key2 == NULL
+        || out == NULL
+        || in == NULL
+        || len < AES_BLOCK_SIZE)
+        return 0;
+
+    /*
+     * Impose a limit of 2^20 blocks per data unit as specified by
+     * IEEE Std 1619-2018.  The earlier and obsolete IEEE Std 1619-2007
+     * indicated that this was a SHOULD NOT rather than a MUST NOT.
+     * NIST SP 800-38E mandates the same limit.
+     */
+    if (len > XTS_MAX_BLOCKS_PER_DATA_UNIT * AES_BLOCK_SIZE) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_XTS_DATA_UNIT_IS_TOO_LARGE);
+        return 0;
+    }
+
+    if (xctx->stream)
+        (*xctx->stream)(in, out, len,
+            xctx->xts.key1, xctx->xts.key2,
+            ctx->iv);
+    else if (CRYPTO_xts128_encrypt(&xctx->xts, ctx->iv, in, out, len,
+                 EVP_CIPHER_CTX_is_encrypting(ctx)))
+        return 0;
+    return 1;
+}
+
+#define aes_xts_cleanup NULL
 
 #define XTS_FLAGS (EVP_CIPH_FLAG_DEFAULT_ASN1 | EVP_CIPH_CUSTOM_IV \
     | EVP_CIPH_ALWAYS_CALL_INIT | EVP_CIPH_CTRL_INIT               \
     | EVP_CIPH_CUSTOM_COPY)
 
 BLOCK_CIPHER_custom(NID_aes, 128, 1, 16, xts, XTS, XTS_FLAGS)
-BLOCK_CIPHER_custom(NID_aes, 256, 1, 16, xts, XTS, XTS_FLAGS)
+    BLOCK_CIPHER_custom(NID_aes, 256, 1, 16, xts, XTS, XTS_FLAGS)
+
+        static int aes_ccm_ctrl(EVP_CIPHER_CTX *c, int type, int arg, void *ptr)
+{
+    EVP_AES_CCM_CTX *cctx = EVP_C_DATA(EVP_AES_CCM_CTX, c);
+    switch (type) {
+    case EVP_CTRL_INIT:
+        cctx->key_set = 0;
+        cctx->iv_set = 0;
+        cctx->L = 8;
+        cctx->M = 12;
+        cctx->tag_set = 0;
+        cctx->len_set = 0;
+        cctx->tls_aad_len = -1;
+        return 1;
+
+    case EVP_CTRL_GET_IVLEN:
+        *(int *)ptr = 15 - cctx->L;
+        return 1;
+
+    case EVP_CTRL_AEAD_TLS1_AAD:
+        /* Save the AAD for later use */
+        if (arg != EVP_AEAD_TLS1_AAD_LEN)
+            return 0;
+        memcpy(EVP_CIPHER_CTX_buf_noconst(c), ptr, arg);
+        cctx->tls_aad_len = arg;
+        {
+            uint16_t len = EVP_CIPHER_CTX_buf_noconst(c)[arg - 2] << 8
+                | EVP_CIPHER_CTX_buf_noconst(c)[arg - 1];
+            /* Correct length for explicit IV */
+            if (len < EVP_CCM_TLS_EXPLICIT_IV_LEN)
+                return 0;
+            len -= EVP_CCM_TLS_EXPLICIT_IV_LEN;
+            /* If decrypting correct for tag too */
+            if (!EVP_CIPHER_CTX_is_encrypting(c)) {
+                if (len < cctx->M)
+                    return 0;
+                len -= cctx->M;
+            }
+            EVP_CIPHER_CTX_buf_noconst(c)[arg - 2] = len >> 8;
+            EVP_CIPHER_CTX_buf_noconst(c)[arg - 1] = len & 0xff;
+        }
+        /* Extra padding: tag appended to record */
+        return cctx->M;
+
+    case EVP_CTRL_CCM_SET_IV_FIXED:
+        /* Sanity check length */
+        if (arg != EVP_CCM_TLS_FIXED_IV_LEN)
+            return 0;
+        /* Just copy to first part of IV */
+        memcpy(c->iv, ptr, arg);
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_IVLEN:
+        arg = 15 - arg;
+        /* fall through */
+    case EVP_CTRL_CCM_SET_L:
+        if (arg < 2 || arg > 8)
+            return 0;
+        cctx->L = arg;
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_TAG:
+        if ((arg & 1) || arg < 4 || arg > 16)
+            return 0;
+        if (EVP_CIPHER_CTX_is_encrypting(c) && ptr)
+            return 0;
+        if (ptr) {
+            cctx->tag_set = 1;
+            memcpy(EVP_CIPHER_CTX_buf_noconst(c), ptr, arg);
+        }
+        cctx->M = arg;
+        return 1;
+
+    case EVP_CTRL_AEAD_GET_TAG:
+        if (!EVP_CIPHER_CTX_is_encrypting(c) || !cctx->tag_set)
+            return 0;
+        if (!CRYPTO_ccm128_tag(&cctx->ccm, ptr, (size_t)arg))
+            return 0;
+        cctx->tag_set = 0;
+        cctx->iv_set = 0;
+        cctx->len_set = 0;
+        return 1;
+
+    case EVP_CTRL_COPY: {
+        EVP_CIPHER_CTX *out = ptr;
+        EVP_AES_CCM_CTX *cctx_out = EVP_C_DATA(EVP_AES_CCM_CTX, out);
+        if (cctx->ccm.key) {
+            if (cctx->ccm.key != &cctx->ks)
+                return 0;
+            cctx_out->ccm.key = &cctx_out->ks;
+        }
+        return 1;
+    }
+
+    default:
+        return -1;
+    }
+}
+
+static int aes_ccm_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    EVP_AES_CCM_CTX *cctx = EVP_C_DATA(EVP_AES_CCM_CTX, ctx);
+
+    if (iv == NULL && key == NULL)
+        return 1;
+
+    if (key != NULL) {
+        const int keylen = EVP_CIPHER_CTX_get_key_length(ctx) * 8;
+
+        if (keylen <= 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+            return 0;
+        }
+        do {
+#ifdef HWAES_CAPABLE
+            if (HWAES_CAPABLE) {
+                HWAES_set_encrypt_key(key, keylen, &cctx->ks.ks);
+
+                CRYPTO_ccm128_init(&cctx->ccm, cctx->M, cctx->L,
+                    &cctx->ks, (block128_f)HWAES_encrypt);
+                cctx->str = NULL;
+                cctx->key_set = 1;
+                break;
+            } else
+#endif
+#ifdef VPAES_CAPABLE
+                if (VPAES_CAPABLE) {
+                vpaes_set_encrypt_key(key, keylen, &cctx->ks.ks);
+                CRYPTO_ccm128_init(&cctx->ccm, cctx->M, cctx->L,
+                    &cctx->ks, (block128_f)vpaes_encrypt);
+                cctx->str = NULL;
+                cctx->key_set = 1;
+                break;
+            }
+#endif
+            AES_set_encrypt_key(key, keylen, &cctx->ks.ks);
+            CRYPTO_ccm128_init(&cctx->ccm, cctx->M, cctx->L,
+                &cctx->ks, (block128_f)AES_encrypt);
+            cctx->str = NULL;
+            cctx->key_set = 1;
+        } while (0);
+    }
+    if (iv != NULL) {
+        memcpy(ctx->iv, iv, 15 - cctx->L);
+        cctx->iv_set = 1;
+    }
+    return 1;
+}
+
+static int aes_ccm_tls_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_AES_CCM_CTX *cctx = EVP_C_DATA(EVP_AES_CCM_CTX, ctx);
+    CCM128_CONTEXT *ccm = &cctx->ccm;
+    /* Encrypt/decrypt must be performed in place */
+    if (out != in || len < (EVP_CCM_TLS_EXPLICIT_IV_LEN + (size_t)cctx->M))
+        return -1;
+    /* If encrypting set explicit IV from sequence number (start of AAD) */
+    if (EVP_CIPHER_CTX_is_encrypting(ctx))
+        memcpy(out, EVP_CIPHER_CTX_buf_noconst(ctx),
+            EVP_CCM_TLS_EXPLICIT_IV_LEN);
+    /* Get rest of IV from explicit IV */
+    memcpy(ctx->iv + EVP_CCM_TLS_FIXED_IV_LEN, in,
+        EVP_CCM_TLS_EXPLICIT_IV_LEN);
+    /* Correct length value */
+    len -= EVP_CCM_TLS_EXPLICIT_IV_LEN + cctx->M;
+    if (CRYPTO_ccm128_setiv(ccm, ctx->iv, 15 - cctx->L,
+            len))
+        return -1;
+    /* Use saved AAD */
+    CRYPTO_ccm128_aad(ccm, EVP_CIPHER_CTX_buf_noconst(ctx),
+        cctx->tls_aad_len);
+    /* Fix buffer to point to payload */
+    in += EVP_CCM_TLS_EXPLICIT_IV_LEN;
+    out += EVP_CCM_TLS_EXPLICIT_IV_LEN;
+    if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+        if (cctx->str ? CRYPTO_ccm128_encrypt_ccm64(ccm, in, out, len,
+                            cctx->str)
+                      : CRYPTO_ccm128_encrypt(ccm, in, out, len))
+            return -1;
+        if (!CRYPTO_ccm128_tag(ccm, out + len, cctx->M))
+            return -1;
+        return (int)(len + EVP_CCM_TLS_EXPLICIT_IV_LEN + cctx->M);
+    } else {
+        if (cctx->str ? !CRYPTO_ccm128_decrypt_ccm64(ccm, in, out, len,
+                            cctx->str)
+                      : !CRYPTO_ccm128_decrypt(ccm, in, out, len)) {
+            unsigned char tag[16];
+            if (CRYPTO_ccm128_tag(ccm, tag, cctx->M)) {
+                if (!CRYPTO_memcmp(tag, in + len, cctx->M))
+                    return (int)len;
+            }
+        }
+        OPENSSL_cleanse(out, len);
+        return -1;
+    }
+}
+
+static int aes_ccm_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_AES_CCM_CTX *cctx = EVP_C_DATA(EVP_AES_CCM_CTX, ctx);
+    CCM128_CONTEXT *ccm = &cctx->ccm;
+    /* If not set up, return error */
+    if (!cctx->key_set)
+        return -1;
+
+    if (cctx->tls_aad_len >= 0)
+        return aes_ccm_tls_cipher(ctx, out, in, len);
+
+    /* EVP_*Final() doesn't return any data */
+    if (in == NULL && out != NULL)
+        return 0;
+
+    if (!cctx->iv_set)
+        return -1;
+
+    if (!out) {
+        if (!in) {
+            if (CRYPTO_ccm128_setiv(ccm, ctx->iv,
+                    15 - cctx->L, len))
+                return -1;
+            cctx->len_set = 1;
+            return (int)len;
+        }
+        /* If have AAD need message length */
+        if (!cctx->len_set && len)
+            return -1;
+        CRYPTO_ccm128_aad(ccm, in, len);
+        return (int)len;
+    }
+
+    /* The tag must be set before actually decrypting data */
+    if (!EVP_CIPHER_CTX_is_encrypting(ctx) && !cctx->tag_set)
+        return -1;
+
+    /* If not set length yet do it */
+    if (!cctx->len_set) {
+        if (CRYPTO_ccm128_setiv(ccm, ctx->iv, 15 - cctx->L, len))
+            return -1;
+        cctx->len_set = 1;
+    }
+    if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+        if (cctx->str ? CRYPTO_ccm128_encrypt_ccm64(ccm, in, out, len,
+                            cctx->str)
+                      : CRYPTO_ccm128_encrypt(ccm, in, out, len))
+            return -1;
+        cctx->tag_set = 1;
+        return (int)len;
+    } else {
+        int rv = -1;
+        if (cctx->str ? !CRYPTO_ccm128_decrypt_ccm64(ccm, in, out, len,
+                            cctx->str)
+                      : !CRYPTO_ccm128_decrypt(ccm, in, out, len)) {
+            unsigned char tag[16];
+            if (CRYPTO_ccm128_tag(ccm, tag, cctx->M)) {
+                if (!CRYPTO_memcmp(tag, EVP_CIPHER_CTX_buf_noconst(ctx),
+                        cctx->M))
+                    rv = (int)len;
+            }
+        }
+        if (rv == -1)
+            OPENSSL_cleanse(out, len);
+        cctx->iv_set = 0;
+        cctx->tag_set = 0;
+        cctx->len_set = 0;
+        return rv;
+    }
+}
+
+#define aes_ccm_cleanup NULL
 
 BLOCK_CIPHER_custom(NID_aes, 128, 1, 12, ccm, CCM,
     EVP_CIPH_FLAG_AEAD_CIPHER | CUSTOM_FLAGS)
-BLOCK_CIPHER_custom(NID_aes, 192, 1, 12, ccm, CCM,
-    EVP_CIPH_FLAG_AEAD_CIPHER | CUSTOM_FLAGS)
-BLOCK_CIPHER_custom(NID_aes, 256, 1, 12, ccm, CCM,
-    EVP_CIPH_FLAG_AEAD_CIPHER | CUSTOM_FLAGS)
+    BLOCK_CIPHER_custom(NID_aes, 192, 1, 12, ccm, CCM,
+        EVP_CIPH_FLAG_AEAD_CIPHER | CUSTOM_FLAGS)
+        BLOCK_CIPHER_custom(NID_aes, 256, 1, 12, ccm, CCM,
+            EVP_CIPH_FLAG_AEAD_CIPHER | CUSTOM_FLAGS)
+
+            typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        AES_KEY ks;
+    } ks;
+    /* Indicates if IV has been set */
+    unsigned char *iv;
+} EVP_AES_WRAP_CTX;
+
+static int aes_wrap_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    int len;
+    EVP_AES_WRAP_CTX *wctx = EVP_C_DATA(EVP_AES_WRAP_CTX, ctx);
+
+    if (iv == NULL && key == NULL)
+        return 1;
+    if (key != NULL) {
+        const int keylen = EVP_CIPHER_CTX_get_key_length(ctx) * 8;
+
+        if (keylen <= 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+            return 0;
+        }
+        if (EVP_CIPHER_CTX_is_encrypting(ctx))
+            AES_set_encrypt_key(key, keylen, &wctx->ks.ks);
+        else
+            AES_set_decrypt_key(key, keylen, &wctx->ks.ks);
+        if (iv == NULL)
+            wctx->iv = NULL;
+    }
+    if (iv != NULL) {
+        if ((len = EVP_CIPHER_CTX_get_iv_length(ctx)) < 0)
+            return 0;
+        memcpy(ctx->iv, iv, len);
+        wctx->iv = ctx->iv;
+    }
+    return 1;
+}
+
+static int aes_wrap_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inlen)
+{
+    EVP_AES_WRAP_CTX *wctx = EVP_C_DATA(EVP_AES_WRAP_CTX, ctx);
+    size_t rv;
+    /* AES wrap with padding has IV length of 4, without padding 8 */
+    int pad = EVP_CIPHER_CTX_get_iv_length(ctx) == 4;
+    /* No final operation so always return zero length */
+    if (!in)
+        return 0;
+    /* Input length must always be non-zero */
+    if (!inlen)
+        return -1;
+    /* If decrypting need at least 16 bytes and multiple of 8 */
+    if (!EVP_CIPHER_CTX_is_encrypting(ctx) && (inlen < 16 || inlen & 0x7))
+        return -1;
+    /* If not padding input must be multiple of 8 */
+    if (!pad && inlen & 0x7)
+        return -1;
+    if (ossl_is_partially_overlapping(out, in, (int)inlen)) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_PARTIALLY_OVERLAPPING);
+        return 0;
+    }
+    if (!out) {
+        if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+            /* If padding round up to multiple of 8 */
+            if (pad)
+                inlen = (inlen + 7) / 8 * 8;
+            /* 8 byte prefix */
+            return (int)(inlen + 8);
+        } else {
+            /*
+             * If not padding output will be exactly 8 bytes smaller than
+             * input. If padding it will be at least 8 bytes smaller but we
+             * don't know how much.
+             */
+            return (int)(inlen - 8);
+        }
+    }
+    if (pad) {
+        if (EVP_CIPHER_CTX_is_encrypting(ctx))
+            rv = CRYPTO_128_wrap_pad(&wctx->ks.ks, wctx->iv,
+                out, in, inlen,
+                (block128_f)AES_encrypt);
+        else
+            rv = CRYPTO_128_unwrap_pad(&wctx->ks.ks, wctx->iv,
+                out, in, inlen,
+                (block128_f)AES_decrypt);
+    } else {
+        if (EVP_CIPHER_CTX_is_encrypting(ctx))
+            rv = CRYPTO_128_wrap(&wctx->ks.ks, wctx->iv,
+                out, in, inlen, (block128_f)AES_encrypt);
+        else
+            rv = CRYPTO_128_unwrap(&wctx->ks.ks, wctx->iv,
+                out, in, inlen, (block128_f)AES_decrypt);
+    }
+    return rv ? (int)rv : -1;
+}
 
 #define WRAP_FLAGS (EVP_CIPH_WRAP_MODE                 \
     | EVP_CIPH_CUSTOM_IV | EVP_CIPH_FLAG_CUSTOM_CIPHER \
@@ -82,7 +3764,11 @@ BLOCK_CIPHER_custom(NID_aes, 256, 1, 12, ccm, CCM,
 
 static const EVP_CIPHER aes_128_wrap = {
     NID_id_aes128_wrap,
-    8, 16, 8, WRAP_FLAGS, EVP_ORIG_GLOBAL
+    8, 16, 8, WRAP_FLAGS, EVP_ORIG_GLOBAL,
+    aes_wrap_init_key, aes_wrap_cipher,
+    NULL,
+    sizeof(EVP_AES_WRAP_CTX),
+    NULL, NULL, NULL, NULL
 };
 
 const EVP_CIPHER *EVP_aes_128_wrap(void)
@@ -92,7 +3778,11 @@ const EVP_CIPHER *EVP_aes_128_wrap(void)
 
 static const EVP_CIPHER aes_192_wrap = {
     NID_id_aes192_wrap,
-    8, 24, 8, WRAP_FLAGS, EVP_ORIG_GLOBAL
+    8, 24, 8, WRAP_FLAGS, EVP_ORIG_GLOBAL,
+    aes_wrap_init_key, aes_wrap_cipher,
+    NULL,
+    sizeof(EVP_AES_WRAP_CTX),
+    NULL, NULL, NULL, NULL
 };
 
 const EVP_CIPHER *EVP_aes_192_wrap(void)
@@ -102,7 +3792,11 @@ const EVP_CIPHER *EVP_aes_192_wrap(void)
 
 static const EVP_CIPHER aes_256_wrap = {
     NID_id_aes256_wrap,
-    8, 32, 8, WRAP_FLAGS, EVP_ORIG_GLOBAL
+    8, 32, 8, WRAP_FLAGS, EVP_ORIG_GLOBAL,
+    aes_wrap_init_key, aes_wrap_cipher,
+    NULL,
+    sizeof(EVP_AES_WRAP_CTX),
+    NULL, NULL, NULL, NULL
 };
 
 const EVP_CIPHER *EVP_aes_256_wrap(void)
@@ -112,7 +3806,11 @@ const EVP_CIPHER *EVP_aes_256_wrap(void)
 
 static const EVP_CIPHER aes_128_wrap_pad = {
     NID_id_aes128_wrap_pad,
-    8, 16, 4, WRAP_FLAGS, EVP_ORIG_GLOBAL
+    8, 16, 4, WRAP_FLAGS, EVP_ORIG_GLOBAL,
+    aes_wrap_init_key, aes_wrap_cipher,
+    NULL,
+    sizeof(EVP_AES_WRAP_CTX),
+    NULL, NULL, NULL, NULL
 };
 
 const EVP_CIPHER *EVP_aes_128_wrap_pad(void)
@@ -122,7 +3820,11 @@ const EVP_CIPHER *EVP_aes_128_wrap_pad(void)
 
 static const EVP_CIPHER aes_192_wrap_pad = {
     NID_id_aes192_wrap_pad,
-    8, 24, 4, WRAP_FLAGS, EVP_ORIG_GLOBAL
+    8, 24, 4, WRAP_FLAGS, EVP_ORIG_GLOBAL,
+    aes_wrap_init_key, aes_wrap_cipher,
+    NULL,
+    sizeof(EVP_AES_WRAP_CTX),
+    NULL, NULL, NULL, NULL
 };
 
 const EVP_CIPHER *EVP_aes_192_wrap_pad(void)
@@ -132,7 +3834,11 @@ const EVP_CIPHER *EVP_aes_192_wrap_pad(void)
 
 static const EVP_CIPHER aes_256_wrap_pad = {
     NID_id_aes256_wrap_pad,
-    8, 32, 4, WRAP_FLAGS, EVP_ORIG_GLOBAL
+    8, 32, 4, WRAP_FLAGS, EVP_ORIG_GLOBAL,
+    aes_wrap_init_key, aes_wrap_cipher,
+    NULL,
+    sizeof(EVP_AES_WRAP_CTX),
+    NULL, NULL, NULL, NULL
 };
 
 const EVP_CIPHER *EVP_aes_256_wrap_pad(void)
@@ -141,10 +3847,307 @@ const EVP_CIPHER *EVP_aes_256_wrap_pad(void)
 }
 
 #ifndef OPENSSL_NO_OCB
+static int aes_ocb_ctrl(EVP_CIPHER_CTX *c, int type, int arg, void *ptr)
+{
+    EVP_AES_OCB_CTX *octx = EVP_C_DATA(EVP_AES_OCB_CTX, c);
+    EVP_CIPHER_CTX *newc;
+    EVP_AES_OCB_CTX *new_octx;
+
+    switch (type) {
+    case EVP_CTRL_INIT:
+        octx->key_set = 0;
+        octx->iv_set = 0;
+        octx->ivlen = EVP_CIPHER_get_iv_length(c->cipher);
+        octx->iv = c->iv;
+        octx->taglen = 16;
+        octx->data_buf_len = 0;
+        octx->aad_buf_len = 0;
+        return 1;
+
+    case EVP_CTRL_GET_IVLEN:
+        *(int *)ptr = octx->ivlen;
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_IVLEN:
+        /* IV len must be 1 to 15 */
+        if (arg <= 0 || arg > 15)
+            return 0;
+
+        octx->ivlen = arg;
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_TAG:
+        if (ptr == NULL) {
+            /* Tag len must be 0 to 16 */
+            if (arg < 0 || arg > 16)
+                return 0;
+
+            octx->taglen = arg;
+            return 1;
+        }
+        if (arg != octx->taglen || EVP_CIPHER_CTX_is_encrypting(c))
+            return 0;
+        memcpy(octx->tag, ptr, arg);
+        return 1;
+
+    case EVP_CTRL_AEAD_GET_TAG:
+        if (arg != octx->taglen || !EVP_CIPHER_CTX_is_encrypting(c))
+            return 0;
+
+        memcpy(ptr, octx->tag, arg);
+        return 1;
+
+    case EVP_CTRL_COPY:
+        newc = (EVP_CIPHER_CTX *)ptr;
+        new_octx = EVP_C_DATA(EVP_AES_OCB_CTX, newc);
+        return CRYPTO_ocb128_copy_ctx(&new_octx->ocb, &octx->ocb,
+            &new_octx->ksenc.ks,
+            &new_octx->ksdec.ks);
+
+    default:
+        return -1;
+    }
+}
+
+static int aes_ocb_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    EVP_AES_OCB_CTX *octx = EVP_C_DATA(EVP_AES_OCB_CTX, ctx);
+
+    if (iv == NULL && key == NULL)
+        return 1;
+
+    if (key != NULL) {
+        const int keylen = EVP_CIPHER_CTX_get_key_length(ctx) * 8;
+
+        if (keylen <= 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+            return 0;
+        }
+        do {
+            /*
+             * We set both the encrypt and decrypt key here because decrypt
+             * needs both. We could possibly optimise to remove setting the
+             * decrypt for an encryption operation.
+             */
+#ifdef HWAES_CAPABLE
+            if (HWAES_CAPABLE) {
+                HWAES_set_encrypt_key(key, keylen, &octx->ksenc.ks);
+                HWAES_set_decrypt_key(key, keylen, &octx->ksdec.ks);
+                if (!CRYPTO_ocb128_init(&octx->ocb,
+                        &octx->ksenc.ks, &octx->ksdec.ks,
+                        (block128_f)HWAES_encrypt,
+                        (block128_f)HWAES_decrypt,
+                        enc ? HWAES_ocb_encrypt
+                            : HWAES_ocb_decrypt))
+                    return 0;
+                break;
+            }
+#endif
+#ifdef VPAES_CAPABLE
+            if (VPAES_CAPABLE) {
+                vpaes_set_encrypt_key(key, keylen, &octx->ksenc.ks);
+                vpaes_set_decrypt_key(key, keylen, &octx->ksdec.ks);
+                if (!CRYPTO_ocb128_init(&octx->ocb,
+                        &octx->ksenc.ks, &octx->ksdec.ks,
+                        (block128_f)vpaes_encrypt,
+                        (block128_f)vpaes_decrypt,
+                        NULL))
+                    return 0;
+                break;
+            }
+#endif
+            AES_set_encrypt_key(key, keylen, &octx->ksenc.ks);
+            AES_set_decrypt_key(key, keylen, &octx->ksdec.ks);
+            if (!CRYPTO_ocb128_init(&octx->ocb,
+                    &octx->ksenc.ks, &octx->ksdec.ks,
+                    (block128_f)AES_encrypt,
+                    (block128_f)AES_decrypt,
+                    NULL))
+                return 0;
+        } while (0);
+
+        /*
+         * If we have an iv we can set it directly, otherwise use saved IV.
+         */
+        if (iv == NULL && octx->iv_set)
+            iv = octx->iv;
+        if (iv) {
+            if (CRYPTO_ocb128_setiv(&octx->ocb, iv, octx->ivlen, octx->taglen)
+                != 1)
+                return 0;
+            octx->iv_set = 1;
+        }
+        octx->key_set = 1;
+    } else {
+        /* If key set use IV, otherwise copy */
+        if (octx->key_set)
+            CRYPTO_ocb128_setiv(&octx->ocb, iv, octx->ivlen, octx->taglen);
+        else
+            memcpy(octx->iv, iv, octx->ivlen);
+        octx->iv_set = 1;
+    }
+    return 1;
+}
+
+static int aes_ocb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    unsigned char *buf;
+    int *buf_len;
+    int written_len = 0;
+    size_t trailing_len;
+    EVP_AES_OCB_CTX *octx = EVP_C_DATA(EVP_AES_OCB_CTX, ctx);
+
+    /* If IV or Key not set then return error */
+    if (!octx->iv_set)
+        return -1;
+
+    if (!octx->key_set)
+        return -1;
+
+    if (in != NULL) {
+        /*
+         * Need to ensure we are only passing full blocks to low-level OCB
+         * routines. We do it here rather than in EVP_EncryptUpdate/
+         * EVP_DecryptUpdate because we need to pass full blocks of AAD too
+         * and those routines don't support that
+         */
+
+        /* Are we dealing with AAD or normal data here? */
+        if (out == NULL) {
+            buf = octx->aad_buf;
+            buf_len = &(octx->aad_buf_len);
+        } else {
+            buf = octx->data_buf;
+            buf_len = &(octx->data_buf_len);
+
+            if (ossl_is_partially_overlapping(out + *buf_len, in, (int)len)) {
+                ERR_raise(ERR_LIB_EVP, EVP_R_PARTIALLY_OVERLAPPING);
+                return 0;
+            }
+        }
+
+        /*
+         * If we've got a partially filled buffer from a previous call then
+         * use that data first
+         */
+        if (*buf_len > 0) {
+            unsigned int remaining;
+
+            remaining = AES_BLOCK_SIZE - (*buf_len);
+            if (remaining > len) {
+                memcpy(buf + (*buf_len), in, len);
+                *(buf_len) += (int)len;
+                return 0;
+            }
+            memcpy(buf + (*buf_len), in, remaining);
+
+            /*
+             * If we get here we've filled the buffer, so process it
+             */
+            len -= remaining;
+            in += remaining;
+            if (out == NULL) {
+                if (!CRYPTO_ocb128_aad(&octx->ocb, buf, AES_BLOCK_SIZE))
+                    return -1;
+            } else if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+                if (!CRYPTO_ocb128_encrypt(&octx->ocb, buf, out,
+                        AES_BLOCK_SIZE))
+                    return -1;
+            } else {
+                if (!CRYPTO_ocb128_decrypt(&octx->ocb, buf, out,
+                        AES_BLOCK_SIZE))
+                    return -1;
+            }
+            written_len = AES_BLOCK_SIZE;
+            *buf_len = 0;
+            if (out != NULL)
+                out += AES_BLOCK_SIZE;
+        }
+
+        /* Do we have a partial block to handle at the end? */
+        trailing_len = len % AES_BLOCK_SIZE;
+
+        /*
+         * If we've got some full blocks to handle, then process these first
+         */
+        if (len != trailing_len) {
+            if (out == NULL) {
+                if (!CRYPTO_ocb128_aad(&octx->ocb, in, len - trailing_len))
+                    return -1;
+            } else if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+                if (!CRYPTO_ocb128_encrypt(&octx->ocb, in, out, len - trailing_len))
+                    return -1;
+            } else {
+                if (!CRYPTO_ocb128_decrypt(&octx->ocb, in, out, len - trailing_len))
+                    return -1;
+            }
+            written_len += (int)(len - trailing_len);
+            in += len - trailing_len;
+        }
+
+        /* Handle any trailing partial block */
+        if (trailing_len > 0) {
+            memcpy(buf, in, trailing_len);
+            *buf_len = (int)trailing_len;
+        }
+
+        return written_len;
+    } else {
+        /*
+         * First of all empty the buffer of any partial block that we might
+         * have been provided - both for data and AAD
+         */
+        if (octx->data_buf_len > 0) {
+            if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+                if (!CRYPTO_ocb128_encrypt(&octx->ocb, octx->data_buf, out,
+                        octx->data_buf_len))
+                    return -1;
+            } else {
+                if (!CRYPTO_ocb128_decrypt(&octx->ocb, octx->data_buf, out,
+                        octx->data_buf_len))
+                    return -1;
+            }
+            written_len = octx->data_buf_len;
+            octx->data_buf_len = 0;
+        }
+        if (octx->aad_buf_len > 0) {
+            if (!CRYPTO_ocb128_aad(&octx->ocb, octx->aad_buf, octx->aad_buf_len))
+                return -1;
+            octx->aad_buf_len = 0;
+        }
+        /* If decrypting then verify */
+        if (!EVP_CIPHER_CTX_is_encrypting(ctx)) {
+            if (octx->taglen < 0)
+                return -1;
+            if (CRYPTO_ocb128_finish(&octx->ocb,
+                    octx->tag, octx->taglen)
+                != 0)
+                return -1;
+            octx->iv_set = 0;
+            return written_len;
+        }
+        /* If encrypting then just get the tag */
+        if (CRYPTO_ocb128_tag(&octx->ocb, octx->tag, 16) != 1)
+            return -1;
+        /* Don't reuse the IV */
+        octx->iv_set = 0;
+        return written_len;
+    }
+}
+
+static int aes_ocb_cleanup(EVP_CIPHER_CTX *c)
+{
+    EVP_AES_OCB_CTX *octx = EVP_C_DATA(EVP_AES_OCB_CTX, c);
+    CRYPTO_ocb128_cleanup(&octx->ocb);
+    return 1;
+}
+
 BLOCK_CIPHER_custom(NID_aes, 128, 16, 12, ocb, OCB,
     EVP_CIPH_FLAG_AEAD_CIPHER | CUSTOM_FLAGS)
-BLOCK_CIPHER_custom(NID_aes, 192, 16, 12, ocb, OCB,
-    EVP_CIPH_FLAG_AEAD_CIPHER | CUSTOM_FLAGS)
-BLOCK_CIPHER_custom(NID_aes, 256, 16, 12, ocb, OCB,
-    EVP_CIPH_FLAG_AEAD_CIPHER | CUSTOM_FLAGS)
+    BLOCK_CIPHER_custom(NID_aes, 192, 16, 12, ocb, OCB,
+        EVP_CIPH_FLAG_AEAD_CIPHER | CUSTOM_FLAGS)
+        BLOCK_CIPHER_custom(NID_aes, 256, 16, 12, ocb, OCB,
+            EVP_CIPH_FLAG_AEAD_CIPHER | CUSTOM_FLAGS)
 #endif /* OPENSSL_NO_OCB */
diff --git a/crypto/evp/e_aes_cbc_hmac_sha1.c b/crypto/evp/e_aes_cbc_hmac_sha1.c
index b7c86b3802..6e914ef096 100644
--- a/crypto/evp/e_aes_cbc_hmac_sha1.c
+++ b/crypto/evp/e_aes_cbc_hmac_sha1.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2011-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2011-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,14 +7,894 @@
  * https://www.openssl.org/source/license.html
  */
 
+/*
+ * AES low level APIs are deprecated for public use, but still ok for internal
+ * use where we're using them to implement the higher level EVP interface, as is
+ * the case here.
+ */
+#include "internal/deprecated.h"
+
+#include 
+#include 
+#include 
+#include 
+#include 
 #include 
+#include 
+#include 
 #include "internal/cryptlib.h"
+#include "crypto/modes.h"
 #include "crypto/evp.h"
+#include "internal/constant_time.h"
+#include "evp_local.h"
+
+typedef struct {
+    AES_KEY ks;
+    SHA_CTX head, tail, md;
+    size_t payload_length; /* AAD length in decrypt case */
+    union {
+        unsigned int tls_ver;
+        unsigned char tls_aad[16]; /* 13 used */
+    } aux;
+} EVP_AES_HMAC_SHA1;
+
+#define NO_PAYLOAD_LENGTH ((size_t)-1)
 
 #if defined(AES_ASM) && (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64))
 
 #define AESNI_CAPABLE (1 << (57 - 32))
 
+int aesni_set_encrypt_key(const unsigned char *userKey, int bits,
+    AES_KEY *key);
+int aesni_set_decrypt_key(const unsigned char *userKey, int bits,
+    AES_KEY *key);
+
+void aesni_cbc_encrypt(const unsigned char *in,
+    unsigned char *out,
+    size_t length,
+    const AES_KEY *key, unsigned char *ivec, int enc);
+
+void aesni_cbc_sha1_enc(const void *inp, void *out, size_t blocks,
+    const AES_KEY *key, unsigned char iv[16],
+    SHA_CTX *ctx, const void *in0);
+
+void aesni256_cbc_sha1_dec(const void *inp, void *out, size_t blocks,
+    const AES_KEY *key, unsigned char iv[16],
+    SHA_CTX *ctx, const void *in0);
+
+#define data(ctx) ((EVP_AES_HMAC_SHA1 *)EVP_CIPHER_CTX_get_cipher_data(ctx))
+
+static int aesni_cbc_hmac_sha1_init_key(EVP_CIPHER_CTX *ctx,
+    const unsigned char *inkey,
+    const unsigned char *iv, int enc)
+{
+    EVP_AES_HMAC_SHA1 *key = data(ctx);
+    int ret;
+    const int keylen = EVP_CIPHER_CTX_get_key_length(ctx) * 8;
+
+    if (keylen <= 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+        return 0;
+    }
+    if (enc)
+        ret = aesni_set_encrypt_key(inkey, keylen, &key->ks);
+    else
+        ret = aesni_set_decrypt_key(inkey, keylen, &key->ks);
+
+    SHA1_Init(&key->head); /* handy when benchmarking */
+    key->tail = key->head;
+    key->md = key->head;
+
+    key->payload_length = NO_PAYLOAD_LENGTH;
+
+    return ret < 0 ? 0 : 1;
+}
+
+#define STITCHED_CALL
+#undef STITCHED_DECRYPT_CALL
+
+#if !defined(STITCHED_CALL)
+#define aes_off 0
+#endif
+
+void sha1_block_data_order(void *c, const void *p, size_t len);
+
+static void sha1_update(SHA_CTX *c, const void *data, size_t len)
+{
+    const unsigned char *ptr = data;
+    size_t res;
+
+    if ((res = c->num)) {
+        res = SHA_CBLOCK - res;
+        if (len < res)
+            res = len;
+        SHA1_Update(c, ptr, res);
+        ptr += res;
+        len -= res;
+    }
+
+    res = len % SHA_CBLOCK;
+    len -= res;
+
+    if (len) {
+        sha1_block_data_order(c, ptr, len / SHA_CBLOCK);
+
+        ptr += len;
+        c->Nh += (unsigned int)(len >> 29);
+        c->Nl += (unsigned int)(len <<= 3);
+        if (c->Nl < (unsigned int)len)
+            c->Nh++;
+    }
+
+    if (res)
+        SHA1_Update(c, ptr, res);
+}
+
+#ifdef SHA1_Update
+#undef SHA1_Update
+#endif
+#define SHA1_Update sha1_update
+
+#if !defined(OPENSSL_NO_MULTIBLOCK)
+
+typedef struct {
+    unsigned int A[8], B[8], C[8], D[8], E[8];
+} SHA1_MB_CTX;
+typedef struct {
+    const unsigned char *ptr;
+    int blocks;
+} HASH_DESC;
+
+void sha1_multi_block(SHA1_MB_CTX *, const HASH_DESC *, int);
+
+typedef struct {
+    const unsigned char *inp;
+    unsigned char *out;
+    int blocks;
+    u64 iv[2];
+} CIPH_DESC;
+
+void aesni_multi_cbc_encrypt(CIPH_DESC *, void *, int);
+
+static size_t tls1_1_multi_block_encrypt(EVP_AES_HMAC_SHA1 *key,
+    unsigned char *out,
+    const unsigned char *inp,
+    size_t inp_len, int n4x)
+{ /* n4x is 1 or 2 */
+    HASH_DESC hash_d[8], edges[8];
+    CIPH_DESC ciph_d[8];
+    unsigned char storage[sizeof(SHA1_MB_CTX) + 32];
+    union {
+        u64 q[16];
+        u32 d[32];
+        u8 c[128];
+    } blocks[8];
+    SHA1_MB_CTX *ctx;
+    unsigned int frag, last, packlen, i, x4 = 4 * n4x, minblocks, processed = 0;
+    size_t ret = 0;
+    u8 *IVs;
+#if defined(BSWAP8)
+    u64 seqnum;
+#endif
+
+    /* ask for IVs in bulk */
+    if (RAND_bytes((IVs = blocks[0].c), 16 * x4) <= 0)
+        return 0;
+
+    ctx = (SHA1_MB_CTX *)(storage + 32 - ((size_t)storage % 32)); /* align */
+
+    frag = (unsigned int)inp_len >> (1 + n4x);
+    last = (unsigned int)inp_len + frag - (frag << (1 + n4x));
+    if (last > frag && ((last + 13 + 9) % 64) < (x4 - 1)) {
+        frag++;
+        last -= x4 - 1;
+    }
+
+    packlen = 5 + 16 + ((frag + 20 + 16) & -16);
+
+    /* populate descriptors with pointers and IVs */
+    hash_d[0].ptr = inp;
+    ciph_d[0].inp = inp;
+    /* 5+16 is place for header and explicit IV */
+    ciph_d[0].out = out + 5 + 16;
+    memcpy(ciph_d[0].out - 16, IVs, 16);
+    memcpy(ciph_d[0].iv, IVs, 16);
+    IVs += 16;
+
+    for (i = 1; i < x4; i++) {
+        ciph_d[i].inp = hash_d[i].ptr = hash_d[i - 1].ptr + frag;
+        ciph_d[i].out = ciph_d[i - 1].out + packlen;
+        memcpy(ciph_d[i].out - 16, IVs, 16);
+        memcpy(ciph_d[i].iv, IVs, 16);
+        IVs += 16;
+    }
+
+#if defined(BSWAP8)
+    memcpy(blocks[0].c, key->md.data, 8);
+    seqnum = BSWAP8(blocks[0].q[0]);
+#endif
+    for (i = 0; i < x4; i++) {
+        unsigned int len = (i == (x4 - 1) ? last : frag);
+#if !defined(BSWAP8)
+        unsigned int carry, j;
+#endif
+
+        ctx->A[i] = key->md.h0;
+        ctx->B[i] = key->md.h1;
+        ctx->C[i] = key->md.h2;
+        ctx->D[i] = key->md.h3;
+        ctx->E[i] = key->md.h4;
+
+        /* fix seqnum */
+#if defined(BSWAP8)
+        blocks[i].q[0] = BSWAP8(seqnum + i);
+#else
+        for (carry = i, j = 8; j--;) {
+            blocks[i].c[j] = ((u8 *)key->md.data)[j] + carry;
+            carry = (blocks[i].c[j] - carry) >> (sizeof(carry) * 8 - 1);
+        }
+#endif
+        blocks[i].c[8] = ((u8 *)key->md.data)[8];
+        blocks[i].c[9] = ((u8 *)key->md.data)[9];
+        blocks[i].c[10] = ((u8 *)key->md.data)[10];
+        /* fix length */
+        blocks[i].c[11] = (u8)(len >> 8);
+        blocks[i].c[12] = (u8)(len);
+
+        memcpy(blocks[i].c + 13, hash_d[i].ptr, 64 - 13);
+        hash_d[i].ptr += 64 - 13;
+        hash_d[i].blocks = (len - (64 - 13)) / 64;
+
+        edges[i].ptr = blocks[i].c;
+        edges[i].blocks = 1;
+    }
+
+    /* hash 13-byte headers and first 64-13 bytes of inputs */
+    sha1_multi_block(ctx, edges, n4x);
+    /* hash bulk inputs */
+#define MAXCHUNKSIZE 2048
+#if MAXCHUNKSIZE % 64
+#error "MAXCHUNKSIZE is not divisible by 64"
+#elif MAXCHUNKSIZE
+    /*
+     * goal is to minimize pressure on L1 cache by moving in shorter steps,
+     * so that hashed data is still in the cache by the time we encrypt it
+     */
+    minblocks = ((frag <= last ? frag : last) - (64 - 13)) / 64;
+    if (minblocks > MAXCHUNKSIZE / 64) {
+        for (i = 0; i < x4; i++) {
+            edges[i].ptr = hash_d[i].ptr;
+            edges[i].blocks = MAXCHUNKSIZE / 64;
+            ciph_d[i].blocks = MAXCHUNKSIZE / 16;
+        }
+        do {
+            sha1_multi_block(ctx, edges, n4x);
+            aesni_multi_cbc_encrypt(ciph_d, &key->ks, n4x);
+
+            for (i = 0; i < x4; i++) {
+                edges[i].ptr = hash_d[i].ptr += MAXCHUNKSIZE;
+                hash_d[i].blocks -= MAXCHUNKSIZE / 64;
+                edges[i].blocks = MAXCHUNKSIZE / 64;
+                ciph_d[i].inp += MAXCHUNKSIZE;
+                ciph_d[i].out += MAXCHUNKSIZE;
+                ciph_d[i].blocks = MAXCHUNKSIZE / 16;
+                memcpy(ciph_d[i].iv, ciph_d[i].out - 16, 16);
+            }
+            processed += MAXCHUNKSIZE;
+            minblocks -= MAXCHUNKSIZE / 64;
+        } while (minblocks > MAXCHUNKSIZE / 64);
+    }
+#endif
+#undef MAXCHUNKSIZE
+    sha1_multi_block(ctx, hash_d, n4x);
+
+    memset(blocks, 0, sizeof(blocks));
+    for (i = 0; i < x4; i++) {
+        unsigned int len = (i == (x4 - 1) ? last : frag),
+                     off = hash_d[i].blocks * 64;
+        const unsigned char *ptr = hash_d[i].ptr + off;
+
+        off = (len - processed) - (64 - 13) - off; /* remainder actually */
+        memcpy(blocks[i].c, ptr, off);
+        blocks[i].c[off] = 0x80;
+        len += 64 + 13; /* 64 is HMAC header */
+        len *= 8; /* convert to bits */
+        if (off < (64 - 8)) {
+#ifdef BSWAP4
+            blocks[i].d[15] = BSWAP4(len);
+#else
+            PUTU32(blocks[i].c + 60, len);
+#endif
+            edges[i].blocks = 1;
+        } else {
+#ifdef BSWAP4
+            blocks[i].d[31] = BSWAP4(len);
+#else
+            PUTU32(blocks[i].c + 124, len);
+#endif
+            edges[i].blocks = 2;
+        }
+        edges[i].ptr = blocks[i].c;
+    }
+
+    /* hash input tails and finalize */
+    sha1_multi_block(ctx, edges, n4x);
+
+    memset(blocks, 0, sizeof(blocks));
+    for (i = 0; i < x4; i++) {
+#ifdef BSWAP4
+        blocks[i].d[0] = BSWAP4(ctx->A[i]);
+        ctx->A[i] = key->tail.h0;
+        blocks[i].d[1] = BSWAP4(ctx->B[i]);
+        ctx->B[i] = key->tail.h1;
+        blocks[i].d[2] = BSWAP4(ctx->C[i]);
+        ctx->C[i] = key->tail.h2;
+        blocks[i].d[3] = BSWAP4(ctx->D[i]);
+        ctx->D[i] = key->tail.h3;
+        blocks[i].d[4] = BSWAP4(ctx->E[i]);
+        ctx->E[i] = key->tail.h4;
+        blocks[i].c[20] = 0x80;
+        blocks[i].d[15] = BSWAP4((64 + 20) * 8);
+#else
+        PUTU32(blocks[i].c + 0, ctx->A[i]);
+        ctx->A[i] = key->tail.h0;
+        PUTU32(blocks[i].c + 4, ctx->B[i]);
+        ctx->B[i] = key->tail.h1;
+        PUTU32(blocks[i].c + 8, ctx->C[i]);
+        ctx->C[i] = key->tail.h2;
+        PUTU32(blocks[i].c + 12, ctx->D[i]);
+        ctx->D[i] = key->tail.h3;
+        PUTU32(blocks[i].c + 16, ctx->E[i]);
+        ctx->E[i] = key->tail.h4;
+        blocks[i].c[20] = 0x80;
+        PUTU32(blocks[i].c + 60, (64 + 20) * 8);
+#endif
+        edges[i].ptr = blocks[i].c;
+        edges[i].blocks = 1;
+    }
+
+    /* finalize MACs */
+    sha1_multi_block(ctx, edges, n4x);
+
+    for (i = 0; i < x4; i++) {
+        unsigned int len = (i == (x4 - 1) ? last : frag), pad, j;
+        unsigned char *out0 = out;
+
+        memcpy(ciph_d[i].out, ciph_d[i].inp, len - processed);
+        ciph_d[i].inp = ciph_d[i].out;
+
+        out += 5 + 16 + len;
+
+        /* write MAC */
+        PUTU32(out + 0, ctx->A[i]);
+        PUTU32(out + 4, ctx->B[i]);
+        PUTU32(out + 8, ctx->C[i]);
+        PUTU32(out + 12, ctx->D[i]);
+        PUTU32(out + 16, ctx->E[i]);
+        out += 20;
+        len += 20;
+
+        /* pad */
+        pad = 15 - len % 16;
+        for (j = 0; j <= pad; j++)
+            *(out++) = pad;
+        len += pad + 1;
+
+        ciph_d[i].blocks = (len - processed) / 16;
+        len += 16; /* account for explicit iv */
+
+        /* arrange header */
+        out0[0] = ((u8 *)key->md.data)[8];
+        out0[1] = ((u8 *)key->md.data)[9];
+        out0[2] = ((u8 *)key->md.data)[10];
+        out0[3] = (u8)(len >> 8);
+        out0[4] = (u8)(len);
+
+        ret += len + 5;
+        inp += frag;
+    }
+
+    aesni_multi_cbc_encrypt(ciph_d, &key->ks, n4x);
+
+    OPENSSL_cleanse(blocks, sizeof(blocks));
+    OPENSSL_cleanse(ctx, sizeof(*ctx));
+
+    return ret;
+}
+#endif
+
+static int aesni_cbc_hmac_sha1_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_AES_HMAC_SHA1 *key = data(ctx);
+    unsigned int l;
+    size_t plen = key->payload_length, iv = 0, /* explicit IV in TLS 1.1 and
+                                                * later */
+        sha_off = 0;
+#if defined(STITCHED_CALL)
+    size_t aes_off = 0, blocks;
+
+    sha_off = SHA_CBLOCK - key->md.num;
+#endif
+
+    key->payload_length = NO_PAYLOAD_LENGTH;
+
+    if (len % AES_BLOCK_SIZE)
+        return 0;
+
+    if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+        if (plen == NO_PAYLOAD_LENGTH)
+            plen = len;
+        else if (len != ((plen + SHA_DIGEST_LENGTH + AES_BLOCK_SIZE) & -AES_BLOCK_SIZE))
+            return 0;
+        else if (key->aux.tls_ver >= TLS1_1_VERSION)
+            iv = AES_BLOCK_SIZE;
+
+#if defined(STITCHED_CALL)
+        if (plen > (sha_off + iv)
+            && (blocks = (plen - (sha_off + iv)) / SHA_CBLOCK)) {
+            SHA1_Update(&key->md, in + iv, sha_off);
+
+            aesni_cbc_sha1_enc(in, out, blocks, &key->ks, ctx->iv,
+                &key->md, in + iv + sha_off);
+            blocks *= SHA_CBLOCK;
+            aes_off += blocks;
+            sha_off += blocks;
+            key->md.Nh += (unsigned int)(blocks >> 29);
+            key->md.Nl += (unsigned int)(blocks <<= 3);
+            if (key->md.Nl < (unsigned int)blocks)
+                key->md.Nh++;
+        } else {
+            sha_off = 0;
+        }
+#endif
+        sha_off += iv;
+        SHA1_Update(&key->md, in + sha_off, plen - sha_off);
+
+        if (plen != len) { /* "TLS" mode of operation */
+            if (in != out)
+                memcpy(out + aes_off, in + aes_off, plen - aes_off);
+
+            /* calculate HMAC and append it to payload */
+            SHA1_Final(out + plen, &key->md);
+            key->md = key->tail;
+            SHA1_Update(&key->md, out + plen, SHA_DIGEST_LENGTH);
+            SHA1_Final(out + plen, &key->md);
+
+            /* pad the payload|hmac */
+            plen += SHA_DIGEST_LENGTH;
+            for (l = (unsigned int)(len - plen - 1); plen < len; plen++)
+                out[plen] = l;
+            /* encrypt HMAC|padding at once */
+            aesni_cbc_encrypt(out + aes_off, out + aes_off, len - aes_off,
+                &key->ks, ctx->iv, 1);
+        } else {
+            aesni_cbc_encrypt(in + aes_off, out + aes_off, len - aes_off,
+                &key->ks, ctx->iv, 1);
+        }
+    } else {
+        union {
+            unsigned int u[SHA_DIGEST_LENGTH / sizeof(unsigned int)];
+            unsigned char c[32 + SHA_DIGEST_LENGTH];
+        } mac, *pmac;
+
+        /* arrange cache line alignment */
+        pmac = (void *)(((size_t)mac.c + 31) & ((size_t)0 - 32));
+
+        if (plen != NO_PAYLOAD_LENGTH) { /* "TLS" mode of operation */
+            size_t inp_len, mask, j, i;
+            unsigned int res, maxpad, pad, bitlen;
+            int ret = 1;
+            union {
+                unsigned int u[SHA_LBLOCK];
+                unsigned char c[SHA_CBLOCK];
+            } *data = (void *)key->md.data;
+#if defined(STITCHED_DECRYPT_CALL)
+            unsigned char tail_iv[AES_BLOCK_SIZE];
+            int stitch = 0;
+            const int keylen = EVP_CIPHER_CTX_get_key_length(ctx);
+
+            if (keylen <= 0) {
+                ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+                return 0;
+            }
+#endif
+
+            if ((key->aux.tls_aad[plen - 4] << 8 | key->aux.tls_aad[plen - 3])
+                >= TLS1_1_VERSION) {
+                if (len < (AES_BLOCK_SIZE + SHA_DIGEST_LENGTH + 1))
+                    return 0;
+
+                /* omit explicit iv */
+                memcpy(ctx->iv, in, AES_BLOCK_SIZE);
+
+                in += AES_BLOCK_SIZE;
+                out += AES_BLOCK_SIZE;
+                len -= AES_BLOCK_SIZE;
+            } else if (len < (SHA_DIGEST_LENGTH + 1))
+                return 0;
+
+#if defined(STITCHED_DECRYPT_CALL)
+            if (len >= 1024 && keylen == 32) {
+                /* decrypt last block */
+                memcpy(tail_iv, in + len - 2 * AES_BLOCK_SIZE,
+                    AES_BLOCK_SIZE);
+                aesni_cbc_encrypt(in + len - AES_BLOCK_SIZE,
+                    out + len - AES_BLOCK_SIZE, AES_BLOCK_SIZE,
+                    &key->ks, tail_iv, 0);
+                stitch = 1;
+            } else
+#endif
+                /* decrypt HMAC|padding at once */
+                aesni_cbc_encrypt(in, out, len, &key->ks,
+                    ctx->iv, 0);
+
+            /* figure out payload length */
+            pad = out[len - 1];
+            maxpad = (unsigned int)(len - (SHA_DIGEST_LENGTH + 1));
+            maxpad |= (255 - maxpad) >> (sizeof(maxpad) * 8 - 8);
+            maxpad &= 255;
+
+            mask = constant_time_ge(maxpad, pad);
+            ret &= mask;
+            /*
+             * If pad is invalid then we will fail the above test but we must
+             * continue anyway because we are in constant time code. However,
+             * we'll use the maxpad value instead of the supplied pad to make
+             * sure we perform well defined pointer arithmetic.
+             */
+            pad = constant_time_select((unsigned int)mask, pad, maxpad);
+
+            inp_len = len - (SHA_DIGEST_LENGTH + pad + 1);
+
+            key->aux.tls_aad[plen - 2] = (unsigned char)(inp_len >> 8);
+            key->aux.tls_aad[plen - 1] = (unsigned char)inp_len;
+
+            /* calculate HMAC */
+            key->md = key->head;
+            SHA1_Update(&key->md, key->aux.tls_aad, plen);
+
+#if defined(STITCHED_DECRYPT_CALL)
+            if (stitch) {
+                blocks = (len - (256 + 32 + SHA_CBLOCK)) / SHA_CBLOCK;
+                aes_off = len - AES_BLOCK_SIZE - blocks * SHA_CBLOCK;
+                sha_off = SHA_CBLOCK - plen;
+
+                aesni_cbc_encrypt(in, out, aes_off, &key->ks, ctx->iv, 0);
+
+                SHA1_Update(&key->md, out, sha_off);
+                aesni256_cbc_sha1_dec(in + aes_off,
+                    out + aes_off, blocks, &key->ks,
+                    ctx->iv, &key->md, out + sha_off);
+
+                sha_off += blocks *= SHA_CBLOCK;
+                out += sha_off;
+                len -= sha_off;
+                inp_len -= sha_off;
+
+                key->md.Nl += (blocks << 3); /* at most 18 bits */
+                memcpy(ctx->iv, tail_iv, AES_BLOCK_SIZE);
+            }
+#endif
+
+#if 1 /* see original reference version in #else */
+            len -= SHA_DIGEST_LENGTH; /* amend mac */
+            if (len >= (256 + SHA_CBLOCK)) {
+                j = (len - (256 + SHA_CBLOCK)) & (0 - SHA_CBLOCK);
+                j += SHA_CBLOCK - key->md.num;
+                SHA1_Update(&key->md, out, j);
+                out += j;
+                len -= j;
+                inp_len -= j;
+            }
+
+            /* but pretend as if we hashed padded payload */
+            bitlen = key->md.Nl + (unsigned int)(inp_len << 3); /* at most 18 bits */
+#ifdef BSWAP4
+            bitlen = BSWAP4(bitlen);
+#else
+            mac.c[0] = 0;
+            mac.c[1] = (unsigned char)(bitlen >> 16);
+            mac.c[2] = (unsigned char)(bitlen >> 8);
+            mac.c[3] = (unsigned char)bitlen;
+            bitlen = mac.u[0];
+#endif
+
+            pmac->u[0] = 0;
+            pmac->u[1] = 0;
+            pmac->u[2] = 0;
+            pmac->u[3] = 0;
+            pmac->u[4] = 0;
+
+            for (res = key->md.num, j = 0; j < len; j++) {
+                size_t c = out[j];
+                mask = (j - inp_len) >> (sizeof(j) * 8 - 8);
+                c &= mask;
+                c |= 0x80 & ~mask & ~((inp_len - j) >> (sizeof(j) * 8 - 8));
+                data->c[res++] = (unsigned char)c;
+
+                if (res != SHA_CBLOCK)
+                    continue;
+
+                /* j is not incremented yet */
+                mask = 0 - ((inp_len + 7 - j) >> (sizeof(j) * 8 - 1));
+                data->u[SHA_LBLOCK - 1] |= bitlen & mask;
+                sha1_block_data_order(&key->md, data, 1);
+                mask &= 0 - ((j - inp_len - 72) >> (sizeof(j) * 8 - 1));
+                pmac->u[0] |= key->md.h0 & mask;
+                pmac->u[1] |= key->md.h1 & mask;
+                pmac->u[2] |= key->md.h2 & mask;
+                pmac->u[3] |= key->md.h3 & mask;
+                pmac->u[4] |= key->md.h4 & mask;
+                res = 0;
+            }
+
+            for (i = res; i < SHA_CBLOCK; i++, j++)
+                data->c[i] = 0;
+
+            if (res > SHA_CBLOCK - 8) {
+                mask = 0 - ((inp_len + 8 - j) >> (sizeof(j) * 8 - 1));
+                data->u[SHA_LBLOCK - 1] |= bitlen & mask;
+                sha1_block_data_order(&key->md, data, 1);
+                mask &= 0 - ((j - inp_len - 73) >> (sizeof(j) * 8 - 1));
+                pmac->u[0] |= key->md.h0 & mask;
+                pmac->u[1] |= key->md.h1 & mask;
+                pmac->u[2] |= key->md.h2 & mask;
+                pmac->u[3] |= key->md.h3 & mask;
+                pmac->u[4] |= key->md.h4 & mask;
+
+                memset(data, 0, SHA_CBLOCK);
+                j += 64;
+            }
+            data->u[SHA_LBLOCK - 1] = bitlen;
+            sha1_block_data_order(&key->md, data, 1);
+            mask = 0 - ((j - inp_len - 73) >> (sizeof(j) * 8 - 1));
+            pmac->u[0] |= key->md.h0 & mask;
+            pmac->u[1] |= key->md.h1 & mask;
+            pmac->u[2] |= key->md.h2 & mask;
+            pmac->u[3] |= key->md.h3 & mask;
+            pmac->u[4] |= key->md.h4 & mask;
+
+#ifdef BSWAP4
+            pmac->u[0] = BSWAP4(pmac->u[0]);
+            pmac->u[1] = BSWAP4(pmac->u[1]);
+            pmac->u[2] = BSWAP4(pmac->u[2]);
+            pmac->u[3] = BSWAP4(pmac->u[3]);
+            pmac->u[4] = BSWAP4(pmac->u[4]);
+#else
+            for (i = 0; i < 5; i++) {
+                res = pmac->u[i];
+                pmac->c[4 * i + 0] = (unsigned char)(res >> 24);
+                pmac->c[4 * i + 1] = (unsigned char)(res >> 16);
+                pmac->c[4 * i + 2] = (unsigned char)(res >> 8);
+                pmac->c[4 * i + 3] = (unsigned char)res;
+            }
+#endif
+            len += SHA_DIGEST_LENGTH;
+#else /* pre-lucky-13 reference version of above */
+            SHA1_Update(&key->md, out, inp_len);
+            res = key->md.num;
+            SHA1_Final(pmac->c, &key->md);
+
+            {
+                unsigned int inp_blocks, pad_blocks;
+
+                /* but pretend as if we hashed padded payload */
+                inp_blocks = 1 + ((SHA_CBLOCK - 9 - res) >> (sizeof(res) * 8 - 1));
+                res += (unsigned int)(len - inp_len);
+                pad_blocks = res / SHA_CBLOCK;
+                res %= SHA_CBLOCK;
+                pad_blocks += 1 + ((SHA_CBLOCK - 9 - res) >> (sizeof(res) * 8 - 1));
+                for (; inp_blocks < pad_blocks; inp_blocks++)
+                    sha1_block_data_order(&key->md, data, 1);
+            }
+#endif
+            key->md = key->tail;
+            SHA1_Update(&key->md, pmac->c, SHA_DIGEST_LENGTH);
+            SHA1_Final(pmac->c, &key->md);
+
+            /* verify HMAC */
+            out += inp_len;
+            len -= inp_len;
+#if 1 /* see original reference version in #else */
+            {
+                unsigned char *p = out + len - 1 - maxpad - SHA_DIGEST_LENGTH;
+                size_t off = out - p;
+                unsigned int c, cmask;
+
+                for (res = 0, i = 0, j = 0; j < maxpad + SHA_DIGEST_LENGTH; j++) {
+                    c = p[j];
+                    cmask = ((int)(j - off - SHA_DIGEST_LENGTH)) >> (sizeof(int) * 8 - 1);
+                    res |= (c ^ pad) & ~cmask; /* ... and padding */
+                    cmask &= ((int)(off - 1 - j)) >> (sizeof(int) * 8 - 1);
+                    res |= (c ^ pmac->c[i]) & cmask;
+                    i += 1 & cmask;
+                }
+
+                res = 0 - ((0 - res) >> (sizeof(res) * 8 - 1));
+                ret &= (int)~res;
+            }
+#else /* pre-lucky-13 reference version of above */
+            for (res = 0, i = 0; i < SHA_DIGEST_LENGTH; i++)
+                res |= out[i] ^ pmac->c[i];
+            res = 0 - ((0 - res) >> (sizeof(res) * 8 - 1));
+            ret &= (int)~res;
+
+            /* verify padding */
+            pad = (pad & ~res) | (maxpad & res);
+            out = out + len - 1 - pad;
+            for (res = 0, i = 0; i < pad; i++)
+                res |= out[i] ^ pad;
+
+            res = (0 - res) >> (sizeof(res) * 8 - 1);
+            ret &= (int)~res;
+#endif
+            return ret;
+        } else {
+#if defined(STITCHED_DECRYPT_CALL)
+            if (len >= 1024 && keylen == 32) {
+                if (sha_off %= SHA_CBLOCK)
+                    blocks = (len - 3 * SHA_CBLOCK) / SHA_CBLOCK;
+                else
+                    blocks = (len - 2 * SHA_CBLOCK) / SHA_CBLOCK;
+                aes_off = len - blocks * SHA_CBLOCK;
+
+                aesni_cbc_encrypt(in, out, aes_off, &key->ks, ctx->iv, 0);
+                SHA1_Update(&key->md, out, sha_off);
+                aesni256_cbc_sha1_dec(in + aes_off,
+                    out + aes_off, blocks, &key->ks,
+                    ctx->iv, &key->md, out + sha_off);
+
+                sha_off += blocks *= SHA_CBLOCK;
+                out += sha_off;
+                len -= sha_off;
+
+                key->md.Nh += blocks >> 29;
+                key->md.Nl += blocks <<= 3;
+                if (key->md.Nl < (unsigned int)blocks)
+                    key->md.Nh++;
+            } else
+#endif
+                /* decrypt HMAC|padding at once */
+                aesni_cbc_encrypt(in, out, len, &key->ks,
+                    ctx->iv, 0);
+
+            SHA1_Update(&key->md, out, len);
+        }
+    }
+
+    return 1;
+}
+
+static int aesni_cbc_hmac_sha1_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg,
+    void *ptr)
+{
+    EVP_AES_HMAC_SHA1 *key = data(ctx);
+
+    switch (type) {
+    case EVP_CTRL_AEAD_SET_MAC_KEY: {
+        unsigned int i;
+        unsigned char hmac_key[64];
+
+        memset(hmac_key, 0, sizeof(hmac_key));
+
+        if (arg > (int)sizeof(hmac_key)) {
+            SHA1_Init(&key->head);
+            SHA1_Update(&key->head, ptr, arg);
+            SHA1_Final(hmac_key, &key->head);
+        } else {
+            memcpy(hmac_key, ptr, arg);
+        }
+
+        for (i = 0; i < sizeof(hmac_key); i++)
+            hmac_key[i] ^= 0x36; /* ipad */
+        SHA1_Init(&key->head);
+        SHA1_Update(&key->head, hmac_key, sizeof(hmac_key));
+
+        for (i = 0; i < sizeof(hmac_key); i++)
+            hmac_key[i] ^= 0x36 ^ 0x5c; /* opad */
+        SHA1_Init(&key->tail);
+        SHA1_Update(&key->tail, hmac_key, sizeof(hmac_key));
+
+        OPENSSL_cleanse(hmac_key, sizeof(hmac_key));
+
+        return 1;
+    }
+    case EVP_CTRL_AEAD_TLS1_AAD: {
+        unsigned char *p = ptr;
+        unsigned int len;
+
+        if (arg != EVP_AEAD_TLS1_AAD_LEN)
+            return -1;
+
+        len = p[arg - 2] << 8 | p[arg - 1];
+
+        if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+            key->payload_length = len;
+            if ((key->aux.tls_ver = p[arg - 4] << 8 | p[arg - 3]) >= TLS1_1_VERSION) {
+                if (len < AES_BLOCK_SIZE)
+                    return 0;
+                len -= AES_BLOCK_SIZE;
+                p[arg - 2] = len >> 8;
+                p[arg - 1] = len;
+            }
+            key->md = key->head;
+            SHA1_Update(&key->md, p, arg);
+
+            return (int)(((len + SHA_DIGEST_LENGTH + AES_BLOCK_SIZE) & -AES_BLOCK_SIZE)
+                - len);
+        } else {
+            memcpy(key->aux.tls_aad, ptr, arg);
+            key->payload_length = arg;
+
+            return SHA_DIGEST_LENGTH;
+        }
+    }
+#if !defined(OPENSSL_NO_MULTIBLOCK)
+    case EVP_CTRL_TLS1_1_MULTIBLOCK_MAX_BUFSIZE:
+        return (int)(5 + 16 + ((arg + 20 + 16) & -16));
+    case EVP_CTRL_TLS1_1_MULTIBLOCK_AAD: {
+        EVP_CTRL_TLS1_1_MULTIBLOCK_PARAM *param = (EVP_CTRL_TLS1_1_MULTIBLOCK_PARAM *)ptr;
+        unsigned int n4x = 1, x4;
+        unsigned int frag, last, packlen, inp_len;
+
+        if (arg < (int)sizeof(EVP_CTRL_TLS1_1_MULTIBLOCK_PARAM))
+            return -1;
+
+        inp_len = param->inp[11] << 8 | param->inp[12];
+
+        if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+            if ((param->inp[9] << 8 | param->inp[10]) < TLS1_1_VERSION)
+                return -1;
+
+            if (inp_len) {
+                if (inp_len < 4096)
+                    return 0; /* too short */
+
+                if (inp_len >= 8192 && OPENSSL_ia32cap_P[2] & (1 << 5))
+                    n4x = 2; /* AVX2 */
+            } else if ((n4x = param->interleave / 4) && n4x <= 2)
+                inp_len = (unsigned int)param->len;
+            else
+                return -1;
+
+            key->md = key->head;
+            SHA1_Update(&key->md, param->inp, 13);
+
+            x4 = 4 * n4x;
+            n4x += 1;
+
+            frag = inp_len >> n4x;
+            last = inp_len + frag - (frag << n4x);
+            if (last > frag && ((last + 13 + 9) % 64 < (x4 - 1))) {
+                frag++;
+                last -= x4 - 1;
+            }
+
+            packlen = 5 + 16 + ((frag + 20 + 16) & -16);
+            packlen = (packlen << n4x) - packlen;
+            packlen += 5 + 16 + ((last + 20 + 16) & -16);
+
+            param->interleave = x4;
+
+            return (int)packlen;
+        } else
+            return -1; /* not yet */
+    }
+    case EVP_CTRL_TLS1_1_MULTIBLOCK_ENCRYPT: {
+        EVP_CTRL_TLS1_1_MULTIBLOCK_PARAM *param = (EVP_CTRL_TLS1_1_MULTIBLOCK_PARAM *)ptr;
+
+        return (int)tls1_1_multi_block_encrypt(key, param->out,
+            param->inp, param->len,
+            param->interleave / 4);
+    }
+    case EVP_CTRL_TLS1_1_MULTIBLOCK_DECRYPT:
+#endif
+    default:
+        return -1;
+    }
+}
+
 static const EVP_CIPHER aesni_128_cbc_hmac_sha1_cipher = {
 #ifdef NID_aes_128_cbc_hmac_sha1
     NID_aes_128_cbc_hmac_sha1,
@@ -23,7 +903,15 @@ static const EVP_CIPHER aesni_128_cbc_hmac_sha1_cipher = {
 #endif
     AES_BLOCK_SIZE, 16, AES_BLOCK_SIZE,
     EVP_CIPH_CBC_MODE | EVP_CIPH_FLAG_DEFAULT_ASN1 | EVP_CIPH_FLAG_AEAD_CIPHER | EVP_CIPH_FLAG_TLS1_1_MULTIBLOCK,
-    EVP_ORIG_GLOBAL
+    EVP_ORIG_GLOBAL,
+    aesni_cbc_hmac_sha1_init_key,
+    aesni_cbc_hmac_sha1_cipher,
+    NULL,
+    sizeof(EVP_AES_HMAC_SHA1),
+    EVP_CIPH_FLAG_DEFAULT_ASN1 ? NULL : EVP_CIPHER_set_asn1_iv,
+    EVP_CIPH_FLAG_DEFAULT_ASN1 ? NULL : EVP_CIPHER_get_asn1_iv,
+    aesni_cbc_hmac_sha1_ctrl,
+    NULL
 };
 
 static const EVP_CIPHER aesni_256_cbc_hmac_sha1_cipher = {
@@ -34,7 +922,15 @@ static const EVP_CIPHER aesni_256_cbc_hmac_sha1_cipher = {
 #endif
     AES_BLOCK_SIZE, 32, AES_BLOCK_SIZE,
     EVP_CIPH_CBC_MODE | EVP_CIPH_FLAG_DEFAULT_ASN1 | EVP_CIPH_FLAG_AEAD_CIPHER | EVP_CIPH_FLAG_TLS1_1_MULTIBLOCK,
-    EVP_ORIG_GLOBAL
+    EVP_ORIG_GLOBAL,
+    aesni_cbc_hmac_sha1_init_key,
+    aesni_cbc_hmac_sha1_cipher,
+    NULL,
+    sizeof(EVP_AES_HMAC_SHA1),
+    EVP_CIPH_FLAG_DEFAULT_ASN1 ? NULL : EVP_CIPHER_set_asn1_iv,
+    EVP_CIPH_FLAG_DEFAULT_ASN1 ? NULL : EVP_CIPHER_get_asn1_iv,
+    aesni_cbc_hmac_sha1_ctrl,
+    NULL
 };
 
 const EVP_CIPHER *EVP_aes_128_cbc_hmac_sha1(void)
diff --git a/crypto/evp/e_aes_cbc_hmac_sha256.c b/crypto/evp/e_aes_cbc_hmac_sha256.c
index c2d2fbd385..28e2bace00 100644
--- a/crypto/evp/e_aes_cbc_hmac_sha256.c
+++ b/crypto/evp/e_aes_cbc_hmac_sha256.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2013-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2013-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -14,19 +14,863 @@
  */
 #include "internal/deprecated.h"
 
+#include 
+#include 
+#include 
+#include 
+#include 
 #include 
 #include 
+#include 
 #include "internal/cryptlib.h"
+#include "crypto/modes.h"
+#include "internal/constant_time.h"
 #include "crypto/evp.h"
+#include "evp_local.h"
+
+typedef struct {
+    AES_KEY ks;
+    SHA256_CTX head, tail, md;
+    size_t payload_length; /* AAD length in decrypt case */
+    union {
+        unsigned int tls_ver;
+        unsigned char tls_aad[16]; /* 13 used */
+    } aux;
+} EVP_AES_HMAC_SHA256;
+
+#define NO_PAYLOAD_LENGTH ((size_t)-1)
 
 #if defined(AES_ASM) && (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64))
 
 #define AESNI_CAPABLE (1 << (57 - 32))
 
+int aesni_set_encrypt_key(const unsigned char *userKey, int bits,
+    AES_KEY *key);
+int aesni_set_decrypt_key(const unsigned char *userKey, int bits,
+    AES_KEY *key);
+
+void aesni_cbc_encrypt(const unsigned char *in,
+    unsigned char *out,
+    size_t length,
+    const AES_KEY *key, unsigned char *ivec, int enc);
+
 int aesni_cbc_sha256_enc(const void *inp, void *out, size_t blocks,
     const AES_KEY *key, unsigned char iv[16],
     SHA256_CTX *ctx, const void *in0);
 
+#define data(ctx) ((EVP_AES_HMAC_SHA256 *)EVP_CIPHER_CTX_get_cipher_data(ctx))
+
+static int aesni_cbc_hmac_sha256_init_key(EVP_CIPHER_CTX *ctx,
+    const unsigned char *inkey,
+    const unsigned char *iv, int enc)
+{
+    EVP_AES_HMAC_SHA256 *key = data(ctx);
+    int ret;
+
+    if (enc)
+        ret = aesni_set_encrypt_key(inkey,
+            EVP_CIPHER_CTX_get_key_length(ctx) * 8,
+            &key->ks);
+    else
+        ret = aesni_set_decrypt_key(inkey,
+            EVP_CIPHER_CTX_get_key_length(ctx) * 8,
+            &key->ks);
+
+    SHA256_Init(&key->head); /* handy when benchmarking */
+    key->tail = key->head;
+    key->md = key->head;
+
+    key->payload_length = NO_PAYLOAD_LENGTH;
+
+    return ret < 0 ? 0 : 1;
+}
+
+#define STITCHED_CALL
+
+#if !defined(STITCHED_CALL)
+#define aes_off 0
+#endif
+
+void sha256_block_data_order(void *c, const void *p, size_t len);
+
+static void sha256_update(SHA256_CTX *c, const void *data, size_t len)
+{
+    const unsigned char *ptr = data;
+    size_t res;
+
+    if ((res = c->num)) {
+        res = SHA256_CBLOCK - res;
+        if (len < res)
+            res = len;
+        SHA256_Update(c, ptr, res);
+        ptr += res;
+        len -= res;
+    }
+
+    res = len % SHA256_CBLOCK;
+    len -= res;
+
+    if (len) {
+        sha256_block_data_order(c, ptr, len / SHA256_CBLOCK);
+
+        ptr += len;
+        c->Nh += (unsigned int)(len >> 29);
+        c->Nl += (unsigned int)(len <<= 3);
+        if (c->Nl < (unsigned int)len)
+            c->Nh++;
+    }
+
+    if (res)
+        SHA256_Update(c, ptr, res);
+}
+
+#ifdef SHA256_Update
+#undef SHA256_Update
+#endif
+#define SHA256_Update sha256_update
+
+#if !defined(OPENSSL_NO_MULTIBLOCK)
+
+typedef struct {
+    unsigned int A[8], B[8], C[8], D[8], E[8], F[8], G[8], H[8];
+} SHA256_MB_CTX;
+typedef struct {
+    const unsigned char *ptr;
+    int blocks;
+} HASH_DESC;
+
+void sha256_multi_block(SHA256_MB_CTX *, const HASH_DESC *, int);
+
+typedef struct {
+    const unsigned char *inp;
+    unsigned char *out;
+    int blocks;
+    u64 iv[2];
+} CIPH_DESC;
+
+void aesni_multi_cbc_encrypt(CIPH_DESC *, void *, int);
+
+static size_t tls1_1_multi_block_encrypt(EVP_AES_HMAC_SHA256 *key,
+    unsigned char *out,
+    const unsigned char *inp,
+    size_t inp_len, int n4x)
+{ /* n4x is 1 or 2 */
+    HASH_DESC hash_d[8], edges[8];
+    CIPH_DESC ciph_d[8];
+    unsigned char storage[sizeof(SHA256_MB_CTX) + 32];
+    union {
+        u64 q[16];
+        u32 d[32];
+        u8 c[128];
+    } blocks[8];
+    SHA256_MB_CTX *ctx;
+    unsigned int frag, last, packlen, i, x4 = 4 * n4x, minblocks, processed = 0;
+    size_t ret = 0;
+    u8 *IVs;
+#if defined(BSWAP8)
+    u64 seqnum;
+#endif
+
+    /* ask for IVs in bulk */
+    if (RAND_bytes((IVs = blocks[0].c), 16 * x4) <= 0)
+        return 0;
+
+    /* align */
+    ctx = (SHA256_MB_CTX *)(storage + 32 - ((size_t)storage % 32));
+
+    frag = (unsigned int)inp_len >> (1 + n4x);
+    last = (unsigned int)inp_len + frag - (frag << (1 + n4x));
+    if (last > frag && ((last + 13 + 9) % 64) < (x4 - 1)) {
+        frag++;
+        last -= x4 - 1;
+    }
+
+    packlen = 5 + 16 + ((frag + 32 + 16) & -16);
+
+    /* populate descriptors with pointers and IVs */
+    hash_d[0].ptr = inp;
+    ciph_d[0].inp = inp;
+    /* 5+16 is place for header and explicit IV */
+    ciph_d[0].out = out + 5 + 16;
+    memcpy(ciph_d[0].out - 16, IVs, 16);
+    memcpy(ciph_d[0].iv, IVs, 16);
+    IVs += 16;
+
+    for (i = 1; i < x4; i++) {
+        ciph_d[i].inp = hash_d[i].ptr = hash_d[i - 1].ptr + frag;
+        ciph_d[i].out = ciph_d[i - 1].out + packlen;
+        memcpy(ciph_d[i].out - 16, IVs, 16);
+        memcpy(ciph_d[i].iv, IVs, 16);
+        IVs += 16;
+    }
+
+#if defined(BSWAP8)
+    memcpy(blocks[0].c, key->md.data, 8);
+    seqnum = BSWAP8(blocks[0].q[0]);
+#endif
+    for (i = 0; i < x4; i++) {
+        unsigned int len = (i == (x4 - 1) ? last : frag);
+#if !defined(BSWAP8)
+        unsigned int carry, j;
+#endif
+
+        ctx->A[i] = key->md.h[0];
+        ctx->B[i] = key->md.h[1];
+        ctx->C[i] = key->md.h[2];
+        ctx->D[i] = key->md.h[3];
+        ctx->E[i] = key->md.h[4];
+        ctx->F[i] = key->md.h[5];
+        ctx->G[i] = key->md.h[6];
+        ctx->H[i] = key->md.h[7];
+
+        /* fix seqnum */
+#if defined(BSWAP8)
+        blocks[i].q[0] = BSWAP8(seqnum + i);
+#else
+        for (carry = i, j = 8; j--;) {
+            blocks[i].c[j] = ((u8 *)key->md.data)[j] + carry;
+            carry = (blocks[i].c[j] - carry) >> (sizeof(carry) * 8 - 1);
+        }
+#endif
+        blocks[i].c[8] = ((u8 *)key->md.data)[8];
+        blocks[i].c[9] = ((u8 *)key->md.data)[9];
+        blocks[i].c[10] = ((u8 *)key->md.data)[10];
+        /* fix length */
+        blocks[i].c[11] = (u8)(len >> 8);
+        blocks[i].c[12] = (u8)(len);
+
+        memcpy(blocks[i].c + 13, hash_d[i].ptr, 64 - 13);
+        hash_d[i].ptr += 64 - 13;
+        hash_d[i].blocks = (len - (64 - 13)) / 64;
+
+        edges[i].ptr = blocks[i].c;
+        edges[i].blocks = 1;
+    }
+
+    /* hash 13-byte headers and first 64-13 bytes of inputs */
+    sha256_multi_block(ctx, edges, n4x);
+    /* hash bulk inputs */
+#define MAXCHUNKSIZE 2048
+#if MAXCHUNKSIZE % 64
+#error "MAXCHUNKSIZE is not divisible by 64"
+#elif MAXCHUNKSIZE
+    /*
+     * goal is to minimize pressure on L1 cache by moving in shorter steps,
+     * so that hashed data is still in the cache by the time we encrypt it
+     */
+    minblocks = ((frag <= last ? frag : last) - (64 - 13)) / 64;
+    if (minblocks > MAXCHUNKSIZE / 64) {
+        for (i = 0; i < x4; i++) {
+            edges[i].ptr = hash_d[i].ptr;
+            edges[i].blocks = MAXCHUNKSIZE / 64;
+            ciph_d[i].blocks = MAXCHUNKSIZE / 16;
+        }
+        do {
+            sha256_multi_block(ctx, edges, n4x);
+            aesni_multi_cbc_encrypt(ciph_d, &key->ks, n4x);
+
+            for (i = 0; i < x4; i++) {
+                edges[i].ptr = hash_d[i].ptr += MAXCHUNKSIZE;
+                hash_d[i].blocks -= MAXCHUNKSIZE / 64;
+                edges[i].blocks = MAXCHUNKSIZE / 64;
+                ciph_d[i].inp += MAXCHUNKSIZE;
+                ciph_d[i].out += MAXCHUNKSIZE;
+                ciph_d[i].blocks = MAXCHUNKSIZE / 16;
+                memcpy(ciph_d[i].iv, ciph_d[i].out - 16, 16);
+            }
+            processed += MAXCHUNKSIZE;
+            minblocks -= MAXCHUNKSIZE / 64;
+        } while (minblocks > MAXCHUNKSIZE / 64);
+    }
+#endif
+#undef MAXCHUNKSIZE
+    sha256_multi_block(ctx, hash_d, n4x);
+
+    memset(blocks, 0, sizeof(blocks));
+    for (i = 0; i < x4; i++) {
+        unsigned int len = (i == (x4 - 1) ? last : frag),
+                     off = hash_d[i].blocks * 64;
+        const unsigned char *ptr = hash_d[i].ptr + off;
+
+        off = (len - processed) - (64 - 13) - off; /* remainder actually */
+        memcpy(blocks[i].c, ptr, off);
+        blocks[i].c[off] = 0x80;
+        len += 64 + 13; /* 64 is HMAC header */
+        len *= 8; /* convert to bits */
+        if (off < (64 - 8)) {
+#ifdef BSWAP4
+            blocks[i].d[15] = BSWAP4(len);
+#else
+            PUTU32(blocks[i].c + 60, len);
+#endif
+            edges[i].blocks = 1;
+        } else {
+#ifdef BSWAP4
+            blocks[i].d[31] = BSWAP4(len);
+#else
+            PUTU32(blocks[i].c + 124, len);
+#endif
+            edges[i].blocks = 2;
+        }
+        edges[i].ptr = blocks[i].c;
+    }
+
+    /* hash input tails and finalize */
+    sha256_multi_block(ctx, edges, n4x);
+
+    memset(blocks, 0, sizeof(blocks));
+    for (i = 0; i < x4; i++) {
+#ifdef BSWAP4
+        blocks[i].d[0] = BSWAP4(ctx->A[i]);
+        ctx->A[i] = key->tail.h[0];
+        blocks[i].d[1] = BSWAP4(ctx->B[i]);
+        ctx->B[i] = key->tail.h[1];
+        blocks[i].d[2] = BSWAP4(ctx->C[i]);
+        ctx->C[i] = key->tail.h[2];
+        blocks[i].d[3] = BSWAP4(ctx->D[i]);
+        ctx->D[i] = key->tail.h[3];
+        blocks[i].d[4] = BSWAP4(ctx->E[i]);
+        ctx->E[i] = key->tail.h[4];
+        blocks[i].d[5] = BSWAP4(ctx->F[i]);
+        ctx->F[i] = key->tail.h[5];
+        blocks[i].d[6] = BSWAP4(ctx->G[i]);
+        ctx->G[i] = key->tail.h[6];
+        blocks[i].d[7] = BSWAP4(ctx->H[i]);
+        ctx->H[i] = key->tail.h[7];
+        blocks[i].c[32] = 0x80;
+        blocks[i].d[15] = BSWAP4((64 + 32) * 8);
+#else
+        PUTU32(blocks[i].c + 0, ctx->A[i]);
+        ctx->A[i] = key->tail.h[0];
+        PUTU32(blocks[i].c + 4, ctx->B[i]);
+        ctx->B[i] = key->tail.h[1];
+        PUTU32(blocks[i].c + 8, ctx->C[i]);
+        ctx->C[i] = key->tail.h[2];
+        PUTU32(blocks[i].c + 12, ctx->D[i]);
+        ctx->D[i] = key->tail.h[3];
+        PUTU32(blocks[i].c + 16, ctx->E[i]);
+        ctx->E[i] = key->tail.h[4];
+        PUTU32(blocks[i].c + 20, ctx->F[i]);
+        ctx->F[i] = key->tail.h[5];
+        PUTU32(blocks[i].c + 24, ctx->G[i]);
+        ctx->G[i] = key->tail.h[6];
+        PUTU32(blocks[i].c + 28, ctx->H[i]);
+        ctx->H[i] = key->tail.h[7];
+        blocks[i].c[32] = 0x80;
+        PUTU32(blocks[i].c + 60, (64 + 32) * 8);
+#endif
+        edges[i].ptr = blocks[i].c;
+        edges[i].blocks = 1;
+    }
+
+    /* finalize MACs */
+    sha256_multi_block(ctx, edges, n4x);
+
+    for (i = 0; i < x4; i++) {
+        unsigned int len = (i == (x4 - 1) ? last : frag), pad, j;
+        unsigned char *out0 = out;
+
+        memcpy(ciph_d[i].out, ciph_d[i].inp, len - processed);
+        ciph_d[i].inp = ciph_d[i].out;
+
+        out += 5 + 16 + len;
+
+        /* write MAC */
+        PUTU32(out + 0, ctx->A[i]);
+        PUTU32(out + 4, ctx->B[i]);
+        PUTU32(out + 8, ctx->C[i]);
+        PUTU32(out + 12, ctx->D[i]);
+        PUTU32(out + 16, ctx->E[i]);
+        PUTU32(out + 20, ctx->F[i]);
+        PUTU32(out + 24, ctx->G[i]);
+        PUTU32(out + 28, ctx->H[i]);
+        out += 32;
+        len += 32;
+
+        /* pad */
+        pad = 15 - len % 16;
+        for (j = 0; j <= pad; j++)
+            *(out++) = pad;
+        len += pad + 1;
+
+        ciph_d[i].blocks = (len - processed) / 16;
+        len += 16; /* account for explicit iv */
+
+        /* arrange header */
+        out0[0] = ((u8 *)key->md.data)[8];
+        out0[1] = ((u8 *)key->md.data)[9];
+        out0[2] = ((u8 *)key->md.data)[10];
+        out0[3] = (u8)(len >> 8);
+        out0[4] = (u8)(len);
+
+        ret += len + 5;
+        inp += frag;
+    }
+
+    aesni_multi_cbc_encrypt(ciph_d, &key->ks, n4x);
+
+    OPENSSL_cleanse(blocks, sizeof(blocks));
+    OPENSSL_cleanse(ctx, sizeof(*ctx));
+
+    return ret;
+}
+#endif
+
+static int aesni_cbc_hmac_sha256_cipher(EVP_CIPHER_CTX *ctx,
+    unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_AES_HMAC_SHA256 *key = data(ctx);
+    unsigned int l;
+    size_t plen = key->payload_length, iv = 0, /* explicit IV in TLS 1.1 and
+                                                * later */
+        sha_off = 0;
+#if defined(STITCHED_CALL)
+    size_t aes_off = 0, blocks;
+
+    sha_off = SHA256_CBLOCK - key->md.num;
+#endif
+
+    key->payload_length = NO_PAYLOAD_LENGTH;
+
+    if (len % AES_BLOCK_SIZE)
+        return 0;
+
+    if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+        if (plen == NO_PAYLOAD_LENGTH)
+            plen = len;
+        else if (len != ((plen + SHA256_DIGEST_LENGTH + AES_BLOCK_SIZE) & -AES_BLOCK_SIZE))
+            return 0;
+        else if (key->aux.tls_ver >= TLS1_1_VERSION)
+            iv = AES_BLOCK_SIZE;
+
+#if defined(STITCHED_CALL)
+        /*
+         * Assembly stitch handles AVX-capable processors, but its
+         * performance is not optimal on AMD Jaguar, ~40% worse, for
+         * unknown reasons. Incidentally processor in question supports
+         * AVX, but not AMD-specific XOP extension, which can be used
+         * to identify it and avoid stitch invocation. So that after we
+         * establish that current CPU supports AVX, we even see if it's
+         * either even XOP-capable Bulldozer-based or GenuineIntel one.
+         * But SHAEXT-capable go ahead...
+         */
+        if (((OPENSSL_ia32cap_P[2] & (1 << 29)) || /* SHAEXT? */
+                ((OPENSSL_ia32cap_P[1] & (1 << (60 - 32))) && /* AVX? */
+                    ((OPENSSL_ia32cap_P[1] & (1 << (43 - 32))) /* XOP? */
+                        | (OPENSSL_ia32cap_P[0] & (1 << 30)))))
+            && /* "Intel CPU"? */
+            plen > (sha_off + iv) && (blocks = (plen - (sha_off + iv)) / SHA256_CBLOCK)) {
+            SHA256_Update(&key->md, in + iv, sha_off);
+
+            (void)aesni_cbc_sha256_enc(in, out, blocks, &key->ks,
+                ctx->iv, &key->md, in + iv + sha_off);
+            blocks *= SHA256_CBLOCK;
+            aes_off += blocks;
+            sha_off += blocks;
+            key->md.Nh += (unsigned int)(blocks >> 29);
+            key->md.Nl += (unsigned int)(blocks <<= 3);
+            if (key->md.Nl < (unsigned int)blocks)
+                key->md.Nh++;
+        } else {
+            sha_off = 0;
+        }
+#endif
+        sha_off += iv;
+        SHA256_Update(&key->md, in + sha_off, plen - sha_off);
+
+        if (plen != len) { /* "TLS" mode of operation */
+            if (in != out)
+                memcpy(out + aes_off, in + aes_off, plen - aes_off);
+
+            /* calculate HMAC and append it to payload */
+            SHA256_Final(out + plen, &key->md);
+            key->md = key->tail;
+            SHA256_Update(&key->md, out + plen, SHA256_DIGEST_LENGTH);
+            SHA256_Final(out + plen, &key->md);
+
+            /* pad the payload|hmac */
+            plen += SHA256_DIGEST_LENGTH;
+            for (l = (unsigned int)(len - plen - 1); plen < len; plen++)
+                out[plen] = l;
+            /* encrypt HMAC|padding at once */
+            aesni_cbc_encrypt(out + aes_off, out + aes_off, len - aes_off,
+                &key->ks, ctx->iv, 1);
+        } else {
+            aesni_cbc_encrypt(in + aes_off, out + aes_off, len - aes_off,
+                &key->ks, ctx->iv, 1);
+        }
+    } else {
+        union {
+            unsigned int u[SHA256_DIGEST_LENGTH / sizeof(unsigned int)];
+            unsigned char c[64 + SHA256_DIGEST_LENGTH];
+        } mac, *pmac;
+
+        /* arrange cache line alignment */
+        pmac = (void *)(((size_t)mac.c + 63) & ((size_t)0 - 64));
+
+        /* decrypt HMAC|padding at once */
+        aesni_cbc_encrypt(in, out, len, &key->ks,
+            ctx->iv, 0);
+
+        if (plen != NO_PAYLOAD_LENGTH) { /* "TLS" mode of operation */
+            size_t inp_len, mask, j, i;
+            unsigned int res, maxpad, pad, bitlen;
+            int ret = 1;
+            union {
+                unsigned int u[SHA_LBLOCK];
+                unsigned char c[SHA256_CBLOCK];
+            } *data = (void *)key->md.data;
+
+            if ((key->aux.tls_aad[plen - 4] << 8 | key->aux.tls_aad[plen - 3])
+                >= TLS1_1_VERSION)
+                iv = AES_BLOCK_SIZE;
+
+            if (len < (iv + SHA256_DIGEST_LENGTH + 1))
+                return 0;
+
+            /* omit explicit iv */
+            out += iv;
+            len -= iv;
+
+            /* figure out payload length */
+            pad = out[len - 1];
+            maxpad = (unsigned int)(len - (SHA256_DIGEST_LENGTH + 1));
+            maxpad |= (255 - maxpad) >> (sizeof(maxpad) * 8 - 8);
+            maxpad &= 255;
+
+            mask = constant_time_ge(maxpad, pad);
+            ret &= mask;
+            /*
+             * If pad is invalid then we will fail the above test but we must
+             * continue anyway because we are in constant time code. However,
+             * we'll use the maxpad value instead of the supplied pad to make
+             * sure we perform well defined pointer arithmetic.
+             */
+            pad = constant_time_select((unsigned int)mask, pad, maxpad);
+
+            inp_len = len - (SHA256_DIGEST_LENGTH + pad + 1);
+
+            key->aux.tls_aad[plen - 2] = (unsigned char)(inp_len >> 8);
+            key->aux.tls_aad[plen - 1] = (unsigned char)inp_len;
+
+            /* calculate HMAC */
+            key->md = key->head;
+            SHA256_Update(&key->md, key->aux.tls_aad, plen);
+
+#if 1 /* see original reference version in #else */
+            len -= SHA256_DIGEST_LENGTH; /* amend mac */
+            if (len >= (256 + SHA256_CBLOCK)) {
+                j = (len - (256 + SHA256_CBLOCK)) & (0 - SHA256_CBLOCK);
+                j += SHA256_CBLOCK - key->md.num;
+                SHA256_Update(&key->md, out, j);
+                out += j;
+                len -= j;
+                inp_len -= j;
+            }
+
+            /* but pretend as if we hashed padded payload */
+            bitlen = key->md.Nl + (unsigned int)(inp_len << 3); /* at most 18 bits */
+#ifdef BSWAP4
+            bitlen = BSWAP4(bitlen);
+#else
+            mac.c[0] = 0;
+            mac.c[1] = (unsigned char)(bitlen >> 16);
+            mac.c[2] = (unsigned char)(bitlen >> 8);
+            mac.c[3] = (unsigned char)bitlen;
+            bitlen = mac.u[0];
+#endif
+
+            pmac->u[0] = 0;
+            pmac->u[1] = 0;
+            pmac->u[2] = 0;
+            pmac->u[3] = 0;
+            pmac->u[4] = 0;
+            pmac->u[5] = 0;
+            pmac->u[6] = 0;
+            pmac->u[7] = 0;
+
+            for (res = key->md.num, j = 0; j < len; j++) {
+                size_t c = out[j];
+                mask = (j - inp_len) >> (sizeof(j) * 8 - 8);
+                c &= mask;
+                c |= 0x80 & ~mask & ~((inp_len - j) >> (sizeof(j) * 8 - 8));
+                data->c[res++] = (unsigned char)c;
+
+                if (res != SHA256_CBLOCK)
+                    continue;
+
+                /* j is not incremented yet */
+                mask = 0 - ((inp_len + 7 - j) >> (sizeof(j) * 8 - 1));
+                data->u[SHA_LBLOCK - 1] |= bitlen & mask;
+                sha256_block_data_order(&key->md, data, 1);
+                mask &= 0 - ((j - inp_len - 72) >> (sizeof(j) * 8 - 1));
+                pmac->u[0] |= key->md.h[0] & mask;
+                pmac->u[1] |= key->md.h[1] & mask;
+                pmac->u[2] |= key->md.h[2] & mask;
+                pmac->u[3] |= key->md.h[3] & mask;
+                pmac->u[4] |= key->md.h[4] & mask;
+                pmac->u[5] |= key->md.h[5] & mask;
+                pmac->u[6] |= key->md.h[6] & mask;
+                pmac->u[7] |= key->md.h[7] & mask;
+                res = 0;
+            }
+
+            for (i = res; i < SHA256_CBLOCK; i++, j++)
+                data->c[i] = 0;
+
+            if (res > SHA256_CBLOCK - 8) {
+                mask = 0 - ((inp_len + 8 - j) >> (sizeof(j) * 8 - 1));
+                data->u[SHA_LBLOCK - 1] |= bitlen & mask;
+                sha256_block_data_order(&key->md, data, 1);
+                mask &= 0 - ((j - inp_len - 73) >> (sizeof(j) * 8 - 1));
+                pmac->u[0] |= key->md.h[0] & mask;
+                pmac->u[1] |= key->md.h[1] & mask;
+                pmac->u[2] |= key->md.h[2] & mask;
+                pmac->u[3] |= key->md.h[3] & mask;
+                pmac->u[4] |= key->md.h[4] & mask;
+                pmac->u[5] |= key->md.h[5] & mask;
+                pmac->u[6] |= key->md.h[6] & mask;
+                pmac->u[7] |= key->md.h[7] & mask;
+
+                memset(data, 0, SHA256_CBLOCK);
+                j += 64;
+            }
+            data->u[SHA_LBLOCK - 1] = bitlen;
+            sha256_block_data_order(&key->md, data, 1);
+            mask = 0 - ((j - inp_len - 73) >> (sizeof(j) * 8 - 1));
+            pmac->u[0] |= key->md.h[0] & mask;
+            pmac->u[1] |= key->md.h[1] & mask;
+            pmac->u[2] |= key->md.h[2] & mask;
+            pmac->u[3] |= key->md.h[3] & mask;
+            pmac->u[4] |= key->md.h[4] & mask;
+            pmac->u[5] |= key->md.h[5] & mask;
+            pmac->u[6] |= key->md.h[6] & mask;
+            pmac->u[7] |= key->md.h[7] & mask;
+
+#ifdef BSWAP4
+            pmac->u[0] = BSWAP4(pmac->u[0]);
+            pmac->u[1] = BSWAP4(pmac->u[1]);
+            pmac->u[2] = BSWAP4(pmac->u[2]);
+            pmac->u[3] = BSWAP4(pmac->u[3]);
+            pmac->u[4] = BSWAP4(pmac->u[4]);
+            pmac->u[5] = BSWAP4(pmac->u[5]);
+            pmac->u[6] = BSWAP4(pmac->u[6]);
+            pmac->u[7] = BSWAP4(pmac->u[7]);
+#else
+            for (i = 0; i < 8; i++) {
+                res = pmac->u[i];
+                pmac->c[4 * i + 0] = (unsigned char)(res >> 24);
+                pmac->c[4 * i + 1] = (unsigned char)(res >> 16);
+                pmac->c[4 * i + 2] = (unsigned char)(res >> 8);
+                pmac->c[4 * i + 3] = (unsigned char)res;
+            }
+#endif
+            len += SHA256_DIGEST_LENGTH;
+#else
+            SHA256_Update(&key->md, out, inp_len);
+            res = key->md.num;
+            SHA256_Final(pmac->c, &key->md);
+
+            {
+                unsigned int inp_blocks, pad_blocks;
+
+                /* but pretend as if we hashed padded payload */
+                inp_blocks = 1 + ((SHA256_CBLOCK - 9 - res) >> (sizeof(res) * 8 - 1));
+                res += (unsigned int)(len - inp_len);
+                pad_blocks = res / SHA256_CBLOCK;
+                res %= SHA256_CBLOCK;
+                pad_blocks += 1 + ((SHA256_CBLOCK - 9 - res) >> (sizeof(res) * 8 - 1));
+                for (; inp_blocks < pad_blocks; inp_blocks++)
+                    sha1_block_data_order(&key->md, data, 1);
+            }
+#endif /* pre-lucky-13 reference version of above */
+            key->md = key->tail;
+            SHA256_Update(&key->md, pmac->c, SHA256_DIGEST_LENGTH);
+            SHA256_Final(pmac->c, &key->md);
+
+            /* verify HMAC */
+            out += inp_len;
+            len -= inp_len;
+#if 1 /* see original reference version in #else */
+            {
+                unsigned char *p = out + len - 1 - maxpad - SHA256_DIGEST_LENGTH;
+                size_t off = out - p;
+                unsigned int c, cmask;
+
+                for (res = 0, i = 0, j = 0; j < maxpad + SHA256_DIGEST_LENGTH;
+                    j++) {
+                    c = p[j];
+                    cmask = ((int)(j - off - SHA256_DIGEST_LENGTH)) >> (sizeof(int) * 8 - 1);
+                    res |= (c ^ pad) & ~cmask; /* ... and padding */
+                    cmask &= ((int)(off - 1 - j)) >> (sizeof(int) * 8 - 1);
+                    res |= (c ^ pmac->c[i]) & cmask;
+                    i += 1 & cmask;
+                }
+
+                res = 0 - ((0 - res) >> (sizeof(res) * 8 - 1));
+                ret &= (int)~res;
+            }
+#else /* pre-lucky-13 reference version of above */
+            for (res = 0, i = 0; i < SHA256_DIGEST_LENGTH; i++)
+                res |= out[i] ^ pmac->c[i];
+            res = 0 - ((0 - res) >> (sizeof(res) * 8 - 1));
+            ret &= (int)~res;
+
+            /* verify padding */
+            pad = (pad & ~res) | (maxpad & res);
+            out = out + len - 1 - pad;
+            for (res = 0, i = 0; i < pad; i++)
+                res |= out[i] ^ pad;
+
+            res = (0 - res) >> (sizeof(res) * 8 - 1);
+            ret &= (int)~res;
+#endif
+            return ret;
+        } else {
+            SHA256_Update(&key->md, out, len);
+        }
+    }
+
+    return 1;
+}
+
+static int aesni_cbc_hmac_sha256_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg,
+    void *ptr)
+{
+    EVP_AES_HMAC_SHA256 *key = data(ctx);
+    unsigned int u_arg = (unsigned int)arg;
+
+    switch (type) {
+    case EVP_CTRL_AEAD_SET_MAC_KEY: {
+        unsigned int i;
+        unsigned char hmac_key[64];
+
+        memset(hmac_key, 0, sizeof(hmac_key));
+
+        if (arg < 0)
+            return -1;
+
+        if (u_arg > sizeof(hmac_key)) {
+            SHA256_Init(&key->head);
+            SHA256_Update(&key->head, ptr, arg);
+            SHA256_Final(hmac_key, &key->head);
+        } else {
+            memcpy(hmac_key, ptr, arg);
+        }
+
+        for (i = 0; i < sizeof(hmac_key); i++)
+            hmac_key[i] ^= 0x36; /* ipad */
+        SHA256_Init(&key->head);
+        SHA256_Update(&key->head, hmac_key, sizeof(hmac_key));
+
+        for (i = 0; i < sizeof(hmac_key); i++)
+            hmac_key[i] ^= 0x36 ^ 0x5c; /* opad */
+        SHA256_Init(&key->tail);
+        SHA256_Update(&key->tail, hmac_key, sizeof(hmac_key));
+
+        OPENSSL_cleanse(hmac_key, sizeof(hmac_key));
+
+        return 1;
+    }
+    case EVP_CTRL_AEAD_TLS1_AAD: {
+        unsigned char *p = ptr;
+        unsigned int len;
+
+        if (arg != EVP_AEAD_TLS1_AAD_LEN)
+            return -1;
+
+        len = p[arg - 2] << 8 | p[arg - 1];
+
+        if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+            key->payload_length = len;
+            if ((key->aux.tls_ver = p[arg - 4] << 8 | p[arg - 3]) >= TLS1_1_VERSION) {
+                if (len < AES_BLOCK_SIZE)
+                    return 0;
+                len -= AES_BLOCK_SIZE;
+                p[arg - 2] = len >> 8;
+                p[arg - 1] = len;
+            }
+            key->md = key->head;
+            SHA256_Update(&key->md, p, arg);
+
+            return (int)(((len + SHA256_DIGEST_LENGTH + AES_BLOCK_SIZE) & -AES_BLOCK_SIZE)
+                - len);
+        } else {
+            memcpy(key->aux.tls_aad, ptr, arg);
+            key->payload_length = arg;
+
+            return SHA256_DIGEST_LENGTH;
+        }
+    }
+#if !defined(OPENSSL_NO_MULTIBLOCK)
+    case EVP_CTRL_TLS1_1_MULTIBLOCK_MAX_BUFSIZE:
+        return (int)(5 + 16 + ((arg + 32 + 16) & -16));
+    case EVP_CTRL_TLS1_1_MULTIBLOCK_AAD: {
+        EVP_CTRL_TLS1_1_MULTIBLOCK_PARAM *param = (EVP_CTRL_TLS1_1_MULTIBLOCK_PARAM *)ptr;
+        unsigned int n4x = 1, x4;
+        unsigned int frag, last, packlen, inp_len;
+
+        if (arg < 0)
+            return -1;
+
+        if (u_arg < sizeof(EVP_CTRL_TLS1_1_MULTIBLOCK_PARAM))
+            return -1;
+
+        inp_len = param->inp[11] << 8 | param->inp[12];
+
+        if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+            if ((param->inp[9] << 8 | param->inp[10]) < TLS1_1_VERSION)
+                return -1;
+
+            if (inp_len) {
+                if (inp_len < 4096)
+                    return 0; /* too short */
+
+                if (inp_len >= 8192 && OPENSSL_ia32cap_P[2] & (1 << 5))
+                    n4x = 2; /* AVX2 */
+            } else if ((n4x = param->interleave / 4) && n4x <= 2)
+                inp_len = (unsigned int)param->len;
+            else
+                return -1;
+
+            key->md = key->head;
+            SHA256_Update(&key->md, param->inp, 13);
+
+            x4 = 4 * n4x;
+            n4x += 1;
+
+            frag = inp_len >> n4x;
+            last = inp_len + frag - (frag << n4x);
+            if (last > frag && ((last + 13 + 9) % 64 < (x4 - 1))) {
+                frag++;
+                last -= x4 - 1;
+            }
+
+            packlen = 5 + 16 + ((frag + 32 + 16) & -16);
+            packlen = (packlen << n4x) - packlen;
+            packlen += 5 + 16 + ((last + 32 + 16) & -16);
+
+            param->interleave = x4;
+
+            return (int)packlen;
+        } else
+            return -1; /* not yet */
+    }
+    case EVP_CTRL_TLS1_1_MULTIBLOCK_ENCRYPT: {
+        EVP_CTRL_TLS1_1_MULTIBLOCK_PARAM *param = (EVP_CTRL_TLS1_1_MULTIBLOCK_PARAM *)ptr;
+
+        return (int)tls1_1_multi_block_encrypt(key, param->out,
+            param->inp, param->len,
+            param->interleave / 4);
+    }
+    case EVP_CTRL_TLS1_1_MULTIBLOCK_DECRYPT:
+#endif
+    default:
+        return -1;
+    }
+}
+
 static const EVP_CIPHER aesni_128_cbc_hmac_sha256_cipher = {
 #ifdef NID_aes_128_cbc_hmac_sha256
     NID_aes_128_cbc_hmac_sha256,
@@ -35,7 +879,15 @@ static const EVP_CIPHER aesni_128_cbc_hmac_sha256_cipher = {
 #endif
     AES_BLOCK_SIZE, 16, AES_BLOCK_SIZE,
     EVP_CIPH_CBC_MODE | EVP_CIPH_FLAG_DEFAULT_ASN1 | EVP_CIPH_FLAG_AEAD_CIPHER | EVP_CIPH_FLAG_TLS1_1_MULTIBLOCK,
-    EVP_ORIG_GLOBAL
+    EVP_ORIG_GLOBAL,
+    aesni_cbc_hmac_sha256_init_key,
+    aesni_cbc_hmac_sha256_cipher,
+    NULL,
+    sizeof(EVP_AES_HMAC_SHA256),
+    EVP_CIPH_FLAG_DEFAULT_ASN1 ? NULL : EVP_CIPHER_set_asn1_iv,
+    EVP_CIPH_FLAG_DEFAULT_ASN1 ? NULL : EVP_CIPHER_get_asn1_iv,
+    aesni_cbc_hmac_sha256_ctrl,
+    NULL
 };
 
 static const EVP_CIPHER aesni_256_cbc_hmac_sha256_cipher = {
@@ -46,7 +898,15 @@ static const EVP_CIPHER aesni_256_cbc_hmac_sha256_cipher = {
 #endif
     AES_BLOCK_SIZE, 32, AES_BLOCK_SIZE,
     EVP_CIPH_CBC_MODE | EVP_CIPH_FLAG_DEFAULT_ASN1 | EVP_CIPH_FLAG_AEAD_CIPHER | EVP_CIPH_FLAG_TLS1_1_MULTIBLOCK,
-    EVP_ORIG_GLOBAL
+    EVP_ORIG_GLOBAL,
+    aesni_cbc_hmac_sha256_init_key,
+    aesni_cbc_hmac_sha256_cipher,
+    NULL,
+    sizeof(EVP_AES_HMAC_SHA256),
+    EVP_CIPH_FLAG_DEFAULT_ASN1 ? NULL : EVP_CIPHER_set_asn1_iv,
+    EVP_CIPH_FLAG_DEFAULT_ASN1 ? NULL : EVP_CIPHER_get_asn1_iv,
+    aesni_cbc_hmac_sha256_ctrl,
+    NULL
 };
 
 const EVP_CIPHER *EVP_aes_128_cbc_hmac_sha256(void)
diff --git a/crypto/evp/e_aria.c b/crypto/evp/e_aria.c
index 4570e1823d..83e272232e 100644
--- a/crypto/evp/e_aria.c
+++ b/crypto/evp/e_aria.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright (c) 2017, Oracle and/or its affiliates.  All rights reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
@@ -8,20 +8,147 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include 
+#include "internal/deprecated.h"
 
+#include "internal/cryptlib.h"
 #ifndef OPENSSL_NO_ARIA
+#include 
+#include 
+#include 
+#include "crypto/aria.h"
 #include "crypto/evp.h"
+#include "crypto/modes.h"
+#include "evp_local.h"
+
+/* ARIA subkey Structure */
+typedef struct {
+    ARIA_KEY ks;
+} EVP_ARIA_KEY;
+
+/* ARIA GCM context */
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        ARIA_KEY ks;
+    } ks; /* ARIA subkey to use */
+    int key_set; /* Set if key initialised */
+    int iv_set; /* Set if an iv is set */
+    GCM128_CONTEXT gcm;
+    unsigned char *iv; /* Temporary IV store */
+    int ivlen; /* IV length */
+    int taglen;
+    int iv_gen; /* It is OK to generate IVs */
+    int tls_aad_len; /* TLS AAD length */
+} EVP_ARIA_GCM_CTX;
+
+/* ARIA CCM context */
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        ARIA_KEY ks;
+    } ks; /* ARIA key schedule to use */
+    int key_set; /* Set if key initialised */
+    int iv_set; /* Set if an iv is set */
+    int tag_set; /* Set if tag is valid */
+    int len_set; /* Set if message length set */
+    int L, M; /* L and M parameters from RFC3610 */
+    int tls_aad_len; /* TLS AAD length */
+    CCM128_CONTEXT ccm;
+    ccm128_f str;
+} EVP_ARIA_CCM_CTX;
+
+/* The subkey for ARIA is generated. */
+static int aria_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    int ret;
+    int mode = EVP_CIPHER_CTX_get_mode(ctx);
+
+    if (enc || (mode != EVP_CIPH_ECB_MODE && mode != EVP_CIPH_CBC_MODE))
+        ret = ossl_aria_set_encrypt_key(key,
+            EVP_CIPHER_CTX_get_key_length(ctx) * 8,
+            EVP_CIPHER_CTX_get_cipher_data(ctx));
+    else
+        ret = ossl_aria_set_decrypt_key(key,
+            EVP_CIPHER_CTX_get_key_length(ctx) * 8,
+            EVP_CIPHER_CTX_get_cipher_data(ctx));
+    if (ret < 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_ARIA_KEY_SETUP_FAILED);
+        return 0;
+    }
+    return 1;
+}
+
+static void aria_cbc_encrypt(const unsigned char *in, unsigned char *out,
+    size_t len, const ARIA_KEY *key,
+    unsigned char *ivec, const int enc)
+{
+
+    if (enc)
+        CRYPTO_cbc128_encrypt(in, out, len, key, ivec,
+            (block128_f)ossl_aria_encrypt);
+    else
+        CRYPTO_cbc128_decrypt(in, out, len, key, ivec,
+            (block128_f)ossl_aria_encrypt);
+}
+
+static void aria_cfb128_encrypt(const unsigned char *in, unsigned char *out,
+    size_t length, const ARIA_KEY *key,
+    unsigned char *ivec, int *num, const int enc)
+{
+
+    CRYPTO_cfb128_encrypt(in, out, length, key, ivec, num, enc,
+        (block128_f)ossl_aria_encrypt);
+}
+
+static void aria_cfb1_encrypt(const unsigned char *in, unsigned char *out,
+    size_t length, const ARIA_KEY *key,
+    unsigned char *ivec, int *num, const int enc)
+{
+    CRYPTO_cfb128_1_encrypt(in, out, length, key, ivec, num, enc,
+        (block128_f)ossl_aria_encrypt);
+}
+
+static void aria_cfb8_encrypt(const unsigned char *in, unsigned char *out,
+    size_t length, const ARIA_KEY *key,
+    unsigned char *ivec, int *num, const int enc)
+{
+    CRYPTO_cfb128_8_encrypt(in, out, length, key, ivec, num, enc,
+        (block128_f)ossl_aria_encrypt);
+}
+
+static void aria_ecb_encrypt(const unsigned char *in, unsigned char *out,
+    const ARIA_KEY *key, const int enc)
+{
+    ossl_aria_encrypt(in, out, key);
+}
+
+static void aria_ofb128_encrypt(const unsigned char *in, unsigned char *out,
+    size_t length, const ARIA_KEY *key,
+    unsigned char *ivec, int *num)
+{
+    CRYPTO_ofb128_encrypt(in, out, length, key, ivec, num,
+        (block128_f)ossl_aria_encrypt);
+}
 
 IMPLEMENT_BLOCK_CIPHER(aria_128, ks, aria, EVP_ARIA_KEY,
     NID_aria_128, 16, 16, 16, 128,
-    0)
+    0, aria_init_key, NULL,
+    EVP_CIPHER_set_asn1_iv,
+    EVP_CIPHER_get_asn1_iv,
+    NULL)
 IMPLEMENT_BLOCK_CIPHER(aria_192, ks, aria, EVP_ARIA_KEY,
     NID_aria_192, 16, 24, 16, 128,
-    0)
+    0, aria_init_key, NULL,
+    EVP_CIPHER_set_asn1_iv,
+    EVP_CIPHER_get_asn1_iv,
+    NULL)
 IMPLEMENT_BLOCK_CIPHER(aria_256, ks, aria, EVP_ARIA_KEY,
     NID_aria_256, 16, 32, 16, 128,
-    0)
+    0, aria_init_key, NULL,
+    EVP_CIPHER_set_asn1_iv,
+    EVP_CIPHER_get_asn1_iv,
+    NULL)
 
 #define IMPLEMENT_ARIA_CFBR(ksize, cbits) \
     IMPLEMENT_CFBR(aria, aria, EVP_ARIA_KEY, ks, ksize, cbits, 16, 0)
@@ -36,16 +163,596 @@ IMPLEMENT_ARIA_CFBR(256, 8)
     static const EVP_CIPHER aria_##keylen##_##mode = {                                \
         nid##_##keylen##_##nmode, blocksize, keylen / 8, ivlen,                       \
         flags | EVP_CIPH_##MODE##_MODE,                                               \
-        EVP_ORIG_GLOBAL                                                               \
+        EVP_ORIG_GLOBAL,                                                              \
+        aria_init_key,                                                                \
+        aria_##mode##_cipher,                                                         \
+        NULL,                                                                         \
+        sizeof(EVP_ARIA_KEY),                                                         \
+        NULL, NULL, NULL, NULL                                                        \
     };                                                                                \
     const EVP_CIPHER *EVP_aria_##keylen##_##mode(void)                                \
     {                                                                                 \
         return &aria_##keylen##_##mode;                                               \
     }
 
+static int aria_ctr_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    int n = EVP_CIPHER_CTX_get_num(ctx);
+    unsigned int num;
+    EVP_ARIA_KEY *dat = EVP_C_DATA(EVP_ARIA_KEY, ctx);
+
+    if (n < 0)
+        return 0;
+    num = (unsigned int)n;
+
+    CRYPTO_ctr128_encrypt(in, out, len, &dat->ks, ctx->iv,
+        EVP_CIPHER_CTX_buf_noconst(ctx), &num,
+        (block128_f)ossl_aria_encrypt);
+    EVP_CIPHER_CTX_set_num(ctx, num);
+    return 1;
+}
+
 BLOCK_CIPHER_generic(NID_aria, 128, 1, 16, ctr, ctr, CTR, 0)
-BLOCK_CIPHER_generic(NID_aria, 192, 1, 16, ctr, ctr, CTR, 0)
-BLOCK_CIPHER_generic(NID_aria, 256, 1, 16, ctr, ctr, CTR, 0)
+    BLOCK_CIPHER_generic(NID_aria, 192, 1, 16, ctr, ctr, CTR, 0)
+        BLOCK_CIPHER_generic(NID_aria, 256, 1, 16, ctr, ctr, CTR, 0)
+
+    /* Authenticated cipher modes (GCM/CCM) */
+
+    /* increment counter (64-bit int) by 1 */
+    static void ctr64_inc(unsigned char *counter)
+{
+    int n = 8;
+    unsigned char c;
+
+    do {
+        --n;
+        c = counter[n];
+        ++c;
+        counter[n] = c;
+        if (c)
+            return;
+    } while (n);
+}
+
+static int aria_gcm_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    int ret;
+    EVP_ARIA_GCM_CTX *gctx = EVP_C_DATA(EVP_ARIA_GCM_CTX, ctx);
+
+    if (!iv && !key)
+        return 1;
+    if (key) {
+        ret = ossl_aria_set_encrypt_key(key,
+            EVP_CIPHER_CTX_get_key_length(ctx) * 8,
+            &gctx->ks.ks);
+        CRYPTO_gcm128_init(&gctx->gcm, &gctx->ks,
+            (block128_f)ossl_aria_encrypt);
+        if (ret < 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_ARIA_KEY_SETUP_FAILED);
+            return 0;
+        }
+
+        /*
+         * If we have an iv can set it directly, otherwise use saved IV.
+         */
+        if (iv == NULL && gctx->iv_set)
+            iv = gctx->iv;
+        if (iv) {
+            CRYPTO_gcm128_setiv(&gctx->gcm, iv, gctx->ivlen);
+            gctx->iv_set = 1;
+        }
+        gctx->key_set = 1;
+    } else {
+        /* If key set use IV, otherwise copy */
+        if (gctx->key_set)
+            CRYPTO_gcm128_setiv(&gctx->gcm, iv, gctx->ivlen);
+        else
+            memcpy(gctx->iv, iv, gctx->ivlen);
+        gctx->iv_set = 1;
+        gctx->iv_gen = 0;
+    }
+    return 1;
+}
+
+static int aria_gcm_ctrl(EVP_CIPHER_CTX *c, int type, int arg, void *ptr)
+{
+    EVP_ARIA_GCM_CTX *gctx = EVP_C_DATA(EVP_ARIA_GCM_CTX, c);
+
+    switch (type) {
+    case EVP_CTRL_INIT:
+        gctx->key_set = 0;
+        gctx->iv_set = 0;
+        gctx->ivlen = EVP_CIPHER_get_iv_length(c->cipher);
+        gctx->iv = c->iv;
+        gctx->taglen = -1;
+        gctx->iv_gen = 0;
+        gctx->tls_aad_len = -1;
+        return 1;
+
+    case EVP_CTRL_GET_IVLEN:
+        *(int *)ptr = gctx->ivlen;
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_IVLEN:
+        if (arg <= 0)
+            return 0;
+        /* Allocate memory for IV if needed */
+        if ((arg > EVP_MAX_IV_LENGTH) && (arg > gctx->ivlen)) {
+            if (gctx->iv != c->iv)
+                OPENSSL_free(gctx->iv);
+            if ((gctx->iv = OPENSSL_malloc(arg)) == NULL)
+                return 0;
+        }
+        gctx->ivlen = arg;
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_TAG:
+        if (arg <= 0 || arg > 16 || EVP_CIPHER_CTX_is_encrypting(c))
+            return 0;
+        memcpy(EVP_CIPHER_CTX_buf_noconst(c), ptr, arg);
+        gctx->taglen = arg;
+        return 1;
+
+    case EVP_CTRL_AEAD_GET_TAG:
+        if (arg <= 0 || arg > 16 || !EVP_CIPHER_CTX_is_encrypting(c)
+            || gctx->taglen < 0)
+            return 0;
+        memcpy(ptr, EVP_CIPHER_CTX_buf_noconst(c), arg);
+        return 1;
+
+    case EVP_CTRL_GCM_SET_IV_FIXED:
+        /* Special case: -1 length restores whole IV */
+        if (arg == -1) {
+            memcpy(gctx->iv, ptr, gctx->ivlen);
+            gctx->iv_gen = 1;
+            return 1;
+        }
+        /*
+         * Fixed field must be at least 4 bytes and invocation field at least
+         * 8.
+         */
+        if ((arg < 4) || (gctx->ivlen - arg) < 8)
+            return 0;
+        if (arg)
+            memcpy(gctx->iv, ptr, arg);
+        if (EVP_CIPHER_CTX_is_encrypting(c)
+            && RAND_bytes(gctx->iv + arg, gctx->ivlen - arg) <= 0)
+            return 0;
+        gctx->iv_gen = 1;
+        return 1;
+
+    case EVP_CTRL_GCM_IV_GEN:
+        if (gctx->iv_gen == 0 || gctx->key_set == 0)
+            return 0;
+        CRYPTO_gcm128_setiv(&gctx->gcm, gctx->iv, gctx->ivlen);
+        if (arg <= 0 || arg > gctx->ivlen)
+            arg = gctx->ivlen;
+        memcpy(ptr, gctx->iv + gctx->ivlen - arg, arg);
+        /*
+         * Invocation field will be at least 8 bytes in size and so no need
+         * to check wrap around or increment more than last 8 bytes.
+         */
+        ctr64_inc(gctx->iv + gctx->ivlen - 8);
+        gctx->iv_set = 1;
+        return 1;
+
+    case EVP_CTRL_GCM_SET_IV_INV:
+        if (gctx->iv_gen == 0 || gctx->key_set == 0
+            || EVP_CIPHER_CTX_is_encrypting(c))
+            return 0;
+        memcpy(gctx->iv + gctx->ivlen - arg, ptr, arg);
+        CRYPTO_gcm128_setiv(&gctx->gcm, gctx->iv, gctx->ivlen);
+        gctx->iv_set = 1;
+        return 1;
+
+    case EVP_CTRL_AEAD_TLS1_AAD:
+        /* Save the AAD for later use */
+        if (arg != EVP_AEAD_TLS1_AAD_LEN)
+            return 0;
+        memcpy(EVP_CIPHER_CTX_buf_noconst(c), ptr, arg);
+        gctx->tls_aad_len = arg;
+        {
+            unsigned int len = EVP_CIPHER_CTX_buf_noconst(c)[arg - 2] << 8
+                | EVP_CIPHER_CTX_buf_noconst(c)[arg - 1];
+            /* Correct length for explicit IV */
+            if (len < EVP_GCM_TLS_EXPLICIT_IV_LEN)
+                return 0;
+            len -= EVP_GCM_TLS_EXPLICIT_IV_LEN;
+            /* If decrypting correct for tag too */
+            if (!EVP_CIPHER_CTX_is_encrypting(c)) {
+                if (len < EVP_GCM_TLS_TAG_LEN)
+                    return 0;
+                len -= EVP_GCM_TLS_TAG_LEN;
+            }
+            EVP_CIPHER_CTX_buf_noconst(c)[arg - 2] = len >> 8;
+            EVP_CIPHER_CTX_buf_noconst(c)[arg - 1] = len & 0xff;
+        }
+        /* Extra padding: tag appended to record */
+        return EVP_GCM_TLS_TAG_LEN;
+
+    case EVP_CTRL_COPY: {
+        EVP_CIPHER_CTX *out = ptr;
+        EVP_ARIA_GCM_CTX *gctx_out = EVP_C_DATA(EVP_ARIA_GCM_CTX, out);
+        if (gctx->gcm.key) {
+            if (gctx->gcm.key != &gctx->ks)
+                return 0;
+            gctx_out->gcm.key = &gctx_out->ks;
+        }
+        if (gctx->iv == c->iv)
+            gctx_out->iv = out->iv;
+        else {
+            if ((gctx_out->iv = OPENSSL_malloc(gctx->ivlen)) == NULL)
+                return 0;
+            memcpy(gctx_out->iv, gctx->iv, gctx->ivlen);
+        }
+        return 1;
+    }
+
+    default:
+        return -1;
+    }
+}
+
+static int aria_gcm_tls_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_ARIA_GCM_CTX *gctx = EVP_C_DATA(EVP_ARIA_GCM_CTX, ctx);
+    int rv = -1;
+
+    /* Encrypt/decrypt must be performed in place */
+    if (out != in
+        || len < (EVP_GCM_TLS_EXPLICIT_IV_LEN + EVP_GCM_TLS_TAG_LEN))
+        return -1;
+    /*
+     * Set IV from start of buffer or generate IV and write to start of
+     * buffer.
+     */
+    if (EVP_CIPHER_CTX_ctrl(ctx, EVP_CIPHER_CTX_is_encrypting(ctx) ? EVP_CTRL_GCM_IV_GEN : EVP_CTRL_GCM_SET_IV_INV,
+            EVP_GCM_TLS_EXPLICIT_IV_LEN, out)
+        <= 0)
+        goto err;
+    /* Use saved AAD */
+    if (CRYPTO_gcm128_aad(&gctx->gcm, EVP_CIPHER_CTX_buf_noconst(ctx),
+            gctx->tls_aad_len))
+        goto err;
+    /* Fix buffer and length to point to payload */
+    in += EVP_GCM_TLS_EXPLICIT_IV_LEN;
+    out += EVP_GCM_TLS_EXPLICIT_IV_LEN;
+    len -= EVP_GCM_TLS_EXPLICIT_IV_LEN + EVP_GCM_TLS_TAG_LEN;
+    if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+        /* Encrypt payload */
+        if (CRYPTO_gcm128_encrypt(&gctx->gcm, in, out, len))
+            goto err;
+        out += len;
+        /* Finally write tag */
+        CRYPTO_gcm128_tag(&gctx->gcm, out, EVP_GCM_TLS_TAG_LEN);
+        rv = (int)(len + EVP_GCM_TLS_EXPLICIT_IV_LEN + EVP_GCM_TLS_TAG_LEN);
+    } else {
+        /* Decrypt */
+        if (CRYPTO_gcm128_decrypt(&gctx->gcm, in, out, len))
+            goto err;
+        /* Retrieve tag */
+        CRYPTO_gcm128_tag(&gctx->gcm, EVP_CIPHER_CTX_buf_noconst(ctx),
+            EVP_GCM_TLS_TAG_LEN);
+        /* If tag mismatch wipe buffer */
+        if (CRYPTO_memcmp(EVP_CIPHER_CTX_buf_noconst(ctx), in + len,
+                EVP_GCM_TLS_TAG_LEN)) {
+            OPENSSL_cleanse(out, len);
+            goto err;
+        }
+        rv = (int)len;
+    }
+
+err:
+    gctx->iv_set = 0;
+    gctx->tls_aad_len = -1;
+    return rv;
+}
+
+static int aria_gcm_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_ARIA_GCM_CTX *gctx = EVP_C_DATA(EVP_ARIA_GCM_CTX, ctx);
+
+    /* If not set up, return error */
+    if (!gctx->key_set)
+        return -1;
+
+    if (gctx->tls_aad_len >= 0)
+        return aria_gcm_tls_cipher(ctx, out, in, len);
+
+    if (!gctx->iv_set)
+        return -1;
+    if (in) {
+        if (out == NULL) {
+            if (CRYPTO_gcm128_aad(&gctx->gcm, in, len))
+                return -1;
+        } else if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+            if (CRYPTO_gcm128_encrypt(&gctx->gcm, in, out, len))
+                return -1;
+        } else {
+            if (CRYPTO_gcm128_decrypt(&gctx->gcm, in, out, len))
+                return -1;
+        }
+        return (int)len;
+    }
+    if (!EVP_CIPHER_CTX_is_encrypting(ctx)) {
+        if (gctx->taglen < 0)
+            return -1;
+        if (CRYPTO_gcm128_finish(&gctx->gcm,
+                EVP_CIPHER_CTX_buf_noconst(ctx),
+                gctx->taglen)
+            != 0)
+            return -1;
+        gctx->iv_set = 0;
+        return 0;
+    }
+    CRYPTO_gcm128_tag(&gctx->gcm, EVP_CIPHER_CTX_buf_noconst(ctx), 16);
+    gctx->taglen = 16;
+    /* Don't reuse the IV */
+    gctx->iv_set = 0;
+    return 0;
+}
+
+static int aria_gcm_cleanup(EVP_CIPHER_CTX *ctx)
+{
+    EVP_ARIA_GCM_CTX *gctx = EVP_C_DATA(EVP_ARIA_GCM_CTX, ctx);
+
+    if (gctx->iv != ctx->iv)
+        OPENSSL_free(gctx->iv);
+
+    return 1;
+}
+
+static int aria_ccm_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    int ret;
+    EVP_ARIA_CCM_CTX *cctx = EVP_C_DATA(EVP_ARIA_CCM_CTX, ctx);
+
+    if (!iv && !key)
+        return 1;
+
+    if (key) {
+        ret = ossl_aria_set_encrypt_key(key,
+            EVP_CIPHER_CTX_get_key_length(ctx) * 8,
+            &cctx->ks.ks);
+        CRYPTO_ccm128_init(&cctx->ccm, cctx->M, cctx->L,
+            &cctx->ks, (block128_f)ossl_aria_encrypt);
+        if (ret < 0) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_ARIA_KEY_SETUP_FAILED);
+            return 0;
+        }
+        cctx->str = NULL;
+        cctx->key_set = 1;
+    }
+    if (iv) {
+        memcpy(ctx->iv, iv, 15 - cctx->L);
+        cctx->iv_set = 1;
+    }
+    return 1;
+}
+
+static int aria_ccm_ctrl(EVP_CIPHER_CTX *c, int type, int arg, void *ptr)
+{
+    EVP_ARIA_CCM_CTX *cctx = EVP_C_DATA(EVP_ARIA_CCM_CTX, c);
+
+    switch (type) {
+    case EVP_CTRL_INIT:
+        cctx->key_set = 0;
+        cctx->iv_set = 0;
+        cctx->L = 8;
+        cctx->M = 12;
+        cctx->tag_set = 0;
+        cctx->len_set = 0;
+        cctx->tls_aad_len = -1;
+        return 1;
+
+    case EVP_CTRL_GET_IVLEN:
+        *(int *)ptr = 15 - cctx->L;
+        return 1;
+
+    case EVP_CTRL_AEAD_TLS1_AAD:
+        /* Save the AAD for later use */
+        if (arg != EVP_AEAD_TLS1_AAD_LEN)
+            return 0;
+        memcpy(EVP_CIPHER_CTX_buf_noconst(c), ptr, arg);
+        cctx->tls_aad_len = arg;
+        {
+            uint16_t len = EVP_CIPHER_CTX_buf_noconst(c)[arg - 2] << 8
+                | EVP_CIPHER_CTX_buf_noconst(c)[arg - 1];
+            /* Correct length for explicit IV */
+            if (len < EVP_CCM_TLS_EXPLICIT_IV_LEN)
+                return 0;
+            len -= EVP_CCM_TLS_EXPLICIT_IV_LEN;
+            /* If decrypting correct for tag too */
+            if (!EVP_CIPHER_CTX_is_encrypting(c)) {
+                if (len < cctx->M)
+                    return 0;
+                len -= cctx->M;
+            }
+            EVP_CIPHER_CTX_buf_noconst(c)[arg - 2] = len >> 8;
+            EVP_CIPHER_CTX_buf_noconst(c)[arg - 1] = len & 0xff;
+        }
+        /* Extra padding: tag appended to record */
+        return cctx->M;
+
+    case EVP_CTRL_CCM_SET_IV_FIXED:
+        /* Sanity check length */
+        if (arg != EVP_CCM_TLS_FIXED_IV_LEN)
+            return 0;
+        /* Just copy to first part of IV */
+        memcpy(c->iv, ptr, arg);
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_IVLEN:
+        arg = 15 - arg;
+        /* fall through */
+    case EVP_CTRL_CCM_SET_L:
+        if (arg < 2 || arg > 8)
+            return 0;
+        cctx->L = arg;
+        return 1;
+    case EVP_CTRL_AEAD_SET_TAG:
+        if ((arg & 1) || arg < 4 || arg > 16)
+            return 0;
+        if (EVP_CIPHER_CTX_is_encrypting(c) && ptr)
+            return 0;
+        if (ptr) {
+            cctx->tag_set = 1;
+            memcpy(EVP_CIPHER_CTX_buf_noconst(c), ptr, arg);
+        }
+        cctx->M = arg;
+        return 1;
+
+    case EVP_CTRL_AEAD_GET_TAG:
+        if (!EVP_CIPHER_CTX_is_encrypting(c) || !cctx->tag_set)
+            return 0;
+        if (!CRYPTO_ccm128_tag(&cctx->ccm, ptr, (size_t)arg))
+            return 0;
+        cctx->tag_set = 0;
+        cctx->iv_set = 0;
+        cctx->len_set = 0;
+        return 1;
+
+    case EVP_CTRL_COPY: {
+        EVP_CIPHER_CTX *out = ptr;
+        EVP_ARIA_CCM_CTX *cctx_out = EVP_C_DATA(EVP_ARIA_CCM_CTX, out);
+        if (cctx->ccm.key) {
+            if (cctx->ccm.key != &cctx->ks)
+                return 0;
+            cctx_out->ccm.key = &cctx_out->ks;
+        }
+        return 1;
+    }
+
+    default:
+        return -1;
+    }
+}
+
+static int aria_ccm_tls_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_ARIA_CCM_CTX *cctx = EVP_C_DATA(EVP_ARIA_CCM_CTX, ctx);
+    CCM128_CONTEXT *ccm = &cctx->ccm;
+
+    /* Encrypt/decrypt must be performed in place */
+    if (out != in || len < (EVP_CCM_TLS_EXPLICIT_IV_LEN + (size_t)cctx->M))
+        return -1;
+    /* If encrypting set explicit IV from sequence number (start of AAD) */
+    if (EVP_CIPHER_CTX_is_encrypting(ctx))
+        memcpy(out, EVP_CIPHER_CTX_buf_noconst(ctx),
+            EVP_CCM_TLS_EXPLICIT_IV_LEN);
+    /* Get rest of IV from explicit IV */
+    memcpy(ctx->iv + EVP_CCM_TLS_FIXED_IV_LEN, in,
+        EVP_CCM_TLS_EXPLICIT_IV_LEN);
+    /* Correct length value */
+    len -= EVP_CCM_TLS_EXPLICIT_IV_LEN + cctx->M;
+    if (CRYPTO_ccm128_setiv(ccm, ctx->iv, 15 - cctx->L,
+            len))
+        return -1;
+    /* Use saved AAD */
+    CRYPTO_ccm128_aad(ccm, EVP_CIPHER_CTX_buf_noconst(ctx),
+        cctx->tls_aad_len);
+    /* Fix buffer to point to payload */
+    in += EVP_CCM_TLS_EXPLICIT_IV_LEN;
+    out += EVP_CCM_TLS_EXPLICIT_IV_LEN;
+    if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+        if (cctx->str ? CRYPTO_ccm128_encrypt_ccm64(ccm, in, out, len, cctx->str)
+                      : CRYPTO_ccm128_encrypt(ccm, in, out, len))
+            return -1;
+        if (!CRYPTO_ccm128_tag(ccm, out + len, cctx->M))
+            return -1;
+        return (int)(len + EVP_CCM_TLS_EXPLICIT_IV_LEN + cctx->M);
+    } else {
+        if (cctx->str ? !CRYPTO_ccm128_decrypt_ccm64(ccm, in, out, len, cctx->str)
+                      : !CRYPTO_ccm128_decrypt(ccm, in, out, len)) {
+            unsigned char tag[16];
+            if (CRYPTO_ccm128_tag(ccm, tag, cctx->M)) {
+                if (!CRYPTO_memcmp(tag, in + len, cctx->M))
+                    return (int)len;
+            }
+        }
+        OPENSSL_cleanse(out, len);
+        return -1;
+    }
+}
+
+static int aria_ccm_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_ARIA_CCM_CTX *cctx = EVP_C_DATA(EVP_ARIA_CCM_CTX, ctx);
+    CCM128_CONTEXT *ccm = &cctx->ccm;
+
+    /* If not set up, return error */
+    if (!cctx->key_set)
+        return -1;
+
+    if (cctx->tls_aad_len >= 0)
+        return aria_ccm_tls_cipher(ctx, out, in, len);
+
+    /* EVP_*Final() doesn't return any data */
+    if (in == NULL && out != NULL)
+        return 0;
+
+    if (!cctx->iv_set)
+        return -1;
+
+    if (!out) {
+        if (!in) {
+            if (CRYPTO_ccm128_setiv(ccm, ctx->iv, 15 - cctx->L, len))
+                return -1;
+            cctx->len_set = 1;
+            return (int)len;
+        }
+        /* If have AAD need message length */
+        if (!cctx->len_set && len)
+            return -1;
+        CRYPTO_ccm128_aad(ccm, in, len);
+        return (int)len;
+    }
+
+    /* The tag must be set before actually decrypting data */
+    if (!EVP_CIPHER_CTX_is_encrypting(ctx) && !cctx->tag_set)
+        return -1;
+
+    /* If not set length yet do it */
+    if (!cctx->len_set) {
+        if (CRYPTO_ccm128_setiv(ccm, ctx->iv, 15 - cctx->L, len))
+            return -1;
+        cctx->len_set = 1;
+    }
+    if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+        if (cctx->str ? CRYPTO_ccm128_encrypt_ccm64(ccm, in, out, len, cctx->str)
+                      : CRYPTO_ccm128_encrypt(ccm, in, out, len))
+            return -1;
+        cctx->tag_set = 1;
+        return (int)len;
+    } else {
+        int rv = -1;
+        if (cctx->str ? !CRYPTO_ccm128_decrypt_ccm64(ccm, in, out, len,
+                            cctx->str)
+                      : !CRYPTO_ccm128_decrypt(ccm, in, out, len)) {
+            unsigned char tag[16];
+            if (CRYPTO_ccm128_tag(ccm, tag, cctx->M)) {
+                if (!CRYPTO_memcmp(tag, EVP_CIPHER_CTX_buf_noconst(ctx),
+                        cctx->M))
+                    rv = (int)len;
+            }
+        }
+        if (rv == -1)
+            OPENSSL_cleanse(out, len);
+        cctx->iv_set = 0;
+        cctx->tag_set = 0;
+        cctx->len_set = 0;
+        return rv;
+    }
+}
+
+#define aria_ccm_cleanup NULL
 
 #define ARIA_AUTH_FLAGS (EVP_CIPH_FLAG_DEFAULT_ASN1    \
     | EVP_CIPH_CUSTOM_IV | EVP_CIPH_FLAG_CUSTOM_CIPHER \
@@ -58,7 +765,12 @@ BLOCK_CIPHER_generic(NID_aria, 256, 1, 16, ctr, ctr, CTR, 0)
         NID_aria_##keylen##_##mode,                    \
         1, keylen / 8, 12,                             \
         ARIA_AUTH_FLAGS | EVP_CIPH_##MODE##_MODE,      \
-        EVP_ORIG_GLOBAL                                \
+        EVP_ORIG_GLOBAL,                               \
+        aria_##mode##_init_key,                        \
+        aria_##mode##_cipher,                          \
+        aria_##mode##_cleanup,                         \
+        sizeof(EVP_ARIA_##MODE##_CTX),                 \
+        NULL, NULL, aria_##mode##_ctrl, NULL           \
     };                                                 \
     const EVP_CIPHER *EVP_aria_##keylen##_##mode(void) \
     {                                                  \
@@ -66,13 +778,11 @@ BLOCK_CIPHER_generic(NID_aria, 256, 1, 16, ctr, ctr, CTR, 0)
     }
 
 BLOCK_CIPHER_aead(128, gcm, GCM)
-BLOCK_CIPHER_aead(192, gcm, GCM)
-BLOCK_CIPHER_aead(256, gcm, GCM)
+    BLOCK_CIPHER_aead(192, gcm, GCM)
+        BLOCK_CIPHER_aead(256, gcm, GCM)
 
-BLOCK_CIPHER_aead(128, ccm, CCM)
-BLOCK_CIPHER_aead(192, ccm, CCM)
-BLOCK_CIPHER_aead(256, ccm, CCM)
+            BLOCK_CIPHER_aead(128, ccm, CCM)
+                BLOCK_CIPHER_aead(192, ccm, CCM)
+                    BLOCK_CIPHER_aead(256, ccm, CCM)
 
-#else
-NON_EMPTY_TRANSLATION_UNIT
 #endif
diff --git a/crypto/evp/e_bf.c b/crypto/evp/e_bf.c
index 3910bb0c61..8cac877e91 100644
--- a/crypto/evp/e_bf.c
+++ b/crypto/evp/e_bf.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,13 +7,43 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include 
+/*
+ * BF low level APIs are deprecated for public use, but still ok for internal
+ * use.
+ */
+#include "internal/deprecated.h"
 
+#include 
+#include "internal/cryptlib.h"
 #ifndef OPENSSL_NO_BF
+#include 
 #include "crypto/evp.h"
+#include 
+#include 
+#include "evp_local.h"
+
+static int bf_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc);
+
+typedef struct {
+    BF_KEY ks;
+} EVP_BF_KEY;
+
+#define data(ctx) EVP_C_DATA(EVP_BF_KEY, ctx)
 
 IMPLEMENT_BLOCK_CIPHER(bf, ks, BF, EVP_BF_KEY, NID_bf, 8, 16, 8, 64,
-    EVP_CIPH_VARIABLE_LENGTH)
-#else
-NON_EMPTY_TRANSLATION_UNIT
+    EVP_CIPH_VARIABLE_LENGTH, bf_init_key, NULL,
+    EVP_CIPHER_set_asn1_iv, EVP_CIPHER_get_asn1_iv, NULL)
+
+static int bf_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    int len = EVP_CIPHER_CTX_get_key_length(ctx);
+
+    if (len < 0)
+        return 0;
+    BF_set_key(&data(ctx)->ks, len, key);
+    return 1;
+}
+
 #endif
diff --git a/crypto/evp/e_camellia.c b/crypto/evp/e_camellia.c
index 2549cd871d..c994bb395d 100644
--- a/crypto/evp/e_camellia.c
+++ b/crypto/evp/e_camellia.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,31 +7,345 @@
  * https://www.openssl.org/source/license.html
  */
 
+/*
+ * Camellia low level APIs are deprecated for public use, but still ok for
+ * internal use.
+ */
+#include "internal/deprecated.h"
+
+#include 
+
+#include 
+#include 
+#include 
+#include 
+#include 
 #include "crypto/evp.h"
+#include "crypto/modes.h"
+#include "crypto/cmll_platform.h"
+#include "evp_local.h"
+
+static int camellia_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc);
+
+/* Camellia subkey Structure */
+typedef struct {
+    CAMELLIA_KEY ks;
+    block128_f block;
+    union {
+        cbc128_f cbc;
+        ctr128_f ctr;
+    } stream;
+} EVP_CAMELLIA_KEY;
+
+#define MAXBITCHUNK ((size_t)1 << (sizeof(size_t) * 8 - 4))
+
+/* Attribute operation for Camellia */
+#define data(ctx) EVP_C_DATA(EVP_CAMELLIA_KEY, ctx)
+
+#if defined(AES_ASM) && (defined(__sparc) || defined(__sparc__))
+/* ---------^^^ this is not a typo, just a way to detect that
+ * assembler support was in general requested... */
+#include "crypto/sparc_arch.h"
+
+static int cmll_t4_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    int ret, mode, bits;
+    EVP_CAMELLIA_KEY *dat = (EVP_CAMELLIA_KEY *)EVP_CIPHER_CTX_get_cipher_data(ctx);
+
+    mode = EVP_CIPHER_CTX_get_mode(ctx);
+    bits = EVP_CIPHER_CTX_get_key_length(ctx) * 8;
+
+    cmll_t4_set_key(key, bits, &dat->ks);
+
+    if ((mode == EVP_CIPH_ECB_MODE || mode == EVP_CIPH_CBC_MODE)
+        && !enc) {
+        ret = 0;
+        dat->block = (block128_f)cmll_t4_decrypt;
+        switch (bits) {
+        case 128:
+            dat->stream.cbc = mode == EVP_CIPH_CBC_MODE ? (cbc128_f)cmll128_t4_cbc_decrypt : NULL;
+            break;
+        case 192:
+        case 256:
+            dat->stream.cbc = mode == EVP_CIPH_CBC_MODE ? (cbc128_f)cmll256_t4_cbc_decrypt : NULL;
+            break;
+        default:
+            ret = -1;
+        }
+    } else {
+        ret = 0;
+        dat->block = (block128_f)cmll_t4_encrypt;
+        switch (bits) {
+        case 128:
+            if (mode == EVP_CIPH_CBC_MODE)
+                dat->stream.cbc = (cbc128_f)cmll128_t4_cbc_encrypt;
+            else if (mode == EVP_CIPH_CTR_MODE)
+                dat->stream.ctr = (ctr128_f)cmll128_t4_ctr32_encrypt;
+            else
+                dat->stream.cbc = NULL;
+            break;
+        case 192:
+        case 256:
+            if (mode == EVP_CIPH_CBC_MODE)
+                dat->stream.cbc = (cbc128_f)cmll256_t4_cbc_encrypt;
+            else if (mode == EVP_CIPH_CTR_MODE)
+                dat->stream.ctr = (ctr128_f)cmll256_t4_ctr32_encrypt;
+            else
+                dat->stream.cbc = NULL;
+            break;
+        default:
+            ret = -1;
+        }
+    }
+
+    if (ret < 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_CAMELLIA_KEY_SETUP_FAILED);
+        return 0;
+    }
+
+    return 1;
+}
+
+#define cmll_t4_cbc_cipher camellia_cbc_cipher
+static int cmll_t4_cbc_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define cmll_t4_ecb_cipher camellia_ecb_cipher
+static int cmll_t4_ecb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define cmll_t4_ofb_cipher camellia_ofb_cipher
+static int cmll_t4_ofb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define cmll_t4_cfb_cipher camellia_cfb_cipher
+static int cmll_t4_cfb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define cmll_t4_cfb8_cipher camellia_cfb8_cipher
+static int cmll_t4_cfb8_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define cmll_t4_cfb1_cipher camellia_cfb1_cipher
+static int cmll_t4_cfb1_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define cmll_t4_ctr_cipher camellia_ctr_cipher
+static int cmll_t4_ctr_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len);
+
+#define BLOCK_CIPHER_generic(nid, keylen, blocksize, ivlen, nmode, mode, MODE, flags)         \
+    static const EVP_CIPHER cmll_t4_##keylen##_##mode = {                                     \
+        nid##_##keylen##_##nmode, blocksize, keylen / 8, ivlen,                               \
+        flags | EVP_CIPH_##MODE##_MODE,                                                       \
+        EVP_ORIG_GLOBAL,                                                                      \
+        cmll_t4_init_key,                                                                     \
+        cmll_t4_##mode##_cipher,                                                              \
+        NULL,                                                                                 \
+        sizeof(EVP_CAMELLIA_KEY),                                                             \
+        NULL, NULL, NULL, NULL                                                                \
+    };                                                                                        \
+    static const EVP_CIPHER camellia_##keylen##_##mode = {                                    \
+        nid##_##keylen##_##nmode, blocksize,                                                  \
+        keylen / 8, ivlen,                                                                    \
+        flags | EVP_CIPH_##MODE##_MODE,                                                       \
+        EVP_ORIG_GLOBAL,                                                                      \
+        camellia_init_key,                                                                    \
+        camellia_##mode##_cipher,                                                             \
+        NULL,                                                                                 \
+        sizeof(EVP_CAMELLIA_KEY),                                                             \
+        NULL, NULL, NULL, NULL                                                                \
+    };                                                                                        \
+    const EVP_CIPHER *EVP_camellia_##keylen##_##mode(void)                                    \
+    {                                                                                         \
+        return SPARC_CMLL_CAPABLE ? &cmll_t4_##keylen##_##mode : &camellia_##keylen##_##mode; \
+    }
+
+#else
 
 #define BLOCK_CIPHER_generic(nid, keylen, blocksize, ivlen, nmode, mode, MODE, flags) \
     static const EVP_CIPHER camellia_##keylen##_##mode = {                            \
-        nid##_##keylen##_##nmode,                                                     \
-        blocksize,                                                                    \
-        keylen / 8,                                                                   \
-        ivlen,                                                                        \
+        nid##_##keylen##_##nmode, blocksize, keylen / 8, ivlen,                       \
         flags | EVP_CIPH_##MODE##_MODE,                                               \
         EVP_ORIG_GLOBAL,                                                              \
+        camellia_init_key,                                                            \
+        camellia_##mode##_cipher,                                                     \
+        NULL,                                                                         \
+        sizeof(EVP_CAMELLIA_KEY),                                                     \
+        NULL, NULL, NULL, NULL                                                        \
     };                                                                                \
     const EVP_CIPHER *EVP_camellia_##keylen##_##mode(void)                            \
     {                                                                                 \
         return &camellia_##keylen##_##mode;                                           \
     }
 
-#define BLOCK_CIPHER_generic_pack(nid, keylen, flags)                                              \
-    BLOCK_CIPHER_generic(nid, keylen, 16, 16, cbc, cbc, CBC, flags | EVP_CIPH_FLAG_DEFAULT_ASN1)   \
-    BLOCK_CIPHER_generic(nid, keylen, 16, 0, ecb, ecb, ECB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1)    \
-    BLOCK_CIPHER_generic(nid, keylen, 1, 16, ofb128, ofb, OFB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1) \
-    BLOCK_CIPHER_generic(nid, keylen, 1, 16, cfb128, cfb, CFB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1) \
-    BLOCK_CIPHER_generic(nid, keylen, 1, 16, cfb1, cfb1, CFB, flags)                               \
-    BLOCK_CIPHER_generic(nid, keylen, 1, 16, cfb8, cfb8, CFB, flags)                               \
-    BLOCK_CIPHER_generic(nid, keylen, 1, 16, ctr, ctr, CTR, flags)
+#endif
+
+#define BLOCK_CIPHER_generic_pack(nid, keylen, flags)                                                          \
+    BLOCK_CIPHER_generic(nid, keylen, 16, 16, cbc, cbc, CBC, flags | EVP_CIPH_FLAG_DEFAULT_ASN1)               \
+        BLOCK_CIPHER_generic(nid, keylen, 16, 0, ecb, ecb, ECB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1)            \
+            BLOCK_CIPHER_generic(nid, keylen, 1, 16, ofb128, ofb, OFB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1)     \
+                BLOCK_CIPHER_generic(nid, keylen, 1, 16, cfb128, cfb, CFB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1) \
+                    BLOCK_CIPHER_generic(nid, keylen, 1, 16, cfb1, cfb1, CFB, flags)                           \
+                        BLOCK_CIPHER_generic(nid, keylen, 1, 16, cfb8, cfb8, CFB, flags)                       \
+                            BLOCK_CIPHER_generic(nid, keylen, 1, 16, ctr, ctr, CTR, flags)
+
+/* The subkey for Camellia is generated. */
+static int camellia_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    int ret, mode;
+    EVP_CAMELLIA_KEY *dat = EVP_C_DATA(EVP_CAMELLIA_KEY, ctx);
+
+    ret = Camellia_set_key(key, EVP_CIPHER_CTX_get_key_length(ctx) * 8,
+        &dat->ks);
+    if (ret < 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_CAMELLIA_KEY_SETUP_FAILED);
+        return 0;
+    }
+
+    mode = EVP_CIPHER_CTX_get_mode(ctx);
+    if ((mode == EVP_CIPH_ECB_MODE || mode == EVP_CIPH_CBC_MODE)
+        && !enc) {
+        dat->block = (block128_f)Camellia_decrypt;
+        dat->stream.cbc = mode == EVP_CIPH_CBC_MODE ? (cbc128_f)Camellia_cbc_encrypt : NULL;
+    } else {
+        dat->block = (block128_f)Camellia_encrypt;
+        dat->stream.cbc = mode == EVP_CIPH_CBC_MODE ? (cbc128_f)Camellia_cbc_encrypt : NULL;
+    }
+
+    return 1;
+}
+
+static int camellia_cbc_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_CAMELLIA_KEY *dat = EVP_C_DATA(EVP_CAMELLIA_KEY, ctx);
+
+    if (dat->stream.cbc)
+        (*dat->stream.cbc)(in, out, len, &dat->ks, ctx->iv,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+    else if (EVP_CIPHER_CTX_is_encrypting(ctx))
+        CRYPTO_cbc128_encrypt(in, out, len, &dat->ks, ctx->iv, dat->block);
+    else
+        CRYPTO_cbc128_decrypt(in, out, len, &dat->ks, ctx->iv, dat->block);
+
+    return 1;
+}
+
+static int camellia_ecb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    size_t bl = EVP_CIPHER_CTX_get_block_size(ctx);
+    size_t i;
+    EVP_CAMELLIA_KEY *dat = EVP_C_DATA(EVP_CAMELLIA_KEY, ctx);
+
+    if (len < bl)
+        return 1;
+
+    for (i = 0, len -= bl; i <= len; i += bl)
+        (*dat->block)(in + i, out + i, &dat->ks);
+
+    return 1;
+}
+
+static int camellia_ofb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_CAMELLIA_KEY *dat = EVP_C_DATA(EVP_CAMELLIA_KEY, ctx);
+
+    int num = EVP_CIPHER_CTX_get_num(ctx);
+    CRYPTO_ofb128_encrypt(in, out, len, &dat->ks, ctx->iv, &num, dat->block);
+    EVP_CIPHER_CTX_set_num(ctx, num);
+    return 1;
+}
+
+static int camellia_cfb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_CAMELLIA_KEY *dat = EVP_C_DATA(EVP_CAMELLIA_KEY, ctx);
+
+    int num = EVP_CIPHER_CTX_get_num(ctx);
+    CRYPTO_cfb128_encrypt(in, out, len, &dat->ks, ctx->iv, &num,
+        EVP_CIPHER_CTX_is_encrypting(ctx), dat->block);
+    EVP_CIPHER_CTX_set_num(ctx, num);
+    return 1;
+}
+
+static int camellia_cfb8_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_CAMELLIA_KEY *dat = EVP_C_DATA(EVP_CAMELLIA_KEY, ctx);
+
+    int num = EVP_CIPHER_CTX_get_num(ctx);
+    CRYPTO_cfb128_8_encrypt(in, out, len, &dat->ks, ctx->iv, &num,
+        EVP_CIPHER_CTX_is_encrypting(ctx), dat->block);
+    EVP_CIPHER_CTX_set_num(ctx, num);
+    return 1;
+}
+
+static int camellia_cfb1_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_CAMELLIA_KEY *dat = EVP_C_DATA(EVP_CAMELLIA_KEY, ctx);
+
+    if (EVP_CIPHER_CTX_test_flags(ctx, EVP_CIPH_FLAG_LENGTH_BITS)) {
+        int num = EVP_CIPHER_CTX_get_num(ctx);
+        CRYPTO_cfb128_1_encrypt(in, out, len, &dat->ks, ctx->iv, &num,
+            EVP_CIPHER_CTX_is_encrypting(ctx),
+            dat->block);
+        EVP_CIPHER_CTX_set_num(ctx, num);
+        return 1;
+    }
+
+    while (len >= MAXBITCHUNK) {
+        int num = EVP_CIPHER_CTX_get_num(ctx);
+        CRYPTO_cfb128_1_encrypt(in, out, MAXBITCHUNK * 8, &dat->ks,
+            ctx->iv, &num,
+            EVP_CIPHER_CTX_is_encrypting(ctx),
+            dat->block);
+        EVP_CIPHER_CTX_set_num(ctx, num);
+        len -= MAXBITCHUNK;
+        out += MAXBITCHUNK;
+        in += MAXBITCHUNK;
+    }
+    if (len) {
+        int num = EVP_CIPHER_CTX_get_num(ctx);
+        CRYPTO_cfb128_1_encrypt(in, out, len * 8, &dat->ks,
+            ctx->iv, &num,
+            EVP_CIPHER_CTX_is_encrypting(ctx),
+            dat->block);
+        EVP_CIPHER_CTX_set_num(ctx, num);
+    }
+
+    return 1;
+}
+
+static int camellia_ctr_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    int snum = EVP_CIPHER_CTX_get_num(ctx);
+    unsigned int num;
+    EVP_CAMELLIA_KEY *dat = EVP_C_DATA(EVP_CAMELLIA_KEY, ctx);
+
+    if (snum < 0)
+        return 0;
+    num = snum;
+    if (dat->stream.ctr)
+        CRYPTO_ctr128_encrypt_ctr32(in, out, len, &dat->ks, ctx->iv,
+            EVP_CIPHER_CTX_buf_noconst(ctx),
+            &num,
+            dat->stream.ctr);
+    else
+        CRYPTO_ctr128_encrypt(in, out, len, &dat->ks, ctx->iv,
+            EVP_CIPHER_CTX_buf_noconst(ctx), &num,
+            dat->block);
+    EVP_CIPHER_CTX_set_num(ctx, num);
+    return 1;
+}
 
 BLOCK_CIPHER_generic_pack(NID_camellia, 128, 0)
-BLOCK_CIPHER_generic_pack(NID_camellia, 192, 0)
-BLOCK_CIPHER_generic_pack(NID_camellia, 256, 0)
+    BLOCK_CIPHER_generic_pack(NID_camellia, 192, 0)
+        BLOCK_CIPHER_generic_pack(NID_camellia, 256, 0)
diff --git a/crypto/evp/e_cast.c b/crypto/evp/e_cast.c
index bffe971dd0..f45469e821 100644
--- a/crypto/evp/e_cast.c
+++ b/crypto/evp/e_cast.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,16 +7,45 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include 
+/*
+ * CAST low level APIs are deprecated for public use, but still ok for
+ * internal use.
+ */
+#include "internal/deprecated.h"
+
+#include 
+#include "internal/cryptlib.h"
 
 #ifndef OPENSSL_NO_CAST
-#include 
+#include 
+#include 
 #include "crypto/evp.h"
+#include 
+#include "evp_local.h"
+
+static int cast_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc);
+
+typedef struct {
+    CAST_KEY ks;
+} EVP_CAST_KEY;
+
+#define data(ctx) EVP_C_DATA(EVP_CAST_KEY, ctx)
 
 IMPLEMENT_BLOCK_CIPHER(cast5, ks, CAST, EVP_CAST_KEY,
     NID_cast5, 8, CAST_KEY_LENGTH, 8, 64,
-    EVP_CIPH_VARIABLE_LENGTH)
+    EVP_CIPH_VARIABLE_LENGTH, cast_init_key, NULL,
+    EVP_CIPHER_set_asn1_iv, EVP_CIPHER_get_asn1_iv, NULL)
+
+static int cast_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    int keylen = EVP_CIPHER_CTX_get_key_length(ctx);
+
+    if (keylen <= 0)
+        return 0;
+    CAST_set_key(&data(ctx)->ks, keylen, key);
+    return 1;
+}
 
-#else
-NON_EMPTY_TRANSLATION_UNIT
 #endif
diff --git a/crypto/evp/e_chacha20_poly1305.c b/crypto/evp/e_chacha20_poly1305.c
index 78dbe45ce4..4db2fd12f9 100644
--- a/crypto/evp/e_chacha20_poly1305.c
+++ b/crypto/evp/e_chacha20_poly1305.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,20 +7,140 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include 
+#include 
+#include "internal/cryptlib.h"
+#include "internal/endian.h"
 
 #ifndef OPENSSL_NO_CHACHA
 
+#include 
+#include 
 #include "crypto/evp.h"
+#include "evp_local.h"
 #include "crypto/chacha.h"
 
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN; /* this ensures even sizeof(EVP_CHACHA_KEY)%8==0 */
+        unsigned int d[CHACHA_KEY_SIZE / 4];
+    } key;
+    unsigned int counter[CHACHA_CTR_SIZE / 4];
+    unsigned char buf[CHACHA_BLK_SIZE];
+    unsigned int partial_len;
+} EVP_CHACHA_KEY;
+
+#define data(ctx) ((EVP_CHACHA_KEY *)(ctx)->cipher_data)
+
+#define CHACHA20_POLY1305_MAX_IVLEN 12
+
+static int chacha_init_key(EVP_CIPHER_CTX *ctx,
+    const unsigned char user_key[CHACHA_KEY_SIZE],
+    const unsigned char iv[CHACHA_CTR_SIZE], int enc)
+{
+    EVP_CHACHA_KEY *key = data(ctx);
+    unsigned int i;
+
+    if (user_key)
+        for (i = 0; i < CHACHA_KEY_SIZE; i += 4) {
+            key->key.d[i / 4] = CHACHA_U8TOU32(user_key + i);
+        }
+
+    if (iv)
+        for (i = 0; i < CHACHA_CTR_SIZE; i += 4) {
+            key->counter[i / 4] = CHACHA_U8TOU32(iv + i);
+        }
+
+    key->partial_len = 0;
+
+    return 1;
+}
+
+static int chacha_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *inp, size_t len)
+{
+    EVP_CHACHA_KEY *key = data(ctx);
+    unsigned int n, rem, ctr32;
+
+    if ((n = key->partial_len)) {
+        while (len && n < CHACHA_BLK_SIZE) {
+            *out++ = *inp++ ^ key->buf[n++];
+            len--;
+        }
+        key->partial_len = n;
+
+        if (len == 0)
+            return 1;
+
+        if (n == CHACHA_BLK_SIZE) {
+            key->partial_len = 0;
+            key->counter[0]++;
+            if (key->counter[0] == 0)
+                key->counter[1]++;
+        }
+    }
+
+    rem = (unsigned int)(len % CHACHA_BLK_SIZE);
+    len -= rem;
+    ctr32 = key->counter[0];
+    while (len >= CHACHA_BLK_SIZE) {
+        size_t blocks = len / CHACHA_BLK_SIZE;
+        /*
+         * 1<<28 is just a not-so-small yet not-so-large number...
+         * Below condition is practically never met, but it has to
+         * be checked for code correctness.
+         */
+        if (sizeof(size_t) > sizeof(unsigned int) && blocks > (1U << 28))
+            blocks = (1U << 28);
+
+        /*
+         * As ChaCha20_ctr32 operates on 32-bit counter, caller
+         * has to handle overflow. 'if' below detects the
+         * overflow, which is then handled by limiting the
+         * amount of blocks to the exact overflow point...
+         */
+        ctr32 += (unsigned int)blocks;
+        if (ctr32 < blocks) {
+            blocks -= ctr32;
+            ctr32 = 0;
+        }
+        blocks *= CHACHA_BLK_SIZE;
+        ChaCha20_ctr32(out, inp, blocks, key->key.d, key->counter);
+        len -= blocks;
+        inp += blocks;
+        out += blocks;
+
+        key->counter[0] = ctr32;
+        if (ctr32 == 0)
+            key->counter[1]++;
+    }
+
+    if (rem) {
+        memset(key->buf, 0, sizeof(key->buf));
+        ChaCha20_ctr32(key->buf, key->buf, CHACHA_BLK_SIZE,
+            key->key.d, key->counter);
+        for (n = 0; n < rem; n++)
+            out[n] = inp[n] ^ key->buf[n];
+        key->partial_len = rem;
+    }
+
+    return 1;
+}
+
 static const EVP_CIPHER chacha20 = {
     NID_chacha20,
     1, /* block_size */
     CHACHA_KEY_SIZE, /* key_len */
     CHACHA_CTR_SIZE, /* iv_len, 128-bit counter in the context */
     EVP_CIPH_CUSTOM_IV | EVP_CIPH_ALWAYS_CALL_INIT,
-    EVP_ORIG_GLOBAL
+    EVP_ORIG_GLOBAL,
+    chacha_init_key,
+    chacha_cipher,
+    NULL,
+    sizeof(EVP_CHACHA_KEY),
+    NULL,
+    NULL,
+    NULL,
+    NULL
 };
 
 const EVP_CIPHER *EVP_chacha20(void)
@@ -29,6 +149,461 @@ const EVP_CIPHER *EVP_chacha20(void)
 }
 
 #ifndef OPENSSL_NO_POLY1305
+#include "crypto/poly1305.h"
+
+typedef struct {
+    EVP_CHACHA_KEY key;
+    unsigned int nonce[12 / 4];
+    unsigned char tag[POLY1305_BLOCK_SIZE];
+    unsigned char tls_aad[POLY1305_BLOCK_SIZE];
+    struct {
+        uint64_t aad, text;
+    } len;
+    int aad, mac_inited, tag_len, nonce_len;
+    size_t tls_payload_length;
+} EVP_CHACHA_AEAD_CTX;
+
+#define NO_TLS_PAYLOAD_LENGTH ((size_t)-1)
+#define aead_data(ctx) ((EVP_CHACHA_AEAD_CTX *)(ctx)->cipher_data)
+#define POLY1305_ctx(actx) ((POLY1305 *)(actx + 1))
+
+static int chacha20_poly1305_init_key(EVP_CIPHER_CTX *ctx,
+    const unsigned char *inkey,
+    const unsigned char *iv, int enc)
+{
+    EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
+
+    if (!inkey && !iv)
+        return 1;
+
+    actx->len.aad = 0;
+    actx->len.text = 0;
+    actx->aad = 0;
+    actx->mac_inited = 0;
+    actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
+
+    if (iv != NULL) {
+        unsigned char temp[CHACHA_CTR_SIZE] = { 0 };
+
+        /* pad on the left */
+        if (actx->nonce_len <= CHACHA_CTR_SIZE)
+            memcpy(temp + CHACHA_CTR_SIZE - actx->nonce_len, iv,
+                actx->nonce_len);
+
+        chacha_init_key(ctx, inkey, temp, enc);
+
+        actx->nonce[0] = actx->key.counter[1];
+        actx->nonce[1] = actx->key.counter[2];
+        actx->nonce[2] = actx->key.counter[3];
+    } else {
+        chacha_init_key(ctx, inkey, NULL, enc);
+    }
+
+    return 1;
+}
+
+#if !defined(OPENSSL_SMALL_FOOTPRINT)
+
+#if defined(POLY1305_ASM) && (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64))
+#define XOR128_HELPERS
+void *xor128_encrypt_n_pad(void *out, const void *inp, void *otp, size_t len);
+void *xor128_decrypt_n_pad(void *out, const void *inp, void *otp, size_t len);
+static const unsigned char zero[4 * CHACHA_BLK_SIZE] = { 0 };
+#else
+static const unsigned char zero[2 * CHACHA_BLK_SIZE] = { 0 };
+#endif
+
+static int chacha20_poly1305_tls_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
+    size_t tail, tohash_len, buf_len, plen = actx->tls_payload_length;
+    unsigned char *buf, *tohash, *ctr, storage[sizeof(zero) + 32];
+
+    if (len != plen + POLY1305_BLOCK_SIZE)
+        return -1;
+
+    buf = storage + ((0 - (size_t)storage) & 15); /* align */
+    ctr = buf + CHACHA_BLK_SIZE;
+    tohash = buf + CHACHA_BLK_SIZE - POLY1305_BLOCK_SIZE;
+
+#ifdef XOR128_HELPERS
+    if (plen <= 3 * CHACHA_BLK_SIZE) {
+        actx->key.counter[0] = 0;
+        buf_len = (plen + 2 * CHACHA_BLK_SIZE - 1) & (0 - CHACHA_BLK_SIZE);
+        ChaCha20_ctr32(buf, zero, buf_len, actx->key.key.d,
+            actx->key.counter);
+        Poly1305_Init(POLY1305_ctx(actx), buf);
+        actx->key.partial_len = 0;
+        memcpy(tohash, actx->tls_aad, POLY1305_BLOCK_SIZE);
+        tohash_len = POLY1305_BLOCK_SIZE;
+        actx->len.aad = EVP_AEAD_TLS1_AAD_LEN;
+        actx->len.text = plen;
+
+        if (plen) {
+            if (EVP_CIPHER_CTX_is_encrypting(ctx))
+                ctr = xor128_encrypt_n_pad(out, in, ctr, plen);
+            else
+                ctr = xor128_decrypt_n_pad(out, in, ctr, plen);
+
+            in += plen;
+            out += plen;
+            tohash_len = (size_t)(ctr - tohash);
+        }
+    }
+#else
+    if (plen <= CHACHA_BLK_SIZE) {
+        size_t i;
+
+        actx->key.counter[0] = 0;
+        ChaCha20_ctr32(buf, zero, (buf_len = 2 * CHACHA_BLK_SIZE),
+            actx->key.key.d, actx->key.counter);
+        Poly1305_Init(POLY1305_ctx(actx), buf);
+        actx->key.partial_len = 0;
+        memcpy(tohash, actx->tls_aad, POLY1305_BLOCK_SIZE);
+        tohash_len = POLY1305_BLOCK_SIZE;
+        actx->len.aad = EVP_AEAD_TLS1_AAD_LEN;
+        actx->len.text = plen;
+
+        if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+            for (i = 0; i < plen; i++) {
+                out[i] = ctr[i] ^= in[i];
+            }
+        } else {
+            for (i = 0; i < plen; i++) {
+                unsigned char c = in[i];
+                out[i] = ctr[i] ^ c;
+                ctr[i] = c;
+            }
+        }
+
+        in += i;
+        out += i;
+
+        tail = (0 - i) & (POLY1305_BLOCK_SIZE - 1);
+        memset(ctr + i, 0, tail);
+        ctr += i + tail;
+        tohash_len += i + tail;
+    }
+#endif
+    else {
+        actx->key.counter[0] = 0;
+        ChaCha20_ctr32(buf, zero, (buf_len = CHACHA_BLK_SIZE),
+            actx->key.key.d, actx->key.counter);
+        Poly1305_Init(POLY1305_ctx(actx), buf);
+        actx->key.counter[0] = 1;
+        actx->key.partial_len = 0;
+        Poly1305_Update(POLY1305_ctx(actx), actx->tls_aad, POLY1305_BLOCK_SIZE);
+        tohash = ctr;
+        tohash_len = 0;
+        actx->len.aad = EVP_AEAD_TLS1_AAD_LEN;
+        actx->len.text = plen;
+
+        if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+            ChaCha20_ctr32(out, in, plen, actx->key.key.d, actx->key.counter);
+            Poly1305_Update(POLY1305_ctx(actx), out, plen);
+        } else {
+            Poly1305_Update(POLY1305_ctx(actx), in, plen);
+            ChaCha20_ctr32(out, in, plen, actx->key.key.d, actx->key.counter);
+        }
+
+        in += plen;
+        out += plen;
+        tail = (0 - plen) & (POLY1305_BLOCK_SIZE - 1);
+        Poly1305_Update(POLY1305_ctx(actx), zero, tail);
+    }
+
+    {
+        DECLARE_IS_ENDIAN;
+
+        if (IS_LITTLE_ENDIAN) {
+            memcpy(ctr, (unsigned char *)&actx->len, POLY1305_BLOCK_SIZE);
+        } else {
+            ctr[0] = (unsigned char)(actx->len.aad);
+            ctr[1] = (unsigned char)(actx->len.aad >> 8);
+            ctr[2] = (unsigned char)(actx->len.aad >> 16);
+            ctr[3] = (unsigned char)(actx->len.aad >> 24);
+            ctr[4] = (unsigned char)(actx->len.aad >> 32);
+            ctr[5] = (unsigned char)(actx->len.aad >> 40);
+            ctr[6] = (unsigned char)(actx->len.aad >> 48);
+            ctr[7] = (unsigned char)(actx->len.aad >> 56);
+
+            ctr[8] = (unsigned char)(actx->len.text);
+            ctr[9] = (unsigned char)(actx->len.text >> 8);
+            ctr[10] = (unsigned char)(actx->len.text >> 16);
+            ctr[11] = (unsigned char)(actx->len.text >> 24);
+            ctr[12] = (unsigned char)(actx->len.text >> 32);
+            ctr[13] = (unsigned char)(actx->len.text >> 40);
+            ctr[14] = (unsigned char)(actx->len.text >> 48);
+            ctr[15] = (unsigned char)(actx->len.text >> 56);
+        }
+        tohash_len += POLY1305_BLOCK_SIZE;
+    }
+
+    Poly1305_Update(POLY1305_ctx(actx), tohash, tohash_len);
+    OPENSSL_cleanse(buf, buf_len);
+    Poly1305_Final(POLY1305_ctx(actx),
+        EVP_CIPHER_CTX_is_encrypting(ctx) ? actx->tag : tohash);
+
+    actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
+
+    if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+        memcpy(out, actx->tag, POLY1305_BLOCK_SIZE);
+    } else {
+        if (CRYPTO_memcmp(tohash, in, POLY1305_BLOCK_SIZE)) {
+            memset(out - (len - POLY1305_BLOCK_SIZE), 0,
+                len - POLY1305_BLOCK_SIZE);
+            return -1;
+        }
+    }
+
+    return (int)len;
+}
+#else
+static const unsigned char zero[CHACHA_BLK_SIZE] = { 0 };
+#endif
+
+static int chacha20_poly1305_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
+    size_t rem, plen = actx->tls_payload_length;
+
+    if (!actx->mac_inited) {
+#if !defined(OPENSSL_SMALL_FOOTPRINT)
+        if (plen != NO_TLS_PAYLOAD_LENGTH && out != NULL)
+            return chacha20_poly1305_tls_cipher(ctx, out, in, len);
+#endif
+        actx->key.counter[0] = 0;
+        ChaCha20_ctr32(actx->key.buf, zero, CHACHA_BLK_SIZE,
+            actx->key.key.d, actx->key.counter);
+        Poly1305_Init(POLY1305_ctx(actx), actx->key.buf);
+        actx->key.counter[0] = 1;
+        actx->key.partial_len = 0;
+        actx->len.aad = actx->len.text = 0;
+        actx->mac_inited = 1;
+        if (plen != NO_TLS_PAYLOAD_LENGTH) {
+            Poly1305_Update(POLY1305_ctx(actx), actx->tls_aad,
+                EVP_AEAD_TLS1_AAD_LEN);
+            actx->len.aad = EVP_AEAD_TLS1_AAD_LEN;
+            actx->aad = 1;
+        }
+    }
+
+    if (in) { /* aad or text */
+        if (out == NULL) { /* aad */
+            Poly1305_Update(POLY1305_ctx(actx), in, len);
+            actx->len.aad += len;
+            actx->aad = 1;
+            return (int)len;
+        } else { /* plain- or ciphertext */
+            if (actx->aad) { /* wrap up aad */
+                if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
+                    Poly1305_Update(POLY1305_ctx(actx), zero,
+                        POLY1305_BLOCK_SIZE - rem);
+                actx->aad = 0;
+            }
+
+            actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
+            if (plen == NO_TLS_PAYLOAD_LENGTH)
+                plen = len;
+            else if (len != plen + POLY1305_BLOCK_SIZE)
+                return -1;
+
+            if (EVP_CIPHER_CTX_is_encrypting(ctx)) { /* plaintext */
+                chacha_cipher(ctx, out, in, plen);
+                Poly1305_Update(POLY1305_ctx(actx), out, plen);
+                in += plen;
+                out += plen;
+                actx->len.text += plen;
+            } else { /* ciphertext */
+                Poly1305_Update(POLY1305_ctx(actx), in, plen);
+                chacha_cipher(ctx, out, in, plen);
+                in += plen;
+                out += plen;
+                actx->len.text += plen;
+            }
+        }
+    }
+    if (in == NULL /* explicit final */
+        || plen != len) { /* or tls mode */
+        DECLARE_IS_ENDIAN;
+        unsigned char temp[POLY1305_BLOCK_SIZE];
+
+        if (actx->aad) { /* wrap up aad */
+            if ((rem = (size_t)actx->len.aad % POLY1305_BLOCK_SIZE))
+                Poly1305_Update(POLY1305_ctx(actx), zero,
+                    POLY1305_BLOCK_SIZE - rem);
+            actx->aad = 0;
+        }
+
+        if ((rem = (size_t)actx->len.text % POLY1305_BLOCK_SIZE))
+            Poly1305_Update(POLY1305_ctx(actx), zero,
+                POLY1305_BLOCK_SIZE - rem);
+
+        if (IS_LITTLE_ENDIAN) {
+            Poly1305_Update(POLY1305_ctx(actx),
+                (unsigned char *)&actx->len, POLY1305_BLOCK_SIZE);
+        } else {
+            temp[0] = (unsigned char)(actx->len.aad);
+            temp[1] = (unsigned char)(actx->len.aad >> 8);
+            temp[2] = (unsigned char)(actx->len.aad >> 16);
+            temp[3] = (unsigned char)(actx->len.aad >> 24);
+            temp[4] = (unsigned char)(actx->len.aad >> 32);
+            temp[5] = (unsigned char)(actx->len.aad >> 40);
+            temp[6] = (unsigned char)(actx->len.aad >> 48);
+            temp[7] = (unsigned char)(actx->len.aad >> 56);
+
+            temp[8] = (unsigned char)(actx->len.text);
+            temp[9] = (unsigned char)(actx->len.text >> 8);
+            temp[10] = (unsigned char)(actx->len.text >> 16);
+            temp[11] = (unsigned char)(actx->len.text >> 24);
+            temp[12] = (unsigned char)(actx->len.text >> 32);
+            temp[13] = (unsigned char)(actx->len.text >> 40);
+            temp[14] = (unsigned char)(actx->len.text >> 48);
+            temp[15] = (unsigned char)(actx->len.text >> 56);
+
+            Poly1305_Update(POLY1305_ctx(actx), temp, POLY1305_BLOCK_SIZE);
+        }
+        Poly1305_Final(POLY1305_ctx(actx),
+            EVP_CIPHER_CTX_is_encrypting(ctx) ? actx->tag : temp);
+        actx->mac_inited = 0;
+
+        if (in != NULL && len != plen) { /* tls mode */
+            if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+                memcpy(out, actx->tag, POLY1305_BLOCK_SIZE);
+            } else {
+                if (CRYPTO_memcmp(temp, in, POLY1305_BLOCK_SIZE)) {
+                    memset(out - plen, 0, plen);
+                    return -1;
+                }
+            }
+        } else if (!EVP_CIPHER_CTX_is_encrypting(ctx)) {
+            if (CRYPTO_memcmp(temp, actx->tag, actx->tag_len))
+                return -1;
+        }
+    }
+    return (int)len;
+}
+
+static int chacha20_poly1305_cleanup(EVP_CIPHER_CTX *ctx)
+{
+    EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
+    if (actx)
+        OPENSSL_cleanse(ctx->cipher_data, sizeof(*actx) + Poly1305_ctx_size());
+    return 1;
+}
+
+static int chacha20_poly1305_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg,
+    void *ptr)
+{
+    EVP_CHACHA_AEAD_CTX *actx = aead_data(ctx);
+
+    switch (type) {
+    case EVP_CTRL_INIT:
+        if (actx == NULL)
+            actx = ctx->cipher_data
+                = OPENSSL_zalloc(sizeof(*actx) + Poly1305_ctx_size());
+        if (actx == NULL) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
+            return 0;
+        }
+        actx->len.aad = 0;
+        actx->len.text = 0;
+        actx->aad = 0;
+        actx->mac_inited = 0;
+        actx->tag_len = 0;
+        actx->nonce_len = 12;
+        actx->tls_payload_length = NO_TLS_PAYLOAD_LENGTH;
+        memset(actx->tls_aad, 0, POLY1305_BLOCK_SIZE);
+        return 1;
+
+    case EVP_CTRL_COPY:
+        if (actx) {
+            EVP_CIPHER_CTX *dst = (EVP_CIPHER_CTX *)ptr;
+
+            dst->cipher_data = OPENSSL_memdup(actx, sizeof(*actx) + Poly1305_ctx_size());
+            if (dst->cipher_data == NULL) {
+                ERR_raise(ERR_LIB_EVP, EVP_R_COPY_ERROR);
+                return 0;
+            }
+        }
+        return 1;
+
+    case EVP_CTRL_GET_IVLEN:
+        *(int *)ptr = actx->nonce_len;
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_IVLEN:
+        if (arg <= 0 || arg > CHACHA20_POLY1305_MAX_IVLEN)
+            return 0;
+        actx->nonce_len = arg;
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_IV_FIXED:
+        if (arg != 12)
+            return 0;
+        actx->nonce[0] = actx->key.counter[1]
+            = CHACHA_U8TOU32((unsigned char *)ptr);
+        actx->nonce[1] = actx->key.counter[2]
+            = CHACHA_U8TOU32((unsigned char *)ptr + 4);
+        actx->nonce[2] = actx->key.counter[3]
+            = CHACHA_U8TOU32((unsigned char *)ptr + 8);
+        return 1;
+
+    case EVP_CTRL_AEAD_SET_TAG:
+        if (arg <= 0 || arg > POLY1305_BLOCK_SIZE)
+            return 0;
+        if (ptr != NULL) {
+            memcpy(actx->tag, ptr, arg);
+            actx->tag_len = arg;
+        }
+        return 1;
+
+    case EVP_CTRL_AEAD_GET_TAG:
+        if (arg <= 0 || arg > POLY1305_BLOCK_SIZE || !EVP_CIPHER_CTX_is_encrypting(ctx))
+            return 0;
+        memcpy(ptr, actx->tag, arg);
+        return 1;
+
+    case EVP_CTRL_AEAD_TLS1_AAD:
+        if (arg != EVP_AEAD_TLS1_AAD_LEN)
+            return 0;
+        {
+            unsigned int len;
+            unsigned char *aad = ptr;
+
+            memcpy(actx->tls_aad, ptr, EVP_AEAD_TLS1_AAD_LEN);
+            len = aad[EVP_AEAD_TLS1_AAD_LEN - 2] << 8 | aad[EVP_AEAD_TLS1_AAD_LEN - 1];
+            aad = actx->tls_aad;
+            if (!EVP_CIPHER_CTX_is_encrypting(ctx)) {
+                if (len < POLY1305_BLOCK_SIZE)
+                    return 0;
+                len -= POLY1305_BLOCK_SIZE; /* discount attached tag */
+                aad[EVP_AEAD_TLS1_AAD_LEN - 2] = (unsigned char)(len >> 8);
+                aad[EVP_AEAD_TLS1_AAD_LEN - 1] = (unsigned char)len;
+            }
+            actx->tls_payload_length = len;
+
+            /*
+             * merge record sequence number as per RFC7905
+             */
+            actx->key.counter[1] = actx->nonce[0];
+            actx->key.counter[2] = actx->nonce[1] ^ CHACHA_U8TOU32(aad);
+            actx->key.counter[3] = actx->nonce[2] ^ CHACHA_U8TOU32(aad + 4);
+            actx->mac_inited = 0;
+
+            return POLY1305_BLOCK_SIZE; /* tag length */
+        }
+
+    case EVP_CTRL_AEAD_SET_MAC_KEY:
+        /* no-op */
+        return 1;
+
+    default:
+        return -1;
+    }
+}
 
 static const EVP_CIPHER chacha20_poly1305 = {
     NID_chacha20_poly1305,
@@ -36,14 +611,20 @@ static const EVP_CIPHER chacha20_poly1305 = {
     CHACHA_KEY_SIZE, /* key_len */
     12, /* iv_len, 96-bit nonce in the context */
     EVP_CIPH_FLAG_AEAD_CIPHER | EVP_CIPH_CUSTOM_IV | EVP_CIPH_ALWAYS_CALL_INIT | EVP_CIPH_CTRL_INIT | EVP_CIPH_CUSTOM_COPY | EVP_CIPH_FLAG_CUSTOM_CIPHER | EVP_CIPH_CUSTOM_IV_LENGTH,
-    EVP_ORIG_GLOBAL
+    EVP_ORIG_GLOBAL,
+    chacha20_poly1305_init_key,
+    chacha20_poly1305_cipher,
+    chacha20_poly1305_cleanup,
+    0, /* 0 moves context-specific structure allocation to ctrl */
+    NULL, /* set_asn1_parameters */
+    NULL, /* get_asn1_parameters */
+    chacha20_poly1305_ctrl,
+    NULL /* app_data */
 };
 
 const EVP_CIPHER *EVP_chacha20_poly1305(void)
 {
-    return &chacha20_poly1305;
+    return (&chacha20_poly1305);
 }
 #endif
-#else
-NON_EMPTY_TRANSLATION_UNIT
 #endif
diff --git a/crypto/evp/e_des.c b/crypto/evp/e_des.c
index 875f186340..b8d10829c2 100644
--- a/crypto/evp/e_des.c
+++ b/crypto/evp/e_des.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,20 +7,239 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include 
+/*
+ * DES low level APIs are deprecated for public use, but still ok for internal
+ * use.
+ */
+#include "internal/deprecated.h"
 
+#include 
+#include "internal/cryptlib.h"
 #ifndef OPENSSL_NO_DES
+#include 
+#include 
 #include "crypto/evp.h"
+#include 
+#include 
+#include "evp_local.h"
+
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        DES_key_schedule ks;
+    } ks;
+    union {
+        void (*cbc)(const void *, void *, size_t,
+            const DES_key_schedule *, unsigned char *);
+    } stream;
+} EVP_DES_KEY;
+
+#if defined(AES_ASM) && (defined(__sparc) || defined(__sparc__))
+/* ----------^^^ this is not a typo, just a way to detect that
+ * assembler support was in general requested... */
+#include "crypto/sparc_arch.h"
+
+#define SPARC_DES_CAPABLE (OPENSSL_sparcv9cap_P[1] & CFR_DES)
+
+void des_t4_key_expand(const void *key, DES_key_schedule *ks);
+void des_t4_cbc_encrypt(const void *inp, void *out, size_t len,
+    const DES_key_schedule *ks, unsigned char iv[8]);
+void des_t4_cbc_decrypt(const void *inp, void *out, size_t len,
+    const DES_key_schedule *ks, unsigned char iv[8]);
+#endif
+
+static int des_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc);
+static int des_ctrl(EVP_CIPHER_CTX *c, int type, int arg, void *ptr);
+
+/*
+ * Because of various casts and different names can't use
+ * IMPLEMENT_BLOCK_CIPHER
+ */
+
+static int des_ecb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    BLOCK_CIPHER_ecb_loop()
+        DES_ecb_encrypt((DES_cblock *)(in + i), (DES_cblock *)(out + i),
+            EVP_CIPHER_CTX_get_cipher_data(ctx),
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+    return 1;
+}
+
+static int des_ofb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    while (inl >= EVP_MAXCHUNK) {
+        int num = EVP_CIPHER_CTX_get_num(ctx);
+        DES_ofb64_encrypt(in, out, (long)EVP_MAXCHUNK,
+            EVP_CIPHER_CTX_get_cipher_data(ctx),
+            (DES_cblock *)ctx->iv, &num);
+        EVP_CIPHER_CTX_set_num(ctx, num);
+        inl -= EVP_MAXCHUNK;
+        in += EVP_MAXCHUNK;
+        out += EVP_MAXCHUNK;
+    }
+    if (inl) {
+        int num = EVP_CIPHER_CTX_get_num(ctx);
+        DES_ofb64_encrypt(in, out, (long)inl,
+            EVP_CIPHER_CTX_get_cipher_data(ctx),
+            (DES_cblock *)ctx->iv, &num);
+        EVP_CIPHER_CTX_set_num(ctx, num);
+    }
+    return 1;
+}
+
+static int des_cbc_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    EVP_DES_KEY *dat = (EVP_DES_KEY *)EVP_CIPHER_CTX_get_cipher_data(ctx);
+
+    if (dat->stream.cbc != NULL) {
+        (*dat->stream.cbc)(in, out, inl, &dat->ks.ks, ctx->iv);
+        return 1;
+    }
+    while (inl >= EVP_MAXCHUNK) {
+        DES_ncbc_encrypt(in, out, (long)EVP_MAXCHUNK,
+            EVP_CIPHER_CTX_get_cipher_data(ctx),
+            (DES_cblock *)ctx->iv,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+        inl -= EVP_MAXCHUNK;
+        in += EVP_MAXCHUNK;
+        out += EVP_MAXCHUNK;
+    }
+    if (inl)
+        DES_ncbc_encrypt(in, out, (long)inl,
+            EVP_CIPHER_CTX_get_cipher_data(ctx),
+            (DES_cblock *)ctx->iv,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+    return 1;
+}
+
+static int des_cfb64_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    while (inl >= EVP_MAXCHUNK) {
+        int num = EVP_CIPHER_CTX_get_num(ctx);
+        DES_cfb64_encrypt(in, out, (long)EVP_MAXCHUNK,
+            EVP_CIPHER_CTX_get_cipher_data(ctx),
+            (DES_cblock *)ctx->iv, &num,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+        EVP_CIPHER_CTX_set_num(ctx, num);
+        inl -= EVP_MAXCHUNK;
+        in += EVP_MAXCHUNK;
+        out += EVP_MAXCHUNK;
+    }
+    if (inl) {
+        int num = EVP_CIPHER_CTX_get_num(ctx);
+        DES_cfb64_encrypt(in, out, (long)inl,
+            EVP_CIPHER_CTX_get_cipher_data(ctx),
+            (DES_cblock *)ctx->iv, &num,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+        EVP_CIPHER_CTX_set_num(ctx, num);
+    }
+    return 1;
+}
+
+/*
+ * Although we have a CFB-r implementation for DES, it doesn't pack the right
+ * way, so wrap it here
+ */
+static int des_cfb1_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    size_t n, chunk = EVP_MAXCHUNK / 8;
+    unsigned char c[1];
+    unsigned char d[1] = { 0 }; /* Appease Coverity */
+
+    if (inl < chunk)
+        chunk = inl;
+
+    while (inl && inl >= chunk) {
+        for (n = 0; n < chunk * 8; ++n) {
+            c[0] = (in[n / 8] & (1 << (7 - n % 8))) ? 0x80 : 0;
+            DES_cfb_encrypt(c, d, 1, 1, EVP_CIPHER_CTX_get_cipher_data(ctx),
+                (DES_cblock *)ctx->iv,
+                EVP_CIPHER_CTX_is_encrypting(ctx));
+            out[n / 8] = (out[n / 8] & ~(0x80 >> (unsigned int)(n % 8))) | ((d[0] & 0x80) >> (unsigned int)(n % 8));
+        }
+        inl -= chunk;
+        in += chunk;
+        out += chunk;
+        if (inl < chunk)
+            chunk = inl;
+    }
+
+    return 1;
+}
+
+static int des_cfb8_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    while (inl >= EVP_MAXCHUNK) {
+        DES_cfb_encrypt(in, out, 8, (long)EVP_MAXCHUNK,
+            EVP_CIPHER_CTX_get_cipher_data(ctx),
+            (DES_cblock *)ctx->iv,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+        inl -= EVP_MAXCHUNK;
+        in += EVP_MAXCHUNK;
+        out += EVP_MAXCHUNK;
+    }
+    if (inl)
+        DES_cfb_encrypt(in, out, 8, (long)inl,
+            EVP_CIPHER_CTX_get_cipher_data(ctx),
+            (DES_cblock *)ctx->iv,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+    return 1;
+}
 
 BLOCK_CIPHER_defs(des, EVP_DES_KEY, NID_des, 8, 8, 8, 64,
-    EVP_CIPH_RAND_KEY)
+    EVP_CIPH_RAND_KEY, des_init_key, NULL,
+    EVP_CIPHER_set_asn1_iv, EVP_CIPHER_get_asn1_iv, des_ctrl)
 
-BLOCK_CIPHER_def_cfb(des, EVP_DES_KEY, NID_des, 8, 8, 1,
-    EVP_CIPH_RAND_KEY)
+    BLOCK_CIPHER_def_cfb(des, EVP_DES_KEY, NID_des, 8, 8, 1,
+        EVP_CIPH_RAND_KEY, des_init_key, NULL,
+        EVP_CIPHER_set_asn1_iv, EVP_CIPHER_get_asn1_iv, des_ctrl)
 
-BLOCK_CIPHER_def_cfb(des, EVP_DES_KEY, NID_des, 8, 8, 8,
-    EVP_CIPH_RAND_KEY)
+        BLOCK_CIPHER_def_cfb(des, EVP_DES_KEY, NID_des, 8, 8, 8,
+            EVP_CIPH_RAND_KEY, des_init_key, NULL,
+            EVP_CIPHER_set_asn1_iv, EVP_CIPHER_get_asn1_iv, des_ctrl)
+
+            static int des_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+                const unsigned char *iv, int enc)
+{
+    DES_cblock *deskey = (DES_cblock *)key;
+    EVP_DES_KEY *dat = (EVP_DES_KEY *)EVP_CIPHER_CTX_get_cipher_data(ctx);
+
+    dat->stream.cbc = NULL;
+#if defined(SPARC_DES_CAPABLE)
+    if (SPARC_DES_CAPABLE) {
+        int mode = EVP_CIPHER_CTX_get_mode(ctx);
+
+        if (mode == EVP_CIPH_CBC_MODE) {
+            des_t4_key_expand(key, &dat->ks.ks);
+            dat->stream.cbc = enc ? des_t4_cbc_encrypt : des_t4_cbc_decrypt;
+            return 1;
+        }
+    }
+#endif
+    DES_set_key_unchecked(deskey, EVP_CIPHER_CTX_get_cipher_data(ctx));
+    return 1;
+}
+
+static int des_ctrl(EVP_CIPHER_CTX *c, int type, int arg, void *ptr)
+{
+
+    switch (type) {
+    case EVP_CTRL_RAND_KEY:
+        if (RAND_priv_bytes(ptr, 8) <= 0)
+            return 0;
+        DES_set_odd_parity((DES_cblock *)ptr);
+        return 1;
+
+    default:
+        return -1;
+    }
+}
 
-#else
-NON_EMPTY_TRANSLATION_UNIT
 #endif
diff --git a/crypto/evp/e_des3.c b/crypto/evp/e_des3.c
index 1c22537fb8..7a674cc718 100644
--- a/crypto/evp/e_des3.c
+++ b/crypto/evp/e_des3.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,22 +7,295 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include 
+/*
+ * DES low level APIs are deprecated for public use, but still ok for internal
+ * use.
+ */
+#include "internal/deprecated.h"
 
+#include 
+#include "internal/cryptlib.h"
 #ifndef OPENSSL_NO_DES
+#include 
 #include "crypto/evp.h"
+#include "crypto/sha.h"
+#include 
+#include 
+#include "evp_local.h"
+
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        DES_key_schedule ks[3];
+    } ks;
+    union {
+        void (*cbc)(const void *, void *, size_t,
+            const DES_key_schedule *, unsigned char *);
+    } stream;
+} DES_EDE_KEY;
+#define ks1 ks.ks[0]
+#define ks2 ks.ks[1]
+#define ks3 ks.ks[2]
+
+#if defined(AES_ASM) && (defined(__sparc) || defined(__sparc__))
+/* ---------^^^ this is not a typo, just a way to detect that
+ * assembler support was in general requested... */
+#include "crypto/sparc_arch.h"
+
+#define SPARC_DES_CAPABLE (OPENSSL_sparcv9cap_P[1] & CFR_DES)
+
+void des_t4_key_expand(const void *key, DES_key_schedule *ks);
+void des_t4_ede3_cbc_encrypt(const void *inp, void *out, size_t len,
+    const DES_key_schedule ks[3], unsigned char iv[8]);
+void des_t4_ede3_cbc_decrypt(const void *inp, void *out, size_t len,
+    const DES_key_schedule ks[3], unsigned char iv[8]);
+#endif
+
+static int des_ede_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc);
+
+static int des_ede3_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc);
+
+static int des3_ctrl(EVP_CIPHER_CTX *c, int type, int arg, void *ptr);
+
+#define data(ctx) EVP_C_DATA(DES_EDE_KEY, ctx)
+
+/*
+ * Because of various casts and different args can't use
+ * IMPLEMENT_BLOCK_CIPHER
+ */
+
+static int des_ede_ecb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    BLOCK_CIPHER_ecb_loop()
+        DES_ecb3_encrypt((const_DES_cblock *)(in + i),
+            (DES_cblock *)(out + i),
+            &data(ctx)->ks1, &data(ctx)->ks2,
+            &data(ctx)->ks3, EVP_CIPHER_CTX_is_encrypting(ctx));
+    return 1;
+}
+
+static int des_ede_ofb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    while (inl >= EVP_MAXCHUNK) {
+        int num = EVP_CIPHER_CTX_get_num(ctx);
+        DES_ede3_ofb64_encrypt(in, out, (long)EVP_MAXCHUNK,
+            &data(ctx)->ks1, &data(ctx)->ks2,
+            &data(ctx)->ks3,
+            (DES_cblock *)ctx->iv,
+            &num);
+        EVP_CIPHER_CTX_set_num(ctx, num);
+        inl -= EVP_MAXCHUNK;
+        in += EVP_MAXCHUNK;
+        out += EVP_MAXCHUNK;
+    }
+    if (inl) {
+        int num = EVP_CIPHER_CTX_get_num(ctx);
+        DES_ede3_ofb64_encrypt(in, out, (long)inl,
+            &data(ctx)->ks1, &data(ctx)->ks2,
+            &data(ctx)->ks3,
+            (DES_cblock *)ctx->iv,
+            &num);
+        EVP_CIPHER_CTX_set_num(ctx, num);
+    }
+    return 1;
+}
+
+static int des_ede_cbc_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    DES_EDE_KEY *dat = data(ctx);
+
+    if (dat->stream.cbc != NULL) {
+        (*dat->stream.cbc)(in, out, inl, dat->ks.ks,
+            ctx->iv);
+        return 1;
+    }
+
+    while (inl >= EVP_MAXCHUNK) {
+        DES_ede3_cbc_encrypt(in, out, (long)EVP_MAXCHUNK,
+            &dat->ks1, &dat->ks2, &dat->ks3,
+            (DES_cblock *)ctx->iv,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+        inl -= EVP_MAXCHUNK;
+        in += EVP_MAXCHUNK;
+        out += EVP_MAXCHUNK;
+    }
+    if (inl)
+        DES_ede3_cbc_encrypt(in, out, (long)inl,
+            &dat->ks1, &dat->ks2, &dat->ks3,
+            (DES_cblock *)ctx->iv,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+    return 1;
+}
+
+static int des_ede_cfb64_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    while (inl >= EVP_MAXCHUNK) {
+        int num = EVP_CIPHER_CTX_get_num(ctx);
+        DES_ede3_cfb64_encrypt(in, out, (long)EVP_MAXCHUNK,
+            &data(ctx)->ks1, &data(ctx)->ks2,
+            &data(ctx)->ks3, (DES_cblock *)ctx->iv,
+            &num, EVP_CIPHER_CTX_is_encrypting(ctx));
+        EVP_CIPHER_CTX_set_num(ctx, num);
+        inl -= EVP_MAXCHUNK;
+        in += EVP_MAXCHUNK;
+        out += EVP_MAXCHUNK;
+    }
+    if (inl) {
+        int num = EVP_CIPHER_CTX_get_num(ctx);
+        DES_ede3_cfb64_encrypt(in, out, (long)inl,
+            &data(ctx)->ks1, &data(ctx)->ks2,
+            &data(ctx)->ks3, (DES_cblock *)ctx->iv,
+            &num, EVP_CIPHER_CTX_is_encrypting(ctx));
+        EVP_CIPHER_CTX_set_num(ctx, num);
+    }
+    return 1;
+}
+
+/*
+ * Although we have a CFB-r implementation for 3-DES, it doesn't pack the
+ * right way, so wrap it here
+ */
+static int des_ede3_cfb1_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    size_t n;
+    unsigned char c[1];
+    unsigned char d[1] = { 0 }; /* Appease Coverity */
+
+    if (!EVP_CIPHER_CTX_test_flags(ctx, EVP_CIPH_FLAG_LENGTH_BITS))
+        inl *= 8;
+    for (n = 0; n < inl; ++n) {
+        c[0] = (in[n / 8] & (1 << (7 - n % 8))) ? 0x80 : 0;
+        DES_ede3_cfb_encrypt(c, d, 1, 1,
+            &data(ctx)->ks1, &data(ctx)->ks2,
+            &data(ctx)->ks3, (DES_cblock *)ctx->iv,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+        out[n / 8] = (out[n / 8] & ~(0x80 >> (unsigned int)(n % 8)))
+            | ((d[0] & 0x80) >> (unsigned int)(n % 8));
+    }
+
+    return 1;
+}
+
+static int des_ede3_cfb8_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    while (inl >= EVP_MAXCHUNK) {
+        DES_ede3_cfb_encrypt(in, out, 8, (long)EVP_MAXCHUNK,
+            &data(ctx)->ks1, &data(ctx)->ks2,
+            &data(ctx)->ks3, (DES_cblock *)ctx->iv,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+        inl -= EVP_MAXCHUNK;
+        in += EVP_MAXCHUNK;
+        out += EVP_MAXCHUNK;
+    }
+    if (inl)
+        DES_ede3_cfb_encrypt(in, out, 8, (long)inl,
+            &data(ctx)->ks1, &data(ctx)->ks2,
+            &data(ctx)->ks3, (DES_cblock *)ctx->iv,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+    return 1;
+}
 
 BLOCK_CIPHER_defs(des_ede, DES_EDE_KEY, NID_des_ede, 8, 16, 8, 64,
-    EVP_CIPH_RAND_KEY | EVP_CIPH_FLAG_DEFAULT_ASN1)
+    EVP_CIPH_RAND_KEY | EVP_CIPH_FLAG_DEFAULT_ASN1,
+    des_ede_init_key, NULL, NULL, NULL, des3_ctrl)
+#define des_ede3_cfb64_cipher des_ede_cfb64_cipher
+#define des_ede3_ofb_cipher des_ede_ofb_cipher
+#define des_ede3_cbc_cipher des_ede_cbc_cipher
+#define des_ede3_ecb_cipher des_ede_ecb_cipher
+    BLOCK_CIPHER_defs(des_ede3, DES_EDE_KEY, NID_des_ede3, 8, 24, 8, 64,
+        EVP_CIPH_RAND_KEY | EVP_CIPH_FLAG_DEFAULT_ASN1,
+        des_ede3_init_key, NULL, NULL, NULL, des3_ctrl)
 
-BLOCK_CIPHER_defs(des_ede3, DES_EDE_KEY, NID_des_ede3, 8, 24, 8, 64,
-    EVP_CIPH_RAND_KEY | EVP_CIPH_FLAG_DEFAULT_ASN1)
+        BLOCK_CIPHER_def_cfb(des_ede3, DES_EDE_KEY, NID_des_ede3, 24, 8, 1,
+            EVP_CIPH_RAND_KEY | EVP_CIPH_FLAG_DEFAULT_ASN1,
+            des_ede3_init_key, NULL, NULL, NULL, des3_ctrl)
 
-BLOCK_CIPHER_def_cfb(des_ede3, DES_EDE_KEY, NID_des_ede3, 24, 8, 1,
-    EVP_CIPH_RAND_KEY | EVP_CIPH_FLAG_DEFAULT_ASN1)
+            BLOCK_CIPHER_def_cfb(des_ede3, DES_EDE_KEY, NID_des_ede3, 24, 8, 8,
+                EVP_CIPH_RAND_KEY | EVP_CIPH_FLAG_DEFAULT_ASN1,
+                des_ede3_init_key, NULL, NULL, NULL, des3_ctrl)
 
-BLOCK_CIPHER_def_cfb(des_ede3, DES_EDE_KEY, NID_des_ede3, 24, 8, 8,
-    EVP_CIPH_RAND_KEY | EVP_CIPH_FLAG_DEFAULT_ASN1)
+                static int des_ede_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+                    const unsigned char *iv, int enc)
+{
+    DES_cblock *deskey = (DES_cblock *)key;
+    DES_EDE_KEY *dat = data(ctx);
+
+    dat->stream.cbc = NULL;
+#if defined(SPARC_DES_CAPABLE)
+    if (SPARC_DES_CAPABLE) {
+        int mode = EVP_CIPHER_CTX_get_mode(ctx);
+
+        if (mode == EVP_CIPH_CBC_MODE) {
+            des_t4_key_expand(&deskey[0], &dat->ks1);
+            des_t4_key_expand(&deskey[1], &dat->ks2);
+            memcpy(&dat->ks3, &dat->ks1, sizeof(dat->ks1));
+            dat->stream.cbc = enc ? des_t4_ede3_cbc_encrypt : des_t4_ede3_cbc_decrypt;
+            return 1;
+        }
+    }
+#endif
+    DES_set_key_unchecked(&deskey[0], &dat->ks1);
+    DES_set_key_unchecked(&deskey[1], &dat->ks2);
+    memcpy(&dat->ks3, &dat->ks1, sizeof(dat->ks1));
+    return 1;
+}
+
+static int des_ede3_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    DES_cblock *deskey = (DES_cblock *)key;
+    DES_EDE_KEY *dat = data(ctx);
+
+    dat->stream.cbc = NULL;
+#if defined(SPARC_DES_CAPABLE)
+    if (SPARC_DES_CAPABLE) {
+        int mode = EVP_CIPHER_CTX_get_mode(ctx);
+
+        if (mode == EVP_CIPH_CBC_MODE) {
+            des_t4_key_expand(&deskey[0], &dat->ks1);
+            des_t4_key_expand(&deskey[1], &dat->ks2);
+            des_t4_key_expand(&deskey[2], &dat->ks3);
+            dat->stream.cbc = enc ? des_t4_ede3_cbc_encrypt : des_t4_ede3_cbc_decrypt;
+            return 1;
+        }
+    }
+#endif
+    DES_set_key_unchecked(&deskey[0], &dat->ks1);
+    DES_set_key_unchecked(&deskey[1], &dat->ks2);
+    DES_set_key_unchecked(&deskey[2], &dat->ks3);
+    return 1;
+}
+
+static int des3_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg, void *ptr)
+{
+
+    DES_cblock *deskey = ptr;
+    int kl;
+
+    switch (type) {
+    case EVP_CTRL_RAND_KEY:
+        kl = EVP_CIPHER_CTX_get_key_length(ctx);
+        if (kl < 0 || RAND_priv_bytes(ptr, kl) <= 0)
+            return 0;
+        DES_set_odd_parity(deskey);
+        if (kl >= 16)
+            DES_set_odd_parity(deskey + 1);
+        if (kl >= 24)
+            DES_set_odd_parity(deskey + 2);
+        return 1;
+
+    default:
+        return -1;
+    }
+}
 
 const EVP_CIPHER *EVP_des_ede(void)
 {
@@ -34,12 +307,114 @@ const EVP_CIPHER *EVP_des_ede3(void)
     return &des_ede3_ecb;
 }
 
+#include 
+
+static const unsigned char wrap_iv[8] = {
+    0x4a, 0xdd, 0xa2, 0x2c, 0x79, 0xe8, 0x21, 0x05
+};
+
+static int des_ede3_unwrap(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    unsigned char icv[8], iv[8], sha1tmp[SHA_DIGEST_LENGTH];
+    int rv = -1;
+
+    if (inl < 24)
+        return -1;
+    if (out == NULL)
+        return (int)(inl - 16);
+    memcpy(ctx->iv, wrap_iv, 8);
+    /* Decrypt first block which will end up as icv */
+    des_ede_cbc_cipher(ctx, icv, in, 8);
+    /* Decrypt central blocks */
+    /*
+     * If decrypting in place move whole output along a block so the next
+     * des_ede_cbc_cipher is in place.
+     */
+    if (out == in) {
+        memmove(out, out + 8, inl - 8);
+        in -= 8;
+    }
+    des_ede_cbc_cipher(ctx, out, in + 8, inl - 16);
+    /* Decrypt final block which will be IV */
+    des_ede_cbc_cipher(ctx, iv, in + inl - 8, 8);
+    /* Reverse order of everything */
+    BUF_reverse(icv, NULL, 8);
+    BUF_reverse(out, NULL, inl - 16);
+    BUF_reverse(ctx->iv, iv, 8);
+    /* Decrypt again using new IV */
+    des_ede_cbc_cipher(ctx, out, out, inl - 16);
+    des_ede_cbc_cipher(ctx, icv, icv, 8);
+    if (ossl_sha1(out, inl - 16, sha1tmp) /* Work out hash of first portion */
+        && CRYPTO_memcmp(sha1tmp, icv, 8) == 0)
+        rv = (int)(inl - 16);
+    OPENSSL_cleanse(icv, 8);
+    OPENSSL_cleanse(sha1tmp, SHA_DIGEST_LENGTH);
+    OPENSSL_cleanse(iv, 8);
+    OPENSSL_cleanse(ctx->iv, 8);
+    if (rv == -1)
+        OPENSSL_cleanse(out, inl - 16);
+
+    return rv;
+}
+
+static int des_ede3_wrap(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    unsigned char sha1tmp[SHA_DIGEST_LENGTH];
+    if (out == NULL)
+        return (int)(inl + 16);
+    /* Copy input to output buffer + 8 so we have space for IV */
+    memmove(out + 8, in, inl);
+    /* Work out ICV */
+    if (!ossl_sha1(in, inl, sha1tmp))
+        return -1;
+    memcpy(out + inl + 8, sha1tmp, 8);
+    OPENSSL_cleanse(sha1tmp, SHA_DIGEST_LENGTH);
+    /* Generate random IV */
+    if (RAND_bytes(ctx->iv, 8) <= 0)
+        return -1;
+    memcpy(out, ctx->iv, 8);
+    /* Encrypt everything after IV in place */
+    des_ede_cbc_cipher(ctx, out + 8, out + 8, inl + 8);
+    BUF_reverse(out, NULL, inl + 16);
+    memcpy(ctx->iv, wrap_iv, 8);
+    des_ede_cbc_cipher(ctx, out, out, inl + 16);
+    return (int)(inl + 16);
+}
+
+static int des_ede3_wrap_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    /*
+     * Sanity check input length: we typically only wrap keys so EVP_MAXCHUNK
+     * is more than will ever be needed. Also input length must be a multiple
+     * of 8 bits.
+     */
+    if (inl >= EVP_MAXCHUNK || inl % 8)
+        return -1;
+
+    if (ossl_is_partially_overlapping(out, in, (int)inl)) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_PARTIALLY_OVERLAPPING);
+        return 0;
+    }
+
+    if (EVP_CIPHER_CTX_is_encrypting(ctx))
+        return des_ede3_wrap(ctx, out, in, inl);
+    else
+        return des_ede3_unwrap(ctx, out, in, inl);
+}
+
 static const EVP_CIPHER des3_wrap = {
     NID_id_smime_alg_CMS3DESwrap,
     8, 24, 0,
     EVP_CIPH_WRAP_MODE | EVP_CIPH_CUSTOM_IV | EVP_CIPH_FLAG_CUSTOM_CIPHER
         | EVP_CIPH_FLAG_DEFAULT_ASN1,
-    EVP_ORIG_GLOBAL
+    EVP_ORIG_GLOBAL,
+    des_ede3_init_key, des_ede3_wrap_cipher,
+    NULL,
+    sizeof(DES_EDE_KEY),
+    NULL, NULL, NULL, NULL
 };
 
 const EVP_CIPHER *EVP_des_ede3_wrap(void)
@@ -47,6 +422,4 @@ const EVP_CIPHER *EVP_des_ede3_wrap(void)
     return &des3_wrap;
 }
 
-#else
-NON_EMPTY_TRANSLATION_UNIT
 #endif
diff --git a/crypto/evp/e_idea.c b/crypto/evp/e_idea.c
index ed704672a3..0371094fe3 100644
--- a/crypto/evp/e_idea.c
+++ b/crypto/evp/e_idea.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,14 +7,72 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include 
+/*
+ * IDEA low level APIs are deprecated for public use, but still ok for internal
+ * use where we're using them to implement the higher level EVP interface, as is
+ * the case here.
+ */
+#include "internal/deprecated.h"
+
+#include 
+#include "internal/cryptlib.h"
 
 #ifndef OPENSSL_NO_IDEA
+#include 
+#include 
 #include "crypto/evp.h"
+#include 
+#include "evp_local.h"
 
-BLOCK_CIPHER_defs(idea, IDEA_KEY_SCHEDULE, NID_idea, 8, 16, 8, 64,
-    0)
+/* Can't use IMPLEMENT_BLOCK_CIPHER because IDEA_ecb_encrypt is different */
+
+typedef struct {
+    IDEA_KEY_SCHEDULE ks;
+} EVP_IDEA_KEY;
+
+static int idea_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc);
+
+/*
+ * NB IDEA_ecb_encrypt doesn't take an 'encrypt' argument so we treat it as a
+ * special case
+ */
+
+static int idea_ecb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    BLOCK_CIPHER_ecb_loop()
+        IDEA_ecb_encrypt(in + i, out + i, &EVP_C_DATA(EVP_IDEA_KEY, ctx)->ks);
+    return 1;
+}
+
+BLOCK_CIPHER_func_cbc(idea, IDEA, EVP_IDEA_KEY, ks)
+    BLOCK_CIPHER_func_ofb(idea, IDEA, 64, EVP_IDEA_KEY, ks)
+        BLOCK_CIPHER_func_cfb(idea, IDEA, 64, EVP_IDEA_KEY, ks)
+
+            BLOCK_CIPHER_defs(idea, IDEA_KEY_SCHEDULE, NID_idea, 8, 16, 8, 64,
+                0, idea_init_key, NULL,
+                EVP_CIPHER_set_asn1_iv, EVP_CIPHER_get_asn1_iv, NULL)
+
+                static int idea_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+                    const unsigned char *iv, int enc)
+{
+    if (!enc) {
+        if (EVP_CIPHER_CTX_get_mode(ctx) == EVP_CIPH_OFB_MODE)
+            enc = 1;
+        else if (EVP_CIPHER_CTX_get_mode(ctx) == EVP_CIPH_CFB_MODE)
+            enc = 1;
+    }
+    if (enc)
+        IDEA_set_encrypt_key(key, &EVP_C_DATA(EVP_IDEA_KEY, ctx)->ks);
+    else {
+        IDEA_KEY_SCHEDULE tmp;
+
+        IDEA_set_encrypt_key(key, &tmp);
+        IDEA_set_decrypt_key(&tmp, &EVP_C_DATA(EVP_IDEA_KEY, ctx)->ks);
+        OPENSSL_cleanse((unsigned char *)&tmp, sizeof(IDEA_KEY_SCHEDULE));
+    }
+    return 1;
+}
 
-#else
-NON_EMPTY_TRANSLATION_UNIT
 #endif
diff --git a/crypto/evp/e_null.c b/crypto/evp/e_null.c
index 67f3dc299b..1303caa892 100644
--- a/crypto/evp/e_null.c
+++ b/crypto/evp/e_null.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,15 +7,45 @@
  * https://www.openssl.org/source/license.html
  */
 
+#include 
+#include "internal/cryptlib.h"
+#include 
+#include 
 #include "crypto/evp.h"
 
+static int null_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc);
+static int null_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl);
 static const EVP_CIPHER n_cipher = {
     NID_undef,
     1, 0, 0, 0,
-    EVP_ORIG_GLOBAL
+    EVP_ORIG_GLOBAL,
+    null_init_key,
+    null_cipher,
+    NULL,
+    0,
+    NULL,
+    NULL,
+    NULL,
+    NULL
 };
 
 const EVP_CIPHER *EVP_enc_null(void)
 {
     return &n_cipher;
 }
+
+static int null_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    return 1;
+}
+
+static int null_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    if (in != out)
+        memcpy(out, in, inl);
+    return 1;
+}
diff --git a/crypto/evp/e_rc2.c b/crypto/evp/e_rc2.c
index 3420662c0c..88e359bd44 100644
--- a/crypto/evp/e_rc2.c
+++ b/crypto/evp/e_rc2.c
@@ -1,34 +1,82 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
  * in the file LICENSE in the source distribution or at
  * https://www.openssl.org/source/license.html
  */
-#include 
+
+/*
+ * RC2 low level APIs are deprecated for public use, but still ok for internal
+ * use.
+ */
+#include "internal/deprecated.h"
+
+#include 
+#include "internal/cryptlib.h"
 
 #ifndef OPENSSL_NO_RC2
+
+#include 
+#include 
 #include "crypto/evp.h"
 #include 
+#include "evp_local.h"
+
+static int rc2_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc);
+static int rc2_meth_to_magic(EVP_CIPHER_CTX *ctx);
+static int rc2_magic_to_meth(int i);
+static int rc2_set_asn1_type_and_iv(EVP_CIPHER_CTX *c, ASN1_TYPE *type);
+static int rc2_get_asn1_type_and_iv(EVP_CIPHER_CTX *c, ASN1_TYPE *type);
+static int rc2_ctrl(EVP_CIPHER_CTX *c, int type, int arg, void *ptr);
+
+typedef struct {
+    int key_bits; /* effective key bits */
+    RC2_KEY ks; /* key schedule */
+} EVP_RC2_KEY;
+
+#define data(ctx) EVP_C_DATA(EVP_RC2_KEY, ctx)
 
 IMPLEMENT_BLOCK_CIPHER(rc2, ks, RC2, EVP_RC2_KEY, NID_rc2,
     8,
     RC2_KEY_LENGTH, 8, 64,
-    EVP_CIPH_VARIABLE_LENGTH | EVP_CIPH_CTRL_INIT)
-
+    EVP_CIPH_VARIABLE_LENGTH | EVP_CIPH_CTRL_INIT,
+    rc2_init_key, NULL,
+    rc2_set_asn1_type_and_iv, rc2_get_asn1_type_and_iv,
+    rc2_ctrl)
+#define RC2_40_MAGIC 0xa0
+#define RC2_64_MAGIC 0x78
+#define RC2_128_MAGIC 0x3a
 static const EVP_CIPHER r2_64_cbc_cipher = {
     NID_rc2_64_cbc,
     8, 8 /* 64 bit */, 8,
     EVP_CIPH_CBC_MODE | EVP_CIPH_VARIABLE_LENGTH | EVP_CIPH_CTRL_INIT,
-    EVP_ORIG_GLOBAL
+    EVP_ORIG_GLOBAL,
+    rc2_init_key,
+    rc2_cbc_cipher,
+    NULL,
+    sizeof(EVP_RC2_KEY),
+    rc2_set_asn1_type_and_iv,
+    rc2_get_asn1_type_and_iv,
+    rc2_ctrl,
+    NULL
 };
 
 static const EVP_CIPHER r2_40_cbc_cipher = {
     NID_rc2_40_cbc,
     8, 5 /* 40 bit */, 8,
     EVP_CIPH_CBC_MODE | EVP_CIPH_VARIABLE_LENGTH | EVP_CIPH_CTRL_INIT,
-    EVP_ORIG_GLOBAL
+    EVP_ORIG_GLOBAL,
+    rc2_init_key,
+    rc2_cbc_cipher,
+    NULL,
+    sizeof(EVP_RC2_KEY),
+    rc2_set_asn1_type_and_iv,
+    rc2_get_asn1_type_and_iv,
+    rc2_ctrl,
+    NULL
 };
 
 const EVP_CIPHER *EVP_rc2_64_cbc(void)
@@ -41,6 +89,111 @@ const EVP_CIPHER *EVP_rc2_40_cbc(void)
     return &r2_40_cbc_cipher;
 }
 
-#else
-NON_EMPTY_TRANSLATION_UNIT
+static int rc2_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    RC2_set_key(&data(ctx)->ks, EVP_CIPHER_CTX_get_key_length(ctx),
+        key, data(ctx)->key_bits);
+    return 1;
+}
+
+static int rc2_meth_to_magic(EVP_CIPHER_CTX *e)
+{
+    int i;
+
+    if (EVP_CIPHER_CTX_ctrl(e, EVP_CTRL_GET_RC2_KEY_BITS, 0, &i) <= 0)
+        return 0;
+    if (i == 128)
+        return RC2_128_MAGIC;
+    else if (i == 64)
+        return RC2_64_MAGIC;
+    else if (i == 40)
+        return RC2_40_MAGIC;
+    else
+        return 0;
+}
+
+static int rc2_magic_to_meth(int i)
+{
+    if (i == RC2_128_MAGIC)
+        return 128;
+    else if (i == RC2_64_MAGIC)
+        return 64;
+    else if (i == RC2_40_MAGIC)
+        return 40;
+    else {
+        ERR_raise(ERR_LIB_EVP, EVP_R_UNSUPPORTED_KEY_SIZE);
+        return 0;
+    }
+}
+
+static int rc2_get_asn1_type_and_iv(EVP_CIPHER_CTX *c, ASN1_TYPE *type)
+{
+    long num = 0;
+    int i = 0;
+    int key_bits;
+    unsigned int l;
+    unsigned char iv[EVP_MAX_IV_LENGTH];
+
+    if (type != NULL) {
+        l = EVP_CIPHER_CTX_get_iv_length(c);
+        OPENSSL_assert(l <= sizeof(iv));
+        i = ASN1_TYPE_get_int_octetstring(type, &num, iv, l);
+        if (i != (int)l)
+            return -1;
+        key_bits = rc2_magic_to_meth((int)num);
+        if (!key_bits)
+            return -1;
+        if (i > 0 && !EVP_CipherInit_ex(c, NULL, NULL, NULL, iv, -1))
+            return -1;
+        if (EVP_CIPHER_CTX_ctrl(c, EVP_CTRL_SET_RC2_KEY_BITS, key_bits,
+                NULL)
+                <= 0
+            || EVP_CIPHER_CTX_set_key_length(c, key_bits / 8) <= 0)
+            return -1;
+    }
+    return i;
+}
+
+static int rc2_set_asn1_type_and_iv(EVP_CIPHER_CTX *c, ASN1_TYPE *type)
+{
+    long num;
+    int i = 0, j;
+
+    if (type != NULL) {
+        num = rc2_meth_to_magic(c);
+        j = EVP_CIPHER_CTX_get_iv_length(c);
+        i = ASN1_TYPE_set_int_octetstring(type, num, c->oiv, j);
+    }
+    return i;
+}
+
+static int rc2_ctrl(EVP_CIPHER_CTX *c, int type, int arg, void *ptr)
+{
+    switch (type) {
+    case EVP_CTRL_INIT:
+        data(c)->key_bits = EVP_CIPHER_CTX_get_key_length(c) * 8;
+        return 1;
+
+    case EVP_CTRL_GET_RC2_KEY_BITS:
+        *(int *)ptr = data(c)->key_bits;
+        return 1;
+
+    case EVP_CTRL_SET_RC2_KEY_BITS:
+        if (arg > 0) {
+            data(c)->key_bits = arg;
+            return 1;
+        }
+        return 0;
+#ifdef PBE_PRF_TEST
+    case EVP_CTRL_PBE_PRF_NID:
+        *(int *)ptr = NID_hmacWithMD5;
+        return 1;
+#endif
+
+    default:
+        return -1;
+    }
+}
+
 #endif
diff --git a/crypto/evp/e_rc4.c b/crypto/evp/e_rc4.c
index 0ca5773130..7ca5e797e5 100644
--- a/crypto/evp/e_rc4.c
+++ b/crypto/evp/e_rc4.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,23 +7,61 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include 
+/*
+ * RC4 low level APIs are deprecated for public use, but still ok for internal
+ * use.
+ */
+#include "internal/deprecated.h"
+
+#include 
+#include "internal/cryptlib.h"
 
 #ifndef OPENSSL_NO_RC4
+
+#include 
+#include 
+#include 
+
 #include "crypto/evp.h"
 
+typedef struct {
+    RC4_KEY ks; /* working key */
+} EVP_RC4_KEY;
+
+#define data(ctx) ((EVP_RC4_KEY *)EVP_CIPHER_CTX_get_cipher_data(ctx))
+
+static int rc4_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc);
+static int rc4_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl);
 static const EVP_CIPHER r4_cipher = {
     NID_rc4,
     1, EVP_RC4_KEY_SIZE, 0,
     EVP_CIPH_VARIABLE_LENGTH,
-    EVP_ORIG_GLOBAL
+    EVP_ORIG_GLOBAL,
+    rc4_init_key,
+    rc4_cipher,
+    NULL,
+    sizeof(EVP_RC4_KEY),
+    NULL,
+    NULL,
+    NULL,
+    NULL
 };
 
 static const EVP_CIPHER r4_40_cipher = {
     NID_rc4_40,
     1, 5 /* 40 bit */, 0,
     EVP_CIPH_VARIABLE_LENGTH,
-    EVP_ORIG_GLOBAL
+    EVP_ORIG_GLOBAL,
+    rc4_init_key,
+    rc4_cipher,
+    NULL,
+    sizeof(EVP_RC4_KEY),
+    NULL,
+    NULL,
+    NULL,
+    NULL
 };
 
 const EVP_CIPHER *EVP_rc4(void)
@@ -35,6 +73,22 @@ const EVP_CIPHER *EVP_rc4_40(void)
 {
     return &r4_40_cipher;
 }
-#else
-NON_EMPTY_TRANSLATION_UNIT
+
+static int rc4_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    int keylen;
+
+    if ((keylen = EVP_CIPHER_CTX_get_key_length(ctx)) <= 0)
+        return 0;
+    RC4_set_key(&data(ctx)->ks, keylen, key);
+    return 1;
+}
+
+static int rc4_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    RC4(&data(ctx)->ks, inl, in, out);
+    return 1;
+}
 #endif
diff --git a/crypto/evp/e_rc4_hmac_md5.c b/crypto/evp/e_rc4_hmac_md5.c
index 520b930b00..53d502650a 100644
--- a/crypto/evp/e_rc4_hmac_md5.c
+++ b/crypto/evp/e_rc4_hmac_md5.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2011-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2011-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,11 +7,239 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include 
+/*
+ * MD5 and RC4 low level APIs are deprecated for public use, but still ok for
+ * internal use.
+ */
+#include "internal/deprecated.h"
+
+#include "internal/cryptlib.h"
+#include 
+
+#include 
+#include 
 
 #if !defined(OPENSSL_NO_RC4) && !defined(OPENSSL_NO_MD5)
+
+#include 
+#include 
+#include 
+#include 
+#include 
 #include "crypto/evp.h"
 
+typedef struct {
+    RC4_KEY ks;
+    MD5_CTX head, tail, md;
+    size_t payload_length;
+} EVP_RC4_HMAC_MD5;
+
+#define NO_PAYLOAD_LENGTH ((size_t)-1)
+
+void rc4_md5_enc(RC4_KEY *key, const void *in0, void *out,
+    MD5_CTX *ctx, const void *inp, size_t blocks);
+
+#define data(ctx) ((EVP_RC4_HMAC_MD5 *)EVP_CIPHER_CTX_get_cipher_data(ctx))
+
+static int rc4_hmac_md5_init_key(EVP_CIPHER_CTX *ctx,
+    const unsigned char *inkey,
+    const unsigned char *iv, int enc)
+{
+    EVP_RC4_HMAC_MD5 *key = data(ctx);
+    const int keylen = EVP_CIPHER_CTX_get_key_length(ctx);
+
+    if (keylen <= 0)
+        return 0;
+
+    RC4_set_key(&key->ks, keylen, inkey);
+
+    MD5_Init(&key->head); /* handy when benchmarking */
+    key->tail = key->head;
+    key->md = key->head;
+
+    key->payload_length = NO_PAYLOAD_LENGTH;
+
+    return 1;
+}
+
+#if defined(RC4_ASM) && defined(MD5_ASM) && (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64))
+#define STITCHED_CALL
+#endif
+
+#if !defined(STITCHED_CALL)
+#define rc4_off 0
+#define md5_off 0
+#endif
+
+static int rc4_hmac_md5_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_RC4_HMAC_MD5 *key = data(ctx);
+#if defined(STITCHED_CALL)
+    size_t rc4_off = 32 - 1 - (key->ks.x & (32 - 1)), /* 32 is $MOD from
+                                                       * rc4_md5-x86_64.pl */
+        md5_off = MD5_CBLOCK - key->md.num, blocks;
+    unsigned int l;
+#endif
+    size_t plen = key->payload_length;
+
+    if (plen != NO_PAYLOAD_LENGTH && len != (plen + MD5_DIGEST_LENGTH))
+        return 0;
+
+    if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
+        if (plen == NO_PAYLOAD_LENGTH)
+            plen = len;
+#if defined(STITCHED_CALL)
+        /* cipher has to "fall behind" */
+        if (rc4_off > md5_off)
+            md5_off += MD5_CBLOCK;
+
+        if (plen > md5_off && (blocks = (plen - md5_off) / MD5_CBLOCK) && (OPENSSL_ia32cap_P[0] & (1 << 20)) == 0) {
+            MD5_Update(&key->md, in, md5_off);
+            RC4(&key->ks, rc4_off, in, out);
+
+            rc4_md5_enc(&key->ks, in + rc4_off, out + rc4_off,
+                &key->md, in + md5_off, blocks);
+            blocks *= MD5_CBLOCK;
+            rc4_off += blocks;
+            md5_off += blocks;
+            key->md.Nh += (unsigned int)(blocks >> 29);
+            key->md.Nl += (unsigned int)(blocks <<= 3);
+            if (key->md.Nl < (unsigned int)blocks)
+                key->md.Nh++;
+        } else {
+            rc4_off = 0;
+            md5_off = 0;
+        }
+#endif
+        MD5_Update(&key->md, in + md5_off, plen - md5_off);
+
+        if (plen != len) { /* "TLS" mode of operation */
+            if (in != out)
+                memcpy(out + rc4_off, in + rc4_off, plen - rc4_off);
+
+            /* calculate HMAC and append it to payload */
+            MD5_Final(out + plen, &key->md);
+            key->md = key->tail;
+            MD5_Update(&key->md, out + plen, MD5_DIGEST_LENGTH);
+            MD5_Final(out + plen, &key->md);
+            /* encrypt HMAC at once */
+            RC4(&key->ks, len - rc4_off, out + rc4_off, out + rc4_off);
+        } else {
+            RC4(&key->ks, len - rc4_off, in + rc4_off, out + rc4_off);
+        }
+    } else {
+        unsigned char mac[MD5_DIGEST_LENGTH];
+#if defined(STITCHED_CALL)
+        /* digest has to "fall behind" */
+        if (md5_off > rc4_off)
+            rc4_off += 2 * MD5_CBLOCK;
+        else
+            rc4_off += MD5_CBLOCK;
+
+        if (len > rc4_off && (blocks = (len - rc4_off) / MD5_CBLOCK) && (OPENSSL_ia32cap_P[0] & (1 << 20)) == 0) {
+            RC4(&key->ks, rc4_off, in, out);
+            MD5_Update(&key->md, out, md5_off);
+
+            rc4_md5_enc(&key->ks, in + rc4_off, out + rc4_off,
+                &key->md, out + md5_off, blocks);
+            blocks *= MD5_CBLOCK;
+            rc4_off += blocks;
+            md5_off += blocks;
+            l = (key->md.Nl + (blocks << 3)) & 0xffffffffU;
+            if (l < key->md.Nl)
+                key->md.Nh++;
+            key->md.Nl = l;
+            key->md.Nh += (unsigned int)(blocks >> 29);
+        } else {
+            md5_off = 0;
+            rc4_off = 0;
+        }
+#endif
+        /* decrypt HMAC at once */
+        RC4(&key->ks, len - rc4_off, in + rc4_off, out + rc4_off);
+        if (plen != NO_PAYLOAD_LENGTH) { /* "TLS" mode of operation */
+            MD5_Update(&key->md, out + md5_off, plen - md5_off);
+
+            /* calculate HMAC and verify it */
+            MD5_Final(mac, &key->md);
+            key->md = key->tail;
+            MD5_Update(&key->md, mac, MD5_DIGEST_LENGTH);
+            MD5_Final(mac, &key->md);
+
+            if (CRYPTO_memcmp(out + plen, mac, MD5_DIGEST_LENGTH))
+                return 0;
+        } else {
+            MD5_Update(&key->md, out + md5_off, len - md5_off);
+        }
+    }
+
+    key->payload_length = NO_PAYLOAD_LENGTH;
+
+    return 1;
+}
+
+static int rc4_hmac_md5_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg,
+    void *ptr)
+{
+    EVP_RC4_HMAC_MD5 *key = data(ctx);
+
+    switch (type) {
+    case EVP_CTRL_AEAD_SET_MAC_KEY: {
+        unsigned int i;
+        unsigned char hmac_key[64];
+
+        memset(hmac_key, 0, sizeof(hmac_key));
+
+        if (arg > (int)sizeof(hmac_key)) {
+            MD5_Init(&key->head);
+            MD5_Update(&key->head, ptr, arg);
+            MD5_Final(hmac_key, &key->head);
+        } else {
+            memcpy(hmac_key, ptr, arg);
+        }
+
+        for (i = 0; i < sizeof(hmac_key); i++)
+            hmac_key[i] ^= 0x36; /* ipad */
+        MD5_Init(&key->head);
+        MD5_Update(&key->head, hmac_key, sizeof(hmac_key));
+
+        for (i = 0; i < sizeof(hmac_key); i++)
+            hmac_key[i] ^= 0x36 ^ 0x5c; /* opad */
+        MD5_Init(&key->tail);
+        MD5_Update(&key->tail, hmac_key, sizeof(hmac_key));
+
+        OPENSSL_cleanse(hmac_key, sizeof(hmac_key));
+
+        return 1;
+    }
+    case EVP_CTRL_AEAD_TLS1_AAD: {
+        unsigned char *p = ptr;
+        unsigned int len;
+
+        if (arg != EVP_AEAD_TLS1_AAD_LEN)
+            return -1;
+
+        len = p[arg - 2] << 8 | p[arg - 1];
+
+        if (!EVP_CIPHER_CTX_is_encrypting(ctx)) {
+            if (len < MD5_DIGEST_LENGTH)
+                return -1;
+            len -= MD5_DIGEST_LENGTH;
+            p[arg - 2] = len >> 8;
+            p[arg - 1] = len;
+        }
+        key->payload_length = len;
+        key->md = key->head;
+        MD5_Update(&key->md, p, arg);
+
+        return MD5_DIGEST_LENGTH;
+    }
+    default:
+        return -1;
+    }
+}
+
 static const EVP_CIPHER r4_hmac_md5_cipher = {
 #ifdef NID_rc4_hmac_md5
     NID_rc4_hmac_md5,
@@ -20,13 +248,19 @@ static const EVP_CIPHER r4_hmac_md5_cipher = {
 #endif
     1, EVP_RC4_KEY_SIZE, 0,
     EVP_CIPH_STREAM_CIPHER | EVP_CIPH_VARIABLE_LENGTH | EVP_CIPH_FLAG_AEAD_CIPHER,
-    EVP_ORIG_GLOBAL
+    EVP_ORIG_GLOBAL,
+    rc4_hmac_md5_init_key,
+    rc4_hmac_md5_cipher,
+    NULL,
+    sizeof(EVP_RC4_HMAC_MD5),
+    NULL,
+    NULL,
+    rc4_hmac_md5_ctrl,
+    NULL
 };
 
 const EVP_CIPHER *EVP_rc4_hmac_md5(void)
 {
     return &r4_hmac_md5_cipher;
 }
-#else
-NON_EMPTY_TRANSLATION_UNIT
 #endif
diff --git a/crypto/evp/e_rc5.c b/crypto/evp/e_rc5.c
index f7a2af207f..5133b28d36 100644
--- a/crypto/evp/e_rc5.c
+++ b/crypto/evp/e_rc5.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,16 +7,78 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include 
+/*
+ * RC5 low level APIs are deprecated for public use, but still ok for internal
+ * use.
+ */
+#include "internal/deprecated.h"
+
+#include 
+#include "internal/cryptlib.h"
 
 #ifndef OPENSSL_NO_RC5
+
+#include 
 #include "crypto/evp.h"
+#include 
+#include "evp_local.h"
 #include 
 
+static int r_32_12_16_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc);
+static int rc5_ctrl(EVP_CIPHER_CTX *c, int type, int arg, void *ptr);
+
+typedef struct {
+    int rounds; /* number of rounds */
+    RC5_32_KEY ks; /* key schedule */
+} EVP_RC5_KEY;
+
+#define data(ctx) EVP_C_DATA(EVP_RC5_KEY, ctx)
+
 IMPLEMENT_BLOCK_CIPHER(rc5_32_12_16, ks, RC5_32, EVP_RC5_KEY, NID_rc5,
     8, RC5_32_KEY_LENGTH, 8, 64,
-    EVP_CIPH_VARIABLE_LENGTH | EVP_CIPH_CTRL_INIT)
+    EVP_CIPH_VARIABLE_LENGTH | EVP_CIPH_CTRL_INIT,
+    r_32_12_16_init_key, NULL, NULL, NULL, rc5_ctrl)
+
+static int rc5_ctrl(EVP_CIPHER_CTX *c, int type, int arg, void *ptr)
+{
+    switch (type) {
+    case EVP_CTRL_INIT:
+        data(c)->rounds = RC5_12_ROUNDS;
+        return 1;
+
+    case EVP_CTRL_GET_RC5_ROUNDS:
+        *(int *)ptr = data(c)->rounds;
+        return 1;
+
+    case EVP_CTRL_SET_RC5_ROUNDS:
+        switch (arg) {
+        case RC5_8_ROUNDS:
+        case RC5_12_ROUNDS:
+        case RC5_16_ROUNDS:
+            data(c)->rounds = arg;
+            return 1;
+
+        default:
+            ERR_raise(ERR_LIB_EVP, EVP_R_UNSUPPORTED_NUMBER_OF_ROUNDS);
+            return 0;
+        }
+
+    default:
+        return -1;
+    }
+}
+
+static int r_32_12_16_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    const int key_len = EVP_CIPHER_CTX_get_key_length(ctx);
+
+    if (key_len > 255 || key_len < 0) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_BAD_KEY_LENGTH);
+        return 0;
+    }
+    return RC5_32_set_key(&data(ctx)->ks, key_len, key, data(ctx)->rounds);
+}
 
-#else
-NON_EMPTY_TRANSLATION_UNIT
 #endif
diff --git a/crypto/evp/e_seed.c b/crypto/evp/e_seed.c
index 5884995abe..a88cab0294 100644
--- a/crypto/evp/e_seed.c
+++ b/crypto/evp/e_seed.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2007-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2007-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,7 +7,35 @@
  * https://www.openssl.org/source/license.html
  */
 
+/*
+ * SEED low level APIs are deprecated for public use, but still ok for
+ * internal use.
+ */
+#include "internal/deprecated.h"
+
+#include 
+#include 
+#include 
+#include 
+#include 
+#include 
 #include "crypto/evp.h"
+#include "evp_local.h"
+
+static int seed_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc);
+
+typedef struct {
+    SEED_KEY_SCHEDULE ks;
+} EVP_SEED_KEY;
 
 IMPLEMENT_BLOCK_CIPHER(seed, ks, SEED, EVP_SEED_KEY, NID_seed,
-    16, 16, 16, 128, EVP_CIPH_FLAG_DEFAULT_ASN1)
+    16, 16, 16, 128, EVP_CIPH_FLAG_DEFAULT_ASN1,
+    seed_init_key, 0, 0, 0, 0)
+
+static int seed_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    SEED_set_key(key, &EVP_C_DATA(EVP_SEED_KEY, ctx)->ks);
+    return 1;
+}
diff --git a/crypto/evp/e_sm4.c b/crypto/evp/e_sm4.c
index bf10d3d390..f833e75516 100644
--- a/crypto/evp/e_sm4.c
+++ b/crypto/evp/e_sm4.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2017-2022 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright 2017 Ribose Inc. All Rights Reserved.
  * Ported from Ribose contributions from Botan.
  *
@@ -9,30 +9,222 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include 
+#include "internal/deprecated.h"
 
+#include "internal/cryptlib.h"
 #ifndef OPENSSL_NO_SM4
+#include 
+#include 
+#include "crypto/sm4.h"
 #include "crypto/evp.h"
+#include "crypto/sm4_platform.h"
+#include "evp_local.h"
+
+typedef struct {
+    union {
+        OSSL_UNION_ALIGN;
+        SM4_KEY ks;
+    } ks;
+    block128_f block;
+    union {
+        ecb128_f ecb;
+        cbc128_f cbc;
+        ctr128_f ctr;
+    } stream;
+} EVP_SM4_KEY;
 
 #define BLOCK_CIPHER_generic(nid, blocksize, ivlen, nmode, mode, MODE, flags) \
     static const EVP_CIPHER sm4_##mode = {                                    \
         nid##_##nmode, blocksize, 128 / 8, ivlen,                             \
         flags | EVP_CIPH_##MODE##_MODE,                                       \
-        EVP_ORIG_GLOBAL                                                       \
+        EVP_ORIG_GLOBAL,                                                      \
+        sm4_init_key,                                                         \
+        sm4_##mode##_cipher,                                                  \
+        NULL,                                                                 \
+        sizeof(EVP_SM4_KEY),                                                  \
+        NULL, NULL, NULL, NULL                                                \
     };                                                                        \
     const EVP_CIPHER *EVP_sm4_##mode(void)                                    \
     {                                                                         \
         return &sm4_##mode;                                                   \
     }
 
-#define DEFINE_BLOCK_CIPHERS(nid, flags)                                                   \
-    BLOCK_CIPHER_generic(nid, 16, 16, cbc, cbc, CBC, flags | EVP_CIPH_FLAG_DEFAULT_ASN1)   \
-    BLOCK_CIPHER_generic(nid, 16, 0, ecb, ecb, ECB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1)    \
-    BLOCK_CIPHER_generic(nid, 1, 16, ofb128, ofb, OFB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1) \
-    BLOCK_CIPHER_generic(nid, 1, 16, cfb128, cfb, CFB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1) \
-    BLOCK_CIPHER_generic(nid, 1, 16, ctr, ctr, CTR, flags)
+#define DEFINE_BLOCK_CIPHERS(nid, flags)                                                               \
+    BLOCK_CIPHER_generic(nid, 16, 16, cbc, cbc, CBC, flags | EVP_CIPH_FLAG_DEFAULT_ASN1)               \
+        BLOCK_CIPHER_generic(nid, 16, 0, ecb, ecb, ECB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1)            \
+            BLOCK_CIPHER_generic(nid, 1, 16, ofb128, ofb, OFB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1)     \
+                BLOCK_CIPHER_generic(nid, 1, 16, cfb128, cfb, CFB, flags | EVP_CIPH_FLAG_DEFAULT_ASN1) \
+                    BLOCK_CIPHER_generic(nid, 1, 16, ctr, ctr, CTR, flags)
+
+static int sm4_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    int mode;
+    EVP_SM4_KEY *dat = EVP_C_DATA(EVP_SM4_KEY, ctx);
+
+    mode = EVP_CIPHER_CTX_get_mode(ctx);
+    if ((mode == EVP_CIPH_ECB_MODE || mode == EVP_CIPH_CBC_MODE)
+        && !enc) {
+#ifdef HWSM4_CAPABLE
+        if (HWSM4_CAPABLE) {
+            HWSM4_set_decrypt_key(key, &dat->ks.ks);
+            dat->block = (block128_f)HWSM4_decrypt;
+            dat->stream.cbc = NULL;
+#ifdef HWSM4_cbc_encrypt
+            if (mode == EVP_CIPH_CBC_MODE)
+                dat->stream.cbc = (cbc128_f)HWSM4_cbc_encrypt;
+#endif
+#ifdef HWSM4_ecb_encrypt
+            if (mode == EVP_CIPH_ECB_MODE)
+                dat->stream.ecb = (ecb128_f)HWSM4_ecb_encrypt;
+#endif
+        } else
+#endif
+#ifdef VPSM4_CAPABLE
+            if (VPSM4_CAPABLE) {
+            vpsm4_set_decrypt_key(key, &dat->ks.ks);
+            dat->block = (block128_f)vpsm4_decrypt;
+            dat->stream.cbc = NULL;
+            if (mode == EVP_CIPH_CBC_MODE)
+                dat->stream.cbc = (cbc128_f)vpsm4_cbc_encrypt;
+            else if (mode == EVP_CIPH_ECB_MODE)
+                dat->stream.ecb = (ecb128_f)vpsm4_ecb_encrypt;
+        } else
+#endif
+        {
+            dat->block = (block128_f)ossl_sm4_decrypt;
+            ossl_sm4_set_key(key, EVP_CIPHER_CTX_get_cipher_data(ctx));
+        }
+    } else
+#ifdef HWSM4_CAPABLE
+        if (HWSM4_CAPABLE) {
+        HWSM4_set_encrypt_key(key, &dat->ks.ks);
+        dat->block = (block128_f)HWSM4_encrypt;
+        dat->stream.cbc = NULL;
+#ifdef HWSM4_cbc_encrypt
+        if (mode == EVP_CIPH_CBC_MODE)
+            dat->stream.cbc = (cbc128_f)HWSM4_cbc_encrypt;
+        else
+#endif
+#ifdef HWSM4_ecb_encrypt
+            if (mode == EVP_CIPH_ECB_MODE)
+            dat->stream.ecb = (ecb128_f)HWSM4_ecb_encrypt;
+        else
+#endif
+#ifdef HWSM4_ctr32_encrypt_blocks
+            if (mode == EVP_CIPH_CTR_MODE)
+            dat->stream.ctr = (ctr128_f)HWSM4_ctr32_encrypt_blocks;
+        else
+#endif
+            (void)0; /* terminate potentially open 'else' */
+    } else
+#endif
+#ifdef VPSM4_CAPABLE
+        if (VPSM4_CAPABLE) {
+        vpsm4_set_encrypt_key(key, &dat->ks.ks);
+        dat->block = (block128_f)vpsm4_encrypt;
+        dat->stream.cbc = NULL;
+        if (mode == EVP_CIPH_CBC_MODE)
+            dat->stream.cbc = (cbc128_f)vpsm4_cbc_encrypt;
+        else if (mode == EVP_CIPH_ECB_MODE)
+            dat->stream.ecb = (ecb128_f)vpsm4_ecb_encrypt;
+        else if (mode == EVP_CIPH_CTR_MODE)
+            dat->stream.ctr = (ctr128_f)vpsm4_ctr32_encrypt_blocks;
+    } else
+#endif
+    {
+        dat->block = (block128_f)ossl_sm4_encrypt;
+        ossl_sm4_set_key(key, EVP_CIPHER_CTX_get_cipher_data(ctx));
+    }
+    return 1;
+}
+
+static int sm4_cbc_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_SM4_KEY *dat = EVP_C_DATA(EVP_SM4_KEY, ctx);
+
+    if (dat->stream.cbc)
+        (*dat->stream.cbc)(in, out, len, &dat->ks.ks, ctx->iv,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+    else if (EVP_CIPHER_CTX_is_encrypting(ctx))
+        CRYPTO_cbc128_encrypt(in, out, len, &dat->ks, ctx->iv,
+            dat->block);
+    else
+        CRYPTO_cbc128_decrypt(in, out, len, &dat->ks,
+            ctx->iv, dat->block);
+    return 1;
+}
+
+static int sm4_cfb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_SM4_KEY *dat = EVP_C_DATA(EVP_SM4_KEY, ctx);
+    int num = EVP_CIPHER_CTX_get_num(ctx);
+
+    CRYPTO_cfb128_encrypt(in, out, len, &dat->ks,
+        ctx->iv, &num,
+        EVP_CIPHER_CTX_is_encrypting(ctx), dat->block);
+    EVP_CIPHER_CTX_set_num(ctx, num);
+    return 1;
+}
+
+static int sm4_ecb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    size_t bl = EVP_CIPHER_CTX_get_block_size(ctx);
+    size_t i;
+    EVP_SM4_KEY *dat = EVP_C_DATA(EVP_SM4_KEY, ctx);
+
+    if (len < bl)
+        return 1;
+
+    if (dat->stream.ecb != NULL)
+        (*dat->stream.ecb)(in, out, len, &dat->ks.ks,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+    else
+        for (i = 0, len -= bl; i <= len; i += bl)
+            (*dat->block)(in + i, out + i, &dat->ks);
+
+    return 1;
+}
+
+static int sm4_ofb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    EVP_SM4_KEY *dat = EVP_C_DATA(EVP_SM4_KEY, ctx);
+    int num = EVP_CIPHER_CTX_get_num(ctx);
+
+    CRYPTO_ofb128_encrypt(in, out, len, &dat->ks,
+        ctx->iv, &num, dat->block);
+    EVP_CIPHER_CTX_set_num(ctx, num);
+    return 1;
+}
+
+static int sm4_ctr_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t len)
+{
+    int n = EVP_CIPHER_CTX_get_num(ctx);
+    unsigned int num;
+    EVP_SM4_KEY *dat = EVP_C_DATA(EVP_SM4_KEY, ctx);
+
+    if (n < 0)
+        return 0;
+    num = (unsigned int)n;
+
+    if (dat->stream.ctr)
+        CRYPTO_ctr128_encrypt_ctr32(in, out, len, &dat->ks,
+            ctx->iv,
+            EVP_CIPHER_CTX_buf_noconst(ctx),
+            &num, dat->stream.ctr);
+    else
+        CRYPTO_ctr128_encrypt(in, out, len, &dat->ks,
+            ctx->iv,
+            EVP_CIPHER_CTX_buf_noconst(ctx), &num,
+            dat->block);
+    EVP_CIPHER_CTX_set_num(ctx, num);
+    return 1;
+}
 
 DEFINE_BLOCK_CIPHERS(NID_sm4, 0)
-#else
-NON_EMPTY_TRANSLATION_UNIT
 #endif
diff --git a/crypto/evp/e_xcbc_d.c b/crypto/evp/e_xcbc_d.c
index 6cda6f7053..eaa021be2c 100644
--- a/crypto/evp/e_xcbc_d.c
+++ b/crypto/evp/e_xcbc_d.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,22 +7,85 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include 
+/*
+ * DES low level APIs are deprecated for public use, but still ok for internal
+ * use.
+ */
+#include "internal/deprecated.h"
+
+#include 
+#include "internal/cryptlib.h"
 
 #ifndef OPENSSL_NO_DES
+
+#include 
+#include 
 #include "crypto/evp.h"
+#include 
+#include "evp_local.h"
+
+static int desx_cbc_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc);
+static int desx_cbc_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl);
+
+typedef struct {
+    DES_key_schedule ks; /* key schedule */
+    DES_cblock inw;
+    DES_cblock outw;
+} DESX_CBC_KEY;
+
+#define data(ctx) EVP_C_DATA(DESX_CBC_KEY, ctx)
 
 static const EVP_CIPHER d_xcbc_cipher = {
     NID_desx_cbc,
     8, 24, 8,
     EVP_CIPH_CBC_MODE,
-    EVP_ORIG_GLOBAL
+    EVP_ORIG_GLOBAL,
+    desx_cbc_init_key,
+    desx_cbc_cipher,
+    NULL,
+    sizeof(DESX_CBC_KEY),
+    EVP_CIPHER_set_asn1_iv,
+    EVP_CIPHER_get_asn1_iv,
+    NULL,
+    NULL
 };
 
 const EVP_CIPHER *EVP_desx_cbc(void)
 {
     return &d_xcbc_cipher;
 }
-#else
-NON_EMPTY_TRANSLATION_UNIT
+
+static int desx_cbc_init_key(EVP_CIPHER_CTX *ctx, const unsigned char *key,
+    const unsigned char *iv, int enc)
+{
+    DES_cblock *deskey = (DES_cblock *)key;
+
+    DES_set_key_unchecked(deskey, &data(ctx)->ks);
+    memcpy(&data(ctx)->inw[0], &key[8], 8);
+    memcpy(&data(ctx)->outw[0], &key[16], 8);
+
+    return 1;
+}
+
+static int desx_cbc_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
+    const unsigned char *in, size_t inl)
+{
+    while (inl >= EVP_MAXCHUNK) {
+        DES_xcbc_encrypt(in, out, (long)EVP_MAXCHUNK, &data(ctx)->ks,
+            (DES_cblock *)ctx->iv,
+            &data(ctx)->inw, &data(ctx)->outw,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+        inl -= EVP_MAXCHUNK;
+        in += EVP_MAXCHUNK;
+        out += EVP_MAXCHUNK;
+    }
+    if (inl)
+        DES_xcbc_encrypt(in, out, (long)inl, &data(ctx)->ks,
+            (DES_cblock *)ctx->iv,
+            &data(ctx)->inw, &data(ctx)->outw,
+            EVP_CIPHER_CTX_is_encrypting(ctx));
+    return 1;
+}
 #endif
diff --git a/crypto/evp/ec_ctrl.c b/crypto/evp/ec_ctrl.c
index be772003e1..096f7f18d7 100644
--- a/crypto/evp/ec_ctrl.c
+++ b/crypto/evp/ec_ctrl.c
@@ -30,7 +30,7 @@ static ossl_inline int evp_pkey_ctx_getset_ecdh_param_checks(const EVP_PKEY_CTX
 
     /* If key type not EC return error */
     if (evp_pkey_ctx_is_legacy(ctx)
-        && ctx->legacy_keytype != EVP_PKEY_EC)
+        && ctx->pmeth != NULL && ctx->pmeth->pkey_id != EVP_PKEY_EC)
         return -1;
 
     return 1;
diff --git a/crypto/evp/ec_support.c b/crypto/evp/ec_support.c
index 4763507ec1..20883c48f1 100644
--- a/crypto/evp/ec_support.c
+++ b/crypto/evp/ec_support.c
@@ -9,7 +9,6 @@
 
 #include 
 #include 
-#include 
 #include "crypto/ec.h"
 #include "internal/nelem.h"
 
@@ -187,51 +186,3 @@ int ossl_ec_curve_nist2nid_int(const char *name)
     }
     return NID_undef;
 }
-
-int EVP_EC_affine2oct(const BIGNUM *x, const BIGNUM *y, size_t field_len,
-    unsigned char **pbuf, size_t *pbsize)
-{
-    unsigned char *buf = NULL;
-    size_t buflen = 0;
-
-    if (x == NULL || y == NULL || pbuf == NULL || pbsize == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
-    if (field_len > 2048) {
-        ERR_raise_data(ERR_LIB_CRYPTO, ERR_R_PASSED_INVALID_ARGUMENT,
-            "The value of field_len is unreasonably large");
-        return 0;
-    }
-
-    /* Checking if affine coordinates are not too long */
-    if (BN_num_bytes(x) > (int)field_len || BN_num_bytes(y) > (int)field_len) {
-        ERR_raise_data(ERR_LIB_CRYPTO, ERR_R_PASSED_INVALID_ARGUMENT,
-            "EC affine coordinate exceeds field length");
-        return 0;
-    }
-
-    /* Converting (X,Y) to the SEC1 uncompressed point encoding blob */
-    buflen = 1 + 2 * field_len;
-    buf = OPENSSL_malloc(buflen);
-    if (buf == NULL)
-        return 0;
-    buf[0] = POINT_CONVERSION_UNCOMPRESSED;
-    if (BN_bn2binpad(x, buf + 1, (int)field_len) < 0) {
-        ERR_raise_data(ERR_LIB_CRYPTO, ERR_R_PASSED_INVALID_ARGUMENT,
-            "failed to encode X coordinate");
-        OPENSSL_free(buf);
-        return 0;
-    }
-    if (BN_bn2binpad(y, buf + 1 + field_len, (int)field_len) < 0) {
-        ERR_raise_data(ERR_LIB_CRYPTO, ERR_R_PASSED_INVALID_ARGUMENT,
-            "failed to encode Y coordinate");
-        OPENSSL_free(buf);
-        return 0;
-    }
-
-    *pbuf = buf;
-    *pbsize = buflen;
-    return 1;
-}
diff --git a/crypto/evp/enc_b64_avx2.c b/crypto/evp/enc_b64_avx2.c
deleted file mode 100644
index dafa834a48..0000000000
--- a/crypto/evp/enc_b64_avx2.c
+++ /dev/null
@@ -1,674 +0,0 @@
-#include 
-#include "enc_b64_scalar.h"
-#include "enc_b64_avx2.h"
-#include "internal/cryptlib.h"
-#include "crypto/evp.h"
-#include "evp_local.h"
-
-#if defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)
-#if !defined(_M_ARM64EC)
-#if defined(HAVE_AVX2_INTRINSICS)
-#define STRINGIFY_IMPLEMENTATION_(a) #a
-#define STRINGIFY(a) STRINGIFY_IMPLEMENTATION_(a)
-
-#ifdef __clang__
-/*
- * clang does not have GCC push pop
- * warning: clang attribute push can't be used within a namespace in clang up
- * til 8.0 so OPENSSL_TARGET_REGION and OPENSSL_UNTARGET_REGION must be
- * outside* of a namespace.
- */
-#define OPENSSL_TARGET_REGION(T)                                       \
-    _Pragma(STRINGIFY(clang attribute push(__attribute__((target(T))), \
-        apply_to = function)))
-#define OPENSSL_UNTARGET_REGION _Pragma("clang attribute pop")
-#elif defined(__GNUC__)
-#define OPENSSL_TARGET_REGION(T) \
-    _Pragma("GCC push_options") _Pragma(STRINGIFY(GCC target(T)))
-#define OPENSSL_UNTARGET_REGION _Pragma("GCC pop_options")
-#endif /* clang then gcc */
-
-/* Default target region macros don't do anything. */
-#ifndef OPENSSL_TARGET_REGION
-#define OPENSSL_TARGET_REGION(T)
-#define OPENSSL_UNTARGET_REGION
-#endif
-
-#define OPENSSL_TARGET_AVX2 \
-    OPENSSL_TARGET_REGION("avx2")
-#define OPENSSL_UNTARGET_AVX2 OPENSSL_UNTARGET_REGION
-
-/*
- * Ensure this whole block is compiled with AVX2 enabled on GCC.
- * Clang/MSVC will just ignore these pragmas.
- */
-
-#include 
-#include 
-#include 
-#include 
-
-OPENSSL_TARGET_AVX2
-static __m256i lookup_pshufb_std(__m256i input)
-{
-    __m256i result = _mm256_subs_epu8(input, _mm256_set1_epi8(51));
-    const __m256i less = _mm256_cmpgt_epi8(_mm256_set1_epi8(26), input);
-
-    result = _mm256_or_si256(result, _mm256_and_si256(less, _mm256_set1_epi8(13)));
-    __m256i shift_LUT = _mm256_setr_epi8('a' - 26, '0' - 52, '0' - 52, '0' - 52, '0' - 52,
-        '0' - 52, '0' - 52,
-        '0' - 52, '0' - 52, '0' - 52, '0' - 52, '+' - 62,
-        '/' - 63, 'A', 0, 0,
-        'a' - 26, '0' - 52, '0' - 52, '0' - 52, '0' - 52,
-        '0' - 52, '0' - 52,
-        '0' - 52, '0' - 52, '0' - 52, '0' - 52, '+' - 62,
-        '/' - 63, 'A', 0, 0);
-
-    result = _mm256_shuffle_epi8(shift_LUT, result);
-    return _mm256_add_epi8(result, input);
-}
-OPENSSL_UNTARGET_AVX2
-
-OPENSSL_TARGET_AVX2
-static ossl_inline __m256i lookup_pshufb_srp(__m256i input)
-{
-    const __m256i zero = _mm256_setzero_si256();
-    const __m256i hi = _mm256_set1_epi8((char)0x80);
-    __m256i invalid = _mm256_or_si256(_mm256_cmpgt_epi8(zero, input),
-        _mm256_cmpgt_epi8(input,
-            _mm256_set1_epi8(63)));
-    __m256i idx = _mm256_setzero_si256();
-
-    idx = _mm256_sub_epi8(idx, _mm256_cmpgt_epi8(input, _mm256_set1_epi8(9)));
-    idx = _mm256_sub_epi8(idx, _mm256_cmpgt_epi8(input, _mm256_set1_epi8(35)));
-    idx = _mm256_blendv_epi8(idx, _mm256_set1_epi8(3),
-        _mm256_cmpeq_epi8(input, _mm256_set1_epi8(62)));
-    idx = _mm256_blendv_epi8(idx, _mm256_set1_epi8(4),
-        _mm256_cmpeq_epi8(input, _mm256_set1_epi8(63)));
-
-    /* Zero-out invalid lanes via PSHUFB's high-bit mechanism */
-    idx = _mm256_or_si256(idx, _mm256_and_si256(invalid, hi));
-
-    const __m256i shift_LUT = _mm256_setr_epi8('0' - 0, 'A' - 10, 'a' - 36, '.' - 62, '/' - 63, 0, 0,
-        0, 0, 0, 0, 0, 0, 0, 0, 0,
-        '0' - 0, 'A' - 10, 'a' - 36, '.' - 62, '/' - 63, 0, 0,
-        0, 0, 0, 0, 0, 0, 0, 0, 0);
-
-    __m256i shift = _mm256_shuffle_epi8(shift_LUT, idx);
-    __m256i ascii = _mm256_add_epi8(shift, input);
-    return ascii;
-}
-OPENSSL_UNTARGET_AVX2
-
-OPENSSL_TARGET_AVX2
-static ossl_inline __m256i shift_right_zeros(__m256i v, int n)
-{
-    switch (n) {
-    case 0:
-        return v;
-    case 1:
-        return _mm256_srli_si256(v, 1);
-    case 2:
-        return _mm256_srli_si256(v, 2);
-    case 3:
-        return _mm256_srli_si256(v, 3);
-    case 4:
-        return _mm256_srli_si256(v, 4);
-    case 5:
-        return _mm256_srli_si256(v, 5);
-    case 6:
-        return _mm256_srli_si256(v, 6);
-    case 7:
-        return _mm256_srli_si256(v, 7);
-    case 8:
-        return _mm256_srli_si256(v, 8);
-    case 9:
-        return _mm256_srli_si256(v, 9);
-    case 10:
-        return _mm256_srli_si256(v, 10);
-    case 11:
-        return _mm256_srli_si256(v, 11);
-    case 12:
-        return _mm256_srli_si256(v, 12);
-    case 13:
-        return _mm256_srli_si256(v, 13);
-    case 14:
-        return _mm256_srli_si256(v, 14);
-    case 15:
-        return _mm256_srli_si256(v, 15);
-    default:
-        return _mm256_setzero_si256();
-    }
-}
-OPENSSL_UNTARGET_AVX2
-
-OPENSSL_TARGET_AVX2
-static ossl_inline __m256i shift_left_zeros(__m256i v, int n)
-{
-    switch (n) {
-    case 0:
-        return v;
-    case 1:
-        return _mm256_slli_si256(v, 1);
-    case 2:
-        return _mm256_slli_si256(v, 2);
-    case 3:
-        return _mm256_slli_si256(v, 3);
-    case 4:
-        return _mm256_slli_si256(v, 4);
-    case 5:
-        return _mm256_slli_si256(v, 5);
-    case 6:
-        return _mm256_slli_si256(v, 6);
-    case 7:
-        return _mm256_slli_si256(v, 7);
-    case 8:
-        return _mm256_slli_si256(v, 8);
-    case 9:
-        return _mm256_slli_si256(v, 9);
-    case 10:
-        return _mm256_slli_si256(v, 10);
-    case 11:
-        return _mm256_slli_si256(v, 11);
-    case 12:
-        return _mm256_slli_si256(v, 12);
-    case 13:
-        return _mm256_slli_si256(v, 13);
-    case 14:
-        return _mm256_slli_si256(v, 14);
-    case 15:
-        return _mm256_slli_si256(v, 15);
-    case 16:
-        return _mm256_setzero_si256();
-    default:
-        return _mm256_setzero_si256();
-    }
-}
-OPENSSL_UNTARGET_AVX2
-
-static const uint8_t shuffle_masks[16][16] = {
-    { 0x80, 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 },
-    { 0, 0x80, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 },
-    { 0, 1, 0x80, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 },
-    { 0, 1, 2, 0x80, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 },
-    { 0, 1, 2, 3, 0x80, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 },
-    { 0, 1, 2, 3, 4, 0x80, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 },
-    { 0, 1, 2, 3, 4, 5, 0x80, 6, 7, 8, 9, 10, 11, 12, 13, 14 },
-    { 0, 1, 2, 3, 4, 5, 6, 0x80, 7, 8, 9, 10, 11, 12, 13, 14 },
-    { 0, 1, 2, 3, 4, 5, 6, 7, 0x80, 8, 9, 10, 11, 12, 13, 14 },
-    { 0, 1, 2, 3, 4, 5, 6, 7, 8, 0x80, 9, 10, 11, 12, 13, 14 },
-    { 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 0x80, 10, 11, 12, 13, 14 },
-    { 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 0x80, 11, 12, 13, 14 },
-    { 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 0x80, 12, 13, 14 },
-    { 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 0x80, 13, 14 },
-    { 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 0x80, 14 },
-    { 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 0x80 }
-};
-
-/**
- * Insert a line feed character in the 64-byte input at index K in [0,32).
- */
-OPENSSL_TARGET_AVX2
-static ossl_inline __m256i insert_line_feed32(__m256i input, int K)
-{
-    __m256i line_feed_vector = _mm256_set1_epi8('\n');
-    __m128i identity = _mm_setr_epi8(0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15);
-
-    if (K >= 16) {
-        __m128i maskhi = _mm_loadu_si128((__m128i *)shuffle_masks[K - 16]);
-        __m256i mask = _mm256_set_m128i(maskhi, identity);
-        __m256i lf_pos = _mm256_cmpeq_epi8(mask, _mm256_set1_epi8((char)0x80));
-        __m256i shuffled = _mm256_shuffle_epi8(input, mask);
-        __m256i result = _mm256_blendv_epi8(shuffled, line_feed_vector, lf_pos);
-
-        return result;
-    }
-    /* Shift input right by 1 byte */
-    __m256i shift = _mm256_alignr_epi8(input, _mm256_permute2x128_si256(input, input, 0x21),
-        15);
-    input = _mm256_blend_epi32(input, shift, 0xF0);
-    __m128i masklo = _mm_loadu_si128((__m128i *)shuffle_masks[K]);
-    __m256i mask = _mm256_set_m128i(identity, masklo);
-    __m256i lf_pos = _mm256_cmpeq_epi8(mask, _mm256_set1_epi8((char)0x80));
-    __m256i shuffled = _mm256_shuffle_epi8(input, mask);
-    __m256i result = _mm256_blendv_epi8(shuffled, line_feed_vector, lf_pos);
-    return result;
-}
-OPENSSL_UNTARGET_AVX2
-
-OPENSSL_TARGET_AVX2
-static ossl_inline size_t ins_nl_gt32(__m256i v, uint8_t *out, int stride,
-    int *wrap_cnt)
-{
-    const int until_nl = stride - *wrap_cnt;
-
-    if (until_nl > 32) {
-        _mm256_storeu_si256((__m256i *)out, v);
-
-        *wrap_cnt += 32;
-        return 32;
-    }
-
-    if (until_nl == 32) {
-        _mm256_storeu_si256((__m256i *)out, v);
-
-        out[32] = '\n';
-        *wrap_cnt = 0;
-        return 33;
-    }
-
-    const uint8_t last = (uint8_t)_mm256_extract_epi8(v, 31);
-    const __m256i with_lf = insert_line_feed32(v, until_nl);
-    _mm256_storeu_si256((__m256i *)out, with_lf);
-    out[32] = last;
-
-    *wrap_cnt = 32 - until_nl;
-    return 33;
-}
-OPENSSL_UNTARGET_AVX2
-
-OPENSSL_TARGET_AVX2
-static ossl_inline size_t insert_nl_gt16(const __m256i v0,
-    uint8_t *output,
-    int wrap_max, int *wrap_cnt)
-{
-    uint8_t *out = output;
-    int wrap_rem = wrap_max - *wrap_cnt;
-    _mm256_storeu_si256((__m256i *)(output), v0);
-
-    if (wrap_rem > 32) {
-        *wrap_cnt += 32;
-        return 32;
-    }
-
-    __m256i all_ff_mask = _mm256_set1_epi8((char)0xFF);
-
-    __m256i mask_second_lane = _mm256_setr_epi8(0, 0, 0, 0, 0, 0, 0, 0,
-        0, 0, 0, 0, 0, 0, 0, 0,
-        (char)0xFF, (char)0xFF, (char)0xFF, (char)0xFF,
-        (char)0xFF, (char)0xFF, (char)0xFF, (char)0xFF,
-        (char)0xFF, (char)0xFF, (char)0xFF, (char)0xFF,
-        (char)0xFF, (char)0xFF, (char)0xFF, (char)0xFF);
-
-    __m256i blended_0L = v0;
-    int surplus_0 = wrap_rem < 16 ? 1 : 0;
-    if (surplus_0 == 1) {
-        __m256i shifted_0_L = shift_left_zeros(shift_right_zeros(v0, wrap_rem),
-            wrap_rem + surplus_0);
-        __m256i mask_shifted_0_L = shift_left_zeros(all_ff_mask, wrap_rem + surplus_0);
-        __m256i mask = _mm256_or_si256(mask_shifted_0_L, mask_second_lane);
-        __m256i shifted_1_L = shift_left_zeros(v0, 1);
-        __m256i shifted = _mm256_blendv_epi8(shifted_0_L, shifted_1_L, mask);
-
-        blended_0L = _mm256_blendv_epi8(v0, shifted, mask);
-        _mm256_storeu_si256((__m256i *)(output), blended_0L);
-        wrap_rem += wrap_max;
-    }
-
-    int surplus_1 = (wrap_rem >= 16 && wrap_rem < 32) ? 1 : 0;
-    int last_of_1L = _mm256_extract_epi8(v0, 31);
-
-    if (surplus_1 == 1) {
-        uint16_t sec_last_of_1L = _mm256_extract_epi8(v0, 30);
-        int wrap_rem_1 = wrap_rem - 16;
-        __m256i shifted_1_L = shift_left_zeros(shift_right_zeros(v0, wrap_rem_1),
-            wrap_rem_1 + surplus_0 + surplus_1);
-        __m256i mask_shifted_1_L = shift_left_zeros(all_ff_mask, wrap_rem_1 + surplus_0 + surplus_1);
-        __m256i mask = _mm256_and_si256(mask_second_lane, mask_shifted_1_L);
-        __m256i blended_1L = _mm256_blendv_epi8(blended_0L, shifted_1_L, mask);
-        _mm256_storeu_si256((__m256i *)(output), blended_1L);
-
-        output[wrap_rem + surplus_0] = '\n';
-        output[31 + surplus_0] = (uint8_t)sec_last_of_1L;
-        output[31 + surplus_0 + surplus_1] = last_of_1L;
-    }
-
-    if (surplus_0 == 1) {
-        output[wrap_rem - wrap_max] = '\n';
-        output[16] = _mm256_extract_epi8(v0, 15);
-        output[31 + surplus_0 + surplus_1] = last_of_1L;
-    }
-
-    *wrap_cnt = wrap_rem > 32 ? 32 - (wrap_rem - wrap_max) : 32 - wrap_rem;
-
-    int nl_at_end = 0;
-    if (*wrap_cnt == wrap_max || *wrap_cnt == 0) {
-        *wrap_cnt = 0;
-        output[32 + surplus_0 + surplus_1] = '\n';
-        nl_at_end = 1;
-    }
-
-    out += 32 + surplus_0 + surplus_1 + nl_at_end;
-    size_t written = (size_t)(out - output);
-
-    return written;
-}
-OPENSSL_UNTARGET_AVX2
-
-OPENSSL_TARGET_AVX2
-static ossl_inline size_t insert_nl_2nd_vec_stride_12(const __m256i v0,
-    uint8_t *output,
-    int dummy_stride,
-    int *wrap_cnt)
-{
-    __m256i shuffling_mask = _mm256_setr_epi8(0, 1, 2, 3, (char)0xFF, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13,
-        (char)0xFF,
-        (char)0xFF, (char)0xFF, 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, (char)0xFF,
-        12);
-    __m256i shuffled = _mm256_shuffle_epi8(v0, shuffling_mask);
-
-    _mm256_storeu_si256((__m256i *)(output + 0), shuffled);
-
-    int16_t rem_1_L_ext = _mm256_extract_epi16(v0, 7);
-    int8_t rem_2_L_ext_P1 = _mm256_extract_epi8(v0, 29);
-    int16_t rem_2_L_ext_P2 = _mm256_extract_epi16(v0, 15);
-
-    uint8_t *out = output;
-    out[4] = '\n';
-    memcpy(out + 15, &rem_1_L_ext, sizeof(rem_1_L_ext));
-    out[16 + 1] = '\n';
-    memcpy(out + 15 + 17, &rem_2_L_ext_P1, sizeof(rem_2_L_ext_P1));
-    out[16 + 14] = '\n';
-    memcpy(out + 15 + 17 + 1, &rem_2_L_ext_P2, sizeof(rem_2_L_ext_P2));
-
-    out += 32 + 3;
-    *wrap_cnt = 4;
-
-    size_t written = (out - output);
-    return written;
-}
-OPENSSL_UNTARGET_AVX2
-
-OPENSSL_TARGET_AVX2
-static ossl_inline __m256i insert_newlines_by_mask(__m256i data, __m256i mask)
-{
-    __m256i newline = _mm256_set1_epi8('\n');
-
-    return _mm256_or_si256(_mm256_and_si256(mask, newline),
-        _mm256_andnot_si256(mask, data));
-}
-OPENSSL_UNTARGET_AVX2
-
-OPENSSL_TARGET_AVX2
-static ossl_inline size_t insert_nl_str4(const __m256i v0, uint8_t *output)
-{
-    __m256i shuffling_mask = _mm256_setr_epi8(0, 1, 2, 3, (char)0xFF, 4, 5, 6,
-        7, (char)0xFF, 8, 9, 10, 11, (char)0xFF, 12,
-        (char)0xFF, (char)0xFF, (char)0xFF, (char)0xFF, 0, 1, 2, 3,
-        (char)0xFF, 4, 5, 6, 7, (char)0xFF, 8, 9);
-    __m256i mask_5_bytes = _mm256_setr_epi8(0, 0, 0, 0, (char)0xFF, 0, 0, 0, 0, (char)0xFF,
-        0, 0, 0, 0, (char)0xFF, 0, 0, 0, 0, (char)0xFF,
-        0, 0, 0, 0, (char)0xFF, 0, 0, 0, 0, (char)0xFF,
-        0, 0);
-    __m256i shuffled_4_bytes = _mm256_shuffle_epi8(v0, shuffling_mask);
-    __m256i v0_w_nl = insert_newlines_by_mask(shuffled_4_bytes, mask_5_bytes);
-
-    _mm256_storeu_si256((__m256i *)(output + 0), v0_w_nl);
-
-    /* Handle cross-lane remainder logic */
-    /* Without macros, _mm256_srli_si256 complains that the last arg must be an 8-bit immediate */
-#define B_LANE 16 /* Bytes per lane */
-#define N_RET_1_L 3 /* bytes "shifted out" of lane 0 */
-#define N_RET_2_L (N_RET_1_L + 4) /* bytes "shifted out" of lane 1 */
-
-    /* Bytes that were shifted out of lane 0 */
-    __m256i rem_1_L = _mm256_srli_si256(v0, B_LANE - N_RET_1_L);
-
-    /* Bytes that were shifted out of lane 1 */
-    __m256i rem_2_L_P1 = _mm256_srli_si256(_mm256_slli_si256(_mm256_srli_si256(v0, B_LANE - N_RET_2_L),
-                                               B_LANE - N_RET_1_L),
-        B_LANE - 2);
-
-    /* isolate the bytes that were shifted out of lane 1 */
-    __m256i rem_2_L_P2 = _mm256_slli_si256(
-        _mm256_srli_si256(v0,
-            B_LANE - N_RET_2_L + N_RET_1_L),
-        N_RET_1_L);
-
-    __m256i rem_2_L = _mm256_or_si256(rem_2_L_P1, rem_2_L_P2);
-
-    int32_t rem_1_L_ext = _mm256_extract_epi32(rem_1_L, 0);
-    int64_t rem_2_L_ext = _mm256_extract_epi64(rem_2_L, 2);
-
-    uint8_t *out = output + 16;
-    memcpy(out, &rem_1_L_ext, sizeof(rem_1_L_ext));
-    out += 3;
-    *out++ = '\n';
-
-    out = output + 32;
-    memcpy(out, &rem_2_L_ext, sizeof(rem_2_L_ext));
-    out += 2;
-    *out++ = '\n';
-    out += 4;
-    *out++ = '\n';
-
-    size_t written = (out - output);
-    return written;
-}
-OPENSSL_UNTARGET_AVX2
-
-OPENSSL_TARGET_AVX2
-static ossl_inline size_t insert_nl_str8(const __m256i v0, uint8_t *output)
-{
-    __m256i shuffling_mask = _mm256_setr_epi8(0, 1, 2, 3, 4, 5, 6, 7, (char)0xFF,
-        8, 9, 10, 11, 12, 13, 14,
-        (char)0xFF, (char)0xFF, 0, 1, 2, 3, 4, 5, 6,
-        7, (char)0xFF, 8, 9, 10, 11, 12);
-    __m256i shuffled_4_bytes = _mm256_shuffle_epi8(v0, shuffling_mask);
-    _mm256_storeu_si256((__m256i *)(output), shuffled_4_bytes);
-    int8_t rem_1_L = _mm256_extract_epi8(v0, 15);
-    int8_t rem_2_L_P1 = _mm256_extract_epi8(v0, 29);
-    int16_t rem_2_L_P2 = _mm256_extract_epi16(v0, 15);
-    uint8_t *out = output;
-
-    memcpy(out + 16, &rem_1_L, sizeof(rem_1_L));
-    memcpy(out + 32, &rem_2_L_P1, sizeof(rem_2_L_P1));
-    memcpy(out + 32 + 1, &rem_2_L_P2, sizeof(rem_2_L_P2));
-
-    output[8] = '\n';
-    output[17] = '\n';
-    output[26] = '\n';
-    output[35] = '\n';
-
-    out += 32 + 4;
-
-    size_t written = (out - output);
-    return written;
-}
-OPENSSL_UNTARGET_AVX2
-
-OPENSSL_TARGET_AVX2
-size_t encode_base64_avx2(EVP_ENCODE_CTX *ctx, unsigned char *dst,
-    const unsigned char *src, int srclen, int ctx_length,
-    int *final_wrap_cnt)
-{
-    const uint8_t *input = (const uint8_t *)src;
-    uint8_t *out = (uint8_t *)dst;
-    int i = 0;
-    int stride = (ctx == NULL) ? 0 : ctx_length / 3 * 4;
-    int wrap_cnt = 0;
-    const int use_srp = (ctx != NULL
-        && (ctx->flags & EVP_ENCODE_CTX_USE_SRP_ALPHABET) != 0);
-    const __m256i shuf = _mm256_set_epi8(10, 11, 9, 10, 7, 8, 6, 7, 4, 5, 3, 4, 1, 2, 0, 1,
-        10, 11, 9, 10, 7, 8, 6, 7, 4, 5, 3, 4, 1, 2, 0, 1);
-    int base = 0;
-
-    /* Process 96 bytes at a time */
-    for (; i + 100 <= srclen; i += 96) {
-        _mm_prefetch((const char *)(input + i + 192), _MM_HINT_T0);
-        /*
-         * Interleaved for each vector: load, shuffle, bit-split, lookup
-         * before starting the next, giving the OoO engine independent work chains
-         * across execution ports.
-         */
-        const __m128i lo0 = _mm_loadu_si128((const __m128i *)(input + i + 4 * 3 * 0));
-        const __m128i hi0 = _mm_loadu_si128((const __m128i *)(input + i + 4 * 3 * 1));
-        __m256i in0 = _mm256_shuffle_epi8(_mm256_set_m128i(hi0, lo0), shuf);
-        const __m256i t0_0 = _mm256_and_si256(in0, _mm256_set1_epi32(0x0fc0fc00));
-        const __m256i t1_0 = _mm256_mulhi_epu16(t0_0, _mm256_set1_epi32(0x04000040));
-        const __m256i t2_0 = _mm256_and_si256(in0, _mm256_set1_epi32(0x003f03f0));
-        const __m256i t3_0 = _mm256_mullo_epi16(t2_0, _mm256_set1_epi32(0x01000010));
-        const __m256i input0 = _mm256_or_si256(t1_0, t3_0);
-
-        const __m128i lo1 = _mm_loadu_si128((const __m128i *)(input + i + 4 * 3 * 2));
-        const __m128i hi1 = _mm_loadu_si128((const __m128i *)(input + i + 4 * 3 * 3));
-        __m256i in1 = _mm256_shuffle_epi8(_mm256_set_m128i(hi1, lo1), shuf);
-        const __m256i t0_1 = _mm256_and_si256(in1, _mm256_set1_epi32(0x0fc0fc00));
-        const __m256i t1_1 = _mm256_mulhi_epu16(t0_1, _mm256_set1_epi32(0x04000040));
-        const __m256i t2_1 = _mm256_and_si256(in1, _mm256_set1_epi32(0x003f03f0));
-        const __m256i t3_1 = _mm256_mullo_epi16(t2_1, _mm256_set1_epi32(0x01000010));
-        const __m256i input1 = _mm256_or_si256(t1_1, t3_1);
-
-        const __m128i lo2 = _mm_loadu_si128((const __m128i *)(input + i + 4 * 3 * 4));
-        const __m128i hi2 = _mm_loadu_si128((const __m128i *)(input + i + 4 * 3 * 5));
-        __m256i in2 = _mm256_shuffle_epi8(_mm256_set_m128i(hi2, lo2), shuf);
-        const __m256i t0_2 = _mm256_and_si256(in2, _mm256_set1_epi32(0x0fc0fc00));
-        const __m256i t1_2 = _mm256_mulhi_epu16(t0_2, _mm256_set1_epi32(0x04000040));
-        const __m256i t2_2 = _mm256_and_si256(in2, _mm256_set1_epi32(0x003f03f0));
-        const __m256i t3_2 = _mm256_mullo_epi16(t2_2, _mm256_set1_epi32(0x01000010));
-        const __m256i input2 = _mm256_or_si256(t1_2, t3_2);
-
-        const __m128i lo3 = _mm_loadu_si128((const __m128i *)(input + i + 4 * 3 * 6));
-        const __m128i hi3 = _mm_loadu_si128((const __m128i *)(input + i + 4 * 3 * 7));
-        __m256i in3 = _mm256_shuffle_epi8(_mm256_set_m128i(hi3, lo3), shuf);
-        const __m256i t0_3 = _mm256_and_si256(in3, _mm256_set1_epi32(0x0fc0fc00));
-        const __m256i t1_3 = _mm256_mulhi_epu16(t0_3, _mm256_set1_epi32(0x04000040));
-        const __m256i t2_3 = _mm256_and_si256(in3, _mm256_set1_epi32(0x003f03f0));
-        const __m256i t3_3 = _mm256_mullo_epi16(t2_3, _mm256_set1_epi32(0x01000010));
-        const __m256i input3 = _mm256_or_si256(t1_3, t3_3);
-
-        __m256i vec0;
-        __m256i vec1;
-        __m256i vec2;
-        __m256i vec3;
-
-        if (use_srp) {
-            vec0 = lookup_pshufb_srp(input0);
-            vec1 = lookup_pshufb_srp(input1);
-            vec2 = lookup_pshufb_srp(input2);
-            vec3 = lookup_pshufb_srp(input3);
-
-        } else {
-            vec0 = lookup_pshufb_std(input0);
-            vec1 = lookup_pshufb_std(input1);
-            vec2 = lookup_pshufb_std(input2);
-            vec3 = lookup_pshufb_std(input3);
-        }
-
-        if (stride == 0) {
-            _mm256_storeu_si256((__m256i *)out, vec0);
-
-            out += 32;
-            _mm256_storeu_si256((__m256i *)out, vec1);
-
-            out += 32;
-            _mm256_storeu_si256((__m256i *)out, vec2);
-
-            out += 32;
-            _mm256_storeu_si256((__m256i *)out, vec3);
-
-            out += 32;
-        } else if (stride == 64) {
-            _mm256_storeu_si256((__m256i *)out, vec0);
-
-            out += 32;
-            _mm256_storeu_si256((__m256i *)out, vec1);
-
-            out += 32;
-            *(out++) = '\n';
-
-            _mm256_storeu_si256((__m256i *)out, vec2);
-            out += 32;
-
-            _mm256_storeu_si256((__m256i *)out, vec3);
-            out += 32;
-
-            *(out++) = '\n';
-        } else if (stride == 4) {
-            int out_idx = 0;
-
-            out_idx += (int)insert_nl_str4(vec0, out + out_idx);
-            out_idx += (int)insert_nl_str4(vec1, out + out_idx);
-            out_idx += (int)insert_nl_str4(vec2, out + out_idx);
-            out_idx += (int)insert_nl_str4(vec3, out + out_idx);
-
-            out += out_idx;
-        } else if (stride == 8) {
-
-            out += insert_nl_str8(vec0, out);
-            out += insert_nl_str8(vec1, out);
-            out += insert_nl_str8(vec2, out);
-            out += insert_nl_str8(vec3, out);
-
-        } else if (stride == 12) {
-            switch (base) {
-            case 0:
-
-                out += insert_nl_gt16(vec0, out, stride, &wrap_cnt);
-                out += insert_nl_2nd_vec_stride_12(vec1, out, stride, &wrap_cnt);
-                out += insert_nl_gt16(vec2, out, stride, &wrap_cnt);
-                out += insert_nl_gt16(vec3, out, stride, &wrap_cnt);
-                break;
-            case 1:
-                out += insert_nl_2nd_vec_stride_12(vec0, out, stride, &wrap_cnt);
-                out += insert_nl_gt16(vec1, out, stride, &wrap_cnt);
-                out += insert_nl_gt16(vec2, out, stride, &wrap_cnt);
-                out += insert_nl_2nd_vec_stride_12(vec3, out, stride, &wrap_cnt);
-                break;
-            default: /* base == 2 */
-                out += insert_nl_gt16(vec0, out, stride, &wrap_cnt);
-                out += insert_nl_gt16(vec1, out, stride, &wrap_cnt);
-                out += insert_nl_2nd_vec_stride_12(vec2, out, stride, &wrap_cnt);
-                out += insert_nl_gt16(vec3, out, stride, &wrap_cnt);
-                break;
-            }
-
-            if (++base == 3)
-                base = 0;
-        } else if (stride >= 32) {
-            out += ins_nl_gt32(vec0, out, stride, &wrap_cnt);
-            out += ins_nl_gt32(vec1, out, stride, &wrap_cnt);
-            out += ins_nl_gt32(vec2, out, stride, &wrap_cnt);
-            out += ins_nl_gt32(vec3, out, stride, &wrap_cnt);
-        } else if (stride >= 16) {
-            out += insert_nl_gt16(vec0, out, stride, &wrap_cnt);
-            out += insert_nl_gt16(vec1, out, stride, &wrap_cnt);
-            out += insert_nl_gt16(vec2, out, stride, &wrap_cnt);
-            out += insert_nl_gt16(vec3, out, stride, &wrap_cnt);
-        }
-    }
-
-    if (stride == 0) {
-        for (; i + 28 <= srclen; i += 24) {
-            /* lo = [xxxx|DDDC|CCBB|BAAA] */
-            /* hi = [xxxx|HHHG|GGFF|FEEE] */
-            const __m128i lo = _mm_loadu_si128((const __m128i *)(input + i));
-            const __m128i hi = _mm_loadu_si128((const __m128i *)(input + i + 4 * 3));
-            /*
-             * bytes from groups A, B and C are needed in separate 32-bit lanes
-             * in = [0HHH|0GGG|0FFF|0EEE[0DDD|0CCC|0BBB|0AAA]
-             */
-            __m256i in = _mm256_shuffle_epi8(_mm256_set_m128i(hi, lo), shuf);
-            const __m256i t0 = _mm256_and_si256(in, _mm256_set1_epi32(0x0fc0fc00));
-            const __m256i t1 = _mm256_mulhi_epu16(t0, _mm256_set1_epi32(0x04000040));
-            const __m256i t2 = _mm256_and_si256(in, _mm256_set1_epi32(0x003f03f0));
-            const __m256i t3 = _mm256_mullo_epi16(t2, _mm256_set1_epi32(0x01000010));
-            const __m256i indices = _mm256_or_si256(t1, t3);
-            _mm256_storeu_si256((__m256i *)out, (use_srp ? lookup_pshufb_srp : lookup_pshufb_std)(indices));
-
-            out += 32;
-        }
-    }
-    *final_wrap_cnt = wrap_cnt;
-
-    if (stride >= 32 && wrap_cnt == stride) {
-        wrap_cnt = 0;
-        *out++ = '\n';
-    }
-
-    return (size_t)(out - (uint8_t *)dst) + evp_encodeblock_int(ctx, out, src + i, srclen - i, final_wrap_cnt);
-}
-OPENSSL_UNTARGET_AVX2
-#endif /* defined(HAVE_AVX2_INTRINSICS) */
-#endif /* !defined(_M_ARM64EC) */
-#endif
diff --git a/crypto/evp/enc_b64_avx2.h b/crypto/evp/enc_b64_avx2.h
deleted file mode 100644
index 71b0a004e7..0000000000
--- a/crypto/evp/enc_b64_avx2.h
+++ /dev/null
@@ -1,25 +0,0 @@
-#ifndef OSSL_CRYPTO_EVP_B64_AVX2_H
-#define OSSL_CRYPTO_EVP_B64_AVX2_H
-
-#include 
-#include 
-
-#if defined(__clang__)
-#define HAVE_AVX2_INTRINSICS 1
-#elif defined(__GNUC__) && (__GNUC__ >= 8)
-#define HAVE_AVX2_INTRINSICS 1
-#elif defined(_MSC_VER) && (_MSC_VER >= 1920) /* MSVC 2019 */
-#define HAVE_AVX2_INTRINSICS 1
-#endif
-
-#if defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)
-#if !defined(_M_ARM64EC)
-#if defined(HAVE_AVX2_INTRINSICS)
-size_t encode_base64_avx2(EVP_ENCODE_CTX *ctx,
-    unsigned char *out, const unsigned char *src, int srclen,
-    int newlines, int *wrap_cnt);
-#endif /* defined(HAVE_AVX2_INTRINSICS) */
-#endif /* !defined(_M_ARM64EC) */
-#endif
-
-#endif
diff --git a/crypto/evp/enc_b64_scalar.c b/crypto/evp/enc_b64_scalar.c
deleted file mode 100644
index 4bdadcea0c..0000000000
--- a/crypto/evp/enc_b64_scalar.c
+++ /dev/null
@@ -1,286 +0,0 @@
-#include 
-#include "internal/cryptlib.h"
-#include "crypto/evp.h"
-#include "evp_local.h"
-#include "enc_b64_scalar.h"
-
-static const unsigned char base64_srp_bin2ascii_0[256] = {
-    '0', '0', '0', '0', '1', '1', '1', '1', '2', '2', '2', '2', '3', '3', '3', '3',
-    '4', '4', '4', '4', '5', '5', '5', '5', '6', '6', '6', '6', '7', '7', '7', '7',
-    '8', '8', '8', '8', '9', '9', '9', '9', 'A', 'A', 'A', 'A', 'B', 'B', 'B', 'B',
-    'C', 'C', 'C', 'C', 'D', 'D', 'D', 'D', 'E', 'E', 'E', 'E', 'F', 'F', 'F', 'F',
-    'G', 'G', 'G', 'G', 'H', 'H', 'H', 'H', 'I', 'I', 'I', 'I', 'J', 'J', 'J', 'J',
-    'K', 'K', 'K', 'K', 'L', 'L', 'L', 'L', 'M', 'M', 'M', 'M', 'N', 'N', 'N', 'N',
-    'O', 'O', 'O', 'O', 'P', 'P', 'P', 'P', 'Q', 'Q', 'Q', 'Q', 'R', 'R', 'R', 'R',
-    'S', 'S', 'S', 'S', 'T', 'T', 'T', 'T', 'U', 'U', 'U', 'U', 'V', 'V', 'V', 'V',
-    'W', 'W', 'W', 'W', 'X', 'X', 'X', 'X', 'Y', 'Y', 'Y', 'Y', 'Z', 'Z', 'Z', 'Z',
-    'a', 'a', 'a', 'a', 'b', 'b', 'b', 'b', 'c', 'c', 'c', 'c', 'd', 'd', 'd', 'd',
-    'e', 'e', 'e', 'e', 'f', 'f', 'f', 'f', 'g', 'g', 'g', 'g', 'h', 'h', 'h', 'h',
-    'i', 'i', 'i', 'i', 'j', 'j', 'j', 'j', 'k', 'k', 'k', 'k', 'l', 'l', 'l', 'l',
-    'm', 'm', 'm', 'm', 'n', 'n', 'n', 'n', 'o', 'o', 'o', 'o', 'p', 'p', 'p', 'p',
-    'q', 'q', 'q', 'q', 'r', 'r', 'r', 'r', 's', 's', 's', 's', 't', 't', 't', 't',
-    'u', 'u', 'u', 'u', 'v', 'v', 'v', 'v', 'w', 'w', 'w', 'w', 'x', 'x', 'x', 'x',
-    'y', 'y', 'y', 'y', 'z', 'z', 'z', 'z', '.', '.', '.', '.', '/', '/', '/', '/'
-};
-
-static const unsigned char base64_srp_bin2ascii_1[256] = {
-    '0', '1', '2', '3', '4', '5', '6', '7', '8', '9', 'A', 'B', 'C', 'D', 'E', 'F',
-    'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V',
-    'W', 'X', 'Y', 'Z', 'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'k', 'l',
-    'm', 'n', 'o', 'p', 'q', 'r', 's', 't', 'u', 'v', 'w', 'x', 'y', 'z', '.', '/',
-    '0', '1', '2', '3', '4', '5', '6', '7', '8', '9', 'A', 'B', 'C', 'D', 'E', 'F',
-    'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V',
-    'W', 'X', 'Y', 'Z', 'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'k', 'l',
-    'm', 'n', 'o', 'p', 'q', 'r', 's', 't', 'u', 'v', 'w', 'x', 'y', 'z', '.', '/',
-    '0', '1', '2', '3', '4', '5', '6', '7', '8', '9', 'A', 'B', 'C', 'D', 'E', 'F',
-    'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V',
-    'W', 'X', 'Y', 'Z', 'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'k', 'l',
-    'm', 'n', 'o', 'p', 'q', 'r', 's', 't', 'u', 'v', 'w', 'x', 'y', 'z', '.', '/',
-    '0', '1', '2', '3', '4', '5', '6', '7', '8', '9', 'A', 'B', 'C', 'D', 'E', 'F',
-    'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V',
-    'W', 'X', 'Y', 'Z', 'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'k', 'l',
-    'm', 'n', 'o', 'p', 'q', 'r', 's', 't', 'u', 'v', 'w', 'x', 'y', 'z', '.', '/'
-};
-
-static const unsigned char base64_srp_bin2ascii_2[256] = {
-    '0', '1', '2', '3', '4', '5', '6', '7', '8', '9', 'A', 'B', 'C', 'D', 'E', 'F',
-    'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V',
-    'W', 'X', 'Y', 'Z', 'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'k', 'l',
-    'm', 'n', 'o', 'p', 'q', 'r', 's', 't', 'u', 'v', 'w', 'x', 'y', 'z', '.', '/',
-    '0', '1', '2', '3', '4', '5', '6', '7', '8', '9', 'A', 'B', 'C', 'D', 'E', 'F',
-    'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V',
-    'W', 'X', 'Y', 'Z', 'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'k', 'l',
-    'm', 'n', 'o', 'p', 'q', 'r', 's', 't', 'u', 'v', 'w', 'x', 'y', 'z', '.', '/',
-    '0', '1', '2', '3', '4', '5', '6', '7', '8', '9', 'A', 'B', 'C', 'D', 'E', 'F',
-    'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V',
-    'W', 'X', 'Y', 'Z', 'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'k', 'l',
-    'm', 'n', 'o', 'p', 'q', 'r', 's', 't', 'u', 'v', 'w', 'x', 'y', 'z', '.', '/',
-    '0', '1', '2', '3', '4', '5', '6', '7', '8', '9', 'A', 'B', 'C', 'D', 'E', 'F',
-    'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V',
-    'W', 'X', 'Y', 'Z', 'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'k', 'l',
-    'm', 'n', 'o', 'p', 'q', 'r', 's', 't', 'u', 'v', 'w', 'x', 'y', 'z', '.', '/'
-};
-
-static const unsigned char base64_std_bin2ascii_0[256] = {
-    'A', 'A', 'A', 'A', 'B', 'B', 'B', 'B', 'C', 'C', 'C', 'C', 'D', 'D', 'D',
-    'D', 'E', 'E', 'E', 'E', 'F', 'F', 'F', 'F', 'G', 'G', 'G', 'G', 'H', 'H',
-    'H', 'H', 'I', 'I', 'I', 'I', 'J', 'J', 'J', 'J', 'K', 'K', 'K', 'K', 'L',
-    'L', 'L', 'L', 'M', 'M', 'M', 'M', 'N', 'N', 'N', 'N', 'O', 'O', 'O', 'O',
-    'P', 'P', 'P', 'P', 'Q', 'Q', 'Q', 'Q', 'R', 'R', 'R', 'R', 'S', 'S', 'S',
-    'S', 'T', 'T', 'T', 'T', 'U', 'U', 'U', 'U', 'V', 'V', 'V', 'V', 'W', 'W',
-    'W', 'W', 'X', 'X', 'X', 'X', 'Y', 'Y', 'Y', 'Y', 'Z', 'Z', 'Z', 'Z', 'a',
-    'a', 'a', 'a', 'b', 'b', 'b', 'b', 'c', 'c', 'c', 'c', 'd', 'd', 'd', 'd',
-    'e', 'e', 'e', 'e', 'f', 'f', 'f', 'f', 'g', 'g', 'g', 'g', 'h', 'h', 'h',
-    'h', 'i', 'i', 'i', 'i', 'j', 'j', 'j', 'j', 'k', 'k', 'k', 'k', 'l', 'l',
-    'l', 'l', 'm', 'm', 'm', 'm', 'n', 'n', 'n', 'n', 'o', 'o', 'o', 'o', 'p',
-    'p', 'p', 'p', 'q', 'q', 'q', 'q', 'r', 'r', 'r', 'r', 's', 's', 's', 's',
-    't', 't', 't', 't', 'u', 'u', 'u', 'u', 'v', 'v', 'v', 'v', 'w', 'w', 'w',
-    'w', 'x', 'x', 'x', 'x', 'y', 'y', 'y', 'y', 'z', 'z', 'z', 'z', '0', '0',
-    '0', '0', '1', '1', '1', '1', '2', '2', '2', '2', '3', '3', '3', '3', '4',
-    '4', '4', '4', '5', '5', '5', '5', '6', '6', '6', '6', '7', '7', '7', '7',
-    '8', '8', '8', '8', '9', '9', '9', '9', '+', '+', '+', '+', '/', '/', '/',
-    '/'
-};
-
-static const unsigned char base64_std_bin2ascii_1[256] = {
-    'A', 'B', 'C', 'D', 'E', 'F', 'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O',
-    'P', 'Q', 'R', 'S', 'T', 'U', 'V', 'W', 'X', 'Y', 'Z', 'a', 'b', 'c', 'd',
-    'e', 'f', 'g', 'h', 'i', 'j', 'k', 'l', 'm', 'n', 'o', 'p', 'q', 'r', 's',
-    't', 'u', 'v', 'w', 'x', 'y', 'z', '0', '1', '2', '3', '4', '5', '6', '7',
-    '8', '9', '+', '/', 'A', 'B', 'C', 'D', 'E', 'F', 'G', 'H', 'I', 'J', 'K',
-    'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V', 'W', 'X', 'Y', 'Z',
-    'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'k', 'l', 'm', 'n', 'o',
-    'p', 'q', 'r', 's', 't', 'u', 'v', 'w', 'x', 'y', 'z', '0', '1', '2', '3',
-    '4', '5', '6', '7', '8', '9', '+', '/', 'A', 'B', 'C', 'D', 'E', 'F', 'G',
-    'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V',
-    'W', 'X', 'Y', 'Z', 'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'k',
-    'l', 'm', 'n', 'o', 'p', 'q', 'r', 's', 't', 'u', 'v', 'w', 'x', 'y', 'z',
-    '0', '1', '2', '3', '4', '5', '6', '7', '8', '9', '+', '/', 'A', 'B', 'C',
-    'D', 'E', 'F', 'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R',
-    'S', 'T', 'U', 'V', 'W', 'X', 'Y', 'Z', 'a', 'b', 'c', 'd', 'e', 'f', 'g',
-    'h', 'i', 'j', 'k', 'l', 'm', 'n', 'o', 'p', 'q', 'r', 's', 't', 'u', 'v',
-    'w', 'x', 'y', 'z', '0', '1', '2', '3', '4', '5', '6', '7', '8', '9', '+',
-    '/'
-};
-
-static const unsigned char base64_std_bin2ascii_2[256] = {
-    'A', 'B', 'C', 'D', 'E', 'F', 'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O',
-    'P', 'Q', 'R', 'S', 'T', 'U', 'V', 'W', 'X', 'Y', 'Z', 'a', 'b', 'c', 'd',
-    'e', 'f', 'g', 'h', 'i', 'j', 'k', 'l', 'm', 'n', 'o', 'p', 'q', 'r', 's',
-    't', 'u', 'v', 'w', 'x', 'y', 'z', '0', '1', '2', '3', '4', '5', '6', '7',
-    '8', '9', '+', '/', 'A', 'B', 'C', 'D', 'E', 'F', 'G', 'H', 'I', 'J', 'K',
-    'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V', 'W', 'X', 'Y', 'Z',
-    'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'k', 'l', 'm', 'n', 'o',
-    'p', 'q', 'r', 's', 't', 'u', 'v', 'w', 'x', 'y', 'z', '0', '1', '2', '3',
-    '4', '5', '6', '7', '8', '9', '+', '/', 'A', 'B', 'C', 'D', 'E', 'F', 'G',
-    'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R', 'S', 'T', 'U', 'V',
-    'W', 'X', 'Y', 'Z', 'a', 'b', 'c', 'd', 'e', 'f', 'g', 'h', 'i', 'j', 'k',
-    'l', 'm', 'n', 'o', 'p', 'q', 'r', 's', 't', 'u', 'v', 'w', 'x', 'y', 'z',
-    '0', '1', '2', '3', '4', '5', '6', '7', '8', '9', '+', '/', 'A', 'B', 'C',
-    'D', 'E', 'F', 'G', 'H', 'I', 'J', 'K', 'L', 'M', 'N', 'O', 'P', 'Q', 'R',
-    'S', 'T', 'U', 'V', 'W', 'X', 'Y', 'Z', 'a', 'b', 'c', 'd', 'e', 'f', 'g',
-    'h', 'i', 'j', 'k', 'l', 'm', 'n', 'o', 'p', 'q', 'r', 's', 't', 'u', 'v',
-    'w', 'x', 'y', 'z', '0', '1', '2', '3', '4', '5', '6', '7', '8', '9', '+',
-    '/'
-};
-
-size_t evp_encodeblock_int(EVP_ENCODE_CTX *ctx, unsigned char *t,
-    const unsigned char *f, int dlen, int *wrap_cnt)
-{
-    int i = 0;
-    size_t ret = 0;
-    uint8_t t1, t2, t3;
-    const unsigned char *e0, *e1, *e2;
-    int srp = (ctx != NULL
-        && (ctx->flags & EVP_ENCODE_CTX_USE_SRP_ALPHABET) != 0);
-    int wrap_cnt_by_input = *wrap_cnt / 4 * 3;
-    const int ctx_length = (ctx != NULL) ? EVP_ENCODE_B64_LENGTH : 0;
-
-    if (srp) {
-        e0 = base64_srp_bin2ascii_0;
-        e1 = base64_srp_bin2ascii_1;
-        e2 = base64_srp_bin2ascii_2;
-    } else {
-        e0 = base64_std_bin2ascii_0;
-        e1 = base64_std_bin2ascii_1;
-        e2 = base64_std_bin2ascii_2;
-    }
-
-    if (ctx_length == 1) {
-        while (i < dlen && ctx != NULL) {
-            t1 = f[i];
-            *(t++) = e0[t1];
-            *(t++) = e1[(t1 & 0x03) << 4];
-            *(t++) = '=';
-            *(t++) = '=';
-            *(t++) = '\n';
-
-            ret += 5;
-            i++;
-        }
-
-        *t = '\0';
-        ret--;
-
-        return ret;
-    } else if (ctx_length % 3 != 0) {
-        i = 0;
-        int wrap_cnt_nm3 = 0;
-        while (i + 2 < dlen) {
-            if (ctx != NULL) {
-                if ((wrap_cnt_nm3 < EVP_ENCODE_B64_LENGTH
-                        && (wrap_cnt_nm3 + 3 + wrap_cnt_by_input) > EVP_ENCODE_B64_LENGTH)
-                    && ((ctx->flags & EVP_ENCODE_CTX_NO_NEWLINES) == 0)) {
-
-                    switch (EVP_ENCODE_B64_LENGTH % 3) {
-                    case 0:
-                        break;
-                    case 1:
-                        t1 = f[i];
-                        *(t++) = e0[t1];
-                        *(t++) = e1[(t1 & 0x03) << 4];
-                        *(t++) = '=';
-                        *(t++) = '=';
-
-                        ret += 4;
-                        i++;
-                        break;
-                    case 2:
-                        t1 = f[i];
-                        t2 = f[i + 1];
-                        *(t++) = e0[t1];
-                        *(t++) = e1[((t1 & 0x03) << 4) | ((t2 >> 4) & 0x0F)];
-                        *(t++) = e2[(t2 & 0x0F) << 2];
-                        *(t++) = '=';
-                        i += 2;
-                        ret += 4;
-                        break;
-                    }
-                    *(t++) = '\n';
-                    ret++;
-                    wrap_cnt_nm3 = 0;
-                }
-            }
-
-            if (ctx_length >= 4 && i + 2 < dlen) {
-                t1 = f[i];
-                t2 = f[i + 1];
-                t3 = f[i + 2];
-                *(t++) = e0[t1];
-                *(t++) = e1[((t1 & 0x03) << 4) | ((t2 >> 4) & 0x0F)];
-                *(t++) = e1[((t2 & 0x0F) << 2) | ((t3 >> 6) & 0x03)];
-                *(t++) = e2[t3];
-                ret += 4;
-                wrap_cnt_nm3 += 3;
-                i += 3;
-            }
-        }
-    } else {
-        for (i = 0; i + 2 < dlen; i += 3) {
-
-            t1 = f[i];
-            t2 = f[i + 1];
-            t3 = f[i + 2];
-            *(t++) = e0[t1];
-            *(t++) = e1[((t1 & 0x03) << 4) | ((t2 >> 4) & 0x0F)];
-            *(t++) = e1[((t2 & 0x0F) << 2) | ((t3 >> 6) & 0x03)];
-            *(t++) = e2[t3];
-            ret += 4;
-
-            if (ctx != NULL) {
-                if ((i + 3 + wrap_cnt_by_input) % EVP_ENCODE_B64_LENGTH == 0
-                    && ((ctx->flags & EVP_ENCODE_CTX_NO_NEWLINES) == 0)
-                    && EVP_ENCODE_B64_LENGTH % 3 == 0) {
-                    *(t++) = '\n';
-                    ret++;
-                }
-            }
-        }
-    }
-
-    switch (dlen - i) {
-    case 0:
-        break;
-    case 1:
-        t1 = f[i];
-        *(t++) = e0[t1];
-        *(t++) = e1[(t1 & 0x03) << 4];
-        *(t++) = '=';
-        *(t++) = '=';
-
-        ret += 4;
-
-        if (ctx != NULL) {
-            if ((i + 1 + wrap_cnt_by_input) % EVP_ENCODE_B64_LENGTH == 0
-                && ((ctx->flags & EVP_ENCODE_CTX_NO_NEWLINES) == 0)
-                && EVP_ENCODE_B64_LENGTH % 3 == 0) {
-                *(t++) = '\n';
-                ret++;
-            }
-        }
-
-        break;
-    case 2:
-        t1 = f[i];
-        t2 = f[i + 1];
-        *(t++) = e0[t1];
-        *(t++) = e1[((t1 & 0x03) << 4) | ((t2 >> 4) & 0x0F)];
-        *(t++) = e2[(t2 & 0x0F) << 2];
-        *(t++) = '=';
-        ret += 4;
-
-        if (ctx != NULL) {
-            if ((i + 2 + wrap_cnt_by_input) % EVP_ENCODE_B64_LENGTH == 0
-                && ((ctx->flags & EVP_ENCODE_CTX_NO_NEWLINES) == 0)
-                && EVP_ENCODE_B64_LENGTH % 3 == 0) {
-                *(t++) = '\n';
-                ret++;
-            }
-        }
-        break;
-    }
-
-    *t = '\0';
-
-    return ret;
-}
diff --git a/crypto/evp/enc_b64_scalar.h b/crypto/evp/enc_b64_scalar.h
deleted file mode 100644
index 43059938cc..0000000000
--- a/crypto/evp/enc_b64_scalar.h
+++ /dev/null
@@ -1,9 +0,0 @@
-#ifndef OSSL_CRYPTO_EVP_B64_SCALAR_H
-#define OSSL_CRYPTO_EVP_B64_SCALAR_H
-#include 
-#include 
-
-size_t evp_encodeblock_int(EVP_ENCODE_CTX *ctx, unsigned char *t,
-    const unsigned char *f, int dlen, int *wrap_cnt);
-
-#endif
diff --git a/crypto/evp/encode.c b/crypto/evp/encode.c
index dd66c7d2d6..53575e7b60 100644
--- a/crypto/evp/encode.c
+++ b/crypto/evp/encode.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -9,27 +9,30 @@
 
 #include 
 #include 
-#include 
 #include "internal/cryptlib.h"
 #include 
 #include "crypto/evp.h"
 #include "evp_local.h"
 
-#if defined(OPENSSL_CPUID_OBJ) && !defined(OPENSSL_NO_ASM) && (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64))
-#if !defined(_M_ARM64EC)
-#define HAS_IA32CAP_IS_64
-#endif /* !defined(_M_ARM64EC) */
-#endif
-
-#include "enc_b64_avx2.h"
-#include "enc_b64_scalar.h"
-
 static unsigned char conv_ascii2bin(unsigned char a,
     const unsigned char *table);
-size_t evp_encodeblock_int(EVP_ENCODE_CTX *ctx, unsigned char *t,
-    const unsigned char *f, int dlen, int *wrap_cnt);
+static int evp_encodeblock_int(EVP_ENCODE_CTX *ctx, unsigned char *t,
+    const unsigned char *f, int dlen);
 static int evp_decodeblock_int(EVP_ENCODE_CTX *ctx, unsigned char *t,
     const unsigned char *f, int n, int eof);
+
+#ifndef CHARSET_EBCDIC
+#define conv_bin2ascii(a, table) ((table)[(a) & 0x3f])
+#else
+/*
+ * We assume that PEM encoded files are EBCDIC files (i.e., printable text
+ * files). Convert them here while decoding. When encoding, output is EBCDIC
+ * (text) format again. (No need for conversion in the conv_bin2ascii macro,
+ * as the underlying textstring data_bin2ascii[] is already EBCDIC)
+ */
+#define conv_bin2ascii(a, table) ((table)[(a) & 0x3f])
+#endif
+
 /*-
  * 64 char lines
  * pad input with 0
@@ -42,6 +45,11 @@ static int evp_decodeblock_int(EVP_ENCODE_CTX *ctx, unsigned char *t,
 #define CHUNKS_PER_LINE (64 / 4)
 #define CHAR_PER_LINE (64 + 1)
 
+static const unsigned char data_bin2ascii[65] = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/";
+
+/* SRP uses a different base64 alphabet */
+static const unsigned char srpdata_bin2ascii[65] = "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz./";
+
 /*-
  * 0xF0 is a EOLN
  * 0xF1 is ignore but next needs to be 0xF0 (for \r\n processing).
@@ -59,35 +67,265 @@ static int evp_decodeblock_int(EVP_ENCODE_CTX *ctx, unsigned char *t,
 #define B64_BASE64(a) (!B64_NOT_BASE64(a))
 
 static const unsigned char data_ascii2bin[128] = {
-    0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xE0,
-    0xF0, 0xFF, 0xFF, 0xF1, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
-    0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
-    0xFF, 0xFF, 0xE0, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
-    0xFF, 0xFF, 0xFF, 0x3E, 0xFF, 0xF2, 0xFF, 0x3F, 0x34, 0x35,
-    0x36, 0x37, 0x38, 0x39, 0x3A, 0x3B, 0x3C, 0x3D, 0xFF, 0xFF,
-    0xFF, 0x00, 0xFF, 0xFF, 0xFF, 0x00, 0x01, 0x02, 0x03, 0x04,
-    0x05, 0x06, 0x07, 0x08, 0x09, 0x0A, 0x0B, 0x0C, 0x0D, 0x0E,
-    0x0F, 0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17, 0x18,
-    0x19, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0x1A, 0x1B, 0x1C,
-    0x1D, 0x1E, 0x1F, 0x20, 0x21, 0x22, 0x23, 0x24, 0x25, 0x26,
-    0x27, 0x28, 0x29, 0x2A, 0x2B, 0x2C, 0x2D, 0x2E, 0x2F, 0x30,
-    0x31, 0x32, 0x33, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xE0,
+    0xF0,
+    0xFF,
+    0xFF,
+    0xF1,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xE0,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0x3E,
+    0xFF,
+    0xF2,
+    0xFF,
+    0x3F,
+    0x34,
+    0x35,
+    0x36,
+    0x37,
+    0x38,
+    0x39,
+    0x3A,
+    0x3B,
+    0x3C,
+    0x3D,
+    0xFF,
+    0xFF,
+    0xFF,
+    0x00,
+    0xFF,
+    0xFF,
+    0xFF,
+    0x00,
+    0x01,
+    0x02,
+    0x03,
+    0x04,
+    0x05,
+    0x06,
+    0x07,
+    0x08,
+    0x09,
+    0x0A,
+    0x0B,
+    0x0C,
+    0x0D,
+    0x0E,
+    0x0F,
+    0x10,
+    0x11,
+    0x12,
+    0x13,
+    0x14,
+    0x15,
+    0x16,
+    0x17,
+    0x18,
+    0x19,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0x1A,
+    0x1B,
+    0x1C,
+    0x1D,
+    0x1E,
+    0x1F,
+    0x20,
+    0x21,
+    0x22,
+    0x23,
+    0x24,
+    0x25,
+    0x26,
+    0x27,
+    0x28,
+    0x29,
+    0x2A,
+    0x2B,
+    0x2C,
+    0x2D,
+    0x2E,
+    0x2F,
+    0x30,
+    0x31,
+    0x32,
+    0x33,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
 };
 
 static const unsigned char srpdata_ascii2bin[128] = {
-    0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xE0,
-    0xF0, 0xFF, 0xFF, 0xF1, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
-    0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
-    0xFF, 0xFF, 0xE0, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF,
-    0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xF2, 0x3E, 0x3F, 0x00, 0x01,
-    0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0xFF, 0xFF,
-    0xFF, 0x00, 0xFF, 0xFF, 0xFF, 0x0A, 0x0B, 0x0C, 0x0D, 0x0E,
-    0x0F, 0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17, 0x18,
-    0x19, 0x1A, 0x1B, 0x1C, 0x1D, 0x1E, 0x1F, 0x20, 0x21, 0x22,
-    0x23, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF, 0x24, 0x25, 0x26,
-    0x27, 0x28, 0x29, 0x2A, 0x2B, 0x2C, 0x2D, 0x2E, 0x2F, 0x30,
-    0x31, 0x32, 0x33, 0x34, 0x35, 0x36, 0x37, 0x38, 0x39, 0x3A,
-    0x3B, 0x3C, 0x3D, 0xFF, 0xFF, 0xFF, 0xFF, 0xFF
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xE0,
+    0xF0,
+    0xFF,
+    0xFF,
+    0xF1,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xE0,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xF2,
+    0x3E,
+    0x3F,
+    0x00,
+    0x01,
+    0x02,
+    0x03,
+    0x04,
+    0x05,
+    0x06,
+    0x07,
+    0x08,
+    0x09,
+    0xFF,
+    0xFF,
+    0xFF,
+    0x00,
+    0xFF,
+    0xFF,
+    0xFF,
+    0x0A,
+    0x0B,
+    0x0C,
+    0x0D,
+    0x0E,
+    0x0F,
+    0x10,
+    0x11,
+    0x12,
+    0x13,
+    0x14,
+    0x15,
+    0x16,
+    0x17,
+    0x18,
+    0x19,
+    0x1A,
+    0x1B,
+    0x1C,
+    0x1D,
+    0x1E,
+    0x1F,
+    0x20,
+    0x21,
+    0x22,
+    0x23,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0x24,
+    0x25,
+    0x26,
+    0x27,
+    0x28,
+    0x29,
+    0x2A,
+    0x2B,
+    0x2C,
+    0x2D,
+    0x2E,
+    0x2F,
+    0x30,
+    0x31,
+    0x32,
+    0x33,
+    0x34,
+    0x35,
+    0x36,
+    0x37,
+    0x38,
+    0x39,
+    0x3A,
+    0x3B,
+    0x3C,
+    0x3D,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
+    0xFF,
 };
 
 #ifndef CHARSET_EBCDIC
@@ -136,6 +374,7 @@ void evp_encode_ctx_set_flags(EVP_ENCODE_CTX *ctx, unsigned int flags)
 
 void EVP_EncodeInit(EVP_ENCODE_CTX *ctx)
 {
+    ctx->length = 48;
     ctx->num = 0;
     ctx->line_num = 0;
     ctx->flags = 0;
@@ -144,70 +383,45 @@ void EVP_EncodeInit(EVP_ENCODE_CTX *ctx)
 int EVP_EncodeUpdate(EVP_ENCODE_CTX *ctx, unsigned char *out, int *outl,
     const unsigned char *in, int inl)
 {
-    int i;
-    size_t j;
+    int i, j;
     size_t total = 0;
 
     *outl = 0;
     if (inl <= 0)
         return 0;
-    assert(EVP_ENCODE_B64_LENGTH <= (int)sizeof(ctx->enc_data));
-    if (EVP_ENCODE_B64_LENGTH - ctx->num > inl) {
+    OPENSSL_assert(ctx->length <= (int)sizeof(ctx->enc_data));
+    if (ctx->length - ctx->num > inl) {
         memcpy(&(ctx->enc_data[ctx->num]), in, inl);
         ctx->num += inl;
         return 1;
     }
     if (ctx->num != 0) {
-        i = EVP_ENCODE_B64_LENGTH - ctx->num;
+        i = ctx->length - ctx->num;
         memcpy(&(ctx->enc_data[ctx->num]), in, i);
         in += i;
         inl -= i;
-        int wrap_cnt = 0;
-        j = evp_encodeblock_int(ctx, out, ctx->enc_data, EVP_ENCODE_B64_LENGTH,
-            &wrap_cnt);
+        j = evp_encodeblock_int(ctx, out, ctx->enc_data, ctx->length);
         ctx->num = 0;
         out += j;
         total = j;
+        if ((ctx->flags & EVP_ENCODE_CTX_NO_NEWLINES) == 0) {
+            *(out++) = '\n';
+            total++;
+        }
         *out = '\0';
     }
-    int wrap_cnt = 0;
-    if (EVP_ENCODE_B64_LENGTH % 3 != 0) {
-        j = evp_encodeblock_int(ctx, out, in, inl - (inl % EVP_ENCODE_B64_LENGTH),
-            &wrap_cnt);
-    } else {
-#if defined(__AVX2__) && defined(HAVE_AVX2_INTRINSICS)
-        const int newlines = !(ctx->flags & EVP_ENCODE_CTX_NO_NEWLINES) ? EVP_ENCODE_B64_LENGTH : 0;
-
-        j = encode_base64_avx2(ctx,
-            (unsigned char *)out,
-            (const unsigned char *)in,
-            inl - (inl % EVP_ENCODE_B64_LENGTH), newlines, &wrap_cnt);
-#elif defined(HAS_IA32CAP_IS_64) && defined(HAVE_AVX2_INTRINSICS)
-        if ((OPENSSL_ia32cap_P[2] & (1u << 5)) != 0) {
-            const int newlines = !(ctx->flags & EVP_ENCODE_CTX_NO_NEWLINES) ? EVP_ENCODE_B64_LENGTH : 0;
-
-            j = encode_base64_avx2(ctx,
-                (unsigned char *)out,
-                (const unsigned char *)in,
-                inl - (inl % EVP_ENCODE_B64_LENGTH), newlines, &wrap_cnt);
-        } else {
-            j = evp_encodeblock_int(ctx, out, in, inl - (inl % EVP_ENCODE_B64_LENGTH),
-                &wrap_cnt);
+    while (inl >= ctx->length && total <= INT_MAX) {
+        j = evp_encodeblock_int(ctx, out, in, ctx->length);
+        in += ctx->length;
+        inl -= ctx->length;
+        out += j;
+        total += j;
+        if ((ctx->flags & EVP_ENCODE_CTX_NO_NEWLINES) == 0) {
+            *(out++) = '\n';
+            total++;
         }
-#else
-        j = evp_encodeblock_int(ctx, out, in, inl - (inl % EVP_ENCODE_B64_LENGTH),
-            &wrap_cnt);
-#endif
+        *out = '\0';
     }
-    in += inl - (inl % EVP_ENCODE_B64_LENGTH);
-    inl -= inl - (inl % EVP_ENCODE_B64_LENGTH);
-    out += j;
-    total += j;
-    if ((ctx->flags & EVP_ENCODE_CTX_NO_NEWLINES) == 0 && EVP_ENCODE_B64_LENGTH % 3 != 0) {
-        *(out++) = '\n';
-        total++;
-    }
-    *out = '\0';
     if (total > INT_MAX) {
         /* Too much output data! */
         *outl = 0;
@@ -223,42 +437,65 @@ int EVP_EncodeUpdate(EVP_ENCODE_CTX *ctx, unsigned char *out, int *outl,
 
 void EVP_EncodeFinal(EVP_ENCODE_CTX *ctx, unsigned char *out, int *outl)
 {
-    size_t ret = 0;
-    int wrap_cnt = 0;
+    unsigned int ret = 0;
 
     if (ctx->num != 0) {
-        ret = evp_encodeblock_int(ctx, out, ctx->enc_data, ctx->num,
-            &wrap_cnt);
-        if (ret > 0) {
-            if ((ctx->flags & EVP_ENCODE_CTX_NO_NEWLINES) == 0)
-                out[ret++] = '\n';
-            out[ret] = '\0';
-            ctx->num = 0;
-        }
+        ret = evp_encodeblock_int(ctx, out, ctx->enc_data, ctx->num);
+        if ((ctx->flags & EVP_ENCODE_CTX_NO_NEWLINES) == 0)
+            out[ret++] = '\n';
+        out[ret] = '\0';
+        ctx->num = 0;
     }
-    *outl = (int)ret;
+    *outl = ret;
+}
+
+static int evp_encodeblock_int(EVP_ENCODE_CTX *ctx, unsigned char *t,
+    const unsigned char *f, int dlen)
+{
+    int i, ret = 0;
+    unsigned long l;
+    const unsigned char *table;
+
+    if (ctx != NULL && (ctx->flags & EVP_ENCODE_CTX_USE_SRP_ALPHABET) != 0)
+        table = srpdata_bin2ascii;
+    else
+        table = data_bin2ascii;
+
+    for (i = dlen; i > 0; i -= 3) {
+        if (i >= 3) {
+            l = (((unsigned long)f[0]) << 16L) | (((unsigned long)f[1]) << 8L) | f[2];
+            *(t++) = conv_bin2ascii(l >> 18L, table);
+            *(t++) = conv_bin2ascii(l >> 12L, table);
+            *(t++) = conv_bin2ascii(l >> 6L, table);
+            *(t++) = conv_bin2ascii(l, table);
+        } else {
+            l = ((unsigned long)f[0]) << 16L;
+            if (i == 2)
+                l |= ((unsigned long)f[1] << 8L);
+
+            *(t++) = conv_bin2ascii(l >> 18L, table);
+            *(t++) = conv_bin2ascii(l >> 12L, table);
+            *(t++) = (i == 1) ? '=' : conv_bin2ascii(l >> 6L, table);
+            *(t++) = '=';
+        }
+        ret += 4;
+        f += 3;
+    }
+
+    *t = '\0';
+    return ret;
 }
 
 int EVP_EncodeBlock(unsigned char *t, const unsigned char *f, int dlen)
 {
-    int wrap_cnt = 0;
-
-#if defined(__AVX2__) && defined(HAVE_AVX2_INTRINSICS)
-    return (int)encode_base64_avx2(NULL, t, f, dlen, 0, &wrap_cnt);
-#elif defined(HAS_IA32CAP_IS_64) && defined(HAVE_AVX2_INTRINSICS)
-    if ((OPENSSL_ia32cap_P[2] & (1u << 5)) != 0)
-        return (int)encode_base64_avx2(NULL, t, f, dlen, 0, &wrap_cnt);
-    else
-        return (int)evp_encodeblock_int(NULL, t, f, dlen, &wrap_cnt);
-#else
-    return (int)evp_encodeblock_int(NULL, t, f, dlen, &wrap_cnt);
-#endif
+    return evp_encodeblock_int(NULL, t, f, dlen);
 }
 
 void EVP_DecodeInit(EVP_ENCODE_CTX *ctx)
 {
     /* Only ctx->num and ctx->flags are used during decoding. */
     ctx->num = 0;
+    ctx->length = 0;
     ctx->line_num = 0;
     ctx->flags = 0;
 }
@@ -452,20 +689,20 @@ static int evp_decodeblock_int(EVP_ENCODE_CTX *ctx, unsigned char *t,
     l = ((((unsigned long)a) << 18L) | (((unsigned long)b) << 12L) | (((unsigned long)c) << 6L) | (((unsigned long)d)));
 
     if (eof == -1)
-        eof = (c == '=') + (d == '=');
+        eof = (f[2] == '=') + (f[3] == '=');
 
     switch (eof) {
     case 2:
-        *t = (unsigned char)(l >> 16L) & 0xff;
+        *(t++) = (unsigned char)(l >> 16L) & 0xff;
         break;
     case 1:
         *(t++) = (unsigned char)(l >> 16L) & 0xff;
-        *t = (unsigned char)(l >> 8L) & 0xff;
+        *(t++) = (unsigned char)(l >> 8L) & 0xff;
         break;
     case 0:
         *(t++) = (unsigned char)(l >> 16L) & 0xff;
         *(t++) = (unsigned char)(l >> 8L) & 0xff;
-        *t = (unsigned char)(l) & 0xff;
+        *(t++) = (unsigned char)(l) & 0xff;
         break;
     }
     ret += 3 - eof;
diff --git a/crypto/evp/evp_enc.c b/crypto/evp/evp_enc.c
index a5c513db0d..bce9d8d2cb 100644
--- a/crypto/evp/evp_enc.c
+++ b/crypto/evp/evp_enc.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -31,7 +31,7 @@ int EVP_CIPHER_CTX_reset(EVP_CIPHER_CTX *ctx)
         return 1;
 
     if (ctx->cipher == NULL || ctx->cipher->prov == NULL)
-        return 1;
+        goto legacy;
 
     if (ctx->algctx != NULL) {
         if (ctx->cipher->freectx != NULL)
@@ -44,6 +44,21 @@ int EVP_CIPHER_CTX_reset(EVP_CIPHER_CTX *ctx)
     ctx->iv_len = -1;
 
     return 1;
+
+    /* Remove legacy code below when legacy support is removed. */
+legacy:
+
+    if (ctx->cipher != NULL) {
+        if (ctx->cipher->cleanup && !ctx->cipher->cleanup(ctx))
+            return 0;
+        /* Cleanse cipher context data */
+        if (ctx->cipher_data && ctx->cipher->ctx_size)
+            OPENSSL_cleanse(ctx->cipher_data, ctx->cipher->ctx_size);
+    }
+    OPENSSL_free(ctx->cipher_data);
+    memset(ctx, 0, sizeof(*ctx));
+    ctx->iv_len = -1;
+    return 1;
 }
 
 EVP_CIPHER_CTX *EVP_CIPHER_CTX_new(void)
@@ -73,6 +88,8 @@ static int evp_cipher_init_internal(EVP_CIPHER_CTX *ctx,
     uint8_t is_pipeline,
     const OSSL_PARAM params[])
 {
+    int n;
+
     /*
      * enc == 1 means we are encrypting.
      * enc == 0 means we are decrypting.
@@ -91,6 +108,35 @@ static int evp_cipher_init_internal(EVP_CIPHER_CTX *ctx,
         return 0;
     }
 
+    /* Code below to be removed when legacy support is dropped. */
+    if (is_pipeline)
+        goto nonlegacy;
+
+    /*
+     * If there are engines involved then we should use legacy handling for now.
+     */
+    if ((cipher != NULL && cipher->origin == EVP_ORIG_METH)
+        || (cipher == NULL && ctx->cipher != NULL
+            && ctx->cipher->origin == EVP_ORIG_METH)) {
+        if (ctx->cipher == ctx->fetched_cipher)
+            ctx->cipher = NULL;
+        EVP_CIPHER_free(ctx->fetched_cipher);
+        ctx->fetched_cipher = NULL;
+        goto legacy;
+    }
+    /*
+     * Ensure a context left lying around from last time is cleared
+     * (legacy code)
+     */
+    if (cipher != NULL && ctx->cipher != NULL) {
+        if (ctx->cipher->cleanup != NULL && !ctx->cipher->cleanup(ctx))
+            return 0;
+        OPENSSL_clear_free(ctx->cipher_data, ctx->cipher->ctx_size);
+        ctx->cipher_data = NULL;
+    }
+
+    /* Start of non-legacy code below */
+nonlegacy:
     /* Ensure a context left lying around from last time is cleared */
     if (cipher != NULL && ctx->cipher != NULL) {
         unsigned long flags = ctx->flags;
@@ -252,6 +298,111 @@ static int evp_cipher_init_internal(EVP_CIPHER_CTX *ctx,
         iv == NULL ? 0
                    : EVP_CIPHER_CTX_get_iv_length(ctx),
         params);
+
+    /* Code below to be removed when legacy support is dropped. */
+legacy:
+
+    if (cipher != NULL) {
+        /*
+         * Ensure a context left lying around from last time is cleared (we
+         * previously attempted to avoid this if the same ENGINE and
+         * EVP_CIPHER could be used).
+         */
+        if (ctx->cipher) {
+            unsigned long flags = ctx->flags;
+            EVP_CIPHER_CTX_reset(ctx);
+            /* Restore encrypt and flags */
+            ctx->encrypt = enc;
+            ctx->flags = flags;
+        }
+
+        ctx->cipher = cipher;
+        if (ctx->cipher->ctx_size) {
+            ctx->cipher_data = OPENSSL_zalloc(ctx->cipher->ctx_size);
+            if (ctx->cipher_data == NULL) {
+                ctx->cipher = NULL;
+                return 0;
+            }
+        } else {
+            ctx->cipher_data = NULL;
+        }
+        ctx->key_len = cipher->key_len;
+        /* Preserve wrap enable flag, zero everything else */
+        ctx->flags &= EVP_CIPHER_CTX_FLAG_WRAP_ALLOW;
+        if (ctx->cipher->flags & EVP_CIPH_CTRL_INIT) {
+            if (EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_INIT, 0, NULL) <= 0) {
+                ctx->cipher = NULL;
+                ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
+                return 0;
+            }
+        }
+    }
+    if (ctx->cipher == NULL)
+        return 0;
+
+    /* we assume block size is a power of 2 in *cryptUpdate */
+    OPENSSL_assert(ctx->cipher->block_size == 1
+        || ctx->cipher->block_size == 8
+        || ctx->cipher->block_size == 16);
+
+    if (!(ctx->flags & EVP_CIPHER_CTX_FLAG_WRAP_ALLOW)
+        && EVP_CIPHER_CTX_get_mode(ctx) == EVP_CIPH_WRAP_MODE) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_WRAP_MODE_NOT_ALLOWED);
+        return 0;
+    }
+
+    if ((EVP_CIPHER_get_flags(EVP_CIPHER_CTX_get0_cipher(ctx))
+            & EVP_CIPH_CUSTOM_IV)
+        == 0) {
+        switch (EVP_CIPHER_CTX_get_mode(ctx)) {
+
+        case EVP_CIPH_STREAM_CIPHER:
+        case EVP_CIPH_ECB_MODE:
+            break;
+
+        case EVP_CIPH_CFB_MODE:
+        case EVP_CIPH_OFB_MODE:
+
+            ctx->num = 0;
+            /* fall-through */
+
+        case EVP_CIPH_CBC_MODE:
+            n = EVP_CIPHER_CTX_get_iv_length(ctx);
+            if (n < 0 || n > (int)sizeof(ctx->iv)) {
+                ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_IV_LENGTH);
+                return 0;
+            }
+            if (iv != NULL)
+                memcpy(ctx->oiv, iv, n);
+            memcpy(ctx->iv, ctx->oiv, n);
+            break;
+
+        case EVP_CIPH_CTR_MODE:
+            ctx->num = 0;
+            /* Don't reuse IV for CTR mode */
+            if (iv != NULL) {
+                n = EVP_CIPHER_CTX_get_iv_length(ctx);
+                if (n <= 0 || n > (int)sizeof(ctx->iv)) {
+                    ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_IV_LENGTH);
+                    return 0;
+                }
+                memcpy(ctx->iv, iv, n);
+            }
+            break;
+
+        default:
+            return 0;
+        }
+    }
+
+    if (key != NULL || (ctx->cipher->flags & EVP_CIPH_ALWAYS_CALL_INIT)) {
+        if (!ctx->cipher->init(ctx, key, iv, enc))
+            return 0;
+    }
+    ctx->buf_len = 0;
+    ctx->final_used = 0;
+    ctx->block_mask = ctx->cipher->block_size - 1;
+    return 1;
 }
 
 /*
@@ -281,6 +432,26 @@ static int evp_cipher_init_skey_internal(EVP_CIPHER_CTX *ctx,
         return 0;
     }
 
+    /*
+     * If there are engines involved then we throw an error
+     */
+    if ((cipher != NULL && cipher->origin == EVP_ORIG_METH)
+        || (cipher == NULL && ctx->cipher != NULL
+            && ctx->cipher->origin == EVP_ORIG_METH)) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
+        return 0;
+    }
+    /*
+     * Ensure a context left lying around from last time is cleared
+     * (legacy code)
+     */
+    if (cipher != NULL && ctx->cipher != NULL) {
+        if (ctx->cipher->cleanup != NULL && !ctx->cipher->cleanup(ctx))
+            return 0;
+        OPENSSL_clear_free(ctx->cipher_data, ctx->cipher->ctx_size);
+        ctx->cipher_data = NULL;
+    }
+
     /* Ensure a context left lying around from last time is cleared */
     if (cipher != NULL && ctx->cipher != NULL) {
         unsigned long flags = ctx->flags;
@@ -647,6 +818,96 @@ int ossl_is_partially_overlapping(const void *ptr1, const void *ptr2, int len)
     return overlapped;
 }
 
+static int evp_EncryptDecryptUpdate(EVP_CIPHER_CTX *ctx,
+    unsigned char *out, int *outl,
+    const unsigned char *in, int inl)
+{
+    int i, j, bl, cmpl = inl;
+
+    if (EVP_CIPHER_CTX_test_flags(ctx, EVP_CIPH_FLAG_LENGTH_BITS))
+        cmpl = safe_div_round_up_int(cmpl, 8, NULL);
+
+    bl = ctx->cipher->block_size;
+
+    if (ctx->cipher->flags & EVP_CIPH_FLAG_CUSTOM_CIPHER) {
+        /* If block size > 1 then the cipher will have to do this check */
+        if (bl == 1 && ossl_is_partially_overlapping(out, in, cmpl)) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_PARTIALLY_OVERLAPPING);
+            return 0;
+        }
+
+        i = ctx->cipher->do_cipher(ctx, out, in, inl);
+        if (i < 0)
+            return 0;
+        else
+            *outl = i;
+        return 1;
+    }
+
+    if (inl <= 0) {
+        *outl = 0;
+        return inl == 0;
+    }
+    if (ossl_is_partially_overlapping(out + ctx->buf_len, in, cmpl)) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_PARTIALLY_OVERLAPPING);
+        return 0;
+    }
+
+    if (ctx->buf_len == 0 && (inl & (ctx->block_mask)) == 0) {
+        if (ctx->cipher->do_cipher(ctx, out, in, inl)) {
+            *outl = inl;
+            return 1;
+        } else {
+            *outl = 0;
+            return 0;
+        }
+    }
+    i = ctx->buf_len;
+    OPENSSL_assert(bl <= (int)sizeof(ctx->buf));
+    if (i != 0) {
+        if (bl - i > inl) {
+            memcpy(&(ctx->buf[i]), in, inl);
+            ctx->buf_len += inl;
+            *outl = 0;
+            return 1;
+        } else {
+            j = bl - i;
+
+            /*
+             * Once we've processed the first j bytes from in, the amount of
+             * data left that is a multiple of the block length is:
+             * (inl - j) & ~(bl - 1)
+             * We must ensure that this amount of data, plus the one block that
+             * we process from ctx->buf does not exceed INT_MAX
+             */
+            if (((inl - j) & ~(bl - 1)) > INT_MAX - bl) {
+                ERR_raise(ERR_LIB_EVP, EVP_R_OUTPUT_WOULD_OVERFLOW);
+                return 0;
+            }
+            memcpy(&(ctx->buf[i]), in, j);
+            inl -= j;
+            in += j;
+            if (!ctx->cipher->do_cipher(ctx, out, ctx->buf, bl))
+                return 0;
+            out += bl;
+            *outl = bl;
+        }
+    } else
+        *outl = 0;
+    i = inl & (bl - 1);
+    inl -= i;
+    if (inl > 0) {
+        if (!ctx->cipher->do_cipher(ctx, out, in, inl))
+            return 0;
+        *outl += inl;
+    }
+
+    if (i != 0)
+        memcpy(ctx->buf, &(in[inl]), i);
+    ctx->buf_len = i;
+    return 1;
+}
+
 int EVP_EncryptUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl,
     const unsigned char *in, int inl)
 {
@@ -654,11 +915,6 @@ int EVP_EncryptUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl,
     size_t soutl, inl_ = (size_t)inl;
     int blocksize;
 
-    if (inl < 0) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_LENGTH);
-        return 0;
-    }
-
     if (ossl_likely(outl != NULL)) {
         *outl = 0;
     } else {
@@ -678,7 +934,7 @@ int EVP_EncryptUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl,
     }
 
     if (ossl_unlikely(ctx->cipher->prov == NULL))
-        return 0;
+        goto legacy;
 
     blocksize = ctx->cipher->block_size;
 
@@ -700,6 +956,11 @@ int EVP_EncryptUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl,
     }
 
     return ret;
+
+    /* Code below to be removed when legacy support is dropped. */
+legacy:
+
+    return evp_EncryptDecryptUpdate(ctx, out, outl, in, inl);
 }
 
 int EVP_EncryptFinal(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl)
@@ -711,7 +972,8 @@ int EVP_EncryptFinal(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl)
 
 int EVP_EncryptFinal_ex(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl)
 {
-    int ret;
+    int n, ret;
+    unsigned int i, b, bl;
     size_t soutl;
     int blocksize;
 
@@ -732,10 +994,8 @@ int EVP_EncryptFinal_ex(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl)
         ERR_raise(ERR_LIB_EVP, EVP_R_NO_CIPHER_SET);
         return 0;
     }
-    if (ctx->cipher->prov == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_NO_CIPHER_SET);
-        return 0;
-    }
+    if (ctx->cipher->prov == NULL)
+        goto legacy;
 
     blocksize = EVP_CIPHER_CTX_get_block_size(ctx);
 
@@ -756,20 +1016,54 @@ int EVP_EncryptFinal_ex(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl)
     }
 
     return ret;
+
+    /* Code below to be removed when legacy support is dropped. */
+legacy:
+
+    if (ctx->cipher->flags & EVP_CIPH_FLAG_CUSTOM_CIPHER) {
+        ret = ctx->cipher->do_cipher(ctx, out, NULL, 0);
+        if (ret < 0)
+            return 0;
+        else
+            *outl = ret;
+        return 1;
+    }
+
+    b = ctx->cipher->block_size;
+    OPENSSL_assert(b <= sizeof(ctx->buf));
+    if (b == 1) {
+        *outl = 0;
+        return 1;
+    }
+    bl = ctx->buf_len;
+    if (ctx->flags & EVP_CIPH_NO_PADDING) {
+        if (bl) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_DATA_NOT_MULTIPLE_OF_BLOCK_LENGTH);
+            return 0;
+        }
+        *outl = 0;
+        return 1;
+    }
+
+    n = b - bl;
+    for (i = bl; i < b; i++)
+        ctx->buf[i] = n;
+    ret = ctx->cipher->do_cipher(ctx, out, ctx->buf, b);
+
+    if (ret)
+        *outl = b;
+
+    return ret;
 }
 
 int EVP_DecryptUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl,
     const unsigned char *in, int inl)
 {
-    int ret;
+    int fix_len, cmpl = inl, ret;
+    unsigned int b;
     size_t soutl, inl_ = (size_t)inl;
     int blocksize;
 
-    if (inl < 0) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_LENGTH);
-        return 0;
-    }
-
     if (ossl_likely(outl != NULL)) {
         *outl = 0;
     } else {
@@ -787,10 +1081,8 @@ int EVP_DecryptUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl,
         ERR_raise(ERR_LIB_EVP, EVP_R_NO_CIPHER_SET);
         return 0;
     }
-    if (ossl_unlikely(ctx->cipher->prov == NULL)) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_NO_CIPHER_SET);
-        return 0;
-    }
+    if (ossl_unlikely(ctx->cipher->prov == NULL))
+        goto legacy;
 
     blocksize = EVP_CIPHER_CTX_get_block_size(ctx);
 
@@ -811,6 +1103,84 @@ int EVP_DecryptUpdate(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl,
     }
 
     return ret;
+
+    /* Code below to be removed when legacy support is dropped. */
+legacy:
+
+    b = ctx->cipher->block_size;
+
+    if (EVP_CIPHER_CTX_test_flags(ctx, EVP_CIPH_FLAG_LENGTH_BITS))
+        cmpl = safe_div_round_up_int(cmpl, 8, NULL);
+
+    if (ctx->cipher->flags & EVP_CIPH_FLAG_CUSTOM_CIPHER) {
+        if (b == 1 && ossl_is_partially_overlapping(out, in, cmpl)) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_PARTIALLY_OVERLAPPING);
+            return 0;
+        }
+
+        fix_len = ctx->cipher->do_cipher(ctx, out, in, inl);
+        if (fix_len < 0) {
+            *outl = 0;
+            return 0;
+        } else
+            *outl = fix_len;
+        return 1;
+    }
+
+    if (inl <= 0) {
+        *outl = 0;
+        return inl == 0;
+    }
+
+    if (ctx->flags & EVP_CIPH_NO_PADDING)
+        return evp_EncryptDecryptUpdate(ctx, out, outl, in, inl);
+
+    OPENSSL_assert(b <= sizeof(ctx->final));
+
+    if (ctx->final_used) {
+        /* see comment about PTRDIFF_T comparison above */
+        if (((PTRDIFF_T)out == (PTRDIFF_T)in)
+            || ossl_is_partially_overlapping(out, in, b)) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_PARTIALLY_OVERLAPPING);
+            return 0;
+        }
+        /*
+         * final_used is only ever set if buf_len is 0. Therefore the maximum
+         * length output we will ever see from evp_EncryptDecryptUpdate is
+         * the maximum multiple of the block length that is <= inl, or just:
+         * inl & ~(b - 1)
+         * Since final_used has been set then the final output length is:
+         * (inl & ~(b - 1)) + b
+         * This must never exceed INT_MAX
+         */
+        if ((inl & ~(b - 1)) > INT_MAX - b) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_OUTPUT_WOULD_OVERFLOW);
+            return 0;
+        }
+        memcpy(out, ctx->final, b);
+        out += b;
+        fix_len = 1;
+    } else
+        fix_len = 0;
+
+    if (!evp_EncryptDecryptUpdate(ctx, out, outl, in, inl))
+        return 0;
+
+    /*
+     * if we have 'decrypted' a multiple of block size, make sure we have a
+     * copy of this last block
+     */
+    if (b > 1 && !ctx->buf_len) {
+        *outl -= b;
+        ctx->final_used = 1;
+        memcpy(ctx->final, &out[*outl], b);
+    } else
+        ctx->final_used = 0;
+
+    if (fix_len)
+        *outl += b;
+
+    return 1;
 }
 
 int EVP_DecryptFinal(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl)
@@ -822,6 +1192,8 @@ int EVP_DecryptFinal(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl)
 
 int EVP_DecryptFinal_ex(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl)
 {
+    int i, n;
+    unsigned int b;
     size_t soutl;
     int ret;
     int blocksize;
@@ -844,10 +1216,8 @@ int EVP_DecryptFinal_ex(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl)
         return 0;
     }
 
-    if (ctx->cipher->prov == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_NO_CIPHER_SET);
-        return 0;
-    }
+    if (ctx->cipher->prov == NULL)
+        goto legacy;
 
     blocksize = EVP_CIPHER_CTX_get_block_size(ctx);
 
@@ -868,38 +1238,103 @@ int EVP_DecryptFinal_ex(EVP_CIPHER_CTX *ctx, unsigned char *out, int *outl)
     }
 
     return ret;
+
+    /* Code below to be removed when legacy support is dropped. */
+legacy:
+
+    *outl = 0;
+    if (ctx->cipher->flags & EVP_CIPH_FLAG_CUSTOM_CIPHER) {
+        i = ctx->cipher->do_cipher(ctx, out, NULL, 0);
+        if (i < 0)
+            return 0;
+        else
+            *outl = i;
+        return 1;
+    }
+
+    b = ctx->cipher->block_size;
+    if (ctx->flags & EVP_CIPH_NO_PADDING) {
+        if (ctx->buf_len) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_DATA_NOT_MULTIPLE_OF_BLOCK_LENGTH);
+            return 0;
+        }
+        *outl = 0;
+        return 1;
+    }
+    if (b > 1) {
+        if (ctx->buf_len || !ctx->final_used) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_WRONG_FINAL_BLOCK_LENGTH);
+            return 0;
+        }
+        OPENSSL_assert(b <= sizeof(ctx->final));
+
+        /*
+         * The following assumes that the ciphertext has been authenticated.
+         * Otherwise it provides a padding oracle.
+         */
+        n = ctx->final[b - 1];
+        if (n == 0 || n > (int)b) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_BAD_DECRYPT);
+            return 0;
+        }
+        for (i = 0; i < n; i++) {
+            if (ctx->final[--b] != n) {
+                ERR_raise(ERR_LIB_EVP, EVP_R_BAD_DECRYPT);
+                return 0;
+            }
+        }
+        n = ctx->cipher->block_size - n;
+        for (i = 0; i < n; i++)
+            out[i] = ctx->final[i];
+        *outl = n;
+    }
+    return 1;
 }
 
 int EVP_CIPHER_CTX_set_key_length(EVP_CIPHER_CTX *c, int keylen)
 {
-    int ok;
-    OSSL_PARAM params[2] = { OSSL_PARAM_END, OSSL_PARAM_END };
-    size_t len;
+    if (c->cipher->prov != NULL) {
+        int ok;
+        OSSL_PARAM params[2] = { OSSL_PARAM_END, OSSL_PARAM_END };
+        size_t len;
 
-    if (c->cipher->prov == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_CIPHER_PARAMETER_ERROR);
-        return 0;
+        if (EVP_CIPHER_CTX_get_key_length(c) == keylen)
+            return 1;
+
+        /* Check the cipher actually understands this parameter */
+        if (OSSL_PARAM_locate_const(EVP_CIPHER_settable_ctx_params(c->cipher),
+                OSSL_CIPHER_PARAM_KEYLEN)
+            == NULL) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+            return 0;
+        }
+
+        params[0] = OSSL_PARAM_construct_size_t(OSSL_CIPHER_PARAM_KEYLEN, &len);
+        if (!OSSL_PARAM_set_int(params, keylen))
+            return 0;
+        ok = evp_do_ciph_ctx_setparams(c->cipher, c->algctx, params);
+        if (ok <= 0)
+            return 0;
+        c->key_len = keylen;
+        return 1;
     }
 
+    /* Code below to be removed when legacy support is dropped. */
+
+    /*
+     * Note there have never been any built-in ciphers that define this flag
+     * since it was first introduced.
+     */
+    if (c->cipher->flags & EVP_CIPH_CUSTOM_KEY_LENGTH)
+        return EVP_CIPHER_CTX_ctrl(c, EVP_CTRL_SET_KEY_LENGTH, keylen, NULL);
     if (EVP_CIPHER_CTX_get_key_length(c) == keylen)
         return 1;
-
-    /* Check the cipher actually understands this parameter */
-    if (OSSL_PARAM_locate_const(EVP_CIPHER_settable_ctx_params(c->cipher),
-            OSSL_CIPHER_PARAM_KEYLEN)
-        == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
-        return 0;
+    if ((keylen > 0) && (c->cipher->flags & EVP_CIPH_VARIABLE_LENGTH)) {
+        c->key_len = keylen;
+        return 1;
     }
-
-    params[0] = OSSL_PARAM_construct_size_t(OSSL_CIPHER_PARAM_KEYLEN, &len);
-    if (!OSSL_PARAM_set_int(params, keylen))
-        return 0;
-    ok = evp_do_ciph_ctx_setparams(c->cipher, c->algctx, params);
-    if (ok <= 0)
-        return 0;
-    c->key_len = keylen;
-    return 1;
+    ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY_LENGTH);
+    return 0;
 }
 
 int EVP_CIPHER_CTX_set_padding(EVP_CIPHER_CTX *ctx, int pad)
@@ -936,10 +1371,8 @@ int EVP_CIPHER_CTX_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg, void *ptr)
         return 0;
     }
 
-    if (ctx->cipher->prov == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_CTRL_NOT_IMPLEMENTED);
-        return 0;
-    }
+    if (ctx->cipher->prov == NULL)
+        goto legacy;
 
     switch (type) {
     case EVP_CTRL_SET_KEY_LENGTH:
@@ -1117,6 +1550,16 @@ int EVP_CIPHER_CTX_ctrl(EVP_CIPHER_CTX *ctx, int type, int arg, void *ptr)
         ret = evp_do_ciph_ctx_setparams(ctx->cipher, ctx->algctx, params);
     else
         ret = evp_do_ciph_ctx_getparams(ctx->cipher, ctx->algctx, params);
+    goto end;
+
+    /* Code below to be removed when legacy support is dropped. */
+legacy:
+    if (ctx->cipher->ctrl == NULL) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_CTRL_NOT_IMPLEMENTED);
+        return 0;
+    }
+
+    ret = ctx->cipher->ctrl(ctx, type, arg, ptr);
 
 end:
     if (ret == EVP_CTRL_RET_UNSUPPORTED) {
@@ -1269,10 +1712,8 @@ int EVP_CIPHER_CTX_copy(EVP_CIPHER_CTX *out, const EVP_CIPHER_CTX *in)
         return 0;
     }
 
-    if (in->cipher->prov == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_INPUT_NOT_INITIALIZED);
-        return 0;
-    }
+    if (in->cipher->prov == NULL)
+        goto legacy;
 
     if (in->cipher->dupctx == NULL) {
         ERR_raise(ERR_LIB_EVP, EVP_R_NOT_ABLE_TO_COPY_CTX);
@@ -1296,6 +1737,29 @@ int EVP_CIPHER_CTX_copy(EVP_CIPHER_CTX *out, const EVP_CIPHER_CTX *in)
     }
 
     return 1;
+
+    /* Code below to be removed when legacy support is dropped. */
+legacy:
+
+    EVP_CIPHER_CTX_reset(out);
+    memcpy(out, in, sizeof(*out));
+
+    if (in->cipher_data && in->cipher->ctx_size) {
+        out->cipher_data = OPENSSL_malloc(in->cipher->ctx_size);
+        if (out->cipher_data == NULL) {
+            out->cipher = NULL;
+            return 0;
+        }
+        memcpy(out->cipher_data, in->cipher_data, in->cipher->ctx_size);
+    }
+
+    if (in->cipher->flags & EVP_CIPH_CUSTOM_COPY)
+        if (!in->cipher->ctrl((EVP_CIPHER_CTX *)in, EVP_CTRL_COPY, 0, out)) {
+            out->cipher = NULL;
+            ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
+            return 0;
+        }
+    return 1;
 }
 
 EVP_CIPHER *evp_cipher_new(void)
@@ -1340,33 +1804,9 @@ static void set_legacy_nid(const char *name, void *vlegacy_nid)
 }
 #endif
 
-static int evp_cipher_up_ref(void *c)
-{
-    EVP_CIPHER *cipher = (EVP_CIPHER *)c;
-    int ref = 0;
-
-    if (cipher->origin == EVP_ORIG_DYNAMIC)
-        return CRYPTO_UP_REF(&cipher->refcnt, &ref);
-    return 1;
-}
-
-static void evp_cipher_free(void *c)
-{
-    EVP_CIPHER *cipher = (EVP_CIPHER *)c;
-    int i;
-
-    if (cipher == NULL || cipher->origin != EVP_ORIG_DYNAMIC)
-        return;
-
-    CRYPTO_DOWN_REF(&cipher->refcnt, &i);
-    if (i > 0)
-        return;
-    evp_cipher_free_int(cipher);
-}
-
 static void *evp_cipher_from_algorithm(const int name_id,
     const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, int no_store)
+    OSSL_PROVIDER *prov)
 {
     const OSSL_DISPATCH *fns = algodef->implementation;
     EVP_CIPHER *cipher = NULL;
@@ -1377,9 +1817,6 @@ static void *evp_cipher_from_algorithm(const int name_id,
         return NULL;
     }
 
-    if (no_store != 0)
-        cipher->flags |= EVP_CIPH_FLAG_NO_STORE;
-
 #ifndef FIPS_MODULE
     cipher->nid = NID_undef;
     if (!evp_names_do_all(prov, name_id, set_legacy_nid, &cipher->nid)
@@ -1515,12 +1952,12 @@ static void *evp_cipher_from_algorithm(const int name_id,
     if ((fnciphcnt != 0 && fnciphcnt != 3 && fnciphcnt != 4)
         || (fnciphcnt == 0 && cipher->ccipher == NULL && fnpipecnt == 0)
         || (fnpipecnt != 0 && (fnpipecnt < 3 || cipher->p_cupdate == NULL || cipher->p_cfinal == NULL))
-        || fnctxcnt != 2
-        || cipher->get_params == NULL) {
+        || fnctxcnt != 2) {
         /*
          * In order to be a consistent set of functions we must have at least
          * a complete set of "encrypt" functions, or a complete set of "decrypt"
-         * functions, or a single "cipher" function.
+         * functions, or a single "cipher" function. In all cases we need both
+         * the "newctx" and "freectx" functions.
          */
         ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_PROVIDER_FUNCTIONS);
         goto err;
@@ -1538,18 +1975,83 @@ static void *evp_cipher_from_algorithm(const int name_id,
     return cipher;
 
 err:
-    evp_cipher_free(cipher);
+    EVP_CIPHER_free(cipher);
     return NULL;
 }
 
+static int evp_cipher_up_ref(void *cipher)
+{
+    return EVP_CIPHER_up_ref(cipher);
+}
+
+static void evp_cipher_free(void *cipher)
+{
+    EVP_CIPHER_free(cipher);
+}
+
+static void *evp_cipher_dup_frozen(void *vin)
+{
+    EVP_CIPHER *in = vin;
+    EVP_CIPHER *out;
+
+    out = OPENSSL_malloc(sizeof(*out));
+    if (out == NULL)
+        return NULL;
+    memcpy(out, in, sizeof(*out));
+    if (!CRYPTO_NEW_REF(&out->refcnt, 1))
+        goto err;
+    out->type_name = OPENSSL_strdup(in->type_name);
+    if (out->type_name == NULL)
+        goto err;
+    out->origin = EVP_ORIG_FROZEN;
+    if (!ossl_provider_up_ref(out->prov)) {
+        OPENSSL_free(out->type_name);
+        goto err;
+    }
+    return out;
+err:
+    CRYPTO_FREE_REF(&out->refcnt);
+    OPENSSL_free(out);
+    return NULL;
+}
+
+static void evp_cipher_frozen_free(void *vin)
+{
+    EVP_CIPHER *cipher = vin;
+    int i;
+
+    if (cipher == NULL || cipher->origin != EVP_ORIG_FROZEN)
+        return;
+
+    CRYPTO_DOWN_REF(&cipher->refcnt, &i);
+    if (i > 0)
+        return;
+    evp_cipher_free_int(cipher);
+}
+
+int evp_cipher_fetch_all(OSSL_LIB_CTX *ctx)
+{
+    int ret = evp_generic_fetch_all(ctx,
+        OSSL_OP_CIPHER,
+        evp_cipher_from_algorithm,
+        evp_cipher_up_ref,
+        evp_cipher_free,
+        evp_cipher_dup_frozen,
+        evp_cipher_frozen_free);
+
+    return ret;
+}
+
 EVP_CIPHER *EVP_CIPHER_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
     const char *properties)
 {
-    EVP_CIPHER *cipher = evp_generic_fetch(ctx, OSSL_OP_CIPHER, algorithm, properties,
-        evp_cipher_from_algorithm, evp_cipher_up_ref,
-        evp_cipher_free);
-
-    return cipher;
+    return evp_generic_fetch(ctx, OSSL_OP_CIPHER,
+        algorithm, properties,
+        evp_cipher_from_algorithm,
+        evp_cipher_up_ref,
+        evp_cipher_free,
+        evp_cipher_dup_frozen,
+        evp_cipher_frozen_free);
 }
 
 EVP_CIPHER *evp_cipher_fetch_from_prov(OSSL_PROVIDER *prov,
@@ -1560,7 +2062,9 @@ EVP_CIPHER *evp_cipher_fetch_from_prov(OSSL_PROVIDER *prov,
         algorithm, properties,
         evp_cipher_from_algorithm,
         evp_cipher_up_ref,
-        evp_cipher_free);
+        evp_cipher_free,
+        evp_cipher_dup_frozen,
+        evp_cipher_frozen_free);
 }
 
 int EVP_CIPHER_can_pipeline(const EVP_CIPHER *cipher, int enc)
@@ -1574,13 +2078,11 @@ int EVP_CIPHER_can_pipeline(const EVP_CIPHER *cipher, int enc)
 
 int EVP_CIPHER_up_ref(EVP_CIPHER *cipher)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    return evp_cipher_up_ref(cipher);
-#else
-    if (cipher->flags & EVP_CIPH_FLAG_NO_STORE)
-        return evp_cipher_up_ref(cipher);
+    int ref = 0;
+
+    if (cipher->origin == EVP_ORIG_DYNAMIC)
+        CRYPTO_UP_REF(&cipher->refcnt, &ref);
     return 1;
-#endif
 }
 
 void evp_cipher_free_int(EVP_CIPHER *cipher)
@@ -1593,24 +2095,23 @@ void evp_cipher_free_int(EVP_CIPHER *cipher)
 
 void EVP_CIPHER_free(EVP_CIPHER *cipher)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    evp_cipher_free(cipher);
-#else
-    if (cipher != NULL && (cipher->flags & EVP_CIPH_FLAG_NO_STORE))
-        evp_cipher_free(cipher);
-#endif
+    int i;
+
+    if (cipher == NULL || cipher->origin != EVP_ORIG_DYNAMIC)
+        return;
+
+    CRYPTO_DOWN_REF(&cipher->refcnt, &i);
+    if (i > 0)
+        return;
+    evp_cipher_free_int(cipher);
 }
 
 void EVP_CIPHER_do_all_provided(OSSL_LIB_CTX *libctx,
     void (*fn)(EVP_CIPHER *mac, void *arg),
     void *arg)
 {
-    struct EVP_CIPHER_do_all_provided_thunk t;
-
-    t.fn = fn;
-    t.arg = arg;
     evp_generic_do_all(libctx, OSSL_OP_CIPHER,
-        EVP_CIPHER_do_all_provided_thunk, &t,
+        (void (*)(void *, void *))fn, arg,
         evp_cipher_from_algorithm, evp_cipher_up_ref,
         evp_cipher_free);
 }
diff --git a/crypto/evp/evp_err.c b/crypto/evp/evp_err.c
index 55b26c7cd7..5672e7293f 100644
--- a/crypto/evp/evp_err.c
+++ b/crypto/evp/evp_err.c
@@ -39,7 +39,6 @@ static const ERR_STRING_DATA EVP_str_reasons[] = {
         "command not supported" },
     { ERR_PACK(ERR_LIB_EVP, 0, EVP_R_CONFLICTING_ALGORITHM_NAME),
         "conflicting algorithm name" },
-    { ERR_PACK(ERR_LIB_EVP, 0, EVP_R_CONTEXT_FINALIZED), "context finalized" },
     { ERR_PACK(ERR_LIB_EVP, 0, EVP_R_COPY_ERROR), "copy error" },
     { ERR_PACK(ERR_LIB_EVP, 0, EVP_R_CTRL_NOT_IMPLEMENTED),
         "ctrl not implemented" },
diff --git a/crypto/evp/evp_fetch.c b/crypto/evp/evp_fetch.c
index 15204628db..aae8f45a3a 100644
--- a/crypto/evp/evp_fetch.c
+++ b/crypto/evp/evp_fetch.c
@@ -11,7 +11,6 @@
 #include 
 #include 
 #include 
-#include 
 #include "internal/cryptlib.h"
 #include "internal/thread_once.h"
 #include "internal/property.h"
@@ -37,9 +36,11 @@ struct evp_method_data_st {
     unsigned int flag_construct_error_occurred : 1;
 
     void *(*method_from_algorithm)(int name_id, const OSSL_ALGORITHM *,
-        OSSL_PROVIDER *, int);
+        OSSL_PROVIDER *);
     int (*refcnt_up_method)(void *method);
     void (*destruct_method)(void *method);
+    void *(*dup_method)(void *method);
+    void (*free_frozen_method)(void *method);
 };
 
 /*
@@ -124,6 +125,37 @@ static uint32_t evp_method_id(int name_id, unsigned int operation_id)
         | (operation_id & METHOD_ID_OPERATION_MASK));
 }
 
+/*
+ * Reverse of evp_method_id().
+ *
+ * Returns 1 on success and fills in |*name_id| and |*operation_id|.
+ * Returns 0 on invalid input.
+ */
+int evp_method_id2name_id_op_id(uint32_t meth_id, int *name_id,
+    unsigned int *operation_id)
+{
+    int n;
+    unsigned int op;
+
+    /* Top bit must be zero (see evp_method_id() comment) */
+    if ((meth_id & 0x80000000u) != 0)
+        return 0;
+
+    op = (unsigned int)(meth_id & METHOD_ID_OPERATION_MASK);
+    n = (int)((meth_id & METHOD_ID_NAME_MASK) >> METHOD_ID_NAME_OFFSET);
+
+    /* Sanity checks to match evp_method_id() requirements */
+    if (op == 0 || op > METHOD_ID_OPERATION_MAX || n > METHOD_ID_NAME_MAX)
+        return 0;
+
+    if (operation_id != NULL)
+        *operation_id = op;
+    if (name_id != NULL)
+        *name_id = n;
+
+    return 1;
+}
+
 static void *get_evp_method_from_store(void *store, const OSSL_PROVIDER **prov,
     void *data)
 {
@@ -201,7 +233,9 @@ static int put_evp_method_in_store(void *store, void *method,
         store, names, methdata->operation_id, meth_id, propdef ? propdef : "");
     return ossl_method_store_add(store, prov, meth_id, propdef, method,
         methdata->refcnt_up_method,
-        methdata->destruct_method);
+        methdata->destruct_method,
+        methdata->dup_method,
+        methdata->free_frozen_method);
 }
 
 /*
@@ -209,7 +243,7 @@ static int put_evp_method_in_store(void *store, void *method,
  * This function is responsible to getting an identity number for it.
  */
 static void *construct_evp_method(const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, void *data, int no_store)
+    OSSL_PROVIDER *prov, void *data)
 {
     /*
      * This function is only called if get_evp_method_from_store() returned
@@ -228,7 +262,7 @@ static void *construct_evp_method(const OSSL_ALGORITHM *algodef,
     if (name_id == 0)
         return NULL;
 
-    method = methdata->method_from_algorithm(name_id, algodef, prov, no_store);
+    method = methdata->method_from_algorithm(name_id, algodef, prov);
 
     /*
      * Flag to indicate that there was actual construction errors.  This
@@ -248,15 +282,49 @@ static void destruct_evp_method(void *method, void *data)
     methdata->destruct_method(method);
 }
 
+static int
+inner_evp_generic_fetch_all(struct evp_method_data_st *methdata,
+    OSSL_PROVIDER *prov)
+{
+    OSSL_METHOD_STORE *store = get_evp_method_store(methdata->libctx);
+
+    if (store == NULL) {
+        ERR_raise(ERR_LIB_EVP, ERR_R_PASSED_INVALID_ARGUMENT);
+        return 0;
+    }
+
+    OSSL_METHOD_CONSTRUCT_METHOD mcm = {
+        get_tmp_evp_method_store,
+        reserve_evp_method_store,
+        unreserve_evp_method_store,
+        NULL,
+        put_evp_method_in_store,
+        construct_evp_method,
+        destruct_evp_method
+    };
+
+    ossl_method_construct(methdata->libctx, methdata->operation_id,
+        &prov, 0 /* !force_cache */,
+        &mcm, methdata);
+    if (methdata->flag_construct_error_occurred != 0) {
+        ERR_raise(ERR_LIB_EVP, ERR_R_INTERNAL_ERROR);
+        return 0;
+    }
+
+    return 1;
+}
+
 static void *
 inner_evp_generic_fetch(struct evp_method_data_st *methdata,
     OSSL_PROVIDER *prov, int operation_id,
     const char *name, ossl_unused const char *properties,
     void *(*new_method)(int name_id,
         const OSSL_ALGORITHM *algodef,
-        OSSL_PROVIDER *prov, int no_store),
+        OSSL_PROVIDER *prov),
     int (*up_ref_method)(void *),
-    void (*free_method)(void *))
+    void (*free_method)(void *),
+    void *(*dup_method)(void *),
+    void (*dup_free_method)(void *))
 {
     OSSL_METHOD_STORE *store = get_evp_method_store(methdata->libctx);
     OSSL_NAMEMAP *namemap = ossl_namemap_stored(methdata->libctx);
@@ -289,8 +357,17 @@ inner_evp_generic_fetch(struct evp_method_data_st *methdata,
         return NULL;
     }
 
+    if (ossl_method_store_is_frozen(store)) {
+        const char *store_propq = ossl_method_store_frozen_propq(store);
+
+        if (*propq == '\0' || strcmp(store_propq, propq) == 0) {
+            ossl_frozen_method_store_cache_get(store, name, propq, operation_id, &method);
+            return method;
+        }
+    }
+
     /* If we haven't received a name id yet, try to get one for the name */
-    name_id = ossl_namemap_name2num(namemap, name);
+    name_id = name != NULL ? ossl_namemap_name2num(namemap, name) : 0;
 
     /*
      * If we have a name id, calculate a method id with evp_method_id().
@@ -330,6 +407,8 @@ inner_evp_generic_fetch(struct evp_method_data_st *methdata,
         methdata->method_from_algorithm = new_method;
         methdata->refcnt_up_method = up_ref_method;
         methdata->destruct_method = free_method;
+        methdata->free_frozen_method = dup_free_method;
+        methdata->dup_method = dup_method;
         methdata->flag_construct_error_occurred = 0;
         if ((method = ossl_method_construct(methdata->libctx, operation_id,
                  &prov, 0 /* !force_cache */,
@@ -351,83 +430,17 @@ inner_evp_generic_fetch(struct evp_method_data_st *methdata,
                 name_id = ossl_namemap_name2num(namemap, name);
             if (name_id == 0) {
                 ERR_raise_data(ERR_LIB_EVP, ERR_R_FETCH_FAILED,
-                    "Algorithm %s cannot be found", name != NULL ? name : "");
-#ifdef OPENSSL_NO_CACHED_FETCH
+                    "Algorithm %s cannot be found", name);
                 free_method(method);
-#endif
                 method = NULL;
             } else {
                 meth_id = evp_method_id(name_id, operation_id);
-                /*
-                 * do not insert method to method store cache when provider
-                 * did ask for not caching it. methods which are not to be
-                 * cached end up in ->tmp_store when provider asks not
-                 * to cache the result (see ossl_method_construct_reserve_store())
-                 */
-                if (meth_id != 0 && methdata->tmp_store == NULL) {
+                if (meth_id != 0)
                     ossl_method_store_cache_set(store, prov, meth_id, propq,
-                        method, up_ref_method, free_method);
-                } else {
-#ifndef OPENSSL_NO_CACHED_FETCH
-                    /*
-                     * There is a corner case we need to handle here.  IF:
-                     * 1) we are fetching an algorithm and plan to return it to the caller
-                     * 2) The provider we fetched from requested no_cache
-                     * Then we are in a situation in which this method that was constructed
-                     * only lives in the tmp_store, and has a reference count of 1.
-                     * On return from this function, that tmp_store is going to be deallocated,
-                     * Which will drop the methods ref count to 0 and free it, after which the
-                     * method will be returned to the called, as an already freed object.
-                     *
-                     * That's bad.  We need to grab an extra ref count on the method before returning
-                     * so that the requestor via EVP_*_fetch has ownership.
-                     *
-                     * BUT we only want to do this in the event that the algorithm is uncached.
-                     * Unfortunately, we don't know that here, because it was the provider that
-                     * made that request.  However, each algorithm type does store that information
-                     * so we have a path forward.  Based on the operation id, call the appropriate
-                     * up_ref method.  That implementation knows how to query its algorithm type and
-                     * decide if a reference needs to be taken here
-                     */
-                    switch (operation_id) {
-                    case OSSL_OP_DIGEST:
-                        EVP_MD_up_ref((EVP_MD *)method);
-                        break;
-                    case OSSL_OP_CIPHER:
-                        EVP_CIPHER_up_ref((EVP_CIPHER *)method);
-                        break;
-                    case OSSL_OP_MAC:
-                        EVP_MAC_up_ref((EVP_MAC *)method);
-                        break;
-                    case OSSL_OP_KDF:
-                        EVP_KDF_up_ref((EVP_KDF *)method);
-                        break;
-                    case OSSL_OP_RAND:
-                        EVP_RAND_up_ref((EVP_RAND *)method);
-                        break;
-                    case OSSL_OP_KEYMGMT:
-                        EVP_KEYMGMT_up_ref((EVP_KEYMGMT *)method);
-                        break;
-                    case OSSL_OP_KEYEXCH:
-                        EVP_KEYEXCH_up_ref((EVP_KEYEXCH *)method);
-                        break;
-                    case OSSL_OP_SIGNATURE:
-                        EVP_SIGNATURE_up_ref((EVP_SIGNATURE *)method);
-                        break;
-                    case OSSL_OP_ASYM_CIPHER:
-                        EVP_ASYM_CIPHER_up_ref((EVP_ASYM_CIPHER *)method);
-                        break;
-                    case OSSL_OP_KEM:
-                        EVP_KEM_up_ref((EVP_KEM *)method);
-                        break;
-                    case OSSL_OP_SKEYMGMT:
-                        EVP_SKEYMGMT_up_ref((EVP_SKEYMGMT *)method);
-                        break;
-                    default:
-                        break;
-                    }
-#endif
-                }
+                        method,
+                        up_ref_method,
+                        free_method,
+                        dup_method, dup_free_method);
             }
         }
 
@@ -462,9 +475,11 @@ void *evp_generic_fetch(OSSL_LIB_CTX *libctx, int operation_id,
     const char *name, const char *properties,
     void *(*new_method)(int name_id,
         const OSSL_ALGORITHM *algodef,
-        OSSL_PROVIDER *prov, int no_store),
+        OSSL_PROVIDER *prov),
     int (*up_ref_method)(void *),
-    void (*free_method)(void *))
+    void (*free_method)(void *),
+    void *(*dup_method)(void *),
+    void (*dup_free_method)(void *))
 {
     struct evp_method_data_st methdata;
     void *method;
@@ -473,11 +488,41 @@ void *evp_generic_fetch(OSSL_LIB_CTX *libctx, int operation_id,
     methdata.tmp_store = NULL;
     method = inner_evp_generic_fetch(&methdata, NULL, operation_id,
         name, properties,
-        new_method, up_ref_method, free_method);
+        new_method,
+        up_ref_method,
+        free_method,
+        dup_method,
+        dup_free_method);
     dealloc_tmp_evp_method_store(methdata.tmp_store);
     return method;
 }
 
+int evp_generic_fetch_all(OSSL_LIB_CTX *libctx, int operation_id,
+    void *(*new_method)(int name_id,
+        const OSSL_ALGORITHM *algodef,
+        OSSL_PROVIDER *prov),
+    int (*up_ref_method)(void *),
+    void (*free_method)(void *),
+    void *(*dup_method)(void *),
+    void (*dup_free_method)(void *))
+{
+    int ret;
+    struct evp_method_data_st methdata = {
+        .libctx = libctx,
+        .name_id = -1,
+        .method_from_algorithm = new_method,
+        .refcnt_up_method = up_ref_method,
+        .destruct_method = free_method,
+        .dup_method = dup_method,
+        .free_frozen_method = dup_free_method,
+        .operation_id = operation_id,
+    };
+
+    ret = inner_evp_generic_fetch_all(&methdata, NULL);
+    dealloc_tmp_evp_method_store(methdata.tmp_store);
+    return ret;
+}
+
 /*
  * evp_generic_fetch_from_prov() is special, and only returns methods from
  * the given provider.
@@ -488,9 +533,11 @@ void *evp_generic_fetch_from_prov(OSSL_PROVIDER *prov, int operation_id,
     const char *name, const char *properties,
     void *(*new_method)(int name_id,
         const OSSL_ALGORITHM *algodef,
-        OSSL_PROVIDER *prov, int no_store),
+        OSSL_PROVIDER *prov),
     int (*up_ref_method)(void *),
-    void (*free_method)(void *))
+    void (*free_method)(void *),
+    void *(*dup_method)(void *),
+    void (*dup_free_method)(void *))
 {
     struct evp_method_data_st methdata;
     void *method;
@@ -499,7 +546,11 @@ void *evp_generic_fetch_from_prov(OSSL_PROVIDER *prov, int operation_id,
     methdata.tmp_store = NULL;
     method = inner_evp_generic_fetch(&methdata, prov, operation_id,
         name, properties,
-        new_method, up_ref_method, free_method);
+        new_method,
+        up_ref_method,
+        free_method,
+        dup_method,
+        dup_free_method);
     dealloc_tmp_evp_method_store(methdata.tmp_store);
     return method;
 }
@@ -702,7 +753,7 @@ void evp_generic_do_all(OSSL_LIB_CTX *libctx, int operation_id,
     void *user_arg,
     void *(*new_method)(int name_id,
         const OSSL_ALGORITHM *algodef,
-        OSSL_PROVIDER *prov, int no_store),
+        OSSL_PROVIDER *prov),
     int (*up_ref_method)(void *),
     void (*free_method)(void *))
 {
@@ -712,7 +763,7 @@ void evp_generic_do_all(OSSL_LIB_CTX *libctx, int operation_id,
     methdata.libctx = libctx;
     methdata.tmp_store = NULL;
     (void)inner_evp_generic_fetch(&methdata, NULL, operation_id, NULL, NULL,
-        new_method, up_ref_method, free_method);
+        new_method, up_ref_method, free_method, NULL, NULL);
 
     data.operation_id = operation_id;
     data.user_fn = user_fn;
diff --git a/crypto/evp/evp_lib.c b/crypto/evp/evp_lib.c
index 644772bf37..f6c3c92b7f 100644
--- a/crypto/evp/evp_lib.c
+++ b/crypto/evp/evp_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -89,7 +89,12 @@ int evp_cipher_param_to_asn1_ex(EVP_CIPHER_CTX *c, ASN1_TYPE *type,
 
     cipher = c->cipher;
     /*
-     * For any implementation, we check the flag
+     * For legacy implementations, we detect custom AlgorithmIdentifier
+     * parameter handling by checking if the function pointer
+     * cipher->set_asn1_parameters is set.  We know that this pointer
+     * is NULL for provided implementations.
+     *
+     * Otherwise, for any implementation, we check the flag
      * EVP_CIPH_FLAG_CUSTOM_ASN1.  If it isn't set, we apply
      * default AI parameter extraction.
      *
@@ -99,7 +104,9 @@ int evp_cipher_param_to_asn1_ex(EVP_CIPHER_CTX *c, ASN1_TYPE *type,
      *
      * If none of the above applies, this operation is unsupported.
      */
-    if ((EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_CUSTOM_ASN1) == 0) {
+    if (cipher->set_asn1_parameters != NULL) {
+        ret = cipher->set_asn1_parameters(c, type);
+    } else if ((EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_CUSTOM_ASN1) == 0) {
         switch (EVP_CIPHER_get_mode(cipher)) {
         case EVP_CIPH_WRAP_MODE:
             if (EVP_CIPHER_is_a(cipher, SN_id_smime_alg_CMS3DESwrap))
@@ -153,7 +160,12 @@ int evp_cipher_asn1_to_param_ex(EVP_CIPHER_CTX *c, ASN1_TYPE *type,
 
     cipher = c->cipher;
     /*
-     * For any implementation, we check the flag
+     * For legacy implementations, we detect custom AlgorithmIdentifier
+     * parameter handling by checking if there the function pointer
+     * cipher->get_asn1_parameters is set.  We know that this pointer
+     * is NULL for provided implementations.
+     *
+     * Otherwise, for any implementation, we check the flag
      * EVP_CIPH_FLAG_CUSTOM_ASN1.  If it isn't set, we apply
      * default AI parameter creation.
      *
@@ -163,7 +175,9 @@ int evp_cipher_asn1_to_param_ex(EVP_CIPHER_CTX *c, ASN1_TYPE *type,
      *
      * If none of the above applies, this operation is unsupported.
      */
-    if ((EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_CUSTOM_ASN1) == 0) {
+    if (cipher->get_asn1_parameters != NULL) {
+        ret = cipher->get_asn1_parameters(c, type);
+    } else if ((EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_CUSTOM_ASN1) == 0) {
         switch (EVP_CIPHER_get_mode(cipher)) {
         case EVP_CIPH_WRAP_MODE:
             ret = 1;
@@ -214,9 +228,10 @@ int evp_cipher_get_asn1_aead_params(EVP_CIPHER_CTX *c, ASN1_TYPE *type,
     if (type == NULL || asn1_params == NULL)
         return 0;
 
-    i = ossl_asn1_type_get_octetstring_int(type, &tl, iv, EVP_MAX_IV_LENGTH);
-    if (i <= 0 || i > EVP_MAX_IV_LENGTH)
+    i = ossl_asn1_type_get_octetstring_int(type, &tl, NULL, EVP_MAX_IV_LENGTH);
+    if (i <= 0)
         return -1;
+    ossl_asn1_type_get_octetstring_int(type, &tl, iv, i);
 
     memcpy(asn1_params->iv, iv, i);
     asn1_params->iv_len = i;
@@ -283,7 +298,7 @@ int EVP_CIPHER_get_type(const EVP_CIPHER *cipher)
     case NID_des_ede3_cfb8:
     case NID_des_ede3_cfb1:
 
-        return NID_des_ede3_cfb64;
+        return NID_des_cfb64;
 
     default:
 #ifdef FIPS_MODULE
@@ -310,7 +325,6 @@ int evp_cipher_cache_constants(EVP_CIPHER *cipher)
     size_t blksz = 0;
     size_t keylen = 0;
     unsigned int mode = 0;
-    int no_store = cipher->flags & EVP_CIPH_FLAG_NO_STORE;
     OSSL_PARAM params[11];
 
     params[0] = OSSL_PARAM_construct_size_t(OSSL_CIPHER_PARAM_BLOCK_SIZE, &blksz);
@@ -333,7 +347,7 @@ int evp_cipher_cache_constants(EVP_CIPHER *cipher)
         cipher->block_size = (int)blksz;
         cipher->iv_len = (int)ivlen;
         cipher->key_len = (int)keylen;
-        cipher->flags = mode | no_store;
+        cipher->flags = mode;
         if (aead)
             cipher->flags |= EVP_CIPH_FLAG_AEAD_CIPHER;
         if (custom_iv)
@@ -367,44 +381,48 @@ int EVP_CIPHER_CTX_get_block_size(const EVP_CIPHER_CTX *ctx)
 
 int EVP_CIPHER_impl_ctx_size(const EVP_CIPHER *e)
 {
-    return 0;
+    return e->ctx_size;
 }
 
 int EVP_Cipher(EVP_CIPHER_CTX *ctx, unsigned char *out,
     const unsigned char *in, unsigned int inl)
 {
-    if (ctx == NULL || ctx->cipher == NULL || ctx->cipher->prov == NULL)
+    if (ctx == NULL || ctx->cipher == NULL)
         return 0;
 
-    /*
-     * If the provided implementation has a ccipher function, we use it,
-     * and translate its return value like this: 0 => -1, 1 => outlen
-     *
-     * Otherwise, we call the cupdate function if in != NULL, or cfinal
-     * if in == NULL.  Regardless of which, we return what we got.
-     */
-    int ret = -1;
-    size_t outl = 0;
-    size_t blocksize = EVP_CIPHER_CTX_get_block_size(ctx);
+    if (ctx->cipher->prov != NULL) {
+        /*
+         * If the provided implementation has a ccipher function, we use it,
+         * and translate its return value like this: 0 => -1, 1 => outlen
+         *
+         * Otherwise, we call the cupdate function if in != NULL, or cfinal
+         * if in == NULL.  Regardless of which, we return what we got.
+         */
+        int ret = -1;
+        size_t outl = 0;
+        size_t blocksize = EVP_CIPHER_CTX_get_block_size(ctx);
 
-    if (blocksize == 0)
-        return 0;
+        if (blocksize == 0)
+            return 0;
 
-    if (ctx->cipher->ccipher != NULL)
-        ret = ctx->cipher->ccipher(ctx->algctx, out, &outl,
-                  inl + (blocksize == 1 ? 0 : blocksize),
-                  in, (size_t)inl)
-            ? (int)outl
-            : -1;
-    else if (in != NULL)
-        ret = ctx->cipher->cupdate(ctx->algctx, out, &outl,
-            inl + (blocksize == 1 ? 0 : blocksize),
-            in, (size_t)inl);
-    else
-        ret = ctx->cipher->cfinal(ctx->algctx, out, &outl,
-            blocksize == 1 ? 0 : blocksize);
+        if (ctx->cipher->ccipher != NULL)
+            ret = ctx->cipher->ccipher(ctx->algctx, out, &outl,
+                      inl + (blocksize == 1 ? 0 : blocksize),
+                      in, (size_t)inl)
+                ? (int)outl
+                : -1;
+        else if (in != NULL)
+            ret = ctx->cipher->cupdate(ctx->algctx, out, &outl,
+                inl + (blocksize == 1 ? 0 : blocksize),
+                in, (size_t)inl);
+        else
+            ret = ctx->cipher->cfinal(ctx->algctx, out, &outl,
+                blocksize == 1 ? 0 : blocksize);
 
-    return ret;
+        return ret;
+    }
+
+    return ctx->cipher->do_cipher(ctx, out, in, inl);
 }
 
 #ifndef OPENSSL_NO_DEPRECATED_3_0
@@ -591,7 +609,6 @@ unsigned char *EVP_CIPHER_CTX_buf_noconst(EVP_CIPHER_CTX *ctx)
     return ctx->buf;
 }
 
-#ifndef OPENSSL_NO_DEPRECATED_4_1
 int EVP_CIPHER_CTX_get_num(const EVP_CIPHER_CTX *ctx)
 {
     int ok;
@@ -617,7 +634,6 @@ int EVP_CIPHER_CTX_set_num(EVP_CIPHER_CTX *ctx, int num)
         ctx->num = (int)n;
     return ok != 0;
 }
-#endif /* OPENSSL_NO_DEPRECATED_4_1 */
 
 int EVP_CIPHER_get_key_length(const EVP_CIPHER *cipher)
 {
@@ -810,6 +826,182 @@ unsigned long EVP_MD_get_flags(const EVP_MD *md)
     return md->flags;
 }
 
+EVP_MD *EVP_MD_meth_new(int md_type, int pkey_type)
+{
+    EVP_MD *md = evp_md_new();
+
+    if (md != NULL) {
+        md->type = md_type;
+        md->pkey_type = pkey_type;
+        md->origin = EVP_ORIG_METH;
+    }
+    return md;
+}
+
+EVP_MD *EVP_MD_meth_dup(const EVP_MD *md)
+{
+    EVP_MD *to = NULL;
+
+    /*
+     * Non-legacy EVP_MDs can't be duplicated like this.
+     * Use EVP_MD_up_ref() instead.
+     */
+    if (md->prov != NULL)
+        return NULL;
+
+    if ((to = EVP_MD_meth_new(md->type, md->pkey_type)) != NULL) {
+        CRYPTO_REF_COUNT refcnt = to->refcnt;
+
+        memcpy(to, md, sizeof(*to));
+        to->refcnt = refcnt;
+        to->origin = EVP_ORIG_METH;
+    }
+    return to;
+}
+
+void evp_md_free_int(EVP_MD *md)
+{
+    OPENSSL_free(md->type_name);
+    ossl_provider_free(md->prov);
+    CRYPTO_FREE_REF(&md->refcnt);
+    OPENSSL_free(md);
+}
+
+void EVP_MD_meth_free(EVP_MD *md)
+{
+    if (md == NULL || md->origin != EVP_ORIG_METH)
+        return;
+
+    evp_md_free_int(md);
+}
+
+int EVP_MD_meth_set_input_blocksize(EVP_MD *md, int blocksize)
+{
+    if (md->block_size != 0)
+        return 0;
+
+    md->block_size = blocksize;
+    return 1;
+}
+int EVP_MD_meth_set_result_size(EVP_MD *md, int resultsize)
+{
+    if (md->md_size != 0)
+        return 0;
+
+    md->md_size = resultsize;
+    return 1;
+}
+int EVP_MD_meth_set_app_datasize(EVP_MD *md, int datasize)
+{
+    if (md->ctx_size != 0)
+        return 0;
+
+    md->ctx_size = datasize;
+    return 1;
+}
+int EVP_MD_meth_set_flags(EVP_MD *md, unsigned long flags)
+{
+    if (md->flags != 0)
+        return 0;
+
+    md->flags = flags;
+    return 1;
+}
+int EVP_MD_meth_set_init(EVP_MD *md, int (*init)(EVP_MD_CTX *ctx))
+{
+    if (md->init != NULL)
+        return 0;
+
+    md->init = init;
+    return 1;
+}
+int EVP_MD_meth_set_update(EVP_MD *md, int (*update)(EVP_MD_CTX *ctx, const void *data, size_t count))
+{
+    if (md->update != NULL)
+        return 0;
+
+    md->update = update;
+    return 1;
+}
+int EVP_MD_meth_set_final(EVP_MD *md, int (*final)(EVP_MD_CTX *ctx, unsigned char *md))
+{
+    if (md->final != NULL)
+        return 0;
+
+    md->final = final;
+    return 1;
+}
+int EVP_MD_meth_set_copy(EVP_MD *md, int (*copy)(EVP_MD_CTX *to, const EVP_MD_CTX *from))
+{
+    if (md->copy != NULL)
+        return 0;
+
+    md->copy = copy;
+    return 1;
+}
+int EVP_MD_meth_set_cleanup(EVP_MD *md, int (*cleanup)(EVP_MD_CTX *ctx))
+{
+    if (md->cleanup != NULL)
+        return 0;
+
+    md->cleanup = cleanup;
+    return 1;
+}
+int EVP_MD_meth_set_ctrl(EVP_MD *md, int (*ctrl)(EVP_MD_CTX *ctx, int cmd, int p1, void *p2))
+{
+    if (md->md_ctrl != NULL)
+        return 0;
+
+    md->md_ctrl = ctrl;
+    return 1;
+}
+
+int EVP_MD_meth_get_input_blocksize(const EVP_MD *md)
+{
+    return md->block_size;
+}
+int EVP_MD_meth_get_result_size(const EVP_MD *md)
+{
+    return md->md_size;
+}
+int EVP_MD_meth_get_app_datasize(const EVP_MD *md)
+{
+    return md->ctx_size;
+}
+unsigned long EVP_MD_meth_get_flags(const EVP_MD *md)
+{
+    return md->flags;
+}
+int (*EVP_MD_meth_get_init(const EVP_MD *md))(EVP_MD_CTX *ctx)
+{
+    return md->init;
+}
+int (*EVP_MD_meth_get_update(const EVP_MD *md))(EVP_MD_CTX *ctx,
+    const void *data,
+    size_t count)
+{
+    return md->update;
+}
+int (*EVP_MD_meth_get_final(const EVP_MD *md))(EVP_MD_CTX *ctx,
+    unsigned char *md)
+{
+    return md->final;
+}
+int (*EVP_MD_meth_get_copy(const EVP_MD *md))(EVP_MD_CTX *to,
+    const EVP_MD_CTX *from)
+{
+    return md->copy;
+}
+int (*EVP_MD_meth_get_cleanup(const EVP_MD *md))(EVP_MD_CTX *ctx)
+{
+    return md->cleanup;
+}
+int (*EVP_MD_meth_get_ctrl(const EVP_MD *md))(EVP_MD_CTX *ctx, int cmd,
+    int p1, void *p2)
+{
+    return md->md_ctrl;
+}
+
 #ifndef OPENSSL_NO_DEPRECATED_3_0
 const EVP_MD *EVP_MD_CTX_md(const EVP_MD_CTX *ctx)
 {
@@ -893,12 +1085,23 @@ void EVP_MD_CTX_set_pkey_ctx(EVP_MD_CTX *ctx, EVP_PKEY_CTX *pctx)
 }
 #endif /* !defined(FIPS_MODULE) */
 
-#ifndef OPENSSL_NO_DEPRECATED_4_0
 void *EVP_MD_CTX_get0_md_data(const EVP_MD_CTX *ctx)
 {
-    return NULL;
+    return ctx->md_data;
+}
+
+int (*EVP_MD_CTX_update_fn(EVP_MD_CTX *ctx))(EVP_MD_CTX *ctx,
+    const void *data, size_t count)
+{
+    return ctx->update;
+}
+
+void EVP_MD_CTX_set_update_fn(EVP_MD_CTX *ctx,
+    int (*update)(EVP_MD_CTX *ctx,
+        const void *data, size_t count))
+{
+    ctx->update = update;
 }
-#endif
 
 void EVP_MD_CTX_set_flags(EVP_MD_CTX *ctx, int flags)
 {
@@ -1030,17 +1233,12 @@ EVP_PKEY *EVP_PKEY_Q_keygen(OSSL_LIB_CTX *libctx, const char *propq,
         params[0] = OSSL_PARAM_construct_size_t(OSSL_PKEY_PARAM_RSA_BITS, &bits);
     } else if (OPENSSL_strcasecmp(type, "EC") == 0) {
         name = va_arg(args, char *);
-        if (name == NULL) {
-            ERR_raise(ERR_LIB_EVP, ERR_R_PASSED_NULL_PARAMETER);
-            goto end;
-        }
         params[0] = OSSL_PARAM_construct_utf8_string(OSSL_PKEY_PARAM_GROUP_NAME,
             name, 0);
     }
 
     ret = evp_pkey_keygen(libctx, type, propq, params);
 
-end:
     va_end(args);
     return ret;
 }
diff --git a/crypto/evp/evp_local.h b/crypto/evp/evp_local.h
index 1f41cfe644..2f002a2412 100644
--- a/crypto/evp/evp_local.h
+++ b/crypto/evp/evp_local.h
@@ -1,5 +1,5 @@
 /*
- * Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,31 +7,20 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_EVP_EVP_LOCAL_H)
-#define OSSL_LIBCRYPTO_EVP_EVP_LOCAL_H
-
 #include 
-#include 
-
-#include 
-
 #include "internal/refcount.h"
 
 #define EVP_CTRL_RET_UNSUPPORTED -1
 
-/*
- * Length of the BASE64-encoded lines when encoding.
- * This needs to be divisible by 3 to keep the AVX2 optimized code path.
- */
-#define EVP_ENCODE_B64_LENGTH 48
-
 struct evp_md_ctx_st {
     const EVP_MD *reqdigest; /* The original requested digest */
     const EVP_MD *digest;
     unsigned long flags;
-
+    void *md_data;
     /* Public key context for sign/verify */
     EVP_PKEY_CTX *pctx;
+    /* Update function: usually copied from EVP_MD */
+    int (*update)(EVP_MD_CTX *ctx, const void *data, size_t count);
 
     /*
      * Opaque ctx returned from a providers digest algorithm implementation
@@ -102,17 +91,16 @@ struct evp_keymgmt_st {
     int id; /* libcrypto internal */
 
     int name_id;
-    int no_store;
     /* NID for the legacy alg if there is one */
     int legacy_alg;
     char *type_name;
     const char *description;
     OSSL_PROVIDER *prov;
     CRYPTO_REF_COUNT refcnt;
+    int origin;
 
     /* Constructor(s), destructor, information */
     OSSL_FUNC_keymgmt_new_fn *new;
-    OSSL_FUNC_keymgmt_new_ex_fn *new_ex;
     OSSL_FUNC_keymgmt_free_fn *free;
     OSSL_FUNC_keymgmt_get_params_fn *get_params;
     OSSL_FUNC_keymgmt_gettable_params_fn *gettable_params;
@@ -149,7 +137,7 @@ struct evp_keymgmt_st {
 
 struct evp_keyexch_st {
     int name_id;
-    int no_store;
+    int origin;
     char *type_name;
     const char *description;
     OSSL_PROVIDER *prov;
@@ -170,7 +158,6 @@ struct evp_keyexch_st {
 
 struct evp_signature_st {
     int name_id;
-    int no_store;
     char *type_name;
     const char *description;
     OSSL_PROVIDER *prov;
@@ -212,9 +199,39 @@ struct evp_signature_st {
     OSSL_FUNC_signature_query_key_types_fn *query_key_types;
 } /* EVP_SIGNATURE */;
 
+struct evp_rand_st {
+    OSSL_PROVIDER *prov;
+    int name_id;
+    int origin;
+    char *type_name;
+    const char *description;
+    CRYPTO_REF_COUNT refcnt;
+
+    const OSSL_DISPATCH *dispatch;
+    OSSL_FUNC_rand_newctx_fn *newctx;
+    OSSL_FUNC_rand_freectx_fn *freectx;
+    OSSL_FUNC_rand_instantiate_fn *instantiate;
+    OSSL_FUNC_rand_uninstantiate_fn *uninstantiate;
+    OSSL_FUNC_rand_generate_fn *generate;
+    OSSL_FUNC_rand_reseed_fn *reseed;
+    OSSL_FUNC_rand_nonce_fn *nonce;
+    OSSL_FUNC_rand_enable_locking_fn *enable_locking;
+    OSSL_FUNC_rand_lock_fn *lock;
+    OSSL_FUNC_rand_unlock_fn *unlock;
+    OSSL_FUNC_rand_gettable_params_fn *gettable_params;
+    OSSL_FUNC_rand_gettable_ctx_params_fn *gettable_ctx_params;
+    OSSL_FUNC_rand_settable_ctx_params_fn *settable_ctx_params;
+    OSSL_FUNC_rand_get_params_fn *get_params;
+    OSSL_FUNC_rand_get_ctx_params_fn *get_ctx_params;
+    OSSL_FUNC_rand_set_ctx_params_fn *set_ctx_params;
+    OSSL_FUNC_rand_verify_zeroization_fn *verify_zeroization;
+    OSSL_FUNC_rand_get_seed_fn *get_seed;
+    OSSL_FUNC_rand_clear_seed_fn *clear_seed;
+} /* EVP_RAND */;
+
 struct evp_skeymgmt_st {
     int name_id;
-    int no_store;
+    int origin;
     char *type_name;
     const char *description;
     OSSL_PROVIDER *prov;
@@ -238,7 +255,7 @@ struct evp_skeymgmt_st {
 
 struct evp_asym_cipher_st {
     int name_id;
-    int no_store;
+    int origin;
     char *type_name;
     const char *description;
     OSSL_PROVIDER *prov;
@@ -259,7 +276,7 @@ struct evp_asym_cipher_st {
 
 struct evp_kem_st {
     int name_id;
-    int no_store;
+    int origin;
     char *type_name;
     const char *description;
     OSSL_PROVIDER *prov;
@@ -292,6 +309,12 @@ int PKCS5_v2_PBKDF2_keyivgen_ex(EVP_CIPHER_CTX *ctx, const char *pass,
 struct evp_Encode_Ctx_st {
     /* number saved in a partial encode/decode */
     int num;
+    /*
+     * The length is either the output line length (in input bytes) or the
+     * shortest input line length that is ok.  Once decoding begins, the
+     * length is adjusted up each time a longer line is decoded
+     */
+    int length;
     /* data to encode */
     unsigned char enc_data[80];
     /* number read on current line */
@@ -311,16 +334,28 @@ void *evp_generic_fetch(OSSL_LIB_CTX *ctx, int operation_id,
     const char *name, const char *properties,
     void *(*new_method)(int name_id,
         const OSSL_ALGORITHM *algodef,
-        OSSL_PROVIDER *prov, int no_store),
+        OSSL_PROVIDER *prov),
     int (*up_ref_method)(void *),
-    void (*free_method)(void *));
+    void (*free_method)(void *),
+    void *(*dup_method)(void *),
+    void (*dup_free_method)(void *));
+int evp_generic_fetch_all(OSSL_LIB_CTX *ctx, int operation_id,
+    void *(*new_method)(int name_id,
+        const OSSL_ALGORITHM *algodef,
+        OSSL_PROVIDER *prov),
+    int (*up_ref_method)(void *),
+    void (*free_method)(void *),
+    void *(*dup_method)(void *),
+    void (*dup_free_method)(void *));
 void *evp_generic_fetch_from_prov(OSSL_PROVIDER *prov, int operation_id,
     const char *name, const char *properties,
     void *(*new_method)(int name_id,
         const OSSL_ALGORITHM *algodef,
-        OSSL_PROVIDER *prov, int no_store),
+        OSSL_PROVIDER *prov),
     int (*up_ref_method)(void *),
-    void (*free_method)(void *));
+    void (*free_method)(void *),
+    void *(*dup_method)(void *),
+    void (*dup_free_method)(void *));
 void evp_generic_do_all_prefetched(OSSL_LIB_CTX *libctx, int operation_id,
     void (*user_fn)(void *method, void *arg),
     void *user_arg);
@@ -329,7 +364,7 @@ void evp_generic_do_all(OSSL_LIB_CTX *libctx, int operation_id,
     void *user_arg,
     void *(*new_method)(int name_id,
         const OSSL_ALGORITHM *algodef,
-        OSSL_PROVIDER *prov, int no_store),
+        OSSL_PROVIDER *prov),
     int (*up_ref_method)(void *),
     void (*free_method)(void *));
 
@@ -393,8 +428,27 @@ int evp_do_md_ctx_setparams(const EVP_MD *md, void *provctx,
 
 OSSL_PARAM *evp_pkey_to_param(EVP_PKEY *pkey, size_t *sz);
 
+#define M_check_autoarg(ctx, arg, arglen, err)                               \
+    if (ctx->pmeth->flags & EVP_PKEY_FLAG_AUTOARGLEN) {                      \
+        size_t pksize = (size_t)EVP_PKEY_get_size(ctx->pkey);                \
+                                                                             \
+        if (pksize == 0) {                                                   \
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_KEY); /*ckerr_ignore*/      \
+            return 0;                                                        \
+        }                                                                    \
+        if (arg == NULL) {                                                   \
+            *arglen = pksize;                                                \
+            return 1;                                                        \
+        }                                                                    \
+        if (*arglen < pksize) {                                              \
+            ERR_raise(ERR_LIB_EVP, EVP_R_BUFFER_TOO_SMALL); /*ckerr_ignore*/ \
+            return 0;                                                        \
+        }                                                                    \
+    }
+
 void evp_pkey_ctx_free_old_ops(EVP_PKEY_CTX *ctx);
 void evp_cipher_free_int(EVP_CIPHER *md);
+void evp_md_free_int(EVP_MD *md);
 
 /* OSSL_PROVIDER * is only used to get the library context */
 int evp_is_a(OSSL_PROVIDER *prov, int number,
@@ -403,28 +457,15 @@ int evp_names_do_all(OSSL_PROVIDER *prov, int number,
     void (*fn)(const char *name, void *data),
     void *data);
 int evp_cipher_cache_constants(EVP_CIPHER *cipher);
-
-#define EVP_DO_ALL_PROVIDED_THUNK(type)                                                       \
-    struct type##_do_all_provided_thunk {                                                     \
-        void (*fn)(type * method, void *arg);                                                 \
-        void *arg;                                                                            \
-    };                                                                                        \
-    static ossl_inline ossl_unused void type##_do_all_provided_thunk(void *method, void *arg) \
-    {                                                                                         \
-        struct type##_do_all_provided_thunk *t = arg;                                         \
-        (*t->fn)((type *)method, t->arg);                                                     \
-    }
-
-EVP_DO_ALL_PROVIDED_THUNK(EVP_ASYM_CIPHER)
-EVP_DO_ALL_PROVIDED_THUNK(EVP_MD)
-EVP_DO_ALL_PROVIDED_THUNK(EVP_CIPHER)
-EVP_DO_ALL_PROVIDED_THUNK(EVP_RAND)
-EVP_DO_ALL_PROVIDED_THUNK(EVP_KEYEXCH)
-EVP_DO_ALL_PROVIDED_THUNK(EVP_KDF)
-EVP_DO_ALL_PROVIDED_THUNK(EVP_KEM)
-EVP_DO_ALL_PROVIDED_THUNK(EVP_KEYMGMT)
-EVP_DO_ALL_PROVIDED_THUNK(EVP_MAC)
-EVP_DO_ALL_PROVIDED_THUNK(EVP_SIGNATURE)
-EVP_DO_ALL_PROVIDED_THUNK(EVP_SKEYMGMT)
-
-#endif /* !defined(OSSL_LIBCRYPTO_EVP_EVP_LOCAL_H) */
+int evp_method_id2name_id_op_id(uint32_t meth_id, int *name_id,
+    unsigned int *operation_id);
+int evp_md_fetch_all(OSSL_LIB_CTX *ctx);
+int evp_cipher_fetch_all(OSSL_LIB_CTX *ctx);
+int evp_kdf_fetch_all(OSSL_LIB_CTX *ctx);
+int evp_rand_fetch_all(OSSL_LIB_CTX *ctx);
+int evp_mac_fetch_all(OSSL_LIB_CTX *ctx);
+int evp_keymgmt_fetch_all(OSSL_LIB_CTX *ctx);
+int evp_kem_fetch_all(OSSL_LIB_CTX *ctx);
+int evp_asym_cipher_fetch_all(OSSL_LIB_CTX *ctx);
+int evp_keyexch_fetch_all(OSSL_LIB_CTX *ctx);
+int evp_skeymgmt_fetch_all(OSSL_LIB_CTX *ctx);
diff --git a/crypto/evp/evp_pbe.c b/crypto/evp/evp_pbe.c
index 0b0554358c..27e8925377 100644
--- a/crypto/evp/evp_pbe.c
+++ b/crypto/evp/evp_pbe.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -97,8 +97,10 @@ int EVP_PBE_CipherInit_ex(ASN1_OBJECT *pbe_obj, const char *pass, int passlen,
     ASN1_TYPE *param, EVP_CIPHER_CTX *ctx, int en_de,
     OSSL_LIB_CTX *libctx, const char *propq)
 {
-    EVP_CIPHER *cipher = NULL;
-    EVP_MD *md = NULL;
+    const EVP_CIPHER *cipher = NULL;
+    EVP_CIPHER *cipher_fetch = NULL;
+    const EVP_MD *md = NULL;
+    EVP_MD *md_fetch = NULL;
     int ret = 0, cipher_nid, md_nid;
     EVP_PBE_KEYGEN_EX *keygen_ex;
     EVP_PBE_KEYGEN *keygen;
@@ -122,21 +124,33 @@ int EVP_PBE_CipherInit_ex(ASN1_OBJECT *pbe_obj, const char *pass, int passlen,
         passlen = (int)strlen(pass);
 
     if (cipher_nid != -1) {
-        cipher = EVP_CIPHER_fetch(libctx, OBJ_nid2sn(cipher_nid), propq);
+        (void)ERR_set_mark();
+        cipher = cipher_fetch = EVP_CIPHER_fetch(libctx, OBJ_nid2sn(cipher_nid), propq);
+        /* Fallback to legacy method */
+        if (cipher == NULL)
+            cipher = EVP_get_cipherbynid(cipher_nid);
         if (cipher == NULL) {
+            (void)ERR_clear_last_mark();
             ERR_raise_data(ERR_LIB_EVP, EVP_R_UNKNOWN_CIPHER,
                 OBJ_nid2sn(cipher_nid));
             goto err;
         }
+        (void)ERR_pop_to_mark();
     }
 
     if (md_nid != -1) {
-        md = EVP_MD_fetch(libctx, OBJ_nid2sn(md_nid), propq);
+        (void)ERR_set_mark();
+        md = md_fetch = EVP_MD_fetch(libctx, OBJ_nid2sn(md_nid), propq);
+        /* Fallback to legacy method */
+        if (md == NULL)
+            md = EVP_get_digestbynid(md_nid);
 
         if (md == NULL) {
+            (void)ERR_clear_last_mark();
             ERR_raise(ERR_LIB_EVP, EVP_R_UNKNOWN_DIGEST);
             goto err;
         }
+        (void)ERR_pop_to_mark();
     }
 
     /* Try extended keygen with libctx/propq first, fall back to legacy keygen */
@@ -146,8 +160,8 @@ int EVP_PBE_CipherInit_ex(ASN1_OBJECT *pbe_obj, const char *pass, int passlen,
         ret = keygen(ctx, pass, passlen, param, cipher, md, en_de);
 
 err:
-    EVP_CIPHER_free(cipher);
-    EVP_MD_free(md);
+    EVP_CIPHER_free(cipher_fetch);
+    EVP_MD_free(md_fetch);
 
     return ret;
 }
diff --git a/crypto/evp/evp_pkey.c b/crypto/evp/evp_pkey.c
index dbabf84b08..690839cffb 100644
--- a/crypto/evp/evp_pkey.c
+++ b/crypto/evp/evp_pkey.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,6 +7,11 @@
  * https://www.openssl.org/source/license.html
  */
 
+/*
+ * Needed for EVP_PKEY_get0_asn1 and EVP_PKEY_asn1_get0_info
+ */
+#define OPENSSL_SUPPRESS_DEPRECATED
+
 #include 
 #include 
 #include "internal/cryptlib.h"
@@ -254,9 +259,9 @@ const char *EVP_PKEY_get0_type_name(const EVP_PKEY *key)
 
 #ifndef OPENSSL_NO_DEPRECATED_3_6
     /* Otherwise fallback to legacy */
-    ameth = evp_pkey_get0_asn1(key);
+    ameth = EVP_PKEY_get0_asn1(key);
     if (ameth != NULL)
-        evp_pkey_asn1_get0_info(NULL, NULL,
+        EVP_PKEY_asn1_get0_info(NULL, NULL,
             NULL, NULL, &name, ameth);
 #endif
 
diff --git a/crypto/evp/evp_pkey_type.c b/crypto/evp/evp_pkey_type.c
index 7864ccbfe5..7d9f82d72a 100644
--- a/crypto/evp/evp_pkey_type.c
+++ b/crypto/evp/evp_pkey_type.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -65,7 +65,7 @@ int EVP_PKEY_type(int type)
     int ret;
     const EVP_PKEY_ASN1_METHOD *ameth;
 
-    ameth = evp_pkey_asn1_find(type);
+    ameth = EVP_PKEY_asn1_find(NULL, type);
     if (ameth)
         ret = ameth->pkey_id;
     else
diff --git a/crypto/evp/evp_rand.c b/crypto/evp/evp_rand.c
index a0041719b5..4d5036b2a6 100644
--- a/crypto/evp/evp_rand.c
+++ b/crypto/evp/evp_rand.c
@@ -21,42 +21,20 @@
 #include "crypto/evp.h"
 #include "evp_local.h"
 
-struct evp_rand_st {
-    OSSL_PROVIDER *prov;
-    int name_id;
-    int no_store;
-    char *type_name;
-    const char *description;
-    CRYPTO_REF_COUNT refcnt;
-
-    const OSSL_DISPATCH *dispatch;
-    OSSL_FUNC_rand_newctx_fn *newctx;
-    OSSL_FUNC_rand_freectx_fn *freectx;
-    OSSL_FUNC_rand_instantiate_fn *instantiate;
-    OSSL_FUNC_rand_uninstantiate_fn *uninstantiate;
-    OSSL_FUNC_rand_generate_fn *generate;
-    OSSL_FUNC_rand_reseed_fn *reseed;
-    OSSL_FUNC_rand_nonce_fn *nonce;
-    OSSL_FUNC_rand_enable_locking_fn *enable_locking;
-    OSSL_FUNC_rand_lock_fn *lock;
-    OSSL_FUNC_rand_unlock_fn *unlock;
-    OSSL_FUNC_rand_gettable_params_fn *gettable_params;
-    OSSL_FUNC_rand_gettable_ctx_params_fn *gettable_ctx_params;
-    OSSL_FUNC_rand_settable_ctx_params_fn *settable_ctx_params;
-    OSSL_FUNC_rand_get_params_fn *get_params;
-    OSSL_FUNC_rand_get_ctx_params_fn *get_ctx_params;
-    OSSL_FUNC_rand_set_ctx_params_fn *set_ctx_params;
-    OSSL_FUNC_rand_verify_zeroization_fn *verify_zeroization;
-    OSSL_FUNC_rand_get_seed_fn *get_seed;
-    OSSL_FUNC_rand_clear_seed_fn *clear_seed;
-} /* EVP_RAND */;
+static void evp_rand_free_int(EVP_RAND *rand)
+{
+    OPENSSL_free(rand->type_name);
+    ossl_provider_free(rand->prov);
+    CRYPTO_FREE_REF(&rand->refcnt);
+    OPENSSL_free(rand);
+}
 
 static int evp_rand_up_ref(void *vrand)
 {
     EVP_RAND *rand = (EVP_RAND *)vrand;
     int ref = 0;
 
-    if (rand != NULL)
+    if (rand != NULL && rand->origin == EVP_ORIG_DYNAMIC)
         return CRYPTO_UP_REF(&rand->refcnt, &ref);
     return 1;
 }
@@ -66,15 +44,12 @@ static void evp_rand_free(void *vrand)
     EVP_RAND *rand = (EVP_RAND *)vrand;
     int ref = 0;
 
-    if (rand == NULL)
+    if (rand == NULL || rand->origin != EVP_ORIG_DYNAMIC)
         return;
     CRYPTO_DOWN_REF(&rand->refcnt, &ref);
     if (ref > 0)
         return;
-    OPENSSL_free(rand->type_name);
-    ossl_provider_free(rand->prov);
-    CRYPTO_FREE_REF(&rand->refcnt);
-    OPENSSL_free(rand);
+    evp_rand_free_int(rand);
 }
 
 static void *evp_rand_new(void)
@@ -91,6 +66,47 @@ static void *evp_rand_new(void)
     return rand;
 }
 
+static void *evp_rand_dup_frozen(void *vin)
+{
+    EVP_RAND *in = vin;
+    EVP_RAND *out;
+
+    out = OPENSSL_malloc(sizeof(*out));
+    if (out == NULL)
+        return NULL;
+    memcpy(out, in, sizeof(*out));
+    if (!CRYPTO_NEW_REF(&out->refcnt, 1))
+        goto err;
+    out->type_name = OPENSSL_strdup(in->type_name);
+    if (out->type_name == NULL)
+        goto err;
+    out->origin = EVP_ORIG_FROZEN;
+    if (out->prov == NULL || !ossl_provider_up_ref(out->prov)) {
+        OPENSSL_free(out->type_name);
+        goto err;
+    }
+    return out;
+
+err:
+    CRYPTO_FREE_REF(&out->refcnt);
+    OPENSSL_free(out);
+    return NULL;
+}
+
+static void evp_rand_frozen_free(void *vin)
+{
+    EVP_RAND *rand = vin;
+    int ref = 0;
+
+    if (rand == NULL || rand->origin != EVP_ORIG_FROZEN)
+        return;
+
+    CRYPTO_DOWN_REF(&rand->refcnt, &ref);
+    if (ref > 0)
+        return;
+    evp_rand_free_int(rand);
+}
+
 /* Enable locking of the underlying DRBG/RAND if available */
 int EVP_RAND_enable_locking(EVP_RAND_CTX *rand)
 {
@@ -117,7 +133,7 @@ static void evp_rand_unlock(EVP_RAND_CTX *rand)
 
 static void *evp_rand_from_algorithm(int name_id,
     const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, int no_store)
+    OSSL_PROVIDER *prov)
 {
     const OSSL_DISPATCH *fns = algodef->implementation;
     EVP_RAND *rand = NULL;
@@ -131,7 +147,6 @@ static void *evp_rand_from_algorithm(int name_id,
         return NULL;
     }
     rand->name_id = name_id;
-    rand->no_store = no_store;
     if ((rand->type_name = ossl_algorithm_get1_first_name(algodef)) == NULL) {
         evp_rand_free(rand);
         return NULL;
@@ -284,30 +299,33 @@ static void *evp_rand_from_algorithm(int name_id,
 EVP_RAND *EVP_RAND_fetch(OSSL_LIB_CTX *libctx, const char *algorithm,
     const char *properties)
 {
-    return evp_generic_fetch(libctx, OSSL_OP_RAND, algorithm, properties,
-        evp_rand_from_algorithm, evp_rand_up_ref,
-        evp_rand_free);
+    return evp_generic_fetch(libctx, OSSL_OP_RAND,
+        algorithm, properties,
+        evp_rand_from_algorithm,
+        evp_rand_up_ref,
+        evp_rand_free,
+        evp_rand_dup_frozen,
+        evp_rand_frozen_free);
+}
+
+int evp_rand_fetch_all(OSSL_LIB_CTX *ctx)
+{
+    return evp_generic_fetch_all(ctx, OSSL_OP_RAND,
+        evp_rand_from_algorithm,
+        evp_rand_up_ref,
+        evp_rand_free,
+        evp_rand_dup_frozen,
+        evp_rand_frozen_free);
 }
 
 int EVP_RAND_up_ref(EVP_RAND *rand)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
     return evp_rand_up_ref(rand);
-#else
-    if (rand->no_store != 0)
-        return evp_rand_up_ref(rand);
-    return 1;
-#endif
 }
 
 void EVP_RAND_free(EVP_RAND *rand)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
     evp_rand_free(rand);
-#else
-    if (rand != NULL && (rand->no_store != 0))
-        evp_rand_free(rand);
-#endif
 }
 
 int evp_rand_get_number(const EVP_RAND *rand)
@@ -505,12 +523,8 @@ void EVP_RAND_do_all_provided(OSSL_LIB_CTX *libctx,
     void (*fn)(EVP_RAND *rand, void *arg),
     void *arg)
 {
-    struct EVP_RAND_do_all_provided_thunk t;
-
-    t.fn = fn;
-    t.arg = arg;
     evp_generic_do_all(libctx, OSSL_OP_RAND,
-        EVP_RAND_do_all_provided_thunk, &t,
+        (void (*)(void *, void *))fn, arg,
         evp_rand_from_algorithm, evp_rand_up_ref,
         evp_rand_free);
 }
diff --git a/crypto/evp/exchange.c b/crypto/evp/exchange.c
index 8718726076..1346b4d4ae 100644
--- a/crypto/evp/exchange.c
+++ b/crypto/evp/exchange.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -19,28 +19,22 @@
 #include "crypto/evp.h"
 #include "evp_local.h"
 
-static void evp_keyexch_free(void *data)
+static void evp_keyexch_free_int(EVP_KEYEXCH *exchange)
 {
-    EVP_KEYEXCH *exchange = (EVP_KEYEXCH *)data;
-    int i;
-
-    if (exchange == NULL)
-        return;
-    CRYPTO_DOWN_REF(&exchange->refcnt, &i);
-    if (i > 0)
-        return;
     OPENSSL_free(exchange->type_name);
     ossl_provider_free(exchange->prov);
     CRYPTO_FREE_REF(&exchange->refcnt);
     OPENSSL_free(exchange);
 }
 
+static void evp_keyexch_free(void *data)
+{
+    EVP_KEYEXCH_free(data);
+}
+
 static int evp_keyexch_up_ref(void *data)
 {
-    EVP_KEYEXCH *exchange = (EVP_KEYEXCH *)data;
-    int ref = 0;
-
-    return CRYPTO_UP_REF(&exchange->refcnt, &ref);
+    return EVP_KEYEXCH_up_ref(data);
 }
 
 static EVP_KEYEXCH *evp_keyexch_new(OSSL_PROVIDER *prov)
@@ -61,9 +55,50 @@ static EVP_KEYEXCH *evp_keyexch_new(OSSL_PROVIDER *prov)
     return exchange;
 }
 
+static void *evp_keyexch_dup_frozen(void *vin)
+{
+    EVP_KEYEXCH *in = vin;
+    EVP_KEYEXCH *out;
+
+    out = OPENSSL_malloc(sizeof(*out));
+    if (out == NULL)
+        return NULL;
+    memcpy(out, in, sizeof(*out));
+    if (!CRYPTO_NEW_REF(&out->refcnt, 1))
+        goto err;
+    out->type_name = OPENSSL_strdup(in->type_name);
+    if (out->type_name == NULL)
+        goto err;
+    out->origin = EVP_ORIG_FROZEN;
+    if (out->prov == NULL || !ossl_provider_up_ref(out->prov)) {
+        OPENSSL_free(out->type_name);
+        goto err;
+    }
+    return out;
+
+err:
+    CRYPTO_FREE_REF(&out->refcnt);
+    OPENSSL_free(out);
+    return NULL;
+}
+
+static void evp_keyexch_frozen_free(void *vin)
+{
+    EVP_KEYEXCH *rand = vin;
+    int ref = 0;
+
+    if (rand == NULL || rand->origin != EVP_ORIG_FROZEN)
+        return;
+
+    CRYPTO_DOWN_REF(&rand->refcnt, &ref);
+    if (ref > 0)
+        return;
+    evp_keyexch_free_int(rand);
+}
+
 static void *evp_keyexch_from_algorithm(int name_id,
     const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, int no_store)
+    OSSL_PROVIDER *prov)
 {
     const OSSL_DISPATCH *fns = algodef->implementation;
     EVP_KEYEXCH *exchange = NULL;
@@ -75,7 +110,6 @@ static void *evp_keyexch_from_algorithm(int name_id,
     }
 
     exchange->name_id = name_id;
-    exchange->no_store = no_store;
     if ((exchange->type_name = ossl_algorithm_get1_first_name(algodef)) == NULL)
         goto err;
     exchange->description = algodef->algorithm_description;
@@ -169,29 +203,29 @@ static void *evp_keyexch_from_algorithm(int name_id,
     return exchange;
 
 err:
-    evp_keyexch_free(exchange);
+    EVP_KEYEXCH_free(exchange);
     return NULL;
 }
 
 void EVP_KEYEXCH_free(EVP_KEYEXCH *exchange)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    evp_keyexch_free(exchange);
-#else
-    if (exchange != NULL && (exchange->no_store != 0))
-        evp_keyexch_free(exchange);
-#endif
+    int i;
+
+    if (exchange == NULL || exchange->origin != EVP_ORIG_DYNAMIC)
+        return;
+    CRYPTO_DOWN_REF(&exchange->refcnt, &i);
+    if (i > 0)
+        return;
+    evp_keyexch_free_int(exchange);
 }
 
 int EVP_KEYEXCH_up_ref(EVP_KEYEXCH *exchange)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    return evp_keyexch_up_ref(exchange);
-#else
-    if (exchange->no_store != 0)
-        return evp_keyexch_up_ref(exchange);
+    int ref = 0;
+
+    if (exchange->origin == EVP_ORIG_DYNAMIC)
+        CRYPTO_UP_REF(&exchange->refcnt, &ref);
     return 1;
-#endif
 }
 
 OSSL_PROVIDER *EVP_KEYEXCH_get0_provider(const EVP_KEYEXCH *exchange)
@@ -202,10 +236,26 @@ OSSL_PROVIDER *EVP_KEYEXCH_get0_provider(const EVP_KEYEXCH *exchange)
 EVP_KEYEXCH *EVP_KEYEXCH_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
     const char *properties)
 {
-    return evp_generic_fetch(ctx, OSSL_OP_KEYEXCH, algorithm, properties,
+    return evp_generic_fetch(ctx,
+        OSSL_OP_KEYEXCH,
+        algorithm,
+        properties,
         evp_keyexch_from_algorithm,
         evp_keyexch_up_ref,
-        evp_keyexch_free);
+        evp_keyexch_free,
+        evp_keyexch_dup_frozen,
+        evp_keyexch_frozen_free);
+}
+
+int evp_keyexch_fetch_all(OSSL_LIB_CTX *ctx)
+{
+    return evp_generic_fetch_all(ctx,
+        OSSL_OP_KEYEXCH,
+        evp_keyexch_from_algorithm,
+        evp_keyexch_up_ref,
+        evp_keyexch_free,
+        evp_keyexch_dup_frozen,
+        evp_keyexch_frozen_free);
 }
 
 EVP_KEYEXCH *evp_keyexch_fetch_from_prov(OSSL_PROVIDER *prov,
@@ -216,7 +266,9 @@ EVP_KEYEXCH *evp_keyexch_fetch_from_prov(OSSL_PROVIDER *prov,
         algorithm, properties,
         evp_keyexch_from_algorithm,
         evp_keyexch_up_ref,
-        evp_keyexch_free);
+        evp_keyexch_free,
+        evp_keyexch_dup_frozen,
+        evp_keyexch_frozen_free);
 }
 
 int EVP_PKEY_derive_init(EVP_PKEY_CTX *ctx)
@@ -245,7 +297,7 @@ int EVP_PKEY_derive_init_ex(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[])
     ERR_set_mark();
 
     if (evp_pkey_ctx_is_legacy(ctx))
-        goto err;
+        goto legacy;
 
     /*
      * Some algorithms (e.g. legacy KDFs) don't have a pkey - so we create
@@ -256,7 +308,7 @@ int EVP_PKEY_derive_init_ex(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[])
 
         if (pkey == NULL
             || !EVP_PKEY_set_type_by_keymgmt(pkey, ctx->keymgmt)
-            || (pkey->keydata = evp_keymgmt_newdata(ctx->keymgmt, NULL)) == NULL) {
+            || (pkey->keydata = evp_keymgmt_newdata(ctx->keymgmt)) == NULL) {
             ERR_clear_last_mark();
             EVP_PKEY_free(pkey);
             ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
@@ -308,9 +360,7 @@ int EVP_PKEY_derive_init_ex(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[])
          * iteration we're on.
          */
         EVP_KEYEXCH_free(exchange);
-        exchange = NULL;
         EVP_KEYMGMT_free(tmp_keymgmt);
-        tmp_keymgmt = NULL;
 
         switch (iter) {
         case 1:
@@ -322,11 +372,8 @@ int EVP_PKEY_derive_init_ex(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[])
             tmp_prov = EVP_KEYMGMT_get0_provider(ctx->keymgmt);
             exchange = evp_keyexch_fetch_from_prov((OSSL_PROVIDER *)tmp_prov,
                 supported_exch, ctx->propquery);
-            if (exchange == NULL) {
-                ERR_pop_to_mark();
-                ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
-                return -2;
-            }
+            if (exchange == NULL)
+                goto legacy;
             break;
         }
         if (exchange == NULL)
@@ -352,14 +399,14 @@ int EVP_PKEY_derive_init_ex(EVP_PKEY_CTX *ctx, const OSSL_PARAM params[])
     }
 
     if (provkey == NULL) {
-        ERR_pop_to_mark();
         EVP_KEYEXCH_free(exchange);
-        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
-        return -2;
+        goto legacy;
     }
 
     ERR_pop_to_mark();
 
+    /* No more legacy from here down to legacy: */
+
     /* A Coverity false positive with up_ref/down_ref and free */
     /* coverity[use_after_free] */
     ctx->op.kex.exchange = exchange;
@@ -380,6 +427,30 @@ err:
     ctx->operation = EVP_PKEY_OP_UNDEFINED;
     EVP_KEYMGMT_free(tmp_keymgmt);
     return 0;
+
+legacy:
+    /*
+     * If we don't have the full support we need with provided methods,
+     * let's go see if legacy does.
+     */
+    ERR_pop_to_mark();
+
+#ifdef FIPS_MODULE
+    return 0;
+#else
+    if (ctx->pmeth == NULL || ctx->pmeth->derive == NULL) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
+        return -2;
+    }
+
+    if (ctx->pmeth->derive_init == NULL)
+        return 1;
+    ret = ctx->pmeth->derive_init(ctx);
+    if (ret <= 0)
+        ctx->operation = EVP_PKEY_OP_UNDEFINED;
+    EVP_KEYMGMT_free(tmp_keymgmt);
+    return ret;
+#endif
 }
 
 int EVP_PKEY_derive_set_peer_ex(EVP_PKEY_CTX *ctx, EVP_PKEY *peer,
@@ -395,10 +466,8 @@ int EVP_PKEY_derive_set_peer_ex(EVP_PKEY_CTX *ctx, EVP_PKEY *peer,
         return -1;
     }
 
-    if (!EVP_PKEY_CTX_IS_DERIVE_OP(ctx) || ctx->op.kex.algctx == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
-        return -2;
-    }
+    if (!EVP_PKEY_CTX_IS_DERIVE_OP(ctx) || ctx->op.kex.algctx == NULL)
+        goto legacy;
 
     if (ctx->op.kex.exchange->set_peer == NULL) {
         ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
@@ -428,24 +497,79 @@ int EVP_PKEY_derive_set_peer_ex(EVP_PKEY_CTX *ctx, EVP_PKEY *peer,
                                                                        EVP_KEYEXCH_get0_provider(ctx->op.kex.exchange),
         EVP_KEYMGMT_get0_name(ctx->keymgmt),
         ctx->propquery);
-    if (tmp_keymgmt == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_NO_KEYMGMT_AVAILABLE);
-        return -1;
-    }
-    /* A Coverity issue with up_ref/down_ref and free */
-    /* coverity[pass_freed_arg] */
-    provkey = evp_pkey_export_to_provider(peer, ctx->libctx,
-        &tmp_keymgmt, ctx->propquery);
+    if (tmp_keymgmt != NULL)
+        /* A Coverity issue with up_ref/down_ref and free */
+        /* coverity[pass_freed_arg] */
+        provkey = evp_pkey_export_to_provider(peer, ctx->libctx,
+            &tmp_keymgmt, ctx->propquery);
     EVP_KEYMGMT_free(tmp_keymgmt_tofree);
 
-    if (provkey == NULL) {
-        ERR_raise(ERR_LIB_EVP, ERR_R_INTERNAL_ERROR);
-        return -1;
-    }
+    /*
+     * If making the key provided wasn't possible, legacy may be able to pick
+     * it up
+     */
+    if (provkey == NULL)
+        goto legacy;
     ret = ctx->op.kex.exchange->set_peer(ctx->op.kex.algctx, provkey);
     if (ret <= 0)
         return ret;
+    goto common;
 
+legacy:
+#ifdef FIPS_MODULE
+    return ret;
+#else
+    if (ctx->pmeth == NULL
+        || !(ctx->pmeth->derive != NULL
+            || ctx->pmeth->encrypt != NULL
+            || ctx->pmeth->decrypt != NULL)
+        || ctx->pmeth->ctrl == NULL) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
+        return -2;
+    }
+    if (ctx->operation != EVP_PKEY_OP_DERIVE
+        && ctx->operation != EVP_PKEY_OP_ENCRYPT
+        && ctx->operation != EVP_PKEY_OP_DECRYPT) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_INITIALIZED);
+        return -1;
+    }
+
+    ret = ctx->pmeth->ctrl(ctx, EVP_PKEY_CTRL_PEER_KEY, 0, peer);
+
+    if (ret <= 0)
+        return ret;
+
+    if (ret == 2)
+        return 1;
+
+    if (ctx->pkey == NULL) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_NO_KEY_SET);
+        return -1;
+    }
+
+    if (ctx->pkey->type != peer->type) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_DIFFERENT_KEY_TYPES);
+        return -1;
+    }
+
+    /*
+     * For clarity.  The error is if parameters in peer are
+     * present (!missing) but don't match.  EVP_PKEY_parameters_eq may return
+     * 1 (match), 0 (don't match) and -2 (comparison is not defined).  -1
+     * (different key types) is impossible here because it is checked earlier.
+     * -2 is OK for us here, as well as 1, so we can check for 0 only.
+     */
+    if (!EVP_PKEY_missing_parameters(peer) && !EVP_PKEY_parameters_eq(ctx->pkey, peer)) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_DIFFERENT_PARAMETERS);
+        return -1;
+    }
+
+    ret = ctx->pmeth->ctrl(ctx, EVP_PKEY_CTRL_PEER_KEY, 1, peer);
+    if (ret <= 0)
+        return ret;
+#endif
+
+common:
     if (!EVP_PKEY_up_ref(peer))
         return -1;
 
@@ -474,15 +598,20 @@ int EVP_PKEY_derive(EVP_PKEY_CTX *ctx, unsigned char *key, size_t *pkeylen)
         return -1;
     }
 
-    if (ctx->op.kex.algctx == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
-        return -2;
-    }
+    if (ctx->op.kex.algctx == NULL)
+        goto legacy;
 
     ret = ctx->op.kex.exchange->derive(ctx->op.kex.algctx, key, pkeylen,
         key != NULL ? *pkeylen : 0);
 
     return ret;
+legacy:
+    if (ctx->pmeth == NULL || ctx->pmeth->derive == NULL) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
+        return -2;
+    }
+
+    M_check_autoarg(ctx, key, pkeylen, EVP_F_EVP_PKEY_DERIVE) return ctx->pmeth->derive(ctx, key, pkeylen);
 }
 
 EVP_SKEY *EVP_PKEY_derive_SKEY(EVP_PKEY_CTX *ctx, EVP_SKEYMGMT *mgmt,
@@ -533,25 +662,25 @@ EVP_SKEY *EVP_PKEY_derive_SKEY(EVP_PKEY_CTX *ctx, EVP_SKEYMGMT *mgmt,
 
         if (ctx->op.kex.exchange->derive == NULL) {
             ERR_raise(ERR_R_EVP_LIB, ERR_R_UNSUPPORTED);
-            goto cleanup;
+            return NULL;
         }
 
         key = OPENSSL_zalloc(keylen);
         if (key == NULL) {
             ERR_raise(ERR_R_EVP_LIB, ERR_R_CRYPTO_LIB);
-            goto cleanup;
+            return NULL;
         }
 
         if (!ctx->op.kex.exchange->derive(ctx->op.kex.algctx, key, &tmplen,
                 tmplen)) {
             OPENSSL_free(key);
-            goto cleanup;
+            return NULL;
         }
 
         if (keylen != tmplen) {
             OPENSSL_free(key);
             ERR_raise(ERR_R_EVP_LIB, ERR_R_INTERNAL_ERROR);
-            goto cleanup;
+            return NULL;
         }
         import_params[0] = OSSL_PARAM_construct_octet_string(OSSL_SKEY_PARAM_RAW_BYTES,
             key, keylen);
@@ -559,25 +688,30 @@ EVP_SKEY *EVP_PKEY_derive_SKEY(EVP_PKEY_CTX *ctx, EVP_SKEYMGMT *mgmt,
         ret = EVP_SKEY_import_SKEYMGMT(ctx->libctx, skeymgmt,
             OSSL_SKEYMGMT_SELECT_SECRET_KEY, import_params);
         OPENSSL_clear_free(key, keylen);
-        goto cleanup;
+        if (mgmt != skeymgmt)
+            EVP_SKEYMGMT_free(skeymgmt);
+        return ret;
     }
 
     ret = evp_skey_alloc(skeymgmt);
-    if (ret == NULL)
-        goto cleanup;
+    if (ret == NULL) {
+        if (mgmt != skeymgmt)
+            EVP_SKEYMGMT_free(skeymgmt);
+        return NULL;
+    }
 
     ret->keydata = ctx->op.kex.exchange->derive_skey(ctx->op.kex.algctx, key_type,
         ossl_provider_ctx(skeymgmt->prov),
         skeymgmt->import, keylen, params);
 
-    if (ret->keydata == NULL) {
-        EVP_SKEY_free(ret);
-        ret = NULL;
-        goto cleanup;
-    }
-cleanup:
     if (mgmt != skeymgmt)
         EVP_SKEYMGMT_free(skeymgmt);
+
+    if (ret->keydata == NULL) {
+        EVP_SKEY_free(ret);
+        return NULL;
+    }
+
     return ret;
 }
 
@@ -606,12 +740,8 @@ void EVP_KEYEXCH_do_all_provided(OSSL_LIB_CTX *libctx,
     void (*fn)(EVP_KEYEXCH *keyexch, void *arg),
     void *arg)
 {
-    struct EVP_KEYEXCH_do_all_provided_thunk t;
-
-    t.fn = fn;
-    t.arg = arg;
     evp_generic_do_all(libctx, OSSL_OP_KEYEXCH,
-        EVP_KEYEXCH_do_all_provided_thunk, &t,
+        (void (*)(void *, void *))fn, arg,
         evp_keyexch_from_algorithm,
         evp_keyexch_up_ref,
         evp_keyexch_free);
diff --git a/crypto/evp/kdf_lib.c b/crypto/evp/kdf_lib.c
index 67351044fb..4c98942992 100644
--- a/crypto/evp/kdf_lib.c
+++ b/crypto/evp/kdf_lib.c
@@ -104,25 +104,11 @@ const OSSL_PROVIDER *EVP_KDF_get0_provider(const EVP_KDF *kdf)
     return kdf->prov;
 }
 
-const EVP_KDF *EVP_KDF_CTX_get0_kdf(const EVP_KDF_CTX *ctx)
+const EVP_KDF *EVP_KDF_CTX_kdf(EVP_KDF_CTX *ctx)
 {
     return ctx->meth;
 }
 
-#if !defined(OPENSSL_NO_DEPRECATED_4_1)
-const EVP_KDF *EVP_KDF_CTX_kdf(const EVP_KDF_CTX *ctx)
-{
-    return EVP_KDF_CTX_get0_kdf(ctx);
-}
-#endif /* !OPENSSL_NO_DEPRECATED_4_1 */
-
-EVP_KDF *EVP_KDF_CTX_get1_kdf(const EVP_KDF_CTX *ctx)
-{
-    if (!EVP_KDF_up_ref(ctx->meth))
-        return NULL;
-    return ctx->meth;
-}
-
 void EVP_KDF_CTX_reset(EVP_KDF_CTX *ctx)
 {
     if (ctx == NULL)
diff --git a/crypto/evp/kdf_meth.c b/crypto/evp/kdf_meth.c
index c6df2971db..bbf045b250 100644
--- a/crypto/evp/kdf_meth.c
+++ b/crypto/evp/kdf_meth.c
@@ -12,17 +12,28 @@
 #include 
 #include 
 #include 
+#include 
 #include "internal/provider.h"
 #include "internal/core.h"
 #include "crypto/evp.h"
 #include "evp_local.h"
 
+static void evp_kdf_free_int(EVP_KDF *kdf)
+{
+    OPENSSL_free(kdf->type_name);
+    ossl_provider_free(kdf->prov);
+    CRYPTO_FREE_REF(&kdf->refcnt);
+    OPENSSL_free(kdf);
+}
+
 static int evp_kdf_up_ref(void *vkdf)
 {
     EVP_KDF *kdf = (EVP_KDF *)vkdf;
     int ref = 0;
 
-    return CRYPTO_UP_REF(&kdf->refcnt, &ref);
+    if (kdf->origin == EVP_ORIG_DYNAMIC)
+        CRYPTO_UP_REF(&kdf->refcnt, &ref);
+    return 1;
 }
 
 static void evp_kdf_free(void *vkdf)
@@ -30,16 +41,52 @@ static void evp_kdf_free(void *vkdf)
     EVP_KDF *kdf = (EVP_KDF *)vkdf;
     int ref = 0;
 
-    if (kdf == NULL)
+    if (kdf == NULL || kdf->origin != EVP_ORIG_DYNAMIC)
         return;
 
     CRYPTO_DOWN_REF(&kdf->refcnt, &ref);
     if (ref > 0)
         return;
-    OPENSSL_free(kdf->type_name);
-    ossl_provider_free(kdf->prov);
-    CRYPTO_FREE_REF(&kdf->refcnt);
-    OPENSSL_free(kdf);
+    evp_kdf_free_int(kdf);
+}
+
+static void *evp_kdf_dup_frozen(void *vin)
+{
+    EVP_KDF *in = vin;
+    EVP_KDF *out;
+
+    out = OPENSSL_malloc(sizeof(*out));
+    if (out == NULL)
+        return NULL;
+    memcpy(out, in, sizeof(*out));
+    if (!CRYPTO_NEW_REF(&out->refcnt, 1))
+        goto err;
+    out->type_name = OPENSSL_strdup(in->type_name);
+    if (out->type_name == NULL)
+        goto err;
+    out->origin = EVP_ORIG_FROZEN;
+    if (out->prov == NULL || !ossl_provider_up_ref(out->prov)) {
+        OPENSSL_free(out->type_name);
+        goto err;
+    }
+    return out;
+err:
+    CRYPTO_FREE_REF(&out->refcnt);
+    OPENSSL_free(out);
+    return NULL;
+}
+
+static void evp_kdf_frozen_free(EVP_KDF *kdf)
+{
+    int ref;
+
+    if (kdf == NULL || kdf->origin != EVP_ORIG_FROZEN)
+        return;
+
+    CRYPTO_DOWN_REF(&kdf->refcnt, &ref);
+    if (ref > 0)
+        return;
+    evp_kdf_free_int(kdf);
 }
 
 static void *evp_kdf_new(void)
@@ -56,7 +103,7 @@ static void *evp_kdf_new(void)
 
 static void *evp_kdf_from_algorithm(int name_id,
     const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, int no_store)
+    OSSL_PROVIDER *prov)
 {
     const OSSL_DISPATCH *fns = algodef->implementation;
     EVP_KDF *kdf = NULL;
@@ -67,8 +114,6 @@ static void *evp_kdf_from_algorithm(int name_id,
         return NULL;
     }
     kdf->name_id = name_id;
-    kdf->no_store = no_store;
-
     if ((kdf->type_name = ossl_algorithm_get1_first_name(algodef)) == NULL)
         goto err;
 
@@ -172,28 +217,28 @@ EVP_KDF *EVP_KDF_fetch(OSSL_LIB_CTX *libctx, const char *algorithm,
 {
     return evp_generic_fetch(libctx, OSSL_OP_KDF, algorithm, properties,
         evp_kdf_from_algorithm, evp_kdf_up_ref,
-        evp_kdf_free);
+        evp_kdf_free, evp_kdf_dup_frozen,
+        (void (*)(void *))evp_kdf_frozen_free);
+}
+
+int evp_kdf_fetch_all(OSSL_LIB_CTX *ctx)
+{
+    return evp_generic_fetch_all(ctx, OSSL_OP_KDF,
+        evp_kdf_from_algorithm,
+        evp_kdf_up_ref,
+        evp_kdf_free,
+        evp_kdf_dup_frozen,
+        (void (*)(void *))evp_kdf_frozen_free);
 }
 
 int EVP_KDF_up_ref(EVP_KDF *kdf)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
     return evp_kdf_up_ref(kdf);
-#else
-    if (kdf->no_store != 0)
-        return evp_kdf_up_ref(kdf);
-    return 1;
-#endif
 }
 
 void EVP_KDF_free(EVP_KDF *kdf)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
     evp_kdf_free(kdf);
-#else
-    if (kdf != NULL && (kdf->no_store != 0))
-        evp_kdf_free(kdf);
-#endif
 }
 
 const OSSL_PARAM *EVP_KDF_gettable_params(const EVP_KDF *kdf)
@@ -247,11 +292,7 @@ void EVP_KDF_do_all_provided(OSSL_LIB_CTX *libctx,
     void (*fn)(EVP_KDF *kdf, void *arg),
     void *arg)
 {
-    struct EVP_KDF_do_all_provided_thunk t;
-
-    t.fn = fn;
-    t.arg = arg;
     evp_generic_do_all(libctx, OSSL_OP_KDF,
-        EVP_KDF_do_all_provided_thunk, &t,
+        (void (*)(void *, void *))fn, arg,
         evp_kdf_from_algorithm, evp_kdf_up_ref, evp_kdf_free);
 }
diff --git a/crypto/evp/kem.c b/crypto/evp/kem.c
index 8ae968d5a5..3e6de42a2c 100644
--- a/crypto/evp/kem.c
+++ b/crypto/evp/kem.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -9,6 +9,7 @@
 
 #include 
 #include 
+#include 
 #include 
 #include 
 #include "internal/cryptlib.h"
@@ -19,15 +20,11 @@
 
 static void evp_kem_free(void *data)
 {
-    EVP_KEM *kem = (EVP_KEM *)data;
-    int i;
+    EVP_KEM_free(data);
+}
 
-    if (kem == NULL)
-        return;
-
-    CRYPTO_DOWN_REF(&kem->refcnt, &i);
-    if (i > 0)
-        return;
+static void evp_kem_free_int(EVP_KEM *kem)
+{
     OPENSSL_free(kem->type_name);
     ossl_provider_free(kem->prov);
     CRYPTO_FREE_REF(&kem->refcnt);
@@ -36,10 +33,48 @@ static void evp_kem_free(void *data)
 
 static int evp_kem_up_ref(void *data)
 {
-    EVP_KEM *kem = (EVP_KEM *)data;
+    return EVP_KEM_up_ref(data);
+}
+
+static void *evp_kem_dup_frozen(void *vin)
+{
+    EVP_KEM *in = vin;
+    EVP_KEM *out;
+
+    out = OPENSSL_malloc(sizeof(*out));
+    if (out == NULL)
+        return NULL;
+    memcpy(out, in, sizeof(*out));
+    if (!CRYPTO_NEW_REF(&out->refcnt, 1))
+        goto err;
+    out->type_name = OPENSSL_strdup(in->type_name);
+    if (out->type_name == NULL)
+        goto err;
+    out->origin = EVP_ORIG_FROZEN;
+    if (out->prov != NULL && !ossl_provider_up_ref(out->prov)) {
+        OPENSSL_free(out->type_name);
+        goto err;
+    }
+    return out;
+
+err:
+    CRYPTO_FREE_REF(&out->refcnt);
+    OPENSSL_free(out);
+    return NULL;
+}
+
+static void evp_kem_frozen_free(void *vin)
+{
+    EVP_KEM *kem = vin;
     int ref = 0;
 
-    return CRYPTO_UP_REF(&kem->refcnt, &ref);
+    if (kem == NULL || kem->origin != EVP_ORIG_FROZEN)
+        return;
+
+    CRYPTO_DOWN_REF(&kem->refcnt, &ref);
+    if (ref > 0)
+        return;
+    evp_kem_free_int(kem);
 }
 
 static int evp_kem_init(EVP_PKEY_CTX *ctx, int operation,
@@ -112,9 +147,7 @@ static int evp_kem_init(EVP_PKEY_CTX *ctx, int operation,
          * iteration we're on.
          */
         EVP_KEM_free(kem);
-        kem = NULL;
         EVP_KEYMGMT_free(tmp_keymgmt);
-        tmp_keymgmt = NULL;
 
         switch (iter) {
         case 1:
@@ -198,7 +231,7 @@ static int evp_kem_init(EVP_PKEY_CTX *ctx, int operation,
         if (provauthkey != NULL && kem->auth_decapsulate_init != NULL) {
             ret = kem->auth_decapsulate_init(ctx->op.encap.algctx, provkey,
                 provauthkey, params);
-        } else if (provauthkey == NULL && kem->decapsulate_init != NULL) {
+        } else if (provauthkey == NULL && kem->encapsulate_init != NULL) {
             ret = kem->decapsulate_init(ctx->op.encap.algctx, provkey, params);
         } else {
             ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
@@ -316,7 +349,7 @@ static EVP_KEM *evp_kem_new(OSSL_PROVIDER *prov)
 }
 
 static void *evp_kem_from_algorithm(int name_id, const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, int no_store)
+    OSSL_PROVIDER *prov)
 {
     const OSSL_DISPATCH *fns = algodef->implementation;
     EVP_KEM *kem = NULL;
@@ -329,8 +362,6 @@ static void *evp_kem_from_algorithm(int name_id, const OSSL_ALGORITHM *algodef,
     }
 
     kem->name_id = name_id;
-    kem->no_store = no_store;
-
     if ((kem->type_name = ossl_algorithm_get1_first_name(algodef)) == NULL)
         goto err;
     kem->description = algodef->algorithm_description;
@@ -443,29 +474,30 @@ static void *evp_kem_from_algorithm(int name_id, const OSSL_ALGORITHM *algodef,
 
     return kem;
 err:
-    evp_kem_free(kem);
+    EVP_KEM_free(kem);
     return NULL;
 }
 
 void EVP_KEM_free(EVP_KEM *kem)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    evp_kem_free(kem);
-#else
-    if (kem != NULL && (kem->no_store != 0))
-        evp_kem_free(kem);
-#endif
+    int i;
+
+    if (kem == NULL || kem->origin != EVP_ORIG_DYNAMIC)
+        return;
+
+    CRYPTO_DOWN_REF(&kem->refcnt, &i);
+    if (i > 0)
+        return;
+    evp_kem_free_int(kem);
 }
 
 int EVP_KEM_up_ref(EVP_KEM *kem)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    return evp_kem_up_ref(kem);
-#else
-    if (kem->no_store != 0)
-        return evp_kem_up_ref(kem);
+    int ref = 0;
+
+    if (kem->origin == EVP_ORIG_DYNAMIC)
+        CRYPTO_UP_REF(&kem->refcnt, &ref);
     return 1;
-#endif
 }
 
 OSSL_PROVIDER *EVP_KEM_get0_provider(const EVP_KEM *kem)
@@ -479,7 +511,9 @@ EVP_KEM *EVP_KEM_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
     return evp_generic_fetch(ctx, OSSL_OP_KEM, algorithm, properties,
         evp_kem_from_algorithm,
         evp_kem_up_ref,
-        evp_kem_free);
+        evp_kem_free,
+        evp_kem_dup_frozen,
+        evp_kem_frozen_free);
 }
 
 EVP_KEM *evp_kem_fetch_from_prov(OSSL_PROVIDER *prov, const char *algorithm,
@@ -488,7 +522,19 @@ EVP_KEM *evp_kem_fetch_from_prov(OSSL_PROVIDER *prov, const char *algorithm,
     return evp_generic_fetch_from_prov(prov, OSSL_OP_KEM, algorithm, properties,
         evp_kem_from_algorithm,
         evp_kem_up_ref,
-        evp_kem_free);
+        evp_kem_free,
+        evp_kem_dup_frozen,
+        evp_kem_frozen_free);
+}
+
+int evp_kem_fetch_all(OSSL_LIB_CTX *ctx)
+{
+    return evp_generic_fetch_all(ctx, OSSL_OP_KEM,
+        evp_kem_from_algorithm,
+        evp_kem_up_ref,
+        evp_kem_free,
+        evp_kem_dup_frozen,
+        evp_kem_frozen_free);
 }
 
 int EVP_KEM_is_a(const EVP_KEM *kem, const char *name)
@@ -515,11 +561,7 @@ void EVP_KEM_do_all_provided(OSSL_LIB_CTX *libctx,
     void (*fn)(EVP_KEM *kem, void *arg),
     void *arg)
 {
-    struct EVP_KEM_do_all_provided_thunk t;
-
-    t.fn = fn;
-    t.arg = arg;
-    evp_generic_do_all(libctx, OSSL_OP_KEM, EVP_KEM_do_all_provided_thunk, &t,
+    evp_generic_do_all(libctx, OSSL_OP_KEM, (void (*)(void *, void *))fn, arg,
         evp_kem_from_algorithm,
         evp_kem_up_ref,
         evp_kem_free);
diff --git a/crypto/evp/keymgmt_lib.c b/crypto/evp/keymgmt_lib.c
index 1d80c747b7..04ac443aad 100644
--- a/crypto/evp/keymgmt_lib.c
+++ b/crypto/evp/keymgmt_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -33,7 +33,7 @@ int evp_keymgmt_util_try_import(const OSSL_PARAM params[], void *arg)
 
     /* Just in time creation of keydata */
     if (data->keydata == NULL) {
-        if ((data->keydata = evp_keymgmt_newdata(data->keymgmt, NULL)) == NULL) {
+        if ((data->keydata = evp_keymgmt_newdata(data->keymgmt)) == NULL) {
             ERR_raise(ERR_LIB_EVP, ERR_R_EVP_LIB);
             return 0;
         }
@@ -219,13 +219,14 @@ static void op_cache_free(OP_CACHE_ELEM *e)
     OPENSSL_free(e);
 }
 
-void evp_keymgmt_util_clear_operation_cache(EVP_PKEY *pk)
+int evp_keymgmt_util_clear_operation_cache(EVP_PKEY *pk)
 {
-    if (pk == NULL)
-        return;
+    if (pk != NULL) {
+        sk_OP_CACHE_ELEM_pop_free(pk->operation_cache, op_cache_free);
+        pk->operation_cache = NULL;
+    }
 
-    sk_OP_CACHE_ELEM_pop_free(pk->operation_cache, op_cache_free);
-    pk->operation_cache = NULL;
+    return 1;
 }
 
 OP_CACHE_ELEM *evp_keymgmt_util_find_operation_cache(EVP_PKEY *pk,
@@ -320,7 +321,7 @@ void *evp_keymgmt_util_fromdata(EVP_PKEY *target, EVP_KEYMGMT *keymgmt,
 {
     void *keydata = NULL;
 
-    if ((keydata = evp_keymgmt_newdata(keymgmt, NULL)) == NULL
+    if ((keydata = evp_keymgmt_newdata(keymgmt)) == NULL
         || !evp_keymgmt_import(keymgmt, keydata, selection, params)
         || !evp_keymgmt_util_assign_pkey(target, keymgmt, keydata)) {
         evp_keymgmt_freedata(keymgmt, keydata);
diff --git a/crypto/evp/keymgmt_meth.c b/crypto/evp/keymgmt_meth.c
index 9cf4ef5e4f..23ee404929 100644
--- a/crypto/evp/keymgmt_meth.c
+++ b/crypto/evp/keymgmt_meth.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,6 +7,7 @@
  * https://www.openssl.org/source/license.html
  */
 
+#include 
 #include 
 #include 
 #include 
@@ -19,15 +20,11 @@
 
 static void evp_keymgmt_free(void *data)
 {
-    EVP_KEYMGMT *keymgmt = (EVP_KEYMGMT *)data;
-    int ref = 0;
+    EVP_KEYMGMT_free(data);
+}
 
-    if (keymgmt == NULL)
-        return;
-
-    CRYPTO_DOWN_REF(&keymgmt->refcnt, &ref);
-    if (ref > 0)
-        return;
+static void evp_keymgmt_free_int(EVP_KEYMGMT *keymgmt)
+{
     OPENSSL_free(keymgmt->type_name);
     ossl_provider_free(keymgmt->prov);
     CRYPTO_FREE_REF(&keymgmt->refcnt);
@@ -36,10 +33,47 @@ static void evp_keymgmt_free(void *data)
 
 static int evp_keymgmt_up_ref(void *data)
 {
-    EVP_KEYMGMT *keymgmt = (EVP_KEYMGMT *)data;
+    return EVP_KEYMGMT_up_ref(data);
+}
+
+static void *evp_keymgmt_dup_frozen(void *vin)
+{
+    EVP_KEYMGMT *in = vin;
+    EVP_KEYMGMT *out;
+
+    out = OPENSSL_malloc(sizeof(*out));
+    if (out == NULL)
+        return NULL;
+    memcpy(out, in, sizeof(*out));
+    if (!CRYPTO_NEW_REF(&out->refcnt, 1))
+        goto err;
+    out->type_name = OPENSSL_strdup(in->type_name);
+    if (out->type_name == NULL)
+        goto err;
+    out->origin = EVP_ORIG_FROZEN;
+    if (out->prov != NULL && !ossl_provider_up_ref(out->prov)) {
+        OPENSSL_free(out->type_name);
+        goto err;
+    }
+    return out;
+err:
+    CRYPTO_FREE_REF(&out->refcnt);
+    OPENSSL_free(out);
+    return NULL;
+}
+
+static void evp_keymgmt_frozen_free(void *vin)
+{
+    EVP_KEYMGMT *keymgmt = vin;
     int ref = 0;
 
-    return CRYPTO_UP_REF(&keymgmt->refcnt, &ref);
+    if (keymgmt == NULL || keymgmt->origin != EVP_ORIG_FROZEN)
+        return;
+
+    CRYPTO_DOWN_REF(&keymgmt->refcnt, &ref);
+    if (ref > 0)
+        return;
+    evp_keymgmt_free_int(keymgmt);
 }
 
 static void *keymgmt_new(void)
@@ -49,7 +83,7 @@ static void *keymgmt_new(void)
     if ((keymgmt = OPENSSL_zalloc(sizeof(*keymgmt))) == NULL)
         return NULL;
     if (!CRYPTO_NEW_REF(&keymgmt->refcnt, 1)) {
-        OPENSSL_free(keymgmt);
+        EVP_KEYMGMT_free(keymgmt);
         return NULL;
     }
     return keymgmt;
@@ -77,7 +111,7 @@ static int get_legacy_alg_type_from_keymgmt(const EVP_KEYMGMT *keymgmt)
 
 static void *keymgmt_from_algorithm(int name_id,
     const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, int no_store)
+    OSSL_PROVIDER *prov)
 {
     const OSSL_DISPATCH *fns = algodef->implementation;
     EVP_KEYMGMT *keymgmt = NULL;
@@ -91,10 +125,8 @@ static void *keymgmt_from_algorithm(int name_id,
         return NULL;
 
     keymgmt->name_id = name_id;
-    keymgmt->no_store = no_store;
-
     if ((keymgmt->type_name = ossl_algorithm_get1_first_name(algodef)) == NULL) {
-        evp_keymgmt_free(keymgmt);
+        EVP_KEYMGMT_free(keymgmt);
         return NULL;
     }
     keymgmt->description = algodef->algorithm_description;
@@ -105,10 +137,6 @@ static void *keymgmt_from_algorithm(int name_id,
             if (keymgmt->new == NULL)
                 keymgmt->new = OSSL_FUNC_keymgmt_new(fns);
             break;
-        case OSSL_FUNC_KEYMGMT_NEW_EX:
-            if (keymgmt->new_ex == NULL)
-                keymgmt->new_ex = OSSL_FUNC_keymgmt_new_ex(fns);
-            break;
         case OSSL_FUNC_KEYMGMT_GEN_INIT:
             if (keymgmt->gen_init == NULL)
                 keymgmt->gen_init = OSSL_FUNC_keymgmt_gen_init(fns);
@@ -257,7 +285,6 @@ static void *keymgmt_from_algorithm(int name_id,
      */
     if (keymgmt->free == NULL
         || (keymgmt->new == NULL
-            && keymgmt->new_ex == NULL
             && keymgmt->gen == NULL
             && keymgmt->load == NULL)
         || keymgmt->has == NULL
@@ -270,13 +297,13 @@ static void *keymgmt_from_algorithm(int name_id,
         || (keymgmt->gen != NULL
             && (keymgmt->gen_init == NULL
                 || keymgmt->gen_cleanup == NULL))) {
-        evp_keymgmt_free(keymgmt);
+        EVP_KEYMGMT_free(keymgmt);
         ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_PROVIDER_FUNCTIONS);
         return NULL;
     }
     keymgmt->prov = prov;
     if (prov != NULL && !ossl_provider_up_ref(prov)) {
-        evp_keymgmt_free(keymgmt);
+        EVP_KEYMGMT_free(keymgmt);
         ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
         return NULL;
     }
@@ -296,7 +323,19 @@ EVP_KEYMGMT *evp_keymgmt_fetch_from_prov(OSSL_PROVIDER *prov,
         name, properties,
         keymgmt_from_algorithm,
         evp_keymgmt_up_ref,
-        evp_keymgmt_free);
+        evp_keymgmt_free,
+        evp_keymgmt_dup_frozen,
+        evp_keymgmt_frozen_free);
+}
+
+int evp_keymgmt_fetch_all(OSSL_LIB_CTX *ctx)
+{
+    return evp_generic_fetch_all(ctx, OSSL_OP_KEYMGMT,
+        keymgmt_from_algorithm,
+        evp_keymgmt_up_ref,
+        evp_keymgmt_free,
+        evp_keymgmt_dup_frozen,
+        evp_keymgmt_frozen_free);
 }
 
 EVP_KEYMGMT *EVP_KEYMGMT_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
@@ -305,28 +344,31 @@ EVP_KEYMGMT *EVP_KEYMGMT_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
     return evp_generic_fetch(ctx, OSSL_OP_KEYMGMT, algorithm, properties,
         keymgmt_from_algorithm,
         evp_keymgmt_up_ref,
-        evp_keymgmt_free);
+        evp_keymgmt_free,
+        evp_keymgmt_dup_frozen,
+        evp_keymgmt_frozen_free);
 }
 
 int EVP_KEYMGMT_up_ref(EVP_KEYMGMT *keymgmt)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    return evp_keymgmt_up_ref(keymgmt);
-#else
-    if (keymgmt->no_store != 0)
-        return evp_keymgmt_up_ref(keymgmt);
+    int ref = 0;
+
+    if (keymgmt->origin == EVP_ORIG_DYNAMIC)
+        CRYPTO_UP_REF(&keymgmt->refcnt, &ref);
     return 1;
-#endif
 }
 
 void EVP_KEYMGMT_free(EVP_KEYMGMT *keymgmt)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    evp_keymgmt_free(keymgmt);
-#else
-    if (keymgmt != NULL && (keymgmt->no_store != 0))
-        evp_keymgmt_free(keymgmt);
-#endif
+    int ref = 0;
+
+    if (keymgmt == NULL || keymgmt->origin != EVP_ORIG_DYNAMIC)
+        return;
+
+    CRYPTO_DOWN_REF(&keymgmt->refcnt, &ref);
+    if (ref > 0)
+        return;
+    evp_keymgmt_free_int(keymgmt);
 }
 
 const OSSL_PROVIDER *EVP_KEYMGMT_get0_provider(const EVP_KEYMGMT *keymgmt)
@@ -364,12 +406,8 @@ void EVP_KEYMGMT_do_all_provided(OSSL_LIB_CTX *libctx,
     void (*fn)(EVP_KEYMGMT *keymgmt, void *arg),
     void *arg)
 {
-    struct EVP_KEYMGMT_do_all_provided_thunk t;
-
-    t.fn = fn;
-    t.arg = arg;
     evp_generic_do_all(libctx, OSSL_OP_KEYMGMT,
-        EVP_KEYMGMT_do_all_provided_thunk, &t,
+        (void (*)(void *, void *))fn, arg,
         keymgmt_from_algorithm,
         evp_keymgmt_up_ref,
         evp_keymgmt_free);
@@ -388,20 +426,18 @@ int EVP_KEYMGMT_names_do_all(const EVP_KEYMGMT *keymgmt,
 /*
  * Internal API that interfaces with the method function pointers
  */
-void *evp_keymgmt_newdata(const EVP_KEYMGMT *keymgmt, const OSSL_PARAM params[])
+void *evp_keymgmt_newdata(const EVP_KEYMGMT *keymgmt)
 {
     void *provctx = ossl_provider_ctx(EVP_KEYMGMT_get0_provider(keymgmt));
 
     /*
-     * Some providers may have a new_ex which accepts parameters. Otherwise we
-     * fall back to the old "new" which doesn't accept params.
+     * 'new' is currently mandatory on its own, but when new
+     * constructors appear, it won't be quite as mandatory,
+     * so we have a check for future cases.
      */
-    if (keymgmt->new_ex == NULL) {
-        if (keymgmt->new == NULL)
-            return NULL;
-        return keymgmt->new(provctx);
-    }
-    return keymgmt->new_ex(provctx, params);
+    if (keymgmt->new == NULL)
+        return NULL;
+    return keymgmt->new(provctx);
 }
 
 void evp_keymgmt_freedata(const EVP_KEYMGMT *keymgmt, void *keydata)
@@ -426,8 +462,8 @@ int evp_keymgmt_gen_set_template(const EVP_KEYMGMT *keymgmt, void *genctx,
     /*
      * It's arguable if we actually should return success in this case, as
      * it allows the caller to set a template key, which is then ignored.
-     * However, this is how the legacy methods used to operate, so we do this in
-     * the interest of backward compatibility.
+     * However, this is how the legacy methods (EVP_PKEY_METHOD) operate,
+     * so we do this in the interest of backward compatibility.
      */
     if (keymgmt->gen_set_template == NULL)
         return 1;
diff --git a/crypto/evp/legacy_blake2.c b/crypto/evp/legacy_blake2.c
index b8809c1067..af8ad536fa 100644
--- a/crypto/evp/legacy_blake2.c
+++ b/crypto/evp/legacy_blake2.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -9,6 +9,33 @@
 
 #include "crypto/evp.h"
 #include "prov/blake2.h" /* diverse BLAKE2 macros */
+#include "legacy_meth.h"
+
+/*
+ * Local hack to adapt the BLAKE2 init functions to what the
+ * legacy function signatures demand.
+ */
+static int blake2s_init(BLAKE2S_CTX *C)
+{
+    BLAKE2S_PARAM P;
+
+    ossl_blake2s_param_init(&P);
+    return ossl_blake2s_init(C, &P);
+}
+static int blake2b_init(BLAKE2B_CTX *C)
+{
+    BLAKE2B_PARAM P;
+
+    ossl_blake2b_param_init(&P);
+    return ossl_blake2b_init(C, &P);
+}
+#define blake2s_update ossl_blake2s_update
+#define blake2b_update ossl_blake2b_update
+#define blake2s_final ossl_blake2s_final
+#define blake2b_final ossl_blake2b_final
+
+IMPLEMENT_LEGACY_EVP_MD_METH_LC(blake2s_int, blake2s)
+IMPLEMENT_LEGACY_EVP_MD_METH_LC(blake2b_int, blake2b)
 
 static const EVP_MD blake2b_md = {
     NID_blake2b512,
@@ -16,7 +43,8 @@ static const EVP_MD blake2b_md = {
     BLAKE2B_DIGEST_LENGTH,
     0,
     EVP_ORIG_GLOBAL,
-    BLAKE2B_BLOCKBYTES,
+    LEGACY_EVP_MD_METH_TABLE(blake2b_int_init, blake2b_int_update,
+        blake2b_int_final, NULL, BLAKE2B_BLOCKBYTES),
 };
 
 const EVP_MD *EVP_blake2b512(void)
@@ -30,7 +58,8 @@ static const EVP_MD blake2s_md = {
     BLAKE2S_DIGEST_LENGTH,
     0,
     EVP_ORIG_GLOBAL,
-    BLAKE2S_BLOCKBYTES,
+    LEGACY_EVP_MD_METH_TABLE(blake2s_int_init, blake2s_int_update,
+        blake2s_int_final, NULL, BLAKE2S_BLOCKBYTES),
 };
 
 const EVP_MD *EVP_blake2s256(void)
diff --git a/crypto/evp/legacy_md2.c b/crypto/evp/legacy_md2.c
index bd587d177c..72cc99ad70 100644
--- a/crypto/evp/legacy_md2.c
+++ b/crypto/evp/legacy_md2.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,8 +7,17 @@
  * https://www.openssl.org/source/license.html
  */
 
+/*
+ * MD2 low level APIs are deprecated for public use, but still ok for
+ * internal use.
+ */
+#include "internal/deprecated.h"
+
 #include 
 #include "crypto/evp.h"
+#include "legacy_meth.h"
+
+IMPLEMENT_LEGACY_EVP_MD_METH(md2, MD2)
 
 static const EVP_MD md2_md = {
     NID_md2,
@@ -16,7 +25,7 @@ static const EVP_MD md2_md = {
     MD2_DIGEST_LENGTH,
     0,
     EVP_ORIG_GLOBAL,
-    MD2_BLOCK
+    LEGACY_EVP_MD_METH_TABLE(md2_init, md2_update, md2_final, NULL, MD2_BLOCK)
 };
 
 const EVP_MD *EVP_md2(void)
diff --git a/crypto/evp/legacy_md4.c b/crypto/evp/legacy_md4.c
index 0dd2a0e23d..4bc852b520 100644
--- a/crypto/evp/legacy_md4.c
+++ b/crypto/evp/legacy_md4.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,6 +15,9 @@
 
 #include 
 #include "crypto/evp.h"
+#include "legacy_meth.h"
+
+IMPLEMENT_LEGACY_EVP_MD_METH(md4, MD4)
 
 static const EVP_MD md4_md = {
     NID_md4,
@@ -22,7 +25,7 @@ static const EVP_MD md4_md = {
     MD4_DIGEST_LENGTH,
     0,
     EVP_ORIG_GLOBAL,
-    MD4_CBLOCK
+    LEGACY_EVP_MD_METH_TABLE(md4_init, md4_update, md4_final, NULL, MD4_CBLOCK),
 };
 
 const EVP_MD *EVP_md4(void)
diff --git a/crypto/evp/legacy_md5.c b/crypto/evp/legacy_md5.c
index b95dea6694..a67be9fef7 100644
--- a/crypto/evp/legacy_md5.c
+++ b/crypto/evp/legacy_md5.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,6 +15,9 @@
 
 #include 
 #include "crypto/evp.h"
+#include "legacy_meth.h"
+
+IMPLEMENT_LEGACY_EVP_MD_METH(md5, MD5)
 
 static const EVP_MD md5_md = {
     NID_md5,
@@ -22,7 +25,7 @@ static const EVP_MD md5_md = {
     MD5_DIGEST_LENGTH,
     0,
     EVP_ORIG_GLOBAL,
-    MD5_CBLOCK
+    LEGACY_EVP_MD_METH_TABLE(md5_init, md5_update, md5_final, NULL, MD5_CBLOCK)
 };
 
 const EVP_MD *EVP_md5(void)
diff --git a/crypto/evp/legacy_md5_sha1.c b/crypto/evp/legacy_md5_sha1.c
index 3b46a44e6f..62947f8b9a 100644
--- a/crypto/evp/legacy_md5_sha1.c
+++ b/crypto/evp/legacy_md5_sha1.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -16,6 +16,13 @@
 
 #include "crypto/evp.h"
 #include "prov/md5_sha1.h" /* diverse MD5_SHA1 macros */
+#include "legacy_meth.h"
+
+IMPLEMENT_LEGACY_EVP_MD_METH_LC(md5_sha1_int, ossl_md5_sha1)
+static int md5_sha1_int_ctrl(EVP_MD_CTX *ctx, int cmd, int mslen, void *ms)
+{
+    return ossl_md5_sha1_ctrl(EVP_MD_CTX_get0_md_data(ctx), cmd, mslen, ms);
+}
 
 static const EVP_MD md5_sha1_md = {
     NID_md5_sha1,
@@ -23,7 +30,9 @@ static const EVP_MD md5_sha1_md = {
     MD5_SHA1_DIGEST_LENGTH,
     0,
     EVP_ORIG_GLOBAL,
-    MD5_SHA1_CBLOCK
+    LEGACY_EVP_MD_METH_TABLE(md5_sha1_int_init, md5_sha1_int_update,
+        md5_sha1_int_final, md5_sha1_int_ctrl,
+        MD5_SHA1_CBLOCK),
 };
 
 const EVP_MD *EVP_md5_sha1(void)
diff --git a/crypto/evp/legacy_mdc2.c b/crypto/evp/legacy_mdc2.c
index 0fd7b9e0a8..2ad432426c 100644
--- a/crypto/evp/legacy_mdc2.c
+++ b/crypto/evp/legacy_mdc2.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,6 +15,9 @@
 
 #include 
 #include "crypto/evp.h"
+#include "legacy_meth.h"
+
+IMPLEMENT_LEGACY_EVP_MD_METH(mdc2, MDC2)
 
 static const EVP_MD mdc2_md = {
     NID_mdc2,
@@ -22,7 +25,8 @@ static const EVP_MD mdc2_md = {
     MDC2_DIGEST_LENGTH,
     0,
     EVP_ORIG_GLOBAL,
-    MDC2_BLOCK
+    LEGACY_EVP_MD_METH_TABLE(mdc2_init, mdc2_update, mdc2_final, NULL,
+        MDC2_BLOCK),
 };
 
 const EVP_MD *EVP_mdc2(void)
diff --git a/crypto/evp/legacy_meth.h b/crypto/evp/legacy_meth.h
new file mode 100644
index 0000000000..ea1e84c7e7
--- /dev/null
+++ b/crypto/evp/legacy_meth.h
@@ -0,0 +1,39 @@
+/*
+ * Copyright 2019-2021 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+#define IMPLEMENT_LEGACY_EVP_MD_METH(nm, fn)                                \
+    static int nm##_init(EVP_MD_CTX *ctx)                                   \
+    {                                                                       \
+        return fn##_Init(EVP_MD_CTX_get0_md_data(ctx));                     \
+    }                                                                       \
+    static int nm##_update(EVP_MD_CTX *ctx, const void *data, size_t count) \
+    {                                                                       \
+        return fn##_Update(EVP_MD_CTX_get0_md_data(ctx), data, count);      \
+    }                                                                       \
+    static int nm##_final(EVP_MD_CTX *ctx, unsigned char *md)               \
+    {                                                                       \
+        return fn##_Final(md, EVP_MD_CTX_get0_md_data(ctx));                \
+    }
+
+#define IMPLEMENT_LEGACY_EVP_MD_METH_LC(nm, fn)                             \
+    static int nm##_init(EVP_MD_CTX *ctx)                                   \
+    {                                                                       \
+        return fn##_init(EVP_MD_CTX_get0_md_data(ctx));                     \
+    }                                                                       \
+    static int nm##_update(EVP_MD_CTX *ctx, const void *data, size_t count) \
+    {                                                                       \
+        return fn##_update(EVP_MD_CTX_get0_md_data(ctx), data, count);      \
+    }                                                                       \
+    static int nm##_final(EVP_MD_CTX *ctx, unsigned char *md)               \
+    {                                                                       \
+        return fn##_final(md, EVP_MD_CTX_get0_md_data(ctx));                \
+    }
+
+#define LEGACY_EVP_MD_METH_TABLE(init, update, final, ctrl, blksz) \
+    init, update, final, NULL, NULL, blksz, 0, ctrl
diff --git a/crypto/evp/legacy_ripemd.c b/crypto/evp/legacy_ripemd.c
index d28e8a0dc9..80f551a97d 100644
--- a/crypto/evp/legacy_ripemd.c
+++ b/crypto/evp/legacy_ripemd.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,6 +15,9 @@
 
 #include 
 #include "crypto/evp.h"
+#include "legacy_meth.h"
+
+IMPLEMENT_LEGACY_EVP_MD_METH(ripe, RIPEMD160)
 
 static const EVP_MD ripemd160_md = {
     NID_ripemd160,
@@ -22,7 +25,8 @@ static const EVP_MD ripemd160_md = {
     RIPEMD160_DIGEST_LENGTH,
     0,
     EVP_ORIG_GLOBAL,
-    RIPEMD160_CBLOCK
+    LEGACY_EVP_MD_METH_TABLE(ripe_init, ripe_update, ripe_final, NULL,
+        RIPEMD160_CBLOCK),
 };
 
 const EVP_MD *EVP_ripemd160(void)
diff --git a/crypto/evp/legacy_sha.c b/crypto/evp/legacy_sha.c
index 77d63cf8cd..0c1a74de30 100644
--- a/crypto/evp/legacy_sha.c
+++ b/crypto/evp/legacy_sha.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -16,6 +16,76 @@
 #include  /* diverse SHA macros */
 #include "internal/sha3.h" /* KECCAK1600_WIDTH */
 #include "crypto/evp.h"
+/* Used by legacy methods */
+#include "crypto/sha.h"
+#include "legacy_meth.h"
+#include "evp_local.h"
+
+/*-
+ * LEGACY methods for SHA.
+ * These only remain to support engines that can get these methods.
+ * Hardware support for SHA3 has been removed from these legacy cases.
+ */
+#define IMPLEMENT_LEGACY_EVP_MD_METH_SHA3(nm, fn, tag)                                 \
+    static int nm##_init(EVP_MD_CTX *ctx)                                              \
+    {                                                                                  \
+        return fn##_init(EVP_MD_CTX_get0_md_data(ctx), tag, ctx->digest->md_size * 8); \
+    }                                                                                  \
+    static int nm##_update(EVP_MD_CTX *ctx, const void *data, size_t count)            \
+    {                                                                                  \
+        return fn##_update(EVP_MD_CTX_get0_md_data(ctx), data, count);                 \
+    }                                                                                  \
+    static int nm##_final(EVP_MD_CTX *ctx, unsigned char *md)                          \
+    {                                                                                  \
+        KECCAK1600_CTX *kctx = EVP_MD_CTX_get0_md_data(ctx);                           \
+        return fn##_final(kctx, md, kctx->md_size);                                    \
+    }
+#define IMPLEMENT_LEGACY_EVP_MD_METH_SHAKE(nm, fn, tag)                                \
+    static int nm##_init(EVP_MD_CTX *ctx)                                              \
+    {                                                                                  \
+        return fn##_init(EVP_MD_CTX_get0_md_data(ctx), tag, ctx->digest->md_size * 8); \
+    }
+
+#define sha512_224_Init sha512_224_init
+#define sha512_256_Init sha512_256_init
+
+#define sha512_224_Update SHA512_Update
+#define sha512_224_Final SHA512_Final
+#define sha512_256_Update SHA512_Update
+#define sha512_256_Final SHA512_Final
+
+IMPLEMENT_LEGACY_EVP_MD_METH(sha1, SHA1)
+IMPLEMENT_LEGACY_EVP_MD_METH(sha224, SHA224)
+IMPLEMENT_LEGACY_EVP_MD_METH(sha256, SHA256)
+IMPLEMENT_LEGACY_EVP_MD_METH(sha384, SHA384)
+IMPLEMENT_LEGACY_EVP_MD_METH(sha512, SHA512)
+IMPLEMENT_LEGACY_EVP_MD_METH(sha512_224_int, sha512_224)
+IMPLEMENT_LEGACY_EVP_MD_METH(sha512_256_int, sha512_256)
+IMPLEMENT_LEGACY_EVP_MD_METH_SHA3(sha3_int, ossl_sha3, '\x06')
+IMPLEMENT_LEGACY_EVP_MD_METH_SHAKE(shake, ossl_sha3, '\x1f')
+
+static int sha1_int_ctrl(EVP_MD_CTX *ctx, int cmd, int p1, void *p2)
+{
+    return ossl_sha1_ctrl(ctx != NULL ? EVP_MD_CTX_get0_md_data(ctx) : NULL,
+        cmd, p1, p2);
+}
+
+static int shake_ctrl(EVP_MD_CTX *evp_ctx, int cmd, int p1, void *p2)
+{
+    KECCAK1600_CTX *ctx;
+
+    if (evp_ctx == NULL)
+        return 0;
+    ctx = evp_ctx->md_data;
+
+    switch (cmd) {
+    case EVP_MD_CTRL_XOF_LEN:
+        ctx->md_size = p1;
+        return 1;
+    default:
+        return 0;
+    }
+}
 
 static const EVP_MD sha1_md = {
     NID_sha1,
@@ -23,7 +93,8 @@ static const EVP_MD sha1_md = {
     SHA_DIGEST_LENGTH,
     EVP_MD_FLAG_DIGALGID_ABSENT,
     EVP_ORIG_GLOBAL,
-    SHA_CBLOCK
+    LEGACY_EVP_MD_METH_TABLE(sha1_init, sha1_update, sha1_final, sha1_int_ctrl,
+        SHA_CBLOCK),
 };
 
 const EVP_MD *EVP_sha1(void)
@@ -37,7 +108,8 @@ static const EVP_MD sha224_md = {
     SHA224_DIGEST_LENGTH,
     EVP_MD_FLAG_DIGALGID_ABSENT,
     EVP_ORIG_GLOBAL,
-    SHA256_CBLOCK
+    LEGACY_EVP_MD_METH_TABLE(sha224_init, sha224_update, sha224_final, NULL,
+        SHA256_CBLOCK),
 };
 
 const EVP_MD *EVP_sha224(void)
@@ -51,7 +123,8 @@ static const EVP_MD sha256_md = {
     SHA256_DIGEST_LENGTH,
     EVP_MD_FLAG_DIGALGID_ABSENT,
     EVP_ORIG_GLOBAL,
-    SHA256_CBLOCK
+    LEGACY_EVP_MD_METH_TABLE(sha256_init, sha256_update, sha256_final, NULL,
+        SHA256_CBLOCK),
 };
 
 const EVP_MD *EVP_sha256(void)
@@ -65,7 +138,8 @@ static const EVP_MD sha512_224_md = {
     SHA224_DIGEST_LENGTH,
     EVP_MD_FLAG_DIGALGID_ABSENT,
     EVP_ORIG_GLOBAL,
-    SHA512_CBLOCK
+    LEGACY_EVP_MD_METH_TABLE(sha512_224_int_init, sha512_224_int_update,
+        sha512_224_int_final, NULL, SHA512_CBLOCK),
 };
 
 const EVP_MD *EVP_sha512_224(void)
@@ -79,7 +153,8 @@ static const EVP_MD sha512_256_md = {
     SHA256_DIGEST_LENGTH,
     EVP_MD_FLAG_DIGALGID_ABSENT,
     EVP_ORIG_GLOBAL,
-    SHA512_CBLOCK
+    LEGACY_EVP_MD_METH_TABLE(sha512_256_int_init, sha512_256_int_update,
+        sha512_256_int_final, NULL, SHA512_CBLOCK),
 };
 
 const EVP_MD *EVP_sha512_256(void)
@@ -93,7 +168,8 @@ static const EVP_MD sha384_md = {
     SHA384_DIGEST_LENGTH,
     EVP_MD_FLAG_DIGALGID_ABSENT,
     EVP_ORIG_GLOBAL,
-    SHA512_CBLOCK
+    LEGACY_EVP_MD_METH_TABLE(sha384_init, sha384_update, sha384_final, NULL,
+        SHA512_CBLOCK),
 };
 
 const EVP_MD *EVP_sha384(void)
@@ -107,7 +183,8 @@ static const EVP_MD sha512_md = {
     SHA512_DIGEST_LENGTH,
     EVP_MD_FLAG_DIGALGID_ABSENT,
     EVP_ORIG_GLOBAL,
-    SHA512_CBLOCK
+    LEGACY_EVP_MD_METH_TABLE(sha512_init, sha512_update, sha512_final, NULL,
+        SHA512_CBLOCK),
 };
 
 const EVP_MD *EVP_sha512(void)
@@ -115,31 +192,34 @@ const EVP_MD *EVP_sha512(void)
     return &sha512_md;
 }
 
-#define EVP_MD_SHA3(bitlen)                        \
-    const EVP_MD *EVP_sha3_##bitlen(void)          \
-    {                                              \
-        static const EVP_MD sha3_##bitlen##_md = { \
-            NID_sha3_##bitlen,                     \
-            NID_RSA_SHA3_##bitlen,                 \
-            bitlen / 8,                            \
-            EVP_MD_FLAG_DIGALGID_ABSENT,           \
-            EVP_ORIG_GLOBAL,                       \
-            (KECCAK1600_WIDTH - bitlen * 2) / 8    \
-        };                                         \
-        return &sha3_##bitlen##_md;                \
+#define EVP_MD_SHA3(bitlen)                                          \
+    const EVP_MD *EVP_sha3_##bitlen(void)                            \
+    {                                                                \
+        static const EVP_MD sha3_##bitlen##_md = {                   \
+            NID_sha3_##bitlen,                                       \
+            NID_RSA_SHA3_##bitlen,                                   \
+            bitlen / 8,                                              \
+            EVP_MD_FLAG_DIGALGID_ABSENT,                             \
+            EVP_ORIG_GLOBAL,                                         \
+            LEGACY_EVP_MD_METH_TABLE(sha3_int_init, sha3_int_update, \
+                sha3_int_final, NULL,                                \
+                (KECCAK1600_WIDTH - bitlen * 2) / 8),                \
+        };                                                           \
+        return &sha3_##bitlen##_md;                                  \
     }
-#define EVP_MD_SHAKE(bitlen)                               \
-    const EVP_MD *EVP_shake##bitlen(void)                  \
-    {                                                      \
-        static const EVP_MD shake##bitlen##_md = {         \
-            NID_shake##bitlen,                             \
-            0,                                             \
-            bitlen / 8,                                    \
-            EVP_MD_FLAG_XOF | EVP_MD_FLAG_DIGALGID_ABSENT, \
-            EVP_ORIG_GLOBAL,                               \
-            (KECCAK1600_WIDTH - bitlen * 2) / 8            \
-        };                                                 \
-        return &shake##bitlen##_md;                        \
+#define EVP_MD_SHAKE(bitlen)                                                      \
+    const EVP_MD *EVP_shake##bitlen(void)                                         \
+    {                                                                             \
+        static const EVP_MD shake##bitlen##_md = {                                \
+            NID_shake##bitlen,                                                    \
+            0,                                                                    \
+            bitlen / 8,                                                           \
+            EVP_MD_FLAG_XOF | EVP_MD_FLAG_DIGALGID_ABSENT,                        \
+            EVP_ORIG_GLOBAL,                                                      \
+            LEGACY_EVP_MD_METH_TABLE(shake_init, sha3_int_update, sha3_int_final, \
+                shake_ctrl, (KECCAK1600_WIDTH - bitlen * 2) / 8),                 \
+        };                                                                        \
+        return &shake##bitlen##_md;                                               \
     }
 
 EVP_MD_SHA3(224)
diff --git a/crypto/evp/legacy_wp.c b/crypto/evp/legacy_wp.c
index 15aeee78b6..21865e6350 100644
--- a/crypto/evp/legacy_wp.c
+++ b/crypto/evp/legacy_wp.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2005-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2005-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,6 +15,9 @@
 
 #include 
 #include "crypto/evp.h"
+#include "legacy_meth.h"
+
+IMPLEMENT_LEGACY_EVP_MD_METH(wp, WHIRLPOOL)
 
 static const EVP_MD whirlpool_md = {
     NID_whirlpool,
@@ -22,7 +25,8 @@ static const EVP_MD whirlpool_md = {
     WHIRLPOOL_DIGEST_LENGTH,
     0,
     EVP_ORIG_GLOBAL,
-    WHIRLPOOL_BBLOCK / 8
+    LEGACY_EVP_MD_METH_TABLE(wp_init, wp_update, wp_final, NULL,
+        WHIRLPOOL_BBLOCK / 8),
 };
 
 const EVP_MD *EVP_whirlpool(void)
diff --git a/crypto/evp/m_null.c b/crypto/evp/m_null.c
index 642fe9ec1e..7b310d7047 100644
--- a/crypto/evp/m_null.c
+++ b/crypto/evp/m_null.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,14 +7,41 @@
  * https://www.openssl.org/source/license.html
  */
 
+#include 
+#include "internal/cryptlib.h"
+#include 
+#include 
+#include 
 #include "crypto/evp.h"
 
+static int init(EVP_MD_CTX *ctx)
+{
+    return 1;
+}
+
+static int update(EVP_MD_CTX *ctx, const void *data, size_t count)
+{
+    return 1;
+}
+
+static int final(EVP_MD_CTX *ctx, unsigned char *md)
+{
+    return 1;
+}
+
 static const EVP_MD null_md = {
     NID_undef,
     NID_undef,
     0,
     0,
-    EVP_ORIG_GLOBAL
+    EVP_ORIG_GLOBAL,
+    init,
+    update,
+    final,
+    NULL,
+    NULL,
+    0,
+    sizeof(EVP_MD *),
 };
 
 const EVP_MD *EVP_md_null(void)
diff --git a/crypto/evp/m_sigver.c b/crypto/evp/m_sigver.c
index a79d656804..d37f8a0f77 100644
--- a/crypto/evp/m_sigver.c
+++ b/crypto/evp/m_sigver.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -17,6 +17,12 @@
 #include "internal/common.h"
 #include "evp_local.h"
 
+static int update(EVP_MD_CTX *ctx, const void *data, size_t datalen)
+{
+    ERR_raise(ERR_LIB_EVP, EVP_R_ONLY_ONESHOT_SUPPORTED);
+    return 0;
+}
+
 /*
  * If we get the "NULL" md then the name comes back as "UNDEF". We want to use
  * NULL for this.
@@ -61,7 +67,7 @@ static int do_sigver_init(EVP_MD_CTX *ctx, EVP_PKEY_CTX **pctx,
     ERR_set_mark();
 
     if (evp_pkey_ctx_is_legacy(locpctx))
-        goto notsupported;
+        goto legacy;
 
     /* do not reinitialize if pkey is set or operation is different */
     if (reinit
@@ -131,9 +137,7 @@ static int do_sigver_init(EVP_MD_CTX *ctx, EVP_PKEY_CTX **pctx,
          * iteration we're on.
          */
         EVP_SIGNATURE_free(signature);
-        signature = NULL;
         EVP_KEYMGMT_free(tmp_keymgmt);
-        tmp_keymgmt = NULL;
 
         switch (iter) {
         case 1:
@@ -147,7 +151,7 @@ static int do_sigver_init(EVP_MD_CTX *ctx, EVP_PKEY_CTX **pctx,
             signature = evp_signature_fetch_from_prov((OSSL_PROVIDER *)tmp_prov,
                 supported_sig, locpctx->propquery);
             if (signature == NULL)
-                goto notsupported;
+                goto legacy;
             break;
         }
         if (signature == NULL)
@@ -219,6 +223,8 @@ reinitialize:
              */
             evp_md_ctx_clear_digest(ctx, 1, 0);
 
+            /* legacy code support for engines */
+            ERR_set_mark();
             /*
              * This might be requested by a later call to EVP_MD_CTX_get0_md().
              * In that case the "explicit fetch" rules apply for that
@@ -229,11 +235,16 @@ reinitialize:
             ctx->fetched_digest = EVP_MD_fetch(locpctx->libctx, mdname, props);
             if (ctx->fetched_digest != NULL) {
                 ctx->digest = ctx->reqdigest = ctx->fetched_digest;
+            } else {
+                /* legacy engine support : remove the mark when this is deleted */
+                ctx->reqdigest = ctx->digest = EVP_get_digestbyname(mdname);
                 if (ctx->digest == NULL) {
+                    (void)ERR_clear_last_mark();
                     ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
                     goto err;
                 }
             }
+            (void)ERR_pop_to_mark();
         }
     }
 
@@ -260,13 +271,8 @@ reinitialize:
      * If the operation was not a success and no digest was found, an error
      * needs to be raised.
      */
-    if (ret > 0 || mdname != NULL) {
-        if (ret > 0)
-            ret = evp_pkey_ctx_use_cached_data(locpctx);
-
-        EVP_KEYMGMT_free(tmp_keymgmt);
-        return ret > 0 ? 1 : 0;
-    }
+    if (ret > 0 || mdname != NULL)
+        goto end;
     if (type == NULL) /* This check is redundant but clarifies matters */
         ERR_raise(ERR_LIB_EVP, EVP_R_NO_DEFAULT_DIGEST);
     ERR_raise_data(ERR_LIB_EVP, EVP_R_PROVIDER_SIGNATURE_FAILURE,
@@ -279,14 +285,85 @@ err:
     EVP_KEYMGMT_free(tmp_keymgmt);
     return 0;
 
-notsupported:
+legacy:
+    /*
+     * If we don't have the full support we need with provided methods,
+     * let's go see if legacy does.
+     */
     ERR_pop_to_mark();
     EVP_KEYMGMT_free(tmp_keymgmt);
+    tmp_keymgmt = NULL;
 
-    ERR_raise_data(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE,
-        ver ? "%s digest_verify_init" : "%s digest_sign_init",
-        EVP_PKEY_get0_type_name(locpctx->pkey));
-    return 0;
+    if (type == NULL && mdname != NULL)
+        type = evp_get_digestbyname_ex(locpctx->libctx, mdname);
+
+    if (ctx->pctx->pmeth == NULL) {
+        ERR_raise_data(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE,
+            ver ? "%s digest_verify_init" : "%s digest_sign_init",
+            EVP_PKEY_get0_type_name(locpctx->pkey));
+        return 0;
+    }
+
+    if (!(ctx->pctx->pmeth->flags & EVP_PKEY_FLAG_SIGCTX_CUSTOM)) {
+
+        if (type == NULL) {
+            int def_nid;
+            if (EVP_PKEY_get_default_digest_nid(pkey, &def_nid) > 0)
+                type = EVP_get_digestbynid(def_nid);
+        }
+
+        if (type == NULL) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_NO_DEFAULT_DIGEST);
+            return 0;
+        }
+    }
+
+    if (ver) {
+        if (ctx->pctx->pmeth->verifyctx_init) {
+            if (ctx->pctx->pmeth->verifyctx_init(ctx->pctx, ctx) <= 0)
+                return 0;
+            ctx->pctx->operation = EVP_PKEY_OP_VERIFYCTX;
+        } else if (ctx->pctx->pmeth->digestverify != 0) {
+            ctx->pctx->operation = EVP_PKEY_OP_VERIFY;
+            ctx->update = update;
+        } else if (EVP_PKEY_verify_init(ctx->pctx) <= 0) {
+            return 0;
+        }
+    } else {
+        if (ctx->pctx->pmeth->signctx_init) {
+            if (ctx->pctx->pmeth->signctx_init(ctx->pctx, ctx) <= 0)
+                return 0;
+            ctx->pctx->operation = EVP_PKEY_OP_SIGNCTX;
+        } else if (ctx->pctx->pmeth->digestsign != 0) {
+            ctx->pctx->operation = EVP_PKEY_OP_SIGN;
+            ctx->update = update;
+        } else if (EVP_PKEY_sign_init(ctx->pctx) <= 0) {
+            return 0;
+        }
+    }
+    if (EVP_PKEY_CTX_set_signature_md(ctx->pctx, type) <= 0)
+        return 0;
+    if (pctx)
+        *pctx = ctx->pctx;
+    if (ctx->pctx->pmeth->flags & EVP_PKEY_FLAG_SIGCTX_CUSTOM)
+        return 1;
+    if (!EVP_DigestInit_ex(ctx, type, NULL))
+        return 0;
+    /*
+     * This indicates the current algorithm requires
+     * special treatment before hashing the tbs-message.
+     */
+    ctx->pctx->flag_call_digest_custom = 0;
+    if (ctx->pctx->pmeth->digest_custom != NULL)
+        ctx->pctx->flag_call_digest_custom = 1;
+
+    ret = 1;
+end:
+    if (ret > 0)
+        ret = evp_pkey_ctx_use_cached_data(locpctx);
+
+    EVP_KEYMGMT_free(tmp_keymgmt);
+    return ret > 0 ? 1 : 0;
 }
 
 int EVP_DigestSignInit_ex(EVP_MD_CTX *ctx, EVP_PKEY_CTX **pctx,
@@ -337,15 +414,11 @@ int EVP_DigestSignUpdate(EVP_MD_CTX *ctx, const void *data, size_t dsize)
         return 0;
     }
 
-    if (pctx == NULL)
-        return EVP_DigestUpdate(ctx, data, dsize);
-
-    if (pctx->operation != EVP_PKEY_OP_SIGNCTX
+    if (pctx == NULL
+        || pctx->operation != EVP_PKEY_OP_SIGNCTX
         || pctx->op.sig.algctx == NULL
-        || pctx->op.sig.signature == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
-        return 0;
-    }
+        || pctx->op.sig.signature == NULL)
+        goto legacy;
 
     signature = pctx->op.sig.signature;
     desc = signature->description != NULL ? signature->description : "";
@@ -362,6 +435,21 @@ int EVP_DigestSignUpdate(EVP_MD_CTX *ctx, const void *data, size_t dsize)
             "%s digest_sign_update:%s", signature->type_name, desc);
     ERR_clear_last_mark();
     return ret;
+
+legacy:
+    if (pctx != NULL) {
+        if (pctx->pmeth == NULL) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
+            return 0;
+        }
+        /* do_sigver_init() checked that |digest_custom| is non-NULL */
+        if (pctx->flag_call_digest_custom
+            && !ctx->pctx->pmeth->digest_custom(ctx->pctx, ctx))
+            return 0;
+        pctx->flag_call_digest_custom = 0;
+    }
+
+    return EVP_DigestUpdate(ctx, data, dsize);
 }
 
 int EVP_DigestVerifyUpdate(EVP_MD_CTX *ctx, const void *data, size_t dsize)
@@ -380,7 +468,7 @@ int EVP_DigestVerifyUpdate(EVP_MD_CTX *ctx, const void *data, size_t dsize)
         || pctx->operation != EVP_PKEY_OP_VERIFYCTX
         || pctx->op.sig.algctx == NULL
         || pctx->op.sig.signature == NULL)
-        return EVP_DigestUpdate(ctx, data, dsize);
+        goto legacy;
 
     signature = pctx->op.sig.signature;
     desc = signature->description != NULL ? signature->description : "";
@@ -397,6 +485,17 @@ int EVP_DigestVerifyUpdate(EVP_MD_CTX *ctx, const void *data, size_t dsize)
             "%s digest_verify_update:%s", signature->type_name, desc);
     ERR_clear_last_mark();
     return ret;
+
+legacy:
+    if (pctx != NULL) {
+        /* do_sigver_init() checked that |digest_custom| is non-NULL */
+        if (pctx->flag_call_digest_custom
+            && !ctx->pctx->pmeth->digest_custom(ctx->pctx, ctx))
+            return 0;
+        pctx->flag_call_digest_custom = 0;
+    }
+
+    return EVP_DigestUpdate(ctx, data, dsize);
 }
 
 int EVP_DigestSignFinal(EVP_MD_CTX *ctx, unsigned char *sigret,
@@ -404,6 +503,7 @@ int EVP_DigestSignFinal(EVP_MD_CTX *ctx, unsigned char *sigret,
 {
     EVP_SIGNATURE *signature;
     const char *desc;
+    int sctx = 0;
     int r = 0;
     EVP_PKEY_CTX *dctx = NULL, *pctx = ctx->pctx;
 
@@ -415,10 +515,8 @@ int EVP_DigestSignFinal(EVP_MD_CTX *ctx, unsigned char *sigret,
     if (pctx == NULL
         || pctx->operation != EVP_PKEY_OP_SIGNCTX
         || pctx->op.sig.algctx == NULL
-        || pctx->op.sig.signature == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
-        return 0;
-    }
+        || pctx->op.sig.signature == NULL)
+        goto legacy;
 
     signature = pctx->op.sig.signature;
     desc = signature->description != NULL ? signature->description : "";
@@ -447,6 +545,79 @@ int EVP_DigestSignFinal(EVP_MD_CTX *ctx, unsigned char *sigret,
     else
         EVP_PKEY_CTX_free(dctx);
     return r;
+
+legacy:
+    if (pctx == NULL || pctx->pmeth == NULL) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
+        return 0;
+    }
+
+    /* do_sigver_init() checked that |digest_custom| is non-NULL */
+    if (pctx->flag_call_digest_custom
+        && !ctx->pctx->pmeth->digest_custom(ctx->pctx, ctx))
+        return 0;
+    pctx->flag_call_digest_custom = 0;
+
+    if (pctx->pmeth->flags & EVP_PKEY_FLAG_SIGCTX_CUSTOM) {
+        if (sigret == NULL)
+            return pctx->pmeth->signctx(pctx, sigret, siglen, ctx);
+        if ((ctx->flags & EVP_MD_CTX_FLAG_FINALISE) != 0) {
+            r = pctx->pmeth->signctx(pctx, sigret, siglen, ctx);
+            ctx->flags |= EVP_MD_CTX_FLAG_FINALISED;
+        } else {
+            dctx = EVP_PKEY_CTX_dup(pctx);
+            if (dctx == NULL)
+                return 0;
+            r = dctx->pmeth->signctx(dctx, sigret, siglen, ctx);
+            EVP_PKEY_CTX_free(dctx);
+        }
+        return r;
+    }
+    if (pctx->pmeth->signctx != NULL)
+        sctx = 1;
+    else
+        sctx = 0;
+    if (sigret != NULL) {
+        unsigned char md[EVP_MAX_MD_SIZE];
+        unsigned int mdlen = 0;
+
+        if (ctx->flags & EVP_MD_CTX_FLAG_FINALISE) {
+            if (sctx)
+                r = pctx->pmeth->signctx(pctx, sigret, siglen, ctx);
+            else
+                r = EVP_DigestFinal_ex(ctx, md, &mdlen);
+        } else {
+            EVP_MD_CTX *tmp_ctx = EVP_MD_CTX_new();
+
+            if (tmp_ctx == NULL)
+                return 0;
+            if (!EVP_MD_CTX_copy_ex(tmp_ctx, ctx)) {
+                EVP_MD_CTX_free(tmp_ctx);
+                return 0;
+            }
+            if (sctx)
+                r = tmp_ctx->pctx->pmeth->signctx(tmp_ctx->pctx,
+                    sigret, siglen, tmp_ctx);
+            else
+                r = EVP_DigestFinal_ex(tmp_ctx, md, &mdlen);
+            EVP_MD_CTX_free(tmp_ctx);
+        }
+        if (sctx || !r)
+            return r;
+        if (EVP_PKEY_sign(pctx, sigret, siglen, md, mdlen) <= 0)
+            return 0;
+    } else {
+        if (sctx) {
+            if (pctx->pmeth->signctx(pctx, sigret, siglen, ctx) <= 0)
+                return 0;
+        } else {
+            int s = EVP_MD_get_size(ctx->digest);
+
+            if (s <= 0 || EVP_PKEY_sign(pctx, sigret, siglen, NULL, s) <= 0)
+                return 0;
+        }
+    }
+    return 1;
 }
 
 int EVP_DigestSign(EVP_MD_CTX *ctx, unsigned char *sigret, size_t *siglen,
@@ -484,6 +655,10 @@ int EVP_DigestSign(EVP_MD_CTX *ctx, unsigned char *sigret, size_t *siglen,
             ERR_clear_last_mark();
             return ret;
         }
+    } else {
+        /* legacy */
+        if (pctx->pmeth != NULL && pctx->pmeth->digestsign != NULL)
+            return pctx->pmeth->digestsign(ctx, sigret, siglen, tbs, tbslen);
     }
 
     if (sigret != NULL && EVP_DigestSignUpdate(ctx, tbs, tbslen) <= 0)
@@ -496,6 +671,9 @@ int EVP_DigestVerifyFinal(EVP_MD_CTX *ctx, const unsigned char *sig,
 {
     EVP_SIGNATURE *signature;
     const char *desc;
+    int vctx = 0;
+    unsigned int mdlen = 0;
+    unsigned char md[EVP_MAX_MD_SIZE];
     int r = 0;
     EVP_PKEY_CTX *dctx = NULL, *pctx = ctx->pctx;
 
@@ -507,10 +685,8 @@ int EVP_DigestVerifyFinal(EVP_MD_CTX *ctx, const unsigned char *sig,
     if (pctx == NULL
         || pctx->operation != EVP_PKEY_OP_VERIFYCTX
         || pctx->op.sig.algctx == NULL
-        || pctx->op.sig.signature == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
-        return 0;
-    }
+        || pctx->op.sig.signature == NULL)
+        goto legacy;
 
     signature = pctx->op.sig.signature;
     desc = signature->description != NULL ? signature->description : "";
@@ -538,6 +714,47 @@ int EVP_DigestVerifyFinal(EVP_MD_CTX *ctx, const unsigned char *sig,
     else
         EVP_PKEY_CTX_free(dctx);
     return r;
+
+legacy:
+    if (pctx == NULL || pctx->pmeth == NULL) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
+        return 0;
+    }
+
+    /* do_sigver_init() checked that |digest_custom| is non-NULL */
+    if (pctx->flag_call_digest_custom
+        && !ctx->pctx->pmeth->digest_custom(ctx->pctx, ctx))
+        return 0;
+    pctx->flag_call_digest_custom = 0;
+
+    if (pctx->pmeth->verifyctx != NULL)
+        vctx = 1;
+    else
+        vctx = 0;
+    if (ctx->flags & EVP_MD_CTX_FLAG_FINALISE) {
+        if (vctx) {
+            r = pctx->pmeth->verifyctx(pctx, sig, (int)siglen, ctx);
+            ctx->flags |= EVP_MD_CTX_FLAG_FINALISED;
+        } else
+            r = EVP_DigestFinal_ex(ctx, md, &mdlen);
+    } else {
+        EVP_MD_CTX *tmp_ctx = EVP_MD_CTX_new();
+        if (tmp_ctx == NULL)
+            return -1;
+        if (!EVP_MD_CTX_copy_ex(tmp_ctx, ctx)) {
+            EVP_MD_CTX_free(tmp_ctx);
+            return -1;
+        }
+        if (vctx)
+            r = tmp_ctx->pctx->pmeth->verifyctx(tmp_ctx->pctx,
+                sig, (int)siglen, tmp_ctx);
+        else
+            r = EVP_DigestFinal_ex(tmp_ctx, md, &mdlen);
+        EVP_MD_CTX_free(tmp_ctx);
+    }
+    if (vctx || !r)
+        return r;
+    return EVP_PKEY_verify(pctx, sig, siglen, md, mdlen);
 }
 
 int EVP_DigestVerify(EVP_MD_CTX *ctx, const unsigned char *sigret,
@@ -572,8 +789,11 @@ int EVP_DigestVerify(EVP_MD_CTX *ctx, const unsigned char *sigret,
             ERR_clear_last_mark();
             return ret;
         }
+    } else {
+        /* legacy */
+        if (pctx->pmeth != NULL && pctx->pmeth->digestverify != NULL)
+            return pctx->pmeth->digestverify(ctx, sigret, siglen, tbs, tbslen);
     }
-
     if (EVP_DigestVerifyUpdate(ctx, tbs, tbslen) <= 0)
         return -1;
     return EVP_DigestVerifyFinal(ctx, sigret, siglen);
diff --git a/crypto/evp/mac_meth.c b/crypto/evp/mac_meth.c
index 2a6fb0abe5..201ebf7852 100644
--- a/crypto/evp/mac_meth.c
+++ b/crypto/evp/mac_meth.c
@@ -11,17 +11,28 @@
 #include 
 #include 
 #include 
+#include 
 #include "internal/provider.h"
 #include "internal/core.h"
 #include "crypto/evp.h"
 #include "evp_local.h"
 
+static void evp_mac_free_int(EVP_MAC *mac)
+{
+    OPENSSL_free(mac->type_name);
+    ossl_provider_free(mac->prov);
+    CRYPTO_FREE_REF(&mac->refcnt);
+    OPENSSL_free(mac);
+}
+
 static int evp_mac_up_ref(void *vmac)
 {
     EVP_MAC *mac = vmac;
     int ref = 0;
 
-    return CRYPTO_UP_REF(&mac->refcnt, &ref);
+    if (mac->origin == EVP_ORIG_DYNAMIC)
+        CRYPTO_UP_REF(&mac->refcnt, &ref);
+    return 1;
 }
 
 static void evp_mac_free(void *vmac)
@@ -29,16 +40,54 @@ static void evp_mac_free(void *vmac)
     EVP_MAC *mac = vmac;
     int ref = 0;
 
-    if (mac == NULL)
+    if (mac == NULL || mac->origin != EVP_ORIG_DYNAMIC)
         return;
 
     CRYPTO_DOWN_REF(&mac->refcnt, &ref);
     if (ref > 0)
         return;
-    OPENSSL_free(mac->type_name);
-    ossl_provider_free(mac->prov);
-    CRYPTO_FREE_REF(&mac->refcnt);
-    OPENSSL_free(mac);
+    evp_mac_free_int(mac);
+}
+
+static void *evp_mac_dup_frozen(void *vin)
+{
+    EVP_MAC *in = vin;
+    EVP_MAC *out;
+
+    out = OPENSSL_malloc(sizeof(*out));
+    if (out == NULL)
+        return NULL;
+    memcpy(out, in, sizeof(*out));
+    if (!CRYPTO_NEW_REF(&out->refcnt, 1))
+        goto err;
+    out->type_name = OPENSSL_strdup(in->type_name);
+    if (out->type_name == NULL)
+        goto err;
+    out->origin = EVP_ORIG_FROZEN;
+    if (out->prov == NULL || !ossl_provider_up_ref(out->prov)) {
+        OPENSSL_free(out->type_name);
+        goto err;
+    }
+    return out;
+
+err:
+    CRYPTO_FREE_REF(&out->refcnt);
+    OPENSSL_free(out);
+    return NULL;
+}
+
+static void evp_mac_frozen_free(void *vin)
+{
+    EVP_MAC *mac = vin;
+    int ref = 0;
+
+    if (mac == NULL || mac->origin != EVP_ORIG_FROZEN)
+        return;
+
+    CRYPTO_DOWN_REF(&mac->refcnt, &ref);
+    if (ref > 0)
+        return;
+    evp_mac_free_int(mac);
 }
 
 static void *evp_mac_new(void)
@@ -55,7 +104,7 @@ static void *evp_mac_new(void)
 
 static void *evp_mac_from_algorithm(int name_id,
     const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, int no_store)
+    OSSL_PROVIDER *prov)
 {
     const OSSL_DISPATCH *fns = algodef->implementation;
     EVP_MAC *mac = NULL;
@@ -66,7 +115,6 @@ static void *evp_mac_from_algorithm(int name_id,
         goto err;
     }
     mac->name_id = name_id;
-    mac->no_store = no_store;
 
     if ((mac->type_name = ossl_algorithm_get1_first_name(algodef)) == NULL)
         goto err;
@@ -175,30 +223,33 @@ err:
 EVP_MAC *EVP_MAC_fetch(OSSL_LIB_CTX *libctx, const char *algorithm,
     const char *properties)
 {
-    return evp_generic_fetch(libctx, OSSL_OP_MAC, algorithm, properties,
-        evp_mac_from_algorithm, evp_mac_up_ref,
-        evp_mac_free);
+    return evp_generic_fetch(libctx, OSSL_OP_MAC,
+        algorithm, properties,
+        evp_mac_from_algorithm,
+        evp_mac_up_ref,
+        evp_mac_free,
+        evp_mac_dup_frozen,
+        evp_mac_frozen_free);
+}
+
+int evp_mac_fetch_all(OSSL_LIB_CTX *ctx)
+{
+    return evp_generic_fetch_all(ctx, OSSL_OP_MAC,
+        evp_mac_from_algorithm,
+        evp_mac_up_ref,
+        evp_mac_free,
+        evp_mac_dup_frozen,
+        evp_mac_frozen_free);
 }
 
 int EVP_MAC_up_ref(EVP_MAC *mac)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
     return evp_mac_up_ref(mac);
-#else
-    if (mac->no_store != 0)
-        return evp_mac_up_ref(mac);
-    return 1;
-#endif
 }
 
 void EVP_MAC_free(EVP_MAC *mac)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
     evp_mac_free(mac);
-#else
-    if (mac != NULL && (mac->no_store != 0))
-        evp_mac_free(mac);
-#endif
 }
 
 const OSSL_PROVIDER *EVP_MAC_get0_provider(const EVP_MAC *mac)
@@ -257,12 +308,8 @@ void EVP_MAC_do_all_provided(OSSL_LIB_CTX *libctx,
     void (*fn)(EVP_MAC *mac, void *arg),
     void *arg)
 {
-    struct EVP_MAC_do_all_provided_thunk t;
-
-    t.fn = fn;
-    t.arg = arg;
     evp_generic_do_all(libctx, OSSL_OP_MAC,
-        EVP_MAC_do_all_provided_thunk, &t,
+        (void (*)(void *, void *))fn, arg,
         evp_mac_from_algorithm, evp_mac_up_ref, evp_mac_free);
 }
 
@@ -274,5 +321,7 @@ EVP_MAC *evp_mac_fetch_from_prov(OSSL_PROVIDER *prov,
         algorithm, properties,
         evp_mac_from_algorithm,
         evp_mac_up_ref,
-        evp_mac_free);
+        evp_mac_free,
+        evp_mac_dup_frozen,
+        evp_mac_frozen_free);
 }
diff --git a/crypto/evp/names.c b/crypto/evp/names.c
index 81029feb87..0129732542 100644
--- a/crypto/evp/names.c
+++ b/crypto/evp/names.c
@@ -190,6 +190,8 @@ void evp_cleanup_int(void)
 
     EVP_PBE_cleanup();
     OBJ_sigid_free();
+
+    evp_app_cleanup_int();
 }
 
 struct doall_cipher {
diff --git a/crypto/evp/p5_crpt.c b/crypto/evp/p5_crpt.c
index 1fc24fcd52..570544c798 100644
--- a/crypto/evp/p5_crpt.c
+++ b/crypto/evp/p5_crpt.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,8 +15,6 @@
 #include 
 #include 
 
-#include 
-
 /*
  * Doesn't do anything now: Builtin PBE algorithms in static table.
  */
diff --git a/crypto/evp/p5_crpt2.c b/crypto/evp/p5_crpt2.c
index acffe82e51..c944496339 100644
--- a/crypto/evp/p5_crpt2.c
+++ b/crypto/evp/p5_crpt2.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -19,19 +19,17 @@
 #include "crypto/evp.h"
 #include "evp_local.h"
 
-#include 
-
 int ossl_pkcs5_pbkdf2_hmac_ex(const char *pass, int passlen,
     const unsigned char *salt, int saltlen, int iter,
     const EVP_MD *digest, int keylen, unsigned char *out,
     OSSL_LIB_CTX *libctx, const char *propq)
 {
     const char *empty = "";
-    int rv = 1;
+    int rv = 1, mode = 1;
     EVP_KDF *kdf;
     EVP_KDF_CTX *kctx;
     const char *mdname = EVP_MD_get0_name(digest);
-    OSSL_PARAM params[5], *p = params;
+    OSSL_PARAM params[6], *p = params;
 
     /* Keep documented behaviour. */
     if (pass == NULL) {
@@ -52,6 +50,7 @@ int ossl_pkcs5_pbkdf2_hmac_ex(const char *pass, int passlen,
         return 0;
     *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_PASSWORD,
         (char *)pass, (size_t)passlen);
+    *p++ = OSSL_PARAM_construct_int(OSSL_KDF_PARAM_PKCS5, &mode);
     *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT,
         (unsigned char *)salt, saltlen);
     *p++ = OSSL_PARAM_construct_int(OSSL_KDF_PARAM_ITER, &iter);
@@ -118,7 +117,8 @@ int PKCS5_v2_PBE_keyivgen_ex(EVP_CIPHER_CTX *ctx, const char *pass, int passlen,
 {
     PBE2PARAM *pbe2 = NULL;
     char ciph_name[80];
-    EVP_CIPHER *cipher = NULL;
+    const EVP_CIPHER *cipher = NULL;
+    EVP_CIPHER *cipher_fetch = NULL;
     EVP_PBE_KEYGEN_EX *kdf;
 
     int rv = 0;
@@ -144,7 +144,11 @@ int PKCS5_v2_PBE_keyivgen_ex(EVP_CIPHER_CTX *ctx, const char *pass, int passlen,
         goto err;
     }
 
-    cipher = EVP_CIPHER_fetch(libctx, ciph_name, propq);
+    (void)ERR_set_mark();
+    cipher = cipher_fetch = EVP_CIPHER_fetch(libctx, ciph_name, propq);
+    /* Fallback to legacy method */
+    if (cipher == NULL)
+        cipher = EVP_get_cipherbyname(ciph_name);
 
     if (cipher == NULL) {
         (void)ERR_clear_last_mark();
@@ -162,7 +166,7 @@ int PKCS5_v2_PBE_keyivgen_ex(EVP_CIPHER_CTX *ctx, const char *pass, int passlen,
     }
     rv = kdf(ctx, pass, passlen, pbe2->keyfunc->parameter, NULL, NULL, en_de, libctx, propq);
 err:
-    EVP_CIPHER_free(cipher);
+    EVP_CIPHER_free(cipher_fetch);
     PBE2PARAM_free(pbe2);
     return rv;
 }
@@ -185,7 +189,8 @@ int PKCS5_v2_PBKDF2_keyivgen_ex(EVP_CIPHER_CTX *ctx, const char *pass,
     unsigned int keylen = 0;
     int prf_nid, hmac_md_nid;
     PBKDF2PARAM *kdf = NULL;
-    EVP_MD *prfmd = NULL;
+    const EVP_MD *prfmd = NULL;
+    EVP_MD *prfmd_fetch = NULL;
 
     if (EVP_CIPHER_CTX_get0_cipher(ctx) == NULL) {
         ERR_raise(ERR_LIB_EVP, EVP_R_NO_CIPHER_SET);
@@ -227,11 +232,16 @@ int PKCS5_v2_PBKDF2_keyivgen_ex(EVP_CIPHER_CTX *ctx, const char *pass,
         goto err;
     }
 
-    prfmd = EVP_MD_fetch(libctx, OBJ_nid2sn(hmac_md_nid), propq);
+    (void)ERR_set_mark();
+    prfmd = prfmd_fetch = EVP_MD_fetch(libctx, OBJ_nid2sn(hmac_md_nid), propq);
+    if (prfmd == NULL)
+        prfmd = EVP_get_digestbynid(hmac_md_nid);
     if (prfmd == NULL) {
+        (void)ERR_clear_last_mark();
         ERR_raise(ERR_LIB_EVP, EVP_R_UNSUPPORTED_PRF);
         goto err;
     }
+    (void)ERR_pop_to_mark();
 
     if (kdf->salt->type != V_ASN1_OCTET_STRING) {
         ERR_raise(ERR_LIB_EVP, EVP_R_UNSUPPORTED_SALT_TYPE);
@@ -249,7 +259,7 @@ int PKCS5_v2_PBKDF2_keyivgen_ex(EVP_CIPHER_CTX *ctx, const char *pass,
 err:
     OPENSSL_cleanse(key, keylen);
     PBKDF2PARAM_free(kdf);
-    EVP_MD_free(prfmd);
+    EVP_MD_free(prfmd_fetch);
     return rv;
 }
 
diff --git a/crypto/evp/p_lib.c b/crypto/evp/p_lib.c
index f13390b54e..df4ca9bce1 100644
--- a/crypto/evp/p_lib.c
+++ b/crypto/evp/p_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -31,7 +31,6 @@
 #include 
 #include 
 #include 
-#include 
 
 #include "internal/numbers.h" /* includes SIZE_MAX */
 #include "internal/ffc.h"
@@ -1518,9 +1517,9 @@ static int pkey_set_type(EVP_PKEY *pkey, int type, const char *str,
     }
 #ifndef FIPS_MODULE
     if (str != NULL)
-        ameth = evp_pkey_asn1_find_str(str, len);
+        ameth = EVP_PKEY_asn1_find_str(NULL, str, len);
     else if (type != EVP_PKEY_NONE)
-        ameth = evp_pkey_asn1_find(type);
+        ameth = EVP_PKEY_asn1_find(NULL, type);
 #endif
 
     {
@@ -1630,7 +1629,7 @@ int EVP_PKEY_up_ref(EVP_PKEY *pkey)
 {
     int i;
 
-    if (!CRYPTO_UP_REF(&pkey->references, &i))
+    if (CRYPTO_UP_REF(&pkey->references, &i) <= 0)
         return 0;
 
     REF_PRINT_COUNT("EVP_PKEY", i, pkey);
@@ -1705,7 +1704,7 @@ void evp_pkey_free_legacy(EVP_PKEY *x)
     const EVP_PKEY_ASN1_METHOD *ameth = x->ameth;
 
     if (ameth == NULL && x->legacy_cache_pkey.ptr != NULL)
-        ameth = evp_pkey_asn1_find(x->type);
+        ameth = EVP_PKEY_asn1_find(NULL, x->type);
 
     if (ameth != NULL) {
         if (x->legacy_cache_pkey.ptr != NULL) {
@@ -1860,8 +1859,6 @@ void *evp_pkey_export_to_provider(EVP_PKEY *pk, OSSL_LIB_CTX *libctx,
 #ifndef FIPS_MODULE
     if (pk->pkey.ptr != NULL) {
         OP_CACHE_ELEM *op;
-        OSSL_PARAM params[2] = { OSSL_PARAM_END, OSSL_PARAM_END };
-        OSSL_PARAM *p = NULL;
 
         /*
          * If the legacy "origin" hasn't changed since last time, we try
@@ -1900,29 +1897,11 @@ void *evp_pkey_export_to_provider(EVP_PKEY *pk, OSSL_LIB_CTX *libctx,
         if (!EVP_KEYMGMT_is_a(tmp_keymgmt, OBJ_nid2sn(pk->type)))
             goto end;
 
-        if (strcmp(OSSL_PROVIDER_get0_name(EVP_KEYMGMT_get0_provider(tmp_keymgmt)), "default") == 0) {
-            /*
-             * We attempt to pass the low-level object to the keymgmt. We only
-             * support this via an internal use only parameter. We break the
-             * normal rules that prevent passing complex objects via OSSL_PARAM,
-             * but this is only for the default provider where we can get away
-             * with this. This is necessary here for backwards compatibility
-             * reasons.
-             */
-            params[0] = OSSL_PARAM_construct_octet_ptr("legacy-object",
-                &pk->pkey.ptr, sizeof(pk->pkey.ptr));
-            p = params;
-        }
-        keydata = evp_keymgmt_newdata(tmp_keymgmt, p);
-        if (keydata == NULL)
+        if ((keydata = evp_keymgmt_newdata(tmp_keymgmt)) == NULL)
             goto end;
 
-        /*
-         * We skip the export if the key data we got back is actually the same
-         * as the low level object we passed in
-         */
-        if (keydata != pk->pkey.ptr
-            && !pk->ameth->export_to(pk, keydata, tmp_keymgmt->import, libctx, propquery)) {
+        if (!pk->ameth->export_to(pk, keydata, tmp_keymgmt->import,
+                libctx, propquery)) {
             evp_keymgmt_freedata(tmp_keymgmt, keydata);
             keydata = NULL;
             goto end;
@@ -1942,10 +1921,14 @@ void *evp_pkey_export_to_provider(EVP_PKEY *pk, OSSL_LIB_CTX *libctx,
 
         if (!CRYPTO_THREAD_write_lock(pk->lock))
             goto end;
-
-        if (pk->ameth->dirty_cnt(pk) != pk->dirty_cnt_copy)
-            evp_keymgmt_util_clear_operation_cache(pk);
-
+        if (pk->ameth->dirty_cnt(pk) != pk->dirty_cnt_copy
+            && !evp_keymgmt_util_clear_operation_cache(pk)) {
+            CRYPTO_THREAD_unlock(pk->lock);
+            evp_keymgmt_freedata(tmp_keymgmt, keydata);
+            keydata = NULL;
+            EVP_KEYMGMT_free(tmp_keymgmt);
+            goto end;
+        }
         EVP_KEYMGMT_free(tmp_keymgmt); /* refcnt-- */
 
         /* Check to make sure some other thread didn't get there first */
@@ -2405,10 +2388,13 @@ int EVP_PKEY_get_ec_point_conv_form(const EVP_PKEY *pkey)
         /* Might work through the legacy route */
         const EC_KEY *ec = EVP_PKEY_get0_EC_KEY(pkey);
 
-        if (ec != NULL)
-            return EC_KEY_get_conv_form(ec);
-#endif
+        if (ec == NULL)
+            return 0;
+
+        return EC_KEY_get_conv_form(ec);
+#else
         return 0;
+#endif
     }
 
     if (!EVP_PKEY_get_utf8_string_param(pkey,
diff --git a/crypto/evp/pmeth_check.c b/crypto/evp/pmeth_check.c
index 376998e5ac..ebab82809c 100644
--- a/crypto/evp/pmeth_check.c
+++ b/crypto/evp/pmeth_check.c
@@ -59,6 +59,22 @@ static int evp_pkey_public_check_combined(EVP_PKEY_CTX *ctx, int checktype)
         != -1)
         return ok;
 
+    if (pkey->type == EVP_PKEY_NONE)
+        goto not_supported;
+
+#ifndef FIPS_MODULE
+    /* legacy */
+    /* call customized public key check function first */
+    if (ctx->pmeth->public_check != NULL)
+        return ctx->pmeth->public_check(pkey);
+
+    /* use default public key check function in ameth */
+    if (pkey->ameth == NULL || pkey->ameth->pkey_public_check == NULL)
+        goto not_supported;
+
+    return pkey->ameth->pkey_public_check(pkey);
+#endif
+not_supported:
     ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
     return -2;
 }
@@ -89,6 +105,22 @@ static int evp_pkey_param_check_combined(EVP_PKEY_CTX *ctx, int checktype)
         != -1)
         return ok;
 
+    if (pkey->type == EVP_PKEY_NONE)
+        goto not_supported;
+
+#ifndef FIPS_MODULE
+    /* legacy */
+    /* call customized param check function first */
+    if (ctx->pmeth->param_check != NULL)
+        return ctx->pmeth->param_check(pkey);
+
+    /* use default param check function in ameth */
+    if (pkey->ameth == NULL || pkey->ameth->pkey_param_check == NULL)
+        goto not_supported;
+
+    return pkey->ameth->pkey_param_check(pkey);
+#endif
+not_supported:
     ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
     return -2;
 }
@@ -143,6 +175,22 @@ int EVP_PKEY_pairwise_check(EVP_PKEY_CTX *ctx)
         != -1)
         return ok;
 
+    if (pkey->type == EVP_PKEY_NONE)
+        goto not_supported;
+
+#ifndef FIPS_MODULE
+    /* legacy */
+    /* call customized check function first */
+    if (ctx->pmeth->check != NULL)
+        return ctx->pmeth->check(pkey);
+
+    /* use default check function in ameth */
+    if (pkey->ameth == NULL || pkey->ameth->pkey_check == NULL)
+        goto not_supported;
+
+    return pkey->ameth->pkey_check(pkey);
+#endif
+not_supported:
     ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
     return -2;
 }
diff --git a/crypto/evp/pmeth_gn.c b/crypto/evp/pmeth_gn.c
index c8ca005e94..0351990a78 100644
--- a/crypto/evp/pmeth_gn.c
+++ b/crypto/evp/pmeth_gn.c
@@ -34,7 +34,7 @@ static int gen_init(EVP_PKEY_CTX *ctx, int operation)
     ctx->operation = operation;
 
     if (ctx->keymgmt == NULL || ctx->keymgmt->gen_init == NULL)
-        goto not_supported;
+        goto legacy;
 
     switch (operation) {
     case EVP_PKEY_OP_PARAMGEN:
@@ -53,6 +53,30 @@ static int gen_init(EVP_PKEY_CTX *ctx, int operation)
         ret = 1;
     goto end;
 
+legacy:
+#ifdef FIPS_MODULE
+    goto not_supported;
+#else
+    if (ctx->pmeth == NULL
+        || (operation == EVP_PKEY_OP_PARAMGEN
+            && ctx->pmeth->paramgen == NULL)
+        || (operation == EVP_PKEY_OP_KEYGEN
+            && ctx->pmeth->keygen == NULL))
+        goto not_supported;
+
+    ret = 1;
+    switch (operation) {
+    case EVP_PKEY_OP_PARAMGEN:
+        if (ctx->pmeth->paramgen_init != NULL)
+            ret = ctx->pmeth->paramgen_init(ctx);
+        break;
+    case EVP_PKEY_OP_KEYGEN:
+        if (ctx->pmeth->keygen_init != NULL)
+            ret = ctx->pmeth->keygen_init(ctx);
+        break;
+    }
+#endif
+
 end:
     if (ret <= 0 && ctx != NULL) {
         evp_pkey_ctx_free_old_ops(ctx);
@@ -125,7 +149,7 @@ int EVP_PKEY_generate(EVP_PKEY_CTX *ctx, EVP_PKEY **ppkey)
     }
 
     if (ctx->op.keymgmt.genctx == NULL)
-        goto not_supported;
+        goto legacy;
 
     /*
      * Assigning gentmp to ctx->keygen_info is something our legacy
@@ -179,6 +203,33 @@ int EVP_PKEY_generate(EVP_PKEY_CTX *ctx, EVP_PKEY **ppkey)
 
     goto end;
 
+legacy:
+#ifdef FIPS_MODULE
+    goto not_supported;
+#else
+    /*
+     * If we get here then we're using legacy paramgen/keygen. In that case
+     * the pkey in ctx (if there is one) had better not be provided (because the
+     * legacy methods may not know how to handle it). However we can only get
+     * here if ctx->op.keymgmt.genctx == NULL, but that should never be the case
+     * if ctx->pkey is provided because we don't allow this when we initialise
+     * the ctx.
+     */
+    if (ctx->pkey != NULL && !ossl_assert(!evp_pkey_is_provided(ctx->pkey)))
+        goto not_accessible;
+
+    switch (ctx->operation) {
+    case EVP_PKEY_OP_PARAMGEN:
+        ret = ctx->pmeth->paramgen(ctx, *ppkey);
+        break;
+    case EVP_PKEY_OP_KEYGEN:
+        ret = ctx->pmeth->keygen(ctx, *ppkey);
+        break;
+    default:
+        goto not_supported;
+    }
+#endif
+
 end:
     if (ret <= 0) {
         if (allocated_pkey != NULL)
@@ -195,6 +246,12 @@ not_initialized:
     ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_INITIALIZED);
     ret = -1;
     goto end;
+#ifndef FIPS_MODULE
+not_accessible:
+    ERR_raise(ERR_LIB_EVP, EVP_R_INACCESSIBLE_DOMAIN_PARAMETERS);
+    ret = -1;
+    goto end;
+#endif
 }
 
 int EVP_PKEY_paramgen(EVP_PKEY_CTX *ctx, EVP_PKEY **ppkey)
diff --git a/crypto/evp/pmeth_lib.c b/crypto/evp/pmeth_lib.c
index 963e0615c2..70abf69b81 100644
--- a/crypto/evp/pmeth_lib.c
+++ b/crypto/evp/pmeth_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -43,6 +43,94 @@ static void evp_pkey_ctx_free_cached_data(EVP_PKEY_CTX *ctx,
     int cmd, const char *name);
 static void evp_pkey_ctx_free_all_cached_data(EVP_PKEY_CTX *ctx);
 
+typedef const EVP_PKEY_METHOD *(*pmeth_fn)(void);
+typedef int sk_cmp_fn_type(const char *const *a, const char *const *b);
+
+static STACK_OF(EVP_PKEY_METHOD) *app_pkey_methods = NULL;
+
+/* This array needs to be in order of NIDs */
+static pmeth_fn standard_methods[] = {
+    ossl_rsa_pkey_method,
+#ifndef OPENSSL_NO_DH
+    ossl_dh_pkey_method,
+#endif
+#ifndef OPENSSL_NO_DSA
+    ossl_dsa_pkey_method,
+#endif
+#ifndef OPENSSL_NO_EC
+    ossl_ec_pkey_method,
+#endif
+    ossl_rsa_pss_pkey_method,
+#ifndef OPENSSL_NO_DH
+    ossl_dhx_pkey_method,
+#endif
+#ifndef OPENSSL_NO_ECX
+    ossl_ecx25519_pkey_method,
+    ossl_ecx448_pkey_method,
+    ossl_ed25519_pkey_method,
+    ossl_ed448_pkey_method,
+#endif
+};
+
+DECLARE_OBJ_BSEARCH_CMP_FN(const EVP_PKEY_METHOD *, pmeth_fn, pmeth_func);
+
+static int pmeth_func_cmp(const EVP_PKEY_METHOD *const *a, pmeth_fn const *b)
+{
+    return ((*a)->pkey_id - ((**b)())->pkey_id);
+}
+
+IMPLEMENT_OBJ_BSEARCH_CMP_FN(const EVP_PKEY_METHOD *, pmeth_fn, pmeth_func);
+
+static int pmeth_cmp(const EVP_PKEY_METHOD *const *a,
+    const EVP_PKEY_METHOD *const *b)
+{
+    return ((*a)->pkey_id - (*b)->pkey_id);
+}
+
+static const EVP_PKEY_METHOD *evp_pkey_meth_find_added_by_application(int type)
+{
+    if (app_pkey_methods != NULL) {
+        int idx;
+        EVP_PKEY_METHOD tmp;
+
+        tmp.pkey_id = type;
+        idx = sk_EVP_PKEY_METHOD_find(app_pkey_methods, &tmp);
+        if (idx >= 0)
+            return sk_EVP_PKEY_METHOD_value(app_pkey_methods, idx);
+    }
+    return NULL;
+}
+
+const EVP_PKEY_METHOD *EVP_PKEY_meth_find(int type)
+{
+    pmeth_fn *ret;
+    EVP_PKEY_METHOD tmp;
+    const EVP_PKEY_METHOD *t;
+
+    if ((t = evp_pkey_meth_find_added_by_application(type)) != NULL)
+        return t;
+
+    tmp.pkey_id = type;
+    t = &tmp;
+    ret = OBJ_bsearch_pmeth_func(&t, standard_methods,
+        OSSL_NELEM(standard_methods));
+    if (ret == NULL || *ret == NULL)
+        return NULL;
+    return (**ret)();
+}
+
+EVP_PKEY_METHOD *EVP_PKEY_meth_new(int id, int flags)
+{
+    EVP_PKEY_METHOD *pmeth;
+
+    pmeth = OPENSSL_zalloc(sizeof(*pmeth));
+    if (pmeth == NULL)
+        return NULL;
+
+    pmeth->pkey_id = id;
+    pmeth->flags = flags | EVP_PKEY_FLAG_DYNAMIC;
+    return pmeth;
+}
 #endif /* FIPS_MODULE */
 
 int evp_pkey_ctx_state(const EVP_PKEY_CTX *ctx)
@@ -68,8 +156,10 @@ int evp_pkey_ctx_state(const EVP_PKEY_CTX *ctx)
 static EVP_PKEY_CTX *int_ctx_new(OSSL_LIB_CTX *libctx, EVP_PKEY *pkey,
     const char *keytype, const char *propquery,
     int id)
+
 {
     EVP_PKEY_CTX *ret = NULL;
+    const EVP_PKEY_METHOD *pmeth = NULL, *app_pmeth = NULL;
     EVP_KEYMGMT *keymgmt = NULL;
 
     /* Code below to be removed when legacy support is dropped. */
@@ -91,6 +181,9 @@ static EVP_PKEY_CTX *int_ctx_new(OSSL_LIB_CTX *libctx, EVP_PKEY *pkey,
 #endif
         }
     }
+    /* If no ID was found here, we can only resort to find a keymgmt */
+    if (id == -1)
+        goto common;
 
 #ifndef FIPS_MODULE
     /*
@@ -98,13 +191,22 @@ static EVP_PKEY_CTX *int_ctx_new(OSSL_LIB_CTX *libctx, EVP_PKEY *pkey,
      * supporting usage with implementations from providers, to make
      * for a smooth transition from legacy stuff to provider based stuff.
      */
-    if (id != -1)
+    if (pkey == NULL || pkey->foreign == 0)
         keytype = OBJ_nid2sn(id);
 
+    if (pkey != NULL && pkey->foreign)
+        pmeth = EVP_PKEY_meth_find(id);
+    else
+        app_pmeth = pmeth = evp_pkey_meth_find_added_by_application(id);
+
     /* END legacy */
 #endif /* FIPS_MODULE */
-    /* We try fetching a provider implementation. */
-    if (keytype != NULL) {
+common:
+    /*
+     * If there's no app supplied pmeth and there's a name, we try
+     * fetching a provider implementation.
+     */
+    if (app_pmeth == NULL && keytype != NULL) {
         /*
          * If |pkey| is given and is provided, we take a reference to its
          * keymgmt.  Otherwise, we fetch one for the keytype we got. This
@@ -152,7 +254,7 @@ static EVP_PKEY_CTX *int_ctx_new(OSSL_LIB_CTX *libctx, EVP_PKEY *pkey,
 #endif
     }
 
-    if (keymgmt == NULL) {
+    if (pmeth == NULL && keymgmt == NULL) {
         ERR_raise(ERR_LIB_EVP, EVP_R_UNSUPPORTED_ALGORITHM);
     } else {
         ret = OPENSSL_zalloc(sizeof(*ret));
@@ -174,6 +276,7 @@ static EVP_PKEY_CTX *int_ctx_new(OSSL_LIB_CTX *libctx, EVP_PKEY *pkey,
     ret->keytype = keytype;
     ret->keymgmt = keymgmt;
     ret->legacy_keytype = id;
+    ret->pmeth = pmeth;
     ret->operation = EVP_PKEY_OP_UNDEFINED;
 
     if (pkey != NULL && !EVP_PKEY_up_ref(pkey)) {
@@ -183,6 +286,14 @@ static EVP_PKEY_CTX *int_ctx_new(OSSL_LIB_CTX *libctx, EVP_PKEY *pkey,
 
     ret->pkey = pkey;
 
+    if (pmeth != NULL && pmeth->init != NULL) {
+        if (pmeth->init(ret) <= 0) {
+            ret->pmeth = NULL;
+            EVP_PKEY_CTX_free(ret);
+            return NULL;
+        }
+    }
+
     return ret;
 }
 
@@ -237,6 +348,8 @@ void EVP_PKEY_CTX_free(EVP_PKEY_CTX *ctx)
 {
     if (ctx == NULL)
         return;
+    if (ctx->pmeth && ctx->pmeth->cleanup)
+        ctx->pmeth->cleanup(ctx);
 
     evp_pkey_ctx_free_old_ops(ctx);
 #ifndef FIPS_MODULE
@@ -252,6 +365,34 @@ void EVP_PKEY_CTX_free(EVP_PKEY_CTX *ctx)
 }
 
 #ifndef FIPS_MODULE
+
+void EVP_PKEY_meth_get0_info(int *ppkey_id, int *pflags,
+    const EVP_PKEY_METHOD *meth)
+{
+    if (ppkey_id)
+        *ppkey_id = meth->pkey_id;
+    if (pflags)
+        *pflags = meth->flags;
+}
+
+void EVP_PKEY_meth_copy(EVP_PKEY_METHOD *dst, const EVP_PKEY_METHOD *src)
+{
+    int pkey_id = dst->pkey_id;
+    int flags = dst->flags;
+
+    *dst = *src;
+
+    /* We only copy the function pointers so restore the other values */
+    dst->pkey_id = pkey_id;
+    dst->flags = flags;
+}
+
+void EVP_PKEY_meth_free(EVP_PKEY_METHOD *pmeth)
+{
+    if (pmeth && (pmeth->flags & EVP_PKEY_FLAG_DYNAMIC))
+        OPENSSL_free(pmeth);
+}
+
 EVP_PKEY_CTX *EVP_PKEY_CTX_new(EVP_PKEY *pkey, ENGINE *e)
 {
     if (!ossl_assert(e == NULL))
@@ -384,39 +525,99 @@ EVP_PKEY_CTX *EVP_PKEY_CTX_dup(const EVP_PKEY_CTX *pctx)
         goto err;
     }
 
+    rctx->pmeth = pctx->pmeth;
+
     if (pctx->peerkey != NULL && !EVP_PKEY_up_ref(pctx->peerkey))
         goto err;
 
     rctx->peerkey = pctx->peerkey;
 
-    if (rctx->operation == EVP_PKEY_OP_UNDEFINED) {
-        EVP_KEYMGMT *tmp_keymgmt = pctx->keymgmt;
-        void *provkey;
+    if (pctx->pmeth == NULL) {
+        if (rctx->operation == EVP_PKEY_OP_UNDEFINED) {
+            EVP_KEYMGMT *tmp_keymgmt = pctx->keymgmt;
+            void *provkey;
 
-        if (pctx->pkey == NULL)
+            if (pctx->pkey == NULL)
+                return rctx;
+
+            provkey = evp_pkey_export_to_provider(pctx->pkey, pctx->libctx,
+                &tmp_keymgmt, pctx->propquery);
+            if (provkey == NULL)
+                goto err;
+            if (!EVP_KEYMGMT_up_ref(tmp_keymgmt))
+                goto err;
+            EVP_KEYMGMT_free(rctx->keymgmt);
+            rctx->keymgmt = tmp_keymgmt;
             return rctx;
-
-        provkey = evp_pkey_export_to_provider(pctx->pkey, pctx->libctx,
-            &tmp_keymgmt, pctx->propquery);
-        if (provkey == NULL)
-            goto err;
-        if (!EVP_KEYMGMT_up_ref(tmp_keymgmt))
-            goto err;
-        EVP_KEYMGMT_free(rctx->keymgmt);
-        rctx->keymgmt = tmp_keymgmt;
+        }
+    } else if (pctx->pmeth->copy(rctx, pctx) > 0) {
         return rctx;
     }
 err:
+    rctx->pmeth = NULL;
     EVP_PKEY_CTX_free(rctx);
     return NULL;
 }
+
+int EVP_PKEY_meth_add0(const EVP_PKEY_METHOD *pmeth)
+{
+    if (app_pkey_methods == NULL) {
+        app_pkey_methods = sk_EVP_PKEY_METHOD_new(pmeth_cmp);
+        if (app_pkey_methods == NULL) {
+            ERR_raise(ERR_LIB_EVP, ERR_R_CRYPTO_LIB);
+            return 0;
+        }
+    }
+    if (!sk_EVP_PKEY_METHOD_push(app_pkey_methods, pmeth)) {
+        ERR_raise(ERR_LIB_EVP, ERR_R_CRYPTO_LIB);
+        return 0;
+    }
+    sk_EVP_PKEY_METHOD_sort(app_pkey_methods);
+    return 1;
+}
+
+void evp_app_cleanup_int(void)
+{
+    if (app_pkey_methods != NULL)
+        sk_EVP_PKEY_METHOD_pop_free(app_pkey_methods, EVP_PKEY_meth_free);
+}
+
+int EVP_PKEY_meth_remove(const EVP_PKEY_METHOD *pmeth)
+{
+    const EVP_PKEY_METHOD *ret;
+
+    ret = sk_EVP_PKEY_METHOD_delete_ptr(app_pkey_methods, pmeth);
+
+    return ret == NULL ? 0 : 1;
+}
+
+size_t EVP_PKEY_meth_get_count(void)
+{
+    size_t rv = OSSL_NELEM(standard_methods);
+
+    if (app_pkey_methods)
+        rv += sk_EVP_PKEY_METHOD_num(app_pkey_methods);
+    return rv;
+}
+
+const EVP_PKEY_METHOD *EVP_PKEY_meth_get0(size_t idx)
+{
+    if (idx < OSSL_NELEM(standard_methods))
+        return (standard_methods[idx])();
+    if (app_pkey_methods == NULL)
+        return NULL;
+    idx -= OSSL_NELEM(standard_methods);
+    if (idx >= (size_t)sk_EVP_PKEY_METHOD_num(app_pkey_methods))
+        return NULL;
+    return sk_EVP_PKEY_METHOD_value(app_pkey_methods, (int)idx);
+}
 #endif
 
 int EVP_PKEY_CTX_is_a(EVP_PKEY_CTX *ctx, const char *keytype)
 {
 #ifndef FIPS_MODULE
     if (evp_pkey_ctx_is_legacy(ctx))
-        return (ctx->legacy_keytype == evp_pkey_name2type(keytype));
+        return (ctx->pmeth->pkey_id == evp_pkey_name2type(keytype));
 #endif
     return EVP_KEYMGMT_is_a(ctx->keymgmt, keytype);
 }
@@ -1048,14 +1249,21 @@ static int evp_pkey_ctx_ctrl_int(EVP_PKEY_CTX *ctx, int keytype, int optype,
 {
     int ret = 0;
 
-    if (ctx->operation == EVP_PKEY_OP_UNDEFINED) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_NO_OPERATION_SET);
-        return -1;
-    }
+    /*
+     * If the method has a |digest_custom| function, we can relax the
+     * operation type check, since this can be called before the operation
+     * is initialized.
+     */
+    if (ctx->pmeth == NULL || ctx->pmeth->digest_custom == NULL) {
+        if (ctx->operation == EVP_PKEY_OP_UNDEFINED) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_NO_OPERATION_SET);
+            return -1;
+        }
 
-    if ((optype != -1) && !(ctx->operation & optype)) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_OPERATION);
-        return -1;
+        if ((optype != -1) && !(ctx->operation & optype)) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_OPERATION);
+            return -1;
+        }
     }
 
     switch (evp_pkey_ctx_state(ctx)) {
@@ -1063,8 +1271,18 @@ static int evp_pkey_ctx_ctrl_int(EVP_PKEY_CTX *ctx, int keytype, int optype,
         return evp_pkey_ctx_ctrl_to_param(ctx, keytype, optype, cmd, p1, p2);
     case EVP_PKEY_STATE_UNKNOWN:
     case EVP_PKEY_STATE_LEGACY:
-        ERR_raise(ERR_LIB_EVP, EVP_R_COMMAND_NOT_SUPPORTED);
-        return -2;
+        if (ctx->pmeth == NULL || ctx->pmeth->ctrl == NULL) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_COMMAND_NOT_SUPPORTED);
+            return -2;
+        }
+        if ((keytype != -1) && (ctx->pmeth->pkey_id != keytype))
+            return -1;
+
+        ret = ctx->pmeth->ctrl(ctx, cmd, p1, p2);
+
+        if (ret == -2)
+            ERR_raise(ERR_LIB_EVP, EVP_R_COMMAND_NOT_SUPPORTED);
+        break;
     }
     return ret;
 }
@@ -1118,8 +1336,17 @@ static int evp_pkey_ctx_ctrl_str_int(EVP_PKEY_CTX *ctx,
         return evp_pkey_ctx_ctrl_str_to_param(ctx, name, value);
     case EVP_PKEY_STATE_UNKNOWN:
     case EVP_PKEY_STATE_LEGACY:
-        ERR_raise(ERR_LIB_EVP, EVP_R_COMMAND_NOT_SUPPORTED);
-        return -2;
+        if (ctx == NULL || ctx->pmeth == NULL || ctx->pmeth->ctrl_str == NULL) {
+            ERR_raise(ERR_LIB_EVP, EVP_R_COMMAND_NOT_SUPPORTED);
+            return -2;
+        }
+        if (strcmp(name, "digest") == 0)
+            ret = EVP_PKEY_CTX_md(ctx,
+                EVP_PKEY_OP_TYPE_SIG | EVP_PKEY_OP_TYPE_CRYPT,
+                EVP_PKEY_CTRL_MD, value);
+        else
+            ret = ctx->pmeth->ctrl_str(ctx, name, value);
+        break;
     }
 
     return ret;
@@ -1199,8 +1426,15 @@ static int evp_pkey_ctx_store_cached_data(EVP_PKEY_CTX *ctx,
             break;
         case EVP_PKEY_STATE_UNKNOWN:
         case EVP_PKEY_STATE_LEGACY:
-            ERR_raise(ERR_LIB_EVP, EVP_R_COMMAND_NOT_SUPPORTED);
-            return -2;
+            if (ctx->pmeth == NULL) {
+                ERR_raise(ERR_LIB_EVP, EVP_R_COMMAND_NOT_SUPPORTED);
+                return -2;
+            }
+            if (EVP_PKEY_type(ctx->pmeth->pkey_id) != EVP_PKEY_type(keytype)) {
+                ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_OPERATION);
+                return -1;
+            }
+            break;
         }
     }
     if (optype != -1 && (ctx->operation & optype) == 0) {
@@ -1216,7 +1450,7 @@ static int evp_pkey_ctx_store_cached_data(EVP_PKEY_CTX *ctx,
             if (ctx->cached_parameters.dist_id_name == NULL)
                 return 0;
         }
-        if (data != NULL) {
+        if (data_len > 0) {
             ctx->cached_parameters.dist_id = OPENSSL_memdup(data, data_len);
             if (ctx->cached_parameters.dist_id == NULL)
                 return 0;
@@ -1308,7 +1542,7 @@ int EVP_PKEY_CTX_str2ctrl(EVP_PKEY_CTX *ctx, int cmd, const char *str)
     len = strlen(str);
     if (len > INT_MAX)
         return -1;
-    return EVP_PKEY_CTX_ctrl(ctx, -1, -1, cmd, (int)len, (void *)str);
+    return ctx->pmeth->ctrl(ctx, cmd, (int)len, (void *)str);
 }
 
 int EVP_PKEY_CTX_hex2ctrl(EVP_PKEY_CTX *ctx, int cmd, const char *hex)
@@ -1321,7 +1555,7 @@ int EVP_PKEY_CTX_hex2ctrl(EVP_PKEY_CTX *ctx, int cmd, const char *hex)
     if (bin == NULL)
         return 0;
     if (binlen <= INT_MAX)
-        rv = EVP_PKEY_CTX_ctrl(ctx, -1, -1, cmd, binlen, bin);
+        rv = ctx->pmeth->ctrl(ctx, cmd, binlen, bin);
     OPENSSL_free(bin);
     return rv;
 }
@@ -1378,4 +1612,401 @@ void *EVP_PKEY_CTX_get_app_data(EVP_PKEY_CTX *ctx)
 {
     return ctx->app_data;
 }
+
+void EVP_PKEY_meth_set_init(EVP_PKEY_METHOD *pmeth,
+    int (*init)(EVP_PKEY_CTX *ctx))
+{
+    pmeth->init = init;
+}
+
+void EVP_PKEY_meth_set_copy(EVP_PKEY_METHOD *pmeth,
+    int (*copy)(EVP_PKEY_CTX *dst,
+        const EVP_PKEY_CTX *src))
+{
+    pmeth->copy = copy;
+}
+
+void EVP_PKEY_meth_set_cleanup(EVP_PKEY_METHOD *pmeth,
+    void (*cleanup)(EVP_PKEY_CTX *ctx))
+{
+    pmeth->cleanup = cleanup;
+}
+
+void EVP_PKEY_meth_set_paramgen(EVP_PKEY_METHOD *pmeth,
+    int (*paramgen_init)(EVP_PKEY_CTX *ctx),
+    int (*paramgen)(EVP_PKEY_CTX *ctx,
+        EVP_PKEY *pkey))
+{
+    pmeth->paramgen_init = paramgen_init;
+    pmeth->paramgen = paramgen;
+}
+
+void EVP_PKEY_meth_set_keygen(EVP_PKEY_METHOD *pmeth,
+    int (*keygen_init)(EVP_PKEY_CTX *ctx),
+    int (*keygen)(EVP_PKEY_CTX *ctx,
+        EVP_PKEY *pkey))
+{
+    pmeth->keygen_init = keygen_init;
+    pmeth->keygen = keygen;
+}
+
+void EVP_PKEY_meth_set_sign(EVP_PKEY_METHOD *pmeth,
+    int (*sign_init)(EVP_PKEY_CTX *ctx),
+    int (*sign)(EVP_PKEY_CTX *ctx,
+        unsigned char *sig, size_t *siglen,
+        const unsigned char *tbs,
+        size_t tbslen))
+{
+    pmeth->sign_init = sign_init;
+    pmeth->sign = sign;
+}
+
+void EVP_PKEY_meth_set_verify(EVP_PKEY_METHOD *pmeth,
+    int (*verify_init)(EVP_PKEY_CTX *ctx),
+    int (*verify)(EVP_PKEY_CTX *ctx,
+        const unsigned char *sig,
+        size_t siglen,
+        const unsigned char *tbs,
+        size_t tbslen))
+{
+    pmeth->verify_init = verify_init;
+    pmeth->verify = verify;
+}
+
+void EVP_PKEY_meth_set_verify_recover(EVP_PKEY_METHOD *pmeth,
+    int (*verify_recover_init)(EVP_PKEY_CTX
+            *ctx),
+    int (*verify_recover)(EVP_PKEY_CTX
+                              *ctx,
+        unsigned char
+            *sig,
+        size_t *siglen,
+        const unsigned char *tbs,
+        size_t tbslen))
+{
+    pmeth->verify_recover_init = verify_recover_init;
+    pmeth->verify_recover = verify_recover;
+}
+
+void EVP_PKEY_meth_set_signctx(EVP_PKEY_METHOD *pmeth,
+    int (*signctx_init)(EVP_PKEY_CTX *ctx,
+        EVP_MD_CTX *mctx),
+    int (*signctx)(EVP_PKEY_CTX *ctx,
+        unsigned char *sig,
+        size_t *siglen,
+        EVP_MD_CTX *mctx))
+{
+    pmeth->signctx_init = signctx_init;
+    pmeth->signctx = signctx;
+}
+
+void EVP_PKEY_meth_set_verifyctx(EVP_PKEY_METHOD *pmeth,
+    int (*verifyctx_init)(EVP_PKEY_CTX *ctx,
+        EVP_MD_CTX *mctx),
+    int (*verifyctx)(EVP_PKEY_CTX *ctx,
+        const unsigned char *sig,
+        int siglen,
+        EVP_MD_CTX *mctx))
+{
+    pmeth->verifyctx_init = verifyctx_init;
+    pmeth->verifyctx = verifyctx;
+}
+
+void EVP_PKEY_meth_set_encrypt(EVP_PKEY_METHOD *pmeth,
+    int (*encrypt_init)(EVP_PKEY_CTX *ctx),
+    int (*encryptfn)(EVP_PKEY_CTX *ctx,
+        unsigned char *out,
+        size_t *outlen,
+        const unsigned char *in,
+        size_t inlen))
+{
+    pmeth->encrypt_init = encrypt_init;
+    pmeth->encrypt = encryptfn;
+}
+
+void EVP_PKEY_meth_set_decrypt(EVP_PKEY_METHOD *pmeth,
+    int (*decrypt_init)(EVP_PKEY_CTX *ctx),
+    int (*decrypt)(EVP_PKEY_CTX *ctx,
+        unsigned char *out,
+        size_t *outlen,
+        const unsigned char *in,
+        size_t inlen))
+{
+    pmeth->decrypt_init = decrypt_init;
+    pmeth->decrypt = decrypt;
+}
+
+void EVP_PKEY_meth_set_derive(EVP_PKEY_METHOD *pmeth,
+    int (*derive_init)(EVP_PKEY_CTX *ctx),
+    int (*derive)(EVP_PKEY_CTX *ctx,
+        unsigned char *key,
+        size_t *keylen))
+{
+    pmeth->derive_init = derive_init;
+    pmeth->derive = derive;
+}
+
+void EVP_PKEY_meth_set_ctrl(EVP_PKEY_METHOD *pmeth,
+    int (*ctrl)(EVP_PKEY_CTX *ctx, int type, int p1,
+        void *p2),
+    int (*ctrl_str)(EVP_PKEY_CTX *ctx,
+        const char *type,
+        const char *value))
+{
+    pmeth->ctrl = ctrl;
+    pmeth->ctrl_str = ctrl_str;
+}
+
+void EVP_PKEY_meth_set_digestsign(EVP_PKEY_METHOD *pmeth,
+    int (*digestsign)(EVP_MD_CTX *ctx, unsigned char *sig, size_t *siglen,
+        const unsigned char *tbs, size_t tbslen))
+{
+    pmeth->digestsign = digestsign;
+}
+
+void EVP_PKEY_meth_set_digestverify(EVP_PKEY_METHOD *pmeth,
+    int (*digestverify)(EVP_MD_CTX *ctx, const unsigned char *sig,
+        size_t siglen, const unsigned char *tbs,
+        size_t tbslen))
+{
+    pmeth->digestverify = digestverify;
+}
+
+void EVP_PKEY_meth_set_check(EVP_PKEY_METHOD *pmeth,
+    int (*check)(EVP_PKEY *pkey))
+{
+    pmeth->check = check;
+}
+
+void EVP_PKEY_meth_set_public_check(EVP_PKEY_METHOD *pmeth,
+    int (*check)(EVP_PKEY *pkey))
+{
+    pmeth->public_check = check;
+}
+
+void EVP_PKEY_meth_set_param_check(EVP_PKEY_METHOD *pmeth,
+    int (*check)(EVP_PKEY *pkey))
+{
+    pmeth->param_check = check;
+}
+
+void EVP_PKEY_meth_set_digest_custom(EVP_PKEY_METHOD *pmeth,
+    int (*digest_custom)(EVP_PKEY_CTX *ctx,
+        EVP_MD_CTX *mctx))
+{
+    pmeth->digest_custom = digest_custom;
+}
+
+void EVP_PKEY_meth_get_init(const EVP_PKEY_METHOD *pmeth,
+    int (**pinit)(EVP_PKEY_CTX *ctx))
+{
+    *pinit = pmeth->init;
+}
+
+void EVP_PKEY_meth_get_copy(const EVP_PKEY_METHOD *pmeth,
+    int (**pcopy)(EVP_PKEY_CTX *dst,
+        const EVP_PKEY_CTX *src))
+{
+    *pcopy = pmeth->copy;
+}
+
+void EVP_PKEY_meth_get_cleanup(const EVP_PKEY_METHOD *pmeth,
+    void (**pcleanup)(EVP_PKEY_CTX *ctx))
+{
+    *pcleanup = pmeth->cleanup;
+}
+
+void EVP_PKEY_meth_get_paramgen(const EVP_PKEY_METHOD *pmeth,
+    int (**pparamgen_init)(EVP_PKEY_CTX *ctx),
+    int (**pparamgen)(EVP_PKEY_CTX *ctx,
+        EVP_PKEY *pkey))
+{
+    if (pparamgen_init)
+        *pparamgen_init = pmeth->paramgen_init;
+    if (pparamgen)
+        *pparamgen = pmeth->paramgen;
+}
+
+void EVP_PKEY_meth_get_keygen(const EVP_PKEY_METHOD *pmeth,
+    int (**pkeygen_init)(EVP_PKEY_CTX *ctx),
+    int (**pkeygen)(EVP_PKEY_CTX *ctx,
+        EVP_PKEY *pkey))
+{
+    if (pkeygen_init)
+        *pkeygen_init = pmeth->keygen_init;
+    if (pkeygen)
+        *pkeygen = pmeth->keygen;
+}
+
+void EVP_PKEY_meth_get_sign(const EVP_PKEY_METHOD *pmeth,
+    int (**psign_init)(EVP_PKEY_CTX *ctx),
+    int (**psign)(EVP_PKEY_CTX *ctx,
+        unsigned char *sig, size_t *siglen,
+        const unsigned char *tbs,
+        size_t tbslen))
+{
+    if (psign_init)
+        *psign_init = pmeth->sign_init;
+    if (psign)
+        *psign = pmeth->sign;
+}
+
+void EVP_PKEY_meth_get_verify(const EVP_PKEY_METHOD *pmeth,
+    int (**pverify_init)(EVP_PKEY_CTX *ctx),
+    int (**pverify)(EVP_PKEY_CTX *ctx,
+        const unsigned char *sig,
+        size_t siglen,
+        const unsigned char *tbs,
+        size_t tbslen))
+{
+    if (pverify_init)
+        *pverify_init = pmeth->verify_init;
+    if (pverify)
+        *pverify = pmeth->verify;
+}
+
+void EVP_PKEY_meth_get_verify_recover(const EVP_PKEY_METHOD *pmeth,
+    int (**pverify_recover_init)(EVP_PKEY_CTX
+            *ctx),
+    int (**pverify_recover)(EVP_PKEY_CTX
+                                *ctx,
+        unsigned char
+            *sig,
+        size_t *siglen,
+        const unsigned char *tbs,
+        size_t tbslen))
+{
+    if (pverify_recover_init)
+        *pverify_recover_init = pmeth->verify_recover_init;
+    if (pverify_recover)
+        *pverify_recover = pmeth->verify_recover;
+}
+
+void EVP_PKEY_meth_get_signctx(const EVP_PKEY_METHOD *pmeth,
+    int (**psignctx_init)(EVP_PKEY_CTX *ctx,
+        EVP_MD_CTX *mctx),
+    int (**psignctx)(EVP_PKEY_CTX *ctx,
+        unsigned char *sig,
+        size_t *siglen,
+        EVP_MD_CTX *mctx))
+{
+    if (psignctx_init)
+        *psignctx_init = pmeth->signctx_init;
+    if (psignctx)
+        *psignctx = pmeth->signctx;
+}
+
+void EVP_PKEY_meth_get_verifyctx(const EVP_PKEY_METHOD *pmeth,
+    int (**pverifyctx_init)(EVP_PKEY_CTX *ctx,
+        EVP_MD_CTX *mctx),
+    int (**pverifyctx)(EVP_PKEY_CTX *ctx,
+        const unsigned char *sig,
+        int siglen,
+        EVP_MD_CTX *mctx))
+{
+    if (pverifyctx_init)
+        *pverifyctx_init = pmeth->verifyctx_init;
+    if (pverifyctx)
+        *pverifyctx = pmeth->verifyctx;
+}
+
+void EVP_PKEY_meth_get_encrypt(const EVP_PKEY_METHOD *pmeth,
+    int (**pencrypt_init)(EVP_PKEY_CTX *ctx),
+    int (**pencryptfn)(EVP_PKEY_CTX *ctx,
+        unsigned char *out,
+        size_t *outlen,
+        const unsigned char *in,
+        size_t inlen))
+{
+    if (pencrypt_init)
+        *pencrypt_init = pmeth->encrypt_init;
+    if (pencryptfn)
+        *pencryptfn = pmeth->encrypt;
+}
+
+void EVP_PKEY_meth_get_decrypt(const EVP_PKEY_METHOD *pmeth,
+    int (**pdecrypt_init)(EVP_PKEY_CTX *ctx),
+    int (**pdecrypt)(EVP_PKEY_CTX *ctx,
+        unsigned char *out,
+        size_t *outlen,
+        const unsigned char *in,
+        size_t inlen))
+{
+    if (pdecrypt_init)
+        *pdecrypt_init = pmeth->decrypt_init;
+    if (pdecrypt)
+        *pdecrypt = pmeth->decrypt;
+}
+
+void EVP_PKEY_meth_get_derive(const EVP_PKEY_METHOD *pmeth,
+    int (**pderive_init)(EVP_PKEY_CTX *ctx),
+    int (**pderive)(EVP_PKEY_CTX *ctx,
+        unsigned char *key,
+        size_t *keylen))
+{
+    if (pderive_init)
+        *pderive_init = pmeth->derive_init;
+    if (pderive)
+        *pderive = pmeth->derive;
+}
+
+void EVP_PKEY_meth_get_ctrl(const EVP_PKEY_METHOD *pmeth,
+    int (**pctrl)(EVP_PKEY_CTX *ctx, int type, int p1,
+        void *p2),
+    int (**pctrl_str)(EVP_PKEY_CTX *ctx,
+        const char *type,
+        const char *value))
+{
+    if (pctrl)
+        *pctrl = pmeth->ctrl;
+    if (pctrl_str)
+        *pctrl_str = pmeth->ctrl_str;
+}
+
+void EVP_PKEY_meth_get_digestsign(const EVP_PKEY_METHOD *pmeth,
+    int (**digestsign)(EVP_MD_CTX *ctx, unsigned char *sig, size_t *siglen,
+        const unsigned char *tbs, size_t tbslen))
+{
+    if (digestsign)
+        *digestsign = pmeth->digestsign;
+}
+
+void EVP_PKEY_meth_get_digestverify(const EVP_PKEY_METHOD *pmeth,
+    int (**digestverify)(EVP_MD_CTX *ctx, const unsigned char *sig,
+        size_t siglen, const unsigned char *tbs,
+        size_t tbslen))
+{
+    if (digestverify)
+        *digestverify = pmeth->digestverify;
+}
+
+void EVP_PKEY_meth_get_check(const EVP_PKEY_METHOD *pmeth,
+    int (**pcheck)(EVP_PKEY *pkey))
+{
+    if (pcheck != NULL)
+        *pcheck = pmeth->check;
+}
+
+void EVP_PKEY_meth_get_public_check(const EVP_PKEY_METHOD *pmeth,
+    int (**pcheck)(EVP_PKEY *pkey))
+{
+    if (pcheck != NULL)
+        *pcheck = pmeth->public_check;
+}
+
+void EVP_PKEY_meth_get_param_check(const EVP_PKEY_METHOD *pmeth,
+    int (**pcheck)(EVP_PKEY *pkey))
+{
+    if (pcheck != NULL)
+        *pcheck = pmeth->param_check;
+}
+
+void EVP_PKEY_meth_get_digest_custom(const EVP_PKEY_METHOD *pmeth,
+    int (**pdigest_custom)(EVP_PKEY_CTX *ctx,
+        EVP_MD_CTX *mctx))
+{
+    if (pdigest_custom != NULL)
+        *pdigest_custom = pmeth->digest_custom;
+}
+
 #endif /* FIPS_MODULE */
diff --git a/crypto/evp/s_lib.c b/crypto/evp/s_lib.c
index 3f76136324..f4d26846c4 100644
--- a/crypto/evp/s_lib.c
+++ b/crypto/evp/s_lib.c
@@ -196,7 +196,7 @@ int EVP_SKEY_up_ref(EVP_SKEY *skey)
 {
     int i;
 
-    if (!CRYPTO_UP_REF(&skey->references, &i))
+    if (CRYPTO_UP_REF(&skey->references, &i) <= 0)
         return 0;
 
     REF_PRINT_COUNT("EVP_SKEY", i, skey);
@@ -287,15 +287,11 @@ EVP_SKEY *EVP_SKEY_to_provider(EVP_SKEY *skey, OSSL_LIB_CTX *libctx,
     }
 
     if (prov != NULL) {
-        if (skey->skeymgmt->prov == prov) {
+        if (skey->skeymgmt->prov == prov)
             skeymgmt = skey->skeymgmt;
-            /* Balance the short-circuit free below */
-            if (!EVP_SKEYMGMT_up_ref(skeymgmt))
-                goto err;
-        } else {
+        else
             skeymgmt = evp_skeymgmt_fetch_from_prov(prov, skey->skeymgmt->type_name,
                 propquery);
-        }
     } else {
         /* If no provider, get the default skeymgmt */
         skeymgmt = EVP_SKEYMGMT_fetch(libctx, skey->skeymgmt->type_name,
@@ -330,9 +326,6 @@ EVP_SKEY *EVP_SKEY_to_provider(EVP_SKEY *skey, OSSL_LIB_CTX *libctx,
 
     ret->keydata = ctx.keydata;
 
-    /* Balance the local reference obtained earlier (fetch or alias up_ref) */
-    EVP_SKEYMGMT_free(skeymgmt);
-
     return ret;
 
 err:
diff --git a/crypto/evp/signature.c b/crypto/evp/signature.c
index 6c6aad7e92..2e7a18f229 100644
--- a/crypto/evp/signature.c
+++ b/crypto/evp/signature.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -22,26 +22,12 @@
 
 static void evp_signature_free(void *data)
 {
-    EVP_SIGNATURE *signature = (EVP_SIGNATURE *)data;
-    int i;
-
-    if (signature == NULL)
-        return;
-    CRYPTO_DOWN_REF(&signature->refcnt, &i);
-    if (i > 0)
-        return;
-    OPENSSL_free(signature->type_name);
-    ossl_provider_free(signature->prov);
-    CRYPTO_FREE_REF(&signature->refcnt);
-    OPENSSL_free(signature);
+    EVP_SIGNATURE_free(data);
 }
 
 static int evp_signature_up_ref(void *data)
 {
-    EVP_SIGNATURE *signature = (EVP_SIGNATURE *)data;
-    int ref = 0;
-
-    return CRYPTO_UP_REF(&signature->refcnt, &ref);
+    return EVP_SIGNATURE_up_ref(data);
 }
 
 static EVP_SIGNATURE *evp_signature_new(OSSL_PROVIDER *prov)
@@ -65,7 +51,7 @@ static EVP_SIGNATURE *evp_signature_new(OSSL_PROVIDER *prov)
 
 static void *evp_signature_from_algorithm(int name_id,
     const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, int no_store)
+    OSSL_PROVIDER *prov)
 {
     const OSSL_DISPATCH *fns = algodef->implementation;
     EVP_SIGNATURE *signature = NULL;
@@ -84,7 +70,6 @@ static void *evp_signature_from_algorithm(int name_id,
     }
 
     signature->name_id = name_id;
-    signature->no_store = no_store;
     if ((signature->type_name = ossl_algorithm_get1_first_name(algodef)) == NULL)
         goto err;
     signature->description = algodef->algorithm_description;
@@ -463,29 +448,31 @@ static void *evp_signature_from_algorithm(int name_id,
 
     return signature;
 err:
-    evp_signature_free(signature);
+    EVP_SIGNATURE_free(signature);
     return NULL;
 }
 
 void EVP_SIGNATURE_free(EVP_SIGNATURE *signature)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    evp_signature_free(signature);
-#else
-    if (signature != NULL && (signature->no_store != 0))
-        evp_signature_free(signature);
-#endif
+    int i;
+
+    if (signature == NULL)
+        return;
+    CRYPTO_DOWN_REF(&signature->refcnt, &i);
+    if (i > 0)
+        return;
+    OPENSSL_free(signature->type_name);
+    ossl_provider_free(signature->prov);
+    CRYPTO_FREE_REF(&signature->refcnt);
+    OPENSSL_free(signature);
 }
 
 int EVP_SIGNATURE_up_ref(EVP_SIGNATURE *signature)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    return evp_signature_up_ref(signature);
-#else
-    if (signature->no_store != 0)
-        return evp_signature_up_ref(signature);
+    int ref = 0;
+
+    CRYPTO_UP_REF(&signature->refcnt, &ref);
     return 1;
-#endif
 }
 
 OSSL_PROVIDER *EVP_SIGNATURE_get0_provider(const EVP_SIGNATURE *signature)
@@ -499,7 +486,7 @@ EVP_SIGNATURE *EVP_SIGNATURE_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
     return evp_generic_fetch(ctx, OSSL_OP_SIGNATURE, algorithm, properties,
         evp_signature_from_algorithm,
         evp_signature_up_ref,
-        evp_signature_free);
+        evp_signature_free, NULL, NULL);
 }
 
 EVP_SIGNATURE *evp_signature_fetch_from_prov(OSSL_PROVIDER *prov,
@@ -510,7 +497,9 @@ EVP_SIGNATURE *evp_signature_fetch_from_prov(OSSL_PROVIDER *prov,
         algorithm, properties,
         evp_signature_from_algorithm,
         evp_signature_up_ref,
-        evp_signature_free);
+        evp_signature_free,
+        NULL,
+        NULL);
 }
 
 int EVP_SIGNATURE_is_a(const EVP_SIGNATURE *signature, const char *name)
@@ -545,12 +534,8 @@ void EVP_SIGNATURE_do_all_provided(OSSL_LIB_CTX *libctx,
         void *arg),
     void *arg)
 {
-    struct EVP_SIGNATURE_do_all_provided_thunk t;
-
-    t.fn = fn;
-    t.arg = arg;
     evp_generic_do_all(libctx, OSSL_OP_SIGNATURE,
-        EVP_SIGNATURE_do_all_provided_thunk, &t,
+        (void (*)(void *, void *))fn, arg,
         evp_signature_from_algorithm,
         evp_signature_up_ref,
         evp_signature_free);
@@ -658,8 +643,7 @@ static int evp_pkey_signature_init(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *signature,
                     break;
             if (*keytypes == NULL) {
                 ERR_raise(ERR_LIB_EVP, EVP_R_SIGNATURE_TYPE_AND_KEY_TYPE_INCOMPATIBLE);
-                ret = -2;
-                goto end;
+                return -2;
             }
         } else {
             /*
@@ -685,19 +669,18 @@ static int evp_pkey_signature_init(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *signature,
             /* If none of the fallbacks helped, we're lost */
             if (!ok) {
                 ERR_raise(ERR_LIB_EVP, EVP_R_SIGNATURE_TYPE_AND_KEY_TYPE_INCOMPATIBLE);
-                ret = -2;
-                goto end;
+                return -2;
             }
         }
 
         if (!EVP_SIGNATURE_up_ref(signature))
-            goto err;
+            return 0;
     } else {
         /* Without a pre-fetched signature, it must be figured out somehow */
         ERR_set_mark();
 
         if (evp_pkey_ctx_is_legacy(ctx))
-            goto notsupported;
+            goto legacy;
 
         if (ctx->pkey == NULL) {
             ERR_clear_last_mark();
@@ -749,9 +732,7 @@ static int evp_pkey_signature_init(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *signature,
              * iteration we're on.
              */
             EVP_SIGNATURE_free(signature);
-            signature = NULL;
             EVP_KEYMGMT_free(tmp_keymgmt);
-            tmp_keymgmt = NULL;
 
             switch (iter) {
             case 1:
@@ -764,7 +745,7 @@ static int evp_pkey_signature_init(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *signature,
                 signature = evp_signature_fetch_from_prov((OSSL_PROVIDER *)tmp_prov,
                     supported_sig, ctx->propquery);
                 if (signature == NULL)
-                    goto notsupported;
+                    goto legacy;
                 break;
             }
             if (signature == NULL)
@@ -792,7 +773,7 @@ static int evp_pkey_signature_init(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *signature,
 
         if (provkey == NULL) {
             EVP_SIGNATURE_free(signature);
-            goto notsupported;
+            goto legacy;
         }
 
         ERR_pop_to_mark();
@@ -868,7 +849,7 @@ static int evp_pkey_signature_init(EVP_PKEY_CTX *ctx, EVP_SIGNATURE *signature,
     }
     goto end;
 
-notsupported:
+legacy:
     /*
      * If we don't have the full support we need with provided methods,
      * let's go see if legacy does.
@@ -877,9 +858,37 @@ notsupported:
     EVP_KEYMGMT_free(tmp_keymgmt);
     tmp_keymgmt = NULL;
 
-    ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
-    return -2;
+    if (ctx->pmeth == NULL
+        || (operation == EVP_PKEY_OP_SIGN && ctx->pmeth->sign == NULL)
+        || (operation == EVP_PKEY_OP_VERIFY && ctx->pmeth->verify == NULL)
+        || (operation == EVP_PKEY_OP_VERIFYRECOVER
+            && ctx->pmeth->verify_recover == NULL)) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
+        return -2;
+    }
 
+    switch (operation) {
+    case EVP_PKEY_OP_SIGN:
+        if (ctx->pmeth->sign_init == NULL)
+            return 1;
+        ret = ctx->pmeth->sign_init(ctx);
+        break;
+    case EVP_PKEY_OP_VERIFY:
+        if (ctx->pmeth->verify_init == NULL)
+            return 1;
+        ret = ctx->pmeth->verify_init(ctx);
+        break;
+    case EVP_PKEY_OP_VERIFYRECOVER:
+        if (ctx->pmeth->verify_recover_init == NULL)
+            return 1;
+        ret = ctx->pmeth->verify_recover_init(ctx);
+        break;
+    default:
+        ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
+        goto err;
+    }
+    if (ret <= 0)
+        goto err;
 end:
 #ifndef FIPS_MODULE
     if (ret > 0)
@@ -1001,10 +1010,8 @@ int EVP_PKEY_sign(EVP_PKEY_CTX *ctx,
         return -1;
     }
 
-    if (ctx->op.sig.algctx == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
-        return -2;
-    }
+    if (ctx->op.sig.algctx == NULL)
+        goto legacy;
 
     signature = ctx->op.sig.signature;
     desc = signature->description != NULL ? signature->description : "";
@@ -1020,6 +1027,14 @@ int EVP_PKEY_sign(EVP_PKEY_CTX *ctx,
         ERR_raise_data(ERR_LIB_EVP, EVP_R_PROVIDER_SIGNATURE_FAILURE,
             "%s sign:%s", signature->type_name, desc);
     return ret;
+legacy:
+
+    if (ctx->pmeth == NULL || ctx->pmeth->sign == NULL) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
+        return -2;
+    }
+
+    M_check_autoarg(ctx, sig, siglen, EVP_F_EVP_PKEY_SIGN) return ctx->pmeth->sign(ctx, sig, siglen, tbs, tbslen);
 }
 
 int EVP_PKEY_verify_init(EVP_PKEY_CTX *ctx)
@@ -1148,10 +1163,8 @@ int EVP_PKEY_verify(EVP_PKEY_CTX *ctx,
         return -1;
     }
 
-    if (ctx->op.sig.algctx == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
-        return -2;
-    }
+    if (ctx->op.sig.algctx == NULL)
+        goto legacy;
 
     signature = ctx->op.sig.signature;
     desc = signature->description != NULL ? signature->description : "";
@@ -1168,6 +1181,13 @@ int EVP_PKEY_verify(EVP_PKEY_CTX *ctx,
             "%s verify:%s", signature->type_name, desc);
 
     return ret;
+legacy:
+    if (ctx->pmeth == NULL || ctx->pmeth->verify == NULL) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
+        return -2;
+    }
+
+    return ctx->pmeth->verify(ctx, sig, siglen, tbs, tbslen);
 }
 
 int EVP_PKEY_verify_recover_init(EVP_PKEY_CTX *ctx)
@@ -1205,10 +1225,8 @@ int EVP_PKEY_verify_recover(EVP_PKEY_CTX *ctx,
         return -1;
     }
 
-    if (ctx->op.sig.algctx == NULL) {
-        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
-        return -2;
-    }
+    if (ctx->op.sig.algctx == NULL)
+        goto legacy;
 
     signature = ctx->op.sig.signature;
     desc = signature->description != NULL ? signature->description : "";
@@ -1224,4 +1242,10 @@ int EVP_PKEY_verify_recover(EVP_PKEY_CTX *ctx,
         ERR_raise_data(ERR_LIB_EVP, EVP_R_PROVIDER_SIGNATURE_FAILURE,
             "%s verify_recover:%s", signature->type_name, desc);
     return ret;
+legacy:
+    if (ctx->pmeth == NULL || ctx->pmeth->verify_recover == NULL) {
+        ERR_raise(ERR_LIB_EVP, EVP_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
+        return -2;
+    }
+    M_check_autoarg(ctx, rout, routlen, EVP_F_EVP_PKEY_VERIFY_RECOVER) return ctx->pmeth->verify_recover(ctx, rout, routlen, sig, siglen);
 }
diff --git a/crypto/evp/skeymgmt_meth.c b/crypto/evp/skeymgmt_meth.c
index dbc14c0e0d..c225151d3f 100644
--- a/crypto/evp/skeymgmt_meth.c
+++ b/crypto/evp/skeymgmt_meth.c
@@ -7,6 +7,7 @@
  * https://www.openssl.org/source/license.html
  */
 
+#include 
 #include 
 #include 
 #include 
@@ -17,7 +18,54 @@
 #include "crypto/evp.h"
 #include "evp_local.h"
 
-static void evp_skeymgmt_free(void *s);
+static void evp_skeymgmt_free_int(EVP_SKEYMGMT *skeymgmt)
+{
+    OPENSSL_free(skeymgmt->type_name);
+    ossl_provider_free(skeymgmt->prov);
+    CRYPTO_FREE_REF(&skeymgmt->refcnt);
+    OPENSSL_free(skeymgmt);
+}
+
+static void *evp_skeymgmt_dup_frozen(void *vin)
+{
+    EVP_SKEYMGMT *in = vin;
+    EVP_SKEYMGMT *out;
+
+    out = OPENSSL_malloc(sizeof(*out));
+    if (out == NULL)
+        return NULL;
+    memcpy(out, in, sizeof(*out));
+    if (!CRYPTO_NEW_REF(&out->refcnt, 1))
+        goto err;
+    out->type_name = OPENSSL_strdup(in->type_name);
+    if (out->type_name == NULL)
+        goto err;
+    out->origin = EVP_ORIG_FROZEN;
+    if (out->prov == NULL || !ossl_provider_up_ref(out->prov)) {
+        OPENSSL_free(out->type_name);
+        goto err;
+    }
+    return out;
+
+err:
+    CRYPTO_FREE_REF(&out->refcnt);
+    OPENSSL_free(out);
+    return NULL;
+}
+
+static void evp_skeymgmt_frozen_free(void *vin)
+{
+    EVP_SKEYMGMT *skeymgmt = vin;
+    int ref = 0;
+
+    if (skeymgmt == NULL || skeymgmt->origin != EVP_ORIG_FROZEN)
+        return;
+
+    CRYPTO_DOWN_REF(&skeymgmt->refcnt, &ref);
+    if (ref > 0)
+        return;
+    evp_skeymgmt_free_int(skeymgmt);
+}
 
 void *evp_skeymgmt_generate(const EVP_SKEYMGMT *skeymgmt, const OSSL_PARAM params[])
 {
@@ -54,7 +102,7 @@ static void *skeymgmt_new(void)
     if ((skeymgmt = OPENSSL_zalloc(sizeof(*skeymgmt))) == NULL)
         return NULL;
     if (!CRYPTO_NEW_REF(&skeymgmt->refcnt, 1)) {
-        evp_skeymgmt_free(skeymgmt);
+        EVP_SKEYMGMT_free(skeymgmt);
         return NULL;
     }
     return skeymgmt;
@@ -62,7 +110,7 @@ static void *skeymgmt_new(void)
 
 static void *skeymgmt_from_algorithm(int name_id,
     const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, int no_store)
+    OSSL_PROVIDER *prov)
 {
     const OSSL_DISPATCH *fns = algodef->implementation;
     EVP_SKEYMGMT *skeymgmt = NULL;
@@ -71,9 +119,8 @@ static void *skeymgmt_from_algorithm(int name_id,
         return NULL;
 
     skeymgmt->name_id = name_id;
-    skeymgmt->no_store = no_store;
     if ((skeymgmt->type_name = ossl_algorithm_get1_first_name(algodef)) == NULL) {
-        evp_skeymgmt_free(skeymgmt);
+        EVP_SKEYMGMT_free(skeymgmt);
         return NULL;
     }
     skeymgmt->description = algodef->algorithm_description;
@@ -115,13 +162,13 @@ static void *skeymgmt_from_algorithm(int name_id,
     if (skeymgmt->free == NULL
         || skeymgmt->import == NULL
         || skeymgmt->export == NULL) {
-        evp_skeymgmt_free(skeymgmt);
+        EVP_SKEYMGMT_free(skeymgmt);
         ERR_raise(ERR_LIB_EVP, EVP_R_INVALID_PROVIDER_FUNCTIONS);
         return NULL;
     }
 
     if (!ossl_provider_up_ref(prov)) {
-        evp_skeymgmt_free(skeymgmt);
+        EVP_SKEYMGMT_free(skeymgmt);
         ERR_raise(ERR_LIB_EVP, EVP_R_INITIALIZATION_ERROR);
         return NULL;
     }
@@ -130,31 +177,6 @@ static void *skeymgmt_from_algorithm(int name_id,
     return skeymgmt;
 }
 
-static int evp_skeymgmt_up_ref(void *s)
-{
-    EVP_SKEYMGMT *skeymgmt = (EVP_SKEYMGMT *)s;
-    int ref = 0;
-
-    return CRYPTO_UP_REF(&skeymgmt->refcnt, &ref);
-}
-
-static void evp_skeymgmt_free(void *s)
-{
-    EVP_SKEYMGMT *skeymgmt = (EVP_SKEYMGMT *)s;
-    int ref = 0;
-
-    if (skeymgmt == NULL)
-        return;
-
-    CRYPTO_DOWN_REF(&skeymgmt->refcnt, &ref);
-    if (ref > 0)
-        return;
-    OPENSSL_free(skeymgmt->type_name);
-    ossl_provider_free(skeymgmt->prov);
-    CRYPTO_FREE_REF(&skeymgmt->refcnt);
-    OPENSSL_free(skeymgmt);
-}
-
 EVP_SKEYMGMT *evp_skeymgmt_fetch_from_prov(OSSL_PROVIDER *prov,
     const char *name,
     const char *properties)
@@ -163,8 +185,10 @@ EVP_SKEYMGMT *evp_skeymgmt_fetch_from_prov(OSSL_PROVIDER *prov,
         OSSL_OP_SKEYMGMT,
         name, properties,
         skeymgmt_from_algorithm,
-        evp_skeymgmt_up_ref,
-        evp_skeymgmt_free);
+        (int (*)(void *))EVP_SKEYMGMT_up_ref,
+        (void (*)(void *))EVP_SKEYMGMT_free,
+        evp_skeymgmt_dup_frozen,
+        evp_skeymgmt_frozen_free);
 }
 
 EVP_SKEYMGMT *EVP_SKEYMGMT_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
@@ -172,29 +196,43 @@ EVP_SKEYMGMT *EVP_SKEYMGMT_fetch(OSSL_LIB_CTX *ctx, const char *algorithm,
 {
     return evp_generic_fetch(ctx, OSSL_OP_SKEYMGMT, algorithm, properties,
         skeymgmt_from_algorithm,
-        evp_skeymgmt_up_ref,
-        evp_skeymgmt_free);
+        (int (*)(void *))EVP_SKEYMGMT_up_ref,
+        (void (*)(void *))EVP_SKEYMGMT_free,
+        evp_skeymgmt_dup_frozen,
+        evp_skeymgmt_frozen_free);
+}
+
+int evp_skeymgmt_fetch_all(OSSL_LIB_CTX *ctx)
+{
+    return evp_generic_fetch_all(ctx,
+        OSSL_OP_SKEYMGMT,
+        skeymgmt_from_algorithm,
+        (int (*)(void *))EVP_SKEYMGMT_up_ref,
+        (void (*)(void *))EVP_SKEYMGMT_free,
+        evp_skeymgmt_dup_frozen,
+        evp_skeymgmt_frozen_free);
 }
 
 int EVP_SKEYMGMT_up_ref(EVP_SKEYMGMT *skeymgmt)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    return evp_skeymgmt_up_ref(skeymgmt);
-#else
-    if (skeymgmt->no_store != 0)
-        return evp_skeymgmt_up_ref(skeymgmt);
+    int ref = 0;
+
+    if (skeymgmt->origin == EVP_ORIG_DYNAMIC)
+        CRYPTO_UP_REF(&skeymgmt->refcnt, &ref);
     return 1;
-#endif
 }
 
 void EVP_SKEYMGMT_free(EVP_SKEYMGMT *skeymgmt)
 {
-#ifdef OPENSSL_NO_CACHED_FETCH
-    evp_skeymgmt_free(skeymgmt);
-#else
-    if (skeymgmt != NULL && (skeymgmt->no_store != 0))
-        evp_skeymgmt_free(skeymgmt);
-#endif
+    int ref = 0;
+
+    if (skeymgmt == NULL || skeymgmt->origin != EVP_ORIG_DYNAMIC)
+        return;
+
+    CRYPTO_DOWN_REF(&skeymgmt->refcnt, &ref);
+    if (ref > 0)
+        return;
+    evp_skeymgmt_free_int(skeymgmt);
 }
 
 const OSSL_PROVIDER *EVP_SKEYMGMT_get0_provider(const EVP_SKEYMGMT *skeymgmt)
@@ -222,15 +260,11 @@ void EVP_SKEYMGMT_do_all_provided(OSSL_LIB_CTX *libctx,
     void (*fn)(EVP_SKEYMGMT *skeymgmt, void *arg),
     void *arg)
 {
-    struct EVP_SKEYMGMT_do_all_provided_thunk t;
-
-    t.fn = fn;
-    t.arg = arg;
     evp_generic_do_all(libctx, OSSL_OP_SKEYMGMT,
-        EVP_SKEYMGMT_do_all_provided_thunk, &t,
+        (void (*)(void *, void *))fn, arg,
         skeymgmt_from_algorithm,
-        evp_skeymgmt_up_ref,
-        evp_skeymgmt_free);
+        (int (*)(void *))EVP_SKEYMGMT_up_ref,
+        (void (*)(void *))EVP_SKEYMGMT_free);
 }
 
 int EVP_SKEYMGMT_names_do_all(const EVP_SKEYMGMT *skeymgmt,
diff --git a/crypto/ex_data.c b/crypto/ex_data.c
index cd443bd4b9..98119d5a6c 100644
--- a/crypto/ex_data.c
+++ b/crypto/ex_data.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -500,3 +500,8 @@ void *CRYPTO_get_ex_data(const CRYPTO_EX_DATA *ad, int idx)
         return NULL;
     return sk_void_value(ad->sk, idx);
 }
+
+OSSL_LIB_CTX *ossl_crypto_ex_data_get_ossl_lib_ctx(const CRYPTO_EX_DATA *ad)
+{
+    return ad->ctx;
+}
diff --git a/crypto/ffc/ffc_backend.c b/crypto/ffc/ffc_backend.c
index cc54d38b0b..fa3182bc80 100644
--- a/crypto/ffc/ffc_backend.c
+++ b/crypto/ffc/ffc_backend.c
@@ -12,9 +12,9 @@
 #include "internal/sizes.h"
 
 /*
- * The intention with the "backend" source file is to offer backend functions
- * for legacy backends (EVP_PKEY_ASN1_METHOD) and provider implementations
- * alike.
+ * The intention with the "backend" source file is to offer backend support
+ * for legacy backends (EVP_PKEY_ASN1_METHOD and EVP_PKEY_METHOD) and provider
+ * implementations alike.
  */
 
 int ossl_ffc_params_fromdata(FFC_PARAMS *ffc, const OSSL_PARAM params[])
diff --git a/crypto/ffc/ffc_params.c b/crypto/ffc/ffc_params.c
index 23d3fab56b..438997931b 100644
--- a/crypto/ffc/ffc_params.c
+++ b/crypto/ffc/ffc_params.c
@@ -12,7 +12,6 @@
 #include "internal/ffc.h"
 #include "internal/param_build_set.h"
 #include "internal/nelem.h"
-#include "internal/zeroization.h"
 
 #ifndef FIPS_MODULE
 #include  /* ossl_ffc_params_print */
@@ -28,27 +27,34 @@ void ossl_ffc_params_init(FFC_PARAMS *params)
 
 void ossl_ffc_params_cleanup(FFC_PARAMS *params)
 {
-    ossl_public_bn_free(params->p);
-    ossl_public_bn_free(params->q);
-    ossl_public_bn_free(params->g);
-    ossl_public_bn_free(params->j);
-    ossl_public_param_free(params->seed, params->seedlen);
-
+#ifdef OPENSSL_PEDANTIC_ZEROIZATION
+    BN_clear_free(params->p);
+    BN_clear_free(params->q);
+    BN_clear_free(params->g);
+    BN_clear_free(params->j);
+    OPENSSL_clear_free(params->seed, params->seedlen);
+#else
+    BN_free(params->p);
+    BN_free(params->q);
+    BN_free(params->g);
+    BN_free(params->j);
+    OPENSSL_free(params->seed);
+#endif
     ossl_ffc_params_init(params);
 }
 
 void ossl_ffc_params_set0_pqg(FFC_PARAMS *d, BIGNUM *p, BIGNUM *q, BIGNUM *g)
 {
     if (p != NULL && p != d->p) {
-        ossl_public_bn_free(d->p);
+        BN_free(d->p);
         d->p = p;
     }
     if (q != NULL && q != d->q) {
-        ossl_public_bn_free(d->q);
+        BN_free(d->q);
         d->q = q;
     }
     if (g != NULL && g != d->g) {
-        ossl_public_bn_free(d->g);
+        BN_free(d->g);
         d->g = g;
     }
 }
@@ -67,7 +73,7 @@ void ossl_ffc_params_get0_pqg(const FFC_PARAMS *d, const BIGNUM **p,
 /* j is the 'cofactor' that is optionally output for ASN1. */
 void ossl_ffc_params_set0_j(FFC_PARAMS *d, BIGNUM *j)
 {
-    ossl_public_bn_free(d->j);
+    BN_free(d->j);
     d->j = NULL;
     if (j != NULL)
         d->j = j;
@@ -79,7 +85,7 @@ int ossl_ffc_params_set_seed(FFC_PARAMS *params,
     if (params->seed != NULL) {
         if (params->seed == seed)
             return 1;
-        ossl_public_param_free(params->seed, params->seedlen);
+        OPENSSL_free(params->seed);
     }
 
     if (seed != NULL && seedlen > 0) {
@@ -166,7 +172,7 @@ static int ffc_bn_cpy(BIGNUM **dst, const BIGNUM *src)
         a = (BIGNUM *)src;
     else if ((a = BN_dup(src)) == NULL)
         return 0;
-    ossl_public_bn_free(*dst);
+    BN_clear_free(*dst);
     *dst = a;
     return 1;
 }
@@ -176,21 +182,17 @@ int ossl_ffc_params_copy(FFC_PARAMS *dst, const FFC_PARAMS *src)
     if (!ffc_bn_cpy(&dst->p, src->p)
         || !ffc_bn_cpy(&dst->g, src->g)
         || !ffc_bn_cpy(&dst->q, src->q)
-        || !ffc_bn_cpy(&dst->j, src->j)) {
-        ossl_ffc_params_cleanup(dst);
+        || !ffc_bn_cpy(&dst->j, src->j))
         return 0;
-    }
 
     dst->mdname = src->mdname;
     dst->mdprops = src->mdprops;
-    ossl_public_param_free(dst->seed, dst->seedlen);
+    OPENSSL_free(dst->seed);
     dst->seedlen = src->seedlen;
     if (src->seed != NULL) {
         dst->seed = OPENSSL_memdup(src->seed, src->seedlen);
-        if (dst->seed == NULL) {
-            ossl_ffc_params_cleanup(dst);
+        if (dst->seed == NULL)
             return 0;
-        }
     } else {
         dst->seed = NULL;
     }
diff --git a/crypto/ffc/ffc_params_generate.c b/crypto/ffc/ffc_params_generate.c
index 73672740b3..d2792383eb 100644
--- a/crypto/ffc/ffc_params_generate.c
+++ b/crypto/ffc/ffc_params_generate.c
@@ -46,8 +46,7 @@ static int ffc_validate_LN(size_t L, size_t N, int type, int verify)
         if (L == 2048 && (N == 224 || N == 256))
             return 112;
 #ifndef OPENSSL_NO_DH
-        ERR_raise_data(ERR_LIB_DH, DH_R_BAD_FFC_PARAMETERS,
-            "(L, N)=(%zu, %zu) should be (2048, 224) or (2048, 256)", L, N);
+        ERR_raise(ERR_LIB_DH, DH_R_BAD_FFC_PARAMETERS);
 #endif
     } else if (type == FFC_PARAM_TYPE_DSA) {
         /* Valid DSA L,N parameters from FIPS 186-4 Section 4.2 */
@@ -59,10 +58,7 @@ static int ffc_validate_LN(size_t L, size_t N, int type, int verify)
         if (L == 3072 && N == 256)
             return 128;
 #ifndef OPENSSL_NO_DSA
-        ERR_raise_data(ERR_LIB_DSA, DSA_R_BAD_FFC_PARAMETERS,
-            "(L, N)=(%zu, %zu) should be (1024, 160) (for verification only), "
-            "(2048, 224), (2048, 256), or (3072, 256)",
-            L, N);
+        ERR_raise(ERR_LIB_DSA, DSA_R_BAD_FFC_PARAMETERS);
 #endif
     }
     return 0;
@@ -78,10 +74,7 @@ static int ffc_validate_LN(size_t L, size_t N, int type, int verify)
         if (L == 2048 && (N == 224 || N == 256))
             return 112;
 #ifndef OPENSSL_NO_DH
-        ERR_raise_data(ERR_LIB_DH, DH_R_BAD_FFC_PARAMETERS,
-            "(L, N)=(%zu, %zu) should be (1024, 160), (2048, 224), or "
-            "(2048, 256)",
-            L, N);
+        ERR_raise(ERR_LIB_DH, DH_R_BAD_FFC_PARAMETERS);
 #endif
     } else if (type == FFC_PARAM_TYPE_DSA) {
         if (L >= 3072 && N >= 256)
@@ -91,8 +84,7 @@ static int ffc_validate_LN(size_t L, size_t N, int type, int verify)
         if (L >= 1024 && N >= 160)
             return 80;
 #ifndef OPENSSL_NO_DSA
-        ERR_raise_data(ERR_LIB_DSA, DSA_R_BAD_FFC_PARAMETERS,
-            "(L, N)=(%zu, %zu) should be at least (1024, 160)", L, N);
+        ERR_raise(ERR_LIB_DSA, DSA_R_BAD_FFC_PARAMETERS);
 #endif
     }
     return 0;
@@ -267,7 +259,7 @@ static int generate_p(BN_CTX *ctx, const EVP_MD *evpmd, int max_counter, int n,
          * X = W + 2^(L-1) where W < 2^(L-1)
          */
         if (!BN_mask_bits(W, L - 1)
-            || BN_copy(X, W) == NULL
+            || !BN_copy(X, W)
             || !BN_add(X, X, test)
             /*
              * A.1.1.2 Step (11.4) AND
diff --git a/crypto/getenv.c b/crypto/getenv.c
index 8ea7128864..aa01ea8af7 100644
--- a/crypto/getenv.c
+++ b/crypto/getenv.c
@@ -17,7 +17,7 @@
 
 char *ossl_safe_getenv(const char *name)
 {
-#if defined(_WIN32) && defined(CP_UTF8)
+#if defined(_WIN32) && defined(CP_UTF8) && !defined(_WIN32_WCE)
     if (GetEnvironmentVariableW(L"OPENSSL_WIN32_UTF8", NULL, 0) != 0) {
         char *val = NULL;
         int vallen = 0;
diff --git a/crypto/hashtable/hashtable.c b/crypto/hashtable/hashtable.c
index 1cce15ed24..10dda82a74 100644
--- a/crypto/hashtable/hashtable.c
+++ b/crypto/hashtable/hashtable.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -81,11 +81,9 @@
 #if defined(__GNUC__) || defined(__CLANG__)
 #define PREFETCH_NEIGHBORHOOD(x) __builtin_prefetch(x.entries)
 #define PREFETCH(x) __builtin_prefetch(x)
-#define ALIGN __attribute__((aligned(8)))
 #else
 #define PREFETCH_NEIGHBORHOOD(x)
 #define PREFETCH(x)
-#define ALIGN
 #endif
 
 /*
@@ -113,7 +111,7 @@ struct ht_internal_value_st {
 struct ht_neighborhood_entry_st {
     uint64_t hash;
     struct ht_internal_value_st *value;
-} ALIGN;
+};
 
 struct ht_neighborhood_st {
     struct ht_neighborhood_entry_st entries[NEIGHBORHOOD_LEN];
@@ -311,7 +309,6 @@ static int ossl_ht_flush_internal(HT *h)
 {
     struct ht_mutable_data_st *newmd = NULL;
     struct ht_mutable_data_st *oldmd = NULL;
-    CRYPTO_RCU_CB_ITEM *cbi = NULL;
 
     newmd = OPENSSL_zalloc(sizeof(*newmd));
     if (newmd == NULL)
@@ -326,15 +323,8 @@ static int ossl_ht_flush_internal(HT *h)
 
     newmd->neighborhood_mask = DEFAULT_NEIGH_LEN - 1;
 
+    /* Swap the old and new mutable data sets */
     if (!h->config.no_rcu) {
-        cbi = ossl_rcu_cb_item_new();
-        if (cbi == NULL) {
-            OPENSSL_free(newmd->neighborhood_ptr_to_free);
-            OPENSSL_free(newmd);
-            return 0;
-        }
-
-        /* Swap the old and new mutable data sets */
         oldmd = ossl_rcu_deref(&h->md);
         ossl_rcu_assign_ptr(&h->md, &newmd);
     } else {
@@ -347,11 +337,11 @@ static int ossl_ht_flush_internal(HT *h)
     h->wpd.neighborhood_len = DEFAULT_NEIGH_LEN;
 
     if (!h->config.no_rcu) {
-        ossl_rcu_call(h->lock, cbi, free_oldmd, oldmd);
-        h->wpd.need_sync = 1;
+        ossl_rcu_call(h->lock, free_oldmd, oldmd);
     } else {
         free_oldmd(oldmd);
     }
+    h->wpd.need_sync = 1;
 
     return 1;
 }
@@ -363,28 +353,21 @@ int ossl_ht_flush(HT *h)
 
 void ossl_ht_free(HT *h)
 {
-    int flush_ok;
-
     if (h == NULL)
         return;
 
-    if (h->config.no_rcu) {
-        free_oldmd(h->md);
-    } else {
-        ossl_ht_write_lock(h);
-        flush_ok = ossl_ht_flush_internal(h);
-        ossl_ht_write_unlock(h);
-        /* Freeing the lock does a final sync for us */
+    ossl_ht_write_lock(h);
+    ossl_ht_flush_internal(h);
+    ossl_ht_write_unlock(h);
+    /* Freeing the lock does a final sync for us */
+    if (!h->config.no_rcu) {
         CRYPTO_THREAD_lock_free(h->atomic_lock);
         ossl_rcu_lock_free(h->lock);
-        if (flush_ok) {
-            OPENSSL_free(h->md->neighborhood_ptr_to_free);
-            OPENSSL_free(h->md);
-        } else {
-            free_oldmd(h->md);
-        }
     }
+    OPENSSL_free(h->md->neighborhood_ptr_to_free);
+    OPENSSL_free(h->md);
     OPENSSL_free(h);
+    return;
 }
 
 size_t ossl_ht_count(HT *h)
@@ -476,7 +459,6 @@ static int grow_hashtable(HT *h, size_t oldsize)
 {
     struct ht_mutable_data_st *newmd;
     struct ht_mutable_data_st *oldmd = ossl_rcu_deref(&h->md);
-    CRYPTO_RCU_CB_ITEM *cbi = NULL;
     int rc = 0;
     uint64_t oldi, oldj, newi, newj;
     uint64_t oldhash;
@@ -523,22 +505,12 @@ static int grow_hashtable(HT *h, size_t oldsize)
             }
             if (rehashed == 0) {
                 /* we ran out of space in a neighborhood, grow again */
-                OPENSSL_free(newmd->neighborhood_ptr_to_free);
+                OPENSSL_free(newmd->neighborhoods);
                 OPENSSL_free(newmd);
                 return grow_hashtable(h, newsize);
             }
         }
     }
-
-    /*
-     * Pre allocate the rcu callback item before assigning the newmd.
-     */
-    if (!h->config.no_rcu) {
-        cbi = ossl_rcu_cb_item_new();
-        if (cbi == NULL)
-            goto out_free;
-    }
-
     /*
      * Now that our entries are all hashed into the new bucket list
      * update our bucket_len and target_max_load
@@ -550,7 +522,7 @@ static int grow_hashtable(HT *h, size_t oldsize)
      */
     if (!h->config.no_rcu) {
         ossl_rcu_assign_ptr(&h->md, &newmd);
-        ossl_rcu_call(h->lock, cbi, free_old_neigh_table, oldmd);
+        ossl_rcu_call(h->lock, free_old_neigh_table, oldmd);
         h->wpd.need_sync = 1;
     } else {
         h->md = newmd;
@@ -564,7 +536,7 @@ static int grow_hashtable(HT *h, size_t oldsize)
 out:
     return rc;
 out_free:
-    OPENSSL_free(newmd->neighborhood_ptr_to_free);
+    OPENSSL_free(newmd->neighborhoods);
     OPENSSL_free(newmd);
     goto out;
 }
@@ -638,18 +610,13 @@ static int ossl_ht_insert_locked(HT *h, uint64_t hash,
                 }
                 /* Do a replacement */
                 if (!h->config.no_rcu) {
-                    CRYPTO_RCU_CB_ITEM *cbi = ossl_rcu_cb_item_new();
-                    if (cbi == NULL)
-                        return 0;
                     if (!CRYPTO_atomic_store(&md->neighborhoods[neigh_idx].entries[j].hash,
-                            hash, h->atomic_lock)) {
-                        ossl_rcu_cb_item_free(cbi);
+                            hash, h->atomic_lock))
                         return 0;
-                    }
                     *olddata = (HT_VALUE *)md->neighborhoods[neigh_idx].entries[j].value;
                     ossl_rcu_assign_ptr(&md->neighborhoods[neigh_idx].entries[j].value,
                         &newval);
-                    ossl_rcu_call(h->lock, cbi, free_old_ht_value, *olddata);
+                    ossl_rcu_call(h->lock, free_old_ht_value, *olddata);
                 } else {
                     md->neighborhoods[neigh_idx].entries[j].hash = hash;
                     *olddata = (HT_VALUE *)md->neighborhoods[neigh_idx].entries[j].value;
@@ -731,18 +698,15 @@ int ossl_ht_insert(HT *h, HT_KEY *key, HT_VALUE *data, HT_VALUE **olddata)
     if (newval == NULL)
         goto out;
 
-    if (key->cached_hash)
-        hash = key->cached_hash;
-    else
-        hash = key->cached_hash = newval->value.key.cached_hash = h->config.ht_hash_fn(key);
-
     /*
      * we have to take our lock here to prevent other changes
      * to the bucket list
      */
+    hash = h->config.ht_hash_fn(key);
+
     for (i = 0;
         (rc = ossl_ht_insert_locked(h, hash, newval, olddata)) == -1
-        && i <= (int)NEIGHBORHOOD_LEN;
+        && i < 4;
         ++i)
         if (!grow_hashtable(h, h->wpd.neighborhood_len)) {
             rc = -1;
@@ -767,10 +731,7 @@ HT_VALUE *ossl_ht_get(HT *h, HT_KEY *key)
     uint64_t ehash;
     int lockless_reads = h->config.lockless_reads;
 
-    if (key->cached_hash)
-        hash = key->cached_hash;
-    else
-        hash = key->cached_hash = h->config.ht_hash_fn(key);
+    hash = h->config.ht_hash_fn(key);
 
     if (!h->config.no_rcu)
         md = ossl_rcu_deref(&h->md);
@@ -829,10 +790,7 @@ int ossl_ht_delete(HT *h, HT_KEY *key)
     if (h->config.lockless_reads)
         return 0;
 
-    if (key->cached_hash)
-        hash = key->cached_hash;
-    else
-        hash = key->cached_hash = h->config.ht_hash_fn(key);
+    hash = h->config.ht_hash_fn(key);
 
     neigh_idx = hash & h->md->neighborhood_mask;
     PREFETCH_NEIGHBORHOOD(h->md->neighborhoods[neigh_idx]);
@@ -843,27 +801,26 @@ int ossl_ht_delete(HT *h, HT_KEY *key)
         if (compare_hash(hash, h->md->neighborhoods[neigh_idx].entries[j].hash)
             && match_key(key, &v->value.key)) {
             if (!h->config.no_rcu) {
-                CRYPTO_RCU_CB_ITEM *cbi = ossl_rcu_cb_item_new();
-                if (cbi == NULL)
-                    break;
                 if (!CRYPTO_atomic_store(&h->md->neighborhoods[neigh_idx].entries[j].hash,
-                        0, h->atomic_lock)) {
-                    ossl_rcu_cb_item_free(cbi);
+                        0, h->atomic_lock))
                     break;
-                }
                 ossl_rcu_assign_ptr(&h->md->neighborhoods[neigh_idx].entries[j].value, &nv);
-                ossl_rcu_call(h->lock, cbi, free_old_entry, v);
             } else {
                 h->md->neighborhoods[neigh_idx].entries[j].hash = 0;
                 h->md->neighborhoods[neigh_idx].entries[j].value = NULL;
-                free_old_entry(v);
             }
             h->wpd.value_count--;
-            h->wpd.need_sync = 1;
             rc = 1;
             break;
         }
     }
+    if (rc == 1) {
+        if (!h->config.no_rcu)
+            ossl_rcu_call(h->lock, free_old_entry, v);
+        else
+            free_old_entry(v);
+        h->wpd.need_sync = 1;
+    }
 
     return rc;
 }
diff --git a/crypto/hmac/hmac.c b/crypto/hmac/hmac.c
index f12b5bf0b3..400dde4d40 100644
--- a/crypto/hmac/hmac.c
+++ b/crypto/hmac/hmac.c
@@ -53,11 +53,9 @@ int HMAC_Init_ex(HMAC_CTX *ctx, const void *key, int len,
         return 0;
 
 #ifdef OPENSSL_HMAC_S390X
-    {
-        int ret = s390x_HMAC_init(ctx, key, len);
-        if (ret != -1) /* -1 means SW fallback */
-            return ret;
-    }
+    rv = s390x_HMAC_init(ctx, key, len);
+    if (rv >= 1)
+        return rv;
 #endif
 
     if (key != NULL) {
diff --git a/crypto/hmac/hmac_s390x.c b/crypto/hmac/hmac_s390x.c
index 873e975284..eede428cf0 100644
--- a/crypto/hmac/hmac_s390x.c
+++ b/crypto/hmac/hmac_s390x.c
@@ -10,7 +10,7 @@
 /* We need to use some engine deprecated APIs */
 #define OPENSSL_SUPPRESS_DEPRECATED
 
-#include "arch/s390x_arch.h"
+#include "crypto/s390x_arch.h"
 #include "hmac_local.h"
 #include "openssl/obj_mac.h"
 #include "openssl/evp.h"
diff --git a/crypto/hpke/hpke_util.c b/crypto/hpke/hpke_util.c
index 3a662bc3f0..5a37f4ca52 100644
--- a/crypto/hpke/hpke_util.c
+++ b/crypto/hpke/hpke_util.c
@@ -406,8 +406,9 @@ EVP_KDF_CTX *ossl_kdf_ctx_create(const char *kdfname, const char *mdname,
     if (kctx != NULL && mdname != NULL) {
         OSSL_PARAM params[3], *p = params;
 
-        *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST,
-            (char *)mdname, 0);
+        if (mdname != NULL)
+            *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST,
+                (char *)mdname, 0);
         if (propq != NULL)
             *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_PROPERTIES,
                 (char *)propq, 0);
diff --git a/crypto/http/http_client.c b/crypto/http/http_client.c
index 34d3a2cccc..181b50e688 100644
--- a/crypto/http/http_client.c
+++ b/crypto/http/http_client.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2001-2025 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright Siemens AG 2018-2020
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
@@ -95,16 +95,6 @@ struct ossl_http_req_ctx_st {
 
 /* Low-level HTTP API implementation */
 
-static int no_crlf(const char *component, const char *value)
-{
-    if (value != NULL && strpbrk(value, "\r\n") != NULL) {
-        ERR_raise_data(ERR_LIB_HTTP, ERR_R_PASSED_INVALID_ARGUMENT,
-            "CR or LF character in %s", component);
-        return 0;
-    }
-    return 1;
-}
-
 OSSL_HTTP_REQ_CTX *OSSL_HTTP_REQ_CTX_new(BIO *wbio, BIO *rbio, int buf_size)
 {
     OSSL_HTTP_REQ_CTX *rctx;
@@ -194,10 +184,6 @@ int OSSL_HTTP_REQ_CTX_set_request_line(OSSL_HTTP_REQ_CTX *rctx, int method_POST,
         ERR_raise(ERR_LIB_HTTP, ERR_R_PASSED_NULL_PARAMETER);
         return 0;
     }
-    if (!no_crlf("server", server)
-        || !no_crlf("port", port)
-        || !no_crlf("path", path))
-        return 0;
     BIO_free(rctx->mem);
     if ((rctx->mem = BIO_new(BIO_s_mem())) == NULL)
         return 0;
@@ -251,9 +237,6 @@ int OSSL_HTTP_REQ_CTX_add1_header(OSSL_HTTP_REQ_CTX *rctx,
         ERR_raise(ERR_LIB_HTTP, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
         return 0;
     }
-    if (!no_crlf("header name", name)
-        || !no_crlf("header value", value))
-        return 0;
 
     if (BIO_puts(rctx->mem, name) <= 0)
         return 0;
@@ -327,7 +310,7 @@ static int set1_content(OSSL_HTTP_REQ_CTX *rctx,
     } else {
         if (HAS_CASE_PREFIX(content_type, "text/"))
             rctx->text = 1;
-        if (!OSSL_HTTP_REQ_CTX_add1_header(rctx, "Content-Type", content_type))
+        if (BIO_printf(rctx->mem, "Content-Type: %s\r\n", content_type) <= 0)
             return 0;
     }
 
@@ -568,7 +551,6 @@ static int may_still_retry(time_t max_time, int *ptimeout)
 int OSSL_HTTP_REQ_CTX_nbio(OSSL_HTTP_REQ_CTX *rctx)
 {
     int i, found_expected_ct = 0, found_keep_alive = 0;
-    int status_code = 0;
     int got_text = 1;
     long n;
     size_t resp_len = 0;
@@ -769,8 +751,8 @@ next_io:
 
         /* First line in response header */
         if (rctx->state == OHS_FIRSTLINE) {
-            status_code = parse_http_line1(buf, &found_keep_alive);
-            switch (status_code) {
+            i = parse_http_line1(buf, &found_keep_alive);
+            switch (i) {
             case HTTP_STATUS_CODE_OK:
                 rctx->state = OHS_HEADERS;
                 goto next_line;
@@ -785,7 +767,7 @@ next_io:
                 /* fall through */
             default:
                 /* must return content if status >= 400 */
-                rctx->state = status_code < HTTP_STATUS_CODES_NONFATAL_ERROR
+                rctx->state = i < HTTP_STATUS_CODES_NONFATAL_ERROR
                     ? OHS_HEADERS_ERROR
                     : OHS_HEADERS;
                 goto next_line; /* continue parsing, also on HTTP error */
@@ -815,17 +797,6 @@ next_io:
             }
             if (OPENSSL_strcasecmp(key, "Content-Type") == 0) {
                 got_text = HAS_CASE_PREFIX(value, "text/");
-                if (got_text
-                    && rctx->state == OHS_HEADERS
-                    && rctx->expect_asn1
-                    && (status_code >= HTTP_STATUS_CODES_NONFATAL_ERROR
-                        || status_code == HTTP_STATUS_CODE_OK)) {
-                    ERR_raise_data(ERR_LIB_HTTP, HTTP_R_CONTENT_TYPE_MISMATCH,
-                        "expected ASN.1 content but got http code %d with Content-Type: %s",
-                        status_code, value);
-                    rctx->state = OHS_HEADERS_ERROR;
-                    goto next_line;
-                }
                 if (rctx->state == OHS_HEADERS
                     && rctx->expected_ct != NULL) {
                     const char *semicolon;
@@ -1461,11 +1432,11 @@ int OSSL_HTTP_proxy_connect(BIO *bio, const char *server, const char *port,
 {
 #undef BUF_SIZE
 #define BUF_SIZE (8 * 1024)
-    char *mbuf = NULL;
+    char *mbuf = OPENSSL_malloc(BUF_SIZE);
     char *mbufp;
     int read_len = 0;
     int ret = 0;
-    BIO *fbio = NULL;
+    BIO *fbio = BIO_new(BIO_f_buffer());
     int rv;
     time_t max_time = timeout > 0 ? time(NULL) + timeout : 0;
 
@@ -1476,21 +1447,14 @@ int OSSL_HTTP_proxy_connect(BIO *bio, const char *server, const char *port,
     }
     if (port == NULL || *port == '\0')
         port = OSSL_HTTPS_PORT;
-    if (!no_crlf("server", server) || !no_crlf("port", port))
-        goto end;
 
-    if ((mbuf = OPENSSL_malloc(BUF_SIZE)) == NULL
-        || (fbio = BIO_new(BIO_f_buffer())) == NULL) {
+    if (mbuf == NULL || fbio == NULL) {
         BIO_printf(bio_err /* may be NULL */, "%s: out of memory", prog);
         goto end;
     }
     BIO_push(fbio, bio);
 
-    /* Add square brackets around a naked IPv6 address */
-    if (server[0] != '[' && strchr(server, ':') != NULL)
-        BIO_printf(fbio, "CONNECT [%s]:%s " HTTP_1_0 "\r\n", server, port);
-    else
-        BIO_printf(fbio, "CONNECT %s:%s " HTTP_1_0 "\r\n", server, port);
+    BIO_printf(fbio, "CONNECT %s:%s " HTTP_1_0 "\r\n", server, port);
 
     /*
      * Workaround for broken proxies which would otherwise close
diff --git a/crypto/http/http_err.c b/crypto/http/http_err.c
index 8598dd1ff4..947a403d60 100644
--- a/crypto/http/http_err.c
+++ b/crypto/http/http_err.c
@@ -1,6 +1,6 @@
 /*
  * Generated by util/mkerr.pl DO NOT EDIT
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -20,8 +20,6 @@ static const ERR_STRING_DATA HTTP_str_reasons[] = {
     { ERR_PACK(ERR_LIB_HTTP, 0, HTTP_R_ASN1_LEN_EXCEEDS_MAX_RESP_LEN),
         "asn1 len exceeds max resp len" },
     { ERR_PACK(ERR_LIB_HTTP, 0, HTTP_R_CONNECT_FAILURE), "connect failure" },
-    { ERR_PACK(ERR_LIB_HTTP, 0, HTTP_R_CONTENT_TYPE_MISMATCH),
-        "content type mismatch" },
     { ERR_PACK(ERR_LIB_HTTP, 0, HTTP_R_ERROR_PARSING_ASN1_LENGTH),
         "error parsing asn1 length" },
     { ERR_PACK(ERR_LIB_HTTP, 0, HTTP_R_ERROR_PARSING_CONTENT_LENGTH),
diff --git a/crypto/http/http_lib.c b/crypto/http/http_lib.c
index 0c394a2d9a..54c5c6ec1d 100644
--- a/crypto/http/http_lib.c
+++ b/crypto/http/http_lib.c
@@ -21,7 +21,6 @@
 #define NI_MAXHOST 255
 #endif
 #include "crypto/ctype.h" /* for ossl_isspace() */
-#define OSSL_URL_SCHEME_SUFFIX "://"
 
 static void init_pstring(char **pstr)
 {
@@ -56,7 +55,6 @@ int OSSL_parse_url(const char *url, char **pscheme, char **puser, char **phost,
     char **ppath, char **pquery, char **pfrag)
 {
     const char *p, *tmp;
-    const char *authority_end;
     const char *scheme, *scheme_end;
     const char *user, *user_end;
     const char *host, *host_end;
@@ -80,28 +78,21 @@ int OSSL_parse_url(const char *url, char **pscheme, char **puser, char **phost,
         return 0;
     }
 
-    /* check for optional prefix "://" as per RFC 3986 */
-    scheme = scheme_end = p = url;
-    if (ossl_isalpha(*p)) {
-        while (*p != '\0'
-            && (ossl_isalpha(*p)
-                || ossl_isdigit(*p)
-                || strchr("+-.", *p) != NULL))
-            p++;
-        if (HAS_PREFIX(p, OSSL_URL_SCHEME_SUFFIX)) {
-            scheme_end = p;
-            p += sizeof(OSSL_URL_SCHEME_SUFFIX) - 1;
-        } else {
-            p = url;
-        }
+    /* check for optional prefix "://" */
+    scheme = scheme_end = url;
+    p = strstr(url, "://");
+    if (p == NULL) {
+        p = url;
+    } else {
+        scheme_end = p;
+        if (scheme_end == scheme)
+            goto parse_err;
+        p += strlen("://");
     }
 
     /* parse optional "userinfo@" */
     user = user_end = host = p;
-    authority_end = strpbrk(p, "/?#");
-    if (authority_end == NULL)
-        authority_end = p + strlen(p);
-    host = memchr(p, '@', authority_end - p);
+    host = strchr(p, '@');
     if (host != NULL)
         user_end = host++;
     else
@@ -110,7 +101,7 @@ int OSSL_parse_url(const char *url, char **pscheme, char **puser, char **phost,
     /* parse hostname/address as far as needed here */
     if (host[0] == '[') {
         /* IPv6 literal, which may include ':' */
-        host_end = memchr(host + 1, ']', authority_end - host - 1);
+        host_end = strchr(host + 1, ']');
         if (host_end == NULL)
             goto parse_err;
         p = ++host_end;
@@ -276,9 +267,6 @@ static int use_proxy(const char *no_proxy, const char *server)
         server = host;
     }
 
-    if (sl == 0)
-        return 1;
-
     /*
      * using environment variable names, both lowercase and uppercase variants,
      * compatible with other HTTP client implementations like wget, curl and git
diff --git a/crypto/idea/i_cfb64.c b/crypto/idea/i_cfb64.c
index 1d530e0606..c8ed385328 100644
--- a/crypto/idea/i_cfb64.c
+++ b/crypto/idea/i_cfb64.c
@@ -37,7 +37,6 @@ void IDEA_cfb64_encrypt(const unsigned char *in, unsigned char *out,
         *num = -1;
         return;
     }
-    n = n & 0x07;
 
     iv = (unsigned char *)ivec;
     if (encrypt) {
diff --git a/crypto/idea/i_ofb64.c b/crypto/idea/i_ofb64.c
index 6c1ced96a3..afa6a960d4 100644
--- a/crypto/idea/i_ofb64.c
+++ b/crypto/idea/i_ofb64.c
@@ -39,7 +39,6 @@ void IDEA_ofb64_encrypt(const unsigned char *in, unsigned char *out,
         *num = -1;
         return;
     }
-    n = n & 0x07;
 
     iv = (unsigned char *)ivec;
     n2l(iv, v0);
diff --git a/crypto/idea/idea_local.h b/crypto/idea/idea_local.h
index 6a3d6829ae..73dcd3adbd 100644
--- a/crypto/idea/idea_local.h
+++ b/crypto/idea/idea_local.h
@@ -7,11 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_IDEA_IDEA_LOCAL_H)
-#define OSSL_LIBCRYPTO_IDEA_IDEA_LOCAL_H
-
-#include "internal/common.h"
-
 #define idea_mul(r, a, b, ul)                                          \
     ul = (unsigned long)a * b;                                         \
     if (ul != 0) {                                                     \
@@ -21,6 +16,89 @@
         r = (-(int)a - b + 1); /* assuming a or b is 0 and in range */ \
     }
 
+/* NOTE - c is not incremented as per n2l */
+#define n2ln(c, l1, l2, n)                           \
+    {                                                \
+        c += n;                                      \
+        l1 = l2 = 0;                                 \
+        switch (n) {                                 \
+        case 8:                                      \
+            l2 = ((unsigned long)(*(--(c))));        \
+        /* fall through */                           \
+        case 7:                                      \
+            l2 |= ((unsigned long)(*(--(c)))) << 8;  \
+        /* fall through */                           \
+        case 6:                                      \
+            l2 |= ((unsigned long)(*(--(c)))) << 16; \
+        /* fall through */                           \
+        case 5:                                      \
+            l2 |= ((unsigned long)(*(--(c)))) << 24; \
+        /* fall through */                           \
+        case 4:                                      \
+            l1 = ((unsigned long)(*(--(c))));        \
+        /* fall through */                           \
+        case 3:                                      \
+            l1 |= ((unsigned long)(*(--(c)))) << 8;  \
+        /* fall through */                           \
+        case 2:                                      \
+            l1 |= ((unsigned long)(*(--(c)))) << 16; \
+        /* fall through */                           \
+        case 1:                                      \
+            l1 |= ((unsigned long)(*(--(c)))) << 24; \
+        }                                            \
+    }
+
+/* NOTE - c is not incremented as per l2n */
+#define l2nn(l1, l2, c, n)                                   \
+    {                                                        \
+        c += n;                                              \
+        switch (n) {                                         \
+        case 8:                                              \
+            *(--(c)) = (unsigned char)(((l2)) & 0xff);       \
+        /* fall through */                                   \
+        case 7:                                              \
+            *(--(c)) = (unsigned char)(((l2) >> 8) & 0xff);  \
+        /* fall through */                                   \
+        case 6:                                              \
+            *(--(c)) = (unsigned char)(((l2) >> 16) & 0xff); \
+        /* fall through */                                   \
+        case 5:                                              \
+            *(--(c)) = (unsigned char)(((l2) >> 24) & 0xff); \
+        /* fall through */                                   \
+        case 4:                                              \
+            *(--(c)) = (unsigned char)(((l1)) & 0xff);       \
+        /* fall through */                                   \
+        case 3:                                              \
+            *(--(c)) = (unsigned char)(((l1) >> 8) & 0xff);  \
+        /* fall through */                                   \
+        case 2:                                              \
+            *(--(c)) = (unsigned char)(((l1) >> 16) & 0xff); \
+        /* fall through */                                   \
+        case 1:                                              \
+            *(--(c)) = (unsigned char)(((l1) >> 24) & 0xff); \
+        }                                                    \
+    }
+
+#undef n2l
+#define n2l(c, l) (l = ((unsigned long)(*((c)++))) << 24L, \
+    l |= ((unsigned long)(*((c)++))) << 16L,               \
+    l |= ((unsigned long)(*((c)++))) << 8L,                \
+    l |= ((unsigned long)(*((c)++))))
+
+#undef l2n
+#define l2n(l, c) (*((c)++) = (unsigned char)(((l) >> 24L) & 0xff), \
+    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff),                \
+    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff),                 \
+    *((c)++) = (unsigned char)(((l)) & 0xff))
+
+#undef s2n
+#define s2n(l, c) (*((c)++) = (unsigned char)(((l)) & 0xff), \
+    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff))
+
+#undef n2s
+#define n2s(c, l) (l = ((IDEA_INT)(*((c)++))) << 8L, \
+    l |= ((IDEA_INT)(*((c)++))))
+
 #define E_IDEA(num)                       \
     x1 &= 0xffff;                         \
     idea_mul(x1, x1, *p, ul);             \
@@ -42,5 +120,3 @@
     ul = x2 ^ t0; /* do the swap to x3 */ \
     x2 = x3 ^ t1;                         \
     x3 = ul;
-
-#endif /* !defined(OSSL_LIBCRYPTO_IDEA_IDEA_LOCAL_H) */
diff --git a/crypto/info.c b/crypto/info.c
index 4baece2246..fe8e5fa2a9 100644
--- a/crypto/info.c
+++ b/crypto/info.c
@@ -7,7 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include 
 #include 
 #include "crypto/rand.h"
 #include "crypto/dso_conf.h"
@@ -22,19 +21,19 @@
 #endif
 
 #if defined(__arm__) || defined(__arm) || defined(__aarch64__)
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 #define CPU_INFO_STR_LEN 128
 #elif defined(__powerpc__) || defined(__POWERPC__) || defined(_ARCH_PPC)
-#include "arch/ppc_arch.h"
+#include "crypto/ppc_arch.h"
 #define CPU_INFO_STR_LEN 128
 #elif defined(__sparcv9) || defined(__sparcv9__)
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 #define CPU_INFO_STR_LEN 128
 #elif defined(__s390__) || defined(__s390x__)
-#include "arch/s390x_arch.h"
+#include "s390x_arch.h"
 #define CPU_INFO_STR_LEN 2048
 #elif defined(__riscv)
-#include "arch/riscv_arch.h"
+#include "crypto/riscv_arch.h"
 #define CPU_INFO_STR_LEN 2048
 #else
 #define CPU_INFO_STR_LEN 256
@@ -50,75 +49,70 @@ char ossl_cpu_info_str[CPU_INFO_STR_LEN] = "";
 
 static CRYPTO_ONCE init_info = CRYPTO_ONCE_STATIC_INIT;
 
-/*
- * Append a printf-formatted suffix to ossl_cpu_info_str, truncating to
- * fit.  The first call writes the base string (the buffer starts empty,
- * so off == 0); subsequent calls extend it.
- */
-static ossl_unused void cpu_info_append(const char *fmt, ...)
-{
-    size_t off = strlen(ossl_cpu_info_str);
-    va_list args;
-
-    if (off >= sizeof(ossl_cpu_info_str))
-        return;
-    va_start(args, fmt);
-    (void)vsnprintf(ossl_cpu_info_str + off,
-        sizeof(ossl_cpu_info_str) - off, fmt, args);
-    va_end(args);
-}
-
 DEFINE_RUN_ONCE_STATIC(init_info_strings)
 {
 #if defined(OPENSSL_CPUID_OBJ)
 #if defined(__i386) || defined(__i386__) || defined(_M_IX86) || defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)
     const char *env;
 
-    cpu_info_append(CPUINFO_PREFIX
-        "OPENSSL_ia32cap=0x%.16llx:0x%.16llx:0x%.16llx:0x%.16llx:0x%.16llx",
+    BIO_snprintf(ossl_cpu_info_str, sizeof(ossl_cpu_info_str),
+        CPUINFO_PREFIX "OPENSSL_ia32cap=0x%.16llx:0x%.16llx:0x%.16llx:0x%.16llx:0x%.16llx",
         (unsigned long long)OPENSSL_ia32cap_P[0] | (unsigned long long)OPENSSL_ia32cap_P[1] << 32,
         (unsigned long long)OPENSSL_ia32cap_P[2] | (unsigned long long)OPENSSL_ia32cap_P[3] << 32,
         (unsigned long long)OPENSSL_ia32cap_P[4] | (unsigned long long)OPENSSL_ia32cap_P[5] << 32,
         (unsigned long long)OPENSSL_ia32cap_P[6] | (unsigned long long)OPENSSL_ia32cap_P[7] << 32,
         (unsigned long long)OPENSSL_ia32cap_P[8] | (unsigned long long)OPENSSL_ia32cap_P[9] << 32);
+
     if ((env = getenv("OPENSSL_ia32cap")) != NULL)
-        cpu_info_append(" env:%s", env);
+        BIO_snprintf(ossl_cpu_info_str + strlen(ossl_cpu_info_str),
+            sizeof(ossl_cpu_info_str) - strlen(ossl_cpu_info_str),
+            " env:%s", env);
 #elif defined(__arm__) || defined(__arm) || defined(__aarch64__)
     const char *env;
 
-    cpu_info_append(CPUINFO_PREFIX "OPENSSL_armcap=0x%x", OPENSSL_armcap_P);
+    BIO_snprintf(ossl_cpu_info_str, sizeof(ossl_cpu_info_str),
+        CPUINFO_PREFIX "OPENSSL_armcap=0x%x", OPENSSL_armcap_P);
     if ((env = getenv("OPENSSL_armcap")) != NULL)
-        cpu_info_append(" env:%s", env);
+        BIO_snprintf(ossl_cpu_info_str + strlen(ossl_cpu_info_str),
+            sizeof(ossl_cpu_info_str) - strlen(ossl_cpu_info_str),
+            " env:%s", env);
 #elif defined(__powerpc__) || defined(__POWERPC__) || defined(_ARCH_PPC)
     const char *env;
 
-    cpu_info_append(CPUINFO_PREFIX "OPENSSL_ppccap=0x%x", OPENSSL_ppccap_P);
+    BIO_snprintf(ossl_cpu_info_str, sizeof(ossl_cpu_info_str),
+        CPUINFO_PREFIX "OPENSSL_ppccap=0x%x", OPENSSL_ppccap_P);
     if ((env = getenv("OPENSSL_ppccap")) != NULL)
-        cpu_info_append(" env:%s", env);
+        BIO_snprintf(ossl_cpu_info_str + strlen(ossl_cpu_info_str),
+            sizeof(ossl_cpu_info_str) - strlen(ossl_cpu_info_str),
+            " env:%s", env);
 #elif defined(__sparcv9) || defined(__sparcv9__)
     const char *env;
 
-    cpu_info_append(CPUINFO_PREFIX "OPENSSL_sparcv9cap=0x%x:0x%x",
+    BIO_snprintf(ossl_cpu_info_str, sizeof(ossl_cpu_info_str),
+        CPUINFO_PREFIX "OPENSSL_sparcv9cap=0x%x:0x%x",
         OPENSSL_sparcv9cap_P[0], OPENSSL_sparcv9cap_P[1]);
     if ((env = getenv("OPENSSL_sparcv9cap")) != NULL)
-        cpu_info_append(" env:%s", env);
+        BIO_snprintf(ossl_cpu_info_str + strlen(ossl_cpu_info_str),
+            sizeof(ossl_cpu_info_str) - strlen(ossl_cpu_info_str),
+            " env:%s", env);
 #elif defined(__s390__) || defined(__s390x__)
     const char *env;
 
-    cpu_info_append(CPUINFO_PREFIX "OPENSSL_s390xcap="
-                                   "stfle:0x%llx:0x%llx:0x%llx:0x%llx:"
-                                   "kimd:0x%llx:0x%llx:"
-                                   "klmd:0x%llx:0x%llx:"
-                                   "km:0x%llx:0x%llx:"
-                                   "kmc:0x%llx:0x%llx:"
-                                   "kmac:0x%llx:0x%llx:"
-                                   "kmctr:0x%llx:0x%llx:"
-                                   "kmo:0x%llx:0x%llx:"
-                                   "kmf:0x%llx:0x%llx:"
-                                   "prno:0x%llx:0x%llx:"
-                                   "kma:0x%llx:0x%llx:"
-                                   "pcc:0x%llx:0x%llx:"
-                                   "kdsa:0x%llx:0x%llx",
+    BIO_snprintf(ossl_cpu_info_str, sizeof(ossl_cpu_info_str),
+        CPUINFO_PREFIX "OPENSSL_s390xcap="
+                       "stfle:0x%llx:0x%llx:0x%llx:0x%llx:"
+                       "kimd:0x%llx:0x%llx:"
+                       "klmd:0x%llx:0x%llx:"
+                       "km:0x%llx:0x%llx:"
+                       "kmc:0x%llx:0x%llx:"
+                       "kmac:0x%llx:0x%llx:"
+                       "kmctr:0x%llx:0x%llx:"
+                       "kmo:0x%llx:0x%llx:"
+                       "kmf:0x%llx:0x%llx:"
+                       "prno:0x%llx:0x%llx:"
+                       "kma:0x%llx:0x%llx:"
+                       "pcc:0x%llx:0x%llx:"
+                       "kdsa:0x%llx:0x%llx",
         OPENSSL_s390xcap_P.stfle[0], OPENSSL_s390xcap_P.stfle[1],
         OPENSSL_s390xcap_P.stfle[2], OPENSSL_s390xcap_P.stfle[3],
         OPENSSL_s390xcap_P.kimd[0], OPENSSL_s390xcap_P.kimd[1],
@@ -134,54 +128,63 @@ DEFINE_RUN_ONCE_STATIC(init_info_strings)
         OPENSSL_s390xcap_P.pcc[0], OPENSSL_s390xcap_P.pcc[1],
         OPENSSL_s390xcap_P.kdsa[0], OPENSSL_s390xcap_P.kdsa[1]);
     if ((env = getenv("OPENSSL_s390xcap")) != NULL)
-        cpu_info_append(" env:%s", env);
+        BIO_snprintf(ossl_cpu_info_str + strlen(ossl_cpu_info_str),
+            sizeof(ossl_cpu_info_str) - strlen(ossl_cpu_info_str),
+            " env:%s", env);
 #elif defined(__riscv)
     const char *env;
     size_t i;
 
-    cpu_info_append(CPUINFO_PREFIX "OPENSSL_riscvcap=RV"
+    BIO_snprintf(ossl_cpu_info_str, sizeof(ossl_cpu_info_str),
+        CPUINFO_PREFIX "OPENSSL_riscvcap=RV"
 #if __riscv_xlen == 32
-                                   "32"
+                       "32"
 #elif __riscv_xlen == 64
-                                   "64"
+                       "64"
 #elif __riscv_xlen == 128
-                                   "128"
+                       "128"
 #endif
 #if defined(__riscv_i) && defined(__riscv_m) && defined(__riscv_a) \
     && defined(__riscv_f) && defined(__riscv_d)                    \
     && defined(__riscv_zicsr) && defined(__riscv_zifencei)
-                                   "G" /* shorthand for IMAFD_Zicsr_Zifencei */
+                       "G" /* shorthand for IMAFD_Zicsr_Zifencei */
 #else
 #ifdef __riscv_i
-                                   "I"
+                       "I"
 #endif
 #ifdef __riscv_m
-                                   "M"
+                       "M"
 #endif
 #ifdef __riscv_a
-                                   "A"
+                       "A"
 #endif
 #ifdef __riscv_f
-                                   "F"
+                       "F"
 #endif
 #ifdef __riscv_d
-                                   "D"
+                       "D"
 #endif
 #endif
 #ifdef __riscv_c
-                                   "C"
+                       "C"
 #endif
     );
     for (i = 0; i < kRISCVNumCaps; i++) {
         if (OPENSSL_riscvcap_P[RISCV_capabilities[i].index]
             & (1 << RISCV_capabilities[i].bit_offset))
             /* Match, display the name */
-            cpu_info_append("_%s", RISCV_capabilities[i].name);
+            BIO_snprintf(ossl_cpu_info_str + strlen(ossl_cpu_info_str),
+                sizeof(ossl_cpu_info_str) - strlen(ossl_cpu_info_str),
+                "_%s", RISCV_capabilities[i].name);
     }
     if (RISCV_HAS_V())
-        cpu_info_append(" vlen:%lu", riscv_vlen());
+        BIO_snprintf(ossl_cpu_info_str + strlen(ossl_cpu_info_str),
+            sizeof(ossl_cpu_info_str) - strlen(ossl_cpu_info_str),
+            " vlen:%lu", riscv_vlen());
     if ((env = getenv("OPENSSL_riscvcap")) != NULL)
-        cpu_info_append(" env:%s", env);
+        BIO_snprintf(ossl_cpu_info_str + strlen(ossl_cpu_info_str),
+            sizeof(ossl_cpu_info_str) - strlen(ossl_cpu_info_str),
+            " env:%s", env);
 #endif
 #endif
 
diff --git a/crypto/init.c b/crypto/init.c
index 302e37f7fa..457ce4ca69 100644
--- a/crypto/init.c
+++ b/crypto/init.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -29,17 +29,19 @@
 #include  /* for OSSL_CMP_log_close() */
 #include 
 #include  /* for OPENSSL_INIT_(NO_)?LOAD_SSL_STRINGS */
-#include "crypto/bn.h"
 #include "crypto/ctype.h"
 #include "sslerr.h"
 
-#ifdef S390X_MOD_EXP
-#include "arch/s390x_arch.h"
-#endif
-
 static int stopped = 0;
 static uint64_t optsdone = 0;
 
+typedef struct ossl_init_stop_st OPENSSL_INIT_STOP;
+struct ossl_init_stop_st {
+    void (*handler)(void);
+    OPENSSL_INIT_STOP *next;
+};
+
+static OPENSSL_INIT_STOP *stop_handlers = NULL;
 /* Guards access to the optsdone variable on platforms without atomics */
 static CRYPTO_RWLOCK *optsdone_lock = NULL;
 /* Guards simultaneous INIT_LOAD_CONFIG calls with non-NULL settings */
@@ -48,7 +50,6 @@ static CRYPTO_THREAD_LOCAL in_init_config_local;
 
 static CRYPTO_ONCE base = CRYPTO_ONCE_STATIC_INIT;
 static int base_inited = 0;
-static int do_global_cleanup = 0;
 DEFINE_RUN_ONCE_STATIC(ossl_init_base)
 {
     /* no need to init trace */
@@ -83,6 +84,98 @@ err:
     return 0;
 }
 
+static CRYPTO_ONCE register_atexit = CRYPTO_ONCE_STATIC_INIT;
+#if !defined(OPENSSL_SYS_UEFI) && defined(_WIN32)
+static int win32atexit(void)
+{
+    OPENSSL_cleanup();
+    return 0;
+}
+#endif
+
+DEFINE_RUN_ONCE_STATIC(ossl_init_register_atexit)
+{
+#ifndef OPENSSL_NO_ATEXIT
+#ifdef OPENSSL_INIT_DEBUG
+    fprintf(stderr, "OPENSSL_INIT: ossl_init_register_atexit()\n");
+#endif
+#ifndef OPENSSL_SYS_UEFI
+#if defined(_WIN32) && !defined(__BORLANDC__)
+    /* We use _onexit() in preference because it gets called on DLL unload */
+    if (_onexit(win32atexit) == NULL)
+        return 0;
+#else
+    if (atexit(OPENSSL_cleanup) != 0)
+        return 0;
+#endif
+#endif
+#endif
+
+    return 1;
+}
+
+DEFINE_RUN_ONCE_STATIC_ALT(ossl_init_no_register_atexit,
+    ossl_init_register_atexit)
+{
+#ifdef OPENSSL_INIT_DEBUG
+    fprintf(stderr, "OPENSSL_INIT: ossl_init_no_register_atexit ok!\n");
+#endif
+    /* Do nothing in this case */
+    return 1;
+}
+
+static CRYPTO_ONCE load_crypto_nodelete = CRYPTO_ONCE_STATIC_INIT;
+DEFINE_RUN_ONCE_STATIC(ossl_init_load_crypto_nodelete)
+{
+    OSSL_TRACE(INIT, "ossl_init_load_crypto_nodelete()\n");
+
+#if !defined(OPENSSL_USE_NODELETE) \
+    && !defined(OPENSSL_NO_PINSHARED)
+#if defined(DSO_WIN32) && !defined(_WIN32_WCE)
+    {
+        HMODULE handle = NULL;
+        BOOL ret;
+
+        /* We don't use the DSO route for WIN32 because there is a better way */
+        ret = GetModuleHandleEx(GET_MODULE_HANDLE_EX_FLAG_FROM_ADDRESS
+                | GET_MODULE_HANDLE_EX_FLAG_PIN,
+            (void *)&base_inited, &handle);
+
+        OSSL_TRACE1(INIT,
+            "ossl_init_load_crypto_nodelete: "
+            "obtained DSO reference? %s\n",
+            (ret == TRUE ? "No!" : "Yes."));
+        return (ret == TRUE) ? 1 : 0;
+    }
+#elif !defined(DSO_NONE)
+    /*
+     * Deliberately leak a reference to ourselves. This will force the library
+     * to remain loaded until the atexit() handler is run at process exit.
+     */
+    {
+        DSO *dso;
+        void *err;
+
+        if (!err_shelve_state(&err))
+            return 0;
+
+        dso = DSO_dsobyaddr(&base_inited, DSO_FLAG_NO_UNLOAD_ON_FREE);
+        /*
+         * In case of No!, it is uncertain our exit()-handlers can still be
+         * called. After dlclose() the whole library might have been unloaded
+         * already.
+         */
+        OSSL_TRACE1(INIT, "obtained DSO reference? %s\n",
+            (dso == NULL ? "No!" : "Yes."));
+        DSO_free(dso);
+        err_unshelve_state(err);
+    }
+#endif
+#endif
+
+    return 1;
+}
+
 static CRYPTO_ONCE load_crypto_strings = CRYPTO_ONCE_STATIC_INIT;
 
 DEFINE_RUN_ONCE_STATIC(ossl_init_load_crypto_strings)
@@ -178,24 +271,27 @@ DEFINE_RUN_ONCE_STATIC_ALT(ossl_init_no_add_all_digests,
 }
 
 static CRYPTO_ONCE config = CRYPTO_ONCE_STATIC_INIT;
+static int config_inited = 0;
 static const OPENSSL_INIT_SETTINGS *conf_settings = NULL;
 DEFINE_RUN_ONCE_STATIC(ossl_init_config)
 {
     int ret = ossl_config_int(NULL);
 
+    config_inited = 1;
     return ret;
 }
 DEFINE_RUN_ONCE_STATIC_ALT(ossl_init_config_settings, ossl_init_config)
 {
     int ret = ossl_config_int(conf_settings);
 
+    config_inited = 1;
     return ret;
 }
 DEFINE_RUN_ONCE_STATIC_ALT(ossl_init_no_config, ossl_init_config)
 {
     OSSL_TRACE(INIT, "ossl_no_config_int()\n");
     ossl_no_config_int();
-
+    config_inited = 1;
     return 1;
 }
 
@@ -210,29 +306,10 @@ DEFINE_RUN_ONCE_STATIC(ossl_init_async)
     return 1;
 }
 
-/*
- * Global cleanup function. This is optional, and not strictly
- * necessary to run. Operating systems have successfully been
- * recovering memory from exiting tasks since the days when I amused
- * myself by drawing dinosaurs in crayon on used punch cards.
- *
- * If we have destructor support, this function is installed and
- * always run as a global destructor. It only does anything if
- * someone has called OPENSSL_cleanup() before it is run.
- *
- * This ensures that we do the actual cleanup requested by an
- * OPENSSL_cleanup() only after subordinate library destructors which
- * may call into OpenSSL have run.
- *
- * If we do not have destructor support, then this function is not
- * normally run, and OPENSSL_cleanup() will do nothing. If we are
- * compiled with the compile time define of
- * DO_NOT_SKIP_OPENSSL_CLEANUP, this function will be called
- * directly from OPENSSL_cleanup() so that cleanup will happen
- * when OPENSSL_cleanup() is called.
- */
-void ossl_cleanup_destructor(void)
+void OPENSSL_cleanup(void)
 {
+    OPENSSL_INIT_STOP *currhandler, *lasthandler;
+
     /*
      * At some point we should consider looking at this function with a view to
      * moving most/all of this into onfree handlers in OSSL_LIB_CTX.
@@ -242,11 +319,7 @@ void ossl_cleanup_destructor(void)
     if (!base_inited)
         return;
 
-    /* If we have not been told to clean up, and we are invoked, return */
-    if (!do_global_cleanup)
-        return;
-
-    /* Might be explicitly called */
+    /* Might be explicitly called and also by atexit */
     if (stopped)
         return;
     stopped = 1;
@@ -257,6 +330,15 @@ void ossl_cleanup_destructor(void)
      */
     OPENSSL_thread_stop();
 
+    currhandler = stop_handlers;
+    while (currhandler != NULL) {
+        currhandler->handler();
+        lasthandler = currhandler;
+        currhandler = currhandler->next;
+        OPENSSL_free(lasthandler);
+    }
+    stop_handlers = NULL;
+
     CRYPTO_THREAD_lock_free(optsdone_lock);
     optsdone_lock = NULL;
     CRYPTO_THREAD_lock_free(init_lock);
@@ -333,10 +415,6 @@ void ossl_cleanup_destructor(void)
     OSSL_TRACE(INIT, "OPENSSL_cleanup: ossl_trace_cleanup()\n");
     ossl_trace_cleanup();
 
-#ifdef S390X_MOD_EXP
-    OPENSSL_s390x_cleanup();
-#endif
-
     base_inited = 0;
 }
 
@@ -382,7 +460,10 @@ int OPENSSL_init_crypto(uint64_t opts, const OPENSSL_INIT_SETTINGS *settings)
      *
      * When the caller specifies OPENSSL_INIT_BASE_ONLY, that should be the
      * *only* option specified.  With that option we return immediately after
-     * doing the requested limited initialization.
+     * doing the requested limited initialization.  Note that
+     * err_shelve_state() called by us via ossl_init_load_crypto_nodelete()
+     * re-enters OPENSSL_init_crypto() with OPENSSL_INIT_BASE_ONLY, but with
+     * base already initialized this is a harmless NOOP.
      *
      * If we remain the only caller of err_shelve_state() the recursion should
      * perhaps be removed, but if in doubt, it can be left in place.
@@ -405,6 +486,23 @@ int OPENSSL_init_crypto(uint64_t opts, const OPENSSL_INIT_SETTINGS *settings)
             return 1;
     }
 
+    /*
+     * Now we don't always set up exit handlers, the INIT_BASE_ONLY calls
+     * should not have the side-effect of setting up exit handlers, and
+     * therefore, this code block is below the INIT_BASE_ONLY-conditioned early
+     * return above.
+     */
+    if ((opts & OPENSSL_INIT_NO_ATEXIT) != 0) {
+        if (!RUN_ONCE_ALT(®ister_atexit, ossl_init_no_register_atexit,
+                ossl_init_register_atexit))
+            return 0;
+    } else if (!RUN_ONCE(®ister_atexit, ossl_init_register_atexit)) {
+        return 0;
+    }
+
+    if (!RUN_ONCE(&load_crypto_nodelete, ossl_init_load_crypto_nodelete))
+        return 0;
+
     if ((opts & OPENSSL_INIT_NO_LOAD_CRYPTO_STRINGS)
         && !RUN_ONCE_ALT(&load_crypto_strings,
             ossl_init_no_load_crypto_strings,
@@ -486,14 +584,66 @@ int OPENSSL_init_crypto(uint64_t opts, const OPENSSL_INIT_SETTINGS *settings)
     return 1;
 }
 
-void OPENSSL_cleanup(void)
+int OPENSSL_atexit(void (*handler)(void))
 {
-    do_global_cleanup = 1;
-#if defined(OSSL_CLEANUP_USING_DESTRUCTOR)
-    return;
-#endif /* defined(OSSL_CLEANUP_USING_DESTRUCTOR) */
+    OPENSSL_INIT_STOP *newhand;
 
-#if defined(DO_NOT_SKIP_OPENSSL_CLEANUP)
-    ossl_cleanup_destructor();
-#endif /* defined(DO_NOT_SKIP_OPENSSL_CLEANUP) */
+#if !defined(OPENSSL_USE_NODELETE) \
+    && !defined(OPENSSL_NO_PINSHARED)
+    {
+#if defined(DSO_WIN32) && !defined(_WIN32_WCE)
+        HMODULE handle = NULL;
+        BOOL ret;
+        union {
+            void *sym;
+            void (*func)(void);
+        } handlersym;
+
+        handlersym.func = handler;
+
+        /*
+         * We don't use the DSO route for WIN32 because there is a better
+         * way
+         */
+        ret = GetModuleHandleEx(GET_MODULE_HANDLE_EX_FLAG_FROM_ADDRESS
+                | GET_MODULE_HANDLE_EX_FLAG_PIN,
+            handlersym.sym, &handle);
+
+        if (!ret)
+            return 0;
+#elif !defined(DSO_NONE)
+        /*
+         * Deliberately leak a reference to the handler. This will force the
+         * library/code containing the handler to remain loaded until we run the
+         * atexit handler. If -znodelete has been used then this is
+         * unnecessary.
+         */
+        DSO *dso = NULL;
+        union {
+            void *sym;
+            void (*func)(void);
+        } handlersym;
+
+        handlersym.func = handler;
+
+        ERR_set_mark();
+        dso = DSO_dsobyaddr(handlersym.sym, DSO_FLAG_NO_UNLOAD_ON_FREE);
+        /* See same code above in ossl_init_base() for an explanation. */
+        OSSL_TRACE1(INIT,
+            "atexit: obtained DSO reference? %s\n",
+            (dso == NULL ? "No!" : "Yes."));
+        DSO_free(dso);
+        ERR_pop_to_mark();
+#endif
+    }
+#endif
+
+    if ((newhand = OPENSSL_malloc(sizeof(*newhand))) == NULL)
+        return 0;
+
+    newhand->handler = handler;
+    newhand->next = stop_handlers;
+    stop_handlers = newhand;
+
+    return 1;
 }
diff --git a/crypto/lhash/lhash_local.h b/crypto/lhash/lhash_local.h
index 8d1b671d18..4a7cdfb9f6 100644
--- a/crypto/lhash/lhash_local.h
+++ b/crypto/lhash/lhash_local.h
@@ -6,11 +6,7 @@
  * in the file LICENSE in the source distribution or at
  * https://www.openssl.org/source/license.html
  */
-#if !defined(OSSL_LIBCRYPTO_LHASH_LHASH_LOCAL_H)
-#define OSSL_LIBCRYPTO_LHASH_LHASH_LOCAL_H
-
 #include 
-#include 
 
 #include "internal/tsan_assist.h"
 
@@ -37,5 +33,3 @@ struct lhash_st {
     unsigned long num_items;
     int error;
 };
-
-#endif /* !defined(OSSL_LIBCRYPTO_LHASH_LHASH_LOCAL_H) */
diff --git a/crypto/lms/lms_key.c b/crypto/lms/lms_key.c
index 58c2205d78..a5d87ad845 100644
--- a/crypto/lms/lms_key.c
+++ b/crypto/lms/lms_key.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -106,25 +106,3 @@ int ossl_lms_key_has(const LMS_KEY *key, int selection)
         return 0;
     return 1;
 }
-
-/* Returns the public key data or NULL if there is no public key */
-const uint8_t *ossl_lms_key_get_pub(const LMS_KEY *key)
-{
-    return key->pub.encoded;
-}
-
-/* The encoded public key size */
-size_t ossl_lms_key_get_pub_len(const LMS_KEY *key)
-{
-    return 24 + key->lms_params->n;
-}
-
-size_t ossl_lms_key_get_collision_strength_bits(const LMS_KEY *key)
-{
-    return key->lms_params->n * 8;
-}
-
-size_t ossl_lms_key_get_sig_len(const LMS_KEY *key)
-{
-    return 12 + key->lms_params->n * (1 + key->ots_params->p + key->lms_params->h);
-}
diff --git a/crypto/lms/lms_params.c b/crypto/lms/lms_params.c
index 722a41940a..6ac6dcdb81 100644
--- a/crypto/lms/lms_params.c
+++ b/crypto/lms/lms_params.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -11,27 +11,27 @@
 
 /* Refer to SP800-208 Section 4 LMS Parameter Sets */
 static const LMS_PARAMS lms_params[] = {
-    { OSSL_LMS_TYPE_SHA256_N32_H5, "SHA256", 32, 5, 128 },
-    { OSSL_LMS_TYPE_SHA256_N32_H10, "SHA256", 32, 10, 128 },
-    { OSSL_LMS_TYPE_SHA256_N32_H15, "SHA256", 32, 15, 128 },
-    { OSSL_LMS_TYPE_SHA256_N32_H20, "SHA256", 32, 20, 128 },
-    { OSSL_LMS_TYPE_SHA256_N32_H25, "SHA256", 32, 25, 128 },
-    { OSSL_LMS_TYPE_SHA256_N24_H5, "SHA256-192", 24, 5, 96 },
-    { OSSL_LMS_TYPE_SHA256_N24_H10, "SHA256-192", 24, 10, 96 },
-    { OSSL_LMS_TYPE_SHA256_N24_H15, "SHA256-192", 24, 15, 96 },
-    { OSSL_LMS_TYPE_SHA256_N24_H20, "SHA256-192", 24, 20, 96 },
-    { OSSL_LMS_TYPE_SHA256_N24_H25, "SHA256-192", 24, 25, 96 },
-    { OSSL_LMS_TYPE_SHAKE_N32_H5, "SHAKE-256", 32, 5, 256 },
-    { OSSL_LMS_TYPE_SHAKE_N32_H10, "SHAKE-256", 32, 10, 256 },
-    { OSSL_LMS_TYPE_SHAKE_N32_H15, "SHAKE-256", 32, 15, 256 },
-    { OSSL_LMS_TYPE_SHAKE_N32_H20, "SHAKE-256", 32, 20, 256 },
-    { OSSL_LMS_TYPE_SHAKE_N32_H25, "SHAKE-256", 32, 25, 256 },
+    { OSSL_LMS_TYPE_SHA256_N32_H5, "SHA256", 32, 5 },
+    { OSSL_LMS_TYPE_SHA256_N32_H10, "SHA256", 32, 10 },
+    { OSSL_LMS_TYPE_SHA256_N32_H15, "SHA256", 32, 15 },
+    { OSSL_LMS_TYPE_SHA256_N32_H20, "SHA256", 32, 20 },
+    { OSSL_LMS_TYPE_SHA256_N32_H25, "SHA256", 32, 25 },
+    { OSSL_LMS_TYPE_SHA256_N24_H5, "SHA256-192", 24, 5 },
+    { OSSL_LMS_TYPE_SHA256_N24_H10, "SHA256-192", 24, 10 },
+    { OSSL_LMS_TYPE_SHA256_N24_H15, "SHA256-192", 24, 15 },
+    { OSSL_LMS_TYPE_SHA256_N24_H20, "SHA256-192", 24, 20 },
+    { OSSL_LMS_TYPE_SHA256_N24_H25, "SHA256-192", 24, 25 },
+    { OSSL_LMS_TYPE_SHAKE_N32_H5, "SHAKE-256", 32, 5 },
+    { OSSL_LMS_TYPE_SHAKE_N32_H10, "SHAKE-256", 32, 10 },
+    { OSSL_LMS_TYPE_SHAKE_N32_H15, "SHAKE-256", 32, 15 },
+    { OSSL_LMS_TYPE_SHAKE_N32_H20, "SHAKE-256", 32, 20 },
+    { OSSL_LMS_TYPE_SHAKE_N32_H25, "SHAKE-256", 32, 25 },
     /* SHAKE-256/192 */
-    { OSSL_LMS_TYPE_SHAKE_N24_H5, "SHAKE-256", 24, 5, 192 },
-    { OSSL_LMS_TYPE_SHAKE_N24_H10, "SHAKE-256", 24, 10, 192 },
-    { OSSL_LMS_TYPE_SHAKE_N24_H15, "SHAKE-256", 24, 15, 192 },
-    { OSSL_LMS_TYPE_SHAKE_N24_H20, "SHAKE-256", 24, 20, 192 },
-    { OSSL_LMS_TYPE_SHAKE_N24_H25, "SHAKE-256", 24, 25, 192 },
+    { OSSL_LMS_TYPE_SHAKE_N24_H5, "SHAKE-256", 24, 5 },
+    { OSSL_LMS_TYPE_SHAKE_N24_H10, "SHAKE-256", 24, 10 },
+    { OSSL_LMS_TYPE_SHAKE_N24_H15, "SHAKE-256", 24, 15 },
+    { OSSL_LMS_TYPE_SHAKE_N24_H20, "SHAKE-256", 24, 20 },
+    { OSSL_LMS_TYPE_SHAKE_N24_H25, "SHAKE-256", 24, 25 },
 
     { 0, NULL, 0, 0 }
 };
diff --git a/crypto/lms/lms_pubkey_decode.c b/crypto/lms/lms_pubkey_decode.c
index 29ca1d44af..b5bb3dc74b 100644
--- a/crypto/lms/lms_pubkey_decode.c
+++ b/crypto/lms/lms_pubkey_decode.c
@@ -95,7 +95,7 @@ int ossl_lms_pubkey_decode(const unsigned char *pub, size_t publen,
 {
     LMS_PUB_KEY *pkey = &lmskey->pub;
 
-    if (pkey->encoded != NULL) {
+    if (pkey->encoded != NULL && pkey->encodedlen != publen) {
         OPENSSL_free(pkey->encoded);
         pkey->encodedlen = 0;
     }
@@ -110,7 +110,6 @@ int ossl_lms_pubkey_decode(const unsigned char *pub, size_t publen,
 err:
     OPENSSL_free(pkey->encoded);
     pkey->encoded = NULL;
-    pkey->encodedlen = 0;
     return 0;
 }
 
@@ -123,17 +122,11 @@ err:
  */
 int ossl_lms_pubkey_from_params(const OSSL_PARAM *pub, LMS_KEY *lmskey)
 {
-    /*
-     * An LMS_KEY with no public key material is unusable - lms_params
-     * and ots_params would remain NULL and any subsequent consumer op
-     * (lms_get_params -> ossl_lms_key_get_pub_len, lms_verify_msg_init
-     * -> setdigest, ...) would dereference NULL.  Require the caller
-     * to supply a well-formed OSSL_PKEY_PARAM_PUB_KEY.
-     */
-    if (pub == NULL
-        || pub->data == NULL
-        || pub->data_type != OSSL_PARAM_OCTET_STRING
-        || !ossl_lms_pubkey_decode(pub->data, pub->data_size, lmskey))
-        return 0;
+    if (pub != NULL) {
+        if (pub->data == NULL
+            || pub->data_type != OSSL_PARAM_OCTET_STRING
+            || !ossl_lms_pubkey_decode(pub->data, pub->data_size, lmskey))
+            return 0;
+    }
     return 1;
 }
diff --git a/include/arch/loongarch_arch.h b/crypto/loongarch_arch.h
similarity index 100%
rename from include/arch/loongarch_arch.h
rename to crypto/loongarch_arch.h
diff --git a/crypto/loongarchcap.c b/crypto/loongarchcap.c
index d259276e47..5375eb3655 100644
--- a/crypto/loongarchcap.c
+++ b/crypto/loongarchcap.c
@@ -7,7 +7,7 @@
  * https://www.openssl.org/source/license.html
  */
 #include 
-#include "arch/loongarch_arch.h"
+#include "loongarch_arch.h"
 
 unsigned int OPENSSL_loongarch_hwcap_P = 0;
 
diff --git a/crypto/md2/md2_dgst.c b/crypto/md2/md2_dgst.c
index 4b99f88bea..61c4b72507 100644
--- a/crypto/md2/md2_dgst.c
+++ b/crypto/md2/md2_dgst.c
@@ -32,32 +32,262 @@ static void md2_block(MD2_CTX *c, const unsigned char *d);
  * a random byte string.
  */
 static const MD2_INT S[256] = {
-    0x29, 0x2E, 0x43, 0xC9, 0xA2, 0xD8, 0x7C, 0x01, 0x3D, 0x36,
-    0x54, 0xA1, 0xEC, 0xF0, 0x06, 0x13, 0x62, 0xA7, 0x05, 0xF3,
-    0xC0, 0xC7, 0x73, 0x8C, 0x98, 0x93, 0x2B, 0xD9, 0xBC, 0x4C,
-    0x82, 0xCA, 0x1E, 0x9B, 0x57, 0x3C, 0xFD, 0xD4, 0xE0, 0x16,
-    0x67, 0x42, 0x6F, 0x18, 0x8A, 0x17, 0xE5, 0x12, 0xBE, 0x4E,
-    0xC4, 0xD6, 0xDA, 0x9E, 0xDE, 0x49, 0xA0, 0xFB, 0xF5, 0x8E,
-    0xBB, 0x2F, 0xEE, 0x7A, 0xA9, 0x68, 0x79, 0x91, 0x15, 0xB2,
-    0x07, 0x3F, 0x94, 0xC2, 0x10, 0x89, 0x0B, 0x22, 0x5F, 0x21,
-    0x80, 0x7F, 0x5D, 0x9A, 0x5A, 0x90, 0x32, 0x27, 0x35, 0x3E,
-    0xCC, 0xE7, 0xBF, 0xF7, 0x97, 0x03, 0xFF, 0x19, 0x30, 0xB3,
-    0x48, 0xA5, 0xB5, 0xD1, 0xD7, 0x5E, 0x92, 0x2A, 0xAC, 0x56,
-    0xAA, 0xC6, 0x4F, 0xB8, 0x38, 0xD2, 0x96, 0xA4, 0x7D, 0xB6,
-    0x76, 0xFC, 0x6B, 0xE2, 0x9C, 0x74, 0x04, 0xF1, 0x45, 0x9D,
-    0x70, 0x59, 0x64, 0x71, 0x87, 0x20, 0x86, 0x5B, 0xCF, 0x65,
-    0xE6, 0x2D, 0xA8, 0x02, 0x1B, 0x60, 0x25, 0xAD, 0xAE, 0xB0,
-    0xB9, 0xF6, 0x1C, 0x46, 0x61, 0x69, 0x34, 0x40, 0x7E, 0x0F,
-    0x55, 0x47, 0xA3, 0x23, 0xDD, 0x51, 0xAF, 0x3A, 0xC3, 0x5C,
-    0xF9, 0xCE, 0xBA, 0xC5, 0xEA, 0x26, 0x2C, 0x53, 0x0D, 0x6E,
-    0x85, 0x28, 0x84, 0x09, 0xD3, 0xDF, 0xCD, 0xF4, 0x41, 0x81,
-    0x4D, 0x52, 0x6A, 0xDC, 0x37, 0xC8, 0x6C, 0xC1, 0xAB, 0xFA,
-    0x24, 0xE1, 0x7B, 0x08, 0x0C, 0xBD, 0xB1, 0x4A, 0x78, 0x88,
-    0x95, 0x8B, 0xE3, 0x63, 0xE8, 0x6D, 0xE9, 0xCB, 0xD5, 0xFE,
-    0x3B, 0x00, 0x1D, 0x39, 0xF2, 0xEF, 0xB7, 0x0E, 0x66, 0x58,
-    0xD0, 0xE4, 0xA6, 0x77, 0x72, 0xF8, 0xEB, 0x75, 0x4B, 0x0A,
-    0x31, 0x44, 0x50, 0xB4, 0x8F, 0xED, 0x1F, 0x1A, 0xDB, 0x99,
-    0x8D, 0x33, 0x9F, 0x11, 0x83, 0x14
+    0x29,
+    0x2E,
+    0x43,
+    0xC9,
+    0xA2,
+    0xD8,
+    0x7C,
+    0x01,
+    0x3D,
+    0x36,
+    0x54,
+    0xA1,
+    0xEC,
+    0xF0,
+    0x06,
+    0x13,
+    0x62,
+    0xA7,
+    0x05,
+    0xF3,
+    0xC0,
+    0xC7,
+    0x73,
+    0x8C,
+    0x98,
+    0x93,
+    0x2B,
+    0xD9,
+    0xBC,
+    0x4C,
+    0x82,
+    0xCA,
+    0x1E,
+    0x9B,
+    0x57,
+    0x3C,
+    0xFD,
+    0xD4,
+    0xE0,
+    0x16,
+    0x67,
+    0x42,
+    0x6F,
+    0x18,
+    0x8A,
+    0x17,
+    0xE5,
+    0x12,
+    0xBE,
+    0x4E,
+    0xC4,
+    0xD6,
+    0xDA,
+    0x9E,
+    0xDE,
+    0x49,
+    0xA0,
+    0xFB,
+    0xF5,
+    0x8E,
+    0xBB,
+    0x2F,
+    0xEE,
+    0x7A,
+    0xA9,
+    0x68,
+    0x79,
+    0x91,
+    0x15,
+    0xB2,
+    0x07,
+    0x3F,
+    0x94,
+    0xC2,
+    0x10,
+    0x89,
+    0x0B,
+    0x22,
+    0x5F,
+    0x21,
+    0x80,
+    0x7F,
+    0x5D,
+    0x9A,
+    0x5A,
+    0x90,
+    0x32,
+    0x27,
+    0x35,
+    0x3E,
+    0xCC,
+    0xE7,
+    0xBF,
+    0xF7,
+    0x97,
+    0x03,
+    0xFF,
+    0x19,
+    0x30,
+    0xB3,
+    0x48,
+    0xA5,
+    0xB5,
+    0xD1,
+    0xD7,
+    0x5E,
+    0x92,
+    0x2A,
+    0xAC,
+    0x56,
+    0xAA,
+    0xC6,
+    0x4F,
+    0xB8,
+    0x38,
+    0xD2,
+    0x96,
+    0xA4,
+    0x7D,
+    0xB6,
+    0x76,
+    0xFC,
+    0x6B,
+    0xE2,
+    0x9C,
+    0x74,
+    0x04,
+    0xF1,
+    0x45,
+    0x9D,
+    0x70,
+    0x59,
+    0x64,
+    0x71,
+    0x87,
+    0x20,
+    0x86,
+    0x5B,
+    0xCF,
+    0x65,
+    0xE6,
+    0x2D,
+    0xA8,
+    0x02,
+    0x1B,
+    0x60,
+    0x25,
+    0xAD,
+    0xAE,
+    0xB0,
+    0xB9,
+    0xF6,
+    0x1C,
+    0x46,
+    0x61,
+    0x69,
+    0x34,
+    0x40,
+    0x7E,
+    0x0F,
+    0x55,
+    0x47,
+    0xA3,
+    0x23,
+    0xDD,
+    0x51,
+    0xAF,
+    0x3A,
+    0xC3,
+    0x5C,
+    0xF9,
+    0xCE,
+    0xBA,
+    0xC5,
+    0xEA,
+    0x26,
+    0x2C,
+    0x53,
+    0x0D,
+    0x6E,
+    0x85,
+    0x28,
+    0x84,
+    0x09,
+    0xD3,
+    0xDF,
+    0xCD,
+    0xF4,
+    0x41,
+    0x81,
+    0x4D,
+    0x52,
+    0x6A,
+    0xDC,
+    0x37,
+    0xC8,
+    0x6C,
+    0xC1,
+    0xAB,
+    0xFA,
+    0x24,
+    0xE1,
+    0x7B,
+    0x08,
+    0x0C,
+    0xBD,
+    0xB1,
+    0x4A,
+    0x78,
+    0x88,
+    0x95,
+    0x8B,
+    0xE3,
+    0x63,
+    0xE8,
+    0x6D,
+    0xE9,
+    0xCB,
+    0xD5,
+    0xFE,
+    0x3B,
+    0x00,
+    0x1D,
+    0x39,
+    0xF2,
+    0xEF,
+    0xB7,
+    0x0E,
+    0x66,
+    0x58,
+    0xD0,
+    0xE4,
+    0xA6,
+    0x77,
+    0x72,
+    0xF8,
+    0xEB,
+    0x75,
+    0x4B,
+    0x0A,
+    0x31,
+    0x44,
+    0x50,
+    0xB4,
+    0x8F,
+    0xED,
+    0x1F,
+    0x1A,
+    0xDB,
+    0x99,
+    0x8D,
+    0x33,
+    0x9F,
+    0x11,
+    0x83,
+    0x14,
 };
 
 const char *MD2_options(void)
diff --git a/crypto/md4/md4_local.h b/crypto/md4/md4_local.h
index c6ccfb1c78..ec2a8c361c 100644
--- a/crypto/md4/md4_local.h
+++ b/crypto/md4/md4_local.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_MD4_MD4_LOCAL_H)
-#define OSSL_LIBCRYPTO_MD4_MD4_LOCAL_H
-
 #include 
 #include 
 #include 
@@ -39,9 +36,7 @@ void md4_block_data_order(MD4_CTX *c, const void *p, size_t num);
     } while (0)
 #define HASH_BLOCK_DATA_ORDER md4_block_data_order
 
-/* clang-format off */
-#include "crypto/md32_common.inc"
-/* clang-format on */
+#include "crypto/md32_common.h"
 
 /*-
 #define F(x,y,z)        (((x) & (y))  |  ((~(x)) & (z)))
@@ -74,5 +69,3 @@ void md4_block_data_order(MD4_CTX *c, const void *p, size_t num);
         a += ((k) + (t) + H((b), (c), (d))); \
         a = ROTATE(a, s);                    \
     };
-
-#endif /* !defined(OSSL_LIBCRYPTO_MD4_MD4_LOCAL_H) */
diff --git a/crypto/md5/asm/md5-aarch64.pl b/crypto/md5/asm/md5-aarch64.pl
index 6ef69715d0..02bc05caaf 100755
--- a/crypto/md5/asm/md5-aarch64.pl
+++ b/crypto/md5/asm/md5-aarch64.pl
@@ -28,7 +28,7 @@ open OUT,"| \"$^X\" $xlate $flavour \"$output\""
 *STDOUT=*OUT;
 
 $code .= <
 #include 
 #include 
@@ -49,9 +46,7 @@ void md5_block_data_order(MD5_CTX *c, const void *p, size_t num);
     } while (0)
 #define HASH_BLOCK_DATA_ORDER md5_block_data_order
 
-/* clang-format off */
-#include "crypto/md32_common.inc"
-/* clang-format on */
+#include "crypto/md32_common.h"
 
 /*-
 #define F(x,y,z)        (((x) & (y))  |  ((~(x)) & (z)))
@@ -95,5 +90,3 @@ void md5_block_data_order(MD5_CTX *c, const void *p, size_t num);
         a = ROTATE(a, s);                    \
         a += b;                              \
     };
-
-#endif /* !defined(OSSL_LIBCRYPTO_MD5_MD5_LOCAL_H) */
diff --git a/crypto/md5/md5_riscv.c b/crypto/md5/md5_riscv.c
index 3bd87a13c4..1f00d9e034 100644
--- a/crypto/md5/md5_riscv.c
+++ b/crypto/md5/md5_riscv.c
@@ -9,12 +9,12 @@
 
 #include 
 #include 
-#include "arch/riscv_arch.h"
+#include "crypto/riscv_arch.h"
 
-void ossl_md5_block_asm_data_order(void *c, const void *p, size_t num);
-void ossl_md5_block_asm_data_order_zbb(void *c, const void *p, size_t num);
-void ossl_md5_block_asm_data_order_riscv64(void *c, const void *p, size_t num);
-void ossl_md5_block_asm_data_order(void *c, const void *p, size_t num)
+void ossl_md5_block_asm_data_order(MD5_CTX *c, const void *p, size_t num);
+void ossl_md5_block_asm_data_order_zbb(MD5_CTX *c, const void *p, size_t num);
+void ossl_md5_block_asm_data_order_riscv64(MD5_CTX *c, const void *p, size_t num);
+void ossl_md5_block_asm_data_order(MD5_CTX *c, const void *p, size_t num)
 {
     if (RISCV_HAS_ZBB()) {
         ossl_md5_block_asm_data_order_zbb(c, p, num);
diff --git a/crypto/mdc2/mdc2dgst.c b/crypto/mdc2/mdc2dgst.c
index 0a62569c2b..6fa9bbd356 100644
--- a/crypto/mdc2/mdc2dgst.c
+++ b/crypto/mdc2/mdc2dgst.c
@@ -19,7 +19,18 @@
 #include 
 #include 
 #include 
-#include "internal/common.h"
+
+#undef c2l
+#define c2l(c, l) (l = ((DES_LONG)(*((c)++))), \
+    l |= ((DES_LONG)(*((c)++))) << 8L,         \
+    l |= ((DES_LONG)(*((c)++))) << 16L,        \
+    l |= ((DES_LONG)(*((c)++))) << 24L)
+
+#undef l2c
+#define l2c(l, c) (*((c)++) = (unsigned char)(((l)) & 0xff), \
+    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff),          \
+    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff),         \
+    *((c)++) = (unsigned char)(((l) >> 24L) & 0xff))
 
 static void mdc2_body(MDC2_CTX *c, const unsigned char *in, size_t len);
 int MDC2_Init(MDC2_CTX *c)
diff --git a/crypto/mem.c b/crypto/mem.c
index 476d6b2529..10252e4ae7 100644
--- a/crypto/mem.c
+++ b/crypto/mem.c
@@ -191,7 +191,6 @@ void *CRYPTO_malloc(size_t num, const char *file, int line)
     void *ptr;
 
     INCREMENT(malloc_count);
-    FAILTEST();
     if (malloc_impl != CRYPTO_malloc) {
         ptr = malloc_impl(num, file, line);
         if (ptr != NULL || num == 0)
@@ -202,6 +201,7 @@ void *CRYPTO_malloc(size_t num, const char *file, int line)
     if (ossl_unlikely(num == 0))
         return NULL;
 
+    FAILTEST();
     if (allow_customize) {
         /*
          * Disallow customization after the first allocation. We only set this
@@ -266,7 +266,6 @@ void *CRYPTO_realloc(void *str, size_t num, const char *file, int line)
     void *ret;
 
     INCREMENT(realloc_count);
-    FAILTEST();
     if (realloc_impl != CRYPTO_realloc) {
         ret = realloc_impl(str, num, file, line);
 
@@ -284,6 +283,7 @@ void *CRYPTO_realloc(void *str, size_t num, const char *file, int line)
         return NULL;
     }
 
+    FAILTEST();
     ret = realloc(str, num);
 
 err:
diff --git a/crypto/mem_sec.c b/crypto/mem_sec.c
index a727d2008d..330c726f2c 100644
--- a/crypto/mem_sec.c
+++ b/crypto/mem_sec.c
@@ -23,10 +23,8 @@
 
 #ifndef OPENSSL_NO_SECURE_MEMORY
 #if defined(_WIN32)
+#include 
 #if defined(WINAPI_FAMILY_PARTITION)
-#if !defined(WINAPI_PARTITION_SYSTEM)
-#define WINAPI_PARTITION_SYSTEM 0
-#endif
 #if !WINAPI_FAMILY_PARTITION(WINAPI_PARTITION_DESKTOP | WINAPI_PARTITION_SYSTEM)
 /*
  * While VirtualLock is available under the app partition (e.g. UWP),
diff --git a/include/arch/mips_arch.h b/crypto/mips_arch.h
similarity index 100%
rename from include/arch/mips_arch.h
rename to crypto/mips_arch.h
diff --git a/crypto/ml_dsa/asm/ml_dsa_ntt-x86_64.pl b/crypto/ml_dsa/asm/ml_dsa_ntt-x86_64.pl
deleted file mode 100644
index 9683930760..0000000000
--- a/crypto/ml_dsa/asm/ml_dsa_ntt-x86_64.pl
+++ /dev/null
@@ -1,2036 +0,0 @@
-#! /usr/bin/env perl
-#
-# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved.
-# Copyright (c) 2026 Intel Corporation. All Rights Reserved.
-#
-# Licensed under the Apache License 2.0 (the "License").  You may not use
-# this file except in compliance with the License.  You can obtain a copy
-# in the file LICENSE in the source distribution or at
-# https://www.openssl.org/source/license.html
-
-###############################################################################
-# ML-DSA AVX2 Vectorized NTT/INTT Assembly Routines
-#
-# Description:
-#   This file provides optimized x86_64 assembly implementations of the Number
-#   Theoretic Transform (NTT) and inverse NTT (INTT) and their modular Montgomery
-#   reduction building blocks for the ML-DSA signature scheme.
-#
-#   The routines are vectorized using AVX2 instructions, performing
-#   modular arithmetic and butterfly operations on multiple
-#   coefficients in parallel. The mathematical structure and transformations strictly
-#   follow those implemented in the corresponding C code (ml_dsa_ntt.c),
-#   ensuring that this file provides a drop-in, performant backend using the
-#   same algorithms and data layout.
-#   There is dedicated zeta table used for INTT only. It is essentially
-#   reformatted original table from ml_dsa_ntt.c file to reduce INTT compute cycles.
-#
-#   This module supports both the forward (NTT) and inverse (INTT)
-#   polynomial transforms, as well as element-wise NTT-domain polynomial
-#   multiplication, compatible with the ML-DSA cryptographic protocol.
-#
-#   Step, offset and zeta index details provided for NTT and INTT level operations
-#   correspond directly to the original C implementations from ml_dsa_ntt.c file.
-#
-# Notes:
-#   - Uses AVX2 instructions and YMM registers that accommodate 8 32-bit coefficients
-#   - Must be kept functionally synchronized with the math and
-#     interface of ml_dsa_ntt.c
-#   - Data structures, twiddle factors ("zetas"), and constants must match
-#     those in the C implementation
-###############################################################################
-
-# $output is the last argument if it looks like a file (it has an extension)
-# $flavour is the first argument if it doesn't look like a file
-$output = $#ARGV >= 0 && $ARGV[$#ARGV] =~ m|\.\w+$| ? pop : undef;
-$flavour = $#ARGV >= 0 && $ARGV[0] !~ m|\.| ? shift : undef;
-
-$win64 = 0;
-$win64 = 1 if ($flavour =~ /[nm]asm|mingw64/ || $output =~ /\.asm$/);
-
-$avx2 = 0;
-
-$0 =~ m/(.*[\/\\])[^\/\\]+$/;
-$dir = $1;
-($xlate = "${dir}x86_64-xlate.pl" and -f $xlate)
-  or ($xlate = "${dir}../../perlasm/x86_64-xlate.pl" and -f $xlate)
-  or die "can't locate x86_64-xlate.pl";
-
-# Check for AVX2 support in assembler
-if (`$ENV{CC} -Wa,-v -c -o /dev/null -x assembler /dev/null 2>&1` =~ /GNU assembler version ([2-9]\.[0-9]+)/) {
-  $avx2 = ($1 >= 2.22);
-}
-
-if (!$avx2
-  && $win64
-  && ($flavour =~ /nasm/ || $ENV{ASM} =~ /nasm/)
-  && `nasm -v 2>&1` =~ /NASM version ([2-9]\.[0-9]+)(?:\.([0-9]+))?/)
-{
-  $avx2 = ($1 >= 2.10);
-}
-
-if (!$avx2 && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([0-9]+\.[0-9]+)/) {
-    $avx2 = ($2>=3.3); # minimal tested version for AVX2
-}
-
-open OUT, "| \"$^X\" \"$xlate\" $flavour \"$output\""
-  or die "can't call $xlate: $!";
-*STDOUT = *OUT;
-
-# ML-DSA constants
-my $ML_DSA_Q = 8380417;             # Q: 2^23 - 2^13 + 1
-my $ML_DSA_Q_NEG_INV = 4236238847;  # -Q^{-1} mod 2^32
-
-#  The multiplicative inverse of 256 mod Q, in Montgomery form is
-#  ((256^{-1} mod Q) * ((2^32 * 2^32) mod Q)) mod Q = (8347681 * 2365951) mod 8380417
-my $inverse_degree_montgomery = 41978;
-
-if ($avx2>0) {{{
-
-# avx2 feature bit
-my $avx2_mask = (1<<5);
-
-$code .= <<___;
-.text
-
-.extern OPENSSL_ia32cap_P
-
-.globl  ml_dsa_ntt_avx2_capable
-.type   ml_dsa_ntt_avx2_capable,\@abi-omnipotent
-.align 32
-ml_dsa_ntt_avx2_capable:
-    mov     OPENSSL_ia32cap_P+8(%rip), %rcx
-    xor     %eax, %eax
-    and     \$$avx2_mask, %ecx
-    cmovnz  %ecx, %eax
-    ret
-.size   ml_dsa_ntt_avx2_capable, .-ml_dsa_ntt_avx2_capable
-___
-
-###############################################################################
-# multiply_mod_Q
-#
-# Description:
-#   The inputs (A and B) are in YMM registers, where each packs 8 32-bit integers.
-#   The result, (A * B mod Q), is also in a YMM register.
-#   This routine is used as the core modular multiplication step in
-#   NTT butterfly operations.
-#
-# Parameters:
-#   inA      - Input YMM containing 8 32-bit unsigned values (A)
-#   inB      - Input YMM containing 8 32-bit unsigned values (B)
-#   out      - Output YMM for (A * B mod Q)
-#   tmp0-tmp2 - Temporary registers for intermediate values
-#   q_neg_inv- YMM containing -Q^{-1} mod 2^32 (for Montgomery reduction)
-#   q        - YMM containing modulus Q
-#   bcast32  – if 1, `inB` is assumed to have each qword formed by
-#              repeating its low dword (DW|DW). Multiplication uses only
-#              the low dword, avoiding the need for `vmovshdup` when
-#              zetas are uniform across all lanes of `inA`.
-#
-# Output:
-#   out      - Resulting 8 packed 32-bit integers, each (A * B) mod Q
-#
-# Side effects:
-#   Clobbers tmp0, tmp1, tmp2
-#
-# Notes:
-#   inA or inB can also be used as out
-###############################################################################
-sub multiply_mod_Q {
-    my ($inA, $inB, $out,
-        $tmp0, $tmp1, $tmp2,
-        $q_neg_inv, $q, $bcast32) = @_;
-
-    if (!defined($bcast32)) {
-        $bcast32 = 0;
-    }
-
-    $code .= <<___;
-    # Multiply A x B
-    vpmuludq $inA, $inB, $tmp0  # multiply even indexes
-    vmovshdup $inA, $tmp1
-___
-    if ($bcast32 == 0) {
-        $code .= <<___;
-    vmovshdup $inB, $tmp2
-    vpmuludq $tmp1, $tmp2, $tmp1  # multiply odd indexes
-___
-    } else {
-        $code .= <<___;
-    vpmuludq $tmp1, $inB, $tmp1   # multiply odd indexes of inA
-___
-    }
-        $code .= <<___;
-    # Montgomery reduction: t1 = (A x B)[31..0] x Qinv
-    vpmuludq $q_neg_inv, $tmp0, $out
-    vpmuludq $q_neg_inv, $tmp1, $tmp2
-
-    # t2 = t1[31..0] x Q
-    vpmuludq $out, $q, $out
-    vpmuludq $tmp2, $q, $tmp2
-
-    # t3 = (A x B) + t2
-    vpaddq  $out, $tmp0, $out
-    vpaddq  $tmp2, $tmp1, $tmp1
-
-    # out = t3 >> 32
-    vmovshdup $out, $out
-    vpblendd \$0xAA, $tmp1, $out, $out
-
-    # out can be between Q and 2Q, do final reduction
-    vpcmpgtd $out, $q, $tmp0    # $tmp0 = $q > $out ? 0xffffffff : 0
-    vpandn $q, $tmp0, $tmp0     # $tmp0 = ~$tmp0 & $q
-    vpsubd $tmp0, $out, $out    # $out -= $tmp0
-___
-}
-
-###############################################################################
-###############################################################################
-###
-### NTT (Number Theoretic Transform)
-###
-###############################################################################
-###############################################################################
-
-###############################################################################
-# ntt_butterfly
-#
-# Description:
-#   Performs the butterfly operation for a single NTT stage on two input YMM's,
-#   applying a twiddle factor ("zetas"). This is the core step in NTT layers:
-#     - Computes t_odd = w_odd * zetas mod Q (Montgomery form)
-#     - n_even = w_even + t_odd mod Q
-#     - n_odd  = (w_even + Q) - t_odd mod Q
-#   Uses AVX2 instructions to process 8 coefficients at a time.
-#
-# Parameters:
-#   w_even  - YMM containing the "even" values
-#   w_odd   - YMM containing the "odd" values
-#   zetas   - YMM containing the twiddle factor(s)
-#   n_even  - Output YMM for the updated even coefficients
-#   n_odd   - Output YMM for the updated odd coefficients
-#   tmp0, tmp1, tmp2, tmp3 - Temporary registers for intermediate values
-#   q_neg_inv - YMM with -Q^{-1} mod 2^32
-#   q       - YMM with modulus Q
-#   level   - current NTT processing level
-#
-# Output:
-#   n_even  - Updated even coefficients after butterfly and reduction
-#   n_odd   - Updated odd coefficients after butterfly and reduction
-#
-# Side effects:
-#   Clobbers tmp0, tmp1, tmp2, tmp3
-###############################################################################
-sub ntt_butterfly {
-    my ($w_even, $w_odd,
-        $zetas,
-        $n_even, $n_odd,
-        $tmp0, $tmp1, $tmp2, $tmp3,
-        $q_neg_inv, $q, $level) = @_;
-
-    if ($level >= 7) {
-        # level 7: each zeta (B) dword is different
-        &multiply_mod_Q($w_odd, # A
-                        $zetas, # B
-                        $tmp0,  # out (AxB)
-                        $tmp1, $tmp2, $tmp3, # tmp
-                        $q_neg_inv, $q, 0);  # qinv, q, no-bcast32
-    } else {
-        # levels 0 to 6: same zeta (B) dwords within each qword
-        &multiply_mod_Q($w_odd, # A
-                        $zetas, # B
-                        $tmp0,  # out (AxB)
-                        $tmp1, $tmp2, $tmp3, # tmp
-                        $q_neg_inv, $q, 1);  # qinv, q, bcast32
-    }
-    $code .= <<___;
-
-    # t_odd = $tmp0
-
-    # compute new w_odd (n_odd): (w_even + Q) - t_odd
-    vpaddd  $q, $w_even, $tmp1
-    vpsubd  $tmp0, $tmp1, $n_odd
-
-    # compute new w_even (n_even): w_even + t_odd
-    vpaddd  $w_even, $tmp0, $n_even
-
-    # reduce n_even & n_odd
-    # - results can be between Q and 2Q
-    vpcmpgtd $n_even, $q, $tmp0 # $tmp0 = $q > $n_even ? 0xffffffff : 0
-    vpcmpgtd $n_odd, $q, $tmp1  # $tmp1 = $q > $n_odd ? 0xffffffff : 0
-    vpandn $q, $tmp0, $tmp0     # $tmp0 = ~$tmp0 & $q
-    vpandn $q, $tmp1, $tmp1     # $tmp1 = ~$tmp1 & $q
-    vpsubd $tmp0, $n_even, $n_even  # $n_even -= $tmp0
-    vpsubd $tmp1, $n_odd, $n_odd    # $n_odd -= $tmp1
-___
-}
-
-###############################################################################
-# ntt_levels0to2
-#
-# Description: Performs the first three layers (levels 0, 1, and 2) of the NTT.
-#   It works on 8 YMM registers, 8 32-bit coefficients each. Coefficients loaded into
-#   YMM's are separated by 32 coefficients (32 x 4 bytes = 128 bytes). All 8 YMM registers
-#   undergo consecutive butterfly operations with the appropriate "zetas" (twiddle factors) for
-#   each level. This function must be called 4 times with different offsets to process all 256
-#   coefficients.
-#
-# Layer/level details:
-#   - Level 0:  offset = 128, step = 1, uses zeta index 1
-#   - Level 1:  offset =  64, step = 2, uses zeta indexes 2, 3
-#   - Level 2:  offset =  32, step = 4, uses zeta indexes 4, 5, 6, 7
-#
-# Prerequisites:
-#   %rdi    - pointer to the coefficients
-#   %r11    - pointer to the zetas (twiddle factors) table
-#   %ymm14  - register with q_neg_inv (for Montgomery reduction)
-#   %ymm15  - register with modulus Q
-#
-# Arguments:
-#   $off    - offset to the start of a group of 8 coefficients (in bytes, relative to %rdi)
-#             valid values: 0*4, 8*4, 16*4 or 24*4
-#
-# Output:
-#   In-place NTT updated coefficients in memory.
-#
-# Notes:
-#   - Must be invoked 4 times for complete polynomial: offsets 0, 8*4, 16*4, 24*4
-###############################################################################
-
-sub ntt_levels0to2 {
-    my ($off) = @_;
-    $code .= <<___;
-    vmovdqu $off+0*4(%rdi), %ymm0
-    vmovdqu $off+32*4(%rdi), %ymm1
-    vmovdqu $off+64*4(%rdi), %ymm2
-    vmovdqu $off+96*4(%rdi), %ymm3
-    vmovdqu $off+128*4(%rdi), %ymm4
-    vmovdqu $off+160*4(%rdi), %ymm5
-    vmovdqu $off+192*4(%rdi), %ymm6
-    vmovdqu $off+224*4(%rdi), %ymm7
-
-    # ==============================================================
-    # level 0: offset = 128, step = 1
-    # zeta indexes = 1
-
-    vpbroadcastd 1*4(%r11), %ymm13
-___
-    &ntt_butterfly("%ymm0", "%ymm4", "%ymm13", "%ymm0", "%ymm4",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm8", "%ymm9", "%ymm10", "%ymm11",            # tmp
-                   "%ymm14", "%ymm15", 0);                          # qinv, q, level
-    &ntt_butterfly("%ymm1", "%ymm5", "%ymm13", "%ymm1", "%ymm5",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm8", "%ymm9", "%ymm10", "%ymm11",            # tmp
-                   "%ymm14", "%ymm15", 0);                          # qinv, q, level
-    &ntt_butterfly("%ymm2", "%ymm6", "%ymm13", "%ymm2", "%ymm6",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm8", "%ymm9", "%ymm10", "%ymm11",            # tmp
-                   "%ymm14", "%ymm15", 0);                          # qinv, q, level
-    &ntt_butterfly("%ymm3", "%ymm7", "%ymm13", "%ymm3", "%ymm7",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm8", "%ymm9", "%ymm10", "%ymm11",            # tmp
-                   "%ymm14", "%ymm15", 0);                          # qinv, q, level
-    $code .= <<___;
-
-    # ==============================================================
-    # level 1: offset = 64, step = 2
-    # zeta indexes = 2, 3
-
-    vpbroadcastd 2*4(%r11), %ymm13
-___
-    &ntt_butterfly("%ymm0", "%ymm2", "%ymm13", "%ymm0", "%ymm2",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm8", "%ymm9", "%ymm10", "%ymm11",            # tmp
-                   "%ymm14", "%ymm15", 1);                          # qinv, q, level
-    &ntt_butterfly("%ymm1", "%ymm3", "%ymm13", "%ymm1", "%ymm3",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm8", "%ymm9", "%ymm10", "%ymm11",            # tmp
-                   "%ymm14", "%ymm15", 1);                          # qinv, q, level
-    $code .= <<___;
-    vpbroadcastd 3*4(%r11), %ymm13
-___
-    &ntt_butterfly("%ymm4", "%ymm6", "%ymm13", "%ymm4", "%ymm6",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm8", "%ymm9", "%ymm10", "%ymm11",            # tmp
-                   "%ymm14", "%ymm15", 1);                          # qinv, q, level
-    &ntt_butterfly("%ymm5", "%ymm7", "%ymm13", "%ymm5", "%ymm7",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm8", "%ymm9", "%ymm10", "%ymm11",            # tmp
-                   "%ymm14", "%ymm15", 1);                          # qinv, q, level
-$code .= <<___;
-
-    # ==============================================================
-    # level 2: offset = 32, step = 4
-    # zeta indexes = 4, 5, 6, 7
-
-    vpbroadcastd 4*4(%r11), %ymm13
-___
-    &ntt_butterfly("%ymm0", "%ymm1", "%ymm13", "%ymm0", "%ymm1",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm8", "%ymm9", "%ymm10", "%ymm11",            # tmp
-                   "%ymm14", "%ymm15", 2);                          # qinv, q, level
-    $code .= <<___;
-    vpbroadcastd 5*4(%r11), %ymm13
-___
-    &ntt_butterfly("%ymm2", "%ymm3", "%ymm13", "%ymm2", "%ymm3",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm8", "%ymm9", "%ymm10", "%ymm11",            # tmp
-                   "%ymm14", "%ymm15", 2);                          # qinv, q, level
-    $code .= <<___;
-    vpbroadcastd 6*4(%r11), %ymm13
-___
-    &ntt_butterfly("%ymm4", "%ymm5", "%ymm13", "%ymm4", "%ymm5",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm8", "%ymm9", "%ymm10", "%ymm11",            # tmp
-                   "%ymm14", "%ymm15", 2);                          # qinv, q, level
-    $code .= <<___;
-    vpbroadcastd 7*4(%r11), %ymm13
-___
-    &ntt_butterfly("%ymm6", "%ymm7", "%ymm13", "%ymm6", "%ymm7",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm8", "%ymm9", "%ymm10", "%ymm11",            # tmp
-                   "%ymm14", "%ymm15", 2);                          # qinv, q, level
-$code .= <<___;
-
-    vmovdqu %ymm0, $off+0*4(%rdi)
-    vmovdqu %ymm1, $off+32*4(%rdi)
-    vmovdqu %ymm2, $off+64*4(%rdi)
-    vmovdqu %ymm3, $off+96*4(%rdi)
-    vmovdqu %ymm4, $off+128*4(%rdi)
-    vmovdqu %ymm5, $off+160*4(%rdi)
-    vmovdqu %ymm6, $off+192*4(%rdi)
-    vmovdqu %ymm7, $off+224*4(%rdi)
-___
-}
-
-###############################################################################
-# ntt_levels3to7
-#
-# Description:
-#   Performs layers 3 through 7 of the NTT on 64 coefficients.
-#
-#   It operates on 8 YMM's registers, each YMM packs 8 32-bit coefficients (64
-#   in total).
-#   Contiguous coefficients are loaded into the YMM registers (no gap between them).
-#
-#   The function must be called 4 times to process 256 coefficients.  At each level, the
-#   function executes butterfly operations in the correct coefficient pattern and applies the
-#   corresponding twiddle factors ("zetas").
-#
-# Layer/level details:
-#   - Level 3: offset = 16, step = 8;   zeta indexes 8...15
-#   - Level 4: offset =  8, step = 16;  zeta indexes 16...31
-#   - Level 5: offset =  4, step = 32;  zeta indexes 32...63
-#   - Level 6: offset =  2, step = 64;  zeta indexes 64...127
-#   - Level 7: offset =  1, step = 128; zeta indexes 128...255
-#
-# Prerequisites:
-#   %rdi    - pointer to the coefficients
-#   %r11    - pointer to the zetas (twiddle factors) table
-#   %ymm14  - q_neg_inv (Montgomery reduction)
-#   %ymm15  - Q (modulus)
-#
-# Arguments:
-#   $off, $l3, $l4, $l5, $l6, $l7
-#     $off - offset to the start of a set of 8 coefficients (in bytes, relative to %rdi)
-#     $l3, $l4, $l5, $l6, $l7 - offsets to required zetas in the table, for levels 3 to 7
-#
-# Output:
-#   In-place NTT-transformed coefficients for the selected group.
-#
-# Notes:
-#   - Should be called 4 times per complete 256-coefficient transform (offsets 0, 64*4, 128*4, 192*4).
-#   - All butterfly operations and twiddle applications handled by subroutine ntt_butterfly.
-###############################################################################
-sub ntt_levels3to7 {
-    my ($off,$l3,$l4,$l5,$l6,$l7) = @_;
-
-    $code .= <<___;
-    # ==============================================================
-    # level 3: offset = 16, step = 8
-    # zeta indexes = 8, 9, 10, 11, 12, 13, 14, 15
-
-    # broadcast zetas
-    vpbroadcastd $l3(%r11), %ymm13  # zeta for coefficients 0-15
-
-    # load w_even and w_odd
-    vmovdqu $off(%rdi), %ymm0       # w_even[0:7]
-    vmovdqu $off+32(%rdi), %ymm1    # w_even[8:15]
-    vmovdqu $off+64(%rdi), %ymm2    # w_odd[0:7]
-    vmovdqu $off+96(%rdi), %ymm3    # w_odd[8:15]
-___
-    # Process first 16 coefficients with zeta in ymm13
-    &ntt_butterfly("%ymm0", "%ymm2", "%ymm13", "%ymm0", "%ymm2",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 3);                          # qinv, q, level
-    &ntt_butterfly("%ymm1", "%ymm3", "%ymm13", "%ymm1", "%ymm3",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 3);                          # qinv, q, level
-$code .= <<___;
-    # broadcast zetas
-    vpbroadcastd $l3+4(%r11), %ymm13  # zeta for coefficients 16-31
-
-    # load w_even and w_odd
-    vmovdqu $off+128(%rdi), %ymm4   # w_even[16:23]
-    vmovdqu $off+160(%rdi), %ymm5   # w_even[24:31]
-    vmovdqu $off+192(%rdi), %ymm6  # w_odd[16:23]
-    vmovdqu $off+224(%rdi), %ymm7  # w_odd[24:31]
-___
-    # Process next 16 coefficients with zeta in ymm13
-    &ntt_butterfly("%ymm4", "%ymm6", "%ymm13", "%ymm4", "%ymm6",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 3);                          # qinv, q, level
-    &ntt_butterfly("%ymm5", "%ymm7", "%ymm13", "%ymm5", "%ymm7",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 3);                          # qinv, q, level
-$code .= <<___;
-
-    # ==============================================================
-    # level 4: offset = 8, step = 16
-    # zeta indexes = 16, 17, 18, ..., 30, 31
-
-    # broadcast zetas for first 8 coefficients
-    vpbroadcastd $l4(%r11), %ymm13      # zeta for coefficients 0-7
-
-    # Prepare w_even and w_odd
-    # Input dword layout:
-    #   ymm0 = [ 0  1  2  3 |  4  5  6  7] (even)
-    #   ymm1 = [ 8  9 10 11 | 12 13 14 15] (even)
-    #   ymm2 = [16 17 18 19 | 20 21 22 23] (odd)
-    #   ymm3 = [24 25 26 27 | 28 29 30 31] (odd)
-    # Required dword layout is the same:
-    #   ymm0 = [ 0  1  2  3 |  4  5  6  7] (even)
-    #   ymm1 = [ 8  9 10 11 | 12 13 14 15] (odd)
-    #   ymm2 = [16 17 18 19 | 20 21 22 23] (even)
-    #   ymm3 = [24 25 26 27 | 28 29 30 31] (odd)
-
-___
-    &ntt_butterfly("%ymm0", "%ymm1", "%ymm13", "%ymm0", "%ymm1",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 4);                          # qinv, q, level
-$code .= <<___;
-    # broadcast zetas for next 8 coefficients
-    vpbroadcastd $l4+4(%r11), %ymm13    # zeta for coefficients 8-15
-___
-    &ntt_butterfly("%ymm2", "%ymm3", "%ymm13", "%ymm2", "%ymm3",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 4);                          # qinv, q, level
-    $code .= <<___;
-    # broadcast zetas for next 8 coefficients
-    vpbroadcastd $l4+8(%r11), %ymm13    # zeta for coefficients 16-23
-___
-    &ntt_butterfly("%ymm4", "%ymm5", "%ymm13", "%ymm4", "%ymm5",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 4);                          # qinv, q, level
-$code .= <<___;
-    # broadcast zetas for next 8 coefficients
-    vpbroadcastd $l4+12(%r11), %ymm13   # zeta for coefficients 24-31
-___
-    &ntt_butterfly("%ymm6", "%ymm7", "%ymm13", "%ymm6", "%ymm7",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 4);                          # qinv, q, level
-    $code .= <<___;
-
-    # ==============================================================
-    # level 5: offset = 4, step = 32
-    # zeta indexes = 32, 33, 34, ..., 62, 63
-
-    # prepare w_even and w_odd
-    # Input dword layout:
-    #   ymm0 = [ 0  1  2  3 |  4  5  6  7] (even)
-    #   ymm1 = [ 8  9 10 11 | 12 13 14 15] (odd)
-    # Required dword layout:
-    #   ymm8 = [ 0  1  2  3 |  8  9 10 11] (even)
-    #   ymm1 = [ 4  5  6  7 | 12 13 14 15] (odd)
-    vperm2i128 \$0x20, %ymm1, %ymm0, %ymm8
-    vperm2i128 \$0x31, %ymm1, %ymm0, %ymm1
-
-    # load zetas for first 8 coefficients
-    vpbroadcastd $l5(%r11), %ymm13         # zetas for coefficients 0-3
-    vpbroadcastd $l5+4(%r11), %ymm12       # zetas for coefficients 4-7
-    vpblendd \$0xf0, %ymm12, %ymm13, %ymm13 # blend into ymm13
-
-___
-    &ntt_butterfly("%ymm8", "%ymm1", "%ymm13", "%ymm0", "%ymm1",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 5);                          # qinv, q, level
-$code .= <<___;
-    # prepare w_even and w_odd
-    vperm2i128 \$0x20, %ymm3, %ymm2, %ymm8
-    vperm2i128 \$0x31, %ymm3, %ymm2, %ymm3
-
-    # load zetas for first 8 coefficients
-    vpbroadcastd $l5+8(%r11), %ymm13        # zetas for coefficients 8-11
-    vpbroadcastd $l5+12(%r11), %ymm12       # zetas for coefficients 12-15
-    vpblendd \$0xf0, %ymm12, %ymm13, %ymm13 # blend into ymm13
-
-___
-    &ntt_butterfly("%ymm8", "%ymm3", "%ymm13", "%ymm2", "%ymm3",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 5);                          # qinv, q, level
-    $code .= <<___;
-    # prepare w_even and w_odd
-    vperm2i128 \$0x20, %ymm5, %ymm4, %ymm8
-    vperm2i128 \$0x31, %ymm5, %ymm4, %ymm5
-
-    # load zetas for next 8 coefficients
-    vpbroadcastd $l5+16(%r11), %ymm13       # zetas for coefficients 16-19
-    vpbroadcastd $l5+20(%r11), %ymm12       # zetas for coefficients 20-23
-    vpblendd \$0xf0, %ymm12, %ymm13, %ymm13 # blend into ymm13
-
-___
-    &ntt_butterfly("%ymm8", "%ymm5", "%ymm13", "%ymm4", "%ymm5",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 5);                          # qinv, q, level
-$code .= <<___;
-    # prepare w_even and w_odd
-    vperm2i128 \$0x20, %ymm7, %ymm6, %ymm8
-    vperm2i128 \$0x31, %ymm7, %ymm6, %ymm7
-
-    # load zetas for next 8 coefficients
-    vpbroadcastd $l5+24(%r11), %ymm13       # zetas for coefficients 24-27
-    vpbroadcastd $l5+28(%r11), %ymm12       # zetas for coefficients 28-31
-    vpblendd \$0xf0, %ymm12, %ymm13, %ymm13 # blend into ymm13
-
-___
-    &ntt_butterfly("%ymm8", "%ymm7", "%ymm13", "%ymm6", "%ymm7",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 5);                          # qinv, q, level
-    $code .= <<___;
-
-    # ==============================================================
-    # level 6: offset = 2, step = 64
-    # zeta indexes = 64, 65, 66, ..., 62, 127
-
-    # Input DWORD layout in memory:
-    #   ymm0 = [ 0  1  2  3] [ 8  9 10 11] (even)
-    #   ymm1 = [ 4  5  6  7] [12 13 14 15] (odd)
-    #   ymm2 = [16 17 18 19] [24 25 26 27] (even)
-    #   ymm3 = [20 21 22 23] [28 29 30 31] (odd)
-    # Desired DWORD layout:
-    #   ymm8 = [ 0  1  4  5] [ 8  9 12 13] (even)
-    #   ymm1 = [ 2  3  6  7] [10 11 14 15] (odd)
-
-    # load & prepare zetas
-    # - it is enough that the 1st dword of each qword is populated
-    vmovdqu $l6(%r11), %xmm13
-    vpmovzxdq %xmm13, %ymm13
-
-    # prepare w_even and w_odd
-    vpunpcklqdq %ymm1, %ymm0, %ymm8
-    vpunpckhqdq %ymm1, %ymm0, %ymm1
-___
-    &ntt_butterfly("%ymm8", "%ymm1", "%ymm13", "%ymm0", "%ymm1",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 6);                          # qinv, q, level
-    $code .= <<___;
-    # load & prepare zetas
-    vmovdqu $l6+16(%r11), %xmm13
-    vpmovzxdq %xmm13, %ymm13
-
-    # prepare w_even and w_odd
-    vpunpcklqdq %ymm3, %ymm2, %ymm8
-    vpunpckhqdq %ymm3, %ymm2, %ymm3
-___
-    &ntt_butterfly("%ymm8", "%ymm3", "%ymm13", "%ymm2", "%ymm3",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 6);                          # qinv, q, level
-    $code .= <<___;
-
-    # load & prepare zetas
-    vmovdqu $l6+32(%r11), %xmm13
-    vpmovzxdq %xmm13, %ymm13
-
-    # prepare w_even and w_odd
-    vpunpcklqdq %ymm5, %ymm4, %ymm8
-    vpunpckhqdq %ymm5, %ymm4, %ymm5
-___
-    &ntt_butterfly("%ymm8", "%ymm5", "%ymm13", "%ymm4", "%ymm5",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 6);                          # qinv, q, level
-$code .= <<___;
-    # load & prepare zetas
-    vmovdqu $l6+48(%r11), %xmm13
-    vpmovzxdq %xmm13, %ymm13
-
-    # prepare w_even and w_odd
-    vpunpcklqdq %ymm7, %ymm6, %ymm8
-    vpunpckhqdq %ymm7, %ymm6, %ymm7
-___
-    &ntt_butterfly("%ymm8", "%ymm7", "%ymm13", "%ymm6", "%ymm7",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 6);                          # qinv, q, level
-    $code .= <<___;
-
-    # ==============================================================
-    # level 7: offset = 1, step = 128
-    # zeta indexes = 128, 129, 130, ..., 254, 255
-
-    # Input DWORD layout:
-    #   ymm0 = [ 0  1  4  5] [ 8  9 12 13]
-    #   ymm1 = [ 2  3  6  7] [10 11 14 15]
-    # Required DWORD layout:
-    #   ymm0 = [ 0  2  4  6] [ 8 10 12 14] (even)
-    #   ymm1 = [ 1  3  5  7] [ 9 11 13 15] (odd)
-
-    vpunpckldq   %ymm1, %ymm0, %ymm8      # ymm8 = [0 2 1 3] [ 8 10  9 11]
-    vpunpckhdq   %ymm1, %ymm0, %ymm9      # ymm9 = [4 6 5 7] [12 14 13 15]
-
-    vshufps      \$0xEE, %ymm9, %ymm8, %ymm1   # ymm1 = [1 3 5 7] [ 9 11 13 15]
-    vshufps      \$0x44, %ymm9, %ymm8, %ymm0   # ymm0 = [0 2 4 6] [ 8 10 12 14]
-
-    # load zetas
-    vmovdqu $l7(%r11), %ymm13          # 8 zetas for coefficients 0-7
-___
-    &ntt_butterfly("%ymm0", "%ymm1", "%ymm13", "%ymm0", "%ymm1",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 7);                          # qinv, q, level
-$code .= <<___;
-    # load zetas
-    vmovdqu $l7+32(%r11), %ymm13       # 8 zetas for coefficients 8-15
-
-    # format w_even and w_odd
-    vpunpckldq   %ymm3, %ymm2, %ymm8
-    vpunpckhdq   %ymm3, %ymm2, %ymm9
-
-    vshufps      \$0xEE, %ymm9, %ymm8, %ymm3
-    vshufps      \$0x44, %ymm9, %ymm8, %ymm2
-___
-    &ntt_butterfly("%ymm2", "%ymm3", "%ymm13", "%ymm2", "%ymm3",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 7);                          # qinv, q, level
-    $code .= <<___;
-
-    # load zetas
-    vmovdqu $l7+64(%r11), %ymm13       # 8 zetas for coefficients 16-23
-
-    # format w_even and w_odd
-    vpunpckldq   %ymm5, %ymm4, %ymm8
-    vpunpckhdq   %ymm5, %ymm4, %ymm9
-
-    vshufps      \$0xEE, %ymm9, %ymm8, %ymm5
-    vshufps      \$0x44, %ymm9, %ymm8, %ymm4
-___
-    &ntt_butterfly("%ymm4", "%ymm5", "%ymm13", "%ymm4", "%ymm5",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 7);                          # qinv, q, level
-$code .= <<___;
-    # load zetas
-    vmovdqu $l7+96(%r11), %ymm13       # 8 zetas for coefficients 24-31
-
-    # format w_even and w_odd
-    vpunpckldq   %ymm7, %ymm6, %ymm8
-    vpunpckhdq   %ymm7, %ymm6, %ymm9
-
-    vshufps      \$0xEE, %ymm9, %ymm8, %ymm7
-    vshufps      \$0x44, %ymm9, %ymm8, %ymm6
-___
-    &ntt_butterfly("%ymm6", "%ymm7", "%ymm13", "%ymm6", "%ymm7",    # w_even, w_odd, zetas, n_even, n_odd
-                   "%ymm9", "%ymm10", "%ymm11", "%ymm12",           # tmp
-                   "%ymm14", "%ymm15", 7);                          # qinv, q, level
-    $code .= <<___;
-
-    # Interleave and store first 16
-    vpunpckldq %ymm1, %ymm0, %ymm8
-    vpunpckhdq %ymm1, %ymm0, %ymm9
-
-    vperm2i128 \$0x20, %ymm9, %ymm8, %ymm10
-    vperm2i128 \$0x31, %ymm9, %ymm8, %ymm11
-    vmovdqu %ymm10, $off(%rdi)
-    vmovdqu %ymm11, $off+32(%rdi)
-
-    vpunpckldq  %ymm3, %ymm2, %ymm8
-    vpunpckhdq  %ymm3, %ymm2, %ymm9
-
-    vperm2i128 \$0x20, %ymm9, %ymm8, %ymm10
-    vperm2i128 \$0x31, %ymm9, %ymm8, %ymm11
-    vmovdqu %ymm10, $off+64(%rdi)
-    vmovdqu %ymm11, $off+96(%rdi)
-
-    # Interleave and store second 16
-    vpunpckldq %ymm5, %ymm4, %ymm8
-    vpunpckhdq %ymm5, %ymm4, %ymm9
-
-    vperm2i128 \$0x20, %ymm9, %ymm8, %ymm10
-    vperm2i128 \$0x31, %ymm9, %ymm8, %ymm11
-    vmovdqu %ymm10, $off+128(%rdi)
-    vmovdqu %ymm11, $off+160(%rdi)
-
-    vpunpckldq  %ymm7, %ymm6, %ymm8
-    vpunpckhdq  %ymm7, %ymm6, %ymm9
-
-    vperm2i128 \$0x20, %ymm9, %ymm8, %ymm10
-    vperm2i128 \$0x31, %ymm9, %ymm8, %ymm11
-    vmovdqu %ymm10, $off+192(%rdi)
-    vmovdqu %ymm11, $off+224(%rdi)
-___
-}
-
-###############################################################################
-###############################################################################
-###
-### INTT (Inverse Number Theoretic Transform)
-###
-###############################################################################
-###############################################################################
-
-###############################################################################
-# intt_butterfly
-#
-# Description:
-#   Performs the butterfly operation for a single stage of the INTT
-#   on two 8-element vectors of 32-bit integers (YMM).
-#
-#   Implements the core data-mixing and modular multiplication steps with a
-#   zeta (twiddle factor), including the modular reductions. The updated even and
-#   odd results are put into the designated registers.
-#
-#   This butterfly operation computes:
-#     n_even = (w_even + w_odd) mod Q
-#     n_odd  = ((w_even + Q) - w_odd) * zetas mod Q
-#   where Q is the NTT modulus, and zetas is the power of a primitive root used
-#   for this stage.
-#
-# Parameters:
-#   w_even    - YMM with "even" input coefficients
-#   w_odd     - YMM with "odd" input coefficients
-#   zetas     - YMM with modular twiddle factors for this butterfly
-#   tmp0-tmp2 - Scratch YMM registers for temporary/intermediate values
-#   n_even    - Output YMM for new even coefficients
-#   n_odd     - Output YMM for new odd coefficients
-#   q_neg_inv - YMM with -Q^{-1} mod 2^32 for Montgomery reduction
-#   q         - YMM with modulus Q
-#   level     - current INTT processing level
-#
-# Output:
-#   n_even, n_odd
-#
-# Side effects:
-#   Clobbers tmp0, tmp1, tmp2
-###############################################################################
-
-sub intt_butterfly {
-    my ($w_even, $w_odd, $zetas,
-        $tmp0, $tmp1, $tmp2,
-        $n_even, $n_odd,
-        $q_neg_inv, $q, $level) = @_;
-
-$code .= <<___;
-    # n_even = reduce_once(w_even + w_odd)
-    # n_odd = (w_even + Q) - w_odd
-    vpaddd $q, $w_even, $tmp1           # n_odd: tmp1 = w_even + Q
-    vpaddd $w_even, $w_odd, $n_even     # n_even: n_even = w_even + w_odd
-    vpsubd $w_odd, $tmp1, $n_odd        # n_odd: n_odd = tmp1 - w_odd
-
-    vpcmpgtd $n_even, $q, $tmp0         # n_even: tmp0 = $q > $n_even ? 0xffffffff : 0
-    vpandn $q, $tmp0, $tmp0             # n_even: tmp0 = ~$tmp0 & $q
-    vpsubd $tmp0, $n_even, $n_even      # n_even: n_even -= $tmp0
-
-    # Multiply n_odd by zetas (step root)
-___
-    if ($level < 1) {
-        # level 0: each zeta (B) dword is different
-        &multiply_mod_Q($n_odd,     # A
-                        $zetas,     # B
-                        $n_odd,     # out (AxB)
-                        $tmp0, $tmp1, $tmp2,    # tmp
-                        $q_neg_inv, $q, 0);     # qinv, q, no-bcast32
-    } else {
-        # levels 1 to 7: same zeta (B) dwords within each qword
-        &multiply_mod_Q($n_odd,     # A
-                        $zetas,     # B
-                        $n_odd,     # out (AxB)
-                        $tmp0, $tmp1, $tmp2,    # tmp
-                        $q_neg_inv, $q, 1);     # qinv, q, bcast32
-    }
-}
-
-###############################################################################
-# intt_levels0to4
-#
-# Description:
-#   Executes the first five stages (levels 0–4) of the INTT
-#   on groups of 32 coefficients (4 YMM registers).
-#
-#   This function hierarchically mixes and transforms groups of coefficients using
-#   butterfly operations and level specific zeta (twiddle) factors, performing all required
-#   re-packing and permutations for each layer.
-#
-#   Each call operates on a block of 64 coefficients, and must be repeated 4 times (with
-#   offsets 0, 64*4, 128*4, 192*4) to process all 256 coefficients.
-#
-# Layer/Level details:
-#   - Level 0: offset = 1,   step = 128;  zeta indexes (new) = 0..127
-#   - Level 1: offset = 2,   step = 64;   zeta indexes (new) = 128..191
-#   - Level 2: offset = 4,   step = 32;   zeta indexes (new) = 192..223
-#   - Level 3: offset = 8,   step = 16;   zeta indexes (new) = 224..239
-#   - Level 4: offset = 16,  step = 8;    zeta indexes (new) = 240..247
-#
-# Prerequisites:
-#   %rdi    - pointer to the coefficients array
-#   %r11    - pointer to the zetas (twiddle factors) table
-#   %ymm14  - q_neg_inv (for Montgomery reduction)
-#   %ymm15  - Q (modulus)
-#
-# Arguments:
-#   $off    - offset (in bytes) to the start of the 16-coefficient group
-#   $l0-$l4 - offsets (in bytes) into the zeta table for each INTT level 0..4
-#
-# Output:
-#   Updated coefficients are written in-place in memory.
-#
-# Notes:
-#   - Function must be called 4 times for a full 256-coefficient INTT layer sweep.
-###############################################################################
-
-sub intt_levels0to4 {
-    my ($off,$l0,$l1,$l2,$l3,$l4) = @_;
-    $code .= <<___;
-    # ==============================================================
-    # level 0: offset = 1, step = 128
-    # zeta indexes (original table) = 255, 254, 253, ... 129, 128
-    # zeta indexes (new table) = 0, 1, 2, .. 127
-
-    # dword layout in memory:
-    #   ymm0 = [0,1,2,3 | 4,5,6,7]
-    #   ymm1 = [8,9,10,11 | 12,13,14,15]
-    # required dword layout in registers:
-    #   ymm0 = [0,2,4,6 | 8,10,12,14]
-    #   ymm1 = [1,3,5,7 | 9,11,13,15]
-
-    # load w_even and w_odd
-    vmovdqu $off(%rdi), %ymm8
-    vmovdqu $off+32(%rdi), %ymm9
-
-    # compact even words into ymm0 (w_even[0:7])
-    vmovdqa idx_even(%rip), %ymm13
-    vpermd %ymm8, %ymm13, %ymm10            # [ 0, 2, 4, 6 | 0, 2, 4, 6]
-    vpermd %ymm9, %ymm13, %ymm11            # [ 8,10,12,14 | 8,10,12,14]
-    vpblendd \$0xf0, %ymm11, %ymm10, %ymm0  # [ 0, 2, 4, 6 | 8,10,12,14]
-
-    # compact odd words into ymm1 (w_odd[0..7])
-    vmovdqa idx_odd(%rip), %ymm13
-    vpermd %ymm8, %ymm13, %ymm10            # [ 1, 3, 5, 7 | 1, 3, 5, 7]
-    vpermd %ymm9, %ymm13, %ymm11            # [ 9,11,13,15 | 9,11,13,15]
-    vpblendd \$0xf0, %ymm11, %ymm10, %ymm1  # [ 1, 3, 5, 7 | 9,11,13,15]
-
-    # load 16 zetas
-    vmovdqu $l0(%r11), %ymm13
-
-___
-
-    &intt_butterfly("%ymm0", "%ymm1", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm0", "%ymm1",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 0);         # qinv, q, level
-
-$code .= <<___;
-
-    # load w_even and w_odd
-    vmovdqu $off+64(%rdi), %ymm8
-    vmovdqu $off+96(%rdi), %ymm9
-
-    # compact even words into ymm2 (w_even[8..15])
-    vmovdqa idx_even(%rip), %ymm13
-    vpermd %ymm8, %ymm13, %ymm10
-    vpermd %ymm9, %ymm13, %ymm11
-    vpblendd \$0xf0, %ymm11, %ymm10, %ymm2
-
-    # compact odd words into ymm3 (w_odd[8..15])
-    vmovdqa idx_odd(%rip), %ymm13
-    vpermd %ymm8, %ymm13, %ymm10
-    vpermd %ymm9, %ymm13, %ymm11
-    vpblendd \$0xf0, %ymm11, %ymm10, %ymm3
-
-    # load 16 zetas
-    vmovdqu $l0+32(%r11), %ymm13
-
-___
-
-    &intt_butterfly("%ymm2", "%ymm3", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm2", "%ymm3",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 0);         # qinv, q, level
-
-$code .= <<___;
-    # load w_even and w_odd
-    vmovdqu $off+128(%rdi), %ymm8
-    vmovdqu $off+160(%rdi), %ymm9
-
-    # compact even words into ymm4 (w_even[16..23])
-    vmovdqa idx_even(%rip), %ymm13
-    vpermd %ymm8, %ymm13, %ymm10            # [ 0, 2, 4, 6 | 0, 2, 4, 6]
-    vpermd %ymm9, %ymm13, %ymm11            # [ 8,10,12,14 | 8,10,12,14]
-    vpblendd \$0xf0, %ymm11, %ymm10, %ymm4  # [ 0, 2, 4, 6 | 8,10,12,14]
-
-    # compact odd words into ymm5 (w_odd[16..23])
-    vmovdqa idx_odd(%rip), %ymm13
-    vpermd %ymm8, %ymm13, %ymm10            # [ 1, 3, 5, 7 | 1, 3, 5, 7]
-    vpermd %ymm9, %ymm13, %ymm11            # [ 9,11,13,15 | 9,11,13,15]
-    vpblendd \$0xf0, %ymm11, %ymm10, %ymm5  # [ 1, 3, 5, 7 | 9,11,13,15]
-
-    # load 16 zetas
-    vmovdqu $l0+64(%r11), %ymm13
-
-___
-
-    &intt_butterfly("%ymm4", "%ymm5", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm4", "%ymm5",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 0);         # qinv, q, level
-
-$code .= <<___;
-
-    # load w_even and w_odd
-    vmovdqu $off+192(%rdi), %ymm8
-    vmovdqu $off+224(%rdi), %ymm9
-
-    # compact even words into ymm6 (w_even[24..31])
-    vmovdqa idx_even(%rip), %ymm13
-    vpermd %ymm8, %ymm13, %ymm10
-    vpermd %ymm9, %ymm13, %ymm11
-    vpblendd \$0xf0, %ymm11, %ymm10, %ymm6
-
-    # compact odd words into ymm7 (w_odd[24..31])
-    vmovdqa idx_odd(%rip), %ymm13
-    vpermd %ymm8, %ymm13, %ymm10
-    vpermd %ymm9, %ymm13, %ymm11
-    vpblendd \$0xf0, %ymm11, %ymm10, %ymm7
-
-    # load 16 zetas
-    vmovdqu $l0+96(%r11), %ymm13
-
-___
-
-    &intt_butterfly("%ymm6", "%ymm7", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm6", "%ymm7",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 0);         # qinv, q, level
-
-$code .= <<___;
-
-    # ==============================================================
-    # level 1: offset = 2, step = 64
-    # zeta indexes = 127, 126, 125, ... 65, 64
-    # zeta indexes (new) = 128, 129, .. 191
-
-    # Result DWORD layout:
-    #   ymm0 = [0,  2,  4,  6,  8, 10, 12, 14]
-    #   ymm1 = [1,  3,  5,  7,  9, 11, 13, 15]
-    # Desired layout for this phase:
-    #   %ymm0 = [0,1,4,5,8,9,12,13]
-    #   %ymm1 = [2,3,6,7,10,11,14,15]
-
-    # Interleave even/odd within each 128-bit lane:
-    vpunpckldq %ymm1, %ymm0, %ymm8     # A = [0,1,2,3 | 8,9,10,11]
-    vpunpckhdq %ymm1, %ymm0, %ymm9     # B = [4,5,6,7 | 12,13,14,15]
-
-    # [0,1,4,5 | 8,9,12,13]
-    vshufps \$0x44, %ymm9, %ymm8, %ymm0
-
-    # [2,3,6,7 | 10,11,14,15]
-    vshufps \$0xee, %ymm9, %ymm8, %ymm1
-
-    # load 4 zetas and populate across ymm
-    vmovdqu $l1(%r11), %xmm13
-    vpmovzxdq %xmm13, %ymm13            # [0 - 1 -] [2 - 3 -]
-___
-
-    &intt_butterfly("%ymm0", "%ymm1", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm0", "%ymm1",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 1);         # qinv, q, level
-
-$code .= <<___;
-
-    # Interleave even/odd within each 128-bit lane:
-    vpunpckldq %ymm3, %ymm2, %ymm8     # A = [0,1,2,3 | 8,9,10,11]
-    vpunpckhdq %ymm3, %ymm2, %ymm9     # B = [4,5,6,7 | 12,13,14,15]
-
-    # ymm2 = [0,1,4,5 | 8,9,12,13]
-    vshufps \$0x44, %ymm9, %ymm8, %ymm2
-
-    # ymm3 = [2,3,6,7 | 10,11,14,15]
-    vshufps \$0xee, %ymm9, %ymm8, %ymm3
-
-    # load 4 zetas and populate across YMM
-    vmovdqu $l1+16(%r11), %xmm13
-    vpmovzxdq %xmm13, %ymm13            # [0 - 1 -] [2 - 3 -]
-___
-
-    &intt_butterfly("%ymm2", "%ymm3", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm2", "%ymm3",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 1);         # qinv, q, level
-
-$code .= <<___;
-    # Interleave even/odd within each 128-bit lane:
-    vpunpckldq %ymm5, %ymm4, %ymm8     # A = [0,1,2,3 | 8,9,10,11]
-    vpunpckhdq %ymm5, %ymm4, %ymm9     # B = [4,5,6,7 | 12,13,14,15]
-
-    # [0,1,4,5 | 8,9,12,13]
-    vshufps \$0x44, %ymm9, %ymm8, %ymm4
-
-    # [2,3,6,7 | 10,11,14,15]
-    vshufps \$0xee, %ymm9, %ymm8, %ymm5
-
-    # load 4 zetas and populate across ymm
-    vmovdqu $l1+32(%r11), %xmm13
-    vpmovzxdq %xmm13, %ymm13            # [0 - 1 -] [2 - 3 -]
-___
-
-    &intt_butterfly("%ymm4", "%ymm5", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm4", "%ymm5",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 1);         # qinv, q, level
-
-$code .= <<___;
-
-    # Interleave even/odd within each 128-bit lane:
-    vpunpckldq %ymm7, %ymm6, %ymm8     # A = [0,1,2,3 | 8,9,10,11]
-    vpunpckhdq %ymm7, %ymm6, %ymm9     # B = [4,5,6,7 | 12,13,14,15]
-
-    # ymm6 = [0,1,4,5 | 8,9,12,13]
-    vshufps \$0x44, %ymm9, %ymm8, %ymm6
-
-    # ymm7 = [2,3,6,7 | 10,11,14,15]
-    vshufps \$0xee, %ymm9, %ymm8, %ymm7
-
-    # load 4 zetas and populate across YMM
-    vmovdqu $l1+48(%r11), %xmm13
-    vpmovzxdq %xmm13, %ymm13            # [0 - 1 -] [2 - 3 -]
-___
-
-    &intt_butterfly("%ymm6", "%ymm7", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm6", "%ymm7",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 1);         # qinv, q, level
-
-$code .= <<___;
-
-    # ==============================================================
-    # level 2: offset = 4, step = 32
-    # zeta indexes = 63, 62, 61, ... 33, 32
-    # zeta indexes (new) = 192, 193, 194, ... 223
-
-    # Result DWORD layout:
-    #   ymm0 = [0,1,4,5,8,9,12,13]
-    #   ymm1 = [16,17,20,21,24,25,28,29]
-    # Desired layout:
-    #   ymm8  = [0,1,2,3, 8,9,10,11]
-    #   ymm1 = [4,5,6,7, 12,13,14,15]
-
-    # ymm8 = [0,1,2,3 | 8,9,10,11]
-    vshufps \$0x44, %ymm1, %ymm0, %ymm8
-
-    # ymm1 = [4,5,6,7 | 12,13,14,15]
-    vshufps \$0xee, %ymm1, %ymm0, %ymm1
-
-    # broadcast zetas
-    vpbroadcastd $l2(%r11), %ymm13
-    vpbroadcastd $l2+4(%r11), %ymm12
-    vpblendd \$0xf0, %ymm12, %ymm13, %ymm13
-___
-
-    &intt_butterfly("%ymm8", "%ymm1", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm0", "%ymm1",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 2);         # qinv, q, level
-
-$code .= <<___;
-    vshufps \$0x44, %ymm3, %ymm2, %ymm8
-    vshufps \$0xee, %ymm3, %ymm2, %ymm3
-
-    # broadcast zetas
-    vpbroadcastd $l2+8(%r11), %ymm13
-    vpbroadcastd $l2+12(%r11), %ymm12
-    vpblendd \$0xf0, %ymm12, %ymm13, %ymm13
-___
-
-    &intt_butterfly("%ymm8", "%ymm3", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm2", "%ymm3",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 2);         # qinv, q, level
-
-$code .= <<___;
-    vshufps \$0x44, %ymm5, %ymm4, %ymm8
-    vshufps \$0xee, %ymm5, %ymm4, %ymm5
-
-    # broadcast zetas
-    vpbroadcastd $l2+16(%r11), %ymm13
-    vpbroadcastd $l2+20(%r11), %ymm12
-    vpblendd \$0xf0, %ymm12, %ymm13, %ymm13
-___
-
-    &intt_butterfly("%ymm8", "%ymm5", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm4", "%ymm5",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 2);         # qinv, q, level
-
-$code .= <<___;
-    vshufps \$0x44, %ymm7, %ymm6, %ymm8
-    vshufps \$0xee, %ymm7, %ymm6, %ymm7
-
-    # broadcast zetas
-    vpbroadcastd $l2+24(%r11), %ymm13
-    vpbroadcastd $l2+28(%r11), %ymm12
-    vpblendd \$0xf0, %ymm12, %ymm13, %ymm13
-___
-
-    &intt_butterfly("%ymm8", "%ymm7", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm6", "%ymm7",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 2);         # qinv, q, level
-
-$code .= <<___;
-
-    # ==============================================================
-    # level 3: offset = 8, step = 16
-    # zeta indexes = 31, 30, 29, ... 17, 16
-    # zeta indexes (new) = 224, 225, 226, ... 239
-
-    #   ymm0 = [0,1,2,3 | 8,9,10,11]
-    #   ymm1 = [16,17,18,19 | 24,25,26,27]
-    vperm2i128 \$0x20, %ymm1, %ymm0, %ymm8      # [0,1,2,3 | 4,5,6,7]
-    vperm2i128 \$0x31, %ymm1, %ymm0, %ymm1      # [8,9,10,11 | 12,13,14,15]
-
-    # broadcast zetas
-    vpbroadcastd $l3(%r11), %ymm13
-___
-
-    &intt_butterfly("%ymm8", "%ymm1", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm0", "%ymm1",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 3);         # qinv, q, level
-
-$code .= <<___;
-
-    vperm2i128 \$0x20, %ymm3, %ymm2, %ymm8
-    vperm2i128 \$0x31, %ymm3, %ymm2, %ymm3
-
-    # broadcast zetas
-    vpbroadcastd $l3+4(%r11), %ymm13
-___
-
-    &intt_butterfly("%ymm8", "%ymm3", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm2", "%ymm3",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 3);         # qinv, q, level
-
-$code .= <<___;
-    vperm2i128 \$0x20, %ymm5, %ymm4, %ymm8      # [0,1,2,3 | 4,5,6,7]
-    vperm2i128 \$0x31, %ymm5, %ymm4, %ymm5      # [8,9,10,11 | 12,13,14,15]
-
-    # broadcast zetas
-    vpbroadcastd $l3+8(%r11), %ymm13
-___
-
-    &intt_butterfly("%ymm8", "%ymm5", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm4", "%ymm5",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 3);         # qinv, q, level
-
-$code .= <<___;
-
-    vperm2i128 \$0x20, %ymm7, %ymm6, %ymm8
-    vperm2i128 \$0x31, %ymm7, %ymm6, %ymm7
-
-    # broadcast zetas
-    vpbroadcastd $l3+12(%r11), %ymm13
-___
-
-    &intt_butterfly("%ymm8", "%ymm7", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm6", "%ymm7",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 3);         # qinv, q, level
-
-$code .= <<___;
-
-    # ==============================================================
-    # level 4: offset = 16, step = 8
-    # zeta indexes = 15, 14, 13, ..., 9, 8
-    # zeta indexes (new) = 240, 241, 242, ... 247
-
-    # broadcast zetas
-    vpbroadcastd $l4(%r11), %ymm13
-___
-
-    &intt_butterfly("%ymm0", "%ymm2", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm0", "%ymm2",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 4);         # qinv, q, level
-
-    &intt_butterfly("%ymm1", "%ymm3", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm1", "%ymm3",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 4);         # qinv, q, level
-
-$code .= <<___;
-    # broadcast zetas
-    vpbroadcastd $l4+4(%r11), %ymm13
-___
-
-    &intt_butterfly("%ymm4", "%ymm6", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm4", "%ymm6",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 4);         # qinv, q, level
-
-    &intt_butterfly("%ymm5", "%ymm7", "%ymm13",     # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12",   # temporary
-                    "%ymm5", "%ymm7",               # n_even, n_odd
-                    "%ymm14", "%ymm15", 4);         # qinv, q, level
-
-$code .= <<___;
-
-    # Store new w_even and w_odd
-    vmovdqu %ymm0, $off(%rdi)
-    vmovdqu %ymm1, $off+32(%rdi)
-    vmovdqu %ymm2, $off+64(%rdi)
-    vmovdqu %ymm3, $off+96(%rdi)
-    vmovdqu %ymm4, $off+128(%rdi)
-    vmovdqu %ymm5, $off+160(%rdi)
-    vmovdqu %ymm6, $off+192(%rdi)
-    vmovdqu %ymm7, $off+224(%rdi)
-___
-}
-
-###############################################################################
-# intt_levels5to7
-#
-# Description:
-#   Processes the last three levels (5 to 7) of the INTT on 64 coefficients.
-#
-#   It completes the hierarchical merging of INTT, applying stage-specific zeta
-#   (twiddle) factors and modular butterfly operations for each level, and performs the final
-#   post-processing Montgomery multiplication at the end of the transform.
-#
-#   It must be invoked 4 times with offsets equal to 0*4, 8*4, 16*4 and 24*4 to cover
-#   all 256 coefficients.
-#
-# Layer/Level details:
-#   - Level 5: offset =  32, step = 4;   zeta indexes (new) = 248..251
-#   - Level 6: offset =  64, step = 2;   zeta indexes (new) = 252, 253
-#   - Level 7: offset = 128, step = 1;   zeta index   (new) = 254
-#
-#   After all INTT levels, multiplies the output by the Montgomery factor
-#   corresponding to the inverse transform scaling (usually the modular inverse of the
-#   NTT degree in Montgomery form), to obtain the final reduced coefficients.
-#
-# Prerequisites:
-#   %rdi    - pointer to the coefficients array
-#   %r11    - pointer to the zetas (twiddle factors) table
-#   %ymm14  - q_neg_inv (for Montgomery reduction)
-#   %ymm15  - Q (modulus)
-#
-# Arguments:
-#   $off    - offset (in bytes) to the start of the 8-coefficient group
-#
-# Output:
-#   Overwrites memory at the given offset with the INTT-processed coefficients.
-#
-# Notes:
-#   - This subroutine must be called 4 times with appropriate offsets to process
-#     all 256 coefficients.
-###############################################################################
-
-sub intt_levels5to7 {
-    my ($off) = @_;
-    $code .= <<___;
-    vmovdqu $off+0*4(%rdi), %ymm0
-    vmovdqu $off+32*4(%rdi), %ymm1
-    vmovdqu $off+64*4(%rdi), %ymm2
-    vmovdqu $off+96*4(%rdi), %ymm3
-    vmovdqu $off+128*4(%rdi), %ymm4
-    vmovdqu $off+160*4(%rdi), %ymm5
-    vmovdqu $off+192*4(%rdi), %ymm6
-    vmovdqu $off+224*4(%rdi), %ymm7
-
-    # ==============================================================
-    # level 5: offset = 32, step = 4
-
-    vpbroadcastd 248*4(%r11), %ymm13
-___
-    &intt_butterfly("%ymm0", "%ymm1", "%ymm13", # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12", # temporary
-                    "%ymm0", "%ymm1",           # n_even, n_odd
-                    "%ymm14", "%ymm15", 5);     # qinv, q, level
-    $code .= <<___;
-    vpbroadcastd 249*4(%r11), %ymm13
-___
-    &intt_butterfly("%ymm2", "%ymm3", "%ymm13", # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12", # temporary
-                    "%ymm2", "%ymm3",           # n_even, n_odd
-                    "%ymm14", "%ymm15", 5);     # qinv, q, level
-
-    $code .= <<___;
-    vpbroadcastd 250*4(%r11), %ymm13
-___
-    &intt_butterfly("%ymm4", "%ymm5", "%ymm13", # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12", # temporary
-                    "%ymm4", "%ymm5",           # n_even, n_odd
-                    "%ymm14", "%ymm15", 5);     # qinv, q, level
-
-    $code .= <<___;
-    vpbroadcastd 251*4(%r11), %ymm13
-___
-    &intt_butterfly("%ymm6", "%ymm7", "%ymm13", # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12", # temporary
-                    "%ymm6", "%ymm7",           # n_even, n_odd
-                    "%ymm14", "%ymm15", 5);     # qinv, q, level
-    $code .= <<___;
-
-    # ==============================================================
-    # level 6: offset = 64, step = 2
-
-    vpbroadcastd 252*4(%r11), %ymm13
-___
-    &intt_butterfly("%ymm0", "%ymm2", "%ymm13", # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12", # temporary
-                    "%ymm0", "%ymm2",           # n_even, n_odd
-                    "%ymm14", "%ymm15", 6);     # qinv, q, level
-    &intt_butterfly("%ymm1", "%ymm3", "%ymm13", # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12", # temporary
-                    "%ymm1", "%ymm3",           # n_even, n_odd
-                    "%ymm14", "%ymm15", 6);     # qinv, q, level
-    $code .= <<___;
-    vpbroadcastd 253*4(%r11), %ymm13
-___
-    &intt_butterfly("%ymm4", "%ymm6", "%ymm13", # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12", # temporary
-                    "%ymm4", "%ymm6",           # n_even, n_odd
-                    "%ymm14", "%ymm15", 6);     # qinv, q, level
-    &intt_butterfly("%ymm5", "%ymm7", "%ymm13", # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12", # temporary
-                    "%ymm5", "%ymm7",           # n_even, n_odd
-                    "%ymm14", "%ymm15", 6);     # qinv, q, level
-$code .= <<___;
-
-    # ==============================================================
-    # level 7: offset = 128, step = 1
-
-    vpbroadcastd 254*4(%r11), %ymm13
-___
-    &intt_butterfly("%ymm0", "%ymm4", "%ymm13", # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12", # temporary
-                    "%ymm0", "%ymm4",           # n_even, n_odd
-                    "%ymm14", "%ymm15", 7);     # qinv, q, level
-    &intt_butterfly("%ymm1", "%ymm5", "%ymm13", # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12", # temporary
-                    "%ymm1", "%ymm5",           # n_even, n_odd
-                    "%ymm14", "%ymm15", 7);     # qinv, q, level
-    &intt_butterfly("%ymm2", "%ymm6", "%ymm13", # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12", # temporary
-                    "%ymm2", "%ymm6",           # n_even, n_odd
-                    "%ymm14", "%ymm15", 7);     # qinv, q, level
-    &intt_butterfly("%ymm3", "%ymm7", "%ymm13", # w_even, w_odd, zetas
-                    "%ymm10", "%ymm11", "%ymm12", # temporary
-                    "%ymm3", "%ymm7",           # n_even, n_odd
-                    "%ymm14", "%ymm15", 7);     # qinv, q, level
-$code .= <<___;
-
-    # ==============================================================
-    # extra multiply
-
-    vpbroadcastd ml_dsa_inverse_degree_montgomery(%rip), %ymm13
-___
-
-    &multiply_mod_Q("%ymm0", "%ymm13", "%ymm0",   # A, B, out (AxB)
-                    "%ymm10", "%ymm11", "%ymm12", # tmp
-                    "%ymm14", "%ymm15", 1);       # qinv, q, bcast32
-    &multiply_mod_Q("%ymm4", "%ymm13", "%ymm4",   # A, B, out (AxB)
-                    "%ymm10", "%ymm11", "%ymm12", # tmp
-                    "%ymm14", "%ymm15", 1);       # qinv, q, bcast32
-    &multiply_mod_Q("%ymm1", "%ymm13", "%ymm1",   # A, B, out (AxB)
-                    "%ymm10", "%ymm11", "%ymm12", # tmp
-                    "%ymm14", "%ymm15", 1);       # qinv, q, bcast32
-    &multiply_mod_Q("%ymm5", "%ymm13", "%ymm5",   # A, B, out (AxB)
-                    "%ymm10", "%ymm11", "%ymm12", # tmp
-                    "%ymm14", "%ymm15", 1);       # qinv, q, bcast32
-    &multiply_mod_Q("%ymm2", "%ymm13", "%ymm2",   # A, B, out (AxB)
-                    "%ymm10", "%ymm11", "%ymm12", # tmp
-                    "%ymm14", "%ymm15", 1);       # qinv, q, bcast32
-    &multiply_mod_Q("%ymm6", "%ymm13", "%ymm6",   # A, B, out (AxB)
-                    "%ymm10", "%ymm11", "%ymm12", # tmp
-                    "%ymm14", "%ymm15", 1);       # qinv, q, bcast32
-    &multiply_mod_Q("%ymm3", "%ymm13", "%ymm3",   # A, B, out (AxB)
-                    "%ymm10", "%ymm11", "%ymm12", # tmp
-                    "%ymm14", "%ymm15", 1);       # qinv, q, bcast32
-    &multiply_mod_Q("%ymm7", "%ymm13", "%ymm7",   # A, B, out (AxB)
-                    "%ymm10", "%ymm11", "%ymm12", # tmp
-                    "%ymm14", "%ymm15", 1);       # qinv, q, bcast32
-
-$code .= <<___;
-
-    vmovdqu %ymm0, $off+0*4(%rdi)
-    vmovdqu %ymm1, $off+32*4(%rdi)
-    vmovdqu %ymm2, $off+64*4(%rdi)
-    vmovdqu %ymm3, $off+96*4(%rdi)
-    vmovdqu %ymm4, $off+128*4(%rdi)
-    vmovdqu %ymm5, $off+160*4(%rdi)
-    vmovdqu %ymm6, $off+192*4(%rdi)
-    vmovdqu %ymm7, $off+224*4(%rdi)
-___
-}
-
-$code .= <<___;
-###############################################################################
-###############################################################################
-### Data section
-
-.section .rodata
-
-###############################################################################
-# zetas_inverse:
-#
-# Description:
-#   Table of inverse NTT "zetas" (twiddle factors), precomputed as powers of the
-#   primitive root of unity (mod Q) required for each stage of the inverse Number
-#   Theoretic Transform (INTT). Entries represent the modular inverses of the
-#   forward NTT zetas (ml_dsa_ntt.c), arranged in bit-reversed or stage-order
-#   as required by the INTT implementation.
-#   Elements of the table are in reversed order vs the original table for the
-#   forward NTT. This is reduce permute operations when preparing zetas in the
-#   correct format for butterfly operations.
-#
-#   Each .long entry corresponds to a 32-bit modular value (Q - zeta) for the
-#   appropriate stage and index.
-#
-#   The exact arrangement and computation of these zetas matches the INTT
-#   schedule and must be consistent with the NTT forward transform (ml_dsa_ntt.c).
-###############################################################################
-.align 64
-zetas_inverse:
-    .long $ML_DSA_Q - 1976782, $ML_DSA_Q - 7534263, $ML_DSA_Q - 1400424, $ML_DSA_Q - 3937738, $ML_DSA_Q - 7018208, $ML_DSA_Q - 8332111, $ML_DSA_Q - 3919660, $ML_DSA_Q - 7826001
-    .long $ML_DSA_Q - 4834730, $ML_DSA_Q - 1612842, $ML_DSA_Q - 7403526, $ML_DSA_Q - 183443,  $ML_DSA_Q - 6094090, $ML_DSA_Q - 7959518, $ML_DSA_Q - 6144432, $ML_DSA_Q - 5441381
-    .long $ML_DSA_Q - 4546524, $ML_DSA_Q - 8119771, $ML_DSA_Q - 7276084, $ML_DSA_Q - 6712985, $ML_DSA_Q - 1910376, $ML_DSA_Q - 6577327, $ML_DSA_Q - 1723600, $ML_DSA_Q - 7953734
-    .long $ML_DSA_Q - 472078,  $ML_DSA_Q - 1717735, $ML_DSA_Q - 7404533, $ML_DSA_Q - 2213111, $ML_DSA_Q - 269760,  $ML_DSA_Q - 3866901, $ML_DSA_Q - 3523897, $ML_DSA_Q - 5341501
-    .long $ML_DSA_Q - 6581310, $ML_DSA_Q - 4686184, $ML_DSA_Q - 1652634, $ML_DSA_Q - 810149,  $ML_DSA_Q - 3014001, $ML_DSA_Q - 1616392, $ML_DSA_Q - 162844,  $ML_DSA_Q - 5196991
-    .long $ML_DSA_Q - 7173032, $ML_DSA_Q - 185531,  $ML_DSA_Q - 3369112, $ML_DSA_Q - 1957272, $ML_DSA_Q - 8215696, $ML_DSA_Q - 2454455, $ML_DSA_Q - 2432395, $ML_DSA_Q - 6366809
-    .long $ML_DSA_Q - 4603424, $ML_DSA_Q - 594136,  $ML_DSA_Q - 4656147, $ML_DSA_Q - 5796124, $ML_DSA_Q - 6533464, $ML_DSA_Q - 6709241, $ML_DSA_Q - 5548557, $ML_DSA_Q - 7838005
-    .long $ML_DSA_Q - 3406031, $ML_DSA_Q - 2235880, $ML_DSA_Q - 777191,  $ML_DSA_Q - 1500165, $ML_DSA_Q - 7005614, $ML_DSA_Q - 5834105, $ML_DSA_Q - 1917081, $ML_DSA_Q - 7100756
-    .long $ML_DSA_Q - 6417775, $ML_DSA_Q - 3306115, $ML_DSA_Q - 1312455, $ML_DSA_Q - 7929317, $ML_DSA_Q - 6950192, $ML_DSA_Q - 5062207, $ML_DSA_Q - 1237275, $ML_DSA_Q - 7047359
-    .long $ML_DSA_Q - 7329447, $ML_DSA_Q - 1903435, $ML_DSA_Q - 1869119, $ML_DSA_Q - 5386378, $ML_DSA_Q - 4832145, $ML_DSA_Q - 2635921, $ML_DSA_Q - 1250494, $ML_DSA_Q - 4613401
-    .long $ML_DSA_Q - 1595974, $ML_DSA_Q - 2486353, $ML_DSA_Q - 1247620, $ML_DSA_Q - 4055324, $ML_DSA_Q - 1265009, $ML_DSA_Q - 5790267, $ML_DSA_Q - 2691481, $ML_DSA_Q - 2842341
-    .long $ML_DSA_Q - 203044,  $ML_DSA_Q - 1735879, $ML_DSA_Q - 5038140, $ML_DSA_Q - 3437287, $ML_DSA_Q - 4108315, $ML_DSA_Q - 5942594, $ML_DSA_Q - 286988,  $ML_DSA_Q - 342297
-    .long $ML_DSA_Q - 4784579, $ML_DSA_Q - 7611795, $ML_DSA_Q - 7855319, $ML_DSA_Q - 4823422, $ML_DSA_Q - 3207046, $ML_DSA_Q - 2031748, $ML_DSA_Q - 5257975, $ML_DSA_Q - 7725090
-    .long $ML_DSA_Q - 7857917, $ML_DSA_Q - 8337157, $ML_DSA_Q - 6767243, $ML_DSA_Q - 495491,  $ML_DSA_Q - 819034,  $ML_DSA_Q - 909542,  $ML_DSA_Q - 1859098, $ML_DSA_Q - 900702
-    .long $ML_DSA_Q - 5187039, $ML_DSA_Q - 7183191, $ML_DSA_Q - 4621053, $ML_DSA_Q - 4860065, $ML_DSA_Q - 3513181, $ML_DSA_Q - 7144689, $ML_DSA_Q - 2434439, $ML_DSA_Q - 266997
-    .long $ML_DSA_Q - 4817955, $ML_DSA_Q - 5933984, $ML_DSA_Q - 2244091, $ML_DSA_Q - 5037939, $ML_DSA_Q - 3817976, $ML_DSA_Q - 2316500, $ML_DSA_Q - 3407706, $ML_DSA_Q - 2091667
-    .long $ML_DSA_Q - 3839961, $ML_DSA_Q - 4751448, $ML_DSA_Q - 4499357, $ML_DSA_Q - 5361315, $ML_DSA_Q - 6940675, $ML_DSA_Q - 7567685, $ML_DSA_Q - 6795489, $ML_DSA_Q - 1285669
-    .long $ML_DSA_Q - 1341330, $ML_DSA_Q - 1315589, $ML_DSA_Q - 8202977, $ML_DSA_Q - 5971092, $ML_DSA_Q - 6529015, $ML_DSA_Q - 3159746, $ML_DSA_Q - 4827145, $ML_DSA_Q - 189548
-    .long $ML_DSA_Q - 7063561, $ML_DSA_Q - 759969,  $ML_DSA_Q - 8169440, $ML_DSA_Q - 2389356, $ML_DSA_Q - 5130689, $ML_DSA_Q - 1653064, $ML_DSA_Q - 8371839, $ML_DSA_Q - 4656075
-    .long $ML_DSA_Q - 3958618, $ML_DSA_Q - 904516,  $ML_DSA_Q - 7280319, $ML_DSA_Q - 44288,   $ML_DSA_Q - 3097992, $ML_DSA_Q - 508951,  $ML_DSA_Q - 264944,  $ML_DSA_Q - 5037034
-    .long $ML_DSA_Q - 6949987, $ML_DSA_Q - 1852771, $ML_DSA_Q - 1349076, $ML_DSA_Q - 7998430, $ML_DSA_Q - 7072248, $ML_DSA_Q - 8357436, $ML_DSA_Q - 7151892, $ML_DSA_Q - 7709315
-    .long $ML_DSA_Q - 5903370, $ML_DSA_Q - 7969390, $ML_DSA_Q - 4686924, $ML_DSA_Q - 5412772, $ML_DSA_Q - 2715295, $ML_DSA_Q - 2147896, $ML_DSA_Q - 7396998, $ML_DSA_Q - 3412210
-    .long $ML_DSA_Q - 126922,  $ML_DSA_Q - 4747489, $ML_DSA_Q - 5223087, $ML_DSA_Q - 5190273, $ML_DSA_Q - 7380215, $ML_DSA_Q - 4296819, $ML_DSA_Q - 1939314, $ML_DSA_Q - 7122806
-    .long $ML_DSA_Q - 6795196, $ML_DSA_Q - 2176455, $ML_DSA_Q - 3475950, $ML_DSA_Q - 6927966, $ML_DSA_Q - 5339162, $ML_DSA_Q - 4702672, $ML_DSA_Q - 6851714, $ML_DSA_Q - 4450022
-    .long $ML_DSA_Q - 5582638, $ML_DSA_Q - 2071892, $ML_DSA_Q - 5823537, $ML_DSA_Q - 3900724, $ML_DSA_Q - 3881043, $ML_DSA_Q - 954230,  $ML_DSA_Q - 531354,  $ML_DSA_Q - 811944
-    .long $ML_DSA_Q - 3699596, $ML_DSA_Q - 6779997, $ML_DSA_Q - 6239768, $ML_DSA_Q - 3507263, $ML_DSA_Q - 4558682, $ML_DSA_Q - 3505694, $ML_DSA_Q - 6736599, $ML_DSA_Q - 6681150
-    .long $ML_DSA_Q - 7841118, $ML_DSA_Q - 2348700, $ML_DSA_Q - 8079950, $ML_DSA_Q - 3539968, $ML_DSA_Q - 5512770, $ML_DSA_Q - 3574422, $ML_DSA_Q - 5336701, $ML_DSA_Q - 4519302
-    .long $ML_DSA_Q - 3915439, $ML_DSA_Q - 5842901, $ML_DSA_Q - 4788269, $ML_DSA_Q - 6718724, $ML_DSA_Q - 3530437, $ML_DSA_Q - 3077325, $ML_DSA_Q - 95776,   $ML_DSA_Q - 2706023
-    .long $ML_DSA_Q - 280005,  $ML_DSA_Q - 4010497, $ML_DSA_Q - 8360995, $ML_DSA_Q - 1757237, $ML_DSA_Q - 5102745, $ML_DSA_Q - 6980856, $ML_DSA_Q - 4520680, $ML_DSA_Q - 6262231
-    .long $ML_DSA_Q - 6271868, $ML_DSA_Q - 2619752, $ML_DSA_Q - 7260833, $ML_DSA_Q - 7830929, $ML_DSA_Q - 3585928, $ML_DSA_Q - 7300517, $ML_DSA_Q - 1024112, $ML_DSA_Q - 2725464
-    .long $ML_DSA_Q - 2680103, $ML_DSA_Q - 3111497, $ML_DSA_Q - 5495562, $ML_DSA_Q - 3119733, $ML_DSA_Q - 6288512, $ML_DSA_Q - 8021166, $ML_DSA_Q - 2353451, $ML_DSA_Q - 1826347
-    .long $ML_DSA_Q - 466468,  $ML_DSA_Q - 7504169, $ML_DSA_Q - 7602457, $ML_DSA_Q - 237124,  $ML_DSA_Q - 7861508, $ML_DSA_Q - 5771523, $ML_DSA_Q - 25847,   $ML_DSA_Q - 4193792
-
-.align 32
-idx_even:
-    .long 0,2,4,6, 0,2,4,6
-
-.align 32
-idx_odd:
-    .long 1,3,5,7, 1,3,5,7
-
-# Modulus Q for ML-DSA NTT (2^23 - 2^13 + 1)
-.align 8
-ml_dsa_q:
-    .quad $ML_DSA_Q
-
-# -Q^{-1} mod 2^32 (Montgomery parameter for ML-DSA modular reduction)
-.align 8
-ml_dsa_q_neg_inv:
-    .quad $ML_DSA_Q_NEG_INV
-
-# (N^{-1} mod Q) in Montgomery form for scaling after inverse NTT
-.align 8
-ml_dsa_inverse_degree_montgomery:
-    .quad $inverse_degree_montgomery
-
-###############################################################################
-###############################################################################
-### Code section
-
-.text
-
-###############################################################################
-# ml_dsa_poly_ntt_mult_avx2
-#
-# C Prototype:
-#   void ml_dsa_poly_ntt_mult_avx2(
-#       const uint32_t *a,       // (rdi) Input polynomial A (in NTT domain)
-#       const uint32_t *b,       // (rsi) Input polynomial B (in NTT domain)
-#       uint32_t *out,           // (rdx) Output polynomial (result)
-#   );
-#
-# Description:
-#   Top-level routine for polynomial multiplication in ML-DSA,
-#   using number-theoretic transform (NTT) methods. This function performs
-#   multiplication of two polynomials in the NTT domain, making full use of
-#   AVX2 vector instructions.
-#   It assumes there are 256 coefficients.
-#
-#   out[i] = a[i] x b[i] mod Q
-#
-#   The function:
-#     - Takes pointers to source polynomials (NTT domain) and destination buffer
-#     - Performs element-wise modular (pointwise) multiplication in the NTT domain
-#     - Applies Montgomery reduction for efficient modular arithmetic
-#
-# Inputs:
-#   a   - First input polynomial, NTT domain
-#   b   - Second input polynomial, NTT domain
-#   out - Destination buffer for output coefficients
-#
-# Output:
-#   - Output buffer 'out' contains the coefficient-wise modular product of
-#     the input polynomials (still in NTT domain)
-#
-###############################################################################
-
-.globl  ml_dsa_poly_ntt_mult_avx2
-.type   ml_dsa_poly_ntt_mult_avx2,\@function,3
-.align 32
-ml_dsa_poly_ntt_mult_avx2:
-.cfi_startproc
-___
-$code .= <<___ if ($win64);
-    lea     -168(%rax), %rsp
-    vmovaps %xmm6,   0(%rsp)
-    vmovaps %xmm7,   16(%rsp)
-    vmovaps %xmm8,   32(%rsp)
-    vmovaps %xmm9,   48(%rsp)
-    vmovaps %xmm10,  64(%rsp)
-    vmovaps %xmm11,  80(%rsp)
-    vmovaps %xmm12,  96(%rsp)
-    vmovaps %xmm13,  112(%rsp)
-    vmovaps %xmm14,  128(%rsp)
-    vmovaps %xmm15,  144(%rsp)
-___
-$code .= <<___;
-.Lntt_mult_body:
-    vpbroadcastq ml_dsa_q_neg_inv(%rip), %ymm14
-    vpbroadcastd ml_dsa_q(%rip), %ymm15
-    xor %r10d, %r10d
-
-.align 32
-.Lmult_loop:
-    # Load a and b into ymm registers
-    vmovdqu (%rdi,%r10), %ymm0   # a[0:7]
-    vmovdqu (%rsi,%r10), %ymm1   # b[0:7]
-
-    # multiply this part of input data
-___
-
-    &multiply_mod_Q("%ymm0", "%ymm1", "%ymm0",  # A, B, out (AxB)
-                    "%ymm8", "%ymm9", "%ymm10", # tmp
-                    "%ymm14", "%ymm15", 0);     # qinv, q, bcast32
-
-$code .= <<___;
-    # store result to output
-    vmovdqu %ymm0, (%rdx,%r10)
-
-    # start new iteration
-    add \$8*4, %r10d
-    cmp \$256*4, %r10d
-    jb .Lmult_loop
-
-    # clear and restore registers
-    vzeroall
-___
-$code .= <<___ if ($win64);
-    vmovaps 0(%rsp),   %xmm6
-    vmovaps 16(%rsp),  %xmm7
-    vmovaps 32(%rsp),  %xmm8
-    vmovaps 48(%rsp),  %xmm9
-    vmovaps 64(%rsp),  %xmm10
-    vmovaps 80(%rsp),  %xmm11
-    vmovaps 96(%rsp),  %xmm12
-    vmovaps 112(%rsp), %xmm13
-    vmovaps 128(%rsp), %xmm14
-    vmovaps 144(%rsp), %xmm15
-    lea     (%rax), %rsp
-___
-$code .= <<___;
-.Lntt_mult_epilogue:
-    ret
-.cfi_endproc
-.size   ml_dsa_poly_ntt_mult_avx2, .-ml_dsa_poly_ntt_mult_avx2
-
-###############################################################################
-# ml_dsa_poly_ntt_avx2
-#
-# C Prototype:
-#   void ml_dsa_poly_ntt_avx2(
-#       uint32_t *p_coeffs,     // Pointer to coefficients (input: normal domain, output: NTT domain)
-#       const uint32_t *p_zetas // Pointer to zeta (twiddle factor) table for the forward NTT
-#   );
-#
-# Description:
-#   Top-level implementation of the forward Number Theoretic
-#   Transform (NTT) for ML-DSA polynomials. This function converts a polynomial
-#   from its standard coefficient (normal) form to its NTT representation,
-#   storing the result in-place in the provided coefficients array. The function
-#   uses stage-specific "zeta" (twiddle factor) tables passed from C (ml_dsa_ntt.c).
-#
-#   The function:
-#     - Takes a buffer of polynomial coefficients in normal (standard) order
-#     - Uses the provided zeta table for all twiddle-factor multiplications
-#     - Processes the NTT in a breadth-first, layered fashion with AVX2 SIMD
-#     - Overwrites the input buffer with its NTT-domain representation
-#
-# Inputs:
-#   p_coeffs - Pointer to the coefficient array (will be overwritten in-place by the NTT result)
-#   p_zetas  - Pointer to the precomputed table of forward NTT zeta (twiddle) factors (from ml_dsa_ntt.c)
-#
-# Output:
-#   - The 'p_coeffs' array is updated in-place with the corresponding NTT-domain representation.
-###############################################################################
-.globl  ml_dsa_poly_ntt_avx2
-.type   ml_dsa_poly_ntt_avx2,\@function,2
-.align 32
-ml_dsa_poly_ntt_avx2:
-.cfi_startproc
-___
-$code .= <<___ if ($win64);
-    lea     -168(%rax), %rsp
-    vmovaps %xmm6,   0(%rsp)
-    vmovaps %xmm7,   16(%rsp)
-    vmovaps %xmm8,   32(%rsp)
-    vmovaps %xmm9,   48(%rsp)
-    vmovaps %xmm10,  64(%rsp)
-    vmovaps %xmm11,  80(%rsp)
-    vmovaps %xmm12,  96(%rsp)
-    vmovaps %xmm13,  112(%rsp)
-    vmovaps %xmm14,  128(%rsp)
-    vmovaps %xmm15,  144(%rsp)
-___
-$code .= <<___;
-.Lntt_body:
-
-    # move p_zetas to r11
-    mov %rsi, %r11
-
-    # load constants
-    vpbroadcastq ml_dsa_q_neg_inv(%rip), %ymm14
-    vpbroadcastd ml_dsa_q(%rip), %ymm15     # 32-bit Q
-
-    # ==============================================================
-    # - level 0: offset = 128, step = 1, zeta indexes = 1
-    # - level 1: offset = 64, step = 2, zeta indexes = 2, 3
-    # - level 2: offset = 32, step = 4, zeta indexes = 4, 5, 6, 7
-    # p_coeffs already in rdi
-___
-
-    &ntt_levels0to2(0*4);
-    &ntt_levels0to2(8*4);
-    &ntt_levels0to2(16*4);
-    &ntt_levels0to2(24*4);
-
-$code .= <<___;
-
-    # ==============================================================
-    # - level 3: offset = 16, step = 8
-    #     zeta indexes = 8, 9, 10, 11, 12, 13, 14, 15
-    # - level 4: offset = 8, step = 16
-    #     zeta indexes = 16, 17, 18, ..., 30, 31
-    # - level 5: offset = 4, step = 32
-    #     zeta indexes = 32, 33, 34, ..., 62, 63
-    # - level 6: offset = 2, step = 64
-    #     zeta indexes = 64, 65, 66, ..., 126, 127
-    # - level 7: offset = 1, step = 128
-    #     zeta indexes = 128, 129, 130, ..., 254, 255
-    # p_coeffs already in rdi
-___
-
-    # arguments:    coeff,   l3,    l4,    l5,    l6,    l7
-    &ntt_levels3to7(  0*4,  8*4,  16*4,  32*4,  64*4, 128*4);
-    &ntt_levels3to7( 64*4, 10*4,  20*4,  40*4,  80*4, 160*4);
-    &ntt_levels3to7(128*4, 12*4,  24*4,  48*4,  96*4, 192*4);
-    &ntt_levels3to7(192*4, 14*4,  28*4,  56*4, 112*4, 224*4);
-
-$code .= <<___;
-
-    # clear and restore registers
-    vzeroall
-___
-$code .= <<___ if ($win64);
-    vmovaps 0(%rsp),   %xmm6
-    vmovaps 16(%rsp),  %xmm7
-    vmovaps 32(%rsp),  %xmm8
-    vmovaps 48(%rsp),  %xmm9
-    vmovaps 64(%rsp),  %xmm10
-    vmovaps 80(%rsp),  %xmm11
-    vmovaps 96(%rsp),  %xmm12
-    vmovaps 112(%rsp), %xmm13
-    vmovaps 128(%rsp), %xmm14
-    vmovaps 144(%rsp), %xmm15
-    lea     (%rax), %rsp
-___
-$code .= <<___;
-.Lntt_epilogue:
-    ret
-.cfi_endproc
-.size   ml_dsa_poly_ntt_avx2, .-ml_dsa_poly_ntt_avx2
-
-###############################################################################
-# ml_dsa_poly_ntt_inverse_avx2
-#
-# C Prototype:
-#     void ml_dsa_poly_ntt_inverse_avx2(
-#        uint32_t *p_coeffs // (rdi) Pointer to coefficients
-#                           // input: NTT domain, output: normal domain, in-place
-#     );
-#
-# Description:
-#   Top-level implementation of the inverse Number Theoretic
-#   Transform (INTT) for ML-DSA polynomial. This function converts a polynomial
-#   from its NTT domain back to the standard coefficient (normal) domain,
-#   storing the result in-place in the provided buffer. The required inverse zeta
-#   (twiddle) factors are managed internally.
-#
-#   The function:
-#     - Accepts a buffer of NTT-domain coefficients
-#     - Overwrites the input buffer with the result in the normal (coefficient) domain
-#
-# Inputs:
-#   p_coeffs - Pointer to the polynomial coefficient array (in-place transform)
-#
-# Output:
-#   - The 'p_coeffs' array is updated in-place to contain the standard domain polynomial.
-#   - Uses 'zetas_inverse' table
-###############################################################################
-.globl  ml_dsa_poly_ntt_inverse_avx2
-.type   ml_dsa_poly_ntt_inverse_avx2,\@function,1
-.align 32
-ml_dsa_poly_ntt_inverse_avx2:
-.cfi_startproc
-___
-$code .= <<___ if ($win64);
-    lea     -168(%rax), %rsp
-    vmovaps %xmm6,   0(%rsp)
-    vmovaps %xmm7,   16(%rsp)
-    vmovaps %xmm8,   32(%rsp)
-    vmovaps %xmm9,   48(%rsp)
-    vmovaps %xmm10,  64(%rsp)
-    vmovaps %xmm11,  80(%rsp)
-    vmovaps %xmm12,  96(%rsp)
-    vmovaps %xmm13,  112(%rsp)
-    vmovaps %xmm14,  128(%rsp)
-    vmovaps %xmm15,  144(%rsp)
-___
-$code .= <<___;
-.Lintt_body:
-    lea zetas_inverse(%rip), %r11
-
-    vpbroadcastq ml_dsa_q_neg_inv(%rip), %ymm14
-    vpbroadcastd ml_dsa_q(%rip), %ymm15
-
-    # ==============================================================
-    # - level 0: offset = 1, step = 128
-    #     zeta indexes (original table) = 255, 254, 253, ... 129, 128
-    #     zeta indexes (new table) = 0, 1, 2, .. 127
-    # - level 1: offset = 2, step = 64
-    #     zeta indexes (original table) = 127, 126, 125, ... 65, 64
-    #     zeta indexes (new table) = 128, 129, .. 191
-    # - level 2: offset = 4, step = 32
-    #     zeta indexes (original table) = 63, 62, 61, ... 33, 32
-    #     zeta indexes (new table) = 192, 193, 194, ... 223
-    # - level 3: offset = 8, step = 16
-    #     zeta indexes (original table) = 31, 30, 29, ... 17, 16
-    #     zeta indexes (new table) = 224, 225, 226, ... 239
-    # - level 4: offset = 16, step = 8
-    #     zeta indexes (original table) = 15, 14, 13, ..., 9, 8
-    #     zeta indexes (new table) = 240, 241, 242, ... 247
-
-___
-
-    #  arguments:    coeff,   l0,    l1,    l2,    l3,    l4
-    &intt_levels0to4(0*4,    0*4, 128*4, 192*4, 224*4, 240*4);
-    &intt_levels0to4(64*4,  32*4, 144*4, 200*4, 228*4, 242*4);
-    &intt_levels0to4(128*4, 64*4, 160*4, 208*4, 232*4, 244*4);
-    &intt_levels0to4(192*4, 96*4, 176*4, 216*4, 236*4, 246*4);
-
-$code .= <<___;
-
-    # ==============================================================
-    # - level 5: offset = 32, step = 4
-    #   zeta indexes (original table) = 7, 6, 5, 4
-    #   zeta indexes (new table) = 248, 249, 250, 251
-    # - level 6: offset = 64, step = 2
-    #   zeta indexes (original table) = 3, 2
-    #   zeta indexes (new table) = 252, 253
-    # - level 7: offset = 128, step = 1
-    #   zeta indexes (original table) = 1
-    #   zeta indexes (new table) = 254
-___
-    &intt_levels5to7(0*4);
-    &intt_levels5to7(8*4);
-    &intt_levels5to7(16*4);
-    &intt_levels5to7(24*4);
-    $code .= <<___;
-
-    # clear and restore registers
-    vzeroall
-___
-$code .= <<___ if ($win64);
-    vmovaps 0(%rsp),   %xmm6
-    vmovaps 16(%rsp),  %xmm7
-    vmovaps 32(%rsp),  %xmm8
-    vmovaps 48(%rsp),  %xmm9
-    vmovaps 64(%rsp),  %xmm10
-    vmovaps 80(%rsp),  %xmm11
-    vmovaps 96(%rsp),  %xmm12
-    vmovaps 112(%rsp), %xmm13
-    vmovaps 128(%rsp), %xmm14
-    vmovaps 144(%rsp), %xmm15
-    lea     (%rax), %rsp
-___
-$code .= <<___;
-.Lintt_epilogue:
-    ret
-.cfi_endproc
-.size   ml_dsa_poly_ntt_inverse_avx2, .-ml_dsa_poly_ntt_inverse_avx2
-___
-
-# Windows SEH exception handler and unwind data
-if ($win64) {
-my $context = "%r8";
-my $disp    = "%r9";
-
-$code .= <<___;
-.extern __imp_RtlVirtualUnwind
-.type   ntt_se_handler,\@abi-omnipotent
-.align  16
-ntt_se_handler:
-    push    %rsi
-    push    %rdi
-    push    %rbx
-    push    %rbp
-    push    %r12
-    push    %r13
-    push    %r14
-    push    %r15
-    pushfq
-    sub     \$64, %rsp
-
-    mov     120($context), %rax     # context->Rax = original %rsp (saved by xlate preamble)
-    mov     248($context), %rbx     # context->Rip
-
-    mov     8($disp), %rsi          # disp->ImageBase
-    mov     56($disp), %r11         # disp->HandlerData
-
-    mov     0(%r11), %r10d          # HandlerData[0]: body label (rva)
-    lea     (%rsi,%r10), %r10
-    cmp     %r10, %rbx              # Rip < body?
-    jb      .Lntt_in_prologue
-
-    mov     4(%r11), %r10d          # HandlerData[1]: epilogue label (rva)
-    lea     (%rsi,%r10), %r10
-    cmp     %r10, %rbx              # Rip >= epilogue?
-    jae     .Lntt_in_prologue
-
-    # In function body: XMM6-XMM15 are saved at 0..144(new_rsp).
-    # context->Rsp = new_rsp = rax - 168
-    mov     152($context), %rsi     # context->Rsp = new_rsp (address of XMM saves)
-    lea     512($context), %rdi     # &context->Xmm6
-    mov     \$20, %ecx              # 10 XMMs * 2 qwords = 20 qwords
-    .long   0xa548f3fc              # cld; rep movsq
-
-.Lntt_in_prologue:
-    # Restore rdi and rsi saved by xlate preamble in shadow space
-    mov     8(%rax), %rcx
-    mov     16(%rax), %rdx
-    mov     %rcx, 176($context)     # context->Rdi
-    mov     %rdx, 168($context)     # context->Rsi
-    mov     %rax, 152($context)     # context->Rsp = original %rsp
-
-    mov     40($disp), %rdi         # disp->ContextRecord
-    mov     $context, %rsi
-    mov     \$154, %ecx             # sizeof(CONTEXT)/8
-    .long   0xa548f3fc              # cld; rep movsq
-
-    mov     $disp, %rsi
-    xor     %rcx, %rcx              # UNW_FLAG_NHANDLER
-    mov     8(%rsi), %rdx           # disp->ImageBase
-    mov     0(%rsi), %r8            # disp->ControlPc
-    mov     16(%rsi), %r9           # disp->FunctionEntry
-    mov     40(%rsi), %r10          # disp->ContextRecord
-    lea     56(%rsi), %r11          # &disp->HandlerData
-    lea     24(%rsi), %r12          # &disp->EstablisherFrame
-    mov     %r10, 32(%rsp)
-    mov     %r11, 40(%rsp)
-    mov     %r12, 48(%rsp)
-    mov     %rcx, 56(%rsp)
-    call    *__imp_RtlVirtualUnwind(%rip)
-
-    mov     \$1, %eax               # ExceptionContinueSearch
-    add     \$64, %rsp
-    popfq
-    pop     %r15
-    pop     %r14
-    pop     %r13
-    pop     %r12
-    pop     %rbp
-    pop     %rbx
-    pop     %rdi
-    pop     %rsi
-    ret
-.size   ntt_se_handler,.-ntt_se_handler
-
-.section    .pdata
-.align  4
-    .rva    .LSEH_begin_ml_dsa_poly_ntt_mult_avx2
-    .rva    .LSEH_end_ml_dsa_poly_ntt_mult_avx2
-    .rva    .LSEH_info_ml_dsa_poly_ntt_mult_avx2
-    .rva    .LSEH_begin_ml_dsa_poly_ntt_avx2
-    .rva    .LSEH_end_ml_dsa_poly_ntt_avx2
-    .rva    .LSEH_info_ml_dsa_poly_ntt_avx2
-    .rva    .LSEH_begin_ml_dsa_poly_ntt_inverse_avx2
-    .rva    .LSEH_end_ml_dsa_poly_ntt_inverse_avx2
-    .rva    .LSEH_info_ml_dsa_poly_ntt_inverse_avx2
-
-.section    .xdata
-.align  8
-.LSEH_info_ml_dsa_poly_ntt_mult_avx2:
-    .byte   9,0,0,0
-    .rva    ntt_se_handler
-    .rva    .Lntt_mult_body,.Lntt_mult_epilogue
-.LSEH_info_ml_dsa_poly_ntt_avx2:
-    .byte   9,0,0,0
-    .rva    ntt_se_handler
-    .rva    .Lntt_body,.Lntt_epilogue
-.LSEH_info_ml_dsa_poly_ntt_inverse_avx2:
-    .byte   9,0,0,0
-    .rva    ntt_se_handler
-    .rva    .Lintt_body,.Lintt_epilogue
-___
-}
-
-}}} else {{{
-# When AVX2 is not available, output stub functions
-# The capable function returns 0, and the operation functions trap if called
-$code .= <<___;
-.text
-
-.globl  ml_dsa_ntt_avx2_capable
-.type   ml_dsa_ntt_avx2_capable,\@abi-omnipotent
-ml_dsa_ntt_avx2_capable:
-    xor     %eax, %eax
-    ret
-.size   ml_dsa_ntt_avx2_capable, .-ml_dsa_ntt_avx2_capable
-
-.globl  ml_dsa_poly_ntt_mult_avx2
-.globl  ml_dsa_poly_ntt_avx2
-.globl  ml_dsa_poly_ntt_inverse_avx2
-.type   ml_dsa_poly_ntt_mult_avx2,\@abi-omnipotent
-ml_dsa_poly_ntt_mult_avx2:
-ml_dsa_poly_ntt_avx2:
-ml_dsa_poly_ntt_inverse_avx2:
-    .byte   0x0f,0x0b       # ud2
-    ret
-.size   ml_dsa_poly_ntt_mult_avx2, .-ml_dsa_poly_ntt_mult_avx2
-___
-}}}
-
-print $code;
-close STDOUT or die "error closing STDOUT: $!";
diff --git a/crypto/ml_dsa/build.info b/crypto/ml_dsa/build.info
index e41867f573..a0aee56f5a 100644
--- a/crypto/ml_dsa/build.info
+++ b/crypto/ml_dsa/build.info
@@ -4,36 +4,7 @@ $COMMON=ml_dsa_encoders.c ml_dsa_key_compress.c ml_dsa_key.c \
         ml_dsa_matrix.c ml_dsa_ntt.c ml_dsa_params.c ml_dsa_sample.c \
         ml_dsa_sign.c
 
-$ML_DSA_ASM=
-IF[{- !$disabled{asm} -}]
-  $ML_DSA_ASM_x86_64=ml_dsa_ntt-x86_64.s
-
-  IF[$ML_DSA_ASM_{- $target{asm_arch} -}]
-    $ML_DSA_ASM=$ML_DSA_ASM_{- $target{asm_arch} -}
-  ENDIF
-ENDIF
-
 IF[{- !$disabled{'ml-dsa'} -}]
-  IF[{- ($target{perlasm_scheme} // '') ne '31' -}]
-    $ML_DSA_VX_s390x=ml_dsa_ntt_vec128.c
-    $ML_DSA_DEF_s390x=OPENSSL_ML_DSA_S390X
-  ENDIF
-
-  # Now that we have defined all the arch specific variables, use the
-  # appropriate ones, and define the appropriate macros
-  IF[$ML_DSA_VX_{- $target{asm_arch} -}]
-    $ML_DSA_VX=$ML_DSA_VX_{- $target{asm_arch} -}
-    $ML_DSA_DEF=$ML_DSA_DEF_{- $target{asm_arch} -}
-  ENDIF
+  SOURCE[../../libcrypto]=$COMMON
+  SOURCE[../../providers/libfips.a]=$COMMON
 ENDIF
-
-DEFINE[../../libcrypto]=$ML_DSA_DEF
-DEFINE[../../providers/libfips.a]=$ML_DSA_DEF
-
-IF[{- !$disabled{'ml-dsa'} -}]
-  SOURCE[../../libcrypto]=$COMMON $ML_DSA_ASM $ML_DSA_VX
-  SOURCE[../../providers/libfips.a]=$COMMON $ML_DSA_ASM $ML_DSA_VX
-ENDIF
-
-# Assembly implementations
-GENERATE[ml_dsa_ntt-x86_64.s]=asm/ml_dsa_ntt-x86_64.pl
diff --git a/crypto/ml_dsa/ml_dsa_hash.h b/crypto/ml_dsa/ml_dsa_hash.h
index 1b7ce63516..7625d3367d 100644
--- a/crypto/ml_dsa/ml_dsa_hash.h
+++ b/crypto/ml_dsa/ml_dsa_hash.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_ML_DSA_ML_DSA_HASH_H)
-#define OSSL_LIBCRYPTO_ML_DSA_ML_DSA_HASH_H
-
 #include 
 
 static ossl_inline ossl_unused int
@@ -42,5 +39,3 @@ shake_xof_3(EVP_MD_CTX *ctx, const EVP_MD *md, const uint8_t *in1, size_t in1_le
         && EVP_DigestUpdate(ctx, in3, in3_len)
         && EVP_DigestSqueeze(ctx, out, out_len);
 }
-
-#endif /* !defined(OSSL_LIBCRYPTO_ML_DSA_ML_DSA_HASH_H) */
diff --git a/crypto/ml_dsa/ml_dsa_key.c b/crypto/ml_dsa/ml_dsa_key.c
index ea5f4ee4da..fdbd3eec6c 100644
--- a/crypto/ml_dsa/ml_dsa_key.c
+++ b/crypto/ml_dsa/ml_dsa_key.c
@@ -73,20 +73,6 @@ end:
     return ret;
 }
 
-/*
- * @brief Fetch digest algorithms based on a propq.
- * For the import case ossl_ml_dsa_key_new() gets passed a NULL propq,
- * so the propq is optionally deferred to the import using OSSL_PARAM.
- */
-int ossl_ml_dsa_key_fetch_digests(ML_DSA_KEY *key, const char *propq)
-{
-    EVP_MD_free(key->shake128_md);
-    EVP_MD_free(key->shake256_md);
-    key->shake128_md = EVP_MD_fetch(key->libctx, "SHAKE-128", propq);
-    key->shake256_md = EVP_MD_fetch(key->libctx, "SHAKE-256", propq);
-    return (key->shake128_md != NULL && key->shake256_md != NULL);
-}
-
 /**
  * @brief Create a new ML_DSA_KEY object
  *
@@ -109,7 +95,9 @@ ML_DSA_KEY *ossl_ml_dsa_key_new(OSSL_LIB_CTX *libctx, const char *propq,
         ret->libctx = libctx;
         ret->params = params;
         ret->prov_flags = ML_DSA_KEY_PROV_FLAGS_DEFAULT;
-        if (!ossl_ml_dsa_key_fetch_digests(ret, propq))
+        ret->shake128_md = EVP_MD_fetch(libctx, "SHAKE-128", propq);
+        ret->shake256_md = EVP_MD_fetch(libctx, "SHAKE-256", propq);
+        if (ret->shake128_md == NULL || ret->shake256_md == NULL)
             goto err;
     }
     return ret;
@@ -293,7 +281,7 @@ int ossl_ml_dsa_key_equal(const ML_DSA_KEY *key1, const ML_DSA_KEY *key2,
         if (!key_checked
             && (selection & OSSL_KEYMGMT_SELECT_PRIVATE_KEY) != 0) {
             if (key1->priv_encoding != NULL && key2->priv_encoding != NULL) {
-                if (CRYPTO_memcmp(key1->priv_encoding, key2->priv_encoding,
+                if (memcmp(key1->priv_encoding, key2->priv_encoding,
                         key1->params->sk_len)
                     != 0)
                     return 0;
@@ -332,7 +320,7 @@ int ossl_ml_dsa_key_has(const ML_DSA_KEY *key, int selection)
  * @returns 1 on success, or 0 on failure.
  */
 static int public_from_private(const ML_DSA_KEY *key, EVP_MD_CTX *md_ctx,
-    const OSSL_ML_DSA_SAMPLE_OPS *sample_ops, VECTOR *t1, VECTOR *t0)
+    VECTOR *t1, VECTOR *t0)
 {
     int ret = 0;
     const ML_DSA_PARAMS *params = key->params;
@@ -351,7 +339,7 @@ static int public_from_private(const ML_DSA_KEY *key, EVP_MD_CTX *md_ctx,
     matrix_init(&a_ntt, s1_ntt.poly + l, k, l);
 
     /* Using rho generate A' = A in NTT form */
-    if (!sample_ops->matrix_expand_A(md_ctx, key->shake128_md, key->rho, &a_ntt))
+    if (!matrix_expand_A(md_ctx, key->shake128_md, key->rho, &a_ntt))
         goto err;
 
     /* t = NTT_inv(A' * NTT(s1)) + s2 */
@@ -376,7 +364,6 @@ err:
 int ossl_ml_dsa_key_public_from_private(ML_DSA_KEY *key)
 {
     int ret = 0;
-    const OSSL_ML_DSA_SAMPLE_OPS *sample_ops = ossl_ml_dsa_sample_ops();
     VECTOR t0;
     EVP_MD_CTX *md_ctx = NULL;
 
@@ -384,7 +371,7 @@ int ossl_ml_dsa_key_public_from_private(ML_DSA_KEY *key)
         return 0;
     ret = ((md_ctx = EVP_MD_CTX_new()) != NULL)
         && ossl_ml_dsa_key_pub_alloc(key) /* allocate space for t1 */
-        && public_from_private(key, md_ctx, sample_ops, &key->t1, &t0)
+        && public_from_private(key, md_ctx, &key->t1, &t0)
         && vector_equal(&t0, &key->t0) /* compare the generated t0 to the expected */
         && ossl_ml_dsa_pk_encode(key)
         && shake_xof(md_ctx, key->shake256_md,
@@ -398,7 +385,6 @@ int ossl_ml_dsa_key_public_from_private(ML_DSA_KEY *key)
 int ossl_ml_dsa_key_pairwise_check(const ML_DSA_KEY *key)
 {
     int ret = 0;
-    const OSSL_ML_DSA_SAMPLE_OPS *sample_ops = ossl_ml_dsa_sample_ops();
     VECTOR t1, t0;
     POLY *polys = NULL;
     uint32_t k = (uint32_t)key->params->k;
@@ -416,7 +402,7 @@ int ossl_ml_dsa_key_pairwise_check(const ML_DSA_KEY *key)
 
     vector_init(&t1, polys, k);
     vector_init(&t0, polys + k, k);
-    if (!public_from_private(key, md_ctx, sample_ops, &t1, &t0))
+    if (!public_from_private(key, md_ctx, &t1, &t0))
         goto err;
 
     ret = vector_equal(&t1, &key->t1) && vector_equal(&t0, &key->t0);
@@ -437,7 +423,6 @@ err:
 static int keygen_internal(ML_DSA_KEY *out)
 {
     int ret = 0;
-    const OSSL_ML_DSA_SAMPLE_OPS *sample_ops = ossl_ml_dsa_sample_ops();
     uint8_t augmented_seed[ML_DSA_SEED_BYTES + 2];
     uint8_t expanded_seed[ML_DSA_RHO_BYTES + ML_DSA_PRIV_SEED_BYTES + ML_DSA_K_BYTES];
     const uint8_t *const rho = expanded_seed; /* p = Public Random Seed */
@@ -464,9 +449,8 @@ static int keygen_internal(ML_DSA_KEY *out)
     memcpy(out->rho, rho, sizeof(out->rho));
     memcpy(out->K, K, sizeof(out->K));
 
-    ret = sample_ops->vector_expand_S(md_ctx, out->shake256_md, params->eta,
-              priv_seed, &out->s1, &out->s2)
-        && public_from_private(out, md_ctx, sample_ops, &out->t1, &out->t0)
+    ret = vector_expand_S(md_ctx, out->shake256_md, params->eta, priv_seed, &out->s1, &out->s2)
+        && public_from_private(out, md_ctx, &out->t1, &out->t0)
         && ossl_ml_dsa_pk_encode(out)
         && shake_xof(md_ctx, out->shake256_md, out->pub_encoding, out->params->pk_len,
             out->tr, sizeof(out->tr))
@@ -508,7 +492,7 @@ int ossl_ml_dsa_generate_key(ML_DSA_KEY *out)
                 "explicit %s private key does not match seed",
                 out->params->alg);
         }
-        OPENSSL_secure_clear_free(sk, out->params->sk_len);
+        OPENSSL_free(sk);
     }
     return ret;
 }
diff --git a/crypto/ml_dsa/ml_dsa_key.h b/crypto/ml_dsa/ml_dsa_key.h
index 6defd090fe..e89bb01ca4 100644
--- a/crypto/ml_dsa/ml_dsa_key.h
+++ b/crypto/ml_dsa/ml_dsa_key.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_ML_DSA_ML_DSA_KEY_H)
-#define OSSL_LIBCRYPTO_ML_DSA_ML_DSA_KEY_H
-
 #include 
 #include "ml_dsa_local.h"
 #include "ml_dsa_vector.h"
@@ -57,5 +54,3 @@ struct ml_dsa_key_st {
     VECTOR s1; /* private secret of size L with short coefficients (-4..4) or (-2..2) */
     /* The s1->poly block is allocated and has space for s2 and t0 also */
 };
-
-#endif /* !defined(OSSL_LIBCRYPTO_ML_DSA_ML_DSA_KEY_H) */
diff --git a/crypto/ml_dsa/ml_dsa_local.h b/crypto/ml_dsa/ml_dsa_local.h
index 23e2db247c..d4f63f7e99 100644
--- a/crypto/ml_dsa/ml_dsa_local.h
+++ b/crypto/ml_dsa/ml_dsa_local.h
@@ -59,21 +59,10 @@ typedef struct vector_st VECTOR;
 typedef struct matrix_st MATRIX;
 typedef struct ml_dsa_sig_st ML_DSA_SIG;
 
-typedef int(ML_DSA_MATRIX_EXPAND_A_FN)(EVP_MD_CTX *g_ctx, const EVP_MD *md,
+int ossl_ml_dsa_matrix_expand_A(EVP_MD_CTX *g_ctx, const EVP_MD *md,
     const uint8_t *rho, MATRIX *out);
-typedef int(ML_DSA_VECTOR_EXPAND_S_FN)(EVP_MD_CTX *h_ctx, const EVP_MD *md,
-    int eta, const uint8_t *seed, VECTOR *s1, VECTOR *s2);
-typedef void(ML_DSA_VECTOR_EXPAND_MASK_FN)(VECTOR *out,
-    const uint8_t rho_prime[ML_DSA_RHO_PRIME_BYTES], uint32_t kappa, uint32_t gamma1,
-    EVP_MD_CTX *h_ctx, const EVP_MD *md);
-
-typedef struct ossl_ml_dsa_sample_ops_st {
-    ML_DSA_MATRIX_EXPAND_A_FN *matrix_expand_A;
-    ML_DSA_VECTOR_EXPAND_S_FN *vector_expand_S;
-    ML_DSA_VECTOR_EXPAND_MASK_FN *vector_expand_mask;
-} OSSL_ML_DSA_SAMPLE_OPS;
-
-const OSSL_ML_DSA_SAMPLE_OPS *ossl_ml_dsa_sample_ops(void);
+int ossl_ml_dsa_vector_expand_S(EVP_MD_CTX *h_ctx, const EVP_MD *md, int eta,
+    const uint8_t *seed, VECTOR *s1, VECTOR *s2);
 void ossl_ml_dsa_matrix_mult_vector(const MATRIX *matrix_kl, const VECTOR *vl,
     VECTOR *vk);
 int ossl_ml_dsa_poly_expand_mask(POLY *out, const uint8_t *seed, size_t seed_len,
@@ -87,16 +76,6 @@ void ossl_ml_dsa_poly_ntt(POLY *s);
 void ossl_ml_dsa_poly_ntt_inverse(POLY *s);
 void ossl_ml_dsa_poly_ntt_mult(const POLY *lhs, const POLY *rhs, POLY *out);
 
-/* Optimization for s390x */
-/* z13 supports VX, z14 supports VXE; z14 means __ARCH__ == 12 */
-#if defined(OPENSSL_ML_DSA_S390X) && defined(__s390x__) && (__ARCH__ >= 12) && defined(__VX__)
-#include "arch/s390x_arch.h"
-#define VX_COMPILER_SUPPORT_VEC128
-void ossl_ml_dsa_poly_ntt_vec128(POLY *p);
-void ossl_ml_dsa_poly_ntt_inverse_vec128(POLY *p);
-void ossl_poly_ntt_mult_scalar_vec128(const POLY *lhs, const POLY *rhs, POLY *out);
-#endif
-
 void ossl_ml_dsa_key_compress_power2_round(uint32_t r, uint32_t *r1, uint32_t *r0);
 uint32_t ossl_ml_dsa_key_compress_high_bits(uint32_t r, uint32_t gamma2);
 void ossl_ml_dsa_key_compress_decompose(uint32_t r, uint32_t gamma2,
@@ -122,26 +101,20 @@ int ossl_ml_dsa_poly_decode_expand_mask(POLY *out,
     const uint8_t *in, size_t in_len,
     uint32_t gamma1);
 
-/*-
- * @brief Reduces 0 <= x < 2*q, mod q.
+/*
+ * @brief Reduces x mod q in constant time
  * i.e. return x < q ? x : x - q;
  *
- * Subtract |q| if the input is larger, without exposing a side-channel,
- * avoiding the "clangover" attack.  See |constish_time_true| for a discussion
- * on why the value barrier is by default omitted.
- *
+ * @param x Where x is assumed to be in the range 0 <= x < 2*q
  * @returns the difference in the range 0..q-1
  */
-static ossl_inline ossl_unused __owur uint32_t reduce_once(uint32_t x)
+static ossl_inline ossl_unused uint32_t reduce_once(uint32_t x)
 {
-    const uint32_t subtracted = x - ML_DSA_Q;
-    uint32_t mask = constish_time_true(subtracted >> 31);
-
-    return (mask & x) | (~mask & subtracted);
+    return constant_time_select_32(constant_time_lt_32(x, ML_DSA_Q), x, x - ML_DSA_Q);
 }
 
 /*
- * @brief Calculates the positive value of (a-b) mod q in constant time.
+ * @brief Calculate The positive value of (a-b) mod q in constant time.
  *
  * a - b mod q gives a value in the range -(q-1)..(q-1)
  * By adding q we get a range of 1..(2q-1).
@@ -158,25 +131,21 @@ static ossl_inline ossl_unused uint32_t mod_sub(uint32_t a, uint32_t b)
 
 /*
  * @brief Returns the absolute value in constant time.
- * i.e.  return is_negative(x) ? -x : x;
+ * i.e. return is_positive(x) ? x : -x;
  */
 static ossl_inline ossl_unused uint32_t abs_signed(uint32_t x)
 {
-    uint32_t mask = 0u - (x >> 31);
-
-    return constant_time_select_32(mask, 0u - x, x);
+    return constant_time_select_32(constant_time_lt_32(x, 0x80000000), x, 0u - x);
 }
 
 /*
  * @brief Returns the absolute value modulo q in constant time
- * i.e return x <= (q-1)/2 ? x : q - x;
+ * i.e return x > (q - 1) / 2 ? q - x : x;
  */
 static ossl_inline ossl_unused uint32_t abs_mod_prime(uint32_t x)
 {
-    uint32_t mask = x - ML_DSA_Q_MINUS1_DIV2;
-
-    mask = 0u - (mask >> 31);
-    return constant_time_select_32(mask, x, ML_DSA_Q - x);
+    return constant_time_select_32(constant_time_lt_32(ML_DSA_Q_MINUS1_DIV2, x),
+        ML_DSA_Q - x, x);
 }
 
 /*
@@ -185,9 +154,7 @@ static ossl_inline ossl_unused uint32_t abs_mod_prime(uint32_t x)
  */
 static ossl_inline ossl_unused uint32_t maximum(uint32_t x, uint32_t y)
 {
-    uint32_t mask = x - y;
-    mask = 0u - (mask >> 31);
-    return constant_time_select_int(mask, y, x);
+    return constant_time_select_int(constant_time_lt(x, y), y, x);
 }
 
 #endif /* OSSL_CRYPTO_ML_DSA_LOCAL_H */
diff --git a/crypto/ml_dsa/ml_dsa_matrix.h b/crypto/ml_dsa/ml_dsa_matrix.h
index e5f4ebf6d9..0352ecac7a 100644
--- a/crypto/ml_dsa/ml_dsa_matrix.h
+++ b/crypto/ml_dsa/ml_dsa_matrix.h
@@ -8,11 +8,6 @@
  */
 
 /* A 'k' by 'l' Matrix object ('k' rows and 'l' columns) containing polynomial scalars */
-#if !defined(OSSL_LIBCRYPTO_ML_DSA_ML_DSA_MATRIX_H)
-#define OSSL_LIBCRYPTO_ML_DSA_ML_DSA_MATRIX_H
-
-#include "ml_dsa_local.h"
-
 struct matrix_st {
     POLY *m_poly;
     size_t k, l;
@@ -41,4 +36,9 @@ matrix_mult_vector(const MATRIX *a, const VECTOR *s, VECTOR *t)
     ossl_ml_dsa_matrix_mult_vector(a, s, t);
 }
 
-#endif /* !defined(OSSL_LIBCRYPTO_ML_DSA_ML_DSA_MATRIX_H) */
+static ossl_inline ossl_unused int
+matrix_expand_A(EVP_MD_CTX *g_ctx, const EVP_MD *md, const uint8_t *rho,
+    MATRIX *out)
+{
+    return ossl_ml_dsa_matrix_expand_A(g_ctx, md, rho, out);
+}
diff --git a/crypto/ml_dsa/ml_dsa_ntt.c b/crypto/ml_dsa/ml_dsa_ntt.c
index 3f5ebd5206..2cce462292 100644
--- a/crypto/ml_dsa/ml_dsa_ntt.c
+++ b/crypto/ml_dsa/ml_dsa_ntt.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -9,39 +9,6 @@
 
 #include "ml_dsa_local.h"
 #include "ml_dsa_poly.h"
-#include 
-
-/* Assembly function declarations for AVX2 implementations */
-#if !defined(OPENSSL_NO_ASM) && (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64))
-#define ML_DSA_NTT_ASM
-int ml_dsa_ntt_avx2_capable(void);
-void ml_dsa_poly_ntt_avx2(uint32_t *p_coeff, const uint32_t *p_zetas);
-void ml_dsa_poly_ntt_inverse_avx2(uint32_t *p_coeff);
-void ml_dsa_poly_ntt_mult_avx2(const uint32_t *a, const uint32_t *b, uint32_t *out);
-#endif
-
-/*
- * Function pointer types for NTT operations.
- * These allow selecting AVX2 or scalar implementations at initialization time.
- */
-typedef void (*ml_dsa_poly_ntt_fn)(POLY *p);
-typedef void (*ml_dsa_poly_ntt_inverse_fn)(POLY *p);
-typedef void (*ml_dsa_poly_ntt_mult_fn)(const POLY *lhs, const POLY *rhs,
-    POLY *out);
-
-/* Forward declarations of scalar NTT functions */
-static void poly_ntt_scalar(POLY *p);
-static void poly_ntt_inverse_scalar(POLY *p);
-static void poly_ntt_mult_scalar(const POLY *lhs, const POLY *rhs, POLY *out);
-
-/*
- * NTT function pointers - initialized to scalar implementations by default.
- */
-static ml_dsa_poly_ntt_fn poly_ntt_impl = poly_ntt_scalar;
-static ml_dsa_poly_ntt_inverse_fn poly_ntt_inverse_impl = poly_ntt_inverse_scalar;
-static ml_dsa_poly_ntt_mult_fn poly_ntt_mult_impl = poly_ntt_mult_scalar;
-
-static CRYPTO_ONCE ml_dsa_ntt_once = CRYPTO_ONCE_STATIC_INIT;
 
 /*
  * This file has multiple parts required for fast matrix multiplication,
@@ -133,19 +100,32 @@ static uint32_t reduce_montgomery(uint64_t a)
 }
 
 /*
- * Scalar (fallback) implementations of NTT operations.
- * These are used when AVX2 is not available.
+ * @brief Multiply two polynomials in the number theoretically transformed state.
+ * See FIPS 204, Algorithm 45, MultiplyNTT()
+ * This function has been modified to use montgomery multiplication
+ *
+ * @param lhs A polynomial multiplicand
+ * @param rhs A polynomial multiplier
+ * @param out The returned result of the polynomial multiply
  */
-static void poly_ntt_mult_scalar(const POLY *lhs, const POLY *rhs, POLY *out)
+void ossl_ml_dsa_poly_ntt_mult(const POLY *lhs, const POLY *rhs, POLY *out)
 {
     int i;
 
     for (i = 0; i < ML_DSA_NUM_POLY_COEFFICIENTS; i++)
-        out->coeff[i] = reduce_montgomery((uint64_t)lhs->coeff[i]
-            * (uint64_t)rhs->coeff[i]);
+        out->coeff[i] = reduce_montgomery((uint64_t)lhs->coeff[i] * (uint64_t)rhs->coeff[i]);
 }
 
-static void poly_ntt_scalar(POLY *p)
+/*
+ * In place number theoretic transform of a given polynomial.
+ *
+ * See FIPS 204, Algorithm 41, NTT()
+ * This function uses montgomery multiplication.
+ *
+ * @param p a polynomial that is used as the input, that is replaced with
+ *        the NTT of the polynomial
+ */
+void ossl_ml_dsa_poly_ntt(POLY *p)
 {
     int i, j, k;
     int step;
@@ -171,7 +151,14 @@ static void poly_ntt_scalar(POLY *p)
     }
 }
 
-static void poly_ntt_inverse_scalar(POLY *p)
+/*
+ * @brief In place inverse number theoretic transform of a given polynomial.
+ * See FIPS 204, Algorithm 42,  NTT^-1()
+ *
+ * @param p a polynomial that is used as the input, that is overwritten with
+ *          the inverse of the NTT.
+ */
+void ossl_ml_dsa_poly_ntt_inverse(POLY *p)
 {
     /*
      * Step: 128, 64, 32, 16, ..., 1
@@ -202,92 +189,5 @@ static void poly_ntt_inverse_scalar(POLY *p)
         }
     }
     for (i = 0; i < ML_DSA_NUM_POLY_COEFFICIENTS; i++)
-        p->coeff[i] = reduce_montgomery((uint64_t)p->coeff[i]
-            * (uint64_t)inverse_degree_montgomery);
-}
-
-/*
- * AVX2 wrapper functions
- */
-#ifdef ML_DSA_NTT_ASM
-static void poly_ntt_mult_avx2_wrapper(const POLY *lhs, const POLY *rhs,
-    POLY *out)
-{
-    ml_dsa_poly_ntt_mult_avx2(&lhs->coeff[0], &rhs->coeff[0], &out->coeff[0]);
-}
-
-static void poly_ntt_avx2_wrapper(POLY *p)
-{
-    ml_dsa_poly_ntt_avx2(&p->coeff[0], zetas_montgomery);
-}
-
-static void poly_ntt_inverse_avx2_wrapper(POLY *p)
-{
-    ml_dsa_poly_ntt_inverse_avx2(&p->coeff[0]);
-}
-#endif
-
-/*
- * Initialize NTT function pointers to AVX2 implementations if available.
- * Scalar implementations are used by default.
- */
-static void ml_dsa_ntt_init(void)
-{
-#ifdef ML_DSA_NTT_ASM
-    if (ml_dsa_ntt_avx2_capable()) {
-        poly_ntt_impl = poly_ntt_avx2_wrapper;
-        poly_ntt_inverse_impl = poly_ntt_inverse_avx2_wrapper;
-        poly_ntt_mult_impl = poly_ntt_mult_avx2_wrapper;
-    }
-#endif
-#ifdef VX_COMPILER_SUPPORT_VEC128
-    if (S390X_VX_CAPABLE) {
-        poly_ntt_impl = ossl_ml_dsa_poly_ntt_vec128;
-        poly_ntt_inverse_impl = ossl_ml_dsa_poly_ntt_inverse_vec128;
-        poly_ntt_mult_impl = ossl_poly_ntt_mult_scalar_vec128;
-    }
-#endif
-}
-
-/*
- * @brief Multiply two polynomials in the number theoretically transformed state.
- * See FIPS 204, Algorithm 45, MultiplyNTT()
- * This function has been modified to use montgomery multiplication
- *
- * @param lhs A polynomial multiplicand
- * @param rhs A polynomial multiplier
- * @param out The returned result of the polynomial multiply
- */
-void ossl_ml_dsa_poly_ntt_mult(const POLY *lhs, const POLY *rhs, POLY *out)
-{
-    (void)CRYPTO_THREAD_run_once(&ml_dsa_ntt_once, ml_dsa_ntt_init);
-    poly_ntt_mult_impl(lhs, rhs, out);
-}
-
-/*
- * In place number theoretic transform of a given polynomial.
- *
- * See FIPS 204, Algorithm 41, NTT()
- * This function uses montgomery multiplication.
- *
- * @param p a polynomial that is used as the input, that is replaced with
- *        the NTT of the polynomial
- */
-void ossl_ml_dsa_poly_ntt(POLY *p)
-{
-    (void)CRYPTO_THREAD_run_once(&ml_dsa_ntt_once, ml_dsa_ntt_init);
-    poly_ntt_impl(p);
-}
-
-/*
- * @brief In place inverse number theoretic transform of a given polynomial.
- * See FIPS 204, Algorithm 42,  NTT^-1()
- *
- * @param p a polynomial that is used as the input, that is overwritten with
- *          the inverse of the NTT.
- */
-void ossl_ml_dsa_poly_ntt_inverse(POLY *p)
-{
-    (void)CRYPTO_THREAD_run_once(&ml_dsa_ntt_once, ml_dsa_ntt_init);
-    poly_ntt_inverse_impl(p);
+        p->coeff[i] = reduce_montgomery((uint64_t)p->coeff[i] * (uint64_t)inverse_degree_montgomery);
 }
diff --git a/crypto/ml_dsa/ml_dsa_ntt_vec128.c b/crypto/ml_dsa/ml_dsa_ntt_vec128.c
deleted file mode 100644
index 54d59a9a08..0000000000
--- a/crypto/ml_dsa/ml_dsa_ntt_vec128.c
+++ /dev/null
@@ -1,708 +0,0 @@
-/*
- * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
- *
- * Licensed under the Apache License 2.0 (the "License").  You may not use
- * this file except in compliance with the License.  You can obtain a copy
- * in the file LICENSE in the source distribution or at
- * https://www.openssl.org/source/license.html
- */
-
-#include "ml_dsa_local.h"
-#include "ml_dsa_poly.h"
-
-#if defined(OPENSSL_ML_DSA_S390X) && defined(__s390x__) && (__ARCH__ >= 12) && defined(__VX__)
-
-#include 
-
-#include 
-
-/* Width of vector registers in bytes */
-#define VECTOR_REG_WIDTH_BYTES 16
-/*
- * __may_alias__ solves the undefined behavior problem in code like
- * vec_int32_t *out_vec_ptr = (vec_int32_t *)out->coeff;
- */
-typedef int32_t vec_int32_t __attribute__((vector_size(VECTOR_REG_WIDTH_BYTES), __may_alias__));
-typedef uint32_t vec_uint32_t __attribute__((vector_size(VECTOR_REG_WIDTH_BYTES), __may_alias__));
-
-typedef int32_t vec_int32_alias_t __attribute__((vector_size(VECTOR_REG_WIDTH_BYTES)));
-typedef uint32_t vec_uint32_alias_t __attribute__((vector_size(VECTOR_REG_WIDTH_BYTES)));
-
-/* Our implementation of the vectorized algorithms assumes NUM_INT32_IN_VECTOR == 4. */
-#define NUM_INT32_IN_VECTOR (VECTOR_REG_WIDTH_BYTES / ((int)sizeof(int32_t)))
-
-/*
- * This file has multiple parts required for fast matrix multiplication,
- * 1) NTT (See https://eprint.iacr.org/2024/585.pdf)
- * NTT and NTT inverse transformations are Discrete Fourier Transforms in a
- * polynomial ring. Fast-Fourier Transformations can then be applied to make
- * multiplications n log(n). This uses the symmetry of the transformation to
- * reduce computations.
- *
- * 2) Montgomery multiplication
- * The multiplication of a.b mod q requires division by q which is a slow operation.
- *
- * When many multiplications mod q are required montgomery multiplication
- * can be used. This requires a number R > q such that R & q are coprime
- * (i.e. GCD(R, q) = 1), so that division happens using R instead of q.
- * If r is a power of 2 then this division can be done as a bit shift.
- *
- * Given that q = 2^23 - 2^13 + 1
- * We can chose a Montgomery multiplier of R = 2^32.
- *
- * To transform |a| into Montgomery form |m| we use
- *   m = a mod q * ((2^32)*(2^32) mod q)
- * which is then Montgomery reduced, removing the excess factor of R = 2^32.
- *
- * A good reference for optimizations around ML-DSA and Montgomery multiplication is
- * [Seiler 2018, Faster AVX2 optimized NTT multiplication for Ring-LWE lattice cryptography].
- */
-
-/*
- * The table in FIPS 204 Appendix B uses the following formula
- * zeta[k]= 1753^bitrev(k) mod q for (k = 1..255) (The first value is not used).
- *
- * As this implementation uses montgomery form with a multiplier of 2^32.
- * The values need to be transformed i.e.
- *
- * zetasMontgomery[k] = reduce_montgomery(zeta[k] * (2^32 * 2^32 mod(q)))
- * reduce_montgomery() is defined below.
- */
-static const int32_t zetas_montgomery[256] = {
-    4193792, 25847, 5771523, 7861508, 237124, 7602457, 7504169, 466468,
-    1826347, 2353451, 8021166, 6288512, 3119733, 5495562, 3111497, 2680103,
-    2725464, 1024112, 7300517, 3585928, 7830929, 7260833, 2619752, 6271868,
-    6262231, 4520680, 6980856, 5102745, 1757237, 8360995, 4010497, 280005,
-    2706023, 95776, 3077325, 3530437, 6718724, 4788269, 5842901, 3915439,
-    4519302, 5336701, 3574422, 5512770, 3539968, 8079950, 2348700, 7841118,
-    6681150, 6736599, 3505694, 4558682, 3507263, 6239768, 6779997, 3699596,
-    811944, 531354, 954230, 3881043, 3900724, 5823537, 2071892, 5582638,
-    4450022, 6851714, 4702672, 5339162, 6927966, 3475950, 2176455, 6795196,
-    7122806, 1939314, 4296819, 7380215, 5190273, 5223087, 4747489, 126922,
-    3412210, 7396998, 2147896, 2715295, 5412772, 4686924, 7969390, 5903370,
-    7709315, 7151892, 8357436, 7072248, 7998430, 1349076, 1852771, 6949987,
-    5037034, 264944, 508951, 3097992, 44288, 7280319, 904516, 3958618,
-    4656075, 8371839, 1653064, 5130689, 2389356, 8169440, 759969, 7063561,
-    189548, 4827145, 3159746, 6529015, 5971092, 8202977, 1315589, 1341330,
-    1285669, 6795489, 7567685, 6940675, 5361315, 4499357, 4751448, 3839961,
-    2091667, 3407706, 2316500, 3817976, 5037939, 2244091, 5933984, 4817955,
-    266997, 2434439, 7144689, 3513181, 4860065, 4621053, 7183191, 5187039,
-    900702, 1859098, 909542, 819034, 495491, 6767243, 8337157, 7857917,
-    7725090, 5257975, 2031748, 3207046, 4823422, 7855319, 7611795, 4784579,
-    342297, 286988, 5942594, 4108315, 3437287, 5038140, 1735879, 203044,
-    2842341, 2691481, 5790267, 1265009, 4055324, 1247620, 2486353, 1595974,
-    4613401, 1250494, 2635921, 4832145, 5386378, 1869119, 1903435, 7329447,
-    7047359, 1237275, 5062207, 6950192, 7929317, 1312455, 3306115, 6417775,
-    7100756, 1917081, 5834105, 7005614, 1500165, 777191, 2235880, 3406031,
-    7838005, 5548557, 6709241, 6533464, 5796124, 4656147, 594136, 4603424,
-    6366809, 2432395, 2454455, 8215696, 1957272, 3369112, 185531, 7173032,
-    5196991, 162844, 1616392, 3014001, 810149, 1652634, 4686184, 6581310,
-    5341501, 3523897, 3866901, 269760, 2213111, 7404533, 1717735, 472078,
-    7953734, 1723600, 6577327, 1910376, 6712985, 7276084, 8119771, 4546524,
-    5441381, 6144432, 7959518, 6094090, 183443, 7403526, 1612842, 4834730,
-    7826001, 3919660, 8332111, 7018208, 3937738, 1400424, 7534263, 1976782
-};
-
-/* clang-format off */
-static const int32_t zetas_montgomery_twisted[256] = {
-        -512,   1830765815,  -1929875197,  -1927777020,
-  1640767044,   1477910809,   1612161321,   1640734244,
-   308362795,  -1815525077,  -1374673746,  -1091570560,
- -1929495947,    515185418,   -285697463,    625853735,
-  1727305304,   2082316400,  -1364982363,    858240904,
-  1806278033,    222489249,   -346752664,    684667772,
-  1654287831,   -878576920,  -1257667336,   -748618599,
-   329347125,   1837364259,  -1443016191,  -1170414139,
- -1846138265,  -1631226336,  -1404529459,   1838055109,
-  1594295556,  -1076973523,  -1898723371,   -594436433,
-  -202001018,   -475984259,   -561427818,   1797021250,
- -1061813248,   2059733582,  -1661512036,  -1104976546,
- -1750224322,   -901666089,    418987550,   1831915354,
- -1925356481,    992097816,    879957085,   2024403852,
-  1484874664,  -1636082790,   -285388938,  -1983539117,
- -1495136972,   -950076367,  -1714807468,   -952438994,
- -1574918426,   -654783358,   1350681040,  -1974159334,
- -2143979938,   1651689966,   1599739335,    140455868,
- -1285853322,  -1039411342,   -993005453,   1955560695,
- -1440787839,   1529189039,    568627425,  -2131021878,
-  -783134478,   -247357818,   -588790216,   1518161567,
-   289871780,    -86965172,  -1262003602,   1708872714,
-  2135294595,   1787797780,  -1018755524,   1638590968,
-  -889861154,   -120646188,   1665705315,  -1669960605,
-  1321868266,   -916321552,   1225434135,   1155548552,
- -1784632064,   2143745727,    666258756,   1210558298,
-   675310539,  -1261461889,  -1555941048,   -318346815,
- -1999506068,    628664288,  -1499481951,  -1729304567,
-  -695180180,   1422575625,  -1375177022,   1424130039,
-  1777179796,  -1185330463,    334803717,    235321234,
-  -178766299,    168022241,   -518252219,   1206536195,
-  1957047971,    985155485,   1146323032,   -894060583,
-     -898413,    991903578,   1363007700,    746144248,
- -1363460237,    912367099,     30313376,  -1420958685,
-  -605900043,    -44694137,   -326425359,   2032221021,
-  2027833505,   1176904445,   1683520343,   1904936415,
-    14253662,   -421552614,   -517299994,   1257750362,
-  1014493059,   -818371957,   2027935493,   1926727421,
-   863641634,   1747917559,  -1372618620,   1931587462,
-  1819892094,   -325927721,    128353683,   1258381763,
-  2124962073,    908452108,  -1123881662,    885133339,
- -1223601433,   1851023420,    137583815,   1629985060,
- -1920467227,  -1176751719,   -635454917,   1967222129,
- -1637785316,  -1354528380,   -642772911,      6363718,
- -1536588519,    -72690498,     45766801,  -1287922799,
-   694382730,   -314284737,    671509323,   1136965287,
-   235104447,    985022747,  -2070602177,   1779436848,
- -1045062171,    963438279,    419615363,   1116720495,
-   831969620,  -1078959975,   1216882041,   1042326958,
-  -300448763,    604552167,   -270590488,   1405999311,
-   756955445,  -1021949427,  -1276805127,    713994584,
-  -260312804,    608791571,    371462360,    940195360,
-  1554794073,    173440395,  -1357098057,  -1542497136,
-  1339088280,  -2126092136,   -384158533,   2061661096,
- -2040058689,  -1316619236,    827959816,   -883155599,
-  -853476187,  -1039370342,   -596344472,   1726753854,
- -2047270595,      6087993,    702390549,  -1547952704,
- -1723816713,   -110126091,   -279505433,    394851342,
- -1591599802,    565464272,   -260424529,    283780712,
-  -440824167,  -1758099916,    -71875109,    776003548,
-  1119856485,  -1600929360,  -1208667170,   1123958026,
-  1544891539,    879867910,  -1499603926,    201262506,
-   155290193,  -1809756372,   2036925263,   1934038752,
-  -973777462,    400711272,   -540420425,    374860238
-};
-
-static const int32_t neg_zetas_montgomery[256] = {
-     4186625,      8354570,      2608894,       518909,
-     8143293,       777960,       876248,      7913949,
-     6554070,      6026966,       359251,      2091905,
-     5260684,      2884855,      5268920,      5700314,
-     5654953,      7356305,      1079900,      4794489,
-      549488,      1119584,      5760665,      2108549,
-     2118186,      3859737,      1399561,      3277672,
-     6623180,        19422,      4369920,      8100412,
-     5674394,      8284641,      5303092,      4849980,
-     1661693,      3592148,      2537516,      4464978,
-     3861115,      3043716,      4805995,      2867647,
-     4840449,       300467,      6031717,       539299,
-     1699267,      1643818,      4874723,      3821735,
-     4873154,      2140649,      1600420,      4680821,
-     7568473,      7849063,      7426187,      4499374,
-     4479693,      2556880,      6308525,      2797779,
-     3930395,      1528703,      3677745,      3041255,
-     1452451,      4904467,      6203962,      1585221,
-     1257611,      6441103,      4083598,      1000202,
-     3190144,      3157330,      3632928,      8253495,
-     4968207,       983419,      6232521,      5665122,
-     2967645,      3693493,       411027,      2477047,
-      671102,      1228525,        22981,      1308169,
-      381987,      7031341,      6527646,      1430430,
-     3343383,      8115473,      7871466,      5282425,
-     8336129,      1100098,      7475901,      4421799,
-     3724342,         8578,      6727353,      3249728,
-     5991061,       210977,      7620448,      1316856,
-     8190869,      3553272,      5220671,      1851402,
-     2409325,       177440,      7064828,      7039087,
-     7094748,      1584928,       812732,      1439742,
-     3019102,      3881060,      3628969,      4540456,
-     6288750,      4972711,      6063917,      4562441,
-     3342478,      6136326,      2446433,      3562462,
-     8113420,      5945978,      1235728,      4867236,
-     3520352,      3759364,      1197226,      3193378,
-     7479715,      6521319,      7470875,      7561383,
-     7884926,      1613174,        43260,       522500,
-      655327,      3122442,      6348669,      5173371,
-     3556995,       525098,       768622,      3595838,
-     8038120,      8093429,      2437823,      4272102,
-     4943130,      3342277,      6644538,      8177373,
-     5538076,      5688936,      2590150,      7115408,
-     4325093,      7132797,      5894064,      6784443,
-     3767016,      7129923,      5744496,      3548272,
-     2994039,      6511298,      6476982,      1050970,
-     1333058,      7143142,      3318210,      1430225,
-      451100,      7067962,      5074302,      1962642,
-     1279661,      6463336,      2546312,      1374803,
-     6880252,      7603226,      6144537,      4974386,
-      542412,      2831860,      1671176,      1846953,
-     2584293,      3724270,      7786281,      3776993,
-     2013608,      5948022,      5925962,       164721,
-     6423145,      5011305,      8194886,      1207385,
-     3183426,      8217573,      6764025,      5366416,
-     7570268,      6727783,      3694233,      1799107,
-     3038916,      4856520,      4513516,      8110657,
-     6167306,       975884,      6662682,      7908339,
-      426683,      6656817,      1803090,      6470041,
-     1667432,      1104333,       260646,      3833893,
-     2939036,      2235985,       420899,      2286327,
-     8196974,       976891,      6767575,      3545687,
-      554416,      4460757,        48306,      1362209,
-     4442679,      6979993,       846154,      6403635
-};
-
-static const int32_t neg_zetas_montgomery_twisted[256] = {
-         513,  -1830765814,   1929875198,   1927777021,
- -1640767043,  -1477910808,  -1612161320,  -1640734243,
-  -308362794,   1815525078,   1374673747,   1091570561,
-  1929495948,   -515185417,    285697464,   -625853734,
- -1727305303,  -2082316399,   1364982364,   -858240903,
- -1806278032,   -222489248,    346752665,   -684667771,
- -1654287830,    878576921,   1257667337,    748618600,
-  -329347124,  -1837364258,   1443016192,   1170414140,
-  1846138266,   1631226337,   1404529460,  -1838055108,
- -1594295555,   1076973524,   1898723372,    594436434,
-   202001019,    475984260,    561427819,  -1797021249,
-  1061813249,  -2059733581,   1661512037,   1104976547,
-  1750224323,    901666090,   -418987549,  -1831915353,
-  1925356482,   -992097815,   -879957084,  -2024403851,
- -1484874663,   1636082791,    285388939,   1983539118,
-  1495136973,    950076368,   1714807469,    952438995,
-  1574918427,    654783359,  -1350681039,   1974159335,
-  2143979939,  -1651689965,  -1599739334,   -140455867,
-  1285853323,   1039411343,    993005454,  -1955560694,
-  1440787840,  -1529189038,   -568627424,   2131021879,
-   783134479,    247357819,    588790217,  -1518161566,
-  -289871779,     86965173,   1262003603,  -1708872713,
- -2135294594,  -1787797779,   1018755525,  -1638590967,
-   889861155,    120646189,  -1665705314,   1669960606,
- -1321868265,    916321553,  -1225434134,  -1155548551,
-  1784632065,  -2143745726,   -666258755,  -1210558297,
-  -675310538,   1261461890,   1555941049,    318346816,
-  1999506069,   -628664287,   1499481952,   1729304568,
-   695180181,  -1422575624,   1375177023,  -1424130038,
- -1777179795,   1185330464,   -334803716,   -235321233,
-   178766300,   -168022240,    518252220,  -1206536194,
- -1957047970,   -985155484,  -1146323031,    894060584,
-      898414,   -991903577,  -1363007699,   -746144247,
-  1363460238,   -912367098,    -30313375,   1420958686,
-   605900044,     44694138,    326425360,  -2032221020,
- -2027833504,  -1176904444,  -1683520342,  -1904936414,
-   -14253661,    421552615,    517299995,  -1257750361,
- -1014493058,    818371958,  -2027935492,  -1926727420,
-  -863641633,  -1747917558,   1372618621,  -1931587461,
- -1819892093,    325927722,   -128353682,  -1258381762,
- -2124962072,   -908452107,   1123881663,   -885133338,
-  1223601434,  -1851023419,   -137583814,  -1629985059,
-  1920467228,   1176751720,    635454918,  -1967222128,
-  1637785317,   1354528381,    642772912,     -6363717,
-  1536588520,     72690499,    -45766800,   1287922800,
-  -694382729,    314284738,   -671509322,  -1136965286,
-  -235104446,   -985022746,   2070602178,  -1779436847,
-  1045062172,   -963438278,   -419615362,  -1116720494,
-  -831969619,   1078959976,  -1216882040,  -1042326957,
-   300448764,   -604552166,    270590489,  -1405999310,
-  -756955444,   1021949428,   1276805128,   -713994583,
-   260312805,   -608791570,   -371462359,   -940195359,
- -1554794072,   -173440394,   1357098058,   1542497137,
- -1339088279,   2126092137,    384158534,  -2061661095,
-  2040058690,   1316619237,   -827959815,    883155600,
-   853476188,   1039370343,    596344473,  -1726753853,
-  2047270596,     -6087992,   -702390548,   1547952705,
-  1723816714,    110126092,    279505434,   -394851341,
-  1591599803,   -565464271,    260424530,   -283780711,
-   440824168,   1758099917,     71875110,   -776003547,
- -1119856484,   1600929361,   1208667171,  -1123958025,
- -1544891538,   -879867909,   1499603927,   -201262505,
-  -155290192,   1809756373,  -2036925262,  -1934038751,
-   973777463,   -400711271,    540420426,   -374860237
-};
-/* clang-format on */
-
-static const vec_int32_t vec_q = { ML_DSA_Q, ML_DSA_Q, ML_DSA_Q, ML_DSA_Q };
-static const vec_int32_t vec_q_inv = { ML_DSA_Q_INV, ML_DSA_Q_INV, ML_DSA_Q_INV, ML_DSA_Q_INV };
-
-/*
- * @brief Reduce a in (-q, q) to a mod q in [0, q).
- *
- * @param a in (-q, q)
- * @returns a mod q in [0, q)
- */
-static ossl_inline
-    vec_int32_t
-    reduce_once_signed(vec_int32_t a)
-{
-    /* mask is 11..11 when a is negative, else 0 */
-    vec_uint32_t mask = -(((vec_uint32_t)a) >> 31);
-    return a + (vec_int32_t)(mask & (vec_uint32_t)vec_q);
-}
-
-/*
- * @brief Reduce a in (-2q, q) to a mod q in [0, q).
- *
- * @param a in (-2q, q)
- * @returns a mod q in [0, q)
- */
-static ossl_inline
-    vec_int32_t
-    reduce_twice_signed(vec_int32_t a)
-{
-    /* mask is 11..11 when a is negative, else 0 */
-    vec_uint32_t mask = -(((vec_uint32_t)a) >> 31);
-    /* b is in (-q, q) */
-    vec_int32_t b = a + (vec_int32_t)(mask & (vec_uint32_t)vec_q);
-    return reduce_once_signed(b);
-}
-
-/*
- * @brief Computes the Montgomery product of a and b.
- *        See [Seiler 2018, Algorithm 3].
- *
- * @param a is the first factor, assumed to be in [0, q).
- * @param a_twist is (int32)((uint32)a * ML_DSA_Q_INV).
- * @param b is the second factor.
- * @returns The Montgomery product of a and b in the range
- *          [0, q).
- */
-
-static ossl_inline
-    vec_int32_t
-    montgomery_multiplication_vectorized(vec_int32_t a, vec_int32_t a_twist, vec_int32_t b)
-{
-    vec_uint32_t k = (vec_uint32_t)a_twist * (vec_uint32_t)b;
-    vec_uint32_t c_u = vec_mulh((vec_uint32_alias_t)k, (vec_uint32_alias_t)vec_q);
-    vec_int32_t c = (vec_int32_t)c_u;
-    vec_int32_t z_high = vec_mulh((vec_int32_alias_t)a, (vec_int32_alias_t)b);
-    vec_int32_t r = z_high - c;
-    return reduce_twice_signed(r);
-}
-
-/*
- * @brief Reduce modulo q to an non-negative vector.
- *        Note that the constant v_scalar equals
- *        floor(2**(floor(log_2(q))-1 * 2**32/q)).
- *
- * @param a in the range -2**31..2**31-1
- * @returns a mod q in the range 0..q-1
- */
-static ossl_inline
-    vec_int32_t
-    reduce_fully(vec_int32_t a)
-{
-    const int32_t v_scalar = 1074791296;
-    const vec_int32_alias_t v = { v_scalar, v_scalar, v_scalar, v_scalar };
-    vec_int32_t t = vec_mulh((vec_int32_alias_t)a, v) >> 21;
-    t *= ML_DSA_Q;
-    vec_int32_t r = a - t; /* in [0, q] */
-    return reduce_once_signed(r);
-}
-
-void ossl_poly_ntt_mult_scalar_vec128(const POLY *lhs, const POLY *rhs, POLY *out)
-{
-    int i;
-    const vec_int32_t *lhs_vec_ptr = (const vec_int32_t *)lhs->coeff;
-    const vec_int32_t *rhs_vec_ptr = (const vec_int32_t *)rhs->coeff;
-    vec_int32_t *out_vec_ptr = (vec_int32_t *)out->coeff;
-
-    for (i = 0; i < ML_DSA_NUM_POLY_COEFFICIENTS / NUM_INT32_IN_VECTOR; i++) {
-        vec_int32_t twist_vec = (vec_int32_t)((vec_uint32_t)lhs_vec_ptr[i] * (vec_uint32_t)vec_q_inv);
-        out_vec_ptr[i] = montgomery_multiplication_vectorized(
-            lhs_vec_ptr[i], twist_vec, rhs_vec_ptr[i]);
-    }
-}
-
-/*
- * In place number theoretic transform of a given polynomial.
- *
- * See FIPS 204, Algorithm 41, NTT()
- * This function uses montgomery multiplication.
- *
- * @param p a polynomial that is used as the input, that is replaced with
- *        the NTT of the polynomial
- */
-void ossl_ml_dsa_poly_ntt_vec128(POLY *p)
-{
-    int i, j, k;
-    int step;
-    int offset = ML_DSA_NUM_POLY_COEFFICIENTS;
-    vec_int32_t *p_vec = (vec_int32_t *)p->coeff;
-
-    /* Step: 1, 2, 4, 8, ..., 32 */
-    for (step = 1; step < ML_DSA_NUM_POLY_COEFFICIENTS / 4; step <<= 1) {
-        k = 0;
-        offset >>= 1; /* Offset: 128, 64, 32, 16, ..., 4 */
-
-        for (i = 0; i < step; i++) {
-            const vec_int32_t zeta = { zetas_montgomery[step + i],
-                zetas_montgomery[step + i],
-                zetas_montgomery[step + i],
-                zetas_montgomery[step + i] };
-            const vec_int32_t zeta_twisted = { zetas_montgomery_twisted[step + i],
-                zetas_montgomery_twisted[step + i],
-                zetas_montgomery_twisted[step + i],
-                zetas_montgomery_twisted[step + i] };
-
-            for (j = k; j < k + offset; j += NUM_INT32_IN_VECTOR) {
-                vec_int32_t w_even_vec = p_vec[j / NUM_INT32_IN_VECTOR];
-                vec_int32_t w_odd_vec = p_vec[(j + offset) / NUM_INT32_IN_VECTOR];
-                vec_int32_t t_odd_vec = montgomery_multiplication_vectorized(
-                    zeta,
-                    zeta_twisted,
-                    w_odd_vec);
-                vec_int32_t coeff_j_vec = (w_even_vec + t_odd_vec);
-                vec_int32_t coeff_j_offset_vec = (w_even_vec - t_odd_vec);
-                p_vec[j / NUM_INT32_IN_VECTOR] = coeff_j_vec;
-                p_vec[(j + offset) / NUM_INT32_IN_VECTOR] = coeff_j_offset_vec;
-            }
-            k += 2 * offset;
-        }
-    }
-
-    /* offset == 2*/
-    k = 0;
-    step = 64;
-    offset = 2;
-    for (j = 0; j < ML_DSA_NUM_POLY_COEFFICIENTS; j += 2 * NUM_INT32_IN_VECTOR) {
-        const vec_int32_t zeta = {
-            zetas_montgomery[step + j / NUM_INT32_IN_VECTOR],
-            zetas_montgomery[step + j / NUM_INT32_IN_VECTOR],
-            zetas_montgomery[step + j / NUM_INT32_IN_VECTOR + 1],
-            zetas_montgomery[step + j / NUM_INT32_IN_VECTOR + 1]
-        };
-        const vec_int32_t zeta_twisted = {
-            zetas_montgomery_twisted[step + j / NUM_INT32_IN_VECTOR],
-            zetas_montgomery_twisted[step + j / NUM_INT32_IN_VECTOR],
-            zetas_montgomery_twisted[step + j / NUM_INT32_IN_VECTOR + 1],
-            zetas_montgomery_twisted[step + j / NUM_INT32_IN_VECTOR + 1]
-        };
-
-        vec_int32_t w_even_vec = {
-            p_vec[j / NUM_INT32_IN_VECTOR][0],
-            p_vec[j / NUM_INT32_IN_VECTOR][1],
-            p_vec[j / NUM_INT32_IN_VECTOR + 1][0],
-            p_vec[j / NUM_INT32_IN_VECTOR + 1][1]
-        };
-        vec_int32_t w_odd_vec = {
-            p_vec[j / NUM_INT32_IN_VECTOR][2],
-            p_vec[j / NUM_INT32_IN_VECTOR][3],
-            p_vec[j / NUM_INT32_IN_VECTOR + 1][2],
-            p_vec[j / NUM_INT32_IN_VECTOR + 1][3]
-        };
-        vec_int32_t t_odd_vec = montgomery_multiplication_vectorized(
-            zeta,
-            zeta_twisted,
-            w_odd_vec);
-        vec_int32_t coeff_j_vec = (w_even_vec + t_odd_vec);
-        vec_int32_t coeff_j_offset_vec = (w_even_vec - t_odd_vec);
-        p_vec[j / NUM_INT32_IN_VECTOR] = (vec_int32_t) {
-            coeff_j_vec[0],
-            coeff_j_vec[1],
-            coeff_j_offset_vec[0],
-            coeff_j_offset_vec[1]
-        };
-        p_vec[j / NUM_INT32_IN_VECTOR + 1] = (vec_int32_t) {
-            coeff_j_vec[2],
-            coeff_j_vec[3],
-            coeff_j_offset_vec[2],
-            coeff_j_offset_vec[3]
-        };
-    }
-
-    /* offset == 1 */
-    k = 0;
-    step = 128;
-    for (i = 0; i < step; i += NUM_INT32_IN_VECTOR) {
-        const vec_int32_t zeta = {
-            zetas_montgomery[step + i],
-            zetas_montgomery[step + i + 1],
-            zetas_montgomery[step + i + 2],
-            zetas_montgomery[step + i + 3]
-        };
-        const vec_int32_t zeta_twisted = {
-            zetas_montgomery_twisted[step + i],
-            zetas_montgomery_twisted[step + i + 1],
-            zetas_montgomery_twisted[step + i + 2],
-            zetas_montgomery_twisted[step + i + 3]
-        };
-
-        vec_int32_t w_even_vec = {
-            p_vec[k / NUM_INT32_IN_VECTOR][0],
-            p_vec[k / NUM_INT32_IN_VECTOR][2],
-            p_vec[k / NUM_INT32_IN_VECTOR + 1][0],
-            p_vec[k / NUM_INT32_IN_VECTOR + 1][2]
-        };
-        vec_int32_t w_odd_vec = {
-            p_vec[k / NUM_INT32_IN_VECTOR][1],
-            p_vec[k / NUM_INT32_IN_VECTOR][3],
-            p_vec[k / NUM_INT32_IN_VECTOR + 1][1],
-            p_vec[k / NUM_INT32_IN_VECTOR + 1][3]
-        };
-        vec_int32_t t_odd_vec = montgomery_multiplication_vectorized(
-            zeta,
-            zeta_twisted,
-            w_odd_vec);
-        vec_int32_t coeff_j_vec = reduce_fully(w_even_vec + t_odd_vec);
-        vec_int32_t coeff_j_offset_vec = reduce_fully(w_even_vec - t_odd_vec);
-
-        p->coeff[k] = coeff_j_vec[0];
-        p->coeff[k + 2] = coeff_j_vec[1];
-        p->coeff[k + 4] = coeff_j_vec[2];
-        p->coeff[k + 6] = coeff_j_vec[3];
-        p->coeff[k + 1] = coeff_j_offset_vec[0];
-        p->coeff[k + 2 + 1] = coeff_j_offset_vec[1];
-        p->coeff[k + 4 + 1] = coeff_j_offset_vec[2];
-        p->coeff[k + 6 + 1] = coeff_j_offset_vec[3];
-
-        k += 2 * NUM_INT32_IN_VECTOR;
-    }
-}
-
-/*
- * @brief In place inverse number theoretic transform of a given polynomial.
- * See FIPS 204, Algorithm 42,  NTT^-1()
- *
- * @param p a polynomial that is used as the input, that is overwritten with
- *          the inverse of the NTT.
- */
-void ossl_ml_dsa_poly_ntt_inverse_vec128(POLY *p)
-{
-    /*
-     * Step: 128, 64, 32, 16, ..., 1
-     * Offset: 1, 2, 4, 8, ..., 128
-     */
-    int i, j, k, offset, step = ML_DSA_NUM_POLY_COEFFICIENTS;
-    /*
-     * The multiplicative inverse of 256 mod q, in Montgomery form is
-     * ((256^-1 mod q) * ((2^32 * 2^32) mod q)) mod q = (8347681 * 2365951) mod 8380417
-     */
-    static const int32_t inverse_degree_montgomery = 41978;
-    static const vec_int32_t vec_inverse_degree_montgomery = {
-        inverse_degree_montgomery,
-        inverse_degree_montgomery,
-        inverse_degree_montgomery,
-        inverse_degree_montgomery
-    };
-    static const int32_t inverse_degree_montgomery_twisted = -8395782;
-    static const vec_int32_t vec_inverse_degree_montgomery_twisted = {
-        inverse_degree_montgomery_twisted,
-        inverse_degree_montgomery_twisted,
-        inverse_degree_montgomery_twisted,
-        inverse_degree_montgomery_twisted
-    };
-
-    vec_int32_t *p_vec = (vec_int32_t *)p->coeff;
-
-    offset = 1;
-    step >>= 1;
-    k = 0;
-
-    for (i = 0; i < step; i += NUM_INT32_IN_VECTOR) {
-        /* offset == 1*/
-        const vec_int32_t zeta = { neg_zetas_montgomery[step + (step - 1 - i)],
-            neg_zetas_montgomery[step + (step - 1 - i - 1)],
-            neg_zetas_montgomery[step + (step - 1 - i - 2)],
-            neg_zetas_montgomery[step + (step - 1 - i - 3)] };
-        const vec_int32_t zeta_twisted = { neg_zetas_montgomery_twisted[step + (step - 1 - i)],
-            neg_zetas_montgomery_twisted[step + (step - 1 - i - 1)],
-            neg_zetas_montgomery_twisted[step + (step - 1 - i - 2)],
-            neg_zetas_montgomery_twisted[step + (step - 1 - i - 3)] };
-        vec_int32_t even = { p->coeff[k],
-            p->coeff[k + 2],
-            p->coeff[k + 4],
-            p->coeff[k + 6] };
-        vec_int32_t odd = { p->coeff[k + 1],
-            p->coeff[k + 1 + 2],
-            p->coeff[k + 1 + 4],
-            p->coeff[k + 1 + 6] };
-
-        vec_int32_t coeff_j = (odd + even);
-        vec_int32_t coeff_j_offset = montgomery_multiplication_vectorized(
-            zeta,
-            zeta_twisted,
-            even - odd);
-
-        p->coeff[k + 0] = coeff_j[0];
-        p->coeff[k + 2] = coeff_j[1];
-        p->coeff[k + 4] = coeff_j[2];
-        p->coeff[k + 6] = coeff_j[3];
-        p->coeff[k + 1 + 0] = coeff_j_offset[0];
-        p->coeff[k + 1 + 2] = coeff_j_offset[1];
-        p->coeff[k + 1 + 4] = coeff_j_offset[2];
-        p->coeff[k + 1 + 6] = coeff_j_offset[3];
-
-        k += 2 * NUM_INT32_IN_VECTOR;
-    }
-
-    /* offset == 2 */
-    offset <<= 1;
-    step >>= 1;
-    k = 0;
-
-    for (i = 0; i < step; i += 2) {
-        const vec_int32_t zeta = { neg_zetas_montgomery[step + (step - 1 - i)],
-            neg_zetas_montgomery[step + (step - 1 - i)],
-            neg_zetas_montgomery[step + (step - 1 - i - 1)],
-            neg_zetas_montgomery[step + (step - 1 - i - 1)] };
-        const vec_int32_t zeta_twisted = { neg_zetas_montgomery_twisted[step + (step - 1 - i)],
-            neg_zetas_montgomery_twisted[step + (step - 1 - i)],
-            neg_zetas_montgomery_twisted[step + (step - 1 - i - 1)],
-            neg_zetas_montgomery_twisted[step + (step - 1 - i - 1)] };
-
-        j = k;
-        vec_int32_t even = { p->coeff[j],
-            p->coeff[j + 1],
-            p->coeff[j + 4],
-            p->coeff[j + 5] };
-        vec_int32_t odd = { p->coeff[j + 2],
-            p->coeff[j + 3],
-            p->coeff[j + 6],
-            p->coeff[j + 7] };
-
-        vec_int32_t coeff_j = (odd + even);
-        vec_int32_t coeff_j_offset = montgomery_multiplication_vectorized(
-            zeta,
-            zeta_twisted,
-            even - odd);
-
-        p_vec[j / NUM_INT32_IN_VECTOR] = (vec_int32_t) {
-            coeff_j[0],
-            coeff_j[1],
-            coeff_j_offset[0],
-            coeff_j_offset[1]
-        };
-        p_vec[j / NUM_INT32_IN_VECTOR + 1] = (vec_int32_t) {
-            coeff_j[2],
-            coeff_j[3],
-            coeff_j_offset[2],
-            coeff_j_offset[3]
-        };
-        k += 2 * 2 * offset;
-    }
-
-    /* offset >= 4 */
-    for (offset <<= 1; offset < ML_DSA_NUM_POLY_COEFFICIENTS; offset <<= 1) {
-        step >>= 1;
-        k = 0;
-
-        for (i = 0; i < step; i++) {
-            const vec_int32_t zeta = { neg_zetas_montgomery[step + (step - 1 - i)],
-                neg_zetas_montgomery[step + (step - 1 - i)],
-                neg_zetas_montgomery[step + (step - 1 - i)],
-                neg_zetas_montgomery[step + (step - 1 - i)] };
-            const vec_int32_t zeta_twisted = { neg_zetas_montgomery_twisted[step + (step - 1 - i)],
-                neg_zetas_montgomery_twisted[step + (step - 1 - i)],
-                neg_zetas_montgomery_twisted[step + (step - 1 - i)],
-                neg_zetas_montgomery_twisted[step + (step - 1 - i)] };
-
-            for (j = k; j < k + offset; j += NUM_INT32_IN_VECTOR) {
-                vec_int32_t even = p_vec[j / NUM_INT32_IN_VECTOR];
-                vec_int32_t odd = p_vec[(j + offset) / NUM_INT32_IN_VECTOR];
-
-                vec_int32_t coeff_j = (odd + even);
-                vec_int32_t coeff_j_offset = montgomery_multiplication_vectorized(
-                    zeta,
-                    zeta_twisted,
-                    even - odd);
-                p_vec[j / NUM_INT32_IN_VECTOR] = coeff_j;
-                p_vec[(j + offset) / NUM_INT32_IN_VECTOR] = coeff_j_offset;
-            }
-            k += 2 * offset;
-        }
-    }
-
-    for (i = 0; i < ML_DSA_NUM_POLY_COEFFICIENTS / NUM_INT32_IN_VECTOR; i += 1) {
-        p_vec[i] = montgomery_multiplication_vectorized(
-            vec_inverse_degree_montgomery,
-            vec_inverse_degree_montgomery_twisted,
-            p_vec[i]);
-    }
-}
-
-#endif
diff --git a/crypto/ml_dsa/ml_dsa_poly.h b/crypto/ml_dsa/ml_dsa_poly.h
index 7998fdd9c1..5edc11be80 100644
--- a/crypto/ml_dsa/ml_dsa_poly.h
+++ b/crypto/ml_dsa/ml_dsa_poly.h
@@ -6,23 +6,13 @@
  * in the file LICENSE in the source distribution or at
  * https://www.openssl.org/source/license.html
  */
-#if !defined(OSSL_LIBCRYPTO_ML_DSA_ML_DSA_POLY_H)
-#define OSSL_LIBCRYPTO_ML_DSA_ML_DSA_POLY_H
-
 #include 
 
-#include "internal/common.h"
-#include "ml_dsa_local.h"
-
 #define ML_DSA_NUM_POLY_COEFFICIENTS 256
 
 /* Polynomial object with 256 coefficients. The coefficients are unsigned 32 bits */
 struct poly_st {
-#if defined(VX_COMPILER_SUPPORT_VEC128)
-    ALIGN16 uint32_t coeff[ML_DSA_NUM_POLY_COEFFICIENTS];
-#else
     uint32_t coeff[ML_DSA_NUM_POLY_COEFFICIENTS];
-#endif
 };
 
 static ossl_inline ossl_unused void
@@ -192,5 +182,3 @@ poly_max_signed(const POLY *p, uint32_t *mx)
         *mx = maximum(*mx, abs);
     }
 }
-
-#endif /* !defined(OSSL_LIBCRYPTO_ML_DSA_ML_DSA_POLY_H) */
diff --git a/crypto/ml_dsa/ml_dsa_sample.c b/crypto/ml_dsa/ml_dsa_sample.c
index afa09b7971..6fae4c4a0d 100644
--- a/crypto/ml_dsa/ml_dsa_sample.c
+++ b/crypto/ml_dsa/ml_dsa_sample.c
@@ -8,12 +8,10 @@
  */
 
 #include 
-#include 
 #include "ml_dsa_local.h"
 #include "ml_dsa_vector.h"
 #include "ml_dsa_matrix.h"
 #include "ml_dsa_hash.h"
-#include "internal/constant_time.h"
 #include "internal/sha3.h"
 #include "internal/packet.h"
 
@@ -36,10 +34,6 @@ typedef int(COEFF_FROM_NIBBLE_FUNC)(uint32_t nibble, uint32_t *out);
 static COEFF_FROM_NIBBLE_FUNC coeff_from_nibble_4;
 static COEFF_FROM_NIBBLE_FUNC coeff_from_nibble_2;
 
-static ML_DSA_MATRIX_EXPAND_A_FN matrix_expand_A_scalar;
-static ML_DSA_VECTOR_EXPAND_S_FN vector_expand_S_scalar;
-static ML_DSA_VECTOR_EXPAND_MASK_FN vector_expand_mask_scalar;
-
 /**
  * @brief Combine 3 bytes to form an coefficient.
  * See FIPS 204, Algorithm 14, CoeffFromThreeBytes()
@@ -165,14 +159,13 @@ static int rej_bounded_poly(EVP_MD_CTX *h_ctx, const EVP_MD *md,
     COEFF_FROM_NIBBLE_FUNC *coef_from_nibble,
     const uint8_t *seed, size_t seed_len, POLY *out)
 {
-    int ret = 0;
     int j = 0;
     uint32_t z0, z1;
     uint8_t blocks[SHAKE256_BLOCKSIZE], *b, *end = blocks + sizeof(blocks);
 
     /* Instead of just squeezing 1 byte at a time, we grab a whole block */
     if (!shake_xof(h_ctx, md, seed, seed_len, blocks, sizeof(blocks)))
-        goto err;
+        return 0;
 
     while (1) {
         for (b = blocks; b < end; b++) {
@@ -180,22 +173,15 @@ static int rej_bounded_poly(EVP_MD_CTX *h_ctx, const EVP_MD *md,
             z1 = *b >> 4; /* high nibble of byte */
 
             if (coef_from_nibble(z0, &out->coeff[j])
-                && ++j >= ML_DSA_NUM_POLY_COEFFICIENTS) {
-                ret = 1;
-                goto err;
-            }
+                && ++j >= ML_DSA_NUM_POLY_COEFFICIENTS)
+                return 1;
             if (coef_from_nibble(z1, &out->coeff[j])
-                && ++j >= ML_DSA_NUM_POLY_COEFFICIENTS) {
-                ret = 1;
-                goto err;
-            }
+                && ++j >= ML_DSA_NUM_POLY_COEFFICIENTS)
+                return 1;
         }
         if (!EVP_DigestSqueeze(h_ctx, blocks, sizeof(blocks)))
-            goto err;
+            return 0;
     }
-err:
-    OPENSSL_cleanse(blocks, sizeof(blocks));
-    return ret;
 }
 
 /**
@@ -211,7 +197,7 @@ err:
  *            in the range of 0..q-1.
  * @returns 1 if the matrix was generated, or 0 on error.
  */
-static int matrix_expand_A_scalar(EVP_MD_CTX *g_ctx, const EVP_MD *md,
+int ossl_ml_dsa_matrix_expand_A(EVP_MD_CTX *g_ctx, const EVP_MD *md,
     const uint8_t *rho, MATRIX *out)
 {
     int ret = 0;
@@ -221,6 +207,7 @@ static int matrix_expand_A_scalar(EVP_MD_CTX *g_ctx, const EVP_MD *md,
 
     /* The seed used for each matrix element is rho + column_index + row_index */
     memcpy(derived_seed, rho, ML_DSA_RHO_BYTES);
+
     for (i = 0; i < out->k; i++) {
         for (j = 0; j < out->l; j++) {
             derived_seed[ML_DSA_RHO_BYTES + 1] = (uint8_t)i;
@@ -253,7 +240,7 @@ err:
  *           the range (q-eta)..0..eta
  * @returns 1 if s1 and s2 were successfully generated, or 0 otherwise.
  */
-static int vector_expand_S_scalar(EVP_MD_CTX *h_ctx, const EVP_MD *md, int eta,
+int ossl_ml_dsa_vector_expand_S(EVP_MD_CTX *h_ctx, const EVP_MD *md, int eta,
     const uint8_t *seed, VECTOR *s1, VECTOR *s2)
 {
     int ret = 0;
@@ -287,7 +274,6 @@ static int vector_expand_S_scalar(EVP_MD_CTX *h_ctx, const EVP_MD *md, int eta,
     }
     ret = 1;
 err:
-    OPENSSL_cleanse(derived_seed, sizeof(derived_seed));
     return ret;
 }
 
@@ -298,11 +284,9 @@ int ossl_ml_dsa_poly_expand_mask(POLY *out, const uint8_t *seed, size_t seed_len
 {
     uint8_t buf[32 * 20];
     size_t buf_len = 32 * (gamma1 == ML_DSA_GAMMA1_TWO_POWER_19 ? 20 : 18);
-    int ret = shake_xof(h_ctx, md, seed, seed_len, buf, buf_len)
-        && ossl_ml_dsa_poly_decode_expand_mask(out, buf, buf_len, gamma1);
 
-    OPENSSL_cleanse(buf, sizeof(buf));
-    return ret;
+    return shake_xof(h_ctx, md, seed, seed_len, buf, buf_len)
+        && ossl_ml_dsa_poly_decode_expand_mask(out, buf, buf_len, gamma1);
 }
 
 /*
@@ -341,23 +325,6 @@ int ossl_ml_dsa_poly_sample_in_ball(POLY *out_c, const uint8_t *seed, int seed_l
      */
     OPENSSL_load_u64_le(&signs, block);
 
-    /*
-     * SampleInBall implements a Fisher-Yates shuffle whose rejection-sampling
-     * inner loop and data-dependent array index unavoidably leak the structure
-     * of the challenge polynomial via memory-access pattern and branch timing.
-     * This is safe: c_tilde = H(mu ‖ w1) is the Fiat-Shamir commitment and is
-     * published in the accepted signature, so the SHAKE bytes that build c are
-     * effectively public.  See the BoringSSL design discussion at
-     * https://boringssl-review.googlesource.com/c/boringssl/+/67747/comment/8d8f01ac_70af3f21/
-     *
-     * The first 8 bytes (the sign bits loaded into |signs| above) are left
-     * tainted: they determine only the ±1 values written into c, which flow
-     * into the CT arithmetic of cs1/cs2/ct0 alongside the already-tainted
-     * secret polynomials and cause no spurious violations there.
-     * Only the rejection-sampling bytes need to be declassified.
-     */
-    CONSTTIME_DECLASSIFY(block + offset, sizeof(block) - offset);
-
     poly_zero(out_c);
 
     /* Loop tau times */
@@ -370,8 +337,6 @@ int ossl_ml_dsa_poly_sample_in_ball(POLY *out_c, const uint8_t *seed, int seed_l
                 /* squeeze another block if the bytes from block have been used */
                 if (!EVP_DigestSqueeze(h_ctx, block, sizeof(block)))
                     return 0;
-                /* See comment above for why the block is declassified. */
-                CONSTTIME_DECLASSIFY(block, sizeof(block));
                 offset = 0;
             }
 
@@ -391,46 +356,3 @@ int ossl_ml_dsa_poly_sample_in_ball(POLY *out_c, const uint8_t *seed, int seed_l
     }
     return 1;
 }
-
-static void vector_expand_mask_scalar(VECTOR *out,
-    const uint8_t rho_prime[ML_DSA_RHO_PRIME_BYTES], uint32_t kappa, uint32_t gamma1,
-    EVP_MD_CTX *h_ctx, const EVP_MD *md)
-{
-    size_t i;
-    uint8_t derived_seed[ML_DSA_RHO_PRIME_BYTES + 2];
-
-    memcpy(derived_seed, rho_prime, ML_DSA_RHO_PRIME_BYTES);
-
-    for (i = 0; i < out->num_poly; i++) {
-        size_t index = kappa + i;
-
-        derived_seed[ML_DSA_RHO_PRIME_BYTES] = index & 0xFF;
-        derived_seed[ML_DSA_RHO_PRIME_BYTES + 1] = (index >> 8) & 0xFF;
-        poly_expand_mask(out->poly + i, derived_seed, sizeof(derived_seed),
-            gamma1, h_ctx, md);
-    }
-    OPENSSL_cleanse(derived_seed, sizeof(derived_seed));
-}
-
-static const OSSL_ML_DSA_SAMPLE_OPS ml_dsa_sample_generic_meth = {
-    matrix_expand_A_scalar,
-    vector_expand_S_scalar,
-    vector_expand_mask_scalar
-};
-
-#if defined(KECCAK1600_ASM)                                                               \
-    && (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)) \
-    && !defined(OPENSSL_NO_ASM)
-#include "ml_dsa_sample_hw_x86_64.inc"
-const OSSL_ML_DSA_SAMPLE_OPS *ossl_ml_dsa_sample_ops(void)
-{
-    if (SHA3_avx512vl_capable())
-        return &ml_dsa_sample_x86_64;
-    return &ml_dsa_sample_generic_meth;
-}
-#else
-const OSSL_ML_DSA_SAMPLE_OPS *ossl_ml_dsa_sample_ops(void)
-{
-    return &ml_dsa_sample_generic_meth;
-}
-#endif
diff --git a/crypto/ml_dsa/ml_dsa_sample_hw_x86_64.inc b/crypto/ml_dsa/ml_dsa_sample_hw_x86_64.inc
deleted file mode 100644
index fcf5f03323..0000000000
--- a/crypto/ml_dsa/ml_dsa_sample_hw_x86_64.inc
+++ /dev/null
@@ -1,307 +0,0 @@
-/*
- * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved.
- * Copyright (c) 2026 Intel Corporation. All Rights Reserved.
- *
- * Licensed under the Apache License 2.0 (the "License").  You may not use
- * this file except in compliance with the License.  You can obtain a copy
- * in the file LICENSE in the source distribution or at
- * https://www.openssl.org/source/license.html
- */
-
-#define ML_DSA_SHAKE_X4_BATCH_SIZE 4
-#define ML_DSA_SHAKE_X4_DONE_MASK ((1 << ML_DSA_SHAKE_X4_BATCH_SIZE) - 1)
-#define ML_DSA_EXPAND_MASK_BYTES_PER_COEFF 32
-#define ML_DSA_EXPAND_MASK_COEFFS_GAMMA1_19 20
-#define ML_DSA_EXPAND_MASK_COEFFS_GAMMA1_17 18
-#define ML_DSA_EXPAND_MASK_BUF_SIZE_GAMMA1_19 \
-    (ML_DSA_EXPAND_MASK_BYTES_PER_COEFF * ML_DSA_EXPAND_MASK_COEFFS_GAMMA1_19)
-#define ML_DSA_EXPAND_MASK_BUF_SIZE_GAMMA1_17 \
-    (ML_DSA_EXPAND_MASK_BYTES_PER_COEFF * ML_DSA_EXPAND_MASK_COEFFS_GAMMA1_17)
-#define ML_DSA_EXPAND_MASK_BUF_SIZE(gamma1)         \
-    ((gamma1) == ML_DSA_GAMMA1_TWO_POWER_19         \
-            ? ML_DSA_EXPAND_MASK_BUF_SIZE_GAMMA1_19 \
-            : ML_DSA_EXPAND_MASK_BUF_SIZE_GAMMA1_17)
-
-static ossl_unused int rej_ntt_poly_mb(const uint8_t *seeds[ML_DSA_SHAKE_X4_BATCH_SIZE],
-    const size_t seed_len, POLY *outs[ML_DSA_SHAKE_X4_BATCH_SIZE], const size_t count)
-{
-    KECCAK1600_X4_AVX512VL_CTX ctx;
-    uint8_t blocks[ML_DSA_SHAKE_X4_BATCH_SIZE][SHAKE128_BLOCKSIZE];
-    int coeff_idx[ML_DSA_SHAKE_X4_BATCH_SIZE] = { 0, 0, 0, 0 };
-    size_t done_mask = 0;
-    size_t lane;
-
-    for (lane = count; lane < ML_DSA_SHAKE_X4_BATCH_SIZE; lane++)
-        done_mask |= ((size_t)1 << lane);
-
-    ossl_sha3_shake128_x4_inc_init_avx512vl(&ctx);
-    ossl_sha3_shake128_x4_inc_absorb_avx512vl(&ctx, seeds[0], seeds[1],
-        seeds[2], seeds[3], seed_len);
-
-    while (done_mask != ML_DSA_SHAKE_X4_DONE_MASK) {
-        ossl_sha3_shake128_x4_inc_squeeze_avx512vl(blocks[0], blocks[1],
-            blocks[2], blocks[3], SHAKE128_BLOCKSIZE, &ctx);
-
-        for (lane = 0; lane < ML_DSA_SHAKE_X4_BATCH_SIZE; lane++) {
-            if (done_mask & ((size_t)1 << lane))
-                continue;
-
-            const uint8_t *b = blocks[lane];
-            const uint8_t *end = b + SHAKE128_BLOCKSIZE;
-
-            for (; b < end && coeff_idx[lane] < ML_DSA_NUM_POLY_COEFFICIENTS; b += 3) {
-                uint32_t *coeff_ptr = &(outs[lane]->coeff[coeff_idx[lane]]);
-
-                if (coeff_from_three_bytes(b, coeff_ptr))
-                    coeff_idx[lane]++;
-            }
-
-            if (coeff_idx[lane] >= ML_DSA_NUM_POLY_COEFFICIENTS)
-                done_mask |= ((size_t)1 << lane);
-        }
-    }
-
-    return 1;
-}
-
-static void vector_expand_mask_mb(VECTOR *out,
-    const uint8_t rho_prime[ML_DSA_RHO_PRIME_BYTES], const uint32_t kappa, const uint32_t gamma1,
-    EVP_MD_CTX *h_ctx, const EVP_MD *md)
-{
-    size_t i;
-    const size_t num_polys = out->num_poly;
-    uint8_t derived_seeds[ML_DSA_SHAKE_X4_BATCH_SIZE][ML_DSA_RHO_PRIME_BYTES + 2];
-    const size_t seed_len = sizeof(derived_seeds[0]);
-    const size_t buf_size = ML_DSA_EXPAND_MASK_BUF_SIZE(gamma1);
-    uint8_t buffers[ML_DSA_SHAKE_X4_BATCH_SIZE][ML_DSA_EXPAND_MASK_BUF_SIZE_GAMMA1_19];
-
-    (void)h_ctx;
-    (void)md;
-
-    for (i = 0; i < ML_DSA_SHAKE_X4_BATCH_SIZE; i++)
-        memcpy(derived_seeds[i], rho_prime, ML_DSA_RHO_PRIME_BYTES);
-
-    for (i = 0; i + (ML_DSA_SHAKE_X4_BATCH_SIZE - 1) < num_polys; i += ML_DSA_SHAKE_X4_BATCH_SIZE) {
-        size_t b;
-
-        for (b = 0; b < ML_DSA_SHAKE_X4_BATCH_SIZE; b++) {
-            const size_t index = kappa + i + b;
-
-            derived_seeds[b][ML_DSA_RHO_PRIME_BYTES] = index & 0xFF;
-            derived_seeds[b][ML_DSA_RHO_PRIME_BYTES + 1] = (index >> 8) & 0xFF;
-        }
-
-        ossl_sha3_shake256_x4_avx512vl(buffers[0], buffers[1], buffers[2], buffers[3], buf_size,
-            derived_seeds[0], derived_seeds[1], derived_seeds[2], derived_seeds[3], seed_len);
-
-        ossl_ml_dsa_poly_decode_expand_mask(&out->poly[i + 0], buffers[0], buf_size, gamma1);
-        ossl_ml_dsa_poly_decode_expand_mask(&out->poly[i + 1], buffers[1], buf_size, gamma1);
-        ossl_ml_dsa_poly_decode_expand_mask(&out->poly[i + 2], buffers[2], buf_size, gamma1);
-        ossl_ml_dsa_poly_decode_expand_mask(&out->poly[i + 3], buffers[3], buf_size, gamma1);
-    }
-
-    /*
-     * num_polys is always 4 (ML-DSA-44), 5 (ML-DSA-65), or 7 (ML-DSA-87), so the
-     * above loops will always runs at least once, initializing derived_seeds.
-     * As a result, 'left' below will be 0, 1, or 3, meaning the 4 way shake will
-     * recalculate values that are not used.
-     */
-    if (i < num_polys) {
-        const size_t left = num_polys - i;
-        size_t b;
-
-        for (b = 0; b < left; b++) {
-            const size_t index = kappa + i + b;
-
-            derived_seeds[b][ML_DSA_RHO_PRIME_BYTES] = (uint8_t)index;
-            derived_seeds[b][ML_DSA_RHO_PRIME_BYTES + 1] = (uint8_t)(index >> 8);
-        }
-
-        ossl_sha3_shake256_x4_avx512vl(buffers[0], buffers[1], buffers[2], buffers[3], buf_size,
-            derived_seeds[0], derived_seeds[1], derived_seeds[2], derived_seeds[3], seed_len);
-
-        ossl_ml_dsa_poly_decode_expand_mask(&out->poly[i + 0], buffers[0], buf_size, gamma1);
-
-        if ((i + 1) < num_polys)
-            ossl_ml_dsa_poly_decode_expand_mask(&out->poly[i + 1], buffers[1], buf_size, gamma1);
-
-        if ((i + 2) < num_polys)
-            ossl_ml_dsa_poly_decode_expand_mask(&out->poly[i + 2], buffers[2], buf_size, gamma1);
-    }
-
-    OPENSSL_cleanse(buffers, sizeof(buffers));
-    OPENSSL_cleanse(derived_seeds, sizeof(derived_seeds));
-}
-
-static ossl_unused int rej_bounded_poly_mb(COEFF_FROM_NIBBLE_FUNC *coef_from_nibble,
-    const uint8_t *seeds[ML_DSA_SHAKE_X4_BATCH_SIZE], const size_t seed_len,
-    POLY *outs[ML_DSA_SHAKE_X4_BATCH_SIZE], const size_t count)
-{
-    KECCAK1600_X4_AVX512VL_CTX ctx;
-    uint8_t blocks[ML_DSA_SHAKE_X4_BATCH_SIZE][SHAKE256_BLOCKSIZE];
-    int coeff_idx[ML_DSA_SHAKE_X4_BATCH_SIZE] = { 0, 0, 0, 0 };
-    size_t done_mask = 0;
-    size_t lane;
-
-    for (lane = count; lane < ML_DSA_SHAKE_X4_BATCH_SIZE; lane++)
-        done_mask |= ((size_t)1 << lane);
-
-    ossl_sha3_shake256_x4_inc_init_avx512vl(&ctx);
-    ossl_sha3_shake256_x4_inc_absorb_avx512vl(&ctx, seeds[0], seeds[1],
-        seeds[2], seeds[3], seed_len);
-
-    while (done_mask != ML_DSA_SHAKE_X4_DONE_MASK) {
-        ossl_sha3_shake256_x4_inc_squeeze_avx512vl(blocks[0], blocks[1],
-            blocks[2], blocks[3], SHAKE256_BLOCKSIZE, &ctx);
-
-        for (lane = 0; lane < ML_DSA_SHAKE_X4_BATCH_SIZE; lane++) {
-            if (done_mask & ((size_t)1 << lane))
-                continue;
-
-            const uint8_t *b = blocks[lane];
-            const uint8_t *end = b + SHAKE256_BLOCKSIZE;
-
-            for (; b < end && coeff_idx[lane] < ML_DSA_NUM_POLY_COEFFICIENTS; b++) {
-                uint32_t z0 = *b & 0x0F;
-                uint32_t z1 = *b >> 4;
-
-                if (coef_from_nibble(z0, &outs[lane]->coeff[coeff_idx[lane]]))
-                    coeff_idx[lane]++;
-
-                if (coeff_idx[lane] >= ML_DSA_NUM_POLY_COEFFICIENTS) {
-                    done_mask |= ((size_t)1 << lane);
-                    break;
-                }
-
-                if (coef_from_nibble(z1, &outs[lane]->coeff[coeff_idx[lane]]))
-                    coeff_idx[lane]++;
-
-                if (coeff_idx[lane] >= ML_DSA_NUM_POLY_COEFFICIENTS) {
-                    done_mask |= ((size_t)1 << lane);
-                    break;
-                }
-            }
-        }
-    }
-
-    OPENSSL_cleanse(blocks, sizeof(blocks));
-    ossl_sha3_shake256_x4_inc_cleanup_avx512vl(&ctx);
-    return 1;
-}
-
-static int matrix_expand_A_mb(EVP_MD_CTX *g_ctx, const EVP_MD *md,
-    const uint8_t *rho, MATRIX *out)
-{
-    size_t b, idx;
-    uint8_t derived_seeds[ML_DSA_SHAKE_X4_BATCH_SIZE][ML_DSA_RHO_BYTES + 2];
-    const size_t seed_len = sizeof(derived_seeds[0]);
-    const uint8_t *seeds[ML_DSA_SHAKE_X4_BATCH_SIZE];
-    POLY *polys[ML_DSA_SHAKE_X4_BATCH_SIZE];
-    POLY *poly = out->m_poly;
-
-    for (b = 0; b < ML_DSA_SHAKE_X4_BATCH_SIZE; b++) {
-        memcpy(derived_seeds[b], rho, ML_DSA_RHO_BYTES);
-        seeds[b] = derived_seeds[b];
-    }
-
-    for (idx = 0; (idx + ML_DSA_SHAKE_X4_BATCH_SIZE - 1) < (out->k * out->l);
-         idx += ML_DSA_SHAKE_X4_BATCH_SIZE) {
-        for (b = 0; b < ML_DSA_SHAKE_X4_BATCH_SIZE; b++) {
-            const size_t row = (idx + b) / out->l;
-            const size_t col = (idx + b) % out->l;
-
-            derived_seeds[b][ML_DSA_RHO_BYTES] = (uint8_t)col;
-            derived_seeds[b][ML_DSA_RHO_BYTES + 1] = (uint8_t)row;
-            polys[b] = &poly[idx + b];
-        }
-
-        if (!rej_ntt_poly_mb(seeds, seed_len, polys, 4))
-            return 0;
-    }
-
-    if (idx < (out->k * out->l)) {
-        const size_t left = (out->k * out->l) - idx;
-
-        for (b = 0; b < left; b++) {
-            const size_t row = (idx + b) / out->l;
-            const size_t col = (idx + b) % out->l;
-
-            derived_seeds[b][ML_DSA_RHO_BYTES] = (uint8_t)col;
-            derived_seeds[b][ML_DSA_RHO_BYTES + 1] = (uint8_t)row;
-            polys[b] = &poly[idx + b];
-        }
-
-        if (!rej_ntt_poly_mb(seeds, seed_len, polys, left))
-            return 0;
-    }
-
-    return 1;
-}
-
-static int vector_expand_S_mb(EVP_MD_CTX *h_ctx, const EVP_MD *md, const int eta,
-    const uint8_t *seed, VECTOR *s1, VECTOR *s2)
-{
-    int ret = 0;
-    size_t b, idx;
-    const size_t l = s1->num_poly;
-    const size_t total = l + s2->num_poly;
-    uint8_t derived_seeds[ML_DSA_SHAKE_X4_BATCH_SIZE][ML_DSA_PRIV_SEED_BYTES + 2];
-    const uint8_t *seeds[ML_DSA_SHAKE_X4_BATCH_SIZE];
-    const size_t seed_len = sizeof(derived_seeds[0]);
-    POLY *polys[ML_DSA_SHAKE_X4_BATCH_SIZE];
-    COEFF_FROM_NIBBLE_FUNC *coef_from_nibble_fn = (eta == ML_DSA_ETA_4) ? coeff_from_nibble_4 : coeff_from_nibble_2;
-
-    for (b = 0; b < ML_DSA_SHAKE_X4_BATCH_SIZE; b++) {
-        memcpy(derived_seeds[b], seed, ML_DSA_PRIV_SEED_BYTES);
-        seeds[b] = derived_seeds[b];
-    }
-
-    for (idx = 0; (idx + ML_DSA_SHAKE_X4_BATCH_SIZE - 1) < total; idx += ML_DSA_SHAKE_X4_BATCH_SIZE) {
-        for (b = 0; b < ML_DSA_SHAKE_X4_BATCH_SIZE; b++) {
-            const size_t poly_idx = idx + b;
-
-            derived_seeds[b][ML_DSA_PRIV_SEED_BYTES] = (uint8_t)(poly_idx);
-            derived_seeds[b][ML_DSA_PRIV_SEED_BYTES + 1] = (uint8_t)(poly_idx >> 8);
-
-            if (poly_idx < l)
-                polys[b] = &s1->poly[poly_idx];
-            else
-                polys[b] = &s2->poly[poly_idx - l];
-        }
-
-        if (!rej_bounded_poly_mb(coef_from_nibble_fn,
-                seeds, seed_len, polys, ML_DSA_SHAKE_X4_BATCH_SIZE))
-            goto err;
-    }
-
-    if (idx < total) {
-        const size_t batch_count = total - idx;
-
-        for (b = 0; b < batch_count; b++) {
-            const size_t poly_idx = idx + b;
-
-            derived_seeds[b][ML_DSA_PRIV_SEED_BYTES] = (uint8_t)(poly_idx);
-            derived_seeds[b][ML_DSA_PRIV_SEED_BYTES + 1] = (uint8_t)(poly_idx >> 8);
-
-            if (poly_idx < l)
-                polys[b] = &s1->poly[poly_idx];
-            else
-                polys[b] = &s2->poly[poly_idx - l];
-        }
-
-        if (!rej_bounded_poly_mb(coef_from_nibble_fn,
-                seeds, seed_len, polys, batch_count))
-            goto err;
-    }
-
-    ret = 1;
-err:
-    OPENSSL_cleanse(derived_seeds, sizeof(derived_seeds));
-    return ret;
-}
-
-static const OSSL_ML_DSA_SAMPLE_OPS ml_dsa_sample_x86_64 = {
-    matrix_expand_A_mb,
-    vector_expand_S_mb,
-    vector_expand_mask_mb
-};
diff --git a/crypto/ml_dsa/ml_dsa_sign.c b/crypto/ml_dsa/ml_dsa_sign.c
index 62dfd08d53..21946ab2be 100644
--- a/crypto/ml_dsa/ml_dsa_sign.c
+++ b/crypto/ml_dsa/ml_dsa_sign.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -14,7 +14,6 @@
 #include 
 #include 
 #include "internal/common.h"
-#include "internal/constant_time.h"
 #include "ml_dsa_local.h"
 #include "ml_dsa_key.h"
 #include "ml_dsa_matrix.h"
@@ -66,29 +65,32 @@ static void signature_init(ML_DSA_SIG *sig,
  * @param ctx_len The size of |ctx|. It must be in the range 0..255
  * @returns an EVP_MD_CTX if the operation is successful, NULL otherwise.
  */
-EVP_MD_CTX *ossl_ml_dsa_mu_init_int(EVP_MD *shake256_md,
-    const uint8_t *tr, size_t tr_len, int encode, int prehash,
+
+EVP_MD_CTX *ossl_ml_dsa_mu_init(const ML_DSA_KEY *key, int encode,
     const uint8_t *ctx, size_t ctx_len)
 {
     EVP_MD_CTX *md_ctx;
     uint8_t itb[2];
 
+    if (key == NULL)
+        return NULL;
+
     md_ctx = EVP_MD_CTX_new();
     if (md_ctx == NULL)
         return NULL;
 
     /* H(.. */
-    if (!EVP_DigestInit_ex2(md_ctx, shake256_md, NULL))
+    if (!EVP_DigestInit_ex2(md_ctx, key->shake256_md, NULL))
         goto err;
     /* ..pk (= key->tr) */
-    if (!EVP_DigestUpdate(md_ctx, tr, tr_len))
+    if (!EVP_DigestUpdate(md_ctx, key->tr, sizeof(key->tr)))
         goto err;
     /* M' = .. */
     if (encode) {
         if (ctx_len > ML_DSA_MAX_CONTEXT_STRING_LEN)
             goto err;
         /* IntegerToBytes(0, 1) .. */
-        itb[0] = prehash ? 1 : 0;
+        itb[0] = 0;
         /* || IntegerToBytes(|ctx|, 1) || .. */
         itb[1] = (uint8_t)ctx_len;
         if (!EVP_DigestUpdate(md_ctx, itb, 2))
@@ -106,15 +108,6 @@ err:
     return NULL;
 }
 
-EVP_MD_CTX *ossl_ml_dsa_mu_init(const ML_DSA_KEY *key, int encode,
-    const uint8_t *ctx, size_t ctx_len)
-{
-    if (key == NULL)
-        return NULL;
-    return ossl_ml_dsa_mu_init_int(key->shake256_md, key->tr, sizeof(key->tr),
-        encode, 0, ctx, ctx_len);
-}
-
 /*
  * @brief: updates the internal ML-DSA hash with an additional message chunk.
  *
@@ -160,23 +153,21 @@ int ossl_ml_dsa_mu_finalize(EVP_MD_CTX *md_ctx, uint8_t *mu, size_t mu_len)
  * @returns 1 on success, 0 on error
  */
 static int ml_dsa_sign_internal(const ML_DSA_KEY *priv,
-    const uint8_t *mu, size_t mu_len, const uint8_t *rnd, size_t rnd_len,
+    const uint8_t *mu, size_t mu_len,
+    const uint8_t *rnd, size_t rnd_len,
     uint8_t *out_sig)
 {
     int ret = 0;
-    const OSSL_ML_DSA_SAMPLE_OPS *sample_ops = ossl_ml_dsa_sample_ops();
     const ML_DSA_PARAMS *params = priv->params;
     EVP_MD_CTX *md_ctx = NULL;
     uint32_t k = (uint32_t)params->k, l = (uint32_t)params->l;
     uint32_t gamma1 = params->gamma1, gamma2 = params->gamma2;
-    uint8_t *alloc = NULL, *w1_encoded = NULL;
-    void *alloc_freeptr = NULL;
+    uint8_t *alloc = NULL, *w1_encoded;
     size_t alloc_len, w1_encoded_len;
     size_t num_polys_sig_k = 2 * k;
     size_t num_polys_k = 5 * k;
     size_t num_polys_l = 3 * l;
     size_t num_polys_k_by_l = k * l;
-    size_t poly_count;
     POLY *p, *c_ntt;
     VECTOR s1_ntt, s2_ntt, t0_ntt, w, w1, cs1, cs2, y;
     MATRIX a_ntt;
@@ -191,25 +182,23 @@ static int ml_dsa_sign_internal(const ML_DSA_KEY *priv,
         return 0;
     }
 
-    /* Allocate w1_encoded buffer */
+    /*
+     * Allocate a single blob for most of the variable size temporary variables.
+     * Mostly used for VECTOR POLYNOMIALS (every POLY is 1K).
+     */
     w1_encoded_len = k * (gamma2 == ML_DSA_GAMMA2_Q_MINUS1_DIV88 ? 192 : 128);
-    w1_encoded = OPENSSL_malloc(w1_encoded_len);
-    if (w1_encoded == NULL)
-        return 0;
-
-    /* Allocate aligned POLY array */
-    poly_count = 1 + num_polys_k + num_polys_l + num_polys_k_by_l + num_polys_sig_k;
-    alloc_len = sizeof(*p) * poly_count;
-    alloc = OPENSSL_aligned_alloc(alloc_len, 16, &alloc_freeptr);
+    alloc_len = w1_encoded_len
+        + sizeof(*p) * (1 + num_polys_k + num_polys_l + num_polys_k_by_l + num_polys_sig_k);
+    alloc = OPENSSL_malloc(alloc_len);
     if (alloc == NULL)
-        goto err;
-
+        return 0;
     md_ctx = EVP_MD_CTX_new();
     if (md_ctx == NULL)
         goto err;
 
-    /* Init the temp vectors to point to the aligned polys blob */
-    p = (POLY *)alloc;
+    w1_encoded = alloc;
+    /* Init the temp vectors to point to the allocated polys blob */
+    p = (POLY *)(w1_encoded + w1_encoded_len);
     c_ntt = p++;
     matrix_init(&a_ntt, p, k, l);
     p += num_polys_k_by_l;
@@ -226,26 +215,9 @@ static int ml_dsa_sign_internal(const ML_DSA_KEY *priv,
     signature_init(&sig, p, k, p + k, l, c_tilde, c_tilde_len);
     /* End of the allocated blob setup */
 
-    /*
-     * Mark the private key material as secret before we start computing with
-     * it.  Any control-flow branch or memory-index that transitively depends
-     * on these bytes will be flagged by Valgrind when the library is built
-     * with enable-ct-validation.
-     */
-    CONSTTIME_SECRET(priv->K, sizeof(priv->K));
-    CONSTTIME_SECRET_VECTOR(priv->s1);
-    CONSTTIME_SECRET_VECTOR(priv->s2);
-    CONSTTIME_SECRET_VECTOR(priv->t0);
-
-    if (!sample_ops->matrix_expand_A(md_ctx, priv->shake128_md, priv->rho, &a_ntt))
+    if (!matrix_expand_A(md_ctx, priv->shake128_md, priv->rho, &a_ntt))
         goto err;
 
-    /*
-     * rho_prime is derived from the secret K and must remain tainted
-     * throughout the rejection loop: knowing it would let an attacker
-     * reconstruct every mask y and recover c*s1 = z - y from the final
-     * signature.  Do NOT declassify it.
-     */
     if (!shake_xof_3(md_ctx, priv->shake256_md, priv->K, sizeof(priv->K),
             rnd, rnd_len, mu, mu_len,
             rho_prime, sizeof(rho_prime)))
@@ -268,8 +240,8 @@ static int ml_dsa_sign_internal(const ML_DSA_KEY *priv,
         VECTOR *ct0 = &w1;
         uint32_t z_max, r0_max, ct0_max, h_ones;
 
-        sample_ops->vector_expand_mask(&y, rho_prime,
-            (uint32_t)kappa, gamma1, md_ctx, priv->shake256_md);
+        vector_expand_mask(&y, rho_prime, sizeof(rho_prime), (uint32_t)kappa,
+            gamma1, md_ctx, priv->shake256_md);
         vector_copy(y_ntt, &y);
         vector_ntt(y_ntt);
 
@@ -299,17 +271,12 @@ static int ml_dsa_sign_internal(const ML_DSA_KEY *priv,
         vector_low_bits(r0, gamma2, r0);
 
         /*
-         * Leaking that the signature is rejected is fine: the next attempt
-         * is (indistinguishable from) independent of this one, so an
-         * observer learns nothing about the secret key beyond the number of
-         * iterations, which is itself safe to reveal.
-         * Declassify the bound-check output so that Valgrind does not flag
-         * these intentional leaks.
+         * Leaking that the signature is rejected is fine as the next attempt at a
+         * signature will be (indistinguishable from) independent of this one.
          */
         z_max = vector_max(&sig.z);
         r0_max = vector_max_signed(r0);
-        if (constant_time_declassify_u32(
-                constant_time_ge(z_max, gamma1 - params->beta)
+        if (value_barrier_32(constant_time_ge(z_max, gamma1 - params->beta)
                 | constant_time_ge(r0_max, gamma2 - params->beta)))
             continue;
 
@@ -320,57 +287,16 @@ static int ml_dsa_sign_internal(const ML_DSA_KEY *priv,
         ct0_max = vector_max(ct0);
         h_ones = (uint32_t)vector_count_ones(&sig.hint);
         /* Same reasoning applies to the leak as above */
-        if (constant_time_declassify_u32(
-                constant_time_ge(ct0_max, gamma2)
+        if (value_barrier_32(constant_time_ge(ct0_max, gamma2)
                 | constant_time_lt(params->omega, h_ones)))
             continue;
-
-        /*
-         * The iteration has passed both rejection tests: the signature is
-         * accepted.  Declassify all three public outputs before encoding.
-         *
-         * sig.z and sig.hint were computed from secret key material (s1,
-         * s2, t0) and carry taint, but the rejection checks above have
-         * verified they lie within the ranges required by the security
-         * proof, so they reveal nothing about the key.
-         *
-         * c_tilde = H(mu || w1) carries taint that propagated from the
-         * secret rho_prime through y → w → w1.  It is the Fiat-Shamir
-         * challenge commitment and is published as part of the signature.
-         * We defer its declassification to here (rather than immediately
-         * after the SHAKE call) so that Valgrind can check that
-         * poly_sample_in_ball_ntt and the NTT challenge arithmetic are
-         * data-oblivious with respect to their tainted inputs.
-         */
-        CONSTTIME_DECLASSIFY(c_tilde, c_tilde_len);
-        CONSTTIME_DECLASSIFY_VECTOR(sig.z);
-        CONSTTIME_DECLASSIFY_VECTOR(sig.hint);
-
         ret = ossl_ml_dsa_sig_encode(&sig, params, out_sig);
         break;
     }
 err:
     EVP_MD_CTX_free(md_ctx);
-    if (alloc_freeptr != NULL) {
-        /* Clear the actual sensitive buffer */
-        if (alloc != NULL)
-            OPENSSL_cleanse(alloc, alloc_len);
-        OPENSSL_free(alloc_freeptr);
-    }
-    if (w1_encoded != NULL)
-        OPENSSL_clear_free(w1_encoded, w1_encoded_len);
+    OPENSSL_clear_free(alloc, alloc_len);
     OPENSSL_cleanse(rho_prime, sizeof(rho_prime));
-    /*
-     * Declassify the private key material before returning.  The key struct
-     * is not owned here, so we do not free it, but we must remove the
-     * "secret" taint so that the caller does not inherit spurious Valgrind
-     * "uninitialised" state.  The polynomial data in |alloc| was already
-     * zeroed and freed above; rho_prime is stack-allocated and cleansed.
-     */
-    CONSTTIME_DECLASSIFY(priv->K, sizeof(priv->K));
-    CONSTTIME_DECLASSIFY_VECTOR(priv->s1);
-    CONSTTIME_DECLASSIFY_VECTOR(priv->s2);
-    CONSTTIME_DECLASSIFY_VECTOR(priv->t0);
     return ret;
 }
 
@@ -389,12 +315,11 @@ err:
  */
 static int ml_dsa_verify_internal(const ML_DSA_KEY *pub,
     const uint8_t *mu, size_t mu_len,
-    const uint8_t *sig_enc, size_t sig_enc_len)
+    const uint8_t *sig_enc,
+    size_t sig_enc_len)
 {
     int ret = 0;
-    const OSSL_ML_DSA_SAMPLE_OPS *sample_ops = ossl_ml_dsa_sample_ops();
-    uint8_t *alloc = NULL, *w1_encoded = NULL;
-    void *alloc_freeptr = NULL;
+    uint8_t *alloc = NULL, *w1_encoded;
     POLY *p, *c_ntt;
     MATRIX a_ntt;
     VECTOR az_ntt, ct1_ntt, *z_ntt, *w1, *w_approx;
@@ -408,8 +333,6 @@ static int ml_dsa_verify_internal(const ML_DSA_KEY *pub,
     size_t num_polys_k = 2 * k;
     size_t num_polys_l = 1 * l;
     size_t num_polys_k_by_l = k * l;
-    size_t poly_count;
-    size_t alloc_len;
     uint8_t c_tilde[ML_DSA_MAX_LAMBDA / 4];
     uint8_t c_tilde_sig[ML_DSA_MAX_LAMBDA / 4];
     EVP_MD_CTX *md_ctx = NULL;
@@ -422,25 +345,19 @@ static int ml_dsa_verify_internal(const ML_DSA_KEY *pub,
         return 0;
     }
 
-    /* Allocate w1_encoded buffer */
+    /* Allocate space for all the POLYNOMIALS used by temporary VECTORS */
     w1_encoded_len = k * (gamma2 == ML_DSA_GAMMA2_Q_MINUS1_DIV88 ? 192 : 128);
-    w1_encoded = OPENSSL_malloc(w1_encoded_len);
-    if (w1_encoded == NULL)
-        return 0;
-
-    /* Allocate aligned POLY array */
-    poly_count = 1 + num_polys_k + num_polys_l + num_polys_k_by_l + num_polys_sig;
-    alloc_len = sizeof(*p) * poly_count;
-    alloc = OPENSSL_aligned_alloc(alloc_len, 16, &alloc_freeptr);
+    alloc = OPENSSL_malloc(w1_encoded_len
+        + sizeof(*p) * (1 + num_polys_k + num_polys_l + num_polys_k_by_l + num_polys_sig));
     if (alloc == NULL)
-        goto err;
-
+        return 0;
     md_ctx = EVP_MD_CTX_new();
     if (md_ctx == NULL)
         goto err;
 
-    /* Init the temp vectors to point to the aligned polys blob */
-    p = (POLY *)alloc;
+    w1_encoded = alloc;
+    /* Init the temp vectors to point to the allocated polys blob */
+    p = (POLY *)(w1_encoded + w1_encoded_len);
     c_ntt = p++;
     matrix_init(&a_ntt, p, k, l);
     p += num_polys_k_by_l;
@@ -450,7 +367,7 @@ static int ml_dsa_verify_internal(const ML_DSA_KEY *pub,
     vector_init(&ct1_ntt, p + k, k);
 
     if (!ossl_ml_dsa_sig_decode(&sig, sig_enc, sig_enc_len, pub->params)
-        || !sample_ops->matrix_expand_A(md_ctx, pub->shake128_md, pub->rho, &a_ntt))
+        || !matrix_expand_A(md_ctx, pub->shake128_md, pub->rho, &a_ntt))
         goto err;
 
     /* Compute verifiers challenge c_ntt = NTT(SampleInBall(c_tilde)) */
@@ -485,9 +402,7 @@ static int ml_dsa_verify_internal(const ML_DSA_KEY *pub,
     ret = (z_max < (uint32_t)(params->gamma1 - params->beta))
         && memcmp(c_tilde, sig.c_tilde, c_tilde_len) == 0;
 err:
-    if (alloc_freeptr != NULL)
-        OPENSSL_free(alloc_freeptr);
-    OPENSSL_free(w1_encoded);
+    OPENSSL_free(alloc);
     EVP_MD_CTX_free(md_ctx);
     return ret;
 }
@@ -497,8 +412,8 @@ err:
  *
  * @returns 1 on success, or 0 on error.
  */
-int ossl_ml_dsa_sign(const ML_DSA_KEY *priv,
-    int msg_is_mu, const uint8_t *msg, size_t msg_len,
+int ossl_ml_dsa_sign(const ML_DSA_KEY *priv, int msg_is_mu,
+    const uint8_t *msg, size_t msg_len,
     const uint8_t *context, size_t context_len,
     const uint8_t *rand, size_t rand_len, int encode,
     unsigned char *sig, size_t *sig_len, size_t sig_size)
@@ -547,8 +462,8 @@ err:
  * See FIPS 203 Section 5.3 Algorithm 3 ML-DSA.Verify()
  * @returns 1 on success, or 0 on error.
  */
-int ossl_ml_dsa_verify(const ML_DSA_KEY *pub,
-    int msg_is_mu, const uint8_t *msg, size_t msg_len,
+int ossl_ml_dsa_verify(const ML_DSA_KEY *pub, int msg_is_mu,
+    const uint8_t *msg, size_t msg_len,
     const uint8_t *context, size_t context_len, int encode,
     const uint8_t *sig, size_t sig_len)
 {
diff --git a/crypto/ml_dsa/ml_dsa_sign.h b/crypto/ml_dsa/ml_dsa_sign.h
index 1a13410050..23f44e1702 100644
--- a/crypto/ml_dsa/ml_dsa_sign.h
+++ b/crypto/ml_dsa/ml_dsa_sign.h
@@ -7,16 +7,9 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_ML_DSA_ML_DSA_SIGN_H)
-#define OSSL_LIBCRYPTO_ML_DSA_ML_DSA_SIGN_H
-
-#include "ml_dsa_vector.h"
-
 struct ml_dsa_sig_st {
     VECTOR z;
     VECTOR hint;
     uint8_t *c_tilde;
     size_t c_tilde_len;
 };
-
-#endif /* !defined(OSSL_LIBCRYPTO_ML_DSA_ML_DSA_SIGN_H) */
diff --git a/crypto/ml_dsa/ml_dsa_vector.h b/crypto/ml_dsa/ml_dsa_vector.h
index 9b83c0420e..b68a4d95d0 100644
--- a/crypto/ml_dsa/ml_dsa_vector.h
+++ b/crypto/ml_dsa/ml_dsa_vector.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_ML_DSA_ML_DSA_VECTOR_H)
-#define OSSL_LIBCRYPTO_ML_DSA_ML_DSA_VECTOR_H
-
 #include 
 #include "ml_dsa_poly.h"
 
@@ -18,11 +15,6 @@ struct vector_st {
     size_t num_poly;
 };
 
-#define CONSTTIME_SECRET_VECTOR(v) \
-    CONSTTIME_SECRET(v.poly, v.num_poly * sizeof(POLY));
-#define CONSTTIME_DECLASSIFY_VECTOR(v) \
-    CONSTTIME_DECLASSIFY(v.poly, v.num_poly * sizeof(POLY));
-
 /**
  * @brief Initialize a Vector object.
  *
@@ -152,6 +144,33 @@ vector_mult_scalar(const VECTOR *lhs, const POLY *rhs, VECTOR *out)
         ossl_ml_dsa_poly_ntt_mult(lhs->poly + i, rhs, out->poly + i);
 }
 
+static ossl_inline ossl_unused int
+vector_expand_S(EVP_MD_CTX *h_ctx, const EVP_MD *md, int eta,
+    const uint8_t *seed, VECTOR *s1, VECTOR *s2)
+{
+    return ossl_ml_dsa_vector_expand_S(h_ctx, md, eta, seed, s1, s2);
+}
+
+static ossl_inline ossl_unused void
+vector_expand_mask(VECTOR *out, const uint8_t *rho_prime, size_t rho_prime_len,
+    uint32_t kappa, uint32_t gamma1,
+    EVP_MD_CTX *h_ctx, const EVP_MD *md)
+{
+    size_t i;
+    uint8_t derived_seed[ML_DSA_RHO_PRIME_BYTES + 2];
+
+    memcpy(derived_seed, rho_prime, ML_DSA_RHO_PRIME_BYTES);
+
+    for (i = 0; i < out->num_poly; i++) {
+        size_t index = kappa + i;
+
+        derived_seed[ML_DSA_RHO_PRIME_BYTES] = index & 0xFF;
+        derived_seed[ML_DSA_RHO_PRIME_BYTES + 1] = (index >> 8) & 0xFF;
+        poly_expand_mask(out->poly + i, derived_seed, sizeof(derived_seed),
+            gamma1, h_ctx, md);
+    }
+}
+
 /* Scale back previously rounded value */
 static ossl_inline ossl_unused void
 vector_scale_power2_round_ntt(const VECTOR *in, VECTOR *out)
@@ -248,5 +267,3 @@ vector_use_hint(const VECTOR *h, const VECTOR *r, uint32_t gamma2, VECTOR *out)
     for (i = 0; i < out->num_poly; i++)
         poly_use_hint(h->poly + i, r->poly + i, gamma2, out->poly + i);
 }
-
-#endif /* !defined(OSSL_LIBCRYPTO_ML_DSA_ML_DSA_VECTOR_H) */
diff --git a/crypto/ml_kem/asm/mlkem_intt_ppc64le.S b/crypto/ml_kem/asm/mlkem_intt_ppc64le.S
deleted file mode 100644
index ff14c45626..0000000000
--- a/crypto/ml_kem/asm/mlkem_intt_ppc64le.S
+++ /dev/null
@@ -1,676 +0,0 @@
-/*
- * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
- *
- * Licensed under the Apache License 2.0 (the "License").  You may not use
- * this file except in compliance with the License.  You can obtain a copy
- * in the file LICENSE in the source distribution or at
- * https://www.openssl.org/source/license.html
- */
-/*
- * Copyright IBM Corp. 2025, 2026
- *
- * ===================================================================================
- * Written by Danny Tsen 
- */
-
-#include "mlkem_ppc_macros_asm.inc"
-
-.machine "any"
-.text
-
-#define ZETA_INTT_OFFSET 0
-
-#define PEER  17
-#define CURR  18
-
-#define V_Z1  28
-#define V_Z2  29
-#define V_Z3  30
-#define V_Z4  31
-#define V_ZETA  31
-
-.macro SAVE_REGS
-        stdu    1, -336(1)
-        mflr    0
-        std     14, 56(1)
-        std     15, 64(1)
-        std     16, 72(1)
-        std     17, 80(1)
-        std     18, 88(1)
-
-        li      10, 128
-        li      11, 144
-        li      12, 160
-        li      14, 176
-        li      15, 192
-        li      16, 208
-        stxvx   32+20, 10, 1
-        stxvx   32+21, 11, 1
-        stxvx   32+22, 12, 1
-        stxvx   32+23, 14, 1
-        stxvx   32+24, 15, 1
-        stxvx   32+25, 16, 1
-        li      10, 224
-        li      11, 240
-        li      12, 256
-        li      14, 272
-        li      15, 288
-        li      16, 304
-        stxvx   32+26, 10, 1
-        stxvx   32+27, 11, 1
-        stxvx   32+28, 12, 1
-        stxvx   32+29, 14, 1
-        stxvx   32+30, 15, 1
-        stxvx   32+31, 16, 1
-.endm
-
-.macro RESTORE_REGS
-        li      10, 128
-        li      11, 144
-        li      12, 160
-        li      14, 176
-        li      15, 192
-        li      16, 208
-        lxvx    32+20, 10, 1
-        lxvx    32+21, 11, 1
-        lxvx    32+22, 12, 1
-        lxvx    32+23, 14, 1
-        lxvx    32+24, 15, 1
-        lxvx    32+25, 16, 1
-        li      10, 224
-        li      11, 240
-        li      12, 256
-        li      14, 272
-        li      15, 288
-        li      16, 304
-        lxvx    32+26, 10, 1
-        lxvx    32+27, 11, 1
-        lxvx    32+28, 12, 1
-        lxvx    32+29, 14, 1
-        lxvx    32+30, 15, 1
-        lxvx    32+31, 16, 1
-        ld      14, 56(1)
-        ld      15, 64(1)
-        ld      16, 72(1)
-        ld      17, 80(1)
-        ld      18, 88(1)
-
-        mtlr    0
-        addi    1, 1, 336
-.endm
-
-/* ===================================================================== */
-/* Delayed writes resulting curr and peer coefficients */
-.macro delayed_writes_curr_peer _c1, _p1, _c2, _p2, _c3, _p3, _c4, _p4
-        stxvd2x    32+\_c1, 0, 5
-        stxvd2x    32+\_p1, 10, 5
-        stxvd2x    32+\_c2, 11, 5
-        stxvd2x    32+\_p2, 12, 5
-        stxvd2x    32+\_c3, 15, 5
-        stxvd2x    32+\_p3, 16, 5
-        stxvd2x    32+\_c4, 17, 5
-        stxvd2x    32+\_p4, 18, 5
-.endm
-
-/*
- * _intt_layer_reduce_4x- common code for layer 6 and 7
- *
- * Assuming input registers and output vectors as follows,
- *   input offsets - curr (0, r11, r15, r17), peer (r10, r12, r16, r18)
- *   output vectors - v20, v21, v22, v23, v24, v25, v26
- */
-.macro _intt_layer_reduce_4x
-        /* even - curr, odd - peer, odd is the updated peer */
-        /* Compute (even - odd + kPrime) */
-        vsubuhm  0, 10, 14
-        vadduhm  20, 14, 10
-        vadduhm  21, 0, V_kPrime16
-        vsubuhm  0, 11, 15
-        vadduhm  22, 15, 11
-        vadduhm  23, 0, V_kPrime16
-        vsubuhm  0, 12, 16
-        vadduhm  24, 16, 12
-        vadduhm  25, 0, V_kPrime16
-        vsubuhm  0, 13, 17
-        vadduhm  26, 17, 13
-        vadduhm  27, 0, V_kPrime16
-        zeta_scalar_mul 21, V_Z1, 8, 9       /* peer * zeta */
-        zeta_scalar_mul 23, V_Z2, 18, 19       /* peer * zeta */
-        Barrett_reduce_delayed_2x 8, 9, 18, 19, 21, 23
-        zeta_scalar_mul 25, V_Z3, 8, 9       /* peer * zeta */
-        zeta_scalar_mul 27, V_Z4, 18, 19       /* peer * zeta */
-        Barrett_reduce_delayed_2x 8, 9, 18, 19, 25, 27
-        reduce_once_4x 21, 23, 25, 27
-.endm
-
-/* Layer 1 layout -
- *  each load contains 2 curr and 2 peer elements.
- *    -> curr1 curr1 peer1 peer1 curr2 curr2 peer2 peer2
- *  vmrgew and vmrgow -> 8 curr elements and 8 peer elements
- */
-/*
- * INTT layer 1,  Offset between legs = 2.
- */
-.macro _load_transpose_layer1
-        lxvd2x     32+0, 0, 5
-        lxvd2x     32+6, 10, 5
-        lxvd2x     32+7, 11, 5
-        lxvd2x     32+8, 12, 5
-        lxvd2x     32+9, 15, 5
-        lxvd2x     32+10, 16, 5
-        lxvd2x     32+11, 17, 5
-        lxvd2x     32+12, 18, 5
-        vmrgew 14, 0, 6
-        vmrgew 15, 7, 8
-        vmrgew 16, 9, 10
-        vmrgew 17, 11, 12
-        vmrgow 13, 11, 12
-        vmrgow 12, 9, 10
-        vmrgow 11, 7, 8
-        vmrgow 10, 0, 6
-.endm
-
-.macro _intt_layer1_reduce_4x
-        lvx     V_Z1, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z2, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z3, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z4, 0, 14
-        addi  14, 14, 16
-        _load_transpose_layer1
-        _intt_layer_reduce_4x
-.endm
-
-.macro INTT_Layer1_4x
-        _intt_layer1_reduce_4x
-        reduce_once_4x 20, 22, 24, 26
-        vmrgow  6, 21, 20
-        vmrgew  7, 21, 20
-        vmrgow  8, 23, 22
-        vmrgew  9, 23, 22
-        vmrgow  10, 25, 24
-        vmrgew  11, 25, 24
-        vmrgow  12, 27, 26
-        vmrgew  13, 27, 26
-        delayed_writes_curr_peer 7, 6, 9, 8, 11, 10, 13, 12
-        addi  5, 5, 128
-.endm
-
-/* Layer 2 layout -
- *  each load contains 4 curr and 4 peer elements
- *  xxpermidi -> 8 curr elements and 8 peer elements
- */
-/*
- * INTT layer 2,  Offset between legs = 4.
- */
-.macro _load_transpose_layer2
-        lxvd2x     4, 0, 5
-        lxvd2x     5, 10, 5
-        lxvd2x     6, 11, 5
-        lxvd2x     7, 12, 5
-        lxvd2x     8, 15, 5
-        lxvd2x     9, 16, 5
-        lxvd2x     10, 17, 5
-        lxvd2x     11, 18, 5
-        xxpermdi 32+14, 5, 4, 3
-        xxpermdi 32+10, 5, 4, 0
-        xxpermdi 32+15, 7, 6, 3
-        xxpermdi 32+11, 7, 6, 0
-        xxpermdi 32+16, 9, 8, 3
-        xxpermdi 32+12, 9, 8, 0
-        xxpermdi 32+17, 11, 10, 3
-        xxpermdi 32+13, 11, 10, 0
-.endm
-
-.macro _intt_layer2_reduce_4x
-        lvx     V_Z1, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z2, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z3, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z4, 0, 14
-        addi  14, 14, 16
-        _load_transpose_layer2
-        _intt_layer_reduce_4x
-.endm
-
-.macro INTT_Layer2_4x
-        _intt_layer2_reduce_4x
-        reduce_once_4x 20, 22, 24, 26
-        xxpermdi 32+6, 32+20, 32+21, 3
-        xxpermdi 32+7, 32+20, 32+21, 0
-        xxpermdi 32+8, 32+22, 32+23, 3
-        xxpermdi 32+9, 32+22, 32+23, 0
-        xxpermdi 32+10, 32+24, 32+25, 3
-        xxpermdi 32+11, 32+24, 32+25, 0
-        xxpermdi 32+12, 32+26, 32+27, 3
-        xxpermdi 32+13, 32+26, 32+27, 0
-        delayed_writes_curr_peer 6, 7, 8, 9, 10, 11, 12, 13
-        addi  5, 5, 128
-.endm
-
-/* ===================================================================== */
-/*
- * INTT computation for layer 3, 4, 5, 6 and 7.
- */
-
-/* Load 8 vectors with 4x pipeline
- *
- * Assuming input registers and output vectors as follows,
- *   input offsets - curr (0, r11, r15, r17), peer (r10, r12, r16, r18)
- *   output vectors - v20, v21, v22, v23, v24, v25, v26
- */
-.macro _intt_scalar_reduce_4x _zeta1, _zeta2, _zeta3, _zeta4
-        /* Load peer */
-        lxvd2x     32+14, 10, 5
-        lxvd2x     32+15, 12, 5
-        lxvd2x     32+16, 16, 5
-        lxvd2x     32+17, 18, 5
-
-        /* Load curr */
-        lxvd2x     32+10, 0, 5
-        lxvd2x     32+11, 11, 5
-        lxvd2x     32+12, 15, 5
-        lxvd2x     32+13, 17, 5
-
-        /* even - curr, odd - peer, odd is the updated peer */
-        /* Compute (even - odd + kPrime) */
-        vsubuhm  0, 10, 14
-        vadduhm  20, 14, 10
-        vadduhm  21, 0, V_kPrime16
-        vsubuhm  0, 11, 15
-        vadduhm  22, 15, 11
-        vadduhm  23, 0, V_kPrime16
-        vsubuhm  0, 12, 16
-        vadduhm  24, 16, 12
-        vadduhm  25, 0, V_kPrime16
-        vsubuhm  0, 13, 17
-        vadduhm  26, 17, 13
-        vadduhm  27, 0, V_kPrime16
-        zeta_scalar_mul 21, \_zeta1, 8, 9       /* peer * zeta */
-        zeta_scalar_mul 23, \_zeta2, 18, 19       /* peer * zeta */
-        Barrett_reduce_delayed_2x 8, 9, 18, 19, 21, 23
-        zeta_scalar_mul 25, \_zeta3, 8, 9       /* peer * zeta */
-        zeta_scalar_mul 27, \_zeta4, 18, 19       /* peer * zeta */
-        Barrett_reduce_delayed_2x 8, 9, 18, 19, 25, 27
-        reduce_once_4x 21, 23, 25, 27
-.endm
-
-/*
- * INTT layer 3, Offset between legs = 8.
- */
-.macro INTT_Layer3_4x
-        lvx     V_Z1, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z2, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z3, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z4, 0, 14
-        addi  14, 14, 16
-        _intt_scalar_reduce_4x V_Z1, V_Z2, V_Z3, V_Z4
-        reduce_once_4x 20, 22, 24, 26
-        delayed_writes_curr_peer 20, 21, 22, 23, 24, 25, 26, 27
-        addi  5, 5, 128
-.endm
-
-/*
- * INTT layer 4, Offset between legs = 16.
- */
-.macro INTT_Layer4_4x
-        lvx     V_Z1, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z2, 0, 14
-        addi  14, 14, 16
-        _intt_scalar_reduce_4x V_Z1, V_Z1, V_Z2, V_Z2
-        reduce_once_4x 20, 22, 24, 26
-        delayed_writes_curr_peer 20, 21, 22, 23, 24, 25, 26, 27
-        addi  5, 5, 128
-.endm
-
-.macro intt_reduce_delayed_write
-        _intt_scalar_reduce_4x V_ZETA, V_ZETA, V_ZETA, V_ZETA
-        reduce_once_4x 20, 22, 24, 26
-        delayed_writes_curr_peer 20, 21, 22, 23, 24, 25, 26, 27
-.endm
-
-/*
- * INTT layer 5, Offset between legs = 32.
- */
-.macro INTT_Layer5_4x
-        lvx     V_ZETA, 0, 14
-        addi  14, 14, 16
-        intt_reduce_delayed_write
-        addi  5, 5, 128
-.endm
-
-/*
- * INTT layer 6, Offset between legs = 64.
- */
-.macro INTT_Layer6_4x
-        intt_reduce_delayed_write
-        addi  5, 5, 64
-.endm
-
-/*
- * INTT layer 7, Offset between legs = 128.
- */
-.macro INTT_Layer7_4x
-        intt_reduce_delayed_write
-        addi  5, 5, 64
-.endm
-
-/* ===================================================================== */
-/* Multiply a scalar by a constant (kInverseDegree=3303). */
-.macro _mul_const_reduce_2x _x1, _x2
-        vmulouh  6, \_x1, V_kInverseDegree
-        vmuleuh  7, \_x1, V_kInverseDegree
-        xxmrglw  32+28, 32+7, 32+6
-        xxmrghw  32+29, 32+7, 32+6
-        vmulouh  6, \_x2, V_kInverseDegree
-        vmuleuh  7, \_x2, V_kInverseDegree
-        xxmrglw  32+30, 32+7, 32+6
-        xxmrghw  32+31, 32+7, 32+6
-        Barrett_reduce_delayed_2x 28, 29, 30, 31, \_x1, \_x2
-.endm
-
-.macro scalar_mul_const_8x
-        lxvd2x     32+20, 0, 5
-        lxvd2x     32+21, 10, 5
-        lxvd2x     32+22, 11, 5
-        lxvd2x     32+23, 12, 5
-        lxvd2x     32+24, 15, 5
-        lxvd2x     32+25, 16, 5
-        lxvd2x     32+26, 17, 5
-        lxvd2x     32+27, 18, 5
-        _mul_const_reduce_2x 20, 21
-        _mul_const_reduce_2x 22, 23
-        _mul_const_reduce_2x 24, 25
-        _mul_const_reduce_2x 26, 27
-        reduce_once_4x 20, 21, 22, 23
-        reduce_once_4x 24, 25, 26, 27
-        /* overload delayed_writes_curr_peer */
-        delayed_writes_curr_peer 20, 21, 22, 23, 24, 25, 26, 27
-        addi  5, 5, 128
-.endm
-
-.macro Load_consts
-        addis   10,2,ntt_consts@toc@ha
-        addi    10,10,ntt_consts@toc@l
-        lvx V_kPrime16, 0, 10
-        li  7, 16
-        lvx V_kPrime32, 7, 10
-        li  7, 32
-        lvx V_kBarrettMultiplier, 7, 10
-        li  7, 48
-        lvx V_kBarrettShift, 7, 10
-        li  7, 64
-        lvx V_kInverseDegree, 7, 10
-.endm
-
-/* ===================================================================== */
-/*
- * mlkem_inverse_ntt_ppc(int16_t *r)
- *   Compute inverse NTT based on the following 7 layers -
- *     len = 2, 4, 8, 16, 32, 64, 128
- *
- *   Each layer compute the coefficients on 2 legs, start and start + len*2 offsets.
- *
- *   leg 1                        leg 2
- *   -----                        -----
- *   start                        start+len*2
- *   start+next                   start+len*2+next
- *   start+next+next              start+len*2+next+next
- *   start+next+next+next         start+len*2+next+next+next
- *
- *   The resulting coefficients then store back to each leg's offset.
- *
- *   Each vector has the same corresponding zeta except len=4 and len=2.
- *
- *   len=4 has 4-4 layout which means every 4 16-bit coefficients have the same zeta.
- *   and len=2 has 2-2-2-2 layout which means every 2 16-bit coefficients have the same zeta.
- *   e.g.
- *         coeff vector    a1   a2   a3  a4  a5  a6  a7  a8
- *         zeta  vector    z1   z1   z2  z2  z3  z3  z4  z4
- *
- *   For len=4 and len=2, each vector will get permuted to leg1 and leg2. Zeta is
- *   pre-arranged for the leg1 and leg2.  After the computation, each vector needs
- *   to transpose back to its original 4-4 or 2-2-2-2 layout.
- */
-.global mlkem_inverse_ntt_ppc
-.align 4
-mlkem_inverse_ntt_ppc:
-
-        SAVE_REGS
-
-        Load_consts
-        addis   8,2,mlkem_intt_zetas@toc@ha
-        addi    8,8,mlkem_intt_zetas@toc@l
-        addi    14, 8, ZETA_INTT_OFFSET
-
-        li      10, 16        // offset to next peer
-        li      11, 32
-        li      12, 48
-        li      15, 64
-        li      16, 80
-        li      17, 96
-        li      18, 112
-
-.align 4
-        /*
-         * Layer 1. len = 2
-         *    Load zeta vectors in 2-2-2-2 layout
-         */
-        mr      5, 3
-
-        INTT_Layer1_4x
-        INTT_Layer1_4x
-        INTT_Layer1_4x
-        INTT_Layer1_4x
-
-.align 4
-        /*
-         * Layer 22. len = 4
-         *    Load zeta vectors in 4-4 layout
-         */
-        mr      5, 3
-
-        INTT_Layer2_4x
-        INTT_Layer2_4x
-        INTT_Layer2_4x
-        INTT_Layer2_4x
-
-.align 4
-        /*
-         * Layer 3. len = 8
-         */
-        mr      5, 3
-
-        INTT_Layer3_4x
-        INTT_Layer3_4x
-        INTT_Layer3_4x
-        INTT_Layer3_4x
-
-.align 4
-        /*
-         * Layer 4. len = 16
-         */
-        mr      5, 3
-        li      10, 32        // offset to next peer
-        li      11, 16
-        li      12, 32+16
-        li      15, 64
-        li      16, 64+32
-        li      17, 64+16
-        li      18, 96+16
-
-        INTT_Layer4_4x
-        INTT_Layer4_4x
-        INTT_Layer4_4x
-        INTT_Layer4_4x
-
-.align 4
-        /*
-         * Layer 5. len = 32
-         */
-        mr      5, 3
-        li      10, 64        // offset to next peer
-        li      11, 16
-        li      12, 64+16
-        li      15, 32
-        li      16, 64+32
-        li      17, 48
-        li      18, 64+48
-
-        INTT_Layer5_4x
-        INTT_Layer5_4x
-        INTT_Layer5_4x
-        INTT_Layer5_4x
-
-.align 4
-        /*
-         * Layer 6. len = 64
-         */
-        mr      5, 3
-        li      10, 128        // offset to next peer
-        li      11, 16
-        li      12, 128+16
-        li      15, 32
-        li      16, 128+32
-        li      17, 48
-        li      18, 128+48
-
-        lvx     V_ZETA, 0, 14
-        addi  14, 14, 16
-        INTT_Layer6_4x
-        INTT_Layer6_4x
-        addi  5, 5, 128
-        lvx     V_ZETA, 0, 14
-        addi  14, 14, 16
-        INTT_Layer6_4x
-        INTT_Layer6_4x
-        addi  5, 5, 128
-
-.align 4
-        /*
-         * Layer 7. len = 128
-         */
-        mr      5, 3
-        li      10, 256        // offset to next peer
-        li      11, 16
-        li      12, 256+16
-        li      15, 32
-        li      16, 256+32
-        li      17, 48
-        li      18, 256+48
-
-        lvx     V_ZETA, 0, 14
-        addi  14, 14, 16
-        INTT_Layer7_4x
-        INTT_Layer7_4x
-        INTT_Layer7_4x
-        INTT_Layer7_4x
-
-        /* Multiply a scalar by a constant. */
-        mr      5, 3
-        li      10, 16
-        li      11, 32
-        li      12, 48
-        li      15, 64
-        li      16, 80
-        li      17, 96
-        li      18, 112
-
-        scalar_mul_const_8x
-        scalar_mul_const_8x
-        scalar_mul_const_8x
-        scalar_mul_const_8x
-
-        RESTORE_REGS
-        blr
-.size     mlkem_inverse_ntt_ppc,.-mlkem_inverse_ntt_ppc
-
-.rodata
-.align 4
-ntt_consts:
-.short kPrime, kPrime, kPrime, kPrime, kPrime, kPrime, kPrime, kPrime
-.long  kPrime, kPrime, kPrime, kPrime
-.long  kBarrettMultiplier, kBarrettMultiplier, kBarrettMultiplier, kBarrettMultiplier
-.long  kBarrettShift, 0, kBarrettShift, 0
-.short kInverseDegree, kInverseDegree, kInverseDegree, kInverseDegree, kInverseDegree, kInverseDegree, kInverseDegree, kInverseDegree
-
-mlkem_intt_zetas:
-/*
- * For intt Len=2
- * reorder zeta array, (1, 2, 3, 4) -> (4, 2, 3, 1)
- * Transpose z[0], z[1], z[2], z[3]
- *    -> z[4], z[4], z[2], z[2], z[3], z[3], z[1], z[1]
- */
-.short  1219, 1219, 2444, 2444, 394, 394, 1175, 1175
-.short  1607, 1607, 1455, 1455, 2117, 2117, 2300, 2300
-.short  2186, 2186, 554, 554, 1179, 1179, 2443, 2443
-.short  525, 525, 2926, 2926, 2237, 2237, 2303, 2303
-.short  1230, 1230, 863, 863, 2768, 2768, 735, 735
-.short  2266, 2266, 556, 556, 3010, 3010, 2572, 2572
-.short  2954, 2954, 1239, 1239, 780, 780, 1684, 1684
-.short  1745, 1745, 1292, 1292, 1031, 1031, 109, 109
-.short  2596, 2596, 3061, 3061, 992, 992, 2688, 2688
-.short  2390, 2390, 892, 892, 1021, 1021, 941, 941
-.short  1482, 1482, 1868, 1868, 2377, 2377, 642, 642
-.short  1626, 1626, 540, 540, 1678, 1678, 1540, 1540
-.short  2573, 2573, 314, 314, 1173, 1173, 279, 279
-.short  1920, 1920, 48, 48, 667, 667, 3096, 3096
-.short  1692, 1692, 1041, 1041, 2606, 2606, 2229, 2229
-.short  3312, 3312, 2746, 2746, 568, 568, 680, 680
-/* For intt Len=4 */
-.short  2419, 2419, 2419, 2419, 2102, 2102, 2102, 2102
-.short  219, 219, 219, 219, 855, 855, 855, 855
-.short  2681, 2681, 2681, 2681, 1848, 1848, 1848, 1848
-.short  712, 712, 712, 712, 682, 682, 682, 682
-.short  927, 927, 927, 927, 1795, 1795, 1795, 1795
-.short  461, 461, 461, 461, 1891, 1891, 1891, 1891
-.short  2877, 2877, 2877, 2877, 2522, 2522, 2522, 2522
-.short  1894, 1894, 1894, 1894, 1010, 1010, 1010, 1010
-.short  1414, 1414, 1414, 1414, 2009, 2009, 2009, 2009
-.short  3296, 3296, 3296, 3296, 464, 464, 464, 464
-.short  2697, 2697, 2697, 2697, 816, 816, 816, 816
-.short  1352, 1352, 1352, 1352, 2679, 2679, 2679, 2679
-.short  1274, 1274, 1274, 1274, 1052, 1052, 1052, 1052
-.short  1025, 1025, 1025, 1025, 2132, 2132, 2132, 2132
-.short  1573, 1573, 1573, 1573, 76, 76, 76, 76
-.short  2998, 2998, 2998, 2998, 3040, 3040, 3040, 3040
-/* For intt Len=8 and others */
-.short  2508, 2508, 2508, 2508, 2508, 2508, 2508, 2508
-.short  1355, 1355, 1355, 1355, 1355, 1355, 1355, 1355
-.short  450, 450, 450, 450, 450, 450, 450, 450
-.short  936, 936, 936, 936, 936, 936, 936, 936
-.short  447, 447, 447, 447, 447, 447, 447, 447
-.short  2794, 2794, 2794, 2794, 2794, 2794, 2794, 2794
-.short  1235, 1235, 1235, 1235, 1235, 1235, 1235, 1235
-.short  1903, 1903, 1903, 1903, 1903, 1903, 1903, 1903
-.short  1996, 1996, 1996, 1996, 1996, 1996, 1996, 1996
-.short  1089, 1089, 1089, 1089, 1089, 1089, 1089, 1089
-.short  3273, 3273, 3273, 3273, 3273, 3273, 3273, 3273
-.short  283, 283, 283, 283, 283, 283, 283, 283
-.short  1853, 1853, 1853, 1853, 1853, 1853, 1853, 1853
-.short  1990, 1990, 1990, 1990, 1990, 1990, 1990, 1990
-.short  882, 882, 882, 882, 882, 882, 882, 882
-.short  3033, 3033, 3033, 3033, 3033, 3033, 3033, 3033
-.short  1583, 1583, 1583, 1583, 1583, 1583, 1583, 1583
-.short  2760, 2760, 2760, 2760, 2760, 2760, 2760, 2760
-.short  69, 69, 69, 69, 69, 69, 69, 69
-.short  543, 543, 543, 543, 543, 543, 543, 543
-.short  2532, 2532, 2532, 2532, 2532, 2532, 2532, 2532
-.short  3136, 3136, 3136, 3136, 3136, 3136, 3136, 3136
-.short  1410, 1410, 1410, 1410, 1410, 1410, 1410, 1410
-.short  2267, 2267, 2267, 2267, 2267, 2267, 2267, 2267
-.short  2481, 2481, 2481, 2481, 2481, 2481, 2481, 2481
-.short  1432, 1432, 1432, 1432, 1432, 1432, 1432, 1432
-.short  2699, 2699, 2699, 2699, 2699, 2699, 2699, 2699
-.short  687, 687, 687, 687, 687, 687, 687, 687
-.short  40, 40, 40, 40, 40, 40, 40, 40
-.short  749, 749, 749, 749, 749, 749, 749, 749
-.short  1600, 1600, 1600, 1600, 1600, 1600, 1600, 1600
diff --git a/crypto/ml_kem/asm/mlkem_ntt_ppc64le.S b/crypto/ml_kem/asm/mlkem_ntt_ppc64le.S
deleted file mode 100644
index 1aefed531e..0000000000
--- a/crypto/ml_kem/asm/mlkem_ntt_ppc64le.S
+++ /dev/null
@@ -1,647 +0,0 @@
-/*
- * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
- *
- * Licensed under the Apache License 2.0 (the "License").  You may not use
- * this file except in compliance with the License.  You can obtain a copy
- * in the file LICENSE in the source distribution or at
- * https://www.openssl.org/source/license.html
- */
-/*
- * Copyright IBM Corp. 2025, 2026
- *
- * ===================================================================================
- * Written by Danny Tsen 
- */
-
-#include "mlkem_ppc_macros_asm.inc"
-
-.machine "any"
-.text
-
-#define ZETA_NTT_OFFSET 0
-
-#define V_Z1  28
-#define V_Z2  29
-#define V_Z3  30
-#define V_Z4  31
-#define V_ZETA  31
-
-.macro SAVE_REGS
-        stdu    1, -336(1)
-        mflr    0
-        std     14, 56(1)
-        std     15, 64(1)
-        std     16, 72(1)
-        std     17, 80(1)
-        std     18, 88(1)
-
-        li      10, 128
-        li      11, 144
-        li      12, 160
-        li      14, 176
-        li      15, 192
-        li      16, 208
-        stxvx   32+20, 10, 1
-        stxvx   32+21, 11, 1
-        stxvx   32+22, 12, 1
-        stxvx   32+23, 14, 1
-        stxvx   32+24, 15, 1
-        stxvx   32+25, 16, 1
-        li      10, 224
-        li      11, 240
-        li      12, 256
-        li      14, 272
-        li      15, 288
-        li      16, 304
-        stxvx   32+26, 10, 1
-        stxvx   32+27, 11, 1
-        stxvx   32+28, 12, 1
-        stxvx   32+29, 14, 1
-        stxvx   32+30, 15, 1
-        stxvx   32+31, 16, 1
-.endm
-
-.macro RESTORE_REGS
-        li      10, 128
-        li      11, 144
-        li      12, 160
-        li      14, 176
-        li      15, 192
-        li      16, 208
-        lxvx    32+20, 10, 1
-        lxvx    32+21, 11, 1
-        lxvx    32+22, 12, 1
-        lxvx    32+23, 14, 1
-        lxvx    32+24, 15, 1
-        lxvx    32+25, 16, 1
-        li      10, 224
-        li      11, 240
-        li      12, 256
-        li      14, 272
-        li      15, 288
-        li      16, 304
-        lxvx    32+26, 10, 1
-        lxvx    32+27, 11, 1
-        lxvx    32+28, 12, 1
-        lxvx    32+29, 14, 1
-        lxvx    32+30, 15, 1
-        lxvx    32+31, 16, 1
-        ld      14, 56(1)
-        ld      15, 64(1)
-        ld      16, 72(1)
-        ld      17, 80(1)
-        ld      18, 88(1)
-
-        mtlr    0
-        addi    1, 1, 336
-.endm
-
-/* ===================================================================== */
-/*
- * NTT computation for layer 1, 2, 3, 4 and 5.
- */
-/* Load 8 vectors with 4x pipeline
- *
- * Assuming input registers and output vectors as follows,
- *   input offsets - curr (0, r11, r15, r17), peer (r10, r12, r16, r18)
- *   output vectors - v20, v21, v22, v23, v24, v25, v26
- */
-.macro _ntt_scalar_reduce_4x _zeta1, _zeta2, _zeta3, _zeta4
-        /* Load peer */
-        lxvd2x     32+14, 10, 5
-        lxvd2x     32+15, 12, 5
-        lxvd2x     32+16, 16, 5
-        lxvd2x     32+17, 18, 5
-
-        zeta_scalar_mul 14, \_zeta1, 20, 21       /* peer * zeta */
-        zeta_scalar_mul 15, \_zeta2, 22, 23       /* peer * zeta */
-        zeta_scalar_mul 16, \_zeta3, 24, 25       /* peer * zeta */
-        zeta_scalar_mul 17, \_zeta4, 26, 27       /* peer * zeta */
-        Barrett_reduce_delayed 20, 21, 14
-        Barrett_reduce_delayed 22, 23, 15
-        Barrett_reduce_delayed 24, 25, 16
-        Barrett_reduce_delayed 26, 27, 17
-        reduce_once_4x 14, 15, 16, 17
-
-        /* Load curr */
-        lxvd2x     32+10, 0, 5
-        lxvd2x     32+11, 11, 5
-        lxvd2x     32+12, 15, 5
-        lxvd2x     32+13, 17, 5
-
-        /* even - curr, odd - peer, odd is the updated peer */
-        /* Compute (even - odd + kPrime) */
-        vsubuhm  0, 10, 14
-        vadduhm  21, 0, V_kPrime16
-        vadduhm  20, 14, 10
-        vsubuhm  0, 11, 15
-        vadduhm  23, 0, V_kPrime16
-        vadduhm  22, 15, 11
-        vsubuhm  0, 12, 16
-        vadduhm  25, 0, V_kPrime16
-        vadduhm  24, 16, 12
-        vsubuhm  0, 13, 17
-        vadduhm  27, 0, V_kPrime16
-        vadduhm  26, 17, 13
-.endm
-
-/* Delayed writes resulting curr and peer coefficients */
-.macro delayed_writes_curr_peer _c1, _p1, _c2, _p2, _c3, _p3, _c4, _p4
-        stxvd2x    32+\_c1, 0, 5
-        stxvd2x    32+\_p1, 10, 5
-        stxvd2x    32+\_c2, 11, 5
-        stxvd2x    32+\_p2, 12, 5
-        stxvd2x    32+\_c3, 15, 5
-        stxvd2x    32+\_p3, 16, 5
-        stxvd2x    32+\_c4, 17, 5
-        stxvd2x    32+\_p4, 18, 5
-.endm
-
-.macro ntt_reduce_delayed_write
-        _ntt_scalar_reduce_4x V_ZETA, V_ZETA, V_ZETA, V_ZETA
-        reduce_once_4x 20, 22, 24, 26
-        reduce_once_4x 21, 23, 25, 27
-        delayed_writes_curr_peer 20, 21, 22, 23, 24, 25, 26, 27
-.endm
-
-/*
- * NTT layer 1, Offset between legs = 128.
- */
-.macro NTT_Layer1_4x
-        ntt_reduce_delayed_write
-        addi  5, 5, 64
-.endm
-
-/*
- * NTT layer 2, Offset between legs = 64.
- */
-.macro NTT_Layer2_4x
-        ntt_reduce_delayed_write
-        addi  5, 5, 64
-.endm
-
-/*
- * NTT layer 3, Offset between legs = 32.
- */
-.macro NTT_Layer3_4x
-        lvx     V_ZETA, 0, 14
-        addi  14, 14, 16
-        ntt_reduce_delayed_write
-        addi  5, 5, 128
-.endm
-
-/*
- * NTT layer 4, Offset between legs = 16.
- */
-.macro NTT_Layer4_4x
-        lvx     V_Z1, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z2, 0, 14
-        addi  14, 14, 16
-        _ntt_scalar_reduce_4x V_Z1, V_Z1, V_Z2, V_Z2
-        reduce_once_4x 20, 22, 24, 26
-        reduce_once_4x 21, 23, 25, 27
-        delayed_writes_curr_peer 20, 21, 22, 23, 24, 25, 26, 27
-        addi  5, 5, 128
-.endm
-
-/*
- * NTT layer 5, Offset between legs = 8.
- */
-.macro NTT_Layer5_4x
-        lvx     V_Z1, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z2, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z3, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z4, 0, 14
-        addi  14, 14, 16
-        _ntt_scalar_reduce_4x V_Z1, V_Z2, V_Z3, V_Z4
-        reduce_once_4x 20, 22, 24, 26
-        reduce_once_4x 21, 23, 25, 27
-        delayed_writes_curr_peer 20, 21, 22, 23, 24, 25, 26, 27
-        addi  5, 5, 128
-.endm
-
-/* ===================================================================== */
-/* Layer 6 layout -
- *  each load contains 4 curr and 4 peer elements
- *  xxpermidi -> 8 curr elements and 8 peer elements
- */
-.macro _load_transpose_layer6
-        lxvd2x     4, 0, 5
-        lxvd2x     5, 10, 5
-        lxvd2x     6, 11, 5
-        lxvd2x     7, 12, 5
-        lxvd2x     8, 15, 5
-        lxvd2x     9, 16, 5
-        lxvd2x     10, 17, 5
-        lxvd2x     11, 18, 5
-        xxpermdi 32+14, 5, 4, 3
-        xxpermdi     0, 5, 4, 0
-        xxpermdi 32+15, 7, 6, 3
-        xxpermdi     1, 7, 6, 0
-        xxpermdi 32+16, 9, 8, 3
-        xxpermdi     2, 9, 8, 0
-        xxpermdi 32+17, 11, 10, 3
-        xxpermdi     3, 11, 10, 0
-.endm
-
-/*
- * _layer_reduce_4x- common code for layer 6 and 7
- *
- * Assuming input registers and output vectors as follows,
- *   input offsets - curr (0, r11, r15, r17), peer (r10, r12, r16, r18)
- *   output vectors - v20, v21, v22, v23, v24, v25, v26
- */
-.macro _layer_reduce_4x
-        zeta_scalar_mul 14, V_Z1, 20, 21       /* peer * zeta */
-        zeta_scalar_mul 15, V_Z2, 22, 23       /* peer * zeta */
-        zeta_scalar_mul 16, V_Z3, 24, 25       /* peer * zeta */
-        zeta_scalar_mul 17, V_Z4, 26, 27       /* peer * zeta */
-        Barrett_reduce_delayed 20, 21, 14
-        Barrett_reduce_delayed 22, 23, 15
-        Barrett_reduce_delayed 24, 25, 16
-        Barrett_reduce_delayed 26, 27, 17
-        reduce_once_4x 14, 15, 16, 17
-
-        /* Load curr */
-        xxlor     32+10, 0, 0
-        xxlor     32+11, 1, 1
-        xxlor     32+12, 2, 2
-        xxlor     32+13, 3, 3
-
-        /* even - curr, odd - peer, odd is the updated peer */
-        /* Compute (even - odd + kPrime) */
-        vsubuhm  0, 10, 14
-        vadduhm  21, 0, V_kPrime16
-        vadduhm  20, 14, 10
-        vsubuhm  0, 11, 15
-        vadduhm  23, 0, V_kPrime16
-        vadduhm  22, 15, 11
-        vsubuhm  0, 12, 16
-        vadduhm  25, 0, V_kPrime16
-        vadduhm  24, 16, 12
-        vsubuhm  0, 13, 17
-        vadduhm  27, 0, V_kPrime16
-        vadduhm  26, 17, 13
-.endm
-
-.macro _ntt_layer6_reduce_4x
-        lvx     V_Z1, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z2, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z3, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z4, 0, 14
-        addi  14, 14, 16
-        _load_transpose_layer6
-        _layer_reduce_4x
-.endm
-
-/*
- * NTT layer 6,  Offset between legs = 4.
- */
-.macro NTT_Layer6_4x
-        _ntt_layer6_reduce_4x
-        reduce_once_4x 20, 22, 24, 26
-        reduce_once_4x 21, 23, 25, 27
-
-        xxpermdi 32+6, 32+20, 32+21, 3
-        xxpermdi 32+7, 32+20, 32+21, 0
-        xxpermdi 32+8, 32+22, 32+23, 3
-        xxpermdi 32+9, 32+22, 32+23, 0
-        xxpermdi 32+10, 32+24, 32+25, 3
-        xxpermdi 32+11, 32+24, 32+25, 0
-        xxpermdi 32+12, 32+26, 32+27, 3
-        xxpermdi 32+13, 32+26, 32+27, 0
-        delayed_writes_curr_peer 6, 7, 8, 9, 10, 11, 12, 13
-        addi  5, 5, 128
-.endm
-
-/* Layer 7 layout -
- *  each load contains 2 curr and 2 peer elements.
- *    -> curr1 curr1 peer1 peer1 curr2 curr2 peer2 peer2
- *  vmrgew and vmrgow -> 8 curr elements and 8 peer elements
- */
-.macro _load_transpose_layer7
-        lxvd2x     32+0, 0, 5
-        lxvd2x     32+6, 10, 5
-        lxvd2x     32+7, 11, 5
-        lxvd2x     32+8, 12, 5
-        lxvd2x     32+9, 15, 5
-        lxvd2x     32+10, 16, 5
-        lxvd2x     32+11, 17, 5
-        lxvd2x     32+12, 18, 5
-        vmrgew 14, 0, 6
-        vmrgow  0, 0, 6
-        vmrgew 15, 7, 8
-        vmrgow  6, 7, 8
-        vmrgew 16, 9, 10
-        vmrgow  8, 9, 10
-        vmrgew 17, 11, 12
-        vmrgow 13, 11, 12
-        xxlor  0, 32+0, 32+0
-        xxlor  1, 32+6, 32+6
-        xxlor  2, 32+8, 32+8
-        xxlor  3, 32+13, 32+13
-.endm
-
-.macro _ntt_layer7_reduce_4x
-        lvx     V_Z1, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z2, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z3, 0, 14
-        addi  14, 14, 16
-        lvx     V_Z4, 0, 14
-        addi  14, 14, 16
-        _load_transpose_layer7
-        _layer_reduce_4x
-.endm
-
-/*
- * NTT layer 7,  Offset between legs = 2.
- */
-.macro NTT_Layer7_4x
-        _ntt_layer7_reduce_4x
-        reduce_once_4x 20, 22, 24, 26
-        reduce_once_4x 21, 23, 25, 27
-
-        vmrgow  6, 21, 20
-        vmrgew  7, 21, 20
-        vmrgow  8, 23, 22
-        vmrgew  9, 23, 22
-        vmrgow  10, 25, 24
-        vmrgew  11, 25, 24
-        vmrgow  12, 27, 26
-        vmrgew  13, 27, 26
-        delayed_writes_curr_peer 7, 6, 9, 8, 11, 10, 13, 12
-        addi  5, 5, 128
-.endm
-
-.macro Load_consts
-        addis   10,2,ntt_consts@toc@ha
-        addi    10,10,ntt_consts@toc@l
-        lvx V_kPrime16, 0, 10
-        li  7, 16
-        lvx V_kPrime32, 7, 10
-        li  7, 32
-        lvx V_kBarrettMultiplier, 7, 10
-        li  7, 48
-        lvx V_kBarrettShift, 7, 10
-        li  7, 64
-        lvx V_kInverseDegree, 7, 10
-.endm
-
-/* ===================================================================== */
-/*
- * mlkem_ntt_ppc(int16_t *r)
- *   Compute forward NTT based on the following 7 layers -
- *     len = 128, 64, 32, 16, 8, 4, 2.
- *
- *   Each layer compute the coefficients on 2 legs, start and start + len*2 offsets.
- *
- *   leg 1                        leg 2
- *   -----                        -----
- *   start                        start+len*2
- *   start+next                   start+len*2+next
- *   start+next+next              start+len*2+next+next
- *   start+next+next+next         start+len*2+next+next+next
- *
- *   The resulting coefficients then store back to each leg's offset.
- *
- *   Each vector has the same corresponding zeta except len=4 and len=2.
- *
- *   len=4 has 4-4 layout which means every 4 16-bit coefficients has the same zeta.
- *   and len=2 has 2-2-2-2 layout which means every 2 16-bit coefficients has the same zeta.
- *   e.g.
- *         coeff vector    a1   a2   a3  a4  a5  a6  a7  a8
- *         zeta  vector    z1   z1   z2  z2  z3  z3  z4  z4
- *
- *   For len=4 and len=2, each vector will get permuted to leg1 and leg2. Zeta is
- *   pre-arranged for the leg1 and leg2.  After the computation, each vector needs
- *   to transpose back to its original 4-4 or 2-2-2-2 layout.
- *
- */
-.global mlkem_ntt_ppc
-.align 4
-mlkem_ntt_ppc:
-        SAVE_REGS
-
-        Load_consts
-        addis   8,2,mlkem_ntt_zetas@toc@ha
-        addi    8,8,mlkem_ntt_zetas@toc@l
-        addi    14, 8, ZETA_NTT_OFFSET
-
-.align 4
-        /*
-         * Layer 1. len = 128
-         */
-        mr      5, 3
-        li      10, 256        // offset to next peer
-        li      11, 16
-        li      12, 256+16
-        li      15, 32
-        li      16, 256+32
-        li      17, 48
-        li      18, 256+48
-
-        lvx     V_ZETA, 0, 14
-        addi  14, 14, 16
-        NTT_Layer1_4x
-        NTT_Layer1_4x
-        NTT_Layer1_4x
-        NTT_Layer1_4x
-
-.align 4
-        /*
-         * Layer 2. len = 64
-         */
-        mr      5, 3
-        li      10, 128        // offset to next peer
-        li      11, 16
-        li      12, 128+16
-        li      15, 32
-        li      16, 128+32
-        li      17, 48
-        li      18, 128+48
-
-        lvx     V_ZETA, 0, 14
-        addi  14, 14, 16
-        NTT_Layer2_4x
-        NTT_Layer2_4x
-        addi  5, 5, 128
-        lvx     V_ZETA, 0, 14
-        addi  14, 14, 16
-        NTT_Layer2_4x
-        NTT_Layer2_4x
-        addi  5, 5, 128
-
-.align 4
-        /*
-         * Layer 3. len = 32
-         */
-        mr      5, 3
-        li      10, 64        // offset to next peer
-        li      11, 16
-        li      12, 64+16
-        li      15, 32
-        li      16, 64+32
-        li      17, 48
-        li      18, 64+48
-
-        NTT_Layer3_4x
-        NTT_Layer3_4x
-        NTT_Layer3_4x
-        NTT_Layer3_4x
-
-.align 4
-        /*
-         * Layer 4. len = 16
-         */
-        mr      5, 3
-        li      10, 32        // offset to next peer
-        li      11, 16
-        li      12, 32+16
-        li      15, 64
-        li      16, 64+32
-        li      17, 64+16
-        li      18, 96+16
-
-        NTT_Layer4_4x
-        NTT_Layer4_4x
-        NTT_Layer4_4x
-        NTT_Layer4_4x
-
-.align 4
-        /*
-         * Layer 5. len = 8
-         */
-        mr      5, 3
-        li      10, 16        // offset to next peer
-        li      11, 32
-        li      12, 48
-        li      15, 64
-        li      16, 80
-        li      17, 96
-        li      18, 112
-
-        NTT_Layer5_4x
-        NTT_Layer5_4x
-        NTT_Layer5_4x
-        NTT_Layer5_4x
-
-.align 4
-        /*
-         * Layer 6. len = 4
-         *    Load zeta vectors in 4-4 layout
-         */
-        mr      5, 3
-
-        NTT_Layer6_4x
-        NTT_Layer6_4x
-        NTT_Layer6_4x
-        NTT_Layer6_4x
-
-.align 4
-        /*
-         * Layer 7. len = 2
-         *    Load zeta vectors in 2-2-2-2 layout
-         */
-        mr      5, 3
-        li      10, 16
-
-        NTT_Layer7_4x
-        NTT_Layer7_4x
-        NTT_Layer7_4x
-        NTT_Layer7_4x
-
-        RESTORE_REGS
-        blr
-.size     mlkem_ntt_ppc,.-mlkem_ntt_ppc
-
-.rodata
-.align 4
-ntt_consts:
-.short kPrime, kPrime, kPrime, kPrime, kPrime, kPrime, kPrime, kPrime
-.long  kPrime, kPrime, kPrime, kPrime
-.long  kBarrettMultiplier, kBarrettMultiplier, kBarrettMultiplier, kBarrettMultiplier
-.long  kBarrettShift, 0, kBarrettShift, 0
-.short kInverseDegree, kInverseDegree, kInverseDegree, kInverseDegree, kInverseDegree, kInverseDegree, kInverseDegree , kInverseDegree
-
-/* zetas */
-mlkem_ntt_zetas:
-/* For ntt len = 128, 64, 32, 16, 8 */
-.short  1729, 1729, 1729, 1729, 1729, 1729, 1729, 1729
-.short  2580, 2580, 2580, 2580, 2580, 2580, 2580, 2580
-.short  3289, 3289, 3289, 3289, 3289, 3289, 3289, 3289
-.short  2642, 2642, 2642, 2642, 2642, 2642, 2642, 2642
-.short  630, 630, 630, 630, 630, 630, 630, 630
-.short  1897, 1897, 1897, 1897, 1897, 1897, 1897, 1897
-.short  848, 848, 848, 848, 848, 848, 848, 848
-.short  1062, 1062, 1062, 1062, 1062, 1062, 1062, 1062
-.short  1919, 1919, 1919, 1919, 1919, 1919, 1919, 1919
-.short  193, 193, 193, 193, 193, 193, 193, 193
-.short  797, 797, 797, 797, 797, 797, 797, 797
-.short  2786, 2786, 2786, 2786, 2786, 2786, 2786, 2786
-.short  3260, 3260, 3260, 3260, 3260, 3260, 3260, 3260
-.short  569, 569, 569, 569, 569, 569, 569, 569
-.short  1746, 1746, 1746, 1746, 1746, 1746, 1746, 1746
-.short  296, 296, 296, 296, 296, 296, 296, 296
-.short  2447, 2447, 2447, 2447, 2447, 2447, 2447, 2447
-.short  1339, 1339, 1339, 1339, 1339, 1339, 1339, 1339
-.short  1476, 1476, 1476, 1476, 1476, 1476, 1476, 1476
-.short  3046, 3046, 3046, 3046, 3046, 3046, 3046, 3046
-.short  56, 56, 56, 56, 56, 56, 56, 56
-.short  2240, 2240, 2240, 2240, 2240, 2240, 2240, 2240
-.short  1333, 1333, 1333, 1333, 1333, 1333, 1333, 1333
-.short  1426, 1426, 1426, 1426, 1426, 1426, 1426, 1426
-.short  2094, 2094, 2094, 2094, 2094, 2094, 2094, 2094
-.short  535, 535, 535, 535, 535, 535, 535, 535
-.short  2882, 2882, 2882, 2882, 2882, 2882, 2882, 2882
-.short  2393, 2393, 2393, 2393, 2393, 2393, 2393, 2393
-.short  2879, 2879, 2879, 2879, 2879, 2879, 2879, 2879
-.short  1974, 1974, 1974, 1974, 1974, 1974, 1974, 1974
-.short  821, 821, 821, 821, 821, 821, 821, 821
-/* For ntt len = 4 */
-.short  289, 289, 289, 289, 331, 331, 331, 331
-.short  3253, 3253, 3253, 3253, 1756, 1756, 1756, 1756
-.short  1197, 1197, 1197, 1197, 2304, 2304, 2304, 2304
-.short  2277, 2277, 2277, 2277, 2055, 2055, 2055, 2055
-.short  650, 650, 650, 650, 1977, 1977, 1977, 1977
-.short  2513, 2513, 2513, 2513, 632, 632, 632, 632
-.short  2865, 2865, 2865, 2865, 33, 33, 33, 33
-.short  1320, 1320, 1320, 1320, 1915, 1915, 1915, 1915
-.short  2319, 2319, 2319, 2319, 1435, 1435, 1435, 1435
-.short  807, 807, 807, 807, 452, 452, 452, 452
-.short  1438, 1438, 1438, 1438, 2868, 2868, 2868, 2868
-.short  1534, 1534, 1534, 1534, 2402, 2402, 2402, 2402
-.short  2647, 2647, 2647, 2647, 2617, 2617, 2617, 2617
-.short  1481, 1481, 1481, 1481, 648, 648, 648, 648
-.short  2474, 2474, 2474, 2474, 3110, 3110, 3110, 3110
-.short  1227, 1227, 1227, 1227, 910, 910, 910, 910
-/*
- * For ntt Len=2
- * reorder zeta array, (1, 2, 3, 4) -> (4, 2, 3, 1)
- * Transpose z[0], z[1], z[2], z[3]
- *    -> z[4], z[4], z[2], z[2], z[3], z[3], z[1], z[1]
- */
-.short  2649, 2649, 2761, 2761, 583, 583, 17, 17
-.short  1100, 1100, 723, 723, 2288, 2288, 1637, 1637
-.short  233, 233, 2662, 2662, 3281, 3281, 1409, 1409
-.short  3050, 3050, 2156, 2156, 3015, 3015, 756, 756
-.short  1789, 1789, 1651, 1651, 2789, 2789, 1703, 1703
-.short  2687, 2687, 952, 952, 1461, 1461, 1847, 1847
-.short  2388, 2388, 2308, 2308, 2437, 2437, 939, 939
-.short  641, 641, 2337, 2337, 268, 268, 733, 733
-.short  3220, 3220, 2298, 2298, 2037, 2037, 1584, 1584
-.short  1645, 1645, 2549, 2549, 2090, 2090, 375, 375
-.short  757, 757, 319, 319, 2773, 2773, 1063, 1063
-.short  2594, 2594, 561, 561, 2466, 2466, 2099, 2099
-.short  1026, 1026, 1092, 1092, 403, 403, 2804, 2804
-.short  886, 886, 2150, 2150, 2775, 2775, 1143, 1143
-.short  1029, 1029, 1212, 1212, 1874, 1874, 1722, 1722
-.short  2154, 2154, 2935, 2935, 885, 885, 2110, 2110
diff --git a/crypto/ml_kem/asm/mlkem_ppc_macros_asm.inc b/crypto/ml_kem/asm/mlkem_ppc_macros_asm.inc
deleted file mode 100644
index 58598ccf58..0000000000
--- a/crypto/ml_kem/asm/mlkem_ppc_macros_asm.inc
+++ /dev/null
@@ -1,152 +0,0 @@
-/*
- * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
- *
- * Licensed under the Apache License 2.0 (the "License").  You may not use
- * this file except in compliance with the License.  You can obtain a copy
- * in the file LICENSE in the source distribution or at
- * https://www.openssl.org/source/license.html
- */
-/*
- * Copyright IBM Corp. 2025, 2026
- *
- * ===================================================================================
- * Written by Danny Tsen 
- */
-
-/* ===================================================================== */
-/* Barrett reduce vectors and constants */
-#define V_kPrime16 1
-#define V_kPrime32 2
-#define V_kBarrettMultiplier 3
-#define V_kBarrettShift 4
-#define V_kInverseDegree 5
-
-#define ML_KEM_PRIME 3329
-#define kPrime 3329
-#define kBarrettShift 24
-#define kBarrettMultiplier 5039
-#define kInverseDegree 3303
-
-/*
- * reduce_once reduces 0 <= x < 2*kPrime, mod kPrime.
- *
- * Subtract |q| if the input is larger, without exposing a side-channel,
- * avoiding the "clangover" attack.  See |constish_time_non_zero| for a
- * discussion on why the value barrier is by default omitted.
- */
-.macro reduce_once _x
-        vsubuhm  6, \_x, V_kPrime16
-        vcmpgtuh 7, V_kPrime16, 6
-        xxsel    32+\_x, 32+\_x, 32+6, 32+7
-.endm
-
-/* reduce_once_4x: pipeline reduce_once in 4x */
-.macro reduce_once_4x _x1, _x2, _x3, _x4
-        vsubuhm  6, \_x1, V_kPrime16
-        vsubuhm  8, \_x2, V_kPrime16
-        vsubuhm  10, \_x3, V_kPrime16
-        vsubuhm  12, \_x4, V_kPrime16
-        vcmpgtuh 7, V_kPrime16, 6
-        vcmpgtuh 9, V_kPrime16, 8
-        vcmpgtuh 11, V_kPrime16, 10
-        vcmpgtuh 13, V_kPrime16, 12
-        xxsel    32+\_x1, 32+\_x1, 32+6, 32+7
-        xxsel    32+\_x2, 32+\_x2, 32+8, 32+9
-        xxsel    32+\_x3, 32+\_x3, 32+10, 32+11
-        xxsel    32+\_x4, 32+\_x4, 32+12, 32+13
-.endm
-
-/* scalar multiplication = coeff * zeta */
-.macro zeta_scalar_mul _coeff, _zeta, _x0, _x1
-        vmulouh  6, \_coeff, \_zeta
-        vmuleuh  7, \_coeff, \_zeta
-        xxmrglw  32+\_x0, 32+7, 32+6
-        xxmrghw  32+\_x1, 32+7, 32+6
-.endm
-
-/*
- * Constant-time reduce x mod kPrime using Barrett reduction. x must be less
- * than kPrime + 2 * kPrime^2.  This is sufficient to reduce a product of
- * two already reduced u_int16 values, in fact it is sufficient for each
- * to be less than 2^12, because (kPrime * (2 * kPrime + 1)) > 2^24.
- *
- * This macro handles 8 coefficients elements.
- * Input vectors: x0, x1
- * Output vector:  updated peer
- * Scratch vectors: v6, v7, v10, v11, v12, v13
- *
- * Barrett_reduce_delayed-
- *    We delay reduce_once in 4x pipeline in each layer
- */
-.macro Barrett_reduce_delayed _x0, _x1, _updated_peer
-        /* uint64_t product = (uint64_t)x * kBarrettMultiplier; */
-        vmulouw  10, \_x0, V_kBarrettMultiplier
-        vmuleuw  11, \_x0, V_kBarrettMultiplier
-        vmulouw  12, \_x1, V_kBarrettMultiplier
-        vmuleuw  13, \_x1, V_kBarrettMultiplier
-
-        /* uint32_t quotient = (uint32_t)(product >> kBarrettShift); */
-        vsrd 10, 10, V_kBarrettShift
-        vsrd 11, 11, V_kBarrettShift
-        vsrd 12, 12, V_kBarrettShift
-        vsrd 13, 13, V_kBarrettShift
-        vmrgow  6, 11, 10
-        vmrgow  7, 13, 12
-
-        /* uint32_t remainder = x - quotient * kPrime; */
-        vmuluwm  10, 6, V_kPrime32
-        vmuluwm  11, 7, V_kPrime32
-        vsubuwm  6, \_x0, 10
-        vsubuwm  7, \_x1, 11
-        vpkuwus  \_updated_peer, 7, 6
-.endm
-
-.macro Barrett_reduce _x0, _x1, _updated_peer
-        Barrett_reduce_delayed \_x0, \_x1, \_updated_peer
-        reduce_once \_updated_peer
-.endm
-
-/*
- * Barrett_reduce_delayed_2x - 2 Barrett_reduce_delayed in parallel
- *   This is only 2x since we don't have enough vectors to support 4x pipeline.
- */
-.macro Barrett_reduce_delayed_2x _x0, _x1, _y0, _y1, _updated_peer1, _updated_peer2
-        /* uint64_t product = (uint64_t)x * kBarrettMultiplier; */
-        vmulouw  10, \_x0, V_kBarrettMultiplier
-        vmuleuw  11, \_x0, V_kBarrettMultiplier
-        vmulouw  12, \_x1, V_kBarrettMultiplier
-        vmuleuw  13, \_x1, V_kBarrettMultiplier
-
-        vmulouw  14, \_y0, V_kBarrettMultiplier
-        vmuleuw  15, \_y0, V_kBarrettMultiplier
-        vmulouw  16, \_y1, V_kBarrettMultiplier
-        vmuleuw  17, \_y1, V_kBarrettMultiplier
-
-        /* uint32_t quotient = (uint32_t)(product >> kBarrettShift); */
-        vsrd 10, 10, V_kBarrettShift
-        vsrd 11, 11, V_kBarrettShift
-        vsrd 12, 12, V_kBarrettShift
-        vsrd 13, 13, V_kBarrettShift
-
-        vsrd 14, 14, V_kBarrettShift
-        vsrd 15, 15, V_kBarrettShift
-        vsrd 16, 16, V_kBarrettShift
-        vsrd 17, 17, V_kBarrettShift
-         vmrgow  6, 11, 10
-         vmrgow  7, 13, 12
-         vmrgow  12, 15, 14
-         vmrgow  13, 17, 16
-
-        /* uint32_t remainder = x - quotient * kPrime; */
-        vmuluwm  10, 6, V_kPrime32
-        vmuluwm  11, 7, V_kPrime32
-        vmuluwm  14, 12, V_kPrime32
-        vmuluwm  15, 13, V_kPrime32
-         vsubuwm  6, \_x0, 10
-         vsubuwm  7, \_x1, 11
-         vsubuwm  16, \_y0, 14
-         vsubuwm  17, \_y1, 15
-        vpkuwus  \_updated_peer1, 7, 6
-        vpkuwus  \_updated_peer2, 17, 16
-.endm
-/* ===================================================================== */
diff --git a/crypto/ml_kem/build.info b/crypto/ml_kem/build.info
index e593701918..e2ea88b35d 100644
--- a/crypto/ml_kem/build.info
+++ b/crypto/ml_kem/build.info
@@ -1,29 +1,6 @@
 LIBS = ../../libcrypto
 
-$MLKEMASM=
-IF[{- !$disabled{asm} -}]
-  $MLKEMDEF_ppc64=MLKEM_NTT_PPC_ASM
-
-  IF[{- $target{sys_id} ne "AIX" && $target{sys_id} ne "MACOSX" -}]
-    $MLKEMASM_ppc64=asm/mlkem_ntt_ppc64le.S asm/mlkem_intt_ppc64le.S
-  ENDIF
-
-  # Now that we have defined all the arch specific variables, use the
-  # appropriate one, and define the appropriate macros
-  IF[$MLKEMASM_{- $target{asm_arch} -}]
-    $MLKEMASM=$MLKEMASM_{- $target{asm_arch} -}
-    $MLKEMDEF=$MLKEMDEF_{- $target{asm_arch} -}
-  ENDIF
-ENDIF
-
-$COMMON=ml_kem.c $MLKEMASM
-
 IF[{- !$disabled{'ml-kem'} -}]
-    SOURCE[../../libcrypto]=$COMMON
-    SOURCE[../../providers/libfips.a]=$COMMON
+    SOURCE[../../libcrypto]=ml_kem.c
+    SOURCE[../../providers/libfips.a]=ml_kem.c
 ENDIF
-
-# Implementations are now spread across several libraries, so the defines
-# need to be applied to all affected libraries and modules.
-DEFINE[../../libcrypto]=$MLKEMDEF
-DEFINE[../../providers/libfips.a]=$MLKEMDEF
diff --git a/crypto/ml_kem/ml_kem.c b/crypto/ml_kem/ml_kem.c
index 89960dc105..53952a9116 100644
--- a/crypto/ml_kem/ml_kem.c
+++ b/crypto/ml_kem/ml_kem.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,6 +15,10 @@
 #include "internal/constant_time.h"
 #include "internal/sha3.h"
 
+#if defined(OPENSSL_CONSTANT_TIME_VALIDATION)
+#include 
+#endif
+
 #if ML_KEM_SEED_BYTES != ML_KEM_SHARED_SECRET_BYTES + ML_KEM_RANDOM_BYTES
 #error "ML-KEM keygen seed length != shared secret + random bytes length"
 #endif
@@ -43,6 +47,29 @@
 #define SHAKE128_BLOCKSIZE SHA3_BLOCKSIZE(128)
 #endif
 
+/*
+ * Return whether a value that can only be 0 or 1 is non-zero, in constant time
+ * in practice!  The return value is a mask that is all ones if true, and all
+ * zeros otherwise (twos-complement arithmetic assumed for unsigned values).
+ *
+ * Although this is used in constant-time selects, we omit a value barrier
+ * here.  Value barriers impede auto-vectorization (likely because it forces
+ * the value to transit through a general-purpose register). On AArch64, this
+ * is a difference of 2x.
+ *
+ * We usually add value barriers to selects because Clang turns consecutive
+ * selects with the same condition into a branch instead of CMOV/CSEL. This
+ * condition does not occur in Kyber, so omitting it seems to be safe so far,
+ * but see |cbd_2|, |cbd_3|, where reduction needs to be specialised to the
+ * sign of the input, rather than adding |q| in advance, and using the generic
+ * |reduce_once|.  (David Benjamin, Chromium)
+ */
+#if 0
+#define constish_time_non_zero(b) (~constant_time_is_zero(b));
+#else
+#define constish_time_non_zero(b) (0u - (b))
+#endif
+
 /*
  * The scalar rejection-sampling buffer size needs to be a multiple of 12, but
  * is otherwise arbitrary, the preferred block size matches the internal buffer
@@ -120,6 +147,30 @@ static void scalar_encode(uint8_t *out, const scalar *s, int bits);
 #define V_SCALAR_BYTES(b) ((DEGREE / 8) * ML_KEM_##b##_DV)
 #define CTEXT_BYTES(b) (U_VECTOR_BYTES(b) + V_SCALAR_BYTES(b))
 
+#if defined(OPENSSL_CONSTANT_TIME_VALIDATION)
+
+/*
+ * CONSTTIME_SECRET takes a pointer and a number of bytes and marks that region
+ * of memory as secret. Secret data is tracked as it flows to registers and
+ * other parts of a memory. If secret data is used as a condition for a branch,
+ * or as a memory index, it will trigger warnings in valgrind.
+ */
+#define CONSTTIME_SECRET(ptr, len) VALGRIND_MAKE_MEM_UNDEFINED(ptr, len)
+
+/*
+ * CONSTTIME_DECLASSIFY takes a pointer and a number of bytes and marks that
+ * region of memory as public. Public data is not subject to constant-time
+ * rules.
+ */
+#define CONSTTIME_DECLASSIFY(ptr, len) VALGRIND_MAKE_MEM_DEFINED(ptr, len)
+
+#else
+
+#define CONSTTIME_SECRET(ptr, len)
+#define CONSTTIME_DECLASSIFY(ptr, len)
+
+#endif
+
 /*
  * Indices of slots in the vinfo tables below
  */
@@ -208,22 +259,134 @@ static const uint16_t kInverseDegree = INVERSE_DEGREE;
  * kNTTRoots = [pow(17, bitreverse(i), p) for i in range(128)]
  */
 static const uint16_t kNTTRoots[128] = {
-    0x001, 0x6c1, 0xa14, 0xcd9, 0xa52, 0x276, 0x769, 0x350,
-    0x426, 0x77f, 0x0c1, 0x31d, 0xae2, 0xcbc, 0x239, 0x6d2,
-    0x128, 0x98f, 0x53b, 0x5c4, 0xbe6, 0x038, 0x8c0, 0x535,
-    0x592, 0x82e, 0x217, 0xb42, 0x959, 0xb3f, 0x7b6, 0x335,
-    0x121, 0x14b, 0xcb5, 0x6dc, 0x4ad, 0x900, 0x8e5, 0x807,
-    0x28a, 0x7b9, 0x9d1, 0x278, 0xb31, 0x021, 0x528, 0x77b,
-    0x90f, 0x59b, 0x327, 0x1c4, 0x59e, 0xb34, 0x5fe, 0x962,
-    0xa57, 0xa39, 0x5c9, 0x288, 0x9aa, 0xc26, 0x4cb, 0x38e,
-    0x011, 0xac9, 0x247, 0xa59, 0x665, 0x2d3, 0x8f0, 0x44c,
-    0x581, 0xa66, 0xcd1, 0x0e9, 0x2f4, 0x86c, 0xbc7, 0xbea,
-    0x6a7, 0x673, 0xae5, 0x6fd, 0x737, 0x3b8, 0x5b5, 0xa7f,
-    0x3ab, 0x904, 0x985, 0x954, 0x2dd, 0x921, 0x10c, 0x281,
-    0x630, 0x8fa, 0x7f5, 0xc94, 0x177, 0x9f5, 0x82a, 0x66d,
-    0x427, 0x13f, 0xad5, 0x2f5, 0x833, 0x231, 0x9a2, 0xa22,
-    0xaf4, 0x444, 0x193, 0x402, 0x477, 0x866, 0xad7, 0x376,
-    0x6ba, 0x4bc, 0x752, 0x405, 0x83e, 0xb77, 0x375, 0x86a
+    1,
+    1729,
+    2580,
+    3289,
+    2642,
+    630,
+    1897,
+    848,
+    1062,
+    1919,
+    193,
+    797,
+    2786,
+    3260,
+    569,
+    1746,
+    296,
+    2447,
+    1339,
+    1476,
+    3046,
+    56,
+    2240,
+    1333,
+    1426,
+    2094,
+    535,
+    2882,
+    2393,
+    2879,
+    1974,
+    821,
+    289,
+    331,
+    3253,
+    1756,
+    1197,
+    2304,
+    2277,
+    2055,
+    650,
+    1977,
+    2513,
+    632,
+    2865,
+    33,
+    1320,
+    1915,
+    2319,
+    1435,
+    807,
+    452,
+    1438,
+    2868,
+    1534,
+    2402,
+    2647,
+    2617,
+    1481,
+    648,
+    2474,
+    3110,
+    1227,
+    910,
+    17,
+    2761,
+    583,
+    2649,
+    1637,
+    723,
+    2288,
+    1100,
+    1409,
+    2662,
+    3281,
+    233,
+    756,
+    2156,
+    3015,
+    3050,
+    1703,
+    1651,
+    2789,
+    1789,
+    1847,
+    952,
+    1461,
+    2687,
+    939,
+    2308,
+    2437,
+    2388,
+    733,
+    2337,
+    268,
+    641,
+    1584,
+    2298,
+    2037,
+    3220,
+    375,
+    2549,
+    2090,
+    1645,
+    1063,
+    319,
+    2773,
+    757,
+    2099,
+    561,
+    2466,
+    2594,
+    2804,
+    1092,
+    403,
+    1026,
+    1143,
+    2150,
+    2775,
+    886,
+    1722,
+    1212,
+    1874,
+    1029,
+    2110,
+    2935,
+    885,
+    2154,
 };
 
 /*
@@ -233,22 +396,134 @@ static const uint16_t kNTTRoots[128] = {
  *  0, 64, 65, ..., 127, 32, 33, ..., 63, 16, 17, ..., 31, 8, 9, ...
  */
 static const uint16_t kInverseNTTRoots[128] = {
-    0x001, 0x497, 0x98c, 0x18a, 0x4c3, 0x8fc, 0x5af, 0x845,
-    0x647, 0x98b, 0x22a, 0x49b, 0x88a, 0x8ff, 0xb6e, 0x8bd,
-    0x20d, 0x2df, 0x35f, 0xad0, 0x4ce, 0xa0c, 0x22c, 0xbc2,
-    0x8da, 0x694, 0x4d7, 0x30c, 0xb8a, 0x06d, 0x50c, 0x407,
-    0x6d1, 0xa80, 0xbf5, 0x3e0, 0xa24, 0x3ad, 0x37c, 0x3fd,
-    0x956, 0x282, 0x74c, 0x949, 0x5ca, 0x604, 0x21c, 0x68e,
-    0x65a, 0x117, 0x13a, 0x495, 0xa0d, 0xc18, 0x030, 0x29b,
-    0x780, 0x8b5, 0x411, 0xa2e, 0x69c, 0x2a8, 0xaba, 0x238,
-    0xcf0, 0x973, 0x836, 0x0db, 0x357, 0xa79, 0x738, 0x2c8,
-    0x2aa, 0x39f, 0x703, 0x1cd, 0x763, 0xb3d, 0x9da, 0x766,
-    0x3f2, 0x586, 0x7d9, 0xce0, 0x1d0, 0xa89, 0x330, 0x548,
-    0xa77, 0x4fa, 0x41c, 0x401, 0x854, 0x625, 0x04c, 0xbb6,
-    0xbe0, 0x9cc, 0x54b, 0x1c2, 0x3a8, 0x1bf, 0xaea, 0x4d3,
-    0x76f, 0x7cc, 0x441, 0xcc9, 0x11b, 0x73d, 0x7c6, 0x372,
-    0xbd9, 0x62f, 0xac8, 0x045, 0x21f, 0x9e4, 0xc40, 0x582,
-    0x8db, 0x9b1, 0x598, 0xa8b, 0x2af, 0x028, 0x2ed, 0x640
+    1,
+    1175,
+    2444,
+    394,
+    1219,
+    2300,
+    1455,
+    2117,
+    1607,
+    2443,
+    554,
+    1179,
+    2186,
+    2303,
+    2926,
+    2237,
+    525,
+    735,
+    863,
+    2768,
+    1230,
+    2572,
+    556,
+    3010,
+    2266,
+    1684,
+    1239,
+    780,
+    2954,
+    109,
+    1292,
+    1031,
+    1745,
+    2688,
+    3061,
+    992,
+    2596,
+    941,
+    892,
+    1021,
+    2390,
+    642,
+    1868,
+    2377,
+    1482,
+    1540,
+    540,
+    1678,
+    1626,
+    279,
+    314,
+    1173,
+    2573,
+    3096,
+    48,
+    667,
+    1920,
+    2229,
+    1041,
+    2606,
+    1692,
+    680,
+    2746,
+    568,
+    3312,
+    2419,
+    2102,
+    219,
+    855,
+    2681,
+    1848,
+    712,
+    682,
+    927,
+    1795,
+    461,
+    1891,
+    2877,
+    2522,
+    1894,
+    1010,
+    1414,
+    2009,
+    3296,
+    464,
+    2697,
+    816,
+    1352,
+    2679,
+    1274,
+    1052,
+    1025,
+    2132,
+    1573,
+    76,
+    2998,
+    3040,
+    2508,
+    1355,
+    450,
+    936,
+    447,
+    2794,
+    1235,
+    1903,
+    1996,
+    1089,
+    3273,
+    283,
+    1853,
+    1990,
+    882,
+    3033,
+    1583,
+    2760,
+    69,
+    543,
+    2532,
+    3136,
+    1410,
+    2267,
+    2481,
+    1432,
+    2699,
+    687,
+    40,
+    749,
+    1600,
 };
 
 /*
@@ -257,22 +532,134 @@ static const uint16_t kInverseNTTRoots[128] = {
  * ModRoots = [pow(17, 2*bitreverse(i) + 1, p) for i in range(128)]
  */
 static const uint16_t kModRoots[128] = {
-    0x011, 0xcf0, 0xac9, 0x238, 0x247, 0xaba, 0xa59, 0x2a8,
-    0x665, 0x69c, 0x2d3, 0xa2e, 0x8f0, 0x411, 0x44c, 0x8b5,
-    0x581, 0x780, 0xa66, 0x29b, 0xcd1, 0x030, 0x0e9, 0xc18,
-    0x2f4, 0xa0d, 0x86c, 0x495, 0xbc7, 0x13a, 0xbea, 0x117,
-    0x6a7, 0x65a, 0x673, 0x68e, 0xae5, 0x21c, 0x6fd, 0x604,
-    0x737, 0x5ca, 0x3b8, 0x949, 0x5b5, 0x74c, 0xa7f, 0x282,
-    0x3ab, 0x956, 0x904, 0x3fd, 0x985, 0x37c, 0x954, 0x3ad,
-    0x2dd, 0xa24, 0x921, 0x3e0, 0x10c, 0xbf5, 0x281, 0xa80,
-    0x630, 0x6d1, 0x8fa, 0x407, 0x7f5, 0x50c, 0xc94, 0x06d,
-    0x177, 0xb8a, 0x9f5, 0x30c, 0x82a, 0x4d7, 0x66d, 0x694,
-    0x427, 0x8da, 0x13f, 0xbc2, 0xad5, 0x22c, 0x2f5, 0xa0c,
-    0x833, 0x4ce, 0x231, 0xad0, 0x9a2, 0x35f, 0xa22, 0x2df,
-    0xaf4, 0x20d, 0x444, 0x8bd, 0x193, 0xb6e, 0x402, 0x8ff,
-    0x477, 0x88a, 0x866, 0x49b, 0xad7, 0x22a, 0x376, 0x98b,
-    0x6ba, 0x647, 0x4bc, 0x845, 0x752, 0x5af, 0x405, 0x8fc,
-    0x83e, 0x4c3, 0xb77, 0x18a, 0x375, 0x98c, 0x86a, 0x497
+    17,
+    3312,
+    2761,
+    568,
+    583,
+    2746,
+    2649,
+    680,
+    1637,
+    1692,
+    723,
+    2606,
+    2288,
+    1041,
+    1100,
+    2229,
+    1409,
+    1920,
+    2662,
+    667,
+    3281,
+    48,
+    233,
+    3096,
+    756,
+    2573,
+    2156,
+    1173,
+    3015,
+    314,
+    3050,
+    279,
+    1703,
+    1626,
+    1651,
+    1678,
+    2789,
+    540,
+    1789,
+    1540,
+    1847,
+    1482,
+    952,
+    2377,
+    1461,
+    1868,
+    2687,
+    642,
+    939,
+    2390,
+    2308,
+    1021,
+    2437,
+    892,
+    2388,
+    941,
+    733,
+    2596,
+    2337,
+    992,
+    268,
+    3061,
+    641,
+    2688,
+    1584,
+    1745,
+    2298,
+    1031,
+    2037,
+    1292,
+    3220,
+    109,
+    375,
+    2954,
+    2549,
+    780,
+    2090,
+    1239,
+    1645,
+    1684,
+    1063,
+    2266,
+    319,
+    3010,
+    2773,
+    556,
+    757,
+    2572,
+    2099,
+    1230,
+    561,
+    2768,
+    2466,
+    863,
+    2594,
+    735,
+    2804,
+    525,
+    1092,
+    2237,
+    403,
+    2926,
+    1026,
+    2303,
+    1143,
+    2186,
+    2150,
+    1179,
+    2775,
+    554,
+    886,
+    2443,
+    1722,
+    1607,
+    1212,
+    2117,
+    1874,
+    1455,
+    1029,
+    2300,
+    2110,
+    1219,
+    2935,
+    394,
+    885,
+    2444,
+    2154,
+    1175,
 };
 
 /*
@@ -405,69 +792,17 @@ static __owur int sample_scalar(scalar *out, EVP_MD_CTX *mdctx)
     return 1;
 }
 
-static CRYPTO_ONCE ml_kem_ntt_once = CRYPTO_ONCE_STATIC_INIT;
-
-#if defined(_ARCH_PPC64)
-#include "arch/ppc_arch.h"
-#endif
-
-#if defined(MLKEM_NTT_PPC_ASM) && defined(_ARCH_PPC64)
-/*
- * PPC64LE Platform supports.
- */
-typedef void (*ml_kem_scalar_ntt_fn)(scalar *p);
-typedef void (*ml_kem_scalar_inverse_ntt_fn)(scalar *p);
-
-static void scalar_ntt_generic(scalar *p);
-static void scalar_inverse_ntt_generic(scalar *p);
-
-static ml_kem_scalar_ntt_fn scalar_ntt = scalar_ntt_generic;
-static ml_kem_scalar_inverse_ntt_fn scalar_inverse_ntt = scalar_inverse_ntt_generic;
-
-void mlkem_ntt_ppc(uint16_t *c);
-void mlkem_inverse_ntt_ppc(uint16_t *c);
-
-static void scalar_ntt_ppc(scalar *s)
-{
-    mlkem_ntt_ppc(s->c);
-}
-
-static void scalar_inverse_ntt_ppc(scalar *s)
-{
-    mlkem_inverse_ntt_ppc(s->c);
-}
-#else
-#define scalar_ntt_generic scalar_ntt
-#define scalar_inverse_ntt_generic scalar_inverse_ntt
-#endif
-
-/*
- * Initialize NTT function pointers to PPC64le implementations if available.
- * Scalar implementations are used by default.
- */
-static void ml_kem_ntt_init(void)
-{
-#if defined(MLKEM_NTT_PPC_ASM) && defined(_ARCH_PPC64)
-#if defined(__LITTLE_ENDIAN__) || (__BYTE_ORDER__ == __ORDER_LITTLE_ENDIAN__)
-    if (OPENSSL_ppccap_P & PPC_CRYPTO207) {
-        scalar_ntt = scalar_ntt_ppc;
-        scalar_inverse_ntt = scalar_inverse_ntt_ppc;
-    }
-#endif
-#endif
-}
-
 /*-
  * reduce_once reduces 0 <= x < 2*kPrime, mod kPrime.
  *
  * Subtract |q| if the input is larger, without exposing a side-channel,
- * avoiding the "clangover" attack.  See |constish_time_true| for a
+ * avoiding the "clangover" attack.  See |constish_time_non_zero| for a
  * discussion on why the value barrier is by default omitted.
  */
 static __owur uint16_t reduce_once(uint16_t x)
 {
     const uint16_t subtracted = x - kPrime;
-    uint16_t mask = constish_time_true(subtracted >> 15);
+    uint16_t mask = constish_time_non_zero(subtracted >> 15);
 
     return (mask & x) | (~mask & subtracted);
 }
@@ -507,7 +842,7 @@ static void scalar_mult_const(scalar *s, uint16_t a)
  * elements in GF(3329^2), with the coefficients of the elements being
  * consecutive entries in |s->c|.
  */
-static void scalar_ntt_generic(scalar *s)
+static void scalar_ntt(scalar *s)
 {
     const uint16_t *roots = kNTTRoots;
     uint16_t *end = s->c + DEGREE;
@@ -539,7 +874,7 @@ static void scalar_ntt_generic(scalar *s)
  * iFFT to account for the fact that 3329 does not have a 512th root of unity,
  * using the precomputed 128 roots of unity stored in InverseNTTRoots.
  */
-static void scalar_inverse_ntt_generic(scalar *s)
+static void scalar_inverse_ntt(scalar *s)
 {
     const uint16_t *roots = kInverseNTTRoots;
     uint16_t *end = s->c + DEGREE;
@@ -767,11 +1102,11 @@ scalar_decode_decompress_add(scalar *out, const uint8_t in[DEGREE / 8])
 
     /*
      * Add |half_q_plus_1| if the bit is set, without exposing a side-channel,
-     * avoiding the "clangover" attack.  See |constish_time_true| for a
+     * avoiding the "clangover" attack.  See |constish_time_non_zero| for a
      * discussion on why the value barrier is by default omitted.
      */
 #define decode_decompress_add_bit                        \
-    mask = constish_time_true(bit0(b));                  \
+    mask = constish_time_non_zero(bit0(b));              \
     *curr = reduce_once(*curr + (mask & half_q_plus_1)); \
     curr++;                                              \
     b >>= 1
@@ -1022,20 +1357,20 @@ static __owur int cbd_2(scalar *out, uint8_t in[ML_KEM_RANDOM_BYTES + 1],
         b = *r++;
 
         /*
-         * Add |kPrime| if |value| underflowed.  See |constish_time_true| for
-         * a discussion on why the value barrier is by default omitted.  While
-         * this could have been written reduce_once(value + kPrime), this is
-         * one extra addition and small range of |value| tempts some versions
-         * of Clang to emit a branch.
+         * Add |kPrime| if |value| underflowed.  See |constish_time_non_zero|
+         * for a discussion on why the value barrier is by default omitted.
+         * While this could have been written reduce_once(value + kPrime), this
+         * is one extra addition and small range of |value| tempts some
+         * versions of Clang to emit a branch.
          */
         value = bit0(b) + bitn(1, b);
         value -= bitn(2, b) + bitn(3, b);
-        mask = constish_time_true(value >> 15);
+        mask = constish_time_non_zero(value >> 15);
         *curr++ = value + (kPrime & mask);
 
         value = bitn(4, b) + bitn(5, b);
         value -= bitn(6, b) + bitn(7, b);
-        mask = constish_time_true(value >> 15);
+        mask = constish_time_non_zero(value >> 15);
         *curr++ = value + (kPrime & mask);
     } while (curr < end);
     return 1;
@@ -1064,7 +1399,7 @@ static __owur int cbd_3(scalar *out, uint8_t in[ML_KEM_RANDOM_BYTES + 1],
         b3 = *r++;
 
         /*
-         * Add |kPrime| if |value| underflowed.  See |constish_time_true|
+         * Add |kPrime| if |value| underflowed.  See |constish_time_non_zero|
          * for a discussion on why the value barrier is by default omitted.
          * While this could have been written reduce_once(value + kPrime), this
          * is one extra addition and small range of |value| tempts some
@@ -1072,22 +1407,22 @@ static __owur int cbd_3(scalar *out, uint8_t in[ML_KEM_RANDOM_BYTES + 1],
          */
         value = bit0(b1) + bitn(1, b1) + bitn(2, b1);
         value -= bitn(3, b1) + bitn(4, b1) + bitn(5, b1);
-        mask = constish_time_true(value >> 15);
+        mask = constish_time_non_zero(value >> 15);
         *curr++ = value + (kPrime & mask);
 
         value = bitn(6, b1) + bitn(7, b1) + bit0(b2);
         value -= bitn(1, b2) + bitn(2, b2) + bitn(3, b2);
-        mask = constish_time_true(value >> 15);
+        mask = constish_time_non_zero(value >> 15);
         *curr++ = value + (kPrime & mask);
 
         value = bitn(4, b2) + bitn(5, b2) + bitn(6, b2);
         value -= bitn(7, b2) + bit0(b3) + bitn(1, b3);
-        mask = constish_time_true(value >> 15);
+        mask = constish_time_non_zero(value >> 15);
         *curr++ = value + (kPrime & mask);
 
         value = bitn(2, b3) + bitn(3, b3) + bitn(4, b3);
         value -= bitn(5, b3) + bitn(6, b3) + bitn(7, b3);
-        mask = constish_time_true(value >> 15);
+        mask = constish_time_non_zero(value >> 15);
         *curr++ = value + (kPrime & mask);
     } while (curr < end);
     return 1;
@@ -1148,7 +1483,7 @@ static __owur int gencbd_vector_ntt(scalar *out, CBD_FUNC cbd, uint8_t *counter,
  * |A| (our key->m, with the public key holding an expanded (16-bit per scalar
  * coefficient) key->t vector).
  *
- * Caller passes storage in |tmp| for two temporary vectors.
+ * Caller passes storage in |tmp| for for two temporary vectors.
  */
 static __owur int encrypt_cpa(uint8_t out[ML_KEM_SHARED_SECRET_BYTES],
     const uint8_t message[DEGREE / 8],
@@ -1449,30 +1784,6 @@ static int encap(uint8_t *ctext, uint8_t secret[ML_KEM_SHARED_SECRET_BYTES],
     return ret;
 }
 
-/*
- * Hash the input message |m'| and public key digest |h|
- * to obtain |K| and |r|.
- */
-static int hash_kr(uint8_t *out, uint8_t *in,
-    EVP_MD_CTX *mdctx, const ML_KEM_KEY *key)
-{
-    unsigned int sz, wanted;
-
-    wanted = ML_KEM_SHARED_SECRET_BYTES + ML_KEM_RANDOM_BYTES;
-    return (EVP_DigestInit_ex(mdctx, key->sha3_512_md, NULL)
-        && EVP_DigestUpdate(mdctx, in, ML_KEM_RANDOM_BYTES)
-        && EVP_DigestUpdate(mdctx, key->pkhash, ML_KEM_PKHASH_BYTES)
-        && EVP_DigestFinal_ex(mdctx, out, &sz)
-        && ossl_assert(sz == wanted));
-}
-
-/*-
- * Decap needs space for: Kbar | K | r | m'
- * We slice up a single buffer to hold them all.
- * We don't need to cleanse the public pkhash value.
- */
-#define DECAP_BUFFER_SZ (2 * ML_KEM_SHARED_SECRET_BYTES + 2 * ML_KEM_RANDOM_BYTES)
-
 /*
  * FIPS 203, Section 6.3, Algorithm 18: ML-KEM.Decaps_internal
  *
@@ -1488,23 +1799,29 @@ static int decap(uint8_t secret[ML_KEM_SHARED_SECRET_BYTES],
     const uint8_t *ctext, uint8_t *tmp_ctext, scalar *tmp,
     EVP_MD_CTX *mdctx, const ML_KEM_KEY *key)
 {
-    uint8_t buf[DECAP_BUFFER_SZ];
-    uint8_t *failure_key = buf; /* Kbar */
-    uint8_t *Kr = failure_key + ML_KEM_SHARED_SECRET_BYTES;
+    uint8_t decrypted[ML_KEM_SHARED_SECRET_BYTES + ML_KEM_PKHASH_BYTES];
+    uint8_t failure_key[ML_KEM_RANDOM_BYTES];
+    uint8_t Kr[ML_KEM_SHARED_SECRET_BYTES + ML_KEM_RANDOM_BYTES];
     uint8_t *r = Kr + ML_KEM_SHARED_SECRET_BYTES;
-    uint8_t *m = r + ML_KEM_RANDOM_BYTES; /* m' */
+    const uint8_t *pkhash = key->pkhash;
     const ML_KEM_VINFO *vinfo = key->vinfo;
     int i;
     uint8_t mask;
-    int ret = 0;
 
     /*
-     * The functions called below (kdf, hash_kr, encrypt_cpa) only fail on
-     * catastrophic failure of an underlying SHA3/SHAKE primitive, for example
-     * a memory allocation failure in EVP_DigestInit_ex(). None of these
-     * failures are dependent on the ciphertext content, so reporting them as a
-     * hard error does not create a chosen-ciphertext oracle and does not affect
-     * the constant-time properties of the implicit rejection path below.
+     * If our KDF is unavailable, fail early! Otherwise, keep going ignoring
+     * any further errors, returning success, and whatever we got for a shared
+     * secret.  The decrypt_cpa() function is just arithmetic on secret data,
+     * so should not be subject to failure that makes its output predictable.
+     *
+     * We guard against "should never happen" catastrophic failure of the
+     * "pure" function |hash_g| by overwriting the shared secret with the
+     * content of the failure key and returning early, if nevertheless hash_g
+     * fails.  This is not constant-time, but a failure of |hash_g| already
+     * implies loss of side-channel resistance.
+     *
+     * The same action is taken, if also |encrypt_cpa| should catastrophically
+     * fail, due to failure of the |PRF| underlying the CBD functions.
      */
     if (!kdf(failure_key, key->z, ctext, vinfo->ctext_bytes, mdctx, key)) {
         ERR_raise_data(ERR_LIB_CRYPTO, ERR_R_INTERNAL_ERROR,
@@ -1512,22 +1829,21 @@ static int decap(uint8_t secret[ML_KEM_SHARED_SECRET_BYTES],
             vinfo->algorithm_name);
         return 0;
     }
-    decrypt_cpa(m, ctext, tmp, key);
-    if (!hash_kr(Kr, m, mdctx, key)
-        || !encrypt_cpa(tmp_ctext, m, r, tmp, mdctx, key)) {
-        ERR_raise_data(ERR_LIB_CRYPTO, ERR_R_INTERNAL_ERROR,
-            "internal error while performing %s decapsulation",
-            vinfo->algorithm_name);
-        goto end;
+    decrypt_cpa(decrypted, ctext, tmp, key);
+    memcpy(decrypted + ML_KEM_SHARED_SECRET_BYTES, pkhash, ML_KEM_PKHASH_BYTES);
+    if (!hash_g(Kr, decrypted, sizeof(decrypted), mdctx, key)
+        || !encrypt_cpa(tmp_ctext, decrypted, r, tmp, mdctx, key)) {
+        memcpy(secret, failure_key, ML_KEM_SHARED_SECRET_BYTES);
+        OPENSSL_cleanse(decrypted, ML_KEM_SHARED_SECRET_BYTES);
+        return 1;
     }
     mask = constant_time_eq_int_8(0,
         CRYPTO_memcmp(ctext, tmp_ctext, vinfo->ctext_bytes));
     for (i = 0; i < ML_KEM_SHARED_SECRET_BYTES; i++)
         secret[i] = constant_time_select_8(mask, Kr[i], failure_key[i]);
-    ret = 1;
-end:
-    OPENSSL_cleanse(buf, DECAP_BUFFER_SZ);
-    return ret;
+    OPENSSL_cleanse(decrypted, ML_KEM_SHARED_SECRET_BYTES);
+    OPENSSL_cleanse(Kr, sizeof(Kr));
+    return 1;
 }
 
 /*
@@ -1537,8 +1853,7 @@ end:
  * The caller should only store private data in `priv` *after* a successful
  * (non-zero) return from this function.
  */
-static __owur int add_storage(scalar *pub, scalar *priv,
-    int private, int dup, ML_KEM_KEY *key)
+static __owur int add_storage(scalar *pub, scalar *priv, int private, ML_KEM_KEY *key)
 {
     int rank = key->vinfo->rank;
 
@@ -1553,11 +1868,9 @@ static __owur int add_storage(scalar *pub, scalar *priv,
     }
 
     /*
-     * We're adding key material, set up rho and pkhash to point to the
-     * rho_pkhash buffer.  Zero the key hash when creating fresh keys.
+     * We're adding key material, set up rho and pkhash to point to the rho_pkhash buffer
      */
-    if (dup == 0)
-        memset(key->rho_pkhash, 0, sizeof(key->rho_pkhash));
+    memset(key->rho_pkhash, 0, sizeof(key->rho_pkhash));
     key->rho = key->rho_pkhash;
     key->pkhash = key->rho_pkhash + ML_KEM_RANDOM_BYTES;
     key->d = key->z = NULL;
@@ -1617,8 +1930,6 @@ void ossl_ml_kem_key_reset(ML_KEM_KEY *key)
 /* Retrieve the parameters of one of the ML-KEM variants */
 const ML_KEM_VINFO *ossl_ml_kem_get_vinfo(int evp_type)
 {
-    (void)CRYPTO_THREAD_run_once(&ml_kem_ntt_once, ml_kem_ntt_init);
-
     switch (evp_type) {
     case EVP_PKEY_ML_KEM_512:
         return &vinfo_map[ML_KEM_512_VINFO];
@@ -1630,27 +1941,6 @@ const ML_KEM_VINFO *ossl_ml_kem_get_vinfo(int evp_type)
     return NULL;
 }
 
-/*
- * @brief Fetch digest algorithms based on a propq.
- * For the import case ossl_ml_kem_key_new() gets passed a NULL propq,
- * so the propq is optionally deferred to the import using OSSL_PARAM.
- */
-int ossl_ml_kem_key_fetch_digest(ML_KEM_KEY *key, const char *propq)
-{
-    if (key->shake128_md != NULL) {
-        EVP_MD_free(key->shake128_md);
-        EVP_MD_free(key->shake256_md);
-        EVP_MD_free(key->sha3_256_md);
-        EVP_MD_free(key->sha3_512_md);
-    }
-    key->shake128_md = EVP_MD_fetch(key->libctx, "SHAKE128", propq);
-    key->shake256_md = EVP_MD_fetch(key->libctx, "SHAKE256", propq);
-    key->sha3_256_md = EVP_MD_fetch(key->libctx, "SHA3-256", propq);
-    key->sha3_512_md = EVP_MD_fetch(key->libctx, "SHA3-512", propq);
-    return (key->shake128_md != NULL && key->shake256_md != NULL
-        && key->sha3_256_md != NULL && key->sha3_512_md != NULL);
-}
-
 ML_KEM_KEY *ossl_ml_kem_key_new(OSSL_LIB_CTX *libctx, const char *properties,
     int evp_type)
 {
@@ -1669,10 +1959,17 @@ ML_KEM_KEY *ossl_ml_kem_key_new(OSSL_LIB_CTX *libctx, const char *properties,
     key->vinfo = vinfo;
     key->libctx = libctx;
     key->prov_flags = ML_KEM_KEY_PROV_FLAGS_DEFAULT;
+    key->shake128_md = EVP_MD_fetch(libctx, "SHAKE128", properties);
+    key->shake256_md = EVP_MD_fetch(libctx, "SHAKE256", properties);
+    key->sha3_256_md = EVP_MD_fetch(libctx, "SHA3-256", properties);
+    key->sha3_512_md = EVP_MD_fetch(libctx, "SHA3-512", properties);
     key->d = key->z = key->rho = key->pkhash = key->encoded_dk = key->seedbuf = NULL;
     key->s = key->m = key->t = NULL;
-    key->shake128_md = key->shake256_md = key->sha3_256_md = key->sha3_512_md = NULL;
-    if (ossl_ml_kem_key_fetch_digest(key, properties))
+
+    if (key->shake128_md != NULL
+        && key->shake256_md != NULL
+        && key->sha3_256_md != NULL
+        && key->sha3_512_md != NULL)
         return key;
 
     ossl_ml_kem_key_free(key);
@@ -1686,6 +1983,8 @@ ML_KEM_KEY *ossl_ml_kem_key_dup(const ML_KEM_KEY *key, int selection)
 {
     int ok = 0;
     ML_KEM_KEY *ret;
+    void *tmp_pub;
+    void *tmp_priv;
 
     if (key == NULL)
         return NULL;
@@ -1707,27 +2006,28 @@ ML_KEM_KEY *ossl_ml_kem_key_dup(const ML_KEM_KEY *key, int selection)
         selection = 0;
     else if (!ossl_ml_kem_have_prvkey(key))
         selection &= ~OSSL_KEYMGMT_SELECT_PRIVATE_KEY;
-    else if ((selection & OSSL_KEYMGMT_SELECT_PRIVATE_KEY) != 0)
-        selection &= ~OSSL_KEYMGMT_SELECT_PUBLIC_KEY;
 
     switch (selection & OSSL_KEYMGMT_SELECT_KEYPAIR) {
     case 0:
         ok = 1;
         break;
     case OSSL_KEYMGMT_SELECT_PUBLIC_KEY:
-        ok = add_storage(OPENSSL_memdup(key->t, key->vinfo->puballoc), NULL, 0, 1, ret);
+        ok = add_storage(OPENSSL_memdup(key->t, key->vinfo->puballoc), NULL, 0, ret);
         break;
     case OSSL_KEYMGMT_SELECT_PRIVATE_KEY:
-        /* Frees both and returns 0 if either is NULL */
-        ok = add_storage(OPENSSL_memdup(key->t, key->vinfo->puballoc),
-            OPENSSL_secure_malloc(key->vinfo->prvalloc), 1, 1, ret);
-        if (ok) {
-            memcpy(ret->s, key->s, key->vinfo->prvalloc);
-
-            /* Duplicated keys retain |d|, if available */
-            if (key->d != NULL)
-                ret->d = ret->z + ML_KEM_RANDOM_BYTES;
+        tmp_pub = OPENSSL_memdup(key->t, key->vinfo->puballoc);
+        if (tmp_pub == NULL)
+            break;
+        tmp_priv = OPENSSL_secure_malloc(key->vinfo->prvalloc);
+        if (tmp_priv == NULL) {
+            OPENSSL_free(tmp_pub);
+            break;
         }
+        if ((ok = add_storage(tmp_pub, tmp_priv, 1, ret)) != 0)
+            memcpy(tmp_priv, key->s, key->vinfo->prvalloc);
+        /* Duplicated keys retain |d|, if available */
+        if (key->d != NULL)
+            ret->d = ret->z + ML_KEM_RANDOM_BYTES;
         break;
     }
 
@@ -1840,7 +2140,7 @@ int ossl_ml_kem_parse_public_key(const uint8_t *in, size_t len, ML_KEM_KEY *key)
         || (mdctx = EVP_MD_CTX_new()) == NULL)
         return 0;
 
-    if (add_storage(OPENSSL_malloc(vinfo->puballoc), NULL, 0, 0, key))
+    if (add_storage(OPENSSL_malloc(vinfo->puballoc), NULL, 0, key))
         ret = parse_pubkey(in, mdctx, key);
 
     if (!ret)
@@ -1868,11 +2168,8 @@ int ossl_ml_kem_parse_private_key(const uint8_t *in, size_t len,
         || (mdctx = EVP_MD_CTX_new()) == NULL)
         return 0;
 
-    /* Clear any unused seed */
-    ossl_ml_kem_key_reset(key);
-
     if (add_storage(OPENSSL_malloc(vinfo->puballoc),
-            OPENSSL_secure_malloc(vinfo->prvalloc), 1, 0, key))
+            OPENSSL_secure_malloc(vinfo->prvalloc), 1, key))
         ret = parse_prvkey(in, mdctx, key);
 
     if (!ret)
@@ -1921,7 +2218,7 @@ int ossl_ml_kem_genkey(uint8_t *pubenc, size_t publen, ML_KEM_KEY *key)
     CONSTTIME_SECRET(seed, ML_KEM_SEED_BYTES);
 
     if (add_storage(OPENSSL_malloc(vinfo->puballoc),
-            OPENSSL_secure_malloc(vinfo->prvalloc), 1, 0, key))
+            OPENSSL_secure_malloc(vinfo->prvalloc), 1, key))
         ret = genkey(seed, mdctx, pubenc, key);
     OPENSSL_cleanse(seed, sizeof(seed));
 
@@ -1974,22 +2271,17 @@ int ossl_ml_kem_encap_seed(uint8_t *ctext, size_t clen,
      * We stack-allocate these.
      */
 #define case_encap_seed(bits)                                        \
-    {                                                                \
+    case EVP_PKEY_ML_KEM_##bits: {                                   \
         scalar tmp[2 * ML_KEM_##bits##_RANK];                        \
                                                                      \
         ret = encap(ctext, shared_secret, entropy, tmp, mdctx, key); \
         OPENSSL_cleanse((void *)tmp, sizeof(tmp));                   \
+        break;                                                       \
     }
     switch (vinfo->evp_type) {
-    case EVP_PKEY_ML_KEM_512:
         case_encap_seed(512);
-        break;
-    case EVP_PKEY_ML_KEM_768:
         case_encap_seed(768);
-        break;
-    case EVP_PKEY_ML_KEM_1024:
         case_encap_seed(1024);
-        break;
     }
 #undef case_encap_seed
 
@@ -2032,27 +2324,25 @@ int ossl_ml_kem_decap(uint8_t *shared_secret, size_t slen,
 #endif
 
     /* Need a private key here */
-    if (!ossl_ml_kem_have_prvkey(key)
-        || shared_secret == NULL
-        || slen < ML_KEM_SHARED_SECRET_BYTES)
+    if (!ossl_ml_kem_have_prvkey(key))
         return 0;
     vinfo = key->vinfo;
 
-    if (slen != ML_KEM_SHARED_SECRET_BYTES
+    if (shared_secret == NULL || slen != ML_KEM_SHARED_SECRET_BYTES
         || ctext == NULL || clen != vinfo->ctext_bytes
         || (mdctx = EVP_MD_CTX_new()) == NULL) {
         (void)RAND_bytes_ex(key->libctx, shared_secret,
             ML_KEM_SHARED_SECRET_BYTES, vinfo->secbits);
         return 0;
     }
+#if defined(OPENSSL_CONSTANT_TIME_VALIDATION)
     /*
      * Data derived from |s| and |z| defaults secret, and to avoid side-channel
      * leaks should not influence control flow.
      */
-#if defined(OPENSSL_CONSTANT_TIME_VALIDATION)
-    classify_bytes = vinfo->rank * sizeof(scalar) + ML_KEM_RANDOM_BYTES;
-#endif
+    classify_bytes = 2 * sizeof(scalar) + ML_KEM_RANDOM_BYTES;
     CONSTTIME_SECRET(key->s, classify_bytes);
+#endif
 
     /*-
      * This avoids the need to handle allocation failures for two (max 2KB
@@ -2061,25 +2351,19 @@ int ossl_ml_kem_decap(uint8_t *shared_secret, size_t slen,
      * We stack-allocate these.
      */
 #define case_decap(bits)                                          \
-    {                                                             \
+    case EVP_PKEY_ML_KEM_##bits: {                                \
         uint8_t cbuf[CTEXT_BYTES(bits)];                          \
         scalar tmp[2 * ML_KEM_##bits##_RANK];                     \
                                                                   \
         ret = decap(shared_secret, ctext, cbuf, tmp, mdctx, key); \
         OPENSSL_cleanse((void *)tmp, sizeof(tmp));                \
+        break;                                                    \
     }
     switch (vinfo->evp_type) {
-    case EVP_PKEY_ML_KEM_512:
         case_decap(512);
-        break;
-    case EVP_PKEY_ML_KEM_768:
         case_decap(768);
-        break;
-    case EVP_PKEY_ML_KEM_1024:
         case_decap(1024);
-        break;
     }
-#undef case_decap
 
     /* Declassify secret inputs and derived outputs before returning control */
     CONSTTIME_DECLASSIFY(key->s, classify_bytes);
@@ -2087,6 +2371,7 @@ int ossl_ml_kem_decap(uint8_t *shared_secret, size_t slen,
     EVP_MD_CTX_free(mdctx);
 
     return ret;
+#undef case_decap
 }
 
 int ossl_ml_kem_pubkey_cmp(const ML_KEM_KEY *key1, const ML_KEM_KEY *key2)
diff --git a/crypto/modes/asm/aes-gcm-armv8-unroll8_64.pl b/crypto/modes/asm/aes-gcm-armv8-unroll8_64.pl
index 81d1c195a9..d516359eb8 100644
--- a/crypto/modes/asm/aes-gcm-armv8-unroll8_64.pl
+++ b/crypto/modes/asm/aes-gcm-armv8-unroll8_64.pl
@@ -170,7 +170,7 @@ open OUT,"| \"$^X\" $xlate $flavour $output";
 *STDOUT=*OUT;
 
 $code=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 #if __ARM_MAX_ARCH__>=8
 ___
diff --git a/crypto/modes/asm/aes-gcm-armv8_64.pl b/crypto/modes/asm/aes-gcm-armv8_64.pl
index d4c076961b..507e8c341e 100755
--- a/crypto/modes/asm/aes-gcm-armv8_64.pl
+++ b/crypto/modes/asm/aes-gcm-armv8_64.pl
@@ -225,7 +225,7 @@ my $rk4v="v22";
 my $rk4d="d22";
 
 $code=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 #if __ARM_MAX_ARCH__>=8
 ___
diff --git a/crypto/modes/asm/aes-gcm-avx512.pl b/crypto/modes/asm/aes-gcm-avx512.pl
index ad6461f9e5..054672bb6b 100644
--- a/crypto/modes/asm/aes-gcm-avx512.pl
+++ b/crypto/modes/asm/aes-gcm-avx512.pl
@@ -72,13 +72,6 @@ if (!$avx512vaes && `$ENV{CC} -v 2>&1`
     }
 }
 
-if (!$avx512vaes && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-    =~ /#define __clang_major__.([0-9]+)/) {
-    if ($1) {
-        $avx512vaes = ($1>=11); #icx started with clang 11
-    }
-}
-
 open OUT, "| \"$^X\" \"$xlate\" $flavour \"$output\""
   or die "can't call $xlate: $!";
 *STDOUT = *OUT;
diff --git a/crypto/modes/asm/aes-gcm-ppc.pl b/crypto/modes/asm/aes-gcm-ppc.pl
index 7355c31cc1..e8a215027e 100644
--- a/crypto/modes/asm/aes-gcm-ppc.pl
+++ b/crypto/modes/asm/aes-gcm-ppc.pl
@@ -1,6 +1,6 @@
 #! /usr/bin/env perl
-# Copyright 2014-2026 The OpenSSL Project Authors. All Rights Reserved.
-# Copyright 2025- IBM Corp. All rights reserved
+# Copyright 2014-2022 The OpenSSL Project Authors. All Rights Reserved.
+# Copyright 2021- IBM Inc. All rights reserved
 #
 # Licensed under the Apache License 2.0 (the "License").  You may not use
 # this file except in compliance with the License.  You can obtain a copy
@@ -8,9 +8,7 @@
 # https://www.openssl.org/source/license.html
 #
 #===================================================================================
-# Accelerated AES-GCM stitched implementation for ppc64le.
-#
-# Written by Danny Tsen 
+# Written by Danny Tsen  for OpenSSL Project,
 #
 # GHASH is based on the Karatsuba multiplication method.
 #
@@ -34,519 +32,420 @@
 # v31 - counter 1
 #
 # AES used,
-#     vs0 - round key 0
+#     vs0 - vs14 for round keys
 #     v15, v16, v17, v18, v19, v20, v21, v22 for 8 blocks (encrypted)
 #
 # This implementation uses stitched AES-GCM approach to improve overall performance.
 # AES is implemented with 8x blocks and GHASH is using 2 4x blocks.
 #
+# Current large block (16384 bytes) performance per second with 128 bit key --
+#
+#                        Encrypt  Decrypt
+# Power10[le] (3.5GHz)   5.32G    5.26G
+#
 # ===================================================================================
 #
-use strict;
-use warnings;
-
 # $output is the last argument if it looks like a file (it has an extension)
 # $flavour is the first argument if it doesn't look like a file
-my $output = $#ARGV >= 0 && $ARGV[$#ARGV] =~ m|\.\w+$| ? pop : undef;
-my $flavour = $#ARGV >= 0 && $ARGV[0] !~ m|\.| ? shift : undef;
+$output = $#ARGV >= 0 && $ARGV[$#ARGV] =~ m|\.\w+$| ? pop : undef;
+$flavour = $#ARGV >= 0 && $ARGV[0] !~ m|\.| ? shift : undef;
 
-$output and open STDOUT,">$output";
+if ($flavour =~ /64/) {
+	$SIZE_T=8;
+	$LRSAVE=2*$SIZE_T;
+	$STU="stdu";
+	$POP="ld";
+	$PUSH="std";
+	$UCMP="cmpld";
+	$SHRI="srdi";
+} elsif ($flavour =~ /32/) {
+	$SIZE_T=4;
+	$LRSAVE=$SIZE_T;
+	$STU="stwu";
+	$POP="lwz";
+	$PUSH="stw";
+	$UCMP="cmplw";
+	$SHRI="srwi";
+} else { die "nonsense $flavour"; }
 
-my $code.=<<___;
+$sp="r1";
+$FRAME=6*$SIZE_T+13*16;	# 13*16 is for v20-v31 offload
+
+$0 =~ m/(.*[\/\\])[^\/\\]+$/; $dir=$1;
+( $xlate="${dir}ppc-xlate.pl" and -f $xlate ) or
+( $xlate="${dir}../../perlasm/ppc-xlate.pl" and -f $xlate) or
+die "can't locate ppc-xlate.pl";
+
+open STDOUT,"| $^X $xlate $flavour \"$output\""
+    or die "can't call $xlate: $!";
+
+$code=<<___;
 .machine        "any"
 .text
 
-.macro SAVE_REGS
-	mflr 0
-	std 0, 16(1)
-	stdu 1,-512(1)
-
-	std	14, 112(1)
-	std	15, 120(1)
-	std	16, 128(1)
-	std	17, 136(1)
-	std	18, 144(1)
-	std	19, 152(1)
-	std	20, 160(1)
-	std	21, 168(1)
-	std	22, 176(1)
-	std	23, 184(1)
-	std	24, 192(1)
-
-	stxv	32+20, 256(1)
-	stxv	32+21, 256+16(1)
-	stxv	32+22, 256+32(1)
-	stxv	32+23, 256+48(1)
-	stxv	32+24, 256+64(1)
-	stxv	32+25, 256+80(1)
-	stxv	32+26, 256+96(1)
-	stxv	32+27, 256+112(1)
-	stxv	32+28, 256+128(1)
-	stxv	32+29, 256+144(1)
-	stxv	32+30, 256+160(1)
-	stxv	32+31, 256+176(1)
-.endm # SAVE_REGS
-
-.macro RESTORE_REGS
-	lxv	32+20, 256(1)
-	lxv	32+21, 256+16(1)
-	lxv	32+22, 256+32(1)
-	lxv	32+23, 256+48(1)
-	lxv	32+24, 256+64(1)
-	lxv	32+25, 256+80(1)
-	lxv	32+26, 256+96(1)
-	lxv	32+27, 256+112(1)
-	lxv	32+28, 256+128(1)
-	lxv	32+29, 256+144(1)
-	lxv	32+30, 256+160(1)
-	lxv	32+31, 256+176(1)
-
-	ld	14, 112(1)
-	ld	15, 120(1)
-	ld	16, 128(1)
-	ld	17, 136(1)
-	ld	18, 144(1)
-	ld	19, 152(1)
-	ld	20, 160(1)
-	ld	21, 168(1)
-	ld	22, 176(1)
-	ld	23, 184(1)
-	ld	24, 192(1)
-
-	addi    1, 1, 512
-	ld 0, 16(1)
-	mtlr 0
-.endm # RESTORE_REGS
-
 # 4x loops
-.macro AES_CIPHER_4x r
-	vcipher	15, 15, \\r
-	vcipher	16, 16, \\r
-	vcipher	17, 17, \\r
-	vcipher	18, 18, \\r
+# v15 - v18 - input states
+# vs1 - vs9 - round keys
+#
+.macro Loop_aes_middle4x
+	xxlor	19+32, 1, 1
+	xxlor	20+32, 2, 2
+	xxlor	21+32, 3, 3
+	xxlor	22+32, 4, 4
+
+	vcipher	15, 15, 19
+	vcipher	16, 16, 19
+	vcipher	17, 17, 19
+	vcipher	18, 18, 19
+
+	vcipher	15, 15, 20
+	vcipher	16, 16, 20
+	vcipher	17, 17, 20
+	vcipher	18, 18, 20
+
+	vcipher	15, 15, 21
+	vcipher	16, 16, 21
+	vcipher	17, 17, 21
+	vcipher	18, 18, 21
+
+	vcipher	15, 15, 22
+	vcipher	16, 16, 22
+	vcipher	17, 17, 22
+	vcipher	18, 18, 22
+
+	xxlor	19+32, 5, 5
+	xxlor	20+32, 6, 6
+	xxlor	21+32, 7, 7
+	xxlor	22+32, 8, 8
+
+	vcipher	15, 15, 19
+	vcipher	16, 16, 19
+	vcipher	17, 17, 19
+	vcipher	18, 18, 19
+
+	vcipher	15, 15, 20
+	vcipher	16, 16, 20
+	vcipher	17, 17, 20
+	vcipher	18, 18, 20
+
+	vcipher	15, 15, 21
+	vcipher	16, 16, 21
+	vcipher	17, 17, 21
+	vcipher	18, 18, 21
+
+	vcipher	15, 15, 22
+	vcipher	16, 16, 22
+	vcipher	17, 17, 22
+	vcipher	18, 18, 22
+
+	xxlor	23+32, 9, 9
+	vcipher	15, 15, 23
+	vcipher	16, 16, 23
+	vcipher	17, 17, 23
+	vcipher	18, 18, 23
 .endm
 
 # 8x loops
-.macro AES_CIPHER_8x r
-	vcipher	15, 15, \\r
-	vcipher	16, 16, \\r
-	vcipher	17, 17, \\r
-	vcipher	18, 18, \\r
-	vcipher	19, 19, \\r
-	vcipher	20, 20, \\r
-	vcipher	21, 21, \\r
-	vcipher	22, 22, \\r
-.endm
+# v15 - v22 - input states
+# vs1 - vs9 - round keys
+#
+.macro Loop_aes_middle8x
+	xxlor	23+32, 1, 1
+	xxlor	24+32, 2, 2
+	xxlor	25+32, 3, 3
+	xxlor	26+32, 4, 4
 
-.macro LOOP_8AES_STATE
-	AES_CIPHER_8x 23
-	AES_CIPHER_8x 24
-	AES_CIPHER_8x 25
-	AES_CIPHER_8x 26
-	AES_CIPHER_8x 27
-	AES_CIPHER_8x 28
-	AES_CIPHER_8x 29
-	AES_CIPHER_8x 1
+	vcipher	15, 15, 23
+	vcipher	16, 16, 23
+	vcipher	17, 17, 23
+	vcipher	18, 18, 23
+	vcipher	19, 19, 23
+	vcipher	20, 20, 23
+	vcipher	21, 21, 23
+	vcipher	22, 22, 23
+
+	vcipher	15, 15, 24
+	vcipher	16, 16, 24
+	vcipher	17, 17, 24
+	vcipher	18, 18, 24
+	vcipher	19, 19, 24
+	vcipher	20, 20, 24
+	vcipher	21, 21, 24
+	vcipher	22, 22, 24
+
+	vcipher	15, 15, 25
+	vcipher	16, 16, 25
+	vcipher	17, 17, 25
+	vcipher	18, 18, 25
+	vcipher	19, 19, 25
+	vcipher	20, 20, 25
+	vcipher	21, 21, 25
+	vcipher	22, 22, 25
+
+	vcipher	15, 15, 26
+	vcipher	16, 16, 26
+	vcipher	17, 17, 26
+	vcipher	18, 18, 26
+	vcipher	19, 19, 26
+	vcipher	20, 20, 26
+	vcipher	21, 21, 26
+	vcipher	22, 22, 26
+
+	xxlor	23+32, 5, 5
+	xxlor	24+32, 6, 6
+	xxlor	25+32, 7, 7
+	xxlor	26+32, 8, 8
+
+	vcipher	15, 15, 23
+	vcipher	16, 16, 23
+	vcipher	17, 17, 23
+	vcipher	18, 18, 23
+	vcipher	19, 19, 23
+	vcipher	20, 20, 23
+	vcipher	21, 21, 23
+	vcipher	22, 22, 23
+
+	vcipher	15, 15, 24
+	vcipher	16, 16, 24
+	vcipher	17, 17, 24
+	vcipher	18, 18, 24
+	vcipher	19, 19, 24
+	vcipher	20, 20, 24
+	vcipher	21, 21, 24
+	vcipher	22, 22, 24
+
+	vcipher	15, 15, 25
+	vcipher	16, 16, 25
+	vcipher	17, 17, 25
+	vcipher	18, 18, 25
+	vcipher	19, 19, 25
+	vcipher	20, 20, 25
+	vcipher	21, 21, 25
+	vcipher	22, 22, 25
+
+	vcipher	15, 15, 26
+	vcipher	16, 16, 26
+	vcipher	17, 17, 26
+	vcipher	18, 18, 26
+	vcipher	19, 19, 26
+	vcipher	20, 20, 26
+	vcipher	21, 21, 26
+	vcipher	22, 22, 26
+
+	xxlor	23+32, 9, 9
+	vcipher	15, 15, 23
+	vcipher	16, 16, 23
+	vcipher	17, 17, 23
+	vcipher	18, 18, 23
+	vcipher	19, 19, 23
+	vcipher	20, 20, 23
+	vcipher	21, 21, 23
+	vcipher	22, 22, 23
 .endm
 
 #
-# PPC_GFMUL128_8x: Compute hash values of 8 blocks based on Karatsuba method.
+# Compute 4x hash values based on Karatsuba method.
 #
-# S1 should xor with the previous digest
-#
-# Xi = v0
-# H Poly = v2
-# Hash keys = v3 - v14
-# vs10: vpermxor vector
-# Scratch: v23 - v29
-#
-.macro PPC_GFMUL128_8x
+ppc_aes_gcm_ghash:
+	vxor		15, 15, 0
 
-	vpmsumd	23, 12, 15		# H4.L * X.L
-	vpmsumd	24, 9, 16
-	vpmsumd	25, 6, 17
-	vpmsumd	26, 3, 18
+	xxlxor		29, 29, 29
 
-	vxor	23, 23, 24
-	vxor	23, 23, 25
-	vxor	23, 23, 26		# L
+	vpmsumd		23, 12, 15		# H4.L * X.L
+	vpmsumd		24, 9, 16
+	vpmsumd		25, 6, 17
+	vpmsumd		26, 3, 18
 
-	vpmsumd	27, 13, 15		# H4.L * X.H + H4.H * X.L
-	vpmsumd	28, 10, 16		# H3.L * X1.H + H3.H * X1.L
-	vpmsumd	25, 7, 17
-	vpmsumd	26, 4, 18
+	vxor		23, 23, 24
+	vxor		23, 23, 25
+	vxor		23, 23, 26		# L
 
-	vxor	24, 27, 28
-	vxor	24, 24, 25
-	vxor	24, 24, 26		# M
+	vpmsumd		24, 13, 15		# H4.L * X.H + H4.H * X.L
+	vpmsumd		25, 10, 16		# H3.L * X1.H + H3.H * X1.L
+	vpmsumd		26, 7, 17
+	vpmsumd		27, 4, 18
 
-	vpmsumd	26, 14, 15		# H4.H * X.H
-	vpmsumd	27, 11, 16
-	vpmsumd	28, 8, 17
-	vpmsumd	29, 5, 18
-
-	vxor	26, 26, 27
-	vxor	26, 26, 28
-	vxor	26, 26, 29
+	vxor		24, 24, 25
+	vxor		24, 24, 26
+	vxor		24, 24, 27		# M
 
 	# sum hash and reduction with H Poly
-	vpmsumd	28, 23, 2		# reduction
+	vpmsumd		28, 23, 2		# reduction
 
-	vxor	1, 1, 1
-	vsldoi	25, 24, 1, 8		# mL
-	vsldoi	1, 1, 24, 8		# mH
-	vxor	23, 23, 25		# mL + L
+	xxlor		29+32, 29, 29
+	vsldoi		26, 24, 29, 8		# mL
+	vsldoi		29, 29, 24, 8		# mH
+	vxor		23, 23, 26		# mL + L
 
-	# This performs swap and xor like,
-	#   vsldoi	23, 23, 23, 8		# swap
-	#   vxor	23, 23, 28
-	xxlor	32+29, 10, 10
-	vpermxor 23, 23, 28, 29
+	vsldoi		23, 23, 23, 8		# swap
+	vxor		23, 23, 28
 
-	vxor	24, 26, 1		# H
+	vpmsumd		24, 14, 15		# H4.H * X.H
+	vpmsumd		25, 11, 16
+	vpmsumd		26, 8, 17
+	vpmsumd		27, 5, 18
+
+	vxor		24, 24, 25
+	vxor		24, 24, 26
+	vxor		24, 24, 27
+
+	vxor		24, 24, 29
 
 	# sum hash and reduction with H Poly
-	#
-	#  vsldoi 25, 23, 23, 8		# swap
-	#  vpmsumd 23, 23, 2
-	#  vxor	27, 25, 24
-	#
-	vpermxor 27, 23, 24, 29
-	vpmsumd	23, 23, 2
-	vxor	0, 23, 27		# Digest of 4 blocks
+	vsldoi		27, 23, 23, 8		# swap
+	vpmsumd		23, 23, 2
+	vxor		27, 27, 24
+	vxor		23, 23, 27
 
-	vxor	19, 19, 0
+	xxlor		32, 23+32, 23+32		# update hash
 
-	# Compute digest for the next 4 blocks
-	vpmsumd	24, 9, 20
-	vpmsumd	25, 6, 21
-	vpmsumd	26, 3, 22
-	vpmsumd	23, 12, 19		# H4.L * X.L
+	blr
 
-	vxor	23, 23, 24
-	vxor	23, 23, 25
-	vxor	23, 23, 26		# L
+#
+# Combine two 4x ghash
+# v15 - v22 - input blocks
+#
+.macro ppc_aes_gcm_ghash2_4x
+	# first 4x hash
+	vxor		15, 15, 0		# Xi + X
 
-	vpmsumd	27, 13, 19		# H4.L * X.H + H4.H * X.L
-	vpmsumd	28, 10, 20		# H3.L * X1.H + H3.H * X1.L
-	vpmsumd	25, 7, 21
-	vpmsumd	26, 4, 22
+	xxlxor		29, 29, 29
 
-	vxor	24, 27, 28
-	vxor	24, 24, 25
-	vxor	24, 24, 26		# M
+	vpmsumd		23, 12, 15		# H4.L * X.L
+	vpmsumd		24, 9, 16
+	vpmsumd		25, 6, 17
+	vpmsumd		26, 3, 18
 
-	vpmsumd	26, 14, 19		# H4.H * X.H
-	vpmsumd	27, 11, 20
-	vpmsumd	28, 8, 21
-	vpmsumd	29, 5, 22
+	vxor		23, 23, 24
+	vxor		23, 23, 25
+	vxor		23, 23, 26		# L
 
-	vxor	26, 26, 27
-	vxor	26, 26, 28
-	vxor	26, 26, 29
+	vpmsumd		24, 13, 15		# H4.L * X.H + H4.H * X.L
+	vpmsumd		25, 10, 16		# H3.L * X1.H + H3.H * X1.L
+	vpmsumd		26, 7, 17
+	vpmsumd		27, 4, 18
+
+	vxor		24, 24, 25
+	vxor		24, 24, 26
 
 	# sum hash and reduction with H Poly
-	vpmsumd	28, 23, 2		# reduction
+	vpmsumd		28, 23, 2		# reduction
 
-	vxor	1, 1, 1
-	vsldoi	25, 24, 1, 8		# mL
-	vsldoi	1, 1, 24, 8		# mH
-	vxor	23, 23, 25		# mL + L
+	xxlor		29+32, 29, 29
 
-	# This performs swap and xor like,
-	#   vsldoi	23, 23, 23, 8		# swap
-	#   vxor	23, 23, 28
-	xxlor	32+29, 10, 10
-	vpermxor 23, 23, 28, 29
+	vxor		24, 24, 27		# M
+	vsldoi		26, 24, 29, 8		# mL
+	vsldoi		29, 29, 24, 8		# mH
+	vxor		23, 23, 26		# mL + L
 
-	vxor	24, 26, 1		# H
+	vsldoi		23, 23, 23, 8		# swap
+	vxor		23, 23, 28
+
+	vpmsumd		24, 14, 15		# H4.H * X.H
+	vpmsumd		25, 11, 16
+	vpmsumd		26, 8, 17
+	vpmsumd		27, 5, 18
+
+	vxor		24, 24, 25
+	vxor		24, 24, 26
+	vxor		24, 24, 27		# H
+
+	vxor		24, 24, 29		# H + mH
 
 	# sum hash and reduction with H Poly
-	#
-	#  vsldoi 25, 23, 23, 8		# swap
-	#  vpmsumd 23, 23, 2
-	#  vxor	27, 25, 24
-	#
-	vpermxor 27, 23, 24, 29
-	vpmsumd	23, 23, 2
-	vxor	0, 23, 27		# Digest of 8 blocks
+	vsldoi		27, 23, 23, 8		# swap
+	vpmsumd		23, 23, 2
+	vxor		27, 27, 24
+	vxor		27, 23, 27		# 1st Xi
+
+	# 2nd 4x hash
+	vpmsumd		24, 9, 20
+	vpmsumd		25, 6, 21
+	vpmsumd		26, 3, 22
+	vxor		19, 19, 27		# Xi + X
+	vpmsumd		23, 12, 19		# H4.L * X.L
+
+	vxor		23, 23, 24
+	vxor		23, 23, 25
+	vxor		23, 23, 26		# L
+
+	vpmsumd		24, 13, 19		# H4.L * X.H + H4.H * X.L
+	vpmsumd		25, 10, 20		# H3.L * X1.H + H3.H * X1.L
+	vpmsumd		26, 7, 21
+	vpmsumd		27, 4, 22
+
+	vxor		24, 24, 25
+	vxor		24, 24, 26
+
+	# sum hash and reduction with H Poly
+	vpmsumd		28, 23, 2		# reduction
+
+	xxlor		29+32, 29, 29
+
+	vxor		24, 24, 27		# M
+	vsldoi		26, 24, 29, 8		# mL
+	vsldoi		29, 29, 24, 8		# mH
+	vxor		23, 23, 26		# mL + L
+
+	vsldoi		23, 23, 23, 8		# swap
+	vxor		23, 23, 28
+
+	vpmsumd		24, 14, 19		# H4.H * X.H
+	vpmsumd		25, 11, 20
+	vpmsumd		26, 8, 21
+	vpmsumd		27, 5, 22
+
+	vxor		24, 24, 25
+	vxor		24, 24, 26
+	vxor		24, 24, 27		# H
+
+	vxor		24, 24, 29		# H + mH
+
+	# sum hash and reduction with H Poly
+	vsldoi		27, 23, 23, 8		# swap
+	vpmsumd		23, 23, 2
+	vxor		27, 27, 24
+	vxor		23, 23, 27
+
+	xxlor		32, 23+32, 23+32		# update hash
+
 .endm
 
 #
-# Compute update single ghash
-# vs10: vpermxor vector
-# scratch: v1, v22..v27
+# Compute update single hash
 #
-.macro PPC_GHASH1x H S1
+.macro ppc_update_hash_1x
+	vxor		28, 28, 0
 
-	vxor	1, 1, 1
+	vxor		19, 19, 19
 
-	vpmsumd	22, 3, \\S1		# L
-	vpmsumd	23, 4, \\S1		# M
-	vpmsumd	24, 5, \\S1		# H
+	vpmsumd		22, 3, 28		# L
+	vpmsumd		23, 4, 28		# M
+	vpmsumd		24, 5, 28		# H
 
-	vpmsumd	27, 22, 2		# reduction
+	vpmsumd		27, 22, 2		# reduction
 
-	vsldoi	25, 23, 1, 8		# mL
-	vsldoi	26, 1, 23, 8		# mH
-	vxor	22, 22, 25		# LL + LL
-	vxor	24, 24, 26		# HH + HH
+	vsldoi		25, 23, 19, 8		# mL
+	vsldoi		26, 19, 23, 8		# mH
+	vxor		22, 22, 25		# LL + LL
+	vxor		24, 24, 26		# HH + HH
 
-	xxlor	32+25, 10, 10
-	vpermxor 22, 22, 27, 25
+	vsldoi		22, 22, 22, 8		# swap
+	vxor		22, 22, 27
 
-	#  vsldoi 23, 22, 22, 8		# swap
-	#  vpmsumd 22, 22, 2		# reduction
-	#  vxor	23, 23, 24
-	vpermxor 23, 22, 24, 25
-	vpmsumd	22, 22, 2		# reduction
+	vsldoi		20, 22, 22, 8		# swap
+	vpmsumd		22, 22, 2		# reduction
+	vxor		20, 20, 24
+	vxor		22, 22, 20
+
+	vmr		0, 22			# update hash
 
-	vxor	\\H, 22, 23
 .endm
 
 #
-# LOAD_HASH_TABLE
-# Xi = v0
-# H Poly = v2
-# Hash keys = v3 - v14
-#
-.macro LOAD_HASH_TABLE
-	# Load Xi
-	lxvb16x	32, 0, 8	# load Xi
-
-	vxor	1, 1, 1
-
-	li	10, 32
-	lxvd2x	2+32, 10, 8	# H Poli
-
-	# load Hash - h^4, h^3, h^2, h
-	li	10, 64
-	lxvd2x	4+32, 10, 8	# H
-	vsldoi	3, 1, 4, 8	# l
-	vsldoi	5, 4, 1, 8	# h
-	li	10, 112
-	lxvd2x	7+32, 10, 8	# H^2
-	vsldoi	6, 1, 7, 8	# l
-	vsldoi	8, 7, 1, 8	# h
-	li	10, 160
-	lxvd2x	10+32, 10, 8	# H^3
-	vsldoi	9, 1, 10, 8	# l
-	vsldoi	11, 10, 1, 8	# h
-	li	10, 208
-	lxvd2x	13+32, 10, 8	# H^4
-	vsldoi	12, 1, 13, 8	# l
-	vsldoi	14, 13, 1, 8	# h
-.endm
-
-.macro PROCESS_8X_AES_STATES
-	vcipherlast     15, 15, 1
-	vcipherlast     16, 16, 1
-	vcipherlast     17, 17, 1
-	vcipherlast     18, 18, 1
-	vcipherlast     19, 19, 1
-	vcipherlast     20, 20, 1
-	vcipherlast     21, 21, 1
-	vcipherlast     22, 22, 1
-
-	lxvb16x	32+23, 0, 14	# load block
-	lxvb16x	32+24, 15, 14	# load block
-	lxvb16x	32+25, 16, 14	# load block
-	lxvb16x	32+26, 17, 14	# load block
-	lxvb16x	32+27, 18, 14	# load block
-	lxvb16x	32+28, 19, 14	# load block
-	lxvb16x	32+29, 20, 14	# load block
-	lxvb16x	32+30, 21, 14	# load block
-	addi	14, 14, 128
-
-	vxor	15, 15, 23
-	vxor	16, 16, 24
-	vxor	17, 17, 25
-	vxor	18, 18, 26
-	vxor	19, 19, 27
-	vxor	20, 20, 28
-	vxor	21, 21, 29
-	vxor	22, 22, 30
-
-	stxvb16x 47, 0, 9	# store output
-	stxvb16x 48, 15, 9	# store output
-	stxvb16x 49, 16, 9	# store output
-	stxvb16x 50, 17, 9	# store output
-	stxvb16x 51, 18, 9	# store output
-	stxvb16x 52, 19, 9	# store output
-	stxvb16x 53, 20, 9	# store output
-	stxvb16x 54, 21, 9	# store output
-	addi	9, 9, 128
-.endm
-
-.macro COMPUTE_STATES
-	xxlor	32+15, 9, 9		# last state
-	vadduwm 15, 15, 31		# state + counter
-	vadduwm 16, 15, 31
-	vadduwm 17, 16, 31
-	vadduwm 18, 17, 31
-	vadduwm 19, 18, 31
-	vadduwm 20, 19, 31
-	vadduwm 21, 20, 31
-	vadduwm 22, 21, 31
-	xxlor	9, 32+22, 32+22		# save last state
-
-        xxlxor	32+15, 32+15, 0		# IV + round key - add round key 0
-	xxlxor	32+16, 32+16, 0
-	xxlxor	32+17, 32+17, 0
-	xxlxor	32+18, 32+18, 0
-	xxlxor	32+19, 32+19, 0
-	xxlxor	32+20, 32+20, 0
-	xxlxor	32+21, 32+21, 0
-	xxlxor	32+22, 32+22, 0
-.endm
-
-################################################################################
-# Compute AES and ghash one block at a time.
-# r23: AES rounds
-# v30: current IV
-# vs0: roundkey 0
-#
-################################################################################
-.align 4
-aes_gcm_crypt_1x:
-
-	cmpdi	5, 16
-	bge	__More_1x
-	blr
-__More_1x:
-	li      10, 16
-	divdu   12, 5, 10
-
-	xxlxor	32+15, 32+30, 0
-
-	# Pre-load 8 AES rounds to scratch vectors.
-	lxv	32+16, 16(6)		# round key 1
-	lxv	32+17, 32(6)		# round key 2
-	lxv	32+18, 48(6)		# round key 3
-	lxv	32+19, 64(6)		# round key 4
-	lxv	32+20, 80(6)		# round key 5
-	lxv	32+21, 96(6)		# round key 6
-	lxv	32+28, 112(6)		# round key 7
-	lxv	32+29, 128(6)		# round key 8
-
-	lwz	23, 240(6)	# n rounds
-	addi	22, 23, -9	# remaining AES rounds
-
-	cmpdi	12, 0
-	bgt	__Loop_1x
-	blr
-
-__Loop_1x:
-	mtctr	22
-	addi	10, 6, 144
-	vcipher	15, 15, 16
-	vcipher	15, 15, 17
-	vcipher	15, 15, 18
-	vcipher	15, 15, 19
-	vcipher	15, 15, 20
-	vcipher	15, 15, 21
-	vcipher	15, 15, 28
-	vcipher	15, 15, 29
-
-__Loop_aes_1state:
-	lxv	32+1, 0(10)
-	vcipher	15, 15, 1
-	addi	10, 10, 16
-	bdnz	__Loop_aes_1state
-	lxv	32+1, 0(10)		# last round key
-	lxvb16x 11, 0, 14		# load input block
-	vcipherlast 15, 15, 1
-
-	xxlxor	32+15, 32+15, 11
-	stxvb16x 32+15, 0, 9	# store output
-	addi	14, 14, 16
-	addi	9, 9, 16
-
-	cmpdi	24, 0	# decrypt?
-	bne	__Encrypt_1x
-	xxlor	15+32, 11, 11
-__Encrypt_1x:
-	vxor	15, 15, 0
-	PPC_GHASH1x 0, 15
-
-	addi	5, 5, -16
-	addi	11, 11, 16
-
-	vadduwm 30, 30, 31		# IV + counter
-	xxlxor	32+15, 32+30, 0
-	addi	12, 12, -1
-	cmpdi	12, 0
-	bgt	__Loop_1x
-
-	stxvb16x 32+0, 0, 8		# update Xi
-	blr
-.size   aes_gcm_crypt_1x,.-aes_gcm_crypt_1x
-
-################################################################################
-# Process a normal partial block when we come here.
-#  Compute partial mask, Load and store partial block to stack.
-#  Compute AES state.
-#   Compute ghash.
-#
-################################################################################
-.align 4
-__Process_partial:
-
-	# create partial mask
-	vspltisb 16, -1
-	li	12, 16
-	sub	12, 12, 5
-	sldi	12, 12, 3
-	mtvsrdd	32+17, 0, 12
-	vslo	16, 16, 17		# partial block mask
-
-	lxvb16x 11, 0, 14		# load partial block
-	xxland	11, 11, 32+16
-
-	# AES crypt partial
-	xxlxor	32+15, 32+30, 0
-	lwz	23, 240(6)		# n rounds
-	addi	22, 23, -1		# loop - 1
-	mtctr	22
-	addi	10, 6, 16
-
-__Loop_aes_pstate:
-	lxv	32+1, 0(10)
-	vcipher	15, 15, 1
-	addi	10, 10, 16
-	bdnz	__Loop_aes_pstate
-	lxv	32+1, 0(10)		# last round key
-	vcipherlast 15, 15, 1
-
-	xxlxor	32+15, 32+15, 11
-	vand	15, 15, 16
-
-	# AES crypt output v15
-	# Write partial
-	li	10, 224
-	stxvb16x 15+32, 10, 1		# write v15 to stack
-	addi	10, 1, 223
-	addi	12, 9, -1
-        mtctr	5			# partial block len
-__Write_partial:
-        lbzu	22, 1(10)
-	stbu	22, 1(12)
-        bdnz	__Write_partial
-
-	cmpdi	24, 0			# decrypt?
-	bne	__Encrypt_partial
-	xxlor	32+15, 11, 11		# decrypt using the input block
-__Encrypt_partial:
-	vxor	15, 15, 0		# ^ previous hash
-	PPC_GHASH1x 0, 15
-	li	5, 0			# done last byte
-	stxvb16x 32+0, 0, 8		# Update X1
-	blr
-.size   __Process_partial,.-__Process_partial
-
-################################################################################
 # ppc_aes_gcm_encrypt (const void *inp, void *out, size_t len,
-#               const char *rk, unsigned char iv[16], void *Xip);
+#               const AES_KEY *key, unsigned char iv[16],
+#               void *Xip);
 #
 #    r3 - inp
 #    r4 - out
@@ -555,84 +454,159 @@ __Encrypt_partial:
 #    r7 - iv
 #    r8 - Xi, HPoli, hash keys
 #
-#    rounds is at offset 240 in rk
-#    Xi is at 0 in gcm_table (Xip).
-#
-################################################################################
 .global ppc_aes_gcm_encrypt
 .align 5
 ppc_aes_gcm_encrypt:
+_ppc_aes_gcm_encrypt:
 
-	SAVE_REGS
-	LOAD_HASH_TABLE
+	stdu 1,-512(1)
+	mflr 0
+
+	std	14,112(1)
+	std	15,120(1)
+	std	16,128(1)
+	std	17,136(1)
+	std	18,144(1)
+	std	19,152(1)
+	std	20,160(1)
+	std	21,168(1)
+	li	9, 256
+	stvx	20, 9, 1
+	addi	9, 9, 16
+	stvx	21, 9, 1
+	addi	9, 9, 16
+	stvx	22, 9, 1
+	addi	9, 9, 16
+	stvx	23, 9, 1
+	addi	9, 9, 16
+	stvx	24, 9, 1
+	addi	9, 9, 16
+	stvx	25, 9, 1
+	addi	9, 9, 16
+	stvx	26, 9, 1
+	addi	9, 9, 16
+	stvx	27, 9, 1
+	addi	9, 9, 16
+	stvx	28, 9, 1
+	addi	9, 9, 16
+	stvx	29, 9, 1
+	addi	9, 9, 16
+	stvx	30, 9, 1
+	addi	9, 9, 16
+	stvx	31, 9, 1
+	std	0, 528(1)
+
+	# Load Xi
+	lxvb16x	32, 0, 8	# load Xi
+
+	# load Hash - h^4, h^3, h^2, h
+	li	10, 32
+	lxvd2x	2+32, 10, 8	# H Poli
+	li	10, 48
+	lxvd2x	3+32, 10, 8	# Hl
+	li	10, 64
+	lxvd2x	4+32, 10, 8	# H
+	li	10, 80
+	lxvd2x	5+32, 10, 8	# Hh
+
+	li	10, 96
+	lxvd2x	6+32, 10, 8	# H^2l
+	li	10, 112
+	lxvd2x	7+32, 10, 8	# H^2
+	li	10, 128
+	lxvd2x	8+32, 10, 8	# H^2h
+
+	li	10, 144
+	lxvd2x	9+32, 10, 8	# H^3l
+	li	10, 160
+	lxvd2x	10+32, 10, 8	# H^3
+	li	10, 176
+	lxvd2x	11+32, 10, 8	# H^3h
+
+	li	10, 192
+	lxvd2x	12+32, 10, 8	# H^4l
+	li	10, 208
+	lxvd2x	13+32, 10, 8	# H^4
+	li	10, 224
+	lxvd2x	14+32, 10, 8	# H^4h
 
 	# initialize ICB: GHASH( IV ), IV - r7
 	lxvb16x	30+32, 0, 7	# load IV  - v30
 
-	mr	14, 3
-	mr	9, 4
+	mr	12, 5		# length
+	li	11, 0		# block index
 
 	# counter 1
 	vxor	31, 31, 31
 	vspltisb 22, 1
 	vsldoi	31, 31, 22,1	# counter 1
 
-	addis	11, 2, permx\@toc\@ha
-	addi	11, 11, permx\@toc\@l
-	lxv	10, 0(11)	# vs10: vpermxor vector
-	li	11, 0
-
-	lxv	0, 0(6)			# round key 0
-
-	#
-	# Process different blocks
-	#
-	cmpdi	5, 128
-	blt	__Process_more_enc
-
-	# load 9 round keys
-	lxv	32+23, 16(6)		# round key 1
-	lxv	32+24, 32(6)		# round key 2
-	lxv	32+25, 48(6)		# round key 3
-	lxv	32+26, 64(6)		# round key 4
-	lxv	32+27, 80(6)		# round key 5
-	lxv	32+28, 96(6)		# round key 6
-	lxv	32+29, 112(6)		# round key 7
-	lxv	32+1, 128(6)		# round key 8
+	# load round key to VSR
+	lxv	0, 0(6)
+	lxv	1, 0x10(6)
+	lxv	2, 0x20(6)
+	lxv	3, 0x30(6)
+	lxv	4, 0x40(6)
+	lxv	5, 0x50(6)
+	lxv	6, 0x60(6)
+	lxv	7, 0x70(6)
+	lxv	8, 0x80(6)
+	lxv	9, 0x90(6)
+	lxv	10, 0xa0(6)
 
 	# load rounds - 10 (128), 12 (192), 14 (256)
-	lwz	23, 240(6)		# n rounds
+	lwz	9,240(6)
 
-__Process_encrypt:
-#
-# Process 8x AES/GCM blocks
-#
-__Process_8x_enc:
-	# 8x blocks
+	#
+	# vxor	state, state, w # addroundkey
+	xxlor	32+29, 0, 0
+	vxor	15, 30, 29	# IV + round key - add round key 0
+
+	cmpdi	9, 10
+	beq	Loop_aes_gcm_8x
+
+	# load 2 more round keys (v11, v12)
+	lxv	11, 0xb0(6)
+	lxv	12, 0xc0(6)
+
+	cmpdi	9, 12
+	beq	Loop_aes_gcm_8x
+
+	# load 2 more round keys (v11, v12, v13, v14)
+	lxv	13, 0xd0(6)
+	lxv	14, 0xe0(6)
+	cmpdi	9, 14
+	beq	Loop_aes_gcm_8x
+
+	b	aes_gcm_out
+
+.align 5
+Loop_aes_gcm_8x:
+	mr	14, 3
+	mr	9, 4
+
+	# n blocks
 	li	10, 128
-	divdu	12, 5, 10	# n 128 bytes-blocks
+	divdu	10, 5, 10	# n 128 bytes-blocks
+	cmpdi	10, 0
+	beq	Loop_last_block
 
-	addi	12, 12, -1	# loop - 1
+	vaddudm	30, 30, 31	# IV + counter
+	vxor	16, 30, 29
+	vaddudm	30, 30, 31
+	vxor	17, 30, 29
+	vaddudm	30, 30, 31
+	vxor	18, 30, 29
+	vaddudm	30, 30, 31
+	vxor	19, 30, 29
+	vaddudm	30, 30, 31
+	vxor	20, 30, 29
+	vaddudm	30, 30, 31
+	vxor	21, 30, 29
+	vaddudm	30, 30, 31
+	vxor	22, 30, 29
 
-	vmr	15, 30		# first state: IV
-	vadduwm	16, 15, 31	# state + counter
-	vadduwm	17, 16, 31
-	vadduwm	18, 17, 31
-	vadduwm	19, 18, 31
-	vadduwm	20, 19, 31
-	vadduwm	21, 20, 31
-	vadduwm	22, 21, 31
-	xxlor	9, 32+22, 32+22	# save last state
-
-	# vxor  state, state, w # addroundkey
-	xxlxor	32+15, 32+15, 0      # IV + round key - add round key 0
-	xxlxor	32+16, 32+16, 0
-	xxlxor	32+17, 32+17, 0
-	xxlxor	32+18, 32+18, 0
-	xxlxor	32+19, 32+19, 0
-	xxlxor	32+20, 32+20, 0
-	xxlxor	32+21, 32+21, 0
-	xxlxor	32+22, 32+22, 0
+	mtctr	10
 
 	li	15, 16
 	li	16, 32
@@ -642,184 +616,523 @@ __Process_8x_enc:
 	li	20, 96
 	li	21, 112
 
-	#
-	# Pre-compute first 8 AES state and leave 1/3/5 more rounds
-	# for the loop.
-	#
-	addi	22, 23, -9		# process 8 keys
-	mtctr	22			# AES key loop
-	addi	10, 6, 144
+	lwz	10, 240(6)
 
-	LOOP_8AES_STATE			# process 8 AES keys
+Loop_8x_block:
 
-__PreLoop_aes_state:
-	lxv	32+1, 0(10)		# round key
-	AES_CIPHER_8x 1
-	addi	10, 10, 16
-	bdnz	__PreLoop_aes_state
-	lxv	32+1, 0(10)		# last round key (v1)
+	lxvb16x		15, 0, 14	# load block
+	lxvb16x		16, 15, 14	# load block
+	lxvb16x		17, 16, 14	# load block
+	lxvb16x		18, 17, 14	# load block
+	lxvb16x		19, 18, 14	# load block
+	lxvb16x		20, 19, 14	# load block
+	lxvb16x		21, 20, 14	# load block
+	lxvb16x		22, 21, 14	# load block
+	addi		14, 14, 128
 
-	cmpdi	12, 0			# Only one loop (8 block)
-	beq	__Finish_ghash
+	Loop_aes_middle8x
 
-#
-# Loop 8x blocks and compute ghash
-#
-__Loop_8x_block_enc:
-	PROCESS_8X_AES_STATES
+	xxlor	23+32, 10, 10
 
-	# Compute ghash here
-	vxor	15, 15, 0
-	PPC_GFMUL128_8x
+	cmpdi	10, 10
+	beq	Do_next_ghash
 
-	COMPUTE_STATES
+	# 192 bits
+	xxlor	24+32, 11, 11
 
-	addi    5, 5, -128
-	addi    11, 11, 128
+	vcipher	15, 15, 23
+	vcipher	16, 16, 23
+	vcipher	17, 17, 23
+	vcipher	18, 18, 23
+	vcipher	19, 19, 23
+	vcipher	20, 20, 23
+	vcipher	21, 21, 23
+	vcipher	22, 22, 23
 
-	lxv	32+23, 16(6)		# round key 1
-	lxv	32+24, 32(6)		# round key 2
-	lxv	32+25, 48(6)		# round key 3
-	lxv	32+26, 64(6)		# round key 4
-	lxv	32+27, 80(6)		# round key 5
-	lxv	32+28, 96(6)		# round key 6
-	lxv	32+29, 112(6)		# round key 7
-	lxv	32+1, 128(6)		# round key 8
+	vcipher	15, 15, 24
+	vcipher	16, 16, 24
+	vcipher	17, 17, 24
+	vcipher	18, 18, 24
+	vcipher	19, 19, 24
+	vcipher	20, 20, 24
+	vcipher	21, 21, 24
+	vcipher	22, 22, 24
 
-	# Compute first 8 AES state and leave 1/3/5 more rounds
-	# for the loop.
-	LOOP_8AES_STATE			# process 8 AES keys
-	mtctr	22			# AES key loop
-	addi	10, 6, 144
+	xxlor	23+32, 12, 12
 
-__LastLoop_aes_state:
-	lxv	32+1, 0(10)		# round key
-	AES_CIPHER_8x 1
-	addi	10, 10, 16
-	bdnz	__LastLoop_aes_state
+	cmpdi	10, 12
+	beq	Do_next_ghash
 
-	lxv	32+1, 0(10)		# last round key (v1)
+	# 256 bits
+	xxlor	24+32, 13, 13
 
-	addi	12, 12, -1
-	cmpdi	12, 0
-	bne	__Loop_8x_block_enc
+	vcipher	15, 15, 23
+	vcipher	16, 16, 23
+	vcipher	17, 17, 23
+	vcipher	18, 18, 23
+	vcipher	19, 19, 23
+	vcipher	20, 20, 23
+	vcipher	21, 21, 23
+	vcipher	22, 22, 23
 
-	#
-	# Remainng blocks
-	#
-__Finish_ghash:
-	PROCESS_8X_AES_STATES
+	vcipher	15, 15, 24
+	vcipher	16, 16, 24
+	vcipher	17, 17, 24
+	vcipher	18, 18, 24
+	vcipher	19, 19, 24
+	vcipher	20, 20, 24
+	vcipher	21, 21, 24
+	vcipher	22, 22, 24
 
-	# Compute ghash here
-	vxor	15, 15, 0
-	PPC_GFMUL128_8x
+	xxlor	23+32, 14, 14
 
-	# Update IV and Xi
-	xxlor	30+32, 9, 9		# last ctr
-	vadduwm	30, 30, 31		# increase ctr
-	stxvb16x 32+0, 0, 8		# update Xi
-
-	addi    5, 5, -128
-	addi    11, 11, 128
-
-	#
-	# Done 8x blocks
-	#
-
-	cmpdi   5, 0
-	beq     aes_gcm_out
-
-__Process_more_enc:
-	li	24, 1			# encrypt
-	bl	aes_gcm_crypt_1x
-	cmpdi   5, 0
-	beq     aes_gcm_out
-
-	bl	__Process_partial
+	cmpdi	10, 14
+	beq	Do_next_ghash
 	b	aes_gcm_out
 
-.size   ppc_aes_gcm_encrypt,.-ppc_aes_gcm_encrypt
+Do_next_ghash:
 
-################################################################################
-# ppc_aes_gcm_decrypt (const void *inp, void *out, size_t len,
-#               const char *rk, unsigned char iv[16], void *Xip);
+	#
+	# last round
+	vcipherlast     15, 15, 23
+	vcipherlast     16, 16, 23
+
+	xxlxor		47, 47, 15
+	stxvb16x        47, 0, 9	# store output
+	xxlxor		48, 48, 16
+	stxvb16x        48, 15, 9	# store output
+
+	vcipherlast     17, 17, 23
+	vcipherlast     18, 18, 23
+
+	xxlxor		49, 49, 17
+	stxvb16x        49, 16, 9	# store output
+	xxlxor		50, 50, 18
+	stxvb16x        50, 17, 9	# store output
+
+	vcipherlast     19, 19, 23
+	vcipherlast     20, 20, 23
+
+	xxlxor		51, 51, 19
+	stxvb16x        51, 18, 9	# store output
+	xxlxor		52, 52, 20
+	stxvb16x        52, 19, 9	# store output
+
+	vcipherlast     21, 21, 23
+	vcipherlast     22, 22, 23
+
+	xxlxor		53, 53, 21
+	stxvb16x        53, 20, 9	# store output
+	xxlxor		54, 54, 22
+	stxvb16x        54, 21, 9	# store output
+
+	addi		9, 9, 128
+
+	# ghash here
+	ppc_aes_gcm_ghash2_4x
+
+	xxlor	27+32, 0, 0
+	vaddudm 30, 30, 31		# IV + counter
+	vmr	29, 30
+	vxor    15, 30, 27		# add round key
+	vaddudm 30, 30, 31
+	vxor    16, 30, 27
+	vaddudm 30, 30, 31
+	vxor    17, 30, 27
+	vaddudm 30, 30, 31
+	vxor    18, 30, 27
+	vaddudm 30, 30, 31
+	vxor    19, 30, 27
+	vaddudm 30, 30, 31
+	vxor    20, 30, 27
+	vaddudm 30, 30, 31
+	vxor    21, 30, 27
+	vaddudm 30, 30, 31
+	vxor    22, 30, 27
+
+	addi    12, 12, -128
+	addi    11, 11, 128
+
+	bdnz	Loop_8x_block
+
+	vmr	30, 29
+
+Loop_last_block:
+	cmpdi   12, 0
+	beq     aes_gcm_out
+
+	# loop last few blocks
+	li      10, 16
+	divdu   10, 12, 10
+
+	mtctr   10
+
+	lwz	10, 240(6)
+
+	cmpdi   12, 16
+	blt     Final_block
+
+.macro Loop_aes_middle_1x
+	xxlor	19+32, 1, 1
+	xxlor	20+32, 2, 2
+	xxlor	21+32, 3, 3
+	xxlor	22+32, 4, 4
+
+	vcipher 15, 15, 19
+	vcipher 15, 15, 20
+	vcipher 15, 15, 21
+	vcipher 15, 15, 22
+
+	xxlor	19+32, 5, 5
+	xxlor	20+32, 6, 6
+	xxlor	21+32, 7, 7
+	xxlor	22+32, 8, 8
+
+	vcipher 15, 15, 19
+	vcipher 15, 15, 20
+	vcipher 15, 15, 21
+	vcipher 15, 15, 22
+
+	xxlor	19+32, 9, 9
+	vcipher 15, 15, 19
+.endm
+
+Next_rem_block:
+	lxvb16x 15, 0, 14		# load block
+
+	Loop_aes_middle_1x
+
+	xxlor	23+32, 10, 10
+
+	cmpdi	10, 10
+	beq	Do_next_1x
+
+	# 192 bits
+	xxlor	24+32, 11, 11
+
+	vcipher	15, 15, 23
+	vcipher	15, 15, 24
+
+	xxlor	23+32, 12, 12
+
+	cmpdi	10, 12
+	beq	Do_next_1x
+
+	# 256 bits
+	xxlor	24+32, 13, 13
+
+	vcipher	15, 15, 23
+	vcipher	15, 15, 24
+
+	xxlor	23+32, 14, 14
+
+	cmpdi	10, 14
+	beq	Do_next_1x
+
+Do_next_1x:
+	vcipherlast     15, 15, 23
+
+	xxlxor		47, 47, 15
+	stxvb16x	47, 0, 9	# store output
+	addi		14, 14, 16
+	addi		9, 9, 16
+
+	vmr		28, 15
+	ppc_update_hash_1x
+
+	addi		12, 12, -16
+	addi		11, 11, 16
+	xxlor		19+32, 0, 0
+	vaddudm		30, 30, 31		# IV + counter
+	vxor		15, 30, 19		# add round key
+
+	bdnz	Next_rem_block
+
+	cmpdi	12, 0
+	beq	aes_gcm_out
+
+Final_block:
+	Loop_aes_middle_1x
+
+	xxlor	23+32, 10, 10
+
+	cmpdi	10, 10
+	beq	Do_final_1x
+
+	# 192 bits
+	xxlor	24+32, 11, 11
+
+	vcipher	15, 15, 23
+	vcipher	15, 15, 24
+
+	xxlor	23+32, 12, 12
+
+	cmpdi	10, 12
+	beq	Do_final_1x
+
+	# 256 bits
+	xxlor	24+32, 13, 13
+
+	vcipher	15, 15, 23
+	vcipher	15, 15, 24
+
+	xxlor	23+32, 14, 14
+
+	cmpdi	10, 14
+	beq	Do_final_1x
+
+Do_final_1x:
+	vcipherlast     15, 15, 23
+
+	lxvb16x	15, 0, 14		# load last block
+	xxlxor	47, 47, 15
+
+	# create partial block mask
+	li	15, 16
+	sub	15, 15, 12		# index to the mask
+
+	vspltisb	16, -1		# first 16 bytes - 0xffff...ff
+	vspltisb	17, 0		# second 16 bytes - 0x0000...00
+	li	10, 192
+	stvx	16, 10, 1
+	addi	10, 10, 16
+	stvx	17, 10, 1
+
+	addi	10, 1, 192
+	lxvb16x	16, 15, 10		# load partial block mask
+	xxland	47, 47, 16
+
+	vmr	28, 15
+	ppc_update_hash_1x
+
+	# * should store only the remaining bytes.
+	bl	Write_partial_block
+
+	b aes_gcm_out
+
+#
+# Write partial block
+# r9 - output
+# r12 - remaining bytes
+# v15 - partial input data
+#
+Write_partial_block:
+	li		10, 192
+	stxvb16x	15+32, 10, 1		# last block
+
+	#add		10, 9, 11		# Output
+	addi		10, 9, -1
+	addi		16, 1, 191
+
+        mtctr		12			# remaining bytes
+	li		15, 0
+
+Write_last_byte:
+        lbzu		14, 1(16)
+	stbu		14, 1(10)
+        bdnz		Write_last_byte
+	blr
+
+aes_gcm_out:
+	# out = state
+	stxvb16x	32, 0, 8		# write out Xi
+	add	3, 11, 12		# return count
+
+	li	9, 256
+	lvx	20, 9, 1
+	addi	9, 9, 16
+	lvx	21, 9, 1
+	addi	9, 9, 16
+	lvx	22, 9, 1
+	addi	9, 9, 16
+	lvx	23, 9, 1
+	addi	9, 9, 16
+	lvx	24, 9, 1
+	addi	9, 9, 16
+	lvx	25, 9, 1
+	addi	9, 9, 16
+	lvx	26, 9, 1
+	addi	9, 9, 16
+	lvx	27, 9, 1
+	addi	9, 9, 16
+	lvx	28, 9, 1
+	addi	9, 9, 16
+	lvx	29, 9, 1
+	addi	9, 9, 16
+	lvx	30, 9, 1
+	addi	9, 9, 16
+	lvx	31, 9, 1
+
+	ld	0, 528(1)
+	ld      14,112(1)
+	ld      15,120(1)
+	ld      16,128(1)
+	ld      17,136(1)
+	ld      18,144(1)
+	ld      19,152(1)
+	ld      20,160(1)
+	ld	21,168(1)
+
+	mtlr	0
+	addi	1, 1, 512
+	blr
+
+#
 # 8x Decrypt
 #
-################################################################################
 .global ppc_aes_gcm_decrypt
 .align 5
 ppc_aes_gcm_decrypt:
+_ppc_aes_gcm_decrypt:
 
-	SAVE_REGS
-	LOAD_HASH_TABLE
+	stdu 1,-512(1)
+	mflr 0
+
+	std	14,112(1)
+	std	15,120(1)
+	std	16,128(1)
+	std	17,136(1)
+	std	18,144(1)
+	std	19,152(1)
+	std	20,160(1)
+	std	21,168(1)
+	li	9, 256
+	stvx	20, 9, 1
+	addi	9, 9, 16
+	stvx	21, 9, 1
+	addi	9, 9, 16
+	stvx	22, 9, 1
+	addi	9, 9, 16
+	stvx	23, 9, 1
+	addi	9, 9, 16
+	stvx	24, 9, 1
+	addi	9, 9, 16
+	stvx	25, 9, 1
+	addi	9, 9, 16
+	stvx	26, 9, 1
+	addi	9, 9, 16
+	stvx	27, 9, 1
+	addi	9, 9, 16
+	stvx	28, 9, 1
+	addi	9, 9, 16
+	stvx	29, 9, 1
+	addi	9, 9, 16
+	stvx	30, 9, 1
+	addi	9, 9, 16
+	stvx	31, 9, 1
+	std	0, 528(1)
+
+	# Load Xi
+	lxvb16x	32, 0, 8	# load Xi
+
+	# load Hash - h^4, h^3, h^2, h
+	li	10, 32
+	lxvd2x	2+32, 10, 8	# H Poli
+	li	10, 48
+	lxvd2x	3+32, 10, 8	# Hl
+	li	10, 64
+	lxvd2x	4+32, 10, 8	# H
+	li	10, 80
+	lxvd2x	5+32, 10, 8	# Hh
+
+	li	10, 96
+	lxvd2x	6+32, 10, 8	# H^2l
+	li	10, 112
+	lxvd2x	7+32, 10, 8	# H^2
+	li	10, 128
+	lxvd2x	8+32, 10, 8	# H^2h
+
+	li	10, 144
+	lxvd2x	9+32, 10, 8	# H^3l
+	li	10, 160
+	lxvd2x	10+32, 10, 8	# H^3
+	li	10, 176
+	lxvd2x	11+32, 10, 8	# H^3h
+
+	li	10, 192
+	lxvd2x	12+32, 10, 8	# H^4l
+	li	10, 208
+	lxvd2x	13+32, 10, 8	# H^4
+	li	10, 224
+	lxvd2x	14+32, 10, 8	# H^4h
 
 	# initialize ICB: GHASH( IV ), IV - r7
 	lxvb16x	30+32, 0, 7	# load IV  - v30
 
-	mr	14, 3
-	mr	9, 4
+	mr	12, 5		# length
+	li	11, 0		# block index
 
 	# counter 1
 	vxor	31, 31, 31
 	vspltisb 22, 1
 	vsldoi	31, 31, 22,1	# counter 1
 
-	addis	11, 2, permx\@toc\@ha
-	addi	11, 11, permx\@toc\@l
-	lxv	10, 0(11)	# vs10: vpermxor vector
-	li	11, 0
-
-	lxv	0, 0(6)			# round key 0
-
-	#
-	# Process different blocks
-	#
-	cmpdi	5, 128
-	blt	__Process_more_dec
-
-	# load 9 round keys
-	lxv	32+23, 16(6)		# round key 1
-	lxv	32+24, 32(6)		# round key 2
-	lxv	32+25, 48(6)		# round key 3
-	lxv	32+26, 64(6)		# round key 4
-	lxv	32+27, 80(6)		# round key 5
-	lxv	32+28, 96(6)		# round key 6
-	lxv	32+29, 112(6)		# round key 7
-	lxv	32+1, 128(6)		# round key 8
+	# load round key to VSR
+	lxv	0, 0(6)
+	lxv	1, 0x10(6)
+	lxv	2, 0x20(6)
+	lxv	3, 0x30(6)
+	lxv	4, 0x40(6)
+	lxv	5, 0x50(6)
+	lxv	6, 0x60(6)
+	lxv	7, 0x70(6)
+	lxv	8, 0x80(6)
+	lxv	9, 0x90(6)
+	lxv	10, 0xa0(6)
 
 	# load rounds - 10 (128), 12 (192), 14 (256)
-	lwz	23, 240(6)		# n rounds
+	lwz	9,240(6)
 
-__Process_decrypt:
-#
-# Process 8x AES/GCM blocks
-#
-__Process_8x_dec:
-	# 8x blocks
+	#
+	# vxor	state, state, w # addroundkey
+	xxlor	32+29, 0, 0
+	vxor	15, 30, 29	# IV + round key - add round key 0
+
+	cmpdi	9, 10
+	beq	Loop_aes_gcm_8x_dec
+
+	# load 2 more round keys (v11, v12)
+	lxv	11, 0xb0(6)
+	lxv	12, 0xc0(6)
+
+	cmpdi	9, 12
+	beq	Loop_aes_gcm_8x_dec
+
+	# load 2 more round keys (v11, v12, v13, v14)
+	lxv	13, 0xd0(6)
+	lxv	14, 0xe0(6)
+	cmpdi	9, 14
+	beq	Loop_aes_gcm_8x_dec
+
+	b	aes_gcm_out
+
+.align 5
+Loop_aes_gcm_8x_dec:
+	mr	14, 3
+	mr	9, 4
+
+	# n blocks
 	li	10, 128
-	divdu	12, 5, 10	# n 128 bytes-blocks
+	divdu	10, 5, 10	# n 128 bytes-blocks
+	cmpdi	10, 0
+	beq	Loop_last_block_dec
 
-	addi	12, 12, -1	# loop - 1
+	vaddudm	30, 30, 31	# IV + counter
+	vxor	16, 30, 29
+	vaddudm	30, 30, 31
+	vxor	17, 30, 29
+	vaddudm	30, 30, 31
+	vxor	18, 30, 29
+	vaddudm	30, 30, 31
+	vxor	19, 30, 29
+	vaddudm	30, 30, 31
+	vxor	20, 30, 29
+	vaddudm	30, 30, 31
+	vxor	21, 30, 29
+	vaddudm	30, 30, 31
+	vxor	22, 30, 29
 
-	vmr	15, 30		# first state: IV
-	vadduwm	16, 15, 31	# state + counter
-	vadduwm	17, 16, 31
-	vadduwm	18, 17, 31
-	vadduwm	19, 18, 31
-	vadduwm	20, 19, 31
-	vadduwm	21, 20, 31
-	vadduwm	22, 21, 31
-	xxlor	9, 32+22, 32+22	# save last state
-
-	# vxor  state, state, w # addroundkey
-	xxlxor	32+15, 32+15, 0      # IV + round key - add round key 0
-	xxlxor	32+16, 32+16, 0
-	xxlxor	32+17, 32+17, 0
-	xxlxor	32+18, 32+18, 0
-	xxlxor	32+19, 32+19, 0
-	xxlxor	32+20, 32+20, 0
-	xxlxor	32+21, 32+21, 0
-	xxlxor	32+22, 32+22, 0
+	mtctr	10
 
 	li	15, 16
 	li	16, 32
@@ -829,218 +1142,297 @@ __Process_8x_dec:
 	li	20, 96
 	li	21, 112
 
+	lwz	10, 240(6)
+
+Loop_8x_block_dec:
+
+	lxvb16x		15, 0, 14	# load block
+	lxvb16x		16, 15, 14	# load block
+	lxvb16x		17, 16, 14	# load block
+	lxvb16x		18, 17, 14	# load block
+	lxvb16x		19, 18, 14	# load block
+	lxvb16x		20, 19, 14	# load block
+	lxvb16x		21, 20, 14	# load block
+	lxvb16x		22, 21, 14	# load block
+	addi		14, 14, 128
+
+	Loop_aes_middle8x
+
+	xxlor	23+32, 10, 10
+
+	cmpdi	10, 10
+	beq	Do_last_aes_dec
+
+	# 192 bits
+	xxlor	24+32, 11, 11
+
+	vcipher	15, 15, 23
+	vcipher	16, 16, 23
+	vcipher	17, 17, 23
+	vcipher	18, 18, 23
+	vcipher	19, 19, 23
+	vcipher	20, 20, 23
+	vcipher	21, 21, 23
+	vcipher	22, 22, 23
+
+	vcipher	15, 15, 24
+	vcipher	16, 16, 24
+	vcipher	17, 17, 24
+	vcipher	18, 18, 24
+	vcipher	19, 19, 24
+	vcipher	20, 20, 24
+	vcipher	21, 21, 24
+	vcipher	22, 22, 24
+
+	xxlor	23+32, 12, 12
+
+	cmpdi	10, 12
+	beq	Do_last_aes_dec
+
+	# 256 bits
+	xxlor	24+32, 13, 13
+
+	vcipher	15, 15, 23
+	vcipher	16, 16, 23
+	vcipher	17, 17, 23
+	vcipher	18, 18, 23
+	vcipher	19, 19, 23
+	vcipher	20, 20, 23
+	vcipher	21, 21, 23
+	vcipher	22, 22, 23
+
+	vcipher	15, 15, 24
+	vcipher	16, 16, 24
+	vcipher	17, 17, 24
+	vcipher	18, 18, 24
+	vcipher	19, 19, 24
+	vcipher	20, 20, 24
+	vcipher	21, 21, 24
+	vcipher	22, 22, 24
+
+	xxlor	23+32, 14, 14
+
+	cmpdi	10, 14
+	beq	Do_last_aes_dec
+	b	aes_gcm_out
+
+Do_last_aes_dec:
+
 	#
-	# Pre-compute first 8 AES state and leave 1/3/5 more rounds
-	# for the loop.
-	#
-	addi	22, 23, -9		# process 8 keys
-	mtctr	22			# AES key loop
-	addi	10, 6, 144
+	# last round
+	vcipherlast     15, 15, 23
+	vcipherlast     16, 16, 23
 
-	LOOP_8AES_STATE			# process 8 AES keys
+	xxlxor		47, 47, 15
+	stxvb16x        47, 0, 9	# store output
+	xxlxor		48, 48, 16
+	stxvb16x        48, 15, 9	# store output
 
-__PreLoop_aes_state_dec:
-	lxv	32+1, 0(10)		# round key
-	AES_CIPHER_8x 1
-	addi	10, 10, 16
-	bdnz	__PreLoop_aes_state_dec
-	lxv	32+1, 0(10)		# last round key (v1)
+	vcipherlast     17, 17, 23
+	vcipherlast     18, 18, 23
 
-	cmpdi	12, 0			# Only one loop (8 block)
-	beq	__Finish_ghash_dec
+	xxlxor		49, 49, 17
+	stxvb16x        49, 16, 9	# store output
+	xxlxor		50, 50, 18
+	stxvb16x        50, 17, 9	# store output
 
-#
-# Loop 8x blocks and compute ghash
-#
-__Loop_8x_block_dec:
-	vcipherlast     15, 15, 1
-	vcipherlast     16, 16, 1
-	vcipherlast     17, 17, 1
-	vcipherlast     18, 18, 1
-	vcipherlast     19, 19, 1
-	vcipherlast     20, 20, 1
-	vcipherlast     21, 21, 1
-	vcipherlast     22, 22, 1
+	vcipherlast     19, 19, 23
+	vcipherlast     20, 20, 23
 
-	lxvb16x	32+23, 0, 14	# load block
-	lxvb16x	32+24, 15, 14	# load block
-	lxvb16x	32+25, 16, 14	# load block
-	lxvb16x	32+26, 17, 14	# load block
-	lxvb16x	32+27, 18, 14	# load block
-	lxvb16x	32+28, 19, 14	# load block
-	lxvb16x	32+29, 20, 14	# load block
-	lxvb16x	32+30, 21, 14	# load block
-	addi	14, 14, 128
+	xxlxor		51, 51, 19
+	stxvb16x        51, 18, 9	# store output
+	xxlxor		52, 52, 20
+	stxvb16x        52, 19, 9	# store output
 
-	vxor	15, 15, 23
-	vxor	16, 16, 24
-	vxor	17, 17, 25
-	vxor	18, 18, 26
-	vxor	19, 19, 27
-	vxor	20, 20, 28
-	vxor	21, 21, 29
-	vxor	22, 22, 30
+	vcipherlast     21, 21, 23
+	vcipherlast     22, 22, 23
 
-	stxvb16x 47, 0, 9	# store output
-	stxvb16x 48, 15, 9	# store output
-	stxvb16x 49, 16, 9	# store output
-	stxvb16x 50, 17, 9	# store output
-	stxvb16x 51, 18, 9	# store output
-	stxvb16x 52, 19, 9	# store output
-	stxvb16x 53, 20, 9	# store output
-	stxvb16x 54, 21, 9	# store output
+	xxlxor		53, 53, 21
+	stxvb16x        53, 20, 9	# store output
+	xxlxor		54, 54, 22
+	stxvb16x        54, 21, 9	# store output
 
-	addi	9, 9, 128
+	addi		9, 9, 128
 
-	vmr	15, 23
-	vmr	16, 24
-	vmr	17, 25
-	vmr	18, 26
-	vmr	19, 27
-	vmr	20, 28
-	vmr	21, 29
-	vmr	22, 30
+	xxlor		15+32, 15, 15
+	xxlor		16+32, 16, 16
+	xxlor		17+32, 17, 17
+	xxlor		18+32, 18, 18
+	xxlor		19+32, 19, 19
+	xxlor		20+32, 20, 20
+	xxlor		21+32, 21, 21
+	xxlor		22+32, 22, 22
 
 	# ghash here
-	vxor	15, 15, 0
-	PPC_GFMUL128_8x
+	ppc_aes_gcm_ghash2_4x
 
-	xxlor	32+15, 9, 9		# last state
-	vadduwm 15, 15, 31		# state + counter
-	vadduwm 16, 15, 31
-	vadduwm 17, 16, 31
-	vadduwm 18, 17, 31
-	vadduwm 19, 18, 31
-	vadduwm 20, 19, 31
-	vadduwm 21, 20, 31
-	vadduwm 22, 21, 31
-	xxlor	9, 32+22, 32+22		# save last state
-
-	xxlor	32+27, 0, 0		# restore roundkey 0
-        vxor    15, 15, 27		# IV + round key - add round key 0
-	vxor	16, 16, 27
-	vxor	17, 17, 27
-	vxor	18, 18, 27
-	vxor	19, 19, 27
-	vxor	20, 20, 27
-	vxor	21, 21, 27
-	vxor	22, 22, 27
-
-	addi    5, 5, -128
+	xxlor	27+32, 0, 0
+	vaddudm 30, 30, 31		# IV + counter
+	vmr	29, 30
+	vxor    15, 30, 27		# add round key
+	vaddudm 30, 30, 31
+	vxor    16, 30, 27
+	vaddudm 30, 30, 31
+	vxor    17, 30, 27
+	vaddudm 30, 30, 31
+	vxor    18, 30, 27
+	vaddudm 30, 30, 31
+	vxor    19, 30, 27
+	vaddudm 30, 30, 31
+	vxor    20, 30, 27
+	vaddudm 30, 30, 31
+	vxor    21, 30, 27
+	vaddudm 30, 30, 31
+	vxor    22, 30, 27
+	addi    12, 12, -128
 	addi    11, 11, 128
 
-	lxv	32+23, 16(6)		# round key 1
-	lxv	32+24, 32(6)		# round key 2
-	lxv	32+25, 48(6)		# round key 3
-	lxv	32+26, 64(6)		# round key 4
-	lxv	32+27, 80(6)		# round key 5
-	lxv	32+28, 96(6)		# round key 6
-	lxv	32+29, 112(6)		# round key 7
-	lxv	32+1, 128(6)		# round key 8
+	bdnz	Loop_8x_block_dec
 
-	LOOP_8AES_STATE			# process 8 AES keys
-	mtctr	22			# AES key loop
-	addi	10, 6, 144
-__LastLoop_aes_state_dec:
-	lxv	32+1, 0(10)		# round key
-	AES_CIPHER_8x 1
-	addi	10, 10, 16
-	bdnz	__LastLoop_aes_state_dec
-	lxv	32+1, 0(10)		# last round key (v1)
+	vmr	30, 29
+
+Loop_last_block_dec:
+	cmpdi   12, 0
+	beq     aes_gcm_out
+
+	# loop last few blocks
+	li      10, 16
+	divdu   10, 12, 10
+
+	mtctr   10
+
+	lwz	10,240(6)
+
+	cmpdi   12, 16
+	blt     Final_block_dec
+
+Next_rem_block_dec:
+	lxvb16x 15, 0, 14		# load block
+
+	Loop_aes_middle_1x
+
+	xxlor	23+32, 10, 10
+
+	cmpdi	10, 10
+	beq	Do_next_1x_dec
+
+	# 192 bits
+	xxlor	24+32, 11, 11
+
+	vcipher	15, 15, 23
+	vcipher	15, 15, 24
+
+	xxlor	23+32, 12, 12
+
+	cmpdi	10, 12
+	beq	Do_next_1x_dec
+
+	# 256 bits
+	xxlor	24+32, 13, 13
+
+	vcipher	15, 15, 23
+	vcipher	15, 15, 24
+
+	xxlor	23+32, 14, 14
+
+	cmpdi	10, 14
+	beq	Do_next_1x_dec
+
+Do_next_1x_dec:
+	vcipherlast     15, 15, 23
+
+	xxlxor  47, 47, 15
+	stxvb16x        47, 0, 9	# store output
+	addi	14, 14, 16
+	addi	9, 9, 16
+
+	xxlor	28+32, 15, 15
+	ppc_update_hash_1x
+
+	addi    12, 12, -16
+	addi    11, 11, 16
+	xxlor	19+32, 0, 0
+	vaddudm 30, 30, 31		# IV + counter
+	vxor	15, 30, 19		# add round key
+
+	bdnz	Next_rem_block_dec
 
-	addi	12, 12, -1
 	cmpdi	12, 0
-	bne	__Loop_8x_block_dec
+	beq	aes_gcm_out
 
-__Finish_ghash_dec:
-	vcipherlast     15, 15, 1
-	vcipherlast     16, 16, 1
-	vcipherlast     17, 17, 1
-	vcipherlast     18, 18, 1
-	vcipherlast     19, 19, 1
-	vcipherlast     20, 20, 1
-	vcipherlast     21, 21, 1
-	vcipherlast     22, 22, 1
+Final_block_dec:
+	Loop_aes_middle_1x
 
-	lxvb16x	32+23, 0, 14	# load block
-	lxvb16x	32+24, 15, 14	# load block
-	lxvb16x	32+25, 16, 14	# load block
-	lxvb16x	32+26, 17, 14	# load block
-	lxvb16x	32+27, 18, 14	# load block
-	lxvb16x	32+28, 19, 14	# load block
-	lxvb16x	32+29, 20, 14	# load block
-	lxvb16x	32+30, 21, 14	# load block
-	addi	14, 14, 128
+	xxlor	23+32, 10, 10
 
-	vxor	15, 15, 23
-	vxor	16, 16, 24
-	vxor	17, 17, 25
-	vxor	18, 18, 26
-	vxor	19, 19, 27
-	vxor	20, 20, 28
-	vxor	21, 21, 29
-	vxor	22, 22, 30
+	cmpdi	10, 10
+	beq	Do_final_1x_dec
 
-	stxvb16x 47, 0, 9	# store output
-	stxvb16x 48, 15, 9	# store output
-	stxvb16x 49, 16, 9	# store output
-	stxvb16x 50, 17, 9	# store output
-	stxvb16x 51, 18, 9	# store output
-	stxvb16x 52, 19, 9	# store output
-	stxvb16x 53, 20, 9	# store output
-	stxvb16x 54, 21, 9	# store output
-	addi	9, 9, 128
+	# 192 bits
+	xxlor	24+32, 11, 11
 
-	vxor	15, 23, 0
-	vmr	16, 24
-	vmr	17, 25
-	vmr	18, 26
-	vmr	19, 27
-	vmr	20, 28
-	vmr	21, 29
-	vmr	22, 30
+	vcipher	15, 15, 23
+	vcipher	15, 15, 24
 
-	#vxor	15, 15, 0
-	PPC_GFMUL128_8x
+	xxlor	23+32, 12, 12
 
-	xxlor	30+32, 9, 9		# last ctr
-	vadduwm	30, 30, 31		# increase ctr
-	stxvb16x 32+0, 0, 8		# update Xi
+	cmpdi	10, 12
+	beq	Do_final_1x_dec
 
-	addi    5, 5, -128
-	addi    11, 11, 128
+	# 256 bits
+	xxlor	24+32, 13, 13
 
-	#
-	# Done 8x blocks
-	#
+	vcipher	15, 15, 23
+	vcipher	15, 15, 24
 
-	cmpdi   5, 0
-	beq     aes_gcm_out
+	xxlor	23+32, 14, 14
 
-__Process_more_dec:
-	li	24, 0			# decrypt
-	bl	aes_gcm_crypt_1x
-	cmpdi   5, 0
-	beq     aes_gcm_out
+	cmpdi	10, 14
+	beq	Do_final_1x_dec
 
-	bl	__Process_partial
-	b	aes_gcm_out
-.size   ppc_aes_gcm_decrypt,.-ppc_aes_gcm_decrypt
+Do_final_1x_dec:
+	vcipherlast     15, 15, 23
 
-aes_gcm_out:
+	lxvb16x	15, 0, 14		# load block
+	xxlxor	47, 47, 15
 
-	mr	3, 11			# return count
+	# create partial block mask
+	li	15, 16
+	sub	15, 15, 12		# index to the mask
+
+	vspltisb	16, -1		# first 16 bytes - 0xffff...ff
+	vspltisb	17, 0		# second 16 bytes - 0x0000...00
+	li	10, 192
+	stvx	16, 10, 1
+	addi	10, 10, 16
+	stvx	17, 10, 1
+
+	addi	10, 1, 192
+	lxvb16x	16, 15, 10		# load block mask
+	xxland	47, 47, 16
+
+	xxlor	28+32, 15, 15
+	ppc_update_hash_1x
+
+	# * should store only the remaining bytes.
+	bl	Write_partial_block
+
+	b aes_gcm_out
 
-	RESTORE_REGS
-	blr
-.size	aes_gcm_out,.-aes_gcm_out
 
-.rodata
-.align 4
-# for vector permute and xor
-permx:
-.long 0x4c5d6e7f, 0x08192a3b, 0xc4d5e6f7, 0x8091a2b3
 ___
 
-print $code;
-close STDOUT or die "error closing STDOUT: $!";
+foreach (split("\n",$code)) {
+	s/\`([^\`]*)\`/eval $1/geo;
+
+	if ($flavour =~ /le$/o) {	# little-endian
+	    s/le\?//o		or
+	    s/be\?/#be#/o;
+	} else {
+	    s/le\?/#le#/o	or
+	    s/be\?//o;
+	}
+	print $_,"\n";
+}
+
+close STDOUT or die "error closing STDOUT: $!"; # enforce flush
diff --git a/crypto/modes/asm/aesni-gcm-x86_64.pl b/crypto/modes/asm/aesni-gcm-x86_64.pl
index f3b920bb3a..a2b3d85364 100644
--- a/crypto/modes/asm/aesni-gcm-x86_64.pl
+++ b/crypto/modes/asm/aesni-gcm-x86_64.pl
@@ -73,13 +73,6 @@ if (!$avx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([0
 	$avx = ($2>=3.0) + ($2>3.0);
 }
 
-if (!$avx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$avx = ($1>=11); #icx started with clang 11
-	}
-}
-
 open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\""
     or die "can't call $xlate: $!";
 *STDOUT=*OUT;
diff --git a/crypto/modes/asm/ghash-armv4.pl b/crypto/modes/asm/ghash-armv4.pl
index b3b82bcf2c..f5618168bc 100644
--- a/crypto/modes/asm/ghash-armv4.pl
+++ b/crypto/modes/asm/ghash-armv4.pl
@@ -55,7 +55,7 @@
 # Câmara, D.; Gouvêa, C. P. L.; López, J. & Dahab, R.: Fast Software
 # Polynomial Multiplication on ARM Processors using the NEON Engine.
 #
-# https://conradoplg.modp.net/files/2010/12/mocrysen13.pdf
+# http://conradoplg.cryptoland.net/files/2010/12/mocrysen13.pdf
 
 # ====================================================================
 # Note about "528B" variant. In ARM case it makes lesser sense to
@@ -142,7 +142,7 @@ ___
 }
 
 $code=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 #if defined(__thumb2__) || defined(__clang__)
 .syntax	unified
@@ -296,7 +296,6 @@ $code.=<<___;
 
 .global	gcm_gmult_4bit
 .type	gcm_gmult_4bit,%function
-.align	4
 gcm_gmult_4bit:
 	stmdb	sp!,{r4-r11,lr}
 	ldrb	$nlo,[$Xi,#15]
diff --git a/crypto/modes/asm/ghash-s390x.pl b/crypto/modes/asm/ghash-s390x.pl
index fbb4ac6ffa..48dc33d99a 100644
--- a/crypto/modes/asm/ghash-s390x.pl
+++ b/crypto/modes/asm/ghash-s390x.pl
@@ -82,7 +82,7 @@ $rem_4bit="%r14";
 $sp="%r15";
 
 $code.=<<___;
-#include "arch/s390x_arch.h"
+#include "s390x_arch.h"
 
 .text
 
diff --git a/crypto/modes/asm/ghash-sparcv9.pl b/crypto/modes/asm/ghash-sparcv9.pl
index 63021645c0..8096d2d033 100644
--- a/crypto/modes/asm/ghash-sparcv9.pl
+++ b/crypto/modes/asm/ghash-sparcv9.pl
@@ -83,7 +83,7 @@ $code.=<<___;
 #ifndef __ASSEMBLER__
 # define __ASSEMBLER__ 1
 #endif
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 #ifdef  __arch64__
 .register	%g2,#scratch
diff --git a/crypto/modes/asm/ghash-x86_64.pl b/crypto/modes/asm/ghash-x86_64.pl
index 5a761cfb1f..eea0648682 100644
--- a/crypto/modes/asm/ghash-x86_64.pl
+++ b/crypto/modes/asm/ghash-x86_64.pl
@@ -121,13 +121,6 @@ if (!$avx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([0
 	$avx = ($2>=3.0) + ($2>3.0);
 }
 
-if (!$avx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$avx = ($1>=11); #icx started with clang 11
-	}
-}
-
 open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\""
     or die "can't call $xlate: $!";
 *STDOUT=*OUT;
diff --git a/crypto/modes/asm/ghashv8-armx.pl b/crypto/modes/asm/ghashv8-armx.pl
index 065154a8b3..5401e50bf8 100644
--- a/crypto/modes/asm/ghashv8-armx.pl
+++ b/crypto/modes/asm/ghashv8-armx.pl
@@ -73,7 +73,7 @@ my ($t0,$t1,$t2,$xC2,$H,$Hhl,$H2)=map("q$_",(8..14));
 my $_byte = ($flavour =~ /win/ ? "DCB" : ".byte");
 
 $code=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 #if __ARM_MAX_ARCH__>=7
 ___
diff --git a/crypto/modes/build.info b/crypto/modes/build.info
index 9fb2d503d8..52d2df19c6 100644
--- a/crypto/modes/build.info
+++ b/crypto/modes/build.info
@@ -35,7 +35,7 @@ IF[{- !$disabled{asm} -}]
   $MODESASM_ppc32=ghashp8-ppc.s
   $MODESDEF_ppc32=
   $MODESASM_ppc64=$MODESASM_ppc32
-  IF[{- $target{perlasm_scheme} =~ /le$/ -}]
+  IF[{- $target{sys_id} ne "AIX" && $target{sys_id} ne "MACOSX" -}]
     $MODESASM_ppc64=$MODESASM_ppc32 aes-gcm-ppc.s
   ENDIF
   $MODESDEF_ppc64=$MODESDEF_ppc32
diff --git a/crypto/modes/ccm128.c b/crypto/modes/ccm128.c
index ba73600f39..02ab4f8831 100644
--- a/crypto/modes/ccm128.c
+++ b/crypto/modes/ccm128.c
@@ -13,9 +13,9 @@
 
 #ifndef STRICT_ALIGNMENT
 #ifdef __GNUC__
-typedef uint64_t u64_a1 __attribute((__aligned__(1)));
+typedef u64 u64_a1 __attribute((__aligned__(1)));
 #else
-typedef uint64_t u64_a1;
+typedef u64 u64_a1;
 #endif
 #endif
 
@@ -28,7 +28,7 @@ void CRYPTO_ccm128_init(CCM128_CONTEXT *ctx,
     block128_f block)
 {
     memset(ctx->nonce.c, 0, sizeof(ctx->nonce.c));
-    ctx->nonce.c[0] = ((uint8_t)(L - 1) & 7) | (uint8_t)(((M - 2) / 2) & 7) << 3;
+    ctx->nonce.c[0] = ((u8)(L - 1) & 7) | (u8)(((M - 2) / 2) & 7) << 3;
     ctx->blocks = 0;
     ctx->block = block;
     ctx->key = key;
@@ -46,17 +46,17 @@ int CRYPTO_ccm128_setiv(CCM128_CONTEXT *ctx,
         return -1; /* nonce is too short */
 
     if (sizeof(mlen) == 8 && L >= 3) {
-        ctx->nonce.c[8] = (uint8_t)(mlen >> (56 % (sizeof(mlen) * 8)));
-        ctx->nonce.c[9] = (uint8_t)(mlen >> (48 % (sizeof(mlen) * 8)));
-        ctx->nonce.c[10] = (uint8_t)(mlen >> (40 % (sizeof(mlen) * 8)));
-        ctx->nonce.c[11] = (uint8_t)(mlen >> (32 % (sizeof(mlen) * 8)));
+        ctx->nonce.c[8] = (u8)(mlen >> (56 % (sizeof(mlen) * 8)));
+        ctx->nonce.c[9] = (u8)(mlen >> (48 % (sizeof(mlen) * 8)));
+        ctx->nonce.c[10] = (u8)(mlen >> (40 % (sizeof(mlen) * 8)));
+        ctx->nonce.c[11] = (u8)(mlen >> (32 % (sizeof(mlen) * 8)));
     } else
         ctx->nonce.u[1] = 0;
 
-    ctx->nonce.c[12] = (uint8_t)(mlen >> 24);
-    ctx->nonce.c[13] = (uint8_t)(mlen >> 16);
-    ctx->nonce.c[14] = (uint8_t)(mlen >> 8);
-    ctx->nonce.c[15] = (uint8_t)mlen;
+    ctx->nonce.c[12] = (u8)(mlen >> 24);
+    ctx->nonce.c[13] = (u8)(mlen >> 16);
+    ctx->nonce.c[14] = (u8)(mlen >> 8);
+    ctx->nonce.c[15] = (u8)mlen;
 
     ctx->nonce.c[0] &= ~0x40; /* clear Adata flag */
     memcpy(&ctx->nonce.c[1], nonce, 14 - L);
@@ -78,29 +78,29 @@ void CRYPTO_ccm128_aad(CCM128_CONTEXT *ctx,
     (*block)(ctx->nonce.c, ctx->cmac.c, ctx->key), ctx->blocks++;
 
     if (alen < (0x10000 - 0x100)) {
-        ctx->cmac.c[0] ^= (uint8_t)(alen >> 8);
-        ctx->cmac.c[1] ^= (uint8_t)alen;
+        ctx->cmac.c[0] ^= (u8)(alen >> 8);
+        ctx->cmac.c[1] ^= (u8)alen;
         i = 2;
     } else if (sizeof(alen) == 8
         && alen >= (size_t)1 << (32 % (sizeof(alen) * 8))) {
         ctx->cmac.c[0] ^= 0xFF;
         ctx->cmac.c[1] ^= 0xFF;
-        ctx->cmac.c[2] ^= (uint8_t)(alen >> (56 % (sizeof(alen) * 8)));
-        ctx->cmac.c[3] ^= (uint8_t)(alen >> (48 % (sizeof(alen) * 8)));
-        ctx->cmac.c[4] ^= (uint8_t)(alen >> (40 % (sizeof(alen) * 8)));
-        ctx->cmac.c[5] ^= (uint8_t)(alen >> (32 % (sizeof(alen) * 8)));
-        ctx->cmac.c[6] ^= (uint8_t)(alen >> 24);
-        ctx->cmac.c[7] ^= (uint8_t)(alen >> 16);
-        ctx->cmac.c[8] ^= (uint8_t)(alen >> 8);
-        ctx->cmac.c[9] ^= (uint8_t)alen;
+        ctx->cmac.c[2] ^= (u8)(alen >> (56 % (sizeof(alen) * 8)));
+        ctx->cmac.c[3] ^= (u8)(alen >> (48 % (sizeof(alen) * 8)));
+        ctx->cmac.c[4] ^= (u8)(alen >> (40 % (sizeof(alen) * 8)));
+        ctx->cmac.c[5] ^= (u8)(alen >> (32 % (sizeof(alen) * 8)));
+        ctx->cmac.c[6] ^= (u8)(alen >> 24);
+        ctx->cmac.c[7] ^= (u8)(alen >> 16);
+        ctx->cmac.c[8] ^= (u8)(alen >> 8);
+        ctx->cmac.c[9] ^= (u8)alen;
         i = 10;
     } else {
         ctx->cmac.c[0] ^= 0xFF;
         ctx->cmac.c[1] ^= 0xFE;
-        ctx->cmac.c[2] ^= (uint8_t)(alen >> 24);
-        ctx->cmac.c[3] ^= (uint8_t)(alen >> 16);
-        ctx->cmac.c[4] ^= (uint8_t)(alen >> 8);
-        ctx->cmac.c[5] ^= (uint8_t)alen;
+        ctx->cmac.c[2] ^= (u8)(alen >> 24);
+        ctx->cmac.c[3] ^= (u8)(alen >> 16);
+        ctx->cmac.c[4] ^= (u8)(alen >> 8);
+        ctx->cmac.c[5] ^= (u8)alen;
         i = 6;
     }
 
@@ -121,7 +121,7 @@ void CRYPTO_ccm128_aad(CCM128_CONTEXT *ctx,
 static void ctr64_inc(unsigned char *counter)
 {
     unsigned int n = 8;
-    uint8_t c;
+    u8 c;
 
     counter += 8;
     do {
@@ -144,8 +144,8 @@ int CRYPTO_ccm128_encrypt(CCM128_CONTEXT *ctx,
     block128_f block = ctx->block;
     void *key = ctx->key;
     union {
-        uint64_t u[2];
-        uint8_t c[16];
+        u64 u[2];
+        u8 c[16];
     } scratch;
 
     if (!(flags0 & 0x40))
@@ -170,8 +170,8 @@ int CRYPTO_ccm128_encrypt(CCM128_CONTEXT *ctx,
     while (len >= 16) {
 #if defined(STRICT_ALIGNMENT)
         union {
-            uint64_t u[2];
-            uint8_t c[16];
+            u64 u[2];
+            u8 c[16];
         } temp;
 
         memcpy(temp.c, inp, 16);
@@ -228,8 +228,8 @@ int CRYPTO_ccm128_decrypt(CCM128_CONTEXT *ctx,
     block128_f block = ctx->block;
     void *key = ctx->key;
     union {
-        uint64_t u[2];
-        uint8_t c[16];
+        u64 u[2];
+        u8 c[16];
     } scratch;
 
     if (!(flags0 & 0x40))
@@ -250,8 +250,8 @@ int CRYPTO_ccm128_decrypt(CCM128_CONTEXT *ctx,
     while (len >= 16) {
 #if defined(STRICT_ALIGNMENT)
         union {
-            uint64_t u[2];
-            uint8_t c[16];
+            u64 u[2];
+            u8 c[16];
         } temp;
 #endif
         (*block)(ctx->nonce.c, scratch.c, key);
@@ -317,8 +317,8 @@ int CRYPTO_ccm128_encrypt_ccm64(CCM128_CONTEXT *ctx,
     block128_f block = ctx->block;
     void *key = ctx->key;
     union {
-        uint64_t u[2];
-        uint8_t c[16];
+        u64 u[2];
+        u8 c[16];
     } scratch;
 
     if (!(flags0 & 0x40))
@@ -381,8 +381,8 @@ int CRYPTO_ccm128_decrypt_ccm64(CCM128_CONTEXT *ctx,
     block128_f block = ctx->block;
     void *key = ctx->key;
     union {
-        uint64_t u[2];
-        uint8_t c[16];
+        u64 u[2];
+        u8 c[16];
     } scratch;
 
     if (!(flags0 & 0x40))
diff --git a/crypto/modes/ctr128.c b/crypto/modes/ctr128.c
index 5954615e7d..6013d6ee41 100644
--- a/crypto/modes/ctr128.c
+++ b/crypto/modes/ctr128.c
@@ -26,12 +26,12 @@ typedef size_t size_t_aX;
 /* increment counter (128-bit int) by 1 */
 static void ctr128_inc(unsigned char *counter)
 {
-    uint32_t n = 16, c = 1;
+    u32 n = 16, c = 1;
 
     do {
         --n;
         c += counter[n];
-        counter[n] = (uint8_t)c;
+        counter[n] = (u8)c;
         c >>= 8;
     } while (n);
 }
@@ -137,12 +137,12 @@ void CRYPTO_ctr128_encrypt(const unsigned char *in, unsigned char *out,
 /* increment upper 96 bits of 128-bit counter by 1 */
 static void ctr96_inc(unsigned char *counter)
 {
-    uint32_t n = 12, c = 1;
+    u32 n = 12, c = 1;
 
     do {
         --n;
         c += counter[n];
-        counter[n] = (uint8_t)c;
+        counter[n] = (u8)c;
         c >>= 8;
     } while (n);
 }
@@ -179,7 +179,7 @@ void CRYPTO_ctr128_encrypt_ctr32(const unsigned char *in, unsigned char *out,
          * overflow, which is then handled by limiting the
          * amount of blocks to the exact overflow point...
          */
-        ctr32 += (uint32_t)blocks;
+        ctr32 += (u32)blocks;
         if (ctr32 < blocks) {
             blocks -= ctr32;
             ctr32 = 0;
diff --git a/crypto/modes/gcm128.c b/crypto/modes/gcm128.c
index 1b77c2e27e..16c13e2961 100644
--- a/crypto/modes/gcm128.c
+++ b/crypto/modes/gcm128.c
@@ -22,9 +22,9 @@ typedef size_t size_t_aX;
 #if defined(BSWAP4) && defined(STRICT_ALIGNMENT)
 /* redefine, because alignment is ensured */
 #undef GETU32
-#define GETU32(p) BSWAP4(*(const uint32_t *)(p))
+#define GETU32(p) BSWAP4(*(const u32 *)(p))
 #undef PUTU32
-#define PUTU32(p, v) *(uint32_t *)(p) = BSWAP4(v)
+#define PUTU32(p, v) *(u32 *)(p) = BSWAP4(v)
 #endif
 
 /* RISC-V uses C implementation as a fallback. */
@@ -34,17 +34,17 @@ typedef size_t size_t_aX;
 #endif
 
 #define PACK(s) ((size_t)(s) << (sizeof(size_t) * 8 - 16))
-#define REDUCE1BIT(V)                                                \
-    do {                                                             \
-        if (sizeof(size_t) == 8) {                                   \
-            uint64_t T = U64(0xe100000000000000) & (0 - (V.lo & 1)); \
-            V.lo = (V.hi << 63) | (V.lo >> 1);                       \
-            V.hi = (V.hi >> 1) ^ T;                                  \
-        } else {                                                     \
-            uint32_t T = 0xe1000000U & (0 - (uint32_t)(V.lo & 1));   \
-            V.lo = (V.hi << 63) | (V.lo >> 1);                       \
-            V.hi = (V.hi >> 1) ^ ((uint64_t)T << 32);                \
-        }                                                            \
+#define REDUCE1BIT(V)                                           \
+    do {                                                        \
+        if (sizeof(size_t) == 8) {                              \
+            u64 T = U64(0xe100000000000000) & (0 - (V.lo & 1)); \
+            V.lo = (V.hi << 63) | (V.lo >> 1);                  \
+            V.hi = (V.hi >> 1) ^ T;                             \
+        } else {                                                \
+            u32 T = 0xe1000000U & (0 - (u32)(V.lo & 1));        \
+            V.lo = (V.hi << 63) | (V.lo >> 1);                  \
+            V.hi = (V.hi >> 1) ^ ((u64)T << 32);                \
+        }                                                       \
     } while (0)
 
 /*-
@@ -85,7 +85,7 @@ typedef size_t size_t_aX;
  * Value of 1 is not appropriate for performance reasons.
  */
 
-static void gcm_init_4bit(u128 Htable[16], const uint64_t H[2])
+static void gcm_init_4bit(u128 Htable[16], const u64 H[2])
 {
     u128 V;
 #if defined(OPENSSL_SMALL_FOOTPRINT)
@@ -165,14 +165,14 @@ static const size_t rem_4bit[16] = {
     PACK(0x9180), PACK(0x8DA0), PACK(0xA9C0), PACK(0xB5E0)
 };
 
-static void gcm_gmult_4bit(uint64_t Xi[2], const u128 Htable[16])
+static void gcm_gmult_4bit(u64 Xi[2], const u128 Htable[16])
 {
     u128 Z;
     int cnt = 15;
     size_t rem, nlo, nhi;
     DECLARE_IS_ENDIAN;
 
-    nlo = ((const uint8_t *)Xi)[15];
+    nlo = ((const u8 *)Xi)[15];
     nhi = nlo >> 4;
     nlo &= 0xf;
 
@@ -186,7 +186,7 @@ static void gcm_gmult_4bit(uint64_t Xi[2], const u128 Htable[16])
         if (sizeof(size_t) == 8)
             Z.hi ^= rem_4bit[rem];
         else
-            Z.hi ^= (uint64_t)rem_4bit[rem] << 32;
+            Z.hi ^= (u64)rem_4bit[rem] << 32;
 
         Z.hi ^= Htable[nhi].hi;
         Z.lo ^= Htable[nhi].lo;
@@ -194,7 +194,7 @@ static void gcm_gmult_4bit(uint64_t Xi[2], const u128 Htable[16])
         if (--cnt < 0)
             break;
 
-        nlo = ((const uint8_t *)Xi)[cnt];
+        nlo = ((const u8 *)Xi)[cnt];
         nhi = nlo >> 4;
         nlo &= 0xf;
 
@@ -204,7 +204,7 @@ static void gcm_gmult_4bit(uint64_t Xi[2], const u128 Htable[16])
         if (sizeof(size_t) == 8)
             Z.hi ^= rem_4bit[rem];
         else
-            Z.hi ^= (uint64_t)rem_4bit[rem] << 32;
+            Z.hi ^= (u64)rem_4bit[rem] << 32;
 
         Z.hi ^= Htable[nlo].hi;
         Z.lo ^= Htable[nlo].lo;
@@ -215,15 +215,15 @@ static void gcm_gmult_4bit(uint64_t Xi[2], const u128 Htable[16])
         Xi[0] = BSWAP8(Z.hi);
         Xi[1] = BSWAP8(Z.lo);
 #else
-        uint8_t *p = (uint8_t *)Xi;
-        uint32_t v;
-        v = (uint32_t)(Z.hi >> 32);
+        u8 *p = (u8 *)Xi;
+        u32 v;
+        v = (u32)(Z.hi >> 32);
         PUTU32(p, v);
-        v = (uint32_t)(Z.hi);
+        v = (u32)(Z.hi);
         PUTU32(p + 4, v);
-        v = (uint32_t)(Z.lo >> 32);
+        v = (u32)(Z.lo >> 32);
         PUTU32(p + 8, v);
-        v = (uint32_t)(Z.lo);
+        v = (u32)(Z.lo);
         PUTU32(p + 12, v);
 #endif
     } else {
@@ -243,8 +243,8 @@ static void gcm_gmult_4bit(uint64_t Xi[2], const u128 Htable[16])
  * mostly as reference and a placeholder for possible future
  * non-trivial optimization[s]...
  */
-static void gcm_ghash_4bit(uint64_t Xi[2], const u128 Htable[16],
-    const uint8_t *inp, size_t len)
+static void gcm_ghash_4bit(u64 Xi[2], const u128 Htable[16],
+    const u8 *inp, size_t len)
 {
     u128 Z;
     int cnt;
@@ -253,7 +253,7 @@ static void gcm_ghash_4bit(uint64_t Xi[2], const u128 Htable[16],
 
     do {
         cnt = 15;
-        nlo = ((const uint8_t *)Xi)[15];
+        nlo = ((const u8 *)Xi)[15];
         nlo ^= inp[15];
         nhi = nlo >> 4;
         nlo &= 0xf;
@@ -268,7 +268,7 @@ static void gcm_ghash_4bit(uint64_t Xi[2], const u128 Htable[16],
             if (sizeof(size_t) == 8)
                 Z.hi ^= rem_4bit[rem];
             else
-                Z.hi ^= (uint64_t)rem_4bit[rem] << 32;
+                Z.hi ^= (u64)rem_4bit[rem] << 32;
 
             Z.hi ^= Htable[nhi].hi;
             Z.lo ^= Htable[nhi].lo;
@@ -276,7 +276,7 @@ static void gcm_ghash_4bit(uint64_t Xi[2], const u128 Htable[16],
             if (--cnt < 0)
                 break;
 
-            nlo = ((const uint8_t *)Xi)[cnt];
+            nlo = ((const u8 *)Xi)[cnt];
             nlo ^= inp[cnt];
             nhi = nlo >> 4;
             nlo &= 0xf;
@@ -287,7 +287,7 @@ static void gcm_ghash_4bit(uint64_t Xi[2], const u128 Htable[16],
             if (sizeof(size_t) == 8)
                 Z.hi ^= rem_4bit[rem];
             else
-                Z.hi ^= (uint64_t)rem_4bit[rem] << 32;
+                Z.hi ^= (u64)rem_4bit[rem] << 32;
 
             Z.hi ^= Htable[nlo].hi;
             Z.lo ^= Htable[nlo].lo;
@@ -298,15 +298,15 @@ static void gcm_ghash_4bit(uint64_t Xi[2], const u128 Htable[16],
             Xi[0] = BSWAP8(Z.hi);
             Xi[1] = BSWAP8(Z.lo);
 #else
-            uint8_t *p = (uint8_t *)Xi;
-            uint32_t v;
-            v = (uint32_t)(Z.hi >> 32);
+            u8 *p = (u8 *)Xi;
+            u32 v;
+            v = (u32)(Z.hi >> 32);
             PUTU32(p, v);
-            v = (uint32_t)(Z.hi);
+            v = (u32)(Z.hi);
             PUTU32(p + 4, v);
-            v = (uint32_t)(Z.lo >> 32);
+            v = (u32)(Z.lo >> 32);
             PUTU32(p + 8, v);
-            v = (uint32_t)(Z.lo);
+            v = (u32)(Z.lo);
             PUTU32(p + 12, v);
 #endif
         } else {
@@ -321,8 +321,8 @@ static void gcm_ghash_4bit(uint64_t Xi[2], const u128 Htable[16],
 }
 #endif
 #else
-void gcm_gmult_4bit(uint64_t Xi[2], const u128 Htable[16]);
-void gcm_ghash_4bit(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp,
+void gcm_gmult_4bit(u64 Xi[2], const u128 Htable[16]);
+void gcm_ghash_4bit(u64 Xi[2], const u128 Htable[16], const u8 *inp,
     size_t len);
 #endif
 
@@ -341,9 +341,9 @@ void gcm_ghash_4bit(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp,
 #if !defined(I386_ONLY) && (defined(__i386) || defined(__i386__) || defined(__x86_64) || defined(__x86_64__) || defined(_M_IX86) || defined(_M_AMD64) || defined(_M_X64))
 #define GHASH_ASM_X86_OR_64
 
-void gcm_init_clmul(u128 Htable[16], const uint64_t Xi[2]);
-void gcm_gmult_clmul(uint64_t Xi[2], const u128 Htable[16]);
-void gcm_ghash_clmul(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp,
+void gcm_init_clmul(u128 Htable[16], const u64 Xi[2]);
+void gcm_gmult_clmul(u64 Xi[2], const u128 Htable[16]);
+void gcm_ghash_clmul(u64 Xi[2], const u128 Htable[16], const u8 *inp,
     size_t len);
 
 #if defined(__i386) || defined(__i386__) || defined(_M_IX86)
@@ -351,77 +351,77 @@ void gcm_ghash_clmul(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp,
 #define gcm_gmult_avx gcm_gmult_clmul
 #define gcm_ghash_avx gcm_ghash_clmul
 #else
-void gcm_init_avx(u128 Htable[16], const uint64_t Xi[2]);
-void gcm_gmult_avx(uint64_t Xi[2], const u128 Htable[16]);
-void gcm_ghash_avx(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp,
+void gcm_init_avx(u128 Htable[16], const u64 Xi[2]);
+void gcm_gmult_avx(u64 Xi[2], const u128 Htable[16]);
+void gcm_ghash_avx(u64 Xi[2], const u128 Htable[16], const u8 *inp,
     size_t len);
 #endif
 
 #if defined(__i386) || defined(__i386__) || defined(_M_IX86)
 #define GHASH_ASM_X86
-void gcm_gmult_4bit_mmx(uint64_t Xi[2], const u128 Htable[16]);
-void gcm_ghash_4bit_mmx(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp,
+void gcm_gmult_4bit_mmx(u64 Xi[2], const u128 Htable[16]);
+void gcm_ghash_4bit_mmx(u64 Xi[2], const u128 Htable[16], const u8 *inp,
     size_t len);
 
-void gcm_gmult_4bit_x86(uint64_t Xi[2], const u128 Htable[16]);
-void gcm_ghash_4bit_x86(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp,
+void gcm_gmult_4bit_x86(u64 Xi[2], const u128 Htable[16]);
+void gcm_ghash_4bit_x86(u64 Xi[2], const u128 Htable[16], const u8 *inp,
     size_t len);
 #endif
 #elif defined(__arm__) || defined(__arm) || defined(__aarch64__) || defined(_M_ARM64)
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 #if __ARM_MAX_ARCH__ >= 7
 #define GHASH_ASM_ARM
 #define PMULL_CAPABLE (OPENSSL_armcap_P & ARMV8_PMULL)
 #if defined(__arm__) || defined(__arm)
 #define NEON_CAPABLE (OPENSSL_armcap_P & ARMV7_NEON)
 #endif
-void gcm_init_neon(u128 Htable[16], const uint64_t Xi[2]);
-void gcm_gmult_neon(uint64_t Xi[2], const u128 Htable[16]);
-void gcm_ghash_neon(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp,
+void gcm_init_neon(u128 Htable[16], const u64 Xi[2]);
+void gcm_gmult_neon(u64 Xi[2], const u128 Htable[16]);
+void gcm_ghash_neon(u64 Xi[2], const u128 Htable[16], const u8 *inp,
     size_t len);
-void gcm_init_v8(u128 Htable[16], const uint64_t Xi[2]);
-void gcm_gmult_v8(uint64_t Xi[2], const u128 Htable[16]);
-void gcm_ghash_v8(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp,
+void gcm_init_v8(u128 Htable[16], const u64 Xi[2]);
+void gcm_gmult_v8(u64 Xi[2], const u128 Htable[16]);
+void gcm_ghash_v8(u64 Xi[2], const u128 Htable[16], const u8 *inp,
     size_t len);
 #endif
 #elif defined(__sparc__) || defined(__sparc)
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 #define GHASH_ASM_SPARC
-void gcm_init_vis3(u128 Htable[16], const uint64_t Xi[2]);
-void gcm_gmult_vis3(uint64_t Xi[2], const u128 Htable[16]);
-void gcm_ghash_vis3(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp,
+void gcm_init_vis3(u128 Htable[16], const u64 Xi[2]);
+void gcm_gmult_vis3(u64 Xi[2], const u128 Htable[16]);
+void gcm_ghash_vis3(u64 Xi[2], const u128 Htable[16], const u8 *inp,
     size_t len);
 #elif defined(OPENSSL_CPUID_OBJ) && (defined(__powerpc__) || defined(__POWERPC__) || defined(_ARCH_PPC))
-#include "arch/ppc_arch.h"
+#include "crypto/ppc_arch.h"
 #define GHASH_ASM_PPC
-void gcm_init_p8(u128 Htable[16], const uint64_t Xi[2]);
-void gcm_gmult_p8(uint64_t Xi[2], const u128 Htable[16]);
-void gcm_ghash_p8(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp,
+void gcm_init_p8(u128 Htable[16], const u64 Xi[2]);
+void gcm_gmult_p8(u64 Xi[2], const u128 Htable[16]);
+void gcm_ghash_p8(u64 Xi[2], const u128 Htable[16], const u8 *inp,
     size_t len);
 #elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64
-#include "arch/riscv_arch.h"
+#include "crypto/riscv_arch.h"
 #define GHASH_ASM_RV64I
 /* Zbc/Zbkc (scalar crypto with clmul) based routines. */
-void gcm_init_rv64i_zbc(u128 Htable[16], const uint64_t Xi[2]);
-void gcm_init_rv64i_zbc__zbb(u128 Htable[16], const uint64_t Xi[2]);
-void gcm_init_rv64i_zbc__zbkb(u128 Htable[16], const uint64_t Xi[2]);
-void gcm_gmult_rv64i_zbc(uint64_t Xi[2], const u128 Htable[16]);
-void gcm_gmult_rv64i_zbc__zbkb(uint64_t Xi[2], const u128 Htable[16]);
-void gcm_ghash_rv64i_zbc(uint64_t Xi[2], const u128 Htable[16],
-    const uint8_t *inp, size_t len);
-void gcm_ghash_rv64i_zbc__zbkb(uint64_t Xi[2], const u128 Htable[16],
-    const uint8_t *inp, size_t len);
+void gcm_init_rv64i_zbc(u128 Htable[16], const u64 Xi[2]);
+void gcm_init_rv64i_zbc__zbb(u128 Htable[16], const u64 Xi[2]);
+void gcm_init_rv64i_zbc__zbkb(u128 Htable[16], const u64 Xi[2]);
+void gcm_gmult_rv64i_zbc(u64 Xi[2], const u128 Htable[16]);
+void gcm_gmult_rv64i_zbc__zbkb(u64 Xi[2], const u128 Htable[16]);
+void gcm_ghash_rv64i_zbc(u64 Xi[2], const u128 Htable[16],
+    const u8 *inp, size_t len);
+void gcm_ghash_rv64i_zbc__zbkb(u64 Xi[2], const u128 Htable[16],
+    const u8 *inp, size_t len);
 /* zvkb/Zvbc (vector crypto with vclmul) based routines. */
-void gcm_init_rv64i_zvkb_zvbc(u128 Htable[16], const uint64_t Xi[2]);
-void gcm_gmult_rv64i_zvkb_zvbc(uint64_t Xi[2], const u128 Htable[16]);
-void gcm_ghash_rv64i_zvkb_zvbc(uint64_t Xi[2], const u128 Htable[16],
-    const uint8_t *inp, size_t len);
+void gcm_init_rv64i_zvkb_zvbc(u128 Htable[16], const u64 Xi[2]);
+void gcm_gmult_rv64i_zvkb_zvbc(u64 Xi[2], const u128 Htable[16]);
+void gcm_ghash_rv64i_zvkb_zvbc(u64 Xi[2], const u128 Htable[16],
+    const u8 *inp, size_t len);
 /* Zvkg (vector crypto with vgmul.vv and vghsh.vv). */
-void gcm_init_rv64i_zvkg(u128 Htable[16], const uint64_t Xi[2]);
-void gcm_init_rv64i_zvkg_zvkb(u128 Htable[16], const uint64_t Xi[2]);
-void gcm_gmult_rv64i_zvkg(uint64_t Xi[2], const u128 Htable[16]);
-void gcm_ghash_rv64i_zvkg(uint64_t Xi[2], const u128 Htable[16],
-    const uint8_t *inp, size_t len);
+void gcm_init_rv64i_zvkg(u128 Htable[16], const u64 Xi[2]);
+void gcm_init_rv64i_zvkg_zvkb(u128 Htable[16], const u64 Xi[2]);
+void gcm_gmult_rv64i_zvkg(u64 Xi[2], const u128 Htable[16]);
+void gcm_ghash_rv64i_zvkg(u64 Xi[2], const u128 Htable[16],
+    const u8 *inp, size_t len);
 #endif
 #endif
 
@@ -560,7 +560,7 @@ static void gcm_get_funcs(struct gcm_funcs_st *ctx)
 #endif
 }
 
-void ossl_gcm_init_4bit(u128 Htable[16], const uint64_t H[2])
+void ossl_gcm_init_4bit(u128 Htable[16], const u64 H[2])
 {
     struct gcm_funcs_st funcs;
 
@@ -568,7 +568,7 @@ void ossl_gcm_init_4bit(u128 Htable[16], const uint64_t H[2])
     funcs.ginit(Htable, H);
 }
 
-void ossl_gcm_gmult_4bit(uint64_t Xi[2], const u128 Htable[16])
+void ossl_gcm_gmult_4bit(u64 Xi[2], const u128 Htable[16])
 {
     struct gcm_funcs_st funcs;
 
@@ -576,11 +576,11 @@ void ossl_gcm_gmult_4bit(uint64_t Xi[2], const u128 Htable[16])
     funcs.gmult(Xi, Htable);
 }
 
-void ossl_gcm_ghash_4bit(uint64_t Xi[2], const u128 Htable[16],
-    const uint8_t *inp, size_t len)
+void ossl_gcm_ghash_4bit(u64 Xi[2], const u128 Htable[16],
+    const u8 *inp, size_t len)
 {
     struct gcm_funcs_st funcs;
-    uint64_t tmp[2];
+    u64 tmp[2];
     size_t i;
 
     gcm_get_funcs(&funcs);
@@ -613,10 +613,10 @@ void CRYPTO_gcm128_init(GCM128_CONTEXT *ctx, void *key, block128_f block)
         ctx->H.u[0] = BSWAP8(ctx->H.u[0]);
         ctx->H.u[1] = BSWAP8(ctx->H.u[1]);
 #else
-        uint8_t *p = ctx->H.c;
-        uint64_t hi, lo;
-        hi = (uint64_t)GETU32(p) << 32 | GETU32(p + 4);
-        lo = (uint64_t)GETU32(p + 8) << 32 | GETU32(p + 12);
+        u8 *p = ctx->H.c;
+        u64 hi, lo;
+        hi = (u64)GETU32(p) << 32 | GETU32(p + 4);
+        lo = (u64)GETU32(p + 8) << 32 | GETU32(p + 12);
         ctx->H.u[0] = hi;
         ctx->H.u[1] = lo;
 #endif
@@ -646,7 +646,7 @@ void CRYPTO_gcm128_setiv(GCM128_CONTEXT *ctx, const unsigned char *iv,
         ctr = 1;
     } else {
         size_t i;
-        uint64_t len0 = len;
+        u64 len0 = len;
 
         /* Borrow ctx->Xi to calculate initial Yi */
         ctx->Xi.u[0] = 0;
@@ -669,14 +669,14 @@ void CRYPTO_gcm128_setiv(GCM128_CONTEXT *ctx, const unsigned char *iv,
 #ifdef BSWAP8
             ctx->Xi.u[1] ^= BSWAP8(len0);
 #else
-            ctx->Xi.c[8] ^= (uint8_t)(len0 >> 56);
-            ctx->Xi.c[9] ^= (uint8_t)(len0 >> 48);
-            ctx->Xi.c[10] ^= (uint8_t)(len0 >> 40);
-            ctx->Xi.c[11] ^= (uint8_t)(len0 >> 32);
-            ctx->Xi.c[12] ^= (uint8_t)(len0 >> 24);
-            ctx->Xi.c[13] ^= (uint8_t)(len0 >> 16);
-            ctx->Xi.c[14] ^= (uint8_t)(len0 >> 8);
-            ctx->Xi.c[15] ^= (uint8_t)(len0);
+            ctx->Xi.c[8] ^= (u8)(len0 >> 56);
+            ctx->Xi.c[9] ^= (u8)(len0 >> 48);
+            ctx->Xi.c[10] ^= (u8)(len0 >> 40);
+            ctx->Xi.c[11] ^= (u8)(len0 >> 32);
+            ctx->Xi.c[12] ^= (u8)(len0 >> 24);
+            ctx->Xi.c[13] ^= (u8)(len0 >> 16);
+            ctx->Xi.c[14] ^= (u8)(len0 >> 8);
+            ctx->Xi.c[15] ^= (u8)(len0);
 #endif
         } else {
             ctx->Xi.u[1] ^= len0;
@@ -718,7 +718,7 @@ int CRYPTO_gcm128_aad(GCM128_CONTEXT *ctx, const unsigned char *aad,
 {
     size_t i;
     unsigned int n;
-    uint64_t alen = ctx->len.u[0];
+    u64 alen = ctx->len.u[0];
 
     if (ctx->len.u[1])
         return -2;
@@ -774,7 +774,7 @@ int CRYPTO_gcm128_encrypt(GCM128_CONTEXT *ctx,
     DECLARE_IS_ENDIAN;
     unsigned int n, ctr, mres;
     size_t i;
-    uint64_t mlen = ctx->len.u[1];
+    u64 mlen = ctx->len.u[1];
     block128_f block = ctx->block;
     void *key = ctx->key;
 
@@ -999,7 +999,7 @@ int CRYPTO_gcm128_decrypt(GCM128_CONTEXT *ctx,
     DECLARE_IS_ENDIAN;
     unsigned int n, ctr, mres;
     size_t i;
-    uint64_t mlen = ctx->len.u[1];
+    u64 mlen = ctx->len.u[1];
     block128_f block = ctx->block;
     void *key = ctx->key;
 
@@ -1057,7 +1057,7 @@ int CRYPTO_gcm128_decrypt(GCM128_CONTEXT *ctx,
                 }
 #else
                 while (n && len) {
-                    uint8_t c = *(in++);
+                    u8 c = *(in++);
                     *(out++) = c ^ ctx->EKi.c[n];
                     ctx->Xi.c[n] ^= c;
                     --len;
@@ -1176,7 +1176,7 @@ int CRYPTO_gcm128_decrypt(GCM128_CONTEXT *ctx,
                 }
 #else
                 while (len--) {
-                    uint8_t c = in[n];
+                    u8 c = in[n];
                     ctx->Xi.c[n] ^= c;
                     out[n] = c ^ ctx->EKi.c[n];
                     ++n;
@@ -1191,7 +1191,7 @@ int CRYPTO_gcm128_decrypt(GCM128_CONTEXT *ctx,
     }
 #endif
     for (i = 0; i < len; ++i) {
-        uint8_t c;
+        u8 c;
         if (n == 0) {
             (*block)(ctx->Yi.c, ctx->EKi.c, key);
             ++ctr;
@@ -1235,7 +1235,7 @@ int CRYPTO_gcm128_encrypt_ctr32(GCM128_CONTEXT *ctx,
     DECLARE_IS_ENDIAN;
     unsigned int n, ctr, mres;
     size_t i;
-    uint64_t mlen = ctx->len.u[1];
+    u64 mlen = ctx->len.u[1];
     void *key = ctx->key;
 
     mlen += len;
@@ -1389,7 +1389,7 @@ int CRYPTO_gcm128_decrypt_ctr32(GCM128_CONTEXT *ctx,
     DECLARE_IS_ENDIAN;
     unsigned int n, ctr, mres;
     size_t i;
-    uint64_t mlen = ctx->len.u[1];
+    u64 mlen = ctx->len.u[1];
     void *key = ctx->key;
 
     mlen += len;
@@ -1443,7 +1443,7 @@ int CRYPTO_gcm128_decrypt_ctr32(GCM128_CONTEXT *ctx,
         }
 #else
         while (n && len) {
-            uint8_t c = *(in++);
+            u8 c = *(in++);
             *(out++) = c ^ ctx->EKi.c[n];
             ctx->Xi.c[n] ^= c;
             --len;
@@ -1527,7 +1527,7 @@ int CRYPTO_gcm128_decrypt_ctr32(GCM128_CONTEXT *ctx,
 #if defined(GHASH)
             out[n] = (ctx->Xn[mres++] = in[n]) ^ ctx->EKi.c[n];
 #else
-            uint8_t c = in[n];
+            u8 c = in[n];
             ctx->Xi.c[mres++] ^= c;
             out[n] = c ^ ctx->EKi.c[n];
 #endif
@@ -1544,8 +1544,8 @@ int CRYPTO_gcm128_finish(GCM128_CONTEXT *ctx, const unsigned char *tag,
     size_t len)
 {
     DECLARE_IS_ENDIAN;
-    uint64_t alen = ctx->len.u[0] << 3;
-    uint64_t clen = ctx->len.u[1] << 3;
+    u64 alen = ctx->len.u[0] << 3;
+    u64 clen = ctx->len.u[1] << 3;
 
 #if defined(GHASH) && !defined(OPENSSL_SMALL_FOOTPRINT)
     u128 bitlen;
@@ -1573,13 +1573,13 @@ int CRYPTO_gcm128_finish(GCM128_CONTEXT *ctx, const unsigned char *tag,
         alen = BSWAP8(alen);
         clen = BSWAP8(clen);
 #else
-        uint8_t *p = ctx->len.c;
+        u8 *p = ctx->len.c;
 
         ctx->len.u[0] = alen;
         ctx->len.u[1] = clen;
 
-        alen = (uint64_t)GETU32(p) << 32 | GETU32(p + 4);
-        clen = (uint64_t)GETU32(p + 8) << 32 | GETU32(p + 12);
+        alen = (u64)GETU32(p) << 32 | GETU32(p + 4);
+        clen = (u64)GETU32(p + 8) << 32 | GETU32(p + 12);
 #endif
     }
 
diff --git a/crypto/modes/ocb128.c b/crypto/modes/ocb128.c
index c6b906a56b..ce72baf6da 100644
--- a/crypto/modes/ocb128.c
+++ b/crypto/modes/ocb128.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2014-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2014-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -17,9 +17,9 @@
 /*
  * Calculate the number of binary trailing zero's in any given number
  */
-static uint32_t ocb_ntz(uint64_t n)
+static u32 ocb_ntz(u64 n)
 {
-    uint32_t cnt = 0;
+    u32 cnt = 0;
 
     /*
      * We do a right-to-left simple sequential search. This is surprisingly
@@ -263,7 +263,7 @@ int CRYPTO_ocb128_setiv(OCB128_CONTEXT *ctx, const unsigned char *iv,
 int CRYPTO_ocb128_aad(OCB128_CONTEXT *ctx, const unsigned char *aad,
     size_t len)
 {
-    uint64_t i, all_num_blocks;
+    u64 i, all_num_blocks;
     size_t num_blocks, last_len;
     OCB_BLOCK tmp;
 
@@ -325,7 +325,7 @@ int CRYPTO_ocb128_encrypt(OCB128_CONTEXT *ctx,
     const unsigned char *in, unsigned char *out,
     size_t len)
 {
-    uint64_t i, all_num_blocks;
+    u64 i, all_num_blocks;
     size_t num_blocks, last_len;
 
     /*
@@ -337,7 +337,7 @@ int CRYPTO_ocb128_encrypt(OCB128_CONTEXT *ctx,
 
     if (num_blocks && all_num_blocks == (size_t)all_num_blocks
         && ctx->stream != NULL) {
-        size_t max_idx = 0, top = (size_t)all_num_blocks, processed_bytes = 0;
+        size_t max_idx = 0, top = (size_t)all_num_blocks;
 
         /*
          * See how many L_{i} entries we need to process data at hand
@@ -351,9 +351,6 @@ int CRYPTO_ocb128_encrypt(OCB128_CONTEXT *ctx,
         ctx->stream(in, out, num_blocks, ctx->keyenc,
             (size_t)ctx->sess.blocks_processed + 1, ctx->sess.offset.c,
             (const unsigned char (*)[16])ctx->l, ctx->sess.checksum.c);
-        processed_bytes = num_blocks * 16;
-        in += processed_bytes;
-        out += processed_bytes;
     } else {
         /* Loop through all full blocks to be encrypted */
         for (i = ctx->sess.blocks_processed + 1; i <= all_num_blocks; i++) {
@@ -420,7 +417,7 @@ int CRYPTO_ocb128_decrypt(OCB128_CONTEXT *ctx,
     const unsigned char *in, unsigned char *out,
     size_t len)
 {
-    uint64_t i, all_num_blocks;
+    u64 i, all_num_blocks;
     size_t num_blocks, last_len;
 
     /*
@@ -432,7 +429,7 @@ int CRYPTO_ocb128_decrypt(OCB128_CONTEXT *ctx,
 
     if (num_blocks && all_num_blocks == (size_t)all_num_blocks
         && ctx->stream != NULL) {
-        size_t max_idx = 0, top = (size_t)all_num_blocks, processed_bytes = 0;
+        size_t max_idx = 0, top = (size_t)all_num_blocks;
 
         /*
          * See how many L_{i} entries we need to process data at hand
@@ -446,9 +443,6 @@ int CRYPTO_ocb128_decrypt(OCB128_CONTEXT *ctx,
         ctx->stream(in, out, num_blocks, ctx->keydec,
             (size_t)ctx->sess.blocks_processed + 1, ctx->sess.offset.c,
             (const unsigned char (*)[16])ctx->l, ctx->sess.checksum.c);
-        processed_bytes = num_blocks * 16;
-        in += processed_bytes;
-        out += processed_bytes;
     } else {
         OCB_BLOCK tmp;
 
diff --git a/crypto/modes/wrap128.c b/crypto/modes/wrap128.c
index 6aa564a8b3..9dbb640129 100644
--- a/crypto/modes/wrap128.c
+++ b/crypto/modes/wrap128.c
@@ -18,7 +18,14 @@
 
 /** RFC 3394 section 2.2.3.1 Default Initial Value */
 static const unsigned char default_iv[] = {
-    0xA6, 0xA6, 0xA6, 0xA6, 0xA6, 0xA6, 0xA6, 0xA6
+    0xA6,
+    0xA6,
+    0xA6,
+    0xA6,
+    0xA6,
+    0xA6,
+    0xA6,
+    0xA6,
 };
 
 /** RFC 5649 section 3 Alternative Initial Value 32-bit constant */
@@ -171,9 +178,7 @@ size_t CRYPTO_128_unwrap(void *key, const unsigned char *iv,
  *
  *  @param[in]  key    Key value.
  *  @param[in]  icv    (Non-standard) IV, 4 bytes. NULL = use default_aiv.
- *  @param[out] out    Ciphertext. Minimal buffer length =
- *                     (inlen rounded up to 8 + 8) bytes, i.e.
- *                     ((inlen + 7) / 8) * 8 + 8.
+ *  @param[out] out    Ciphertext. Minimal buffer length = (inlen + 15) bytes.
  *                     Input and output buffers can overlap if block function
  *                     supports that.
  *  @param[in]  in     Plaintext as n 64-bit blocks, n >= 2.
diff --git a/crypto/modes/xts128.c b/crypto/modes/xts128.c
index f4bc0eccbc..7b55d1e0b3 100644
--- a/crypto/modes/xts128.c
+++ b/crypto/modes/xts128.c
@@ -14,9 +14,9 @@
 
 #ifndef STRICT_ALIGNMENT
 #ifdef __GNUC__
-typedef uint64_t u64_a1 __attribute((__aligned__(1)));
+typedef u64 u64_a1 __attribute((__aligned__(1)));
 #else
-typedef uint64_t u64_a1;
+typedef u64 u64_a1;
 #endif
 #endif
 
@@ -27,9 +27,9 @@ int CRYPTO_xts128_encrypt(const XTS128_CONTEXT *ctx,
 {
     DECLARE_IS_ENDIAN;
     union {
-        uint64_t u[2];
-        uint32_t d[4];
-        uint8_t c[16];
+        u64 u[2];
+        u32 d[4];
+        u8 c[16];
     } tweak, scratch;
     unsigned int i;
 
@@ -83,15 +83,15 @@ int CRYPTO_xts128_encrypt(const XTS128_CONTEXT *ctx,
                  * + substitutes for |, because c is 1 bit
                  */
                 c += ((size_t)tweak.c[i]) << 1;
-                tweak.c[i] = (uint8_t)c;
+                tweak.c[i] = (u8)c;
                 c = c >> 8;
             }
-            tweak.c[0] ^= (uint8_t)(0x87 & (0 - c));
+            tweak.c[0] ^= (u8)(0x87 & (0 - c));
         }
     }
     if (enc) {
         for (i = 0; i < len; ++i) {
-            uint8_t c = inp[i];
+            u8 c = inp[i];
             out[i] = scratch.c[i];
             scratch.c[i] = c;
         }
@@ -103,8 +103,8 @@ int CRYPTO_xts128_encrypt(const XTS128_CONTEXT *ctx,
         memcpy(out - 16, scratch.c, 16);
     } else {
         union {
-            uint64_t u[2];
-            uint8_t c[16];
+            u64 u[2];
+            u8 c[16];
         } tweak1;
 
         if (IS_LITTLE_ENDIAN) {
@@ -122,10 +122,10 @@ int CRYPTO_xts128_encrypt(const XTS128_CONTEXT *ctx,
                  * + substitutes for |, because c is 1 bit
                  */
                 c += ((size_t)tweak.c[i]) << 1;
-                tweak1.c[i] = (uint8_t)c;
+                tweak1.c[i] = (u8)c;
                 c = c >> 8;
             }
-            tweak1.c[0] ^= (uint8_t)(0x87 & (0 - c));
+            tweak1.c[0] ^= (u8)(0x87 & (0 - c));
         }
 #if defined(STRICT_ALIGNMENT)
         memcpy(scratch.c, inp, 16);
@@ -140,7 +140,7 @@ int CRYPTO_xts128_encrypt(const XTS128_CONTEXT *ctx,
         scratch.u[1] ^= tweak1.u[1];
 
         for (i = 0; i < len; ++i) {
-            uint8_t c = inp[16 + i];
+            u8 c = inp[16 + i];
             out[16 + i] = scratch.c[i];
             scratch.c[i] = c;
         }
diff --git a/crypto/modes/xts128gb.c b/crypto/modes/xts128gb.c
index 586d69e48c..563077277c 100644
--- a/crypto/modes/xts128gb.c
+++ b/crypto/modes/xts128gb.c
@@ -14,9 +14,9 @@
 
 #ifndef STRICT_ALIGNMENT
 #ifdef __GNUC__
-typedef uint64_t u64_a1 __attribute((__aligned__(1)));
+typedef u64 u64_a1 __attribute((__aligned__(1)));
 #else
-typedef uint64_t u64_a1;
+typedef u64 u64_a1;
 #endif
 #endif
 
@@ -27,9 +27,9 @@ int ossl_crypto_xts128gb_encrypt(const XTS128_CONTEXT *ctx,
 {
     DECLARE_IS_ENDIAN;
     union {
-        uint64_t u[2];
-        uint32_t d[4];
-        uint8_t c[16];
+        u64 u[2];
+        u32 d[4];
+        u8 c[16];
     } tweak, scratch;
     unsigned int i;
 
@@ -69,18 +69,18 @@ int ossl_crypto_xts128gb_encrypt(const XTS128_CONTEXT *ctx,
             return 0;
 
         if (IS_LITTLE_ENDIAN) {
-            uint8_t res;
-            uint64_t hi, lo;
+            u8 res;
+            u64 hi, lo;
 #ifdef BSWAP8
             hi = BSWAP8(tweak.u[0]);
             lo = BSWAP8(tweak.u[1]);
 #else
-            uint8_t *p = tweak.c;
+            u8 *p = tweak.c;
 
-            hi = (uint64_t)GETU32(p) << 32 | GETU32(p + 4);
-            lo = (uint64_t)GETU32(p + 8) << 32 | GETU32(p + 12);
+            hi = (u64)GETU32(p) << 32 | GETU32(p + 4);
+            lo = (u64)GETU32(p + 8) << 32 | GETU32(p + 12);
 #endif
-            res = (uint8_t)lo & 1;
+            res = (u8)lo & 1;
             tweak.u[0] = (lo >> 1) | (hi << 63);
             tweak.u[1] = hi >> 1;
             if (res)
@@ -91,13 +91,13 @@ int ossl_crypto_xts128gb_encrypt(const XTS128_CONTEXT *ctx,
 #else
             p = tweak.c;
 
-            hi = (uint64_t)GETU32(p) << 32 | GETU32(p + 4);
-            lo = (uint64_t)GETU32(p + 8) << 32 | GETU32(p + 12);
+            hi = (u64)GETU32(p) << 32 | GETU32(p + 4);
+            lo = (u64)GETU32(p + 8) << 32 | GETU32(p + 12);
 #endif
             tweak.u[0] = lo;
             tweak.u[1] = hi;
         } else {
-            uint8_t carry, res;
+            u8 carry, res;
             carry = 0;
             for (i = 0; i < 16; ++i) {
                 res = (tweak.c[i] << 7) & 0x80;
@@ -110,7 +110,7 @@ int ossl_crypto_xts128gb_encrypt(const XTS128_CONTEXT *ctx,
     }
     if (enc) {
         for (i = 0; i < len; ++i) {
-            uint8_t c = inp[i];
+            u8 c = inp[i];
             out[i] = scratch.c[i];
             scratch.c[i] = c;
         }
@@ -122,23 +122,23 @@ int ossl_crypto_xts128gb_encrypt(const XTS128_CONTEXT *ctx,
         memcpy(out - 16, scratch.c, 16);
     } else {
         union {
-            uint64_t u[2];
-            uint8_t c[16];
+            u64 u[2];
+            u8 c[16];
         } tweak1;
 
         if (IS_LITTLE_ENDIAN) {
-            uint8_t res;
-            uint64_t hi, lo;
+            u8 res;
+            u64 hi, lo;
 #ifdef BSWAP8
             hi = BSWAP8(tweak.u[0]);
             lo = BSWAP8(tweak.u[1]);
 #else
-            uint8_t *p = tweak.c;
+            u8 *p = tweak.c;
 
-            hi = (uint64_t)GETU32(p) << 32 | GETU32(p + 4);
-            lo = (uint64_t)GETU32(p + 8) << 32 | GETU32(p + 12);
+            hi = (u64)GETU32(p) << 32 | GETU32(p + 4);
+            lo = (u64)GETU32(p + 8) << 32 | GETU32(p + 12);
 #endif
-            res = (uint8_t)lo & 1;
+            res = (u8)lo & 1;
             tweak1.u[0] = (lo >> 1) | (hi << 63);
             tweak1.u[1] = hi >> 1;
             if (res)
@@ -149,13 +149,13 @@ int ossl_crypto_xts128gb_encrypt(const XTS128_CONTEXT *ctx,
 #else
             p = tweak1.c;
 
-            hi = (uint64_t)GETU32(p) << 32 | GETU32(p + 4);
-            lo = (uint64_t)GETU32(p + 8) << 32 | GETU32(p + 12);
+            hi = (u64)GETU32(p) << 32 | GETU32(p + 4);
+            lo = (u64)GETU32(p + 8) << 32 | GETU32(p + 12);
 #endif
             tweak1.u[0] = lo;
             tweak1.u[1] = hi;
         } else {
-            uint8_t carry, res;
+            u8 carry, res;
             carry = 0;
             for (i = 0; i < 16; ++i) {
                 res = (tweak.c[i] << 7) & 0x80;
@@ -178,7 +178,7 @@ int ossl_crypto_xts128gb_encrypt(const XTS128_CONTEXT *ctx,
         scratch.u[1] ^= tweak1.u[1];
 
         for (i = 0; i < len; ++i) {
-            uint8_t c = inp[16 + i];
+            u8 c = inp[16 + i];
             out[16 + i] = scratch.c[i];
             scratch.c[i] = c;
         }
diff --git a/crypto/o_dir.c b/crypto/o_dir.c
index ed92b9f130..36d33fbed4 100644
--- a/crypto/o_dir.c
+++ b/crypto/o_dir.c
@@ -31,6 +31,8 @@
 # include "LPdir_vms.c"
 #elif defined OPENSSL_SYS_WIN32
 # include "LPdir_win32.c"
+#elif defined OPENSSL_SYS_WINCE
+# include "LPdir_wince.c"
 #else
 # include "LPdir_nyi.c"
 #endif
diff --git a/crypto/o_str.c b/crypto/o_str.c
index 2192d48775..22d8028beb 100644
--- a/crypto/o_str.c
+++ b/crypto/o_str.c
@@ -299,11 +299,6 @@ static int buf2hexstr_sep(char *str, size_t str_n, size_t *strlength,
     int has_sep = (sep != CH_ZERO);
     size_t i, len = has_sep ? buflen * 3 : 1 + buflen * 2;
 
-    if (buflen > (has_sep ? SIZE_MAX / 3 : (SIZE_MAX - 1) / 2)) {
-        ERR_raise(ERR_LIB_CRYPTO, CRYPTO_R_TOO_MANY_BYTES);
-        return 0;
-    }
-
     if (len == 0)
         ++len;
     if (strlength != NULL)
@@ -349,13 +344,7 @@ char *ossl_buf2hexstr_sep(const unsigned char *buf, long buflen, char sep)
     if (buflen == 0)
         return OPENSSL_zalloc(1);
 
-    if ((sep != CH_ZERO && (size_t)buflen > SIZE_MAX / 3)
-        || (sep == CH_ZERO && (size_t)buflen > (SIZE_MAX - 1) / 2)) {
-        ERR_raise(ERR_LIB_CRYPTO, CRYPTO_R_TOO_MANY_BYTES);
-        return NULL;
-    }
-
-    tmp_n = (sep != CH_ZERO) ? (size_t)buflen * 3 : 1 + (size_t)buflen * 2;
+    tmp_n = (sep != CH_ZERO) ? buflen * 3 : 1 + buflen * 2;
     if ((tmp = OPENSSL_malloc(tmp_n)) == NULL)
         return NULL;
 
@@ -377,7 +366,7 @@ char *OPENSSL_buf2hexstr(const unsigned char *buf, long buflen)
 
 int openssl_strerror_r(int errnum, char *buf, size_t buflen)
 {
-#if defined(_MSC_VER) && _MSC_VER >= 1400
+#if defined(_MSC_VER) && _MSC_VER >= 1400 && !defined(_WIN32_WCE)
     return !strerror_s(buf, buflen, errnum);
 #elif defined(_GNU_SOURCE)
     char *err;
diff --git a/crypto/objects/o_names.c b/crypto/objects/o_names.c
index 9ab9a2acd1..7c0bdddc7c 100644
--- a/crypto/objects/o_names.c
+++ b/crypto/objects/o_names.c
@@ -29,6 +29,12 @@ static LHASH_OF(OBJ_NAME) *names_lh = NULL;
 static int names_type_num = OBJ_NAME_TYPE_NUM;
 static CRYPTO_RWLOCK *obj_lock = NULL;
 
+struct name_funcs_st {
+    unsigned long (*hash_func)(const char *name);
+    int (*cmp_func)(const char *a, const char *b);
+    void (*free_func)(const char *, int, const char *);
+};
+
 static STACK_OF(NAME_FUNCS) *name_funcs_stack;
 
 /*
diff --git a/crypto/objects/obj_dat.c b/crypto/objects/obj_dat.c
index 570fde8d15..ac95d098b9 100644
--- a/crypto/objects/obj_dat.c
+++ b/crypto/objects/obj_dat.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,7 +15,6 @@
 #include "internal/tsan_assist.h"
 #include 
 #include 
-#include "crypto/asn1/asn1_local.h"
 #include "crypto/objects.h"
 #include 
 #include "crypto/asn1.h"
@@ -162,7 +161,8 @@ static unsigned long added_obj_hash(const ADDED_OBJ *ca)
  */
 static int obj_equivalent(const ASN1_OBJECT *a, const ASN1_OBJECT *b)
 {
-    return OBJ_cmp(a, b) == 0
+    return a->length == b->length
+        && memcmp(a->data, b->data, (size_t)a->length) == 0
         && (a->sn == NULL) == (b->sn == NULL)
         && strcmp(a->sn ? a->sn : "", b->sn ? b->sn : "") == 0
         && (a->ln == NULL) == (b->ln == NULL)
@@ -181,7 +181,10 @@ static int added_obj_cmp(const ADDED_OBJ *ca, const ADDED_OBJ *cb)
     b = cb->obj;
     switch (ca->type) {
     case ADDED_DATA:
-        return OBJ_cmp(a, b);
+        i = (a->length - b->length);
+        if (i)
+            return i;
+        return memcmp(a->data, b->data, (size_t)a->length);
     case ADDED_SNAME:
         if (a->sn == NULL)
             return -1;
@@ -292,7 +295,16 @@ const char *OBJ_nid2ln(int n)
 
 static int obj_cmp(const ASN1_OBJECT *const *ap, const unsigned int *bp)
 {
-    return OBJ_cmp(*ap, &nid_objs[*bp]);
+    int j;
+    const ASN1_OBJECT *a = *ap;
+    const ASN1_OBJECT *b = &nid_objs[*bp];
+
+    j = (a->length - b->length);
+    if (j)
+        return j;
+    if (a->length == 0)
+        return 0;
+    return memcmp(a->data, b->data, a->length);
 }
 
 IMPLEMENT_OBJ_BSEARCH_CMP_FN(const ASN1_OBJECT *, unsigned int, obj);
@@ -399,7 +411,7 @@ int OBJ_obj2txt(char *buf, int buf_len, const ASN1_OBJECT *a, int no_name)
             s = OBJ_nid2sn(nid);
         if (s != NULL) {
             if (buf != NULL)
-                return (int)OPENSSL_strlcpy(buf, s, buf_len);
+                OPENSSL_strlcpy(buf, s, buf_len);
             return (int)strlen(s);
         }
     }
@@ -606,7 +618,7 @@ const void *OBJ_bsearch_ex_(const void *key, const void *base, int num,
     int (*cmp)(const void *, const void *),
     int flags)
 {
-    const char *p = ossl_bsearch(key, base, num, size, cmp, NULL, flags);
+    const char *p = ossl_bsearch(key, base, num, size, cmp, flags);
 
 #ifdef CHARSET_EBCDIC
     /*
@@ -616,8 +628,8 @@ const void *OBJ_bsearch_ex_(const void *key, const void *base, int num,
      */
     if (p == NULL) {
         const char *base_ = base;
-        int i = 0, c = 0;
-        const char *p1;
+        int l, h, i = 0, c = 0;
+        char *p1;
 
         for (i = 0; i < num; ++i) {
             p1 = &(base_[i * size]);
@@ -709,7 +721,7 @@ int OBJ_create(const char *oid, const char *sn, const char *ln)
             return NID_undef;
     } else {
         /* Create a no-OID ASN1_OBJECT */
-        tmpoid = ossl_asn1_object_new();
+        tmpoid = ASN1_OBJECT_new();
         if (tmpoid == NULL) {
             ERR_raise(ERR_LIB_OBJ, ERR_R_ASN1_LIB);
             return NID_undef;
diff --git a/crypto/objects/obj_dat.h b/crypto/objects/obj_dat.h
index c7925932d5..40d6f9ca4d 100644
--- a/crypto/objects/obj_dat.h
+++ b/crypto/objects/obj_dat.h
@@ -2,25 +2,15 @@
  * WARNING: do not edit!
  * Generated by crypto/objects/obj_dat.pl
  *
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
  * in the file LICENSE in the source distribution or at
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_OBJECTS_OBJ_DAT_H)
-#define OSSL_LIBCRYPTO_OBJECTS_OBJ_DAT_H
-
-/* clang-format off */
-
-#include 
-#include 
-
-#include 
-
 /* Serialized OID's */
-static const unsigned char so[9582] = {
+static const unsigned char so[9571] = {
     0x2A,0x86,0x48,0x86,0xF7,0x0D,                 /* [    0] OBJ_rsadsi */
     0x2A,0x86,0x48,0x86,0xF7,0x0D,0x01,            /* [    6] OBJ_pkcs */
     0x2A,0x86,0x48,0x86,0xF7,0x0D,0x02,0x02,       /* [   13] OBJ_md2 */
@@ -1363,10 +1353,9 @@ static const unsigned char so[9582] = {
     0x2A,0x86,0x48,0x86,0xF7,0x0D,0x01,0x09,0x10,0x03,0x1E,  /* [ 9538] OBJ_HKDF_SHA512 */
     0x2A,0x86,0x48,0x86,0xF7,0x0D,0x01,0x09,0x10,0x0D,  /* [ 9549] OBJ_id_smime_ori */
     0x2A,0x86,0x48,0x86,0xF7,0x0D,0x01,0x09,0x10,0x0D,0x03,  /* [ 9559] OBJ_id_smime_ori_kem */
-    0x2A,0x86,0x48,0x86,0xF7,0x0D,0x01,0x09,0x10,0x03,0x11,  /* [ 9570] OBJ_id_alg_hss_lms_hashsig */
 };
 
-#define NUM_NID 1502
+#define NUM_NID 1501
 static const ASN1_OBJECT nid_objs[NUM_NID] = {
     {"UNDEF", "undefined", NID_undef},
     {"rsadsi", "RSA Data Security, Inc.", NID_rsadsi, 6, &so[0]},
@@ -2869,10 +2858,9 @@ static const ASN1_OBJECT nid_objs[NUM_NID] = {
     {"id-alg-hkdf-with-sha512", "HKDF-SHA512", NID_HKDF_SHA512, 11, &so[9538]},
     {"id-smime-ori", "id-smime-ori", NID_id_smime_ori, 10, &so[9549]},
     {"id-smime-ori-kem", "id-smime-ori-kem", NID_id_smime_ori_kem, 11, &so[9559]},
-    {"id-alg-hss-lms-hashsig", "id-alg-hss-lms-hashsig", NID_id_alg_hss_lms_hashsig, 11, &so[9570]},
 };
 
-#define NUM_SN 1493
+#define NUM_SN 1492
 static const unsigned int sn_objs[NUM_SN] = {
      364,    /* "AD_DVCS" */
      419,    /* "AES-128-CBC" */
@@ -3505,7 +3493,6 @@ static const unsigned int sn_objs[NUM_SN] = {
     1496,    /* "id-alg-hkdf-with-sha256" */
     1497,    /* "id-alg-hkdf-with-sha384" */
     1498,    /* "id-alg-hkdf-with-sha512" */
-    1501,    /* "id-alg-hss-lms-hashsig" */
     1456,    /* "id-alg-ml-kem-1024" */
     1454,    /* "id-alg-ml-kem-512" */
     1455,    /* "id-alg-ml-kem-768" */
@@ -4369,7 +4356,7 @@ static const unsigned int sn_objs[NUM_SN] = {
     1289,    /* "zstd" */
 };
 
-#define NUM_LN 1493
+#define NUM_LN 1492
 static const unsigned int ln_objs[NUM_LN] = {
      363,    /* "AD Time Stamping" */
      405,    /* "ANSI X9.62" */
@@ -5198,7 +5185,6 @@ static const unsigned int ln_objs[NUM_LN] = {
      323,    /* "id-alg-des40" */
      326,    /* "id-alg-dh-pop" */
      325,    /* "id-alg-dh-sig-hmac-sha1" */
-    1501,    /* "id-alg-hss-lms-hashsig" */
      324,    /* "id-alg-noSignature" */
      907,    /* "id-camellia128-wrap" */
      908,    /* "id-camellia192-wrap" */
@@ -5866,7 +5852,7 @@ static const unsigned int ln_objs[NUM_LN] = {
      125,    /* "zlib compression" */
 };
 
-#define NUM_OBJ 1350
+#define NUM_OBJ 1349
 static const unsigned int obj_objs[NUM_OBJ] = {
        0,    /* OBJ_undef                        0 */
      181,    /* OBJ_iso                          1 */
@@ -7180,7 +7166,6 @@ static const unsigned int obj_objs[NUM_OBJ] = {
      247,    /* OBJ_id_smime_alg_CMSRC2wrap      1 2 840 113549 1 9 16 3 7 */
      125,    /* OBJ_zlib_compression             1 2 840 113549 1 9 16 3 8 */
      893,    /* OBJ_id_alg_PWRI_KEK              1 2 840 113549 1 9 16 3 9 */
-    1501,    /* OBJ_id_alg_hss_lms_hashsig       1 2 840 113549 1 9 16 3 17 */
     1496,    /* OBJ_HKDF_SHA256                  1 2 840 113549 1 9 16 3 28 */
     1497,    /* OBJ_HKDF_SHA384                  1 2 840 113549 1 9 16 3 29 */
     1498,    /* OBJ_HKDF_SHA512                  1 2 840 113549 1 9 16 3 30 */
@@ -7219,6 +7204,3 @@ static const unsigned int obj_objs[NUM_OBJ] = {
     1168,    /* OBJ_uacurve8                     1 2 804 2 1 1 1 1 3 1 1 2 8 */
     1169,    /* OBJ_uacurve9                     1 2 804 2 1 1 1 1 3 1 1 2 9 */
 };
-/* clang-format on */
-
-#endif /* !defined(OSSL_LIBCRYPTO_OBJECTS_OBJ_DAT_H) */
diff --git a/crypto/objects/obj_dat.pl b/crypto/objects/obj_dat.pl
index 54c42cdbeb..510a906f57 100644
--- a/crypto/objects/obj_dat.pl
+++ b/crypto/objects/obj_dat.pl
@@ -165,16 +165,6 @@ print <<"EOF";
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_OBJECTS_OBJ_DAT_H)
-#define OSSL_LIBCRYPTO_OBJECTS_OBJ_DAT_H
-
-/* clang-format off */
-
-#include 
-#include 
-
-#include 
-
 EOF
 
 print "/* Serialized OID's */\n";
@@ -219,11 +209,11 @@ printf "static const unsigned int obj_objs[NUM_OBJ] = {\n";
 # Compare DER; prefer shorter; if some length, use the "smaller" encoding.
 sub obj_cmp
 {
-    my $A = $obj_len{$obj{$nid{$a}}} // 0;
-    my $B = $obj_len{$obj{$nid{$b}}} // 0;
+    no warnings "uninitialized";
+    my $A = $obj_len{$obj{$nid{$a}}};
+    my $B = $obj_len{$obj{$nid{$b}}};
     my $r = $A - $B;
     return $r if $r != 0;
-    return 0 if $A == 0;
 
     $A = $obj_der{$obj{$nid{$a}}};
     $B = $obj_der{$obj{$nid{$b}}};
@@ -237,5 +227,3 @@ foreach (sort obj_cmp @a) {
     printf "    %4d,    /* %-32s %s */\n", $_, $m, $v;
 }
 print  "};\n";
-print "/* clang-format on */\n";
-print "\n#endif /* !defined(OSSL_LIBCRYPTO_OBJECTS_OBJ_DAT_H) */\n";
diff --git a/crypto/objects/obj_lib.c b/crypto/objects/obj_lib.c
index 89be08810c..adc22a10e2 100644
--- a/crypto/objects/obj_lib.c
+++ b/crypto/objects/obj_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -12,7 +12,6 @@
 #include 
 #include 
 #include "crypto/asn1.h"
-#include "crypto/asn1/asn1_local.h"
 
 ASN1_OBJECT *OBJ_dup(const ASN1_OBJECT *o)
 {
@@ -24,7 +23,7 @@ ASN1_OBJECT *OBJ_dup(const ASN1_OBJECT *o)
     if (!(o->flags & ASN1_OBJECT_FLAG_DYNAMIC))
         return (ASN1_OBJECT *)o;
 
-    r = ossl_asn1_object_new();
+    r = ASN1_OBJECT_new();
     if (r == NULL) {
         ERR_raise(ERR_LIB_OBJ, ERR_R_ASN1_LIB);
         return NULL;
@@ -59,7 +58,5 @@ int OBJ_cmp(const ASN1_OBJECT *a, const ASN1_OBJECT *b)
     ret = (a->length - b->length);
     if (ret)
         return ret;
-    if (a->length == 0)
-        return 0;
     return memcmp(a->data, b->data, a->length);
 }
diff --git a/crypto/objects/obj_local.h b/crypto/objects/obj_local.h
index 29e5cc034b..73848a6fbf 100644
--- a/crypto/objects/obj_local.h
+++ b/crypto/objects/obj_local.h
@@ -7,22 +7,8 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_OBJECTS_OBJ_LOCAL_H)
-#define OSSL_LIBCRYPTO_OBJECTS_OBJ_LOCAL_H
-
-#include 
-#include 
-#include 
-
-typedef struct name_funcs_st {
-    unsigned long (*hash_func)(const char *name);
-    int (*cmp_func)(const char *a, const char *b);
-    void (*free_func)(const char *, int, const char *);
-} NAME_FUNCS;
-
+typedef struct name_funcs_st NAME_FUNCS;
 DEFINE_STACK_OF(NAME_FUNCS)
 DEFINE_LHASH_OF_EX(OBJ_NAME);
 typedef struct added_obj_st ADDED_OBJ;
 DEFINE_LHASH_OF_EX(ADDED_OBJ);
-
-#endif /* !defined(OSSL_LIBCRYPTO_OBJECTS_OBJ_LOCAL_H) */
diff --git a/crypto/objects/obj_mac.num b/crypto/objects/obj_mac.num
index e72170b47f..b48d054d32 100644
--- a/crypto/objects/obj_mac.num
+++ b/crypto/objects/obj_mac.num
@@ -1498,4 +1498,3 @@ HKDF_SHA384		1497
 HKDF_SHA512		1498
 id_smime_ori		1499
 id_smime_ori_kem		1500
-id_alg_hss_lms_hashsig		1501
diff --git a/crypto/objects/obj_xref.h b/crypto/objects/obj_xref.h
index 46de3ccf4a..fed298906e 100644
--- a/crypto/objects/obj_xref.h
+++ b/crypto/objects/obj_xref.h
@@ -2,7 +2,7 @@
  * WARNING: do not edit!
  * Generated by objxref.pl
  *
- * Copyright 1998-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1998-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -10,12 +10,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_OBJECTS_OBJ_XREF_H)
-#define OSSL_LIBCRYPTO_OBJECTS_OBJ_XREF_H
-
-/* clang-format off */
-
-#include 
 
 typedef struct {
     int sign_id;
@@ -81,8 +75,6 @@ static const nid_triple sigoid_srt[] = {
      NID_id_GostR3410_2012_512},
     {NID_ED25519, NID_undef, NID_ED25519},
     {NID_ED448, NID_undef, NID_ED448},
-    {NID_dsa_with_SHA384, NID_sha384, NID_dsa},
-    {NID_dsa_with_SHA512, NID_sha512, NID_dsa},
     {NID_ecdsa_with_SHA3_224, NID_sha3_224, NID_X9_62_id_ecPublicKey},
     {NID_ecdsa_with_SHA3_256, NID_sha3_256, NID_X9_62_id_ecPublicKey},
     {NID_ecdsa_with_SHA3_384, NID_sha3_384, NID_X9_62_id_ecPublicKey},
@@ -131,12 +123,10 @@ static const nid_triple *const sigoid_srt_xref[] = {
     &sigoid_srt[32],
     &sigoid_srt[37],
     &sigoid_srt[14],
-    &sigoid_srt[44],
     &sigoid_srt[21],
     &sigoid_srt[33],
     &sigoid_srt[38],
     &sigoid_srt[15],
-    &sigoid_srt[45],
     &sigoid_srt[22],
     &sigoid_srt[34],
     &sigoid_srt[39],
@@ -151,16 +141,13 @@ static const nid_triple *const sigoid_srt_xref[] = {
     &sigoid_srt[28],
     &sigoid_srt[40],
     &sigoid_srt[41],
+    &sigoid_srt[48],
+    &sigoid_srt[44],
+    &sigoid_srt[49],
+    &sigoid_srt[45],
     &sigoid_srt[50],
     &sigoid_srt[46],
     &sigoid_srt[51],
     &sigoid_srt[47],
     &sigoid_srt[52],
-    &sigoid_srt[48],
-    &sigoid_srt[53],
-    &sigoid_srt[49],
-    &sigoid_srt[54],
 };
-/* clang-format on */
-
-#endif /* !defined(OSSL_LIBCRYPTO_OBJECTS_OBJ_XREF_H) */
diff --git a/crypto/objects/obj_xref.txt b/crypto/objects/obj_xref.txt
index 2f82617a84..71bc12af74 100644
--- a/crypto/objects/obj_xref.txt
+++ b/crypto/objects/obj_xref.txt
@@ -64,8 +64,6 @@ ecdsa_with_SHA3_512     sha3_512    X9_62_id_ecPublicKey
 
 dsa_with_SHA224		sha224	dsa
 dsa_with_SHA256		sha256	dsa
-dsa_with_SHA384		sha384	dsa
-dsa_with_SHA512		sha512	dsa
 
 id_GostR3411_94_with_GostR3410_2001	id_GostR3411_94 id_GostR3410_2001
 id_GostR3411_94_with_GostR3410_94	id_GostR3411_94 id_GostR3410_94
diff --git a/crypto/objects/objects.pl b/crypto/objects/objects.pl
index bc6941ff16..51bc248b3f 100644
--- a/crypto/objects/objects.pl
+++ b/crypto/objects/objects.pl
@@ -148,10 +148,9 @@ print <<"EOF";
  */
 
 #ifndef OPENSSL_OBJ_MAC_H
-#define OPENSSL_OBJ_MAC_H
-#pragma once
+# define OPENSSL_OBJ_MAC_H
+# pragma once
 
-/* clang-format off */
 #define SN_undef                        "UNDEF"
 #define LN_undef                        "undefined"
 #define NID_undef                       0
@@ -178,7 +177,6 @@ foreach (sort { $a <=> $b } keys %ordern)
 	}
 
 print <
 
 typedef struct {
     int sign_id;
@@ -135,8 +129,6 @@ foreach (@srt2)
 	}
 
 print "};\n";
-print "/* clang-format on */\n";
-print "\n#endif /* !defined(OSSL_LIBCRYPTO_OBJECTS_OBJ_XREF_H) */\n";
 
 sub check_oid
 	{
diff --git a/crypto/ocsp/ocsp_cl.c b/crypto/ocsp/ocsp_cl.c
index 432edba314..22d6692a91 100644
--- a/crypto/ocsp/ocsp_cl.c
+++ b/crypto/ocsp/ocsp_cl.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2001-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -16,7 +16,6 @@
 #include 
 #include 
 #include 
-#include 
 #include "ocsp_local.h"
 
 /*
@@ -71,7 +70,7 @@ int OCSP_request_sign(OCSP_REQUEST *req,
     X509 *signer,
     EVP_PKEY *key,
     const EVP_MD *dgst,
-    const STACK_OF(X509) *certs, unsigned long flags)
+    STACK_OF(X509) *certs, unsigned long flags)
 {
     if (!OCSP_request_set1_name(req, X509_get_subject_name(signer)))
         goto err;
@@ -289,20 +288,6 @@ int OCSP_resp_find_status(OCSP_BASICRESP *bs, OCSP_CERTID *id, int *status,
     return 1;
 }
 
-static int gentime_to_posix(ASN1_GENERALIZEDTIME *time, int64_t *out_time)
-{
-    struct tm ctm;
-
-    if (!ASN1_GENERALIZEDTIME_check(time))
-        return 0;
-    if (!ASN1_TIME_to_tm(time, &ctm))
-        return 0;
-    if (!OPENSSL_tm_to_posix(&ctm, out_time))
-        return 0;
-
-    return 1;
-}
-
 /*
  * Check validity of thisUpdate and nextUpdate fields. It is possible that
  * the request will take a few seconds to process and/or the time won't be
@@ -314,52 +299,55 @@ static int gentime_to_posix(ASN1_GENERALIZEDTIME *time, int64_t *out_time)
 int OCSP_check_validity(ASN1_GENERALIZEDTIME *thisupd,
     ASN1_GENERALIZEDTIME *nextupd, long nsec, long maxsec)
 {
-    int64_t t_now, this_time, next_time;
-    int ret = 0;
+    int ret = 1;
+    time_t t_now, t_tmp;
 
-    if (nsec < 0)
-        nsec = 0;
-
-    t_now = (int64_t)time(NULL);
-    /* Check thisUpdate is valid */
-    if (!gentime_to_posix(thisupd, &this_time)) {
+    time(&t_now);
+    /* Check thisUpdate is valid and not more than nsec in the future */
+    if (!ASN1_GENERALIZEDTIME_check(thisupd)) {
         ERR_raise(ERR_LIB_OCSP, OCSP_R_ERROR_IN_THISUPDATE_FIELD);
-        goto err;
-    }
-    /* Check if thisUpdate is more than nsec in the future */
-    if (this_time > t_now + nsec) {
-        ERR_raise(ERR_LIB_OCSP, OCSP_R_STATUS_NOT_YET_VALID);
-        goto err;
-    }
-    /*
-     * If maxsec specified check thisUpdate is not more than maxsec in
-     * the past
-     */
-    if (maxsec >= 0 && this_time < t_now - maxsec) {
-        ERR_raise(ERR_LIB_OCSP, OCSP_R_STATUS_TOO_OLD);
-        goto err;
-    }
-    if (nextupd != NULL) {
-        /* Check nextUpdate is valid */
-        if (!gentime_to_posix(nextupd, &next_time)) {
-            ERR_raise(ERR_LIB_OCSP, OCSP_R_ERROR_IN_NEXTUPDATE_FIELD);
-            goto err;
-        }
-        /* Check nextUpdate is not more than nsec in the past */
-        if (next_time < t_now - nsec) {
+        ret = 0;
+    } else {
+        t_tmp = t_now + nsec;
+        if (X509_cmp_time(thisupd, &t_tmp) > 0) {
             ERR_raise(ERR_LIB_OCSP, OCSP_R_STATUS_NOT_YET_VALID);
-            goto err;
+            ret = 0;
         }
-        /* Also don't allow nextUpdate to precede thisUpdate */
-        if (next_time < this_time) {
-            ERR_raise(ERR_LIB_OCSP, OCSP_R_NEXTUPDATE_BEFORE_THISUPDATE);
-            goto err;
+
+        /*
+         * If maxsec specified check thisUpdate is not more than maxsec in
+         * the past
+         */
+        if (maxsec >= 0) {
+            t_tmp = t_now - maxsec;
+            if (X509_cmp_time(thisupd, &t_tmp) < 0) {
+                ERR_raise(ERR_LIB_OCSP, OCSP_R_STATUS_TOO_OLD);
+                ret = 0;
+            }
         }
     }
 
-    ret = 1;
+    if (nextupd == NULL)
+        return ret;
+
+    /* Check nextUpdate is valid and not more than nsec in the past */
+    if (!ASN1_GENERALIZEDTIME_check(nextupd)) {
+        ERR_raise(ERR_LIB_OCSP, OCSP_R_ERROR_IN_NEXTUPDATE_FIELD);
+        ret = 0;
+    } else {
+        t_tmp = t_now - nsec;
+        if (X509_cmp_time(nextupd, &t_tmp) < 0) {
+            ERR_raise(ERR_LIB_OCSP, OCSP_R_STATUS_EXPIRED);
+            ret = 0;
+        }
+    }
+
+    /* Also don't allow nextUpdate to precede thisUpdate */
+    if (ASN1_STRING_cmp(nextupd, thisupd) < 0) {
+        ERR_raise(ERR_LIB_OCSP, OCSP_R_NEXTUPDATE_BEFORE_THISUPDATE);
+        ret = 0;
+    }
 
-err:
     return ret;
 }
 
diff --git a/crypto/ocsp/ocsp_ext.c b/crypto/ocsp/ocsp_ext.c
index 038be72b04..4149f7f66d 100644
--- a/crypto/ocsp/ocsp_ext.c
+++ b/crypto/ocsp/ocsp_ext.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -41,14 +41,14 @@ int OCSP_REQUEST_get_ext_by_critical(OCSP_REQUEST *x, int crit, int lastpos)
     return (X509v3_get_ext_by_critical(x->tbsRequest.requestExtensions, crit, lastpos));
 }
 
-const X509_EXTENSION *OCSP_REQUEST_get_ext(OCSP_REQUEST *x, int loc)
+X509_EXTENSION *OCSP_REQUEST_get_ext(OCSP_REQUEST *x, int loc)
 {
     return X509v3_get_ext(x->tbsRequest.requestExtensions, loc);
 }
 
 X509_EXTENSION *OCSP_REQUEST_delete_ext(OCSP_REQUEST *x, int loc)
 {
-    return X509v3_delete_extension(&x->tbsRequest.requestExtensions, loc);
+    return X509v3_delete_ext(x->tbsRequest.requestExtensions, loc);
 }
 
 void *OCSP_REQUEST_get1_ext_d2i(OCSP_REQUEST *x, int nid, int *crit, int *idx)
@@ -63,7 +63,7 @@ int OCSP_REQUEST_add1_ext_i2d(OCSP_REQUEST *x, int nid, void *value, int crit,
         crit, flags);
 }
 
-int OCSP_REQUEST_add_ext(OCSP_REQUEST *x, const X509_EXTENSION *ex, int loc)
+int OCSP_REQUEST_add_ext(OCSP_REQUEST *x, X509_EXTENSION *ex, int loc)
 {
     return (X509v3_add_ext(&(x->tbsRequest.requestExtensions), ex, loc) != NULL);
 }
@@ -91,14 +91,14 @@ int OCSP_ONEREQ_get_ext_by_critical(OCSP_ONEREQ *x, int crit, int lastpos)
     return (X509v3_get_ext_by_critical(x->singleRequestExtensions, crit, lastpos));
 }
 
-const X509_EXTENSION *OCSP_ONEREQ_get_ext(OCSP_ONEREQ *x, int loc)
+X509_EXTENSION *OCSP_ONEREQ_get_ext(OCSP_ONEREQ *x, int loc)
 {
     return X509v3_get_ext(x->singleRequestExtensions, loc);
 }
 
 X509_EXTENSION *OCSP_ONEREQ_delete_ext(OCSP_ONEREQ *x, int loc)
 {
-    return X509v3_delete_extension(&x->singleRequestExtensions, loc);
+    return X509v3_delete_ext(x->singleRequestExtensions, loc);
 }
 
 void *OCSP_ONEREQ_get1_ext_d2i(OCSP_ONEREQ *x, int nid, int *crit, int *idx)
@@ -113,7 +113,7 @@ int OCSP_ONEREQ_add1_ext_i2d(OCSP_ONEREQ *x, int nid, void *value, int crit,
         flags);
 }
 
-int OCSP_ONEREQ_add_ext(OCSP_ONEREQ *x, const X509_EXTENSION *ex, int loc)
+int OCSP_ONEREQ_add_ext(OCSP_ONEREQ *x, X509_EXTENSION *ex, int loc)
 {
     return (X509v3_add_ext(&(x->singleRequestExtensions), ex, loc) != NULL);
 }
@@ -142,14 +142,14 @@ int OCSP_BASICRESP_get_ext_by_critical(OCSP_BASICRESP *x, int crit,
     return (X509v3_get_ext_by_critical(x->tbsResponseData.responseExtensions, crit, lastpos));
 }
 
-const X509_EXTENSION *OCSP_BASICRESP_get_ext(OCSP_BASICRESP *x, int loc)
+X509_EXTENSION *OCSP_BASICRESP_get_ext(OCSP_BASICRESP *x, int loc)
 {
     return X509v3_get_ext(x->tbsResponseData.responseExtensions, loc);
 }
 
 X509_EXTENSION *OCSP_BASICRESP_delete_ext(OCSP_BASICRESP *x, int loc)
 {
-    return X509v3_delete_extension(&x->tbsResponseData.responseExtensions, loc);
+    return X509v3_delete_ext(x->tbsResponseData.responseExtensions, loc);
 }
 
 void *OCSP_BASICRESP_get1_ext_d2i(OCSP_BASICRESP *x, int nid, int *crit,
@@ -166,7 +166,7 @@ int OCSP_BASICRESP_add1_ext_i2d(OCSP_BASICRESP *x, int nid, void *value,
         value, crit, flags);
 }
 
-int OCSP_BASICRESP_add_ext(OCSP_BASICRESP *x, const X509_EXTENSION *ex, int loc)
+int OCSP_BASICRESP_add_ext(OCSP_BASICRESP *x, X509_EXTENSION *ex, int loc)
 {
     return (X509v3_add_ext(&(x->tbsResponseData.responseExtensions), ex, loc)
         != NULL);
@@ -196,14 +196,14 @@ int OCSP_SINGLERESP_get_ext_by_critical(OCSP_SINGLERESP *x, int crit,
     return X509v3_get_ext_by_critical(x->singleExtensions, crit, lastpos);
 }
 
-const X509_EXTENSION *OCSP_SINGLERESP_get_ext(OCSP_SINGLERESP *x, int loc)
+X509_EXTENSION *OCSP_SINGLERESP_get_ext(OCSP_SINGLERESP *x, int loc)
 {
     return X509v3_get_ext(x->singleExtensions, loc);
 }
 
 X509_EXTENSION *OCSP_SINGLERESP_delete_ext(OCSP_SINGLERESP *x, int loc)
 {
-    return X509v3_delete_extension(&x->singleExtensions, loc);
+    return X509v3_delete_ext(x->singleExtensions, loc);
 }
 
 void *OCSP_SINGLERESP_get1_ext_d2i(OCSP_SINGLERESP *x, int nid, int *crit,
@@ -218,7 +218,7 @@ int OCSP_SINGLERESP_add1_ext_i2d(OCSP_SINGLERESP *x, int nid, void *value,
     return X509V3_add1_i2d(&x->singleExtensions, nid, value, crit, flags);
 }
 
-int OCSP_SINGLERESP_add_ext(OCSP_SINGLERESP *x, const X509_EXTENSION *ex, int loc)
+int OCSP_SINGLERESP_add_ext(OCSP_SINGLERESP *x, X509_EXTENSION *ex, int loc)
 {
     return (X509v3_add_ext(&(x->singleExtensions), ex, loc) != NULL);
 }
@@ -310,7 +310,7 @@ int OCSP_check_nonce(OCSP_REQUEST *req, OCSP_BASICRESP *bs)
      */
 
     int req_idx, resp_idx;
-    const X509_EXTENSION *req_ext, *resp_ext;
+    X509_EXTENSION *req_ext, *resp_ext;
     req_idx = OCSP_REQUEST_get_ext_by_NID(req, NID_id_pkix_OCSP_Nonce, -1);
     resp_idx = OCSP_BASICRESP_get_ext_by_NID(bs, NID_id_pkix_OCSP_Nonce, -1);
     /* Check both absent */
@@ -339,7 +339,7 @@ int OCSP_check_nonce(OCSP_REQUEST *req, OCSP_BASICRESP *bs)
 
 int OCSP_copy_nonce(OCSP_BASICRESP *resp, OCSP_REQUEST *req)
 {
-    const X509_EXTENSION *req_ext;
+    X509_EXTENSION *req_ext;
     int req_idx;
     /* Check for nonce in request */
     req_idx = OCSP_REQUEST_get_ext_by_NID(req, NID_id_pkix_OCSP_Nonce, -1);
@@ -360,7 +360,7 @@ X509_EXTENSION *OCSP_crlID_new(const char *url, long *n, char *tim)
     if (url) {
         if ((cid->crlUrl = ASN1_IA5STRING_new()) == NULL)
             goto err;
-        if (!(ASN1_STRING_set_string(cid->crlUrl, url)))
+        if (!(ASN1_STRING_set(cid->crlUrl, url, -1)))
             goto err;
     }
     if (n) {
@@ -446,7 +446,7 @@ X509_EXTENSION *OCSP_url_svcloc_new(const X509_NAME *issuer, const char **urls)
             goto err;
         if ((ia5 = ASN1_IA5STRING_new()) == NULL)
             goto err;
-        if (!ASN1_STRING_set_string((ASN1_STRING *)ia5, *urls))
+        if (!ASN1_STRING_set((ASN1_STRING *)ia5, *urls, -1))
             goto err;
         /* ad->location is allocated inside ACCESS_DESCRIPTION_new */
         ad->location->type = GEN_URI;
diff --git a/crypto/ocsp/ocsp_lib.c b/crypto/ocsp/ocsp_lib.c
index 49a620a076..b8f3bdccc0 100644
--- a/crypto/ocsp/ocsp_lib.c
+++ b/crypto/ocsp/ocsp_lib.c
@@ -24,7 +24,7 @@ OCSP_CERTID *OCSP_cert_to_id(const EVP_MD *dgst, const X509 *subject,
 {
     const X509_NAME *iname;
     const ASN1_INTEGER *serial;
-    const ASN1_BIT_STRING *ikey;
+    ASN1_BIT_STRING *ikey;
 
     if (!dgst)
         dgst = EVP_sha1();
diff --git a/crypto/ocsp/ocsp_local.h b/crypto/ocsp/ocsp_local.h
index 82676ce2d4..03c5aaef86 100644
--- a/crypto/ocsp/ocsp_local.h
+++ b/crypto/ocsp/ocsp_local.h
@@ -7,12 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_OCSP_OCSP_LOCAL_H)
-#define OSSL_LIBCRYPTO_OCSP_OCSP_LOCAL_H
-
-#include 
-#include 
-
 #include "crypto/x509.h" /* for ossl_x509_add_cert_new() */
 
 /*-  CertID ::= SEQUENCE {
@@ -250,5 +244,3 @@ struct ocsp_service_locator_st {
     ASN1_item_verify_ex(ASN1_ITEM_rptr(OCSP_RESPDATA), \
         &(a)->signatureAlgorithm, (a)->signature,      \
         &(a)->tbsResponseData, NULL, r, libctx, propq)
-
-#endif /* !defined(OSSL_LIBCRYPTO_OCSP_OCSP_LOCAL_H) */
diff --git a/crypto/ocsp/ocsp_prn.c b/crypto/ocsp/ocsp_prn.c
index c304777bda..5a9e49480c 100644
--- a/crypto/ocsp/ocsp_prn.c
+++ b/crypto/ocsp/ocsp_prn.c
@@ -98,7 +98,7 @@ int OCSP_REQUEST_print(BIO *bp, OCSP_REQUEST *o, unsigned long flags)
     if (BIO_write(bp, "OCSP Request Data:\n", 19) <= 0)
         goto err;
     l = ASN1_INTEGER_get(inf->version);
-    if (BIO_printf(bp, "    Version: %ld (0x%lx)", l + 1, l) <= 0)
+    if (BIO_printf(bp, "    Version: %lu (0x%lx)", l + 1, l) <= 0)
         goto err;
     if (inf->requestorName != NULL) {
         if (BIO_write(bp, "\n    Requestor Name: ", 21) <= 0)
@@ -166,7 +166,7 @@ int OCSP_RESPONSE_print(BIO *bp, OCSP_RESPONSE *o, unsigned long flags)
         goto err;
     rd = &br->tbsResponseData;
     l = ASN1_INTEGER_get(rd->version);
-    if (BIO_printf(bp, "\n    Version: %ld (0x%lx)\n", l + 1, l) <= 0)
+    if (BIO_printf(bp, "\n    Version: %lu (0x%lx)\n", l + 1, l) <= 0)
         goto err;
     if (BIO_puts(bp, "    Responder Id: ") <= 0)
         goto err;
diff --git a/crypto/ocsp/ocsp_srv.c b/crypto/ocsp/ocsp_srv.c
index fa99da8a7f..56276ad601 100644
--- a/crypto/ocsp/ocsp_srv.c
+++ b/crypto/ocsp/ocsp_srv.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2001-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -164,18 +164,17 @@ int OCSP_basic_add1_cert(OCSP_BASICRESP *resp, X509 *cert)
  */
 int OCSP_basic_sign_ctx(OCSP_BASICRESP *brsp,
     X509 *signer, EVP_MD_CTX *ctx,
-    const STACK_OF(X509) *certs, unsigned long flags)
+    STACK_OF(X509) *certs, unsigned long flags)
 {
     OCSP_RESPID *rid;
-    EVP_PKEY_CTX *pkctx;
     EVP_PKEY *pkey;
 
-    if (ctx == NULL || (pkctx = EVP_MD_CTX_get_pkey_ctx(ctx)) == NULL) {
+    if (ctx == NULL || EVP_MD_CTX_get_pkey_ctx(ctx) == NULL) {
         ERR_raise(ERR_LIB_OCSP, OCSP_R_NO_SIGNER_KEY);
         goto err;
     }
 
-    pkey = EVP_PKEY_CTX_get0_pkey(pkctx);
+    pkey = EVP_PKEY_CTX_get0_pkey(EVP_MD_CTX_get_pkey_ctx(ctx));
     if (pkey == NULL || !X509_check_private_key(signer, pkey)) {
         ERR_raise(ERR_LIB_OCSP, OCSP_R_PRIVATE_KEY_DOES_NOT_MATCH_CERTIFICATE);
         goto err;
@@ -212,7 +211,7 @@ err:
 
 int OCSP_basic_sign(OCSP_BASICRESP *brsp,
     X509 *signer, EVP_PKEY *key, const EVP_MD *dgst,
-    const STACK_OF(X509) *certs, unsigned long flags)
+    STACK_OF(X509) *certs, unsigned long flags)
 {
     EVP_MD_CTX *ctx = EVP_MD_CTX_new();
     EVP_PKEY_CTX *pkctx = NULL;
@@ -301,7 +300,7 @@ int OCSP_RESPID_match_ex(OCSP_RESPID *respid, X509 *cert, OSSL_LIB_CTX *libctx,
         if (!X509_pubkey_digest(cert, sha1, md, NULL))
             goto err;
 
-        ret = (ASN1_STRING_length_ex(respid->value.byKey) == SHA_DIGEST_LENGTH)
+        ret = (ASN1_STRING_length(respid->value.byKey) == SHA_DIGEST_LENGTH)
             && (memcmp(ASN1_STRING_get0_data(respid->value.byKey), md,
                     SHA_DIGEST_LENGTH)
                 == 0);
diff --git a/crypto/ocsp/ocsp_vfy.c b/crypto/ocsp/ocsp_vfy.c
index 70e670cd63..3b6b1fe052 100644
--- a/crypto/ocsp/ocsp_vfy.c
+++ b/crypto/ocsp/ocsp_vfy.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2001-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -14,8 +14,8 @@
 #include "ocsp_local.h"
 
 static int ocsp_find_signer(X509 **psigner, OCSP_BASICRESP *bs,
-    const STACK_OF(X509) *certs, unsigned long flags);
-static X509 *ocsp_find_signer_sk(const STACK_OF(X509) *certs, OCSP_RESPID *id);
+    STACK_OF(X509) *certs, unsigned long flags);
+static X509 *ocsp_find_signer_sk(STACK_OF(X509) *certs, OCSP_RESPID *id);
 static int ocsp_check_issuer(OCSP_BASICRESP *bs, STACK_OF(X509) *chain);
 static int ocsp_check_ids(STACK_OF(OCSP_SINGLERESP) *sresp,
     OCSP_CERTID **ret);
@@ -23,7 +23,7 @@ static int ocsp_match_issuerid(X509 *cert, OCSP_CERTID *cid,
     STACK_OF(OCSP_SINGLERESP) *sresp);
 static int ocsp_check_delegated(X509 *x);
 static int ocsp_req_find_signer(X509 **psigner, OCSP_REQUEST *req,
-    const X509_NAME *nm, const STACK_OF(X509) *certs,
+    const X509_NAME *nm, STACK_OF(X509) *certs,
     unsigned long flags);
 
 /* Returns 1 on success, 0 on failure, or -1 on fatal error */
@@ -95,7 +95,7 @@ static int ocsp_verify(OCSP_REQUEST *req, OCSP_BASICRESP *bs,
 }
 
 /* Verify a basic response message */
-int OCSP_basic_verify(OCSP_BASICRESP *bs, const STACK_OF(X509) *certs,
+int OCSP_basic_verify(OCSP_BASICRESP *bs, STACK_OF(X509) *certs,
     X509_STORE *st, unsigned long flags)
 {
     X509 *signer, *x;
@@ -160,13 +160,13 @@ end:
 }
 
 int OCSP_resp_get0_signer(OCSP_BASICRESP *bs, X509 **signer,
-    const STACK_OF(X509) *extra_certs)
+    STACK_OF(X509) *extra_certs)
 {
     return ocsp_find_signer(signer, bs, extra_certs, 0) > 0;
 }
 
 static int ocsp_find_signer(X509 **psigner, OCSP_BASICRESP *bs,
-    const STACK_OF(X509) *certs, unsigned long flags)
+    STACK_OF(X509) *certs, unsigned long flags)
 {
     X509 *signer;
     OCSP_RESPID *rid = &bs->tbsResponseData.responderId;
@@ -185,7 +185,7 @@ static int ocsp_find_signer(X509 **psigner, OCSP_BASICRESP *bs,
     return 0;
 }
 
-static X509 *ocsp_find_signer_sk(const STACK_OF(X509) *certs, OCSP_RESPID *id)
+static X509 *ocsp_find_signer_sk(STACK_OF(X509) *certs, OCSP_RESPID *id)
 {
     int i, r;
     unsigned char tmphash[SHA_DIGEST_LENGTH], *keyhash;
@@ -314,11 +314,17 @@ static int ocsp_match_issuerid(X509 *cert, OCSP_CERTID *cid,
 
         OBJ_obj2txt(name, sizeof(name), cid->hashAlgorithm.algorithm, 0);
 
+        (void)ERR_set_mark();
         dgst = EVP_MD_fetch(NULL, name, NULL);
+        if (dgst == NULL)
+            dgst = (EVP_MD *)EVP_get_digestbyname(name);
+
         if (dgst == NULL) {
+            (void)ERR_clear_last_mark();
             ERR_raise(ERR_LIB_OCSP, OCSP_R_UNKNOWN_MESSAGE_DIGEST);
             goto end;
         }
+        (void)ERR_pop_to_mark();
 
         mdlen = EVP_MD_get_size(dgst);
         if (mdlen <= 0) {
@@ -374,7 +380,7 @@ static int ocsp_check_delegated(X509 *x)
  * Just find the signer's certificate and verify it against a given trust value.
  * Returns 1 on success, 0 on failure and on fatal error.
  */
-int OCSP_request_verify(OCSP_REQUEST *req, const STACK_OF(X509) *certs,
+int OCSP_request_verify(OCSP_REQUEST *req, STACK_OF(X509) *certs,
     X509_STORE *store, unsigned long flags)
 {
     X509 *signer;
@@ -411,7 +417,7 @@ int OCSP_request_verify(OCSP_REQUEST *req, const STACK_OF(X509) *certs,
 }
 
 static int ocsp_req_find_signer(X509 **psigner, OCSP_REQUEST *req,
-    const X509_NAME *nm, const STACK_OF(X509) *certs,
+    const X509_NAME *nm, STACK_OF(X509) *certs,
     unsigned long flags)
 {
     X509 *signer;
diff --git a/crypto/ocsp/v3_ocsp.c b/crypto/ocsp/v3_ocsp.c
index 408c2a1548..d31c74ef45 100644
--- a/crypto/ocsp/v3_ocsp.c
+++ b/crypto/ocsp/v3_ocsp.c
@@ -143,7 +143,7 @@ static void *ocsp_nonce_new(void)
 static int i2d_ocsp_nonce(const void *a, unsigned char **pp)
 {
     const ASN1_OCTET_STRING *os = a;
-    if (pp != NULL && os->length > 0) {
+    if (pp) {
         memcpy(*pp, os->data, os->length);
         *pp += os->length;
     }
@@ -164,8 +164,7 @@ static void *d2i_ocsp_nonce(void *a, const unsigned char **pp, long length)
     if (!ASN1_OCTET_STRING_set(os, *pp, length))
         goto err;
 
-    if (length > 0)
-        *pp += length;
+    *pp += length;
 
     if (pos)
         *pos = os;
diff --git a/crypto/param_build.c b/crypto/param_build.c
index c268730db2..b1b7c3518b 100644
--- a/crypto/param_build.c
+++ b/crypto/param_build.c
@@ -121,22 +121,12 @@ void OSSL_PARAM_BLD_free(OSSL_PARAM_BLD *bld)
 
 int OSSL_PARAM_BLD_push_int(OSSL_PARAM_BLD *bld, const char *key, int num)
 {
-    if (bld == NULL || key == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     return param_push_num(bld, key, &num, sizeof(num), OSSL_PARAM_INTEGER);
 }
 
 int OSSL_PARAM_BLD_push_uint(OSSL_PARAM_BLD *bld, const char *key,
     unsigned int num)
 {
-    if (bld == NULL || key == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     return param_push_num(bld, key, &num, sizeof(num),
         OSSL_PARAM_UNSIGNED_INTEGER);
 }
@@ -144,22 +134,12 @@ int OSSL_PARAM_BLD_push_uint(OSSL_PARAM_BLD *bld, const char *key,
 int OSSL_PARAM_BLD_push_long(OSSL_PARAM_BLD *bld, const char *key,
     long int num)
 {
-    if (bld == NULL || key == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     return param_push_num(bld, key, &num, sizeof(num), OSSL_PARAM_INTEGER);
 }
 
 int OSSL_PARAM_BLD_push_ulong(OSSL_PARAM_BLD *bld, const char *key,
     unsigned long int num)
 {
-    if (bld == NULL || key == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     return param_push_num(bld, key, &num, sizeof(num),
         OSSL_PARAM_UNSIGNED_INTEGER);
 }
@@ -167,22 +147,12 @@ int OSSL_PARAM_BLD_push_ulong(OSSL_PARAM_BLD *bld, const char *key,
 int OSSL_PARAM_BLD_push_int32(OSSL_PARAM_BLD *bld, const char *key,
     int32_t num)
 {
-    if (bld == NULL || key == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     return param_push_num(bld, key, &num, sizeof(num), OSSL_PARAM_INTEGER);
 }
 
 int OSSL_PARAM_BLD_push_uint32(OSSL_PARAM_BLD *bld, const char *key,
     uint32_t num)
 {
-    if (bld == NULL || key == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     return param_push_num(bld, key, &num, sizeof(num),
         OSSL_PARAM_UNSIGNED_INTEGER);
 }
@@ -190,22 +160,12 @@ int OSSL_PARAM_BLD_push_uint32(OSSL_PARAM_BLD *bld, const char *key,
 int OSSL_PARAM_BLD_push_int64(OSSL_PARAM_BLD *bld, const char *key,
     int64_t num)
 {
-    if (bld == NULL || key == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     return param_push_num(bld, key, &num, sizeof(num), OSSL_PARAM_INTEGER);
 }
 
 int OSSL_PARAM_BLD_push_uint64(OSSL_PARAM_BLD *bld, const char *key,
     uint64_t num)
 {
-    if (bld == NULL || key == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     return param_push_num(bld, key, &num, sizeof(num),
         OSSL_PARAM_UNSIGNED_INTEGER);
 }
@@ -213,11 +173,6 @@ int OSSL_PARAM_BLD_push_uint64(OSSL_PARAM_BLD *bld, const char *key,
 int OSSL_PARAM_BLD_push_size_t(OSSL_PARAM_BLD *bld, const char *key,
     size_t num)
 {
-    if (bld == NULL || key == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     return param_push_num(bld, key, &num, sizeof(num),
         OSSL_PARAM_UNSIGNED_INTEGER);
 }
@@ -225,11 +180,6 @@ int OSSL_PARAM_BLD_push_size_t(OSSL_PARAM_BLD *bld, const char *key,
 int OSSL_PARAM_BLD_push_time_t(OSSL_PARAM_BLD *bld, const char *key,
     time_t num)
 {
-    if (bld == NULL || key == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     return param_push_num(bld, key, &num, sizeof(num),
         OSSL_PARAM_INTEGER);
 }
@@ -237,11 +187,6 @@ int OSSL_PARAM_BLD_push_time_t(OSSL_PARAM_BLD *bld, const char *key,
 int OSSL_PARAM_BLD_push_double(OSSL_PARAM_BLD *bld, const char *key,
     double num)
 {
-    if (bld == NULL || key == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     return param_push_num(bld, key, &num, sizeof(num), OSSL_PARAM_REAL);
 }
 
@@ -251,11 +196,6 @@ static int push_BN(OSSL_PARAM_BLD *bld, const char *key,
     int n, secure = 0;
     OSSL_PARAM_BLD_DEF *pd;
 
-    if (bld == NULL || key == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     if (!ossl_assert(type == OSSL_PARAM_UNSIGNED_INTEGER
             || type == OSSL_PARAM_INTEGER))
         return 0;
@@ -293,11 +233,6 @@ static int push_BN(OSSL_PARAM_BLD *bld, const char *key,
 int OSSL_PARAM_BLD_push_BN(OSSL_PARAM_BLD *bld, const char *key,
     const BIGNUM *bn)
 {
-    if (bld == NULL || key == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     if (bn != NULL && BN_is_negative(bn))
         return push_BN(bld, key, bn, BN_num_bytes(bn) + 1,
             OSSL_PARAM_INTEGER);
@@ -308,11 +243,6 @@ int OSSL_PARAM_BLD_push_BN(OSSL_PARAM_BLD *bld, const char *key,
 int OSSL_PARAM_BLD_push_BN_pad(OSSL_PARAM_BLD *bld, const char *key,
     const BIGNUM *bn, size_t sz)
 {
-    if (bld == NULL || key == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     if (bn != NULL && BN_is_negative(bn))
         return push_BN(bld, key, bn, BN_num_bytes(bn),
             OSSL_PARAM_INTEGER);
@@ -325,11 +255,6 @@ int OSSL_PARAM_BLD_push_utf8_string(OSSL_PARAM_BLD *bld, const char *key,
     OSSL_PARAM_BLD_DEF *pd;
     int secure;
 
-    if (bld == NULL || key == NULL || buf == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     if (bsize == 0)
         bsize = strlen(buf);
     secure = CRYPTO_secure_allocated(buf);
@@ -345,11 +270,6 @@ int OSSL_PARAM_BLD_push_utf8_ptr(OSSL_PARAM_BLD *bld, const char *key,
 {
     OSSL_PARAM_BLD_DEF *pd;
 
-    if (bld == NULL || key == NULL || buf == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     if (bsize == 0)
         bsize = strlen(buf);
     pd = param_push(bld, key, bsize, sizeof(buf), OSSL_PARAM_UTF8_PTR, 0);
@@ -365,11 +285,6 @@ int OSSL_PARAM_BLD_push_octet_string(OSSL_PARAM_BLD *bld, const char *key,
     OSSL_PARAM_BLD_DEF *pd;
     int secure;
 
-    if (bld == NULL || key == NULL || (buf == NULL && bsize != 0)) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     secure = CRYPTO_secure_allocated(buf);
     pd = param_push(bld, key, bsize, bsize, OSSL_PARAM_OCTET_STRING, secure);
     if (pd == NULL)
@@ -383,11 +298,6 @@ int OSSL_PARAM_BLD_push_octet_ptr(OSSL_PARAM_BLD *bld, const char *key,
 {
     OSSL_PARAM_BLD_DEF *pd;
 
-    if (bld == NULL || key == NULL || (buf == NULL && bsize != 0)) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
     pd = param_push(bld, key, bsize, sizeof(buf), OSSL_PARAM_OCTET_PTR, 0);
     if (pd == NULL)
         return 0;
@@ -452,18 +362,10 @@ OSSL_PARAM *OSSL_PARAM_BLD_to_param(OSSL_PARAM_BLD *bld)
 {
     OSSL_PARAM_ALIGNED_BLOCK *blk, *s = NULL;
     OSSL_PARAM *params, *last;
-    int num;
-    size_t p_blks, total, ss;
-
-    if (bld == NULL) {
-        ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
-
-    num = sk_OSSL_PARAM_BLD_DEF_num(bld->params);
-    p_blks = ossl_param_bytes_to_blocks((1 + num) * sizeof(*params));
-    total = OSSL_PARAM_ALIGN_SIZE * (p_blks + bld->total_blocks);
-    ss = OSSL_PARAM_ALIGN_SIZE * bld->secure_blocks;
+    const int num = sk_OSSL_PARAM_BLD_DEF_num(bld->params);
+    const size_t p_blks = ossl_param_bytes_to_blocks((1 + num) * sizeof(*params));
+    const size_t total = OSSL_PARAM_ALIGN_SIZE * (p_blks + bld->total_blocks);
+    const size_t ss = OSSL_PARAM_ALIGN_SIZE * bld->secure_blocks;
 
     if (ss > 0) {
         s = OPENSSL_secure_malloc(ss);
diff --git a/crypto/param_build_set.c b/crypto/param_build_set.c
index 51a2678350..db49683ed9 100644
--- a/crypto/param_build_set.c
+++ b/crypto/param_build_set.c
@@ -73,11 +73,6 @@ int ossl_param_build_set_bn_pad(OSSL_PARAM_BLD *bld, OSSL_PARAM *p,
         return OSSL_PARAM_BLD_push_BN_pad(bld, key, bn, sz);
     p = OSSL_PARAM_locate(p, key);
     if (p != NULL) {
-        /* Size probe: NULL data means "report the required size". */
-        if (p->data == NULL) {
-            p->return_size = sz;
-            return 1;
-        }
         if (sz > p->data_size) {
             ERR_raise(ERR_LIB_CRYPTO, CRYPTO_R_TOO_SMALL_BUFFER);
             return 0;
diff --git a/crypto/params_from_text.c b/crypto/params_from_text.c
index 7401a5f4e4..60bae1707d 100644
--- a/crypto/params_from_text.c
+++ b/crypto/params_from_text.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright (c) 2019, Oracle and/or its affiliates.  All rights reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
@@ -198,7 +198,6 @@ static int construct_from_text(OSSL_PARAM *to, const OSSL_PARAM *paramdef,
     return 1;
 }
 
-#ifndef FIPS_MODULE
 /**
  * OSSL_PARAM_print_to_bio - Print OSSL_PARAM array to a bio
  *
@@ -303,7 +302,6 @@ int OSSL_PARAM_print_to_bio(const OSSL_PARAM *p, BIO *bio, int print_values)
 end:
     return ok == -1 ? 0 : 1;
 }
-#endif /* FIPS_MODULE */
 
 int OSSL_PARAM_allocate_from_text(OSSL_PARAM *to,
     const OSSL_PARAM *paramdefs,
diff --git a/crypto/pem/pem_info.c b/crypto/pem/pem_info.c
index fa189f0c5d..8f38fe0580 100644
--- a/crypto/pem/pem_info.c
+++ b/crypto/pem/pem_info.c
@@ -24,14 +24,6 @@
 #include 
 #include "crypto/evp.h"
 
-typedef enum {
-    PEM_INFO_NONE,
-    PEM_INFO_X509,
-    PEM_INFO_X509_AUX,
-    PEM_INFO_X509_CRL,
-    PEM_INFO_PKEY
-} pem_info_type;
-
 #ifndef OPENSSL_NO_STDIO
 STACK_OF(X509_INFO)
 *PEM_X509_INFO_read_ex(FILE *fp, STACK_OF(X509_INFO) *sk, pem_password_cb *cb,
@@ -71,7 +63,7 @@ STACK_OF(X509_INFO) *PEM_X509_INFO_read_bio_ex(BIO *bp, STACK_OF(X509_INFO) *sk,
     int ok = 0;
     STACK_OF(X509_INFO) *ret = NULL;
     unsigned int i, raw, ptype;
-    pem_info_type itype = PEM_INFO_NONE;
+    d2i_of_void *d2i = 0;
 
     if (sk == NULL) {
         if ((ret = sk_X509_INFO_new_null()) == NULL) {
@@ -86,7 +78,6 @@ STACK_OF(X509_INFO) *PEM_X509_INFO_read_bio_ex(BIO *bp, STACK_OF(X509_INFO) *sk,
     for (;;) {
         raw = 0;
         ptype = 0;
-        itype = PEM_INFO_NONE;
         ERR_set_mark();
         i = PEM_read_bio(bp, &name, &header, &data, &len);
         if (i == 0) {
@@ -111,15 +102,15 @@ STACK_OF(X509_INFO) *PEM_X509_INFO_read_bio_ex(BIO *bp, STACK_OF(X509_INFO) *sk,
                 goto start;
             }
             if ((strcmp(name, PEM_STRING_X509_TRUSTED) == 0))
-                itype = PEM_INFO_X509_AUX;
+                d2i = (D2I_OF(void))d2i_X509_AUX;
             else
-                itype = PEM_INFO_X509;
+                d2i = (D2I_OF(void))d2i_X509;
             xi->x509 = X509_new_ex(libctx, propq);
             if (xi->x509 == NULL)
                 goto err;
             pp = &(xi->x509);
         } else if (strcmp(name, PEM_STRING_X509_CRL) == 0) {
-            itype = PEM_INFO_X509_CRL;
+            d2i = (D2I_OF(void))d2i_X509_CRL;
             if (xi->crl != NULL) {
                 if (!sk_X509_INFO_push(ret, xi))
                     goto err;
@@ -146,7 +137,7 @@ STACK_OF(X509_INFO) *PEM_X509_INFO_read_bio_ex(BIO *bp, STACK_OF(X509_INFO) *sk,
             xi->enc_data = NULL;
             xi->enc_len = 0;
 
-            itype = PEM_INFO_PKEY;
+            d2i = (D2I_OF(void))d2i_AutoPrivateKey;
             xi->x_pkey = X509_PKEY_new();
             if (xi->x_pkey == NULL)
                 goto err;
@@ -155,11 +146,11 @@ STACK_OF(X509_INFO) *PEM_X509_INFO_read_bio_ex(BIO *bp, STACK_OF(X509_INFO) *sk,
                 || strcmp(name, PEM_STRING_PKCS8) == 0)
                 raw = 1;
         } else { /* unknown */
-            itype = PEM_INFO_NONE;
+            d2i = NULL;
             pp = NULL;
         }
 
-        if (itype != PEM_INFO_NONE) {
+        if (d2i != NULL) {
             if (!raw) {
                 EVP_CIPHER_INFO cipher;
 
@@ -169,36 +160,15 @@ STACK_OF(X509_INFO) *PEM_X509_INFO_read_bio_ex(BIO *bp, STACK_OF(X509_INFO) *sk,
                     goto err;
                 p = data;
                 if (ptype) {
-                    if (d2i_PrivateKey_ex(ptype, (EVP_PKEY **)pp, &p, len,
+                    if (d2i_PrivateKey_ex(ptype, pp, &p, len,
                             libctx, propq)
                         == NULL) {
                         ERR_raise(ERR_LIB_PEM, ERR_R_ASN1_LIB);
                         goto err;
                     }
-                } else {
-                    void *decoded = NULL;
-
-                    switch (itype) {
-                    case PEM_INFO_X509:
-                        decoded = d2i_X509((X509 **)pp, &p, len);
-                        break;
-                    case PEM_INFO_X509_AUX:
-                        decoded = d2i_X509_AUX((X509 **)pp, &p, len);
-                        break;
-                    case PEM_INFO_X509_CRL:
-                        decoded = d2i_X509_CRL((X509_CRL **)pp, &p, len);
-                        break;
-                    case PEM_INFO_PKEY:
-                        decoded = d2i_AutoPrivateKey_ex((EVP_PKEY **)pp, &p,
-                            len, libctx, propq);
-                        break;
-                    default:
-                        break;
-                    }
-                    if (decoded == NULL) {
-                        ERR_raise(ERR_LIB_PEM, ERR_R_ASN1_LIB);
-                        goto err;
-                    }
+                } else if (d2i(pp, &p, len) == NULL) {
+                    ERR_raise(ERR_LIB_PEM, ERR_R_ASN1_LIB);
+                    goto err;
                 }
             } else { /* encrypted key data */
                 if (!PEM_get_EVP_CIPHER_INFO(header, &xi->enc_cipher))
diff --git a/crypto/pem/pem_lib.c b/crypto/pem/pem_lib.c
index 8eff7e950a..2f7e51b16b 100644
--- a/crypto/pem/pem_lib.c
+++ b/crypto/pem/pem_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -25,7 +25,6 @@
 #include 
 #include "crypto/asn1.h"
 #include 
-#include "crypto/evp.h"
 
 #define MIN_LENGTH 4
 
@@ -146,7 +145,7 @@ static int check_pem(const char *nm, const char *name)
              * NB: ENGINE implementations won't contain a deprecated old
              * private key decode function so don't look for them.
              */
-            ameth = evp_pkey_asn1_find_str(nm, slen);
+            ameth = EVP_PKEY_asn1_find_str(NULL, nm, slen);
             if (ameth && ameth->old_priv_decode)
                 return 1;
         }
@@ -158,7 +157,7 @@ static int check_pem(const char *nm, const char *name)
         const EVP_PKEY_ASN1_METHOD *ameth;
         slen = ossl_pem_check_suffix(nm, "PARAMETERS");
         if (slen > 0) {
-            ameth = evp_pkey_asn1_find_str(nm, slen);
+            ameth = EVP_PKEY_asn1_find_str(NULL, nm, slen);
             if (ameth) {
                 int r;
                 if (ameth->param_decode)
diff --git a/crypto/pem/pem_local.h b/crypto/pem/pem_local.h
index 840b6acb7f..ef2874db4a 100644
--- a/crypto/pem/pem_local.h
+++ b/crypto/pem/pem_local.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_PEM_PEM_LOCAL_H)
-#define OSSL_LIBCRYPTO_PEM_PEM_LOCAL_H
-
 #include 
 #include 
 #include 
@@ -165,5 +162,3 @@
 #define IMPLEMENT_PEM_provided_rw_cb(name, TYPE, type, str, asn1) \
     IMPLEMENT_PEM_read(name, TYPE, str, asn1)                     \
     IMPLEMENT_PEM_provided_write_cb(name, TYPE, type, str, asn1)
-
-#endif /* !defined(OSSL_LIBCRYPTO_PEM_PEM_LOCAL_H) */
diff --git a/crypto/pem/pem_pkey.c b/crypto/pem/pem_pkey.c
index d6eb42c602..6542aa2a7c 100644
--- a/crypto/pem/pem_pkey.c
+++ b/crypto/pem/pem_pkey.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -174,7 +174,7 @@ static EVP_PKEY *pem_read_bio_key_legacy(BIO *bp, EVP_PKEY **x,
         PKCS8_PRIV_KEY_INFO_free(p8inf);
     } else if ((slen = ossl_pem_check_suffix(nm, "PRIVATE KEY")) > 0) {
         const EVP_PKEY_ASN1_METHOD *ameth;
-        ameth = evp_pkey_asn1_find_str(nm, slen);
+        ameth = EVP_PKEY_asn1_find_str(NULL, nm, slen);
         if (ameth == NULL || ameth->old_priv_decode == NULL)
             goto p8err;
         ret = ossl_d2i_PrivateKey_legacy(ameth->pkey_id, x, &p, len, libctx,
diff --git a/crypto/pem/pvkfmt.c b/crypto/pem/pvkfmt.c
index 31b46183a4..9bfbb01e43 100644
--- a/crypto/pem/pvkfmt.c
+++ b/crypto/pem/pvkfmt.c
@@ -893,13 +893,13 @@ static void *do_PVK_body_key(const unsigned char **in,
                 (unsigned char *)psbuf, inlen, libctx, propq))
             goto err;
         p += saltlen;
+        /* Copy BLOBHEADER across, decrypt rest */
+        memcpy(enctmp, p, 8);
+        p += 8;
         if (keylen < 8) {
             ERR_raise(ERR_LIB_PEM, PEM_R_PVK_TOO_SHORT);
             goto err;
         }
-        /* Copy BLOBHEADER across, decrypt rest */
-        memcpy(enctmp, p, 8);
-        p += 8;
         inlen = keylen - 8;
         q = enctmp + 8;
         if ((rc4 = EVP_CIPHER_fetch(libctx, "RC4", propq)) == NULL)
diff --git a/crypto/perlasm/riscv.pm b/crypto/perlasm/riscv.pm
index 5d62f3a660..bac41fb453 100644
--- a/crypto/perlasm/riscv.pm
+++ b/crypto/perlasm/riscv.pm
@@ -468,16 +468,6 @@ sub vadd_vv {
     return ".word ".($template | ($vm << 25) | ($vs2 << 20) | ($vs1 << 15) | ($vd << 7));
 }
 
-sub vrgather_vv {
-    # vrgather.vv vd, vs2, vs1, vm
-    my $template = 0b001100_0_00000_00000_000_00000_1010111;
-    my $vd = read_vreg shift;
-    my $vs2 = read_vreg shift;
-    my $vs1 = read_vreg shift;
-    my $vm = read_mask_vreg shift;
-    return ".word ".($template | ($vm << 25) | ($vs2 << 20) | ($vs1 << 15) | ($vd << 7));
-}
-
 sub vadd_vx {
     # vadd.vx vd, vs2, rs1, vm
     my $template = 0b000000_0_00000_00000_100_00000_1010111;
@@ -589,16 +579,6 @@ sub vluxei8_v {
     return ".word ".($template | ($vm << 25) | ($vs2 << 20) | ($rs1 << 15) | ($vd << 7));
 }
 
-sub vluxei32_v {
-    # vluxei32.v vd, (rs1), vs2, vm
-    my $template = 0b000001_0_00000_00000_110_00000_0000111;
-    my $vd = read_vreg shift;
-    my $rs1 = read_reg shift;
-    my $vs2 = read_vreg shift;
-    my $vm = read_mask_vreg shift;
-    return ".word ".($template | ($vm << 25) | ($vs2 << 20) | ($rs1 << 15) | ($vd << 7));
-}
-
 sub vmerge_vim {
     # vmerge.vim vd, vs2, imm, v0
     my $template = 0b0101110_00000_00000_011_00000_1010111;
@@ -644,14 +624,6 @@ sub vmv_v_i {
     return ".word ".($template | ($imm << 15) | ($vd << 7));
 }
 
-sub vmv1r_v {
-    # vmv1r.v vd, vs1
-    my $template = 0b1001111_00000_00000_011_00000_1010111;
-    my $vd = read_vreg shift;
-    my $vs1 = read_vreg shift;
-    return ".word ".($template | ($vs1 << 20) | ($vd << 7));
-}
-
 sub vmv_v_x {
     # vmv.v.x vd, rs1
     my $template = 0b0101111_00000_00000_100_00000_1010111;
@@ -1120,13 +1092,4 @@ sub vsm3me_vv {
     return ".word ".($template | ($vs2 << 20) | ($vs1 << 15 ) | ($vd << 7));
 }
 
-sub vrgather_vv{
-    # vrgather.vv vd, vs2, vs1
-    my $template = 0b11001_00000_00000_000_00000_1010111;
-    my $vd = read_vreg shift;
-    my $vs2 = read_vreg shift;
-    my $vs1 = read_vreg shift;
-    return ".word ".($template | ($vs2 << 20) | ($vs1 << 15 ) | ($vd << 7));
-}
-
 1;
diff --git a/crypto/perlasm/x86_64-xlate.pl b/crypto/perlasm/x86_64-xlate.pl
index cd8d35ea67..6ee56b874b 100755
--- a/crypto/perlasm/x86_64-xlate.pl
+++ b/crypto/perlasm/x86_64-xlate.pl
@@ -664,7 +664,8 @@ my %globals;
 	);
 
     # Following constants are defined in x86_64 ABI supplement, for
-    # example available at https://gitlab.com/x86-psABIs/x86-64-ABI.
+    # example available at https://www.uclibc.org/docs/psABI-x86_64.pdf,
+    # see section 3.7 "Stack Unwind Algorithm".
     my %DW_reg_idx = (
 	"%rax"=>0,  "%rdx"=>1,  "%rcx"=>2,  "%rbx"=>3,
 	"%rsi"=>4,  "%rdi"=>5,  "%rbp"=>6,  "%rsp"=>7,
diff --git a/crypto/perlasm/x86gas.pl b/crypto/perlasm/x86gas.pl
index 04e0d043b4..d810fd5479 100644
--- a/crypto/perlasm/x86gas.pl
+++ b/crypto/perlasm/x86gas.pl
@@ -14,8 +14,6 @@ package x86gas;
 $::lbdecor=$::aout?"L":".L";		# local label decoration
 $nmdecor=($::aout or $::coff)?"_":"";	# external name decoration
 
-$initseg="";
-
 $align=16;
 $align=log($align)/log(2) if ($::aout);
 $com_start="#" if ($::aout or $::coff);
@@ -173,7 +171,6 @@ sub ::file_end
 	elsif ($::elf)	{ push (@out,"$tmp,4\n"); }
 	else		{ push (@out,"$tmp\n"); }
     }
-    push(@out,$initseg) if ($initseg);
     if ($::elf) {
 	push(@out,"
 	.section \".note.gnu.property\", \"a\"
@@ -237,48 +234,6 @@ sub ::picmeup
     {	&::lea($dst,&::DWP($sym));	}
 }
 
-sub ::initseg
-{ my $f=$nmdecor.shift;
-
-    if ($::android)
-    {	$initseg.=<<___;
-.section	.init_array
-.align	4
-.long	$f
-___
-    }
-    elsif ($::elf)
-    {	$initseg.=<<___;
-.section	.init
-	call	$f
-___
-    }
-    elsif ($::coff)
-    {   $initseg.=<<___;	# applies to both Cygwin and Mingw
-.section	.ctors
-.long	$f
-___
-    }
-    elsif ($::macosx)
-    {	$initseg.=<<___;
-.mod_init_func
-.align 2
-.long   $f
-___
-    }
-    elsif ($::aout)
-    {	my $ctor="${nmdecor}_GLOBAL_\$I\$$f";
-	$initseg.=".text\n";
-	$initseg.=".type	$ctor,\@function\n" if ($::pic);
-	$initseg.=<<___;	# OpenBSD way...
-.globl	$ctor
-.align	2
-$ctor:
-	jmp	$f
-___
-    }
-}
-
 sub ::dataseg
 {   push(@out,".data\n");   }
 
diff --git a/crypto/perlasm/x86masm.pl b/crypto/perlasm/x86masm.pl
index 98dedec8de..1c567f23dd 100644
--- a/crypto/perlasm/x86masm.pl
+++ b/crypto/perlasm/x86masm.pl
@@ -14,7 +14,6 @@ package x86masm;
 $::lbdecor="\$L";	# local label decoration
 $nmdecor="_";		# external name decoration
 
-$initseg="";
 $segment="";
 
 sub ::generic
@@ -149,7 +148,6 @@ ___
 	grep {s/(^EXTERN\s+${nmdecor}OPENSSL_ia32cap_P)/\;$1/} @out;
 	push (@out,$comm);
     }
-    push (@out,$initseg) if ($initseg);
     push (@out,"END\n");
 }
 
@@ -183,17 +181,6 @@ sub ::picmeup
     &::lea($dst,&::DWP($sym));
 }
 
-sub ::initseg
-{ my $f=$nmdecor.shift;
-
-    $initseg.=<<___;
-.CRT\$XCU	SEGMENT DWORD PUBLIC 'DATA'
-EXTERN	$f:NEAR
-DD	$f
-.CRT\$XCU	ENDS
-___
-}
-
 sub ::dataseg
 {   push(@out,"$segment\tENDS\n_DATA\tSEGMENT\n"); $segment="_DATA";   }
 
diff --git a/crypto/perlasm/x86nasm.pl b/crypto/perlasm/x86nasm.pl
index 0d223a617b..110ecddab3 100644
--- a/crypto/perlasm/x86nasm.pl
+++ b/crypto/perlasm/x86nasm.pl
@@ -15,8 +15,6 @@ $::lbdecor="L\$";		# local label decoration
 $nmdecor="_";			# external name decoration
 $drdecor=$::mwerks?".":"";	# directive decoration
 
-$initseg="";
-
 sub ::generic
 { my $opcode=shift;
   my $tmp;
@@ -133,7 +131,6 @@ ___
 	grep {s/(^extern\s+${nmdecor}OPENSSL_ia32cap_P)/\;$1/} @out;
 	push (@out,$comm)
     }
-    push (@out,$initseg) if ($initseg);
 }
 
 sub ::comment {   foreach (@_) { push(@out,"\t; $_\n"); }   }
@@ -161,17 +158,6 @@ sub ::picmeup
     &::lea($dst,&::DWP($sym));
 }
 
-sub ::initseg
-{ my $f=$nmdecor.shift;
-    if ($::win32)
-    {	$initseg=<<___;
-segment	.CRT\$XCU data align=4
-extern	$f
-dd	$f
-___
-    }
-}
-
 sub ::dataseg
 {   if ($mwerks)	{ push(@out,".section\t.data,4\n");   }
     else		{ push(@out,"section\t.data align=4\n"); }
diff --git a/crypto/pkcs12/p12_add.c b/crypto/pkcs12/p12_add.c
index 1217317783..4750974d60 100644
--- a/crypto/pkcs12/p12_add.c
+++ b/crypto/pkcs12/p12_add.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -98,7 +98,8 @@ PKCS7 *PKCS12_pack_p7encdata_ex(int pbe_nid, const char *pass, int passlen,
 {
     PKCS7 *p7;
     X509_ALGOR *pbe;
-    EVP_CIPHER *pbe_ciph = NULL;
+    const EVP_CIPHER *pbe_ciph = NULL;
+    EVP_CIPHER *pbe_ciph_fetch = NULL;
 
     if ((p7 = PKCS7_new_ex(ctx, propq)) == NULL) {
         ERR_raise(ERR_LIB_PKCS12, ERR_R_ASN1_LIB);
@@ -110,7 +111,9 @@ PKCS7 *PKCS12_pack_p7encdata_ex(int pbe_nid, const char *pass, int passlen,
     }
 
     ERR_set_mark();
-    pbe_ciph = EVP_CIPHER_fetch(ctx, OBJ_nid2sn(pbe_nid), propq);
+    pbe_ciph = pbe_ciph_fetch = EVP_CIPHER_fetch(ctx, OBJ_nid2sn(pbe_nid), propq);
+    if (pbe_ciph == NULL)
+        pbe_ciph = EVP_get_cipherbynid(pbe_nid);
     ERR_pop_to_mark();
 
     if (pbe_ciph != NULL) {
@@ -132,12 +135,12 @@ PKCS7 *PKCS12_pack_p7encdata_ex(int pbe_nid, const char *pass, int passlen,
         goto err;
     }
 
-    EVP_CIPHER_free(pbe_ciph);
+    EVP_CIPHER_free(pbe_ciph_fetch);
     return p7;
 
 err:
     PKCS7_free(p7);
-    EVP_CIPHER_free(pbe_ciph);
+    EVP_CIPHER_free(pbe_ciph_fetch);
     return NULL;
 }
 
@@ -219,6 +222,6 @@ STACK_OF(PKCS7) *PKCS12_unpack_authsafes(const PKCS12 *p12)
     }
     return p7s;
 err:
-    sk_PKCS7_pop_free(p7s, PKCS7_free);
+    sk_PKCS7_free(p7s);
     return NULL;
 }
diff --git a/crypto/pkcs12/p12_attr.c b/crypto/pkcs12/p12_attr.c
index 677f303b05..ec609d9b5a 100644
--- a/crypto/pkcs12/p12_attr.c
+++ b/crypto/pkcs12/p12_attr.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -12,11 +12,9 @@
 #include 
 #include "p12_local.h"
 
-#include 
-
 /* Add a local keyid to a safebag */
 
-int PKCS12_add_localkeyid(PKCS12_SAFEBAG *bag, const unsigned char *name,
+int PKCS12_add_localkeyid(PKCS12_SAFEBAG *bag, unsigned char *name,
     int namelen)
 {
     if (X509at_add1_attr_by_NID(&bag->attrib, NID_localKeyID,
@@ -99,7 +97,7 @@ int PKCS12_add1_attr_by_txt(PKCS12_SAFEBAG *bag, const char *attrname, int type,
         return 0;
 }
 
-const ASN1_TYPE *PKCS12_get_attr_gen(const STACK_OF(X509_ATTRIBUTE) *attrs,
+ASN1_TYPE *PKCS12_get_attr_gen(const STACK_OF(X509_ATTRIBUTE) *attrs,
     int attr_nid)
 {
     int i = X509at_get_attr_by_NID(attrs, attr_nid, -1);
diff --git a/crypto/pkcs12/p12_crpt.c b/crypto/pkcs12/p12_crpt.c
index e796385101..b7519f7b58 100644
--- a/crypto/pkcs12/p12_crpt.c
+++ b/crypto/pkcs12/p12_crpt.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -14,8 +14,6 @@
 #include "crypto/evp.h"
 #include 
 
-#include 
-
 /* PKCS#12 PBE algorithms now in static table */
 
 void PKCS12_PBE_add(void)
diff --git a/crypto/pkcs12/p12_crt.c b/crypto/pkcs12/p12_crt.c
index 948d46b851..90a6fe1182 100644
--- a/crypto/pkcs12/p12_crt.c
+++ b/crypto/pkcs12/p12_crt.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -20,7 +20,7 @@ static PKCS12_SAFEBAG *pkcs12_add_cert_bag(STACK_OF(PKCS12_SAFEBAG) **pbags,
     X509 *cert,
     const char *name,
     int namelen,
-    const unsigned char *keyid,
+    unsigned char *keyid,
     int keyidlen);
 
 static int copy_bag_attr(PKCS12_SAFEBAG *bag, EVP_PKEY *pkey, int nid)
@@ -46,7 +46,7 @@ PKCS12 *PKCS12_create_ex2(const char *pass, const char *name, EVP_PKEY *pkey,
     unsigned char keyid[EVP_MAX_MD_SIZE];
     unsigned int keyidlen = 0;
     int namelen = -1;
-    const unsigned char *pkeyid = NULL;
+    unsigned char *pkeyid = NULL;
     int pkeyidlen = -1;
 
     /* Set defaults */
@@ -190,7 +190,7 @@ static PKCS12_SAFEBAG *pkcs12_add_cert_bag(STACK_OF(PKCS12_SAFEBAG) **pbags,
     X509 *cert,
     const char *name,
     int namelen,
-    const unsigned char *keyid,
+    unsigned char *keyid,
     int keyidlen)
 {
     PKCS12_SAFEBAG *bag = NULL;
@@ -219,7 +219,7 @@ PKCS12_SAFEBAG *PKCS12_add_cert(STACK_OF(PKCS12_SAFEBAG) **pbags, X509 *cert)
 {
     char *name = NULL;
     int namelen = -1;
-    const unsigned char *keyid = NULL;
+    unsigned char *keyid = NULL;
     int keyidlen = -1;
 
     /*
diff --git a/crypto/pkcs12/p12_decr.c b/crypto/pkcs12/p12_decr.c
index 535481cdfe..606713b9ee 100644
--- a/crypto/pkcs12/p12_decr.c
+++ b/crypto/pkcs12/p12_decr.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -12,8 +12,6 @@
 #include 
 #include 
 
-#include 
-
 /*
  * Encrypt/Decrypt a buffer based on password and algor, result in a
  * OPENSSL_malloc'ed buffer
@@ -79,7 +77,7 @@ unsigned char *PKCS12_pbe_crypt_ex(const X509_ALGOR *algor,
         }
     }
 
-    if ((out = OPENSSL_zalloc(max_out_len)) == NULL)
+    if ((out = OPENSSL_malloc(max_out_len)) == NULL)
         goto err;
 
     if (!EVP_CipherUpdate(ctx, out, &i, in, inlen)) {
@@ -105,7 +103,7 @@ unsigned char *PKCS12_pbe_crypt_ex(const X509_ALGOR *algor,
         if (EVP_CIPHER_CTX_is_encrypting(ctx)) {
             if (EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_GET_TAG,
                     (int)mac_len, out + outlen)
-                <= 0) {
+                < 0) {
                 OPENSSL_free(out);
                 out = NULL;
                 ERR_raise(ERR_LIB_PKCS12, ERR_R_INTERNAL_ERROR);
@@ -148,11 +146,6 @@ void *PKCS12_item_decrypt_d2i_ex(const X509_ALGOR *algor, const ASN1_ITEM *it,
     void *ret;
     int outlen = 0;
 
-    if (oct == NULL) {
-        ERR_raise(ERR_LIB_PKCS12, ERR_R_PASSED_NULL_PARAMETER);
-        return NULL;
-    }
-
     if (!PKCS12_pbe_crypt_ex(algor, pass, passlen, oct->data, oct->length,
             &out, &outlen, 0, libctx, propq))
         return NULL;
diff --git a/crypto/pkcs12/p12_kiss.c b/crypto/pkcs12/p12_kiss.c
index 1c2e49a57f..10b581612d 100644
--- a/crypto/pkcs12/p12_kiss.c
+++ b/crypto/pkcs12/p12_kiss.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -196,17 +196,11 @@ static int parse_bag(PKCS12_SAFEBAG *bag, const char *pass, int passlen,
     ASN1_BMPSTRING *fname = NULL;
     ASN1_OCTET_STRING *lkid = NULL;
 
-    if ((attrib = PKCS12_SAFEBAG_get0_attr(bag, NID_friendlyName))) {
-        if (attrib->type != V_ASN1_BMPSTRING)
-            return 0;
+    if ((attrib = PKCS12_SAFEBAG_get0_attr(bag, NID_friendlyName)))
         fname = attrib->value.bmpstring;
-    }
 
-    if ((attrib = PKCS12_SAFEBAG_get0_attr(bag, NID_localKeyID))) {
-        if (attrib->type != V_ASN1_OCTET_STRING)
-            return 0;
+    if ((attrib = PKCS12_SAFEBAG_get0_attr(bag, NID_localKeyID)))
         lkid = attrib->value.octet_string;
-    }
 
     switch (PKCS12_SAFEBAG_get_nid(bag)) {
     case NID_keyBag:
diff --git a/crypto/pkcs12/p12_local.h b/crypto/pkcs12/p12_local.h
index ef5866ad9b..34ffffb692 100644
--- a/crypto/pkcs12/p12_local.h
+++ b/crypto/pkcs12/p12_local.h
@@ -7,13 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_PKCS12_P12_LOCAL_H)
-#define OSSL_LIBCRYPTO_PKCS12_P12_LOCAL_H
-
-#include 
-#include 
-#include 
-
 struct PKCS12_MAC_DATA_st {
     X509_SIG *dinfo;
     ASN1_OCTET_STRING *salt;
@@ -50,5 +43,3 @@ struct pkcs12_bag_st {
 };
 
 const PKCS7_CTX *ossl_pkcs12_get0_pkcs7ctx(const PKCS12 *p12);
-
-#endif /* !defined(OSSL_LIBCRYPTO_PKCS12_P12_LOCAL_H) */
diff --git a/crypto/pkcs12/p12_mutl.c b/crypto/pkcs12/p12_mutl.c
index 60843bd951..f8d0bbd109 100644
--- a/crypto/pkcs12/p12_mutl.c
+++ b/crypto/pkcs12/p12_mutl.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -22,8 +22,6 @@
 #include 
 #include "p12_local.h"
 
-#include 
-
 static int pkcs12_pbmac1_pbkdf2_key_gen(const char *pass, int passlen,
     unsigned char *salt, int saltlen,
     int id, int iter, int keylen,
@@ -125,6 +123,8 @@ static int PBMAC1_PBKDF2_HMAC(OSSL_LIB_CTX *ctx, const char *propq,
         ERR_raise(ERR_LIB_PKCS12, ERR_R_UNSUPPORTED);
         goto err;
     }
+    keylen = ASN1_INTEGER_get(pbkdf2_param->keylength);
+    pbkdf2_salt = pbkdf2_param->salt->value.octet_string;
 
     if (pbkdf2_param->prf == NULL) {
         kdf_hmac_nid = NID_hmacWithSHA1;
@@ -139,24 +139,6 @@ static int PBMAC1_PBKDF2_HMAC(OSSL_LIB_CTX *ctx, const char *propq,
         goto err;
     }
 
-    /* Validate salt is an OCTET STRING choice */
-    if (pbkdf2_param->salt == NULL
-        || pbkdf2_param->salt->type != V_ASN1_OCTET_STRING) {
-        ERR_raise_data(ERR_LIB_PKCS12, PKCS12_R_PARSE_ERROR, "Invalid Salt");
-        goto err;
-    }
-    pbkdf2_salt = pbkdf2_param->salt->value.octet_string;
-
-    /* RFC 9879 specifies missing key length as invalid */
-    if (pbkdf2_param->keylength != NULL)
-        keylen = ASN1_INTEGER_get(pbkdf2_param->keylength);
-    /* RFC 9879 specifies too short key length as untrustworthy too */
-    if (keylen < 20 || keylen > EVP_MAX_MD_SIZE) {
-        ERR_raise_data(ERR_LIB_PKCS12, PKCS12_R_PARSE_ERROR,
-            "Invalid Key length (%d is not in the range 20..64)", keylen);
-        goto err;
-    }
-
     if (PKCS5_PBKDF2_HMAC(pass, passlen, pbkdf2_salt->data, pbkdf2_salt->length,
             ASN1_INTEGER_get(pbkdf2_param->iter), kdf_md, keylen, key)
         <= 0) {
@@ -185,7 +167,9 @@ static int pkcs12_gen_mac(PKCS12 *p12, const char *pass, int passlen,
         const char *propq))
 {
     int ret = 0;
-    EVP_MD *md;
+    const EVP_MD *md;
+    EVP_MD *md_fetch;
+    HMAC_CTX *hmac = NULL;
     unsigned char key[EVP_MAX_MD_SIZE], *salt;
     int saltlen, iter;
     char md_name[80];
@@ -195,7 +179,6 @@ static int pkcs12_gen_mac(PKCS12 *p12, const char *pass, int passlen,
     const ASN1_OBJECT *macoid;
     OSSL_LIB_CTX *libctx;
     const char *propq;
-    size_t md_sz, outlen;
 
     if (!PKCS7_type_is_data(p12->authsafes)) {
         ERR_raise(ERR_LIB_PKCS12, PKCS12_R_CONTENT_TYPE_NOT_DATA);
@@ -224,18 +207,22 @@ static int pkcs12_gen_mac(PKCS12 *p12, const char *pass, int passlen,
         if (OBJ_obj2txt(md_name, sizeof(md_name), macoid, 0) < 0)
             return 0;
     }
-    md = EVP_MD_fetch(libctx, md_name, propq);
+    (void)ERR_set_mark();
+    md = md_fetch = EVP_MD_fetch(libctx, md_name, propq);
+    if (md == NULL)
+        md = EVP_get_digestbynid(OBJ_obj2nid(macoid));
 
     if (md == NULL) {
+        (void)ERR_clear_last_mark();
         ERR_raise(ERR_LIB_PKCS12, PKCS12_R_UNKNOWN_DIGEST_ALGORITHM);
         return 0;
     }
+    (void)ERR_pop_to_mark();
 
     keylen = EVP_MD_get_size(md);
     md_nid = EVP_MD_get_type(md);
     if (keylen <= 0)
         goto err;
-    md_sz = keylen;
 
     /* For PBMAC1 we use a special keygen callback if not provided (e.g. on verification) */
     if (pbmac1_md_nid != NID_undef && pkcs12_key_gen == NULL) {
@@ -253,7 +240,7 @@ static int pkcs12_gen_mac(PKCS12 *p12, const char *pass, int passlen,
             goto err;
         }
     } else {
-        EVP_MD *hmac_md = md;
+        EVP_MD *hmac_md = (EVP_MD *)md;
         int fetched = 0;
 
         if (pbmac1_kdf_nid != NID_undef) {
@@ -287,18 +274,19 @@ static int pkcs12_gen_mac(PKCS12 *p12, const char *pass, int passlen,
             }
         }
     }
-    if (EVP_Q_mac(libctx, "HMAC", propq, md_name, NULL, key, keylen,
-            p12->authsafes->d.data->data, p12->authsafes->d.data->length,
-            mac, md_sz, &outlen)
-        == NULL)
+    if ((hmac = HMAC_CTX_new()) == NULL
+        || !HMAC_Init_ex(hmac, key, keylen, md, NULL)
+        || !HMAC_Update(hmac, p12->authsafes->d.data->data,
+            p12->authsafes->d.data->length)
+        || !HMAC_Final(hmac, mac, maclen)) {
         goto err;
-    if (outlen > UINT_MAX)
-        goto err;
-    *maclen = (unsigned int)outlen;
+    }
     ret = 1;
+
 err:
     OPENSSL_cleanse(key, sizeof(key));
-    EVP_MD_free(md);
+    HMAC_CTX_free(hmac);
+    EVP_MD_free(md_fetch);
     return ret;
 }
 
@@ -350,7 +338,7 @@ int PKCS12_verify_mac(PKCS12 *p12, const char *pass, int passlen)
         }
     }
     X509_SIG_get0(p12->mac->dinfo, NULL, &macoct);
-    if ((maclen != ASN1_STRING_length_ex(macoct))
+    if ((maclen != (unsigned int)ASN1_STRING_length(macoct))
         || CRYPTO_memcmp(mac, ASN1_STRING_get0_data(macoct), maclen) != 0)
         return 0;
 
@@ -530,8 +518,6 @@ int PKCS12_set_pbmac1_pbkdf2(PKCS12 *p12, const char *pass, int passlen,
     X509_ALGOR_free(param->messageAuthScheme);
     param->keyDerivationFunc = alg;
     param->messageAuthScheme = hmac_alg;
-    alg = NULL;
-    hmac_alg = NULL;
 
     X509_SIG_getm(p12->mac->dinfo, &macalg, &macoct);
     if (!ASN1_TYPE_pack_sequence(ASN1_ITEM_rptr(PBMAC1PARAM), param, &macalg->parameter))
@@ -553,8 +539,6 @@ int PKCS12_set_pbmac1_pbkdf2(PKCS12 *p12, const char *pass, int passlen,
     ret = 1;
 
 err:
-    X509_ALGOR_free(alg);
-    X509_ALGOR_free(hmac_alg);
     PBMAC1PARAM_free(param);
     OPENSSL_free(known_salt);
     return ret;
diff --git a/crypto/pkcs12/p12_npas.c b/crypto/pkcs12/p12_npas.c
index 44763e8668..db0c18c37b 100644
--- a/crypto/pkcs12/p12_npas.c
+++ b/crypto/pkcs12/p12_npas.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,8 +15,6 @@
 #include 
 #include "p12_local.h"
 
-#include 
-
 /* PKCS#12 password change routine */
 
 static int newpass_p12(PKCS12 *p12, const char *oldpass, const char *newpass);
diff --git a/crypto/pkcs12/p12_sbag.c b/crypto/pkcs12/p12_sbag.c
index 2bb7c6fa8b..4848daf2e9 100644
--- a/crypto/pkcs12/p12_sbag.c
+++ b/crypto/pkcs12/p12_sbag.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -14,7 +14,7 @@
 #include "crypto/x509.h"
 
 #ifndef OPENSSL_NO_DEPRECATED_1_1_0
-const ASN1_TYPE *PKCS12_get_attr(const PKCS12_SAFEBAG *bag, int attr_nid)
+ASN1_TYPE *PKCS12_get_attr(const PKCS12_SAFEBAG *bag, int attr_nid)
 {
     return PKCS12_get_attr_gen(bag->attrib, attr_nid);
 }
@@ -26,7 +26,7 @@ const ASN1_TYPE *PKCS12_SAFEBAG_get0_attr(const PKCS12_SAFEBAG *bag,
     return PKCS12_get_attr_gen(bag->attrib, attr_nid);
 }
 
-const ASN1_TYPE *PKCS8_get_attr(PKCS8_PRIV_KEY_INFO *p8, int attr_nid)
+ASN1_TYPE *PKCS8_get_attr(PKCS8_PRIV_KEY_INFO *p8, int attr_nid)
 {
     return PKCS12_get_attr_gen(PKCS8_pkey_get0_attrs(p8), attr_nid);
 }
@@ -252,11 +252,14 @@ PKCS12_SAFEBAG *PKCS12_SAFEBAG_create_pkcs8_encrypt_ex(int pbe_nid,
     const char *propq)
 {
     PKCS12_SAFEBAG *bag = NULL;
-    EVP_CIPHER *pbe_ciph = NULL;
+    const EVP_CIPHER *pbe_ciph = NULL;
+    EVP_CIPHER *pbe_ciph_fetch = NULL;
     X509_SIG *p8;
 
     ERR_set_mark();
-    pbe_ciph = EVP_CIPHER_fetch(ctx, OBJ_nid2sn(pbe_nid), propq);
+    pbe_ciph = pbe_ciph_fetch = EVP_CIPHER_fetch(ctx, OBJ_nid2sn(pbe_nid), propq);
+    if (pbe_ciph == NULL)
+        pbe_ciph = EVP_get_cipherbynid(pbe_nid);
     ERR_pop_to_mark();
 
     if (pbe_ciph != NULL)
@@ -272,7 +275,7 @@ PKCS12_SAFEBAG *PKCS12_SAFEBAG_create_pkcs8_encrypt_ex(int pbe_nid,
         X509_SIG_free(p8);
 
 err:
-    EVP_CIPHER_free(pbe_ciph);
+    EVP_CIPHER_free(pbe_ciph_fetch);
     return bag;
 }
 
diff --git a/crypto/pkcs12/p12_utl.c b/crypto/pkcs12/p12_utl.c
index 3c19f727a1..50adce6b26 100644
--- a/crypto/pkcs12/p12_utl.c
+++ b/crypto/pkcs12/p12_utl.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -12,7 +12,6 @@
 #include 
 #include "p12_local.h"
 #include "crypto/pkcs7/pk7_local.h"
-#include 
 
 /* Cheap and nasty Unicode stuff */
 
@@ -80,14 +79,13 @@ unsigned char *OPENSSL_utf82uni(const char *asc, int asclen,
 {
     int ulen, i, j;
     unsigned char *unitmp, *ret;
-    uint32_t utf32chr = 0;
+    unsigned long utf32chr = 0;
 
     if (asclen == -1)
         asclen = (int)strlen(asc);
 
     for (ulen = 0, i = 0; i < asclen; i += j) {
-        j = ossl_utf8_getc_internal((const unsigned char *)asc + i, asclen - i,
-            &utf32chr);
+        j = UTF8_getc((const unsigned char *)asc + i, asclen - i, &utf32chr);
 
         /*
          * Following condition is somewhat opportunistic is sense that
@@ -123,8 +121,7 @@ unsigned char *OPENSSL_utf82uni(const char *asc, int asclen,
         return NULL;
     /* re-run the loop writing down UTF-16 characters in big-endian order */
     for (unitmp = ret, i = 0; i < asclen; i += j) {
-        j = ossl_utf8_getc_internal((const unsigned char *)asc + i, asclen - i,
-            &utf32chr);
+        j = UTF8_getc((const unsigned char *)asc + i, asclen - i, &utf32chr);
         if (utf32chr >= 0x10000) { /* pair if UTF-16 characters */
             unsigned int hi, lo;
 
@@ -152,7 +149,7 @@ unsigned char *OPENSSL_utf82uni(const char *asc, int asclen,
 
 static int bmp_to_utf8(char *str, const unsigned char *utf16, int len)
 {
-    uint32_t utf32chr;
+    unsigned long utf32chr;
 
     if (len == 0)
         return 0;
@@ -178,8 +175,9 @@ static int bmp_to_utf8(char *str, const unsigned char *utf16, int len)
         utf32chr += 0x10000;
     }
 
-    return ossl_utf8_putc_internal((unsigned char *)str, 4, utf32chr);
+    return UTF8_putc((unsigned char *)str, len > 4 ? 4 : len, utf32chr);
 }
+
 char *OPENSSL_uni2utf8(const unsigned char *uni, int unilen)
 {
     int asclen, i, j;
@@ -188,8 +186,6 @@ char *OPENSSL_uni2utf8(const unsigned char *uni, int unilen)
     /* string must contain an even number of bytes */
     if (unilen & 1)
         return NULL;
-    if (unilen < 0)
-        return NULL;
 
     for (asclen = 0, i = 0; i < unilen;) {
         j = bmp_to_utf8(NULL, uni + i, unilen - i);
@@ -217,11 +213,6 @@ char *OPENSSL_uni2utf8(const unsigned char *uni, int unilen)
     /* re-run the loop emitting UTF-8 string */
     for (asclen = 0, i = 0; i < unilen;) {
         j = bmp_to_utf8(asctmp + asclen, uni + i, unilen - i);
-        /* when UTF8_putc fails */
-        if (j < 0) {
-            OPENSSL_free(asctmp);
-            return NULL;
-        }
         if (j == 4)
             i += 4;
         else
diff --git a/crypto/pkcs7/pk7_attr.c b/crypto/pkcs7/pk7_attr.c
index 28f073f36f..a1c09840e8 100644
--- a/crypto/pkcs7/pk7_attr.c
+++ b/crypto/pkcs7/pk7_attr.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -17,8 +17,6 @@
 #include 
 #include 
 
-#include 
-
 int PKCS7_add_attrib_smimecap(PKCS7_SIGNER_INFO *si,
     STACK_OF(X509_ALGOR) *cap)
 {
@@ -30,7 +28,7 @@ int PKCS7_add_attrib_smimecap(PKCS7_SIGNER_INFO *si,
     }
     seq->length = ASN1_item_i2d((ASN1_VALUE *)cap, &seq->data,
         ASN1_ITEM_rptr(X509_ALGORS));
-    if (ASN1_STRING_length_ex(seq) == 0 || ASN1_STRING_get0_data(seq) == NULL) {
+    if (seq->length <= 0 || seq->data == NULL) {
         ASN1_STRING_free(seq);
         return 1;
     }
@@ -44,19 +42,16 @@ int PKCS7_add_attrib_smimecap(PKCS7_SIGNER_INFO *si,
 
 STACK_OF(X509_ALGOR) *PKCS7_get_smimecap(PKCS7_SIGNER_INFO *si)
 {
-    const ASN1_TYPE *cap;
+    ASN1_TYPE *cap;
     const unsigned char *p;
-    size_t len;
 
     cap = PKCS7_get_signed_attribute(si, NID_SMIMECapabilities);
     if (cap == NULL || (cap->type != V_ASN1_SEQUENCE))
         return NULL;
-    p = ASN1_STRING_get0_data(cap->value.sequence);
-    len = ASN1_STRING_length_ex(cap->value.sequence);
-    if (len > INT_MAX)
-        return NULL;
+    p = cap->value.sequence->data;
     return (STACK_OF(X509_ALGOR) *)
-        ASN1_item_d2i(NULL, &p, (int)len, ASN1_ITEM_rptr(X509_ALGORS));
+        ASN1_item_d2i(NULL, &p, cap->value.sequence->length,
+            ASN1_ITEM_rptr(X509_ALGORS));
 }
 
 /* Basic smime-capabilities OID and optional integer arg */
@@ -132,7 +127,7 @@ int PKCS7_add1_attrib_digest(PKCS7_SIGNER_INFO *si,
     os = ASN1_OCTET_STRING_new();
     if (os == NULL)
         return 0;
-    if (!ASN1_STRING_set_data(os, md, mdlen)
+    if (!ASN1_STRING_set(os, md, mdlen)
         || !PKCS7_add_signed_attribute(si, NID_pkcs9_messageDigest,
             V_ASN1_OCTET_STRING, os)) {
         ASN1_OCTET_STRING_free(os);
diff --git a/crypto/pkcs7/pk7_doit.c b/crypto/pkcs7/pk7_doit.c
index 33d2eaafdf..02444d983c 100644
--- a/crypto/pkcs7/pk7_doit.c
+++ b/crypto/pkcs7/pk7_doit.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -18,11 +18,9 @@
 #include "crypto/evp.h"
 #include "pk7_local.h"
 
-#include 
-
 static int add_attribute(STACK_OF(X509_ATTRIBUTE) **sk, int nid, int atrtype,
     void *value);
-static const ASN1_TYPE *get_attribute(const STACK_OF(X509_ATTRIBUTE) *sk, int nid);
+static ASN1_TYPE *get_attribute(const STACK_OF(X509_ATTRIBUTE) *sk, int nid);
 
 int PKCS7_type_is_other(PKCS7 *p7)
 {
@@ -74,19 +72,16 @@ static ASN1_OCTET_STRING *pkcs7_get1_data(PKCS7 *p7)
     if (PKCS7_type_is_other(p7) && (p7->d.other != NULL)
         && (p7->d.other->type == V_ASN1_SEQUENCE)
         && (p7->d.other->value.sequence != NULL)
-        && (ASN1_STRING_length_ex(p7->d.other->value.sequence) > 0)) {
-        const unsigned char *data = ASN1_STRING_get0_data(p7->d.other->value.sequence);
+        && (p7->d.other->value.sequence->length > 0)) {
+        const unsigned char *data = p7->d.other->value.sequence->data;
         long len;
         int inf, tag, class;
-        size_t tmp;
 
-        tmp = ASN1_STRING_length_ex(p7->d.other->value.sequence);
-        if (tmp > INT_MAX)
-            return NULL;
         os = ASN1_OCTET_STRING_new();
         if (os == NULL)
             return NULL;
-        inf = ASN1_get_object(&data, &len, &tag, &class, (int)tmp);
+        inf = ASN1_get_object(&data, &len, &tag, &class,
+            p7->d.other->value.sequence->length);
         if (inf != V_ASN1_CONSTRUCTED || tag != V_ASN1_SEQUENCE
             || !ASN1_OCTET_STRING_set(os, data, len)) {
             ASN1_OCTET_STRING_free(os);
@@ -101,7 +96,8 @@ static int pkcs7_bio_add_digest(BIO **pbio, X509_ALGOR *alg,
 {
     BIO *btmp;
     char name[OSSL_MAX_NAME_SIZE];
-    EVP_MD *md = NULL;
+    EVP_MD *fetched = NULL;
+    const EVP_MD *md;
 
     if ((btmp = BIO_new(BIO_f_md())) == NULL) {
         ERR_raise(ERR_LIB_PKCS7, ERR_R_BIO_LIB);
@@ -110,20 +106,27 @@ static int pkcs7_bio_add_digest(BIO **pbio, X509_ALGOR *alg,
 
     OBJ_obj2txt(name, sizeof(name), alg->algorithm, 0);
 
-    md = EVP_MD_fetch(ossl_pkcs7_ctx_get0_libctx(ctx), name,
+    (void)ERR_set_mark();
+    fetched = EVP_MD_fetch(ossl_pkcs7_ctx_get0_libctx(ctx), name,
         ossl_pkcs7_ctx_get0_propq(ctx));
+    if (fetched != NULL)
+        md = fetched;
+    else
+        md = EVP_get_digestbyname(name);
 
     if (md == NULL) {
+        (void)ERR_clear_last_mark();
         ERR_raise(ERR_LIB_PKCS7, PKCS7_R_UNKNOWN_DIGEST_TYPE);
         goto err;
     }
+    (void)ERR_pop_to_mark();
 
     if (BIO_set_md(btmp, md) <= 0) {
         ERR_raise(ERR_LIB_PKCS7, ERR_R_BIO_LIB);
-        EVP_MD_free(md);
+        EVP_MD_free(fetched);
         goto err;
     }
-    EVP_MD_free(md);
+    EVP_MD_free(fetched);
     if (*pbio == NULL)
         *pbio = btmp;
     else if (!BIO_push(*pbio, btmp)) {
@@ -200,8 +203,15 @@ static int pkcs7_decrypt_rinfo(unsigned char **pek, int *peklen,
     if (EVP_PKEY_decrypt_init(pctx) <= 0)
         goto err;
 
+    if (EVP_PKEY_is_a(pkey, "RSA"))
+        /* upper layer pkcs7 code incorrectly assumes that a successful RSA
+         * decryption means that the key matches ciphertext (which never
+         * was the case, implicit rejection or not), so to make it work
+         * disable implicit rejection for RSA keys */
+        EVP_PKEY_CTX_ctrl_str(pctx, "rsa_pkcs1_implicit_rejection", "0");
+
     ret = evp_pkey_decrypt_alloc(pctx, &ek, &eklen, fixlen,
-        ASN1_STRING_get0_data(ri->enc_key), ASN1_STRING_length_ex(ri->enc_key));
+        ri->enc_key->data, ri->enc_key->length);
     if (ret <= 0)
         goto err;
 
@@ -374,7 +384,7 @@ BIO *PKCS7_dataInit(PKCS7 *p7, BIO *bio)
     if (bio == NULL) {
         if (PKCS7_is_detached(p7)) {
             bio = BIO_new(BIO_s_null());
-        } else if (os != NULL && ASN1_STRING_length_ex(os) > 0) {
+        } else if (os != NULL && os->length > 0) {
             /*
              * bio needs a copy of os->data instead of a pointer because
              * the data will be used after os has been freed
@@ -382,9 +392,7 @@ BIO *PKCS7_dataInit(PKCS7 *p7, BIO *bio)
             bio = BIO_new(BIO_s_mem());
             if (bio != NULL) {
                 BIO_set_mem_eof_return(bio, 0);
-                const unsigned char *os_data = ASN1_STRING_get0_data(os);
-                size_t os_len = ASN1_STRING_length_ex(os);
-                if (os_len > INT_MAX || BIO_write(bio, os_data, (int)os_len) != (int)os_len) {
+                if (BIO_write(bio, os->data, os->length) != os->length) {
                     BIO_free_all(bio);
                     bio = NULL;
                 }
@@ -432,8 +440,10 @@ BIO *PKCS7_dataDecode(PKCS7 *p7, EVP_PKEY *pkey, BIO *in_bio, X509 *pcert)
     BIO *out = NULL, *btmp = NULL, *etmp = NULL, *bio = NULL;
     X509_ALGOR *xa;
     ASN1_OCTET_STRING *data_body = NULL;
-    EVP_MD *md = NULL;
-    EVP_CIPHER *cipher = NULL;
+    EVP_MD *evp_md = NULL;
+    const EVP_MD *md;
+    EVP_CIPHER *evp_cipher = NULL;
+    const EVP_CIPHER *cipher = NULL;
     EVP_CIPHER_CTX *evp_ctx = NULL;
     X509_ALGOR *enc_alg = NULL;
     STACK_OF(X509_ALGOR) *md_sk = NULL;
@@ -487,12 +497,19 @@ BIO *PKCS7_dataDecode(PKCS7 *p7, EVP_PKEY *pkey, BIO *in_bio, X509 *pcert)
 
         OBJ_obj2txt(name, sizeof(name), enc_alg->algorithm, 0);
 
-        cipher = EVP_CIPHER_fetch(libctx, name, propq);
+        (void)ERR_set_mark();
+        evp_cipher = EVP_CIPHER_fetch(libctx, name, propq);
+        if (evp_cipher != NULL)
+            cipher = evp_cipher;
+        else
+            cipher = EVP_get_cipherbyname(name);
 
         if (cipher == NULL) {
+            (void)ERR_clear_last_mark();
             ERR_raise(ERR_LIB_PKCS7, PKCS7_R_UNSUPPORTED_CIPHER_TYPE);
             goto err;
         }
+        (void)ERR_pop_to_mark();
         break;
     case NID_pkcs7_enveloped:
         rsk = p7->d.enveloped->recipientinfo;
@@ -501,12 +518,19 @@ BIO *PKCS7_dataDecode(PKCS7 *p7, EVP_PKEY *pkey, BIO *in_bio, X509 *pcert)
         data_body = p7->d.enveloped->enc_data->enc_data;
         OBJ_obj2txt(name, sizeof(name), enc_alg->algorithm, 0);
 
-        cipher = EVP_CIPHER_fetch(libctx, name, propq);
+        (void)ERR_set_mark();
+        evp_cipher = EVP_CIPHER_fetch(libctx, name, propq);
+        if (evp_cipher != NULL)
+            cipher = evp_cipher;
+        else
+            cipher = EVP_get_cipherbyname(name);
 
         if (cipher == NULL) {
+            (void)ERR_clear_last_mark();
             ERR_raise(ERR_LIB_PKCS7, PKCS7_R_UNSUPPORTED_CIPHER_TYPE);
             goto err;
         }
+        (void)ERR_pop_to_mark();
         break;
     default:
         ERR_raise(ERR_LIB_PKCS7, PKCS7_R_UNSUPPORTED_CONTENT_TYPE);
@@ -530,19 +554,26 @@ BIO *PKCS7_dataDecode(PKCS7 *p7, EVP_PKEY *pkey, BIO *in_bio, X509 *pcert)
 
             OBJ_obj2txt(name, sizeof(name), xa->algorithm, 0);
 
-            md = EVP_MD_fetch(libctx, name, propq);
+            (void)ERR_set_mark();
+            evp_md = EVP_MD_fetch(libctx, name, propq);
+            if (evp_md != NULL)
+                md = evp_md;
+            else
+                md = EVP_get_digestbyname(name);
 
             if (md == NULL) {
+                (void)ERR_clear_last_mark();
                 ERR_raise(ERR_LIB_PKCS7, PKCS7_R_UNKNOWN_DIGEST_TYPE);
                 goto err;
             }
+            (void)ERR_pop_to_mark();
 
             if (BIO_set_md(btmp, md) <= 0) {
-                EVP_MD_free(md);
+                EVP_MD_free(evp_md);
                 ERR_raise(ERR_LIB_PKCS7, ERR_R_BIO_LIB);
                 goto err;
             }
-            EVP_MD_free(md);
+            EVP_MD_free(evp_md);
             if (out == NULL)
                 out = btmp;
             else
@@ -659,12 +690,8 @@ BIO *PKCS7_dataDecode(PKCS7 *p7, EVP_PKEY *pkey, BIO *in_bio, X509 *pcert)
     if (in_bio != NULL) {
         bio = in_bio;
     } else {
-        size_t data_body_len = ASN1_STRING_length_ex(data_body);
-        if (data_body_len > INT_MAX)
-            goto err;
-        if (data_body_len > 0)
-            bio = BIO_new_mem_buf(ASN1_STRING_get0_data(data_body),
-                (int)data_body_len);
+        if (data_body->length > 0)
+            bio = BIO_new_mem_buf(data_body->data, data_body->length);
         else {
             bio = BIO_new(BIO_s_mem());
             if (bio == NULL)
@@ -676,11 +703,11 @@ BIO *PKCS7_dataDecode(PKCS7 *p7, EVP_PKEY *pkey, BIO *in_bio, X509 *pcert)
     }
     BIO_push(out, bio);
     bio = NULL;
-    EVP_CIPHER_free(cipher);
+    EVP_CIPHER_free(evp_cipher);
     return out;
 
 err:
-    EVP_CIPHER_free(cipher);
+    EVP_CIPHER_free(evp_cipher);
     OPENSSL_clear_free(ek, eklen);
     OPENSSL_clear_free(tkey, tkeylen);
     BIO_free_all(out);
@@ -804,10 +831,6 @@ int PKCS7_dataFinal(PKCS7 *p7, BIO *bio)
         break;
     case NID_pkcs7_signed:
         si_sk = p7->d.sign->signer_info;
-        if (p7->d.sign->contents == NULL) {
-            ERR_raise(ERR_LIB_PKCS7, PKCS7_R_NO_CONTENT);
-            goto err;
-        }
         os = PKCS7_get_octet_string(p7->d.sign->contents);
         /* If detached data then the content is excluded */
         if (PKCS7_type_is_data(p7->d.sign->contents) && p7->detached) {
@@ -818,10 +841,6 @@ int PKCS7_dataFinal(PKCS7 *p7, BIO *bio)
         break;
 
     case NID_pkcs7_digest:
-        if (p7->d.digest->contents == NULL) {
-            ERR_raise(ERR_LIB_PKCS7, PKCS7_R_NO_CONTENT);
-            goto err;
-        }
         os = PKCS7_get_octet_string(p7->d.digest->contents);
         /* If detached data then the content is excluded */
         if (PKCS7_type_is_data(p7->d.digest->contents) && p7->detached) {
@@ -1036,19 +1055,18 @@ int PKCS7_dataVerify(X509_STORE *cert_store, X509_STORE_CTX *ctx, BIO *bio,
         goto err;
     }
 
-    if (PKCS7_signatureVerify(bio, p7, si, signer) <= 0)
-        goto err;
-    ret = 1;
+    return PKCS7_signatureVerify(bio, p7, si, signer);
 err:
     return ret;
 }
 
 int PKCS7_signatureVerify(BIO *bio, PKCS7 *p7, PKCS7_SIGNER_INFO *si,
-    const X509 *signer)
+    X509 *signer)
 {
     ASN1_OCTET_STRING *os;
     EVP_MD_CTX *mdc_tmp, *mdc;
-    EVP_MD *md = NULL;
+    const EVP_MD *md;
+    EVP_MD *fetched_md = NULL;
     int ret = 0, i;
     int md_type;
     STACK_OF(X509_ATTRIBUTE) *sk;
@@ -1106,7 +1124,7 @@ int PKCS7_signatureVerify(BIO *bio, PKCS7 *p7, PKCS7_SIGNER_INFO *si,
         unsigned char md_dat[EVP_MAX_MD_SIZE];
         unsigned int md_len;
         int alen;
-        const ASN1_OCTET_STRING *message_digest;
+        ASN1_OCTET_STRING *message_digest;
 
         if (!EVP_DigestFinal_ex(mdc_tmp, md_dat, &md_len))
             goto err;
@@ -1115,18 +1133,25 @@ int PKCS7_signatureVerify(BIO *bio, PKCS7 *p7, PKCS7_SIGNER_INFO *si,
             ERR_raise(ERR_LIB_PKCS7, PKCS7_R_UNABLE_TO_FIND_MESSAGE_DIGEST);
             goto err;
         }
-        if ((ASN1_STRING_length_ex(message_digest) != md_len)
-            || (memcmp(ASN1_STRING_get0_data(message_digest), md_dat, md_len))) {
+        if ((message_digest->length != (int)md_len) || (memcmp(message_digest->data, md_dat, md_len))) {
             ERR_raise(ERR_LIB_PKCS7, PKCS7_R_DIGEST_FAILURE);
             ret = -1;
             goto err;
         }
 
-        md = EVP_MD_fetch(libctx, OBJ_nid2sn(md_type), propq);
+        (void)ERR_set_mark();
+        fetched_md = EVP_MD_fetch(libctx, OBJ_nid2sn(md_type), propq);
+
+        if (fetched_md != NULL)
+            md = fetched_md;
+        else
+            md = EVP_get_digestbynid(md_type);
 
         if (md == NULL || !EVP_VerifyInit_ex(mdc_tmp, md, NULL)) {
+            (void)ERR_clear_last_mark();
             goto err;
         }
+        (void)ERR_pop_to_mark();
 
         alen = ASN1_item_i2d((ASN1_VALUE *)sk, &abuf,
             ASN1_ITEM_rptr(PKCS7_ATTR_VERIFY));
@@ -1146,13 +1171,7 @@ int PKCS7_signatureVerify(BIO *bio, PKCS7 *p7, PKCS7_SIGNER_INFO *si,
         goto err;
     }
 
-    const unsigned char *sig_data = ASN1_STRING_get0_data(os);
-    size_t sig_len = ASN1_STRING_length_ex(os);
-    if (sig_len > INT_MAX) {
-        ret = -1;
-        goto err;
-    }
-    i = EVP_VerifyFinal_ex(mdc_tmp, sig_data, (int)sig_len, pkey, libctx, propq);
+    i = EVP_VerifyFinal_ex(mdc_tmp, os->data, os->length, pkey, libctx, propq);
     if (i <= 0) {
         ERR_raise(ERR_LIB_PKCS7, PKCS7_R_SIGNATURE_FAILURE);
         ret = -1;
@@ -1162,7 +1181,7 @@ int PKCS7_signatureVerify(BIO *bio, PKCS7 *p7, PKCS7_SIGNER_INFO *si,
 err:
     OPENSSL_free(abuf);
     EVP_MD_CTX_free(mdc_tmp);
-    EVP_MD_free(md);
+    EVP_MD_free(fetched_md);
     return ret;
 }
 
@@ -1180,23 +1199,23 @@ PKCS7_ISSUER_AND_SERIAL *PKCS7_get_issuer_and_serial(PKCS7 *p7, int idx)
     rsk = p7->d.signed_and_enveloped->recipientinfo;
     if (rsk == NULL)
         return NULL;
-    if (idx < 0 || sk_PKCS7_RECIP_INFO_num(rsk) <= idx)
+    if (sk_PKCS7_RECIP_INFO_num(rsk) <= idx)
         return NULL;
     ri = sk_PKCS7_RECIP_INFO_value(rsk, idx);
     return ri->issuer_and_serial;
 }
 
-const ASN1_TYPE *PKCS7_get_signed_attribute(const PKCS7_SIGNER_INFO *si, int nid)
+ASN1_TYPE *PKCS7_get_signed_attribute(const PKCS7_SIGNER_INFO *si, int nid)
 {
     return get_attribute(si->auth_attr, nid);
 }
 
-const ASN1_TYPE *PKCS7_get_attribute(const PKCS7_SIGNER_INFO *si, int nid)
+ASN1_TYPE *PKCS7_get_attribute(const PKCS7_SIGNER_INFO *si, int nid)
 {
     return get_attribute(si->unauth_attr, nid);
 }
 
-static const ASN1_TYPE *get_attribute(const STACK_OF(X509_ATTRIBUTE) *sk, int nid)
+static ASN1_TYPE *get_attribute(const STACK_OF(X509_ATTRIBUTE) *sk, int nid)
 {
     int idx = X509at_get_attr_by_NID(sk, nid, -1);
 
@@ -1205,13 +1224,11 @@ static const ASN1_TYPE *get_attribute(const STACK_OF(X509_ATTRIBUTE) *sk, int ni
     return X509_ATTRIBUTE_get0_type(X509at_get_attr(sk, idx), 0);
 }
 
-const ASN1_OCTET_STRING *PKCS7_digest_from_attributes(STACK_OF(X509_ATTRIBUTE) *sk)
+ASN1_OCTET_STRING *PKCS7_digest_from_attributes(STACK_OF(X509_ATTRIBUTE) *sk)
 {
-    const ASN1_TYPE *astype;
+    ASN1_TYPE *astype;
     if ((astype = get_attribute(sk, NID_pkcs9_messageDigest)) == NULL)
         return NULL;
-    if (astype->type != V_ASN1_OCTET_STRING)
-        return NULL;
     return astype->value.octet_string;
 }
 
diff --git a/crypto/pkcs7/pk7_lib.c b/crypto/pkcs7/pk7_lib.c
index a9640769cf..675c694e66 100644
--- a/crypto/pkcs7/pk7_lib.c
+++ b/crypto/pkcs7/pk7_lib.c
@@ -48,8 +48,7 @@ long PKCS7_ctrl(PKCS7 *p7, int cmd, long larg, char *parg)
         break;
     case PKCS7_OP_GET_DETACHED_SIGNATURE:
         if (nid == NID_pkcs7_signed) {
-            if (p7->d.sign == NULL || p7->d.sign->contents == NULL
-                || p7->d.sign->contents->d.ptr == NULL)
+            if (p7->d.sign == NULL || p7->d.sign->contents->d.ptr == NULL)
                 ret = 1;
             else
                 ret = 0;
@@ -537,7 +536,7 @@ int PKCS7_set_digest(PKCS7 *p7, const EVP_MD *md)
     }
 
     ERR_raise(ERR_LIB_PKCS7, PKCS7_R_WRONG_CONTENT_TYPE);
-    return 0;
+    return 1;
 }
 
 STACK_OF(PKCS7_SIGNER_INFO) *PKCS7_get_signer_info(PKCS7 *p7)
@@ -743,10 +742,6 @@ int PKCS7_stream(unsigned char ***boundary, PKCS7 *p7)
         break;
 
     case NID_pkcs7_signed:
-        if (p7->d.sign == NULL || p7->d.sign->contents == NULL) {
-            ERR_raise(ERR_LIB_PKCS7, PKCS7_R_NO_CONTENT);
-            break;
-        }
         os = p7->d.sign->contents->d.data;
         break;
 
diff --git a/crypto/pkcs7/pk7_local.h b/crypto/pkcs7/pk7_local.h
index 2155b7b56f..79f909f3dd 100644
--- a/crypto/pkcs7/pk7_local.h
+++ b/crypto/pkcs7/pk7_local.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_PKCS7_PK7_LOCAL_H)
-#define OSSL_LIBCRYPTO_PKCS7_PK7_LOCAL_H
-
 #include "crypto/pkcs7.h"
 
 STACK_OF(X509) *pkcs7_get0_certificates(const PKCS7 *p7);
@@ -18,5 +15,3 @@ OSSL_LIB_CTX *ossl_pkcs7_ctx_get0_libctx(const PKCS7_CTX *ctx);
 const char *ossl_pkcs7_ctx_get0_propq(const PKCS7_CTX *ctx);
 
 int ossl_pkcs7_ctx_propagate(const PKCS7 *from, PKCS7 *to);
-
-#endif /* !defined(OSSL_LIBCRYPTO_PKCS7_PK7_LOCAL_H) */
diff --git a/crypto/pkcs7/pk7_smime.c b/crypto/pkcs7/pk7_smime.c
index 7ede4b6694..97f2005897 100644
--- a/crypto/pkcs7/pk7_smime.c
+++ b/crypto/pkcs7/pk7_smime.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -20,8 +20,9 @@
 
 static int pkcs7_copy_existing_digest(PKCS7 *p7, PKCS7_SIGNER_INFO *si);
 
-PKCS7 *PKCS7_sign_ex(X509 *signcert, EVP_PKEY *pkey, const STACK_OF(X509) *certs,
-    BIO *data, int flags, OSSL_LIB_CTX *libctx, const char *propq)
+PKCS7 *PKCS7_sign_ex(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs,
+    BIO *data, int flags, OSSL_LIB_CTX *libctx,
+    const char *propq)
 {
     PKCS7 *p7;
     int i;
@@ -63,7 +64,7 @@ err:
     return NULL;
 }
 
-PKCS7 *PKCS7_sign(X509 *signcert, EVP_PKEY *pkey, const STACK_OF(X509) *certs,
+PKCS7 *PKCS7_sign(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs,
     BIO *data, int flags)
 {
     return PKCS7_sign_ex(signcert, pkey, certs, data, flags, NULL, NULL);
@@ -185,7 +186,7 @@ static int pkcs7_copy_existing_digest(PKCS7 *p7, PKCS7_SIGNER_INFO *si)
     int i;
     STACK_OF(PKCS7_SIGNER_INFO) *sinfos;
     PKCS7_SIGNER_INFO *sitmp;
-    const ASN1_OCTET_STRING *osdig = NULL;
+    ASN1_OCTET_STRING *osdig = NULL;
     sinfos = PKCS7_get_signer_info(p7);
     for (i = 0; i < sk_PKCS7_SIGNER_INFO_num(sinfos); i++) {
         sitmp = sk_PKCS7_SIGNER_INFO_value(sinfos, i);
@@ -199,21 +200,15 @@ static int pkcs7_copy_existing_digest(PKCS7 *p7, PKCS7_SIGNER_INFO *si)
         }
     }
 
-    if (osdig != NULL) {
-        size_t len;
-        len = ASN1_STRING_length_ex(osdig);
-        if (len > INT_MAX)
-            goto err;
-        return PKCS7_add1_attrib_digest(si, ASN1_STRING_get0_data(osdig), (int)len);
-    }
+    if (osdig != NULL)
+        return PKCS7_add1_attrib_digest(si, osdig->data, osdig->length);
 
-err:
     ERR_raise(ERR_LIB_PKCS7, PKCS7_R_NO_MATCHING_DIGEST_TYPE_FOUND);
     return 0;
 }
 
 /* This strongly overlaps with CMS_verify(), partly with PKCS7_dataVerify() */
-int PKCS7_verify(PKCS7 *p7, const STACK_OF(X509) *certs, X509_STORE *store,
+int PKCS7_verify(PKCS7 *p7, STACK_OF(X509) *certs, X509_STORE *store,
     BIO *indata, BIO *out, int flags)
 {
     STACK_OF(X509) *signers;
@@ -227,7 +222,6 @@ int PKCS7_verify(PKCS7 *p7, const STACK_OF(X509) *certs, X509_STORE *store,
     int i, j = 0, k, ret = 0;
     BIO *p7bio = NULL;
     BIO *tmpout = NULL;
-    BIO *next = NULL;
     const PKCS7_CTX *p7_ctx;
 
     if (p7 == NULL) {
@@ -358,17 +352,16 @@ err:
         BIO_free(tmpout);
     X509_STORE_CTX_free(cert_ctx);
     OPENSSL_free(buf);
-    while (p7bio != NULL && p7bio != indata) {
-        next = BIO_pop(p7bio);
-        BIO_free(p7bio);
-        p7bio = next;
-    }
+    if (indata != NULL)
+        BIO_pop(p7bio);
+    BIO_free_all(p7bio);
     sk_X509_free(signers);
     sk_X509_free(untrusted);
     return ret;
 }
 
-STACK_OF(X509) *PKCS7_get0_signers(PKCS7 *p7, const STACK_OF(X509) *certs, int flags)
+STACK_OF(X509) *PKCS7_get0_signers(PKCS7 *p7, STACK_OF(X509) *certs,
+    int flags)
 {
     STACK_OF(X509) *signers, *included_certs;
     STACK_OF(PKCS7_SIGNER_INFO) *sinfos;
@@ -428,7 +421,7 @@ STACK_OF(X509) *PKCS7_get0_signers(PKCS7 *p7, const STACK_OF(X509) *certs, int f
 
 /* Build a complete PKCS#7 enveloped data */
 
-PKCS7 *PKCS7_encrypt_ex(const STACK_OF(X509) *certs, BIO *in,
+PKCS7 *PKCS7_encrypt_ex(STACK_OF(X509) *certs, BIO *in,
     const EVP_CIPHER *cipher, int flags,
     OSSL_LIB_CTX *libctx, const char *propq)
 {
@@ -470,7 +463,8 @@ err:
     return NULL;
 }
 
-PKCS7 *PKCS7_encrypt(const STACK_OF(X509) *certs, BIO *in, const EVP_CIPHER *cipher, int flags)
+PKCS7 *PKCS7_encrypt(STACK_OF(X509) *certs, BIO *in, const EVP_CIPHER *cipher,
+    int flags)
 {
     return PKCS7_encrypt_ex(certs, in, cipher, flags, NULL, NULL);
 }
diff --git a/crypto/poly1305/asm/poly1305-armv4.pl b/crypto/poly1305/asm/poly1305-armv4.pl
index 31500feed2..05751238fe 100755
--- a/crypto/poly1305/asm/poly1305-armv4.pl
+++ b/crypto/poly1305/asm/poly1305-armv4.pl
@@ -48,7 +48,7 @@ if ($flavour && $flavour ne "void") {
 ($ctx,$inp,$len,$padbit)=map("r$_",(0..3));
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 #if defined(__thumb2__)
 .syntax	unified
diff --git a/crypto/poly1305/asm/poly1305-armv8.pl b/crypto/poly1305/asm/poly1305-armv8.pl
index 17bf15d781..6659cd631f 100755
--- a/crypto/poly1305/asm/poly1305-armv8.pl
+++ b/crypto/poly1305/asm/poly1305-armv8.pl
@@ -55,7 +55,7 @@ my ($mac,$nonce)=($inp,$len);
 my ($h0,$h1,$h2,$r0,$r1,$s1,$t0,$t1,$d0,$d1,$d2) = map("x$_",(4..14));
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 .text
 
diff --git a/crypto/poly1305/asm/poly1305-armv9-sve2.pl b/crypto/poly1305/asm/poly1305-armv9-sve2.pl
index 7f957f0188..b68741fe58 100755
--- a/crypto/poly1305/asm/poly1305-armv9-sve2.pl
+++ b/crypto/poly1305/asm/poly1305-armv9-sve2.pl
@@ -104,7 +104,7 @@ my ($pwr,$mask) = map("x$_",(25..26));
 my $is_base2_26 = "w17";
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 .text
 
diff --git a/crypto/poly1305/asm/poly1305-mips.pl b/crypto/poly1305/asm/poly1305-mips.pl
index 7ecf285520..a41def668c 100755
--- a/crypto/poly1305/asm/poly1305-mips.pl
+++ b/crypto/poly1305/asm/poly1305-mips.pl
@@ -71,7 +71,7 @@ $SAVED_REGS_MASK = ($flavour =~ /nubi/i) ? "0x0003f000" : "0x00030000";
 ($in0,$in1,$tmp0,$tmp1,$tmp2,$tmp3,$tmp4) = ($a4,$a5,$a6,$a7,$at,$t0,$t1);
 
 $code.=<<___;
-#include "arch/mips_arch.h"
+#include "mips_arch.h"
 
 #ifdef MIPSEB
 # define MSB 0
diff --git a/crypto/poly1305/asm/poly1305-s390x.pl b/crypto/poly1305/asm/poly1305-s390x.pl
index 34e4f5cf2d..8f3f97a1cf 100755
--- a/crypto/poly1305/asm/poly1305-s390x.pl
+++ b/crypto/poly1305/asm/poly1305-s390x.pl
@@ -68,7 +68,7 @@ my ($ctx,$inp,$len,$padbit) = map("%r$_",(2..5));
 
 PERLASM_BEGIN($output);
 
-INCLUDE	("arch/s390x_arch.h");
+INCLUDE	("s390x_arch.h");
 TEXT	();
 
 ################
diff --git a/crypto/poly1305/asm/poly1305-sparcv9.pl b/crypto/poly1305/asm/poly1305-sparcv9.pl
index 62ab114acb..a3282a8058 100755
--- a/crypto/poly1305/asm/poly1305-sparcv9.pl
+++ b/crypto/poly1305/asm/poly1305-sparcv9.pl
@@ -55,7 +55,7 @@ $code.=<<___;
 #ifndef __ASSEMBLER__
 # define __ASSEMBLER__ 1
 #endif
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 #ifdef	__arch64__
 .register	%g2,#scratch
diff --git a/crypto/poly1305/asm/poly1305-x86.pl b/crypto/poly1305/asm/poly1305-x86.pl
index 42e575516e..7a81cd7584 100755
--- a/crypto/poly1305/asm/poly1305-x86.pl
+++ b/crypto/poly1305/asm/poly1305-x86.pl
@@ -73,13 +73,6 @@ if ($sse2) {
 	if (!$avx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|based on LLVM) ([0-9]+\.[0-9]+)/) {
 		$avx = ($2>=3.0) + ($2>3.0);
 	}
-
-	if (!$avx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-		=~ /#define __clang_major__.([0-9]+)/) {
-		if ($1) {
-			$avx = ($1>=11); #icx started with clang 11
-		}
-	}
 }
 
 ########################################################################
diff --git a/crypto/poly1305/asm/poly1305-x86_64.pl b/crypto/poly1305/asm/poly1305-x86_64.pl
index a70ec0f952..04c6da3c61 100755
--- a/crypto/poly1305/asm/poly1305-x86_64.pl
+++ b/crypto/poly1305/asm/poly1305-x86_64.pl
@@ -95,13 +95,6 @@ if (!$avx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([0
 	$avx = ($2>=3.0) + ($2>3.0);
 }
 
-if (!$avx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$avx = ($1>=11); #icx started with clang 11
-	}
-}
-
 open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\""
     or die "can't call $xlate: $!";
 *STDOUT=*OUT;
diff --git a/crypto/poly1305/poly1305.c b/crypto/poly1305/poly1305.c
index 09167cb9d4..656dee783c 100644
--- a/crypto/poly1305/poly1305.c
+++ b/crypto/poly1305/poly1305.c
@@ -7,7 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include 
 #include 
 #include 
 #include 
@@ -61,6 +60,8 @@ static unsigned int U8TOU32(const unsigned char *p)
  *                                              
  */
 
+typedef unsigned int u32;
+
 /*
  * poly1305_blocks processes a multiple of POLY1305_BLOCK_SIZE blocks
  * of |inp| no longer than |len|. Behaviour for |len| not divisible by
@@ -81,7 +82,7 @@ static unsigned int U8TOU32(const unsigned char *p)
  *      handled locally.
  */
 static void
-poly1305_blocks(void *ctx, const unsigned char *inp, size_t len, uint32_t padbit);
+poly1305_blocks(void *ctx, const unsigned char *inp, size_t len, u32 padbit);
 
 /*
  * Type-agnostic "rip-off" from constant_time.h
@@ -91,21 +92,22 @@ poly1305_blocks(void *ctx, const unsigned char *inp, size_t len, uint32_t padbit
 
 #if defined(INT64_MAX) && defined(INT128_MAX)
 
+typedef unsigned long u64;
 typedef uint128_t u128;
 
 typedef struct {
-    uint64_t h[3];
-    uint64_t r[2];
+    u64 h[3];
+    u64 r[2];
 } poly1305_internal;
 
 /* pick 32-bit unsigned integer in little endian order */
-static uint64_t U8TOU64(const unsigned char *p)
+static u64 U8TOU64(const unsigned char *p)
 {
-    return (((uint64_t)(p[0] & 0xff)) | ((uint64_t)(p[1] & 0xff) << 8) | ((uint64_t)(p[2] & 0xff) << 16) | ((uint64_t)(p[3] & 0xff) << 24) | ((uint64_t)(p[4] & 0xff) << 32) | ((uint64_t)(p[5] & 0xff) << 40) | ((uint64_t)(p[6] & 0xff) << 48) | ((uint64_t)(p[7] & 0xff) << 56));
+    return (((u64)(p[0] & 0xff)) | ((u64)(p[1] & 0xff) << 8) | ((u64)(p[2] & 0xff) << 16) | ((u64)(p[3] & 0xff) << 24) | ((u64)(p[4] & 0xff) << 32) | ((u64)(p[5] & 0xff) << 40) | ((u64)(p[6] & 0xff) << 48) | ((u64)(p[7] & 0xff) << 56));
 }
 
 /* store a 32-bit unsigned integer in little endian */
-static void U64TO8(unsigned char *p, uint64_t v)
+static void U64TO8(unsigned char *p, u64 v)
 {
     p[0] = (unsigned char)((v) & 0xff);
     p[1] = (unsigned char)((v >> 8) & 0xff);
@@ -132,12 +134,12 @@ static void poly1305_init(void *ctx, const unsigned char key[16])
 }
 
 static void
-poly1305_blocks(void *ctx, const unsigned char *inp, size_t len, uint32_t padbit)
+poly1305_blocks(void *ctx, const unsigned char *inp, size_t len, u32 padbit)
 {
     poly1305_internal *st = (poly1305_internal *)ctx;
-    uint64_t r0, r1;
-    uint64_t s1;
-    uint64_t h0, h1, h2, c;
+    u64 r0, r1;
+    u64 s1;
+    u64 h0, h1, h2, c;
     u128 d0, d1;
 
     r0 = st->r[0];
@@ -151,13 +153,13 @@ poly1305_blocks(void *ctx, const unsigned char *inp, size_t len, uint32_t padbit
 
     while (len >= POLY1305_BLOCK_SIZE) {
         /* h += m[i] */
-        h0 = (uint64_t)(d0 = (u128)h0 + U8TOU64(inp + 0));
-        h1 = (uint64_t)(d1 = (u128)h1 + (d0 >> 64) + U8TOU64(inp + 8));
+        h0 = (u64)(d0 = (u128)h0 + U8TOU64(inp + 0));
+        h1 = (u64)(d1 = (u128)h1 + (d0 >> 64) + U8TOU64(inp + 8));
         /*
          * padbit can be zero only when original len was
          * POLY1305_BLOCK_SIZE, but we don't check
          */
-        h2 += (uint64_t)(d1 >> 64) + padbit;
+        h2 += (u64)(d1 >> 64) + padbit;
 
         /* h *= r "%" p, where "%" stands for "partial remainder" */
         d0 = ((u128)h0 * r0) + ((u128)h1 * s1);
@@ -166,9 +168,9 @@ poly1305_blocks(void *ctx, const unsigned char *inp, size_t len, uint32_t padbit
 
         /* last reduction step: */
         /* a) h2:h0 = h2<<128 + d1<<64 + d0 */
-        h0 = (uint64_t)d0;
-        h1 = (uint64_t)(d1 += d0 >> 64);
-        h2 += (uint64_t)(d1 >> 64);
+        h0 = (u64)d0;
+        h1 = (u64)(d1 += d0 >> 64);
+        h2 += (u64)(d1 >> 64);
         /* b) (h2:h0 += (h2:h0>>130) * 5) %= 2^130 */
         c = (h2 >> 2) + (h2 & ~3UL);
         h2 &= 3;
@@ -195,22 +197,22 @@ poly1305_blocks(void *ctx, const unsigned char *inp, size_t len, uint32_t padbit
 }
 
 static void poly1305_emit(void *ctx, unsigned char mac[16],
-    const uint32_t nonce[4])
+    const u32 nonce[4])
 {
     poly1305_internal *st = (poly1305_internal *)ctx;
-    uint64_t h0, h1, h2;
-    uint64_t g0, g1, g2;
+    u64 h0, h1, h2;
+    u64 g0, g1, g2;
     u128 t;
-    uint64_t mask;
+    u64 mask;
 
     h0 = st->h[0];
     h1 = st->h[1];
     h2 = st->h[2];
 
     /* compare to modulus by computing h + -p */
-    g0 = (uint64_t)(t = (u128)h0 + 5);
-    g1 = (uint64_t)(t = (u128)h1 + (t >> 64));
-    g2 = h2 + (uint64_t)(t >> 64);
+    g0 = (u64)(t = (u128)h0 + 5);
+    g1 = (u64)(t = (u128)h1 + (t >> 64));
+    g2 = h2 + (u64)(t >> 64);
 
     /* if there was carry into 131st bit, h1:h0 = g1:g0 */
     mask = 0 - (g2 >> 2);
@@ -221,8 +223,8 @@ static void poly1305_emit(void *ctx, unsigned char mac[16],
     h1 = (h1 & mask) | g1;
 
     /* mac = (h + nonce) % (2^128) */
-    h0 = (uint64_t)(t = (u128)h0 + nonce[0] + ((uint64_t)nonce[1] << 32));
-    h1 = (uint64_t)(t = (u128)h1 + nonce[2] + ((uint64_t)nonce[3] << 32) + (t >> 64));
+    h0 = (u64)(t = (u128)h0 + nonce[0] + ((u64)nonce[1] << 32));
+    h1 = (u64)(t = (u128)h1 + nonce[2] + ((u64)nonce[3] << 32) + (t >> 64));
 
     U64TO8(mac + 0, h0);
     U64TO8(mac + 8, h1);
@@ -230,9 +232,17 @@ static void poly1305_emit(void *ctx, unsigned char mac[16],
 
 #else
 
+#if defined(_WIN32) && !defined(__MINGW32__)
+typedef unsigned __int64 u64;
+#elif defined(__arch64__)
+typedef unsigned long u64;
+#else
+typedef unsigned long long u64;
+#endif
+
 typedef struct {
-    uint32_t h[5];
-    uint32_t r[4];
+    u32 h[5];
+    u32 r[4];
 } poly1305_internal;
 
 /* store a 32-bit unsigned integer in little endian */
@@ -263,13 +273,13 @@ static void poly1305_init(void *ctx, const unsigned char key[16])
 }
 
 static void
-poly1305_blocks(void *ctx, const unsigned char *inp, size_t len, uint32_t padbit)
+poly1305_blocks(void *ctx, const unsigned char *inp, size_t len, u32 padbit)
 {
     poly1305_internal *st = (poly1305_internal *)ctx;
-    uint32_t r0, r1, r2, r3;
-    uint32_t s1, s2, s3;
-    uint32_t h0, h1, h2, h3, h4, c;
-    uint64_t d0, d1, d2, d3;
+    u32 r0, r1, r2, r3;
+    u32 s1, s2, s3;
+    u32 h0, h1, h2, h3, h4, c;
+    u64 d0, d1, d2, d3;
 
     r0 = st->r[0];
     r1 = st->r[1];
@@ -288,26 +298,26 @@ poly1305_blocks(void *ctx, const unsigned char *inp, size_t len, uint32_t padbit
 
     while (len >= POLY1305_BLOCK_SIZE) {
         /* h += m[i] */
-        h0 = (uint32_t)(d0 = (uint64_t)h0 + U8TOU32(inp + 0));
-        h1 = (uint32_t)(d1 = (uint64_t)h1 + (d0 >> 32) + U8TOU32(inp + 4));
-        h2 = (uint32_t)(d2 = (uint64_t)h2 + (d1 >> 32) + U8TOU32(inp + 8));
-        h3 = (uint32_t)(d3 = (uint64_t)h3 + (d2 >> 32) + U8TOU32(inp + 12));
-        h4 += (uint32_t)(d3 >> 32) + padbit;
+        h0 = (u32)(d0 = (u64)h0 + U8TOU32(inp + 0));
+        h1 = (u32)(d1 = (u64)h1 + (d0 >> 32) + U8TOU32(inp + 4));
+        h2 = (u32)(d2 = (u64)h2 + (d1 >> 32) + U8TOU32(inp + 8));
+        h3 = (u32)(d3 = (u64)h3 + (d2 >> 32) + U8TOU32(inp + 12));
+        h4 += (u32)(d3 >> 32) + padbit;
 
         /* h *= r "%" p, where "%" stands for "partial remainder" */
-        d0 = ((uint64_t)h0 * r0) + ((uint64_t)h1 * s3) + ((uint64_t)h2 * s2) + ((uint64_t)h3 * s1);
-        d1 = ((uint64_t)h0 * r1) + ((uint64_t)h1 * r0) + ((uint64_t)h2 * s3) + ((uint64_t)h3 * s2) + (h4 * s1);
-        d2 = ((uint64_t)h0 * r2) + ((uint64_t)h1 * r1) + ((uint64_t)h2 * r0) + ((uint64_t)h3 * s3) + (h4 * s2);
-        d3 = ((uint64_t)h0 * r3) + ((uint64_t)h1 * r2) + ((uint64_t)h2 * r1) + ((uint64_t)h3 * r0) + (h4 * s3);
+        d0 = ((u64)h0 * r0) + ((u64)h1 * s3) + ((u64)h2 * s2) + ((u64)h3 * s1);
+        d1 = ((u64)h0 * r1) + ((u64)h1 * r0) + ((u64)h2 * s3) + ((u64)h3 * s2) + (h4 * s1);
+        d2 = ((u64)h0 * r2) + ((u64)h1 * r1) + ((u64)h2 * r0) + ((u64)h3 * s3) + (h4 * s2);
+        d3 = ((u64)h0 * r3) + ((u64)h1 * r2) + ((u64)h2 * r1) + ((u64)h3 * r0) + (h4 * s3);
         h4 = (h4 * r0);
 
         /* last reduction step: */
         /* a) h4:h0 = h4<<128 + d3<<96 + d2<<64 + d1<<32 + d0 */
-        h0 = (uint32_t)d0;
-        h1 = (uint32_t)(d1 += d0 >> 32);
-        h2 = (uint32_t)(d2 += d1 >> 32);
-        h3 = (uint32_t)(d3 += d2 >> 32);
-        h4 += (uint32_t)(d3 >> 32);
+        h0 = (u32)d0;
+        h1 = (u32)(d1 += d0 >> 32);
+        h2 = (u32)(d2 += d1 >> 32);
+        h3 = (u32)(d3 += d2 >> 32);
+        h4 += (u32)(d3 >> 32);
         /* b) (h4:h0 += (h4:h0>>130) * 5) %= 2^130 */
         c = (h4 >> 2) + (h4 & ~3U);
         h4 &= 3;
@@ -338,13 +348,13 @@ poly1305_blocks(void *ctx, const unsigned char *inp, size_t len, uint32_t padbit
 }
 
 static void poly1305_emit(void *ctx, unsigned char mac[16],
-    const uint32_t nonce[4])
+    const u32 nonce[4])
 {
     poly1305_internal *st = (poly1305_internal *)ctx;
-    uint32_t h0, h1, h2, h3, h4;
-    uint32_t g0, g1, g2, g3, g4;
-    uint64_t t;
-    uint32_t mask;
+    u32 h0, h1, h2, h3, h4;
+    u32 g0, g1, g2, g3, g4;
+    u64 t;
+    u32 mask;
 
     h0 = st->h[0];
     h1 = st->h[1];
@@ -353,11 +363,11 @@ static void poly1305_emit(void *ctx, unsigned char mac[16],
     h4 = st->h[4];
 
     /* compare to modulus by computing h + -p */
-    g0 = (uint32_t)(t = (uint64_t)h0 + 5);
-    g1 = (uint32_t)(t = (uint64_t)h1 + (t >> 32));
-    g2 = (uint32_t)(t = (uint64_t)h2 + (t >> 32));
-    g3 = (uint32_t)(t = (uint64_t)h3 + (t >> 32));
-    g4 = h4 + (uint32_t)(t >> 32);
+    g0 = (u32)(t = (u64)h0 + 5);
+    g1 = (u32)(t = (u64)h1 + (t >> 32));
+    g2 = (u32)(t = (u64)h2 + (t >> 32));
+    g3 = (u32)(t = (u64)h3 + (t >> 32));
+    g4 = h4 + (u32)(t >> 32);
 
     /* if there was carry into 131st bit, h3:h0 = g3:g0 */
     mask = 0 - (g4 >> 2);
@@ -372,10 +382,10 @@ static void poly1305_emit(void *ctx, unsigned char mac[16],
     h3 = (h3 & mask) | g3;
 
     /* mac = (h + nonce) % (2^128) */
-    h0 = (uint32_t)(t = (uint64_t)h0 + nonce[0]);
-    h1 = (uint32_t)(t = (uint64_t)h1 + (t >> 32) + nonce[1]);
-    h2 = (uint32_t)(t = (uint64_t)h2 + (t >> 32) + nonce[2]);
-    h3 = (uint32_t)(t = (uint64_t)h3 + (t >> 32) + nonce[3]);
+    h0 = (u32)(t = (u64)h0 + nonce[0]);
+    h1 = (u32)(t = (u64)h1 + (t >> 32) + nonce[1]);
+    h2 = (u32)(t = (u64)h2 + (t >> 32) + nonce[2]);
+    h3 = (u32)(t = (u64)h3 + (t >> 32) + nonce[3]);
 
     U32TO8(mac + 0, h0);
     U32TO8(mac + 4, h1);
diff --git a/crypto/poly1305/poly1305_base2_44.c b/crypto/poly1305/poly1305_base2_44.c
new file mode 100644
index 0000000000..7e28970fbe
--- /dev/null
+++ b/crypto/poly1305/poly1305_base2_44.c
@@ -0,0 +1,166 @@
+/*
+ * Copyright 2016-2021 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+/*
+ * This module is meant to be used as template for base 2^44 assembly
+ * implementation[s]. On side note compiler-generated code is not
+ * slower than compiler-generated base 2^64 code on [high-end] x86_64,
+ * even though amount of multiplications is 50% higher. Go figure...
+ */
+#include 
+
+typedef unsigned char u8;
+typedef unsigned int u32;
+typedef unsigned long u64;
+typedef uint128_t u128;
+
+typedef struct {
+    u64 h[3];
+    u64 s[2];
+    u64 r[3];
+} poly1305_internal;
+
+#define POLY1305_BLOCK_SIZE 16
+
+/* pick 64-bit unsigned integer in little endian order */
+static u64 U8TOU64(const unsigned char *p)
+{
+    return (((u64)(p[0] & 0xff)) | ((u64)(p[1] & 0xff) << 8) | ((u64)(p[2] & 0xff) << 16) | ((u64)(p[3] & 0xff) << 24) | ((u64)(p[4] & 0xff) << 32) | ((u64)(p[5] & 0xff) << 40) | ((u64)(p[6] & 0xff) << 48) | ((u64)(p[7] & 0xff) << 56));
+}
+
+/* store a 64-bit unsigned integer in little endian */
+static void U64TO8(unsigned char *p, u64 v)
+{
+    p[0] = (unsigned char)((v) & 0xff);
+    p[1] = (unsigned char)((v >> 8) & 0xff);
+    p[2] = (unsigned char)((v >> 16) & 0xff);
+    p[3] = (unsigned char)((v >> 24) & 0xff);
+    p[4] = (unsigned char)((v >> 32) & 0xff);
+    p[5] = (unsigned char)((v >> 40) & 0xff);
+    p[6] = (unsigned char)((v >> 48) & 0xff);
+    p[7] = (unsigned char)((v >> 56) & 0xff);
+}
+
+int poly1305_init(void *ctx, const unsigned char key[16])
+{
+    poly1305_internal *st = (poly1305_internal *)ctx;
+    u64 r0, r1;
+
+    /* h = 0 */
+    st->h[0] = 0;
+    st->h[1] = 0;
+    st->h[2] = 0;
+
+    r0 = U8TOU64(&key[0]) & 0x0ffffffc0fffffff;
+    r1 = U8TOU64(&key[8]) & 0x0ffffffc0ffffffc;
+
+    /* break r1:r0 to three 44-bit digits, masks are 1<<44-1 */
+    st->r[0] = r0 & 0x0fffffffffff;
+    st->r[1] = ((r0 >> 44) | (r1 << 20)) & 0x0fffffffffff;
+    st->r[2] = (r1 >> 24);
+
+    st->s[0] = (st->r[1] + (st->r[1] << 2)) << 2;
+    st->s[1] = (st->r[2] + (st->r[2] << 2)) << 2;
+
+    return 0;
+}
+
+void poly1305_blocks(void *ctx, const unsigned char *inp, size_t len,
+    u32 padbit)
+{
+    poly1305_internal *st = (poly1305_internal *)ctx;
+    u64 r0, r1, r2;
+    u64 s1, s2;
+    u64 h0, h1, h2, c;
+    u128 d0, d1, d2;
+    u64 pad = (u64)padbit << 40;
+
+    r0 = st->r[0];
+    r1 = st->r[1];
+    r2 = st->r[2];
+
+    s1 = st->s[0];
+    s2 = st->s[1];
+
+    h0 = st->h[0];
+    h1 = st->h[1];
+    h2 = st->h[2];
+
+    while (len >= POLY1305_BLOCK_SIZE) {
+        u64 m0, m1;
+
+        m0 = U8TOU64(inp + 0);
+        m1 = U8TOU64(inp + 8);
+
+        /* h += m[i], m[i] is broken to 44-bit digits */
+        h0 += m0 & 0x0fffffffffff;
+        h1 += ((m0 >> 44) | (m1 << 20)) & 0x0fffffffffff;
+        h2 += (m1 >> 24) + pad;
+
+        /* h *= r "%" p, where "%" stands for "partial remainder" */
+        d0 = ((u128)h0 * r0) + ((u128)h1 * s2) + ((u128)h2 * s1);
+        d1 = ((u128)h0 * r1) + ((u128)h1 * r0) + ((u128)h2 * s2);
+        d2 = ((u128)h0 * r2) + ((u128)h1 * r1) + ((u128)h2 * r0);
+
+        /* "lazy" reduction step */
+        h0 = (u64)d0 & 0x0fffffffffff;
+        h1 = (u64)(d1 += (u64)(d0 >> 44)) & 0x0fffffffffff;
+        h2 = (u64)(d2 += (u64)(d1 >> 44)) & 0x03ffffffffff; /* last 42 bits */
+
+        c = (d2 >> 42);
+        h0 += c + (c << 2);
+
+        inp += POLY1305_BLOCK_SIZE;
+        len -= POLY1305_BLOCK_SIZE;
+    }
+
+    st->h[0] = h0;
+    st->h[1] = h1;
+    st->h[2] = h2;
+}
+
+void poly1305_emit(void *ctx, unsigned char mac[16], const u32 nonce[4])
+{
+    poly1305_internal *st = (poly1305_internal *)ctx;
+    u64 h0, h1, h2;
+    u64 g0, g1, g2;
+    u128 t;
+    u64 mask;
+
+    h0 = st->h[0];
+    h1 = st->h[1];
+    h2 = st->h[2];
+
+    /* after "lazy" reduction, convert 44+bit digits to 64-bit ones */
+    h0 = (u64)(t = (u128)h0 + (h1 << 44));
+    h1 >>= 20;
+    h1 = (u64)(t = (u128)h1 + (h2 << 24) + (t >> 64));
+    h2 >>= 40;
+    h2 += (u64)(t >> 64);
+
+    /* compare to modulus by computing h + -p */
+    g0 = (u64)(t = (u128)h0 + 5);
+    g1 = (u64)(t = (u128)h1 + (t >> 64));
+    g2 = h2 + (u64)(t >> 64);
+
+    /* if there was carry into 131st bit, h1:h0 = g1:g0 */
+    mask = 0 - (g2 >> 2);
+    g0 &= mask;
+    g1 &= mask;
+    mask = ~mask;
+    h0 = (h0 & mask) | g0;
+    h1 = (h1 & mask) | g1;
+
+    /* mac = (h + nonce) % (2^128) */
+    h0 = (u64)(t = (u128)h0 + nonce[0] + ((u64)nonce[1] << 32));
+    h1 = (u64)(t = (u128)h1 + nonce[2] + ((u64)nonce[3] << 32) + (t >> 64));
+
+    U64TO8(mac + 0, h0);
+    U64TO8(mac + 8, h1);
+}
diff --git a/crypto/poly1305/poly1305_ieee754.c b/crypto/poly1305/poly1305_ieee754.c
new file mode 100644
index 0000000000..bd7426466e
--- /dev/null
+++ b/crypto/poly1305/poly1305_ieee754.c
@@ -0,0 +1,487 @@
+/*
+ * Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+/*
+ * This module is meant to be used as template for non-x87 floating-
+ * point assembly modules. The template itself is x86_64-specific
+ * though, as it was debugged on x86_64. So that implementer would
+ * have to recognize platform-specific parts, UxTOy and inline asm,
+ * and act accordingly.
+ *
+ * Huh? x86_64-specific code as template for non-x87? Note seven, which
+ * is not a typo, but reference to 80-bit precision. This module on the
+ * other hand relies on 64-bit precision operations, which are default
+ * for x86_64 code. And since we are at it, just for sense of it,
+ * large-block performance in cycles per processed byte for *this* code
+ * is:
+ *                      gcc-4.8         icc-15.0        clang-3.4(*)
+ *
+ * Westmere             4.96            5.09            4.37
+ * Sandy Bridge         4.95            4.90            4.17
+ * Haswell              4.92            4.87            3.78
+ * Bulldozer            4.67            4.49            4.68
+ * VIA Nano             7.07            7.05            5.98
+ * Silvermont           10.6            9.61            12.6
+ *
+ * (*)  clang managed to discover parallelism and deployed SIMD;
+ *
+ * And for range of other platforms with unspecified gcc versions:
+ *
+ * Freescale e300       12.5
+ * PPC74x0              10.8
+ * POWER6               4.92
+ * POWER7               4.50
+ * POWER8               4.10
+ *
+ * z10                  11.2
+ * z196+                7.30
+ *
+ * UltraSPARC III       16.0
+ * SPARC T4             16.1
+ */
+
+#if !(defined(__GNUC__) && __GNUC__ >= 2)
+#error "this is gcc-specific template"
+#endif
+
+#include 
+
+typedef unsigned char u8;
+typedef unsigned int u32;
+typedef unsigned long long u64;
+typedef union {
+    double d;
+    u64 u;
+} elem64;
+
+#define TWO(p) ((double)(1ULL << (p)))
+#define TWO0 TWO(0)
+#define TWO32 TWO(32)
+#define TWO64 (TWO32 * TWO(32))
+#define TWO96 (TWO64 * TWO(32))
+#define TWO130 (TWO96 * TWO(34))
+
+#define EXP(p) ((1023ULL + (p)) << 52)
+
+#if defined(__x86_64__) || (defined(__PPC__) && defined(__LITTLE_ENDIAN__))
+#define U8TOU32(p) (*(const u32 *)(p))
+#define U32TO8(p, v) (*(u32 *)(p) = (v))
+#elif defined(__PPC__) || defined(__POWERPC__)
+#define U8TOU32(p) ({u32 ret; asm ("lwbrx	%0,0,%1":"=r"(ret):"b"(p)); ret; })
+#define U32TO8(p, v) asm("stwbrx %0,0,%1" ::"r"(v), "b"(p) : "memory")
+#elif defined(__s390x__)
+#define U8TOU32(p) ({u32 ret; asm ("lrv	%0,%1":"=d"(ret):"m"(*(u32 *)(p))); ret; })
+#define U32TO8(p, v) asm("strv	%1,%0" : "=m"(*(u32 *)(p)) : "d"(v))
+#endif
+
+#ifndef U8TOU32
+#define U8TOU32(p) ((u32)(p)[0] | (u32)(p)[1] << 8 | (u32)(p)[2] << 16 | (u32)(p)[3] << 24)
+#endif
+#ifndef U32TO8
+#define U32TO8(p, v) ((p)[0] = (u8)(v), (p)[1] = (u8)((v) >> 8), \
+    (p)[2] = (u8)((v) >> 16), (p)[3] = (u8)((v) >> 24))
+#endif
+
+typedef struct {
+    elem64 h[4];
+    double r[8];
+    double s[6];
+} poly1305_internal;
+
+/* "round toward zero (truncate), mask all exceptions" */
+#if defined(__x86_64__)
+static const u32 mxcsr = 0x7f80;
+#elif defined(__PPC__) || defined(__POWERPC__)
+static const u64 one = 1;
+#elif defined(__s390x__)
+static const u32 fpc = 1;
+#elif defined(__sparc__)
+static const u64 fsr = 1ULL << 30;
+#elif defined(__mips__)
+static const u32 fcsr = 1;
+#else
+#error "unrecognized platform"
+#endif
+
+int poly1305_init(void *ctx, const unsigned char key[16])
+{
+    poly1305_internal *st = (poly1305_internal *)ctx;
+    elem64 r0, r1, r2, r3;
+
+    /* h = 0, biased */
+#if 0
+    st->h[0].d = TWO(52)*TWO0;
+    st->h[1].d = TWO(52)*TWO32;
+    st->h[2].d = TWO(52)*TWO64;
+    st->h[3].d = TWO(52)*TWO96;
+#else
+    st->h[0].u = EXP(52 + 0);
+    st->h[1].u = EXP(52 + 32);
+    st->h[2].u = EXP(52 + 64);
+    st->h[3].u = EXP(52 + 96);
+#endif
+
+    if (key) {
+        /*
+         * set "truncate" rounding mode
+         */
+#if defined(__x86_64__)
+        u32 mxcsr_orig;
+
+        asm volatile("stmxcsr	%0" : "=m"(mxcsr_orig));
+        asm volatile("ldmxcsr	%0" ::"m"(mxcsr));
+#elif defined(__PPC__) || defined(__POWERPC__)
+        double fpscr_orig, fpscr = *(double *)&one;
+
+        asm volatile("mffs	%0" : "=f"(fpscr_orig));
+        asm volatile("mtfsf	255,%0" ::"f"(fpscr));
+#elif defined(__s390x__)
+        u32 fpc_orig;
+
+        asm volatile("stfpc	%0" : "=m"(fpc_orig));
+        asm volatile("lfpc	%0" ::"m"(fpc));
+#elif defined(__sparc__)
+        u64 fsr_orig;
+
+        asm volatile("stx	%%fsr,%0" : "=m"(fsr_orig));
+        asm volatile("ldx	%0,%%fsr" ::"m"(fsr));
+#elif defined(__mips__)
+        u32 fcsr_orig;
+
+        asm volatile("cfc1	%0,$31" : "=r"(fcsr_orig));
+        asm volatile("ctc1	%0,$31" ::"r"(fcsr));
+#endif
+
+        /* r &= 0xffffffc0ffffffc0ffffffc0fffffff */
+        r0.u = EXP(52 + 0) | (U8TOU32(&key[0]) & 0x0fffffff);
+        r1.u = EXP(52 + 32) | (U8TOU32(&key[4]) & 0x0ffffffc);
+        r2.u = EXP(52 + 64) | (U8TOU32(&key[8]) & 0x0ffffffc);
+        r3.u = EXP(52 + 96) | (U8TOU32(&key[12]) & 0x0ffffffc);
+
+        st->r[0] = r0.d - TWO(52) * TWO0;
+        st->r[2] = r1.d - TWO(52) * TWO32;
+        st->r[4] = r2.d - TWO(52) * TWO64;
+        st->r[6] = r3.d - TWO(52) * TWO96;
+
+        st->s[0] = st->r[2] * (5.0 / TWO130);
+        st->s[2] = st->r[4] * (5.0 / TWO130);
+        st->s[4] = st->r[6] * (5.0 / TWO130);
+
+        /*
+         * base 2^32 -> base 2^16
+         */
+        st->r[1] = (st->r[0] + TWO(52) * TWO(16) * TWO0) - TWO(52) * TWO(16) * TWO0;
+        st->r[0] -= st->r[1];
+
+        st->r[3] = (st->r[2] + TWO(52) * TWO(16) * TWO32) - TWO(52) * TWO(16) * TWO32;
+        st->r[2] -= st->r[3];
+
+        st->r[5] = (st->r[4] + TWO(52) * TWO(16) * TWO64) - TWO(52) * TWO(16) * TWO64;
+        st->r[4] -= st->r[5];
+
+        st->r[7] = (st->r[6] + TWO(52) * TWO(16) * TWO96) - TWO(52) * TWO(16) * TWO96;
+        st->r[6] -= st->r[7];
+
+        st->s[1] = (st->s[0] + TWO(52) * TWO(16) * TWO0 / TWO96) - TWO(52) * TWO(16) * TWO0 / TWO96;
+        st->s[0] -= st->s[1];
+
+        st->s[3] = (st->s[2] + TWO(52) * TWO(16) * TWO32 / TWO96) - TWO(52) * TWO(16) * TWO32 / TWO96;
+        st->s[2] -= st->s[3];
+
+        st->s[5] = (st->s[4] + TWO(52) * TWO(16) * TWO64 / TWO96) - TWO(52) * TWO(16) * TWO64 / TWO96;
+        st->s[4] -= st->s[5];
+
+        /*
+         * restore original FPU control register
+         */
+#if defined(__x86_64__)
+        asm volatile("ldmxcsr	%0" ::"m"(mxcsr_orig));
+#elif defined(__PPC__) || defined(__POWERPC__)
+        asm volatile("mtfsf	255,%0" ::"f"(fpscr_orig));
+#elif defined(__s390x__)
+        asm volatile("lfpc	%0" ::"m"(fpc_orig));
+#elif defined(__sparc__)
+        asm volatile("ldx	%0,%%fsr" ::"m"(fsr_orig));
+#elif defined(__mips__)
+        asm volatile("ctc1	%0,$31" ::"r"(fcsr_orig));
+#endif
+    }
+
+    return 0;
+}
+
+void poly1305_blocks(void *ctx, const unsigned char *inp, size_t len,
+    int padbit)
+{
+    poly1305_internal *st = (poly1305_internal *)ctx;
+    elem64 in0, in1, in2, in3;
+    u64 pad = (u64)padbit << 32;
+
+    double x0, x1, x2, x3;
+    double h0lo, h0hi, h1lo, h1hi, h2lo, h2hi, h3lo, h3hi;
+    double c0lo, c0hi, c1lo, c1hi, c2lo, c2hi, c3lo, c3hi;
+
+    const double r0lo = st->r[0];
+    const double r0hi = st->r[1];
+    const double r1lo = st->r[2];
+    const double r1hi = st->r[3];
+    const double r2lo = st->r[4];
+    const double r2hi = st->r[5];
+    const double r3lo = st->r[6];
+    const double r3hi = st->r[7];
+
+    const double s1lo = st->s[0];
+    const double s1hi = st->s[1];
+    const double s2lo = st->s[2];
+    const double s2hi = st->s[3];
+    const double s3lo = st->s[4];
+    const double s3hi = st->s[5];
+
+    /*
+     * set "truncate" rounding mode
+     */
+#if defined(__x86_64__)
+    u32 mxcsr_orig;
+
+    asm volatile("stmxcsr	%0" : "=m"(mxcsr_orig));
+    asm volatile("ldmxcsr	%0" ::"m"(mxcsr));
+#elif defined(__PPC__) || defined(__POWERPC__)
+    double fpscr_orig, fpscr = *(double *)&one;
+
+    asm volatile("mffs		%0" : "=f"(fpscr_orig));
+    asm volatile("mtfsf	255,%0" ::"f"(fpscr));
+#elif defined(__s390x__)
+    u32 fpc_orig;
+
+    asm volatile("stfpc	%0" : "=m"(fpc_orig));
+    asm volatile("lfpc		%0" ::"m"(fpc));
+#elif defined(__sparc__)
+    u64 fsr_orig;
+
+    asm volatile("stx		%%fsr,%0" : "=m"(fsr_orig));
+    asm volatile("ldx		%0,%%fsr" ::"m"(fsr));
+#elif defined(__mips__)
+    u32 fcsr_orig;
+
+    asm volatile("cfc1		%0,$31" : "=r"(fcsr_orig));
+    asm volatile("ctc1		%0,$31" ::"r"(fcsr));
+#endif
+
+    /*
+     * load base 2^32 and de-bias
+     */
+    h0lo = st->h[0].d - TWO(52) * TWO0;
+    h1lo = st->h[1].d - TWO(52) * TWO32;
+    h2lo = st->h[2].d - TWO(52) * TWO64;
+    h3lo = st->h[3].d - TWO(52) * TWO96;
+
+#ifdef __clang__
+    h0hi = 0;
+    h1hi = 0;
+    h2hi = 0;
+    h3hi = 0;
+#else
+    in0.u = EXP(52 + 0) | U8TOU32(&inp[0]);
+    in1.u = EXP(52 + 32) | U8TOU32(&inp[4]);
+    in2.u = EXP(52 + 64) | U8TOU32(&inp[8]);
+    in3.u = EXP(52 + 96) | U8TOU32(&inp[12]) | pad;
+
+    x0 = in0.d - TWO(52) * TWO0;
+    x1 = in1.d - TWO(52) * TWO32;
+    x2 = in2.d - TWO(52) * TWO64;
+    x3 = in3.d - TWO(52) * TWO96;
+
+    x0 += h0lo;
+    x1 += h1lo;
+    x2 += h2lo;
+    x3 += h3lo;
+
+    goto fast_entry;
+#endif
+
+    do {
+        in0.u = EXP(52 + 0) | U8TOU32(&inp[0]);
+        in1.u = EXP(52 + 32) | U8TOU32(&inp[4]);
+        in2.u = EXP(52 + 64) | U8TOU32(&inp[8]);
+        in3.u = EXP(52 + 96) | U8TOU32(&inp[12]) | pad;
+
+        x0 = in0.d - TWO(52) * TWO0;
+        x1 = in1.d - TWO(52) * TWO32;
+        x2 = in2.d - TWO(52) * TWO64;
+        x3 = in3.d - TWO(52) * TWO96;
+
+        /*
+         * note that there are multiple ways to accumulate input, e.g.
+         * one can as well accumulate to h0lo-h1lo-h1hi-h2hi...
+         */
+        h0lo += x0;
+        h0hi += x1;
+        h2lo += x2;
+        h2hi += x3;
+
+        /*
+         * carries that cross 32n-bit (and 130-bit) boundaries
+         */
+        c0lo = (h0lo + TWO(52) * TWO32) - TWO(52) * TWO32;
+        c1lo = (h1lo + TWO(52) * TWO64) - TWO(52) * TWO64;
+        c2lo = (h2lo + TWO(52) * TWO96) - TWO(52) * TWO96;
+        c3lo = (h3lo + TWO(52) * TWO130) - TWO(52) * TWO130;
+
+        c0hi = (h0hi + TWO(52) * TWO32) - TWO(52) * TWO32;
+        c1hi = (h1hi + TWO(52) * TWO64) - TWO(52) * TWO64;
+        c2hi = (h2hi + TWO(52) * TWO96) - TWO(52) * TWO96;
+        c3hi = (h3hi + TWO(52) * TWO130) - TWO(52) * TWO130;
+
+        /*
+         * base 2^48 -> base 2^32 with last reduction step
+         */
+        x1 = (h1lo - c1lo) + c0lo;
+        x2 = (h2lo - c2lo) + c1lo;
+        x3 = (h3lo - c3lo) + c2lo;
+        x0 = (h0lo - c0lo) + c3lo * (5.0 / TWO130);
+
+        x1 += (h1hi - c1hi) + c0hi;
+        x2 += (h2hi - c2hi) + c1hi;
+        x3 += (h3hi - c3hi) + c2hi;
+        x0 += (h0hi - c0hi) + c3hi * (5.0 / TWO130);
+
+#ifndef __clang__
+    fast_entry:
+#endif
+        /*
+         * base 2^32 * base 2^16 = base 2^48
+         */
+        h0lo = s3lo * x1 + s2lo * x2 + s1lo * x3 + r0lo * x0;
+        h1lo = r0lo * x1 + s3lo * x2 + s2lo * x3 + r1lo * x0;
+        h2lo = r1lo * x1 + r0lo * x2 + s3lo * x3 + r2lo * x0;
+        h3lo = r2lo * x1 + r1lo * x2 + r0lo * x3 + r3lo * x0;
+
+        h0hi = s3hi * x1 + s2hi * x2 + s1hi * x3 + r0hi * x0;
+        h1hi = r0hi * x1 + s3hi * x2 + s2hi * x3 + r1hi * x0;
+        h2hi = r1hi * x1 + r0hi * x2 + s3hi * x3 + r2hi * x0;
+        h3hi = r2hi * x1 + r1hi * x2 + r0hi * x3 + r3hi * x0;
+
+        inp += 16;
+        len -= 16;
+
+    } while (len >= 16);
+
+    /*
+     * carries that cross 32n-bit (and 130-bit) boundaries
+     */
+    c0lo = (h0lo + TWO(52) * TWO32) - TWO(52) * TWO32;
+    c1lo = (h1lo + TWO(52) * TWO64) - TWO(52) * TWO64;
+    c2lo = (h2lo + TWO(52) * TWO96) - TWO(52) * TWO96;
+    c3lo = (h3lo + TWO(52) * TWO130) - TWO(52) * TWO130;
+
+    c0hi = (h0hi + TWO(52) * TWO32) - TWO(52) * TWO32;
+    c1hi = (h1hi + TWO(52) * TWO64) - TWO(52) * TWO64;
+    c2hi = (h2hi + TWO(52) * TWO96) - TWO(52) * TWO96;
+    c3hi = (h3hi + TWO(52) * TWO130) - TWO(52) * TWO130;
+
+    /*
+     * base 2^48 -> base 2^32 with last reduction step
+     */
+    x1 = (h1lo - c1lo) + c0lo;
+    x2 = (h2lo - c2lo) + c1lo;
+    x3 = (h3lo - c3lo) + c2lo;
+    x0 = (h0lo - c0lo) + c3lo * (5.0 / TWO130);
+
+    x1 += (h1hi - c1hi) + c0hi;
+    x2 += (h2hi - c2hi) + c1hi;
+    x3 += (h3hi - c3hi) + c2hi;
+    x0 += (h0hi - c0hi) + c3hi * (5.0 / TWO130);
+
+    /*
+     * store base 2^32, with bias
+     */
+    st->h[1].d = x1 + TWO(52) * TWO32;
+    st->h[2].d = x2 + TWO(52) * TWO64;
+    st->h[3].d = x3 + TWO(52) * TWO96;
+    st->h[0].d = x0 + TWO(52) * TWO0;
+
+    /*
+     * restore original FPU control register
+     */
+#if defined(__x86_64__)
+    asm volatile("ldmxcsr	%0" ::"m"(mxcsr_orig));
+#elif defined(__PPC__) || defined(__POWERPC__)
+    asm volatile("mtfsf	255,%0" ::"f"(fpscr_orig));
+#elif defined(__s390x__)
+    asm volatile("lfpc		%0" ::"m"(fpc_orig));
+#elif defined(__sparc__)
+    asm volatile("ldx		%0,%%fsr" ::"m"(fsr_orig));
+#elif defined(__mips__)
+    asm volatile("ctc1		%0,$31" ::"r"(fcsr_orig));
+#endif
+}
+
+void poly1305_emit(void *ctx, unsigned char mac[16], const u32 nonce[4])
+{
+    poly1305_internal *st = (poly1305_internal *)ctx;
+    u64 h0, h1, h2, h3, h4;
+    u32 g0, g1, g2, g3, g4;
+    u64 t;
+    u32 mask;
+
+    /*
+     * thanks to bias masking exponent gives integer result
+     */
+    h0 = st->h[0].u & 0x000fffffffffffffULL;
+    h1 = st->h[1].u & 0x000fffffffffffffULL;
+    h2 = st->h[2].u & 0x000fffffffffffffULL;
+    h3 = st->h[3].u & 0x000fffffffffffffULL;
+
+    /*
+     * can be partially reduced, so reduce...
+     */
+    h4 = h3 >> 32;
+    h3 &= 0xffffffffU;
+    g4 = h4 & -4;
+    h4 &= 3;
+    g4 += g4 >> 2;
+
+    h0 += g4;
+    h1 += h0 >> 32;
+    h0 &= 0xffffffffU;
+    h2 += h1 >> 32;
+    h1 &= 0xffffffffU;
+    h3 += h2 >> 32;
+    h2 &= 0xffffffffU;
+
+    /* compute h + -p */
+    g0 = (u32)(t = h0 + 5);
+    g1 = (u32)(t = h1 + (t >> 32));
+    g2 = (u32)(t = h2 + (t >> 32));
+    g3 = (u32)(t = h3 + (t >> 32));
+    g4 = h4 + (u32)(t >> 32);
+
+    /* if there was carry, select g0-g3 */
+    mask = 0 - (g4 >> 2);
+    g0 &= mask;
+    g1 &= mask;
+    g2 &= mask;
+    g3 &= mask;
+    mask = ~mask;
+    g0 |= (h0 & mask);
+    g1 |= (h1 & mask);
+    g2 |= (h2 & mask);
+    g3 |= (h3 & mask);
+
+    /* mac = (h + nonce) % (2^128) */
+    g0 = (u32)(t = (u64)g0 + nonce[0]);
+    g1 = (u32)(t = (u64)g1 + (t >> 32) + nonce[1]);
+    g2 = (u32)(t = (u64)g2 + (t >> 32) + nonce[2]);
+    g3 = (u32)(t = (u64)g3 + (t >> 32) + nonce[3]);
+
+    U32TO8(mac + 0, g0);
+    U32TO8(mac + 4, g1);
+    U32TO8(mac + 8, g2);
+    U32TO8(mac + 12, g3);
+}
diff --git a/crypto/poly1305/poly1305_ppc.c b/crypto/poly1305/poly1305_ppc.c
index 4a2a943a8b..a40ce729b7 100644
--- a/crypto/poly1305/poly1305_ppc.c
+++ b/crypto/poly1305/poly1305_ppc.c
@@ -10,7 +10,7 @@
 #include 
 #include 
 #include "crypto/poly1305.h"
-#include "arch/ppc_arch.h"
+#include "crypto/ppc_arch.h"
 
 void poly1305_init_int(void *ctx, const unsigned char key[16]);
 void poly1305_blocks(void *ctx, const unsigned char *inp, size_t len,
diff --git a/crypto/ppccap.c b/crypto/ppccap.c
index e029eb3051..91a3e09573 100644
--- a/crypto/ppccap.c
+++ b/crypto/ppccap.c
@@ -28,7 +28,7 @@
 #endif
 #include 
 #include "internal/cryptlib.h"
-#include "arch/ppc_arch.h"
+#include "crypto/ppc_arch.h"
 
 unsigned int OPENSSL_ppccap_P = 0;
 
@@ -134,9 +134,6 @@ static unsigned long getauxval(unsigned long key)
 #define HWCAP_ARCH_3_00 (1U << 23)
 #define HWCAP_ARCH_3_1 (1U << 18)
 
-#if defined(__GNUC__)
-__attribute__((constructor))
-#endif
 void OPENSSL_cpuid_setup(void)
 {
     char *e;
diff --git a/crypto/property/property.c b/crypto/property/property.c
index aa0bb283f1..b086d0c056 100644
--- a/crypto/property/property.c
+++ b/crypto/property/property.c
@@ -12,40 +12,34 @@
 #include 
 #include 
 #include 
-#include 
 #include "internal/property.h"
 #include "internal/provider.h"
+#include "internal/core.h"
 #include "internal/tsan_assist.h"
-#include "internal/threads_common.h"
-#include "internal/list.h"
-#include "internal/time.h"
+#include "internal/hashtable.h"
 #include 
 #include 
 #include 
 #include "crypto/sparse_array.h"
 #include "property_local.h"
 #include "crypto/context.h"
+#include "crypto/evp.h"
+#include "crypto/evp/evp_local.h"
+#include "internal/namemap.h"
 
 /*
- * The shard count was determined through performance testing with the evp_fetch
- * tool on an Intel Xeon Gold 6248R CPU @ 3.00GHz. Testing showed that 4 shards
- * delivered the best performance for 16 or
- * more threads, and close to best performance at below 16 threads.
+ * The number of elements in the query cache before we initiate a flush.
+ * If reducing this, also ensure the stochastic test in test/property_test.c
+ * isn't likely to fail.
  */
-#ifndef NUM_SHARDS_BITS
-#define NUM_SHARDS_BITS 2
-#endif
-#define NUM_SHARDS (1 << NUM_SHARDS_BITS)
-
-#ifndef MAX_CACHE_LINES_BITS
-#define MAX_CACHE_LINES_BITS 3
-#endif
-#define MAX_CACHE_LINES (1 << MAX_CACHE_LINES_BITS)
+#define IMPL_CACHE_FLUSH_THRESHOLD 500
 
 typedef struct {
     void *method;
     int (*up_ref)(void *);
     void (*free)(void *);
+    void *(*dup)(void *);
+    void (*free_dup)(void *);
 } METHOD;
 
 typedef struct {
@@ -56,50 +50,33 @@ typedef struct {
 
 DEFINE_STACK_OF(IMPLEMENTATION)
 
-typedef struct query_st {
-    struct query_st *next; /* list pointer for lookup table */
-    void *saptr; /* pointer to our owning STORED_ALGORITHM */
-    int nid; /* nid of this query */
-    int archived; /* Mark entry as no longer findable */
-    OSSL_PROVIDER *prov; /*provider this belongs to */
-    char *prop_query; /* query string */
-    METHOD method; /* METHOD for this query */
+typedef struct {
+    const OSSL_PROVIDER *provider;
+    const char *query;
+    METHOD method;
+    char body[1];
 } QUERY;
 
+DEFINE_LHASH_OF_EX(QUERY);
+
 typedef struct {
     int nid;
     STACK_OF(IMPLEMENTATION) *impls;
+    LHASH_OF(QUERY) *cache;
 } ALGORITHM;
 
-typedef struct {
-    SPARSE_ARRAY_OF(ALGORITHM) * algs;
-
-    QUERY *cache_lists[MAX_CACHE_LINES];
-    QUERY *archive;
-
-    /*
-     * Lock to protect each shard of |algs| from concurrent writing,
-     * when individual implementations or queries are inserted.  This is used
-     * by the appropriate functions here.
-     */
-    CRYPTO_RWLOCK *lock;
-    CRYPTO_RWLOCK *alock;
-
-    /* query cache specific values */
-
-} STORED_ALGORITHMS;
-
-static int ossl_method_store_atomic_insert_to_list(STORED_ALGORITHMS *sa, QUERY *new);
-static int ossl_method_store_atomic_archive(STORED_ALGORITHMS *sa, QUERY *old);
-static QUERY *ossl_method_store_atomic_find_in_list(STORED_ALGORITHMS *sa, int nid,
-    OSSL_PROVIDER *prov, const char *prop_query);
-static void ossl_cache_lists_flush(STORED_ALGORITHMS *sa);
-static void ossl_cache_lists_free(STORED_ALGORITHMS *sa);
-static void ossl_method_store_atomic_clean_archive(STORED_ALGORITHMS *sa);
-
 struct ossl_method_store_st {
     OSSL_LIB_CTX *ctx;
-    STORED_ALGORITHMS *algs;
+    SPARSE_ARRAY_OF(ALGORITHM) * algs;
+
+    /* (nid, propq) -> method  */
+    HT *frozen_algs;
+    /*
+     * Lock to protect the |algs| array from concurrent writing, when
+     * individual implementations or queries are inserted.  This is used
+     * by the appropriate functions here.
+     */
+    CRYPTO_RWLOCK *lock;
     /*
      * Lock to reserve the whole store.  This is used when fetching a set
      * of algorithms, via these functions, found in crypto/core_fetch.c:
@@ -107,12 +84,40 @@ struct ossl_method_store_st {
      * ossl_method_construct_unreserve_store()
      */
     CRYPTO_RWLOCK *biglock;
+
+    /* query cache specific values */
+
+    /* Count of the query cache entries for all algs */
+    size_t cache_nelem;
+
+    /* Flag: 1 if query cache entries for all algs need flushing */
+    int cache_need_flush;
+
+    /* Flag: 1 if method store is frozen */
+    int frozen;
+
+    /* Property query associated with frozen state */
+    char *frozen_propq;
 };
 
+typedef struct {
+    LHASH_OF(QUERY) *cache;
+    size_t nelem;
+    uint32_t seed;
+    unsigned char using_global_seed;
+} IMPL_CACHE_FLUSH;
+
 DEFINE_SPARSE_ARRAY_OF(ALGORITHM);
 
 DEFINE_STACK_OF(ALGORITHM)
 
+HT_START_KEY_DEFN(frozen_cache_key)
+HT_DEF_KEY_FIELD_CHAR_ARRAY(name, 64)
+/* TODO(FREEZE): allow variable length propq */
+HT_DEF_KEY_FIELD_CHAR_ARRAY(propq, 64)
+HT_DEF_KEY_FIELD(op_id, unsigned int)
+HT_END_KEY_DEFN(FROZEN_CACHE_KEY)
+
 typedef struct ossl_global_properties_st {
     OSSL_PROPERTY_LIST *list;
 #ifndef FIPS_MODULE
@@ -120,32 +125,9 @@ typedef struct ossl_global_properties_st {
 #endif
 } OSSL_GLOBAL_PROPERTIES;
 
-#define stored_algs_shard(store, nid) (&(store)->algs[(nid) & (NUM_SHARDS - 1)])
-
-static void ossl_method_cache_flush_alg(STORED_ALGORITHMS *sa,
+static void ossl_method_cache_flush_alg(OSSL_METHOD_STORE *store,
     ALGORITHM *alg);
-static void ossl_method_cache_flush(STORED_ALGORITHMS *sa, int nid);
-
-static ossl_inline QUERY *QUERY_new(size_t prop_query_len)
-{
-    /*
-     * allocate a new QUERY with the associated property query buffer
-     * immediately following it
-     */
-    QUERY *new = OPENSSL_malloc(sizeof(QUERY) + prop_query_len + 1);
-    if (new != NULL)
-        new->prop_query = (char *)(new + 1);
-    return new;
-}
-
-static ossl_inline void QUERY_free(QUERY *q)
-{
-    /*
-     * because we allocate the QUERY with its property query string
-     * as one contiguous chunk, this frees both
-     */
-    OPENSSL_free(q);
-}
+static void ossl_method_cache_flush(OSSL_METHOD_STORE *store, int nid);
 
 /* Global properties are stored per library context */
 void ossl_ctx_global_properties_free(void *vglobp)
@@ -206,21 +188,61 @@ static void ossl_method_free(METHOD *method)
     (*method->free)(method->method);
 }
 
-static __owur int ossl_property_read_lock(STORED_ALGORITHMS *p)
+static void ossl_method_free_frozen(METHOD *method)
+{
+    (*method->free_dup)(method->method);
+}
+
+static METHOD *ossl_method_dup(METHOD *method)
+{
+    METHOD *dup;
+
+    dup = OPENSSL_zalloc(sizeof(*dup));
+    if (dup == NULL)
+        return NULL;
+
+    memcpy(dup, method, sizeof(*dup));
+
+    dup->method = (*method->dup)(method->method);
+    if (dup->method == NULL) {
+        OPENSSL_free(dup);
+        return NULL;
+    }
+
+    return dup;
+}
+
+static __owur int ossl_property_read_lock(OSSL_METHOD_STORE *p)
 {
     return p != NULL ? CRYPTO_THREAD_read_lock(p->lock) : 0;
 }
 
-static __owur int ossl_property_write_lock(STORED_ALGORITHMS *p)
+static __owur int ossl_property_write_lock(OSSL_METHOD_STORE *p)
 {
     return p != NULL ? CRYPTO_THREAD_write_lock(p->lock) : 0;
 }
 
-static int ossl_property_unlock(STORED_ALGORITHMS *p)
+static int ossl_property_unlock(OSSL_METHOD_STORE *p)
 {
     return p != 0 ? CRYPTO_THREAD_unlock(p->lock) : 0;
 }
 
+static unsigned long query_hash(const QUERY *a)
+{
+    return OPENSSL_LH_strhash(a->query);
+}
+
+static int query_cmp(const QUERY *a, const QUERY *b)
+{
+    int res = strcmp(a->query, b->query);
+
+    if (res == 0 && a->provider != NULL && b->provider != NULL)
+        res = b->provider > a->provider ? 1
+            : b->provider < a->provider ? -1
+                                        : 0;
+    return res;
+}
+
 static void impl_free(IMPLEMENTATION *impl)
 {
     if (impl != NULL) {
@@ -229,92 +251,32 @@ static void impl_free(IMPLEMENTATION *impl)
     }
 }
 
-static ossl_inline void impl_cache_free_unlinked(QUERY *elem)
+static void impl_cache_free(QUERY *elem)
 {
     if (elem != NULL) {
         ossl_method_free(&elem->method);
-        QUERY_free(elem);
+        OPENSSL_free(elem);
     }
 }
 
-static void impl_cache_flush_alg(ALGORITHM *alg, STORED_ALGORITHMS *sa)
+static void impl_cache_flush_alg(ossl_uintmax_t idx, ALGORITHM *alg)
 {
-    QUERY *q;
-    int i;
-
-    /*
-     * Instead of iterating over the hashtable with the
-     * ossl_ht_foreach_until function, we just traverse the
-     * linked list, as it much faster this way, as we avoid having
-     * to visit lots of potentially empty nodes
-     */
-    for (i = 0; i < MAX_CACHE_LINES; i++) {
-        if (!CRYPTO_atomic_load_ptr((void **)&sa->cache_lists[i], (void **)&q, sa->alock))
-            return;
-        while (q != NULL) {
-            if (q->nid == alg->nid)
-                ossl_method_store_atomic_archive(sa, q);
-            if (!CRYPTO_atomic_load_ptr((void **)&q->next, (void **)&q, sa->alock))
-                return;
-        }
-    }
+    lh_QUERY_doall(alg->cache, &impl_cache_free);
+    lh_QUERY_flush(alg->cache);
 }
 
 static void alg_cleanup(ossl_uintmax_t idx, ALGORITHM *a, void *arg)
 {
-    STORED_ALGORITHMS *sa = arg;
+    OSSL_METHOD_STORE *store = arg;
 
     if (a != NULL) {
         sk_IMPLEMENTATION_pop_free(a->impls, &impl_free);
+        lh_QUERY_doall(a->cache, &impl_cache_free);
+        lh_QUERY_free(a->cache);
         OPENSSL_free(a);
     }
-    if (sa != NULL)
-        ossl_sa_ALGORITHM_set(sa->algs, idx, NULL);
-}
-
-static void stored_algs_free(STORED_ALGORITHMS *sa)
-{
-    if (sa == NULL)
-        return;
-
-    for (int i = 0; i < NUM_SHARDS; ++i) {
-        ossl_sa_ALGORITHM_doall_arg(sa[i].algs, &alg_cleanup, &sa[i]);
-        ossl_sa_ALGORITHM_free(sa[i].algs);
-        ossl_cache_lists_free(&sa[i]);
-        CRYPTO_THREAD_lock_free(sa[i].lock);
-        CRYPTO_THREAD_lock_free(sa[i].alock);
-    }
-
-    OPENSSL_free(sa);
-}
-
-static STORED_ALGORITHMS *stored_algs_new(OSSL_LIB_CTX *ctx)
-{
-    STORED_ALGORITHMS *ret;
-
-    ret = OPENSSL_calloc(NUM_SHARDS, sizeof(STORED_ALGORITHMS));
-    if (ret == NULL)
-        return NULL;
-
-    for (int i = 0; i < NUM_SHARDS; ++i) {
-        ret[i].algs = ossl_sa_ALGORITHM_new();
-        if (ret[i].algs == NULL)
-            goto err;
-
-        ret[i].lock = CRYPTO_THREAD_lock_new();
-        if (ret[i].lock == NULL)
-            goto err;
-        ret[i].alock = CRYPTO_THREAD_lock_new();
-        if (ret[i].alock == NULL)
-            goto err;
-    }
-
-    return ret;
-
-err:
-    stored_algs_free(ret);
-
-    return NULL;
+    if (store != NULL)
+        ossl_sa_ALGORITHM_set(store->algs, idx, NULL);
 }
 
 /*
@@ -328,7 +290,8 @@ OSSL_METHOD_STORE *ossl_method_store_new(OSSL_LIB_CTX *ctx)
     res = OPENSSL_zalloc(sizeof(*res));
     if (res != NULL) {
         res->ctx = ctx;
-        if ((res->algs = stored_algs_new(ctx)) == NULL
+        if ((res->algs = ossl_sa_ALGORITHM_new()) == NULL
+            || (res->lock = CRYPTO_THREAD_lock_new()) == NULL
             || (res->biglock = CRYPTO_THREAD_lock_new()) == NULL) {
             ossl_method_store_free(res);
             return NULL;
@@ -339,12 +302,17 @@ OSSL_METHOD_STORE *ossl_method_store_new(OSSL_LIB_CTX *ctx)
 
 void ossl_method_store_free(OSSL_METHOD_STORE *store)
 {
-    if (store == NULL)
-        return;
-
-    stored_algs_free(store->algs);
-    CRYPTO_THREAD_lock_free(store->biglock);
-    OPENSSL_free(store);
+    if (store != NULL) {
+        if (store->algs != NULL)
+            ossl_sa_ALGORITHM_doall_arg(store->algs, &alg_cleanup, store);
+        if (store->frozen_algs != NULL)
+            ossl_ht_free(store->frozen_algs);
+        ossl_sa_ALGORITHM_free(store->algs);
+        CRYPTO_THREAD_lock_free(store->lock);
+        CRYPTO_THREAD_lock_free(store->biglock);
+        OPENSSL_free(store->frozen_propq);
+        OPENSSL_free(store);
+    }
 }
 
 int ossl_method_lock_store(OSSL_METHOD_STORE *store)
@@ -357,14 +325,14 @@ int ossl_method_unlock_store(OSSL_METHOD_STORE *store)
     return store != NULL ? CRYPTO_THREAD_unlock(store->biglock) : 0;
 }
 
-static ALGORITHM *ossl_method_store_retrieve(STORED_ALGORITHMS *sa, int nid)
+static ALGORITHM *ossl_method_store_retrieve(OSSL_METHOD_STORE *store, int nid)
 {
-    return ossl_sa_ALGORITHM_get(sa->algs, nid);
+    return ossl_sa_ALGORITHM_get(store->algs, nid);
 }
 
-static int ossl_method_store_insert(STORED_ALGORITHMS *sa, ALGORITHM *alg)
+static int ossl_method_store_insert(OSSL_METHOD_STORE *store, ALGORITHM *alg)
 {
-    return ossl_sa_ALGORITHM_set(sa->algs, alg->nid, alg);
+    return ossl_sa_ALGORITHM_set(store->algs, alg->nid, alg);
 }
 
 /**
@@ -395,15 +363,16 @@ static int ossl_method_store_insert(STORED_ALGORITHMS *sa, ALGORITHM *alg)
 int ossl_method_store_add(OSSL_METHOD_STORE *store, const OSSL_PROVIDER *prov,
     int nid, const char *properties, void *method,
     int (*method_up_ref)(void *),
-    void (*method_destruct)(void *))
+    void (*method_destruct)(void *),
+    void *(*method_dup)(void *),
+    void (*free_frozen)(void *))
 {
-    STORED_ALGORITHMS *sa;
     ALGORITHM *alg = NULL;
     IMPLEMENTATION *impl;
     int ret = 0;
     int i;
 
-    if (nid <= 0 || method == NULL || store == NULL)
+    if (nid <= 0 || method == NULL || store == NULL || store->frozen == 1)
         return 0;
 
     if (properties == NULL)
@@ -419,16 +388,16 @@ int ossl_method_store_add(OSSL_METHOD_STORE *store, const OSSL_PROVIDER *prov,
     impl->method.method = method;
     impl->method.up_ref = method_up_ref;
     impl->method.free = method_destruct;
+    impl->method.dup = method_dup;
+    impl->method.free_dup = free_frozen;
     if (!ossl_method_up_ref(&impl->method)) {
         OPENSSL_free(impl);
         return 0;
     }
     impl->provider = prov;
 
-    sa = stored_algs_shard(store, nid);
-
     /* Insert into the hash table if required */
-    if (!ossl_property_write_lock(sa)) {
+    if (!ossl_property_write_lock(store)) {
         impl_free(impl);
         return 0;
     }
@@ -444,7 +413,7 @@ int ossl_method_store_add(OSSL_METHOD_STORE *store, const OSSL_PROVIDER *prov,
      * method to the algorithm cache, in case the one selected by the next
      * query selects a different implementation
      */
-    ossl_method_cache_flush(sa, nid);
+    ossl_method_cache_flush(store, nid);
 
     /*
      * Parse the properties associated with this method, and convert it to a
@@ -466,16 +435,16 @@ int ossl_method_store_add(OSSL_METHOD_STORE *store, const OSSL_PROVIDER *prov,
      * Check if we have an algorithm cache already for this nid.  If so use
      * it, otherwise, create it, and insert it into the store
      */
-    alg = ossl_method_store_retrieve(sa, nid);
+    alg = ossl_method_store_retrieve(store, nid);
     if (alg == NULL) {
         if ((alg = OPENSSL_zalloc(sizeof(*alg))) == NULL
-            || (alg->impls = sk_IMPLEMENTATION_new_null()) == NULL)
+            || (alg->impls = sk_IMPLEMENTATION_new_null()) == NULL
+            || (alg->cache = lh_QUERY_new(&query_hash, &query_cmp)) == NULL)
             goto err;
         alg->nid = nid;
-        if (!ossl_method_store_insert(sa, alg))
+        if (!ossl_method_store_insert(store, alg))
             goto err;
-        OSSL_TRACE2(QUERY, "Inserted an alg with nid %d into the stored algorithms %p\n",
-            nid, (void *)sa);
+        OSSL_TRACE2(QUERY, "Inserted an alg with nid %d into the store %p\n", nid, (void *)store);
     }
 
     /* Push onto stack if there isn't one there already */
@@ -501,13 +470,13 @@ int ossl_method_store_add(OSSL_METHOD_STORE *store, const OSSL_PROVIDER *prov,
         OSSL_TRACE_END(QUERY);
 #endif
     }
-    ossl_property_unlock(sa);
+    ossl_property_unlock(store);
     if (ret == 0)
         impl_free(impl);
     return ret;
 
 err:
-    ossl_property_unlock(sa);
+    ossl_property_unlock(store);
     alg_cleanup(0, alg, NULL);
     impl_free(impl);
     return 0;
@@ -517,20 +486,17 @@ int ossl_method_store_remove(OSSL_METHOD_STORE *store, int nid,
     const void *method)
 {
     ALGORITHM *alg = NULL;
-    STORED_ALGORITHMS *sa;
     int i;
 
-    if (nid <= 0 || method == NULL || store == NULL)
+    if (nid <= 0 || method == NULL || store == NULL || store->frozen == 1)
         return 0;
 
-    sa = stored_algs_shard(store, nid);
-    if (!ossl_property_write_lock(sa))
+    if (!ossl_property_write_lock(store))
         return 0;
-    ossl_method_cache_flush(sa, nid);
-    ossl_method_store_atomic_clean_archive(sa);
-    alg = ossl_method_store_retrieve(sa, nid);
+    ossl_method_cache_flush(store, nid);
+    alg = ossl_method_store_retrieve(store, nid);
     if (alg == NULL) {
-        ossl_property_unlock(sa);
+        ossl_property_unlock(store);
         return 0;
     }
 
@@ -545,16 +511,16 @@ int ossl_method_store_remove(OSSL_METHOD_STORE *store, int nid,
         if (impl->method.method == method) {
             impl_free(impl);
             (void)sk_IMPLEMENTATION_delete(alg->impls, i);
-            ossl_property_unlock(sa);
+            ossl_property_unlock(store);
             return 1;
         }
     }
-    ossl_property_unlock(sa);
+    ossl_property_unlock(store);
     return 0;
 }
 
 struct alg_cleanup_by_provider_data_st {
-    STORED_ALGORITHMS *sa;
+    OSSL_METHOD_STORE *store;
     const OSSL_PROVIDER *prov;
 };
 
@@ -616,7 +582,7 @@ alg_cleanup_by_provider(ossl_uintmax_t idx, ALGORITHM *alg, void *arg)
      * any implementation, though.
      */
     if (count > 0)
-        ossl_method_cache_flush_alg(data->sa, alg);
+        ossl_method_cache_flush_alg(data->store, alg);
 }
 
 int ossl_method_store_remove_all_provided(OSSL_METHOD_STORE *store,
@@ -624,17 +590,12 @@ int ossl_method_store_remove_all_provided(OSSL_METHOD_STORE *store,
 {
     struct alg_cleanup_by_provider_data_st data;
 
-    for (int k = 0; k < NUM_SHARDS; ++k) {
-        STORED_ALGORITHMS *sa = &store->algs[k];
-
-        if (!ossl_property_write_lock(sa))
-            return 0;
-        data.prov = prov;
-        data.sa = sa;
-        ossl_sa_ALGORITHM_doall_arg(sa->algs, &alg_cleanup_by_provider, &data);
-        ossl_method_store_atomic_clean_archive(sa);
-        ossl_property_unlock(sa);
-    }
+    if (store == NULL || store->frozen == 1 || !ossl_property_write_lock(store))
+        return 0;
+    data.prov = prov;
+    data.store = store;
+    ossl_sa_ALGORITHM_doall_arg(store->algs, &alg_cleanup_by_provider, &data);
+    ossl_property_unlock(store);
     return 1;
 }
 
@@ -673,24 +634,20 @@ void ossl_method_store_do_all(OSSL_METHOD_STORE *store,
     STACK_OF(ALGORITHM) *tmpalgs;
     ALGORITHM *alg;
 
-    if (store == NULL)
-        return;
+    if (store != NULL) {
 
-    for (int k = 0; k < NUM_SHARDS; ++k) {
-        STORED_ALGORITHMS *sa = &store->algs[k];
-
-        if (!ossl_property_read_lock(sa))
+        if (!ossl_property_read_lock(store))
             return;
 
         tmpalgs = sk_ALGORITHM_new_reserve(NULL,
-            (int)ossl_sa_ALGORITHM_num(sa->algs));
+            (int)ossl_sa_ALGORITHM_num(store->algs));
         if (tmpalgs == NULL) {
-            ossl_property_unlock(sa);
+            ossl_property_unlock(store);
             return;
         }
 
-        ossl_sa_ALGORITHM_doall_arg(sa->algs, alg_copy, tmpalgs);
-        ossl_property_unlock(sa);
+        ossl_sa_ALGORITHM_doall_arg(store->algs, alg_copy, tmpalgs);
+        ossl_property_unlock(store);
         numalgs = sk_ALGORITHM_num(tmpalgs);
         for (i = 0; i < numalgs; i++) {
             alg = sk_ALGORITHM_value(tmpalgs, i);
@@ -702,32 +659,9 @@ void ossl_method_store_do_all(OSSL_METHOD_STORE *store,
     }
 }
 
-/**
- * @brief Fetches a method from the method store matching the given properties.
- *
- * This function searches the method store for an implementation of a specified
- * method, identified by its id (nid), and matching the given property query. If
- * successful, it returns the method and its associated provider.
- *
- * @param store Pointer to the OSSL_METHOD_STORE from which to fetch the method.
- *              Must be non-null.
- * @param nid (identifier) of the method to be fetched. Must be > 0
- * @param prop_query String containing the property query to match against.
- * @param prov_rw Pointer to the OSSL_PROVIDER to restrict the search to, or
- *                to receive the matched provider.
- * @param method Pointer to receive the fetched method. Must be non-null.
- *
- * @return 1 if the method is successfully fetched, 0 on failure.
- *
- * If tracing is enabled, a message is printed indicating the property query and
- * the resolved provider.
- *
- * NOTE: The nid parameter here is _not_ a NID in the sense of the NID_* macros.
- * It is a unique internal identifier value.
- */
-int ossl_method_store_fetch(OSSL_METHOD_STORE *store,
+static int ossl_method_store_fetch_best_impl(OSSL_METHOD_STORE *store,
     int nid, const char *prop_query,
-    const OSSL_PROVIDER **prov_rw, void **method)
+    const OSSL_PROVIDER **prov_rw, IMPLEMENTATION **rbest_impl)
 {
     OSSL_PROPERTY_LIST **plp;
     ALGORITHM *alg;
@@ -736,9 +670,8 @@ int ossl_method_store_fetch(OSSL_METHOD_STORE *store,
     const OSSL_PROVIDER *prov = prov_rw != NULL ? *prov_rw : NULL;
     int ret = 0;
     int j, best = -1, score, optional;
-    STORED_ALGORITHMS *sa;
 
-    if (nid <= 0 || method == NULL || store == NULL)
+    if (nid <= 0 || store == NULL || rbest_impl == NULL)
         return 0;
 
 #if !defined(FIPS_MODULE) && !defined(OPENSSL_NO_AUTOLOAD_CONFIG)
@@ -747,23 +680,18 @@ int ossl_method_store_fetch(OSSL_METHOD_STORE *store,
         return 0;
 #endif
 
-    sa = stored_algs_shard(store, nid);
-
     /* This only needs to be a read lock, because the query won't create anything */
-    if (!ossl_property_read_lock(sa))
+    if (!ossl_property_read_lock(store))
         return 0;
 
-    OSSL_TRACE2(QUERY, "Retrieving by nid %d from stored algorithms %p\n",
-        nid, (void *)sa);
-    alg = ossl_method_store_retrieve(sa, nid);
+    OSSL_TRACE2(QUERY, "Retrieving by nid %d from store %p\n", nid, (void *)store);
+    alg = ossl_method_store_retrieve(store, nid);
     if (alg == NULL) {
-        ossl_property_unlock(sa);
-        OSSL_TRACE2(QUERY, "Failed to retrieve by nid %d from stored algorithms %p\n",
-            nid, (void *)sa);
+        ossl_property_unlock(store);
+        OSSL_TRACE2(QUERY, "Failed to retrieve by nid %d from store %p\n", nid, (void *)store);
         return 0;
     }
-    OSSL_TRACE2(QUERY, "Retrieved by nid %d from stored algorithms %p\n",
-        nid, (void *)sa);
+    OSSL_TRACE2(QUERY, "Retrieved by nid %d from store %p\n", nid, (void *)store);
 
     /*
      * If a property query string is provided, convert it to an
@@ -798,8 +726,7 @@ int ossl_method_store_fetch(OSSL_METHOD_STORE *store,
      */
     if (pq == NULL) {
         for (j = 0; j < sk_IMPLEMENTATION_num(alg->impls); j++) {
-            impl = sk_IMPLEMENTATION_value(alg->impls, j);
-            if (impl != NULL
+            if ((impl = sk_IMPLEMENTATION_value(alg->impls, j)) != NULL
                 && (prov == NULL || impl->provider == prov)) {
                 best_impl = impl;
                 ret = 1;
@@ -816,8 +743,7 @@ int ossl_method_store_fetch(OSSL_METHOD_STORE *store,
      */
     optional = ossl_property_has_optional(pq);
     for (j = 0; j < sk_IMPLEMENTATION_num(alg->impls); j++) {
-        impl = sk_IMPLEMENTATION_value(alg->impls, j);
-        if (impl != NULL
+        if ((impl = sk_IMPLEMENTATION_value(alg->impls, j)) != NULL
             && (prov == NULL || impl->provider == prov)) {
             score = ossl_property_match_count(pq, impl->properties);
             if (score > best) {
@@ -831,17 +757,9 @@ int ossl_method_store_fetch(OSSL_METHOD_STORE *store,
     }
 fin:
     if (ret) {
-        *method = best_impl->method.method;
+        *rbest_impl = best_impl;
         if (prov_rw != NULL)
             *prov_rw = best_impl->provider;
-#ifdef OPENSSL_NO_CACHED_FETCH
-        if (!ossl_method_up_ref(&best_impl->method)) {
-            ret = 0;
-            *method = NULL;
-            if (prov_rw != NULL)
-                *prov_rw = NULL;
-        }
-#endif
     } else {
         ret = 0;
     }
@@ -861,429 +779,192 @@ fin:
     OSSL_TRACE_END(QUERY);
 #endif
 
-    ossl_property_unlock(sa);
+    ossl_property_unlock(store);
     ossl_property_free(p2);
     return ret;
 }
 
-static void ossl_method_cache_flush_alg(STORED_ALGORITHMS *sa,
+/**
+ * @brief Fetches a method from the method store matching the given properties.
+ *
+ * This function searches the method store for an implementation of a specified
+ * method, identified by its id (nid), and matching the given property query. If
+ * successful, it returns the method and its associated provider.
+ *
+ * @param store Pointer to the OSSL_METHOD_STORE from which to fetch the method.
+ *              Must be non-null.
+ * @param nid (identifier) of the method to be fetched. Must be > 0
+ * @param prop_query String containing the property query to match against.
+ * @param prov_rw Pointer to the OSSL_PROVIDER to restrict the search to, or
+ *                to receive the matched provider.
+ * @param method Pointer to receive the fetched method. Must be non-null.
+ *
+ * @return 1 if the method is successfully fetched, 0 on failure.
+ *
+ * If tracing is enabled, a message is printed indicating the property query and
+ * the resolved provider.
+ *
+ * NOTE: The nid parameter here is _not_ a NID in the sense of the NID_* macros.
+ * It is a unique internal identifier value.
+ */
+int ossl_method_store_fetch(OSSL_METHOD_STORE *store,
+    int nid, const char *prop_query,
+    const OSSL_PROVIDER **prov_rw, void **method)
+{
+    IMPLEMENTATION *best_impl = NULL;
+    int ret = 0;
+
+    if (nid <= 0 || store == NULL || method == NULL)
+        return 0;
+
+    ret = ossl_method_store_fetch_best_impl(store, nid, prop_query, prov_rw, &best_impl);
+    if (ret && ossl_method_up_ref(&best_impl->method))
+        *method = best_impl->method.method;
+    else
+        ret = 0;
+
+    return ret;
+}
+
+static void ossl_method_cache_flush_alg(OSSL_METHOD_STORE *store,
     ALGORITHM *alg)
 {
-    impl_cache_flush_alg(alg, sa);
+    store->cache_nelem -= lh_QUERY_num_items(alg->cache);
+    impl_cache_flush_alg(0, alg);
 }
 
-static void ossl_method_cache_flush(STORED_ALGORITHMS *sa, int nid)
+static void ossl_method_cache_flush(OSSL_METHOD_STORE *store, int nid)
 {
-    ALGORITHM *alg = ossl_method_store_retrieve(sa, nid);
+    ALGORITHM *alg = ossl_method_store_retrieve(store, nid);
 
     if (alg != NULL)
-        ossl_method_cache_flush_alg(sa, alg);
-}
-
-static void ossl_cache_lists_flush(STORED_ALGORITHMS *sa)
-{
-    int i;
-    QUERY *idx, *idxn;
-
-    for (i = 0; i < MAX_CACHE_LINES; i++) {
-        if (!CRYPTO_atomic_load_ptr((void **)&sa->cache_lists[i], (void **)&idx, sa->alock))
-            break;
-        while (idx != NULL) {
-            if (!CRYPTO_atomic_load_ptr((void **)&idx->next, (void **)&idxn, sa->alock))
-                break;
-            ossl_method_store_atomic_archive(sa, idx);
-            idx = idxn;
-        }
-    }
-}
-
-static void ossl_cache_lists_free(STORED_ALGORITHMS *sa)
-{
-    int i;
-    QUERY *idx, *idxn;
-
-    for (i = 0; i < MAX_CACHE_LINES; i++) {
-        if (!CRYPTO_atomic_load_ptr((void **)&sa->cache_lists[i], (void **)&idx, sa->alock))
-            return;
-        while (idx != NULL) {
-            if (!CRYPTO_atomic_load_ptr((void **)&idx->next, (void **)&idxn, sa->alock))
-                return;
-            impl_cache_free_unlinked(idx);
-            idx = idxn;
-        }
-    }
-
-    if (!CRYPTO_atomic_load_ptr((void **)&sa->archive, (void **)&idx, sa->alock))
-        return;
-    while (idx != NULL) {
-        if (!CRYPTO_atomic_load_ptr((void **)&idx->next, (void **)&idxn, sa->alock))
-            return;
-        impl_cache_free_unlinked(idx);
-        idx = idxn;
-    }
+        ossl_method_cache_flush_alg(store, alg);
 }
 
 int ossl_method_store_cache_flush_all(OSSL_METHOD_STORE *store)
 {
-    for (int i = 0; i < NUM_SHARDS; ++i) {
-        STORED_ALGORITHMS *sa = &store->algs[i];
-
-        if (!ossl_property_write_lock(sa))
-            return 0;
-        ossl_cache_lists_flush(sa);
-        ossl_method_store_atomic_clean_archive(sa);
-        ossl_property_unlock(sa);
-    }
-
+    if (store == NULL || store->frozen == 1 || !ossl_property_write_lock(store))
+        return 0;
+    ossl_sa_ALGORITHM_doall(store->algs, &impl_cache_flush_alg);
+    store->cache_nelem = 0;
+    ossl_property_unlock(store);
     return 1;
 }
 
-static ossl_inline int ossl_method_store_cache_get_atomic(OSSL_METHOD_STORE *store, OSSL_PROVIDER *prov,
-    int nid, const char *prop_query, STORED_ALGORITHMS *sa, void **method)
+IMPLEMENT_LHASH_DOALL_ARG(QUERY, IMPL_CACHE_FLUSH);
+
+/*
+ * Flush an element from the query cache (perhaps).
+ *
+ * In order to avoid taking a write lock or using atomic operations
+ * to keep accurate least recently used (LRU) or least frequently used
+ * (LFU) information, the procedure used here is to stochastically
+ * flush approximately half the cache.
+ *
+ * This procedure isn't ideal, LRU or LFU would be better.  However,
+ * in normal operation, reaching a full cache would be unexpected.
+ * It means that no steady state of algorithm queries has been reached.
+ * That is, it is most likely an attack of some form.  A suboptimal clearance
+ * strategy that doesn't degrade performance of the normal case is
+ * preferable to a more refined approach that imposes a performance
+ * impact.
+ */
+static void impl_cache_flush_cache(QUERY *c, IMPL_CACHE_FLUSH *state)
 {
-    QUERY *r = NULL;
-    int res = 0;
+    uint32_t n;
 
-    r = ossl_method_store_atomic_find_in_list(sa, nid, prov, prop_query);
+    /*
+     * Implement the 32 bit xorshift as suggested by George Marsaglia in:
+     *      https://doi.org/10.18637/jss.v008.i14
+     *
+     * This is a very fast PRNG so there is no need to extract bits one at a
+     * time and use the entire value each time.
+     */
+    n = state->seed;
+    n ^= n << 13;
+    n ^= n >> 17;
+    n ^= n << 5;
+    state->seed = n;
 
-    if (r != NULL) {
-        *method = r->method.method;
-        res = 1;
-#ifdef OPENSSL_NO_CACHED_FETCH
-        if (!ossl_method_up_ref(&r->method)) {
-            *method = NULL;
-            res = 0;
-        }
-#endif
+    if ((n & 1) != 0)
+        impl_cache_free(lh_QUERY_delete(state->cache, c));
+    else
+        state->nelem++;
+}
+
+static void impl_cache_flush_one_alg(ossl_uintmax_t idx, ALGORITHM *alg,
+    void *v)
+{
+    IMPL_CACHE_FLUSH *state = (IMPL_CACHE_FLUSH *)v;
+    unsigned long orig_down_load = lh_QUERY_get_down_load(alg->cache);
+
+    state->cache = alg->cache;
+    lh_QUERY_set_down_load(alg->cache, 0);
+    lh_QUERY_doall_IMPL_CACHE_FLUSH(state->cache, &impl_cache_flush_cache,
+        state);
+    lh_QUERY_set_down_load(alg->cache, orig_down_load);
+}
+
+static void ossl_method_cache_flush_some(OSSL_METHOD_STORE *store)
+{
+    IMPL_CACHE_FLUSH state;
+    static TSAN_QUALIFIER uint32_t global_seed = 1;
+
+    state.nelem = 0;
+    state.using_global_seed = 0;
+    if ((state.seed = OPENSSL_rdtsc()) == 0) {
+        /* If there is no timer available, seed another way */
+        state.using_global_seed = 1;
+        state.seed = tsan_load(&global_seed);
     }
-
-    return res;
+    store->cache_need_flush = 0;
+    ossl_sa_ALGORITHM_doall_arg(store->algs, &impl_cache_flush_one_alg, &state);
+    store->cache_nelem = state.nelem;
+    /* Without a timer, update the global seed */
+    if (state.using_global_seed)
+        tsan_add(&global_seed, state.seed);
 }
 
 int ossl_method_store_cache_get(OSSL_METHOD_STORE *store, OSSL_PROVIDER *prov,
     int nid, const char *prop_query, void **method)
 {
-    int ret;
-    STORED_ALGORITHMS *sa;
+    ALGORITHM *alg;
+    QUERY elem, *r;
+    int res = 0;
 
     if (nid <= 0 || store == NULL || prop_query == NULL)
         return 0;
 
-    sa = stored_algs_shard(store, nid);
-
-    /*
-     * Do an atomic linked list walk to search for our entry
-     */
-    ret = ossl_method_store_cache_get_atomic(store, prov, nid, prop_query, sa,
-        method);
-
-    return ret;
-}
-
-static int ossl_method_store_atomic_archive(STORED_ALGORITHMS *sa, QUERY *old)
-{
-    if (!CRYPTO_atomic_store_int(&old->archived, 1, sa->alock))
+    if (!ossl_property_read_lock(store))
         return 0;
-    return 1;
-}
+    alg = ossl_method_store_retrieve(store, nid);
+    if (alg == NULL)
+        goto err;
 
-static ossl_inline int ossl_method_store_put_in_archive(STORED_ALGORITHMS *sa, QUERY *old)
-{
-    /*
-     * point the item we're removing's next pointer to the top of the archive list
-     * Note: We're writing to the old->next here which is shared, so that's suspicious, but
-     * because we've already removed old from the cache_list in ossl_method_store_clean_archive
-     * this is safe for the following reasons:
-     * 1) the clean path is done under a write lock, so sa->archive is guaranteed stable
-     * 2) any concurrent reader (ie ossl_method_store_cache_set|get, if visiting the old node
-     * while we're moving it, will either read the true next value (pointing to the next element
-     * in the cache_list), or the one we write here (the next list in the archive)
-     *
-     * Reading the true next value is fine, as that's the normal traversal anyway.
-     * Reading the next pointer as pointing into the archive list is not great, but in the worst
-     * case this results in a transient failed cache lookup, which just means a temporary slow path
-     * retrieval of an algorithm.
-     */
-    if (!CRYPTO_atomic_load_ptr((void **)&sa->archive, (void **)&old->next, sa->alock))
-        return 0;
-    /*
-     * And update the head of the archive list to be our new entry
-     */
-    if (!CRYPTO_atomic_store_ptr((void **)&sa->archive, (void **)&old, sa->alock))
-        return 0;
-    return 1;
-}
-
-/*
- * Migrate archived items to the archive list.  Must be done with the property write
- * lock held
- */
-static void ossl_method_store_atomic_clean_archive(STORED_ALGORITHMS *sa)
-{
-    QUERY *idx, *idxn, *tmp;
-    int archived;
-    int i;
-    int lock_failed;
-
-    /*
-     * For each of our linked lists
-     */
-    for (i = 0; i < MAX_CACHE_LINES; i++) {
-    restart_list:
-        /*
-         * Get the head of the list
-         */
-        if (!CRYPTO_atomic_load_ptr((void **)&sa->cache_lists[i], (void **)&idx, sa->alock))
-            continue;
-        /*
-         * If its NULL, the list is currently empty, move on to the next one
-         */
-        if (idx == NULL)
-            continue;
-        /*
-         * Get its archived value
-         */
-        if (!CRYPTO_atomic_load_int(&idx->archived, &archived, sa->alock))
-            continue;
-        /*
-         * Also fetch its next pointer to idxn
-         */
-        if (!CRYPTO_atomic_load_ptr((void **)&idx->next, (void **)&idxn, sa->alock))
-            continue;
-        /*
-         * If its been archived, we want to move it to the archive list
-         */
-        if (archived == 1) {
-            /*
-             * We know this is the current list head we're working with
-             * so store the next pointer to be the new list head
-             */
-            if (!CRYPTO_atomic_cmp_exch_ptr((void **)&sa->cache_lists[i], (void **)&idx, idxn, sa->alock,
-                    &lock_failed)) {
-                if (lock_failed)
-                    continue;
-                else
-                    goto restart_list;
-            }
-
-            if (!ossl_method_store_put_in_archive(sa, idx))
-                continue;
-            goto restart_list;
-        }
-
-        /*
-         * At this point our state is:
-         * idx - points to an element in cache_lists[i]
-         * idxn points to the next entry (i.e. idx->next)
-         */
-        while (idx != NULL) {
-            /*
-             * We know idx isn't archived, so we start looking at idxn
-             */
-            if (idxn != NULL) {
-                /*
-                 * if its not NULL, see if its archived
-                 */
-                if (!CRYPTO_atomic_load_int(&idxn->archived, &archived, sa->alock))
-                    break;
-                /*
-                 * If it is, remove it
-                 */
-                if (archived == 1) {
-                    /*
-                     * Start by making idx skip idxn in the list
-                     * First load the expected next value of idx->next
-                     */
-                    if (!CRYPTO_atomic_load_ptr((void **)&idx->next, (void **)&tmp, sa->alock))
-                        break;
-
-                    /*
-                     * Now compare the value of idx->next to what we just loaded to tmp above
-                     * if they match, we can safely update idx->next to skip the idxn entry
-                     * by pointing idx->next to idxn->next.
-                     * If the comparison fails, then we need to start the list traversal over again.
-                     * Note: This should never happen, as once an item is in the list, this is the
-                     * only path in which an in-list item has its next pointer mutated, and this
-                     * occurs under a write lock, but we should be safe here
-                     */
-                    if (!CRYPTO_atomic_cmp_exch_ptr((void **)&idx->next,
-                            (void **)&tmp, (void *)idxn->next,
-                            sa->alock, &lock_failed)) {
-                        if (lock_failed)
-                            break;
-                        /*
-                         * The list was mutated while we were trying to mutate it
-                         * Normally we would just use the reloaded value of tmp here to re-attempt
-                         * the removal, but since idx was changed underneath us, we don't know where
-                         * we are in the list anymore.  Its safer to just restart the whole traversal
-                         */
-                        goto restart_list;
-                    }
-
-                    if (!ossl_method_store_put_in_archive(sa, idxn))
-                        break;
-
-                    /*
-                     * Idx just got a new next pointer above, so just update idxn, so we are sure that idx
-                     * still isn't archived
-                     */
-                    if (!CRYPTO_atomic_load_ptr((void **)&idx->next, (void **)&idxn, sa->alock))
-                        break;
-                } else {
-                    /*
-                     * idxn wasn't archived, so we need to advance both pointers here
-                     */
-                    idx = idxn;
-                    if (!CRYPTO_atomic_load_ptr((void **)&idx->next, (void **)&idxn, sa->alock))
-                        break;
-                }
-            } else {
-                /*
-                 * idxn is NULL, that means we're at the end of the list.
-                 * Just advance idx to idxn and the loop will break on the next iteration
-                 */
-                idx = idxn;
-            }
-        }
-    }
-}
-
-static QUERY *ossl_method_store_atomic_find_in_list(STORED_ALGORITHMS *sa, int nid,
-    OSSL_PROVIDER *prov, const char *prop_query)
-{
-    int nididx = (nid >> NUM_SHARDS_BITS) & (MAX_CACHE_LINES - 1);
-    int archived;
-    QUERY *idx;
-    QUERY *ret = NULL;
-
-    if (!CRYPTO_atomic_load_ptr((void **)&sa->cache_lists[nididx], (void **)&idx, sa->alock))
-        goto out;
-
-    while (idx != NULL) {
-        if (!CRYPTO_atomic_load_int(&idx->archived, &archived, sa->alock))
-            goto out;
-        if (archived == 0 && idx->nid == nid && idx->prov == prov
-            && (strcmp(idx->prop_query, prop_query) == 0)) {
-            ret = idx;
-            break;
-        }
-        if (!CRYPTO_atomic_load_ptr((void **)&idx->next, (void **)&idx, sa->alock))
-            goto out;
-    }
-out:
-    return ret;
-}
-
-static int ossl_method_store_atomic_insert_to_list(STORED_ALGORITHMS *sa, QUERY *new)
-{
-    int nid = (new->nid >> NUM_SHARDS_BITS) & (MAX_CACHE_LINES - 1);
-    QUERY *headptr;
-    int ret = 0;
-    int lock_failed;
-
-    if (!CRYPTO_atomic_load_ptr((void **)&sa->cache_lists[nid], (void **)&headptr, sa->alock))
-        goto out;
-try_again:
-    if (!CRYPTO_atomic_store_ptr((void **)&new->next, (void **)&headptr, sa->alock))
-        goto out;
-    if (!CRYPTO_atomic_cmp_exch_ptr((void **)&sa->cache_lists[nid], (void **)&headptr, new, sa->alock,
-            &lock_failed)) {
-        if (lock_failed == 1)
-            goto out;
-        goto try_again;
-    }
-    ret = 1;
-out:
-    return ret;
-}
-
-static ossl_inline int ossl_method_store_cache_set_atomic(OSSL_METHOD_STORE *store, OSSL_PROVIDER *prov,
-    int nid, const char *prop_query, STORED_ALGORITHMS *sa, void *method,
-    int (*method_up_ref)(void *),
-    void (*method_destruct)(void *))
-{
-    QUERY *p = NULL;
-    int res = 1;
-
-    if (method == NULL) {
-        p = ossl_method_store_atomic_find_in_list(sa, nid, prov, prop_query);
-        if (p != NULL)
-            ossl_method_store_atomic_archive(sa, p);
-        goto end;
-    }
-
-    p = ossl_method_store_atomic_find_in_list(sa, nid, prov, prop_query);
-    if (p != NULL)
-        ossl_method_store_atomic_archive(sa, p);
-
-    p = QUERY_new(strlen(prop_query));
-    if (p != NULL) {
-        TSAN_BENIGN(p, "Unpublished value is safe on subsequent read");
-        p->saptr = sa;
-        p->nid = nid;
-        p->prov = prov;
-        p->archived = 0;
-        strcpy(p->prop_query, prop_query);
-        p->method.method = method;
-        p->method.up_ref = method_up_ref;
-        p->method.free = method_destruct;
-        if (!ossl_method_up_ref(&p->method))
-            goto err;
-
-        if (!ossl_method_store_atomic_insert_to_list(sa, p)) {
-            ossl_method_free(&p->method);
-            goto err;
-        }
-
-        /*
-         * We also want to add this method into the cache against a key computed
-         * _only_ from nid and property query.  This lets us match in the event
-         * someone does a lookup against a NULL provider (i.e. the "any provided
-         * alg will do" match).
-         *
-         * Only insert it if no NULL-provider entry exists yet for this nid and
-         * property query.  The first provider to cache this nid owns that
-         * entry, which matches the provider ossl_method_store_fetch would pick
-         * by implementation order.  Without this check, a later cache_set from
-         * a different provider would overwrite it and change which provider an
-         * "any provider" lookup resolves to.
-         */
-        if (ossl_method_store_atomic_find_in_list(sa, nid, NULL, prop_query) == NULL) {
-            p = QUERY_new(strlen(prop_query));
-            if (p == NULL)
-                goto err;
-            TSAN_BENIGN(p, "Unpublished value is safe on subsequent read");
-            p->saptr = sa;
-            p->nid = nid;
-            p->prov = NULL;
-            p->archived = 0;
-            strcpy(p->prop_query, prop_query);
-            p->method.method = method;
-            p->method.up_ref = method_up_ref;
-            p->method.free = method_destruct;
-            if (!ossl_method_up_ref(&p->method))
-                goto err;
-            if (!ossl_method_store_atomic_insert_to_list(sa, p)) {
-                ossl_method_free(&p->method);
-                goto err;
-            }
-        }
-
-        goto end;
+    elem.query = prop_query;
+    elem.provider = prov;
+    r = lh_QUERY_retrieve(alg->cache, &elem);
+    if (r == NULL)
+        goto err;
+    if (ossl_method_up_ref(&r->method)) {
+        *method = r->method.method;
+        res = 1;
     }
 err:
-    res = 0;
-    QUERY_free(p);
-end:
+    ossl_property_unlock(store);
     return res;
 }
 
 int ossl_method_store_cache_set(OSSL_METHOD_STORE *store, OSSL_PROVIDER *prov,
     int nid, const char *prop_query, void *method,
     int (*method_up_ref)(void *),
-    void (*method_destruct)(void *))
+    void (*method_destruct)(void *),
+    void *(*method_dup)(void *),
+    void (*free_dup)(void *))
 {
-    STORED_ALGORITHMS *sa;
+    QUERY elem, *old, *p = NULL;
+    ALGORITHM *alg;
+    size_t len;
     int res = 1;
 
     if (nid <= 0 || store == NULL || prop_query == NULL)
@@ -1292,13 +973,240 @@ int ossl_method_store_cache_set(OSSL_METHOD_STORE *store, OSSL_PROVIDER *prov,
     if (!ossl_assert(prov != NULL))
         return 0;
 
-    sa = stored_algs_shard(store, nid);
-
-    /*
-     * Do an atomic insert into the appropriate cache linked list
-     */
-    res = ossl_method_store_cache_set_atomic(store, prov, nid, prop_query, sa, method,
-        method_up_ref, method_destruct);
+    if (!ossl_property_write_lock(store))
+        return 0;
+    if (store->cache_need_flush)
+        ossl_method_cache_flush_some(store);
+    alg = ossl_method_store_retrieve(store, nid);
+    if (alg == NULL)
+        goto err;
 
+    if (method == NULL) {
+        elem.query = prop_query;
+        elem.provider = prov;
+        if ((old = lh_QUERY_delete(alg->cache, &elem)) != NULL) {
+            impl_cache_free(old);
+            store->cache_nelem--;
+        }
+        goto end;
+    }
+    p = OPENSSL_malloc(sizeof(*p) + (len = strlen(prop_query)));
+    if (p != NULL) {
+        p->query = p->body;
+        p->provider = prov;
+        p->method.method = method;
+        p->method.up_ref = method_up_ref;
+        p->method.free = method_destruct;
+        p->method.dup = method_dup;
+        p->method.free_dup = free_dup;
+        if (!ossl_method_up_ref(&p->method))
+            goto err;
+        memcpy((char *)p->query, prop_query, len + 1);
+        if ((old = lh_QUERY_insert(alg->cache, p)) != NULL) {
+            impl_cache_free(old);
+            goto end;
+        }
+        if (!lh_QUERY_error(alg->cache)) {
+            if (++store->cache_nelem >= IMPL_CACHE_FLUSH_THRESHOLD)
+                store->cache_need_flush = 1;
+            goto end;
+        }
+        ossl_method_free(&p->method);
+    }
+err:
+    res = 0;
+    OPENSSL_free(p);
+end:
+    ossl_property_unlock(store);
     return res;
 }
+
+int ossl_frozen_method_store_cache_get(OSSL_METHOD_STORE *store,
+    const char *alg_name, const char *prop_query, unsigned int operation_id,
+    void **method)
+{
+    FROZEN_CACHE_KEY key;
+    HT_VALUE *val;
+
+    if (store == NULL
+        || alg_name == NULL
+        || prop_query == NULL
+        || store->frozen_algs == NULL)
+        return 0;
+
+    HT_INIT_KEY(&key);
+    HT_SET_KEY_STRING_CASE(&key, name, alg_name);
+    HT_SET_KEY_STRING(&key, propq, prop_query);
+    HT_SET_KEY_FIELD(&key, op_id, operation_id);
+
+    val = ossl_ht_get(store->frozen_algs, TO_HT_KEY(&key));
+    if (val == NULL)
+        return 1;
+    *method = ((METHOD *)val->value)->method;
+
+    return 1;
+}
+
+struct alg_freeze_st {
+    OSSL_METHOD_STORE *store;
+    int nid;
+
+    int ret;
+};
+
+static void frozen_cache_free(HT_VALUE *val)
+{
+    METHOD *method = (METHOD *)val->value;
+    if (method == NULL || method->free_dup == NULL)
+        return;
+    ossl_method_free_frozen(method);
+
+    OPENSSL_free(method);
+}
+
+static int freeze_alg(OSSL_METHOD_STORE *store, ALGORITHM *alg,
+    const char *propq, const char *alg_name, int operation_id)
+{
+    int ret = 0;
+    IMPLEMENTATION *best_impl = NULL;
+    FROZEN_CACHE_KEY key;
+    HT_VALUE val = { 0 };
+    const OSSL_PROVIDER *prov = NULL;
+
+    HT_INIT_KEY(&key);
+    HT_SET_KEY_STRING_CASE(&key, name, alg_name);
+    HT_SET_KEY_STRING(&key, propq, propq);
+    HT_SET_KEY_FIELD(&key, op_id, operation_id);
+
+    if (ossl_ht_get(store->frozen_algs, TO_HT_KEY(&key)) != NULL)
+        return 1;
+
+    ret = ossl_method_store_fetch_best_impl(store,
+        alg->nid, propq, &prov, &best_impl);
+    if (ret == 0 || best_impl == NULL
+        || best_impl->method.dup == NULL
+        || best_impl->method.free_dup == NULL)
+        return 1;
+
+    val.value = ossl_method_dup(&best_impl->method);
+    if (val.value == NULL)
+        return ret;
+
+    ret = ossl_ht_insert(store->frozen_algs, TO_HT_KEY(&key), &val, NULL);
+    if (ret <= 0) {
+        frozen_cache_free(&val);
+        return 0;
+    }
+
+    return 1;
+}
+
+static void alg_freeze(ossl_uintmax_t idx, ALGORITHM *alg, void *arg)
+{
+    struct alg_freeze_st *af = arg;
+    OSSL_NAMEMAP *nm = ossl_namemap_stored(af->store->ctx);
+    int name_id;
+    unsigned int op_id;
+    const char *name;
+    int i = 0;
+
+    if (alg == NULL
+        || !evp_method_id2name_id_op_id(alg->nid, &name_id, &op_id)) {
+        af->ret = 0;
+        return;
+    }
+
+    for (;;) {
+        name = ossl_namemap_num2name(nm, name_id, i++);
+        if (name == NULL)
+            break;
+        if (*af->store->frozen_propq != '\0') {
+            af->ret = freeze_alg(af->store, alg, af->store->frozen_propq, name, op_id);
+            if (!af->ret)
+                return;
+        }
+        af->ret = freeze_alg(af->store, alg, "", name, op_id);
+        if (!af->ret)
+            return;
+    }
+}
+
+/**
+ * @brief Freezes the method store's cache into a hash table.
+ *
+ * This function creates a frozen copy of the method store's cache, storing it
+ * in a hash table for efficient retrieval. Each entry in the cache is duplicated
+ * to ensure that the frozen cache is independent of the original store.
+ *
+ * @param store Pointer to the OSSL_METHOD_STORE to be frozen.
+ *
+ * @return 1 on success, 0 on failure.
+ *
+ * If the store is NULL or if any duplication fails, the function returns 0.
+ * On success, it returns 1 after populating the frozen cache.
+ */
+int ossl_method_store_freeze_cache(OSSL_METHOD_STORE *store, const char *propq)
+{
+    HT_CONFIG ht_conf = {
+        .ht_free_fn = frozen_cache_free,
+        .init_neighborhoods = store->cache_nelem,
+        .collision_check = 1,
+        .no_rcu = 1,
+    };
+    struct alg_freeze_st af = {
+        .store = store,
+        .ret = 1,
+    };
+    propq = propq != NULL ? propq : "";
+
+    if (store == NULL || store->frozen == 1)
+        return 0;
+
+    store->frozen_propq = OPENSSL_strdup(propq);
+    if (store->frozen_propq == NULL)
+        goto err;
+
+    store->frozen_algs = ossl_ht_new(&ht_conf);
+    if (store->frozen_algs == NULL)
+        goto err;
+
+    if (evp_md_fetch_all(store->ctx) <= 0
+        || evp_cipher_fetch_all(store->ctx) <= 0
+        || evp_rand_fetch_all(store->ctx) <= 0
+        || evp_mac_fetch_all(store->ctx) <= 0
+        || evp_keymgmt_fetch_all(store->ctx) <= 0
+        || evp_kdf_fetch_all(store->ctx) <= 0
+        || evp_kem_fetch_all(store->ctx) <= 0
+        || evp_asym_cipher_fetch_all(store->ctx) <= 0
+        || evp_keyexch_fetch_all(store->ctx) <= 0
+        || evp_skeymgmt_fetch_all(store->ctx) <= 0)
+        goto err;
+
+    ossl_sa_ALGORITHM_doall_arg(store->algs, &alg_freeze, &af);
+    if (af.ret <= 0)
+        goto err;
+
+    store->frozen = 1;
+
+    return 1;
+
+err:
+    OPENSSL_free(store->frozen_propq);
+    ossl_ht_free(store->frozen_algs);
+    store->frozen_algs = NULL;
+    store->frozen_propq = NULL;
+
+    return 0;
+}
+
+int ossl_method_store_is_frozen(OSSL_METHOD_STORE *store)
+{
+    return store != NULL && store->frozen == 1;
+}
+
+const char *ossl_method_store_frozen_propq(OSSL_METHOD_STORE *store)
+{
+    if (store == NULL)
+        return NULL;
+    return store->frozen_propq;
+}
diff --git a/crypto/property/property_local.h b/crypto/property/property_local.h
index 0e63b2b67f..98484240bb 100644
--- a/crypto/property/property_local.h
+++ b/crypto/property/property_local.h
@@ -8,9 +8,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_PROPERTY_PROPERTY_LOCAL_H)
-#define OSSL_LIBCRYPTO_PROPERTY_PROPERTY_LOCAL_H
-
 #include 
 #include "internal/property.h"
 
@@ -58,5 +55,3 @@ int ossl_property_has_optional(const OSSL_PROPERTY_LIST *query);
 OSSL_PROPERTY_LIST *ossl_prop_defn_get(OSSL_LIB_CTX *ctx, const char *prop);
 int ossl_prop_defn_set(OSSL_LIB_CTX *ctx, const char *prop,
     OSSL_PROPERTY_LIST **pl);
-
-#endif /* !defined(OSSL_LIBCRYPTO_PROPERTY_PROPERTY_LOCAL_H) */
diff --git a/crypto/property/property_query.c b/crypto/property/property_query.c
index 6b6b96a4ee..f5daca2aad 100644
--- a/crypto/property/property_query.c
+++ b/crypto/property/property_query.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -30,7 +30,7 @@ ossl_property_find_property(const OSSL_PROPERTY_LIST *list,
         return NULL;
 
     return ossl_bsearch(&name_idx, list->properties, list->num_properties,
-        sizeof(*list->properties), &property_idx_cmp, NULL, 0);
+        sizeof(*list->properties), &property_idx_cmp, 0);
 }
 
 OSSL_PROPERTY_TYPE ossl_property_get_type(const OSSL_PROPERTY_DEFINITION *prop)
diff --git a/crypto/provider_core.c b/crypto/provider_core.c
index 93732995be..0e33e750d9 100644
--- a/crypto/provider_core.c
+++ b/crypto/provider_core.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -486,7 +486,7 @@ int ossl_provider_up_ref(OSSL_PROVIDER *prov)
 {
     int ref = 0;
 
-    if (!CRYPTO_UP_REF(&prov->refcnt, &ref))
+    if (CRYPTO_UP_REF(&prov->refcnt, &ref) <= 0)
         return 0;
 
 #ifndef FIPS_MODULE
@@ -1134,7 +1134,7 @@ static int provider_init(OSSL_PROVIDER *prov)
         prov->error_strings[0].error = ERR_PACK(prov->error_lib, 0, 0);
         prov->error_strings[0].string = prov->name;
         /*
-         * Copy reasonstrings item 0..cnt-1 to prov->error_strings positions
+         * Copy reasonstrings item 0..cnt-1 to prov->error_trings positions
          * 1..cnt.
          */
         for (cnt2 = 1; cnt2 <= cnt; cnt2++) {
@@ -1576,7 +1576,7 @@ int ossl_provider_doall_activated(OSSL_LIB_CTX *ctx,
              * to avoid upping the ref count on the parent provider, which we
              * must not do while holding locks.
              */
-            if (!CRYPTO_UP_REF(&prov->refcnt, &ref)) {
+            if (CRYPTO_UP_REF(&prov->refcnt, &ref) <= 0) {
                 CRYPTO_THREAD_unlock(prov->flag_lock);
                 goto err_unlock;
             }
@@ -2456,6 +2456,7 @@ static void core_self_test_get_callback(OPENSSL_CORE_CTX *libctx,
     OSSL_SELF_TEST_get_callback((OSSL_LIB_CTX *)libctx, cb, cbarg);
 }
 
+#ifdef OPENSSL_NO_FIPS_JITTER
 static size_t rand_get_entropy(const OSSL_CORE_HANDLE *handle,
     unsigned char **pout, int entropy,
     size_t min_len, size_t max_len)
@@ -2463,6 +2464,31 @@ static size_t rand_get_entropy(const OSSL_CORE_HANDLE *handle,
     return ossl_rand_get_entropy((OSSL_LIB_CTX *)core_get_libctx(handle),
         pout, entropy, min_len, max_len);
 }
+#else
+/*
+ * OpenSSL FIPS providers prior to 3.2 call rand_get_entropy API from
+ * core, instead of the newer get_user_entropy. Newer API call honors
+ * runtime configuration of random seed source and can be configured
+ * to use os getranom() or another seed source, such as
+ * JITTER. However, 3.0.9 only calls this API. Note that no other
+ * providers known to use this, and it is core <-> provider only
+ * API. Public facing EVP and getrandom bytes already correctly honor
+ * runtime configuration for seed source. There are no other providers
+ * packaged in Wolfi, or even known to exist that use this api. Thus
+ * it is safe to say any caller of this API is in fact 3.0.9 FIPS
+ * provider. Also note that the passed in handle is invalid and cannot
+ * be safely dereferences in such cases. Due to a bug in FIPS
+ * providers 3.0.0, 3.0.8 and 3.0.9. See
+ * https://github.com/openssl/openssl/blob/master/doc/internal/man3/ossl_rand_get_entropy.pod#notes
+ */
+size_t ossl_rand_jitter_get_seed(unsigned char **, int, size_t, size_t);
+static size_t rand_get_entropy(const OSSL_CORE_HANDLE *handle,
+    unsigned char **pout, int entropy,
+    size_t min_len, size_t max_len)
+{
+    return ossl_rand_jitter_get_seed(pout, entropy, min_len, max_len);
+}
+#endif
 
 static size_t rand_get_user_entropy(const OSSL_CORE_HANDLE *handle,
     unsigned char **pout, int entropy,
diff --git a/crypto/provider_local.h b/crypto/provider_local.h
index a7c830ab51..7799980808 100644
--- a/crypto/provider_local.h
+++ b/crypto/provider_local.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_PROVIDER_LOCAL_H)
-#define OSSL_LIBCRYPTO_PROVIDER_LOCAL_H
-
 #include 
 
 typedef struct {
@@ -34,5 +31,3 @@ int ossl_provider_info_add_to_store(OSSL_LIB_CTX *libctx,
 int ossl_provider_info_add_parameter(OSSL_PROVIDER_INFO *provinfo,
     const char *name,
     const char *value);
-
-#endif /* !defined(OSSL_LIBCRYPTO_PROVIDER_LOCAL_H) */
diff --git a/crypto/punycode.c b/crypto/punycode.c
index 1b99594d5b..5098437f69 100644
--- a/crypto/punycode.c
+++ b/crypto/punycode.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -271,7 +271,7 @@ int ossl_a2ulabel(const char *in, char *out, size_t outlen)
         return -1;
 
     while (1) {
-        const char *tmpptr = strchr(inptr, '.');
+        char *tmpptr = strchr(inptr, '.');
         size_t delta = tmpptr != NULL ? (size_t)(tmpptr - inptr) : strlen(inptr);
 
         if (!HAS_PREFIX(inptr, "xn--")) {
diff --git a/crypto/rand/rand_deprecated.c b/crypto/rand/rand_deprecated.c
index 07b6ff04e8..d1eabc0080 100644
--- a/crypto/rand/rand_deprecated.c
+++ b/crypto/rand/rand_deprecated.c
@@ -12,7 +12,8 @@
 #include 
 
 #if defined(OPENSSL_SYS_WINDOWS) || defined(OPENSSL_SYS_WIN32)
-#ifndef OPENSSL_NO_DEPRECATED_1_1_0
+#include 
+#if OPENSSL_API_COMPAT < 0x10100000L
 
 #define DEPRECATED_RAND_FUNCTIONS_DEFINED
 
diff --git a/crypto/rand/rand_egd.c b/crypto/rand/rand_egd.c
index c3f0a12ef1..ba8aa34dc2 100644
--- a/crypto/rand/rand_egd.c
+++ b/crypto/rand/rand_egd.c
@@ -108,13 +108,10 @@ int RAND_query_egd_bytes(const char *path, unsigned char *buf, int bytes)
 {
     FILE *fp = NULL;
     struct sockaddr_un addr;
-    int mybuffer, ret = -1, i, numbytes, fd = -1;
+    int mybuffer, ret = -1, i, numbytes, fd;
     unsigned char tempbuf[255];
-#if defined(OPENSSL_SYS_TANDEM)
-    int hpns_connect_attempt = 0;
-#endif
 
-    if (bytes <= 0 || bytes > (int)sizeof(tempbuf))
+    if (bytes > (int)sizeof(tempbuf))
         return -1;
 
     /* Make socket. */
@@ -129,8 +126,9 @@ int RAND_query_egd_bytes(const char *path, unsigned char *buf, int bytes)
 #else
     fd = socket(AF_UNIX, SOCK_STREAM, 0);
 #endif
-    if (fd == -1)
+    if (fd == -1 || (fp = fdopen(fd, "r+")) == NULL)
         return -1;
+    setbuf(fp, NULL);
 
     /* Try to connect */
     for (;;) {
@@ -173,14 +171,6 @@ int RAND_query_egd_bytes(const char *path, unsigned char *buf, int bytes)
         }
     }
 
-    /* Create stream only after a successful connect to avoid stale FILE* on fd swap. */
-    fp = fdopen(fd, "r+");
-    if (fp == NULL) {
-        close(fd);
-        return -1;
-    }
-    setbuf(fp, NULL);
-
     /* Make request, see how many bytes we can get back. */
     tempbuf[0] = 1;
     tempbuf[1] = bytes;
@@ -190,9 +180,6 @@ int RAND_query_egd_bytes(const char *path, unsigned char *buf, int bytes)
         goto err;
     numbytes = tempbuf[0];
 
-    if (numbytes <= 0 || numbytes > bytes || numbytes > (int)sizeof(tempbuf))
-        goto err;
-
     /* Which buffer are we using? */
     mybuffer = buf == NULL;
     if (mybuffer)
@@ -209,8 +196,6 @@ int RAND_query_egd_bytes(const char *path, unsigned char *buf, int bytes)
 err:
     if (fp != NULL)
         fclose(fp);
-    else if (fd != -1)
-        close(fd);
     return ret;
 }
 
diff --git a/crypto/rand/rand_lib.c b/crypto/rand/rand_lib.c
index 63a3d1bca8..db6aeaaa2e 100644
--- a/crypto/rand/rand_lib.c
+++ b/crypto/rand/rand_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -25,6 +25,12 @@
 #include "internal/provider.h"
 #include "internal/common.h"
 
+/* clang-format off */
+#ifndef OPENSSL_DEFAULT_SEED_SRC
+#define OPENSSL_DEFAULT_SEED_SRC SEED-SRC
+#endif
+/* clang-format on */
+
 typedef struct rand_global_st {
     /*
      * The three shared DRBG instances
@@ -226,9 +232,11 @@ static int rand_set_rand_method_internal(const RAND_METHOD *meth,
         return 0;
     if (!RUN_ONCE(&rand_init, do_rand_init))
         return 0;
-    if (!CRYPTO_atomic_store_ptr((void **)&default_RAND_meth, (void **)&meth,
-            rand_meth_lock))
+
+    if (!CRYPTO_THREAD_write_lock(rand_meth_lock))
         return 0;
+    default_RAND_meth = meth;
+    CRYPTO_THREAD_unlock(rand_meth_lock);
     return 1;
 }
 
@@ -240,35 +248,26 @@ int RAND_set_rand_method(const RAND_METHOD *meth)
 const RAND_METHOD *RAND_get_rand_method(void)
 {
     const RAND_METHOD *tmp_meth = NULL;
-    int lock_failed;
 
     if (!RUN_ONCE(&rand_init, do_rand_init))
-        goto end;
-
-    if (CRYPTO_atomic_load_ptr((void **)&default_RAND_meth, (void **)&tmp_meth,
-            rand_meth_lock)) {
-        if (tmp_meth != NULL)
-            return tmp_meth;
-    } else {
         return NULL;
-    }
 
-    /*
-     * We atomically compare and exchange default_RAND_meth
-     * if default_RAND_meth is NULL, we assign ossl_rand_meth to it
-     * If this returns 1, then the exchange was successful, and we can just
-     * return &ossl_rand_meth
-     * If it fails, then the contents of default_RAND_meth are written to tmp_meth
-     * which we can just return as is
-     */
-    if (CRYPTO_atomic_cmp_exch_ptr((void **)&default_RAND_meth, (void **)&tmp_meth,
-            (void *)&ossl_rand_meth, rand_meth_lock, &lock_failed)) {
-        tmp_meth = &ossl_rand_meth;
-    } else {
-        if (lock_failed == 1)
-            return NULL;
-    }
-end:
+    if (rand_meth_lock == NULL)
+        return NULL;
+
+    if (!CRYPTO_THREAD_read_lock(rand_meth_lock))
+        return NULL;
+    tmp_meth = default_RAND_meth;
+    CRYPTO_THREAD_unlock(rand_meth_lock);
+    if (tmp_meth != NULL)
+        return tmp_meth;
+
+    if (!CRYPTO_THREAD_write_lock(rand_meth_lock))
+        return NULL;
+    if (default_RAND_meth == NULL)
+        default_RAND_meth = &ossl_rand_meth;
+    tmp_meth = default_RAND_meth;
+    CRYPTO_THREAD_unlock(rand_meth_lock);
     return tmp_meth;
 }
 #endif /* OPENSSL_NO_DEPRECATED_3_0 */
@@ -528,30 +527,22 @@ static EVP_RAND_CTX *rand_new_seed(OSSL_LIB_CTX *libctx)
     const char *propq;
     char *name;
     EVP_RAND_CTX *ctx = NULL;
-    int fallback = 0;
 #ifdef OPENSSL_NO_FIPS_JITTER
     RAND_GLOBAL *dgbl = rand_get_global(libctx);
 
     if (dgbl == NULL)
         return NULL;
     propq = dgbl->seed_propq;
-    if (dgbl->seed_name != NULL) {
-        name = dgbl->seed_name;
-    } else {
-        fallback = 1;
-        name = OPENSSL_SEED_SRC_NAME;
-    }
+    name = dgbl->seed_name != NULL ? dgbl->seed_name
+                                   : OPENSSL_MSTR(OPENSSL_DEFAULT_SEED_SRC);
 #else /* !OPENSSL_NO_FIPS_JITTER */
-    name = OPENSSL_SEED_SRC_NAME;
+    name = "JITTER";
     propq = "";
 #endif /* OPENSSL_NO_FIPS_JITTER */
 
-    ERR_set_mark();
     rand = EVP_RAND_fetch(libctx, name, propq);
-    ERR_pop_to_mark();
     if (rand == NULL) {
-        if (!fallback)
-            ERR_raise(ERR_LIB_RAND, RAND_R_UNABLE_TO_FETCH_DRBG);
+        ERR_raise(ERR_LIB_RAND, RAND_R_UNABLE_TO_FETCH_DRBG);
         goto err;
     }
     ctx = EVP_RAND_CTX_new(rand, NULL);
@@ -704,11 +695,6 @@ static EVP_RAND_CTX *rand_get0_primary(OSSL_LIB_CTX *ctx, RAND_GLOBAL *dgbl)
     if (seed == NULL) {
         ERR_set_mark();
         seed = newseed = rand_new_seed(ctx);
-        if (ERR_count_to_mark() > 0) {
-            EVP_RAND_CTX_free(newseed);
-            ERR_clear_last_mark();
-            return NULL;
-        }
         ERR_pop_to_mark();
     }
 #endif /* !FIPS_MODULE || !OPENSSL_NO_FIPS_JITTER */
diff --git a/crypto/rand/rand_uniform.c b/crypto/rand/rand_uniform.c
index 0b7f7a3c0a..877150af4e 100644
--- a/crypto/rand/rand_uniform.c
+++ b/crypto/rand/rand_uniform.c
@@ -47,7 +47,7 @@ uint32_t ossl_rand_uniform_uint32(OSSL_LIB_CTX *ctx, uint32_t upper, int *err)
      * We are generating a fixed point number on the interval [0, 1).
      * Multiplying this by the range gives us a number on [0, upper).
      * The high word of the multiplication result represents the integral
-     * part we want.  The lower word is the fractional part.  We can early exit
+     * part we want.  The lower word is the fractional part.  We can early exit if
      * if the fractional part is small enough that no carry from the next lower
      * word can cause an overflow and carry into the integer part.  This
      * happens when the fractional part is bounded by 2^32 - upper which
@@ -69,7 +69,7 @@ uint32_t ossl_rand_uniform_uint32(OSSL_LIB_CTX *ctx, uint32_t upper, int *err)
      * repeat the process with the next lower word.
      *
      * Each *bit* of randomness has a probability of one half of terminating
-     * this process, so each word beyond the first has a probability
+     * this process, so each each word beyond the first has a probability
      * of 2^-32 of not terminating the process.  That is, we're extremely
      * likely to stop very rapidly.
      */
diff --git a/crypto/rand/randfile.c b/crypto/rand/randfile.c
index c2be28a122..ab059bb5e8 100644
--- a/crypto/rand/randfile.c
+++ b/crypto/rand/randfile.c
@@ -35,7 +35,8 @@
 #ifndef OPENSSL_NO_POSIX_IO
 #include 
 #include 
-#if defined(_WIN32)
+#if defined(_WIN32) && !defined(_WIN32_WCE)
+#include 
 #include 
 #define stat _stat
 #define chmod _chmod
@@ -69,8 +70,7 @@
  * This declaration is a nasty hack to get around vms' extension to fopen for
  * passing in sharing options being disabled by /STANDARD=ANSI89
  */
-static __FILE_ptr32 (*const vms_fopen)(const char *, const char *, ...)
-    = (__FILE_ptr32 (*)(const char *, const char *, ...))fopen;
+static __FILE_ptr32 (*const vms_fopen)(const char *, const char *, ...) = (__FILE_ptr32 (*)(const char *, const char *, ...))fopen;
 #define VMS_OPEN_ATTRS \
     "shr=get,put,upd,del", "ctx=bin,stm", "rfm=stm", "rat=none", "mrs=0"
 #define openssl_fopen(fname, mode) vms_fopen((fname), (mode), VMS_OPEN_ATTRS)
@@ -272,7 +272,7 @@ const char *RAND_file_name(char *buf, size_t size)
     size_t len;
     int use_randfile = 1;
 
-#if defined(_WIN32) && defined(CP_UTF8)
+#if defined(_WIN32) && defined(CP_UTF8) && !defined(_WIN32_WCE)
     DWORD envlen;
     WCHAR *var;
 
diff --git a/crypto/rc2/rc2_cbc.c b/crypto/rc2/rc2_cbc.c
index 2a487ed507..46baa9b772 100644
--- a/crypto/rc2/rc2_cbc.c
+++ b/crypto/rc2/rc2_cbc.c
@@ -14,7 +14,7 @@
 #include "internal/deprecated.h"
 
 #include 
-#include "internal/common.h"
+#include "rc2_local.h"
 
 void RC2_cbc_encrypt(const unsigned char *in, unsigned char *out, long length,
     RC2_KEY *ks, unsigned char *iv, int encrypt)
diff --git a/crypto/rc2/rc2_local.h b/crypto/rc2/rc2_local.h
index b2be41d419..f4bd06aaa6 100644
--- a/crypto/rc2/rc2_local.h
+++ b/crypto/rc2/rc2_local.h
@@ -7,9 +7,79 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_RC2_RC2_LOCAL_H)
-#define OSSL_LIBCRYPTO_RC2_RC2_LOCAL_H
+#undef c2l
+#define c2l(c, l) (l = ((unsigned long)(*((c)++))), \
+    l |= ((unsigned long)(*((c)++))) << 8L,         \
+    l |= ((unsigned long)(*((c)++))) << 16L,        \
+    l |= ((unsigned long)(*((c)++))) << 24L)
 
-#include "internal/common.h"
+/* NOTE - c is not incremented as per c2l */
+#undef c2ln
+#define c2ln(c, l1, l2, n)                            \
+    {                                                 \
+        c += n;                                       \
+        l1 = l2 = 0;                                  \
+        switch (n) {                                  \
+        case 8:                                       \
+            l2 = ((unsigned long)(*(--(c)))) << 24L;  \
+        /* fall through */                            \
+        case 7:                                       \
+            l2 |= ((unsigned long)(*(--(c)))) << 16L; \
+        /* fall through */                            \
+        case 6:                                       \
+            l2 |= ((unsigned long)(*(--(c)))) << 8L;  \
+        /* fall through */                            \
+        case 5:                                       \
+            l2 |= ((unsigned long)(*(--(c))));        \
+        /* fall through */                            \
+        case 4:                                       \
+            l1 = ((unsigned long)(*(--(c)))) << 24L;  \
+        /* fall through */                            \
+        case 3:                                       \
+            l1 |= ((unsigned long)(*(--(c)))) << 16L; \
+        /* fall through */                            \
+        case 2:                                       \
+            l1 |= ((unsigned long)(*(--(c)))) << 8L;  \
+        /* fall through */                            \
+        case 1:                                       \
+            l1 |= ((unsigned long)(*(--(c))));        \
+        }                                             \
+    }
 
-#endif /* !defined(OSSL_LIBCRYPTO_RC2_RC2_LOCAL_H) */
+#undef l2c
+#define l2c(l, c) (*((c)++) = (unsigned char)(((l)) & 0xff), \
+    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff),          \
+    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff),         \
+    *((c)++) = (unsigned char)(((l) >> 24L) & 0xff))
+
+/* NOTE - c is not incremented as per l2c */
+#undef l2cn
+#define l2cn(l1, l2, c, n)                                    \
+    {                                                         \
+        c += n;                                               \
+        switch (n) {                                          \
+        case 8:                                               \
+            *(--(c)) = (unsigned char)(((l2) >> 24L) & 0xff); \
+        /* fall through */                                    \
+        case 7:                                               \
+            *(--(c)) = (unsigned char)(((l2) >> 16L) & 0xff); \
+        /* fall through */                                    \
+        case 6:                                               \
+            *(--(c)) = (unsigned char)(((l2) >> 8L) & 0xff);  \
+        /* fall through */                                    \
+        case 5:                                               \
+            *(--(c)) = (unsigned char)(((l2)) & 0xff);        \
+        /* fall through */                                    \
+        case 4:                                               \
+            *(--(c)) = (unsigned char)(((l1) >> 24L) & 0xff); \
+        /* fall through */                                    \
+        case 3:                                               \
+            *(--(c)) = (unsigned char)(((l1) >> 16L) & 0xff); \
+        /* fall through */                                    \
+        case 2:                                               \
+            *(--(c)) = (unsigned char)(((l1) >> 8L) & 0xff);  \
+        /* fall through */                                    \
+        case 1:                                               \
+            *(--(c)) = (unsigned char)(((l1)) & 0xff);        \
+        }                                                     \
+    }
diff --git a/crypto/rc2/rc2_skey.c b/crypto/rc2/rc2_skey.c
index 02bfe45f2d..e82a7627a0 100644
--- a/crypto/rc2/rc2_skey.c
+++ b/crypto/rc2/rc2_skey.c
@@ -14,35 +14,265 @@
 #include "internal/deprecated.h"
 
 #include 
-#include "internal/common.h"
+#include "rc2_local.h"
 
 static const unsigned char key_table[256] = {
-    0xd9, 0x78, 0xf9, 0xc4, 0x19, 0xdd, 0xb5, 0xed, 0x28, 0xe9,
-    0xfd, 0x79, 0x4a, 0xa0, 0xd8, 0x9d, 0xc6, 0x7e, 0x37, 0x83,
-    0x2b, 0x76, 0x53, 0x8e, 0x62, 0x4c, 0x64, 0x88, 0x44, 0x8b,
-    0xfb, 0xa2, 0x17, 0x9a, 0x59, 0xf5, 0x87, 0xb3, 0x4f, 0x13,
-    0x61, 0x45, 0x6d, 0x8d, 0x09, 0x81, 0x7d, 0x32, 0xbd, 0x8f,
-    0x40, 0xeb, 0x86, 0xb7, 0x7b, 0x0b, 0xf0, 0x95, 0x21, 0x22,
-    0x5c, 0x6b, 0x4e, 0x82, 0x54, 0xd6, 0x65, 0x93, 0xce, 0x60,
-    0xb2, 0x1c, 0x73, 0x56, 0xc0, 0x14, 0xa7, 0x8c, 0xf1, 0xdc,
-    0x12, 0x75, 0xca, 0x1f, 0x3b, 0xbe, 0xe4, 0xd1, 0x42, 0x3d,
-    0xd4, 0x30, 0xa3, 0x3c, 0xb6, 0x26, 0x6f, 0xbf, 0x0e, 0xda,
-    0x46, 0x69, 0x07, 0x57, 0x27, 0xf2, 0x1d, 0x9b, 0xbc, 0x94,
-    0x43, 0x03, 0xf8, 0x11, 0xc7, 0xf6, 0x90, 0xef, 0x3e, 0xe7,
-    0x06, 0xc3, 0xd5, 0x2f, 0xc8, 0x66, 0x1e, 0xd7, 0x08, 0xe8,
-    0xea, 0xde, 0x80, 0x52, 0xee, 0xf7, 0x84, 0xaa, 0x72, 0xac,
-    0x35, 0x4d, 0x6a, 0x2a, 0x96, 0x1a, 0xd2, 0x71, 0x5a, 0x15,
-    0x49, 0x74, 0x4b, 0x9f, 0xd0, 0x5e, 0x04, 0x18, 0xa4, 0xec,
-    0xc2, 0xe0, 0x41, 0x6e, 0x0f, 0x51, 0xcb, 0xcc, 0x24, 0x91,
-    0xaf, 0x50, 0xa1, 0xf4, 0x70, 0x39, 0x99, 0x7c, 0x3a, 0x85,
-    0x23, 0xb8, 0xb4, 0x7a, 0xfc, 0x02, 0x36, 0x5b, 0x25, 0x55,
-    0x97, 0x31, 0x2d, 0x5d, 0xfa, 0x98, 0xe3, 0x8a, 0x92, 0xae,
-    0x05, 0xdf, 0x29, 0x10, 0x67, 0x6c, 0xba, 0xc9, 0xd3, 0x00,
-    0xe6, 0xcf, 0xe1, 0x9e, 0xa8, 0x2c, 0x63, 0x16, 0x01, 0x3f,
-    0x58, 0xe2, 0x89, 0xa9, 0x0d, 0x38, 0x34, 0x1b, 0xab, 0x33,
-    0xff, 0xb0, 0xbb, 0x48, 0x0c, 0x5f, 0xb9, 0xb1, 0xcd, 0x2e,
-    0xc5, 0xf3, 0xdb, 0x47, 0xe5, 0xa5, 0x9c, 0x77, 0x0a, 0xa6,
-    0x20, 0x68, 0xfe, 0x7f, 0xc1, 0xad
+    0xd9,
+    0x78,
+    0xf9,
+    0xc4,
+    0x19,
+    0xdd,
+    0xb5,
+    0xed,
+    0x28,
+    0xe9,
+    0xfd,
+    0x79,
+    0x4a,
+    0xa0,
+    0xd8,
+    0x9d,
+    0xc6,
+    0x7e,
+    0x37,
+    0x83,
+    0x2b,
+    0x76,
+    0x53,
+    0x8e,
+    0x62,
+    0x4c,
+    0x64,
+    0x88,
+    0x44,
+    0x8b,
+    0xfb,
+    0xa2,
+    0x17,
+    0x9a,
+    0x59,
+    0xf5,
+    0x87,
+    0xb3,
+    0x4f,
+    0x13,
+    0x61,
+    0x45,
+    0x6d,
+    0x8d,
+    0x09,
+    0x81,
+    0x7d,
+    0x32,
+    0xbd,
+    0x8f,
+    0x40,
+    0xeb,
+    0x86,
+    0xb7,
+    0x7b,
+    0x0b,
+    0xf0,
+    0x95,
+    0x21,
+    0x22,
+    0x5c,
+    0x6b,
+    0x4e,
+    0x82,
+    0x54,
+    0xd6,
+    0x65,
+    0x93,
+    0xce,
+    0x60,
+    0xb2,
+    0x1c,
+    0x73,
+    0x56,
+    0xc0,
+    0x14,
+    0xa7,
+    0x8c,
+    0xf1,
+    0xdc,
+    0x12,
+    0x75,
+    0xca,
+    0x1f,
+    0x3b,
+    0xbe,
+    0xe4,
+    0xd1,
+    0x42,
+    0x3d,
+    0xd4,
+    0x30,
+    0xa3,
+    0x3c,
+    0xb6,
+    0x26,
+    0x6f,
+    0xbf,
+    0x0e,
+    0xda,
+    0x46,
+    0x69,
+    0x07,
+    0x57,
+    0x27,
+    0xf2,
+    0x1d,
+    0x9b,
+    0xbc,
+    0x94,
+    0x43,
+    0x03,
+    0xf8,
+    0x11,
+    0xc7,
+    0xf6,
+    0x90,
+    0xef,
+    0x3e,
+    0xe7,
+    0x06,
+    0xc3,
+    0xd5,
+    0x2f,
+    0xc8,
+    0x66,
+    0x1e,
+    0xd7,
+    0x08,
+    0xe8,
+    0xea,
+    0xde,
+    0x80,
+    0x52,
+    0xee,
+    0xf7,
+    0x84,
+    0xaa,
+    0x72,
+    0xac,
+    0x35,
+    0x4d,
+    0x6a,
+    0x2a,
+    0x96,
+    0x1a,
+    0xd2,
+    0x71,
+    0x5a,
+    0x15,
+    0x49,
+    0x74,
+    0x4b,
+    0x9f,
+    0xd0,
+    0x5e,
+    0x04,
+    0x18,
+    0xa4,
+    0xec,
+    0xc2,
+    0xe0,
+    0x41,
+    0x6e,
+    0x0f,
+    0x51,
+    0xcb,
+    0xcc,
+    0x24,
+    0x91,
+    0xaf,
+    0x50,
+    0xa1,
+    0xf4,
+    0x70,
+    0x39,
+    0x99,
+    0x7c,
+    0x3a,
+    0x85,
+    0x23,
+    0xb8,
+    0xb4,
+    0x7a,
+    0xfc,
+    0x02,
+    0x36,
+    0x5b,
+    0x25,
+    0x55,
+    0x97,
+    0x31,
+    0x2d,
+    0x5d,
+    0xfa,
+    0x98,
+    0xe3,
+    0x8a,
+    0x92,
+    0xae,
+    0x05,
+    0xdf,
+    0x29,
+    0x10,
+    0x67,
+    0x6c,
+    0xba,
+    0xc9,
+    0xd3,
+    0x00,
+    0xe6,
+    0xcf,
+    0xe1,
+    0x9e,
+    0xa8,
+    0x2c,
+    0x63,
+    0x16,
+    0x01,
+    0x3f,
+    0x58,
+    0xe2,
+    0x89,
+    0xa9,
+    0x0d,
+    0x38,
+    0x34,
+    0x1b,
+    0xab,
+    0x33,
+    0xff,
+    0xb0,
+    0xbb,
+    0x48,
+    0x0c,
+    0x5f,
+    0xb9,
+    0xb1,
+    0xcd,
+    0x2e,
+    0xc5,
+    0xf3,
+    0xdb,
+    0x47,
+    0xe5,
+    0xa5,
+    0x9c,
+    0x77,
+    0x0a,
+    0xa6,
+    0x20,
+    0x68,
+    0xfe,
+    0x7f,
+    0xc1,
+    0xad,
 };
 
 #if defined(_MSC_VER) && defined(_ARM_)
diff --git a/crypto/rc2/rc2cfb64.c b/crypto/rc2/rc2cfb64.c
index 88c460b004..ccc69fa6bf 100644
--- a/crypto/rc2/rc2cfb64.c
+++ b/crypto/rc2/rc2cfb64.c
@@ -14,7 +14,7 @@
 #include "internal/deprecated.h"
 
 #include 
-#include "internal/common.h"
+#include "rc2_local.h"
 
 /*
  * The input and output encrypted as though 64bit cfb mode is being used.
@@ -27,7 +27,7 @@ void RC2_cfb64_encrypt(const unsigned char *in, unsigned char *out,
     int *num, int encrypt)
 {
     register unsigned long v0, v1, t;
-    register int n = *num & 0x07;
+    register int n = *num;
     register long l = length;
     unsigned long ti[2];
     unsigned char *iv, c, cc;
diff --git a/crypto/rc2/rc2ofb64.c b/crypto/rc2/rc2ofb64.c
index 45fe7aecd2..b659b72a10 100644
--- a/crypto/rc2/rc2ofb64.c
+++ b/crypto/rc2/rc2ofb64.c
@@ -14,7 +14,7 @@
 #include "internal/deprecated.h"
 
 #include 
-#include "internal/common.h"
+#include "rc2_local.h"
 
 /*
  * The input and output encrypted as though 64bit ofb mode is being used.
@@ -26,7 +26,7 @@ void RC2_ofb64_encrypt(const unsigned char *in, unsigned char *out,
     int *num)
 {
     register unsigned long v0, v1, t;
-    register int n = *num & 0x07;
+    register int n = *num;
     register long l = length;
     unsigned char d[8];
     register char *dp;
diff --git a/crypto/rc4/asm/rc4-md5-x86_64.pl b/crypto/rc4/asm/rc4-md5-x86_64.pl
index c4440ab32c..f814d6f86f 100644
--- a/crypto/rc4/asm/rc4-md5-x86_64.pl
+++ b/crypto/rc4/asm/rc4-md5-x86_64.pl
@@ -26,7 +26,7 @@
 # and Jim Guilford of Intel. MD5 is fresh implementation aiming to
 # minimize register usage, which was used as "main thread" with RC4
 # weaved into it, one RC4 round per one MD5 round. In addition to the
-# stitched subroutine the script can generate standalone replacement
+# stiched subroutine the script can generate standalone replacement
 # ossl_md5_block_asm_data_order and RC4. Below are performance numbers in
 # cycles per processed byte, less is better, for these the standalone
 # subroutines, sum of them, and stitched one:
diff --git a/crypto/rc5/rc5_local.h b/crypto/rc5/rc5_local.h
index 7b5f8c847b..57a1642c97 100644
--- a/crypto/rc5/rc5_local.h
+++ b/crypto/rc5/rc5_local.h
@@ -7,11 +7,84 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_RC5_RC5_LOCAL_H)
-#define OSSL_LIBCRYPTO_RC5_RC5_LOCAL_H
-
 #include 
-#include "internal/common.h"
+
+#undef c2l
+#define c2l(c, l) (l = ((unsigned long)(*((c)++))), \
+    l |= ((unsigned long)(*((c)++))) << 8L,         \
+    l |= ((unsigned long)(*((c)++))) << 16L,        \
+    l |= ((unsigned long)(*((c)++))) << 24L)
+
+/* NOTE - c is not incremented as per c2l */
+#undef c2ln
+#define c2ln(c, l1, l2, n)                            \
+    {                                                 \
+        c += n;                                       \
+        l1 = l2 = 0;                                  \
+        switch (n) {                                  \
+        case 8:                                       \
+            l2 = ((unsigned long)(*(--(c)))) << 24L;  \
+        /* fall through */                            \
+        case 7:                                       \
+            l2 |= ((unsigned long)(*(--(c)))) << 16L; \
+        /* fall through */                            \
+        case 6:                                       \
+            l2 |= ((unsigned long)(*(--(c)))) << 8L;  \
+        /* fall through */                            \
+        case 5:                                       \
+            l2 |= ((unsigned long)(*(--(c))));        \
+        /* fall through */                            \
+        case 4:                                       \
+            l1 = ((unsigned long)(*(--(c)))) << 24L;  \
+        /* fall through */                            \
+        case 3:                                       \
+            l1 |= ((unsigned long)(*(--(c)))) << 16L; \
+        /* fall through */                            \
+        case 2:                                       \
+            l1 |= ((unsigned long)(*(--(c)))) << 8L;  \
+        /* fall through */                            \
+        case 1:                                       \
+            l1 |= ((unsigned long)(*(--(c))));        \
+        }                                             \
+    }
+
+#undef l2c
+#define l2c(l, c) (*((c)++) = (unsigned char)(((l)) & 0xff), \
+    *((c)++) = (unsigned char)(((l) >> 8L) & 0xff),          \
+    *((c)++) = (unsigned char)(((l) >> 16L) & 0xff),         \
+    *((c)++) = (unsigned char)(((l) >> 24L) & 0xff))
+
+/* NOTE - c is not incremented as per l2c */
+#undef l2cn
+#define l2cn(l1, l2, c, n)                                    \
+    {                                                         \
+        c += n;                                               \
+        switch (n) {                                          \
+        case 8:                                               \
+            *(--(c)) = (unsigned char)(((l2) >> 24L) & 0xff); \
+        /* fall through */                                    \
+        case 7:                                               \
+            *(--(c)) = (unsigned char)(((l2) >> 16L) & 0xff); \
+        /* fall through */                                    \
+        case 6:                                               \
+            *(--(c)) = (unsigned char)(((l2) >> 8L) & 0xff);  \
+        /* fall through */                                    \
+        case 5:                                               \
+            *(--(c)) = (unsigned char)(((l2)) & 0xff);        \
+        /* fall through */                                    \
+        case 4:                                               \
+            *(--(c)) = (unsigned char)(((l1) >> 24L) & 0xff); \
+        /* fall through */                                    \
+        case 3:                                               \
+            *(--(c)) = (unsigned char)(((l1) >> 16L) & 0xff); \
+        /* fall through */                                    \
+        case 2:                                               \
+            *(--(c)) = (unsigned char)(((l1) >> 8L) & 0xff);  \
+        /* fall through */                                    \
+        case 1:                                               \
+            *(--(c)) = (unsigned char)(((l1)) & 0xff);        \
+        }                                                     \
+    }
 
 #if (defined(OPENSSL_SYS_WIN32) && defined(_MSC_VER))
 #define ROTATE_l32(a, n) _lrotl(a, n)
@@ -19,7 +92,7 @@
 #elif defined(__ICC)
 #define ROTATE_l32(a, n) _rotl(a, n)
 #define ROTATE_r32(a, n) _rotr(a, n)
-#elif defined(__GNUC__) && !defined(__STRICT_ANSI__) && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM) && !defined(PEDANTIC)
+#elif defined(__GNUC__) && __GNUC__ >= 2 && !defined(__STRICT_ANSI__) && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM) && !defined(PEDANTIC)
 #if defined(__i386) || defined(__i386__) || defined(__x86_64) || defined(__x86_64__)
 #define ROTATE_l32(a, n) ({              \
     register unsigned int ret;           \
@@ -70,5 +143,3 @@
     a &= RC5_32_MASK;        \
     a = ROTATE_r32(a, b);    \
     a ^= b;
-
-#endif /* !defined(OSSL_LIBCRYPTO_RC5_RC5_LOCAL_H) */
diff --git a/crypto/rc5/rc5cfb64.c b/crypto/rc5/rc5cfb64.c
index 7e3357f039..f2f4b9bdfb 100644
--- a/crypto/rc5/rc5cfb64.c
+++ b/crypto/rc5/rc5cfb64.c
@@ -27,7 +27,7 @@ void RC5_32_cfb64_encrypt(const unsigned char *in, unsigned char *out,
     unsigned char *ivec, int *num, int encrypt)
 {
     register unsigned long v0, v1, t;
-    register int n = *num & 0x07;
+    register int n = *num;
     register long l = length;
     unsigned long ti[2];
     unsigned char *iv, c, cc;
diff --git a/crypto/rc5/rc5ofb64.c b/crypto/rc5/rc5ofb64.c
index e55b519956..30487521f2 100644
--- a/crypto/rc5/rc5ofb64.c
+++ b/crypto/rc5/rc5ofb64.c
@@ -26,7 +26,7 @@ void RC5_32_ofb64_encrypt(const unsigned char *in, unsigned char *out,
     unsigned char *ivec, int *num)
 {
     register unsigned long v0, v1, t;
-    register int n = *num & 0x07;
+    register int n = *num;
     register long l = length;
     unsigned char d[8];
     register char *dp;
diff --git a/crypto/rcu_internal.h b/crypto/rcu_internal.h
index e4b9aab6fa..3408923eba 100644
--- a/crypto/rcu_internal.h
+++ b/crypto/rcu_internal.h
@@ -11,8 +11,6 @@
 #define OPENSSL_RCU_INTERNAL_H
 #pragma once
 
-#include 
-
 struct rcu_qp;
 
 struct rcu_cb_item {
diff --git a/crypto/ripemd/rmd_local.h b/crypto/ripemd/rmd_local.h
index a1dd480282..f2934a7332 100644
--- a/crypto/ripemd/rmd_local.h
+++ b/crypto/ripemd/rmd_local.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_RIPEMD_RMD_LOCAL_H)
-#define OSSL_LIBCRYPTO_RIPEMD_RMD_LOCAL_H
-
 #include 
 #include 
 #include 
@@ -51,9 +48,7 @@ void ripemd160_block_data_order(RIPEMD160_CTX *c, const void *p, size_t num);
     } while (0)
 #define HASH_BLOCK_DATA_ORDER ripemd160_block_data_order
 
-/* clang-format off */
-#include "crypto/md32_common.inc"
-/* clang-format on */
+#include "crypto/md32_common.h"
 
 /*
  * Transformed F2 and F4 are courtesy of Wei Dai
@@ -106,5 +101,3 @@ void ripemd160_block_data_order(RIPEMD160_CTX *c, const void *p, size_t num);
         a = ROTATE(a, s) + e;        \
         c = ROTATE(c, 10);           \
     }
-
-#endif /* !defined(OSSL_LIBCRYPTO_RIPEMD_RMD_LOCAL_H) */
diff --git a/crypto/ripemd/rmdconst.h b/crypto/ripemd/rmdconst.h
index bb48abe49a..f9daf1b09f 100644
--- a/crypto/ripemd/rmdconst.h
+++ b/crypto/ripemd/rmdconst.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_RIPEMD_RMDCONST_H)
-#define OSSL_LIBCRYPTO_RIPEMD_RMDCONST_H
-
 #define KL0 0x00000000L
 #define KL1 0x5A827999L
 #define KL2 0x6ED9EBA1L
@@ -351,5 +348,3 @@
 #define SR78 11
 #define WR79 11
 #define SR79 11
-
-#endif /* !defined(OSSL_LIBCRYPTO_RIPEMD_RMDCONST_H) */
diff --git a/crypto/riscvcap.c b/crypto/riscvcap.c
index 760fc5b0dd..54f01f5d39 100644
--- a/crypto/riscvcap.c
+++ b/crypto/riscvcap.c
@@ -15,7 +15,7 @@
 #include "internal/cryptlib.h"
 
 #define OPENSSL_RISCVCAP_IMPL
-#include "arch/riscv_arch.h"
+#include "crypto/riscv_arch.h"
 
 #ifdef OSSL_RISCV_HWPROBE
 #include 
@@ -26,6 +26,9 @@
 
 extern size_t riscv_vlen_asm(void);
 
+static void parse_env(const char *envstr);
+static void strtoupper(char *str);
+
 static size_t vlen = 0;
 
 #ifdef OSSL_RISCV_HWPROBE
@@ -47,15 +50,10 @@ size_t OPENSSL_instrument_bus2(unsigned int *out, size_t cnt, size_t max)
     return 0;
 }
 
-static void strtoupper(const char *str, char *dst, size_t dstlen)
+static void strtoupper(char *str)
 {
-    for (size_t i = 0; i < dstlen; i++) {
-        if (i == dstlen - 1 || str[i] == '\0') {
-            dst[i] = '\0';
-            break;
-        }
-        dst[i] = toupper((unsigned char)str[i]);
-    }
+    for (char *x = str; *x; ++x)
+        *x = toupper((unsigned char)*x);
 }
 
 /* parse_env() parses a RISC-V architecture string. An example of such a string
@@ -70,24 +68,15 @@ static void parse_env(const char *envstr)
     char buf[BUFLEN];
 
     /* Convert env str to all uppercase */
-    strtoupper(envstr, envstrupper, sizeof(envstrupper));
+    OPENSSL_strlcpy(envstrupper, envstr, sizeof(envstrupper));
+    strtoupper(envstrupper);
 
     for (size_t i = 0; i < kRISCVNumCaps; ++i) {
-        size_t len = strlen(RISCV_capabilities[i].name);
         /* Prefix capability with underscore in preparation for search */
-        /*
-         * Avoid using higher level library functions which may require
-         * library initialization (such as BIO_snprintf) as this may be called
-         * in a constructor before library initialization
-         */
-        if (len < BUFLEN - 1) {
-            buf[0] = '_';
-            memcpy(buf + 1, RISCV_capabilities[i].name, len);
-            buf[len + 1] = '\0';
-            if (strstr(envstrupper, buf) != NULL) {
-                /* Match, set relevant bit in OPENSSL_riscvcap_P[] */
-                OPENSSL_riscvcap_P[RISCV_capabilities[i].index] |= (1 << RISCV_capabilities[i].bit_offset);
-            }
+        BIO_snprintf(buf, BUFLEN, "_%s", RISCV_capabilities[i].name);
+        if (strstr(envstrupper, buf) != NULL) {
+            /* Match, set relevant bit in OPENSSL_riscvcap_P[] */
+            OPENSSL_riscvcap_P[RISCV_capabilities[i].index] |= (1 << RISCV_capabilities[i].bit_offset);
         }
     }
 }
@@ -129,9 +118,6 @@ size_t riscv_vlen(void)
     return vlen;
 }
 
-#if defined(__GNUC__)
-__attribute__((constructor))
-#endif
 void OPENSSL_cpuid_setup(void)
 {
     char *e;
diff --git a/crypto/rsa/build.info b/crypto/rsa/build.info
index bf5316883e..ad3370db39 100644
--- a/crypto/rsa/build.info
+++ b/crypto/rsa/build.info
@@ -7,7 +7,7 @@ $COMMON=rsa_ossl.c rsa_gen.c rsa_lib.c rsa_sign.c rsa_pk1.c \
 
 SOURCE[../../libcrypto]=$COMMON\
         rsa_saos.c rsa_err.c rsa_asn1.c rsa_ameth.c rsa_prn.c \
-        rsa_meth.c rsa_mp.c
+        rsa_pmeth.c rsa_meth.c rsa_mp.c
 IF[{- !$disabled{'deprecated-0.9.8'} -}]
   SOURCE[../../libcrypto]=rsa_depr.c
 ENDIF
diff --git a/crypto/rsa/rsa_ameth.c b/crypto/rsa/rsa_ameth.c
index 1eb4649481..87bbaf04e3 100644
--- a/crypto/rsa/rsa_ameth.c
+++ b/crypto/rsa/rsa_ameth.c
@@ -653,10 +653,6 @@ static int rsa_item_sign(EVP_MD_CTX *ctx, const ASN1_ITEM *it, const void *asn,
     int pad_mode;
     EVP_PKEY_CTX *pkctx = EVP_MD_CTX_get_pkey_ctx(ctx);
 
-    if (pkctx == NULL) {
-        ERR_raise(ERR_LIB_RSA, ERR_R_INTERNAL_ERROR);
-        return 0;
-    }
     if (EVP_PKEY_CTX_get_rsa_padding(pkctx, &pad_mode) <= 0)
         return 0;
     if (pad_mode == RSA_PKCS1_PADDING)
diff --git a/crypto/rsa/rsa_backend.c b/crypto/rsa/rsa_backend.c
index 161d9a9c56..8ed857414d 100644
--- a/crypto/rsa/rsa_backend.c
+++ b/crypto/rsa/rsa_backend.c
@@ -28,9 +28,9 @@
 #include "rsa_local.h"
 
 /*
- * The intention with the "backend" source file is to offer backend functions
- * for legacy backends (EVP_PKEY_ASN1_METHOD) and provider implementations
- * alike.
+ * The intention with the "backend" source file is to offer backend support
+ * for legacy backends (EVP_PKEY_ASN1_METHOD and EVP_PKEY_METHOD) and provider
+ * implementations alike.
  */
 
 DEFINE_STACK_OF(BIGNUM)
@@ -64,8 +64,9 @@ static int collect_numbers(STACK_OF(BIGNUM) *numbers,
 int ossl_rsa_fromdata(RSA *rsa, const OSSL_PARAM params[], int include_private)
 {
     const OSSL_PARAM *param_n, *param_e, *param_d = NULL;
+    const OSSL_PARAM *param_p, *param_q = NULL;
     const OSSL_PARAM *param_derive = NULL;
-    BIGNUM *n = NULL, *e = NULL, *d = NULL;
+    BIGNUM *p = NULL, *q = NULL, *n = NULL, *e = NULL, *d = NULL;
     STACK_OF(BIGNUM) *factors = NULL, *exps = NULL, *coeffs = NULL;
     int is_private = 0;
     int derive_from_pq = 0;
@@ -103,8 +104,10 @@ int ossl_rsa_fromdata(RSA *rsa, const OSSL_PARAM params[], int include_private)
                 goto err;
 
             /* we need at minimum p, q */
-            if (OSSL_PARAM_locate_const(params, OSSL_PKEY_PARAM_RSA_FACTOR1) == NULL
-                || OSSL_PARAM_locate_const(params, OSSL_PKEY_PARAM_RSA_FACTOR2) == NULL) {
+            param_p = OSSL_PARAM_locate_const(params, OSSL_PKEY_PARAM_RSA_FACTOR1);
+            param_q = OSSL_PARAM_locate_const(params, OSSL_PKEY_PARAM_RSA_FACTOR2);
+            if ((param_p == NULL || !OSSL_PARAM_get_BN(param_p, &p))
+                || (param_q == NULL || !OSSL_PARAM_get_BN(param_q, &q))) {
                 ERR_raise(ERR_LIB_RSA, ERR_R_PASSED_NULL_PARAMETER);
                 goto err;
             }
@@ -227,10 +230,12 @@ int ossl_rsa_fromdata(RSA *rsa, const OSSL_PARAM params[], int include_private)
 
     if (!ossl_rsa_check_factors(rsa)) {
         ERR_raise_data(ERR_LIB_RSA, RSA_R_INVALID_KEYPAIR,
-            "RSA factors/exponents are too big for n-modulus\n");
+            "RSA factors/exponents are too big for for n-modulus\n");
         goto err;
     }
 
+    BN_clear_free(p);
+    BN_clear_free(q);
     sk_BIGNUM_free(factors);
     sk_BIGNUM_free(exps);
     sk_BIGNUM_free(coeffs);
@@ -532,8 +537,7 @@ RSA *ossl_rsa_dup(const RSA *rsa, int selection)
     }
 
     if (rsa->pss != NULL) {
-        if ((dupkey->pss = RSA_PSS_PARAMS_dup(rsa->pss)) == NULL)
-            goto err;
+        dupkey->pss = RSA_PSS_PARAMS_dup(rsa->pss);
         if (rsa->pss->maskGenAlgorithm != NULL
             && dupkey->pss->maskGenAlgorithm == NULL) {
             dupkey->pss->maskHash = ossl_x509_algor_mgf1_decode(rsa->pss->maskGenAlgorithm);
diff --git a/crypto/rsa/rsa_err.c b/crypto/rsa/rsa_err.c
index aced712b1d..8f20f68efe 100644
--- a/crypto/rsa/rsa_err.c
+++ b/crypto/rsa/rsa_err.c
@@ -127,6 +127,8 @@ static const ERR_STRING_DATA RSA_str_reasons[] = {
         "salt length check failed" },
     { ERR_PACK(ERR_LIB_RSA, 0, RSA_R_SLEN_RECOVERY_FAILED),
         "salt length recovery failed" },
+    { ERR_PACK(ERR_LIB_RSA, 0, RSA_R_SSLV3_ROLLBACK_ATTACK),
+        "sslv3 rollback attack" },
     { ERR_PACK(ERR_LIB_RSA, 0, RSA_R_THE_ASN1_OBJECT_IDENTIFIER_IS_NOT_KNOWN_FOR_THIS_MD),
         "the asn1 object identifier is not known for this md" },
     { ERR_PACK(ERR_LIB_RSA, 0, RSA_R_UNKNOWN_ALGORITHM_TYPE),
diff --git a/crypto/rsa/rsa_gen.c b/crypto/rsa/rsa_gen.c
index df44f50a76..9e053edb7c 100644
--- a/crypto/rsa/rsa_gen.c
+++ b/crypto/rsa/rsa_gen.c
@@ -645,6 +645,7 @@ static int rsa_keygen(OSSL_LIB_CTX *libctx, RSA *rsa, int bits, int primes,
         OSSL_SELF_TEST_get_callback(libctx, &stcb, &stcbarg);
         ok = rsa_keygen_pairwise_test(rsa, stcb, stcbarg);
         if (!ok) {
+            ossl_set_error_state(OSSL_SELF_TEST_TYPE_PCT);
             /* Clear intermediate results */
             BN_clear_free(rsa->d);
             BN_clear_free(rsa->p);
diff --git a/crypto/rsa/rsa_lib.c b/crypto/rsa/rsa_lib.c
index 88a7a2b93f..2781cf82d2 100644
--- a/crypto/rsa/rsa_lib.c
+++ b/crypto/rsa/rsa_lib.c
@@ -17,10 +17,9 @@
 #include 
 #include 
 #include 
-#include "internal/common.h"
 #include "internal/cryptlib.h"
 #include "internal/refcount.h"
-#include "internal/zeroization.h"
+#include "internal/common.h"
 #include "crypto/bn.h"
 #include "crypto/evp.h"
 #include "crypto/rsa.h"
@@ -138,8 +137,13 @@ void RSA_free(RSA *r)
     CRYPTO_THREAD_lock_free(r->lock);
     CRYPTO_FREE_REF(&r->references);
 
-    ossl_public_bn_free(r->n);
-    ossl_public_bn_free(r->e);
+#ifdef OPENSSL_PEDANTIC_ZEROIZATION
+    BN_clear_free(r->n);
+    BN_clear_free(r->e);
+#else
+    BN_free(r->n);
+    BN_free(r->e);
+#endif
     BN_clear_free(r->d);
     BN_clear_free(r->p);
     BN_clear_free(r->q);
@@ -163,7 +167,7 @@ int RSA_up_ref(RSA *r)
 {
     int i;
 
-    if (!CRYPTO_UP_REF(&r->references, &i))
+    if (CRYPTO_UP_REF(&r->references, &i) <= 0)
         return 0;
 
     REF_PRINT_COUNT("RSA", i, r);
@@ -380,11 +384,11 @@ int RSA_set0_key(RSA *r, BIGNUM *n, BIGNUM *e, BIGNUM *d)
         return 0;
 
     if (n != NULL) {
-        ossl_public_bn_free(r->n);
+        BN_free(r->n);
         r->n = n;
     }
     if (e != NULL) {
-        ossl_public_bn_free(r->e);
+        BN_free(r->e);
         r->e = e;
     }
     if (d != NULL) {
@@ -705,9 +709,9 @@ int RSA_get_version(RSA *r)
 int RSA_pkey_ctx_ctrl(EVP_PKEY_CTX *ctx, int optype, int cmd, int p1, void *p2)
 {
     /* If key type not RSA or RSA-PSS return error */
-    if (ctx == NULL
-        || (ctx->legacy_keytype != EVP_PKEY_RSA
-            && ctx->legacy_keytype != EVP_PKEY_RSA_PSS))
+    if (ctx != NULL && ctx->pmeth != NULL
+        && ctx->pmeth->pkey_id != EVP_PKEY_RSA
+        && ctx->pmeth->pkey_id != EVP_PKEY_RSA_PSS)
         return -1;
     return EVP_PKEY_CTX_ctrl(ctx, -1, optype, cmd, p1, p2);
 }
diff --git a/crypto/rsa/rsa_local.h b/crypto/rsa/rsa_local.h
index 7ea7ee6541..b41bb34c27 100644
--- a/crypto/rsa/rsa_local.h
+++ b/crypto/rsa/rsa_local.h
@@ -144,8 +144,9 @@ struct rsa_meth_st {
         BIGNUM *e, BN_GENCB *cb);
 };
 
-/* Macro to test if a pkey is for a PSS key */
+/* Macros to test if a pkey or ctx is for a PSS key */
 #define pkey_is_pss(pkey) (pkey->ameth->pkey_id == EVP_PKEY_RSA_PSS)
+#define pkey_ctx_is_pss(ctx) (ctx->pmeth->pkey_id == EVP_PKEY_RSA_PSS)
 int ossl_rsa_multiprime_derive(RSA *rsa, int bits, int primes,
     BIGNUM *e_value,
     STACK_OF(BIGNUM) *factors, STACK_OF(BIGNUM) *exps,
diff --git a/crypto/rsa/rsa_ossl.c b/crypto/rsa/rsa_ossl.c
index 674ee4b10d..b883baa58f 100644
--- a/crypto/rsa/rsa_ossl.c
+++ b/crypto/rsa/rsa_ossl.c
@@ -1184,12 +1184,9 @@ static int rsa_ossl_finish(RSA *rsa)
 static int rsa_ossl_s390x_mod_exp(BIGNUM *r0, const BIGNUM *i, RSA *rsa,
     BN_CTX *ctx)
 {
-    int rc;
-
     if (rsa->version != RSA_ASN1_VERSION_MULTI) {
-        rc = s390x_crt(r0, i, rsa->p, rsa->q, rsa->dmp1, rsa->dmq1, rsa->iqmp);
-        if (rc >= 0)
-            return rc;
+        if (s390x_crt(r0, i, rsa->p, rsa->q, rsa->dmp1, rsa->dmq1, rsa->iqmp) == 1)
+            return 1;
     }
     return rsa_ossl_mod_exp(r0, i, rsa, ctx);
 }
diff --git a/crypto/rsa/rsa_pmeth.c b/crypto/rsa/rsa_pmeth.c
new file mode 100644
index 0000000000..dfc9537b3a
--- /dev/null
+++ b/crypto/rsa/rsa_pmeth.c
@@ -0,0 +1,935 @@
+/*
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
+ *
+ * Licensed under the Apache License 2.0 (the "License").  You may not use
+ * this file except in compliance with the License.  You can obtain a copy
+ * in the file LICENSE in the source distribution or at
+ * https://www.openssl.org/source/license.html
+ */
+
+/*
+ * RSA low level APIs are deprecated for public use, but still ok for
+ * internal use.
+ */
+#include "internal/deprecated.h"
+
+#include "internal/constant_time.h"
+
+#include 
+#include "internal/cryptlib.h"
+#include 
+#include 
+#include 
+#include 
+#include 
+#include 
+#include 
+#include "crypto/evp.h"
+#include "crypto/rsa.h"
+#include "rsa_local.h"
+
+/* RSA pkey context structure */
+
+typedef struct {
+    /* Key gen parameters */
+    int nbits;
+    BIGNUM *pub_exp;
+    int primes;
+    /* Keygen callback info */
+    int gentmp[2];
+    /* RSA padding mode */
+    int pad_mode;
+    /* message digest */
+    const EVP_MD *md;
+    /* message digest for MGF1 */
+    const EVP_MD *mgf1md;
+    /* PSS salt length */
+    int saltlen;
+    /* Minimum salt length or -1 if no PSS parameter restriction */
+    int min_saltlen;
+    /* Temp buffer */
+    unsigned char *tbuf;
+    /* OAEP label */
+    unsigned char *oaep_label;
+    size_t oaep_labellen;
+    /* if to use implicit rejection in PKCS#1 v1.5 decryption */
+    int implicit_rejection;
+} RSA_PKEY_CTX;
+
+/* True if PSS parameters are restricted */
+#define rsa_pss_restricted(rctx) (rctx->min_saltlen != -1)
+
+static int pkey_rsa_init(EVP_PKEY_CTX *ctx)
+{
+    RSA_PKEY_CTX *rctx = OPENSSL_zalloc(sizeof(*rctx));
+
+    if (rctx == NULL)
+        return 0;
+    rctx->nbits = 2048;
+    rctx->primes = RSA_DEFAULT_PRIME_NUM;
+    if (pkey_ctx_is_pss(ctx))
+        rctx->pad_mode = RSA_PKCS1_PSS_PADDING;
+    else
+        rctx->pad_mode = RSA_PKCS1_PADDING;
+    /* Maximum for sign, auto for verify */
+    rctx->saltlen = RSA_PSS_SALTLEN_AUTO;
+    rctx->min_saltlen = -1;
+    rctx->implicit_rejection = 1;
+    ctx->data = rctx;
+    ctx->keygen_info = rctx->gentmp;
+    ctx->keygen_info_count = 2;
+
+    return 1;
+}
+
+static int pkey_rsa_copy(EVP_PKEY_CTX *dst, const EVP_PKEY_CTX *src)
+{
+    RSA_PKEY_CTX *dctx, *sctx;
+
+    if (!pkey_rsa_init(dst))
+        return 0;
+    sctx = src->data;
+    dctx = dst->data;
+    dctx->nbits = sctx->nbits;
+    if (sctx->pub_exp) {
+        dctx->pub_exp = BN_dup(sctx->pub_exp);
+        if (!dctx->pub_exp)
+            return 0;
+    }
+    dctx->pad_mode = sctx->pad_mode;
+    dctx->md = sctx->md;
+    dctx->mgf1md = sctx->mgf1md;
+    dctx->saltlen = sctx->saltlen;
+    dctx->implicit_rejection = sctx->implicit_rejection;
+    if (sctx->oaep_label) {
+        OPENSSL_free(dctx->oaep_label);
+        dctx->oaep_label = OPENSSL_memdup(sctx->oaep_label, sctx->oaep_labellen);
+        if (!dctx->oaep_label)
+            return 0;
+        dctx->oaep_labellen = sctx->oaep_labellen;
+    }
+    return 1;
+}
+
+static int setup_tbuf(RSA_PKEY_CTX *ctx, EVP_PKEY_CTX *pk)
+{
+    if (ctx->tbuf != NULL)
+        return 1;
+    if ((ctx->tbuf = OPENSSL_malloc(RSA_size(EVP_PKEY_get0_RSA(pk->pkey)))) == NULL)
+        return 0;
+    return 1;
+}
+
+static void pkey_rsa_cleanup(EVP_PKEY_CTX *ctx)
+{
+    RSA_PKEY_CTX *rctx = ctx->data;
+    if (rctx) {
+        BN_free(rctx->pub_exp);
+        OPENSSL_free(rctx->tbuf);
+        OPENSSL_free(rctx->oaep_label);
+        OPENSSL_free(rctx);
+    }
+}
+
+static int pkey_rsa_sign(EVP_PKEY_CTX *ctx, unsigned char *sig,
+    size_t *siglen, const unsigned char *tbs,
+    size_t tbslen)
+{
+    int ret;
+    RSA_PKEY_CTX *rctx = ctx->data;
+    /*
+     * Discard const. Its marked as const because this may be a cached copy of
+     * the "real" key. These calls don't make any modifications that need to
+     * be reflected back in the "original" key.
+     */
+    RSA *rsa = (RSA *)EVP_PKEY_get0_RSA(ctx->pkey);
+    int md_size;
+
+    if (rctx->md) {
+        md_size = EVP_MD_get_size(rctx->md);
+        if (md_size <= 0) {
+            ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_DIGEST_LENGTH);
+            return -1;
+        }
+
+        if (tbslen != (size_t)md_size) {
+            ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_DIGEST_LENGTH);
+            return -1;
+        }
+
+        if (EVP_MD_get_type(rctx->md) == NID_mdc2) {
+            unsigned int sltmp;
+            if (rctx->pad_mode != RSA_PKCS1_PADDING)
+                return -1;
+            ret = RSA_sign_ASN1_OCTET_STRING(0, tbs, (int)tbslen, sig, &sltmp, rsa);
+
+            if (ret <= 0)
+                return ret;
+            ret = sltmp;
+        } else if (rctx->pad_mode == RSA_X931_PADDING) {
+            if ((size_t)RSA_size(rsa) < tbslen + 1) {
+                ERR_raise(ERR_LIB_RSA, RSA_R_KEY_SIZE_TOO_SMALL);
+                return -1;
+            }
+            if (!setup_tbuf(rctx, ctx)) {
+                ERR_raise(ERR_LIB_RSA, ERR_R_RSA_LIB);
+                return -1;
+            }
+            memcpy(rctx->tbuf, tbs, tbslen);
+            rctx->tbuf[tbslen] = RSA_X931_hash_id(EVP_MD_get_type(rctx->md));
+            ret = RSA_private_encrypt((int)(tbslen + 1), rctx->tbuf,
+                sig, rsa, RSA_X931_PADDING);
+        } else if (rctx->pad_mode == RSA_PKCS1_PADDING) {
+            unsigned int sltmp;
+            ret = RSA_sign(EVP_MD_get_type(rctx->md),
+                tbs, (unsigned int)tbslen, sig, &sltmp, rsa);
+            if (ret <= 0)
+                return ret;
+            ret = sltmp;
+        } else if (rctx->pad_mode == RSA_PKCS1_PSS_PADDING) {
+            if (!setup_tbuf(rctx, ctx))
+                return -1;
+            if (!RSA_padding_add_PKCS1_PSS_mgf1(rsa,
+                    rctx->tbuf, tbs,
+                    rctx->md, rctx->mgf1md,
+                    rctx->saltlen))
+                return -1;
+            ret = RSA_private_encrypt(RSA_size(rsa), rctx->tbuf,
+                sig, rsa, RSA_NO_PADDING);
+        } else {
+            return -1;
+        }
+    } else {
+        ret = RSA_private_encrypt((int)tbslen, tbs, sig, rsa, rctx->pad_mode);
+    }
+    if (ret < 0)
+        return ret;
+    *siglen = ret;
+    return 1;
+}
+
+static int pkey_rsa_verifyrecover(EVP_PKEY_CTX *ctx,
+    unsigned char *rout, size_t *routlen,
+    const unsigned char *sig, size_t siglen)
+{
+    int ret;
+    RSA_PKEY_CTX *rctx = ctx->data;
+    /*
+     * Discard const. Its marked as const because this may be a cached copy of
+     * the "real" key. These calls don't make any modifications that need to
+     * be reflected back in the "original" key.
+     */
+    RSA *rsa = (RSA *)EVP_PKEY_get0_RSA(ctx->pkey);
+
+    if (rctx->md) {
+        if (rctx->pad_mode == RSA_X931_PADDING) {
+            if (!setup_tbuf(rctx, ctx))
+                return -1;
+            ret = RSA_public_decrypt((int)siglen, sig, rctx->tbuf, rsa,
+                RSA_X931_PADDING);
+            if (ret <= 0)
+                return 0;
+            ret--;
+            if (rctx->tbuf[ret] != RSA_X931_hash_id(EVP_MD_get_type(rctx->md))) {
+                ERR_raise(ERR_LIB_RSA, RSA_R_ALGORITHM_MISMATCH);
+                return 0;
+            }
+            if (ret != EVP_MD_get_size(rctx->md)) {
+                ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_DIGEST_LENGTH);
+                return 0;
+            }
+            if (rout)
+                memcpy(rout, rctx->tbuf, ret);
+        } else if (rctx->pad_mode == RSA_PKCS1_PADDING) {
+            size_t sltmp;
+            ret = ossl_rsa_verify(EVP_MD_get_type(rctx->md),
+                NULL, 0, rout, &sltmp,
+                sig, siglen, rsa);
+            if (ret <= 0)
+                return 0;
+            ret = (int)sltmp;
+        } else {
+            return -1;
+        }
+    } else {
+        ret = RSA_public_decrypt((int)siglen, sig, rout, rsa, rctx->pad_mode);
+    }
+    if (ret <= 0)
+        return ret;
+    *routlen = ret;
+    return 1;
+}
+
+static int pkey_rsa_verify(EVP_PKEY_CTX *ctx,
+    const unsigned char *sig, size_t siglen,
+    const unsigned char *tbs, size_t tbslen)
+{
+    RSA_PKEY_CTX *rctx = ctx->data;
+    /*
+     * Discard const. Its marked as const because this may be a cached copy of
+     * the "real" key. These calls don't make any modifications that need to
+     * be reflected back in the "original" key.
+     */
+    RSA *rsa = (RSA *)EVP_PKEY_get0_RSA(ctx->pkey);
+    size_t rslen;
+    int md_size;
+
+    if (rctx->md) {
+        if (rctx->pad_mode == RSA_PKCS1_PADDING)
+            return RSA_verify(EVP_MD_get_type(rctx->md), tbs, (unsigned int)tbslen,
+                sig, (unsigned int)siglen, rsa);
+        md_size = EVP_MD_get_size(rctx->md);
+        if (md_size <= 0) {
+            ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_DIGEST_LENGTH);
+            return -1;
+        }
+        if (tbslen != (size_t)md_size) {
+            ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_DIGEST_LENGTH);
+            return -1;
+        }
+        if (rctx->pad_mode == RSA_X931_PADDING) {
+            if (pkey_rsa_verifyrecover(ctx, NULL, &rslen, sig, siglen) <= 0)
+                return 0;
+        } else if (rctx->pad_mode == RSA_PKCS1_PSS_PADDING) {
+            int ret;
+            if (!setup_tbuf(rctx, ctx))
+                return -1;
+            ret = RSA_public_decrypt((int)siglen, sig, rctx->tbuf,
+                rsa, RSA_NO_PADDING);
+            if (ret <= 0)
+                return 0;
+            ret = RSA_verify_PKCS1_PSS_mgf1(rsa, tbs,
+                rctx->md, rctx->mgf1md,
+                rctx->tbuf, rctx->saltlen);
+            if (ret <= 0)
+                return 0;
+            return 1;
+        } else {
+            return -1;
+        }
+    } else {
+        if (!setup_tbuf(rctx, ctx))
+            return -1;
+        rslen = RSA_public_decrypt((int)siglen, sig, rctx->tbuf,
+            rsa, rctx->pad_mode);
+        if (rslen <= 0)
+            return 0;
+    }
+
+    if ((rslen != tbslen) || memcmp(tbs, rctx->tbuf, rslen))
+        return 0;
+
+    return 1;
+}
+
+static int pkey_rsa_encrypt(EVP_PKEY_CTX *ctx,
+    unsigned char *out, size_t *outlen,
+    const unsigned char *in, size_t inlen)
+{
+    int ret;
+    RSA_PKEY_CTX *rctx = ctx->data;
+    /*
+     * Discard const. Its marked as const because this may be a cached copy of
+     * the "real" key. These calls don't make any modifications that need to
+     * be reflected back in the "original" key.
+     */
+    RSA *rsa = (RSA *)EVP_PKEY_get0_RSA(ctx->pkey);
+
+    if (rctx->pad_mode == RSA_PKCS1_OAEP_PADDING) {
+        int klen = RSA_size(rsa);
+        if (!setup_tbuf(rctx, ctx))
+            return -1;
+        if (!RSA_padding_add_PKCS1_OAEP_mgf1(rctx->tbuf, klen,
+                in, (int)inlen,
+                rctx->oaep_label,
+                (int)rctx->oaep_labellen,
+                rctx->md, rctx->mgf1md))
+            return -1;
+        ret = RSA_public_encrypt(klen, rctx->tbuf, out, rsa, RSA_NO_PADDING);
+    } else {
+        ret = RSA_public_encrypt((int)inlen, in, out, rsa, rctx->pad_mode);
+    }
+    if (ret < 0)
+        return ret;
+    *outlen = ret;
+    return 1;
+}
+
+static int pkey_rsa_decrypt(EVP_PKEY_CTX *ctx,
+    unsigned char *out, size_t *outlen,
+    const unsigned char *in, size_t inlen)
+{
+    int ret;
+    int pad_mode;
+    RSA_PKEY_CTX *rctx = ctx->data;
+    /*
+     * Discard const. Its marked as const because this may be a cached copy of
+     * the "real" key. These calls don't make any modifications that need to
+     * be reflected back in the "original" key.
+     */
+    RSA *rsa = (RSA *)EVP_PKEY_get0_RSA(ctx->pkey);
+
+    if (rctx->pad_mode == RSA_PKCS1_OAEP_PADDING) {
+        if (!setup_tbuf(rctx, ctx))
+            return -1;
+        ret = RSA_private_decrypt((int)inlen, in, rctx->tbuf, rsa, RSA_NO_PADDING);
+        if (ret <= 0)
+            return ret;
+        ret = RSA_padding_check_PKCS1_OAEP_mgf1(out, ret, rctx->tbuf,
+            ret, ret,
+            rctx->oaep_label,
+            (int)rctx->oaep_labellen,
+            rctx->md, rctx->mgf1md);
+    } else {
+        if (rctx->pad_mode == RSA_PKCS1_PADDING && rctx->implicit_rejection == 0)
+            pad_mode = RSA_PKCS1_NO_IMPLICIT_REJECT_PADDING;
+        else
+            pad_mode = rctx->pad_mode;
+        ret = RSA_private_decrypt((int)inlen, in, out, rsa, pad_mode);
+    }
+    *outlen = constant_time_select_s(constant_time_msb_s(ret), *outlen, ret);
+    ret = constant_time_select_int(constant_time_msb(ret), ret, 1);
+    return ret;
+}
+
+static int check_padding_md(const EVP_MD *md, int padding)
+{
+    int mdnid;
+
+    if (!md)
+        return 1;
+
+    mdnid = EVP_MD_get_type(md);
+
+    if (padding == RSA_NO_PADDING) {
+        ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_PADDING_MODE);
+        return 0;
+    }
+
+    if (padding == RSA_X931_PADDING) {
+        if (RSA_X931_hash_id(mdnid) == -1) {
+            ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_X931_DIGEST);
+            return 0;
+        }
+    } else {
+        switch (mdnid) {
+        /* List of all supported RSA digests */
+        case NID_sha1:
+        case NID_sha224:
+        case NID_sha256:
+        case NID_sha384:
+        case NID_sha512:
+        case NID_sha512_224:
+        case NID_sha512_256:
+        case NID_md5:
+        case NID_md5_sha1:
+        case NID_md2:
+        case NID_md4:
+        case NID_mdc2:
+        case NID_ripemd160:
+        case NID_sha3_224:
+        case NID_sha3_256:
+        case NID_sha3_384:
+        case NID_sha3_512:
+            return 1;
+
+        default:
+            ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_DIGEST);
+            return 0;
+        }
+    }
+
+    return 1;
+}
+
+static int pkey_rsa_ctrl(EVP_PKEY_CTX *ctx, int type, int p1, void *p2)
+{
+    RSA_PKEY_CTX *rctx = ctx->data;
+    int md_size;
+
+    switch (type) {
+    case EVP_PKEY_CTRL_RSA_PADDING:
+        if ((p1 >= RSA_PKCS1_PADDING) && (p1 <= RSA_PKCS1_PSS_PADDING)) {
+            if (!check_padding_md(rctx->md, p1))
+                return 0;
+            if (p1 == RSA_PKCS1_PSS_PADDING) {
+                if (!(ctx->operation & (EVP_PKEY_OP_SIGN | EVP_PKEY_OP_VERIFY)))
+                    goto bad_pad;
+                if (!rctx->md)
+                    rctx->md = EVP_sha1();
+            } else if (pkey_ctx_is_pss(ctx)) {
+                goto bad_pad;
+            }
+            if (p1 == RSA_PKCS1_OAEP_PADDING) {
+                if (!(ctx->operation & EVP_PKEY_OP_TYPE_CRYPT))
+                    goto bad_pad;
+                if (!rctx->md)
+                    rctx->md = EVP_sha1();
+            }
+            rctx->pad_mode = p1;
+            return 1;
+        }
+    bad_pad:
+        ERR_raise(ERR_LIB_RSA, RSA_R_ILLEGAL_OR_UNSUPPORTED_PADDING_MODE);
+        return -2;
+
+    case EVP_PKEY_CTRL_GET_RSA_PADDING:
+        *(int *)p2 = rctx->pad_mode;
+        return 1;
+
+    case EVP_PKEY_CTRL_RSA_PSS_SALTLEN:
+    case EVP_PKEY_CTRL_GET_RSA_PSS_SALTLEN:
+        if (rctx->pad_mode != RSA_PKCS1_PSS_PADDING) {
+            ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_PSS_SALTLEN);
+            return -2;
+        }
+        if (type == EVP_PKEY_CTRL_GET_RSA_PSS_SALTLEN) {
+            *(int *)p2 = rctx->saltlen;
+        } else {
+            if (p1 < RSA_PSS_SALTLEN_MAX)
+                return -2;
+            if (rsa_pss_restricted(rctx)) {
+                if (p1 == RSA_PSS_SALTLEN_AUTO
+                    && ctx->operation == EVP_PKEY_OP_VERIFY) {
+                    ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_PSS_SALTLEN);
+                    return -2;
+                }
+                md_size = EVP_MD_get_size(rctx->md);
+                if (md_size <= 0) {
+                    ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_DIGEST_LENGTH);
+                    return -2;
+                }
+                if ((p1 == RSA_PSS_SALTLEN_DIGEST
+                        && rctx->min_saltlen > md_size)
+                    || (p1 >= 0 && p1 < rctx->min_saltlen)) {
+                    ERR_raise(ERR_LIB_RSA, RSA_R_PSS_SALTLEN_TOO_SMALL);
+                    return 0;
+                }
+            }
+            rctx->saltlen = p1;
+        }
+        return 1;
+
+    case EVP_PKEY_CTRL_RSA_KEYGEN_BITS:
+        if (p1 < RSA_MIN_MODULUS_BITS) {
+            ERR_raise(ERR_LIB_RSA, RSA_R_KEY_SIZE_TOO_SMALL);
+            return -2;
+        }
+        rctx->nbits = p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_RSA_KEYGEN_PUBEXP:
+        if (p2 == NULL || !BN_is_odd((BIGNUM *)p2) || BN_is_one((BIGNUM *)p2)) {
+            ERR_raise(ERR_LIB_RSA, RSA_R_BAD_E_VALUE);
+            return -2;
+        }
+        BN_free(rctx->pub_exp);
+        rctx->pub_exp = p2;
+        return 1;
+
+    case EVP_PKEY_CTRL_RSA_KEYGEN_PRIMES:
+        if (p1 < RSA_DEFAULT_PRIME_NUM || p1 > RSA_MAX_PRIME_NUM) {
+            ERR_raise(ERR_LIB_RSA, RSA_R_KEY_PRIME_NUM_INVALID);
+            return -2;
+        }
+        rctx->primes = p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_RSA_OAEP_MD:
+    case EVP_PKEY_CTRL_GET_RSA_OAEP_MD:
+        if (rctx->pad_mode != RSA_PKCS1_OAEP_PADDING) {
+            ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_PADDING_MODE);
+            return -2;
+        }
+        if (type == EVP_PKEY_CTRL_GET_RSA_OAEP_MD)
+            *(const EVP_MD **)p2 = rctx->md;
+        else
+            rctx->md = p2;
+        return 1;
+
+    case EVP_PKEY_CTRL_MD:
+        if (!check_padding_md(p2, rctx->pad_mode))
+            return 0;
+        if (rsa_pss_restricted(rctx)) {
+            if (EVP_MD_get_type(rctx->md) == EVP_MD_get_type(p2))
+                return 1;
+            ERR_raise(ERR_LIB_RSA, RSA_R_DIGEST_NOT_ALLOWED);
+            return 0;
+        }
+        rctx->md = p2;
+        return 1;
+
+    case EVP_PKEY_CTRL_GET_MD:
+        *(const EVP_MD **)p2 = rctx->md;
+        return 1;
+
+    case EVP_PKEY_CTRL_RSA_MGF1_MD:
+    case EVP_PKEY_CTRL_GET_RSA_MGF1_MD:
+        if (rctx->pad_mode != RSA_PKCS1_PSS_PADDING
+            && rctx->pad_mode != RSA_PKCS1_OAEP_PADDING) {
+            ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_MGF1_MD);
+            return -2;
+        }
+        if (type == EVP_PKEY_CTRL_GET_RSA_MGF1_MD) {
+            if (rctx->mgf1md)
+                *(const EVP_MD **)p2 = rctx->mgf1md;
+            else
+                *(const EVP_MD **)p2 = rctx->md;
+        } else {
+            if (rsa_pss_restricted(rctx)) {
+                if (EVP_MD_get_type(rctx->mgf1md) == EVP_MD_get_type(p2))
+                    return 1;
+                ERR_raise(ERR_LIB_RSA, RSA_R_MGF1_DIGEST_NOT_ALLOWED);
+                return 0;
+            }
+            rctx->mgf1md = p2;
+        }
+        return 1;
+
+    case EVP_PKEY_CTRL_RSA_OAEP_LABEL:
+        if (rctx->pad_mode != RSA_PKCS1_OAEP_PADDING) {
+            ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_PADDING_MODE);
+            return -2;
+        }
+        OPENSSL_free(rctx->oaep_label);
+        if (p2 && p1 > 0) {
+            rctx->oaep_label = p2;
+            rctx->oaep_labellen = p1;
+        } else {
+            rctx->oaep_label = NULL;
+            rctx->oaep_labellen = 0;
+        }
+        return 1;
+
+    case EVP_PKEY_CTRL_GET_RSA_OAEP_LABEL:
+        if (rctx->pad_mode != RSA_PKCS1_OAEP_PADDING) {
+            ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_PADDING_MODE);
+            return -2;
+        }
+        if (p2 == NULL) {
+            ERR_raise(ERR_LIB_EVP, ERR_R_PASSED_NULL_PARAMETER);
+            return 0;
+        }
+        *(unsigned char **)p2 = rctx->oaep_label;
+        return (int)rctx->oaep_labellen;
+
+    case EVP_PKEY_CTRL_RSA_IMPLICIT_REJECTION:
+        if (rctx->pad_mode != RSA_PKCS1_PADDING) {
+            ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_PADDING_MODE);
+            return -2;
+        }
+        rctx->implicit_rejection = p1;
+        return 1;
+
+    case EVP_PKEY_CTRL_DIGESTINIT:
+    case EVP_PKEY_CTRL_PKCS7_SIGN:
+#ifndef OPENSSL_NO_CMS
+    case EVP_PKEY_CTRL_CMS_SIGN:
+#endif
+        return 1;
+
+    case EVP_PKEY_CTRL_PKCS7_ENCRYPT:
+    case EVP_PKEY_CTRL_PKCS7_DECRYPT:
+#ifndef OPENSSL_NO_CMS
+    case EVP_PKEY_CTRL_CMS_DECRYPT:
+    case EVP_PKEY_CTRL_CMS_ENCRYPT:
+#endif
+        if (!pkey_ctx_is_pss(ctx))
+            return 1;
+    /* fall through */
+    case EVP_PKEY_CTRL_PEER_KEY:
+        ERR_raise(ERR_LIB_RSA, RSA_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE);
+        return -2;
+
+    default:
+        return -2;
+    }
+}
+
+static int pkey_rsa_ctrl_str(EVP_PKEY_CTX *ctx,
+    const char *type, const char *value)
+{
+    if (value == NULL) {
+        ERR_raise(ERR_LIB_RSA, RSA_R_VALUE_MISSING);
+        return 0;
+    }
+    if (strcmp(type, "rsa_padding_mode") == 0) {
+        int pm;
+
+        if (strcmp(value, "pkcs1") == 0) {
+            pm = RSA_PKCS1_PADDING;
+        } else if (strcmp(value, "none") == 0) {
+            pm = RSA_NO_PADDING;
+        } else if (strcmp(value, "oeap") == 0) {
+            pm = RSA_PKCS1_OAEP_PADDING;
+        } else if (strcmp(value, "oaep") == 0) {
+            pm = RSA_PKCS1_OAEP_PADDING;
+        } else if (strcmp(value, "x931") == 0) {
+            pm = RSA_X931_PADDING;
+        } else if (strcmp(value, "pss") == 0) {
+            pm = RSA_PKCS1_PSS_PADDING;
+        } else {
+            ERR_raise(ERR_LIB_RSA, RSA_R_UNKNOWN_PADDING_TYPE);
+            return -2;
+        }
+        return EVP_PKEY_CTX_set_rsa_padding(ctx, pm);
+    }
+
+    if (strcmp(type, "rsa_pss_saltlen") == 0) {
+        int saltlen;
+
+        if (!strcmp(value, "digest"))
+            saltlen = RSA_PSS_SALTLEN_DIGEST;
+        else if (!strcmp(value, "max"))
+            saltlen = RSA_PSS_SALTLEN_MAX;
+        else if (!strcmp(value, "auto"))
+            saltlen = RSA_PSS_SALTLEN_AUTO;
+        else
+            saltlen = atoi(value);
+        return EVP_PKEY_CTX_set_rsa_pss_saltlen(ctx, saltlen);
+    }
+
+    if (strcmp(type, "rsa_keygen_bits") == 0) {
+        int nbits = atoi(value);
+
+        return EVP_PKEY_CTX_set_rsa_keygen_bits(ctx, nbits);
+    }
+
+    if (strcmp(type, "rsa_keygen_pubexp") == 0) {
+        int ret;
+
+        BIGNUM *pubexp = NULL;
+        if (!BN_asc2bn(&pubexp, value))
+            return 0;
+        ret = EVP_PKEY_CTX_set1_rsa_keygen_pubexp(ctx, pubexp);
+        BN_free(pubexp);
+        return ret;
+    }
+
+    if (strcmp(type, "rsa_keygen_primes") == 0) {
+        int nprimes = atoi(value);
+
+        return EVP_PKEY_CTX_set_rsa_keygen_primes(ctx, nprimes);
+    }
+
+    if (strcmp(type, "rsa_mgf1_md") == 0)
+        return EVP_PKEY_CTX_md(ctx,
+            EVP_PKEY_OP_TYPE_SIG | EVP_PKEY_OP_TYPE_CRYPT,
+            EVP_PKEY_CTRL_RSA_MGF1_MD, value);
+
+    if (pkey_ctx_is_pss(ctx)) {
+
+        if (strcmp(type, "rsa_pss_keygen_mgf1_md") == 0)
+            return EVP_PKEY_CTX_md(ctx, EVP_PKEY_OP_KEYGEN,
+                EVP_PKEY_CTRL_RSA_MGF1_MD, value);
+
+        if (strcmp(type, "rsa_pss_keygen_md") == 0)
+            return EVP_PKEY_CTX_md(ctx, EVP_PKEY_OP_KEYGEN,
+                EVP_PKEY_CTRL_MD, value);
+
+        if (strcmp(type, "rsa_pss_keygen_saltlen") == 0) {
+            int saltlen = atoi(value);
+
+            return EVP_PKEY_CTX_set_rsa_pss_keygen_saltlen(ctx, saltlen);
+        }
+    }
+
+    if (strcmp(type, "rsa_oaep_md") == 0)
+        return EVP_PKEY_CTX_md(ctx, EVP_PKEY_OP_TYPE_CRYPT,
+            EVP_PKEY_CTRL_RSA_OAEP_MD, value);
+
+    if (strcmp(type, "rsa_oaep_label") == 0) {
+        unsigned char *lab;
+        long lablen;
+        int ret;
+
+        lab = OPENSSL_hexstr2buf(value, &lablen);
+        if (!lab)
+            return 0;
+        ret = EVP_PKEY_CTX_set0_rsa_oaep_label(ctx, lab, lablen);
+        if (ret <= 0)
+            OPENSSL_free(lab);
+        return ret;
+    }
+
+    return -2;
+}
+
+/* Set PSS parameters when generating a key, if necessary */
+static int rsa_set_pss_param(RSA *rsa, EVP_PKEY_CTX *ctx)
+{
+    RSA_PKEY_CTX *rctx = ctx->data;
+
+    if (!pkey_ctx_is_pss(ctx))
+        return 1;
+    /* If all parameters are default values don't set pss */
+    if (rctx->md == NULL && rctx->mgf1md == NULL && rctx->saltlen == -2)
+        return 1;
+    rsa->pss = ossl_rsa_pss_params_create(rctx->md, rctx->mgf1md,
+        rctx->saltlen == -2
+            ? 0
+            : rctx->saltlen);
+    if (rsa->pss == NULL)
+        return 0;
+    return 1;
+}
+
+static int pkey_rsa_keygen(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)
+{
+    RSA *rsa = NULL;
+    RSA_PKEY_CTX *rctx = ctx->data;
+    BN_GENCB *pcb;
+    int ret;
+
+    if (rctx->pub_exp == NULL) {
+        rctx->pub_exp = BN_new();
+        if (rctx->pub_exp == NULL || !BN_set_word(rctx->pub_exp, RSA_F4))
+            return 0;
+    }
+    rsa = RSA_new();
+    if (rsa == NULL)
+        return 0;
+    if (ctx->pkey_gencb) {
+        pcb = BN_GENCB_new();
+        if (pcb == NULL) {
+            RSA_free(rsa);
+            return 0;
+        }
+        evp_pkey_set_cb_translate(pcb, ctx);
+    } else {
+        pcb = NULL;
+    }
+    ret = RSA_generate_multi_prime_key(rsa, rctx->nbits, rctx->primes,
+        rctx->pub_exp, pcb);
+    BN_GENCB_free(pcb);
+    if (ret > 0 && !rsa_set_pss_param(rsa, ctx)) {
+        RSA_free(rsa);
+        return 0;
+    }
+    if (ret > 0)
+        EVP_PKEY_assign(pkey, ctx->pmeth->pkey_id, rsa);
+    else
+        RSA_free(rsa);
+    return ret;
+}
+
+static const EVP_PKEY_METHOD rsa_pkey_meth = {
+    EVP_PKEY_RSA,
+    EVP_PKEY_FLAG_AUTOARGLEN,
+    pkey_rsa_init,
+    pkey_rsa_copy,
+    pkey_rsa_cleanup,
+
+    0, 0,
+
+    0,
+    pkey_rsa_keygen,
+
+    0,
+    pkey_rsa_sign,
+
+    0,
+    pkey_rsa_verify,
+
+    0,
+    pkey_rsa_verifyrecover,
+
+    0, 0, 0, 0,
+
+    0,
+    pkey_rsa_encrypt,
+
+    0,
+    pkey_rsa_decrypt,
+
+    0, 0,
+
+    pkey_rsa_ctrl,
+    pkey_rsa_ctrl_str
+};
+
+const EVP_PKEY_METHOD *ossl_rsa_pkey_method(void)
+{
+    return &rsa_pkey_meth;
+}
+
+/*
+ * Called for PSS sign or verify initialisation: checks PSS parameter
+ * sanity and sets any restrictions on key usage.
+ */
+
+static int pkey_pss_init(EVP_PKEY_CTX *ctx)
+{
+    const RSA *rsa;
+    RSA_PKEY_CTX *rctx = ctx->data;
+    const EVP_MD *md;
+    const EVP_MD *mgf1md;
+    int min_saltlen, max_saltlen, md_size;
+
+    /* Should never happen */
+    if (!pkey_ctx_is_pss(ctx))
+        return 0;
+    rsa = EVP_PKEY_get0_RSA(ctx->pkey);
+    /* If no restrictions just return */
+    if (rsa->pss == NULL)
+        return 1;
+    /* Get and check parameters */
+    if (!ossl_rsa_pss_get_param(rsa->pss, &md, &mgf1md, &min_saltlen))
+        return 0;
+
+    /* See if minimum salt length exceeds maximum possible */
+    md_size = EVP_MD_get_size(md);
+    if (md_size <= 0) {
+        ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_DIGEST_LENGTH);
+        return 0;
+    }
+    max_saltlen = RSA_size(rsa) - md_size;
+    if ((RSA_bits(rsa) & 0x7) == 1)
+        max_saltlen--;
+    if (min_saltlen > max_saltlen) {
+        ERR_raise(ERR_LIB_RSA, RSA_R_INVALID_SALT_LENGTH);
+        return 0;
+    }
+
+    rctx->min_saltlen = min_saltlen;
+
+    /*
+     * Set PSS restrictions as defaults: we can then block any attempt to
+     * use invalid values in pkey_rsa_ctrl
+     */
+
+    rctx->md = md;
+    rctx->mgf1md = mgf1md;
+    rctx->saltlen = min_saltlen;
+
+    return 1;
+}
+
+static const EVP_PKEY_METHOD rsa_pss_pkey_meth = {
+    EVP_PKEY_RSA_PSS,
+    EVP_PKEY_FLAG_AUTOARGLEN,
+    pkey_rsa_init,
+    pkey_rsa_copy,
+    pkey_rsa_cleanup,
+
+    0, 0,
+
+    0,
+    pkey_rsa_keygen,
+
+    pkey_pss_init,
+    pkey_rsa_sign,
+
+    pkey_pss_init,
+    pkey_rsa_verify,
+
+    0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0,
+
+    pkey_rsa_ctrl,
+    pkey_rsa_ctrl_str
+};
+
+const EVP_PKEY_METHOD *ossl_rsa_pss_pkey_method(void)
+{
+    return &rsa_pss_pkey_meth;
+}
diff --git a/crypto/rsa/rsa_saos.c b/crypto/rsa/rsa_saos.c
index 28844843f3..afcc4c9a4d 100644
--- a/crypto/rsa/rsa_saos.c
+++ b/crypto/rsa/rsa_saos.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -19,7 +19,6 @@
 #include 
 #include 
 #include 
-#include 
 
 int RSA_sign_ASN1_OCTET_STRING(int type,
     const unsigned char *m, unsigned int m_len,
diff --git a/crypto/rsa/rsa_sp800_56b_check.c b/crypto/rsa/rsa_sp800_56b_check.c
index b9f39dd091..6033988933 100644
--- a/crypto/rsa/rsa_sp800_56b_check.c
+++ b/crypto/rsa/rsa_sp800_56b_check.c
@@ -104,7 +104,7 @@ int ossl_rsa_check_prime_factor_range(const BIGNUM *p, int nbits, BN_CTX *ctx)
         goto err;
 
     /* set low = (√2)(2^(nbits/2 - 1) */
-    if (BN_copy(low, &ossl_bn_inv_sqrt_2) == NULL)
+    if (!BN_copy(low, &ossl_bn_inv_sqrt_2))
         goto err;
 
     if (shift >= 0) {
diff --git a/include/arch/s390x_arch.h b/crypto/s390x_arch.h
similarity index 95%
rename from include/arch/s390x_arch.h
rename to crypto/s390x_arch.h
index 95c01dd2dc..c3a805b359 100644
--- a/include/arch/s390x_arch.h
+++ b/crypto/s390x_arch.h
@@ -31,7 +31,6 @@ void s390x_kma(const unsigned char *aad, size_t alen, const unsigned char *in,
 int s390x_pcc(unsigned int fc, void *param);
 int s390x_kdsa(unsigned int fc, void *param, const unsigned char *in,
     size_t len);
-void OPENSSL_s390x_cleanup(void);
 
 void s390x_flip_endian32(unsigned char dst[32], const unsigned char src[32]);
 void s390x_flip_endian64(unsigned char dst[64], const unsigned char src[64]);
@@ -204,9 +203,4 @@ extern int OPENSSL_s390xcex_nodev;
 #define S390X_KMAC_IIMP 0x4000
 #define S390X_KMAC_CCUP 0x2000
 
-/* Are the s390x vector instructions (VX and VXE) supported? */
-/* This is the case for >= z13 (VX) and >= z14 (VXE).        */
-#define S390X_VX_CAPABLE ( \
-    (OPENSSL_s390xcap_P.stfle[2] & S390X_CAPBIT(S390X_VX)) && (OPENSSL_s390xcap_P.stfle[2] & S390X_CAPBIT(S390X_VXE)))
-
 #endif
diff --git a/crypto/s390xcap.c b/crypto/s390xcap.c
index 2d2d4b9f3b..e1e75173af 100644
--- a/crypto/s390xcap.c
+++ b/crypto/s390xcap.c
@@ -14,7 +14,7 @@
 #include 
 #include "internal/cryptlib.h"
 #include "crypto/ctype.h"
-#include "arch/s390x_arch.h"
+#include "s390x_arch.h"
 
 #if defined(OPENSSL_SYS_LINUX) && !defined(FIPS_MODULE)
 #include 
@@ -221,6 +221,7 @@ void OPENSSL_cpuid_setup(void)
         OPENSSL_s390xcex = -1;
     } else {
         OPENSSL_s390xcex = open("/dev/z90crypt", O_RDWR | O_CLOEXEC);
+        OPENSSL_atexit(OPENSSL_s390x_cleanup);
     }
     OPENSSL_s390xcex_nodev = 0;
 #endif
@@ -228,7 +229,6 @@ void OPENSSL_cpuid_setup(void)
 
 static int parse_env(struct OPENSSL_s390xcap_st *cap, int *cex)
 {
-    /* clang-format off */
     /*-
      * CPU model data
      * (only the STFLE- and QUERY-bits relevant to libcrypto are set)
@@ -239,19 +239,19 @@ static int parse_env(struct OPENSSL_s390xcap_st *cap, int *cex)
      * Facility detection would fail on real hw (no STFLE).
      */
     static const struct OPENSSL_s390xcap_st z900 = {
-        .stfle  = { 0ULL, 0ULL, 0ULL, 0ULL },
-        .kimd   = { 0ULL, 0ULL },
-        .klmd   = { 0ULL, 0ULL },
-        .km     = { 0ULL, 0ULL },
-        .kmc    = { 0ULL, 0ULL },
-        .kmac   = { 0ULL, 0ULL },
-        .kmctr  = { 0ULL, 0ULL },
-        .kmo    = { 0ULL, 0ULL },
-        .kmf    = { 0ULL, 0ULL },
-        .prno   = { 0ULL, 0ULL },
-        .kma    = { 0ULL, 0ULL },
-        .pcc    = { 0ULL, 0ULL },
-        .kdsa   = { 0ULL, 0ULL },
+        /*.stfle  = */ { 0ULL, 0ULL, 0ULL, 0ULL },
+        /*.kimd   = */ { 0ULL, 0ULL },
+        /*.klmd   = */ { 0ULL, 0ULL },
+        /*.km     = */ { 0ULL, 0ULL },
+        /*.kmc    = */ { 0ULL, 0ULL },
+        /*.kmac   = */ { 0ULL, 0ULL },
+        /*.kmctr  = */ { 0ULL, 0ULL },
+        /*.kmo    = */ { 0ULL, 0ULL },
+        /*.kmf    = */ { 0ULL, 0ULL },
+        /*.prno   = */ { 0ULL, 0ULL },
+        /*.kma    = */ { 0ULL, 0ULL },
+        /*.pcc    = */ { 0ULL, 0ULL },
+        /*.kdsa   = */ { 0ULL, 0ULL },
     };
 
     /*-
@@ -259,27 +259,20 @@ static int parse_env(struct OPENSSL_s390xcap_st *cap, int *cex)
      * Implements MSA. Facility detection would fail on real hw (no STFLE).
      */
     static const struct OPENSSL_s390xcap_st z990 = {
-        .stfle  = { S390X_CAPBIT(S390X_MSA),
-                    0ULL, 0ULL, 0ULL },
-        .kimd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1),
-                    0ULL },
-        .klmd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1),
-                    0ULL },
-        .km     = { S390X_CAPBIT(S390X_QUERY),
-                    0ULL },
-        .kmc    = { S390X_CAPBIT(S390X_QUERY),
-                    0ULL },
-        .kmac   = { S390X_CAPBIT(S390X_QUERY),
-                    0ULL },
-        .kmctr  = { 0ULL, 0ULL },
-        .kmo    = { 0ULL, 0ULL },
-        .kmf    = { 0ULL, 0ULL },
-        .prno   = { 0ULL, 0ULL },
-        .kma    = { 0ULL, 0ULL },
-        .pcc    = { 0ULL, 0ULL },
-        .kdsa   = { 0ULL, 0ULL },
+        /*.stfle  = */ { S390X_CAPBIT(S390X_MSA),
+            0ULL, 0ULL, 0ULL },
+        /*.kimd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1), 0ULL },
+        /*.klmd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1), 0ULL },
+        /*.km     = */ { S390X_CAPBIT(S390X_QUERY), 0ULL },
+        /*.kmc    = */ { S390X_CAPBIT(S390X_QUERY), 0ULL },
+        /*.kmac   = */ { S390X_CAPBIT(S390X_QUERY), 0ULL },
+        /*.kmctr  = */ { 0ULL, 0ULL },
+        /*.kmo    = */ { 0ULL, 0ULL },
+        /*.kmf    = */ { 0ULL, 0ULL },
+        /*.prno   = */ { 0ULL, 0ULL },
+        /*.kma    = */ { 0ULL, 0ULL },
+        /*.pcc    = */ { 0ULL, 0ULL },
+        /*.kdsa   = */ { 0ULL, 0ULL },
     };
 
     /*-
@@ -287,32 +280,21 @@ static int parse_env(struct OPENSSL_s390xcap_st *cap, int *cex)
      * Implements MSA and MSA1.
      */
     static const struct OPENSSL_s390xcap_st z9 = {
-        .stfle  = { S390X_CAPBIT(S390X_MSA)
-                    | S390X_CAPBIT(S390X_STCKF),
-                    0ULL, 0ULL, 0ULL },
-        .kimd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256),
-                    0ULL },
-        .klmd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256),
-                    0ULL },
-        .km     = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128),
-                    0ULL },
-        .kmc    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128),
-                    0ULL },
-        .kmac   = { S390X_CAPBIT(S390X_QUERY),
-                    0ULL },
-        .kmctr  = { 0ULL, 0ULL },
-        .kmo    = { 0ULL, 0ULL },
-        .kmf    = { 0ULL, 0ULL },
-        .prno   = { 0ULL, 0ULL },
-        .kma    = { 0ULL, 0ULL },
-        .pcc    = { 0ULL, 0ULL },
-        .kdsa   = { 0ULL, 0ULL },
+        /*.stfle  = */ { S390X_CAPBIT(S390X_MSA)
+                | S390X_CAPBIT(S390X_STCKF),
+            0ULL, 0ULL, 0ULL },
+        /*.kimd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256), 0ULL },
+        /*.klmd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256), 0ULL },
+        /*.km     = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128), 0ULL },
+        /*.kmc    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128), 0ULL },
+        /*.kmac   = */ { S390X_CAPBIT(S390X_QUERY), 0ULL },
+        /*.kmctr  = */ { 0ULL, 0ULL },
+        /*.kmo    = */ { 0ULL, 0ULL },
+        /*.kmf    = */ { 0ULL, 0ULL },
+        /*.prno   = */ { 0ULL, 0ULL },
+        /*.kma    = */ { 0ULL, 0ULL },
+        /*.pcc    = */ { 0ULL, 0ULL },
+        /*.kdsa   = */ { 0ULL, 0ULL },
     };
 
     /*-
@@ -320,38 +302,21 @@ static int parse_env(struct OPENSSL_s390xcap_st *cap, int *cex)
      * Implements MSA and MSA1-2.
      */
     static const struct OPENSSL_s390xcap_st z10 = {
-        .stfle  = { S390X_CAPBIT(S390X_MSA)
-                    | S390X_CAPBIT(S390X_STCKF),
-                    0ULL, 0ULL, 0ULL },
-        .kimd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256)
-                    | S390X_CAPBIT(S390X_SHA_512),
-                    0ULL },
-        .klmd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256)
-                    | S390X_CAPBIT(S390X_SHA_512),
-                    0ULL },
-        .km     = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmc    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmac   = { S390X_CAPBIT(S390X_QUERY),
-                    0ULL },
-        .kmctr  = { 0ULL, 0ULL },
-        .kmo    = { 0ULL, 0ULL },
-        .kmf    = { 0ULL, 0ULL },
-        .prno   = { 0ULL, 0ULL },
-        .kma    = { 0ULL, 0ULL },
-        .pcc    = { 0ULL, 0ULL },
-        .kdsa   = { 0ULL, 0ULL },
+        /*.stfle  = */ { S390X_CAPBIT(S390X_MSA)
+                | S390X_CAPBIT(S390X_STCKF),
+            0ULL, 0ULL, 0ULL },
+        /*.kimd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256) | S390X_CAPBIT(S390X_SHA_512), 0ULL },
+        /*.klmd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256) | S390X_CAPBIT(S390X_SHA_512), 0ULL },
+        /*.km     = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmc    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmac   = */ { S390X_CAPBIT(S390X_QUERY), 0ULL },
+        /*.kmctr  = */ { 0ULL, 0ULL },
+        /*.kmo    = */ { 0ULL, 0ULL },
+        /*.kmf    = */ { 0ULL, 0ULL },
+        /*.prno   = */ { 0ULL, 0ULL },
+        /*.kma    = */ { 0ULL, 0ULL },
+        /*.pcc    = */ { 0ULL, 0ULL },
+        /*.kdsa   = */ { 0ULL, 0ULL },
     };
 
     /*-
@@ -359,58 +324,23 @@ static int parse_env(struct OPENSSL_s390xcap_st *cap, int *cex)
      * Implements MSA and MSA1-4.
      */
     static const struct OPENSSL_s390xcap_st z196 = {
-        .stfle  = { S390X_CAPBIT(S390X_MSA)
-                    | S390X_CAPBIT(S390X_STCKF),
-                    S390X_CAPBIT(S390X_MSA3)
-                    | S390X_CAPBIT(S390X_MSA4),
-                    0ULL, 0ULL },
-        .kimd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256)
-                    | S390X_CAPBIT(S390X_SHA_512),
-                    S390X_CAPBIT(S390X_GHASH) },
-        .klmd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256)
-                    | S390X_CAPBIT(S390X_SHA_512),
-                    0ULL },
-        .km     = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256)
-                    | S390X_CAPBIT(S390X_XTS_AES_128)
-                    | S390X_CAPBIT(S390X_XTS_AES_256),
-                    0ULL },
-        .kmc    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmac   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmctr  = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmo    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmf    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .prno   = { 0ULL, 0ULL },
-        .kma    = { 0ULL, 0ULL },
-        .pcc    = { S390X_CAPBIT(S390X_QUERY),
-                    0ULL },
-        .kdsa   = { 0ULL, 0ULL },
+        /*.stfle  = */ { S390X_CAPBIT(S390X_MSA)
+                | S390X_CAPBIT(S390X_STCKF),
+            S390X_CAPBIT(S390X_MSA3)
+                | S390X_CAPBIT(S390X_MSA4),
+            0ULL, 0ULL },
+        /*.kimd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256) | S390X_CAPBIT(S390X_SHA_512), S390X_CAPBIT(S390X_GHASH) },
+        /*.klmd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256) | S390X_CAPBIT(S390X_SHA_512), 0ULL },
+        /*.km     = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256) | S390X_CAPBIT(S390X_XTS_AES_128) | S390X_CAPBIT(S390X_XTS_AES_256), 0ULL },
+        /*.kmc    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmac   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmctr  = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmo    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmf    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.prno   = */ { 0ULL, 0ULL },
+        /*.kma    = */ { 0ULL, 0ULL },
+        /*.pcc    = */ { S390X_CAPBIT(S390X_QUERY), 0ULL },
+        /*.kdsa   = */ { 0ULL, 0ULL },
     };
 
     /*-
@@ -418,58 +348,23 @@ static int parse_env(struct OPENSSL_s390xcap_st *cap, int *cex)
      * Implements MSA and MSA1-4.
      */
     static const struct OPENSSL_s390xcap_st zEC12 = {
-        .stfle  = { S390X_CAPBIT(S390X_MSA)
-                    | S390X_CAPBIT(S390X_STCKF),
-                    S390X_CAPBIT(S390X_MSA3)
-                    | S390X_CAPBIT(S390X_MSA4),
-                    0ULL, 0ULL },
-        .kimd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256)
-                    | S390X_CAPBIT(S390X_SHA_512),
-                    S390X_CAPBIT(S390X_GHASH) },
-        .klmd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256)
-                    | S390X_CAPBIT(S390X_SHA_512),
-                    0ULL },
-        .km     = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256)
-                    | S390X_CAPBIT(S390X_XTS_AES_128)
-                    | S390X_CAPBIT(S390X_XTS_AES_256),
-                    0ULL },
-        .kmc    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmac   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmctr  = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmo    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmf    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .prno   = { 0ULL, 0ULL },
-        .kma    = { 0ULL, 0ULL },
-        .pcc    = { S390X_CAPBIT(S390X_QUERY),
-                    0ULL },
-        .kdsa   = { 0ULL, 0ULL },
+        /*.stfle  = */ { S390X_CAPBIT(S390X_MSA)
+                | S390X_CAPBIT(S390X_STCKF),
+            S390X_CAPBIT(S390X_MSA3)
+                | S390X_CAPBIT(S390X_MSA4),
+            0ULL, 0ULL },
+        /*.kimd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256) | S390X_CAPBIT(S390X_SHA_512), S390X_CAPBIT(S390X_GHASH) },
+        /*.klmd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256) | S390X_CAPBIT(S390X_SHA_512), 0ULL },
+        /*.km     = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256) | S390X_CAPBIT(S390X_XTS_AES_128) | S390X_CAPBIT(S390X_XTS_AES_256), 0ULL },
+        /*.kmc    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmac   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmctr  = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmo    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmf    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.prno   = */ { 0ULL, 0ULL },
+        /*.kma    = */ { 0ULL, 0ULL },
+        /*.pcc    = */ { S390X_CAPBIT(S390X_QUERY), 0ULL },
+        /*.kdsa   = */ { 0ULL, 0ULL },
     };
 
     /*-
@@ -477,62 +372,25 @@ static int parse_env(struct OPENSSL_s390xcap_st *cap, int *cex)
      * Implements MSA and MSA1-5.
      */
     static const struct OPENSSL_s390xcap_st z13 = {
-        .stfle  = { S390X_CAPBIT(S390X_MSA)
-                    | S390X_CAPBIT(S390X_STCKF)
-                    | S390X_CAPBIT(S390X_MSA5),
-                    S390X_CAPBIT(S390X_MSA3)
-                    | S390X_CAPBIT(S390X_MSA4),
-                    S390X_CAPBIT(S390X_VX),
-                    0ULL },
-        .kimd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256)
-                    | S390X_CAPBIT(S390X_SHA_512),
-                    S390X_CAPBIT(S390X_GHASH) },
-        .klmd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256)
-                    | S390X_CAPBIT(S390X_SHA_512),
-                    0ULL },
-        .km     = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256)
-                    | S390X_CAPBIT(S390X_XTS_AES_128)
-                    | S390X_CAPBIT(S390X_XTS_AES_256),
-                    0ULL },
-        .kmc    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmac   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmctr  = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmo    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmf    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .prno   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_512_DRNG),
-                    0ULL },
-        .kma    = { 0ULL, 0ULL },
-        .pcc    = { S390X_CAPBIT(S390X_QUERY),
-                    0ULL },
-        .kdsa   = { 0ULL, 0ULL },
+        /*.stfle  = */ { S390X_CAPBIT(S390X_MSA)
+                | S390X_CAPBIT(S390X_STCKF)
+                | S390X_CAPBIT(S390X_MSA5),
+            S390X_CAPBIT(S390X_MSA3)
+                | S390X_CAPBIT(S390X_MSA4),
+            S390X_CAPBIT(S390X_VX),
+            0ULL },
+        /*.kimd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256) | S390X_CAPBIT(S390X_SHA_512), S390X_CAPBIT(S390X_GHASH) },
+        /*.klmd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256) | S390X_CAPBIT(S390X_SHA_512), 0ULL },
+        /*.km     = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256) | S390X_CAPBIT(S390X_XTS_AES_128) | S390X_CAPBIT(S390X_XTS_AES_256), 0ULL },
+        /*.kmc    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmac   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmctr  = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmo    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmf    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.prno   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_512_DRNG), 0ULL },
+        /*.kma    = */ { 0ULL, 0ULL },
+        /*.pcc    = */ { S390X_CAPBIT(S390X_QUERY), 0ULL },
+        /*.kdsa   = */ { 0ULL, 0ULL },
     };
 
     /*-
@@ -540,81 +398,28 @@ static int parse_env(struct OPENSSL_s390xcap_st *cap, int *cex)
      * Implements MSA and MSA1-8.
      */
     static const struct OPENSSL_s390xcap_st z14 = {
-        .stfle  = { S390X_CAPBIT(S390X_MSA)
-                    | S390X_CAPBIT(S390X_STCKF)
-                    | S390X_CAPBIT(S390X_MSA5),
-                    S390X_CAPBIT(S390X_MSA3)
-                    | S390X_CAPBIT(S390X_MSA4),
-                    S390X_CAPBIT(S390X_VX)
-                    | S390X_CAPBIT(S390X_VXD)
-                    | S390X_CAPBIT(S390X_VXE)
-                    | S390X_CAPBIT(S390X_MSA8),
-                    0ULL },
-        .kimd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256)
-                    | S390X_CAPBIT(S390X_SHA_512)
-                    | S390X_CAPBIT(S390X_SHA3_224)
-                    | S390X_CAPBIT(S390X_SHA3_256)
-                    | S390X_CAPBIT(S390X_SHA3_384)
-                    | S390X_CAPBIT(S390X_SHA3_512)
-                    | S390X_CAPBIT(S390X_SHAKE_128)
-                    | S390X_CAPBIT(S390X_SHAKE_256),
-                    S390X_CAPBIT(S390X_GHASH) },
-        .klmd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256)
-                    | S390X_CAPBIT(S390X_SHA_512)
-                    | S390X_CAPBIT(S390X_SHA3_224)
-                    | S390X_CAPBIT(S390X_SHA3_256)
-                    | S390X_CAPBIT(S390X_SHA3_384)
-                    | S390X_CAPBIT(S390X_SHA3_512)
-                    | S390X_CAPBIT(S390X_SHAKE_128)
-                    | S390X_CAPBIT(S390X_SHAKE_256),
-                    0ULL },
-        .km     = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256)
-                    | S390X_CAPBIT(S390X_XTS_AES_128)
-                    | S390X_CAPBIT(S390X_XTS_AES_256),
-                    0ULL },
-        .kmc    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmac   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmctr  = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmo    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmf    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .prno   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_512_DRNG),
-                    S390X_CAPBIT(S390X_TRNG) },
-        .kma    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .pcc    = { S390X_CAPBIT(S390X_QUERY),
-                    0ULL },
-        .kdsa   = { 0ULL, 0ULL },
+        /*.stfle  = */ { S390X_CAPBIT(S390X_MSA)
+                | S390X_CAPBIT(S390X_STCKF)
+                | S390X_CAPBIT(S390X_MSA5),
+            S390X_CAPBIT(S390X_MSA3)
+                | S390X_CAPBIT(S390X_MSA4),
+            S390X_CAPBIT(S390X_VX)
+                | S390X_CAPBIT(S390X_VXD)
+                | S390X_CAPBIT(S390X_VXE)
+                | S390X_CAPBIT(S390X_MSA8),
+            0ULL },
+        /*.kimd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256) | S390X_CAPBIT(S390X_SHA_512) | S390X_CAPBIT(S390X_SHA3_224) | S390X_CAPBIT(S390X_SHA3_256) | S390X_CAPBIT(S390X_SHA3_384) | S390X_CAPBIT(S390X_SHA3_512) | S390X_CAPBIT(S390X_SHAKE_128) | S390X_CAPBIT(S390X_SHAKE_256), S390X_CAPBIT(S390X_GHASH) },
+        /*.klmd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256) | S390X_CAPBIT(S390X_SHA_512) | S390X_CAPBIT(S390X_SHA3_224) | S390X_CAPBIT(S390X_SHA3_256) | S390X_CAPBIT(S390X_SHA3_384) | S390X_CAPBIT(S390X_SHA3_512) | S390X_CAPBIT(S390X_SHAKE_128) | S390X_CAPBIT(S390X_SHAKE_256), 0ULL },
+        /*.km     = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256) | S390X_CAPBIT(S390X_XTS_AES_128) | S390X_CAPBIT(S390X_XTS_AES_256), 0ULL },
+        /*.kmc    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmac   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmctr  = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmo    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmf    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.prno   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_512_DRNG), S390X_CAPBIT(S390X_TRNG) },
+        /*.kma    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.pcc    = */ { S390X_CAPBIT(S390X_QUERY), 0ULL },
+        /*.kdsa   = */ { 0ULL, 0ULL },
     };
 
     /*-
@@ -622,99 +427,29 @@ static int parse_env(struct OPENSSL_s390xcap_st *cap, int *cex)
      * Implements MSA and MSA1-9.
      */
     static const struct OPENSSL_s390xcap_st z15 = {
-        .stfle  = { S390X_CAPBIT(S390X_MSA)
-                    | S390X_CAPBIT(S390X_STCKF)
-                    | S390X_CAPBIT(S390X_MSA5),
-                    S390X_CAPBIT(S390X_MSA3)
-                    | S390X_CAPBIT(S390X_MSA4),
-                    S390X_CAPBIT(S390X_VX)
-                    | S390X_CAPBIT(S390X_VXD)
-                    | S390X_CAPBIT(S390X_VXE)
-                    | S390X_CAPBIT(S390X_MSA8)
-                    | S390X_CAPBIT(S390X_MSA9),
-                    0ULL },
-        .kimd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256)
-                    | S390X_CAPBIT(S390X_SHA_512)
-                    | S390X_CAPBIT(S390X_SHA3_224)
-                    | S390X_CAPBIT(S390X_SHA3_256)
-                    | S390X_CAPBIT(S390X_SHA3_384)
-                    | S390X_CAPBIT(S390X_SHA3_512)
-                    | S390X_CAPBIT(S390X_SHAKE_128)
-                    | S390X_CAPBIT(S390X_SHAKE_256),
-                    S390X_CAPBIT(S390X_GHASH) },
-        .klmd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256)
-                    | S390X_CAPBIT(S390X_SHA_512)
-                    | S390X_CAPBIT(S390X_SHA3_224)
-                    | S390X_CAPBIT(S390X_SHA3_256)
-                    | S390X_CAPBIT(S390X_SHA3_384)
-                    | S390X_CAPBIT(S390X_SHA3_512)
-                    | S390X_CAPBIT(S390X_SHAKE_128)
-                    | S390X_CAPBIT(S390X_SHAKE_256),
-                    0ULL },
-        .km     = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256)
-                    | S390X_CAPBIT(S390X_XTS_AES_128)
-                    | S390X_CAPBIT(S390X_XTS_AES_256),
-                    0ULL },
-        .kmc    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmac   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmctr  = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmo    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmf    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL},
-        .prno   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_512_DRNG),
-                    S390X_CAPBIT(S390X_TRNG) },
-        .kma    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .pcc    = { S390X_CAPBIT(S390X_QUERY),
-                    S390X_CAPBIT(S390X_SCALAR_MULTIPLY_P256)
-                    | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_P384)
-                    | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_P521)
-                    | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_ED25519)
-                    | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_ED448)
-                    | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_X25519)
-                    | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_X448) },
-        .kdsa   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_ECDSA_VERIFY_P256)
-                    | S390X_CAPBIT(S390X_ECDSA_VERIFY_P384)
-                    | S390X_CAPBIT(S390X_ECDSA_VERIFY_P521)
-                    | S390X_CAPBIT(S390X_ECDSA_SIGN_P256)
-                    | S390X_CAPBIT(S390X_ECDSA_SIGN_P384)
-                    | S390X_CAPBIT(S390X_ECDSA_SIGN_P521)
-                    | S390X_CAPBIT(S390X_EDDSA_VERIFY_ED25519)
-                    | S390X_CAPBIT(S390X_EDDSA_VERIFY_ED448)
-                    | S390X_CAPBIT(S390X_EDDSA_SIGN_ED25519)
-                    | S390X_CAPBIT(S390X_EDDSA_SIGN_ED448),
-                    0ULL },
+        /*.stfle  = */ { S390X_CAPBIT(S390X_MSA)
+                | S390X_CAPBIT(S390X_STCKF)
+                | S390X_CAPBIT(S390X_MSA5),
+            S390X_CAPBIT(S390X_MSA3)
+                | S390X_CAPBIT(S390X_MSA4),
+            S390X_CAPBIT(S390X_VX)
+                | S390X_CAPBIT(S390X_VXD)
+                | S390X_CAPBIT(S390X_VXE)
+                | S390X_CAPBIT(S390X_MSA8)
+                | S390X_CAPBIT(S390X_MSA9),
+            0ULL },
+        /*.kimd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256) | S390X_CAPBIT(S390X_SHA_512) | S390X_CAPBIT(S390X_SHA3_224) | S390X_CAPBIT(S390X_SHA3_256) | S390X_CAPBIT(S390X_SHA3_384) | S390X_CAPBIT(S390X_SHA3_512) | S390X_CAPBIT(S390X_SHAKE_128) | S390X_CAPBIT(S390X_SHAKE_256), S390X_CAPBIT(S390X_GHASH) },
+        /*.klmd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256) | S390X_CAPBIT(S390X_SHA_512) | S390X_CAPBIT(S390X_SHA3_224) | S390X_CAPBIT(S390X_SHA3_256) | S390X_CAPBIT(S390X_SHA3_384) | S390X_CAPBIT(S390X_SHA3_512) | S390X_CAPBIT(S390X_SHAKE_128) | S390X_CAPBIT(S390X_SHAKE_256), 0ULL },
+        /*.km     = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256) | S390X_CAPBIT(S390X_XTS_AES_128) | S390X_CAPBIT(S390X_XTS_AES_256), 0ULL },
+        /*.kmc    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmac   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmctr  = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmo    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmf    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.prno   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_512_DRNG), S390X_CAPBIT(S390X_TRNG) },
+        /*.kma    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.pcc    = */ { S390X_CAPBIT(S390X_QUERY), S390X_CAPBIT(S390X_SCALAR_MULTIPLY_P256) | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_P384) | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_P521) | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_ED25519) | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_ED448) | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_X25519) | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_X448) },
+        /*.kdsa   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_ECDSA_VERIFY_P256) | S390X_CAPBIT(S390X_ECDSA_VERIFY_P384) | S390X_CAPBIT(S390X_ECDSA_VERIFY_P521) | S390X_CAPBIT(S390X_ECDSA_SIGN_P256) | S390X_CAPBIT(S390X_ECDSA_SIGN_P384) | S390X_CAPBIT(S390X_ECDSA_SIGN_P521) | S390X_CAPBIT(S390X_EDDSA_VERIFY_ED25519) | S390X_CAPBIT(S390X_EDDSA_VERIFY_ED448) | S390X_CAPBIT(S390X_EDDSA_SIGN_ED25519) | S390X_CAPBIT(S390X_EDDSA_SIGN_ED448), 0ULL },
     };
 
     /*-
@@ -727,108 +462,32 @@ static int parse_env(struct OPENSSL_s390xcap_st *cap, int *cex)
      * Implements MSA and MSA1-12.
      */
     static const struct OPENSSL_s390xcap_st z17 = {
-        .stfle  = { S390X_CAPBIT(S390X_MSA)
-                    | S390X_CAPBIT(S390X_STCKF)
-                    | S390X_CAPBIT(S390X_MSA5),
-                    S390X_CAPBIT(S390X_MSA3)
-                    | S390X_CAPBIT(S390X_MSA4)
-                    | S390X_CAPBIT(S390X_MSA12),
-                    S390X_CAPBIT(S390X_VX)
-                    | S390X_CAPBIT(S390X_VXD)
-                    | S390X_CAPBIT(S390X_VXE)
-                    | S390X_CAPBIT(S390X_MSA8)
-                    | S390X_CAPBIT(S390X_MSA9),
-                    0ULL },
-        .kimd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256)
-                    | S390X_CAPBIT(S390X_SHA_512)
-                    | S390X_CAPBIT(S390X_SHA3_224)
-                    | S390X_CAPBIT(S390X_SHA3_256)
-                    | S390X_CAPBIT(S390X_SHA3_384)
-                    | S390X_CAPBIT(S390X_SHA3_512)
-                    | S390X_CAPBIT(S390X_SHAKE_128)
-                    | S390X_CAPBIT(S390X_SHAKE_256),
-                    S390X_CAPBIT(S390X_GHASH) },
-        .klmd   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_1)
-                    | S390X_CAPBIT(S390X_SHA_256)
-                    | S390X_CAPBIT(S390X_SHA_512)
-                    | S390X_CAPBIT(S390X_SHA3_224)
-                    | S390X_CAPBIT(S390X_SHA3_256)
-                    | S390X_CAPBIT(S390X_SHA3_384)
-                    | S390X_CAPBIT(S390X_SHA3_512)
-                    | S390X_CAPBIT(S390X_SHAKE_128)
-                    | S390X_CAPBIT(S390X_SHAKE_256),
-                    0ULL },
-        .km     = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256)
-                    | S390X_CAPBIT(S390X_XTS_AES_128)
-                    | S390X_CAPBIT(S390X_XTS_AES_256),
-                    S390X_CAPBIT(S390X_XTS_AES_128_MSA10)
-                    | S390X_CAPBIT(S390X_XTS_AES_256_MSA10) },
-        .kmc    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmac   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    S390X_CAPBIT(S390X_HMAC_SHA_224)
-                    | S390X_CAPBIT(S390X_HMAC_SHA_256)
-                    | S390X_CAPBIT(S390X_HMAC_SHA_384)
-                    | S390X_CAPBIT(S390X_HMAC_SHA_512) },
-        .kmctr  = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmo    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .kmf    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .prno   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_SHA_512_DRNG),
-                    S390X_CAPBIT(S390X_TRNG) },
-        .kma    = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_AES_128)
-                    | S390X_CAPBIT(S390X_AES_192)
-                    | S390X_CAPBIT(S390X_AES_256),
-                    0ULL },
-        .pcc    = { S390X_CAPBIT(S390X_QUERY),
-                    S390X_CAPBIT(S390X_SCALAR_MULTIPLY_P256)
-                    | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_P384)
-                    | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_P521)
-                    | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_ED25519)
-                    | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_ED448)
-                    | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_X25519)
-                    | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_X448) },
-        .kdsa   = { S390X_CAPBIT(S390X_QUERY)
-                    | S390X_CAPBIT(S390X_ECDSA_VERIFY_P256)
-                    | S390X_CAPBIT(S390X_ECDSA_VERIFY_P384)
-                    | S390X_CAPBIT(S390X_ECDSA_VERIFY_P521)
-                    | S390X_CAPBIT(S390X_ECDSA_SIGN_P256)
-                    | S390X_CAPBIT(S390X_ECDSA_SIGN_P384)
-                    | S390X_CAPBIT(S390X_ECDSA_SIGN_P521)
-                    | S390X_CAPBIT(S390X_EDDSA_VERIFY_ED25519)
-                    | S390X_CAPBIT(S390X_EDDSA_VERIFY_ED448)
-                    | S390X_CAPBIT(S390X_EDDSA_SIGN_ED25519)
-                    | S390X_CAPBIT(S390X_EDDSA_SIGN_ED448),
-                    0ULL },
+        /*.stfle  = */ { S390X_CAPBIT(S390X_MSA)
+                | S390X_CAPBIT(S390X_STCKF)
+                | S390X_CAPBIT(S390X_MSA5),
+            S390X_CAPBIT(S390X_MSA3)
+                | S390X_CAPBIT(S390X_MSA4)
+                | S390X_CAPBIT(S390X_MSA12),
+            S390X_CAPBIT(S390X_VX)
+                | S390X_CAPBIT(S390X_VXD)
+                | S390X_CAPBIT(S390X_VXE)
+                | S390X_CAPBIT(S390X_MSA8)
+                | S390X_CAPBIT(S390X_MSA9),
+            0ULL },
+        /*.kimd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256) | S390X_CAPBIT(S390X_SHA_512) | S390X_CAPBIT(S390X_SHA3_224) | S390X_CAPBIT(S390X_SHA3_256) | S390X_CAPBIT(S390X_SHA3_384) | S390X_CAPBIT(S390X_SHA3_512) | S390X_CAPBIT(S390X_SHAKE_128) | S390X_CAPBIT(S390X_SHAKE_256), S390X_CAPBIT(S390X_GHASH) },
+        /*.klmd   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_1) | S390X_CAPBIT(S390X_SHA_256) | S390X_CAPBIT(S390X_SHA_512) | S390X_CAPBIT(S390X_SHA3_224) | S390X_CAPBIT(S390X_SHA3_256) | S390X_CAPBIT(S390X_SHA3_384) | S390X_CAPBIT(S390X_SHA3_512) | S390X_CAPBIT(S390X_SHAKE_128) | S390X_CAPBIT(S390X_SHAKE_256), 0ULL },
+        /*.km     = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256) | S390X_CAPBIT(S390X_XTS_AES_128) | S390X_CAPBIT(S390X_XTS_AES_256), S390X_CAPBIT(S390X_XTS_AES_128_MSA10) | S390X_CAPBIT(S390X_XTS_AES_256_MSA10) },
+        /*.kmc    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmac   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), S390X_CAPBIT(S390X_HMAC_SHA_224) | S390X_CAPBIT(S390X_HMAC_SHA_256) | S390X_CAPBIT(S390X_HMAC_SHA_384) | S390X_CAPBIT(S390X_HMAC_SHA_512) },
+        /*.kmctr  = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmo    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.kmf    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.prno   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_SHA_512_DRNG), S390X_CAPBIT(S390X_TRNG) },
+        /*.kma    = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_AES_128) | S390X_CAPBIT(S390X_AES_192) | S390X_CAPBIT(S390X_AES_256), 0ULL },
+        /*.pcc    = */ { S390X_CAPBIT(S390X_QUERY), S390X_CAPBIT(S390X_SCALAR_MULTIPLY_P256) | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_P384) | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_P521) | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_ED25519) | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_ED448) | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_X25519) | S390X_CAPBIT(S390X_SCALAR_MULTIPLY_X448) },
+        /*.kdsa   = */ { S390X_CAPBIT(S390X_QUERY) | S390X_CAPBIT(S390X_ECDSA_VERIFY_P256) | S390X_CAPBIT(S390X_ECDSA_VERIFY_P384) | S390X_CAPBIT(S390X_ECDSA_VERIFY_P521) | S390X_CAPBIT(S390X_ECDSA_SIGN_P256) | S390X_CAPBIT(S390X_ECDSA_SIGN_P384) | S390X_CAPBIT(S390X_ECDSA_SIGN_P521) | S390X_CAPBIT(S390X_EDDSA_VERIFY_ED25519) | S390X_CAPBIT(S390X_EDDSA_VERIFY_ED448) | S390X_CAPBIT(S390X_EDDSA_SIGN_ED25519) | S390X_CAPBIT(S390X_EDDSA_SIGN_ED448), 0ULL },
     };
 
-    /* clang-format on */
-
     char *tok_begin, *tok_end, *buff, tok[S390X_STFLE_MAX][LEN + 1];
     int rc, off, i, n;
 
@@ -845,7 +504,6 @@ static int parse_env(struct OPENSSL_s390xcap_st *cap, int *cex)
     tok_end = strtok(NULL, ";");
 
     while (tok_begin != NULL) {
-        /* clang-format off */
         /* stfle token */
         if ((n = sscanf(tok_begin,
                  " stfle : %" STR(LEN) "[^:] : "
@@ -861,38 +519,20 @@ static int parse_env(struct OPENSSL_s390xcap_st *cap, int *cex)
         }
 
         /* query function tokens */
-        else if TOK_FUNC(kimd)
-        else if TOK_FUNC(klmd)
-        else if TOK_FUNC(km)
-        else if TOK_FUNC(kmc)
-        else if TOK_FUNC(kmac)
-        else if TOK_FUNC(kmctr)
-        else if TOK_FUNC(kmo)
-        else if TOK_FUNC(kmf)
-        else if TOK_FUNC(prno)
-        else if TOK_FUNC(kma)
-        else if TOK_FUNC(pcc)
-        else if TOK_FUNC(kdsa)
+        else if TOK_FUNC (kimd)
+            else if TOK_FUNC (klmd) else if TOK_FUNC (km) else if TOK_FUNC (kmc) else if TOK_FUNC (kmac) else if TOK_FUNC (kmctr) else if TOK_FUNC (kmo) else if TOK_FUNC (kmf) else if TOK_FUNC (prno) else if TOK_FUNC (kma) else if TOK_FUNC (pcc) else if TOK_FUNC (kdsa)
 
-        /* CPU model tokens */
-        else if TOK_CPU(z900)
-        else if TOK_CPU(z990)
-        else if TOK_CPU(z9)
-        else if TOK_CPU(z10)
-        else if TOK_CPU(z196)
-        else if TOK_CPU(zEC12)
-        else if TOK_CPU(z13)
-        else if TOK_CPU(z14)
-        else if TOK_CPU(z15)
-        else if TOK_CPU_ALIAS(z16, z15)
-        else if TOK_CPU(z17)
+                /* CPU model tokens */
+                else if TOK_CPU (z900) else if TOK_CPU (z990) else if TOK_CPU (z9) else if TOK_CPU (z10) else if TOK_CPU (z196) else if TOK_CPU (zEC12) else if TOK_CPU (z13) else if TOK_CPU (z14) else if TOK_CPU (z15) else if TOK_CPU_ALIAS (z16, z15) else if TOK_CPU (z17)
 
-        /* nocex to deactivate cex support */
-        else if (sscanf(tok_begin, " %" STR(LEN) "s %" STR(LEN) "s ",
-                     tok[0], tok[1]) == 1
-            && !strcmp(tok[0], "nocex")) {
-            *cex = 0;
-        }
+                /* nocex to deactivate cex support */
+                else if (sscanf(tok_begin, " %" STR(LEN) "s %" STR(LEN) "s ",
+                             tok[0], tok[1])
+                        == 1
+                    && !strcmp(tok[0], "nocex"))
+            {
+                *cex = 0;
+            }
 
         /* whitespace(ignored) or invalid tokens */
         else {
@@ -902,7 +542,6 @@ static int parse_env(struct OPENSSL_s390xcap_st *cap, int *cex)
                 tok_begin++;
             }
         }
-        /* clang-format on */
 
         tok_begin = tok_end;
         tok_end = strtok(NULL, ";");
diff --git a/crypto/s390xcpuid.pl b/crypto/s390xcpuid.pl
index dce17a3bfa..36457d798a 100755
--- a/crypto/s390xcpuid.pl
+++ b/crypto/s390xcpuid.pl
@@ -26,7 +26,7 @@ $sp="%r15";
 $stdframe=16*$SIZE_T+4*8;
 
 $code=<<___;
-#include "arch/s390x_arch.h"
+#include "s390x_arch.h"
 
 .text
 
@@ -527,11 +527,6 @@ s390x_flip_endian64:
 ___
 }
 
-$code.=<<___;
-.section	.init
-	brasl	$ra,OPENSSL_cpuid_setup
-___
-
 $code =~ s/\`([^\`]*)\`/eval $1/gem;
 print $code;
 close STDOUT or die "error closing STDOUT: $!";	# force flush
diff --git a/crypto/sha/asm/keccak1600-armv4.pl b/crypto/sha/asm/keccak1600-armv4.pl
index 896ce6ec5b..4e81bb805b 100755
--- a/crypto/sha/asm/keccak1600-armv4.pl
+++ b/crypto/sha/asm/keccak1600-armv4.pl
@@ -113,7 +113,7 @@ my @D = map(8*$_, (25..29));
 my @T = map([ 8*$_, 8*($_+1), 8*($_+2), 8*($_+3), 8*($_+4) ], (30,35,40,45,50));
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 #if defined(__thumb2__)
 .syntax	unified
diff --git a/crypto/sha/asm/keccak1600-armv8.pl b/crypto/sha/asm/keccak1600-armv8.pl
index 48247dcd27..61096079d3 100755
--- a/crypto/sha/asm/keccak1600-armv8.pl
+++ b/crypto/sha/asm/keccak1600-armv8.pl
@@ -80,7 +80,7 @@ my @rhotates = ([  0,  1, 62, 28, 27 ],
                 [ 18,  2, 61, 56, 14 ]);
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 .rodata
 
diff --git a/crypto/sha/asm/keccak1600-avx512.pl b/crypto/sha/asm/keccak1600-avx512.pl
index 1b40130a6e..2a295d1c85 100755
--- a/crypto/sha/asm/keccak1600-avx512.pl
+++ b/crypto/sha/asm/keccak1600-avx512.pl
@@ -22,7 +22,7 @@
 # It's impossible to have one that is optimal for every step, hence
 # it's changing as algorithm progresses. Data is saved in linear order,
 # but in-register order morphs between rounds. Even rounds take in
-# linear layout, and odd rounds - transposed, or "vertically-shaped"...
+# linear layout, and odd rounds - transposed, or "verticaly-shaped"...
 #
 ########################################################################
 # Numbers are cycles per processed byte out of large message.
diff --git a/crypto/sha/asm/keccak1600-s390x.pl b/crypto/sha/asm/keccak1600-s390x.pl
index 696dcbb863..5bd5f04cda 100755
--- a/crypto/sha/asm/keccak1600-s390x.pl
+++ b/crypto/sha/asm/keccak1600-s390x.pl
@@ -67,7 +67,6 @@ my @rhotates = ([  0,  1, 62, 28, 27 ],
 
 $code.=<<___;
 .text
-.machine	"z10"
 
 .type	__KeccakF1600,\@function
 .align	32
diff --git a/crypto/sha/asm/keccak1600x4-avx512vl.pl b/crypto/sha/asm/keccak1600x4-avx512vl.pl
deleted file mode 100755
index a7fc1814f5..0000000000
--- a/crypto/sha/asm/keccak1600x4-avx512vl.pl
+++ /dev/null
@@ -1,2349 +0,0 @@
-#!/usr/bin/env perl
-#
-# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved.
-# Copyright (c) 2026 Intel Corporation. All Rights Reserved.
-#
-# Licensed under the Apache License 2.0 (the "License").  You may not use
-# this file except in compliance with the License.  You can obtain a copy
-# in the file LICENSE in the source distribution or at
-# https://www.openssl.org/source/license.html
-
-###############################################################################
-# Keccak x4 AVX512VL SHA3/SHAKE Assembly Routines
-#
-# Description:
-#   This file emits x86_64 assembly for AVX512VL accelerated Keccak-f[1600]
-#   processing of 4 independent states in parallel ("x4").
-#
-#   It provides the core 24-round Keccak permutation and x4 helper routines
-#   used by SHA3 and SHAKE absorb/finalize/squeeze paths. Data from four
-#   input/output lanes is packed across YMM registers so lane-local operations
-#   execute in SIMD.
-#
-###############################################################################
-
-# $output is the last argument if it looks like a file (it has an extension)
-# $flavour is the first argument if it doesn't look like a file
-$output = $#ARGV >= 0 && $ARGV[$#ARGV] =~ m|\.\w+$| ? pop : undef;
-$flavour = $#ARGV >= 0 && $ARGV[0] !~ m|\.| ? shift : undef;
-
-$win64=0; $win64=1 if ($flavour =~ /[nm]asm|mingw64/ || $output =~ /\.asm$/);
-
-$avx512vl = 0;
-
-$0 =~ m/(.*[\/\\])[^\/\\]+$/; $dir=$1;
-( $xlate="${dir}x86_64-xlate.pl" and -f $xlate ) or
-( $xlate="${dir}../../perlasm/x86_64-xlate.pl" and -f $xlate) or
-die "can't locate x86_64-xlate.pl";
-
-# Check for AVX512VL support in assembler
-if (`$ENV{CC} -Wa,-v -c -o /dev/null -x assembler /dev/null 2>&1` =~ /GNU assembler version (\d+)\.(\d+)/) {
-  my ($gas_major, $gas_minor) = ($1, $2);
-  $avx512vl = ($gas_major > 2 || ($gas_major == 2 && $gas_minor >= 26));
-}
-
-if (!$avx512vl
-  && $win64
-  && ($flavour =~ /nasm/ || $ENV{ASM} =~ /nasm/)
-  && `nasm -v 2>&1` =~ /NASM version ([2-9]\.[0-9]+)(?:\.([0-9]+))?/)
-{
-  $avx512vl = ($1 >= 2.12);
-}
-
-if (!$avx512vl && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([0-9]+\.[0-9]+)/) {
-    $avx512vl = ($2>=3.9);
-}
-
-open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\""
-    or die "can't call $xlate: $!";
-*STDOUT=*OUT;
-
-$arg1="%rdi";
-$arg2="%rsi";
-$arg3="%rdx";
-$arg4="%rcx";
-$arg5="%r8";
-$arg6="%r9";
-$roundn="%r13d";
-$tblptr="%r14";
-
-# Define SHAKE rates
-$SHAKE128_RATE="\$168";
-$SHAKE256_RATE="\$136";
-
-# Stack frame offsets for SHAKE x4 wrapper functions
-$STATE_SIZE="808";    # (25 * 8 * 4) + 8 = 808 bytes
-$sf_arg1="0";
-$sf_arg2="8";
-$sf_arg3="16";
-$sf_arg4="24";
-$sf_arg5="32";
-$sf_state_ptr="40";
-$sf_state_x4="48";
-$sf_size="856";       # 48 + 808 = 856 bytes
-
-# Emit an internal helper call used by one-shot wrappers.
-# - Win64: call the provided *_internal shim and bracket it with 32-byte
-#   shadow space so shim entry can use xlate-compatible [rsp+8]/[rsp+16].
-# - non-Win64: call the local function entry label (.L_), which
-#   sits at the same address as the public symbol.  Calling the public
-#   global symbol by name here would break Mach-O builds: the call textually
-#   precedes the symbol's .globl declaration, so x86_64-xlate.pl never gets
-#   a chance to prepend the platform's leading-underscore, leaving an
-#   undefined reference to the un-decorated name.
-# The argument must be the shim/internal symbol name, e.g.
-#   SHA3_shake128_x4_inc_squeeze_avx512vl_internal
-sub call_internal {
-    my ($shim_name) = @_;
-    my $external_name = $shim_name;
-
-    $external_name =~ s/_internal$//;
-
-    return <<___ if ($win64);
-    sub     \$32, %rsp
-    call    $shim_name
-    add     \$32, %rsp
-___
-
-    return <<___;
-    call    .L_$external_name
-___
-}
-
-if ($avx512vl>0) {{{
-
-my $avx512_mask = (1<<31)|(1<<30)|(1<<17)|(1<<16);  # AVX512VL|BW|DQ|F
-
-$code .= <<___;
-.text
-
-.extern OPENSSL_ia32cap_P
-
-.globl  SHA3_avx512vl_capable
-.type   SHA3_avx512vl_capable,\@abi-omnipotent
-.align 32
-SHA3_avx512vl_capable:
-    mov     OPENSSL_ia32cap_P+8(%rip), %ecx
-    xor     %eax, %eax
-    # 1<<31|1<<30|1<<17|1<<16: AVX512VL|AVX512BW|AVX512DQ|AVX512F
-    and     \$$avx512_mask, %ecx
-    cmp     \$$avx512_mask, %ecx
-    cmove   %ecx, %eax
-    ret
-.size   SHA3_avx512vl_capable, .-SHA3_avx512vl_capable
-___
-
-$code.=<<___;
-.text
-
-# Perform Keccak permutation
-#
-# YMM registers 0 to 24 are used as Keccak state registers.
-# This function, as is, can work on 1 to 4 independent states at the same time.
-#
-# There is no clear boundary between Theta, Rho, Pi, Chi and Iota steps.
-# Instructions corresponding to these steps overlap for better efficiency.
-#
-# Arguments:
-# ymm0-ymm24    [in/out]    Keccak state registers (one SIMD per one state register)
-# ymm25-ymm31   [clobbered] temporary SIMD registers
-# $roundn       [clobbered] used for round tracking
-# $tblptr       [clobbered] used for access to SHA3 constant table
-.type keccak_1600_permute,\@abi-omnipotent
-.align  32
-keccak_1600_permute:
-.cfi_startproc
-    mov     \$24, $roundn        # 24 rounds
-    lea     iotas(%rip), $tblptr # Load the address of the SHA3 round constants
-
-.align  32
-.Lkeccak_rnd_loop:
-    # Theta step
-
-    # Compute column parities
-    # C[5] = [0, 0, 0, 0, 0]
-    # for x in 0 to 4:
-    #     C[x] = state[x][0] XOR state[x][1] XOR state[x][2] XOR state[x][3] XOR state[x][4]
-
-    vmovdqa64   %ymm0, %ymm25
-    vpternlogq  \$0x96, %ymm5, %ymm10, %ymm25
-    vmovdqa64   %ymm1, %ymm26
-    vpternlogq  \$0x96, %ymm11, %ymm6, %ymm26
-    vmovdqa64   %ymm2, %ymm27
-    vpternlogq  \$0x96, %ymm12, %ymm7, %ymm27
-
-    vmovdqa64   %ymm3, %ymm28
-    vpternlogq  \$0x96, %ymm13, %ymm8, %ymm28
-    vmovdqa64   %ymm4, %ymm29
-    vpternlogq  \$0x96, %ymm14, %ymm9, %ymm29
-    vpternlogq  \$0x96, %ymm20, %ymm15, %ymm25
-
-    vpternlogq  \$0x96, %ymm21, %ymm16, %ymm26
-    vpternlogq  \$0x96, %ymm22, %ymm17, %ymm27
-    vpternlogq  \$0x96, %ymm23, %ymm18, %ymm28
-
-    # Start computing D values and keep computing column parity
-    # D[5] = [0, 0, 0, 0, 0]
-    # for x in 0 to 4:
-    #     D[x] = C[(x+4) mod 5] XOR ROTATE_LEFT(C[(x+1) mod 5], 1)
-
-    vprolq      \$1, %ymm26, %ymm30
-    vprolq      \$1, %ymm27, %ymm31
-    vpternlogq  \$0x96, %ymm24, %ymm19, %ymm29
-
-    # Continue computing D values and apply Theta
-    # for x in 0 to 4:
-    #     for y in 0 to 4:
-    #         state[x][y] = state[x][y] XOR D[x]
-
-    vpternlogq  \$0x96, %ymm30, %ymm29, %ymm0
-    vpternlogq  \$0x96, %ymm30, %ymm29, %ymm10
-    vpternlogq  \$0x96, %ymm30, %ymm29, %ymm20
-
-    vpternlogq  \$0x96, %ymm30, %ymm29, %ymm5
-    vpternlogq  \$0x96, %ymm30, %ymm29, %ymm15
-    vprolq      \$1, %ymm28, %ymm30
-
-    vpternlogq  \$0x96, %ymm31, %ymm25, %ymm6
-    vpternlogq  \$0x96, %ymm31, %ymm25, %ymm16
-    vpternlogq  \$0x96, %ymm31, %ymm25, %ymm1
-
-    vpternlogq  \$0x96, %ymm31, %ymm25, %ymm11
-    vpternlogq  \$0x96, %ymm31, %ymm25, %ymm21
-    vprolq      \$1, %ymm29, %ymm31
-
-    vpbroadcastq    ($tblptr), %ymm29 # Load the round constant into ymm29 (Iota)
-    add         \$8, $tblptr          # Increment the pointer to the next round constant
-
-    vpternlogq  \$0x96, %ymm30, %ymm26, %ymm12
-    vpternlogq  \$0x96, %ymm30, %ymm26, %ymm7
-    vpternlogq  \$0x96, %ymm30, %ymm26, %ymm22
-
-    vpternlogq  \$0x96, %ymm30, %ymm26, %ymm17
-    vpternlogq  \$0x96, %ymm30, %ymm26, %ymm2
-    vprolq      \$1, %ymm25, %ymm30
-
-    # Rho step
-    # Keep applying Theta and start Rho step
-    #
-    # ROTATION_OFFSETS[5][5] = [
-    #     [0, 1, 62, 28, 27],
-    #     [36, 44, 6, 55, 20],
-    #     [3, 10, 43, 25, 39],
-    #     [41, 45, 15, 21, 8],
-    #     [18, 2, 61, 56, 14] ]
-    #
-    # for x in 0 to 4:
-    #     for y in 0 to 4:
-    #         state[x][y] = ROTATE_LEFT(state[x][y], ROTATION_OFFSETS[x][y])
-
-    vpternlogq  \$0x96, %ymm31, %ymm27, %ymm3
-    vpternlogq  \$0x96, %ymm31, %ymm27, %ymm13
-    vpternlogq  \$0x96, %ymm31, %ymm27, %ymm23
-
-    vprolq      \$44, %ymm6, %ymm6
-    vpternlogq  \$0x96, %ymm31, %ymm27, %ymm18
-    vpternlogq  \$0x96, %ymm31, %ymm27, %ymm8
-
-    vprolq      \$43, %ymm12, %ymm12
-    vprolq      \$21, %ymm18, %ymm18
-    vpternlogq  \$0x96, %ymm30, %ymm28, %ymm24
-
-    vprolq      \$14, %ymm24, %ymm24
-    vprolq      \$28, %ymm3, %ymm3
-    vpternlogq  \$0x96, %ymm30, %ymm28, %ymm9
-
-    vprolq      \$20, %ymm9, %ymm9
-    vprolq      \$3, %ymm10, %ymm10
-    vpternlogq  \$0x96, %ymm30, %ymm28, %ymm19
-
-    vprolq      \$45, %ymm16, %ymm16
-    vprolq      \$61, %ymm22, %ymm22
-    vpternlogq  \$0x96, %ymm30, %ymm28, %ymm4
-
-    vprolq      \$1, %ymm1, %ymm1
-    vprolq      \$6, %ymm7, %ymm7
-    vpternlogq  \$0x96, %ymm30, %ymm28, %ymm14
-
-    # Continue with Rho and start Pi and Chi steps at the same time
-    # Ternary logic 0xD2 is used for Chi step
-    #
-    # for x in 0 to 4:
-    #     for y in 0 to 4:
-    #         state[x][y] = state[x][y] XOR ((NOT state[(x+1) mod 5][y]) AND state[(x+2) mod 5][y])
-
-    vprolq      \$25, %ymm13, %ymm13
-    vprolq      \$8, %ymm19, %ymm19
-    vmovdqa64   %ymm0, %ymm30
-    vpternlogq  \$0xD2, %ymm12, %ymm6, %ymm30
-
-    vprolq      \$18, %ymm20, %ymm20
-    vprolq      \$27, %ymm4, %ymm4
-    vpxorq      %ymm29, %ymm30, %ymm30 # Iota step
-
-    vprolq      \$36, %ymm5, %ymm5
-    vprolq      \$10, %ymm11, %ymm11
-    vmovdqa64   %ymm6, %ymm31
-    vpternlogq  \$0xD2, %ymm18, %ymm12, %ymm31
-
-    vprolq      \$15, %ymm17, %ymm17
-    vprolq      \$56, %ymm23, %ymm23
-    vpternlogq  \$0xD2, %ymm24, %ymm18, %ymm12
-
-    vprolq      \$62, %ymm2, %ymm2
-    vprolq      \$55, %ymm8, %ymm8
-    vpternlogq  \$0xD2, %ymm0, %ymm24, %ymm18
-
-    vprolq      \$39, %ymm14, %ymm14
-    vprolq      \$41, %ymm15, %ymm15
-    vpternlogq  \$0xD2, %ymm6, %ymm0, %ymm24
-    vmovdqa64   %ymm30, %ymm0
-    vmovdqa64   %ymm31, %ymm6
-
-    vprolq      \$2, %ymm21, %ymm21
-    vmovdqa64   %ymm3, %ymm30
-    vpternlogq  \$0xD2, %ymm10, %ymm9, %ymm30
-    vmovdqa64   %ymm9, %ymm31
-    vpternlogq  \$0xD2, %ymm16, %ymm10, %ymm31
-
-    vpternlogq  \$0xD2, %ymm22, %ymm16, %ymm10
-    vpternlogq  \$0xD2, %ymm3, %ymm22, %ymm16
-    vpternlogq  \$0xD2, %ymm9, %ymm3, %ymm22
-    vmovdqa64   %ymm30, %ymm3
-    vmovdqa64   %ymm31, %ymm9
-
-    vmovdqa64   %ymm1, %ymm30
-    vpternlogq  \$0xD2, %ymm13, %ymm7, %ymm30
-    vmovdqa64   %ymm7, %ymm31
-    vpternlogq  \$0xD2, %ymm19, %ymm13, %ymm31
-    vpternlogq  \$0xD2, %ymm20, %ymm19, %ymm13
-
-    vpternlogq  \$0xD2, %ymm1, %ymm20, %ymm19
-    vpternlogq  \$0xD2, %ymm7, %ymm1, %ymm20
-    vmovdqa64   %ymm30, %ymm1
-    vmovdqa64   %ymm31, %ymm7
-    vmovdqa64   %ymm4, %ymm30
-    vpternlogq  \$0xD2, %ymm11, %ymm5, %ymm30
-
-    vmovdqa64   %ymm5, %ymm31
-    vpternlogq  \$0xD2, %ymm17, %ymm11, %ymm31
-    vpternlogq  \$0xD2, %ymm23, %ymm17, %ymm11
-    vpternlogq  \$0xD2, %ymm4, %ymm23, %ymm17
-
-    vpternlogq  \$0xD2, %ymm5, %ymm4, %ymm23
-    vmovdqa64   %ymm30, %ymm4
-    vmovdqa64   %ymm31, %ymm5
-    vmovdqa64   %ymm2, %ymm30
-    vpternlogq  \$0xD2, %ymm14, %ymm8, %ymm30
-    vmovdqa64   %ymm8, %ymm31
-    vpternlogq  \$0xD2, %ymm15, %ymm14, %ymm31
-
-    vpternlogq  \$0xD2, %ymm21, %ymm15, %ymm14
-    vpternlogq  \$0xD2, %ymm2, %ymm21, %ymm15
-    vpternlogq  \$0xD2, %ymm8, %ymm2, %ymm21
-    vmovdqa64   %ymm30, %ymm2
-    vmovdqa64   %ymm31, %ymm8
-
-    # Complete the steps and get updated state registers in ymm0 to ymm24
-    vmovdqa64   %ymm3,  %ymm30
-    vmovdqa64   %ymm18, %ymm3
-    vmovdqa64   %ymm17, %ymm18
-    vmovdqa64   %ymm11, %ymm17
-    vmovdqa64   %ymm7,  %ymm11
-    vmovdqa64   %ymm10, %ymm7
-    vmovdqa64   %ymm1,  %ymm10
-    vmovdqa64   %ymm6,  %ymm1
-    vmovdqa64   %ymm9,  %ymm6
-    vmovdqa64   %ymm22, %ymm9
-    vmovdqa64   %ymm14, %ymm22
-    vmovdqa64   %ymm20, %ymm14
-    vmovdqa64   %ymm2,  %ymm20
-    vmovdqa64   %ymm12, %ymm2
-    vmovdqa64   %ymm13, %ymm12
-    vmovdqa64   %ymm19, %ymm13
-    vmovdqa64   %ymm23, %ymm19
-    vmovdqa64   %ymm15, %ymm23
-    vmovdqa64   %ymm4,  %ymm15
-    vmovdqa64   %ymm24, %ymm4
-    vmovdqa64   %ymm21, %ymm24
-    vmovdqa64   %ymm8,  %ymm21
-    vmovdqa64   %ymm16, %ymm8
-    vmovdqa64   %ymm5,  %ymm16
-    vmovdqa64   %ymm30, %ymm5
-
-    dec         $roundn           # Decrement the round counter
-    jnz         .Lkeccak_rnd_loop # Jump to the start of the loop if r13d is not zero
-    ret
-.cfi_endproc
-.size   keccak_1600_permute,.-keccak_1600_permute
-
-# Initialize YMM registers 0-24 to zero
-.globl  keccak_1600_init_state
-.type   keccak_1600_init_state,\@abi-omnipotent
-.align  32
-keccak_1600_init_state:
-.cfi_startproc
-    vpxorq      %ymm0, %ymm0, %ymm0
-    vmovdqa64   %ymm0, %ymm1
-    vmovdqa64   %ymm0, %ymm2
-    vmovdqa64   %ymm0, %ymm3
-    vmovdqa64   %ymm0, %ymm4
-    vmovdqa64   %ymm0, %ymm5
-    vmovdqa64   %ymm0, %ymm6
-    vmovdqa64   %ymm0, %ymm7
-    vmovdqa64   %ymm0, %ymm8
-    vmovdqa64   %ymm0, %ymm9
-    vmovdqa64   %ymm0, %ymm10
-    vmovdqa64   %ymm0, %ymm11
-    vmovdqa64   %ymm0, %ymm12
-    vmovdqa64   %ymm0, %ymm13
-    vmovdqa64   %ymm0, %ymm14
-    vmovdqa64   %ymm0, %ymm15
-    vmovdqa64   %ymm0, %ymm16
-    vmovdqa64   %ymm0, %ymm17
-    vmovdqa64   %ymm0, %ymm18
-    vmovdqa64   %ymm0, %ymm19
-    vmovdqa64   %ymm0, %ymm20
-    vmovdqa64   %ymm0, %ymm21
-    vmovdqa64   %ymm0, %ymm22
-    vmovdqa64   %ymm0, %ymm23
-    vmovdqa64   %ymm0, %ymm24
-    ret
-.cfi_endproc
-.size   keccak_1600_init_state,.-keccak_1600_init_state
-
-.globl  keccak_1600_load_state_x4
-.type   keccak_1600_load_state_x4,\@abi-omnipotent
-.align  32
-keccak_1600_load_state_x4:
-.cfi_startproc
-    vmovdqu64   32*0($arg1),  %ymm0
-    vmovdqu64   32*1($arg1),  %ymm1
-    vmovdqu64   32*2($arg1),  %ymm2
-    vmovdqu64   32*3($arg1),  %ymm3
-    vmovdqu64   32*4($arg1),  %ymm4
-    vmovdqu64   32*5($arg1),  %ymm5
-    vmovdqu64   32*6($arg1),  %ymm6
-    vmovdqu64   32*7($arg1),  %ymm7
-    vmovdqu64   32*8($arg1),  %ymm8
-    vmovdqu64   32*9($arg1),  %ymm9
-    vmovdqu64   32*10($arg1), %ymm10
-    vmovdqu64   32*11($arg1), %ymm11
-    vmovdqu64   32*12($arg1), %ymm12
-    vmovdqu64   32*13($arg1), %ymm13
-    vmovdqu64   32*14($arg1), %ymm14
-    vmovdqu64   32*15($arg1), %ymm15
-    vmovdqu64   32*16($arg1), %ymm16
-    vmovdqu64   32*17($arg1), %ymm17
-    vmovdqu64   32*18($arg1), %ymm18
-    vmovdqu64   32*19($arg1), %ymm19
-    vmovdqu64   32*20($arg1), %ymm20
-    vmovdqu64   32*21($arg1), %ymm21
-    vmovdqu64   32*22($arg1), %ymm22
-    vmovdqu64   32*23($arg1), %ymm23
-    vmovdqu64   32*24($arg1), %ymm24
-    ret
-.cfi_endproc
-.size   keccak_1600_load_state_x4,.-keccak_1600_load_state_x4
-
-
-.globl  keccak_1600_save_state_x4
-.type   keccak_1600_save_state_x4,\@abi-omnipotent
-.align  32
-keccak_1600_save_state_x4:
-.cfi_startproc
-    vmovdqu64   %ymm0,  32*0($arg1)
-    vmovdqu64   %ymm1,  32*1($arg1)
-    vmovdqu64   %ymm2,  32*2($arg1)
-    vmovdqu64   %ymm3,  32*3($arg1)
-    vmovdqu64   %ymm4,  32*4($arg1)
-    vmovdqu64   %ymm5,  32*5($arg1)
-    vmovdqu64   %ymm6,  32*6($arg1)
-    vmovdqu64   %ymm7,  32*7($arg1)
-    vmovdqu64   %ymm8,  32*8($arg1)
-    vmovdqu64   %ymm9,  32*9($arg1)
-    vmovdqu64   %ymm10, 32*10($arg1)
-    vmovdqu64   %ymm11, 32*11($arg1)
-    vmovdqu64   %ymm12, 32*12($arg1)
-    vmovdqu64   %ymm13, 32*13($arg1)
-    vmovdqu64   %ymm14, 32*14($arg1)
-    vmovdqu64   %ymm15, 32*15($arg1)
-    vmovdqu64   %ymm16, 32*16($arg1)
-    vmovdqu64   %ymm17, 32*17($arg1)
-    vmovdqu64   %ymm18, 32*18($arg1)
-    vmovdqu64   %ymm19, 32*19($arg1)
-    vmovdqu64   %ymm20, 32*20($arg1)
-    vmovdqu64   %ymm21, 32*21($arg1)
-    vmovdqu64   %ymm22, 32*22($arg1)
-    vmovdqu64   %ymm23, 32*23($arg1)
-    vmovdqu64   %ymm24, 32*24($arg1)
-    ret
-.cfi_endproc
-.size   keccak_1600_save_state_x4,.-keccak_1600_save_state_x4
-
-
-# Add input data to state when message length is less than rate
-# Arguments:
-#   r10:        state pointer to absorb into (clobbered)
-#   arg2 (rsi): message pointer lane 0 (updated on output)
-#   arg3 (rdx): message pointer lane 1 (updated on output)
-#   arg4 (rcx): message pointer lane 2 (updated on output)
-#   arg5 (r8):  message pointer lane 3 (updated on output)
-#   r12:        length in bytes (clobbered on output)
-# Clobbers: r9, rbx, r15, k1, ymm31-ymm29
-.globl  keccak_1600_partial_add_x4
-.type   keccak_1600_partial_add_x4,\@abi-omnipotent
-.align  32
-keccak_1600_partial_add_x4:
-.cfi_startproc
-    mov     8*100(%r10), %r9
-    test    \$7, %r9d
-    jz      .Lstart_aligned_to_4x8
-
-    # Start offset is not aligned to register size
-    mov     %r9, %r15 # %r15 = s[100]
-
-    and     \$7, %r9d
-    neg     %r9d
-    add     \$8, %r9d     # register capacity = 8 - (offset % 8)
-    cmp     %r9d, %r12d
-    cmovnae   %r12d, %r9d # %r9d = min(register capacity, length)
-
-    lea     byte_kmask_0_to_7(%rip), %rbx
-    kmovb   (%rbx,%r9), %k1 # message load mask
-
-    mov     %r15, %rbx
-    and     \$~7, %ebx
-    lea     (%r10,%rbx,4), %r10 # get to state starting register
-
-    mov     %r15, %rbx
-    and     \$7, %ebx
-
-    vmovdqu8    (%r10), %ymm31 # load & store / allocate SB for the register
-    vmovdqu8    %ymm31, (%r10)
-
-    vmovdqu8    ($arg2), %xmm31{%k1}{z}        # Read 1 to 7 bytes from lane 0
-    vmovdqu8    8*0(%r10,%rbx), %xmm30{%k1}{z} # Read 1 to 7 bytes from state reg lane 0
-    vpxorq      %xmm30, %xmm31, %xmm31
-    vmovdqu8    %xmm31, 8*0(%r10,%rbx){%k1}    # Write 1 to 7 bytes to state reg lane 0
-
-    vmovdqu8    ($arg3), %xmm31{%k1}{z}        # Read 1 to 7 bytes from lane 1
-    vmovdqu8    8*1(%r10,%rbx), %xmm30{%k1}{z} # Read 1 to 7 bytes from state reg lane 1
-    vpxorq      %xmm30, %xmm31, %xmm31
-    vmovdqu8    %xmm31, 8*1(%r10,%rbx){%k1}    # Write 1 to 7 bytes to state reg lane 1
-
-    vmovdqu8    ($arg4), %xmm31{%k1}{z}        # Read 1 to 7 bytes from lane 2
-    vmovdqu8    8*2(%r10,%rbx), %xmm30{%k1}{z} # Read 1 to 7 bytes from state reg lane 2
-    vpxorq      %xmm30, %xmm31, %xmm31
-    vmovdqu8    %xmm31, 8*2(%r10,%rbx){%k1}    # Write 1 to 7 bytes to state reg lane 2
-
-    vmovdqu8    ($arg5), %xmm31{%k1}{z}        # Read 1 to 7 bytes from lane 3
-    vmovdqu8    8*3(%r10,%rbx), %xmm30{%k1}{z} # Read 1 to 7 bytes from state reg lane 3
-    vpxorq      %xmm30, %xmm31, %xmm31
-    vmovdqu8    %xmm31, 8*3(%r10,%rbx){%k1}    # Write 1 to 7 bytes to state reg lane 3
-
-    sub     %r9, %r12
-    jz      .Lzero_bytes
-
-    add     %r9, $arg2
-    add     %r9, $arg3
-    add     %r9, $arg4
-    add     %r9, $arg5
-    add     \$32, %r10
-    xor     %r9, %r9
-    jmp     .Lymm_loop
-
-.Lstart_aligned_to_4x8:
-    lea     (%r10,%r9,4), %r10
-    xor     %r9, %r9
-
-.align  32
-.Lymm_loop:
-    cmp     \$8, %r12d
-    jb      .Llt_8_bytes
-
-    vmovq       ($arg2,%r9), %xmm31              # Read 8 bytes from lane 0
-    vpinsrq     \$1, ($arg3,%r9), %xmm31, %xmm31 # Read 8 bytes from lane 1
-    vmovq       ($arg4,%r9), %xmm30              # Read 8 bytes from lane 2
-    vpinsrq     \$1, ($arg5,%r9),%xmm30, %xmm30  # Read 8 bytes from lane 3
-    vinserti32x4 \$1, %xmm30, %ymm31, %ymm31
-    vpxorq      (%r10,%r9,4), %ymm31, %ymm31     # Add data with the state
-    vmovdqu64   %ymm31, (%r10,%r9,4)
-    add     \$8, %r9
-    sub     \$8, %r12
-    jz      .Lzero_bytes
-
-    jmp     .Lymm_loop
-
-.align  32
-.Lzero_bytes:
-    add     %r9, $arg2
-    add     %r9, $arg3
-    add     %r9, $arg4
-    add     %r9, $arg5
-    ret
-
-.align  32
-.Llt_8_bytes:
-    add     %r9, $arg2
-    add     %r9, $arg3
-    add     %r9, $arg4
-    add     %r9, $arg5
-    lea     (%r10,%r9,4), %r10
-
-    lea     byte_kmask_0_to_7(%rip), %rbx
-    kmovb   (%rbx,%r12), %k1 # message load mask
-
-    vmovdqu8    ($arg2), %xmm31{%k1}{z} # Read 1 to 7 bytes from lane 0
-    vmovdqu8    ($arg3), %xmm30{%k1}{z} # Read 1 to 7 bytes from lane 1
-    vpunpcklqdq %xmm30, %xmm31, %xmm31  # Interleave data from lane 0 and lane 1
-    vmovdqu8    ($arg4), %xmm30{%k1}{z} # Read 1 to 7 bytes from lane 2
-    vmovdqu8    ($arg5), %xmm29{%k1}{z} # Read 1 to 7 bytes from lane 3
-    vpunpcklqdq %xmm29, %xmm30, %xmm30  # Interleave data from lane 2 and lane 3
-    vinserti32x4 \$1, %xmm30, %ymm31, %ymm31
-
-    vpxorq      (%r10), %ymm31, %ymm31 # Add data to the state
-    vmovdqu64   %ymm31, (%r10)         # Update state in memory
-
-    add     %r12, $arg2 # increment message pointer lane 0
-    add     %r12, $arg3 # increment message pointer lane 1
-    add     %r12, $arg4 # increment message pointer lane 2
-    add     %r12, $arg5 # increment message pointer lane 3
-    ret
-.cfi_endproc
-.size   keccak_1600_partial_add_x4,.-keccak_1600_partial_add_x4
-
-
-# Extract bytes from state and write to outputs
-# Arguments:
-#   r10:        state pointer to start extracting from (clobbered)
-#   arg1 (rdi): output pointer lane 0 (updated on output)
-#   arg2 (rsi): output pointer lane 1 (updated on output)
-#   arg3 (rdx): output pointer lane 2 (updated on output)
-#   arg4 (rcx): output pointer lane 3 (updated on output)
-#   r12:        length in bytes (clobbered on output)
-#   r11:        state offset to start extract from
-.globl  keccak_1600_extract_bytes_x4
-.type   keccak_1600_extract_bytes_x4,\@abi-omnipotent
-.align  32
-keccak_1600_extract_bytes_x4:
-.cfi_startproc
-    or      %r12, %r12
-    jz      .Lextract_zero_bytes
-
-    test    \$7, %r11d
-    jz      .Lextract_start_aligned_to_4x8
-
-    # Extract offset is not aligned to the register size (8 bytes)
-    mov     %r11, %r9
-
-    and     \$7, %r9d
-    neg     %r9d
-    add     \$8, %r9d     # register capacity = 8 - (offset % 8)
-    cmp     %r9d, %r12d
-    cmovnae   %r12d, %r9d # %r9d = min(register capacity, length)
-
-    lea     byte_kmask_0_to_7(%rip), %rbx
-    kmovb   (%rbx,%r9), %k1 # message store mask
-
-    mov     %r11, %rbx
-    and     \$~7, %ebx
-    lea     (%r10,%rbx,4), %r10 # get to state starting register
-
-    mov     %r11, %rbx
-    and     \$7, %ebx
-
-    vmovdqu8    8*0(%r10,%rbx), %xmm31{%k1}{z} # Read 1-7 bytes from state reg lane 0
-    vmovdqu8    %xmm31, ($arg1){%k1}           # Write 1-7 bytes to lane 0 output
-
-    vmovdqu8    8*1(%r10,%rbx), %xmm31{%k1}{z} # Read 1-7 bytes from state reg lane 1
-    vmovdqu8    %xmm31, ($arg2){%k1}           # Write 1-7 bytes to lane 1 output
-
-    vmovdqu8    8*2(%r10,%rbx), %xmm31{%k1}{z} # Read 1-7 bytes from state reg lane 2
-    vmovdqu8    %xmm31, ($arg3){%k1}           # Write 1-7 bytes to lane 2 output
-
-    vmovdqu8    8*3(%r10,%rbx), %xmm31{%k1}{z} # Read 1-7 bytes from state reg lane 3
-    vmovdqu8    %xmm31, ($arg4){%k1}           # Write 1-7 bytes to lane 3 output
-
-    # Increment output registers
-    add     %r9, $arg1
-    add     %r9, $arg2
-    add     %r9, $arg3
-    add     %r9, $arg4
-
-    # Decrement length to extract
-    sub     %r9, %r12
-    jz      .Lextract_zero_bytes
-
-    # More data to extract, update state register pointer
-    add     \$32, %r10
-    xor     %r9, %r9
-    jmp     .Lextract_ymm_loop
-
-.Lextract_start_aligned_to_4x8:
-        lea     (%r10,%r11,4), %r10
-        xor     %r9, %r9
-
-.align  32
-.Lextract_ymm_loop:
-    cmp     \$8, %r12
-    jb      .Lextract_lt_8_bytes
-
-    vmovdqu64   (%r10), %xmm31
-    vmovdqu64   16(%r10), %xmm30
-    vmovq       %xmm31, ($arg1,%r9)
-    vpextrq     \$1, %xmm31, ($arg2,%r9)
-    vmovq       %xmm30, ($arg3,%r9)
-    vpextrq     \$1, %xmm30, ($arg4,%r9)
-    add     \$8, %r9
-    sub     \$8, %r12
-    jz      .Lzero_bytes_left
-
-    add     \$32, %r10
-    jmp     .Lextract_ymm_loop
-
-.align  32
-.Lzero_bytes_left:
-    # Increment output pointers
-    add     %r9, $arg1
-    add     %r9, $arg2
-    add     %r9, $arg3
-    add     %r9, $arg4
-.Lextract_zero_bytes:
-    ret
-
-.align  32
-.Lextract_lt_8_bytes:
-    add     %r9, $arg1
-    add     %r9, $arg2
-    add     %r9, $arg3
-    add     %r9, $arg4
-
-    lea     byte_kmask_0_to_7(%rip), %r9
-    kmovb   (%r9,%r12), %k1 # k1 is the mask of message bytes to read
-
-    vmovq       0*8(%r10), %xmm31    # Read 8 bytes from state lane 0
-    vmovdqu8    %xmm31, ($arg1){%k1} # Extract 1-7 bytes into output 0
-    vmovq       1*8(%r10), %xmm31    # Read 8 bytes from state lane 1
-    vmovdqu8    %xmm31, ($arg2){%k1} # Extract 1-7 bytes into output 1
-    vmovq       2*8(%r10), %xmm31    # Read 8 bytes from state lane 2
-    vmovdqu8    %xmm31, ($arg3){%k1} # Extract 1-7 bytes into output 2
-    vmovq       3*8(%r10), %xmm31    # Read 8 bytes from state lane 3
-    vmovdqu8    %xmm31, ($arg4){%k1} # Extract 1-7 bytes into output 3
-
-    # Increment output pointers
-    add     %r12, $arg1
-    add     %r12, $arg2
-    add     %r12, $arg3
-    add     %r12, $arg4
-    ret
-.cfi_endproc
-.size   keccak_1600_extract_bytes_x4,.-keccak_1600_extract_bytes_x4
-
-
-# SHAKE128 x4 multi-buffer functions
-# These functions process 4 independent SHAKE128 streams in parallel using AVX-512VL
-# State layout: 25 ymm registers (200 bytes each) + 1 qword = 808 bytes per context
-# Rate: 168 bytes for SHAKE128
-
-# SHA3_shake128_x4_avx512vl
-# One-shot SHAKE-128 x4 function: init + absorb + finalize + squeeze
-# Arguments:
-#   arg1 (rdi): pointer to output lane 0
-#   arg2 (rsi): pointer to output lane 1
-#   arg3 (rdx): pointer to output lane 2
-#   arg4 (rcx): pointer to output lane 3
-#   arg5 (r8):  output length in bytes (must be same for all lanes)
-#   arg6 (r9):  pointer to input lane 0
-#   [stack+0]:  pointer to input lane 1
-#   [stack+8]:  pointer to input lane 2
-#   [stack+16]: pointer to input lane 3
-#   [stack+24]: input length in bytes (must be same for all lanes)
-# Returns: void
-.globl  SHA3_shake128_x4_avx512vl
-.type   SHA3_shake128_x4_avx512vl,\@function,10
-.align  32
-SHA3_shake128_x4_avx512vl:
-.cfi_startproc
-    push    %rbp
-.cfi_push       %rbp
-    mov     %rsp, %rbp
-    push    %rbx
-.cfi_push       %rbx
-___
-$code .= <<___ if ($win64);
-    sub     \$160, %rsp
-    vmovups %xmm6,   0(%rsp)
-    vmovups %xmm7,   16(%rsp)
-    vmovups %xmm8,   32(%rsp)
-    vmovups %xmm9,   48(%rsp)
-    vmovups %xmm10,  64(%rsp)
-    vmovups %xmm11,  80(%rsp)
-    vmovups %xmm12,  96(%rsp)
-    vmovups %xmm13,  112(%rsp)
-    vmovups %xmm14,  128(%rsp)
-    vmovups %xmm15,  144(%rsp)
-___
-$code.=<<___;
-
-    sub     \$$sf_size, %rsp
-    mov     %rsp, %rbx
-
-.Lshake128_x4_body:
-    mov     $arg1, $sf_arg1(%rbx)
-    mov     $arg2, $sf_arg2(%rbx)
-    mov     $arg3, $sf_arg3(%rbx)
-    mov     $arg4, $sf_arg4(%rbx)
-    mov     $arg5, $sf_arg5(%rbx)
-
-    lea     $sf_state_x4(%rbx), $arg1 # start of x4 state on the stack frame
-    mov     $arg1, $sf_state_ptr(%rbx)
-
-    # Initialize the state array to zero
-    call    keccak_1600_init_state
-
-    call    keccak_1600_save_state_x4
-
-    movq    \$0, 8*100($arg1) # clear s[100]
-
-    mov     $sf_state_ptr(%rbx), $arg1
-    mov     $arg6, $arg2
-___
-$code .= <<___ if ($win64);
-    # xlate prologue handles up to six arguments. For one-shot x4 wrappers
-    # (10 args), the remaining four stay in Win64 stack slots.
-    mov     64(%rbp), $arg3 # arg7 from stack
-    mov     72(%rbp), $arg4 # arg8 from stack
-    mov     80(%rbp), $arg5 # arg9 from stack
-    mov     88(%rbp), $arg6 # arg10 from stack
-___
-$code .= <<___ if (!$win64);
-    mov     16(%rbp), $arg3 # arg7 from stack
-    mov     24(%rbp), $arg4 # arg8 from stack
-    mov     32(%rbp), $arg5 # arg9 from stack
-    mov     40(%rbp), $arg6 # arg10 from stack
-___
-$code.=<<___;
-    # Internal entry avoids Win64 xlate prologue argument remapping.
-___
-$code .= call_internal("SHA3_shake128_x4_inc_absorb_avx512vl_internal");
-$code.=<<___;
-
-    mov     $sf_state_ptr(%rbx), $arg1
-    call    .L_SHA3_shake128_x4_inc_finalize_avx512vl
-
-    # squeeze
-    mov     $sf_arg1(%rbx), $arg1
-    mov     $sf_arg2(%rbx), $arg2
-    mov     $sf_arg3(%rbx), $arg3
-    mov     $sf_arg4(%rbx), $arg4
-    mov     $sf_arg5(%rbx), $arg5
-    mov     $sf_state_ptr(%rbx), $arg6
-___
-$code .= call_internal("SHA3_shake128_x4_inc_squeeze_avx512vl_internal");
-$code.=<<___;
-
-    # Clear the temporary buffer
-    lea     $sf_state_x4(%rbx), %r9
-    vpxorq      %ymm31, %ymm31, %ymm31
-    vmovdqu64   %ymm31, 32*0(%r9)
-    vmovdqu64   %ymm31, 32*1(%r9)
-    vmovdqu64   %ymm31, 32*2(%r9)
-    vmovdqu64   %ymm31, 32*3(%r9)
-    vmovdqu64   %ymm31, 32*4(%r9)
-    vmovdqu64   %ymm31, 32*5(%r9)
-    vmovdqu64   %ymm31, 32*6(%r9)
-    vmovdqu64   %ymm31, 32*7(%r9)
-    vmovdqu64   %ymm31, 32*8(%r9)
-    vmovdqu64   %ymm31, 32*9(%r9)
-    vmovdqu64   %ymm31, 32*10(%r9)
-    vmovdqu64   %ymm31, 32*11(%r9)
-    vmovdqu64   %ymm31, 32*12(%r9)
-    vmovdqu64   %ymm31, 32*13(%r9)
-    vmovdqu64   %ymm31, 32*14(%r9)
-    vmovdqu64   %ymm31, 32*15(%r9)
-    vmovdqu64   %ymm31, 32*16(%r9)
-    vmovdqu64   %ymm31, 32*17(%r9)
-    vmovdqu64   %ymm31, 32*18(%r9)
-    vmovdqu64   %ymm31, 32*19(%r9)
-    vmovdqu64   %ymm31, 32*20(%r9)
-    vmovdqu64   %ymm31, 32*21(%r9)
-    vmovdqu64   %ymm31, 32*22(%r9)
-    vmovdqu64   %ymm31, 32*23(%r9)
-    vmovdqu64   %ymm31, 32*24(%r9)
-    vmovq       %xmm31, 32*25(%r9)
-
-.Lshake128_x4_epilogue:
-___
-$code .= <<___ if ($win64);
-    vmovups $sf_size+0(%rsp),   %xmm6
-    vmovups $sf_size+16(%rsp),  %xmm7
-    vmovups $sf_size+32(%rsp),  %xmm8
-    vmovups $sf_size+48(%rsp),  %xmm9
-    vmovups $sf_size+64(%rsp),  %xmm10
-    vmovups $sf_size+80(%rsp),  %xmm11
-    vmovups $sf_size+96(%rsp),  %xmm12
-    vmovups $sf_size+112(%rsp), %xmm13
-    vmovups $sf_size+128(%rsp), %xmm14
-    vmovups $sf_size+144(%rsp), %xmm15
-    add     \$160, %rsp
-___
-$code.=<<___;
-    add     \$$sf_size, %rsp
-    pop     %rbx
-.cfi_pop        %rbx
-    pop     %rbp
-.cfi_pop        %rbp
-    ret
-.cfi_endproc
-.size   SHA3_shake128_x4_avx512vl,.-SHA3_shake128_x4_avx512vl
-
-___
-
-$code .= <<___ if ($win64);
-# Internal Win64 shim for absorb entry. It establishes xlate-compatible
-# unwind state and then jumps to the function entry after the prologue.
-# This is required for internal calls since the xlate ABI conversion
-# is already done in the caller function.
-.type   SHA3_shake128_x4_inc_absorb_avx512vl_internal,\@abi-omnipotent
-.align  32
-.LSEH_begin_SHA3_shake128_x4_inc_absorb_avx512vl_internal:
-SHA3_shake128_x4_inc_absorb_avx512vl_internal:
-    mov     %rsp, %rax
-    mov     $arg1, 8(%rsp)
-    mov     $arg2, 16(%rsp)
-    jmp     .L_SHA3_shake128_x4_inc_absorb_avx512vl
-.LSEH_end_SHA3_shake128_x4_inc_absorb_avx512vl_internal:
-.size   SHA3_shake128_x4_inc_absorb_avx512vl_internal,.-SHA3_shake128_x4_inc_absorb_avx512vl_internal
-___
-$code.=<<___;
-
-# SHA3_shake128_x4_inc_absorb_avx512vl
-# Absorb input data into 4 parallel SHAKE128 states
-# Arguments:
-#   arg1 (rdi): pointer to state context (808 bytes)
-#   arg2 (rsi): pointer to lane 0 input data
-#   arg3 (rdx): pointer to lane 1 input data
-#   arg4 (rcx): pointer to lane 2 input data
-#   arg5 (r8):  pointer to lane 3 input data
-#   arg6 (r9):  input length in bytes (must be same for all lanes)
-# Returns: void
-# Note: Input is XORed into state and Keccak permutation is applied for each rate-sized block
-.globl  SHA3_shake128_x4_inc_absorb_avx512vl
-.type   SHA3_shake128_x4_inc_absorb_avx512vl,\@function,6
-.align  32
-SHA3_shake128_x4_inc_absorb_avx512vl:
-.L_SHA3_shake128_x4_inc_absorb_avx512vl:
-.cfi_startproc
-        push    %rbp
-.cfi_push       %rbp
-        push    %rbx
-.cfi_push       %rbx
-        push    %r12
-.cfi_push       %r12
-        push    %r13
-.cfi_push       %r13
-        push    %r14
-.cfi_push       %r14
-        push    %r15
-.cfi_push       %r15
-___
-$code .= <<___ if ($win64);
-    sub     \$160, %rsp
-    vmovups %xmm6,   0(%rsp)
-    vmovups %xmm7,   16(%rsp)
-    vmovups %xmm8,   32(%rsp)
-    vmovups %xmm9,   48(%rsp)
-    vmovups %xmm10,  64(%rsp)
-    vmovups %xmm11,  80(%rsp)
-    vmovups %xmm12,  96(%rsp)
-    vmovups %xmm13,  112(%rsp)
-    vmovups %xmm14,  128(%rsp)
-    vmovups %xmm15,  144(%rsp)
-___
-$code.=<<___;
-
-.Lshake128_absorb_body:
-    # check for partially processed block
-    mov     8*100($arg1), %r14
-    or      %r14, %r14 # s[100] == 0?
-    je      .Lshake128_absorb_main_loop_start
-
-    # process remaining bytes if message long enough
-    mov     \$168, %r12 # SHAKE128_RATE = 168
-    sub     %r14, %r12  # %r12 = capacity
-
-    cmp     %r12, $arg6 # if mlen <= capacity then no permute
-    jbe     .Lshake128_absorb_skip_permute
-
-    sub     %r12, $arg6
-    mov     $arg6, %r11 # preserve remaining length across helper calls
-
-    # r10/state, arg2-arg5/inputs, r12/length
-    mov     $arg1, %r10                # %r10 = state
-    call    keccak_1600_partial_add_x4 # arg2-arg5 are updated
-
-    call    keccak_1600_load_state_x4
-
-    call    keccak_1600_permute
-
-    movq    \$0, 8*100($arg1) # clear s[100]
-    jmp     .Lshake128_absorb_partial_block_done
-
-.Lshake128_absorb_skip_permute:
-    # r10/state, arg2-arg5/inputs, r12/length
-    mov     $arg1, %r10
-    mov     $arg6, %r12
-    mov     $arg6, %r11 # preserve input length across helper call
-    call    keccak_1600_partial_add_x4
-
-    lea     (%r11,%r14), %r15
-    mov     %r15, 8*100($arg1) # s[100] += inlen
-
-    cmp     \$168, %r15 # check s[100] below SHAKE128_RATE
-    jb      .Lshake128_absorb_exit
-
-    call    keccak_1600_load_state_x4
-
-    call    keccak_1600_permute
-
-    call    keccak_1600_save_state_x4
-
-    movq    \$0, 8*100($arg1) # clear s[100]
-    jmp     .Lshake128_absorb_exit
-
-.Lshake128_absorb_main_loop_start:
-    call    keccak_1600_load_state_x4
-    mov     $arg6, %r11 # full input length when no prior partial block
-
-.Lshake128_absorb_partial_block_done:
-    xor     %r12, %r12  # zero message offset
-
-    # Process the input message in blocks
-.align  32
-.Lshake128_absorb_while_loop:
-    cmp     \$168, %r11 # compare mlen to SHAKE128_RATE
-    jb      .Lshake128_absorb_while_loop_done
-
-    # Inline absorb_bytes_x4 for SHAKE128_RATE (168 bytes = 21 ymm registers)
-___
-
-# Generate absorb code for SHAKE128 rate (168 bytes)
-for (my $i = 0; $i < 21; $i++) {
-    my $offset = $i * 8;
-    $code.=<<___;
-        vmovq       $offset($arg2,%r12), %xmm31
-        vpinsrq     \$1, $offset($arg3,%r12), %xmm31, %xmm31
-        vmovq       $offset($arg4,%r12), %xmm30
-        vpinsrq     \$1, $offset($arg5,%r12), %xmm30, %xmm30
-        vinserti32x4 \$1, %xmm30, %ymm31, %ymm31
-        vpxorq      %ymm31, %ymm$i, %ymm$i
-___
-}
-
-$code.=<<___;
-    sub     \$168, %r11         # Subtract the rate from the remaining length
-    add     \$168, %r12         # Adjust offset to next block
-    call    keccak_1600_permute # Perform the Keccak permutation
-
-    jmp     .Lshake128_absorb_while_loop
-
-.align  32
-.Lshake128_absorb_while_loop_done:
-    call    keccak_1600_save_state_x4
-
-    mov     %r11, 8*100($arg1) # update s[100]
-    or      %r11, %r11
-    jz      .Lshake128_absorb_exit
-
-    movq    \$0, 8*100($arg1) # clear s[100]
-
-    # r10/state, arg2-arg5/input, r12/length
-    mov     $arg1, %r10
-    add     %r12, $arg2
-    add     %r12, $arg3
-    add     %r12, $arg4
-    add     %r12, $arg5
-    mov     %r11, %r12
-    call    keccak_1600_partial_add_x4
-
-    mov     %r11, 8*100($arg1) # update s[100]
-
-.Lshake128_absorb_exit:
-    # Clear sensitive registers
-    vpxorq      %xmm16, %xmm16, %xmm16
-    vmovdqa64   %ymm16, %ymm17
-    vmovdqa64   %ymm16, %ymm18
-    vmovdqa64   %ymm16, %ymm19
-    vmovdqa64   %ymm16, %ymm20
-    vmovdqa64   %ymm16, %ymm21
-    vmovdqa64   %ymm16, %ymm22
-    vmovdqa64   %ymm16, %ymm23
-    vmovdqa64   %ymm16, %ymm24
-    vmovdqa64   %ymm16, %ymm25
-    vmovdqa64   %ymm16, %ymm26
-    vmovdqa64   %ymm16, %ymm27
-    vmovdqa64   %ymm16, %ymm28
-    vmovdqa64   %ymm16, %ymm29
-    vmovdqa64   %ymm16, %ymm30
-    vmovdqa64   %ymm16, %ymm31
-.Lshake128_absorb_epilogue:
-    vzeroall
-___
-$code .= <<___ if ($win64);
-    vmovups 0(%rsp),   %xmm6
-    vmovups 16(%rsp),  %xmm7
-    vmovups 32(%rsp),  %xmm8
-    vmovups 48(%rsp),  %xmm9
-    vmovups 64(%rsp),  %xmm10
-    vmovups 80(%rsp),  %xmm11
-    vmovups 96(%rsp),  %xmm12
-    vmovups 112(%rsp), %xmm13
-    vmovups 128(%rsp), %xmm14
-    vmovups 144(%rsp), %xmm15
-    add     \$160, %rsp
-___
-$code.=<<___;
-
-    pop     %r15
-.cfi_pop        %r15
-    pop     %r14
-.cfi_pop        %r14
-    pop     %r13
-.cfi_pop        %r13
-    pop     %r12
-.cfi_pop        %r12
-    pop     %rbx
-.cfi_pop        %rbx
-    pop     %rbp
-.cfi_pop        %rbp
-    ret
-.cfi_endproc
-.size   SHA3_shake128_x4_inc_absorb_avx512vl,.-SHA3_shake128_x4_inc_absorb_avx512vl
-
-
-# SHA3_shake128_x4_inc_finalize_avx512vl
-# Finalize absorption phase for 4 parallel SHAKE-128 states
-# Adds padding and terminator bytes and clears the absorb offset
-# Arguments:
-#   arg1 (rdi): pointer to state context (808 bytes)
-# Returns: void
-# Note: After this call, state is ready for squeezing output
-.globl  SHA3_shake128_x4_inc_finalize_avx512vl
-.type   SHA3_shake128_x4_inc_finalize_avx512vl,\@function,1
-.align  32
-SHA3_shake128_x4_inc_finalize_avx512vl:
-.L_SHA3_shake128_x4_inc_finalize_avx512vl:
-.cfi_startproc
-    mov         8*100($arg1), %r11 # load state offset from s[100]
-    mov         %r11, %r10
-    and         \$~7, %r10d        # offset to the state register
-    and         \$7, %r11d         # offset within the register
-
-    # add EOM byte right after the message
-    vmovdqu32   ($arg1,%r10,4), %ymm31
-    lea         shake_msg_pad_x4(%rip), %r9
-    sub         %r11, %r9
-    vmovdqu32   (%r9), %ymm30
-    vpxorq      %ymm30, %ymm31, %ymm31
-    vmovdqu32   %ymm31, ($arg1,%r10,4)
-
-    # add terminating byte at offset equal to rate - 1 (SHAKE128_RATE = 168)
-    vmovdqu32   640($arg1), %ymm31 # 168*4 - 32 = 672 - 32 = 640
-    vmovdqa32   shake_terminator_byte_x4(%rip), %ymm30
-    vpxorq      %ymm30, %ymm31, %ymm31
-    vmovdqu32   %ymm31, 640($arg1)
-
-    movq        \$0, 8*100($arg1) # clear s[100]
-    vpxorq      %ymm31, %ymm31, %ymm31
-    ret
-.cfi_endproc
-.size   SHA3_shake128_x4_inc_finalize_avx512vl,.-SHA3_shake128_x4_inc_finalize_avx512vl
-
-___
-
-$code .= <<___ if ($win64);
-# Internal Win64 shim for squeeze entry. It establishes xlate-compatible
-# unwind state and then jumps to the function entry after the prologue.
-# This is required for internal calls since the xlate ABI conversion
-# is already done in the caller function.
-.type   SHA3_shake128_x4_inc_squeeze_avx512vl_internal,\@abi-omnipotent
-.align  32
-.LSEH_begin_SHA3_shake128_x4_inc_squeeze_avx512vl_internal:
-SHA3_shake128_x4_inc_squeeze_avx512vl_internal:
-    mov     %rsp, %rax
-    mov     $arg1, 8(%rsp)
-    mov     $arg2, 16(%rsp)
-    jmp     .L_SHA3_shake128_x4_inc_squeeze_avx512vl
-.LSEH_end_SHA3_shake128_x4_inc_squeeze_avx512vl_internal:
-.size   SHA3_shake128_x4_inc_squeeze_avx512vl_internal,.-SHA3_shake128_x4_inc_squeeze_avx512vl_internal
-___
-$code.=<<___;
-
-# SHA3_shake128_x4_inc_squeeze_avx512vl
-# Squeeze output from 4 parallel SHAKE128 states
-# Arguments:
-#   arg1 (rdi): pointer to lane 0 output buffer
-#   arg2 (rsi): pointer to lane 1 output buffer
-#   arg3 (rdx): pointer to lane 2 output buffer
-#   arg4 (rcx): pointer to lane 3 output buffer
-#   arg5 (r8):  output length in bytes (must be same for all lanes)
-#   arg6 (r9):  pointer to state context (808 bytes)
-# Returns: void
-# Note: Can be called multiple times to generate arbitrary-length output
-.globl  SHA3_shake128_x4_inc_squeeze_avx512vl
-.type   SHA3_shake128_x4_inc_squeeze_avx512vl,\@function,6
-.align  32
-SHA3_shake128_x4_inc_squeeze_avx512vl:
-.L_SHA3_shake128_x4_inc_squeeze_avx512vl:
-.cfi_startproc
-    push    %rbp
-.cfi_push       %rbp
-    push    %rbx
-.cfi_push       %rbx
-    push    %r12
-.cfi_push       %r12
-    push    %r13
-.cfi_push       %r13
-    push    %r14
-.cfi_push       %r14
-    push    %r15
-.cfi_push       %r15
-___
-$code .= <<___ if ($win64);
-    sub     \$160, %rsp
-    vmovups %xmm6,   0(%rsp)
-    vmovups %xmm7,   16(%rsp)
-    vmovups %xmm8,   32(%rsp)
-    vmovups %xmm9,   48(%rsp)
-    vmovups %xmm10,  64(%rsp)
-    vmovups %xmm11,  80(%rsp)
-    vmovups %xmm12,  96(%rsp)
-    vmovups %xmm13,  112(%rsp)
-    vmovups %xmm14,  128(%rsp)
-    vmovups %xmm15,  144(%rsp)
-___
-$code.=<<___;
-
-.Lshake128_squeeze_body:
-    or      $arg5, $arg5
-    jz      .Lshake128_squeeze_done
-
-    # check for partially processed block
-    mov     8*100($arg6), %r15 # s[100] - capacity
-    or      %r15, %r15
-    jnz     .Lshake128_squeeze_no_init_permute
-
-    mov     $arg1, %r14
-    mov     $arg6, $arg1
-    call    keccak_1600_load_state_x4
-
-    mov     %r14, $arg1
-
-    xor     %rbp, %rbp
-    jmp     .Lshake128_squeeze_loop
-
-.align  32
-.Lshake128_squeeze_no_init_permute:
-    # extract bytes: r10 - state/src, arg1-arg4 - output/dst, r12 - length = min(capacity, outlen), r11 - offset
-    mov     $arg6, %r10
-    mov     $arg6, %r14 # preserve state pointer across extract helper
-
-    mov     %r15, %r12
-    cmp     %r15, $arg5
-    cmovnae $arg5, %r12 # %r12 = min(capacity, outlen)
-
-    sub     %r12, $arg5 # outlen -= length
-
-    mov     \$168, %r11d # SHAKE128_RATE
-    sub     %r15, %r11   # state offset
-
-    sub     %r12, %r15         # capacity -= length
-    mov     %r15, 8*100($arg6) # update s[100]
-
-    call    keccak_1600_extract_bytes_x4
-    mov     %r14, $arg6        # restore state pointer after helper clobbers
-
-    or      %r15, %r15
-    jnz     .Lshake128_squeeze_done # check s[100] not zero
-
-    mov     $arg1, %r13 # preserve arg1
-    mov     %r14, $arg1
-    call    keccak_1600_load_state_x4
-
-    mov     %r13, $arg1
-    xor     %rbp, %rbp
-
-.align  32
-.Lshake128_squeeze_loop:
-    cmp     \$168, $arg5 # outlen > SHAKE128_RATE
-    jb      .Lshake128_squeeze_final_extract
-
-    call    keccak_1600_permute
-
-    # Extract SHAKE128 rate bytes (168 bytes = 21 x 8 bytes) inline
-___
-
-# Generate extract code for SHAKE128 rate (168 bytes = 21 ymm registers)
-for (my $i = 0; $i < 21; $i++) {
-    my $offset = $i * 8;
-    $code.=<<___;
-        vextracti64x2 \$1, %ymm$i, %xmm31
-        vmovq       %xmm$i, $offset($arg1,%rbp)
-        vpextrq     \$1, %xmm$i, $offset($arg2,%rbp)
-        vmovq       %xmm31, $offset($arg3,%rbp)
-        vpextrq     \$1, %xmm31, $offset($arg4,%rbp)
-___
-}
-
-$code.=<<___;
-    add     \$168, %rbp  # dst offset += SHAKE128_RATE
-    sub     \$168, $arg5 # outlen -= SHAKE128_RATE
-    jmp     .Lshake128_squeeze_loop
-
-.align  32
-.Lshake128_squeeze_final_extract:
-    or      $arg5, $arg5
-    jz      .Lshake128_squeeze_no_end_permute
-
-    # update output pointers
-    add     %rbp, $arg1
-    add     %rbp, $arg2
-    add     %rbp, $arg3
-    add     %rbp, $arg4
-
-    mov     \$168, %r15d       # SHAKE128_RATE
-    sub     $arg5, %r15
-    mov     %r15, 8*100($arg6) # s[100] = capacity
-
-    call    keccak_1600_permute
-
-    mov     $arg1, %r14
-    mov     $arg6, $arg1
-    call    keccak_1600_save_state_x4
-
-    mov     %r14, $arg1
-
-    # extract bytes: r10 - state/src, arg1-arg4 - output/dst, r12 - length, r11 - offset = 0
-    mov     $arg6, %r10
-    mov     $arg5, %r12
-    xor     %r11, %r11
-    call    keccak_1600_extract_bytes_x4
-
-    jmp     .Lshake128_squeeze_done
-
-.Lshake128_squeeze_no_end_permute:
-    movq    \$0, 8*100($arg6) # s[100] = 0
-    mov     $arg6, $arg1
-    call    keccak_1600_save_state_x4
-
-.Lshake128_squeeze_done:
-    # Clear sensitive registers
-    vpxorq      %xmm16, %xmm16, %xmm16
-    vmovdqa64   %ymm16, %ymm17
-    vmovdqa64   %ymm16, %ymm18
-    vmovdqa64   %ymm16, %ymm19
-    vmovdqa64   %ymm16, %ymm20
-    vmovdqa64   %ymm16, %ymm21
-    vmovdqa64   %ymm16, %ymm22
-    vmovdqa64   %ymm16, %ymm23
-    vmovdqa64   %ymm16, %ymm24
-    vmovdqa64   %ymm16, %ymm25
-    vmovdqa64   %ymm16, %ymm26
-    vmovdqa64   %ymm16, %ymm27
-    vmovdqa64   %ymm16, %ymm28
-    vmovdqa64   %ymm16, %ymm29
-    vmovdqa64   %ymm16, %ymm30
-    vmovdqa64   %ymm16, %ymm31
-.Lshake128_squeeze_epilogue:
-    vzeroall
-___
-$code .= <<___ if ($win64);
-    vmovups 0(%rsp),   %xmm6
-    vmovups 16(%rsp),  %xmm7
-    vmovups 32(%rsp),  %xmm8
-    vmovups 48(%rsp),  %xmm9
-    vmovups 64(%rsp),  %xmm10
-    vmovups 80(%rsp),  %xmm11
-    vmovups 96(%rsp),  %xmm12
-    vmovups 112(%rsp), %xmm13
-    vmovups 128(%rsp), %xmm14
-    vmovups 144(%rsp), %xmm15
-    add     \$160, %rsp
-___
-$code.=<<___;
-
-    pop %r15
-.cfi_pop    %r15
-    pop %r14
-.cfi_pop    %r14
-    pop %r13
-.cfi_pop    %r13
-    pop %r12
-.cfi_pop    %r12
-    pop %rbx
-.cfi_pop    %rbx
-    pop %rbp
-.cfi_pop    %rbp
-    ret
-.cfi_endproc
-.size   SHA3_shake128_x4_inc_squeeze_avx512vl,.-SHA3_shake128_x4_inc_squeeze_avx512vl
-
-
-# SHAKE256 x4 multi-buffer functions
-# These functions process 4 independent SHAKE256 streams in parallel using AVX-512VL
-# State layout: 25 ymm registers (200 bytes each) + 1 qword = 808 bytes per context
-# Rate: 136 bytes for SHAKE256
-
-# SHA3_shake256_x4_avx512vl
-# One-shot SHAKE-256 x4 function: init + absorb + finalize + squeeze
-# Arguments:
-#   arg1 (rdi): pointer to output lane 0
-#   arg2 (rsi): pointer to output lane 1
-#   arg3 (rdx): pointer to output lane 2
-#   arg4 (rcx): pointer to output lane 3
-#   arg5 (r8):  output length in bytes (must be same for all lanes)
-#   arg6 (r9):  pointer to input lane 0
-#   [stack+0]:  pointer to input lane 1
-#   [stack+8]:  pointer to input lane 2
-#   [stack+16]: pointer to input lane 3
-#   [stack+24]: input length in bytes (must be same for all lanes)
-# Returns: void
-.globl  SHA3_shake256_x4_avx512vl
-.type   SHA3_shake256_x4_avx512vl,\@function,10
-.align  32
-SHA3_shake256_x4_avx512vl:
-.cfi_startproc
-    push    %rbp
-.cfi_push       %rbp
-    mov     %rsp, %rbp
-    push    %rbx
-.cfi_push       %rbx
-___
-$code .= <<___ if ($win64);
-    sub     \$160, %rsp
-    vmovups %xmm6,   0(%rsp)
-    vmovups %xmm7,   16(%rsp)
-    vmovups %xmm8,   32(%rsp)
-    vmovups %xmm9,   48(%rsp)
-    vmovups %xmm10,  64(%rsp)
-    vmovups %xmm11,  80(%rsp)
-    vmovups %xmm12,  96(%rsp)
-    vmovups %xmm13,  112(%rsp)
-    vmovups %xmm14,  128(%rsp)
-    vmovups %xmm15,  144(%rsp)
-___
-$code.=<<___;
-
-    sub     \$$sf_size, %rsp
-    mov     %rsp, %rbx
-
-.Lshake256_x4_body:
-    mov     $arg1, $sf_arg1(%rbx)
-    mov     $arg2, $sf_arg2(%rbx)
-    mov     $arg3, $sf_arg3(%rbx)
-    mov     $arg4, $sf_arg4(%rbx)
-    mov     $arg5, $sf_arg5(%rbx)
-
-    lea     $sf_state_x4(%rbx), $arg1 # start of x4 state on the stack frame
-    mov     $arg1, $sf_state_ptr(%rbx)
-
-    # Initialize the state array to zero
-    call    keccak_1600_init_state
-
-    call    keccak_1600_save_state_x4
-
-    movq    \$0, 8*100($arg1) # clear s[100]
-
-    mov     $sf_state_ptr(%rbx), $arg1
-    mov     $arg6, $arg2
-___
-$code .= <<___ if ($win64);
-    # xlate prologue handles up to six arguments. For one-shot x4 wrappers
-    # (10 args), the remaining four stay in Win64 stack slots.
-    mov     64(%rbp), $arg3 # arg7 from stack
-    mov     72(%rbp), $arg4 # arg8 from stack
-    mov     80(%rbp), $arg5 # arg9 from stack
-    mov     88(%rbp), $arg6 # arg10 from stack
-___
-$code .= <<___ if (!$win64);
-    mov     16(%rbp), $arg3 # arg7 from stack
-    mov     24(%rbp), $arg4 # arg8 from stack
-    mov     32(%rbp), $arg5 # arg9 from stack
-    mov     40(%rbp), $arg6 # arg10 from stack
-___
-$code.=<<___;
-    # Internal entry avoids Win64 xlate prologue argument remapping.
-___
-$code .= call_internal("SHA3_shake256_x4_inc_absorb_avx512vl_internal");
-$code.=<<___;
-
-    mov     $sf_state_ptr(%rbx), $arg1
-    call    .L_SHA3_shake256_x4_inc_finalize_avx512vl
-
-    # squeeze
-    mov     $sf_arg1(%rbx), $arg1
-    mov     $sf_arg2(%rbx), $arg2
-    mov     $sf_arg3(%rbx), $arg3
-    mov     $sf_arg4(%rbx), $arg4
-    mov     $sf_arg5(%rbx), $arg5
-    mov     $sf_state_ptr(%rbx), $arg6
-___
-$code .= call_internal("SHA3_shake256_x4_inc_squeeze_avx512vl_internal");
-$code.=<<___;
-
-    # Clear the temporary buffer
-    lea     $sf_state_x4(%rbx), %r9
-    vpxorq      %ymm31, %ymm31, %ymm31
-    vmovdqu64   %ymm31, 32*0(%r9)
-    vmovdqu64   %ymm31, 32*1(%r9)
-    vmovdqu64   %ymm31, 32*2(%r9)
-    vmovdqu64   %ymm31, 32*3(%r9)
-    vmovdqu64   %ymm31, 32*4(%r9)
-    vmovdqu64   %ymm31, 32*5(%r9)
-    vmovdqu64   %ymm31, 32*6(%r9)
-    vmovdqu64   %ymm31, 32*7(%r9)
-    vmovdqu64   %ymm31, 32*8(%r9)
-    vmovdqu64   %ymm31, 32*9(%r9)
-    vmovdqu64   %ymm31, 32*10(%r9)
-    vmovdqu64   %ymm31, 32*11(%r9)
-    vmovdqu64   %ymm31, 32*12(%r9)
-    vmovdqu64   %ymm31, 32*13(%r9)
-    vmovdqu64   %ymm31, 32*14(%r9)
-    vmovdqu64   %ymm31, 32*15(%r9)
-    vmovdqu64   %ymm31, 32*16(%r9)
-    vmovdqu64   %ymm31, 32*17(%r9)
-    vmovdqu64   %ymm31, 32*18(%r9)
-    vmovdqu64   %ymm31, 32*19(%r9)
-    vmovdqu64   %ymm31, 32*20(%r9)
-    vmovdqu64   %ymm31, 32*21(%r9)
-    vmovdqu64   %ymm31, 32*22(%r9)
-    vmovdqu64   %ymm31, 32*23(%r9)
-    vmovdqu64   %ymm31, 32*24(%r9)
-    vmovq       %xmm31, 32*25(%r9)
-
-.Lshake256_x4_epilogue:
-___
-$code .= <<___ if ($win64);
-    vmovups $sf_size+0(%rsp),   %xmm6
-    vmovups $sf_size+16(%rsp),  %xmm7
-    vmovups $sf_size+32(%rsp),  %xmm8
-    vmovups $sf_size+48(%rsp),  %xmm9
-    vmovups $sf_size+64(%rsp),  %xmm10
-    vmovups $sf_size+80(%rsp),  %xmm11
-    vmovups $sf_size+96(%rsp),  %xmm12
-    vmovups $sf_size+112(%rsp), %xmm13
-    vmovups $sf_size+128(%rsp), %xmm14
-    vmovups $sf_size+144(%rsp), %xmm15
-    add     \$160, %rsp
-___
-$code.=<<___;
-    add     \$$sf_size, %rsp
-    pop     %rbx
-.cfi_pop        %rbx
-    pop     %rbp
-.cfi_pop        %rbp
-    ret
-.cfi_endproc
-.size   SHA3_shake256_x4_avx512vl,.-SHA3_shake256_x4_avx512vl
-
-___
-
-$code .= <<___ if ($win64);
-# Internal Win64 shim for absorb entry. It establishes xlate-compatible
-# unwind state and then jumps to the function entry after the prologue.
-# This is required for internal calls since the xlate ABI conversion
-# is already done in the caller function.
-.type   SHA3_shake256_x4_inc_absorb_avx512vl_internal,\@abi-omnipotent
-.align  32
-.LSEH_begin_SHA3_shake256_x4_inc_absorb_avx512vl_internal:
-SHA3_shake256_x4_inc_absorb_avx512vl_internal:
-    mov     %rsp, %rax
-    mov     $arg1, 8(%rsp)
-    mov     $arg2, 16(%rsp)
-    jmp     .L_SHA3_shake256_x4_inc_absorb_avx512vl
-.LSEH_end_SHA3_shake256_x4_inc_absorb_avx512vl_internal:
-.size   SHA3_shake256_x4_inc_absorb_avx512vl_internal,.-SHA3_shake256_x4_inc_absorb_avx512vl_internal
-___
-$code.=<<___;
-
-# SHA3_shake256_x4_inc_absorb_avx512vl
-# Absorb input data into 4 parallel SHAKE256 states
-# Arguments:
-#   arg1 (rdi): pointer to state context (808 bytes)
-#   arg2 (rsi): pointer to lane 0 input data
-#   arg3 (rdx): pointer to lane 1 input data
-#   arg4 (rcx): pointer to lane 2 input data
-#   arg5 (r8):  pointer to lane 3 input data
-#   arg6 (r9):  input length in bytes (must be same for all lanes)
-# Returns: void
-# Note: Input is XORed into state and Keccak permutation is applied for each rate-sized block
-.globl  SHA3_shake256_x4_inc_absorb_avx512vl
-.type   SHA3_shake256_x4_inc_absorb_avx512vl,\@function,6
-.align  32
-SHA3_shake256_x4_inc_absorb_avx512vl:
-.L_SHA3_shake256_x4_inc_absorb_avx512vl:
-.cfi_startproc
-    push    %rbp
-.cfi_push       %rbp
-    push    %rbx
-.cfi_push       %rbx
-    push    %r12
-.cfi_push       %r12
-    push    %r13
-.cfi_push       %r13
-    push    %r14
-.cfi_push       %r14
-    push    %r15
-.cfi_push       %r15
-___
-$code .= <<___ if ($win64);
-    sub     \$160, %rsp
-    vmovups %xmm6,   0(%rsp)
-    vmovups %xmm7,   16(%rsp)
-    vmovups %xmm8,   32(%rsp)
-    vmovups %xmm9,   48(%rsp)
-    vmovups %xmm10,  64(%rsp)
-    vmovups %xmm11,  80(%rsp)
-    vmovups %xmm12,  96(%rsp)
-    vmovups %xmm13,  112(%rsp)
-    vmovups %xmm14,  128(%rsp)
-    vmovups %xmm15,  144(%rsp)
-___
-$code.=<<___;
-
-.Lshake256_absorb_body:
-    # check for partially processed block
-    mov     8*100($arg1), %r14
-    or      %r14, %r14 # s[100] == 0?
-    je      .Lshake256_absorb_main_loop_start
-
-    # process remaining bytes if message long enough
-    mov     \$136, %r12 # SHAKE256_RATE = 136
-    sub     %r14, %r12  # %r12 = capacity
-
-    cmp     %r12, $arg6 # if mlen <= capacity then no permute
-    jbe     .Lshake256_absorb_skip_permute
-
-    sub     %r12, $arg6
-    mov     $arg6, %r11 # preserve remaining length across helper calls
-
-    # r10/state, arg2-arg5/inputs, r12/length
-    mov     $arg1, %r10                # %r10 = state
-    call    keccak_1600_partial_add_x4 # arg2-arg5 are updated
-
-    call    keccak_1600_load_state_x4
-
-    call    keccak_1600_permute
-
-    movq    \$0, 8*100($arg1) # clear s[100]
-    jmp     .Lshake256_absorb_partial_block_done
-
-.Lshake256_absorb_skip_permute:
-    # r10/state, arg2-arg5/inputs, r12/length
-    mov     $arg1, %r10
-    mov     $arg6, %r12
-    mov     $arg6, %r11 # preserve input length across helper call
-    call    keccak_1600_partial_add_x4
-
-    lea     (%r11,%r14), %r15
-    mov     %r15, 8*100($arg1) # s[100] += inlen
-
-    cmp     \$136, %r15 # check s[100] below SHAKE256_RATE
-    jb      .Lshake256_absorb_exit
-
-    call    keccak_1600_load_state_x4
-
-    call    keccak_1600_permute
-
-    call    keccak_1600_save_state_x4
-
-    movq    \$0, 8*100($arg1) # clear s[100]
-    jmp     .Lshake256_absorb_exit
-
-.Lshake256_absorb_main_loop_start:
-    call    keccak_1600_load_state_x4
-    mov     $arg6, %r11 # full input length when no prior partial block
-
-.Lshake256_absorb_partial_block_done:
-    xor     %r12, %r12  # zero message offset
-
-    # Process the input message in blocks
-.align  32
-.Lshake256_absorb_while_loop:
-    cmp     \$136, %r11 # compare mlen to SHAKE256_RATE
-    jb      .Lshake256_absorb_while_loop_done
-
-    # Inline absorb_bytes_x4 for SHAKE256_RATE (136 bytes = 17 ymm registers)
-___
-
-# Generate absorb code for SHAKE256 rate (136 bytes)
-for (my $i = 0; $i < 17; $i++) {
-    my $offset = $i * 8;
-    $code.=<<___;
-        vmovq       $offset($arg2,%r12), %xmm31
-        vpinsrq     \$1, $offset($arg3,%r12), %xmm31, %xmm31
-        vmovq       $offset($arg4,%r12), %xmm30
-        vpinsrq     \$1, $offset($arg5,%r12), %xmm30, %xmm30
-        vinserti32x4 \$1, %xmm30, %ymm31, %ymm31
-        vpxorq      %ymm31, %ymm$i, %ymm$i
-___
-}
-
-$code.=<<___;
-    sub     \$136, %r11         # Subtract the rate from the remaining length
-    add     \$136, %r12         # Adjust offset to next block
-    call    keccak_1600_permute # Perform the Keccak permutation
-
-    jmp     .Lshake256_absorb_while_loop
-
-.align  32
-.Lshake256_absorb_while_loop_done:
-    call    keccak_1600_save_state_x4
-
-    mov     %r11, 8*100($arg1) # update s[100]
-    or      %r11, %r11
-    jz      .Lshake256_absorb_exit
-
-    movq    \$0, 8*100($arg1) # clear s[100]
-
-    # r10/state, arg2-arg5/input, r12/length
-    mov     $arg1, %r10
-    add     %r12, $arg2
-    add     %r12, $arg3
-    add     %r12, $arg4
-    add     %r12, $arg5
-    mov     %r11, %r12
-    call    keccak_1600_partial_add_x4
-
-    mov     %r11, 8*100($arg1) # update s[100]
-
-.Lshake256_absorb_exit:
-    # Clear sensitive registers
-    vpxorq      %xmm16, %xmm16, %xmm16
-    vmovdqa64   %ymm16, %ymm17
-    vmovdqa64   %ymm16, %ymm18
-    vmovdqa64   %ymm16, %ymm19
-    vmovdqa64   %ymm16, %ymm20
-    vmovdqa64   %ymm16, %ymm21
-    vmovdqa64   %ymm16, %ymm22
-    vmovdqa64   %ymm16, %ymm23
-    vmovdqa64   %ymm16, %ymm24
-    vmovdqa64   %ymm16, %ymm25
-    vmovdqa64   %ymm16, %ymm26
-    vmovdqa64   %ymm16, %ymm27
-    vmovdqa64   %ymm16, %ymm28
-    vmovdqa64   %ymm16, %ymm29
-    vmovdqa64   %ymm16, %ymm30
-    vmovdqa64   %ymm16, %ymm31
-.Lshake256_absorb_epilogue:
-    vzeroall
-___
-$code .= <<___ if ($win64);
-    vmovups 0(%rsp),   %xmm6
-    vmovups 16(%rsp),  %xmm7
-    vmovups 32(%rsp),  %xmm8
-    vmovups 48(%rsp),  %xmm9
-    vmovups 64(%rsp),  %xmm10
-    vmovups 80(%rsp),  %xmm11
-    vmovups 96(%rsp),  %xmm12
-    vmovups 112(%rsp), %xmm13
-    vmovups 128(%rsp), %xmm14
-    vmovups 144(%rsp), %xmm15
-    add     \$160, %rsp
-___
-$code.=<<___;
-
-    pop %r15
-.cfi_pop    %r15
-    pop %r14
-.cfi_pop    %r14
-    pop %r13
-.cfi_pop    %r13
-    pop %r12
-.cfi_pop    %r12
-    pop %rbx
-.cfi_pop    %rbx
-    pop %rbp
-.cfi_pop    %rbp
-    ret
-.cfi_endproc
-.size   SHA3_shake256_x4_inc_absorb_avx512vl,.-SHA3_shake256_x4_inc_absorb_avx512vl
-
-
-# SHA3_shake256_x4_inc_finalize_avx512vl
-# Finalize absorption phase for 4 parallel SHAKE-256 states
-# Adds padding and terminator bytes and clears the absorb offset
-# Arguments:
-#   arg1 (rdi): pointer to state context (808 bytes)
-# Returns: void
-# Note: After this call, state is ready for squeezing output
-.globl  SHA3_shake256_x4_inc_finalize_avx512vl
-.type   SHA3_shake256_x4_inc_finalize_avx512vl,\@function,1
-.align  32
-SHA3_shake256_x4_inc_finalize_avx512vl:
-.L_SHA3_shake256_x4_inc_finalize_avx512vl:
-.cfi_startproc
-    mov     8*100($arg1), %r11 # load state offset from s[100]
-    mov     %r11, %r10
-    and     \$~7, %r10d        # offset to the state register
-    and     \$7, %r11d         # offset within the register
-
-    # add EOM byte right after the message
-    vmovdqu32   ($arg1,%r10,4), %ymm31
-    lea         shake_msg_pad_x4(%rip), %r9
-    sub         %r11, %r9
-    vmovdqu32   (%r9), %ymm30
-    vpxorq      %ymm30, %ymm31, %ymm31
-    vmovdqu32   %ymm31, ($arg1,%r10,4)
-
-    # add terminating byte at offset equal to rate - 1 (SHAKE256_RATE = 136)
-    vmovdqu32   512($arg1), %ymm31 # 136*4 - 32 = 544 - 32 = 512
-    vmovdqa32   shake_terminator_byte_x4(%rip), %ymm30
-    vpxorq      %ymm30, %ymm31, %ymm31
-    vmovdqu32   %ymm31, 512($arg1)
-
-    movq        \$0, 8*100($arg1) # clear s[100]
-    vpxorq      %ymm31, %ymm31, %ymm31
-    ret
-.cfi_endproc
-.size   SHA3_shake256_x4_inc_finalize_avx512vl,.-SHA3_shake256_x4_inc_finalize_avx512vl
-
-___
-
-$code .= <<___ if ($win64);
-# Internal Win64 shim for squeeze entry. It establishes xlate-compatible
-# unwind state and then jumps to the function entry after the prologue.
-# This is required for internal calls since the xlate ABI conversion
-# is already done in the caller function.
-.type   SHA3_shake256_x4_inc_squeeze_avx512vl_internal,\@abi-omnipotent
-.align  32
-.LSEH_begin_SHA3_shake256_x4_inc_squeeze_avx512vl_internal:
-SHA3_shake256_x4_inc_squeeze_avx512vl_internal:
-    mov     %rsp, %rax
-    mov     $arg1, 8(%rsp)
-    mov     $arg2, 16(%rsp)
-    jmp     .L_SHA3_shake256_x4_inc_squeeze_avx512vl
-.LSEH_end_SHA3_shake256_x4_inc_squeeze_avx512vl_internal:
-.size   SHA3_shake256_x4_inc_squeeze_avx512vl_internal,.-SHA3_shake256_x4_inc_squeeze_avx512vl_internal
-___
-$code.=<<___;
-
-# SHA3_shake256_x4_inc_squeeze_avx512vl
-# Squeeze output from 4 parallel SHAKE256 states
-# Arguments:
-#   arg1 (rdi): pointer to lane 0 output buffer
-#   arg2 (rsi): pointer to lane 1 output buffer
-#   arg3 (rdx): pointer to lane 2 output buffer
-#   arg4 (rcx): pointer to lane 3 output buffer
-#   arg5 (r8):  output length in bytes (must be same for all lanes)
-#   arg6 (r9):  pointer to state context (808 bytes)
-# Returns: void
-# Note: Can be called multiple times to generate arbitrary-length output
-.globl  SHA3_shake256_x4_inc_squeeze_avx512vl
-.type   SHA3_shake256_x4_inc_squeeze_avx512vl,\@function,6
-.align  32
-SHA3_shake256_x4_inc_squeeze_avx512vl:
-.L_SHA3_shake256_x4_inc_squeeze_avx512vl:
-.cfi_startproc
-    push    %rbp
-.cfi_push       %rbp
-    push    %rbx
-.cfi_push       %rbx
-    push    %r12
-.cfi_push       %r12
-    push    %r13
-.cfi_push       %r13
-    push    %r14
-.cfi_push       %r14
-    push    %r15
-.cfi_push       %r15
-___
-$code .= <<___ if ($win64);
-    sub     \$160, %rsp
-    vmovups %xmm6,   0(%rsp)
-    vmovups %xmm7,   16(%rsp)
-    vmovups %xmm8,   32(%rsp)
-    vmovups %xmm9,   48(%rsp)
-    vmovups %xmm10,  64(%rsp)
-    vmovups %xmm11,  80(%rsp)
-    vmovups %xmm12,  96(%rsp)
-    vmovups %xmm13,  112(%rsp)
-    vmovups %xmm14,  128(%rsp)
-    vmovups %xmm15,  144(%rsp)
-___
-$code.=<<___;
-
-.Lshake256_squeeze_body:
-    or      $arg5, $arg5
-    jz      .Lshake256_squeeze_done
-
-    # check for partially processed block
-    mov     8*100($arg6), %r15 # s[100] - capacity
-    or      %r15, %r15
-    jnz     .Lshake256_squeeze_no_init_permute
-
-    mov     $arg1, %r14
-    mov     $arg6, $arg1
-    call    keccak_1600_load_state_x4
-
-    mov     %r14, $arg1
-
-    xor     %rbp, %rbp
-    jmp     .Lshake256_squeeze_loop
-
-.align  32
-.Lshake256_squeeze_no_init_permute:
-    # extract bytes: r10 - state/src, arg1-arg4 - output/dst, r12 - length = min(capacity, outlen), r11 - offset
-    mov     $arg6, %r10
-    mov     $arg6, %r14 # preserve state pointer across extract helper
-
-    mov     %r15, %r12
-    cmp     %r15, $arg5
-    cmovnae $arg5, %r12 # %r12 = min(capacity, outlen)
-
-    sub     %r12, $arg5 # outlen -= length
-
-    mov     \$136, %r11d # SHAKE256_RATE
-    sub     %r15, %r11   # state offset
-
-    sub     %r12, %r15         # capacity -= length
-    mov     %r15, 8*100($arg6) # update s[100]
-
-    call    keccak_1600_extract_bytes_x4
-    mov     %r14, $arg6        # restore state pointer after helper clobbers
-
-    or      %r15, %r15
-    jnz     .Lshake256_squeeze_done # check s[100] not zero
-
-    mov     $arg1, %r13 # preserve arg1
-    mov     %r14, $arg1
-    call    keccak_1600_load_state_x4
-
-    mov     %r13, $arg1
-    xor     %rbp, %rbp
-
-.align  32
-.Lshake256_squeeze_loop:
-    cmp     \$136, $arg5 # outlen > SHAKE256_RATE
-    jb      .Lshake256_squeeze_final_extract
-
-    call    keccak_1600_permute
-
-    # Extract SHAKE256 rate bytes (136 bytes = 17 x 8 bytes) inline
-___
-
-# Generate extract code for SHAKE256 rate (136 bytes = 17 ymm registers)
-for (my $i = 0; $i < 17; $i++) {
-    my $offset = $i * 8;
-    $code.=<<___;
-        vextracti64x2 \$1, %ymm$i, %xmm31
-        vmovq       %xmm$i, $offset($arg1,%rbp)
-        vpextrq     \$1, %xmm$i, $offset($arg2,%rbp)
-        vmovq       %xmm31, $offset($arg3,%rbp)
-        vpextrq     \$1, %xmm31, $offset($arg4,%rbp)
-___
-}
-
-$code.=<<___;
-    add     \$136, %rbp  # dst offset += SHAKE256_RATE
-    sub     \$136, $arg5 # outlen -= SHAKE256_RATE
-    jmp     .Lshake256_squeeze_loop
-
-.align  32
-.Lshake256_squeeze_final_extract:
-    or      $arg5, $arg5
-    jz      .Lshake256_squeeze_no_end_permute
-
-    # update output pointers
-    add     %rbp, $arg1
-    add     %rbp, $arg2
-    add     %rbp, $arg3
-    add     %rbp, $arg4
-
-    mov     \$136, %r15d       # SHAKE256_RATE
-    sub     $arg5, %r15
-    mov     %r15, 8*100($arg6) # s[100] = capacity
-
-    call    keccak_1600_permute
-
-    mov     $arg1, %r14
-    mov     $arg6, $arg1
-    call    keccak_1600_save_state_x4
-
-    mov     %r14, $arg1
-
-    # extract bytes: r10 - state/src, arg1-arg4 - output/dst, r12 - length, r11 - offset = 0
-    mov     $arg6, %r10
-    mov     $arg5, %r12
-    xor     %r11, %r11
-    call    keccak_1600_extract_bytes_x4
-
-    jmp     .Lshake256_squeeze_done
-
-.Lshake256_squeeze_no_end_permute:
-    movq    \$0, 8*100($arg6) # s[100] = 0
-    mov     $arg6, $arg1
-    call    keccak_1600_save_state_x4
-
-.Lshake256_squeeze_done:
-    # Clear sensitive registers
-    vpxorq      %xmm16, %xmm16, %xmm16
-    vmovdqa64   %ymm16, %ymm17
-    vmovdqa64   %ymm16, %ymm18
-    vmovdqa64   %ymm16, %ymm19
-    vmovdqa64   %ymm16, %ymm20
-    vmovdqa64   %ymm16, %ymm21
-    vmovdqa64   %ymm16, %ymm22
-    vmovdqa64   %ymm16, %ymm23
-    vmovdqa64   %ymm16, %ymm24
-    vmovdqa64   %ymm16, %ymm25
-    vmovdqa64   %ymm16, %ymm26
-    vmovdqa64   %ymm16, %ymm27
-    vmovdqa64   %ymm16, %ymm28
-    vmovdqa64   %ymm16, %ymm29
-    vmovdqa64   %ymm16, %ymm30
-    vmovdqa64   %ymm16, %ymm31
-.Lshake256_squeeze_epilogue:
-    vzeroall
-___
-$code .= <<___ if ($win64);
-    vmovups 0(%rsp),   %xmm6
-    vmovups 16(%rsp),  %xmm7
-    vmovups 32(%rsp),  %xmm8
-    vmovups 48(%rsp),  %xmm9
-    vmovups 64(%rsp),  %xmm10
-    vmovups 80(%rsp),  %xmm11
-    vmovups 96(%rsp),  %xmm12
-    vmovups 112(%rsp), %xmm13
-    vmovups 128(%rsp), %xmm14
-    vmovups 144(%rsp), %xmm15
-    add     \$160, %rsp
-___
-$code.=<<___;
-
-    pop %r15
-.cfi_pop    %r15
-    pop %r14
-.cfi_pop    %r14
-    pop %r13
-.cfi_pop    %r13
-    pop %r12
-.cfi_pop    %r12
-    pop %rbx
-.cfi_pop    %rbx
-    pop %rbp
-.cfi_pop    %rbp
-    ret
-.cfi_endproc
-.size   SHA3_shake256_x4_inc_squeeze_avx512vl,.-SHA3_shake256_x4_inc_squeeze_avx512vl
-___
-
-if ($win64) {
-my $context = "%r8";
-my $disp    = "%r9";
-
-$code.=<<___;
-.extern __imp_RtlVirtualUnwind
-.type   keccak_se_handler,\@abi-omnipotent
-.align  16
-keccak_se_handler:
-    push    %rsi
-    push    %rdi
-    push    %rbx
-    push    %rbp
-    push    %r12
-    push    %r13
-    push    %r14
-    push    %r15
-    pushfq
-    sub     \$64, %rsp
-
-    mov     120($context), %rax # context->Rax = original %rsp from xlate prologue
-    mov     248($context), %rbx # context->Rip
-
-    mov     8($disp), %rsi  # disp->ImageBase
-    mov     56($disp), %r11 # disp->HandlerData
-
-    mov     0(%r11), %r10d # HandlerData[0]: body label (rva)
-    lea     (%rsi,%r10), %r10
-    cmp     %r10, %rbx     # Rip < body?
-    jb      .Lkeccak_in_prologue
-
-    mov     4(%r11), %r10d # HandlerData[1]: epilogue label (rva)
-    lea     (%rsi,%r10), %r10
-    cmp     %r10, %rbx     # Rip >= epilogue?
-    jae     .Lkeccak_in_epilogue
-
-    # In function body:
-    # HandlerData[2]: delta from context->Rsp(body) to original %rsp
-    # HandlerData[3]: offset of XMM6 save area from context->Rsp(body), -1 if none
-    # HandlerData[4]: number of saved non-volatiles in stack frame layout (2 or 6)
-    # HandlerData[5]: delta from context->Rsp(epilogue) to original %rsp
-    mov     152($context), %rdx # body rsp
-    mov     8(%r11), %r10d
-    lea     (%rdx,%r10), %rax   # original rsp
-    jmp     .Lkeccak_restore_body_or_epilogue
-
-.Lkeccak_in_epilogue:
-    mov     152($context), %rdx # epilogue rsp
-    mov     20(%r11), %r10d
-    lea     (%rdx,%r10), %rax   # original rsp
-
-.Lkeccak_restore_body_or_epilogue:
-    mov     8(%rax), %rcx       # xlate shadow save of original rdi
-    mov     16(%rax), %rsi      # xlate shadow save of original rsi
-    mov     %rax, 152($context) # context->Rsp = original rsp
-    mov     %rsi, 168($context) # context->Rsi
-    mov     %rcx, 176($context) # context->Rdi
-
-    mov     16(%r11), %r10d # gpr save count
-    cmp     \$6, %r10d
-    jne     .Lkeccak_restore_two
-
-    mov     -24(%rax), %r12
-    mov     -32(%rax), %r13
-    mov     -40(%rax), %r14
-    mov     -48(%rax), %r15
-    mov     %r12, 216($context) # context->R12
-    mov     %r13, 224($context) # context->R13
-    mov     %r14, 232($context) # context->R14
-    mov     %r15, 240($context) # context->R15
-
-.Lkeccak_restore_two:
-    mov     -8(%rax), %rbp
-    mov     -16(%rax), %rbx
-    mov     %rbp, 160($context) # context->Rbp
-    mov     %rbx, 144($context) # context->Rbx
-
-    mov     12(%r11), %r10d # xmm save offset from body rsp
-    cmp     \$-1, %r10d
-    je      .Lkeccak_in_prologue
-
-    lea     (%rdx,%r10), %rsi   # source = xmm save area
-    lea     512($context), %rdi # &context->Xmm6
-    mov     \$20, %ecx          # 10 XMM * 2 qwords
-    .long   0xa548f3fc          # cld; rep movsq
-
-.Lkeccak_in_prologue:
-    mov     8(%rax), %rcx
-    mov     16(%rax), %rdx
-    mov     %rcx, 176($context) # context->Rdi
-    mov     %rdx, 168($context) # context->Rsi
-    mov     %rax, 152($context) # context->Rsp = original rsp
-
-    mov     40($disp), %rdi # disp->ContextRecord
-    mov     $context, %rsi
-    mov     \$154, %ecx     # sizeof(CONTEXT)/8
-    .long   0xa548f3fc      # cld; rep movsq
-
-    mov     $disp, %rsi
-    xor     %rcx, %rcx     # UNW_FLAG_NHANDLER
-    mov     8(%rsi), %rdx  # disp->ImageBase
-    mov     0(%rsi), %r8   # disp->ControlPc
-    mov     16(%rsi), %r9  # disp->FunctionEntry
-    mov     40(%rsi), %r10 # disp->ContextRecord
-    lea     56(%rsi), %r11 # &disp->HandlerData
-    lea     24(%rsi), %r12 # &disp->EstablisherFrame
-    mov     %r10, 32(%rsp)
-    mov     %r11, 40(%rsp)
-    mov     %r12, 48(%rsp)
-    mov     %rcx, 56(%rsp)
-    call    *__imp_RtlVirtualUnwind(%rip)
-
-    mov     \$1, %eax # ExceptionContinueSearch
-    add     \$64, %rsp
-    popfq
-    pop     %r15
-    pop     %r14
-    pop     %r13
-    pop     %r12
-    pop     %rbp
-    pop     %rbx
-    pop     %rdi
-    pop     %rsi
-    ret
-.size   keccak_se_handler,.-keccak_se_handler
-
-.section    .pdata
-.align  4
-    .rva    .LSEH_begin_SHA3_shake128_x4_avx512vl
-    .rva    .LSEH_end_SHA3_shake128_x4_avx512vl
-    .rva    .LSEH_info_SHA3_shake128_x4_avx512vl
-    .rva    .LSEH_begin_SHA3_shake128_x4_inc_absorb_avx512vl_internal
-    .rva    .LSEH_end_SHA3_shake128_x4_inc_absorb_avx512vl_internal
-    .rva    .LSEH_info_SHA3_shake128_x4_inc_absorb_avx512vl_internal
-    .rva    .LSEH_begin_SHA3_shake128_x4_inc_absorb_avx512vl
-    .rva    .LSEH_end_SHA3_shake128_x4_inc_absorb_avx512vl
-    .rva    .LSEH_info_SHA3_shake128_x4_inc_absorb_avx512vl
-    .rva    .LSEH_begin_SHA3_shake128_x4_inc_squeeze_avx512vl_internal
-    .rva    .LSEH_end_SHA3_shake128_x4_inc_squeeze_avx512vl_internal
-    .rva    .LSEH_info_SHA3_shake128_x4_inc_squeeze_avx512vl_internal
-    .rva    .LSEH_begin_SHA3_shake128_x4_inc_squeeze_avx512vl
-    .rva    .LSEH_end_SHA3_shake128_x4_inc_squeeze_avx512vl
-    .rva    .LSEH_info_SHA3_shake128_x4_inc_squeeze_avx512vl
-    .rva    .LSEH_begin_SHA3_shake256_x4_avx512vl
-    .rva    .LSEH_end_SHA3_shake256_x4_avx512vl
-    .rva    .LSEH_info_SHA3_shake256_x4_avx512vl
-    .rva    .LSEH_begin_SHA3_shake256_x4_inc_absorb_avx512vl_internal
-    .rva    .LSEH_end_SHA3_shake256_x4_inc_absorb_avx512vl_internal
-    .rva    .LSEH_info_SHA3_shake256_x4_inc_absorb_avx512vl_internal
-    .rva    .LSEH_begin_SHA3_shake256_x4_inc_absorb_avx512vl
-    .rva    .LSEH_end_SHA3_shake256_x4_inc_absorb_avx512vl
-    .rva    .LSEH_info_SHA3_shake256_x4_inc_absorb_avx512vl
-    .rva    .LSEH_begin_SHA3_shake256_x4_inc_squeeze_avx512vl_internal
-    .rva    .LSEH_end_SHA3_shake256_x4_inc_squeeze_avx512vl_internal
-    .rva    .LSEH_info_SHA3_shake256_x4_inc_squeeze_avx512vl_internal
-    .rva    .LSEH_begin_SHA3_shake256_x4_inc_squeeze_avx512vl
-    .rva    .LSEH_end_SHA3_shake256_x4_inc_squeeze_avx512vl
-    .rva    .LSEH_info_SHA3_shake256_x4_inc_squeeze_avx512vl
-
-.section    .xdata
-.align  8
-.LSEH_info_SHA3_shake128_x4_avx512vl:
-    .byte   9,0,0,0
-    .rva    keccak_se_handler
-    .rva    .Lshake128_x4_body,.Lshake128_x4_epilogue
-    .long   1032,856,2,1032
-.LSEH_info_SHA3_shake128_x4_inc_absorb_avx512vl:
-    .byte   9,0,0,0
-    .rva    keccak_se_handler
-    .rva    .Lshake128_absorb_body,.Lshake128_absorb_epilogue
-    .long   208,0,6,208
-.LSEH_info_SHA3_shake128_x4_inc_absorb_avx512vl_internal:
-    .byte   9,0,0,0
-    .rva    keccak_se_handler
-    .rva    .Lshake128_absorb_body,.Lshake128_absorb_epilogue
-    .long   208,0,6,208
-.LSEH_info_SHA3_shake128_x4_inc_squeeze_avx512vl:
-    .byte   9,0,0,0
-    .rva    keccak_se_handler
-    .rva    .Lshake128_squeeze_body,.Lshake128_squeeze_epilogue
-    .long   208,0,6,208
-.LSEH_info_SHA3_shake128_x4_inc_squeeze_avx512vl_internal:
-    .byte   9,0,0,0
-    .rva    keccak_se_handler
-    .rva    .Lshake128_squeeze_body,.Lshake128_squeeze_epilogue
-    .long   208,0,6,208
-.LSEH_info_SHA3_shake256_x4_avx512vl:
-    .byte   9,0,0,0
-    .rva    keccak_se_handler
-    .rva    .Lshake256_x4_body,.Lshake256_x4_epilogue
-    .long   1032,856,2,1032
-.LSEH_info_SHA3_shake256_x4_inc_absorb_avx512vl:
-    .byte   9,0,0,0
-    .rva    keccak_se_handler
-    .rva    .Lshake256_absorb_body,.Lshake256_absorb_epilogue
-    .long   208,0,6,208
-.LSEH_info_SHA3_shake256_x4_inc_absorb_avx512vl_internal:
-    .byte   9,0,0,0
-    .rva    keccak_se_handler
-    .rva    .Lshake256_absorb_body,.Lshake256_absorb_epilogue
-    .long   208,0,6,208
-.LSEH_info_SHA3_shake256_x4_inc_squeeze_avx512vl:
-    .byte   9,0,0,0
-    .rva    keccak_se_handler
-    .rva    .Lshake256_squeeze_body,.Lshake256_squeeze_epilogue
-    .long   208,0,6,208
-.LSEH_info_SHA3_shake256_x4_inc_squeeze_avx512vl_internal:
-    .byte   9,0,0,0
-    .rva    keccak_se_handler
-    .rva    .Lshake256_squeeze_body,.Lshake256_squeeze_epilogue
-    .long   208,0,6,208
-___
-}
-
-$code.=<<___;
-
-.section .rodata align=128
-.align  128
-.type   iotas,\@object
-iotas:
-    .quad   0x0000000000000001
-    .quad   0x0000000000008082
-    .quad   0x800000000000808a
-    .quad   0x8000000080008000
-    .quad   0x000000000000808b
-    .quad   0x0000000080000001
-    .quad   0x8000000080008081
-    .quad   0x8000000000008009
-    .quad   0x000000000000008a
-    .quad   0x0000000000000088
-    .quad   0x0000000080008009
-    .quad   0x000000008000000a
-    .quad   0x000000008000808b
-    .quad   0x800000000000008b
-    .quad   0x8000000000008089
-    .quad   0x8000000000008003
-    .quad   0x8000000000008002
-    .quad   0x8000000000000080
-    .quad   0x000000000000800a
-    .quad   0x800000008000000a
-    .quad   0x8000000080008081
-    .quad   0x8000000000008080
-    .quad   0x0000000080000001
-    .quad   0x8000000080008008
-.size   iotas,.-iotas
-
-.align  8
-byte_kmask_0_to_7:
-    .byte   0x00, 0x01, 0x03, 0x07, 0x0f, 0x1f, 0x3f, 0x7f
-
-.align  32
-shake_terminator_byte_x4:
-    .byte   0, 0, 0, 0, 0, 0, 0, 0x80
-    .byte   0, 0, 0, 0, 0, 0, 0, 0x80
-    .byte   0, 0, 0, 0, 0, 0, 0, 0x80
-    .byte   0, 0, 0, 0, 0, 0, 0, 0x80
-
-.align  8
-    .byte   0, 0, 0, 0, 0, 0, 0, 0
-shake_msg_pad_x4:
-    .byte   0x1F, 0, 0, 0, 0, 0, 0, 0
-    .byte   0x1F, 0, 0, 0, 0, 0, 0, 0
-    .byte   0x1F, 0, 0, 0, 0, 0, 0, 0
-    .byte   0x1F, 0, 0, 0, 0, 0, 0, 0
-
-.asciz  "Keccak-1600 absorb and squeeze for AVX512VL, CRYPTOGAMS by "
-___
-
-}}} else {{{
-
-# When AVX512VL is not available, output stub functions
-# The capable function returns 0, and the operation functions are not defined (will use C fallback)
-
-$code .= <<___;
-.text
-
-.globl  SHA3_avx512vl_capable
-.type   SHA3_avx512vl_capable,\@abi-omnipotent
-SHA3_avx512vl_capable:
-    xor     %eax, %eax
-    ret
-.size   SHA3_avx512vl_capable, .-SHA3_avx512vl_capable
-
-.globl  SHA3_shake128_x4_inc_absorb_avx512vl
-.globl  SHA3_shake256_x4_inc_absorb_avx512vl
-.globl  SHA3_shake128_x4_inc_finalize_avx512vl
-.globl  SHA3_shake256_x4_inc_finalize_avx512vl
-.globl  SHA3_shake128_x4_inc_squeeze_avx512vl
-.globl  SHA3_shake256_x4_inc_squeeze_avx512vl
-.globl  SHA3_shake128_x4_avx512vl
-.globl  SHA3_shake256_x4_avx512vl
-.type   SHA3_shake128_x4_inc_absorb_avx512vl,\@abi-omnipotent
-SHA3_shake128_x4_inc_absorb_avx512vl:
-SHA3_shake256_x4_inc_absorb_avx512vl:
-SHA3_shake128_x4_inc_finalize_avx512vl:
-SHA3_shake256_x4_inc_finalize_avx512vl:
-SHA3_shake128_x4_inc_squeeze_avx512vl:
-SHA3_shake256_x4_inc_squeeze_avx512vl:
-SHA3_shake128_x4_avx512vl:
-SHA3_shake256_x4_avx512vl:
-    .byte   0x0f,0x0b # ud2
-    ret
-.size   SHA3_shake128_x4_inc_absorb_avx512vl, .-SHA3_shake128_x4_inc_absorb_avx512vl
-___
-}}}
-
-print $code;
-close STDOUT or die "error closing STDOUT: $!";
diff --git a/crypto/sha/asm/sha1-586.pl b/crypto/sha/asm/sha1-586.pl
index 277c33ea7f..d98be771b0 100644
--- a/crypto/sha/asm/sha1-586.pl
+++ b/crypto/sha/asm/sha1-586.pl
@@ -146,9 +146,6 @@ $ymm=1 if ($xmm && !$ymm && $ARGV[0] eq "win32" &&
 $ymm=1 if ($xmm && !$ymm && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|based on LLVM) ([0-9]+\.[0-9]+)/ &&
 		$2>=3.0);	# first version supporting AVX
 
-$ymm=1 if ($xmm && !$ymm && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__` =~ /#define __clang_major__.([0-9]+)/ &&
-		$1>=11); #icx started with clang 11
-
 $shaext=$xmm;	### set to zero if compiling for 1.0.1
 
 &external_label("OPENSSL_ia32cap_P") if ($xmm);
diff --git a/crypto/sha/asm/sha1-armv4-large.pl b/crypto/sha/asm/sha1-armv4-large.pl
index 38f5ae988d..7ef7bd6e91 100644
--- a/crypto/sha/asm/sha1-armv4-large.pl
+++ b/crypto/sha/asm/sha1-armv4-large.pl
@@ -187,7 +187,7 @@ ___
 }
 
 $code=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 
 #if defined(__thumb2__)
 .syntax	unified
diff --git a/crypto/sha/asm/sha1-armv8.pl b/crypto/sha/asm/sha1-armv8.pl
index 4eeec6b0b2..1c1920f702 100644
--- a/crypto/sha/asm/sha1-armv8.pl
+++ b/crypto/sha/asm/sha1-armv8.pl
@@ -175,7 +175,7 @@ ___
 }
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 #ifndef	__KERNEL__
 .extern OPENSSL_armcap_P
 .hidden OPENSSL_armcap_P
diff --git a/crypto/sha/asm/sha1-mb-x86_64.pl b/crypto/sha/asm/sha1-mb-x86_64.pl
index 5a8c0755e1..8edb96d2f7 100644
--- a/crypto/sha/asm/sha1-mb-x86_64.pl
+++ b/crypto/sha/asm/sha1-mb-x86_64.pl
@@ -76,13 +76,6 @@ if (!$avx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([0
 	$avx = ($2>=3.0) + ($2>3.0);
 }
 
-if (!$avx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$avx = ($1>=11); #icx started with clang 11
-	}
-}
-
 open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\""
     or die "can't call $xlate: $!";
 *STDOUT=*OUT;
diff --git a/crypto/sha/asm/sha1-mips.pl b/crypto/sha/asm/sha1-mips.pl
index c60791b175..870a05a109 100644
--- a/crypto/sha/asm/sha1-mips.pl
+++ b/crypto/sha/asm/sha1-mips.pl
@@ -343,7 +343,7 @@ $FRAMESIZE=16;	# large enough to accommodate NUBI saved registers
 $SAVED_REGS_MASK = ($flavour =~ /nubi/i) ? "0xc0fff008" : "0xc0ff0000";
 
 $code=<<___;
-#include "arch/mips_arch.h"
+#include "mips_arch.h"
 
 .text
 
diff --git a/crypto/sha/asm/sha1-s390x.pl b/crypto/sha/asm/sha1-s390x.pl
index 448b4a8848..6762932a87 100644
--- a/crypto/sha/asm/sha1-s390x.pl
+++ b/crypto/sha/asm/sha1-s390x.pl
@@ -162,7 +162,7 @@ ___
 }
 
 $code.=<<___;
-#include "arch/s390x_arch.h"
+#include "s390x_arch.h"
 
 .text
 .align	64
diff --git a/crypto/sha/asm/sha1-sparcv9.pl b/crypto/sha/asm/sha1-sparcv9.pl
index 24ee48222a..a95d5717ee 100644
--- a/crypto/sha/asm/sha1-sparcv9.pl
+++ b/crypto/sha/asm/sha1-sparcv9.pl
@@ -190,7 +190,7 @@ $code.=<<___;
 #ifndef __ASSEMBLER__
 # define __ASSEMBLER__ 1
 #endif
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 #ifdef __arch64__
 .register	%g2,#scratch
diff --git a/crypto/sha/asm/sha1-x86_64.pl b/crypto/sha/asm/sha1-x86_64.pl
index af9d172153..5b9eb8f96f 100755
--- a/crypto/sha/asm/sha1-x86_64.pl
+++ b/crypto/sha/asm/sha1-x86_64.pl
@@ -124,13 +124,6 @@ if (!$avx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([0
 	$avx = ($2>=3.0) + ($2>3.0);
 }
 
-if (!$avx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$avx = ($1>=11); #icx started with clang 11
-	}
-}
-
 $shaext=1;	### set to zero if compiling for 1.0.1
 $avx=1		if (!$shaext && $avx);
 
diff --git a/crypto/sha/asm/sha256-586.pl b/crypto/sha/asm/sha256-586.pl
index 68a9fa9e64..97a7bccba9 100644
--- a/crypto/sha/asm/sha256-586.pl
+++ b/crypto/sha/asm/sha256-586.pl
@@ -99,13 +99,6 @@ if ($xmm && !$avx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|based on LLV
 	$avx = ($2>=3.0) + ($2>3.0);
 }
 
-if ($xmm && !$avx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$avx = ($1>=11); #icx started with clang 11
-	}
-}
-
 $shaext=$xmm;	### set to zero if compiling for 1.0.1
 
 $unroll_after = 64*4;	# If pre-evicted from L1P cache first spin of
diff --git a/crypto/sha/asm/sha256-armv4.pl b/crypto/sha/asm/sha256-armv4.pl
index 1bcf7cea4f..ba05676f14 100644
--- a/crypto/sha/asm/sha256-armv4.pl
+++ b/crypto/sha/asm/sha256-armv4.pl
@@ -177,7 +177,7 @@ ___
 
 $code=<<___;
 #ifndef __KERNEL__
-# include "arch/arm_arch.h"
+# include "arm_arch.h"
 #else
 # define __ARM_ARCH__ __LINUX_ARM_ARCH__
 # define __ARM_MAX_ARCH__ 7
diff --git a/crypto/sha/asm/sha256-loongarch64.pl b/crypto/sha/asm/sha256-loongarch64.pl
index 3cba5ba258..d23205521b 100644
--- a/crypto/sha/asm/sha256-loongarch64.pl
+++ b/crypto/sha/asm/sha256-loongarch64.pl
@@ -42,9 +42,6 @@ use warnings;
 my $output = $#ARGV >= 0 && $ARGV[$#ARGV] =~ m|\.\w+$| ? pop : undef;
 my $flavour = $#ARGV >= 0 && $ARGV[0] !~ m|\.| ? shift : undef;
 
-my $use_lsx = $flavour && $flavour =~ /lsx/i ? 1 : 0;
-my $isaext = "_" . ( $use_lsx ? "lsx" : "la64v100" );
-
 $output and open STDOUT,">$output";
 
 my $code=<<___;
@@ -54,132 +51,32 @@ ___
 my $K256 = "K256";
 
 # Function arguments
-my ($zero,$ra,$tp,$sp,$fp)=("\$zero", "\$ra", "\$tp", "\$sp", "\$fp");
-my ($a0,$a1,$a2,$a3,$a4,$a5,$a6,$a7)=map("\$a$_",(0..7));
-my ($t0,$t1,$t2,$t3,$t4,$t5,$t6,$t7,$t8)=map("\$t$_",(0..8));
-my ($s0,$s1,$s2,$s3,$s4,$s5,$s6,$s7,$s8)=map("\$s$_",(0..8));
-my ($va0, $va1, $va2, $va3, $va4, $va5, $va6, $va7) = map("\$vr$_",(0..7));
-my ($vt0, $vt1, $vt2, $vt3, $vt4, $vt5, $vt6, $vt7) = map("\$vr$_",(8..15));
+my ($zero,$ra,$tp,$sp,$fp)=map("\$r$_",(0..3,22));
+my ($a0,$a1,$a2,$a3,$a4,$a5,$a6,$a7)=map("\$r$_",(4..11));
+my ($t0,$t1,$t2,$t3,$t4,$t5,$t6,$t7,$t8,$x)=map("\$r$_",(12..21));
+my ($s0,$s1,$s2,$s3,$s4,$s5,$s6,$s7,$s8)=map("\$r$_",(23..31));
 
 my ($INP, $LEN, $ADDR) = ($a1, $a2, $sp);
 my ($KT, $T1, $T2, $T3, $T4, $T5, $T6) = ($t0, $t1, $t2, $t3, $t4, $t5, $t6);
-my ($A, $B, $C, $D, $E, $F, $G, $H) = ($s0, $s1, $s2, $s3, $s4, $s5, $s6, $s7);
-my @VMSGS = ($va0, $va1, $va2, $va3, $va4, $va5, $va6, $va7);
-
-sub strip {
-    my ($str) = @_;
-    $str =~ s/^\s+|\s+$//g;
-    return $str;
-}
-
-sub MSGSCHEDULE0_lsx {
-    my ($index) = @_;
-    my $msg = $VMSGS[$index / 2];
-    my $msg2 = $VMSGS[$index / 2 + 1];
-    my ($tmp0, $tmp1) = ($vt0, $vt1);
-    my $code;
-
-    if ($index % 4 == 0) {
-        $code = <<___;
-    vld $tmp0, $INP, @{[4*$index]}
-    vshuf4i.b $tmp0, $tmp0, 0b00011011  # 0123
-    vldi $msg2, 0
-    vilvl.w $msg, $msg2, $tmp0  # 0_1_
-    vilvh.w $msg2, $msg2, $tmp0  # 2_3_
-___
-    }
-
-    $code .= <<___;
-    vpickve2gr.w $T1, $msg, @{[($index%2)*2]}
-___
-
-    return strip($code);
-}
+my ($A, $B, $C, $D ,$E ,$F ,$G ,$H) = ($s0, $s1, $s2, $s3, $s4, $s5, $s6, $s7);
 
 sub MSGSCHEDULE0 {
     my ($index) = @_;
-
-    if ($use_lsx) {
-        return MSGSCHEDULE0_lsx($index);
-    }
-
     my $code=<<___;
-    ld.w $T1, $INP, @{[4*$index]}
+    ld.w $T1, $INP, 4*$index
     revb.2w $T1, $T1
-    st.w $T1, $ADDR, @{[4*$index]}
+    st.w $T1, $ADDR, 4*$index
 ___
-
-    return strip($code);
-}
-
-sub MSGSCHEDULE1_lsx {
-    my ($index) = @_;
-    my $msgidx = ($index / 2) % 8;
-    my $m01 = $VMSGS[$msgidx];
-    my $m23 = $VMSGS[($msgidx + 1) % 8];
-    my $m45 = $VMSGS[($msgidx + 2) % 8];
-    my $m67 = $VMSGS[($msgidx + 3) % 8];
-    my $m89 = $VMSGS[($msgidx + 4) % 8];
-    my $mab = $VMSGS[($msgidx + 5) % 8];
-    my $mcd = $VMSGS[($msgidx + 6) % 8];
-    my $mef = $VMSGS[($msgidx + 7) % 8];
-    my ($m12, $tmp0, $tmp1) = ($vt0, $vt1, $vt2);
-    my $code;
-
-    if ($index % 2 == 0) {
-        # re-align to get $m12 and "$m9a" ($tmp0)
-        # $m01 += $m9a
-        $code = <<___;
-    # m01 & new = $m01, m23 = $m23, m45 = $m45, m67 = $m67
-    # m89 = $m89, mab = $mab, mcd = $mcd, mef = $mef
-    vbsrl.v $m12, $m01, 8  # 1___
-    vextrins.w $m12, $m23, 0b00100000  # 1_2_
-    vbsrl.v $tmp0, $m89, 8  # 9___
-    vextrins.w $tmp0, $mab, 0b00100000  # 9_a_
-    vadd.w $m01, $m01, $tmp0
-___
-
-        # $m01 += sigma0($m12)
-        $code .= <<___;
-    vrotri.w $tmp0, $m12, 7
-    vrotri.w $tmp1, $m12, 18
-    vsrli.w $m12, $m12, 3
-    vxor.v $tmp0, $tmp0, $tmp1
-    vxor.v $m12, $m12, $tmp0
-    vadd.w $m01, $m01, $m12
-___
-
-        # $m01 += sigma1($mef)
-        # now m1234 can be re-used as temporary
-        $code .= <<___;
-    vrotri.w $tmp0, $mef, 17
-    vrotri.w $tmp1, $mef, 19
-    vsrli.w $m12, $mef, 10
-    vxor.v $tmp0, $tmp0, $tmp1
-    vxor.v $m12, $m12, $tmp0
-    vadd.w $m01, $m01, $m12
-___
-    }
-
-    $code .= <<___;
-    vpickve2gr.w $T1, $m01, @{[($index%2)*2]}
-___
-
-    return strip($code);
+    return $code;
 }
 
 sub MSGSCHEDULE1 {
     my ($index) = @_;
-
-    if ($use_lsx) {
-        return MSGSCHEDULE1_lsx($index);
-    }
-
     my $code=<<___;
-    ld.w $T1, $ADDR, @{[(($index-2)&0x0f)*4]}
-    ld.w $T2, $ADDR, @{[(($index-15)&0x0f)*4]}
-    ld.w $T3, $ADDR, @{[(($index-7)&0x0f)*4]}
-    ld.w $T4, $ADDR, @{[($index&0x0f)*4]}
+    ld.w $T1, $ADDR, (($index-2)&0x0f)*4
+    ld.w $T2, $ADDR, (($index-15)&0x0f)*4
+    ld.w $T3, $ADDR, (($index-7)&0x0f)*4
+    ld.w $T4, $ADDR, ($index&0x0f)*4
     rotri.w $T5, $T1, 17
     rotri.w $T6, $T1, 19
     srli.w $T1, $T1, 10
@@ -193,15 +90,15 @@ sub MSGSCHEDULE1 {
     xor $T2, $T2, $T6
     add.w $T1, $T1, $T2
     add.w $T1, $T1, $T4
-    st.w $T1, $ADDR, @{[($index&0x0f)*4]}
+    st.w $T1, $ADDR, ($index&0x0f)*4
 ___
-    return strip($code);
+    return $code;
 }
 
 sub sha256_T1 {
     my ($index, $e, $f, $g, $h) = @_;
     my $code=<<___;
-    ld.w $T4, $KT, @{[4*$index]}
+    ld.w $T4, $KT, 4*$index
     add.w $h, $h, $T1
     add.w $h, $h, $T4
     rotri.w $T2, $e, 6
@@ -215,7 +112,7 @@ sub sha256_T1 {
     xor $T1, $T1, $g
     add.w $T1, $T1, $h
 ___
-    return strip($code);
+    return $code;
 }
 
 sub sha256_T2 {
@@ -232,29 +129,45 @@ sub sha256_T2 {
     xor $T4, $T4, $T3
     add.w $T2, $T2, $T4
 ___
-    return strip($code);
+    return $code;
 }
 
 sub SHA256ROUND {
     my ($index, $a, $b, $c, $d, $e, $f, $g, $h) = @_;
-    my $ms = $index < 16 ? \&MSGSCHEDULE0 : \&MSGSCHEDULE1;
     my $code=<<___;
-    @{[$ms->($index)]}
     @{[sha256_T1 $index, $e, $f, $g, $h]}
     @{[sha256_T2 $a, $b, $c]}
     add.w $d, $d, $T1
     add.w $h, $T2, $T1
 ___
-    return strip($code);
+    return $code;
+}
+
+sub SHA256ROUND0 {
+    my ($index, $a, $b, $c, $d, $e, $f, $g, $h) = @_;
+    my $code=<<___;
+    @{[MSGSCHEDULE0 $index]}
+    @{[SHA256ROUND $index, $a, $b, $c, $d, $e, $f, $g, $h]}
+___
+    return $code;
+}
+
+sub SHA256ROUND1 {
+    my ($index, $a, $b, $c, $d, $e, $f, $g, $h) = @_;
+    my $code=<<___;
+    @{[MSGSCHEDULE1 $index]}
+    @{[SHA256ROUND $index, $a, $b, $c, $d, $e, $f, $g, $h]}
+___
+    return $code;
 }
 
 ################################################################################
-# void sha256_block_data_order$isaext(void *c, const void *p, size_t len)
+# void sha256_block_data_order(void *c, const void *p, size_t len)
 $code .= <<___;
 .p2align 3
-.globl sha256_block_data_order@{[$isaext]}
-.type   sha256_block_data_order@{[$isaext]},\@function
-sha256_block_data_order@{[$isaext]}:
+.globl sha256_block_data_order
+.type   sha256_block_data_order,\@function
+sha256_block_data_order:
 
     addi.d $sp, $sp, -80
 
@@ -268,17 +181,9 @@ sha256_block_data_order@{[$isaext]}:
     st.d $s7, $sp, 56
     st.d $s8, $sp, 64
     st.d $fp, $sp, 72
-___
 
-# SHA256 LSX needs neither dedicated shuffle control word, nor stack space for
-# internal states
-if (!$use_lsx) {
-    $code .= <<___;
     addi.d $sp, $sp, -64
-___
-}
 
-$code .= <<___;
     la $KT, $K256
 
     # load ctx
@@ -294,22 +199,87 @@ $code .= <<___;
 L_round_loop:
     # Decrement length by 1
     addi.d $LEN, $LEN, -1
-___
 
-for (my $i = 0; $i < 64; $i += 8) {
-    $code .= <<___;
-    @{[SHA256ROUND $i, $A, $B, $C, $D, $E, $F, $G, $H]}
-    @{[SHA256ROUND $i+1, $H, $A, $B, $C, $D, $E, $F, $G]}
-    @{[SHA256ROUND $i+2, $G, $H, $A, $B, $C, $D, $E, $F]}
-    @{[SHA256ROUND $i+3, $F, $G, $H, $A, $B, $C, $D, $E]}
-    @{[SHA256ROUND $i+4, $E, $F, $G, $H, $A, $B, $C, $D]}
-    @{[SHA256ROUND $i+5, $D, $E, $F, $G, $H, $A, $B, $C]}
-    @{[SHA256ROUND $i+6, $C, $D, $E, $F, $G, $H, $A, $B]}
-    @{[SHA256ROUND $i+7, $B, $C, $D, $E, $F, $G, $H, $A]}
-___
-}
+    @{[SHA256ROUND0 0, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA256ROUND0 1, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA256ROUND0 2, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA256ROUND0 3, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA256ROUND0 4, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA256ROUND0 5, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA256ROUND0 6, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA256ROUND0 7, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA256ROUND0 8, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA256ROUND0 9, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA256ROUND0 10, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA256ROUND0 11, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA256ROUND0 12, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA256ROUND0 13, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA256ROUND0 14, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA256ROUND0 15, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA256ROUND1 16, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA256ROUND1 17, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA256ROUND1 18, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA256ROUND1 19, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA256ROUND1 20, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA256ROUND1 21, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA256ROUND1 22, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA256ROUND1 23, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA256ROUND1 24, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA256ROUND1 25, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA256ROUND1 26, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA256ROUND1 27, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA256ROUND1 28, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA256ROUND1 29, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA256ROUND1 30, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA256ROUND1 31, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA256ROUND1 32, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA256ROUND1 33, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA256ROUND1 34, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA256ROUND1 35, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA256ROUND1 36, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA256ROUND1 37, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA256ROUND1 38, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA256ROUND1 39, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA256ROUND1 40, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA256ROUND1 41, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA256ROUND1 42, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA256ROUND1 43, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA256ROUND1 44, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA256ROUND1 45, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA256ROUND1 46, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA256ROUND1 47, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA256ROUND1 48, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA256ROUND1 49, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA256ROUND1 50, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA256ROUND1 51, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA256ROUND1 52, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA256ROUND1 53, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA256ROUND1 54, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA256ROUND1 55, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA256ROUND1 56, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA256ROUND1 57, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA256ROUND1 58, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA256ROUND1 59, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA256ROUND1 60, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA256ROUND1 61, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA256ROUND1 62, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA256ROUND1 63, $B, $C, $D, $E, $F, $G, $H, $A]}
 
-$code .= <<___;
     ld.w $T1, $a0, 0
     ld.w $T2, $a0, 4
     ld.w $T3, $a0, 8
@@ -343,15 +313,9 @@ $code .= <<___;
     addi.d $INP, $INP, 64
 
     bnez $LEN, L_round_loop
-___
 
-if (!$use_lsx) {
-    $code .= <<___;
     addi.d $sp, $sp, 64
-___
-}
 
-$code .= <<___;
     ld.d $s0, $sp, 0
     ld.d $s1, $sp, 8
     ld.d $s2, $sp, 16
@@ -366,7 +330,7 @@ $code .= <<___;
     addi.d $sp, $sp, 80
 
     ret
-.size sha256_block_data_order@{[$isaext]},.-sha256_block_data_order@{[$isaext]}
+.size sha256_block_data_order,.-sha256_block_data_order
 
 .section .rodata
 .p2align 3
diff --git a/crypto/sha/asm/sha256-mb-x86_64.pl b/crypto/sha/asm/sha256-mb-x86_64.pl
index 0175f5b36f..3f90402741 100644
--- a/crypto/sha/asm/sha256-mb-x86_64.pl
+++ b/crypto/sha/asm/sha256-mb-x86_64.pl
@@ -77,13 +77,6 @@ if (!$avx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([0
 	$avx = ($2>=3.0) + ($2>3.0);
 }
 
-if (!$avx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$avx = ($1>=11); #icx started with clang 11
-	}
-}
-
 open OUT,"| \"$^X\" \"$xlate\" $flavour \"$output\""
     or die "can't call $xlate: $!";
 *STDOUT=*OUT;
diff --git a/crypto/sha/asm/sha512-armv4.pl b/crypto/sha/asm/sha512-armv4.pl
index 619cb36516..597854b6a6 100644
--- a/crypto/sha/asm/sha512-armv4.pl
+++ b/crypto/sha/asm/sha512-armv4.pl
@@ -203,7 +203,7 @@ my $_word = ($flavour =~ /win/ ? "DCDU" : ".word");
 
 $code=<<___;
 #ifndef __KERNEL__
-# include "arch/arm_arch.h"
+# include "arm_arch.h"
 # define VFP_ABI_PUSH	vstmdb	sp!,{d8-d15}
 # define VFP_ABI_POP	vldmia	sp!,{d8-d15}
 #else
@@ -291,7 +291,6 @@ WORD64(0x5fcb6fab,0x3ad6faec, 0x6c44198c,0x4a475817)
 
 .global	sha512_block_data_order
 .type	sha512_block_data_order,%function
-.align 5
 sha512_block_data_order:
 .Lsha512_block_data_order:
 #if __ARM_ARCH__<7 && !defined(__thumb2__)
diff --git a/crypto/sha/asm/sha512-armv8.pl b/crypto/sha/asm/sha512-armv8.pl
index 66c29a5eef..6fb26e912b 100644
--- a/crypto/sha/asm/sha512-armv8.pl
+++ b/crypto/sha/asm/sha512-armv8.pl
@@ -190,7 +190,7 @@ ___
 }
 
 $code.=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 #ifndef	__KERNEL__
 .extern	OPENSSL_armcap_P
 .hidden	OPENSSL_armcap_P
diff --git a/crypto/sha/asm/sha512-loongarch64.pl b/crypto/sha/asm/sha512-loongarch64.pl
index 44d1736586..4e4b09976e 100644
--- a/crypto/sha/asm/sha512-loongarch64.pl
+++ b/crypto/sha/asm/sha512-loongarch64.pl
@@ -42,9 +42,6 @@ use warnings;
 my $output = $#ARGV >= 0 && $ARGV[$#ARGV] =~ m|\.\w+$| ? pop : undef;
 my $flavour = $#ARGV >= 0 && $ARGV[0] !~ m|\.| ? shift : undef;
 
-my $use_lsx = $flavour && $flavour =~ /lsx/i ? 1 : 0;
-my $isaext = "_" . ( $use_lsx ? "lsx" : "la64v100" );
-
 $output and open STDOUT,">$output";
 
 my $code=<<___;
@@ -54,126 +51,33 @@ ___
 my $K512 = "K512";
 
 # Function arguments
-my ($zero,$ra,$tp,$sp,$fp)=("\$zero", "\$ra", "\$tp", "\$sp", "\$fp");
-my ($a0,$a1,$a2,$a3,$a4,$a5,$a6,$a7)=map("\$a$_",(0..7));
-my ($t0,$t1,$t2,$t3,$t4,$t5,$t6,$t7,$t8)=map("\$t$_",(0..8));
-my ($s0,$s1,$s2,$s3,$s4,$s5,$s6,$s7,$s8)=map("\$s$_",(0..8));
-my ($va0, $va1, $va2, $va3, $va4, $va5, $va6, $va7) = map("\$vr$_",(0..7));
-my ($vt0, $vt1, $vt2, $vt3, $vt4, $vt5, $vt6, $vt7) = map("\$vr$_",(8..15));
+
+my ($zero,$ra,$tp,$sp,$fp)=map("\$r$_",(0..3,22));
+my ($a0,$a1,$a2,$a3,$a4,$a5,$a6,$a7)=map("\$r$_",(4..11));
+my ($t0,$t1,$t2,$t3,$t4,$t5,$t6,$t7,$t8,$x)=map("\$r$_",(12..21));
+my ($s0,$s1,$s2,$s3,$s4,$s5,$s6,$s7,$s8)=map("\$r$_",(23..31));
 
 my ($INP, $LEN, $ADDR) = ($a1, $a2, $sp);
 my ($KT, $T1, $T2, $T3, $T4, $T5, $T6) = ($t0, $t1, $t2, $t3, $t4, $t5, $t6);
-my ($A, $B, $C, $D, $E, $F, $G, $H) = ($s0, $s1, $s2, $s3, $s4, $s5, $s6, $s7);
-my @VMSGS = ($va0, $va1, $va2, $va3, $va4, $va5, $va6, $va7);
-
-sub strip {
-    my ($str) = @_;
-    $str =~ s/^\s+|\s+$//g;
-    return $str;
-}
-
-sub MSGSCHEDULE0_lsx {
-    my ($index) = @_;
-    my $msg = $VMSGS[$index / 2];
-    my $code;
-
-    if ($index % 2 == 0) {
-        $code = <<___;
-    vld $msg, $INP, @{[8*$index]}
-    vshuf4i.b $msg, $msg, 0b00011011
-    vshuf4i.w $msg, $msg, 0b10110001
-___
-    }
-
-    $code .= <<___;
-    vpickve2gr.d $T1, $msg, @{[$index%2]}
-___
-
-    return strip($code);
-}
+my ($A, $B, $C, $D ,$E ,$F ,$G ,$H) = ($s0, $s1, $s2, $s3, $s4, $s5, $s6, $s7);
 
 sub MSGSCHEDULE0 {
     my ($index) = @_;
-
-    if ($use_lsx) {
-        return MSGSCHEDULE0_lsx($index);
-    }
-
     my $code=<<___;
-    ld.d $T1, $INP, @{[8*$index]}
+    ld.d $T1, $INP, 8*$index
     revb.d $T1, $T1
-    st.d $T1, $ADDR, @{[8*$index]}
+    st.d $T1, $ADDR, 8*$index
 ___
-    return strip($code);
-}
-
-sub MSGSCHEDULE1_lsx {
-    my ($index) = @_;
-    my $msgidx = ($index / 2) % 8;
-    my $m01 = $VMSGS[$msgidx];
-    my $m23 = $VMSGS[($msgidx + 1) % 8];
-    my $m45 = $VMSGS[($msgidx + 2) % 8];
-    my $m67 = $VMSGS[($msgidx + 3) % 8];
-    my $m89 = $VMSGS[($msgidx + 4) % 8];
-    my $mab = $VMSGS[($msgidx + 5) % 8];
-    my $mcd = $VMSGS[($msgidx + 6) % 8];
-    my $mef = $VMSGS[($msgidx + 7) % 8];
-    my ($m12, $tmp0, $tmp1) = ($vt0, $vt1, $vt2);
-    my $code;
-
-    if ($index % 2 == 0) {
-        # re-align to get $m12 and "$m9a" ($tmp0)
-        $code = <<___;
-    # m01 & new = $m01, m23 = $m23, m45 = $m45, m67 = $m67
-    # m89 = $m89, mab = $mab, mcd = $mcd, mef = $mef
-    vori.b $m12, $m01, 0
-    vshuf4i.d $m12, $m23, 0b1001
-    vori.b $tmp0, $m89, 0
-    vshuf4i.d $tmp0, $mab, 0b1001
-    vadd.d $m01, $m01, $tmp0
-___
-
-        # $m01 += sigma0($m12)
-        $code .= <<___;
-    vrotri.d $tmp0, $m12, 1
-    vrotri.d $tmp1, $m12, 8
-    vsrli.d $m12, $m12, 7
-    vxor.v $tmp0, $tmp0, $tmp1
-    vxor.v $m12, $m12, $tmp0
-    vadd.d $m01, $m01, $m12
-___
-
-        # $m01 += sigma1
-        # now m12 can be re-used as temporary
-        $code .= <<___;
-    vrotri.d $tmp0, $mef, 19
-    vrotri.d $tmp1, $mef, 61
-    vsrli.d $m12, $mef, 6
-    vxor.v $tmp0, $tmp0, $tmp1
-    vxor.v $m12, $m12, $tmp0
-    vadd.d $m01, $m01, $m12
-___
-    }
-
-    $code .= <<___;
-    vpickve2gr.d $T1, $m01, @{[$index%2]}
-___
-
-    return strip($code);
+    return $code;
 }
 
 sub MSGSCHEDULE1 {
     my ($index) = @_;
-
-    if ($use_lsx) {
-        return MSGSCHEDULE1_lsx($index);
-    }
-
     my $code=<<___;
-    ld.d $T1, $ADDR, @{[(($index-2)&0x0f)*8]}
-    ld.d $T2, $ADDR, @{[(($index-15)&0x0f)*8]}
-    ld.d $T3, $ADDR, @{[(($index-7)&0x0f)*8]}
-    ld.d $T4, $ADDR, @{[($index&0x0f)*8]}
+    ld.d $T1, $ADDR, (($index-2)&0x0f)*8
+    ld.d $T2, $ADDR, (($index-15)&0x0f)*8
+    ld.d $T3, $ADDR, (($index-7)&0x0f)*8
+    ld.d $T4, $ADDR, ($index&0x0f)*8
     rotri.d $T5, $T1, 19
     rotri.d $T6, $T1, 61
     srli.d $T1, $T1, 6
@@ -187,15 +91,15 @@ sub MSGSCHEDULE1 {
     xor $T2, $T2, $T6
     add.d $T1, $T1, $T2
     add.d $T1, $T1, $T4
-    st.d $T1, $ADDR, @{[8*($index&0x0f)]}
+    st.d $T1, $ADDR, 8*($index&0x0f)
 ___
-    return strip($code);
+    return $code;
 }
 
 sub sha512_T1 {
     my ($index, $e, $f, $g, $h) = @_;
     my $code=<<___;
-    ld.d $T4, $KT, @{[8*$index]}
+    ld.d $T4, $KT, 8*$index
     add.d $h, $h, $T1
     add.d $h, $h, $T4
     rotri.d $T2, $e, 14
@@ -209,7 +113,7 @@ sub sha512_T1 {
     xor $T1, $T1, $g
     add.d $T1, $T1, $h
 ___
-    return strip($code);
+    return $code;
 }
 
 sub sha512_T2 {
@@ -226,29 +130,45 @@ sub sha512_T2 {
     xor $T3, $T3, $T5
     add.d $T2, $T2, $T3
 ___
-    return strip($code);
+    return $code;
 }
 
 sub SHA512ROUND {
     my ($index, $a, $b, $c, $d, $e, $f, $g, $h) = @_;
-    my $ms = $index < 16 ? \&MSGSCHEDULE0 : \&MSGSCHEDULE1;
     my $code=<<___;
-    @{[$ms->($index)]}
     @{[sha512_T1 $index, $e, $f, $g, $h]}
     @{[sha512_T2 $a, $b, $c]}
     add.d $d, $d, $T1
     add.d $h, $T2, $T1
 ___
-    return strip($code);
+    return $code;
+}
+
+sub SHA512ROUND0 {
+    my ($index, $a, $b, $c, $d, $e, $f, $g, $h) = @_;
+    my $code=<<___;
+    @{[MSGSCHEDULE0 $index]}
+    @{[SHA512ROUND $index, $a, $b, $c, $d, $e, $f, $g, $h]}
+___
+    return $code;
+}
+
+sub SHA512ROUND1 {
+    my ($index, $a, $b, $c, $d, $e, $f, $g, $h) = @_;
+    my $code=<<___;
+    @{[MSGSCHEDULE1 $index]}
+    @{[SHA512ROUND $index, $a, $b, $c, $d, $e, $f, $g, $h]}
+___
+    return $code;
 }
 
 ################################################################################
-# void sha512_block_data_order$isaext(void *c, const void *p, size_t len)
+# void sha512_block_data_order(void *c, const void *p, size_t len)
 $code .= <<___;
 .p2align 3
-.globl sha512_block_data_order@{[$isaext]}
-.type   sha512_block_data_order@{[$isaext]},\@function
-sha512_block_data_order@{[$isaext]}:
+.globl sha512_block_data_order
+.type   sha512_block_data_order,\@function
+sha512_block_data_order:
 
     addi.d $sp, $sp, -80
 
@@ -262,17 +182,9 @@ sha512_block_data_order@{[$isaext]}:
     st.d $s7, $sp, 56
     st.d $s8, $sp, 64
     st.d $fp, $sp, 72
-___
 
-# SHA512 LSX needs neither dedicated shuffle control word, nor stack space for
-# internal states
-if (!$use_lsx) {
-    $code .= <<___;
     addi.d $sp, $sp, -128
-___
-}
 
-$code .= <<___;
     la $KT, $K512
 
     # load ctx
@@ -288,22 +200,107 @@ $code .= <<___;
 L_round_loop:
     # Decrement length by 1
     addi.d $LEN, $LEN, -1
-___
 
-for (my $i = 0; $i < 80; $i += 8) {
-    $code .= <<___;
-    @{[SHA512ROUND $i, $A, $B, $C, $D, $E, $F, $G, $H]}
-    @{[SHA512ROUND $i+1, $H, $A, $B, $C, $D, $E, $F, $G]}
-    @{[SHA512ROUND $i+2, $G, $H, $A, $B, $C, $D, $E, $F]}
-    @{[SHA512ROUND $i+3, $F, $G, $H, $A, $B, $C, $D, $E]}
-    @{[SHA512ROUND $i+4, $E, $F, $G, $H, $A, $B, $C, $D]}
-    @{[SHA512ROUND $i+5, $D, $E, $F, $G, $H, $A, $B, $C]}
-    @{[SHA512ROUND $i+6, $C, $D, $E, $F, $G, $H, $A, $B]}
-    @{[SHA512ROUND $i+7, $B, $C, $D, $E, $F, $G, $H, $A]}
-___
-}
+    @{[SHA512ROUND0 0, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA512ROUND0 1, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA512ROUND0 2, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA512ROUND0 3, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA512ROUND0 4, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA512ROUND0 5, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA512ROUND0 6, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA512ROUND0 7, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA512ROUND0 8, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA512ROUND0 9, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA512ROUND0 10, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA512ROUND0 11, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA512ROUND0 12, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA512ROUND0 13, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA512ROUND0 14, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA512ROUND0 15, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA512ROUND1 16, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA512ROUND1 17, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA512ROUND1 18, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA512ROUND1 19, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA512ROUND1 20, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA512ROUND1 21, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA512ROUND1 22, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA512ROUND1 23, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA512ROUND1 24, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA512ROUND1 25, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA512ROUND1 26, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA512ROUND1 27, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA512ROUND1 28, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA512ROUND1 29, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA512ROUND1 30, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA512ROUND1 31, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA512ROUND1 32, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA512ROUND1 33, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA512ROUND1 34, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA512ROUND1 35, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA512ROUND1 36, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA512ROUND1 37, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA512ROUND1 38, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA512ROUND1 39, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA512ROUND1 40, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA512ROUND1 41, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA512ROUND1 42, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA512ROUND1 43, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA512ROUND1 44, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA512ROUND1 45, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA512ROUND1 46, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA512ROUND1 47, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA512ROUND1 48, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA512ROUND1 49, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA512ROUND1 50, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA512ROUND1 51, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA512ROUND1 52, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA512ROUND1 53, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA512ROUND1 54, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA512ROUND1 55, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA512ROUND1 56, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA512ROUND1 57, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA512ROUND1 58, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA512ROUND1 59, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA512ROUND1 60, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA512ROUND1 61, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA512ROUND1 62, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA512ROUND1 63, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA512ROUND1 64, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA512ROUND1 65, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA512ROUND1 66, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA512ROUND1 67, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA512ROUND1 68, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA512ROUND1 69, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA512ROUND1 70, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA512ROUND1 71, $B, $C, $D, $E, $F, $G, $H, $A]}
+
+    @{[SHA512ROUND1 72, $A, $B, $C, $D, $E, $F, $G, $H]}
+    @{[SHA512ROUND1 73, $H, $A, $B, $C, $D, $E, $F, $G]}
+    @{[SHA512ROUND1 74, $G, $H, $A, $B, $C, $D, $E, $F]}
+    @{[SHA512ROUND1 75, $F, $G, $H, $A, $B, $C, $D, $E]}
+
+    @{[SHA512ROUND1 76, $E, $F, $G, $H, $A, $B, $C, $D]}
+    @{[SHA512ROUND1 77, $D, $E, $F, $G, $H, $A, $B, $C]}
+    @{[SHA512ROUND1 78, $C, $D, $E, $F, $G, $H, $A, $B]}
+    @{[SHA512ROUND1 79, $B, $C, $D, $E, $F, $G, $H, $A]}
 
-$code .= <<___;
     ld.d $T1, $a0, 0
     ld.d $T2, $a0, 8
     ld.d $T3, $a0, 16
@@ -337,15 +334,9 @@ $code .= <<___;
     addi.d $INP, $INP, 128
 
     bnez $LEN, L_round_loop
-___
 
-if (!$use_lsx) {
-    $code .= <<___;
     addi.d $sp, $sp, 128
-___
-}
 
-$code .= <<___;
     ld.d $s0, $sp, 0
     ld.d $s1, $sp, 8
     ld.d $s2, $sp, 16
@@ -360,7 +351,7 @@ $code .= <<___;
     addi.d $sp, $sp, 80
 
     ret
-.size sha512_block_data_order@{[$isaext]},.-sha512_block_data_order@{[$isaext]}
+.size sha512_block_data_order,.-sha512_block_data_order
 
 .section .rodata
 .p2align 3
diff --git a/crypto/sha/asm/sha512-mips.pl b/crypto/sha/asm/sha512-mips.pl
index cbca8163a0..58aac18eb9 100644
--- a/crypto/sha/asm/sha512-mips.pl
+++ b/crypto/sha/asm/sha512-mips.pl
@@ -308,7 +308,7 @@ $FRAMESIZE=16*$SZ+16*$SZREG;
 $SAVED_REGS_MASK = ($flavour =~ /nubi/i) ? "0xc0fff008" : "0xc0ff0000";
 
 $code.=<<___;
-#include "arch/mips_arch.h"
+#include "mips_arch.h"
 
 .text
 .set	noat
diff --git a/crypto/sha/asm/sha512-riscv64-zvkb-zvknhb.pl b/crypto/sha/asm/sha512-riscv64-zvkb-zvknhb.pl
index 29a51b2f2b..c5df987296 100644
--- a/crypto/sha/asm/sha512-riscv64-zvkb-zvknhb.pl
+++ b/crypto/sha/asm/sha512-riscv64-zvkb-zvknhb.pl
@@ -70,7 +70,6 @@ my $K512 = "K512";
 
 # Function arguments
 my ($H, $INP, $LEN, $KT, $H2, $INDEX_PATTERN) = ("a0", "a1", "a2", "a3", "t3", "t4");
-my ($T0, $T1) = ("t0", "t1");
 
 ################################################################################
 # void sha512_block_data_order_zvkb_zvknhb(void *c, const void *p, size_t len)
@@ -79,6 +78,8 @@ $code .= <<___;
 .globl sha512_block_data_order_zvkb_zvknhb
 .type sha512_block_data_order_zvkb_zvknhb,\@function
 sha512_block_data_order_zvkb_zvknhb:
+    @{[vsetivli "zero", 4, "e64", "m2", "ta", "ma"]}
+
     # H is stored as {a,b,c,d},{e,f,g,h}, but we need {f,e,b,a},{h,g,d,c}
     # The dst vtype is e64m2 and the index vtype is e8mf4.
     # We use index-load with the following index pattern at v1.
@@ -104,226 +105,9 @@ sha512_block_data_order_zvkb_zvknhb:
     @{[vsetivli "zero", 1, "e8", "m1", "ta", "ma"]}
     @{[vmv_v_i $V0, 0x01]}
 
-    # Obtain VLEN and select the corresponding branch
-    csrr t0, vlenb
-    srl t1, t0, 5
-    beqz t1, sha512_block_data_order_zvkb_zvknhb_zvl128
-sha512_block_data_order_zvkb_zvknhb_zvl256_zvl512:
-    # When vlen=256 or 512, the round constants K512 can be loaded
-    # at once in vector register files.
-    @{[vsetivli "zero", 4, "e64", "m1", "ta", "ma"]}
-    # Load round constants K512
-    la $KT, $K512
-    @{[vle64_v $V2, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V3, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V4, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V5, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V6, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V7, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V8, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V9, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V11, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V13, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V15, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V17, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V19, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V21, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V23, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V25, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V27, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V29, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V30, ($KT)]}
-    addi $KT, $KT, 32
-    @{[vle64_v $V31, ($KT)]}
+    @{[vsetivli "zero", 4, "e64", "m2", "ta", "ma"]}
 
-L_round_loop_256_512:
-    # Decrement length by 1
-    addi $LEN, $LEN, -1
-
-    # Keep the current state as we need it later: H' = H+{a',b',c',...,h'}.
-    @{[vmv1r_v $V26, $V22]}
-    @{[vmv1r_v $V28, $V24]}
-
-    # Load the 1024-bits of the message block in v10, v12, v14, v16
-    # and perform the endian swap.
-    @{[vle64_v $V10, $INP]}
-    @{[vrev8_v $V10, $V10]}
-    addi $INP, $INP, 32
-    @{[vle64_v $V12, $INP]}
-    @{[vrev8_v $V12, $V12]}
-    addi $INP, $INP, 32
-    @{[vle64_v $V14, $INP]}
-    @{[vrev8_v $V14, $V14]}
-    addi $INP, $INP, 32
-    @{[vle64_v $V16, $INP]}
-    @{[vrev8_v $V16, $V16]}
-    addi $INP, $INP, 32
-
-    # Quad-round 0 (+0, v10->v12->v14->v16)
-    @{[vadd_vv $V18, $V2, $V10]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V14, $V12, $V0]}
-    @{[vsha2ms_vv $V10, $V18, $V16]}
-
-    # Quad-round 1 (+1, v12->v14->v16->v10)
-    @{[vadd_vv $V18, $V3, $V12]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V16, $V14, $V0]}
-    @{[vsha2ms_vv $V12, $V18, $V10]}
-
-    # Quad-round 2 (+2, v14->v16->v10->v12)
-    @{[vadd_vv $V18, $V4, $V14]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V10, $V16, $V0]}
-    @{[vsha2ms_vv $V14, $V18, $V12]}
-
-    # Quad-round 3 (+3, v16->v10->v12->v14)
-    @{[vadd_vv $V18, $V5, $V16]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V12, $V10, $V0]}
-    @{[vsha2ms_vv $V16, $V18, $V14]}
-
-    # Quad-round 4 (+4, v10->v12->v14->v16)
-    @{[vadd_vv $V18, $V6, $V10]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V14, $V12, $V0]}
-    @{[vsha2ms_vv $V10, $V18, $V16]}
-
-    # Quad-round 5 (+5, v12->v14->v16->v10)
-    @{[vadd_vv $V18, $V7, $V12]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V16, $V14, $V0]}
-    @{[vsha2ms_vv $V12, $V18, $V10]}
-
-    # Quad-round 6 (+6, v14->v16->v10->v12)
-    @{[vadd_vv $V18, $V8, $V14]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V10, $V16, $V0]}
-    @{[vsha2ms_vv $V14, $V18, $V12]}
-
-    # Quad-round 7 (+7, v16->v10->v12->v14)
-    @{[vadd_vv $V18, $V9, $V16]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V12, $V10, $V0]}
-    @{[vsha2ms_vv $V16, $V18, $V14]}
-
-    # Quad-round 8 (+8, v10->v12->v14->v16)
-    @{[vadd_vv $V18, $V11, $V10]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V14, $V12, $V0]}
-    @{[vsha2ms_vv $V10, $V18, $V16]}
-
-    # Quad-round 9 (+9, v12->v14->v16->v10)
-    @{[vadd_vv $V18, $V13, $V12]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V16, $V14, $V0]}
-    @{[vsha2ms_vv $V12, $V18, $V10]}
-
-    # Quad-round 10 (+10, v14->v16->v10->v12)
-    @{[vadd_vv $V18, $V15, $V14]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V10, $V16, $V0]}
-    @{[vsha2ms_vv $V14, $V18, $V12]}
-
-    # Quad-round 11 (+11, v16->v10->v12->v14)
-    @{[vadd_vv $V18, $V17, $V16]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V12, $V10, $V0]}
-    @{[vsha2ms_vv $V16, $V18, $V14]}
-
-    # Quad-round 12 (+12, v10->v12->v14->v16)
-    @{[vadd_vv $V18, $V19, $V10]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V14, $V12, $V0]}
-    @{[vsha2ms_vv $V10, $V18, $V16]}
-
-    # Quad-round 13 (+13, v12->v14->v16->v10)
-    @{[vadd_vv $V18, $V21, $V12]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V16, $V14, $V0]}
-    @{[vsha2ms_vv $V12, $V18, $V10]}
-
-    # Quad-round 14 (+14, v14->v16->v10->v12)
-    @{[vadd_vv $V18, $V23, $V14]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V10, $V16, $V0]}
-    @{[vsha2ms_vv $V14, $V18, $V12]}
-
-    # Quad-round 15 (+15, v16->v10->v12->v14)
-    @{[vadd_vv $V18, $V25, $V16]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-    @{[vmerge_vvm $V18, $V12, $V10, $V0]}
-    @{[vsha2ms_vv $V16, $V18, $V14]}
-
-    # Quad-round 16 (+0, v10->v12->v14->v16)
-    # Note that we stop generating new message schedule words (Wt, v10-16)
-    # as we already generated all the words we end up consuming (i.e., W[79:76]).
-    @{[vadd_vv $V18, $V27, $V10]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-
-    # Quad-round 17 (+1, v12->v14->v16->v10)
-    @{[vadd_vv $V18, $V29, $V12]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-
-    # Quad-round 18 (+2, v14->v16->v10->v12)
-    @{[vadd_vv $V18, $V30, $V14]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-
-    # Quad-round 19 (+3, v16->v10->v12->v14)
-    @{[vadd_vv $V18, $V31, $V16]}
-    @{[vsha2cl_vv $V24, $V22, $V18]}
-    @{[vsha2ch_vv $V22, $V24, $V18]}
-
-    # H' = H+{a',b',c',...,h'}
-    @{[vadd_vv $V22, $V26, $V22]}
-    @{[vadd_vv $V24, $V28, $V24]}
-    bnez $LEN, L_round_loop_256_512
-
-    # Store {f,e,b,a},{h,g,d,c} back to {a,b,c,d},{e,f,g,h}.
-    @{[vsuxei8_v $V22, ($H), $V1]}
-    @{[vsuxei8_v $V24, ($H2), $V1]}
-
-    ret
-sha512_block_data_order_zvkb_zvknhb_zvl128:
-    @{[vsetivli $T0, 4, "e64", "m2", "ta", "ma"]}
-L_round_loop_128:
+L_round_loop:
     # Load round constants K512
     la $KT, $K512
 
@@ -420,7 +204,7 @@ L_round_loop_128:
     # H' = H+{a',b',c',...,h'}
     @{[vadd_vv $V22, $V26, $V22]}
     @{[vadd_vv $V24, $V28, $V24]}
-    bnez $LEN, L_round_loop_128
+    bnez $LEN, L_round_loop
 
     # Store {f,e,b,a},{h,g,d,c} back to {a,b,c,d},{e,f,g,h}.
     @{[vsuxei8_v $V22, ($H), $V1]}
diff --git a/crypto/sha/asm/sha512-s390x.pl b/crypto/sha/asm/sha512-s390x.pl
index 7d57eaaa47..f4cf4848cf 100644
--- a/crypto/sha/asm/sha512-s390x.pl
+++ b/crypto/sha/asm/sha512-s390x.pl
@@ -172,7 +172,7 @@ ___
 }
 
 $code.=<<___;
-#include "arch/s390x_arch.h"
+#include "s390x_arch.h"
 
 .text
 .align	64
diff --git a/crypto/sha/asm/sha512-sparcv9.pl b/crypto/sha/asm/sha512-sparcv9.pl
index b2c64c7a3f..4763e714eb 100644
--- a/crypto/sha/asm/sha512-sparcv9.pl
+++ b/crypto/sha/asm/sha512-sparcv9.pl
@@ -397,7 +397,7 @@ $code.=<<___;
 #ifndef __ASSEMBLER__
 # define __ASSEMBLER__ 1
 #endif
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 #ifdef __arch64__
 .register	%g2,#scratch
diff --git a/crypto/sha/asm/sha512-x86_64.pl b/crypto/sha/asm/sha512-x86_64.pl
index 4db4b1beb0..029468db9f 100755
--- a/crypto/sha/asm/sha512-x86_64.pl
+++ b/crypto/sha/asm/sha512-x86_64.pl
@@ -144,13 +144,6 @@ if (!$avx && `$ENV{CC} -v 2>&1` =~ /((?:clang|LLVM) version|.*based on LLVM) ([0
 	$avx = ($2>=3.0) + ($2>3.0);
 }
 
-if (!$avx && `$ENV{CC} -x c /dev/null -dM -E|grep __clang_major__`
-	=~ /#define __clang_major__.([0-9]+)/) {
-	if ($1) {
-		$avx = ($1>=11); #icx started with clang 11
-	}
-}
-
 $shaext=1;	### set to zero if compiling for 1.0.1
 $avx=1		if (!$shaext && $avx);
 
diff --git a/crypto/sha/build.info b/crypto/sha/build.info
index 88e8b9cc5e..c3d927c85a 100644
--- a/crypto/sha/build.info
+++ b/crypto/sha/build.info
@@ -18,9 +18,7 @@ IF[{- !$disabled{asm} -}]
   $SHA1ASM_alpha=sha1-alpha.S
   $SHA1DEF_alpha=SHA1_ASM
 
-  $SHA1ASM_loongarch64=sha_loongarch.c \
-        sha256-loongarch64.S sha256-loongarch64-lsx.S \
-        sha512-loongarch64.S sha512-loongarch64-lsx.S
+  $SHA1ASM_loongarch64=sha256-loongarch64.S sha512-loongarch64.S
   $SHA1DEF_loongarch64=SHA256_ASM SHA512_ASM
 
   $SHA1ASM_mips32=sha1-mips.S sha256-mips.S
@@ -65,7 +63,7 @@ ENDIF
 $KECCAK1600ASM=keccak1600.c
 IF[{- !$disabled{asm} -}]
   $KECCAK1600ASM_x86=
-  $KECCAK1600ASM_x86_64=keccak1600-x86_64.s keccak1600x4-avx512vl.s sha3_x4_avx512vl.c
+  $KECCAK1600ASM_x86_64=keccak1600-x86_64.s
 
   $KECCAK1600ASM_s390x=keccak1600-s390x.S
 
@@ -82,7 +80,7 @@ IF[{- !$disabled{asm} -}]
   ENDIF
 ENDIF
 
-$COMMON=sha1dgst.c sha256.c sha512.c sha3.c sha3_encode.c $SHA1ASM $KECCAK1600ASM
+$COMMON=sha1dgst.c sha256.c sha512.c sha3.c $SHA1ASM $KECCAK1600ASM
 SOURCE[../../libcrypto]=$COMMON sha1_one.c
 SOURCE[../../providers/libfips.a]= $COMMON
 
@@ -140,12 +138,8 @@ GENERATE[sha512-parisc.s]=asm/sha512-parisc.pl
 
 GENERATE[sha256-loongarch64.S]=asm/sha256-loongarch64.pl
 INCLUDE[sha256-loongarch64.o]=..
-GENERATE[sha256-loongarch64-lsx.S]=asm/sha256-loongarch64.pl lsx
-INCLUDE[sha256-loongarch64-lsx.o]=..
 GENERATE[sha512-loongarch64.S]=asm/sha512-loongarch64.pl
 INCLUDE[sha512-loongarch64.o]=..
-GENERATE[sha512-loongarch64-lsx.S]=asm/sha512-loongarch64.pl lsx
-INCLUDE[sha512-loongarch64-lsx.o]=..
 
 GENERATE[sha1-mips.S]=asm/sha1-mips.pl
 INCLUDE[sha1-mips.o]=..
@@ -198,8 +192,4 @@ GENERATE[keccak1600-avx512vl.S]=asm/keccak1600-avx512vl.pl
 GENERATE[keccak1600-mmx.S]=asm/keccak1600-mmx.pl
 GENERATE[keccak1600p8-ppc.S]=asm/keccak1600p8-ppc.pl
 
-# keccak1600x4-avx512vl.s supports multi-squeeze
-# Currently only used in ML-DSA on x86_64 with AVX-512VL support
-GENERATE[keccak1600x4-avx512vl.s]=asm/keccak1600x4-avx512vl.pl
-
 GENERATE[sha1-thumb.S]=asm/sha1-thumb.pl
diff --git a/crypto/sha/keccak1600.c b/crypto/sha/keccak1600.c
index 26d75f1b8e..59e688ce43 100644
--- a/crypto/sha/keccak1600.c
+++ b/crypto/sha/keccak1600.c
@@ -111,7 +111,7 @@ static const uint64_t iotas[] = {
 /*
  * This is straightforward or "maximum clarity" implementation aiming
  * to resemble section 3.2 of the FIPS PUB 202 "SHA-3 Standard:
- * Permutation-Based Hash and Extendable-Output Functions" as much as
+ * Permutation-Based Hash and Extendible-Output Functions" as much as
  * possible. With one caveat. Because of the way C stores matrices,
  * references to A[x,y] in the specification are presented as A[y][x].
  * Implementation unrolls inner x-loops so that modulo 5 operations are
diff --git a/crypto/sha/sha1dgst.c b/crypto/sha/sha1dgst.c
index 3fe0aebfff..e8f1ef5244 100644
--- a/crypto/sha/sha1dgst.c
+++ b/crypto/sha/sha1dgst.c
@@ -20,7 +20,7 @@
 #include 
 #include 
 
-/* The implementation is in crypto/md32_common.inc */
+/* The implementation is in crypto/md32_common.h */
 
 #include "sha_local.h"
 #include "crypto/sha.h"
diff --git a/crypto/sha/sha256.c b/crypto/sha/sha256.c
index 8cbbfdbb30..0268e09dde 100644
--- a/crypto/sha/sha256.c
+++ b/crypto/sha/sha256.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2004-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2004-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -119,8 +119,7 @@ int SHA224_Final(unsigned char *md, SHA256_CTX *c)
         }                                                           \
     } while (0)
 
-#define HASH_UPDATE_THUNK
-#define HASH_UPDATE SHA256_Update_thunk
+#define HASH_UPDATE SHA256_Update
 #define HASH_TRANSFORM SHA256_Transform
 #define HASH_FINAL SHA256_Final
 #define HASH_BLOCK_DATA_ORDER sha256_block_data_order
@@ -133,15 +132,7 @@ void sha256_block_data_order_c(SHA256_CTX *ctx, const void *in, size_t num);
 #endif /* SHA256_ASM */
     void sha256_block_data_order(SHA256_CTX *ctx, const void *in, size_t num);
 
-/* clang-format off */
-#include "crypto/md32_common.inc"
-/* clang-format on */
-#undef HASH_UPDATE_THUNK
-
-int SHA256_Update(SHA256_CTX *ctx, const void *data, size_t sz)
-{
-    return SHA256_Update_thunk((void *)ctx, (const unsigned char *)data, sz);
-}
+#include "crypto/md32_common.h"
 
 #if !defined(SHA256_ASM) || defined(INCLUDE_C_SHA256)
 static const SHA_LONG K256[64] = {
@@ -164,7 +155,7 @@ static const SHA_LONG K256[64] = {
 };
 
 #ifndef PEDANTIC
-#if defined(__GNUC__) && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM)
+#if defined(__GNUC__) && __GNUC__ >= 2 && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM)
 #if defined(__riscv_zknh)
 #define Sigma0(x) ({ MD32_REG_T ret;            \
                         asm ("sha256sum0 %0, %1"    \
diff --git a/crypto/sha/sha3.c b/crypto/sha/sha3.c
index 5c8754cfd6..21e1070bee 100644
--- a/crypto/sha/sha3.c
+++ b/crypto/sha/sha3.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2017-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -8,21 +8,10 @@
  */
 
 #include 
-#include "internal/sha3.h"
-#include "internal/common.h"
-
-#if defined(__aarch64__) && defined(KECCAK1600_ASM)
-#include "arch/arm_arch.h"
-#endif
-
 #if defined(__s390x__) && defined(OPENSSL_CPUID_OBJ)
-#include "arch/s390x_arch.h"
-#if defined(KECCAK1600_ASM)
-#define S390_SHA3 1
-#define S390_SHA3_CAPABLE(name) \
-    ((OPENSSL_s390xcap_P.kimd[0] & S390X_CAPBIT(name)) && (OPENSSL_s390xcap_P.klmd[0] & S390X_CAPBIT(name)))
-#endif
+#include "crypto/s390x_arch.h"
 #endif
+#include "internal/sha3.h"
 
 void SHA3_squeeze(uint64_t A[5][5], unsigned char *out, size_t len, size_t r, int next);
 
@@ -60,98 +49,67 @@ int ossl_keccak_init(KECCAK1600_CTX *ctx, unsigned char pad, size_t bitlen, size
     return ret;
 }
 
-/*
- * A buffered absorb function that calls a platform specific absorb
- * method.
- */
-int ossl_sha3_absorb(KECCAK1600_CTX *ctx, const unsigned char *inp, size_t len)
+int ossl_sha3_update(KECCAK1600_CTX *ctx, const void *_inp, size_t len)
 {
-    const size_t bsz = ctx->block_size;
+    const unsigned char *inp = _inp;
+    size_t bsz = ctx->block_size;
     size_t num, rem;
 
-    if (ossl_unlikely(len == 0))
+    if (len == 0)
         return 1;
 
-    if (!(ctx->xof_state == XOF_STATE_INIT || ctx->xof_state == XOF_STATE_ABSORB))
+    if (ctx->xof_state == XOF_STATE_SQUEEZE
+        || ctx->xof_state == XOF_STATE_FINAL)
         return 0;
 
-    /* Is there anything in the buffer already ? */
-    if ((num = ctx->bufsz) != 0) {
-        /* Calculate how much space is left in the buffer */
+    if ((num = ctx->bufsz) != 0) { /* process intermediate buffer? */
         rem = bsz - num;
-        /* If the new input does not fill the buffer then just add it */
+
         if (len < rem) {
             memcpy(ctx->buf + num, inp, len);
             ctx->bufsz += len;
             return 1;
         }
-        /* otherwise fill up the buffer and absorb the buffer */
+        /*
+         * We have enough data to fill or overflow the intermediate
+         * buffer. So we append |rem| bytes and process the block,
+         * leaving the rest for later processing...
+         */
         memcpy(ctx->buf + num, inp, rem);
-        /* Update the input pointer */
-        inp += rem;
-        len -= rem;
-        ctx->meth.absorb(ctx, ctx->buf, bsz);
+        inp += rem, len -= rem;
+        (void)SHA3_absorb(ctx->A, ctx->buf, bsz, bsz);
         ctx->bufsz = 0;
-        ctx->xof_state = XOF_STATE_ABSORB;
+        /* ctx->buf is processed, ctx->num is guaranteed to be zero */
     }
-    /* Absorb the input - rem = leftover part of the input < blocksize) */
-    rem = ctx->meth.absorb(ctx, inp, len);
+
     if (len >= bsz)
-        ctx->xof_state = XOF_STATE_ABSORB;
-    /* Copy the leftover bit of the input into the buffer */
-    if (ossl_likely(rem > 0)) {
+        rem = SHA3_absorb(ctx->A, inp, len, bsz);
+    else
+        rem = len;
+
+    if (rem) {
         memcpy(ctx->buf, inp + len - rem, rem);
         ctx->bufsz = rem;
     }
+
     return 1;
 }
 
 /*
- * Call a platform specific final method.
- * In most cases outlen should be set to ctx->mdlen.
- * This function assumes the caller has checked outlen is bounded.
+ * ossl_sha3_final()is a single shot method
+ * (Use ossl_sha3_squeeze for multiple calls).
+ * outlen is the variable size output.
  */
 int ossl_sha3_final(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen)
 {
-    int ret;
+    size_t bsz = ctx->block_size;
+    size_t num = ctx->bufsz;
 
+    if (outlen == 0)
+        return 1;
     if (ctx->xof_state == XOF_STATE_SQUEEZE
         || ctx->xof_state == XOF_STATE_FINAL)
         return 0;
-    if (outlen == 0)
-        return 1;
-
-    ret = ctx->meth.final(ctx, out, outlen);
-    ctx->xof_state = XOF_STATE_FINAL;
-    return ret;
-}
-
-/* Calls a platform specific squeeze method */
-int ossl_sha3_squeeze(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen)
-{
-    int ret = 0;
-
-    if (ctx->xof_state == XOF_STATE_FINAL)
-        return 0;
-    ret = ctx->meth.squeeze(ctx, out, outlen);
-    ctx->xof_state = XOF_STATE_SQUEEZE;
-    return ret;
-}
-
-/* Default version of the absorb() */
-size_t ossl_sha3_absorb_default(KECCAK1600_CTX *ctx, const unsigned char *inp, size_t len)
-{
-    return SHA3_absorb(ctx->A, inp, len, ctx->block_size);
-}
-
-/*
- * Default version of the final() is a single shot method
- * (Use ossl_sha3_default_squeeze() for multiple calls).
- */
-int ossl_sha3_final_default(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen)
-{
-    size_t bsz = ctx->block_size;
-    size_t num = ctx->bufsz;
 
     /*
      * Pad the data with 10*1. Note that |num| can be |bsz - 1|
@@ -164,6 +122,7 @@ int ossl_sha3_final_default(KECCAK1600_CTX *ctx, unsigned char *out, size_t outl
 
     (void)SHA3_absorb(ctx->A, ctx->buf, bsz, bsz);
 
+    ctx->xof_state = XOF_STATE_FINAL;
     SHA3_squeeze(ctx->A, out, outlen, bsz, 0);
     return 1;
 }
@@ -178,13 +137,19 @@ int ossl_sha3_final_default(KECCAK1600_CTX *ctx, unsigned char *out, size_t outl
  * buffer the results. The next request will use the buffer first
  * to grab output bytes.
  */
-int ossl_shake_squeeze_default(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen)
+int ossl_sha3_squeeze(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen)
 {
     size_t bsz = ctx->block_size;
     size_t num = ctx->bufsz;
     size_t len;
     int next = 1;
 
+    if (outlen == 0)
+        return 1;
+
+    if (ctx->xof_state == XOF_STATE_FINAL)
+        return 0;
+
     /*
      * On the first squeeze call, finish the absorb process,
      * by adding the trailing padding and then doing
@@ -200,6 +165,7 @@ int ossl_shake_squeeze_default(KECCAK1600_CTX *ctx, unsigned char *out, size_t o
         ctx->buf[num] = ctx->pad;
         ctx->buf[bsz - 1] |= 0x80;
         (void)SHA3_absorb(ctx->A, ctx->buf, bsz, bsz);
+        ctx->xof_state = XOF_STATE_SQUEEZE;
         num = ctx->bufsz = 0;
         next = 0;
     }
@@ -236,119 +202,6 @@ int ossl_shake_squeeze_default(KECCAK1600_CTX *ctx, unsigned char *out, size_t o
         /* Step 4. Remember the leftover part of the squeezed block */
         ctx->bufsz = bsz - outlen;
     }
-    return 1;
-}
-
-static PROV_SHA3_METHOD shake_generic_meth = {
-    ossl_sha3_absorb_default,
-    ossl_sha3_final_default,
-    ossl_shake_squeeze_default
-};
-
-#if defined(S390_SHA3)
-
-/*-
- * The platform specific parts of the absorb() and final() for S390X.
- */
-static size_t sha3_absorb_s390x(KECCAK1600_CTX *ctx, const unsigned char *inp, size_t len)
-{
-    size_t rem = len % ctx->block_size;
-    unsigned int fc;
-
-    if (len - rem > 0) {
-        fc = ctx->pad;
-        fc |= ctx->xof_state == XOF_STATE_INIT ? S390X_KIMD_NIP : 0;
-        s390x_kimd(inp, len - rem, fc, ctx->A);
-    }
-    return rem;
-}
-
-static int shake_final_s390x(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen)
-{
-    unsigned int fc;
-
-    fc = ctx->pad | S390X_KLMD_DUFOP;
-    fc |= ctx->xof_state == XOF_STATE_INIT ? S390X_KLMD_NIP : 0;
-    s390x_klmd(ctx->buf, ctx->bufsz, out, outlen, fc, ctx->A);
-    return 1;
-}
-
-static int shake_squeeze_s390x(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen)
-{
-    unsigned int fc;
-    size_t len;
-
-    /*
-     * On the first squeeze call, finish the absorb process (incl. padding).
-     */
-    if (ctx->xof_state != XOF_STATE_SQUEEZE) {
-        fc = ctx->pad;
-        fc |= ctx->xof_state == XOF_STATE_INIT ? S390X_KLMD_NIP : 0;
-        s390x_klmd(ctx->buf, ctx->bufsz, out, outlen, fc, ctx->A);
-        ctx->bufsz = outlen % ctx->block_size;
-        /* reuse ctx->bufsz to count bytes squeezed from current sponge */
-        return 1;
-    }
-    if (ctx->bufsz != 0) {
-        len = ctx->block_size - ctx->bufsz;
-        if (outlen < len)
-            len = outlen;
-        memcpy(out, (char *)ctx->A + ctx->bufsz, len);
-        out += len;
-        outlen -= len;
-        ctx->bufsz += len;
-        if (ctx->bufsz == ctx->block_size)
-            ctx->bufsz = 0;
-    }
-    if (outlen == 0)
-        return 1;
-    s390x_klmd(NULL, 0, out, outlen, ctx->pad | S390X_KLMD_PS, ctx->A);
-    ctx->bufsz = outlen % ctx->block_size;
 
     return 1;
 }
-
-static PROV_SHA3_METHOD shake_s390x_meth = {
-    sha3_absorb_s390x,
-    shake_final_s390x,
-    shake_squeeze_s390x
-};
-#elif defined(__aarch64__) && defined(KECCAK1600_ASM)
-
-size_t SHA3_absorb_cext(uint64_t A[5][5], const unsigned char *inp, size_t len,
-    size_t r);
-/*-
- * Hardware-assisted ARMv8.2 SHA3 extension version of the absorb()
- */
-static size_t sha3_absorb_arm(KECCAK1600_CTX *ctx, const unsigned char *inp, size_t len)
-{
-    return SHA3_absorb_cext(ctx->A, inp, len, ctx->block_size);
-}
-
-static PROV_SHA3_METHOD shake_ARMSHA3_meth = {
-    sha3_absorb_arm,
-    ossl_sha3_final_default,
-    ossl_shake_squeeze_default
-};
-#endif
-
-KECCAK1600_CTX *ossl_shake256_new(void)
-{
-    KECCAK1600_CTX *ctx = OPENSSL_zalloc(sizeof(*ctx));
-
-    if (ctx == NULL)
-        return NULL;
-    ossl_keccak_init(ctx, '\x1f', 256, 0);
-    ctx->md_size = SIZE_MAX;
-    ctx->meth = shake_generic_meth;
-#if defined(S390_SHA3)
-    if (S390_SHA3_CAPABLE(S390X_SHAKE_256)) {
-        ctx->pad = S390X_SHAKE_256;
-        ctx->meth = shake_s390x_meth;
-    }
-#elif defined(__aarch64__) && defined(KECCAK1600_ASM)
-    if (OPENSSL_armcap_P & ARMV8_HAVE_SHA3_AND_WORTH_USING)
-        ctx->meth = shake_ARMSHA3_meth;
-#endif
-    return ctx;
-}
diff --git a/crypto/sha/sha3_encode.c b/crypto/sha/sha3_encode.c
deleted file mode 100644
index 1d4e38b86f..0000000000
--- a/crypto/sha/sha3_encode.c
+++ /dev/null
@@ -1,158 +0,0 @@
-/*
- * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved.
- *
- * Licensed under the Apache License 2.0 (the "License").  You may not use
- * this file except in compliance with the License.  You can obtain a copy
- * in the file LICENSE in the source distribution or at
- * https://www.openssl.org/source/license.html
- */
-
-/* including crypto/sha.h requires this for SHA256_CTX */
-#include "internal/deprecated.h"
-
-/*
- * NIST.SP.800-185 Encoding/Padding Methods used for SHA3 derived functions
- * e.g. It is used by KMAC and cSHAKE
- */
-
-#include  /* memcpy */
-#include 
-#include 
-#include "crypto/sha.h"
-#include "internal/common.h" /* ossl_assert */
-
-/* Returns the number of bytes required to store 'bits' into a byte array */
-static unsigned int get_encode_size(size_t bits)
-{
-    unsigned int cnt = 0, sz = sizeof(size_t);
-
-    while (bits && (cnt < sz)) {
-        ++cnt;
-        bits >>= 8;
-    }
-    /* If bits is zero 1 byte is required */
-    if (cnt == 0)
-        cnt = 1;
-    return cnt;
-}
-
-/*
- * Convert an integer into bytes. The number of bytes is appended
- * to the end of the buffer.
- * Returns an array of bytes 'out' of size *out_len.
- *
- * e.g if bits = 32, out[2] = { 0x20, 0x01 }
- */
-int ossl_sp800_185_right_encode(unsigned char *out,
-    size_t out_max_len, size_t *out_len,
-    size_t bits)
-{
-    unsigned int len = get_encode_size(bits);
-    int i;
-
-    if (len >= out_max_len) {
-        ERR_raise(ERR_LIB_PROV, PROV_R_LENGTH_TOO_LARGE);
-        return 0;
-    }
-
-    /* MSB's are at the start of the bytes array */
-    for (i = len - 1; i >= 0; --i) {
-        out[i] = (unsigned char)(bits & 0xFF);
-        bits >>= 8;
-    }
-    /* Tack the length onto the end */
-    out[len] = (unsigned char)len;
-
-    /* The Returned length includes the tacked on byte */
-    *out_len = len + 1;
-    return 1;
-}
-
-/*
- * Encodes a string with a left encoded length added. Note that the
- * in_len is converted to bits (* 8).
- *
- * e.g- in="KMAC" gives out[6] = { 0x01, 0x20, 0x4B, 0x4D, 0x41, 0x43 }
- *                                 len   bits    K     M     A     C
- */
-int ossl_sp800_185_encode_string(unsigned char *out,
-    size_t out_max_len, size_t *out_len,
-    const unsigned char *in, size_t in_len)
-{
-    if (in == NULL) {
-        *out_len = 0;
-    } else {
-        size_t i, bits, len, sz;
-
-        bits = 8 * in_len;
-        len = get_encode_size(bits);
-        sz = 1 + len + in_len;
-
-        if (sz > out_max_len) {
-            ERR_raise(ERR_LIB_PROV, PROV_R_LENGTH_TOO_LARGE);
-            return 0;
-        }
-
-        out[0] = (unsigned char)len;
-        for (i = len; i > 0; --i) {
-            out[i] = (bits & 0xFF);
-            bits >>= 8;
-        }
-        memcpy(out + len + 1, in, in_len);
-        *out_len = sz;
-    }
-    return 1;
-}
-
-/*
- * Returns a zero padded encoding of the inputs in1 and an optional
- * in2 (can be NULL). The padded output must be a multiple of the blocksize 'w'.
- * The value of w is in bytes (< 256).
- *
- * The returned output is:
- *    zero_padded(multiple of w, (left_encode(w) || in1 [|| in2])
- */
-int ossl_sp800_185_bytepad(unsigned char *out, size_t out_len_max, size_t *out_len,
-    const unsigned char *in1, size_t in1_len,
-    const unsigned char *in2, size_t in2_len,
-    size_t w)
-{
-    size_t len;
-    unsigned char *p = out;
-    size_t sz;
-
-    if (!ossl_assert(w <= 255))
-        return 0;
-    sz = (2 + in1_len + (in2 != NULL ? in2_len : 0) + w - 1) / w * w;
-    if (out_len_max != 0 && sz > out_len_max)
-        return 0;
-
-    if (out == NULL) {
-        if (out_len == NULL) {
-            ERR_raise(ERR_LIB_PROV, ERR_R_PASSED_NULL_PARAMETER);
-            return 0;
-        }
-        *out_len = sz;
-        return 1;
-    }
-
-    /* Left encoded w */
-    *p++ = 1;
-    *p++ = (unsigned char)w;
-    /* || in1 */
-    memcpy(p, in1, in1_len);
-    p += in1_len;
-    /* [ || in2 ] */
-    if (in2 != NULL && in2_len > 0) {
-        memcpy(p, in2, in2_len);
-        p += in2_len;
-    }
-    /* Figure out the pad size (divisible by w) */
-    len = p - out;
-    /* zero pad the end of the buffer */
-    if (sz != len)
-        memset(p, 0, sz - len);
-    if (out_len != NULL)
-        *out_len = sz;
-    return 1;
-}
diff --git a/crypto/sha/sha3_x4_avx512vl.c b/crypto/sha/sha3_x4_avx512vl.c
deleted file mode 100644
index 86a8282814..0000000000
--- a/crypto/sha/sha3_x4_avx512vl.c
+++ /dev/null
@@ -1,213 +0,0 @@
-/*
- * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved.
- * Copyright (c) 2026 Intel Corporation. All Rights Reserved.
- *
- * Licensed under the Apache License 2.0 (the "License").  You may not use
- * this file except in compliance with the License.  You can obtain a copy
- * in the file LICENSE in the source distribution or at
- * https://www.openssl.org/source/license.html
- */
-
-/*
- * SHAKE x4 multi-buffer implementation for AVX-512VL
- *
- * This file provides incremental API wrappers around the AVX-512VL
- * assembly implementations for processing 4 SHAKE instances in parallel.
- *
- * Callers should check SHA3_avx512vl_capable() before calling.
- */
-
-#include "internal/sha3.h"
-#include 
-#include 
-
-#if defined(KECCAK1600_ASM)                                                               \
-    && (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)) \
-    && !defined(OPENSSL_NO_ASM)
-
-/* External assembly function declarations */
-extern void SHA3_shake128_x4_inc_absorb_avx512vl(
-    uint64_t *state,
-    const void *in0, const void *in1,
-    const void *in2, const void *in3,
-    size_t inlen);
-
-extern void SHA3_shake256_x4_inc_absorb_avx512vl(
-    uint64_t *state,
-    const void *in0, const void *in1,
-    const void *in2, const void *in3,
-    size_t inlen);
-
-extern void SHA3_shake128_x4_inc_finalize_avx512vl(uint64_t *state);
-extern void SHA3_shake256_x4_inc_finalize_avx512vl(uint64_t *state);
-
-extern void SHA3_shake128_x4_inc_squeeze_avx512vl(
-    void *out0, void *out1,
-    void *out2, void *out3,
-    size_t outlen,
-    uint64_t *state);
-
-extern void SHA3_shake256_x4_inc_squeeze_avx512vl(
-    void *out0, void *out1,
-    void *out2, void *out3,
-    size_t outlen,
-    uint64_t *state);
-
-/* One-shot assembly function declarations */
-extern void SHA3_shake128_x4_avx512vl(
-    void *out0, void *out1,
-    void *out2, void *out3,
-    size_t outlen,
-    const void *in0, const void *in1,
-    const void *in2, const void *in3,
-    size_t inlen);
-
-extern void SHA3_shake256_x4_avx512vl(
-    void *out0, void *out1,
-    void *out2, void *out3,
-    size_t outlen,
-    const void *in0, const void *in1,
-    const void *in2, const void *in3,
-    size_t inlen);
-
-/*
- * SHAKE-128 x4 Implementation
- */
-
-void ossl_sha3_shake128_x4_inc_init_avx512vl(KECCAK1600_X4_AVX512VL_CTX *ctx)
-{
-    memset(ctx->A, 0, sizeof(ctx->A));
-    ctx->rate = SHA3_BLOCKSIZE(128);
-    ctx->finalized = 0;
-}
-
-void ossl_sha3_shake128_x4_inc_absorb_avx512vl(
-    KECCAK1600_X4_AVX512VL_CTX *ctx,
-    const void *in0, const void *in1,
-    const void *in2, const void *in3,
-    size_t inlen)
-{
-    if (ctx->finalized) {
-        /* Error: cannot absorb after finalize */
-        return;
-    }
-
-    SHA3_shake128_x4_inc_absorb_avx512vl(
-        ctx->A, in0, in1, in2, in3, inlen);
-}
-
-void ossl_sha3_shake128_x4_inc_cleanup_avx512vl(KECCAK1600_X4_AVX512VL_CTX *ctx)
-{
-    OPENSSL_cleanse(ctx, sizeof(*ctx));
-}
-
-static void ossl_sha3_shake128_x4_inc_finalize_avx512vl(KECCAK1600_X4_AVX512VL_CTX *ctx)
-{
-    if (ctx->finalized) {
-        return; /* Already finalized */
-    }
-
-    SHA3_shake128_x4_inc_finalize_avx512vl(ctx->A);
-    ctx->finalized = 1;
-}
-
-void ossl_sha3_shake128_x4_inc_squeeze_avx512vl(
-    void *out0, void *out1,
-    void *out2, void *out3,
-    size_t outlen,
-    KECCAK1600_X4_AVX512VL_CTX *ctx)
-{
-    if (!ctx->finalized) {
-        /* Auto-finalize on first squeeze */
-        ossl_sha3_shake128_x4_inc_finalize_avx512vl(ctx);
-    }
-
-    SHA3_shake128_x4_inc_squeeze_avx512vl(
-        out0, out1, out2, out3, outlen, ctx->A);
-}
-
-/*
- * SHAKE-256 x4 Implementation
- */
-
-void ossl_sha3_shake256_x4_inc_init_avx512vl(KECCAK1600_X4_AVX512VL_CTX *ctx)
-{
-    memset(ctx->A, 0, sizeof(ctx->A));
-    ctx->rate = SHA3_BLOCKSIZE(256);
-    ctx->finalized = 0;
-}
-
-void ossl_sha3_shake256_x4_inc_absorb_avx512vl(
-    KECCAK1600_X4_AVX512VL_CTX *ctx,
-    const void *in0, const void *in1,
-    const void *in2, const void *in3,
-    size_t inlen)
-{
-    if (ctx->finalized) {
-        /* Error: cannot absorb after finalize */
-        return;
-    }
-
-    SHA3_shake256_x4_inc_absorb_avx512vl(
-        ctx->A, in0, in1, in2, in3, inlen);
-}
-
-void ossl_sha3_shake256_x4_inc_cleanup_avx512vl(KECCAK1600_X4_AVX512VL_CTX *ctx)
-{
-    OPENSSL_cleanse(ctx, sizeof(*ctx));
-}
-
-static void ossl_sha3_shake256_x4_inc_finalize_avx512vl(KECCAK1600_X4_AVX512VL_CTX *ctx)
-{
-    if (ctx->finalized) {
-        return; /* Already finalized */
-    }
-
-    SHA3_shake256_x4_inc_finalize_avx512vl(ctx->A);
-    ctx->finalized = 1;
-}
-
-void ossl_sha3_shake256_x4_inc_squeeze_avx512vl(
-    void *out0, void *out1,
-    void *out2, void *out3,
-    size_t outlen,
-    KECCAK1600_X4_AVX512VL_CTX *ctx)
-{
-    if (!ctx->finalized) {
-        /* Auto-finalize on first squeeze */
-        ossl_sha3_shake256_x4_inc_finalize_avx512vl(ctx);
-    }
-
-    SHA3_shake256_x4_inc_squeeze_avx512vl(
-        out0, out1, out2, out3, outlen, ctx->A);
-}
-
-/*
- * Single-call wrapper APIs
- */
-
-void ossl_sha3_shake128_x4_avx512vl(
-    void *out0, void *out1,
-    void *out2, void *out3,
-    size_t outlen,
-    const void *in0, const void *in1,
-    const void *in2, const void *in3,
-    size_t inlen)
-{
-    SHA3_shake128_x4_avx512vl(out0, out1, out2, out3, outlen,
-        in0, in1, in2, in3, inlen);
-}
-
-void ossl_sha3_shake256_x4_avx512vl(
-    void *out0, void *out1,
-    void *out2, void *out3,
-    size_t outlen,
-    const void *in0, const void *in1,
-    const void *in2, const void *in3,
-    size_t inlen)
-{
-    SHA3_shake256_x4_avx512vl(out0, out1, out2, out3, outlen,
-        in0, in1, in2, in3, inlen);
-}
-
-#endif /* KECCAK1600_ASM && x86_64 && !OPENSSL_NO_ASM */
diff --git a/crypto/sha/sha512.c b/crypto/sha/sha512.c
index 9ba32f2926..4c3a3b6c09 100644
--- a/crypto/sha/sha512.c
+++ b/crypto/sha/sha512.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2004-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2004-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,7 +15,6 @@
 
 #include 
 #include 
-#include 
 /*-
  * IMPLEMENTATION NOTES.
  *
@@ -26,7 +25,7 @@
  *   on [aligned] data in host byte order, and one operating on data in input
  *   stream byte order;
  * - share common byte-order neutral collector and padding function
- *   implementations, crypto/md32_common.inc;
+ *   implementations, crypto/md32_common.h;
  *
  * Neither of the above applies to this SHA-512 implementation. Reasons
  * [in reverse order] are:
@@ -72,8 +71,6 @@
 #define U64(C) C##ULL
 #endif
 
-int SHA512_Update_thunk(void *cp, const unsigned char *data, size_t len);
-
 int sha512_224_init(SHA512_CTX *c)
 {
     c->h[0] = U64(0x8c3d37c819544da2);
@@ -155,11 +152,7 @@ void sha512_block_data_order_c(SHA512_CTX *ctx, const void *in, size_t num);
 #endif
     void sha512_block_data_order(SHA512_CTX *ctx, const void *in, size_t num);
 
-#define OUTPUT_RESULT(md, len)      \
-    for (n = 0; n < (len / 8); n++) \
-    md = OPENSSL_store_u64_be(md, (uint64_t)c->h[n])
-
-int SHA512_Final(unsigned char *out, SHA512_CTX *c)
+int SHA512_Final(unsigned char *md, SHA512_CTX *c)
 {
     unsigned char *p = (unsigned char *)c->u.p;
     size_t n = c->num;
@@ -177,33 +170,44 @@ int SHA512_Final(unsigned char *out, SHA512_CTX *c)
     c->u.d[SHA_LBLOCK - 2] = c->Nh;
     c->u.d[SHA_LBLOCK - 1] = c->Nl;
 #else
-    uint8_t *cu = p + sizeof(c->u) - 16;
-
-    cu = OPENSSL_store_u64_be(cu, (uint64_t)c->Nh);
-    cu = OPENSSL_store_u64_be(cu, (uint64_t)c->Nl);
+    p[sizeof(c->u) - 1] = (unsigned char)(c->Nl);
+    p[sizeof(c->u) - 2] = (unsigned char)(c->Nl >> 8);
+    p[sizeof(c->u) - 3] = (unsigned char)(c->Nl >> 16);
+    p[sizeof(c->u) - 4] = (unsigned char)(c->Nl >> 24);
+    p[sizeof(c->u) - 5] = (unsigned char)(c->Nl >> 32);
+    p[sizeof(c->u) - 6] = (unsigned char)(c->Nl >> 40);
+    p[sizeof(c->u) - 7] = (unsigned char)(c->Nl >> 48);
+    p[sizeof(c->u) - 8] = (unsigned char)(c->Nl >> 56);
+    p[sizeof(c->u) - 9] = (unsigned char)(c->Nh);
+    p[sizeof(c->u) - 10] = (unsigned char)(c->Nh >> 8);
+    p[sizeof(c->u) - 11] = (unsigned char)(c->Nh >> 16);
+    p[sizeof(c->u) - 12] = (unsigned char)(c->Nh >> 24);
+    p[sizeof(c->u) - 13] = (unsigned char)(c->Nh >> 32);
+    p[sizeof(c->u) - 14] = (unsigned char)(c->Nh >> 40);
+    p[sizeof(c->u) - 15] = (unsigned char)(c->Nh >> 48);
+    p[sizeof(c->u) - 16] = (unsigned char)(c->Nh >> 56);
 #endif
 
     sha512_block_data_order(c, p, 1);
 
-    if (out == NULL)
+    if (md == 0)
         return 0;
 
-    /* Let compiler decide if it's appropriate to unroll... */
     switch (c->md_len) {
-    case SHA256_192_DIGEST_LENGTH:
-        OUTPUT_RESULT(out, SHA256_192_DIGEST_LENGTH);
-        break;
-    case SHA256_DIGEST_LENGTH:
-        OUTPUT_RESULT(out, SHA256_DIGEST_LENGTH);
-        break;
-    case SHA384_DIGEST_LENGTH:
-        OUTPUT_RESULT(out, SHA384_DIGEST_LENGTH);
-        break;
-    case SHA512_DIGEST_LENGTH:
-        OUTPUT_RESULT(out, SHA512_DIGEST_LENGTH);
-        break;
-    case SHA224_DIGEST_LENGTH: {
-        OUTPUT_RESULT(out, SHA224_DIGEST_LENGTH);
+    /* Let compiler decide if it's appropriate to unroll... */
+    case SHA224_DIGEST_LENGTH:
+        for (n = 0; n < SHA224_DIGEST_LENGTH / 8; n++) {
+            SHA_LONG64 t = c->h[n];
+
+            *(md++) = (unsigned char)(t >> 56);
+            *(md++) = (unsigned char)(t >> 48);
+            *(md++) = (unsigned char)(t >> 40);
+            *(md++) = (unsigned char)(t >> 32);
+            *(md++) = (unsigned char)(t >> 24);
+            *(md++) = (unsigned char)(t >> 16);
+            *(md++) = (unsigned char)(t >> 8);
+            *(md++) = (unsigned char)(t);
+        }
         /*
          * For 224 bits, there are four bytes left over that have to be
          * processed separately.
@@ -211,13 +215,54 @@ int SHA512_Final(unsigned char *out, SHA512_CTX *c)
         {
             SHA_LONG64 t = c->h[SHA224_DIGEST_LENGTH / 8];
 
-            *(out++) = (unsigned char)(t >> 56);
-            *(out++) = (unsigned char)(t >> 48);
-            *(out++) = (unsigned char)(t >> 40);
-            *(out++) = (unsigned char)(t >> 32);
+            *(md++) = (unsigned char)(t >> 56);
+            *(md++) = (unsigned char)(t >> 48);
+            *(md++) = (unsigned char)(t >> 40);
+            *(md++) = (unsigned char)(t >> 32);
+        }
+        break;
+    case SHA256_DIGEST_LENGTH:
+        for (n = 0; n < SHA256_DIGEST_LENGTH / 8; n++) {
+            SHA_LONG64 t = c->h[n];
+
+            *(md++) = (unsigned char)(t >> 56);
+            *(md++) = (unsigned char)(t >> 48);
+            *(md++) = (unsigned char)(t >> 40);
+            *(md++) = (unsigned char)(t >> 32);
+            *(md++) = (unsigned char)(t >> 24);
+            *(md++) = (unsigned char)(t >> 16);
+            *(md++) = (unsigned char)(t >> 8);
+            *(md++) = (unsigned char)(t);
+        }
+        break;
+    case SHA384_DIGEST_LENGTH:
+        for (n = 0; n < SHA384_DIGEST_LENGTH / 8; n++) {
+            SHA_LONG64 t = c->h[n];
+
+            *(md++) = (unsigned char)(t >> 56);
+            *(md++) = (unsigned char)(t >> 48);
+            *(md++) = (unsigned char)(t >> 40);
+            *(md++) = (unsigned char)(t >> 32);
+            *(md++) = (unsigned char)(t >> 24);
+            *(md++) = (unsigned char)(t >> 16);
+            *(md++) = (unsigned char)(t >> 8);
+            *(md++) = (unsigned char)(t);
+        }
+        break;
+    case SHA512_DIGEST_LENGTH:
+        for (n = 0; n < SHA512_DIGEST_LENGTH / 8; n++) {
+            SHA_LONG64 t = c->h[n];
+
+            *(md++) = (unsigned char)(t >> 56);
+            *(md++) = (unsigned char)(t >> 48);
+            *(md++) = (unsigned char)(t >> 40);
+            *(md++) = (unsigned char)(t >> 32);
+            *(md++) = (unsigned char)(t >> 24);
+            *(md++) = (unsigned char)(t >> 16);
+            *(md++) = (unsigned char)(t >> 8);
+            *(md++) = (unsigned char)(t);
         }
         break;
-    }
     /* ... as well as make sure md_len is not abused. */
     default:
         return 0;
@@ -231,11 +276,11 @@ int SHA384_Final(unsigned char *md, SHA512_CTX *c)
     return SHA512_Final(md, c);
 }
 
-int SHA512_Update_thunk(void *cp, const unsigned char *data, size_t len)
+int SHA512_Update(SHA512_CTX *c, const void *_data, size_t len)
 {
-    SHA512_CTX *c = (SHA512_CTX *)cp;
     SHA_LONG64 l;
     unsigned char *p = c->u.p;
+    const unsigned char *data = (const unsigned char *)_data;
 
     if (len == 0)
         return 1;
@@ -279,14 +324,9 @@ int SHA512_Update_thunk(void *cp, const unsigned char *data, size_t len)
     return 1;
 }
 
-int SHA512_Update(SHA512_CTX *c, const void *_data, size_t len)
-{
-    return SHA512_Update_thunk((void *)c, (const unsigned char *)_data, len);
-}
-
 int SHA384_Update(SHA512_CTX *c, const void *data, size_t len)
 {
-    return SHA512_Update_thunk((void *)c, (const unsigned char *)data, len);
+    return SHA512_Update(c, data, len);
 }
 
 void SHA512_Transform(SHA512_CTX *c, const unsigned char *data)
@@ -343,7 +383,7 @@ static const SHA_LONG64 K512[80] = {
 };
 
 #ifndef PEDANTIC
-#if defined(__GNUC__) && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM)
+#if defined(__GNUC__) && __GNUC__ >= 2 && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM)
 #if defined(__x86_64) || defined(__x86_64__)
 #define ROTR(a, n) ({ SHA_LONG64 ret;             \
                                 asm ("rorq %1,%0"       \
diff --git a/crypto/sha/sha_local.h b/crypto/sha/sha_local.h
index afe6df66d4..3879c57526 100644
--- a/crypto/sha/sha_local.h
+++ b/crypto/sha/sha_local.h
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_SHA_SHA_LOCAL_H)
-#define OSSL_LIBCRYPTO_SHA_SHA_LOCAL_H
-
 #include 
 #include 
 
@@ -37,8 +34,7 @@
         (void)HOST_l2c(ll, (s)); \
     } while (0)
 
-#define HASH_UPDATE_THUNK
-#define HASH_UPDATE SHA1_Update_thunk
+#define HASH_UPDATE SHA1_Update
 #define HASH_TRANSFORM SHA1_Transform
 #define HASH_FINAL SHA1_Final
 #define HASH_INIT SHA1_Init
@@ -52,15 +48,7 @@ static void sha1_block_data_order(SHA_CTX *c, const void *p, size_t num);
 void sha1_block_data_order(SHA_CTX *c, const void *p, size_t num);
 #endif
 
-/* clang-format off */
-#include "crypto/md32_common.inc"
-/* clang-format on */
-#undef HASH_UPDATE_THUNK
-
-int SHA1_Update(SHA_CTX *c, const void *data, size_t len)
-{
-    return SHA1_Update_thunk((void *)c, (const unsigned char *)data, len);
-}
+#include "crypto/md32_common.h"
 
 #define INIT_DATA_h0 0x67452301UL
 #define INIT_DATA_h1 0xefcdab89UL
@@ -443,5 +431,3 @@ static void HASH_BLOCK_DATA_ORDER(SHA_CTX *c, const void *p, size_t num)
 #endif
 
 #endif
-
-#endif /* !defined(OSSL_LIBCRYPTO_SHA_SHA_LOCAL_H) */
diff --git a/crypto/sha/sha_loongarch.c b/crypto/sha/sha_loongarch.c
deleted file mode 100644
index 1576e6f493..0000000000
--- a/crypto/sha/sha_loongarch.c
+++ /dev/null
@@ -1,41 +0,0 @@
-/*
- * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved.
- *
- * Licensed under the Apache License 2.0 (the "License").  You may not use
- * this file except in compliance with the License.  You can obtain a copy
- * in the file LICENSE in the source distribution or at
- * https://www.openssl.org/source/license.html
- */
-
-#include 
-#include 
-
-#include 
-#include 
-#include "arch/loongarch_arch.h"
-
-void sha256_block_data_order_la64v100(void *ctx, const void *in, size_t num);
-void sha256_block_data_order_lsx(void *ctx, const void *in, size_t num);
-void sha256_block_data_order(void *ctx, const void *in, size_t num);
-
-void sha256_block_data_order(void *ctx, const void *in, size_t num)
-{
-    if (OPENSSL_loongarch_hwcap_P & LOONGARCH_HWCAP_LSX) {
-        sha256_block_data_order_lsx(ctx, in, num);
-    } else {
-        sha256_block_data_order_la64v100(ctx, in, num);
-    }
-}
-
-void sha512_block_data_order_la64v100(void *ctx, const void *in, size_t num);
-void sha512_block_data_order_lsx(void *ctx, const void *in, size_t num);
-void sha512_block_data_order(void *ctx, const void *in, size_t num);
-
-void sha512_block_data_order(void *ctx, const void *in, size_t num)
-{
-    if (OPENSSL_loongarch_hwcap_P & LOONGARCH_HWCAP_LSX) {
-        sha512_block_data_order_lsx(ctx, in, num);
-    } else {
-        sha512_block_data_order_la64v100(ctx, in, num);
-    }
-}
diff --git a/crypto/sha/sha_ppc.c b/crypto/sha/sha_ppc.c
index 0e5c5c5709..9853a2321a 100644
--- a/crypto/sha/sha_ppc.c
+++ b/crypto/sha/sha_ppc.c
@@ -12,7 +12,7 @@
 
 #include 
 #include 
-#include "arch/ppc_arch.h"
+#include "crypto/ppc_arch.h"
 
 void sha256_block_p8(void *ctx, const void *inp, size_t len);
 void sha256_block_ppc(void *ctx, const void *inp, size_t len);
diff --git a/crypto/sha/sha_riscv.c b/crypto/sha/sha_riscv.c
index 100ecacdde..5a0eaaf11b 100644
--- a/crypto/sha/sha_riscv.c
+++ b/crypto/sha/sha_riscv.c
@@ -12,15 +12,15 @@
 
 #include 
 #include 
-#include "arch/riscv_arch.h"
+#include "crypto/riscv_arch.h"
 
 void sha256_block_data_order_zvkb_zvknha_or_zvknhb(void *ctx, const void *in,
     size_t num);
 void sha256_block_data_order_zbb(void *ctx, const void *in, size_t num);
 void sha256_block_data_order_riscv64(void *ctx, const void *in, size_t num);
-void sha256_block_data_order(void *ctx, const void *in, size_t num);
+void sha256_block_data_order(SHA256_CTX *ctx, const void *in, size_t num);
 
-void sha256_block_data_order(void *ctx, const void *in, size_t num)
+void sha256_block_data_order(SHA256_CTX *ctx, const void *in, size_t num)
 {
     if (RISCV_HAS_ZVKB() && (RISCV_HAS_ZVKNHA() || RISCV_HAS_ZVKNHB()) && riscv_vlen() >= 128) {
         sha256_block_data_order_zvkb_zvknha_or_zvknhb(ctx, in, num);
@@ -34,9 +34,9 @@ void sha256_block_data_order(void *ctx, const void *in, size_t num)
 void sha512_block_data_order_zvkb_zvknhb(void *ctx, const void *in, size_t num);
 void sha512_block_data_order_zbb(void *ctx, const void *in, size_t num);
 void sha512_block_data_order_c(void *ctx, const void *in, size_t num);
-void sha512_block_data_order(void *ctx, const void *in, size_t num);
+void sha512_block_data_order(SHA512_CTX *ctx, const void *in, size_t num);
 
-void sha512_block_data_order(void *ctx, const void *in, size_t num)
+void sha512_block_data_order(SHA512_CTX *ctx, const void *in, size_t num)
 {
     if (RISCV_HAS_ZVKB_AND_ZVKNHB() && riscv_vlen() >= 128) {
         sha512_block_data_order_zvkb_zvknhb(ctx, in, num);
diff --git a/crypto/sleep.c b/crypto/sleep.c
index 3d8be852c9..9273995be6 100644
--- a/crypto/sleep.c
+++ b/crypto/sleep.c
@@ -67,6 +67,7 @@ static void ossl_sleep_millis(uint64_t millis)
 
 #endif
 #elif defined(_WIN32) && !defined(OPENSSL_SYS_UEFI)
+#include 
 
 static void ossl_sleep_millis(uint64_t millis)
 {
diff --git a/crypto/slh_dsa/slh_adrs.h b/crypto/slh_dsa/slh_adrs.h
index f07d7e8b55..556d0ad286 100644
--- a/crypto/slh_dsa/slh_adrs.h
+++ b/crypto/slh_dsa/slh_adrs.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_SLH_DSA_SLH_ADRS_H)
-#define OSSL_LIBCRYPTO_SLH_DSA_SLH_ADRS_H
-
 #include 
 
 /*
@@ -72,5 +69,3 @@ typedef struct slh_adrs_func_st {
 } SLH_ADRS_FUNC;
 
 const SLH_ADRS_FUNC *ossl_slh_get_adrs_fn(int is_compressed);
-
-#endif /* !defined(OSSL_LIBCRYPTO_SLH_DSA_SLH_ADRS_H) */
diff --git a/crypto/slh_dsa/slh_dsa.c b/crypto/slh_dsa/slh_dsa.c
index 6519e8640f..77c20daceb 100644
--- a/crypto/slh_dsa/slh_dsa.c
+++ b/crypto/slh_dsa/slh_dsa.c
@@ -119,11 +119,11 @@ static int slh_sign_internal(SLH_DSA_HASH_CTX *hctx,
         /* Generate ht signature and append to the SLH-DSA signature */
         && ossl_slh_ht_sign(hctx, pk_fors, sk_seed, pk_seed, tree_id, leaf_id,
             wpkt);
+    *sig_len = sig_len_expected;
+    ret = 1;
 err:
     if (!WPACKET_finish(wpkt))
         ret = 0;
-    if (ret)
-        *sig_len = sig_len_expected;
     return ret;
 }
 
@@ -232,7 +232,6 @@ static uint8_t *msg_encode(const uint8_t *msg, size_t msg_len,
     const uint8_t *ctx, size_t ctx_len, int encode,
     uint8_t *tmp, size_t tmp_len, size_t *out_len)
 {
-    WPACKET pkt;
     uint8_t *encoded = NULL;
     size_t encoded_len;
 
@@ -241,14 +240,11 @@ static uint8_t *msg_encode(const uint8_t *msg, size_t msg_len,
         *out_len = msg_len;
         return (uint8_t *)msg;
     }
-
     if (ctx_len > SLH_DSA_MAX_CONTEXT_STRING_LEN)
         return NULL;
 
     /* Pure encoding */
     encoded_len = 1 + 1 + ctx_len + msg_len;
-    if (encoded_len < msg_len) /* Check for overflow */
-        return NULL;
     *out_len = encoded_len;
     if (encoded_len <= tmp_len) {
         encoded = tmp;
@@ -257,17 +253,10 @@ static uint8_t *msg_encode(const uint8_t *msg, size_t msg_len,
         if (encoded == NULL)
             return NULL;
     }
-    if (!WPACKET_init_static_len(&pkt, encoded, encoded_len, 0)
-        || !WPACKET_put_bytes_u8(&pkt, 0)
-        || !WPACKET_put_bytes_u8(&pkt, (uint8_t)ctx_len)
-        || !WPACKET_memcpy(&pkt, ctx, ctx_len)
-        || !WPACKET_memcpy(&pkt, msg, msg_len)
-        || !WPACKET_finish(&pkt)) {
-        if (encoded != tmp)
-            OPENSSL_free(encoded);
-        encoded = NULL;
-        WPACKET_cleanup(&pkt);
-    }
+    encoded[0] = 0;
+    encoded[1] = (uint8_t)ctx_len;
+    memcpy(&encoded[2], ctx, ctx_len);
+    memcpy(&encoded[2 + ctx_len], msg, msg_len);
     return encoded;
 }
 
diff --git a/crypto/slh_dsa/slh_dsa_hash_ctx.c b/crypto/slh_dsa/slh_dsa_hash_ctx.c
index 0c7282af87..9dca01acf5 100644
--- a/crypto/slh_dsa/slh_dsa_hash_ctx.c
+++ b/crypto/slh_dsa/slh_dsa_hash_ctx.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -11,8 +11,6 @@
 #include "slh_dsa_local.h"
 #include "slh_dsa_key.h"
 #include 
-#include 
-#include "crypto/evp.h"
 
 /**
  * @brief Create a SLH_DSA_HASH_CTX that contains parameters, functions, and
@@ -33,10 +31,23 @@ SLH_DSA_HASH_CTX *ossl_slh_dsa_hash_ctx_new(const SLH_DSA_KEY *key)
         return NULL;
 
     ret->key = key;
-    if (key->pub != NULL
-        && !ossl_slh_dsa_hash_ctx_prehash_pk_seed(ret, SLH_DSA_PK_SEED(key), key->params->n))
+    ret->md_ctx = EVP_MD_CTX_new();
+    if (ret->md_ctx == NULL)
         goto err;
-    if (!key->params->is_shake) {
+    if (EVP_DigestInit_ex2(ret->md_ctx, key->md, NULL) != 1)
+        goto err;
+    if (key->md_big != NULL) {
+        /* Gets here for SHA2 algorithms */
+        if (key->md_big == key->md) {
+            ret->md_big_ctx = ret->md_ctx;
+        } else {
+            /* Only gets here for SHA2 */
+            ret->md_big_ctx = EVP_MD_CTX_new();
+            if (ret->md_big_ctx == NULL)
+                goto err;
+            if (EVP_DigestInit_ex2(ret->md_big_ctx, key->md_big, NULL) != 1)
+                goto err;
+        }
         if (key->hmac != NULL) {
             ret->hmac_ctx = EVP_MAC_CTX_new(key->hmac);
             if (ret->hmac_ctx == NULL)
@@ -65,8 +76,17 @@ SLH_DSA_HASH_CTX *ossl_slh_dsa_hash_ctx_dup(const SLH_DSA_HASH_CTX *src)
     /* Note that the key is not ref counted, since it does not own the key */
     ret->key = src->key;
 
-    if (!src->key->hash_func->prehash_dup(ret, src))
+    if (src->md_ctx != NULL
+        && (ret->md_ctx = EVP_MD_CTX_dup(src->md_ctx)) == NULL)
         goto err;
+    if (src->md_big_ctx != NULL) {
+        if (src->md_big_ctx != src->md_ctx) {
+            if ((ret->md_big_ctx = EVP_MD_CTX_dup(src->md_big_ctx)) == NULL)
+                goto err;
+        } else {
+            ret->md_big_ctx = ret->md_ctx;
+        }
+    }
     if (src->hmac_ctx != NULL
         && (ret->hmac_ctx = EVP_MAC_CTX_dup(src->hmac_ctx)) == NULL)
         goto err;
@@ -76,19 +96,6 @@ err:
     return NULL;
 }
 
-/**
- * @brief Cache the pk seed.
- * SLH_DSA performs a large number of hash operations that consist of either
- *  SHAKE256(PK.seed || .. ) OR
- *  SHA256(PK.seed || toByte(0, 64 - n) || ...)
- * So cache this value and reuse it as the starting point for many hash functions.
- */
-int ossl_slh_dsa_hash_ctx_prehash_pk_seed(SLH_DSA_HASH_CTX *ctx,
-    const uint8_t *pkseed, size_t n)
-{
-    return ctx->key->hash_func->prehash_pk_seed(ctx, pkseed, n);
-}
-
 /**
  * @brief Destroy a SLH_DSA_HASH_CTX
  *
@@ -98,8 +105,9 @@ void ossl_slh_dsa_hash_ctx_free(SLH_DSA_HASH_CTX *ctx)
 {
     if (ctx == NULL)
         return;
-    OPENSSL_free(ctx->shactx);
-    OPENSSL_free(ctx->shactx_pkseed);
+    EVP_MD_CTX_free(ctx->md_ctx);
+    if (ctx->md_big_ctx != ctx->md_ctx)
+        EVP_MD_CTX_free(ctx->md_big_ctx);
     EVP_MAC_CTX_free(ctx->hmac_ctx);
     OPENSSL_free(ctx);
 }
diff --git a/crypto/slh_dsa/slh_dsa_key.c b/crypto/slh_dsa/slh_dsa_key.c
index f99a00efb9..9df2d75a86 100644
--- a/crypto/slh_dsa/slh_dsa_key.c
+++ b/crypto/slh_dsa/slh_dsa_key.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -23,11 +23,12 @@ static int slh_dsa_compute_pk_root(SLH_DSA_HASH_CTX *ctx, SLH_DSA_KEY *out, int
 static void slh_dsa_key_hash_cleanup(SLH_DSA_KEY *key)
 {
     OPENSSL_free(key->propq);
-    EVP_MD_free(key->md_sha512);
+    if (key->md_big != key->md)
+        EVP_MD_free(key->md_big);
+    key->md_big = NULL;
     EVP_MD_free(key->md);
     EVP_MAC_free(key->hmac);
     key->md = NULL;
-    key->md_sha512 = NULL;
 }
 
 static int slh_dsa_key_hash_init(SLH_DSA_KEY *key)
@@ -44,10 +45,13 @@ static int slh_dsa_key_hash_init(SLH_DSA_KEY *key)
      * SHAKE algorithm(s) use SHAKE for all functions.
      */
     if (is_shake == 0) {
-        if (security_category != 1) {
+        if (security_category == 1) {
+            /* For category 1 SHA2-256 is used for all hash operations */
+            key->md_big = key->md;
+        } else {
             /* Security categories 3 & 5 also need SHA-512 */
-            key->md_sha512 = EVP_MD_fetch(key->libctx, "SHA2-512", key->propq);
-            if (key->md_sha512 == NULL)
+            key->md_big = EVP_MD_fetch(key->libctx, "SHA2-512", key->propq);
+            if (key->md_big == NULL)
                 goto err;
         }
         key->hmac = EVP_MAC_fetch(key->libctx, "HMAC", key->propq);
@@ -55,16 +59,17 @@ static int slh_dsa_key_hash_init(SLH_DSA_KEY *key)
             goto err;
     }
     key->adrs_func = ossl_slh_get_adrs_fn(is_shake == 0);
-    key->hash_func = ossl_slh_get_hash_fn(is_shake, security_category);
+    key->hash_func = ossl_slh_get_hash_fn(is_shake);
     return 1;
 err:
+    slh_dsa_key_hash_cleanup(key);
     return 0;
 }
 
 static void slh_dsa_key_hash_dup(SLH_DSA_KEY *dst, const SLH_DSA_KEY *src)
 {
-    if (src->md_sha512 != NULL)
-        EVP_MD_up_ref(src->md_sha512);
+    if (src->md_big != NULL && src->md_big != src->md)
+        EVP_MD_up_ref(src->md_big);
     if (src->md != NULL)
         EVP_MD_up_ref(src->md);
     if (src->hmac != NULL)
@@ -201,7 +206,7 @@ int ossl_slh_dsa_key_equal(const SLH_DSA_KEY *key1, const SLH_DSA_KEY *key2,
         if (!key_checked
             && (selection & OSSL_KEYMGMT_SELECT_PRIVATE_KEY) != 0) {
             if (key1->has_priv && key2->has_priv) {
-                if (CRYPTO_memcmp(key1->priv, key2->priv,
+                if (memcmp(key1->priv, key2->priv,
                         key1->params->pk_len)
                     != 0)
                     return 0;
@@ -377,9 +382,7 @@ int ossl_slh_dsa_generate_key(SLH_DSA_HASH_CTX *ctx, SLH_DSA_KEY *out,
             || RAND_bytes_ex(lib_ctx, pub, pk_seed_len, 0) <= 0)
             goto err;
     }
-
-    if (!ossl_slh_dsa_hash_ctx_prehash_pk_seed(ctx, pub, pk_seed_len)
-        || !slh_dsa_compute_pk_root(ctx, out, 0))
+    if (!slh_dsa_compute_pk_root(ctx, out, 0))
         goto err;
     out->pub = pub;
     out->has_priv = 1;
diff --git a/crypto/slh_dsa/slh_dsa_key.h b/crypto/slh_dsa/slh_dsa_key.h
index 6f7554a315..37b7aa1b16 100644
--- a/crypto/slh_dsa/slh_dsa_key.h
+++ b/crypto/slh_dsa/slh_dsa_key.h
@@ -1,5 +1,5 @@
 /*
- * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,18 +7,8 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_SLH_DSA_SLH_DSA_KEY_H)
-#define OSSL_LIBCRYPTO_SLH_DSA_SLH_DSA_KEY_H
-
-#include 
 #include 
 
-#include "crypto/slh_dsa.h"
-
-#include "slh_params.h"
-#include "slh_adrs.h"
-#include "slh_hash.h"
-
 #define SLH_DSA_MAX_N 32
 #define SLH_DSA_SK_SEED(key) ((key)->priv)
 #define SLH_DSA_SK_PRF(key) ((key)->priv + (key)->params->n)
@@ -54,9 +44,7 @@ struct slh_dsa_key_st {
     const SLH_HASH_FUNC *hash_func;
     /* See FIPS 205 Section 11.1 */
 
-    EVP_MD *md; /* Used for general SHAKE and SHA-256 hashes */
-    EVP_MD *md_sha512; /* Used for SHA-512 hashes */
+    EVP_MD *md; /* Used for SHAKE and SHA-256 */
+    EVP_MD *md_big; /* Used for SHA-256 or SHA-512 */
     EVP_MAC *hmac;
 };
-
-#endif /* !defined(OSSL_LIBCRYPTO_SLH_DSA_SLH_DSA_KEY_H) */
diff --git a/crypto/slh_dsa/slh_dsa_local.h b/crypto/slh_dsa/slh_dsa_local.h
index f11bf097cd..57dfc1eb13 100644
--- a/crypto/slh_dsa/slh_dsa_local.h
+++ b/crypto/slh_dsa/slh_dsa_local.h
@@ -1,5 +1,5 @@
 /*
- * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_SLH_DSA_SLH_DSA_LOCAL_H)
-#define OSSL_LIBCRYPTO_SLH_DSA_SLH_DSA_LOCAL_H
-
 #include "crypto/slh_dsa.h"
 #include "slh_hash.h"
 #include "slh_params.h"
@@ -50,8 +47,8 @@
  */
 struct slh_dsa_hash_ctx_st {
     const SLH_DSA_KEY *key; /* This key is not owned by this object */
-    void *shactx; /* A low level SHAKE object */
-    void *shactx_pkseed; /* A low level SHAKE or SHA256 object with PK.seed hashed in it */
+    EVP_MD_CTX *md_ctx; /* Either SHAKE OR SHA-256 */
+    EVP_MD_CTX *md_big_ctx; /* Either SHA-512 or points to |md_ctx| for SHA-256*/
     EVP_MAC_CTX *hmac_ctx; /* required by SHA algorithms for PRFmsg() */
     int hmac_digest_used; /* Used for lazy init of hmac_ctx digest */
 };
@@ -66,11 +63,11 @@ __owur int ossl_slh_wots_pk_from_sig(SLH_DSA_HASH_CTX *ctx,
     PACKET *sig_rpkt, const uint8_t *msg,
     const uint8_t *pk_seed, uint8_t *adrs,
     uint8_t *pk_out, size_t pk_out_len);
+
 __owur int ossl_slh_xmss_node(SLH_DSA_HASH_CTX *ctx, const uint8_t *sk_seed,
     uint32_t node_id, uint32_t height,
     const uint8_t *pk_seed, uint8_t *adrs,
     uint8_t *pk_out, size_t pk_out_len);
-
 __owur int ossl_slh_xmss_sign(SLH_DSA_HASH_CTX *ctx, const uint8_t *msg,
     const uint8_t *sk_seed, uint32_t node_id,
     const uint8_t *pk_seed, uint8_t *adrs,
@@ -96,5 +93,3 @@ __owur int ossl_slh_fors_pk_from_sig(SLH_DSA_HASH_CTX *ctx, PACKET *sig_rpkt,
     const uint8_t *md, const uint8_t *pk_seed,
     uint8_t *adrs,
     uint8_t *pk_out, size_t pk_out_len);
-
-#endif /* !defined(OSSL_LIBCRYPTO_SLH_DSA_SLH_DSA_LOCAL_H) */
diff --git a/crypto/slh_dsa/slh_fors.c b/crypto/slh_dsa/slh_fors.c
index 10335cc5df..78587589db 100644
--- a/crypto/slh_dsa/slh_fors.c
+++ b/crypto/slh_dsa/slh_fors.c
@@ -156,7 +156,7 @@ int ossl_slh_fors_sign(SLH_DSA_HASH_CTX *ctx, const uint8_t *md,
         /*
          * Give each of the k trees a unique range at each level.
          * e.g. If we have 4096 leaf nodes (2^a = 2^12) for each tree
-         * i will use indexes from 4096 * i + (0..4095) for its bottom level.
+         * tree i will use indexes from 4096 * i + (0..4095) for its bottom level.
          * For the next level up from the bottom there would be 2048 nodes
          * (so tree i uses indexes 2048 * i + (0...2047) for this level)
          */
diff --git a/crypto/slh_dsa/slh_hash.c b/crypto/slh_dsa/slh_hash.c
index 6e25371f29..951019819c 100644
--- a/crypto/slh_dsa/slh_hash.c
+++ b/crypto/slh_dsa/slh_hash.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -16,177 +16,156 @@
 #include "slh_dsa_local.h"
 #include "slh_dsa_key.h"
 
-#include "openssl/sha.h"
-#include "internal/sha3.h"
-#include "crypto/evp.h"
-#include "crypto/sha.h"
-
 #define MAX_DIGEST_SIZE 64 /* SHA-512 is used for security category 3 & 5 */
-#define NIBBLE_MASK 15
-
-/* Most hash functions in SLH-DSA truncate the output */
-#define sha256_final(ctx, out, outlen)    \
-    (ctx)->md_len = (unsigned int)outlen; \
-    SHA256_Final(out, ctx)
-
-#define sha512_final(ctx, out, outlen)    \
-    (ctx)->md_len = (unsigned int)outlen; \
-    SHA512_Final(out, ctx)
-
-static OSSL_SLH_HASHFUNC_PRF slh_prf_sha256;
-static OSSL_SLH_HASHFUNC_PRF slh_prf_shake;
-
-static OSSL_SLH_HASHFUNC_F slh_f_sha256;
-static OSSL_SLH_HASHFUNC_F slh_f_shake;
 
+static OSSL_SLH_HASHFUNC_H_MSG slh_hmsg_sha2;
+static OSSL_SLH_HASHFUNC_PRF slh_prf_sha2;
 static OSSL_SLH_HASHFUNC_PRF_MSG slh_prf_msg_sha2;
-static OSSL_SLH_HASHFUNC_PRF_MSG slh_prf_msg_shake;
+static OSSL_SLH_HASHFUNC_F slh_f_sha2;
+static OSSL_SLH_HASHFUNC_H slh_h_sha2;
+static OSSL_SLH_HASHFUNC_T slh_t_sha2;
 
-static OSSL_SLH_HASHFUNC_H_MSG slh_hmsg_sha256;
-static OSSL_SLH_HASHFUNC_H_MSG slh_hmsg_sha512;
 static OSSL_SLH_HASHFUNC_H_MSG slh_hmsg_shake;
-
-static OSSL_SLH_HASHFUNC_H slh_h_sha256;
-static OSSL_SLH_HASHFUNC_H slh_h_sha512;
+static OSSL_SLH_HASHFUNC_PRF slh_prf_shake;
+static OSSL_SLH_HASHFUNC_PRF_MSG slh_prf_msg_shake;
+static OSSL_SLH_HASHFUNC_F slh_f_shake;
 static OSSL_SLH_HASHFUNC_H slh_h_shake;
-static OSSL_SLH_HASHFUNC_T slh_t_sha256;
-static OSSL_SLH_HASHFUNC_T slh_t_sha512;
-static OSSL_SLH_HASHFUNC_wots_pk_gen slh_wots_pk_gen_sha2;
-static OSSL_SLH_HASHFUNC_wots_pk_gen slh_wots_pk_gen_shake;
+static OSSL_SLH_HASHFUNC_T slh_t_shake;
 
-static const uint8_t zeros[128] = { 0 };
+static ossl_inline int xof_digest_3(EVP_MD_CTX *ctx,
+    const uint8_t *in1, size_t in1_len,
+    const uint8_t *in2, size_t in2_len,
+    const uint8_t *in3, size_t in3_len,
+    uint8_t *out, size_t out_len)
+{
+    return (EVP_DigestInit_ex2(ctx, NULL, NULL) == 1
+        && EVP_DigestUpdate(ctx, in1, in1_len) == 1
+        && EVP_DigestUpdate(ctx, in2, in2_len) == 1
+        && EVP_DigestUpdate(ctx, in3, in3_len) == 1
+        && EVP_DigestFinalXOF(ctx, out, out_len) == 1);
+}
+
+static ossl_inline int xof_digest_4(EVP_MD_CTX *ctx,
+    const uint8_t *in1, size_t in1_len,
+    const uint8_t *in2, size_t in2_len,
+    const uint8_t *in3, size_t in3_len,
+    const uint8_t *in4, size_t in4_len,
+    uint8_t *out, size_t out_len)
+{
+    return (EVP_DigestInit_ex2(ctx, NULL, NULL) == 1
+        && EVP_DigestUpdate(ctx, in1, in1_len) == 1
+        && EVP_DigestUpdate(ctx, in2, in2_len) == 1
+        && EVP_DigestUpdate(ctx, in3, in3_len) == 1
+        && EVP_DigestUpdate(ctx, in4, in4_len) == 1
+        && EVP_DigestFinalXOF(ctx, out, out_len) == 1);
+}
 
 /* See FIPS 205 Section 11.1 */
 static int
-slh_hmsg_shake(SLH_DSA_HASH_CTX *hctx, const uint8_t *r,
+slh_hmsg_shake(SLH_DSA_HASH_CTX *ctx, const uint8_t *r,
     const uint8_t *pk_seed, const uint8_t *pk_root,
     const uint8_t *msg, size_t msg_len,
     uint8_t *out, size_t out_len)
 {
-    KECCAK1600_CTX *sctx = (KECCAK1600_CTX *)(hctx->shactx);
-    const SLH_DSA_PARAMS *params = hctx->key->params;
+    const SLH_DSA_PARAMS *params = ctx->key->params;
     size_t m = params->m;
     size_t n = params->n;
 
-    ossl_sha3_reset(sctx);
-    ossl_sha3_absorb(sctx, r, n);
-    ossl_sha3_absorb(sctx, pk_seed, n);
-    ossl_sha3_absorb(sctx, pk_root, n);
-    ossl_sha3_absorb(sctx, msg, msg_len);
-    ossl_sha3_squeeze(sctx, out, m);
-    return 1;
+    return xof_digest_4(ctx->md_ctx, r, n, pk_seed, n, pk_root, n,
+        msg, msg_len, out, m);
 }
 
 static int
-slh_prf_msg_shake(SLH_DSA_HASH_CTX *hctx, const uint8_t *sk_prf,
+slh_prf_shake(SLH_DSA_HASH_CTX *ctx,
+    const uint8_t *pk_seed, const uint8_t *sk_seed,
+    const uint8_t *adrs, uint8_t *out, size_t out_len)
+{
+    const SLH_DSA_PARAMS *params = ctx->key->params;
+    size_t n = params->n;
+
+    return xof_digest_3(ctx->md_ctx, pk_seed, n, adrs, SLH_ADRS_SIZE,
+        sk_seed, n, out, n);
+}
+
+static int
+slh_prf_msg_shake(SLH_DSA_HASH_CTX *ctx, const uint8_t *sk_prf,
     const uint8_t *opt_rand, const uint8_t *msg, size_t msg_len,
     WPACKET *pkt)
 {
     unsigned char out[SLH_MAX_N];
-    const SLH_DSA_PARAMS *params = hctx->key->params;
+    const SLH_DSA_PARAMS *params = ctx->key->params;
     size_t n = params->n;
-    KECCAK1600_CTX *sctx = (KECCAK1600_CTX *)(hctx->shactx);
 
-    ossl_sha3_reset(sctx);
-    ossl_sha3_absorb(sctx, sk_prf, n);
-    ossl_sha3_absorb(sctx, opt_rand, n);
-    ossl_sha3_absorb(sctx, msg, msg_len);
-    ossl_sha3_squeeze(sctx, out, n);
-    return WPACKET_memcpy(pkt, out, n);
+    return xof_digest_3(ctx->md_ctx, sk_prf, n, opt_rand, n, msg, msg_len, out, n)
+        && WPACKET_memcpy(pkt, out, n);
 }
 
 static int
-slh_f_shake(SLH_DSA_HASH_CTX *hctx, const uint8_t *pk_seed, const uint8_t *adrs,
+slh_f_shake(SLH_DSA_HASH_CTX *ctx, const uint8_t *pk_seed, const uint8_t *adrs,
     const uint8_t *m1, size_t m1_len, uint8_t *out, size_t out_len)
 {
-    const SLH_DSA_PARAMS *params = hctx->key->params;
+    const SLH_DSA_PARAMS *params = ctx->key->params;
     size_t n = params->n;
-    KECCAK1600_CTX sctx = *((KECCAK1600_CTX *)(hctx->shactx_pkseed));
 
-    ossl_sha3_absorb(&sctx, adrs, SLH_ADRS_SIZE);
-    ossl_sha3_absorb(&sctx, m1, m1_len);
-    ossl_sha3_squeeze(&sctx, out, n);
-    return 1;
+    return xof_digest_3(ctx->md_ctx, pk_seed, n, adrs, SLH_ADRS_SIZE, m1, m1_len, out, n);
 }
 
 static int
-slh_prf_shake(SLH_DSA_HASH_CTX *hctx,
-    const uint8_t *pk_seed, const uint8_t *sk_seed,
-    const uint8_t *adrs, uint8_t *out, size_t out_len)
-{
-    const SLH_DSA_PARAMS *params = hctx->key->params;
-    size_t n = params->n;
-    KECCAK1600_CTX sctx = *((KECCAK1600_CTX *)(hctx->shactx_pkseed));
-
-    ossl_sha3_absorb(&sctx, adrs, SLH_ADRS_SIZE);
-    ossl_sha3_absorb(&sctx, sk_seed, n);
-    ossl_sha3_squeeze(&sctx, out, n);
-    return 1;
-}
-
-static int
-slh_h_shake(SLH_DSA_HASH_CTX *hctx, const uint8_t *pk_seed, const uint8_t *adrs,
+slh_h_shake(SLH_DSA_HASH_CTX *ctx, const uint8_t *pk_seed, const uint8_t *adrs,
     const uint8_t *m1, const uint8_t *m2, uint8_t *out, size_t out_len)
 {
-    KECCAK1600_CTX ctx = *((KECCAK1600_CTX *)(hctx->shactx_pkseed)), *sctx = &ctx;
-    const SLH_DSA_PARAMS *params = hctx->key->params;
+    const SLH_DSA_PARAMS *params = ctx->key->params;
     size_t n = params->n;
 
-    ossl_sha3_absorb(sctx, adrs, SLH_ADRS_SIZE);
-    ossl_sha3_absorb(sctx, m1, n);
-    ossl_sha3_absorb(sctx, m2, n);
-    ossl_sha3_squeeze(sctx, out, n);
-    return 1;
+    return xof_digest_4(ctx->md_ctx, pk_seed, n, adrs, SLH_ADRS_SIZE, m1, n, m2, n, out, n);
+}
+
+static int
+slh_t_shake(SLH_DSA_HASH_CTX *ctx, const uint8_t *pk_seed, const uint8_t *adrs,
+    const uint8_t *ml, size_t ml_len, uint8_t *out, size_t out_len)
+{
+    const SLH_DSA_PARAMS *params = ctx->key->params;
+    size_t n = params->n;
+
+    return xof_digest_3(ctx->md_ctx, pk_seed, n, adrs, SLH_ADRS_SIZE, ml, ml_len, out, n);
+}
+
+static ossl_inline int
+digest_4(EVP_MD_CTX *ctx,
+    const uint8_t *in1, size_t in1_len, const uint8_t *in2, size_t in2_len,
+    const uint8_t *in3, size_t in3_len, const uint8_t *in4, size_t in4_len,
+    uint8_t *out)
+{
+    return (EVP_DigestInit_ex2(ctx, NULL, NULL) == 1
+        && EVP_DigestUpdate(ctx, in1, in1_len) == 1
+        && EVP_DigestUpdate(ctx, in2, in2_len) == 1
+        && EVP_DigestUpdate(ctx, in3, in3_len) == 1
+        && EVP_DigestUpdate(ctx, in4, in4_len) == 1
+        && EVP_DigestFinal_ex(ctx, out, NULL) == 1);
 }
 
 /* FIPS 205 Section 11.2.1 and 11.2.2 */
 
 static int
-slh_hmsg_sha256(SLH_DSA_HASH_CTX *hctx, const uint8_t *r, const uint8_t *pk_seed,
+slh_hmsg_sha2(SLH_DSA_HASH_CTX *hctx, const uint8_t *r, const uint8_t *pk_seed,
     const uint8_t *pk_root, const uint8_t *msg, size_t msg_len,
     uint8_t *out, size_t out_len)
 {
-    SHA256_CTX ctx, *sctx = &ctx;
     const SLH_DSA_PARAMS *params = hctx->key->params;
     size_t m = params->m;
     size_t n = params->n;
-    uint8_t seed[2 * SLH_MAX_N + SHA256_DIGEST_LENGTH];
-    long seed_len = SHA256_DIGEST_LENGTH + (long)(2 * n);
+    uint8_t seed[2 * SLH_MAX_N + MAX_DIGEST_SIZE];
+    int sz = EVP_MD_get_size(hctx->key->md_big);
+    size_t seed_len = (size_t)sz + 2 * n;
+
+    if (sz <= 0)
+        return 0;
 
     memcpy(seed, r, n);
     memcpy(seed + n, pk_seed, n);
-
-    SHA256_Init(sctx);
-    SHA256_Update(sctx, r, n);
-    SHA256_Update(sctx, pk_seed, n);
-    SHA256_Update(sctx, pk_root, n);
-    SHA256_Update(sctx, msg, msg_len);
-    return SHA256_Final(seed + 2 * n, sctx)
-        && (PKCS1_MGF1(out, (long)m, seed, seed_len, hctx->key->md) == 0);
-}
-
-static int
-slh_hmsg_sha512(SLH_DSA_HASH_CTX *hctx, const uint8_t *r, const uint8_t *pk_seed,
-    const uint8_t *pk_root, const uint8_t *msg, size_t msg_len,
-    uint8_t *out, size_t out_len)
-{
-    SHA512_CTX ctx, *sctx = &ctx;
-    const SLH_DSA_PARAMS *params = hctx->key->params;
-    size_t m = params->m;
-    size_t n = params->n;
-    uint8_t seed[2 * SLH_MAX_N + SHA512_DIGEST_LENGTH];
-    long seed_len = SHA512_DIGEST_LENGTH + (long)(2 * n);
-
-    memcpy(seed, r, n);
-    memcpy(seed + n, pk_seed, n);
-
-    SHA512_Init(sctx);
-    SHA512_Update(sctx, r, n);
-    SHA512_Update(sctx, pk_seed, n);
-    SHA512_Update(sctx, pk_root, n);
-    SHA512_Update(sctx, msg, msg_len);
-    return SHA512_Final(seed + 2 * n, sctx)
-        && (PKCS1_MGF1(out, (long)m, seed, seed_len, hctx->key->md_sha512) == 0);
+    return digest_4(hctx->md_big_ctx, r, n, pk_seed, n, pk_root, n, msg, msg_len,
+               seed + 2 * n)
+        && (PKCS1_MGF1(out, (long)m, seed, (long)seed_len, hctx->key->md_big) == 0);
 }
 
 static int
@@ -209,11 +188,10 @@ slh_prf_msg_sha2(SLH_DSA_HASH_CTX *hctx,
      * So we do a lazy update here on the first call.
      */
     if (hctx->hmac_digest_used == 0) {
-        const char *nm = EVP_MD_get0_name(key->md_sha512 == NULL ? key->md : key->md_sha512);
-
         p = params;
         /* The underlying digest to be used */
-        *p++ = OSSL_PARAM_construct_utf8_string(OSSL_MAC_PARAM_DIGEST, (char *)nm, 0);
+        *p++ = OSSL_PARAM_construct_utf8_string(OSSL_MAC_PARAM_DIGEST,
+            (char *)EVP_MD_get0_name(key->md_big), 0);
         if (key->propq != NULL)
             *p++ = OSSL_PARAM_construct_utf8_string(OSSL_MAC_PARAM_PROPERTIES,
                 (char *)key->propq, 0);
@@ -230,272 +208,79 @@ slh_prf_msg_sha2(SLH_DSA_HASH_CTX *hctx,
     return ret;
 }
 
+static ossl_inline int
+do_hash(EVP_MD_CTX *ctx, size_t n, const uint8_t *pk_seed, const uint8_t *adrs,
+    const uint8_t *m, size_t m_len, size_t b, uint8_t *out, size_t out_len)
+{
+    int ret;
+    uint8_t zeros[128] = { 0 };
+    uint8_t digest[MAX_DIGEST_SIZE];
+
+    ret = digest_4(ctx, pk_seed, n, zeros, b - n, adrs, SLH_ADRSC_SIZE,
+        m, m_len, digest);
+    /* Truncated returned value is n = 16 bytes */
+    memcpy(out, digest, n);
+    return ret;
+}
+
 static int
-slh_prf_sha256(SLH_DSA_HASH_CTX *hctx, const uint8_t *pk_seed,
+slh_prf_sha2(SLH_DSA_HASH_CTX *hctx, const uint8_t *pk_seed,
     const uint8_t *sk_seed, const uint8_t *adrs,
     uint8_t *out, size_t out_len)
 {
-    SHA256_CTX ctx = *((SHA256_CTX *)hctx->shactx_pkseed), *sctx = &ctx;
     size_t n = hctx->key->params->n;
 
-    SHA256_Update(sctx, adrs, SLH_ADRSC_SIZE);
-    SHA256_Update(sctx, sk_seed, n);
-    sha256_final(sctx, out, n);
-    return 1;
+    return do_hash(hctx->md_ctx, n, pk_seed, adrs, sk_seed, n,
+        OSSL_SLH_DSA_SHA2_NUM_ZEROS_H_AND_T_BOUND1, out, out_len);
 }
 
 static int
-slh_wots_pk_gen_sha2(SLH_DSA_HASH_CTX *hctx,
-    const uint8_t *sk_seed, const uint8_t *pk_seed,
-    uint8_t *adrs, uint8_t *pk_out, size_t pk_out_len)
-{
-    int ret = 0;
-    size_t n = hctx->key->params->n;
-    size_t i, j = 0, len = SLH_WOTS_LEN(n);
-    uint8_t sk[SLH_MAX_N];
-    SHA256_CTX *sctx = (SHA256_CTX *)(hctx->shactx_pkseed);
-    SHA256_CTX ctx;
-    const SLH_ADRS_FUNC *adrsf = hctx->key->adrs_func;
-    SLH_ADRS_DECLARE(sk_adrs);
-    SLH_ADRS_FN_DECLARE(adrsf, set_chain_address);
-    SLH_ADRS_FN_DECLARE(adrsf, set_hash_address);
-
-    adrsf->copy(sk_adrs, adrs);
-    adrsf->set_type_and_clear(sk_adrs, SLH_ADRS_TYPE_WOTS_PRF);
-    adrsf->copy_keypair_address(sk_adrs, adrs);
-
-    for (i = 0; i < len; ++i) { /* len = 2n + 3 */
-        set_chain_address(sk_adrs, (uint32_t)i);
-
-        /* PRF */
-        ctx = *sctx;
-        SHA256_Update(&ctx, sk_adrs, SLH_ADRSC_SIZE);
-        SHA256_Update(&ctx, sk_seed, n);
-        sha256_final(&ctx, sk, n);
-
-        set_chain_address(adrs, (uint32_t)i);
-        for (j = 0; j < NIBBLE_MASK; ++j) {
-            set_hash_address(adrs, (uint32_t)j);
-            /* F */
-            ctx = *sctx;
-            SHA256_Update(&ctx, adrs, SLH_ADRSC_SIZE);
-            SHA256_Update(&ctx, sk, n);
-            sha256_final(&ctx, sk, n);
-        }
-        memcpy(pk_out, sk, n);
-        pk_out += n;
-    }
-    ret = 1;
-    return ret;
-}
-
-int slh_wots_pk_gen_shake(SLH_DSA_HASH_CTX *hctx,
-    const uint8_t *sk_seed, const uint8_t *pk_seed,
-    uint8_t *adrs, uint8_t *pk_out, size_t pk_out_len)
-{
-    int ret = 0;
-    size_t n = hctx->key->params->n;
-    size_t i, j = 0, len = SLH_WOTS_LEN(n);
-    uint8_t sk[SLH_MAX_N];
-    const SLH_ADRS_FUNC *adrsf = hctx->key->adrs_func;
-    SLH_ADRS_DECLARE(sk_adrs);
-    SLH_ADRS_FN_DECLARE(adrsf, set_chain_address);
-    SLH_ADRS_FN_DECLARE(adrsf, set_hash_address);
-    KECCAK1600_CTX *sctx = (KECCAK1600_CTX *)(hctx->shactx_pkseed);
-    KECCAK1600_CTX ctx;
-
-    adrsf->copy(sk_adrs, adrs);
-    adrsf->set_type_and_clear(sk_adrs, SLH_ADRS_TYPE_WOTS_PRF);
-    adrsf->copy_keypair_address(sk_adrs, adrs);
-
-    for (i = 0; i < len; ++i) { /* len = 2n + 3 */
-        set_chain_address(sk_adrs, (uint32_t)i);
-
-        /* PRF */
-        ctx = *sctx;
-        ossl_sha3_absorb(&ctx, sk_adrs, SLH_ADRS_SIZE);
-        ossl_sha3_absorb(&ctx, sk_seed, n);
-        ossl_sha3_squeeze(&ctx, sk, n);
-
-        set_chain_address(adrs, (uint32_t)i);
-        for (j = 0; j < NIBBLE_MASK; ++j) {
-            set_hash_address(adrs, (uint32_t)j);
-            /* F */
-            ctx = *sctx;
-            ossl_sha3_absorb(&ctx, adrs, SLH_ADRS_SIZE);
-            ossl_sha3_absorb(&ctx, sk, n);
-            ossl_sha3_squeeze(&ctx, sk, n);
-        }
-        memcpy(pk_out, sk, n);
-        pk_out += n;
-    }
-    ret = 1;
-    return ret;
-}
-
-static int
-slh_f_sha256(SLH_DSA_HASH_CTX *hctx, const uint8_t *pk_seed, const uint8_t *adrs,
+slh_f_sha2(SLH_DSA_HASH_CTX *hctx, const uint8_t *pk_seed, const uint8_t *adrs,
     const uint8_t *m1, size_t m1_len, uint8_t *out, size_t out_len)
 {
-    SHA256_CTX ctx = *((SHA256_CTX *)hctx->shactx_pkseed), *sctx = &ctx;
-
-    SHA256_Update(sctx, adrs, SLH_ADRSC_SIZE);
-    SHA256_Update(sctx, m1, m1_len);
-    sha256_final(sctx, out, hctx->key->params->n);
-    return 1;
+    return do_hash(hctx->md_ctx, hctx->key->params->n, pk_seed, adrs, m1, m1_len,
+        OSSL_SLH_DSA_SHA2_NUM_ZEROS_H_AND_T_BOUND1, out, out_len);
 }
 
 static int
-slh_h_sha256(SLH_DSA_HASH_CTX *hctx, const uint8_t *pk_seed, const uint8_t *adrs,
+slh_h_sha2(SLH_DSA_HASH_CTX *hctx, const uint8_t *pk_seed, const uint8_t *adrs,
     const uint8_t *m1, const uint8_t *m2, uint8_t *out, size_t out_len)
 {
-    SHA256_CTX ctx = *((SHA256_CTX *)hctx->shactx_pkseed), *sctx = &ctx;
+    uint8_t m[SLH_MAX_N * 2];
     const SLH_DSA_PARAMS *prms = hctx->key->params;
     size_t n = prms->n;
 
-    SHA256_Update(sctx, adrs, SLH_ADRSC_SIZE);
-    SHA256_Update(sctx, m1, n);
-    SHA256_Update(sctx, m2, n);
-    sha256_final(sctx, out, n);
-    return 1;
+    memcpy(m, m1, n);
+    memcpy(m + n, m2, n);
+    return do_hash(hctx->md_big_ctx, n, pk_seed, adrs, m, 2 * n,
+        prms->sha2_h_and_t_bound, out, out_len);
 }
 
 static int
-slh_h_sha512(SLH_DSA_HASH_CTX *hctx, const uint8_t *pk_seed, const uint8_t *adrs,
-    const uint8_t *m1, const uint8_t *m2, uint8_t *out, size_t out_len)
-{
-    SHA512_CTX ctx, *sctx = &ctx;
-    const SLH_DSA_PARAMS *prms = hctx->key->params;
-    size_t n = prms->n;
-
-    SHA512_Init(sctx);
-    SHA512_Update(sctx, pk_seed, n);
-    SHA512_Update(sctx, zeros, 128 - n);
-    SHA512_Update(sctx, adrs, SLH_ADRSC_SIZE);
-    SHA512_Update(sctx, m1, n);
-    SHA512_Update(sctx, m2, n);
-    sha512_final(sctx, out, n);
-    return 1;
-}
-
-static int
-slh_t_sha256(SLH_DSA_HASH_CTX *hctx, const uint8_t *pk_seed, const uint8_t *adrs,
+slh_t_sha2(SLH_DSA_HASH_CTX *hctx, const uint8_t *pk_seed, const uint8_t *adrs,
     const uint8_t *ml, size_t ml_len, uint8_t *out, size_t out_len)
 {
-    SHA256_CTX ctx = *((SHA256_CTX *)hctx->shactx_pkseed), *sctx = &ctx;
-
-    SHA256_Update(sctx, adrs, SLH_ADRSC_SIZE);
-    SHA256_Update(sctx, ml, ml_len);
-    sha256_final(sctx, out, hctx->key->params->n);
-    return 1;
-}
-
-static int
-slh_t_sha512(SLH_DSA_HASH_CTX *hctx, const uint8_t *pk_seed, const uint8_t *adrs,
-    const uint8_t *ml, size_t ml_len, uint8_t *out, size_t out_len)
-{
-    SHA512_CTX ctx, *sctx = &ctx;
     const SLH_DSA_PARAMS *prms = hctx->key->params;
-    size_t n = prms->n;
 
-    SHA512_Init(sctx);
-    SHA512_Update(sctx, pk_seed, n);
-    SHA512_Update(sctx, zeros, 128 - n);
-    SHA512_Update(sctx, adrs, SLH_ADRSC_SIZE);
-    SHA512_Update(sctx, ml, ml_len);
-    sha512_final(sctx, out, hctx->key->params->n);
-    return 1;
+    return do_hash(hctx->md_big_ctx, prms->n, pk_seed, adrs, ml, ml_len,
+        prms->sha2_h_and_t_bound, out, out_len);
 }
 
-static int slh_hash_shake_precache(SLH_DSA_HASH_CTX *hctx, const uint8_t *pkseed, size_t n)
-{
-    KECCAK1600_CTX *ctx = NULL, *seedctx = NULL;
-
-    ctx = ossl_shake256_new();
-    if (ctx == NULL)
-        return 0;
-    seedctx = OPENSSL_memdup(ctx, sizeof(*ctx));
-    if (seedctx == NULL) {
-        OPENSSL_free(ctx);
-        return 0;
-    }
-    ossl_sha3_absorb(seedctx, pkseed, n);
-    hctx->shactx = (void *)ctx;
-    hctx->shactx_pkseed = (void *)seedctx;
-    return 1;
-}
-
-static int slh_hash_shake_dup(SLH_DSA_HASH_CTX *dst, const SLH_DSA_HASH_CTX *src)
-{
-    if (src->shactx != NULL) {
-        dst->shactx = OPENSSL_memdup(src->shactx, sizeof(KECCAK1600_CTX));
-        if (dst->shactx == NULL)
-            return 0;
-    }
-    if (src->shactx_pkseed != NULL) {
-        dst->shactx_pkseed = OPENSSL_memdup(src->shactx_pkseed, sizeof(KECCAK1600_CTX));
-        if (dst->shactx_pkseed == NULL) {
-            OPENSSL_free(dst->shactx);
-            dst->shactx = NULL;
-            return 0;
-        }
-    }
-    return 1;
-}
-
-static int slh_hash_sha256_precache(SLH_DSA_HASH_CTX *hctx, const uint8_t *pkseed, size_t n)
-{
-    SHA256_CTX *ctx = OPENSSL_zalloc(sizeof(*ctx));
-
-    if (ctx == NULL)
-        return 0;
-    SHA256_Init(ctx);
-    SHA256_Update(ctx, pkseed, n);
-    SHA256_Update(ctx, zeros, 64 - n);
-    hctx->shactx_pkseed = (void *)ctx;
-    return 1;
-}
-
-static int slh_hash_sha256_dup(SLH_DSA_HASH_CTX *dst, const SLH_DSA_HASH_CTX *src)
-{
-    if (src->shactx_pkseed != NULL) {
-        dst->shactx_pkseed = OPENSSL_memdup(src->shactx_pkseed, sizeof(SHA256_CTX));
-        if (dst->shactx_pkseed == NULL)
-            return 0;
-    }
-    return 1;
-}
-
-const SLH_HASH_FUNC *ossl_slh_get_hash_fn(int is_shake, int security_category)
+const SLH_HASH_FUNC *ossl_slh_get_hash_fn(int is_shake)
 {
     static const SLH_HASH_FUNC methods[] = {
-        { slh_hash_shake_precache,
-            slh_hash_shake_dup,
-            slh_hmsg_shake,
+        { slh_hmsg_shake,
             slh_prf_shake,
             slh_prf_msg_shake,
             slh_f_shake,
             slh_h_shake,
-            slh_f_shake,
-            slh_wots_pk_gen_shake },
-        { slh_hash_sha256_precache,
-            slh_hash_sha256_dup,
-            slh_hmsg_sha256,
-            slh_prf_sha256,
+            slh_t_shake },
+        { slh_hmsg_sha2,
+            slh_prf_sha2,
             slh_prf_msg_sha2,
-            slh_f_sha256,
-            slh_h_sha256,
-            slh_t_sha256,
-            slh_wots_pk_gen_sha2 },
-        { slh_hash_sha256_precache,
-            slh_hash_sha256_dup,
-            slh_hmsg_sha512,
-            slh_prf_sha256,
-            slh_prf_msg_sha2,
-            slh_f_sha256,
-            slh_h_sha512,
-            slh_t_sha512,
-            slh_wots_pk_gen_sha2 }
+            slh_f_sha2,
+            slh_h_sha2,
+            slh_t_sha2 }
     };
-    return &methods[is_shake ? 0 : (security_category == 1 ? 1 : 2)];
+    return &methods[is_shake ? 0 : 1];
 }
diff --git a/crypto/slh_dsa/slh_hash.h b/crypto/slh_dsa/slh_hash.h
index 27f2332392..51e542139f 100644
--- a/crypto/slh_dsa/slh_hash.h
+++ b/crypto/slh_dsa/slh_hash.h
@@ -1,5 +1,5 @@
 /*
- * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -12,9 +12,6 @@
 #pragma once
 
 #include 
-
-#include "crypto/slh_dsa.h"
-
 #include "slh_adrs.h"
 #include "internal/packet.h"
 
@@ -50,29 +47,20 @@ typedef int(OSSL_SLH_HASHFUNC_H)(SLH_DSA_HASH_CTX *ctx, const uint8_t *pk_seed,
     const uint8_t *m1, const uint8_t *m2,
     uint8_t *out, size_t out_len);
 
-#define OSSL_SLH_HASHFUNC_T OSSL_SLH_HASHFUNC_F
-
-typedef int(OSSL_SLH_HASHFUNC_wots_pk_gen)(SLH_DSA_HASH_CTX *hctx,
-    const uint8_t *sk_seed, const uint8_t *pk_seed,
-    uint8_t *adrs, uint8_t *pk_out, size_t pk_out_len);
-
-typedef int(OSSL_SLH_HASHFUNC_prehash_pk_seed)(SLH_DSA_HASH_CTX *hctx,
-    const uint8_t *pk_seed, size_t n);
-typedef int(OSSL_SLH_HASHFUNC_prehash_dup)(SLH_DSA_HASH_CTX *dst,
-    const SLH_DSA_HASH_CTX *src);
+typedef int(OSSL_SLH_HASHFUNC_T)(SLH_DSA_HASH_CTX *ctx, const uint8_t *pk_seed,
+    const uint8_t *adrs,
+    const uint8_t *m1, size_t m1_len,
+    uint8_t *out, size_t out_len);
 
 typedef struct slh_hash_func_st {
-    OSSL_SLH_HASHFUNC_prehash_pk_seed *prehash_pk_seed;
-    OSSL_SLH_HASHFUNC_prehash_dup *prehash_dup;
     OSSL_SLH_HASHFUNC_H_MSG *H_MSG;
     OSSL_SLH_HASHFUNC_PRF *PRF;
     OSSL_SLH_HASHFUNC_PRF_MSG *PRF_MSG;
     OSSL_SLH_HASHFUNC_F *F;
     OSSL_SLH_HASHFUNC_H *H;
     OSSL_SLH_HASHFUNC_T *T;
-    OSSL_SLH_HASHFUNC_wots_pk_gen *wots_pk_gen;
 } SLH_HASH_FUNC;
 
-const SLH_HASH_FUNC *ossl_slh_get_hash_fn(int is_shake, int security_category);
+const SLH_HASH_FUNC *ossl_slh_get_hash_fn(int is_shake);
 
 #endif
diff --git a/crypto/slh_dsa/slh_params.h b/crypto/slh_dsa/slh_params.h
index edc3644b61..fea14d5d6a 100644
--- a/crypto/slh_dsa/slh_params.h
+++ b/crypto/slh_dsa/slh_params.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_SLH_DSA_SLH_PARAMS_H)
-#define OSSL_LIBCRYPTO_SLH_DSA_SLH_PARAMS_H
-
 #include 
 
 /*
@@ -40,5 +37,3 @@ typedef struct slh_dsa_params_st {
 } SLH_DSA_PARAMS;
 
 const SLH_DSA_PARAMS *ossl_slh_dsa_params_get(const char *alg);
-
-#endif /* !defined(OSSL_LIBCRYPTO_SLH_DSA_SLH_PARAMS_H) */
diff --git a/crypto/slh_dsa/slh_wots.c b/crypto/slh_dsa/slh_wots.c
index 3b84474c41..1c612e8561 100644
--- a/crypto/slh_dsa/slh_wots.c
+++ b/crypto/slh_dsa/slh_wots.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -142,22 +142,45 @@ int ossl_slh_wots_pk_gen(SLH_DSA_HASH_CTX *ctx,
     int ret = 0;
     const SLH_DSA_KEY *key = ctx->key;
     size_t n = key->params->n;
-    size_t len = SLH_WOTS_LEN(n); /* 2 * n + 3 */
+    size_t i, len = SLH_WOTS_LEN(n); /* 2 * n + 3 */
+    uint8_t sk[SLH_MAX_N];
     uint8_t tmp[SLH_WOTS_LEN_MAX * SLH_MAX_N];
-    size_t tmp_len = n * len;
+    WPACKET pkt, *tmp_wpkt = &pkt; /* Points to the |tmp| buffer */
+    size_t tmp_len = 0;
 
     SLH_HASH_FUNC_DECLARE(key, hashf);
     SLH_ADRS_FUNC_DECLARE(key, adrsf);
+    SLH_HASH_FN_DECLARE(hashf, PRF);
+    SLH_ADRS_FN_DECLARE(adrsf, set_chain_address);
+    SLH_ADRS_DECLARE(sk_adrs);
     SLH_ADRS_DECLARE(wots_pk_adrs);
 
-    if (!hashf->wots_pk_gen(ctx, sk_seed, pk_seed, adrs, tmp, tmp_len))
-        goto end;
+    if (!WPACKET_init_static_len(tmp_wpkt, tmp, sizeof(tmp), 0))
+        return 0;
+    adrsf->copy(sk_adrs, adrs);
+    adrsf->set_type_and_clear(sk_adrs, SLH_ADRS_TYPE_WOTS_PRF);
+    adrsf->copy_keypair_address(sk_adrs, adrs);
 
+    for (i = 0; i < len; ++i) { /* len = 2n + 3 */
+        set_chain_address(sk_adrs, (uint32_t)i);
+        if (!PRF(ctx, pk_seed, sk_seed, sk_adrs, sk, sizeof(sk)))
+            goto end;
+
+        set_chain_address(adrs, (uint32_t)i);
+        if (!slh_wots_chain(ctx, sk, 0, NIBBLE_MASK, pk_seed, adrs, tmp_wpkt))
+            goto end;
+    }
+
+    if (!WPACKET_get_total_written(tmp_wpkt, &tmp_len)) /* should be n * (2 * n + 3) */
+        goto end;
     adrsf->copy(wots_pk_adrs, adrs);
     adrsf->set_type_and_clear(wots_pk_adrs, SLH_ADRS_TYPE_WOTS_PK);
     adrsf->copy_keypair_address(wots_pk_adrs, adrs);
     ret = hashf->T(ctx, pk_seed, wots_pk_adrs, tmp, tmp_len, pk_out, pk_out_len);
 end:
+    WPACKET_finish(tmp_wpkt);
+    OPENSSL_cleanse(tmp, sizeof(tmp));
+    OPENSSL_cleanse(sk, n);
     return ret;
 }
 
diff --git a/crypto/sm2/sm2_crypt.c b/crypto/sm2/sm2_crypt.c
index 6e787f5d28..7a8c758552 100644
--- a/crypto/sm2/sm2_crypt.c
+++ b/crypto/sm2/sm2_crypt.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright 2017 Ribose Inc. All Rights Reserved.
  * Ported from Ribose contributions from Botan.
  *
@@ -78,7 +78,7 @@ int ossl_sm2_plaintext_size(const unsigned char *ct, size_t ct_size,
         return 0;
     }
 
-    *pt_size = ASN1_STRING_length_ex(sm2_ctext->C2);
+    *pt_size = sm2_ctext->C2->length;
     SM2_Ciphertext_free(sm2_ctext);
 
     return 1;
@@ -253,19 +253,8 @@ again:
         goto done;
     }
 
-    ciphertext_leni = i2d_SM2_Ciphertext(&ctext_struct, NULL);
-    /* Ensure cast to size_t is safe */
-    if (ciphertext_leni < 0) {
-        ERR_raise(ERR_LIB_SM2, ERR_R_INTERNAL_ERROR);
-        goto done;
-    }
-
-    if (*ciphertext_len < (size_t)ciphertext_leni) {
-        ERR_raise(ERR_LIB_SM2, SM2_R_BUFFER_TOO_SMALL);
-        goto done;
-    }
-
     ciphertext_leni = i2d_SM2_Ciphertext(&ctext_struct, &ciphertext_buf);
+    /* Ensure cast to size_t is safe */
     if (ciphertext_leni < 0) {
         ERR_raise(ERR_LIB_SM2, ERR_R_INTERNAL_ERROR);
         goto done;
@@ -282,7 +271,6 @@ done:
     OPENSSL_free(x2y2);
     OPENSSL_free(C3);
     EVP_MD_CTX_free(hash);
-    BN_CTX_end(ctx);
     BN_CTX_free(ctx);
     EC_POINT_free(kG);
     EC_POINT_free(kP);
@@ -309,7 +297,7 @@ int ossl_sm2_decrypt(const EC_KEY *key,
     uint8_t *msg_mask = NULL;
     const uint8_t *C2 = NULL;
     const uint8_t *C3 = NULL;
-    size_t c3_len, msg_len = 0;
+    int msg_len = 0;
     EVP_MD_CTX *hash = NULL;
     OSSL_LIB_CTX *libctx = ossl_ec_key_get_libctx(key);
     const char *propq = ossl_ec_key_get0_propq(key);
@@ -326,18 +314,14 @@ int ossl_sm2_decrypt(const EC_KEY *key,
         goto done;
     }
 
-    msg_len = ASN1_STRING_length_ex(sm2_ctext->C2);
-    if (msg_len > INT_MAX)
-        goto done;
-
-    c3_len = ASN1_STRING_length_ex(sm2_ctext->C3);
-    if (c3_len > INT_MAX || c3_len != (size_t)hash_size) {
+    if (sm2_ctext->C3->length != hash_size) {
         ERR_raise(ERR_LIB_SM2, SM2_R_INVALID_ENCODING);
         goto done;
     }
 
-    C2 = ASN1_STRING_get0_data(sm2_ctext->C2);
-    C3 = ASN1_STRING_get0_data(sm2_ctext->C3);
+    C2 = sm2_ctext->C2->data;
+    C3 = sm2_ctext->C3->data;
+    msg_len = sm2_ctext->C2->length;
     if (*ptext_len < (size_t)msg_len) {
         ERR_raise(ERR_LIB_SM2, SM2_R_BUFFER_TOO_SMALL);
         goto done;
@@ -382,7 +366,7 @@ int ossl_sm2_decrypt(const EC_KEY *key,
 
     if (BN_bn2binpad(x2, x2y2, field_size) < 0
         || BN_bn2binpad(y2, x2y2 + field_size, field_size) < 0
-        || !ossl_ecdh_kdf_X9_63(msg_mask, (int)msg_len, x2y2, 2 * field_size,
+        || !ossl_ecdh_kdf_X9_63(msg_mask, msg_len, x2y2, 2 * field_size,
             NULL, 0, digest, libctx, propq)) {
         ERR_raise(ERR_LIB_SM2, ERR_R_INTERNAL_ERROR);
         goto done;
@@ -393,7 +377,7 @@ int ossl_sm2_decrypt(const EC_KEY *key,
         goto done;
     }
 
-    for (i = 0; i != (int)msg_len; ++i)
+    for (i = 0; i != msg_len; ++i)
         ptext_buf[i] = C2[i] ^ msg_mask[i];
 
     hash = EVP_MD_CTX_new();
@@ -404,7 +388,7 @@ int ossl_sm2_decrypt(const EC_KEY *key,
 
     if (!EVP_DigestInit(hash, digest)
         || !EVP_DigestUpdate(hash, x2y2, field_size)
-        || !EVP_DigestUpdate(hash, ptext_buf, (int)msg_len)
+        || !EVP_DigestUpdate(hash, ptext_buf, msg_len)
         || !EVP_DigestUpdate(hash, x2y2 + field_size, field_size)
         || !EVP_DigestFinal(hash, computed_C3, NULL)) {
         ERR_raise(ERR_LIB_SM2, ERR_R_EVP_LIB);
@@ -417,7 +401,7 @@ int ossl_sm2_decrypt(const EC_KEY *key,
     }
 
     rc = 1;
-    *ptext_len = (int)msg_len;
+    *ptext_len = msg_len;
 
 done:
     if (rc == 0)
@@ -427,7 +411,6 @@ done:
     OPENSSL_free(x2y2);
     OPENSSL_free(computed_C3);
     EC_POINT_free(C1);
-    BN_CTX_end(ctx);
     BN_CTX_free(ctx);
     SM2_Ciphertext_free(sm2_ctext);
     EVP_MD_CTX_free(hash);
diff --git a/crypto/sm2/sm2_sign.c b/crypto/sm2/sm2_sign.c
index 5e29900968..590a730974 100644
--- a/crypto/sm2/sm2_sign.c
+++ b/crypto/sm2/sm2_sign.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright 2017 Ribose Inc. All Rights Reserved.
  * Ported from Ribose contributions from Botan.
  *
@@ -20,25 +20,10 @@
 #include 
 #include 
 
-/*
- * [SM2 Signature Scheme]
- * (https://datatracker.ietf.org/doc/html/rfc8998#section-3.2.1)
- *
- * If either a client or a server needs to verify the peer's SM2 certificate
- * contained in the Certificate message, then the following ASCII string value
- * MUST be used as the SM2 identifier according to [GMT.0009-2012]:
- *
- * 1234567812345678
- */
-static const uint8_t default_sm2_id[] = {
-    0x31, 0x32, 0x33, 0x34, 0x35, 0x36, 0x37, 0x38,
-    0x31, 0x32, 0x33, 0x34, 0x35, 0x36, 0x37, 0x38
-};
-
 int ossl_sm2_compute_z_digest(uint8_t *out,
     const EVP_MD *digest,
     const uint8_t *id,
-    size_t id_len,
+    const size_t id_len,
     const EC_KEY *key)
 {
     int rc = 0;
@@ -75,7 +60,6 @@ int ossl_sm2_compute_z_digest(uint8_t *out,
         goto done;
     }
 
-    BN_CTX_start(ctx);
     p = BN_CTX_get(ctx);
     a = BN_CTX_get(ctx);
     b = BN_CTX_get(ctx);
@@ -96,11 +80,6 @@ int ossl_sm2_compute_z_digest(uint8_t *out,
 
     /* Z = h(ENTL || ID || a || b || xG || yG || xA || yA) */
 
-    if (id == NULL) {
-        id = default_sm2_id;
-        id_len = sizeof(default_sm2_id);
-    }
-
     if (id_len >= (UINT16_MAX / 8)) {
         /* too large */
         ERR_raise(ERR_LIB_SM2, SM2_R_ID_TOO_LARGE);
@@ -162,7 +141,6 @@ int ossl_sm2_compute_z_digest(uint8_t *out,
 
 done:
     OPENSSL_free(buf);
-    BN_CTX_end(ctx);
     BN_CTX_free(ctx);
     EVP_MD_CTX_free(hash);
     return rc;
@@ -344,7 +322,6 @@ done:
         BN_free(s);
     }
 
-    BN_CTX_end(ctx);
     BN_CTX_free(ctx);
     EC_POINT_free(kG);
     return sig;
@@ -428,8 +405,8 @@ static int sm2_sig_verify(const EC_KEY *key, const ECDSA_SIG *sig,
         ret = 1;
 
 done:
-    EC_POINT_free(pt);
     BN_CTX_end(ctx);
+    EC_POINT_free(pt);
     BN_CTX_free(ctx);
     return ret;
 }
diff --git a/crypto/sm3/asm/sm3-armv8.pl b/crypto/sm3/asm/sm3-armv8.pl
index 6c51df28f8..f36e0e2be9 100644
--- a/crypto/sm3/asm/sm3-armv8.pl
+++ b/crypto/sm3/asm/sm3-armv8.pl
@@ -51,7 +51,7 @@ $code.=<<___;
 ___
 }
 
-# A round of compression function
+# A round of compresson function
 # Input:
 # 	ab - choose instruction among sm3tt1a, sm3tt1b, sm3tt2a, sm3tt2b
 # 	vstate0 - vstate1, store digest status(A - H)
@@ -109,7 +109,7 @@ ___
 }
 
 $code=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 .text
 ___
 
diff --git a/crypto/sm3/asm/sm3-riscv64-zvksh.pl b/crypto/sm3/asm/sm3-riscv64-zvksh.pl
index 2bee96e2c4..1b8fd2eea0 100755
--- a/crypto/sm3/asm/sm3-riscv64-zvksh.pl
+++ b/crypto/sm3/asm/sm3-riscv64-zvksh.pl
@@ -63,7 +63,7 @@ ___
 ################################################################################
 # ossl_hwsm3_block_data_order_zvksh(SM3_CTX *c, const void *p, size_t num);
 {
-my ($CTX, $INPUT, $NUM, $EVENNUM , $TMPADDR) = ("a0", "a1", "a2", "a6", "t0");
+my ($CTX, $INPUT, $NUM) = ("a0", "a1", "a2");
 my ($V0, $V1, $V2, $V3, $V4, $V5, $V6, $V7,
     $V8, $V9, $V10, $V11, $V12, $V13, $V14, $V15,
     $V16, $V17, $V18, $V19, $V20, $V21, $V22, $V23,
@@ -76,178 +76,8 @@ $code .= <<___;
 .globl ossl_hwsm3_block_data_order_zvksh
 .type ossl_hwsm3_block_data_order_zvksh,\@function
 ossl_hwsm3_block_data_order_zvksh:
-    # Obtain VLEN and select the corresponding branch
-    csrr t0, vlenb
-    srl t1, t0, 5
-    beqz t1, ossl_hwsm3_block_data_order_zvksh_zvl128
-    srl t1, t0, 6
-    beqz t1, ossl_hwsm3_block_data_order_zvksh_zvl256
-ossl_hwsm3_block_data_order_zvksh_zvl512:
-    @{[vsetivli "zero", 8, "e32", "m1", "tu", "mu"]}
-    @{[vle32_v $V26, $CTX]}
-    @{[vrev8_v $V26, $V26]}
-    @{[vsetivli "zero", 16, "e32", "m1", "ta", "ma"]}
-    la $TMPADDR, ORDER_BY_ZVL512_DATA
-    @{[vle32_v $V30, $TMPADDR]}
-    addi $TMPADDR, $TMPADDR, 64
-    @{[vle32_v $V31, $TMPADDR]}
-    la $TMPADDR, ORDER_BY_ZVL512_EXP
-    @{[vle32_v $V29, $TMPADDR]}
-    addi $TMPADDR, $TMPADDR, 64
-    @{[vle32_v $V28, $TMPADDR]}
-    srli $EVENNUM , $NUM, 1
-    andi $NUM, $NUM, 1
-    beqz $EVENNUM , ossl_hwsm3_block_data_order_zvksh_zvl256
-L_sm3_loop_zvl512:
-    # Use indexed loads (ORDER_BY_RVV512_DATA) to load two blocks in the
-    # word order expected by the later vrgather/vsm3c stages.
-    @{[vluxei32_v $V0, $INPUT, $V30]}
-    @{[vluxei32_v $V1, $INPUT, $V31]}
-    @{[vrgather_vv $V9, $V0, $V29]}
-    @{[vrgather_vv $V10, $V9, $V29]}
-    @{[vrgather_vv $V11, $V1, $V28]}
-    @{[vor_vv $V10, $V10, $V11]}
-    @{[vrgather_vv $V11, $V10, $V29]}
-    @{[vrgather_vv $V12, $V1, $V29]}
-    @{[vrgather_vv $V13, $V12, $V29]}
-    @{[vsm3me_vv $V2, $V1, $V0]}
-    @{[vrgather_vv $V14, $V2, $V28]}
-    @{[vor_vv $V13, $V13, $V14]}
-    @{[vrgather_vv $V14, $V13, $V29]}
-    @{[vrgather_vv $V15, $V2, $V29]}
-    @{[vrgather_vv $V16, $V15, $V29]}
-    @{[vsm3me_vv $V3, $V2, $V1]}
-    @{[vrgather_vv $V17, $V3, $V28]}
-    @{[vor_vv $V16, $V16, $V17]}
-    @{[vrgather_vv $V17, $V16, $V29]}
-    @{[vrgather_vv $V18, $V3, $V29]}
-    @{[vrgather_vv $V19, $V18, $V29]}
-    @{[vsm3me_vv $V4, $V3, $V2]}
-    @{[vrgather_vv $V20, $V4, $V28]}
-    @{[vor_vv $V19, $V19, $V20]}
-    @{[vrgather_vv $V20, $V19, $V29]}
-    @{[vrgather_vv $V21, $V4, $V29]}
-    @{[vrgather_vv $V22, $V21, $V29]}
-    @{[vsm3me_vv $V5, $V4, $V3]}
-    @{[vrgather_vv $V23, $V5, $V28]}
-    @{[vor_vv $V22, $V22, $V23]}
-    @{[vrgather_vv $V23, $V22, $V29]}
-    @{[vrgather_vv $V24, $V5, $V29]}
-    @{[vrgather_vv $V25, $V24, $V29]}
-    @{[vsm3me_vv $V6, $V5, $V4]}
-    @{[vrgather_vv $V27, $V6, $V28]}
-    @{[vor_vv $V25, $V25, $V27]}
-    @{[vsm3me_vv $V7, $V6, $V5]}
-    @{[vsm3me_vv $V8, $V7, $V6]}
-    @{[vmv_v_v $V27, $V26]}
-    @{[vsetivli "zero", 8, "e32", "m1", "tu", "mu"]}
-    @{[vsm3c_vi $V26, $V0, 0]}
-    @{[vsm3c_vi $V26, $V9, 1]}
-    @{[vsm3c_vi $V26, $V10, 2]}
-    @{[vsm3c_vi $V26, $V11, 3]}
-    @{[vsm3c_vi $V26, $V1, 4]}
-    @{[vsm3c_vi $V26, $V12, 5]}
-    @{[vsm3c_vi $V26, $V13, 6]}
-    @{[vsm3c_vi $V26, $V14, 7]}
-    @{[vsm3c_vi $V26, $V2, 8]}
-    @{[vsm3c_vi $V26, $V15, 9]}
-    @{[vsm3c_vi $V26, $V16, 10]}
-    @{[vsm3c_vi $V26, $V17, 11]}
-    @{[vsm3c_vi $V26, $V3, 12]}
-    @{[vsm3c_vi $V26, $V18, 13]}
-    @{[vsm3c_vi $V26, $V19, 14]}
-    @{[vsm3c_vi $V26, $V20, 15]}
-    @{[vsm3c_vi $V26, $V4, 16]}
-    @{[vsm3c_vi $V26, $V21, 17]}
-    @{[vsm3c_vi $V26, $V22, 18]}
-    @{[vsm3c_vi $V26, $V23, 19]}
-    @{[vsm3c_vi $V26, $V5, 20]}
-    @{[vsm3c_vi $V26, $V24, 21]}
-    @{[vsm3c_vi $V26, $V25, 22]}
-    @{[vrgather_vv $V9, $V25, $V29]}
-    @{[vrgather_vv $V10, $V6, $V29]}
-    @{[vrgather_vv $V11, $V10, $V29]}
-    @{[vrgather_vv $V12, $V7, $V28]}
-    @{[vor_vv $V11, $V11, $V12]}
-    @{[vrgather_vv $V12, $V11, $V29]}
-    @{[vrgather_vv $V13, $V7, $V29]}
-    @{[vrgather_vv $V14, $V13, $V29]}
-    @{[vrgather_vv $V15, $V8, $V28]}
-    @{[vor_vv $V14, $V14, $V15]}
-    @{[vrgather_vv $V15, $V14, $V29]}
-    @{[vsm3c_vi $V26, $V9, 23]}
-    @{[vsm3c_vi $V26, $V6, 24]}
-    @{[vsm3c_vi $V26, $V10, 25]}
-    @{[vsm3c_vi $V26, $V11, 26]}
-    @{[vsm3c_vi $V26, $V12, 27]}
-    @{[vsm3c_vi $V26, $V7, 28]}
-    @{[vsm3c_vi $V26, $V13, 29]}
-    @{[vsm3c_vi $V26, $V14, 30]}
-    @{[vsm3c_vi $V26, $V15, 31]}
-    @{[vsetivli "zero", 16, "e32", "m1", "ta", "ma"]}
-    @{[vxor_vv $V26, $V26, $V27]}
-    @{[vslideup_vi $V27, $V26, 8]}
-    @{[vmv_v_v $V26, $V27]}
-    @{[vsm3c_vi $V26, $V0, 0]}
-    @{[vsm3c_vi $V26, $V9, 1]}
-    @{[vsm3c_vi $V26, $V10, 2]}
-    @{[vsm3c_vi $V26, $V11, 3]}
-    @{[vsm3c_vi $V26, $V1, 4]}
-    @{[vsm3c_vi $V26, $V12, 5]}
-    @{[vsm3c_vi $V26, $V13, 6]}
-    @{[vsm3c_vi $V26, $V14, 7]}
-    @{[vsm3c_vi $V26, $V2, 8]}
-    @{[vsm3c_vi $V26, $V15, 9]}
-    @{[vsm3c_vi $V26, $V16, 10]}
-    @{[vsm3c_vi $V26, $V17, 11]}
-    @{[vsm3c_vi $V26, $V3, 12]}
-    @{[vsm3c_vi $V26, $V18, 13]}
-    @{[vsm3c_vi $V26, $V19, 14]}
-    @{[vsm3c_vi $V26, $V20, 15]}
-    @{[vsm3c_vi $V26, $V4, 16]}
-    @{[vsm3c_vi $V26, $V21, 17]}
-    @{[vsm3c_vi $V26, $V22, 18]}
-    @{[vsm3c_vi $V26, $V23, 19]}
-    @{[vsm3c_vi $V26, $V5, 20]}
-    @{[vsm3c_vi $V26, $V24, 21]}
-    @{[vsm3c_vi $V26, $V25, 22]}
-    @{[vrgather_vv $V9, $V25, $V29]}
-    @{[vrgather_vv $V10, $V6, $V29]}
-    @{[vrgather_vv $V11, $V10, $V29]}
-    @{[vrgather_vv $V12, $V7, $V28]}
-    @{[vor_vv $V11, $V11, $V12]}
-    @{[vrgather_vv $V12, $V11, $V29]}
-    @{[vrgather_vv $V13, $V7, $V29]}
-    @{[vrgather_vv $V14, $V13, $V29]}
-    @{[vrgather_vv $V15, $V8, $V28]}
-    @{[vor_vv $V14, $V14, $V15]}
-    @{[vrgather_vv $V15, $V14, $V29]}
-    @{[vsm3c_vi $V26, $V9, 23]}
-    @{[vsm3c_vi $V26, $V6, 24]}
-    @{[vsm3c_vi $V26, $V10, 25]}
-    @{[vsm3c_vi $V26, $V11, 26]}
-    @{[vsm3c_vi $V26, $V12, 27]}
-    @{[vsm3c_vi $V26, $V7, 28]}
-    @{[vsm3c_vi $V26, $V13, 29]}
-    @{[vsm3c_vi $V26, $V14, 30]}
-    @{[vsm3c_vi $V26, $V15, 31]}
-    @{[vxor_vv $V26, $V26, $V27]}
-    @{[vslidedown_vi $V27, $V26, 8]}
-    @{[vmv_v_v $V26, $V27]}
-    addi $EVENNUM , $EVENNUM , -1
-    addi $INPUT, $INPUT, 128
-    bnez $EVENNUM , L_sm3_loop_zvl512
-    @{[vsetivli "zero", 8, "e32", "m1", "ta", "ma"]}
-    @{[vrev8_v $V26, $V26]}
-    @{[vse32_v $V26, $CTX]}
-    bnez $NUM, ossl_hwsm3_block_data_order_zvksh_zvl256
-    ret
-ossl_hwsm3_block_data_order_zvksh_zvl256:
-    @{[vsetivli "zero", 8, "e32", "m1", "ta", "ma"]}
-    j ossl_hwsm3_block_data_order_zvksh_single
-ossl_hwsm3_block_data_order_zvksh_zvl128:
     @{[vsetivli "zero", 8, "e32", "m2", "ta", "ma"]}
-ossl_hwsm3_block_data_order_zvksh_single:
+
     # Load initial state of hash context (c->A-H).
     @{[vle32_v $V0, $CTX]}
     @{[vrev8_v $V0, $V0]}
@@ -390,19 +220,6 @@ L_sm3_end:
     ret
 
 .size ossl_hwsm3_block_data_order_zvksh,.-ossl_hwsm3_block_data_order_zvksh
-
-.section .rodata
-.p2align 3
-.type ORDER_BY_ZVL512_DATA,\@object
-ORDER_BY_ZVL512_DATA:
-    .word 0, 4, 8, 12, 16, 20, 24, 28, 64, 68, 72, 76, 80, 84, 88, 92, 32, 36, 40, 44, 48, 52, 56, 60, 96, 100, 104, 108, 112, 116, 120, 124
-.size ORDER_BY_ZVL512_DATA, .-ORDER_BY_ZVL512_DATA
-
-.p2align 3
-.type ORDER_BY_ZVL512_EXP,\@object
-ORDER_BY_ZVL512_EXP:
-    .word 2, 3, 4, 5, 6, 7, 255, 255, 10, 11, 12, 13, 14, 15, 255, 255, 255, 255, 255, 255, 0, 1, 2, 3, 255, 255, 255, 255, 8, 9, 10, 11
-.size ORDER_BY_ZVL512_EXP, .-ORDER_BY_ZVL512_EXP
 ___
 }
 
diff --git a/crypto/sm3/asm/sm3-x86_64.pl b/crypto/sm3/asm/sm3-x86_64.pl
index 2f6ddf5616..d3c9d0541a 100755
--- a/crypto/sm3/asm/sm3-x86_64.pl
+++ b/crypto/sm3/asm/sm3-x86_64.pl
@@ -35,8 +35,8 @@ if (`$ENV{CC} -Wa,-v -c -o /dev/null -x assembler /dev/null 2>&1`
 }
 
 if (!$avx2_sm3_ni && $win64 && ($flavour =~ /nasm/ || $ENV{ASM} =~ /nasm/) &&
-	   `nasm -v 2>&1` =~ /NASM version ([2-9])\.([0-9]+)(?:\.([0-9]+))?/) {
-    my ($major, $minor, $patch) = ($1, $2, defined($3) ? $3 : 0);
+	   `nasm -v 2>&1` =~ /NASM version ([2-9])\.([0-9]+)\.([0-9]+)/) {
+    my ($major, $minor, $patch) = ($1, $2, $3);
     $avx2_sm3_ni = ($major > 2) || ($major == 2 && $minor > 10); # minimal avx2 supported version, binary translation for SM3 instructions (sub sm3op) is used
 	$avx2_sm3_ni_native = ($major > 2) || ($major == 2 && $minor > 16) || ($major == 2 && $minor == 16 && $patch >= 2); # support added at NASM 2.16.02
 }
diff --git a/crypto/sm3/legacy_sm3.c b/crypto/sm3/legacy_sm3.c
index b71e79af24..7f5ee97807 100644
--- a/crypto/sm3/legacy_sm3.c
+++ b/crypto/sm3/legacy_sm3.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2017-2021 The OpenSSL Project Authors. All Rights Reserved.
  * Copyright 2017 Ribose Inc. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
@@ -9,15 +9,19 @@
  */
 
 #include "crypto/evp.h"
+#include "../evp/legacy_meth.h"
 #include "internal/sm3.h"
 
+IMPLEMENT_LEGACY_EVP_MD_METH_LC(sm3_int, ossl_sm3)
+
 static const EVP_MD sm3_md = {
     NID_sm3,
     NID_sm3WithRSAEncryption,
     SM3_DIGEST_LENGTH,
     0,
     EVP_ORIG_GLOBAL,
-    SM3_CBLOCK
+    LEGACY_EVP_MD_METH_TABLE(sm3_int_init, sm3_int_update, sm3_int_final, NULL,
+        SM3_CBLOCK),
 };
 
 const EVP_MD *EVP_sm3(void)
diff --git a/crypto/sm3/sm3_local.h b/crypto/sm3/sm3_local.h
index 41639b3c95..d6c9a96710 100644
--- a/crypto/sm3/sm3_local.h
+++ b/crypto/sm3/sm3_local.h
@@ -9,9 +9,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_SM3_SM3_LOCAL_H)
-#define OSSL_LIBCRYPTO_SM3_SM3_LOCAL_H
-
 #include 
 #include "internal/cryptlib.h"
 #include "internal/sm3.h"
@@ -47,12 +44,12 @@
 
 #if defined(OPENSSL_SM3_ASM)
 #if defined(__aarch64__) || defined(_M_ARM64)
-#include "arch/arm_arch.h"
+#include "crypto/arm_arch.h"
 #define HWSM3_CAPABLE (OPENSSL_armcap_P & ARMV8_SM3)
 void ossl_hwsm3_block_data_order(SM3_CTX *c, const void *p, size_t num);
 #endif
 #if defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64
-#include "arch/riscv_arch.h"
+#include "crypto/riscv_arch.h"
 #define HWSM3_CAPABLE 1
 void ossl_hwsm3_block_data_order(SM3_CTX *c, const void *p, size_t num);
 #endif
@@ -72,12 +69,10 @@ void ossl_hwsm3_block_data_order(SM3_CTX *c, const void *p, size_t num);
 void ossl_sm3_block_data_order(SM3_CTX *c, const void *p, size_t num);
 void ossl_sm3_transform(SM3_CTX *c, const unsigned char *data);
 
-/* clang-format off */
-#include "crypto/md32_common.inc"
-/* clang-format on */
+#include "crypto/md32_common.h"
 
 #ifndef PEDANTIC
-#if defined(__GNUC__) && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM)
+#if defined(__GNUC__) && __GNUC__ >= 2 && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM)
 #if defined(__riscv_zksh)
 #define P0(x) ({ MD32_REG_T ret;        \
                        asm ("sm3p0 %0, %1" \
@@ -134,5 +129,3 @@ void ossl_sm3_transform(SM3_CTX *c, const unsigned char *data);
 #define SM3_F 0x163138aaUL
 #define SM3_G 0xe38dee4dUL
 #define SM3_H 0xb0fb0e4eUL
-
-#endif /* !defined(OSSL_LIBCRYPTO_SM3_SM3_LOCAL_H) */
diff --git a/crypto/sm3/sm3_riscv.c b/crypto/sm3/sm3_riscv.c
index 3dcb3d2938..f8abc4e277 100644
--- a/crypto/sm3/sm3_riscv.c
+++ b/crypto/sm3/sm3_riscv.c
@@ -12,7 +12,7 @@
 
 #include 
 #include "internal/sm3.h"
-#include "arch/riscv_arch.h"
+#include "crypto/riscv_arch.h"
 #include 
 
 void ossl_hwsm3_block_data_order_zvksh(SM3_CTX *c, const void *p, size_t num);
diff --git a/crypto/sm4/asm/sm4-armv8.pl b/crypto/sm4/asm/sm4-armv8.pl
index 8024922ece..1fe12dead4 100755
--- a/crypto/sm4/asm/sm4-armv8.pl
+++ b/crypto/sm4/asm/sm4-armv8.pl
@@ -111,7 +111,7 @@ ___
 }
 
 $code=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 .arch	armv8-a+crypto
 .text
 ___
diff --git a/crypto/sm4/asm/sm4-riscv64-zvksed.pl b/crypto/sm4/asm/sm4-riscv64-zvksed.pl
index 7fa3ff5ff8..66fd127aed 100644
--- a/crypto/sm4/asm/sm4-riscv64-zvksed.pl
+++ b/crypto/sm4/asm/sm4-riscv64-zvksed.pl
@@ -2,7 +2,7 @@
 # This file is dual-licensed, meaning that you can use it under your
 # choice of either of the following two licenses:
 #
-# Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved.
+# Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.
 #
 # Licensed under the Apache License 2.0 (the "License"). You can obtain
 # a copy in the file LICENSE in the source distribution or at
@@ -236,14 +236,8 @@ my ($in,$out,$len,$keys,$ivp)=("a0","a1","a2","a3","a4");
 my ($tmp,$base)=("t0","t2");
 my ($vdata0,$vdata1,$vdata2,$vdata3,$vdata4,$vdata5,$vdata6,$vdata7)=("v1","v2","v3","v4","v5","v6","v7","v24");
 my ($vivec)=("v8");
-my ($vindex)=("v0");
 
 $code .= <<___;
-.section .rodata
-.align 4
-.Lreverse_index:
-    .word 3, 2, 1, 0
-.text
 .p2align 3
 .globl rv64i_zvksed_sm4_cbc_encrypt
 .type rv64i_zvksed_sm4_cbc_encrypt,\@function
@@ -260,10 +254,6 @@ rv64i_zvksed_sm4_cbc_encrypt:
 
     # Load IV
     @{[vle32_v $vivec, $ivp]}
-
-    # Load the reverse index (for IV updates)
-    la $tmp, .Lreverse_index
-    @{[vle32_v $vindex, $tmp]}
 # =====================================================
 # If data length ≥ 64 bytes, process 4 blocks in batch:
 # 4-block CBC encryption pipeline:
@@ -295,8 +285,12 @@ rv64i_zvksed_sm4_cbc_encrypt:
     @{[enc_blk $vdata0]}
     @{[vrev8_v $vdata0, $vdata0]}
 
+    # Save the ciphertext (in reverse element order)
+    li $tmp_stride, $STRIDE
+    @{[reverse_order_S $vdata0, $out]}
     #Update IV to ciphertext block 0
-    @{[vrgather_vv $vivec, $vdata0, $vindex]}
+    @{[vle32_v $vivec, $out]}
+    addi $out, $out, $BLOCK_SIZE
 
     @{[vxor_vv $vdata1, $vdata1, $vivec]}
 
@@ -304,8 +298,11 @@ rv64i_zvksed_sm4_cbc_encrypt:
     @{[enc_blk $vdata1]}
     @{[vrev8_v $vdata1, $vdata1]}
 
+    @{[reverse_order_S $vdata1, $out]}
+
     #Update IV to ciphertext block 1
-    @{[vrgather_vv $vivec, $vdata1, $vindex]}
+    @{[vle32_v $vivec, $out]}
+    addi $out, $out, $BLOCK_SIZE
 
     @{[vxor_vv $vdata2, $vdata2, $vivec]}
 
@@ -313,8 +310,10 @@ rv64i_zvksed_sm4_cbc_encrypt:
     @{[enc_blk $vdata2]}
     @{[vrev8_v $vdata2, $vdata2]}
 
+    @{[reverse_order_S $vdata2, $out]}
     #Update IV to ciphertext block 2
-    @{[vrgather_vv $vivec, $vdata2, $vindex]}
+    @{[vle32_v $vivec, $out]}
+    addi $out, $out, $BLOCK_SIZE
 
     @{[vxor_vv $vdata3, $vdata3, $vivec]}
 
@@ -322,18 +321,9 @@ rv64i_zvksed_sm4_cbc_encrypt:
     @{[enc_blk $vdata3]}
     @{[vrev8_v $vdata3, $vdata3]}
 
-    #Update IV to ciphertext block 3
-    @{[vrgather_vv $vivec, $vdata3, $vindex]}
-
-    # Save the ciphertext (in reverse element order)
-    li $tmp_stride, $STRIDE
-    @{[reverse_order_S $vdata0, $out]}
-    addi $out, $out, $BLOCK_SIZE
-    @{[reverse_order_S $vdata1, $out]}
-    addi $out, $out, $BLOCK_SIZE
-    @{[reverse_order_S $vdata2, $out]}
-    addi $out, $out, $BLOCK_SIZE
     @{[reverse_order_S $vdata3, $out]}
+    #Update IV to ciphertext block 3
+    @{[vle32_v $vivec, $out]}
     addi $out, $out, $BLOCK_SIZE
 
     addi $len, $len, -$FOUR_BLOCKS
@@ -354,12 +344,12 @@ rv64i_zvksed_sm4_cbc_encrypt:
     @{[enc_blk $vdata0]}
     @{[vrev8_v $vdata0, $vdata0]}
 
-    # Update IV to ciphertext block 0
-    @{[vrgather_vv $vivec, $vdata0, $vindex]}
-
     # Save the ciphertext (in reverse element order)
     li $tmp_stride, $STRIDE
     @{[reverse_order_S $vdata0, $out]}
+
+    # Update IV to ciphertext block 0
+    @{[vle32_v $vivec, $out]}
     addi $out, $out, $BLOCK_SIZE
     addi $len, $len, -$BLOCK_SIZE
 
@@ -451,56 +441,56 @@ rv64i_zvksed_sm4_cbc_decrypt:
     addi $base, $in, -128
     @{[reverse_order_L $vivec, $base]}
 
+    # Save the plaintext (in reverse element order)
+    @{[reverse_order_S $vdata0, $out]}
+    addi $out, $out, $BLOCK_SIZE
+
     @{[vxor_vv $vdata1, $vdata1, $vivec]}
 
     addi $base, $in, -112
     @{[reverse_order_L $vivec, $base]}
+    @{[reverse_order_S $vdata1, $out]}
+    addi $out, $out, $BLOCK_SIZE
 
     @{[vxor_vv $vdata2, $vdata2, $vivec]}
 
     addi $base, $in, -96
     @{[reverse_order_L $vivec, $base]}
+    @{[reverse_order_S $vdata2, $out]}
+    addi $out, $out, $BLOCK_SIZE
 
     @{[vxor_vv $vdata3, $vdata3, $vivec]}
 
     addi $base, $in, -80
     @{[reverse_order_L $vivec, $base]}
+    @{[reverse_order_S $vdata3, $out]}
+    addi $out, $out, $BLOCK_SIZE
 
     @{[vxor_vv $vdata4, $vdata4, $vivec]}
 
     addi $base, $in, -64
     @{[reverse_order_L $vivec, $base]}
+    @{[reverse_order_S $vdata4, $out]}
+    addi $out, $out, $BLOCK_SIZE
 
     @{[vxor_vv $vdata5, $vdata5, $vivec]}
 
     addi $base, $in, -48
     @{[reverse_order_L $vivec, $base]}
+    @{[reverse_order_S $vdata5, $out]}
+    addi $out, $out, $BLOCK_SIZE
 
     @{[vxor_vv $vdata6, $vdata6, $vivec]}
 
     addi $base, $in, -32
     @{[reverse_order_L $vivec, $base]}
+    @{[reverse_order_S $vdata6, $out]}
+    addi $out, $out, $BLOCK_SIZE
 
     @{[vxor_vv $vdata7, $vdata7, $vivec]}
 
     addi $base, $in, -16
     @{[reverse_order_L $vivec, $base]}
-
-    # Save the plaintext (in reverse element order)
-    @{[reverse_order_S $vdata0, $out]}
-    addi $out, $out, $BLOCK_SIZE
-    @{[reverse_order_S $vdata1, $out]}
-    addi $out, $out, $BLOCK_SIZE
-    @{[reverse_order_S $vdata2, $out]}
-    addi $out, $out, $BLOCK_SIZE
-    @{[reverse_order_S $vdata3, $out]}
-    addi $out, $out, $BLOCK_SIZE
-    @{[reverse_order_S $vdata4, $out]}
-    addi $out, $out, $BLOCK_SIZE
-    @{[reverse_order_S $vdata5, $out]}
-    addi $out, $out, $BLOCK_SIZE
-    @{[reverse_order_S $vdata6, $out]}
-    addi $out, $out, $BLOCK_SIZE
     @{[reverse_order_S $vdata7, $out]}
     addi $out, $out, $BLOCK_SIZE
 
@@ -548,29 +538,28 @@ rv64i_zvksed_sm4_cbc_decrypt:
     # Update ciphertext to IV (in reverse element order)
     addi $base, $in, -64
     @{[reverse_order_L $vivec, $base]}
+    # Save the plaintext (in reverse element order)
+    @{[reverse_order_S $vdata0, $out]}
+    addi $out, $out, $BLOCK_SIZE
 
     @{[vxor_vv $vdata1, $vdata1, $vivec]}
 
     addi $base, $in, -48
     @{[reverse_order_L $vivec, $base]}
+    @{[reverse_order_S $vdata1, $out]}
+    addi $out, $out, $BLOCK_SIZE
 
     @{[vxor_vv $vdata2, $vdata2, $vivec]}
 
     addi $base, $in, -32
     @{[reverse_order_L $vivec, $base]}
+    @{[reverse_order_S $vdata2, $out]}
+    addi $out, $out, $BLOCK_SIZE
 
     @{[vxor_vv $vdata3, $vdata3, $vivec]}
 
     addi $base, $in, -16
     @{[reverse_order_L $vivec, $base]}
-
-    # Save the plaintext (in reverse element order)
-    @{[reverse_order_S $vdata0, $out]}
-    addi $out, $out, $BLOCK_SIZE
-    @{[reverse_order_S $vdata1, $out]}
-    addi $out, $out, $BLOCK_SIZE
-    @{[reverse_order_S $vdata2, $out]}
-    addi $out, $out, $BLOCK_SIZE
     @{[reverse_order_S $vdata3, $out]}
     addi $out, $out, $BLOCK_SIZE
 
diff --git a/crypto/sm4/asm/sm4-x86_64.pl b/crypto/sm4/asm/sm4-x86_64.pl
index f5b485968e..9fc40fb96a 100644
--- a/crypto/sm4/asm/sm4-x86_64.pl
+++ b/crypto/sm4/asm/sm4-x86_64.pl
@@ -35,8 +35,8 @@ if (`$ENV{CC} -Wa,-v -c -o /dev/null -x assembler /dev/null 2>&1`
 }
 
 if (!$avx2_sm4_ni && $win64 && ($flavour =~ /nasm/ || $ENV{ASM} =~ /nasm/) &&
-       `nasm -v 2>&1` =~ /NASM version ([2-9])\.([0-9]+)(?:\.([0-9]+))?/) {
-    my ($major, $minor, $patch) = ($1, $2, defined($3) ? $3 : 0);
+       `nasm -v 2>&1` =~ /NASM version ([2-9])\.([0-9]+)\.([0-9]+)/) {
+    my ($major, $minor, $patch) = ($1, $2, $3);
     $avx2_sm4_ni = ($major > 2) || ($major == 2 && $minor > 10); # minimal avx2 supported version, binary translation for SM4 instructions (sub sm4op) is used
     $avx2_sm4_ni_native = ($major > 2) || ($major == 2 && $minor > 16) || ($major == 2 && $minor == 16 && $patch >= 2); # support added at NASM 2.16.02
 }
diff --git a/crypto/sm4/asm/vpsm4-armv8.pl b/crypto/sm4/asm/vpsm4-armv8.pl
index e242af75ee..c60ace1536 100755
--- a/crypto/sm4/asm/vpsm4-armv8.pl
+++ b/crypto/sm4/asm/vpsm4-armv8.pl
@@ -537,7 +537,7 @@ ___
 }
 
 $code=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 .arch	armv8-a
 .text
 
diff --git a/crypto/sm4/asm/vpsm4_ex-armv8.pl b/crypto/sm4/asm/vpsm4_ex-armv8.pl
index fdb0d29947..2a1916268d 100644
--- a/crypto/sm4/asm/vpsm4_ex-armv8.pl
+++ b/crypto/sm4/asm/vpsm4_ex-armv8.pl
@@ -1,5 +1,5 @@
 #! /usr/bin/env perl
-# Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved.
+# Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved.
 #
 # Licensed under the Apache License 2.0 (the "License").  You may not use
 # this file except in compliance with the License.  You can obtain a copy
@@ -476,13 +476,12 @@ sub load_sbox () {
 
 $code.=<<___;
 	adrp $xtmp2, .Lsbox_magic
-	add $xtmp2, $xtmp2, #:lo12:.Lsbox_magic
-	ldr $MaskQ, [$xtmp2]
-	ldr $TAHMatQ, [$xtmp2, 16]
-	ldr $TALMatQ, [$xtmp2, 32]
-	ldr $ATAHMatQ, [$xtmp2, 48]
-	ldr $ATALMatQ, [$xtmp2, 64]
-	ldr $ANDMaskQ, [$xtmp2, 80]
+	ldr $MaskQ, [$xtmp2, #:lo12:.Lsbox_magic]
+	ldr $TAHMatQ, [$xtmp2, #:lo12:.Lsbox_magic+16]
+	ldr $TALMatQ, [$xtmp2, #:lo12:.Lsbox_magic+32]
+	ldr $ATAHMatQ, [$xtmp2, #:lo12:.Lsbox_magic+48]
+	ldr $ATALMatQ, [$xtmp2, #:lo12:.Lsbox_magic+64]
+	ldr $ANDMaskQ, [$xtmp2, #:lo12:.Lsbox_magic+80]
 ___
 }
 
@@ -539,7 +538,7 @@ ___
 }
 
 $code=<<___;
-#include "arch/arm_arch.h"
+#include "arm_arch.h"
 .arch	armv8-a+crypto
 .text
 
@@ -560,25 +559,13 @@ _${prefix}_consts:
 .Lshuffles:
 	.quad 0x0B0A090807060504,0x030201000F0E0D0C
 .Lxts_magic:
-#ifndef __AARCH64EB__
 	.quad 0x0101010101010187,0x0101010101010101
-#else
-	.quad 0x0101010101010101,0x0101010101010187
-#endif
 .Lsbox_magic:
-#ifndef __AARCH64EB__
 	.quad 0x0b0e0104070a0d00,0x0306090c0f020508
 	.quad 0x62185a2042387a00,0x22581a6002783a40
 	.quad 0x15df62a89e54e923,0xc10bb67c4a803df7
 	.quad 0xb9aa6b78c1d21300,0x1407c6d56c7fbead
 	.quad 0x6404462679195b3b,0xe383c1a1fe9edcbc
-#else
-	.quad 0x0306090c0f020508,0x0b0e0104070a0d00
-	.quad 0x22581a6002783a40,0x62185a2042387a00
-	.quad 0xc10bb67c4a803df7,0x15df62a89e54e923
-	.quad 0x1407c6d56c7fbead,0xb9aa6b78c1d21300
-	.quad 0xe383c1a1fe9edcbc,0x6404462679195b3b
-#endif
 	.quad 0x0f0f0f0f0f0f0f0f,0x0f0f0f0f0f0f0f0f
 
 .size	_${prefix}_consts,.-_${prefix}_consts
diff --git a/crypto/sparccpuid.S b/crypto/sparccpuid.S
index aa92241197..fa58db98b4 100644
--- a/crypto/sparccpuid.S
+++ b/crypto/sparccpuid.S
@@ -422,7 +422,3 @@ _sparcv9_vis1_instrument_bus2:
 	sub	%o3,%o1,%o0
 .type	_sparcv9_vis1_instrument_bus2,#function
 .size	_sparcv9_vis1_instrument_bus2,.-_sparcv9_vis1_instrument_bus2
-
-.section	".init",#alloc,#execinstr
-	call	OPENSSL_cpuid_setup
-	nop
diff --git a/crypto/sparcv9cap.c b/crypto/sparcv9cap.c
index cea44ada9b..b7f109581f 100644
--- a/crypto/sparcv9cap.c
+++ b/crypto/sparcv9cap.c
@@ -16,7 +16,7 @@
 #include 
 #include 
 #include "internal/cryptlib.h"
-#include "arch/sparc_arch.h"
+#include "crypto/sparc_arch.h"
 
 #if defined(__GNUC__) && defined(__linux)
 __attribute__((visibility("hidden")))
@@ -71,7 +71,7 @@ static void common_handler(int sig)
 }
 
 #if defined(__sun) && defined(__SVR4)
-#if defined(__GNUC__)
+#if defined(__GNUC__) && __GNUC__ >= 2
 extern unsigned int getisax(unsigned int vec[], unsigned int sz) __attribute__((weak));
 #elif defined(__SUNPRO_C)
 #pragma weak getisax
diff --git a/crypto/ssl_err.c b/crypto/ssl_err.c
index 9766b64314..6b88675200 100644
--- a/crypto/ssl_err.c
+++ b/crypto/ssl_err.c
@@ -1,6 +1,6 @@
 /*
  * Generated by util/mkerr.pl DO NOT EDIT
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -37,8 +37,6 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_BAD_DIGEST_LENGTH), "bad digest length" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_BAD_EARLY_DATA), "bad early data" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_BAD_ECC_CERT), "bad ecc cert" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_BAD_ECHCONFIG_EXTENSION),
-        "bad echconfig extension" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_BAD_ECPOINT), "bad ecpoint" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_BAD_EXTENSION), "bad extension" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_BAD_HANDSHAKE_LENGTH),
@@ -158,8 +156,6 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
         "ecc cert not for signing" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_ECDH_REQUIRED_FOR_SUITEB_MODE),
         "ecdh required for suiteb mode" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_ECH_DECODE_ERROR), "ech decode error" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_ECH_REQUIRED), "ech required" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_EE_KEY_TOO_SMALL), "ee key too small" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_EMPTY_RAW_PUBLIC_KEY),
         "empty raw public key" },
@@ -426,6 +422,36 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
         "srtp protection profile list too long" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SRTP_UNKNOWN_PROTECTION_PROFILE),
         "srtp unknown protection profile" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH),
+        "ssl3 ext invalid max fragment length" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSL3_EXT_INVALID_SERVERNAME),
+        "ssl3 ext invalid servername" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSL3_EXT_INVALID_SERVERNAME_TYPE),
+        "ssl3 ext invalid servername type" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSL3_SESSION_ID_TOO_LONG),
+        "ssl3 session id too long" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_BAD_CERTIFICATE),
+        "ssl/tls alert bad certificate" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_BAD_RECORD_MAC),
+        "ssl/tls alert bad record mac" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_CERTIFICATE_EXPIRED),
+        "ssl/tls alert certificate expired" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_CERTIFICATE_REVOKED),
+        "ssl/tls alert certificate revoked" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_CERTIFICATE_UNKNOWN),
+        "ssl/tls alert certificate unknown" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_DECOMPRESSION_FAILURE),
+        "ssl/tls alert decompression failure" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_HANDSHAKE_FAILURE),
+        "ssl/tls alert handshake failure" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_ILLEGAL_PARAMETER),
+        "ssl/tls alert illegal parameter" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_NO_CERTIFICATE),
+        "ssl/tls alert no certificate" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_UNEXPECTED_MESSAGE),
+        "ssl/tls alert unexpected message" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSLV3_ALERT_UNSUPPORTED_CERTIFICATE),
+        "ssl/tls alert unsupported certificate" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSL_COMMAND_SECTION_EMPTY),
         "ssl command section empty" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_SSL_COMMAND_SECTION_NOT_FOUND),
@@ -504,40 +530,10 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
         "tlsv1 unrecognized name" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLSV1_UNSUPPORTED_EXTENSION),
         "tlsv1 unsupported extension" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_BAD_CERTIFICATE),
-        "tls alert bad certificate" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_BAD_RECORD_MAC),
-        "tls alert bad record mac" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_CERTIFICATE_EXPIRED),
-        "tls alert certificate expired" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_CERTIFICATE_REVOKED),
-        "tls alert certificate revoked" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_CERTIFICATE_UNKNOWN),
-        "tls alert certificate unknown" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_DECOMPRESSION_FAILURE),
-        "tls alert decompression failure" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_HANDSHAKE_FAILURE),
-        "tls alert handshake failure" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_ILLEGAL_PARAMETER),
-        "tls alert illegal parameter" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_NO_CERTIFICATE),
-        "tls alert no certificate" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_UNEXPECTED_MESSAGE),
-        "tls alert unexpected message" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ALERT_UNSUPPORTED_CERTIFICATE),
-        "tls alert unsupported certificate" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH),
-        "tls ext invalid max fragment length" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_EXT_INVALID_SERVERNAME),
-        "tls ext invalid servername" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_EXT_INVALID_SERVERNAME_TYPE),
-        "tls ext invalid servername type" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_ILLEGAL_EXPORTER_LABEL),
         "tls illegal exporter label" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_INVALID_ECPOINTFORMAT_LIST),
         "tls invalid ecpointformat list" },
-    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TLS_SESSION_ID_TOO_LONG),
-        "tls session id too long" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TOO_MANY_KEY_UPDATES),
         "too many key updates" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_TOO_MANY_WARN_ALERTS),
@@ -548,6 +544,10 @@ static const ERR_STRING_DATA SSL_str_reasons[] = {
         "unable to find ecdh parameters" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNABLE_TO_FIND_PUBLIC_KEY_PARAMETERS),
         "unable to find public key parameters" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNABLE_TO_LOAD_SSL3_MD5_ROUTINES),
+        "unable to load ssl3 md5 routines" },
+    { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES),
+        "unable to load ssl3 sha1 routines" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_CCS_MESSAGE),
         "unexpected ccs message" },
     { ERR_PACK(ERR_LIB_SSL, 0, SSL_R_UNEXPECTED_END_OF_EARLY_DATA),
diff --git a/crypto/sslerr.h b/crypto/sslerr.h
index f2936b7d99..968f27b00a 100644
--- a/crypto/sslerr.h
+++ b/crypto/sslerr.h
@@ -1,6 +1,6 @@
 /*
  * Generated by util/mkerr.pl DO NOT EDIT
- * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
diff --git a/crypto/stack/stack.c b/crypto/stack/stack.c
index 5799bf9d7c..d35348743b 100644
--- a/crypto/stack/stack.c
+++ b/crypto/stack/stack.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -31,9 +31,7 @@ struct stack_st {
     int sorted;
     int num_alloc;
     OPENSSL_sk_compfunc comp;
-    int (*cmp_thunk)(OPENSSL_sk_compfunc, const void *, const void *);
     OPENSSL_sk_freefunc_thunk free_thunk;
-    OPENSSL_sk_copyfunc_thunk copy_thunk;
 };
 
 OPENSSL_sk_compfunc OPENSSL_sk_set_cmp_func(OPENSSL_STACK *sk,
@@ -48,16 +46,6 @@ OPENSSL_sk_compfunc OPENSSL_sk_set_cmp_func(OPENSSL_STACK *sk,
     return old;
 }
 
-static void free_with_thunk(OPENSSL_STACK *sk, OPENSSL_sk_freefunc free_func, const void *data)
-{
-    if (data == NULL)
-        return;
-    if (sk->free_thunk != NULL)
-        sk->free_thunk(free_func, (void *)data);
-    else
-        free_func((void *)data);
-}
-
 static OPENSSL_STACK *internal_copy(const OPENSSL_STACK *sk,
     OPENSSL_sk_copyfunc copy_func,
     OPENSSL_sk_freefunc free_func)
@@ -89,14 +77,10 @@ static OPENSSL_STACK *internal_copy(const OPENSSL_STACK *sk,
         for (i = 0; i < ret->num; ++i) {
             if (sk->data[i] == NULL)
                 continue;
-            if (ret->copy_thunk != NULL)
-                ret->data[i] = ret->copy_thunk(copy_func, sk->data[i]);
-            else
-                ret->data[i] = copy_func(sk->data[i]);
-
-            if (ret->data[i] == NULL) {
+            if ((ret->data[i] = copy_func(sk->data[i])) == NULL) {
                 while (--i >= 0)
-                    free_with_thunk(ret, free_func, ret->data[i]);
+                    if (ret->data[i] != NULL)
+                        free_func((void *)ret->data[i]);
                 goto err;
             }
         }
@@ -218,11 +202,6 @@ static int sk_reserve(OPENSSL_STACK *st, int n, int exact)
     return 1;
 }
 
-static ossl_inline int cmp_with_thunk(const OPENSSL_STACK *st, const void *a, const void *b)
-{
-    return (st->cmp_thunk == NULL) ? st->comp(a, b) : st->cmp_thunk(st->comp, a, b);
-}
-
 OPENSSL_STACK *OPENSSL_sk_new_reserve(OPENSSL_sk_compfunc c, int n)
 {
     OPENSSL_STACK *st = OPENSSL_zalloc(sizeof(OPENSSL_STACK));
@@ -264,26 +243,8 @@ OPENSSL_STACK *OPENSSL_sk_set_thunks(OPENSSL_STACK *st, OPENSSL_sk_freefunc_thun
     return st;
 }
 
-OPENSSL_STACK *OPENSSL_sk_set_cmp_thunks(OPENSSL_STACK *st, int (*c_thunk)(int (*)(const void *, const void *), const void *, const void *))
-{
-    if (st != NULL)
-        st->cmp_thunk = c_thunk;
-
-    return st;
-}
-
-OPENSSL_STACK *OPENSSL_sk_set_copy_thunks(OPENSSL_STACK *st, OPENSSL_sk_copyfunc_thunk cp_thunk)
-{
-    if (st != NULL)
-        st->copy_thunk = cp_thunk;
-
-    return st;
-}
-
 int OPENSSL_sk_insert(OPENSSL_STACK *st, const void *data, int loc)
 {
-    int cmp_ret;
-
     if (st == NULL) {
         ERR_raise(ERR_LIB_CRYPTO, ERR_R_PASSED_NULL_PARAMETER);
         return 0;
@@ -307,16 +268,11 @@ int OPENSSL_sk_insert(OPENSSL_STACK *st, const void *data, int loc)
     st->num++;
     if (st->sorted && st->num > 1) {
         if (st->comp != NULL) {
-            if (loc > 0) {
-                cmp_ret = cmp_with_thunk(st, &st->data[loc - 1], &st->data[loc]);
-                if (cmp_ret > 0)
-                    st->sorted = 0;
-            }
-            if (loc < st->num - 1) {
-                cmp_ret = cmp_with_thunk(st, &st->data[loc + 1], &st->data[loc]);
-                if (cmp_ret < 0)
-                    st->sorted = 0;
-            }
+            if (loc > 0 && (st->comp(&st->data[loc - 1], &st->data[loc]) > 0))
+                st->sorted = 0;
+            if (loc < st->num - 1
+                && (st->comp(&st->data[loc + 1], &st->data[loc]) < 0))
+                st->sorted = 0;
         } else {
             st->sorted = 0;
         }
@@ -363,7 +319,6 @@ static int internal_find(const OPENSSL_STACK *st, const void *data,
 {
     const void *r;
     int i, count = 0;
-    int cmp_ret;
     int *pnum = pnum_matched;
 
     if (st == NULL || st->num == 0)
@@ -388,9 +343,8 @@ static int internal_find(const OPENSSL_STACK *st, const void *data,
     if (!st->sorted) {
         int res = -1;
 
-        for (i = 0; i < st->num; i++) {
-            cmp_ret = cmp_with_thunk(st, &data, st->data + i);
-            if (cmp_ret == 0) {
+        for (i = 0; i < st->num; i++)
+            if (st->comp(&data, st->data + i) == 0) {
                 if (res == -1)
                     res = i;
                 ++*pnum;
@@ -398,7 +352,6 @@ static int internal_find(const OPENSSL_STACK *st, const void *data,
                 if (pnum_matched == NULL)
                     return i;
             }
-        }
         if (res == -1)
             *pnum = 0;
         return res;
@@ -406,7 +359,7 @@ static int internal_find(const OPENSSL_STACK *st, const void *data,
 
     if (pnum_matched != NULL)
         ret_val_options |= OSSL_BSEARCH_FIRST_VALUE_ON_MATCH;
-    r = ossl_bsearch(&data, st->data, st->num, sizeof(void *), st->comp, st->cmp_thunk,
+    r = ossl_bsearch(&data, st->data, st->num, sizeof(void *), st->comp,
         ret_val_options);
 
     if (pnum_matched != NULL) {
@@ -415,8 +368,7 @@ static int internal_find(const OPENSSL_STACK *st, const void *data,
             const void **p = (const void **)r;
 
             while (p < st->data + st->num) {
-                cmp_ret = cmp_with_thunk(st, &data, p);
-                if (cmp_ret != 0)
+                if (st->comp(&data, p) != 0)
                     break;
                 ++*pnum;
                 ++p;
@@ -483,9 +435,14 @@ void OPENSSL_sk_pop_free(OPENSSL_STACK *st, OPENSSL_sk_freefunc func)
     if (st == NULL)
         return;
 
-    for (i = 0; i < st->num; i++)
-        free_with_thunk(st, func, st->data[i]);
-
+    for (i = 0; i < st->num; i++) {
+        if (st->data[i] != NULL) {
+            if (st->free_thunk != NULL)
+                st->free_thunk(func, (void *)st->data[i]);
+            else
+                func((void *)st->data[i]);
+        }
+    }
     OPENSSL_sk_free(st);
 }
 
diff --git a/crypto/store/store_err.c b/crypto/store/store_err.c
index 8ee9d5eebe..afde022997 100644
--- a/crypto/store/store_err.c
+++ b/crypto/store/store_err.c
@@ -1,6 +1,6 @@
 /*
  * Generated by util/mkerr.pl DO NOT EDIT
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -39,7 +39,7 @@ static const ERR_STRING_DATA OSSL_STORE_str_reasons[] = {
     { ERR_PACK(ERR_LIB_OSSL_STORE, 0, OSSL_STORE_R_NOT_A_PUBLIC_KEY),
         "not a public key" },
     { ERR_PACK(ERR_LIB_OSSL_STORE, 0, OSSL_STORE_R_NOT_A_SYMMETRIC_KEY),
-        "not a symmetric key" },
+     "not a symmetric key" },
     { ERR_PACK(ERR_LIB_OSSL_STORE, 0, OSSL_STORE_R_NOT_PARAMETERS),
         "not parameters" },
     { ERR_PACK(ERR_LIB_OSSL_STORE, 0, OSSL_STORE_R_NO_LOADERS_FOUND),
diff --git a/crypto/store/store_lib.c b/crypto/store/store_lib.c
index 1086cbcd5b..ea0ab3423b 100644
--- a/crypto/store/store_lib.c
+++ b/crypto/store/store_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -498,10 +498,6 @@ int OSSL_STORE_delete(const char *uri, OSSL_LIB_CTX *libctx, const char *propq,
     int res = 0;
     struct ossl_passphrase_data_st pwdata = { 0 };
 
-    if (uri == NULL) {
-        ERR_raise(ERR_LIB_OSSL_STORE, ERR_R_PASSED_NULL_PARAMETER);
-        return 0;
-    }
     OPENSSL_strlcpy(scheme, uri, sizeof(scheme));
     if ((p = strchr(scheme, ':')) != NULL)
         *p++ = '\0';
@@ -942,7 +938,7 @@ int OSSL_STORE_supports_search(OSSL_STORE_CTX *ctx, int search_type)
 }
 
 /* Search term constructors */
-OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_name(const X509_NAME *name)
+OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_name(X509_NAME *name)
 {
     OSSL_STORE_SEARCH *search = OPENSSL_zalloc(sizeof(*search));
 
@@ -954,7 +950,7 @@ OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_name(const X509_NAME *name)
     return search;
 }
 
-OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_issuer_serial(const X509_NAME *name,
+OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_issuer_serial(X509_NAME *name,
     const ASN1_INTEGER *serial)
 {
     OSSL_STORE_SEARCH *search = OPENSSL_zalloc(sizeof(*search));
@@ -1026,7 +1022,7 @@ int OSSL_STORE_SEARCH_get_type(const OSSL_STORE_SEARCH *criterion)
     return criterion->search_type;
 }
 
-const X509_NAME *OSSL_STORE_SEARCH_get0_name(const OSSL_STORE_SEARCH *criterion)
+X509_NAME *OSSL_STORE_SEARCH_get0_name(const OSSL_STORE_SEARCH *criterion)
 {
     return criterion->name;
 }
diff --git a/crypto/store/store_local.h b/crypto/store/store_local.h
index 995024d5c9..dd7c107a50 100644
--- a/crypto/store/store_local.h
+++ b/crypto/store/store_local.h
@@ -1,5 +1,5 @@
 /*
- * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2016-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_STORE_STORE_LOCAL_H)
-#define OSSL_LIBCRYPTO_STORE_STORE_LOCAL_H
-
 #include 
 #include "internal/thread_once.h"
 #include "internal/refcount.h"
@@ -57,7 +54,7 @@ struct ossl_store_search_st {
      * Used by OSSL_STORE_SEARCH_BY_NAME and
      * OSSL_STORE_SEARCH_BY_ISSUER_SERIAL
      */
-    const X509_NAME *name;
+    X509_NAME *name;
 
     /* Used by OSSL_STORE_SEARCH_BY_ISSUER_SERIAL */
     const ASN1_INTEGER *serial;
@@ -104,7 +101,6 @@ struct ossl_store_loader_st {
     const char *propdef;
     const char *description;
 
-    int no_store;
     CRYPTO_REF_COUNT refcnt;
 
     OSSL_FUNC_store_open_fn *p_open;
@@ -179,5 +175,3 @@ struct ossl_load_result_data_st {
     OSSL_STORE_CTX *ctx;
 };
 OSSL_CALLBACK ossl_store_handle_load_result;
-
-#endif /* !defined(OSSL_LIBCRYPTO_STORE_STORE_LOCAL_H) */
diff --git a/crypto/store/store_meth.c b/crypto/store/store_meth.c
index 1d54d89978..63f41741a8 100644
--- a/crypto/store/store_meth.c
+++ b/crypto/store/store_meth.c
@@ -16,20 +16,17 @@
 #include "store_local.h"
 #include "crypto/context.h"
 
-static int up_ref_loader(void *method)
+int OSSL_STORE_LOADER_up_ref(OSSL_STORE_LOADER *loader)
 {
-    OSSL_STORE_LOADER *loader = (OSSL_STORE_LOADER *)method;
     int ref = 0;
 
     if (loader->prov != NULL)
-        return CRYPTO_UP_REF(&loader->refcnt, &ref);
+        CRYPTO_UP_REF(&loader->refcnt, &ref);
     return 1;
 }
 
-static void free_loader(void *method)
+void OSSL_STORE_LOADER_free(OSSL_STORE_LOADER *loader)
 {
-    OSSL_STORE_LOADER *loader = (OSSL_STORE_LOADER *)method;
-
     if (loader != NULL && loader->prov != NULL) {
         int i;
 
@@ -42,27 +39,6 @@ static void free_loader(void *method)
     OPENSSL_free(loader);
 }
 
-int OSSL_STORE_LOADER_up_ref(OSSL_STORE_LOADER *loader)
-{
-#ifdef OPENSSL_NO_CACHED_FETCH
-    return up_ref_loader(loader);
-#else
-    if (loader->no_store != 0)
-        return up_ref_loader(loader);
-    return 1;
-#endif
-}
-
-void OSSL_STORE_LOADER_free(OSSL_STORE_LOADER *loader)
-{
-#ifdef OPENSSL_NO_CACHED_FETCH
-    free_loader(loader);
-#else
-    if (loader != NULL && (loader->no_store != 0))
-        free_loader(loader);
-#endif
-}
-
 /*
  * OSSL_STORE_LOADER_new() expects the scheme as a constant string,
  * which we currently don't have, so we need an alternative allocator.
@@ -85,6 +61,16 @@ static OSSL_STORE_LOADER *new_loader(OSSL_PROVIDER *prov)
     return loader;
 }
 
+static int up_ref_loader(void *method)
+{
+    return OSSL_STORE_LOADER_up_ref(method);
+}
+
+static void free_loader(void *method)
+{
+    OSSL_STORE_LOADER_free(method);
+}
+
 /* Data to be passed through ossl_method_construct() */
 struct loader_data_st {
     OSSL_LIB_CTX *libctx;
@@ -186,11 +172,11 @@ static int put_loader_in_store(void *store, void *method,
         return 0;
 
     return ossl_method_store_add(store, prov, id, propdef, method,
-        up_ref_loader, free_loader);
+        up_ref_loader, free_loader, NULL, NULL);
 }
 
 static void *loader_from_algorithm(int scheme_id, const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, int no_store)
+    OSSL_PROVIDER *prov)
 {
     OSSL_STORE_LOADER *loader = NULL;
     const OSSL_DISPATCH *fns = algodef->implementation;
@@ -200,7 +186,6 @@ static void *loader_from_algorithm(int scheme_id, const OSSL_ALGORITHM *algodef,
     loader->scheme_id = scheme_id;
     loader->propdef = algodef->property_definition;
     loader->description = algodef->algorithm_description;
-    loader->no_store = no_store;
 
     for (; fns->function_id != 0; fns++) {
         switch (fns->function_id) {
@@ -252,7 +237,7 @@ static void *loader_from_algorithm(int scheme_id, const OSSL_ALGORITHM *algodef,
         || loader->p_eof == NULL
         || loader->p_close == NULL) {
         /* Only set_ctx_params is optional */
-        free_loader(loader);
+        OSSL_STORE_LOADER_free(loader);
         ERR_raise(ERR_LIB_OSSL_STORE, OSSL_STORE_R_LOADER_INCOMPLETE);
         return NULL;
     }
@@ -265,7 +250,7 @@ static void *loader_from_algorithm(int scheme_id, const OSSL_ALGORITHM *algodef,
  * then call loader_from_algorithm() with that identity number.
  */
 static void *construct_loader(const OSSL_ALGORITHM *algodef,
-    OSSL_PROVIDER *prov, void *data, int no_store)
+    OSSL_PROVIDER *prov, void *data)
 {
     /*
      * This function is only called if get_loader_from_store() returned
@@ -281,7 +266,7 @@ static void *construct_loader(const OSSL_ALGORITHM *algodef,
     void *method = NULL;
 
     if (id != 0)
-        method = loader_from_algorithm(id, algodef, prov, no_store);
+        method = loader_from_algorithm(id, algodef, prov);
 
     /*
      * Flag to indicate that there was actual construction errors.  This
@@ -297,7 +282,7 @@ static void *construct_loader(const OSSL_ALGORITHM *algodef,
 /* Intermediary function to avoid ugly casts, used below */
 static void destruct_loader(void *method, void *data)
 {
-    free_loader(method);
+    OSSL_STORE_LOADER_free(method);
 }
 
 /* Fetching support.  Can fetch by numeric identity or by scheme */
@@ -317,7 +302,7 @@ inner_loader_fetch(struct loader_data_st *methdata,
     }
 
     /* If we haven't received a name id yet, try to get one for the name */
-    id = ossl_namemap_name2num(namemap, scheme);
+    id = scheme != NULL ? ossl_namemap_name2num(namemap, scheme) : 0;
 
     /*
      * If we haven't found the name yet, chances are that the algorithm to
@@ -353,19 +338,8 @@ inner_loader_fetch(struct loader_data_st *methdata,
              */
             if (id == 0)
                 id = ossl_namemap_name2num(namemap, scheme);
-            if (id != 0 && methdata->tmp_store == NULL) {
-                ossl_method_store_cache_set(store, prov, id, propq, method,
-                    up_ref_loader, free_loader);
-            } else {
-                /*
-                 * Like with EVP methods, if the provider requests no caching we need
-                 * to take an extra refcount here so that the tmp_stored loader
-                 * lives beyond the freeing of that tmp_store
-                 */
-#ifndef OPENSSL_NO_CACHED_FETCH
-                OSSL_STORE_LOADER_up_ref((OSSL_STORE_LOADER *)method);
-#endif
-            }
+            ossl_method_store_cache_set(store, prov, id, propq, method,
+                up_ref_loader, free_loader, NULL, NULL);
         }
 
         /*
diff --git a/crypto/store/store_result.c b/crypto/store/store_result.c
index a47eb2a601..1900b42dcc 100644
--- a/crypto/store/store_result.c
+++ b/crypto/store/store_result.c
@@ -673,12 +673,11 @@ static int try_pkcs12(struct extracted_param_data_st *data, OSSL_STORE_INFO **v,
 }
 
 static int try_skey(struct extracted_param_data_st *data, OSSL_STORE_INFO **v,
-    const OSSL_PROVIDER *provider, OSSL_LIB_CTX *libctx, const char *propq)
+                    const OSSL_PROVIDER *provider, OSSL_LIB_CTX *libctx, const char *propq)
 {
     EVP_SKEY *skey = NULL;
     const char *skeymgmt_name = data->data_type == NULL
-        ? OSSL_SKEY_TYPE_GENERIC
-        : data->data_type;
+                                ? OSSL_SKEY_TYPE_GENERIC : data->data_type;
     size_t keysize = 0;
     unsigned char *keybytes = NULL;
 
@@ -686,13 +685,13 @@ static int try_skey(struct extracted_param_data_st *data, OSSL_STORE_INFO **v,
         return 0;
 
     if (data->octet_data != NULL) {
-        keysize = data->octet_data_size;
+        keysize  = data->octet_data_size;
         keybytes = (unsigned char *)data->octet_data;
         skey = EVP_SKEY_import_raw_key(libctx, skeymgmt_name,
-            keybytes, keysize, propq);
+                                       keybytes, keysize, propq);
     } else if (data->ref != NULL) {
         EVP_SKEYMGMT *skeymgmt = evp_skeymgmt_fetch_from_prov((OSSL_PROVIDER *)provider,
-            skeymgmt_name, propq);
+                                                              skeymgmt_name, propq);
         OSSL_PARAM params[2];
 
         /*
@@ -702,10 +701,10 @@ static int try_skey(struct extracted_param_data_st *data, OSSL_STORE_INFO **v,
         if (skeymgmt == NULL)
             return 0;
 
-        keysize = data->ref_size;
+        keysize  = data->ref_size;
         keybytes = (unsigned char *)data->ref;
         params[0] = OSSL_PARAM_construct_octet_ptr(OSSL_OBJECT_PARAM_REFERENCE,
-            (void **)&keybytes, keysize);
+                                                   (void **)&keybytes, keysize);
         params[1] = OSSL_PARAM_construct_end();
 
         skey = EVP_SKEY_import_SKEYMGMT(libctx, skeymgmt, OSSL_SKEYMGMT_SELECT_ALL, params);
diff --git a/crypto/thread/arch/thread_win.c b/crypto/thread/arch/thread_win.c
index 1026ed3de3..3240054702 100644
--- a/crypto/thread/arch/thread_win.c
+++ b/crypto/thread/arch/thread_win.c
@@ -7,11 +7,11 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include "internal/thread_arch.h"
-#include "internal/e_os.h"
+#include 
 
 #if defined(OPENSSL_THREADS_WINNT)
 #include 
+#include 
 
 static unsigned __stdcall thread_start_thunk(LPVOID vthread)
 {
@@ -590,4 +590,10 @@ void ossl_crypto_condvar_free(CRYPTO_CONDVAR **cv)
 }
 
 #endif
+
+void ossl_crypto_mem_barrier(void)
+{
+    MemoryBarrier();
+}
+
 #endif
diff --git a/crypto/threads_none.c b/crypto/threads_none.c
index 170fa32897..da807fc82c 100644
--- a/crypto/threads_none.c
+++ b/crypto/threads_none.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -72,23 +72,18 @@ void ossl_synchronize_rcu(CRYPTO_RCU_LOCK *lock)
     }
 }
 
-CRYPTO_RCU_CB_ITEM *ossl_rcu_cb_item_new(void)
+int ossl_rcu_call(CRYPTO_RCU_LOCK *lock, rcu_cb_fn cb, void *data)
 {
-    return OPENSSL_zalloc(sizeof(CRYPTO_RCU_CB_ITEM));
-}
+    struct rcu_cb_item *new = OPENSSL_zalloc(sizeof(*new));
 
-void ossl_rcu_cb_item_free(CRYPTO_RCU_CB_ITEM *item)
-{
-    OPENSSL_free(item);
-}
+    if (new == NULL)
+        return 0;
 
-void ossl_rcu_call(CRYPTO_RCU_LOCK *lock, CRYPTO_RCU_CB_ITEM *item,
-    rcu_cb_fn cb, void *data)
-{
-    item->fn = cb;
-    item->data = data;
-    item->next = lock->cb_items;
-    lock->cb_items = item;
+    new->fn = cb;
+    new->data = data;
+    new->next = lock->cb_items;
+    lock->cb_items = new;
+    return 1;
 }
 
 void *ossl_rcu_uptr_deref(void **p)
@@ -280,41 +275,6 @@ int CRYPTO_atomic_load_int(int *val, int *ret, CRYPTO_RWLOCK *lock)
     return 1;
 }
 
-int CRYPTO_atomic_store_int(int *dst, int val, CRYPTO_RWLOCK *lock)
-{
-    *dst = val;
-
-    return 1;
-}
-
-int CRYPTO_atomic_load_ptr(void **ptr, void **ret, CRYPTO_RWLOCK *lock)
-{
-    *ret = *ptr;
-    return 1;
-}
-
-int CRYPTO_atomic_store_ptr(void **dst, void **val, CRYPTO_RWLOCK *lock)
-{
-    *dst = *val;
-    return 1;
-}
-
-int CRYPTO_atomic_cmp_exch_ptr(void **ptr, void **expect, void *desire, CRYPTO_RWLOCK *lock, int *lock_failed)
-{
-    int lock_sink;
-
-    if (lock_failed == NULL)
-        lock_failed = &lock_sink;
-
-    *lock_failed = 0;
-    if (*ptr == *expect) {
-        *ptr = desire;
-        return 1;
-    }
-    *expect = *ptr;
-    return 0;
-}
-
 int openssl_init_fork_handlers(void)
 {
     return 0;
diff --git a/crypto/threads_pthread.c b/crypto/threads_pthread.c
index 7cf820b546..75d26c9b30 100644
--- a/crypto/threads_pthread.c
+++ b/crypto/threads_pthread.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -45,7 +45,14 @@
 #endif
 #include "rcu_internal.h"
 
+#if defined(__clang__) && defined(__has_feature)
+#if __has_feature(thread_sanitizer)
+#define __SANITIZE_THREAD__
+#endif
+#endif
+
 #if defined(__SANITIZE_THREAD__)
+#include 
 #define TSAN_FAKE_UNLOCK(x)          \
     __tsan_mutex_pre_unlock((x), 0); \
     __tsan_mutex_post_unlock((x), 0)
@@ -53,20 +60,27 @@
 #define TSAN_FAKE_LOCK(x)          \
     __tsan_mutex_pre_lock((x), 0); \
     __tsan_mutex_post_lock((x), 0, 0)
-
-#define TSAN_LOAD_MEM_ORDER __ATOMIC_ACQUIRE
-#define TSAN_STORE_MEM_ORDER __ATOMIC_RELEASE
 #else
 #define TSAN_FAKE_UNLOCK(x)
 #define TSAN_FAKE_LOCK(x)
-#define TSAN_LOAD_MEM_ORDER __ATOMIC_RELAXED
-#define TSAN_STORE_MEM_ORDER __ATOMIC_RELAXED
 #endif
 
 #if defined(__sun)
 #include 
 #endif
 
+#if defined(__apple_build_version__) && __apple_build_version__ < 6000000
+/*
+ * OS/X 10.7 and 10.8 had a weird version of clang which has __ATOMIC_ACQUIRE and
+ * __ATOMIC_ACQ_REL but which expects only one parameter for __atomic_is_lock_free()
+ * rather than two which has signature __atomic_is_lock_free(sizeof(_Atomic(T))).
+ * All of this makes impossible to use __atomic_is_lock_free here.
+ *
+ * See: https://github.com/llvm/llvm-project/commit/a4c2602b714e6c6edb98164550a5ae829b2de760
+ */
+#define BROKEN_CLANG_ATOMICS
+#endif
+
 #if defined(OPENSSL_THREADS) && !defined(CRYPTO_TDEBUG) && !defined(OPENSSL_SYS_WINDOWS)
 
 #if defined(OPENSSL_SYS_UNIX)
@@ -81,7 +95,7 @@
  * implementation
  * Likewise is there a problem with the glibc implementation on riscv.
  */
-#if defined(PTHREAD_RWLOCK_INITIALIZER) && !defined(_KLT_MODEL_) && !defined(_PUT_MODEL_) \
+#if defined(PTHREAD_RWLOCK_INITIALIZER) && !defined(_KLT_MODEL_) \
     && !defined(__riscv)
 #define USE_RWLOCK
 #endif
@@ -110,7 +124,8 @@
  */
 typedef void *pvoid;
 
-#if defined(OSSL_USE_GCC_ATOMICS)
+#if defined(__GNUC__) && defined(__ATOMIC_ACQUIRE) && !defined(BROKEN_CLANG_ATOMICS) \
+    && !defined(USE_ATOMIC_FALLBACKS)
 #define ATOMIC_LOAD_N(t, p, o) __atomic_load_n(p, o)
 #define ATOMIC_STORE_N(t, p, v, o) __atomic_store_n(p, v, o)
 #define ATOMIC_STORE(t, p, v, o) __atomic_store(p, v, o)
@@ -522,27 +537,24 @@ void ossl_synchronize_rcu(CRYPTO_RCU_LOCK *lock)
     }
 }
 
-CRYPTO_RCU_CB_ITEM *ossl_rcu_cb_item_new(void)
-{
-    return OPENSSL_zalloc(sizeof(CRYPTO_RCU_CB_ITEM));
-}
-
-void ossl_rcu_cb_item_free(CRYPTO_RCU_CB_ITEM *item)
-{
-    OPENSSL_free(item);
-}
-
 /*
  * Note: This call assumes its made under the protection of
  * ossl_rcu_write_lock
  */
-void ossl_rcu_call(CRYPTO_RCU_LOCK *lock, CRYPTO_RCU_CB_ITEM *item,
-    rcu_cb_fn cb, void *data)
+int ossl_rcu_call(CRYPTO_RCU_LOCK *lock, rcu_cb_fn cb, void *data)
 {
-    item->fn = cb;
-    item->data = data;
-    item->next = lock->cb_items;
-    lock->cb_items = item;
+    struct rcu_cb_item *new = OPENSSL_zalloc(sizeof(*new));
+
+    if (new == NULL)
+        return 0;
+
+    new->data = data;
+    new->fn = cb;
+
+    new->next = lock->cb_items;
+    lock->cb_items = new;
+
+    return 1;
 }
 
 void *ossl_rcu_uptr_deref(void **p)
@@ -558,9 +570,6 @@ void ossl_rcu_assign_uptr(void **p, void **v)
 CRYPTO_RCU_LOCK *ossl_rcu_lock_new(int num_writers, OSSL_LIB_CTX *ctx)
 {
     struct rcu_lock_st *new;
-    pthread_mutex_t *mutexes[3] = { NULL };
-    pthread_cond_t *conds[2] = { NULL };
-    int i;
 
     /*
      * We need a minimum of 2 qp's
@@ -577,40 +586,19 @@ CRYPTO_RCU_LOCK *ossl_rcu_lock_new(int num_writers, OSSL_LIB_CTX *ctx)
         return NULL;
 
     new->ctx = ctx;
-    i = 0;
-    mutexes[i] = pthread_mutex_init(&new->write_lock, NULL) == 0 ? &new->write_lock : NULL;
-    if (mutexes[i++] == NULL)
-        goto err;
-    mutexes[i] = pthread_mutex_init(&new->prior_lock, NULL) == 0 ? &new->prior_lock : NULL;
-    if (mutexes[i++] == NULL)
-        goto err;
-    mutexes[i] = pthread_mutex_init(&new->alloc_lock, NULL) == 0 ? &new->alloc_lock : NULL;
-    if (mutexes[i++] == NULL)
-        goto err;
-    conds[i - 3] = pthread_cond_init(&new->prior_signal, NULL) == 0 ? &new->prior_signal : NULL;
-    if (conds[i - 3] == NULL)
-        goto err;
-    i++;
-    conds[i - 3] = pthread_cond_init(&new->alloc_signal, NULL) == 0 ? &new->alloc_signal : NULL;
-    if (conds[i - 3] == NULL)
-        goto err;
-    i++;
+    pthread_mutex_init(&new->write_lock, NULL);
+    pthread_mutex_init(&new->prior_lock, NULL);
+    pthread_mutex_init(&new->alloc_lock, NULL);
+    pthread_cond_init(&new->prior_signal, NULL);
+    pthread_cond_init(&new->alloc_signal, NULL);
+
     new->qp_group = allocate_new_qp_group(new, num_writers);
-    if (new->qp_group == NULL)
-        goto err;
+    if (new->qp_group == NULL) {
+        OPENSSL_free(new);
+        new = NULL;
+    }
 
     return new;
-
-err:
-    for (i = 0; i < 3; i++)
-        if (mutexes[i] != NULL)
-            pthread_mutex_destroy(mutexes[i]);
-    for (i = 0; i < 2; i++)
-        if (conds[i] != NULL)
-            pthread_cond_destroy(conds[i]);
-    OPENSSL_free(new->qp_group);
-    OPENSSL_free(new);
-    return NULL;
 }
 
 void ossl_rcu_lock_free(CRYPTO_RCU_LOCK *lock)
@@ -624,17 +612,6 @@ void ossl_rcu_lock_free(CRYPTO_RCU_LOCK *lock)
     ossl_synchronize_rcu(rlock);
 
     OPENSSL_free(rlock->qp_group);
-    /*
-     * Some targets (BSD) allocate heap when initializing
-     * a mutex or condition, to prevent leaks, those need
-     * to be destroyed here
-     */
-    pthread_mutex_destroy(&rlock->write_lock);
-    pthread_mutex_destroy(&rlock->prior_lock);
-    pthread_mutex_destroy(&rlock->alloc_lock);
-    pthread_cond_destroy(&rlock->prior_signal);
-    pthread_cond_destroy(&rlock->alloc_signal);
-
     /* There should only be a single qp left now */
     OPENSSL_free(rlock);
 }
@@ -875,7 +852,6 @@ static ossl_inline int ossl_rwlock_unlock(pthread_rwlock_t *lock)
 
 #else /* !REPORT_RWLOCK_CONTENTION */
 
-#if defined(USE_RWLOCK)
 static ossl_inline void ossl_init_rwlock_contention_data(void)
 {
 }
@@ -894,7 +870,6 @@ static ossl_inline int ossl_rwlock_unlock(pthread_rwlock_t *rwlock)
 {
     return pthread_rwlock_unlock(rwlock);
 }
-#endif /* USE_RWLOCK */
 #endif /* REPORT_RWLOCK_CONTENTION */
 
 CRYPTO_RWLOCK *CRYPTO_THREAD_lock_new(void)
@@ -1053,12 +1028,12 @@ int CRYPTO_THREAD_compare_id(CRYPTO_THREAD_ID a, CRYPTO_THREAD_ID b)
 
 int CRYPTO_atomic_add(int *val, int amount, int *ret, CRYPTO_RWLOCK *lock)
 {
-#if defined(OSSL_USE_GCC_ATOMICS)
+#if defined(__GNUC__) && defined(__ATOMIC_ACQ_REL) && !defined(BROKEN_CLANG_ATOMICS)
     if (__atomic_is_lock_free(sizeof(*val), val)) {
         *ret = __atomic_add_fetch(val, amount, __ATOMIC_ACQ_REL);
         return 1;
     }
-#elif defined(OSSL_USE_SOLARIS_ATOMICS)
+#elif defined(__sun) && (defined(__SunOS_5_10) || defined(__SunOS_5_11))
     /* This will work for all future Solaris versions. */
     if (ret != NULL) {
         *ret = atomic_add_int_nv((volatile unsigned int *)val, amount);
@@ -1080,12 +1055,12 @@ int CRYPTO_atomic_add(int *val, int amount, int *ret, CRYPTO_RWLOCK *lock)
 int CRYPTO_atomic_add64(uint64_t *val, uint64_t op, uint64_t *ret,
     CRYPTO_RWLOCK *lock)
 {
-#if defined(OSSL_USE_GCC_ATOMICS)
+#if defined(__GNUC__) && defined(__ATOMIC_ACQ_REL) && !defined(BROKEN_CLANG_ATOMICS)
     if (__atomic_is_lock_free(sizeof(*val), val)) {
         *ret = __atomic_add_fetch(val, op, __ATOMIC_ACQ_REL);
         return 1;
     }
-#elif defined(OSSL_USE_SOLARIS_ATOMICS)
+#elif defined(__sun) && (defined(__SunOS_5_10) || defined(__SunOS_5_11))
     /* This will work for all future Solaris versions. */
     if (ret != NULL) {
         *ret = atomic_add_64_nv(val, op);
@@ -1106,12 +1081,12 @@ int CRYPTO_atomic_add64(uint64_t *val, uint64_t op, uint64_t *ret,
 int CRYPTO_atomic_and(uint64_t *val, uint64_t op, uint64_t *ret,
     CRYPTO_RWLOCK *lock)
 {
-#if defined(OSSL_USE_GCC_ATOMICS)
+#if defined(__GNUC__) && defined(__ATOMIC_ACQ_REL) && !defined(BROKEN_CLANG_ATOMICS)
     if (__atomic_is_lock_free(sizeof(*val), val)) {
         *ret = __atomic_and_fetch(val, op, __ATOMIC_ACQ_REL);
         return 1;
     }
-#elif defined(OSSL_USE_SOLARIS_ATOMICS)
+#elif defined(__sun) && (defined(__SunOS_5_10) || defined(__SunOS_5_11))
     /* This will work for all future Solaris versions. */
     if (ret != NULL) {
         *ret = atomic_and_64_nv(val, op);
@@ -1132,12 +1107,12 @@ int CRYPTO_atomic_and(uint64_t *val, uint64_t op, uint64_t *ret,
 int CRYPTO_atomic_or(uint64_t *val, uint64_t op, uint64_t *ret,
     CRYPTO_RWLOCK *lock)
 {
-#if defined(OSSL_USE_GCC_ATOMICS)
+#if defined(__GNUC__) && defined(__ATOMIC_ACQ_REL) && !defined(BROKEN_CLANG_ATOMICS)
     if (__atomic_is_lock_free(sizeof(*val), val)) {
         *ret = __atomic_or_fetch(val, op, __ATOMIC_ACQ_REL);
         return 1;
     }
-#elif defined(OSSL_USE_SOLARIS_ATOMICS)
+#elif defined(__sun) && (defined(__SunOS_5_10) || defined(__SunOS_5_11))
     /* This will work for all future Solaris versions. */
     if (ret != NULL) {
         *ret = atomic_or_64_nv(val, op);
@@ -1157,12 +1132,12 @@ int CRYPTO_atomic_or(uint64_t *val, uint64_t op, uint64_t *ret,
 
 int CRYPTO_atomic_load(uint64_t *val, uint64_t *ret, CRYPTO_RWLOCK *lock)
 {
-#if defined(OSSL_USE_GCC_ATOMICS)
+#if defined(__GNUC__) && defined(__ATOMIC_ACQ_REL) && !defined(BROKEN_CLANG_ATOMICS)
     if (__atomic_is_lock_free(sizeof(*val), val)) {
         __atomic_load(val, ret, __ATOMIC_ACQUIRE);
         return 1;
     }
-#elif defined(OSSL_USE_SOLARIS_ATOMICS)
+#elif defined(__sun) && (defined(__SunOS_5_10) || defined(__SunOS_5_11))
     /* This will work for all future Solaris versions. */
     if (ret != NULL) {
         *ret = atomic_or_64_nv(val, 0);
@@ -1180,12 +1155,12 @@ int CRYPTO_atomic_load(uint64_t *val, uint64_t *ret, CRYPTO_RWLOCK *lock)
 
 int CRYPTO_atomic_store(uint64_t *dst, uint64_t val, CRYPTO_RWLOCK *lock)
 {
-#if defined(OSSL_USE_GCC_ATOMICS)
+#if defined(__GNUC__) && defined(__ATOMIC_ACQ_REL) && !defined(BROKEN_CLANG_ATOMICS)
     if (__atomic_is_lock_free(sizeof(*dst), dst)) {
         __atomic_store(dst, &val, __ATOMIC_RELEASE);
         return 1;
     }
-#elif defined(OSSL_USE_SOLARIS_ATOMICS)
+#elif defined(__sun) && (defined(__SunOS_5_10) || defined(__SunOS_5_11))
     /* This will work for all future Solaris versions. */
     if (dst != NULL) {
         atomic_swap_64(dst, val);
@@ -1203,12 +1178,12 @@ int CRYPTO_atomic_store(uint64_t *dst, uint64_t val, CRYPTO_RWLOCK *lock)
 
 int CRYPTO_atomic_load_int(int *val, int *ret, CRYPTO_RWLOCK *lock)
 {
-#if defined(OSSL_USE_GCC_ATOMICS)
+#if defined(__GNUC__) && defined(__ATOMIC_ACQ_REL) && !defined(BROKEN_CLANG_ATOMICS)
     if (__atomic_is_lock_free(sizeof(*val), val)) {
         __atomic_load(val, ret, __ATOMIC_ACQUIRE);
         return 1;
     }
-#elif defined(OSSL_USE_SOLARIS_ATOMICS)
+#elif defined(__sun) && (defined(__SunOS_5_10) || defined(__SunOS_5_11))
     /* This will work for all future Solaris versions. */
     if (ret != NULL) {
         *ret = (int)atomic_or_uint_nv((unsigned int *)val, 0);
@@ -1224,89 +1199,6 @@ int CRYPTO_atomic_load_int(int *val, int *ret, CRYPTO_RWLOCK *lock)
     return 1;
 }
 
-int CRYPTO_atomic_store_int(int *dst, int val, CRYPTO_RWLOCK *lock)
-{
-#if defined(OSSL_USE_GCC_ATOMICS)
-    if (__atomic_is_lock_free(sizeof(*dst), dst)) {
-        __atomic_store(dst, &val, __ATOMIC_RELEASE);
-        return 1;
-    }
-#elif defined(OSSL_USE_SOLARIS_ATOMICS)
-    /* This will work for all future Solaris versions. */
-    if (dst != NULL) {
-        atomic_swap_uint((unsigned int)dst, (unsigned int)val);
-        return 1;
-    }
-#endif
-    if (lock == NULL || !CRYPTO_THREAD_write_lock(lock))
-        return 0;
-    *dst = val;
-    if (!CRYPTO_THREAD_unlock(lock))
-        return 0;
-
-    return 1;
-}
-
-int CRYPTO_atomic_load_ptr(void **ptr, void **ret, CRYPTO_RWLOCK *lock)
-{
-#if defined(__GNUC__) && defined(__ATOMIC_RELAXED) && !defined(BROKEN_CLANG_ATOMICS)
-    *ret = __atomic_load_n(ptr, TSAN_LOAD_MEM_ORDER);
-    return 1;
-#else
-    if (lock == NULL || !CRYPTO_THREAD_read_lock(lock))
-        return 0;
-    *ret = *ptr;
-    if (!CRYPTO_THREAD_unlock(lock))
-        return 0;
-    return 1;
-#endif
-}
-
-int CRYPTO_atomic_store_ptr(void **dst, void **val, CRYPTO_RWLOCK *lock)
-{
-#if defined(__GNUC__) && defined(__ATOMIC_RELAXED) && !defined(BROKEN_CLANG_ATOMICS)
-    __atomic_store(dst, val, TSAN_STORE_MEM_ORDER);
-    return 1;
-#else
-    if (lock == NULL || !CRYPTO_THREAD_write_lock(lock))
-        return 0;
-    *dst = *val;
-    if (!CRYPTO_THREAD_unlock(lock))
-        return 0;
-    return 1;
-#endif
-}
-
-int CRYPTO_atomic_cmp_exch_ptr(void **ptr, void **expect, void *desire, CRYPTO_RWLOCK *lock, int *lock_failed)
-{
-#if defined(__GNUC__) && defined(__ATOMIC_RELAXED) && !defined(BROKEN_CLANG_ATOMICS)
-    if (lock_failed != NULL)
-        *lock_failed = 0;
-    return __atomic_compare_exchange_n(ptr, expect, desire, 0, __ATOMIC_ACQ_REL, __ATOMIC_RELAXED) ? 1 : 0;
-#else
-    int lock_sink;
-    int ret = 0;
-
-    if (lock_failed == NULL)
-        lock_failed = &lock_sink;
-
-    *lock_failed = 0;
-    if (lock == NULL || !CRYPTO_THREAD_write_lock(lock)) {
-        *lock_failed = 1;
-        return 0;
-    }
-    if (*ptr == *expect) {
-        ret = 1;
-        *ptr = desire;
-    } else {
-        *expect = *ptr;
-    }
-    if (!CRYPTO_THREAD_unlock(lock))
-        *lock_failed = 1;
-    return ret;
-#endif
-}
-
 #ifndef FIPS_MODULE
 int openssl_init_fork_handlers(void)
 {
diff --git a/crypto/threads_win.c b/crypto/threads_win.c
index d777010cd8..c315c86404 100644
--- a/crypto/threads_win.c
+++ b/crypto/threads_win.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,13 +7,26 @@
  * https://www.openssl.org/source/license.html
  */
 
-#include "internal/e_os.h"
-
+#if defined(_WIN32)
+#include 
 #if defined(_WIN32_WINNT) && _WIN32_WINNT >= 0x600
 #define USE_RWLOCK
 #endif
-
+#endif
 #include 
+
+/*
+ * VC++ 2008 or earlier x86 compilers do not have an inline implementation
+ * of InterlockedOr64 for 32bit and will fail to run on Windows XP 32bit.
+ * https://docs.microsoft.com/en-us/cpp/intrinsics/interlockedor-intrinsic-functions#requirements
+ * To work around this problem, we implement a manual locking mechanism for
+ * only VC++ 2008 or earlier x86 compilers.
+ */
+
+#if ((defined(_MSC_VER) && defined(_M_IX86) && _MSC_VER <= 1600) || (defined(__MINGW32__) && !defined(__MINGW64__)))
+#define NO_INTERLOCKEDOR64
+#endif
+
 #include 
 #include 
 #include "internal/common.h"
@@ -38,7 +51,7 @@ typedef struct {
  * atomically updated
  */
 struct rcu_qp {
-    uint64_t users;
+    volatile uint64_t users;
 };
 
 struct thread_qp {
@@ -107,7 +120,7 @@ struct rcu_lock_st {
     /* signal to wake threads waiting on prior_lock */
     CRYPTO_CONDVAR *prior_signal;
 
-    /* lock used without OSSL_USE_INTERLOCKEDOR64: VS2010 x86, mingw32 */
+    /* lock used with NO_INTERLOCKEDOR64: VS2010 x86 */
     CRYPTO_RWLOCK *rw_lock;
 };
 
@@ -326,18 +339,17 @@ static struct rcu_qp *update_qp(CRYPTO_RCU_LOCK *lock, uint32_t *curr_id)
 
     /* update the reader index to be the prior qp */
     tmp = lock->current_alloc_idx;
-#if (!defined(OSSL_USE_INTERLOCKEDOR64))
-    /* This cannot fail, avoid unused result warning */
-    ossl_unused int r = CRYPTO_THREAD_write_lock(lock->rw_lock);
+#if (defined(NO_INTERLOCKEDOR64))
+    CRYPTO_THREAD_write_lock(lock->rw_lock);
     lock->reader_idx = tmp;
     CRYPTO_THREAD_unlock(lock->rw_lock);
 #else
     InterlockedExchange((LONG volatile *)&lock->reader_idx, tmp);
 #endif
 
-    ossl_crypto_mutex_unlock(lock->alloc_lock);
     /* wake up any waiters */
-    ossl_crypto_condvar_signal(lock->alloc_signal);
+    ossl_crypto_condvar_broadcast(lock->alloc_signal);
+    ossl_crypto_mutex_unlock(lock->alloc_lock);
     return &lock->qp_group[current_idx];
 }
 
@@ -346,8 +358,8 @@ static void retire_qp(CRYPTO_RCU_LOCK *lock,
 {
     ossl_crypto_mutex_lock(lock->alloc_lock);
     lock->writers_alloced--;
+    ossl_crypto_condvar_broadcast(lock->alloc_signal);
     ossl_crypto_mutex_unlock(lock->alloc_lock);
-    ossl_crypto_condvar_signal(lock->alloc_signal);
 }
 
 void ossl_synchronize_rcu(CRYPTO_RCU_LOCK *lock)
@@ -376,8 +388,8 @@ void ossl_synchronize_rcu(CRYPTO_RCU_LOCK *lock)
     } while (count != (uint64_t)0);
 
     lock->next_to_retire++;
-    ossl_crypto_mutex_unlock(lock->prior_lock);
     ossl_crypto_condvar_broadcast(lock->prior_signal);
+    ossl_crypto_mutex_unlock(lock->prior_lock);
 
     retire_qp(lock, qp);
 
@@ -393,26 +405,23 @@ void ossl_synchronize_rcu(CRYPTO_RCU_LOCK *lock)
     return;
 }
 
-CRYPTO_RCU_CB_ITEM *ossl_rcu_cb_item_new(void)
-{
-    return OPENSSL_zalloc(sizeof(CRYPTO_RCU_CB_ITEM));
-}
-
-void ossl_rcu_cb_item_free(CRYPTO_RCU_CB_ITEM *item)
-{
-    OPENSSL_free(item);
-}
-
 /*
  * Note, must be called under the protection of ossl_rcu_write_lock
  */
-void ossl_rcu_call(CRYPTO_RCU_LOCK *lock, CRYPTO_RCU_CB_ITEM *item,
-    rcu_cb_fn cb, void *data)
+int ossl_rcu_call(CRYPTO_RCU_LOCK *lock, rcu_cb_fn cb, void *data)
 {
-    item->fn = cb;
-    item->data = data;
-    item->next = lock->cb_items;
-    lock->cb_items = item;
+    struct rcu_cb_item *new;
+
+    new = OPENSSL_zalloc(sizeof(struct rcu_cb_item));
+    if (new == NULL)
+        return 0;
+    new->data = data;
+    new->fn = cb;
+
+    new->next = lock->cb_items;
+    lock->cb_items = new;
+
+    return 1;
 }
 
 void *ossl_rcu_uptr_deref(void **p)
@@ -442,11 +451,15 @@ CRYPTO_RWLOCK *CRYPTO_THREAD_lock_new(void)
         /* Don't set error, to avoid recursion blowup. */
         return NULL;
 
+#if !defined(_WIN32_WCE)
     /* 0x400 is the spin count value suggested in the documentation */
     if (!InitializeCriticalSectionAndSpinCount(lock, 0x400)) {
         OPENSSL_free(lock);
         return NULL;
     }
+#else
+    InitializeCriticalSection(lock);
+#endif
 #endif
 
     return lock;
@@ -527,20 +540,6 @@ int CRYPTO_THREAD_run_once(CRYPTO_ONCE *once, void (*init)(void))
         result = InterlockedCompareExchange(lock, ONCE_ININIT, ONCE_UNINITED);
         if (result == ONCE_UNINITED) {
             init();
-            /*
-             * On weakly ordered systems, it may happen that the write to *lock
-             * below completes prior to some writes in whatever the init()
-             * callback routine above may do.  In this case, other threads
-             * entering here may see unsynchronized data in whatever the init
-             * routine initializes, leading to erroneous behavior.
-             *
-             * We should use InitOnceExecuteOnce here to implement this, but
-             * doing so requires that we modify the definition of the
-             * CRYPTO_ONCE type, which is an ABI breakage.  So instead
-             * just insert a memory barrier here to ensure that any pending
-             * writes are flushed to memory prior to setting ONCE_DONE below
-             */
-            MemoryBarrier();
             *lock = ONCE_DONE;
             return 1;
         }
@@ -610,9 +609,8 @@ int CRYPTO_THREAD_compare_id(CRYPTO_THREAD_ID a, CRYPTO_THREAD_ID b)
 
 int CRYPTO_atomic_add(int *val, int amount, int *ret, CRYPTO_RWLOCK *lock)
 {
-#if (!defined(OSSL_USE_INTERLOCKEDOR64))
-    OPENSSL_assert(lock != NULL);
-    if (!CRYPTO_THREAD_write_lock(lock))
+#if (defined(NO_INTERLOCKEDOR64))
+    if (lock == NULL || !CRYPTO_THREAD_write_lock(lock))
         return 0;
     *val += amount;
     *ret = *val;
@@ -631,9 +629,8 @@ int CRYPTO_atomic_add(int *val, int amount, int *ret, CRYPTO_RWLOCK *lock)
 int CRYPTO_atomic_add64(uint64_t *val, uint64_t op, uint64_t *ret,
     CRYPTO_RWLOCK *lock)
 {
-#if (!defined(OSSL_USE_INTERLOCKEDOR64))
-    OPENSSL_assert(lock != NULL);
-    if (!CRYPTO_THREAD_write_lock(lock))
+#if (defined(NO_INTERLOCKEDOR64))
+    if (lock == NULL || !CRYPTO_THREAD_write_lock(lock))
         return 0;
     *val += op;
     *ret = *val;
@@ -651,9 +648,8 @@ int CRYPTO_atomic_add64(uint64_t *val, uint64_t op, uint64_t *ret,
 int CRYPTO_atomic_and(uint64_t *val, uint64_t op, uint64_t *ret,
     CRYPTO_RWLOCK *lock)
 {
-#if (!defined(OSSL_USE_INTERLOCKEDOR64))
-    OPENSSL_assert(lock != NULL);
-    if (!CRYPTO_THREAD_write_lock(lock))
+#if (defined(NO_INTERLOCKEDOR64))
+    if (lock == NULL || !CRYPTO_THREAD_write_lock(lock))
         return 0;
     *val &= op;
     *ret = *val;
@@ -671,9 +667,8 @@ int CRYPTO_atomic_and(uint64_t *val, uint64_t op, uint64_t *ret,
 int CRYPTO_atomic_or(uint64_t *val, uint64_t op, uint64_t *ret,
     CRYPTO_RWLOCK *lock)
 {
-#if (!defined(OSSL_USE_INTERLOCKEDOR64))
-    OPENSSL_assert(lock != NULL);
-    if (!CRYPTO_THREAD_write_lock(lock))
+#if (defined(NO_INTERLOCKEDOR64))
+    if (lock == NULL || !CRYPTO_THREAD_write_lock(lock))
         return 0;
     *val |= op;
     *ret = *val;
@@ -690,9 +685,8 @@ int CRYPTO_atomic_or(uint64_t *val, uint64_t op, uint64_t *ret,
 
 int CRYPTO_atomic_load(uint64_t *val, uint64_t *ret, CRYPTO_RWLOCK *lock)
 {
-#if (!defined(OSSL_USE_INTERLOCKEDOR64))
-    OPENSSL_assert(lock != NULL);
-    if (!CRYPTO_THREAD_read_lock(lock))
+#if (defined(NO_INTERLOCKEDOR64))
+    if (lock == NULL || !CRYPTO_THREAD_read_lock(lock))
         return 0;
     *ret = *val;
     if (!CRYPTO_THREAD_unlock(lock))
@@ -707,9 +701,8 @@ int CRYPTO_atomic_load(uint64_t *val, uint64_t *ret, CRYPTO_RWLOCK *lock)
 
 int CRYPTO_atomic_store(uint64_t *dst, uint64_t val, CRYPTO_RWLOCK *lock)
 {
-#if (!defined(OSSL_USE_INTERLOCKEDOR64))
-    OPENSSL_assert(lock != NULL);
-    if (!CRYPTO_THREAD_read_lock(lock))
+#if (defined(NO_INTERLOCKEDOR64))
+    if (lock == NULL || !CRYPTO_THREAD_read_lock(lock))
         return 0;
     *dst = val;
     if (!CRYPTO_THREAD_unlock(lock))
@@ -717,16 +710,15 @@ int CRYPTO_atomic_store(uint64_t *dst, uint64_t val, CRYPTO_RWLOCK *lock)
 
     return 1;
 #else
-    InterlockedExchange64((LONG64 volatile *)dst, val);
+    InterlockedExchange64(dst, val);
     return 1;
 #endif
 }
 
 int CRYPTO_atomic_load_int(int *val, int *ret, CRYPTO_RWLOCK *lock)
 {
-#if (!defined(OSSL_USE_INTERLOCKEDOR64))
-    OPENSSL_assert(lock != NULL);
-    if (!CRYPTO_THREAD_read_lock(lock))
+#if (defined(NO_INTERLOCKEDOR64))
+    if (lock == NULL || !CRYPTO_THREAD_read_lock(lock))
         return 0;
     *ret = *val;
     if (!CRYPTO_THREAD_unlock(lock))
@@ -740,57 +732,6 @@ int CRYPTO_atomic_load_int(int *val, int *ret, CRYPTO_RWLOCK *lock)
 #endif
 }
 
-int CRYPTO_atomic_store_int(int *dst, int val, CRYPTO_RWLOCK *lock)
-{
-#if (!defined(OSSL_USE_INTERLOCKEDOR64))
-    OPENSSL_assert(lock != NULL);
-    if (!CRYPTO_THREAD_read_lock(lock))
-        return 0;
-    *dst = val;
-    if (!CRYPTO_THREAD_unlock(lock))
-        return 0;
-
-    return 1;
-#else
-    InterlockedExchange((LONG volatile *)dst, val);
-    return 1;
-#endif
-}
-
-int CRYPTO_atomic_load_ptr(void **ptr, void **ret, CRYPTO_RWLOCK *lock)
-{
-    /*
-     * Windows doesn't have an atomic to do this properly, but the ms learn
-     * site here:
-     * https://learn.microsoft.com/en-us/windows/win32/api/winnt/nf-winnt-interlockedcompareexchangepointer
-     * suggests that using InterlockedCompareExchangePointer can be used to
-     * devise a load operation
-     */
-    *ret = InterlockedCompareExchangePointer(ptr, NULL, NULL);
-    return 1;
-}
-
-int CRYPTO_atomic_store_ptr(void **dst, void **val, CRYPTO_RWLOCK *lock)
-{
-    InterlockedExchangePointer(dst, *val);
-    return 1;
-}
-
-int CRYPTO_atomic_cmp_exch_ptr(void **ptr, void **expect, void *desire, CRYPTO_RWLOCK *lock, int *lock_failed)
-{
-    void *initial;
-
-    if (lock_failed != NULL)
-        lock_failed = 0;
-
-    /* Load the current pointer value */
-    initial = InterlockedCompareExchangePointer(ptr, desire, *expect);
-    if (*expect == initial)
-        return 1;
-    *expect = initial;
-    return 0;
-}
-
 int openssl_init_fork_handlers(void)
 {
     return 0;
diff --git a/crypto/ts/ts_asn1.c b/crypto/ts/ts_asn1.c
index 56d41df554..93a741d04d 100644
--- a/crypto/ts/ts_asn1.c
+++ b/crypto/ts/ts_asn1.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -17,7 +17,7 @@ ASN1_SEQUENCE(TS_MSG_IMPRINT) = {
     ASN1_SIMPLE(TS_MSG_IMPRINT, hashed_msg, ASN1_OCTET_STRING)
 } static_ASN1_SEQUENCE_END(TS_MSG_IMPRINT)
 
-IMPLEMENT_ASN1_FUNCTIONS(TS_MSG_IMPRINT)
+    IMPLEMENT_ASN1_FUNCTIONS(TS_MSG_IMPRINT)
 IMPLEMENT_ASN1_DUP_FUNCTION(TS_MSG_IMPRINT)
 TS_MSG_IMPRINT *d2i_TS_MSG_IMPRINT_bio(BIO *bp, TS_MSG_IMPRINT **a)
 {
@@ -51,7 +51,7 @@ ASN1_SEQUENCE(TS_REQ) = {
     ASN1_IMP_SEQUENCE_OF_OPT(TS_REQ, extensions, X509_EXTENSION, 0)
 } static_ASN1_SEQUENCE_END(TS_REQ)
 
-IMPLEMENT_ASN1_FUNCTIONS(TS_REQ)
+    IMPLEMENT_ASN1_FUNCTIONS(TS_REQ)
 IMPLEMENT_ASN1_DUP_FUNCTION(TS_REQ)
 TS_REQ *d2i_TS_REQ_bio(BIO *bp, TS_REQ **a)
 {
@@ -80,7 +80,7 @@ ASN1_SEQUENCE(TS_ACCURACY) = {
     ASN1_IMP_OPT(TS_ACCURACY, micros, ASN1_INTEGER, 1)
 } static_ASN1_SEQUENCE_END(TS_ACCURACY)
 
-IMPLEMENT_ASN1_FUNCTIONS(TS_ACCURACY)
+    IMPLEMENT_ASN1_FUNCTIONS(TS_ACCURACY)
 IMPLEMENT_ASN1_DUP_FUNCTION(TS_ACCURACY)
 
 ASN1_SEQUENCE(TS_TST_INFO) = {
@@ -96,7 +96,7 @@ ASN1_SEQUENCE(TS_TST_INFO) = {
     ASN1_IMP_SEQUENCE_OF_OPT(TS_TST_INFO, extensions, X509_EXTENSION, 1)
 } static_ASN1_SEQUENCE_END(TS_TST_INFO)
 
-IMPLEMENT_ASN1_FUNCTIONS(TS_TST_INFO)
+    IMPLEMENT_ASN1_FUNCTIONS(TS_TST_INFO)
 IMPLEMENT_ASN1_DUP_FUNCTION(TS_TST_INFO)
 TS_TST_INFO *d2i_TS_TST_INFO_bio(BIO *bp, TS_TST_INFO **a)
 {
@@ -127,7 +127,7 @@ ASN1_SEQUENCE(TS_STATUS_INFO) = {
     ASN1_OPT(TS_STATUS_INFO, failure_info, ASN1_BIT_STRING)
 } static_ASN1_SEQUENCE_END(TS_STATUS_INFO)
 
-IMPLEMENT_ASN1_FUNCTIONS(TS_STATUS_INFO)
+    IMPLEMENT_ASN1_FUNCTIONS(TS_STATUS_INFO)
 IMPLEMENT_ASN1_DUP_FUNCTION(TS_STATUS_INFO)
 
 static int ts_resp_set_tst_info(TS_RESP *a)
@@ -175,7 +175,7 @@ ASN1_SEQUENCE_cb(TS_RESP, ts_resp_cb) = {
     ASN1_OPT(TS_RESP, token, PKCS7),
 } static_ASN1_SEQUENCE_END_cb(TS_RESP, TS_RESP)
 
-IMPLEMENT_ASN1_FUNCTIONS(TS_RESP)
+    IMPLEMENT_ASN1_FUNCTIONS(TS_RESP)
 
 IMPLEMENT_ASN1_DUP_FUNCTION(TS_RESP)
 
@@ -208,7 +208,6 @@ TS_TST_INFO *PKCS7_to_TS_TST_INFO(PKCS7 *token)
     ASN1_TYPE *tst_info_wrapper;
     ASN1_OCTET_STRING *tst_info_der;
     const unsigned char *p;
-    size_t len;
 
     if (!PKCS7_type_is_signed(token)) {
         ERR_raise(ERR_LIB_TS, TS_R_BAD_PKCS7_TYPE);
@@ -230,11 +229,6 @@ TS_TST_INFO *PKCS7_to_TS_TST_INFO(PKCS7 *token)
         return NULL;
     }
     tst_info_der = tst_info_wrapper->value.octet_string;
-    p = ASN1_STRING_get0_data(tst_info_der);
-    len = ASN1_STRING_length_ex(tst_info_der);
-    if (len > INT_MAX) {
-        ERR_raise(ERR_LIB_TS, TS_R_BAD_TYPE);
-        return NULL;
-    }
-    return d2i_TS_TST_INFO(NULL, &p, (int)len);
+    p = tst_info_der->data;
+    return d2i_TS_TST_INFO(NULL, &p, tst_info_der->length);
 }
diff --git a/crypto/ts/ts_lib.c b/crypto/ts/ts_lib.c
index 26b3994ccb..c4392ef02e 100644
--- a/crypto/ts/ts_lib.c
+++ b/crypto/ts/ts_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -48,8 +48,8 @@ int TS_OBJ_print_bio(BIO *bio, const ASN1_OBJECT *obj)
 int TS_ext_print_bio(BIO *bio, const STACK_OF(X509_EXTENSION) *extensions)
 {
     int i, critical, n;
-    const X509_EXTENSION *ex;
-    const ASN1_OBJECT *obj;
+    X509_EXTENSION *ex;
+    ASN1_OBJECT *obj;
 
     BIO_printf(bio, "Extensions:\n");
     n = X509v3_get_ext_count(extensions);
@@ -86,7 +86,7 @@ int TS_MSG_IMPRINT_print_bio(BIO *bio, TS_MSG_IMPRINT *a)
     BIO_printf(bio, "Message data:\n");
     msg = a->hashed_msg;
     BIO_dump_indent(bio, (const char *)ASN1_STRING_get0_data(msg),
-        (int)ASN1_STRING_length_ex(msg), 4);
+        ASN1_STRING_length(msg), 4);
 
     return 1;
 }
diff --git a/crypto/ts/ts_local.h b/crypto/ts/ts_local.h
index be1be4ad5f..7aebad0948 100644
--- a/crypto/ts/ts_local.h
+++ b/crypto/ts/ts_local.h
@@ -7,19 +7,11 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_TS_TS_LOCAL_H)
-#define OSSL_LIBCRYPTO_TS_TS_LOCAL_H
-
-#include 
-#include 
-#include 
-
 /*-
  * MessageImprint ::= SEQUENCE  {
  *      hashAlgorithm                AlgorithmIdentifier,
  *      hashedMessage                OCTET STRING  }
  */
-
 struct TS_msg_imprint_st {
     X509_ALGOR *hash_algo;
     ASN1_OCTET_STRING *hashed_msg;
@@ -158,5 +150,3 @@ struct TS_verify_ctx {
     /* Must be set only with TS_VFY_TSA_NAME. */
     GENERAL_NAME *tsa_name;
 };
-
-#endif /* !defined(OSSL_LIBCRYPTO_TS_TS_LOCAL_H) */
diff --git a/crypto/ts/ts_req_utils.c b/crypto/ts/ts_req_utils.c
index 882b379d70..89e1bda450 100644
--- a/crypto/ts/ts_req_utils.c
+++ b/crypto/ts/ts_req_utils.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -162,14 +162,14 @@ int TS_REQ_get_ext_by_critical(TS_REQ *a, int crit, int lastpos)
     return X509v3_get_ext_by_critical(a->extensions, crit, lastpos);
 }
 
-const X509_EXTENSION *TS_REQ_get_ext(TS_REQ *a, int loc)
+X509_EXTENSION *TS_REQ_get_ext(TS_REQ *a, int loc)
 {
     return X509v3_get_ext(a->extensions, loc);
 }
 
 X509_EXTENSION *TS_REQ_delete_ext(TS_REQ *a, int loc)
 {
-    return X509v3_delete_extension(&a->extensions, loc);
+    return X509v3_delete_ext(a->extensions, loc);
 }
 
 int TS_REQ_add_ext(TS_REQ *a, X509_EXTENSION *ex, int loc)
diff --git a/crypto/ts/ts_rsp_sign.c b/crypto/ts/ts_rsp_sign.c
index e9151f750e..cdd8f4d401 100644
--- a/crypto/ts/ts_rsp_sign.c
+++ b/crypto/ts/ts_rsp_sign.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -298,7 +298,7 @@ int TS_RESP_CTX_set_status_info(TS_RESP_CTX *ctx,
     }
     if (text) {
         if ((utf8_text = ASN1_UTF8STRING_new()) == NULL
-            || !ASN1_STRING_set_string(utf8_text, text)) {
+            || !ASN1_STRING_set(utf8_text, text, (int)strlen(text))) {
             ERR_raise(ERR_LIB_TS, ERR_R_ASN1_LIB);
             goto err;
         }
@@ -487,7 +487,7 @@ static int ts_RESP_check_request(TS_RESP_CTX *ctx)
         return 0;
     }
     digest = msg_imprint->hashed_msg;
-    if (ASN1_STRING_length_ex(digest) != (size_t)md_size) {
+    if (digest->length != md_size) {
         TS_RESP_CTX_set_status_info(ctx, TS_STATUS_REJECTION,
             "Bad message digest.");
         TS_RESP_CTX_add_failure_info(ctx, TS_INFO_BAD_DATA_FORMAT);
@@ -645,7 +645,7 @@ static int ossl_ess_add1_signing_cert(PKCS7_SIGNER_INFO *si,
 
     p = pp;
     i2d_ESS_SIGNING_CERT(sc, &p);
-    if ((seq = ASN1_STRING_new()) == NULL || !ASN1_STRING_set_data(seq, pp, len)) {
+    if ((seq = ASN1_STRING_new()) == NULL || !ASN1_STRING_set(seq, pp, len)) {
         ASN1_STRING_free(seq);
         OPENSSL_free(pp);
         return 0;
@@ -676,7 +676,7 @@ static int ossl_ess_add1_signing_cert_v2(PKCS7_SIGNER_INFO *si,
 
     p = pp;
     i2d_ESS_SIGNING_CERT_V2(sc, &p);
-    if ((seq = ASN1_STRING_new()) == NULL || !ASN1_STRING_set_data(seq, pp, len)) {
+    if ((seq = ASN1_STRING_new()) == NULL || !ASN1_STRING_set(seq, pp, len)) {
         ASN1_STRING_free(seq);
         OPENSSL_free(pp);
         return 0;
diff --git a/crypto/ts/ts_rsp_utils.c b/crypto/ts/ts_rsp_utils.c
index 3ee394a07e..2352c7adb9 100644
--- a/crypto/ts/ts_rsp_utils.c
+++ b/crypto/ts/ts_rsp_utils.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -323,14 +323,14 @@ int TS_TST_INFO_get_ext_by_critical(TS_TST_INFO *a, int crit, int lastpos)
     return X509v3_get_ext_by_critical(a->extensions, crit, lastpos);
 }
 
-const X509_EXTENSION *TS_TST_INFO_get_ext(TS_TST_INFO *a, int loc)
+X509_EXTENSION *TS_TST_INFO_get_ext(TS_TST_INFO *a, int loc)
 {
     return X509v3_get_ext(a->extensions, loc);
 }
 
 X509_EXTENSION *TS_TST_INFO_delete_ext(TS_TST_INFO *a, int loc)
 {
-    return X509v3_delete_extension(&a->extensions, loc);
+    return X509v3_delete_ext(a->extensions, loc);
 }
 
 int TS_TST_INFO_add_ext(TS_TST_INFO *a, X509_EXTENSION *ex, int loc)
diff --git a/crypto/ts/ts_rsp_verify.c b/crypto/ts/ts_rsp_verify.c
index 1b45243ca8..3876e30f47 100644
--- a/crypto/ts/ts_rsp_verify.c
+++ b/crypto/ts/ts_rsp_verify.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -84,7 +84,7 @@ static const struct {
  *      - Verify the signature value.
  *      - Returns the signer certificate in 'signer', if 'signer' is not NULL.
  */
-int TS_RESP_verify_signature(PKCS7 *token, const STACK_OF(X509) *certs,
+int TS_RESP_verify_signature(PKCS7 *token, STACK_OF(X509) *certs,
     X509_STORE *store, X509 **signer_out)
 {
     STACK_OF(PKCS7_SIGNER_INFO) *sinfos = NULL;
@@ -205,34 +205,26 @@ end:
 
 static ESS_SIGNING_CERT *ossl_ess_get_signing_cert(const PKCS7_SIGNER_INFO *si)
 {
-    const ASN1_TYPE *attr;
+    ASN1_TYPE *attr;
     const unsigned char *p;
-    size_t len;
 
     attr = PKCS7_get_signed_attribute(si, NID_id_smime_aa_signingCertificate);
-    if (attr == NULL || attr->type != V_ASN1_SEQUENCE)
+    if (attr == NULL)
         return NULL;
-    p = ASN1_STRING_get0_data(attr->value.sequence);
-    len = ASN1_STRING_length_ex(attr->value.sequence);
-    if (len > INT_MAX)
-        return NULL;
-    return d2i_ESS_SIGNING_CERT(NULL, &p, (int)len);
+    p = attr->value.sequence->data;
+    return d2i_ESS_SIGNING_CERT(NULL, &p, attr->value.sequence->length);
 }
 
 static ESS_SIGNING_CERT_V2 *ossl_ess_get_signing_cert_v2(const PKCS7_SIGNER_INFO *si)
 {
-    const ASN1_TYPE *attr;
+    ASN1_TYPE *attr;
     const unsigned char *p;
-    size_t len;
 
     attr = PKCS7_get_signed_attribute(si, NID_id_smime_aa_signingCertificateV2);
-    if (attr == NULL || attr->type != V_ASN1_SEQUENCE)
+    if (attr == NULL)
         return NULL;
-    p = ASN1_STRING_get0_data(attr->value.sequence);
-    len = ASN1_STRING_length_ex(attr->value.sequence);
-    if (len > INT_MAX)
-        return NULL;
-    return d2i_ESS_SIGNING_CERT_V2(NULL, &p, (int)len);
+    p = attr->value.sequence->data;
+    return d2i_ESS_SIGNING_CERT_V2(NULL, &p, attr->value.sequence->length);
 }
 
 static int ts_check_signing_certs(const PKCS7_SIGNER_INFO *si,
@@ -442,10 +434,17 @@ static int ts_compute_imprint(BIO *data, TS_TST_INFO *tst_info,
 
     OBJ_obj2txt(name, sizeof(name), md_alg_resp->algorithm, 0);
 
+    (void)ERR_set_mark();
     md = EVP_MD_fetch(NULL, name, NULL);
+
+    if (md == NULL)
+        md = (EVP_MD *)EVP_get_digestbyname(name);
+
     if (md == NULL) {
+        (void)ERR_clear_last_mark();
         goto err;
     }
+    (void)ERR_pop_to_mark();
 
     length = EVP_MD_get_size(md);
     if (length <= 0)
@@ -490,7 +489,6 @@ static int ts_check_imprints(X509_ALGOR *algor_a,
     TS_MSG_IMPRINT *b = tst_info->msg_imprint;
     X509_ALGOR *algor_b = b->hash_algo;
     int ret = 0;
-    size_t len;
 
     if (algor_a) {
         if (OBJ_cmp(algor_a->algorithm, algor_b->algorithm))
@@ -504,11 +502,7 @@ static int ts_check_imprints(X509_ALGOR *algor_a,
             goto err;
     }
 
-    len = ASN1_STRING_length_ex(b->hashed_msg);
-    if (len > INT_MAX)
-        goto err;
-
-    ret = len_a == (unsigned)len && memcmp(imprint_a, ASN1_STRING_get0_data(b->hashed_msg), len) == 0;
+    ret = len_a == (unsigned)ASN1_STRING_length(b->hashed_msg) && memcmp(imprint_a, ASN1_STRING_get0_data(b->hashed_msg), len_a) == 0;
 err:
     if (!ret)
         ERR_raise(ERR_LIB_TS, TS_R_MESSAGE_IMPRINT_MISMATCH);
diff --git a/crypto/ts/ts_verify_ctx.c b/crypto/ts/ts_verify_ctx.c
index 76835866d7..ec9993ed9f 100644
--- a/crypto/ts/ts_verify_ctx.c
+++ b/crypto/ts/ts_verify_ctx.c
@@ -142,7 +142,6 @@ TS_VERIFY_CTX *TS_REQ_to_TS_VERIFY_CTX(TS_REQ *req, TS_VERIFY_CTX *ctx)
     X509_ALGOR *md_alg;
     ASN1_OCTET_STRING *msg;
     const ASN1_INTEGER *nonce;
-    size_t tmp;
 
     OPENSSL_assert(req != NULL);
     if (ret)
@@ -163,11 +162,8 @@ TS_VERIFY_CTX *TS_REQ_to_TS_VERIFY_CTX(TS_REQ *req, TS_VERIFY_CTX *ctx)
     if ((ret->md_alg = X509_ALGOR_dup(md_alg)) == NULL)
         goto err;
     msg = imprint->hashed_msg;
-    tmp = ASN1_STRING_length_ex(msg);
-    if (tmp > INT_MAX)
-        goto err;
-    ret->imprint_len = (unsigned int)tmp;
-    if (ret->imprint_len == 0)
+    ret->imprint_len = ASN1_STRING_length(msg);
+    if (ret->imprint_len <= 0)
         goto err;
     if ((ret->imprint = OPENSSL_malloc(ret->imprint_len)) == NULL)
         goto err;
diff --git a/crypto/ui/ui_openssl.c b/crypto/ui/ui_openssl.c
index 5b97cc6448..41823a739f 100644
--- a/crypto/ui/ui_openssl.c
+++ b/crypto/ui/ui_openssl.c
@@ -60,8 +60,11 @@
 #endif
 
 #ifdef WIN_CONSOLE_BUG
+#include 
+#ifndef OPENSSL_SYS_WINCE
 #include 
 #endif
+#endif
 
 /*
  * There are 6 types of terminal interface supported, TERMIO, TERMIOS, VMS,
@@ -163,7 +166,7 @@ static long tty_orig[3], tty_new[3]; /* XXX Is there any guarantee that this
                                       * structures? */
 static long status;
 static unsigned short channel = 0;
-#elif defined(_WIN32)
+#elif defined(_WIN32) && !defined(_WIN32_WCE)
 static DWORD tty_orig, tty_new;
 #else
 #if !defined(OPENSSL_SYS_MSDOS) || defined(__DJGPP__)
@@ -174,10 +177,12 @@ static FILE *tty_in, *tty_out;
 static int is_a_tty;
 
 /* Declare static functions */
+#if !defined(OPENSSL_SYS_WINCE)
 static int read_till_nl(FILE *);
 static void recsig(int);
 static void pushsig(void);
 static void popsig(void);
+#endif
 #if defined(OPENSSL_SYS_MSDOS) && !defined(_WIN32)
 static int noecho_fgets(char *buf, int size, FILE *tty);
 #endif
@@ -251,6 +256,7 @@ static int read_string(UI *ui, UI_STRING *uis)
     return 1;
 }
 
+#if !defined(OPENSSL_SYS_WINCE)
 /* Internal functions to read a string without echoing */
 static int read_till_nl(FILE *in)
 {
@@ -265,6 +271,7 @@ static int read_till_nl(FILE *in)
 }
 
 static volatile sig_atomic_t intr_signal;
+#endif
 
 static int read_string_inner(UI *ui, UI_STRING *uis, int echo, int strip_nl)
 {
@@ -272,6 +279,7 @@ static int read_string_inner(UI *ui, UI_STRING *uis, int echo, int strip_nl)
     int ok;
     char result[BUFSIZ];
     int maxsize = BUFSIZ - 1;
+#if !defined(OPENSSL_SYS_WINCE)
     char *p = NULL;
     int echo_eol = !echo;
 
@@ -351,6 +359,9 @@ error:
 
     if (ps >= 1)
         popsig();
+#else
+    ok = 1;
+#endif
 
     OPENSSL_cleanse(result, BUFSIZ);
     return ok;
@@ -366,7 +377,7 @@ static int open_console(UI *ui)
 #if defined(OPENSSL_SYS_VXWORKS)
     tty_in = stdin;
     tty_out = stderr;
-#elif defined(_WIN32)
+#elif defined(_WIN32) && !defined(_WIN32_WCE)
     if ((tty_out = fopen("conout$", "w")) == NULL)
         tty_out = stderr;
 
@@ -495,7 +506,7 @@ static int noecho_console(UI *ui)
         }
     }
 #endif
-#if defined(_WIN32)
+#if defined(_WIN32) && !defined(_WIN32_WCE)
     if (is_a_tty) {
         tty_new = tty_orig;
         tty_new &= ~ENABLE_ECHO_INPUT;
@@ -527,7 +538,7 @@ static int echo_console(UI *ui)
         }
     }
 #endif
-#if defined(_WIN32)
+#if defined(_WIN32) && !defined(_WIN32_WCE)
     if (is_a_tty) {
         tty_new = tty_orig;
         SetConsoleMode(GetStdHandle(STD_INPUT_HANDLE), tty_new);
@@ -557,6 +568,7 @@ static int close_console(UI *ui)
     return ret;
 }
 
+#if !defined(OPENSSL_SYS_WINCE)
 /* Internal functions to handle signals and act on them */
 static void pushsig(void)
 {
@@ -637,6 +649,7 @@ static void recsig(int i)
 {
     intr_signal = i;
 }
+#endif
 
 /* Internal functions specific for Windows */
 #if defined(OPENSSL_SYS_MSDOS) && !defined(_WIN32)
@@ -652,7 +665,11 @@ static int noecho_fgets(char *buf, int size, FILE *tty)
             break;
         }
         size--;
+#if defined(_WIN32)
+        i = _getch();
+#else
         i = getch();
+#endif
         if (i == '\r')
             i = '\n';
         *(p++) = i;
diff --git a/crypto/vms_rms.h b/crypto/vms_rms.h
index 3c3c98ea13..fed6cd0fc3 100644
--- a/crypto/vms_rms.h
+++ b/crypto/vms_rms.h
@@ -7,9 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_VMS_RMS_H)
-#define OSSL_LIBCRYPTO_VMS_RMS_H
-
 #ifdef NAML$C_MAXRSS
 
 #define CC_RMS_NAMX cc$rms_naml
@@ -61,5 +58,3 @@
 #endif /* def NAM$M_NO_SHORT_UPCASE [else] */
 
 #endif /* def NAML$C_MAXRSS [else] */
-
-#endif /* !defined(OSSL_LIBCRYPTO_VMS_RMS_H) */
diff --git a/crypto/whrlpool/wp_block.c b/crypto/whrlpool/wp_block.c
index 62fa849dad..dab8cf9793 100644
--- a/crypto/whrlpool/wp_block.c
+++ b/crypto/whrlpool/wp_block.c
@@ -44,9 +44,17 @@
 
 #include "internal/cryptlib.h"
 #include "wp_local.h"
-#include 
 #include 
 
+typedef unsigned char u8;
+#if (defined(_WIN32) || defined(_WIN64)) && !defined(__MINGW32)
+typedef unsigned __int64 u64;
+#elif defined(__arch64__)
+typedef unsigned long u64;
+#else
+typedef unsigned long long u64;
+#endif
+
 #define ROUNDS 10
 
 #define STRICT_ALIGNMENT
@@ -61,16 +69,16 @@
 
 #ifndef STRICT_ALIGNMENT
 #ifdef __GNUC__
-typedef uint64_t u64_a1 __attribute((__aligned__(1)));
+typedef u64 u64_a1 __attribute((__aligned__(1)));
 #else
-typedef uint64_t u64_a1;
+typedef u64 u64_a1;
 #endif
 #endif
 
 #if defined(__GNUC__) && !defined(STRICT_ALIGNMENT)
-typedef uint64_t u64_aX __attribute((__aligned__(1)));
+typedef u64 u64_aX __attribute((__aligned__(1)));
 #else
-typedef uint64_t u64_aX;
+typedef u64 u64_aX;
 #endif
 
 #undef SMALL_REGISTER_BANK
@@ -103,10 +111,10 @@ typedef uint64_t u64_aX;
 #pragma intrinsic(_rotl64)
 #define ROTATE(a, n) _rotl64((a), n)
 #endif
-#elif defined(__GNUC__)
+#elif defined(__GNUC__) && __GNUC__ >= 2
 #if defined(__x86_64) || defined(__x86_64__)
 #if defined(L_ENDIAN)
-#define ROTATE(a, n) ({ uint64_t ret; asm ("rolq %1,%0"   \
+#define ROTATE(a, n) ({ u64 ret; asm ("rolq %1,%0"   \
                                    : "=r"(ret) : "J"(n),"0"(a) : "cc"); ret; })
 #elif defined(B_ENDIAN)
 /*
@@ -116,15 +124,15 @@ typedef uint64_t u64_aX;
  * won't do same for x86_64? Naturally no. And this line is waiting
  * ready for that brave soul:-)
  */
-#define ROTATE(a, n) ({ uint64_t ret; asm ("rorq %1,%0"   \
+#define ROTATE(a, n) ({ u64 ret; asm ("rorq %1,%0"   \
                                    : "=r"(ret) : "J"(n),"0"(a) : "cc"); ret; })
 #endif
 #elif defined(__ia64) || defined(__ia64__)
 #if defined(L_ENDIAN)
-#define ROTATE(a, n) ({ uint64_t ret; asm ("shrp %0=%1,%1,%2"     \
+#define ROTATE(a, n) ({ u64 ret; asm ("shrp %0=%1,%1,%2"     \
                                    : "=r"(ret) : "r"(a),"M"(64-(n))); ret; })
 #elif defined(B_ENDIAN)
-#define ROTATE(a, n) ({ uint64_t ret; asm ("shrp %0=%1,%1,%2"     \
+#define ROTATE(a, n) ({ u64 ret; asm ("shrp %0=%1,%1,%2"     \
                                    : "=r"(ret) : "r"(a),"M"(n)); ret; })
 #endif
 #endif
@@ -202,7 +210,7 @@ typedef uint64_t u64_aX;
 #define N 2
 #define LL(c0, c1, c2, c3, c4, c5, c6, c7) c0, c1, c2, c3, c4, c5, c6, c7, \
                                            c0, c1, c2, c3, c4, c5, c6, c7
-#define C0(K, i) (((uint64_t *)(Cx.c + 0))[2 * K.c[(i) * 8 + 0]])
+#define C0(K, i) (((u64 *)(Cx.c + 0))[2 * K.c[(i) * 8 + 0]])
 #define C1(K, i) (((u64_a1 *)(Cx.c + 7))[2 * K.c[(i) * 8 + 1]])
 #define C2(K, i) (((u64_a1 *)(Cx.c + 6))[2 * K.c[(i) * 8 + 2]])
 #define C3(K, i) (((u64_a1 *)(Cx.c + 5))[2 * K.c[(i) * 8 + 3]])
@@ -213,8 +221,8 @@ typedef uint64_t u64_aX;
 #endif
 
 static const union {
-    uint8_t c[(256 * N + ROUNDS) * sizeof(uint64_t)];
-    uint64_t q[(256 * N + ROUNDS)];
+    u8 c[(256 * N + ROUNDS) * sizeof(u64)];
+    u64 q[(256 * N + ROUNDS)];
 } Cx = {
     { /* Note endian-neutral representation:-) */
         LL(0x18, 0x18, 0x60, 0x18, 0xc0, 0x78, 0x30, 0xd8),
@@ -488,10 +496,10 @@ static const union {
 void whirlpool_block(WHIRLPOOL_CTX *ctx, const void *inp, size_t n)
 {
     int r;
-    const uint8_t *p = inp;
+    const u8 *p = inp;
     union {
-        uint64_t q[8];
-        uint8_t c[64];
+        u64 q[8];
+        u8 c[64];
     } S, K, *H = (void *)ctx->H.q;
 
 #ifdef GO_FOR_MMX
@@ -499,7 +507,7 @@ void whirlpool_block(WHIRLPOOL_CTX *ctx, const void *inp, size_t n)
 #endif
     do {
 #ifdef OPENSSL_SMALL_FOOTPRINT
-        uint64_t L[8];
+        u64 L[8];
         int i;
 
         for (i = 0; i < 64; i++)
@@ -518,7 +526,7 @@ void whirlpool_block(WHIRLPOOL_CTX *ctx, const void *inp, size_t n)
         for (i = 0; i < 64; i++)
             H->c[i] ^= S.c[i] ^ p[i];
 #else
-        uint64_t L0, L1, L2, L3, L4, L5, L6, L7;
+        u64 L0, L1, L2, L3, L4, L5, L6, L7;
 
 #ifdef STRICT_ALIGNMENT
         if ((size_t)p & 7) {
diff --git a/crypto/whrlpool/wp_local.h b/crypto/whrlpool/wp_local.h
index 8e7c8b52ec..73dc2a003d 100644
--- a/crypto/whrlpool/wp_local.h
+++ b/crypto/whrlpool/wp_local.h
@@ -7,11 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_WHRLPOOL_WP_LOCAL_H)
-#define OSSL_LIBCRYPTO_WHRLPOOL_WP_LOCAL_H
-
 #include 
 
 void whirlpool_block(WHIRLPOOL_CTX *, const void *, size_t);
-
-#endif /* !defined(OSSL_LIBCRYPTO_WHRLPOOL_WP_LOCAL_H) */
diff --git a/crypto/x509/by_file.c b/crypto/x509/by_file.c
index 678c1bbb7e..5c99557649 100644
--- a/crypto/x509/by_file.c
+++ b/crypto/x509/by_file.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -17,8 +17,6 @@
 #include 
 #include "x509_local.h"
 
-#include 
-
 static int by_file_ctrl(X509_LOOKUP *ctx, int cmd, const char *argc,
     long argl, char **ret);
 static int by_file_ctrl_ex(X509_LOOKUP *ctx, int cmd, const char *argc,
diff --git a/crypto/x509/ext_dat.h b/crypto/x509/ext_dat.h
index 668f05c6e9..5d4c2fdb86 100644
--- a/crypto/x509/ext_dat.h
+++ b/crypto/x509/ext_dat.h
@@ -7,11 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_X509_EXT_DAT_H)
-#define OSSL_LIBCRYPTO_X509_EXT_DAT_H
-
-#include 
-
 int ossl_v3_name_cmp(const char *name, const char *cmp);
 
 extern const X509V3_EXT_METHOD ossl_v3_bcons, ossl_v3_nscert, ossl_v3_key_usage, ossl_v3_ext_ku;
@@ -54,5 +49,3 @@ extern const X509V3_EXT_METHOD ossl_v3_time_specification;
 extern const X509V3_EXT_METHOD ossl_v3_attribute_mappings;
 extern const X509V3_EXT_METHOD ossl_v3_allowed_attribute_assignments;
 extern const X509V3_EXT_METHOD ossl_v3_aa_issuing_dist_point;
-
-#endif /* !defined(OSSL_LIBCRYPTO_X509_EXT_DAT_H) */
diff --git a/crypto/x509/pcy_cache.c b/crypto/x509/pcy_cache.c
index bffa96fd6c..d1ee35377b 100644
--- a/crypto/x509/pcy_cache.c
+++ b/crypto/x509/pcy_cache.c
@@ -134,7 +134,6 @@ static int policy_cache_new(X509 *x)
         /* If not absent some problem with extension */
         if (i != -1)
             goto bad_cache;
-        POLICY_CONSTRAINTS_free(ext_pcons);
         return 1;
     }
 
@@ -142,10 +141,8 @@ static int policy_cache_new(X509 *x)
 
     /* NB: ext_cpols freed by policy_cache_set_policies */
 
-    if (i <= 0) {
-        POLICY_CONSTRAINTS_free(ext_pcons);
+    if (i <= 0)
         return i;
-    }
 
     ext_pmaps = X509_get_ext_d2i(x, NID_policy_mappings, &i, NULL);
 
diff --git a/crypto/x509/pcy_local.h b/crypto/x509/pcy_local.h
index 0892c8dd0b..957ea59723 100644
--- a/crypto/x509/pcy_local.h
+++ b/crypto/x509/pcy_local.h
@@ -7,14 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#if !defined(OSSL_LIBCRYPTO_X509_PCY_LOCAL_H)
-#define OSSL_LIBCRYPTO_X509_PCY_LOCAL_H
-
-#include 
-#include 
-#include 
-#include 
-
 typedef struct X509_POLICY_DATA_st X509_POLICY_DATA;
 
 DEFINE_STACK_OF(X509_POLICY_DATA)
@@ -177,5 +169,3 @@ int ossl_policy_node_match(const X509_POLICY_LEVEL *lvl,
     const X509_POLICY_NODE *node, const ASN1_OBJECT *oid);
 
 const X509_POLICY_CACHE *ossl_policy_cache_set(X509 *x);
-
-#endif /* !defined(OSSL_LIBCRYPTO_X509_PCY_LOCAL_H) */
diff --git a/crypto/x509/pcy_tree.c b/crypto/x509/pcy_tree.c
index ea3f8ae20b..cdf39ba5c7 100644
--- a/crypto/x509/pcy_tree.c
+++ b/crypto/x509/pcy_tree.c
@@ -680,10 +680,8 @@ int X509_policy_check(X509_POLICY_TREE **ptree, int *pexplicit_policy,
     } else {
         *pexplicit_policy = 1;
         /* Tree empty and requireExplicit True: Error */
-        if (init_ret & X509_PCY_TREE_EMPTY) {
-            X509_policy_tree_free(tree);
+        if (init_ret & X509_PCY_TREE_EMPTY)
             return X509_PCY_TREE_FAILURE;
-        }
     }
 
     ret = tree_evaluate(tree);
@@ -709,15 +707,13 @@ int X509_policy_check(X509_POLICY_TREE **ptree, int *pexplicit_policy,
     if (!ret)
         goto error;
 
+    *ptree = tree;
+
     if (init_ret & X509_PCY_TREE_EXPLICIT) {
         nodes = X509_policy_tree_get0_user_policies(tree);
-        if (sk_X509_POLICY_NODE_num(nodes) <= 0) {
-            X509_policy_tree_free(tree);
+        if (sk_X509_POLICY_NODE_num(nodes) <= 0)
             return X509_PCY_TREE_FAILURE;
-        }
     }
-
-    *ptree = tree;
     return X509_PCY_TREE_VALID;
 
 error:
diff --git a/crypto/x509/standard_exts.h b/crypto/x509/standard_exts.h
index e72cc98da7..46bda55558 100644
--- a/crypto/x509/standard_exts.h
+++ b/crypto/x509/standard_exts.h
@@ -12,11 +12,6 @@
  * of the ext_nid values.
  */
 
-#if !defined(OSSL_LIBCRYPTO_X509_STANDARD_EXTS_H)
-#define OSSL_LIBCRYPTO_X509_STANDARD_EXTS_H
-
-#include "ext_dat.h"
-
 static const X509V3_EXT_METHOD *const standard_exts[] = {
     &ossl_v3_nscert,
     &ossl_v3_ns_ia5_list[0],
@@ -102,5 +97,3 @@ static const X509V3_EXT_METHOD *const standard_exts[] = {
 /* Number of standard extensions */
 
 #define STANDARD_EXTENSION_COUNT OSSL_NELEM(standard_exts)
-
-#endif /* !defined(OSSL_LIBCRYPTO_X509_STANDARD_EXTS_H) */
diff --git a/crypto/x509/t_acert.c b/crypto/x509/t_acert.c
index f98c4c46b9..1ee6b9eacb 100644
--- a/crypto/x509/t_acert.c
+++ b/crypto/x509/t_acert.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -14,11 +14,9 @@
 #include 
 #include 
 
-#include 
-
 static int print_attribute(BIO *bp, X509_ATTRIBUTE *a)
 {
-    const ASN1_OBJECT *aobj;
+    ASN1_OBJECT *aobj;
     int i, j, count;
     int ret = 0;
 
@@ -42,7 +40,7 @@ static int print_attribute(BIO *bp, X509_ATTRIBUTE *a)
         goto err;
 
     for (i = 0; i < count; i++) {
-        const ASN1_TYPE *at;
+        ASN1_TYPE *at;
         int type;
         ASN1_BIT_STRING *bs;
 
@@ -64,10 +62,8 @@ static int print_attribute(BIO *bp, X509_ATTRIBUTE *a)
         case V_ASN1_SEQUENCE:
             if (BIO_puts(bp, "\n") <= 0)
                 goto err;
-            if (ASN1_parse_dump(bp, at->value.sequence->data,
-                    at->value.sequence->length, i, 1)
-                <= 0)
-                goto err;
+            ASN1_parse_dump(bp, at->value.sequence->data,
+                at->value.sequence->length, i, 1);
             break;
         default:
             if (BIO_printf(bp, "unable to print attribute of type 0x%X\n",
@@ -244,8 +240,8 @@ int X509_ACERT_print_ex(BIO *bp, X509_ACERT *x, unsigned long nmflags,
             if (BIO_printf(bp, "%8sExtensions:\n", "") <= 0)
                 goto err;
             for (i = 0; i < sk_X509_EXTENSION_num(exts); i++) {
-                const ASN1_OBJECT *obj;
-                const X509_EXTENSION *ex;
+                ASN1_OBJECT *obj;
+                X509_EXTENSION *ex;
                 int critical;
 
                 ex = sk_X509_EXTENSION_value(exts, i);
diff --git a/crypto/x509/t_req.c b/crypto/x509/t_req.c
index 0461b2ff89..bb10d6f6f1 100644
--- a/crypto/x509/t_req.c
+++ b/crypto/x509/t_req.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -17,8 +17,6 @@
 #include 
 #include 
 
-#include 
-
 #ifndef OPENSSL_NO_STDIO
 int X509_REQ_print_fp(FILE *fp, const X509_REQ *x)
 {
@@ -114,10 +112,10 @@ int X509_REQ_print_ex(BIO *bp, const X509_REQ *x, unsigned long nmflags, unsigne
                 goto err;
         } else {
             for (i = 0; i < X509_REQ_get_attr_count(x); i++) {
-                const ASN1_TYPE *at;
+                ASN1_TYPE *at;
                 X509_ATTRIBUTE *a;
                 ASN1_BIT_STRING *bs = NULL;
-                const ASN1_OBJECT *aobj;
+                ASN1_OBJECT *aobj;
                 int j, type = 0, count = 1, ii = 0;
 
                 a = X509_REQ_get_attr(x, i);
@@ -171,8 +169,8 @@ int X509_REQ_print_ex(BIO *bp, const X509_REQ *x, unsigned long nmflags, unsigne
             if (BIO_printf(bp, "%12sRequested Extensions:\n", "") <= 0)
                 goto err;
             for (i = 0; i < sk_X509_EXTENSION_num(exts); i++) {
-                const ASN1_OBJECT *obj;
-                const X509_EXTENSION *ex;
+                ASN1_OBJECT *obj;
+                X509_EXTENSION *ex;
                 int critical;
                 ex = sk_X509_EXTENSION_value(exts, i);
                 if (BIO_printf(bp, "%16s", "") <= 0)
diff --git a/crypto/x509/t_x509.c b/crypto/x509/t_x509.c
index abe1b7557d..c4927d357b 100644
--- a/crypto/x509/t_x509.c
+++ b/crypto/x509/t_x509.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,6 +7,11 @@
  * https://www.openssl.org/source/license.html
  */
 
+/*
+ * because of EVP_PKEY_asn1_find deprecation
+ */
+#define OPENSSL_SUPPRESS_DEPRECATED
+
 #include 
 #include "internal/cryptlib.h"
 #include 
@@ -16,7 +21,6 @@
 #include 
 #include "crypto/asn1.h"
 #include "crypto/x509.h"
-#include "crypto/evp.h"
 
 void OSSL_STACK_OF_X509_free(STACK_OF(X509) *certs)
 {
@@ -24,12 +28,12 @@ void OSSL_STACK_OF_X509_free(STACK_OF(X509) *certs)
 }
 
 #ifndef OPENSSL_NO_STDIO
-int X509_print_fp(FILE *fp, const X509 *x)
+int X509_print_fp(FILE *fp, X509 *x)
 {
     return X509_print_ex_fp(fp, x, XN_FLAG_COMPAT, X509_FLAG_COMPAT);
 }
 
-int X509_print_ex_fp(FILE *fp, const X509 *x, unsigned long nmflag, unsigned long cflag)
+int X509_print_ex_fp(FILE *fp, X509 *x, unsigned long nmflag, unsigned long cflag)
 {
     BIO *b;
     int ret;
@@ -134,7 +138,7 @@ int X509_print_ex(BIO *bp, const X509 *x, unsigned long nmflags, unsigned long c
             goto err;
     }
     if (!(cflag & X509_FLAG_NO_PUBKEY)) {
-        const X509_PUBKEY *xpkey = X509_get_X509_PUBKEY(x);
+        X509_PUBKEY *xpkey = X509_get_X509_PUBKEY(x);
         ASN1_OBJECT *xpoid;
         X509_PUBKEY_get0_param(&xpoid, NULL, NULL, NULL, xpkey);
         if (BIO_write(bp, "        Subject Public Key Info:\n", 33) <= 0)
@@ -200,7 +204,7 @@ int X509_ocspid_print(BIO *bp, const X509 *x)
     int derlen;
     int i;
     unsigned char SHA1md[SHA_DIGEST_LENGTH];
-    const ASN1_BIT_STRING *keybstr;
+    ASN1_BIT_STRING *keybstr;
     const X509_NAME *subj;
     EVP_MD *md = NULL;
 
@@ -244,7 +248,7 @@ int X509_ocspid_print(BIO *bp, const X509 *x)
         goto err;
 
     if (!EVP_Digest(ASN1_STRING_get0_data(keybstr),
-            ASN1_STRING_length_ex(keybstr), SHA1md, NULL, md, NULL))
+            ASN1_STRING_length(keybstr), SHA1md, NULL, md, NULL))
         goto err;
     for (i = 0; i < SHA_DIGEST_LENGTH; i++) {
         if (BIO_printf(bp, "%02X", SHA1md[i]) <= 0)
@@ -303,7 +307,7 @@ int X509_signature_print(BIO *bp, const X509_ALGOR *sigalg,
         int pkey_nid, dig_nid;
         const EVP_PKEY_ASN1_METHOD *ameth;
         if (OBJ_find_sigid_algs(sig_nid, &dig_nid, &pkey_nid)) {
-            ameth = evp_pkey_asn1_find(pkey_nid);
+            ameth = EVP_PKEY_asn1_find(NULL, pkey_nid);
             if (ameth && ameth->sig_print)
                 return ameth->sig_print(bp, sigalg, sig, indent + 4, 0);
         }
@@ -319,7 +323,7 @@ int X509_signature_print(BIO *bp, const X509_ALGOR *sigalg,
 int X509_aux_print(BIO *out, const X509 *x, int indent)
 {
     char oidstr[80], first;
-    const STACK_OF(ASN1_OBJECT) *trust, *reject;
+    STACK_OF(ASN1_OBJECT) *trust, *reject;
     const unsigned char *alias, *keyid;
     int keyidlen;
     int i;
@@ -374,45 +378,34 @@ int X509_aux_print(BIO *out, const X509 *x, int indent)
  * Helper functions for improving certificate verification error diagnostics
  */
 
-int ossl_x509_print_ex_brief(BIO *bio, const X509 *cert, unsigned long neg_cflags)
+int ossl_x509_print_ex_brief(BIO *bio, X509 *cert, unsigned long neg_cflags)
 {
     unsigned long flags = ASN1_STRFLGS_RFC2253 | ASN1_STRFLGS_ESC_QUOTE | XN_FLAG_SEP_CPLUS_SPC | XN_FLAG_FN_SN;
-    X509_VERIFY_PARAM *vpm = X509_VERIFY_PARAM_new();
-    int error, ret = 0;
 
-    if (vpm == NULL) {
-        ret = BIO_printf(bio, "    (malloc failed)\n") > 0;
-        goto err;
-    }
-    if (cert == NULL) {
-        ret = BIO_printf(bio, "    (no certificate)\n") > 0;
-        goto err;
-    }
+    if (cert == NULL)
+        return BIO_printf(bio, "    (no certificate)\n") > 0;
     if (BIO_printf(bio, "    certificate\n") <= 0
         || !X509_print_ex(bio, cert, flags, ~X509_FLAG_NO_SUBJECT))
-        goto err;
-    if (X509_check_issued(cert, cert) == X509_V_OK) {
+        return 0;
+    if (X509_check_issued((X509 *)cert, cert) == X509_V_OK) {
         if (BIO_printf(bio, "        self-issued\n") <= 0)
-            goto err;
+            return 0;
     } else {
         if (BIO_printf(bio, " ") <= 0
             || !X509_print_ex(bio, cert, flags, ~X509_FLAG_NO_ISSUER))
-            goto err;
+            return 0;
     }
     if (!X509_print_ex(bio, cert, flags,
             ~(X509_FLAG_NO_SERIAL | X509_FLAG_NO_VALIDITY)))
-        goto err;
-
-    if (!X509_check_certificate_times(vpm, cert, &error)) {
-        if (BIO_printf(bio, "        %s\n", X509_verify_cert_error_string(error)) <= 0)
-            goto err;
-    }
-    ret = X509_print_ex(bio, cert, flags,
+        return 0;
+    if (X509_cmp_current_time(X509_get0_notBefore(cert)) > 0)
+        if (BIO_printf(bio, "        not yet valid\n") <= 0)
+            return 0;
+    if (X509_cmp_current_time(X509_get0_notAfter(cert)) < 0)
+        if (BIO_printf(bio, "        no more valid\n") <= 0)
+            return 0;
+    return X509_print_ex(bio, cert, flags,
         ~neg_cflags & ~X509_FLAG_EXTENSIONS_ONLY_KID);
-
-err:
-    X509_VERIFY_PARAM_free(vpm);
-    return ret;
 }
 
 static int print_certs(BIO *bio, const STACK_OF(X509) *certs)
diff --git a/crypto/x509/v3_aaa.c b/crypto/x509/v3_aaa.c
index ab61780a6a..64d0791eb4 100644
--- a/crypto/x509/v3_aaa.c
+++ b/crypto/x509/v3_aaa.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -39,10 +39,10 @@ static int i2r_ALLOWED_ATTRIBUTES_CHOICE(X509V3_EXT_METHOD *method,
     OSSL_ALLOWED_ATTRIBUTES_CHOICE *a,
     BIO *out, int indent)
 {
-    const ASN1_OBJECT *attr_obj;
+    ASN1_OBJECT *attr_obj;
     int attr_nid, j;
     X509_ATTRIBUTE *attr;
-    const ASN1_TYPE *av;
+    ASN1_TYPE *av;
 
     switch (a->type) {
     case (OSSL_AAA_ATTRIBUTE_TYPE):
diff --git a/crypto/x509/v3_ac_tgt.c b/crypto/x509/v3_ac_tgt.c
index 5471ba3907..654263e216 100644
--- a/crypto/x509/v3_ac_tgt.c
+++ b/crypto/x509/v3_ac_tgt.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,6 +7,11 @@
  * https://www.openssl.org/source/license.html
  */
 
+/*
+ * Needed for EVP_PKEY_asn1_find
+ */
+#define OPENSSL_SUPPRESS_DEPRECATED
+
 #include 
 #include 
 #include 
@@ -18,9 +23,6 @@
 #include "ext_dat.h"
 #include "x509_local.h"
 #include "crypto/asn1.h"
-#include "crypto/evp.h"
-
-#include 
 
 static int i2r_ISSUER_SERIAL(X509V3_EXT_METHOD *method,
     OSSL_ISSUER_SERIAL *iss,
@@ -44,7 +46,7 @@ ASN1_SEQUENCE(OSSL_ISSUER_SERIAL) = {
     ASN1_OPT(OSSL_ISSUER_SERIAL, issuerUID, ASN1_BIT_STRING),
 } static_ASN1_SEQUENCE_END(OSSL_ISSUER_SERIAL)
 
-ASN1_SEQUENCE(OSSL_OBJECT_DIGEST_INFO)
+    ASN1_SEQUENCE(OSSL_OBJECT_DIGEST_INFO)
     = {
           ASN1_EMBED(OSSL_OBJECT_DIGEST_INFO, digestedObjectType, ASN1_ENUMERATED),
           ASN1_OPT(OSSL_OBJECT_DIGEST_INFO, otherObjectTypeID, ASN1_OBJECT),
@@ -52,14 +54,14 @@ ASN1_SEQUENCE(OSSL_OBJECT_DIGEST_INFO)
           ASN1_EMBED(OSSL_OBJECT_DIGEST_INFO, objectDigest, ASN1_BIT_STRING),
       } static_ASN1_SEQUENCE_END(OSSL_OBJECT_DIGEST_INFO)
 
-ASN1_SEQUENCE(OSSL_TARGET_CERT)
+        ASN1_SEQUENCE(OSSL_TARGET_CERT)
     = {
           ASN1_SIMPLE(OSSL_TARGET_CERT, targetCertificate, OSSL_ISSUER_SERIAL),
           ASN1_OPT(OSSL_TARGET_CERT, targetName, GENERAL_NAME),
           ASN1_OPT(OSSL_TARGET_CERT, certDigestInfo, OSSL_OBJECT_DIGEST_INFO),
       } static_ASN1_SEQUENCE_END(OSSL_TARGET_CERT)
 
-ASN1_CHOICE(OSSL_TARGET)
+        ASN1_CHOICE(OSSL_TARGET)
     = {
           ASN1_EXP(OSSL_TARGET, choice.targetName, GENERAL_NAME, 0),
           ASN1_EXP(OSSL_TARGET, choice.targetGroup, GENERAL_NAME, 1),
@@ -151,7 +153,7 @@ static int i2r_OBJECT_DIGEST_INFO(X509V3_EXT_METHOD *method,
         int pkey_nid, dig_nid;
         const EVP_PKEY_ASN1_METHOD *ameth;
         if (OBJ_find_sigid_algs(sig_nid, &dig_nid, &pkey_nid)) {
-            ameth = evp_pkey_asn1_find(pkey_nid);
+            ameth = EVP_PKEY_asn1_find(NULL, pkey_nid);
             if (ameth && ameth->sig_print)
                 return ameth->sig_print(out, digalg, sig, indent + 4, 0);
         }
diff --git a/crypto/x509/v3_addr.c b/crypto/x509/v3_addr.c
index e245e2b08a..f5436d1d3b 100644
--- a/crypto/x509/v3_addr.c
+++ b/crypto/x509/v3_addr.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -409,11 +409,6 @@ static int make_addressPrefix(IPAddressOrRange **result, unsigned char *addr,
 {
     int bytelen = (prefixlen + 7) / 8, bitlen = prefixlen % 8;
     IPAddressOrRange *aor;
-    unsigned char *prefix = NULL;
-    uint8_t unused_bits = 0;
-
-    if (bitlen > 0)
-        unused_bits = 8 - bitlen;
 
     if (prefixlen < 0 || prefixlen > (afilen * 8))
         return 0;
@@ -422,23 +417,16 @@ static int make_addressPrefix(IPAddressOrRange **result, unsigned char *addr,
     aor->type = IPAddressOrRange_addressPrefix;
     if (aor->u.addressPrefix == NULL && (aor->u.addressPrefix = ASN1_BIT_STRING_new()) == NULL)
         goto err;
-    if (bytelen > 0) {
-        prefix = OPENSSL_malloc(bytelen);
-        if (prefix == NULL)
-            goto err;
-        memcpy(prefix, addr, bytelen);
-        if (unused_bits)
-            prefix[bytelen - 1] &= ~(0xFF >> bitlen);
-    }
-    if (!ASN1_BIT_STRING_set1(aor->u.addressPrefix, prefix, bytelen, unused_bits))
+    if (!ASN1_BIT_STRING_set(aor->u.addressPrefix, addr, bytelen))
         goto err;
-    *result = aor;
+    if (bitlen > 0)
+        aor->u.addressPrefix->data[bytelen - 1] &= ~(0xFF >> bitlen);
+    ossl_asn1_string_set_bits_left(aor->u.addressPrefix, 8 - bitlen);
 
-    OPENSSL_free(prefix);
+    *result = aor;
     return 1;
 
 err:
-    OPENSSL_free(prefix);
     IPAddressOrRange_free(aor);
     return 0;
 }
@@ -473,8 +461,9 @@ static int make_addressRange(IPAddressOrRange **result,
 
     for (i = length; i > 0 && min[i - 1] == 0x00; --i)
         ;
-    if (!ASN1_BIT_STRING_set1(aor->u.addressRange->min, min, i, 0))
+    if (!ASN1_BIT_STRING_set(aor->u.addressRange->min, min, i))
         goto err;
+    ossl_asn1_string_set_bits_left(aor->u.addressRange->min, 0);
     if (i > 0) {
         unsigned char b = min[i - 1];
         int j = 1;
@@ -486,8 +475,9 @@ static int make_addressRange(IPAddressOrRange **result,
 
     for (i = length; i > 0 && max[i - 1] == 0xFF; --i)
         ;
-    if (!ASN1_BIT_STRING_set1(aor->u.addressRange->max, max, i, 0))
+    if (!ASN1_BIT_STRING_set(aor->u.addressRange->max, max, i))
         goto err;
+    ossl_asn1_string_set_bits_left(aor->u.addressRange->max, 0);
     if (i > 0) {
         unsigned char b = max[i - 1];
         int j = 1;
@@ -554,7 +544,7 @@ err:
  * Add an inheritance element.
  */
 int X509v3_addr_add_inherit(IPAddrBlocks *addr,
-    unsigned afi, const unsigned *safi)
+    const unsigned afi, const unsigned *safi)
 {
     IPAddressFamily *f = make_IPAddressFamily(addr, afi, safi);
 
@@ -605,7 +595,7 @@ static IPAddressOrRanges *make_prefix_or_range(IPAddrBlocks *addr,
 int X509v3_addr_add_prefix(IPAddrBlocks *addr,
     const unsigned afi,
     const unsigned *safi,
-    unsigned char *a, int prefixlen)
+    unsigned char *a, const int prefixlen)
 {
     IPAddressOrRanges *aors = make_prefix_or_range(addr, afi, safi);
     IPAddressOrRange *aor;
@@ -623,7 +613,7 @@ int X509v3_addr_add_prefix(IPAddrBlocks *addr,
  * Add a range.
  */
 int X509v3_addr_add_range(IPAddrBlocks *addr,
-    unsigned afi,
+    const unsigned afi,
     const unsigned *safi,
     unsigned char *min, unsigned char *max)
 {
@@ -662,9 +652,9 @@ static int extract_min_max(IPAddressOrRange *aor,
  * Public wrapper for extract_min_max().
  */
 int X509v3_addr_get_range(IPAddressOrRange *aor,
-    unsigned afi,
+    const unsigned afi,
     unsigned char *min,
-    unsigned char *max, int length)
+    unsigned char *max, const int length)
 {
     int afi_length = length_from_afi(afi);
 
@@ -689,15 +679,10 @@ static int IPAddressFamily_cmp(const IPAddressFamily *const *a_,
 {
     const ASN1_OCTET_STRING *a = (*a_)->addressFamily;
     const ASN1_OCTET_STRING *b = (*b_)->addressFamily;
-    int cmp, len = (a->length <= b->length) ? a->length : b->length;
+    int len = ((a->length <= b->length) ? a->length : b->length);
+    int cmp = memcmp(a->data, b->data, len);
 
-    if (len > 0) {
-        cmp = memcmp(a->data, b->data, len);
-        if (cmp != 0)
-            return cmp;
-    }
-
-    return a->length - b->length;
+    return cmp ? cmp : a->length - b->length;
 }
 
 static int IPAddressFamily_check_len(const IPAddressFamily *f)
@@ -769,7 +754,6 @@ int X509v3_addr_is_canonical(IPAddrBlocks *addr)
         aors = f->ipAddressChoice->u.addressesOrRanges;
         if (sk_IPAddressOrRange_num(aors) == 0)
             return 0;
-
         for (j = 0; j < sk_IPAddressOrRange_num(aors) - 1; j++) {
             IPAddressOrRange *a = sk_IPAddressOrRange_value(aors, j);
             IPAddressOrRange *b = sk_IPAddressOrRange_value(aors, j + 1);
@@ -824,106 +808,78 @@ int X509v3_addr_is_canonical(IPAddrBlocks *addr)
 
 /*
  * Whack an IPAddressOrRanges into canonical form.
- *
- * After the initial sort, the merge runs as a single linear sweep
- * over the list using a write index.  Adjacent entries are folded
- * into the previous output by replacing it with a freshly built
- * merged range; both old entries are then freed and the source slot
- * is left NULL so the asn1 free machinery does not double-free on a
- * subsequent abort.  Total cost is O(N log N) sort + O(N) merge,
- * with no stack deletes inside the loop.
  */
 static int IPAddressOrRanges_canonize(IPAddressOrRanges *aors,
     const unsigned afi)
 {
-    int length = length_from_afi(afi);
-    int read, write = 0, n;
-
-    sk_IPAddressOrRange_sort(aors);
-    n = sk_IPAddressOrRange_num(aors);
+    int i, j, length = length_from_afi(afi);
 
     /*
-     * Error paths below all `return 0` directly.  Slots at
-     * [write..read-1] are NULL (from earlier iterations) and slots at
-     * [read..n-1] still hold their original entries; the caller's
-     * normal teardown walks the whole stack and frees each non-NULL
-     * slot safely, so leaving the stack in this mixed state is sound.
+     * Sort the IPAddressOrRanges sequence.
      */
-    for (read = 0; read < n; read++) {
-        IPAddressOrRange *cur = sk_IPAddressOrRange_value(aors, read);
-        unsigned char c_min[ADDR_RAW_BUF_LEN], c_max[ADDR_RAW_BUF_LEN];
+    sk_IPAddressOrRange_sort(aors);
 
-        if (!extract_min_max(cur, c_min, c_max, length))
+    /*
+     * Clean up representation issues, punt on duplicates or overlaps.
+     */
+    for (i = 0; i < sk_IPAddressOrRange_num(aors) - 1; i++) {
+        IPAddressOrRange *a = sk_IPAddressOrRange_value(aors, i);
+        IPAddressOrRange *b = sk_IPAddressOrRange_value(aors, i + 1);
+        unsigned char a_min[ADDR_RAW_BUF_LEN], a_max[ADDR_RAW_BUF_LEN];
+        unsigned char b_min[ADDR_RAW_BUF_LEN], b_max[ADDR_RAW_BUF_LEN];
+
+        if (!extract_min_max(a, a_min, a_max, length) || !extract_min_max(b, b_min, b_max, length))
             return 0;
 
         /*
-         * Punt inverted range.
+         * Punt inverted ranges.
          */
-        if (memcmp(c_min, c_max, length) > 0)
+        if (memcmp(a_min, a_max, length) > 0 || memcmp(b_min, b_max, length) > 0)
             return 0;
 
-        if (write > 0) {
-            IPAddressOrRange *prev = sk_IPAddressOrRange_value(aors,
-                write - 1);
-            unsigned char p_min[ADDR_RAW_BUF_LEN], p_max[ADDR_RAW_BUF_LEN];
-            unsigned char c_min_minus_one[ADDR_RAW_BUF_LEN];
-            int j;
-
-            if (!extract_min_max(prev, p_min, p_max, length))
-                return 0;
-
-            /*
-             * Reject overlap with the previous accepted entry.
-             */
-            if (memcmp(p_max, c_min, length) >= 0)
-                return 0;
-
-            /*
-             * Adjacency test: does c_min - 1 equal p_max?  Work on a
-             * scratch copy so the original c_min stays intact for use
-             * as the lower bound if we end up keeping cur.
-             */
-            memcpy(c_min_minus_one, c_min, length);
-            for (j = length - 1;
-                j >= 0 && c_min_minus_one[j]-- == 0x00;
-                j--)
-                ;
-            if (memcmp(p_max, c_min_minus_one, length) == 0) {
-                IPAddressOrRange *merged;
-
-                if (!make_addressRange(&merged, p_min, c_max, length))
-                    return 0;
-                /*
-                 * Replace prev with merged, free the originals, and
-                 * NULL the source slot so the stack does not retain a
-                 * second reference to cur.
-                 */
-                (void)sk_IPAddressOrRange_set(aors, write - 1, merged);
-                IPAddressOrRange_free(prev);
-                IPAddressOrRange_free(cur);
-                (void)sk_IPAddressOrRange_set(aors, read, NULL);
-                continue;
-            }
-        }
+        /*
+         * Punt overlaps.
+         */
+        if (memcmp(a_max, b_min, length) >= 0)
+            return 0;
 
         /*
-         * Keep cur.  Slide it forward into the write slot if we have
-         * fallen behind, and NULL the source slot to avoid duplicate
-         * ownership.
+         * Merge if a and b are adjacent.  We check for
+         * adjacency by subtracting one from b_min first.
          */
-        if (write != read) {
-            (void)sk_IPAddressOrRange_set(aors, write, cur);
-            (void)sk_IPAddressOrRange_set(aors, read, NULL);
+        for (j = length - 1; j >= 0 && b_min[j]-- == 0x00; j--)
+            ;
+        if (memcmp(a_max, b_min, length) == 0) {
+            IPAddressOrRange *merged;
+
+            if (!make_addressRange(&merged, a_min, b_max, length))
+                return 0;
+            (void)sk_IPAddressOrRange_set(aors, i, merged);
+            (void)sk_IPAddressOrRange_delete(aors, i + 1);
+            IPAddressOrRange_free(a);
+            IPAddressOrRange_free(b);
+            --i;
+            continue;
         }
-        write++;
     }
 
     /*
-     * Compaction succeeded: every slot at [write..n-1] is NULL, so
-     * popping the tail leaves the canonicalised list at [0..write-1].
+     * Check for inverted final range.
      */
-    while (sk_IPAddressOrRange_num(aors) > write)
-        (void)sk_IPAddressOrRange_pop(aors);
+    j = sk_IPAddressOrRange_num(aors) - 1;
+    {
+        IPAddressOrRange *a = sk_IPAddressOrRange_value(aors, j);
+
+        if (a != NULL && a->type == IPAddressOrRange_addressRange) {
+            unsigned char a_min[ADDR_RAW_BUF_LEN], a_max[ADDR_RAW_BUF_LEN];
+
+            if (!extract_min_max(a, a_min, a_max, length))
+                return 0;
+            if (memcmp(a_min, a_max, length) > 0)
+                return 0;
+        }
+    }
+
     return 1;
 }
 
@@ -1254,7 +1210,7 @@ int X509v3_addr_subset(IPAddrBlocks *a, IPAddrBlocks *b)
  * X509_V_OK.
  */
 static int addr_validate_path_internal(X509_STORE_CTX *ctx,
-    const STACK_OF(X509) *chain,
+    STACK_OF(X509) *chain,
     IPAddrBlocks *ext)
 {
     IPAddrBlocks *child = NULL;
@@ -1388,7 +1344,7 @@ int X509v3_addr_validate_path(X509_STORE_CTX *ctx)
  * RFC 3779 2.3 path validation of an extension.
  * Test whether chain covers extension.
  */
-int X509v3_addr_validate_resource_set(const STACK_OF(X509) *chain,
+int X509v3_addr_validate_resource_set(STACK_OF(X509) *chain,
     IPAddrBlocks *ext, int allow_inheritance)
 {
     if (ext == NULL)
diff --git a/crypto/x509/v3_admis.h b/crypto/x509/v3_admis.h
index fa4a409f24..75a07c1fcd 100644
--- a/crypto/x509/v3_admis.h
+++ b/crypto/x509/v3_admis.h
@@ -10,10 +10,6 @@
 #ifndef OSSL_CRYPTO_X509_V3_ADMIS_H
 #define OSSL_CRYPTO_X509_V3_ADMIS_H
 
-#include 
-#include 
-#include 
-
 struct NamingAuthority_st {
     ASN1_OBJECT *namingAuthorityId;
     ASN1_IA5STRING *namingAuthorityUrl;
diff --git a/crypto/x509/v3_akid.c b/crypto/x509/v3_akid.c
index 95b904c757..08c751b77c 100644
--- a/crypto/x509/v3_akid.c
+++ b/crypto/x509/v3_akid.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2022 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -66,8 +66,7 @@ static STACK_OF(CONF_VALUE) *i2v_AUTHORITY_KEYID(X509V3_EXT_METHOD *method,
         extlist = tmpextlist;
     }
     if (akeyid->serial) {
-        tmp = i2s_ASN1_INTEGER(NULL, akeyid->serial);
-
+        tmp = i2s_ASN1_OCTET_STRING(NULL, akeyid->serial);
         if (tmp == NULL) {
             ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
             goto err;
@@ -85,13 +84,6 @@ err:
     return NULL;
 }
 
-enum qualifier {
-    NEVER,
-    NONSS,
-    MAYBE,
-    GOTTO,
-};
-
 /*-
  * Three explicit tags may be given, where 'keyid' and 'issuer' may be combined:
  * 'none': do not add any authority key identifier.
@@ -105,6 +97,7 @@ static AUTHORITY_KEYID *v2i_AUTHORITY_KEYID(X509V3_EXT_METHOD *method,
     X509V3_CTX *ctx,
     STACK_OF(CONF_VALUE) *values)
 {
+    char keyid = 0, issuer = 0;
     int i, n = sk_CONF_VALUE_num(values);
     CONF_VALUE *cnf;
     ASN1_OCTET_STRING *ikeyid = NULL;
@@ -112,37 +105,33 @@ static AUTHORITY_KEYID *v2i_AUTHORITY_KEYID(X509V3_EXT_METHOD *method,
     GENERAL_NAMES *gens = NULL;
     GENERAL_NAME *gen = NULL;
     ASN1_INTEGER *serial = NULL;
-    const X509_EXTENSION *ext;
+    X509_EXTENSION *ext;
     X509 *issuer_cert;
     int same_issuer, ss;
     AUTHORITY_KEYID *akeyid = AUTHORITY_KEYID_new();
-    enum qualifier keyid = NEVER, issuer = NEVER;
 
     if (akeyid == NULL)
         goto err;
 
-    if (n == 1 && strcmp(sk_CONF_VALUE_value(values, 0)->name, "none") == 0)
+    if (n == 1 && strcmp(sk_CONF_VALUE_value(values, 0)->name, "none") == 0) {
         return akeyid;
+    }
 
     for (i = 0; i < n; i++) {
-        enum qualifier q = MAYBE;
-
         cnf = sk_CONF_VALUE_value(values, i);
-        if (cnf->value != NULL && *cnf->value != '\0') {
-            if (strcmp(cnf->value, "always") == 0) {
-                q = GOTTO;
-            } else if (strcmp(cnf->value, "nonss") == 0) {
-                q = NONSS;
-            } else {
-                ERR_raise_data(ERR_LIB_X509V3, X509V3_R_UNKNOWN_OPTION,
-                    "name=%s option=%s", cnf->name, cnf->value);
-                goto err;
-            }
+        if (cnf->value != NULL && strcmp(cnf->value, "always") != 0) {
+            ERR_raise_data(ERR_LIB_X509V3, X509V3_R_UNKNOWN_OPTION,
+                "name=%s option=%s", cnf->name, cnf->value);
+            goto err;
         }
-        if (strcmp(cnf->name, "keyid") == 0 && keyid == NEVER) {
-            keyid = q;
+        if (strcmp(cnf->name, "keyid") == 0 && keyid == 0) {
+            keyid = 1;
+            if (cnf->value != NULL)
+                keyid = 2;
         } else if (strcmp(cnf->name, "issuer") == 0 && issuer == 0) {
-            issuer = q;
+            issuer = 1;
+            if (cnf->value != NULL)
+                issuer = 2;
         } else if (strcmp(cnf->name, "none") == 0
             || strcmp(cnf->name, "keyid") == 0
             || strcmp(cnf->name, "issuer") == 0) {
@@ -175,66 +164,43 @@ static AUTHORITY_KEYID *v2i_AUTHORITY_KEYID(X509V3_EXT_METHOD *method,
         ss = same_issuer;
     ERR_pop_to_mark();
 
-    if (keyid > NONSS || (keyid == NONSS && !ss)) {
+    /* unless forced with "always", AKID is suppressed for self-signed certs */
+    if (keyid == 2 || (keyid == 1 && !ss)) {
         /*
-         * The subject key identifier of the issuer cert is acceptable unless
-         * the issuer cert is same as subject cert, but the subject will not
-         * be self-signed (i.e. will be signed with a different key).
+         * prefer any pre-existing subject key identifier of the issuer cert
+         * except issuer cert is same as subject cert and is not self-signed
          */
         i = X509_get_ext_by_NID(issuer_cert, NID_subject_key_identifier, -1);
         if (i >= 0 && (ext = X509_get_ext(issuer_cert, i)) != NULL
             && !(same_issuer && !ss)) {
             ikeyid = X509V3_EXT_d2i(ext);
-            /* Ignore empty keyids in the issuer cert */
-            if (ASN1_STRING_length_ex(ikeyid) == 0) {
+            if (ASN1_STRING_length(ikeyid) == 0) /* indicating "none" */ {
                 ASN1_OCTET_STRING_free(ikeyid);
                 ikeyid = NULL;
             }
         }
-        /*
-         * If we have that other key in hand, synthesise a fallback AKID,
-         * emulating s2i_skey_id(..., "hash").
-         *
-         * When creating self-signed certificates, we do not synthesise
-         * best-effort keyids, instead the keyid needs be set first.  The
-         * X509V3_EXT_add_nconf_sk() function makes every effort to process the
-         * SKID before the AKID, but some callers may specify extensions
-         * piecemeal.  We don't want to mispredict it being set later and end
-         * up with a "dangling" AKID keyid.
-         */
-        if (ikeyid == NULL && same_issuer && !ss && ctx->issuer_pkey != NULL) {
+        if (ikeyid == NULL && same_issuer && ctx->issuer_pkey != NULL) {
+            /* generate fallback AKID, emulating s2i_skey_id(..., "hash") */
             X509_PUBKEY *pubkey = NULL;
 
             if (X509_PUBKEY_set(&pubkey, ctx->issuer_pkey))
                 ikeyid = ossl_x509_pubkey_hash(pubkey);
             X509_PUBKEY_free(pubkey);
         }
-        if (keyid == GOTTO && ikeyid == NULL) {
+        if (keyid == 2 && ikeyid == NULL) {
             ERR_raise(ERR_LIB_X509V3, X509V3_R_UNABLE_TO_GET_ISSUER_KEYID);
             goto err;
         }
     }
 
-    /*
-     * When the same object is specified as both the issuer and subject
-     * certificate, but with a different (forced) issuer public key (so not
-     * self-signed), we don't have access to the true issuer certificate's
-     * serial number, so can't create an isser+serial AKID.
-     */
-    if (!same_issuer || ss) {
-        if (issuer == GOTTO
-            || (ikeyid == NULL
-                && (issuer == MAYBE
-                    || (issuer == NONSS && !ss)))) {
-            isname = X509_NAME_dup(X509_get_issuer_name(issuer_cert));
-            serial = ASN1_INTEGER_dup(X509_get0_serialNumber(issuer_cert));
+    if (issuer == 2 || (issuer == 1 && !ss && ikeyid == NULL)) {
+        isname = X509_NAME_dup(X509_get_issuer_name(issuer_cert));
+        serial = ASN1_INTEGER_dup(X509_get0_serialNumber(issuer_cert));
+        if (isname == NULL || serial == NULL) {
+            ERR_raise(ERR_LIB_X509V3, X509V3_R_UNABLE_TO_GET_ISSUER_DETAILS);
+            goto err;
         }
     }
-    /* "always" fails unless both issuer and serial are available */
-    if (issuer == GOTTO && (isname == NULL || serial == NULL)) {
-        ERR_raise(ERR_LIB_X509V3, X509V3_R_UNABLE_TO_GET_ISSUER_DETAILS);
-        goto err;
-    }
 
     if (isname != NULL) {
         if ((gens = sk_GENERAL_NAME_new_null()) == NULL
diff --git a/crypto/x509/v3_asid.c b/crypto/x509/v3_asid.c
index c00ded15f9..b6dedde738 100644
--- a/crypto/x509/v3_asid.c
+++ b/crypto/x509/v3_asid.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -347,22 +347,13 @@ int X509v3_asid_is_canonical(ASIdentifiers *asid)
 
 /*
  * Whack an ASIdentifierChoice into canonical form.
- *
- * After the initial sort, the merge runs as a single linear sweep
- * over the list using a write index.  Each entry is examined once;
- * adjacent / mergeable entries extend the previous output's upper
- * bound in O(1) and the source slot is left NULL so the asn1 free
- * machinery does not double-free on a subsequent abort.  Total cost
- * is O(N log N) sort + O(N) merge, with no stack deletes inside the
- * loop.
  */
 static int ASIdentifierChoice_canonize(ASIdentifierChoice *choice)
 {
     ASN1_INTEGER *a_max_plus_one = NULL;
     ASN1_INTEGER *orig;
     BIGNUM *bn = NULL;
-    int read, write = 0, n;
-    int ret = 0;
+    int i, ret = 0;
 
     /*
      * Nothing to do for empty element or inheritance.
@@ -379,135 +370,112 @@ static int ASIdentifierChoice_canonize(ASIdentifierChoice *choice)
     }
 
     /*
-     * Sort the list, then merge in a single sweep using a write index.
+     * We have a non-empty list.  Sort it.
      */
     sk_ASIdOrRange_sort(choice->u.asIdsOrRanges);
-    n = sk_ASIdOrRange_num(choice->u.asIdsOrRanges);
 
-    for (read = 0; read < n; read++) {
-        ASIdOrRange *cur = sk_ASIdOrRange_value(choice->u.asIdsOrRanges, read);
-        ASN1_INTEGER *c_min = NULL, *c_max = NULL;
+    /*
+     * Now check for errors and suboptimal encoding, rejecting the
+     * former and fixing the latter.
+     */
+    for (i = 0; i < sk_ASIdOrRange_num(choice->u.asIdsOrRanges) - 1; i++) {
+        ASIdOrRange *a = sk_ASIdOrRange_value(choice->u.asIdsOrRanges, i);
+        ASIdOrRange *b = sk_ASIdOrRange_value(choice->u.asIdsOrRanges, i + 1);
+        ASN1_INTEGER *a_min = NULL, *a_max = NULL, *b_min = NULL, *b_max = NULL;
 
-        if (!extract_min_max(cur, &c_min, &c_max))
+        if (!extract_min_max(a, &a_min, &a_max)
+            || !extract_min_max(b, &b_min, &b_max))
             goto done;
 
         /*
-         * Punt inverted range.
+         * Make sure we're properly sorted (paranoia).
          */
-        if (ASN1_INTEGER_cmp(c_min, c_max) > 0)
+        if (!ossl_assert(ASN1_INTEGER_cmp(a_min, b_min) <= 0))
             goto done;
 
-        if (write > 0) {
-            ASIdOrRange *prev = sk_ASIdOrRange_value(choice->u.asIdsOrRanges,
-                write - 1);
-            ASN1_INTEGER *p_min = NULL, *p_max = NULL;
+        /*
+         * Punt inverted ranges.
+         */
+        if (ASN1_INTEGER_cmp(a_min, a_max) > 0 || ASN1_INTEGER_cmp(b_min, b_max) > 0)
+            goto done;
 
-            if (!extract_min_max(prev, &p_min, &p_max))
-                goto done;
-
-            /*
-             * Make sure we're properly sorted (paranoia).
-             */
-            if (!ossl_assert(ASN1_INTEGER_cmp(p_min, c_min) <= 0))
-                goto done;
-
-            /*
-             * Reject overlap with the previous accepted entry.
-             */
-            if (ASN1_INTEGER_cmp(p_max, c_min) >= 0) {
-                ERR_raise(ERR_LIB_X509V3, X509V3_R_EXTENSION_VALUE_ERROR);
-                goto done;
-            }
-
-            /*
-             * Calculate p_max + 1 to check for adjacency.
-             */
-            if ((bn == NULL && (bn = BN_new()) == NULL)
-                || ASN1_INTEGER_to_BN(p_max, bn) == NULL
-                || !BN_add_word(bn, 1)) {
-                ERR_raise(ERR_LIB_X509V3, ERR_R_BN_LIB);
-                goto done;
-            }
-            if ((a_max_plus_one = BN_to_ASN1_INTEGER(bn,
-                     orig = a_max_plus_one))
-                == NULL) {
-                a_max_plus_one = orig;
-                ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
-                goto done;
-            }
-
-            /*
-             * If prev and cur are adjacent, fold cur into prev.
-             */
-            if (ASN1_INTEGER_cmp(a_max_plus_one, c_min) == 0) {
-                ASRange *r;
-
-                switch (prev->type) {
-                case ASIdOrRange_id:
-                    if ((r = OPENSSL_malloc(sizeof(*r))) == NULL)
-                        goto done;
-                    r->min = p_min;
-                    r->max = c_max;
-                    prev->type = ASIdOrRange_range;
-                    prev->u.range = r;
-                    break;
-                case ASIdOrRange_range:
-                    ASN1_INTEGER_free(prev->u.range->max);
-                    prev->u.range->max = c_max;
-                    break;
-                }
-                /*
-                 * Detach c_max from cur so freeing cur does not free
-                 * the value we just transferred to prev.
-                 */
-                switch (cur->type) {
-                case ASIdOrRange_id:
-                    cur->u.id = NULL;
-                    break;
-                case ASIdOrRange_range:
-                    cur->u.range->max = NULL;
-                    break;
-                }
-                ASIdOrRange_free(cur);
-                /*
-                 * NULL the source slot so any later teardown does not
-                 * walk a freed pointer.  We do not advance `write`.
-                 */
-                (void)sk_ASIdOrRange_set(choice->u.asIdsOrRanges, read, NULL);
-                continue;
-            }
+        /*
+         * Check for overlaps.
+         */
+        if (ASN1_INTEGER_cmp(a_max, b_min) >= 0) {
+            ERR_raise(ERR_LIB_X509V3, X509V3_R_EXTENSION_VALUE_ERROR);
+            goto done;
         }
 
         /*
-         * Keep cur.  Slide it forward into the write slot if we have
-         * fallen behind, and NULL the source slot to avoid duplicate
-         * ownership.
+         * Calculate a_max + 1 to check for adjacency.
          */
-        if (write != read) {
-            (void)sk_ASIdOrRange_set(choice->u.asIdsOrRanges, write, cur);
-            (void)sk_ASIdOrRange_set(choice->u.asIdsOrRanges, read, NULL);
+        if ((bn == NULL && (bn = BN_new()) == NULL) || ASN1_INTEGER_to_BN(a_max, bn) == NULL || !BN_add_word(bn, 1)) {
+            ERR_raise(ERR_LIB_X509V3, ERR_R_BN_LIB);
+            goto done;
+        }
+
+        if ((a_max_plus_one = BN_to_ASN1_INTEGER(bn, orig = a_max_plus_one)) == NULL) {
+            a_max_plus_one = orig;
+            ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
+            goto done;
+        }
+
+        /*
+         * If a and b are adjacent, merge them.
+         */
+        if (ASN1_INTEGER_cmp(a_max_plus_one, b_min) == 0) {
+            ASRange *r;
+            switch (a->type) {
+            case ASIdOrRange_id:
+                if ((r = OPENSSL_malloc(sizeof(*r))) == NULL)
+                    goto done;
+                r->min = a_min;
+                r->max = b_max;
+                a->type = ASIdOrRange_range;
+                a->u.range = r;
+                break;
+            case ASIdOrRange_range:
+                ASN1_INTEGER_free(a->u.range->max);
+                a->u.range->max = b_max;
+                break;
+            }
+            switch (b->type) {
+            case ASIdOrRange_id:
+                b->u.id = NULL;
+                break;
+            case ASIdOrRange_range:
+                b->u.range->max = NULL;
+                break;
+            }
+            ASIdOrRange_free(b);
+            (void)sk_ASIdOrRange_delete(choice->u.asIdsOrRanges, i + 1);
+            i--;
+            continue;
         }
-        write++;
     }
 
+    /*
+     * Check for final inverted range.
+     */
+    i = sk_ASIdOrRange_num(choice->u.asIdsOrRanges) - 1;
+    {
+        ASIdOrRange *a = sk_ASIdOrRange_value(choice->u.asIdsOrRanges, i);
+        ASN1_INTEGER *a_min, *a_max;
+        if (a != NULL && a->type == ASIdOrRange_range) {
+            if (!extract_min_max(a, &a_min, &a_max)
+                || ASN1_INTEGER_cmp(a_min, a_max) > 0)
+                goto done;
+        }
+    }
+
+    /* Paranoia */
+    if (!ossl_assert(ASIdentifierChoice_is_canonical(choice)))
+        goto done;
+
     ret = 1;
 
 done:
-    /*
-     * On success every slot at [write..n-1] is NULL, so popping the
-     * tail leaves the canonicalised list at [0..write-1].  On error we
-     * leave the tail untouched; the slots are either NULL (from earlier
-     * iterations) or original entries the loop never reached, both of
-     * which the caller's ASIdentifierChoice_free path handles safely.
-     */
-    if (ret) {
-        while (sk_ASIdOrRange_num(choice->u.asIdsOrRanges) > write)
-            (void)sk_ASIdOrRange_pop(choice->u.asIdsOrRanges);
-        /* Paranoia */
-        if (!ossl_assert(ASIdentifierChoice_is_canonical(choice)))
-            ret = 0;
-    }
-
     ASN1_INTEGER_free(a_max_plus_one);
     BN_free(bn);
     return ret;
@@ -749,7 +717,7 @@ int X509v3_asid_subset(ASIdentifiers *a, ASIdentifiers *b)
  * Core code for RFC 3779 3.3 path validation.
  */
 static int asid_validate_path_internal(X509_STORE_CTX *ctx,
-    const STACK_OF(X509) *chain,
+    STACK_OF(X509) *chain,
     ASIdentifiers *ext)
 {
     ASIdOrRanges *child_as = NULL, *child_rdi = NULL;
@@ -888,7 +856,7 @@ int X509v3_asid_validate_path(X509_STORE_CTX *ctx)
  * RFC 3779 3.3 path validation of an extension.
  * Test whether chain covers extension.
  */
-int X509v3_asid_validate_resource_set(const STACK_OF(X509) *chain,
+int X509v3_asid_validate_resource_set(STACK_OF(X509) *chain,
     ASIdentifiers *ext, int allow_inheritance)
 {
     if (ext == NULL)
diff --git a/crypto/x509/v3_authattid.c b/crypto/x509/v3_authattid.c
index 018ae05449..829593ed6c 100644
--- a/crypto/x509/v3_authattid.c
+++ b/crypto/x509/v3_authattid.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -14,8 +14,6 @@
 #include "crypto/asn1.h"
 #include "ext_dat.h"
 
-#include 
-
 DECLARE_ASN1_ITEM(OSSL_ISSUER_SERIAL)
 
 ASN1_ITEM_TEMPLATE(OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX) = ASN1_EX_TEMPLATE_TYPE(ASN1_TFLG_SEQUENCE_OF, 0, OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX, OSSL_ISSUER_SERIAL)
diff --git a/crypto/x509/v3_battcons.c b/crypto/x509/v3_battcons.c
index 2905fb4398..3d03066402 100644
--- a/crypto/x509/v3_battcons.c
+++ b/crypto/x509/v3_battcons.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -14,8 +14,6 @@
 #include "x509_local.h"
 #include "ext_dat.h"
 
-#include 
-
 static STACK_OF(CONF_VALUE) *i2v_OSSL_BASIC_ATTR_CONSTRAINTS(
     X509V3_EXT_METHOD *method,
     OSSL_BASIC_ATTR_CONSTRAINTS *battcons,
diff --git a/crypto/x509/v3_bcons.c b/crypto/x509/v3_bcons.c
index 21e819542d..b909966f02 100644
--- a/crypto/x509/v3_bcons.c
+++ b/crypto/x509/v3_bcons.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -16,8 +16,6 @@
 #include "ext_dat.h"
 #include "x509_local.h"
 
-#include 
-
 static STACK_OF(CONF_VALUE) *i2v_BASIC_CONSTRAINTS(X509V3_EXT_METHOD *method,
     BASIC_CONSTRAINTS *bcons,
     STACK_OF(CONF_VALUE)
diff --git a/crypto/x509/v3_bitst.c b/crypto/x509/v3_bitst.c
index 1b0204bf75..89c3deddd3 100644
--- a/crypto/x509/v3_bitst.c
+++ b/crypto/x509/v3_bitst.c
@@ -52,7 +52,7 @@ STACK_OF(CONF_VALUE) *i2v_ASN1_BIT_STRING(X509V3_EXT_METHOD *method,
     for (bnam = method->usr_data; bnam->lname; bnam++) {
         /*
          * If the bitnumber did not change from the last iteration, this entry
-         * is an alias for the previous bit; treat the first result as
+         * is an an alias for the previous bit; treat the first result as
          * canonical and ignore the rest.
          */
         if (last_seen_bit == bnam->bitnum)
diff --git a/crypto/x509/v3_conf.c b/crypto/x509/v3_conf.c
index 6b6f845735..f9350d6381 100644
--- a/crypto/x509/v3_conf.c
+++ b/crypto/x509/v3_conf.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -294,7 +294,7 @@ static unsigned char *generic_asn1(const char *value, X509V3_CTX *ctx,
 static void delete_ext(STACK_OF(X509_EXTENSION) *sk, X509_EXTENSION *dext)
 {
     int idx;
-    const ASN1_OBJECT *obj;
+    ASN1_OBJECT *obj;
 
     obj = X509_EXTENSION_get_object(dext);
     while ((idx = X509v3_get_ext_by_OBJ(sk, obj, -1)) >= 0)
@@ -346,10 +346,6 @@ int X509V3_EXT_add_nconf_sk(CONF *conf, X509V3_CTX *ctx, const char *section,
         }
         X509_EXTENSION_free(ext);
     }
-    if (sk != NULL && sk_X509_EXTENSION_num(*sk) == 0) {
-        sk_X509_EXTENSION_free(*sk);
-        *sk = NULL;
-    }
     return 1;
 }
 
@@ -361,7 +357,6 @@ int X509V3_EXT_add_nconf(CONF *conf, X509V3_CTX *ctx, const char *section,
     X509 *cert)
 {
     STACK_OF(X509_EXTENSION) **sk = NULL;
-
     if (cert != NULL)
         sk = &cert->cert_info.extensions;
     return X509V3_EXT_add_nconf_sk(conf, ctx, section, sk);
@@ -380,40 +375,6 @@ int X509V3_EXT_CRL_add_nconf(CONF *conf, X509V3_CTX *ctx, const char *section,
     return X509V3_EXT_add_nconf_sk(conf, ctx, section, sk);
 }
 
-static int
-update_req_extensions(X509_REQ *req, int *pnid, STACK_OF(X509_EXTENSION) *exts)
-{
-    unsigned char *ext = NULL;
-    int ret = 0, loc = -1, extlen = 0;
-
-    if (pnid == NULL || *pnid == NID_undef)
-        if ((pnid = X509_REQ_get_extension_nids()) == NULL)
-            return 0;
-    loc = X509at_get_attr_by_NID(req->req_info.attributes, *pnid, -1);
-
-    if (exts != NULL) {
-        extlen = ASN1_item_i2d((const ASN1_VALUE *)exts,
-            &ext, ASN1_ITEM_rptr(X509_EXTENSIONS));
-        if (extlen <= 0)
-            return ret;
-    }
-
-    if (loc != -1) {
-        X509_ATTRIBUTE *att = X509_REQ_delete_attr(req, loc);
-
-        if (att == NULL)
-            goto end;
-        X509_ATTRIBUTE_free(att);
-    }
-    if (sk_X509_EXTENSION_num(exts) > 0)
-        ret = X509_REQ_add1_attr_by_NID(req, *pnid, V_ASN1_SEQUENCE, ext, extlen);
-    else
-        ret = 1;
-end:
-    OPENSSL_free(ext);
-    return ret;
-}
-
 /*
  * Add extensions to certificate request. Just check in case req is NULL.
  * Note that on error new elements may remain added to req if req != NULL.
@@ -422,26 +383,10 @@ int X509V3_EXT_REQ_add_nconf(CONF *conf, X509V3_CTX *ctx, const char *section,
     X509_REQ *req)
 {
     STACK_OF(X509_EXTENSION) *exts = NULL;
-    int ret, *pnid = NULL;
+    int ret = X509V3_EXT_add_nconf_sk(conf, ctx, section, &exts);
 
-    /*
-     * Load current extensions if any, so we can replace any duplicates, possibly
-     * with nothing in the case of empty AKID/SKID.
-     */
-    if (req != NULL) {
-        for (pnid = X509_REQ_get_extension_nids(); *pnid != NID_undef; pnid++) {
-            exts = ossl_x509_req_get1_extensions_by_nid(req, *pnid);
-            if (sk_X509_EXTENSION_num(exts) > 0)
-                break;
-            sk_X509_EXTENSION_free(exts);
-            exts = NULL;
-        }
-    }
-
-    ret = X509V3_EXT_add_nconf_sk(conf, ctx, section, &exts);
-    /* Replace original extension list (stack) with updated stack */
-    if (ret && req != NULL)
-        ret = update_req_extensions(req, pnid, exts);
+    if (ret && req != NULL && exts != NULL)
+        ret = X509_REQ_add_extensions(req, exts);
     sk_X509_EXTENSION_pop_free(exts, X509_EXTENSION_free);
     return ret;
 }
@@ -454,7 +399,9 @@ char *X509V3_get_string(X509V3_CTX *ctx, const char *name, const char *section)
         ERR_raise(ERR_LIB_X509V3, X509V3_R_OPERATION_NOT_DEFINED);
         return NULL;
     }
-    return ctx->db_meth->get_string(ctx->db, name, section);
+    if (ctx->db_meth->get_string)
+        return ctx->db_meth->get_string(ctx->db, name, section);
+    return NULL;
 }
 
 STACK_OF(CONF_VALUE) *X509V3_get_section(X509V3_CTX *ctx, const char *section)
@@ -463,7 +410,9 @@ STACK_OF(CONF_VALUE) *X509V3_get_section(X509V3_CTX *ctx, const char *section)
         ERR_raise(ERR_LIB_X509V3, X509V3_R_OPERATION_NOT_DEFINED);
         return NULL;
     }
-    return ctx->db_meth->get_section(ctx->db, section);
+    if (ctx->db_meth->get_section)
+        return ctx->db_meth->get_section(ctx->db, section);
+    return NULL;
 }
 
 void X509V3_string_free(X509V3_CTX *ctx, char *str)
@@ -501,20 +450,24 @@ static X509V3_CONF_METHOD nconf_method = {
 
 void X509V3_set_nconf(X509V3_CTX *ctx, CONF *conf)
 {
-    if (ctx == NULL)
+    if (ctx == NULL) {
+        ERR_raise(ERR_LIB_X509V3, ERR_R_PASSED_NULL_PARAMETER);
         return;
+    }
     ctx->db_meth = &nconf_method;
     ctx->db = conf;
 }
 
-void X509V3_set_ctx(X509V3_CTX *ctx, X509 *issuer, X509 *subject, X509_REQ *req,
+void X509V3_set_ctx(X509V3_CTX *ctx, X509 *issuer, X509 *subj, X509_REQ *req,
     X509_CRL *crl, int flags)
 {
-    if (ctx == NULL)
+    if (ctx == NULL) {
+        ERR_raise(ERR_LIB_X509V3, ERR_R_PASSED_NULL_PARAMETER);
         return;
+    }
     ctx->flags = flags;
     ctx->issuer_cert = issuer;
-    ctx->subject_cert = subject;
+    ctx->subject_cert = subj;
     ctx->subject_req = req;
     ctx->crl = crl;
     ctx->db_meth = NULL;
diff --git a/crypto/x509/v3_cpols.c b/crypto/x509/v3_cpols.c
index 2cc71f567b..9d95a91240 100644
--- a/crypto/x509/v3_cpols.c
+++ b/crypto/x509/v3_cpols.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -18,8 +18,6 @@
 #include "pcy_local.h"
 #include "ext_dat.h"
 
-#include 
-
 /* Certificate policies extension support: this one is a bit complex... */
 
 static int i2r_certpol(X509V3_EXT_METHOD *method, STACK_OF(POLICYINFO) *pol,
@@ -208,7 +206,8 @@ static POLICYINFO *policy_section(X509V3_CTX *ctx,
                 ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
                 goto err;
             }
-            if (!ASN1_STRING_set_string(qual->d.cpsuri, cnf->value)) {
+            if (!ASN1_STRING_set(qual->d.cpsuri, cnf->value,
+                    (int)strlen(cnf->value))) {
                 ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
                 goto err;
             }
@@ -257,7 +256,7 @@ err:
 
 static int displaytext_get_tag_len(const char *tagstr)
 {
-    const char *colon = strchr(tagstr, ':');
+    char *colon = strchr(tagstr, ':');
 
     return (colon == NULL) ? -1 : (int)(colon - tagstr);
 }
@@ -324,7 +323,7 @@ static POLICYQUALINFO *notice_section(X509V3_CTX *ctx,
             if (tag_len != 0)
                 value += tag_len + 1;
             len = (int)strlen(value);
-            if (!ASN1_STRING_set_data(not->exptext, (uint8_t *)value, len)) {
+            if (!ASN1_STRING_set(not->exptext, value, len)) {
                 ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
                 goto err;
             }
@@ -343,7 +342,8 @@ static POLICYQUALINFO *notice_section(X509V3_CTX *ctx,
                 nref->organization->type = V_ASN1_IA5STRING;
             else
                 nref->organization->type = V_ASN1_VISIBLESTRING;
-            if (!ASN1_STRING_set_string(nref->organization, cnf->value)) {
+            if (!ASN1_STRING_set(nref->organization, cnf->value,
+                    (int)strlen(cnf->value))) {
                 ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
                 goto err;
             }
diff --git a/crypto/x509/v3_genn.c b/crypto/x509/v3_genn.c
index 23a2435842..d63168a77a 100644
--- a/crypto/x509/v3_genn.c
+++ b/crypto/x509/v3_genn.c
@@ -49,7 +49,13 @@ ASN1_ITEM_TEMPLATE(GENERAL_NAMES) = ASN1_EX_TEMPLATE_TYPE(ASN1_TFLG_SEQUENCE_OF,
 ASN1_ITEM_TEMPLATE_END(GENERAL_NAMES)
 
 IMPLEMENT_ASN1_FUNCTIONS(GENERAL_NAMES)
-IMPLEMENT_ASN1_DUP_FUNCTION(GENERAL_NAME)
+
+GENERAL_NAME *GENERAL_NAME_dup(const GENERAL_NAME *a)
+{
+    return (GENERAL_NAME *)ASN1_dup((i2d_of_void *)i2d_GENERAL_NAME,
+        (d2i_of_void *)d2i_GENERAL_NAME,
+        (char *)a);
+}
 
 int GENERAL_NAME_set1_X509_NAME(GENERAL_NAME **tgt, const X509_NAME *src)
 {
diff --git a/crypto/x509/v3_ia5.c b/crypto/x509/v3_ia5.c
index a8fa52a439..6dbf627a1d 100644
--- a/crypto/x509/v3_ia5.c
+++ b/crypto/x509/v3_ia5.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -14,8 +14,6 @@
 #include 
 #include "ext_dat.h"
 
-#include 
-
 const X509V3_EXT_METHOD ossl_v3_ns_ia5_list[8] = {
     EXT_IA5STRING(NID_netscape_base_url),
     EXT_IA5STRING(NID_netscape_revocation_url),
@@ -52,7 +50,7 @@ ASN1_IA5STRING *s2i_ASN1_IA5STRING(X509V3_EXT_METHOD *method,
         ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
         return NULL;
     }
-    if (!ASN1_STRING_set_string((ASN1_STRING *)ia5, str)) {
+    if (!ASN1_STRING_set((ASN1_STRING *)ia5, str, (int)strlen(str))) {
         ASN1_IA5STRING_free(ia5);
         return NULL;
     }
diff --git a/crypto/x509/v3_ist.c b/crypto/x509/v3_ist.c
index a4d3437192..fb7aaacbb3 100644
--- a/crypto/x509/v3_ist.c
+++ b/crypto/x509/v3_ist.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,8 +15,6 @@
 #include 
 #include "ext_dat.h"
 
-#include 
-
 /*
  * Issuer Sign Tool (1.2.643.100.112) The name of the tool used to signs the subject (ASN1_SEQUENCE)
  * This extension is required to obtain the status of a qualified certificate at Russian Federation.
@@ -50,30 +48,34 @@ static ISSUER_SIGN_TOOL *v2i_issuer_sign_tool(X509V3_EXT_METHOD *method, X509V3_
             continue;
         }
         if (strcmp(cnf->name, "signTool") == 0) {
+            ist->signTool = ASN1_UTF8STRING_new();
             if (ist->signTool == NULL
                 || cnf->value == NULL
-                || !ASN1_STRING_set_string(ist->signTool, cnf->value)) {
+                || !ASN1_STRING_set(ist->signTool, cnf->value, (int)strlen(cnf->value))) {
                 ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
                 goto err;
             }
         } else if (strcmp(cnf->name, "cATool") == 0) {
+            ist->cATool = ASN1_UTF8STRING_new();
             if (ist->cATool == NULL
                 || cnf->value == NULL
-                || !ASN1_STRING_set_string(ist->cATool, cnf->value)) {
+                || !ASN1_STRING_set(ist->cATool, cnf->value, (int)strlen(cnf->value))) {
                 ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
                 goto err;
             }
         } else if (strcmp(cnf->name, "signToolCert") == 0) {
+            ist->signToolCert = ASN1_UTF8STRING_new();
             if (ist->signToolCert == NULL
                 || cnf->value == NULL
-                || !ASN1_STRING_set_string(ist->signToolCert, cnf->value)) {
+                || !ASN1_STRING_set(ist->signToolCert, cnf->value, (int)strlen(cnf->value))) {
                 ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
                 goto err;
             }
         } else if (strcmp(cnf->name, "cAToolCert") == 0) {
+            ist->cAToolCert = ASN1_UTF8STRING_new();
             if (ist->cAToolCert == NULL
                 || cnf->value == NULL
-                || !ASN1_STRING_set_string(ist->cAToolCert, cnf->value)) {
+                || !ASN1_STRING_set(ist->cAToolCert, cnf->value, (int)strlen(cnf->value))) {
                 ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
                 goto err;
             }
diff --git a/crypto/x509/v3_lib.c b/crypto/x509/v3_lib.c
index a099177dba..fe6c235c5d 100644
--- a/crypto/x509/v3_lib.c
+++ b/crypto/x509/v3_lib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,7 +15,6 @@
 #include 
 
 #include "ext_dat.h"
-#include "x509_local.h"
 
 static STACK_OF(X509V3_EXT_METHOD) *ext_list = NULL;
 
@@ -71,7 +70,7 @@ const X509V3_EXT_METHOD *X509V3_EXT_get_nid(int nid)
     return sk_X509V3_EXT_METHOD_value(ext_list, idx);
 }
 
-const X509V3_EXT_METHOD *X509V3_EXT_get(const X509_EXTENSION *ext)
+const X509V3_EXT_METHOD *X509V3_EXT_get(X509_EXTENSION *ext)
 {
     int nid;
     if ((nid = OBJ_obj2nid(X509_EXTENSION_get_object(ext))) == NID_undef)
@@ -130,57 +129,23 @@ int X509V3_add_standard_extensions(void)
     return 1;
 }
 
-int ossl_ignored_x509_extension(const X509_EXTENSION *ex, int flags)
-{
-    /*
-     * Empty OCTET STRINGs and empty SEQUENCEs encode to just two bytes of tag
-     * (0x04 or 0x30) and length (0x00).  We use this fact to suppress empty
-     * AKID and SKID extensions that may be briefly generated when processing
-     * the "= none" value or only ":nonss"-qualified AKIDs when the subject is
-     * self-signed.
-     *
-     * The resulting extension is empty, and must not be retained, but does
-     * serve to drop any previous value of the same extension, when called
-     * via
-     * - X509v3_add_extensions(), or
-     * - either of X509V3_add1_i2d() or X509V3_EXT_add_nconf_sk(),
-     *   with a flags (or ctx->flags) value that allows replacement.
-     */
-    if (ex->value.length == 2
-        && (ex->value.data[0] == 0x30 || ex->value.data[0] == 0x04)) {
-        ASN1_OBJECT *obj = ex->object;
-        ASN1_OBJECT *skid = OBJ_nid2obj(NID_subject_key_identifier);
-        ASN1_OBJECT *akid = OBJ_nid2obj(NID_authority_key_identifier);
-
-        if (OBJ_cmp(obj, skid) == 0 || OBJ_cmp(obj, akid) == 0) {
-            if ((flags & X509V3_ADD_SILENT) == 0)
-                ERR_raise_data(ERR_LIB_X509, X509_R_INVALID_EXTENSION,
-                    "Invalid empty X.509 %s extension", obj->sn);
-            return 1;
-        }
-    }
-    return 0;
-}
-
 /* Return an extension internal structure */
 
-void *X509V3_EXT_d2i(const X509_EXTENSION *ext)
+void *X509V3_EXT_d2i(X509_EXTENSION *ext)
 {
     const X509V3_EXT_METHOD *method;
     const unsigned char *p;
-    const ASN1_STRING *extvalue;
-    size_t extlen;
+    ASN1_STRING *extvalue;
+    int extlen;
 
     if ((method = X509V3_EXT_get(ext)) == NULL)
         return NULL;
     extvalue = X509_EXTENSION_get_data(ext);
     p = ASN1_STRING_get0_data(extvalue);
-    extlen = ASN1_STRING_length_ex(extvalue);
-    if (extlen > INT_MAX)
-        return NULL;
+    extlen = ASN1_STRING_length(extvalue);
     if (method->it)
-        return ASN1_item_d2i(NULL, &p, (int)extlen, ASN1_ITEM_ptr(method->it));
-    return method->d2i(NULL, &p, (int)extlen);
+        return ASN1_item_d2i(NULL, &p, extlen, ASN1_ITEM_ptr(method->it));
+    return method->d2i(NULL, &p, extlen);
 }
 
 /*-
@@ -313,13 +278,9 @@ int X509V3_add1_i2d(STACK_OF(X509_EXTENSION) **x, int nid, void *value,
     /* If extension exists replace it.. */
     if (extidx >= 0) {
         extmp = sk_X509_EXTENSION_value(*x, extidx);
-        if (ossl_ignored_x509_extension(ext, X509V3_ADD_SILENT)) {
-            if (!sk_X509_EXTENSION_delete(*x, extidx))
-                return -1;
-        } else if (!sk_X509_EXTENSION_set(*x, extidx, ext)) {
-            return -1;
-        }
         X509_EXTENSION_free(extmp);
+        if (!sk_X509_EXTENSION_set(*x, extidx, ext))
+            return -1;
         return 1;
     }
 
diff --git a/crypto/x509/v3_ncons.c b/crypto/x509/v3_ncons.c
index 5f2710e9f5..a791fe6511 100644
--- a/crypto/x509/v3_ncons.c
+++ b/crypto/x509/v3_ncons.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2003-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2003-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -277,10 +277,10 @@ static int add_lengths(int *out, int a, int b)
  *  X509_V_ERR_UNSUPPORTED_NAME_SYNTAX: bad or unsupported syntax of name
  */
 
-int NAME_CONSTRAINTS_check(const X509 *x, NAME_CONSTRAINTS *nc)
+int NAME_CONSTRAINTS_check(X509 *x, NAME_CONSTRAINTS *nc)
 {
     int r, i, name_count, constraint_count;
-    const X509_NAME *nm;
+    X509_NAME *nm;
 
     nm = X509_get_subject_name(x);
 
@@ -299,8 +299,7 @@ int NAME_CONSTRAINTS_check(const X509 *x, NAME_CONSTRAINTS *nc)
     if (X509_NAME_entry_count(nm) > 0) {
         GENERAL_NAME gntmp;
         gntmp.type = GEN_DIRNAME;
-        /* XXX casts away const (but does not mutate) */
-        gntmp.d.directoryName = (X509_NAME *)nm;
+        gntmp.d.directoryName = nm;
 
         r = nc_match(&gntmp, nc);
 
@@ -318,8 +317,7 @@ int NAME_CONSTRAINTS_check(const X509 *x, NAME_CONSTRAINTS *nc)
             if (i == -1)
                 break;
             ne = X509_NAME_get_entry(nm, i);
-            /* XXX casts away const (but does not mutate) */
-            gntmp.d.rfc822Name = (ASN1_STRING *)X509_NAME_ENTRY_get_data(ne);
+            gntmp.d.rfc822Name = X509_NAME_ENTRY_get_data(ne);
             if (gntmp.d.rfc822Name->type != V_ASN1_IA5STRING)
                 return X509_V_ERR_UNSUPPORTED_NAME_SYNTAX;
 
@@ -340,7 +338,7 @@ int NAME_CONSTRAINTS_check(const X509 *x, NAME_CONSTRAINTS *nc)
     return X509_V_OK;
 }
 
-static int cn2dnsid(const ASN1_STRING *cn, unsigned char **dnsid, size_t *idlen)
+static int cn2dnsid(ASN1_STRING *cn, unsigned char **dnsid, size_t *idlen)
 {
     int utf8_length;
     unsigned char *utf8_value;
@@ -436,7 +434,7 @@ static int cn2dnsid(const ASN1_STRING *cn, unsigned char **dnsid, size_t *idlen)
 /*
  * Check CN against DNS-ID name constraints.
  */
-int NAME_CONSTRAINTS_check_CN(const X509 *x, NAME_CONSTRAINTS *nc)
+int NAME_CONSTRAINTS_check_CN(X509 *x, NAME_CONSTRAINTS *nc)
 {
     int r, i;
     const X509_NAME *nm = X509_get_subject_name(x);
@@ -451,8 +449,8 @@ int NAME_CONSTRAINTS_check_CN(const X509 *x, NAME_CONSTRAINTS *nc)
     /* Process any commonName attributes in subject name */
 
     for (i = -1;;) {
-        const X509_NAME_ENTRY *ne;
-        const ASN1_STRING *cn;
+        X509_NAME_ENTRY *ne;
+        ASN1_STRING *cn;
         unsigned char *idval;
         size_t idlen;
 
@@ -615,12 +613,6 @@ static int nc_dn(const X509_NAME *nm, const X509_NAME *base)
         return X509_V_ERR_OUT_OF_MEM;
     if (base->canon_enclen > nm->canon_enclen)
         return X509_V_ERR_PERMITTED_VIOLATION;
-    /*
-     * An empty base Name has no canonical encoding (canon_enc == NULL) and is
-     * a prefix of every Name, so it matches unconditionally.
-     */
-    if (base->canon_enclen == 0)
-        return X509_V_OK;
     if (memcmp(base->canon_enc, nm->canon_enc, base->canon_enclen))
         return X509_V_ERR_PERMITTED_VIOLATION;
     return X509_V_OK;
@@ -797,7 +789,6 @@ static int nc_uri(ASN1_IA5STRING *uri, ASN1_IA5STRING *base)
     if (scheme == NULL || *scheme == '\0') {
         ERR_raise_data(ERR_LIB_X509V3, X509_V_ERR_UNSUPPORTED_NAME_SYNTAX,
             "x509: missing scheme in URI: %s\n", uri_copy);
-        OPENSSL_free(scheme);
         OPENSSL_free(uri_copy);
         ret = X509_V_ERR_UNSUPPORTED_NAME_SYNTAX;
         goto end;
diff --git a/crypto/x509/v3_pci.c b/crypto/x509/v3_pci.c
index 78e76e130c..7d0a5faf4b 100644
--- a/crypto/x509/v3_pci.c
+++ b/crypto/x509/v3_pci.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2004-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2004-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -49,8 +49,6 @@
 #include 
 #include "ext_dat.h"
 
-#include 
-
 static int i2r_pci(X509V3_EXT_METHOD *method, PROXY_CERT_INFO_EXTENSION *ext,
     BIO *out, int indent);
 static PROXY_CERT_INFO_EXTENSION *r2i_pci(X509V3_EXT_METHOD *method,
diff --git a/crypto/x509/v3_prn.c b/crypto/x509/v3_prn.c
index 0fb7c9e38a..088cffed69 100644
--- a/crypto/x509/v3_prn.c
+++ b/crypto/x509/v3_prn.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -66,33 +66,31 @@ void X509V3_EXT_val_prn(BIO *out, STACK_OF(CONF_VALUE) *val, int indent,
 
 /* Main routine: print out a general extension */
 
-int X509V3_EXT_print(BIO *out, const X509_EXTENSION *ext, unsigned long flag,
+int X509V3_EXT_print(BIO *out, X509_EXTENSION *ext, unsigned long flag,
     int indent)
 {
     void *ext_str = NULL;
     char *value = NULL;
-    const ASN1_OCTET_STRING *extoct;
+    ASN1_OCTET_STRING *extoct;
     const unsigned char *p;
-    size_t extlen;
+    int extlen;
     const X509V3_EXT_METHOD *method;
     STACK_OF(CONF_VALUE) *nval = NULL;
     int ok = 1;
 
     extoct = X509_EXTENSION_get_data(ext);
     p = ASN1_STRING_get0_data(extoct);
-    extlen = ASN1_STRING_length_ex(extoct);
-    if (extlen > INT_MAX)
-        return 0;
+    extlen = ASN1_STRING_length(extoct);
 
     if ((method = X509V3_EXT_get(ext)) == NULL)
-        return unknown_ext_print(out, p, (int)extlen, flag, indent, 0);
+        return unknown_ext_print(out, p, extlen, flag, indent, 0);
     if (method->it)
-        ext_str = ASN1_item_d2i(NULL, &p, (int)extlen, ASN1_ITEM_ptr(method->it));
+        ext_str = ASN1_item_d2i(NULL, &p, extlen, ASN1_ITEM_ptr(method->it));
     else
-        ext_str = method->d2i(NULL, &p, (int)extlen);
+        ext_str = method->d2i(NULL, &p, extlen);
 
     if (!ext_str)
-        return unknown_ext_print(out, p, (int)extlen, flag, indent, 1);
+        return unknown_ext_print(out, p, extlen, flag, indent, 1);
 
     if (method->i2s) {
         if ((value = method->i2s(method, ext_str)) == NULL) {
@@ -152,8 +150,8 @@ int X509V3_extensions_print(BIO *bp, const char *title,
     }
 
     for (i = 0; i < sk_X509_EXTENSION_num(exts); i++) {
-        const ASN1_OBJECT *obj;
-        const X509_EXTENSION *ex;
+        ASN1_OBJECT *obj;
+        X509_EXTENSION *ex;
 
         ex = sk_X509_EXTENSION_value(exts, i);
         obj = X509_EXTENSION_get_object(ex);
@@ -193,9 +191,9 @@ static int unknown_ext_print(BIO *out, const unsigned char *ext, int extlen,
         return 1;
 
     case X509V3_EXT_PARSE_UNKNOWN:
-        return ASN1_parse_dump(out, ext, extlen, indent, -1) > 0;
+        return ASN1_parse_dump(out, ext, extlen, indent, -1);
     case X509V3_EXT_DUMP_UNKNOWN:
-        return BIO_dump_indent(out, (const char *)ext, extlen, indent) > 0;
+        return BIO_dump_indent(out, (const char *)ext, extlen, indent);
 
     default:
         return 1;
@@ -203,7 +201,7 @@ static int unknown_ext_print(BIO *out, const unsigned char *ext, int extlen,
 }
 
 #ifndef OPENSSL_NO_STDIO
-int X509V3_EXT_print_fp(FILE *fp, const X509_EXTENSION *ext, int flag, int indent)
+int X509V3_EXT_print_fp(FILE *fp, X509_EXTENSION *ext, int flag, int indent)
 {
     BIO *bio_tmp;
     int ret;
diff --git a/crypto/x509/v3_purp.c b/crypto/x509/v3_purp.c
index 462e2f12c8..0955a7aed5 100644
--- a/crypto/x509/v3_purp.c
+++ b/crypto/x509/v3_purp.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,8 +15,6 @@
 #include "crypto/x509.h"
 #include "internal/tsan_assist.h"
 #include "x509_local.h"
-#include "crypto/objects/obj_dat.h"
-#include "internal/hashfunc.h"
 
 static int check_ssl_ca(const X509 *x);
 static int check_purpose_ssl_client(const X509_PURPOSE *xp, const X509 *x,
@@ -40,7 +38,6 @@ static int no_check_purpose(const X509_PURPOSE *xp, const X509 *x,
     int non_leaf);
 static int check_purpose_ocsp_helper(const X509_PURPOSE *xp, const X509 *x,
     int non_leaf);
-static int check_name_constraints(const NAME_CONSTRAINTS *nc);
 
 static int xp_cmp(const X509_PURPOSE *const *a, const X509_PURPOSE *const *b);
 static void xptable_free(X509_PURPOSE *p);
@@ -82,16 +79,18 @@ static int xp_cmp(const X509_PURPOSE *const *a, const X509_PURPOSE *const *b)
     return (*a)->purpose - (*b)->purpose;
 }
 
-int X509_check_purpose(const X509 *x, int id, int non_leaf)
+/*
+ * As much as I'd like to make X509_check_purpose use a "const" X509* I really
+ * can't because it does recalculate hashes and do other non-const things.
+ * If id == -1 it just calls x509v3_cache_extensions() for its side-effect.
+ * Returns 1 on success, 0 if x does not allow purpose, -1 on (internal) error.
+ */
+int X509_check_purpose(X509 *x, int id, int non_leaf)
 {
     int idx;
     const X509_PURPOSE *pt;
 
-    /*
-     * TODO: This cast can be dropped when https://github.com/openssl/openssl/pull/30067
-     * gets merged
-     */
-    if (!ossl_x509v3_cache_extensions((X509 *)x))
+    if (!ossl_x509v3_cache_extensions(x))
         return -1;
     if (id == -1)
         return 1;
@@ -307,7 +306,7 @@ static int nid_cmp(const int *a, const int *b)
 DECLARE_OBJ_BSEARCH_CMP_FN(int, int, nid);
 IMPLEMENT_OBJ_BSEARCH_CMP_FN(int, int, nid);
 
-int X509_supported_extension(const X509_EXTENSION *ex)
+int X509_supported_extension(X509_EXTENSION *ex)
 {
     /*
      * This table is a list of the NIDs of supported extensions: that is
@@ -389,16 +388,16 @@ static int setup_dp(const X509 *x, DIST_POINT *dp)
 }
 
 /* Return 1 on success, 0 if x is invalid, -1 on (internal) error. */
-static int setup_crldp(const X509 *x, STACK_OF(DIST_POINT) **tmp_crldp)
+static int setup_crldp(X509 *x)
 {
     int i;
 
-    *tmp_crldp = X509_get_ext_d2i(x, NID_crl_distribution_points, &i, NULL);
-    if (*tmp_crldp == NULL && i != -1)
+    x->crldp = X509_get_ext_d2i(x, NID_crl_distribution_points, &i, NULL);
+    if (x->crldp == NULL && i != -1)
         return 0;
 
-    for (i = 0; i < sk_DIST_POINT_num(*tmp_crldp); i++) {
-        int res = setup_dp(x, sk_DIST_POINT_value(*tmp_crldp, i));
+    for (i = 0; i < sk_DIST_POINT_num(x->crldp); i++) {
+        int res = setup_dp(x, sk_DIST_POINT_value(x->crldp, i));
 
         if (res < 1)
             return res;
@@ -423,90 +422,6 @@ static int check_sig_alg_match(const EVP_PKEY *issuer_key, const X509 *subject)
     return X509_V_ERR_SIGNATURE_ALGORITHM_MISMATCH;
 }
 
-static unsigned long oid_hash(const void *p)
-{
-    const ASN1_OBJECT *a = p;
-
-    return (unsigned long)ossl_fnv1a_hash((uint8_t *)a->data, a->length);
-}
-
-static int oid_cmp(const void *a, const void *b)
-{
-    return OBJ_cmp((const ASN1_OBJECT *)a, (const ASN1_OBJECT *)b);
-}
-
-/*
- * Scan all extensions of a certificate to collect extension-related flags.
- * Detects duplicate extensions (RFC 5280 section 4.2), the presence of a
- * freshest CRL extension and unsupported critical extensions.
- *
- * In the future, if needed, this scanning function could return the index
- * of the offending extension on error, allowing the caller to identify which
- * extension caused the problem and report it via ERR_raise_data().
- */
-static void scan_ext_flags(const X509 *x509, uint32_t *flags)
-{
-    OPENSSL_LHASH *h = NULL;
-    uint8_t ex_bitset[(NUM_NID + 7) / 8];
-
-    memset(ex_bitset, 0, sizeof(ex_bitset));
-    /* A certificate MUST NOT include more than one instance of an extension. */
-    for (int i = 0; i < X509_get_ext_count(x509); i++) {
-        const X509_EXTENSION *ex = X509_get_ext(x509, i);
-        const ASN1_OBJECT *a = X509_EXTENSION_get_object(ex);
-        int nid = OBJ_obj2nid(a);
-
-        /*
-         * Known NIDs within the build-time bitset limit are checked for
-         * duplicates in constant time. Unknown OIDs and dynamically registered
-         * NIDs that exceed the limit fall back to duplicate detection via a
-         * hash table.
-         */
-        if (nid > NID_undef && nid < NUM_NID) {
-            unsigned int ex_bit = nid;
-
-            if ((ex_bitset[ex_bit >> 3] & (1u << (ex_bit & 7))) != 0) {
-                *flags |= EXFLAG_DUPLICATE;
-                break;
-            }
-            ex_bitset[ex_bit >> 3] |= (1u << (ex_bit & 7));
-        } else {
-            /*
-             * Extensions with unknown NID (NID_undef) and dynamically
-             * registered NIDs are handled here by hashing the OID (data/length).
-             * A zero-length OID should not reach this point, but we check for
-             * it anyway and assign the EXFLAG_INVALID flag if it does.
-             */
-            if (a->length < 1) {
-                *flags |= EXFLAG_INVALID;
-                break;
-            }
-            /*
-             * Hashing the OID should be manageable more cheaply as well, and
-             * without additional dynamic allocations. In the case of this
-             * corner case, it’s not a problem at all, but the other duplicate
-             * detections also require hashing, so for the sake of consistency
-             * it would make sense to use a cheaper construct here later as well.
-             */
-            if (h == NULL && (h = OPENSSL_LH_new(oid_hash, oid_cmp)) == NULL)
-                break;
-            if (OPENSSL_LH_insert(h, (void *)a) != NULL) {
-                *flags |= EXFLAG_DUPLICATE;
-                break;
-            }
-        }
-        if (nid == NID_freshest_crl)
-            *flags |= EXFLAG_FRESHEST;
-        if (!X509_EXTENSION_get_critical(ex))
-            continue;
-        if (!X509_supported_extension(ex)) {
-            *flags |= EXFLAG_CRITICAL;
-            break;
-        }
-    }
-    OPENSSL_LH_free(h);
-}
-
 #define V1_ROOT (EXFLAG_V1 | EXFLAG_SS)
 #define ku_reject(x, usage) \
     (((x)->ex_flags & EXFLAG_KUSAGE) != 0 && ((x)->ex_kusage & (usage)) == 0)
@@ -521,13 +436,8 @@ static void scan_ext_flags(const X509 *x509, uint32_t *flags)
  * x->sha1_hash is filled in, or else EXFLAG_NO_FINGERPRINT is set in x->flags.
  * X509_SIG_INFO_VALID is set in x->flags if x->siginf was filled successfully.
  * Set EXFLAG_INVALID and return 0 in case the certificate is invalid.
- *
- * This is usually called by side-effect on objects, and forces us to keep
- * mutable X509 objects around. We should really make this go away.
- * In the interest of being able to do so, this function explicitly takes
- * a const argument and casts away const.
  */
-int ossl_x509v3_cache_extensions(const X509 *const_x)
+int ossl_x509v3_cache_extensions(X509 *x)
 {
     BASIC_CONSTRAINTS *bs;
     PROXY_CERT_INFO_EXTENSION *pci;
@@ -536,53 +446,35 @@ int ossl_x509v3_cache_extensions(const X509 *const_x)
     EXTENDED_KEY_USAGE *extusage;
     int i;
     int res;
-    uint32_t tmp_ex_flags;
-    unsigned char tmp_sha1_hash[SHA_DIGEST_LENGTH];
-    long tmp_ex_pathlen;
-    long tmp_ex_pcpathlen;
-    uint32_t tmp_ex_kusage;
-    uint32_t tmp_ex_xkusage;
-    uint32_t tmp_ex_nscert;
-    ASN1_OCTET_STRING *tmp_skid;
-    AUTHORITY_KEYID *tmp_akid;
-    STACK_OF(GENERAL_NAME) *tmp_altname;
-    NAME_CONSTRAINTS *tmp_nc;
-    STACK_OF(DIST_POINT) *tmp_crldp = NULL;
-    X509_SIG_INFO tmp_siginf;
 
 #ifdef tsan_ld_acq
     /* Fast lock-free check, see end of the function for details. */
-    if (tsan_ld_acq((TSAN_QUALIFIER int *)&const_x->ex_cached))
-        return (const_x->ex_flags & EXFLAG_INVALID) == 0;
+    if (tsan_ld_acq((TSAN_QUALIFIER int *)&x->ex_cached))
+        return (x->ex_flags & EXFLAG_INVALID) == 0;
 #endif
 
-    if (!CRYPTO_THREAD_read_lock(const_x->lock))
+    if (!CRYPTO_THREAD_write_lock(x->lock))
         return 0;
-    tmp_ex_flags = const_x->ex_flags;
-    tmp_ex_pcpathlen = const_x->ex_pcpathlen;
-    tmp_ex_kusage = const_x->ex_kusage;
-    tmp_ex_nscert = const_x->ex_nscert;
-
-    if ((tmp_ex_flags & EXFLAG_SET) != 0) { /* Cert has already been processed */
-        CRYPTO_THREAD_unlock(const_x->lock);
-        return (tmp_ex_flags & EXFLAG_INVALID) == 0;
+    if ((x->ex_flags & EXFLAG_SET) != 0) { /* Cert has already been processed */
+        CRYPTO_THREAD_unlock(x->lock);
+        return (x->ex_flags & EXFLAG_INVALID) == 0;
     }
 
     ERR_set_mark();
 
     /* Cache the SHA1 digest of the cert */
-    if (!X509_digest(const_x, EVP_sha1(), tmp_sha1_hash, NULL))
-        tmp_ex_flags |= EXFLAG_NO_FINGERPRINT;
+    if (!X509_digest(x, EVP_sha1(), x->sha1_hash, NULL))
+        x->ex_flags |= EXFLAG_NO_FINGERPRINT;
 
     /* V1 should mean no extensions ... */
-    if (X509_get_version(const_x) == X509_VERSION_1)
-        tmp_ex_flags |= EXFLAG_V1;
+    if (X509_get_version(x) == X509_VERSION_1)
+        x->ex_flags |= EXFLAG_V1;
 
     /* Handle basic constraints */
-    tmp_ex_pathlen = -1;
-    if ((bs = X509_get_ext_d2i(const_x, NID_basic_constraints, &i, NULL)) != NULL) {
+    x->ex_pathlen = -1;
+    if ((bs = X509_get_ext_d2i(x, NID_basic_constraints, &i, NULL)) != NULL) {
         if (bs->ca)
-            tmp_ex_flags |= EXFLAG_CA;
+            x->ex_flags |= EXFLAG_CA;
         if (bs->pathlen != NULL) {
             /*
              * The error case !bs->ca is checked by check_chain()
@@ -590,86 +482,86 @@ int ossl_x509v3_cache_extensions(const X509 *const_x)
              */
             if (bs->pathlen->type == V_ASN1_NEG_INTEGER) {
                 ERR_raise(ERR_LIB_X509V3, X509V3_R_NEGATIVE_PATHLEN);
-                tmp_ex_flags |= EXFLAG_INVALID;
+                x->ex_flags |= EXFLAG_INVALID;
             } else {
-                tmp_ex_pathlen = ASN1_INTEGER_get(bs->pathlen);
+                x->ex_pathlen = ASN1_INTEGER_get(bs->pathlen);
             }
         }
         BASIC_CONSTRAINTS_free(bs);
-        tmp_ex_flags |= EXFLAG_BCONS;
+        x->ex_flags |= EXFLAG_BCONS;
     } else if (i != -1) {
-        tmp_ex_flags |= EXFLAG_INVALID;
+        x->ex_flags |= EXFLAG_INVALID;
     }
 
     /* Handle proxy certificates */
-    if ((pci = X509_get_ext_d2i(const_x, NID_proxyCertInfo, &i, NULL)) != NULL) {
-        if ((tmp_ex_flags & EXFLAG_CA) != 0
-            || X509_get_ext_by_NID(const_x, NID_subject_alt_name, -1) >= 0
-            || X509_get_ext_by_NID(const_x, NID_issuer_alt_name, -1) >= 0) {
-            tmp_ex_flags |= EXFLAG_INVALID;
+    if ((pci = X509_get_ext_d2i(x, NID_proxyCertInfo, &i, NULL)) != NULL) {
+        if ((x->ex_flags & EXFLAG_CA) != 0
+            || X509_get_ext_by_NID(x, NID_subject_alt_name, -1) >= 0
+            || X509_get_ext_by_NID(x, NID_issuer_alt_name, -1) >= 0) {
+            x->ex_flags |= EXFLAG_INVALID;
         }
         if (pci->pcPathLengthConstraint != NULL)
-            tmp_ex_pcpathlen = ASN1_INTEGER_get(pci->pcPathLengthConstraint);
+            x->ex_pcpathlen = ASN1_INTEGER_get(pci->pcPathLengthConstraint);
         else
-            tmp_ex_pcpathlen = -1;
+            x->ex_pcpathlen = -1;
         PROXY_CERT_INFO_EXTENSION_free(pci);
-        tmp_ex_flags |= EXFLAG_PROXY;
+        x->ex_flags |= EXFLAG_PROXY;
     } else if (i != -1) {
-        tmp_ex_flags |= EXFLAG_INVALID;
+        x->ex_flags |= EXFLAG_INVALID;
     }
 
     /* Handle (basic) key usage */
-    if ((usage = X509_get_ext_d2i(const_x, NID_key_usage, &i, NULL)) != NULL) {
-        tmp_ex_kusage = 0;
+    if ((usage = X509_get_ext_d2i(x, NID_key_usage, &i, NULL)) != NULL) {
+        x->ex_kusage = 0;
         if (usage->length > 0) {
-            tmp_ex_kusage = usage->data[0];
+            x->ex_kusage = usage->data[0];
             if (usage->length > 1)
-                tmp_ex_kusage |= usage->data[1] << 8;
+                x->ex_kusage |= usage->data[1] << 8;
         }
-        tmp_ex_flags |= EXFLAG_KUSAGE;
+        x->ex_flags |= EXFLAG_KUSAGE;
         ASN1_BIT_STRING_free(usage);
         /* Check for empty key usage according to RFC 5280 section 4.2.1.3 */
-        if (tmp_ex_kusage == 0) {
+        if (x->ex_kusage == 0) {
             ERR_raise(ERR_LIB_X509V3, X509V3_R_EMPTY_KEY_USAGE);
-            tmp_ex_flags |= EXFLAG_INVALID;
+            x->ex_flags |= EXFLAG_INVALID;
         }
     } else if (i != -1) {
-        tmp_ex_flags |= EXFLAG_INVALID;
+        x->ex_flags |= EXFLAG_INVALID;
     }
 
     /* Handle extended key usage */
-    tmp_ex_xkusage = 0;
-    if ((extusage = X509_get_ext_d2i(const_x, NID_ext_key_usage, &i, NULL)) != NULL) {
-        tmp_ex_flags |= EXFLAG_XKUSAGE;
+    x->ex_xkusage = 0;
+    if ((extusage = X509_get_ext_d2i(x, NID_ext_key_usage, &i, NULL)) != NULL) {
+        x->ex_flags |= EXFLAG_XKUSAGE;
         for (i = 0; i < sk_ASN1_OBJECT_num(extusage); i++) {
             switch (OBJ_obj2nid(sk_ASN1_OBJECT_value(extusage, i))) {
             case NID_server_auth:
-                tmp_ex_xkusage |= XKU_SSL_SERVER;
+                x->ex_xkusage |= XKU_SSL_SERVER;
                 break;
             case NID_client_auth:
-                tmp_ex_xkusage |= XKU_SSL_CLIENT;
+                x->ex_xkusage |= XKU_SSL_CLIENT;
                 break;
             case NID_email_protect:
-                tmp_ex_xkusage |= XKU_SMIME;
+                x->ex_xkusage |= XKU_SMIME;
                 break;
             case NID_code_sign:
-                tmp_ex_xkusage |= XKU_CODE_SIGN;
+                x->ex_xkusage |= XKU_CODE_SIGN;
                 break;
             case NID_ms_sgc:
             case NID_ns_sgc:
-                tmp_ex_xkusage |= XKU_SGC;
+                x->ex_xkusage |= XKU_SGC;
                 break;
             case NID_OCSP_sign:
-                tmp_ex_xkusage |= XKU_OCSP_SIGN;
+                x->ex_xkusage |= XKU_OCSP_SIGN;
                 break;
             case NID_time_stamp:
-                tmp_ex_xkusage |= XKU_TIMESTAMP;
+                x->ex_xkusage |= XKU_TIMESTAMP;
                 break;
             case NID_dvcs:
-                tmp_ex_xkusage |= XKU_DVCS;
+                x->ex_xkusage |= XKU_DVCS;
                 break;
             case NID_anyExtendedKeyUsage:
-                tmp_ex_xkusage |= XKU_ANYEKU;
+                x->ex_xkusage |= XKU_ANYEKU;
                 break;
             default:
                 /* Ignore unknown extended key usage */
@@ -678,134 +570,112 @@ int ossl_x509v3_cache_extensions(const X509 *const_x)
         }
         sk_ASN1_OBJECT_pop_free(extusage, ASN1_OBJECT_free);
     } else if (i != -1) {
-        tmp_ex_flags |= EXFLAG_INVALID;
+        x->ex_flags |= EXFLAG_INVALID;
     }
 
     /* Handle legacy Netscape extension */
-    if ((ns = X509_get_ext_d2i(const_x, NID_netscape_cert_type, &i, NULL)) != NULL) {
+    if ((ns = X509_get_ext_d2i(x, NID_netscape_cert_type, &i, NULL)) != NULL) {
         if (ns->length > 0)
-            tmp_ex_nscert = ns->data[0];
+            x->ex_nscert = ns->data[0];
         else
-            tmp_ex_nscert = 0;
-        tmp_ex_flags |= EXFLAG_NSCERT;
+            x->ex_nscert = 0;
+        x->ex_flags |= EXFLAG_NSCERT;
         ASN1_BIT_STRING_free(ns);
     } else if (i != -1) {
-        tmp_ex_flags |= EXFLAG_INVALID;
+        x->ex_flags |= EXFLAG_INVALID;
     }
 
     /* Handle subject key identifier and issuer/authority key identifier */
-    tmp_skid = X509_get_ext_d2i(const_x, NID_subject_key_identifier, &i, NULL);
-    if (tmp_skid == NULL && i != -1)
-        tmp_ex_flags |= EXFLAG_INVALID;
+    x->skid = X509_get_ext_d2i(x, NID_subject_key_identifier, &i, NULL);
+    if (x->skid == NULL && i != -1)
+        x->ex_flags |= EXFLAG_INVALID;
 
-    tmp_akid = X509_get_ext_d2i(const_x, NID_authority_key_identifier, &i, NULL);
-    if (tmp_akid == NULL && i != -1)
-        tmp_ex_flags |= EXFLAG_INVALID;
+    x->akid = X509_get_ext_d2i(x, NID_authority_key_identifier, &i, NULL);
+    if (x->akid == NULL && i != -1)
+        x->ex_flags |= EXFLAG_INVALID;
 
-    /* Setting EXFLAG_SS is equivalent to ossl_x509_likely_issued(const_x, const_x) == X509_V_OK */
-    if (X509_NAME_cmp(X509_get_subject_name(const_x), X509_get_issuer_name(const_x)) == 0) {
-        tmp_ex_flags |= EXFLAG_SI; /* Certificate is self-issued: subject == issuer */
-        /*
-         * When the SKID is missing, which is rare for self-issued certs,
-         * we could afford doing the (accurate) actual self-signature check, but
-         * decided against it for efficiency reasons and according to RFC 5280,
-         * CA certs MUST have an SKID and non-root certs MUST have an AKID.
-         */
-        if (X509_check_akid(const_x, tmp_akid) == X509_V_OK
-            && check_sig_alg_match(X509_get0_pubkey(const_x), const_x) == X509_V_OK) {
-            /*
-             * Assume self-signed if the signature alg matches the pkey alg and
-             * AKID is missing or matches respective fields in the same cert
-             * Not checking if any given key usage extension allows signing.
-             */
-            tmp_ex_flags |= EXFLAG_SS;
-        }
+    /* Check if subject name matches issuer */
+    if (X509_NAME_cmp(X509_get_subject_name(x), X509_get_issuer_name(x)) == 0) {
+        x->ex_flags |= EXFLAG_SI; /* Cert is self-issued */
+        if (X509_check_akid(x, x->akid) == X509_V_OK /* SKID matches AKID */
+            /* .. and the signature alg matches the PUBKEY alg: */
+            && check_sig_alg_match(X509_get0_pubkey(x), x) == X509_V_OK)
+            x->ex_flags |= EXFLAG_SS; /* indicate self-signed */
+        /* This is very related to ossl_x509_likely_issued(x, x) == X509_V_OK */
     }
 
     /* Handle subject alternative names and various other extensions */
-    tmp_altname = X509_get_ext_d2i(const_x, NID_subject_alt_name, &i, NULL);
-    if (tmp_altname == NULL && i != -1)
-        tmp_ex_flags |= EXFLAG_INVALID;
-    tmp_nc = X509_get_ext_d2i(const_x, NID_name_constraints, &i, NULL);
-    if (tmp_nc == NULL && i != -1)
-        tmp_ex_flags |= EXFLAG_INVALID;
-    if (!check_name_constraints(tmp_nc))
-        tmp_ex_flags |= EXFLAG_INVALID;
+    x->altname = X509_get_ext_d2i(x, NID_subject_alt_name, &i, NULL);
+    if (x->altname == NULL && i != -1)
+        x->ex_flags |= EXFLAG_INVALID;
+    x->nc = X509_get_ext_d2i(x, NID_name_constraints, &i, NULL);
+    if (x->nc == NULL && i != -1)
+        x->ex_flags |= EXFLAG_INVALID;
 
     /* Handle CRL distribution point entries */
-    res = setup_crldp(const_x, &tmp_crldp);
+    res = setup_crldp(x);
     if (res == 0)
-        tmp_ex_flags |= EXFLAG_INVALID;
+        x->ex_flags |= EXFLAG_INVALID;
 
 #ifndef OPENSSL_NO_RFC3779
-    STACK_OF(IPAddressFamily) *tmp_rfc3779_addr
-        = X509_get_ext_d2i(const_x, NID_sbgp_ipAddrBlock, &i, NULL);
-    if (tmp_rfc3779_addr == NULL && i != -1)
-        tmp_ex_flags |= EXFLAG_INVALID;
-
-    struct ASIdentifiers_st *tmp_rfc3779_asid
-        = X509_get_ext_d2i(const_x, NID_sbgp_autonomousSysNum, &i, NULL);
-    if (tmp_rfc3779_asid == NULL && i != -1)
-        tmp_ex_flags |= EXFLAG_INVALID;
+    x->rfc3779_addr = X509_get_ext_d2i(x, NID_sbgp_ipAddrBlock, &i, NULL);
+    if (x->rfc3779_addr == NULL && i != -1)
+        x->ex_flags |= EXFLAG_INVALID;
+    x->rfc3779_asid = X509_get_ext_d2i(x, NID_sbgp_autonomousSysNum, &i, NULL);
+    if (x->rfc3779_asid == NULL && i != -1)
+        x->ex_flags |= EXFLAG_INVALID;
 #endif
+    for (i = 0; i < X509_get_ext_count(x); i++) {
+        X509_EXTENSION *ex = X509_get_ext(x, i);
+        int nid = OBJ_obj2nid(X509_EXTENSION_get_object(ex));
 
-    scan_ext_flags(const_x, &tmp_ex_flags);
+        if (nid == NID_freshest_crl)
+            x->ex_flags |= EXFLAG_FRESHEST;
+        if (!X509_EXTENSION_get_critical(ex))
+            continue;
+        if (!X509_supported_extension(ex)) {
+            x->ex_flags |= EXFLAG_CRITICAL;
+            break;
+        }
+        switch (nid) {
+        case NID_basic_constraints:
+            x->ex_flags |= EXFLAG_BCONS_CRITICAL;
+            break;
+        case NID_authority_key_identifier:
+            x->ex_flags |= EXFLAG_AKID_CRITICAL;
+            break;
+        case NID_subject_key_identifier:
+            x->ex_flags |= EXFLAG_SKID_CRITICAL;
+            break;
+        case NID_subject_alt_name:
+            x->ex_flags |= EXFLAG_SAN_CRITICAL;
+            break;
+        default:
+            break;
+        }
+    }
 
     /* Set x->siginf, ignoring errors due to unsupported algos */
-    (void)ossl_x509_init_sig_info(const_x, &tmp_siginf);
-
-    tmp_ex_flags |= EXFLAG_SET; /* Indicate that cert has been processed */
-    ERR_pop_to_mark();
-
-    CRYPTO_THREAD_unlock(const_x->lock);
-    /*
-     * Now that we've done all the compute intensive work under read lock
-     * do all the updating under a write lock
-     */
-    if (!CRYPTO_THREAD_write_lock(const_x->lock))
-        return 0;
-    ((X509 *)const_x)->ex_flags = tmp_ex_flags;
-    ((X509 *)const_x)->ex_pathlen = tmp_ex_pathlen;
-    ((X509 *)const_x)->ex_pcpathlen = tmp_ex_pcpathlen;
-    if (!(tmp_ex_flags & EXFLAG_NO_FINGERPRINT))
-        memcpy(((X509 *)const_x)->sha1_hash, tmp_sha1_hash, SHA_DIGEST_LENGTH);
-    if (tmp_ex_flags & EXFLAG_KUSAGE)
-        ((X509 *)const_x)->ex_kusage = tmp_ex_kusage;
-    ((X509 *)const_x)->ex_xkusage = tmp_ex_xkusage;
-    if (tmp_ex_flags & EXFLAG_NSCERT)
-        ((X509 *)const_x)->ex_nscert = tmp_ex_nscert;
-    ASN1_OCTET_STRING_free(((X509 *)const_x)->skid);
-    ((X509 *)const_x)->skid = tmp_skid;
-    AUTHORITY_KEYID_free(((X509 *)const_x)->akid);
-    ((X509 *)const_x)->akid = tmp_akid;
-    sk_GENERAL_NAME_pop_free(((X509 *)const_x)->altname, GENERAL_NAME_free);
-    ((X509 *)const_x)->altname = tmp_altname;
-    NAME_CONSTRAINTS_free(((X509 *)const_x)->nc);
-    ((X509 *)const_x)->nc = tmp_nc;
-    sk_DIST_POINT_pop_free(((X509 *)const_x)->crldp, DIST_POINT_free);
-    ((X509 *)const_x)->crldp = tmp_crldp;
-#ifndef OPENSSL_NO_RFC3779
-    sk_IPAddressFamily_pop_free(((X509 *)const_x)->rfc3779_addr, IPAddressFamily_free);
-    ((X509 *)const_x)->rfc3779_addr = tmp_rfc3779_addr;
-    ASIdentifiers_free(((X509 *)const_x)->rfc3779_asid);
-    ((X509 *)const_x)->rfc3779_asid = tmp_rfc3779_asid;
-#endif
-    ((X509 *)const_x)->siginf = tmp_siginf;
+    (void)ossl_x509_init_sig_info(x);
 
+    x->ex_flags |= EXFLAG_SET; /* Indicate that cert has been processed */
 #ifdef tsan_st_rel
-    tsan_st_rel((TSAN_QUALIFIER int *)&const_x->ex_cached, 1);
+    tsan_st_rel((TSAN_QUALIFIER int *)&x->ex_cached, 1);
     /*
      * Above store triggers fast lock-free check in the beginning of the
      * function. But one has to ensure that the structure is "stable", i.e.
      * all stores are visible on all processors. Hence the release fence.
      */
 #endif
-    CRYPTO_THREAD_unlock(const_x->lock);
-    if (tmp_ex_flags & EXFLAG_INVALID) {
-        ERR_raise(ERR_LIB_X509V3, X509V3_R_INVALID_CERTIFICATE);
-        return 0;
+    ERR_pop_to_mark();
+
+    if ((x->ex_flags & EXFLAG_INVALID) == 0) {
+        CRYPTO_THREAD_unlock(x->lock);
+        return 1;
     }
-    return 1;
+    CRYPTO_THREAD_unlock(x->lock);
+    ERR_raise(ERR_LIB_X509V3, X509V3_R_INVALID_CERTIFICATE);
+    return 0;
 }
 
 /*-
@@ -859,7 +729,7 @@ void X509_set_proxy_pathlen(X509 *x, long l)
     x->ex_pcpathlen = l;
 }
 
-int X509_check_ca(const X509 *x)
+int X509_check_ca(X509 *x)
 {
     /* Note 0 normally means "not a CA" - but in this case means error. */
     if (!ossl_x509v3_cache_extensions(x))
@@ -1082,7 +952,7 @@ static int check_purpose_code_sign(const X509_PURPOSE *xp, const X509 *x,
     if (i_ext < 0)
         return 0;
     if (i_ext >= 0) {
-        const X509_EXTENSION *ext = X509_get_ext((X509 *)x, i_ext);
+        X509_EXTENSION *ext = X509_get_ext((X509 *)x, i_ext);
         if (!X509_EXTENSION_get_critical(ext))
             return 0;
     }
@@ -1104,45 +974,6 @@ static int no_check_purpose(const X509_PURPOSE *xp, const X509 *x,
     return 1;
 }
 
-static int check_name_constraints(const NAME_CONSTRAINTS *nc)
-{
-    GENERAL_SUBTREE *sub;
-    int ret = 1;
-
-    if (nc == NULL)
-        goto done;
-
-    for (int i = 0; nc->permittedSubtrees != NULL
-        && i < sk_GENERAL_SUBTREE_num(nc->permittedSubtrees);
-        i++) {
-        sub = sk_GENERAL_SUBTREE_value(nc->permittedSubtrees, i);
-        if (sub->base->type == GEN_OTHERNAME
-            && OBJ_obj2nid(sub->base->d.otherName->type_id)
-                == NID_id_on_SmtpUTF8Mailbox) {
-            /* RFC 9598 prohibits GEN_OTHERNAME email constraints */
-            ERR_raise(ERR_LIB_X509V3, X509_V_ERR_UNSUPPORTED_CONSTRAINT_TYPE);
-            ret = 0;
-            goto done;
-        }
-    }
-    for (int i = 0; nc->excludedSubtrees != NULL
-        && i < sk_GENERAL_SUBTREE_num(nc->excludedSubtrees);
-        i++) {
-        sub = sk_GENERAL_SUBTREE_value(nc->excludedSubtrees, i);
-        if (sub->base->type == GEN_OTHERNAME
-            && OBJ_obj2nid(sub->base->d.otherName->type_id)
-                == NID_id_on_SmtpUTF8Mailbox) {
-            /* RFC 9598 prohibits GEN_OTHERNAME email constraints */
-            ERR_raise(ERR_LIB_X509V3, X509_V_ERR_UNSUPPORTED_CONSTRAINT_TYPE);
-            ret = 0;
-            goto done;
-        }
-    }
-
-done:
-    return ret;
-}
-
 /*-
  * Various checks to see if one certificate potentially issued the second.
  * This can be used to prune a set of possible issuer certificates which
@@ -1156,7 +987,7 @@ done:
  * Returns 0 for OK, or positive for reason for mismatch
  * where reason codes match those for X509_verify_cert().
  */
-int X509_check_issued(const X509 *issuer, const X509 *subject)
+int X509_check_issued(X509 *issuer, X509 *subject)
 {
     int ret;
 
@@ -1165,13 +996,8 @@ int X509_check_issued(const X509 *issuer, const X509 *subject)
     return ossl_x509_signing_allowed(issuer, subject);
 }
 
-/*
- * Do the checks 1., 2., and 3. as described above for X509_check_issued().
- * These are very similar to a section of ossl_x509v3_cache_extensions().
- * If |issuer| equals |subject| (such that self-signature should be checked),
- * use the EXFLAG_SS result of ossl_x509v3_cache_extensions().
- */
-int ossl_x509_likely_issued(const X509 *issuer, const X509 *subject)
+/* do the checks 1., 2., and 3. as described above for X509_check_issued() */
+int ossl_x509_likely_issued(X509 *issuer, X509 *subject)
 {
     int ret;
 
@@ -1180,29 +1006,11 @@ int ossl_x509_likely_issued(const X509 *issuer, const X509 *subject)
         != 0)
         return X509_V_ERR_SUBJECT_ISSUER_MISMATCH;
 
-    /* set issuer->skid, subject->akid, and subject->ex_flags */
+    /* set issuer->skid and subject->akid */
     if (!ossl_x509v3_cache_extensions(issuer)
         || !ossl_x509v3_cache_extensions(subject))
         return X509_V_ERR_UNSPECIFIED;
 
-    if (issuer == subject
-        || (X509_NAME_cmp(X509_get_issuer_name(issuer), X509_get_issuer_name(subject)) == 0
-            && ASN1_INTEGER_cmp(X509_get0_serialNumber(issuer), X509_get0_serialNumber(subject)) == 0))
-        /*
-         * At this point, we can assume that issuer and subject
-         * are semantically the same cert because they are identical
-         * or at least have the same issuer and serial number,
-         * which (for any sane cert issuer) implies equality of the two certs.
-         * In this case, for consistency with chain building and validation,
-         * we make our issuance judgment depend on the presence of EXFLAG_SS.
-         * This is used for corrected chain building in the corner case of
-         * a self-issued but not actually self-signed trust anchor cert
-         * without subject and issuer key identifiers (i.e., no SKID and AKID).
-         */
-        return (issuer->ex_flags & EXFLAG_SS) != 0
-            ? X509_V_OK
-            : X509_V_ERR_CERT_SIGNATURE_FAILURE;
-
     ret = X509_check_akid(issuer, subject->akid);
     if (ret != X509_V_OK)
         return ret;
@@ -1229,12 +1037,6 @@ int ossl_x509_signing_allowed(const X509 *issuer, const X509 *subject)
     return X509_V_OK;
 }
 
-/*
- * check if all sub-fields of the authority key identifier information akid,
- * as far as present, match the respective subjectKeyIdentifier extension (if
- * present in issuer), serialNumber field, and issuer fields of issuer.
- * returns X509_V_OK also if akid is NULL because this means no restriction.
- */
 int X509_check_akid(const X509 *issuer, const AUTHORITY_KEYID *akid)
 {
     if (akid == NULL)
@@ -1271,14 +1073,14 @@ int X509_check_akid(const X509 *issuer, const AUTHORITY_KEYID *akid)
     return X509_V_OK;
 }
 
-uint32_t X509_get_extension_flags(const X509 *x)
+uint32_t X509_get_extension_flags(X509 *x)
 {
     /* Call for side-effect of computing hash and caching extensions */
     X509_check_purpose(x, -1, 0);
     return x->ex_flags;
 }
 
-uint32_t X509_get_key_usage(const X509 *x)
+uint32_t X509_get_key_usage(X509 *x)
 {
     /* Call for side-effect of computing hash and caching extensions */
     if (X509_check_purpose(x, -1, 0) != 1)
@@ -1286,7 +1088,7 @@ uint32_t X509_get_key_usage(const X509 *x)
     return (x->ex_flags & EXFLAG_KUSAGE) != 0 ? x->ex_kusage : UINT32_MAX;
 }
 
-uint32_t X509_get_extended_key_usage(const X509 *x)
+uint32_t X509_get_extended_key_usage(X509 *x)
 {
     /* Call for side-effect of computing hash and caching extensions */
     if (X509_check_purpose(x, -1, 0) != 1)
@@ -1294,7 +1096,7 @@ uint32_t X509_get_extended_key_usage(const X509 *x)
     return (x->ex_flags & EXFLAG_XKUSAGE) != 0 ? x->ex_xkusage : UINT32_MAX;
 }
 
-const ASN1_OCTET_STRING *X509_get0_subject_key_id(const X509 *x)
+const ASN1_OCTET_STRING *X509_get0_subject_key_id(X509 *x)
 {
     /* Call for side-effect of computing hash and caching extensions */
     if (X509_check_purpose(x, -1, 0) != 1)
@@ -1302,7 +1104,7 @@ const ASN1_OCTET_STRING *X509_get0_subject_key_id(const X509 *x)
     return x->skid;
 }
 
-const ASN1_OCTET_STRING *X509_get0_authority_key_id(const X509 *x)
+const ASN1_OCTET_STRING *X509_get0_authority_key_id(X509 *x)
 {
     /* Call for side-effect of computing hash and caching extensions */
     if (X509_check_purpose(x, -1, 0) != 1)
@@ -1310,7 +1112,7 @@ const ASN1_OCTET_STRING *X509_get0_authority_key_id(const X509 *x)
     return (x->akid != NULL ? x->akid->keyid : NULL);
 }
 
-const GENERAL_NAMES *X509_get0_authority_issuer(const X509 *x)
+const GENERAL_NAMES *X509_get0_authority_issuer(X509 *x)
 {
     /* Call for side-effect of computing hash and caching extensions */
     if (X509_check_purpose(x, -1, 0) != 1)
@@ -1318,7 +1120,7 @@ const GENERAL_NAMES *X509_get0_authority_issuer(const X509 *x)
     return (x->akid != NULL ? x->akid->issuer : NULL);
 }
 
-const ASN1_INTEGER *X509_get0_authority_serial(const X509 *x)
+const ASN1_INTEGER *X509_get0_authority_serial(X509 *x)
 {
     /* Call for side-effect of computing hash and caching extensions */
     if (X509_check_purpose(x, -1, 0) != 1)
@@ -1326,7 +1128,7 @@ const ASN1_INTEGER *X509_get0_authority_serial(const X509 *x)
     return (x->akid != NULL ? x->akid->serial : NULL);
 }
 
-long X509_get_pathlen(const X509 *x)
+long X509_get_pathlen(X509 *x)
 {
     /* Called for side effect of caching extensions */
     if (X509_check_purpose(x, -1, 0) != 1
@@ -1335,7 +1137,7 @@ long X509_get_pathlen(const X509 *x)
     return x->ex_pathlen;
 }
 
-long X509_get_proxy_pathlen(const X509 *x)
+long X509_get_proxy_pathlen(X509 *x)
 {
     /* Called for side effect of caching extensions */
     if (X509_check_purpose(x, -1, 0) != 1
diff --git a/crypto/x509/v3_san.c b/crypto/x509/v3_san.c
index f1b028f78c..fcd7465271 100644
--- a/crypto/x509/v3_san.c
+++ b/crypto/x509/v3_san.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -337,7 +337,7 @@ static int copy_issuer(X509V3_CTX *ctx, GENERAL_NAMES *gens)
 {
     GENERAL_NAMES *ialt = NULL;
     GENERAL_NAME *gen;
-    const X509_EXTENSION *ext;
+    X509_EXTENSION *ext;
     int i, num;
 
     if (ctx != NULL && (ctx->flags & X509V3_CTX_TEST) != 0)
@@ -418,7 +418,7 @@ err:
 
 static int copy_email(X509V3_CTX *ctx, GENERAL_NAMES *gens, int move_p)
 {
-    const X509_NAME *nm;
+    X509_NAME *nm;
     ASN1_IA5STRING *email = NULL;
     X509_NAME_ENTRY *ne;
     GENERAL_NAME *gen = NULL;
@@ -432,23 +432,19 @@ static int copy_email(X509V3_CTX *ctx, GENERAL_NAMES *gens, int move_p)
         return 0;
     }
     /* Find the subject name */
-    nm = ctx->subject_cert != NULL ? X509_get_subject_name(ctx->subject_cert)
-                                   : X509_REQ_get_subject_name(ctx->subject_req);
+    nm = ctx->subject_cert != NULL ? X509_get_subject_name(ctx->subject_cert) : X509_REQ_get_subject_name(ctx->subject_req);
 
     /* Now add any email address(es) to STACK */
     while ((i = X509_NAME_get_index_by_NID(nm,
                 NID_pkcs9_emailAddress, i))
         >= 0) {
-        if (move_p) {
-            /* We should really not support deleting things in a const object
-             * to rip the pointer out of it. If we truly want a new object
-             * without this in it, we should just construct one without it.
-             */
-            return 0;
-        }
-        /* XXX Casts away const */
-        ne = (X509_NAME_ENTRY *)X509_NAME_get_entry(nm, i);
+        ne = X509_NAME_get_entry(nm, i);
         email = ASN1_STRING_dup(X509_NAME_ENTRY_get_data(ne));
+        if (move_p) {
+            X509_NAME_delete_entry(nm, i);
+            X509_NAME_ENTRY_free(ne);
+            i--;
+        }
         if (email == NULL || (gen = GENERAL_NAME_new()) == NULL) {
             ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
             goto err;
@@ -575,8 +571,7 @@ GENERAL_NAME *a2i_GENERAL_NAME(GENERAL_NAME *out,
     }
 
     if (is_string) {
-        if ((gen->d.ia5 = ASN1_IA5STRING_new()) == NULL
-            || !ASN1_STRING_set_string(gen->d.ia5, value)) {
+        if ((gen->d.ia5 = ASN1_IA5STRING_new()) == NULL || !ASN1_STRING_set(gen->d.ia5, (unsigned char *)value, (int)strlen(value))) {
             ASN1_IA5STRING_free(gen->d.ia5);
             gen->d.ia5 = NULL;
             ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
@@ -635,8 +630,7 @@ GENERAL_NAME *v2i_GENERAL_NAME_ex(GENERAL_NAME *out,
 
 static int do_othername(GENERAL_NAME *gen, const char *value, X509V3_CTX *ctx)
 {
-    char *objtmp = NULL;
-    const char *p;
+    char *objtmp = NULL, *p;
     size_t objlen;
 
     if ((p = strchr(value, ';')) == NULL)
diff --git a/crypto/x509/v3_sda.c b/crypto/x509/v3_sda.c
index 6887ef8850..a3ecc3318d 100644
--- a/crypto/x509/v3_sda.c
+++ b/crypto/x509/v3_sda.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -22,7 +22,7 @@ static int i2r_ATTRIBUTES_SYNTAX(X509V3_EXT_METHOD *method,
     BIO *out, int indent)
 {
     X509_ATTRIBUTE *attr;
-    const ASN1_TYPE *av;
+    ASN1_TYPE *av;
     int i, j, attr_nid;
 
     if (!attrlst) {
@@ -37,7 +37,7 @@ static int i2r_ATTRIBUTES_SYNTAX(X509V3_EXT_METHOD *method,
     }
 
     for (i = 0; i < sk_X509_ATTRIBUTE_num(attrlst); i++) {
-        const ASN1_OBJECT *attr_obj;
+        ASN1_OBJECT *attr_obj;
         attr = sk_X509_ATTRIBUTE_value(attrlst, i);
         attr_obj = X509_ATTRIBUTE_get0_object(attr);
         attr_nid = OBJ_obj2nid(attr_obj);
diff --git a/crypto/x509/v3_timespec.c b/crypto/x509/v3_timespec.c
index f29265f4be..28f9a1c610 100644
--- a/crypto/x509/v3_timespec.c
+++ b/crypto/x509/v3_timespec.c
@@ -167,7 +167,7 @@ static int i2r_OSSL_DAY_TIME(X509V3_EXT_METHOD *method,
         return 0;
     if (dt->minute && !ASN1_INTEGER_get_int64(&m, dt->minute))
         return 0;
-    if (dt->second && !ASN1_INTEGER_get_int64(&s, dt->second))
+    if (dt->minute && !ASN1_INTEGER_get_int64(&s, dt->second))
         return 0;
     return BIO_printf(out, "%02lld:%02lld:%02lld",
                (long long int)h, (long long int)m, (long long int)s)
diff --git a/crypto/x509/v3_usernotice.c b/crypto/x509/v3_usernotice.c
index 8a53eff96e..9bf1502f75 100644
--- a/crypto/x509/v3_usernotice.c
+++ b/crypto/x509/v3_usernotice.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -11,8 +11,6 @@
 #include 
 #include "ext_dat.h"
 
-#include 
-
 ASN1_ITEM_TEMPLATE(OSSL_USER_NOTICE_SYNTAX) = ASN1_EX_TEMPLATE_TYPE(ASN1_TFLG_SEQUENCE_OF, 0, OSSL_USER_NOTICE_SYNTAX, USERNOTICE)
 ASN1_ITEM_TEMPLATE_END(OSSL_USER_NOTICE_SYNTAX)
 
diff --git a/crypto/x509/v3_utf8.c b/crypto/x509/v3_utf8.c
index dc7c86fb7f..e9aaedab81 100644
--- a/crypto/x509/v3_utf8.c
+++ b/crypto/x509/v3_utf8.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -14,8 +14,6 @@
 #include 
 #include "ext_dat.h"
 
-#include 
-
 /*
  * Subject Sign Tool (1.2.643.100.111) The name of the tool used to signs the subject (UTF8String)
  * This extension is required to obtain the status of a qualified certificate at Russian Federation.
@@ -55,7 +53,7 @@ ASN1_UTF8STRING *s2i_ASN1_UTF8STRING(X509V3_EXT_METHOD *method,
         ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
         return NULL;
     }
-    if (!ASN1_STRING_set_string(utf8, str)) {
+    if (!ASN1_STRING_set((ASN1_STRING *)utf8, str, (int)strlen(str))) {
         ERR_raise(ERR_LIB_X509V3, ERR_R_ASN1_LIB);
         ASN1_UTF8STRING_free(utf8);
         return NULL;
diff --git a/crypto/x509/v3_utl.c b/crypto/x509/v3_utl.c
index 4ccfcacadb..e7abe6150a 100644
--- a/crypto/x509/v3_utl.c
+++ b/crypto/x509/v3_utl.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -446,7 +446,7 @@ static int sk_strcmp(const char *const *a, const char *const *b)
     return strcmp(*a, *b);
 }
 
-STACK_OF(OPENSSL_STRING) *X509_get1_email(const X509 *x)
+STACK_OF(OPENSSL_STRING) *X509_get1_email(X509 *x)
 {
     GENERAL_NAMES *gens;
     STACK_OF(OPENSSL_STRING) *ret;
@@ -457,7 +457,7 @@ STACK_OF(OPENSSL_STRING) *X509_get1_email(const X509 *x)
     return ret;
 }
 
-STACK_OF(OPENSSL_STRING) *X509_get1_ocsp(const X509 *x)
+STACK_OF(OPENSSL_STRING) *X509_get1_ocsp(X509 *x)
 {
     AUTHORITY_INFO_ACCESS *info;
     STACK_OF(OPENSSL_STRING) *ret = NULL;
@@ -479,7 +479,7 @@ STACK_OF(OPENSSL_STRING) *X509_get1_ocsp(const X509 *x)
     return ret;
 }
 
-STACK_OF(OPENSSL_STRING) *X509_REQ_get1_email(const X509_REQ *x)
+STACK_OF(OPENSSL_STRING) *X509_REQ_get1_email(X509_REQ *x)
 {
     GENERAL_NAMES *gens;
     STACK_OF(X509_EXTENSION) *exts;
@@ -497,7 +497,7 @@ static STACK_OF(OPENSSL_STRING) *get_email(const X509_NAME *name,
     GENERAL_NAMES *gens)
 {
     STACK_OF(OPENSSL_STRING) *ret = NULL;
-    const X509_NAME_ENTRY *ne;
+    X509_NAME_ENTRY *ne;
     const ASN1_IA5STRING *email;
     GENERAL_NAME *gen;
     int i = -1;
@@ -866,8 +866,8 @@ static int do_check_string(const ASN1_STRING *a, int cmp_type, equal_fn equal,
     return rv;
 }
 
-static int do_x509_check(const X509 *x, const char *chk, size_t chklen,
-    unsigned int flags, int check_type, int othername_nid, char **peername)
+static int do_x509_check(X509 *x, const char *chk, size_t chklen,
+    unsigned int flags, int check_type, char **peername)
 {
     GENERAL_NAMES *gens = NULL;
     const X509_NAME *name = NULL;
@@ -913,8 +913,6 @@ static int do_x509_check(const X509 *x, const char *chk, size_t chklen,
             default:
                 continue;
             case GEN_OTHERNAME:
-                if (check_type != GEN_OTHERNAME)
-                    continue;
                 switch (OBJ_obj2nid(gen->d.otherName->type_id)) {
                 default:
                     continue;
@@ -944,7 +942,7 @@ static int do_x509_check(const X509 *x, const char *chk, size_t chklen,
                      * choose to turn it off, doing so is at this time a best
                      * practice.
                      */
-                    if (othername_nid != NID_id_on_SmtpUTF8Mailbox
+                    if (check_type != GEN_EMAIL
                         || gen->d.otherName->value->type != V_ASN1_UTF8STRING)
                         continue;
                     alt_type = 0;
@@ -1001,7 +999,7 @@ static int do_x509_check(const X509 *x, const char *chk, size_t chklen,
     return 0;
 }
 
-int ossl_x509_check_host(const X509 *x, const char *chk, size_t chklen,
+int X509_check_host(X509 *x, const char *chk, size_t chklen,
     unsigned int flags, char **peername)
 {
     if (chk == NULL)
@@ -1017,41 +1015,10 @@ int ossl_x509_check_host(const X509 *x, const char *chk, size_t chklen,
         return -2;
     if (chklen > 1 && chk[chklen - 1] == '\0')
         --chklen;
-    return do_x509_check(x, chk, chklen, flags, GEN_DNS, 0, peername);
+    return do_x509_check(x, chk, chklen, flags, GEN_DNS, peername);
 }
 
-#if !defined(OPENSSL_NO_DEPRECATED_4_1)
-int X509_check_host(const X509 *x, const char *chk, size_t chklen,
-    unsigned int flags, char **peername)
-{
-    return ossl_x509_check_host(x, chk, chklen, flags, peername);
-}
-#endif /* !defined(OPENSSL_NO_DEPRECATED_4_1) */
-
-int ossl_x509_check_rfc822(X509 *x, const char *chk, size_t chklen,
-    unsigned int flags)
-{
-    return do_x509_check(x, chk, chklen, flags, GEN_EMAIL, 0, NULL) == 1;
-}
-
-int ossl_x509_check_smtputf8(X509 *x, const char *chk, size_t chklen,
-    unsigned int flags)
-{
-    return do_x509_check(x, chk, chklen, flags, GEN_OTHERNAME,
-               NID_id_on_SmtpUTF8Mailbox, NULL)
-        == 1;
-}
-
-int ossl_x509_check_ip(const X509 *x, const unsigned char *chk, size_t chklen,
-    unsigned int flags)
-{
-    if (chk == NULL)
-        return -2;
-    return do_x509_check(x, (char *)chk, chklen, flags, GEN_IPADD, 0, NULL);
-}
-
-#if !defined(OPENSSL_NO_DEPRECATED_4_1)
-int X509_check_email(const X509 *x, const char *chk, size_t chklen,
+int X509_check_email(X509 *x, const char *chk, size_t chklen,
     unsigned int flags)
 {
     if (chk == NULL)
@@ -1067,23 +1034,18 @@ int X509_check_email(const X509 *x, const char *chk, size_t chklen,
         return -2;
     if (chklen > 1 && chk[chklen - 1] == '\0')
         --chklen;
-    /*
-     * As this is public API, historically it has supported checking
-     * whatever is supplied against both RFC822 and SMTPUTF8.
-     */
-    if (do_x509_check(x, chk, chklen, flags, GEN_EMAIL, 0, NULL) == 1)
-        return 1;
-    return do_x509_check(x, chk, chklen, flags, GEN_OTHERNAME,
-        NID_id_on_SmtpUTF8Mailbox, NULL);
+    return do_x509_check(x, chk, chklen, flags, GEN_EMAIL, NULL);
 }
 
-int X509_check_ip(const X509 *x, const unsigned char *chk, size_t chklen,
+int X509_check_ip(X509 *x, const unsigned char *chk, size_t chklen,
     unsigned int flags)
 {
-    return ossl_x509_check_ip(x, chk, chklen, flags);
+    if (chk == NULL)
+        return -2;
+    return do_x509_check(x, (char *)chk, chklen, flags, GEN_IPADD, NULL);
 }
 
-int X509_check_ip_asc(const X509 *x, const char *ipasc, unsigned int flags)
+int X509_check_ip_asc(X509 *x, const char *ipasc, unsigned int flags)
 {
     unsigned char ipout[16];
     size_t iplen;
@@ -1093,11 +1055,10 @@ int X509_check_ip_asc(const X509 *x, const char *ipasc, unsigned int flags)
     iplen = (size_t)ossl_a2i_ipadd(ipout, ipasc);
     if (iplen == 0)
         return -2;
-    return do_x509_check(x, (char *)ipout, iplen, flags, GEN_IPADD, 0, NULL);
+    return do_x509_check(x, (char *)ipout, iplen, flags, GEN_IPADD, NULL);
 }
-#endif /* !defined(OPENSSL_NO_DEPRECATED_4_1) */
 
-char *ossl_ipaddr_to_asc(const unsigned char *p, int len)
+char *ossl_ipaddr_to_asc(unsigned char *p, int len)
 {
     /*
      * 40 is enough space for the longest IPv6 address + nul terminator byte
@@ -1160,16 +1121,15 @@ ASN1_OCTET_STRING *a2i_IPADDRESS_NC(const char *ipasc)
     ASN1_OCTET_STRING *ret = NULL;
     unsigned char ipout[32];
     char *iptmp = NULL, *p;
-    const char *slash;
     int iplen1, iplen2;
 
-    slash = strchr(ipasc, '/');
-    if (slash == NULL)
+    p = strchr(ipasc, '/');
+    if (p == NULL)
         return NULL;
     iptmp = OPENSSL_strdup(ipasc);
     if (iptmp == NULL)
         return NULL;
-    p = iptmp + (slash - ipasc);
+    p = iptmp + (p - ipasc);
     *p++ = 0;
 
     iplen1 = ossl_a2i_ipadd(ipout, iptmp);
diff --git a/crypto/x509/x509_att.c b/crypto/x509/x509_att.c
index e08e490274..a0fb445472 100644
--- a/crypto/x509/x509_att.c
+++ b/crypto/x509/x509_att.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -238,11 +238,11 @@ STACK_OF(X509_ATTRIBUTE) *X509at_add1_attr_by_txt(STACK_OF(X509_ATTRIBUTE)
     return ret;
 }
 
-const void *X509at_get0_data_by_OBJ(const STACK_OF(X509_ATTRIBUTE) *x,
+void *X509at_get0_data_by_OBJ(const STACK_OF(X509_ATTRIBUTE) *x,
     const ASN1_OBJECT *obj, int lastpos, int type)
 {
     int i = X509at_get_attr_by_OBJ(x, obj, lastpos);
-    const X509_ATTRIBUTE *at;
+    X509_ATTRIBUTE *at;
 
     if (i == -1)
         return NULL;
@@ -365,7 +365,7 @@ int X509_ATTRIBUTE_set1_data(X509_ATTRIBUTE *attr, int attrtype,
         atype = stmp->type;
     } else if (len != -1) {
         if ((stmp = ASN1_STRING_type_new(attrtype)) == NULL
-            || !ASN1_STRING_set_data(stmp, data, len)) {
+            || !ASN1_STRING_set(stmp, data, len)) {
             ERR_raise(ERR_LIB_X509, ERR_R_ASN1_LIB);
             goto err;
         }
@@ -411,7 +411,7 @@ int X509_ATTRIBUTE_count(const X509_ATTRIBUTE *attr)
     return sk_ASN1_TYPE_num(attr->set);
 }
 
-const ASN1_OBJECT *X509_ATTRIBUTE_get0_object(const X509_ATTRIBUTE *attr)
+ASN1_OBJECT *X509_ATTRIBUTE_get0_object(X509_ATTRIBUTE *attr)
 {
     if (attr == NULL) {
         ERR_raise(ERR_LIB_X509, ERR_R_PASSED_NULL_PARAMETER);
@@ -420,10 +420,10 @@ const ASN1_OBJECT *X509_ATTRIBUTE_get0_object(const X509_ATTRIBUTE *attr)
     return attr->object;
 }
 
-const void *X509_ATTRIBUTE_get0_data(const X509_ATTRIBUTE *attr, int idx,
+void *X509_ATTRIBUTE_get0_data(X509_ATTRIBUTE *attr, int idx,
     int atrtype, void *data)
 {
-    const ASN1_TYPE *ttmp = X509_ATTRIBUTE_get0_type(attr, idx);
+    ASN1_TYPE *ttmp = X509_ATTRIBUTE_get0_type(attr, idx);
 
     if (ttmp == NULL)
         return NULL;
@@ -436,7 +436,7 @@ const void *X509_ATTRIBUTE_get0_data(const X509_ATTRIBUTE *attr, int idx,
     return ttmp->value.ptr;
 }
 
-const ASN1_TYPE *X509_ATTRIBUTE_get0_type(const X509_ATTRIBUTE *attr, int idx)
+ASN1_TYPE *X509_ATTRIBUTE_get0_type(X509_ATTRIBUTE *attr, int idx)
 {
     if (attr == NULL) {
         ERR_raise(ERR_LIB_X509, ERR_R_PASSED_NULL_PARAMETER);
diff --git a/crypto/x509/x509_cmp.c b/crypto/x509/x509_cmp.c
index 6cf674ea85..6d9848d234 100644
--- a/crypto/x509/x509_cmp.c
+++ b/crypto/x509/x509_cmp.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -34,7 +34,7 @@ int X509_issuer_and_serial_cmp(const X509 *a, const X509 *b)
 }
 
 #ifndef OPENSSL_NO_MD5
-unsigned long X509_issuer_and_serial_hash(const X509 *a)
+unsigned long X509_issuer_and_serial_hash(X509 *a)
 {
     unsigned long ret = 0;
     EVP_MD_CTX *ctx = EVP_MD_CTX_new();
@@ -97,24 +97,24 @@ int X509_CRL_match(const X509_CRL *a, const X509_CRL *b)
     return rv < 0 ? -1 : rv > 0;
 }
 
-const X509_NAME *X509_get_issuer_name(const X509 *a)
+X509_NAME *X509_get_issuer_name(const X509 *a)
 {
     return a->cert_info.issuer;
 }
 
-unsigned long X509_issuer_name_hash(const X509 *x)
+unsigned long X509_issuer_name_hash(X509 *x)
 {
     return X509_NAME_hash_ex(x->cert_info.issuer, NULL, NULL, NULL);
 }
 
 #ifndef OPENSSL_NO_MD5
-unsigned long X509_issuer_name_hash_old(const X509 *x)
+unsigned long X509_issuer_name_hash_old(X509 *x)
 {
     return X509_NAME_hash_old(x->cert_info.issuer);
 }
 #endif
 
-const X509_NAME *X509_get_subject_name(const X509 *a)
+X509_NAME *X509_get_subject_name(const X509 *a)
 {
     return a->cert_info.subject;
 }
@@ -129,13 +129,13 @@ const ASN1_INTEGER *X509_get0_serialNumber(const X509 *a)
     return &a->cert_info.serialNumber;
 }
 
-unsigned long X509_subject_name_hash(const X509 *x)
+unsigned long X509_subject_name_hash(X509 *x)
 {
     return X509_NAME_hash_ex(x->cert_info.subject, NULL, NULL, NULL);
 }
 
 #ifndef OPENSSL_NO_MD5
-unsigned long X509_subject_name_hash_old(const X509 *x)
+unsigned long X509_subject_name_hash_old(X509 *x)
 {
     return X509_NAME_hash_old(x->cert_info.subject);
 }
@@ -178,7 +178,7 @@ int X509_cmp(const X509 *a, const X509 *b)
     return rv < 0 ? -1 : rv > 0;
 }
 
-int ossl_x509_add_cert_new(STACK_OF(X509) **p_sk, const X509 *cert, int flags)
+int ossl_x509_add_cert_new(STACK_OF(X509) **p_sk, X509 *cert, int flags)
 {
     if (*p_sk == NULL && (*p_sk = sk_X509_new_null()) == NULL) {
         ERR_raise(ERR_LIB_X509, ERR_R_CRYPTO_LIB);
@@ -187,7 +187,7 @@ int ossl_x509_add_cert_new(STACK_OF(X509) **p_sk, const X509 *cert, int flags)
     return X509_add_cert(*p_sk, cert, flags);
 }
 
-int X509_add_cert(STACK_OF(X509) *sk, const X509 *cert, int flags)
+int X509_add_cert(STACK_OF(X509) *sk, X509 *cert, int flags)
 {
     if (sk == NULL) {
         ERR_raise(ERR_LIB_X509, ERR_R_PASSED_NULL_PARAMETER);
@@ -213,23 +213,19 @@ int X509_add_cert(STACK_OF(X509) *sk, const X509 *cert, int flags)
         if (ret != 0)
             return ret > 0 ? 1 : 0;
     }
-    /*
-     * Note: We're technically mutating the cert here, but its just to up
-     * the reference count, so that should be safe, so cast away
-     */
-    if ((flags & X509_ADD_FLAG_UP_REF) != 0 && !X509_up_ref((X509 *)cert))
+    if ((flags & X509_ADD_FLAG_UP_REF) != 0 && !X509_up_ref(cert))
         return 0;
-    if (!sk_X509_insert(sk, (X509 *)cert,
+    if (!sk_X509_insert(sk, cert,
             (flags & X509_ADD_FLAG_PREPEND) != 0 ? 0 : -1)) {
         if ((flags & X509_ADD_FLAG_UP_REF) != 0)
-            X509_free((X509 *)cert);
+            X509_free(cert);
         ERR_raise(ERR_LIB_X509, ERR_R_CRYPTO_LIB);
         return 0;
     }
     return 1;
 }
 
-int X509_add_certs(STACK_OF(X509) *sk, const STACK_OF(X509) *certs, int flags)
+int X509_add_certs(STACK_OF(X509) *sk, STACK_OF(X509) *certs, int flags)
 /* compiler would allow 'const' for the certs, yet they may get up-ref'ed */
 {
     if (sk == NULL) {
@@ -239,7 +235,8 @@ int X509_add_certs(STACK_OF(X509) *sk, const STACK_OF(X509) *certs, int flags)
     return ossl_x509_add_certs_new(&sk, certs, flags);
 }
 
-int ossl_x509_add_certs_new(STACK_OF(X509) **p_sk, const STACK_OF(X509) *certs, int flags)
+int ossl_x509_add_certs_new(STACK_OF(X509) **p_sk, STACK_OF(X509) *certs,
+    int flags)
 /* compiler would allow 'const' for the certs, yet they may get up-ref'ed */
 {
     int n = sk_X509_num(certs /* may be NULL */);
@@ -345,7 +342,7 @@ end:
 #endif
 
 /* Search a stack of X509 for a match */
-X509 *X509_find_by_issuer_and_serial(const STACK_OF(X509) *sk, const X509_NAME *name,
+X509 *X509_find_by_issuer_and_serial(STACK_OF(X509) *sk, const X509_NAME *name,
     const ASN1_INTEGER *serial)
 {
     int i;
@@ -365,7 +362,7 @@ X509 *X509_find_by_issuer_and_serial(const STACK_OF(X509) *sk, const X509_NAME *
     return NULL;
 }
 
-X509 *X509_find_by_subject(const STACK_OF(X509) *sk, const X509_NAME *name)
+X509 *X509_find_by_subject(STACK_OF(X509) *sk, const X509_NAME *name)
 {
     X509 *x509;
     int i;
@@ -385,7 +382,7 @@ EVP_PKEY *X509_get0_pubkey(const X509 *x)
     return X509_PUBKEY_get0(x->cert_info.key);
 }
 
-EVP_PKEY *X509_get_pubkey(const X509 *x)
+EVP_PKEY *X509_get_pubkey(X509 *x)
 {
     if (x == NULL)
         return NULL;
@@ -470,7 +467,7 @@ static int check_suite_b(EVP_PKEY *pkey, int sign_nid, unsigned long *pflags)
     return X509_V_OK;
 }
 
-int X509_chain_check_suiteb(int *perror_depth, const X509 *x, STACK_OF(X509) *chain,
+int X509_chain_check_suiteb(int *perror_depth, X509 *x, STACK_OF(X509) *chain,
     unsigned long flags)
 {
     int rv, i, sign_nid;
@@ -556,7 +553,7 @@ int X509_CRL_check_suiteb(X509_CRL *crl, EVP_PKEY *pk, unsigned long flags)
 }
 
 #else
-int X509_chain_check_suiteb(int *perror_depth, const X509 *x, STACK_OF(X509) *chain,
+int X509_chain_check_suiteb(int *perror_depth, X509 *x, STACK_OF(X509) *chain,
     unsigned long flags)
 {
     return 0;
diff --git a/crypto/x509/x509_def.c b/crypto/x509/x509_def.c
index 797f687d13..5a6ecaf476 100644
--- a/crypto/x509/x509_def.c
+++ b/crypto/x509/x509_def.c
@@ -30,7 +30,7 @@ static char *x509_cert_fileptr = NULL;
 
 static void get_windows_default_path(char *pathname, const char *suffix)
 {
-    const char *ossldir;
+    char *ossldir;
 
     ossldir = ossl_get_openssldir();
 
diff --git a/crypto/x509/x509_err.c b/crypto/x509/x509_err.c
index b78f210fd4..3d6e8768f8 100644
--- a/crypto/x509/x509_err.c
+++ b/crypto/x509/x509_err.c
@@ -1,6 +1,6 @@
 /*
  * Generated by util/mkerr.pl DO NOT EDIT
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -26,8 +26,6 @@ static const ERR_STRING_DATA X509_str_reasons[] = {
     { ERR_PACK(ERR_LIB_X509, 0, X509_R_CERT_ALREADY_IN_HASH_TABLE),
         "cert already in hash table" },
     { ERR_PACK(ERR_LIB_X509, 0, X509_R_CRL_ALREADY_DELTA), "crl already delta" },
-    { ERR_PACK(ERR_LIB_X509, 0, X509_R_CRL_SIGNATURE_ALGORITHM_MISMATCH),
-        "crl signature algorithm mismatch" },
     { ERR_PACK(ERR_LIB_X509, 0, X509_R_CRL_VERIFY_FAILURE),
         "crl verify failure" },
     { ERR_PACK(ERR_LIB_X509, 0, X509_R_DUPLICATE_ATTRIBUTE),
@@ -41,7 +39,6 @@ static const ERR_STRING_DATA X509_str_reasons[] = {
         "invalid attributes" },
     { ERR_PACK(ERR_LIB_X509, 0, X509_R_INVALID_DIRECTORY), "invalid directory" },
     { ERR_PACK(ERR_LIB_X509, 0, X509_R_INVALID_DISTPOINT), "invalid distpoint" },
-    { ERR_PACK(ERR_LIB_X509, 0, X509_R_INVALID_EXTENSION), "invalid extension" },
     { ERR_PACK(ERR_LIB_X509, 0, X509_R_INVALID_FIELD_NAME),
         "invalid field name" },
     { ERR_PACK(ERR_LIB_X509, 0, X509_R_INVALID_TRUST), "invalid trust" },
diff --git a/crypto/x509/x509_ext.c b/crypto/x509/x509_ext.c
index 8c9c5d96bc..88315e6d5c 100644
--- a/crypto/x509/x509_ext.c
+++ b/crypto/x509/x509_ext.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2017 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -37,18 +37,26 @@ int X509_CRL_get_ext_by_critical(const X509_CRL *x, int crit, int lastpos)
     return X509v3_get_ext_by_critical(x->crl.extensions, crit, lastpos);
 }
 
-const X509_EXTENSION *X509_CRL_get_ext(const X509_CRL *x, int loc)
+X509_EXTENSION *X509_CRL_get_ext(const X509_CRL *x, int loc)
 {
     return X509v3_get_ext(x->crl.extensions, loc);
 }
 
+static X509_EXTENSION *delete_ext(STACK_OF(X509_EXTENSION) **sk, int loc)
+{
+    X509_EXTENSION *ret = X509v3_delete_ext(*sk, loc);
+
+    /* Empty extension lists are omitted. */
+    if (*sk != NULL && sk_X509_EXTENSION_num(*sk) == 0) {
+        sk_X509_EXTENSION_pop_free(*sk, X509_EXTENSION_free);
+        *sk = NULL;
+    }
+    return ret;
+}
+
 X509_EXTENSION *X509_CRL_delete_ext(X509_CRL *x, int loc)
 {
-    X509_EXTENSION *ret = X509v3_delete_extension(&x->crl.extensions, loc);
-
-    if (ret != NULL)
-        x->crl.enc.modified = 1;
-    return ret;
+    return delete_ext(&x->crl.extensions, loc);
 }
 
 void *X509_CRL_get_ext_d2i(const X509_CRL *x, int nid, int *crit, int *idx)
@@ -62,7 +70,7 @@ int X509_CRL_add1_ext_i2d(X509_CRL *x, int nid, void *value, int crit,
     return X509V3_add1_i2d(&x->crl.extensions, nid, value, crit, flags);
 }
 
-int X509_CRL_add_ext(X509_CRL *x, const X509_EXTENSION *ex, int loc)
+int X509_CRL_add_ext(X509_CRL *x, X509_EXTENSION *ex, int loc)
 {
     return (X509v3_add_ext(&(x->crl.extensions), ex, loc) != NULL);
 }
@@ -84,43 +92,22 @@ int X509_get_ext_by_OBJ(const X509 *x, const ASN1_OBJECT *obj, int lastpos)
 
 int X509_get_ext_by_critical(const X509 *x, int crit, int lastpos)
 {
-    return X509v3_get_ext_by_critical(x->cert_info.extensions, crit, lastpos);
+    return (X509v3_get_ext_by_critical(x->cert_info.extensions, crit, lastpos));
 }
 
-const X509_EXTENSION *X509_get_ext(const X509 *x, int loc)
+X509_EXTENSION *X509_get_ext(const X509 *x, int loc)
 {
     return X509v3_get_ext(x->cert_info.extensions, loc);
 }
 
 X509_EXTENSION *X509_delete_ext(X509 *x, int loc)
 {
-    X509_EXTENSION *ret;
-
-    ret = X509v3_delete_extension(&x->cert_info.extensions, loc);
-    if (ret != NULL)
-        x->cert_info.enc.modified = 1;
-    return ret;
+    return delete_ext(&x->cert_info.extensions, loc);
 }
 
-int X509_add_ext(X509 *x, const X509_EXTENSION *ex, int loc)
+int X509_add_ext(X509 *x, X509_EXTENSION *ex, int loc)
 {
-    STACK_OF(X509_EXTENSION) **exts = &x->cert_info.extensions;
-
-    /* x->cert_info.extensions might initially be NULL */
-    if (X509v3_add_ext(exts, ex, loc) == NULL)
-        return 0;
-    /*
-     * An ignored "empty" SKID or AKID extension will appear to be successfully
-     * added, even though nothing is pushed onto the resulting stack.  However,
-     * if the stack was initially NULL or empty, it will now be non-NULL, but
-     * empty, deallocate and make it NULL in that case.
-     */
-    if (sk_X509_EXTENSION_num(*exts) == 0) {
-        sk_X509_EXTENSION_free(*exts);
-        *exts = NULL;
-    }
-    x->cert_info.enc.modified = 1;
-    return 1;
+    return (X509v3_add_ext(&(x->cert_info.extensions), ex, loc) != NULL);
 }
 
 void *X509_get_ext_d2i(const X509 *x, int nid, int *crit, int *idx)
@@ -131,11 +118,6 @@ void *X509_get_ext_d2i(const X509 *x, int nid, int *crit, int *idx)
 int X509_add1_ext_i2d(X509 *x, int nid, void *value, int crit,
     unsigned long flags)
 {
-    /*
-     * Assume modified, sadly the underlying function does not tell us whether
-     * changes were made, or not.
-     */
-    x->cert_info.enc.modified = 1;
     return X509V3_add1_i2d(&x->cert_info.extensions, nid, value, crit,
         flags);
 }
@@ -161,14 +143,14 @@ int X509_REVOKED_get_ext_by_critical(const X509_REVOKED *x, int crit, int lastpo
     return X509v3_get_ext_by_critical(x->extensions, crit, lastpos);
 }
 
-const X509_EXTENSION *X509_REVOKED_get_ext(const X509_REVOKED *x, int loc)
+X509_EXTENSION *X509_REVOKED_get_ext(const X509_REVOKED *x, int loc)
 {
     return X509v3_get_ext(x->extensions, loc);
 }
 
 X509_EXTENSION *X509_REVOKED_delete_ext(X509_REVOKED *x, int loc)
 {
-    return X509v3_delete_extension(&x->extensions, loc);
+    return delete_ext(&x->extensions, loc);
 }
 
 int X509_REVOKED_add_ext(X509_REVOKED *x, X509_EXTENSION *ex, int loc)
diff --git a/crypto/x509/x509_local.h b/crypto/x509/x509_local.h
index a3433336ca..9eef700436 100644
--- a/crypto/x509/x509_local.h
+++ b/crypto/x509/x509_local.h
@@ -1,41 +1,24 @@
 /*
- * Copyright 2014-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2014-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
  * in the file LICENSE in the source distribution or at
  * https://www.openssl.org/source/license.html
  */
-#if !defined(OSSL_LIBCRYPTO_X509_X509_LOCAL_H)
-#define OSSL_LIBCRYPTO_X509_X509_LOCAL_H
-
-#include 
-#include 
 
 #include "internal/refcount.h"
 #include "internal/hashtable.h"
 
-#include 
-
 #define X509V3_conf_add_error_name_value(val) \
     ERR_add_error_data(4, "name=", (val)->name, ", value=", (val)->value)
 
-/*
- * Really all I want is CRYPTO_BUFFER from BoringSSL, but let's just do this
- * for now.
- */
-typedef struct ossl_x509_buffer_st {
-    const uint8_t *data;
-    size_t len;
-} X509_BUFFER;
-
-DEFINE_STACK_OF(X509_BUFFER)
-
 /*
  * This structure holds all parameters associated with a verify operation by
  * including an X509_VERIFY_PARAM structure in related structures the
  * parameters used can be customized
  */
+
 struct X509_VERIFY_PARAM_st {
     char *name;
     int64_t check_time; /* Time to use */
@@ -47,16 +30,13 @@ struct X509_VERIFY_PARAM_st {
     int auth_level; /* Security level for chain verification */
     STACK_OF(ASN1_OBJECT) *policies; /* Permissible policies */
     /* Peer identity details */
-    STACK_OF(X509_BUFFER) *hosts; /* Set of acceptable names */
-    int (*validate_host)(const char *name, size_t len);
-    STACK_OF(X509_BUFFER) *ips; /* Set of acceptable ip addresses */
-    int (*validate_ip)(const uint8_t *name, size_t len);
-    STACK_OF(X509_BUFFER) *rfc822s; /* Set of acceptable RFC 822 names */
-    int (*validate_rfc822)(const char *name, size_t len);
-    STACK_OF(X509_BUFFER) *smtputf8s; /* Set of acceptable SMTP Utf8 names */
-    int (*validate_smtputf8)(const char *name, size_t len);
+    STACK_OF(OPENSSL_STRING) *hosts; /* Set of acceptable names */
     unsigned int hostflags; /* Flags to control matching features */
     char *peername; /* Matching hostname in peer certificate */
+    char *email; /* If not NULL email address to match */
+    size_t emaillen;
+    unsigned char *ip; /* If not NULL IP address to match */
+    size_t iplen; /* Length of IP address */
 };
 
 /* No error callback if depth < 0 */
@@ -156,9 +136,9 @@ struct x509_store_st {
     /* error callback */
     int (*verify_cb)(int ok, X509_STORE_CTX *ctx);
     /* get issuers cert from ctx */
-    X509_STORE_CTX_get_issuer_fn get_issuer;
+    int (*get_issuer)(X509 **issuer, X509_STORE_CTX *ctx, X509 *x);
     /* check issued */
-    X509_STORE_CTX_check_issued_fn check_issued;
+    int (*check_issued)(X509_STORE_CTX *ctx, X509 *x, X509 *issuer);
     /* Check revocation status of chain */
     int (*check_revocation)(X509_STORE_CTX *ctx);
     /* retrieve CRL */
@@ -169,8 +149,9 @@ struct x509_store_st {
     int (*cert_crl)(X509_STORE_CTX *ctx, X509_CRL *crl, X509 *x);
     /* Check policy status of the chain */
     int (*check_policy)(X509_STORE_CTX *ctx);
-    STACK_OF(X509) *(*lookup_certs)(const X509_STORE_CTX *ctx,
+    STACK_OF(X509) *(*lookup_certs)(X509_STORE_CTX *ctx,
         const X509_NAME *nm);
+    /* cannot constify 'ctx' param due to lookup_certs_sk() in x509_vfy.c */
     STACK_OF(X509_CRL) *(*lookup_crls)(const X509_STORE_CTX *ctx,
         const X509_NAME *nm);
     int (*cleanup)(X509_STORE_CTX *ctx);
@@ -186,17 +167,10 @@ DEFINE_STACK_OF(BY_DIR_ENTRY)
 typedef STACK_OF(X509_NAME_ENTRY) STACK_OF_X509_NAME_ENTRY;
 DEFINE_STACK_OF(STACK_OF_X509_NAME_ENTRY)
 
-int ossl_ignored_x509_extension(const X509_EXTENSION *ex, int flags);
-int ossl_x509_likely_issued(const X509 *issuer, const X509 *subject);
+int ossl_x509_likely_issued(X509 *issuer, X509 *subject);
 int ossl_x509_signing_allowed(const X509 *issuer, const X509 *subject);
 int ossl_x509_store_ctx_get_by_subject(const X509_STORE_CTX *ctx, X509_LOOKUP_TYPE type,
     const X509_NAME *name, X509_OBJECT *ret);
 __owur int ossl_x509_store_read_lock(X509_STORE *xs);
 STACK_OF(X509_OBJECT) *ossl_x509_store_ht_get_by_name(const X509_STORE *store,
     const X509_NAME *xn);
-int ossl_x509_check_rfc822(X509 *x, const char *chk, size_t chklen,
-    unsigned int flags);
-int ossl_x509_check_smtputf8(X509 *x, const char *chk, size_t chklen,
-    unsigned int flags);
-
-#endif /* !defined(OSSL_LIBCRYPTO_X509_X509_LOCAL_H) */
diff --git a/crypto/x509/x509_lu.c b/crypto/x509/x509_lu.c
index 5be50c2195..1167fcf1fc 100644
--- a/crypto/x509/x509_lu.c
+++ b/crypto/x509/x509_lu.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -287,7 +287,7 @@ int X509_STORE_up_ref(X509_STORE *xs)
 {
     int i;
 
-    if (!CRYPTO_UP_REF(&xs->references, &i))
+    if (CRYPTO_UP_REF(&xs->references, &i) <= 0)
         return 0;
 
     REF_PRINT_COUNT("X509_STORE", i, xs);
@@ -494,16 +494,29 @@ int X509_STORE_CTX_get_by_subject(const X509_STORE_CTX *ctx,
 {
     return ossl_x509_store_ctx_get_by_subject(ctx, type, name, ret) > 0;
 }
-static int x509_store_add_obj(X509_STORE *store, X509_OBJECT *obj)
-{
-    const X509_NAME *xn;
-    STACK_OF(X509_OBJECT) *objs = NULL;
-    int ret = 0, added = 0;
 
-    if (obj->type == X509_LU_CRL)
+static int x509_store_add(X509_STORE *store, void *x, int crl)
+{
+    X509_OBJECT *obj;
+    int ret = 0, added = 0;
+    X509_NAME *xn;
+    STACK_OF(X509_OBJECT) *objs = NULL;
+
+    if (x == NULL)
+        return 0;
+    obj = X509_OBJECT_new();
+    if (obj == NULL)
+        return 0;
+
+    if (crl) {
+        obj->type = X509_LU_CRL;
+        obj->data.crl = (X509_CRL *)x;
         xn = obj->data.crl->crl.issuer;
-    else
+    } else {
+        obj->type = X509_LU_X509;
+        obj->data.x509 = (X509 *)x;
         xn = obj->data.x509->cert_info.subject;
+    }
 
     if (xn == NULL) {
         obj->type = X509_LU_NONE;
@@ -546,45 +559,9 @@ static int x509_store_add_obj(X509_STORE *store, X509_OBJECT *obj)
     return ret;
 }
 
-static int x509_store_add_x509(X509_STORE *store, const X509 *x)
+int X509_STORE_add_cert(X509_STORE *xs, X509 *x)
 {
-    X509_OBJECT *obj;
-
-    if (x == NULL)
-        return 0;
-    obj = X509_OBJECT_new();
-    if (obj == NULL)
-        return 0;
-
-    obj->type = X509_LU_X509;
-    /*
-     * XXX Casts away const, get rid of this once we can have the x509
-     * member of OBJECT be const.
-     */
-    obj->data.x509 = (X509 *)x;
-
-    return x509_store_add_obj(store, obj);
-}
-
-static int x509_store_add_crl(X509_STORE *store, X509_CRL *crl)
-{
-    X509_OBJECT *obj;
-
-    if (crl == NULL)
-        return 0;
-    obj = X509_OBJECT_new();
-    if (obj == NULL)
-        return 0;
-
-    obj->type = X509_LU_CRL;
-    obj->data.crl = crl;
-
-    return x509_store_add_obj(store, obj);
-}
-
-int X509_STORE_add_cert(X509_STORE *xs, const X509 *x)
-{
-    if (!x509_store_add_x509(xs, x)) {
+    if (!x509_store_add(xs, x, 0)) {
         ERR_raise(ERR_LIB_X509, ERR_R_X509_LIB);
         return 0;
     }
@@ -593,7 +570,7 @@ int X509_STORE_add_cert(X509_STORE *xs, const X509 *x)
 
 int X509_STORE_add_crl(X509_STORE *xs, X509_CRL *x)
 {
-    if (!x509_store_add_crl(xs, x)) {
+    if (!x509_store_add(xs, x, 1)) {
         ERR_raise(ERR_LIB_X509, ERR_R_X509_LIB);
         return 0;
     }
@@ -741,12 +718,7 @@ static X509_OBJECT *x509_object_dup(const X509_OBJECT *obj)
 
     ret->type = obj->type;
     ret->data = obj->data;
-
-    if (!X509_OBJECT_up_ref_count(ret)) {
-        OPENSSL_free(ret);
-        return NULL;
-    }
-
+    X509_OBJECT_up_ref_count(ret);
     return ret;
 }
 
@@ -769,7 +741,6 @@ static int obj_ht_foreach_object(HT_VALUE *v, void *arg)
     return 1;
 
 err:
-    X509_OBJECT_free(dup);
     sk_X509_OBJECT_pop_free(*sk, X509_OBJECT_free);
     *sk = NULL;
 
@@ -858,7 +829,7 @@ out_free:
  * Collect from |ctx->store| all certs with subject matching |nm|.
  * Returns NULL on internal/fatal error, empty stack if not found.
  */
-STACK_OF(X509) *X509_STORE_CTX_get1_certs(const X509_STORE_CTX *ctx,
+STACK_OF(X509) *X509_STORE_CTX_get1_certs(X509_STORE_CTX *ctx,
     const X509_NAME *nm)
 {
     int i, idx = -1, cnt = 0;
diff --git a/crypto/x509/x509_meth.c b/crypto/x509/x509_meth.c
index 96de9b9086..e7b228a33f 100644
--- a/crypto/x509/x509_meth.c
+++ b/crypto/x509/x509_meth.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2018-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -17,8 +17,6 @@
 #include 
 #include "x509_local.h"
 
-#include 
-
 X509_LOOKUP_METHOD *X509_LOOKUP_meth_new(const char *name)
 {
     X509_LOOKUP_METHOD *method = OPENSSL_zalloc(sizeof(X509_LOOKUP_METHOD));
diff --git a/crypto/x509/x509_r2x.c b/crypto/x509/x509_r2x.c
index 714ac7222e..b373a2caa4 100644
--- a/crypto/x509/x509_r2x.c
+++ b/crypto/x509/x509_r2x.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2020 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -17,7 +17,7 @@
 #include 
 #include 
 
-X509 *X509_REQ_to_X509(const X509_REQ *r, int days, EVP_PKEY *pkey)
+X509 *X509_REQ_to_X509(X509_REQ *r, int days, EVP_PKEY *pkey)
 {
     X509 *ret = NULL;
     X509_CINF *xi = NULL;
diff --git a/crypto/x509/x509_req.c b/crypto/x509/x509_req.c
index 90f9b641f7..014c7aa361 100644
--- a/crypto/x509/x509_req.c
+++ b/crypto/x509/x509_req.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -19,7 +19,7 @@
 #include 
 #include 
 
-X509_REQ *X509_to_X509_REQ(const X509 *x, EVP_PKEY *pkey, const EVP_MD *md)
+X509_REQ *X509_to_X509_REQ(X509 *x, EVP_PKEY *pkey, const EVP_MD *md)
 {
     X509_REQ *ret;
     X509_REQ_INFO *ri;
@@ -117,11 +117,11 @@ void X509_REQ_set_extension_nids(int *nids)
     ext_nids = nids;
 }
 
-STACK_OF(X509_EXTENSION) *
-ossl_x509_req_get1_extensions_by_nid(const X509_REQ *req, int nid)
+static STACK_OF(X509_EXTENSION) *get_extensions_by_nid(const X509_REQ *req,
+    int nid)
 {
     X509_ATTRIBUTE *attr;
-    const ASN1_TYPE *ext = NULL;
+    ASN1_TYPE *ext = NULL;
     const unsigned char *p;
     int idx = X509_REQ_get_attr_by_NID(req, nid, -1);
 
@@ -147,7 +147,7 @@ STACK_OF(X509_EXTENSION) *X509_REQ_get_extensions(const X509_REQ *req)
     if (req == NULL || ext_nids == NULL)
         return NULL;
     for (pnid = ext_nids; *pnid != NID_undef; pnid++) {
-        exts = ossl_x509_req_get1_extensions_by_nid(req, *pnid);
+        exts = get_extensions_by_nid(req, *pnid);
         if (exts == NULL)
             return NULL;
         if (sk_X509_EXTENSION_num(exts) > 0)
@@ -176,7 +176,7 @@ int X509_REQ_add_extensions_nid(X509_REQ *req,
 
     loc = X509at_get_attr_by_NID(req->req_info.attributes, nid, -1);
     if (loc != -1) {
-        if ((mod_exts = ossl_x509_req_get1_extensions_by_nid(req, nid)) == NULL)
+        if ((mod_exts = get_extensions_by_nid(req, nid)) == NULL)
             return 0;
         if (X509v3_add_extensions(&mod_exts, exts) == NULL)
             goto end;
@@ -308,7 +308,7 @@ long X509_REQ_get_version(const X509_REQ *req)
     return ASN1_INTEGER_get(req->req_info.version);
 }
 
-const X509_NAME *X509_REQ_get_subject_name(const X509_REQ *req)
+X509_NAME *X509_REQ_get_subject_name(const X509_REQ *req)
 {
     return req->req_info.subject;
 }
diff --git a/crypto/x509/x509_set.c b/crypto/x509/x509_set.c
index 11439bcafb..af5af61058 100644
--- a/crypto/x509/x509_set.c
+++ b/crypto/x509/x509_set.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,6 +7,11 @@
  * https://www.openssl.org/source/license.html
  */
 
+/*
+ * because of EVP_PKEY_asn1_find deprecation
+ */
+#include "internal/deprecated.h"
+
 #include 
 #include "internal/cryptlib.h"
 #include "internal/refcount.h"
@@ -17,7 +22,6 @@
 #include 
 #include "crypto/asn1.h"
 #include "crypto/x509.h"
-#include "crypto/evp.h"
 #include "x509_local.h"
 
 int X509_set_version(X509 *x, long version)
@@ -117,7 +121,7 @@ int X509_up_ref(X509 *x)
 {
     int i;
 
-    if (!CRYPTO_UP_REF(&x->references, &i))
+    if (CRYPTO_UP_REF(&x->references, &i) <= 0)
         return 0;
 
     REF_PRINT_COUNT("X509", i, x);
@@ -140,12 +144,12 @@ const ASN1_TIME *X509_get0_notAfter(const X509 *x)
     return x->cert_info.validity.notAfter;
 }
 
-ASN1_TIME *X509_getm_notBefore(X509 *x)
+ASN1_TIME *X509_getm_notBefore(const X509 *x)
 {
     return x->cert_info.validity.notBefore;
 }
 
-ASN1_TIME *X509_getm_notAfter(X509 *x)
+ASN1_TIME *X509_getm_notAfter(const X509 *x)
 {
     return x->cert_info.validity.notAfter;
 }
@@ -155,7 +159,7 @@ int X509_get_signature_type(const X509 *x)
     return EVP_PKEY_type(OBJ_obj2nid(x->sig_alg.algorithm));
 }
 
-const X509_PUBKEY *X509_get_X509_PUBKEY(const X509 *x)
+X509_PUBKEY *X509_get_X509_PUBKEY(const X509 *x)
 {
     return x->cert_info.key;
 }
@@ -202,7 +206,7 @@ void X509_SIG_INFO_set(X509_SIG_INFO *siginf, int mdnid, int pknid,
     siginf->flags = flags;
 }
 
-int X509_get_signature_info(const X509 *x, int *mdnid, int *pknid, int *secbits,
+int X509_get_signature_info(X509 *x, int *mdnid, int *pknid, int *secbits,
     uint32_t *flags)
 {
     X509_check_purpose(x, -1, -1);
@@ -211,11 +215,10 @@ int X509_get_signature_info(const X509 *x, int *mdnid, int *pknid, int *secbits,
 
 /* Modify *siginf according to alg and sig. Return 1 on success, else 0. */
 static int x509_sig_info_init(X509_SIG_INFO *siginf, const X509_ALGOR *alg,
-    const ASN1_STRING *sig, const EVP_PKEY *pubkey,
-    OSSL_LIB_CTX *libctx, const char *propq)
+    const ASN1_STRING *sig, const EVP_PKEY *pubkey)
 {
     int pknid, mdnid, md_size;
-    EVP_MD *md;
+    const EVP_MD *md;
     const EVP_PKEY_ASN1_METHOD *ameth;
 
     siginf->mdnid = NID_undef;
@@ -233,7 +236,7 @@ static int x509_sig_info_init(X509_SIG_INFO *siginf, const X509_ALGOR *alg,
     switch (mdnid) {
     case NID_undef:
         /* If we have one, use a custom handler for this algorithm */
-        ameth = evp_pkey_asn1_find(pknid);
+        ameth = EVP_PKEY_asn1_find(NULL, pknid);
         if (ameth != NULL && ameth->siginf_set != NULL
             && ameth->siginf_set(siginf, alg, sig))
             break;
@@ -277,25 +280,11 @@ static int x509_sig_info_init(X509_SIG_INFO *siginf, const X509_ALGOR *alg,
         break;
     default:
         /* Security bits: half number of bits in digest */
-        {
-            char md_name[80];
-            ASN1_OBJECT *md_obj = OBJ_nid2obj(mdnid);
-
-            if (md_obj == NULL
-                || i2t_ASN1_OBJECT(md_name, sizeof(md_name), md_obj) <= 0) {
-                ERR_raise_data(ERR_LIB_X509, X509_R_ERROR_GETTING_MD_BY_NID,
-                    "nid=%d", mdnid);
-                return 0;
-            }
-            md = EVP_MD_fetch(libctx, md_name, propq);
-            if (md == NULL) {
-                ERR_raise_data(ERR_LIB_X509, X509_R_ERROR_GETTING_MD_BY_NID,
-                    "nid=%d name=%s", mdnid, md_name);
-                return 0;
-            }
+        if ((md = EVP_get_digestbynid(mdnid)) == NULL) {
+            ERR_raise(ERR_LIB_X509, X509_R_ERROR_GETTING_MD_BY_NID);
+            return 0;
         }
         md_size = EVP_MD_get_size(md);
-        EVP_MD_free(md);
         if (md_size <= 0)
             return 0;
         siginf->secbits = md_size * 4;
@@ -313,8 +302,8 @@ static int x509_sig_info_init(X509_SIG_INFO *siginf, const X509_ALGOR *alg,
 }
 
 /* Returns 1 on success, 0 on failure */
-int ossl_x509_init_sig_info(const X509 *x, X509_SIG_INFO *info)
+int ossl_x509_init_sig_info(X509 *x)
 {
-    return x509_sig_info_init(info, &x->sig_alg, &x->signature,
-        X509_PUBKEY_get0(x->cert_info.key), x->libctx, x->propq);
+    return x509_sig_info_init(&x->siginf, &x->sig_alg, &x->signature,
+        X509_PUBKEY_get0(x->cert_info.key));
 }
diff --git a/crypto/x509/x509_trust.c b/crypto/x509/x509_trust.c
index 4b9d82aeaf..167a5e888e 100644
--- a/crypto/x509/x509_trust.c
+++ b/crypto/x509/x509_trust.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,12 +15,12 @@
 static int tr_cmp(const X509_TRUST *const *a, const X509_TRUST *const *b);
 static void trtable_free(X509_TRUST *p);
 
-static int trust_1oidany(X509_TRUST *trust, const X509 *x, int flags);
-static int trust_1oid(X509_TRUST *trust, const X509 *x, int flags);
-static int trust_compat(X509_TRUST *trust, const X509 *x, int flags);
+static int trust_1oidany(X509_TRUST *trust, X509 *x, int flags);
+static int trust_1oid(X509_TRUST *trust, X509 *x, int flags);
+static int trust_compat(X509_TRUST *trust, X509 *x, int flags);
 
-static int obj_trust(int id, const X509 *x, int flags);
-static int (*default_trust)(int id, const X509 *x, int flags) = obj_trust;
+static int obj_trust(int id, X509 *x, int flags);
+static int (*default_trust)(int id, X509 *x, int flags) = obj_trust;
 
 /*
  * WARNING: the following table should be kept in order of trust and without
@@ -54,17 +54,17 @@ static int tr_cmp(const X509_TRUST *const *a, const X509_TRUST *const *b)
     return (*a)->trust - (*b)->trust;
 }
 
-int (*X509_TRUST_set_default(int (*trust)(int, const X509 *, int)))(int, const X509 *,
+int (*X509_TRUST_set_default(int (*trust)(int, X509 *, int)))(int, X509 *,
     int)
 {
-    int (*oldtrust)(int, const X509 *, int);
+    int (*oldtrust)(int, X509 *, int);
     oldtrust = default_trust;
     default_trust = trust;
     return oldtrust;
 }
 
 /* Returns X509_TRUST_TRUSTED, X509_TRUST_REJECTED, or X509_TRUST_UNTRUSTED */
-int X509_check_trust(const X509 *x, int id, int flags)
+int X509_check_trust(X509 *x, int id, int flags)
 {
     X509_TRUST *pt;
     int idx;
@@ -124,7 +124,7 @@ int X509_TRUST_set(int *t, int trust)
     return 1;
 }
 
-int X509_TRUST_add(int id, int flags, int (*ck)(X509_TRUST *, const X509 *, int),
+int X509_TRUST_add(int id, int flags, int (*ck)(X509_TRUST *, X509 *, int),
     const char *name, int arg1, void *arg2)
 {
     int idx;
@@ -214,7 +214,7 @@ int X509_TRUST_get_trust(const X509_TRUST *xp)
     return xp->trust;
 }
 
-static int trust_1oidany(X509_TRUST *trust, const X509 *x, int flags)
+static int trust_1oidany(X509_TRUST *trust, X509 *x, int flags)
 {
     /*
      * Declare the chain verified if the desired trust OID is not rejected in
@@ -226,7 +226,7 @@ static int trust_1oidany(X509_TRUST *trust, const X509 *x, int flags)
     return obj_trust(trust->arg1, x, flags);
 }
 
-static int trust_1oid(X509_TRUST *trust, const X509 *x, int flags)
+static int trust_1oid(X509_TRUST *trust, X509 *x, int flags)
 {
     /*
      * Declare the chain verified only if the desired trust OID is not
@@ -237,7 +237,7 @@ static int trust_1oid(X509_TRUST *trust, const X509 *x, int flags)
     return obj_trust(trust->arg1, x, flags);
 }
 
-static int trust_compat(X509_TRUST *trust, const X509 *x, int flags)
+static int trust_compat(X509_TRUST *trust, X509 *x, int flags)
 {
     /* Call for side-effect of setting EXFLAG_SS for self-signed-certs */
     if (X509_check_purpose(x, -1, 0) != 1)
@@ -255,7 +255,7 @@ static int trust_compat(X509_TRUST *trust, const X509 *x, int flags)
  * If |flags| includes X509_TRUST_OK_ANY_EKU then anyEKU serves as wildcard.
  * Return X509_TRUST_UNTRUSTED if no clear decision has been reached here.
  */
-static int obj_trust(int id, const X509 *x, int flags)
+static int obj_trust(int id, X509 *x, int flags)
 {
     X509_CERT_AUX *ax = x->aux;
     int i;
diff --git a/crypto/x509/x509_txt.c b/crypto/x509/x509_txt.c
index 3a77e52f32..a415237b8b 100644
--- a/crypto/x509/x509_txt.c
+++ b/crypto/x509/x509_txt.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -223,12 +223,6 @@ const char *X509_verify_cert_error_string(long n)
         return "Certificate public key has explicit ECC parameters";
     case X509_V_ERR_RPK_UNTRUSTED:
         return "Raw public key untrusted, no trusted keys configured";
-    case X509_V_ERR_EMPTY_AUTHORITY_KEY_IDENTIFIER:
-        return "Empty Authority Key Identifier";
-    case X509_V_ERR_AKID_ISSUER_SERIAL_NOT_PAIRED:
-        return "Authority Key Identifier issuer and serial number must be paired";
-    case X509_V_ERR_DUPLICATE_EXTENSION:
-        return "Certificate includes more than one instance of a particular extension";
 
         /*
          * Entries must be kept consistent with include/openssl/x509_vfy.h.in
diff --git a/crypto/x509/x509_v3.c b/crypto/x509/x509_v3.c
index d3fc114163..611a5dabd6 100644
--- a/crypto/x509/x509_v3.c
+++ b/crypto/x509/x509_v3.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -17,8 +17,6 @@
 #include 
 #include "x509_local.h"
 
-#include 
-
 int X509v3_get_ext_count(const STACK_OF(X509_EXTENSION) *x)
 {
     int ret;
@@ -82,7 +80,7 @@ int X509v3_get_ext_by_critical(const STACK_OF(X509_EXTENSION) *sk, int crit,
     return -1;
 }
 
-const X509_EXTENSION *X509v3_get_ext(const STACK_OF(X509_EXTENSION) *x, int loc)
+X509_EXTENSION *X509v3_get_ext(const STACK_OF(X509_EXTENSION) *x, int loc)
 {
     if (x == NULL || sk_X509_EXTENSION_num(x) <= loc || loc < 0)
         return NULL;
@@ -92,27 +90,16 @@ const X509_EXTENSION *X509v3_get_ext(const STACK_OF(X509_EXTENSION) *x, int loc)
 
 X509_EXTENSION *X509v3_delete_ext(STACK_OF(X509_EXTENSION) *x, int loc)
 {
-    return sk_X509_EXTENSION_delete(x, loc);
-}
+    X509_EXTENSION *ret;
 
-X509_EXTENSION *X509v3_delete_extension(STACK_OF(X509_EXTENSION) **x, int loc)
-{
-    X509_EXTENSION *ext;
-
-    if (x == NULL)
+    if (x == NULL || sk_X509_EXTENSION_num(x) <= loc || loc < 0)
         return NULL;
-
-    /* Set extensions to NULL when last element dropped */
-    if ((ext = X509v3_delete_ext(*x, loc)) != NULL
-        && sk_X509_EXTENSION_num(*x) == 0) {
-        sk_X509_EXTENSION_free(*x);
-        *x = NULL;
-    }
-    return ext;
+    ret = sk_X509_EXTENSION_delete(x, loc);
+    return ret;
 }
 
 STACK_OF(X509_EXTENSION) *X509v3_add_ext(STACK_OF(X509_EXTENSION) **x,
-    const X509_EXTENSION *ex, int loc)
+    X509_EXTENSION *ex, int loc)
 {
     X509_EXTENSION *new_ex = NULL;
     int n;
@@ -131,9 +118,6 @@ STACK_OF(X509_EXTENSION) *X509v3_add_ext(STACK_OF(X509_EXTENSION) **x,
     } else
         sk = *x;
 
-    if (ossl_ignored_x509_extension(ex, X509V3_ADD_SILENT))
-        goto done;
-
     n = sk_X509_EXTENSION_num(sk);
     if (loc > n)
         loc = n;
@@ -148,7 +132,6 @@ STACK_OF(X509_EXTENSION) *X509v3_add_ext(STACK_OF(X509_EXTENSION) **x,
         ERR_raise(ERR_LIB_X509, ERR_R_CRYPTO_LIB);
         goto err;
     }
-done:
     if (*x == NULL)
         *x = sk;
     return sk;
@@ -171,8 +154,8 @@ STACK_OF(X509_EXTENSION) *X509v3_add_extensions(STACK_OF(X509_EXTENSION) **targe
     }
 
     for (i = 0; i < sk_X509_EXTENSION_num(exts); i++) {
-        const X509_EXTENSION *ext = sk_X509_EXTENSION_value(exts, i);
-        const ASN1_OBJECT *obj = X509_EXTENSION_get_object(ext);
+        X509_EXTENSION *ext = sk_X509_EXTENSION_value(exts, i);
+        ASN1_OBJECT *obj = X509_EXTENSION_get_object(ext);
         int idx = X509v3_get_ext_by_OBJ(*target, obj, -1);
 
         /* Does extension exist in target? */
@@ -254,7 +237,7 @@ int X509_EXTENSION_set_critical(X509_EXTENSION *ex, int crit)
     return 1;
 }
 
-int X509_EXTENSION_set_data(X509_EXTENSION *ex, const ASN1_OCTET_STRING *data)
+int X509_EXTENSION_set_data(X509_EXTENSION *ex, ASN1_OCTET_STRING *data)
 {
     int i;
 
@@ -266,14 +249,14 @@ int X509_EXTENSION_set_data(X509_EXTENSION *ex, const ASN1_OCTET_STRING *data)
     return 1;
 }
 
-const ASN1_OBJECT *X509_EXTENSION_get_object(const X509_EXTENSION *ex)
+ASN1_OBJECT *X509_EXTENSION_get_object(X509_EXTENSION *ex)
 {
     if (ex == NULL)
         return NULL;
     return ex->object;
 }
 
-const ASN1_OCTET_STRING *X509_EXTENSION_get_data(const X509_EXTENSION *ex)
+ASN1_OCTET_STRING *X509_EXTENSION_get_data(X509_EXTENSION *ex)
 {
     if (ex == NULL)
         return NULL;
diff --git a/crypto/x509/x509_vfy.c b/crypto/x509/x509_vfy.c
index 977672d8fc..c535334f24 100644
--- a/crypto/x509/x509_vfy.c
+++ b/crypto/x509/x509_vfy.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -7,7 +7,6 @@
  * https://www.openssl.org/source/license.html
  */
 
-#define OPENSSL_SUPPRESS_DEPRECATED
 #include "internal/deprecated.h"
 
 #include 
@@ -52,7 +51,7 @@ static int verify_rpk(X509_STORE_CTX *ctx);
 static int dane_verify(X509_STORE_CTX *ctx);
 static int dane_verify_rpk(X509_STORE_CTX *ctx);
 static int null_callback(int ok, X509_STORE_CTX *e);
-static int check_issued(X509_STORE_CTX *ctx, const X509 *x, const X509 *issuer);
+static int check_issued(X509_STORE_CTX *ctx, X509 *x, X509 *issuer);
 static int check_extensions(X509_STORE_CTX *ctx);
 static int check_name_constraints(X509_STORE_CTX *ctx);
 static int check_id(X509_STORE_CTX *ctx);
@@ -99,7 +98,7 @@ static int null_callback(int ok, X509_STORE_CTX *e)
  * to match issuer and subject names (i.e., the cert being self-issued) and any
  * present authority key identifier to match the subject key identifier, etc.
  */
-int X509_self_signed(const X509 *cert, int verify_signature)
+int X509_self_signed(X509 *cert, int verify_signature)
 {
     EVP_PKEY *pkey;
 
@@ -107,7 +106,7 @@ int X509_self_signed(const X509 *cert, int verify_signature)
         ERR_raise(ERR_LIB_X509, X509_R_UNABLE_TO_GET_CERTS_PUBLIC_KEY);
         return -1;
     }
-    if (!ossl_x509v3_cache_extensions((X509 *)cert))
+    if (!ossl_x509v3_cache_extensions(cert))
         return -1;
     if ((cert->ex_flags & EXFLAG_SS) == 0)
         return 0;
@@ -161,13 +160,13 @@ static int lookup_cert_match(X509 **result, X509_STORE_CTX *ctx, X509 *x)
  *
  * Returns 0 to abort verification with an error, non-zero to continue.
  */
-static int verify_cb_cert(X509_STORE_CTX *ctx, const X509 *x, int depth, int err)
+static int verify_cb_cert(X509_STORE_CTX *ctx, X509 *x, int depth, int err)
 {
     if (depth < 0)
         depth = ctx->error_depth;
     else
         ctx->error_depth = depth;
-    ctx->current_cert = x != NULL ? (X509 *)x : sk_X509_value(ctx->chain, depth);
+    ctx->current_cert = x != NULL ? x : sk_X509_value(ctx->chain, depth);
     if (err != X509_V_OK)
         ctx->error = err;
     return ctx->verify_cb(0, ctx);
@@ -412,7 +411,7 @@ static int sk_X509_contains(STACK_OF(X509) *sk, X509 *cert)
  * Maybe not touch X509_STORE_CTX_get1_issuer(), for API backward compatibility.
  */
 static X509 *get0_best_issuer_sk(X509_STORE_CTX *ctx, int check_signing_allowed,
-    int no_dup, STACK_OF(X509) *sk, const X509 *x)
+    int no_dup, STACK_OF(X509) *sk, X509 *x)
 {
     int i;
     X509 *candidate, *issuer = NULL;
@@ -453,7 +452,7 @@ static X509 *get0_best_issuer_sk(X509_STORE_CTX *ctx, int check_signing_allowed,
  *  0 certificate not found.
  * -1 some other error.
  */
-int X509_STORE_CTX_get1_issuer(X509 **issuer, X509_STORE_CTX *ctx, const X509 *x)
+int X509_STORE_CTX_get1_issuer(X509 **issuer, X509_STORE_CTX *ctx, X509 *x)
 {
     const X509_NAME *xn = X509_get_issuer_name(x);
     X509_OBJECT *obj = X509_OBJECT_new();
@@ -491,7 +490,7 @@ end:
 }
 
 /* Check that the given certificate |x| is issued by the certificate |issuer| */
-static int check_issued(ossl_unused X509_STORE_CTX *ctx, const X509 *x, const X509 *issuer)
+static int check_issued(ossl_unused X509_STORE_CTX *ctx, X509 *x, X509 *issuer)
 {
     int err = ossl_x509_likely_issued(issuer, x);
 
@@ -508,7 +507,7 @@ static int check_issued(ossl_unused X509_STORE_CTX *ctx, const X509 *x, const X5
  * Alternative get_issuer method: look up from a STACK_OF(X509) in other_ctx.
  * Returns -1 on internal error.
  */
-static int get1_best_issuer_other_sk(X509 **issuer, X509_STORE_CTX *ctx, const X509 *x)
+static int get1_best_issuer_other_sk(X509 **issuer, X509_STORE_CTX *ctx, X509 *x)
 {
     *issuer = get0_best_issuer_sk(ctx, 0, 1 /* no_dup */, ctx->other_ctx, x);
     if (*issuer == NULL)
@@ -520,7 +519,7 @@ static int get1_best_issuer_other_sk(X509 **issuer, X509_STORE_CTX *ctx, const X
  * Alternative lookup method: look from a STACK stored in other_ctx.
  * Returns NULL on internal/fatal error, empty stack if not found.
  */
-static STACK_OF(X509) *lookup_certs_sk(const X509_STORE_CTX *ctx, const X509_NAME *nm)
+static STACK_OF(X509) *lookup_certs_sk(X509_STORE_CTX *ctx, const X509_NAME *nm)
 {
     STACK_OF(X509) *sk = sk_X509_new_null();
     X509 *x;
@@ -533,6 +532,7 @@ static STACK_OF(X509) *lookup_certs_sk(const X509_STORE_CTX *ctx, const X509_NAM
         if (X509_NAME_cmp(nm, X509_get_subject_name(x)) == 0) {
             if (!X509_add_cert(sk, x, X509_ADD_FLAG_UP_REF)) {
                 OSSL_STACK_OF_X509_free(sk);
+                ctx->error = X509_V_ERR_OUT_OF_MEM;
                 return NULL;
             }
         }
@@ -625,9 +625,6 @@ static int check_extensions(X509_STORE_CTX *ctx)
 
     for (i = 0; i < num; i++) {
         x = sk_X509_value(ctx->chain, i);
-        /* RFC 5280, 4.2: a given extension MUST NOT appear more than once */
-        CB_FAIL_IF((x->ex_flags & EXFLAG_DUPLICATE) != 0,
-            ctx, x, i, X509_V_ERR_DUPLICATE_EXTENSION);
         CB_FAIL_IF((ctx->param->flags & X509_V_FLAG_IGNORE_CRITICAL) == 0
                 && (x->ex_flags & EXFLAG_CRITICAL) != 0,
             ctx, x, i, X509_V_ERR_UNHANDLED_CRITICAL_EXTENSION);
@@ -676,6 +673,10 @@ static int check_extensions(X509_STORE_CTX *ctx)
                 CB_FAIL_IF((x->ex_kusage & KU_KEY_CERT_SIGN) == 0, ctx,
                     x, i, X509_V_ERR_PATHLEN_WITHOUT_KU_KEY_CERT_SIGN);
             }
+            CB_FAIL_IF((x->ex_flags & EXFLAG_CA) != 0
+                    && (x->ex_flags & EXFLAG_BCONS) != 0
+                    && (x->ex_flags & EXFLAG_BCONS_CRITICAL) == 0,
+                ctx, x, i, X509_V_ERR_CA_BCONS_NOT_CRITICAL);
             /* Check Key Usage according to RFC 5280 section 4.2.1.3 */
             if ((x->ex_flags & EXFLAG_CA) != 0) {
                 CB_FAIL_IF((x->ex_flags & EXFLAG_KUSAGE) == 0,
@@ -693,6 +694,10 @@ static int check_extensions(X509_STORE_CTX *ctx)
                            || x->altname == NULL)
                     && X509_NAME_entry_count(X509_get_subject_name(x)) == 0,
                 ctx, x, i, X509_V_ERR_SUBJECT_NAME_EMPTY);
+            CB_FAIL_IF(X509_NAME_entry_count(X509_get_subject_name(x)) == 0
+                    && x->altname != NULL
+                    && (x->ex_flags & EXFLAG_SAN_CRITICAL) == 0,
+                ctx, x, i, X509_V_ERR_EMPTY_SUBJECT_SAN_NOT_CRITICAL);
             /* Check SAN is non-empty according to RFC 5280 section 4.2.1.6 */
             CB_FAIL_IF(x->altname != NULL
                     && sk_GENERAL_NAME_num(x->altname) <= 0,
@@ -700,31 +705,21 @@ static int check_extensions(X509_STORE_CTX *ctx)
             /* Check sig alg consistency acc. to RFC 5280 section 4.1.1.2 */
             CB_FAIL_IF(X509_ALGOR_cmp(&x->sig_alg, &x->cert_info.signature) != 0,
                 ctx, x, i, X509_V_ERR_SIGNATURE_ALGORITHM_INCONSISTENCY);
+            CB_FAIL_IF(x->akid != NULL
+                    && (x->ex_flags & EXFLAG_AKID_CRITICAL) != 0,
+                ctx, x, i, X509_V_ERR_AUTHORITY_KEY_IDENTIFIER_CRITICAL);
+            CB_FAIL_IF(x->skid != NULL
+                    && (x->ex_flags & EXFLAG_SKID_CRITICAL) != 0,
+                ctx, x, i, X509_V_ERR_SUBJECT_KEY_IDENTIFIER_CRITICAL);
             if (X509_get_version(x) >= X509_VERSION_3) {
                 /* Check AKID presence acc. to RFC 5280 section 4.2.1.1 */
-                /*
-                 * This means not last cert in chain, taken as generated by
-                 * conforming CAs and not self-signed.
-                 */
-                unsigned int check_akid = (i + 1 < num)
-                    && ((x->ex_flags & EXFLAG_SS) == 0);
-                CB_FAIL_IF(check_akid != 0 && x->akid == NULL,
-                    ctx, x, i, X509_V_ERR_MISSING_AUTHORITY_KEY_IDENTIFIER);
-                CB_FAIL_IF(check_akid != 0 && x->akid != NULL
-                        && x->akid->keyid == NULL && x->akid->issuer == NULL
-                        && x->akid->serial == NULL,
-                    ctx, x, i, X509_V_ERR_EMPTY_AUTHORITY_KEY_IDENTIFIER);
-                /*
-                 * The authorityCertIssuer and authorityCertSerialNumber fields
-                 * are paired and MUST either both be present or both be absent.
-                 *
-                 * Issuer without serial is ambiguous, and serial without issuer
-                 * is meaningless, leading to unresolvable and misleading issuer
-                 * identification.
-                 */
-                CB_FAIL_IF(x->akid != NULL
-                        && (x->akid->issuer == NULL) != (x->akid->serial == NULL),
-                    ctx, x, i, X509_V_ERR_AKID_ISSUER_SERIAL_NOT_PAIRED);
+                CB_FAIL_IF(i + 1 < num /*
+                                        * this means not last cert in chain,
+                                        * taken as "generated by conforming CAs"
+                                        */
+                        && (x->akid == NULL || x->akid->keyid == NULL),
+                    ctx,
+                    x, i, X509_V_ERR_MISSING_AUTHORITY_KEY_IDENTIFIER);
                 /* Check SKID presence acc. to RFC 5280 section 4.2.1.2 */
                 CB_FAIL_IF((x->ex_flags & EXFLAG_CA) != 0 && x->skid == NULL,
                     ctx, x, i, X509_V_ERR_MISSING_SUBJECT_KEY_IDENTIFIER);
@@ -775,7 +770,7 @@ static int check_extensions(X509_STORE_CTX *ctx)
     return 1;
 }
 
-static int has_san_id(const X509 *x, int gtype)
+static int has_san_id(X509 *x, int gtype)
 {
     int i;
     int ret = 0;
@@ -806,7 +801,7 @@ static int check_name_constraints(X509_STORE_CTX *ctx)
 
     /* Check name constraints for all certificates */
     for (i = sk_X509_num(ctx->chain) - 1; i >= 0; i--) {
-        const X509 *x = sk_X509_value(ctx->chain, i);
+        X509 *x = sk_X509_value(ctx->chain, i);
         int j;
 
         /* Ignore self-issued certs unless last in chain */
@@ -820,9 +815,8 @@ static int check_name_constraints(X509_STORE_CTX *ctx)
          * (RFC 3820: 3.4, 4.1.3 (a)(4))
          */
         if ((x->ex_flags & EXFLAG_PROXY) != 0) {
-            const X509_NAME *tmpsubject = X509_get_subject_name(x);
-            const X509_NAME *tmpissuer = X509_get_issuer_name(x);
-            X509_NAME *tmpsubject2;
+            X509_NAME *tmpsubject = X509_get_subject_name(x);
+            X509_NAME *tmpissuer = X509_get_issuer_name(x);
             X509_NAME_ENTRY *tmpentry = NULL;
             int last_nid = 0;
             int err = X509_V_OK;
@@ -859,23 +853,23 @@ static int check_name_constraints(X509_STORE_CTX *ctx)
              * Check that the last subject RDN is a commonName, and that
              * all the previous RDNs match the issuer exactly
              */
-            tmpsubject2 = X509_NAME_dup(tmpsubject);
-            if (tmpsubject2 == NULL) {
+            tmpsubject = X509_NAME_dup(tmpsubject);
+            if (tmpsubject == NULL) {
                 ERR_raise(ERR_LIB_X509, ERR_R_ASN1_LIB);
                 ctx->error = X509_V_ERR_OUT_OF_MEM;
                 return -1;
             }
 
-            tmpentry = X509_NAME_delete_entry(tmpsubject2, last_loc);
+            tmpentry = X509_NAME_delete_entry(tmpsubject, last_loc);
             last_nid = OBJ_obj2nid(X509_NAME_ENTRY_get_object(tmpentry));
 
             if (last_nid != NID_commonName
-                || X509_NAME_cmp(tmpsubject2, tmpissuer) != 0) {
+                || X509_NAME_cmp(tmpsubject, tmpissuer) != 0) {
                 err = X509_V_ERR_PROXY_SUBJECT_NAME_VIOLATION;
             }
 
             X509_NAME_ENTRY_free(tmpentry);
-            X509_NAME_free(tmpsubject2);
+            X509_NAME_free(tmpsubject);
 
         proxy_name_done:
             CB_FAIL_IF(err != X509_V_OK, ctx, x, i, err);
@@ -929,57 +923,20 @@ static int check_id_error(X509_STORE_CTX *ctx, int errcode)
 
 static int check_hosts(X509 *x, X509_VERIFY_PARAM *vpm)
 {
-    const uint8_t *name;
-    int n = sk_X509_BUFFER_num(vpm->hosts);
+    int i;
+    int n = sk_OPENSSL_STRING_num(vpm->hosts);
+    char *name;
 
     if (vpm->peername != NULL) {
         OPENSSL_free(vpm->peername);
         vpm->peername = NULL;
     }
-    for (int i = 0; i < n; ++i) {
-        size_t len = sk_X509_BUFFER_value(vpm->hosts, i)->len;
-        name = sk_X509_BUFFER_value(vpm->hosts, i)->data;
-        if (ossl_x509_check_host(x, (const char *)name, len, vpm->hostflags,
-                &vpm->peername)
-            > 0)
+    for (i = 0; i < n; ++i) {
+        name = sk_OPENSSL_STRING_value(vpm->hosts, i);
+        if (X509_check_host(x, name, 0, vpm->hostflags, &vpm->peername) > 0)
             return 1;
     }
-    return n <= 0;
-}
-
-static int check_email(X509 *x, X509_VERIFY_PARAM *vpm)
-{
-    const uint8_t *name;
-    int nasc = sk_X509_BUFFER_num(vpm->rfc822s);
-    int nutf = sk_X509_BUFFER_num(vpm->smtputf8s);
-
-    for (int i = 0; i < nasc; ++i) {
-        size_t len = sk_X509_BUFFER_value(vpm->rfc822s, i)->len;
-        name = sk_X509_BUFFER_value(vpm->rfc822s, i)->data;
-        if (ossl_x509_check_rfc822(x, (const char *)name, len, vpm->hostflags))
-            return 1;
-    }
-    for (int i = 0; i < nutf; ++i) {
-        size_t len = sk_X509_BUFFER_value(vpm->smtputf8s, i)->len;
-        name = sk_X509_BUFFER_value(vpm->smtputf8s, i)->data;
-        if (ossl_x509_check_smtputf8(x, (const char *)name, len, vpm->hostflags))
-            return 1;
-    }
-    return nasc <= 0 && nutf <= 0;
-}
-
-static int check_ips(X509 *x, X509_VERIFY_PARAM *vpm)
-{
-    const uint8_t *name;
-    int n = sk_X509_BUFFER_num(vpm->ips);
-
-    for (int i = 0; i < n; ++i) {
-        size_t len = sk_X509_BUFFER_value(vpm->ips, i)->len;
-        name = sk_X509_BUFFER_value(vpm->ips, i)->data;
-        if (ossl_x509_check_ip(x, name, len, vpm->hostflags) > 0)
-            return 1;
-    }
-    return n <= 0;
+    return n == 0;
 }
 
 static int check_id(X509_STORE_CTX *ctx)
@@ -991,13 +948,12 @@ static int check_id(X509_STORE_CTX *ctx)
         if (!check_id_error(ctx, X509_V_ERR_HOSTNAME_MISMATCH))
             return 0;
     }
-
-    if (!check_email(x, vpm)) {
+    if (vpm->email != NULL
+        && X509_check_email(x, vpm->email, vpm->emaillen, 0) <= 0) {
         if (!check_id_error(ctx, X509_V_ERR_EMAIL_MISMATCH))
             return 0;
     }
-
-    if (vpm->ips != NULL && check_ips(x, vpm) <= 0) {
+    if (vpm->ip != NULL && X509_check_ip(x, vpm->ip, vpm->iplen, 0) <= 0) {
         if (!check_id_error(ctx, X509_V_ERR_IP_ADDRESS_MISMATCH))
             return 0;
     }
@@ -1205,16 +1161,6 @@ static int check_revocation(X509_STORE_CTX *ctx)
 
             /* the issuer certificate is the next in the chain */
             ctx->current_issuer = sk_X509_value(ctx->chain, i + 1);
-            if (ctx->current_issuer == NULL) {
-                /*
-                 * No issuer exists at i+1 — this is the partial-chain
-                 * trust anchor. OCSP requires an issuer to build the
-                 * CertID, so skip OCSP checking for this certificate.
-                 */
-                if ((ctx->param->flags & X509_V_FLAG_PARTIAL_CHAIN) != 0)
-                    continue;
-                return verify_cb_ocsp(ctx, X509_V_ERR_OCSP_VERIFY_FAILED);
-            }
 
             ok = check_cert_ocsp_resp(ctx);
 
@@ -1296,7 +1242,7 @@ static int check_cert_ocsp_resp(X509_STORE_CTX *ctx)
     OCSP_CERTID *sr_cert_id = NULL;
     ASN1_GENERALIZEDTIME *rev, *thisupd, *nextupd;
     ASN1_OBJECT *cert_id_md_oid;
-    EVP_MD *cert_id_md = NULL;
+    EVP_MD *cert_id_md;
     OCSP_CERTID *cert_id = NULL;
     int ret = V_OCSP_CERTSTATUS_UNKNOWN;
     int num;
@@ -1313,12 +1259,11 @@ static int check_cert_ocsp_resp(X509_STORE_CTX *ctx)
 
     if (OCSP_response_status(resp) != OCSP_RESPONSE_STATUS_SUCCESSFUL) {
         OCSP_BASICRESP_free(bs);
-        bs = NULL;
         ret = X509_V_ERR_OCSP_RESP_INVALID;
         goto end;
     }
 
-    if (OCSP_basic_verify(bs, ctx->chain, ctx->store, 0) <= 0) {
+    if (OCSP_basic_verify(bs, ctx->chain, ctx->store, OCSP_TRUSTOTHER) <= 0) {
         ret = X509_V_ERR_OCSP_SIGNATURE_FAILURE;
         goto end;
     }
@@ -1330,17 +1275,13 @@ static int check_cert_ocsp_resp(X509_STORE_CTX *ctx)
         /* determine the md algorithm which was used to create cert id */
         sr_cert_id = (OCSP_CERTID *)OCSP_SINGLERESP_get0_id(sr);
         OCSP_id_get0_info(NULL, &cert_id_md_oid, NULL, NULL, sr_cert_id);
-        if (cert_id_md_oid != NULL) {
-            char md_name[80];
-
-            if (i2t_ASN1_OBJECT(md_name, sizeof(md_name), cert_id_md_oid) > 0)
-                cert_id_md = EVP_MD_fetch(ctx->libctx, md_name, ctx->propq);
-        }
+        if (cert_id_md_oid != NULL)
+            cert_id_md = (EVP_MD *)EVP_get_digestbyobj(cert_id_md_oid);
+        else
+            cert_id_md = NULL;
 
         /* search the stack for the requested OCSP response */
         cert_id = OCSP_cert_to_id(cert_id_md, ctx->current_cert, ctx->current_issuer);
-        EVP_MD_free(cert_id_md);
-        cert_id_md = NULL;
         if (cert_id == NULL) {
             ret = X509_V_ERR_OCSP_RESP_INVALID;
             goto end;
@@ -1428,7 +1369,7 @@ static int check_cert_crl(X509_STORE_CTX *ctx)
             ok = verify_cb_crl(ctx, X509_V_ERR_UNABLE_TO_GET_CRL);
             goto done;
         }
-
+        ctx->current_crl = crl;
         ok = ctx->check_crl(ctx, crl);
         if (!ok)
             goto done;
@@ -1451,7 +1392,6 @@ static int check_cert_crl(X509_STORE_CTX *ctx)
                 goto done;
         }
 
-        ctx->current_crl = NULL;
         X509_CRL_free(crl);
         X509_CRL_free(dcrl);
         crl = NULL;
@@ -1497,6 +1437,9 @@ int ossl_x509_check_crl_time(X509_STORE_CTX *ctx, X509_CRL *crl, int notify)
     if (!get_verification_time(ctx->param, &verification_time))
         return 1;
 
+    if (notify)
+        ctx->current_crl = crl;
+
     if (!certificate_time_to_posix(X509_CRL_get0_lastUpdate(crl),
             &last_update)) {
         err = X509_V_ERR_ERROR_IN_CRL_LAST_UPDATE_FIELD;
@@ -1523,6 +1466,9 @@ int ossl_x509_check_crl_time(X509_STORE_CTX *ctx, X509_CRL *crl, int notify)
         }
     }
 
+    if (notify)
+        ctx->current_crl = NULL;
+
     return 1;
 }
 
@@ -1588,7 +1534,7 @@ static int get_crl_sk(X509_STORE_CTX *ctx, X509_CRL **pcrl, X509_CRL **pdcrl,
  */
 static int crl_extension_match(X509_CRL *a, X509_CRL *b, int nid)
 {
-    const ASN1_OCTET_STRING *exta = NULL, *extb = NULL;
+    ASN1_OCTET_STRING *exta = NULL, *extb = NULL;
     int i = X509_CRL_get_ext_by_NID(a, nid, -1);
 
     if (i >= 0) {
@@ -1637,8 +1583,6 @@ static int check_delta_base(X509_CRL *delta, X509_CRL *base)
     if (ASN1_INTEGER_cmp(delta->base_crl_number, base->crl_number) > 0)
         return 0;
     /* Delta CRL number must exceed full CRL number */
-    if (delta->crl_number == NULL)
-        return 0;
     return ASN1_INTEGER_cmp(delta->crl_number, base->crl_number) > 0;
 }
 
@@ -1693,12 +1637,6 @@ static int get_crl_score(X509_STORE_CTX *ctx, X509 **pissuer,
     /* Invalid IDP cannot be processed */
     if ((crl->idp_flags & IDP_INVALID) != 0)
         return 0;
-    /*
-     * Reject delta CRLs unconditionally here. They are considered by
-     * get_delta_sk() after a base CRL is selected.
-     */
-    if (crl->base_crl_number != NULL)
-        return 0;
     /* Reason codes or indirect CRLs need extended CRL support */
     if ((ctx->param->flags & X509_V_FLAG_EXTENDED_CRL_SUPPORT) == 0) {
         if (crl->idp_flags & (IDP_INDIRECT | IDP_REASONS))
@@ -1708,6 +1646,9 @@ static int get_crl_score(X509_STORE_CTX *ctx, X509 **pissuer,
         if ((crl->idp_reasons & ~tmp_reasons) == 0)
             return 0;
     }
+    /* Don't process deltas at this stage */
+    else if (crl->base_crl_number != NULL)
+        return 0;
     /* If issuer name doesn't match certificate need indirect CRL */
     if (X509_NAME_cmp(X509_get_issuer_name(x), X509_CRL_get_issuer(crl)) != 0) {
         if ((crl->idp_flags & IDP_INDIRECT) == 0)
@@ -2014,8 +1955,6 @@ static int check_crl(X509_STORE_CTX *ctx, X509_CRL *crl)
     int cnum = ctx->error_depth;
     int chnum = sk_X509_num(ctx->chain) - 1;
 
-    ctx->current_crl = crl;
-
     /* If we have an alternative CRL issuer cert use that */
     if (ctx->current_issuer != NULL) {
         issuer = ctx->current_issuer;
@@ -2187,13 +2126,9 @@ memerr:
 /*-
  * Check certificate validity times.
  *
- * Returns 1 if the certificate |x| is temporally valid at the
- * verification time requested by |vpm|, or 0 otherwise. if |error| is
- * non-NULL, |*error| will be set to 0 when the certificate is
- * temporally valid, otherwise it will be set to a non-zero error
- * code.
+ * Return 1 on success, 0 otherwise.
  */
-int X509_check_certificate_times(const X509_VERIFY_PARAM *vpm, const X509 *x,
+int ossl_x509_check_certificate_times(const X509_VERIFY_PARAM *vpm, X509 *x,
     int *error)
 {
     int ret = 0, err = 0;
@@ -2417,14 +2352,13 @@ static int internal_verify(X509_STORE_CTX *ctx)
     return 1;
 }
 
-#if !defined(OPENSSL_NO_DEPRECATED_4_0)
 int X509_cmp_current_time(const ASN1_TIME *ctm)
 {
     return X509_cmp_time(ctm, NULL);
 }
 
 /* returns 0 on error, otherwise 1 if ctm > cmp_time, else -1 */
-int X509_cmp_time(const ASN1_TIME *ctm, const time_t *cmp_time)
+int X509_cmp_time(const ASN1_TIME *ctm, time_t *cmp_time)
 {
     int64_t cert_time, posix_time = cmp_time == NULL ? (int64_t)time(NULL) : (int64_t)*cmp_time;
 
@@ -2487,20 +2421,19 @@ int X509_cmp_timeframe(const X509_VERIFY_PARAM *vpm,
         return -1;
     return 0;
 }
-#endif /* !defined(OPENSSL_NO_DEPRECATED_4_0) */
 
 ASN1_TIME *X509_gmtime_adj(ASN1_TIME *s, long adj)
 {
     return X509_time_adj(s, adj, NULL);
 }
 
-ASN1_TIME *X509_time_adj(ASN1_TIME *s, long offset_sec, const time_t *in_tm)
+ASN1_TIME *X509_time_adj(ASN1_TIME *s, long offset_sec, time_t *in_tm)
 {
     return X509_time_adj_ex(s, 0, offset_sec, in_tm);
 }
 
 ASN1_TIME *X509_time_adj_ex(ASN1_TIME *s,
-    int offset_day, long offset_sec, const time_t *in_tm)
+    int offset_day, long offset_sec, time_t *in_tm)
 {
     time_t t;
 
@@ -2519,7 +2452,7 @@ ASN1_TIME *X509_time_adj_ex(ASN1_TIME *s,
 }
 
 /* Copy any missing public key parameters up the chain towards pkey */
-int X509_get_pubkey_parameters(EVP_PKEY *pkey, const STACK_OF(X509) *chain)
+int X509_get_pubkey_parameters(EVP_PKEY *pkey, STACK_OF(X509) *chain)
 {
     EVP_PKEY *ktmp = NULL, *ktmp2;
     int i, j;
@@ -2633,7 +2566,8 @@ X509_CRL *X509_CRL_diff(X509_CRL *base, X509_CRL *newer,
      * number to correct value too.
      */
     for (i = 0; i < X509_CRL_get_ext_count(newer); i++) {
-        const X509_EXTENSION *ext = X509_CRL_get_ext(newer, i);
+        X509_EXTENSION *ext = X509_CRL_get_ext(newer, i);
+
         if (!X509_CRL_add_ext(crl, ext, -1)) {
             ERR_raise(ERR_LIB_X509, ERR_R_X509_LIB);
             goto err;
@@ -2894,7 +2828,7 @@ int X509_STORE_CTX_init_rpk(X509_STORE_CTX *ctx, X509_STORE *store, EVP_PKEY *rp
     return 1;
 }
 
-int X509_STORE_CTX_init(X509_STORE_CTX *ctx, X509_STORE *store, const X509 *x509,
+int X509_STORE_CTX_init(X509_STORE_CTX *ctx, X509_STORE *store, X509 *x509,
     STACK_OF(X509) *chain)
 {
     if (ctx == NULL) {
@@ -2904,7 +2838,7 @@ int X509_STORE_CTX_init(X509_STORE_CTX *ctx, X509_STORE *store, const X509 *x509
     X509_STORE_CTX_cleanup(ctx);
 
     ctx->store = store;
-    ctx->cert = (X509 *)x509; /* XXX casts away const */
+    ctx->cert = x509;
     ctx->untrusted = chain;
     ctx->crls = NULL;
     ctx->num_untrusted = 0;
@@ -3408,7 +3342,7 @@ static int dane_match_cert(X509_STORE_CTX *ctx, X509 *cert, int depth)
                     break;
                 }
 
-                X509_free(dane->mcert);
+                OPENSSL_free(dane->mcert);
                 dane->mcert = cert;
                 dane->mdpth = depth;
                 dane->mtlsa = t;
@@ -4012,7 +3946,7 @@ memerr:
     return -1;
 }
 
-STACK_OF(X509) *X509_build_chain(const X509 *target, STACK_OF(X509) *certs,
+STACK_OF(X509) *X509_build_chain(X509 *target, STACK_OF(X509) *certs,
     X509_STORE *store, int with_self_signed,
     OSSL_LIB_CTX *libctx, const char *propq)
 {
@@ -4032,8 +3966,7 @@ STACK_OF(X509) *X509_build_chain(const X509 *target, STACK_OF(X509) *certs,
         goto err;
     if (!finish_chain)
         X509_STORE_CTX_set0_trusted_stack(ctx, certs);
-    /* XXX casts away const */
-    if (!ossl_x509_add_cert_new(&ctx->chain, (X509 *)target, X509_ADD_FLAG_UP_REF)) {
+    if (!ossl_x509_add_cert_new(&ctx->chain, target, X509_ADD_FLAG_UP_REF)) {
         ctx->error = X509_V_ERR_OUT_OF_MEM;
         goto err;
     }
diff --git a/crypto/x509/x509_vpm.c b/crypto/x509/x509_vpm.c
index 44b116923b..dc214409af 100644
--- a/crypto/x509/x509_vpm.c
+++ b/crypto/x509/x509_vpm.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2004-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2004-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -14,343 +14,70 @@
 #include 
 #include 
 #include 
-
-#include "crypto/ctype.h"
 #include "crypto/x509.h"
 
 #include "x509_local.h"
 
-typedef enum {
-    OSSL_CHARSET_NONASCII,
-    OSSL_CHARSET_ASCII,
-    OSSL_CHARSET_ASCII_ALNUM,
-} ossl_charset_t;
-
 /* X509_VERIFY_PARAM functions */
 
 #define SET_HOST 0
 #define ADD_HOST 1
 
-static X509_BUFFER *buffer_from_bytes(const uint8_t *bytes, size_t length)
+static char *str_copy(const char *s)
 {
-    X509_BUFFER *buf;
-
-    if ((buf = OPENSSL_zalloc(sizeof(*buf))) != NULL
-        && (buf->data = OPENSSL_memdup(bytes, length)) != NULL) {
-        buf->len = length;
-    } else {
-        OPENSSL_free(buf);
-        buf = NULL;
-    }
-    return buf;
+    return OPENSSL_strdup(s);
 }
 
-/*
- * Copies |length| bytes from |bytes| to a new buffer, making the data
- * A C string. It is an error for the |bytes| to contain any \0 values
- * within |length|. |bytes| need not itself be \0 terminated, the data
- * in the buffer will be on success.
- */
-static X509_BUFFER *buffer_from_string(const uint8_t *bytes, size_t length)
+static void str_free(char *s)
 {
-    X509_BUFFER *buf, *ret = NULL;
-    uint8_t *data = NULL;
-
-    if ((buf = OPENSSL_zalloc(sizeof(*buf))) == NULL)
-        goto err;
-
-    if ((data = (uint8_t *)OPENSSL_strndup((char *)bytes, length)) == NULL)
-        goto err;
-
-    if (strlen((char *)data) != length)
-        goto err;
-
-    ret = buf;
-    buf = NULL;
-    ret->data = data;
-    ret->len = length;
-    data = NULL;
-
-err:
-    OPENSSL_free(buf);
-    OPENSSL_free(data);
-
-    return ret;
+    OPENSSL_free(s);
 }
 
-static X509_BUFFER *buffer_copy(const X509_BUFFER *b)
+static int int_x509_param_set_hosts(X509_VERIFY_PARAM *vpm, int mode,
+    const char *name, size_t namelen)
 {
-    return buffer_from_bytes(b->data, b->len);
-}
-
-static void buffer_free(X509_BUFFER *b)
-{
-    if (b == NULL)
-        return;
-    OPENSSL_free((void *)b->data);
-    OPENSSL_free(b);
-}
-
-static int replace_buffer_stack(STACK_OF(X509_BUFFER) **dest,
-    STACK_OF(X509_BUFFER) *const *src)
-{
-    sk_X509_BUFFER_pop_free(*dest, buffer_free);
-    *dest = NULL;
-    if (*src != NULL) {
-        *dest = sk_X509_BUFFER_deep_copy(*src, buffer_copy, buffer_free);
-        if (*dest == NULL)
-            return 0;
-    }
-    return 1;
-}
-
-static int buffer_cmp(const X509_BUFFER *const *a, const X509_BUFFER *const *b)
-{
-    if ((*a)->len < (*b)->len)
-        return -1;
-    if ((*a)->len > (*b)->len)
-        return 1;
-    if ((*b)->len == 0)
-        return 0;
-    return memcmp((*a)->data, (*b)->data, (*b)->len);
-}
-
-static void clear_buffer_stack(STACK_OF(X509_BUFFER) **buffer_stack)
-{
-    sk_X509_BUFFER_pop_free(*buffer_stack, buffer_free);
-    *buffer_stack = NULL;
-}
-
-static int add_bytes_to_buffer_stack(STACK_OF(X509_BUFFER) **buffer_stack,
-    const uint8_t *name, size_t name_len)
-{
-    STACK_OF(X509_BUFFER) *tmp_stack = NULL;
-    X509_BUFFER *copy = NULL;
-    int ret = 0;
-
-    if ((copy = buffer_from_bytes(name, name_len)) == NULL)
-        goto err;
-
-    tmp_stack = *buffer_stack;
-    if (tmp_stack == NULL && (tmp_stack = sk_X509_BUFFER_new(buffer_cmp)) == NULL)
-        goto err;
-
-    if (!sk_X509_BUFFER_push(tmp_stack, copy))
-        goto err;
-
-    ret = 1;
-    copy = NULL;
-    *buffer_stack = tmp_stack;
-    tmp_stack = NULL;
-
-err:
-    sk_X509_BUFFER_pop_free(tmp_stack, buffer_free);
-    buffer_free(copy);
-
-    return ret;
-}
-
-static int add_string_to_buffer_stack(STACK_OF(X509_BUFFER) **buffer_stack,
-    const uint8_t *name, size_t name_len)
-{
-    STACK_OF(X509_BUFFER) *tmp_stack = NULL;
-    X509_BUFFER *copy = NULL;
-    int ret = 0;
-
-    if ((copy = buffer_from_string(name, name_len)) == NULL)
-        goto err;
-
-    tmp_stack = *buffer_stack;
-    if (tmp_stack == NULL && (tmp_stack = sk_X509_BUFFER_new(buffer_cmp)) == NULL)
-        goto err;
-
-    if (!sk_X509_BUFFER_push(tmp_stack, copy))
-        goto err;
-
-    ret = 1;
-    copy = NULL;
-    *buffer_stack = tmp_stack;
-    tmp_stack = NULL;
-
-err:
-    sk_X509_BUFFER_pop_free(tmp_stack, buffer_free);
-    buffer_free(copy);
-
-    return ret;
-}
-
-static int validate_string_name(const char *name, size_t *name_len)
-{
-    size_t len = *name_len;
-
-    if (name == NULL || len == 0)
-        return 0;
+    char *copy;
 
     /*
-     * Accept the trailing \0 byte if this is a C string. This is to
-     * preserver behaviour that is traditional for the
-     * set1_[host|email] functions.
+     * Refuse names with embedded NUL bytes, except perhaps as final byte.
+     * XXX: Do we need to push an error onto the error stack?
      */
-    if (name[len - 1] == '\0')
-        len--;
-
-    /* Refuse the empty string */
-    if (len == 0)
+    if (namelen == 0 || name == NULL)
+        namelen = name ? strlen(name) : 0;
+    else if (name != NULL
+        && memchr(name, '\0', namelen > 1 ? namelen - 1 : namelen) != NULL)
         return 0;
+    if (namelen > 0 && name[namelen - 1] == '\0')
+        --namelen;
 
-    /* Refuse values with embedded \0 bytes other than at the end */
-    if (memchr(name, '\0', len) != NULL)
-        return 0;
-
-    *name_len = len;
-    return 1;
-}
-
-/*
- * Default input validation for verification parameter names. As these
- * could potentially come from untrusted input, doing basic input
- * validation makes sense, and ensures that subsequent parsing or
- * comparisons do not need to handle extreme out of range input.
- */
-
-/* Default ip name input validation */
-static int validate_ip_name(const uint8_t *name, size_t len)
-{
-    if (name != NULL && (len == 4 || len == 16))
+    if (mode == SET_HOST) {
+        sk_OPENSSL_STRING_pop_free(vpm->hosts, str_free);
+        vpm->hosts = NULL;
+    }
+    if (name == NULL || namelen == 0)
         return 1;
-    return 0;
-}
 
-static ossl_charset_t ossl_name_charset(int c, ossl_charset_t charset)
-{
-    if (ossl_isalnum(c))
-        return 1;
-    if (ossl_isascii(c))
-        return charset == OSSL_CHARSET_ASCII
-            || charset == OSSL_CHARSET_NONASCII;
-    return charset == OSSL_CHARSET_NONASCII;
-}
-
-static int is_label_ok(int c, ossl_charset_t charset)
-{
-    if (!ossl_name_charset(c, charset) && c != '_')
-        return 0;
-    else
-        return c != '.' && c != '-';
-}
-
-/* Default host name input validation */
-static int validate_hostname_part(const char *name, size_t len,
-    ossl_charset_t charset)
-{
-    size_t i, part_len;
-    char c, prev;
-
-    if (len < 2 || len > 256)
+    copy = OPENSSL_strndup(name, namelen);
+    if (copy == NULL)
         return 0;
 
-    part_len = 0;
-    prev = '\0';
-    for (i = 0; i < len; i++) {
-        c = name[i];
-        if (c == '.') {
-            /*
-             * Can not start a label with a .
-             * unless it is the very first character.
-             */
-            if (part_len == 0 && i != 0)
-                return 0;
-            /* Can not end a label with a - */
-            if (prev == '-')
-                return 0;
-            part_len = 0;
-        } else {
-            /* Can not start a label with a - */
-            if (part_len == 0 && c == '-') {
-                return 0;
-            }
-            if (!is_label_ok(c, charset) && c != '-')
-                return 0;
-            part_len++;
+    if (vpm->hosts == NULL && (vpm->hosts = sk_OPENSSL_STRING_new_null()) == NULL) {
+        OPENSSL_free(copy);
+        return 0;
+    }
+
+    if (!sk_OPENSSL_STRING_push(vpm->hosts, copy)) {
+        OPENSSL_free(copy);
+        if (sk_OPENSSL_STRING_num(vpm->hosts) == 0) {
+            sk_OPENSSL_STRING_free(vpm->hosts);
+            vpm->hosts = NULL;
         }
-        if (part_len > 63)
-            return 0;
-
-        prev = c;
-    }
-    /* Can not end with a . or a _ */
-    if (prev == '.' || prev == '-')
         return 0;
-
-    return 1;
-}
-
-static int validate_local_part(const char *name, size_t len,
-    ossl_charset_t *out_charset)
-{
-    ossl_charset_t charset = OSSL_CHARSET_ASCII;
-    size_t i;
-
-    for (i = 0; i < len; i++) {
-        if (name[i] == '\0')
-            return 0;
-        if (!ossl_isascii(name[i]))
-            charset = OSSL_CHARSET_NONASCII;
     }
 
-    *out_charset = charset;
     return 1;
 }
 
-/* Default email name input validation */
-static int validate_email_name(const char *name, size_t len, int rfc822)
-{
-    size_t dns_len, local_len;
-    const char *at, *next, *dnsname;
-    ossl_charset_t local_charset;
-
-    /*
-     * 64 for local part, 1 for @, 255 for domain name
-     */
-    if (len > 320)
-        goto err;
-
-    /* Reject it if there is no @ */
-    if ((at = memchr(name, '@', len)) == NULL)
-        goto err;
-
-    /* Go to the last @ */
-    while ((next = memchr(at + 1, '@', len - (at - name + 1))) != NULL)
-        at = next;
-
-    /* Ensure the local part is not oversize */
-    local_len = at - name;
-    if (local_len > 64)
-        goto err;
-
-    if (!validate_local_part(name, local_len, &local_charset))
-        goto err;
-
-    if (rfc822 && local_charset == OSSL_CHARSET_NONASCII)
-        goto err;
-
-    if (!rfc822 && local_charset == OSSL_CHARSET_ASCII)
-        goto err;
-
-    /* What is after the @ must be valid as a dns name */
-    dnsname = at + 1;
-    dns_len = len - local_len - 1;
-
-    if (rfc822)
-        return validate_hostname_part(dnsname, dns_len, OSSL_CHARSET_ASCII_ALNUM);
-
-    return validate_hostname_part(dnsname, dns_len, OSSL_CHARSET_NONASCII);
-
-err:
-    ERR_raise(ERR_LIB_X509, ERR_R_PASSED_INVALID_ARGUMENT);
-    return 0;
-}
-
 X509_VERIFY_PARAM *X509_VERIFY_PARAM_new(void)
 {
     X509_VERIFY_PARAM *param;
@@ -370,11 +97,10 @@ void X509_VERIFY_PARAM_free(X509_VERIFY_PARAM *param)
     if (param == NULL)
         return;
     sk_ASN1_OBJECT_pop_free(param->policies, ASN1_OBJECT_free);
-    clear_buffer_stack(¶m->hosts);
-    clear_buffer_stack(¶m->ips);
-    clear_buffer_stack(¶m->rfc822s);
-    clear_buffer_stack(¶m->smtputf8s);
+    sk_OPENSSL_STRING_pop_free(param->hosts, str_free);
     OPENSSL_free(param->peername);
+    OPENSSL_free(param->email);
+    OPENSSL_free(param->ip);
     OPENSSL_free(param);
 }
 
@@ -466,28 +192,24 @@ int X509_VERIFY_PARAM_inherit(X509_VERIFY_PARAM *dest,
     x509_verify_param_copy(hostflags, 0);
 
     if (test_x509_verify_param_copy(hosts, NULL)) {
-        if (!replace_buffer_stack(&dest->hosts, &src->hosts))
-            return 0;
+        sk_OPENSSL_STRING_pop_free(dest->hosts, str_free);
+        dest->hosts = NULL;
+        if (src->hosts != NULL) {
+            dest->hosts = sk_OPENSSL_STRING_deep_copy(src->hosts, str_copy, str_free);
+            if (dest->hosts == NULL)
+                return 0;
+        }
     }
-    x509_verify_param_copy(validate_host, NULL);
 
-    if (test_x509_verify_param_copy(ips, NULL)) {
-        if (!replace_buffer_stack(&dest->ips, &src->ips))
+    if (test_x509_verify_param_copy(email, NULL)) {
+        if (!X509_VERIFY_PARAM_set1_email(dest, src->email, src->emaillen))
             return 0;
     }
-    x509_verify_param_copy(validate_ip, NULL);
 
-    if (test_x509_verify_param_copy(rfc822s, NULL)) {
-        if (!replace_buffer_stack(&dest->rfc822s, &src->rfc822s))
+    if (test_x509_verify_param_copy(ip, NULL)) {
+        if (!X509_VERIFY_PARAM_set1_ip(dest, src->ip, src->iplen))
             return 0;
     }
-    x509_verify_param_copy(validate_rfc822, NULL);
-
-    if (test_x509_verify_param_copy(smtputf8s, NULL)) {
-        if (!replace_buffer_stack(&dest->smtputf8s, &src->smtputf8s))
-            return 0;
-    }
-    x509_verify_param_copy(validate_smtputf8, NULL);
 
     return 1;
 }
@@ -509,6 +231,31 @@ int X509_VERIFY_PARAM_set1(X509_VERIFY_PARAM *to,
     return ret;
 }
 
+static int int_x509_param_set1(char **pdest, size_t *pdestlen,
+    const char *src, size_t srclen)
+{
+    char *tmp;
+
+    if (src != NULL) {
+        if (srclen == 0)
+            srclen = strlen(src);
+
+        tmp = OPENSSL_malloc(srclen + 1);
+        if (tmp == NULL)
+            return 0;
+        memcpy(tmp, src, srclen);
+        tmp[srclen] = '\0'; /* enforce NUL termination */
+    } else {
+        tmp = NULL;
+        srclen = 0;
+    }
+    OPENSSL_free(*pdest);
+    *pdest = tmp;
+    if (pdestlen != NULL)
+        *pdestlen = srclen;
+    return 1;
+}
+
 int X509_VERIFY_PARAM_set1_name(X509_VERIFY_PARAM *param, const char *name)
 {
     OPENSSL_free(param->name);
@@ -642,169 +389,19 @@ int X509_VERIFY_PARAM_set1_policies(X509_VERIFY_PARAM *param,
 
 char *X509_VERIFY_PARAM_get0_host(X509_VERIFY_PARAM *param, int idx)
 {
-    X509_BUFFER *buf = sk_X509_BUFFER_value(param->hosts, idx);
-
-    return (buf != NULL) ? (char *)buf->data : NULL;
+    return sk_OPENSSL_STRING_value(param->hosts, idx);
 }
 
 int X509_VERIFY_PARAM_set1_host(X509_VERIFY_PARAM *param,
-    const char *dnsname, size_t len)
+    const char *name, size_t namelen)
 {
-    clear_buffer_stack(¶m->hosts);
-    if (dnsname == NULL)
-        return 1;
-    if (len == 0)
-        len = strlen(dnsname);
-    if (len == 0)
-        return 1;
-    return X509_VERIFY_PARAM_add1_host(param, dnsname, len);
+    return int_x509_param_set_hosts(param, SET_HOST, name, namelen);
 }
 
 int X509_VERIFY_PARAM_add1_host(X509_VERIFY_PARAM *param,
-    const char *dnsname, size_t len)
+    const char *name, size_t namelen)
 {
-    if (dnsname == NULL)
-        return 1;
-    if (len == 0)
-        len = strlen(dnsname);
-    if (len == 0)
-        return 1;
-    if (!validate_string_name(dnsname, &len))
-        return 0;
-    if (param->validate_host != NULL) {
-        if (!param->validate_host(dnsname, len))
-            return 0;
-    } else {
-        if (!validate_hostname_part(dnsname, len, OSSL_CHARSET_ASCII_ALNUM))
-            return 0;
-    }
-    return add_string_to_buffer_stack(¶m->hosts, (const uint8_t *)dnsname, len);
-}
-
-void X509_VERIFY_PARAM_set1_host_input_validation(X509_VERIFY_PARAM *param,
-    int (*validate_host)(const char *name, size_t len))
-{
-    param->validate_host = validate_host;
-}
-
-int X509_VERIFY_PARAM_set1_ip(X509_VERIFY_PARAM *param,
-    const uint8_t *ip, size_t len)
-{
-    clear_buffer_stack(¶m->ips);
-    if (ip == NULL)
-        return 1;
-    return X509_VERIFY_PARAM_add1_ip(param, ip, len);
-}
-
-int X509_VERIFY_PARAM_add1_ip(X509_VERIFY_PARAM *param,
-    const uint8_t *ip, size_t len)
-{
-    if (param->validate_ip != NULL) {
-        if (!param->validate_ip(ip, len))
-            return 0;
-    } else {
-        if (!validate_ip_name(ip, len))
-            return 0;
-    }
-    return add_bytes_to_buffer_stack(¶m->ips, ip, len);
-}
-
-void X509_VERIFY_PARAM_set1_ip_input_validation(X509_VERIFY_PARAM *param,
-    int (*validate_ip)(const uint8_t *name, size_t len))
-{
-    param->validate_ip = validate_ip;
-}
-
-char *X509_VERIFY_PARAM_get0_email(X509_VERIFY_PARAM *param)
-{
-    X509_BUFFER *buf = sk_X509_BUFFER_value(param->rfc822s, 0);
-
-    if ((buf = sk_X509_BUFFER_value(param->rfc822s, 0)) != NULL
-        || (buf = sk_X509_BUFFER_value(param->smtputf8s, 0)) != NULL)
-        return (char *)buf->data;
-
-    return NULL;
-}
-
-int X509_VERIFY_PARAM_set1_email(X509_VERIFY_PARAM *param,
-    const char *email, size_t len)
-{
-    int ret = 0;
-
-    if (X509_VERIFY_PARAM_set1_smtputf8(param, email, len))
-        ret = 1;
-    if (X509_VERIFY_PARAM_set1_rfc822(param, email, len))
-        ret = 1;
-
-    return ret;
-}
-
-int X509_VERIFY_PARAM_set1_smtputf8(X509_VERIFY_PARAM *param,
-    const char *email, size_t len)
-{
-    clear_buffer_stack(¶m->smtputf8s);
-    if (email == NULL)
-        return 1;
-    return X509_VERIFY_PARAM_add1_smtputf8(param, email, len);
-}
-
-int X509_VERIFY_PARAM_add1_smtputf8(X509_VERIFY_PARAM *param,
-    const char *email, size_t len)
-{
-    if (len == 0)
-        len = strlen(email);
-    if (!validate_string_name(email, &len))
-        return 0;
-    if (param->validate_smtputf8 != NULL) {
-        if (!param->validate_smtputf8(email, len))
-            return 0;
-    } else {
-        if (!validate_email_name(email, len, /*rfc822 =*/0))
-            return 0;
-    }
-
-    return add_string_to_buffer_stack(¶m->smtputf8s,
-        (const uint8_t *)email, len);
-}
-
-void X509_VERIFY_PARAM_set1_smtputf8_input_validation(X509_VERIFY_PARAM *param,
-    int (*validate_smtputf8)(const char *name, size_t len))
-{
-    param->validate_smtputf8 = validate_smtputf8;
-}
-
-int X509_VERIFY_PARAM_set1_rfc822(X509_VERIFY_PARAM *param,
-    const char *email, size_t len)
-{
-    clear_buffer_stack(¶m->rfc822s);
-    if (email == NULL)
-        return 1;
-    return X509_VERIFY_PARAM_add1_rfc822(param, email, len);
-}
-
-int X509_VERIFY_PARAM_add1_rfc822(X509_VERIFY_PARAM *param,
-    const char *email, size_t len)
-{
-    if (len == 0)
-        len = strlen(email);
-    if (!validate_string_name(email, &len))
-        return 0;
-    if (param->validate_rfc822 != NULL) {
-        if (!param->validate_rfc822(email, len))
-            return 0;
-    } else {
-        if (!validate_email_name(email, len, /*rfc822 =*/1))
-            return 0;
-    }
-
-    return add_string_to_buffer_stack(¶m->rfc822s,
-        (const uint8_t *)email, len);
-}
-
-void X509_VERIFY_PARAM_set1_rfc822_input_validation(X509_VERIFY_PARAM *param,
-    int (*validate_rfc822)(const char *name, size_t len))
-{
-    param->validate_rfc822 = validate_rfc822;
+    return int_x509_param_set_hosts(param, ADD_HOST, name, namelen);
 }
 
 void X509_VERIFY_PARAM_set_hostflags(X509_VERIFY_PARAM *param,
@@ -841,58 +438,58 @@ void X509_VERIFY_PARAM_move_peername(X509_VERIFY_PARAM *to,
         from->peername = NULL;
 }
 
-static const unsigned char *int_X509_VERIFY_PARAM_get0_ip(X509_VERIFY_PARAM *param, size_t *plen, size_t idx)
+char *X509_VERIFY_PARAM_get0_email(X509_VERIFY_PARAM *param)
 {
-    X509_BUFFER *buf;
+    return param->email;
+}
 
-    if (idx > INT_MAX)
-        return NULL;
+int X509_VERIFY_PARAM_set1_email(X509_VERIFY_PARAM *param,
+    const char *email, size_t emaillen)
+{
+    return int_x509_param_set1(¶m->email, ¶m->emaillen,
+        email, emaillen);
+}
 
-    if (param == NULL || param->ips == NULL) {
+static unsigned char *int_X509_VERIFY_PARAM_get0_ip(X509_VERIFY_PARAM *param, size_t *plen)
+{
+    if (param == NULL || param->ip == NULL) {
         ERR_raise(ERR_LIB_X509, ERR_R_PASSED_NULL_PARAMETER);
         return NULL;
     }
-
-    buf = sk_X509_BUFFER_value(param->ips, (int)idx);
-
-    if (buf != NULL) {
-        if (plen != NULL)
-            *plen = buf->len;
-        return (unsigned char *)buf->data;
-    }
-    return NULL;
+    if (plen != NULL)
+        *plen = param->iplen;
+    return param->ip;
 }
 
 char *X509_VERIFY_PARAM_get1_ip_asc(X509_VERIFY_PARAM *param)
 {
     size_t iplen;
-    const unsigned char *ip = int_X509_VERIFY_PARAM_get0_ip(param, &iplen, 0);
+    unsigned char *ip = int_X509_VERIFY_PARAM_get0_ip(param, &iplen);
 
     return ip == NULL ? NULL : ossl_ipaddr_to_asc(ip, (int)iplen);
 }
 
+int X509_VERIFY_PARAM_set1_ip(X509_VERIFY_PARAM *param,
+    const unsigned char *ip, size_t iplen)
+{
+    if (iplen != 0 && iplen != 4 && iplen != 16) {
+        ERR_raise(ERR_LIB_X509, ERR_R_PASSED_INVALID_ARGUMENT);
+        return 0;
+    }
+    return int_x509_param_set1((char **)¶m->ip, ¶m->iplen,
+        (char *)ip, iplen);
+}
+
 int X509_VERIFY_PARAM_set1_ip_asc(X509_VERIFY_PARAM *param, const char *ipasc)
 {
     unsigned char ipout[16];
-    size_t iplen;
+    size_t iplen = (size_t)ossl_a2i_ipadd(ipout, ipasc);
 
-    if (ipasc == NULL)
-        return X509_VERIFY_PARAM_set1_ip(param, NULL, 0);
-    if ((iplen = (size_t)ossl_a2i_ipadd(ipout, ipasc)) == 0)
+    if (iplen == 0)
         return 0;
     return X509_VERIFY_PARAM_set1_ip(param, ipout, iplen);
 }
 
-int X509_VERIFY_PARAM_add1_ip_asc(X509_VERIFY_PARAM *param, const char *ipasc)
-{
-    unsigned char ipout[16];
-    size_t iplen;
-
-    if ((iplen = (size_t)ossl_a2i_ipadd(ipout, ipasc)) == 0)
-        return 0;
-    return X509_VERIFY_PARAM_add1_ip(param, ipout, iplen);
-}
-
 int X509_VERIFY_PARAM_get_depth(const X509_VERIFY_PARAM *param)
 {
     return param->depth;
@@ -908,6 +505,8 @@ const char *X509_VERIFY_PARAM_get0_name(const X509_VERIFY_PARAM *param)
     return param->name;
 }
 
+#define vpm_empty_id NULL, 0U, NULL, NULL, 0, NULL, 0
+
 /*
  * Default verify parameters: these are used for various applications and can
  * be overridden by the user specified table. NB: the 'name' field *must* be
@@ -915,54 +514,66 @@ const char *X509_VERIFY_PARAM_get0_name(const X509_VERIFY_PARAM *param)
  */
 
 static const X509_VERIFY_PARAM default_table[] = {
-    {
-        .name = "code_sign", /* Code sign parameters */
-        .purpose = X509_PURPOSE_CODE_SIGN,
-        .trust = X509_TRUST_OBJECT_SIGN,
-        .depth = -1,
-        .auth_level = -1,
-    },
-    {
-        .name = "default", /* X509 default parameters */
-        .flags = X509_V_FLAG_TRUSTED_FIRST,
-        .depth = 100,
-        .auth_level = -1,
-    },
-    {
-        .name = "pkcs7", /* S/MIME sign parameters */
-        .purpose = X509_PURPOSE_SMIME_SIGN,
-        .trust = X509_TRUST_EMAIL,
-        .depth = -1,
-        .auth_level = -1,
-    },
-    {
-        .name = "smime_encrypt", /* S/MIME encryption parameters */
-        .purpose = X509_PURPOSE_SMIME_ENCRYPT,
-        .trust = X509_TRUST_EMAIL,
-        .depth = -1,
-        .auth_level = -1,
-    },
-    {
-        .name = "smime_sign", /* S/MIME signature parameters */
-        .purpose = X509_PURPOSE_SMIME_SIGN,
-        .trust = X509_TRUST_EMAIL,
-        .depth = -1,
-        .auth_level = -1,
-    },
-    {
-        .name = "ssl_client", /* SSL/TLS client parameters */
-        .purpose = X509_PURPOSE_SSL_CLIENT,
-        .trust = X509_TRUST_SSL_CLIENT,
-        .depth = -1,
-        .auth_level = -1,
-    },
-    {
-        .name = "ssl_server", /* SSL/TLS server parameters */
-        .purpose = X509_PURPOSE_SSL_SERVER,
-        .trust = X509_TRUST_SSL_SERVER,
-        .depth = -1,
-        .auth_level = -1,
-    }
+    { "code_sign", /* Code sign parameters */
+        0, /* check time to use */
+        0, /* inheritance flags */
+        0, /* flags */
+        X509_PURPOSE_CODE_SIGN, /* purpose */
+        X509_TRUST_OBJECT_SIGN, /* trust */
+        -1, /* depth */
+        -1, /* auth_level */
+        NULL, /* policies */
+        vpm_empty_id },
+    { "default", /* X509 default parameters */
+        0, /* check time to use */
+        0, /* inheritance flags */
+        X509_V_FLAG_TRUSTED_FIRST, /* flags */
+        0, /* purpose */
+        0, /* trust */
+        100, /* depth */
+        -1, /* auth_level */
+        NULL, /* policies */
+        vpm_empty_id },
+    { "pkcs7", /* S/MIME sign parameters */
+        0, /* check time to use */
+        0, /* inheritance flags */
+        0, /* flags */
+        X509_PURPOSE_SMIME_SIGN, /* purpose */
+        X509_TRUST_EMAIL, /* trust */
+        -1, /* depth */
+        -1, /* auth_level */
+        NULL, /* policies */
+        vpm_empty_id },
+    { "smime_sign", /* S/MIME sign parameters */
+        0, /* check time to use */
+        0, /* inheritance flags */
+        0, /* flags */
+        X509_PURPOSE_SMIME_SIGN, /* purpose */
+        X509_TRUST_EMAIL, /* trust */
+        -1, /* depth */
+        -1, /* auth_level */
+        NULL, /* policies */
+        vpm_empty_id },
+    { "ssl_client", /* SSL/TLS client parameters */
+        0, /* check time to use */
+        0, /* inheritance flags */
+        0, /* flags */
+        X509_PURPOSE_SSL_CLIENT, /* purpose */
+        X509_TRUST_SSL_CLIENT, /* trust */
+        -1, /* depth */
+        -1, /* auth_level */
+        NULL, /* policies */
+        vpm_empty_id },
+    { "ssl_server", /* SSL/TLS server parameters */
+        0, /* check time to use */
+        0, /* inheritance flags */
+        0, /* flags */
+        X509_PURPOSE_SSL_SERVER, /* purpose */
+        X509_TRUST_SSL_SERVER, /* trust */
+        -1, /* depth */
+        -1, /* auth_level */
+        NULL, /* policies */
+        vpm_empty_id }
 };
 
 static STACK_OF(X509_VERIFY_PARAM) *param_table = NULL;
diff --git a/crypto/x509/x509aset.c b/crypto/x509/x509aset.c
index 17b988c67c..03afc4ae56 100644
--- a/crypto/x509/x509aset.c
+++ b/crypto/x509/x509aset.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -12,8 +12,6 @@
 #include 
 #include "x509_acert.h"
 
-#include 
-
 static int replace_gentime(ASN1_STRING **dest, const ASN1_GENERALIZEDTIME *src)
 {
     ASN1_STRING *s;
diff --git a/crypto/x509/x509cset.c b/crypto/x509/x509cset.c
index ec3e1f5360..8e0874aa1d 100644
--- a/crypto/x509/x509cset.c
+++ b/crypto/x509/x509cset.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2001-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -75,7 +75,7 @@ int X509_CRL_up_ref(X509_CRL *crl)
 {
     int i;
 
-    if (!CRYPTO_UP_REF(&crl->references, &i))
+    if (CRYPTO_UP_REF(&crl->references, &i) <= 0)
         return 0;
 
     REF_PRINT_COUNT("X509_CRL", i, crl);
@@ -110,7 +110,7 @@ ASN1_TIME *X509_CRL_get_nextUpdate(X509_CRL *crl)
 }
 #endif
 
-const X509_NAME *X509_CRL_get_issuer(const X509_CRL *crl)
+X509_NAME *X509_CRL_get_issuer(const X509_CRL *crl)
 {
     return crl->crl.issuer;
 }
diff --git a/crypto/x509/x509name.c b/crypto/x509/x509name.c
index 58167d9a78..6345e3273e 100644
--- a/crypto/x509/x509name.c
+++ b/crypto/x509/x509name.c
@@ -1,12 +1,11 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
  * in the file LICENSE in the source distribution or at
  * https://www.openssl.org/source/license.html
  */
-#include "internal/deprecated.h"
 
 #include 
 #include "internal/cryptlib.h"
@@ -17,8 +16,6 @@
 #include 
 #include "crypto/x509.h"
 
-OSSL_BEGIN_ALLOW_DEPRECATED
-#if !defined(OPENSSL_NO_DEPRECATED_4_0)
 int X509_NAME_get_text_by_NID(const X509_NAME *name, int nid,
     char *buf, int len)
 {
@@ -49,8 +46,6 @@ int X509_NAME_get_text_by_OBJ(const X509_NAME *name, const ASN1_OBJECT *obj,
     buf[i] = '\0';
     return i;
 }
-#endif /* !defined(OPENSSL_NO_DEPRECATED_4_0) */
-OSSL_END_ALLOW_DEPRECATED
 
 int X509_NAME_entry_count(const X509_NAME *name)
 {
@@ -94,7 +89,7 @@ int X509_NAME_get_index_by_OBJ(const X509_NAME *name, const ASN1_OBJECT *obj,
     return -1;
 }
 
-const X509_NAME_ENTRY *X509_NAME_get_entry(const X509_NAME *name, int loc)
+X509_NAME_ENTRY *X509_NAME_get_entry(const X509_NAME *name, int loc)
 {
     if (name == NULL || sk_X509_NAME_ENTRY_num(name->entries) <= loc
         || loc < 0)
@@ -332,12 +327,9 @@ int X509_NAME_ENTRY_set_data(X509_NAME_ENTRY *ne, int type,
                    OBJ_obj2nid(ne->object))
             ? 1
             : 0;
-    if (len < -1)
-        return 0;
-    if (len == -1)
-        i = ASN1_STRING_set_string(ne->value, (const char *)bytes);
-    else
-        i = ASN1_STRING_set_data(ne->value, bytes, (size_t)len);
+    if (len < 0)
+        len = (int)strlen((const char *)bytes);
+    i = ASN1_STRING_set(ne->value, bytes, len);
     if (!i)
         return 0;
     if (type != V_ASN1_UNDEF) {
@@ -349,14 +341,14 @@ int X509_NAME_ENTRY_set_data(X509_NAME_ENTRY *ne, int type,
     return 1;
 }
 
-const ASN1_OBJECT *X509_NAME_ENTRY_get_object(const X509_NAME_ENTRY *ne)
+ASN1_OBJECT *X509_NAME_ENTRY_get_object(const X509_NAME_ENTRY *ne)
 {
     if (ne == NULL)
         return NULL;
     return ne->object;
 }
 
-const ASN1_STRING *X509_NAME_ENTRY_get_data(const X509_NAME_ENTRY *ne)
+ASN1_STRING *X509_NAME_ENTRY_get_data(const X509_NAME_ENTRY *ne)
 {
     if (ne == NULL)
         return NULL;
diff --git a/crypto/x509/x_all.c b/crypto/x509/x_all.c
index ef16a7fc88..1de8274c28 100644
--- a/crypto/x509/x_all.c
+++ b/crypto/x509/x_all.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -25,111 +25,12 @@
 #include 
 #include 
 #include "internal/asn1.h"
-#include "crypto/asn1.h"
 #include "crypto/pkcs7.h"
 #include "crypto/x509.h"
 #include "crypto/x509_acert.h"
 #include "crypto/rsa.h"
-#include "x509_local.h"
 
-static void *RSA_new_thunk(void)
-{
-    return RSA_new();
-}
-
-static void *d2i_RSA_PUBKEY_thunk(void **a, const unsigned char **in, long len)
-{
-    return d2i_RSA_PUBKEY((RSA **)a, in, len);
-}
-
-static int i2d_RSA_PUBKEY_thunk(const void *a, unsigned char **out)
-{
-    return i2d_RSA_PUBKEY((const RSA *)a, out);
-}
-
-static void *EVP_PKEY_new_thunk(void)
-{
-    return EVP_PKEY_new();
-}
-
-static void *d2i_AutoPrivateKey_thunk(void **a, const unsigned char **in,
-    long len)
-{
-    return d2i_AutoPrivateKey((EVP_PKEY **)a, in, len);
-}
-
-static void *d2i_PUBKEY_thunk(void **a, const unsigned char **in, long len)
-{
-    return d2i_PUBKEY((EVP_PKEY **)a, in, len);
-}
-
-static int i2d_PrivateKey_thunk(const void *a, unsigned char **out)
-{
-    return i2d_PrivateKey((const EVP_PKEY *)a, out);
-}
-
-static int i2d_PUBKEY_thunk(const void *a, unsigned char **out)
-{
-    return i2d_PUBKEY((const EVP_PKEY *)a, out);
-}
-
-#ifndef OPENSSL_NO_DSA
-static void *DSA_new_thunk(void)
-{
-    return DSA_new();
-}
-
-static void *d2i_DSAPrivateKey_thunk(void **a, const unsigned char **in,
-    long len)
-{
-    return d2i_DSAPrivateKey((DSA **)a, in, len);
-}
-
-static int i2d_DSAPrivateKey_thunk(const void *a, unsigned char **out)
-{
-    return i2d_DSAPrivateKey((const DSA *)a, out);
-}
-
-static void *d2i_DSA_PUBKEY_thunk(void **a, const unsigned char **in, long len)
-{
-    return d2i_DSA_PUBKEY((DSA **)a, in, len);
-}
-
-static int i2d_DSA_PUBKEY_thunk(const void *a, unsigned char **out)
-{
-    return i2d_DSA_PUBKEY((const DSA *)a, out);
-}
-#endif
-
-#ifndef OPENSSL_NO_EC
-static void *EC_KEY_new_thunk(void)
-{
-    return EC_KEY_new();
-}
-
-static void *d2i_EC_PUBKEY_thunk(void **a, const unsigned char **in, long len)
-{
-    return d2i_EC_PUBKEY((EC_KEY **)a, in, len);
-}
-
-static int i2d_EC_PUBKEY_thunk(const void *a, unsigned char **out)
-{
-    return i2d_EC_PUBKEY((const EC_KEY *)a, out);
-}
-
-static void *d2i_ECPrivateKey_thunk(void **a, const unsigned char **in,
-    long len)
-{
-    return d2i_ECPrivateKey((EC_KEY **)a, in, len);
-}
-
-static int i2d_ECPrivateKey_thunk(const void *a, unsigned char **out)
-{
-    return i2d_ECPrivateKey((const EC_KEY *)a, out);
-}
-#endif
-
-int X509_verify(const X509 *a, EVP_PKEY *r)
+int X509_verify(X509 *a, EVP_PKEY *r)
 {
     if (X509_ALGOR_cmp(&a->sig_alg, &a->cert_info.signature) != 0)
         return 0;
@@ -173,32 +74,14 @@ int NETSCAPE_SPKI_verify(NETSCAPE_SPKI *a, EVP_PKEY *r)
         &a->sig_algor, a->signature, a->spkac, r);
 }
 
-/* Detect invalid empty SKID or AKID extensions. */
-
-static int bad_keyid_exts(const STACK_OF(X509_EXTENSION) *exts)
-{
-    int i, n = sk_X509_EXTENSION_num(exts);
-
-    for (i = 0; i < n; ++i) {
-        X509_EXTENSION *ext = sk_X509_EXTENSION_value(exts, i);
-
-        if (ossl_ignored_x509_extension(ext, X509V3_ADD_DEFAULT))
-            return 1;
-    }
-    return 0;
-}
-
 int X509_sign(X509 *x, EVP_PKEY *pkey, const EVP_MD *md)
 {
-    const STACK_OF(X509_EXTENSION) *exts;
-
     if (x == NULL) {
         ERR_raise(ERR_LIB_X509, ERR_R_PASSED_NULL_PARAMETER);
         return 0;
     }
-    if ((exts = X509_get0_extensions(x)) != NULL
-        && sk_X509_EXTENSION_num(exts) > 0
-        && (bad_keyid_exts(exts) || !X509_set_version(x, X509_VERSION_3)))
+    if (sk_X509_EXTENSION_num(X509_get0_extensions(x)) > 0
+        && !X509_set_version(x, X509_VERSION_3))
         return 0;
 
     /*
@@ -216,14 +99,10 @@ int X509_sign(X509 *x, EVP_PKEY *pkey, const EVP_MD *md)
 
 int X509_sign_ctx(X509 *x, EVP_MD_CTX *ctx)
 {
-    const STACK_OF(X509_EXTENSION) *exts;
-
     if (x == NULL) {
         ERR_raise(ERR_LIB_X509, ERR_R_PASSED_NULL_PARAMETER);
         return 0;
     }
-    if ((exts = X509_get0_extensions(x)) != NULL && bad_keyid_exts(exts))
-        return 0;
     if (sk_X509_EXTENSION_num(X509_get0_extensions(x)) > 0
         && !X509_set_version(x, X509_VERSION_3))
         return 0;
@@ -260,18 +139,10 @@ X509 *X509_load_http(const char *url, BIO *bio, BIO *rbio, int timeout)
 
 int X509_REQ_sign(X509_REQ *x, EVP_PKEY *pkey, const EVP_MD *md)
 {
-    STACK_OF(X509_EXTENSION) *exts;
-    int bad = 0;
-
     if (x == NULL) {
         ERR_raise(ERR_LIB_X509, ERR_R_PASSED_NULL_PARAMETER);
         return 0;
     }
-    if ((exts = ossl_x509_req_get1_extensions_by_nid(x, NID_ext_req)) != NULL)
-        bad = bad_keyid_exts(exts);
-    sk_X509_EXTENSION_pop_free(exts, X509_EXTENSION_free);
-    if (bad)
-        return 0;
     x->req_info.enc.modified = 1;
     return ASN1_item_sign_ex(ASN1_ITEM_rptr(X509_REQ_INFO), &x->sig_alg, NULL,
         x->signature, &x->req_info, NULL,
@@ -280,18 +151,10 @@ int X509_REQ_sign(X509_REQ *x, EVP_PKEY *pkey, const EVP_MD *md)
 
 int X509_REQ_sign_ctx(X509_REQ *x, EVP_MD_CTX *ctx)
 {
-    STACK_OF(X509_EXTENSION) *exts;
-    int bad = 0;
-
     if (x == NULL) {
         ERR_raise(ERR_LIB_X509, ERR_R_PASSED_NULL_PARAMETER);
         return 0;
     }
-    if ((exts = ossl_x509_req_get1_extensions_by_nid(x, NID_ext_req)) != NULL)
-        bad = bad_keyid_exts(exts);
-    sk_X509_EXTENSION_pop_free(exts, X509_EXTENSION_free);
-    if (bad)
-        return 0;
     x->req_info.enc.modified = 1;
     return ASN1_item_sign_ctx(ASN1_ITEM_rptr(X509_REQ_INFO),
         &x->sig_alg, NULL, x->signature, &x->req_info,
@@ -487,8 +350,10 @@ RSA *d2i_RSAPublicKey_fp(FILE *fp, RSA **rsa)
 
 RSA *d2i_RSA_PUBKEY_fp(FILE *fp, RSA **rsa)
 {
-    return ASN1_d2i_fp(RSA_new_thunk, d2i_RSA_PUBKEY_thunk, fp,
-        CHECKED_PPTR_OF(RSA, rsa));
+    return ASN1_d2i_fp((void *(*)(void))
+                           RSA_new,
+        (D2I_OF(void))d2i_RSA_PUBKEY, fp,
+        (void **)rsa);
 }
 
 int i2d_RSAPublicKey_fp(FILE *fp, const RSA *rsa)
@@ -498,7 +363,7 @@ int i2d_RSAPublicKey_fp(FILE *fp, const RSA *rsa)
 
 int i2d_RSA_PUBKEY_fp(FILE *fp, const RSA *rsa)
 {
-    return ASN1_i2d_fp(i2d_RSA_PUBKEY_thunk, fp, rsa);
+    return ASN1_i2d_fp((I2D_OF(void))i2d_RSA_PUBKEY, fp, rsa);
 }
 #endif
 
@@ -519,8 +384,7 @@ RSA *d2i_RSAPublicKey_bio(BIO *bp, RSA **rsa)
 
 RSA *d2i_RSA_PUBKEY_bio(BIO *bp, RSA **rsa)
 {
-    return ASN1_d2i_bio(RSA_new_thunk, d2i_RSA_PUBKEY_thunk, bp,
-        CHECKED_PPTR_OF(RSA, rsa));
+    return ASN1_d2i_bio_of(RSA, RSA_new, d2i_RSA_PUBKEY, bp, rsa);
 }
 
 int i2d_RSAPublicKey_bio(BIO *bp, const RSA *rsa)
@@ -530,55 +394,50 @@ int i2d_RSAPublicKey_bio(BIO *bp, const RSA *rsa)
 
 int i2d_RSA_PUBKEY_bio(BIO *bp, const RSA *rsa)
 {
-    return ASN1_i2d_bio(i2d_RSA_PUBKEY_thunk, bp, rsa);
+    return ASN1_i2d_bio_of(RSA, i2d_RSA_PUBKEY, bp, rsa);
 }
 
 #ifndef OPENSSL_NO_DSA
 #ifndef OPENSSL_NO_STDIO
 DSA *d2i_DSAPrivateKey_fp(FILE *fp, DSA **dsa)
 {
-    return ASN1_d2i_fp(DSA_new_thunk, d2i_DSAPrivateKey_thunk, fp,
-        CHECKED_PPTR_OF(DSA, dsa));
+    return ASN1_d2i_fp_of(DSA, DSA_new, d2i_DSAPrivateKey, fp, dsa);
 }
 
 int i2d_DSAPrivateKey_fp(FILE *fp, const DSA *dsa)
 {
-    return ASN1_i2d_fp(i2d_DSAPrivateKey_thunk, fp,
-        CHECKED_PTR_OF(const DSA, dsa));
+    return ASN1_i2d_fp_of(DSA, i2d_DSAPrivateKey, fp, dsa);
 }
 
 DSA *d2i_DSA_PUBKEY_fp(FILE *fp, DSA **dsa)
 {
-    return ASN1_d2i_fp(DSA_new_thunk, d2i_DSA_PUBKEY_thunk, fp,
-        CHECKED_PPTR_OF(DSA, dsa));
+    return ASN1_d2i_fp_of(DSA, DSA_new, d2i_DSA_PUBKEY, fp, dsa);
 }
 
 int i2d_DSA_PUBKEY_fp(FILE *fp, const DSA *dsa)
 {
-    return ASN1_i2d_fp(i2d_DSA_PUBKEY_thunk, fp,
-        CHECKED_PTR_OF(const DSA, dsa));
+    return ASN1_i2d_fp_of(DSA, i2d_DSA_PUBKEY, fp, dsa);
 }
 #endif
 
 DSA *d2i_DSAPrivateKey_bio(BIO *bp, DSA **dsa)
 {
-    return ASN1_d2i_bio(DSA_new_thunk, d2i_DSAPrivateKey_thunk, bp, (void **)dsa);
+    return ASN1_d2i_bio_of(DSA, DSA_new, d2i_DSAPrivateKey, bp, dsa);
 }
 
 int i2d_DSAPrivateKey_bio(BIO *bp, const DSA *dsa)
 {
-    return ASN1_i2d_bio(i2d_DSAPrivateKey_thunk, bp,
-        CHECKED_PTR_OF(const DSA, dsa));
+    return ASN1_i2d_bio_of(DSA, i2d_DSAPrivateKey, bp, dsa);
 }
 
 DSA *d2i_DSA_PUBKEY_bio(BIO *bp, DSA **dsa)
 {
-    return ASN1_d2i_bio(DSA_new_thunk, d2i_DSA_PUBKEY_thunk, bp, (void **)dsa);
+    return ASN1_d2i_bio_of(DSA, DSA_new, d2i_DSA_PUBKEY, bp, dsa);
 }
 
 int i2d_DSA_PUBKEY_bio(BIO *bp, const DSA *dsa)
 {
-    return ASN1_i2d_bio(i2d_DSA_PUBKEY_thunk, bp, dsa);
+    return ASN1_i2d_bio_of(DSA, i2d_DSA_PUBKEY, bp, dsa);
 }
 
 #endif
@@ -587,56 +446,49 @@ int i2d_DSA_PUBKEY_bio(BIO *bp, const DSA *dsa)
 #ifndef OPENSSL_NO_STDIO
 EC_KEY *d2i_EC_PUBKEY_fp(FILE *fp, EC_KEY **eckey)
 {
-    return ASN1_d2i_fp(EC_KEY_new_thunk, d2i_EC_PUBKEY_thunk, fp,
-        CHECKED_PPTR_OF(EC_KEY, eckey));
+    return ASN1_d2i_fp_of(EC_KEY, EC_KEY_new, d2i_EC_PUBKEY, fp, eckey);
 }
 
 int i2d_EC_PUBKEY_fp(FILE *fp, const EC_KEY *eckey)
 {
-    return ASN1_i2d_fp(i2d_EC_PUBKEY_thunk, fp, CHECKED_PTR_OF(const EC_KEY, eckey));
+    return ASN1_i2d_fp_of(EC_KEY, i2d_EC_PUBKEY, fp, eckey);
 }
 
 EC_KEY *d2i_ECPrivateKey_fp(FILE *fp, EC_KEY **eckey)
 {
-    return ASN1_d2i_fp(EC_KEY_new_thunk, d2i_ECPrivateKey_thunk, fp,
-        CHECKED_PPTR_OF(EC_KEY, eckey));
+    return ASN1_d2i_fp_of(EC_KEY, EC_KEY_new, d2i_ECPrivateKey, fp, eckey);
 }
 
 int i2d_ECPrivateKey_fp(FILE *fp, const EC_KEY *eckey)
 {
-    return ASN1_i2d_fp(i2d_ECPrivateKey_thunk, fp,
-        CHECKED_PTR_OF(const EC_KEY, eckey));
+    return ASN1_i2d_fp_of(EC_KEY, i2d_ECPrivateKey, fp, eckey);
 }
 #endif
 EC_KEY *d2i_EC_PUBKEY_bio(BIO *bp, EC_KEY **eckey)
 {
-    return ASN1_d2i_bio(EC_KEY_new_thunk, d2i_EC_PUBKEY_thunk, bp,
-        CHECKED_PPTR_OF(EC_KEY, eckey));
+    return ASN1_d2i_bio_of(EC_KEY, EC_KEY_new, d2i_EC_PUBKEY, bp, eckey);
 }
 
 int i2d_EC_PUBKEY_bio(BIO *bp, const EC_KEY *ecdsa)
 {
-    return ASN1_i2d_bio(i2d_EC_PUBKEY_thunk, bp,
-        CHECKED_PTR_OF(const EC_KEY, ecdsa));
+    return ASN1_i2d_bio_of(EC_KEY, i2d_EC_PUBKEY, bp, ecdsa);
 }
 
 EC_KEY *d2i_ECPrivateKey_bio(BIO *bp, EC_KEY **eckey)
 {
-    return ASN1_d2i_bio(EC_KEY_new_thunk, d2i_ECPrivateKey_thunk, bp,
-        CHECKED_PPTR_OF(EC_KEY, eckey));
+    return ASN1_d2i_bio_of(EC_KEY, EC_KEY_new, d2i_ECPrivateKey, bp, eckey);
 }
 
 int i2d_ECPrivateKey_bio(BIO *bp, const EC_KEY *eckey)
 {
-    return ASN1_i2d_bio(i2d_ECPrivateKey_thunk, bp,
-        CHECKED_PTR_OF(const EC_KEY, eckey));
+    return ASN1_i2d_bio_of(EC_KEY, i2d_ECPrivateKey, bp, eckey);
 }
 #endif
 
 int X509_pubkey_digest(const X509 *data, const EVP_MD *type,
     unsigned char *md, unsigned int *len)
 {
-    const ASN1_BIT_STRING *key = X509_get0_pubkey_bitstr(data);
+    ASN1_BIT_STRING *key = X509_get0_pubkey_bitstr(data);
 
     if (key == NULL)
         return 0;
@@ -732,7 +584,8 @@ ASN1_OCTET_STRING *X509_digest_sig(const X509 *cert,
         }
     } else if ((md = EVP_MD_fetch(cert->libctx, OBJ_nid2sn(mdnid),
                     cert->propq))
-        == NULL) {
+            == NULL
+        && (md = (EVP_MD *)EVP_get_digestbynid(mdnid)) == NULL) {
         ERR_raise(ERR_LIB_X509, X509_R_UNSUPPORTED_ALGORITHM);
         return NULL;
     }
@@ -797,57 +650,61 @@ int PKCS7_ISSUER_AND_SERIAL_digest(PKCS7_ISSUER_AND_SERIAL *data,
 #ifndef OPENSSL_NO_STDIO
 X509_SIG *d2i_PKCS8_fp(FILE *fp, X509_SIG **p8)
 {
-    return ASN1_item_d2i_fp(ASN1_ITEM_rptr(X509_SIG), fp, p8);
+    return ASN1_d2i_fp_of(X509_SIG, X509_SIG_new, d2i_X509_SIG, fp, p8);
 }
 
 int i2d_PKCS8_fp(FILE *fp, const X509_SIG *p8)
 {
-    return ASN1_item_i2d_fp(ASN1_ITEM_rptr(X509_SIG), fp, p8);
+    return ASN1_i2d_fp_of(X509_SIG, i2d_X509_SIG, fp, p8);
 }
 #endif
 
 X509_SIG *d2i_PKCS8_bio(BIO *bp, X509_SIG **p8)
 {
-    return ASN1_item_d2i_bio(ASN1_ITEM_rptr(X509_SIG), bp, p8);
+    return ASN1_d2i_bio_of(X509_SIG, X509_SIG_new, d2i_X509_SIG, bp, p8);
 }
 
 int i2d_PKCS8_bio(BIO *bp, const X509_SIG *p8)
 {
-    return ASN1_item_i2d_bio(ASN1_ITEM_rptr(X509_SIG), bp, p8);
+    return ASN1_i2d_bio_of(X509_SIG, i2d_X509_SIG, bp, p8);
 }
 
 #ifndef OPENSSL_NO_STDIO
 X509_PUBKEY *d2i_X509_PUBKEY_fp(FILE *fp, X509_PUBKEY **xpk)
 {
-    return ASN1_item_d2i_fp(ASN1_ITEM_rptr(X509_PUBKEY), fp, xpk);
+    return ASN1_d2i_fp_of(X509_PUBKEY, X509_PUBKEY_new, d2i_X509_PUBKEY,
+        fp, xpk);
 }
 
 int i2d_X509_PUBKEY_fp(FILE *fp, const X509_PUBKEY *xpk)
 {
-    return ASN1_item_i2d_fp(ASN1_ITEM_rptr(X509_PUBKEY), fp, xpk);
+    return ASN1_i2d_fp_of(X509_PUBKEY, i2d_X509_PUBKEY, fp, xpk);
 }
 #endif
 
 X509_PUBKEY *d2i_X509_PUBKEY_bio(BIO *bp, X509_PUBKEY **xpk)
 {
-    return ASN1_item_d2i_bio(ASN1_ITEM_rptr(X509_PUBKEY), bp, xpk);
+    return ASN1_d2i_bio_of(X509_PUBKEY, X509_PUBKEY_new, d2i_X509_PUBKEY,
+        bp, xpk);
 }
 
 int i2d_X509_PUBKEY_bio(BIO *bp, const X509_PUBKEY *xpk)
 {
-    return ASN1_item_i2d_bio(ASN1_ITEM_rptr(X509_PUBKEY), bp, xpk);
+    return ASN1_i2d_bio_of(X509_PUBKEY, i2d_X509_PUBKEY, bp, xpk);
 }
 
 #ifndef OPENSSL_NO_STDIO
 PKCS8_PRIV_KEY_INFO *d2i_PKCS8_PRIV_KEY_INFO_fp(FILE *fp,
     PKCS8_PRIV_KEY_INFO **p8inf)
 {
-    return ASN1_item_d2i_fp(ASN1_ITEM_rptr(PKCS8_PRIV_KEY_INFO), fp, p8inf);
+    return ASN1_d2i_fp_of(PKCS8_PRIV_KEY_INFO, PKCS8_PRIV_KEY_INFO_new,
+        d2i_PKCS8_PRIV_KEY_INFO, fp, p8inf);
 }
 
 int i2d_PKCS8_PRIV_KEY_INFO_fp(FILE *fp, const PKCS8_PRIV_KEY_INFO *p8inf)
 {
-    return ASN1_item_i2d_fp(ASN1_ITEM_rptr(PKCS8_PRIV_KEY_INFO), fp, p8inf);
+    return ASN1_i2d_fp_of(PKCS8_PRIV_KEY_INFO, i2d_PKCS8_PRIV_KEY_INFO, fp,
+        p8inf);
 }
 
 int i2d_PKCS8PrivateKeyInfo_fp(FILE *fp, const EVP_PKEY *key)
@@ -865,14 +722,12 @@ int i2d_PKCS8PrivateKeyInfo_fp(FILE *fp, const EVP_PKEY *key)
 
 int i2d_PrivateKey_fp(FILE *fp, const EVP_PKEY *pkey)
 {
-    return ASN1_i2d_fp(i2d_PrivateKey_thunk, fp,
-        CHECKED_PTR_OF(const EVP_PKEY, pkey));
+    return ASN1_i2d_fp_of(EVP_PKEY, i2d_PrivateKey, fp, pkey);
 }
 
 EVP_PKEY *d2i_PrivateKey_fp(FILE *fp, EVP_PKEY **a)
 {
-    return ASN1_d2i_fp(EVP_PKEY_new_thunk, d2i_AutoPrivateKey_thunk,
-        fp, CHECKED_PPTR_OF(EVP_PKEY, a));
+    return ASN1_d2i_fp_of(EVP_PKEY, EVP_PKEY_new, d2i_AutoPrivateKey, fp, a);
 }
 
 EVP_PKEY *d2i_PrivateKey_ex_fp(FILE *fp, EVP_PKEY **a, OSSL_LIB_CTX *libctx,
@@ -893,8 +748,7 @@ EVP_PKEY *d2i_PrivateKey_ex_fp(FILE *fp, EVP_PKEY **a, OSSL_LIB_CTX *libctx,
 
 int i2d_PUBKEY_fp(FILE *fp, const EVP_PKEY *pkey)
 {
-    return ASN1_i2d_fp(i2d_PUBKEY_thunk, fp,
-        CHECKED_PTR_OF(const EVP_PKEY, pkey));
+    return ASN1_i2d_fp_of(EVP_PKEY, i2d_PUBKEY, fp, pkey);
 }
 
 EVP_PKEY *d2i_PUBKEY_ex_fp(FILE *fp, EVP_PKEY **a, OSSL_LIB_CTX *libctx,
@@ -915,8 +769,7 @@ EVP_PKEY *d2i_PUBKEY_ex_fp(FILE *fp, EVP_PKEY **a, OSSL_LIB_CTX *libctx,
 
 EVP_PKEY *d2i_PUBKEY_fp(FILE *fp, EVP_PKEY **a)
 {
-    return ASN1_d2i_fp(EVP_PKEY_new_thunk, d2i_PUBKEY_thunk, fp,
-        CHECKED_PPTR_OF(EVP_PKEY, a));
+    return ASN1_d2i_fp_of(EVP_PKEY, EVP_PKEY_new, d2i_PUBKEY, fp, a);
 }
 
 #endif
@@ -924,12 +777,14 @@ EVP_PKEY *d2i_PUBKEY_fp(FILE *fp, EVP_PKEY **a)
 PKCS8_PRIV_KEY_INFO *d2i_PKCS8_PRIV_KEY_INFO_bio(BIO *bp,
     PKCS8_PRIV_KEY_INFO **p8inf)
 {
-    return ASN1_item_d2i_bio(ASN1_ITEM_rptr(PKCS8_PRIV_KEY_INFO), bp, p8inf);
+    return ASN1_d2i_bio_of(PKCS8_PRIV_KEY_INFO, PKCS8_PRIV_KEY_INFO_new,
+        d2i_PKCS8_PRIV_KEY_INFO, bp, p8inf);
 }
 
 int i2d_PKCS8_PRIV_KEY_INFO_bio(BIO *bp, const PKCS8_PRIV_KEY_INFO *p8inf)
 {
-    return ASN1_item_i2d_bio(ASN1_ITEM_rptr(PKCS8_PRIV_KEY_INFO), bp, p8inf);
+    return ASN1_i2d_bio_of(PKCS8_PRIV_KEY_INFO, i2d_PKCS8_PRIV_KEY_INFO, bp,
+        p8inf);
 }
 
 int i2d_PKCS8PrivateKeyInfo_bio(BIO *bp, const EVP_PKEY *key)
@@ -947,14 +802,12 @@ int i2d_PKCS8PrivateKeyInfo_bio(BIO *bp, const EVP_PKEY *key)
 
 int i2d_PrivateKey_bio(BIO *bp, const EVP_PKEY *pkey)
 {
-    return ASN1_i2d_bio(i2d_PrivateKey_thunk, bp,
-        CHECKED_PTR_OF(const EVP_PKEY, pkey));
+    return ASN1_i2d_bio_of(EVP_PKEY, i2d_PrivateKey, bp, pkey);
 }
 
 EVP_PKEY *d2i_PrivateKey_bio(BIO *bp, EVP_PKEY **a)
 {
-    return ASN1_d2i_bio(EVP_PKEY_new_thunk, d2i_AutoPrivateKey_thunk,
-        bp, CHECKED_PPTR_OF(EVP_PKEY, a));
+    return ASN1_d2i_bio_of(EVP_PKEY, EVP_PKEY_new, d2i_AutoPrivateKey, bp, a);
 }
 
 EVP_PKEY *d2i_PrivateKey_ex_bio(BIO *bp, EVP_PKEY **a, OSSL_LIB_CTX *libctx,
@@ -978,8 +831,7 @@ err:
 
 int i2d_PUBKEY_bio(BIO *bp, const EVP_PKEY *pkey)
 {
-    return ASN1_i2d_bio(i2d_PUBKEY_thunk, bp,
-        CHECKED_PTR_OF(const EVP_PKEY, pkey));
+    return ASN1_i2d_bio_of(EVP_PKEY, i2d_PUBKEY, bp, pkey);
 }
 
 EVP_PKEY *d2i_PUBKEY_ex_bio(BIO *bp, EVP_PKEY **a, OSSL_LIB_CTX *libctx,
@@ -1003,8 +855,7 @@ err:
 
 EVP_PKEY *d2i_PUBKEY_bio(BIO *bp, EVP_PKEY **a)
 {
-    return ASN1_d2i_bio(EVP_PKEY_new_thunk, d2i_PUBKEY_thunk, bp,
-        CHECKED_PPTR_OF(EVP_PKEY, a));
+    return ASN1_d2i_bio_of(EVP_PKEY, EVP_PKEY_new, d2i_PUBKEY, bp, a);
 }
 
 #ifndef OPENSSL_NO_STDIO
diff --git a/crypto/x509/x_attrib.c b/crypto/x509/x_attrib.c
index 648d64bcf3..f4c225a8ff 100644
--- a/crypto/x509/x_attrib.c
+++ b/crypto/x509/x_attrib.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -15,8 +15,6 @@
 #include "x509_local.h"
 #include 
 
-#include 
-
 /*-
  * X509_ATTRIBUTE: this has the following form:
  *
diff --git a/crypto/x509/x_crl.c b/crypto/x509/x_crl.c
index e19f0e181d..7314d30dbd 100644
--- a/crypto/x509/x_crl.c
+++ b/crypto/x509/x_crl.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -8,6 +8,7 @@
  */
 
 #include 
+#include "internal/cryptlib.h"
 #include 
 #include 
 #include "crypto/x509.h"
@@ -79,6 +80,7 @@ ASN1_SEQUENCE_enc(X509_CRL_INFO, enc, crl_inf_cb) = {
 
 static int crl_set_issuers(X509_CRL *crl)
 {
+
     int i, j;
     GENERAL_NAMES *most_recent_issuer, *gtmp;
     STACK_OF(X509_REVOKED) *revoked;
@@ -89,8 +91,6 @@ static int crl_set_issuers(X509_CRL *crl)
      */
     if (crl->crl.lastUpdate == NULL) {
         crl->flags |= EXFLAG_INVALID;
-        ERR_raise_data(ERR_LIB_ASN1, ASN1_R_ILLEGAL_TIME_VALUE,
-            "lastUpdate in CRL is not well-formed");
         return 0;
     }
 
@@ -121,8 +121,6 @@ static int crl_set_issuers(X509_CRL *crl)
          */
         if ((rev_date = X509_REVOKED_get0_revocationDate(rev)) == NULL) {
             crl->flags |= EXFLAG_INVALID;
-            ERR_raise_data(ERR_LIB_ASN1, ASN1_R_ILLEGAL_TIME_VALUE,
-                "revocationDate in CRL is not well-formed");
             return 0;
         }
 
@@ -141,8 +139,6 @@ static int crl_set_issuers(X509_CRL *crl)
              */
             if (crl->idp == NULL || !crl->idp->indirectCRL) {
                 crl->flags |= EXFLAG_INVALID;
-                ERR_raise_data(ERR_LIB_ASN1, ASN1_R_INVALID_VALUE,
-                    "CRL Certificate Issuer extension requires Indirect CRL flag to be set");
                 GENERAL_NAMES_free(gtmp);
                 return 0;
             }
@@ -175,6 +171,7 @@ static int crl_set_issuers(X509_CRL *crl)
             rev->reason = CRL_REASON_NONE;
 
         /* Check for critical CRL entry extensions and validate time. */
+
         exts = rev->extensions;
 
         for (j = 0; j < sk_X509_EXTENSION_num(exts); j++) {
@@ -189,8 +186,6 @@ static int crl_set_issuers(X509_CRL *crl)
             if (nid == NID_invalidity_date) {
                 if ((inv_date = X509V3_EXT_d2i(ext)) == NULL) {
                     crl->flags |= EXFLAG_INVALID;
-                    ERR_raise_data(ERR_LIB_ASN1, ASN1_R_ILLEGAL_TIME_VALUE,
-                        "invalidityDate in CRL is not well-formed");
                     return 0;
                 }
                 ASN1_GENERALIZEDTIME_free(inv_date);
@@ -247,12 +242,9 @@ static int crl_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it,
     case ASN1_OP_D2I_POST:
         if (!X509_CRL_digest(crl, EVP_sha1(), crl->sha1_hash, NULL))
             crl->flags |= EXFLAG_NO_FINGERPRINT;
-        crl->idp = X509_CRL_get_ext_d2i(crl, NID_issuing_distribution_point, &i, NULL);
-        if (crl->idp == NULL && i != -1) {
-            ERR_raise_data(ERR_LIB_ASN1, ASN1_R_ILLEGAL_OBJECT,
-                "CRL: malformed CRL issuing distribution point");
-            return 0;
-        }
+        crl->idp = X509_CRL_get_ext_d2i(crl,
+            NID_issuing_distribution_point, &i,
+            NULL);
         if (crl->idp != NULL) {
             if (!setup_idp(crl, crl->idp))
                 crl->flags |= EXFLAG_INVALID;
@@ -266,21 +258,20 @@ static int crl_cb(int operation, ASN1_VALUE **pval, const ASN1_ITEM *it,
         if (crl->akid == NULL && i != -1)
             crl->flags |= EXFLAG_INVALID;
 
-        crl->crl_number = X509_CRL_get_ext_d2i(crl, NID_crl_number, &i, NULL);
-        if (crl->crl_number == NULL && i != -1) {
-            ERR_raise_data(ERR_LIB_ASN1, ASN1_R_ILLEGAL_OBJECT,
-                "CRL: malformed CRL number extension");
-            return 0;
-        }
-        crl->base_crl_number = X509_CRL_get_ext_d2i(crl, NID_delta_crl, &i, NULL);
-        if (crl->base_crl_number == NULL && i != -1) {
-            ERR_raise_data(ERR_LIB_ASN1, ASN1_R_ILLEGAL_OBJECT,
-                "CRL: malformed Delta CRL Indicator");
-            return 0;
-        }
+        crl->crl_number = X509_CRL_get_ext_d2i(crl,
+            NID_crl_number, &i, NULL);
+        if (crl->crl_number == NULL && i != -1)
+            crl->flags |= EXFLAG_INVALID;
+
+        crl->base_crl_number = X509_CRL_get_ext_d2i(crl,
+            NID_delta_crl, &i,
+            NULL);
+        if (crl->base_crl_number == NULL && i != -1)
+            crl->flags |= EXFLAG_INVALID;
         /* Delta CRLs must have CRL number */
         if (crl->base_crl_number && !crl->crl_number)
             crl->flags |= EXFLAG_INVALID;
+
         /*
          * See if we have any unhandled critical CRL extensions and indicate
          * this in a flag. We only currently handle IDP so anything else
@@ -455,7 +446,7 @@ int X509_CRL_get0_by_serial(X509_CRL *crl,
     return 0;
 }
 
-int X509_CRL_get0_by_cert(X509_CRL *crl, X509_REVOKED **ret, const X509 *x)
+int X509_CRL_get0_by_cert(X509_CRL *crl, X509_REVOKED **ret, X509 *x)
 {
     if (crl->meth->crl_lookup)
         return crl->meth->crl_lookup(crl, ret,
@@ -466,10 +457,6 @@ int X509_CRL_get0_by_cert(X509_CRL *crl, X509_REVOKED **ret, const X509 *x)
 
 static int def_crl_verify(X509_CRL *crl, EVP_PKEY *r)
 {
-    if (X509_ALGOR_cmp(&crl->sig_alg, &crl->crl.sig_alg) != 0) {
-        ERR_raise(ERR_LIB_X509, X509_R_CRL_SIGNATURE_ALGORITHM_MISMATCH);
-        return 0;
-    }
     return ASN1_item_verify_ex(ASN1_ITEM_rptr(X509_CRL_INFO),
         &crl->sig_alg, &crl->signature, &crl->crl, NULL,
         r, crl->libctx, crl->propq);
diff --git a/crypto/x509/x_exten.c b/crypto/x509/x_exten.c
index 405029f81a..51b268433d 100644
--- a/crypto/x509/x_exten.c
+++ b/crypto/x509/x_exten.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -13,8 +13,6 @@
 #include 
 #include "x509_local.h"
 
-#include 
-
 ASN1_SEQUENCE(X509_EXTENSION) = {
     ASN1_SIMPLE(X509_EXTENSION, object, ASN1_OBJECT),
     ASN1_OPT(X509_EXTENSION, critical, ASN1_FBOOLEAN),
diff --git a/crypto/x509/x_name.c b/crypto/x509/x_name.c
index 961f474e5b..90588c8c67 100644
--- a/crypto/x509/x_name.c
+++ b/crypto/x509/x_name.c
@@ -404,10 +404,8 @@ static int asn1_string_canon(ASN1_STRING *out, const ASN1_STRING *in)
 
     out->type = V_ASN1_UTF8STRING;
     out->length = ASN1_STRING_to_UTF8(&out->data, in);
-    if (out->length < 0)
+    if (out->length == -1)
         return 0;
-    if (out->length == 0)
-        return 1;
 
     to = out->data;
     from = to;
diff --git a/crypto/x509/x_pubkey.c b/crypto/x509/x_pubkey.c
index 888bcfd7b1..bed050bde5 100644
--- a/crypto/x509/x_pubkey.c
+++ b/crypto/x509/x_pubkey.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -64,7 +64,8 @@ ASN1_SEQUENCE(X509_PUBKEY_INTERNAL) = {
     ASN1_SIMPLE(X509_PUBKEY, public_key, ASN1_BIT_STRING)
 } static_ASN1_SEQUENCE_END_name(X509_PUBKEY, X509_PUBKEY_INTERNAL)
 
-X509_PUBKEY *ossl_d2i_X509_PUBKEY_INTERNAL(const unsigned char **pp, long len, OSSL_LIB_CTX *libctx, const char *propq)
+                                          X509_PUBKEY
+    * ossl_d2i_X509_PUBKEY_INTERNAL(const unsigned char **pp, long len, OSSL_LIB_CTX *libctx, const char *propq)
 {
     X509_PUBKEY *xpub = OPENSSL_zalloc(sizeof(*xpub));
 
@@ -199,19 +200,8 @@ static int x509_pubkey_ex_d2i_ex(ASN1_VALUE **pval,
         }
         p = in_saved;
 
-        /*
-         * TPM 1.2 Endorsement Key certificates use NID_rsaesOaep in the
-         * SPKI AlgorithmIdentifier with a plain RSAPublicKey body, per
-         * TCG Credential Profiles V1.2 section 3.2.7.  Map the OID to
-         * "RSA" here so the provider decoder is selected; the OAEP
-         * AlgorithmIdentifier parameters are not interpreted.  Keep
-         * this in sync with x509_pubkey_decode() and
-         * ossl_spki2typespki_der_decode().
-         */
-        if (OBJ_obj2nid(pubkey->algor->algorithm) == NID_rsaesOaep) {
-            OPENSSL_strlcpy(txtoidname, "RSA", sizeof(txtoidname));
-        } else if (OBJ_obj2txt(txtoidname, sizeof(txtoidname),
-                       pubkey->algor->algorithm, 0)
+        if (OBJ_obj2txt(txtoidname, sizeof(txtoidname),
+                pubkey->algor->algorithm, 0)
             <= 0) {
             ERR_clear_last_mark();
             goto end;
@@ -233,7 +223,7 @@ static int x509_pubkey_ex_d2i_ex(ASN1_VALUE **pval,
                      * bytes.
                      */
                     ERR_clear_last_mark();
-                    ERR_raise(ERR_LIB_ASN1, ASN1_R_DECODE_ERROR);
+                    ERR_raise(ERR_LIB_ASN1, EVP_R_DECODE_ERROR);
                     goto end;
                 }
             }
@@ -306,8 +296,9 @@ X509_PUBKEY *X509_PUBKEY_dup(const X509_PUBKEY *a)
     }
     if ((pubkey->algor = X509_ALGOR_dup(a->algor)) == NULL
         || (pubkey->public_key = ASN1_BIT_STRING_new()) == NULL
-        || !ASN1_BIT_STRING_set1(pubkey->public_key,
-            a->public_key->data, a->public_key->length, 0)) {
+        || !ASN1_BIT_STRING_set(pubkey->public_key,
+            a->public_key->data,
+            a->public_key->length)) {
         x509_pubkey_ex_free((ASN1_VALUE **)&pubkey,
             ASN1_ITEM_rptr(X509_PUBKEY_INTERNAL));
         ERR_raise(ERR_LIB_X509, ERR_R_ASN1_LIB);
@@ -420,16 +411,6 @@ static int x509_pubkey_decode(EVP_PKEY **ppkey, const X509_PUBKEY *key)
     if (!key->flag_force_legacy)
         return 0;
 
-    /*
-     * NID_rsaesOaep uses the same underlying RSAPublicKey body as
-     * NID_rsaEncryption (TCG Credential Profiles V1.2 section 3.2.7).
-     * Remap so EVP_PKEY_set_type() below finds the RSA ameth.  Keep
-     * this in sync with x509_pubkey_ex_d2i_ex() and
-     * ossl_spki2typespki_der_decode().
-     */
-    if (nid == NID_rsaesOaep)
-        nid = NID_rsaEncryption;
-
     pkey = EVP_PKEY_new();
     if (pkey == NULL) {
         ERR_raise(ERR_LIB_X509, ERR_R_EVP_LIB);
@@ -1019,7 +1000,7 @@ void X509_PUBKEY_set0_public_key(X509_PUBKEY *pub,
     unsigned char *penc, int penclen)
 {
     ASN1_STRING_set0(pub->public_key, penc, penclen);
-    ossl_asn1_bit_string_set_unused_bits(pub->public_key, 0);
+    ossl_asn1_string_set_bits_left(pub->public_key, 0);
 }
 
 int X509_PUBKEY_set0_param(X509_PUBKEY *pub, ASN1_OBJECT *aobj,
@@ -1048,7 +1029,7 @@ int X509_PUBKEY_get0_param(ASN1_OBJECT **ppkalg,
     return 1;
 }
 
-const ASN1_BIT_STRING *X509_get0_pubkey_bitstr(const X509 *x)
+ASN1_BIT_STRING *X509_get0_pubkey_bitstr(const X509 *x)
 {
     if (x == NULL)
         return NULL;
diff --git a/crypto/x509/x_x509.c b/crypto/x509/x_x509.c
index 570434eaea..2c62e0cd8a 100644
--- a/crypto/x509/x_x509.c
+++ b/crypto/x509/x_x509.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -304,7 +304,7 @@ void X509_set0_distinguishing_id(X509 *x, ASN1_OCTET_STRING *d_id)
     x->distinguishing_id = d_id;
 }
 
-const ASN1_OCTET_STRING *X509_get0_distinguishing_id(const X509 *x)
+ASN1_OCTET_STRING *X509_get0_distinguishing_id(X509 *x)
 {
     return x->distinguishing_id;
 }
diff --git a/crypto/x509/x_x509a.c b/crypto/x509/x_x509a.c
index 3fa17fb925..8a9ff6eb88 100644
--- a/crypto/x509/x_x509a.c
+++ b/crypto/x509/x_x509a.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1999-2021 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -50,8 +50,6 @@ static X509_CERT_AUX *aux_get(X509 *x)
 int X509_alias_set1(X509 *x, const unsigned char *name, int len)
 {
     X509_CERT_AUX *aux;
-    size_t len_s;
-
     if (!name) {
         if (!x || !x->aux || !x->aux->alias)
             return 1;
@@ -61,25 +59,14 @@ int X509_alias_set1(X509 *x, const unsigned char *name, int len)
     }
     if ((aux = aux_get(x)) == NULL)
         return 0;
-
-    if (len < -1)
-        return 0;
-
-    if (len == -1)
-        len_s = strlen((const char *)name);
-    else
-        len_s = len;
-
     if (aux->alias == NULL && (aux->alias = ASN1_UTF8STRING_new()) == NULL)
         return 0;
-    return ASN1_STRING_set_data(aux->alias, name, len_s);
+    return ASN1_STRING_set(aux->alias, name, len);
 }
 
 int X509_keyid_set1(X509 *x, const unsigned char *id, int len)
 {
     X509_CERT_AUX *aux;
-    size_t len_s;
-
     if (!id) {
         if (!x || !x->aux || !x->aux->keyid)
             return 1;
@@ -89,22 +76,13 @@ int X509_keyid_set1(X509 *x, const unsigned char *id, int len)
     }
     if ((aux = aux_get(x)) == NULL)
         return 0;
-
-    if (len < -1)
-        return 0;
-
-    if (len == -1)
-        len_s = strlen((const char *)id);
-    else
-        len_s = len;
-
     if (aux->keyid == NULL
         && (aux->keyid = ASN1_OCTET_STRING_new()) == NULL)
         return 0;
-    return ASN1_STRING_set_data(aux->keyid, id, len_s);
+    return ASN1_STRING_set(aux->keyid, id, len);
 }
 
-const unsigned char *X509_alias_get0(const X509 *x, int *len)
+unsigned char *X509_alias_get0(const X509 *x, int *len)
 {
     if (!x->aux || !x->aux->alias)
         return NULL;
@@ -113,7 +91,7 @@ const unsigned char *X509_alias_get0(const X509 *x, int *len)
     return x->aux->alias->data;
 }
 
-const unsigned char *X509_keyid_get0(const X509 *x, int *len)
+unsigned char *X509_keyid_get0(const X509 *x, int *len)
 {
     if (!x->aux || !x->aux->keyid)
         return NULL;
@@ -181,14 +159,14 @@ void X509_reject_clear(X509 *x)
     }
 }
 
-const STACK_OF(ASN1_OBJECT) *X509_get0_trust_objects(const X509 *x)
+STACK_OF(ASN1_OBJECT) *X509_get0_trust_objects(const X509 *x)
 {
     if (x->aux != NULL)
         return x->aux->trust;
     return NULL;
 }
 
-const STACK_OF(ASN1_OBJECT) *X509_get0_reject_objects(const X509 *x)
+STACK_OF(ASN1_OBJECT) *X509_get0_reject_objects(const X509 *x)
 {
     if (x->aux != NULL)
         return x->aux->reject;
diff --git a/crypto/x86_64cpuid.pl b/crypto/x86_64cpuid.pl
index cf8a7605a6..6bfe09084d 100644
--- a/crypto/x86_64cpuid.pl
+++ b/crypto/x86_64cpuid.pl
@@ -30,9 +30,6 @@ print<<___;
 #include crypto/cryptlib.h
 .extern		OPENSSL_cpuid_setup
 .hidden		OPENSSL_cpuid_setup
-.section	.init
-	call	OPENSSL_cpuid_setup
-
 .hidden	OPENSSL_ia32cap_P
 .comm	OPENSSL_ia32cap_P,40,4	# <--Should match with internal/cryptlib.h OPENSSL_IA32CAP_P_MAX_INDEXES
 .text
diff --git a/crypto/x86cpuid.pl b/crypto/x86cpuid.pl
index 32f6e43523..329a57618f 100644
--- a/crypto/x86cpuid.pl
+++ b/crypto/x86cpuid.pl
@@ -493,8 +493,6 @@ my $rdop = shift;
 &gen_random("rdrand");
 &gen_random("rdseed");
 
-&initseg("OPENSSL_cpuid_setup");
-
 &hidden("OPENSSL_cpuid_setup");
 &hidden("OPENSSL_ia32cap_P");
 
diff --git a/demos/Makefile b/demos/Makefile
index 3b411fe052..208249e0fd 100644
--- a/demos/Makefile
+++ b/demos/Makefile
@@ -6,7 +6,6 @@ MODULES = bio \
           encrypt \
           guide \
           http3 \
-          info \
           kdf \
           keyexch \
           mac \
diff --git a/demos/README.txt b/demos/README.txt
index 9caafcad77..1a7d4f447f 100644
--- a/demos/README.txt
+++ b/demos/README.txt
@@ -36,18 +36,12 @@ guide:                   Sample code from the OpenSSL Guide tutorials. See
 quic-client-block.c:     A simple blocking QUIC client
 quic-client-non-block.c: A simple non-blocking QUIC client
 quic-multi-stream.c:     A simple QUIC client using multiple streams
-quic-server-block.c:     A simple blocking QUIC server
-quic-server-non-block.c: A simple non-blocking QUIC server
 tls-client-block.c:      A simple blocking SSL/TLS client
 tls-client-non-block.c:  A simple non-blocking SSL/TLS client
-tls-server-block.c:      A simple blocking SSL/TLS server
 
 http3:                 Demonstration of how to use OpenSSL's QUIC capabilities
                        for HTTP/3.
 
-info:
-fips-version.c         Demonstration of how to query the FIPS provider version
-
 kdf:
 hkdf.c                 Demonstration of HMAC based key derivation
 pbkdf2.c               Demonstration of PBKDF2 password based key derivation
@@ -84,5 +78,4 @@ rsa_pss_hash.c            Compute and verify an RSA-PSS signature over a buffer
 smime:                 Demonstrations related to S/MIME
 
 sslecho:
-echecho.c              Simple SSL/TLS echo client/server that uses ECH.
 main.c                 Simple SSL/TLS echo client/server.
diff --git a/demos/bio/sconnect.c b/demos/bio/sconnect.c
index 92320ca138..7cdfa401f4 100644
--- a/demos/bio/sconnect.c
+++ b/demos/bio/sconnect.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 1998-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 1998-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -65,23 +65,15 @@ int main(int argc, char *argv[])
 
     /* Use it inside an SSL BIO */
     ssl_bio = BIO_new(BIO_f_ssl());
-    if (ssl_bio == NULL)
-        goto err;
-
     BIO_set_ssl(ssl_bio, ssl, BIO_CLOSE);
 
     /* Lets use a connect BIO under the SSL BIO */
     out = BIO_new(BIO_s_connect());
-    if (out == NULL) {
-        BIO_free(ssl_bio);
-        goto err;
-    }
-
     BIO_set_conn_hostname(out, hostport);
 
     /* The BIO has parsed the host:port and even IPv6 literals in [] */
     hostname = BIO_get_conn_hostname(out);
-    if (!hostname || SSL_set1_dnsname(ssl, hostname) <= 0) {
+    if (!hostname || SSL_set1_host(ssl, hostname) <= 0) {
         BIO_free(ssl_bio);
         goto err;
     }
diff --git a/demos/build.info b/demos/build.info
index be3252fa9d..3c74e8f331 100644
--- a/demos/build.info
+++ b/demos/build.info
@@ -1,4 +1,4 @@
-SUBDIRS=bio cipher digest info keyexch mac kdf pkcs12 pkey signature \
+SUBDIRS=bio cipher digest keyexch mac kdf pkey signature \
         encrypt encode sslecho
 
 IF[{- !$disabled{"h3demo"} -}]
diff --git a/demos/cipher/aeskeywrap.c b/demos/cipher/aeskeywrap.c
index 189eb5c688..89de1e242c 100644
--- a/demos/cipher/aeskeywrap.c
+++ b/demos/cipher/aeskeywrap.c
@@ -27,24 +27,102 @@ static const unsigned char wrap_key[] = {
 
 /* Unique initialisation vector */
 static const unsigned char wrap_iv[] = {
-    0x99, 0xaa, 0x3e, 0x68, 0xed, 0x81, 0x73, 0xa0, 0xee, 0xd0,
-    0x66, 0x84, 0x99, 0xaa, 0x3e, 0x68
+    0x99,
+    0xaa,
+    0x3e,
+    0x68,
+    0xed,
+    0x81,
+    0x73,
+    0xa0,
+    0xee,
+    0xd0,
+    0x66,
+    0x84,
+    0x99,
+    0xaa,
+    0x3e,
+    0x68,
 };
 
 /* Example plaintext to encrypt */
 static const unsigned char wrap_pt[] = {
-    0xad, 0x4f, 0xc9, 0xfc, 0x77, 0x69, 0xc9, 0xea, 0xfc, 0xdf,
-    0x00, 0xac, 0x34, 0xec, 0x40, 0xbc, 0x28, 0x3f, 0xa4, 0x5e,
-    0xd8, 0x99, 0xe4, 0x5d, 0x5e, 0x7a, 0xc4, 0xe6, 0xca, 0x7b,
-    0xa5, 0xb7
+    0xad,
+    0x4f,
+    0xc9,
+    0xfc,
+    0x77,
+    0x69,
+    0xc9,
+    0xea,
+    0xfc,
+    0xdf,
+    0x00,
+    0xac,
+    0x34,
+    0xec,
+    0x40,
+    0xbc,
+    0x28,
+    0x3f,
+    0xa4,
+    0x5e,
+    0xd8,
+    0x99,
+    0xe4,
+    0x5d,
+    0x5e,
+    0x7a,
+    0xc4,
+    0xe6,
+    0xca,
+    0x7b,
+    0xa5,
+    0xb7,
 };
 
 /* Expected ciphertext value */
 static const unsigned char wrap_ct[] = {
-    0x97, 0x99, 0x55, 0xca, 0xf6, 0x3e, 0x95, 0x54, 0x39, 0xd6,
-    0xaf, 0x63, 0xff, 0x2c, 0xe3, 0x96, 0xf7, 0x0d, 0x2c, 0x9c,
-    0xc7, 0x43, 0xc0, 0xb6, 0x31, 0x43, 0xb9, 0x20, 0xac, 0x6b,
-    0xd3, 0x67, 0xad, 0x01, 0xaf, 0xa7, 0x32, 0x74, 0x26, 0x92
+    0x97,
+    0x99,
+    0x55,
+    0xca,
+    0xf6,
+    0x3e,
+    0x95,
+    0x54,
+    0x39,
+    0xd6,
+    0xaf,
+    0x63,
+    0xff,
+    0x2c,
+    0xe3,
+    0x96,
+    0xf7,
+    0x0d,
+    0x2c,
+    0x9c,
+    0xc7,
+    0x43,
+    0xc0,
+    0xb6,
+    0x31,
+    0x43,
+    0xb9,
+    0x20,
+    0xac,
+    0x6b,
+    0xd3,
+    0x67,
+    0xad,
+    0x01,
+    0xaf,
+    0xa7,
+    0x32,
+    0x74,
+    0x26,
+    0x92,
 };
 
 /*
diff --git a/demos/cipher/ariacbc.c b/demos/cipher/ariacbc.c
index f5bb44490d..637dfcef0c 100644
--- a/demos/cipher/ariacbc.c
+++ b/demos/cipher/ariacbc.c
@@ -27,8 +27,22 @@ static const unsigned char cbc_key[] = {
 
 /* Unique initialisation vector */
 static const unsigned char cbc_iv[] = {
-    0x99, 0xaa, 0x3e, 0x68, 0xed, 0x81, 0x73, 0xa0, 0xee, 0xd0,
-    0x66, 0x84, 0x99, 0xaa, 0x3e, 0x68
+    0x99,
+    0xaa,
+    0x3e,
+    0x68,
+    0xed,
+    0x81,
+    0x73,
+    0xa0,
+    0xee,
+    0xd0,
+    0x66,
+    0x84,
+    0x99,
+    0xaa,
+    0x3e,
+    0x68,
 };
 
 /* Example plaintext to encrypt */
diff --git a/demos/cms/cms_ver.c b/demos/cms/cms_ver.c
index 1fdb4fc795..b454983d30 100644
--- a/demos/cms/cms_ver.c
+++ b/demos/cms/cms_ver.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2008-2023 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -21,7 +21,7 @@ static void print_signingTime(CMS_ContentInfo *cms)
     STACK_OF(CMS_SignerInfo) *sis;
     CMS_SignerInfo *si;
     X509_ATTRIBUTE *attr;
-    const ASN1_TYPE *t;
+    ASN1_TYPE *t;
     ASN1_UTCTIME *utctime;
     ASN1_GENERALIZEDTIME *gtime;
     BIO *b;
diff --git a/demos/digest/EVP_MD_demo.c b/demos/digest/EVP_MD_demo.c
index a01ab695bf..622b8b1f87 100644
--- a/demos/digest/EVP_MD_demo.c
+++ b/demos/digest/EVP_MD_demo.c
@@ -62,13 +62,70 @@ static const char *hamlet_2 = "The insolence of Office, and the spurns\n"
 
 /* The known value of the SHA3-512 digest of the above soliloqy */
 static const unsigned char known_answer[] = {
-    0xbb, 0x69, 0xf8, 0x09, 0x9c, 0x2e, 0x00, 0x3d, 0xa4, 0x29,
-    0x5f, 0x59, 0x4b, 0x89, 0xe4, 0xd9, 0xdb, 0xa2, 0xe5, 0xaf,
-    0xa5, 0x87, 0x73, 0x9d, 0x83, 0x72, 0xcf, 0xea, 0x84, 0x66,
-    0xc1, 0xf9, 0xc9, 0x78, 0xef, 0xba, 0x3d, 0xe9, 0xc1, 0xff,
-    0xa3, 0x75, 0xc7, 0x58, 0x74, 0x8e, 0x9c, 0x1d, 0x14, 0xd9,
-    0xdd, 0xd1, 0xfd, 0x24, 0x30, 0xd6, 0x81, 0xca, 0x8f, 0x78,
-    0x29, 0x19, 0x9a, 0xfe
+    0xbb,
+    0x69,
+    0xf8,
+    0x09,
+    0x9c,
+    0x2e,
+    0x00,
+    0x3d,
+    0xa4,
+    0x29,
+    0x5f,
+    0x59,
+    0x4b,
+    0x89,
+    0xe4,
+    0xd9,
+    0xdb,
+    0xa2,
+    0xe5,
+    0xaf,
+    0xa5,
+    0x87,
+    0x73,
+    0x9d,
+    0x83,
+    0x72,
+    0xcf,
+    0xea,
+    0x84,
+    0x66,
+    0xc1,
+    0xf9,
+    0xc9,
+    0x78,
+    0xef,
+    0xba,
+    0x3d,
+    0xe9,
+    0xc1,
+    0xff,
+    0xa3,
+    0x75,
+    0xc7,
+    0x58,
+    0x74,
+    0x8e,
+    0x9c,
+    0x1d,
+    0x14,
+    0xd9,
+    0xdd,
+    0xd1,
+    0xfd,
+    0x24,
+    0x30,
+    0xd6,
+    0x81,
+    0xca,
+    0x8f,
+    0x78,
+    0x29,
+    0x19,
+    0x9a,
+    0xfe,
 };
 
 static int demonstrate_digest(void)
@@ -147,8 +204,8 @@ static int demonstrate_digest(void)
     fprintf(stdout, "\n");
     /* Check digest_value against the known answer */
     if ((size_t)digest_length != sizeof(known_answer)) {
-        fprintf(stdout, "Digest length(%u) not equal to known answer length(%zu).\n",
-            digest_length, sizeof(known_answer));
+        fprintf(stdout, "Digest length(%d) not equal to known answer length(%lu).\n",
+            digest_length, (unsigned long)sizeof(known_answer));
     } else if (memcmp(digest_value, known_answer, digest_length) != 0) {
         for (j = 0; j < sizeof(known_answer); j++) {
             fprintf(stdout, "%02x", known_answer[j]);
diff --git a/demos/encrypt/rsa_encrypt.h b/demos/encrypt/rsa_encrypt.h
index 9cd98e3866..be9ee66eda 100644
--- a/demos/encrypt/rsa_encrypt.h
+++ b/demos/encrypt/rsa_encrypt.h
@@ -9,158 +9,1494 @@
 
 /* Private RSA key used for decryption */
 static const unsigned char priv_key_der[] = {
-    0x30, 0x82, 0x04, 0xa4, 0x02, 0x01, 0x00, 0x02, 0x82, 0x01,
-    0x01, 0x00, 0xc2, 0x44, 0xbc, 0xcf, 0x5b, 0xca, 0xcd, 0x80,
-    0x77, 0xae, 0xf9, 0x7a, 0x34, 0xbb, 0x37, 0x6f, 0x5c, 0x76,
-    0x4c, 0xe4, 0xbb, 0x0c, 0x1d, 0xe7, 0xfe, 0x0f, 0xda, 0xcf,
-    0x8c, 0x56, 0x65, 0x72, 0x6e, 0x2c, 0xf9, 0xfd, 0x87, 0x43,
-    0xeb, 0x4c, 0x26, 0xb1, 0xd3, 0xf0, 0x87, 0xb1, 0x18, 0x68,
-    0x14, 0x7d, 0x3c, 0x2a, 0xfa, 0xc2, 0x5d, 0x70, 0x19, 0x11,
-    0x00, 0x2e, 0xb3, 0x9c, 0x8e, 0x38, 0x08, 0xbe, 0xe3, 0xeb,
-    0x7d, 0x6e, 0xc7, 0x19, 0xc6, 0x7f, 0x59, 0x48, 0x84, 0x1b,
-    0xe3, 0x27, 0x30, 0x46, 0x30, 0xd3, 0xfc, 0xfc, 0xb3, 0x35,
-    0x75, 0xc4, 0x31, 0x1a, 0xc0, 0xc2, 0x4c, 0x0b, 0xc7, 0x01,
-    0x95, 0xb2, 0xdc, 0x17, 0x77, 0x9b, 0x09, 0x15, 0x04, 0xbc,
-    0xdb, 0x57, 0x0b, 0x26, 0xda, 0x59, 0x54, 0x0d, 0x6e, 0xb7,
-    0x89, 0xbc, 0x53, 0x9d, 0x5f, 0x8c, 0xad, 0x86, 0x97, 0xd2,
-    0x48, 0x4f, 0x5c, 0x94, 0xdd, 0x30, 0x2f, 0xcf, 0xfc, 0xde,
-    0x20, 0x31, 0x25, 0x9d, 0x29, 0x25, 0x78, 0xb7, 0xd2, 0x5b,
-    0x5d, 0x99, 0x5b, 0x08, 0x12, 0x81, 0x79, 0x89, 0xa0, 0xcf,
-    0x8f, 0x40, 0xb1, 0x77, 0x72, 0x3b, 0x13, 0xfc, 0x55, 0x43,
-    0x70, 0x29, 0xd5, 0x41, 0xed, 0x31, 0x4b, 0x2d, 0x6c, 0x7d,
-    0xcf, 0x99, 0x5f, 0xd1, 0x72, 0x9f, 0x8b, 0x32, 0x96, 0xde,
-    0x5d, 0x8b, 0x19, 0x77, 0x75, 0xff, 0x09, 0xbf, 0x26, 0xe9,
-    0xd7, 0x3d, 0xc7, 0x1a, 0x81, 0xcf, 0x05, 0x1b, 0x89, 0xbf,
-    0x45, 0x32, 0xbf, 0x5e, 0xc9, 0xe3, 0x5c, 0x33, 0x4a, 0x72,
-    0x47, 0xf4, 0x24, 0xae, 0x9b, 0x38, 0x24, 0x76, 0x9a, 0xa2,
-    0x9a, 0x50, 0x50, 0x49, 0xf5, 0x26, 0xb9, 0x55, 0xa6, 0x47,
-    0xc9, 0x14, 0xa2, 0xca, 0xd4, 0xa8, 0x8a, 0x9f, 0xe9, 0x5a,
-    0x5a, 0x12, 0xaa, 0x30, 0xd5, 0x78, 0x8b, 0x39, 0x02, 0x03,
-    0x01, 0x00, 0x01, 0x02, 0x82, 0x01, 0x00, 0x22, 0x5d, 0xb9,
-    0x8e, 0xef, 0x1c, 0x91, 0xbd, 0x03, 0xaf, 0x1a, 0xe8, 0x00,
-    0xf3, 0x0b, 0x8b, 0xf2, 0x2d, 0xe5, 0x4d, 0x63, 0x3f, 0x71,
-    0xfc, 0xeb, 0xc7, 0x4f, 0x3c, 0x7f, 0x05, 0x7b, 0x9d, 0xc2,
-    0x1a, 0xc7, 0xc0, 0x8f, 0x50, 0xb7, 0x0b, 0xba, 0x1e, 0xa4,
-    0x30, 0xfd, 0x38, 0x19, 0x6a, 0xb4, 0x11, 0x31, 0x77, 0x22,
-    0xf4, 0x06, 0x46, 0x81, 0xd0, 0xad, 0x99, 0x15, 0x62, 0x01,
-    0x10, 0xad, 0x8f, 0x63, 0x4f, 0x71, 0xd9, 0x8a, 0x74, 0x27,
-    0x56, 0xb8, 0xeb, 0x28, 0x9f, 0xac, 0x4f, 0xee, 0xec, 0xc3,
-    0xcf, 0x84, 0x86, 0x09, 0x87, 0xd0, 0x04, 0xfc, 0x70, 0xd0,
-    0x9f, 0xae, 0x87, 0x38, 0xd5, 0xb1, 0x6f, 0x3a, 0x1b, 0x16,
-    0xa8, 0x00, 0xf3, 0xcc, 0x6a, 0x42, 0x5d, 0x04, 0x16, 0x83,
-    0xf2, 0xe0, 0x79, 0x1d, 0xd8, 0x6f, 0x0f, 0xb7, 0x34, 0xf4,
-    0x45, 0xb5, 0x1e, 0xc5, 0xb5, 0x78, 0xa7, 0xd3, 0xa3, 0x23,
-    0x35, 0xbc, 0x7b, 0x01, 0x59, 0x7d, 0xee, 0xb9, 0x4f, 0xda,
-    0x28, 0xad, 0x5d, 0x25, 0xab, 0x66, 0x6a, 0xb0, 0x61, 0xf6,
-    0x12, 0xa7, 0xee, 0xd1, 0xe7, 0xb1, 0x8b, 0x91, 0x29, 0xba,
-    0xb5, 0xf8, 0x78, 0xc8, 0x6b, 0x76, 0x67, 0x32, 0xe8, 0xf3,
-    0x4e, 0x59, 0xba, 0xc1, 0x44, 0xc0, 0xec, 0x8d, 0x7c, 0x63,
-    0xb2, 0x6e, 0x0c, 0xb9, 0x33, 0x42, 0x0c, 0x8d, 0xae, 0x4e,
-    0x54, 0xc8, 0x8a, 0xef, 0xf9, 0x47, 0xc8, 0x99, 0x84, 0xc8,
-    0x46, 0xf6, 0xa6, 0x53, 0x59, 0xf8, 0x60, 0xe3, 0xd7, 0x1d,
-    0x10, 0x95, 0xf5, 0x6d, 0xf4, 0xa3, 0x18, 0x40, 0xd7, 0x14,
-    0x04, 0xac, 0x8c, 0x69, 0xd6, 0x14, 0xdc, 0xd8, 0xcc, 0xbc,
-    0x1c, 0xac, 0xd7, 0x21, 0x2b, 0x7e, 0x29, 0x88, 0x06, 0xa0,
-    0xf4, 0x06, 0x08, 0x14, 0x04, 0x4d, 0x32, 0x33, 0x84, 0x9c,
-    0x20, 0x8e, 0xcf, 0x02, 0x81, 0x81, 0x00, 0xf3, 0xf9, 0xbd,
-    0xd5, 0x43, 0x6f, 0x27, 0x4a, 0x92, 0xd6, 0x18, 0x3d, 0x4b,
-    0xf1, 0x77, 0x7c, 0xaf, 0xce, 0x01, 0x17, 0x98, 0xcb, 0xbe,
-    0x06, 0x86, 0x3a, 0x13, 0x72, 0x4b, 0x7c, 0x81, 0x51, 0x24,
-    0x5d, 0xc3, 0xe9, 0xa2, 0x63, 0x1e, 0x4a, 0xeb, 0x66, 0xae,
-    0x01, 0x5e, 0xa4, 0xa4, 0x74, 0x9e, 0xee, 0x32, 0xe5, 0x59,
-    0x1b, 0x37, 0xef, 0x7d, 0xb3, 0x42, 0x8c, 0x93, 0x8b, 0xd3,
-    0x1e, 0x83, 0x43, 0xb5, 0x88, 0x3e, 0x24, 0xeb, 0xdc, 0x92,
-    0x2d, 0xcc, 0x9a, 0x9d, 0xf1, 0x7d, 0x16, 0x71, 0xcb, 0x25,
-    0x47, 0x36, 0xb0, 0xc4, 0x6b, 0xc8, 0x53, 0x4a, 0x25, 0x80,
-    0x47, 0x77, 0xdb, 0x97, 0x13, 0x15, 0x0f, 0x4a, 0xfa, 0x0c,
-    0x6c, 0x44, 0x13, 0x2f, 0xbc, 0x9a, 0x6b, 0x13, 0x57, 0xfc,
-    0x42, 0xb9, 0xe9, 0xd3, 0x2e, 0xd2, 0x11, 0xf4, 0xc5, 0x84,
-    0x55, 0xd2, 0xdf, 0x1d, 0xa7, 0x02, 0x81, 0x81, 0x00, 0xcb,
-    0xd7, 0xd6, 0x9d, 0x71, 0xb3, 0x86, 0xbe, 0x68, 0xed, 0x67,
-    0xe1, 0x51, 0x92, 0x17, 0x60, 0x58, 0xb3, 0x2a, 0x56, 0xfd,
-    0x18, 0xfb, 0x39, 0x4b, 0x14, 0xc6, 0xf6, 0x67, 0x0e, 0x31,
-    0xe3, 0xb3, 0x2f, 0x1f, 0xec, 0x16, 0x1c, 0x23, 0x2b, 0x60,
-    0x36, 0xd1, 0xcb, 0x4a, 0x03, 0x6a, 0x3a, 0x4c, 0x8c, 0xf2,
-    0x73, 0x08, 0x23, 0x29, 0xda, 0xcb, 0xf7, 0xb6, 0x18, 0x97,
-    0xc6, 0xfe, 0xd4, 0x40, 0x06, 0x87, 0x9d, 0x6e, 0xbb, 0x5d,
-    0x14, 0x44, 0xc8, 0x19, 0xfa, 0x7f, 0x0c, 0xc5, 0x02, 0x92,
-    0x00, 0xbb, 0x2e, 0x4f, 0x50, 0xb0, 0x71, 0x9f, 0xf3, 0x94,
-    0x12, 0xb8, 0x6c, 0x5f, 0xe1, 0x83, 0x7b, 0xbc, 0x8c, 0x0a,
-    0x6f, 0x09, 0x6a, 0x35, 0x4f, 0xf9, 0xa4, 0x92, 0x93, 0xe3,
-    0xad, 0x36, 0x25, 0x28, 0x90, 0x85, 0xd2, 0x9f, 0x86, 0xfd,
-    0xd9, 0xa8, 0x61, 0xe9, 0xb2, 0xec, 0x1f, 0x02, 0x81, 0x81,
-    0x00, 0xdd, 0x1c, 0x52, 0xda, 0x2b, 0xc2, 0x5a, 0x26, 0xb0,
-    0xcb, 0x0d, 0xae, 0xc7, 0xdb, 0xf0, 0x41, 0x75, 0x87, 0x4a,
-    0xe0, 0x1a, 0xdf, 0x53, 0xb9, 0xcf, 0xfe, 0x64, 0x4f, 0x6a,
-    0x70, 0x4d, 0x36, 0xbf, 0xb1, 0xa6, 0xf3, 0x5f, 0xf3, 0x5a,
-    0xa9, 0xe5, 0x8b, 0xea, 0x59, 0x5d, 0x6f, 0xf3, 0x87, 0xa9,
-    0xde, 0x11, 0x0c, 0x60, 0x64, 0x55, 0x9e, 0x5c, 0x1a, 0x91,
-    0x4e, 0x9c, 0x0d, 0xd5, 0xe9, 0x4a, 0x67, 0x9b, 0xe6, 0xfd,
-    0x03, 0x33, 0x2b, 0x74, 0xe3, 0xc3, 0x11, 0xc1, 0xe0, 0xf1,
-    0x4f, 0xdd, 0x13, 0x92, 0x16, 0x67, 0x4f, 0x6e, 0xc4, 0x8c,
-    0x0a, 0x48, 0x21, 0x92, 0x8f, 0xb2, 0xe5, 0xb5, 0x96, 0x5a,
-    0xb8, 0xc0, 0x67, 0xbb, 0xc8, 0x87, 0x2d, 0xa8, 0x4e, 0xd2,
-    0xd8, 0x05, 0xf0, 0xf0, 0xb3, 0x7c, 0x90, 0x98, 0x8f, 0x4f,
-    0x5d, 0x6c, 0xab, 0x71, 0x92, 0xe2, 0x88, 0xc8, 0xf3, 0x02,
-    0x81, 0x81, 0x00, 0x99, 0x27, 0x5a, 0x00, 0x81, 0x65, 0x39,
-    0x5f, 0xe6, 0xc6, 0x38, 0xbe, 0x79, 0xe3, 0x21, 0xdd, 0x29,
-    0xc7, 0xb3, 0x90, 0x18, 0x29, 0xa4, 0xd7, 0xaf, 0x29, 0xb5,
-    0x33, 0x7c, 0xca, 0x95, 0x81, 0x57, 0x27, 0x98, 0xfc, 0x70,
-    0xc0, 0x43, 0x4c, 0x5b, 0xc5, 0xd4, 0x6a, 0xc0, 0xf9, 0x3f,
-    0xde, 0xfd, 0x95, 0x08, 0xb4, 0x94, 0xf0, 0x96, 0x89, 0xe5,
-    0xa6, 0x00, 0x13, 0x0a, 0x36, 0x61, 0x50, 0x67, 0xaa, 0x80,
-    0x4a, 0x30, 0xe0, 0x65, 0x56, 0xcd, 0x36, 0xeb, 0x0d, 0xe2,
-    0x57, 0x5d, 0xce, 0x48, 0x94, 0x74, 0x0e, 0x9f, 0x59, 0x28,
-    0xb8, 0xb6, 0x4c, 0xf4, 0x7b, 0xfc, 0x44, 0xb0, 0xe5, 0x67,
-    0x3c, 0x98, 0xb5, 0x3f, 0x41, 0x9d, 0xf9, 0x46, 0x85, 0x08,
-    0x34, 0x36, 0x4d, 0x17, 0x4b, 0x14, 0xdb, 0x66, 0x56, 0xef,
-    0xb5, 0x08, 0x57, 0x0c, 0x73, 0x74, 0xa7, 0xdc, 0x46, 0xaa,
-    0x51, 0x02, 0x81, 0x80, 0x1e, 0x50, 0x4c, 0xde, 0x9c, 0x60,
-    0x6d, 0xd7, 0x31, 0xf6, 0xd8, 0x4f, 0xc2, 0x25, 0x7d, 0x83,
-    0xb3, 0xe7, 0xed, 0x92, 0xe7, 0x28, 0x1e, 0xb3, 0x9b, 0xcb,
-    0xf2, 0x86, 0xa4, 0x49, 0x45, 0x5e, 0xba, 0x1d, 0xdb, 0x21,
-    0x5d, 0xdf, 0xeb, 0x3c, 0x5e, 0x01, 0xc6, 0x68, 0x25, 0x28,
-    0xe6, 0x1a, 0xbf, 0xc1, 0xa1, 0xc5, 0x92, 0x0b, 0x08, 0x43,
-    0x0e, 0x5a, 0xa3, 0x85, 0x8a, 0x65, 0xb4, 0x54, 0xa1, 0x4c,
-    0x20, 0xa2, 0x5a, 0x08, 0xf6, 0x90, 0x0d, 0x9a, 0xd7, 0x20,
-    0xf1, 0x10, 0x66, 0x28, 0x4c, 0x22, 0x56, 0xa6, 0xb9, 0xff,
-    0xd0, 0x6a, 0x62, 0x8c, 0x9f, 0xf8, 0x7c, 0xf4, 0xad, 0xd7,
-    0xe8, 0xf9, 0x87, 0x43, 0xbf, 0x73, 0x5b, 0x04, 0xc7, 0xd0,
-    0x77, 0xcc, 0xe3, 0xbe, 0xda, 0xc2, 0x07, 0xed, 0x8d, 0x2a,
-    0x15, 0x77, 0x1d, 0x53, 0x47, 0xe0, 0xa2, 0x11, 0x41, 0x0d,
-    0xe2, 0xe7
+    0x30,
+    0x82,
+    0x04,
+    0xa4,
+    0x02,
+    0x01,
+    0x00,
+    0x02,
+    0x82,
+    0x01,
+    0x01,
+    0x00,
+    0xc2,
+    0x44,
+    0xbc,
+    0xcf,
+    0x5b,
+    0xca,
+    0xcd,
+    0x80,
+    0x77,
+    0xae,
+    0xf9,
+    0x7a,
+    0x34,
+    0xbb,
+    0x37,
+    0x6f,
+    0x5c,
+    0x76,
+    0x4c,
+    0xe4,
+    0xbb,
+    0x0c,
+    0x1d,
+    0xe7,
+    0xfe,
+    0x0f,
+    0xda,
+    0xcf,
+    0x8c,
+    0x56,
+    0x65,
+    0x72,
+    0x6e,
+    0x2c,
+    0xf9,
+    0xfd,
+    0x87,
+    0x43,
+    0xeb,
+    0x4c,
+    0x26,
+    0xb1,
+    0xd3,
+    0xf0,
+    0x87,
+    0xb1,
+    0x18,
+    0x68,
+    0x14,
+    0x7d,
+    0x3c,
+    0x2a,
+    0xfa,
+    0xc2,
+    0x5d,
+    0x70,
+    0x19,
+    0x11,
+    0x00,
+    0x2e,
+    0xb3,
+    0x9c,
+    0x8e,
+    0x38,
+    0x08,
+    0xbe,
+    0xe3,
+    0xeb,
+    0x7d,
+    0x6e,
+    0xc7,
+    0x19,
+    0xc6,
+    0x7f,
+    0x59,
+    0x48,
+    0x84,
+    0x1b,
+    0xe3,
+    0x27,
+    0x30,
+    0x46,
+    0x30,
+    0xd3,
+    0xfc,
+    0xfc,
+    0xb3,
+    0x35,
+    0x75,
+    0xc4,
+    0x31,
+    0x1a,
+    0xc0,
+    0xc2,
+    0x4c,
+    0x0b,
+    0xc7,
+    0x01,
+    0x95,
+    0xb2,
+    0xdc,
+    0x17,
+    0x77,
+    0x9b,
+    0x09,
+    0x15,
+    0x04,
+    0xbc,
+    0xdb,
+    0x57,
+    0x0b,
+    0x26,
+    0xda,
+    0x59,
+    0x54,
+    0x0d,
+    0x6e,
+    0xb7,
+    0x89,
+    0xbc,
+    0x53,
+    0x9d,
+    0x5f,
+    0x8c,
+    0xad,
+    0x86,
+    0x97,
+    0xd2,
+    0x48,
+    0x4f,
+    0x5c,
+    0x94,
+    0xdd,
+    0x30,
+    0x2f,
+    0xcf,
+    0xfc,
+    0xde,
+    0x20,
+    0x31,
+    0x25,
+    0x9d,
+    0x29,
+    0x25,
+    0x78,
+    0xb7,
+    0xd2,
+    0x5b,
+    0x5d,
+    0x99,
+    0x5b,
+    0x08,
+    0x12,
+    0x81,
+    0x79,
+    0x89,
+    0xa0,
+    0xcf,
+    0x8f,
+    0x40,
+    0xb1,
+    0x77,
+    0x72,
+    0x3b,
+    0x13,
+    0xfc,
+    0x55,
+    0x43,
+    0x70,
+    0x29,
+    0xd5,
+    0x41,
+    0xed,
+    0x31,
+    0x4b,
+    0x2d,
+    0x6c,
+    0x7d,
+    0xcf,
+    0x99,
+    0x5f,
+    0xd1,
+    0x72,
+    0x9f,
+    0x8b,
+    0x32,
+    0x96,
+    0xde,
+    0x5d,
+    0x8b,
+    0x19,
+    0x77,
+    0x75,
+    0xff,
+    0x09,
+    0xbf,
+    0x26,
+    0xe9,
+    0xd7,
+    0x3d,
+    0xc7,
+    0x1a,
+    0x81,
+    0xcf,
+    0x05,
+    0x1b,
+    0x89,
+    0xbf,
+    0x45,
+    0x32,
+    0xbf,
+    0x5e,
+    0xc9,
+    0xe3,
+    0x5c,
+    0x33,
+    0x4a,
+    0x72,
+    0x47,
+    0xf4,
+    0x24,
+    0xae,
+    0x9b,
+    0x38,
+    0x24,
+    0x76,
+    0x9a,
+    0xa2,
+    0x9a,
+    0x50,
+    0x50,
+    0x49,
+    0xf5,
+    0x26,
+    0xb9,
+    0x55,
+    0xa6,
+    0x47,
+    0xc9,
+    0x14,
+    0xa2,
+    0xca,
+    0xd4,
+    0xa8,
+    0x8a,
+    0x9f,
+    0xe9,
+    0x5a,
+    0x5a,
+    0x12,
+    0xaa,
+    0x30,
+    0xd5,
+    0x78,
+    0x8b,
+    0x39,
+    0x02,
+    0x03,
+    0x01,
+    0x00,
+    0x01,
+    0x02,
+    0x82,
+    0x01,
+    0x00,
+    0x22,
+    0x5d,
+    0xb9,
+    0x8e,
+    0xef,
+    0x1c,
+    0x91,
+    0xbd,
+    0x03,
+    0xaf,
+    0x1a,
+    0xe8,
+    0x00,
+    0xf3,
+    0x0b,
+    0x8b,
+    0xf2,
+    0x2d,
+    0xe5,
+    0x4d,
+    0x63,
+    0x3f,
+    0x71,
+    0xfc,
+    0xeb,
+    0xc7,
+    0x4f,
+    0x3c,
+    0x7f,
+    0x05,
+    0x7b,
+    0x9d,
+    0xc2,
+    0x1a,
+    0xc7,
+    0xc0,
+    0x8f,
+    0x50,
+    0xb7,
+    0x0b,
+    0xba,
+    0x1e,
+    0xa4,
+    0x30,
+    0xfd,
+    0x38,
+    0x19,
+    0x6a,
+    0xb4,
+    0x11,
+    0x31,
+    0x77,
+    0x22,
+    0xf4,
+    0x06,
+    0x46,
+    0x81,
+    0xd0,
+    0xad,
+    0x99,
+    0x15,
+    0x62,
+    0x01,
+    0x10,
+    0xad,
+    0x8f,
+    0x63,
+    0x4f,
+    0x71,
+    0xd9,
+    0x8a,
+    0x74,
+    0x27,
+    0x56,
+    0xb8,
+    0xeb,
+    0x28,
+    0x9f,
+    0xac,
+    0x4f,
+    0xee,
+    0xec,
+    0xc3,
+    0xcf,
+    0x84,
+    0x86,
+    0x09,
+    0x87,
+    0xd0,
+    0x04,
+    0xfc,
+    0x70,
+    0xd0,
+    0x9f,
+    0xae,
+    0x87,
+    0x38,
+    0xd5,
+    0xb1,
+    0x6f,
+    0x3a,
+    0x1b,
+    0x16,
+    0xa8,
+    0x00,
+    0xf3,
+    0xcc,
+    0x6a,
+    0x42,
+    0x5d,
+    0x04,
+    0x16,
+    0x83,
+    0xf2,
+    0xe0,
+    0x79,
+    0x1d,
+    0xd8,
+    0x6f,
+    0x0f,
+    0xb7,
+    0x34,
+    0xf4,
+    0x45,
+    0xb5,
+    0x1e,
+    0xc5,
+    0xb5,
+    0x78,
+    0xa7,
+    0xd3,
+    0xa3,
+    0x23,
+    0x35,
+    0xbc,
+    0x7b,
+    0x01,
+    0x59,
+    0x7d,
+    0xee,
+    0xb9,
+    0x4f,
+    0xda,
+    0x28,
+    0xad,
+    0x5d,
+    0x25,
+    0xab,
+    0x66,
+    0x6a,
+    0xb0,
+    0x61,
+    0xf6,
+    0x12,
+    0xa7,
+    0xee,
+    0xd1,
+    0xe7,
+    0xb1,
+    0x8b,
+    0x91,
+    0x29,
+    0xba,
+    0xb5,
+    0xf8,
+    0x78,
+    0xc8,
+    0x6b,
+    0x76,
+    0x67,
+    0x32,
+    0xe8,
+    0xf3,
+    0x4e,
+    0x59,
+    0xba,
+    0xc1,
+    0x44,
+    0xc0,
+    0xec,
+    0x8d,
+    0x7c,
+    0x63,
+    0xb2,
+    0x6e,
+    0x0c,
+    0xb9,
+    0x33,
+    0x42,
+    0x0c,
+    0x8d,
+    0xae,
+    0x4e,
+    0x54,
+    0xc8,
+    0x8a,
+    0xef,
+    0xf9,
+    0x47,
+    0xc8,
+    0x99,
+    0x84,
+    0xc8,
+    0x46,
+    0xf6,
+    0xa6,
+    0x53,
+    0x59,
+    0xf8,
+    0x60,
+    0xe3,
+    0xd7,
+    0x1d,
+    0x10,
+    0x95,
+    0xf5,
+    0x6d,
+    0xf4,
+    0xa3,
+    0x18,
+    0x40,
+    0xd7,
+    0x14,
+    0x04,
+    0xac,
+    0x8c,
+    0x69,
+    0xd6,
+    0x14,
+    0xdc,
+    0xd8,
+    0xcc,
+    0xbc,
+    0x1c,
+    0xac,
+    0xd7,
+    0x21,
+    0x2b,
+    0x7e,
+    0x29,
+    0x88,
+    0x06,
+    0xa0,
+    0xf4,
+    0x06,
+    0x08,
+    0x14,
+    0x04,
+    0x4d,
+    0x32,
+    0x33,
+    0x84,
+    0x9c,
+    0x20,
+    0x8e,
+    0xcf,
+    0x02,
+    0x81,
+    0x81,
+    0x00,
+    0xf3,
+    0xf9,
+    0xbd,
+    0xd5,
+    0x43,
+    0x6f,
+    0x27,
+    0x4a,
+    0x92,
+    0xd6,
+    0x18,
+    0x3d,
+    0x4b,
+    0xf1,
+    0x77,
+    0x7c,
+    0xaf,
+    0xce,
+    0x01,
+    0x17,
+    0x98,
+    0xcb,
+    0xbe,
+    0x06,
+    0x86,
+    0x3a,
+    0x13,
+    0x72,
+    0x4b,
+    0x7c,
+    0x81,
+    0x51,
+    0x24,
+    0x5d,
+    0xc3,
+    0xe9,
+    0xa2,
+    0x63,
+    0x1e,
+    0x4a,
+    0xeb,
+    0x66,
+    0xae,
+    0x01,
+    0x5e,
+    0xa4,
+    0xa4,
+    0x74,
+    0x9e,
+    0xee,
+    0x32,
+    0xe5,
+    0x59,
+    0x1b,
+    0x37,
+    0xef,
+    0x7d,
+    0xb3,
+    0x42,
+    0x8c,
+    0x93,
+    0x8b,
+    0xd3,
+    0x1e,
+    0x83,
+    0x43,
+    0xb5,
+    0x88,
+    0x3e,
+    0x24,
+    0xeb,
+    0xdc,
+    0x92,
+    0x2d,
+    0xcc,
+    0x9a,
+    0x9d,
+    0xf1,
+    0x7d,
+    0x16,
+    0x71,
+    0xcb,
+    0x25,
+    0x47,
+    0x36,
+    0xb0,
+    0xc4,
+    0x6b,
+    0xc8,
+    0x53,
+    0x4a,
+    0x25,
+    0x80,
+    0x47,
+    0x77,
+    0xdb,
+    0x97,
+    0x13,
+    0x15,
+    0x0f,
+    0x4a,
+    0xfa,
+    0x0c,
+    0x6c,
+    0x44,
+    0x13,
+    0x2f,
+    0xbc,
+    0x9a,
+    0x6b,
+    0x13,
+    0x57,
+    0xfc,
+    0x42,
+    0xb9,
+    0xe9,
+    0xd3,
+    0x2e,
+    0xd2,
+    0x11,
+    0xf4,
+    0xc5,
+    0x84,
+    0x55,
+    0xd2,
+    0xdf,
+    0x1d,
+    0xa7,
+    0x02,
+    0x81,
+    0x81,
+    0x00,
+    0xcb,
+    0xd7,
+    0xd6,
+    0x9d,
+    0x71,
+    0xb3,
+    0x86,
+    0xbe,
+    0x68,
+    0xed,
+    0x67,
+    0xe1,
+    0x51,
+    0x92,
+    0x17,
+    0x60,
+    0x58,
+    0xb3,
+    0x2a,
+    0x56,
+    0xfd,
+    0x18,
+    0xfb,
+    0x39,
+    0x4b,
+    0x14,
+    0xc6,
+    0xf6,
+    0x67,
+    0x0e,
+    0x31,
+    0xe3,
+    0xb3,
+    0x2f,
+    0x1f,
+    0xec,
+    0x16,
+    0x1c,
+    0x23,
+    0x2b,
+    0x60,
+    0x36,
+    0xd1,
+    0xcb,
+    0x4a,
+    0x03,
+    0x6a,
+    0x3a,
+    0x4c,
+    0x8c,
+    0xf2,
+    0x73,
+    0x08,
+    0x23,
+    0x29,
+    0xda,
+    0xcb,
+    0xf7,
+    0xb6,
+    0x18,
+    0x97,
+    0xc6,
+    0xfe,
+    0xd4,
+    0x40,
+    0x06,
+    0x87,
+    0x9d,
+    0x6e,
+    0xbb,
+    0x5d,
+    0x14,
+    0x44,
+    0xc8,
+    0x19,
+    0xfa,
+    0x7f,
+    0x0c,
+    0xc5,
+    0x02,
+    0x92,
+    0x00,
+    0xbb,
+    0x2e,
+    0x4f,
+    0x50,
+    0xb0,
+    0x71,
+    0x9f,
+    0xf3,
+    0x94,
+    0x12,
+    0xb8,
+    0x6c,
+    0x5f,
+    0xe1,
+    0x83,
+    0x7b,
+    0xbc,
+    0x8c,
+    0x0a,
+    0x6f,
+    0x09,
+    0x6a,
+    0x35,
+    0x4f,
+    0xf9,
+    0xa4,
+    0x92,
+    0x93,
+    0xe3,
+    0xad,
+    0x36,
+    0x25,
+    0x28,
+    0x90,
+    0x85,
+    0xd2,
+    0x9f,
+    0x86,
+    0xfd,
+    0xd9,
+    0xa8,
+    0x61,
+    0xe9,
+    0xb2,
+    0xec,
+    0x1f,
+    0x02,
+    0x81,
+    0x81,
+    0x00,
+    0xdd,
+    0x1c,
+    0x52,
+    0xda,
+    0x2b,
+    0xc2,
+    0x5a,
+    0x26,
+    0xb0,
+    0xcb,
+    0x0d,
+    0xae,
+    0xc7,
+    0xdb,
+    0xf0,
+    0x41,
+    0x75,
+    0x87,
+    0x4a,
+    0xe0,
+    0x1a,
+    0xdf,
+    0x53,
+    0xb9,
+    0xcf,
+    0xfe,
+    0x64,
+    0x4f,
+    0x6a,
+    0x70,
+    0x4d,
+    0x36,
+    0xbf,
+    0xb1,
+    0xa6,
+    0xf3,
+    0x5f,
+    0xf3,
+    0x5a,
+    0xa9,
+    0xe5,
+    0x8b,
+    0xea,
+    0x59,
+    0x5d,
+    0x6f,
+    0xf3,
+    0x87,
+    0xa9,
+    0xde,
+    0x11,
+    0x0c,
+    0x60,
+    0x64,
+    0x55,
+    0x9e,
+    0x5c,
+    0x1a,
+    0x91,
+    0x4e,
+    0x9c,
+    0x0d,
+    0xd5,
+    0xe9,
+    0x4a,
+    0x67,
+    0x9b,
+    0xe6,
+    0xfd,
+    0x03,
+    0x33,
+    0x2b,
+    0x74,
+    0xe3,
+    0xc3,
+    0x11,
+    0xc1,
+    0xe0,
+    0xf1,
+    0x4f,
+    0xdd,
+    0x13,
+    0x92,
+    0x16,
+    0x67,
+    0x4f,
+    0x6e,
+    0xc4,
+    0x8c,
+    0x0a,
+    0x48,
+    0x21,
+    0x92,
+    0x8f,
+    0xb2,
+    0xe5,
+    0xb5,
+    0x96,
+    0x5a,
+    0xb8,
+    0xc0,
+    0x67,
+    0xbb,
+    0xc8,
+    0x87,
+    0x2d,
+    0xa8,
+    0x4e,
+    0xd2,
+    0xd8,
+    0x05,
+    0xf0,
+    0xf0,
+    0xb3,
+    0x7c,
+    0x90,
+    0x98,
+    0x8f,
+    0x4f,
+    0x5d,
+    0x6c,
+    0xab,
+    0x71,
+    0x92,
+    0xe2,
+    0x88,
+    0xc8,
+    0xf3,
+    0x02,
+    0x81,
+    0x81,
+    0x00,
+    0x99,
+    0x27,
+    0x5a,
+    0x00,
+    0x81,
+    0x65,
+    0x39,
+    0x5f,
+    0xe6,
+    0xc6,
+    0x38,
+    0xbe,
+    0x79,
+    0xe3,
+    0x21,
+    0xdd,
+    0x29,
+    0xc7,
+    0xb3,
+    0x90,
+    0x18,
+    0x29,
+    0xa4,
+    0xd7,
+    0xaf,
+    0x29,
+    0xb5,
+    0x33,
+    0x7c,
+    0xca,
+    0x95,
+    0x81,
+    0x57,
+    0x27,
+    0x98,
+    0xfc,
+    0x70,
+    0xc0,
+    0x43,
+    0x4c,
+    0x5b,
+    0xc5,
+    0xd4,
+    0x6a,
+    0xc0,
+    0xf9,
+    0x3f,
+    0xde,
+    0xfd,
+    0x95,
+    0x08,
+    0xb4,
+    0x94,
+    0xf0,
+    0x96,
+    0x89,
+    0xe5,
+    0xa6,
+    0x00,
+    0x13,
+    0x0a,
+    0x36,
+    0x61,
+    0x50,
+    0x67,
+    0xaa,
+    0x80,
+    0x4a,
+    0x30,
+    0xe0,
+    0x65,
+    0x56,
+    0xcd,
+    0x36,
+    0xeb,
+    0x0d,
+    0xe2,
+    0x57,
+    0x5d,
+    0xce,
+    0x48,
+    0x94,
+    0x74,
+    0x0e,
+    0x9f,
+    0x59,
+    0x28,
+    0xb8,
+    0xb6,
+    0x4c,
+    0xf4,
+    0x7b,
+    0xfc,
+    0x44,
+    0xb0,
+    0xe5,
+    0x67,
+    0x3c,
+    0x98,
+    0xb5,
+    0x3f,
+    0x41,
+    0x9d,
+    0xf9,
+    0x46,
+    0x85,
+    0x08,
+    0x34,
+    0x36,
+    0x4d,
+    0x17,
+    0x4b,
+    0x14,
+    0xdb,
+    0x66,
+    0x56,
+    0xef,
+    0xb5,
+    0x08,
+    0x57,
+    0x0c,
+    0x73,
+    0x74,
+    0xa7,
+    0xdc,
+    0x46,
+    0xaa,
+    0x51,
+    0x02,
+    0x81,
+    0x80,
+    0x1e,
+    0x50,
+    0x4c,
+    0xde,
+    0x9c,
+    0x60,
+    0x6d,
+    0xd7,
+    0x31,
+    0xf6,
+    0xd8,
+    0x4f,
+    0xc2,
+    0x25,
+    0x7d,
+    0x83,
+    0xb3,
+    0xe7,
+    0xed,
+    0x92,
+    0xe7,
+    0x28,
+    0x1e,
+    0xb3,
+    0x9b,
+    0xcb,
+    0xf2,
+    0x86,
+    0xa4,
+    0x49,
+    0x45,
+    0x5e,
+    0xba,
+    0x1d,
+    0xdb,
+    0x21,
+    0x5d,
+    0xdf,
+    0xeb,
+    0x3c,
+    0x5e,
+    0x01,
+    0xc6,
+    0x68,
+    0x25,
+    0x28,
+    0xe6,
+    0x1a,
+    0xbf,
+    0xc1,
+    0xa1,
+    0xc5,
+    0x92,
+    0x0b,
+    0x08,
+    0x43,
+    0x0e,
+    0x5a,
+    0xa3,
+    0x85,
+    0x8a,
+    0x65,
+    0xb4,
+    0x54,
+    0xa1,
+    0x4c,
+    0x20,
+    0xa2,
+    0x5a,
+    0x08,
+    0xf6,
+    0x90,
+    0x0d,
+    0x9a,
+    0xd7,
+    0x20,
+    0xf1,
+    0x10,
+    0x66,
+    0x28,
+    0x4c,
+    0x22,
+    0x56,
+    0xa6,
+    0xb9,
+    0xff,
+    0xd0,
+    0x6a,
+    0x62,
+    0x8c,
+    0x9f,
+    0xf8,
+    0x7c,
+    0xf4,
+    0xad,
+    0xd7,
+    0xe8,
+    0xf9,
+    0x87,
+    0x43,
+    0xbf,
+    0x73,
+    0x5b,
+    0x04,
+    0xc7,
+    0xd0,
+    0x77,
+    0xcc,
+    0xe3,
+    0xbe,
+    0xda,
+    0xc2,
+    0x07,
+    0xed,
+    0x8d,
+    0x2a,
+    0x15,
+    0x77,
+    0x1d,
+    0x53,
+    0x47,
+    0xe0,
+    0xa2,
+    0x11,
+    0x41,
+    0x0d,
+    0xe2,
+    0xe7,
 };
 
 /* The matching public key used for encryption*/
 static const unsigned char pub_key_der[] = {
-    0x30, 0x82, 0x01, 0x22, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86,
-    0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x01, 0x05, 0x00, 0x03,
-    0x82, 0x01, 0x0f, 0x00, 0x30, 0x82, 0x01, 0x0a, 0x02, 0x82,
-    0x01, 0x01, 0x00, 0xc2, 0x44, 0xbc, 0xcf, 0x5b, 0xca, 0xcd,
-    0x80, 0x77, 0xae, 0xf9, 0x7a, 0x34, 0xbb, 0x37, 0x6f, 0x5c,
-    0x76, 0x4c, 0xe4, 0xbb, 0x0c, 0x1d, 0xe7, 0xfe, 0x0f, 0xda,
-    0xcf, 0x8c, 0x56, 0x65, 0x72, 0x6e, 0x2c, 0xf9, 0xfd, 0x87,
-    0x43, 0xeb, 0x4c, 0x26, 0xb1, 0xd3, 0xf0, 0x87, 0xb1, 0x18,
-    0x68, 0x14, 0x7d, 0x3c, 0x2a, 0xfa, 0xc2, 0x5d, 0x70, 0x19,
-    0x11, 0x00, 0x2e, 0xb3, 0x9c, 0x8e, 0x38, 0x08, 0xbe, 0xe3,
-    0xeb, 0x7d, 0x6e, 0xc7, 0x19, 0xc6, 0x7f, 0x59, 0x48, 0x84,
-    0x1b, 0xe3, 0x27, 0x30, 0x46, 0x30, 0xd3, 0xfc, 0xfc, 0xb3,
-    0x35, 0x75, 0xc4, 0x31, 0x1a, 0xc0, 0xc2, 0x4c, 0x0b, 0xc7,
-    0x01, 0x95, 0xb2, 0xdc, 0x17, 0x77, 0x9b, 0x09, 0x15, 0x04,
-    0xbc, 0xdb, 0x57, 0x0b, 0x26, 0xda, 0x59, 0x54, 0x0d, 0x6e,
-    0xb7, 0x89, 0xbc, 0x53, 0x9d, 0x5f, 0x8c, 0xad, 0x86, 0x97,
-    0xd2, 0x48, 0x4f, 0x5c, 0x94, 0xdd, 0x30, 0x2f, 0xcf, 0xfc,
-    0xde, 0x20, 0x31, 0x25, 0x9d, 0x29, 0x25, 0x78, 0xb7, 0xd2,
-    0x5b, 0x5d, 0x99, 0x5b, 0x08, 0x12, 0x81, 0x79, 0x89, 0xa0,
-    0xcf, 0x8f, 0x40, 0xb1, 0x77, 0x72, 0x3b, 0x13, 0xfc, 0x55,
-    0x43, 0x70, 0x29, 0xd5, 0x41, 0xed, 0x31, 0x4b, 0x2d, 0x6c,
-    0x7d, 0xcf, 0x99, 0x5f, 0xd1, 0x72, 0x9f, 0x8b, 0x32, 0x96,
-    0xde, 0x5d, 0x8b, 0x19, 0x77, 0x75, 0xff, 0x09, 0xbf, 0x26,
-    0xe9, 0xd7, 0x3d, 0xc7, 0x1a, 0x81, 0xcf, 0x05, 0x1b, 0x89,
-    0xbf, 0x45, 0x32, 0xbf, 0x5e, 0xc9, 0xe3, 0x5c, 0x33, 0x4a,
-    0x72, 0x47, 0xf4, 0x24, 0xae, 0x9b, 0x38, 0x24, 0x76, 0x9a,
-    0xa2, 0x9a, 0x50, 0x50, 0x49, 0xf5, 0x26, 0xb9, 0x55, 0xa6,
-    0x47, 0xc9, 0x14, 0xa2, 0xca, 0xd4, 0xa8, 0x8a, 0x9f, 0xe9,
-    0x5a, 0x5a, 0x12, 0xaa, 0x30, 0xd5, 0x78, 0x8b, 0x39, 0x02,
-    0x03, 0x01, 0x00, 0x01
+    0x30,
+    0x82,
+    0x01,
+    0x22,
+    0x30,
+    0x0d,
+    0x06,
+    0x09,
+    0x2a,
+    0x86,
+    0x48,
+    0x86,
+    0xf7,
+    0x0d,
+    0x01,
+    0x01,
+    0x01,
+    0x05,
+    0x00,
+    0x03,
+    0x82,
+    0x01,
+    0x0f,
+    0x00,
+    0x30,
+    0x82,
+    0x01,
+    0x0a,
+    0x02,
+    0x82,
+    0x01,
+    0x01,
+    0x00,
+    0xc2,
+    0x44,
+    0xbc,
+    0xcf,
+    0x5b,
+    0xca,
+    0xcd,
+    0x80,
+    0x77,
+    0xae,
+    0xf9,
+    0x7a,
+    0x34,
+    0xbb,
+    0x37,
+    0x6f,
+    0x5c,
+    0x76,
+    0x4c,
+    0xe4,
+    0xbb,
+    0x0c,
+    0x1d,
+    0xe7,
+    0xfe,
+    0x0f,
+    0xda,
+    0xcf,
+    0x8c,
+    0x56,
+    0x65,
+    0x72,
+    0x6e,
+    0x2c,
+    0xf9,
+    0xfd,
+    0x87,
+    0x43,
+    0xeb,
+    0x4c,
+    0x26,
+    0xb1,
+    0xd3,
+    0xf0,
+    0x87,
+    0xb1,
+    0x18,
+    0x68,
+    0x14,
+    0x7d,
+    0x3c,
+    0x2a,
+    0xfa,
+    0xc2,
+    0x5d,
+    0x70,
+    0x19,
+    0x11,
+    0x00,
+    0x2e,
+    0xb3,
+    0x9c,
+    0x8e,
+    0x38,
+    0x08,
+    0xbe,
+    0xe3,
+    0xeb,
+    0x7d,
+    0x6e,
+    0xc7,
+    0x19,
+    0xc6,
+    0x7f,
+    0x59,
+    0x48,
+    0x84,
+    0x1b,
+    0xe3,
+    0x27,
+    0x30,
+    0x46,
+    0x30,
+    0xd3,
+    0xfc,
+    0xfc,
+    0xb3,
+    0x35,
+    0x75,
+    0xc4,
+    0x31,
+    0x1a,
+    0xc0,
+    0xc2,
+    0x4c,
+    0x0b,
+    0xc7,
+    0x01,
+    0x95,
+    0xb2,
+    0xdc,
+    0x17,
+    0x77,
+    0x9b,
+    0x09,
+    0x15,
+    0x04,
+    0xbc,
+    0xdb,
+    0x57,
+    0x0b,
+    0x26,
+    0xda,
+    0x59,
+    0x54,
+    0x0d,
+    0x6e,
+    0xb7,
+    0x89,
+    0xbc,
+    0x53,
+    0x9d,
+    0x5f,
+    0x8c,
+    0xad,
+    0x86,
+    0x97,
+    0xd2,
+    0x48,
+    0x4f,
+    0x5c,
+    0x94,
+    0xdd,
+    0x30,
+    0x2f,
+    0xcf,
+    0xfc,
+    0xde,
+    0x20,
+    0x31,
+    0x25,
+    0x9d,
+    0x29,
+    0x25,
+    0x78,
+    0xb7,
+    0xd2,
+    0x5b,
+    0x5d,
+    0x99,
+    0x5b,
+    0x08,
+    0x12,
+    0x81,
+    0x79,
+    0x89,
+    0xa0,
+    0xcf,
+    0x8f,
+    0x40,
+    0xb1,
+    0x77,
+    0x72,
+    0x3b,
+    0x13,
+    0xfc,
+    0x55,
+    0x43,
+    0x70,
+    0x29,
+    0xd5,
+    0x41,
+    0xed,
+    0x31,
+    0x4b,
+    0x2d,
+    0x6c,
+    0x7d,
+    0xcf,
+    0x99,
+    0x5f,
+    0xd1,
+    0x72,
+    0x9f,
+    0x8b,
+    0x32,
+    0x96,
+    0xde,
+    0x5d,
+    0x8b,
+    0x19,
+    0x77,
+    0x75,
+    0xff,
+    0x09,
+    0xbf,
+    0x26,
+    0xe9,
+    0xd7,
+    0x3d,
+    0xc7,
+    0x1a,
+    0x81,
+    0xcf,
+    0x05,
+    0x1b,
+    0x89,
+    0xbf,
+    0x45,
+    0x32,
+    0xbf,
+    0x5e,
+    0xc9,
+    0xe3,
+    0x5c,
+    0x33,
+    0x4a,
+    0x72,
+    0x47,
+    0xf4,
+    0x24,
+    0xae,
+    0x9b,
+    0x38,
+    0x24,
+    0x76,
+    0x9a,
+    0xa2,
+    0x9a,
+    0x50,
+    0x50,
+    0x49,
+    0xf5,
+    0x26,
+    0xb9,
+    0x55,
+    0xa6,
+    0x47,
+    0xc9,
+    0x14,
+    0xa2,
+    0xca,
+    0xd4,
+    0xa8,
+    0x8a,
+    0x9f,
+    0xe9,
+    0x5a,
+    0x5a,
+    0x12,
+    0xaa,
+    0x30,
+    0xd5,
+    0x78,
+    0x8b,
+    0x39,
+    0x02,
+    0x03,
+    0x01,
+    0x00,
+    0x01,
 };
diff --git a/demos/guide/build.info b/demos/guide/build.info
index 7b5b54f073..de184ff0d1 100644
--- a/demos/guide/build.info
+++ b/demos/guide/build.info
@@ -5,7 +5,6 @@
 #    LD_LIBRARY_PATH=../.. ./tls-client-block www.example.com 443
 
 PROGRAMS{noinst} = tls-client-block \
-                   tls-server-block \
                    quic-client-block \
                    quic-multi-stream \
                    tls-client-non-block \
@@ -18,10 +17,6 @@ INCLUDE[tls-client-block]=../../include
 SOURCE[tls-client-block]=tls-client-block.c
 DEPEND[tls-client-block]=../../libcrypto ../../libssl
 
-INCLUDE[tls-server-block]=../../include
-SOURCE[tls-server-block]=tls-server-block.c
-DEPEND[tls-server-block]=../../libcrypto ../../libssl
-
 INCLUDE[quic-client-block]=../../include
 SOURCE[quic-client-block]=quic-client-block.c
 DEPEND[quic-client-block]=../../libcrypto ../../libssl
diff --git a/demos/guide/quic-client-block.c b/demos/guide/quic-client-block.c
index 805569d8eb..80eccbab84 100644
--- a/demos/guide/quic-client-block.c
+++ b/demos/guide/quic-client-block.c
@@ -1,5 +1,5 @@
 /*
- *  Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved.
+ *  Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  *  Licensed under the Apache License 2.0 (the "License").  You may not use
  *  this file except in compliance with the License.  You can obtain a copy
@@ -109,8 +109,8 @@ static BIO *create_socket_bio(const char *hostname, const char *port,
 }
 
 /*
- * Simple application to send a basic HTTP/1.1 request to a server and
- * print the response on the screen. Note that HTTP/1.1 over QUIC is
+ * Simple application to send a basic HTTP/1.0 request to a server and
+ * print the response on the screen. Note that HTTP/1.0 over QUIC is
  * non-standard and will not typically be supported by real world servers. This
  * is for demonstration purposes only.
  */
@@ -121,8 +121,8 @@ int main(int argc, char *argv[])
     BIO *bio = NULL;
     int res = EXIT_FAILURE;
     int ret;
-    unsigned char alpn[] = { 8, 'h', 't', 't', 'p', '/', '1', '.', '1' };
-    const char *request_start = "GET / HTTP/1.1\r\nConnection: close\r\nHost: ";
+    unsigned char alpn[] = { 8, 'h', 't', 't', 'p', '/', '1', '.', '0' };
+    const char *request_start = "GET / HTTP/1.0\r\nConnection: close\r\nHost: ";
     const char *request_end = "\r\n\r\n";
     size_t written, readbytes;
     char buf[160];
@@ -204,7 +204,7 @@ int main(int argc, char *argv[])
      * Virtually all clients should do this unless you really know what you
      * are doing.
      */
-    if (!SSL_set1_dnsname(ssl, hostname)) {
+    if (!SSL_set1_host(ssl, hostname)) {
         printf("Failed to set the certificate verification hostname");
         goto end;
     }
diff --git a/demos/guide/quic-client-non-block.c b/demos/guide/quic-client-non-block.c
index 0271285773..9e8760dde2 100644
--- a/demos/guide/quic-client-non-block.c
+++ b/demos/guide/quic-client-non-block.c
@@ -1,5 +1,5 @@
 /*
- *  Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved.
+ *  Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  *  Licensed under the Apache License 2.0 (the "License").  You may not use
  *  this file except in compliance with the License.  You can obtain a copy
@@ -216,8 +216,8 @@ static int handle_io_failure(SSL *ssl, int res)
     }
 }
 /*
- * Simple application to send a basic HTTP/1.1 request to a server and
- * print the response on the screen. Note that HTTP/1.1 over QUIC is
+ * Simple application to send a basic HTTP/1.0 request to a server and
+ * print the response on the screen. Note that HTTP/1.0 over QUIC is
  * non-standard and will not typically be supported by real world servers. This
  * is for demonstration purposes only.
  */
@@ -228,8 +228,8 @@ int main(int argc, char *argv[])
     BIO *bio = NULL;
     int res = EXIT_FAILURE;
     int ret;
-    unsigned char alpn[] = { 8, 'h', 't', 't', 'p', '/', '1', '.', '1' };
-    const char *request_start = "GET / HTTP/1.1\r\nConnection: close\r\nHost: ";
+    unsigned char alpn[] = { 8, 'h', 't', 't', 'p', '/', '1', '.', '0' };
+    const char *request_start = "GET / HTTP/1.0\r\nConnection: close\r\nHost: ";
     const char *request_end = "\r\n\r\n";
     size_t written, readbytes = 0;
     char buf[160];
@@ -313,7 +313,7 @@ int main(int argc, char *argv[])
      * Virtually all clients should do this unless you really know what you
      * are doing.
      */
-    if (!SSL_set1_dnsname(ssl, hostname)) {
+    if (!SSL_set1_host(ssl, hostname)) {
         printf("Failed to set the certificate verification hostname");
         goto end;
     }
diff --git a/demos/guide/quic-multi-stream.c b/demos/guide/quic-multi-stream.c
index fd92243225..d08ab4dac1 100644
--- a/demos/guide/quic-multi-stream.c
+++ b/demos/guide/quic-multi-stream.c
@@ -1,5 +1,5 @@
 /*
- *  Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved.
+ *  Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  *  Licensed under the Apache License 2.0 (the "License").  You may not use
  *  this file except in compliance with the License.  You can obtain a copy
@@ -126,8 +126,8 @@ static int write_a_request(SSL *stream, const char *request_start,
 }
 
 /*
- * Simple application to send basic HTTP/1.1 requests to a server and print the
- * response on the screen. Note that HTTP/1.1 over QUIC is not a real protocol
+ * Simple application to send basic HTTP/1.0 requests to a server and print the
+ * response on the screen. Note that HTTP/1.0 over QUIC is not a real protocol
  * and will not be supported by real world servers. This is for demonstration
  * purposes only.
  */
@@ -139,9 +139,9 @@ int main(int argc, char *argv[])
     BIO *bio = NULL;
     int res = EXIT_FAILURE;
     int ret;
-    unsigned char alpn[] = { 8, 'h', 't', 't', 'p', '/', '1', '.', '1' };
-    const char *request1_start = "GET /request1.html HTTP/1.1\r\nConnection: close\r\nHost: ";
-    const char *request2_start = "GET /request2.html HTTP/1.1\r\nConnection: close\r\nHost: ";
+    unsigned char alpn[] = { 8, 'h', 't', 't', 'p', '/', '1', '.', '0' };
+    const char *request1_start = "GET /request1.html HTTP/1.0\r\nConnection: close\r\nHost: ";
+    const char *request2_start = "GET /request2.html HTTP/1.0\r\nConnection: close\r\nHost: ";
     size_t readbytes;
     char buf[160];
     BIO_ADDR *peer_addr = NULL;
@@ -231,7 +231,7 @@ int main(int argc, char *argv[])
      * Virtually all clients should do this unless you really know what you
      * are doing.
      */
-    if (!SSL_set1_dnsname(ssl, hostname)) {
+    if (!SSL_set1_host(ssl, hostname)) {
         printf("Failed to set the certificate verification hostname");
         goto end;
     }
@@ -351,7 +351,7 @@ int main(int argc, char *argv[])
     }
 
     /*
-     * In our hypothetical HTTP/1.1 over QUIC protocol that we are using we
+     * In our hypothetical HTTP/1.0 over QUIC protocol that we are using we
      * assume that the server will respond with a server initiated stream
      * containing the data requested in our uni-directional stream. This doesn't
      * really make sense to do in a real protocol, but its just for
diff --git a/demos/guide/quic-server-block.c b/demos/guide/quic-server-block.c
index 434516679b..b97a54f150 100644
--- a/demos/guide/quic-server-block.c
+++ b/demos/guide/quic-server-block.c
@@ -51,6 +51,15 @@ static void errx(int status, const char *fmt, ...)
     va_end(ap);
     exit(status);
 }
+
+static void warnx(const char *fmt, ...)
+{
+    va_list ap;
+
+    va_start(ap, fmt);
+    vwarnx(fmt, ap);
+    va_end(ap);
+}
 #endif
 
 /*
@@ -268,7 +277,7 @@ err:
     return ok;
 }
 
-/* Minimal QUIC HTTP/1.1 server. */
+/* Minimal QUIC HTTP/1.0 server. */
 int main(int argc, char *argv[])
 {
     int res = EXIT_FAILURE;
@@ -276,6 +285,8 @@ int main(int argc, char *argv[])
     int fd;
     unsigned long port;
 #ifdef _WIN32
+    static const char *progname;
+
     progname = argv[0];
 #endif
 
diff --git a/demos/guide/quic-server-non-block.c b/demos/guide/quic-server-non-block.c
index eb954f9f79..15563c6ca8 100644
--- a/demos/guide/quic-server-non-block.c
+++ b/demos/guide/quic-server-non-block.c
@@ -51,6 +51,15 @@ static void errx(int status, const char *fmt, ...)
     va_end(ap);
     exit(status);
 }
+
+static void warnx(const char *fmt, ...)
+{
+    va_list ap;
+
+    va_start(ap, fmt);
+    vwarnx(fmt, ap);
+    va_end(ap);
+}
 #endif
 
 /*
@@ -454,7 +463,7 @@ err:
     return ok;
 }
 
-/* Minimal QUIC HTTP/1.1 server. */
+/* Minimal QUIC HTTP/1.0 server. */
 int main(int argc, char *argv[])
 {
     int res = EXIT_FAILURE;
diff --git a/demos/guide/tls-client-block.c b/demos/guide/tls-client-block.c
index c94e09cc07..4536b1ffa0 100644
--- a/demos/guide/tls-client-block.c
+++ b/demos/guide/tls-client-block.c
@@ -1,5 +1,5 @@
 /*
- *  Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved.
+ *  Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  *  Licensed under the Apache License 2.0 (the "License").  You may not use
  *  this file except in compliance with the License.  You can obtain a copy
@@ -94,7 +94,7 @@ static BIO *create_socket_bio(const char *hostname, const char *port, int family
 }
 
 /*
- * Simple application to send a basic HTTP/1.1 request to a server and
+ * Simple application to send a basic HTTP/1.0 request to a server and
  * print the response on the screen.
  */
 int main(int argc, char *argv[])
@@ -104,7 +104,7 @@ int main(int argc, char *argv[])
     BIO *bio = NULL;
     int res = EXIT_FAILURE;
     int ret;
-    const char *request_start = "GET / HTTP/1.1\r\nConnection: close\r\nHost: ";
+    const char *request_start = "GET / HTTP/1.0\r\nConnection: close\r\nHost: ";
     const char *request_end = "\r\n\r\n";
     size_t written, readbytes;
     char buf[160];
@@ -194,7 +194,7 @@ int main(int argc, char *argv[])
      * Virtually all clients should do this unless you really know what you
      * are doing.
      */
-    if (!SSL_set1_dnsname(ssl, hostname)) {
+    if (!SSL_set1_host(ssl, hostname)) {
         printf("Failed to set the certificate verification hostname");
         goto end;
     }
diff --git a/demos/guide/tls-client-non-block.c b/demos/guide/tls-client-non-block.c
index 9c21a5df1e..3103e6725b 100644
--- a/demos/guide/tls-client-non-block.c
+++ b/demos/guide/tls-client-non-block.c
@@ -1,5 +1,5 @@
 /*
- *  Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved.
+ *  Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  *  Licensed under the Apache License 2.0 (the "License").  You may not use
  *  this file except in compliance with the License.  You can obtain a copy
@@ -171,7 +171,7 @@ static int handle_io_failure(SSL *ssl, int res)
 }
 
 /*
- * Simple application to send a basic HTTP/1.1 request to a server and
+ * Simple application to send a basic HTTP/1.0 request to a server and
  * print the response on the screen.
  */
 int main(int argc, char *argv[])
@@ -181,7 +181,7 @@ int main(int argc, char *argv[])
     BIO *bio = NULL;
     int res = EXIT_FAILURE;
     int ret;
-    const char *request_start = "GET / HTTP/1.1\r\nConnection: close\r\nHost: ";
+    const char *request_start = "GET / HTTP/1.0\r\nConnection: close\r\nHost: ";
     const char *request_end = "\r\n\r\n";
     size_t written, readbytes = 0;
     char buf[160];
@@ -273,7 +273,7 @@ int main(int argc, char *argv[])
      * Virtually all clients should do this unless you really know what you
      * are doing.
      */
-    if (!SSL_set1_dnsname(ssl, hostname)) {
+    if (!SSL_set1_host(ssl, hostname)) {
         printf("Failed to set the certificate verification hostname");
         goto end;
     }
diff --git a/demos/guide/tls-server-block.c b/demos/guide/tls-server-block.c
index 8e8410f995..2bee2219ed 100644
--- a/demos/guide/tls-server-block.c
+++ b/demos/guide/tls-server-block.c
@@ -64,7 +64,6 @@ int main(int argc, char *argv[])
 {
     int res = EXIT_FAILURE;
     long opts;
-    long old_timeout;
     const char *hostport;
     SSL_CTX *ctx = NULL;
     BIO *acceptor_bio;
@@ -175,11 +174,7 @@ int main(int argc, char *argv[])
      * byte array, that identifies the server application, and reduces the
      * chance of inappropriate cache sharing.
      */
-    if (SSL_CTX_set_session_id_context(ctx, (void *)cache_id, sizeof(cache_id)) <= 0) {
-        SSL_CTX_free(ctx);
-        ERR_print_errors_fp(stderr);
-        errx(res, "Failed to set server session ID context");
-    }
+    SSL_CTX_set_session_id_context(ctx, (void *)cache_id, sizeof(cache_id));
     SSL_CTX_set_session_cache_mode(ctx, SSL_SESS_CACHE_SERVER);
 
     /*
@@ -196,9 +191,7 @@ int main(int argc, char *argv[])
      * loaded servers with sporadic connections from any given client, a longer
      * time may be appropriate.
      */
-    old_timeout = SSL_CTX_set_timeout(ctx, 3600);
-    if (old_timeout != 3600)
-        warnx("Changing session timeout from %ld to 3600", old_timeout);
+    SSL_CTX_set_timeout(ctx, 3600);
 
     /*
      * Clients rarely employ certificate-based authentication, and so we don't
diff --git a/demos/http3/ossl-nghttp3-demo-server.c b/demos/http3/ossl-nghttp3-demo-server.c
index 227ac6e264..b2b4d954f4 100644
--- a/demos/http3/ossl-nghttp3-demo-server.c
+++ b/demos/http3/ossl-nghttp3-demo-server.c
@@ -291,7 +291,7 @@ static int on_recv_header(nghttp3_conn *conn, int64_t stream_id, int32_t token,
     fprintf(stdout, "\n");
 
     if (token == NGHTTP3_QPACK_TOKEN__PATH) {
-        int len = (((vvalue.len) < (MAXURL)) ? (vvalue.len) : (MAXURL - 1));
+        int len = (((vvalue.len) < (MAXURL)) ? (vvalue.len) : (MAXURL));
 
         memset(h3ssl->url, 0, sizeof(h3ssl->url));
         if (vvalue.base[0] == '/') {
@@ -323,7 +323,7 @@ static int on_recv_data(nghttp3_conn *conn, int64_t stream_id,
     const uint8_t *data, size_t datalen,
     void *conn_user_data, void *stream_user_data)
 {
-    fprintf(stderr, "on_recv_data! %zu\n", datalen);
+    fprintf(stderr, "on_recv_data! %ld\n", (unsigned long)datalen);
     fprintf(stderr, "on_recv_data! %.*s\n", (int)datalen, data);
     return 0;
 }
@@ -502,7 +502,7 @@ static int read_from_ssl_ids(nghttp3_conn **curh3conn, struct h3ssl *h3ssl)
         printf("SSL_poll failed\n");
         return -1; /* something is wrong */
     }
-    printf("read_from_ssl_ids %zu events\n", result_count);
+    printf("read_from_ssl_ids %ld events\n", (unsigned long)result_count);
     if (result_count == 0) {
         /* Timeout may be something somewhere */
         return 0;
@@ -862,12 +862,12 @@ static int quic_server_write(struct h3ssl *h3ssl, uint64_t streamid,
                 ERR_print_errors_fp(stderr);
                 return 0;
             }
-            printf("written %zu on %llu flags %llu\n", len,
+            printf("written %lld on %lld flags %lld\n", (unsigned long long)len,
                 (unsigned long long)streamid, (unsigned long long)flags);
             return 1;
         }
     }
-    printf("quic_server_write %zu on %llu (NOT FOUND!)\n", len,
+    printf("quic_server_write %lld on %lld (NOT FOUND!)\n", (unsigned long long)len,
         (unsigned long long)streamid);
     return 0;
 }
@@ -1035,7 +1035,7 @@ static int wait_for_activity(SSL *ssl)
      * "select" (with updated timeouts).
      */
 
-    return select(sock + 1, &read_fd, &write_fd, NULL, tvp);
+    return (select(sock + 1, &read_fd, &write_fd, NULL, tvp));
 }
 
 /* Main loop for server to accept QUIC connections. */
@@ -1226,8 +1226,8 @@ static int run_quic_server(SSL_CTX *ctx, int fd)
                 size_t numbytes = vec[i].len;
                 int flagwrite = 0;
 
-                printf("quic_server_write on %llu for %zu\n",
-                    (unsigned long long)streamid, vec[i].len);
+                printf("quic_server_write on %llu for %ld\n",
+                    (unsigned long long)streamid, (unsigned long)vec[i].len);
                 if (fin && i == sveccnt - 1)
                     flagwrite = SSL_WRITE_FLAG_CONCLUDE;
                 if (!quic_server_write(&h3ssl, streamid, vec[i].base,
diff --git a/demos/http3/ossl-nghttp3-demo.c b/demos/http3/ossl-nghttp3-demo.c
index 3f82a27443..a8d5cebbf2 100644
--- a/demos/http3/ossl-nghttp3-demo.c
+++ b/demos/http3/ossl-nghttp3-demo.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -14,19 +14,6 @@
 
 static int done;
 
-/**
- * @brief variable to record output basename path
- */
-static char *dlpath = NULL;
-
-/**
- * @brief struct to hold user data for async http3 writes
- */
-struct stream_user_data {
-    char *outpath;
-    FILE *fp;
-};
-
 static void make_nv(nghttp3_nv *nv, const char *name, const char *value)
 {
     nv->name = (uint8_t *)name;
@@ -67,94 +54,58 @@ static int on_end_headers(nghttp3_conn *h3conn, int64_t stream_id,
 
 static int on_recv_data(nghttp3_conn *h3conn, int64_t stream_id,
     const uint8_t *data, size_t datalen,
-    void *conn_user_data, void *user_data)
+    void *conn_user_data, void *stream_user_data)
 {
-    FILE *outfp;
     size_t wr;
-    struct stream_user_data *sdata = OSSL_DEMO_H3_STREAM_get_user_data((const OSSL_DEMO_H3_STREAM *)user_data);
 
-    if (dlpath == NULL) {
-        outfp = stdout;
-    } else {
-        if (sdata->fp == NULL) {
-            sdata->fp = fopen(sdata->outpath, "w+");
-        }
-        if (sdata->fp == NULL) {
-            fprintf(stderr, "Failed to open %s for writing\n", sdata->outpath);
-            return 1;
-        }
-        outfp = sdata->fp;
-    }
-    /* HTTP response body data - write it. */
+    /* HTTP response body data - write it to stdout. */
     while (datalen > 0) {
-        fprintf(stderr, "writing %lu bytes to %s\n", datalen, sdata->outpath);
-        wr = fwrite(data, 1, datalen, outfp);
-        if (ferror(outfp))
+        wr = fwrite(data, 1, datalen, stdout);
+        if (ferror(stdout))
             return 1;
 
         data += wr;
         datalen -= wr;
     }
+
     return 0;
 }
 
 static int on_end_stream(nghttp3_conn *h3conn, int64_t stream_id,
-    void *conn_user_data, void *user_data)
+    void *conn_user_data, void *stream_user_data)
 {
     /* HTTP transaction is done - set done flag so that we stop looping. */
     done = 1;
     return 0;
 }
 
-static int try_conn(OSSL_DEMO_H3_CONN *conn, const char *bare_hostname, const char *path)
+static int try_conn(OSSL_DEMO_H3_CONN *conn, const char *bare_hostname)
 {
     nghttp3_nv nva[16];
     size_t num_nv = 0;
-    struct stream_user_data *sdata;
-    size_t needed_size;
-    int pathsize;
 
     /* Build HTTP headers. */
     make_nv(&nva[num_nv++], ":method", "GET");
     make_nv(&nva[num_nv++], ":scheme", "https");
     make_nv(&nva[num_nv++], ":authority", bare_hostname);
-    make_nv(&nva[num_nv++], ":path", path);
+    make_nv(&nva[num_nv++], ":path", "/");
     make_nv(&nva[num_nv++], "user-agent", "OpenSSL-Demo/nghttp3");
 
-    needed_size = sizeof(struct stream_user_data);
-    pathsize = snprintf(NULL, 0, "%s/%s", dlpath, path);
-    if (pathsize < 0) {
-        fprintf(stderr, "Unable to format path string\n");
-        return 0;
-    }
-    needed_size += pathsize;
-
-    sdata = malloc(needed_size + 1);
-    if (sdata == NULL)
-        return 0;
-    sdata->outpath = (char *)(sdata + 1);
-    sprintf(sdata->outpath, "%s/%s", dlpath, path);
-    sdata->fp = NULL;
-    fprintf(stderr, "Requesting %s\n", sdata->outpath);
     /* Submit request. */
-    if (!OSSL_DEMO_H3_CONN_submit_request(conn, nva, num_nv, NULL, sdata)) {
-        fprintf(stderr, "Cannot submit HTTP/3 request\n");
+    if (!OSSL_DEMO_H3_CONN_submit_request(conn, nva, num_nv, NULL, NULL)) {
+        ERR_raise_data(ERR_LIB_USER, ERR_R_OPERATION_FAIL,
+            "cannot submit HTTP/3 request");
         return 0;
     }
 
     /* Wait for request to complete. */
     done = 0;
-    while (!done) {
+    while (!done)
         if (!OSSL_DEMO_H3_CONN_handle_events(conn)) {
-            fprintf(stderr, "Cannot handle events\n");
+            ERR_raise_data(ERR_LIB_USER, ERR_R_OPERATION_FAIL,
+                "cannot handle events");
             return 0;
         }
-    }
-    if (sdata->fp != NULL) {
-        fclose(sdata->fp);
-        fprintf(stderr, "Closing local FILE pointer for %s\n", sdata->outpath);
-    }
-    free(sdata);
     return 1;
 }
 
@@ -169,53 +120,13 @@ int main(int argc, char **argv)
     char *hostname, *service;
     BIO_ADDRINFO *bai = NULL;
     const BIO_ADDRINFO *bai_walk;
-    FILE *req_fp = NULL;
-    size_t req_count = 0;
-    char **req_array = NULL;
-    size_t i;
-    char buffer[PATH_MAX];
 
     /* Check arguments. */
     if (argc < 2) {
-        fprintf(stderr, "usage: %s  [requestfile.txt ]\n", argv[0]);
+        fprintf(stderr, "usage: %s \n", argv[0]);
         goto err;
     }
 
-    /*
-     * If we have more than two arguments, then we are accepting both a request file
-     * which is a newline separated list of paths to request from the server
-     * as well as a download location relative to the current working directory
-     */
-    if (argc >= 4) {
-        dlpath = argv[3];
-        fprintf(stderr, "setting download path to %s, and reading %s\n", dlpath, argv[2]);
-
-        /*
-         * Read in our request file, one path per line
-         */
-        req_fp = fopen(argv[2], "r");
-        if (req_fp == NULL) {
-            fprintf(stderr, "Unable to open request file\n");
-            goto err;
-        }
-        while (!feof(req_fp)) {
-            req_count++;
-            req_array = realloc(req_array, sizeof(char *) * req_count);
-            req_array[req_count - 1] = NULL;
-            if (fscanf(req_fp, "%s", buffer) != 1) {
-                req_count--;
-                if (feof(req_fp))
-                    break;
-                fprintf(stderr, "Failed to read request file at index %lu\n", req_count);
-                fclose(req_fp);
-                goto err;
-            }
-            req_array[req_count - 1] = calloc(1, strlen(buffer) + 1);
-            memcpy(req_array[req_count - 1], buffer, strlen(buffer));
-        }
-        fclose(req_fp);
-    }
-
     addr = argv[1];
 
     hostname = NULL;
@@ -245,7 +156,7 @@ int main(int argc, char **argv)
     if ((ctx = SSL_CTX_new(OSSL_QUIC_client_method())) == NULL)
         goto err;
 
-    SSL_CTX_set_verify(ctx, SSL_VERIFY_NONE, NULL);
+    SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER, NULL);
 
     if (SSL_CTX_set_default_verify_paths(ctx) == 0)
         goto err;
@@ -272,26 +183,23 @@ int main(int argc, char **argv)
         conn = OSSL_DEMO_H3_CONN_new_for_addr(ctx, bai_walk, hostname,
             &callbacks, NULL, NULL);
         if (conn != NULL) {
-            for (i = 0; i < req_count; i++) {
-                if (try_conn(conn, addr, req_array[i]) == 0) {
-                    /*
-                     * Failure, bail out.
-                     */
-                    OSSL_DEMO_H3_CONN_free(conn);
-                    conn = NULL;
-                    ret = 1;
-                    goto err;
-                }
+            if (try_conn(conn, addr) == 0) {
+                /*
+                 * Failure, try the next address.
+                 */
+                OSSL_DEMO_H3_CONN_free(conn);
+                conn = NULL;
+                ret = 1;
+            } else {
+                /*
+                 * Success, done.
+                 */
+                ret = 0;
+                break;
             }
-            fprintf(stderr, "all requests complete\n");
-            ret = 0;
         }
     }
 err:
-    for (i = 0; i < req_count; i++)
-        free(req_array[i]);
-    free(req_array);
-
     if (ret != 0)
         ERR_print_errors_fp(stderr);
 
diff --git a/demos/http3/ossl-nghttp3.c b/demos/http3/ossl-nghttp3.c
index e75f226221..050254d928 100644
--- a/demos/http3/ossl-nghttp3.c
+++ b/demos/http3/ossl-nghttp3.c
@@ -1,5 +1,5 @@
 /*
- * Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved.
+ * Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.
  *
  * Licensed under the Apache License 2.0 (the "License").  You may not use
  * this file except in compliance with the License.  You can obtain a copy
@@ -126,6 +126,19 @@ err:
     return NULL;
 }
 
+static OSSL_DEMO_H3_STREAM *h3_conn_accept_stream(OSSL_DEMO_H3_CONN *conn, SSL *qstream)
+{
+    OSSL_DEMO_H3_STREAM *s;
+
+    if ((s = OPENSSL_zalloc(sizeof(OSSL_DEMO_H3_STREAM))) == NULL)
+        return NULL;
+
+    s->id = SSL_get_stream_id(qstream);
+    s->s = qstream;
+    lh_OSSL_DEMO_H3_STREAM_insert(conn->streams, s);
+    return s;
+}
+
 static void h3_conn_remove_stream(OSSL_DEMO_H3_CONN *conn, OSSL_DEMO_H3_STREAM *s)
 {
     if (s == NULL)
@@ -416,7 +429,7 @@ OSSL_DEMO_H3_CONN *OSSL_DEMO_H3_CONN_new_for_addr(SSL_CTX *ctx, const BIO_ADDRIN
     qconn_bio = NULL;
 
     /* Set the hostname we will validate the X.509 certificate against. */
-    if (SSL_set1_dnsname(qconn, bare_hostname) <= 0)
+    if (SSL_set1_host(qconn, bare_hostname) <= 0)
         goto err;
 
     /* Configure SNI */
@@ -446,25 +459,6 @@ SSL *OSSL_DEMO_H3_CONN_get0_connection(const OSSL_DEMO_H3_CONN *conn)
     return conn->qconn;
 }
 
-typedef struct ossl_demo_h3_poll_list {
-    SSL_POLL_ITEM *poll_list;
-    OSSL_DEMO_H3_STREAM **h3_streams;
-    OSSL_DEMO_H3_CONN *conn;
-    size_t poll_count;
-    size_t idx;
-} OSSL_DEMO_H3_POLL_LIST;
-
-static void h3_conn_collect_streams(OSSL_DEMO_H3_STREAM *s, void *list)
-{
-    OSSL_DEMO_H3_POLL_LIST *pollist = list;
-
-    pollist->poll_list[pollist->idx].desc = SSL_as_poll_descriptor(s->s);
-    pollist->poll_list[pollist->idx].revents = 0;
-    pollist->poll_list[pollist->idx].events = SSL_POLL_EVENT_R;
-    pollist->h3_streams[pollist->idx] = s;
-    pollist->idx++;
-}
-
 /* Pumps received data to the HTTP/3 stack for a single stream. */
 static void h3_conn_pump_stream(OSSL_DEMO_H3_STREAM *s, void *conn_)
 {
@@ -543,7 +537,7 @@ static void h3_conn_pump_stream(OSSL_DEMO_H3_STREAM *s, void *conn_)
             break;
 
         /*
-         * This function is confusingly named as it is named from nghttp3's
+         * This function is confusingly named as it is is named from nghttp3's
          * 'perspective'; it is used to pass data *into* the HTTP/3 stack which
          * has been received from the network.
          */
@@ -584,10 +578,6 @@ int OSSL_DEMO_H3_CONN_handle_events(OSSL_DEMO_H3_CONN *conn)
     nghttp3_vec vecs[8] = { 0 };
     OSSL_DEMO_H3_STREAM key, *s;
     SSL *snew;
-    OSSL_DEMO_H3_POLL_LIST *pollist = NULL;
-    size_t poll_num;
-    struct timeval poll_timeout;
-    size_t result_count;
 
     if (conn == NULL)
         return 0;
@@ -604,6 +594,15 @@ int OSSL_DEMO_H3_CONN_handle_events(OSSL_DEMO_H3_CONN *conn)
     for (;;) {
         if ((snew = SSL_accept_stream(conn->qconn, SSL_ACCEPT_STREAM_NO_BLOCK)) == NULL)
             break;
+
+        /*
+         * Each new incoming stream gets wrapped into an OSSL_DEMO_H3_STREAM object and
+         * added into our stream ID map.
+         */
+        if (h3_conn_accept_stream(conn, snew) == NULL) {
+            SSL_free(snew);
+            return 0;
+        }
     }
 
     /* 2. Pump outgoing data from HTTP/3 engine to QUIC. */
@@ -705,36 +704,9 @@ int OSSL_DEMO_H3_CONN_handle_events(OSSL_DEMO_H3_CONN *conn)
         }
     }
 
-    /* 3. Build a list of streams to poll on */
+    /* 3. Pump incoming data from QUIC to HTTP/3 engine. */
     conn->pump_res = 1; /* cleared in below call if an error occurs */
-    poll_num = lh_OSSL_DEMO_H3_STREAM_num_items(conn->streams);
-    pollist = OPENSSL_malloc(sizeof(OSSL_DEMO_H3_POLL_LIST) + (sizeof(SSL_POLL_ITEM) * poll_num) + (sizeof(OSSL_DEMO_H3_STREAM *) * poll_num));
-    pollist->poll_count = poll_num;
-    pollist->poll_list = (SSL_POLL_ITEM *)(pollist + 1);
-    pollist->h3_streams = (OSSL_DEMO_H3_STREAM **)(pollist->poll_list + poll_num);
-    pollist->conn = conn;
-    pollist->idx = 0;
-    lh_OSSL_DEMO_H3_STREAM_doall_arg(conn->streams, h3_conn_collect_streams, pollist);
-    poll_timeout.tv_sec = 0;
-    poll_timeout.tv_usec = 0;
-    result_count = 0;
-
-    /* 4. poll the list built above, looking for streams that are ready to read */
-    if (!SSL_poll(pollist->poll_list, pollist->idx, sizeof(SSL_POLL_ITEM),
-            &poll_timeout, 0, &result_count)) {
-        fprintf(stderr, "Failed to poll\n");
-        goto end;
-    }
-
-    /* 5. Pump incoming data from QUIC to HTTP/3 engine. */
-    for (i = 0; result_count != 0; i++) {
-        if (pollist->poll_list[i].revents == SSL_POLL_EVENT_R) {
-            result_count--;
-            h3_conn_pump_stream(pollist->h3_streams[i], pollist->conn);
-        }
-    }
-end:
-    OPENSSL_free(pollist);
+    lh_OSSL_DEMO_H3_STREAM_doall_arg(conn->streams, h3_conn_pump_stream, conn);
     if (!conn->pump_res)
         return 0;
 
diff --git a/demos/info/Makefile b/demos/info/Makefile
deleted file mode 100644
index 05f1707ba5..0000000000
--- a/demos/info/Makefile
+++ /dev/null
@@ -1,32 +0,0 @@
-#
-# To run the demos when linked with a shared library (default) ensure
-# that libcrypto is on the library path. For example:
-#
-
-TESTS = fips-version
-
-CFLAGS  = -I../../include -g -Wall
-LDFLAGS = -L../..
-LDLIBS  = -lcrypto
-
-all: $(TESTS)
-
-fips-version: fips-version.o
-
-$(TESTS):
-	$(CC) $(CFLAGS) $(LDFLAGS) -o $@ $< $(LDLIBS)
-
-clean:
-	$(RM) *.o $(TESTS)
-
-.PHONY: test
-test: all
-	@echo "\nINFO tests:"
-	@set -e; for tst in $(TESTS); do \
-		echo "\n"$$tst; \
-                LD_LIBRARY_PATH=../.. \
-                OPENSSL_CONF=../../test/fips-and-base.cnf \
-                OPENSSL_MODULES=../../providers \
-                OPENSSL_CONF_INCLUDE=../../providers \
-                ./$$tst; \
-	done
diff --git a/demos/info/build.info b/demos/info/build.info
deleted file mode 100644
index b5339cec91..0000000000
--- a/demos/info/build.info
+++ /dev/null
@@ -1,11 +0,0 @@
-#
-# To run the demos when linked with a shared library (default) ensure
-# that libcrypto is on the library path. For example:
-#
-#    LD_LIBRARY_PATH=../.. ./info
-
-PROGRAMS{noinst} = fips-version
-
-INCLUDE[fips-version]=../../include
-SOURCE[fips-version]=fips-version.c
-DEPEND[fips-version]=../../libcrypto
diff --git a/demos/info/fips-version.c b/demos/info/fips-version.c
deleted file mode 100644
index 6b1bb4bfab..0000000000
--- a/demos/info/fips-version.c
+++ /dev/null
@@ -1,61 +0,0 @@
-/*
- * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved.
- *
- * Licensed under the Apache License 2.0 (the "License").  You may not use
- * this file except in compliance with the License.  You can obtain a copy
- * in the file LICENSE in the source distribution or at
- * https://www.openssl.org/source/license.html
- */
-
-#include 
-#include 
-#include 
-#include 
-#include 
-
-int main(int argc, char **argv)
-{
-    int ret = EXIT_FAILURE;
-    OSSL_LIB_CTX *libctx;
-    OSSL_PROVIDER *fips_provider = NULL;
-    OSSL_PARAM params[2];
-    char *version;
-
-    /* Replace this with your libctx if you are using a non-default one */
-    libctx = NULL;
-
-    /* Check if the FIPS provider is available in this libctx */
-    if (!OSSL_PROVIDER_available(libctx, "fips")) {
-        puts("FIPS provider is not available");
-        goto done;
-    }
-
-    /* Load the FIPS provider */
-    fips_provider = OSSL_PROVIDER_load(libctx, "fips");
-    if (fips_provider == NULL) {
-        puts("Failed to load FIPS provider");
-        goto done;
-    }
-
-    /* Query the FIPS provider version */
-    params[0] = OSSL_PARAM_construct_utf8_ptr(OSSL_PROV_PARAM_VERSION,
-        &version, 0);
-    params[1] = OSSL_PARAM_construct_end();
-    OSSL_PARAM_set_all_unmodified(params);
-    if (!OSSL_PROVIDER_get_params(fips_provider, params)) {
-        puts("Failed to query FIPS provider version");
-        goto done;
-    }
-
-    /* Check if the FIPS provider returned a version to us */
-    if (!OSSL_PARAM_modified(params)) {
-        puts("FIPS provider failed to set version");
-        goto done;
-    }
-
-    printf("FIPS provider version is %s\n", version);
-    ret = EXIT_SUCCESS;
-done:
-    OSSL_PROVIDER_unload(fips_provider);
-    return ret;
-}
diff --git a/demos/mac/cmac-aes256.c b/demos/mac/cmac-aes256.c
index 778ac10862..bffdc48fe8 100644
--- a/demos/mac/cmac-aes256.c
+++ b/demos/mac/cmac-aes256.c
@@ -26,10 +26,38 @@
  * It is done here solely for educational purposes.
  */
 static unsigned char key[] = {
-    0x6c, 0xde, 0x14, 0xf5, 0xd5, 0x2a, 0x4a, 0xdf, 0x12, 0x39,
-    0x1e, 0xbf, 0x36, 0xf9, 0x6a, 0x46, 0x48, 0xd0, 0xb6, 0x51,
-    0x89, 0xfc, 0x24, 0x85, 0xa8, 0x8d, 0xdf, 0x7e, 0x80, 0x14,
-    0xc8, 0xce
+    0x6c,
+    0xde,
+    0x14,
+    0xf5,
+    0xd5,
+    0x2a,
+    0x4a,
+    0xdf,
+    0x12,
+    0x39,
+    0x1e,
+    0xbf,
+    0x36,
+    0xf9,
+    0x6a,
+    0x46,
+    0x48,
+    0xd0,
+    0xb6,
+    0x51,
+    0x89,
+    0xfc,
+    0x24,
+    0x85,
+    0xa8,
+    0x8d,
+    0xdf,
+    0x7e,
+    0x80,
+    0x14,
+    0xc8,
+    0xce,
 };
 
 static const unsigned char data[] = "To be, or not to be, that is the question,\n"
@@ -52,8 +80,22 @@ static const unsigned char data[] = "To be, or not to be, that is the question,\
 
 /* The known value of the CMAC/AES256 MAC of the above soliloqy */
 static const unsigned char expected_output[] = {
-    0x67, 0x92, 0x32, 0x23, 0x50, 0x3d, 0xc5, 0xba, 0x78, 0xd4,
-    0x6d, 0x63, 0xf2, 0x2b, 0xe9, 0x56
+    0x67,
+    0x92,
+    0x32,
+    0x23,
+    0x50,
+    0x3d,
+    0xc5,
+    0xba,
+    0x78,
+    0xd4,
+    0x6d,
+    0x63,
+    0xf2,
+    0x2b,
+    0xe9,
+    0x56,
 };
 
 /*
diff --git a/demos/mac/hmac-sha512.c b/demos/mac/hmac-sha512.c
index e9a4fbaf23..9aadfb500a 100644
--- a/demos/mac/hmac-sha512.c
+++ b/demos/mac/hmac-sha512.c
@@ -26,13 +26,70 @@
  * It is done here solely for educational purposes.
  */
 static unsigned char key[] = {
-    0x25, 0xfd, 0x12, 0x99, 0xdf, 0xad, 0x1a, 0x03, 0x0a, 0x81,
-    0x3c, 0x2d, 0xcc, 0x05, 0xd1, 0x5c, 0x17, 0x7a, 0x36, 0x73,
-    0x17, 0xef, 0x41, 0x75, 0x71, 0x18, 0xe0, 0x1a, 0xda, 0x99,
-    0xc3, 0x61, 0x38, 0xb5, 0xb1, 0xe0, 0x82, 0x2c, 0x70, 0xa4,
-    0xc0, 0x8e, 0x5e, 0xf9, 0x93, 0x9f, 0xcf, 0xf7, 0x32, 0x4d,
-    0x0c, 0xbd, 0x31, 0x12, 0x0f, 0x9a, 0x15, 0xee, 0x82, 0xdb,
-    0x8d, 0x29, 0x54, 0x14
+    0x25,
+    0xfd,
+    0x12,
+    0x99,
+    0xdf,
+    0xad,
+    0x1a,
+    0x03,
+    0x0a,
+    0x81,
+    0x3c,
+    0x2d,
+    0xcc,
+    0x05,
+    0xd1,
+    0x5c,
+    0x17,
+    0x7a,
+    0x36,
+    0x73,
+    0x17,
+    0xef,
+    0x41,
+    0x75,
+    0x71,
+    0x18,
+    0xe0,
+    0x1a,
+    0xda,
+    0x99,
+    0xc3,
+    0x61,
+    0x38,
+    0xb5,
+    0xb1,
+    0xe0,
+    0x82,
+    0x2c,
+    0x70,
+    0xa4,
+    0xc0,
+    0x8e,
+    0x5e,
+    0xf9,
+    0x93,
+    0x9f,
+    0xcf,
+    0xf7,
+    0x32,
+    0x4d,
+    0x0c,
+    0xbd,
+    0x31,
+    0x12,
+    0x0f,
+    0x9a,
+    0x15,
+    0xee,
+    0x82,
+    0xdb,
+    0x8d,
+    0x29,
+    0x54,
+    0x14,
 };
 
 static const unsigned char data[] = "To be, or not to be, that is the question,\n"
@@ -55,13 +112,70 @@ static const unsigned char data[] = "To be, or not to be, that is the question,\
 
 /* The known value of the HMAC/SHA3-512 MAC of the above soliloqy */
 static const unsigned char expected_output[] = {
-    0x3b, 0x77, 0x5f, 0xf1, 0x4f, 0x9e, 0xb9, 0x23, 0x8f, 0xdc,
-    0xa0, 0x68, 0x15, 0x7b, 0x8a, 0xf1, 0x96, 0x23, 0xaa, 0x3c,
-    0x1f, 0xe9, 0xdc, 0x89, 0x11, 0x7d, 0x58, 0x07, 0xe7, 0x96,
-    0x17, 0xe3, 0x44, 0x8b, 0x03, 0x37, 0x91, 0xc0, 0x6e, 0x06,
-    0x7c, 0x54, 0xe4, 0xa4, 0xcc, 0xd5, 0x16, 0xbb, 0x5e, 0x4d,
-    0x64, 0x7d, 0x88, 0x23, 0xc9, 0xb7, 0x25, 0xda, 0xbe, 0x4b,
-    0xe4, 0xd5, 0x34, 0x30
+    0x3b,
+    0x77,
+    0x5f,
+    0xf1,
+    0x4f,
+    0x9e,
+    0xb9,
+    0x23,
+    0x8f,
+    0xdc,
+    0xa0,
+    0x68,
+    0x15,
+    0x7b,
+    0x8a,
+    0xf1,
+    0x96,
+    0x23,
+    0xaa,
+    0x3c,
+    0x1f,
+    0xe9,
+    0xdc,
+    0x89,
+    0x11,
+    0x7d,
+    0x58,
+    0x07,
+    0xe7,
+    0x96,
+    0x17,
+    0xe3,
+    0x44,
+    0x8b,
+    0x03,
+    0x37,
+    0x91,
+    0xc0,
+    0x6e,
+    0x06,
+    0x7c,
+    0x54,
+    0xe4,
+    0xa4,
+    0xcc,
+    0xd5,
+    0x16,
+    0xbb,
+    0x5e,
+    0x4d,
+    0x64,
+    0x7d,
+    0x88,
+    0x23,
+    0xc9,
+    0xb7,
+    0x25,
+    0xda,
+    0xbe,
+    0x4b,
+    0xe4,
+    0xd5,
+    0x34,
+    0x30,
 };
 
 /*
diff --git a/demos/pkcs12/build.info b/demos/pkcs12/build.info
deleted file mode 100644
index 6fd35d1822..0000000000
--- a/demos/pkcs12/build.info
+++ /dev/null
@@ -1,16 +0,0 @@
-#
-# To run the demos when linked with a shared library (default) ensure that
-# libcrypto is on the library path. For example:
-#
-#    LD_LIBRARY_PATH=../.. ./pkread
-
-PROGRAMS{noinst} = pkread \
-                   pkwrite
-
-INCLUDE[pkread]=../../include
-SOURCE[pkread]=pkread.c
-DEPEND[pkread]=../../libcrypto
-
-INCLUDE[pkwrite]=../../include
-SOURCE[pkwrite]=pkwrite.c
-DEPEND[pkwrite]=../../libcrypto
diff --git a/demos/pkcs12/pkwrite.c b/demos/pkcs12/pkwrite.c
index b274943ce8..7bb73f35a4 100644
--- a/demos/pkcs12/pkwrite.c
+++ b/demos/pkcs12/pkwrite.c
@@ -25,6 +25,8 @@ int main(int argc, char **argv)
         fprintf(stderr, "Usage: pkwrite infile password name p12file\n");
         exit(EXIT_FAILURE);
     }
+    OpenSSL_add_all_algorithms();
+    ERR_load_crypto_strings();
     if ((fp = fopen(argv[1], "r")) == NULL) {
         fprintf(stderr, "Error opening file %s\n", argv[1]);
         exit(EXIT_FAILURE);
diff --git a/demos/quic/poll-server/quic-server-ssl-poll-http.c b/demos/quic/poll-server/quic-server-ssl-poll-http.c
index c76dc609a2..ca3990c792 100644
--- a/demos/quic/poll-server/quic-server-ssl-poll-http.c
+++ b/demos/quic/poll-server/quic-server-ssl-poll-http.c
@@ -317,6 +317,16 @@ errx(int status, const char *fmt, ...)
     exit(status);
 }
 
+static void
+warnx(const char *fmt, ...)
+{
+    va_list ap;
+
+    va_start(ap, fmt);
+    vwarnx(fmt, ap);
+    va_end(ap);
+}
+
 /*
  * we can get away with this mock-up on windows.
  * we generate payload for any URL we obtain in
diff --git a/demos/signature/EVP_DSA_Signature_demo.c b/demos/signature/EVP_DSA_Signature_demo.c
index 088c568724..548860a812 100644
--- a/demos/signature/EVP_DSA_Signature_demo.c
+++ b/demos/signature/EVP_DSA_Signature_demo.c
@@ -148,7 +148,7 @@ static int extract_keypair(const EVP_PKEY *pkey,
     ret = 1;
 end:
     if (ret != 1) {
-        OSSL_PARAM_clear_free(keypair);
+        OSSL_PARAM_free(keypair);
         keypair = NULL;
     }
     *p_keypair = keypair;
@@ -306,7 +306,7 @@ end:
     EVP_PKEY_free(params);
     EVP_PKEY_free(pkey);
     OSSL_PARAM_free(public_key);
-    OSSL_PARAM_clear_free(keypair);
+    OSSL_PARAM_free(keypair);
     OSSL_LIB_CTX_free(libctx);
 
     return ret;
diff --git a/demos/signature/EVP_EC_Signature_demo.h b/demos/signature/EVP_EC_Signature_demo.h
index c7527beebc..8195756793 100644
--- a/demos/signature/EVP_EC_Signature_demo.h
+++ b/demos/signature/EVP_EC_Signature_demo.h
@@ -9,79 +9,707 @@
 
 /* Signers private EC key */
 static const unsigned char priv_key_der[] = {
-    0x30, 0x82, 0x01, 0x68, 0x02, 0x01, 0x01, 0x04, 0x20, 0x51,
-    0x77, 0xae, 0xf4, 0x18, 0xf4, 0x6b, 0xc4, 0xe5, 0xbb, 0xe9,
-    0xe6, 0x9e, 0x6d, 0xb0, 0xea, 0x12, 0xf9, 0xf3, 0xdb, 0x9d,
-    0x56, 0x59, 0xf7, 0x5a, 0x17, 0xd7, 0xd1, 0xe4, 0xd7, 0x47,
-    0x28, 0xa0, 0x81, 0xfa, 0x30, 0x81, 0xf7, 0x02, 0x01, 0x01,
-    0x30, 0x2c, 0x06, 0x07, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x01,
-    0x01, 0x02, 0x21, 0x00, 0xff, 0xff, 0xff, 0xff, 0x00, 0x00,
-    0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
-    0x00, 0x00, 0x00, 0x00, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
-    0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x30, 0x5b, 0x04, 0x20,
-    0xff, 0xff, 0xff, 0xff, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00,
-    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
-    0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
-    0xff, 0xfc, 0x04, 0x20, 0x5a, 0xc6, 0x35, 0xd8, 0xaa, 0x3a,
-    0x93, 0xe7, 0xb3, 0xeb, 0xbd, 0x55, 0x76, 0x98, 0x86, 0xbc,
-    0x65, 0x1d, 0x06, 0xb0, 0xcc, 0x53, 0xb0, 0xf6, 0x3b, 0xce,
-    0x3c, 0x3e, 0x27, 0xd2, 0x60, 0x4b, 0x03, 0x15, 0x00, 0xc4,
-    0x9d, 0x36, 0x08, 0x86, 0xe7, 0x04, 0x93, 0x6a, 0x66, 0x78,
-    0xe1, 0x13, 0x9d, 0x26, 0xb7, 0x81, 0x9f, 0x7e, 0x90, 0x04,
-    0x41, 0x04, 0x6b, 0x17, 0xd1, 0xf2, 0xe1, 0x2c, 0x42, 0x47,
-    0xf8, 0xbc, 0xe6, 0xe5, 0x63, 0xa4, 0x40, 0xf2, 0x77, 0x03,
-    0x7d, 0x81, 0x2d, 0xeb, 0x33, 0xa0, 0xf4, 0xa1, 0x39, 0x45,
-    0xd8, 0x98, 0xc2, 0x96, 0x4f, 0xe3, 0x42, 0xe2, 0xfe, 0x1a,
-    0x7f, 0x9b, 0x8e, 0xe7, 0xeb, 0x4a, 0x7c, 0x0f, 0x9e, 0x16,
-    0x2b, 0xce, 0x33, 0x57, 0x6b, 0x31, 0x5e, 0xce, 0xcb, 0xb6,
-    0x40, 0x68, 0x37, 0xbf, 0x51, 0xf5, 0x02, 0x21, 0x00, 0xff,
-    0xff, 0xff, 0xff, 0x00, 0x00, 0x00, 0x00, 0xff, 0xff, 0xff,
-    0xff, 0xff, 0xff, 0xff, 0xff, 0xbc, 0xe6, 0xfa, 0xad, 0xa7,
-    0x17, 0x9e, 0x84, 0xf3, 0xb9, 0xca, 0xc2, 0xfc, 0x63, 0x25,
-    0x51, 0x02, 0x01, 0x01, 0xa1, 0x44, 0x03, 0x42, 0x00, 0x04,
-    0x4f, 0xe7, 0x7b, 0xb6, 0xbb, 0x54, 0x42, 0x39, 0xed, 0x5d,
-    0xe5, 0x40, 0xc8, 0xd8, 0x71, 0xca, 0x6d, 0x83, 0x71, 0xd1,
-    0x88, 0x2a, 0x65, 0x00, 0x6c, 0xc6, 0x2f, 0x01, 0x31, 0x49,
-    0xbe, 0x76, 0x7a, 0x67, 0x6a, 0x28, 0x33, 0xc7, 0x5b, 0xb9,
-    0x24, 0x45, 0x24, 0x6e, 0xf0, 0x6d, 0x2f, 0x34, 0x06, 0x53,
-    0x73, 0x6a, 0xff, 0x90, 0x90, 0xc1, 0x6d, 0x9b, 0x94, 0x0d,
-    0x0e, 0x1f, 0x95, 0x65
+    0x30,
+    0x82,
+    0x01,
+    0x68,
+    0x02,
+    0x01,
+    0x01,
+    0x04,
+    0x20,
+    0x51,
+    0x77,
+    0xae,
+    0xf4,
+    0x18,
+    0xf4,
+    0x6b,
+    0xc4,
+    0xe5,
+    0xbb,
+    0xe9,
+    0xe6,
+    0x9e,
+    0x6d,
+    0xb0,
+    0xea,
+    0x12,
+    0xf9,
+    0xf3,
+    0xdb,
+    0x9d,
+    0x56,
+    0x59,
+    0xf7,
+    0x5a,
+    0x17,
+    0xd7,
+    0xd1,
+    0xe4,
+    0xd7,
+    0x47,
+    0x28,
+    0xa0,
+    0x81,
+    0xfa,
+    0x30,
+    0x81,
+    0xf7,
+    0x02,
+    0x01,
+    0x01,
+    0x30,
+    0x2c,
+    0x06,
+    0x07,
+    0x2a,
+    0x86,
+    0x48,
+    0xce,
+    0x3d,
+    0x01,
+    0x01,
+    0x02,
+    0x21,
+    0x00,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0x00,
+    0x00,
+    0x00,
+    0x01,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0x30,
+    0x5b,
+    0x04,
+    0x20,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0x00,
+    0x00,
+    0x00,
+    0x01,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xfc,
+    0x04,
+    0x20,
+    0x5a,
+    0xc6,
+    0x35,
+    0xd8,
+    0xaa,
+    0x3a,
+    0x93,
+    0xe7,
+    0xb3,
+    0xeb,
+    0xbd,
+    0x55,
+    0x76,
+    0x98,
+    0x86,
+    0xbc,
+    0x65,
+    0x1d,
+    0x06,
+    0xb0,
+    0xcc,
+    0x53,
+    0xb0,
+    0xf6,
+    0x3b,
+    0xce,
+    0x3c,
+    0x3e,
+    0x27,
+    0xd2,
+    0x60,
+    0x4b,
+    0x03,
+    0x15,
+    0x00,
+    0xc4,
+    0x9d,
+    0x36,
+    0x08,
+    0x86,
+    0xe7,
+    0x04,
+    0x93,
+    0x6a,
+    0x66,
+    0x78,
+    0xe1,
+    0x13,
+    0x9d,
+    0x26,
+    0xb7,
+    0x81,
+    0x9f,
+    0x7e,
+    0x90,
+    0x04,
+    0x41,
+    0x04,
+    0x6b,
+    0x17,
+    0xd1,
+    0xf2,
+    0xe1,
+    0x2c,
+    0x42,
+    0x47,
+    0xf8,
+    0xbc,
+    0xe6,
+    0xe5,
+    0x63,
+    0xa4,
+    0x40,
+    0xf2,
+    0x77,
+    0x03,
+    0x7d,
+    0x81,
+    0x2d,
+    0xeb,
+    0x33,
+    0xa0,
+    0xf4,
+    0xa1,
+    0x39,
+    0x45,
+    0xd8,
+    0x98,
+    0xc2,
+    0x96,
+    0x4f,
+    0xe3,
+    0x42,
+    0xe2,
+    0xfe,
+    0x1a,
+    0x7f,
+    0x9b,
+    0x8e,
+    0xe7,
+    0xeb,
+    0x4a,
+    0x7c,
+    0x0f,
+    0x9e,
+    0x16,
+    0x2b,
+    0xce,
+    0x33,
+    0x57,
+    0x6b,
+    0x31,
+    0x5e,
+    0xce,
+    0xcb,
+    0xb6,
+    0x40,
+    0x68,
+    0x37,
+    0xbf,
+    0x51,
+    0xf5,
+    0x02,
+    0x21,
+    0x00,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xbc,
+    0xe6,
+    0xfa,
+    0xad,
+    0xa7,
+    0x17,
+    0x9e,
+    0x84,
+    0xf3,
+    0xb9,
+    0xca,
+    0xc2,
+    0xfc,
+    0x63,
+    0x25,
+    0x51,
+    0x02,
+    0x01,
+    0x01,
+    0xa1,
+    0x44,
+    0x03,
+    0x42,
+    0x00,
+    0x04,
+    0x4f,
+    0xe7,
+    0x7b,
+    0xb6,
+    0xbb,
+    0x54,
+    0x42,
+    0x39,
+    0xed,
+    0x5d,
+    0xe5,
+    0x40,
+    0xc8,
+    0xd8,
+    0x71,
+    0xca,
+    0x6d,
+    0x83,
+    0x71,
+    0xd1,
+    0x88,
+    0x2a,
+    0x65,
+    0x00,
+    0x6c,
+    0xc6,
+    0x2f,
+    0x01,
+    0x31,
+    0x49,
+    0xbe,
+    0x76,
+    0x7a,
+    0x67,
+    0x6a,
+    0x28,
+    0x33,
+    0xc7,
+    0x5b,
+    0xb9,
+    0x24,
+    0x45,
+    0x24,
+    0x6e,
+    0xf0,
+    0x6d,
+    0x2f,
+    0x34,
+    0x06,
+    0x53,
+    0x73,
+    0x6a,
+    0xff,
+    0x90,
+    0x90,
+    0xc1,
+    0x6d,
+    0x9b,
+    0x94,
+    0x0d,
+    0x0e,
+    0x1f,
+    0x95,
+    0x65,
 };
 
 /* The matching public key used for verifying */
 static const unsigned char pub_key_der[] = {
-    0x30, 0x82, 0x01, 0x4b, 0x30, 0x82, 0x01, 0x03, 0x06, 0x07,
-    0x2a, 0x86, 0x48, 0xce, 0x3d, 0x02, 0x01, 0x30, 0x81, 0xf7,
-    0x02, 0x01, 0x01, 0x30, 0x2c, 0x06, 0x07, 0x2a, 0x86, 0x48,
-    0xce, 0x3d, 0x01, 0x01, 0x02, 0x21, 0x00, 0xff, 0xff, 0xff,
-    0xff, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0x00,
-    0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0xff, 0xff, 0xff,
-    0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x30,
-    0x5b, 0x04, 0x20, 0xff, 0xff, 0xff, 0xff, 0x00, 0x00, 0x00,
-    0x01, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00,
-    0x00, 0x00, 0x00, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff,
-    0xff, 0xff, 0xff, 0xff, 0xfc, 0x04, 0x20, 0x5a, 0xc6, 0x35,
-    0xd8, 0xaa, 0x3a, 0x93, 0xe7, 0xb3, 0xeb, 0xbd, 0x55, 0x76,
-    0x98, 0x86, 0xbc, 0x65, 0x1d, 0x06, 0xb0, 0xcc, 0x53, 0xb0,
-    0xf6, 0x3b, 0xce, 0x3c, 0x3e, 0x27, 0xd2, 0x60, 0x4b, 0x03,
-    0x15, 0x00, 0xc4, 0x9d, 0x36, 0x08, 0x86, 0xe7, 0x04, 0x93,
-    0x6a, 0x66, 0x78, 0xe1, 0x13, 0x9d, 0x26, 0xb7, 0x81, 0x9f,
-    0x7e, 0x90, 0x04, 0x41, 0x04, 0x6b, 0x17, 0xd1, 0xf2, 0xe1,
-    0x2c, 0x42, 0x47, 0xf8, 0xbc, 0xe6, 0xe5, 0x63, 0xa4, 0x40,
-    0xf2, 0x77, 0x03, 0x7d, 0x81, 0x2d, 0xeb, 0x33, 0xa0, 0xf4,
-    0xa1, 0x39, 0x45, 0xd8, 0x98, 0xc2, 0x96, 0x4f, 0xe3, 0x42,
-    0xe2, 0xfe, 0x1a, 0x7f, 0x9b, 0x8e, 0xe7, 0xeb, 0x4a, 0x7c,
-    0x0f, 0x9e, 0x16, 0x2b, 0xce, 0x33, 0x57, 0x6b, 0x31, 0x5e,
-    0xce, 0xcb, 0xb6, 0x40, 0x68, 0x37, 0xbf, 0x51, 0xf5, 0x02,
-    0x21, 0x00, 0xff, 0xff, 0xff, 0xff, 0x00, 0x00, 0x00, 0x00,
-    0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xbc, 0xe6,
-    0xfa, 0xad, 0xa7, 0x17, 0x9e, 0x84, 0xf3, 0xb9, 0xca, 0xc2,
-    0xfc, 0x63, 0x25, 0x51, 0x02, 0x01, 0x01, 0x03, 0x42, 0x00,
-    0x04, 0x4f, 0xe7, 0x7b, 0xb6, 0xbb, 0x54, 0x42, 0x39, 0xed,
-    0x5d, 0xe5, 0x40, 0xc8, 0xd8, 0x71, 0xca, 0x6d, 0x83, 0x71,
-    0xd1, 0x88, 0x2a, 0x65, 0x00, 0x6c, 0xc6, 0x2f, 0x01, 0x31,
-    0x49, 0xbe, 0x76, 0x7a, 0x67, 0x6a, 0x28, 0x33, 0xc7, 0x5b,
-    0xb9, 0x24, 0x45, 0x24, 0x6e, 0xf0, 0x6d, 0x2f, 0x34, 0x06,
-    0x53, 0x73, 0x6a, 0xff, 0x90, 0x90, 0xc1, 0x6d, 0x9b, 0x94,
-    0x0d, 0x0e, 0x1f, 0x95, 0x65
+    0x30,
+    0x82,
+    0x01,
+    0x4b,
+    0x30,
+    0x82,
+    0x01,
+    0x03,
+    0x06,
+    0x07,
+    0x2a,
+    0x86,
+    0x48,
+    0xce,
+    0x3d,
+    0x02,
+    0x01,
+    0x30,
+    0x81,
+    0xf7,
+    0x02,
+    0x01,
+    0x01,
+    0x30,
+    0x2c,
+    0x06,
+    0x07,
+    0x2a,
+    0x86,
+    0x48,
+    0xce,
+    0x3d,
+    0x01,
+    0x01,
+    0x02,
+    0x21,
+    0x00,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0x00,
+    0x00,
+    0x00,
+    0x01,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0x30,
+    0x5b,
+    0x04,
+    0x20,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0x00,
+    0x00,
+    0x00,
+    0x01,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xfc,
+    0x04,
+    0x20,
+    0x5a,
+    0xc6,
+    0x35,
+    0xd8,
+    0xaa,
+    0x3a,
+    0x93,
+    0xe7,
+    0xb3,
+    0xeb,
+    0xbd,
+    0x55,
+    0x76,
+    0x98,
+    0x86,
+    0xbc,
+    0x65,
+    0x1d,
+    0x06,
+    0xb0,
+    0xcc,
+    0x53,
+    0xb0,
+    0xf6,
+    0x3b,
+    0xce,
+    0x3c,
+    0x3e,
+    0x27,
+    0xd2,
+    0x60,
+    0x4b,
+    0x03,
+    0x15,
+    0x00,
+    0xc4,
+    0x9d,
+    0x36,
+    0x08,
+    0x86,
+    0xe7,
+    0x04,
+    0x93,
+    0x6a,
+    0x66,
+    0x78,
+    0xe1,
+    0x13,
+    0x9d,
+    0x26,
+    0xb7,
+    0x81,
+    0x9f,
+    0x7e,
+    0x90,
+    0x04,
+    0x41,
+    0x04,
+    0x6b,
+    0x17,
+    0xd1,
+    0xf2,
+    0xe1,
+    0x2c,
+    0x42,
+    0x47,
+    0xf8,
+    0xbc,
+    0xe6,
+    0xe5,
+    0x63,
+    0xa4,
+    0x40,
+    0xf2,
+    0x77,
+    0x03,
+    0x7d,
+    0x81,
+    0x2d,
+    0xeb,
+    0x33,
+    0xa0,
+    0xf4,
+    0xa1,
+    0x39,
+    0x45,
+    0xd8,
+    0x98,
+    0xc2,
+    0x96,
+    0x4f,
+    0xe3,
+    0x42,
+    0xe2,
+    0xfe,
+    0x1a,
+    0x7f,
+    0x9b,
+    0x8e,
+    0xe7,
+    0xeb,
+    0x4a,
+    0x7c,
+    0x0f,
+    0x9e,
+    0x16,
+    0x2b,
+    0xce,
+    0x33,
+    0x57,
+    0x6b,
+    0x31,
+    0x5e,
+    0xce,
+    0xcb,
+    0xb6,
+    0x40,
+    0x68,
+    0x37,
+    0xbf,
+    0x51,
+    0xf5,
+    0x02,
+    0x21,
+    0x00,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0x00,
+    0x00,
+    0x00,
+    0x00,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xff,
+    0xbc,
+    0xe6,
+    0xfa,
+    0xad,
+    0xa7,
+    0x17,
+    0x9e,
+    0x84,
+    0xf3,
+    0xb9,
+    0xca,
+    0xc2,
+    0xfc,
+    0x63,
+    0x25,
+    0x51,
+    0x02,
+    0x01,
+    0x01,
+    0x03,
+    0x42,
+    0x00,
+    0x04,
+    0x4f,
+    0xe7,
+    0x7b,
+    0xb6,
+    0xbb,
+    0x54,
+    0x42,
+    0x39,
+    0xed,
+    0x5d,
+    0xe5,
+    0x40,
+    0xc8,
+    0xd8,
+    0x71,
+    0xca,
+    0x6d,
+    0x83,
+    0x71,
+    0xd1,
+    0x88,
+    0x2a,
+    0x65,
+    0x00,
+    0x6c,
+    0xc6,
+    0x2f,
+    0x01,
+    0x31,
+    0x49,
+    0xbe,
+    0x76,
+    0x7a,
+    0x67,
+    0x6a,
+    0x28,
+    0x33,
+    0xc7,
+    0x5b,
+    0xb9,
+    0x24,
+    0x45,
+    0x24,
+    0x6e,
+    0xf0,
+    0x6d,
+    0x2f,
+    0x34,
+    0x06,
+    0x53,
+    0x73,
+    0x6a,
+    0xff,
+    0x90,
+    0x90,
+    0xc1,
+    0x6d,
+    0x9b,
+    0x94,
+    0x0d,
+    0x0e,
+    0x1f,
+    0x95,
+    0x65,
 };
diff --git a/demos/sslecho/Makefile b/demos/sslecho/Makefile
index 79b0efe697..defb1597e1 100644
--- a/demos/sslecho/Makefile
+++ b/demos/sslecho/Makefile
@@ -4,7 +4,7 @@
 #
 #    LD_LIBRARY_PATH=../.. ./sslecho
 
-TESTS = sslecho echecho
+TESTS = sslecho
 
 CFLAGS  = -I../../include -g -Wall
 LDFLAGS = -L../..
@@ -14,8 +14,6 @@ all: $(TESTS)
 
 sslecho: main.o
 
-echecho: echecho.o
-
 $(TESTS):
 	$(CC) $(CFLAGS) $(LDFLAGS) -o $@ $< $(LDLIBS)
 
diff --git a/demos/sslecho/README.md b/demos/sslecho/README.md
index 8ef3e93b74..58f7ca0724 100644
--- a/demos/sslecho/README.md
+++ b/demos/sslecho/README.md
@@ -24,48 +24,3 @@ The cert.pem and key.pem files included are self signed certificates with the
 "Common Name" of 'localhost'.
 
 Best to create the 'pem' files using an actual hostname.
-
-Encrypted Client Hello (ECH) Variant
-====================================
-
-``echecho.c`` implements the same functionality but demonstrates minimal code
-changes needed to use ECH. The ``echecho`` binary has the same user interface
-discussed above but enables ECH for the connection, based on hard-coded ECH
-configuration data. A real server would load file(s), and a real client would
-acquire an ECHConfigList from the DNS.
-
-All that's required to use ECH is to load ECH data via `OSSL_ECHSTORE_read_*`
-APIs and then enable ECH via ``SSL_CTX_set1_echstore()``. Both client and
-server check and print out the status of ECH using ``SSL_ech_get1_status()``,
-but that's optional.
-
-To run the server:
-
-            $ LD_LIBRARY_PATH=../.. ./echecho s
-
-To run the client:
-
-            $ LD_LIBRARY_PATH=../.. ./echecho c localhost
-
-All going well both server and client will print the ECH status at the
-start of each connection. That looks like:
-
-            ECH worked (status: 1, inner: localhost, outer: example.com)
-
-If the non-ECH demo client (``sslecho``) is used instead the server will
-output:
-
-            ECH failed/not-tried (status: -101, inner: (null), outer: (null))
-
-If the non-ECH demo server (i.e., ``sslecho``) is used, the client will exit
-with an error as ECH was attempted and failed. In a debug build, that looks
-like:
-
-            80EBEE54227F0000:error:0A000163:SSL routines:tls_process_initial_server_flight:ech required:ssl/statem/statem_clnt.c:3274:
-
-A real client would likely fall back to not using ECH, but the above
-is ok for a demo.
-
-In that case, the server will also exit based on the ECH alert from the client:
-
-            403787A8307F0000:error:0A000461:SSL routines:ssl3_read_bytes:reason(1121):../ssl/record/rec_layer_s3.c:1588:SSL alert number 121
diff --git a/demos/sslecho/build.info b/demos/sslecho/build.info
index 7784357ed6..d42716cd51 100644
--- a/demos/sslecho/build.info
+++ b/demos/sslecho/build.info
@@ -6,15 +6,6 @@
 
 PROGRAMS{noinst} = sslecho
 
-
 INCLUDE[sslecho]=../../include
 SOURCE[sslecho]=main.c
 DEPEND[sslecho]=../../libcrypto ../../libssl
-
-IF[{- !$disabled{"ech"} -}]
-    PROGRAMS{noinst} = echecho
-
-    INCLUDE[echecho]=../../include
-    SOURCE[echecho]=echecho.c
-    DEPEND[echecho]=../../libcrypto ../../libssl
-ENDIF
diff --git a/demos/sslecho/echecho.c b/demos/sslecho/echecho.c
deleted file mode 100644
index d9c757cba2..0000000000
--- a/demos/sslecho/echecho.c
+++ /dev/null
@@ -1,442 +0,0 @@
-/*
- *  Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
- *
- *  Licensed under the Apache License 2.0 (the "License").  You may not use
- *  this file except in compliance with the License.  You can obtain a copy
- *  in the file LICENSE in the source distribution or at
- *  https://www.openssl.org/source/license.html
- */
-
-#include 
-#include 
-#include 
-#include 
-#include 
-
-#if !defined(OPENSSL_SYS_WINDOWS)
-#include 
-#include 
-#include 
-
-#define SOCKET int
-#define INVALID_SOCKET -1
-#define closesocket(s) close(s)
-#else /* defined(OPENSSL_SYS_WINDOWS) */
-#include 
-#include 
-#endif /* !defined(OPENSSL_SYS_WINDOWS) */
-
-static const int server_port = 4433;
-
-static const char echconfig[]
-    = "AD7+DQA65wAgACA8wVN2BtscOl3vQheUzHeIkVmKIiydUhDCliA4iyQRCwAEAAEA"
-      "AQALZXhhbXBsZS5jb20AAA==";
-static const char echprivbuf[]
-    = "-----BEGIN PRIVATE KEY-----\n"
-      "MC4CAQAwBQYDK2VuBCIEICjd4yGRdsoP9gU7YT7My8DHx1Tjme8GYDXrOMCi8v1V\n"
-      "-----END PRIVATE KEY-----\n"
-      "-----BEGIN ECHCONFIG-----\n"
-      "AD7+DQA65wAgACA8wVN2BtscOl3vQheUzHeIkVmKIiydUhDCliA4iyQRCwAEAAEA"
-      "AQALZXhhbXBsZS5jb20AAA==\n"
-      "-----END ECHCONFIG-----\n";
-
-/*
- * This flag won't be useful until both accept/read (TCP & SSL) methods
- * can be called with a timeout. TBD.
- */
-static volatile bool server_running = true;
-
-static SOCKET create_socket(bool isServer)
-{
-    SOCKET s;
-    int optval = 1;
-    struct sockaddr_in addr = { 0 };
-
-    s = socket(AF_INET, SOCK_STREAM, 0);
-    if (s == INVALID_SOCKET) {
-        perror("Unable to create socket");
-        exit(EXIT_FAILURE);
-    }
-
-    if (isServer) {
-        addr.sin_family = AF_INET;
-        addr.sin_port = htons(server_port);
-        addr.sin_addr.s_addr = INADDR_ANY;
-
-        /* Reuse the address; good for quick restarts */
-        if (setsockopt(s, SOL_SOCKET, SO_REUSEADDR, (void *)&optval, sizeof(optval))
-            < 0) {
-            perror("setsockopt(SO_REUSEADDR) failed");
-            exit(EXIT_FAILURE);
-        }
-
-        if (bind(s, (struct sockaddr *)&addr, sizeof(addr)) < 0) {
-            perror("Unable to bind");
-            exit(EXIT_FAILURE);
-        }
-
-        if (listen(s, 1) < 0) {
-            perror("Unable to listen");
-            exit(EXIT_FAILURE);
-        }
-    }
-
-    return s;
-}
-
-static SSL_CTX *create_context(bool isServer)
-{
-    const SSL_METHOD *method;
-    SSL_CTX *ctx;
-
-    if (isServer)
-        method = TLS_server_method();
-    else
-        method = TLS_client_method();
-
-    ctx = SSL_CTX_new(method);
-    if (ctx == NULL) {
-        perror("Unable to create SSL context");
-        ERR_print_errors_fp(stderr);
-        exit(EXIT_FAILURE);
-    }
-
-    return ctx;
-}
-
-static int configure_ech(SSL_CTX *ctx, int server,
-    unsigned char *buf, size_t len)
-{
-    OSSL_ECHSTORE *es = NULL;
-    BIO *es_in = BIO_new_mem_buf(buf, (int)len);
-
-    if (es_in == NULL || (es = OSSL_ECHSTORE_new(NULL, NULL)) == NULL)
-        goto err;
-    if (server && OSSL_ECHSTORE_read_pem(es, es_in, 1) != 1)
-        goto err;
-    if (!server && OSSL_ECHSTORE_read_echconfiglist(es, es_in) != 1)
-        goto err;
-    if (SSL_CTX_set1_echstore(ctx, es) != 1)
-        goto err;
-    BIO_free_all(es_in);
-    return 1;
-err:
-    OSSL_ECHSTORE_free(es);
-    BIO_free_all(es_in);
-    return 0;
-}
-
-static void configure_server_context(SSL_CTX *ctx)
-{
-    /* Set the key and cert */
-    if (SSL_CTX_use_certificate_chain_file(ctx, "cert.pem") <= 0) {
-        ERR_print_errors_fp(stderr);
-        exit(EXIT_FAILURE);
-    }
-
-    if (SSL_CTX_use_PrivateKey_file(ctx, "key.pem", SSL_FILETYPE_PEM) <= 0) {
-        ERR_print_errors_fp(stderr);
-        exit(EXIT_FAILURE);
-    }
-
-    if (configure_ech(ctx, 1, (unsigned char *)echprivbuf,
-            sizeof(echprivbuf) - 1)
-        != 1) {
-        ERR_print_errors_fp(stderr);
-        exit(EXIT_FAILURE);
-    }
-}
-
-static void configure_client_context(SSL_CTX *ctx)
-{
-    /*
-     * Configure the client to abort the handshake if certificate verification
-     * fails
-     */
-    SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER, NULL);
-    /*
-     * In a real application you would probably just use the default system
-     * certificate trust store and call:
-     *     SSL_CTX_set_default_verify_paths(ctx);
-     * In this demo though we are using a self-signed certificate,
-     * so the client must trust it directly.
-     */
-    if (!SSL_CTX_load_verify_locations(ctx, "cert.pem", NULL)) {
-        ERR_print_errors_fp(stderr);
-        exit(EXIT_FAILURE);
-    }
-    if (configure_ech(ctx, 0, (unsigned char *)echconfig,
-            sizeof(echconfig) - 1)
-        != 1) {
-        ERR_print_errors_fp(stderr);
-        exit(EXIT_FAILURE);
-    }
-}
-
-static void usage(void)
-{
-    printf("Usage: echecho s\n");
-    printf("       --or--\n");
-    printf("       echecho c ip\n");
-    printf("       c=client, s=server, ip=dotted ip of server\n");
-    exit(1);
-}
-
-#define BUFFERSIZE 1024
-int main(int argc, char **argv)
-{
-    bool isServer;
-    int result;
-
-    SSL_CTX *ssl_ctx = NULL;
-    SSL *ssl = NULL;
-
-    SOCKET server_skt = INVALID_SOCKET;
-    SOCKET client_skt = INVALID_SOCKET;
-
-    /* used by fgets */
-    char buffer[BUFFERSIZE];
-    char *txbuf = NULL;
-    size_t txcap = 0;
-
-    char rxbuf[128];
-    size_t rxcap = sizeof(rxbuf);
-    int rxlen;
-
-    char *rem_server_ip = NULL;
-
-    struct sockaddr_in addr = { 0 };
-    socklen_t addr_len = (socklen_t)sizeof(addr);
-
-    char *outer_sni = NULL, *inner_sni = NULL;
-    int ech_status;
-
-    /* Splash */
-    printf("\nechecho : Simple Echo Client/Server: %s : %s\n\n", __DATE__,
-        __TIME__);
-
-    /* Need to know if client or server */
-    if (argc < 2) {
-        usage();
-        /* NOTREACHED */
-    }
-    isServer = (argv[1][0] == 's') ? true : false;
-    /* If client get remote server address (could be 127.0.0.1) */
-    if (!isServer) {
-        if (argc != 3) {
-            usage();
-            /* NOTREACHED */
-        }
-        rem_server_ip = argv[2];
-    }
-
-    /* Create context used by both client and server */
-    ssl_ctx = create_context(isServer);
-
-    /* If server */
-    if (isServer) {
-
-        printf("We are the server on port: %d\n\n", server_port);
-
-        /* Configure server context with appropriate key files */
-        configure_server_context(ssl_ctx);
-
-        /* Create server socket; will bind with server port and listen */
-        server_skt = create_socket(true);
-
-        /*
-         * Loop to accept clients.
-         * Need to implement timeouts on TCP & SSL connect/read functions
-         * before we can catch a CTRL-C and kill the server.
-         */
-        while (server_running) {
-            /* Wait for TCP connection from client */
-            client_skt = accept(server_skt, (struct sockaddr *)&addr,
-                &addr_len);
-            if (client_skt == INVALID_SOCKET) {
-                perror("Unable to accept");
-                exit(EXIT_FAILURE);
-            }
-
-            printf("Client TCP connection accepted\n");
-
-            /* Create server SSL structure using newly accepted client socket */
-            ssl = SSL_new(ssl_ctx);
-            if (SSL_set_fd(ssl, (int)client_skt) <= 0) {
-                puts("Unable to set fd for the SSL object");
-                ERR_print_errors_fp(stderr);
-                exit(EXIT_FAILURE);
-            }
-
-            /* Wait for SSL connection from the client */
-            if (SSL_accept(ssl) <= 0) {
-                ERR_print_errors_fp(stderr);
-                server_running = false;
-            } else {
-
-                printf("Client SSL connection accepted\n\n");
-
-                ech_status = SSL_ech_get1_status(ssl, &inner_sni, &outer_sni);
-                printf("ECH %s (status: %d, inner: %s, outer: %s)\n",
-                    (ech_status == 1 ? "worked" : "failed/not-tried"),
-                    ech_status, inner_sni, outer_sni);
-                OPENSSL_free(inner_sni);
-                OPENSSL_free(outer_sni);
-                inner_sni = outer_sni = NULL;
-
-                /* Echo loop */
-                while (true) {
-                    /*
-                     * Get message from client; will fail if client closes
-                     * connection
-                     */
-                    if ((rxlen = SSL_read(ssl, rxbuf, (int)rxcap)) <= 0) {
-                        if (rxlen == 0) {
-                            printf("Client closed connection\n");
-                        }
-                        ERR_print_errors_fp(stderr);
-                        break;
-                    }
-                    /* Insure null terminated input */
-                    rxbuf[rxlen] = 0;
-                    /* Look for kill switch */
-                    if (strcmp(rxbuf, "kill\n") == 0) {
-                        /* Terminate...with extreme prejudice */
-                        printf("Server received 'kill' command\n");
-                        server_running = false;
-                        break;
-                    }
-                    /* Show received message */
-                    printf("Received: %s", rxbuf);
-                    /* Echo it back */
-                    if (SSL_write(ssl, rxbuf, rxlen) <= 0) {
-                        ERR_print_errors_fp(stderr);
-                    }
-                }
-            }
-            if (server_running) {
-                /* Cleanup for next client */
-                SSL_shutdown(ssl);
-                SSL_free(ssl);
-                closesocket(client_skt);
-                /*
-                 * Set client_skt to INVALID_SOCKET to avoid double close when
-                 * server_running become false before next accept
-                 */
-                client_skt = INVALID_SOCKET;
-            }
-        }
-        printf("Server exiting...\n");
-    }
-    /* Else client */
-    else {
-
-        printf("We are the client\n\n");
-
-        /* Configure client context so we verify the server correctly */
-        configure_client_context(ssl_ctx);
-
-        /* Create "bare" socket */
-        client_skt = create_socket(false);
-        /* Set up connect address */
-        addr.sin_family = AF_INET;
-        inet_pton(AF_INET, rem_server_ip, &addr.sin_addr.s_addr);
-        addr.sin_port = htons(server_port);
-        /* Do TCP connect with server */
-        if (connect(client_skt, (struct sockaddr *)&addr, sizeof(addr)) != 0) {
-            perror("Unable to TCP connect to server");
-            goto exit;
-        } else {
-            printf("TCP connection to server successful\n");
-        }
-
-        /* Create client SSL structure using dedicated client socket */
-        ssl = SSL_new(ssl_ctx);
-        if (SSL_set_fd(ssl, (int)client_skt) <= 0) {
-            puts("Unable to set fd for the SSL object");
-            ERR_print_errors_fp(stderr);
-            exit(EXIT_FAILURE);
-        }
-        /* Set hostname for SNI */
-        SSL_set_tlsext_host_name(ssl, rem_server_ip);
-        /* Configure server hostname check */
-        if (SSL_set1_ipaddr(ssl, rem_server_ip) <= 0) {
-            puts("Unable to set IP address for the SSL object");
-            ERR_print_errors_fp(stderr);
-            exit(EXIT_FAILURE);
-        }
-
-        /* Now do SSL connect with server */
-        if (SSL_connect(ssl) == 1) {
-
-            printf("SSL connection to server successful\n\n");
-
-            ech_status = SSL_ech_get1_status(ssl, &inner_sni, &outer_sni);
-            printf("ECH %s (status: %d, inner: %s, outer: %s)\n",
-                (ech_status == 1 ? "worked" : "failed/not-tried"),
-                ech_status, inner_sni, outer_sni);
-            OPENSSL_free(inner_sni);
-            OPENSSL_free(outer_sni);
-            inner_sni = outer_sni = NULL;
-
-            /* Loop to send input from keyboard */
-            while (true) {
-                /* Get a line of input */
-                memset(buffer, 0, BUFFERSIZE);
-                txbuf = fgets(buffer, BUFFERSIZE, stdin);
-
-                /* Exit loop on error */
-                if (txbuf == NULL) {
-                    break;
-                }
-                /* Exit loop if just a carriage return */
-                if (txbuf[0] == '\n') {
-                    break;
-                }
-                /* Send it to the server */
-                if ((result = SSL_write(ssl, txbuf, (int)strlen(txbuf))) <= 0) {
-                    printf("Server closed connection\n");
-                    ERR_print_errors_fp(stderr);
-                    break;
-                }
-
-                /* Wait for the echo */
-                rxlen = SSL_read(ssl, rxbuf, (int)rxcap);
-                if (rxlen <= 0) {
-                    printf("Server closed connection\n");
-                    ERR_print_errors_fp(stderr);
-                    break;
-                } else {
-                    /* Show it */
-                    rxbuf[rxlen] = 0;
-                    printf("Received: %s", rxbuf);
-                }
-            }
-            printf("Client exiting...\n");
-        } else {
-
-            printf("SSL connection to server failed\n\n");
-
-            ERR_print_errors_fp(stderr);
-        }
-    }
-exit:
-    /* Close up */
-    if (ssl != NULL) {
-        SSL_shutdown(ssl);
-        SSL_free(ssl);
-    }
-    SSL_CTX_free(ssl_ctx);
-
-    if (client_skt != INVALID_SOCKET)
-        closesocket(client_skt);
-    if (server_skt != INVALID_SOCKET)
-        closesocket(server_skt);
-
-    if (txbuf != NULL && txcap > 0)
-        free(txbuf);
-
-    printf("echecho exiting\n");
-
-    return 0;
-}
diff --git a/demos/sslecho/main.c b/demos/sslecho/main.c
index dfa5d263bd..4d4fc96973 100644
--- a/demos/sslecho/main.c
+++ b/demos/sslecho/main.c
@@ -1,5 +1,5 @@
 /*
- *  Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved.
+ *  Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved.
  *
  *  Licensed under the Apache License 2.0 (the "License").  You may not use
  *  this file except in compliance with the License.  You can obtain a copy
@@ -19,7 +19,6 @@
 #include 
 
 #define SOCKET int
-#define INVALID_SOCKET -1
 #define closesocket(s) close(s)
 
 #else
@@ -46,7 +45,7 @@ static SOCKET create_socket(flag isServer)
     struct sockaddr_in addr;
 
     s = socket(AF_INET, SOCK_STREAM, 0);
-    if (s == INVALID_SOCKET) {
+    if (s < 0) {
         perror("Unable to create socket");
         exit(EXIT_FAILURE);
     }
@@ -147,8 +146,8 @@ int main(int argc, char **argv)
     SSL_CTX *ssl_ctx = NULL;
     SSL *ssl = NULL;
 
-    SOCKET server_skt = INVALID_SOCKET;
-    SOCKET client_skt = INVALID_SOCKET;
+    SOCKET server_skt = -1;
+    SOCKET client_skt = -1;
 
     /* used by fgets */
     char buffer[BUFFERSIZE];
@@ -214,7 +213,7 @@ int main(int argc, char **argv)
             /* Wait for TCP connection from client */
             client_skt = accept(server_skt, (struct sockaddr *)&addr,
                 &addr_len);
-            if (client_skt == INVALID_SOCKET) {
+            if (client_skt < 0) {
                 perror("Unable to accept");
                 exit(EXIT_FAILURE);
             }
@@ -271,10 +270,10 @@ int main(int argc, char **argv)
                 SSL_free(ssl);
                 closesocket(client_skt);
                 /*
-                 * Set client_skt to INVALID_SOCKET to avoid double close when
+                 * Set client_skt to -1 to avoid double close when
                  * server_running become false before next accept
                  */
-                client_skt = INVALID_SOCKET;
+                client_skt = -1;
             }
         }
         printf("Server exiting...\n");
@@ -310,7 +309,7 @@ int main(int argc, char **argv)
         /* Set hostname for SNI */
         SSL_set_tlsext_host_name(ssl, rem_server_ip);
         /* Configure server hostname check */
-        if (!SSL_set1_dnsname(ssl, rem_server_ip)) {
+        if (!SSL_set1_host(ssl, rem_server_ip)) {
             ERR_print_errors_fp(stderr);
             goto exit;
         }
@@ -369,9 +368,9 @@ exit:
     }
     SSL_CTX_free(ssl_ctx);
 
-    if (client_skt != INVALID_SOCKET)
+    if (client_skt != -1)
         closesocket(client_skt);
-    if (server_skt != INVALID_SOCKET)
+    if (server_skt != -1)
         closesocket(server_skt);
 
     printf("sslecho exiting\n");
diff --git a/doc/build.info b/doc/build.info
index 44b06941e4..4e62ed9be8 100644
--- a/doc/build.info
+++ b/doc/build.info
@@ -8,6 +8,8 @@ DEPEND[html/man1/openssl-asn1parse.html]=man1/openssl-asn1parse.pod
 GENERATE[html/man1/openssl-asn1parse.html]=man1/openssl-asn1parse.pod
 DEPEND[man/man1/openssl-asn1parse.1]=man1/openssl-asn1parse.pod
 GENERATE[man/man1/openssl-asn1parse.1]=man1/openssl-asn1parse.pod
+DEPEND[man1/openssl-asn1parse.pod]{pod}=man1/openssl-asn1parse.pod.in
+GENERATE[man1/openssl-asn1parse.pod]=man1/openssl-asn1parse.pod.in
 DEPEND[html/man1/openssl-ca.html]=man1/openssl-ca.pod
 GENERATE[html/man1/openssl-ca.html]=man1/openssl-ca.pod
 DEPEND[man/man1/openssl-ca.1]=man1/openssl-ca.pod
@@ -24,6 +26,8 @@ DEPEND[html/man1/openssl-cmds.html]=man1/openssl-cmds.pod
 GENERATE[html/man1/openssl-cmds.html]=man1/openssl-cmds.pod
 DEPEND[man/man1/openssl-cmds.1]=man1/openssl-cmds.pod
 GENERATE[man/man1/openssl-cmds.1]=man1/openssl-cmds.pod
+DEPEND[man1/openssl-cmds.pod]{pod}=man1/openssl-cmds.pod.in
+GENERATE[man1/openssl-cmds.pod]=man1/openssl-cmds.pod.in
 DEPEND[html/man1/openssl-cmp.html]=man1/openssl-cmp.pod
 GENERATE[html/man1/openssl-cmp.html]=man1/openssl-cmp.pod
 DEPEND[man/man1/openssl-cmp.1]=man1/openssl-cmp.pod
@@ -40,6 +44,8 @@ DEPEND[html/man1/openssl-configutl.html]=man1/openssl-configutl.pod
 GENERATE[html/man1/openssl-configutl.html]=man1/openssl-configutl.pod
 DEPEND[man/man1/openssl-configutl.1]=man1/openssl-configutl.pod
 GENERATE[man/man1/openssl-configutl.1]=man1/openssl-configutl.pod
+DEPEND[man1/openssl-configutl.pod]{pod}=man1/openssl-configutl.pod.in
+GENERATE[man1/openssl-configutl.pod]=man1/openssl-configutl.pod.in
 DEPEND[html/man1/openssl-crl.html]=man1/openssl-crl.pod
 GENERATE[html/man1/openssl-crl.html]=man1/openssl-crl.pod
 DEPEND[man/man1/openssl-crl.1]=man1/openssl-crl.pod
@@ -82,12 +88,6 @@ DEPEND[man/man1/openssl-ec.1]=man1/openssl-ec.pod
 GENERATE[man/man1/openssl-ec.1]=man1/openssl-ec.pod
 DEPEND[man1/openssl-ec.pod]{pod}=man1/openssl-ec.pod.in
 GENERATE[man1/openssl-ec.pod]=man1/openssl-ec.pod.in
-DEPEND[html/man1/openssl-ech.html]=man1/openssl-ech.pod
-GENERATE[html/man1/openssl-ech.html]=man1/openssl-ech.pod
-DEPEND[man/man1/openssl-ech.1]=man1/openssl-ech.pod
-GENERATE[man/man1/openssl-ech.1]=man1/openssl-ech.pod
-DEPEND[man1/openssl-ech.pod]{pod}=man1/openssl-ech.pod.in
-GENERATE[man1/openssl-ech.pod]=man1/openssl-ech.pod.in
 DEPEND[html/man1/openssl-ecparam.html]=man1/openssl-ecparam.pod
 GENERATE[html/man1/openssl-ecparam.html]=man1/openssl-ecparam.pod
 DEPEND[man/man1/openssl-ecparam.1]=man1/openssl-ecparam.pod
@@ -104,10 +104,14 @@ DEPEND[html/man1/openssl-errstr.html]=man1/openssl-errstr.pod
 GENERATE[html/man1/openssl-errstr.html]=man1/openssl-errstr.pod
 DEPEND[man/man1/openssl-errstr.1]=man1/openssl-errstr.pod
 GENERATE[man/man1/openssl-errstr.1]=man1/openssl-errstr.pod
+DEPEND[man1/openssl-errstr.pod]{pod}=man1/openssl-errstr.pod.in
+GENERATE[man1/openssl-errstr.pod]=man1/openssl-errstr.pod.in
 DEPEND[html/man1/openssl-fipsinstall.html]=man1/openssl-fipsinstall.pod
 GENERATE[html/man1/openssl-fipsinstall.html]=man1/openssl-fipsinstall.pod
 DEPEND[man/man1/openssl-fipsinstall.1]=man1/openssl-fipsinstall.pod
 GENERATE[man/man1/openssl-fipsinstall.1]=man1/openssl-fipsinstall.pod
+DEPEND[man1/openssl-fipsinstall.pod]{pod}=man1/openssl-fipsinstall.pod.in
+GENERATE[man1/openssl-fipsinstall.pod]=man1/openssl-fipsinstall.pod.in
 DEPEND[html/man1/openssl-format-options.html]=man1/openssl-format-options.pod
 GENERATE[html/man1/openssl-format-options.html]=man1/openssl-format-options.pod
 DEPEND[man/man1/openssl-format-options.1]=man1/openssl-format-options.pod
@@ -134,6 +138,8 @@ DEPEND[html/man1/openssl-info.html]=man1/openssl-info.pod
 GENERATE[html/man1/openssl-info.html]=man1/openssl-info.pod
 DEPEND[man/man1/openssl-info.1]=man1/openssl-info.pod
 GENERATE[man/man1/openssl-info.1]=man1/openssl-info.pod
+DEPEND[man1/openssl-info.pod]{pod}=man1/openssl-info.pod.in
+GENERATE[man1/openssl-info.pod]=man1/openssl-info.pod.in
 DEPEND[html/man1/openssl-kdf.html]=man1/openssl-kdf.pod
 GENERATE[html/man1/openssl-kdf.html]=man1/openssl-kdf.pod
 DEPEND[man/man1/openssl-kdf.1]=man1/openssl-kdf.pod
@@ -272,6 +278,8 @@ DEPEND[html/man1/openssl-sess_id.html]=man1/openssl-sess_id.pod
 GENERATE[html/man1/openssl-sess_id.html]=man1/openssl-sess_id.pod
 DEPEND[man/man1/openssl-sess_id.1]=man1/openssl-sess_id.pod
 GENERATE[man/man1/openssl-sess_id.1]=man1/openssl-sess_id.pod
+DEPEND[man1/openssl-sess_id.pod]{pod}=man1/openssl-sess_id.pod.in
+GENERATE[man1/openssl-sess_id.pod]=man1/openssl-sess_id.pod.in
 DEPEND[html/man1/openssl-skeyutl.html]=man1/openssl-skeyutl.pod
 GENERATE[html/man1/openssl-skeyutl.html]=man1/openssl-skeyutl.pod
 DEPEND[man/man1/openssl-skeyutl.1]=man1/openssl-skeyutl.pod
@@ -328,6 +336,8 @@ DEPEND[html/man1/openssl-version.html]=man1/openssl-version.pod
 GENERATE[html/man1/openssl-version.html]=man1/openssl-version.pod
 DEPEND[man/man1/openssl-version.1]=man1/openssl-version.pod
 GENERATE[man/man1/openssl-version.1]=man1/openssl-version.pod
+DEPEND[man1/openssl-version.pod]{pod}=man1/openssl-version.pod.in
+GENERATE[man1/openssl-version.pod]=man1/openssl-version.pod.in
 DEPEND[html/man1/openssl-x509.html]=man1/openssl-x509.pod
 GENERATE[html/man1/openssl-x509.html]=man1/openssl-x509.pod
 DEPEND[man/man1/openssl-x509.1]=man1/openssl-x509.pod
@@ -358,7 +368,6 @@ html/man1/openssl-dhparam.html \
 html/man1/openssl-dsa.html \
 html/man1/openssl-dsaparam.html \
 html/man1/openssl-ec.html \
-html/man1/openssl-ech.html \
 html/man1/openssl-ecparam.html \
 html/man1/openssl-enc.html \
 html/man1/openssl-errstr.html \
@@ -420,7 +429,6 @@ man/man1/openssl-dhparam.1 \
 man/man1/openssl-dsa.1 \
 man/man1/openssl-dsaparam.1 \
 man/man1/openssl-ec.1 \
-man/man1/openssl-ech.1 \
 man/man1/openssl-ecparam.1 \
 man/man1/openssl-enc.1 \
 man/man1/openssl-errstr.1 \
@@ -471,14 +479,6 @@ DEPEND[html/man3/ADMISSIONS.html]=man3/ADMISSIONS.pod
 GENERATE[html/man3/ADMISSIONS.html]=man3/ADMISSIONS.pod
 DEPEND[man/man3/ADMISSIONS.3]=man3/ADMISSIONS.pod
 GENERATE[man/man3/ADMISSIONS.3]=man3/ADMISSIONS.pod
-DEPEND[html/man3/ASN1_BIT_STRING_get_length.html]=man3/ASN1_BIT_STRING_get_length.pod
-GENERATE[html/man3/ASN1_BIT_STRING_get_length.html]=man3/ASN1_BIT_STRING_get_length.pod
-DEPEND[man/man3/ASN1_BIT_STRING_get_length.3]=man3/ASN1_BIT_STRING_get_length.pod
-GENERATE[man/man3/ASN1_BIT_STRING_get_length.3]=man3/ASN1_BIT_STRING_get_length.pod
-DEPEND[html/man3/ASN1_BIT_STRING_new.html]=man3/ASN1_BIT_STRING_new.pod
-GENERATE[html/man3/ASN1_BIT_STRING_new.html]=man3/ASN1_BIT_STRING_new.pod
-DEPEND[man/man3/ASN1_BIT_STRING_new.3]=man3/ASN1_BIT_STRING_new.pod
-GENERATE[man/man3/ASN1_BIT_STRING_new.3]=man3/ASN1_BIT_STRING_new.pod
 DEPEND[html/man3/ASN1_EXTERN_FUNCS.html]=man3/ASN1_EXTERN_FUNCS.pod
 GENERATE[html/man3/ASN1_EXTERN_FUNCS.html]=man3/ASN1_EXTERN_FUNCS.pod
 DEPEND[man/man3/ASN1_EXTERN_FUNCS.3]=man3/ASN1_EXTERN_FUNCS.pod
@@ -699,10 +699,6 @@ DEPEND[html/man3/BIO_set_callback.html]=man3/BIO_set_callback.pod
 GENERATE[html/man3/BIO_set_callback.html]=man3/BIO_set_callback.pod
 DEPEND[man/man3/BIO_set_callback.3]=man3/BIO_set_callback.pod
 GENERATE[man/man3/BIO_set_callback.3]=man3/BIO_set_callback.pod
-DEPEND[html/man3/BIO_set_flags.html]=man3/BIO_set_flags.pod
-GENERATE[html/man3/BIO_set_flags.html]=man3/BIO_set_flags.pod
-DEPEND[man/man3/BIO_set_flags.3]=man3/BIO_set_flags.pod
-GENERATE[man/man3/BIO_set_flags.3]=man3/BIO_set_flags.pod
 DEPEND[html/man3/BIO_should_retry.html]=man3/BIO_should_retry.pod
 GENERATE[html/man3/BIO_should_retry.html]=man3/BIO_should_retry.pod
 DEPEND[man/man3/BIO_should_retry.3]=man3/BIO_should_retry.pod
@@ -1119,6 +1115,10 @@ DEPEND[html/man3/ERR_put_error.html]=man3/ERR_put_error.pod
 GENERATE[html/man3/ERR_put_error.html]=man3/ERR_put_error.pod
 DEPEND[man/man3/ERR_put_error.3]=man3/ERR_put_error.pod
 GENERATE[man/man3/ERR_put_error.3]=man3/ERR_put_error.pod
+DEPEND[html/man3/ERR_remove_state.html]=man3/ERR_remove_state.pod
+GENERATE[html/man3/ERR_remove_state.html]=man3/ERR_remove_state.pod
+DEPEND[man/man3/ERR_remove_state.3]=man3/ERR_remove_state.pod
+GENERATE[man/man3/ERR_remove_state.3]=man3/ERR_remove_state.pod
 DEPEND[html/man3/ERR_set_mark.html]=man3/ERR_set_mark.pod
 GENERATE[html/man3/ERR_set_mark.html]=man3/ERR_set_mark.pod
 DEPEND[man/man3/ERR_set_mark.3]=man3/ERR_set_mark.pod
@@ -1131,10 +1131,6 @@ DEPEND[html/man3/EVP_BytesToKey.html]=man3/EVP_BytesToKey.pod
 GENERATE[html/man3/EVP_BytesToKey.html]=man3/EVP_BytesToKey.pod
 DEPEND[man/man3/EVP_BytesToKey.3]=man3/EVP_BytesToKey.pod
 GENERATE[man/man3/EVP_BytesToKey.3]=man3/EVP_BytesToKey.pod
-DEPEND[html/man3/EVP_CIPHER_CTX_get_app_data.html]=man3/EVP_CIPHER_CTX_get_app_data.pod
-GENERATE[html/man3/EVP_CIPHER_CTX_get_app_data.html]=man3/EVP_CIPHER_CTX_get_app_data.pod
-DEPEND[man/man3/EVP_CIPHER_CTX_get_app_data.3]=man3/EVP_CIPHER_CTX_get_app_data.pod
-GENERATE[man/man3/EVP_CIPHER_CTX_get_app_data.3]=man3/EVP_CIPHER_CTX_get_app_data.pod
 DEPEND[html/man3/EVP_CIPHER_CTX_get_cipher_data.html]=man3/EVP_CIPHER_CTX_get_cipher_data.pod
 GENERATE[html/man3/EVP_CIPHER_CTX_get_cipher_data.html]=man3/EVP_CIPHER_CTX_get_cipher_data.pod
 DEPEND[man/man3/EVP_CIPHER_CTX_get_cipher_data.3]=man3/EVP_CIPHER_CTX_get_cipher_data.pod
@@ -1143,6 +1139,10 @@ DEPEND[html/man3/EVP_CIPHER_CTX_get_original_iv.html]=man3/EVP_CIPHER_CTX_get_or
 GENERATE[html/man3/EVP_CIPHER_CTX_get_original_iv.html]=man3/EVP_CIPHER_CTX_get_original_iv.pod
 DEPEND[man/man3/EVP_CIPHER_CTX_get_original_iv.3]=man3/EVP_CIPHER_CTX_get_original_iv.pod
 GENERATE[man/man3/EVP_CIPHER_CTX_get_original_iv.3]=man3/EVP_CIPHER_CTX_get_original_iv.pod
+DEPEND[html/man3/EVP_CIPHER_meth_new.html]=man3/EVP_CIPHER_meth_new.pod
+GENERATE[html/man3/EVP_CIPHER_meth_new.html]=man3/EVP_CIPHER_meth_new.pod
+DEPEND[man/man3/EVP_CIPHER_meth_new.3]=man3/EVP_CIPHER_meth_new.pod
+GENERATE[man/man3/EVP_CIPHER_meth_new.3]=man3/EVP_CIPHER_meth_new.pod
 DEPEND[html/man3/EVP_DigestInit.html]=man3/EVP_DigestInit.pod
 GENERATE[html/man3/EVP_DigestInit.html]=man3/EVP_DigestInit.pod
 DEPEND[man/man3/EVP_DigestInit.3]=man3/EVP_DigestInit.pod
@@ -1155,10 +1155,6 @@ DEPEND[html/man3/EVP_DigestVerifyInit.html]=man3/EVP_DigestVerifyInit.pod
 GENERATE[html/man3/EVP_DigestVerifyInit.html]=man3/EVP_DigestVerifyInit.pod
 DEPEND[man/man3/EVP_DigestVerifyInit.3]=man3/EVP_DigestVerifyInit.pod
 GENERATE[man/man3/EVP_DigestVerifyInit.3]=man3/EVP_DigestVerifyInit.pod
-DEPEND[html/man3/EVP_EC_gen.html]=man3/EVP_EC_gen.pod
-GENERATE[html/man3/EVP_EC_gen.html]=man3/EVP_EC_gen.pod
-DEPEND[man/man3/EVP_EC_gen.3]=man3/EVP_EC_gen.pod
-GENERATE[man/man3/EVP_EC_gen.3]=man3/EVP_EC_gen.pod
 DEPEND[html/man3/EVP_EncodeInit.html]=man3/EVP_EncodeInit.pod
 GENERATE[html/man3/EVP_EncodeInit.html]=man3/EVP_EncodeInit.pod
 DEPEND[man/man3/EVP_EncodeInit.3]=man3/EVP_EncodeInit.pod
@@ -1187,6 +1183,10 @@ DEPEND[html/man3/EVP_MAC.html]=man3/EVP_MAC.pod
 GENERATE[html/man3/EVP_MAC.html]=man3/EVP_MAC.pod
 DEPEND[man/man3/EVP_MAC.3]=man3/EVP_MAC.pod
 GENERATE[man/man3/EVP_MAC.3]=man3/EVP_MAC.pod
+DEPEND[html/man3/EVP_MD_meth_new.html]=man3/EVP_MD_meth_new.pod
+GENERATE[html/man3/EVP_MD_meth_new.html]=man3/EVP_MD_meth_new.pod
+DEPEND[man/man3/EVP_MD_meth_new.3]=man3/EVP_MD_meth_new.pod
+GENERATE[man/man3/EVP_MD_meth_new.3]=man3/EVP_MD_meth_new.pod
 DEPEND[html/man3/EVP_OpenInit.html]=man3/EVP_OpenInit.pod
 GENERATE[html/man3/EVP_OpenInit.html]=man3/EVP_OpenInit.pod
 DEPEND[man/man3/EVP_OpenInit.3]=man3/EVP_OpenInit.pod
@@ -1199,6 +1199,10 @@ DEPEND[html/man3/EVP_PKEY2PKCS8.html]=man3/EVP_PKEY2PKCS8.pod
 GENERATE[html/man3/EVP_PKEY2PKCS8.html]=man3/EVP_PKEY2PKCS8.pod
 DEPEND[man/man3/EVP_PKEY2PKCS8.3]=man3/EVP_PKEY2PKCS8.pod
 GENERATE[man/man3/EVP_PKEY2PKCS8.3]=man3/EVP_PKEY2PKCS8.pod
+DEPEND[html/man3/EVP_PKEY_ASN1_METHOD.html]=man3/EVP_PKEY_ASN1_METHOD.pod
+GENERATE[html/man3/EVP_PKEY_ASN1_METHOD.html]=man3/EVP_PKEY_ASN1_METHOD.pod
+DEPEND[man/man3/EVP_PKEY_ASN1_METHOD.3]=man3/EVP_PKEY_ASN1_METHOD.pod
+GENERATE[man/man3/EVP_PKEY_ASN1_METHOD.3]=man3/EVP_PKEY_ASN1_METHOD.pod
 DEPEND[html/man3/EVP_PKEY_CTX_ctrl.html]=man3/EVP_PKEY_CTX_ctrl.pod
 GENERATE[html/man3/EVP_PKEY_CTX_ctrl.html]=man3/EVP_PKEY_CTX_ctrl.pod
 DEPEND[man/man3/EVP_PKEY_CTX_ctrl.3]=man3/EVP_PKEY_CTX_ctrl.pod
@@ -1243,6 +1247,10 @@ DEPEND[html/man3/EVP_PKEY_CTX_set_tls1_prf_md.html]=man3/EVP_PKEY_CTX_set_tls1_p
 GENERATE[html/man3/EVP_PKEY_CTX_set_tls1_prf_md.html]=man3/EVP_PKEY_CTX_set_tls1_prf_md.pod
 DEPEND[man/man3/EVP_PKEY_CTX_set_tls1_prf_md.3]=man3/EVP_PKEY_CTX_set_tls1_prf_md.pod
 GENERATE[man/man3/EVP_PKEY_CTX_set_tls1_prf_md.3]=man3/EVP_PKEY_CTX_set_tls1_prf_md.pod
+DEPEND[html/man3/EVP_PKEY_asn1_get_count.html]=man3/EVP_PKEY_asn1_get_count.pod
+GENERATE[html/man3/EVP_PKEY_asn1_get_count.html]=man3/EVP_PKEY_asn1_get_count.pod
+DEPEND[man/man3/EVP_PKEY_asn1_get_count.3]=man3/EVP_PKEY_asn1_get_count.pod
+GENERATE[man/man3/EVP_PKEY_asn1_get_count.3]=man3/EVP_PKEY_asn1_get_count.pod
 DEPEND[html/man3/EVP_PKEY_check.html]=man3/EVP_PKEY_check.pod
 GENERATE[html/man3/EVP_PKEY_check.html]=man3/EVP_PKEY_check.pod
 DEPEND[man/man3/EVP_PKEY_check.3]=man3/EVP_PKEY_check.pod
@@ -1311,6 +1319,14 @@ DEPEND[html/man3/EVP_PKEY_keygen.html]=man3/EVP_PKEY_keygen.pod
 GENERATE[html/man3/EVP_PKEY_keygen.html]=man3/EVP_PKEY_keygen.pod
 DEPEND[man/man3/EVP_PKEY_keygen.3]=man3/EVP_PKEY_keygen.pod
 GENERATE[man/man3/EVP_PKEY_keygen.3]=man3/EVP_PKEY_keygen.pod
+DEPEND[html/man3/EVP_PKEY_meth_get_count.html]=man3/EVP_PKEY_meth_get_count.pod
+GENERATE[html/man3/EVP_PKEY_meth_get_count.html]=man3/EVP_PKEY_meth_get_count.pod
+DEPEND[man/man3/EVP_PKEY_meth_get_count.3]=man3/EVP_PKEY_meth_get_count.pod
+GENERATE[man/man3/EVP_PKEY_meth_get_count.3]=man3/EVP_PKEY_meth_get_count.pod
+DEPEND[html/man3/EVP_PKEY_meth_new.html]=man3/EVP_PKEY_meth_new.pod
+GENERATE[html/man3/EVP_PKEY_meth_new.html]=man3/EVP_PKEY_meth_new.pod
+DEPEND[man/man3/EVP_PKEY_meth_new.3]=man3/EVP_PKEY_meth_new.pod
+GENERATE[man/man3/EVP_PKEY_meth_new.3]=man3/EVP_PKEY_meth_new.pod
 DEPEND[html/man3/EVP_PKEY_new.html]=man3/EVP_PKEY_new.pod
 GENERATE[html/man3/EVP_PKEY_new.html]=man3/EVP_PKEY_new.pod
 DEPEND[man/man3/EVP_PKEY_new.3]=man3/EVP_PKEY_new.pod
@@ -1499,10 +1515,6 @@ DEPEND[html/man3/MDC2_Init.html]=man3/MDC2_Init.pod
 GENERATE[html/man3/MDC2_Init.html]=man3/MDC2_Init.pod
 DEPEND[man/man3/MDC2_Init.3]=man3/MDC2_Init.pod
 GENERATE[man/man3/MDC2_Init.3]=man3/MDC2_Init.pod
-DEPEND[html/man3/NAME_CONSTRAINTS_check.html]=man3/NAME_CONSTRAINTS_check.pod
-GENERATE[html/man3/NAME_CONSTRAINTS_check.html]=man3/NAME_CONSTRAINTS_check.pod
-DEPEND[man/man3/NAME_CONSTRAINTS_check.3]=man3/NAME_CONSTRAINTS_check.pod
-GENERATE[man/man3/NAME_CONSTRAINTS_check.3]=man3/NAME_CONSTRAINTS_check.pod
 DEPEND[html/man3/NCONF_new_ex.html]=man3/NCONF_new_ex.pod
 GENERATE[html/man3/NCONF_new_ex.html]=man3/NCONF_new_ex.pod
 DEPEND[man/man3/NCONF_new_ex.3]=man3/NCONF_new_ex.pod
@@ -2775,10 +2787,6 @@ DEPEND[html/man3/SSL_session_reused.html]=man3/SSL_session_reused.pod
 GENERATE[html/man3/SSL_session_reused.html]=man3/SSL_session_reused.pod
 DEPEND[man/man3/SSL_session_reused.3]=man3/SSL_session_reused.pod
 GENERATE[man/man3/SSL_session_reused.3]=man3/SSL_session_reused.pod
-DEPEND[html/man3/SSL_set1_echstore.html]=man3/SSL_set1_echstore.pod
-GENERATE[html/man3/SSL_set1_echstore.html]=man3/SSL_set1_echstore.pod
-DEPEND[man/man3/SSL_set1_echstore.3]=man3/SSL_set1_echstore.pod
-GENERATE[man/man3/SSL_set1_echstore.3]=man3/SSL_set1_echstore.pod
 DEPEND[html/man3/SSL_set1_host.html]=man3/SSL_set1_host.pod
 GENERATE[html/man3/SSL_set1_host.html]=man3/SSL_set1_host.pod
 DEPEND[man/man3/SSL_set1_host.3]=man3/SSL_set1_host.pod
@@ -2891,10 +2899,6 @@ DEPEND[html/man3/UI_new.html]=man3/UI_new.pod
 GENERATE[html/man3/UI_new.html]=man3/UI_new.pod
 DEPEND[man/man3/UI_new.3]=man3/UI_new.pod
 GENERATE[man/man3/UI_new.3]=man3/UI_new.pod
-DEPEND[html/man3/X509V3_EXT_print.html]=man3/X509V3_EXT_print.pod
-GENERATE[html/man3/X509V3_EXT_print.html]=man3/X509V3_EXT_print.pod
-DEPEND[man/man3/X509V3_EXT_print.3]=man3/X509V3_EXT_print.pod
-GENERATE[man/man3/X509V3_EXT_print.3]=man3/X509V3_EXT_print.pod
 DEPEND[html/man3/X509V3_get_d2i.html]=man3/X509V3_get_d2i.pod
 GENERATE[html/man3/X509V3_get_d2i.html]=man3/X509V3_get_d2i.pod
 DEPEND[man/man3/X509V3_get_d2i.3]=man3/X509V3_get_d2i.pod
@@ -3031,10 +3035,6 @@ DEPEND[html/man3/X509_check_ca.html]=man3/X509_check_ca.pod
 GENERATE[html/man3/X509_check_ca.html]=man3/X509_check_ca.pod
 DEPEND[man/man3/X509_check_ca.3]=man3/X509_check_ca.pod
 GENERATE[man/man3/X509_check_ca.3]=man3/X509_check_ca.pod
-DEPEND[html/man3/X509_check_certificate_times.html]=man3/X509_check_certificate_times.pod
-GENERATE[html/man3/X509_check_certificate_times.html]=man3/X509_check_certificate_times.pod
-DEPEND[man/man3/X509_check_certificate_times.3]=man3/X509_check_certificate_times.pod
-GENERATE[man/man3/X509_check_certificate_times.3]=man3/X509_check_certificate_times.pod
 DEPEND[html/man3/X509_check_host.html]=man3/X509_check_host.pod
 GENERATE[html/man3/X509_check_host.html]=man3/X509_check_host.pod
 DEPEND[man/man3/X509_check_host.3]=man3/X509_check_host.pod
@@ -3055,6 +3055,10 @@ DEPEND[html/man3/X509_cmp.html]=man3/X509_cmp.pod
 GENERATE[html/man3/X509_cmp.html]=man3/X509_cmp.pod
 DEPEND[man/man3/X509_cmp.3]=man3/X509_cmp.pod
 GENERATE[man/man3/X509_cmp.3]=man3/X509_cmp.pod
+DEPEND[html/man3/X509_cmp_time.html]=man3/X509_cmp_time.pod
+GENERATE[html/man3/X509_cmp_time.html]=man3/X509_cmp_time.pod
+DEPEND[man/man3/X509_cmp_time.3]=man3/X509_cmp_time.pod
+GENERATE[man/man3/X509_cmp_time.3]=man3/X509_cmp_time.pod
 DEPEND[html/man3/X509_digest.html]=man3/X509_digest.pod
 GENERATE[html/man3/X509_digest.html]=man3/X509_digest.pod
 DEPEND[man/man3/X509_digest.3]=man3/X509_digest.pod
@@ -3173,8 +3177,6 @@ DEPEND[man/man3/s2i_ASN1_IA5STRING.3]=man3/s2i_ASN1_IA5STRING.pod
 GENERATE[man/man3/s2i_ASN1_IA5STRING.3]=man3/s2i_ASN1_IA5STRING.pod
 IMAGEDOCS[man3]=
 HTMLDOCS[man3]=html/man3/ADMISSIONS.html \
-html/man3/ASN1_BIT_STRING_get_length.html \
-html/man3/ASN1_BIT_STRING_new.html \
 html/man3/ASN1_EXTERN_FUNCS.html \
 html/man3/ASN1_INTEGER_get_int64.html \
 html/man3/ASN1_INTEGER_new.html \
@@ -3230,7 +3232,6 @@ html/man3/BIO_s_null.html \
 html/man3/BIO_s_socket.html \
 html/man3/BIO_sendmmsg.html \
 html/man3/BIO_set_callback.html \
-html/man3/BIO_set_flags.html \
 html/man3/BIO_should_retry.html \
 html/man3/BIO_socket_wait.html \
 html/man3/BN_BLINDING_new.html \
@@ -3335,16 +3336,16 @@ html/man3/ERR_load_strings.html \
 html/man3/ERR_new.html \
 html/man3/ERR_print_errors.html \
 html/man3/ERR_put_error.html \
+html/man3/ERR_remove_state.html \
 html/man3/ERR_set_mark.html \
 html/man3/EVP_ASYM_CIPHER_free.html \
 html/man3/EVP_BytesToKey.html \
-html/man3/EVP_CIPHER_CTX_get_app_data.html \
 html/man3/EVP_CIPHER_CTX_get_cipher_data.html \
 html/man3/EVP_CIPHER_CTX_get_original_iv.html \
+html/man3/EVP_CIPHER_meth_new.html \
 html/man3/EVP_DigestInit.html \
 html/man3/EVP_DigestSignInit.html \
 html/man3/EVP_DigestVerifyInit.html \
-html/man3/EVP_EC_gen.html \
 html/man3/EVP_EncodeInit.html \
 html/man3/EVP_EncryptInit.html \
 html/man3/EVP_KDF.html \
@@ -3352,9 +3353,11 @@ html/man3/EVP_KEM_free.html \
 html/man3/EVP_KEYEXCH_free.html \
 html/man3/EVP_KEYMGMT.html \
 html/man3/EVP_MAC.html \
+html/man3/EVP_MD_meth_new.html \
 html/man3/EVP_OpenInit.html \
 html/man3/EVP_PBE_CipherInit.html \
 html/man3/EVP_PKEY2PKCS8.html \
+html/man3/EVP_PKEY_ASN1_METHOD.html \
 html/man3/EVP_PKEY_CTX_ctrl.html \
 html/man3/EVP_PKEY_CTX_get0_libctx.html \
 html/man3/EVP_PKEY_CTX_get0_pkey.html \
@@ -3366,6 +3369,7 @@ html/man3/EVP_PKEY_CTX_set_params.html \
 html/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_md.html \
 html/man3/EVP_PKEY_CTX_set_scrypt_N.html \
 html/man3/EVP_PKEY_CTX_set_tls1_prf_md.html \
+html/man3/EVP_PKEY_asn1_get_count.html \
 html/man3/EVP_PKEY_check.html \
 html/man3/EVP_PKEY_copy_parameters.html \
 html/man3/EVP_PKEY_decapsulate.html \
@@ -3383,6 +3387,8 @@ html/man3/EVP_PKEY_get_size.html \
 html/man3/EVP_PKEY_gettable_params.html \
 html/man3/EVP_PKEY_is_a.html \
 html/man3/EVP_PKEY_keygen.html \
+html/man3/EVP_PKEY_meth_get_count.html \
+html/man3/EVP_PKEY_meth_new.html \
 html/man3/EVP_PKEY_new.html \
 html/man3/EVP_PKEY_print_private.html \
 html/man3/EVP_PKEY_set1_RSA.html \
@@ -3430,7 +3436,6 @@ html/man3/GENERAL_NAME.html \
 html/man3/HMAC.html \
 html/man3/MD5.html \
 html/man3/MDC2_Init.html \
-html/man3/NAME_CONSTRAINTS_check.html \
 html/man3/NCONF_new_ex.html \
 html/man3/OBJ_nid2obj.html \
 html/man3/OCSP_REQUEST_new.html \
@@ -3749,7 +3754,6 @@ html/man3/SSL_read.html \
 html/man3/SSL_read_early_data.html \
 html/man3/SSL_rstate_string.html \
 html/man3/SSL_session_reused.html \
-html/man3/SSL_set1_echstore.html \
 html/man3/SSL_set1_host.html \
 html/man3/SSL_set1_initial_peer_addr.html \
 html/man3/SSL_set1_server_cert_type.html \
@@ -3778,7 +3782,6 @@ html/man3/UI_STRING.html \
 html/man3/UI_UTIL_read_pw.html \
 html/man3/UI_create_method.html \
 html/man3/UI_new.html \
-html/man3/X509V3_EXT_print.html \
 html/man3/X509V3_get_d2i.html \
 html/man3/X509V3_set_ctx.html \
 html/man3/X509_ACERT_add1_attr.html \
@@ -3813,12 +3816,12 @@ html/man3/X509_STORE_set_verify_cb_func.html \
 html/man3/X509_VERIFY_PARAM_set_flags.html \
 html/man3/X509_add_cert.html \
 html/man3/X509_check_ca.html \
-html/man3/X509_check_certificate_times.html \
 html/man3/X509_check_host.html \
 html/man3/X509_check_issued.html \
 html/man3/X509_check_private_key.html \
 html/man3/X509_check_purpose.html \
 html/man3/X509_cmp.html \
+html/man3/X509_cmp_time.html \
 html/man3/X509_digest.html \
 html/man3/X509_dup.html \
 html/man3/X509_get0_distinguishing_id.html \
@@ -3849,8 +3852,6 @@ html/man3/i2d_re_X509_tbs.html \
 html/man3/o2i_SCT_LIST.html \
 html/man3/s2i_ASN1_IA5STRING.html
 MANDOCS[man3]=man/man3/ADMISSIONS.3 \
-man/man3/ASN1_BIT_STRING_get_length.3 \
-man/man3/ASN1_BIT_STRING_new.3 \
 man/man3/ASN1_EXTERN_FUNCS.3 \
 man/man3/ASN1_INTEGER_get_int64.3 \
 man/man3/ASN1_INTEGER_new.3 \
@@ -3906,7 +3907,6 @@ man/man3/BIO_s_null.3 \
 man/man3/BIO_s_socket.3 \
 man/man3/BIO_sendmmsg.3 \
 man/man3/BIO_set_callback.3 \
-man/man3/BIO_set_flags.3 \
 man/man3/BIO_should_retry.3 \
 man/man3/BIO_socket_wait.3 \
 man/man3/BN_BLINDING_new.3 \
@@ -4011,16 +4011,16 @@ man/man3/ERR_load_strings.3 \
 man/man3/ERR_new.3 \
 man/man3/ERR_print_errors.3 \
 man/man3/ERR_put_error.3 \
+man/man3/ERR_remove_state.3 \
 man/man3/ERR_set_mark.3 \
 man/man3/EVP_ASYM_CIPHER_free.3 \
 man/man3/EVP_BytesToKey.3 \
-man/man3/EVP_CIPHER_CTX_get_app_data.3 \
 man/man3/EVP_CIPHER_CTX_get_cipher_data.3 \
 man/man3/EVP_CIPHER_CTX_get_original_iv.3 \
+man/man3/EVP_CIPHER_meth_new.3 \
 man/man3/EVP_DigestInit.3 \
 man/man3/EVP_DigestSignInit.3 \
 man/man3/EVP_DigestVerifyInit.3 \
-man/man3/EVP_EC_gen.3 \
 man/man3/EVP_EncodeInit.3 \
 man/man3/EVP_EncryptInit.3 \
 man/man3/EVP_KDF.3 \
@@ -4028,9 +4028,11 @@ man/man3/EVP_KEM_free.3 \
 man/man3/EVP_KEYEXCH_free.3 \
 man/man3/EVP_KEYMGMT.3 \
 man/man3/EVP_MAC.3 \
+man/man3/EVP_MD_meth_new.3 \
 man/man3/EVP_OpenInit.3 \
 man/man3/EVP_PBE_CipherInit.3 \
 man/man3/EVP_PKEY2PKCS8.3 \
+man/man3/EVP_PKEY_ASN1_METHOD.3 \
 man/man3/EVP_PKEY_CTX_ctrl.3 \
 man/man3/EVP_PKEY_CTX_get0_libctx.3 \
 man/man3/EVP_PKEY_CTX_get0_pkey.3 \
@@ -4042,6 +4044,7 @@ man/man3/EVP_PKEY_CTX_set_params.3 \
 man/man3/EVP_PKEY_CTX_set_rsa_pss_keygen_md.3 \
 man/man3/EVP_PKEY_CTX_set_scrypt_N.3 \
 man/man3/EVP_PKEY_CTX_set_tls1_prf_md.3 \
+man/man3/EVP_PKEY_asn1_get_count.3 \
 man/man3/EVP_PKEY_check.3 \
 man/man3/EVP_PKEY_copy_parameters.3 \
 man/man3/EVP_PKEY_decapsulate.3 \
@@ -4059,6 +4062,8 @@ man/man3/EVP_PKEY_get_size.3 \
 man/man3/EVP_PKEY_gettable_params.3 \
 man/man3/EVP_PKEY_is_a.3 \
 man/man3/EVP_PKEY_keygen.3 \
+man/man3/EVP_PKEY_meth_get_count.3 \
+man/man3/EVP_PKEY_meth_new.3 \
 man/man3/EVP_PKEY_new.3 \
 man/man3/EVP_PKEY_print_private.3 \
 man/man3/EVP_PKEY_set1_RSA.3 \
@@ -4106,7 +4111,6 @@ man/man3/GENERAL_NAME.3 \
 man/man3/HMAC.3 \
 man/man3/MD5.3 \
 man/man3/MDC2_Init.3 \
-man/man3/NAME_CONSTRAINTS_check.3 \
 man/man3/NCONF_new_ex.3 \
 man/man3/OBJ_nid2obj.3 \
 man/man3/OCSP_REQUEST_new.3 \
@@ -4425,7 +4429,6 @@ man/man3/SSL_read.3 \
 man/man3/SSL_read_early_data.3 \
 man/man3/SSL_rstate_string.3 \
 man/man3/SSL_session_reused.3 \
-man/man3/SSL_set1_echstore.3 \
 man/man3/SSL_set1_host.3 \
 man/man3/SSL_set1_initial_peer_addr.3 \
 man/man3/SSL_set1_server_cert_type.3 \
@@ -4454,7 +4457,6 @@ man/man3/UI_STRING.3 \
 man/man3/UI_UTIL_read_pw.3 \
 man/man3/UI_create_method.3 \
 man/man3/UI_new.3 \
-man/man3/X509V3_EXT_print.3 \
 man/man3/X509V3_get_d2i.3 \
 man/man3/X509V3_set_ctx.3 \
 man/man3/X509_ACERT_add1_attr.3 \
@@ -4489,12 +4491,12 @@ man/man3/X509_STORE_set_verify_cb_func.3 \
 man/man3/X509_VERIFY_PARAM_set_flags.3 \
 man/man3/X509_add_cert.3 \
 man/man3/X509_check_ca.3 \
-man/man3/X509_check_certificate_times.3 \
 man/man3/X509_check_host.3 \
 man/man3/X509_check_issued.3 \
 man/man3/X509_check_private_key.3 \
 man/man3/X509_check_purpose.3 \
 man/man3/X509_cmp.3 \
+man/man3/X509_cmp_time.3 \
 man/man3/X509_digest.3 \
 man/man3/X509_dup.3 \
 man/man3/X509_get0_distinguishing_id.3 \
@@ -4619,10 +4621,6 @@ DEPEND[html/man7/EVP_KDF-HMAC-DRBG.html]=man7/EVP_KDF-HMAC-DRBG.pod
 GENERATE[html/man7/EVP_KDF-HMAC-DRBG.html]=man7/EVP_KDF-HMAC-DRBG.pod
 DEPEND[man/man7/EVP_KDF-HMAC-DRBG.7]=man7/EVP_KDF-HMAC-DRBG.pod
 GENERATE[man/man7/EVP_KDF-HMAC-DRBG.7]=man7/EVP_KDF-HMAC-DRBG.pod
-DEPEND[html/man7/EVP_KDF-IKEV2KDF.html]=man7/EVP_KDF-IKEV2KDF.pod
-GENERATE[html/man7/EVP_KDF-IKEV2KDF.html]=man7/EVP_KDF-IKEV2KDF.pod
-DEPEND[man/man7/EVP_KDF-IKEV2KDF.7]=man7/EVP_KDF-IKEV2KDF.pod
-GENERATE[man/man7/EVP_KDF-IKEV2KDF.7]=man7/EVP_KDF-IKEV2KDF.pod
 DEPEND[html/man7/EVP_KDF-KB.html]=man7/EVP_KDF-KB.pod
 GENERATE[html/man7/EVP_KDF-KB.html]=man7/EVP_KDF-KB.pod
 DEPEND[man/man7/EVP_KDF-KB.7]=man7/EVP_KDF-KB.pod
@@ -4655,10 +4653,6 @@ DEPEND[html/man7/EVP_KDF-SNMPKDF.html]=man7/EVP_KDF-SNMPKDF.pod
 GENERATE[html/man7/EVP_KDF-SNMPKDF.html]=man7/EVP_KDF-SNMPKDF.pod
 DEPEND[man/man7/EVP_KDF-SNMPKDF.7]=man7/EVP_KDF-SNMPKDF.pod
 GENERATE[man/man7/EVP_KDF-SNMPKDF.7]=man7/EVP_KDF-SNMPKDF.pod
-DEPEND[html/man7/EVP_KDF-SRTPKDF.html]=man7/EVP_KDF-SRTPKDF.pod
-GENERATE[html/man7/EVP_KDF-SRTPKDF.html]=man7/EVP_KDF-SRTPKDF.pod
-DEPEND[man/man7/EVP_KDF-SRTPKDF.7]=man7/EVP_KDF-SRTPKDF.pod
-GENERATE[man/man7/EVP_KDF-SRTPKDF.7]=man7/EVP_KDF-SRTPKDF.pod
 DEPEND[html/man7/EVP_KDF-SS.html]=man7/EVP_KDF-SS.pod
 GENERATE[html/man7/EVP_KDF-SS.html]=man7/EVP_KDF-SS.pod
 DEPEND[man/man7/EVP_KDF-SS.7]=man7/EVP_KDF-SS.pod
@@ -4771,10 +4765,6 @@ DEPEND[html/man7/EVP_MD-MDC2.html]=man7/EVP_MD-MDC2.pod
 GENERATE[html/man7/EVP_MD-MDC2.html]=man7/EVP_MD-MDC2.pod
 DEPEND[man/man7/EVP_MD-MDC2.7]=man7/EVP_MD-MDC2.pod
 GENERATE[man/man7/EVP_MD-MDC2.7]=man7/EVP_MD-MDC2.pod
-DEPEND[html/man7/EVP_MD-ML-DSA-MU.html]=man7/EVP_MD-ML-DSA-MU.pod
-GENERATE[html/man7/EVP_MD-ML-DSA-MU.html]=man7/EVP_MD-ML-DSA-MU.pod
-DEPEND[man/man7/EVP_MD-ML-DSA-MU.7]=man7/EVP_MD-ML-DSA-MU.pod
-GENERATE[man/man7/EVP_MD-ML-DSA-MU.7]=man7/EVP_MD-ML-DSA-MU.pod
 DEPEND[html/man7/EVP_MD-NULL.html]=man7/EVP_MD-NULL.pod
 GENERATE[html/man7/EVP_MD-NULL.html]=man7/EVP_MD-NULL.pod
 DEPEND[man/man7/EVP_MD-NULL.7]=man7/EVP_MD-NULL.pod
@@ -4843,10 +4833,6 @@ DEPEND[html/man7/EVP_PKEY-ML-KEM.html]=man7/EVP_PKEY-ML-KEM.pod
 GENERATE[html/man7/EVP_PKEY-ML-KEM.html]=man7/EVP_PKEY-ML-KEM.pod
 DEPEND[man/man7/EVP_PKEY-ML-KEM.7]=man7/EVP_PKEY-ML-KEM.pod
 GENERATE[man/man7/EVP_PKEY-ML-KEM.7]=man7/EVP_PKEY-ML-KEM.pod
-DEPEND[html/man7/EVP_PKEY-MLX-KEM.html]=man7/EVP_PKEY-MLX-KEM.pod
-GENERATE[html/man7/EVP_PKEY-MLX-KEM.html]=man7/EVP_PKEY-MLX-KEM.pod
-DEPEND[man/man7/EVP_PKEY-MLX-KEM.7]=man7/EVP_PKEY-MLX-KEM.pod
-GENERATE[man/man7/EVP_PKEY-MLX-KEM.7]=man7/EVP_PKEY-MLX-KEM.pod
 DEPEND[html/man7/EVP_PKEY-RSA.html]=man7/EVP_PKEY-RSA.pod
 GENERATE[html/man7/EVP_PKEY-RSA.html]=man7/EVP_PKEY-RSA.pod
 DEPEND[man/man7/EVP_PKEY-RSA.7]=man7/EVP_PKEY-RSA.pod
@@ -4927,10 +4913,6 @@ DEPEND[html/man7/EVP_SIGNATURE-SLH-DSA.html]=man7/EVP_SIGNATURE-SLH-DSA.pod
 GENERATE[html/man7/EVP_SIGNATURE-SLH-DSA.html]=man7/EVP_SIGNATURE-SLH-DSA.pod
 DEPEND[man/man7/EVP_SIGNATURE-SLH-DSA.7]=man7/EVP_SIGNATURE-SLH-DSA.pod
 GENERATE[man/man7/EVP_SIGNATURE-SLH-DSA.7]=man7/EVP_SIGNATURE-SLH-DSA.pod
-DEPEND[html/man7/EVP_SIGNATURE-SM2.html]=man7/EVP_SIGNATURE-SM2.pod
-GENERATE[html/man7/EVP_SIGNATURE-SM2.html]=man7/EVP_SIGNATURE-SM2.pod
-DEPEND[man/man7/EVP_SIGNATURE-SM2.7]=man7/EVP_SIGNATURE-SM2.pod
-GENERATE[man/man7/EVP_SIGNATURE-SM2.7]=man7/EVP_SIGNATURE-SM2.pod
 DEPEND[html/man7/OSSL_PROVIDER-FIPS.html]=man7/OSSL_PROVIDER-FIPS.pod
 GENERATE[html/man7/OSSL_PROVIDER-FIPS.html]=man7/OSSL_PROVIDER-FIPS.pod
 DEPEND[man/man7/OSSL_PROVIDER-FIPS.7]=man7/OSSL_PROVIDER-FIPS.pod
@@ -5234,7 +5216,6 @@ html/man7/EVP_CIPHER-SM4.html \
 html/man7/EVP_KDF-ARGON2.html \
 html/man7/EVP_KDF-HKDF.html \
 html/man7/EVP_KDF-HMAC-DRBG.html \
-html/man7/EVP_KDF-IKEV2KDF.html \
 html/man7/EVP_KDF-KB.html \
 html/man7/EVP_KDF-KRB5KDF.html \
 html/man7/EVP_KDF-PBKDF1.html \
@@ -5243,7 +5224,6 @@ html/man7/EVP_KDF-PKCS12KDF.html \
 html/man7/EVP_KDF-PVKKDF.html \
 html/man7/EVP_KDF-SCRYPT.html \
 html/man7/EVP_KDF-SNMPKDF.html \
-html/man7/EVP_KDF-SRTPKDF.html \
 html/man7/EVP_KDF-SS.html \
 html/man7/EVP_KDF-SSHKDF.html \
 html/man7/EVP_KDF-TLS13_KDF.html \
@@ -5272,7 +5252,6 @@ html/man7/EVP_MD-MD4.html \
 html/man7/EVP_MD-MD5-SHA1.html \
 html/man7/EVP_MD-MD5.html \
 html/man7/EVP_MD-MDC2.html \
-html/man7/EVP_MD-ML-DSA-MU.html \
 html/man7/EVP_MD-NULL.html \
 html/man7/EVP_MD-RIPEMD160.html \
 html/man7/EVP_MD-SHA1.html \
@@ -5290,7 +5269,6 @@ html/man7/EVP_PKEY-HMAC.html \
 html/man7/EVP_PKEY-LMS.html \
 html/man7/EVP_PKEY-ML-DSA.html \
 html/man7/EVP_PKEY-ML-KEM.html \
-html/man7/EVP_PKEY-MLX-KEM.html \
 html/man7/EVP_PKEY-RSA.html \
 html/man7/EVP_PKEY-SLH-DSA.html \
 html/man7/EVP_PKEY-SM2.html \
@@ -5311,7 +5289,6 @@ html/man7/EVP_SIGNATURE-LMS.html \
 html/man7/EVP_SIGNATURE-ML-DSA.html \
 html/man7/EVP_SIGNATURE-RSA.html \
 html/man7/EVP_SIGNATURE-SLH-DSA.html \
-html/man7/EVP_SIGNATURE-SM2.html \
 html/man7/OSSL_PROVIDER-FIPS.html \
 html/man7/OSSL_PROVIDER-base.html \
 html/man7/OSSL_PROVIDER-default.html \
@@ -5400,7 +5377,6 @@ man/man7/EVP_CIPHER-SM4.7 \
 man/man7/EVP_KDF-ARGON2.7 \
 man/man7/EVP_KDF-HKDF.7 \
 man/man7/EVP_KDF-HMAC-DRBG.7 \
-man/man7/EVP_KDF-IKEV2KDF.7 \
 man/man7/EVP_KDF-KB.7 \
 man/man7/EVP_KDF-KRB5KDF.7 \
 man/man7/EVP_KDF-PBKDF1.7 \
@@ -5409,7 +5385,6 @@ man/man7/EVP_KDF-PKCS12KDF.7 \
 man/man7/EVP_KDF-PVKKDF.7 \
 man/man7/EVP_KDF-SCRYPT.7 \
 man/man7/EVP_KDF-SNMPKDF.7 \
-man/man7/EVP_KDF-SRTPKDF.7 \
 man/man7/EVP_KDF-SS.7 \
 man/man7/EVP_KDF-SSHKDF.7 \
 man/man7/EVP_KDF-TLS13_KDF.7 \
@@ -5438,7 +5413,6 @@ man/man7/EVP_MD-MD4.7 \
 man/man7/EVP_MD-MD5-SHA1.7 \
 man/man7/EVP_MD-MD5.7 \
 man/man7/EVP_MD-MDC2.7 \
-man/man7/EVP_MD-ML-DSA-MU.7 \
 man/man7/EVP_MD-NULL.7 \
 man/man7/EVP_MD-RIPEMD160.7 \
 man/man7/EVP_MD-SHA1.7 \
@@ -5456,7 +5430,6 @@ man/man7/EVP_PKEY-HMAC.7 \
 man/man7/EVP_PKEY-LMS.7 \
 man/man7/EVP_PKEY-ML-DSA.7 \
 man/man7/EVP_PKEY-ML-KEM.7 \
-man/man7/EVP_PKEY-MLX-KEM.7 \
 man/man7/EVP_PKEY-RSA.7 \
 man/man7/EVP_PKEY-SLH-DSA.7 \
 man/man7/EVP_PKEY-SM2.7 \
@@ -5477,7 +5450,6 @@ man/man7/EVP_SIGNATURE-LMS.7 \
 man/man7/EVP_SIGNATURE-ML-DSA.7 \
 man/man7/EVP_SIGNATURE-RSA.7 \
 man/man7/EVP_SIGNATURE-SLH-DSA.7 \
-man/man7/EVP_SIGNATURE-SM2.7 \
 man/man7/OSSL_PROVIDER-FIPS.7 \
 man/man7/OSSL_PROVIDER-base.7 \
 man/man7/OSSL_PROVIDER-default.7 \
diff --git a/doc/designs/ech-api.md b/doc/designs/ech-api.md
deleted file mode 100644
index fe452ef4d6..0000000000
--- a/doc/designs/ech-api.md
+++ /dev/null
@@ -1,667 +0,0 @@
-Encrypted ClientHello (ECH) APIs
-================================
-
-OpenSSL 4.0 includes an implementation of Encrypted Client Hello (ECH), as
-specified in RFC 9849. These are design notes for the APIs implemented for ECH.
-
-The ECH Protocol
-----------------
-
-ECH involves creating an "inner" ClientHello (CH) that contains the potentially
-sensitive content of a CH, primarily the SNI and perhaps the ALPN values. That
-inner CH is then encrypted and embedded (as a CH extension) in an outer CH that
-contains presumably less sensitive values. The spec includes a "compression"
-scheme that allows the inner CH to refer to extensions from the outer CH where
-the same value would otherwise be present in both.
-
-ECH makes use of [HPKE](https://datatracker.ietf.org/doc/rfc9180/) for the
-encryption of the inner CH. HPKE code was merged to the master branch in
-November 2022.
-
-The ECH APIs are documented
-[here](../../doc/man3/SSL_set1_echstore.pod)
-The descriptions here are less formal and provide some justification for the
-API design.
-
-Unless otherwise stated all APIs return 1 in the case of success and 0 for
-error. All APIs call `SSLfatal` or `ERR_raise` macros as appropriate before
-returning an error.
-
-Prototypes are mostly in
-[`include/openssl/ech.h`](../../include/openssl/ech.h).
-
-General Approach
-----------------
-
-This ECH implementation was prototyped via integrations with curl, apache2,
-lighttpd, nginx, freenginx and HAProxy. The implementation interoperates with all other
-known ECH implementations, including browsers, the libraries they use
-(NSS/BoringSSL), a closed-source server implementation (Cloudflare's test
-server) and with wolfSSL and Rustls.
-
-The approach taken has been to minimise the application layer code
-changes required to ECH-enable those applications. There is of course a tension
-between that minimisation goal and providing generic and future-proof
-interfaces.
-
-ECH Specification
------------------
-
-RFC 9849 is an IETF TLS WG specification. It has been stable since
-[draft-13](https://datatracker.ietf.org/doc/draft-ietf-tls-esni/13/), published
-in August 2021.
-
-The only current ECHConfig version defined is 0xfe0d which is the value used in
-RFC 9849.
-
-```c
-/* version from RFC 9849 */
-#  define OSSL_ECH_RFC9849_VERSION 0xfe0d
-/* latest version from an RFC */
-#  define OSSL_ECH_CURRENT_VERSION OSSL_ECH_RFC9849_VERSION
-```
-
-Note that 0xfe0d is also the value of the ECH extension codepoint:
-
-```c
-#  define TLSEXT_TYPE_ech                       0xfe0d
-```
-
-The uses of those should be correctly differentiated in the implementation, to
-more easily avoid problems if/when new versions are defined.
-
-ECH PEM file format
--------------------
-
-Servers supporting ECH need to read a set of ECH private keys and
-ECHConfigLists from storage. There is a specification for a
-[PEM file format for ECH](https://datatracker.ietf.org/doc/rfc9934)
-that is supported by the library.
-
-This PEM file format is supported by code for a number of TLS servers,
-including (at the time of writing) lighttpd, freenginx, nginx, apache2 and HAProxy.
-ECH support in those servers is currently an experimental feature or similar.
-
-Minimal Sample Code
--------------------
-
-OpenSSL includes code for an [`sslecho`](../../demos/sslecho) demo.  We've
-added a minimal [`echecho`](../../demos/sslecho/echecho.c) that shows how to
-ECH-enable this demo.
-
-Handling Custom Extensions
---------------------------
-
-OpenSSL supports custom extensions (via `SSL_CTX_add_custom_ext()`) so that
-extension values are supplied and parsed by client and server applications via
-a callback.  The ECH specification of course doesn't deal with such
-implementation matters, but comprehensive ECH support for such custom
-extensions could quickly become complex. At present, in the absence of evidence
-of sensitive custom extension values, we handle all such extensions by using
-the ECH compression mechanism.  That means we require no API changes, only make
-one call to the application callbacks and get interoperability, but that such
-extension values remain visible to network observers. That could change if some
-custom value turns out to be sensitive such that we'd prefer to not include it
-in the outer CH.
-
-Padding
--------
-
-The privacy protection provided by ECH benefits from an observer not being able
-to differentiate access to different web origins based on TLS handshake
-packets. Some TLS handshake messages can however reduce the size of the
-anonymity-set due to message-sizes. In particular the Certificate message size
-will depend on the name of the SNI from the inner ClientHello. TLS however does
-allow for record layer padding which can reduce the impact of underlying
-message sizes on the size of the anonymity set. The
-`SSL_CTX_record_padding_ex()` and `SSL_record_padding_ex()` APIs allow for
-setting separate padding sizes for the handshake messages, (that most affect
-ECH), and application data messages (where padding may affect efficiency more).
-
-ECHConfig Extensions
---------------------
-
-The ECH protocol supports extensibility within the ECHConfig structure
-via a typical TLS type, length, value scheme.  However, to date, there are no
-extensions defined, nor do other implementations provide APIs for adding or
-manipulating ECHConfig extensions. We therefore take the same approach here.
-
-When running the ECH protocol, implementations are required to skip over
-unknown ECHConfig extensions, or to fail for so-called "mandatory" unsupported
-ECHConfig extensions. Our library code is compliant in that respect - it will
-skip over extensions that are not "mandatory" (extension type high bit clear)
-and fail if any "mandatory" ECHConfig extension (extension type high bit set)
-is seen.
-
-For testing purposes, ECHConfigList values that contain ECHConfig extensions
-can be produced using external scripts, and used with the library, but there is
-no API support for generating such, and the library has no support for any
-specific ECHConfig extension type.  (Other than skipping over or failing as
-described above.)
-
-In general, the ECHConfig extensibility mechanism seems to have little proven
-utility. (If new fields for an ECHConfig are required, a new ECHConfig version
-with the proposed changes could just as easily be developed/deployed.)
-
-The theory for ECHConfig extensions is that such values might be used to
-control the outer ClientHello - controls to affect the inner ClientHello, when
-ECH is used, are envisaged to be published as SvcParamKey values in SVCB/HTTP
-resource records in the DNS.
-
-Should some useful ECHConfig extensions be defined in future, then the
-`OSSL_ECHSTORE` APIs could be extended to enable management of such, or, new
-opaque types could be developed enabling further manipulation of ECHConfig and
-ECHConfigList values.
-
-ECH keys versus TLS server keys
--------------------------------
-
-ECH private keys are similar to, but different from, TLS server private keys
-used to authenticate servers. Notably:
-
-- ECH private keys are expected to be rotated roughly hourly, rather than every
-  month or two for TLS server private keys. Hourly ECH key rotation is an
-  attempt to provide better forward secrecy, given ECH implements an
-  ephemeral-static ECDH scheme.
-
-- ECH private keys stand alone - there are no hierarchies and there is no
-  chaining, and no certificates and no defined relationships between current
-  and older ECH private keys. The expectation is that a "current" ECH public key
-  will be published in the DNS and that plus approx. 2 "older" ECH private keys
-  will remain usable for decryption at any given time. This is a way to balance
-  DNS TTLs versus forward secrecy and robustness.
-
-- In particular, the above means that we do not see any need to repeatedly
-  parse or process related ECHConfigList structures - each can be processed
-  independently for all practical purposes, and there is no equivalent to
-  X.509 path processing.
-
-- There are all the usual algorithm variations, and those will likely result in
-  the same x25519 versus p256 combinatorics. How that plays out has yet to be
-  seen as FIPS compliance for ECH is not (yet) a thing. For OpenSSL, it seems
-  wise to be agnostic and support all relevant combinations. (And doing so is not
-  that hard.)
-
-- At the time of writing there is work ongoing to specify use of post-quantum
-  KEMs with HPKE. Once that work matures, and the relevant (hybrid) KEMs are
-  supported by OpenSSL, then they should be usable with ECH. It is quite likely
-  at least some test code will need changes due to the increase in the size
-  of the ECH extension. For now, there is no support for e.g. use of an
-  equivalent to X25519MLKEM768 for ECH encryption. ECH does work fine if
-  X25519MLKEM768 is used for the TLS key exchange.
-
-ECH Store APIs
---------------
-
-We introduce an externally opaque type `OSSL_ECHSTORE` to allow applications
-to create and manage ECHConfigList values and associated meta-data. The
-external APIs using `OSSL_ECHSTORE` are:
-
-```c
-typedef struct ossl_echstore_st OSSL_ECHSTORE;
-
-/* if a caller wants to index the last entry in the store */
-# define OSSL_ECHSTORE_LAST -1
-/* if a caller wants all entries in the store, e.g. to print public values */
-#  define OSSL_ECHSTORE_ALL -2
-
-OSSL_ECHSTORE *OSSL_ECHSTORE_new(OSSL_LIB_CTX *libctx, const char *propq);
-void OSSL_ECHSTORE_free(OSSL_ECHSTORE *es);
-int OSSL_ECHSTORE_new_config(OSSL_ECHSTORE *es,
-                             uint16_t echversion, uint8_t max_name_length,
-                             const char *public_name, OSSL_HPKE_SUITE suite);
-int OSSL_ECHSTORE_write_pem(OSSL_ECHSTORE *es, int index, BIO *out);
-
-int OSSL_ECHSTORE_read_echconfiglist(OSSL_ECHSTORE *es, BIO *in);
-
-int OSSL_ECHSTORE_get1_info(OSSL_ECHSTORE *es, int index, time_t *loaded_secs,
-                            char **public_name, char **echconfig,
-                            int *has_private, int *for_retry);
-int OSSL_ECHSTORE_downselect(OSSL_ECHSTORE *es, int index);
-
-int OSSL_ECHSTORE_set1_key_and_read_pem(OSSL_ECHSTORE *es, EVP_PKEY *priv,
-                                        BIO *in, int for_retry);
-int OSSL_ECHSTORE_read_pem(OSSL_ECHSTORE *es, BIO *in, int for_retry);
-int OSSL_ECHSTORE_num_entries(OSSL_ECHSTORE *es, int *numentries);
-int OSSL_ECHSTORE_num_keys(OSSL_ECHSTORE *es, int *numkeys);
-int OSSL_ECHSTORE_flush_keys(OSSL_ECHSTORE *es, time_t age);
-```
-
-`OSSL_ECHSTORE_new()` and `OSSL_ECHSTORE_free()` are relatively obvious.
-
-`OSSL_ECHSTORE_new_config()` allows the caller to create a new private key
-value and the related "singleton" ECHConfigList structure.
-`OSSL_ECHSTORE_write_pem()` allows the caller to produce a "PEM" data
-structure (conforming to the ECH PEM file format)
-from the `OSSL_ECHSTORE` entry identified by the `index`. (An `index` of
-`OSSL_ECHSTORE_LAST` will select the last entry. An `index` of
-`OSSL_ECHSTORE_ALL` will output all public values, and no private values.)
-These two APIs will typically be used via the `openssl ech` command line tool.
-
-`OSSL_ECHSTORE_read_echconfiglist()` will typically be used by a client to
-ingest the "ech=" SvcParamKey value found in an SVCB or HTTPS RR retrieved from
-the DNS. The resulting set of ECHConfig values can then be associated with an
-`SSL_CTX` or `SSL` structure for TLS connections.
-
-`OSSL_ECHSTORE_get1_info()` presents the caller with information about the
-content of the store for logging or for display, e.g. in a command line tool.
-`OSSL_ECHSTORE_downselect()` API gives the client a way to select one
-particular ECHConfig value from the set stored (discarding the rest).
-
-`OSSL_ECHSTORE_set1_key_and_read_pem()` and `OSSL_ECHSTORE_read_pem()` can be
-used to load a private key value and associated "singleton" ECHConfigList.
-Those can be used (by servers) to enable ECH for an `SSL_CTX` or `SSL`
-connection. In addition to loading those values, the application can also
-indicate via `for_retry` which ECHConfig value(s) are to be included in the
-`retry_configs` fallback scheme defined by the ECH protocol.
-
-`OSSL_ECHSTORE_num_entries()` and `OSSL_ECHSTORE_num_keys()` allow an
-application  to see how many usable ECH configs and private keys are currently
-in the store, and `OSSL_ECHSTORE_flush_keys()` allows a server to flush keys
-that are older than `age` seconds.  The general model is that a server can
-maintain an `OSSL_ECHSTORE` into which it periodically loads the "latest" set
-of keys, e.g.  hourly, and also discards the keys that are too old, e.g. more
-than 3 hours old. This allows for more robust private key management even if
-public key distribution suffers temporary failures.
-
-The APIs the clients and servers can use to associate an `OSSL_ECHSTORE`
-with an `SSL_CTX` or `SSL` structure:
-
-```c
-int SSL_CTX_set1_echstore(SSL_CTX *ctx, OSSL_ECHSTORE *es);
-int SSL_set1_echstore(SSL *s, OSSL_ECHSTORE *es);
-```
-
-ECH will be enabled for the relevant `SSL_CTX` or `SSL` connection
-when these functions succeed. Any previously associated `OSSL_ECHSTORE`
-will be `OSSL_ECHSTORE_free()`ed.
-
-There is also an API that allows setting an ECHConfigList for an SSL
-connection, that is compatible with BoringSSL, leading to smaller code changes
-for clients that support OpenSSL or BoringSSL. Note that the input `ecl` here
-for OpenSSL can be either base64 or binary encoded, but for BoringSSL it must
-be binary encoded.
-
-```c
-int SSL_set1_ech_config_list(SSL *ssl, const uint8_t *ecl, size_t ecl_len);
-```
-
-To access the `OSSL_ECHSTORE` associated with an `SSL_CTX` or
-`SSL` connection:
-
-```c
-OSSL_ECHSTORE *SSL_CTX_get1_echstore(const SSL_CTX *ctx);
-OSSL_ECHSTORE *SSL_get1_echstore(const SSL *s);
-```
-
-The resulting `OSSL_ECHSTORE` can be modified and then re-associated
-with an `SSL_CTX` or `SSL` connection.
-
-ECH Store Internals
--------------------
-
-The internal structure of an ECH Store is as described below:
-
-```c
-typedef struct ossl_echext_st {
-    uint16_t type;
-    uint16_t len;
-    unsigned char *val;
-} OSSL_ECHEXT;
-
-DEFINE_STACK_OF(OSSL_ECHEXT)
-
-typedef struct ossl_echstore_entry_st {
-    uint16_t version; /* 0xfe0d for RFC 9849 */
-    char *public_name;
-    size_t pub_len;
-    unsigned char *pub;
-    unsigned int nsuites;
-    OSSL_HPKE_SUITE *suites;
-    uint8_t max_name_length;
-    uint8_t config_id;
-    STACK_OF(OSSL_ECHEXT) *exts;
-    time_t loadtime; /* time public and private key were loaded from file */
-    EVP_PKEY *keyshare; /* long(ish) term ECH private keyshare on a server */
-    int for_retry; /* whether to use this ECHConfigList in a retry */
-    size_t encoded_len; /* length of overall encoded content */
-    unsigned char *encoded; /* overall encoded content */
-} OSSL_ECHSTORE_ENTRY;
-
-DEFINE_STACK_OF(OSSL_ECHSTORE_ENTRY)
-
-struct ossl_echstore_st {
-    STACK_OF(OSSL_ECHSTORE_ENTRY) *entries;
-    OSSL_LIB_CTX *libctx;
-    const char *propq;
-};
-```
-
-Some notes on the above ECHConfig fields:
-
-- `version` should be `OSSL_ECH_CURRENT_VERSION` for the current version.
-
-- `public_name` field is the name used in the SNI of the outer ClientHello, and
-  that a server ought be able to authenticate if using the `retry_configs`
-  fallback mechanism.
-
-- `config_id` is a one-octet value used by servers to select which private
-  value to use to attempt ECH decryption. Servers can also do trial decryption
-  if desired, as clients might use a random value for the `confid_id` as an
-  anti-fingerprinting mechanism. (The use of one octet for this value was the
-  result of an extended debate about efficiency versus fingerprinting.)
-
-- The `max_name_length` is an element of the ECHConfigList that is used by
-  clients as part of a padding algorithm. (That design is part of the spec, but
-  isn't necessarily great - the idea is to include the longest value that might
-  be the length of a DNS name included as an inner CH SNI.) A value of 0 is
-  perhaps most likely to be used, indicating that the maximum isn't known.
-
-Essentially, an ECH store is a set of ECHConfig values, plus optionally
-(for servers), relevant private key value information.
-
-When a non-singleton ECHConfigList is ingested, that is expanded into
-a store that is the same as if a set of singleton ECHConfigList values
-had been ingested sequentially.
-
-In addition to the obvious fields from each ECHConfig, we also store:
-
-- The `encoded` value (and length) of the ECHConfig, as that is used
-  as an input for the HPKE encapsulation of the inner ClientHello. (Used
-  by both clients and servers.)
-
-- The `EVP_PKEY` pointer to the private key value associated with the
-  relevant ECHConfig, for use by servers.
-
-- The time at which a private key value and/or ECHConfigList were loaded.
-  This value is useful when servers periodically re-load sets of files
-  or PEM structures from memory, e.g. for the HAProxy server.
-
-ECH Split-mode
---------------
-
-RFC 9849 defines two modes for ECH - 'shared-mode' which is supported in
-this release, and a 'split-mode' which is not yet supported.
-
-ECH split-mode involves a front-end server that only does ECH decryption and
-then passes on the decrypted inner CH to a back-end TLS server that negotiates
-the actual TLS session with the client, based on the inner CH content.
-
-This release does however support servers that act as the back-end TLS server
-in an ECH split-mode scenario, as the functionality required is internal and
-also required when using shared-mode.
-
-Different encodings
--------------------
-
-ECHConfigList values may be provided via a command line argument to the calling
-application or (more likely) have been retrieved from DNS resource records by
-the application. ECHConfigList values may be provided in various encodings
-(base64 or binary) each of which may suit different applications.
-
-If the input contains more than one (syntactically correct) ECHConfigList, then only
-those that contain locally supported options (e.g. AEAD ciphers) will be
-returned. If no ECHConfigList found has supported options then none will be
-returned and the function will return NULL.
-
-Additional Client Controls
---------------------------
-
-Clients can additionally more directly control the values to be used for inner
-and outer SNI and ALPN values via specific APIs. This allows a client to
-override the `public_name` present in an ECHConfigList that will otherwise
-be used for the outer SNI. The `no_outer` input allows a client to emit an
-outer CH with no SNI at all. Providing a `NULL` for the `outer_name` means
-to send the `public_name` provided from the ECHConfigList.
-
-```c
-int SSL_ech_set1_server_names(SSL *s, const char *inner_name,
-                              const char *outer_name, int no_outer);
-int SSL_ech_set1_outer_server_name(SSL *s, const char *outer_name, int no_outer);
-int SSL_ech_set1_outer_alpn_protos(SSL *s, const unsigned char *protos,
-                                   size_t protos_len);
-int SSL_CTX_ech_set1_outer_alpn_protos(SSL_CTX *s, const unsigned char *protos,
-                                       size_t protos_len);
-```
-
-If a client attempts ECH but that fails, or sends an ECH-GREASEd CH, to
-an ECH-supporting server, then that server may return an ECH "retry-config"
-value that the client could choose to use in a subsequent connection. The
-client can detect this situation via the `SSL_ech_get1_status()` API and
-can access the retry config value via:
-
-```c
-OSSL_ECHSTORE *SSL_ech_get1_retry_config(SSL *s);
-```
-
-GREASEing
----------
-
-"GREASEing" is defined in
-[RFC8701](https://datatracker.ietf.org/doc/html/rfc8701) and is a mechanism
-intended to discourage protocol ossification that can be used for ECH.  GREASEd
-ECH may turn out to be important as an initial step towards widespread
-deployment of ECH.
-
-If a client wishes to GREASE ECH using a specific HPKE suite or ECH version
-(represented by the TLS extension type code-point) then it can set those values
-via:
-
-```c
-int SSL_ech_set1_grease_suite(SSL *s, const char *suite);
-int SSL_ech_set_grease_type(SSL *s, uint16_t type);
-```
-
-ECH Status API
---------------
-
-Clients and servers can check the status of ECH processing
-on an SSL connection using this API:
-
-```c
-int SSL_ech_get1_status(SSL *s, char **inner_sni, char **outer_sni);
-
-/* Return codes from SSL_ech_get1_status */
-#  define SSL_ECH_STATUS_BACKEND    4 /* ECH back-end: saw an ech_is_inner */
-#  define SSL_ECH_STATUS_GREASE_ECH 3 /* GREASEd and got an ECH in return */
-#  define SSL_ECH_STATUS_GREASE     2 /* ECH GREASE happened  */
-#  define SSL_ECH_STATUS_SUCCESS    1 /* Success */
-#  define SSL_ECH_STATUS_FAILED     0 /* Some internal or protocol error */
-#  define SSL_ECH_STATUS_BAD_CALL   -100 /* Some in/out arguments were NULL */
-#  define SSL_ECH_STATUS_NOT_TRIED  -101 /* ECH wasn't attempted  */
-#  define SSL_ECH_STATUS_BAD_NAME   -102 /* ECH ok but server cert bad */
-#  define SSL_ECH_STATUS_NOT_CONFIGURED -103 /* ECH wasn't configured */
-#  define SSL_ECH_STATUS_FAILED_ECH -105 /* We tried, failed and got an ECH, from a good name */
-#  define SSL_ECH_STATUS_FAILED_ECH_BAD_NAME -106 /* We tried, failed and got an ECH, from a bad name */
-```
-
-The `inner_sni` and `outer_sni` values should be freed by callers
-via `OPENSSL_free()`.
-
-The function returns one of the status values above.
-
-Call-backs and options
-----------------------
-
-Clients and servers can set a callback that will be triggered when ECH is
-attempted and the result of ECH processing is known. The callback function can
-access a string (`str`) that can be used for logging (but not for branching).
-Callback functions might typically call `SSL_ech_get1_status()` if branching
-is required.
-
-```c
-typedef unsigned int (*SSL_ech_cb_func)(SSL *s, const char *str);
-
-void SSL_ech_set_callback(SSL *s, SSL_ech_cb_func f);
-void SSL_CTX_ech_set_callback(SSL_CTX *ctx, SSL_ech_cb_func f);
-```
-
-The following options are defined for ECH and may be set via
-`SSL_set_options()`:
-
-```c
-/* Set this to tell client to emit greased ECH values */
-# define SSL_OP_ECH_GREASE                               SSL_OP_BIT(37)
-/*
- * If this is set then the server side will attempt trial decryption
- * of ECHs even if there is no matching ECH config_id. That's a bit
- * inefficient, but more privacy friendly.
- */
-# define SSL_OP_ECH_TRIALDECRYPT                         SSL_OP_BIT(38)
-/*
- * If set, clients will ignore the supplied ECH config_id and replace
- * that with a random value.
- */
-# define SSL_OP_ECH_IGNORE_CID                           SSL_OP_BIT(39)
-/*
- * If set, servers will add GREASEy ECHConfig values to those sent
- * in retry_configs.
- */
-# define SSL_OP_ECH_GREASE_RETRY_CONFIG                  SSL_OP_BIT(40)
-```
-
-Build Options
--------------
-
-Almost all ECH code is protected via `#ifndef OPENSSL_NO_ECH` and there is a
-`no-ech` option to build without this code.
-
-Applications using ECH may choose to detect the availability of ECH in
-the library by checking that `SSL_OP_ECH_GREASE` is defined. This is
-used by some server applications today.
-
-ECH Tests
----------
-
-The following tests are included in the `make test` target:
-
-- [`test_app_ech`](../../test/recipes/20-test_app_ech.t)
-- [`test_ech`](../../test/ech_test.c)
-- [`test_ech_corrupt`](../../test/ech_corrupt_test.c)
-- [`test_ech_client_server`](../../test/recipes/82-test_ech_client_server.t)
-
-There are also two external tests to check interoperability
-with the NSS and BoringSSL libraries:
-
-- [`test_external_ech_nss`](../../test/recipes/95-test_external_ech_nss.t)
-- [`test_external_ech_bssl`](../../test/recipes/95-test_external_ech_bssl.t)
-
-The `test_app_ech` test exercises the `openssl ech` command line utility that
-can be used to generate and manipulate ECH keys and configurations.
-
-The `test_ech` test exercises ECH APIs, including round-trip tests that use ECH
-in TLS sessions. The code for this includes many valid and invalid test vectors
-and is designed to be relatively easily extended with additional tests.
-
-`test_ech_corrupt` is modelled on [sslcorruptetst.c](../../test/sslcorrupttest.c)
-and mainly includes tests where variously incorrectly encoded inner ClientHello
-test vectors are encrypted using HPKE and then successfully decrypted by a
-server that then rejects the connection returning the expected error code.
-
-`test_ech_client_server` exercises the various ECH command line
-options for the OpenSSL `s_client` and `s_server` commands. Changes to
-the output from those command may require changes to these tests as
-they use pattern matching on the outputs to detect expected successes
-or failures.
-
-The external tests check that the library correctly interoperates, as a client
-or server, with NSS or BoringSSL. These require a build configured with
-`enable-external-tests`.  In order to avoid potential supply-chain issues, you
-need to download and build the relevant NSS or BoringSSL library manually in
-the correct location. When you first attempt to run these external tests, they
-will provide instructions for how to download and build NSS or BoringSSL in the
-correct manner. The client/server tests here are not very extensive and just
-check that a basic configuration interoperates.
-
-How to measure coverage of ECH tests
-------------------------------------
-
-There are likely many ways to do this, but the following is the
-recipe used during ECH development:
-
-```bash
-./config --debug enable-external-tests --coverage no-asm no-afalgeng no-shared -DPEDANTIC -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
-make -s -j12
-make test TESTS='test_ech test_ech_corrupt test_app_ech test_ech_client_server test_external_ech_bssl test_external_ech_nss'
-# next line failed, was replaced the the one following
-# lcov -d . -c -o ./lcov.info
-/usr/bin/geninfo . --output-filename ./lcov.info --memory 0 --ignore-errors mismatch
-genhtml ./lcov.info --output-directory $HOME/tmp/myco
-```
-
-To clean away the coverage files:
-
-```bash
-find . -name '*.gcda'  -exec rm {} \;
-find . -name '*.gcno'  -exec rm {} \;
-rm lcov.info
-make clean
-make -j12
-```
-
-Checking memory errors
-----------------------
-
-As is typical with the library there is a good bit of code that handles error
-cases that are hard to test. Causing memory allocation failures though allows
-us to get at most of those code fragments.
-
-To get to those error handling lines of code, one can use an exhaustive script
-that incrementally allows more and more memory allocations to work before
-triggering failures such as:
-
-```bash
-#!/bin/bash
-#
-# run 16k tests
-
-# if you want tracing
-# export OPENSSL_TRACE="TLS"
-logfile=loads.log
-iter=0
-
-function whenisitagain()
-{
-    /bin/date -u +%Y%m%d-%H%M%S
-}
-NOW=$(whenisitagain)
-echo "==================================" >>$logfile
-echo "Started at $NOW" >>$logfile
-
-# 16,000 calls without failures should be enough for the
-# test to pass - gprof says we have 15,558 calls to
-# CRYPTO_malloc for the test below
-while ((iter < 16000))
-do
-    echo "Doing $iter" >>$logfile
-    iter=$((iter+1))
-    export OPENSSL_MALLOC_FAILURES="$iter@0;0@99;"
-    ./test/ech_test -test 6 -iter 1 >>$logfile 2>&1
-    echo "Done $iter"
-    echo "Done $iter" >>$logfile
-    echo "" >>$logfile
-    echo "" >>$logfile
-done
-
-NOW=$(whenisitagain)
-echo "Ended at $NOW" >>$logfile
-echo "==================================" >>$logfile
-```
-
-An `OPENSSL_MALLOC_FAILURES` value of `100@0;0@99` means to allow the first 100
-memory allocations to work, and to then switch to a mode where there's a 99%
-chance of memory allocation failing. By using `$iter` we just keep incrementing
-how far into the run we allow nominal memory allocation before we break things,
-which should result in (eventually:-) hitting every possible memory allocation
-failure handling line of code.
-
-You need to build with the `crypto-mdebug` option to get the memory allocation
-failure, so that'd be something like:
-
-```bash
-./config --debug enable-external-tests enable-crypto-mdebug --coverage no-asm no-afalgeng no-shared -DPEDANTIC -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
-```
-
-The script above gets us from 75% lines of code covered based on normal tests
-to 85.6% for the `ech_internal.c` file, which is our least well covered by
-normal tests. The script takes about 20 minutes to run on a developer laptop.
diff --git a/doc/designs/evp_skey.md b/doc/designs/evp_skey.md
index e79874ee30..ac5e7bd125 100644
--- a/doc/designs/evp_skey.md
+++ b/doc/designs/evp_skey.md
@@ -102,9 +102,9 @@ EVP_SKEY *EVP_SKEY_generate(OSSL_LIB_CTX *libctx, const char *skeymgmtname,
 EVP_SKEY *EVP_SKEY_import(OSSL_LIB_CTX *libctx, const char *skeymgmtname,
                           const char *propquery,
                           int selection, const OSSL_PARAM *params);
-EVP_SKEY *EVP_SKEY_import_raw_key(OSSL_LIB_CTX *libctx, const char *skeymgmtname,
-                                  unsigned char *key, size_t keylen,
-                                  const char *propquery);
+EVP_SKEY *EVP_SKEY_import_raw(OSSL_LIB_CTX *libctx, const char *skeymgmtname,
+                              const char *key, size_t keylen,
+                              const char *propquery);
 int EVP_SKEY_up_ref(EVP_SKEY *skey);
 void EVP_SKEY_free(EVP_SKEY *skey);
 ```
diff --git a/doc/designs/evp_skey_multi.md b/doc/designs/evp_skey_multi.md
deleted file mode 100644
index dfff81ed17..0000000000
--- a/doc/designs/evp_skey_multi.md
+++ /dev/null
@@ -1,87 +0,0 @@
-Simultaneous derivation of several EVP_SKEY objects
-===================================================
-
-There are situations where we need to derive several symmetric keys
-simultaneously.  The most relevant one for OpenSSL is TLS protocol, when we
-need to derive 2-4 keys, depending on the protocol version. With raw bytes
-buffer, the approach was to derive a combined buffer of the necessary length
-and chop it. It doesn't work this way for EVP_SKEY objects.
-
-This document proposes API and a general approach to deal with such situations.
-
-Model use case
---------------
-
-TLS 1.2 and below requires simultaneous derivation of 2 IVs and 2 or 4 keys (2 for
-ciphers and 2 for MACs).  IVs are public and can be accessed directly, keys are
-returned as EVP_SKEY objects.
-
-The API is designed from the perspective of being a transparent wrapper for
-PKCS#11 mechanisms for simultaneous key generation and avoid the extra calls to
-token API from the provider.
-
-Libcrypto API
--------------
-
-As all the objects are derived in one transaction, we can store a single opaque
-pointer keeping all the keys inside in the EVP_KDF_CTX object, and provide the
-API for access to a particular object.
-
-To derive the opaque keys and and bytes buffers, we use the function
-
-```C
-int EVP_KDF_derive_SKEYs(EVP_KDF_CTX *ctx, EVP_SKEYMGMT *mgmt,
-                         const char *propquery, const OSSL_PARAM params[]);
-```
-
-This function doesn't directly return objects when this functions succeeds,
-they are stored in the EVP_KDF_CTX object.
-
-The options that define key types and sizes, number of keys or IVs and their
-length can generally be specified by passing appropriate parameters in the
-`params` argument. If no params are provided, defaults may be used by specific
-KDF operations.
-
-The params can also be set by a preceding call to `EVP_KDF_CTX_set_params`.
-
-To access the individual EVP_SKEY values, we introduce the functions
-
-```C
-EVP_SKEY *EVP_KDF_CTX_get0_SKEY(EVP_KDF_CTX *ctx, const char *purpose);
-EVP_SKEY *EVP_KDF_CTX_get1_SKEY(EVP_KDF_CTX *ctx, const char *purpose);
-```
-
-where the `purpose` argument is a name of the particular EVP_SKEY purpose (e.g.
-"client_MAC_key", "server_CIPHER_key") as specified by the documentation of the
-specific KDF operation that was executed.
-
-To access an IV, the proposed API is
-
-```C
-int EVP_KDF_CTX_get0_IV(EVP_KDF_CTX *ctx, const char *purpose,
-                        unsigned char **pIV, size_t *pIVlen);
-```
-
-where the `purpose` argument is a documented name of the particular IV purpose
-(e.g. "client_IV") and `pIVlen` argument is a way to get the length of
-generated IV.
-
-Provider API
-------------
-
-We extend the EVP_KDF structure with the following member functions:
-
-```C
-OSSL_CORE_MAKE_FUNC(int, kdf_derive_multi, (void *kctx,
-                    const OSSL_PARAM params[]))
-
-OSSL_CORE_MAKE_FUNC(int, kdf_get_skey,
-                    (void *kctx, void *skeydata, const char *purpose, bool incr_refcount))
-
-OSSL_CORE_MAKE_FUNC(unsigned char *, kdf_get_iv,
-                    (void *kctx, const char *purpose))
-
-```
-
-Providers may either imply some KDF-specific defaults when it's obvious from
-the KDF specification or throw an error otherwise.
diff --git a/doc/designs/fips_deferred_tests.md b/doc/designs/fips_deferred_tests.md
index 7b8a4747da..fb64be26b3 100644
--- a/doc/designs/fips_deferred_tests.md
+++ b/doc/designs/fips_deferred_tests.md
@@ -88,13 +88,16 @@ function, as this is the earliest point at which an application signals its
 intent to use the algorithm.
 
 The self-test state is maintained in a structure of type `FIPS_DEFERRED_TEST`,
-this structure will be augmented with an array of pointers to other state
-structures of the same type that this test depends on for certification
-reasons but would not be otherwise implicitly exercised by test (or perhaps
-ordering is important).
+this structure will be augmented with two arrays of pointers to other state
+structures of the same type.
 
-Note that recursions are cut short by the fact that calling into a "parent"
-test results only in that test being recorded as seen but not processed.
+One will handle test equivalency and will be named 'also_satisfies', the other
+will handle explicit dependencies that are not implicitly handled by
+initialization functions.
+
+Note that the `also_satisfies` list will *not* be used recursively (see the
+Examples section for an explanation of why this can't be done), while the
+`depends_on` list is used in a recursive fashion.
 
 Dependency Handling
 -------------------
@@ -139,7 +142,7 @@ will be removed from this initial sequence.
 Even though these tests will be forcibly executed at module initialization
 they will use the same execution architecture via FIPS_DEFERRED_TEST state,
 so that they can be depended on by other tests and can mark other tests
-passed via equivalency.
+passed via equivalency (`also_satisfies` lists).
 
 Error Handling
 --------------
@@ -177,18 +180,35 @@ satisfying KAT requirements also for the inner algorithm used.
 
 For example the self-test for HMAC is considered sufficient also for testing
 the underlying digest. Therefore the current HMAC test (which uses SHA-256)
-will invoke the SHA-256 algorithm which will call into the test machinery and
-will be recorded as an algorithm invoked by the test.
+will link to the SHA-256 in the 'also_satisfies' list.
 
 When the application invokes EVP_MAC_init() it internally causes the FIPS
 module hmac_init() function to execute. If the HMAC test has not been run yet
-it will be executed.
+it will be executed. This test lists the SHA-256 test as also satisfied
 
 Once the HMAC test is complete the FIPS_KAT_deferred code will check the
-list of additional algorithms invoked as part of the test and will mark each
-of them as passed.
+'also_satisfies' list and will mark each test in that list as passed. Note that
+this is not done recursivively because there is no guarantee that a higher
+level test always transitively satisfies lower level test. A high level test
+should list explicitly in `also_satisfies` all the algorithms that can be
+considered tested.
 
-### Example 3: simple tests and dependencies behavior
+### Example 3: composite algorithms and equivalence behavior
+
+An example of a high level test that would incorrectly mark `also_satisfies`
+tests if it were allowed to do it recursively is the following:
+
+Let's assume the application invokes the PBKDF2 derivation function. Let's also
+assume, for the sake of argument, that the PBKDF2 test uses HMAC with SHA3-256
+in its KAT.  The PBKDF2 test can list HMAC as also satisfied, but if we were to
+recursively mark the tests in HMAC's `also_satisfies` list as passed, this would
+incorrectly mark the SHA-256 digest as passed because that's the digest used by
+the HMAC's own test.  However this is not what was actually tested.
+
+In order to properly mark the actual test that have been used, the PBKDF2 test
+will explicitly list HMAC and SHA3-256 in the `also_satisfies` list of tests.
+
+### Example 4: simple tests and dependencies behavior
 
 Another example is the use of `depends_on` to run equivalent but broader tests
 when that makes sense. For example if we consider the HMAC test as low impact,
@@ -206,11 +226,14 @@ SHA-256 lists the HMAC test as "dependency" in the `depends_on` list.
 When FIPS_KAT_deferred is invoked it checks whether there are tests listed in
 the depends_on list before executing the actual self-test, and if there are
 tests, it executes those first (recursively). It will find the HMAC test and
-execute it.  The HMAC test invokes the SHA-256 test and records it, therefore at
-the end of the test, the SHA-256 test will be marked as passed and control
-returned back up to the calling test. FIPS_KAT_deferred will now check if the
-SHA-256 test is already passed. Finding it already passed just returns and never
-actually executes the SHA-256 test directly.
+execute it.  The HMAC test lists SHA-256 as also satisfied, therefore at the end
+of the test, the SHA-256 test will be marked as passed and control returned back
+up to the calling test. FIPS_KAT_deferred will now check if the SHA-256 test is
+already passed. Finding it already passed just returns and never actually
+executes the SHA-256 test directly. In case of mistakes (for example the HMAC
+test is later changed to use SHA3-256 and marks only that algorithm as also
+satisfied) the SHA-256 self-test is executed, but this hollow test just returns
+failure, catching the fact that a change of dependent self-test broke a promise.
 
 Note that this is a special case of using dependencies to satisfy a test via
 indirection, in some cases dependencies will just be necessary tests that have
@@ -267,6 +290,7 @@ struct fips_deferred_test_st {
     const char *algorithm;
     int category;
     int state;
+    struct fips_deferred_test_st *also_satisfies;
     struct fips_deferred_test_st *depends_on;
 };
 
diff --git a/doc/designs/passing-algorithmidentifier-parameters.md b/doc/designs/passing-algorithmidentifier-parameters.md
index 0e6126b056..9c5669e86b 100644
--- a/doc/designs/passing-algorithmidentifier-parameters.md
+++ b/doc/designs/passing-algorithmidentifier-parameters.md
@@ -129,10 +129,10 @@ at all when such parameter data needs to be passed.
 Background / tl;dr
 ------------------
 
-### AlgorithmIdentifier parameter and how it's used
+### AlgorithmIdenfier parameter and how it's used
 
 OpenSSL has historically done a few tricks to not have to pass
-AlgorithmIdentifier parameter data to the backend implementations of
+AlgorithmIdenfier parameter data to the backend implementations of
 cryptographic operations:
 
 - In some cases, they were passed as part of the lower level key structure
diff --git a/doc/designs/quic-design/quic-ackm.md b/doc/designs/quic-design/quic-ackm.md
index 38d72aac3c..488fded5e1 100644
--- a/doc/designs/quic-design/quic-ackm.md
+++ b/doc/designs/quic-design/quic-ackm.md
@@ -424,7 +424,7 @@ This should be called for a packet before attempting to process its contents.
 Failure to do so may may result in processing a duplicated packet in violation
 of the RFC.
 
-The return value of this function transitions from 1 to 0 for a given PN once
+The returrn value of this function transitions from 1 to 0 for a given PN once
 that PN is passed to ossl_ackm_on_rx_packet, thus this function must be used
 before calling `ossl_ackm_on_rx_packet`.
 
diff --git a/doc/designs/quic-design/quic-api-ssl-funcs.md b/doc/designs/quic-design/quic-api-ssl-funcs.md
index 37229c26e6..6333bafab8 100644
--- a/doc/designs/quic-design/quic-api-ssl-funcs.md
+++ b/doc/designs/quic-design/quic-api-ssl-funcs.md
@@ -108,6 +108,9 @@ Notes:
 | `SSL_test_functions`                         | Global  | 🟩U   | 🟦U   | 🟩NC       | 🟢Done       |
 | `SSL_select_next_proto`                      | Global  | 🟩U   | 🟦U   | 🟩NC       | 🟢Done       |
 | **⇒ Methods**                                |         |       |       |            |              |
+| `SSLv3_method`                               | Global  | 🟩U   | 🟦U   | 🟩NC       | 🟢Done       |
+| `SSLv3_client_method`                        | Global  | 🟩U   | 🟦U   | 🟩NC       | 🟢Done       |
+| `SSLv3_server_method`                        | Global  | 🟩U   | 🟦U   | 🟩NC       | 🟢Done       |
 | `TLS_method`                                 | Global  | 🟩U   | 🟦U   | 🟩NC       | 🟢Done       |
 | `TLS_client_method`                          | Global  | 🟩U   | 🟦U   | 🟩NC       | 🟢Done       |
 | `TLS_server_method`                          | Global  | 🟩U   | 🟦U   | 🟩NC       | 🟢Done       |
diff --git a/doc/designs/quic-design/quic-requirements.md b/doc/designs/quic-design/quic-requirements.md
index daeb50db66..c8aeedc7b7 100644
--- a/doc/designs/quic-design/quic-requirements.md
+++ b/doc/designs/quic-design/quic-requirements.md
@@ -60,7 +60,7 @@ and that were specific to QUIC
 
 * For the MVP a single interop target (i.e. the server implementation list):
 
-  1. [Cloudflare](https://cloudflare-quic.com/)
+  1. [Cloudfare](https://cloudflare-quic.com/)
 
 * Testing against other implementations is not a release requirement for the MVP.
 
diff --git a/doc/fingerprints.txt b/doc/fingerprints.txt
index e8015f26b9..bdcad14723 100644
--- a/doc/fingerprints.txt
+++ b/doc/fingerprints.txt
@@ -13,9 +13,6 @@ The following is the list of fingerprints for the keys that are
 currently in use to sign OpenSSL distributions:
 
 OpenSSL:
-B146 647E 45A7 B339 47AB 226B 2A2C 87D1 6169 2D40
-
-OpenSSL (old keys):
 BA54 73A2 B058 7B07 FB27 CF2D 2160 94DF D0CB 81EF
 
 Richard Levitte:
diff --git a/doc/internal/man3/OSSL_SAFE_MATH_SIGNED.pod b/doc/internal/man3/OSSL_SAFE_MATH_SIGNED.pod
index 740555e6ad..16bd7f205c 100644
--- a/doc/internal/man3/OSSL_SAFE_MATH_SIGNED.pod
+++ b/doc/internal/man3/OSSL_SAFE_MATH_SIGNED.pod
@@ -80,7 +80,7 @@ This example is of a function that computes the size of a record that
 has a four byte element count which is followed by that many elements.
 It returns zero on overflow.
 
- OSSL_SAFE_MATH_UNSIGNED(sizet, size_t)
+ OSSL_SAFE_MATH_UNSIGNED(sizet, size_t, SIZE_MAX)
 
  size_t compute_record_size(uint32_t n)
  {
diff --git a/doc/internal/man3/evp_generic_fetch.pod b/doc/internal/man3/evp_generic_fetch.pod
index 53f29c1e98..016494239e 100644
--- a/doc/internal/man3/evp_generic_fetch.pod
+++ b/doc/internal/man3/evp_generic_fetch.pod
@@ -187,7 +187,8 @@ And here's the implementation of the FOO method fetcher:
         EVP_FOO *foo = vfoo;
         int ref = 0;
 
-        return CRYPTO_UP_REF(&foo->refcnt, &ref);
+        CRYPTO_UP_REF(&foo->refcnt, &ref);
+        return 1;
     }
 
     static void foo_free(void *vfoo)
diff --git a/doc/internal/man3/evp_keymgmt_newdata.pod b/doc/internal/man3/evp_keymgmt_newdata.pod
index 3b96a6a936..9b3f2c55f1 100644
--- a/doc/internal/man3/evp_keymgmt_newdata.pod
+++ b/doc/internal/man3/evp_keymgmt_newdata.pod
@@ -13,7 +13,7 @@ evp_keymgmt_export, evp_keymgmt_export_types
 
  #include "crypto/evp.h"
 
- void *evp_keymgmt_newdata(const EVP_KEYMGMT *keymgmt, const OSSL_PARAM params[]);
+ void *evp_keymgmt_newdata(const EVP_KEYMGMT *keymgmt);
  void evp_keymgmt_freedata(const EVP_KEYMGMT *keymgmt, void *keyddata);
  int evp_keymgmt_get_params(const EVP_KEYMGMT *keymgmt,
                             void *keydata, OSSL_PARAM params[]);
@@ -39,8 +39,7 @@ first argument, which they also retrieve a provider context from when
 needed.  The rest of the arguments are simply passed on to the
 function they wrap around.
 
-evp_keymgmt_newdata() calls the method's new() function or new_ex() if there is
-one.
+evp_keymgmt_newdata() calls the method's new() function.
 
 evp_keymgmt_freedata() calls the method's free() function.
 
@@ -79,7 +78,7 @@ The functions described here were all added in OpenSSL 3.0.
 
 =head1 COPYRIGHT
 
-Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved.
 
 Licensed under the Apache License 2.0 (the "License").  You may not use
 this file except in compliance with the License.  You can obtain a copy
diff --git a/doc/internal/man3/evp_keymgmt_util_export_to_provider.pod b/doc/internal/man3/evp_keymgmt_util_export_to_provider.pod
index 0ddd2d062f..1008d21131 100644
--- a/doc/internal/man3/evp_keymgmt_util_export_to_provider.pod
+++ b/doc/internal/man3/evp_keymgmt_util_export_to_provider.pod
@@ -25,7 +25,7 @@ OP_CACHE_ELEM
  OP_CACHE_ELEM *evp_keymgmt_util_find_operation_cache(EVP_PKEY *pk,
                                                       EVP_KEYMGMT *keymgmt,
                                                       int selection);
- void evp_keymgmt_util_clear_operation_cache(EVP_PKEY *pk);
+ int evp_keymgmt_util_clear_operation_cache(EVP_PKEY *pk);
  int evp_keymgmt_util_cache_keydata(EVP_PKEY *pk, EVP_KEYMGMT *keymgmt,
                                     void *keydata, int selection);
  void evp_keymgmt_util_cache_keyinfo(EVP_PKEY *pk);
@@ -81,7 +81,8 @@ evp_keymgmt_util_find_operation_cache() returns a pointer to the
 operation cache slot.  If I is NULL, or if there is no slot
 with a match for I, NULL is returned.
 
-evp_keymgmt_util_cache_keydata() return 1 on success or 0 otherwise.
+evp_keymgmt_util_cache_keydata() and evp_keymgmt_util_clear_operation_cache()
+return 1 on success or 0 otherwise.
 
 =head1 NOTES
 
@@ -90,11 +91,11 @@ B with EVP_PKEY_assign_RSA() and similar functions.
 
 =head1 SEE ALSO
 
-L
+L, L
 
 =head1 COPYRIGHT
 
-Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
+Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved.
 
 Licensed under the Apache License 2.0 (the "License").  You may not use
 this file except in compliance with the License.  You can obtain a copy
diff --git a/doc/internal/man3/ossl_cmp_msg_check_update.pod b/doc/internal/man3/ossl_cmp_msg_check_update.pod
index eab0247492..2a6a9fccb0 100644
--- a/doc/internal/man3/ossl_cmp_msg_check_update.pod
+++ b/doc/internal/man3/ossl_cmp_msg_check_update.pod
@@ -51,7 +51,6 @@ The callback is passed also the arguments B, B, and 
 The callback should return 1 on acceptance, 0 on rejection, or -1 on error.
 It should not put an error on the error stack since this could be misleading.
 
-Unless the B is set in the B,
 ossl_cmp_msg_check_update() adds all extraCerts contained in the  to
 the list of untrusted certificates in B such that they are already usable
 for OSSL_CMP_validate_msg(), which is called internally, and for future use.
@@ -59,7 +58,7 @@ Thus they are available also to the certificate confirmation callback, and the
 peer does not need to send them again (at least not in the same transaction).
 Note that it does not help validating the message before storing the extraCerts
 because they are not part of the protected portion of the message anyway.
-For efficiency, the extraCerts being cached are prepended to the list so they get used first.
+For efficiency, the extraCerts are prepended to the list so they get used first.
 
 If all checks pass then ossl_cmp_msg_check_update()
 records in B the senderNonce of the received message as the new recipNonce
diff --git a/doc/internal/man3/ossl_rcu_lock_new.pod b/doc/internal/man3/ossl_rcu_lock_new.pod
index aca2693e23..57b5e4d73d 100644
--- a/doc/internal/man3/ossl_rcu_lock_new.pod
+++ b/doc/internal/man3/ossl_rcu_lock_new.pod
@@ -6,7 +6,6 @@ ossl_rcu_lock_new,
 ossl_rcu_lock_free, ossl_rcu_read_lock,
 ossl_rcu_read_unlock, ossl_rcu_write_lock,
 ossl_rcu_write_unlock, ossl_synchronize_rcu,
-ossl_rcu_cb_item_new, ossl_rcu_cb_item_free,
 ossl_rcu_call, ossl_rcu_deref,
 ossl_rcu_assign_ptr, ossl_rcu_uptr_deref,
 ossl_rcu_assign_uptr
@@ -20,10 +19,7 @@ ossl_rcu_assign_uptr
  void ossl_rcu_write_unlock(CRYPTO_RCU_LOCK *lock);
  void ossl_rcu_read_unlock(CRYPTO_RCU_LOCK *lock);
  void ossl_synchronize_rcu(CRYPTO_RCU_LOCK *lock);
- CRYPTO_RCU_CB_ITEM *ossl_rcu_cb_item_new(void);
- void ossl_rcu_cb_item_free(CRYPTO_RCU_CB_ITEM *item);
- void ossl_rcu_call(CRYPTO_RCU_LOCK *lock, CRYPTO_RCU_CB_ITEM *item,
-                    rcu_cb_fn cb, void *data);
+ void ossl_rcu_call(CRYPTO_RCU_LOCK *lock, rcu_cb_fn cb, void *data);
  void *ossl_rcu_deref(void **p);
  void ossl_rcu_uptr_deref(void **p);
  void ossl_rcu_assign_ptr(void **p, void **v);
@@ -100,29 +96,10 @@ the write side thread is safe to free.
 
 =item *
 
-ossl_rcu_cb_item_new() allocates a callback item suitable for use with
-ossl_rcu_call().  Returns NULL on allocation failure.  The item is owned by
-the caller until it is passed to ossl_rcu_call(), at which point ownership
-transfers to the lock and the item must not be touched again by the caller.
-
-=item *
-
-ossl_rcu_cb_item_free() frees a callback item that was allocated by
-ossl_rcu_cb_item_new() but never passed to ossl_rcu_call().  Use this to
-release the item on the failure path of an operation that decided not to
-publish its update.
-
-=item *
-
-ossl_rcu_call() enqueues a callback function I to the lock, to be
-called with I when the next synchronization completes.  The caller
-must provide a callback item I previously obtained from
-ossl_rcu_cb_item_new().  After this call the lock owns the item and will
-free it after invoking the callback.  This function does not allocate and
-cannot fail, which lets callers allocate the item before performing any
-publish (assign_ptr) and bail cleanly if allocation fails.  Note: it is
-not guaranteed that the thread which enqueued the callback will be the
-thread which executes the callback.
+ossl_rcu_call() enqueues a callback function to the lock, to be called
+when the next synchronization completes.  Note: It is not guaranteed that the
+thread which enqueued the callback will be the thread which executes the
+callback
 
 =item *
 
@@ -144,9 +121,6 @@ ossl_rcu_lock_free() frees an allocated RCU lock
 
 ossl_rcu_lock_new() returns a pointer to a newly created RCU lock structure.
 
-ossl_rcu_cb_item_new() returns a pointer to a newly created callback item,
-or NULL on allocation failure.
-
 ossl_rcu_deref() and ossl_rcu_uptr_deref() return the value pointed
 to by the passed in value v.
 
@@ -178,7 +152,7 @@ This example safely initializes and uses a lock.
 
  static void myinit(void)
  {
-     lock = ossl_rcu_lock_new(1, NULL);
+     lock = ossl_rcu_lock_new(1);
  }
 
  static int initlock(void)
@@ -188,16 +162,10 @@ This example safely initializes and uses a lock.
      return 1;
  }
 
- static void free_old_foo(void *data)
- {
-     OPENSSL_free(data);
- }
-
- static int writer_thread(void)
+ static void writer_thread()
  {
     struct foo *newfoo;
     struct foo *oldfoo;
-    CRYPTO_RCU_CB_ITEM *cbi;
 
     initlock();
 
@@ -209,60 +177,48 @@ This example safely initializes and uses a lock.
      * 1) create a new shared object
      */
     newfoo = OPENSSL_zalloc(sizeof(struct foo));
-    if (newfoo == NULL)
-        return 0;
 
     /*
-     * 2) Pre allocate the rcu callback item before any publish.
-     */
-    cbi = ossl_rcu_cb_item_new();
-    if (cbi == NULL) {
-        OPENSSL_free(newfoo);
-        return 0;
-    }
-
-    /*
-     * 3) acquire the write side lock
+     * acquire the write side lock
      */
     ossl_rcu_write_lock(lock);
 
     /*
-     * 4) read the old pointer
+     * 2) read the old pointer
      */
     oldfoo = ossl_rcu_deref(&fooptr);
 
     /*
-     * 5) Copy the old pointer to the new object, and
+     * 3) Copy the old pointer to the new object, and
      *    make any needed adjustments
      */
     memcpy(newfoo, oldfoo, sizeof(struct foo));
     newfoo->aval++;
 
     /*
-     * 6) Update the shared pointer to the new value
+     * 4) Update the shared pointer to the new value
      */
     ossl_rcu_assign_ptr(&fooptr, &newfoo);
 
     /*
-     * 7) Schedule the old pointer to be freed when readers are done.
-     */
-    ossl_rcu_call(lock, cbi, free_old_foo, oldfoo);
-
-    /*
-     * 8) Release the write side lock
+     * 5) Release the write side lock
      */
     ossl_rcu_write_unlock(lock);
 
     /*
-     * 9) wait for any read side holds on the old data
-     *    to be released, after which free_old_foo will run
+     * 6) wait for any read side holds on the old data
+     *    to be released
      */
     ossl_synchronize_rcu(lock);
 
-    return 1;
+    /*
+     * 7) free the old pointer, now that there are no
+     *    further readers
+     */
+    OPENSSL_free(oldfoo);
  }
 
- static void reader_thread(void)
+ static void reader_thread()
  {
     struct foo *myfoo = NULL;
     int a;
@@ -293,7 +249,7 @@ L, L.
 
 =head1 COPYRIGHT
 
-Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved.
+Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.
 
 Licensed under the Apache License 2.0 (the "License").  You may not use
 this file except in compliance with the License.  You can obtain a copy
diff --git a/doc/internal/man7/EVP_PKEY.pod b/doc/internal/man7/EVP_PKEY.pod
index 7123a8fb22..b8588b0dfb 100644
--- a/doc/internal/man7/EVP_PKEY.pod
+++ b/doc/internal/man7/EVP_PKEY.pod
@@ -31,7 +31,7 @@ and it can take one of the following forms:
 This is the form that an B in OpenSSL prior to 3.0 had.  The
 internal key in the B is a pointer to the low-level key
 types, such as B, B and B, and is governed by an associated
-B.
+L and an L.
 
 The functions available through those two method structures get full
 access to the B and therefore have a lot of freedom to
@@ -94,8 +94,8 @@ the L, the dirty count is maintained in the B
 itself, and is incremented every time L or its
 specialised derivatives are called.
 For legacy origin keys, this requires the associated
-B to implement the dirty_cnt() function.  All
-of OpenSSL's built-in B implement this
+L to implement the dirty_cnt() function.  All
+of OpenSSL's built-in L implement this
 function.
 
 =head2 Export cache for provider operations
@@ -122,7 +122,7 @@ there are two forms of the latter, we have the "legacy origin" and the
 The export to the operation key cache can be performed independent of
 what form the origin has.
 For a legacy origin, this requires that the associated
-B implements the functions export_to() and
+L implements the functions export_to() and
 dirty_cnt().
 For a provider native origin, this requires that the associated
 L implements the OSSL_FUNC_keymgmt_export() function
@@ -166,7 +166,7 @@ Export the internal origin key to the provider, using the appropriate
 method.
 
 For legacy origin keys, that's done with the help of the
-B export_to() function.
+L export_to() function.
 
 For provider native origin keys, that's done by retrieving the key
 data in L form from the origin keys, using the
@@ -203,7 +203,7 @@ L.
 
 =head1 COPYRIGHT
 
-Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved.
+Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved.
 
 Licensed under the Apache License 2.0 (the "License").  You may not use
 this file except in compliance with the License.  You can obtain a copy
diff --git a/doc/internal/man7/VERSION.pod b/doc/internal/man7/VERSION.pod
index 8ffd836c13..4bc8ba6b93 100644
--- a/doc/internal/man7/VERSION.pod
+++ b/doc/internal/man7/VERSION.pod
@@ -26,7 +26,7 @@ The keys that are recognised are:
 
 The three parts of OpenSSL's 3 numbered version number, MAJOR.MINOR.PATCH.
 These are used to compose the values for the C macros B,
-B, B.
+B, B.
 
 =item B
 
diff --git a/doc/internal/man7/deprecation.pod b/doc/internal/man7/deprecation.pod
index f27e664b49..de34c30fa2 100644
--- a/doc/internal/man7/deprecation.pod
+++ b/doc/internal/man7/deprecation.pod
@@ -2,11 +2,6 @@
 
 =head1 NAME
 
-OPENSSL_NO_DEPRECATED_4_1, OSSL_DEPRECATEDIN_4_1,
-OPENSSL_NO_DEPRECATED_4_0, OSSL_DEPRECATEDIN_4_0,
-OPENSSL_NO_DEPRECATED_3_6, OSSL_DEPRECATEDIN_3_6,
-OPENSSL_NO_DEPRECATED_3_5, OSSL_DEPRECATEDIN_3_5,
-OPENSSL_NO_DEPRECATED_3_4, OSSL_DEPRECATEDIN_3_4,
 OPENSSL_NO_DEPRECATED_3_1, OSSL_DEPRECATEDIN_3_1,
 OPENSSL_NO_DEPRECATED_3_0, OSSL_DEPRECATEDIN_3_0,
 OPENSSL_NO_DEPRECATED_1_1_1, OSSL_DEPRECATEDIN_1_1_1,
@@ -136,7 +131,7 @@ L
 
 =head1 COPYRIGHT
 
-Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved.
+Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved.
 
 Licensed under the Apache License 2.0 (the "License").  You may not use
 this file except in compliance with the License.  You can obtain a copy
diff --git a/doc/internal/man7/valgrind-tests.pod b/doc/internal/man7/valgrind-tests.pod
deleted file mode 100644
index e5b31b868d..0000000000
--- a/doc/internal/man7/valgrind-tests.pod
+++ /dev/null
@@ -1,49 +0,0 @@
-=pod
-
-=head1 NAME
-
-valgrind-tests - How we test for valgrind
-
-=head1 DESCRIPTION
-
-We have CI jobs that run to verify that the suppression file we
-ship with valgrind functions correctly when users use valgrind
-with full leak checking.
-
-While doing full leak checking shows the global objects the library
-frees on exit as leaks, which really are not leaks, it is a chore
-to continuously tell people to ignore the results from the library.
-
-==head1 ENVIRONMENT
-
-Normally the openssl application main program and the test main program
-always call OPENSSL_cleanup(). This means that running these applications
-under valgrind will not show anything. Therefore we selectively disable
-the call to OPENSSL_cleanup() when running these applications for
-testing.
-
-the test environment sets the environment variable
-
-I when using valgrind to run our tests.
-
-As such the main programs above are instrumented so that when they
-are built and the  header can be seen in the
-include path, the macro RUNNING_ON_VALGRIND is used at exit time
-to test to see if the program is actually running under valgrind.
-
-If the program is running under valgrind, the program checks to
-see if I is set in the environment. If so,
-the call to OPENSSL_cleanup() is skipped on exit. This will ensure
-the library globals are noticed by valgrind with full leak checking
-ensuring our suppression file is working in CI.
-
-=head1 COPYRIGHT
-
-Copyright 2026 The OpenSSL Project Authors. All Rights Reserved.
-
-Licensed under the Apache License 2.0 (the "License").  You may not use
-this file except in compliance with the License.  You can obtain a copy
-in the file LICENSE in the source distribution or at
-L.
-
-=cut
diff --git a/doc/man1/CA.pl.pod b/doc/man1/CA.pl.pod
index 3d7c644249..184382ee83 100644
--- a/doc/man1/CA.pl.pod
+++ b/doc/man1/CA.pl.pod
@@ -106,7 +106,7 @@ If there is an additional argument on the command line it will be used as the
 list box), otherwise the name "My Certificate" is used.
 Delegates work to L.
 
-=item B<-sign>, B<-xsign>
+=item B<-sign>, B<-signcert>, B<-xsign>
 
 Calls the L command to sign a certificate request. It expects the
 request to be in the file F. The new certificate is written to the
diff --git a/doc/man1/build.info b/doc/man1/build.info
index d5e0c43447..aba8a89dd5 100644
--- a/doc/man1/build.info
+++ b/doc/man1/build.info
@@ -17,7 +17,6 @@ DEPEND[openssl-dsaparam.pod]=../perlvars.pm
 DEPEND[openssl-dsa.pod]=../perlvars.pm
 DEPEND[openssl-ecparam.pod]=../perlvars.pm
 DEPEND[openssl-ec.pod]=../perlvars.pm
-DEPEND[openssl-ech.pod]=../perlvars.pm
 DEPEND[openssl-enc.pod]=../perlvars.pm
 DEPEND[openssl-errstr.pod]=../perlvars.pm
 DEPEND[openssl-fipsinstall.pod]=../perlvars.pm
diff --git a/doc/man1/openssl-asn1parse.pod b/doc/man1/openssl-asn1parse.pod.in
similarity index 98%
rename from doc/man1/openssl-asn1parse.pod
rename to doc/man1/openssl-asn1parse.pod.in
index d4cf3fb432..6fd5ed692d 100644
--- a/doc/man1/openssl-asn1parse.pod
+++ b/doc/man1/openssl-asn1parse.pod.in
@@ -1,4 +1,5 @@
 =pod
+{- OpenSSL::safe::output_do_not_edit_headers(); -}
 
 =head1 NAME
 
@@ -209,7 +210,7 @@ L
 
 =head1 COPYRIGHT
 
-Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved.
+Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved.
 
 Licensed under the Apache License 2.0 (the "License").  You may not use
 this file except in compliance with the License.  You can obtain a copy
diff --git a/doc/man1/openssl-ca.pod.in b/doc/man1/openssl-ca.pod.in
index 7e75d020db..33bc11a431 100644
--- a/doc/man1/openssl-ca.pod.in
+++ b/doc/man1/openssl-ca.pod.in
@@ -55,8 +55,9 @@ B B
 [B<-preserveDN>]
 [B<-noemailDN>]
 [B<-batch>]
-[B<-extfile> I]
+[B<-msie_hack>]
 [B<-extensions> I
] +[B<-extfile> I
] [B<-subj> I] [B<-utf8>] [B<-sigopt> I:I] @@ -228,14 +229,6 @@ Don't output the text form of a certificate to the output file. Specify the date output format. Values are: rfc_822 and iso_8601. Defaults to rfc_822. -Note that despite its name, the rfc_822 format does not conform to RFC 822 -or its successors RFC 2822 and RFC 5322. It outputs dates in the format -"Mmm DD HH:MM:SS YYYY GMT" (e.g., "Jul 31 22:20:50 2017 GMT"). The month -appears before the day, unlike all three RFCs, which put the day first. -The 4-digit year differs from RFC 822 (which used 2-digit years), and the -timezone name "GMT" is obsolete per RFC 2822 and RFC 5322 (which require -numeric offsets such as "+0000"). - =item B<-startdate> I, B<-not_before> I This allows the start date to be explicitly set. The format of the @@ -277,6 +270,13 @@ the configuration file which decides which fields should be mandatory or match the CA certificate. Check out the B section for more information. +=item B<-msie_hack> + +This is a deprecated option to make this command work with very old versions +of the IE certificate enrollment control "certenr3". It used UniversalStrings +for almost everything. Since the old control has various security bugs +its use is strongly discouraged. + =item B<-preserveDN> Normally the DN order of a certificate is the same as the order of the @@ -310,9 +310,9 @@ extension section format. =item B<-extfile> I -An additional configuration I to read certificate extensions from -(using its unnamed (C) section unless the B<-extensions> option is -also used). +An additional configuration file to read certificate extensions from +(using the default section unless the B<-extensions> option is also +used). =item B<-subj> I @@ -673,6 +673,12 @@ Sign a certificate request: openssl ca -in req.pem -out newcert.pem +Sign an SM2 certificate request: + + openssl ca -in sm2.csr -out sm2.crt -md sm3 \ + -sigopt "distid:1234567812345678" \ + -vfyopt "distid:1234567812345678" + Sign a certificate request, using CA extensions: openssl ca -in req.pem -extensions v3_ca -out newcert.pem @@ -844,12 +850,6 @@ and key identifier extensions are included by default. The B<-engine> option was removed in OpenSSL 4.0. -The B<-msie-hack> option was removed in OpenSSL 4.0. - -As of OpenSSL 4.0, the B utility no longer has specialised built-in logic -to add the SKID or AKID extensions, they are handled through configuration -files and command-line options just like any other extension. - =head1 SEE ALSO L, @@ -862,7 +862,7 @@ L =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-ciphers.pod.in b/doc/man1/openssl-ciphers.pod.in index db8b6e55e1..217326d122 100644 --- a/doc/man1/openssl-ciphers.pod.in +++ b/doc/man1/openssl-ciphers.pod.in @@ -12,6 +12,7 @@ B B [B<-s>] [B<-v>] [B<-V>] +[B<-ssl3>] [B<-tls1>] [B<-tls1_1>] [B<-tls1_2>] @@ -30,9 +31,6 @@ This command converts textual OpenSSL cipher lists into ordered SSL cipher preference lists. It can be used to determine the appropriate cipherlist. -As of OpenSSL 4.0 the list of TLS 1.3 ciphersuites I and TLS 1.2 ciphers -I are processed case-insensitively. - =head1 OPTIONS =over 4 @@ -78,7 +76,7 @@ L. Like B<-v>, but include the official cipher suite values in hex. -=item B<-tls1_3>, B<-tls1_2>, B<-tls1_1>, B<-tls1> +=item B<-tls1_3>, B<-tls1_2>, B<-tls1_1>, B<-tls1>, B<-ssl3> In combination with the B<-s> option, list the ciphers which could be used if the specified protocol were negotiated. @@ -122,16 +120,16 @@ the IANA TLS Cipher Suites Registry The actual cipher string can take several different forms. -It can consist of a single cipher suite such as B. +It can consist of a single cipher suite such as B. It can represent a list of cipher suites containing a certain algorithm, or -cipher suites of a certain type. For example B represents all cipher -suites using the digest algorithm SHA256 and B represents all -cipher suites introduced in TLS v.1.2. +cipher suites of a certain type. For example B represents all ciphers +suites using the digest algorithm SHA1 and B represents all SSL v3 +algorithms. Lists of cipher suites can be combined in a single cipher string using the B<+> character. This is used as a logical B operation. For example -B represents all cipher suites using the SHA256 B the AES +B represents all cipher suites containing the SHA1 B the DES algorithms. Each cipher string can be optionally preceded by the characters B, @@ -162,7 +160,7 @@ See L for a description of what each level means. The cipher list can be prefixed with the B keyword, which enables the default cipher list as defined below. Unlike cipher strings, this prefix may not be combined with other strings using B<+> character. -For example, B is not valid. +For example, B is not valid. The content of the default list is determined at compile time and normally corresponds to B. @@ -175,12 +173,11 @@ The following is a list of all permitted cipher strings and their meanings. =item B -The cipher suites included in B, but not enabled by default. The default -cipher suite list provides strong security and reasonable interoperability. -A cipher suite can be not included in the default list for different reasons: -because it is weak, or not "mature" enough, or not widely used, etc. -Note that this rule does not cover B, which is not included by B -(use B if necessary). +The ciphers included in B, but not enabled by default. Currently +this includes all RC4 and anonymous ciphers. Note that this rule does +not cover B, which is not included by B (use B if +necessary). Note that RC4 based cipher suites are not built into OpenSSL by +default (see the enable-weak-ssl-ciphers option to Configure). =item B @@ -230,8 +227,14 @@ When in doubt, include B in your cipherlist. =item B, B, B -Cipher suites using RSA key exchange, RSA authentication, or both of them -respectively. +Cipher suites using RSA key exchange or authentication. B is an alias for +B. + +=item B, B, B + +Cipher suites using static DH key agreement and DH certificates signed by CAs +with RSA and DSS keys or either respectively. +All these cipher suites have been removed in OpenSSL 1.1.0. =item B, B, B @@ -264,17 +267,24 @@ Anonymous Elliptic Curve Diffie-Hellman cipher suites. Cipher suites using DSS authentication, i.e. the certificates carry DSS keys. +=item B + +Cipher suites effectively using DH authentication, i.e. the certificates carry +DH keys. +All these cipher suites have been removed in OpenSSL 1.1.0. + =item B, B Cipher suites using ECDSA authentication, i.e. the certificates carry ECDSA keys. -=item B, B +=item B, B, B -Lists cipher suites introduced in TLS v1.2 or TLS v1.0 respectively. +Lists cipher suites which are only supported in at least TLS v1.2, TLS v1.0 or +SSL v3.0 respectively. Note: there are no cipher suites specific to TLS v1.1. -Since this is only the minimum version, if, for example, TLSv1.2 is negotiated -then both TLSv1.2 and TLSv1.0 cipher suites are available. +Since this is only the minimum version, if, for example, TLSv1.0 is negotiated +then both TLSv1.0 and SSLv3.0 cipher suites are available. Note: these cipher strings B change the negotiated version of SSL or TLS, they only affect the list of available cipher suites. @@ -295,13 +305,10 @@ cipher suites are only supported in TLS v1.2. B references CCM cipher suites using both 16 and 8 octet Integrity Check Value (ICV) while B only references 8 octet ICV. -=item B, B +=item B, B, B -Cipher suites using 128 bit ARIA or 256 bit ARIA respectively. - -=item B, B - -Cipher suites using either 128 or 256 bit ARIA. +Cipher suites using 128 bit ARIA, 256 bit ARIA or either 128 or 256 bit +ARIA. =item B, B, B @@ -351,46 +358,24 @@ Cipher suites using SHA256 or SHA384. =item B -Cipher suites using GOST R 34.10 (either 2001 or 2012) for authentication +Cipher suites using GOST R 34.10 (either 2001 or 94) for authentication (needs a provider that supports GOST algorithms). =item B -Cipher suites that can be uses with GOST R 34.10-2001 keys for authentication. - -=item B - -Cipher suites that can be used with GOST R 34.10-2012 keys for authentication. +Cipher suites using GOST R 34.10-2001 authentication. =item B -Cipher suites using VKO 34.10 key exchange and key wrap specified in the -RFC 4357 or RFC 7836. - -=item B - -Cipher suites using VKO 34.10 key exchange specified in the RFC 7836 and -KExp15 key export specified in the RFC 9189. +Cipher suites, using VKO 34.10 key exchange, specified in the RFC 4357. =item B Cipher suites, using HMAC based on GOST R 34.11-94. -=item B - -Cipher suites, using HMAC based on GOST R 34.11-2012 256 bits. - =item B -Cipher suites using GOST 28147-89 MAC B HMAC with S-boxes A. - -=item B - -Cipher suites using GOST 28147-89 MAC B HMAC with S-boxes Z. - -=item B - -Cipher suites using any GOST cipher (GOST 28147-89, Magma or Kuznyechik). +Cipher suites using GOST 28147-89 MAC B HMAC. =item B @@ -405,14 +390,6 @@ Cipher suites using PSK key exchange, ECDHE_PSK, DHE_PSK or RSA_PSK. Cipher suites using PSK authentication (currently all PSK modes apart from RSA_PSK). -=item B, B - -Cipher suites using SRP key exchange. - -=item B - -Cipher suites using SRP authentication. - =item B, B, B Enables suite B mode of operation using 128 (permitting 192 bit mode by peer) @@ -447,398 +424,310 @@ It should be noted, that several cipher suite names do not include the authentication used, e.g. DES-CBC3-SHA. In these cases, RSA authentication is used. -=head2 AES cipher suites for TLS v1.2 +=head2 SSL v3.0 cipher suites - TLS_DH_anon_WITH_AES_128_CBC_SHA256 ADH-AES128-SHA256 - TLS_DH_anon_WITH_AES_128_CBC_SHA ADH-AES128-SHA - TLS_DH_anon_WITH_AES_128_GCM_SHA256 ADH-AES128-GCM-SHA256 - TLS_DH_anon_WITH_AES_256_CBC_SHA256 ADH-AES256-SHA256 - TLS_DH_anon_WITH_AES_256_CBC_SHA ADH-AES256-SHA - TLS_DH_anon_WITH_AES_256_GCM_SHA384 ADH-AES256-GCM-SHA384 - TLS_DHE_DSS_WITH_AES_128_CBC_SHA256 DHE-DSS-AES128-SHA256 - TLS_DHE_DSS_WITH_AES_128_CBC_SHA DHE-DSS-AES128-SHA - TLS_DHE_DSS_WITH_AES_128_GCM_SHA256 DHE-DSS-AES128-GCM-SHA256 - TLS_DHE_DSS_WITH_AES_256_CBC_SHA256 DHE-DSS-AES256-SHA256 - TLS_DHE_DSS_WITH_AES_256_CBC_SHA DHE-DSS-AES256-SHA - TLS_DHE_DSS_WITH_AES_256_GCM_SHA384 DHE-DSS-AES256-GCM-SHA384 - TLS_DHE_PSK_WITH_AES_128_CBC_SHA256 DHE-PSK-AES128-CBC-SHA256 - TLS_DHE_PSK_WITH_AES_128_CBC_SHA DHE-PSK-AES128-CBC-SHA - TLS_DHE_PSK_WITH_AES_128_CCM_8 DHE-PSK-AES128-CCM8 - TLS_DHE_PSK_WITH_AES_128_CCM DHE-PSK-AES128-CCM - TLS_DHE_PSK_WITH_AES_128_GCM_SHA256 DHE-PSK-AES128-GCM-SHA256 - TLS_DHE_PSK_WITH_AES_256_CBC_SHA384 DHE-PSK-AES256-CBC-SHA384 - TLS_DHE_PSK_WITH_AES_256_CBC_SHA DHE-PSK-AES256-CBC-SHA - TLS_DHE_PSK_WITH_AES_256_CCM_8 DHE-PSK-AES256-CCM8 - TLS_DHE_PSK_WITH_AES_256_CCM DHE-PSK-AES256-CCM - TLS_DHE_PSK_WITH_AES_256_GCM_SHA384 DHE-PSK-AES256-GCM-SHA384 - TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 DHE-RSA-AES128-SHA256 - TLS_DHE_RSA_WITH_AES_128_CBC_SHA DHE-RSA-AES128-SHA - TLS_DHE_RSA_WITH_AES_128_CCM_8 DHE-RSA-AES128-CCM8 - TLS_DHE_RSA_WITH_AES_128_CCM DHE-RSA-AES128-CCM - TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 DHE-RSA-AES128-GCM-SHA256 - TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 DHE-RSA-AES256-SHA256 - TLS_DHE_RSA_WITH_AES_256_CBC_SHA DHE-RSA-AES256-SHA - TLS_DHE_RSA_WITH_AES_256_CCM_8 DHE-RSA-AES256-CCM8 - TLS_DHE_RSA_WITH_AES_256_CCM DHE-RSA-AES256-CCM - TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 DHE-RSA-AES256-GCM-SHA384 - TLS_ECDH_anon_WITH_AES_128_CBC_SHA AECDH-AES128-SHA - TLS_ECDH_anon_WITH_AES_128_CCM_8 AECDH-AES128-CCM8 - TLS_ECDH_anon_WITH_AES_128_CCM AECDH-AES128-CCM - TLS_ECDH_anon_WITH_AES_256_CBC_SHA AECDH-AES256-SHA - TLS_ECDH_anon_WITH_AES_256_CCM_8 AECDH-AES256-CCM8 - TLS_ECDH_anon_WITH_AES_256_CCM AECDH-AES256-CCM - TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256 ECDH-ECDSA-AES128-SHA256 - TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA ECDH-ECDSA-AES128-SHA - TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256 ECDH-ECDSA-AES128-GCM-SHA256 - TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384 ECDH-ECDSA-AES256-SHA384 - TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA ECDH-ECDSA-AES256-SHA - TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384 ECDH-ECDSA-AES256-GCM-SHA384 - TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 ECDHE-ECDSA-AES128-SHA256 - TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA ECDHE-ECDSA-AES128-SHA - TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8 ECDHE-ECDSA-AES128-CCM8 - TLS_ECDHE_ECDSA_WITH_AES_128_CCM ECDHE-ECDSA-AES128-CCM - TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 ECDHE-ECDSA-AES128-GCM-SHA256 - TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 ECDHE-ECDSA-AES256-SHA384 - TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA ECDHE-ECDSA-AES256-SHA - TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8 ECDHE-ECDSA-AES256-CCM8 - TLS_ECDHE_ECDSA_WITH_AES_256_CCM ECDHE-ECDSA-AES256-CCM - TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 ECDHE-ECDSA-AES256-GCM-SHA384 - TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256 ECDHE-PSK-AES128-CBC-SHA256 - TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA ECDHE-PSK-AES128-CBC-SHA - TLS_ECDHE_PSK_WITH_AES_128_CCM_8_SHA256 ECDHE-PSK-AES128-CCM8 - TLS_ECDHE_PSK_WITH_AES_128_CCM_SHA256 ECDHE-PSK-AES128-CCM - TLS_ECDHE_PSK_WITH_AES_128_GCM_SHA256 ECDHE-PSK-AES128-GCM-SHA256 - TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA384 ECDHE-PSK-AES256-CBC-SHA384 - TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA ECDHE-PSK-AES256-CBC-SHA - TLS_ECDHE_PSK_WITH_AES_256_GCM_SHA384 ECDHE-PSK-AES256-GCM-SHA384 - TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDHE-RSA-AES128-SHA256 - TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA ECDHE-RSA-AES128-SHA - TLS_ECDHE_RSA_WITH_AES_128_CCM_8 ECDHE-RSA-AES128-CCM8 - TLS_ECDHE_RSA_WITH_AES_128_CCM ECDHE-RSA-AES128-CCM - TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDHE-RSA-AES128-GCM-SHA256 - TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 ECDHE-RSA-AES256-SHA384 - TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA ECDHE-RSA-AES256-SHA - TLS_ECDHE_RSA_WITH_AES_256_CCM_8 ECDHE-RSA-AES256-CCM8 - TLS_ECDHE_RSA_WITH_AES_256_CCM ECDHE-RSA-AES256-CCM - TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDHE-RSA-AES256-GCM-SHA384 - TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256 ECDH-RSA-AES128-SHA256 - TLS_ECDH_RSA_WITH_AES_128_CBC_SHA ECDH-RSA-AES128-SHA - TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256 ECDH-RSA-AES128-GCM-SHA256 - TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384 ECDH-RSA-AES256-SHA384 - TLS_ECDH_RSA_WITH_AES_256_CBC_SHA ECDH-RSA-AES256-SHA - TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384 ECDH-RSA-AES256-GCM-SHA384 - TLS_PSK_WITH_AES_128_CBC_SHA256 PSK-AES128-CBC-SHA256 - TLS_PSK_WITH_AES_128_CBC_SHA PSK-AES128-CBC-SHA - TLS_PSK_WITH_AES_128_CCM_8 PSK-AES128-CCM8 - TLS_PSK_WITH_AES_128_CCM PSK-AES128-CCM - TLS_PSK_WITH_AES_128_GCM_SHA256 PSK-AES128-GCM-SHA256 - TLS_PSK_WITH_AES_256_CBC_SHA384 PSK-AES256-CBC-SHA384 - TLS_PSK_WITH_AES_256_CBC_SHA PSK-AES256-CBC-SHA - TLS_PSK_WITH_AES_256_CCM_8 PSK-AES256-CCM8 - TLS_PSK_WITH_AES_256_CCM PSK-AES256-CCM - TLS_PSK_WITH_AES_256_GCM_SHA384 PSK-AES256-GCM-SHA384 - TLS_RSA_PSK_WITH_AES_128_CBC_SHA256 RSA-PSK-AES128-CBC-SHA256 - TLS_RSA_PSK_WITH_AES_128_CBC_SHA RSA-PSK-AES128-CBC-SHA - TLS_RSA_PSK_WITH_AES_128_GCM_SHA256 RSA-PSK-AES128-GCM-SHA256 - TLS_RSA_PSK_WITH_AES_256_CBC_SHA384 RSA-PSK-AES256-CBC-SHA384 - TLS_RSA_PSK_WITH_AES_256_CBC_SHA RSA-PSK-AES256-CBC-SHA - TLS_RSA_PSK_WITH_AES_256_GCM_SHA384 RSA-PSK-AES256-GCM-SHA384 - TLS_RSA_WITH_AES_128_CBC_SHA256 AES128-SHA256 - TLS_RSA_WITH_AES_128_CBC_SHA AES128-SHA - TLS_RSA_WITH_AES_128_CCM_8 AES128-CCM8 - TLS_RSA_WITH_AES_128_CCM AES128-CCM - TLS_RSA_WITH_AES_128_GCM_SHA256 AES128-GCM-SHA256 - TLS_RSA_WITH_AES_256_CBC_SHA256 AES256-SHA256 - TLS_RSA_WITH_AES_256_CBC_SHA AES256-SHA - TLS_RSA_WITH_AES_256_CCM_8 AES256-CCM8 - TLS_RSA_WITH_AES_256_CCM AES256-CCM - TLS_RSA_WITH_AES_256_GCM_SHA384 AES256-GCM-SHA384 + SSL_RSA_WITH_NULL_MD5 NULL-MD5 + SSL_RSA_WITH_NULL_SHA NULL-SHA + SSL_RSA_WITH_RC4_128_MD5 RC4-MD5 + SSL_RSA_WITH_RC4_128_SHA RC4-SHA + SSL_RSA_WITH_IDEA_CBC_SHA IDEA-CBC-SHA + SSL_RSA_WITH_3DES_EDE_CBC_SHA DES-CBC3-SHA -=head2 Camellia cipher suites for TLS v1.2 + SSL_DH_DSS_WITH_3DES_EDE_CBC_SHA DH-DSS-DES-CBC3-SHA + SSL_DH_RSA_WITH_3DES_EDE_CBC_SHA DH-RSA-DES-CBC3-SHA + SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA DHE-DSS-DES-CBC3-SHA + SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA DHE-RSA-DES-CBC3-SHA - TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA256 ADH-CAMELLIA128-SHA256 - TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA ADH-CAMELLIA128-SHA - TLS_DH_anon_WITH_CAMELLIA_128_GCM_SHA256 ADH-CAMELLIA128-GCM-SHA256 - TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA256 ADH-CAMELLIA256-SHA256 - TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA ADH-CAMELLIA256-SHA - TLS_DH_anon_WITH_CAMELLIA_256_GCM_SHA384 ADH-CAMELLIA256-GCM-SHA384 - TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA256 DHE-DSS-CAMELLIA128-SHA256 - TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA DHE-DSS-CAMELLIA128-SHA - TLS_DHE_DSS_WITH_CAMELLIA_128_GCM_SHA256 DHE-DSS-CAMELLIA128-GCM-SHA256 - TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA256 DHE-DSS-CAMELLIA256-SHA256 - TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA DHE-DSS-CAMELLIA256-SHA - TLS_DHE_DSS_WITH_CAMELLIA_256_GCM_SHA384 DHE-DSS-CAMELLIA256-GCM-SHA384 - TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 DHE-RSA-CAMELLIA128-SHA256 - TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA DHE-RSA-CAMELLIA128-SHA - TLS_DHE_RSA_WITH_CAMELLIA_128_GCM_SHA256 DHE-RSA-CAMELLIA128-GCM-SHA256 - TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256 DHE-RSA-CAMELLIA256-SHA256 - TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA DHE-RSA-CAMELLIA256-SHA - TLS_DHE_RSA_WITH_CAMELLIA_256_GCM_SHA384 DHE-RSA-CAMELLIA256-GCM-SHA384 - TLS_ECDH_ECDSA_WITH_CAMELLIA_128_CBC_SHA256 ECDH-ECDSA-CAMELLIA128-SHA256 - TLS_ECDH_ECDSA_WITH_CAMELLIA_256_CBC_SHA384 ECDH-ECDSA-CAMELLIA256-SHA384 - TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256 ECDHE-ECDSA-CAMELLIA128-SHA256 - TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384 ECDHE-ECDSA-CAMELLIA256-SHA384 - TLS_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 ECDHE-PSK-CAMELLIA128-SHA256 - TLS_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 ECDHE-PSK-CAMELLIA256-SHA384 - TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 ECDHE-RSA-CAMELLIA128-SHA256 - TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384 ECDHE-RSA-CAMELLIA256-SHA384 - TLS_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256 ECDH-RSA-CAMELLIA128-SHA256 - TLS_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384 ECDH-RSA-CAMELLIA256-SHA384 - TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256 CAMELLIA128-SHA256 - TLS_RSA_WITH_CAMELLIA_128_CBC_SHA CAMELLIA128-SHA - TLS_RSA_WITH_CAMELLIA_128_GCM_SHA256 CAMELLIA128-GCM-SHA256 - TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256 CAMELLIA256-SHA256 - TLS_RSA_WITH_CAMELLIA_256_CBC_SHA CAMELLIA256-SHA - TLS_RSA_WITH_CAMELLIA_256_GCM_SHA384 CAMELLIA256-GCM-SHA384 + SSL_DH_anon_WITH_RC4_128_MD5 ADH-RC4-MD5 + SSL_DH_anon_WITH_3DES_EDE_CBC_SHA ADH-DES-CBC3-SHA -=head2 SEED cipher suites for TLS v1.2 + SSL_FORTEZZA_KEA_WITH_NULL_SHA Not implemented. + SSL_FORTEZZA_KEA_WITH_FORTEZZA_CBC_SHA Not implemented. + SSL_FORTEZZA_KEA_WITH_RC4_128_SHA Not implemented. - TLS_DH_anon_WITH_SEED_CBC_SHA ADH-SEED-SHA - TLS_DHE_DSS_WITH_SEED_CBC_SHA DHE-DSS-SEED-SHA - TLS_DHE_RSA_WITH_SEED_CBC_SHA DHE-RSA-SEED-SHA - TLS_RSA_WITH_SEED_CBC_SHA SEED-SHA +=head2 TLS v1.0 cipher suites -=head2 GOST cipher suites for TLS v1.2 + TLS_RSA_WITH_NULL_MD5 NULL-MD5 + TLS_RSA_WITH_NULL_SHA NULL-SHA + TLS_RSA_WITH_RC4_128_MD5 RC4-MD5 + TLS_RSA_WITH_RC4_128_SHA RC4-SHA + TLS_RSA_WITH_IDEA_CBC_SHA IDEA-CBC-SHA + TLS_RSA_WITH_3DES_EDE_CBC_SHA DES-CBC3-SHA + + TLS_DH_DSS_WITH_3DES_EDE_CBC_SHA Not implemented. + TLS_DH_RSA_WITH_3DES_EDE_CBC_SHA Not implemented. + TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA DHE-DSS-DES-CBC3-SHA + TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA DHE-RSA-DES-CBC3-SHA + + TLS_DH_anon_WITH_RC4_128_MD5 ADH-RC4-MD5 + TLS_DH_anon_WITH_3DES_EDE_CBC_SHA ADH-DES-CBC3-SHA + +=head2 AES cipher suites from RFC3268, extending TLS v1.0 + + TLS_RSA_WITH_AES_128_CBC_SHA AES128-SHA + TLS_RSA_WITH_AES_256_CBC_SHA AES256-SHA + + TLS_DH_DSS_WITH_AES_128_CBC_SHA DH-DSS-AES128-SHA + TLS_DH_DSS_WITH_AES_256_CBC_SHA DH-DSS-AES256-SHA + TLS_DH_RSA_WITH_AES_128_CBC_SHA DH-RSA-AES128-SHA + TLS_DH_RSA_WITH_AES_256_CBC_SHA DH-RSA-AES256-SHA + + TLS_DHE_DSS_WITH_AES_128_CBC_SHA DHE-DSS-AES128-SHA + TLS_DHE_DSS_WITH_AES_256_CBC_SHA DHE-DSS-AES256-SHA + TLS_DHE_RSA_WITH_AES_128_CBC_SHA DHE-RSA-AES128-SHA + TLS_DHE_RSA_WITH_AES_256_CBC_SHA DHE-RSA-AES256-SHA + + TLS_DH_anon_WITH_AES_128_CBC_SHA ADH-AES128-SHA + TLS_DH_anon_WITH_AES_256_CBC_SHA ADH-AES256-SHA + +=head2 Camellia cipher suites from RFC4132, extending TLS v1.0 + + TLS_RSA_WITH_CAMELLIA_128_CBC_SHA CAMELLIA128-SHA + TLS_RSA_WITH_CAMELLIA_256_CBC_SHA CAMELLIA256-SHA + + TLS_DH_DSS_WITH_CAMELLIA_128_CBC_SHA DH-DSS-CAMELLIA128-SHA + TLS_DH_DSS_WITH_CAMELLIA_256_CBC_SHA DH-DSS-CAMELLIA256-SHA + TLS_DH_RSA_WITH_CAMELLIA_128_CBC_SHA DH-RSA-CAMELLIA128-SHA + TLS_DH_RSA_WITH_CAMELLIA_256_CBC_SHA DH-RSA-CAMELLIA256-SHA + + TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA DHE-DSS-CAMELLIA128-SHA + TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA DHE-DSS-CAMELLIA256-SHA + TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA DHE-RSA-CAMELLIA128-SHA + TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA DHE-RSA-CAMELLIA256-SHA + + TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA ADH-CAMELLIA128-SHA + TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA ADH-CAMELLIA256-SHA + +=head2 SEED cipher suites from RFC4162, extending TLS v1.0 + + TLS_RSA_WITH_SEED_CBC_SHA SEED-SHA + + TLS_DH_DSS_WITH_SEED_CBC_SHA DH-DSS-SEED-SHA + TLS_DH_RSA_WITH_SEED_CBC_SHA DH-RSA-SEED-SHA + + TLS_DHE_DSS_WITH_SEED_CBC_SHA DHE-DSS-SEED-SHA + TLS_DHE_RSA_WITH_SEED_CBC_SHA DHE-RSA-SEED-SHA + + TLS_DH_anon_WITH_SEED_CBC_SHA ADH-SEED-SHA + +=head2 GOST cipher suites from draft-chudov-cryptopro-cptls, extending TLS v1.0 Note: these ciphers require a provider that supports GOST cryptographic algorithms, such as the B provider, which isn't part of the OpenSSL distribution. - TLS_GOSTR341001_WITH_28147_CNT_IMIT GOST2001-GOST89-GOST89 - TLS_GOSTR341001_WITH_NULL_GOSTR3411 GOST2001-NULL-GOST94 - IANA-GOST2012-GOST8912-GOST8912 - LEGACY-GOST2012-GOST8912-GOST8912 - GOST2012-NULL-GOST12 - GOST2012-KUZNYECHIK-KUZNYECHIKOMAC - GOST2012-MAGMA-MAGMAOMAC + TLS_GOSTR341094_WITH_28147_CNT_IMIT GOST94-GOST89-GOST89 + TLS_GOSTR341001_WITH_28147_CNT_IMIT GOST2001-GOST89-GOST89 + TLS_GOSTR341094_WITH_NULL_GOSTR3411 GOST94-NULL-GOST94 + TLS_GOSTR341001_WITH_NULL_GOSTR3411 GOST2001-NULL-GOST94 + +=head2 GOST cipher suites, extending TLS v1.2 + +Note: these ciphers require a provider that supports GOST cryptographic +algorithms, such as the B provider, which isn't part of the OpenSSL +distribution. + + TLS_GOSTR341112_256_WITH_28147_CNT_IMIT GOST2012-GOST8912-GOST8912 + TLS_GOSTR341112_256_WITH_NULL_GOSTR3411 GOST2012-NULL-GOST12 + +Note: GOST2012-GOST8912-GOST8912 is an alias for two ciphers ID +old LEGACY-GOST2012-GOST8912-GOST8912 and new IANA-GOST2012-GOST8912-GOST8912 + + +=head2 Additional Export 1024 and other cipher suites + +Note: these ciphers can also be used in SSL v3. + + TLS_DHE_DSS_WITH_RC4_128_SHA DHE-DSS-RC4-SHA + +=head2 Elliptic curve cipher suites + + TLS_ECDHE_RSA_WITH_NULL_SHA ECDHE-RSA-NULL-SHA + TLS_ECDHE_RSA_WITH_RC4_128_SHA ECDHE-RSA-RC4-SHA + TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA ECDHE-RSA-DES-CBC3-SHA + TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA ECDHE-RSA-AES128-SHA + TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA ECDHE-RSA-AES256-SHA + + TLS_ECDHE_ECDSA_WITH_NULL_SHA ECDHE-ECDSA-NULL-SHA + TLS_ECDHE_ECDSA_WITH_RC4_128_SHA ECDHE-ECDSA-RC4-SHA + TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA ECDHE-ECDSA-DES-CBC3-SHA + TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA ECDHE-ECDSA-AES128-SHA + TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA ECDHE-ECDSA-AES256-SHA + + TLS_ECDH_anon_WITH_NULL_SHA AECDH-NULL-SHA + TLS_ECDH_anon_WITH_RC4_128_SHA AECDH-RC4-SHA + TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA AECDH-DES-CBC3-SHA + TLS_ECDH_anon_WITH_AES_128_CBC_SHA AECDH-AES128-SHA + TLS_ECDH_anon_WITH_AES_256_CBC_SHA AECDH-AES256-SHA + +=head2 TLS v1.2 cipher suites + + TLS_RSA_WITH_NULL_SHA256 NULL-SHA256 + + TLS_RSA_WITH_AES_128_CBC_SHA256 AES128-SHA256 + TLS_RSA_WITH_AES_256_CBC_SHA256 AES256-SHA256 + TLS_RSA_WITH_AES_128_GCM_SHA256 AES128-GCM-SHA256 + TLS_RSA_WITH_AES_256_GCM_SHA384 AES256-GCM-SHA384 + + TLS_DH_RSA_WITH_AES_128_CBC_SHA256 DH-RSA-AES128-SHA256 + TLS_DH_RSA_WITH_AES_256_CBC_SHA256 DH-RSA-AES256-SHA256 + TLS_DH_RSA_WITH_AES_128_GCM_SHA256 DH-RSA-AES128-GCM-SHA256 + TLS_DH_RSA_WITH_AES_256_GCM_SHA384 DH-RSA-AES256-GCM-SHA384 + + TLS_DH_DSS_WITH_AES_128_CBC_SHA256 DH-DSS-AES128-SHA256 + TLS_DH_DSS_WITH_AES_256_CBC_SHA256 DH-DSS-AES256-SHA256 + TLS_DH_DSS_WITH_AES_128_GCM_SHA256 DH-DSS-AES128-GCM-SHA256 + TLS_DH_DSS_WITH_AES_256_GCM_SHA384 DH-DSS-AES256-GCM-SHA384 + + TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 DHE-RSA-AES128-SHA256 + TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 DHE-RSA-AES256-SHA256 + TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 DHE-RSA-AES128-GCM-SHA256 + TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 DHE-RSA-AES256-GCM-SHA384 + + TLS_DHE_DSS_WITH_AES_128_CBC_SHA256 DHE-DSS-AES128-SHA256 + TLS_DHE_DSS_WITH_AES_256_CBC_SHA256 DHE-DSS-AES256-SHA256 + TLS_DHE_DSS_WITH_AES_128_GCM_SHA256 DHE-DSS-AES128-GCM-SHA256 + TLS_DHE_DSS_WITH_AES_256_GCM_SHA384 DHE-DSS-AES256-GCM-SHA384 + + TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDHE-RSA-AES128-SHA256 + TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 ECDHE-RSA-AES256-SHA384 + TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDHE-RSA-AES128-GCM-SHA256 + TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDHE-RSA-AES256-GCM-SHA384 + + TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 ECDHE-ECDSA-AES128-SHA256 + TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 ECDHE-ECDSA-AES256-SHA384 + TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 ECDHE-ECDSA-AES128-GCM-SHA256 + TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 ECDHE-ECDSA-AES256-GCM-SHA384 + + TLS_DH_anon_WITH_AES_128_CBC_SHA256 ADH-AES128-SHA256 + TLS_DH_anon_WITH_AES_256_CBC_SHA256 ADH-AES256-SHA256 + TLS_DH_anon_WITH_AES_128_GCM_SHA256 ADH-AES128-GCM-SHA256 + TLS_DH_anon_WITH_AES_256_GCM_SHA384 ADH-AES256-GCM-SHA384 + + RSA_WITH_AES_128_CCM AES128-CCM + RSA_WITH_AES_256_CCM AES256-CCM + DHE_RSA_WITH_AES_128_CCM DHE-RSA-AES128-CCM + DHE_RSA_WITH_AES_256_CCM DHE-RSA-AES256-CCM + RSA_WITH_AES_128_CCM_8 AES128-CCM8 + RSA_WITH_AES_256_CCM_8 AES256-CCM8 + DHE_RSA_WITH_AES_128_CCM_8 DHE-RSA-AES128-CCM8 + DHE_RSA_WITH_AES_256_CCM_8 DHE-RSA-AES256-CCM8 + ECDHE_ECDSA_WITH_AES_128_CCM ECDHE-ECDSA-AES128-CCM + ECDHE_ECDSA_WITH_AES_256_CCM ECDHE-ECDSA-AES256-CCM + ECDHE_ECDSA_WITH_AES_128_CCM_8 ECDHE-ECDSA-AES128-CCM8 + ECDHE_ECDSA_WITH_AES_256_CCM_8 ECDHE-ECDSA-AES256-CCM8 =head2 ARIA cipher suites from RFC6209, extending TLS v1.2 Note: the CBC modes mentioned in this RFC are not supported. - TLS_DH_anon_WITH_ARIA_128_CBC_SHA256 ADH-ARIA128-CBC-SHA256 - TLS_DH_anon_WITH_ARIA_128_GCM_SHA256 ADH-ARIA128-GCM-SHA256 - TLS_DH_anon_WITH_ARIA_256_CBC_SHA384 ADH-ARIA256-CBC-SHA384 - TLS_DH_anon_WITH_ARIA_256_GCM_SHA384 ADH-ARIA256-GCM-SHA384 - TLS_DHE_DSS_WITH_ARIA_128_GCM_SHA256 DHE-DSS-ARIA128-GCM-SHA256 - TLS_DHE_DSS_WITH_ARIA_256_GCM_SHA384 DHE-DSS-ARIA256-GCM-SHA384 - TLS_DHE_PSK_WITH_ARIA_128_CBC_SHA256 DHE-PSK-ARIA128-CBC-SHA256 - TLS_DHE_PSK_WITH_ARIA_128_GCM_SHA256 DHE-PSK-ARIA128-GCM-SHA256 - TLS_DHE_PSK_WITH_ARIA_256_CBC_SHA384 DHE-PSK-ARIA256-CBC-SHA384 - TLS_DHE_PSK_WITH_ARIA_256_GCM_SHA384 DHE-PSK-ARIA256-GCM-SHA384 - TLS_DHE_RSA_WITH_ARIA_128_CBC_SHA256 DHE-RSA-ARIA128-CBC-SHA256 - TLS_DHE_RSA_WITH_ARIA_128_GCM_SHA256 DHE-RSA-ARIA128-GCM-SHA256 - TLS_DHE_RSA_WITH_ARIA_256_CBC_SHA384 DHE-RSA-ARIA256-CBC-SHA384 - TLS_DHE_RSA_WITH_ARIA_256_GCM_SHA384 DHE-RSA-ARIA256-GCM-SHA384 - TLS_ECDHE_ECDSA_WITH_ARIA_128_CBC_SHA256 ECDHE-ECDSA-ARIA128-CBC-SHA256 - TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256 ECDHE-ECDSA-ARIA128-GCM-SHA256 - TLS_ECDHE_ECDSA_WITH_ARIA_256_CBC_SHA384 ECDHE-ECDSA-ARIA256-CBC-SHA384 - TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384 ECDHE-ECDSA-ARIA256-GCM-SHA384 - TLS_ECDHE_PSK_WITH_ARIA_128_CBC_SHA256 ECDHE-PSK-ARIA128-CBC-SHA256 - TLS_ECDHE_PSK_WITH_ARIA_128_GCM_SHA256 ECDHE-PSK-ARIA128-GCM-SHA256 - TLS_ECDHE_PSK_WITH_ARIA_256_CBC_SHA384 ECDHE-PSK-ARIA256-CBC-SHA384 - TLS_ECDHE_PSK_WITH_ARIA_256_GCM_SHA384 ECDHE-PSK-ARIA256-GCM-SHA384 - TLS_ECDHE_RSA_WITH_ARIA_128_CBC_SHA256 ECDHE-RSA-ARIA128-CBC-SHA256 - TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256 ECDHE-RSA-ARIA128-GCM-SHA256 - TLS_ECDHE_RSA_WITH_ARIA_256_CBC_SHA384 ECDHE-RSA-ARIA256-CBC-SHA384 - TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384 ECDHE-RSA-ARIA256-GCM-SHA384 - TLS_PSK_WITH_ARIA_128_CBC_SHA256 PSK-ARIA128-CBC-SHA256 - TLS_PSK_WITH_ARIA_128_GCM_SHA256 PSK-ARIA128-GCM-SHA256 - TLS_PSK_WITH_ARIA_256_GCM_SHA384 PSK-ARIA256-GCM-SHA384 - TLS_RSA_PSK_WITH_ARIA_128_CBC_SHA256 RSA-PSK-ARIA128-CBC-SHA256 - TLS_RSA_PSK_WITH_ARIA_128_GCM_SHA256 RSA-PSK-ARIA128-GCM-SHA256 - TLS_RSA_PSK_WITH_ARIA_256_CBC_SHA384 RSA-PSK-ARIA256-CBC-SHA384 - TLS_RSA_PSK_WITH_ARIA_256_GCM_SHA384 RSA-PSK-ARIA256-GCM-SHA384 - TLS_RSA_WITH_ARIA_128_CBC_SHA256 ARIA128-CBC-SHA256 - TLS_RSA_WITH_ARIA_128_GCM_SHA256 ARIA128-GCM-SHA256 - TLS_RSA_WITH_ARIA_256_CBC_SHA384 ARIA256-CBC-SHA384 - TLS_RSA_WITH_ARIA_256_GCM_SHA384 ARIA256-GCM-SHA384 + TLS_RSA_WITH_ARIA_128_GCM_SHA256 ARIA128-GCM-SHA256 + TLS_RSA_WITH_ARIA_256_GCM_SHA384 ARIA256-GCM-SHA384 + TLS_DHE_RSA_WITH_ARIA_128_GCM_SHA256 DHE-RSA-ARIA128-GCM-SHA256 + TLS_DHE_RSA_WITH_ARIA_256_GCM_SHA384 DHE-RSA-ARIA256-GCM-SHA384 + TLS_DHE_DSS_WITH_ARIA_128_GCM_SHA256 DHE-DSS-ARIA128-GCM-SHA256 + TLS_DHE_DSS_WITH_ARIA_256_GCM_SHA384 DHE-DSS-ARIA256-GCM-SHA384 + TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256 ECDHE-ECDSA-ARIA128-GCM-SHA256 + TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384 ECDHE-ECDSA-ARIA256-GCM-SHA384 + TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256 ECDHE-ARIA128-GCM-SHA256 + TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384 ECDHE-ARIA256-GCM-SHA384 + TLS_PSK_WITH_ARIA_128_GCM_SHA256 PSK-ARIA128-GCM-SHA256 + TLS_PSK_WITH_ARIA_256_GCM_SHA384 PSK-ARIA256-GCM-SHA384 + TLS_DHE_PSK_WITH_ARIA_128_GCM_SHA256 DHE-PSK-ARIA128-GCM-SHA256 + TLS_DHE_PSK_WITH_ARIA_256_GCM_SHA384 DHE-PSK-ARIA256-GCM-SHA384 + TLS_RSA_PSK_WITH_ARIA_128_GCM_SHA256 RSA-PSK-ARIA128-GCM-SHA256 + TLS_RSA_PSK_WITH_ARIA_256_GCM_SHA384 RSA-PSK-ARIA256-GCM-SHA384 -=head2 ChaCha20-Poly1305 cipher suites, extending TLS v1.2 +=head2 Camellia HMAC-Based cipher suites from RFC6367, extending TLS v1.2 - TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256 DHE-PSK-CHACHA20-POLY1305 - TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256 DHE-RSA-CHACHA20-POLY1305 - TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 ECDHE-ECDSA-CHACHA20-POLY1305 - TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256 ECDHE-PSK-CHACHA20-POLY1305 - TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDHE-RSA-CHACHA20-POLY1305 - TLS_PSK_WITH_CHACHA20_POLY1305_SHA256 PSK-CHACHA20-POLY1305 - TLS_RSA_PSK_WITH_CHACHA20_POLY1305_SHA256 RSA-PSK-CHACHA20-POLY1305 - -=head2 Elliptic curve cipher suites for TLS v.1.2 - - TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA AECDH-DES-CBC3-SHA - TLS_ECDH_anon_WITH_AES_128_CBC_SHA AECDH-AES128-SHA - TLS_ECDH_anon_WITH_AES_128_CCM_8 AECDH-AES128-CCM8 - TLS_ECDH_anon_WITH_AES_128_CCM AECDH-AES128-CCM - TLS_ECDH_anon_WITH_AES_256_CBC_SHA AECDH-AES256-SHA - TLS_ECDH_anon_WITH_AES_256_CCM_8 AECDH-AES256-CCM8 - TLS_ECDH_anon_WITH_AES_256_CCM AECDH-AES256-CCM - TLS_ECDH_anon_WITH_RC4_128_SHA AECDH-RC4-SHA - TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA ECDH-ECDSA-DES-CBC3-SHA - TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256 ECDH-ECDSA-AES128-SHA256 - TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA ECDH-ECDSA-AES128-SHA - TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256 ECDH-ECDSA-AES128-GCM-SHA256 - TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384 ECDH-ECDSA-AES256-SHA384 - TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA ECDH-ECDSA-AES256-SHA - TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384 ECDH-ECDSA-AES256-GCM-SHA384 - TLS_ECDH_ECDSA_WITH_CAMELLIA_128_CBC_SHA256 ECDH-ECDSA-CAMELLIA128-SHA256 - TLS_ECDH_ECDSA_WITH_CAMELLIA_256_CBC_SHA384 ECDH-ECDSA-CAMELLIA256-SHA384 - TLS_ECDH_ECDSA_WITH_RC4_128_SHA ECDH-ECDSA-RC4-SHA - TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA ECDH-RSA-DES-CBC3-SHA - TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256 ECDH-RSA-AES128-SHA256 - TLS_ECDH_RSA_WITH_AES_128_CBC_SHA ECDH-RSA-AES128-SHA - TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256 ECDH-RSA-AES128-GCM-SHA256 - TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384 ECDH-RSA-AES256-SHA384 - TLS_ECDH_RSA_WITH_AES_256_CBC_SHA ECDH-RSA-AES256-SHA - TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384 ECDH-RSA-AES256-GCM-SHA384 - TLS_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256 ECDH-RSA-CAMELLIA128-SHA256 - TLS_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384 ECDH-RSA-CAMELLIA256-SHA384 - TLS_ECDH_RSA_WITH_RC4_128_SHA ECDH-RSA-RC4-SHA - TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA ECDHE-ECDSA-DES-CBC3-SHA - TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 ECDHE-ECDSA-AES128-SHA256 - TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA ECDHE-ECDSA-AES128-SHA - TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8 ECDHE-ECDSA-AES128-CCM8 - TLS_ECDHE_ECDSA_WITH_AES_128_CCM ECDHE-ECDSA-AES128-CCM - TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 ECDHE-ECDSA-AES128-GCM-SHA256 - TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 ECDHE-ECDSA-AES256-SHA384 - TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA ECDHE-ECDSA-AES256-SHA - TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8 ECDHE-ECDSA-AES256-CCM8 - TLS_ECDHE_ECDSA_WITH_AES_256_CCM ECDHE-ECDSA-AES256-CCM - TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 ECDHE-ECDSA-AES256-GCM-SHA384 - TLS_ECDHE_ECDSA_WITH_ARIA_128_CBC_SHA256 ECDHE-ECDSA-ARIA128-CBC-SHA256 - TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256 ECDHE-ECDSA-ARIA128-GCM-SHA256 - TLS_ECDHE_ECDSA_WITH_ARIA_256_CBC_SHA384 ECDHE-ECDSA-ARIA256-CBC-SHA384 - TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384 ECDHE-ECDSA-ARIA256-GCM-SHA384 - TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256 ECDHE-ECDSA-CAMELLIA128-SHA256 - TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384 ECDHE-ECDSA-CAMELLIA256-SHA384 - TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 ECDHE-ECDSA-CHACHA20-POLY1305 - TLS_ECDHE_ECDSA_WITH_RC4_128_SHA ECDHE-ECDSA-RC4-SHA - TLS_ECDHE_ECDSA_WITH_SM4_CCM_SM3 ECDHE-ECDSA-SM4-CCM-SM3 - TLS_ECDHE_ECDSA_WITH_SM4_GCM_SM3 ECDHE-ECDSA-SM4-GCM-SM3 - TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA ECDHE-RSA-DES-CBC3-SHA - TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 ECDHE-RSA-AES128-SHA256 - TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA ECDHE-RSA-AES128-SHA - TLS_ECDHE_RSA_WITH_AES_128_CCM_8 ECDHE-RSA-AES128-CCM8 - TLS_ECDHE_RSA_WITH_AES_128_CCM ECDHE-RSA-AES128-CCM - TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 ECDHE-RSA-AES128-GCM-SHA256 - TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 ECDHE-RSA-AES256-SHA384 - TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA ECDHE-RSA-AES256-SHA - TLS_ECDHE_RSA_WITH_AES_256_CCM_8 ECDHE-RSA-AES256-CCM8 - TLS_ECDHE_RSA_WITH_AES_256_CCM ECDHE-RSA-AES256-CCM - TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ECDHE-RSA-AES256-GCM-SHA384 - TLS_ECDHE_RSA_WITH_ARIA_128_CBC_SHA256 ECDHE-RSA-ARIA128-CBC-SHA256 - TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256 ECDHE-RSA-ARIA128-GCM-SHA256 - TLS_ECDHE_RSA_WITH_ARIA_256_CBC_SHA384 ECDHE-RSA-ARIA256-CBC-SHA384 - TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384 ECDHE-RSA-ARIA256-GCM-SHA384 - TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 ECDHE-RSA-CAMELLIA128-SHA256 - TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384 ECDHE-RSA-CAMELLIA256-SHA384 - TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDHE-RSA-CHACHA20-POLY1305 - TLS_ECDHE_RSA_WITH_RC4_128_SHA ECDHE-RSA-RC4-SHA - TLS_ECDHE_RSA_WITH_SM4_CCM_SM3 ECDHE-RSA-SM4-CCM-SM3 - TLS_ECDHE_RSA_WITH_SM4_GCM_SM3 ECDHE-RSA-SM4-GCM-SM3 - TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA ECDHE-PSK-DES-CBC3-SHA - TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256 ECDHE-PSK-AES128-CBC-SHA256 - TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA ECDHE-PSK-AES128-CBC-SHA - TLS_ECDHE_PSK_WITH_AES_128_CCM_8_SHA256 ECDHE-PSK-AES128-CCM8 - TLS_ECDHE_PSK_WITH_AES_128_CCM_SHA256 ECDHE-PSK-AES128-CCM - TLS_ECDHE_PSK_WITH_AES_128_GCM_SHA256 ECDHE-PSK-AES128-GCM-SHA256 - TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA384 ECDHE-PSK-AES256-CBC-SHA384 - TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA ECDHE-PSK-AES256-CBC-SHA - TLS_ECDHE_PSK_WITH_AES_256_GCM_SHA384 ECDHE-PSK-AES256-GCM-SHA384 - TLS_ECDHE_PSK_WITH_ARIA_128_CBC_SHA256 ECDHE-PSK-ARIA128-CBC-SHA256 - TLS_ECDHE_PSK_WITH_ARIA_128_GCM_SHA256 ECDHE-PSK-ARIA128-GCM-SHA256 - TLS_ECDHE_PSK_WITH_ARIA_256_CBC_SHA384 ECDHE-PSK-ARIA256-CBC-SHA384 - TLS_ECDHE_PSK_WITH_ARIA_256_GCM_SHA384 ECDHE-PSK-ARIA256-GCM-SHA384 - TLS_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 ECDHE-PSK-CAMELLIA128-SHA256 - TLS_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 ECDHE-PSK-CAMELLIA256-SHA384 - TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256 ECDHE-PSK-CHACHA20-POLY1305 - TLS_ECDHE_PSK_WITH_RC4_128_SHA ECDHE-PSK-RC4-SHA - TLS_ECDHE_PSK_WITH_SM4_CCM_SM3 ECDHE-PSK-SM4-CCM-SM3 - TLS_ECDHE_PSK_WITH_SM4_GCM_SM3 ECDHE-PSK-SM4-GCM-SM3 + TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256 ECDHE-ECDSA-CAMELLIA128-SHA256 + TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384 ECDHE-ECDSA-CAMELLIA256-SHA384 + TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 ECDHE-RSA-CAMELLIA128-SHA256 + TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384 ECDHE-RSA-CAMELLIA256-SHA384 =head2 Pre-shared keying (PSK) cipher suites - TLS_DHE_PSK_WITH_AES_128_CBC_SHA256 DHE-PSK-AES128-CBC-SHA256 - TLS_DHE_PSK_WITH_AES_128_CBC_SHA DHE-PSK-AES128-CBC-SHA - TLS_DHE_PSK_WITH_AES_128_CCM_8 DHE-PSK-AES128-CCM8 - TLS_DHE_PSK_WITH_AES_128_CCM DHE-PSK-AES128-CCM - TLS_DHE_PSK_WITH_AES_128_GCM_SHA256 DHE-PSK-AES128-GCM-SHA256 - TLS_DHE_PSK_WITH_AES_256_CBC_SHA384 DHE-PSK-AES256-CBC-SHA384 - TLS_DHE_PSK_WITH_AES_256_CBC_SHA DHE-PSK-AES256-CBC-SHA - TLS_DHE_PSK_WITH_AES_256_CCM_8 DHE-PSK-AES256-CCM8 - TLS_DHE_PSK_WITH_AES_256_CCM DHE-PSK-AES256-CCM - TLS_DHE_PSK_WITH_AES_256_GCM_SHA384 DHE-PSK-AES256-GCM-SHA384 - TLS_DHE_PSK_WITH_ARIA_128_CBC_SHA256 DHE-PSK-ARIA128-CBC-SHA256 - TLS_DHE_PSK_WITH_ARIA_128_GCM_SHA256 DHE-PSK-ARIA128-GCM-SHA256 - TLS_DHE_PSK_WITH_ARIA_256_CBC_SHA384 DHE-PSK-ARIA256-CBC-SHA384 - TLS_DHE_PSK_WITH_ARIA_256_GCM_SHA384 DHE-PSK-ARIA256-GCM-SHA384 - TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256 DHE-PSK-CHACHA20-POLY1305 - TLS_DHE_PSK_WITH_SM4_CCM_SM3 DHE-PSK-SM4-CCM-SM3 - TLS_DHE_PSK_WITH_SM4_GCM_SM3 DHE-PSK-SM4-GCM-SM3 - TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA ECDHE-PSK-DES-CBC3-SHA - TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256 ECDHE-PSK-AES128-CBC-SHA256 - TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA ECDHE-PSK-AES128-CBC-SHA - TLS_ECDHE_PSK_WITH_AES_128_CCM_8_SHA256 ECDHE-PSK-AES128-CCM8 - TLS_ECDHE_PSK_WITH_AES_128_CCM_SHA256 ECDHE-PSK-AES128-CCM - TLS_ECDHE_PSK_WITH_AES_128_GCM_SHA256 ECDHE-PSK-AES128-GCM-SHA256 - TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA384 ECDHE-PSK-AES256-CBC-SHA384 - TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA ECDHE-PSK-AES256-CBC-SHA - TLS_ECDHE_PSK_WITH_AES_256_GCM_SHA384 ECDHE-PSK-AES256-GCM-SHA384 - TLS_ECDHE_PSK_WITH_ARIA_128_CBC_SHA256 ECDHE-PSK-ARIA128-CBC-SHA256 - TLS_ECDHE_PSK_WITH_ARIA_128_GCM_SHA256 ECDHE-PSK-ARIA128-GCM-SHA256 - TLS_ECDHE_PSK_WITH_ARIA_256_CBC_SHA384 ECDHE-PSK-ARIA256-CBC-SHA384 - TLS_ECDHE_PSK_WITH_ARIA_256_GCM_SHA384 ECDHE-PSK-ARIA256-GCM-SHA384 - TLS_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 ECDHE-PSK-CAMELLIA128-SHA256 - TLS_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 ECDHE-PSK-CAMELLIA256-SHA384 - TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256 ECDHE-PSK-CHACHA20-POLY1305 - TLS_ECDHE_PSK_WITH_RC4_128_SHA ECDHE-PSK-RC4-SHA - TLS_ECDHE_PSK_WITH_SM4_CCM_SM3 ECDHE-PSK-SM4-CCM-SM3 - TLS_ECDHE_PSK_WITH_SM4_GCM_SM3 ECDHE-PSK-SM4-GCM-SM3 - TLS_PSK_WITH_AES_128_CBC_SHA256 PSK-AES128-CBC-SHA256 - TLS_PSK_WITH_AES_128_CBC_SHA PSK-AES128-CBC-SHA - TLS_PSK_WITH_AES_128_CCM_8 PSK-AES128-CCM8 - TLS_PSK_WITH_AES_128_CCM PSK-AES128-CCM - TLS_PSK_WITH_AES_128_GCM_SHA256 PSK-AES128-GCM-SHA256 - TLS_PSK_WITH_AES_256_CBC_SHA384 PSK-AES256-CBC-SHA384 - TLS_PSK_WITH_AES_256_CBC_SHA PSK-AES256-CBC-SHA - TLS_PSK_WITH_AES_256_CCM_8 PSK-AES256-CCM8 - TLS_PSK_WITH_AES_256_CCM PSK-AES256-CCM - TLS_PSK_WITH_AES_256_GCM_SHA384 PSK-AES256-GCM-SHA384 - TLS_PSK_WITH_ARIA_128_CBC_SHA256 PSK-ARIA128-CBC-SHA256 - TLS_PSK_WITH_ARIA_128_GCM_SHA256 PSK-ARIA128-GCM-SHA256 - TLS_PSK_WITH_ARIA_256_GCM_SHA384 PSK-ARIA256-GCM-SHA384 - TLS_PSK_WITH_CHACHA20_POLY1305_SHA256 PSK-CHACHA20-POLY1305 - TLS_RSA_PSK_WITH_AES_128_CBC_SHA256 RSA-PSK-AES128-CBC-SHA256 - TLS_RSA_PSK_WITH_AES_128_CBC_SHA RSA-PSK-AES128-CBC-SHA - TLS_RSA_PSK_WITH_AES_128_GCM_SHA256 RSA-PSK-AES128-GCM-SHA256 - TLS_RSA_PSK_WITH_AES_256_CBC_SHA384 RSA-PSK-AES256-CBC-SHA384 - TLS_RSA_PSK_WITH_AES_256_CBC_SHA RSA-PSK-AES256-CBC-SHA - TLS_RSA_PSK_WITH_AES_256_GCM_SHA384 RSA-PSK-AES256-GCM-SHA384 - TLS_RSA_PSK_WITH_ARIA_128_CBC_SHA256 RSA-PSK-ARIA128-CBC-SHA256 - TLS_RSA_PSK_WITH_ARIA_128_GCM_SHA256 RSA-PSK-ARIA128-GCM-SHA256 - TLS_RSA_PSK_WITH_ARIA_256_CBC_SHA384 RSA-PSK-ARIA256-CBC-SHA384 - TLS_RSA_PSK_WITH_ARIA_256_GCM_SHA384 RSA-PSK-ARIA256-GCM-SHA384 - TLS_RSA_PSK_WITH_CHACHA20_POLY1305_SHA256 RSA-PSK-CHACHA20-POLY1305 - TLS_RSA_PSK_WITH_SM4_CCM_SM3 RSA-PSK-SM4-CCM-SM3 - TLS_RSA_PSK_WITH_SM4_GCM_SM3 RSA-PSK-SM4-GCM-SM3 + PSK_WITH_NULL_SHA PSK-NULL-SHA + DHE_PSK_WITH_NULL_SHA DHE-PSK-NULL-SHA + RSA_PSK_WITH_NULL_SHA RSA-PSK-NULL-SHA -=head2 Other TLS v1.2 cipher suites + PSK_WITH_RC4_128_SHA PSK-RC4-SHA + PSK_WITH_3DES_EDE_CBC_SHA PSK-3DES-EDE-CBC-SHA + PSK_WITH_AES_128_CBC_SHA PSK-AES128-CBC-SHA + PSK_WITH_AES_256_CBC_SHA PSK-AES256-CBC-SHA - TLS_RSA_WITH_NULL_MD5 NULL-MD5 - TLS_RSA_WITH_NULL_SHA NULL-SHA - TLS_RSA_WITH_NULL_SHA256 NULL-SHA256 - TLS_RSA_WITH_RC4_128_MD5 RC4-MD5 - TLS_RSA_WITH_RC4_128_SHA RC4-SHA - TLS_RSA_WITH_IDEA_CBC_SHA IDEA-CBC-SHA - TLS_RSA_WITH_3DES_EDE_CBC_SHA DES-CBC3-SHA - TLS_RSA_WITH_SM4_CCM_SM3 SM4-CCM-SM3 - TLS_RSA_WITH_SM4_GCM_SM3 SM4-GCM-SM3 - TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA DHE-DSS-DES-CBC3-SHA - TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA DHE-RSA-DES-CBC3-SHA - TLS_DHE_RSA_WITH_SM4_CCM_SM3 DHE-RSA-SM4-CCM-SM3 - TLS_DHE_RSA_WITH_SM4_GCM_SM3 DHE-RSA-SM4-GCM-SM3 - TLS_DH_anon_WITH_RC4_128_MD5 ADH-RC4-MD5 - TLS_DH_anon_WITH_3DES_EDE_CBC_SHA ADH-DES-CBC3-SHA + DHE_PSK_WITH_RC4_128_SHA DHE-PSK-RC4-SHA + DHE_PSK_WITH_3DES_EDE_CBC_SHA DHE-PSK-3DES-EDE-CBC-SHA + DHE_PSK_WITH_AES_128_CBC_SHA DHE-PSK-AES128-CBC-SHA + DHE_PSK_WITH_AES_256_CBC_SHA DHE-PSK-AES256-CBC-SHA + + RSA_PSK_WITH_RC4_128_SHA RSA-PSK-RC4-SHA + RSA_PSK_WITH_3DES_EDE_CBC_SHA RSA-PSK-3DES-EDE-CBC-SHA + RSA_PSK_WITH_AES_128_CBC_SHA RSA-PSK-AES128-CBC-SHA + RSA_PSK_WITH_AES_256_CBC_SHA RSA-PSK-AES256-CBC-SHA + + PSK_WITH_AES_128_GCM_SHA256 PSK-AES128-GCM-SHA256 + PSK_WITH_AES_256_GCM_SHA384 PSK-AES256-GCM-SHA384 + DHE_PSK_WITH_AES_128_GCM_SHA256 DHE-PSK-AES128-GCM-SHA256 + DHE_PSK_WITH_AES_256_GCM_SHA384 DHE-PSK-AES256-GCM-SHA384 + RSA_PSK_WITH_AES_128_GCM_SHA256 RSA-PSK-AES128-GCM-SHA256 + RSA_PSK_WITH_AES_256_GCM_SHA384 RSA-PSK-AES256-GCM-SHA384 + + PSK_WITH_AES_128_CBC_SHA256 PSK-AES128-CBC-SHA256 + PSK_WITH_AES_256_CBC_SHA384 PSK-AES256-CBC-SHA384 + PSK_WITH_NULL_SHA256 PSK-NULL-SHA256 + PSK_WITH_NULL_SHA384 PSK-NULL-SHA384 + DHE_PSK_WITH_AES_128_CBC_SHA256 DHE-PSK-AES128-CBC-SHA256 + DHE_PSK_WITH_AES_256_CBC_SHA384 DHE-PSK-AES256-CBC-SHA384 + DHE_PSK_WITH_NULL_SHA256 DHE-PSK-NULL-SHA256 + DHE_PSK_WITH_NULL_SHA384 DHE-PSK-NULL-SHA384 + RSA_PSK_WITH_AES_128_CBC_SHA256 RSA-PSK-AES128-CBC-SHA256 + RSA_PSK_WITH_AES_256_CBC_SHA384 RSA-PSK-AES256-CBC-SHA384 + RSA_PSK_WITH_NULL_SHA256 RSA-PSK-NULL-SHA256 + RSA_PSK_WITH_NULL_SHA384 RSA-PSK-NULL-SHA384 + PSK_WITH_AES_128_GCM_SHA256 PSK-AES128-GCM-SHA256 + PSK_WITH_AES_256_GCM_SHA384 PSK-AES256-GCM-SHA384 + + ECDHE_PSK_WITH_RC4_128_SHA ECDHE-PSK-RC4-SHA + ECDHE_PSK_WITH_3DES_EDE_CBC_SHA ECDHE-PSK-3DES-EDE-CBC-SHA + ECDHE_PSK_WITH_AES_128_CBC_SHA ECDHE-PSK-AES128-CBC-SHA + ECDHE_PSK_WITH_AES_256_CBC_SHA ECDHE-PSK-AES256-CBC-SHA + ECDHE_PSK_WITH_AES_128_CBC_SHA256 ECDHE-PSK-AES128-CBC-SHA256 + ECDHE_PSK_WITH_AES_256_CBC_SHA384 ECDHE-PSK-AES256-CBC-SHA384 + ECDHE_PSK_WITH_NULL_SHA ECDHE-PSK-NULL-SHA + ECDHE_PSK_WITH_NULL_SHA256 ECDHE-PSK-NULL-SHA256 + ECDHE_PSK_WITH_NULL_SHA384 ECDHE-PSK-NULL-SHA384 + + PSK_WITH_CAMELLIA_128_CBC_SHA256 PSK-CAMELLIA128-SHA256 + PSK_WITH_CAMELLIA_256_CBC_SHA384 PSK-CAMELLIA256-SHA384 + + DHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 DHE-PSK-CAMELLIA128-SHA256 + DHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 DHE-PSK-CAMELLIA256-SHA384 + + RSA_PSK_WITH_CAMELLIA_128_CBC_SHA256 RSA-PSK-CAMELLIA128-SHA256 + RSA_PSK_WITH_CAMELLIA_256_CBC_SHA384 RSA-PSK-CAMELLIA256-SHA384 + + ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 ECDHE-PSK-CAMELLIA128-SHA256 + ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 ECDHE-PSK-CAMELLIA256-SHA384 + + PSK_WITH_AES_128_CCM PSK-AES128-CCM + PSK_WITH_AES_256_CCM PSK-AES256-CCM + DHE_PSK_WITH_AES_128_CCM DHE-PSK-AES128-CCM + DHE_PSK_WITH_AES_256_CCM DHE-PSK-AES256-CCM + PSK_WITH_AES_128_CCM_8 PSK-AES128-CCM8 + PSK_WITH_AES_256_CCM_8 PSK-AES256-CCM8 + DHE_PSK_WITH_AES_128_CCM_8 DHE-PSK-AES128-CCM8 + DHE_PSK_WITH_AES_256_CCM_8 DHE-PSK-AES256-CCM8 + +=head2 ChaCha20-Poly1305 cipher suites, extending TLS v1.2 + + TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 ECDHE-RSA-CHACHA20-POLY1305 + TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 ECDHE-ECDSA-CHACHA20-POLY1305 + TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256 DHE-RSA-CHACHA20-POLY1305 + TLS_PSK_WITH_CHACHA20_POLY1305_SHA256 PSK-CHACHA20-POLY1305 + TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256 ECDHE-PSK-CHACHA20-POLY1305 + TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256 DHE-PSK-CHACHA20-POLY1305 + TLS_RSA_PSK_WITH_CHACHA20_POLY1305_SHA256 RSA-PSK-CHACHA20-POLY1305 =head2 TLS v1.3 cipher suites @@ -847,8 +736,6 @@ Note: the CBC modes mentioned in this RFC are not supported. TLS_CHACHA20_POLY1305_SHA256 TLS_CHACHA20_POLY1305_SHA256 TLS_AES_128_CCM_SHA256 TLS_AES_128_CCM_SHA256 TLS_AES_128_CCM_8_SHA256 TLS_AES_128_CCM_8_SHA256 - TLS_SM4_GCM_SM3 TLS_SM4_GCM_SM3 - TLS_SM4_CCM_SM3 TLS_SM4_CCM_SM3 =head2 TLS v1.3 integrity-only cipher suites according to RFC 9150 @@ -859,12 +746,12 @@ Note: these ciphers are purely HMAC based and do not provide any confidentiality and thus are disabled by default. These ciphers are only available at security level 0. -=head2 "EDH-" aliases to "DHE-" names for backward compatibility +=head2 Older names used by OpenSSL The following names are accepted by older releases: - EDH-RSA-DES-CBC3-SHA - alias of DHE-RSA-DES-CBC3-SHA - EDH-DSS-DES-CBC3-SHA - alias of DHE-DSS-DES-CBC3-SHA + SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA EDH-RSA-DES-CBC3-SHA (DHE-RSA-DES-CBC3-SHA) + SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA EDH-DSS-DES-CBC3-SHA (DHE-DSS-DES-CBC3-SHA) =head1 NOTES @@ -887,9 +774,13 @@ authentication (aNULL): openssl ciphers -v 'ALL:!aNULL' -Include only AES ciphers and then place RSA ciphers last: +Include only 3DES ciphers and then place RSA ciphers last: - openssl ciphers -v 'AES:+RSA' + openssl ciphers -v '3DES:+RSA' + +Include all RC4 ciphers but leave out those without authentication: + + openssl ciphers -v 'RC4:!COMPLEMENTOFDEFAULT' Include all ciphers with RSA authentication but leave out ciphers without encryption. @@ -921,12 +812,9 @@ OpenSSL 3.2.0. The support for TLS v1.3 integrity-only cipher suites was added in OpenSSL 3.4. -The list of TLS 1.3 ciphersuites I and TLS 1.2 ciphers -I were case-sensitive prior to OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-cmds.pod b/doc/man1/openssl-cmds.pod.in similarity index 96% rename from doc/man1/openssl-cmds.pod rename to doc/man1/openssl-cmds.pod.in index 1f1ce07c2a..89890e43a9 100644 --- a/doc/man1/openssl-cmds.pod +++ b/doc/man1/openssl-cmds.pod.in @@ -1,4 +1,5 @@ =pod +{- OpenSSL::safe::output_do_not_edit_headers(); -} =head1 NAME @@ -151,7 +152,7 @@ The B command was removed in OpenSSL 4.0. =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-cmp.pod.in b/doc/man1/openssl-cmp.pod.in index 797414ea94..b12ca950ab 100644 --- a/doc/man1/openssl-cmp.pod.in +++ b/doc/man1/openssl-cmp.pod.in @@ -70,7 +70,6 @@ Server authentication options: [B<-expect_sender> I] [B<-ignore_keyusage>] [B<-unprotected_errors>] -[B<-nonmatched_error_nonces>] [B<-ta_in_ip_extracerts>] [B<-no_cache_extracerts>] [B<-srvcertout> I] @@ -117,7 +116,7 @@ TLS connection options: [B<-tls_keypass> I] [B<-tls_extra> I|I] [B<-tls_trusted> I|I] -[B<-tls_host> I] +[B<-tls_host> I] Client-side debugging options: @@ -528,22 +527,17 @@ Reason numbers defined in RFC 5280 are: =item B<-server> I<[http[s]://][userinfo@]host[:port][/path][?query][#fragment]> The I domain name or IP address and optionally I -of the CMP server to connect to via HTTP(S). -An IP address may be for v4 or v6, such as C<127.0.0.1> or C<[::1]> for C. -If the I string is an IPv6 address, it must be enclosed in C<[> and C<]>. - -For TLS connections, the name verified in server certificates is I -unless the B<-tls_host> option is used to specify a different name. -If I is a DNS name, it is also used for -TLS Server Name Indication (SNI) according to RFC 3546 section 3.1. +of the CMP server to connect to using HTTP(S). +IP address may be for v4 or v6, such as C<127.0.0.1> or C<[::1]> for localhost. +If the host string is an IPv6 address, it must be enclosed in C<[> and C<]>. This option excludes I<-port> and I<-use_mock_srv>. It is ignored if I<-rspin> is given with enough filename arguments. If the scheme C is given, the B<-tls_used> option is implied. When TLS is used, the default port is 443, otherwise 80. -The optional userinfo component is ignored. -Any given query and fragment components are handled as part of the path component. +The optional userinfo and fragment components are ignored. +Any given query component is handled as part of the path component. If a path is included it provides the default value for the B<-path> option. =item B<-proxy> I<[http[s]://][userinfo@]host[:port][/path][?query][#fragment]> @@ -555,7 +549,6 @@ The proxy port defaults to 80 or 443 if the scheme is C; apart from that the optional C or C prefix is ignored (note that using TLS may be required by B<-tls_used> or B<-server> with the prefix C), as well as any path, userinfo, and query, and fragment components. - Defaults to the environment variable C if set, else C in case no TLS is used, otherwise C if set, else C. This option is ignored if I<-server> is not given. @@ -723,12 +716,6 @@ with a signature key." =back -=item B<-nonmatched_error_nonces> - -Accept missing or non-matching transactionID or recipNonce values in error messages. -This can be helpful in case the server cannot provide a proper error message, -for instance if it was unable to parse the ASN.1 encoding of a request message. - =item B<-ta_in_ip_extracerts> This is a quirk option added to support 3GPP TS 33.310. @@ -748,15 +735,9 @@ implements a form of trust-on-first-use (TOFU). =item B<-no_cache_extracerts> Do not cache certificates in the extraCerts field of CMP messages received. -By default, they are kept as they may be helpful for validating further messages. +By default, they are kept as they may be helful for validating further messages. This option applies to both CMP clients and the mock server. -In any case, after successfully validating an incoming message, its protection -certificate (if any) is cached for reuse with validation of subsequent messages. -This is done not only for efficiency but also -to eliminate the need for the sender to include its certificate and related chain -in the extraCerts field of subsequent messages of the same transaction. - =item B<-srvcertout> I The file where to save the successfully validated certificate, if any, @@ -1005,7 +986,7 @@ L. =item B<-tls_used> -Require the CMP client to use TLS (regardless if other TLS-related options are set) +Make the CMP client use TLS (regardless if other TLS-related options are set) for message exchange with the server via HTTP. This option is not supported with the I<-port> option. It is implied if the B<-server> option is given with the scheme C. @@ -1050,10 +1031,11 @@ The certificate verification options B<-verify_hostname>, B<-verify_ip>, and B<-verify_email> have no effect on the certificate verification enabled via this option. -=item B<-tls_host> I +=item B<-tls_host> I -Hostname or IP address to be checked in the TLS server certificate. -If not given it defaults to the host part of the B<-server> option URL argument. +Address to be checked during hostname validation. +This may be a DNS name or an IP address. +If not given it defaults to the B<-server> address. =back @@ -1552,11 +1534,9 @@ The B<-ta_in_ip_extracerts> quirk option was added in OpenSSL 4.0. The B<-engine> option was removed in OpenSSL 4.0. -The B<-nonmatched_error_nonces> option was added in OpenSSL 4.1. - =head1 COPYRIGHT -Copyright 2007-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-cms.pod.in b/doc/man1/openssl-cms.pod.in index 8da6ee0229..4d79fe9add 100644 --- a/doc/man1/openssl-cms.pod.in +++ b/doc/man1/openssl-cms.pod.in @@ -425,7 +425,7 @@ Currently, the AES variants with GCM mode are the only supported AEAD algorithms. If not specified, AES-256-CBC is used as the default. Only used with B<-encrypt> and -B<-EncryptedData_encrypt> commands. +B<-EncryptedData_create> commands. =item B<-kekcipher> I @@ -474,12 +474,6 @@ B parameter of the B type's KDF. Digest algorithm to use when signing or resigning. If not present then the default digest algorithm for the signing key will be used (usually SHA-256). -Note that, in the case signed attributes are not used (B<-noattr>), for -some hash-less signing schemes the given digest algorithm will be ignored -and a digest algorithm required by the signing scheme will be used. This is -the case for EdDSA (RFC 8419). For SLH-DSA (RFC 9814) and ML-DSA (RFC 9882), -the scheme-suggested digest algorithm will only be used if none is given. - =item B<-signer> I A signing certificate. When signing or resigning a message, this option can be @@ -811,7 +805,7 @@ The use of PSS with B<-sign>. The use of OAEP or non-RSA keys with B<-encrypt>. -Additionally the B<-EncryptedData_encrypt> and B<-data_create> type cannot +Additionally the B<-EncryptedData_create> and B<-data_create> type cannot be processed by the older L command. =head1 EXAMPLES @@ -908,7 +902,7 @@ Use SHA256 KDF with an ECDH certificate: Print CMS signed binary data in human-readable form: - openssl cms -in signed.cms -binary -inform DER -cmsout -print +openssl cms -in signed.cms -binary -inform DER -cmsout -print =head1 BUGS @@ -930,10 +924,6 @@ the list of permitted ciphers in a database and only use those. No revocation checking is done on the signer's certificate. -Ed448 signing is not supported when using signed-data with signed attributes -since OpenSSL does not currently support the digestAlgorithm id-shake256-len -as required per RFC 8419. - =head1 SEE ALSO L @@ -964,7 +954,7 @@ The B<-engine> option was removed in OpenSSL 4.0. =head1 COPYRIGHT -Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2008-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-configutl.pod b/doc/man1/openssl-configutl.pod.in similarity index 93% rename from doc/man1/openssl-configutl.pod rename to doc/man1/openssl-configutl.pod.in index 2ac5bdb31c..98f05bd800 100644 --- a/doc/man1/openssl-configutl.pod +++ b/doc/man1/openssl-configutl.pod.in @@ -1,4 +1,5 @@ =pod +{- OpenSSL::safe::output_do_not_edit_headers(); -} =head1 NAME @@ -61,7 +62,7 @@ The B command was added in OpenSSL 3.6. =head1 COPYRIGHT -Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-crl.pod.in b/doc/man1/openssl-crl.pod.in index 3d12d1700d..4327b6157b 100644 --- a/doc/man1/openssl-crl.pod.in +++ b/doc/man1/openssl-crl.pod.in @@ -87,14 +87,6 @@ for testing. Specify the date output format. Values are: rfc_822 and iso_8601. Defaults to rfc_822. -Note that despite its name, the rfc_822 format does not conform to RFC 822 -or its successors RFC 2822 and RFC 5322. It outputs dates in the format -"Mmm DD HH:MM:SS YYYY GMT" (e.g., "Jul 31 22:20:50 2017 GMT"). The month -appears before the day, unlike all three RFCs, which put the day first. -The 4-digit year differs from RFC 822 (which used 2-digit years), and the -timezone name "GMT" is obsolete per RFC 2822 and RFC 5322 (which require -numeric offsets such as "+0000"). - =item B<-text> Print out the CRL in text form. diff --git a/doc/man1/openssl-dgst.pod.in b/doc/man1/openssl-dgst.pod.in index 73e439ad14..8aa2cf79c1 100644 --- a/doc/man1/openssl-dgst.pod.in +++ b/doc/man1/openssl-dgst.pod.in @@ -118,11 +118,10 @@ Filename to output to, or standard output by default. Digitally sign the digest using the given private key. Note that for algorithms that only support one-shot signing -(such as Ed25519, ED448, ML-DSA-44, ML-DSA-65 and ML-DSA-87) the digest must not +(such as Ed25519, ED448, ML-DSA-44, ML-DSA-65 andML-DSA-87) the digest must not be set. For these algorithms the input is buffered (and not digested) before -signing. When the input is from a file, memory-mapped I/O is used on -supported platforms (Unix\-like), allowing large files without a size limit; when -input is from stdin or on unsupported platforms, input is limited to 16MB. +signing. For these algorithms, if the input is larger than 16MB an error +will occur. =item B<-keyform> B|B|B @@ -144,10 +143,6 @@ see L. Verify the signature using the public key in "filename". The output is either "Verified OK" or "Verification Failure". -For one-shot verification algorithms (e.g. Ed25519, Ed448), when the input -is from a file, memory-mapped I/O is used on supported platforms (Unix\-like), -allowing large files; when input is from stdin or on unsupported platforms, -input is limited to 16MB. =item B<-prverify> I @@ -336,11 +331,6 @@ The B<-engine> and B<-engine_impl> options were removed in OpenSSL 4.0. The B<-hmac-env> and B<-hmac-stdin> options were added in OpenSSL 4.0. -Since OpenSSL 4.1, one-shot sign and verify (e.g. Ed25519, Ed448) with input -from a file uses memory-mapped I/O on supported platforms (Unix\-like), allowing -large files to be processed without the previous 16MB limit for file-based -input. - =head1 COPYRIGHT Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. diff --git a/doc/man1/openssl-ec.pod.in b/doc/man1/openssl-ec.pod.in index 2fd397da00..a60b796c00 100644 --- a/doc/man1/openssl-ec.pod.in +++ b/doc/man1/openssl-ec.pod.in @@ -122,6 +122,9 @@ This specifies how the points on the elliptic curve are converted into octet strings. Possible values are: B, B (the default value) and B. For more information regarding the point conversion forms please read the X9.62 standard. +B Due to patent issues the B option is disabled +by default for binary curves and can be enabled by defining +the preprocessor macro B at compile time. =item B<-param_enc> I diff --git a/doc/man1/openssl-ech.pod.in b/doc/man1/openssl-ech.pod.in deleted file mode 100644 index b5c412f17b..0000000000 --- a/doc/man1/openssl-ech.pod.in +++ /dev/null @@ -1,116 +0,0 @@ -=pod -{- OpenSSL::safe::output_do_not_edit_headers(); -} - -=head1 NAME - -openssl-ech - ECH key generation - -=head1 SYNOPSIS - -B B -[B<-help>] -[B<-verbose>] -[B<-in> I] -[B<-out> I] -[B<-public_name> I] -[B<-max_name_len> I] -[B<-suite> I] -[B<-ech_version> I] -[B<-select> I] -[B<-text>] - -=head1 DESCRIPTION - -The L command generates Encrypted Client Hello (ECH) key pairs -in the ECHConfig PEM file format as specified in -L. - -That format consists of an optional private key in PKCS#8 format and a base64 -encoded ECHConfigList containing an entry with a matching public value (and -possibly other entries as well). - -=head1 OPTIONS - -The following options are supported: - -=over 4 - -=item B<-help> - -Print out a usage message. - -=item B<-verbose> - -Print more verbosely. - -=item B<-in> - -Provide an input ECH PEM file for printing or merging. Up to five -input files can be provided via use of multiple B arguments. - -=item B<-out> I - -Name of output ECHConfig PEM file. If a new key pair was generated the output -file will contain the private key and encoded ECHConfigList. If one or more -input files was provided the output file will contain a set of ECHConfigList -values with public keys from the inputs, and no private key(s). - -=item B<-text> - -Provide human-readable text output. - -=item B<-public_name> I - -The DNS name to use in the "public_name" field of the ECHConfig. - -=item B<-max_name_len> I - -Maximum name length field value to use in the ECHConfig. - -=item B<-suite> I - -HPKE suite to use in the ECHConfig. - -=item B<-ech_version> I - -The ECH version to use in the ECHConfig. Only 0xfe0d is supported in this version. - -=item B<-select> I - -Select the N-th ECHConfig/public key from the set of input ECH PEM files and output -that. - -=back - -=head1 NOTES - -Ciphersuites are specified using a comma-separated list of IANA-registered -codes/numbers e.g. "-c 0x20,1,3" or a comma-separated list of strings from: -- KEMs: p256, p384, p521, x25519, x448 -- KDFs: hkdf-sha256, hkdf-sha384, hkdf-sha512 -- AEADs: aes128gcm, aes256gcm, chachapoly1305 - -For example the default is: x25519, hkdf-sha256, aes128gcm -See L for details. - -=head1 SEE ALSO - -L, -L, -L, -L - -=head1 HISTORY - -This functionality described here was added in OpenSSL 4.0. - -=head1 COPYRIGHT - -Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. - -Licensed under the Apache License 2.0 (the "License"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file LICENSE in the source distribution or at -L. - -=cut diff --git a/doc/man1/openssl-ecparam.pod.in b/doc/man1/openssl-ecparam.pod.in index d48f19d789..ca4e002762 100644 --- a/doc/man1/openssl-ecparam.pod.in +++ b/doc/man1/openssl-ecparam.pod.in @@ -98,6 +98,9 @@ This specifies how the points on the elliptic curve are converted into octet strings. Possible values are: B, B (the default value) and B. For more information regarding the point conversion forms please read the X9.62 standard. +B Due to patent issues the B option is disabled +by default for binary curves and can be enabled by defining +the preprocessor macro B at compile time. =item B<-param_enc> I diff --git a/doc/man1/openssl-enc.pod.in b/doc/man1/openssl-enc.pod.in index ce38c078ea..fd05d777c9 100644 --- a/doc/man1/openssl-enc.pod.in +++ b/doc/man1/openssl-enc.pod.in @@ -61,9 +61,7 @@ either by itself or in addition to the encryption or decryption. =item B<-I> -The cipher to use. This option is specified by prepending a hyphen to the -cipher name (e.g., B<-aes-256-cbc>), not as an argument to a C<-cipher> flag. -Use C to see the available ciphers. +The cipher to use. =item B<-help> @@ -521,7 +519,7 @@ The B<-skeyuri> and B<-storepass> options were added in OpenSSL 4.0. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-errstr.pod b/doc/man1/openssl-errstr.pod.in similarity index 88% rename from doc/man1/openssl-errstr.pod rename to doc/man1/openssl-errstr.pod.in index c27ceadf55..49a50adc19 100644 --- a/doc/man1/openssl-errstr.pod +++ b/doc/man1/openssl-errstr.pod.in @@ -1,4 +1,5 @@ =pod +{- OpenSSL::safe::output_do_not_edit_headers(); -} =head1 NAME @@ -43,7 +44,7 @@ to produce the error message: =head1 COPYRIGHT -Copyright 2004-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2004-2020 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-fipsinstall.pod b/doc/man1/openssl-fipsinstall.pod.in similarity index 97% rename from doc/man1/openssl-fipsinstall.pod rename to doc/man1/openssl-fipsinstall.pod.in index fc12abf2bb..2db5acd242 100644 --- a/doc/man1/openssl-fipsinstall.pod +++ b/doc/man1/openssl-fipsinstall.pod.in @@ -1,4 +1,5 @@ =pod +{- OpenSSL::safe::output_do_not_edit_headers(); -} =head1 NAME @@ -53,7 +54,6 @@ B [B<-corrupt_desc> I] [B<-corrupt_type> I] [B<-config> I] -[B<-defer_tests>] =head1 DESCRIPTION @@ -396,12 +396,6 @@ data that is included by the base C configuration file. See L for further information on how to set up a provider section. All other options are ignored if '-config' is used. -=item B<-defer_tests> - -Configure the module to not run all self-tests at startup and allow tests -execution to be deferred to the first time the algorithm to be tested is -invoked. - =back =head1 NOTES @@ -493,13 +487,9 @@ B<-x963kdf_key_check>, B<-x942kdf_key_check>, B<-ecdh_cofactor_check> -The following options was added in OpenSSL 4.0: - -B<-defer_tests> - =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-format-options.pod b/doc/man1/openssl-format-options.pod index 2da9bef5ef..b85b34a682 100644 --- a/doc/man1/openssl-format-options.pod +++ b/doc/man1/openssl-format-options.pod @@ -64,7 +64,7 @@ A binary format, encoded or parsed according to Distinguished Encoding Rules A DER-encoded file containing a PKCS#12 object. It might be necessary to provide a decryption password to retrieve -the private key or certificate. +the private key. =item B @@ -73,11 +73,11 @@ a block of base-64 encoding (defined in IETF RFC 4648), with specific lines used to mark the start and end: Text before the BEGIN line is ignored. - -----BEGIN object-type----- + ----- BEGIN object-type ----- OT43gQKBgQC/2OHZoko6iRlNOAQ/tMVFNq7fL81GivoQ9F1U0Qr+DH3ZfaH8eIkX xT0ToMPJUzWAn8pZv0snA0um6SIgvkCuxO84OkANCVbttzXImIsL7pFzfcwV/ERK UM6j0ZuSMFOCr/lGPAoOQU0fskidGEHi1/kW+suSr28TqsyYZpwBDQ== - -----END object-type----- + ----- END object-type ----- Text after the END line is also ignored The I must match the type of object that is expected. diff --git a/doc/man1/openssl-genpkey.pod.in b/doc/man1/openssl-genpkey.pod.in index 214b9b322a..76fc3ac134 100644 --- a/doc/man1/openssl-genpkey.pod.in +++ b/doc/man1/openssl-genpkey.pod.in @@ -23,7 +23,6 @@ B B [B<-paramfile> I] [B<-algorithm> I] [B<-pkeyopt> I:I] -[B<-encopt> I:I] [B<-genparam>] [B<-text>] {- $OpenSSL::safe::opt_r_synopsis -} @@ -74,15 +73,10 @@ see L. =item B<-I> -Encrypts the private key with the specified cipher. This option is specified -by prepending a hyphen to the cipher name. For example, to encrypt with -AES-128 in CBC mode, use B<-aes-128-cbc>. To encrypt with AES-256 in CBC mode, -use B<-aes-256-cbc>. - -Note: the cipher name is used directly as the option (e.g., B<-aes-256-cbc>), -not as an argument to a C<-cipher> flag. - -Use C to see the available ciphers. +Encrypts the private key using the specified algorithm. The algorithm can be +specified using a name that is accepted by the EVP_get_cipherbyname() function. +For example, use the syntax B<-aes-128-cbc> to specify the AES encryption +algorithm with a 128-bit key in CBC mode. =item B<-algorithm> I @@ -91,13 +85,6 @@ precede any B<-pkeyopt> options. The options B<-paramfile> and B<-algorithm> are mutually exclusive. Providers may add algorithms in addition to the standard built-in ones. -A complete list of available algorithms can be obtained using: - openssl list -public-key-algorithms - -When selecting an algorithm from this output, use the C for legacy -algorithms, or the portion of the C field before the C<@> symbol for -provided algorithms. - Valid built-in algorithm names for private key generation are RSA, RSA-PSS, EC, X25519, X448, ED25519, ED448, ML-DSA and ML-KEM. @@ -109,28 +96,14 @@ PKCS#3 refers to DH Keys. Some options are not shared between DH and DHX keys. =item B<-pkeyopt> I:I -Set the public key algorithm option I to I. -The precise set of -supported options depends on the public key algorithm used and its +Set the public key algorithm option I to I. The precise set of +options supported depends on the public key algorithm used and its implementation. See L and L below for more details. To list the possible I values for an algorithm use: B B -algorithm XXX -help -=item B<-encopt> I:I - -Set the private key encoder parameter I to I. -In order to set multiple parameters, multiple B<-encopt> options can be -specified, each specifying a single parameter. -The precise set of supported parameters depends on the public key algorithm -involved and its implementation. -This is primarily applicable to B and B, whose private key -encoding to a B object can take a number of different forms. -The C parameter can be used to select the preferred output -forms. -See L and L for details. - =item B<-genparam> Generate a set of parameters instead of a private key. If used this option must @@ -580,15 +553,9 @@ Support for B and B was added in OpenSSL 3.5. The B<-engine> option was removed in OpenSSL 4.0. -The B<-encopt> option was added in OpenSSL 4.0. - -As of OpenSSL 4.0 the B<-pass> and B<-I> options apply when -private keys are output in either B or B form. -Previously, these private key encryption options were ignored in B form. - =head1 COPYRIGHT -Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-info.pod b/doc/man1/openssl-info.pod.in similarity index 93% rename from doc/man1/openssl-info.pod rename to doc/man1/openssl-info.pod.in index 0b73a8f3c7..33618874dd 100644 --- a/doc/man1/openssl-info.pod +++ b/doc/man1/openssl-info.pod.in @@ -1,4 +1,5 @@ =pod +{- OpenSSL::safe::output_do_not_edit_headers(); -} =head1 NAME @@ -83,7 +84,7 @@ The B<-enginesdir> option was removed in OpenSSL 4.0. =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-kdf.pod.in b/doc/man1/openssl-kdf.pod.in index 61113846c8..ae153b4b81 100644 --- a/doc/man1/openssl-kdf.pod.in +++ b/doc/man1/openssl-kdf.pod.in @@ -140,8 +140,8 @@ This option is identical to the B<-mac> option. =item I Specifies the name of a supported KDF algorithm which will be used. -The supported algorithms names include TLS1-PRF, HKDF, IKEV2KDF, SSKDF, PBKDF2, -SNMPKDF, SRTPKDF, SSHKDF, X942KDF-ASN1, X942KDF-CONCAT, X963KDF and SCRYPT. +The supported algorithms names include TLS1-PRF, HKDF, SSKDF, PBKDF2, +SNMPKDF, SSHKDF, X942KDF-ASN1, X942KDF-CONCAT, X963KDF and SCRYPT. =back @@ -157,55 +157,6 @@ Use HKDF to create a hex-encoded derived key from a secret key, salt and info: openssl kdf -keylen 10 -kdfopt digest:SHA2-256 -kdfopt key:secret \ -kdfopt salt:salt -kdfopt info:label HKDF -Use IKEV2KDF to create a hex-encoded SEEDKEY from initiator_nonce, - responder_nonce, and shared secret: - - openssl kdf -keylen 32 -kdfopt digest:SHA256 \ - -kdfopt hexni:3651FEF5C9C35E93 \ - -kdfopt hexnr:C09A8B90A3F04D59 \ - -kdfopt hexsecret:D084A30166A50FB7325C3960874A839449EF9741C2F4F947D0201DD8C1269273D79509F37E3CA3EB4FA2FE2A28254E289CD3F34DAD4EB4DF1A07685A4B8A94FA61E2491F7598B3CE65547FF133B3F63D1AC4175EAA695033F3CEDB026A6873A36455172A8540B8A5D23A0143BED0390EE49B168269D75FFFEE9FB62BE965993C \ - -kdfopt mode:0 IKEV2KDF - -Use IKEV2KDF to create a hex-encoded Derived Key Material (DKM) from initiator_nonce, - responder_nonce, SPI_initiator, SPI_responder and SEEDKEY(seed): - - openssl kdf -keylen 224 -kdfopt digest:SHA256 \ - -kdfopt hexni:3651FEF5C9C35E93 \ - -kdfopt hexnr:C09A8B90A3F04D59 \ - -kdfopt hexspii:8E5C3AE507221684 \ - -kdfopt hexspir:B1F201BB155C3ACD \ - -kdfopt hexseed:EFAA7AB0EAA85A3D0BE2100CD4B6FE00FF5025A9EAFDDB3EF518E9F0D3FE60E6 \ - -kdfopt mode:1 IKEV2KDF - -Use IKEV2KDF to create a hex-encoded DKM(Child_SA) from initiator_nonce, - responder_nonce and sk_d(key): - - openssl kdf -keylen 224 -kdfopt digest:SHA256 \ - -kdfopt hexni:3651FEF5C9C35E93 \ - -kdfopt hexnr:C09A8B90A3F04D59 \ - -kdfopt hexkey:462B9DD525D4FD71169174272779E704BAF62C6231779AE9EFE8C58B21916B42 \ - -kdfopt mode:1 IKEV2KDF - -Use IKEV2KDF to create a hex-encoded DKM(Child_DH) from initiator_nonce, - responder_nonce, sk_d(key) and new shared secret: - - openssl kdf -keylen 224 -kdfopt digest:SHA256 \ - -kdfopt hexni:3651FEF5C9C35E93 \ - -kdfopt hexnr:C09A8B90A3F04D59 \ - -kdfopt hexkey:462B9DD525D4FD71169174272779E704BAF62C6231779AE9EFE8C58B21916B42 \ - -kdfopt hexsecret:52F00AB174C25D5B7139AE5FF4E8E9EDDEE5992D2E36ADF8A559FFD90DAB1442E4FBE429D320C0F33552A17D1557FA41EA70E8FB916C4FA27ED52B5F8EBD8461AFA78F1159159A64055AC5F6319E29C28EAE58CBC6847770F32C3FED1D04750484F854790F95E9EC01BC5BC461F24966462E359511329305038E94DEB6DD42C2 \ - -kdfopt mode:1 IKEV2KDF - -Use IKEV2KDF to create a hex-encoded REKEY from initiator_nonce, - responder_nonce, sk_d(key) and new shared secret: - - openssl kdf -keylen 32 -kdfopt digest:SHA256 \ - -kdfopt hexni:3651FEF5C9C35E93 \ - -kdfopt hexnr:C09A8B90A3F04D59 \ - -kdfopt hexkey:462B9DD525D4FD71169174272779E704BAF62C6231779AE9EFE8C58B21916B42 \ - -kdfopt hexsecret:52F00AB174C25D5B7139AE5FF4E8E9EDDEE5992D2E36ADF8A559FFD90DAB1442E4FBE429D320C0F33552A17D1557FA41EA70E8FB916C4FA27ED52B5F8EBD8461AFA78F1159159A64055AC5F6319E29C28EAE58CBC6847770F32C3FED1D04750484F854790F95E9EC01BC5BC461F24966462E359511329305038E94DEB6DD42C2 \ - -kdfopt mode:2 IKEV2KDF - Use SSKDF with KMAC to create a hex-encoded derived key from a secret key, salt and info: openssl kdf -keylen 64 -kdfopt mac:KMAC-128 -kdfopt maclen:20 \ @@ -226,18 +177,9 @@ Use SSKDF with Hash to create a hex-encoded derived key from a secret key, salt Use SNMPKDF to create a hex-encoded derived key from an engine ID, hash and password: - openssl kdf -keylen 32 -kdfopt digest:SHA256 \ + openssl kdf -keylen 20 -kdfopt digest:SHA1 \ -kdfopt pass:IFUcNbMl \ - -kdfopt hexeid:800002b805123456789abcdef0123456789abcdef0123456789abcdef0123456 - SNMPKDF - -Use SRTPKDF to create a SRTP authentication derived key from a cipher, mkey, msalt, - kdr, index and label: - - openssl kdf -keylen 20 -kdfopt cipher:AES-128-CTR \ - -kdfopt key:E1F97A0D3E018BE0D64FA32C06DE4139 \ - -kdfopt salt:0EC675AD498AFEEBB6960B3AABE6 \ - -kdfopt index:000000000000 -kdfopt label:1 SRTPKDF + -kdfopt hexeid:800002b805123456789abcdef0123456789abcdef0123456789abcdef0123456 SNMPKDF Use SSHKDF to create a hex-encoded derived key from a secret key, hash and session_id: @@ -273,7 +215,6 @@ L, L, L, L, -L, L, L, L, @@ -286,7 +227,7 @@ Added in OpenSSL 3.0 =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-list.pod.in b/doc/man1/openssl-list.pod.in index 4b2582bf9d..9159eebd80 100644 --- a/doc/man1/openssl-list.pod.in +++ b/doc/man1/openssl-list.pod.in @@ -251,7 +251,7 @@ be displayed. =item B<-disabled> -Display a list of disabled features, protocols, and algorithms, those that were compiled out +Display a list of disabled features, those that were compiled out of the installation. =item B<-objects> diff --git a/doc/man1/openssl-pkcs12.pod.in b/doc/man1/openssl-pkcs12.pod.in index ab49c95291..1f153bd326 100644 --- a/doc/man1/openssl-pkcs12.pod.in +++ b/doc/man1/openssl-pkcs12.pod.in @@ -406,10 +406,6 @@ Although there are a large number of options most of them are very rarely used. For PKCS#12 file parsing only B<-in> and B<-out> need to be used for PKCS#12 file creation B<-export> and B<-name> are also used. -When loading using B<-in>, An error will occur if the PKCS12 macdata contains -PBMAC1 and the related PBKDF2 parameters are missing, or if the associated -key length is not in the range 1 to 64. - If none of the B<-clcerts>, B<-cacerts> or B<-nocerts> options are present then all certificates will be output in the order they appear in the input PKCS#12 files. There is no guarantee that the first certificate present is diff --git a/doc/man1/openssl-pkcs8.pod.in b/doc/man1/openssl-pkcs8.pod.in index 884a5d5a38..e2356b4aea 100644 --- a/doc/man1/openssl-pkcs8.pod.in +++ b/doc/man1/openssl-pkcs8.pod.in @@ -74,7 +74,7 @@ is included. =item B<-traditional> -When this option is present and B<-topk8> is not, a traditional format private +When this option is present and B<-topk8> is not a traditional format private key is written. =item B<-in> I diff --git a/doc/man1/openssl-pkey.pod.in b/doc/man1/openssl-pkey.pod.in index bb6fcde863..238d0c812a 100644 --- a/doc/man1/openssl-pkey.pod.in +++ b/doc/man1/openssl-pkey.pod.in @@ -22,7 +22,6 @@ B B [B<-pubin>] [B<-out> I] [B<-outform> B|B] -[B<-encopt> I:I] [B<-I>] [B<-passout> I] [B<-traditional>] @@ -115,27 +114,11 @@ When password input is interrupted, the output file is not touched. The key output format; the default is B. See L for details. -=item B<-encopt> I:I - -Set the private key encoder parameter I to I. -In order to set multiple parameters, multiple B<-encopt> options can be -specified, each specifying a single parameter. -The precise set of supported parameters depends on the public key algorithm -involved and its implementation. -This is primarily applicable to B and B, whose private key -encoding to a B object can take a number of different forms. -The C parameter can be used to select the preferred output -forms. -See L and L for details. - =item B<-I> -Encrypt the PEM encoded private key with the supplied cipher. This option is -specified by prepending a hyphen to the cipher name (e.g., B<-aes-256-cbc> -or B<-aes128>), not as an argument to a C<-cipher> flag. -In B output form encryption is supported only in the default B -form and is not available when the B<-traditional> option is used. -Use C to see the available ciphers. +Encrypt the PEM encoded private key with the supplied cipher. Any algorithm +name accepted by EVP_get_cipherbyname() is acceptable such as B. +Encryption is not supported for DER output. =item B<-passout> I @@ -147,9 +130,8 @@ see L. =item B<-traditional> Normally a private key is written using standard format: this is PKCS#8 form -with the appropriate encryption algorithm (if any). -If the B<-traditional> option is specified then the older "traditional" format -is used instead, and in B output form encryption is not available. +with the appropriate encryption algorithm (if any). If the B<-traditional> +option is specified then the older "traditional" format is used instead. =item B<-pubout> @@ -179,9 +161,12 @@ This cannot be combined with encoded output in DER format. This option only applies to elliptic-curve based keys. This specifies how the points on the elliptic curve are converted -into octet strings. Possible values are: B (the default -value), B and B. For more information regarding +into octet strings. Possible values are: B (the default +value), B and B. For more information regarding the point conversion forms please read the X9.62 standard. +B Due to patent issues the B option is disabled +by default for binary curves and can be enabled by defining +the preprocessor macro B at compile time. =item B<-ec_param_enc> I @@ -245,16 +230,9 @@ L The B<-engine> option was removed in OpenSSL 4.0. -The B<-encopt> option was added in OpenSSL 4.0. - -As of OpenSSL 4.0 the B<-pass> and B<-I> options apply when private -keys are output in both B and B (except with B<-traditional>) forms. -Previously, these private key encryption options were rejected in combination -with the B output form. - =head1 COPYRIGHT -Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2006-2023 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-pkeyutl.pod.in b/doc/man1/openssl-pkeyutl.pod.in index 590bfe3a6d..750455c995 100644 --- a/doc/man1/openssl-pkeyutl.pod.in +++ b/doc/man1/openssl-pkeyutl.pod.in @@ -77,10 +77,6 @@ is implied since OpenSSL 3.5, and required in earlier versions. The B<-digest> option implies B<-rawin> since OpenSSL 3.5. -When the input is read from a file (B<-in> I), the command may -use memory-mapped I/O on supported platforms for better performance and -to handle large files without loading the entire file into memory. - =item B<-digest> I This option can only be used with B<-sign> and B<-verify>. @@ -210,7 +206,7 @@ derived shared-secret value generated in the encapsulation process. Encapsulation is supported with a number of public key algorithms, currently: L, L, -L, +L, and L. The ECX and EC algorithms use the @@ -677,21 +673,14 @@ L, =head1 HISTORY Since OpenSSL 3.5, -the B<-digest> option implies B<-rawin>. The B<-rawin> option is no longer -required when signing or verifying with a key type that does not support a -prehash digest, such as Ed25519, Ed448, ML-DSA, or SLH-DSA. For these key -types, B<-digest> is not supported. +the B<-digest> option implies B<-rawin>, and these two options are +no longer required when signing or verifying with an Ed25519 or Ed448 key. Also since OpenSSL 3.5, the B<-kemop> option is no longer required for any of the supported algorithms, the only supported B is now the default. The B<-engine> option was removed in OpenSSL 4.0. -Since OpenSSL 4.1, when reading raw input from a file (B<-in> I) for -oneshot sign/verify (such as Ed25519, Ed448, and ML-DSA), the command uses -memory-mapped I/O on supported platforms, allowing large files to be processed -without loading the entire file into memory. - =head1 COPYRIGHT Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved. diff --git a/doc/man1/openssl-prime.pod.in b/doc/man1/openssl-prime.pod.in index f5b65fd7b2..e128e4c0b0 100644 --- a/doc/man1/openssl-prime.pod.in +++ b/doc/man1/openssl-prime.pod.in @@ -36,11 +36,7 @@ Display an option summary. =item B<-hex> -When used with B<-generate>, output the generated prime in hexadecimal -format instead of decimal. When checking primality, interpret the input -numbers as hexadecimal instead of decimal. Note that the output in -hexadecimal is always present when checking primality, regardless of -this option. +Enable hex format for output from prime generation or input to primality checking. =item B<-in> diff --git a/doc/man1/openssl-rand.pod.in b/doc/man1/openssl-rand.pod.in index 4d4cda2b4d..d38961acc3 100644 --- a/doc/man1/openssl-rand.pod.in +++ b/doc/man1/openssl-rand.pod.in @@ -12,7 +12,6 @@ B [B<-out> I] [B<-base64>] [B<-hex>] -[B<-n>] {- $OpenSSL::safe::opt_r_synopsis -} {- $OpenSSL::safe::opt_provider_synopsis -} I[K|M|G|T] @@ -56,10 +55,6 @@ Perform base64 encoding on the output. Show the output as a hex string. -=item B<-n> - -Do not output the trailing newline. - {- $OpenSSL::safe::opt_r_item -} {- $OpenSSL::safe::opt_provider_item -} diff --git a/doc/man1/openssl-rehash.pod.in b/doc/man1/openssl-rehash.pod.in index a5c3a850d1..aa367cce4e 100644 --- a/doc/man1/openssl-rehash.pod.in +++ b/doc/man1/openssl-rehash.pod.in @@ -24,24 +24,33 @@ B {- $OpenSSL::safe::opt_provider_synopsis -} [I] ... +B +[B<-h>] +[B<-help>] +[B<-old>] +[B<-n>] +[B<-v>] +{- $OpenSSL::safe::opt_provider_synopsis -} +[I] ... + =head1 DESCRIPTION +This command is generally equivalent to the external +script B, +except for minor differences noted below. + B scans directories and calculates a hash value of each F<.pem>, F<.crt>, F<.cer>, or F<.crl> -file in the specified directory list -that is in PEM format and contains exactly one certificate or CRL. -The extension matching is case-insensitive and uses C locale. -For each of these files, it creates a symbolic link with its name being the -hash value of the certificate subject name or CRL issuer name, respectively. -In this context, the first 4 bytes of SHA-1 digest is used. +file in the specified directory list and creates symbolic links +for each file, where the name of the link is the hash value. (If the platform does not support symbolic links, a copy is made.) This command is useful as many programs that use OpenSSL require directories to be set up like this in order to find certificates. If any directories are named on the command line, then those are processed in turn. If not, then the B environment variable -is consulted; this should be a colon-separated list of directories -(or semicolon-separated on Windows), like the B variable. +is consulted; this should be a colon-separated list of directories, +like the Unix B variable. If that is not set then the default directory (installation-specific but often F) is processed. @@ -59,12 +68,28 @@ the period, like this: IBI. Multiple objects may have the same hash; they will be indicated by incrementing the I value. Duplicates are found by comparing the -full SHA-1 fingerprint of the certificate or CRL in DER representation. -A warning will be displayed if a duplicate is found. +full SHA-1 fingerprint. A warning will be displayed if a duplicate +is found. -A warning will also be displayed if there are files with a recognized filename -extension that cannot be parsed as either a certificate or a CRL in PEM format -or contain more than one such object. +A warning will also be displayed if there are files that +cannot be parsed as either a certificate or a CRL or if +more than one such object appears in the file. + +=head2 Script Configuration + +The B script +uses the B program to compute the hashes and +fingerprints. If not found in the user's B, then set the +B environment variable to the full pathname. +Any program can be used, it will be invoked as follows for either +a certificate or CRL: + + $OPENSSL x509 -hash -fingerprint -noout -in FILENAME + $OPENSSL crl -hash -fingerprint -noout -in FILENAME + +where I is the filename. It must output the hash of the +file on the first line, and the fingerprint on the second, +optionally prefixed with some text and an equals sign. =head1 OPTIONS @@ -118,9 +143,7 @@ or it is not usable (that is, does not exist or is not executable). =item B -List of directories to operate on. -On Unix-like systems the list entries are separated by a colon. -On Windows they are separated by a semicolon. +Colon separated list of directories to operate on. Ignored if directories are listed on the command line. =back @@ -131,13 +154,9 @@ L, L, L -=head1 HISTORY - -B was removed in OpenSSL 4.0. Use B instead. - =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-req.pod.in b/doc/man1/openssl-req.pod.in index d3d490a687..ae9724b16e 100644 --- a/doc/man1/openssl-req.pod.in +++ b/doc/man1/openssl-req.pod.in @@ -312,15 +312,15 @@ X.509 extensions to be added can be specified in the configuration file, possibly using the B<-config> and B<-extensions> options, and/or using the B<-addext> option. -Unless B<-x509v1> is given, generated certificates bear X.509 version 3 -even if no extensions are added. +Unless B<-x509v1> is given, generated certificates bear X.509 version 3. +Unless specified otherwise, +key identifier extensions are included as described in L. =item B<-x509v1> Request generation of certificates with X.509 version 1. This implies B<-x509>. -If X.509 extensions are added, X.509 version 3 is used regardless of this -option. +If X.509 extensions are given, anyway X.509 version 3 is set. =item B<-CA> I|I @@ -387,49 +387,23 @@ values for certain extensions such as subjectAltName. =item B<-extensions> I
, B<-reqexts> I
-Can be used to override the name of the configuration file section from which -X.509 extensions are included in certificates (when B<-x509> is in use) or -certificate requests. +Can be used to override the name of the configuration file section +from which X.509 extensions are included +in the certificate (when B<-x509> is in use) or certificate request. This allows several different sections to be used in the same configuration file to specify requests for a variety of purposes. -When signing a new CSR or X.509 certificate, if neither the the B<-extensions> -option nor its alias B<-reqexts> are specified, the name of the extension -section is taken from from C section of the configuration file. -Specifically, from the value of that section's C variable (for -a CSR) or its C variable (for a certificate). -If there is no setting for the variable (name/value assignment, see -L) in question, the configuration file does not add any extensions. -The B<-section> option can be used to override C with a custom section in -which to look for the above C and C variables. - -OpenSSL 4.0 removed built-in generation of the B and -B extensions when generating certificates. -Any desired extensions need to be listed either in the configuration file or -via the B<-addext> option described below. - =item B<-addext> I -Add a specific extension to the certificate (if B<-x509> is in use) or -certificate request. -The argument must have the form of a C pair as it would appear in a -configuration file. +Add a specific extension to the certificate (if B<-x509> is in use) +or certificate request. The argument must have the form of +a C pair as it would appear in a config file. -Each extension can appear at most once in a certificate or certificate request. -Extensions listed via the option on the command-line override any corresponding -extensions in the configuration file. +If an extension is added using this option that has the same OID as one +defined in the extension section of the config file, it overrides that one. -This option can be given multiple times, but any given extension can be -specified through this option at most once. - -To drop any unwanted B or B -extensions that may be added by default via the configuration file use either -or both of the options below: - - -addext subjectKeyIdentifier=none - -addext authorityKeyIdentifier=none - -These work as expected even if the extensions were not there to begin with. +This option can be given multiple times. +Doing so, the same key must not be given more than once. =item B<-precert> @@ -695,6 +669,15 @@ Generate a self-signed root certificate: openssl req -x509 -newkey rsa:2048 -keyout key.pem -out req.pem +Create an SM2 private key and then generate a certificate request from it: + + openssl ecparam -genkey -name SM2 -out sm2.key + openssl req -new -key sm2.key -out sm2.csr -sm3 -sigopt "distid:1234567812345678" + +Examine and verify an SM2 certificate request: + + openssl req -verify -in sm2.csr -sm3 -vfyopt "distid:1234567812345678" + Example of a file pointed to by the B option: 1.2.3.4 shortName A longer Name @@ -864,13 +847,9 @@ Since OpenSSL 3.3, the B<-verify> option will exit with 1 on failure. The B<-engine> option was removed in OpenSSL 4.0. -As of OpenSSL 4.0, the B utility no longer has specialised built-in logic -to add the SKID or AKID extensions, they are handled through configuration -files and command-line options just like any other extension. - =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-s_client.pod.in b/doc/man1/openssl-s_client.pod.in index 3257e9f680..bc2d3c822f 100644 --- a/doc/man1/openssl-s_client.pod.in +++ b/doc/man1/openssl-s_client.pod.in @@ -26,13 +26,9 @@ B B [B<-verify> I] [B<-verify_return_error>] [B<-verify_quiet>] -{- $OpenSSL::safe::opt_trust_synopsis -} [B<-verifyCAfile> I] [B<-verifyCApath> I] [B<-verifyCAstore> I] -[B<-chainCAfile> I] -[B<-chainCApath> I] -[B<-chainCAstore> I] [B<-cert> I] [B<-certform> B|B|B] [B<-cert_chain> I] @@ -43,6 +39,9 @@ B B [B<-key> I|I] [B<-keyform> B|B|B] [B<-pass> I] +[B<-chainCAfile> I] +[B<-chainCApath> I] +[B<-chainCAstore> I] [B<-requestCAfile> I] [B<-dane_tlsa_domain> I] [B<-dane_tlsa_rrdata> I] @@ -77,7 +76,6 @@ B B [B<-sctp>] [B<-sctp_label_bug>] [B<-fallback_scsv>] -[B<-grease>] [B<-async>] [B<-maxfraglen> I] [B<-max_send_frag>] @@ -117,23 +115,14 @@ B B {- $OpenSSL::safe::opt_name_synopsis -} {- $OpenSSL::safe::opt_version_synopsis -} {- $OpenSSL::safe::opt_x_synopsis -} +{- $OpenSSL::safe::opt_trust_synopsis -} {- $OpenSSL::safe::opt_s_synopsis -} {- $OpenSSL::safe::opt_r_synopsis -} {- $OpenSSL::safe::opt_provider_synopsis -} {- $OpenSSL::safe::opt_v_synopsis -} [B<-enable_server_rpk>] [B<-enable_client_rpk>] -[B<-expected-rpks>] [I:I] -[B<-ech_config_list>] -[B<-ech_outer_alpn> I] -[B<-ech_grease>] -[B<-ech_grease_suite> I] -[B<-ech_grease_type> I] -[B<-ech_ignore_cid>] -[B<-ech_outer_sni> I] -[B<-ech_no_outer_sni>] -[B<-ech_select> I] =head1 DESCRIPTION @@ -188,13 +177,6 @@ specified with this flag and issues an HTTP CONNECT command to connect to the desired server. If the host string is an IPv6 address, it must be enclosed in C<[> and C<]>. -=item B<-ech_config_list> I - -Specifies the ECHConfigList value to use for Encrypted Client Hello (ECH) for -the TLS session. The value must be a base64 encoded ECHConfigList. - -The ECHConfigList structure is defined in RFC 9849. - =item B<-proxy_user> I When used with the B<-proxy> flag, the program will attempt to authenticate @@ -325,68 +307,44 @@ This will typically abort the handshake with a fatal error. Limit verify output to only errors. -{- $OpenSSL::safe::opt_trust_item -} - -The certificates loaded via the B<-CAfile>, B<-CApath>, and B<-CAstore> options -are used as trust anchors when verifying the server's certificate unless -overridden by B<-verifyCAfile>, B<-verifyCApath>, or B<-verifyCAstore> options. -They are also used as trust anchors when attempting -to build the client certificate chain provided to the server unless -overridden by B<-chainCAfile>, B<-chainCApath>, or B<-chainCAstore> options. - =item B<-verifyCAfile> I -A file in PEM format containing one or more CA certificates -to trust for verifying the server's certificate. - -This and the following two options, B<-verifyCApath> and B<-verifyCAstore>, -take precedence over the B<-CAfile>, B<-CApath>, and B<-CAstore> options. +A file in PEM format containing trusted certificates to use +for verifying the server's certificate. =item B<-verifyCApath> I -A directory with files in PEM format containing CA certificates -to trust for verifying the server's certificate. +A directory containing trusted certificates to use +for verifying the server's certificate. This directory must be in "hash format", see L for more information. =item B<-verifyCAstore> I -URI of a store containing CA certificates -to trust for verifying the server's certificate. -The URI may indicate a single certificate, as well as a collection of them. -With URIs in the C scheme, this is generally treated like B<-verifyCApath> or -B<-verifyCAfile>, depending on if the URI indicates a directory or a single file. -See L for more information on stores and supported schemes. - -When any of B<-verifyCAfile>, B<-verifyCApath>, or B<-verifyCAstore> is -specified, they are loaded into a separate verification store (via -L) and used for server certificate -verification instead of the store built from B<-CAfile>, B<-CApath>, and -B<-CAstore>. +The URI of a store containing trusted certificates to use +for verifying the server's certificate. =item B<-chainCAfile> I -A file in PEM format containing one or more trusted CA certificates to use -when attempting to build the client certificate chain provided to the server. - -This and the following two options, B<-chainCApath> and B<-chainCAstore>, -take precedence over the B<-CAfile>, B<-CApath>, and B<-CAstore> options. +A file in PEM format containing trusted certificates to use +when attempting to build the client certificate chain. =item B<-chainCApath> I -A directory with files in PEM format containing trusted CA certificates to use -when attempting to build the client certificate chain provided to the server. +A directory containing trusted certificates to use +for building the client certificate chain provided to the server. This directory must be in "hash format", see L for more information. =item B<-chainCAstore> I The URI of a store containing trusted certificates to use -when attempting to build the client certificate chain provided to the server. +when attempting to build the client certificate chain. The URI may indicate a single certificate, as well as a collection of them. -With URIs in the C scheme, this is generally treated like B<-chainCApath> or -B<-chainCAfile>, depending on whether the URI points to a directory or a single file. -See L for more information on stores and supported schemes. +With URIs in the C scheme, this acts as B<-chainCAfile> or +B<-chainCApath>, depending on if the URI indicates a directory or a +single file. +See L for more information on the C scheme. =item B<-requestCAfile> I @@ -400,8 +358,7 @@ Enable RFC6698/RFC7671 DANE TLSA authentication and specify the TLSA base domain which becomes the default SNI hint and the primary reference identifier for hostname checks. This must be used in combination with at least one instance of the B<-dane_tlsa_rrdata> -option below, or else at least one B<-expected-rpks> option (from -which associated TLSA "3 1 0" records are synthesised internally). +option below. When DANE authentication succeeds, the diagnostic output will include the lowest (closest to 0) depth at which a TLSA record authenticated @@ -598,13 +555,6 @@ available where OpenSSL has support for SCTP enabled. Send TLS_FALLBACK_SCSV in the ClientHello. -=item B<-grease> - -Send GREASE (Generate Random Extensions And Sustain Extensibility) values in -the ClientHello as defined in RFC 8701. This injects random reserved values -into cipher suites, supported groups, supported versions, signature algorithms, -key share, and extensions to prevent ecosystem ossification. - =item B<-async> Switch on asynchronous mode. Cryptographic operations will be performed @@ -744,6 +694,9 @@ The I list is a comma-separated list of protocol names that the client should advertise support for. The list should contain the most desirable protocols first. Protocol names are printable ASCII strings, for example "http/1.1" or "spdy/3". +An empty list of protocols is treated specially and will cause the +client to advertise support for the TLS extension but disconnect just +after receiving ServerHello with a list of server supported protocols. The flag B<-nextprotoneg> cannot be specified if B<-tls1_3> is used. =item B<-ct>, B<-noct> @@ -818,6 +771,8 @@ Enable creation of connections via TCP fast open (RFC7413). {- $OpenSSL::safe::opt_x_item -} +{- $OpenSSL::safe::opt_trust_item -} + {- $OpenSSL::safe::opt_s_item -} {- $OpenSSL::safe::opt_r_item -} @@ -845,28 +800,6 @@ provided a suitable key and public certificate pair is configured. Some servers may nevertheless not request any client credentials, or may request a certificate. -=item B<-expected-rpks> I - -This option implies the B<-enable_server_rpk> option and can be specified -multiple times. -Each PEM I should contain one or more public keys, private keys or -certificates. -With a private key or certificate an attempt is made to extract the associated -public key. -Each resulting public key is added (via a call to L as -a valid raw public key that the server may present to be considered verified. -If a server nevertheless presents an X.509 certificate, the enclosed public key -is validated as though it were presented as a raw public key instead. - -If the B<-dane_tlsa_domain> and B<-dane_tlsa_rrdata> options (with certificate -usage B and selector B) are also used then the specified -TLSA records are used in combination with the keys found via the -B<-expected-rpks> option(s). - -Verification success or failure is reported as a DANE verification success or -failure, because verification of raw public keys is internally mapped to -verification of DANE TLSA records derived from the specified keys. - =item I:I Rather than providing B<-connect>, the target host and optional port may @@ -875,63 +808,6 @@ nor B<-connect> are provided, falls back to attempting to connect to I on port I<4433>. If the host string is an IPv6 address, it must be enclosed in C<[> and C<]>. -=item B<-ech_outer_alpn> I - -When doing Encrypted Client Hello (ECH), this allows the caller to specify -ALPN values to use in the outer ClientHello. (A "normal" ALPN value -specified via -alpn will be used in the inner ClientHello.) - -=item B<-ech_grease> - -When not really doing Encrypted Client Hello (ECH), one can emit a so-called -GREASE value, which is essentially a random value in order to try ensure that -server code is less likely to ossify. - -=item B<-ech_grease_suite> I - -When B<-ech_grease> is specified, one can choose which ECH ciphersuite to use -via this parameter. - -The comma-separated suite string names an HPKE suite in the form of -I,I,I, e.g. "x25519,hkdf-sha256,aes256gcm" or can use -the numeric values (in decimal or hexadecimal form) from the HPKE specification -so "0x20,0x01,0x02" is the same as the previous example. - -KEM values supported: p256 or 0x10; p384 or 0x11, p521 or 0x12, x25519 or 0x20, x448 or 0x21 - -KDF values supported: hkdf-sha256 or 0x01, hkdf-sha384 or 0x02, hkdf-sha512 or 0x03 - -AEAD values supported: aes128gcm or 0x01, aes256gcm or 0x02, chachapoly1305 or 0x03 - -=item B<-ech_grease_type> I - -Allows the client to set the TLS extension type for a GREASEd ECH value -(currently equivalent to the ECH version number). The current default is -0xfe0d. - -=item B<-ech_ignore_cid> - -Encrypted Client Hello (ECH) extensions contain a configuration identifier -(cid) taken from the ECHConfigList usually found in the domain name system -(DNS). As those identifiers could be revealing, the client has the option to -use a random value instead. - -=item B<-ech_outer_sni> I - -When doing Encrypted Client Hello (ECH), this allows the caller to specify a -subject name indication (SNI) value to use in the outer ClientHello over-riding -the public_name value from the relevant ECHConfigList. - -=item B<-ech_no_outer_sni> - -Setting this flag means no SNI will be emitted in the outer ClientHello. - -=item B<-ech_select> I - -If an ECHConfigList contains more than one ECHConfig then the client will by -default use the first that works. This allows the caller to specify which -ECHConfig to use (using a zero-based index). - =back =head1 CONNECTED COMMANDS (BASIC) @@ -1036,7 +912,7 @@ then an HTTP command can be given such as "GET /" to retrieve a web page. If the handshake fails then there are several possible causes, if it is nothing obvious like no client certificate then the B<-bugs>, -B<-tls1>, B<-no_tls1> options can be tried +B<-ssl3>, B<-tls1>, B<-no_ssl3>, B<-no_tls1> options can be tried in case it is a buggy server. In particular you should play with these options B submitting a bug report to an OpenSSL mailing list. @@ -1134,7 +1010,7 @@ L, L, L, L, -L +L =head1 HISTORY @@ -1158,13 +1034,9 @@ The and B<-ocsp_check_all> options were added in OpenSSL 3.6. -The B options were added in OpenSSL 4.0. - -The B<-expected-rpks> option was added in OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-s_server.pod.in b/doc/man1/openssl-s_server.pod.in index 2a295cac22..dbf6a30da4 100644 --- a/doc/man1/openssl-s_server.pod.in +++ b/doc/man1/openssl-s_server.pod.in @@ -135,12 +135,6 @@ B B {- $OpenSSL::safe::opt_provider_synopsis -} [B<-enable_server_rpk>] [B<-enable_client_rpk>] -[B<-expected-rpks>] -[B<-ech_key> I] -[B<-ech_dir> I] -[B<-ech_noretry_dir> I] -[B<-ech_trialdecrypt>] -[B<-ech_greaseretries>] =head1 DESCRIPTION @@ -341,11 +335,8 @@ Download CRLs from distribution points given in CDP extensions of certificates =item B<-verifyCAfile> I -A file in PEM format containing trusted CA certificates (root and/or -intermediate) used to verify the client certificate chain. - -This and the following two options, B<-verifyCApath> and B<-verifyCAstore>, -take precedence over the B<-CAfile>, B<-CApath>, and B<-CAstore> options. +A file in PEM format CA containing trusted certificates to use +for verifying client certificates. =item B<-verifyCApath> I @@ -356,26 +347,14 @@ see L for more information. =item B<-verifyCAstore> I -URI of a store containing trusted certificates to use +The URI of a store containing trusted certificates to use for verifying client certificates. -The URI may indicate a single certificate, as well as a collection of them. -With URIs in the C scheme, this is generally treated like B<-verifyCApath> or -B<-verifyCAfile>, depending on whether the URI points to a directory or a single file. -See L for more information on stores and supported schemes. - -Note that B<-CAfile> is the sole source of acceptable issuing -CA names sent to the client in the Certificate Request message during the -handshake; B<-CApath>, B<-CAstore>, and the B<-verifyCA*> options do not -contribute to this list. =item B<-chainCAfile> I A file in PEM format containing trusted certificates to use when attempting to build the server certificate chain. -This and the following two options, B<-chainCApath> and B<-chainCAstore>, -take precedence over the B<-CAfile>, B<-CApath>, and B<-CAstore> options. - =item B<-chainCApath> I A directory containing trusted certificates to use @@ -388,9 +367,10 @@ see L for more information. The URI of a store containing trusted certificates to use for building the server certificate chain provided to the client. The URI may indicate a single certificate, as well as a collection of them. -With URIs in the C scheme, this is generally treated like B<-chainCApath> or -B<-chainCAfile>, depending on whether the URI points to a directory or a single file. -See L for more information on stores and supported schemes. +With URIs in the C scheme, this acts as B<-chainCAfile> or +B<-chainCApath>, depending on if the URI indicates a directory or a +single file. +See L for more information on the C scheme. =item B<-nocert> @@ -789,10 +769,6 @@ has been negotiated, and early data is enabled on the server. A full handshake is forced if a session ticket is used a second or subsequent time. Any early data that was sent will be rejected. -Note that the server manages an internal cache of session tickets. If a client -closes the connection without sending the close_notify alert, the -corresponding session ticket is removed and a full handshake is forced. - =item B<-tfo> Enable acceptance of TCP Fast Open (RFC7413) connections. @@ -811,17 +787,6 @@ Pre-compresses certificates (RFC8879) that will be sent during the handshake. {- $OpenSSL::safe::opt_trust_item -} -The certificates loaded via the B<-CAfile>, B<-CApath>, and B<-CAstore> options -are used as trust anchors when verifying client certificates unless -overridden by B<-verifyCAfile>, B<-verifyCApath>, or B<-verifyCAstore> options. -They are also used as trust anchors when attempting -to build the server certificate chain provided to clients unless -overridden by B<-chainCAfile>, B<-chainCApath>, or B<-chainCAstore> options. - -B<-CAfile> also determines the list of acceptable issuing CA names -sent to the client in the Certificate Request message during the handshake; -B<-CApath>, B<-CAstore>, and the B<-verifyCA*> options do not contribute here. - {- $OpenSSL::safe::opt_r_item -} {- $OpenSSL::safe::opt_provider_item -} @@ -850,50 +815,7 @@ support raw public keys may elect to use them. Clients that don't support raw public keys or prefer to use X.509 certificates can still elect to send X.509 certificates as usual. -=item B<-expected-rpks> I - -This option implies the B<-enable_client_rpk> option and can be specified -multiple times. -Each PEM I should contain one or more public keys, private keys or -certificates. -With a private key or certificate an attempt is made to extract the associated -public key. -Each resulting public key is added (via a call to L as -a valid raw public key that the client may present to be considered verified. -If a client nevertheless presents an X.509 certificate, the enclosed public key -is validated as though it were presented as a raw public key instead. - -Verification success or failure is reported as a DANE verification success or -failure, because verification of raw public keys is internally mapped to -verification of DANE TLSA records derived from the specified keys. - -=item I:I - -=item B<-ech_key> I - -Load one Encrypted Client Hello (ECH) key pair. - -=item B<-ech_dir> I - -Attempt to load an ECH key pair from every file in the named directory. -Any keys successfully loaded will be returned in 'retry_configs'. - -=item B<-ech_noretry_dir> I - -Attempt to load an ECH key pair from every file in the named directory. -Keys loaded will not be returned in 'retry_configs'. - -=item B<-ech_trialdecrypt> - -When an Encrypted Client Hello (ECH) extension is seen in a ClientHello, -attempt to decrypt with all known ECH private keys if necessary. Without -this, the ECH "config_id" is used to match against the loaded ECH private -keys and decryption is only attempted when there's a match. - -=item B<-ech_greaseretries> - -If set, servers will add GREASEy ECHConfig values to those sent -in retry_configs. +Raw public keys are extracted from the configured certificate/private key. =back @@ -987,7 +909,7 @@ L, L, L, L, -L +L =head1 HISTORY @@ -1009,15 +931,11 @@ options were added in OpenSSL 3.2. The B<-status_all> option was added in OpenSSL 3.6. -The B options were added in OpenSSL 4.0. - -The B<-engine> option was removed in OpenSSL 4.0. - -The B<-expected-rpks> option was added in OpenSSL 4.0. +The B option was removed in OpenSSL 4.0. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-s_time.pod.in b/doc/man1/openssl-s_time.pod.in index 32b104d0ab..b483aab68e 100644 --- a/doc/man1/openssl-s_time.pod.in +++ b/doc/man1/openssl-s_time.pod.in @@ -17,7 +17,7 @@ B B [B<-new>] [B<-verify> I] [B<-time> I] -[B<-testmode>] +[B<-ssl3>] [B<-tls1>] [B<-tls1_1>] [B<-tls1_2>] @@ -118,13 +118,6 @@ and optionally transfer payload data from a server. Server and client performance and the link speed determine how many connections it can establish. -=item B<-testmode> - -Runs the s_time command in test mode. Performs only 1 iteration of the new -connection test and 2 iterations of the session reuse test (the latter to -ensure session resumption is actually exercised) regardless of any B<-time> -value. This is intended for use by the test suite. - {- $OpenSSL::safe::opt_name_item -} {- $OpenSSL::safe::opt_trust_item -} @@ -135,7 +128,7 @@ value. This is intended for use by the test suite. This is an obsolete synonym for B<-CAfile>. -=item B<-tls1>, B<-tls1_1>, B<-tls1_2>, B<-tls1_3> +=item B<-ssl3>, B<-tls1>, B<-tls1_1>, B<-tls1_2>, B<-tls1_3> See L. @@ -158,7 +151,7 @@ by the client the same way the aforementioned option does. This command can be used to measure the performance of an SSL connection. To connect to an SSL HTTP server and get the default page the command - openssl s_time -connect servername:443 -www / -CApath yourdir -CAfile yourfile.pem -cipher commoncipher + openssl s_time -connect servername:443 -www / -CApath yourdir -CAfile yourfile.pem -cipher commoncipher [-ssl3] would typically be used (https uses port 443). I is a cipher to which both client and server can agree, see the L command @@ -166,7 +159,7 @@ for details. If the handshake fails then there are several possible causes, if it is nothing obvious like no client certificate then the B<-bugs> and -B<-tls1> options can be tried +B<-ssl3> options can be tried in case it is a buggy server. In particular you should play with these options B submitting a bug report to an OpenSSL mailing list. @@ -198,8 +191,6 @@ fails. The B<-cafile> option was deprecated in OpenSSL 3.0. -The B<-testmode> option was added in OpenSSL 4.1. - =head1 SEE ALSO L, @@ -210,7 +201,7 @@ L =head1 COPYRIGHT -Copyright 2004-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2004-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-sess_id.pod b/doc/man1/openssl-sess_id.pod.in similarity index 95% rename from doc/man1/openssl-sess_id.pod rename to doc/man1/openssl-sess_id.pod.in index 552ecb99e6..92d7500f4f 100644 --- a/doc/man1/openssl-sess_id.pod +++ b/doc/man1/openssl-sess_id.pod.in @@ -1,4 +1,5 @@ =pod +{- OpenSSL::safe::output_do_not_edit_headers(); -} =head1 NAME @@ -97,7 +98,7 @@ These are described below in more detail. =item B -This is the protocol in use TLSv1.3, TLSv1.2, TLSv1.1 or TLSv1. +This is the protocol in use TLSv1.3, TLSv1.2, TLSv1.1, TLSv1 or SSLv3. =item B @@ -151,7 +152,7 @@ L =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-smime.pod.in b/doc/man1/openssl-smime.pod.in index 498d0c5725..061f1f23fb 100644 --- a/doc/man1/openssl-smime.pod.in +++ b/doc/man1/openssl-smime.pod.in @@ -54,9 +54,8 @@ I ... =head1 DESCRIPTION -This command handles S/MIME according to RFC 2311 (1998) with no CMS support. -It can encrypt, decrypt, sign and verify S/MIME 2.0 messages. For newer messages -use the OpenSSL CMS tool. +This command handles S/MIME mail. It can encrypt, decrypt, sign +and verify S/MIME messages. =head1 OPTIONS diff --git a/doc/man1/openssl-verification-options.pod b/doc/man1/openssl-verification-options.pod index e330f8f015..84940673ca 100644 --- a/doc/man1/openssl-verification-options.pod +++ b/doc/man1/openssl-verification-options.pod @@ -73,41 +73,9 @@ The most crucial input to certificate validation is a I, which includes a collection of certificates and validation options. This is akin to what is used in the trust stores of Mozilla Firefox, or Apple's and Microsoft's certificate stores, ... -By default all apparently self-signed certificates in the trust store +By default all self-signed certificates in the trust store are considered to be trust anchors, for all or for specified purposes. -For efficiency reasons, apparently self-signed certificates (based on certificate metadata) -are not subjected to cryptographic self-signature check. -A certificate is apparently self-signed if and only if all of the following conditions are met: - -=over 4 - -=item * - -it is self-issued, i.e., its C and C fields are equal, - -=item * - -the algorithm identifiers of its public key and signature match, - -=item * - -if it has an authorityKeyIdentifier (AKID) extension containing the C field, -its value matches the subjectKeyIdentifier (SKID) extension if present, - -=item * - -if it has an AKID containing the C field, -its value equals the serial number of the certificate, and - -=item * - -if it has an AKID containing the C field -and its C include at least one C, -the first such name equals the C field of the certificate. - -=back - Independent of any extended key usage (EKU) X.509v3 extension included, from the OpenSSL perspective a trust anchor certificate should be augmented with local trust attributes, giving an explicit designation for which @@ -146,7 +114,7 @@ It has a positive trust attribute accepting the EKU associated with the intended purpose or it does not have any positive trust attribute and one of the following compatibility conditions apply: -It is apparently self-signed or the B<-partial_chain> option is given +It is self-signed or the B<-partial_chain> option is given (which corresponds to the B flag being set). =back @@ -176,7 +144,7 @@ the subjectKeyIdentifier and authorityKeyIdentifier extensions are very useful. The subject alternative names (SAN) and issuer alternative names given in subjectAltName or issuerAltName extensions are not relevant for chain building. -Once a apparently self-signed certificate has been added, chain construction stops. +Once a self-signed certificate has been added, chain construction stops. In this case it must fully match a trust anchor, otherwise chain building fails. A candidate issuer certificate matches a subject certificate @@ -212,12 +180,6 @@ it must allow for certificate signing (keyCertSign). The lookup first searches for issuer certificates in the trust store. If it does not find a match there it consults the list of untrusted ("intermediate" CA) certificates, if provided. -If one issuer certificate was found in the trust store, the list of -untrusted certificates will not be consulted anymore to find further -issuer certificates. Therefore, either only the root certificate or an -uninterrupted chain to the root certificate must be provided in the trust -store for a successful verification, if B -is not enabled. =head2 Certification Path Validation @@ -242,7 +204,7 @@ in the L section below. The third step is to check the trust settings on the last certificate or trust anchor, which typically is given as a self-signed root CA certificate. If specified, it must be trusted for the given use. -For compatibility, an apparently self-signed certificate +For compatibility, a self-signed certificate with no trust attributes is considered to be valid for all uses. The fourth, and final, step is to check the validity of the certificate chain. @@ -292,8 +254,7 @@ Do not load the default file of trusted certificates. Use the specified directory as a collection of trusted certificates, i.e., a trust store. -Each file should contain exactly one certificate in PEM format. -It should be named with the hash value of the X.509 SubjectName of the +Files should be named with the hash value of the X.509 SubjectName of each certificate. This is so that the library can extract the IssuerName, hash it, and directly lookup the file to get the issuer certificate. See L for information on creating this type of directory. @@ -304,12 +265,12 @@ Do not use the default directory of trusted certificates. =item B<-CAstore> I -Use I as a store of trusted certificates. -The URI may indicate a single certificate or a collection of them. -When the URI references a file, only the PEM format is supported. -With URIs in the C scheme, this is generally treated like B<-CApath> or -B<-CAfile>, depending on whether the URI indicates a directory or a single file. -See L for more information on stores and supported schemes. +Use I as a store of CA certificates. +The URI may indicate a single certificate, as well as a collection of them. +With URIs in the C scheme, this acts as B<-CAfile> or +B<-CApath>, depending on if the URI indicates a single file or +directory. +See L for more information on the C scheme. These certificates are also used when building the server certificate chain (for example with L) or client certificate @@ -317,7 +278,7 @@ chain (for example with L). =item B<-no-CAstore> -Do not use the default store of trusted certificates. +Do not use the default store of trusted CA certificates. =back @@ -355,6 +316,10 @@ among others, the following certificate well-formedness conditions are checked: =item * +The basicConstraints of CA certificates must be marked critical. + +=item * + CA certificates must explicitly include the keyUsage extension. =item * @@ -384,8 +349,13 @@ The signatureAlgorithm field and the cert signature must be consistent. =item * +Any given authorityKeyIdentifier and any given subjectKeyIdentifier +must not be marked critical. + +=item * + The authorityKeyIdentifier must be given for X.509v3 certs unless they -are apparently self-signed. +are self-signed. =item * @@ -457,7 +427,7 @@ This certificate may be self-issued or belong to an intermediate CA. =item B<-check_ss_sig> Verify the signature of -the last certificate in a chain if the certificate is apparently self-signed. +the last certificate in a chain if the certificate is supposedly self-signed. This is prohibited and will result in an error if it is a non-conforming CA certificate with key usage restrictions not including the keyCertSign bit. This verification is disabled by default because it doesn't add any security. @@ -480,9 +450,9 @@ Since B<-trusted_first> is always on, this option has no effect. =item B<-trusted> I -Parse I as a set of one or more certificates in PEM format. +Parse I as a set of one or more certificates. Each of them qualifies as trusted if has a suitable positive trust attribute -or it is apparently self-signed or the B<-partial_chain> option is specified. +or it is self-signed or the B<-partial_chain> option is specified. This option implies the B<-no-CAfile>, B<-no-CApath>, and B<-no-CAstore> options and it cannot be used with the B<-CAfile>, B<-CApath> or B<-CAstore> options, so only certificates specified using the B<-trusted> option are trust anchors. @@ -490,7 +460,7 @@ This option may be used multiple times. =item B<-untrusted> I -Parse I as a set of one or more certificates in PEM format. +Parse I as a set of one or more certificates. All certificates (typically of intermediate CAs) are considered untrusted and may be used to construct a certificate chain from the target certificate to a trust anchor. @@ -533,7 +503,7 @@ and thus the commands L and L check for consistency with TLS server (C) or TLS client use (C), respectively. By default, CMS signature validation, which can be done via L, -checks for consistency with the S/MIME signing purpose (C). +checks for consistency with S/MIME signing use (C). While IETF RFC 5280 says that B and B are only for WWW use, in practice they are used for all kinds of TLS clients @@ -567,7 +537,7 @@ the subject certificate. Use a set of verification parameters, also known as verification method, identified by I. The currently predefined methods are named C, -C, C with alias C, C, C, and C. +C, C with alias C, C, and C. These mimic the combinations of purpose and trust settings used in SSL/(D)TLS, CMS/PKCS7 (including S/MIME), and code signing. @@ -677,13 +647,6 @@ it checks that any present EKU extension (that does not contain B) contains the respective EKU as detailed below. Moreover, it does these checks even for trust anchor certificates. -=head3 Duplicate Extensions - -According to RFC 5280 section 4.2, a certificate MUST NOT include more -than one instance of a particular extension. If a duplicate extension is -detected, the certificate is rejected. -This check applies to all certificates: end-entity certificates, intermediate CA certificates, and root CA (trust anchor) certificates. - =head3 Checks Implied by Specific Predefined Policies A specific description of each check is given below. The comments about @@ -814,12 +777,11 @@ L Since OpenSSL 1.1.0, the B<-trusted_first> option is always enabled. -The checks enabled by B<-x509_strict> have been extended in OpenSSL 3.0, -which has been partially reverted in OpenSSL 4.0. +The checks enabled by B<-x509_strict> have been extended in OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-verify.pod.in b/doc/man1/openssl-verify.pod.in index 2d7ec3ce9d..0f6a1ba463 100644 --- a/doc/man1/openssl-verify.pod.in +++ b/doc/man1/openssl-verify.pod.in @@ -97,11 +97,6 @@ input. =back -Note that the first parameter that does not begin with a B<-> ends the list -of options and starts the list of certificates. If you place any options -after a certificate filename, they will be interpreted not as options -but as certificates. - =head1 DIAGNOSTICS When a verify operation fails the output messages can be somewhat cryptic. The @@ -138,7 +133,7 @@ The B<-engine> option was removed in OpenSSL 4.0. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-version.pod b/doc/man1/openssl-version.pod.in similarity index 95% rename from doc/man1/openssl-version.pod rename to doc/man1/openssl-version.pod.in index 5c08f22f6e..ba666244f3 100644 --- a/doc/man1/openssl-version.pod +++ b/doc/man1/openssl-version.pod.in @@ -1,4 +1,5 @@ =pod +{- OpenSSL::safe::output_do_not_edit_headers(); -} =head1 NAME @@ -103,7 +104,7 @@ in a bug report. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl-x509.pod.in b/doc/man1/openssl-x509.pod.in index cbb2ab29e2..43a5747d80 100644 --- a/doc/man1/openssl-x509.pod.in +++ b/doc/man1/openssl-x509.pod.in @@ -229,14 +229,6 @@ but are described in the L section. Specify the date output format. Values are: rfc_822 and iso_8601. Defaults to rfc_822. -Note that despite its name, the rfc_822 format does not conform to RFC 822 -or its successors RFC 2822 and RFC 5322. It outputs dates in the format -"Mmm DD HH:MM:SS YYYY GMT" (e.g., "Jul 31 22:20:50 2017 GMT"). The month -appears before the day, unlike all three RFCs, which put the day first. -The 4-digit year differs from RFC 822 (which used 2-digit years), and the -timezone name "GMT" is obsolete per RFC 2822 and RFC 5322 (which require -numeric offsets such as "+0000"). - =item B<-text> Prints out the certificate in text form. Full details are printed including the @@ -379,15 +371,6 @@ Check that the certificate matches the specified email address. Check that the certificate matches the specified IP address. -Certificate checking is done with X.509 certificate verification, -which will fail when encountering an error. As such, when combining -the B<-checkhost>, B<-checkemail>, and B<-checkip> flags, verify will -indicate success if all checks pass, and will indicate failure if they -do not. A diagnostic message of only the first encountered failed -check that stops certificate verification will be printed in the -failing case. If a specific diagnostic message is needed for -individual checks they should be tried individually. - =back =head2 Certificate Output Options @@ -500,45 +483,20 @@ neither subject identifier nor authority key identifier extensions are included. Configuration file containing certificate and request X.509 extensions to add. -When both of the B<-extfile> I and B<-extensions> I
options -are given, the extensions to add are taken from the named I
of the -file named I. -This file must exist, be readable, and all the listed extensions must be valid. - -If only the B<-extfile> I option is given, the section name to use is -taken from the value of the variable named C in the file's unnamed -section (also called its B section, see L). -If no B setting is found, the file's B (unnamed) section -itself is instead used as the list of extensions to add. -As before, the file must be readable and all the extensions must be valid. - -Prior to OpenSSL 4.0, the B<-extensions> option required that the B<-extfile> -option be also specified. -As of OpenSSL 4.0 the default configuration file is used instead as described -below. - -If only the B<-extensions> I
option is given, the named I
of -the default configuration file, whether from the C environment -variable, or the built-in default, is used as list of extensions to add. -As before, the file must be readable and all the extensions must be valid. - -If neither of the options are given, an attempt is made to open the default -configuration file (as detailed above). -If the file does not exist or cannot be opened, no extensions are added. -If the unnamed section (B, see L) of the file does not list -an B variable, no extensions are added. -Otherwise, the section named by the B variable is taken to be the -list of extensions to add. -The extensions listed there must all be valid. - =item B<-extensions> I
The section in the extfile to add X.509 extensions from. -See the description of B<-extfile> above for details. +If this option is not +specified then the extensions should either be contained in the unnamed +(default) section or the default section should contain a variable called +"extensions" which contains the section to use. See the L manual page for details of the extension section format. +Unless specified otherwise, +key identifier extensions are included as described in L. + =item B<-sigopt> I:I Pass options to the signature algorithm during sign operations. @@ -870,7 +828,6 @@ L, L, L, L, -L, L =head1 HISTORY @@ -891,17 +848,9 @@ and key identifier extensions are included by default. The B<-engine> option was removed in OpenSSL 4.0. -OpenSSL 4.0 added support for specifying extensions to add via the default -configuration file. -See B<-extfile> above for details. - -As of OpenSSL 4.0, the B utility no longer has specialised built-in logic -to add the SKID or AKID extensions, they are handled through configuration -files and command-line options just like any other extension. - =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man1/openssl.pod b/doc/man1/openssl.pod index 27f1d3c88e..9b6ed98cfb 100644 --- a/doc/man1/openssl.pod +++ b/doc/man1/openssl.pod @@ -123,10 +123,6 @@ L and L. EC (Elliptic curve) key processing. -=item B - -Encrypted Client Hello (ECH) admin. See L. - =item B EC parameter manipulation and generation. @@ -601,7 +597,7 @@ OpenSSL was built. =over 4 -=item B<-tls1>, B<-tls1_1>, B<-tls1_2>, B<-tls1_3>, B<-no_ssl3>, B<-no_tls1>, B<-no_tls1_1>, B<-no_tls1_2>, B<-no_tls1_3> +=item B<-ssl3>, B<-tls1>, B<-tls1_1>, B<-tls1_2>, B<-tls1_3>, B<-no_ssl3>, B<-no_tls1>, B<-no_tls1_1>, B<-no_tls1_2>, B<-no_tls1_3> These options require or disable the use of the specified SSL or TLS protocols. When a specific TLS version is required, only that version will be offered or @@ -760,7 +756,7 @@ a replacement. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/ADMISSIONS.pod b/doc/man3/ADMISSIONS.pod index d4db385d9b..f86aac922a 100644 --- a/doc/man3/ADMISSIONS.pod +++ b/doc/man3/ADMISSIONS.pod @@ -98,7 +98,7 @@ PROFESSION_INFO_set0_registrationNumber The B, B, B, and B types are opaque structures representing the analogous types defined in the Common PKI Specification published -by L. +by L. Knowledge of those structures and their semantics is assumed. The conventional routines to convert between DER and the local format diff --git a/doc/man3/ASN1_BIT_STRING_get_length.pod b/doc/man3/ASN1_BIT_STRING_get_length.pod deleted file mode 100644 index 7fb935cdde..0000000000 --- a/doc/man3/ASN1_BIT_STRING_get_length.pod +++ /dev/null @@ -1,156 +0,0 @@ -=pod - -=head1 NAME - -ASN1_BIT_STRING_set, -ASN1_BIT_STRING_set1, -ASN1_BIT_STRING_set_bit, -ASN1_BIT_STRING_get_bit, -ASN1_BIT_STRING_check, -ASN1_BIT_STRING_name_print, -ASN1_BIT_STRING_num_asc, -ASN1_BIT_STRING_set_asc, -ASN1_BIT_STRING_get_length - ASN1_BIT_STRING accessors - -=head1 SYNOPSIS - - #include - - typedef struct BIT_STRING_BITNAME_st { - int bitnum; - const char *lname; - const char *sname; - } BIT_STRING_BITNAME; - - int ASN1_BIT_STRING_set_bit(ASN1_BIT_STRING *a, int n, int value); - int ASN1_BIT_STRING_get_bit(const ASN1_BIT_STRING *a, int n); - int ASN1_BIT_STRING_check(const ASN1_BIT_STRING *a, - const unsigned char *flags, int flags_len); - - int ASN1_BIT_STRING_get_length(const ASN1_BIT_STRING *bitstr, - size_t *length, int *unused_bits); - int ASN1_BIT_STRING_set1(ASN1_BIT_STRING *bitstr, const uint8_t *data, - size_t length, int unused_bits); - -The following function have been deprecated since OpenSSL 4.1, and can be -hidden entirely by defining B with a suitable version value, -see L: - - int ASN1_BIT_STRING_set(ASN1_BIT_STRING *a, unsigned char *d, int length); - int ASN1_BIT_STRING_name_print(BIO *out, ASN1_BIT_STRING *bs, - BIT_STRING_BITNAME *tbl, int indent); - int ASN1_BIT_STRING_num_asc(const char *name, BIT_STRING_BITNAME *tbl); - int ASN1_BIT_STRING_set_asc(ASN1_BIT_STRING *bs, const char *name, - int value, BIT_STRING_BITNAME *tbl); - -=head1 DESCRIPTION - -The ASN.1 BIT STRING type holds a bit string of arbitrary bit length. -In the distinguished encoding rules DER, its bits are encoded in -groups of eight, leaving between zero and seven bits of the -last octet unused. If there are unused bits, they must all be set to -zero. - -ASN1_BIT_STRING_set_bit() sets the Ith bit (counted from 0 as the -least significant bit) of a bit string I to I which is -interpreted as a boolean. - -ASN1_BIT_STRING_get_bit() returns the bit value of the Ith bit in the -bit string I. - -ASN1_BIT_STRING_check() checks if the I bit string contains only bits -specified by the I vector. I is the length of I -in bytes. - -ASN1_BIT_STRING_get_length() returns the number of octets in I -containing bit values in I and the number of unused bits in -the last octet in I. The value returned in -I is guaranteed to be between 0 and 7, inclusive. - -ASN1_BIT_STRING_set() sets the octets of I to the bits in the -byte string I of I octets. - -ASN1_BIT_STRING_set1() sets the type of I to -I and its octets to the bits in the byte string -I of length I octets, making sure that the last -I bits in the last byte are zero. - -ASN1_BIT_STRING_name_print() prints the corresponding bit name specified -in I to I based on the bit string I. I might be -specified for a number of spaces to indent the line. This function has -been deprecated as of OpenSSL 4.1. For a replacement strategy, consider -using a descriptive #define for the bit value, or if your application -truly needs to do this with strings, implementing your own string to -integer lookup table. - -ASN1_BIT_STRING_num_asc() searches for the provided I in I -and I fields of I's elements and returns the corresponding -I field value in case there is a match found. This function has -been deprecated as of OpenSSL 4.1. For a replacement strategy, consider -using a descriptive #define for the bit value, or if your application -truly needs to do this with strings, implementing your own string to -integer lookup table. - -ASN1_BIT_STRING_set_asc() sets the corresponding bit to I in I -based on the conversion table I. This function has -been deprecated as of OpenSSL 4.1. For a replacement strategy, consider -using a descriptive #define for the bit value, or if your application -truly needs to do this with strings, implementing your own string to -integer lookup table. - -=head1 RETURN VALUES - -ASN1_BIT_STRING_set_bit() returns 1 on success or 0 on incorrect input -values. - -ASN1_BIT_STRING_get_bit() returns the value of the requested bit or 0 -when data not available for the requested arguments. - -ASN1_BIT_STRING_check() returns 0 if there is at least one bit set in -I which is not specified in I, 1 otherwise. - -ASN1_BIT_STRING_name_print() returns 1 on success, or 0 when the print -functions fail. - -ASN1_BIT_STRING_num_asc() returns the bit number of the requested -I or -1 when the name was not found. - -ASN1_BIT_STRING_set_asc() returns 1 on success or 0 on failure. - -ASN1_BIT_STRING_get_length() returns 1 on success or 0 if the encoding -of I is internally inconsistent, or if one of I, -I, or I is NULL. - -ASN1_BIT_STRING_set() returns 1 on success or 0 if memory allocation fails, -I is not specified (value less than 0) and I is NULL or -I is larger than INT_MAX-1. - -ASN1_BIT_STRING_set1() returns 1 on success or 0 if memory allocation -fails or if I is NULL, I is too large, I is -zero and I is nonzero, I is less than 0 or -greater than 7, or any unused bit in the last octet of I is -nonzero. - -=head1 HISTORY - -Functions ASN1_BIT_STRING_get_length() and ASN1_BIT_STRING_set1() were -added in OpenSSL version 4.0. - -ASN1_BIT_STRING_set() was deprecated in OpenSSL 4.1 in favour of -ASN1_BIT_STRING_set1(). -ASN1_BIT_STRING_name_print() ASN1_BIT_STRING_num_asc(), and -ASN1_BIT_STRING_set_asc(), Along with the BIT_STRING_BITNAME structure -were present but undocumented in all versions of OpenSSL as public -API. They are unused by the library. They were documented and then -deprecated in OpenSSL 4.1. - -=head1 COPYRIGHT - -Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - -Licensed under the Apache License 2.0 (the "License"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file LICENSE in the source distribution or at -L. - -=cut diff --git a/doc/man3/ASN1_BIT_STRING_new.pod b/doc/man3/ASN1_BIT_STRING_new.pod deleted file mode 100644 index 010aa25392..0000000000 --- a/doc/man3/ASN1_BIT_STRING_new.pod +++ /dev/null @@ -1,45 +0,0 @@ -=pod - -=head1 NAME - -ASN1_BIT_STRING_new, ASN1_BIT_STRING_free - ASN1_BIT_STRING allocation functions - -=head1 SYNOPSIS - -=for openssl generic - - #include - - ASN1_BIT_STRING *ASN1_BIT_STRING_new(void); - void ASN1_BIT_STRING_free(ASN1_BIT_STRING *a); - -=head1 DESCRIPTION - -ASN1_BIT_STRING_new() returns an allocated B structure. - -ASN1_BIT_STRING_free() frees up a single B object. -If the argument is NULL, nothing is done. - -B structure representing the ASN.1 BIT_STRING type. - -=head1 RETURN VALUES - -ASN1_BIT_STRING_new() return a valid B structure or NULL -if an error occurred. - -ASN1_BIT_STRING_free() does not return a value. - -=head1 SEE ALSO - -L - -=head1 COPYRIGHT - -Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - -Licensed under the Apache License 2.0 (the "License"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file LICENSE in the source distribution or at -L. - -=cut diff --git a/doc/man3/ASN1_INTEGER_get_int64.pod b/doc/man3/ASN1_INTEGER_get_int64.pod index d25c87a5e2..4ba6c4c0d7 100644 --- a/doc/man3/ASN1_INTEGER_get_int64.pod +++ b/doc/man3/ASN1_INTEGER_get_int64.pod @@ -108,7 +108,7 @@ B structure respectively or NULL if an error occurs. They will only fail due to a memory allocation error. ASN1_INTEGER_to_BN() and ASN1_ENUMERATED_to_BN() return a B structure -or NULL if an error occurs. They can fail if the passed type is incorrect +of NULL if an error occurs. They can fail if the passed type is incorrect (due to programming error) or due to a memory allocation failure. =head1 SEE ALSO diff --git a/doc/man3/ASN1_OBJECT_new.pod b/doc/man3/ASN1_OBJECT_new.pod index 28f917cb1a..4e1a3740ea 100644 --- a/doc/man3/ASN1_OBJECT_new.pod +++ b/doc/man3/ASN1_OBJECT_new.pod @@ -8,21 +8,15 @@ ASN1_OBJECT_new, ASN1_OBJECT_free - object allocation functions #include - void ASN1_OBJECT_free(ASN1_OBJECT *a); - -The following functions have been deprecated since OpenSSL 4.0, and can be -hidden entirely by defining B with a suitable version value, -see L: - ASN1_OBJECT *ASN1_OBJECT_new(void); + void ASN1_OBJECT_free(ASN1_OBJECT *a); =head1 DESCRIPTION The B allocation routines, allocate and free an B structure, which represents an ASN1 OBJECT IDENTIFIER. -ASN1_OBJECT_new() is deprecated and exists for legacy backward compatibility -reasons and always returns NULL. +ASN1_OBJECT_new() allocates and initializes an B structure. ASN1_OBJECT_free() frees up the B structure I. If I is NULL, nothing is done. @@ -35,21 +29,19 @@ such as OBJ_nid2obj() are used instead. =head1 RETURN VALUES -ASN1_OBJECT_new() always return NULL. +If the allocation fails, ASN1_OBJECT_new() returns NULL and sets an error +code that can be obtained by L. +Otherwise it returns a pointer to the newly allocated structure. ASN1_OBJECT_free() returns no value. =head1 SEE ALSO -L - -=head1 HISTORY - -ASN1_OBJECT_new() was deprecated in OpenSSL 4.0. +L, L =head1 COPYRIGHT -Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2002-2016 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/ASN1_STRING_length.pod b/doc/man3/ASN1_STRING_length.pod index 5b047f084a..47cacb253a 100644 --- a/doc/man3/ASN1_STRING_length.pod +++ b/doc/man3/ASN1_STRING_length.pod @@ -2,7 +2,6 @@ =head1 NAME -ASN1_STRING_set_data, ASN1_STRING_set_string, ASN1_STRING_length_ex, ASN1_STRING_dup, ASN1_STRING_cmp, ASN1_STRING_set, ASN1_STRING_length, ASN1_STRING_type, ASN1_STRING_get0_data, ASN1_STRING_to_UTF8 - ASN1_STRING utility functions @@ -11,30 +10,19 @@ ASN1_STRING_to_UTF8 - ASN1_STRING utility functions #include + int ASN1_STRING_length(ASN1_STRING *x); const unsigned char *ASN1_STRING_get0_data(const ASN1_STRING *x); ASN1_STRING *ASN1_STRING_dup(const ASN1_STRING *a); int ASN1_STRING_cmp(ASN1_STRING *a, ASN1_STRING *b); + int ASN1_STRING_set(ASN1_STRING *str, const void *data, int len); + int ASN1_STRING_type(const ASN1_STRING *x); int ASN1_STRING_to_UTF8(unsigned char **out, const ASN1_STRING *in); - int ASN1_STRING_set_data(ASN1_STRING *str, const uint8_t *data, size_t len); - - int ASN1_STRING_set_string(ASN1_STRING *str, const char *data); - - size_t ASN1_STRING_length_ex(const ASN1_STRING *x); - -The following functions have been deprecated since OpenSSL 4.1, and can be -hidden entirely by defining B with a suitable version value, -see L: - - int ASN1_STRING_set(ASN1_STRING *str, const void *data, int len); - - int ASN1_STRING_length(ASN1_STRING *x); - =head1 DESCRIPTION These functions allow an B structure to be manipulated. @@ -50,25 +38,9 @@ ASN1_STRING_dup() returns a copy of the structure I. ASN1_STRING_cmp() compares I and I returning 0 if the two are identical. The string types and content are compared. -ASN1_STRING_set() allocates memory for string I to hold I -bytes of data. Any previously allocated memory owned by I will be -freed or re-used. If I is not NULL, I bytes are copied -from the memory pointed to by I to I. If I is -1 then -the length is determined by strlen(data). - -ASN1_STRING_set_data() allocates memory for string I to hold -I bytes of data. Any previously allocated memory owned by I -will be freed or re-used. If I is not NULL, I bytes are -copied from the memory pointed to by I to I. It is an error -to use this function on a string of type B. - -ASN1_STRING_set_string() allocates memory for the string I and makes -a copy of the characters from I. Any previously -allocated memory owned by I will be freed or re-used. I -must point to a valid NUL-terminated C string, and must not be -NULL. The terminating NUL byte is not included in the data copied into -I. It is an error to use this function on a string of type -B. +ASN1_STRING_set() sets the data of string I to the buffer +I or length I. The supplied data is copied. If I +is -1 then the length is determined by strlen(data). ASN1_STRING_type() returns the type of I, using standard constants such as B. @@ -98,9 +70,8 @@ actual string type itself: for example for an IA5String the data will be ASCII, for a BMPString two bytes per character in big endian format, and for a UTF8String it will be in UTF8 format. -Similar care should be taken to ensure the data is in the correct -format when calling ASN1_STRING_set(), ASN1_STRING_set_data(), or -ASN1_STRING_set_string(). +Similar care should be take to ensure the data is in the correct format +when calling ASN1_STRING_set(). =head1 RETURN VALUES @@ -115,8 +86,7 @@ error occurred. ASN1_STRING_cmp() returns an integer greater than, equal to, or less than 0, according to whether I is greater than, equal to, or less than I. -ASN1_STRING_set(), ASN1_STRING_set_data(), and -ASN1_STRING_set_string() return 1 on success or 0 on error or failure. +ASN1_STRING_set() returns 1 on success or 0 on error. ASN1_STRING_type() returns the type of I. @@ -127,11 +97,6 @@ negative value if an error occurred. L -=head1 HISTORY - -ASN1_STRING_set_data(), ASN1_STRING_set_string(), and ASN1_STRING_length_ex() -were added in OpenSSL 4.1. - =head1 COPYRIGHT Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved. diff --git a/doc/man3/ASN1_STRING_new.pod b/doc/man3/ASN1_STRING_new.pod index 7698f7411e..642b6f4777 100644 --- a/doc/man3/ASN1_STRING_new.pod +++ b/doc/man3/ASN1_STRING_new.pod @@ -2,8 +2,7 @@ =head1 NAME -ASN1_STRING_new, ASN1_STRING_type_new, ASN1_STRING_free, -ASN1_STRING_new_not_owned - +ASN1_STRING_new, ASN1_STRING_type_new, ASN1_STRING_free - ASN1_STRING allocation functions =head1 SYNOPSIS @@ -12,7 +11,6 @@ ASN1_STRING allocation functions ASN1_STRING *ASN1_STRING_new(void); ASN1_STRING *ASN1_STRING_type_new(int type); - ASN1_STRING *ASN1_STRING_new_not_owned(int type, const uint8_t *data, size_t length); void ASN1_STRING_free(ASN1_STRING *a); =head1 DESCRIPTION @@ -23,15 +21,6 @@ is undefined. ASN1_STRING_type_new() returns an allocated B structure of type I. -ASN1_STRING_new_not_owned() returns an allocated B -structure of type I, and sets the data returned string to the -bytes at I of length I. Ownership of I is not -transferred, and it is the caller's responsibility to ensure that -I outlives any successfully returned result. The provided I -must not be V_ASN1_BIT_STRING, the provided I must be greater -than 0, and I must not be NULL. It is an error if the provided -data size exceeds the internal limit of the ASN1_STRING implementation. - ASN1_STRING_free() frees up I. If I is NULL nothing is done. @@ -40,16 +29,10 @@ If I is NULL nothing is done. Other string types call the B functions. For example ASN1_OCTET_STRING_new() calls ASN1_STRING_type_new(V_ASN1_OCTET_STRING). -ASN1_STRING_new_not_owned() does not automatically call strlen() -to determine a length, or guarantee that the data is a C string. The -data contained in the string and the lifetime of it are the -responsibility of the caller. - =head1 RETURN VALUES -ASN1_STRING_new(), ASN1_STRING_type_new(), and -ASN1_STRING_new_not_owned() return a valid B -structure or NULL if an error occurred. +ASN1_STRING_new() and ASN1_STRING_type_new() return a valid +B structure or NULL if an error occurred. ASN1_STRING_free() does not return a value. @@ -57,10 +40,6 @@ ASN1_STRING_free() does not return a value. L -=head1 HISTORY - -ASN1_STRING_new_not_owned() was added in OpenSSL 4.1. - =head1 COPYRIGHT Copyright 2002-2023 The OpenSSL Project Authors. All Rights Reserved. diff --git a/doc/man3/ASN1_aux_cb.pod b/doc/man3/ASN1_aux_cb.pod index 9a38ab168f..9963ea1350 100644 --- a/doc/man3/ASN1_aux_cb.pod +++ b/doc/man3/ASN1_aux_cb.pod @@ -59,7 +59,7 @@ Arbitrary application data =item I -Flags which indicate the auxiliary functionality supported. +Flags which indicate the auxiliarly functionality supported. The B flag indicates that objects support reference counting. @@ -106,11 +106,9 @@ During the processing of an B object the callbacks set via I or I will be invoked as a result of various events indicated via the I parameter. The value of I<*in> will be the B object being processed based on the template in I. An -additional operation specific parameter may be passed in I. The -currently supported operations are as follows. Unless noted otherwise below, -the callbacks should return a positive value on success and zero on error; -some operations recognise additional return values, and a few do not consult -the return value at all. +additional operation specific parameter may be passed in I. The currently +supported operations are as follows. The callbacks should return a positive +value on success or zero on error, unless otherwise noted below. =over 4 @@ -132,15 +130,13 @@ I<*pval>. Invoked when processing a B, B or B structure immediately before an B is freed. If the callback originally constructed the B via B then it should free it at -this point and return 2; the caller will then skip its normal freeing. Any -other return value (including zero) causes the caller to proceed with normal -freeing; the hook cannot signal an error. +this point and return 2 from the callback. Otherwise it should return 1 for +success or 0 on error. =item B Invoked when processing a B, B or B structure -immediately after B sub-structures are freed. The caller does not -consult the return value from this hook. +immediately after B sub-structures are freed. =item B @@ -166,10 +162,7 @@ immediately after a "i2d" operation for the B. Invoked when processing a B or B structure immediately before printing the B. The I argument will be a pointer to an -B structure (see below). If the callback has fully printed the -value itself it should return 2; the caller will then skip the per-field -printing loop and the matching B callback. Return zero on -error or any other positive value to continue with normal printing. +B structure (see below). =item B @@ -267,41 +260,8 @@ The streaming I/O boundary. =head1 RETURN VALUES -In general the callbacks return zero on error and a positive value on -success. Several operations have additional or different return-value -semantics, summarised here: - -=over 4 - -=item * - -B recognises a return of 2, meaning that the callback has -allocated the B itself and normal allocation should be skipped. - -=item * - -B recognises a return of 2, meaning that the callback has -freed the B itself and normal freeing should be skipped. Other -return values (including zero) cause normal freeing to proceed; the hook -cannot signal an error. - -=item * - -B's return value is not consulted by the caller. - -=item * - -B recognises a return of 2, meaning that the callback -has printed the value itself; the caller will skip the per-field printing -loop and the matching B invocation. - -=item * - -B, B, B, and -B treat any non-positive return value (zero or -negative) as an error. - -=back +The callbacks return 0 on error and a positive value on success. Some operations +require specific positive success values as noted above. =head1 SEE ALSO diff --git a/doc/man3/ASN1_item_d2i_bio.pod b/doc/man3/ASN1_item_d2i_bio.pod index 9b3f389a23..f8e4678367 100644 --- a/doc/man3/ASN1_item_d2i_bio.pod +++ b/doc/man3/ASN1_item_d2i_bio.pod @@ -59,16 +59,6 @@ B provided in the I parameter and the property query string in I. See L for more information about algorithm fetching. -When reading from I, decoding consumes one complete DER-encoded structure -and leaves any following bytes in the BIO, so concatenated structures can be -read with successive calls. Reaching the end of the input cleanly, at a -structure boundary, is not treated as an error: the function returns NULL -without adding to the error queue. If the end of the input is reached in the -middle of a structure, or an indefinite-length value is missing its -end-of-contents octets (that is, the input is truncated), an error is queued -with reason code B. The same applies to -ASN1_item_d2i_fp_ex(). - ASN1_item_d2i_bio() is the same as ASN1_item_d2i_bio_ex() except that the default B is used (i.e. NULL) and with a NULL property query string. @@ -102,12 +92,6 @@ that the I and I can be used when doing algorithm fetching. ASN1_item_d2i_bio(), ASN1_item_unpack_ex() and ASN1_item_unpack() return a pointer to an B or NULL on error. -The ASN1_item_d2i_bio() and ASN1_item_d2i_fp() functions, including their -B<_ex> variants, also return NULL at a clean end of input. In that case the -error queue is left unchanged, so a caller reading concatenated structures in -a loop can distinguish a clean end of input from a decoding error by -inspecting the error queue, for example with L. - ASN1_item_i2d_mem_bio() returns a pointer to a memory BIO or NULL on error. ASN1_item_pack() returns a pointer to an B or NULL on error. @@ -121,7 +105,7 @@ The function ASN1_item_unpack_ex() was added in OpenSSL 3.2. =head1 COPYRIGHT -Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2021-2023 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/BIO_ctrl.pod b/doc/man3/BIO_ctrl.pod index 6d6a72eb46..2f9f3978e8 100644 --- a/doc/man3/BIO_ctrl.pod +++ b/doc/man3/BIO_ctrl.pod @@ -65,11 +65,8 @@ BIO_tell() returns the current file position of a file related BIO. BIO_flush() normally writes out any internally buffered data, in some cases it is used to signal EOF and that no more data will be written. -BIO_eof() returns 1 if the BIO has reached end-of-file as a result of -the most recent read operation. The precise meaning of "EOF" varies -according to the BIO type. The function reports the result of the -previous read attempt and does not update this state based on subsequent -operations. +BIO_eof() returns 1 if the BIO has read EOF, the precise meaning of +"EOF" varies according to the BIO type. BIO_set_close() sets the BIO B close flag to B. B can take the value BIO_CLOSE or BIO_NOCLOSE. Typically BIO_CLOSE is used @@ -182,7 +179,7 @@ were added in OpenSSL 3.2. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2022 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/BIO_f_cipher.pod b/doc/man3/BIO_f_cipher.pod index f733f12cf6..cb6b14a0c0 100644 --- a/doc/man3/BIO_f_cipher.pod +++ b/doc/man3/BIO_f_cipher.pod @@ -58,10 +58,6 @@ should be called to determine if the decrypt was successful. As always, if BIO_gets() or BIO_puts() support is needed then it can be achieved by preceding the cipher BIO with a buffering BIO. -BIO_f_cipher() uses a fixed size buffer when calling EVP_CipherUpdate(), -which is a potential point of failure for ciphers that do not support -streaming (such as AES-WRAP). - =head1 RETURN VALUES BIO_f_cipher() returns the cipher BIO method. @@ -75,7 +71,7 @@ BIO_get_cipher_ctx() returns 1 for success and <=0 for failure. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/BIO_f_ssl.pod b/doc/man3/BIO_f_ssl.pod index 000f34e9e9..a6eff2bb49 100644 --- a/doc/man3/BIO_f_ssl.pod +++ b/doc/man3/BIO_f_ssl.pod @@ -56,7 +56,6 @@ SSL structure is also freed using SSL_free(). BIO_set_ssl() sets the internal SSL pointer of SSL BIO B to B using the close flag B. -On success, ownership of B is transferred to BIO B. BIO_get_ssl() retrieves the SSL pointer of SSL BIO B, it can then be manipulated using the standard SSL library functions. diff --git a/doc/man3/BIO_get_data.pod b/doc/man3/BIO_get_data.pod index b2debd2bc5..aeb6b1c7e9 100644 --- a/doc/man3/BIO_get_data.pod +++ b/doc/man3/BIO_get_data.pod @@ -18,7 +18,7 @@ BIO_get_shutdown - functions for managing BIO state information =head1 DESCRIPTION -These functions can be used when implementing a custom BIO. +These functions are mainly useful when implementing a custom BIO. The BIO_set_data() function associates the custom data pointed to by B with the BIO. This data can subsequently be retrieved via a call to BIO_get_data(). @@ -36,13 +36,6 @@ The BIO_set_shutdown() and BIO_get_shutdown() functions set and get the state of this BIO's shutdown (i.e. BIO_CLOSE) flag. If set then the underlying resource is also closed when the BIO is freed. -=head1 WARNINGS - -Do not use BIO_set_data(), BIO_get_data(), BIO_set_init(), BIO_get_init(), outside -the implementation of a custom BIO. -Calling BIO_set_data() on an existing BIO implementation with data that it does -not expect will lead to unexpected results. - =head1 RETURN VALUES BIO_get_data() returns a pointer to the implementation specific custom data @@ -62,7 +55,7 @@ The functions described here were added in OpenSSL 1.1.0. =head1 COPYRIGHT -Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2016 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/BIO_meth_new.pod b/doc/man3/BIO_meth_new.pod index 9dfd8d7c03..e7d5ff6723 100644 --- a/doc/man3/BIO_meth_new.pod +++ b/doc/man3/BIO_meth_new.pod @@ -111,35 +111,16 @@ BIO_meth_get_write_ex() and BIO_meth_set_write_ex() get and set the function used for writing arbitrary length data to the BIO respectively. This function will be called in response to the application calling BIO_write_ex() or BIO_write(). The parameters for the function have the same meaning as for -BIO_write_ex() and it must return values as described for BIO_write_ex(). - -Older code may call BIO_meth_get_write() and BIO_meth_set_write() instead -to set an old-style write function. The parameters for the function have the -same meaning as for BIO_write() and it must return values as described for -BIO_write(). - -Functions set by BIO_meth_set_write_ex() and BIO_meth_set_write() must call -BIO_set_flags() to set the BIO_FLAGS_SHOULD_RETRY flag in relevant situations. - -Applications should not call both BIO_meth_set_write_ex() and -BIO_meth_set_write() or call BIO_meth_get_write() +BIO_write_ex(). Older code may call BIO_meth_get_write() and +BIO_meth_set_write() instead. Applications should not call both +BIO_meth_set_write_ex() and BIO_meth_set_write() or call BIO_meth_get_write() when the function was set with BIO_meth_set_write_ex(). BIO_meth_get_read_ex() and BIO_meth_set_read_ex() get and set the function used for reading arbitrary length data from the BIO respectively. This function will be called in response to the application calling BIO_read_ex() or BIO_read(). -The parameters for the function have the same meaning as for BIO_read_ex() -and it must return values as described for BIO_read_ex(). -The function must handle the end-of-file condition (if applicable) and return 0 -in this case. - -Older code may call BIO_meth_get_read() and BIO_meth_set_read() instead to -set an old-style read function. The parameters for the function have the same -meaning as for BIO_read() and it must return values as described for BIO_read(). - -Functions set by BIO_meth_set_read_ex() and BIO_meth_set_read() must call -BIO_set_flags() to set the BIO_FLAGS_SHOULD_RETRY flag in relevant situations. - +The parameters for the function have the same meaning as for BIO_read_ex(). +Older code may call BIO_meth_get_read() and BIO_meth_set_read() instead. Applications should not call both BIO_meth_set_read_ex() and BIO_meth_set_read() or call BIO_meth_get_read() when the function was set with BIO_meth_set_read_ex(). @@ -160,14 +141,6 @@ processing ctrl messages in the BIO respectively. See the L page fo more information. This function will be called in response to the application calling BIO_ctrl(). The parameters for the function have the same meaning as for BIO_ctrl(). -If the concept of end-of-file is meaningful for a BIO and the read method is -set using BIO_meth_set_read_ex(), the ctrl function must handle the BIO_CTRL_EOF -command and return an appropriate value (1 if EOF has been reached, 0 if not, -or a negative value on failure), at least immediately after a read operation. -If the read method is set using BIO_meth_set_read(), handling of the -BIO_CTRL_EOF command is not mandatory; however, if such handling is implemented, -it must return 1 if the read function returned 0 when attempting to read a -nonzero number of bytes. BIO_meth_get_create() and BIO_meth_set_create() get and set the function used for creating a new instance of the BIO respectively. This function will be @@ -237,7 +210,7 @@ OpenSSL 3.5. =head1 COPYRIGHT -Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/BIO_push.pod b/doc/man3/BIO_push.pod index 8170a48c0c..84ce3f042d 100644 --- a/doc/man3/BIO_push.pod +++ b/doc/man3/BIO_push.pod @@ -20,7 +20,7 @@ Otherwise it prepends I, which may be a single BIO or a chain of BIOs, to I (unless I is NULL). It then makes a control call on I and returns I. -BIO_pop() removes the BIO I from any chain it is part of. +BIO_pop() removes the BIO I from any chain is is part of. If I is NULL the function does nothing and returns NULL. Otherwise it makes a control call on I and returns the next BIO in the chain, or NULL if there is no next BIO. diff --git a/doc/man3/BIO_read.pod b/doc/man3/BIO_read.pod index 5c7dd00a34..f337aab353 100644 --- a/doc/man3/BIO_read.pod +++ b/doc/man3/BIO_read.pod @@ -52,9 +52,7 @@ For implementing this, unfortunately the data needs to be read byte-by-byte. BIO_write() attempts to write I bytes from I to BIO I. -BIO_puts() attempts to write a NUL-terminated string I to BIO I, -without the terminating NUL byte and without appending '\n' -(so, similar to fputs(3), and not puts(3)). +BIO_puts() attempts to write a NUL-terminated string I to BIO I. =head1 RETURN VALUES @@ -63,11 +61,6 @@ BIO_read_ex() returns 1 if data was successfully read, and 0 otherwise. BIO_write_ex() returns 1 if no error was encountered writing data, 0 otherwise. Requesting to write 0 bytes is not considered an error. -BIO_read() returns the number of bytes read on success. -A return value of 0 indicates that end-of-file was reached, or that a read -of zero bytes was requested. -A negative return value indicates an error condition. - BIO_write() returns -2 if the "write" operation is not implemented by the BIO or -1 on other errors. Otherwise it returns the number of bytes written. @@ -126,7 +119,7 @@ I parameter of the function can be NULL since OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/BIO_s_accept.pod b/doc/man3/BIO_s_accept.pod index ad50d2e530..1fad672dd9 100644 --- a/doc/man3/BIO_s_accept.pod +++ b/doc/man3/BIO_s_accept.pod @@ -110,8 +110,8 @@ BIO_set_bind_mode() and BIO_get_bind_mode() set and retrieve the current bind mode. If B (the default) is set then another socket cannot be bound to the same port. If B is set then other sockets can bind to the -same port. If B is set then an -attempt is first made to use B, if this fails +same port. If B is set then and +attempt is first made to use BIO_BIN_NORMAL, if this fails and the port is not in use then a second attempt is made using B. If B is set, then the socket will be configured to accept TCP Fast Open @@ -127,7 +127,7 @@ connection, or request a retry in non blocking mode. When an accept BIO is at the end of a chain it will await an incoming connection before processing I/O calls. When an accept -BIO is not at the end of a chain it passes I/O calls to the next +BIO is not at then end of a chain it passes I/O calls to the next BIO in the chain. When a connection is established a new socket BIO is created for @@ -161,10 +161,10 @@ and freeing up the accept BIO after the initial connection. If the underlying accept socket is nonblocking and BIO_do_accept() is called to await an incoming connection it is possible for -BIO_should_io_special() to return true with the reason B. -If this happens then it is an indication that an accept attempt would block: -the application should take appropriate action to wait until the underlying -socket has accepted a connection and retry the call. +BIO_should_io_special() with the reason BIO_RR_ACCEPT. If this happens +then it is an indication that an accept attempt would block: the application +should take appropriate action to wait until the underlying socket has +accepted a connection and retry the call. BIO_set_accept_name(), BIO_get_accept_name(), BIO_set_accept_port(), BIO_get_accept_port(), BIO_set_nbio_accept(), BIO_set_accept_bios(), @@ -244,7 +244,7 @@ BIO_set_tfo_accept() was added in OpenSSL 3.2. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2022 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/BIO_s_bio.pod b/doc/man3/BIO_s_bio.pod index 482edfcfc8..653fe4785a 100644 --- a/doc/man3/BIO_s_bio.pod +++ b/doc/man3/BIO_s_bio.pod @@ -5,8 +5,7 @@ BIO_s_bio, BIO_make_bio_pair, BIO_destroy_bio_pair, BIO_shutdown_wr, BIO_set_write_buf_size, BIO_get_write_buf_size, BIO_new_bio_pair, BIO_get_write_guarantee, BIO_ctrl_get_write_guarantee, BIO_get_read_request, -BIO_ctrl_get_read_request, BIO_ctrl_reset_read_request, -BIO_nread0, BIO_nread, BIO_nwrite0, BIO_nwrite - BIO pair BIO +BIO_ctrl_get_read_request, BIO_ctrl_reset_read_request - BIO pair BIO =head1 SYNOPSIS @@ -29,11 +28,6 @@ BIO_nread0, BIO_nread, BIO_nwrite0, BIO_nwrite - BIO pair BIO size_t BIO_ctrl_get_read_request(BIO *b); int BIO_ctrl_reset_read_request(BIO *b); - int BIO_nread0(BIO *bio, char **buf); - int BIO_nread(BIO *bio, char **buf, int num); - int BIO_nwrite0(BIO *bio, char **buf); - int BIO_nwrite(BIO *bio, char **buf, int num); - =head1 DESCRIPTION BIO_s_bio() returns the method for a BIO pair. A BIO pair is a pair of source/sink @@ -104,44 +98,6 @@ than that returned by BIO_get_write_guarantee(). BIO_ctrl_reset_read_request() can also be used to reset the value returned by BIO_get_read_request() to zero. -=head2 Non-copying Interface - -BIO_nread0(), BIO_nread(), BIO_nwrite0(), and BIO_nwrite() provide a non-copying -interface for reading from and writing to BIO pairs. These functions allow -direct access to the internal buffer, avoiding the overhead of copying data. - -BIO_nread0() returns in B<*buf> a pointer to the start of the available data -in the peer's write buffer and returns the number of bytes available. -This allows reading directly from the buffer without copying. -It does not consume the data; a subsequent call to BIO_nread() is needed -to advance the buffer position. - -BIO_nread() is similar to BIO_nread0() but also advances the read position -by up to B bytes. The actual number of bytes consumed is returned. -The B<*buf> pointer is set to the start of the data that was consumed. -Since the data is considered consumed after this call, the pointer returned -by BIO_nread() should not be used afterwards unless the caller also -controls the writing side. The typical pattern is to call BIO_nread0() first, -use the data, and then call BIO_nread() to consume it. - -BIO_nwrite0() returns in B<*buf> a pointer to the start of the available -space in the write buffer and returns the number of bytes that can be written. -This allows writing directly to the buffer without copying. -It does not commit the data; a subsequent call to BIO_nwrite() is needed -to update the buffer length. - -BIO_nwrite() is similar to BIO_nwrite0() but also commits up to B bytes -as written. The actual number of bytes committed is returned. -The B<*buf> pointer is set to the start of the region that was committed. -BIO_nwrite() should only be called after the data has actually been written -to the buffer obtained from BIO_nwrite0(), since committing signals data -availability to the reading side. - -Note that due to the ring buffer implementation, if wrapping around would be -required, BIO_nread0() and BIO_nwrite0() may return less than the total -available space. In such cases, a second call may be needed to access the -remaining data or space. - =head1 NOTES Both halves of a BIO pair should be freed. That is even if one half is implicit @@ -177,17 +133,6 @@ locations for B and B. Check the error stack for more information. [XXXXX: More return values need to be added here] -BIO_nread0() returns the number of bytes available for reading, 0 if the peer -has closed and no data remains (EOF), or -1 if no data is currently available -(retry may be appropriate). If the BIO is not initialized, -2 is returned. - -BIO_nwrite0() returns the number of bytes of space available for writing, or -1 -if no space is currently available (retry may be appropriate) or the BIO has -been closed. If the BIO is not initialized, -2 is returned. - -BIO_nread() and BIO_nwrite() return the number of bytes consumed or committed -respectively, or the same error values as BIO_nread0() and BIO_nwrite0(). - =head1 EXAMPLES The BIO pair can be used to have full control over the network access of an @@ -231,30 +176,6 @@ and must be transferred to the network. Use BIO_ctrl_get_read_request() to find out, how many bytes must be written into the buffer before the SSL_operation() can successfully be continued. -A typical usage pattern for the non-copying write interface is: - - int ret; - char *buf; - - ret = BIO_nwrite0(bio, &buf); - if (ret > 0) { - /* write up to 'ret' bytes directly to 'buf' */ - memcpy(buf, data, len); - BIO_nwrite(bio, &buf, len); /* commit the write */ - } - -A typical usage pattern for the non-copying read interface is: - - int ret; - char *buf; - - ret = BIO_nread0(bio, &buf); - if (ret > 0) { - /* read up to 'ret' bytes directly from 'buf' */ - process_data(buf, ret); - BIO_nread(bio, &buf, ret); /* consume the data */ - } - =head1 WARNINGS As the data is buffered, SSL_operation() may return with an ERROR_SSL_WANT_READ diff --git a/doc/man3/BIO_s_datagram.pod b/doc/man3/BIO_s_datagram.pod index b28dcf088c..634c3a9af4 100644 --- a/doc/man3/BIO_s_datagram.pod +++ b/doc/man3/BIO_s_datagram.pod @@ -65,7 +65,7 @@ the underlying socket is configured and how it is to be used; see below. =item -Use of BIO_s_datagram() with an unconnected network socket is hazardous because +Use of BIO_s_datagram() with an unconnected network socket is hazardous hecause any successful call to BIO_read() results in the peer address used for any subsequent call to BIO_write() being set to the source address of the datagram received by that call to BIO_read(). Thus, unless the caller calls diff --git a/doc/man3/BIO_s_file.pod b/doc/man3/BIO_s_file.pod index 6cd1da02a3..5dcd4bbbca 100644 --- a/doc/man3/BIO_s_file.pod +++ b/doc/man3/BIO_s_file.pod @@ -14,8 +14,8 @@ BIO_rw_filename - FILE bio BIO *BIO_new_file(const char *filename, const char *mode); BIO *BIO_new_fp(FILE *stream, int flags); - long BIO_set_fp(BIO *b, FILE *fp, int flags); - long BIO_get_fp(BIO *b, FILE **fpp); + BIO_set_fp(BIO *b, FILE *fp, int flags); + BIO_get_fp(BIO *b, FILE **fpp); int BIO_read_filename(BIO *b, char *name); int BIO_write_filename(BIO *b, char *name); @@ -87,7 +87,8 @@ BIO_s_file() returns the file BIO method. BIO_new_file() and BIO_new_fp() return a file BIO or NULL if an error occurred. -BIO_set_fp() and BIO_get_fp() return 1 for success or <=0 for failure. +BIO_set_fp() and BIO_get_fp() return 1 for success or <=0 for failure +(although the current implementation never return 0). BIO_seek() returns 0 for success or negative values for failure. diff --git a/doc/man3/BIO_s_mem.pod b/doc/man3/BIO_s_mem.pod index 192e7f4e9d..f938567298 100644 --- a/doc/man3/BIO_s_mem.pod +++ b/doc/man3/BIO_s_mem.pod @@ -77,11 +77,6 @@ it will return zero and BIO_should_retry(b) will be false. If B is non zero then it will return B when it is empty and it will set the read retry flag (that is BIO_read_retry(b) is true). To avoid ambiguity with a normal positive return value B should be set to a negative value, typically -1. -The default behaviour for read-only BIOs is as if BIO_set_mem_eof_return(0) -were called. The default behaviour for read-write BIOs is special: BIO_eof() -returns EOF for an empty buffer, while the BIO_read() behaviour remains -identical to the case BIO_set_mem_eof_return(-1). This default behaviour -is maintained for backward compatibility. Calling this macro will fail for datagram mem BIOs. BIO_get_mem_data() sets *B to a pointer to the start of the memory BIOs data @@ -208,7 +203,7 @@ BIO_s_dgram_mem() was added in OpenSSL 3.2. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/BIO_s_socket.pod b/doc/man3/BIO_s_socket.pod index 8200cb20fe..d8b1647fbe 100644 --- a/doc/man3/BIO_s_socket.pod +++ b/doc/man3/BIO_s_socket.pod @@ -2,7 +2,7 @@ =head1 NAME -BIO_s_socket, BIO_new_socket, BIO_set_send_flags - socket BIO +BIO_s_socket, BIO_new_socket - socket BIO =head1 SYNOPSIS @@ -12,8 +12,6 @@ BIO_s_socket, BIO_new_socket, BIO_set_send_flags - socket BIO BIO *BIO_new_socket(int sock, int close_flag); - long BIO_set_send_flags(BIO *b, int flags); - =head1 DESCRIPTION BIO_s_socket() returns the socket BIO method. This is a wrapper @@ -27,11 +25,6 @@ when the BIO is freed. BIO_new_socket() returns a socket BIO using B and B. -BIO_set_send_flags() sets flags passed to send(), sendto() and sendmsg(). -The set of available flags is platform-dependent. The main intention is to -allow setting the MSG_NOSIGNAL flag to avoid a crash on receiving the SIGPIPE -signal. - =head1 NOTES Socket BIOs also support any relevant functionality of file descriptor @@ -49,15 +42,9 @@ BIO_s_socket() returns the socket BIO method. BIO_new_socket() returns the newly allocated BIO or NULL is an error occurred. -BIO_set_send_flags() returns 1 on success, 0 on errors. - -=head1 HISTORY - -BIO_set_send_flags() was added in OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2016 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/BIO_set_flags.pod b/doc/man3/BIO_set_flags.pod deleted file mode 100644 index 78f15ec7aa..0000000000 --- a/doc/man3/BIO_set_flags.pod +++ /dev/null @@ -1,205 +0,0 @@ -=pod - -=head1 NAME - -BIO_set_flags, BIO_clear_flags, BIO_test_flags, BIO_get_flags, -BIO_set_retry_read, BIO_set_retry_write, BIO_set_retry_special, -BIO_clear_retry_flags, BIO_get_retry_flags -- manipulate and interpret BIO flags - -=head1 SYNOPSIS - - #include - - void BIO_set_flags(BIO *b, int flags); - void BIO_clear_flags(BIO *b, int flags); - int BIO_test_flags(const BIO *b, int flags); - int BIO_get_flags(const BIO *b); - - void BIO_set_retry_read(BIO *b); - void BIO_set_retry_write(BIO *b); - void BIO_set_retry_special(BIO *b); - void BIO_clear_retry_flags(BIO *b); - int BIO_get_retry_flags(BIO *b); - -=head1 DESCRIPTION - -A B has an internal set of bit flags that describe its state. These -functions and macros are used primarily by B implementations and by code -that builds B chains to manipulate those flags. - -BIO_set_flags() sets the bits given in I in the B I. Any bits -already set in the B's flag word remain set. - -BIO_clear_flags() clears the bits given in I from the B I. Any -other bits in the flag word are left unchanged. - -BIO_test_flags() tests the bits given in I in the B I and -returns a nonzero value if any of them are currently set and zero -otherwise. - -BIO_get_flags() returns the current flag word from the B I. This is -equivalent to testing for all bits and returning the result. - -The following convenience macros are built on top of these primitives and are -used to maintain the retry state of a BIO: - -BIO_set_retry_read() marks the B I as being in a retryable state -by setting the B flag. In addition, it sets the -B flag to indicate that the retry condition is -associated with a read operation. - -BIO_set_retry_write() marks the B I as being in a retryable state -by setting the B flag. In addition, it sets the -B flag to indicate that the retry condition is -associated with a write operation. - -BIO_set_retry_special() marks the B I as being in a retryable state -by setting the B flag. In addition, it sets the -B flag to indicate that the retry condition is -associated with a read operation some "special" condition. -The precise meaning of this condition depends on the B type. - -BIO_clear_retry_flags() clears all retry-related bits from I, i.e. -B, B, B, and -B. - -BIO_get_retry_flags() returns retry-related bits that are -currently set in I. The result is a subset of -B. - -The retry bits are interpreted by the higher level macros -BIO_should_read(), BIO_should_write(), BIO_should_io_special(), -BIO_retry_type() and BIO_should_retry(), as documented in -L. Application code will typically use those macros -rather than manipulate the underlying flags directly. - -The following flag bits are currently defined for use with BIO_set_flags(), -BIO_clear_flags() and BIO_test_flags(): - -=over 4 - -=item B - -The last I/O operation should be retried when the B becomes readable. -This flag is normally set by the B implementation via BIO_set_retry_read() -after a failed read operation. - -=item B - -The last I/O operation should be retried when the B becomes writable. -This flag is normally set by the B implementation via BIO_set_retry_write() -after a failed write operation. - -=item B - -The last I/O operation should be retried when some "special" condition -becomes true. The precise meaning of this condition depends on the B -type and is usually obtained via BIO_get_retry_BIO() and -BIO_get_retry_reason() as described in L. -This flag is normally set by the B implementation via -BIO_set_retry_special(). - -=item B - -The bitwise OR of B, B and -B. This mask is used when clearing or extracting -the retry-direction bits. - -=item B - -Set if the last I/O operation on the B should be retried at a later time. -If this bit is not set then the condition is treated as an error. -This flag is normally set by the B implementation. - -=back - -The following flag can be used only with the B. -The result of using this flag with other BIOs is unpredictable. - -=over 4 - -=item B - -When set on a base64 filter B this flag disables the generation of -newline characters in the encoded output and causes newlines to be ignored -in the input. See also L. -The flag has no effect on any other built-in B types. - -=back - -The following flags can be used only with the B and -B. The result of using these flags with other BIOs -is unpredictable. - -=over 4 - -=item B - -When set on a memory B this flag indicates that the underlying buffer is -read only. Attempts to write to such a B will fail. -The flag has no effect on any other built-in B types. - -=item B - -On a memory B this flag modifies the behaviour of BIO_reset(). When it -is set, resetting the B does not clear the underlying buffer but only -resets the current read position. -The flag has no effect on any other built-in B types. - -=item B - -This flag is for internal use only. It should not be used outside BIO -implementations. - -=back - -A range of additional flag values is reserved for internal use by OpenSSL -to track kernel TLS (KTLS) state. This range and the corresponding flag -macros are not part of the public API and must not be used by applications. - -=head1 RETURN VALUES - -BIO_get_flags() returns a bit mask of the flags currently set on the B. - -BIO_test_flags() returns a bit mask consisting of those flags from the -argument that are currently set in the B. Consequently, it returns a -nonzero value if and only if at least one of the requested flags is set. - -BIO_get_retry_flags() returns a bit mask consisting of those flags from -B, B, B, and -B that are currently set in the I. - -=head1 NOTES - -Ordinary application code will rarely need to call BIO_set_flags(), -BIO_clear_flags() or BIO_test_flags() directly. They are intended for B -implementations and for code that forwards retry state from one B in a -chain to another. -After a failed I/O operation, applications should normally use -BIO_should_retry() and related macros as described in -L instead of inspecting the flags directly. - -These functions and macros are not thread-safe. If a single B -is accessed from multiple threads, the caller must provide appropriate -external synchronisation. - -=head1 SEE ALSO - -L, L, L - -=head1 HISTORY - -The functions and macros described here have been available in OpenSSL since -at least 1.1.0 (B since 1.1.1). - -=head1 COPYRIGHT - -Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - -Licensed under the Apache License 2.0 (the "License"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file LICENSE in the source distribution or at -L. - -=cut diff --git a/doc/man3/BN_add.pod b/doc/man3/BN_add.pod index edbc48c50f..46966d9963 100644 --- a/doc/man3/BN_add.pod +++ b/doc/man3/BN_add.pod @@ -108,10 +108,8 @@ BN_gcd() computes the greatest common divisor of I and I and places the result in I. I may be the same B as I or I. -For all functions that take a I parameter, it must be a previously -allocated B used for temporary variables; see L. -Unless stated otherwise in the documentation for a specific function, -the I parameter must not be NULL. +For all functions, I is a previously allocated B used for +temporary variables; see L. Unless noted otherwise, the result B must be different from the arguments. diff --git a/doc/man3/CMS_EncryptedData_decrypt.pod b/doc/man3/CMS_EncryptedData_decrypt.pod index f7375f2c58..80bbdcc95f 100644 --- a/doc/man3/CMS_EncryptedData_decrypt.pod +++ b/doc/man3/CMS_EncryptedData_decrypt.pod @@ -46,7 +46,7 @@ are used when retrieving algorithms from providers. CMS_EncryptedData_decrypt() returns 0 if an error occurred otherwise returns 1. CMS_EnvelopedData_decrypt() returns NULL if an error occurred, -otherwise a BIO containing the decrypted content. +otherwise a BIO containing the decypted content. =head1 SEE ALSO diff --git a/doc/man3/CMS_add1_signer.pod b/doc/man3/CMS_add1_signer.pod index 58b8bcc51d..c7618f6f32 100644 --- a/doc/man3/CMS_add1_signer.pod +++ b/doc/man3/CMS_add1_signer.pod @@ -87,10 +87,6 @@ scheme will be used. This is the case for EdDSA (RFC 8419). For SLH-DSA (RFC 981 and ML-DSA (RFC 9882), the scheme-suggested hash will only be used if B is NULL. -Signing with Ed448 is currently not supported for the case of signed-data -with signedAttributes due to missing support for id-shake256-len (RFC 8419; -sec 3.1). - CMS_add1_signer() returns an internal pointer to the CMS_SignerInfo structure just added, this can be used to set additional attributes before it is finalized. diff --git a/doc/man3/CMS_decrypt.pod b/doc/man3/CMS_decrypt.pod index 66a94287b6..121b74a30a 100644 --- a/doc/man3/CMS_decrypt.pod +++ b/doc/man3/CMS_decrypt.pod @@ -68,7 +68,7 @@ then the above behaviour is modified and an error B returned if no recipient encrypted key can be decrypted B generating a random content encryption key. Applications should use this flag with B especially in automated gateways as it can leave them -open to attack. See L for more details. +open to attack. It is possible to determine the correct recipient key by other means (for example looking them up in a database) and setting them in the CMS structure @@ -103,7 +103,7 @@ mentioned in CMS_verify() also applies to CMS_decrypt(). =head1 SEE ALSO -L, L, L +L, L =head1 HISTORY diff --git a/doc/man3/CMS_encrypt.pod b/doc/man3/CMS_encrypt.pod index 96fceea242..bccf7fe432 100644 --- a/doc/man3/CMS_encrypt.pod +++ b/doc/man3/CMS_encrypt.pod @@ -8,10 +8,10 @@ CMS_encrypt_ex, CMS_encrypt - create a CMS envelopedData structure #include - CMS_ContentInfo *CMS_encrypt_ex(const STACK_OF(X509) *certs, BIO *in, + CMS_ContentInfo *CMS_encrypt_ex(STACK_OF(X509) *certs, BIO *in, const EVP_CIPHER *cipher, unsigned int flags, OSSL_LIB_CTX *libctx, const char *propq); - CMS_ContentInfo *CMS_encrypt(const STACK_OF(X509) *certs, BIO *in, + CMS_ContentInfo *CMS_encrypt(STACK_OF(X509) *certs, BIO *in, const EVP_CIPHER *cipher, unsigned int flags); =head1 DESCRIPTION @@ -106,7 +106,7 @@ The B flag was first supported in OpenSSL 1.0.0. =head1 COPYRIGHT -Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2008-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/CMS_sign_receipt.pod b/doc/man3/CMS_sign_receipt.pod index 0edd60e24a..2d3542a991 100644 --- a/doc/man3/CMS_sign_receipt.pod +++ b/doc/man3/CMS_sign_receipt.pod @@ -9,7 +9,7 @@ CMS_sign_receipt - create a CMS signed receipt #include CMS_ContentInfo *CMS_sign_receipt(CMS_SignerInfo *si, X509 *signcert, - EVP_PKEY *pkey, const STACK_OF(X509) *certs, + EVP_PKEY *pkey, STACK_OF(X509) *certs, unsigned int flags); =head1 DESCRIPTION @@ -42,7 +42,7 @@ L =head1 COPYRIGHT -Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/CMS_verify.pod b/doc/man3/CMS_verify.pod index 9ec172468d..bef4858c91 100644 --- a/doc/man3/CMS_verify.pod +++ b/doc/man3/CMS_verify.pod @@ -10,13 +10,11 @@ CMS_SignerInfo_verify_content, CMS_SignerInfo_verify_ex #include - int CMS_verify(CMS_ContentInfo *cms, const STACK_OF(X509) *certs, - X509_STORE *store, + int CMS_verify(CMS_ContentInfo *cms, STACK_OF(X509) *certs, X509_STORE *store, BIO *detached_data, BIO *out, unsigned int flags); BIO *CMS_SignedData_verify(CMS_SignedData *sd, BIO *detached_data, - const STACK_OF(X509) *scerts, X509_STORE *store, - const STACK_OF(X509) *extra, - const STACK_OF(X509_CRL) *crls, + STACK_OF(X509) *scerts, X509_STORE *store, + STACK_OF(X509) *extra, STACK_OF(X509_CRL) *crls, unsigned int flags, OSSL_LIB_CTX *libctx, const char *propq); @@ -88,11 +86,8 @@ the I parameter (if it is not NULL) and then looking in any certificates contained in the I structure unless B is set. If any signing certificate cannot be located the operation fails. -Each signing certificate is chain verified +Each signing certificate is chain verified using the I purpose and using the trusted certificate store I if supplied. -The purpose required in this verification is I -unless a different one (or B) -has been set in I using L. Any internal certificates in the message, which may have been added using L, are used as untrusted CAs. If CRL checking is enabled in I and B is not set, @@ -179,7 +174,6 @@ be held in memory if it is not detached. =head1 SEE ALSO L, L, L, -L, L, L, L @@ -189,7 +183,7 @@ CMS_SignedData_verify() was added in OpenSSL 3.2. =head1 COPYRIGHT -Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2008-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/CMS_verify_receipt.pod b/doc/man3/CMS_verify_receipt.pod index 3d85aff6ba..bf3019ae72 100644 --- a/doc/man3/CMS_verify_receipt.pod +++ b/doc/man3/CMS_verify_receipt.pod @@ -9,7 +9,7 @@ CMS_verify_receipt - verify a CMS signed receipt #include int CMS_verify_receipt(CMS_ContentInfo *rcms, CMS_ContentInfo *ocms, - const STACK_OF(X509) *certs, X509_STORE *store, + STACK_OF(X509) *certs, X509_STORE *store, unsigned int flags); =head1 DESCRIPTION @@ -44,7 +44,7 @@ L, =head1 COPYRIGHT -Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/CONF_modules_load_file.pod b/doc/man3/CONF_modules_load_file.pod index 4c7029e780..86de167801 100644 --- a/doc/man3/CONF_modules_load_file.pod +++ b/doc/man3/CONF_modules_load_file.pod @@ -162,6 +162,12 @@ context. Therefore, even if used with a freshly created library context, the function is not thread safe, and should not be used except as part of early application initialisation. +Applications that want to use multiple library contexts may find that the most +recently loaded configuration file perturbs prior settings in other library +contexts. +For example, B module settings are not library context specific, and the +last configuration file loaded that has an C setting changes the +SSL settings for all library contexts. The L and L functions can be used to perform late customisation of SSL contexts and connection handles. Here I means that the chosen section's settings are applied in addition diff --git a/doc/man3/CRYPTO_THREAD_run_once.pod b/doc/man3/CRYPTO_THREAD_run_once.pod index c2ce869af9..e977b91e86 100644 --- a/doc/man3/CRYPTO_THREAD_run_once.pod +++ b/doc/man3/CRYPTO_THREAD_run_once.pod @@ -7,8 +7,6 @@ CRYPTO_THREAD_lock_new, CRYPTO_THREAD_read_lock, CRYPTO_THREAD_write_lock, CRYPTO_THREAD_unlock, CRYPTO_THREAD_lock_free, CRYPTO_atomic_add, CRYPTO_atomic_add64, CRYPTO_atomic_and, CRYPTO_atomic_or, CRYPTO_atomic_load, CRYPTO_atomic_store, CRYPTO_atomic_load_int, -CRYPTO_atomic_store_int, CRYPTO_atomic_load_ptr, CRYPTO_atomic_store_ptr, -CRYPTO_atomic_cmp_exch_ptr, OSSL_set_max_threads, OSSL_get_max_threads, OSSL_get_thread_support_flags, OSSL_THREAD_SUPPORT_FLAG_THREAD_POOL, OSSL_THREAD_SUPPORT_FLAG_DEFAULT_SPAWN - OpenSSL thread support @@ -36,11 +34,6 @@ OSSL_THREAD_SUPPORT_FLAG_DEFAULT_SPAWN - OpenSSL thread support int CRYPTO_atomic_load(uint64_t *val, uint64_t *ret, CRYPTO_RWLOCK *lock); int CRYPTO_atomic_store(uint64_t *dst, uint64_t val, CRYPTO_RWLOCK *lock); int CRYPTO_atomic_load_int(int *val, int *ret, CRYPTO_RWLOCK *lock); - int CRYPTO_atomic_store_int(int *dst, int val, CRYPTO_RWLOCK *lock); - int CRYPTO_atomic_load_ptr(void **ptr, void **ret, CRYPTO_RWLOCK *lock); - int CRYPTO_atomic_store_ptr(void **dst, void **val, CRYPTO_RWLOCK *lock); - int CRYPTO_atomic_cmp_exch_ptr(void **ptr, void **expect, void *desire, CRYPTO_RWLOCK *lock, - int *lock_failed); int OSSL_set_max_threads(OSSL_LIB_CTX *ctx, uint64_t max_threads); uint64_t OSSL_get_max_threads(OSSL_LIB_CTX *ctx); @@ -155,44 +148,6 @@ on an I value instead of a I value. =item * -CRYPTO_atomic_store_int() works identically to CRYPTO_atomic_store() but -operates on an I value instead of a I value. - -=item * - -int CRYPTO_atomic_load_ptr(void **ptr, void **ret, CRYPTO_RWLOCK *lock); - -CRYPTO_atomic_load_ptr() atomically loads the void * contents of I<*ptr> to the contents of I<*ret>. -I will be used to emulate atomic operations on platforms that do not support -atomic operations. - -=item * - -int CRYPTO_atomic_store_ptr(void **dst, void **val, CRYPTO_RWLOCK *lock); - -CRYPTO_atomic_store_ptr() atomically stores the contents of I<*val> to the location pointed -to by I<*p>. -I will be used to emulate atomic operations on platforms that do not support -atomic operations. - -=item * - -int CRYPTO_atomic_cmp_exch_ptr(void **ptr, void **expect, void *desire, CRYPTO_RWLOCK *lock, - int *lock_failed); - -CRYPTO_atomic_cmp_exch_ptr() atomically performs a read-modify-write operation. If the contents of -I<*ptr> matches the contents of I<*expect> then the value of I is stored in I<*ptr> and the -function returns 1. If I<*ptr> does not match the contents of I<*expect>, then the contents of -I<*ptr> are atomically loaded to the contents of I<*expect> and the function returns 0. -I will be used to emulate atomic operations on platforms that do not support -atomic operations. Note that this function contains an additional parameter I which -this function will set to 0 (to indicate the lock functioned properly), or 1 (to indicate the lock -encountered a failure). This parameter allows callers to determine if a failure was caused by a -locking error (which is generally a permanent/fatal error), or because the compare and exchange -operation itself failed (which is a transient error indicating the need to retry the operation. - -=item * - OSSL_set_max_threads() sets the maximum number of threads to be used by the thread pool. If the argument is 0, thread pooling is disabled. OpenSSL will not create any threads and existing threads in the thread pool will be torn @@ -318,14 +273,9 @@ OSSL_get_thread_support_flags() were added in OpenSSL 3.2. CRYPTO_atomic_store(), CRYPTO_atomic_add64(), CRYPTO_atomic_and() were added in OpenSSL 3.4. -CRYPTO_atomic_store_int() was added in OpenSSL 4.0. - -CRYPTO_atomic_load_ptr(), CRYPTO_atomic_store_ptr(), CRYPTO_atomic_cmp_exch_ptr() -were added in OpenSSL 4.1 - =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/CTLOG_STORE_new.pod b/doc/man3/CTLOG_STORE_new.pod index f342637012..361eda57b1 100644 --- a/doc/man3/CTLOG_STORE_new.pod +++ b/doc/man3/CTLOG_STORE_new.pod @@ -4,7 +4,6 @@ CTLOG_STORE_new_ex, CTLOG_STORE_new, CTLOG_STORE_free, -CTLOG_STORE_add0_log, CTLOG_STORE_load_default_file, CTLOG_STORE_load_file - Create and populate a Certificate Transparency log list @@ -16,17 +15,14 @@ Create and populate a Certificate Transparency log list CTLOG_STORE *CTLOG_STORE_new(void); void CTLOG_STORE_free(CTLOG_STORE *store); - int CTLOG_STORE_add0_log(CTLOG_STORE *store, CTLOG *log); - int CTLOG_STORE_load_default_file(CTLOG_STORE *store); int CTLOG_STORE_load_file(CTLOG_STORE *store, const char *file); =head1 DESCRIPTION A CTLOG_STORE is a container for a list of CTLOGs (Certificate Transparency -logs). The list can be loaded from one or more files, or populated -programmatically, and then searched by LogID (see RFC 6962, Section 3.2, for -the definition of a LogID). +logs). The list can be loaded from one or more files and then searched by LogID +(see RFC 6962, Section 3.2, for the definition of a LogID). CTLOG_STORE_new_ex() creates an empty list of CT logs associated with the library context I and the property query string I. @@ -34,10 +30,8 @@ the library context I and the property query string I. CTLOG_STORE_new() does the same thing as CTLOG_STORE_new_ex() but with the default library context and property query string. -The CTLOG_STORE is then populated by CTLOG_STORE_load_default_file(), -CTLOG_STORE_load_file(), or CTLOG_STORE_add0_log(). - -CTLOG_STORE_load_default_file() loads from the default +The CTLOG_STORE is then populated by CTLOG_STORE_load_default_file() or +CTLOG_STORE_load_file(). CTLOG_STORE_load_default_file() loads from the default file, which is named F in OPENSSLDIR (see the output of L). This can be overridden using an environment variable named B. CTLOG_STORE_load_file() loads from a caller-specified file @@ -56,11 +50,6 @@ The expected format of the file is: description = Log 2 key = -CTLOG_STORE_add0_log() adds a single CTLOG (see L) to the store. -On success, the store takes ownership of I and the caller must not free -it. On failure, the caller retains ownership and is responsible for freeing -I. - Once a CTLOG_STORE is no longer required, it should be passed to CTLOG_STORE_free(). This will delete all of the CTLOGs stored within, along with the CTLOG_STORE itself. If the argument is NULL, nothing is done. @@ -73,8 +62,6 @@ invalid if it is missing a "key" or "description" field. =head1 RETURN VALUES -B returns 1 on success, 0 on failure. - Both B and B return 1 if all CT logs in the file are successfully parsed and loaded, 0 otherwise. @@ -86,8 +73,8 @@ L =head1 HISTORY -CTLOG_STORE_add0_log was added in OpenSSL 4.1. CTLOG_STORE_new_ex was added in -OpenSSL 3.0. All other functions were added in OpenSSL 1.1.0. +CTLOG_STORE_new_ex was added in OpenSSL 3.0. All other functions were +added in OpenSSL 1.1.0. =head1 COPYRIGHT diff --git a/doc/man3/DEFINE_STACK_OF.pod b/doc/man3/DEFINE_STACK_OF.pod index 5f4fcaa487..7d65af2af0 100644 --- a/doc/man3/DEFINE_STACK_OF.pod +++ b/doc/man3/DEFINE_STACK_OF.pod @@ -16,8 +16,7 @@ OPENSSL_sk_dup, OPENSSL_sk_find, OPENSSL_sk_find_ex, OPENSSL_sk_find_all, OPENSSL_sk_free, OPENSSL_sk_insert, OPENSSL_sk_is_sorted, OPENSSL_sk_new, OPENSSL_sk_new_null, OPENSSL_sk_new_reserve, OPENSSL_sk_num, OPENSSL_sk_pop, OPENSSL_sk_pop_free, OPENSSL_sk_push, OPENSSL_sk_reserve, OPENSSL_sk_set, -OPENSSL_sk_set_thunks, OPENSSL_sk_set_cmp_thunks, OPENSSL_sk_set_copy_thunks, -OPENSSL_sk_set_cmp_func, OPENSSL_sk_shift, +OPENSSL_sk_set_thunks, OPENSSL_sk_set_cmp_func, OPENSSL_sk_shift, OPENSSL_sk_sort, OPENSSL_sk_unshift, OPENSSL_sk_value, OPENSSL_sk_zero - stack container @@ -241,13 +240,11 @@ OPENSSL_sk_free(), OPENSSL_sk_insert(), OPENSSL_sk_is_sorted(), OPENSSL_sk_new(), OPENSSL_sk_new_null(), OPENSSL_sk_new_reserve(), OPENSSL_sk_num(), OPENSSL_sk_pop(), OPENSSL_sk_pop_free(), OPENSSL_sk_push(), OPENSSL_sk_reserve(), OPENSSL_sk_set(), OPENSSL_sk_set_cmp_func(), -OPENSSL_sk_set_thunks(), OPENSSL_sk_set_cmp_thunks(), -OPENSSL_sk_set_copy_thunks(), OPENSSL_sk_shift(), OPENSSL_sk_sort(), +OPENSSL_sk_set_thunks(), OPENSSL_sk_shift(), OPENSSL_sk_sort(), OPENSSL_sk_unshift(), OPENSSL_sk_value(), OPENSSL_sk_zero(). -OPENSSL_sk_set_thunks(), OPENSSL_sk_set_cmp_thunks(), and -OPENSSL_sk_set_copy_thunks(), while public by necessity, are actually internal -and should not be used. +OPENSSL_sk_set_thunks(), while public by necessity, is actually an internal +function and should not be used. =head1 RETURN VALUES @@ -306,13 +303,9 @@ was changed to return 0 in this condition as for other errors. OPENSSL_sk_set_thunks() was added in OpenSSL 3.6.0. -OPENSSL_sk_set_cmp_thunks() was added in OpenSSL 4.0.0. - -OPENSSL_sk_set_copy_thunks() was added in OpenSSL 4.1.0. - =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/DH_generate_parameters.pod b/doc/man3/DH_generate_parameters.pod index c535d0b64d..e677885597 100644 --- a/doc/man3/DH_generate_parameters.pod +++ b/doc/man3/DH_generate_parameters.pod @@ -3,7 +3,7 @@ =head1 NAME DH_generate_parameters_ex, DH_generate_parameters, -DH_check, DH_check_params, DH_check_pub_key, +DH_check, DH_check_params, DH_check_ex, DH_check_params_ex, DH_check_pub_key_ex - generate and check Diffie-Hellman parameters @@ -20,7 +20,6 @@ see L: int DH_check(DH *dh, int *codes); int DH_check_params(DH *dh, int *codes); - int DH_check_pub_key(const DH *dh, const BIGNUM *pub_key, int *codes); int DH_check_ex(const DH *dh); int DH_check_params_ex(const DH *dh); @@ -133,10 +132,10 @@ If 0 is returned or B<*codes> is set to a nonzero value the supplied parameters should not be used for Diffie-Hellman operations otherwise the security properties of the key exchange are not guaranteed. -DH_check_ex(), DH_check_params_ex() and DH_check_pub_key_ex() are similar to -DH_check(), DH_check_params() and DH_check_pub_key() respectively, but the -error reasons are added to the thread's error queue instead of provided as -return values from the function. +DH_check_ex(), DH_check_params() and DH_check_pub_key_ex() are similar to +DH_check() and DH_check_params() respectively, but the error reasons are added +to the thread's error queue instead of provided as return values from the +function. =head1 RETURN VALUES @@ -165,7 +164,7 @@ DH_generate_parameters_ex() instead. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2020 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/DTLS_get_data_mtu.pod b/doc/man3/DTLS_get_data_mtu.pod index f68fe85d5c..ee74fa1704 100644 --- a/doc/man3/DTLS_get_data_mtu.pod +++ b/doc/man3/DTLS_get_data_mtu.pod @@ -2,60 +2,31 @@ =head1 NAME -DTLS_get_data_mtu, DTLS_set_link_mtu, DTLS_get_link_min_mtu, SSL_set_mtu -- DTLS MTU handling +DTLS_get_data_mtu - Get maximum data payload size =head1 SYNOPSIS #include size_t DTLS_get_data_mtu(const SSL *ssl); - long DTLS_set_link_mtu(SSL *ssl, long mtu); - long DTLS_get_link_min_mtu(SSL *ssl); - long SSL_set_mtu(SSL *ssl, long mtu); =head1 DESCRIPTION -DTLS_get_data_mtu() obtains the maximum data payload size for the established -DTLS connection I, based on the DTLS record MTU and the overhead +This function obtains the maximum data payload size for the established +DTLS connection B, based on the DTLS record MTU and the overhead of the DTLS record header, encryption and authentication currently in use. -DTLS_set_link_mtu() sets the link layer MTU for the DTLS connection I -to I. This is the maximum on-the-wire packet size including IP and UDP -headers. OpenSSL subtracts the IP/UDP overhead internally to determine the -maximum DTLS record size, and uses this to fragment handshake messages and -limit the size of application data records. - -DTLS_get_link_min_mtu() returns the minimum link MTU that OpenSSL will use -for the DTLS connection I. This is the smallest MTU that still allows -DTLS to function properly. - -SSL_set_mtu() sets the DTLS record-level MTU for the connection I to -I. Unlike DTLS_set_link_mtu(), this value should not include IP or UDP -header overhead; it represents the maximum DTLS packet size directly. - =head1 RETURN VALUES -DTLS_get_data_mtu() returns the maximum data payload size on success, or 0 -on failure. - -DTLS_set_link_mtu() returns 1 on success or 0 on failure. - -SSL_set_mtu() returns the MTU value on success or 0 on failure. - -DTLS_get_link_min_mtu() returns the minimum link MTU value. +Returns the maximum data payload size on success, or 0 on failure. =head1 HISTORY -DTLS_get_data_mtu() was added in OpenSSL 1.1.1. - -SSL_set_mtu() was added in OpenSSL 0.9.8. - -DTLS_set_link_mtu() and DTLS_get_link_min_mtu() were added in OpenSSL 1.0.2. +The DTLS_get_data_mtu() function was added in OpenSSL 1.1.1. =head1 COPYRIGHT -Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2016 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/EC_GROUP_copy.pod b/doc/man3/EC_GROUP_copy.pod index c63b6da9b6..e525fad0bf 100644 --- a/doc/man3/EC_GROUP_copy.pod +++ b/doc/man3/EC_GROUP_copy.pod @@ -2,17 +2,18 @@ =head1 NAME -EC_GROUP_get0_order, EC_GROUP_order_bits, EC_GROUP_security_bits, -EC_GROUP_get0_cofactor, EC_GROUP_copy, EC_GROUP_dup, EC_GROUP_method_of, -EC_GROUP_set_generator, EC_GROUP_get0_generator, EC_GROUP_get_order, -EC_GROUP_get_cofactor, EC_GROUP_set_curve_name, EC_GROUP_get_curve_name, -EC_GROUP_set_asn1_flag, EC_GROUP_get_asn1_flag, -EC_GROUP_set_point_conversion_form, EC_GROUP_get_point_conversion_form, -EC_GROUP_get0_seed, EC_GROUP_get_seed_len, EC_GROUP_set_seed, -EC_GROUP_get_degree, EC_GROUP_check, EC_GROUP_check_named_curve, -EC_GROUP_check_discriminant, EC_GROUP_cmp, EC_GROUP_get_basis_type, -EC_GROUP_get_trinomial_basis, EC_GROUP_get_pentanomial_basis, -EC_GROUP_get0_field, EC_GROUP_get_field_type +EC_GROUP_get0_order, EC_GROUP_order_bits, EC_GROUP_get0_cofactor, +EC_GROUP_copy, EC_GROUP_dup, EC_GROUP_method_of, EC_GROUP_set_generator, +EC_GROUP_get0_generator, EC_GROUP_get_order, EC_GROUP_get_cofactor, +EC_GROUP_set_curve_name, EC_GROUP_get_curve_name, EC_GROUP_set_asn1_flag, +EC_GROUP_get_asn1_flag, EC_GROUP_set_point_conversion_form, +EC_GROUP_get_point_conversion_form, EC_GROUP_get0_seed, +EC_GROUP_get_seed_len, EC_GROUP_set_seed, EC_GROUP_get_degree, +EC_GROUP_check, EC_GROUP_check_named_curve, +EC_GROUP_check_discriminant, EC_GROUP_cmp, +EC_GROUP_get_basis_type, EC_GROUP_get_trinomial_basis, +EC_GROUP_get_pentanomial_basis, EC_GROUP_get0_field, +EC_GROUP_get_field_type - Functions for manipulating EC_GROUP objects =head1 SYNOPSIS @@ -29,7 +30,6 @@ EC_GROUP_get0_field, EC_GROUP_get_field_type int EC_GROUP_get_order(const EC_GROUP *group, BIGNUM *order, BN_CTX *ctx); const BIGNUM *EC_GROUP_get0_order(const EC_GROUP *group); int EC_GROUP_order_bits(const EC_GROUP *group); - int EC_GROUP_security_bits(const EC_GROUP *group); int EC_GROUP_get_cofactor(const EC_GROUP *group, BIGNUM *cofactor, BN_CTX *ctx); const BIGNUM *EC_GROUP_get0_cofactor(const EC_GROUP *group); const BIGNUM *EC_GROUP_get0_field(const EC_GROUP *group); @@ -223,8 +223,6 @@ EC_GROUP_check_named_curve() returns the nid of the matching named curve, otherw EC_GROUP_get0_order() returns an internal pointer to the group order. EC_GROUP_order_bits() returns the number of bits in the group order. -EC_GROUP_security_bits() returns the symmetric-equivalent security bit count of the group, -rounding down to the standard sizes (80, 112, 128, 192, 256) when the value is at least 80. EC_GROUP_get0_cofactor() returns an internal pointer to the group cofactor. EC_GROUP_get0_field() returns an internal pointer to the group field. For curves over GF(p), this is the modulus; for curves over GF(2^m), this is the irreducible polynomial defining the field. @@ -252,11 +250,9 @@ EC_GROUP_method_of() was deprecated in OpenSSL 3.0. EC_GROUP_get0_field(), EC_GROUP_check_named_curve() and EC_GROUP_get_field_type() were added in OpenSSL 3.0. EC_GROUP_get0_order(), EC_GROUP_order_bits() and EC_GROUP_get0_cofactor() were added in OpenSSL 1.1.0. -EC_GROUP_security_bits() was added in OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2013-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2013-2023 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/EC_GROUP_new.pod b/doc/man3/EC_GROUP_new.pod index 10a9659da4..6c6b61af8a 100644 --- a/doc/man3/EC_GROUP_new.pod +++ b/doc/man3/EC_GROUP_new.pod @@ -22,9 +22,7 @@ EC_GROUP_get_curve_GFp, EC_GROUP_set_curve_GF2m, EC_GROUP_get_curve_GF2m, EC_get_builtin_curves, -OSSL_EC_curve_nid2name, -EC_curve_nid2nist, -EC_curve_nist2nid - +OSSL_EC_curve_nid2name - Functions for creating and destroying EC_GROUP objects =head1 SYNOPSIS @@ -59,8 +57,6 @@ Functions for creating and destroying EC_GROUP objects size_t EC_get_builtin_curves(EC_builtin_curve *r, size_t nitems); const char *OSSL_EC_curve_nid2name(int nid); - const char *EC_curve_nid2nist(int nid); - int EC_curve_nist2nid(const char *name); The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining B with a suitable version value, @@ -194,20 +190,6 @@ If I is NULL nothing is done. OSSL_EC_curve_nid2name() converts a curve I into the corresponding name. -EC_curve_nid2nist() converts a curve I into the corresponding NIST name. -NIST names are standardized curve names defined by NIST, such as "P-192", "P-224", -"P-256", "P-384", and "P-521" for prime field curves, and "B-163", "B-233", -"B-283", "B-409", "B-571", "K-163", "K-233", "K-283", "K-409", and "K-571" for -binary field curves. -If the curve specified by I does not have a NIST name, this function returns -NULL. - -EC_curve_nist2nid() converts a NIST curve name I to the corresponding NID. -The I argument should be a string containing a NIST curve name such as -"P-256" or "B-163". -If the name does not correspond to a known NIST curve, this function returns -NID_undef. - =head1 RETURN VALUES All EC_GROUP_new* functions return a pointer to the newly constructed group, or @@ -221,12 +203,6 @@ EC_GROUP_get_curve_GF2m() return 1 on success or 0 on error. OSSL_EC_curve_nid2name() returns a character string constant, or NULL on error. -EC_curve_nid2nist() returns a pointer to a constant string containing the NIST -name for the specified curve, or NULL if the curve does not have a NIST name. - -EC_curve_nist2nid() returns the NID of the curve with the given NIST name, or -NID_undef if the name does not correspond to a known NIST curve. - =head1 SEE ALSO L, L, @@ -262,7 +238,7 @@ instead. =head1 COPYRIGHT -Copyright 2013-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2013-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/EC_KEY_new.pod b/doc/man3/EC_KEY_new.pod index 9495174366..2bdfd6d96a 100644 --- a/doc/man3/EC_KEY_new.pod +++ b/doc/man3/EC_KEY_new.pod @@ -2,6 +2,7 @@ =head1 NAME +EVP_EC_gen, EC_KEY_get_method, EC_KEY_set_method, EC_KEY_new_ex, EC_KEY_new, EC_KEY_get_flags, EC_KEY_set_flags, EC_KEY_clear_flags, EC_KEY_new_by_curve_name_ex, EC_KEY_new_by_curve_name, EC_KEY_free, @@ -20,6 +21,8 @@ EC_KEY objects #include + EVP_PKEY *EVP_EC_gen(const char *curve); + The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining B with a suitable version value, see L: @@ -64,6 +67,8 @@ see L: =head1 DESCRIPTION +EVP_EC_gen() generates a new EC key pair on the given I. + All of the functions described below are deprecated. Applications should instead use EVP_EC_gen(), L, or L and L. @@ -218,14 +223,15 @@ L =head1 HISTORY -All the functions described here were deprecated in OpenSSL 3.0. +EVP_EC_gen() was added in OpenSSL 3.0. +All other functions described here were deprecated in OpenSSL 3.0. For replacement see L. The EC_KEY_get0_engine() was removed in OpenSSL 4.0. =head1 COPYRIGHT -Copyright 2013-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2013-2023 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/ERR_remove_state.pod b/doc/man3/ERR_remove_state.pod new file mode 100644 index 0000000000..2ef34c7c34 --- /dev/null +++ b/doc/man3/ERR_remove_state.pod @@ -0,0 +1,51 @@ +=pod + +=head1 NAME + +ERR_remove_thread_state, ERR_remove_state - DEPRECATED + +=head1 SYNOPSIS + +The following function has been deprecated since OpenSSL 1.0.0, and can be +hidden entirely by defining B with a suitable version value, +see L: + + void ERR_remove_state(unsigned long tid); + +The following function has been deprecated since OpenSSL 1.1.0, and can be +hidden entirely by defining B with a suitable version value, +see L: + + void ERR_remove_thread_state(void *tid); + +=head1 DESCRIPTION + +ERR_remove_state() frees the error queue associated with the specified +thread, identified by B. +ERR_remove_thread_state() does the same thing, except the identifier is +an opaque pointer. + +=head1 RETURN VALUES + +ERR_remove_state() and ERR_remove_thread_state() return no value. + +=head1 SEE ALSO + +LL + +=head1 HISTORY + +ERR_remove_state() was deprecated in OpenSSL 1.0.0 and +ERR_remove_thread_state() was deprecated in OpenSSL 1.1.0; these functions +and should not be used. + +=head1 COPYRIGHT + +Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved. + +Licensed under the Apache License 2.0 (the "License"). You may not use +this file except in compliance with the License. You can obtain a copy +in the file LICENSE in the source distribution or at +L. + +=cut diff --git a/doc/man3/EVP_CIPHER_CTX_get_app_data.pod b/doc/man3/EVP_CIPHER_CTX_get_app_data.pod deleted file mode 100644 index 3865bb4390..0000000000 --- a/doc/man3/EVP_CIPHER_CTX_get_app_data.pod +++ /dev/null @@ -1,38 +0,0 @@ -=pod - -=head1 NAME - -EVP_CIPHER_CTX_get_app_data, EVP_CIPHER_CTX_set_app_data - Routines to -inspect and modify application data related to EVP_CIPHER_CTX - -=head1 SYNOPSIS - - #include - - void *EVP_CIPHER_CTX_get_app_data(const EVP_CIPHER_CTX *ctx); - void EVP_CIPHER_CTX_set_app_data(EVP_CIPHER_CTX *ctx, void *data); - -=head1 DESCRIPTION - -The functions EVP_CIPHER_CTX_set_app_data() and EVP_CIPHER_CTX_get_app_data() -associate an opaque, application-defined pointer with an EVP_CIPHER_CTX object. - -This pointer is not interpreted by the library and is reserved entirely for use -by the application. It may be used to store arbitrary context or state that -needs to be accessible wherever the corresponding EVP_CIPHER_CTX is available. - -=head1 RETURN VALUES - -The EVP_CIPHER_CTX_get_app_data() function returns a opaque pointer to the -current application data for the EVP_CIPHER_CTX. - -=head1 COPYRIGHT - -Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - -Licensed under the Apache License 2.0 (the "License"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file LICENSE in the source distribution or at -L. - -=cut diff --git a/doc/man3/EVP_CIPHER_meth_new.pod b/doc/man3/EVP_CIPHER_meth_new.pod new file mode 100644 index 0000000000..8638cd3009 --- /dev/null +++ b/doc/man3/EVP_CIPHER_meth_new.pod @@ -0,0 +1,260 @@ +=pod + +=head1 NAME + +EVP_CIPHER_meth_new, EVP_CIPHER_meth_dup, EVP_CIPHER_meth_free, +EVP_CIPHER_meth_set_iv_length, EVP_CIPHER_meth_set_flags, +EVP_CIPHER_meth_set_impl_ctx_size, EVP_CIPHER_meth_set_init, +EVP_CIPHER_meth_set_do_cipher, EVP_CIPHER_meth_set_cleanup, +EVP_CIPHER_meth_set_set_asn1_params, EVP_CIPHER_meth_set_get_asn1_params, +EVP_CIPHER_meth_set_ctrl, EVP_CIPHER_meth_get_init, +EVP_CIPHER_meth_get_do_cipher, EVP_CIPHER_meth_get_cleanup, +EVP_CIPHER_meth_get_set_asn1_params, EVP_CIPHER_meth_get_get_asn1_params, +EVP_CIPHER_meth_get_ctrl +- Routines to build up EVP_CIPHER methods + +=head1 SYNOPSIS + + #include + +The following functions have been deprecated since OpenSSL 3.0, and can be +hidden entirely by defining B with a suitable version value, +see L: + + EVP_CIPHER *EVP_CIPHER_meth_new(int cipher_type, int block_size, int key_len); + EVP_CIPHER *EVP_CIPHER_meth_dup(const EVP_CIPHER *cipher); + void EVP_CIPHER_meth_free(EVP_CIPHER *cipher); + + int EVP_CIPHER_meth_set_iv_length(EVP_CIPHER *cipher, int iv_len); + int EVP_CIPHER_meth_set_flags(EVP_CIPHER *cipher, unsigned long flags); + int EVP_CIPHER_meth_set_impl_ctx_size(EVP_CIPHER *cipher, int ctx_size); + int EVP_CIPHER_meth_set_init(EVP_CIPHER *cipher, + int (*init)(EVP_CIPHER_CTX *ctx, + const unsigned char *key, + const unsigned char *iv, + int enc)); + int EVP_CIPHER_meth_set_do_cipher(EVP_CIPHER *cipher, + int (*do_cipher)(EVP_CIPHER_CTX *ctx, + unsigned char *out, + const unsigned char *in, + size_t inl)); + int EVP_CIPHER_meth_set_cleanup(EVP_CIPHER *cipher, + int (*cleanup)(EVP_CIPHER_CTX *)); + int EVP_CIPHER_meth_set_set_asn1_params(EVP_CIPHER *cipher, + int (*set_asn1_parameters)(EVP_CIPHER_CTX *, + ASN1_TYPE *)); + int EVP_CIPHER_meth_set_get_asn1_params(EVP_CIPHER *cipher, + int (*get_asn1_parameters)(EVP_CIPHER_CTX *, + ASN1_TYPE *)); + int EVP_CIPHER_meth_set_ctrl(EVP_CIPHER *cipher, + int (*ctrl)(EVP_CIPHER_CTX *, int type, + int arg, void *ptr)); + + int (*EVP_CIPHER_meth_get_init(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *ctx, + const unsigned char *key, + const unsigned char *iv, + int enc); + int (*EVP_CIPHER_meth_get_do_cipher(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *ctx, + unsigned char *out, + const unsigned char *in, + size_t inl); + int (*EVP_CIPHER_meth_get_cleanup(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *); + int (*EVP_CIPHER_meth_get_set_asn1_params(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *, + ASN1_TYPE *); + int (*EVP_CIPHER_meth_get_get_asn1_params(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *, + ASN1_TYPE *); + int (*EVP_CIPHER_meth_get_ctrl(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *, + int type, int arg, + void *ptr); + +=head1 DESCRIPTION + +All of the functions described on this page are deprecated. +Applications should instead use the OSSL_PROVIDER APIs. + +The B type is a structure for symmetric cipher method +implementation. + +EVP_CIPHER_meth_new() creates a new B structure. + +EVP_CIPHER_meth_dup() creates a copy of B. + +EVP_CIPHER_meth_free() destroys a B structure. +If the argument is NULL, nothing is done. + +EVP_CIPHER_meth_set_iv_length() sets the length of the IV. +This is only needed when the implemented cipher mode requires it. + +EVP_CIPHER_meth_set_flags() sets the flags to describe optional +behaviours in the particular B. +With the exception of cipher modes, of which only one may be present, +several flags can be or'd together. +The available flags are: + +=over 4 + +=item EVP_CIPH_STREAM_CIPHER, EVP_CIPH_ECB_MODE EVP_CIPH_CBC_MODE, +EVP_CIPH_CFB_MODE, EVP_CIPH_OFB_MODE, EVP_CIPH_CTR_MODE, EVP_CIPH_GCM_MODE, +EVP_CIPH_CCM_MODE, EVP_CIPH_XTS_MODE, EVP_CIPH_WRAP_MODE, +EVP_CIPH_OCB_MODE, EVP_CIPH_SIV_MODE + +The cipher mode. + +=item EVP_CIPH_VARIABLE_LENGTH + +This cipher is of variable length. + +=item EVP_CIPH_CUSTOM_IV + +Storing and initialising the IV is left entirely to the +implementation. + +=item EVP_CIPH_ALWAYS_CALL_INIT + +Set this if the implementation's init() function should be called even +if B is B. + +=item EVP_CIPH_CTRL_INIT + +Set this to have the implementation's ctrl() function called with +command code B early in its setup. + +=item EVP_CIPH_CUSTOM_KEY_LENGTH + +Checking and setting the key length after creating the B +is left to the implementation. +Whenever someone uses EVP_CIPHER_CTX_set_key_length() on a +B with this flag set, the implementation's ctrl() function +will be called with the control code B and +the key length in B. + +=item EVP_CIPH_NO_PADDING + +Don't use standard block padding. + +=item EVP_CIPH_RAND_KEY + +Making a key with random content is left to the implementation. +This is done by calling the implementation's ctrl() function with the +control code B and the pointer to the key memory +storage in B. + +=item EVP_CIPH_CUSTOM_COPY + +Set this to have the implementation's ctrl() function called with +command code B at the end of EVP_CIPHER_CTX_copy(). +The intended use is for further things to deal with after the +implementation specific data block has been copied. +The destination B is passed to the control with the +B parameter. +The implementation specific data block is reached with +EVP_CIPHER_CTX_get_cipher_data(). + +=item EVP_CIPH_FLAG_DEFAULT_ASN1 + +Use the default EVP routines to pass IV to and from ASN.1. + +=item EVP_CIPH_FLAG_LENGTH_BITS + +Signals that the length of the input buffer for encryption / +decryption is to be understood as the number of bits instead of +bytes for this implementation. +This is only useful for CFB1 ciphers. + +=item EVP_CIPH_FLAG_CTS + +Indicates that the cipher uses ciphertext stealing. This is currently +used to indicate that the cipher is a one shot that only allows a single call to +EVP_CipherUpdate(). + +=item EVP_CIPH_FLAG_CUSTOM_CIPHER + +This indicates that the implementation takes care of everything, +including padding, buffering and finalization. +The EVP routines will simply give them control and do nothing more. + +=item EVP_CIPH_FLAG_AEAD_CIPHER + +This indicates that this is an AEAD cipher implementation. + +=item EVP_CIPH_FLAG_TLS1_1_MULTIBLOCK + +Allow interleaving of crypto blocks, a particular optimization only applicable +to certain TLS ciphers. + +=back + +EVP_CIPHER_meth_set_impl_ctx_size() sets the size of the EVP_CIPHER's +implementation context so that it can be automatically allocated. + +EVP_CIPHER_meth_set_init() sets the cipher init function for +B. +The cipher init function is called by EVP_CipherInit(), +EVP_CipherInit_ex(), EVP_EncryptInit(), EVP_EncryptInit_ex(), +EVP_DecryptInit(), EVP_DecryptInit_ex(). + +EVP_CIPHER_meth_set_do_cipher() sets the cipher function for +B. +The cipher function is called by EVP_CipherUpdate(), +EVP_EncryptUpdate(), EVP_DecryptUpdate(), EVP_CipherFinal(), +EVP_EncryptFinal(), EVP_EncryptFinal_ex(), EVP_DecryptFinal() and +EVP_DecryptFinal_ex(). + +EVP_CIPHER_meth_set_cleanup() sets the function for B to do +extra cleanup before the method's private data structure is cleaned +out and freed. +Note that the cleanup function is passed a B, the +private data structure is then available with +EVP_CIPHER_CTX_get_cipher_data(). +This cleanup function is called by EVP_CIPHER_CTX_reset() and +EVP_CIPHER_CTX_free(). + +EVP_CIPHER_meth_set_set_asn1_params() sets the function for B +to set the AlgorithmIdentifier "parameter" based on the passed cipher. +This function is called by EVP_CIPHER_param_to_asn1(). +EVP_CIPHER_meth_set_get_asn1_params() sets the function for B +that sets the cipher parameters based on an ASN.1 AlgorithmIdentifier +"parameter". +Both these functions are needed when there is a need for custom data +(more or other than the cipher IV). +They are called by EVP_CIPHER_param_to_asn1() and +EVP_CIPHER_asn1_to_param() respectively if defined. + +EVP_CIPHER_meth_set_ctrl() sets the control function for B. + +EVP_CIPHER_meth_get_init(), EVP_CIPHER_meth_get_do_cipher(), +EVP_CIPHER_meth_get_cleanup(), EVP_CIPHER_meth_get_set_asn1_params(), +EVP_CIPHER_meth_get_get_asn1_params() and EVP_CIPHER_meth_get_ctrl() +are all used to retrieve the method data given with the +EVP_CIPHER_meth_set_*() functions above. + +=head1 RETURN VALUES + +EVP_CIPHER_meth_new() and EVP_CIPHER_meth_dup() return a pointer to a +newly created B, or NULL on failure. +All EVP_CIPHER_meth_set_*() functions return 1. +All EVP_CIPHER_meth_get_*() functions return pointers to their +respective B function. + +=head1 SEE ALSO + +L + +=head1 HISTORY + +All of these functions were deprecated in OpenSSL 3.0. + +The functions described here were added in OpenSSL 1.1.0. +The B structure created with these functions became reference +counted in OpenSSL 3.0. + +=head1 COPYRIGHT + +Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved. + +Licensed under the Apache License 2.0 (the "License"). You may not use +this file except in compliance with the License. You can obtain a copy +in the file LICENSE in the source distribution or at +L. + +=cut diff --git a/doc/man3/EVP_DigestInit.pod b/doc/man3/EVP_DigestInit.pod index 13c85e6c9b..804a76f73b 100644 --- a/doc/man3/EVP_DigestInit.pod +++ b/doc/man3/EVP_DigestInit.pod @@ -13,13 +13,12 @@ EVP_MD_CTX_set_flags, EVP_MD_CTX_clear_flags, EVP_MD_CTX_test_flags, EVP_Q_digest, EVP_Digest, EVP_DigestInit_ex2, EVP_DigestInit_ex, EVP_DigestInit, EVP_DigestUpdate, EVP_DigestFinal_ex, EVP_DigestFinalXOF, EVP_DigestFinal, EVP_DigestSqueeze, -EVP_MD_CTX_serialize, EVP_MD_CTX_deserialize, EVP_MD_is_a, EVP_MD_get0_name, EVP_MD_get0_description, EVP_MD_names_do_all, EVP_MD_get0_provider, EVP_MD_get_type, EVP_MD_get_pkey_type, EVP_MD_get_size, EVP_MD_get_block_size, EVP_MD_get_flags, EVP_MD_CTX_get0_name, EVP_MD_CTX_md, EVP_MD_CTX_get0_md, EVP_MD_CTX_get1_md, EVP_MD_CTX_get_type, EVP_MD_CTX_get_size_ex, EVP_MD_CTX_get_block_size, -EVP_MD_CTX_get0_md_data, +EVP_MD_CTX_get0_md_data, EVP_MD_CTX_update_fn, EVP_MD_CTX_set_update_fn, EVP_md_null, EVP_get_digestbyname, EVP_get_digestbynid, EVP_get_digestbyobj, EVP_MD_CTX_get_pkey_ctx, EVP_MD_CTX_set_pkey_ctx, @@ -66,8 +65,6 @@ EVP_MD_CTX_type, EVP_MD_CTX_pkey_ctx, EVP_MD_CTX_md_data int EVP_DigestFinal_ex(EVP_MD_CTX *ctx, unsigned char *md, unsigned int *s); int EVP_DigestFinalXOF(EVP_MD_CTX *ctx, unsigned char *out, size_t outlen); int EVP_DigestSqueeze(EVP_MD_CTX *ctx, unsigned char *out, size_t outlen); - int EVP_MD_CTX_serialize(EVP_MD_CTX *ctx, unsigned char *out, size_t *outlen); - int EVP_MD_CTX_deserialize(EVP_MD_CTX *ctx, const unsigned char *in, size_t inlen); EVP_MD_CTX *EVP_MD_CTX_dup(const EVP_MD_CTX *in); int EVP_MD_CTX_copy_ex(EVP_MD_CTX *out, const EVP_MD_CTX *in); @@ -97,6 +94,7 @@ EVP_MD_CTX_type, EVP_MD_CTX_pkey_ctx, EVP_MD_CTX_md_data int EVP_MD_CTX_get_size_ex(const EVP_MD_CTX *ctx); int EVP_MD_CTX_get_block_size(const EVP_MD_CTX *ctx); int EVP_MD_CTX_get_type(const EVP_MD_CTX *ctx); + void *EVP_MD_CTX_get0_md_data(const EVP_MD_CTX *ctx); const EVP_MD *EVP_md_null(void); @@ -123,7 +121,7 @@ EVP_MD_CTX_type, EVP_MD_CTX_pkey_ctx, EVP_MD_CTX_md_data #define EVP_MD_CTX_block_size EVP_MD_CTX_get_block_size #define EVP_MD_CTX_type EVP_MD_CTX_get_type #define EVP_MD_CTX_pkey_ctx EVP_MD_CTX_get_pkey_ctx - + #define EVP_MD_CTX_md_data EVP_MD_CTX_get0_md_data The following functions have been deprecated since OpenSSL 3.0, and can be hidden entirely by defining B with a suitable version value, @@ -131,13 +129,12 @@ see L: const EVP_MD *EVP_MD_CTX_md(const EVP_MD_CTX *ctx); -The following functions have been deprecated since OpenSSL 4.0, and can be -hidden entirely by defining B with a suitable version value, -see L: + int (*EVP_MD_CTX_update_fn(EVP_MD_CTX *ctx))(EVP_MD_CTX *ctx, + const void *data, size_t count); - void *EVP_MD_CTX_get0_md_data(const EVP_MD_CTX *ctx); - - #define EVP_MD_CTX_md_data EVP_MD_CTX_get0_md_data + void EVP_MD_CTX_set_update_fn(EVP_MD_CTX *ctx, + int (*update)(EVP_MD_CTX *ctx, + const void *data, size_t count)); =head1 DESCRIPTION @@ -150,9 +147,8 @@ Each Message digest algorithm (such as SHA256) produces a fixed size output length which is returned when EVP_DigestFinal_ex() is called. Extendable Output Functions (XOF) such as SHAKE256 have a variable sized output length I which can be used with either EVP_DigestFinalXOF() or -EVP_DigestSqueeze(). EVP_DigestFinal_ex() may also be used for XOF algorithms, but -for XOF algorithms that do not have a default size the "xoflen" must be set -beforehand (See L). +EVP_DigestSqueeze(). EVP_DigestFinal_ex() may also be used for an XOF, but the +"xoflen" must be set beforehand (See L). Note that EVP_MD_get_size() and EVP_MD_CTX_get_size_ex() behave differently for an XOF. @@ -323,29 +319,6 @@ Similar to EVP_DigestFinalXOF() but allows multiple calls to be made to squeeze variable length output data. EVP_DigestFinalXOF() should not be called after this. -=item EVP_MD_CTX_serialize() and EVP_MD_CTX_deserialize() - -EVP_MD_CTX_serialize() serializes the state of the digest context I -and stores it in I, unless I is NULL. -Otherwise the maximum necessary size of the output buffer is written to -the I parameter. If I is not NULL then before the call the -I parameter must contain the length of the I buffer. If the -call is successful the data is written to I and the amount of data -written to I. - -EVP_MD_CTX_deserialize() deserializes the data from I of size I -into the digest context I. - -These functions do not guarantee importability of state exported by a -different OpenSSL version and does not guarantee interoperability between -different providers. Some providers may not allow export/import across -process boundaries. - -NOTE: Applications must guarantee that only trusted data is used during -deserialization. The deserialization operation is not built to address -adversarial data compromise, and only basic checks to protect from simple -mistakes are implemented. - =item EVP_MD_CTX_dup() Can be used to duplicate the message digest state from I. This is useful @@ -387,7 +360,7 @@ L) will be considered. =item EVP_MD_xof() Returns 1 if I is an Extendable-output Function (XOF) otherwise it returns -0. SHAKE128, SHAKE256, CSHAKE128 and CSHAKE256 are XOF functions. +0. SHAKE128 and SHAKE256 are XOF functions. It returns 0 for BLAKE2B algorithms. =item EVP_MD_get0_name(), @@ -438,8 +411,9 @@ returns B. This function is normally used when setting ASN1 OIDs. =item EVP_MD_CTX_get0_md_data() -This function is deprecated and exists for legacy backward compatibility reasons -and always returns NULL. +Return the digest method private data for the passed B. +The space is allocated by OpenSSL and has the size originally set with +EVP_MD_meth_set_app_datasize(). =item EVP_MD_CTX_get0_md(), EVP_MD_CTX_get1_md() @@ -453,11 +427,20 @@ should not be used after the EVP_MD_CTX is freed. EVP_MD_CTX_get1_md() is the same except the ownership is passed to the caller and is from the passed B. +=item EVP_MD_CTX_set_update_fn() + +Sets the update function for I to I. +This is the function that is called by EVP_DigestUpdate(). If not set, the +update function from the B type specified at initialization is used. + +=item EVP_MD_CTX_update_fn() + +Returns the update function for I. + =item EVP_MD_get_flags() Returns the I flags. Note that these are different from the B -ones. See the "flags" parameter as documented in L for a -description of the available flags. +ones. See L for more information. =item EVP_MD_get_pkey_type() @@ -532,7 +515,7 @@ following OSSL_PARAM keys: Sets or gets the digest length for extendable output functions. The value should not exceed what can be given using a B. -It may be used by SHAKE-128, CSHAKE-128, SHAKE-256 and CSHAKE-256, to set the +It may be used by SHAKE-128 and SHAKE-256 to set the output length used by EVP_DigestFinal_ex() and EVP_DigestFinal(). =item "size" (B) @@ -553,20 +536,6 @@ EVP_MD_CTX_set_params() can be used with the following OSSL_PARAM keys: Sets the padding type. It is used by the MDC2 algorithm. -=item "function-name" (B) - -Sets the function name string. -It is used by L. - -=item "customization" (B) - -Sets a customisation string. -It is used by L. - -=item "properties" (B) - -Sets properties to be used when fetching algorithm implementations. - =back EVP_MD_CTX_get_params() can be used with the following OSSL_PARAM keys: @@ -663,9 +632,7 @@ EVP_DigestInit_ex(), EVP_DigestInit(), EVP_DigestUpdate(), EVP_DigestFinal_ex(), -EVP_DigestFinalXOF(), -EVP_MD_CTX_serialize(), -EVP_MD_CTX_deserialize(), and +EVP_DigestFinalXOF(), and EVP_DigestFinal() return 1 for @@ -831,6 +798,7 @@ digest name passed on the command line. =head1 SEE ALSO +L, L, L, L, @@ -895,12 +863,9 @@ to be aliases for EVP_MD_CTX_get_size_ex(), previously they were aliases for EVP_MD_get_size which returned a constant value. This is required for XOF digests since they do not have a fixed size. -The EVP_MD_CTX_serialize() and EVP_MD_CTX_deserialize() functions were added in -OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/EVP_EC_gen.pod b/doc/man3/EVP_EC_gen.pod deleted file mode 100644 index 6279a73445..0000000000 --- a/doc/man3/EVP_EC_gen.pod +++ /dev/null @@ -1,49 +0,0 @@ -=pod - -=head1 NAME - -EVP_EC_gen, EVP_EC_affine2oct -- EVP routines for EC keys - -=head1 SYNOPSIS - - #include - - EVP_PKEY *EVP_EC_gen(const char *curve); - int EVP_EC_affine2oct(const BIGNUM *x, const BIGNUM *y, size_t field_len, - unsigned char **pbuf, size_t *pbsize); - -=head1 DESCRIPTION - -EVP_EC_gen() generates a new EC key pair on the given I. - -EVP_EC_affine2oct() converts affine coordinates I and I of an EC point -to an octet string conforming to Sec. 2.3.4 of the SECG SEC 1 -("Elliptic Curve Cryptography") standard. This octet string can further -be passed to OSSL_PARAM_BLD_push_octet_string(). The length of the field degree -representation (in bytes) must be passed to I. The function allocates -a buffer for octet string and places a pointer to I<*pbuf>. It's the caller's -responsibility to free this buffer with OPENSSL_free(). - -=head1 RETURN VALUES - -EVP_EC_gen() returns the EC key pair generated or NULL on error. - -EVP_EC_affine2oct() returns 1 on success or 0 on error. - -=head1 HISTORY - -EVP_EC_gen() was added in OpenSSL 3.0. - -EVP_EC_affine2oct() was added in OpenSSL 4.1. - -=head1 COPYRIGHT - -Copyright 2013-2026 The OpenSSL Project Authors. All Rights Reserved. - -Licensed under the Apache License 2.0 (the "License"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file LICENSE in the source distribution or at -L. - -=cut diff --git a/doc/man3/EVP_EncryptInit.pod b/doc/man3/EVP_EncryptInit.pod index ee438947ab..05801a17a5 100644 --- a/doc/man3/EVP_EncryptInit.pod +++ b/doc/man3/EVP_EncryptInit.pod @@ -69,6 +69,8 @@ EVP_CIPHER_CTX_get_block_size, EVP_CIPHER_CTX_get_key_length, EVP_CIPHER_CTX_get_iv_length, EVP_CIPHER_CTX_get_tag_length, +EVP_CIPHER_CTX_get_app_data, +EVP_CIPHER_CTX_set_app_data, EVP_CIPHER_CTX_flags, EVP_CIPHER_CTX_set_flags, EVP_CIPHER_CTX_clear_flags, @@ -226,8 +228,12 @@ EVP_CIPHER_CTX_mode int EVP_CIPHER_CTX_get_key_length(const EVP_CIPHER_CTX *ctx); int EVP_CIPHER_CTX_get_iv_length(const EVP_CIPHER_CTX *ctx); int EVP_CIPHER_CTX_get_tag_length(const EVP_CIPHER_CTX *ctx); + void *EVP_CIPHER_CTX_get_app_data(const EVP_CIPHER_CTX *ctx); + void EVP_CIPHER_CTX_set_app_data(const EVP_CIPHER_CTX *ctx, void *data); int EVP_CIPHER_CTX_get_type(const EVP_CIPHER_CTX *ctx); int EVP_CIPHER_CTX_get_mode(const EVP_CIPHER_CTX *ctx); + int EVP_CIPHER_CTX_get_num(const EVP_CIPHER_CTX *ctx); + int EVP_CIPHER_CTX_set_num(EVP_CIPHER_CTX *ctx, int num); int EVP_CIPHER_CTX_is_encrypting(const EVP_CIPHER_CTX *ctx); int EVP_CIPHER_param_to_asn1(EVP_CIPHER_CTX *c, ASN1_TYPE *type); @@ -251,17 +257,10 @@ EVP_CIPHER_CTX_mode #define EVP_CIPHER_CTX_key_length EVP_CIPHER_CTX_get_key_length #define EVP_CIPHER_CTX_iv_length EVP_CIPHER_CTX_get_iv_length #define EVP_CIPHER_CTX_tag_length EVP_CIPHER_CTX_get_tag_length + #define EVP_CIPHER_CTX_num EVP_CIPHER_CTX_get_num #define EVP_CIPHER_CTX_type EVP_CIPHER_CTX_get_type #define EVP_CIPHER_CTX_mode EVP_CIPHER_CTX_get_mode -The following functions and alias have been deprecated since OpenSSL 4.1, and -can be hidden entirely by defining B with a suitable version -value, see L: - - int EVP_CIPHER_CTX_get_num(const EVP_CIPHER_CTX *ctx); - int EVP_CIPHER_CTX_set_num(EVP_CIPHER_CTX *ctx, int num); - #define EVP_CIPHER_CTX_num EVP_CIPHER_CTX_get_num - The following function has been deprecated since OpenSSL 3.0, and can be hidden entirely by defining B with a suitable version value, see L: @@ -417,8 +416,7 @@ encrypted data. For most ciphers and modes, the amount of data written can be anything from zero bytes to (inl + cipher_block_size - 1) bytes. For wrap cipher modes, the amount of data written can be anything -from zero bytes to (inl rounded up to cipher_block_size + cipher_block_size) -bytes. +from zero bytes to (inl + cipher_block_size) bytes. For stream ciphers, the amount of data written can be anything from zero bytes to inl bytes. Thus, the buffer pointed to by I must contain sufficient room for the @@ -814,11 +812,6 @@ Gets 1 if the cipher algorithm I supports the gettable EVP_CIPHER_CTX parameter B. Only DES and 3DES set this to 1, all other OpenSSL ciphers return 0. -=item "encrypt-then-mac" (B) - -Gets 1 if the cipher algorithm I supports TLS Encrypt-then-MAC, -otherwise it gets 0. - =item "decrypt-only" (B Gets 1 if the cipher algorithm I implementation supports only @@ -846,7 +839,6 @@ Gets or sets the cipher specific "num" parameter for the cipher context I. Built-in ciphers typically use this to track how much of the current underlying block has been "used" already. See also EVP_CIPHER_CTX_get_num() and EVP_CIPHER_CTX_set_num(). -This parameter was deprecated in OpenSSL 4.1. =item "keylen" (B) @@ -1352,30 +1344,16 @@ See L "tls-multi". See L "has-randkey". -=item EVP_CIPH_FLAG_ENC_THEN_MAC - -See L "encrypt-then-mac". - -=item EVP_CIPH_STREAM_CIPHER, EVP_CIPH_ECB_MODE EVP_CIPH_CBC_MODE, -EVP_CIPH_CFB_MODE, EVP_CIPH_OFB_MODE, EVP_CIPH_CTR_MODE, EVP_CIPH_GCM_MODE, -EVP_CIPH_CCM_MODE, EVP_CIPH_XTS_MODE, EVP_CIPH_WRAP_MODE, -EVP_CIPH_OCB_MODE, EVP_CIPH_SIV_MODE - -See L "mode". - =back -EVP_CIPHER_flags() also uses the flag B to indicate -that the cipher supports any input length when used with the EVP_Cipher() -function. See EVP_Cipher() for more details. - -The following flags are defined for legacy purposes and are not returned by -EVP_CIPHER_flags(): +EVP_CIPHER_flags() uses the following flags for legacy purposes only: =over 4 =item EVP_CIPH_VARIABLE_LENGTH +=item EVP_CIPH_FLAG_CUSTOM_CIPHER + =item EVP_CIPH_ALWAYS_CALL_INIT =item EVP_CIPH_CTRL_INIT @@ -1386,6 +1364,9 @@ EVP_CIPHER_flags(): =item EVP_CIPH_FLAG_DEFAULT_ASN1 +See L for further information related to the above +flags. + =back =head1 RETURN VALUES @@ -1475,10 +1456,6 @@ for failure. EVP_CIPHER_names_do_all() returns 1 if the callback was called for all names. A return value of 0 means that the callback was not called for any names. -EVP_CIPHER_get_params(), EVP_CIPHER_CTX_get_params() and -EVP_CIPHER_CTX_set_params() return a positive value for success and 0 or a negative value for -failure. - =head1 CIPHER LISTING All algorithms have a fixed key length unless otherwise stated. @@ -1503,12 +1480,7 @@ depending on the mode specified. To specify additional authenticated data (AAD), a call to EVP_CipherUpdate(), EVP_EncryptUpdate() or EVP_DecryptUpdate() should be made with the output parameter I set to NULL. In this case, on success, the parameter -I is set to the number of AAD bytes processed in that call -(that is, the value of I), and does not include any plaintext -or ciphertext bytes processed by other calls. - -If no AAD is used, this call can be omitted. See the mode-specific notes -below for any exceptions. +I is set to the number of bytes authenticated. When decrypting, the return value of EVP_DecryptFinal() or EVP_CipherFinal() indicates whether the operation was successful. If it does not indicate success, @@ -1952,9 +1924,6 @@ EVP_CIPHER_CTX_reset(). The EVP_CIPHER_CTX_cipher() function was deprecated in OpenSSL 3.0; use EVP_CIPHER_CTX_get0_cipher() instead. -The EVP_CIPHER_CTX_get_num(), EVP_CIPHER_CTX_set_num() functions and the -EVP_CIPHER_CTX_num() macro were deprecated in OpenSSL 4.1. - The EVP_EncryptInit_ex2(), EVP_DecryptInit_ex2(), EVP_CipherInit_ex2(), EVP_CIPHER_fetch(), EVP_CIPHER_free(), EVP_CIPHER_up_ref(), EVP_CIPHER_CTX_get0_cipher(), EVP_CIPHER_CTX_get1_cipher(), @@ -1990,7 +1959,7 @@ rather than a 0 return value indicating an error. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/EVP_KDF.pod b/doc/man3/EVP_KDF.pod index 6df44e8643..b9cc14eb79 100644 --- a/doc/man3/EVP_KDF.pod +++ b/doc/man3/EVP_KDF.pod @@ -6,7 +6,7 @@ EVP_KDF, EVP_KDF_fetch, EVP_KDF_free, EVP_KDF_up_ref, EVP_KDF_CTX, EVP_KDF_CTX_new, EVP_KDF_CTX_free, EVP_KDF_CTX_dup, EVP_KDF_CTX_reset, EVP_KDF_derive, EVP_KDF_CTX_set_SKEY, EVP_KDF_derive_SKEY, -EVP_KDF_CTX_get_kdf_size, EVP_KDF_CTX_get0_kdf, EVP_KDF_CTX_get1_kdf, +EVP_KDF_CTX_get_kdf_size, EVP_KDF_get0_provider, EVP_KDF_CTX_kdf, EVP_KDF_is_a, EVP_KDF_get0_name, EVP_KDF_names_do_all, EVP_KDF_get0_description, EVP_KDF_CTX_get_params, EVP_KDF_CTX_set_params, EVP_KDF_do_all_provided, @@ -22,8 +22,7 @@ EVP_KDF_CTX_gettable_params, EVP_KDF_CTX_settable_params - EVP KDF routines typedef struct evp_kdf_ctx_st EVP_KDF_CTX; EVP_KDF_CTX *EVP_KDF_CTX_new(EVP_KDF *kdf); - const EVP_KDF *EVP_KDF_CTX_get0_kdf(const EVP_KDF_CTX *ctx); - EVP_KDF *EVP_KDF_CTX_get1_kdf(EVP_KDF_CTX *ctx); + const EVP_KDF *EVP_KDF_CTX_kdf(EVP_KDF_CTX *ctx); void EVP_KDF_CTX_free(EVP_KDF_CTX *ctx); EVP_KDF_CTX *EVP_KDF_CTX_dup(const EVP_KDF_CTX *src); void EVP_KDF_CTX_reset(EVP_KDF_CTX *ctx); @@ -58,12 +57,6 @@ EVP_KDF_CTX_gettable_params, EVP_KDF_CTX_settable_params - EVP KDF routines const OSSL_PARAM *EVP_KDF_CTX_settable_params(const EVP_KDF *kdf); const OSSL_PROVIDER *EVP_KDF_get0_provider(const EVP_KDF *kdf); -The following functions have been deprecated since OpenSSL 4.1, -and can be hidden entirely by defining B with a suitable -version value, see L: - - const EVP_KDF *EVP_KDF_CTX_kdf(const EVP_KDF_CTX *ctx); - =head1 DESCRIPTION The EVP KDF routines are a high-level interface to Key Derivation Function @@ -106,10 +99,8 @@ EVP_KDF_CTX_new() creates a new context for the KDF implementation I. EVP_KDF_CTX_free() frees up the context I. If I is NULL, nothing is done. -EVP_KDF_CTX_get0_kdf() returns the B associated with the context -I. EVP_KDF_CTX_get1_kdf() is the same, except ownership is passed -to the caller. -EVP_KDF_CTX_kdf() is an alias for EVP_KDF_CTX_get0_kdf(). +EVP_KDF_CTX_kdf() returns the B associated with the context +I. =head2 Computing functions @@ -333,12 +324,6 @@ This functionality was added in OpenSSL 3.0. EVP_KDF_derive_SKEY() and EVP_KDF_CTX_set_SKEY() functions were introduced in OpenSSL 3.6. -EVP_KDF_CTX_get0_kdf() and EVP_KDF_CTX_get1_kdf() functions were introduced -in OpenSSL 4.1. - -EVP_KDF_CTX_kdf() function was deprecated in favour of EVP_KDF_CTX_get0_kdf() -in OpenSSL 4.1. - =head1 COPYRIGHT Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. diff --git a/doc/man3/EVP_MAC.pod b/doc/man3/EVP_MAC.pod index 1ca411e5d7..e766a5d234 100644 --- a/doc/man3/EVP_MAC.pod +++ b/doc/man3/EVP_MAC.pod @@ -147,7 +147,7 @@ as part of this call or separately using EVP_MAC_CTX_set_params(). Providing non-NULL I to this function is equivalent to calling EVP_MAC_CTX_set_params() with those I for the same I beforehand. Note: There are additional requirements for some MAC algorithms during -re-initialization (i.e. calling EVP_MAC_init() on an EVP_MAC after EVP_MAC_final() +re-initalization (i.e. calling EVP_MAC_init() on an EVP_MAC after EVP_MAC_final() has been called on the same object). See the NOTES section below. EVP_MAC_init() should be called before EVP_MAC_update() and EVP_MAC_final(). @@ -259,7 +259,7 @@ The standard parameter names are: Its value is the MAC key as an array of bytes. For MACs that use an underlying computation algorithm, the algorithm -must be set first, see "cipher" and "digest" parameters below. +must be set first, see parameter names "algorithm" below. =item "iv" (B) @@ -352,7 +352,7 @@ The usage of the parameter names "custom", "iv" and "salt" correspond to the names used in the standard where the algorithm was defined. Some MAC algorithms store internal state that cannot be extracted during -re-initialization. For example GMAC cannot extract an B from the +re-initalization. For example GMAC cannot extract an B from the underlying CIPHER context, and so calling EVP_MAC_init() on an EVP_MAC object after EVP_MAC_final() has been called cannot reset its cipher state to what it was when the B was initially generated. For such instances, an @@ -499,7 +499,7 @@ The EVP_MAC_init_SKEY() function was added in OpenSSL 3.5. =head1 COPYRIGHT -Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2018-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/EVP_MD_meth_new.pod b/doc/man3/EVP_MD_meth_new.pod new file mode 100644 index 0000000000..3497973323 --- /dev/null +++ b/doc/man3/EVP_MD_meth_new.pod @@ -0,0 +1,205 @@ +=pod + +=head1 NAME + +EVP_MD_meth_new, EVP_MD_meth_dup, EVP_MD_meth_free, +EVP_MD_meth_set_input_blocksize, +EVP_MD_meth_set_result_size, EVP_MD_meth_set_app_datasize, +EVP_MD_meth_set_flags, EVP_MD_meth_set_init, EVP_MD_meth_set_update, +EVP_MD_meth_set_final, EVP_MD_meth_set_copy, EVP_MD_meth_set_cleanup, +EVP_MD_meth_set_ctrl, EVP_MD_meth_get_input_blocksize, +EVP_MD_meth_get_result_size, EVP_MD_meth_get_app_datasize, +EVP_MD_meth_get_flags, EVP_MD_meth_get_init, EVP_MD_meth_get_update, +EVP_MD_meth_get_final, EVP_MD_meth_get_copy, EVP_MD_meth_get_cleanup, +EVP_MD_meth_get_ctrl +- Routines to build up legacy EVP_MD methods + +=head1 SYNOPSIS + + #include + +The following functions have been deprecated since OpenSSL 3.0, and can be +hidden entirely by defining B with a suitable version value, +see L: + + EVP_MD *EVP_MD_meth_new(int md_type, int pkey_type); + void EVP_MD_meth_free(EVP_MD *md); + EVP_MD *EVP_MD_meth_dup(const EVP_MD *md); + + int EVP_MD_meth_set_input_blocksize(EVP_MD *md, int blocksize); + int EVP_MD_meth_set_result_size(EVP_MD *md, int resultsize); + int EVP_MD_meth_set_app_datasize(EVP_MD *md, int datasize); + int EVP_MD_meth_set_flags(EVP_MD *md, unsigned long flags); + int EVP_MD_meth_set_init(EVP_MD *md, int (*init)(EVP_MD_CTX *ctx)); + int EVP_MD_meth_set_update(EVP_MD *md, int (*update)(EVP_MD_CTX *ctx, + const void *data, + size_t count)); + int EVP_MD_meth_set_final(EVP_MD *md, int (*final)(EVP_MD_CTX *ctx, + unsigned char *md)); + int EVP_MD_meth_set_copy(EVP_MD *md, int (*copy)(EVP_MD_CTX *to, + const EVP_MD_CTX *from)); + int EVP_MD_meth_set_cleanup(EVP_MD *md, int (*cleanup)(EVP_MD_CTX *ctx)); + int EVP_MD_meth_set_ctrl(EVP_MD *md, int (*ctrl)(EVP_MD_CTX *ctx, int cmd, + int p1, void *p2)); + + int EVP_MD_meth_get_input_blocksize(const EVP_MD *md); + int EVP_MD_meth_get_result_size(const EVP_MD *md); + int EVP_MD_meth_get_app_datasize(const EVP_MD *md); + unsigned long EVP_MD_meth_get_flags(const EVP_MD *md); + int (*EVP_MD_meth_get_init(const EVP_MD *md))(EVP_MD_CTX *ctx); + int (*EVP_MD_meth_get_update(const EVP_MD *md))(EVP_MD_CTX *ctx, + const void *data, + size_t count); + int (*EVP_MD_meth_get_final(const EVP_MD *md))(EVP_MD_CTX *ctx, + unsigned char *md); + int (*EVP_MD_meth_get_copy(const EVP_MD *md))(EVP_MD_CTX *to, + const EVP_MD_CTX *from); + int (*EVP_MD_meth_get_cleanup(const EVP_MD *md))(EVP_MD_CTX *ctx); + int (*EVP_MD_meth_get_ctrl(const EVP_MD *md))(EVP_MD_CTX *ctx, int cmd, + int p1, void *p2); + +=head1 DESCRIPTION + +All of the functions described on this page are deprecated. +Applications should instead use the OSSL_PROVIDER APIs. + +The B type is a structure for digest method implementation. +It can also have associated public/private key signing and verifying +routines. + +EVP_MD_meth_new() creates a new B structure. +These B structures are reference counted. + +EVP_MD_meth_dup() creates a copy of B. + +EVP_MD_meth_free() decrements the reference count for the B structure. +If the reference count drops to 0 then the structure is freed. +If the argument is NULL, nothing is done. + +EVP_MD_meth_set_input_blocksize() sets the internal input block size +for the method B to B bytes. + +EVP_MD_meth_set_result_size() sets the size of the result that the +digest method in B is expected to produce to B bytes. + +The digest method may have its own private data, which OpenSSL will +allocate for it. EVP_MD_meth_set_app_datasize() should be used to +set the size for it to B. + +EVP_MD_meth_set_flags() sets the flags to describe optional +behaviours in the particular B. Several flags can be or'd +together. The available flags are: + +=over 4 + +=item EVP_MD_FLAG_ONESHOT + +This digest method can only handle one block of input. + +=item EVP_MD_FLAG_XOF + +This digest method is an extensible-output function (XOF) and supports +the B control. + +=item EVP_MD_FLAG_DIGALGID_NULL + +When setting up a DigestAlgorithmIdentifier, this flag will have the +parameter set to NULL by default. Use this for PKCS#1. I + +=item EVP_MD_FLAG_DIGALGID_ABSENT + +When setting up a DigestAlgorithmIdentifier, this flag will have the +parameter be left absent by default. I + +=item EVP_MD_FLAG_DIGALGID_CUSTOM + +Custom DigestAlgorithmIdentifier handling via ctrl, with +B as default. I +Currently unused. + +=item EVP_MD_FLAG_FIPS + +This digest method is suitable for use in FIPS mode. +Currently unused. + +=back + +EVP_MD_meth_set_init() sets the digest init function for B. +The digest init function is called by EVP_Digest(), EVP_DigestInit(), +EVP_DigestInit_ex(), EVP_SignInit, EVP_SignInit_ex(), EVP_VerifyInit() +and EVP_VerifyInit_ex(). + +EVP_MD_meth_set_update() sets the digest update function for B. +The digest update function is called by EVP_Digest(), EVP_DigestUpdate() and +EVP_SignUpdate(). + +EVP_MD_meth_set_final() sets the digest final function for B. +The digest final function is called by EVP_Digest(), EVP_DigestFinal(), +EVP_DigestFinal_ex(), EVP_SignFinal() and EVP_VerifyFinal(). + +EVP_MD_meth_set_copy() sets the function for B to do extra +computations after the method's private data structure has been copied +from one B to another. If all that's needed is to copy +the data, there is no need for this copy function. +Note that the copy function is passed two B, the private +data structure is then available with EVP_MD_CTX_get0_md_data(). +This copy function is called by EVP_MD_CTX_copy() and +EVP_MD_CTX_copy_ex(). + +EVP_MD_meth_set_cleanup() sets the function for B to do extra +cleanup before the method's private data structure is cleaned out and +freed. +Note that the cleanup function is passed a B, the +private data structure is then available with EVP_MD_CTX_get0_md_data(). +This cleanup function is called by EVP_MD_CTX_reset() and +EVP_MD_CTX_free(). + +EVP_MD_meth_set_ctrl() sets the control function for B. +See L for the available controls. + +EVP_MD_meth_get_input_blocksize(), EVP_MD_meth_get_result_size(), +EVP_MD_meth_get_app_datasize(), EVP_MD_meth_get_flags(), +EVP_MD_meth_get_init(), EVP_MD_meth_get_update(), +EVP_MD_meth_get_final(), EVP_MD_meth_get_copy(), +EVP_MD_meth_get_cleanup() and EVP_MD_meth_get_ctrl() are all used +to retrieve the method data given with the EVP_MD_meth_set_*() +functions above. + +=head1 RETURN VALUES + +EVP_MD_meth_new() and EVP_MD_meth_dup() return a pointer to a newly +created B, or NULL on failure. +All EVP_MD_meth_set_*() functions return 1. +EVP_MD_get_input_blocksize(), EVP_MD_meth_get_result_size(), +EVP_MD_meth_get_app_datasize() and EVP_MD_meth_get_flags() return the +indicated sizes or flags. +All other EVP_CIPHER_meth_get_*() functions return pointers to their +respective B function. + +=head1 SEE ALSO + +L, L, L + +=head1 HISTORY + +All of these functions were deprecated in OpenSSL 3.0. + +The B structure was openly available in OpenSSL before version +1.1. +The functions described here were added in OpenSSL 1.1. +The B structure created with these functions became reference +counted in OpenSSL 3.0. + +=head1 COPYRIGHT + +Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved. + +Licensed under the Apache License 2.0 (the "License"). You may not use +this file except in compliance with the License. You can obtain a copy +in the file LICENSE in the source distribution or at +L. + +=cut diff --git a/doc/man3/EVP_PKEY_ASN1_METHOD.pod b/doc/man3/EVP_PKEY_ASN1_METHOD.pod new file mode 100644 index 0000000000..f688356432 --- /dev/null +++ b/doc/man3/EVP_PKEY_ASN1_METHOD.pod @@ -0,0 +1,455 @@ +=pod + +=head1 NAME + +EVP_PKEY_ASN1_METHOD, +EVP_PKEY_asn1_new, +EVP_PKEY_asn1_copy, +EVP_PKEY_asn1_free, +EVP_PKEY_asn1_add0, +EVP_PKEY_asn1_add_alias, +EVP_PKEY_asn1_set_public, +EVP_PKEY_asn1_set_private, +EVP_PKEY_asn1_set_param, +EVP_PKEY_asn1_set_free, +EVP_PKEY_asn1_set_ctrl, +EVP_PKEY_asn1_set_item, +EVP_PKEY_asn1_set_siginf, +EVP_PKEY_asn1_set_check, +EVP_PKEY_asn1_set_public_check, +EVP_PKEY_asn1_set_param_check, +EVP_PKEY_asn1_set_security_bits, +EVP_PKEY_asn1_set_set_priv_key, +EVP_PKEY_asn1_set_set_pub_key, +EVP_PKEY_asn1_set_get_priv_key, +EVP_PKEY_asn1_set_get_pub_key, +EVP_PKEY_get0_asn1 +- manipulating and registering EVP_PKEY_ASN1_METHOD structure + +=head1 SYNOPSIS + +The following functions have been deprecated since OpenSSL 3.6, and can be +hidden entirely by defining B with a suitable version value, +see L; use the provider API instead. + + #include + + typedef struct evp_pkey_asn1_method_st EVP_PKEY_ASN1_METHOD; + + EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_new(int id, int flags, + const char *pem_str, + const char *info); + void EVP_PKEY_asn1_copy(EVP_PKEY_ASN1_METHOD *dst, + const EVP_PKEY_ASN1_METHOD *src); + void EVP_PKEY_asn1_free(EVP_PKEY_ASN1_METHOD *ameth); + int EVP_PKEY_asn1_add0(const EVP_PKEY_ASN1_METHOD *ameth); + int EVP_PKEY_asn1_add_alias(int to, int from); + + void EVP_PKEY_asn1_set_public(EVP_PKEY_ASN1_METHOD *ameth, + int (*pub_decode) (EVP_PKEY *pk, + const X509_PUBKEY *pub), + int (*pub_encode) (X509_PUBKEY *pub, + const EVP_PKEY *pk), + int (*pub_cmp) (const EVP_PKEY *a, + const EVP_PKEY *b), + int (*pub_print) (BIO *out, + const EVP_PKEY *pkey, + int indent, ASN1_PCTX *pctx), + int (*pkey_size) (const EVP_PKEY *pk), + int (*pkey_bits) (const EVP_PKEY *pk)); + void EVP_PKEY_asn1_set_private(EVP_PKEY_ASN1_METHOD *ameth, + int (*priv_decode) (EVP_PKEY *pk, + const PKCS8_PRIV_KEY_INFO + *p8inf), + int (*priv_encode) (PKCS8_PRIV_KEY_INFO *p8, + const EVP_PKEY *pk), + int (*priv_print) (BIO *out, + const EVP_PKEY *pkey, + int indent, + ASN1_PCTX *pctx)); + void EVP_PKEY_asn1_set_param(EVP_PKEY_ASN1_METHOD *ameth, + int (*param_decode) (EVP_PKEY *pkey, + const unsigned char **pder, + int derlen), + int (*param_encode) (const EVP_PKEY *pkey, + unsigned char **pder), + int (*param_missing) (const EVP_PKEY *pk), + int (*param_copy) (EVP_PKEY *to, + const EVP_PKEY *from), + int (*param_cmp) (const EVP_PKEY *a, + const EVP_PKEY *b), + int (*param_print) (BIO *out, + const EVP_PKEY *pkey, + int indent, + ASN1_PCTX *pctx)); + + void EVP_PKEY_asn1_set_free(EVP_PKEY_ASN1_METHOD *ameth, + void (*pkey_free) (EVP_PKEY *pkey)); + void EVP_PKEY_asn1_set_ctrl(EVP_PKEY_ASN1_METHOD *ameth, + int (*pkey_ctrl) (EVP_PKEY *pkey, int op, + long arg1, void *arg2)); + void EVP_PKEY_asn1_set_item(EVP_PKEY_ASN1_METHOD *ameth, + int (*item_verify) (EVP_MD_CTX *ctx, + const ASN1_ITEM *it, + void *asn, + X509_ALGOR *a, + ASN1_BIT_STRING *sig, + EVP_PKEY *pkey), + int (*item_sign) (EVP_MD_CTX *ctx, + const ASN1_ITEM *it, + void *asn, + X509_ALGOR *alg1, + X509_ALGOR *alg2, + ASN1_BIT_STRING *sig)); + + void EVP_PKEY_asn1_set_siginf(EVP_PKEY_ASN1_METHOD *ameth, + int (*siginf_set) (X509_SIG_INFO *siginf, + const X509_ALGOR *alg, + const ASN1_STRING *sig)); + + void EVP_PKEY_asn1_set_check(EVP_PKEY_ASN1_METHOD *ameth, + int (*pkey_check) (const EVP_PKEY *pk)); + + void EVP_PKEY_asn1_set_public_check(EVP_PKEY_ASN1_METHOD *ameth, + int (*pkey_pub_check) (const EVP_PKEY *pk)); + + void EVP_PKEY_asn1_set_param_check(EVP_PKEY_ASN1_METHOD *ameth, + int (*pkey_param_check) (const EVP_PKEY *pk)); + + void EVP_PKEY_asn1_set_security_bits(EVP_PKEY_ASN1_METHOD *ameth, + int (*pkey_security_bits) (const EVP_PKEY + *pk)); + + void EVP_PKEY_asn1_set_set_priv_key(EVP_PKEY_ASN1_METHOD *ameth, + int (*set_priv_key) (EVP_PKEY *pk, + const unsigned char + *priv, + size_t len)); + + void EVP_PKEY_asn1_set_set_pub_key(EVP_PKEY_ASN1_METHOD *ameth, + int (*set_pub_key) (EVP_PKEY *pk, + const unsigned char *pub, + size_t len)); + + void EVP_PKEY_asn1_set_get_priv_key(EVP_PKEY_ASN1_METHOD *ameth, + int (*get_priv_key) (const EVP_PKEY *pk, + unsigned char *priv, + size_t *len)); + + void EVP_PKEY_asn1_set_get_pub_key(EVP_PKEY_ASN1_METHOD *ameth, + int (*get_pub_key) (const EVP_PKEY *pk, + unsigned char *pub, + size_t *len)); + + const EVP_PKEY_ASN1_METHOD *EVP_PKEY_get0_asn1(const EVP_PKEY *pkey); + +=head1 DESCRIPTION + +B is a structure which holds a set of ASN.1 +conversion, printing and information methods for a specific public key +algorithm. + +There are two places where the B objects are +stored: one is a built-in array representing the standard methods for +different algorithms, and the other one is a stack of user-defined +application-specific methods, which can be manipulated by using +L. + +=head2 Methods + +The methods are the underlying implementations of a particular public +key algorithm present by the B object. + + int (*pub_decode) (EVP_PKEY *pk, const X509_PUBKEY *pub); + int (*pub_encode) (X509_PUBKEY *pub, const EVP_PKEY *pk); + int (*pub_cmp) (const EVP_PKEY *a, const EVP_PKEY *b); + int (*pub_print) (BIO *out, const EVP_PKEY *pkey, int indent, + ASN1_PCTX *pctx); + +The pub_decode() and pub_encode() methods are called to decode / +encode B ASN.1 parameters to / from B. +They MUST return 0 on error, 1 on success. +They're called by L and L. + +The pub_cmp() method is called when two public keys are to be +compared. +It MUST return 1 when the keys are equal, 0 otherwise. +It's called by L. + +The pub_print() method is called to print a public key in humanly +readable text to B, indented B spaces. +It MUST return 0 on error, 1 on success. +It's called by L. + + int (*priv_decode) (EVP_PKEY *pk, const PKCS8_PRIV_KEY_INFO *p8inf); + int (*priv_encode) (PKCS8_PRIV_KEY_INFO *p8, const EVP_PKEY *pk); + int (*priv_print) (BIO *out, const EVP_PKEY *pkey, int indent, + ASN1_PCTX *pctx); + +The priv_decode() and priv_encode() methods are called to decode / +encode B form private key to / from B. +They MUST return 0 on error, 1 on success. +They're called by L and L. + +The priv_print() method is called to print a private key in humanly +readable text to B, indented B spaces. +It MUST return 0 on error, 1 on success. +It's called by L. + + int (*pkey_size) (const EVP_PKEY *pk); + int (*pkey_bits) (const EVP_PKEY *pk); + int (*pkey_security_bits) (const EVP_PKEY *pk); + +The pkey_size() method returns the key size in bytes. +It's called by L. + +The pkey_bits() method returns the key size in bits. +It's called by L. + + int (*param_decode) (EVP_PKEY *pkey, + const unsigned char **pder, int derlen); + int (*param_encode) (const EVP_PKEY *pkey, unsigned char **pder); + int (*param_missing) (const EVP_PKEY *pk); + int (*param_copy) (EVP_PKEY *to, const EVP_PKEY *from); + int (*param_cmp) (const EVP_PKEY *a, const EVP_PKEY *b); + int (*param_print) (BIO *out, const EVP_PKEY *pkey, int indent, + ASN1_PCTX *pctx); + +The param_decode() and param_encode() methods are called to decode / +encode DER formatted parameters to / from B. +They MUST return 0 on error, 1 on success. +They're called by L and the B +L. + +The param_missing() method returns 0 if a key parameter is missing, +otherwise 1. +It's called by L. + +The param_copy() method copies key parameters from B to B. +It MUST return 0 on error, 1 on success. +It's called by L. + +The param_cmp() method compares the parameters of keys B and B. +It MUST return 1 when the keys are equal, 0 when not equal, or a +negative number on error. +It's called by L. + +The param_print() method prints the private key parameters in humanly +readable text to B, indented B spaces. +It MUST return 0 on error, 1 on success. +It's called by L. + + int (*sig_print) (BIO *out, + const X509_ALGOR *sigalg, const ASN1_STRING *sig, + int indent, ASN1_PCTX *pctx); + +The sig_print() method prints a signature in humanly readable text to +B, indented B spaces. +B contains the exact signature algorithm. +If the signature in B doesn't correspond to what this method +expects, X509_signature_dump() must be used as a last resort. +It MUST return 0 on error, 1 on success. +It's called by L. + + void (*pkey_free) (EVP_PKEY *pkey); + +The pkey_free() method helps freeing the internals of B. +It's called by L, L, +L, and L. + + int (*pkey_ctrl) (EVP_PKEY *pkey, int op, long arg1, void *arg2); + +The pkey_ctrl() method adds extra algorithm specific control. +It's called by L, +L, +L, L, +L, ... + + int (*old_priv_decode) (EVP_PKEY *pkey, + const unsigned char **pder, int derlen); + int (*old_priv_encode) (const EVP_PKEY *pkey, unsigned char **pder); + +The old_priv_decode() and old_priv_encode() methods decode / encode +they private key B from / to a DER formatted array. +These are exclusively used to help decoding / encoding older (pre +PKCS#8) PEM formatted encrypted private keys. +old_priv_decode() MUST return 0 on error, 1 on success. +old_priv_encode() MUST the return same kind of values as +i2d_PrivateKey(). +They're called by L and L. + + int (*item_verify) (EVP_MD_CTX *ctx, const ASN1_ITEM *it, void *asn, + X509_ALGOR *a, ASN1_BIT_STRING *sig, EVP_PKEY *pkey); + int (*item_sign) (EVP_MD_CTX *ctx, const ASN1_ITEM *it, void *asn, + X509_ALGOR *alg1, X509_ALGOR *alg2, + ASN1_BIT_STRING *sig); + +The item_sign() and item_verify() methods make it possible to have +algorithm specific signatures and verification of them. + +item_sign() MUST return one of: + +=over 4 + +=item <=0 + +error + +=item Z<>1 + +item_sign() did everything, OpenSSL internals just needs to pass the +signature length back. + +=item Z<>2 + +item_sign() did nothing, OpenSSL internal standard routines are +expected to continue with the default signature production. + +=item Z<>3 + +item_sign() set the algorithm identifier B and B, +OpenSSL internals should just sign using those algorithms. + +=back + +item_verify() MUST return one of: + +=over 4 + +=item <=0 + +error + +=item Z<>1 + +item_sign() did everything, OpenSSL internals just needs to pass the +signature length back. + +=item Z<>2 + +item_sign() did nothing, OpenSSL internal standard routines are +expected to continue with the default signature production. + +=back + +item_verify() and item_sign() are called by L and +L, and by extension, L, +L, L, L, ... + + int (*siginf_set) (X509_SIG_INFO *siginf, const X509_ALGOR *alg, + const ASN1_STRING *sig); + +The siginf_set() method is used to set custom B +parameters. +It MUST return 0 on error, or 1 on success. +It's called as part of L, L +and L. + + int (*pkey_check) (const EVP_PKEY *pk); + int (*pkey_public_check) (const EVP_PKEY *pk); + int (*pkey_param_check) (const EVP_PKEY *pk); + +The pkey_check(), pkey_public_check() and pkey_param_check() methods are used +to check the validity of B for key-pair, public component and parameters, +respectively. +They MUST return 0 for an invalid key, or 1 for a valid key. +They are called by L, L and +L respectively. + + int (*set_priv_key) (EVP_PKEY *pk, const unsigned char *priv, size_t len); + int (*set_pub_key) (EVP_PKEY *pk, const unsigned char *pub, size_t len); + +The set_priv_key() and set_pub_key() methods are used to set the raw private and +public key data for an EVP_PKEY. They MUST return 0 on error, or 1 on success. +They are called by L, and +L respectively. + + size_t (*dirty) (const EVP_PKEY *pk); + void *(*export_to) (const EVP_PKEY *pk, EVP_KEYMGMT *keymgmt); + +dirty_cnt() returns the internal key's dirty count. +This can be used to synchronise different copies of the same keys. + +The export_to() method exports the key material from the given key to +a provider, through the L interface, if that provider +supports importing key material. + +=head2 Functions + +EVP_PKEY_asn1_new() creates and returns a new B +object, and associates the given B, B, B and +B. +B is a NID, B is the PEM type string, B is a +descriptive string. +The following B are supported: + + ASN1_PKEY_SIGPARAM_NULL + +If B is set, then the signature algorithm +parameters are given the type B by default, otherwise +they will be given the type B (i.e. the parameter is +omitted). +See L for more information. + +EVP_PKEY_asn1_copy() copies an B object from +B to B. +This function is not thread safe, it's recommended to only use this +when initializing the application. + +EVP_PKEY_asn1_free() frees an existing B pointed +by B. If the argument is NULL, nothing is done. + +EVP_PKEY_asn1_add0() adds B to the user defined stack of +methods unless another B with the same NID is +already there. +This function is not thread safe, it's recommended to only use this +when initializing the application. + +EVP_PKEY_asn1_add_alias() creates an alias with the NID B for the +B with NID B unless another +B with the same NID is already added. +This function is not thread safe, it's recommended to only use this +when initializing the application. + +EVP_PKEY_asn1_set_public(), EVP_PKEY_asn1_set_private(), +EVP_PKEY_asn1_set_param(), EVP_PKEY_asn1_set_free(), +EVP_PKEY_asn1_set_ctrl(), EVP_PKEY_asn1_set_item(), +EVP_PKEY_asn1_set_siginf(), EVP_PKEY_asn1_set_check(), +EVP_PKEY_asn1_set_public_check(), EVP_PKEY_asn1_set_param_check(), +EVP_PKEY_asn1_set_security_bits(), EVP_PKEY_asn1_set_set_priv_key(), +EVP_PKEY_asn1_set_set_pub_key(), EVP_PKEY_asn1_set_get_priv_key() and +EVP_PKEY_asn1_set_get_pub_key() set the diverse methods of the given +B object. + +EVP_PKEY_get0_asn1() finds the B associated +with the key B. + +=head1 RETURN VALUES + +EVP_PKEY_asn1_new() returns NULL on error, or a pointer to an +B object otherwise. + +EVP_PKEY_asn1_add0() and EVP_PKEY_asn1_add_alias() return 0 on error, +or 1 on success. + +EVP_PKEY_get0_asn1() returns NULL on error, or a pointer to a constant +B object otherwise. + +=head1 HISTORY + +The signature of the I functional argument of +EVP_PKEY_asn1_set_public() has changed in OpenSSL 3.0 so its I +parameter is now constified. + +All of these functions were deprecated in OpenSSL 3.6. + +=head1 COPYRIGHT + +Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved. + +Licensed under the Apache License 2.0 (the "License"). You may not use +this file except in compliance with the License. You can obtain a copy +in the file LICENSE in the source distribution or at +L. + +=cut diff --git a/doc/man3/EVP_PKEY_CTX_new.pod b/doc/man3/EVP_PKEY_CTX_new.pod index 9ded13de5d..fff102a769 100644 --- a/doc/man3/EVP_PKEY_CTX_new.pod +++ b/doc/man3/EVP_PKEY_CTX_new.pod @@ -48,9 +48,6 @@ EVP_PKEY_CTX_new_id() and EVP_PKEY_CTX_new_from_name() are normally used when no B structure is associated with the operations, for example during parameter generation or key generation for some algorithms. -The key returned by L is not associated with the -generation context. To perform operations using that key, create a new context -with L. EVP_PKEY_CTX_dup() duplicates the context I. It is not supported for a keygen operation. @@ -128,7 +125,7 @@ added in OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/EVP_PKEY_asn1_get_count.pod b/doc/man3/EVP_PKEY_asn1_get_count.pod new file mode 100644 index 0000000000..f367c74b04 --- /dev/null +++ b/doc/man3/EVP_PKEY_asn1_get_count.pod @@ -0,0 +1,85 @@ +=pod + +=head1 NAME + +EVP_PKEY_asn1_find, +EVP_PKEY_asn1_find_str, +EVP_PKEY_asn1_get_count, +EVP_PKEY_asn1_get0, +EVP_PKEY_asn1_get0_info +- enumerate public key ASN.1 methods + +=head1 SYNOPSIS + +The following functions have been deprecated since OpenSSL 3.6, and can be +hidden entirely by defining B with a suitable version value, +see L; use the provider API instead. + + #include + + int EVP_PKEY_asn1_get_count(void); + const EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_get0(int idx); + const EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_find(ENGINE **pe, int type); + const EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_find_str(ENGINE **pe, + const char *str, int len); + int EVP_PKEY_asn1_get0_info(int *ppkey_id, int *pkey_base_id, + int *ppkey_flags, const char **pinfo, + const char **ppem_str, + const EVP_PKEY_ASN1_METHOD *ameth); + +=head1 DESCRIPTION + +EVP_PKEY_asn1_count() returns a count of the number of public key +ASN.1 methods available: it includes standard methods and any methods +added by the application. + +EVP_PKEY_asn1_get0() returns the public key ASN.1 method B. +The value of B must be between zero and EVP_PKEY_asn1_get_count() +- 1. + +EVP_PKEY_asn1_find() looks up the B with NID +B. +If B isn't B, then NULL will be placed at the given address, as +ENGINEs were removed, therefore none can be found. + +EVP_PKEY_asn1_find_str() looks up the B with PEM +type string B. +Just like EVP_PKEY_asn1_find(), if B isn't B, then NULL will be placed +at the given address, as ENGINEs were removed, therefore none can be found. + +EVP_PKEY_asn1_get0_info() returns the public key ID, base public key +ID (both NIDs), any flags, the method description and PEM type string +associated with the public key ASN.1 method B<*ameth>. + +EVP_PKEY_asn1_count(), EVP_PKEY_asn1_get0(), EVP_PKEY_asn1_find() and +EVP_PKEY_asn1_find_str() are not thread safe, but as long as all +B objects are added before the application gets +threaded, using them is safe. See L. + +=head1 RETURN VALUES + +EVP_PKEY_asn1_count() returns the number of available public key methods. + +EVP_PKEY_asn1_get0() return a public key method or B if B is +out of range. + +EVP_PKEY_asn1_get0_info() returns 0 on failure, 1 on success. + +=head1 SEE ALSO + +L, L + +=head1 HISTORY + +These functions were deprecated in OpenSSL 3.6. + +=head1 COPYRIGHT + +Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved. + +Licensed under the Apache License 2.0 (the "License"). You may not use +this file except in compliance with the License. You can obtain a copy +in the file LICENSE in the source distribution or at +L. + +=cut diff --git a/doc/man3/EVP_PKEY_decrypt.pod b/doc/man3/EVP_PKEY_decrypt.pod index 6b46329793..5e624e8c61 100644 --- a/doc/man3/EVP_PKEY_decrypt.pod +++ b/doc/man3/EVP_PKEY_decrypt.pod @@ -17,13 +17,12 @@ EVP_PKEY_decrypt - decrypt using a public key algorithm =head1 DESCRIPTION -The EVP_PKEY_decrypt_init() function initializes the public key algorithm -context I for a decryption operation. A key must already be associated -with I; this is normally done by creating it with -L or L. +The EVP_PKEY_decrypt_init() function initializes a public key algorithm +context using key I for a decryption operation. -The EVP_PKEY_decrypt_init_ex() function is the same as -EVP_PKEY_decrypt_init() but additionally sets the algorithm-specific I. +The EVP_PKEY_decrypt_init_ex() function initializes a public key algorithm +context using key I for a decryption operation and sets the +algorithm specific I. The EVP_PKEY_decrypt() function performs a public key decryption operation using I. The data to be decrypted is specified using the I and @@ -89,7 +88,7 @@ Decrypt data using OAEP (for RSA keys): * NB: assumes key, in, inlen are already set up * and that key is an RSA private key */ - ctx = EVP_PKEY_CTX_new_from_pkey(NULL, key, NULL); + ctx = EVP_PKEY_CTX_new(key, NULL); if (!ctx) /* Error occurred */ if (EVP_PKEY_decrypt_init(ctx) <= 0) @@ -126,7 +125,7 @@ These functions were added in OpenSSL 1.0.0. =head1 COPYRIGHT -Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/EVP_PKEY_encrypt.pod b/doc/man3/EVP_PKEY_encrypt.pod index fda95c218e..1fb41f99f4 100644 --- a/doc/man3/EVP_PKEY_encrypt.pod +++ b/doc/man3/EVP_PKEY_encrypt.pod @@ -17,13 +17,12 @@ EVP_PKEY_encrypt_init, EVP_PKEY_encrypt - encrypt using a public key algorithm =head1 DESCRIPTION -The EVP_PKEY_encrypt_init() function initializes the public key algorithm -context I for an encryption operation. A key must already be associated -with I; this is normally done by creating it with -L or L. +The EVP_PKEY_encrypt_init() function initializes a public key algorithm +context using key B for an encryption operation. -The EVP_PKEY_encrypt_init_ex() function is the same as -EVP_PKEY_encrypt_init() but additionally sets the algorithm-specific I. +The EVP_PKEY_encrypt_init_ex() function initializes a public key algorithm +context using key B for an encryption operation and sets the +algorithm specific B. The EVP_PKEY_encrypt() function performs a public key encryption operation using B. The data to be encrypted is specified using the B and @@ -67,7 +66,7 @@ L for means to load a public key. * NB: assumes key, in, inlen are already set up, * and that key is an RSA public key */ - ctx = EVP_PKEY_CTX_new_from_pkey(NULL, key, NULL); + ctx = EVP_PKEY_CTX_new(key, NULL); if (!ctx) /* Error occurred */ if (EVP_PKEY_encrypt_init(ctx) <= 0) @@ -105,7 +104,7 @@ These functions were added in OpenSSL 1.0.0. =head1 COPYRIGHT -Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2006-2021 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/EVP_PKEY_fromdata.pod b/doc/man3/EVP_PKEY_fromdata.pod index 44d8788db0..3e3e7dab8b 100644 --- a/doc/man3/EVP_PKEY_fromdata.pod +++ b/doc/man3/EVP_PKEY_fromdata.pod @@ -203,7 +203,7 @@ TODO Write a set of cookbook documents and link to them. EVP_PKEY_free(pkey); EVP_PKEY_CTX_free(ctx); - OSSL_PARAM_clear_free(params); + OSSL_PARAM_free(params); OSSL_PARAM_BLD_free(param_bld); BN_free(priv); diff --git a/doc/man3/EVP_PKEY_get_default_digest_nid.pod b/doc/man3/EVP_PKEY_get_default_digest_nid.pod index 3a3a03f56a..726d129b52 100644 --- a/doc/man3/EVP_PKEY_get_default_digest_nid.pod +++ b/doc/man3/EVP_PKEY_get_default_digest_nid.pod @@ -25,8 +25,9 @@ EVP_PKEY_get_default_digest_nid() sets I to the default message digest NID for the public key signature operations associated with key I. Note that some signature algorithms (i.e. Ed25519 and Ed448) do not use a digest during signing. In this case I will be set -to NID_undef. This function is only reliable for legacy keys; these keys have -typically been created with L or similar. +to NID_undef. This function is only reliable for legacy keys, which +are keys with a B; these keys have typically +been created with L or similar. =head1 NOTES @@ -55,7 +56,7 @@ This function was added in OpenSSL 1.0.0. =head1 COPYRIGHT -Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2006-2023 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/EVP_PKEY_get_size.pod b/doc/man3/EVP_PKEY_get_size.pod index f7ec7c5f84..0c49d65be0 100644 --- a/doc/man3/EVP_PKEY_get_size.pod +++ b/doc/man3/EVP_PKEY_get_size.pod @@ -40,61 +40,7 @@ receive that length), to avoid bugs. EVP_PKEY_get_bits() returns the cryptographic length of the cryptosystem to which the key in I belongs, in bits. Note that the definition -of cryptographic length is specific to the key cryptosystem: - -=over 4 - -=item B - -The bit length of the modulus B. - -=item B - -The bit length of the prime B

. - -=item B - -The bit length of the prime B

. - -=item B - -The bit length of the group order. - -=item B - -253 (fixed for the curve). - -=item B - -448 (fixed for the curve). - -=item B - -256 (fixed for the curve). - -=item B - -456 (fixed for the curve). - -=item B - -The bit size of the public key (8 times the public key length in bytes). -For B, B, and B, this is 10496, 15616, and -20736 bits respectively. - -=item B - -The bit size of the public key (8 times the public key length in bytes). -For B, B, and B variants, this is -256, 384, and 512 bits respectively. - -=item B - -The security strength indicator from the algorithm name: 512, 768, or 1024 -for B, B, and B respectively. - -=back - +of cryptographic length is specific to the key cryptosystem. This length corresponds to the provider parameter B. EVP_PKEY_get_security_bits() returns the number of security bits of the given @@ -108,24 +54,6 @@ The post-quantum security category is an integer value from 0 to 5 that is based on an algorithm's classification on the range of security strengths offered by the existing standards in symmetric cryptography: -=begin man - -.TS H -box,center; -cb lb -c l. -Security Category Attack Type -_ -0 Weak -1 Key search on a block cipher with a 128-bit key -2 Collision search on a 256-bit hash function -3 Key search on a block cipher with a 192-bit key -4 Collision search on a 384-bit hash function -5 Key search on a block cipher with a 256-bit key -.TE - -=end man - =begin text Security Attack diff --git a/doc/man3/EVP_PKEY_keygen.pod b/doc/man3/EVP_PKEY_keygen.pod index 71daed31c0..82bfa5cad6 100644 --- a/doc/man3/EVP_PKEY_keygen.pod +++ b/doc/man3/EVP_PKEY_keygen.pod @@ -66,12 +66,6 @@ parameters or key are written to I<*ppkey>. If I<*ppkey> is NULL when this function is called, it will be allocated, and should be freed by the caller when no longer useful, using L. -When a key is generated, EVP_PKEY_generate() does not associate it with I -or change I into a context for operations using that key. To use the -generated key, create a new context with L, -passing I<*ppkey>. The generation context can be reused for further generation -operations or freed. - EVP_PKEY_paramgen() and EVP_PKEY_keygen() do exactly the same thing as EVP_PKEY_generate(), after checking that the corresponding EVP_PKEY_paramgen_init() or EVP_PKEY_keygen_init() was used to initialize I. @@ -92,12 +86,10 @@ If the callback returns 0 then the key generation operation is aborted and an error occurs. This might occur during a time consuming operation where a user clicks on a "cancel" button. -The functions EVP_PKEY_CTX_set_app_data() and EVP_PKEY_CTX_get_app_data() -associate an opaque, application-defined pointer with an EVP_PKEY_CTX object. - -This pointer is not interpreted by the library and is reserved entirely for use -by the application. It may be used to store arbitrary context or state that -needs to be accessible wherever the corresponding EVP_PKEY_CTX is available. +The functions EVP_PKEY_CTX_set_app_data() and EVP_PKEY_CTX_get_app_data() set +and retrieve an opaque pointer. This can be used to set some application +defined value which can be retrieved in the callback: for example a handle +which is used to update a "progress dialog". EVP_PKEY_Q_keygen() abstracts from the explicit use of B while providing a 'quick' but limited way of generating a new asymmetric key pair. @@ -159,7 +151,7 @@ in functions which require the use of a public key or parameters. =head1 EXAMPLES -Generate a 2048 bit RSA key, then initialize a context for encryption: +Generate a 2048 bit RSA key: #include #include @@ -167,7 +159,7 @@ Generate a 2048 bit RSA key, then initialize a context for encryption: EVP_PKEY_CTX *ctx; EVP_PKEY *pkey = NULL; - ctx = EVP_PKEY_CTX_new_from_name(NULL, "RSA", NULL); + ctx = EVP_PKEY_CTX_new_id(EVP_PKEY_RSA, NULL); if (!ctx) /* Error occurred */ if (EVP_PKEY_keygen_init(ctx) <= 0) @@ -176,15 +168,7 @@ Generate a 2048 bit RSA key, then initialize a context for encryption: /* Error */ /* Generate key */ - if (EVP_PKEY_generate(ctx, &pkey) <= 0) - /* Error */ - - /* ctx is still a generation context; pkey contains the generated key */ - EVP_PKEY_CTX_free(ctx); - ctx = EVP_PKEY_CTX_new_from_pkey(NULL, pkey, NULL); - if (!ctx) - /* Error occurred */ - if (EVP_PKEY_encrypt_init(ctx) <= 0) + if (EVP_PKEY_keygen(ctx, &pkey) <= 0) /* Error */ Generate a key from a set of parameters: @@ -254,7 +238,7 @@ EVP_PKEY_Q_keygen() and EVP_PKEY_generate() were added in OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/EVP_PKEY_meth_get_count.pod b/doc/man3/EVP_PKEY_meth_get_count.pod new file mode 100644 index 0000000000..4950a58b24 --- /dev/null +++ b/doc/man3/EVP_PKEY_meth_get_count.pod @@ -0,0 +1,61 @@ +=pod + +=head1 NAME + +EVP_PKEY_meth_get_count, EVP_PKEY_meth_get0, EVP_PKEY_meth_get0_info - enumerate public key methods + +=head1 SYNOPSIS + + #include + +The following functions have been deprecated since OpenSSL 3.0, and can be +hidden entirely by defining B with a suitable version value, +see L: + + size_t EVP_PKEY_meth_get_count(void); + const EVP_PKEY_METHOD *EVP_PKEY_meth_get0(size_t idx); + void EVP_PKEY_meth_get0_info(int *ppkey_id, int *pflags, + const EVP_PKEY_METHOD *meth); + +=head1 DESCRIPTION + +All of the functions described on this page are deprecated. +Applications should instead use the OSSL_PROVIDER APIs. + +EVP_PKEY_meth_count() returns a count of the number of public key methods +available: it includes standard methods and any methods added by the +application. + +EVP_PKEY_meth_get0() returns the public key method B. The value of B +must be between zero and EVP_PKEY_meth_get_count() - 1. + +EVP_PKEY_meth_get0_info() returns the public key ID (a NID) and any flags +associated with the public key method B<*meth>. + +=head1 RETURN VALUES + +EVP_PKEY_meth_count() returns the number of available public key methods. + +EVP_PKEY_meth_get0() return a public key method or B if B is +out of range. + +EVP_PKEY_meth_get0_info() does not return a value. + +=head1 SEE ALSO + +L + +=head1 HISTORY + +All of these functions were deprecated in OpenSSL 3.0. + +=head1 COPYRIGHT + +Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved. + +Licensed under the Apache License 2.0 (the "License"). You may not use +this file except in compliance with the License. You can obtain a copy +in the file LICENSE in the source distribution or at +L. + +=cut diff --git a/doc/man3/EVP_PKEY_meth_new.pod b/doc/man3/EVP_PKEY_meth_new.pod new file mode 100644 index 0000000000..1b0adb2913 --- /dev/null +++ b/doc/man3/EVP_PKEY_meth_new.pod @@ -0,0 +1,466 @@ +=pod + +=head1 NAME + +EVP_PKEY_meth_new, EVP_PKEY_meth_free, EVP_PKEY_meth_copy, EVP_PKEY_meth_find, +EVP_PKEY_meth_add0, EVP_PKEY_METHOD, +EVP_PKEY_meth_set_init, EVP_PKEY_meth_set_copy, EVP_PKEY_meth_set_cleanup, +EVP_PKEY_meth_set_paramgen, EVP_PKEY_meth_set_keygen, EVP_PKEY_meth_set_sign, +EVP_PKEY_meth_set_verify, EVP_PKEY_meth_set_verify_recover, EVP_PKEY_meth_set_signctx, +EVP_PKEY_meth_set_verifyctx, EVP_PKEY_meth_set_encrypt, EVP_PKEY_meth_set_decrypt, +EVP_PKEY_meth_set_derive, EVP_PKEY_meth_set_ctrl, +EVP_PKEY_meth_set_digestsign, EVP_PKEY_meth_set_digestverify, +EVP_PKEY_meth_set_check, +EVP_PKEY_meth_set_public_check, EVP_PKEY_meth_set_param_check, +EVP_PKEY_meth_set_digest_custom, +EVP_PKEY_meth_get_init, EVP_PKEY_meth_get_copy, EVP_PKEY_meth_get_cleanup, +EVP_PKEY_meth_get_paramgen, EVP_PKEY_meth_get_keygen, EVP_PKEY_meth_get_sign, +EVP_PKEY_meth_get_verify, EVP_PKEY_meth_get_verify_recover, EVP_PKEY_meth_get_signctx, +EVP_PKEY_meth_get_verifyctx, EVP_PKEY_meth_get_encrypt, EVP_PKEY_meth_get_decrypt, +EVP_PKEY_meth_get_derive, EVP_PKEY_meth_get_ctrl, +EVP_PKEY_meth_get_digestsign, EVP_PKEY_meth_get_digestverify, +EVP_PKEY_meth_get_check, +EVP_PKEY_meth_get_public_check, EVP_PKEY_meth_get_param_check, +EVP_PKEY_meth_get_digest_custom, +EVP_PKEY_meth_remove +- manipulating EVP_PKEY_METHOD structure + +=head1 SYNOPSIS + + #include + +The following functions have been deprecated since OpenSSL 3.0, and can be +hidden entirely by defining B with a suitable version value, +see L: + + typedef struct evp_pkey_method_st EVP_PKEY_METHOD; + + EVP_PKEY_METHOD *EVP_PKEY_meth_new(int id, int flags); + void EVP_PKEY_meth_free(EVP_PKEY_METHOD *pmeth); + void EVP_PKEY_meth_copy(EVP_PKEY_METHOD *dst, const EVP_PKEY_METHOD *src); + const EVP_PKEY_METHOD *EVP_PKEY_meth_find(int type); + int EVP_PKEY_meth_add0(const EVP_PKEY_METHOD *pmeth); + int EVP_PKEY_meth_remove(const EVP_PKEY_METHOD *pmeth); + + void EVP_PKEY_meth_set_init(EVP_PKEY_METHOD *pmeth, + int (*init) (EVP_PKEY_CTX *ctx)); + void EVP_PKEY_meth_set_copy(EVP_PKEY_METHOD *pmeth, + int (*copy) (EVP_PKEY_CTX *dst, + const EVP_PKEY_CTX *src)); + void EVP_PKEY_meth_set_cleanup(EVP_PKEY_METHOD *pmeth, + void (*cleanup) (EVP_PKEY_CTX *ctx)); + void EVP_PKEY_meth_set_paramgen(EVP_PKEY_METHOD *pmeth, + int (*paramgen_init) (EVP_PKEY_CTX *ctx), + int (*paramgen) (EVP_PKEY_CTX *ctx, + EVP_PKEY *pkey)); + void EVP_PKEY_meth_set_keygen(EVP_PKEY_METHOD *pmeth, + int (*keygen_init) (EVP_PKEY_CTX *ctx), + int (*keygen) (EVP_PKEY_CTX *ctx, + EVP_PKEY *pkey)); + void EVP_PKEY_meth_set_sign(EVP_PKEY_METHOD *pmeth, + int (*sign_init) (EVP_PKEY_CTX *ctx), + int (*sign) (EVP_PKEY_CTX *ctx, + unsigned char *sig, size_t *siglen, + const unsigned char *tbs, + size_t tbslen)); + void EVP_PKEY_meth_set_verify(EVP_PKEY_METHOD *pmeth, + int (*verify_init) (EVP_PKEY_CTX *ctx), + int (*verify) (EVP_PKEY_CTX *ctx, + const unsigned char *sig, + size_t siglen, + const unsigned char *tbs, + size_t tbslen)); + void EVP_PKEY_meth_set_verify_recover(EVP_PKEY_METHOD *pmeth, + int (*verify_recover_init) (EVP_PKEY_CTX + *ctx), + int (*verify_recover) (EVP_PKEY_CTX + *ctx, + unsigned char + *sig, + size_t *siglen, + const unsigned + char *tbs, + size_t tbslen)); + void EVP_PKEY_meth_set_signctx(EVP_PKEY_METHOD *pmeth, + int (*signctx_init) (EVP_PKEY_CTX *ctx, + EVP_MD_CTX *mctx), + int (*signctx) (EVP_PKEY_CTX *ctx, + unsigned char *sig, + size_t *siglen, + EVP_MD_CTX *mctx)); + void EVP_PKEY_meth_set_verifyctx(EVP_PKEY_METHOD *pmeth, + int (*verifyctx_init) (EVP_PKEY_CTX *ctx, + EVP_MD_CTX *mctx), + int (*verifyctx) (EVP_PKEY_CTX *ctx, + const unsigned char *sig, + int siglen, + EVP_MD_CTX *mctx)); + void EVP_PKEY_meth_set_encrypt(EVP_PKEY_METHOD *pmeth, + int (*encrypt_init) (EVP_PKEY_CTX *ctx), + int (*encryptfn) (EVP_PKEY_CTX *ctx, + unsigned char *out, + size_t *outlen, + const unsigned char *in, + size_t inlen)); + void EVP_PKEY_meth_set_decrypt(EVP_PKEY_METHOD *pmeth, + int (*decrypt_init) (EVP_PKEY_CTX *ctx), + int (*decrypt) (EVP_PKEY_CTX *ctx, + unsigned char *out, + size_t *outlen, + const unsigned char *in, + size_t inlen)); + void EVP_PKEY_meth_set_derive(EVP_PKEY_METHOD *pmeth, + int (*derive_init) (EVP_PKEY_CTX *ctx), + int (*derive) (EVP_PKEY_CTX *ctx, + unsigned char *key, + size_t *keylen)); + void EVP_PKEY_meth_set_ctrl(EVP_PKEY_METHOD *pmeth, + int (*ctrl) (EVP_PKEY_CTX *ctx, int type, int p1, + void *p2), + int (*ctrl_str) (EVP_PKEY_CTX *ctx, + const char *type, + const char *value)); + void EVP_PKEY_meth_set_digestsign(EVP_PKEY_METHOD *pmeth, + int (*digestsign) (EVP_MD_CTX *ctx, + unsigned char *sig, + size_t *siglen, + const unsigned char *tbs, + size_t tbslen)); + void EVP_PKEY_meth_set_digestverify(EVP_PKEY_METHOD *pmeth, + int (*digestverify) (EVP_MD_CTX *ctx, + const unsigned char *sig, + size_t siglen, + const unsigned char *tbs, + size_t tbslen)); + void EVP_PKEY_meth_set_check(EVP_PKEY_METHOD *pmeth, + int (*check) (EVP_PKEY *pkey)); + void EVP_PKEY_meth_set_public_check(EVP_PKEY_METHOD *pmeth, + int (*check) (EVP_PKEY *pkey)); + void EVP_PKEY_meth_set_param_check(EVP_PKEY_METHOD *pmeth, + int (*check) (EVP_PKEY *pkey)); + void EVP_PKEY_meth_set_digest_custom(EVP_PKEY_METHOD *pmeth, + int (*digest_custom) (EVP_PKEY_CTX *ctx, + EVP_MD_CTX *mctx)); + + void EVP_PKEY_meth_get_init(const EVP_PKEY_METHOD *pmeth, + int (**pinit) (EVP_PKEY_CTX *ctx)); + void EVP_PKEY_meth_get_copy(const EVP_PKEY_METHOD *pmeth, + int (**pcopy) (EVP_PKEY_CTX *dst, + EVP_PKEY_CTX *src)); + void EVP_PKEY_meth_get_cleanup(const EVP_PKEY_METHOD *pmeth, + void (**pcleanup) (EVP_PKEY_CTX *ctx)); + void EVP_PKEY_meth_get_paramgen(const EVP_PKEY_METHOD *pmeth, + int (**pparamgen_init) (EVP_PKEY_CTX *ctx), + int (**pparamgen) (EVP_PKEY_CTX *ctx, + EVP_PKEY *pkey)); + void EVP_PKEY_meth_get_keygen(const EVP_PKEY_METHOD *pmeth, + int (**pkeygen_init) (EVP_PKEY_CTX *ctx), + int (**pkeygen) (EVP_PKEY_CTX *ctx, + EVP_PKEY *pkey)); + void EVP_PKEY_meth_get_sign(const EVP_PKEY_METHOD *pmeth, + int (**psign_init) (EVP_PKEY_CTX *ctx), + int (**psign) (EVP_PKEY_CTX *ctx, + unsigned char *sig, size_t *siglen, + const unsigned char *tbs, + size_t tbslen)); + void EVP_PKEY_meth_get_verify(const EVP_PKEY_METHOD *pmeth, + int (**pverify_init) (EVP_PKEY_CTX *ctx), + int (**pverify) (EVP_PKEY_CTX *ctx, + const unsigned char *sig, + size_t siglen, + const unsigned char *tbs, + size_t tbslen)); + void EVP_PKEY_meth_get_verify_recover(const EVP_PKEY_METHOD *pmeth, + int (**pverify_recover_init) (EVP_PKEY_CTX + *ctx), + int (**pverify_recover) (EVP_PKEY_CTX + *ctx, + unsigned char + *sig, + size_t *siglen, + const unsigned + char *tbs, + size_t tbslen)); + void EVP_PKEY_meth_get_signctx(const EVP_PKEY_METHOD *pmeth, + int (**psignctx_init) (EVP_PKEY_CTX *ctx, + EVP_MD_CTX *mctx), + int (**psignctx) (EVP_PKEY_CTX *ctx, + unsigned char *sig, + size_t *siglen, + EVP_MD_CTX *mctx)); + void EVP_PKEY_meth_get_verifyctx(const EVP_PKEY_METHOD *pmeth, + int (**pverifyctx_init) (EVP_PKEY_CTX *ctx, + EVP_MD_CTX *mctx), + int (**pverifyctx) (EVP_PKEY_CTX *ctx, + const unsigned char *sig, + int siglen, + EVP_MD_CTX *mctx)); + void EVP_PKEY_meth_get_encrypt(const EVP_PKEY_METHOD *pmeth, + int (**pencrypt_init) (EVP_PKEY_CTX *ctx), + int (**pencryptfn) (EVP_PKEY_CTX *ctx, + unsigned char *out, + size_t *outlen, + const unsigned char *in, + size_t inlen)); + void EVP_PKEY_meth_get_decrypt(const EVP_PKEY_METHOD *pmeth, + int (**pdecrypt_init) (EVP_PKEY_CTX *ctx), + int (**pdecrypt) (EVP_PKEY_CTX *ctx, + unsigned char *out, + size_t *outlen, + const unsigned char *in, + size_t inlen)); + void EVP_PKEY_meth_get_derive(const EVP_PKEY_METHOD *pmeth, + int (**pderive_init) (EVP_PKEY_CTX *ctx), + int (**pderive) (EVP_PKEY_CTX *ctx, + unsigned char *key, + size_t *keylen)); + void EVP_PKEY_meth_get_ctrl(const EVP_PKEY_METHOD *pmeth, + int (**pctrl) (EVP_PKEY_CTX *ctx, int type, int p1, + void *p2), + int (**pctrl_str) (EVP_PKEY_CTX *ctx, + const char *type, + const char *value)); + void EVP_PKEY_meth_get_digestsign(const EVP_PKEY_METHOD *pmeth, + int (**digestsign) (EVP_MD_CTX *ctx, + unsigned char *sig, + size_t *siglen, + const unsigned char *tbs, + size_t tbslen)); + void EVP_PKEY_meth_get_digestverify(const EVP_PKEY_METHOD *pmeth, + int (**digestverify) (EVP_MD_CTX *ctx, + const unsigned char *sig, + size_t siglen, + const unsigned char *tbs, + size_t tbslen)); + void EVP_PKEY_meth_get_check(const EVP_PKEY_METHOD *pmeth, + int (**pcheck) (EVP_PKEY *pkey)); + void EVP_PKEY_meth_get_public_check(const EVP_PKEY_METHOD *pmeth, + int (**pcheck) (EVP_PKEY *pkey)); + void EVP_PKEY_meth_get_param_check(const EVP_PKEY_METHOD *pmeth, + int (**pcheck) (EVP_PKEY *pkey)); + void EVP_PKEY_meth_get_digest_custom(const EVP_PKEY_METHOD *pmeth, + int (**pdigest_custom) (EVP_PKEY_CTX *ctx, + EVP_MD_CTX *mctx)); + +=head1 DESCRIPTION + +All of the functions described on this page are deprecated. +Applications should instead use the OSSL_PROVIDER APIs. + +B is a structure which holds a set of methods for a +specific public key cryptographic algorithm. Those methods are usually +used to perform different jobs, such as generating a key, signing or +verifying, encrypting or decrypting, etc. + +There are two places where the B objects are stored: one +is a built-in static array representing the standard methods for different +algorithms, and the other one is a stack of user-defined application-specific +methods, which can be manipulated by using L. + +The B objects are usually referenced by B +objects. + +=head2 Methods + +The methods are the underlying implementations of a particular public key +algorithm present by the B object. + + int (*init) (EVP_PKEY_CTX *ctx); + int (*copy) (EVP_PKEY_CTX *dst, const EVP_PKEY_CTX *src); + void (*cleanup) (EVP_PKEY_CTX *ctx); + +The init() method is called to initialize algorithm-specific data when a new +B is created. As opposed to init(), the cleanup() method is called +when an B is freed. The copy() method is called when an B +is being duplicated. Refer to L, L, +L and L. + + int (*paramgen_init) (EVP_PKEY_CTX *ctx); + int (*paramgen) (EVP_PKEY_CTX *ctx, EVP_PKEY *pkey); + +The paramgen_init() and paramgen() methods deal with key parameter generation. +They are called by L and L to +handle the parameter generation process. + + int (*keygen_init) (EVP_PKEY_CTX *ctx); + int (*keygen) (EVP_PKEY_CTX *ctx, EVP_PKEY *pkey); + +The keygen_init() and keygen() methods are used to generate the actual key for +the specified algorithm. They are called by L and +L. + + int (*sign_init) (EVP_PKEY_CTX *ctx); + int (*sign) (EVP_PKEY_CTX *ctx, unsigned char *sig, size_t *siglen, + const unsigned char *tbs, size_t tbslen); + +The sign_init() and sign() methods are used to generate the signature of a +piece of data using a private key. They are called by L +and L. + + int (*verify_init) (EVP_PKEY_CTX *ctx); + int (*verify) (EVP_PKEY_CTX *ctx, + const unsigned char *sig, size_t siglen, + const unsigned char *tbs, size_t tbslen); + +The verify_init() and verify() methods are used to verify whether a signature is +valid. They are called by L and L. + + int (*verify_recover_init) (EVP_PKEY_CTX *ctx); + int (*verify_recover) (EVP_PKEY_CTX *ctx, + unsigned char *rout, size_t *routlen, + const unsigned char *sig, size_t siglen); + +The verify_recover_init() and verify_recover() methods are used to verify a +signature and then recover the digest from the signature (for instance, a +signature that was generated by RSA signing algorithm). They are called by +L and L. + + int (*signctx_init) (EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx); + int (*signctx) (EVP_PKEY_CTX *ctx, unsigned char *sig, size_t *siglen, + EVP_MD_CTX *mctx); + +The signctx_init() and signctx() methods are used to sign a digest present by +a B object. They are called by the EVP_DigestSign functions. See +L for details. + + int (*verifyctx_init) (EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx); + int (*verifyctx) (EVP_PKEY_CTX *ctx, const unsigned char *sig, int siglen, + EVP_MD_CTX *mctx); + +The verifyctx_init() and verifyctx() methods are used to verify a signature +against the data in a B object. They are called by the various +EVP_DigestVerify functions. See L for details. + + int (*encrypt_init) (EVP_PKEY_CTX *ctx); + int (*encrypt) (EVP_PKEY_CTX *ctx, unsigned char *out, size_t *outlen, + const unsigned char *in, size_t inlen); + +The encrypt_init() and encrypt() methods are used to encrypt a piece of data. +They are called by L and L. + + int (*decrypt_init) (EVP_PKEY_CTX *ctx); + int (*decrypt) (EVP_PKEY_CTX *ctx, unsigned char *out, size_t *outlen, + const unsigned char *in, size_t inlen); + +The decrypt_init() and decrypt() methods are used to decrypt a piece of data. +They are called by L and L. + + int (*derive_init) (EVP_PKEY_CTX *ctx); + int (*derive) (EVP_PKEY_CTX *ctx, unsigned char *key, size_t *keylen); + +The derive_init() and derive() methods are used to derive the shared secret +from a public key algorithm (for instance, the DH algorithm). They are called by +L and L. + + int (*ctrl) (EVP_PKEY_CTX *ctx, int type, int p1, void *p2); + int (*ctrl_str) (EVP_PKEY_CTX *ctx, const char *type, const char *value); + +The ctrl() and ctrl_str() methods are used to adjust algorithm-specific +settings. See L and related functions for details. + + int (*digestsign) (EVP_MD_CTX *ctx, unsigned char *sig, size_t *siglen, + const unsigned char *tbs, size_t tbslen); + int (*digestverify) (EVP_MD_CTX *ctx, const unsigned char *sig, + size_t siglen, const unsigned char *tbs, + size_t tbslen); + +The digestsign() and digestverify() methods are used to generate or verify +a signature in a one-shot mode. They could be called by L +and L. + + int (*check) (EVP_PKEY *pkey); + int (*public_check) (EVP_PKEY *pkey); + int (*param_check) (EVP_PKEY *pkey); + +The check(), public_check() and param_check() methods are used to validate a +key-pair, the public component and parameters respectively for a given B. +They could be called by L, L and +L respectively. + + int (*digest_custom) (EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx); + +The digest_custom() method is used to generate customized digest content before +the real message is passed to functions like L or +L. This is usually required by some public key +signature algorithms like SM2 which requires a hashed prefix to the message to +be signed. The digest_custom() function will be called by L +and L. + +=head2 Functions + +EVP_PKEY_meth_new() creates and returns a new B object, +and associates the given B and B. The following flags are +supported: + + EVP_PKEY_FLAG_AUTOARGLEN + EVP_PKEY_FLAG_SIGCTX_CUSTOM + +If an B is set with the B flag, the +maximum size of the output buffer will be automatically calculated or checked +in corresponding EVP methods by the EVP framework. Thus the implementations of +these methods don't need to care about handling the case of returning output +buffer size by themselves. For details on the output buffer size, refer to +L. + +The B is used to indicate the signctx() method +of an B is always called by the EVP framework while doing a +digest signing operation by calling L. + +EVP_PKEY_meth_free() frees an existing B pointed by +B. If the argument is NULL, nothing is done. + +EVP_PKEY_meth_copy() copies an B object from B +to B. + +EVP_PKEY_meth_find() finds an B object with the B. +This function first searches through the user-defined method objects and +then the built-in objects. + +EVP_PKEY_meth_add0() adds B to the user defined stack of methods. + +EVP_PKEY_meth_remove() removes an B object added by +EVP_PKEY_meth_add0(). + +The EVP_PKEY_meth_set functions set the corresponding fields of +B structure with the arguments passed. + +The EVP_PKEY_meth_get functions get the corresponding fields of +B structure to the arguments provided. + +=head1 RETURN VALUES + +EVP_PKEY_meth_new() returns a pointer to a new B +object or returns NULL on error. + +EVP_PKEY_meth_free() and EVP_PKEY_meth_copy() do not return values. + +EVP_PKEY_meth_find() returns a pointer to the found B +object or returns NULL if not found. + +EVP_PKEY_meth_add0() returns 1 if method is added successfully or 0 +if an error occurred. + +EVP_PKEY_meth_remove() returns 1 if method is removed successfully or +0 if an error occurred. + +All EVP_PKEY_meth_set and EVP_PKEY_meth_get functions have no return +values. For the 'get' functions, function pointers are returned by +arguments. + +=head1 HISTORY + +All of these functions were deprecated in OpenSSL 3.0. + +The signature of the I functional argument of EVP_PKEY_meth_set_copy() +has changed in OpenSSL 3.0 so its I parameter is now constified. + +=head1 COPYRIGHT + +Copyright 2017-2024 The OpenSSL Project Authors. All Rights Reserved. + +Licensed under the Apache License 2.0 (the "License"). You may not use +this file except in compliance with the License. You can obtain a copy +in the file LICENSE in the source distribution or at +L. + +=cut diff --git a/doc/man3/EVP_PKEY_set_type.pod b/doc/man3/EVP_PKEY_set_type.pod index ff53ac399e..5a326df012 100644 --- a/doc/man3/EVP_PKEY_set_type.pod +++ b/doc/man3/EVP_PKEY_set_type.pod @@ -22,15 +22,21 @@ I is NULL, these functions will still return the same return values as if it wasn't. EVP_PKEY_set_type() initialises I to contain an internal legacy -key. It is an error if no legacy implementations could be found for +key. When doing this, it finds a L +corresponding to I, and associates I with the findings. +It is an error if no L could be found for I. EVP_PKEY_set_type_str() initialises I to contain an internal legacy -key. It is an error if no legacy implementation could be found for I. +key. When doing this, it finds a L +corresponding to I that has then length I, and associates +I with the findings. +It is an error if no L could be found for +I. For both EVP_PKEY_set_type() and EVP_PKEY_set_type_str(), I gets a numeric type, which can be retrieved with L. This -numeric type is taken from the internal legacy implementation that was +numeric type is taken from the L that was found, and is equal to or closely related to I in the case of EVP_PKEY_set_type(), or related to I in the case of EVP_PKEY_set_type_str(). @@ -47,12 +53,12 @@ All functions described here return 1 if successful, or 0 on error. =head1 SEE ALSO L, L, L, -L, +L, L, L =head1 COPYRIGHT -Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/EVP_PKEY_todata.pod b/doc/man3/EVP_PKEY_todata.pod index d3455ce1bd..8e54f228ac 100644 --- a/doc/man3/EVP_PKEY_todata.pod +++ b/doc/man3/EVP_PKEY_todata.pod @@ -20,8 +20,8 @@ array of L. EVP_PKEY_todata() extracts values from a key I using the I. I is described in L. -L or L should be used to free the -returned parameters in I<*params>. +L should be used to free the returned parameters in +I<*params>. EVP_PKEY_export() is similar to EVP_PKEY_todata() but uses a callback I that gets passed the value of I. diff --git a/doc/man3/EVP_PKEY_verify_recover.pod b/doc/man3/EVP_PKEY_verify_recover.pod index 52682f2aa5..10084d61c1 100644 --- a/doc/man3/EVP_PKEY_verify_recover.pod +++ b/doc/man3/EVP_PKEY_verify_recover.pod @@ -22,10 +22,10 @@ EVP_PKEY_verify_recover_init_ex2, EVP_PKEY_verify_recover =head1 DESCRIPTION EVP_PKEY_verify_recover_init() initializes a public key algorithm context -I for a verify-recover operation using the algorithm given when the -context was created using L or variants thereof. The -algorithm is used to fetch a B method implicitly, see -L for more information about implicit fetches. +I for signing using the algorithm given when the context was created +using L or variants thereof. The algorithm is used to +fetch a B method implicitly, see L +for more information about implicit fetches. EVP_PKEY_verify_recover_init_ex() is the same as EVP_PKEY_verify_recover_init() but additionally sets the passed parameters @@ -35,8 +35,8 @@ EVP_PKEY_verify_recover_init_ex2() is the same as EVP_PKEY_verify_recover_init_e but works with an explicitly fetched B I. A context I without a pre-loaded key cannot be used with this function. Depending on what algorithm was fetched, certain details revolving around the -treatment of the input to EVP_PKEY_verify_recover() may be pre-determined, and -in that case, those details may normally not be changed. +treatment of the input to EVP_PKEY_verify() may be pre-determined, and in that +case, those details may normally not be changed. See L below for a deeper explanation. The EVP_PKEY_verify_recover() function recovers signed data @@ -132,7 +132,7 @@ The EVP_PKEY_verify_recover_init_ex() function was added in OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2013-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2013-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/EVP_RAND.pod b/doc/man3/EVP_RAND.pod index 3eb5c13d0c..19519d4008 100644 --- a/doc/man3/EVP_RAND.pod +++ b/doc/man3/EVP_RAND.pod @@ -79,7 +79,7 @@ both deterministic and not. If you just want to generate random bytes then you don't need to use these functions: just call RAND_bytes() or RAND_priv_bytes(). If you want to do more, these calls should be used instead of the older -RAND functions. +RAND and RAND_DRBG functions. After creating a B for the required algorithm using EVP_RAND_CTX_new(), inputs to the algorithm are supplied either by @@ -412,7 +412,7 @@ The remaining functions were added in OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/EVP_SKEY.pod b/doc/man3/EVP_SKEY.pod index f45aac10c5..9f013cc8c7 100644 --- a/doc/man3/EVP_SKEY.pod +++ b/doc/man3/EVP_SKEY.pod @@ -20,7 +20,7 @@ EVP_SKEY_get0_provider_name, EVP_SKEY_free, EVP_SKEY_is_a, EVP_SKEY_to_provider const char *propquery, int selection, const OSSL_PARAM *params); EVP_SKEY *EVP_SKEY_import_raw_key(OSSL_LIB_CTX *libctx, const char *skeymgmtname, - unsigned char *key, size_t len, + unsigned char *key, size_t *len, const char *propquery); EVP_SKEY *EVP_SKEY_import_SKEYMGMT(OSSL_LIB_CTX *libctx, EVP_SKEYMGMT *skeymgmt, int selection, const OSSL_PARAM *params); @@ -57,10 +57,8 @@ which is used by OpenSSL to store symmetric keys, assigns the B object associated with the key, and initializes the object from the B argument. -The EVP_SKEY_import_raw_key() function is a helper that creates an B -object containing the raw byte representation of the symmetric keys from the -buffer I having length I. The I defines the name of the -target B for the newly created key. +The EVP_SKEY_import_raw_key() function is a helper that creates an B object +containing the raw byte representation of the symmetric keys. The EVP_SKEY_import_SKEYMGMT() function is a helper that creates an B object containing the representation of the symmetric keys specific to the @@ -162,7 +160,7 @@ The EVP_SKEY_import_SKEYMGMT() function was introduced in OpenSSL 4.0. =head1 COPYRIGHT -Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/EVP_aes_128_gcm.pod b/doc/man3/EVP_aes_128_gcm.pod index 1fc88056a7..707c1bd90b 100644 --- a/doc/man3/EVP_aes_128_gcm.pod +++ b/doc/man3/EVP_aes_128_gcm.pod @@ -173,12 +173,14 @@ See L for further information. =head1 RETURN VALUES These functions return an B structure that contains the -implementation of the symmetric cipher. +implementation of the symmetric cipher. See L for +details of the B structure. =head1 SEE ALSO L, -L +L, +L =head1 COPYRIGHT diff --git a/doc/man3/EVP_aria_128_gcm.pod b/doc/man3/EVP_aria_128_gcm.pod index dd13559741..9a8f9abb76 100644 --- a/doc/man3/EVP_aria_128_gcm.pod +++ b/doc/man3/EVP_aria_128_gcm.pod @@ -102,12 +102,14 @@ See L for further information. =head1 RETURN VALUES These functions return an B structure that contains the -implementation of the symmetric cipher. +implementation of the symmetric cipher. See L for +details of the B structure. =head1 SEE ALSO L, -L +L, +L =head1 COPYRIGHT diff --git a/doc/man3/EVP_bf_cbc.pod b/doc/man3/EVP_bf_cbc.pod index 2eea0d4c3a..11a909207a 100644 --- a/doc/man3/EVP_bf_cbc.pod +++ b/doc/man3/EVP_bf_cbc.pod @@ -47,12 +47,14 @@ See L for further information. =head1 RETURN VALUES These functions return an B structure that contains the -implementation of the symmetric cipher. +implementation of the symmetric cipher. See L for +details of the B structure. =head1 SEE ALSO L, -L +L, +L =head1 COPYRIGHT diff --git a/doc/man3/EVP_blake2b512.pod b/doc/man3/EVP_blake2b512.pod index b28d0fcb66..7bf08f6495 100644 --- a/doc/man3/EVP_blake2b512.pod +++ b/doc/man3/EVP_blake2b512.pod @@ -44,7 +44,8 @@ but this is only available through L. =head1 RETURN VALUES These functions return a B structure that contains the -implementation of the message digest. +implementation of the message digest. See L for +details of the B structure. =head1 CONFORMING TO diff --git a/doc/man3/EVP_camellia_128_ecb.pod b/doc/man3/EVP_camellia_128_ecb.pod index 27b3e37af4..cb6e12e212 100644 --- a/doc/man3/EVP_camellia_128_ecb.pod +++ b/doc/man3/EVP_camellia_128_ecb.pod @@ -85,12 +85,14 @@ See L for further information. =head1 RETURN VALUES These functions return an B structure that contains the -implementation of the symmetric cipher. +implementation of the symmetric cipher. See L for +details of the B structure. =head1 SEE ALSO L, -L +L, +L =head1 COPYRIGHT diff --git a/doc/man3/EVP_cast5_cbc.pod b/doc/man3/EVP_cast5_cbc.pod index 7497d6104b..7fef059815 100644 --- a/doc/man3/EVP_cast5_cbc.pod +++ b/doc/man3/EVP_cast5_cbc.pod @@ -47,12 +47,14 @@ See L for further information. =head1 RETURN VALUES These functions return an B structure that contains the -implementation of the symmetric cipher. +implementation of the symmetric cipher. See L for +details of the B structure. =head1 SEE ALSO L, -L +L, +L =head1 COPYRIGHT diff --git a/doc/man3/EVP_chacha20.pod b/doc/man3/EVP_chacha20.pod index d7766257ff..54fb5a49f8 100644 --- a/doc/man3/EVP_chacha20.pod +++ b/doc/man3/EVP_chacha20.pod @@ -53,12 +53,14 @@ uses a 32 bit counter and a 96 bit nonce for the IV. =head1 RETURN VALUES These functions return an B structure that contains the -implementation of the symmetric cipher. +implementation of the symmetric cipher. See L for +details of the B structure. =head1 SEE ALSO L, -L +L, +L =head1 COPYRIGHT diff --git a/doc/man3/EVP_des_cbc.pod b/doc/man3/EVP_des_cbc.pod index 07725fbb35..442be8993a 100644 --- a/doc/man3/EVP_des_cbc.pod +++ b/doc/man3/EVP_des_cbc.pod @@ -95,12 +95,14 @@ See L for further information. =head1 RETURN VALUES These functions return an B structure that contains the -implementation of the symmetric cipher. +implementation of the symmetric cipher. See L for +details of the B structure. =head1 SEE ALSO L, -L +L, +L =head1 COPYRIGHT diff --git a/doc/man3/EVP_desx_cbc.pod b/doc/man3/EVP_desx_cbc.pod index 5911cec205..c22c0de479 100644 --- a/doc/man3/EVP_desx_cbc.pod +++ b/doc/man3/EVP_desx_cbc.pod @@ -37,12 +37,14 @@ See L for further information. =head1 RETURN VALUES These functions return an B structure that contains the -implementation of the symmetric cipher. +implementation of the symmetric cipher. See L for +details of the B structure. =head1 SEE ALSO L, -L +L, +L =head1 COPYRIGHT diff --git a/doc/man3/EVP_idea_cbc.pod b/doc/man3/EVP_idea_cbc.pod index 7fb5c9b85f..a36aae0bc9 100644 --- a/doc/man3/EVP_idea_cbc.pod +++ b/doc/man3/EVP_idea_cbc.pod @@ -45,12 +45,14 @@ See L for further information. =head1 RETURN VALUES These functions return an B structure that contains the -implementation of the symmetric cipher. +implementation of the symmetric cipher. See L for +details of the B structure. =head1 SEE ALSO L, -L +L, +L =head1 COPYRIGHT diff --git a/doc/man3/EVP_md2.pod b/doc/man3/EVP_md2.pod index cd7d6393cd..a6f3a010de 100644 --- a/doc/man3/EVP_md2.pod +++ b/doc/man3/EVP_md2.pod @@ -34,7 +34,8 @@ See L for further information. =head1 RETURN VALUES These functions return a B structure that contains the -implementation of the message digest. +implementation of the message digest. See L for +details of the B structure. =head1 CONFORMING TO diff --git a/doc/man3/EVP_md4.pod b/doc/man3/EVP_md4.pod index 354da7c6d1..a4e1a7d0a6 100644 --- a/doc/man3/EVP_md4.pod +++ b/doc/man3/EVP_md4.pod @@ -35,7 +35,8 @@ See L for further information. =head1 RETURN VALUES These functions return a B structure that contains the -implementation of the message digest. +implementation of the message digest. See L for +details of the B structure. =head1 CONFORMING TO diff --git a/doc/man3/EVP_md5.pod b/doc/man3/EVP_md5.pod index ff1f217b79..42370fb3d0 100644 --- a/doc/man3/EVP_md5.pod +++ b/doc/man3/EVP_md5.pod @@ -46,7 +46,8 @@ See L for further information. =head1 RETURN VALUES These functions return a B structure that contains the -implementation of the message digest. +implementation of the message digest. See L for +details of the B structure. =head1 CONFORMING TO diff --git a/doc/man3/EVP_mdc2.pod b/doc/man3/EVP_mdc2.pod index 0f111f46e8..3681bd06a6 100644 --- a/doc/man3/EVP_mdc2.pod +++ b/doc/man3/EVP_mdc2.pod @@ -36,7 +36,8 @@ See L for further information. =head1 RETURN VALUES These functions return a B structure that contains the -implementation of the message digest. +implementation of the message digest. See L for +details of the B structure. =head1 CONFORMING TO diff --git a/doc/man3/EVP_rc2_cbc.pod b/doc/man3/EVP_rc2_cbc.pod index 5b431bbbe0..17f6f4b3e2 100644 --- a/doc/man3/EVP_rc2_cbc.pod +++ b/doc/man3/EVP_rc2_cbc.pod @@ -61,12 +61,14 @@ See L for further information. =head1 RETURN VALUES These functions return an B structure that contains the -implementation of the symmetric cipher. +implementation of the symmetric cipher. See L for +details of the B structure. =head1 SEE ALSO L, -L +L, +L =head1 COPYRIGHT diff --git a/doc/man3/EVP_rc4.pod b/doc/man3/EVP_rc4.pod index 024a231e1b..0311ef278c 100644 --- a/doc/man3/EVP_rc4.pod +++ b/doc/man3/EVP_rc4.pod @@ -53,12 +53,14 @@ See L for further information. =head1 RETURN VALUES These functions return an B structure that contains the -implementation of the symmetric cipher. +implementation of the symmetric cipher. See L for +details of the B structure. =head1 SEE ALSO L, -L +L, +L =head1 COPYRIGHT diff --git a/doc/man3/EVP_rc5_32_12_16_cbc.pod b/doc/man3/EVP_rc5_32_12_16_cbc.pod index d6c97aaca9..69fc2f2cc6 100644 --- a/doc/man3/EVP_rc5_32_12_16_cbc.pod +++ b/doc/man3/EVP_rc5_32_12_16_cbc.pod @@ -66,12 +66,15 @@ See L for further information. =head1 RETURN VALUES These functions return an B structure that contains the -implementation of the symmetric cipher. +implementation of the symmetric cipher. See L for +details of the B structure. + =head1 SEE ALSO L, -L +L, +L =head1 COPYRIGHT diff --git a/doc/man3/EVP_ripemd160.pod b/doc/man3/EVP_ripemd160.pod index f29cbf3247..5b96fd09f8 100644 --- a/doc/man3/EVP_ripemd160.pod +++ b/doc/man3/EVP_ripemd160.pod @@ -35,7 +35,8 @@ See L for further information. =head1 RETURN VALUES These functions return a B structure that contains the -implementation of the message digest. +implementation of the message digest. See L for +details of the B structure. =head1 CONFORMING TO diff --git a/doc/man3/EVP_seed_cbc.pod b/doc/man3/EVP_seed_cbc.pod index d81ce36397..2c821d07c3 100644 --- a/doc/man3/EVP_seed_cbc.pod +++ b/doc/man3/EVP_seed_cbc.pod @@ -47,12 +47,14 @@ See L for further information. =head1 RETURN VALUES These functions return an B structure that contains the -implementation of the symmetric cipher. +implementation of the symmetric cipher. See L for +details of the B structure. =head1 SEE ALSO L, -L +L, +L =head1 COPYRIGHT diff --git a/doc/man3/EVP_set_default_properties.pod b/doc/man3/EVP_set_default_properties.pod index 356b590778..0c0f67c7cb 100644 --- a/doc/man3/EVP_set_default_properties.pod +++ b/doc/man3/EVP_set_default_properties.pod @@ -3,8 +3,7 @@ =head1 NAME EVP_set_default_properties, EVP_default_properties_enable_fips, -EVP_default_properties_is_fips_enabled, EVP_get1_default_properties, -FIPS_mode +EVP_default_properties_is_fips_enabled, EVP_get1_default_properties - manage default properties for future algorithm fetches =head1 SYNOPSIS @@ -15,7 +14,6 @@ FIPS_mode char *EVP_get1_default_properties(OSSL_LIB_CTX *libctx); int EVP_default_properties_enable_fips(OSSL_LIB_CTX *libctx, int enable); int EVP_default_properties_is_fips_enabled(OSSL_LIB_CTX *libctx); - #define FIPS_mode() EVP_default_properties_is_fips_enabled(NULL) =head1 DESCRIPTION @@ -53,12 +51,6 @@ EVP_get1_default_properties() is not thread safe. The application must ensure that the context reference is valid and default fetching properties are not being modified by a different thread. -EVP_default_properties_is_fips_enabled() and FIPS_mode() are hints of -intent, but not proof. If you are looking to validate whether the default -configuration is using a validated module, many additional checks are -needed; please consult the documentation of the provider you are using -and the associated security policy. - =head1 RETURN VALUES EVP_set_default_properties() and EVP_default_properties_enable_fips() return 1 @@ -71,10 +63,6 @@ property is set for the given I, otherwise it returns 0. EVP_get1_default_properties() returns allocated memory that must be freed by L on success and NULL on failure. -FIPS_mode() is a convenience define which calls -EVP_default_properties_is_fips_enabled(NULL) against the default -library context. - =head1 SEE ALSO L @@ -86,8 +74,6 @@ EVP_default_properties_is_fips_enabled() were added in OpenSSL 3.0. The function EVP_get1_default_properties() was added in OpenSSL 3.5. -FIPS_mode() is restored as a define to -EVP_default_properties_is_fips_enabled(NULL) in OpenSSL 4.1. =head1 COPYRIGHT diff --git a/doc/man3/EVP_sha1.pod b/doc/man3/EVP_sha1.pod index d9ad72ec3b..6fc8f07b06 100644 --- a/doc/man3/EVP_sha1.pod +++ b/doc/man3/EVP_sha1.pod @@ -35,7 +35,8 @@ See L for further information. =head1 RETURN VALUES These functions return a B structure that contains the -implementation of the message digest. +implementation of the message digest. See L for +details of the B structure. =head1 CONFORMING TO diff --git a/doc/man3/EVP_sha224.pod b/doc/man3/EVP_sha224.pod index 8c3a55d403..be09e49ee3 100644 --- a/doc/man3/EVP_sha224.pod +++ b/doc/man3/EVP_sha224.pod @@ -55,7 +55,8 @@ See L for further information. =head1 RETURN VALUES These functions return a B structure that contains the -implementation of the message digest. +implementation of the message digest. See L for +details of the B structure. =head1 CONFORMING TO diff --git a/doc/man3/EVP_sha3_224.pod b/doc/man3/EVP_sha3_224.pod index 47b18fc1c4..93c0d0b9fb 100644 --- a/doc/man3/EVP_sha3_224.pod +++ b/doc/man3/EVP_sha3_224.pod @@ -60,7 +60,8 @@ See L for further information. =head1 RETURN VALUES These functions return a B structure that contains the -implementation of the message digest. +implementation of the message digest. See L for +details of the B structure. =head1 CONFORMING TO diff --git a/doc/man3/EVP_sm3.pod b/doc/man3/EVP_sm3.pod index 89224359b2..65be55e88d 100644 --- a/doc/man3/EVP_sm3.pod +++ b/doc/man3/EVP_sm3.pod @@ -34,7 +34,8 @@ See L for further information. =head1 RETURN VALUES These functions return a B structure that contains the -implementation of the message digest. +implementation of the message digest. See L for +details of the B structure. =head1 CONFORMING TO diff --git a/doc/man3/EVP_sm4_cbc.pod b/doc/man3/EVP_sm4_cbc.pod index 49d43c552b..48be7a31ad 100644 --- a/doc/man3/EVP_sm4_cbc.pod +++ b/doc/man3/EVP_sm4_cbc.pod @@ -51,12 +51,14 @@ See L for further information. =head1 RETURN VALUES These functions return a B structure that contains the -implementation of the symmetric cipher. +implementation of the symmetric cipher. See L for +details of the B structure. =head1 SEE ALSO L, -L +L, +L =head1 COPYRIGHT diff --git a/doc/man3/EVP_whirlpool.pod b/doc/man3/EVP_whirlpool.pod index ef86d28b6c..c5d465b16f 100644 --- a/doc/man3/EVP_whirlpool.pod +++ b/doc/man3/EVP_whirlpool.pod @@ -36,7 +36,8 @@ See L for further information. =head1 RETURN VALUES These functions return a B structure that contains the -implementation of the message digest. +implementation of the message digest. See L for +details of the B structure. =head1 CONFORMING TO diff --git a/doc/man3/HMAC.pod b/doc/man3/HMAC.pod index d6cd404ab6..53a3853eb2 100644 --- a/doc/man3/HMAC.pod +++ b/doc/man3/HMAC.pod @@ -112,9 +112,6 @@ be authenticated (I bytes at I). HMAC_Final() places the message authentication code in I, which must have space for the hash function output. -After calling HMAC_Final() no calls to HMAC_Update() or HMAC_Final() can be -made, but HMAC_Init_ex() can be called to initialize a new HMAC -operation. HMAC_CTX_copy() copies all of the internal state from I into I. diff --git a/doc/man3/NAME_CONSTRAINTS_check.pod b/doc/man3/NAME_CONSTRAINTS_check.pod deleted file mode 100644 index 3dfe39ea29..0000000000 --- a/doc/man3/NAME_CONSTRAINTS_check.pod +++ /dev/null @@ -1,211 +0,0 @@ -=pod - -=head1 NAME - -NAME_CONSTRAINTS_check, -NAME_CONSTRAINTS_check_CN - check a certificate's names against a name -constraints extension - -=head1 SYNOPSIS - - #include - - int NAME_CONSTRAINTS_check(const X509 *x, NAME_CONSTRAINTS *nc); - int NAME_CONSTRAINTS_check_CN(const X509 *x, NAME_CONSTRAINTS *nc); - -=head1 DESCRIPTION - -NAME_CONSTRAINTS_check() tests whether the names asserted by certificate -I satisfy the name constraints I. It implements the matching -primitive of RFC 5280 section 4.2.1.10: given a constraint set (a -B structure containing zero or more B -and B) and a candidate certificate, decide whether the -certificate's names fall within the permitted subtrees and outside the -excluded subtrees. - -The names considered by NAME_CONSTRAINTS_check() are: - -=over 4 - -=item * - -The certificate's subject distinguished name, matched as a B -general-name type. The subject is considered only when it is nonempty. - -=item * - -Each B attribute appearing within the subject distinguished -name, matched as an B general-name type. These attributes are -the historical, pre-SAN way of expressing an email address in a -certificate's subject, and RFC 5280 requires that they be subjected to -name-constraint checking. - -=item * - -Each entry in the certificate's subject alternative name extension, matched -according to its declared general-name type. - -=back - -NAME_CONSTRAINTS_check() implements matching for the following -general-name types: B, B, B, -B, and B. The B form -B (RFC 8398) is additionally matched against -B subtrees. Any other general-name type, including -B, B, B, and other B -forms, yields B. - -For each name considered, the function evaluates two conditions: - -=over 4 - -=item * - -If I contains at least one B of the same general-name -type as the name, the name must match at least one of those permitted -subtrees. If I contains no permitted subtrees of that type, no -permitted-subtrees test is imposed on names of that type. - -=item * - -The name must not match any B of the same general-name -type in I. - -=back - -The function returns at the first violation encountered; it does not -collect or report multiple failures. - -For B entries, matching follows the byte/label algorithm of -RFC 5280 section 4.2.1.10, which RFC 5280 mandates when no -protocol-specific matching rules apply. Because this match is performed -without awareness of any specific higher-level protocol, additional -matching rules defined by later or more specific protocols must be -applied independently of this function to the certificate chain. - -NAME_CONSTRAINTS_check() performs only the constraint match for a single -certificate against a single constraint set. It does B perform the -chain-wide enforcement of RFC 5280 section 6.1.4(g)-(j): callers wishing to -enforce name constraints across an entire certification path must walk the -chain themselves and apply each ancestor's constraint set to certificates -lower in the chain, observing the usual exceptions (for example, -self-issued intermediate certificates are exempt from constraints imposed -by certificates above them, except when they are the leaf of the chain). -For full RFC 5280 name-constraint enforcement integrated with chain -validation, applications should use L, which performs -this internally. - -NAME_CONSTRAINTS_check() enforces an implementation limit on the product -of the certificate's name count and the constraint set's subtree count, to -prevent computationally expensive matching on pathological input. If that -limit is exceeded the function returns B without -performing any matching. The current limit is 2**20 (1,048,576) on the -product of the name count (subject DN entries plus B -entries) and the subtree count (B plus -B). - -=head1 RETURN VALUES - -NAME_CONSTRAINTS_check() returns B if every name considered -satisfies the constraints. Otherwise it returns one of the following -B codes: - -=over 4 - -=item B - -A name of a type for which I contains at least one permitted subtree -failed to match any of those subtrees. - -=item B - -A name matched an excluded subtree. - -=item B - -A subtree in I specified a B other than 0 or a B at -all. RFC 5280 requires that these B fields not be used, -and a constraint set that uses them cannot be processed. - -=item B - -A general-name type for which matching is not implemented was encountered. -The list of supported types is given in the DESCRIPTION above. - -=item B - -A name in the certificate is encoded in a way that cannot be matched (for -example, an B attribute in the subject that is not encoded -as an B). - -=item B - -The product of the certificate's name count and the constraint set's -subtree count exceeded the implementation limit; no matching was -performed. - -=back - -Other B codes may be returned by deeper name-matching -helpers (for example, codes arising from individual general-name type -comparisons). Callers should treat the return value as the authoritative -success/failure signal and treat any value other than B as a -failure, rather than enumerating the specific codes above. - -=head1 NOTES - -NAME_CONSTRAINTS_check() does not match the certificate's commonName -against B name constraints; that check is provided by a separate -function, B(). The commonName-as-DNS-identity -practice is a legacy concern: modern certificates assert DNS identities -through B entries in the subject alternative name extension, -which NAME_CONSTRAINTS_check() already covers. NAME_CONSTRAINTS_check_CN() -is required only for older certificates that express a DNS identity -through their commonName instead of, or in addition to, the SAN; for -certificates conforming to modern profiles a call to NAME_CONSTRAINTS_check() -alone is generally sufficient. - -=head1 BUGS - -RFC 9525's wildcard semantics apply only to presented-identifier -matching for TLS service identity, and explicitly call out they are not -valid for any other purpose; they do not define wildcard handling -for name-constraint matching. NAME_CONSTRAINTS_check() therefore -follows RFC 5280's requirements for when this is undefined, and treats -the B<*> character in a B as a literal label component, per -the RFC 5280 algorithm, which is often contrary to caller expectation. - -Even if specified in the future, due to the "fallback implementation" -nature of matching wildcards in SAN B entries specified by -RFC 5280, name constraint behaviour in the presence of wildcards -should not be strictly relied upon across implementations and -protocols. This matters most for the use of B -constraints, which should not be relied upon to reliably constrain -signing certificates for a PKI in a security dependent manner unless -the consumers of these certificates are themselves known to be -constrained by other means to only use implementations that provide -different semantics, or the PKI can be constrained by other means to -ensure that wildcards are never issued from such signing -certificates. - -=head1 SEE ALSO - -L, -L - -=head1 HISTORY - -NAME_CONSTRAINTS_check() was added in OpenSSL 1.0.0. - -NAME_CONSTRAINTS_check_CN() was added in OpenSSL 1.1.0. - -=head1 COPYRIGHT - -Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - -Licensed under the Apache License 2.0 (the "License"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file LICENSE in the source distribution or at -L. - -=cut diff --git a/doc/man3/OCSP_REQUEST_new.pod b/doc/man3/OCSP_REQUEST_new.pod index 3891964ffb..3f171e8229 100644 --- a/doc/man3/OCSP_REQUEST_new.pod +++ b/doc/man3/OCSP_REQUEST_new.pod @@ -17,7 +17,7 @@ OCSP_request_onereq_get0 - OCSP request functions int OCSP_request_sign(OCSP_REQUEST *req, X509 *signer, EVP_PKEY *key, const EVP_MD *dgst, - const STACK_OF(X509) *certs, unsigned long flags); + STACK_OF(X509) *certs, unsigned long flags); int OCSP_request_add1_cert(OCSP_REQUEST *req, X509 *cert); @@ -109,7 +109,7 @@ L =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/OCSP_resp_find_status.pod b/doc/man3/OCSP_resp_find_status.pod index 714d58d4de..bc5db70862 100644 --- a/doc/man3/OCSP_resp_find_status.pod +++ b/doc/man3/OCSP_resp_find_status.pod @@ -51,7 +51,7 @@ OCSP_check_validity, OCSP_basic_verify ASN1_GENERALIZEDTIME *nextupd, long sec, long maxsec); - int OCSP_basic_verify(OCSP_BASICRESP *bs, const STACK_OF(X509) *certs, + int OCSP_basic_verify(OCSP_BASICRESP *bs, STACK_OF(X509) *certs, X509_STORE *st, unsigned long flags); =head1 DESCRIPTION @@ -210,7 +210,7 @@ L =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2022 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/OCSP_response_status.pod b/doc/man3/OCSP_response_status.pod index 9a94c9ab3c..0902ae8a31 100644 --- a/doc/man3/OCSP_response_status.pod +++ b/doc/man3/OCSP_response_status.pod @@ -26,10 +26,10 @@ OCSP_RESPID_match, OCSP_basic_sign, OCSP_basic_sign_ctx int OCSP_RESPID_match(OCSP_RESPID *respid, X509 *cert); int OCSP_basic_sign(OCSP_BASICRESP *brsp, X509 *signer, EVP_PKEY *key, - const EVP_MD *dgst, const STACK_OF(X509) *certs, + const EVP_MD *dgst, STACK_OF(X509) *certs, unsigned long flags); int OCSP_basic_sign_ctx(OCSP_BASICRESP *brsp, X509 *signer, EVP_MD_CTX *ctx, - const STACK_OF(X509) *certs, unsigned long flags); + STACK_OF(X509) *certs, unsigned long flags); =head1 DESCRIPTION @@ -124,7 +124,7 @@ The OCSP_basic_sign_ctx() function was added in OpenSSL 1.1.1. =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/OPENSSL_FILE.pod b/doc/man3/OPENSSL_FILE.pod index 22128a5c5b..7d9dc2b3b8 100644 --- a/doc/man3/OPENSSL_FILE.pod +++ b/doc/man3/OPENSSL_FILE.pod @@ -3,7 +3,6 @@ =head1 NAME OPENSSL_FILE, OPENSSL_LINE, OPENSSL_FUNC, -OSSL_BEGIN_ALLOW_DEPRECATED, OSSL_END_ALLOW_DEPRECATED, OPENSSL_MSTR, OPENSSL_MSTR_HELPER - generic C programming utility macros @@ -18,9 +17,6 @@ OPENSSL_MSTR, OPENSSL_MSTR_HELPER #define OPENSSL_MSTR_HELPER(x) #x #define OPENSSL_MSTR(x) OPENSSL_MSTR_HELPER(x) - #define OSSL_BEGIN_ALLOW_DEPRECATED /* compiler specific */ - #define OSSL_END_ALLOW_DEPRECATED /* compiler specific */ - =head1 DESCRIPTION The macros B and B @@ -35,17 +31,6 @@ The macro B yields the expansion of the macro given as argument, which is useful for concatenation with string constants. The macro B is an auxiliary macro for this purpose. -The macros B and -B respectively disable and then -re-enable compiler warnings for deprecated functions within a source -file, for compilers which OpenSSL supports. They are equivalent to -disabling the warnings with compiler-specific options, but may be -convenient when you wish to use deprecated OpenSSL functions -temporarily in limited areas of code without turning off warnings more -globally. It is nevertheless important to remember to eventually -transition such code to replacement functions, as deprecated functions -may be removed in later major OpenSSL releases. - =head1 RETURN VALUES see above @@ -59,12 +44,9 @@ L B, B, and B were added in OpenSSL 3.0. -B and B were -added in OpenSSL 4.0, inspired by BoringSSL. - =head1 COPYRIGHT -Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2018-2019 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/OPENSSL_init_crypto.pod b/doc/man3/OPENSSL_init_crypto.pod index ae7e89ec25..3ef6aba822 100644 --- a/doc/man3/OPENSSL_init_crypto.pod +++ b/doc/man3/OPENSSL_init_crypto.pod @@ -4,7 +4,7 @@ OPENSSL_INIT_new, OPENSSL_INIT_set_config_filename, OPENSSL_INIT_set_config_appname, OPENSSL_INIT_set_config_file_flags, -OPENSSL_INIT_free, OPENSSL_init_crypto, OPENSSL_cleanup, +OPENSSL_INIT_free, OPENSSL_init_crypto, OPENSSL_cleanup, OPENSSL_atexit, OPENSSL_thread_stop_ex, OPENSSL_thread_stop - OpenSSL initialisation and deinitialisation functions @@ -14,6 +14,7 @@ and deinitialisation functions void OPENSSL_cleanup(void); int OPENSSL_init_crypto(uint64_t opts, const OPENSSL_INIT_SETTINGS *settings); + int OPENSSL_atexit(void (*handler)(void)); void OPENSSL_thread_stop_ex(OSSL_LIB_CTX *ctx); void OPENSSL_thread_stop(void); @@ -35,7 +36,8 @@ application is multi-threaded), and these resources must be freed prior to the thread closing. As of version 1.1.0 OpenSSL will automatically allocate all resources that it -needs so no explicit initialisation is required. +needs so no explicit initialisation is required. Similarly it will also +automatically deinitialise as required. However, there may be situations when explicit initialisation is desirable or needed, for example when some nondefault initialisation is required. The @@ -124,7 +126,10 @@ See OPENSSL_fork_prepare(3) for details. =item OPENSSL_INIT_NO_ATEXIT -The option has no effect in 4.0 and later. +By default OpenSSL will attempt to clean itself up when the process exits via an +"atexit" handler. Using this option suppresses that behaviour. This means that +the application will have to clean up OpenSSL explicitly using +OPENSSL_cleanup(). =back @@ -134,28 +139,17 @@ OPENSSL_init_crypto(). For example: OPENSSL_init_crypto(OPENSSL_INIT_NO_ADD_ALL_CIPHERS | OPENSSL_INIT_NO_ADD_ALL_DIGESTS, NULL); -The OPENSSL_cleanup() function requests deinitialization of OpenSSL -(both libcrypto and libssl). OpenSSL installs a global destructor -function at initialization time if the toolchain supports this. This -destructor is run after exit and after subordinate library destructors -have run. By default the destructor does nothing. If deinitialization -has been requested by a call to OPENSSL_cleanup(), then the destructor -frees all global resources allocated by OpenSSL. - -If the toolchain building OpenSSL does not support a global -destructor, by default OPENSSL_cleanup will do nothing, as this is the -safest option, allowing the operating system to then reap all library -resources on process exit. Note, this may, on some leak detection -tools (like valgrind) result in reports that indicate reachable memory -remains on exit in certain configurations. As these are not formally -leaks, it is recommended that reachable memory reports be suppressed -when running such tools. - -If OpenSSL is compiled with the compile time option of DO_NOT_SKIP_OPENSSL_CLEANUP -OPENSSL_cleanup() will deinitialize the library immediately when called. This -is not normally recommended unless you are certain that the global resources -will not be used by something after the point at which OPENSSL_cleanup() is -called. +The OPENSSL_cleanup() function deinitialises OpenSSL (both libcrypto +and libssl). All resources allocated by OpenSSL are freed. Typically there +should be no need to call this function directly as it is initiated +automatically on application exit. This is done via the standard C library +atexit() function. In the event that the application will close in a manner +that will not call the registered atexit() handlers then the application should +call OPENSSL_cleanup() directly. Developers of libraries using OpenSSL +are discouraged from calling this function and should instead, typically, rely +on auto-deinitialisation. This is to avoid error conditions where both an +application and a library it depends on both use OpenSSL, and the library +deinitialises it before the application has finished using it. Once OPENSSL_cleanup() has been called the library cannot be reinitialised. Attempts to call OPENSSL_init_crypto() will fail and an ERR_R_INIT_FAIL error @@ -164,6 +158,12 @@ OpenSSL error strings will not be available, only an error code. This code can be put through the openssl errstr command line application to produce a human readable error (see L). +The OPENSSL_atexit() function enables the registration of a +function to be called during OPENSSL_cleanup(). Stop handlers are +called after deinitialisation of resources local to a thread, but before other +process wide resources are freed. In the event that multiple stop handlers are +registered, no guarantees are made about the order of execution. + The OPENSSL_thread_stop_ex() function deallocates resources associated with the current thread for the given OSSL_LIB_CTX B. The B parameter can be NULL in which case the default OSSL_LIB_CTX is used. @@ -226,7 +226,7 @@ call should use the RTLD_NODELETE flag (where available on the platform). =head1 RETURN VALUES -The functions OPENSSL_init_crypto, and +The functions OPENSSL_init_crypto, OPENSSL_atexit() and OPENSSL_INIT_set_config_appname() return 1 on success or 0 on error. =head1 SEE ALSO @@ -235,7 +235,7 @@ L =head1 HISTORY -The OPENSSL_init_crypto(), OPENSSL_cleanup() +The OPENSSL_init_crypto(), OPENSSL_cleanup(), OPENSSL_atexit(), OPENSSL_thread_stop(), OPENSSL_INIT_new(), OPENSSL_INIT_set_config_appname() and OPENSSL_INIT_free() functions were added in OpenSSL 1.1.0. @@ -249,7 +249,7 @@ B is defined to 0 since OpenSSL 4.0. =head1 COPYRIGHT -Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/OPENSSL_malloc.pod b/doc/man3/OPENSSL_malloc.pod index 1907469fcd..30ceeb6ec0 100644 --- a/doc/man3/OPENSSL_malloc.pod +++ b/doc/man3/OPENSSL_malloc.pod @@ -13,7 +13,7 @@ CRYPTO_malloc_array, CRYPTO_aligned_alloc_array, CRYPTO_calloc, CRYPTO_realloc, CRYPTO_realloc_array, CRYPTO_free, OPENSSL_strdup, OPENSSL_strndup, OPENSSL_memdup, OPENSSL_strlcpy, OPENSSL_strlcat, OPENSSL_strtoul, -CRYPTO_strdup, CRYPTO_strndup, CRYPTO_memdup, +CRYPTO_strdup, CRYPTO_strndup, OPENSSL_mem_debug_push, OPENSSL_mem_debug_pop, CRYPTO_mem_debug_push, CRYPTO_mem_debug_pop, CRYPTO_clear_realloc, CRYPTO_clear_realloc_array, CRYPTO_clear_free, @@ -69,7 +69,6 @@ OPENSSL_MALLOC_SEED void CRYPTO_free(void *str, const char *file, int line); char *CRYPTO_strdup(const char *p, const char *file, int line); char *CRYPTO_strndup(const char *p, size_t num, const char *file, int line); - void *CRYPTO_memdup(void *data, size_t s, const char *file, int line); void *CRYPTO_clear_realloc(void *p, size_t old_len, size_t num, const char *file, int line); void *CRYPTO_clear_realloc_array(void *p, size_t old_len, size_t num, @@ -139,8 +138,8 @@ in the I variable, rather than the returned pointer. OPENSSL_clear_realloc() and OPENSSL_clear_free() should be used when the buffer at B holds sensitive information. The old buffer is filled with zero's by calling OPENSSL_cleanse() -before ultimately calling OPENSSL_free(). If the argument to -OPENSSL_clear_free() is NULL, nothing is done. +before ultimately calling OPENSSL_free(). If the argument to OPENSSL_free() is +NULL, nothing is done. OPENSSL_malloc_array(), OPENSSL_calloc(), OPENSSL_aligned_alloc_array(), OPENSSL_realloc_array(), and OPENSSL_clear_realloc_array() are variants @@ -239,16 +238,14 @@ OPENSSL_malloc(), OPENSSL_aligned_alloc(), OPENSSL_zalloc(), OPENSSL_realloc(), OPENSSL_malloc_array(), OPENSSL_aligned_alloc_array(), OPENSSL_calloc(), OPENSSL_realloc_array(), OPENSSL_clear_realloc(), OPENSSL_clear_realloc_array(), -OPENSSL_strdup(), OPENSSL_strndup(), OPENSSL_memdup(), -CRYPTO_malloc(), CRYPTO_aligned_alloc(), CRYPTO_zalloc(), CRYPTO_realloc(), -CRYPTO_malloc_array(), CRYPTO_aligned_alloc_array(), CRYPTO_calloc(), -CRYPTO_realloc_array(), +CRYPTO_malloc(), CRYPTO_zalloc(), CRYPTO_realloc(), +CRYPTO_malloc_array(), CRYPTO_calloc(), CRYPTO_realloc_array(), CRYPTO_clear_realloc(), CRYPTO_clear_realloc_array(), -CRYPTO_strdup(), CRYPTO_strndup(), and CRYPTO_memdup() +OPENSSL_strdup(), and OPENSSL_strndup() return a pointer to allocated memory or NULL on error. -OPENSSL_aligned_alloc(), OPENSSL_aligned_alloc_array(), CRYPTO_aligned_alloc(), -and CRYPTO_aligned_alloc_array() set B to NULL on error. +OPENSSL_aligned_alloc() and OPENSSL_aligned_alloc_array() set B +to NULL on error. CRYPTO_set_mem_functions() returns 1 on success or 0 on failure (almost always because allocations have already happened). @@ -321,10 +318,6 @@ the caller may need to fall back to a non-aligned memory allocation Before OpenSSL 4.0, the call to OPENSSL_aligned_alloc() did not have an explicit upper limit on the value of I. -Before OpenSSL 4.1, allocations done by custom memory functions -and zero-sized allocations did not progress allocation counter -used against B specification. - =head1 COPYRIGHT Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. diff --git a/doc/man3/OPENSSL_secure_malloc.pod b/doc/man3/OPENSSL_secure_malloc.pod index 510e3bac8f..e9586be0eb 100644 --- a/doc/man3/OPENSSL_secure_malloc.pod +++ b/doc/man3/OPENSSL_secure_malloc.pod @@ -8,7 +8,7 @@ OPENSSL_secure_zalloc, CRYPTO_secure_zalloc, OPENSSL_secure_malloc_array, CRYPTO_secure_malloc_array, OPENSSL_secure_calloc, CRYPTO_secure_calloc, OPENSSL_secure_free, CRYPTO_secure_free, OPENSSL_secure_clear_free, CRYPTO_secure_clear_free, OPENSSL_secure_actual_size, -CRYPTO_secure_actual_size, CRYPTO_secure_allocated, +CRYPTO_secure_allocated, CRYPTO_secure_used - secure heap storage =head1 SYNOPSIS @@ -42,7 +42,6 @@ CRYPTO_secure_used - secure heap storage void CRYPTO_secure_clear_free(void *ptr, size_t num, const char *, int); size_t OPENSSL_secure_actual_size(const void *ptr); - size_t CRYPTO_secure_actual_size(const void *ptr); int CRYPTO_secure_allocated(const void *ptr); size_t CRYPTO_secure_used(); @@ -120,9 +119,6 @@ OPENSSL_secure_actual_size() tells the actual size allocated to the pointer; implementations may allocate more space than initially requested, in order to "round up" and reduce secure heap fragmentation. -CRYPTO_secure_actual_size() is an alias to OPENSSL_secure_actual_size(), -identical in arguments, return value, and behaviour. - OPENSSL_secure_allocated() tells if a pointer is allocated in the secure heap. CRYPTO_secure_used() returns the number of bytes allocated in the @@ -145,9 +141,6 @@ return a pointer into the secure heap of the requested size, if it is initialised, a pointer returned by the underlying OPENSSL_malloc() call, if it is not, or C on error. -OPENSSL_secure_actual_size() and CRYPTO_secure_actual_size() return positive -size in bytes on success or 0 on error. - CRYPTO_secure_allocated() returns 1 if the pointer is in the secure heap, or 0 if not. CRYPTO_secure_malloc_done() returns 1 if the secure memory area is released, or 0 if not. diff --git a/doc/man3/OSSL_CMP_CTX_new.pod b/doc/man3/OSSL_CMP_CTX_new.pod index 9e4cd0c22a..f395db9e39 100644 --- a/doc/man3/OSSL_CMP_CTX_new.pod +++ b/doc/man3/OSSL_CMP_CTX_new.pod @@ -335,12 +335,6 @@ B This setting leads to unspecified behavior and it is meant exclusively to allow interoperability with server implementations violating RFC 9810. -=item B - -Accept missing or non-matching transactionID or recipNonce in error messages. -This can be helpful in case the server cannot provide a proper error message, -for instance if it was unable to parse the ASN.1 encoding of a request message. - =item B Ignore key usage restrictions in the signer's certificate when @@ -367,12 +361,6 @@ implements a form of trust-on-first-use (TOFU). Do not cache certificates received in the extraCerts CMP message field. Otherwise they are stored to potentially help validate further messages. -In any case, after successfully validating an incoming message, its protection -certificate (if any) is cached for reuse with validation of subsequent messages. -This is done not only for efficiency but also -to eliminate the need for the sender to include its certificate and related chain -in the extraCerts field of subsequent messages of the same transaction. - =back OSSL_CMP_CTX_get_option() reads the current value of the given option @@ -846,7 +834,7 @@ Perform a Certification Request transaction, making use of the new credentials: OSSL_CMP_CTX_set1_cert(cmp_ctx, initialCert); OSSL_CMP_CTX_set1_pkey(cmp_ctx, initialKey); - OSSL_CMP_CTX_set0_newPkey(cmp_ctx, 1, currentKey); + OSSL_CMP_CTX_set0_newPkey(cmp_ctx, 1, curentKey); currentCert = OSSL_CMP_exec_CR_ses(cmp_ctx); Perform a Key Update Request, signed using the cert (and key) to be updated: @@ -894,17 +882,11 @@ OSSL_CMP_CTX_set1_serialNumber(), OSSL_CMP_CTX_get0_libctx(), OSSL_CMP_CTX_get0_propq(), and OSSL_CMP_CTX_get0_validatedSrvCert() were added in OpenSSL 3.2. -The B option as well as -OSSL_CMP_CTX_get0_geninfo_ITAVs() were added in OpenSSL 3.3. +OSSL_CMP_CTX_get0_geninfo_ITAVs() was added in OpenSSL 3.3. Support for central key generation, requested via B, was added in OpenSSL 3.5. - -The B option was added in OpenSSL 4.0. - -The B option was added in OpenSSL 4.1. - =head1 COPYRIGHT Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved. diff --git a/doc/man3/OSSL_CMP_SRV_CTX_new.pod b/doc/man3/OSSL_CMP_SRV_CTX_new.pod index aac88bafcc..34862a0906 100644 --- a/doc/man3/OSSL_CMP_SRV_CTX_new.pod +++ b/doc/man3/OSSL_CMP_SRV_CTX_new.pod @@ -40,7 +40,7 @@ OSSL_CMP_SRV_CTX_set_grant_implicit_confirm const OSSL_CMP_MSG *req, int certReqId, const OSSL_CRMF_MSG *crm, - const X509_REQ *p10, + const X509_REQ *p10cr, X509 **certOut, STACK_OF(X509) **chainOut, STACK_OF(X509) **caPubs); @@ -188,7 +188,7 @@ was added in OpenSSL 3.3. =head1 COPYRIGHT -Copyright 2007-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2007-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/OSSL_CRMF_MSG_get0_tmpl.pod b/doc/man3/OSSL_CRMF_MSG_get0_tmpl.pod index 3e190be297..a8a5a36b68 100644 --- a/doc/man3/OSSL_CRMF_MSG_get0_tmpl.pod +++ b/doc/man3/OSSL_CRMF_MSG_get0_tmpl.pod @@ -62,7 +62,7 @@ OSSL_CRMF_MSG_centralkeygen_requested int OSSL_CRMF_MSG_get_certReqId(const OSSL_CRMF_MSG *crm); int OSSL_CRMF_MSG_centralkeygen_requested(const OSSL_CRMF_MSG *crm, - const X509_REQ *p10); + const X509_REQ *p10cr); =head1 DESCRIPTION @@ -127,7 +127,7 @@ OSSL_CRMF_MSG_get_certReqId() retrieves the certReqId of I. OSSL_CRMF_MSG_centralkeygen_requested() returns 1 if central key generation is requested i.e., the public key in the certificate request (I is taken if it is non-NULL, -otherwise I) is NULL or has an empty key value (with length zero). +otherwise I) is NULL or has an empty key value (with length zero). In case I is non-NULL, this is checked for consistency with its B field (must be NULL if and only if central key generation is requested). Otherwise it returns 0, and on error a negative value. @@ -158,7 +158,7 @@ and OSSL_CRMF_MSG_centralkeygen_requested() were added in OpenSSL 3.5. =head1 COPYRIGHT -Copyright 2007-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/OSSL_ENCODER_CTX.pod b/doc/man3/OSSL_ENCODER_CTX.pod index 23291f8e18..f06b9fd86f 100644 --- a/doc/man3/OSSL_ENCODER_CTX.pod +++ b/doc/man3/OSSL_ENCODER_CTX.pod @@ -6,7 +6,6 @@ OSSL_ENCODER_CTX, OSSL_ENCODER_CTX_new, OSSL_ENCODER_settable_ctx_params, OSSL_ENCODER_CTX_set_params, -OSSL_ENCODER_CTX_ctrl_string, OSSL_ENCODER_CTX_free, OSSL_ENCODER_CTX_set_selection, OSSL_ENCODER_CTX_set_output_type, @@ -36,8 +35,6 @@ OSSL_ENCODER_CTX_set_cleanup const OSSL_PARAM *OSSL_ENCODER_settable_ctx_params(OSSL_ENCODER *encoder); int OSSL_ENCODER_CTX_set_params(OSSL_ENCODER_CTX *ctx, const OSSL_PARAM params[]); - int OSSL_ENCODER_CTX_ctrl_string(OSSL_ENCODER_CTX *ctx, - const char *name, const char *val); void OSSL_ENCODER_CTX_free(OSSL_ENCODER_CTX *ctx); int OSSL_ENCODER_CTX_set_selection(OSSL_ENCODER_CTX *ctx, int selection); @@ -104,13 +101,6 @@ OSSL_ENCODER_CTX_set_params() attempts to set parameters specified with an L array I. Parameters that the implementation doesn't recognise should be ignored. -OSSL_ENCODER_CTX_ctrl_string() attempts to set a single parameter named I -by parsing the specified string I to the type of a settable parameter -associated with one of the underlying encoders. -An error is reported if no parameter named I is a settable in any of the -underlying encoders, the I fails to parse, or the encoder implementation -rejects the parsed value. - OSSL_ENCODER_CTX_free() frees the given context I. If the argument is NULL, nothing is done. @@ -192,8 +182,6 @@ OSSL_ENCODER_CTX_set_params() returns 1 if all recognised parameters were valid, or 0 if one of them was invalid or caused some other failure in the implementation. -OSSL_ENCODER_CTX_ctrl_string() returns 1 on success and 0 on error. - OSSL_ENCODER_CTX_add_encoder(), OSSL_ENCODER_CTX_add_extra(), OSSL_ENCODER_CTX_set_cleanup(), diff --git a/doc/man3/OSSL_ESS_check_signing_certs.pod b/doc/man3/OSSL_ESS_check_signing_certs.pod index f8a57ae746..726dbc285c 100644 --- a/doc/man3/OSSL_ESS_check_signing_certs.pod +++ b/doc/man3/OSSL_ESS_check_signing_certs.pod @@ -4,8 +4,7 @@ OSSL_ESS_signing_cert_new_init, OSSL_ESS_signing_cert_v2_new_init, -OSSL_ESS_check_signing_certs, -OSSL_ESS_check_signing_certs_ex +OSSL_ESS_check_signing_certs - Enhanced Security Services (ESS) functions =head1 SYNOPSIS @@ -25,12 +24,6 @@ OSSL_ESS_check_signing_certs_ex const STACK_OF(X509) *chain, int require_signing_cert); - int OSSL_ESS_check_signing_certs_ex(const ESS_SIGNING_CERT *ss, - const ESS_SIGNING_CERT_V2 *ssv2, - const STACK_OF(X509) *chain, - OSSL_LIB_CTX *libctx, - const char *propq, - int require_signing_cert); =head1 DESCRIPTION OSSL_ESS_signing_cert_new_init() generates a new B structure @@ -59,10 +52,6 @@ In addition to the checks required by RFCs 2624 and 5035, if the B field is included in an B or B it must match the certificate issuer and serial number attributes. -OSSL_ESS_check_signing_certs_ex() functions identically to OSSL_ESS_check_signing_certs(), -but offers additional parameters, I and I, for users who wish to specify a nondefault -library context and property query, when the function fetches digests to validate the certs. - =head1 NOTES ESS has been defined in RFC 2634, which has been updated in RFC 5035 @@ -74,7 +63,7 @@ This is used for TSP (RFC 3161) and CAdES-BES (informational RFC 5126). OSSL_ESS_signing_cert_new_init() and OSSL_ESS_signing_cert_v2_new_init() return a pointer to the new structure or NULL on malloc failure. -OSSL_ESS_check_signing_certs() and OSSL_ESS_check_signing_certs_ex() return 1 on success, +OSSL_ESS_check_signing_certs() returns 1 on success, 0 if a required certificate cannot be found, -1 on other error. =head1 SEE ALSO @@ -87,11 +76,9 @@ L OSSL_ESS_signing_cert_new_init(), OSSL_ESS_signing_cert_v2_new_init(), and OSSL_ESS_check_signing_certs() were added in OpenSSL 3.0. -OSSL_ESS_check_signing_certs_ex() was added in OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2021-2022 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/OSSL_HPKE_CTX_new.pod b/doc/man3/OSSL_HPKE_CTX_new.pod index a7fd32122f..89a6fcafe1 100644 --- a/doc/man3/OSSL_HPKE_CTX_new.pod +++ b/doc/man3/OSSL_HPKE_CTX_new.pod @@ -451,12 +451,12 @@ OSSL_HPKE_get_ciphertext_size() and OSSL_HPKE_get_public_encap_size(). OSSL_HPKE_str2suite() maps input I strings to an B object. The input I should be a comma-separated string with a KEM, -KDF and AEAD name in that order, for example "x25519,hkdf-sha256,aes-128-gcm". +KDF and AEAD name in that order, for example "x25519,hkdf-sha256,aes128gcm". This can be used by command line tools that accept string form names for HPKE codepoints. Valid (case-insensitive) names are: "p-256", "p-384", "p-521", "x25519" and "x448" for KEM, "hkdf-sha256", "hkdf-sha384" and "hkdf-sha512" for KDF, and -"aes-128-gcm", "aes-256-gcm", "chacha20-poly1305" and "exporter" for AEAD. +"aes-gcm-128", "aes-gcm-256", "chacha20-poly1305" and "exporter" for AEAD. String variants of the numbers listed in L can also be used. @@ -566,7 +566,7 @@ This functionality described here was added in OpenSSL 3.2. =head1 COPYRIGHT -Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/OSSL_HTTP_REQ_CTX.pod b/doc/man3/OSSL_HTTP_REQ_CTX.pod index 88e90c2330..210f33801c 100644 --- a/doc/man3/OSSL_HTTP_REQ_CTX.pod +++ b/doc/man3/OSSL_HTTP_REQ_CTX.pod @@ -86,12 +86,9 @@ For backward compatibility, I may begin with C and thus convey an absoluteURI. In this case it indicates HTTP proxy use and provides also the server (and optionally the port) that the proxy shall forward the request to. In this case the I and I arguments must be NULL. -The I, I, and I arguments must not contain CR or LF -characters. OSSL_HTTP_REQ_CTX_add1_header() adds header I with value I to the context I. It can be called more than once to add multiple header lines. -The I and I arguments must not contain CR or LF characters. For example, to add a C header for C you would call: OSSL_HTTP_REQ_CTX_add1_header(ctx, "Host", "example.com"); @@ -111,10 +108,10 @@ in the header line, followed by a C<;> character and any further text. For instance, if the I argument specifies C, this is matched by C, C, etc. -If the I parameter is nonzero, a structure in ASN.1 DER/BER encoding -will be expected as the response content and input streaming is disabled. -This means that an ASN.1 sequence header is required, its length field is checked, -and OSSL_HTTP_REQ_CTX_get0_mem_bio() should be used to get the buffered response. +If the I parameter is nonzero a structure in ASN.1 encoding will be +expected as the response content and input streaming is disabled. This means +that an ASN.1 sequence header is required, its length field is checked, and +OSSL_HTTP_REQ_CTX_get0_mem_bio() should be used to get the buffered response. Otherwise (by default) any input format is allowed, with body length checks being performed on error messages only. In this case the BIO given as I argument to OSSL_HTTP_REQ_CTX_new() should @@ -146,7 +143,6 @@ The HTTP header C is filled out with the length of the request. I must be NULL if I is NULL. If I isn't NULL, the HTTP header C is also added with the given string value. -The I argument must not contain CR or LF characters. The header lines are added to the internal memory B for the request header. OSSL_HTTP_REQ_CTX_nbio() attempts to send the request prepared in I diff --git a/doc/man3/OSSL_HTTP_parse_url.pod b/doc/man3/OSSL_HTTP_parse_url.pod index 1e8c3efa77..bc29fb18d1 100644 --- a/doc/man3/OSSL_HTTP_parse_url.pod +++ b/doc/man3/OSSL_HTTP_parse_url.pod @@ -32,9 +32,7 @@ see L: =head1 DESCRIPTION -OSSL_HTTP_adapt_proxy() determines whether a proxy should be used -when connecting to the given I. -It takes an optional proxy hostname I +OSSL_HTTP_adapt_proxy() takes an optional proxy hostname I and returns it transformed according to the optional I parameter, I, I, and the applicable environment variable, as follows. If I is NULL, take any default value from the C @@ -42,13 +40,11 @@ environment variable, or from C if I is nonzero. If this still does not yield a proxy hostname, take any further default value from the C environment variable, or from C if I is nonzero. -Return the determined proxy host if I is the empty string -or I is not in the exclusion list. -The exclusion list is a list of server hosts separated by C<,> -and/or whitespace. -They may be given via the I parameter. -If it is NULL, the exclusion list is taken from the C -environment variable if set, otherwise from C. +If I is NULL, take any default exclusion value from the C +environment variable, or else from C. +Return the determined proxy host unless the exclusion value, +which is a list of proxy hosts separated by C<,> and/or whitespace, +contains I. Otherwise return NULL. When I is a string delimited by C<[> and C<]>, which are used for IPv6 addresses, the enclosing C<[> and C<]> are stripped prior to comparison. diff --git a/doc/man3/OSSL_HTTP_transfer.pod b/doc/man3/OSSL_HTTP_transfer.pod index 6c03e347fb..eaa0986666 100644 --- a/doc/man3/OSSL_HTTP_transfer.pod +++ b/doc/man3/OSSL_HTTP_transfer.pod @@ -158,7 +158,6 @@ pre-established with a TLS proxy using the HTTP CONNECT method, optionally using proxy client credentials I and I, to connect with TLS protection ultimately to I and I. If the I argument is NULL or the empty string it defaults to "443". -The I and I arguments must not contain CR or LF characters. If the I parameter is > 0 this indicates the maximum number of seconds the connection setup is allowed to take. A value <= 0 enables waiting indefinitely, i.e., no timeout. @@ -179,8 +178,6 @@ else HTTP POST with the contents of I and optional I, where the length of the data in I does not need to be determined in advance: the BIO will be read on-the-fly while sending the request, which supports streaming. The optional list I may contain additional custom HTTP header lines. -The I, I names and values, and I must not contain -CR or LF characters. The I parameter specifies the maximum allowed response content length, where the value 0 indicates no limit. For the meaning of the I, I, I, diff --git a/doc/man3/OSSL_LIB_CTX.pod b/doc/man3/OSSL_LIB_CTX.pod index 013c047339..d9516195eb 100644 --- a/doc/man3/OSSL_LIB_CTX.pod +++ b/doc/man3/OSSL_LIB_CTX.pod @@ -5,7 +5,8 @@ OSSL_LIB_CTX, OSSL_LIB_CTX_get_data, OSSL_LIB_CTX_new, OSSL_LIB_CTX_new_from_dispatch, OSSL_LIB_CTX_new_child, OSSL_LIB_CTX_free, OSSL_LIB_CTX_load_config, -OSSL_LIB_CTX_get0_global_default, OSSL_LIB_CTX_set0_default +OSSL_LIB_CTX_get0_global_default, OSSL_LIB_CTX_set0_default, +OSSL_LIB_CTX_freeze - OpenSSL library context =head1 SYNOPSIS @@ -24,6 +25,7 @@ OSSL_LIB_CTX_get0_global_default, OSSL_LIB_CTX_set0_default OSSL_LIB_CTX *OSSL_LIB_CTX_get0_global_default(void); OSSL_LIB_CTX *OSSL_LIB_CTX_set0_default(OSSL_LIB_CTX *ctx); void *OSSL_LIB_CTX_get_data(OSSL_LIB_CTX *ctx, int index); + void *OSSL_LIB_CTX_freeze(OSSL_LIB_CTX *ctx, const char *propq); =head1 DESCRIPTION @@ -92,10 +94,6 @@ multiple threads on a single I. OSSL_LIB_CTX_free() frees the given I, unless it happens to be the default OpenSSL library context. If the argument is NULL, nothing is done. -Any providers loaded into I are automatically deactivated and freed -as part of the library context cleanup. -Any B pointers obtained from I must not be used after -this call. OSSL_LIB_CTX_get0_global_default() returns a concrete (non NULL) reference to the global default library context. @@ -125,6 +123,32 @@ If ctx is NULL then the function operates on the default library context. OSSL_LIB_CTX_get_data() returns a memory address whose interpretation depends on the index. +OSSL_LIB_CTX_freeze() freezes the method store associated with the +library context, and builds a fast lookup cache which will be used by +subsequent EVP calls to fetch implementations. A frozen method store +may no longer be modified, and operations attempting to do so (such as +loading a new provider) will fail. This function must only be called +from a non-threaded context, before any worker threads have been +dispatched. A frozen method store can not be un-frozen, or frozen again. + +OSSL_LIB_CTX_freeze() builds the lookup cache using an optional propq +query string argument. OSSL_LIB_CTX_freeze() will build a cache of +methods for all algorithms for the NULL property query, and if propq +is non-NULL, it will also cache the methods for all algorithms +matching the propq query string. Once frozen, future method store +lookups using the the NULL propq or the provided propq will be +answered from the cache. Any method store lookups for an algorithm +using a different propq query string will not be answered from the +cache, and will be looked up by the normal slower method. + +OSSL_LIB_CTX_freeze() is intended for use where applications with +worker threads are not able to be structured to pre-fetch and retain +the algorithm methods from the method store prior to use, and which +therefore may pay a considerable performance penalty for the method +store lookup every time an algorithm is used. Applications which can +pre-fetch the methods they need before their use should not use +OSSL_LIB_CTX_freeze(). + =head1 RETURN VALUES OSSL_LIB_CTX_new(), OSSL_LIB_CTX_get0_global_default() and @@ -138,15 +162,20 @@ OSSL_LIB_CTX_load_config() returns 1 on success, 0 on error. OSSL_LIB_CTX_get_data() returns a memory address whose interpretation depends on the index. +OSSL_LIB_CTX_freeze() returns 1 on success, 0 on error. A frozen library context +cannot be frozen again. + =head1 HISTORY All of the functions described on this page were added in OpenSSL 3.0. OSSL_LIB_CTX_get_data() was introduced in OpenSSL 3.4. +OSSL_LIB_CTX_freeze() was introduced in OpenSSL 4.0. + =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/OSSL_PARAM_BLD.pod b/doc/man3/OSSL_PARAM_BLD.pod index b5a2839385..a9dea41211 100644 --- a/doc/man3/OSSL_PARAM_BLD.pod +++ b/doc/man3/OSSL_PARAM_BLD.pod @@ -58,8 +58,7 @@ If the argument is NULL, nothing is done. OSSL_PARAM_BLD_to_param() converts a built up OSSL_PARAM_BLD structure I into an allocated OSSL_PARAM array. The OSSL_PARAM array and all associated storage must be freed by calling -OSSL_PARAM_free(); if the contents of OSSL_PARAM array are confidential call -OSSL_PARAM_clear_free(). +OSSL_PARAM_free() with the functions return value. OSSL_PARAM_BLD_free() can safely be called any time after this function is. =begin comment @@ -178,7 +177,7 @@ private key. OSSL_PARAM_BLD_free(bld); /* Use params */ ... - OSSL_PARAM_clear_free(params); + OSSL_PARAM_free(params); =head2 Example 2 @@ -200,7 +199,7 @@ public key. =head1 SEE ALSO -L, L, L, L +L, L, L =head1 HISTORY diff --git a/doc/man3/OSSL_PROVIDER.pod b/doc/man3/OSSL_PROVIDER.pod index 82c0a85a06..f90b5d7a9e 100644 --- a/doc/man3/OSSL_PROVIDER.pod +++ b/doc/man3/OSSL_PROVIDER.pod @@ -124,11 +124,6 @@ configuration file. OSSL_PROVIDER_unload() unloads the given provider. For a provider added with OSSL_PROVIDER_add_builtin(), this simply runs its teardown function. -It is not necessary to explicitly unload providers before calling -L, as freeing a library context automatically -deactivates and frees all providers associated with it. -OSSL_PROVIDER_unload() must not be called after L -has been called on the associated library context. OSSL_PROVIDER_available() checks if a named provider is available for use. @@ -286,7 +281,7 @@ were added in OpenSSL 3.5. =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/OSSL_STORE_SEARCH.pod b/doc/man3/OSSL_STORE_SEARCH.pod index bbd54676e0..bd512890c6 100644 --- a/doc/man3/OSSL_STORE_SEARCH.pod +++ b/doc/man3/OSSL_STORE_SEARCH.pod @@ -22,8 +22,8 @@ OSSL_STORE_SEARCH_get0_digest typedef struct ossl_store_search_st OSSL_STORE_SEARCH; - OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_name(const X509_NAME *name); - OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_issuer_serial(const X509_NAME *name, + OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_name(X509_NAME *name); + OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_issuer_serial(X509_NAME *name, const ASN1_INTEGER *serial); OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_key_fingerprint(const EVP_MD *digest, @@ -34,7 +34,7 @@ OSSL_STORE_SEARCH_get0_digest void OSSL_STORE_SEARCH_free(OSSL_STORE_SEARCH *search); int OSSL_STORE_SEARCH_get_type(const OSSL_STORE_SEARCH *criterion); - const X509_NAME *OSSL_STORE_SEARCH_get0_name(OSSL_STORE_SEARCH *criterion); + X509_NAME *OSSL_STORE_SEARCH_get0_name(OSSL_STORE_SEARCH *criterion); const ASN1_INTEGER *OSSL_STORE_SEARCH_get0_serial(const OSSL_STORE_SEARCH *criterion); const unsigned char *OSSL_STORE_SEARCH_get0_bytes(const OSSL_STORE_SEARCH @@ -184,7 +184,7 @@ were added in OpenSSL 1.1.1. =head1 COPYRIGHT -Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/PKCS12_SAFEBAG_get0_attrs.pod b/doc/man3/PKCS12_SAFEBAG_get0_attrs.pod index fc92a5695d..8ed67fbdf7 100644 --- a/doc/man3/PKCS12_SAFEBAG_get0_attrs.pod +++ b/doc/man3/PKCS12_SAFEBAG_get0_attrs.pod @@ -11,8 +11,8 @@ PKCS12_SAFEBAG_get0_attrs, PKCS12_get_attr_gen const STACK_OF(X509_ATTRIBUTE) *PKCS12_SAFEBAG_get0_attrs(const PKCS12_SAFEBAG *bag); - const ASN1_TYPE *PKCS12_get_attr_gen(const STACK_OF(X509_ATTRIBUTE) *attrs, - int attr_nid); + ASN1_TYPE *PKCS12_get_attr_gen(const STACK_OF(X509_ATTRIBUTE) *attrs, + int attr_nid); =head1 DESCRIPTION @@ -40,7 +40,7 @@ L =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/PKCS12_add_localkeyid.pod b/doc/man3/PKCS12_add_localkeyid.pod index a386673a50..6d9ff9883e 100644 --- a/doc/man3/PKCS12_add_localkeyid.pod +++ b/doc/man3/PKCS12_add_localkeyid.pod @@ -8,7 +8,7 @@ PKCS12_add_localkeyid - Add the localKeyId attribute to a PKCS#12 safeBag #include - int PKCS12_add_localkeyid(PKCS12_SAFEBAG *bag, const unsigned char *name, + int PKCS12_add_localkeyid(PKCS12_SAFEBAG *bag, const char *name, int namelen); =head1 DESCRIPTION @@ -28,7 +28,7 @@ L =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/PKCS12_gen_mac.pod b/doc/man3/PKCS12_gen_mac.pod index edcbeb5612..752db3bd4a 100644 --- a/doc/man3/PKCS12_gen_mac.pod +++ b/doc/man3/PKCS12_gen_mac.pod @@ -37,8 +37,6 @@ The default key generation mechanism used is PKCS12KDF. PKCS12_verify_mac() verifies the PKCS#12 object's HMAC using the supplied password. -If the PKCS12 macdata contains PBMAC1 an error will occur if the related PBKDF2 -parameters are missing, or if the associated key length is not in the range 1 to 64. PKCS12_setup_mac() sets the MAC part of the PKCS#12 structure with the supplied parameters. diff --git a/doc/man3/PKCS5_PBE_keyivgen.pod b/doc/man3/PKCS5_PBE_keyivgen.pod index eff685c102..f697628db1 100644 --- a/doc/man3/PKCS5_PBE_keyivgen.pod +++ b/doc/man3/PKCS5_PBE_keyivgen.pod @@ -110,13 +110,6 @@ I less than 1 is treated as a single iteration. I is the message digest function used in the derivation. -I is the initialization vector (IV) to use for the encryption algorithm. -If I is NULL, then a random IV will be generated. - -I is the numeric identifier (NID) for the pseudo-random function to -use with PBKDF2. If I is not specified (for example, I is set to 0), -a default PRF is used, which is currently set to SHA-256 (NID_hmacWithSHA256). - Functions ending in _ex() take optional parameters I and I which are used to select appropriate algorithm implementations. @@ -125,9 +118,7 @@ are used to select appropriate algorithm implementations. PKCS5_pbe_set(), PKCS5_pbe_set_ex(), PKCS5_pbe2_set(), PKCS5_pbe2_set_iv(), PKCS5_pbe2_set_iv_ex() and PKCS5_pbe2_set_scrypt() generate an B object which represents an AlgorithmIdentifier containing the algorithm OID and -associated parameters for the PBE algorithm. These functions encode the -key derivation parameters (such as salt and iteration count) and the -encryption parameters (such as the IV) into the ASN.1 structure. +associated parameters for the PBE algorithm. PKCS5_pbkdf2_set() and PKCS5_pbkdf2_set_ex() generate an B object which represents an AlgorithmIdentifier containing the algorithm OID and diff --git a/doc/man3/PKCS5_PBKDF2_HMAC.pod b/doc/man3/PKCS5_PBKDF2_HMAC.pod index d8f1d68c13..3da271bdbf 100644 --- a/doc/man3/PKCS5_PBKDF2_HMAC.pod +++ b/doc/man3/PKCS5_PBKDF2_HMAC.pod @@ -36,9 +36,6 @@ equal to 1. RFC 2898 suggests an iteration count of at least 1000. Any B value less than 1 is invalid; such values will result in failure and raise the PROV_R_INVALID_ITERATION_COUNT error. -Lower bounds checks are provider dependent and are described in the -L B. - B is the message digest function used in the derivation. PKCS5_PBKDF2_HMAC_SHA1() calls PKCS5_PBKDF2_HMAC() with EVP_sha1(). @@ -70,7 +67,7 @@ L =head1 COPYRIGHT -Copyright 2014-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2014-2021 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/PKCS7_decrypt.pod b/doc/man3/PKCS7_decrypt.pod index 3534559d59..aea15937ab 100644 --- a/doc/man3/PKCS7_decrypt.pod +++ b/doc/man3/PKCS7_decrypt.pod @@ -22,14 +22,6 @@ B is an optional set of flags. Although the recipients certificate is not needed to decrypt the data it is needed to locate the appropriate (of possible several) recipients in the PKCS#7 structure. -When RSA PKCS#1 v1.5 Key Transport is in use, the invoked EVP_PKEY_decrypt() -will use implicit rejection mechanism. It always returns the result of RSA -decryption of the symmetric key to avoid Marvin attack. This result is -deterministic and can happen to match the symmetric cipher used for the content -encryption. In case when the certificate is not provided, the last -RecipientInfo producing the key looking valid will be used. It may cause -getting garbage content on decryption. - The following flags can be passed in the B parameter. If the B flag is set MIME headers for type B are deleted @@ -46,9 +38,12 @@ The error can be obtained from ERR_get_error(3) PKCS7_decrypt() must be passed the correct recipient key and certificate. It would be better if it could look up the correct key and certificate from a database. +The lack of single pass processing and need to hold all data in memory as +mentioned in PKCS7_sign() also applies to PKCS7_verify(). + =head1 SEE ALSO -L, L, L +L, L =head1 COPYRIGHT diff --git a/doc/man3/PKCS7_encrypt.pod b/doc/man3/PKCS7_encrypt.pod index 02d00325e5..79c769a776 100644 --- a/doc/man3/PKCS7_encrypt.pod +++ b/doc/man3/PKCS7_encrypt.pod @@ -9,11 +9,11 @@ PKCS7_encrypt_ex, PKCS7_encrypt #include - PKCS7 *PKCS7_encrypt_ex(const STACK_OF(X509) *certs, BIO *in, + PKCS7 *PKCS7_encrypt_ex(STACK_OF(X509) *certs, BIO *in, const EVP_CIPHER *cipher, int flags, OSSL_LIB_CTX *libctx, const char *propq); - PKCS7 *PKCS7_encrypt(const STACK_OF(X509) *certs, BIO *in, - const EVP_CIPHER *cipher, int flags); + PKCS7 *PKCS7_encrypt(STACK_OF(X509) *certs, BIO *in, const EVP_CIPHER *cipher, + int flags); =head1 DESCRIPTION @@ -86,7 +86,7 @@ The B flag was added in OpenSSL 1.0.0. =head1 COPYRIGHT -Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/PKCS7_sign.pod b/doc/man3/PKCS7_sign.pod index 620b3b699d..5c55aa191d 100644 --- a/doc/man3/PKCS7_sign.pod +++ b/doc/man3/PKCS7_sign.pod @@ -9,11 +9,10 @@ PKCS7_sign_ex, PKCS7_sign #include - PKCS7 *PKCS7_sign_ex(X509 *signcert, EVP_PKEY *pkey, - const STACK_OF(X509) *certs, + PKCS7 *PKCS7_sign_ex(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs, BIO *data, int flags, OSSL_LIB_CTX *libctx, const char *propq); - PKCS7 *PKCS7_sign(X509 *signcert, EVP_PKEY *pkey, const STACK_OF(X509) *certs, + PKCS7 *PKCS7_sign(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs, BIO *data, int flags); =head1 DESCRIPTION @@ -123,7 +122,7 @@ The B flag was added in OpenSSL 1.0.0. =head1 COPYRIGHT -Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2002-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/PKCS7_verify.pod b/doc/man3/PKCS7_verify.pod index 3dd30b63bf..b9e1ee3035 100644 --- a/doc/man3/PKCS7_verify.pod +++ b/doc/man3/PKCS7_verify.pod @@ -2,20 +2,16 @@ =head1 NAME -PKCS7_verify, PKCS7_dataVerify, PKCS7_get0_signers - verify a PKCS#7 signedData structure +PKCS7_verify, PKCS7_get0_signers - verify a PKCS#7 signedData structure =head1 SYNOPSIS #include - int PKCS7_verify(PKCS7 *p7, const STACK_OF(X509) *certs, X509_STORE *store, + int PKCS7_verify(PKCS7 *p7, STACK_OF(X509) *certs, X509_STORE *store, BIO *indata, BIO *out, int flags); - int PKCS7_dataVerify(X509_STORE *cert_store, X509_STORE_CTX *ctx, - BIO *bio, PKCS7 *p7, PKCS7_SIGNER_INFO *si); - - STACK_OF(X509) *PKCS7_get0_signers(PKCS7 *p7, const STACK_OF(X509) *certs, - int flags); + STACK_OF(X509) *PKCS7_get0_signers(PKCS7 *p7, STACK_OF(X509) *certs, int flags); =head1 DESCRIPTION @@ -34,27 +30,10 @@ Otherwise I should be NULL, and then the signed data must be in I. The content is written to the BIO I unless it is NULL. I is an optional set of flags, which can be used to modify the operation. -PKCS7_get0_signers() retrieves the signer certificates from I, it does +PKCS7_get0_signers() retrieves the signer's certificates from I, it does B check their validity or whether any signatures are valid. The I and I parameters have the same meanings as in PKCS7_verify(). -PKCS7_dataVerify() operates in a similar fashion to PKCS7_verify, with a few -notable exceptions: - -=over 4 - -=item PKCS7_dataVerify does not support the passing of the I parameter. - -=item PKCS7_dataVerify obtains its signer info from the passed in signer data -via the I parameter, rather than parsing the signers from the PKCS7 object -directly. - -=back - -PKCS7_dataVerify() is available for backwards compatibility with older versions -of OpenSSL, but it is generally recommended that users use the PKCS7_verify() -API instead, as it offers greater flexibility in the verification process. - =head1 VERIFY PROCESS Normally the verify process proceeds as follows. @@ -73,11 +52,8 @@ the I parameter (if it is not NULL). Then they are looked up in any certificates contained in the I structure unless B is set. If any signer's certificates cannot be located the operation fails. -Each signer's certificate is chain verified +Each signer's certificate is chain verified using the B purpose and using the trusted certificate store I if supplied. -The purpose required in this verification is I -unless a different one (or B) has been set in -I using L and unless B is set. Any internal certificates in the message, which may have been added using L, are used as untrusted CAs unless B is set. @@ -135,8 +111,7 @@ timestamp). =head1 RETURN VALUES -PKCS7_verify() and PKCS7_dataVerify() return 1 for a successful verification -and 0 if an error occurs. +PKCS7_verify() returns 1 for a successful verification and 0 if an error occurs. PKCS7_get0_signers() returns all signers or NULL if an error occurred. @@ -154,12 +129,11 @@ be held in memory if it is not detached. =head1 SEE ALSO L, L, L, -L, L, L =head1 COPYRIGHT -Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2002-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/RSA_set_method.pod b/doc/man3/RSA_set_method.pod index 50ace68087..cee191a6cd 100644 --- a/doc/man3/RSA_set_method.pod +++ b/doc/man3/RSA_set_method.pod @@ -138,7 +138,9 @@ and RSA_get_method() return pointers to the respective RSA_METHODs. RSA_set_default_method() returns no value. -RSA_set_method() returns 1 for success. It always succeeds. +RSA_set_method() returns a pointer to the old RSA_METHOD implementation +that was replaced. The return type may be replaced with a B +declaration in a future release. RSA_new_method() returns NULL and sets an error code that can be obtained by L if the allocation fails. Otherwise @@ -169,7 +171,7 @@ was replaced to always return NULL in OpenSSL 1.1.1. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_CIPHER_get_name.pod b/doc/man3/SSL_CIPHER_get_name.pod index d0cee8adf1..4a159a68b8 100644 --- a/doc/man3/SSL_CIPHER_get_name.pod +++ b/doc/man3/SSL_CIPHER_get_name.pod @@ -46,11 +46,13 @@ B is NULL, it returns "(NONE)". SSL_CIPHER_standard_name() returns a pointer to the standard RFC name of B. If the B is NULL, it returns "(NONE)". If the B -has no standard name, it returns B. +has no standard name, it returns B. If B was defined in both +SSLv3 and TLS, it returns the TLS name. OPENSSL_cipher_name() returns a pointer to the OpenSSL name of B. If the B is NULL, or B has no corresponding OpenSSL name, -it returns "(NONE)". +it returns "(NONE)". Where both exist, B should be the TLS name rather +than the SSLv3 name. SSL_CIPHER_get_bits() returns the number of secret bits used for B. If B is NULL, 0 is returned. diff --git a/doc/man3/SSL_COMP_add_compression_method.pod b/doc/man3/SSL_COMP_add_compression_method.pod index 56f708ca88..4b32023959 100644 --- a/doc/man3/SSL_COMP_add_compression_method.pod +++ b/doc/man3/SSL_COMP_add_compression_method.pod @@ -40,7 +40,7 @@ maintain the internal table of compression methods. =head1 NOTES -The TLS standard allows the integration of compression methods +The TLS standard (or SSLv3) allows the integration of compression methods into the communication. The TLS RFC does however not specify compression methods or their corresponding identifiers, so there is currently no compatible way to integrate compression with unknown peers. It is therefore currently not @@ -48,7 +48,7 @@ recommended to integrate compression into applications. Applications for non-public use may agree on certain compression methods. Using different compression methods with the same identifier will lead to connection failure. -An OpenSSL client speaking a protocol that allows compression (TLSv1) +An OpenSSL client speaking a protocol that allows compression (SSLv3, TLSv1) will unconditionally send the list of all compression methods enabled with SSL_COMP_add_compression_method() to the server during the handshake. Unlike the mechanisms to set a cipher list, there is no method available to diff --git a/doc/man3/SSL_CONF_CTX_set_flags.pod b/doc/man3/SSL_CONF_CTX_set_flags.pod index c60d017aa6..78c3ce7585 100644 --- a/doc/man3/SSL_CONF_CTX_set_flags.pod +++ b/doc/man3/SSL_CONF_CTX_set_flags.pod @@ -28,9 +28,8 @@ Currently the following B values are recognised: =item SSL_CONF_FLAG_CMDLINE, SSL_CONF_FLAG_FILE -recognise options intended for command line or configuration file use. One of -these flags, but not both, must be set. If an attempt is made to set one of -these flags when the other is already set then the new flag is ignored. +recognise options intended for command line or configuration file use. At +least one of these flags must be set. =item SSL_CONF_FLAG_CLIENT, SSL_CONF_FLAG_SERVER @@ -76,7 +75,7 @@ These functions were added in OpenSSL 1.0.2. =head1 COPYRIGHT -Copyright 2012-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2012-2016 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_CONF_cmd.pod b/doc/man3/SSL_CONF_cmd.pod index 15f969eb61..3b84f16074 100644 --- a/doc/man3/SSL_CONF_cmd.pod +++ b/doc/man3/SSL_CONF_cmd.pod @@ -177,14 +177,16 @@ respectively: $ openssl list -tls1_2 -tls-groups $ openssl list -tls1_3 -tls-groups -The recommended groups for TLS 1.3 are presently documented in the default -TLS group list in the OpenSSL code base. Starting with OpenSSL 3.5, the -hybrid algorithm B is first in this default list. -It mitigates against threats from future quantum computers while -still providing state-of-the-art classical key exchange protection. +The recommended groups (in order of decreasing performance) for TLS 1.3 are presently: -Further details regarding post-quantum algorithm considerations are documented -in the HISTORY section below. +B, +B, +B, +and +B. + +The stronger security margins of the last two, come at a significant +performance penalty. An enriched alternative syntax, that enables clients to send multiple keyshares and allows servers to prioritise some groups over others, is described in @@ -246,7 +248,7 @@ See L for more information. =item B<-min_protocol> I, B<-max_protocol> I Sets the minimum and maximum supported protocol. -Currently supported protocol values are B, B, +Currently supported protocol values are B, B, B, B, B for TLS; B, B for DTLS, and B for no limit. If either the lower or upper bound is not specified then only the other bound @@ -309,15 +311,12 @@ operations are permitted. =item B<-no_ssl3>, B<-no_tls1>, B<-no_tls1_1>, B<-no_tls1_2>, B<-no_tls1_3> -Disables protocol support for TLSv1.0, TLSv1.1, TLSv1.2 or TLSv1.3 by -setting the corresponding options B, +Disables protocol support for SSLv3, TLSv1.0, TLSv1.1, TLSv1.2 or TLSv1.3 by +setting the corresponding options B, B, B, B and B respectively. These options are deprecated, use B<-min_protocol> and B<-max_protocol> instead. -Note that B<-no_ssl3> is a no-op since support for SSLv3 was removed in OpenSSL -4.0. - =item B<-anti_replay>, B<-no_anti_replay> Switches replay protection, on or off respectively. With replay protection on, @@ -496,7 +495,7 @@ This is a synonym for the "Groups" command. This sets the minimum supported SSL, TLS or DTLS version. -Currently supported protocol values are B, B, +Currently supported protocol values are B, B, B, B, B, B and B. The SSL and TLS bounds apply only to TLS-based contexts, while the DTLS bounds apply only to DTLS-based contexts. @@ -508,7 +507,7 @@ The value B applies to both types of contexts and disables the limits. This sets the maximum supported SSL, TLS or DTLS version. -Currently supported protocol values are B, B, +Currently supported protocol values are B, B, B, B, B, B and B. The SSL and TLS bounds apply only to TLS-based contexts, while the DTLS bounds apply only to DTLS-based contexts. @@ -531,7 +530,7 @@ effect. Only enabling some protocol versions does not disable the other protocol versions. -Currently supported protocol values are B, B, +Currently supported protocol values are B, B, B, B, B, B and B. The special value B refers to all supported versions. @@ -563,7 +562,7 @@ B: SSL/TLS compression support, disabled by default. Inverse of B. B: use empty fragments as a countermeasure against a -TLS 1.0 protocol vulnerability affecting CBC ciphers. It +SSL 3.0/TLS 1.0 protocol vulnerability affecting CBC ciphers. It is set by default. Inverse of B. B: enable various bug workarounds. Same as B. @@ -576,7 +575,7 @@ B. Only used by servers. B: use server and not client preference order when determining which cipher suite, signature algorithm or elliptic curve -(TLS 1.2) or group (TLS 1.3) to use for an incoming connection. +(TLS 1.2) or group (TSL 1.3) to use for an incoming connection. Equivalent to B. Only used by servers. B: prioritizes ChaCha ciphers when the client has a @@ -731,15 +730,16 @@ argument. The order of operations is significant. This can be used to set either defaults or values which cannot be overridden. For example if an application calls: - SSL_CONF_cmd(ctx, "Protocol", "-TLSv1"); + SSL_CONF_cmd(ctx, "Protocol", "-SSLv3"); SSL_CONF_cmd(ctx, userparam, uservalue); -it will disable TLSv1 support by default but the user can override it. If +it will disable SSLv3 support by default but the user can override it. If however the call sequence is: SSL_CONF_cmd(ctx, userparam, uservalue); - SSL_CONF_cmd(ctx, "Protocol", "-TLSv1"); -TLSv1 is B disabled and attempt to override this by the user are + SSL_CONF_cmd(ctx, "Protocol", "-SSLv3"); + +SSLv3 is B disabled and attempt to override this by the user are ignored. By checking the return code of SSL_CONF_cmd() it is possible to query if a @@ -794,22 +794,22 @@ Set supported signature algorithms: There are various ways to select the supported protocols. -This sets the minimum protocol version to TLSv1.1, and so disables TLSv1. +This set the minimum protocol version to TLSv1, and so disables SSLv3. This is the recommended way to disable protocols. - SSL_CONF_cmd(ctx, "MinProtocol", "TLSv1.1"); + SSL_CONF_cmd(ctx, "MinProtocol", "TLSv1"); -The following also disables TLSv1: +The following also disables SSLv3: - SSL_CONF_cmd(ctx, "Protocol", "-TLSv1"); + SSL_CONF_cmd(ctx, "Protocol", "-SSLv3"); The following will first enable all protocols, and then disable -TLSv1. +SSLv3. If no protocol versions were disabled before this has the same effect as -"-TLSv1", but if some versions were disables this will re-enable them before -disabling TLSv1. +"-SSLv3", but if some versions were disables this will re-enable them before +disabling SSLv3. - SSL_CONF_cmd(ctx, "Protocol", "ALL,-TLSv1"); + SSL_CONF_cmd(ctx, "Protocol", "ALL,-SSLv3"); Only enable TLSv1.2: @@ -865,12 +865,12 @@ added in OpenSSL 3.2. B was added in OpenSSL 3.3. -OpenSSL 3.5 introduced support for post-quantum (PQ) TLS key exchange via the +OpenSSL 3.5 introduces support for post-quantum (PQ) TLS key exchange via the B, B and B TLS groups. These are based on the underlying B, B and B algorithms from FIPS 203. -OpenSSL 3.5 also introduced support for three B ECDH PQ key exchange +OpenSSL 3.5 also introduces support for three B ECDH PQ key exchange TLS groups: B, B and B. They offer CPU performance comparable to the associated ECDH group, though at @@ -881,15 +881,11 @@ group. Also its key exchange messages at close to 1700 bytes are larger than the roughly 1200 bytes for the first two groups. -OpenSSL 4.0 introduced the B (also known as C) key -exchange group as specified in RFC8998, and B, which is a -hybrid of the B group with B. - As of OpenSSL 3.5 key exchange group names are case-insensitive. =head1 COPYRIGHT -Copyright 2012-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2012-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_CTX_dane_enable.pod b/doc/man3/SSL_CTX_dane_enable.pod index 7d6623544f..d558e63895 100644 --- a/doc/man3/SSL_CTX_dane_enable.pod +++ b/doc/man3/SSL_CTX_dane_enable.pod @@ -66,7 +66,7 @@ L if (and only if) you want to enable DANE for that connection. The B argument specifies the RFC7671 TLSA base domain, which will be the primary peer reference identifier for certificate name checks. -Additional server names can be specified via L. +Additional server names can be specified via L. The B is used as the default SNI hint if none has yet been specified via L. @@ -216,7 +216,7 @@ the lifetime of the SSL connection. */ SSL_dane_set_flags(ssl, DANE_FLAG_NO_DANE_EE_NAMECHECKS); - if (!SSL_add1_dnsname(ssl, nexthop_domain)) + if (!SSL_add1_host(ssl, nexthop_domain)) /* error */ SSL_set_hostflags(ssl, X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS); @@ -353,7 +353,7 @@ L with B equal to B. L, L, -L, +L, L, L, L, @@ -376,7 +376,7 @@ These functions were added in OpenSSL 1.1.0. =head1 COPYRIGHT -Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2016-2023 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_CTX_load_verify_locations.pod b/doc/man3/SSL_CTX_load_verify_locations.pod index b127ac3868..7e3b2771f2 100644 --- a/doc/man3/SSL_CTX_load_verify_locations.pod +++ b/doc/man3/SSL_CTX_load_verify_locations.pod @@ -27,20 +27,18 @@ SSL_CTX_set_default_verify_store, SSL_CTX_load_verify_locations =head1 DESCRIPTION -SSL_CTX_load_verify_dir(), SSL_CTX_load_verify_file(), -SSL_CTX_load_verify_store(), and SSL_CTX_load_verify_locations() specify -the locations at which trusted CA certificates are located. -For details, see the L below. -The SSL context I must not be NULL. +SSL_CTX_load_verify_locations(), SSL_CTX_load_verify_dir(), +SSL_CTX_load_verify_file(), SSL_CTX_load_verify_store() specifies the +locations for B, at which CA certificates for verification purposes +are located. The certificates available via B, B and +B are trusted. B B be NULL Details of the certificate verification and chain checking process are described in L. -SSL_CTX_set_default_verify_paths() specifies the default locations from -which trusted CA certificates in PEM format are loaded when needed. -For details, see the L below. - -There is one default directory, one default file, and one default store. +SSL_CTX_set_default_verify_paths() specifies that the default locations from +which CA certificates are loaded should be used. There is one default directory, +one default file and one default store. The default CA certificates directory is called F in the default OpenSSL directory, and this is also the default store. Alternatively the B environment variable can be defined to @@ -49,7 +47,7 @@ The default CA certificates file is called F in the default OpenSSL directory. Alternatively the B environment variable can be defined to override this location. -I must not be NULL. +B B be NULL. SSL_CTX_set_default_verify_dir() is similar to SSL_CTX_set_default_verify_paths() except that just the default directory is @@ -65,63 +63,51 @@ used. =head1 NOTES -The CA certificates specified by calling the above functions are used -as trust anchors for peer certificate verification purposes unless overridden -by L, L, -L, or L. -They are also used as trust anchors for -building the client or server's own certificate chain unless overridden -by L, L, -L, or L. - -The I is processed on execution of the SSL_CTX_load_verify_locations() -and SSL_CTX_load_verify_file() functions. -With SSL_CTX_load_verify_file() it must not be NULL. -If I is not NULL, it points to a file of CA certificates in PEM +If B is not NULL, it points to a file of CA certificates in PEM format. The file can contain several CA certificates identified by -----BEGIN CERTIFICATE----- ... (CA certificate in base64 encoding) ... -----END CERTIFICATE----- -sequences. Before, between, and after the certificates text is allowed, -which can be used, e.g., for descriptions of the certificates. +sequences. Before, between, and after the certificates text is allowed +which can be used e.g. for descriptions of the certificates. -The I is not immediately processed on execution of the -SSL_CTX_load_verify_locations() and SSL_CTX_load_verify_dir() functions. -With SSL_CTX_load_verify_dir() it must not be NULL. -If I is not NULL, it points to a directory containing CA certificates -in PEM format. The files each contain exactly one CA certificate. The files are +The B is processed on execution of the SSL_CTX_load_verify_locations() +function. + +If B is not NULL, it points to a directory containing CA certificates +in PEM format. The files each contain one CA certificate. The files are looked up by the CA subject name hash value, which must hence be available. -If more than one CA certificate with the same subject name hash value exist, the -extension must be different (e.g., C<9d66eef0.0>, C<9d66eef0.1>, etc). The search +If more than one CA certificate with the same name hash value exist, the +extension must be different (e.g. 9d66eef0.0, 9d66eef0.1 etc). The search is performed in the ordering of the extension number, regardless of other properties of the certificates. -Use the L utility to create the necessary links. +Use the B utility to create the necessary links. -The certificate files in I are only looked up when required, e.g., when -building the client or server's own certificate chain -or when verifying a peer certificate. +The certificates in B are only looked up when required, e.g. when +building the certificate chain or when actually performing the verification +of a peer certificate. When looking up CA certificates for chain building, the OpenSSL library -will search for suitable certificates first in I, then in I. +will search for suitable certificates first in B, then in B. Details of the chain building process are described in L. -I must not be NULL. It must be a URI to a store, which may +If B is not NULL, it's a URI for to a store, which may represent a single container or a whole catalogue of containers. -If I starts with the scheme C, it is treated like a local file -or directory. See also ossl_store-file(7). +Apart from the B not necessarily being a local file or +directory, it's generally treated the same way as a B. In server mode, when requesting a client certificate, the server must send the list of CAs of which it will accept client certificates. This list -is not influenced by the contents of I or I and must +is not influenced by the contents of B or B and must explicitly be set using the L family of functions. When building its own certificate chain, an OpenSSL client/server will -try to fill in missing certificates from I/I, if the +try to fill in missing certificates from B/B, if the certificate chain was not explicitly specified (see L, L. @@ -143,7 +129,7 @@ For SSL_CTX_load_verify_locations the following return values can occur: =item Z<>0 -The operation failed because both I and I are NULL or the +The operation failed because B and B are NULL or the processing at one of the locations specified failed. Check the error stack to find out the reason. @@ -168,29 +154,21 @@ ca1.pem ca2.pem ca3.pem: openssl x509 -in $i -text >> CAfile.pem done -Prepare the directory /path/to/certs containing several CA certificates -for use as I: +Prepare the directory /some/where/certs containing several CA certificates +for use as B: - openssl rehash /path/to/certs + cd /some/where/certs + c_rehash . =head1 SEE ALSO -L, -L, -L, -L, -L, -L, -L, -L, -L, +L, L, L, L, L, L, -L, -L, ossl_store-file(7) +L =head1 COPYRIGHT diff --git a/doc/man3/SSL_CTX_new.pod b/doc/man3/SSL_CTX_new.pod index 84433459a5..627d9e7f0d 100644 --- a/doc/man3/SSL_CTX_new.pod +++ b/doc/man3/SSL_CTX_new.pod @@ -2,9 +2,15 @@ =head1 NAME -SSL_CTX_new, SSL_CTX_new_ex, SSL_CTX_up_ref, TLS_method, TLS_server_method, -TLS_client_method, SSLv23_method, SSLv23_server_method, SSLv23_client_method, -DTLS_method, DTLS_server_method, DTLS_client_method +TLSv1_2_method, TLSv1_2_server_method, TLSv1_2_client_method, +SSL_CTX_new, SSL_CTX_new_ex, SSL_CTX_up_ref, SSLv3_method, +SSLv3_server_method, SSLv3_client_method, TLSv1_method, TLSv1_server_method, +TLSv1_client_method, TLSv1_1_method, TLSv1_1_server_method, +TLSv1_1_client_method, TLS_method, TLS_server_method, TLS_client_method, +SSLv23_method, SSLv23_server_method, SSLv23_client_method, DTLS_method, +DTLS_server_method, DTLS_client_method, DTLSv1_method, DTLSv1_server_method, +DTLSv1_client_method, DTLSv1_2_method, DTLSv1_2_server_method, +DTLSv1_2_client_method - create a new SSL_CTX object as framework for TLS/SSL or DTLS enabled functions @@ -25,10 +31,46 @@ functions const SSL_METHOD *SSLv23_server_method(void); const SSL_METHOD *SSLv23_client_method(void); + #ifndef OPENSSL_NO_SSL3_METHOD + const SSL_METHOD *SSLv3_method(void); + const SSL_METHOD *SSLv3_server_method(void); + const SSL_METHOD *SSLv3_client_method(void); + #endif + + #ifndef OPENSSL_NO_TLS1_METHOD + const SSL_METHOD *TLSv1_method(void); + const SSL_METHOD *TLSv1_server_method(void); + const SSL_METHOD *TLSv1_client_method(void); + #endif + + #ifndef OPENSSL_NO_TLS1_1_METHOD + const SSL_METHOD *TLSv1_1_method(void); + const SSL_METHOD *TLSv1_1_server_method(void); + const SSL_METHOD *TLSv1_1_client_method(void); + #endif + + #ifndef OPENSSL_NO_TLS1_2_METHOD + const SSL_METHOD *TLSv1_2_method(void); + const SSL_METHOD *TLSv1_2_server_method(void); + const SSL_METHOD *TLSv1_2_client_method(void); + #endif + const SSL_METHOD *DTLS_method(void); const SSL_METHOD *DTLS_server_method(void); const SSL_METHOD *DTLS_client_method(void); + #ifndef OPENSSL_NO_DTLS1_METHOD + const SSL_METHOD *DTLSv1_method(void); + const SSL_METHOD *DTLSv1_server_method(void); + const SSL_METHOD *DTLSv1_client_method(void); + #endif + + #ifndef OPENSSL_NO_DTLS1_2_METHOD + const SSL_METHOD *DTLSv1_2_method(void); + const SSL_METHOD *DTLSv1_2_server_method(void); + const SSL_METHOD *DTLSv1_2_client_method(void); + #endif + =head1 DESCRIPTION SSL_CTX_new_ex() creates a new B object, which holds various @@ -78,6 +120,15 @@ can be one of the following: =over 4 +=item TLS_method(), TLS_server_method(), TLS_client_method() + +These are the general-purpose I SSL/TLS methods. +The actual protocol version used will be negotiated to the highest version +mutually supported by the client and the server. +The supported protocols are SSLv3, TLSv1, TLSv1.1, TLSv1.2 and TLSv1.3. +Applications should use these methods, and avoid the version-specific +methods described below, which are deprecated. + =item SSLv23_method(), SSLv23_server_method(), SSLv23_client_method() These functions do not exist anymore, they have been renamed to @@ -87,17 +138,41 @@ ones by preprocessor macros, to ensure that existing code which uses the old function names still compiles. However, using the old function names is deprecated and new code should call the new functions instead. -=item TLS_method(), TLS_server_method(), TLS_client_method() +=item TLSv1_2_method(), TLSv1_2_server_method(), TLSv1_2_client_method() -These are the general-purpose I SSL/TLS methods. -The actual protocol version used will be negotiated to the highest version -mutually supported by the client and the server. -The supported protocols are TLSv1, TLSv1.1, TLSv1.2 and TLSv1.3. +A TLS/SSL connection established with these methods will only understand the +TLSv1.2 protocol. These methods are deprecated. + +=item TLSv1_1_method(), TLSv1_1_server_method(), TLSv1_1_client_method() + +A TLS/SSL connection established with these methods will only understand the +TLSv1.1 protocol. These methods are deprecated. + +=item TLSv1_method(), TLSv1_server_method(), TLSv1_client_method() + +A TLS/SSL connection established with these methods will only understand the +TLSv1 protocol. These methods are deprecated. + +=item SSLv3_method(), SSLv3_server_method(), SSLv3_client_method() + +A TLS/SSL connection established with these methods will only understand the +SSLv3 protocol. +The SSLv3 protocol is deprecated and should not be used. =item DTLS_method(), DTLS_server_method(), DTLS_client_method() These are the version-flexible DTLS methods. -The supported protocols are DTLS 1.0 and DTLS 1.2. +Currently supported protocols are DTLS 1.0 and DTLS 1.2. + +=item DTLSv1_2_method(), DTLSv1_2_server_method(), DTLSv1_2_client_method() + +These are the version-specific methods for DTLSv1.2. +These methods are deprecated. + +=item DTLSv1_method(), DTLSv1_server_method(), DTLSv1_client_method() + +These are the version-specific methods for DTLSv1. +These methods are deprecated. =back @@ -107,6 +182,8 @@ callbacks, the keys and certificates and the options to their default values. TLS_method(), TLS_server_method(), TLS_client_method(), DTLS_method(), DTLS_server_method() and DTLS_client_method() are the I methods. +All other methods only support one specific protocol version. +Use the I methods instead of the version specific methods. If you want to limit the supported protocols for the version flexible methods you can use L, @@ -172,11 +249,9 @@ All version-specific methods were deprecated in OpenSSL 1.1.0. SSL_CTX_new_ex() was added in OpenSSL 3.0. -All version-specific methods were removed in OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_CTX_set0_CA_list.pod b/doc/man3/SSL_CTX_set0_CA_list.pod index 0435d3107b..64e8117f92 100644 --- a/doc/man3/SSL_CTX_set0_CA_list.pod +++ b/doc/man3/SSL_CTX_set0_CA_list.pod @@ -70,11 +70,6 @@ SSL_set_client_CA_list() sets the B of CAs sent to the client when requesting a client certificate for the chosen B, overriding the setting valid for B's SSL_CTX object. Ownership of B is transferred to B and it should not be freed by the caller. -Note that passing NULL for B does not clear the CA list; instead, the -setting from B's SSL_CTX object will be used. Note also that passing an -empty stack created with sk_X509_NAME_new_null() will clear the per-connection -client CA list, but during the handshake the generic CA list (set via -L) may still be used as a fallback. SSL_CTX_get_client_CA_list() returns the list of client CAs explicitly set for B using SSL_CTX_set_client_CA_list(). The returned list should not be freed @@ -183,7 +178,7 @@ L =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_CTX_set1_curves.pod b/doc/man3/SSL_CTX_set1_curves.pod index f791c28682..352fe34347 100755 --- a/doc/man3/SSL_CTX_set1_curves.pod +++ b/doc/man3/SSL_CTX_set1_curves.pod @@ -4,8 +4,7 @@ SSL_CTX_set1_groups, SSL_CTX_set1_groups_list, SSL_set1_groups, SSL_set1_groups_list, SSL_get1_groups, SSL_get0_iana_groups, -SSL_get0_ec_point_formats, SSL_get_shared_group, SSL_get_negotiated_group, -SSL_CTX_set1_curves, +SSL_get_shared_group, SSL_get_negotiated_group, SSL_CTX_set1_curves, SSL_CTX_set1_curves_list, SSL_set1_curves, SSL_set1_curves_list, SSL_get1_curves, SSL_get_shared_curve, SSL_CTX_get0_implemented_groups - EC supported curve functions @@ -14,23 +13,22 @@ SSL_get1_curves, SSL_get_shared_curve, SSL_CTX_get0_implemented_groups #include - int SSL_CTX_set1_groups(SSL_CTX *ctx, const int *glist, int glistlen); - int SSL_CTX_set1_groups_list(SSL_CTX *ctx, const char *list); + int SSL_CTX_set1_groups(SSL_CTX *ctx, int *glist, int glistlen); + int SSL_CTX_set1_groups_list(SSL_CTX *ctx, char *list); - int SSL_set1_groups(SSL *ssl, const int *glist, int glistlen); - int SSL_set1_groups_list(SSL *ssl, const char *list); + int SSL_set1_groups(SSL *ssl, int *glist, int glistlen); + int SSL_set1_groups_list(SSL *ssl, char *list); int SSL_get1_groups(SSL *ssl, int *groups); int SSL_get0_iana_groups(SSL *ssl, uint16_t **out); - int SSL_get0_ec_point_formats(SSL *ssl, const unsigned char **plst); int SSL_get_shared_group(SSL *s, int n); int SSL_get_negotiated_group(SSL *s); - int SSL_CTX_set1_curves(SSL_CTX *ctx, const int *clist, int clistlen); - int SSL_CTX_set1_curves_list(SSL_CTX *ctx, const char *list); + int SSL_CTX_set1_curves(SSL_CTX *ctx, int *clist, int clistlen); + int SSL_CTX_set1_curves_list(SSL_CTX *ctx, char *list); - int SSL_set1_curves(SSL *ssl, const int *clist, int clistlen); - int SSL_set1_curves_list(SSL *ssl, const char *list); + int SSL_set1_curves(SSL *ssl, int *clist, int clistlen); + int SSL_set1_curves_list(SSL *ssl, char *list); int SSL_get1_curves(SSL *ssl, int *curves); int SSL_get_shared_curve(SSL *s, int n); @@ -42,13 +40,13 @@ SSL_get1_curves, SSL_get_shared_curve, SSL_CTX_get0_implemented_groups For all of the functions below that set the supported groups there must be at least one group in the list. A number of these functions identify groups via a -unique integer B value. However, support for some groups may be added by -external providers. In this case there will be no B assigned for the group. +unique integer NID value. However, support for some groups may be added by +external providers. In this case there will be no NID assigned for the group. When setting such groups applications should use the "list" form of these functions (i.e. SSL_CTX_set1_groups_list() and SSL_set1_groups_list()). SSL_CTX_set1_groups() sets the supported groups for B to B -groups in the array B. The array consist of all B of supported groups. +groups in the array B. The array consist of all NIDs of supported groups. The supported groups for B include: B, B, @@ -75,27 +73,20 @@ B is set, the order of the elements in the array determines the selected group. Otherwise, the order is ignored and the client's order determines the selection. -For a TLS 1.3 server, the groups determine the selected group, but selection is -more complex. -A TLS 1.3 client sends both a group list and predicted keyshares for a subset -of groups. -A server choosing a group outside the client's predicted subset incurs an extra -roundtrip. -However, in some situations, the most preferred group may not be predicted. - -When groups are specified via SSL_CTX_set1_groups() as a list of B -values, OpenSSL considers all supported groups in I to be comparable in -security and prioritises avoiding roundtrips above either client or server -preference order. -If an application uses an external provider to extend OpenSSL with, e.g., a -post-quantum algorithm, this behavior may allow a network attacker to downgrade -connections to a weaker algorithm. -It is therefore recommended to use SSL_CTX_set1_groups_list() instead, making -it possible to specify group tuples as described below. +For a TLS 1.3 server, the groups determine the selected group, but +selection is more complex. A TLS 1.3 client sends both a group list as well as a +predicted subset of groups. Choosing a group outside the predicted subset incurs +an extra roundtrip. However, in some situations, the most preferred group may +not be predicted. OpenSSL considers all supported groups in I to be comparable +in security and prioritizes avoiding roundtrips above either client or server +preference order. If an application uses an external provider to extend OpenSSL +with, e.g., a post-quantum algorithm, this behavior may allow a network attacker +to downgrade connections to a weaker algorithm. It is therefore recommended +to use SSL_CTX_set1_groups_list() with the ability to specify group tuples. SSL_CTX_set1_groups_list() sets the supported groups for B to string I. In contrast to SSL_CTX_set1_groups(), the names of the -groups, rather than their B, are used. +groups, rather than their NIDs, are used. The commands below list the available groups for TLS 1.2 and TLS 1.3, respectively: @@ -111,76 +102,30 @@ The preferred group names are those defined by L. The I can be used to define several group tuples of comparable security -levels, and can specify which predicted key shares should be sent by a client. -Group tuples are used by OpenSSL TLS servers to decide whether to request a -stronger keyshare than those predicted by sending a Hello Retry Request -(B) even if some of the predicted groups are supported. -OpenSSL clients largely ignore tuple boundaries, and pay attention only to the -overall order of I elements and which groups are selected as predicted -keyshares as described below. -Tuple boundaries do however affect the behaviour of keyshare predictions -that C from an unsupported or deleted tuple element to the first -remaining element of the same tuple, when no other elements of that tuple -are marked as predicted keyshares. - -The specified list elements can optionally be ignored if not implemented +levels, and can specify which key shares should be sent by a client. +The specified list elements can optionally be ignored, if not implemented (listing unknown groups otherwise results in error). -It is also possible to specify the built-in default set of groups, and to -explicitly remove a group from that list. +It is also possible to specify the built-in default set of groups, and to explicitly +remove a group from that list. -In its simplest legacy form, the string I is just a colon separated list -of group names, for example "P-521:P-384:P-256:X25519:ffdhe2048". -The first group listed will in this case be used as the sole predicted -B sent by a client in a TLSv1.3 B. -The list should be in order of preference with the most preferred group first. +In its simplest form, the string I is just a colon separated list +of group names, for example "P-521:P-384:P-256:X25519:ffdhe2048". The first +group listed will also be used for the B sent by a client in a +TLSv1.3 B. For servers note the discussion above. The list should +be in order of preference with the most preferred group first. -A more expressive syntax supports definition of group tuples of comparable -security by separating them from each other with C characters. +Group tuples of comparable security are defined by separating them from each +other by a tuple separator C. Keyshares to be sent by a client are specified +by prepending a C<*> to the group name, while any C<*> will be ignored by a +server. The following string I for example defines three tuples when +used on the server-side, and triggers the generation of three key shares +when used on the client-side: P-521:*P-256/*P-384/*X25519:P-384:ffdhe2048. -The predicted keyshares to be sent by clients can be explicitly specified by -adding a C<*> prefix to the associated group name. -These C<*> prefixes are ignored by servers. - -If a group name is prefixed with the C character, it will be ignored if an -implementation is missing. -Otherwise, listing an unknown group name will cause a failure to parse the -I. -Note that whether a group is known or not may depend on the OpenSSL version, -how OpenSSL was compiled and/or which providers are loaded. -Make sure you have the correct spelling of the group name and when in doubt -prefix it with a C to handle configurations in which it might nevertheless -be unknown. - -If a group name is prefixed with the C<-> character, it will be removed from -the list of groups specified up to that point. -It can be added again if specified later. -Removal of groups that have not been included earlier in the list is silently -ignored. - -The pseudo group name C can be used to select the OpenSSL built-in -default list of groups. -Prepending one or more groups to C using only C<:> separators prepends those -groups to the built-in default list's first tuple. -Additional tuples can be prepended by use of the C separator. -Appending a set of groups to C using only C<:> separators appends those -groups to the built-in default list's last tuple. -Additional tuples can be appended by use of the C separator. - -The B list selects B as one of the predicted keyshares. -In rare cases this can lead to failures or timeouts because the resulting -larger TLS Client Hello message may no longer fit in a single TCP segment and -firewall software may erroneously disrupt the TLS handshake. -If this is an issue or concern, prepending C without a C<*> -prefix leads to its occurrence in the default list to be ignored as a duplicate, -and along with that also the keyshare prediction. -The group will then only be selected by servers that specifically expect it, -after a Hello Retry Request (HRR). -Servers that specifically prefer B, are much less likely to be -found behind problematic firewalls. - -The following string I for example defines three tuples when used on the -server-side, and triggers the generation of three key shares when used on the -client-side: P-521:*P-256/*P-384/*X25519:P-384:ffdhe2048. +If a group name is preceded with the C character, it will be ignored if an +implementation is missing. If a group name is preceded with the C<-> character, it +will be removed from the list of groups if present (including not sending a +key share for this group), ignored otherwise. The pseudo group name +C can be used to select the OpenSSL built-in default list of groups. For a TLS 1.3 client, all the groups in the string I are added to the supported groups extension of a C, in the order in which they are listed, @@ -248,19 +193,6 @@ identifiers, as assigned by IANA. The group list is returned in the same order that was received in the ClientHello. The return value is the number of groups, not the number of bytes written. -SSL_get0_ec_point_formats() retrieves the peer's B -extension as a byte array of B values in the -order received. If the peer sent the extension, B<*plst> is set to an -internal buffer holding the list and its length is returned; otherwise -the return value is 0 and B<*plst> is left unchanged. The returned -pointer is owned by the B connection and must not be freed. The -point format no longer affects certificate selection or acceptance. - -The B extension applies only to TLS 1.2 and below, but -the peer's list is recorded even when TLS 1.3 is ultimately negotiated, -since a TLS 1.3 B may still carry the extension for -backward compatibility. - SSL_get_shared_group() returns the NID of the shared group B for a server-side SSL B. If B is -1 then the total number of shared groups is returned, which may be zero. Other than for diagnostic purposes, @@ -319,10 +251,6 @@ SSL_get1_groups() returns the number of groups, which may be zero. SSL_get0_iana_groups() returns the number of (uint16_t) groups, which may be zero. -SSL_get0_ec_point_formats() returns the number of point formats sent by -the peer in its B extension, or 0 if no such extension -was received. - SSL_get_shared_group() returns the NID of shared group B or NID_undef if there is no shared group B; or the total number of shared groups if B is -1. @@ -402,11 +330,7 @@ SSL_set1_groups_list() was added in OpenSSL 3.3. Support for B was added in OpenSSL 3.5. -OpenSSL 3.5 also introduced support for group tuples, the C<*> keyshare -prediction prefix, the C tuple separator, the C pseudo-group, -and the C<-> prefix. - -OpenSSL 3.5 also introduced support for three I ECDH PQ key exchange +OpenSSL 3.5 also introduces support for three I ECDH PQ key exchange TLS groups: B, B and B. They offer CPU performance comparable to the associated ECDH group, though at @@ -417,10 +341,6 @@ group. Also its key exchange messages at close to 1700 bytes are larger than the roughly 1200 bytes for the first two groups. -OpenSSL 4.0 introduced the B (also known as C) key -exchange group as specified in RFC8998, and B, which is a -hybrid of the B group with B. - As of OpenSSL 3.5 key exchange group names are case-insensitive. B was first implemented in OpenSSL 3.5. @@ -431,7 +351,7 @@ supported groups as comparable in security. =head1 COPYRIGHT -Copyright 2013-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2013-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_CTX_set1_verify_cert_store.pod b/doc/man3/SSL_CTX_set1_verify_cert_store.pod index 4352a78525..ba8a380bb8 100644 --- a/doc/man3/SSL_CTX_set1_verify_cert_store.pod +++ b/doc/man3/SSL_CTX_set1_verify_cert_store.pod @@ -31,16 +31,10 @@ verification or chain store =head1 DESCRIPTION SSL_CTX_set0_verify_cert_store() and SSL_CTX_set1_verify_cert_store() -set the certificate store used for peer certificate verification to B. -They override for this purpose any locations set by -L, L, -L, L, etc. +set the certificate store used for certificate verification to B. -SSL_CTX_set0_chain_cert_store() and SSL_CTX_set1_chain_cert_store() set the -cert store for building the chain of the own client/server certificate to B. -They override for this purpose any locations set by -L, L, -L, L, etc. +SSL_CTX_set0_chain_cert_store() and SSL_CTX_set1_chain_cert_store() +set the certificate store used for certificate chain building to B. SSL_set0_verify_cert_store(), SSL_set1_verify_cert_store(), SSL_set0_chain_cert_store() and SSL_set1_chain_cert_store() are similar @@ -93,24 +87,16 @@ All these functions return 1 for success and 0 for failure. =head1 SEE ALSO L, -L, -L, -L, -L, -L, -L, -L, -L, -L, -L, -L, -L, -L, -L, -L, -L, -L, -L, +L +L +L +L +L +L +L +L +L +L L =head1 HISTORY diff --git a/doc/man3/SSL_CTX_set_alpn_select_cb.pod b/doc/man3/SSL_CTX_set_alpn_select_cb.pod index 88c36227f1..dd5517df4d 100644 --- a/doc/man3/SSL_CTX_set_alpn_select_cb.pod +++ b/doc/man3/SSL_CTX_set_alpn_select_cb.pod @@ -2,8 +2,7 @@ =head1 NAME -SSL_CTX_set_alpn_protos, SSL_set_alpn_protos, SSL_CTX_get0_alpn_protos, -SSL_get0_alpn_protos, SSL_CTX_set_alpn_select_cb, +SSL_CTX_set_alpn_protos, SSL_set_alpn_protos, SSL_CTX_set_alpn_select_cb, SSL_CTX_set_next_proto_select_cb, SSL_CTX_set_next_protos_advertised_cb, SSL_select_next_proto, SSL_get0_alpn_selected, SSL_get0_next_proto_negotiated - handle application layer protocol negotiation (ALPN) @@ -48,11 +47,6 @@ SSL_select_next_proto, SSL_get0_alpn_selected, SSL_get0_next_proto_negotiated void SSL_get0_next_proto_negotiated(const SSL *s, const unsigned char **data, unsigned *len); - void SSL_CTX_get0_alpn_protos(SSL_CTX *ctx, const unsigned char **protos, - unsigned int *protos_len); - void SSL_get0_alpn_protos(SSL *ssl, const unsigned char **protos, - unsigned int *protos_len); - =head1 DESCRIPTION SSL_CTX_set_alpn_protos() and SSL_set_alpn_protos() are used by the client to @@ -61,12 +55,6 @@ protocol-list format, described below. The length of B is specified in B. Setting B to 0 clears any existing list of ALPN protocols and no ALPN extension will be sent to the server. -SSL_CTX_get0_alpn_protos() and SSL_get0_alpn_protos() are used by the client to -get the list of protocols available to be negotiated. The B are in -protocol-list format, described below. Returns a pointer to protocol list in -B with length B. It is not NUL-terminated. B must -not be freed. - SSL_CTX_set_alpn_select_cb() sets the application callback B used by a server to select which protocol to use for the incoming connection. When B is NULL, ALPN is not used. The B value is a pointer which is passed to @@ -214,7 +202,7 @@ L =head1 COPYRIGHT -Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_CTX_set_cipher_list.pod b/doc/man3/SSL_CTX_set_cipher_list.pod index f9d1bc8433..1df33ba11d 100644 --- a/doc/man3/SSL_CTX_set_cipher_list.pod +++ b/doc/man3/SSL_CTX_set_cipher_list.pod @@ -25,24 +25,18 @@ OSSL_default_ciphersuites =head1 DESCRIPTION -SSL_CTX_set_cipher_list() sets the list of available ciphers (TLSv1.2 and -below) for B using the control string B. -The format of the string is described in L. -As of OpenSSL 4.0, B is processed case-insensitively. -The list of ciphers is inherited by all B objects created from B. -This function does not affect TLSv1.3 ciphersuites. -Use SSL_CTX_set_ciphersuites() to configure those. -B B be NULL. +SSL_CTX_set_cipher_list() sets the list of available ciphers (TLSv1.2 and below) +for B using the control string B. The format of the string is described +in L. The list of ciphers is inherited by all +B objects created from B. This function does not impact TLSv1.3 +ciphersuites. Use SSL_CTX_set_ciphersuites() to configure those. B B be NULL. SSL_set_cipher_list() sets the list of ciphers (TLSv1.2 and below) only for B. SSL_CTX_set_ciphersuites() is used to configure the available TLSv1.3 -ciphersuites for B. -This is a simple colon (":") separated list of TLSv1.3 ciphersuite names in -order of preference. -As of OpenSSL 4.0, B is processed case-insensitively. -Valid TLSv1.3 ciphersuite names are: +ciphersuites for B. This is a simple colon (":") separated list of TLSv1.3 +ciphersuite names in order of preference. Valid TLSv1.3 ciphersuite names are: =over 4 @@ -56,10 +50,6 @@ Valid TLSv1.3 ciphersuite names are: =item TLS_AES_128_CCM_8_SHA256 -=item TLS_SM4_GCM_SM3 - -=item TLS_SM4_CCM_SM3 - =item TLS_SHA384_SHA384 - integrity-only =item TLS_SHA256_SHA256 - integrity-only @@ -131,11 +121,9 @@ L OSSL_default_cipher_list() and OSSL_default_ciphersites() are new in 3.0. -Cipher names were case-sensitive prior to OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_CTX_set_client_hello_cb.pod b/doc/man3/SSL_CTX_set_client_hello_cb.pod index 820c0261ce..6367c68a62 100644 --- a/doc/man3/SSL_CTX_set_client_hello_cb.pod +++ b/doc/man3/SSL_CTX_set_client_hello_cb.pod @@ -9,6 +9,7 @@ SSL_CTX_set_client_hello_cb, SSL_client_hello_cb_fn, SSL_client_hello_isv2, SSL_ typedef int (*SSL_client_hello_cb_fn)(SSL *s, int *al, void *arg); void SSL_CTX_set_client_hello_cb(SSL_CTX *c, SSL_client_hello_cb_fn *f, void *arg); + int SSL_client_hello_isv2(SSL *s); unsigned int SSL_client_hello_get0_legacy_version(SSL *s); size_t SSL_client_hello_get0_random(SSL *s, const unsigned char **out); size_t SSL_client_hello_get0_session_id(SSL *s, const unsigned char **out); @@ -22,12 +23,6 @@ SSL_CTX_set_client_hello_cb, SSL_client_hello_cb_fn, SSL_client_hello_isv2, SSL_ int SSL_client_hello_get0_ext(SSL *s, unsigned int type, const unsigned char **out, size_t *outlen); -The following functions have been deprecated since OpenSSL 4.0, and can be -hidden entirely by defining B with a suitable version value, -see L: - - int SSL_client_hello_isv2(SSL *s); - =head1 DESCRIPTION SSL_CTX_set_client_hello_cb() sets the callback function, which is automatically @@ -45,9 +40,14 @@ function, the ClientHello callback will be called again, and, if it returns success, normal handshake processing will continue from that point. SSL_client_hello_isv2() indicates whether the ClientHello was carried in a -SSLv2 record and is in the SSLv2 format. -Support for the SSLv2 format was removed in 4.0 and this function -will always return 0. +SSLv2 record and is in the SSLv2 format. The SSLv2 format has substantial +differences from the normal SSLv3 format, including using three bytes per +cipher suite, and not allowing extensions. Additionally, the SSLv2 format +'challenge' field is exposed via SSL_client_hello_get0_random(), padded to +SSL3_RANDOM_SIZE bytes with zeros if needed. For SSLv2 format ClientHellos, +SSL_client_hello_get0_compression_methods() returns a dummy list that only includes +the null compression method, since the SSLv2 format does not include a +mechanism by which to negotiate compression. SSL_client_hello_get0_random(), SSL_client_hello_get0_session_id(), SSL_client_hello_get0_ciphers(), and @@ -111,18 +111,13 @@ The SSL_client_hello_get0_*() functions return raw ClientHello data, whereas SSL_client_hello_get1_extensions_present() returns only recognized extensions (so unknown/GREASE-extensions are not included). -When Encrypted Client Hello (ECH) is used, and ECH decryption has succeeded, -then the inner ClientHello message is the content visible to the ClientHello -callback functions. If ECH decryption failed, then the outer ClientHello -message content will be provided. - =head1 RETURN VALUES The application's supplied ClientHello callback returns SSL_CLIENT_HELLO_SUCCESS on success, SSL_CLIENT_HELLO_ERROR on failure, and SSL_CLIENT_HELLO_RETRY to suspend processing. -SSL_client_hello_isv2() returns 0. +SSL_client_hello_isv2() returns 1 for SSLv2-format ClientHellos and 0 otherwise. SSL_client_hello_get0_random(), SSL_client_hello_get0_session_id(), SSL_client_hello_get0_ciphers(), and @@ -154,7 +149,7 @@ was added in OpenSSL 3.2.0. =head1 COPYRIGHT -Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2017-2022 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_CTX_set_min_proto_version.pod b/doc/man3/SSL_CTX_set_min_proto_version.pod index c1bf21ac42..d9b61dcce9 100644 --- a/doc/man3/SSL_CTX_set_min_proto_version.pod +++ b/doc/man3/SSL_CTX_set_min_proto_version.pod @@ -39,7 +39,7 @@ controlled by system configuration. Getters return 0 in case B or B have been configured to automatically use the lowest or highest version supported by the library. -Currently supported versions are B, +Currently supported versions are B, B, B, B, B for TLS and B, B for DTLS. diff --git a/doc/man3/SSL_CTX_set_msg_callback.pod b/doc/man3/SSL_CTX_set_msg_callback.pod index 7acc796a24..f046c77b53 100644 --- a/doc/man3/SSL_CTX_set_msg_callback.pod +++ b/doc/man3/SSL_CTX_set_msg_callback.pod @@ -92,7 +92,7 @@ The SSL_trace() function can be used as a pre-written callback in a call to SSL_CTX_set_msg_callback() or SSL_set_msg_callback(). It requires a BIO to be set as the callback argument via SSL_CTX_set_msg_callback_arg() or SSL_set_msg_callback_arg(). Setting this callback will cause human readable -diagnostic tracing information about an SSL/TLS/QUIC connection to be written to +diagostic tracing information about an SSL/TLS/QUIC connection to be written to the BIO. =head1 NOTES @@ -108,8 +108,8 @@ processed. Due to automatic protocol version negotiation, I is not necessarily the protocol version used by the sender of the message: If -a TLS 1.1 ClientHello message is received by an TLS 1-only server, -I will be B. +a TLS 1.0 ClientHello message is received by an SSL 3.0-only server, +I will be B. Pseudo content type values may be sent at various points during the processing of data. The following pseudo content types are currently defined: diff --git a/doc/man3/SSL_CTX_set_options.pod b/doc/man3/SSL_CTX_set_options.pod index 400e492f3a..d78bdd5a31 100644 --- a/doc/man3/SSL_CTX_set_options.pod +++ b/doc/man3/SSL_CTX_set_options.pod @@ -71,7 +71,7 @@ CSP 3.x. =item SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS -Disables a countermeasure against an TLS 1.0 protocol +Disables a countermeasure against an SSL 3.0/TLS 1.0 protocol vulnerability affecting CBC ciphers, which cannot be handled by some broken SSL implementations. This option has no effect for connections using other ciphers. @@ -349,16 +349,6 @@ In TLSv1.3 it is possible to suppress all tickets (stateful and stateless) from being sent by calling L or L. -All tickets (stateful and stateless) are also suppressed when the server has set -B and the server-side session cache is disabled via -B through L. -Both conditions together indicate a clear intent to suppress resumption, so -sending B messages would be wasteful and misleading. - -From the server's perspective, a TLS 1.3 client that does not send the -B extension is effectively signaling no interest in -session tickets and session resumption, so tickets are also suppressed in this case. - =item SSL_OP_PRIORITIZE_CHACHA When SSL_OP_SERVER_PREFERENCE is set, temporarily reprioritize @@ -380,54 +370,6 @@ only understands up to SSLv3. In this case the client must still use the same SSLv3.1=TLSv1 announcement. Some clients step down to SSLv3 with respect to the server's answer and violate the version rollback protection.) -=item SSL_OP_ECH_GREASE - -If set, TLS ClientHello messages emitted by the client will include GREASE -Encrypted ClientHello (ECH) extension values, if ECH is not really being -attempted. - -=item SSL_OP_ECH_TRIALDECRYPT - -If set, servers will attempt to decrypt ECH extensions using all loaded -ECH key pairs. By default, servers will only attempt decryption using -an ECH key pair that matches the config_id in the ECH extension value -received. - -Note that a server that has loaded many ECH configurations and that enables ECH -trial decryption will attempt decryption with every ECH key when presented with -a GREASEd ECH, (see B) and with possibly that many even -when presented with a real ECH. That could easily become an accidental denial -of service. - -Note also that the ECH specification recommends that servers that enable this -option consider implementing some form of rate limiting mechanism to limit the -potential damage caused in such scenarios. - -If trial decryption is enabled then decryption will be attempted with the ECH -configurations in the order they were loaded. So, where it is possible to load -the configuration most likely to be used first, that would improve efficiency. - -=item SSL_OP_ECH_GREASE_RETRY_CONFIG - -If set, servers will add GREASEy ECHConfig values to those sent to the -client after the client GREASEd or the client tried and failed to use -ECH. - -=item SSL_OP_ECH_IGNORED_CID - -If set, TLS ClientHello messages emitted by the client will ignore the -ECHConfig config_id chosen by the server and use a random octet. - -=item SSL_OP_GREASE - -If set, TLS ClientHello messages will include GREASE (Generate Random -Extensions And Sustain Extensibility) values as defined in RFC 8701. This -injects random reserved values (matching the 0x?A?A pattern) into cipher -suites, supported groups, supported versions, signature algorithms, key share -entries, and extensions. GREASE values help prevent ecosystem ossification by -ensuring servers and middleboxes tolerate unknown values. The injected values -are consistent across HelloRetryRequest replays within the same connection. - =back The following options no longer have any effect but their identifiers are @@ -612,7 +554,7 @@ B constant. =head1 COPYRIGHT -Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2001-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_CTX_set_psk_client_callback.pod b/doc/man3/SSL_CTX_set_psk_client_callback.pod index 146e3d03a5..dd302983fd 100644 --- a/doc/man3/SSL_CTX_set_psk_client_callback.pod +++ b/doc/man3/SSL_CTX_set_psk_client_callback.pod @@ -93,14 +93,6 @@ be used as the basis for a PSK. Ownership of the SSL_SESSION object is passed to the OpenSSL library and so it should not be freed by the application. -Note that as described above, the callback may be called a second time during a -handshake. Since ownership of the SSL_SESSION is transferred to OpenSSL on each -call, if the callback wishes to return the same SSL_SESSION pointer on a -subsequent invocation, it must first call L to increment -the reference count. Failure to do so will result in a use-after-free error. -Alternatively, the callback may return a different SSL_SESSION object on each -call (e.g., by calling L). - It is also possible for the callback to succeed but not supply a PSK. In this case no PSK will be sent to the server but the handshake will continue. To do this the callback should return successfully and ensure that B<*sess> is @@ -177,7 +169,7 @@ were added in OpenSSL 1.1.1. =head1 COPYRIGHT -Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2006-2020 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_CTX_set_security_level.pod b/doc/man3/SSL_CTX_set_security_level.pod index 38bd87b5f0..b490c74039 100644 --- a/doc/man3/SSL_CTX_set_security_level.pod +++ b/doc/man3/SSL_CTX_set_security_level.pod @@ -78,7 +78,7 @@ DSA and DH keys shorter than 1024 bits and ECC keys shorter than 160 bits are prohibited. Any cipher suite using MD5 for the MAC is also prohibited. Any cipher suites using CCM with a 64 bit authentication tag are prohibited. Note that signatures using SHA1 and MD5 are also forbidden at this level as they -have less than 80 security bits. Additionally, TLS 1.0, TLS 1.1 and +have less than 80 security bits. Additionally, SSLv3, TLS 1.0, TLS 1.1 and DTLS 1.0 are all disabled at this level. =item B diff --git a/doc/man3/SSL_CTX_set_session_cache_mode.pod b/doc/man3/SSL_CTX_set_session_cache_mode.pod index 4234aa6344..25b588f580 100644 --- a/doc/man3/SSL_CTX_set_session_cache_mode.pod +++ b/doc/man3/SSL_CTX_set_session_cache_mode.pod @@ -8,8 +8,8 @@ SSL_CTX_set_session_cache_mode, SSL_CTX_get_session_cache_mode - enable/disable #include - long SSL_CTX_set_session_cache_mode(SSL_CTX *ctx, long mode); - long SSL_CTX_get_session_cache_mode(SSL_CTX *ctx); + long SSL_CTX_set_session_cache_mode(SSL_CTX ctx, long mode); + long SSL_CTX_get_session_cache_mode(SSL_CTX ctx); =head1 DESCRIPTION @@ -47,12 +47,6 @@ The following session cache modes and modifiers are available: No session caching for client or server takes place. -For a server, setting B together with the -B option (see L) suppresses the -issuance of B messages. The combination indicates a clear -intent to disable session resumption, so no stateful or stateless tickets are -sent to the client. - =item SSL_SESS_CACHE_CLIENT Client sessions are added to the session cache. As there is no reliable way diff --git a/doc/man3/SSL_CTX_set_session_id_context.pod b/doc/man3/SSL_CTX_set_session_id_context.pod index a2a588d36b..c9572bd0d8 100644 --- a/doc/man3/SSL_CTX_set_session_id_context.pod +++ b/doc/man3/SSL_CTX_set_session_id_context.pod @@ -38,6 +38,9 @@ is set by the SSL/TLS server. The SSL_CTX_set_session_id_context() and SSL_set_session_id_context() functions are therefore only useful on the server side. +OpenSSL clients will check the session id context returned by the server +when reusing a session. + The maximum length of the B is limited to B. @@ -48,24 +51,11 @@ certificates are used, stored sessions will not be reused but a fatal error will be flagged and the handshake will fail. -If a client attempts to resume a session and the server detects that the session -id context associated with the session is different to the current session id -context then the resumption will fail. The handshake will continue normally but -no resumption will occur. - -It is vital that the session id context is set before any session resumption -occurs. Sessions get created early in the handshake. If the session id context -is not set by the time the session gets created then the session will be -associated with an empty session id context. The already created session will -not get updated if the session id context is later set. In particular the -callback set via the L function will -be invoked after the session gets created, so if the session id context is set -in the callback then this will be too late for the current handshake and the -session id context setting will be ignored with respect to resumption. Typically -the session id context should be set before the TLS handshake starts, but it may -occur as late as in the callback set via the L -function. - +If a server returns a different session id context to an OpenSSL client +when reusing a session, an error will be flagged and the handshake will +fail. OpenSSL servers will always return the correct session id context, +as an OpenSSL server checks the session id context itself before reusing +a session as described above. =head1 RETURN VALUES diff --git a/doc/man3/SSL_CTX_set_split_send_fragment.pod b/doc/man3/SSL_CTX_set_split_send_fragment.pod index d26b41fcfe..22433e5e37 100644 --- a/doc/man3/SSL_CTX_set_split_send_fragment.pod +++ b/doc/man3/SSL_CTX_set_split_send_fragment.pod @@ -38,7 +38,7 @@ able to process multiple simultaneous crypto operations. This capability could be utilised to parallelise the processing of a single connection. For example a single write can be split into multiple records and each one encrypted independently and in parallel. Note: this would only work in -TLS1.1+. There was no support in TLSv1.0 or DTLS (any version). This +TLS1.1+. There was no support in SSLv3, TLSv1.0 or DTLS (any version). This capability is known as "pipelining" within OpenSSL. In order to benefit from the pipelining capability, you would need to have an diff --git a/doc/man3/SSL_CTX_set_tlsext_servername_callback.pod b/doc/man3/SSL_CTX_set_tlsext_servername_callback.pod index 285d7d57b0..a0a4bd6367 100644 --- a/doc/man3/SSL_CTX_set_tlsext_servername_callback.pod +++ b/doc/man3/SSL_CTX_set_tlsext_servername_callback.pod @@ -14,7 +14,7 @@ SSL_set_tlsext_host_name - handle server name indication (SNI) int (*cb)(SSL *s, int *al, void *arg)); long SSL_CTX_set_tlsext_servername_arg(SSL_CTX *ctx, void *arg); - const char *SSL_get_servername(const SSL *s, int type); + const char *SSL_get_servername(const SSL *s, const int type); int SSL_get_servername_type(const SSL *s); int SSL_set_tlsext_host_name(const SSL *s, const char *name); @@ -26,14 +26,10 @@ the ClientHello callback, which can be set using SSL_CTX_set_client_hello_cb(). However, even where the ClientHello callback is used, the servername callback is still necessary in order to acknowledge the servername requested by the client. -SSL_CTX_set_tlsext_servername_callback() sets the application callback I +SSL_CTX_set_tlsext_servername_callback() sets the application callback B used by a server to perform any actions or configuration required based on -the B extension received in the incoming connection. When I -is NULL, SNI is not used. Note that this callback occurs late in the processing -of the ClientHello message. In particular it happens after session resumption -has occurred, and so typically this callback should not call functions such -as L since it is too late to affect the session -resumption for the current handshake. +the servername extension received in the incoming connection. When B +is NULL, SNI is not used. The servername callback should return one of the following values: @@ -49,14 +45,14 @@ up a different configuration for the selected servername in this case. In this case the servername requested by the client is not accepted and the handshake will be aborted. The value of the alert to be used should be stored in -the location pointed to by the I parameter to the callback. By default this +the location pointed to by the B parameter to the callback. By default this value is initialised to SSL_AD_UNRECOGNIZED_NAME. =item SSL_TLSEXT_ERR_ALERT_WARNING If this value is returned then the servername is not accepted by the server. However, the handshake will continue and send a warning alert instead. The value -of the alert should be stored in the location pointed to by the I parameter +of the alert should be stored in the location pointed to by the B parameter as for SSL_TLSEXT_ERR_ALERT_FATAL above. Note that TLSv1.3 does not support warning alerts, so if TLSv1.3 has been negotiated then this return value is treated the same way as SSL_TLSEXT_ERR_NOACK. @@ -69,7 +65,7 @@ No alerts are sent and the server will not acknowledge the requested servername. =back SSL_CTX_set_tlsext_servername_arg() sets a context-specific argument to be -passed into the callback (via the I parameter) for this B. +passed into the callback (via the B parameter) for this B. The behaviour of SSL_get_servername() depends on a number of different factors. In particular note that in TLSv1.3 the servername is negotiated in every @@ -127,21 +123,12 @@ client is processed. The servername, certificate and ALPN callbacks occur after a servername extension from the client is processed. SSL_get_servername_type() returns the servername type or -1 if no servername -is present. -The only type defined in RFC 3546 and supported here is B. +is present. Currently the only supported type (defined in RFC3546) is +B. -SSL_set_tlsext_host_name() sets the Server Name Indication (SNI) -ClientHello extension defined in RFC 3546 section 3.1 -to contain the value I of type B. -If I is NULL, it clears the SNI extension. - -Using this function may also be important for correct routing of connection requests. -TLS clients should call this function alongside L or -L to set the expected server hostname(s) for certificate validation. - -The SSL_set_tlsext_host_name() function should only be called on SSL objects -that will act as clients; otherwise, the configured I will be ignored. -In the future, calling this function on the server side may result in an error. +SSL_set_tlsext_host_name() sets the server name indication ClientHello extension +to contain the value B. The type of server name indication extension is set +to B (defined in RFC3546). =head1 NOTES @@ -149,6 +136,9 @@ Several callbacks are executed during ClientHello processing, including the ClientHello, ALPN, and servername callbacks. The ClientHello callback is executed first, then the servername callback, followed by the ALPN callback. +The SSL_set_tlsext_host_name() function should only be called on SSL objects +that will act as clients; otherwise the configured B will be ignored. + =head1 RETURN VALUES SSL_CTX_set_tlsext_servername_callback() and @@ -158,9 +148,7 @@ SSL_set_tlsext_host_name() returns 1 on success, 0 in case of error. =head1 SEE ALSO L, L, -L, L, -L, L, -L, L +L, L =head1 HISTORY @@ -181,7 +169,7 @@ NULL. =head1 COPYRIGHT -Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2017-2020 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_CTX_set_tlsext_ticket_key_cb.pod b/doc/man3/SSL_CTX_set_tlsext_ticket_key_cb.pod index 4176bc467b..e4871590f7 100644 --- a/doc/man3/SSL_CTX_set_tlsext_ticket_key_cb.pod +++ b/doc/man3/SSL_CTX_set_tlsext_ticket_key_cb.pod @@ -29,7 +29,8 @@ see L: SSL_CTX_set_tlsext_ticket_key_evp_cb() sets a callback function I for handling session tickets for the ssl context I. Session tickets, defined in RFC5077 provide an enhanced session resumption capability where the server -implementation is not required to maintain per session state. +implementation is not required to maintain per session state. It only applies +to TLS and there is no SSLv3 implementation. The callback function I will be called for every client instigated TLS session when session ticket extension is presented in the TLS hello diff --git a/doc/man3/SSL_CTX_set_verify.pod b/doc/man3/SSL_CTX_set_verify.pod index 1a9ef7d83e..58774796cd 100644 --- a/doc/man3/SSL_CTX_set_verify.pod +++ b/doc/man3/SSL_CTX_set_verify.pod @@ -74,9 +74,7 @@ SSL_CTX_set_client_cert_cb() if no certificate is provided at initialization. SSL_verify_client_post_handshake() causes a CertificateRequest message to be sent by a server on the given B connection. The SSL_VERIFY_PEER flag must -be set; the SSL_VERIFY_POST_HANDSHAKE flag is optional. The -SSL_VERIFY_FAIL_IF_NO_PEER_CERT flag is also applicable and has the same -effect as with the client authentication during the handshake. +be set; the SSL_VERIFY_POST_HANDSHAKE flag is optional. =head1 NOTES diff --git a/doc/man3/SSL_CTX_use_certificate.pod b/doc/man3/SSL_CTX_use_certificate.pod index a2a7d5e3e3..3d5049c286 100644 --- a/doc/man3/SSL_CTX_use_certificate.pod +++ b/doc/man3/SSL_CTX_use_certificate.pod @@ -100,20 +100,18 @@ SSL_CTX_use_PrivateKey() or SSL_use_PrivateKey(). On success the reference counter of the B/B is incremented. SSL_CTX_use_cert_and_key() and SSL_use_cert_and_key() assign the X.509 -certificate B, private key B, and certificate chain B onto -the corresponding B or B. -If B is not NULL, a check is performed to verify that B matches -the public key of B. -If the B argument is 0, the function fails if a certificate of the -same public key type has already been set. -If B is non-0, any previously set certificate, private key, and -chain of the same type are replaced. -If B is NULL, then the public key of B is used as the private key. -This is intended to be used with hardware that stores the private key -securely, such that it cannot be accessed by OpenSSL. -The reference counts of B, B, and the certificates in B are -incremented; the caller should free its own references when they are no -longer needed. +certificate B, private key B, and certificate B onto the +corresponding B or B. The B argument must be the private +key of the X.509 certificate B. If the B argument is 0, then +B, B and B are set only if all were not previously set. +If B is non-0, then the certificate, private key and chain certs +are always set. If B is NULL, then the public key of B is used as +the private key. This is intended to be used with hardware +that stores the private key securely, such that it cannot be +accessed by OpenSSL. The reference count of the public key is incremented +(twice if there is no private key); it is not copied nor duplicated. This +allows all private key validations checks to succeed without an actual +private key being assigned via SSL_CTX_use_PrivateKey(), etc. SSL_CTX_use_PrivateKey_ASN1() adds the private key of type B stored at memory location B (length B) to B. @@ -140,23 +138,9 @@ this B, the last item added into B will be checked. =head1 NOTES -Each B or B object has an internal certificate store that can -hold multiple private keys and associated certificate chains at a time. -By default B objects use the settings of the parent B. -This allows a TLS server to support multiple certificate types (e.g., RSA, -ECDSA, or post-quantum algorithms) on a single listening socket, at most -one of each type. -During the TLS handshake, OpenSSL automatically selects the most preferred -mutually supported certificate type, based on the signature algorithms and -cipher suites (TLS 1.2 and prior) advertised by the client. -To load multiple keys and associated certificate chains, simply call the -certificate and private key loading functions multiple times with different key -types. -For example, the SSL_CTX_use_cert_and_key() and SSL_use_cert_and_key() -functions can be called multiple times on the same B or B object, -respectively, with a different certificate type (and matching private key type) -in each call. -For TLS 1.2, see also L. +The internal certificate store of OpenSSL can hold several private +key/certificate pairs at a time. The certificate used depends on the +cipher selected, see also L. When reading certificates and private keys from file, files of type SSL_FILETYPE_ASN1 (also known as B, binary encoding) can only contain diff --git a/doc/man3/SSL_CTX_use_psk_identity_hint.pod b/doc/man3/SSL_CTX_use_psk_identity_hint.pod index 1adc864c66..e3802b74f0 100644 --- a/doc/man3/SSL_CTX_use_psk_identity_hint.pod +++ b/doc/man3/SSL_CTX_use_psk_identity_hint.pod @@ -50,16 +50,10 @@ in B<*sess>. The SSL_SESSION object should, as a minimum, set the master key, the ciphersuite and the protocol version. See L for details. -It is also possible for the callback to succeed but not supply a PSK. To do this -the callback should return successfully and ensure that B<*sess> is NULL. In -this case no PSK will be used and, if a certificate has also been configured, -then the handshake will continue. If no certificate has been configured then the -handshake will fail with a "decrypt_error" alert. This alert is the same one -that is used in the event that a valid PSK identity is found but the TLSv1.3 -"binder" fails to verify. It is used to prevent an attacker from being able to -determine whether a PSK identity is valid or not based on the alert received -(see Appendix E.6 of RFC8446). Note that this is not a constant time check and -so timing side channels may still exist. +It is also possible for the callback to succeed but not supply a PSK. In this +case no PSK will be used but the handshake will continue. To do this the +callback should return successfully and ensure that B<*sess> is +NULL. Identity hints are not relevant for TLSv1.3. A server application wishing to use PSK ciphersuites for TLSv1.2 and below may call SSL_CTX_use_psk_identity_hint() diff --git a/doc/man3/SSL_get_SSL_CTX.pod b/doc/man3/SSL_get_SSL_CTX.pod index 8655d6288f..02443c104e 100644 --- a/doc/man3/SSL_get_SSL_CTX.pod +++ b/doc/man3/SSL_get_SSL_CTX.pod @@ -17,10 +17,7 @@ B was created with L. =head1 RETURN VALUES -The pointer to the SSL_CTX object is returned. This is an internal pointer -and the reference count is not incremented. The returned pointer should not -be freed. If the caller needs to retain the SSL_CTX for longer than the SSL -object, it should call L to increment the reference count. +The pointer to the SSL_CTX object is returned. =head1 SEE ALSO @@ -28,7 +25,7 @@ L, L =head1 COPYRIGHT -Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2001-2016 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_get_ciphers.pod b/doc/man3/SSL_get_ciphers.pod index 2a8e070525..add0fc4cd0 100644 --- a/doc/man3/SSL_get_ciphers.pod +++ b/doc/man3/SSL_get_ciphers.pod @@ -51,13 +51,12 @@ list received from the client on B. If B is NULL, no ciphers are available, or B is not operating in server mode, NULL is returned. SSL_bytes_to_cipher_list() treats the supplied B octets in B -as a wire-protocol cipher suite specification in the two-octet -SSLv3/TLS wire format, and parses the cipher suites supported by the library +as a wire-protocol cipher suite specification (in the three-octet-per-cipher +SSLv2 wire format if B is nonzero; otherwise the two-octet +SSLv3/TLS wire format), and parses the cipher suites supported by the library into the returned stacks of SSL_CIPHER objects sk and Signalling Cipher-Suite -Values scsvs. -The B is no longer supported and should always be set to 0. -Unsupported cipher suites are ignored. -Returns 1 on success and 0 on failure. +Values scsvs. Unsupported cipher suites are ignored. Returns 1 on success +and 0 on failure. SSL_get_cipher_list() returns a pointer to the name of the SSL_CIPHER listed for B with B. If B is NULL, no ciphers are @@ -76,8 +75,6 @@ description of SSL_get1_supported_ciphers() above). This function will return available shared ciphersuites whether or not they are enabled. This is a server side function only and must only be called after the completion of the initial handshake. -The function sets an empty string when B fails the handshake due to the -absence of shared ciphers. =head1 NOTES @@ -110,7 +107,7 @@ L =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_get_error.pod b/doc/man3/SSL_get_error.pod index d434ef332c..a599a9eee6 100644 --- a/doc/man3/SSL_get_error.pod +++ b/doc/man3/SSL_get_error.pod @@ -14,11 +14,17 @@ SSL_get_error - obtain result code for TLS/SSL I/O operation SSL_get_error() returns a result code (suitable for the C "switch" statement) for a preceding call to SSL_connect(), SSL_accept(), SSL_do_handshake(), -SSL_read_ex(), SSL_read(), SSL_read_early_data(), SSL_peek_ex(), SSL_peek(), -SSL_write_ex(), SSL_write(), SSL_write_early_data(), SSL_sendfile() -or SSL_shutdown() on B. The value returned by that TLS/SSL I/O +SSL_read_ex(), SSL_read(), SSL_peek_ex(), SSL_peek(), SSL_shutdown(), +SSL_write_ex() or SSL_write() on B. The value returned by that TLS/SSL I/O function must be passed to SSL_get_error() in parameter B. +In addition to B and B, SSL_get_error() inspects the +current thread's OpenSSL error queue. Thus, SSL_get_error() must be +used in the same thread that performed the TLS/SSL I/O operation, and no +other OpenSSL function calls should appear in between. The current +thread's error queue must be empty before the TLS/SSL I/O operation is +attempted, or SSL_get_error() will not work reliably. + =head1 NOTES Some TLS implementations do not send a close_notify alert on shutdown. @@ -175,26 +181,18 @@ connection and SSL_shutdown() must not be called. =back -The OpenSSL error queue can be inspected with the B family of functions, -such as L and L. - =head1 SEE ALSO -L, -L, ERR_print_errors(3), ERR_peek_last_error_all(3) +L =head1 HISTORY The SSL_ERROR_WANT_ASYNC error code was added in OpenSSL 1.1.0. The SSL_ERROR_WANT_CLIENT_HELLO_CB error code was added in OpenSSL 1.1.1. -Since OpenSSL 4.0 SSL_get_error() no longer depends on the state of the -error stack, so it is no longer necessary to empty the error queue -before the TLS/SSL I/O operations. - =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_get_peer_certificate.pod b/doc/man3/SSL_get_peer_certificate.pod index 822b00c155..1897a43ebe 100644 --- a/doc/man3/SSL_get_peer_certificate.pod +++ b/doc/man3/SSL_get_peer_certificate.pod @@ -21,9 +21,6 @@ version value, see L: =head1 DESCRIPTION -SSL_get_peer_certificate() is deprecated. Use SSL_get0_peer_certificate() or -SSL_get1_peer_certificate() instead. - These functions return a pointer to the X509 certificate the peer presented. If the peer did not present a certificate, NULL is returned. @@ -77,7 +74,7 @@ SSL_get_peer_certificate() was deprecated in 3.0.0. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_get_shared_sigalgs.pod b/doc/man3/SSL_get_shared_sigalgs.pod index 36391a3939..cb9ce02500 100644 --- a/doc/man3/SSL_get_shared_sigalgs.pod +++ b/doc/man3/SSL_get_shared_sigalgs.pod @@ -2,20 +2,12 @@ =head1 NAME -SSL_get0_shared_sigalg, SSL_get0_sigalg, -SSL_get_shared_sigalgs, SSL_get_sigalgs - -get shared or peer signature algorithms +SSL_get_shared_sigalgs, SSL_get_sigalgs - get supported signature algorithms =head1 SYNOPSIS #include - int SSL_get0_sigalg(SSL *s, int idx, unsigned int *codepoint, - const char **name); - - int SSL_get0_shared_sigalg(SSL *s, int idx, unsigned int *codepoint, - const char **name); - int SSL_get_shared_sigalgs(SSL *s, int idx, int *psign, int *phash, int *psignhash, unsigned char *rsig, unsigned char *rhash); @@ -26,62 +18,21 @@ get shared or peer signature algorithms =head1 DESCRIPTION -SSL_get0_shared_sigalg() returns the names and codepoints of signature -algorithms shared with the peer in the SSL connection I. -When I is negative, the number of algorithms is returned, and the output -parameters remain unmodified. -Otherwise, when I is nonnegative, it is the index of the shared -signature algorithm to return starting from zero. -The signature algorithm name is written to I<*name> (if I) is not NULL). -The name reported is the IANA registered name for that algorithm, and is -expected to work verbatim if used in a B configuration -setting (see L). -The signature algorithm codepoint is written to I<*codepoint> (if I -is not NULL). -This function is better suited for inspecting TLS 1.3 signature algorithms than -the older SSL_get_shared_sigalgs(). - -SSL_get0_sigalg() returns the names and codepoints of signature -algorithms advertised by the peer in the SSL connection I. -When I is negative, the number of algorithms is returned, and the output -parameters remain unmodified. -Otherwise, when I is nonnegative, it is the index of the peer -signature algorithm to return starting from zero. -For signature algorithms that are locally known, the name reported is the IANA -registered name for that algorithm, and is expected to work verbatim if used in -a B configuration setting (see L). -The signature algorithm codepoint is written to I<*codepoint> (if I -is not NULL). -If the signature algorithm is known, its name is written to I<*name> (if -I) is not NULL). -This function is better suited for inspecting TLS 1.3 signature algorithms than -the older SSL_get_sigalgs(). - -SSL_get_shared_sigalgs() returns information about the supported signature -algorithms shared with the peer in the SSL connection I. -When I is negative, the number of shared algorithms is returned, and -the output parameters remain unmodified. -Otherwise, when I is nonnegative, it is the index of the shared -signature algorithm to return starting from zero. -The signature algorithm NID is written to I<*psign>, the hash NID to I<*phash> -and the sign and hash NID to I<*psignhash>. -As of TLS 1.3 signature algorithms are not always a pairing of of a separate -public key algorithm and a digest algorithm, and so I<*phash> and I<*psignhash> -may not always be meaningful. -The raw B and B bytes of the signature algorithm codepoint are -written to I<*rhash> and I<*rsig>. -For example, the B signature algorithm, with codepoint B<0x0401>, -gives B<0x04> for I<*rhash> and B<0x01> for I<*rsig>. +SSL_get_shared_sigalgs() returns information about the shared signature +algorithms supported by peer B. The parameter B indicates the index +of the shared signature algorithm to return starting from zero. The signature +algorithm NID is written to B<*psign>, the hash NID to B<*phash> and the +sign and hash NID to B<*psignhash>. The raw signature and hash values +are written to B<*rsig> and B<*rhash>. SSL_get_sigalgs() is similar to SSL_get_shared_sigalgs() except it returns -information about all signature algorithms advertised by the peer in the order +information about all signature algorithms supported by B in the order they were sent by the peer. =head1 RETURN VALUES -SSL_get0_sigalg(), SSL_get0_shared_sigalg(), SSL_get_shared_sigalgs() and -SSL_get_sigalgs() return the number of signature algorithms or B<0> if the -I parameter is out of range (too large). +SSL_get_shared_sigalgs() and SSL_get_sigalgs() return the number of +signature algorithms or B<0> if the B parameter is out of range. =head1 NOTES @@ -94,8 +45,8 @@ If an application is only interested in the highest preference shared signature algorithm it can just set B to zero. Any or all of the parameters B, B, B, B or -B can be set to NULL if the value is not required. By setting -them all to NULL and setting B to zero the total number of +B can be set to B if the value is not required. By setting +them all to B and setting B to zero the total number of signature algorithms can be determined: which can be zero. These functions must be called after the peer has sent a list of supported @@ -125,17 +76,9 @@ signature algorithm does not use a hash (for example Ed25519). L, L -=head1 HISTORY - -Prior to OpenSSL 4.0 SSL_get_shared_sigalgs() treated negative I values -the same way as out-of-range (too large positive) values, and returned 0. - -SSL_get0_shared_sigalg() and SSL_get0_sigalg() were added in OpenSSL -4.0. - =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2018 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_get_value_uint.pod b/doc/man3/SSL_get_value_uint.pod index c757f1ba25..df0ee6176b 100644 --- a/doc/man3/SSL_get_value_uint.pod +++ b/doc/man3/SSL_get_value_uint.pod @@ -12,9 +12,6 @@ SSL_VALUE_CLASS_FEATURE_REQUEST, SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, SSL_VALUE_CLASS_FEATURE_NEGOTIATED, SSL_VALUE_QUIC_STREAM_BIDI_LOCAL_AVAIL, SSL_VALUE_QUIC_STREAM_BIDI_REMOTE_AVAIL, SSL_VALUE_QUIC_STREAM_UNI_LOCAL_AVAIL, SSL_VALUE_QUIC_STREAM_UNI_REMOTE_AVAIL, SSL_VALUE_QUIC_IDLE_TIMEOUT, -SSL_VALUE_QUIC_UDP_PAYLOAD_SIZE_MAX, SSL_VALUE_QUIC_WINDOWCON, -SSL_VALUE_QUIC_WINDOWBSTR, SSL_VALUE_QUIC_WINDOWUSTR, -SSL_VALUE_QUIC_ACK_DELAY_EXPONENT, SSL_VALUE_QUIC_ACK_DELAY_MAX, SSL_VALUE_EVENT_HANDLING_MODE, SSL_VALUE_EVENT_HANDLING_MODE_INHERIT, SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT, @@ -48,12 +45,6 @@ manage negotiable features and configuration values for an SSL object #define SSL_VALUE_QUIC_STREAM_UNI_LOCAL_AVAIL #define SSL_VALUE_QUIC_STREAM_UNI_REMOTE_AVAIL #define SSL_VALUE_QUIC_IDLE_TIMEOUT - #define SSL_VALUE_QUIC_UDP_PAYLOAD_SIZE_MAX - #define SSL_VALUE_QUIC_WINDOWCON - #define SSL_VALUE_QUIC_WINDOWBSTR - #define SSL_VALUE_QUIC_WINDOWUSTR - #define SSL_VALUE_QUIC_ACK_DELAY_EXPONENT - #define SSL_VALUE_QUIC_ACK_DELAY_MAX #define SSL_VALUE_EVENT_HANDLING_MODE #define SSL_VALUE_EVENT_HANDLING_MODE_INHERIT @@ -167,7 +158,7 @@ documentation for a specific value specifies otherwise. =over 4 -=item B (connection/listener object) +=item B (connection object) Negotiated feature value. This configures the desired QUIC idle timeout in milliseconds, where 0 represents a lack of an idle timeout. This feature can @@ -177,65 +168,6 @@ changed. This release of OpenSSL uses a default value of 30 seconds. This default value may change between releases of OpenSSL. -=item B (connection/listener object) - -Feature (peer) request value. This configures the maximum UDP payload size in -bytes, corresponding to the QUIC max_udp_payload_size transport parameter -as defined in RFC 9000, Section 18.2. It limits the size of UDP datagrams the -local QUIC stack is willing to receive from the peer. It does not change the -maximum datagram payload size used on the transmit path. This feature can only -be configured prior to connection establishment and cannot be subsequently -changed. This value will be sent to the peer in the transport parameters. - -This release of OpenSSL uses a default value of 1200 bytes. This default value -may change between releases of OpenSSL. - -=item B (connection/listener object) - -Feature (peer) request value. This configures the initial QUIC connection-level -flow control receive window in bytes. This feature can only be configured prior -to connection establishment and cannot be subsequently changed. This value will -be sent to the peer in the transport parameters. - -This release of OpenSSL uses a default value of 768 * 1024 bytes. This default -value may change between releases of OpenSSL. - -=item B (connection/listener object) - -Feature (peer) request value. This sets the initial receive window size, in -bytes, for QUIC stream flow control on a bidirectional stream created by the -local endpoint. This feature can only be configured prior to connection -establishment and cannot be subsequently changed. This value will be sent to the -peer in the transport parameters. - -This release of OpenSSL uses a default value of 512 * 1024 bytes. This default -value may change between releases of OpenSSL. - -=item B (connection/listener object) - -As above, but configures the initial receive window size for QUIC stream flow -control on a unidirectional stream created by the remote endpoint. - -=item B (connection/listener object) - -Feature (peer) request value. This configures the ACK delay exponent. This -feature can only be configured prior to connection establishment and cannot be -subsequently changed. This value will be sent to the peer in the transport -parameters. - -This release of OpenSSL uses a default value of 3. This default value may change -between releases of OpenSSL. - -=item B (connection/listener object) - -Feature (peer) request value. This configures the maximum ACK delay in -milliseconds. This feature can only be configured prior to connection -establishment and cannot be subsequently changed. This value will be sent to the -peer in the transport parameters. - -This release of OpenSSL uses a default value of 25 milliseconds. This default -value may change between releases of OpenSSL. - =item B (connection object) Generic read-only statistical value. The number of bidirectional, @@ -407,16 +339,11 @@ L, L =head1 HISTORY -The values SSL_VALUE_QUIC_UDP_PAYLOAD_SIZE_MAX, SSL_VALUE_QUIC_WINDOWCON, -SSL_VALUE_QUIC_WINDOWBSTR, SSL_VALUE_QUIC_WINDOWUSTR, -SSL_VALUE_QUIC_ACK_DELAY_EXPONENT, and SSL_VALUE_QUIC_ACK_DELAY_MAX -were added in OpenSSL 4.1. - -The remaining functions and values described here were all added in OpenSSL 3.3. +These functions were added in OpenSSL 3.3. =head1 COPYRIGHT -Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2002-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_get_version.pod b/doc/man3/SSL_get_version.pod index 2d9fd78cfc..2412cbd1c2 100644 --- a/doc/man3/SSL_get_version.pod +++ b/doc/man3/SSL_get_version.pod @@ -3,8 +3,7 @@ =head1 NAME SSL_client_version, SSL_get_version, SSL_is_dtls, SSL_is_tls, SSL_is_quic, -SSL_CTX_is_quic, SSL_CTX_is_server, SSL_version - get the protocol information -of a connection +SSL_CTX_is_quic, SSL_version - get the protocol information of a connection =head1 SYNOPSIS @@ -18,7 +17,6 @@ of a connection int SSL_is_tls(const SSL *ssl); int SSL_is_quic(const SSL *ssl); int SSL_CTX_is_quic(const SSL_CTX *ctx); - int SSL_CTX_is_server(const SSL_CTX *ctx); int SSL_version(const SSL *s); @@ -43,9 +41,6 @@ SSL_is_quic() returns 1 if the connection is using QUIC or 0 if not. SSL_CTX_is_quic() returns 1 if the ctx creates QUIC SSL objects or 0 if not. -SSL_CTX_is_server() returns 1 if the ctx uses a I that allows it to be -a server (i.e. server-only or generic method) or 0 if not. - =head1 RETURN VALUES @@ -100,6 +95,10 @@ of the following: =over 4 +=item SSL3_VERSION + +The connection uses the SSLv3 protocol. + =item TLS1_VERSION The connection uses the TLSv1.0 protocol. @@ -144,12 +143,11 @@ L The SSL_is_dtls() function was added in OpenSSL 1.1.0. The SSL_is_tls() and SSL_is_quic() functions were added in OpenSSL 3.2. -The SSL_CTX_is_quic() and SSL_CTX_is_server() functions were added in -OpenSSL 4.0 +The SSL_CTX_is_quic() function was added in OpenSSL 4.0 =head1 COPYRIGHT -Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2001-2023 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_new.pod b/doc/man3/SSL_new.pod index 829229461d..d01996fba1 100644 --- a/doc/man3/SSL_new.pod +++ b/doc/man3/SSL_new.pod @@ -94,8 +94,6 @@ SSL_set0_client_CA_list() or similar functions =item any client certificate types configured via SSL_set1_client_certificate_types -=item any Encrypted Client Hello (ECH) settings (see L). - =back SSL_dup() is not supported on QUIC SSL objects and returns NULL if called on @@ -129,7 +127,7 @@ L =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2023 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_set1_echstore.pod b/doc/man3/SSL_set1_echstore.pod deleted file mode 100644 index a67c3e2acf..0000000000 --- a/doc/man3/SSL_set1_echstore.pod +++ /dev/null @@ -1,427 +0,0 @@ -=pod - -=head1 NAME - -SSL_set1_echstore, -OSSL_ECHSTORE_new, OSSL_ECHSTORE_free, -OSSL_ECHSTORE_new_config, OSSL_ECHSTORE_write_pem, -OSSL_ECHSTORE_read_echconfiglist, OSSL_ECHSTORE_get1_info, -OSSL_ECHSTORE_downselect, OSSL_ECHSTORE_set1_key_and_read_pem, -OSSL_ECHSTORE_read_pem, OSSL_ECHSTORE_num_entries, -OSSL_ECHSTORE_num_keys, OSSL_ECHSTORE_flush_keys, -SSL_CTX_set1_echstore, -SSL_CTX_get1_echstore, SSL_get1_echstore, SSL_ech_set1_server_names, -SSL_ech_set1_outer_server_name, SSL_ech_set1_outer_alpn_protos, -SSL_ech_get1_status, SSL_ech_set1_grease_suite, SSL_ech_set_grease_type, -SSL_ech_set_callback, SSL_ech_get1_retry_config, -SSL_CTX_ech_set1_outer_alpn_protos, -SSL_CTX_ech_set_callback,SSL_set1_ech_config_list -- Encrypted Client Hello (ECH) functions - -=head1 SYNOPSIS - - #include - - OSSL_ECHSTORE *OSSL_ECHSTORE_new(OSSL_LIB_CTX *libctx, const char *propq); - void OSSL_ECHSTORE_free(OSSL_ECHSTORE *es); - int OSSL_ECHSTORE_new_config(OSSL_ECHSTORE *es, - uint16_t echversion, uint16_t max_name_length, - const char *public_name, OSSL_HPKE_SUITE suite); - int OSSL_ECHSTORE_write_pem(OSSL_ECHSTORE *es, int index, BIO *out); - int OSSL_ECHSTORE_read_echconfiglist(OSSL_ECHSTORE *es, BIO *in); - int OSSL_ECHSTORE_get1_info(OSSL_ECHSTORE *es, int index, time_t *loaded_secs, - char **public_name, char **echconfig, - int *has_private, int *for_retry); - int OSSL_ECHSTORE_downselect(OSSL_ECHSTORE *es, int index); - int OSSL_ECHSTORE_set1_key_and_read_pem(OSSL_ECHSTORE *es, EVP_PKEY *priv, - BIO *in, int for_retry); - int OSSL_ECHSTORE_read_pem(OSSL_ECHSTORE *es, BIO *in, int for_retry); - int OSSL_ECHSTORE_num_entries(OSSL_ECHSTORE *es, int *numentries); - int OSSL_ECHSTORE_num_keys(OSSL_ECHSTORE *es, int *numkeys); - int OSSL_ECHSTORE_flush_keys(OSSL_ECHSTORE *es, time_t age); - int SSL_CTX_set1_echstore(SSL_CTX *ctx, OSSL_ECHSTORE *es); - int SSL_set1_echstore(SSL *s, OSSL_ECHSTORE *es); - OSSL_ECHSTORE *SSL_CTX_get1_echstore(const SSL_CTX *ctx); - OSSL_ECHSTORE *SSL_get1_echstore(const SSL *s); - int SSL_ech_set1_server_names(SSL *s, const char *inner_name, - const char *outer_name, int no_outer); - int SSL_ech_set1_outer_server_name(SSL *s, const char *outer_name, int no_outer); - int SSL_ech_set1_outer_alpn_protos(SSL *s, const unsigned char *protos, - const size_t protos_len); - int SSL_ech_get1_status(SSL *s, char **inner_sni, char **outer_sni); - int SSL_ech_set1_grease_suite(SSL *s, const char *suite); - int SSL_ech_set_grease_type(SSL *s, uint16_t type); - void SSL_ech_set_callback(SSL *s, SSL_ech_cb_func f); - int SSL_ech_get1_retry_config(SSL *s, unsigned char **ec, size_t *eclen); - void SSL_CTX_ech_set_callback(SSL_CTX *ctx, SSL_ech_cb_func f); - int SSL_CTX_ech_set1_outer_alpn_protos(SSL_CTX *ctx, - const unsigned char *protos, - const size_t protos_len); - int SSL_set1_ech_config_list(SSL *ssl, const uint8_t *ecl, size_t ecl_len); - -=head1 DESCRIPTION - -The Encrypted Client Hello (ECH) APIs described here are built around -the concept of an B which contains ECH configuration -information relevant for an B or B connection. - -This release only supports ECH shared-mode and has no support for -ECH split-mode. - -=head2 OSSL_ECHSTORE APIs - -The externally opaque type B allows applications to create and -manage ECHConfigList values, ECH private keys and associated meta-data. The -external APIs using B are: - -OSSL_ECHSTORE_new() and OSSL_ECHSTORE_free() create and free the -internal storage required. - -OSSL_ECHSTORE_new_config() allows the caller to create a new private key -value and a related "singleton" ECHConfigList structure. -("Singleton" meaning the ECHConfigList only contains one public key.) -The I is the ECHConfig version to use, which is typically -B with a value of 0xfe0d. The I -specifies the maximum known DNS name length that will be present in an ECH -extension (if known) and is used for ECH padding but should typically be zero, -to indicate no known maximum. The I is the DNS name to use in -the ECHConfig I field, and the I specifies the -B to use (see L for details.) - -OSSL_ECHSTORE_write_pem() allows the caller to produce an ECH PEM data structure -(conforming to the ECH PEM file format) from the B entry -identified by the I. (An I of B will select the -last entry. An I of B will output all public values, -and no private values, otherwise the I selects a specific entry with -zero selecting the first entry.) The output will be written to the I -B. - -The B APIs above will typically be used via the "openssl ech" -command line tool. - -OSSL_ECHSTORE_read_echconfiglist() reads from the I B and parses a -base64-encoded ECHConfigList value normally found in the "ech=" SvcParamKey -present in an SVCB or HTTPS RR retrieved from the DNS. The resulting set of -ECHConfig values, are associated with the I store, and can then be -associated with an B or B structure for TLS client connections. - -Input B values (such a I above) must not use unterminated B's. - -OSSL_ECHSTORE_get1_info() queries the store provided by I and finds the -entry within the store specified by I. The number of seconds since that -entry was first generated or loaded/decoded is stored in I, and -the related public name is stored in I<*public_name>. This function also -outputs a string useful for logging or display (as described in the -L section) and stores that in I<*echconfig>. It is -the callers responsibility to free the strings returned in I and -I after they have been returned. If the specified entry has a -private key associated with it then I will be set to 1, otherwise -it will be set to 0. Similarly if the ECHConfig for this entry will be included -in "retry-configs" then the I will be set to 1 or zero if that -ECHConfig will not be included in retry-configs. - -The ECH fallback scheme involving retry-configs is described -in Section 6.1.1 of RFC 9849. - -OSSL_ECHSTORE_downselect() provides the caller a way to select one particular -ECHConfig value based on the zero-based I from those stored in the -I, discarding the rest. This can be used by a client (via L -and L or equivalent) to pick a specific ECHConfig to use -in a TLS connection. - -OSSL_ECHSTORE_set1_key_and_read_pem() and OSSL_ECHSTORE_read_pem() can be used -to load a private key value and associated ECHConfigList from the B I -into an B structure. The former function pairs a -previously-loaded private key (in B format) with an associated -base64-encoded ECHConfigList in the I B. The latter function reads -both from an ECH PEM file. Those can be used (by servers) to enable ECH for an -B or B connection. In addition to loading those values, the -application can also indicate via I which ECHConfig values are to be -included in the I fallback scheme defined by the ECH protocol. - -An ECH PEM file may contain a private key and an ECHConfigList with more than -one ECHConfig, for example if different public keys, I values, or -AEAD/KDF settings are to be supported. When such a file is read, the resulting -B will contain one entry for each ECHConfig in the -ECHConfigList, so will be presented to applications as a set of "singleton" -ECHConfig values, with the private key associated with each matching public key -value. - -OSSL_ECHSTORE_num_entries() and OSSL_ECHSTORE_num_keys() allow an application -to see how many ECH configs (in I) and private keys (in -I) are present in the I B store. - -OSSL_ECHSTORE_flush_keys() allows a server to flush keys from I that were -loaded more than I seconds ago. The general model is that a server can -maintain an B into which it periodically loads the "latest" set -of keys, e.g. hourly, and also discards the keys that are too old, e.g. more -than 3 hours old. This allows for more robust private key management even if -public key distribution suffers temporary failures. - -SSL_CTX_set1_echstore() and SSL_set1_echstore() allow clients and servers to -associate I (an B) with an B or B structure. -ECH will be enabled for the relevant B or B connection when these -functions succeed. Any previously associated B will be freed via -OSSL_ECHSTORE_free(). Internally, B values within an B -or B connection are deep-copied, and are not refcounted. - -SSL_CTX_get1_echstore() and SSL_get1_echstore() provide access to the -B associated with an B or B connection. The -returned B can be modified and then re-associated with an -B or B connection. - -=head2 Client ECH Controls - -SSL_set1_ech_config_list() allows clients to setup ECH by associating an -ECHConfigList, I with an B connection I. This is compatible with -current BoringSSL APIs, allowing for smaller code changes for clients that -support OpenSSL or BoringSSL. Note that the input I here for OpenSSL can -be either base64 or binary encoded, but for BoringSSL it must be binary -encoded. - -SSL_ech_set1_server_names() and SSL_ech_set1_outer_server_name() allow clients -to more directly control the values to be used for inner and outer Server Name -Indication (SNI) values for an B connection, I. The I -provided will be used as with L to populate the -SNI value for the inner ClientHello. The I, if non-NULL, can -over-ride the public_name field of the ECHConfig used for the connection. The -I input allows a client to emit an outer ClientHello with no SNI at -all. Providing a NULL for the I means to send the I -provided from the ECHConfigList unless the I provided has the value -1. - -If a client has called L or -L then the ALPN value will be the same in the inner and -outer ClientHello messages. SSL_ech_set1_outer_alpn_protos() and -SSL_CTX_ech_set1_outer_alpn_protos() allow clients to set a specific value for -the ALPN sent in the outer ClientHello of the B connection, I. The -I and I inputs must be provided as for -L. - -If a client attempts ECH but that fails, or sends an ECH-GREASE'd ClientHello, -to an ECH-supporting server, then that server may return a set of ECH -retry-config values that the client could choose to use in a subsequent -connection. The client can detect this situation if SSL_ech_get1_status() for -the B connection I, returns a status of B, -and can then access the ECH retry config values via SSL_ech_get1_retry_config() -where the I value returned will contain a binary-encoded ECHConfigList -of length I. - -If a client makes a real attempt at ECH that fails then the server can also -return retry config values, and those can be used if they were authenticated -under the outer SNI used for the session. In this case the TLS session fails -returning the error B, and the ECH status of -B indicates that retry config values can be -accessed using SSL_ech_get1_retry_config(). The application can then choose to -use those in a subsequent attempt to establish a TLS session with the server. -If the TLS session fails for some other reason (e.g. a bad server Finished -message), then the retry config values will not be returned to the application. - -"GREASEing" (defined in RFC8701) is a mechanism intended to discourage protocol -ossification that can be used for ECH. - -SSL_ech_set1_grease_suite() allows a client to GREASE ECH for the B -connection I, using a specific B as the value for I -(see L). SSL_ech_set_grease_type() allows a -client to add a GREASE'd ECH for the B connection I, using the -specified ClientHello extension number I. - -Clients and servers can query the status of ECH for a B connection I, -using the SSL_ech_get1_status() function. As SNI handling is core to ECH this -will also return the I and I values to be used or that -were used as well as a status code as the return value. These name values must -be freed by the caller. The various status values returned by this function -are as described in L. - -=head2 Callback Functions - -Applications can set a callback function that will be called when the -outcome from an attempt at ECH has been determined. On the server, -that happens early, as part of construction of the ServerHello message. -On the client, the callback will happen after the SeverHello has -been processed. In the event of HelloRetryRequest, the callback will -only be triggered when processing the second ServerHello. The callback -function will be triggered even if the client is only GREASEing. - -The callback function prototype is: - - typedef unsigned int (*SSL_ech_cb_func)(SSL *s, const char *str); - -To set a callback function for the B connection I, use -SSL_ech_set_callback() or SSL_CTX_ech_set_callback() for a B I - -the I input should match the above prototype. - -When the callback function is called, the I will point at a string -intended for logging describing the state of ECH processing. -Applications should not attempt to parse that string as the value depends -on compile time settings, local configuration and the specific processing -that happened prior to the callback. Applications that need to branch based -on the outcome of ECH processing should instead make a call to -SSL_ech_get1_status() from within their callback function. - -An example string I as seen on a client might be: - - ech_attempted=1 - ech_attempted_type=0xfe0d - ech_atttempted_cid=0x5d - ech_done=1 - ech_grease=0 - ech_returned_len=0 - ech_backend=0 - ech_success=1 - 2 ECHConfig values loaded - cfg(0): [fe0d,5d,cover.defo.ie,[0020,0001,0001],190984309c1a24cb944c005eb79d9c72ca9a4a979194b553dfd0bffc6b5c152d,00,00] - cfg(1): [fe0d,fd,cover.defo.ie,[0020,0001,0001],46dd4e2c81bb15ef9d194c99b86983844e2a1387e4fb7e7d3b8d368c8e1b4d2a,00,00] - -=head2 Constants - -Some externally visible limits: - -=over 4 - -=item B 1500, maximum length of an ECH ciphertext to en/decode - -=item B 32, minimum length of an encoded ECHConfig - -=item B 1500, maximum length of an encoded ECHConfig - -=item B 512, maximum length of an ECHConfig extension - -=item B 255, maximum for ECHConfig max name length - -=item B 255, maximum length of an ECHConfig public name - -=item B 255, maximum overall length of an ALPN - -=item B 20, maximum number of extensions compressed via outer-exts - -=item B 32, maximum total number of extensions allowed - -=back - -ECH version - the only supported version is 0xfe0d currently. - -=over 4 - -=item B 0xfe0d, official ECHConfig version - -=item B OSSL_ECH_RFC9849_VERSION - -=back - -Values for I - -=over 4 - -=item B 1. use corresponding ECHConfig values - -=item B 0. don't use corresponding ECHConfig values - -=back - -Indexing an OSSL_ECHSTORE - -=over 4 - -=item B, -1 select the last entry in the store - -=item B, -2 select all entries in the store, e.g. to print public values - -=back - -=head2 String form of ECHConfig - -OSSL_ECHSTORE_get1_info() returns the string form of the ECH public name plus -a string describing the content of the ECHConfig for example: - - [fe0d,4d,example.com,[0020,0001,0002],c103d20dddce9b4445829bf01f5b533b728bfa0ebe3a97da33574bc096bb846e,00,00] - -In the order presented in the example above, the I is 0xfe0d, the -I is 0x4d, the I is "example.com", there is one -ciphersuite with a I of 0x20, I is 0x01 and I is 0x02; -the I is the hexadecimal string "c1...6e", the I -is 0x00 and the I length is 0x00 as no ECHConfig extensions are -present. - -=head1 RETURN VALUES - -SSL_set1_echstore(), SSL_set1_ech_config_list(), OSSL_ECHSTORE_new_config(), -OSSL_ECHSTORE_write_pem(), OSSL_ECHSTORE_read_echconfiglist(), -OSSL_ECHSTORE_get1_info(), OSSL_ECHSTORE_downselect(), -OSSL_ECHSTORE_set1_key_and_read_pem(), OSSL_ECHSTORE_read_pem(), -OSSL_ECHSTORE_num_keys(), OSSL_ECHSTORE_num_entries(), -OSSL_ECHSTORE_flush_keys(), SSL_CTX_set1_echstore(), -SSL_ech_set_server_names(), SSL_ech_set_outer_server_name(), -SSL_ech_set_outer_alpn_protos(), -SSL_ech_set_grease_suite(), SSL_ech_set_grease_type(), -SSL_ech_get_retry_config() and SSL_CTX_ech_set1_outer_alpn_protos() all return -zero on error and one on success. - -SSL_ech_get1_status() returns one of the following values: - -=over 4 - -=item B 4, ECH backend: saw an ech_is_inner - -=item B 3, GREASEd and got an ECH in return - -=item B 2, ECH GREASE happened - -=item B 1, Success - -=item B 0, Some internal or protocol error - -=item B -100, Some in/out arguments were NULL - -=item B -101, ECH wasn't attempted - -=item B -102, ECH ok but server or client cert bad - -=item B -103, ECH wasn't configured - -=item B -105, We tried, failed and got an ECH, from a verified name - -=item B -106, We tried, failed and got an ECH, from a bad name - -=back - -SSL_ech_set_callback(), SSL_CTX_ech_set_callback(), OSSL_ECHSTORE_free() have -no return value. - -SSL_CTX_get1_echstore(), SSL_get1_echstore() and OSSL_ECHSTORE_new() return a -pointer to an B. - -Note that SSL_CTX_ech_set1_outer_alpn_protos() and -SSL_ech_set1_outer_alpn_protos() return zero on error and 1 on success. This -is in contrast to L and L -which (unusually for OpenSSL) return 0 on success and 1 on error. - -=head1 SEE ALSO - -=over 4 - -=item Encrypted ClientHello specification: L - -=item ECH PEM file format specification: L - -=item RFC8701: L - -=back - -ECH command line options are described in the manual pages for -L, L and L. - -=head1 HISTORY - -The functionality described here was added in OpenSSL 4.0. - -=head1 COPYRIGHT - -Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - -Licensed under the Apache License 2.0 (the "License"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file LICENSE in the source distribution or at -L. - -=cut diff --git a/doc/man3/SSL_set1_host.pod b/doc/man3/SSL_set1_host.pod index 3a2487a268..b65116a53f 100644 --- a/doc/man3/SSL_set1_host.pod +++ b/doc/man3/SSL_set1_host.pod @@ -2,10 +2,7 @@ =head1 NAME -SSL_set1_dnsname, SSL_add1_dnsname, -SSL_set1_ipaddr, SSL_add1_ipaddr, -SSL_set1_host, SSL_add1_host, -SSL_set_hostflags, SSL_get0_peername - +SSL_set1_host, SSL_add1_host, SSL_set_hostflags, SSL_get0_peername - SSL server verification parameters =head1 SYNOPSIS @@ -14,58 +11,39 @@ SSL server verification parameters int SSL_set1_host(SSL *s, const char *host); int SSL_add1_host(SSL *s, const char *host); - int SSL_set1_dnsname(SSL *s, const char *dnsname); - int SSL_add1_dnsname(SSL *s, const char *dnsname); - int SSL_set1_ipaddr(SSL *s, const uint8_t *ip_asc); - int SSL_add1_ipaddr(SSL *s, const char *ip_asc); void SSL_set_hostflags(SSL *s, unsigned int flags); const char *SSL_get0_peername(SSL *s); - int SSL_set1_host(SSL *s, const char *host); - int SSL_add1_host(SSL *s, const char *host); - =head1 DESCRIPTION -These functions maintain lists of expected matches for peer -certificate subject alternative name (SAN) values is peer certificates -presented in an SSL connection. A peer certificate will be considered -a match for validation purposes if all of the following are true: +These functions configure server hostname checks in the SSL client. -* Any name in the dnsname list, if not empty, matches any SAN dnsname - in the certificate. If verification flags allow it, these will also - attempt to match against the CN in the subject. +SSL_set1_host() sets in the verification parameters of I +the expected DNS hostname or IP address to I, +clearing any previously specified IP address and hostnames. +If I is NULL or the empty string, IP address +and hostname checks are not performed on the peer certificate. +When a nonempty I is specified, certificate verification automatically +checks the peer hostname via L with I as specified +via SSL_set_hostflags(). Clients that enable DANE TLSA authentication +via L should leave it to that function to set +the primary reference identifier of the peer, and should not call +SSL_set1_host(). -* Any address in the IP address list, if not empty, matches any IP - address SAN in the certificate. +SSL_add1_host() adds I as an additional reference identifier +that can match the peer's certificate. Any previous hostnames +set via SSL_set1_host() or SSL_add1_host() are retained. +Adding an IP address is allowed only if no IP address has been set before. +No change is made if I is NULL or empty. +When an IP address and/or multiple hostnames are configured, +the peer is considered verified when any of these matches. +This function is required for DANE TLSA in the presence of service name indirection +via CNAME, MX or SRV records as specified in RFCs 7671, 7672, and 7673. -The set1 family of functions clears the list, and sets the first value -to the provided parameter if the provided parameter is not NULL. - -The add1 family of functions adds a single entry to the list. - -SSL_set1_dnsname() clears the list of dnsnames to match certificate -SAN dnsnames. -If I is not NULL, it will be checked for -validity and added to the list of DNS name reference identifiers as its first entry. - -SSL_set1_ipaddr() clears the list of addresses to match certificate IP address SANs. -If is not NULL, it is parsed as an -IPv4 or IPv6 address and added to the list as its first entry. - -SSL_add1_dnsname() adds I to the list of DNS name reference -identifiers, if it has the correct structure for a DNS name. This -function is required for DANE TLSA in the presence of service name -indirection via CNAME, MX or SRV records as specified in RFCs 7671, -7672, and 7673. - -SSL_add1_ipaddr() adds I to the list of IP addresses, if it parses as an IP address. - -It is recommended that TLS clients use SSL_set1_dnsname() to configure server -hostname validation and L to configure -Server Name Indication (SNI), which may be crucial also for correct -server certificate selection and/or routing of the connection request. -SSL_set1_ipaddr() -should be used for server IP address validation, +TLS clients are recommended to use SSL_set1_host() or SSL_add1_host() +for server hostname or IP address validation, +as well as L for Server Name Indication (SNI), +which may be crucial also for correct routing of the connection request. SSL_set_hostflags() sets the I that will be passed to L when name checks are applicable, by default @@ -90,35 +68,8 @@ of scope with the RFC 7671 DANE-EE(3) certificate usage, and the internal check will be suppressed as appropriate when DANE is enabled. -=head1 DEPRECATED FUNCTIONS - -SSL_set1_host and SSL_add1_host are deprecated as of OpenSSL 4.0.0. -SSL_set1_dnsname(), SSL_add1_dnsname(), SSL_set1_ipaddr() and SSL_add1_ipaddr() should be used instead. - -SSL_set1_host() sets in the verification parameters of I -the expected DNS hostname or IP address to I, -clearing any previously specified IP address and hostnames. -If I is NULL or the empty string, IP address -and hostname checks are not performed on the peer certificate. -When a nonempty I is specified, certificate verification automatically -checks the peer hostname via L with I as specified -via SSL_set_hostflags(). Clients that enable DANE TLSA authentication -via L should leave it to that function to set -the primary reference identifier of the peer, and should not call -SSL_set1_host(). - -SSL_add1_host() adds I as an additional reference identifier -that can match the peer's certificate. Any previous hostnames set via -SSL_set1_host() or SSL_add1_host() are retained. Adding an IP address -is allowed only if no IP address has been set before. No change is -made if I is NULL or empty. The peer is considered verified -when any of the added hostnames, if present, match, and the provided -IP address, if present, matches. - =head1 RETURN VALUES -SSL_set1_dnsname(), SSL_set1_ipaddr(), -SSL_add1_dnsname(), SSL_add1_ipaddr(), SSL_set1_host() and SSL_add1_host() return 1 for success and 0 for failure. @@ -140,9 +91,9 @@ and must be copied by the application if it is to be retained beyond the lifetime of the SSL connection. SSL_set_hostflags(ssl, X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS); - if (!SSL_set1_dnsname(ssl, "smtp.example.com")) + if (!SSL_set1_host(ssl, "smtp.example.com")) /* error */ - if (!SSL_add1_dnsname(ssl, "example.com")) + if (!SSL_add1_host(ssl, "example.com")) /* error */ /* XXX: Perform SSL_connect() handshake and handle errors here */ @@ -164,11 +115,9 @@ L, L These functions were added in OpenSSL 1.1.0. -SSL_set1_host and SSL_add1_host were deprecated in OpenSSL 4.0.0 - =head1 COPYRIGHT -Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_set_connect_state.pod b/doc/man3/SSL_set_connect_state.pod index 7c1969e7fc..559d23a759 100644 --- a/doc/man3/SSL_set_connect_state.pod +++ b/doc/man3/SSL_set_connect_state.pod @@ -23,8 +23,6 @@ SSL_set_accept_state() sets B to work in server mode. SSL_is_server() checks if B is working in server mode. -B must point to a valid SSL object and B be NULL. - =head1 NOTES When the SSL_CTX object was created with L, diff --git a/doc/man3/SSL_set_session_secret_cb.pod b/doc/man3/SSL_set_session_secret_cb.pod index e40479ce1f..e79d81d40a 100644 --- a/doc/man3/SSL_set_session_secret_cb.pod +++ b/doc/man3/SSL_set_session_secret_cb.pod @@ -2,10 +2,8 @@ =head1 NAME -SSL_set_session_secret_cb, tls_session_secret_cb_fn, -SSL_set_session_ticket_ext, SSL_set_session_ticket_ext_cb, -tls_session_ticket_ext_cb_fn -- set the session secret and EAP-FAST session ticket extension callbacks +SSL_set_session_secret_cb, tls_session_secret_cb_fn +- set the session secret callback =head1 SYNOPSIS @@ -19,15 +17,6 @@ tls_session_ticket_ext_cb_fn tls_session_secret_cb_fn session_secret_cb, void *arg); - typedef int (*tls_session_ticket_ext_cb_fn)(SSL *s, const unsigned char *data, - int len, void *arg); - - int SSL_set_session_ticket_ext(SSL *s, void *ext_data, int ext_len); - - int SSL_set_session_ticket_ext_cb(SSL *s, - tls_session_ticket_ext_cb_fn cb, - void *arg); - =head1 DESCRIPTION SSL_set_session_secret_cb() sets the session secret callback to be used @@ -55,29 +44,13 @@ server. The callback is also supplied with an additional argument in I which is the argument that was provided to the original SSL_set_session_secret_cb() call. -SSL_set_session_ticket_ext() is used on the client-side to set the session ticket -extension data for EAP-FAST (RFC4851). The I argument is a pointer to -the extension data, and I is the length of that data. I must -be between 0 and 65535. If I is NULL, then the session ticket -extension will not be sent. - -SSL_set_session_ticket_ext_cb() is used on the server-side to set a callback -(I) that will be called when a session ticket extension is received. The -callback is supplied with the extension data in I and its length in -I, as well as the additional argument I that was provided when the -callback was set. - =head1 RETURN VALUES -SSL_set_session_secret_cb(), SSL_set_session_ticket_ext(), and -SSL_set_session_ticket_ext_cb() return 1 on success and 0 on failure. +SSL_set_session_secret_cb() returns 1 on success and 0 on failure. -If the session secret callback returns 1 then this indicates it has successfully -set the secret. A return value of 0 indicates that the secret has not been set. -On the client this will cause an immediate abort of the handshake. - -The session ticket extension callback should return 1 for success. A return value -of 0 indicates failure and will cause the handshake to abort immediately. +If the callback returns 1 then this indicates it has successfully set the +secret. A return value of 0 indicates that the secret has not been set. On the +client this will cause an immediate abort of the handshake. =head1 SEE ALSO @@ -86,7 +59,7 @@ L =head1 COPYRIGHT -Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/SSL_want.pod b/doc/man3/SSL_want.pod index 719e2011d5..53a1174938 100644 --- a/doc/man3/SSL_want.pod +++ b/doc/man3/SSL_want.pod @@ -31,7 +31,7 @@ by SSL_want(). SSL_want() examines the internal state information of the SSL object. Its return values are similar to that of L. -Unlike L, which also evaluates (indirectly) the +Unlike L, which also evaluates the error queue, the results are obtained by examining an internal state flag only. The information must therefore only be used for normal operation under nonblocking I/O. Error conditions are not handled and must be treated @@ -116,7 +116,7 @@ SSL_want_retry_verify() was added in OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2001-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/UI_new.pod b/doc/man3/UI_new.pod index 613dd4ce6d..eb80f453d5 100644 --- a/doc/man3/UI_new.pod +++ b/doc/man3/UI_new.pod @@ -159,20 +159,17 @@ With the description "pass phrase" and the filename "foo.key", that becomes string and may include encodings that will be processed by the other method functions. -UI_add_user_data() sets the user data pointer for the method to use at any +UI_add_user_data() adds a user data pointer for the method to use at any time. The built-in UI method doesn't care about this info. Note that several -calls to this function doesn't add data, it replaces the previous pointer +calls to this function doesn't add data, it replaces the previous blob with the one given as argument. -The return value is the previously set user data pointer if it was set -using UI_add_user_data() and thus the caller owns it, otherwise NULL. UI_dup_user_data() duplicates the user data and works as an alternative to UI_add_user_data() when the user data needs to be preserved for a longer duration, perhaps even the lifetime of the application. The UI object takes ownership of this duplicate and will free it whenever it gets replaced or the UI is destroyed. UI_dup_user_data() returns 0 on success, or -1 on memory -allocation failure or if the method doesn't have a duplicator and a destructor -function. +allocation failure or if the method doesn't have a duplicator function. UI_get0_user_data() retrieves the data that has last been given to the UI with UI_add_user_data() or UI_dup_user_data. @@ -227,9 +224,6 @@ is less than or equal to 0 otherwise. UI_construct_prompt() returns a string or NULL if an error occurred. -UI_add_user_data() returns -the user data pointer previously set using this function, otherwise NULL. - UI_dup_user_data() returns 0 on success or -1 on error. UI_get0_result() returns a string or NULL on error. @@ -251,7 +245,7 @@ The UI_dup_user_data() function was added in OpenSSL 1.1.1. =head1 COPYRIGHT -Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2001-2020 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509V3_EXT_print.pod b/doc/man3/X509V3_EXT_print.pod deleted file mode 100644 index 3dca6c021e..0000000000 --- a/doc/man3/X509V3_EXT_print.pod +++ /dev/null @@ -1,51 +0,0 @@ -=pod - -=head1 NAME - -X509V3_EXT_print, X509V3_EXT_print_fp - pretty print X509 certificate extensions - -=head1 SYNOPSIS - - #include - - int X509V3_EXT_print(BIO *out, const X509_EXTENSION *ext, unsigned long flag, int indent); - int X509V3_EXT_print_fp(FILE *out, const X509_EXTENSION *ext, int flag, int indent); - -=head1 DESCRIPTION - -X509V3_EXT_print() and X509V3_EXT_print_fp() parse and print the extension -info from I to I or I with indentation set via I. -I determines the behaviour if an extension could not be parsed and can be -one of: -B (equivalent to 0): an unknown or unparsable extension -stops the parsing and the function returns a failure. -B: an unknown or unparsable extension is handled by -printing it through the B function, and the function returns -success. -B: an unknown or unparsable extension is handled by -printing it through the B function, and the function returns -success, -B: an unknown or unparsable extension is handled by -printing either "" or "", and the function returns -success. - -=head1 RETURN VALUES - -X509V3_EXT_print() and X509V3_EXT_print_fp() return 1 for success and 0 for -failure. - -=head1 SEE ALSO - -L, -L, - -=head1 COPYRIGHT - -Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - -Licensed under the Apache License 2.0 (the "License"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file LICENSE in the source distribution or at -L. - -=cut diff --git a/doc/man3/X509V3_get_d2i.pod b/doc/man3/X509V3_get_d2i.pod index 2ddf35c33d..330464e0c8 100644 --- a/doc/man3/X509V3_get_d2i.pod +++ b/doc/man3/X509V3_get_d2i.pod @@ -19,7 +19,7 @@ X509_REVOKED_get0_extensions - X509 extension decode and encode functions int X509V3_add1_i2d(STACK_OF(X509_EXTENSION) **x, int nid, void *value, int crit, unsigned long flags); - void *X509V3_EXT_d2i(const X509_EXTENSION *ext); + void *X509V3_EXT_d2i(X509_EXTENSION *ext); X509_EXTENSION *X509V3_EXT_i2d(int ext_nid, int crit, void *ext_struc); void *X509_get_ext_d2i(const X509 *x, int nid, int *crit, int *idx); @@ -253,7 +253,7 @@ X509_ACERT_get0_extensions() were added in OpenSSL 3.4. =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509V3_set_ctx.pod b/doc/man3/X509V3_set_ctx.pod index 62b5950658..6f9af309f4 100644 --- a/doc/man3/X509V3_set_ctx.pod +++ b/doc/man3/X509V3_set_ctx.pod @@ -19,6 +19,7 @@ X509V3_set_ctx() fills in the basic fields of I of type B, providing details potentially needed by functions producing X509 v3 extensions. These may make use of fields of the certificate I, the certification request I, or the certificate revocation list I. +At most one of these three parameters can be non-NULL. When constructing the subject key identifier of a certificate by computing a hash value of its public key, the public key is taken from I or I. Similarly, when constructing subject alternative names from any email addresses @@ -44,8 +45,6 @@ to provide fallback data for the authority key identifier extension. =head1 RETURN VALUES -X509V3_set_ctx() does not return a value. - X509V3_set_issuer_pkey() returns 1 on success and 0 on error. =head1 SEE ALSO @@ -60,7 +59,7 @@ CTX_TEST was deprecated in OpenSSL 3.0; use X509V3_CTX_TEST instead. =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_ALGOR_dup.pod b/doc/man3/X509_ALGOR_dup.pod index 64db83f749..6133735ea5 100644 --- a/doc/man3/X509_ALGOR_dup.pod +++ b/doc/man3/X509_ALGOR_dup.pod @@ -15,7 +15,7 @@ X509_ALGOR_copy - AlgorithmIdentifier functions int X509_ALGOR_set0(X509_ALGOR *alg, ASN1_OBJECT *aobj, int ptype, void *pval); void X509_ALGOR_get0(const ASN1_OBJECT **paobj, int *pptype, const void **ppval, const X509_ALGOR *alg); - int X509_ALGOR_set_md(X509_ALGOR *alg, const EVP_MD *md); + void X509_ALGOR_set_md(X509_ALGOR *alg, const EVP_MD *md); int X509_ALGOR_cmp(const X509_ALGOR *a, const X509_ALGOR *b); int X509_ALGOR_copy(X509_ALGOR *dest, const X509_ALGOR *src); @@ -49,23 +49,20 @@ a duplicate of each (and free any thing pointed to from within *dest). X509_ALGOR_dup() returns a valid B structure or NULL if an error occurred. -X509_ALGOR_set0(), X509_ALGOR_set_md(), and X509_ALGOR_copy() -return 1 on success or 0 on error. +X509_ALGOR_set0() and X509_ALGOR_copy() return 1 on success or 0 on error. -X509_ALGOR_get0() returns no values. +X509_ALGOR_get0() and X509_ALGOR_set_md() return no values. X509_ALGOR_cmp() returns 0 if the two parameters have identical encodings and nonzero otherwise. =head1 HISTORY -X509_ALGOR_copy() was added in OpenSSL 1.1.1e. - -X509_ALGOR_set_md() returns a value since OpenSSL 4.0. +The X509_ALGOR_copy() was added in 1.1.1e. =head1 COPYRIGHT -Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2002-2022 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_ATTRIBUTE.pod b/doc/man3/X509_ATTRIBUTE.pod index a7054395b7..f2f7597d0b 100644 --- a/doc/man3/X509_ATTRIBUTE.pod +++ b/doc/man3/X509_ATTRIBUTE.pod @@ -61,11 +61,11 @@ X509_ATTRIBUTE_get0_data, X509_ATTRIBUTE_get0_object, X509_ATTRIBUTE_get0_type int X509_ATTRIBUTE_set1_object(X509_ATTRIBUTE *attr, const ASN1_OBJECT *obj); int X509_ATTRIBUTE_set1_data(X509_ATTRIBUTE *attr, int attrtype, const void *data, int len); - const void *X509_ATTRIBUTE_get0_data(const X509_ATTRIBUTE *attr, int idx, - int atrtype, void *data); + void *X509_ATTRIBUTE_get0_data(X509_ATTRIBUTE *attr, int idx, int atrtype, + void *data); int X509_ATTRIBUTE_count(const X509_ATTRIBUTE *attr); - const ASN1_OBJECT *X509_ATTRIBUTE_get0_object(const X509_ATTRIBUTE *attr); - const ASN1_TYPE *X509_ATTRIBUTE_get0_type(const X509_ATTRIBUTE *attr, int idx); + ASN1_OBJECT *X509_ATTRIBUTE_get0_object(X509_ATTRIBUTE *attr); + ASN1_TYPE *X509_ATTRIBUTE_get0_type(X509_ATTRIBUTE *attr, int idx); =head1 DESCRIPTION @@ -253,7 +253,7 @@ L, =head1 COPYRIGHT -Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_CRL_get0_by_serial.pod b/doc/man3/X509_CRL_get0_by_serial.pod index be625c61f3..8ec5bfc0da 100644 --- a/doc/man3/X509_CRL_get0_by_serial.pod +++ b/doc/man3/X509_CRL_get0_by_serial.pod @@ -14,7 +14,7 @@ functions int X509_CRL_get0_by_serial(X509_CRL *crl, X509_REVOKED **ret, const ASN1_INTEGER *serial); - int X509_CRL_get0_by_cert(X509_CRL *crl, X509_REVOKED **ret, const X509 *x); + int X509_CRL_get0_by_cert(X509_CRL *crl, X509_REVOKED **ret, X509 *x); STACK_OF(X509_REVOKED) *X509_CRL_get_REVOKED(const X509_CRL *crl); @@ -105,15 +105,11 @@ L =head1 HISTORY -X509_CRL_get0_by_cert() was constified in OpenSSL 4.0. - X509_CRL_get_REVOKED() was constified in OpenSSL 4.0. -X509_CRL_get0_by_cert was constified in OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2020 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_EXTENSION_set_object.pod b/doc/man3/X509_EXTENSION_set_object.pod index 627a68d6fa..ff5de78ad7 100644 --- a/doc/man3/X509_EXTENSION_set_object.pod +++ b/doc/man3/X509_EXTENSION_set_object.pod @@ -12,7 +12,7 @@ functions int X509_EXTENSION_set_object(X509_EXTENSION *ex, const ASN1_OBJECT *obj); int X509_EXTENSION_set_critical(X509_EXTENSION *ex, int crit); - int X509_EXTENSION_set_data(X509_EXTENSION *ex, const ASN1_OCTET_STRING *data); + int X509_EXTENSION_set_data(X509_EXTENSION *ex, ASN1_OCTET_STRING *data); X509_EXTENSION *X509_EXTENSION_create_by_NID(X509_EXTENSION **ex, int nid, int crit, @@ -21,9 +21,9 @@ functions const ASN1_OBJECT *obj, int crit, ASN1_OCTET_STRING *data); - const ASN1_OBJECT *X509_EXTENSION_get_object(const X509_EXTENSION *ex); + ASN1_OBJECT *X509_EXTENSION_get_object(X509_EXTENSION *ex); int X509_EXTENSION_get_critical(const X509_EXTENSION *ex); - const ASN1_OCTET_STRING *X509_EXTENSION_get_data(const X509_EXTENSION *ne); + ASN1_OCTET_STRING *X509_EXTENSION_get_data(X509_EXTENSION *ne); =head1 DESCRIPTION @@ -86,7 +86,7 @@ L =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2016 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_LOOKUP.pod b/doc/man3/X509_LOOKUP.pod index b17a47e9bb..2c1d88c0fd 100644 --- a/doc/man3/X509_LOOKUP.pod +++ b/doc/man3/X509_LOOKUP.pod @@ -123,14 +123,10 @@ I indicates what type of object is expected. This can only be used with a lookup using the implementation L. -X509_LOOKUP_add_store_ex() passes a URI for a directory-like or file-like -structure from which containers with certificates and CRLs are loaded on demand +X509_LOOKUP_add_store_ex() passes a URI for a directory-like structure +from which containers with certificates and CRLs are loaded on demand into the associated B. The library context I and property query I are used when fetching algorithms from providers. -If I is not NULL, it must be a URI to a store, which may -represent a single container or a whole catalogue of containers. -If I starts with the scheme C, it is treated like a local file -or directory. See also ossl_store-file(7). X509_LOOKUP_add_store() is similar to X509_LOOKUP_add_store_ex() but uses NULL for the library context I and property query I. diff --git a/doc/man3/X509_LOOKUP_hash_dir.pod b/doc/man3/X509_LOOKUP_hash_dir.pod index b512f2a3cf..35160e87c5 100644 --- a/doc/man3/X509_LOOKUP_hash_dir.pod +++ b/doc/man3/X509_LOOKUP_hash_dir.pod @@ -81,7 +81,7 @@ set of CAs. B is a more advanced method, which loads certificates and CRLs on demand, and caches them in memory once -they are loaded. It also checks for newer CRLs +they are loaded. As of OpenSSL 1.0.0, it also checks for newer CRLs upon each lookup, so that newer CRLs are as soon as they appear in the directory. @@ -110,8 +110,12 @@ When checking for new CRLs once one CRL for given hash value is loaded, hash_dir lookup method checks only for certificates with sequence number greater than that of the already cached CRL. +Note that the hash algorithm used for subject name hashing changed in OpenSSL +1.0.0, and all certificate stores have to be rehashed when moving from OpenSSL +0.9.8 to 1.0.0. + OpenSSL includes a L utility which creates symlinks with -hashed names for files in PEM format in a given directory. +hashed names for all files with F<.pem> suffix in a given directory. =head2 OSSL_STORE Method @@ -140,7 +144,6 @@ the number of loaded objects or 0 on error. =head1 SEE ALSO -L, L, L, L, @@ -149,9 +152,6 @@ L =head1 HISTORY -The hash algorithm used for subject name hashing changed in OpenSSL 1.0.0. -All certificate stores had to be rehashed when moving from OpenSSL 0.9.8 to 1.0.0. - The functions X509_load_cert_file_ex(), X509_load_cert_crl_file_ex() and X509_LOOKUP_store() were added in OpenSSL 3.0. diff --git a/doc/man3/X509_NAME_ENTRY_get_object.pod b/doc/man3/X509_NAME_ENTRY_get_object.pod index c35c6c202a..7533a586b1 100644 --- a/doc/man3/X509_NAME_ENTRY_get_object.pod +++ b/doc/man3/X509_NAME_ENTRY_get_object.pod @@ -11,8 +11,8 @@ X509_NAME_ENTRY_create_by_OBJ - X509_NAME_ENTRY utility functions #include - const ASN1_OBJECT *X509_NAME_ENTRY_get_object(const X509_NAME_ENTRY *ne); - const ASN1_STRING *X509_NAME_ENTRY_get_data(const X509_NAME_ENTRY *ne); + ASN1_OBJECT *X509_NAME_ENTRY_get_object(const X509_NAME_ENTRY *ne); + ASN1_STRING *X509_NAME_ENTRY_get_data(const X509_NAME_ENTRY *ne); int X509_NAME_ENTRY_set_object(X509_NAME_ENTRY *ne, const ASN1_OBJECT *obj); int X509_NAME_ENTRY_set_data(X509_NAME_ENTRY *ne, int type, @@ -86,7 +86,7 @@ L =head1 COPYRIGHT -Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2002-2018 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_NAME_get_index_by_NID.pod b/doc/man3/X509_NAME_get_index_by_NID.pod index 6a9764fda8..d786b420a1 100644 --- a/doc/man3/X509_NAME_get_index_by_NID.pod +++ b/doc/man3/X509_NAME_get_index_by_NID.pod @@ -15,9 +15,7 @@ X509_NAME lookup and enumeration functions const ASN1_OBJECT *obj, int lastpos); int X509_NAME_entry_count(const X509_NAME *name); - const X509_NAME_ENTRY *X509_NAME_get_entry(const X509_NAME *name, int loc); - - Deprecated Functions: + X509_NAME_ENTRY *X509_NAME_get_entry(const X509_NAME *name, int loc); int X509_NAME_get_text_by_NID(const X509_NAME *name, int nid, char *buf, int len); @@ -53,12 +51,13 @@ of space needed in B (excluding the final null) is returned. =head1 NOTES -X509_NAME_get_text_by_NID() and X509_NAME_get_text_by_OBJ() have been -deprecated since OpenSSL 4.0. They have various limitations which make -them of minimal use in practice. They can only find the first matching -entry and will copy the contents of the field verbatim: this can be -highly confusing if the target is a multicharacter string type like a -BMPString or a UTF8String. +X509_NAME_get_text_by_NID() and X509_NAME_get_text_by_OBJ() should be +considered deprecated because they +have various limitations which make them +of minimal use in practice. They can only find the first matching +entry and will copy the contents of the field verbatim: this can +be highly confusing if the target is a multicharacter string type +like a BMPString or a UTF8String. For a more general solution X509_NAME_get_index_by_NID() or X509_NAME_get_index_by_OBJ() should be used followed by @@ -117,7 +116,7 @@ L, L =head1 COPYRIGHT -Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2002-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_NAME_print_ex.pod b/doc/man3/X509_NAME_print_ex.pod index f09bd1f79f..e43bb191f5 100644 --- a/doc/man3/X509_NAME_print_ex.pod +++ b/doc/man3/X509_NAME_print_ex.pod @@ -32,8 +32,9 @@ I is ignored. Otherwise, at most I bytes will be written, including the ending '\0', and I is returned. -X509_NAME_print() prints out I to I on a single line. -The I parameter is ignored and retained only for API compatibility. +X509_NAME_print() prints out I to I indenting each line by I +characters. Multiple lines are used if the output (including indent) exceeds +80 characters. =head1 NOTES diff --git a/doc/man3/X509_STORE_CTX_get_by_subject.pod b/doc/man3/X509_STORE_CTX_get_by_subject.pod index b13d109a30..a08f52592c 100644 --- a/doc/man3/X509_STORE_CTX_get_by_subject.pod +++ b/doc/man3/X509_STORE_CTX_get_by_subject.pod @@ -28,17 +28,6 @@ stores the looked up object in I. X509_STORE_CTX_get_obj_by_subject() is like X509_STORE_CTX_get_by_subject() but returns the found object on success, else NULL. -=head1 NOTES - -These functions are safe to use in a multithreaded environment and with -lookup functions on the same store. - -Applications sharing a store across threads should manage its lifetime with -L and L, and must ensure that -all lookup operations have completed before the store is freed. See -L for more discussion of the B threading -model. - =head1 RETURN VALUES X509_STORE_CTX_get_by_subject() returns 1 if the lookup was successful, else 0. @@ -48,8 +37,7 @@ X509_STORE_CTX_get_obj_by_subject() returns an object on success, else NULL. =head1 SEE ALSO L, -L, -L +L =head1 COPYRIGHT diff --git a/doc/man3/X509_STORE_CTX_get_error.pod b/doc/man3/X509_STORE_CTX_get_error.pod index dd45b9ef89..c181b6a5a3 100644 --- a/doc/man3/X509_STORE_CTX_get_error.pod +++ b/doc/man3/X509_STORE_CTX_get_error.pod @@ -6,7 +6,6 @@ X509_STORE_CTX_get_error, X509_STORE_CTX_set_error, X509_STORE_CTX_get_error_depth, X509_STORE_CTX_set_error_depth, X509_STORE_CTX_get_current_cert, X509_STORE_CTX_set_current_cert, X509_STORE_CTX_get0_cert, X509_STORE_CTX_get1_chain, -X509_STORE_CTX_get0_current_crl, X509_verify_cert_error_string - get or set certificate verification status information @@ -21,8 +20,8 @@ information X509 *X509_STORE_CTX_get_current_cert(const X509_STORE_CTX *ctx); void X509_STORE_CTX_set_current_cert(X509_STORE_CTX *ctx, X509 *x); X509 *X509_STORE_CTX_get0_cert(const X509_STORE_CTX *ctx); + STACK_OF(X509) *X509_STORE_CTX_get1_chain(const X509_STORE_CTX *ctx); - X509_CRL *X509_STORE_CTX_get0_current_crl(const X509_STORE_CTX *ctx); const char *X509_verify_cert_error_string(long n); @@ -79,15 +78,6 @@ When it is no longer needed it should be free up using: OSSL_STACK_OF_X509_free(chain); -X509_STORE_CTX_get0_current_crl() returns an internal pointer to the -possibly unverified CRL being actively considered during verification -by the I, or NULL. The returned value is NULL when the -verification is not considering a specific CRL, or has finished CRL -verification. As this pointer is an internal value used only during -X509 verification, the values seen and order in which they are seen if -called during the verification callback should not be relied upon to -be consistent. - X509_verify_cert_error_string() returns a human readable error string for verification error I. @@ -100,9 +90,6 @@ X509_STORE_CTX_get_error_depth() returns a nonnegative error depth. X509_STORE_CTX_get_current_cert() returns the certificate which caused the error or NULL if no certificate is relevant to the error. -X509_STORE_CTX_get_current_crl() returns the CRL which caused the error -or NULL if no CRL is relevant to the error. - X509_verify_cert_error_string() returns a human readable error string for verification error I. @@ -506,22 +493,6 @@ consistent with the supplied purpose. No TLS records were configured to validate the raw public key, or DANE was not enabled on the connection. -=item B - -Missing Authority Key Identifier. - -=item B - -Authority Key Identifier has no attributes. - -=item B - -Authority Key Identifier issuer and serial number must be paired. - -=item B - -Certificate includes more than one instance of a particular extension. - =back =head1 NOTES @@ -552,7 +523,7 @@ L. =head1 COPYRIGHT -Copyright 2009-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2009-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_STORE_CTX_new.pod b/doc/man3/X509_STORE_CTX_new.pod index bef593f723..143438655e 100644 --- a/doc/man3/X509_STORE_CTX_new.pod +++ b/doc/man3/X509_STORE_CTX_new.pod @@ -19,8 +19,7 @@ X509_STORE_CTX_verify_fn, X509_STORE_CTX_set_ocsp_resp, X509_STORE_CTX_set_purpose, X509_STORE_CTX_set_trust, -X509_STORE_CTX_purpose_inherit, -X509_STORE_CTX_set_time +X509_STORE_CTX_purpose_inherit - X509_STORE_CTX initialisation =head1 SYNOPSIS @@ -64,9 +63,6 @@ X509_STORE_CTX_set_time int X509_STORE_CTX_purpose_inherit(X509_STORE_CTX *ctx, int def_purpose, int purpose, int trust); - void X509_STORE_CTX_set_time(X509_STORE_CTX *ctx, unsigned long flags, - time_t t); - =head1 DESCRIPTION These functions initialise an B structure for subsequent use @@ -278,16 +274,6 @@ the default trust id for I. If the default trust id for the purpose is I and I is 0 then the default trust id associated with the I value is used for the trust setting instead. -X509_STORE_CTX_set_time() sets the verification time in I to I, -which is a POSIX time value representing seconds since 1970-01-01T00:00:00Z -(see L). -This is a convenience function that calls L -on the verification parameters associated with I. -By default, the current system time is used for certificate verification. -Setting a specific time is useful for testing or when verifying historical -certificates. -The I parameter is ignored. - =head1 NOTES The certificates and CRLs in a store are used internally and should B @@ -316,8 +302,8 @@ present, or NULL if absent. X509_STORE_CTX_cleanup(), X509_STORE_CTX_free(), X509_STORE_CTX_set0_trusted_stack(), X509_STORE_CTX_set_cert(), -X509_STORE_CTX_set0_crls(), X509_STORE_CTX_set0_param(), and -X509_STORE_CTX_set_time() do not return values. +X509_STORE_CTX_set0_crls() and X509_STORE_CTX_set0_param() do not return +values. X509_STORE_CTX_set_default() returns 1 for success or 0 if an error occurred. @@ -327,7 +313,7 @@ used. =head1 SEE ALSO L, L, -L, L +L =head1 HISTORY @@ -342,7 +328,7 @@ There is no need to call X509_STORE_CTX_cleanup() explicitly since OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2009-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2009-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_STORE_add_cert.pod b/doc/man3/X509_STORE_add_cert.pod index cb083dc1d0..7b57e04721 100644 --- a/doc/man3/X509_STORE_add_cert.pod +++ b/doc/man3/X509_STORE_add_cert.pod @@ -18,7 +18,7 @@ X509_STORE_load_locations_ex, X509_STORE_load_locations typedef x509_store_st X509_STORE; - int X509_STORE_add_cert(X509_STORE *xs, const X509 *x); + int X509_STORE_add_cert(X509_STORE *xs, X509 *x); int X509_STORE_add_crl(X509_STORE *xs, X509_CRL *x); int X509_STORE_set_depth(X509_STORE *store, int depth); int X509_STORE_set_flags(X509_STORE *xs, unsigned long flags); @@ -95,28 +95,21 @@ L I and adds it to the B I. This also associates the B with the lookup, so B functions can look up objects in that store. -X509_STORE_load_file_ex() loads trusted certificate(s) into an B -from a given file in PEM format. The library context I and property +X509_STORE_load_file_ex() loads trusted certificate(s) into an +B from a given file. The library context I and property query I are used when fetching algorithms from providers. X509_STORE_load_file() is similar to X509_STORE_load_file_ex() but uses NULL for the library context I and property query I. -X509_STORE_load_path() sets in B the given directory with -certificate files in PEM format as source of trusted certificate(s). -The certificate files in I

are only looked up when required, e.g., when -building the certificate chain or when verifying a peer certificate. +X509_STORE_load_path() loads trusted certificate(s) into an +B from a given directory path. The certificates in the directory must be in hashed form, as documented in L. -Use the L utility to create the necessary links. -X509_STORE_load_store_ex() loads trusted certificate(s) into an B -from a given URI. The library context I and +X509_STORE_load_store_ex() loads trusted certificate(s) into an +B from a store at a given URI. The library context I and property query I are used when fetching algorithms from providers. -I must not be NULL. It must be a URI to a store, which may -represent a single container or a whole catalogue of containers. -If I starts with the scheme C, it is treated like a local file -or directory. X509_STORE_load_store() is similar to X509_STORE_load_store_ex() but uses NULL for the library context I and property query I. @@ -124,7 +117,8 @@ uses NULL for the library context I and property query I. X509_STORE_load_locations_ex() combines X509_STORE_load_file_ex() and X509_STORE_load_path() for a given file and/or directory path. -It is permitted to specify just a file, just a directory, or both paths. +It is permitted to specify just a file, just a directory, or both +paths. X509_STORE_load_locations() is similar to X509_STORE_load_locations_ex() but uses NULL for the library context I and property query I. @@ -155,9 +149,8 @@ L, or NULL on error. =head1 SEE ALSO -L, -L, -L, +L. +L. L, L @@ -169,7 +162,7 @@ X509_STORE_load_locations_ex() were added in OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2017-2021 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_STORE_new.pod b/doc/man3/X509_STORE_new.pod index 330cbe53c7..9162080e0c 100644 --- a/doc/man3/X509_STORE_new.pod +++ b/doc/man3/X509_STORE_new.pod @@ -23,40 +23,12 @@ The X509_STORE_new() function returns a new X509_STORE. X509_STORE_up_ref() increments the reference count associated with the X509_STORE object. -X509_STORE_lock() locks the store from reads and writes by other threads, -and X509_STORE_unlock() unlocks it. Not all operations require locking -the store, see the notes on thread safety below. +X509_STORE_lock() locks the store from modification by other threads, +X509_STORE_unlock() unlocks it. -X509_STORE_free() decrements the reference count of the X509_STORE object. -The store's memory is only freed when its reference count drops to -zero. +X509_STORE_free() frees up a single X509_STORE object. If the argument is NULL, nothing is done. -=head1 NOTES - -=head2 Thread Safety - -When an B is shared across multiple threads, each thread or -component that holds a pointer to it should call X509_STORE_up_ref() to -acquire a reference, and release the reference with X509_STORE_free() when -done. - -Adding certificates or CRLs, for example L or -L, as well as looking up objects from the cache -with L are safe to call concurrently -from multiple threads on the same store without external synchronization, -provided the ownership to the X509_STORE is obtained by acquiring a -reference in advance. - -Store I functions (X509_STORE_set_flags(), -X509_STORE_set_depth(), X509_STORE_set_purpose(), X509_STORE_set_trust(), -and similar) are B safe to call concurrently with any other operation -on the same store; the store must be fully configured before being shared -with other threads. - -One useful pattern is having a single owner thread that calls -X509_STORE_free() only after joining with all threads that use the store. - =head1 RETURN VALUES X509_STORE_new() returns a newly created X509_STORE or NULL if the call fails. diff --git a/doc/man3/X509_STORE_set_verify_cb_func.pod b/doc/man3/X509_STORE_set_verify_cb_func.pod index b309a6e04a..57fc6c9f64 100644 --- a/doc/man3/X509_STORE_set_verify_cb_func.pod +++ b/doc/man3/X509_STORE_set_verify_cb_func.pod @@ -41,9 +41,9 @@ X509_STORE_CTX_lookup_certs_fn, X509_STORE_CTX_lookup_crls_fn #include typedef int (*X509_STORE_CTX_get_issuer_fn)(X509 **issuer, - X509_STORE_CTX *ctx, const X509 *x); + X509_STORE_CTX *ctx, X509 *x); typedef int (*X509_STORE_CTX_check_issued_fn)(X509_STORE_CTX *ctx, - const X509 *x, const X509 *issuer); + X509 *x, X509 *issuer); typedef int (*X509_STORE_CTX_check_revocation_fn)(X509_STORE_CTX *ctx); typedef int (*X509_STORE_CTX_get_crl_fn)(X509_STORE_CTX *ctx, X509_CRL **crl, X509 *x); @@ -65,7 +65,7 @@ X509_STORE_CTX_lookup_certs_fn, X509_STORE_CTX_lookup_crls_fn void X509_STORE_set_verify(X509_STORE *xs, X509_STORE_CTX_verify_fn verify); X509_STORE_CTX_verify_fn X509_STORE_CTX_get_verify(const X509_STORE_CTX *ctx); - int X509_STORE_CTX_get1_issuer(X509 **issuer, X509_STORE_CTX *ctx, const X509 *x); + int X509_STORE_CTX_get1_issuer(X509 **issuer, X509_STORE_CTX *ctx, X509 *x); X509_STORE_CTX_get_issuer_fn X509_STORE_get_get_issuer(const X509_STORE_CTX *ctx); void X509_STORE_set_get_issuer(X509_STORE *xs, X509_STORE_CTX_get_issuer_fn get_issuer); @@ -277,7 +277,7 @@ were added in OpenSSL 1.1.0. =head1 COPYRIGHT -Copyright 2009-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2009-2021 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_VERIFY_PARAM_set_flags.pod b/doc/man3/X509_VERIFY_PARAM_set_flags.pod index a2078ae247..267975778b 100644 --- a/doc/man3/X509_VERIFY_PARAM_set_flags.pod +++ b/doc/man3/X509_VERIFY_PARAM_set_flags.pod @@ -16,17 +16,9 @@ X509_VERIFY_PARAM_set1_host, X509_VERIFY_PARAM_add1_host, X509_VERIFY_PARAM_set_hostflags, X509_VERIFY_PARAM_get_hostflags, X509_VERIFY_PARAM_get0_peername, -X509_VERIFY_PARAM_get0_email, -X509_VERIFY_PARAM_set1_email, -X509_VERIFY_PARAM_set1_rfc822, X509_VERIFY_PARAM_add1_rfc822, -X509_VERIFY_PARAM_set1_smtputf8, X509_VERIFY_PARAM_add1_smtputf8, -X509_VERIFY_PARAM_set1_ip, X509_VERIFY_PARAM_add1_ip, -X509_VERIFY_PARAM_set1_ip_asc, X509_VERIFY_PARAM_add1_ip_asc, -X509_VERIFY_PARAM_get1_ip_asc, -X509_VERIFY_PARAM_set1_host_input_validation, -X509_VERIFY_PARAM_set1_rfc822_input_validation, -X509_VERIFY_PARAM_set1_smtputf8_input_validation, -X509_VERIFY_PARAM_set1_ip_input_validation +X509_VERIFY_PARAM_get0_email, X509_VERIFY_PARAM_set1_email, +X509_VERIFY_PARAM_set1_ip, X509_VERIFY_PARAM_get1_ip_asc, +X509_VERIFY_PARAM_set1_ip_asc - X509 verification parameters =head1 SYNOPSIS @@ -74,83 +66,64 @@ X509_VERIFY_PARAM_set1_ip_input_validation char *X509_VERIFY_PARAM_get0_email(X509_VERIFY_PARAM *param); int X509_VERIFY_PARAM_set1_email(X509_VERIFY_PARAM *param, const char *email, size_t emaillen); - int X509_VERIFY_PARAM_set1_rfc822(X509_VERIFY_PARAM *param, - const char *email, size_t emaillen); - int X509_VERIFY_PARAM_add1_rfc822(X509_VERIFY_PARAM *param, - const char *email, size_t emaillen); - int X509_VERIFY_PARAM_set1_smtputf8(X509_VERIFY_PARAM *param, - const char *email, size_t emaillen); - int X509_VERIFY_PARAM_add1_smtputf8(X509_VERIFY_PARAM *param, - const char *email, size_t emaillen); char *X509_VERIFY_PARAM_get1_ip_asc(X509_VERIFY_PARAM *param); int X509_VERIFY_PARAM_set1_ip(X509_VERIFY_PARAM *param, const unsigned char *ip, size_t iplen); - int X509_VERIFY_PARAM_add1_ip(X509_VERIFY_PARAM *param, - const unsigned char *ip, size_t iplen); - int X509_VERIFY_PARAM_set1_ip_asc(X509_VERIFY_PARAM *param, const char *ip_asc); - int X509_VERIFY_PARAM_add1_ip_asc(X509_VERIFY_PARAM *param, const char *ip_asc); - void X509_VERIFY_PARAM_set1_ip_input_validation(X509_VERIFY_PARAM *param, - int (*validate_ip)(const uint8_t *name, size_t len)); - void X509_VERIFY_PARAM_set1_host_input_validation(X509_VERIFY_PARAM *param, - int (*validate_host)(const char *name, size_t len)); - void X509_VERIFY_PARAM_set1_rfc822_input_validation(X509_VERIFY_PARAM *param, - int (*validate_rfc822)(const char *name, size_t len)); - void X509_VERIFY_PARAM_set1_smtputf8_input_validation(X509_VERIFY_PARAM *param, - int (*validate_smtputf8)(const char *name, size_t len)); + int X509_VERIFY_PARAM_set1_ip_asc(X509_VERIFY_PARAM *param, const char *ipasc); =head1 DESCRIPTION These functions manipulate the B structure associated with a certificate verification operation. -The X509_VERIFY_PARAM_set_flags() function sets the flags in I by oring -it with I. See L for a complete -description of values the I parameter can take. +The X509_VERIFY_PARAM_set_flags() function sets the flags in B by oring +it with B. See L for a complete +description of values the B parameter can take. -X509_VERIFY_PARAM_get_flags() returns the flags in I. +X509_VERIFY_PARAM_get_flags() returns the flags in B. -X509_VERIFY_PARAM_get_inh_flags() returns the inheritance flags in I +X509_VERIFY_PARAM_get_inh_flags() returns the inheritance flags in B which specifies how verification flags are copied from one structure to another. X509_VERIFY_PARAM_set_inh_flags() sets the inheritance flags. -See the L section for a description of these bits. +See the B section for a description of these bits. -X509_VERIFY_PARAM_clear_flags() clears the flags I in I. +X509_VERIFY_PARAM_clear_flags() clears the flags B in B. -X509_VERIFY_PARAM_set_purpose() sets the verification purpose in I -to I. This determines the acceptable purpose of the certificate +X509_VERIFY_PARAM_set_purpose() sets the verification purpose in B +to B. This determines the acceptable purpose of the certificate chain, for example B. -The purpose requirement is cleared if I is B. +The purpose requirement is cleared if B is X509_PURPOSE_DEFAULT_ANY. -X509_VERIFY_PARAM_get_purpose() returns the purpose in I. +X509_VERIFY_PARAM_get_purpose() returns the purpose in B. -X509_VERIFY_PARAM_set_trust() sets the trust setting in I to -I. +X509_VERIFY_PARAM_set_trust() sets the trust setting in B to +B. -X509_VERIFY_PARAM_set_time() sets the verification time in I to -I. Normally the current time is used. +X509_VERIFY_PARAM_set_time() sets the verification time in B to +B. Normally the current time is used. -X509_VERIFY_PARAM_add0_policy() adds I to the acceptable policy set. +X509_VERIFY_PARAM_add0_policy() adds B to the acceptable policy set. Contrary to preexisting documentation of this function it does not enable policy checking. X509_VERIFY_PARAM_set1_policies() enables policy checking (it is disabled -by default) and sets the acceptable policy set to I. Any existing -policy set is cleared. The I parameter can be NULL to clear +by default) and sets the acceptable policy set to B. Any existing +policy set is cleared. The B parameter can be B to clear an existing policy set. -X509_VERIFY_PARAM_set_depth() sets the maximum verification depth to I. +X509_VERIFY_PARAM_set_depth() sets the maximum verification depth to B. That is the maximum number of intermediate CA certificates that can appear in a chain. A maximal depth chain contains 2 more certificates than the limit, since neither the end-entity certificate nor the trust-anchor count against this limit. -Thus a I limit of 0 only allows the end-entity certificate to be signed -directly by the trust anchor, while with a I limit of 1 there can be one +Thus a B limit of 0 only allows the end-entity certificate to be signed +directly by the trust anchor, while with a B limit of 1 there can be one intermediate CA certificate between the trust anchor and the end-entity certificate. X509_VERIFY_PARAM_set_auth_level() sets the authentication security level to -I. +B. The authentication security level determines the acceptable signature and public key strength when verifying certificate chains. For a certificate chain to validate, the public keys of all the certificates @@ -166,21 +139,21 @@ Security level 1 requires at least 80-bit-equivalent security and is broadly interoperable, though it will, for example, reject MD5 signatures or RSA keys shorter than 1024 bits. -X509_VERIFY_PARAM_get0_host() returns the Ith expected DNS hostname that has +X509_VERIFY_PARAM_get0_host() returns the Bth expected DNS hostname that has been set using X509_VERIFY_PARAM_set1_host() or X509_VERIFY_PARAM_add1_host(). -To obtain all names start with I = 0 and increment I as long as no NULL +To obtain all names start with B = 0 and increment B as long as no NULL pointer is returned. -X509_VERIFY_PARAM_set1_host() sets in I the expected -DNS hostname to I, clearing any previously specified hostname. -If I is NULL or the empty string, the list of hostnames is cleared -and hostname checks are not performed on the peer certificate. -If I is zero, I must be NUL-terminated, -otherwise I must be set to the length of I. +X509_VERIFY_PARAM_set1_host() sets the expected DNS hostname to +B clearing any previously specified hostname. If +B is NULL, or empty the list of hostnames is cleared, and +name checks are not performed on the peer certificate. If B +is NUL-terminated, B may be zero, otherwise B +must be set to the length of B. When a hostname is specified, certificate verification automatically invokes L -with flags equal to the I argument given to +with flags equal to the B argument given to X509_VERIFY_PARAM_set_hostflags() (default zero). Applications are strongly advised to use this interface in preference to explicitly calling L, hostname checks may be out of scope @@ -203,10 +176,10 @@ flag takes precedence over the B flag. X509_VERIFY_PARAM_get_hostflags() returns any host flags previously set via a call to X509_VERIFY_PARAM_set_hostflags(). -X509_VERIFY_PARAM_add1_host() adds I as an additional reference +X509_VERIFY_PARAM_add1_host() adds B as an additional reference identifier that can match the peer's certificate. Any previous names set via X509_VERIFY_PARAM_set1_host() or X509_VERIFY_PARAM_add1_host() -are retained, no change is made if I is NULL or the empty string. When +are retained, no change is made if B is NULL or empty. When multiple names are configured, the peer is considered verified when any name matches. @@ -217,113 +190,31 @@ reference identifier specifies a parent domain (starts with ".") rather than a hostname, the peer name may be a wildcard name or a sub-domain of the reference identifier respectively. The return string is allocated by the library and is no longer valid once the -associated I argument is freed. Applications must not free +associated B argument is freed. Applications must not free the return value. X509_VERIFY_PARAM_get0_email() returns the expected RFC822 email address. -The _rfc822() family of functions is used for email names that have -ASCII localpart addresses, in which case the domain part of the -address must be represented in A-label form. They are used to -specify the list of values to match against the SAN Email names in -certificates. - -X509_VERIFY_PARAM_set1_rfc822() clears all expected RFC822 email -addresses, and sets the expected RFC822 email address to I. If -I is NULL no expected address is set. Otherwise, if -I is zero, I must be NUL-terminated; if I -is nonzero, I must be set to the length of I. When -any email address is specified, certificate verification automatically -invokes L. - -X509_VERIFY_PARAM_add1_rfc822() adds I as an additional -reference identifier that can match RFC822 email addresses in the -peer's certificate. Any previous names set via -X509_VERIFY_PARAM_set1_rfc822(), X509_VERIFY_PARAM_add1_rfc822(), or -X509_VERIFY_PARAM_set1_email() are -retained on success, no change is made on failure. It is a failure if -email is NULL or the empty string. -The peer is considered verified -when any one of the specified RFC822 or SMTPUTF8 names matches a corresponding email -address SAN in the certificate. - -The _smtputf8() family of functions is used for email names that have -a non-ASCII localpart addresses, in which case the domain part of the -address must be represented in U-label form. They are used to -specify the list of values to match against the OTHERNAME SMTPUTF8 names in -certificates. - -X509_VERIFY_PARAM_set1_smtputf8() sets the expected SMTPUTF8 email address to -I. -If I is NULL, SMTPUTF8 email checking is disabled. Otherwise, -if I is zero, I must be NUL-terminated; if I is nonzero, -I must be set to the length of I. When any email address +X509_VERIFY_PARAM_set1_email() sets the expected RFC822 email address to +B. If B is NUL-terminated, B may be zero, otherwise +B must be set to the length of B. When an email address is specified, certificate verification automatically invokes L. -X509_VERIFY_PARAM_add1_smtputf8() adds I as an additional -reference identifier that can match SMTPUTF8 email addresses in the -peer's certificate. Any previous names set via -X509_VERIFY_PARAM_set1_smtputf8(), X509_VERIFY_PARAM_add1_smtputf8(), or -X509_VERIFY_PARAM_set1_email() are -retained on success, no change is made on failure. It is a failure if -email is NULL or the empty string. The peer is considered verified -when any one of the specified RFC822 or SMTPUTF8 names matches a corresponding email -address SAN in the certificate. - -X509_VERIFY_PARAM_set1_email() calls X509_VERIFY_PARAM_set_rfc822(), and -X509_VERIFY_PARAM_set_smtputf8() and succeeds if either call succeeds. - X509_VERIFY_PARAM_get1_ip_asc() returns the expected IP address as a string. The caller is responsible for freeing it. -X509_VERIFY_PARAM_set1_ip() sets the expected IP address to I. -If I is NULL, IP address checking is disabled. Otherwise, -the I argument must be in binary format, in network byte-order and -I must be set to 4 for IPv4 and 16 for IPv6. When an IP +X509_VERIFY_PARAM_set1_ip() sets the expected IP address to B. +The B argument is in binary format, in network byte-order and +B must be set to 4 for IPv4 and 16 for IPv6. When an IP address is specified, certificate verification automatically invokes L. -X509_VERIFY_PARAM_add1_ip() adds I as an additional reference -identifier that can match the peer's certificate on success. Any -previous addresses set via X509_VERIFY_PARAM_set1_ip(), -X509_VERIFY_PARAM_add1_ip(), X509_VERIFY_PARAM_set1_ip_asc(), or -X509_VERIFY_PARAM_add1_ip_asc() are retained. No change is made on -failure. -It is a failure if I is NULL or the value I is neither 4 nor 16 bytes. -When -multiple names are configured, the peer is considered verified when -any name matches. - X509_VERIFY_PARAM_set1_ip_asc() sets the expected IP address to -I. The I argument must be a NUL-terminated ASCII string: +B. The B argument is a NUL-terminal ASCII string: dotted decimal quad for IPv4 and colon-separated hexadecimal for IPv6. The condensed "::" notation is supported for IPv6 addresses. -X509_VERIFY_PARAM_add1_ip_asc() adds I as an additional -reference identifier that can match the peer's certificate on success. -The I argument must be a NUL-terminated ASCII string: dotted -decimal quad for IPv4 and colon-separated hexadecimal for IPv6. The -condensed "::" notation is supported for IPv6 addresses. Any previous -names set via X509_VERIFY_PARAM_set1_ip(), -X509_VERIFY_PARAM_add1_ip(), X509_VERIFY_PARAM_set1_ip_asc(), or -X509_VERIFY_PARAM_add1_ip_asc() are retained. No change is made on -failure. -It is a failure if I is NULL or the empty string. -When multiple addresses are configured, the peer is considered verified -when any one of the specified addresses matches a corresponding IP address SAN in the certificate. - -X509_VERIFY_PARAM_set1_host_input_validation(), -X509_VERIFY_PARAM_set1_rfc822_input_validation(), -X509_VERIFY_PARAM_set1_smtputf8_input_validation(), and -X509_VERIFY_PARAM_set1_ip_input_validation() set a verification -function to validate the input on setting the corresponding validation -parameter expected values. -These functions make it possible to override OpenSSL's built-in input validation of -the corresponding verification parameters. -If the provided function succeeds, the corresponding -input will be accepted for use in certificate verification. - =head1 RETURN VALUES X509_VERIFY_PARAM_set_flags(), X509_VERIFY_PARAM_clear_flags(), @@ -331,10 +222,8 @@ X509_VERIFY_PARAM_set_inh_flags(), X509_VERIFY_PARAM_set_purpose(), X509_VERIFY_PARAM_set_trust(), X509_VERIFY_PARAM_add0_policy() X509_VERIFY_PARAM_set1_policies(), X509_VERIFY_PARAM_set1_host(), X509_VERIFY_PARAM_add1_host(), -X509_VERIFY_PARAM_set1_email(), -X509_VERIFY_PARAM_set1_ip(), X509_VERIFY_PARAM_add1_ip(), -X509_VERIFY_PARAM_set1_ip_asc(), -X509_VERIFY_PARAM_add1_ip_asc() return 1 for success and 0 for +X509_VERIFY_PARAM_set1_email(), X509_VERIFY_PARAM_set1_ip() and +X509_VERIFY_PARAM_set1_ip_asc() return 1 for success and 0 for failure. X509_VERIFY_PARAM_get0_host(), X509_VERIFY_PARAM_get0_email(), and @@ -369,14 +258,6 @@ certificate. An error occurs if a suitable CRL cannot be found. B expands CRL checking to the entire certificate chain if B has also been enabled, and is otherwise ignored. -B enables Online Certificate Status Protocol (OCSP) -checking for the certificate chain leaf certificate. An error occurs if a suitable -OCSP response cannot be found. - -B expands OCSP checking to the entire certificate -chain if B has also been enabled, and is otherwise -ignored. - B disables critical extension checking. By default any unhandled critical extensions in certificates or (if checked) CRLs result in a fatal error. If this flag is set unhandled critical extensions are @@ -394,9 +275,9 @@ no policy checking is performed. Additional information is sent to the verification callback relating to policy checking. B, B and -B set the C, C and C flags respectively as defined in -RFC 5280. Policy checking is automatically enabled if any of these flags +B set the B, B and B flags respectively as defined in +B. Policy checking is automatically enabled if any of these flags are set. If B is set and the policy checking is successful @@ -421,7 +302,7 @@ check the signature anyway. A side effect of not checking the self-signature of such a certificate is that disabled or unsupported message digests used for the signature are not treated as fatal errors. -When B is set, which is the default since +When B is set, which is always the case since OpenSSL 1.1.0, construction of the certificate chain in L searches the trust store for issuer certificates before searching the provided untrusted certificates. @@ -430,14 +311,22 @@ requirements and lead to a locally trusted root. This is especially important when some certificates in the trust store have explicit trust settings (see "TRUST SETTINGS" in L). -The B flag suppresses checking for alternative chains. +The B flag could have been used before OpenSSL 1.1.0 +to suppress checking for alternative chains. +By default, unless B is set, when building a +certificate chain, if the first certificate chain found is not trusted, then +OpenSSL will attempt to replace untrusted certificates supplied by the peer +with certificates from the trust store to see if an alternative chain can be +found that is trusted. +As of OpenSSL 1.1.0, with B always set, this option +has no effect. The B flag causes non-self-signed certificates in the trust store to be treated as trust anchors, in the same way as self-signed root CA certificates. This makes it possible to trust self-issued certificates as well as certificates issued by an intermediate CA without having to trust their ancestor root CA. -With B set, chain +With OpenSSL 1.1.0 and later and B set, chain construction stops as soon as the first certificate contained in the trust store is added to the chain, whether that certificate is a self-signed "root" certificate or a not self-signed "intermediate" or self-issued certificate. @@ -478,12 +367,6 @@ instead of functions which work in specific structures such as X509_STORE_CTX_set_flags() which are likely to be deprecated in a future release. -TLS clients are recommended to set up validation of server hostname(s) and/or -IP address (directly using the above functions -or more conveniently using L or L) -and to use L for Server Name Indication (SNI), -which may be crucial also for correct routing of the connection request. - =head1 BUGS Delta CRL checking is currently primitive. Only a single delta can be used and @@ -497,7 +380,7 @@ CRLs from the CRL distribution points extension. =head1 EXAMPLES Enable CRL checking when performing certificate verification during SSL -connections associated with an B structure I: +connections associated with an B structure B: X509_VERIFY_PARAM *param; @@ -508,23 +391,14 @@ connections associated with an B structure I: =head1 SEE ALSO -L, L, L, L, L, -L, L =head1 HISTORY -Until OpenSSL 1.1.0, by default (unless B was set), when building a -certificate chain, if the first certificate chain found was not trusted, -OpenSSL would attempt to replace untrusted certificates supplied by the peer -with certificates from the trust store to see if an alternative chain can be -found that is trusted. -Since OpenSSL 1.1.0 version, the B is set by default. - The B flag was added in OpenSSL 1.1.0. The flag B was deprecated in OpenSSL 1.1.0 and has no effect. @@ -542,7 +416,7 @@ The X509_VERIFY_PARAM_get_purpose() function was added in OpenSSL 3.5. =head1 COPYRIGHT -Copyright 2009-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2009-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_add_cert.pod b/doc/man3/X509_add_cert.pod index 4f571e394d..f59b93ba54 100644 --- a/doc/man3/X509_add_cert.pod +++ b/doc/man3/X509_add_cert.pod @@ -10,8 +10,8 @@ X509 certificate list addition functions #include - int X509_add_cert(STACK_OF(X509) *sk, const X509 *cert, int flags); - int X509_add_certs(STACK_OF(X509) *sk, const STACK_OF(X509) *certs, int flags); + int X509_add_cert(STACK_OF(X509) *sk, X509 *cert, int flags); + int X509_add_certs(STACK_OF(X509) *sk, STACK_OF(X509) *certs, int flags); =head1 DESCRIPTION @@ -65,11 +65,9 @@ L The functions X509_add_cert() and X509_add_certs() were added in OpenSSL 3.0. -X509_add_cert() had its cert parameter converted to be I in OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_check_ca.pod b/doc/man3/X509_check_ca.pod index 6a8b1da9a5..91eba44f41 100644 --- a/doc/man3/X509_check_ca.pod +++ b/doc/man3/X509_check_ca.pod @@ -8,7 +8,7 @@ X509_check_ca - check if given certificate is CA certificate #include - int X509_check_ca(const X509 *cert); + int X509_check_ca(X509 *cert); =head1 DESCRIPTION @@ -38,7 +38,7 @@ L =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_check_host.pod b/doc/man3/X509_check_host.pod index 6b095f9582..0156194c99 100644 --- a/doc/man3/X509_check_host.pod +++ b/doc/man3/X509_check_host.pod @@ -8,13 +8,13 @@ X509_check_host, X509_check_email, X509_check_ip, X509_check_ip_asc - X.509 cert #include - int X509_check_host(const X509 *, const char *name, size_t namelen, + int X509_check_host(X509 *, const char *name, size_t namelen, unsigned int flags, char **peername); - int X509_check_email(const X509 *, const char *address, size_t addresslen, + int X509_check_email(X509 *, const char *address, size_t addresslen, unsigned int flags); - int X509_check_ip(const X509 *, const unsigned char *address, size_t addresslen, + int X509_check_ip(X509 *, const unsigned char *address, size_t addresslen, unsigned int flags); - int X509_check_ip_asc(const X509 *, const char *address, unsigned int flags); + int X509_check_ip_asc(X509 *, const char *address, unsigned int flags); =head1 DESCRIPTION @@ -134,11 +134,11 @@ NULs. =head1 NOTES -Applications should use X509_VERIFY_PARAM_set1_host() and -X509_verify_cert() rather than explicitly calling -L. Hostname checks may be out of scope with the -DANE-EE(3) certificate usage, and the internal checks will be -suppressed as appropriate when DANE support is enabled. +Applications are encouraged to use X509_VERIFY_PARAM_set1_host() +rather than explicitly calling L. Hostname +checks may be out of scope with the DANE-EE(3) certificate usage, +and the internal checks will be suppressed as appropriate when +DANE support is enabled. =head1 SEE ALSO @@ -146,18 +146,15 @@ L, L, L, L, -L, -L +L =head1 HISTORY These functions were added in OpenSSL 1.0.2. -These functions were deprecated in OpenSSL 4.1.0. - =head1 COPYRIGHT -Copyright 2012-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2012-2022 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_check_issued.pod b/doc/man3/X509_check_issued.pod index 3d82ce56c1..b83bc1396b 100644 --- a/doc/man3/X509_check_issued.pod +++ b/doc/man3/X509_check_issued.pod @@ -2,77 +2,41 @@ =head1 NAME -X509_check_issued, X509_check_akid -- helper functions to check whether one certificate is a potential issuer of another certificate +X509_check_issued - checks if certificate is apparently issued by another +certificate =head1 SYNOPSIS #include - int X509_check_issued(const X509 *issuer, const X509 *subject); - int X509_check_akid(const X509 *issuer, const AUTHORITY_KEYID *akid); + int X509_check_issued(X509 *issuer, X509 *subject); + =head1 DESCRIPTION X509_check_issued() checks if certificate I was apparently issued -using (CA) certificate I. It checks if the issuer field of I -equals the subject field of I. Moreover, it compares using -X509_check_akid() all sub-fields of the B extension of +using (CA) certificate I. This function takes into account not only +matching of the issuer field of I with the subject field of I, +but also compares all sub-fields of the B extension of I, as far as present, with the respective B, serial number, and issuer fields of I, as far as present. It also checks -if the I signature algorithm matches the I public key algorithm -and if any B field given in I allows certificate signing. +if the B field (if present) of I allows certificate signing. It does not actually check the certificate signature. An error is returned if the I or the I are incomplete certificates. -X509_check_akid() is a more low-level function. -It assumes that various internal fields of I have already been filled in, -for instance by calling L with its I parameter being -1. -It checks whether the fields of the subject certificate's authority key identifier I, -match the corresponding fields of the I certificate. -In more detail: -It returns B if I is NULL (because this means no restriction) -or all the following conditions are met: - -=over 4 - -=item * - -if I has the C field, -its value matches the B (SKID) extension of I if present, - -=item * - -if I has the C field, -its value equals the serial number of the I certificate, and - -=item * - -if I has the C field -and its C include at least one C, -the first such name equals the C field of the I certificate. - -=back - - =head1 RETURN VALUES -X509_check_issued() and X509_check_akid() -return B if all checks are successful -or some B constant indicating why the issuer does not match. +X509_check_issued() returns B if all checks are successful +or some B constant to indicate an error. =head1 SEE ALSO L, L, L, -L, L, L - -=head1 HISTORY - -X509_check_issued() has had its arguments altered to be const in OpenSSL 4.0. +L, L =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_check_purpose.pod b/doc/man3/X509_check_purpose.pod index 8828207955..59440dc013 100644 --- a/doc/man3/X509_check_purpose.pod +++ b/doc/man3/X509_check_purpose.pod @@ -20,7 +20,7 @@ X509_PURPOSE_set - functions related to checking the purpose of a certificate #include - int X509_check_purpose(const X509 *x, int id, int ca); + int X509_check_purpose(X509 *x, int id, int ca); int X509_PURPOSE_get_count(void); int X509_PURPOSE_get_unused_id(OSSL_LIB_CTX *libctx); @@ -62,8 +62,6 @@ Below are the potential ID's that can be checked: The checks performed take into account the X.509 extensions keyUsage, extendedKeyUsage, and basicConstraints. -No actual check is performed if I is -1. - X509_PURPOSE_get_count() returns the number of currently defined purposes. X509_PURPOSE_get_unused_id() returns the smallest purpose id not yet used, @@ -101,11 +99,6 @@ X509_PURPOSE_set() assigns the given I id to the location pointed at by I

. This resets to the any purpose if I is B. -=head1 NOTES - -X509_check_purpose() fills in various internal fields of the certificate structure I. -This is safe despite the I argument's type change to I as of OpenSSL 4.0. - =head1 RETURN VALUES X509_check_purpose() returns the following values. @@ -178,11 +171,9 @@ X509_PURPOSE_add() or X509_PURPOSE_cleanup(void) is being called. X509_PURPOSE_get_unused_id() was added in OpensSL 3.5. -X509_check_purpose() had its B parameter converted to const in OpenSSL 4.0.0. - =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy in the file LICENSE in the source distribution or at L. diff --git a/doc/man3/X509_check_certificate_times.pod b/doc/man3/X509_cmp_time.pod similarity index 52% rename from doc/man3/X509_check_certificate_times.pod rename to doc/man3/X509_cmp_time.pod index 2f3c9ccb17..52b1722c9f 100644 --- a/doc/man3/X509_check_certificate_times.pod +++ b/doc/man3/X509_cmp_time.pod @@ -2,44 +2,23 @@ =head1 NAME -X509_check_certificate_times, X509_time_adj, X509_time_adj_ex, X509_gmtime_adj, -X509_cmp_time, X509_cmp_current_time, X509_cmp_timeframe - X509 time functions +X509_cmp_time, X509_cmp_current_time, X509_cmp_timeframe, +X509_time_adj, X509_time_adj_ex, X509_gmtime_adj +- X509 time functions =head1 SYNOPSIS - int X509_check_certificate_times(const X509_VERIFY_PARAM *vpm, const X509 *x, - int *error); - ASN1_TIME *X509_time_adj(ASN1_TIME *asn1_time, long offset_sec, - const time_t *in_tm); - ASN1_TIME *X509_time_adj_ex(ASN1_TIME *asn1_time, int offset_day, long - offset_sec, const time_t *in_tm); - ASN1_TIME *X509_gmtime_adj(ASN1_TIME *asn1_time, long offset_sec); - -The following functions have been deprecated since OpenSSL 4.0, and can be -hidden entirely by defining B with a suitable version value, -see L: - - int X509_cmp_time(const ASN1_TIME *asn1_time, const time_t *in_tm); + int X509_cmp_time(const ASN1_TIME *asn1_time, time_t *in_tm); int X509_cmp_current_time(const ASN1_TIME *asn1_time); int X509_cmp_timeframe(const X509_VERIFY_PARAM *vpm, const ASN1_TIME *start, const ASN1_TIME *end); + ASN1_TIME *X509_time_adj(ASN1_TIME *asn1_time, long offset_sec, time_t *in_tm); + ASN1_TIME *X509_time_adj_ex(ASN1_TIME *asn1_time, int offset_day, long + offset_sec, time_t *in_tm); + ASN1_TIME *X509_gmtime_adj(ASN1_TIME *asn1_time, long offset_sec); =head1 DESCRIPTION -X509_check_certificate_times() compares the notBefore and notAfter -times in certificate I to check the certificate for temporal validity. -The time used for the check will be the current system time, unless -The the reference time included in the verification parameter I -is non NULL and I has the flag B set. - -The notBefore and notAfter times in the certificate will be accepted -only if they are either the format of a GeneralizedTime -(YYYYMMDDHHMMSSZ), or a UTCTime (YYMMDDHHMMSSZ) as per RFC5280, with -the exception that the requirement: "CAs conforming to this profile -MUST always encode certificate validity dates through the year 2049 as -UTCTime; certificate validity dates in 2050 or later MUST be encoded -as GeneralizedTime." is not enforced. - X509_cmp_time() compares the ASN1_TIME in I with the time in . @@ -73,35 +52,11 @@ X509_time_adj() with the last parameter as NULL. =head1 BUGS -Unlike many standard comparison functions, The deprecated functions -X509_cmp_time() and X509_cmp_current_time() return 0 on error, and -return -1 when the values are equal. - -The deprecated function X509_cmp_timeframe() may accept invalid -certificate times as infinitely valid. +Unlike many standard comparison functions, X509_cmp_time() and +X509_cmp_current_time() return 0 on error. =head1 RETURN VALUES -X509_check_certiticate_times() returns 1 if the certificate is -temporally valid at the verification time as per the rules from RFC -5280. It returns 0 otherwise. if I is non NULL, the integer -value it points to will be set to an error code when the certificate -is not temporally valid, or 0 when the certificate is temporally valid. - -The integer pointed to by I will be set to -X509_V_ERR_ERROR_IN_CERT_NOT_BEFORE_FIELD -or -X509_V_ERR_ERROR_IN_CERT_NOT_AFTER_FIELD -if the certificate has an invalid notBefore or notAfter field, respectively. - -The integer pointed to by I will be set to -X509_V_ERR_CERT_NOT_YET_VALID -or -X509_V_ERR_CERT_HAS_EXPIRED -if the -verification time is outside of the certificate's correctly encoded -validity window as per RFC5280. - X509_cmp_time() and X509_cmp_current_time() return -1 if I is earlier than, or equal to, I (resp. current time), and 1 otherwise. These methods return 0 on error. @@ -130,31 +85,13 @@ as valid forever. X509_time_adj(), X509_time_adj_ex() and X509_gmtime_adj() return a pointer to the updated ASN1_TIME structure, and NULL on error. -=head1 SEE ALSO - -L -L -L -L L -L - =head1 HISTORY -X509_cmp_timeframe(), X509_cmp_current_time(), and -X509_cmp_timeframe() were deprecated in OpenSSL 4.0 - -For replacement, consider using X509_check_certificate_times() for use -with X509 certificates. For applications checking individual ASN1_TIME -values, consider using ASN1_TIME_to_tm(3) with appropriate validity -checking of the I value for your application, and subsequent -comparison of either the resulting I structure, or conversion to -posix seconds via OPENSSL_tm_to_posix(3) - -X509_check_certificate_times() was added in OpenSSL 4.0. +X509_cmp_timeframe() was added in OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2017-2018 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_get0_distinguishing_id.pod b/doc/man3/X509_get0_distinguishing_id.pod index 5a6f8a7818..7db260cdce 100644 --- a/doc/man3/X509_get0_distinguishing_id.pod +++ b/doc/man3/X509_get0_distinguishing_id.pod @@ -10,7 +10,7 @@ X509_REQ_get0_distinguishing_id, X509_REQ_set0_distinguishing_id #include - const ASN1_OCTET_STRING *X509_get0_distinguishing_id(const X509 *x); + ASN1_OCTET_STRING *X509_get0_distinguishing_id(X509 *x); void X509_set0_distinguishing_id(X509 *x, ASN1_OCTET_STRING *distid); ASN1_OCTET_STRING *X509_REQ_get0_distinguishing_id(X509_REQ *x); void X509_REQ_set0_distinguishing_id(X509_REQ *x, ASN1_OCTET_STRING *distid); @@ -63,7 +63,7 @@ L, L =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_get0_signature.pod b/doc/man3/X509_get0_signature.pod index 585b011548..f8d47a27b8 100644 --- a/doc/man3/X509_get0_signature.pod +++ b/doc/man3/X509_get0_signature.pod @@ -35,7 +35,7 @@ X509_ACERT_get_signature_nid - signature information int X509_CRL_get_signature_nid(const X509_CRL *crl); const X509_ALGOR *X509_CRL_get0_tbs_sigalg(const X509_crl *crl); - int X509_get_signature_info(const X509 *x, int *mdnid, int *pknid, int *secbits, + int X509_get_signature_info(X509 *x, int *mdnid, int *pknid, int *secbits, uint32_t *flags); int X509_SIG_INFO_get(const X509_SIG_INFO *siginf, int *mdnid, int *pknid, @@ -153,7 +153,7 @@ The X509_CRL_get0_tbs_sigalg() function was added in OpenSSL 3.6. =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_get_default_cert_file.pod b/doc/man3/X509_get_default_cert_file.pod index a604cf5571..1e65b22700 100644 --- a/doc/man3/X509_get_default_cert_file.pod +++ b/doc/man3/X509_get_default_cert_file.pod @@ -24,7 +24,7 @@ the default path when it is asked to load trusted CA certificates from a file and no other path is specified. If the file exists, CA certificates are loaded from the file. -The X509_get_default_cert_dir() function returns a default delimiter-separated +The X509_get_default_cert_dir() function returns a default delimeter-separated list of paths to a directories containing trusted CA certificates named in the hashed format. OpenSSL will use this as the default list of paths when it is asked to load trusted CA certificates from a directory and no other path is diff --git a/doc/man3/X509_get_extension_flags.pod b/doc/man3/X509_get_extension_flags.pod index bc2ec51ecc..054eab5a26 100644 --- a/doc/man3/X509_get_extension_flags.pod +++ b/doc/man3/X509_get_extension_flags.pod @@ -18,17 +18,17 @@ X509_get_proxy_pathlen - retrieve certificate extension data #include - long X509_get_pathlen(const X509 *x); - uint32_t X509_get_extension_flags(const X509 *x); - uint32_t X509_get_key_usage(const X509 *x); - uint32_t X509_get_extended_key_usage(const X509 *x); - const ASN1_OCTET_STRING *X509_get0_subject_key_id(const X509 *x); - const ASN1_OCTET_STRING *X509_get0_authority_key_id(const X509 *x); - const GENERAL_NAMES *X509_get0_authority_issuer(const X509 *x); - const ASN1_INTEGER *X509_get0_authority_serial(const X509 *x); + long X509_get_pathlen(X509 *x); + uint32_t X509_get_extension_flags(X509 *x); + uint32_t X509_get_key_usage(X509 *x); + uint32_t X509_get_extended_key_usage(X509 *x); + const ASN1_OCTET_STRING *X509_get0_subject_key_id(X509 *x); + const ASN1_OCTET_STRING *X509_get0_authority_key_id(X509 *x); + const GENERAL_NAMES *X509_get0_authority_issuer(X509 *x); + const ASN1_INTEGER *X509_get0_authority_serial(X509 *x); void X509_set_proxy_flag(X509 *x); void X509_set_proxy_pathlen(int l); - long X509_get_proxy_pathlen(const X509 *x); + long X509_get_proxy_pathlen(X509 *x); =head1 DESCRIPTION @@ -199,7 +199,7 @@ X509_get_proxy_pathlen() were added in OpenSSL 1.1.0. =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2021 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_get_pubkey.pod b/doc/man3/X509_get_pubkey.pod index f1037906da..86c1edac63 100644 --- a/doc/man3/X509_get_pubkey.pod +++ b/doc/man3/X509_get_pubkey.pod @@ -11,10 +11,10 @@ X509_REQ_get_X509_PUBKEY #include - EVP_PKEY *X509_get_pubkey(const X509 *x); + EVP_PKEY *X509_get_pubkey(X509 *x); EVP_PKEY *X509_get0_pubkey(const X509 *x); int X509_set_pubkey(X509 *x, EVP_PKEY *pkey); - const X509_PUBKEY *X509_get_X509_PUBKEY(const X509 *x); + X509_PUBKEY *X509_get_X509_PUBKEY(const X509 *x); EVP_PKEY *X509_REQ_get_pubkey(X509_REQ *req); EVP_PKEY *X509_REQ_get0_pubkey(const X509_REQ *req); @@ -82,11 +82,9 @@ X509_REQ_get0_X509_PUBKEY() was constified in OpenSSL 4.0. X509_get_pubkey() and X509_REQ_get_pubkey() are deprecated but retained for backward compatibility. -X509_get_pubkey() was converted to use a const parameter in OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_get_subject_name.pod b/doc/man3/X509_get_subject_name.pod index 20b68096a3..56c5404a43 100644 --- a/doc/man3/X509_get_subject_name.pod +++ b/doc/man3/X509_get_subject_name.pod @@ -17,18 +17,18 @@ get X509_NAME hashes or get and set issuer or subject names unsigned long X509_NAME_hash_ex(const X509_NAME *x, OSSL_LIB_CTX *libctx, const char *propq, int *ok); - const X509_NAME *X509_get_subject_name(const X509 *x); + X509_NAME *X509_get_subject_name(const X509 *x); int X509_set_subject_name(X509 *x, const X509_NAME *name); - unsigned long X509_subject_name_hash(const X509 *x); + unsigned long X509_subject_name_hash(X509 *x); - const X509_NAME *X509_get_issuer_name(const X509 *x); + X509_NAME *X509_get_issuer_name(const X509 *x); int X509_set_issuer_name(X509 *x, const X509_NAME *name); - unsigned long X509_issuer_name_hash(const X509 *x); + unsigned long X509_issuer_name_hash(X509 *x); - const X509_NAME *X509_REQ_get_subject_name(const X509_REQ *req); + X509_NAME *X509_REQ_get_subject_name(const X509_REQ *req); int X509_REQ_set_subject_name(X509_REQ *req, const X509_NAME *name); - const X509_NAME *X509_CRL_get_issuer(const X509_CRL *crl); + X509_NAME *X509_CRL_get_issuer(const X509_CRL *crl); int X509_CRL_set_issuer_name(X509_CRL *x, const X509_NAME *name); #include @@ -132,7 +132,7 @@ were added in OpenSSL 3.4. =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_sign.pod b/doc/man3/X509_sign.pod index afbdc67eb3..92bd52b484 100644 --- a/doc/man3/X509_sign.pod +++ b/doc/man3/X509_sign.pod @@ -52,10 +52,6 @@ is not always updated meaning a stale version is sometimes used. This is not normally a problem because modifying the signed portion will invalidate the signature and signing will always update the encoding. -When signing X509 certificates and certificate requests, any B -subjectKeyIdentifier (empty string) or authorityKeyIdentifier (empty sequence) -extensions are flagged as an error and the signature operation fails. - =head1 RETURN VALUES All functions return the size of the signature @@ -84,7 +80,7 @@ in OpenSSL 3.4. =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_verify.pod b/doc/man3/X509_verify.pod index 863b286d16..ad08a5fafa 100644 --- a/doc/man3/X509_verify.pod +++ b/doc/man3/X509_verify.pod @@ -12,7 +12,7 @@ verify certificate, certificate request, or CRL signature #include int X509_verify(X509 *x, EVP_PKEY *pkey); - int X509_self_signed(const X509 *cert, int verify_signature); + int X509_self_signed(X509 *cert, int verify_signature); int X509_REQ_verify_ex(X509_REQ *a, EVP_PKEY *pkey, OSSL_LIB_CTX *libctx, const char *propq); @@ -77,11 +77,9 @@ X509_REQ_verify_ex(), and X509_self_signed() were added in OpenSSL 3.0. X509_ACERT_verify() was added in OpenSSL 3.4. -X509_self_signed() had its cert parameter modified to be I in OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509_verify_cert.pod b/doc/man3/X509_verify_cert.pod index aaaaace4d6..360e974812 100644 --- a/doc/man3/X509_verify_cert.pod +++ b/doc/man3/X509_verify_cert.pod @@ -2,477 +2,99 @@ =head1 NAME +X509_build_chain, X509_verify_cert, -X509_STORE_CTX_verify, -X509_build_chain - build and verify X509 certificate chain +X509_STORE_CTX_verify - build and verify X509 certificate chain =head1 SYNOPSIS #include - int X509_verify_cert(X509_STORE_CTX *ctx); - int X509_STORE_CTX_verify(X509_STORE_CTX *ctx); - STACK_OF(X509) *X509_build_chain(const X509 *target, STACK_OF(X509) *certs, + STACK_OF(X509) *X509_build_chain(X509 *target, STACK_OF(X509) *certs, X509_STORE *store, int with_self_signed, OSSL_LIB_CTX *libctx, const char *propq); + int X509_verify_cert(X509_STORE_CTX *ctx); + int X509_STORE_CTX_verify(X509_STORE_CTX *ctx); =head1 DESCRIPTION -=head2 X509_verify_cert and X509_STORE_CTX_verify - -X509_verify_cert() attempts to build and validate a certificate chain for the -target certificate set in I. The verification context, of type -B, must first be constructed with L and -initialised with L. It carries the target certificate, -the trust store, an optional stack of untrusted certificates that may assist -chain construction, verification parameters such as flags and a verification -purpose, an optional verification callback, and, after a call, the verification -outcome. - -A B can be used for only one verification. Calling -X509_verify_cert() a second time on the same context without reinitialising it -fails with a negative return value, and L -subsequently returns B. - -When the target is a certificate, the function performs the following steps in -order. The first step that fails aborts verification, except where a -verification callback explicitly waives the error (see -L below): - -=over 4 - -=item 1. - -B Starting from the target certificate, the verification -machinery seeks an issuer for the certificate currently at the top of the -chain, drawing candidates from I's untrusted stack and from the trust -store. By default the search is untrusted-first: the untrusted stack is -examined before the trust store. Setting B on -I's verification parameters reverses this. When an untrusted-first -search fails to reach a trust anchor and B is not -set, the search is retried with progressively shorter untrusted prefixes in -an attempt to find an alternative trusted path. The chain length is bounded -by the configured depth limit (see L); -exceeding it yields B. If more than one -chain is possible, only one is taken. - -Failure to build a chain to a trust anchor yields an error such as -B, -B, -B, -B, or -B. - -=item 2. - -B per RFC 5280, including basic constraints, -key usage and the verification purpose set via -L. - -=item 3. - -B against the configured authentication level, covering -issuer key sizes (B) and signature algorithm -strength (B). The leaf key is checked separately -before chain construction begins (B). - -=item 4. - -B against any hostnames, email addresses or IP addresses -configured on the verification parameters -(L and related). - -=item 5. - -B via CRLs and, when configured, OCSP. The set of checks -performed is controlled by flags such as B and -B. - -=item 6. - -B on every certificate in the chain, -walking from the trust anchor down to the target. The signature on the -chain's terminating certificate is not verified: trust is taken from its -presence in the trust store rather than from its signature. This applies -both to a conventional self-signed trust anchor and, when -B is in effect, to a non-self-signed -intermediate promoted to anchor status. B -requests that the self-signature on a self-signed terminator be verified; -it has no effect when the terminator is a non-self-signed certificate. -Validity periods are checked on every certificate, including the -terminator. - -=item 7. - -B per RFC 5280 section 4.2.1.10; see -L for details of the matching primitive and -the general-name types it covers. - -=item 8. - -B of AS-number and IP-address delegation -extensions, performed by default unless OpenSSL was built with -B. - -=item 9. - -B, performed only when -B is set. - -=back - -Several B values modify the behaviour of these checks; -representative ones are named at the relevant step above, but the list there -is not exhaustive. The complete set of verification flags, the effect each -one has, and the functions used to query and modify them are documented in -L. - -Applications rarely call X509_verify_cert() directly. It is invoked internally -by OpenSSL during S/MIME and CMS verification and during the TLS handshake. - -X509_STORE_CTX_verify() behaves identically to X509_verify_cert() except for -the selection of the target certificate: if no target has been set on I -(see L) and the untrusted stack is nonempty, the -first certificate in the untrusted stack is adopted as the target before -verification begins. If a target was set explicitly, X509_STORE_CTX_verify() -uses it and does not consult the untrusted stack for this purpose. - -=head2 Raw public key targets - -When the verification target is a raw public key rather than a certificate -(set via L), both functions validate the raw public -key instead of a certificate chain. The set of possible checks is significantly -reduced: there are no extensions, names, CRLs or signatures to verify. The raw -public key can be authenticated only via DANE TLSA records, either locally -synthesised or obtained by the application from DNS. Raw public key DANE TLSA -records may be added via L or L. - -=head2 X509_build_chain - -X509_build_chain() builds a certificate chain starting from I, using -the same chain-construction algorithm as X509_verify_cert() (see -L above). It internally uses a -B structure associated with the library context I -and property query string I, both of which may be NULL. The role of -I depends on I: - -=over 4 - -=item * - -If I is non-NULL, I is treated as an optional list of -B intermediate certificates that may help complete the chain, and -the chain must reach a trust anchor contained in I. If no chain to a -trust anchor can be built, the function fails and returns NULL. - -=item * - -If I is NULL, I is installed as the B stack for the -internal context (see L). In this mode -the function builds the chain as far as it can but does not require it to -reach an anchor: if chain construction fails partway, the partial chain built -so far is still returned. - -=back - -Because the internal B is allocated and freed inside -X509_build_chain(), search-policy flags such as B -and B and the configured depth limit always take -their default values, and the specific B code that caused -chain construction to fail is not reported back: the function signals only -success or failure through its return value (and, when I is NULL, may -also return a partial chain). - -On success the returned stack starts with a newly up-referenced I -followed by the issuer certificates that were found. A self-signed certificate -at the top of the chain is included in the returned stack when either -I is 1, or the chain consists solely of I (for -example because I itself is self-signed or no further issuer could -be found). When the chain has more than one element and I -is 0, the self-signed top is omitted from the result. - -The caller is responsible for freeing the returned stack. - -=head1 THE VERIFICATION CALLBACK - -Each B carries a I with the signature - - int (*verify_cb)(int ok, X509_STORE_CTX *ctx); - -This callback is invoked by X509_verify_cert() and X509_STORE_CTX_verify() -at multiple points during verification, both to B and to -B. It is installed by L -on the context, or it is inherited at L time from -the B (see L). If neither has -been set, a default callback is used which simply returns its I argument -unchanged, causing every error to abort verification. - -=head2 When the callback is called - -There are two distinct invocation patterns: - -=over 4 - -=item B (I = 0) - -The callback is called with I set to 0 each time a check fails. Before the -call, the verification machinery records the B code describing -the failure on I, and for certificate-level errors also records the -depth at which the error was detected and the certificate in question. The -callback inspects these via L, -L, and L. -CRL- and OCSP-related errors update only the error code; the depth and -current certificate retain their values from a preceding context. - -=item B (I = 1) - -During the signature-and-validity pass, after each certificate in the chain -has been checked successfully, the callback is called with I set to 1. -The current certificate, current issuer, and error depth (queryable -respectively via L, -L, and -L) describe the certificate that has just -been accepted. The callback may use this to log progress, but B return -a nonzero value, otherwise verification is aborted. - -=back - -The callback's return value controls subsequent verification: - -=over 4 - -=item * - -A nonzero return value causes verification to B. For an error -notification this constitutes B the error. - -=item * - -A zero return value causes verification to B immediately. The function -returns 0 to its caller in this case, regardless of whether the callback was -invoked with I = 0 or I = 1. - -=back - -=head2 Sticky errors - -When the callback waives an error by returning nonzero, the underlying check is -treated as passed for control-flow purposes, but the error code recorded on -I is B reset to B. A subsequent successful return from -X509_verify_cert() therefore does B imply that -L will return B: it may still hold -the last error code that was waived. This is intentional. Only the callback -itself is permitted to overwrite the error code, via -L, and only at its own risk. - -=head2 Dangers - -A verification callback that returns nonzero on an error notification has, by -definition, suppressed an authentication check that OpenSSL considered -necessary. Callers should treat installing a callback that waives errors as a -deliberate weakening of the security guarantees of X509_verify_cert(), to be -done only for specific, well-understood error codes. The following pitfalls are -common: - -=over 4 - -=item * - -B. A callback that returns 1 unconditionally turns -X509_verify_cert() into "accept anything" and is almost always wrong outside of -diagnostics. Inspect the error code via L and -waive only the specific codes you intend to. - -=item * - -B. Because the callback is also called with -I = 1, a callback that mistakenly returns 0 in that case causes -verification to fail even though every check passed. The caller cannot -distinguish this from a genuine failure based on the return value alone. - -=item * - -B. The sticky-error rule exists so that a waived -error remains visible to the caller after verification returns. A callback -that calls L with B hides this -information and can also mask a later error if the callback is invoked again -before verification completes. - -=item * - -B. The B is live during -the callback: the verification routines are actively reading its chain, -parameters, and other state. Calling context-mutating functions from within -the callback -- for example, replacing the verified chain via -L, swapping the trust store or -untrusted stack, or changing verification flags, depth, purpose, or target --- can corrupt the in-progress verification, produce inconsistent behaviour -between later steps of the pipeline, or, in the case of the verified chain, -cause use-after-free. The only mutators reasonable from within a callback -are the error-related setters (L, -L, L), -and even those should be used sparingly (see L). - -=item * - -B. The callback is on the hot path of every -certificate check; expensive work performed there will slow every TLS handshake -or S/MIME verification that uses the surrounding context. - -=item * - -B. The error depth, from -L, records where an error was detected -during chain processing, not the position of the certificate in the final -chain. Always consult L in addition to -the depth when deciding whether to waive. - -=item * - -B. The set of errors the callback -observes, and the order in which it observes them, depends on the internal -order in which verification checks are performed. When a certificate has more -than one problem, only the first check to detect a problem causes the -callback to be invoked for that certificate; later checks are not reached -unless the callback waives the earlier error. This ordering is an -implementation detail and is not part of the stable API: a refactor that -reorders internal checks without altering the binary success/failure contract -of X509_verify_cert() may still change which B code the -callback sees, or whether a given code is reported at all. Callbacks that -branch on a specific error code being reported, or that assume earlier checks -have already filtered out certain conditions, can therefore change behaviour -silently across OpenSSL releases. Write callbacks defensively: re-fetch the -error code and the current certificate via L -and L afresh on each invocation, and -treat "this error code never appears" as an assumption that may be -invalidated. More fundamentally, because the set and order of error -notifications is not a stable contract, the callback cannot be relied upon to -observe any particular condition or sequence of conditions; that makes it an -unsound mechanism for enforcing or modifying security policy. Use of the -verification callback to alter verification outcomes -- to waive errors, to -inject conditional acceptance, or to gate behaviour on a specific -B code being reported -- is therefore discouraged in production -code. Reserve the callback for diagnostic and logging purposes, where future -changes in which errors appear, or in what order, are not security-relevant. - -=back - -The default callback waives nothing and is the safe choice; it is the right -behaviour for almost all production uses. +X509_build_chain() builds a certificate chain starting from I +using the optional list of intermediate CA certificates I. +If I is NULL it builds the chain as far down as possible, ignoring errors. +Else the chain must reach a trust anchor contained in I. +It internally uses a B structure associated with the library +context I and property query string I, both of which may be NULL. +In case there is more than one possibility for the chain, only one is taken. + +On success it returns a pointer to a new stack of (up_ref'ed) certificates +starting with I and followed by all available intermediate certificates. +A self-signed trust anchor is included only if I is the trust anchor +of I is 1. +If a non-NULL stack is returned the caller is responsible for freeing it. + +The X509_verify_cert() function attempts to discover and validate a +certificate chain based on parameters in I. +The verification context, of type B, can be constructed +using L and L. +It usually includes a target certificate to be verified, +a set of certificates serving as trust anchors, +a list of non-trusted certificates that may be helpful for chain construction, +flags such as X509_V_FLAG_X509_STRICT, and various other optional components +such as a callback function that allows customizing the verification outcome. +A complete description of the certificate verification process is contained in +the L manual page. + +Applications rarely call this function directly but it is used by +OpenSSL internally for certificate validation, in both the S/MIME and +SSL/TLS code. + +A negative return value from X509_verify_cert() can occur if it is invoked +incorrectly, such as with no certificate set in I, or when it is called +twice in succession without reinitialising I for the second call. +A negative return value can also happen due to internal resource problems +or because an internal inconsistency has been detected. +Applications must interpret any return value <= 0 as an error. + +The X509_STORE_CTX_verify() behaves like X509_verify_cert() except that its +target certificate is the first element of the list of untrusted certificates +in I unless a target certificate is set explicitly. + +When the verification target is a raw public key, rather than a certificate, +both functions validate the target raw public key. +In that case the number of possible checks is significantly reduced. +The raw public key can be authenticated only via DANE TLSA records, either +locally synthesised or obtained by the application from DNS. +Raw public key DANE TLSA records may be added via L or +L. =head1 RETURN VALUES -X509_verify_cert() and X509_STORE_CTX_verify() return: +X509_build_chain() returns NULL on error, else a stack of certificates. -=over 4 +Both X509_verify_cert() and X509_STORE_CTX_verify() +return 1 if a complete chain can be built and validated, +otherwise they return 0, and in exceptional circumstances (such as malloc +failure and internal errors) they can also return a negative code. -=item B<1> +If a complete chain can be built and validated both functions return 1. +If the certificate must be rejected on the basis of the data available +or any required certificate status data is not available they return 0. +If no definite answer possible they usually return a negative code. -if a complete chain has been built and every check either succeeded or was -waived by the verification callback. Note that the latter case does not -guarantee that L returns B; see -L. The return value is the authoritative success/failure -signal: callers do not need to additionally check that -L returns B to consider verification -successful. They may consult it to learn whether, and which, errors were -waived by the verification callback. - -=item B<0> - -if verification was rejected. This occurs when a check failed and the callback -did not waive the error, when a trust decision actively rejected the chain, or -when the verification callback returned 0 from a success notification (see -L). When a certificate would have failed more -than one check, the specific B code returned by -L reflects whichever check fired first; this -ordering is an implementation detail and is not stable across releases. -Callers must therefore treat the return value as the authoritative -success/failure signal, and treat the specific error code as diagnostic -information that may shift over time. - -=item A B value - -on a hard error that prevented verification from running to completion. The -documented cases are: I is NULL; I has no target certificate set; -I has already been used for a previous verification; memory allocation -failed; the trust store lookup function returned an error; or an internal -invariant was violated. In these cases L -returns an appropriate B value (B, -B, B or -B). - -=back - -In all failure modes, additional information can be obtained from -L and the related accessors. Applications must -treat any return value E= 0 as verification not having succeeded. - -X509_build_chain() returns NULL on error. Otherwise it returns a newly -allocated stack of certificates that the caller must free; the stack may -represent only a partial chain when I is NULL. - -=head1 BUGS - -Several aspects of chain construction depart from the recommendations of -RFC 4158 (Certification Path Building) and from strict RFC 5280 path -validation. Callers should be aware of the following: - -The chain search is not optimised in the manner described by RFC 4158 -sections 3.1 to 3.5. Candidate issuers are not scored against the set of -heuristics RFC 4158 recommends; at each step the first viable candidate -is committed to, with the only preference being for a candidate whose -validity period covers the current time. There is no tree-traversal -backtracking: when an initial chain does not reach a trust anchor, the -search is retried with progressively shorter untrusted prefixes (unless -B is set), but different candidate issuers at -intermediate positions of the same chain are not tried. In simple -hierarchical PKIs this is rarely an issue. In cross-certified or bridged -PKI environments X509_verify_cert() may fail to find a valid certification -path even when one demonstrably exists in the available certificate set. - -Issuer key usage is not enforced during chain construction. RFC 5280 -section 6.1.4(n) and RFC 4158 section 3.5.3 call for verifying that an -issuer candidate's keyUsage extension permits certificate signing -(B) before that candidate is selected. OpenSSL defers this -check to the later extension-validation pass: if two candidate issuers -exist for a certificate, and the one lacking B happens to be -selected first, verification fails on the extension check rather than -backing off and trying the other candidate. The misuse is ultimately -caught, but a chain that would have validated through the alternative -issuer is not built. - -B relaxes the trust-anchor requirement from -the one defined by RFC 5280 section 6.1.1(d). With the flag set, any -certificate in the trust store is acceptable as the terminator of the -chain, even if it is not a self-signed root. This is an intentional and -now-common deviation that supports modern practices such as pinning trust -to a specific intermediate, or shortening chains by treating a -sufficiently-trusted intermediate as the trust point and eliding the root -above it. Callers should nevertheless be aware that the chain returned in -this mode does not necessarily terminate at an RFC 5280-style trust -anchor. - -L caps each per-pair check at 2**20 -comparisons, but the chain orchestrator issues B(B-1)/2 such -checks for an B-certificate chain. An adversary submitting a -maximally constructed chain can therefore force up to approximately -6.3 million name-constraint comparisons in a four-certificate chain -(one leaf and three name-constrained signers), or approximately 5.2 -billion at the default chain-depth limit of 100. +On error or failure additional error information can be obtained by +examining I using, for example, L. Even if +verification indicated success, the stored error code may be different from +X509_V_OK, likely because a verification callback function has waived the error. =head1 SEE ALSO -L, L, L, L, L, L, L, -L, -L, -L, -L +L =head1 HISTORY @@ -480,7 +102,7 @@ X509_build_chain() and X509_STORE_CTX_verify() were added in OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2009-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2009-2023 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/X509v3_get_ext_by_NID.pod b/doc/man3/X509v3_get_ext_by_NID.pod index e068e52c8b..38caf524a6 100644 --- a/doc/man3/X509v3_get_ext_by_NID.pod +++ b/doc/man3/X509v3_get_ext_by_NID.pod @@ -4,22 +4,21 @@ X509v3_get_ext_count, X509v3_get_ext, X509v3_get_ext_by_NID, X509v3_get_ext_by_OBJ, X509v3_get_ext_by_critical, X509v3_delete_ext, -X509v3_delete_extension, X509v3_add_ext, X509v3_add_extensions, -X509_get_ext_count, X509_get_ext, X509_get_ext_by_NID, X509_get_ext_by_OBJ, -X509_get_ext_by_critical, X509_delete_ext, X509_add_ext, -X509_CRL_get_ext_count, X509_CRL_get_ext, X509_CRL_get_ext_by_NID, -X509_CRL_get_ext_by_OBJ, X509_CRL_get_ext_by_critical, X509_CRL_delete_ext, -X509_CRL_add_ext, X509_REVOKED_get_ext_count, X509_REVOKED_get_ext, -X509_REVOKED_get_ext_by_NID, X509_REVOKED_get_ext_by_OBJ, -X509_REVOKED_get_ext_by_critical, X509_REVOKED_delete_ext, X509_REVOKED_add_ext -- extension stack utility functions +X509v3_add_ext, X509v3_add_extensions, X509_get_ext_count, X509_get_ext, +X509_get_ext_by_NID, X509_get_ext_by_OBJ, X509_get_ext_by_critical, +X509_delete_ext, X509_add_ext, X509_CRL_get_ext_count, X509_CRL_get_ext, +X509_CRL_get_ext_by_NID, X509_CRL_get_ext_by_OBJ, X509_CRL_get_ext_by_critical, +X509_CRL_delete_ext, X509_CRL_add_ext, X509_REVOKED_get_ext_count, +X509_REVOKED_get_ext, X509_REVOKED_get_ext_by_NID, X509_REVOKED_get_ext_by_OBJ, +X509_REVOKED_get_ext_by_critical, X509_REVOKED_delete_ext, +X509_REVOKED_add_ext - extension stack utility functions =head1 SYNOPSIS #include int X509v3_get_ext_count(const STACK_OF(X509_EXTENSION) *x); - const X509_EXTENSION *X509v3_get_ext(const STACK_OF(X509_EXTENSION) *x, int loc); + X509_EXTENSION *X509v3_get_ext(const STACK_OF(X509_EXTENSION) *x, int loc); int X509v3_get_ext_by_NID(const STACK_OF(X509_EXTENSION) *x, int nid, int lastpos); @@ -28,32 +27,31 @@ X509_REVOKED_get_ext_by_critical, X509_REVOKED_delete_ext, X509_REVOKED_add_ext int X509v3_get_ext_by_critical(const STACK_OF(X509_EXTENSION) *x, int crit, int lastpos); X509_EXTENSION *X509v3_delete_ext(STACK_OF(X509_EXTENSION) *x, int loc); - X509_EXTENSION *X509v3_delete_extension(STACK_OF(X509_EXTENSION) **x, int loc); STACK_OF(X509_EXTENSION) *X509v3_add_ext(STACK_OF(X509_EXTENSION) **x, - const X509_EXTENSION *ex, int loc); + X509_EXTENSION *ex, int loc); STACK_OF(X509_EXTENSION) *X509v3_add_extensions(STACK_OF(X509_EXTENSION) **target, const STACK_OF(X509_EXTENSION) *exts); int X509_get_ext_count(const X509 *x); - const X509_EXTENSION *X509_get_ext(const X509 *x, int loc); + X509_EXTENSION *X509_get_ext(const X509 *x, int loc); int X509_get_ext_by_NID(const X509 *x, int nid, int lastpos); int X509_get_ext_by_OBJ(const X509 *x, const ASN1_OBJECT *obj, int lastpos); int X509_get_ext_by_critical(const X509 *x, int crit, int lastpos); X509_EXTENSION *X509_delete_ext(X509 *x, int loc); - int X509_add_ext(X509 *x, const X509_EXTENSION *ex, int loc); + int X509_add_ext(X509 *x, X509_EXTENSION *ex, int loc); int X509_CRL_get_ext_count(const X509_CRL *x); - const X509_EXTENSION *X509_CRL_get_ext(const X509_CRL *x, int loc); + X509_EXTENSION *X509_CRL_get_ext(const X509_CRL *x, int loc); int X509_CRL_get_ext_by_NID(const X509_CRL *x, int nid, int lastpos); int X509_CRL_get_ext_by_OBJ(const X509_CRL *x, const ASN1_OBJECT *obj, int lastpos); int X509_CRL_get_ext_by_critical(const X509_CRL *x, int crit, int lastpos); X509_EXTENSION *X509_CRL_delete_ext(X509_CRL *x, int loc); - int X509_CRL_add_ext(X509_CRL *x, const X509_EXTENSION *ex, int loc); + int X509_CRL_add_ext(X509_CRL *x, X509_EXTENSION *ex, int loc); int X509_REVOKED_get_ext_count(const X509_REVOKED *x); - const X509_EXTENSION *X509_REVOKED_get_ext(const X509_REVOKED *x, int loc); + X509_EXTENSION *X509_REVOKED_get_ext(const X509_REVOKED *x, int loc); int X509_REVOKED_get_ext_by_NID(const X509_REVOKED *x, int nid, int lastpos); int X509_REVOKED_get_ext_by_OBJ(const X509_REVOKED *x, const ASN1_OBJECT *obj, int lastpos); @@ -84,12 +82,6 @@ X509v3_delete_ext() deletes the extension with index I from I. The deleted extension is returned and must be freed by the caller. If I is an invalid index value, NULL is returned. -X509v3_delete_extension() extends X509v3_delete_ext() by deallocating the -extension stack I<*x> if it becomes empty, and in that case also setting I<*x> -to NULL. -This is a convenience wrapper for cases in which a list of extensions is optional and -should be omitted if the stack becomes empty. - X509v3_add_ext() inserts extension I to STACK I<*x> at position I. If I is -1, the new extension is added to the end. A new STACK is allocated if I<*x> is NULL. @@ -104,21 +96,18 @@ that has the same OID as a pre-existing one replaces this earlier one. X509_get_ext_count(), X509_get_ext(), X509_get_ext_by_NID(), X509_get_ext_by_OBJ(), X509_get_ext_by_critical(), X509_delete_ext() and X509_add_ext() operate on the extensions of certificate I. They are -otherwise identical to the X509v3 functions except that X509_delete_ext() -behaves like X509v3_delete_extension(). +otherwise identical to the X509v3 functions. X509_CRL_get_ext_count(), X509_CRL_get_ext(), X509_CRL_get_ext_by_NID(), X509_CRL_get_ext_by_OBJ(), X509_CRL_get_ext_by_critical(), X509_CRL_delete_ext() and X509_CRL_add_ext() operate on the extensions of -CRL I. They are otherwise identical to the X509v3 functions except that -X509_CRL_delete_ext() behaves like X509v3_delete_extension(). +CRL I. They are otherwise identical to the X509v3 functions. X509_REVOKED_get_ext_count(), X509_REVOKED_get_ext(), X509_REVOKED_get_ext_by_NID(), X509_REVOKED_get_ext_by_OBJ(), X509_REVOKED_get_ext_by_critical(), X509_REVOKED_delete_ext() and X509_REVOKED_add_ext() operate on the extensions of CRL entry I. -They are otherwise identical to the X509v3 functions except that -X509_REVOKED_delete_ext() behaves like X509v3_delete_extension(). +They are otherwise identical to the X509v3 functions. =head1 NOTES @@ -138,24 +127,13 @@ X509v3_delete_ext() and its variants are a bit counter-intuitive because these functions do not free the extension they delete. They return an B object which must be explicitly freed using X509_EXTENSION_free(). -X509v3_delete_extension() behaves similarly, but it may also deallocate -the extension stack if it becomes empty, setting it to NULL. - -X509v3_add_ext(), X509v3_add_extensions() and X509_add_ext() ignore any -B values of the C (empty OCTET STRING) or the -C (empty SEQUENCE) extensions. -These empty values are not added to the extension list. -In the case of X509v3_add_extensions() any previous instance of the same -extension is deleted, so the call is not necessarily without side-effects in -that case. =head1 RETURN VALUES X509v3_get_ext_count() returns the extension count or 0 for failure. -X509v3_get_ext(), X509v3_delete_ext(), X509v3_delete_extension() and -X509_delete_ext() return an B structure or NULL if an error -occurs. +X509v3_get_ext(), X509v3_delete_ext() and X509_delete_ext() return an +B structure or NULL if an error occurs. X509v3_get_ext_by_OBJ() and X509v3_get_ext_by_critical() return the extension index or -1 if an error occurs. @@ -178,11 +156,9 @@ L X509v3_add_extensions() was added in OpenSSL 3.4. -X509v3_delete_extension() was added in OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man3/d2i_X509.pod b/doc/man3/d2i_X509.pod index 53f5aaacb7..8e04c2286c 100644 --- a/doc/man3/d2i_X509.pod +++ b/doc/man3/d2i_X509.pod @@ -471,29 +471,21 @@ encoding. Unlike the C structures which can have pointers to sub-objects within, the DER is a serialized encoding, suitable for sending over the network, writing to a file, and so on. -B>() attempts to decode I bytes at I<*ppin>. -When there is no error, a pointer to a B> object is returned and I<*ppin> is -incremented to the byte following the parsed data. -The caller owns the returned object and needs to free it when it is no longer needed, -e.g., via X509_free() for B objects. +B>() attempts to decode I bytes at I<*ppin>. If successful a +pointer to the B> structure is returned and I<*ppin> is incremented to +the byte following the parsed data. If I is not NULL then a pointer +to the returned structure is also written to I<*a>. If an error occurred +then NULL is returned. The caller retains ownership of the +returned object and needs to free it when it is no longer needed, e.g. +using X509_free() for X509 objects or DSA_SIG_free() for DSA_SIG objects. -If either I or I<*a> is NULL, then fresh storage is allocated for the -returned object, and if I is not NULL then I<*a> is set equal to the -returned pointer. - -When both I and I<*a> are not NULL, I<*a> MUST be a pointer to an -existing I object, which is reused to hold the decoded result. -On error (NULL return value), the object is freed and I<*a> is set to NULL. - -From OpenSSL 3.x onwards, reuse is only supported when I<*a> points to a newly -allocated, and not otherwise modified, I object. -Allocation can be via one of the various _ex() routines, which make it possible -to associate the allocated object with a chosen I (library context) -or I (property query), see the B section. -No other reuse is supported (see B below, and the discussion in the -B section). -The returned object is not suitable for another reuse: each reuse attempt MUST -start with a newly allocated object. +On a successful return, if I<*a> is not NULL then it is assumed that I<*a> +contains a valid B> structure and an attempt is made to reuse it. +For B> structures where it matters it is possible to set up a library +context on the decoded structure this way (see the B section). +However using the "reuse" capability for other purposes is B (see B below, and the discussion in the B +section). B_bio>() is similar to B>() except it attempts to parse data from BIO I. @@ -600,10 +592,6 @@ B_bio>() and B_fp>(), as well as i2d_ASN1_bio_stream(), return 1 for success and 0 if an error occurs. -On error, these functions may record the error in the OpenSSL error queue. -That error queue can be inspected with the B family of functions, such as -L and L. - =head1 EXAMPLES Allocate and encode the DER encoding of an X509 structure: @@ -716,10 +704,6 @@ structure has been modified after deserialization or previous serialization. This is because some objects cache the encoding for efficiency reasons. -=head1 SEE ALSO - -ERR_print_errors(3), ERR_peek_last_error_all(3) - =head1 HISTORY d2i_OSSL_ATTRIBUTES_SYNTAX(), d2i_OSSL_BASIC_ATTR_CONSTRAINTS(), diff --git a/doc/man5/config.pod b/doc/man5/config.pod index 2e455ea78c..36159c7820 100644 --- a/doc/man5/config.pod +++ b/doc/man5/config.pod @@ -89,11 +89,13 @@ A configuration file is divided into a number of I. A section begins with the section name in square brackets, and ends when a new section starts, or at the end of the file. The section name can consist of alphanumeric characters and underscores. -Whitespace between the name and the brackets is ignored. +Whitespace between the name and the brackets is removed. -The content at the start of the configuration file that precedes its first -named section is special and is referred to as the B or B -section. +The first section of a configuration file is special and is referred to +as the B section. This section is usually unnamed and spans from +the start of file until the first named section. When a name is being +looked up, it is first looked up in the current or named section, +and then the default section if necessary. The environment is mapped onto a section called B. @@ -531,7 +533,7 @@ L. =head1 COPYRIGHT -Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man5/fips_config.pod b/doc/man5/fips_config.pod index 2e5a789b44..c3f7b8f3ab 100644 --- a/doc/man5/fips_config.pod +++ b/doc/man5/fips_config.pod @@ -52,13 +52,6 @@ Regardless of the value, the operation (e.g., key generation) that called the continuous test will return an error code if its continuous test fails. The operation may then be retried if the error mode has not been triggered. -=item B - -If set to C<1>, the module will not run the self tests during initialization. -Instead, the self tests will be run on demand when a particular algorithm is -used. -The default value of C<0> runs the self tests during initialization. - =item B The calculated MAC of the FIPS provider file. @@ -234,7 +227,7 @@ This functionality was added in OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man5/x509v3_config.pod b/doc/man5/x509v3_config.pod index 449882ad63..781891966e 100644 --- a/doc/man5/x509v3_config.pod +++ b/doc/man5/x509v3_config.pod @@ -175,7 +175,7 @@ Examples: =head2 Subject Key Identifier -The Subject Key Identifier (SKID) extension takes three possible forms: +The SKID extension specification has a value with three choices. =over 4 @@ -191,13 +191,12 @@ STRING subjectPublicKey (excluding the tag, length, and number of unused bits). =item A hex string (possibly with C<:> separating bytes) -The specified value is used directly. +The provided value is output directly. This choice is strongly discouraged. =back -See L, L, and L documentation -for further details relevant to each of the command-line utilities. +By default the B, B, and B apps behave as if B was given. Example: @@ -205,56 +204,35 @@ Example: =head2 Authority Key Identifier -The Authority Key Identifier (SKID) extension takes two different forms. +The AKID extension specification may have the value B +indicating that no AKID shall be included. +Otherwise it may have the value B or B +or both of them, separated by C<,>. +Either or both can have the option B, +indicated by putting a colon C<:> between the value and this option. +For self-signed certificates the AKID is suppressed unless B is present. -The value B indicates that no AKID shall be included. +By default the B, B, and B apps behave as if B was given +for self-signed certificates and BC<,> B otherwise. -Otherwise, the value syntax is that of a comma-separated list of either or both -of the B or B keywords. +If B is present, an attempt is made to +copy the subject key identifier (SKID) from the issuer certificate except if +the issuer certificate is the same as the current one and it is not self-signed. +The hash of the public key related to the signing key is taken as fallback +if the issuer certificate is the same as the current certificate. +If B is present but no value can be obtained, an error is returned. -The B keyword asks that the AKID include the issuer's subject key -identifier. - -The B keyword asks that the AKID include the serial number and issuer -distinguished name (grandparent name of subject certificate) of the issuer -certificate. -Unless qualified with C (as described below), these are added only as a -fallback if the B is not requested, or no SKID was available in the -issuer certificate. - -Either or both keywords can be suffixed with an optional qualifier, which can -be either C or C. -If the qualifier is present, it is separated from the keyword by a colon -(C<:>). - -The C qualifier makes that AKID element mandatory, an error is raised -if that element cannot be included. -The B certificate's issuer name and serial number are no longer a -fallback when the B qualifier is used. -The C qualifier makes that AKID element further conditional on the -certificate not being self-signed. - -When creating a self-signed certificate, be sure to specify a SKID extension if -you want to have a mandatory (C qualified) B in the AKID -extension. - -See L, L, and L for further -details relevant to that specific command-line utility. +If B is present, and in addition it has the option B specified +or B is not present, +then the issuer DN and serial number are copied from the issuer certificate. +If this fails, an error is returned. Examples: - # Keyid preferred, otherwise issuer name & serial authorityKeyIdentifier = keyid, issuer - # As above, but skip the extension entirely if self-signed - authorityKeyIdentifier = keyid:nonss, issuer:nonss - - # Keyid when possible, issuer name & serial always authorityKeyIdentifier = keyid, issuer:always - # Keyid when possible, issuer as fallback when not self-signed - authorityKeyIdentifier = keyid, issuer:nonss - =head2 Subject Alternative Name This is a multi-valued extension that supports several types of name @@ -628,18 +606,9 @@ invalid extensions if they are not used carefully. L, L, L, L -=head1 HISTORY - -OpenSSL 4.0 updated the syntax of the B (SKID) and -B (AKID) extensions, described above, to introduce the -C qualifier for the B and B keywords. -The command-line utilities no longer have specialised built-in logic to add -these extensions, they are handled through configuration files and command-line -options just like any other extension. - =head1 COPYRIGHT -Copyright 2004-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2004-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_CIPHER-AES.pod b/doc/man7/EVP_CIPHER-AES.pod index 0cb6d20829..7bd3746c9b 100644 --- a/doc/man7/EVP_CIPHER-AES.pod +++ b/doc/man7/EVP_CIPHER-AES.pod @@ -65,14 +65,9 @@ L. =head1 NOTES -The AES-SIV, AES-WRAP, and GCM-SIV mode implementations do not support -streaming. That means to obtain correct results there can be only one -L or L call on the payload after -the initialization of the context. - -When wrapping with AES-WRAP-PAD ciphers, the output buffer must be at least -I rounded up to the cipher block size (8 bytes) plus the block size. -That is, the minimum output buffer size is C<((inl + 7) / 8) * 8 + 8> bytes. +The AES-SIV and AES-WRAP mode implementations do not support streaming. That +means to obtain correct results there can be only one L +or L call after the initialization of the context. The AES-XTS implementations allow streaming to be performed, but each L or L call requires each input diff --git a/doc/man7/EVP_CIPHER-DES.pod b/doc/man7/EVP_CIPHER-DES.pod index 30cf56b60f..7ece7c5e0f 100644 --- a/doc/man7/EVP_CIPHER-DES.pod +++ b/doc/man7/EVP_CIPHER-DES.pod @@ -61,16 +61,6 @@ The following algorithms are available in the legacy provider: This implementation supports the parameters described in L including "encrypt-check" and "fips-indicator". -=head1 NOTES - -The DES3-WRAP implementation does not support streaming. That means to obtain -correct results there can be only one L or -L call after the initialization of the context. - -When wrapping (encrypting) with DES3-WRAP, the output buffer must be at least -I + 16 bytes. The extra 16 bytes accommodate an 8-byte IV and an -8-byte integrity check value (ICV) prepended and appended by the algorithm. - =head1 SEE ALSO L, L, L, @@ -78,7 +68,7 @@ L, =head1 COPYRIGHT -Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_KDF-IKEV2KDF.pod b/doc/man7/EVP_KDF-IKEV2KDF.pod deleted file mode 100644 index cac50f44c5..0000000000 --- a/doc/man7/EVP_KDF-IKEV2KDF.pod +++ /dev/null @@ -1,349 +0,0 @@ -=pod - -=head1 NAME - -EVP_KDF-IKEV2KDF - The IKEV2KDF EVP_KDF implementation - -=head1 DESCRIPTION - -Support for computing the B KDF through the B API. - -The EVP_KDF-IKEV2KDF algorithm implements the IKEv2 key derivation function. -It is defined in RFC 7296, sections 2.13, 2.14, 2.17, 2.18 and is used by the -Internet Key Exchange version 2 (IKEv2) protocol to derive various keys from -the shared secret established during the Diffie-Hellman (DH) exchange. -RFC 4753 specifies additional ECDH groups for use with IKEv2. -The key derivation requires several inputs including the hash function, -the shared secret (g^ir), nonces from both parties, the Security -Parameter Index (SPI) values from both parties, and new shared secret (new g^ir). -SA refers to the Security Association established between the two parties. - -=head2 Identity - -"IKEV2KDF" is the name for this implementation; it -can be used with the EVP_KDF_fetch() function. - -=head2 Supported parameters - -The supported parameters are: - -=over 4 - -=item "properties" (B) - -=item "digest" (B) - -These parameters work as described in L. -The digest parameter must be set to one of "SHA1", "SHA224", "SHA256", "SHA384", -or "SHA512" for the IKEV2KDF implementation. -If a value is already set, the contents are replaced. - -=item "secret" (B) - -This parameter sets the shared secret (g^ir) used for generating the SEEDKEY, -or the new shared secret (new g^ir) used for deriving DKM(Child_DH) or REKEY. -The shared secret length is in the range of 8 to 1024 bytes as specified in the NIST -ACVP draft (L). -If a value is already set, the contents are replaced. - -=item "ni" (B) - -This parameter sets the initiator's nonce (Ni) value for the KDF. -The nonce length is in the range of 8 to 256 bytes as specified in NIST -ACVP draft (L). -If a value is already set, the contents are replaced. - -=item "nr" (B) - -This parameter sets the responder's nonce (Nr) value for the KDF. -The nonce length is in the range of 8 to 256 bytes as specified in NIST -ACVP draft (L). -If a value is already set, the contents are replaced. - -=item "spii" (B) - -This parameter sets the initiator's Security Parameter Index (SPIi) value -for the KDF. If a value is already set, the contents are replaced. - -=item "spir" (B) - -This parameter sets the responder's Security Parameter Index (SPIr) value -for the KDF. If a value is already set, the contents are replaced. - -=item "seedkey" (B) - -This parameter sets the SEEDKEY used for deriving DKM(Initial SA). -If a value is already set, the contents are replaced. - -=item "key" (B) - -This parameter sets the SK_d used for deriving DKM(Child_SA) or REKEY. -If a value is already set, the contents are replaced. - -=item "mode" (B) - -This parameter sets the IKEv2 KDF mode. The IKEV2KDF implementation supports -three different modes of operation: - -=over 8 - -=item EVP_KDF_IKEV2_MODE_GEN - -It generates the SKEYSEED used in deriving key material. -It is the default mode if the "mode" parameter is not set. -It takes the shared secret (g^ir) and nonces (Ni and Nr) as input and -generates the SKEYSEED. - -=item EVP_KDF_IKEV2_MODE_DKM - -It operates in three stages, based on the input parameter sets. - -It first performs initial key derivation: it derives the initial set of keys -(SK_d, SK_ai, SK_ar, SK_ei, SK_er, SK_pi, SK_pr) using SKEYSEED generated in -"EVP_KDF_IKEV2_MODE_GEN", the nonces (from both sides), and security parameter -index (SPI) values (from both sides). - -Then, it derives keying material for the Child_SA, using the SK_d as input -along with new nonces. - -Finally, it derives keying material for the Child_DH, using the SK_d as input -along with new nonces and new shared secret (new g^ir). - -=item EVP_KDF_IKEV2_MODE_REKEY - -It derives a new SKEYSEED when rekeying the IKE SA, using the existing SK_d as -input along with new nonces and new shared secret (new g^ir). - -=back - -=back - -=head1 NOTES - -A context for IKEV2KDF can be obtained by calling: - - EVP_KDF *kdf = EVP_KDF_fetch(NULL, "IKEV2KDF", NULL); - EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf); - -The output length for IKEV2KDF can be specified by the caller based on the -specific key being derived (e.g., SK_d, SK_ai, SK_ar, SK_ei, SK_er, SK_pi, SK_pr). -Different keys may require different lengths depending on the cryptographic -algorithms being used. - -=head1 EXAMPLES - -=head2 Example of SEEDKEY generation - -This example derives a 32-byte SEEDKEY using SHA-256 with the appropriate -shared secret and nonces: - - EVP_KDF *kdf = NULL; - EVP_KDF_CTX *kctx = NULL; - unsigned char secret[32] = "0123456789abcdef0123456789abcdef"; /* g^ir */ - unsigned char ni[8] = "01234567"; - unsigned char nr[8] = "89abcdef"; - int mode = EVP_KDF_IKEV2_MODE_GEN; - unsigned char out[32]; - size_t outlen = sizeof(out); - OSSL_PARAM params[6], *p = params; - - kdf = EVP_KDF_fetch(NULL, "IKEV2KDF", NULL); - kctx = EVP_KDF_CTX_new(kdf); - if (!kctx) { - /* Error handling */ - } - - *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, - SN_sha256, strlen(SN_sha256)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SECRET, - secret, sizeof(secret)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_IKEV2KDF_NI, - ni, sizeof(ni)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_IKEV2KDF_NR, - nr, sizeof(nr)); - *p++ = OSSL_PARAM_construct_int(OSSL_KDF_PARAM_MODE, &mode); - *p = OSSL_PARAM_construct_end(); - if (EVP_KDF_derive(kctx, out, outlen, params) <= 0) { - /* Error */ - ; - } - EVP_KDF_CTX_free(kctx); - EVP_KDF_free(kdf); - -=head2 Example of deriving key material DKM(Initial SA) - - EVP_KDF *kdf = NULL; - EVP_KDF_CTX *kctx = NULL; - unsigned char ni[8] = "01234567"; - unsigned char nr[8] = "89abcdef"; - unsigned char spii[8] = "01234567"; - unsigned char spir[8] = "89abcdef"; - unsigned char skeyseed[32] = "0123456789abcdef0123456789abcdef"; - int mode = EVP_KDF_IKEV2_MODE_DKM; - unsigned char out[224]; - OSSL_PARAM params[8], *p = params; - - kdf = EVP_KDF_fetch(NULL, "IKEV2KDF", NULL); - kctx = EVP_KDF_CTX_new(kdf); - if (!kctx) { - /* Error handling */ - } - - *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, - SN_sha256, strlen(SN_sha256)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SEED, - skeyseed, sizeof(skeyseed)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_IKEV2KDF_NI, - ni, sizeof(ni)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_IKEV2KDF_NR, - nr, sizeof(nr)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_IKEV2KDF_SPII, - spii, sizeof(spii)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_IKEV2KDF_SPIR, - spir, sizeof(spir)); - *p++ = OSSL_PARAM_construct_int(OSSL_KDF_PARAM_MODE, &mode); - *p = OSSL_PARAM_construct_end(); - if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) { - /* Error handling */ - ; - } - EVP_KDF_CTX_free(kctx); - EVP_KDF_free(kdf); - -=head2 Example of generating DKM(Child_SA) - - EVP_KDF *kdf = NULL; - EVP_KDF_CTX *kctx = NULL; - unsigned char ni[8] = "01234567"; - unsigned char nr[8] = "89abcdef"; - unsigned char sk_d[32] = "0123456789abcdef0123456789abcdef"; - int mode = EVP_KDF_IKEV2_MODE_DKM; - unsigned char out[224]; - OSSL_PARAM params[6], *p = params; - - kdf = EVP_KDF_fetch(NULL, "IKEV2KDF", NULL); - kctx = EVP_KDF_CTX_new(kdf); - if (!kctx) { - /* Error handling */ - } - - *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, - SN_sha256, strlen(SN_sha256)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, - sk_d, sizeof(sk_d)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_IKEV2KDF_NI, - ni, sizeof(ni)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_IKEV2KDF_NR, - nr, sizeof(nr)); - *p++ = OSSL_PARAM_construct_int(OSSL_KDF_PARAM_MODE, &mode); - *p = OSSL_PARAM_construct_end(); - if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) { - /* Error handling */ - ; - } - EVP_KDF_CTX_free(kctx); - EVP_KDF_free(kdf); - -=head2 Example of generating DKM(Child_DH) - - EVP_KDF *kdf = NULL; - EVP_KDF_CTX *kctx = NULL; - unsigned char ni[8] = "01234567"; - unsigned char nr[8] = "89abcdef"; - unsigned char sk_d[32] = "0123456789abcdef0123456789abcdef"; - unsigned char new_secret[32] = "0123456789abcdef0123456789abcdef"; /* new g^ir */ - int mode = EVP_KDF_IKEV2_MODE_DKM; - unsigned char out[224]; - OSSL_PARAM params[7], *p = params; - - kdf = EVP_KDF_fetch(NULL, "IKEV2KDF", NULL); - kctx = EVP_KDF_CTX_new(kdf); - if (!kctx) { - /* Error handling */ - } - - *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, - SN_sha256, strlen(SN_sha256)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, - sk_d, sizeof(sk_d)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SECRET, - new_secret, sizeof(new_secret)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_IKEV2KDF_NI, - ni, sizeof(ni)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_IKEV2KDF_NR, - nr, sizeof(nr)); - *p++ = OSSL_PARAM_construct_int(OSSL_KDF_PARAM_MODE, &mode); - *p = OSSL_PARAM_construct_end(); - if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) { - /* Error */ - ; - } - EVP_KDF_CTX_free(kctx); - EVP_KDF_free(kdf); - -=head2 Example of rekeying the IKE SA - - EVP_KDF *kdf = NULL; - EVP_KDF_CTX *kctx = NULL; - unsigned char ni[8] = "01234567"; - unsigned char nr[8] = "89abcdef"; - unsigned char sk_d[32] = "0123456789abcdef0123456789abcdef"; - unsigned char new_secret[32] = "0123456789abcdef0123456789abcdef"; /* new g^ir */ - int mode = EVP_KDF_IKEV2_MODE_REKEY; - unsigned char out[32]; - OSSL_PARAM params[7], *p = params; - - kdf = EVP_KDF_fetch(NULL, "IKEV2KDF", NULL); - kctx = EVP_KDF_CTX_new(kdf); - if (!kctx) { - /* Error handling */ - } - - *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, - SN_sha256, strlen(SN_sha256)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, - sk_d, sizeof(sk_d)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SECRET, - new_secret, sizeof(new_secret)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_IKEV2KDF_NI, - ni, sizeof(ni)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_IKEV2KDF_NR, - nr, sizeof(nr)); - *p++ = OSSL_PARAM_construct_int(OSSL_KDF_PARAM_MODE, &mode); - *p = OSSL_PARAM_construct_end(); - if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) { - /* Error handling */ - ; - } - EVP_KDF_CTX_free(kctx); - EVP_KDF_free(kdf); - -=head1 CONFORMING TO - -RFC 7296 and SP800-135 - -=head1 SEE ALSO - -L, -L, -L, -L, -L, -L, -L, -L - -=head1 HISTORY - -This functionality was added in OpenSSL 4.1. - -=head1 COPYRIGHT - -Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - -Licensed under the Apache License 2.0 (the "License"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file LICENSE in the source distribution or at -L. - -=cut diff --git a/doc/man7/EVP_KDF-PBKDF2.pod b/doc/man7/EVP_KDF-PBKDF2.pod index abe999bd36..79de97d713 100644 --- a/doc/man7/EVP_KDF-PBKDF2.pod +++ b/doc/man7/EVP_KDF-PBKDF2.pod @@ -40,10 +40,6 @@ This parameter has a default value of 2048. These parameters work as described in L. -B PBKDF2 uses HMAC internally, which does not support eXtendable Output -Function (XOF) digests such as SHAKE128 or SHAKE256. Attempting to use an XOF -digest with PBKDF2 will result in an error. - =item "pkcs5" (B) This parameter can be used to enable or disable SP800-132 compliance checks. @@ -118,7 +114,7 @@ This functionality was added in OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_KDF-SNMPKDF.pod b/doc/man7/EVP_KDF-SNMPKDF.pod index 9a2973722b..c0bcb70dee 100644 --- a/doc/man7/EVP_KDF-SNMPKDF.pod +++ b/doc/man7/EVP_KDF-SNMPKDF.pod @@ -29,9 +29,9 @@ The supported parameters are: =item "digest" (B) -=item "pass" (B) +=item "pass" (B) -These parameters work as described in L. +These parameters works as described in L. =item "eid" (B) @@ -70,7 +70,7 @@ This example derives an 8 byte IV using SHA1 with a 1K "key" and appropriate *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, SN_sha1, strlen(SN_sha1)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_PASSWORD, + *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_PASS, pass, sizeof(pass)); *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SNMPKDF_EID, eid, sizeof(eid)); @@ -100,7 +100,7 @@ This functionality was added in OpenSSL 4.0. =head1 COPYRIGHT -Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_KDF-SRTPKDF.pod b/doc/man7/EVP_KDF-SRTPKDF.pod deleted file mode 100644 index 92639d85ad..0000000000 --- a/doc/man7/EVP_KDF-SRTPKDF.pod +++ /dev/null @@ -1,198 +0,0 @@ -=pod - -=head1 NAME - -EVP_KDF-SRTPKDF - The SRTP EVP_KDF implementation - -=head1 DESCRIPTION - -Support for computing the B KDF through the B API. - -The EVP_KDF-SRTP algorithm implements the SRTP key derivation function. -SRTP follows the specification in RFC 3711 Section 4.3.3, where various -cryptographic keys (encryption, authentication, and salt keys) are derived -from a master key and master salt using AES encryption with specific labels. - -The output keys are used for SRTP and SRTCP packet protection. - -=head2 Identity - -"SRTP" is the name for this implementation; it can be used with the -EVP_KDF_fetch() function. - -=head2 Supported parameters - -The supported parameters are: - -=over 4 - -=item "properties" (B) - -=item "cipher" (B) - -This parameter sets the cipher to be used for the key derivation. -It must be set to one of "AES-128-CTR", "AES-192-CTR" or "AES-256-CTR". - -=item "key" (B) - -This parameter sets the master key value. This must be 16 bytes for AES-128, -24 bytes for AES-192 or 32 bytes for AES-256. - -=item "salt" (B) - -This parameter sets the master salt value. The must be at least 14 bytes. -Note that larger salts are truncated. - -=item "kdr" (B) - -This parameter sets the key derivation rate (KDR). The KDR controls -how often keys are rederived. If not set or set to zero, no key -rederivation is performed. The KDR value is power of 2 in the range 2^0 to 2^24. - -=item "index" (B) - -This parameter sets the index value used in key derivation. The length must be -at least 6 bytes for RTP packets, or at least 4 bytes for RTCP packets. -Note that larger index values are truncated. -If it is not set, or it has zero length, no key rederivation is performed. - -=item "label" (B) - -This parameter sets the label that identifies the type of key to derive. -Valid values are: - -=over 4 - -=item 0 - SRTP encryption key - -=item 1 - SRTP authentication key - -=item 2 - SRTP salt key - -=item 3 - SRTCP encryption key - -=item 4 - SRTCP authentication key - -=item 5 - SRTCP salt key - -=item 6 - SRTP encryption key (alternative) - -=item 7 - SRTP salt key (alternative) - -=back - -=back - -=head1 NOTES - -A context for SRTP can be obtained by calling: - - EVP_KDF *kdf = EVP_KDF_fetch(NULL, "SRTP", NULL); - EVP_KDF_CTX *kctx = EVP_KDF_CTX_new(kdf); - -The output length of the SRTP KDF derive operation is determined by the label: - -=over 4 - -=item Labels 0, 3, 6: Output length equals the cipher key length - -=item Labels 1, 4: Output length is 20 bytes (160 bits) - -=item Labels 2, 5, 7: Output length is 14 bytes (112 bits) - -=back - -=head1 EXAMPLES - -This example derives an SRTP encryption key (label 0) using AES-128-CTR -with a 16-byte master key and 14-byte master salt: - - EVP_KDF *kdf; - EVP_KDF_CTX *kctx; - unsigned char out[16]; - unsigned char master_key[16] = { /* master key bytes */ }; - unsigned char master_salt[14] = { /* master salt bytes */ }; - uint32_t label = 0; - OSSL_PARAM params[5], *p = params; - - kdf = EVP_KDF_fetch(NULL, "SRTP", NULL); - kctx = EVP_KDF_CTX_new(kdf); - EVP_KDF_free(kdf); - - *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_CIPHER, - "AES-128-CTR", 0); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, - master_key, sizeof(master_key)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT, - master_salt, sizeof(master_salt)); - *p++ = OSSL_PARAM_construct_uint32(OSSL_KDF_PARAM_SRTPKDF_LABEL, &label); - *p = OSSL_PARAM_construct_end(); - - if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) { - error("EVP_KDF_derive"); - } - - EVP_KDF_CTX_free(kctx); - -This example derives an SRTP authentication key (label 1) with key derivation -rate and index: - - EVP_KDF *kdf; - EVP_KDF_CTX *kctx; - unsigned char out[20]; - unsigned char master_key[16] = { /* master key bytes */ }; - unsigned char master_salt[14] = { /* master salt bytes */ }; - uint32_t kdr = 0x1000; /* KDR */ - unsigned char index[6] = { 0x00, 0x00, 0x00, 0x00, 0x00, 0x01 }; /* index */ - uint32_t label = 1; - OSSL_PARAM params[7], *p = params; - - kdf = EVP_KDF_fetch(NULL, "SRTP", NULL); - kctx = EVP_KDF_CTX_new(kdf); - EVP_KDF_free(kdf); - - *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_CIPHER, - "AES-128-CTR", 0); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_KEY, - master_key, sizeof(master_key)); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT, - master_salt, sizeof(master_salt)); - *p++ = OSSL_PARAM_construct_uint32(OSSL_KDF_PARAM_SRTPKDF_KDR, &kdr); - *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SRTPKDF_INDEX, - index, sizeof(index)); - *p++ = OSSL_PARAM_construct_uint32(OSSL_KDF_PARAM_SRTPKDF_LABEL, &label); - *p = OSSL_PARAM_construct_end(); - - if (EVP_KDF_derive(kctx, out, sizeof(out), params) <= 0) { - error("EVP_KDF_derive"); - } - - EVP_KDF_CTX_free(kctx); - -=head1 CONFORMING TO - -RFC 3711 Section 4.3.3 (SRTP Key Derivation) - -=head1 SEE ALSO - -L, -L, -L, -L, -L, -L - -=head1 HISTORY - -The SRTPKDF was added in OpenSSL 4.0.0. - -=head1 COPYRIGHT - -Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - -Licensed under the Apache License 2.0 (the "License"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file LICENSE in the source distribution or at -L. - -=cut diff --git a/doc/man7/EVP_KDF-X963.pod b/doc/man7/EVP_KDF-X963.pod index f767bf866a..2df67a728e 100644 --- a/doc/man7/EVP_KDF-X963.pod +++ b/doc/man7/EVP_KDF-X963.pod @@ -8,8 +8,7 @@ EVP_KDF-X963 - The X9.63-2001 EVP_KDF implementation The EVP_KDF-X963 algorithm implements the key derivation function (X963KDF). X963KDF is used by Cryptographic Message Syntax (CMS) for EC KeyAgreement, to -derive a key using input such as a shared secret key and shared info. It is -also used by SM2 encryption and decryption operations. +derive a key using input such as a shared secret key and shared info. The output is considered to be keying material. @@ -136,7 +135,7 @@ This functionality was added in OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_KEYEXCH-ECDH.pod b/doc/man7/EVP_KEYEXCH-ECDH.pod index 26b962a65f..280338ee92 100644 --- a/doc/man7/EVP_KEYEXCH-ECDH.pod +++ b/doc/man7/EVP_KEYEXCH-ECDH.pod @@ -8,25 +8,6 @@ EVP_KEYEXCH-ECDH - ECDH Key Exchange algorithm support Key exchange support for the B key type. -This algorithm supports B key agreement for general elliptic curves. -Specialised support for the B and B curves is documented in -L and L. - -As specified in L, when -B is the negotiated key agreement group in TLS, B shared secret -derivation is used instead of the normal key agreement protocol (KAP) specified -in the C standard for the B elliptic curve. -This B key agreement variant is also sometimes called C. -When a B key is generated or imported, the EC group name parameter to -specify remains C. -The resulting B key can only be used for C key -agreement. -C is TLS-specific, it should not be used in other protocols, -absent a specification of its use in the protocol in question. - -The B hybrid post-quantum key exchange algorithm -uses C for its C component. - =head2 ECDH Key Exchange parameters =over 4 @@ -140,13 +121,9 @@ L, L, L, -=head1 HISTORY - -Support for C via B was added in OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_MD-ML-DSA-MU.pod b/doc/man7/EVP_MD-ML-DSA-MU.pod deleted file mode 100644 index d9669af4d9..0000000000 --- a/doc/man7/EVP_MD-ML-DSA-MU.pod +++ /dev/null @@ -1,180 +0,0 @@ -=pod - -=head1 NAME - -EVP_MD-ML-DSA-MU - The ML-DSA-MU EVP_MD implementation - -=head1 DESCRIPTION - -Support for computing the value of external mu for ML-DSA using the B API. - -Normally the value of C is calculated internally as part of an ML-DSA -sign or verify operation. C is defined as: - mu = SHAKE256(tr || M', 64) - -Where B is the hash of the encoded public key, and, for Pure (ML-DSA): - M' = 0x00 || ctx_len || ctx || message - -In cases where prehashing the message is required, FIPS 204 allows -the C calculation to be done externally and then C can be passed to -ML-DSA sign or verify operations. - -PreHash (HASH-ML-DSA) is also supported and uses: - M' = 0x01 || ctx_len || ctx || OID || HashedMessage - -The output C value can then be supplied as an input to L -using the ML-DSA Signature Parameter B (i.e. C). -This allows larger messages to be hashed (or hidden) before they are passed to -pure ML-DSA sign or verify operations. - -=head2 Identities - -This implementation is available with the FIPS provider as well as the -default provider, and is identified with the name "ML-DSA-MU". - -=head2 Parameters - -This implementation supports the following settable L parameters: - -=over 4 - -=item "pub" (B) - -A B encoded public key value of size 1312, 1952 or 2592 bytes -depending on the respective key type of B, B or B. -This can be retrieved from a L key by calling -EVP_PKEY_get_octet_string_param(key, OSSL_PKEY_PARAM_PUB_KEY, pub, sizeof(pub), &publen) -This parameter MUST be set or an error will occur. - -=item "context-string" (B) - -An optional string of octets with length at most 255. By default it is the empty string. - -=item "digest" (B) - -An optional parameter related to "HASH-ML-DSA". If used it determines the OID in -the definition of PreHash M' above. - -When this parameter is not specified, pure ML-DSA C is computed, and the -input data is expected to be the full message, otherwise the input data must -be the result of prehashing the message with the corresponding digest algorithm. - -The HASH-ML-DSA variant is available to enable specialised use-cases, -in which signing the full message with pure ML-DSA is not practical, and -the external-mu API is a viable alternative. -HASH-ML-DSA is not used in protocols such as X509 & CMS (See RFC 9981 and 9982), -and is not presently implemented as an independent OpenSSL signature algorithm. - -It is the users responsibility to chose a digest that has the minimum required -security strength. To match the security category for B, B -and B the user should chose a digest that has a security strength of -at least 128 bits, 192 bits and 256 bits respectively. - -OpenSSL accepts the following digest names: - -=over 4 - -=item "SHA-224" and "SHA3-224" - -These digests have a security strength of 112 bits. - -=item "SHA-256" and "SHA3-256" - -These digests have a security strength of 128 bits. - -=item "SHA-384" and "SHA3-384" - -These digests have a security strength of 192 bits. - -=item "SHA-512" and "SHA3-512" - -These digests have a security strength of 256 bits. - -=item "SHAKE-128" and "SHAKE-256" - -For SHAKE-128 and SHAKE-256 the expected XOF digest -lengths are 32 and 64 respectively which correspond to a security strength of -128 and 256 bits respectively. - -=back - -The total size of the C passed to EVP_DigestUpdate() MUST match -the size of the digest. - -=item "properties" (B) - -Sets the properties to be queried when trying to fetch the underlying digest. - -=back - -=head2 Gettable Parameters - -This implementation supports the common gettable parameters described -in L. - -=head1 CONFORMING TO - -FIPS 204 and -https://csrc.nist.gov/csrc/media/Projects/post-quantum-cryptography/documents/faq/fips204-sec6-03192025.pdf - -=head1 EXAMPLES - -To generate external 'mu' given an existing ML-DSA key and a large message: - - calculate_mu(EVP_PKEY *pkey, const unsigned char *msg, size_t msglen, - const unsigned char *ctx, size_t ctxlen, unsigned char mu[64]) - { - unsigned char pub[2592]; - size_t publen = 0, chunk; - OSSL_PARAM params[4], *p = params; - - /* Retrieve the ML-DSA encoded public key */ - EVP_PKEY_get_octet_string_param(pkey, OSSL_PKEY_PARAM_PUB_KEY, - pub, sizeof(pub), &publen); - - *p++ = OSSL_PARAM_construct_octet_string(OSSL_DIGEST_PARAM_MU_PUB_KEY, pub, publen); - /* This is an optional parameter */ - if (ctx != NULL && ctxlen != 0) - *p++ = OSSL_PARAM_construct_octet_string(OSSL_DIGEST_PARAM_MU_CONTEXT_STRING, ctx, ctxlen); - /* - * Optionally we could also set the digest name for HASH-ML-DSA - * *p++ = OSSL_PARAM_construct_utf8_string(OSSL_DIGEST_PARAM_MU_DIGEST, "SHA-512", 0); - */ - *p = OSSL_PARAM_construct_end(); - - mdctx = EVP_MD_CTX_new(); - md = EVP_MD_fetch(libctx, "ML-DSA-MU", NULL); - EVP_DigestInit_ex2(mdctx, md, params); - /* Call EVP_DigestUpdate() multiple times to stream the message */ - while (msglen != 0) { - /* Account for the last chunk being less than 64 */ - chunk = (msglen >= 64) ? 64 : msglen; - EVP_DigestUpdate(mdctx, msg, chunk); - msg += chunk; - msglen -= chunk; - } - EVP_DigestFinalXOF(mdctx, mu, sizeof(mu)) - } - -=head1 SEE ALSO - -L, -L, -L, -L, -L - -=head1 HISTORY - -The B pseudo-digest was added in OpenSSL 4.0.0. - -=head1 COPYRIGHT - -Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - -Licensed under the Apache License 2.0 (the "License"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file LICENSE in the source distribution or at -L. - -=cut diff --git a/doc/man7/EVP_MD-SHA3.pod b/doc/man7/EVP_MD-SHA3.pod index 4ece848076..bc5c3508be 100644 --- a/doc/man7/EVP_MD-SHA3.pod +++ b/doc/man7/EVP_MD-SHA3.pod @@ -30,22 +30,13 @@ default provider, and includes the following varieties: This implementation supports the common gettable parameters described in L. -=head1 CONFORMING TO - -=over 4 - -=item FIPS 202 - -=back - =head1 SEE ALSO -L, L, L, -L +L, L, L =head1 COPYRIGHT -Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_MD-SHAKE.pod b/doc/man7/EVP_MD-SHAKE.pod index cc8d8a47cb..343349d92e 100644 --- a/doc/man7/EVP_MD-SHAKE.pod +++ b/doc/man7/EVP_MD-SHAKE.pod @@ -2,20 +2,17 @@ =head1 NAME -EVP_MD-SHAKE, EVP_MD-CSHAKE, EVP_MD-CSHAKE-KECCAK, +EVP_MD-SHAKE, EVP_MD-KECCAK-KMAC - The SHAKE / KECCAK family EVP_MD implementations =head1 DESCRIPTION -Support for computing SHAKE, CSHAKE or CSHAKE-KECCAK digests through the +Support for computing SHAKE or KECCAK-KMAC digests through the B API. -CSHAKE is an Extendable Output Function (XOF), that allows custom strings -"n" and "s". If these strings are both empty then it is identical to SHAKE, -otherwise it uses CSHAKE-KECCAK. - -CSHAKE-KECCAK is an Extendable Output Function (XOF), with a definition -similar to SHAKE but appends 2 extra zero bits. It is used internally by CSHAKE. +KECCAK-KMAC is an Extendable Output Function (XOF), with a definition +similar to SHAKE, used by the KMAC EVP_MAC implementation (see +L). =head2 Identities @@ -24,6 +21,20 @@ provider, and includes the following varieties: =over 4 +=item KECCAK-KMAC-128 + +Known names are "KECCAK-KMAC-128" and "KECCAK-KMAC128". This is used +by L. Using the notation from NIST FIPS 202 +(Section 6.2), we have S = S +(see the description of KMAC128 in Appendix A of NIST SP 800-185). + +=item KECCAK-KMAC-256 + +Known names are "KECCAK-KMAC-256" and "KECCAK-KMAC256". This is used +by L. Using the notation from NIST FIPS 202 +(Section 6.2), we have S = S +(see the description of KMAC256 in Appendix A of NIST SP 800-185). + =item SHAKE-128 Known names are "SHAKE-128" and "SHAKE128". @@ -32,28 +43,6 @@ Known names are "SHAKE-128" and "SHAKE128". Known names are "SHAKE-256" and "SHAKE256". -=item CSHAKE-128 - -Known names are "CSHAKE-128" and "CSHAKE128". - -=item CSHAKE-256 - -Known names are "CSHAKE-256" and "CSHAKE256". - -=item CSHAKE-KECCAK-128 - -Other known names are "KECCAK-KMAC-128" and "KECCAK-KMAC128". This is used -by L. Using the notation from NIST FIPS 202 -(Section 6.2), we have S = S -(see the description of KMAC128 in Appendix A of NIST SP 800-185). - -=item CSHAKE-KECCAK-256 - -Other known names are "KECCAK-KMAC-256" and "KECCAK-KMAC256". This is used -by L. Using the notation from NIST FIPS 202 -(Section 6.2), we have S = S -(see the description of KMAC256 in Appendix A of NIST SP 800-185). - =back =head2 Parameters @@ -70,62 +59,26 @@ The length of the "xoflen" parameter should not exceed that of a B. The SHAKE-128 and SHAKE-256 implementations do not have any default digest length. -The CSHAKE-128 and CSHAKE-256 implementations have default digest lengths of -32 and 64 bytes respectively (which correspond to security strengths of 128 and -256 bits respectively). - -For SHAKE this parameter must be set before calling either EVP_DigestFinal_ex() -or EVP_DigestFinal(), since these functions were not designed to handle -variable length output. If it is not set CSHAKE will use the default value. -It is recommended to either use EVP_DigestSqueeze() or +This parameter must be set before calling either EVP_DigestFinal_ex() or +EVP_DigestFinal(), since these functions were not designed to handle variable +length output. It is recommended to either use EVP_DigestSqueeze() or EVP_DigestFinalXOF() instead. =item "size" (B) An alias of "xoflen". -=item "function-name" (B) - -Sets the function name string used by CSHAKE that can be set to one of -"", "TupleHash", "ParallelHash" or "KMAC". The default value is "". - -=item "customization" (B) - -Sets a customisation string used by CSHAKE. -It is an optional value with a length of at most 512 bytes, and is -empty by default. - -=item "properties" (B) - -An optional property used internally by CSHAKE when fetching either -SHAKE or KECCAK algorithms. - =back See L for further information related to parameters =head1 NOTES -For SHAKE-128 and CSHAKE-128, to ensure the maximum security strength of -128 bits, the output length passed to EVP_DigestFinalXOF() should be at least 32. +For SHAKE-128, to ensure the maximum security strength of 128 bits, the output +length passed to EVP_DigestFinalXOF() should be at least 32. -For SHAKE-256 and CSHAKE-256, to ensure the maximum security strength of -256 bits, the output length passed to EVP_DigestFinalXOF() should be at least 64. - -The SHA3 specification allows bit strings to be used, but OpenSSL only allows -byte strings for inputs, and outputs. - -=head1 CONFORMING TO - -=over 4 - -=item FIPS 202 (SHA3 and SHAKE) - -=item SP800-185 Section 3 cSHAKE - -=item SP800-185 Section 4 KMAC - -=back +For SHAKE-256, to ensure the maximum security strength of 256 bits, the output +length passed to EVP_DigestFinalXOF() should be at least 64. =head1 SEE ALSO @@ -136,11 +89,9 @@ L, L, L Since OpenSSL 3.4 the SHAKE-128 and SHAKE-256 implementations have no default digest length. -CSHAKE-128 and CSHAKE-256 were added in OpenSSL 4.0 - =head1 COPYRIGHT -Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_MD-common.pod b/doc/man7/EVP_MD-common.pod index b5b7ae1494..5a6b5b94f7 100644 --- a/doc/man7/EVP_MD-common.pod +++ b/doc/man7/EVP_MD-common.pod @@ -30,48 +30,17 @@ This value can also be retrieved with L. =item "flags" (B) Diverse flags that describe exceptional behaviour for the digest. +These flags are described in L. The length of the "flags" parameter should equal that of an B. -Several flags can be or'd together. The available flags are: +=begin comment -=over 4 +The description of these flags should probably be moved. Also, +EVP_MD_FLAG_FIPS isn't relevant any more. -=item EVP_MD_FLAG_ONESHOT - -This digest method can only handle one block of input. - -=item EVP_MD_FLAG_XOF - -This digest method is an extensible-output function (XOF) and supports -the B control. - -=item EVP_MD_FLAG_DIGALGID_NULL - -When setting up a DigestAlgorithmIdentifier, this flag will have the -parameter set to NULL by default. Use this for PKCS#1. I - -=item EVP_MD_FLAG_DIGALGID_ABSENT - -When setting up a DigestAlgorithmIdentifier, this flag will have the -parameter be left absent by default. I - -=item EVP_MD_FLAG_DIGALGID_CUSTOM - -Custom DigestAlgorithmIdentifier handling via ctrl, with -B as default. I -Currently unused. - -=item EVP_MD_FLAG_FIPS - -This digest method is suitable for use in FIPS mode. -Currently unused. - -=back +=end comment This value can also be retrieved with L. diff --git a/doc/man7/EVP_PKEY-EC.pod b/doc/man7/EVP_PKEY-EC.pod index 714b5c3b60..25177aa2da 100644 --- a/doc/man7/EVP_PKEY-EC.pod +++ b/doc/man7/EVP_PKEY-EC.pod @@ -94,18 +94,6 @@ Sets or gets the point_conversion_form for the I. For a description of point_conversion_forms please see L. Valid values are "uncompressed" or "compressed". The default value is "uncompressed". -At key generation time the public point is emitted in uncompressed -form. Any B supplied via -B(3) or B<-pkeyopt point-format:EformE> -is validated -- an invalid value is rejected -- but is otherwise -ignored on the generated key. - -On EC parameter generation the B setting selects the -encoding of the group's generator. On an existing key the setting -is honoured normally, so imported keys retain their original form -through B(3), B(3), -B(3) and PEM/DER encoding and decoding. - =item "group-check" (B) Sets or Gets the type of group check done when EVP_PKEY_param_check() is called. @@ -173,15 +161,6 @@ The following Gettable types are also available for the built-in EC algorithm: =over 4 -=item "field-degree" (B) - -This is the bit length of the curve's field coefficients. -It coincides with the B parameter for binary -fields, and is otherwise (for prime fields) equal to the bit length of the -field's characteristic. -For most curves (e.g. C) this number is embedded in the curve's -name. - =item "basis-type" (B) Supports the values "tpBasis" for a trinomial or "ppBasis" for a pentanomial. @@ -215,8 +194,7 @@ OpenSSL FIPS provider's EC algorithm: =item "key-check" (B) -See L for descriptions -of additional parameters generally available across all algorithms. +See L for further information. =back @@ -251,13 +229,6 @@ For EC Keys, L and L conform to SP800-56Ar3 I and I respectively. -=head1 NOTES - -"qx" (B) and "qy" (B) -can be used for getting the EC public key affine coordinates. To set -them call EVP_EC_affine2oct() to convert affine coordinates to -an octet string and then use "pub" (B). - =head1 EXAMPLES An B context can be obtained by calling: @@ -329,13 +300,9 @@ L, L, L -=head1 HISTORY - -The B parameter was added in OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_PKEY-LMS.pod b/doc/man7/EVP_PKEY-LMS.pod index dd2619c26c..a51e9be436 100644 --- a/doc/man7/EVP_PKEY-LMS.pod +++ b/doc/man7/EVP_PKEY-LMS.pod @@ -27,16 +27,6 @@ is expected to be in XDR format. =back -The following parameters is gettable using EVP_PKEY_get_utf8_string_param(). - -=over 4 - -=item "mandatory-digest" (B) - -The empty string, signifying that no digest may be specified. - -=back - =head1 CONFORMING TO =over 4 @@ -101,12 +91,10 @@ L =head1 HISTORY This functionality was added in OpenSSL 3.6. -The gettable "mandatory-digest" and support for loading LMS public keys in -SubjectPublicKeyInfo format was added in OpenSSL 4.0. =head1 COPYRIGHT -Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_PKEY-ML-DSA.pod b/doc/man7/EVP_PKEY-ML-DSA.pod index 173c3ddf2f..11498c161f 100644 --- a/doc/man7/EVP_PKEY-ML-DSA.pod +++ b/doc/man7/EVP_PKEY-ML-DSA.pod @@ -96,11 +96,6 @@ respective key type of B, B or B. The encoded private key value of size 2560, 4032 or 4896 bytes depending on the respective key type of B, B or B. -=item "properties" (B) - -Can be used when importing raw keys using L, -to fetch internal digest algorithms. - =back =head2 Provider configuration parameters diff --git a/doc/man7/EVP_PKEY-ML-KEM.pod b/doc/man7/EVP_PKEY-ML-KEM.pod index 31f2f2f0a3..d8bc67022d 100644 --- a/doc/man7/EVP_PKEY-ML-KEM.pod +++ b/doc/man7/EVP_PKEY-ML-KEM.pod @@ -116,11 +116,6 @@ are empty. Once a public or private key component is set, no further changes are allowed. This parameter is gettable and settable (once only). -=item "properties" (B) - -Can be used when importing raw keys using L, -to fetch internal digest algorithms. - =back =head2 Provider configuration parameters diff --git a/doc/man7/EVP_PKEY-MLX-KEM.pod b/doc/man7/EVP_PKEY-MLX-KEM.pod deleted file mode 100644 index 12134056b0..0000000000 --- a/doc/man7/EVP_PKEY-MLX-KEM.pod +++ /dev/null @@ -1,221 +0,0 @@ -=pod - -=head1 NAME - -EVP_PKEY-MLX-KEM, EVP_KEYMGMT-MLX-KEM - Hybrid ML-KEM key support for TLS 1.3 - -=head1 DESCRIPTION - -These hybrid ML_KEM algorithms derive the session secret from both a -ECDH (classical) algorithm (such as X25519, or P-256) and a post-quantum -algorithm (ML_KEM), ensuring that key agreement remains secure unless both -schemes are broken. - -The algorithms supported here are specifically for use in TLS 1.3 and are not -suitable for other purposes. There is no encoder/decoder support, and -EVP_PKEY_CTX_new_id() is also not supported as there are no associated EVP_PKEY -type identifiers. - -The following names can be used by EVP_PKEY_CTX_new_from_name() using OpenSSL's -default and FIPS providers. - -=over 4 - -=item B - -The shared secret is the concatenation of a 32 byte L shared -secret followed by a 32 byte L shared secret. X25519 is not an -approved FIPS algorithm, but this combination is still allowed by FIPS 140-3 -since ML-KEM is FIPS approved. - -=item B - -Similar to B with a higher security strength, the shared secret -is the concatenation of a 32 byte L shared secret followed -by a 56 byte L shared secret. - -=item B - -The shared secret is the concatenation of a 32 byte L shared -secret followed by a 32 byte L shared secret. -Both algorithms used are FIPS approved. - -=item B - -Similar to B with a higher security strength, the shared -secret is the concatenation of a 48 byte L shared -secret followed by a 32 byte L shared secret. - -=back - -The following name is supported only in OpenSSL's default provider. - -=over 4 - -=item B - -The shared secret is the concatenation of a 32 byte L shared -secret followed by a 32 byte L shared secret. - -=back - -=head2 Keygen Parameters - -No mandatory parameters are required for generating a key pair. -To set the optional parameter, use L after calling -L. - -=over 4 - -=item "properties" (B) - -Sets properties to be used when fetching algorithm implementations used for -the B, B or B algorithms. - -=back - -=head2 Common parameters - -See L) -for common information related to parameters. - -The following common gettables can be retrieved using -L, they retrieve information related to the ML-KEM -algorithm. - -=over 4 - -=item 'bits' (B) - -=item "security-bits" (B) - -=item "security-category" (B) - -=item "max-size" (B) - -This value is the combined size of the 2 shared secrets as described above. - -=back - -The following parameters are also handled. - -=over 4 - -=item "encoded-pub-key" (B) - -Used for getting and setting the encoding of concatenated public keys. -The public keys can not be modified once they are set. - -The format of the public keys for the different algorithms is: - -=over 4 - -=item B - -A 65 byte EC public key followed by a 1184 byte ML-KEM-768 public key. - -=item B - -A 97 byte EC public key followed by a 1568 byte ML-KEM-1024 public key. - -=item B - -A 1184 byte ML-KEM-768 public key followed by a 32 byte X25519 public key. - -=item B - -A 1568 byte ML-KEM-1024 public key followed by a 56 byte X448 public key. - -=item B - -A 65 byte SM2 public key followed by a 1184 byte ML-KEM-768 public key. - -=back - -=item "pub" (B) - -The public key value. - -This parameter is only used when importing or exporting the public key value with -the EVP_PKEY_fromdata() and EVP_PKEY_todata() functions. -The public key format format is the same as "encoded-pub-key". - -=item "priv" (B) - -The private key value which is the concatenation of 2 internal private keys. - -This parameter can be used when importing or exporting the private key value -using the EVP_PKEY_fromdata() and EVP_PKEY_todata() functions. -Initial import aside, this parameter is otherwise only gettable. - -The format of the private keys for the different algorithms is: - -=over 4 - -=item B - -32 byte EC private key followed by a 2400 byte ML-KEM-768 private key. - -=item B - -48 byte EC private key followed by a 3168 byte ML-KEM-1024 private key. - -=item B - -2400 byte ML-KEM-768 private key followed by a 32 byte X25519 private key. - -=item B - -3168 byte ML-KEM-1024 private key followed by a 56 byte X448 private key. - -=item B - -32 byte SM2 private key followed by a 2400 byte ML-KEM-768 private key. - -=back - -=back - -=head1 CONFORMING TO - -=over 4 - -=item https://datatracker.ietf.org/doc/draft-ietf-tls-ecdhe-mlkem/ - -Note that B is not defined by this document. - -=item SP800-227 - -The general notation used in this document says that outputs are -combined/processed in order of the names. -B and B however use the reverse order since -X25519 and X448 are not FIPS approved algorithms. -Even though they are not FIPS approved the hybrid combination is still allowed -since MLKEM is FIPS approved. - -=back - -=head1 SEE ALSO - -L, -L, -L, -L, -L - -=head1 HISTORY - -This functionality was added in OpenSSL 3.5. - -Support for B was added in OpenSSL 4.0. - -=head1 COPYRIGHT - -Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - -Licensed under the Apache License 2.0 (the "License"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file LICENSE in the source distribution or at -L. - -=cut diff --git a/doc/man7/EVP_PKEY-SLH-DSA.pod b/doc/man7/EVP_PKEY-SLH-DSA.pod index 5406ceab62..0cb4f97d4d 100644 --- a/doc/man7/EVP_PKEY-SLH-DSA.pod +++ b/doc/man7/EVP_PKEY-SLH-DSA.pod @@ -13,18 +13,12 @@ EVP_PKEY-SLH-DSA-SHAKE-256s, EVP_PKEY-SLH-DSA-SHAKE-256f =head1 DESCRIPTION -SLH-DSA implements the algorithms B, B, -B, B, -B, B, -B, B, -B, B, -B and B. -The corresponding key types B, B, -B, B, -B, B, -B, B, -B, B, -B and B are +The B, B, +B, B, +B, B, +B, B, +B, B, +B and B key types are implemented in OpenSSL's default and FIPS providers. These implementations support the associated key, containing the public key I and the private key I. @@ -152,7 +146,7 @@ This functionality was added in OpenSSL 3.5. =head1 COPYRIGHT -Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_PKEY-SM2.pod b/doc/man7/EVP_PKEY-SM2.pod index 1a58043deb..28a0e995d5 100644 --- a/doc/man7/EVP_PKEY-SM2.pod +++ b/doc/man7/EVP_PKEY-SM2.pod @@ -7,33 +7,13 @@ EVP_PKEY-SM2, EVP_KEYMGMT-SM2, SM2 =head1 DESCRIPTION -The B algorithm was first defined by the Chinese national standard C and was later standardized by ISO as ISO/IEC 14888. -B is an elliptic curve-based algorithm. -Its implementation in OpenSSL supports both signature and encryption schemes -via the EVP interface. -Under the name C it also supports C as described in -L. +The B algorithm was first defined by the Chinese national standard GM/T +0003-2012 and was later standardized by ISO as ISO/IEC 14888. B is actually +an elliptic curve based algorithm. The current implementation in OpenSSL supports +both signature and encryption schemes via the EVP interface. -The B signature algorithm takes an optional I -parameter (B), which is used as part of a message -prefix before hashing with B. -As specified in L, -when B is used as part of the B TLS signature scheme, -this identifier must be set to the constant string C. -The OpenSSL TLS stack passes a protocol version parameter -(B) to the signature algorithm, which then -in the case of B internally sets the distinguishing identifier to the -expected constant. -When B is used for other purposes (e.g. in certificate signing or -verification), and no explicit value of the distinguishing identifier is -specified, a default value of C<1234567812345678> is used. - -An explicit empty distinguishing identifier value may need to be used to verify -or create signatures that are compatible with versions of OpenSSL prior to 4.0. -With the commandline tools an empty value can be specified with the use of -either the B<-pkeyopt> (L) or B<-sigopt> -(L) option with a value of C. +When doing the B signature algorithm, it requires a distinguishing identifier +to form the message prefix which is hashed before the real message is hashed. =head2 Common SM2 parameters @@ -105,16 +85,9 @@ L, L, L -=head1 HISTORY - -Support for the B TLS signature scheme was added in OpenSSL 4.0. - -The default value of the SM2 distinguishing identifier changed from empty to -C<1234567812345678> as of OpenSSL 4.0. - =head1 COPYRIGHT -Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_SIGNATURE-DSA.pod b/doc/man7/EVP_SIGNATURE-DSA.pod index d50e44f161..2c0f0073a4 100644 --- a/doc/man7/EVP_SIGNATURE-DSA.pod +++ b/doc/man7/EVP_SIGNATURE-DSA.pod @@ -3,7 +3,7 @@ =head1 NAME EVP_SIGNATURE-DSA -- The EVP_PKEY B signature implementation +- The B DSA signature implementation =head1 DESCRIPTION @@ -116,7 +116,7 @@ OpenSSL 3.4. See L for more information. =head1 COPYRIGHT -Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_SIGNATURE-ECDSA.pod b/doc/man7/EVP_SIGNATURE-ECDSA.pod index aa1d1a8f0d..bc75ed1408 100644 --- a/doc/man7/EVP_SIGNATURE-ECDSA.pod +++ b/doc/man7/EVP_SIGNATURE-ECDSA.pod @@ -2,7 +2,7 @@ =head1 NAME -EVP_SIGNATURE-ECDSA - The EVP_PKEY B signature implementation +EVP_SIGNATURE-ECDSA - The EVP_PKEY ECDSA signature implementation. =head1 DESCRIPTION @@ -104,7 +104,7 @@ L, =head1 COPYRIGHT -Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_SIGNATURE-ED25519.pod b/doc/man7/EVP_SIGNATURE-ED25519.pod index 745955e592..559968664e 100644 --- a/doc/man7/EVP_SIGNATURE-ED25519.pod +++ b/doc/man7/EVP_SIGNATURE-ED25519.pod @@ -6,7 +6,7 @@ EVP_SIGNATURE-ED25519, EVP_SIGNATURE-ED448, Ed25519, Ed448 -- The EVP_PKEY B and B signature implementations +- EVP_PKEY Ed25519 and Ed448 support =head1 DESCRIPTION @@ -175,7 +175,7 @@ L, =head1 COPYRIGHT -Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2017-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_SIGNATURE-HMAC.pod b/doc/man7/EVP_SIGNATURE-HMAC.pod index 50578aa94c..6628d9ebc2 100644 --- a/doc/man7/EVP_SIGNATURE-HMAC.pod +++ b/doc/man7/EVP_SIGNATURE-HMAC.pod @@ -4,7 +4,7 @@ EVP_SIGNATURE-HMAC, EVP_SIGNATURE-Siphash, EVP_SIGNATURE-Poly1305, EVP_SIGNATURE-CMAC -- The legacy EVP_PKEY B signature implementations +- The legacy B MAC signature implementations =head1 DESCRIPTION @@ -39,7 +39,7 @@ L, =head1 COPYRIGHT -Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2020 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_SIGNATURE-LMS.pod b/doc/man7/EVP_SIGNATURE-LMS.pod index f5c7548211..d6665a0b5d 100644 --- a/doc/man7/EVP_SIGNATURE-LMS.pod +++ b/doc/man7/EVP_SIGNATURE-LMS.pod @@ -3,7 +3,7 @@ =head1 NAME EVP_SIGNATURE-LMS -- The EVP_PKEY B signature implementation +- The EVP_PKEY Leighton-Micali Signature (LMS) implementation =head1 DESCRIPTION @@ -24,9 +24,6 @@ that specify the digest name are not necessary. LMS support is disabled by default at compile-time. To enable, specify the B build configuration option. -For backwards compatibility reasons EVP_DigestVerifyInit_ex() and -EVP_DigestVerify() may also be used, but the digest passed in I must be NULL. - LMS should only be used for older deployments. New deployments should use either L or . @@ -59,12 +56,10 @@ L, =head1 HISTORY This functionality was added in OpenSSL 3.6. -Support for EVP_DigestVerifyInit_ex() and EVP_DigestVerify() was added in -OpenSSL 4.0. =head1 COPYRIGHT -Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_SIGNATURE-ML-DSA.pod b/doc/man7/EVP_SIGNATURE-ML-DSA.pod index 963c484465..c9ccf1aafb 100644 --- a/doc/man7/EVP_SIGNATURE-ML-DSA.pod +++ b/doc/man7/EVP_SIGNATURE-ML-DSA.pod @@ -3,8 +3,8 @@ =head1 NAME EVP_SIGNATURE-ML-DSA, -EVP_SIGNATURE-ML-DSA-44, EVP_SIGNATURE-ML-DSA-65, EVP_SIGNATURE-ML-DSA-87 -- The EVP_PKEY B signature implementations +EVP_SIGNATURE-ML-DSA-44, EVP_SIGNATURE-ML-DSA-65, EVP_SIGNATURE-ML-DSA-87, +- EVP_SIGNATURE ML-DSA support =head1 DESCRIPTION @@ -67,25 +67,19 @@ If set the size must be 32 bytes. =item "deterministic" (B) The default value of 0 causes the per message randomness to be randomly -generated using a DRBG. Setting this to a nonzero value causes the per message -randomness to be set to 32 bytes of zeros. This value is ignored -if "test-entropy" is provided. +generated using a DRBG. Setting this to 1 causes the per message randomness +to be set to 32 bytes of zeros. This value is ignored if "test-entropy" is set. =item "mu" (B) The default value of 0 causes sign and verify operations to process a raw message. -Setting this to a nonzero value causes those operations to assume the input is -the C value from -L Algorithm 7 step 6 and Algorithm 8 step 7. +Setting this to 1 causes those operations to assume the input is the C value +from L Algorithm 7 step 6 and +Algorithm 8 step 7. Note that the message encoding steps from L Algorithm 2 step 10 and -Algorithm 3 step 5 are omitted when this setting is nonzero. - -See L for more information on generating an -external-mu value. - -The "context-string" is ignored if this value is nonzero. +Algorithm 3 step 5 are omitted when this setting is 1. =back @@ -101,17 +95,17 @@ passed in I must be NULL. To sign a message using an ML-DSA EVP_PKEY structure: - void do_sign(EVP_PKEY *key, const unsigned char *msg, size_t msg_len) + void do_sign(EVP_PKEY *key, unsigned char *msg, size_t msg_len) { size_t sig_len; unsigned char *sig = NULL; - OSSL_PARAM params[2]; + const OSSL_PARAM params[] = { + OSSL_PARAM_octet_string("context-string", (unsigned char *)"A context string", 16), + OSSL_PARAM_END + }; EVP_PKEY_CTX *sctx = EVP_PKEY_CTX_new_from_pkey(NULL, pkey, NULL); EVP_SIGNATURE *sig_alg = EVP_SIGNATURE_fetch(NULL, "ML-DSA-65", NULL); - /* The context string is an optional parameter */ - params[0] = OSSL_PARAM_construct_octet_string(OSSL_SIGNATURE_PARAM_CONTEXT_STRING, (unsigned char *)"A context string", 16), - params[1] = OSSL_PARAM_construct_end(); EVP_PKEY_sign_message_init(sctx, sig_alg, params); /* Calculate the required size for the signature by passing a NULL buffer. */ EVP_PKEY_sign(sctx, NULL, &sig_len, msg, msg_len); @@ -123,35 +117,9 @@ To sign a message using an ML-DSA EVP_PKEY structure: EVP_PKEY_CTX_free(sctx); } -To sign a message using an ML-DSA EVP_PKEY structure and an external mu: - - void do_sign(EVP_PKEY *key, const unsigned char mu[64]) - { - int use_mu_instead_of_msg = 1; - size_t sig_len; - unsigned char *sig = NULL; - OSSL_PARAM params[2]; - EVP_PKEY_CTX *sctx = EVP_PKEY_CTX_new_from_pkey(NULL, pkey, NULL); - EVP_SIGNATURE *sig_alg = EVP_SIGNATURE_fetch(NULL, "ML-DSA-65", NULL); - - params[0] = OSSL_PARAM_construct_int(OSSL_SIGNATURE_PARAM_MU, &use_mu_instead_of_msg); - params[1] = OSSL_PARAM_construct_end(); - - EVP_PKEY_sign_message_init(sctx, sig_alg, params); - /* Calculate the required size for the signature by passing a NULL buffer. */ - EVP_PKEY_sign(sctx, NULL, &sig_len, mu, 64); - sig = OPENSSL_malloc(sig_len); - EVP_PKEY_sign(sctx, sig, &sig_len, mu, 64); - ... - OPENSSL_free(sig); - EVP_SIGNATURE_free(sig_alg); - EVP_PKEY_CTX_free(sctx); - } - =head1 SEE ALSO -L, -L, +L L, L, L, @@ -163,7 +131,7 @@ This functionality was added in OpenSSL 3.5. =head1 COPYRIGHT -Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_SIGNATURE-RSA.pod b/doc/man7/EVP_SIGNATURE-RSA.pod index 7ec9eda5c1..5dc27ac283 100644 --- a/doc/man7/EVP_SIGNATURE-RSA.pod +++ b/doc/man7/EVP_SIGNATURE-RSA.pod @@ -3,7 +3,7 @@ =head1 NAME EVP_SIGNATURE-RSA -- The EVP_PKEY B signature implementation +- The EVP_PKEY RSA signature implementation =head1 DESCRIPTION @@ -192,7 +192,7 @@ L, =head1 COPYRIGHT -Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_SIGNATURE-SLH-DSA.pod b/doc/man7/EVP_SIGNATURE-SLH-DSA.pod index d4cb257400..c1699793ce 100644 --- a/doc/man7/EVP_SIGNATURE-SLH-DSA.pod +++ b/doc/man7/EVP_SIGNATURE-SLH-DSA.pod @@ -9,7 +9,7 @@ EVP_SIGNATURE-SLH-DSA-SHA2-256s, EVP_SIGNATURE-SLH-DSA-SHA2-256f, EVP_SIGNATURE-SLH-DSA-SHAKE-128s, EVP_SIGNATURE-SLH-DSA-SHAKE-128f, EVP_SIGNATURE-SLH-DSA-SHAKE-192s, EVP_SIGNATURE-SLH-DSA-SHAKE-192f, EVP_SIGNATURE-SLH-DSA-SHAKE-256s, EVP_SIGNATURE-SLH-DSA-SHAKE-256f -- The EVP_PKEY B signature implementations +- EVP_PKEY SLH-DSA support =head1 DESCRIPTION @@ -96,7 +96,7 @@ To sign a message using an SLH-DSA EVP_PKEY structure: size_t sig_len; unsigned char *sig = NULL; const OSSL_PARAM params[] = { - OSSL_PARAM_octet_string("context-string", (unsigned char *)"A context string", 16), + OSSL_PARAM_octet_string("context-string", (unsigned char *)"A context string", 33), OSSL_PARAM_END }; EVP_PKEY_CTX *sctx = EVP_PKEY_CTX_new_from_pkey(NULL, pkey, NULL); @@ -126,7 +126,7 @@ This functionality was added in OpenSSL 3.5. =head1 COPYRIGHT -Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/EVP_SIGNATURE-SM2.pod b/doc/man7/EVP_SIGNATURE-SM2.pod deleted file mode 100644 index 7395bc9944..0000000000 --- a/doc/man7/EVP_SIGNATURE-SM2.pod +++ /dev/null @@ -1,97 +0,0 @@ -=pod - -=head1 NAME - -EVP_SIGNATURE-SM2 - The EVP_PKEY SM2 signature implementation. - -=head1 DESCRIPTION - -Support for computing SM2 signatures. -See L for information related to SM2 keys. - -This signature algorithm can be explicitly fetched with -L, and implicitly fetched (through L) with L and -L. - -=head2 SM2 Signature Parameters - -The following signature parameters can be set using -L, L or -L. - -=over 4 - -=item "digest" (B) - -This defaults to the C digest if not explicitly specified. - -=item "digest-size" (B) - -This defaults to 32 bytes if not explicitly specified. -Digests of a different size are not supported with B. - -=item "distid" (B) - -The I defaults to C<1234567812345678> if not -explicitly specified. - -An explicit empty distinguishing identifier value may need to be used to verify -or create signatures that are compatible with versions of OpenSSL prior to 4.0. -With the commandline tools an empty value can be specified with the use of -either the B<-pkeyopt> (L) or B<-sigopt> -(L) option with a value of C. - -=item "tls-version" (B) - -The OpenSSL 4.0 or later TLS protocol engine passes this parameter to the -underlying signature algorithm when signing or verifying TLS -B messages. -When the protocol version is TLS 1.3 (0x0304), the SM2 signature algorithm will -use the RFC8998 I instead of the default value noted -above. - -=back - -The following signature parameters can be retrieved using -EVP_PKEY_CTX_get_params(). - -=over 4 - -=item "algorithm-id" (B) - -This returns the DER encoding of the B signature OID. - -=item "digest" (B) - -=item "digest-size" (B) - -=back - -=head1 SEE ALSO - -L, -L, -L, -L, -L, -L, - -=head1 HISTORY - -The default value of the SM2 distinguishing identifier changed from empty to -C<1234567812345678> as of OpenSSL 4.0. - -Support for the B parameter was added in -OpenSSL 4.0. - -=head1 COPYRIGHT - -Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. - -Licensed under the Apache License 2.0 (the "License"). You may not use -this file except in compliance with the License. You can obtain a copy -in the file LICENSE in the source distribution or at -L. - -=cut diff --git a/doc/man7/OSSL_PROVIDER-FIPS.pod b/doc/man7/OSSL_PROVIDER-FIPS.pod index c45788ddf9..b18140f554 100644 --- a/doc/man7/OSSL_PROVIDER-FIPS.pod +++ b/doc/man7/OSSL_PROVIDER-FIPS.pod @@ -69,13 +69,9 @@ The OpenSSL FIPS provider supports these operations and algorithms: =item SHAKE, see L -=item CSHAKE, see L +=item KECCAK-KMAC, see L -=item CSHAKE-KECCAK, see L - -It is used internally as a sub algorithm of CSHAKE. - -=item ML-DSA-MU, see L +KECCAK-KMAC is only used internally as a sub algorithm of KMAC. =back @@ -115,8 +111,6 @@ It is used internally as a sub algorithm of CSHAKE. =item HKDF-SHA512, see L -=item IKEV2KDF, see L - =item TLS13-KDF, see L =item SSKDF, see L @@ -125,8 +119,6 @@ It is used internally as a sub algorithm of CSHAKE. =item SNMPKDF, see L -=item SRTPKDF, see L - =item SSHKDF, see L =item TLS1-PRF, see L @@ -153,19 +145,7 @@ It is used internally as a sub algorithm of CSHAKE. =item X448, see L -=item ML-KEM-512, see L - -=item ML-KEM-768, see L - -=item ML-KEM-1024, see L - -=item X25519MLKEM768, see L - -=item X448MLKEM1024, see L - -=item SecP256r1MLKEM768, see L - -=item SecP384r1MLKEM1024, see L +=item ML-KEM, see L =item TLS1-PRF @@ -269,20 +249,6 @@ included in SP 800-56Arev3 are not approved for key agreement". =item ML-DSA-87, see L -=item MK-KEM-512, see L - -=item MK-KEM-768, see L - -=item MK-KEM-1024, see L - -=item X25519MLKEM768, see L - -=item X448MLKEM1024, see L - -=item SecP256r1MLKEM768, see L - -=item SecP384r1MLKEM1024, see L - =item SLH-DSA-SHA2-128s, see L =item SLH-DSA-SHA2-128f, see L @@ -355,11 +321,10 @@ Uses HMAC SHA256 on the module file to validate that the module has not been modified. The integrity value is compared to a value written to a configuration file during installation. -=item "KAT_Mac" (B) +=item "KAT_Integrity" (B) Used during the Module Integrity test to perform a known answer test on -HMAC SHA256 prior to using it. In pre-4.0 versions -B ("KAT_Integrity") was used for this. +HMAC SHA256 prior to using it. =item "KAT_Cipher" (B) @@ -508,8 +473,6 @@ Key agreement tests used with the "KAT_KA" type. =item "HKDF" (B) -=item "IKEV2KDF" (B) - =item "TLS13_KDF_EXTRACT" (B) =item "TLS13_KDF_EXPAND" (B) @@ -524,8 +487,6 @@ Key agreement tests used with the "KAT_KA" type. =item "SNMPKDF" (B) -=item "SRTPKDF" (B) - =item "SSHKDF" (B) =item "TLS12_PRF" (B) @@ -645,13 +606,11 @@ L The HKDF-SHA256, HKDF-SHA384 and HKDF-SHA512 algorithms were added in OpenSSL 3.6. -The CSHAKE-128 and CSHAKE-256 algorithms were added in OpenSSL 4.0. - All other functionality was added in OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/OSSL_PROVIDER-base.pod b/doc/man7/OSSL_PROVIDER-base.pod index ca1744f97b..fdc7d0e54e 100644 --- a/doc/man7/OSSL_PROVIDER-base.pod +++ b/doc/man7/OSSL_PROVIDER-base.pod @@ -132,10 +132,6 @@ are also available in the default provider. =item SLH-DSA-SHAKE-256f -=item LMS - -Private keys are not supported for LMS. - =back In addition to this provider, all of these encoding algorithms are also @@ -206,10 +202,6 @@ combination with the FIPS provider. =item SLH-DSA-SHAKE-256f -=item LMS - -Private keys are not supported for LMS. - =back In addition to this provider, all of these decoding algorithms are also @@ -238,14 +230,11 @@ L, L This functionality was added in OpenSSL 3.0. -Support for B and B was added in OpenSSL 3.5. - -Support for B Public Key (SubjectPublicKeyInfo) encoders and decoders -was added in OpenSSL 4.0. +Support for B and was added in OpenSSL 3.5. =head1 COPYRIGHT -Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/OSSL_PROVIDER-default.pod b/doc/man7/OSSL_PROVIDER-default.pod index e61d3d8137..f0743d99d7 100644 --- a/doc/man7/OSSL_PROVIDER-default.pod +++ b/doc/man7/OSSL_PROVIDER-default.pod @@ -59,12 +59,10 @@ The OpenSSL default provider supports these operations and algorithms: =item KECCAK, see L +=item KECCAK-KMAC, see L + =item SHAKE, see L -=item CSHAKE, see L - -=item CSHAKE-KECCAK, see L - =item BLAKE2, see L =item SM3, see L @@ -77,8 +75,6 @@ The OpenSSL default provider supports these operations and algorithms: =item NULL, see L -=item ML-DSA-MU, see L - =back =head2 Symmetric Ciphers @@ -135,8 +131,6 @@ The OpenSSL default provider supports these operations and algorithms: =item HKDF-SHA512, see L -=item IKEV2KDF, see L - =item TLS13-KDF, see L =item SSKDF, see L @@ -147,8 +141,6 @@ The OpenSSL default provider supports these operations and algorithms: =item SNMPKDF, see L -=item SRTPKDF, see L - =item SSHKDF, see L =item TLS1-PRF, see L @@ -189,16 +181,6 @@ The OpenSSL default provider supports these operations and algorithms: =item ML-KEM-1024, see L -=item X25519MLKEM768, see L - -=item X448MLKEM1024, see L - -=item SecP256r1MLKEM768, see L - -=item SecP384r1MLKEM1024, see L - -=item curveSM2MLKEM768, see L - =item TLS1-PRF =item HKDF @@ -333,16 +315,6 @@ The OpenSSL default provider supports these operations and algorithms: =item MK-KEM-1024, see L -=item X25519MLKEM768, see L - -=item X448MLKEM1024, see L - -=item SecP256r1MLKEM768, see L - -=item SecP384r1MLKEM1024, see L - -=item curveSM2MLKEM768, see L - =item SLH-DSA-SHA2-128s, see L =item SLH-DSA-SHA2-128f, see L @@ -466,10 +438,6 @@ are also available in the base provider. =item SLH-DSA-SHAKE-256f -=item LMS - -Private keys are not supported for LMS. - =back In addition to this provider, all of these encoding algorithms are also @@ -538,10 +506,6 @@ combination with the FIPS provider. =item SLH-DSA-SHAKE-256f -=item LMS - -Private keys are not supported for LMS. - =back In addition to this provider, all of these decoding algorithms are also @@ -568,25 +532,15 @@ L =head1 HISTORY -Base functionality was added in OpenSSL 3.0. - The RIPEMD160 digest was added to the default provider in OpenSSL 3.0.7. -Support for B, B, B and -B was added in OpenSSL 3.5. - The HKDF-SHA256, HKDF-SHA384 and HKDF-SHA512 algorithms were added in OpenSSL 3.6. -Support for B Public Key (SubjectPublicKeyInfo) encoders and decoders -was added in OpenSSL 4.0. - -Support for B was added in OpenSSL 4.0. - -Support for CSHAKE-128 and CSHAKE-256 was added in OpenSSL 4.0. +All other functionality was added in OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/fips_module.pod b/doc/man7/fips_module.pod index 824bbedcde..d42acaba45 100644 --- a/doc/man7/fips_module.pod +++ b/doc/man7/fips_module.pod @@ -18,19 +18,7 @@ For information related to installing the FIPS module see L. Note that the old functions FIPS_mode() and FIPS_mode_set() are no longer -present so you should remove them from your application if you use them. A -convenience define FIPS_mode() to EVP_default_properties_is_fips_enabled(NULL) -is provided in the openssl/evp.h header. This is a hint of intent, but not -proof. If you are looking to validate whether the default configuration is using -a validated module, many additional checks are needed; please consult the -security policy of the module you are using. Most applications should load the -default library context and use it as is, without ever using FIPS_mode() or -checking EVP_default_properties_is_fips_enabled(). This enables your -application to work unmodified with all the different types of cryptographic -providers available to OpenSSL. There are many alternative third-party providers -that implement FIPS cryptography. For example, the wolfCrypt and SymCrypt -providers can be used with OpenSSL at run time to also provide FIPS -cryptography. +present so you must remove them from your application if you use them. Applications written to use the OpenSSL 3.0 FIPS module should not use any legacy APIs or features that avoid the FIPS module. Specifically this includes: @@ -44,7 +32,8 @@ Low level cryptographic APIs (use the high level APIs, such as EVP, instead) =item * Any functions that create or modify custom "METHODS" (for example -RSA_meth_new(), EC_KEY_METHOD_new(), etc.) +EVP_MD_meth_new(), EVP_CIPHER_meth_new(), EVP_PKEY_meth_new(), RSA_meth_new(), +EC_KEY_METHOD_new(), etc.) =back diff --git a/doc/man7/openssl-core_dispatch.h.pod b/doc/man7/openssl-core_dispatch.h.pod index 7f99fe2a81..a19e1331fa 100644 --- a/doc/man7/openssl-core_dispatch.h.pod +++ b/doc/man7/openssl-core_dispatch.h.pod @@ -24,7 +24,7 @@ are named as follows: These macros have the form C>. -=item dispatch numbers +=item dipatch numbers These macros have the form C_I>, where C> is the same as in the macro for the operation this diff --git a/doc/man7/openssl-env.pod b/doc/man7/openssl-env.pod index 27debe8ae2..0fe4661994 100644 --- a/doc/man7/openssl-env.pod +++ b/doc/man7/openssl-env.pod @@ -130,13 +130,6 @@ This output usually makes sense only if you know OpenSSL internals well. The value of this environment variable is a comma-separated list of names, with the following available: -=item B - -This environment variable is used to flag the fact that unit tests are being run -(i.e. `make test`). It is used to detect when the OpenSSL should behave in a special -manner during unit tests (i.e. when unit tests are being run on fuzzing builds). It should -generally not be set by users. - =over 4 =item B @@ -283,8 +276,6 @@ This variable is considered a security-sensitive environment variable. =item B, B Specify the default directory or file containing CA certificates. -B can contain multiple directories separated by colons -(or semicolons on Windows). See L. These variables are considered security-sensitive environment variables, @@ -332,7 +323,7 @@ directory from which dynamic engines were loaded. =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/openssl-quic.pod b/doc/man7/openssl-quic.pod index 041bb5804d..75ca85d7ed 100644 --- a/doc/man7/openssl-quic.pod +++ b/doc/man7/openssl-quic.pod @@ -899,20 +899,6 @@ that a call to L is performed after the specified timeout =back -=head1 WINDOWS APPLICATION NOTES - -QUIC protocol uses UDP sockets. The recvfrom() function on Windows may fail -with C error causing OpenSSL QUIC stack to enter permanent -error, which prevents further communication over QUIC protocol. Applications -should disable SIO_UDP_CONNRESET and SIO_UDP_NETRESET error notification -on UDP sockets they pass to OpenSSL QUIC stack. More details can be found here: -https://learn.microsoft.com/en-us/windows/win32/winsock/winsock-ioctls#sio_udp_connreset-opcode-setting-i-t3 - -OpenSSL attempts to always disable SIO_UDP_CONNRESET and SIO_UDP_NETRESET -on UDP sockets it receives from application, but no error is reported back -if the respective C calls fail. Robust application should set those -options itself so it can handle error notifications from C properly. - =head1 SEE ALSO L, L, @@ -932,7 +918,7 @@ L, L =head1 COPYRIGHT -Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/openssl-threads.pod b/doc/man7/openssl-threads.pod index bf2b2fb553..7f29a327ac 100644 --- a/doc/man7/openssl-threads.pod +++ b/doc/man7/openssl-threads.pod @@ -84,14 +84,6 @@ In this specific case, and probably for factory methods in general, it is not safe to modify the factory object after it has been used to create other objects. -An B connection object created by L should only be used -by a single thread at a time. -While it is possible for one thread to use an B object and then pass -it to another thread, the application must ensure that no two threads -are using the same B object concurrently. -Each thread handling TLS connections in parallel should create its own -B object from the shared B. - =head1 SEE ALSO CRYPTO_THREAD_run_once(3), diff --git a/doc/man7/openssl_user_macros.pod.in b/doc/man7/openssl_user_macros.pod.in index b579a03af0..829fe69aeb 100644 --- a/doc/man7/openssl_user_macros.pod.in +++ b/doc/man7/openssl_user_macros.pod.in @@ -88,17 +88,6 @@ versions up to and including the version given by B (or the default value given above, when B isn't defined) will be hidden. -=item B - -ENGINE API, as defined in openssl/engine.h, was permanently removed in OpenSSL 4.0. - -The user application can use the define B to enable stub macros -for API ENGINE functions. It should temporarily help the easy transition of applications -without source code modifications. - -Note that all stub macros emulate API function failures; they will not restore -the removed API even if the B define is used. - =back =head1 COPYRIGHT diff --git a/doc/man7/ossl-guide-migration.pod b/doc/man7/ossl-guide-migration.pod index bf5c57d617..ad2d530884 100644 --- a/doc/man7/ossl-guide-migration.pod +++ b/doc/man7/ossl-guide-migration.pod @@ -2,7 +2,7 @@ =head1 NAME -ossl-guide-migration, migration_guide, ossl-migration-guide +ossl-guide-migration, migration_guide - OpenSSL Guide: Migrating from older OpenSSL versions =head1 SYNOPSIS @@ -11,39 +11,12 @@ See the individual manual pages for details. =head1 DESCRIPTION -This guide details the changes required to migrate to new versions of OpenSSL, -covering OpenSSL 3.0 and later versions. -For earlier versions, refer to +This guide details the changes required to migrate to new versions of OpenSSL. +Currently this covers OpenSSL 3.0 & 3.1. For earlier versions refer to L. -For an overview of some of the key concepts introduced since OpenSSL 3.0, see +For an overview of some of the key concepts introduced in OpenSSL 3.0 see L. -=head1 OPENSSL 4.1 - -=head2 Main Changes from OpenSSL 4.0 - -=head3 Deprecation of EVP_CIPHER_CTX_get_num() and EVP_CIPHER_CTX_set_num() - -These functions have been deprecated in OpenSSL 4.1 since they were primarily -used by engines, which were removed in OpenSSL 4.0. -OpenSSL Provider algorithms maintain their state internally and should not -expose this information. If required the state should be set and get -via an OSSL_PARAM, bearing in mind that the bounds must be checked if setting -this value. - -=head3 Deprecation of ASN1_BIT_STRING_set() - -This function was deprecated in OpenSSL 4.1 in favour of -ASN1_BIT_STRING_set1(). The new functions in addition to what -ASN1_BIT_STRING_set() does, validates the function arguments and sets -unused bits after setting the BIT STRING value. - -=head3 Deprecation of EVP_KDF_CTX_kdf() - -This function is deprecated in favour of EVP_KDF_CTX_get0_ctx(), to align -with the naming of functions that provide similar functionality for other kinds -of EVP context oobjects. - =head1 OPENSSL 4.0 =head2 Main Changes from OpenSSL 3.6 @@ -64,216 +37,11 @@ features available in OpenSSL 4.0. Some functions have been removed that were deprecated in previous versions of OpenSSL. See L. -The ASN1_STRING type has been made opaque. Accessors for the needed -values from this type have been present since OpenSSL 1.1, Code -which directly attempts to access internals of ASN1_STRING should be -converted to use the accessors. The ASN1_FLAGS have also been made -private, most of which were purely internal. ASN1_STRING_FLAG_BITS_LEFT, -which used to be exposed to allow manipulating the internal representation -of a bit string should be replaced by using the appropriate setter for -an ASN1_BIT_STRING type, instead of direct flag and structure manipulation. - -=head2 Upgrading from OpenSSL 3.x - -=head3 The B type is now opaque - -B is the basis for many types in OpenSSL. Since OpenSSL 1.1.1 -accessor functions have been available to access and create B -values of various types. See L, -L, L and L. - -If your code uses direct access to B structure members you will -need to convert it to allocate the correct type B, and use accessors. - -If your code has in the past used an B as a stack allocated -object, you will need to allocate it from the heap with -L or L. - -The flags member of B has become inaccessible, and the definitions -of the flags are no longer public. This includes the public definition -of the flags: - -=over 4 - -=item B - -=item B - -=item B - -=item B - -=item B - -=back - -For the first four values, these were internal use flags which were never -user settable in a way that would not cause things to break. - -The final flag was used to indicate that an B has a -value of unused bits left - Most applications do not touch this. You -should not use ASN1_STRING_set() to set the value of an -B that may have unused bits on the end. To ensure -the number of unused bits is correctly set in an B -type, use the functions L or -L to set the value of an B, and -ensure that the number of unused bits is correctly set. The function -L may be used to retrieve the length in -bytes, and the number of unused bits of an B. - -=head3 Constification of B functions - -A large number of public API functions that access an B * object have -been constified. This change has been made to allow for future improvements -to the B layer to reduce the number of memory allocations and copies -that are made. These changes can impact code which uses these functions if -a returned pointer value which was not const in previous versions of OpenSSL -has now been made const. When such a value is assigned to a non-const pointer -variable you will get a compiler warning. - -The returned values being const is an indication that you may not mutate these -values safely. - -Typically, you will need to change any variables holding these values -to be const. If for some reason you need to mutate the returned object, you should -make a copy of the returned const object into a mutable non-const object, -bearing in mind that your copy has no effect on the original B object itself. - -The following functions have had arguments / return values related to B -constified. For full details see their relevant manual pages. - -NAME_CONSTRAINTS_check, -NAME_CONSTRAINTS_check_CN, -L, -L, -X509_alias_get0, -L, -X509_chain_check_suiteb, -L, -L, -L, -L, -L, -L, -L, -X509_check_trust, -L, -X509_find_by_issuer_and_serial, -X509_find_by_subject, -L, -L, -L, -L, -L, -L, -L, -X509_get_pubkey_parameters, -L, -L, -L, -L, -L, -X509_get0_reject_objects, -L, -X509_get0_trust_objects, -X509_get1_email, -X509_get1_ocsp, -X509_issuer_and_serial_hash, -L, -X509_issuer_name_hash_old, -X509_keyid_get0, -L, -X509_print_ex_fp, -X509_print_fp, -X509_REQ_get1_email, -X509_REQ_to_X509, -L, -L, -L, -L, -X509_subject_name_hash_old, -X509_to_X509_REQ, -X509_TRUST_add, -X509v3_addr_validate_resource_set, -X509v3_asid_validate_resource_set - -The following two functions we "un-constified" As they were documented as returning -an explicitly mutable pointer from within an B object: - -=over 4 - -=item L - -=item L - -=back - -=head3 Removal of atexit() usage - -libcrypto no longer arms OPENSSL_cleanup() function as atexit(3) handler. -Memory leak detectors may report there is allocated, but still reachable, -allocated memory at application exit. If clean report is desired, then -application must call OPENSSL_cleanup() explicitly before main() returns. - -=head3 Removal of fixed (D)TLS version method functions - -SSLv3_method(), SSLv3_server_method(), SSLv3_client_method(), -TLSv1_method(), TLSv1_server_method(), TLSv1_client_method(), -TLSv1_1_method(), TLSv1_1_server_method(), TLSv1_1_client_method(), -TLSv1_2_method(), TLSv1_2_server_method(), TLSv1_2_client_method(), -DTLSv1_method(), DTLSv1_server_method(), DTLSv1_client_method(), -DTLSv1_2_method(), DTLSv1_2_server_method() and DTLSv1_2_client_method() -were deprecated in the OpenSSL 1.1.0 release. - -Migrating applications should use -DTLS_method(), DTLS_server_method(), DTLS_client_method(), -TLS_method(), TLS_server_method(), TLS_client_method(), -instead and set the version with the SSL_CTX_set_min_proto_version() and/or -SSL_CTX_set_max_proto_version() API's. - -=head3 Deprecation of EVP_MD_CTX_get0_md_data() - -The function EVP_MD_CTX_get0_md_data() has been deprecated in 4.0. This function -is only useful in previous versions to obtain the data stored in an -B by a custom EVP_MD implementation. However, the ability to create -custom EVP_MD implementations has been removed in OpenSSL 4.0, so this function -is no longer useful. It always returns NULL, so should simply be removed from -applications that call it. Applications wishing to use a custom digest -implementation should instead use the provider API. - -=head3 Deprecation of ASN1_OBJECT_new() - -The function ASN1_OBJECT_new() has been deprecated in 4.0. The function is only -useful internally because the type is opaque and there exist no setter functions. -Hence, there never was a real use case for the function and calls to it can -simply be removed. - -=head3 Practical behaviour change of EVP_get_cipherby* and EVP_get_digestby* functions - -Before 4.0 functions B and B were often -used as fallback for EVP_CIPHER_fetch() and EVP_MD_fetch() implying the -possibility to access an algorithm implementation provided by an engine. In -case when an engine-provided algorithm was not available, these functions on -success return the implementation from the default OpenSSL library context with -default properties. Version 4.0 doesn't support engines, so, on success, these -functions always return the implementation from the default OpenSSL library -context with default properties. This is probably not the desired result for -applications that use a nondefault library context. - -The other difference between B/B and -EVP_CIPHER_fetch()/EVP_MD_fetch() is that the former functions deal with -algorithm aliases algorithm aliases added via OBJ_NAME_add(), and the newer -ones don't (except the ones declared in a specific provider as explicit -aliases). Applications wishing to preserve alias handling behaviour can first -check for an alias using B (with B -or B) and fall back to EVP_CIPHER_fetch() or -EVP_MD_fetch() if no match is found. - =head1 OPENSSL 3.6 =head2 Main Changes from OpenSSL 3.5 -The functions EVP_PKEY_asn1_*() and EVP_PKEY_get0_asn1() were deprecated in +The functions EVP_PKEY_asn1_*() and L were deprecated in favour of the provider API. EVP_PKEY_assign_[DSA|SIPHASH]() were also deprecated. Please use the new high level and provider API. @@ -392,8 +160,8 @@ more information about providers. The refactoring to support Providers conflicts internally with the APIs used to support engines, including the ENGINE API and any function that creates or -modifies custom "METHODS" (for example EVP_MD_meth_new(), -EVP_CIPHER_meth_new(), EVP_PKEY_meth_new(), L, +modifies custom "METHODS" (for example L, +L, L, L, L, etc.). These functions are being deprecated in OpenSSL 3.0, and users of these APIs should know that their use can likely bypass provider selection and configuration, with unintended consequences. @@ -649,9 +417,7 @@ implemented by EVP_RAND and EVP_RAND_CTX. These functions are legacy APIs that are not applicable to the new provider model. Applications should instead use L and -L. A convenience define from FIPS_mode() -to L is provided in the - header. +L. =head4 Key generation is slower @@ -2777,7 +2543,7 @@ The migration guide was created for OpenSSL 3.0. =head1 COPYRIGHT -Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/ossl-guide-quic-client-block.pod b/doc/man7/ossl-guide-quic-client-block.pod index 9d5bc62da5..394580b2de 100644 --- a/doc/man7/ossl-guide-quic-client-block.pod +++ b/doc/man7/ossl-guide-quic-client-block.pod @@ -16,7 +16,7 @@ ossl-guide-quic-client-block This page will present various source code samples demonstrating how to write a simple blocking QUIC client application which connects to a server, sends an -HTTP/1.1 request to it, and reads back the response. Note that HTTP/1.1 over +HTTP/1.0 request to it, and reads back the response. Note that HTTP/1.0 over QUIC is non-standard and will not be supported by real world servers. This is for demonstration purposes only. @@ -205,7 +205,7 @@ simple client that we developed in L did not use it. However QUIC mandates that the TLS handshake used in establishing a QUIC connection must use ALPN. - unsigned char alpn[] = { 8, 'h', 't', 't', 'p', '/', '1', '.', '1' }; + unsigned char alpn[] = { 8, 'h', 't', 't', 'p', '/', '1', '.', '0' }; /* SSL_set_alpn_protos returns 0 for success! */ if (SSL_set_alpn_protos(ssl, alpn, sizeof(alpn)) != 0) { @@ -215,7 +215,7 @@ connection must use ALPN. The ALPN is specified using a length prefixed array of unsigned chars (it is not a NUL terminated string). Our original TLS blocking client demo was using -HTTP/1.1. We will use the same for this example. Unlike most OpenSSL functions +HTTP/1.0. We will use the same for this example. Unlike most OpenSSL functions L returns zero for success and nonzero for failure. =head2 Setting the peer address diff --git a/doc/man7/ossl-guide-quic-client-non-block.pod b/doc/man7/ossl-guide-quic-client-non-block.pod index c7f66079d7..06a13e36b6 100644 --- a/doc/man7/ossl-guide-quic-client-non-block.pod +++ b/doc/man7/ossl-guide-quic-client-non-block.pod @@ -173,7 +173,7 @@ stream but no data has not yet arrived from the peer for that stream). L and L will return 0 to indicate an error and L and L will return 0 or a negative value to indicate -an error. L will return a negative value to indicate an error. +an error. L will return a negative value to incidate an error. In the event of an error an application should call L to find out what type of error has occurred. If the error is non-fatal and can be diff --git a/doc/man7/ossl-guide-quic-multi-stream.pod b/doc/man7/ossl-guide-quic-multi-stream.pod index f2b8084bd5..1493d1c2b2 100644 --- a/doc/man7/ossl-guide-quic-multi-stream.pod +++ b/doc/man7/ossl-guide-quic-multi-stream.pod @@ -159,7 +159,7 @@ object it will return NULL. This section will present various source code samples demonstrating how to write a simple multi-stream QUIC client application which connects to a server, send -some HTTP/1.1 requests to it, and read back the responses. Note that HTTP/1.1 +some HTTP/1.0 requests to it, and read back the responses. Note that HTTP/1.0 over QUIC is non-standard and will not be supported by real world servers. This is for demonstration purposes only. @@ -349,7 +349,7 @@ arrived and is available for us to accept. In the event of an error it will return B. /* - * In our hypothetical HTTP/1.1 over QUIC protocol that we are using we + * In our hypothetical HTTP/1.0 over QUIC protocol that we are using we * assume that the server will respond with a server initiated stream * containing the data requested in our uni-directional stream. This doesn't * really make sense to do in a real protocol, but its just for diff --git a/doc/man7/ossl-guide-quic-server-block.pod b/doc/man7/ossl-guide-quic-server-block.pod index ec78a0ada8..d44c60613f 100644 --- a/doc/man7/ossl-guide-quic-server-block.pod +++ b/doc/man7/ossl-guide-quic-server-block.pod @@ -19,7 +19,7 @@ simple, non-concurrent, QUIC "echo" server application which accepts one client connection at a time, echoing input from the client back to the same client. Once the current client disconnects, the next client connection is accepted. -The server only accepts HTTP/1.1 requests, which is non-standard and will not +The server only accepts HTTP/1.0 requests, which is non-standard and will not be supported by real world servers. This is for demonstration purposes only. Both the accepting socket and client connections are "blocking". A more typical @@ -130,14 +130,14 @@ select an ALPN the server considers acceptable. /* Setup ALPN negotiation callback to decide which ALPN is accepted. */ SSL_CTX_set_alpn_select_cb(ctx, select_alpn, NULL); -In this case, we only accept "http/1.1" and "hq-interop". +In this case, we only accept "http/1.0" and "hq-interop". /* - * ALPN strings for TLS handshake. Only 'http/1.1' and 'hq-interop' + * ALPN strings for TLS handshake. Only 'http/1.0' and 'hq-interop' * are accepted. */ static const unsigned char alpn_ossltest[] = { - 8, 'h', 't', 't', 'p', '/', '1', '.', '1', + 8, 'h', 't', 't', 'p', '/', '1', '.', '0', 10, 'h', 'q', '-', 'i', 'n', 't', 'e', 'r', 'o', 'p', }; diff --git a/doc/man7/ossl-guide-quic-server-non-block.pod b/doc/man7/ossl-guide-quic-server-non-block.pod index 2a5cfaa603..d5f0b91dff 100644 --- a/doc/man7/ossl-guide-quic-server-non-block.pod +++ b/doc/man7/ossl-guide-quic-server-non-block.pod @@ -19,14 +19,14 @@ simple, non-concurrent, QUIC "echo" server application which accepts one client connection at a time, echoing input from the client back to the same client. Once the current client disconnects, the next client connection is accepted. -The server only accepts C and C ALPN's and doesn't actually +The server only accepts C and C ALPN's and doesn't actually implement HTTP but only does a simple echo. This is non-standard and will not be supported by real world servers. This is for demonstration purposes only. There are various methods to test this server: B and -B will send a basic HTTP/1.1 request, which the server +B will send a basic HTTP/1.0 request, which the server will echo back. You can also test this server by running -C and entering +C and entering text that will be echoed back by the server. Both the listening socket and connected socket are "nonblocking". However, @@ -140,14 +140,14 @@ select an ALPN the server considers acceptable. /* Setup ALPN negotiation callback to decide which ALPN is accepted. */ SSL_CTX_set_alpn_select_cb(ctx, select_alpn, NULL); -In this case, we only accept "http/1.1" and "hq-interop". +In this case, we only accept "http/1.0" and "hq-interop". /* - * ALPN strings for TLS handshake. Only 'http/1.1' and 'hq-interop' + * ALPN strings for TLS handshake. Only 'http/1.0' and 'hq-interop' * are accepted. */ static const unsigned char alpn_ossltest[] = { - 8, 'h', 't', 't', 'p', '/', '1', '.', '1', + 8, 'h', 't', 't', 'p', '/', '1', '.', '0', 10, 'h', 'q', '-', 'i', 'n', 't', 'e', 'r', 'o', 'p', }; diff --git a/doc/man7/ossl-guide-tls-client-block.pod b/doc/man7/ossl-guide-tls-client-block.pod index e508eb23ec..dc731e6685 100644 --- a/doc/man7/ossl-guide-tls-client-block.pod +++ b/doc/man7/ossl-guide-tls-client-block.pod @@ -15,7 +15,7 @@ ossl-guide-tls-client-block =head1 SIMPLE BLOCKING TLS CLIENT EXAMPLE This page will present various source code samples demonstrating how to write -a simple TLS client application which connects to a server, sends an HTTP/1.1 +a simple TLS client application which connects to a server, sends an HTTP/1.0 request to it, and reads back the response. We use a blocking socket for the purposes of this example. This means that @@ -353,7 +353,7 @@ chunks. First we write the start of the request. Secondly we write the hostname we are sending the request to. Finally we send the end of the request. size_t written; - const char *request_start = "GET / HTTP/1.1\r\nConnection: close\r\nHost: "; + const char *request_start = "GET / HTTP/1.0\r\nConnection: close\r\nHost: "; const char *request_end = "\r\n\r\n"; /* Write an HTTP GET request to the peer */ diff --git a/doc/man7/ossl-guide-tls-client-non-block.pod b/doc/man7/ossl-guide-tls-client-non-block.pod index a45086caf6..ee03f6624b 100644 --- a/doc/man7/ossl-guide-tls-client-non-block.pod +++ b/doc/man7/ossl-guide-tls-client-non-block.pod @@ -140,7 +140,7 @@ from the underlying socket but the data has not yet arrived from the peer). L and L will return 0 to indicate an error and L and L will return 0 or a negative value to indicate -an error. L will return a negative value to indicate an error. +an error. L will return a negative value to incidate an error. In the event of an error an application should call L to find out what type of error has occurred. If the error is non-fatal and can be diff --git a/doc/man7/ossl-guide-tls-introduction.pod b/doc/man7/ossl-guide-tls-introduction.pod index 4b69a9e642..5789524324 100644 --- a/doc/man7/ossl-guide-tls-introduction.pod +++ b/doc/man7/ossl-guide-tls-introduction.pod @@ -165,7 +165,7 @@ directly in B. For example if B is "/usr/local/ssl", then save it as "/usr/local/ssl/cert.pem". You can also use environment variables to override the default location that -OpenSSL will look for its trusted certificate store. Set the B +OpenSSL will look for its trusted certificate store. Set the B environment variable to give the directory where OpenSSL should looks for its certificates or the B environment variable to give the name of a single file containing all of the certificates. See L for diff --git a/doc/man7/ossl-guide-tls-server-block.pod b/doc/man7/ossl-guide-tls-server-block.pod index f445492282..44ca2d7d8b 100644 --- a/doc/man7/ossl-guide-tls-server-block.pod +++ b/doc/man7/ossl-guide-tls-server-block.pod @@ -170,7 +170,7 @@ key agreement, but the certificate exchange is avoided. Most servers, including this one, do not solicit client certificates. We therefore do not need a "trust store" and allow the handshake to complete even when the client does not present a certificate. Note: Even if a client did -present a trusted certificate, for it to be useful, the server application +present a trusted ceritificate, for it to be useful, the server application would still need custom code to use the verified identity to grant nondefault access to that particular client. Some servers grant access to all clients with certificates from a private CA, this then requires processing of diff --git a/doc/man7/ossl-removed-api.pod b/doc/man7/ossl-removed-api.pod index 324bf33c76..4e2e5660a3 100644 --- a/doc/man7/ossl-removed-api.pod +++ b/doc/man7/ossl-removed-api.pod @@ -3,147 +3,6 @@ =head1 NAME ASN1_STRING_data, -BIO_f_reliable, -DTLSv1_method, -DTLSv1_server_method, -DTLSv1_client_method, -DTLSv1_2_method, -DTLSv1_2_server_method, -DTLSv1_2_client_method, -ERR_get_state, -ERR_remove_state, -ERR_remove_thread_state, -EVP_CIPHER_meth_new, -EVP_CIPHER_meth_dup, -EVP_CIPHER_meth_free, -EVP_CIPHER_meth_set_iv_length, -EVP_CIPHER_meth_set_flags, -EVP_CIPHER_meth_set_impl_ctx_size, -EVP_CIPHER_meth_set_init, -EVP_CIPHER_meth_set_do_cipher, -EVP_CIPHER_meth_set_cleanup, -EVP_CIPHER_meth_set_set_asn1_params, -EVP_CIPHER_meth_set_get_asn1_params, -EVP_CIPHER_meth_set_ctrl, -EVP_CIPHER_meth_get_init, -EVP_CIPHER_meth_get_do_cipher, -EVP_CIPHER_meth_get_cleanup, -EVP_CIPHER_meth_get_set_asn1_params, -EVP_CIPHER_meth_get_get_asn1_params, -EVP_CIPHER_meth_get_ctrl, -EVP_MD_meth_new, -EVP_MD_meth_dup, -EVP_MD_meth_free, -EVP_MD_meth_set_input_blocksize, -EVP_MD_meth_set_result_size, -EVP_MD_meth_set_app_datasize, -EVP_MD_meth_set_flags, -EVP_MD_meth_set_init, -EVP_MD_meth_set_update, -EVP_MD_meth_set_final, -EVP_MD_meth_set_copy, -EVP_MD_meth_set_cleanup, -EVP_MD_meth_set_ctrl, -EVP_MD_meth_get_input_blocksize, -EVP_MD_meth_get_result_size, -EVP_MD_meth_get_app_datasize, -EVP_MD_meth_get_flags, -EVP_MD_meth_get_init, -EVP_MD_meth_get_update, -EVP_MD_meth_get_final, -EVP_MD_meth_get_copy, -EVP_MD_meth_get_cleanup, -EVP_MD_meth_get_ctrl, -EVP_PKEY_meth_find, -EVP_PKEY_meth_new, -EVP_PKEY_meth_get0_info, -EVP_PKEY_meth_copy, -EVP_PKEY_meth_free, -EVP_PKEY_meth_add0, -EVP_PKEY_meth_remove, -EVP_PKEY_meth_get_count, -EVP_PKEY_meth_get0, -EVP_PKEY_meth_set_init, -EVP_PKEY_meth_set_copy, -EVP_PKEY_meth_set_cleanup, -EVP_PKEY_meth_set_paramgen, -EVP_PKEY_meth_set_keygen, -EVP_PKEY_meth_set_sign, -EVP_PKEY_meth_set_verify, -EVP_PKEY_meth_set_verify_recover, -EVP_PKEY_meth_set_signctx, -EVP_PKEY_meth_set_verifyctx, -EVP_PKEY_meth_set_encrypt, -EVP_PKEY_meth_set_decrypt, -EVP_PKEY_meth_set_derive, -EVP_PKEY_meth_set_ctrl, -EVP_PKEY_meth_set_digestsign, -EVP_PKEY_meth_set_digestverify, -EVP_PKEY_meth_set_check, -EVP_PKEY_meth_set_public_check, -EVP_PKEY_meth_set_param_check, -EVP_PKEY_meth_set_digest_custom, -EVP_PKEY_meth_get_init, -EVP_PKEY_meth_get_copy, -EVP_PKEY_meth_get_cleanup, -EVP_PKEY_meth_get_paramgen, -EVP_PKEY_meth_get_keygen, -EVP_PKEY_meth_get_sign, -EVP_PKEY_meth_get_verify, -EVP_PKEY_meth_get_verify_recover, -EVP_PKEY_meth_get_signctx, -EVP_PKEY_meth_get_verifyctx, -EVP_PKEY_meth_get_encrypt, -EVP_PKEY_meth_get_decrypt, -EVP_PKEY_meth_get_derive, -EVP_PKEY_meth_get_ctrl, -EVP_PKEY_meth_get_digestsign, -EVP_PKEY_meth_get_digestverify, -EVP_PKEY_meth_get_check, -EVP_PKEY_meth_get_public_check, -EVP_PKEY_meth_get_param_check, -EVP_PKEY_meth_get_digest_custom, -EVP_MD_CTX_update_fn, -EVP_MD_CTX_set_update_fn, -EVP_PKEY_asn1_add0, -EVP_PKEY_asn1_add_alias, -EVP_PKEY_asn1_get_count, -EVP_PKEY_asn1_get0, -EVP_PKEY_asn1_find, -EVP_PKEY_asn1_find_str, -EVP_PKEY_asn1_get0_info, -EVP_PKEY_get0_asn1, -EVP_PKEY_asn1_new, -EVP_PKEY_asn1_copy, -EVP_PKEY_asn1_free, -EVP_PKEY_asn1_set_public, -EVP_PKEY_asn1_set_private, -EVP_PKEY_asn1_set_param, -EVP_PKEY_asn1_set_free, -EVP_PKEY_asn1_set_ctrl, -EVP_PKEY_asn1_set_item, -EVP_PKEY_asn1_set_siginf, -EVP_PKEY_asn1_set_check, -EVP_PKEY_asn1_set_public_check, -EVP_PKEY_asn1_set_param_check, -EVP_PKEY_asn1_set_set_priv_key, -EVP_PKEY_asn1_set_set_pub_key, -EVP_PKEY_asn1_set_get_priv_key, -EVP_PKEY_asn1_set_get_pub_key, -EVP_PKEY_asn1_set_security_bits, -OPENSSL_atexit, -SSLv3_method, -SSLv3_server_method, -SSLv3_client_method, -TLSv1_method, -TLSv1_server_method, -TLSv1_client_method, -TLSv1_1_method, -TLSv1_1_server_method, -TLSv1_1_client_method, -TLSv1_2_method, -TLSv1_2_server_method, -TLSv1_2_client_method, ossl-removed-api - API that has been removed from OpenSSL =head1 SYNOPSIS @@ -175,288 +34,6 @@ This includes consulting the L documentation. =item ASN1_STRING_data (Deprecated in 1.1.1) - see L -=item BIO_f_reliable (Broken since 3.0.0) - removed without replacement - -=item DTLSv1_method (Deprecated in 1.1.0) - consult L - -=item DTLSv1_client_method (Deprecated in 1.1.0) - consult L - -=item DTLSv1_server_method (Deprecated in 1.1.0) - consult L - -=item DTLSv1_2_method (Deprecated in 1.1.0) - consult L - -=item DTLSv1_2_client_method (Deprecated in 1.1.0) - consult L - -=item DTLSv1_2_server_method (Deprecated in 1.1.0) - consult L - -=item ERR_get_state (Deprecated in 3.0.0) - removed, no use with opaque ERR_STATE - -=item ERR_remove_state (Deprecated in 1.0.0) - removed, no-op - -=item ERR_remove_thread_state (Deprecated in 1.1.0) - removed, no-op - -=item EVP_CIPHER_meth_new (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_dup (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_free (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_set_iv_length (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_set_flags (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_set_impl_ctx_size (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_set_init (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_set_do_cipher (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_set_cleanup (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_set_set_asn1_params (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_set_get_asn1_params (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_set_ctrl (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_get_init (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_get_do_cipher (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_get_cleanup (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_get_set_asn1_params (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_get_get_asn1_params (Deprecated in 3.0.0) - consult L - -=item EVP_CIPHER_meth_get_ctrl (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_new (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_dup (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_free (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_set_input_blocksize (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_set_result_size (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_set_app_datasize (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_set_flags (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_set_init (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_set_update (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_set_final (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_set_copy (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_set_cleanup (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_set_ctrl (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_get_input_blocksize (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_get_result_size (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_get_app_datasize (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_get_flags (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_get_init (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_get_update (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_get_final (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_get_copy (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_get_cleanup (Deprecated in 3.0.0) - consult L - -=item EVP_MD_meth_get_ctrl (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_find (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_new (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get0_info (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_copy (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_free (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_add0 (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_remove (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_count (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get0 (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_init (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_copy (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_cleanup (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_paramgen (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_keygen (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_sign (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_verify (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_verify_recover (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_signctx (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_verifyctx (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_encrypt (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_decrypt (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_derive (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_ctrl (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_digestsign (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_digestverify (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_check (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_public_check (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_param_check (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_set_digest_custom (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_init (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_copy (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_cleanup (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_paramgen (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_keygen (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_sign (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_verify (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_verify_recover (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_signctx (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_verifyctx (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_encrypt (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_decrypt (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_derive (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_ctrl (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_digestsign (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_digestverify (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_check (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_public_check (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_param_check (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_meth_get_digest_custom (Deprecated in 3.0.0) - consult L - -=item EVP_MD_CTX_update_fn (Deprecated in 3.0.0) - consult L - -=item EVP_MD_CTX_set_update_fn (Deprecated in 3.0.0) - consult L - -=item EVP_PKEY_asn1_add0 (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_add_alias (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_get_count (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_get0 (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_find (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_find_str (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_get0_info (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_get0_asn1 (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_new (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_copy (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_free (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_set_public (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_set_private (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_set_param (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_set_free (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_set_ctrl (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_set_item (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_set_siginf (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_set_check (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_set_public_check (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_set_param_check (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_set_set_priv_key (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_set_set_pub_key (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_set_get_priv_key (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_set_get_pub_key (Deprecated in 3.6.0) - consult L - -=item EVP_PKEY_asn1_set_security_bits (Deprecated in 3.6.0) - consult L - -=item OPENSSL_atexit - No longer used, use libc atexit() if you must use this. - -=item SSLv3_method (Deprecated in 1.1.0) - consult L - -=item SSLv3_server_method (Deprecated in 1.1.0) - consult L - -=item SSLv3_client_method (Deprecated in 1.1.0) - consult L - -=item TLSv1_method (Deprecated in 1.1.0) - consult L - -=item TLSv1_server_method (Deprecated in 1.1.0) - consult L - -=item TLSv1_client_method (Deprecated in 1.1.0) - consult L - -=item TLSv1_1_method (Deprecated in 1.1.0) - consult L - -=item TLSv1_1_server_method (Deprecated in 1.1.0) - consult L - -=item TLSv1_1_client_method (Deprecated in 1.1.0) - consult L - -=item TLSv1_2_method (Deprecated in 1.1.0) - consult L - -=item TLSv1_2_server_method (Deprecated in 1.1.0) - consult L - -=item TLSv1_2_client_method (Deprecated in 1.1.0) - consult L - =back =head1 SEE ALSO @@ -465,7 +42,7 @@ L =head1 COPYRIGHT -Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/ossl_store.pod b/doc/man7/ossl_store.pod index 0441fe34e9..5e16a10f2f 100644 --- a/doc/man7/ossl_store.pod +++ b/doc/man7/ossl_store.pod @@ -32,7 +32,6 @@ dynamically from the calling application or from a loadable provider. Support for the 'file' scheme is built into C. See L for more information. -For information on the 'org.openssl.winstore' scheme, see L. =head2 UI_METHOD and pass phrases @@ -79,8 +78,7 @@ other encoding is undefined. L, L, L, L, -L, -L, L +L =head1 COPYRIGHT diff --git a/doc/man7/property.pod b/doc/man7/property.pod index 7adf282ebf..eb0f6b176c 100644 --- a/doc/man7/property.pod +++ b/doc/man7/property.pod @@ -142,38 +142,6 @@ Note that the local property query could not use "fips=no" because that would disallow any implementations with "fips=yes" rather than not caring about the setting. -=head1 PREDEFINED NAMES - -=for comment This list should correspond to the array 'predefined_names' in crypto/property/property_parse.c - -Currently known predefined names are: - -=over 4 - -=item C - -The conventional property value is the provider's name. This may be different from the name returned by L. - -It is a convention among OpenSSL provider implementations to define a property with this name. It is not mandatory to do this. - -=item C - -The conventional property value is the provider's version. - -OpenSSL provider implementations do not define a property with this name. - -=item C - -The conventional property value is boolean (C<"yes"> or C<"no">), indication whether the implementation conforms to FIPS standards or not. - -It is a convention among OpenSSL provider implementations to define a property with this name where applicable. It is not mandatory to do this, but is strongly recommended. - -=item C, C, C - -Properties with these names are used by encoders (see L) and decoders (see L). - -=back - =head1 SYNTAX The lexical syntax in EBNF is given by: @@ -199,7 +167,7 @@ Properties were added in OpenSSL 3.0 =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/provider-asym_cipher.pod b/doc/man7/provider-asym_cipher.pod index e28f57f742..9679c5c985 100644 --- a/doc/man7/provider-asym_cipher.pod +++ b/doc/man7/provider-asym_cipher.pod @@ -38,9 +38,9 @@ provider-asym_cipher - The asym_cipher library E-E provider functions /* Asymmetric Cipher parameters */ int OSSL_FUNC_asym_cipher_get_ctx_params(void *ctx, OSSL_PARAM params[]); - const OSSL_PARAM *OSSL_FUNC_asym_cipher_gettable_ctx_params(void *ctx, void *provctx); + const OSSL_PARAM *OSSL_FUNC_asym_cipher_gettable_ctx_params(void *provctx); int OSSL_FUNC_asym_cipher_set_ctx_params(void *ctx, const OSSL_PARAM params[]); - const OSSL_PARAM *OSSL_FUNC_asym_cipher_settable_ctx_params(void *ctx, void *provctx); + const OSSL_PARAM *OSSL_FUNC_asym_cipher_settable_ctx_params(void *provctx); =head1 DESCRIPTION diff --git a/doc/man7/provider-base.pod b/doc/man7/provider-base.pod index fe74789d8f..023ac12f68 100644 --- a/doc/man7/provider-base.pod +++ b/doc/man7/provider-base.pod @@ -141,8 +141,7 @@ For example, the "function" core_gettable_params() has these: static ossl_inline OSSL_NAME_core_gettable_params_fn OSSL_FUNC_core_gettable_params(const OSSL_DISPATCH *opf); -L array entries contain a I field that -identifies the function. The I numbers are provided as +L arrays are indexed by numbers that are provided as macros in L, as follows: For I (the L array passed from F to the @@ -1017,7 +1016,7 @@ were added in OpenSSL 3.5. =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/provider-cipher.pod b/doc/man7/provider-cipher.pod index a7dea25fd3..679c35e0f9 100644 --- a/doc/man7/provider-cipher.pod +++ b/doc/man7/provider-cipher.pod @@ -294,7 +294,7 @@ OSSL_FUNC_cipher_decrypt_skey_init() were introduced in OpenSSL 3.5. =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/provider-digest.pod b/doc/man7/provider-digest.pod index 6d90534f9e..c44de648dc 100644 --- a/doc/man7/provider-digest.pod +++ b/doc/man7/provider-digest.pod @@ -30,10 +30,6 @@ provider-digest - The digest library E-E provider functions int OSSL_FUNC_digest_digest(void *provctx, const unsigned char *in, size_t inl, unsigned char *out, size_t *outl, size_t outsz); - /* Digest state serialization */ - int OSSL_FUNC_digest_serialize(void *dctx, unsigned char *out, size_t *outl); - int OSSL_FUNC_digest_deserialize(void *dctx, const unsigned char *in, size_t inl); - /* Digest parameter descriptors */ const OSSL_PARAM *OSSL_FUNC_digest_gettable_params(void *provctx); @@ -88,9 +84,6 @@ macros in L, as follows: OSSL_FUNC_digest_final OSSL_FUNC_DIGEST_FINAL OSSL_FUNC_digest_digest OSSL_FUNC_DIGEST_DIGEST - OSSL_FUNC_digest_serialize OSSL_FUNC_DIGEST_SERIALIZE - OSSL_FUNC_digest_deserialize OSSL_FUNC_DIGEST_DESERIALIZE - OSSL_FUNC_digest_get_params OSSL_FUNC_DIGEST_GET_PARAMS OSSL_FUNC_digest_get_ctx_params OSSL_FUNC_DIGEST_GET_CTX_PARAMS OSSL_FUNC_digest_set_ctx_params OSSL_FUNC_DIGEST_SET_CTX_PARAMS @@ -159,26 +152,6 @@ I bytes at I should be digested and the result should be stored at I. The length of the digest should be stored in I<*outl> which should not exceed I bytes. -=head2 Digest State Serialization Functions - -OSSL_FUNC_digest_serialize() serializes the state of the digest context I. -If I is NULL, then the maximum necessary size for the output buffer is -written to I<*outl>. -If I is not NULL, then I<*outl> is assumed to contain the length of the -I buffer. If the call is successful, the serialized data is written -to I and the amount of data written is stored in I<*outl>. - -OSSL_FUNC_digest_deserialize() deserializes the data from I of size I -into the digest context I. -The context I should be initialized before calling this function. -After a successful deserialization, the context is ready to be used for -any subsequent digest operations. - -The content of the state and its validity (over time, process lifetime, etc) are -completely in control of the provider. The documentation for each provider -should state what guarantees it can offer in terms of recovering the state of a -serialized blob. - =head2 Digest Parameters See L for further details on the parameters structure used by @@ -281,11 +254,9 @@ See L for further details on the parameters structure. OSSL_FUNC_digest_newctx() and OSSL_FUNC_digest_dupctx() should return the newly created provider side digest context, or NULL on failure. -OSSL_FUNC_digest_init(), OSSL_FUNC_digest_update(), OSSL_FUNC_digest_final(), -OSSL_FUNC_digest_digest(), OSSL_FUNC_digest_get_params(), -OSSL_FUNC_digest_set_ctx_params(), OSSL_FUNC_digest_get_ctx_params(), -OSSL_FUNC_digest_serialize(), and OSSL_FUNC_digest_deserialize() should return 1 for -success or 0 on error. +OSSL_FUNC_digest_init(), OSSL_FUNC_digest_update(), OSSL_FUNC_digest_final(), OSSL_FUNC_digest_digest(), +OSSL_FUNC_digest_set_params() and OSSL_FUNC_digest_get_params() should return 1 for success or +0 on error. OSSL_FUNC_digest_size() should return the digest size. @@ -307,7 +278,7 @@ L, L, L, L, L, L, L, L, L L, L, L, -L, L, +L, L, L =head1 HISTORY @@ -317,7 +288,7 @@ OSSL_FUNC_digest_copyctx() was added in 3.5 version. =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/provider-keymgmt.pod b/doc/man7/provider-keymgmt.pod index ff69d0db7b..237ea87a7f 100644 --- a/doc/man7/provider-keymgmt.pod +++ b/doc/man7/provider-keymgmt.pod @@ -16,7 +16,6 @@ provider-keymgmt - The KEYMGMT library E-E provider functions /* Key object (keydata) creation and destruction */ void *OSSL_FUNC_keymgmt_new(void *provctx); - void *OSSL_FUNC_keymgmt_new_ex(void *provctx, const OSSL_PARAM params[]); void OSSL_FUNC_keymgmt_free(void *keydata); /* Generation, a more complex constructor */ @@ -220,9 +219,7 @@ since a match of one half implies a match of the other half. OSSL_FUNC_keymgmt_new() should create a provider side key object. The provider context I is passed and may be incorporated in the -key object, but that is not mandatory. OSSL_FUNC_keymgmt_new_ex() may optionally -be defined and does the same as OSSL_FUNC_keymgmt_new(), but also accepts an -array of parameters. Currently no parameters are defined for this function. +key object, but that is not mandatory. OSSL_FUNC_keymgmt_free() should free the passed I. @@ -569,7 +566,7 @@ Support for the B algorithm was added in OpenSSL 3.6. =head1 COPYRIGHT -Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. Licensed under the Apache License 2.0 (the "License"). You may not use this file except in compliance with the License. You can obtain a copy diff --git a/doc/man7/provider-signature.pod b/doc/man7/provider-signature.pod index 1e4e99c0b1..d5af5a2e38 100644 --- a/doc/man7/provider-signature.pod +++ b/doc/man7/provider-signature.pod @@ -269,6 +269,7 @@ OSSL_FUNC_signature_gettable_ctx_params() functions, as well as the "md_params" functions. The OSSL_FUNC_signature_dupctx() function is optional. +It is not yet used by OpenSSL. The OSSL_FUNC_signature_query_key_types() function is optional. When present, it should return a NULL-terminated array of strings diff --git a/doc/man7/provider-storemgmt.pod b/doc/man7/provider-storemgmt.pod index 6c9f460754..2210600217 100644 --- a/doc/man7/provider-storemgmt.pod +++ b/doc/man7/provider-storemgmt.pod @@ -192,9 +192,7 @@ decoder implementations. =item "input-type" (B) Type of the input format as a hint to use when decoding the objects in the -store, such as C and C. -See L for details on their use for OpenSSL commands. - +store. =back diff --git a/doc/perlvars.pm b/doc/perlvars.pm index 5bc8ac61c5..ae3dfad545 100644 --- a/doc/perlvars.pm +++ b/doc/perlvars.pm @@ -136,13 +136,14 @@ $OpenSSL::safe::opt_versiontls_synopsis = "" . "[B<-no_tls1_1>]\n" . "[B<-no_tls1_2>]\n" . "[B<-no_tls1_3>]\n" +. "[B<-ssl3>]\n" . "[B<-tls1>]\n" . "[B<-tls1_1>]\n" . "[B<-tls1_2>]\n" . "[B<-tls1_3>]"; $OpenSSL::safe::opt_versiontls_item = "" . "=item B<-no_ssl3>, B<-no_tls1>, B<-no_tls1_1>, B<-no_tls1_2>, B<-no_tls1_3>,\n" -. "B<-tls1>, B<-tls1_1>, B<-tls1_2>, B<-tls1_3>\n" +. "B<-ssl3>, B<-tls1>, B<-tls1_1>, B<-tls1_2>, B<-tls1_3>\n" . "\n" . "See L."; diff --git a/exporters/build.info b/exporters/build.info index 54d5684da2..4ef487a41a 100644 --- a/exporters/build.info +++ b/exporters/build.info @@ -19,7 +19,6 @@ DEPEND[openssl.pc]=libcrypto.pc libssl.pc DEPEND[""]=openssl.pc GENERATE[../installdata.pm]=../util/mkinstallvars.pl \ - COMMENT="This file provides configuration information for OpenSSL" \ "PREFIX=$(INSTALLTOP)" BINDIR=bin "LIBDIR=$(LIBDIR)" "libdir=$(libdir)" \ INCLUDEDIR=include APPLINKDIR=include/openssl \ "MODULESDIR=$(MODULESDIR)" \ diff --git a/exporters/cmake/OpenSSLConfig.cmake.in b/exporters/cmake/OpenSSLConfig.cmake.in index 4970528573..79602796cb 100644 --- a/exporters/cmake/OpenSSLConfig.cmake.in +++ b/exporters/cmake/OpenSSLConfig.cmake.in @@ -1,8 +1,8 @@ # Generated by OpenSSL -# {- $OpenSSL::safe::installdata::COMMENT // "" -} {- use lib catdir($config{sourcedir}, 'Configurations'); use platform; + use Data::Dumper; our %lib_info = ( map { my %x = (); diff --git a/exporters/cmake/OpenSSLConfigVersion.cmake.in b/exporters/cmake/OpenSSLConfigVersion.cmake.in index 15bae56972..b1290a9eec 100644 --- a/exporters/cmake/OpenSSLConfigVersion.cmake.in +++ b/exporters/cmake/OpenSSLConfigVersion.cmake.in @@ -1,5 +1,4 @@ # Generated by OpenSSL -# {- $OpenSSL::safe::installdata::COMMENT // "" -} set(PACKAGE_VERSION {- $config{version} -}) diff --git a/exporters/pkg-config/libcrypto.pc.in b/exporters/pkg-config/libcrypto.pc.in index b0481093a1..952bd8130c 100644 --- a/exporters/pkg-config/libcrypto.pc.in +++ b/exporters/pkg-config/libcrypto.pc.in @@ -1,4 +1,3 @@ -# {- $OpenSSL::safe::installdata::COMMENT // "" -} prefix={- $OpenSSL::safe::installdata::PREFIX[0] -} exec_prefix=${prefix} libdir={- if (defined $OpenSSL::safe::installdata::LIBDIR_REL_PREFIX[0]) { @@ -11,8 +10,7 @@ libdir={- if (defined $OpenSSL::safe::installdata::LIBDIR_REL_PREFIX[0]) { } -} includedir={- $OUT = ''; $OUT .= '${prefix}/' . $_ . ' ' - foreach (@OpenSSL::safe::installdata::INCLUDEDIR_REL_PREFIX); - $OUT =~ s/\s+\z//; -} + foreach (@OpenSSL::safe::installdata::INCLUDEDIR_REL_PREFIX); -} modulesdir=${libdir}/{- $OpenSSL::safe::installdata::MODULESDIR_REL_LIBDIR[0] -} Name: OpenSSL-libcrypto @@ -25,5 +23,4 @@ Cflags:{- $OUT = ' -I${includedir}'; $OUT = ''; $OUT .= ' -I${prefix}/' . $_ . ' ' foreach (@OpenSSL::safe::installdata::INCLUDEDIR_REL_PREFIX); - $OUT =~ s/\s+\z//; } -} diff --git a/exporters/pkg-config/libssl.pc.in b/exporters/pkg-config/libssl.pc.in index 50132b7502..162db65c99 100644 --- a/exporters/pkg-config/libssl.pc.in +++ b/exporters/pkg-config/libssl.pc.in @@ -1,4 +1,3 @@ -# {- $OpenSSL::safe::installdata::COMMENT // "" -} prefix={- $OpenSSL::safe::installdata::PREFIX[0] -} exec_prefix=${prefix} libdir={- if (defined $OpenSSL::safe::installdata::LIBDIR_REL_PREFIX[0]) { @@ -11,8 +10,7 @@ libdir={- if (defined $OpenSSL::safe::installdata::LIBDIR_REL_PREFIX[0]) { } -} includedir={- $OUT = ''; $OUT .= '${prefix}/' . $_ . ' ' - foreach (@OpenSSL::safe::installdata::INCLUDEDIR_REL_PREFIX); - $OUT =~ s/\s+\z//; -} + foreach (@OpenSSL::safe::installdata::INCLUDEDIR_REL_PREFIX); -} Name: OpenSSL-libssl Description: Secure Sockets Layer and cryptography libraries @@ -24,5 +22,4 @@ Cflags:{- $OUT = ' -I${includedir}'; $OUT = ''; $OUT .= ' -I${prefix}/' . $_ . ' ' foreach (@OpenSSL::safe::installdata::INCLUDEDIR_REL_PREFIX); - $OUT =~ s/\s+\z//; } -} diff --git a/exporters/pkg-config/openssl.pc.in b/exporters/pkg-config/openssl.pc.in index 3573ed9872..73eb8e73c2 100644 --- a/exporters/pkg-config/openssl.pc.in +++ b/exporters/pkg-config/openssl.pc.in @@ -1,4 +1,3 @@ -# {- $OpenSSL::safe::installdata::COMMENT // "" -} prefix={- $OpenSSL::safe::installdata::PREFIX[0] -} exec_prefix=${prefix} libdir={- if (defined $OpenSSL::safe::installdata::LIBDIR_REL_PREFIX[0]) { @@ -11,8 +10,7 @@ libdir={- if (defined $OpenSSL::safe::installdata::LIBDIR_REL_PREFIX[0]) { } -} includedir={- $OUT = ''; $OUT .= '${prefix}/' . $_ . ' ' - foreach (@OpenSSL::safe::installdata::INCLUDEDIR_REL_PREFIX); - $OUT =~ s/\s+\z//; -} + foreach (@OpenSSL::safe::installdata::INCLUDEDIR_REL_PREFIX); -} Name: OpenSSL Description: Secure Sockets Layer and cryptography libraries and tools diff --git a/external/perl/Text-Template-1.56/lib/Text/Template.pm b/external/perl/Text-Template-1.56/lib/Text/Template.pm index dec5b61419..be38c73ce4 100644 --- a/external/perl/Text-Template-1.56/lib/Text/Template.pm +++ b/external/perl/Text-Template-1.56/lib/Text/Template.pm @@ -2337,8 +2337,8 @@ There are not quite enough tests in the test suite. =head1 SOURCE -The development version is on github at L -and may be cloned from L +The development version is on github at L +and may be cloned from L =head1 BUGS diff --git a/external/perl/Text-Template-1.56/lib/Text/Template/Preprocess.pm b/external/perl/Text-Template-1.56/lib/Text/Template/Preprocess.pm index b4f7d53eba..4fea67b383 100644 --- a/external/perl/Text-Template-1.56/lib/Text/Template/Preprocess.pm +++ b/external/perl/Text-Template-1.56/lib/Text/Template/Preprocess.pm @@ -122,8 +122,8 @@ L =head1 SOURCE -The development version is on github at L -and may be cloned from L +The development version is on github at L +and may be cloned from L =head1 BUGS diff --git a/fuzz/README.md b/fuzz/README.md index 118ad684e9..795606fec2 100644 --- a/fuzz/README.md +++ b/fuzz/README.md @@ -29,7 +29,7 @@ to the `libFuzzer` library file while configuring; this is represented as -fsanitize=fuzzer-no-link \ enable-ec_nistp_64_gcc_128 -fno-sanitize=alignment \ enable-weak-ssl-ciphers enable-rc5 enable-md2 \ - enable-nextprotoneg \ + enable-ssl3 enable-ssl3-method enable-nextprotoneg \ --debug Clang uses the gcc libstdc++ library so this must also be installed. You can @@ -95,7 +95,8 @@ prebuilt fuzzer library. This is represented as `$PATH_TO_LIBFUZZER_DIR` below. -fsanitize=fuzzer-no-link \ enable-ec_nistp_64_gcc_128 -fno-sanitize=alignment \ enable-weak-ssl-ciphers enable-rc5 enable-md2 \ - enable-nextprotoneg --debug + enable-ssl3 enable-ssl3-method enable-nextprotoneg \ + --debug AFL --- @@ -107,8 +108,9 @@ Configure for fuzzing: sudo apt-get install afl-clang CC=afl-clang-fast ./config enable-fuzz-afl no-shared no-module \ -DPEDANTIC enable-tls1_3 enable-weak-ssl-ciphers enable-rc5 \ - enable-md2 enable-nextprotoneg enable-ec_nistp_64_gcc_128 \ - -fno-sanitize=alignment --debug + enable-md2 enable-ssl3 enable-ssl3-method enable-nextprotoneg \ + enable-ec_nistp_64_gcc_128 -fno-sanitize=alignment \ + --debug make clean make diff --git a/fuzz/acert.c b/fuzz/acert.c index 3af3c3e87a..14c2f657ee 100644 --- a/fuzz/acert.c +++ b/fuzz/acert.c @@ -26,16 +26,13 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) { const unsigned char *p = buf; unsigned char *der = NULL; - X509_ACERT *acert; - acert = d2i_X509_ACERT(NULL, &p, (long)len); + X509_ACERT *acert = d2i_X509_ACERT(NULL, &p, (long)len); if (acert != NULL) { BIO *bio = BIO_new(BIO_s_null()); - if (bio != NULL) { - X509_ACERT_print(bio, acert); - BIO_free(bio); - } + X509_ACERT_print(bio, acert); + BIO_free(bio); i2d_X509_ACERT(acert, &der); OPENSSL_free(der); diff --git a/fuzz/asn1.c b/fuzz/asn1.c index 12ba8a13d4..934e1447e9 100644 --- a/fuzz/asn1.c +++ b/fuzz/asn1.c @@ -277,6 +277,9 @@ static ASN1_PCTX *pctx; TYPE *type = D2I(NULL, &p, (long)len); \ \ if (type != NULL) { \ + BIO *bio = BIO_new(BIO_s_null()); \ + \ + BIO_free(bio); \ I2D(type, &der); \ OPENSSL_free(der); \ TYPE##_free(type); \ @@ -287,8 +290,6 @@ int FuzzerInitialize(int *argc, char ***argv) { FuzzerSetRand(); pctx = ASN1_PCTX_new(); - if (pctx == NULL) - return 0; ASN1_PCTX_set_flags(pctx, ASN1_PCTX_FLAGS_SHOW_ABSENT | ASN1_PCTX_FLAGS_SHOW_SEQUENCE | ASN1_PCTX_FLAGS_SHOW_SSOF | ASN1_PCTX_FLAGS_SHOW_TYPE | ASN1_PCTX_FLAGS_SHOW_FIELD_STRUCT_NAME); ASN1_PCTX_set_str_flags(pctx, ASN1_STRFLGS_UTF8_CONVERT | ASN1_STRFLGS_SHOW_TYPE | ASN1_STRFLGS_DUMP_ALL); diff --git a/fuzz/bignum.c b/fuzz/bignum.c index eec776e7b3..b9dcb49ebe 100644 --- a/fuzz/bignum.c +++ b/fuzz/bignum.c @@ -28,6 +28,7 @@ int FuzzerInitialize(int *argc, char ***argv) int FuzzerTestOneInput(const uint8_t *buf, size_t len) { + int success = 0; size_t l1 = 0, l2 = 0, l3 = 0; int s1 = 0, s3 = 0; BN_CTX *ctx; @@ -44,10 +45,6 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) b5 = BN_new(); ctx = BN_CTX_new(); - if (b1 == NULL || b2 == NULL || b3 == NULL || b4 == NULL || b5 == NULL - || ctx == NULL) - goto done; - /* Divide the input into three parts, using the values of the first two * bytes to choose lengths, which generate b1, b2 and b3. Use three bits * of the third byte to choose signs for the three numbers. @@ -65,25 +62,23 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) s3 = buf[0] & 4; ++buf; } - if (BN_bin2bn(buf, (int)l1, b1) != b1) - goto done; + OPENSSL_assert(BN_bin2bn(buf, (int)l1, b1) == b1); BN_set_negative(b1, s1); - if (BN_bin2bn(buf + l1, (int)l2, b2) != b2) - goto done; - if (BN_bin2bn(buf + l1 + l2, (int)l3, b3) != b3) - goto done; + OPENSSL_assert(BN_bin2bn(buf + l1, (int)l2, b2) == b2); + OPENSSL_assert(BN_bin2bn(buf + l1 + l2, (int)l3, b3) == b3); BN_set_negative(b3, s3); /* mod 0 is undefined */ - if (BN_is_zero(b3)) + if (BN_is_zero(b3)) { + success = 1; goto done; + } - if (!BN_mod_exp(b4, b1, b2, b3, ctx)) - goto done; - if (!BN_mod_exp_simple(b5, b1, b2, b3, ctx)) - goto done; + OPENSSL_assert(BN_mod_exp(b4, b1, b2, b3, ctx)); + OPENSSL_assert(BN_mod_exp_simple(b5, b1, b2, b3, ctx)); - if (BN_cmp(b4, b5) != 0) { + success = BN_cmp(b4, b5) == 0; + if (!success) { BN_print_fp(stdout, b1); putchar('\n'); BN_print_fp(stdout, b2); @@ -97,6 +92,7 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) } done: + OPENSSL_assert(success); BN_free(b1); BN_free(b2); BN_free(b3); diff --git a/fuzz/bndiv.c b/fuzz/bndiv.c index c3a2d2f305..a52f7b598b 100644 --- a/fuzz/bndiv.c +++ b/fuzz/bndiv.c @@ -37,19 +37,6 @@ int FuzzerInitialize(int *argc, char ***argv) b5 = BN_new(); ctx = BN_CTX_new(); - if (b1 == NULL || b2 == NULL || b3 == NULL || b4 == NULL || b5 == NULL - || ctx == NULL) { - BN_free(b1); - BN_free(b2); - BN_free(b3); - BN_free(b4); - BN_free(b5); - BN_CTX_free(ctx); - b1 = b2 = b3 = b4 = b5 = NULL; - ctx = NULL; - return 0; - } - OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CRYPTO_STRINGS, NULL); ERR_clear_error(); @@ -82,19 +69,18 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) ++buf; l2 = len - l1; } - if (BN_bin2bn(buf, (int)l1, b1) != b1) - goto done; + OPENSSL_assert(BN_bin2bn(buf, (int)l1, b1) == b1); BN_set_negative(b1, s1); - if (BN_bin2bn(buf + l1, (int)l2, b2) != b2) - goto done; + OPENSSL_assert(BN_bin2bn(buf + l1, (int)l2, b2) == b2); BN_set_negative(b2, s2); /* divide by 0 is an error */ - if (BN_is_zero(b2)) + if (BN_is_zero(b2)) { + success = 1; goto done; + } - if (!BN_div(b3, b4, b1, b2, ctx)) - goto done; + OPENSSL_assert(BN_div(b3, b4, b1, b2, ctx)); if (BN_is_zero(b1)) success = BN_is_zero(b3) && BN_is_zero(b4); else if (BN_is_negative(b1)) @@ -103,10 +89,8 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) else success = (BN_is_negative(b3) == BN_is_negative(b2) || BN_is_zero(b3)) && (!BN_is_negative(b4) || BN_is_zero(b4)); - if (!BN_mul(b5, b3, b2, ctx)) - goto done; - if (!BN_add(b5, b5, b4)) - goto done; + OPENSSL_assert(BN_mul(b5, b3, b2, ctx)); + OPENSSL_assert(BN_add(b5, b5, b4)); success = success && BN_cmp(b5, b1) == 0; if (!success) { @@ -130,6 +114,7 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) } done: + OPENSSL_assert(success); ERR_clear_error(); return 0; diff --git a/fuzz/build.info b/fuzz/build.info index fcbb76234c..552d9fcbce 100644 --- a/fuzz/build.info +++ b/fuzz/build.info @@ -10,7 +10,7 @@ IF[{- !$disabled{"fuzz-afl"} || !$disabled{"fuzz-libfuzzer"} -}] PROGRAMS{noinst}=asn1 asn1parse bignum bndiv client conf crl server smime - PROGRAMS{noinst}=pkcs12 punycode pem decoder hashtable acert + PROGRAMS{noinst}=punycode pem decoder hashtable acert PROGRAMS{noinst}=v3name PROGRAMS{noinst}=provider @@ -50,10 +50,6 @@ IF[{- !$disabled{"fuzz-afl"} || !$disabled{"fuzz-libfuzzer"} -}] PROGRAMS{noinst}=dtlsclient dtlsserver ENDIF - IF[{- !$disabled{"ech"} -}] - PROGRAMS{noinst}=echconfiglist_parser - ENDIF - SOURCE[asn1]=asn1.c driver.c fuzz_rand.c INCLUDE[asn1]=../include {- $ex_inc -} DEPEND[asn1]=../libcrypto ../libssl {- $ex_lib -} @@ -86,10 +82,6 @@ IF[{- !$disabled{"fuzz-afl"} || !$disabled{"fuzz-libfuzzer"} -}] INCLUDE[cms]=../include {- $ex_inc -} DEPEND[cms]=../libcrypto {- $ex_lib -} - SOURCE[pkcs12]=pkcs12.c driver.c - INCLUDE[pkcs12]=../include {- $ex_inc -} - DEPEND[pkcs12]=../libcrypto {- $ex_lib -} - SOURCE[conf]=conf.c driver.c INCLUDE[conf]=../include {- $ex_inc -} DEPEND[conf]=../libcrypto {- $ex_lib -} @@ -110,10 +102,6 @@ IF[{- !$disabled{"fuzz-afl"} || !$disabled{"fuzz-libfuzzer"} -}] INCLUDE[dtlsserver]=../include {- $ex_inc -} DEPEND[dtlsserver]=../libcrypto ../libssl {- $ex_lib -} - SOURCE[echconfiglist_parser]=echconfiglist_parser.c driver.c - INCLUDE[echconfiglist_parser]=../include {- $ex_inc -} - DEPEND[echconfiglist_parser]=../libcrypto ../libssl {- $ex_lib -} - SOURCE[pem]=pem.c driver.c INCLUDE[pem]=../include {- $ex_inc -} DEPEND[pem]=../libcrypto.a {- $ex_lib -} @@ -184,10 +172,8 @@ IF[{- !$disabled{"fuzz-afl"} || !$disabled{"fuzz-libfuzzer"} -}] ENDIF IF[{- !$disabled{tests} -}] - $FUZZTESTSRC=test-corpus.c ../test/mfail/mfail.c - PROGRAMS{noinst}=asn1-test asn1parse-test bignum-test bndiv-test client-test conf-test crl-test server-test smime-test - PROGRAMS{noinst}=pkcs12-test punycode-test pem-test decoder-test hashtable-test acert-test + PROGRAMS{noinst}=punycode-test pem-test decoder-test hashtable-test acert-test PROGRAMS{noinst}=v3name-test PROGRAMS{noinst}=provider-test @@ -228,139 +214,127 @@ IF[{- !$disabled{tests} -}] PROGRAMS{noinst}=dtlsclient-test dtlsserver-test ENDIF - IF[{- !$disabled{"ech"} -}] - PROGRAMS{noinst}=echconfiglist_parser-test - ENDIF + SOURCE[asn1-test]=asn1.c test-corpus.c fuzz_rand.c + INCLUDE[asn1-test]=../include + DEPEND[asn1-test]=../libcrypto ../libssl - SOURCE[asn1-test]=asn1.c $FUZZTESTSRC fuzz_rand.c - INCLUDE[asn1-test]=../include ../test/mfail - DEPEND[asn1-test]=../libcrypto.a ../libssl.a + SOURCE[asn1parse-test]=asn1parse.c test-corpus.c + INCLUDE[asn1parse-test]=../include + DEPEND[asn1parse-test]=../libcrypto - SOURCE[asn1parse-test]=asn1parse.c $FUZZTESTSRC - INCLUDE[asn1parse-test]=../include ../test/mfail - DEPEND[asn1parse-test]=../libcrypto.a + SOURCE[bignum-test]=bignum.c test-corpus.c + INCLUDE[bignum-test]=../include + DEPEND[bignum-test]=../libcrypto - SOURCE[bignum-test]=bignum.c $FUZZTESTSRC - INCLUDE[bignum-test]=../include ../test/mfail - DEPEND[bignum-test]=../libcrypto.a + SOURCE[bndiv-test]=bndiv.c test-corpus.c + INCLUDE[bndiv-test]=../include + DEPEND[bndiv-test]=../libcrypto - SOURCE[bndiv-test]=bndiv.c $FUZZTESTSRC - INCLUDE[bndiv-test]=../include ../test/mfail - DEPEND[bndiv-test]=../libcrypto.a + SOURCE[client-test]=client.c test-corpus.c fuzz_rand.c + INCLUDE[client-test]=../include + DEPEND[client-test]=../libcrypto ../libssl - SOURCE[client-test]=client.c $FUZZTESTSRC fuzz_rand.c - INCLUDE[client-test]=../include ../test/mfail - DEPEND[client-test]=../libcrypto.a ../libssl.a - - SOURCE[cmp-test]=cmp.c $FUZZTESTSRC fuzz_rand.c - INCLUDE[cmp-test]=../include ../test/mfail + SOURCE[cmp-test]=cmp.c test-corpus.c fuzz_rand.c + INCLUDE[cmp-test]=../include DEPEND[cmp-test]=../libcrypto.a # referring to static lib allows using non-exported functions - SOURCE[ml-kem-test]=ml-kem.c $FUZZTESTSRC - INCLUDE[ml-kem-test]=../include ../test/mfail + SOURCE[ml-kem-test]=ml-kem.c test-corpus.c fuzz_rand.c + INCLUDE[ml-kem-test]=../include DEPEND[ml-kem-test]=../libcrypto.a # referring to static lib allows using non-exported functions - SOURCE[ml-dsa-test]=ml-dsa.c $FUZZTESTSRC - INCLUDE[ml-dsa-test]=../include ../test/mfail + SOURCE[ml-dsa-test]=ml-dsa.c test-corpus.c fuzz_rand.c + INCLUDE[ml-dsa-test]=../include DEPEND[ml-dsa-test]=../libcrypto.a # referring to static lib allows using non-exported functions - SOURCE[slh-dsa-test]=slh-dsa.c $FUZZTESTSRC fuzz_rand.c - INCLUDE[slh-dsa-test]=../include ../test/mfail + SOURCE[slh-dsa-test]=slh-dsa.c test-corpus.c fuzz_rand.c + INCLUDE[slh-dsa-test]=../include DEPEND[slh-dsa-test]=../libcrypto.a # referring to static lib allows using non-exported functions - SOURCE[cms-test]=cms.c $FUZZTESTSRC - INCLUDE[cms-test]=../include ../test/mfail - DEPEND[cms-test]=../libcrypto.a + SOURCE[cms-test]=cms.c test-corpus.c + INCLUDE[cms-test]=../include + DEPEND[cms-test]=../libcrypto - SOURCE[pkcs12-test]=pkcs12.c $FUZZTESTSRC - INCLUDE[pkcs12-test]=../include ../test/mfail - DEPEND[pkcs12-test]=../libcrypto.a + SOURCE[conf-test]=conf.c test-corpus.c + INCLUDE[conf-test]=../include + DEPEND[conf-test]=../libcrypto - SOURCE[conf-test]=conf.c $FUZZTESTSRC - INCLUDE[conf-test]=../include ../test/mfail - DEPEND[conf-test]=../libcrypto.a + SOURCE[crl-test]=crl.c test-corpus.c + INCLUDE[crl-test]=../include + DEPEND[crl-test]=../libcrypto - SOURCE[crl-test]=crl.c $FUZZTESTSRC - INCLUDE[crl-test]=../include ../test/mfail - DEPEND[crl-test]=../libcrypto.a + SOURCE[ct-test]=ct.c test-corpus.c + INCLUDE[ct-test]=../include + DEPEND[ct-test]=../libcrypto - SOURCE[ct-test]=ct.c $FUZZTESTSRC - INCLUDE[ct-test]=../include ../test/mfail - DEPEND[ct-test]=../libcrypto.a + SOURCE[dtlsclient-test]=dtlsclient.c test-corpus.c fuzz_rand.c + INCLUDE[dtlsclient-test]=../include + DEPEND[dtlsclient-test]=../libcrypto ../libssl - SOURCE[dtlsclient-test]=dtlsclient.c $FUZZTESTSRC fuzz_rand.c - INCLUDE[dtlsclient-test]=../include ../test/mfail - DEPEND[dtlsclient-test]=../libcrypto.a ../libssl.a + SOURCE[dtlsserver-test]=dtlsserver.c test-corpus.c fuzz_rand.c + INCLUDE[dtlsserver-test]=../include + DEPEND[dtlsserver-test]=../libcrypto ../libssl - SOURCE[dtlsserver-test]=dtlsserver.c $FUZZTESTSRC fuzz_rand.c - INCLUDE[dtlsserver-test]=../include ../test/mfail - DEPEND[dtlsserver-test]=../libcrypto.a ../libssl.a - - SOURCE[echconfiglist_parser-test]=echconfiglist_parser.c $FUZZTESTSRC - INCLUDE[echconfiglist_parser-test]=../include ../test/mfail - DEPEND[echconfiglist_parser-test]=../libcrypto.a ../libssl.a - - SOURCE[pem-test]=pem.c $FUZZTESTSRC - INCLUDE[pem-test]=../include ../test/mfail + SOURCE[pem-test]=pem.c test-corpus.c + INCLUDE[pem-test]=../include DEPEND[pem-test]=../libcrypto.a - SOURCE[decoder-test]=decoder.c $FUZZTESTSRC fuzz_rand.c - INCLUDE[decoder-test]=../include ../test/mfail - DEPEND[decoder-test]=../libcrypto.a + SOURCE[decoder-test]=decoder.c test-corpus.c fuzz_rand.c + INCLUDE[decoder-test]=../include + DEPEND[decoder-test]=../libcrypto - SOURCE[hashtable-test]=hashtable.c $FUZZTESTSRC fuzz_rand.c - INCLUDE[hashtable-test]=../include ../test/mfail + SOURCE[hashtable-test]=hashtable.c test-corpus.c fuzz_rand.c + INCLUDE[hashtable-test]=../include DEPEND[hashtable-test]=../libcrypto.a - SOURCE[acert-test]=acert.c $FUZZTESTSRC - INCLUDE[acert-test]=../include ../test/mfail - DEPEND[acert-test]=../libcrypto.a + SOURCE[acert-test]=acert.c test-corpus.c + INCLUDE[acert-test]=../include + DEPEND[acert-test]=../libcrypto - SOURCE[punycode-test]=punycode.c $FUZZTESTSRC - INCLUDE[punycode-test]=../include ../test/mfail + SOURCE[punycode-test]=punycode.c test-corpus.c + INCLUDE[punycode-test]=../include DEPEND[punycode-test]=../libcrypto.a - SOURCE[smime-test]=smime.c $FUZZTESTSRC - INCLUDE[smime-test]=../include ../test/mfail - DEPEND[smime-test]=../libcrypto.a ../libssl.a + SOURCE[smime-test]=smime.c test-corpus.c + INCLUDE[smime-test]=../include + DEPEND[smime-test]=../libcrypto ../libssl - SOURCE[v3name-test]=v3name.c $FUZZTESTSRC - INCLUDE[v3name-test]=../include ../test/mfail + SOURCE[v3name-test]=v3name.c test-corpus.c + INCLUDE[v3name-test]=../include DEPEND[v3name-test]=../libcrypto.a - SOURCE[quic-client-test]=quic-client.c $FUZZTESTSRC fuzz_rand.c - INCLUDE[quic-client-test]=../include ../test/mfail + SOURCE[quic-client-test]=quic-client.c test-corpus.c fuzz_rand.c + INCLUDE[quic-client-test]=../include DEPEND[quic-client-test]=../libcrypto.a ../libssl.a - SOURCE[quic-server-test]=quic-server.c $FUZZTESTSRC fuzz_rand.c - INCLUDE[quic-server-test]=../include ../test/mfail + SOURCE[quic-server-test]=quic-server.c test-corpus.c fuzz_rand.c + INCLUDE[quic-server-test]=../include DEPEND[quic-server-test]=../libcrypto.a ../libssl.a - SOURCE[quic-srtm-test]=quic-srtm.c $FUZZTESTSRC fuzz_rand.c - INCLUDE[quic-srtm-test]=../include ../test/mfail + SOURCE[quic-srtm-test]=quic-srtm.c test-corpus.c fuzz_rand.c + INCLUDE[quic-srtm-test]=../include DEPEND[quic-srtm-test]=../libcrypto.a ../libssl.a - SOURCE[quic-lcidm-test]=quic-lcidm.c $FUZZTESTSRC fuzz_rand.c - INCLUDE[quic-lcidm-test]=../include ../test/mfail + SOURCE[quic-lcidm-test]=quic-lcidm.c test-corpus.c fuzz_rand.c + INCLUDE[quic-lcidm-test]=../include DEPEND[quic-lcidm-test]=../libcrypto.a ../libssl.a - SOURCE[quic-rcidm-test]=quic-rcidm.c $FUZZTESTSRC fuzz_rand.c - INCLUDE[quic-rcidm-test]=../include ../test/mfail + SOURCE[quic-rcidm-test]=quic-rcidm.c test-corpus.c fuzz_rand.c + INCLUDE[quic-rcidm-test]=../include DEPEND[quic-rcidm-test]=../libcrypto.a ../libssl.a - SOURCE[server-test]=server.c $FUZZTESTSRC fuzz_rand.c - INCLUDE[server-test]=../include ../test/mfail - DEPEND[server-test]=../libcrypto.a ../libssl.a + SOURCE[server-test]=server.c test-corpus.c fuzz_rand.c + INCLUDE[server-test]=../include + DEPEND[server-test]=../libcrypto ../libssl - SOURCE[x509-test]=x509.c $FUZZTESTSRC fuzz_rand.c - INCLUDE[x509-test]=../include ../test/mfail - DEPEND[x509-test]=../libcrypto.a + SOURCE[x509-test]=x509.c test-corpus.c fuzz_rand.c + INCLUDE[x509-test]=../include + DEPEND[x509-test]=../libcrypto - SOURCE[provider-test]=provider.c $FUZZTESTSRC - INCLUDE[provider-test]=../include ../test/mfail - DEPEND[provider-test]=../libcrypto.a + SOURCE[provider-test]=provider.c test-corpus.c + INCLUDE[provider-test]=../include + DEPEND[provider-test]=../libcrypto ENDIF diff --git a/fuzz/client.c b/fuzz/client.c index 64d30dd09e..d916218c27 100644 --- a/fuzz/client.c +++ b/fuzz/client.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -69,17 +69,15 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) return 0; /* This only fuzzes the initial flow from the client so far. */ - ctx = SSL_CTX_new(TLS_method()); + ctx = SSL_CTX_new(SSLv23_method()); if (ctx == NULL) goto end; client = SSL_new(ctx); if (client == NULL) goto end; - if (SSL_set_min_proto_version(client, 0) != 1) - goto end; - if (SSL_set_cipher_list(client, "ALL:eNULL:@SECLEVEL=0") != 1) - goto end; + OPENSSL_assert(SSL_set_min_proto_version(client, 0) == 1); + OPENSSL_assert(SSL_set_cipher_list(client, "ALL:eNULL:@SECLEVEL=0") == 1); SSL_set_tlsext_host_name(client, "localhost"); in = BIO_new(BIO_s_mem()); if (in == NULL) @@ -91,8 +89,7 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) } SSL_set_bio(client, in, out); SSL_set_connect_state(client); - if ((size_t)BIO_write(in, buf, (int)len) != len) - goto end; + OPENSSL_assert((size_t)BIO_write(in, buf, (int)len) == len); if (SSL_do_handshake(client) == 1) { /* Keep reading application data until error or EOF. */ uint8_t tmp[1024]; diff --git a/fuzz/cmp.c b/fuzz/cmp.c index ae4dcc033d..698c352a5b 100644 --- a/fuzz/cmp.c +++ b/fuzz/cmp.c @@ -1,5 +1,5 @@ /* - * Copyright 2007-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -176,31 +176,13 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) return 0; in = BIO_new(BIO_s_mem()); - if (in == NULL) { - ERR_clear_error(); - return 0; - } - if ((size_t)BIO_write(in, buf, (int)len) != len) { - BIO_free(in); - ERR_clear_error(); - return 0; - } - + OPENSSL_assert((size_t)BIO_write(in, buf, (int)len) == len); msg = d2i_OSSL_CMP_MSG_bio(in, NULL); if (msg != NULL) { BIO *out = BIO_new(BIO_s_null()); OSSL_CMP_SRV_CTX *srv_ctx = OSSL_CMP_SRV_CTX_new(NULL, NULL); OSSL_CMP_CTX *client_ctx = OSSL_CMP_CTX_new(NULL, NULL); - if (out == NULL) { - OSSL_CMP_CTX_free(client_ctx); - OSSL_CMP_SRV_CTX_free(srv_ctx); - OSSL_CMP_MSG_free(msg); - BIO_free(in); - ERR_clear_error(); - return 0; - } - i2d_OSSL_CMP_MSG_bio(out, msg); ASN1_item_print(out, (ASN1_VALUE *)msg, 4, ASN1_ITEM_rptr(OSSL_CMP_MSG), NULL); diff --git a/fuzz/cms.c b/fuzz/cms.c index d45bf1b63c..0cd8ea9551 100644 --- a/fuzz/cms.c +++ b/fuzz/cms.c @@ -34,23 +34,13 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) return 0; in = BIO_new(BIO_s_mem()); - if (in == NULL) { - ERR_clear_error(); - return 0; - } - if ((size_t)BIO_write(in, buf, (int)len) != len) { - BIO_free(in); - ERR_clear_error(); - return 0; - } + OPENSSL_assert((size_t)BIO_write(in, buf, (int)len) == len); cms = d2i_CMS_bio(in, NULL); if (cms != NULL) { BIO *out = BIO_new(BIO_s_null()); - if (out != NULL) { - i2d_CMS_bio(out, cms); - BIO_free(out); - } + i2d_CMS_bio(out, cms); + BIO_free(out); CMS_ContentInfo_free(cms); } diff --git a/fuzz/conf.c b/fuzz/conf.c index 116759a0a1..9c5353868b 100644 --- a/fuzz/conf.c +++ b/fuzz/conf.c @@ -33,15 +33,9 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) return 0; conf = NCONF_new(NULL); - if (conf == NULL) - return 0; in = BIO_new(BIO_s_mem()); - if (in == NULL) - goto end; - if ((size_t)BIO_write(in, buf, (int)len) != len) - goto end; + OPENSSL_assert((size_t)BIO_write(in, buf, (int)len) == len); NCONF_load_bio(conf, in, &eline); -end: NCONF_free(conf); BIO_free(in); ERR_clear_error(); diff --git a/fuzz/corpora b/fuzz/corpora index e79bbce6dc..ce771805c0 160000 --- a/fuzz/corpora +++ b/fuzz/corpora @@ -1 +1 @@ -Subproject commit e79bbce6dc62e794eab651d4be29b3d499d6df5c +Subproject commit ce771805c094d098c25a218bc8e9f7344eccbc5a diff --git a/fuzz/crl.c b/fuzz/crl.c index f704321ac5..c22f5d55e2 100644 --- a/fuzz/crl.c +++ b/fuzz/crl.c @@ -29,11 +29,8 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) X509_CRL *crl = d2i_X509_CRL(NULL, &p, (long)len); if (crl != NULL) { BIO *bio = BIO_new(BIO_s_null()); - - if (bio != NULL) { - X509_CRL_print(bio, crl); - BIO_free(bio); - } + X509_CRL_print(bio, crl); + BIO_free(bio); i2d_X509_CRL(crl, &der); OPENSSL_free(der); diff --git a/fuzz/ct.c b/fuzz/ct.c index 74fbf66c04..e46574d8eb 100644 --- a/fuzz/ct.c +++ b/fuzz/ct.c @@ -32,11 +32,8 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) STACK_OF(SCT) *scts = d2i_SCT_LIST(NULL, pp, (long)len); if (scts != NULL) { BIO *bio = BIO_new(BIO_s_null()); - - if (bio != NULL) { - SCT_LIST_print(scts, bio, 4, "\n", NULL); - BIO_free(bio); - } + SCT_LIST_print(scts, bio, 4, "\n", NULL); + BIO_free(bio); if (i2d_SCT_LIST(scts, &der)) { /* Silence unused result warning */ diff --git a/fuzz/decoder.c b/fuzz/decoder.c index 227c24fd71..3a9a48ad21 100644 --- a/fuzz/decoder.c +++ b/fuzz/decoder.c @@ -25,8 +25,6 @@ int FuzzerInitialize(int *argc, char ***argv) NULL); pctx = ASN1_PCTX_new(); - if (pctx == NULL) - return 0; ASN1_PCTX_set_flags(pctx, ASN1_PCTX_FLAGS_SHOW_ABSENT | ASN1_PCTX_FLAGS_SHOW_SEQUENCE | ASN1_PCTX_FLAGS_SHOW_SSOF | ASN1_PCTX_FLAGS_SHOW_TYPE | ASN1_PCTX_FLAGS_SHOW_FIELD_STRUCT_NAME); ASN1_PCTX_set_str_flags(pctx, ASN1_STRFLGS_UTF8_CONVERT | ASN1_STRFLGS_SHOW_TYPE | ASN1_STRFLGS_DUMP_ALL); @@ -43,15 +41,9 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) BIO *bio; bio = BIO_new(BIO_s_null()); - if (bio == NULL) { - ERR_clear_error(); - return 0; - } dctx = OSSL_DECODER_CTX_new_for_pkey(&pkey, NULL, NULL, NULL, 0, NULL, NULL); if (dctx == NULL) { - BIO_free(bio); - ERR_clear_error(); return 0; } if (OSSL_DECODER_from_data(dctx, &buf, &len)) { @@ -62,29 +54,27 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) EVP_PKEY_print_params(bio, pkey, 1, pctx); pkey2 = EVP_PKEY_dup(pkey); - if (pkey2 != NULL) { - EVP_PKEY_eq(pkey, pkey2); - EVP_PKEY_free(pkey2); - } + OPENSSL_assert(pkey2 != NULL); + EVP_PKEY_eq(pkey, pkey2); + EVP_PKEY_free(pkey2); ctx = EVP_PKEY_CTX_new(pkey, NULL); - if (ctx != NULL) { - /* - * Param check will take too long time on large DH parameters. - * Skip it. - */ - if ((!EVP_PKEY_is_a(pkey, "DH") && !EVP_PKEY_is_a(pkey, "DHX")) - || EVP_PKEY_get_bits(pkey) <= 2048) - EVP_PKEY_param_check(ctx); + /* + * Param check will take too long time on large DH parameters. + * Skip it. + */ + if ((!EVP_PKEY_is_a(pkey, "DH") && !EVP_PKEY_is_a(pkey, "DHX")) + || EVP_PKEY_get_bits(pkey) <= 2048) + EVP_PKEY_param_check(ctx); - EVP_PKEY_public_check(ctx); - /* Private and pairwise checks are unbounded, skip for large keys. */ - if (EVP_PKEY_get_bits(pkey) <= 4096) { - EVP_PKEY_private_check(ctx); - EVP_PKEY_pairwise_check(ctx); - } - EVP_PKEY_CTX_free(ctx); + EVP_PKEY_public_check(ctx); + /* Private and pairwise checks are unbounded, skip for large keys. */ + if (EVP_PKEY_get_bits(pkey) <= 4096) { + EVP_PKEY_private_check(ctx); + EVP_PKEY_pairwise_check(ctx); } + OPENSSL_assert(ctx != NULL); + EVP_PKEY_CTX_free(ctx); EVP_PKEY_free(pkey); } OSSL_DECODER_CTX_free(dctx); diff --git a/fuzz/dtlsclient.c b/fuzz/dtlsclient.c index 2dc5ed709c..f07bc6ed67 100644 --- a/fuzz/dtlsclient.c +++ b/fuzz/dtlsclient.c @@ -76,10 +76,8 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) client = SSL_new(ctx); if (client == NULL) goto end; - if (SSL_set_min_proto_version(client, 0) != 1) - goto end; - if (SSL_set_cipher_list(client, "ALL:eNULL:@SECLEVEL=0") != 1) - goto end; + OPENSSL_assert(SSL_set_min_proto_version(client, 0) == 1); + OPENSSL_assert(SSL_set_cipher_list(client, "ALL:eNULL:@SECLEVEL=0") == 1); SSL_set_tlsext_host_name(client, "localhost"); in = BIO_new(BIO_s_mem()); if (in == NULL) @@ -91,8 +89,7 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) } SSL_set_bio(client, in, out); SSL_set_connect_state(client); - if ((size_t)BIO_write(in, buf, (int)len) != len) - goto end; + OPENSSL_assert((size_t)BIO_write(in, buf, (int)len) == len); if (SSL_do_handshake(client) == 1) { /* Keep reading application data until error or EOF. */ uint8_t tmp[1024]; diff --git a/fuzz/dtlsserver.c b/fuzz/dtlsserver.c index 84ded9a4df..cace23d2c7 100644 --- a/fuzz/dtlsserver.c +++ b/fuzz/dtlsserver.c @@ -50,174 +50,1331 @@ a2vbz3gpOsl87U0c01JCl9SZXDSO09w= -----END CERTIFICATE----- */ static const uint8_t RSACertificatePEM[] = { - 0x2d, 0x2d, 0x2d, 0x2d, 0x2d, 0x42, 0x45, 0x47, - 0x49, 0x4e, 0x20, 0x43, 0x45, 0x52, 0x54, 0x49, - 0x46, 0x49, 0x43, 0x41, 0x54, 0x45, 0x2d, 0x2d, - 0x2d, 0x2d, 0x2d, 0x0a, 0x4d, 0x49, 0x49, 0x44, - 0x6f, 0x7a, 0x43, 0x43, 0x41, 0x6f, 0x75, 0x67, - 0x41, 0x77, 0x49, 0x42, 0x41, 0x67, 0x49, 0x55, - 0x53, 0x4b, 0x77, 0x51, 0x44, 0x31, 0x71, 0x52, - 0x74, 0x53, 0x2b, 0x6c, 0x72, 0x69, 0x64, 0x61, - 0x77, 0x6d, 0x61, 0x59, 0x4b, 0x36, 0x63, 0x65, - 0x6a, 0x32, 0x6b, 0x77, 0x44, 0x51, 0x59, 0x4a, - 0x4b, 0x6f, 0x5a, 0x49, 0x68, 0x76, 0x63, 0x4e, - 0x41, 0x51, 0x45, 0x4c, 0x0a, 0x42, 0x51, 0x41, - 0x77, 0x59, 0x54, 0x45, 0x4c, 0x4d, 0x41, 0x6b, - 0x47, 0x41, 0x31, 0x55, 0x45, 0x42, 0x68, 0x4d, - 0x43, 0x62, 0x6d, 0x38, 0x78, 0x43, 0x7a, 0x41, - 0x4a, 0x42, 0x67, 0x4e, 0x56, 0x42, 0x41, 0x67, - 0x4d, 0x41, 0x6d, 0x35, 0x76, 0x4d, 0x51, 0x73, - 0x77, 0x43, 0x51, 0x59, 0x44, 0x56, 0x51, 0x51, - 0x48, 0x44, 0x41, 0x4a, 0x75, 0x62, 0x7a, 0x45, - 0x4c, 0x4d, 0x41, 0x6b, 0x47, 0x0a, 0x41, 0x31, - 0x55, 0x45, 0x43, 0x67, 0x77, 0x43, 0x62, 0x6d, - 0x38, 0x78, 0x43, 0x7a, 0x41, 0x4a, 0x42, 0x67, - 0x4e, 0x56, 0x42, 0x41, 0x73, 0x4d, 0x41, 0x6d, - 0x35, 0x76, 0x4d, 0x51, 0x73, 0x77, 0x43, 0x51, - 0x59, 0x44, 0x56, 0x51, 0x51, 0x44, 0x44, 0x41, - 0x4a, 0x75, 0x62, 0x7a, 0x45, 0x52, 0x4d, 0x41, - 0x38, 0x47, 0x43, 0x53, 0x71, 0x47, 0x53, 0x49, - 0x62, 0x33, 0x44, 0x51, 0x45, 0x4a, 0x0a, 0x41, - 0x52, 0x59, 0x43, 0x62, 0x6d, 0x38, 0x77, 0x48, - 0x68, 0x63, 0x4e, 0x4d, 0x6a, 0x51, 0x77, 0x4d, - 0x6a, 0x49, 0x34, 0x4d, 0x54, 0x6b, 0x7a, 0x4e, - 0x7a, 0x45, 0x77, 0x57, 0x68, 0x63, 0x4e, 0x4d, - 0x6a, 0x55, 0x77, 0x4d, 0x6a, 0x49, 0x33, 0x4d, - 0x54, 0x6b, 0x7a, 0x4e, 0x7a, 0x45, 0x77, 0x57, - 0x6a, 0x42, 0x68, 0x4d, 0x51, 0x73, 0x77, 0x43, - 0x51, 0x59, 0x44, 0x56, 0x51, 0x51, 0x47, 0x0a, - 0x45, 0x77, 0x4a, 0x75, 0x62, 0x7a, 0x45, 0x4c, - 0x4d, 0x41, 0x6b, 0x47, 0x41, 0x31, 0x55, 0x45, - 0x43, 0x41, 0x77, 0x43, 0x62, 0x6d, 0x38, 0x78, - 0x43, 0x7a, 0x41, 0x4a, 0x42, 0x67, 0x4e, 0x56, - 0x42, 0x41, 0x63, 0x4d, 0x41, 0x6d, 0x35, 0x76, - 0x4d, 0x51, 0x73, 0x77, 0x43, 0x51, 0x59, 0x44, - 0x56, 0x51, 0x51, 0x4b, 0x44, 0x41, 0x4a, 0x75, - 0x62, 0x7a, 0x45, 0x4c, 0x4d, 0x41, 0x6b, 0x47, - 0x0a, 0x41, 0x31, 0x55, 0x45, 0x43, 0x77, 0x77, - 0x43, 0x62, 0x6d, 0x38, 0x78, 0x43, 0x7a, 0x41, - 0x4a, 0x42, 0x67, 0x4e, 0x56, 0x42, 0x41, 0x4d, - 0x4d, 0x41, 0x6d, 0x35, 0x76, 0x4d, 0x52, 0x45, - 0x77, 0x44, 0x77, 0x59, 0x4a, 0x4b, 0x6f, 0x5a, - 0x49, 0x68, 0x76, 0x63, 0x4e, 0x41, 0x51, 0x6b, - 0x42, 0x46, 0x67, 0x4a, 0x75, 0x62, 0x7a, 0x43, - 0x43, 0x41, 0x53, 0x49, 0x77, 0x44, 0x51, 0x59, - 0x4a, 0x0a, 0x4b, 0x6f, 0x5a, 0x49, 0x68, 0x76, - 0x63, 0x4e, 0x41, 0x51, 0x45, 0x42, 0x42, 0x51, - 0x41, 0x44, 0x67, 0x67, 0x45, 0x50, 0x41, 0x44, - 0x43, 0x43, 0x41, 0x51, 0x6f, 0x43, 0x67, 0x67, - 0x45, 0x42, 0x41, 0x4c, 0x57, 0x5a, 0x42, 0x39, - 0x4d, 0x74, 0x61, 0x73, 0x30, 0x56, 0x39, 0x53, - 0x79, 0x61, 0x2b, 0x55, 0x68, 0x45, 0x61, 0x62, - 0x77, 0x7a, 0x73, 0x33, 0x45, 0x6f, 0x6c, 0x2b, - 0x2f, 0x4d, 0x0a, 0x68, 0x77, 0x55, 0x46, 0x57, - 0x49, 0x46, 0x72, 0x72, 0x38, 0x74, 0x56, 0x79, - 0x59, 0x76, 0x67, 0x38, 0x58, 0x73, 0x2f, 0x4b, - 0x6e, 0x43, 0x32, 0x56, 0x61, 0x45, 0x70, 0x6e, - 0x45, 0x6c, 0x74, 0x42, 0x4e, 0x4c, 0x61, 0x4f, - 0x41, 0x44, 0x5a, 0x47, 0x55, 0x75, 0x58, 0x7a, - 0x7a, 0x35, 0x45, 0x62, 0x63, 0x63, 0x62, 0x32, - 0x69, 0x31, 0x38, 0x67, 0x68, 0x76, 0x4d, 0x44, - 0x58, 0x35, 0x6f, 0x0a, 0x4f, 0x77, 0x41, 0x41, - 0x69, 0x64, 0x4c, 0x33, 0x74, 0x76, 0x36, 0x6c, - 0x68, 0x38, 0x2f, 0x56, 0x75, 0x6a, 0x38, 0x74, - 0x70, 0x4c, 0x41, 0x35, 0x33, 0x53, 0x44, 0x52, - 0x35, 0x56, 0x54, 0x51, 0x63, 0x78, 0x69, 0x74, - 0x69, 0x70, 0x73, 0x63, 0x63, 0x6a, 0x61, 0x63, - 0x48, 0x44, 0x66, 0x74, 0x54, 0x71, 0x44, 0x41, - 0x37, 0x2b, 0x39, 0x34, 0x53, 0x54, 0x54, 0x38, - 0x51, 0x53, 0x48, 0x74, 0x0a, 0x57, 0x75, 0x35, - 0x46, 0x6d, 0x58, 0x50, 0x4b, 0x76, 0x4a, 0x4c, - 0x6d, 0x50, 0x75, 0x4b, 0x51, 0x4a, 0x4d, 0x62, - 0x4f, 0x4a, 0x53, 0x47, 0x44, 0x4a, 0x4c, 0x76, - 0x64, 0x54, 0x2f, 0x30, 0x64, 0x79, 0x4d, 0x39, - 0x61, 0x55, 0x33, 0x78, 0x4b, 0x77, 0x36, 0x34, - 0x69, 0x76, 0x37, 0x53, 0x33, 0x6c, 0x61, 0x45, - 0x52, 0x57, 0x79, 0x57, 0x34, 0x2f, 0x4f, 0x65, - 0x6d, 0x4d, 0x51, 0x58, 0x73, 0x0a, 0x69, 0x2b, - 0x6b, 0x62, 0x61, 0x6e, 0x70, 0x56, 0x4e, 0x4a, - 0x56, 0x6d, 0x71, 0x54, 0x74, 0x53, 0x2b, 0x71, - 0x2f, 0x46, 0x79, 0x59, 0x76, 0x76, 0x72, 0x31, - 0x4e, 0x70, 0x58, 0x30, 0x4f, 0x63, 0x2f, 0x41, - 0x35, 0x48, 0x32, 0x48, 0x59, 0x51, 0x36, 0x66, - 0x36, 0x50, 0x33, 0x6e, 0x76, 0x4a, 0x32, 0x32, - 0x49, 0x4f, 0x58, 0x6f, 0x49, 0x63, 0x4e, 0x6a, - 0x49, 0x31, 0x46, 0x6d, 0x4b, 0x62, 0x0a, 0x58, - 0x33, 0x4e, 0x4a, 0x48, 0x65, 0x74, 0x48, 0x58, - 0x74, 0x79, 0x5a, 0x4b, 0x58, 0x63, 0x66, 0x70, - 0x69, 0x7a, 0x6c, 0x6a, 0x73, 0x4e, 0x76, 0x62, - 0x66, 0x66, 0x73, 0x4c, 0x36, 0x74, 0x77, 0x78, - 0x6a, 0x6a, 0x43, 0x52, 0x33, 0x4a, 0x64, 0x55, - 0x71, 0x50, 0x31, 0x78, 0x45, 0x43, 0x65, 0x75, - 0x6f, 0x4c, 0x42, 0x4d, 0x7a, 0x6b, 0x43, 0x41, - 0x77, 0x45, 0x41, 0x41, 0x61, 0x4e, 0x54, 0x0a, - 0x4d, 0x46, 0x45, 0x77, 0x48, 0x51, 0x59, 0x44, - 0x56, 0x52, 0x30, 0x4f, 0x42, 0x42, 0x59, 0x45, - 0x46, 0x4b, 0x5a, 0x32, 0x62, 0x39, 0x49, 0x4a, - 0x33, 0x59, 0x57, 0x43, 0x59, 0x79, 0x4d, 0x6b, - 0x52, 0x4f, 0x6a, 0x74, 0x6a, 0x46, 0x37, 0x43, - 0x78, 0x73, 0x66, 0x61, 0x4d, 0x42, 0x38, 0x47, - 0x41, 0x31, 0x55, 0x64, 0x49, 0x77, 0x51, 0x59, - 0x4d, 0x42, 0x61, 0x41, 0x46, 0x4b, 0x5a, 0x32, - 0x0a, 0x62, 0x39, 0x49, 0x4a, 0x33, 0x59, 0x57, - 0x43, 0x59, 0x79, 0x4d, 0x6b, 0x52, 0x4f, 0x6a, - 0x74, 0x6a, 0x46, 0x37, 0x43, 0x78, 0x73, 0x66, - 0x61, 0x4d, 0x41, 0x38, 0x47, 0x41, 0x31, 0x55, - 0x64, 0x45, 0x77, 0x45, 0x42, 0x2f, 0x77, 0x51, - 0x46, 0x4d, 0x41, 0x4d, 0x42, 0x41, 0x66, 0x38, - 0x77, 0x44, 0x51, 0x59, 0x4a, 0x4b, 0x6f, 0x5a, - 0x49, 0x68, 0x76, 0x63, 0x4e, 0x41, 0x51, 0x45, - 0x4c, 0x0a, 0x42, 0x51, 0x41, 0x44, 0x67, 0x67, - 0x45, 0x42, 0x41, 0x47, 0x4a, 0x6f, 0x48, 0x44, - 0x54, 0x73, 0x41, 0x69, 0x75, 0x52, 0x74, 0x41, - 0x43, 0x54, 0x47, 0x69, 0x47, 0x7a, 0x2f, 0x6f, - 0x79, 0x4e, 0x5a, 0x66, 0x48, 0x2f, 0x4f, 0x55, - 0x4a, 0x61, 0x69, 0x6a, 0x55, 0x4d, 0x61, 0x4c, - 0x62, 0x48, 0x64, 0x2f, 0x4a, 0x47, 0x32, 0x4c, - 0x36, 0x67, 0x74, 0x70, 0x41, 0x43, 0x59, 0x59, - 0x32, 0x62, 0x0a, 0x41, 0x6f, 0x4c, 0x6b, 0x49, - 0x63, 0x43, 0x6c, 0x33, 0x38, 0x6e, 0x73, 0x4c, - 0x59, 0x4d, 0x4c, 0x5a, 0x33, 0x32, 0x42, 0x62, - 0x63, 0x35, 0x6a, 0x6e, 0x50, 0x2f, 0x51, 0x79, - 0x33, 0x64, 0x32, 0x48, 0x4b, 0x73, 0x54, 0x4a, - 0x35, 0x49, 0x74, 0x34, 0x71, 0x78, 0x44, 0x67, - 0x74, 0x62, 0x74, 0x70, 0x55, 0x38, 0x65, 0x35, - 0x4d, 0x68, 0x45, 0x65, 0x4a, 0x6f, 0x65, 0x4d, - 0x48, 0x4f, 0x43, 0x0a, 0x66, 0x69, 0x7a, 0x62, - 0x63, 0x57, 0x63, 0x37, 0x57, 0x37, 0x6d, 0x32, - 0x53, 0x4c, 0x66, 0x70, 0x65, 0x51, 0x4a, 0x57, - 0x4d, 0x67, 0x75, 0x32, 0x44, 0x61, 0x30, 0x48, - 0x59, 0x45, 0x44, 0x53, 0x2f, 0x78, 0x7a, 0x4c, - 0x6e, 0x37, 0x70, 0x78, 0x51, 0x67, 0x5a, 0x70, - 0x4f, 0x72, 0x4d, 0x51, 0x37, 0x49, 0x68, 0x69, - 0x31, 0x6a, 0x77, 0x58, 0x66, 0x4b, 0x46, 0x71, - 0x49, 0x49, 0x61, 0x6c, 0x0a, 0x67, 0x36, 0x53, - 0x69, 0x6a, 0x52, 0x47, 0x58, 0x68, 0x37, 0x6f, - 0x6e, 0x45, 0x41, 0x78, 0x45, 0x6d, 0x4b, 0x4c, - 0x6b, 0x70, 0x56, 0x51, 0x52, 0x71, 0x36, 0x33, - 0x33, 0x42, 0x59, 0x50, 0x56, 0x36, 0x6f, 0x64, - 0x78, 0x74, 0x58, 0x44, 0x68, 0x78, 0x79, 0x4a, - 0x4b, 0x79, 0x47, 0x6a, 0x53, 0x4a, 0x73, 0x51, - 0x6f, 0x4b, 0x76, 0x39, 0x6f, 0x43, 0x46, 0x32, - 0x6b, 0x41, 0x64, 0x41, 0x69, 0x0a, 0x43, 0x76, - 0x76, 0x61, 0x74, 0x71, 0x52, 0x57, 0x52, 0x77, - 0x67, 0x49, 0x65, 0x6c, 0x6e, 0x31, 0x53, 0x77, - 0x39, 0x45, 0x65, 0x36, 0x63, 0x54, 0x59, 0x5a, - 0x43, 0x47, 0x32, 0x55, 0x2b, 0x2f, 0x55, 0x66, - 0x2b, 0x4c, 0x73, 0x37, 0x66, 0x6a, 0x4e, 0x38, - 0x74, 0x72, 0x62, 0x2f, 0x53, 0x68, 0x6d, 0x78, - 0x6f, 0x38, 0x64, 0x6f, 0x2f, 0x6e, 0x70, 0x42, - 0x6e, 0x7a, 0x38, 0x6a, 0x2b, 0x31, 0x0a, 0x61, - 0x32, 0x76, 0x62, 0x7a, 0x33, 0x67, 0x70, 0x4f, - 0x73, 0x6c, 0x38, 0x37, 0x55, 0x30, 0x63, 0x30, - 0x31, 0x4a, 0x43, 0x6c, 0x39, 0x53, 0x5a, 0x58, - 0x44, 0x53, 0x4f, 0x30, 0x39, 0x77, 0x3d, 0x0a, - 0x2d, 0x2d, 0x2d, 0x2d, 0x2d, 0x45, 0x4e, 0x44, - 0x20, 0x43, 0x45, 0x52, 0x54, 0x49, 0x46, 0x49, - 0x43, 0x41, 0x54, 0x45, 0x2d, 0x2d, 0x2d, 0x2d, - 0x2d, 0x0a + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x42, + 0x45, + 0x47, + 0x49, + 0x4e, + 0x20, + 0x43, + 0x45, + 0x52, + 0x54, + 0x49, + 0x46, + 0x49, + 0x43, + 0x41, + 0x54, + 0x45, + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x0a, + 0x4d, + 0x49, + 0x49, + 0x44, + 0x6f, + 0x7a, + 0x43, + 0x43, + 0x41, + 0x6f, + 0x75, + 0x67, + 0x41, + 0x77, + 0x49, + 0x42, + 0x41, + 0x67, + 0x49, + 0x55, + 0x53, + 0x4b, + 0x77, + 0x51, + 0x44, + 0x31, + 0x71, + 0x52, + 0x74, + 0x53, + 0x2b, + 0x6c, + 0x72, + 0x69, + 0x64, + 0x61, + 0x77, + 0x6d, + 0x61, + 0x59, + 0x4b, + 0x36, + 0x63, + 0x65, + 0x6a, + 0x32, + 0x6b, + 0x77, + 0x44, + 0x51, + 0x59, + 0x4a, + 0x4b, + 0x6f, + 0x5a, + 0x49, + 0x68, + 0x76, + 0x63, + 0x4e, + 0x41, + 0x51, + 0x45, + 0x4c, + 0x0a, + 0x42, + 0x51, + 0x41, + 0x77, + 0x59, + 0x54, + 0x45, + 0x4c, + 0x4d, + 0x41, + 0x6b, + 0x47, + 0x41, + 0x31, + 0x55, + 0x45, + 0x42, + 0x68, + 0x4d, + 0x43, + 0x62, + 0x6d, + 0x38, + 0x78, + 0x43, + 0x7a, + 0x41, + 0x4a, + 0x42, + 0x67, + 0x4e, + 0x56, + 0x42, + 0x41, + 0x67, + 0x4d, + 0x41, + 0x6d, + 0x35, + 0x76, + 0x4d, + 0x51, + 0x73, + 0x77, + 0x43, + 0x51, + 0x59, + 0x44, + 0x56, + 0x51, + 0x51, + 0x48, + 0x44, + 0x41, + 0x4a, + 0x75, + 0x62, + 0x7a, + 0x45, + 0x4c, + 0x4d, + 0x41, + 0x6b, + 0x47, + 0x0a, + 0x41, + 0x31, + 0x55, + 0x45, + 0x43, + 0x67, + 0x77, + 0x43, + 0x62, + 0x6d, + 0x38, + 0x78, + 0x43, + 0x7a, + 0x41, + 0x4a, + 0x42, + 0x67, + 0x4e, + 0x56, + 0x42, + 0x41, + 0x73, + 0x4d, + 0x41, + 0x6d, + 0x35, + 0x76, + 0x4d, + 0x51, + 0x73, + 0x77, + 0x43, + 0x51, + 0x59, + 0x44, + 0x56, + 0x51, + 0x51, + 0x44, + 0x44, + 0x41, + 0x4a, + 0x75, + 0x62, + 0x7a, + 0x45, + 0x52, + 0x4d, + 0x41, + 0x38, + 0x47, + 0x43, + 0x53, + 0x71, + 0x47, + 0x53, + 0x49, + 0x62, + 0x33, + 0x44, + 0x51, + 0x45, + 0x4a, + 0x0a, + 0x41, + 0x52, + 0x59, + 0x43, + 0x62, + 0x6d, + 0x38, + 0x77, + 0x48, + 0x68, + 0x63, + 0x4e, + 0x4d, + 0x6a, + 0x51, + 0x77, + 0x4d, + 0x6a, + 0x49, + 0x34, + 0x4d, + 0x54, + 0x6b, + 0x7a, + 0x4e, + 0x7a, + 0x45, + 0x77, + 0x57, + 0x68, + 0x63, + 0x4e, + 0x4d, + 0x6a, + 0x55, + 0x77, + 0x4d, + 0x6a, + 0x49, + 0x33, + 0x4d, + 0x54, + 0x6b, + 0x7a, + 0x4e, + 0x7a, + 0x45, + 0x77, + 0x57, + 0x6a, + 0x42, + 0x68, + 0x4d, + 0x51, + 0x73, + 0x77, + 0x43, + 0x51, + 0x59, + 0x44, + 0x56, + 0x51, + 0x51, + 0x47, + 0x0a, + 0x45, + 0x77, + 0x4a, + 0x75, + 0x62, + 0x7a, + 0x45, + 0x4c, + 0x4d, + 0x41, + 0x6b, + 0x47, + 0x41, + 0x31, + 0x55, + 0x45, + 0x43, + 0x41, + 0x77, + 0x43, + 0x62, + 0x6d, + 0x38, + 0x78, + 0x43, + 0x7a, + 0x41, + 0x4a, + 0x42, + 0x67, + 0x4e, + 0x56, + 0x42, + 0x41, + 0x63, + 0x4d, + 0x41, + 0x6d, + 0x35, + 0x76, + 0x4d, + 0x51, + 0x73, + 0x77, + 0x43, + 0x51, + 0x59, + 0x44, + 0x56, + 0x51, + 0x51, + 0x4b, + 0x44, + 0x41, + 0x4a, + 0x75, + 0x62, + 0x7a, + 0x45, + 0x4c, + 0x4d, + 0x41, + 0x6b, + 0x47, + 0x0a, + 0x41, + 0x31, + 0x55, + 0x45, + 0x43, + 0x77, + 0x77, + 0x43, + 0x62, + 0x6d, + 0x38, + 0x78, + 0x43, + 0x7a, + 0x41, + 0x4a, + 0x42, + 0x67, + 0x4e, + 0x56, + 0x42, + 0x41, + 0x4d, + 0x4d, + 0x41, + 0x6d, + 0x35, + 0x76, + 0x4d, + 0x52, + 0x45, + 0x77, + 0x44, + 0x77, + 0x59, + 0x4a, + 0x4b, + 0x6f, + 0x5a, + 0x49, + 0x68, + 0x76, + 0x63, + 0x4e, + 0x41, + 0x51, + 0x6b, + 0x42, + 0x46, + 0x67, + 0x4a, + 0x75, + 0x62, + 0x7a, + 0x43, + 0x43, + 0x41, + 0x53, + 0x49, + 0x77, + 0x44, + 0x51, + 0x59, + 0x4a, + 0x0a, + 0x4b, + 0x6f, + 0x5a, + 0x49, + 0x68, + 0x76, + 0x63, + 0x4e, + 0x41, + 0x51, + 0x45, + 0x42, + 0x42, + 0x51, + 0x41, + 0x44, + 0x67, + 0x67, + 0x45, + 0x50, + 0x41, + 0x44, + 0x43, + 0x43, + 0x41, + 0x51, + 0x6f, + 0x43, + 0x67, + 0x67, + 0x45, + 0x42, + 0x41, + 0x4c, + 0x57, + 0x5a, + 0x42, + 0x39, + 0x4d, + 0x74, + 0x61, + 0x73, + 0x30, + 0x56, + 0x39, + 0x53, + 0x79, + 0x61, + 0x2b, + 0x55, + 0x68, + 0x45, + 0x61, + 0x62, + 0x77, + 0x7a, + 0x73, + 0x33, + 0x45, + 0x6f, + 0x6c, + 0x2b, + 0x2f, + 0x4d, + 0x0a, + 0x68, + 0x77, + 0x55, + 0x46, + 0x57, + 0x49, + 0x46, + 0x72, + 0x72, + 0x38, + 0x74, + 0x56, + 0x79, + 0x59, + 0x76, + 0x67, + 0x38, + 0x58, + 0x73, + 0x2f, + 0x4b, + 0x6e, + 0x43, + 0x32, + 0x56, + 0x61, + 0x45, + 0x70, + 0x6e, + 0x45, + 0x6c, + 0x74, + 0x42, + 0x4e, + 0x4c, + 0x61, + 0x4f, + 0x41, + 0x44, + 0x5a, + 0x47, + 0x55, + 0x75, + 0x58, + 0x7a, + 0x7a, + 0x35, + 0x45, + 0x62, + 0x63, + 0x63, + 0x62, + 0x32, + 0x69, + 0x31, + 0x38, + 0x67, + 0x68, + 0x76, + 0x4d, + 0x44, + 0x58, + 0x35, + 0x6f, + 0x0a, + 0x4f, + 0x77, + 0x41, + 0x41, + 0x69, + 0x64, + 0x4c, + 0x33, + 0x74, + 0x76, + 0x36, + 0x6c, + 0x68, + 0x38, + 0x2f, + 0x56, + 0x75, + 0x6a, + 0x38, + 0x74, + 0x70, + 0x4c, + 0x41, + 0x35, + 0x33, + 0x53, + 0x44, + 0x52, + 0x35, + 0x56, + 0x54, + 0x51, + 0x63, + 0x78, + 0x69, + 0x74, + 0x69, + 0x70, + 0x73, + 0x63, + 0x63, + 0x6a, + 0x61, + 0x63, + 0x48, + 0x44, + 0x66, + 0x74, + 0x54, + 0x71, + 0x44, + 0x41, + 0x37, + 0x2b, + 0x39, + 0x34, + 0x53, + 0x54, + 0x54, + 0x38, + 0x51, + 0x53, + 0x48, + 0x74, + 0x0a, + 0x57, + 0x75, + 0x35, + 0x46, + 0x6d, + 0x58, + 0x50, + 0x4b, + 0x76, + 0x4a, + 0x4c, + 0x6d, + 0x50, + 0x75, + 0x4b, + 0x51, + 0x4a, + 0x4d, + 0x62, + 0x4f, + 0x4a, + 0x53, + 0x47, + 0x44, + 0x4a, + 0x4c, + 0x76, + 0x64, + 0x54, + 0x2f, + 0x30, + 0x64, + 0x79, + 0x4d, + 0x39, + 0x61, + 0x55, + 0x33, + 0x78, + 0x4b, + 0x77, + 0x36, + 0x34, + 0x69, + 0x76, + 0x37, + 0x53, + 0x33, + 0x6c, + 0x61, + 0x45, + 0x52, + 0x57, + 0x79, + 0x57, + 0x34, + 0x2f, + 0x4f, + 0x65, + 0x6d, + 0x4d, + 0x51, + 0x58, + 0x73, + 0x0a, + 0x69, + 0x2b, + 0x6b, + 0x62, + 0x61, + 0x6e, + 0x70, + 0x56, + 0x4e, + 0x4a, + 0x56, + 0x6d, + 0x71, + 0x54, + 0x74, + 0x53, + 0x2b, + 0x71, + 0x2f, + 0x46, + 0x79, + 0x59, + 0x76, + 0x76, + 0x72, + 0x31, + 0x4e, + 0x70, + 0x58, + 0x30, + 0x4f, + 0x63, + 0x2f, + 0x41, + 0x35, + 0x48, + 0x32, + 0x48, + 0x59, + 0x51, + 0x36, + 0x66, + 0x36, + 0x50, + 0x33, + 0x6e, + 0x76, + 0x4a, + 0x32, + 0x32, + 0x49, + 0x4f, + 0x58, + 0x6f, + 0x49, + 0x63, + 0x4e, + 0x6a, + 0x49, + 0x31, + 0x46, + 0x6d, + 0x4b, + 0x62, + 0x0a, + 0x58, + 0x33, + 0x4e, + 0x4a, + 0x48, + 0x65, + 0x74, + 0x48, + 0x58, + 0x74, + 0x79, + 0x5a, + 0x4b, + 0x58, + 0x63, + 0x66, + 0x70, + 0x69, + 0x7a, + 0x6c, + 0x6a, + 0x73, + 0x4e, + 0x76, + 0x62, + 0x66, + 0x66, + 0x73, + 0x4c, + 0x36, + 0x74, + 0x77, + 0x78, + 0x6a, + 0x6a, + 0x43, + 0x52, + 0x33, + 0x4a, + 0x64, + 0x55, + 0x71, + 0x50, + 0x31, + 0x78, + 0x45, + 0x43, + 0x65, + 0x75, + 0x6f, + 0x4c, + 0x42, + 0x4d, + 0x7a, + 0x6b, + 0x43, + 0x41, + 0x77, + 0x45, + 0x41, + 0x41, + 0x61, + 0x4e, + 0x54, + 0x0a, + 0x4d, + 0x46, + 0x45, + 0x77, + 0x48, + 0x51, + 0x59, + 0x44, + 0x56, + 0x52, + 0x30, + 0x4f, + 0x42, + 0x42, + 0x59, + 0x45, + 0x46, + 0x4b, + 0x5a, + 0x32, + 0x62, + 0x39, + 0x49, + 0x4a, + 0x33, + 0x59, + 0x57, + 0x43, + 0x59, + 0x79, + 0x4d, + 0x6b, + 0x52, + 0x4f, + 0x6a, + 0x74, + 0x6a, + 0x46, + 0x37, + 0x43, + 0x78, + 0x73, + 0x66, + 0x61, + 0x4d, + 0x42, + 0x38, + 0x47, + 0x41, + 0x31, + 0x55, + 0x64, + 0x49, + 0x77, + 0x51, + 0x59, + 0x4d, + 0x42, + 0x61, + 0x41, + 0x46, + 0x4b, + 0x5a, + 0x32, + 0x0a, + 0x62, + 0x39, + 0x49, + 0x4a, + 0x33, + 0x59, + 0x57, + 0x43, + 0x59, + 0x79, + 0x4d, + 0x6b, + 0x52, + 0x4f, + 0x6a, + 0x74, + 0x6a, + 0x46, + 0x37, + 0x43, + 0x78, + 0x73, + 0x66, + 0x61, + 0x4d, + 0x41, + 0x38, + 0x47, + 0x41, + 0x31, + 0x55, + 0x64, + 0x45, + 0x77, + 0x45, + 0x42, + 0x2f, + 0x77, + 0x51, + 0x46, + 0x4d, + 0x41, + 0x4d, + 0x42, + 0x41, + 0x66, + 0x38, + 0x77, + 0x44, + 0x51, + 0x59, + 0x4a, + 0x4b, + 0x6f, + 0x5a, + 0x49, + 0x68, + 0x76, + 0x63, + 0x4e, + 0x41, + 0x51, + 0x45, + 0x4c, + 0x0a, + 0x42, + 0x51, + 0x41, + 0x44, + 0x67, + 0x67, + 0x45, + 0x42, + 0x41, + 0x47, + 0x4a, + 0x6f, + 0x48, + 0x44, + 0x54, + 0x73, + 0x41, + 0x69, + 0x75, + 0x52, + 0x74, + 0x41, + 0x43, + 0x54, + 0x47, + 0x69, + 0x47, + 0x7a, + 0x2f, + 0x6f, + 0x79, + 0x4e, + 0x5a, + 0x66, + 0x48, + 0x2f, + 0x4f, + 0x55, + 0x4a, + 0x61, + 0x69, + 0x6a, + 0x55, + 0x4d, + 0x61, + 0x4c, + 0x62, + 0x48, + 0x64, + 0x2f, + 0x4a, + 0x47, + 0x32, + 0x4c, + 0x36, + 0x67, + 0x74, + 0x70, + 0x41, + 0x43, + 0x59, + 0x59, + 0x32, + 0x62, + 0x0a, + 0x41, + 0x6f, + 0x4c, + 0x6b, + 0x49, + 0x63, + 0x43, + 0x6c, + 0x33, + 0x38, + 0x6e, + 0x73, + 0x4c, + 0x59, + 0x4d, + 0x4c, + 0x5a, + 0x33, + 0x32, + 0x42, + 0x62, + 0x63, + 0x35, + 0x6a, + 0x6e, + 0x50, + 0x2f, + 0x51, + 0x79, + 0x33, + 0x64, + 0x32, + 0x48, + 0x4b, + 0x73, + 0x54, + 0x4a, + 0x35, + 0x49, + 0x74, + 0x34, + 0x71, + 0x78, + 0x44, + 0x67, + 0x74, + 0x62, + 0x74, + 0x70, + 0x55, + 0x38, + 0x65, + 0x35, + 0x4d, + 0x68, + 0x45, + 0x65, + 0x4a, + 0x6f, + 0x65, + 0x4d, + 0x48, + 0x4f, + 0x43, + 0x0a, + 0x66, + 0x69, + 0x7a, + 0x62, + 0x63, + 0x57, + 0x63, + 0x37, + 0x57, + 0x37, + 0x6d, + 0x32, + 0x53, + 0x4c, + 0x66, + 0x70, + 0x65, + 0x51, + 0x4a, + 0x57, + 0x4d, + 0x67, + 0x75, + 0x32, + 0x44, + 0x61, + 0x30, + 0x48, + 0x59, + 0x45, + 0x44, + 0x53, + 0x2f, + 0x78, + 0x7a, + 0x4c, + 0x6e, + 0x37, + 0x70, + 0x78, + 0x51, + 0x67, + 0x5a, + 0x70, + 0x4f, + 0x72, + 0x4d, + 0x51, + 0x37, + 0x49, + 0x68, + 0x69, + 0x31, + 0x6a, + 0x77, + 0x58, + 0x66, + 0x4b, + 0x46, + 0x71, + 0x49, + 0x49, + 0x61, + 0x6c, + 0x0a, + 0x67, + 0x36, + 0x53, + 0x69, + 0x6a, + 0x52, + 0x47, + 0x58, + 0x68, + 0x37, + 0x6f, + 0x6e, + 0x45, + 0x41, + 0x78, + 0x45, + 0x6d, + 0x4b, + 0x4c, + 0x6b, + 0x70, + 0x56, + 0x51, + 0x52, + 0x71, + 0x36, + 0x33, + 0x33, + 0x42, + 0x59, + 0x50, + 0x56, + 0x36, + 0x6f, + 0x64, + 0x78, + 0x74, + 0x58, + 0x44, + 0x68, + 0x78, + 0x79, + 0x4a, + 0x4b, + 0x79, + 0x47, + 0x6a, + 0x53, + 0x4a, + 0x73, + 0x51, + 0x6f, + 0x4b, + 0x76, + 0x39, + 0x6f, + 0x43, + 0x46, + 0x32, + 0x6b, + 0x41, + 0x64, + 0x41, + 0x69, + 0x0a, + 0x43, + 0x76, + 0x76, + 0x61, + 0x74, + 0x71, + 0x52, + 0x57, + 0x52, + 0x77, + 0x67, + 0x49, + 0x65, + 0x6c, + 0x6e, + 0x31, + 0x53, + 0x77, + 0x39, + 0x45, + 0x65, + 0x36, + 0x63, + 0x54, + 0x59, + 0x5a, + 0x43, + 0x47, + 0x32, + 0x55, + 0x2b, + 0x2f, + 0x55, + 0x66, + 0x2b, + 0x4c, + 0x73, + 0x37, + 0x66, + 0x6a, + 0x4e, + 0x38, + 0x74, + 0x72, + 0x62, + 0x2f, + 0x53, + 0x68, + 0x6d, + 0x78, + 0x6f, + 0x38, + 0x64, + 0x6f, + 0x2f, + 0x6e, + 0x70, + 0x42, + 0x6e, + 0x7a, + 0x38, + 0x6a, + 0x2b, + 0x31, + 0x0a, + 0x61, + 0x32, + 0x76, + 0x62, + 0x7a, + 0x33, + 0x67, + 0x70, + 0x4f, + 0x73, + 0x6c, + 0x38, + 0x37, + 0x55, + 0x30, + 0x63, + 0x30, + 0x31, + 0x4a, + 0x43, + 0x6c, + 0x39, + 0x53, + 0x5a, + 0x58, + 0x44, + 0x53, + 0x4f, + 0x30, + 0x39, + 0x77, + 0x3d, + 0x0a, + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x45, + 0x4e, + 0x44, + 0x20, + 0x43, + 0x45, + 0x52, + 0x54, + 0x49, + 0x46, + 0x49, + 0x43, + 0x41, + 0x54, + 0x45, + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x0a, }; +#ifndef OPENSSL_NO_DEPRECATED_3_0 /* -----BEGIN PRIVATE KEY----- MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQC1mQfTLWrNFfUs @@ -249,222 +1406,1715 @@ hljAVnB9v6NMfcRERTx10SUc -----END PRIVATE KEY----- */ static const uint8_t RSAPrivateKeyPEM[] = { - 0x2d, 0x2d, 0x2d, 0x2d, 0x2d, 0x42, 0x45, 0x47, - 0x49, 0x4e, 0x20, 0x50, 0x52, 0x49, 0x56, 0x41, - 0x54, 0x45, 0x20, 0x4b, 0x45, 0x59, 0x2d, 0x2d, - 0x2d, 0x2d, 0x2d, 0x0a, 0x4d, 0x49, 0x49, 0x45, - 0x76, 0x67, 0x49, 0x42, 0x41, 0x44, 0x41, 0x4e, - 0x42, 0x67, 0x6b, 0x71, 0x68, 0x6b, 0x69, 0x47, - 0x39, 0x77, 0x30, 0x42, 0x41, 0x51, 0x45, 0x46, - 0x41, 0x41, 0x53, 0x43, 0x42, 0x4b, 0x67, 0x77, - 0x67, 0x67, 0x53, 0x6b, 0x41, 0x67, 0x45, 0x41, - 0x41, 0x6f, 0x49, 0x42, 0x41, 0x51, 0x43, 0x31, - 0x6d, 0x51, 0x66, 0x54, 0x4c, 0x57, 0x72, 0x4e, - 0x46, 0x66, 0x55, 0x73, 0x0a, 0x6d, 0x76, 0x6c, - 0x49, 0x52, 0x47, 0x6d, 0x38, 0x4d, 0x37, 0x4e, - 0x78, 0x4b, 0x4a, 0x66, 0x76, 0x7a, 0x49, 0x63, - 0x46, 0x42, 0x56, 0x69, 0x42, 0x61, 0x36, 0x2f, - 0x4c, 0x56, 0x63, 0x6d, 0x4c, 0x34, 0x50, 0x46, - 0x37, 0x50, 0x79, 0x70, 0x77, 0x74, 0x6c, 0x57, - 0x68, 0x4b, 0x5a, 0x78, 0x4a, 0x62, 0x51, 0x54, - 0x53, 0x32, 0x6a, 0x67, 0x41, 0x32, 0x52, 0x6c, - 0x4c, 0x6c, 0x38, 0x38, 0x2b, 0x0a, 0x52, 0x47, - 0x33, 0x48, 0x47, 0x39, 0x6f, 0x74, 0x66, 0x49, - 0x49, 0x62, 0x7a, 0x41, 0x31, 0x2b, 0x61, 0x44, - 0x73, 0x41, 0x41, 0x49, 0x6e, 0x53, 0x39, 0x37, - 0x62, 0x2b, 0x70, 0x59, 0x66, 0x50, 0x31, 0x62, - 0x6f, 0x2f, 0x4c, 0x61, 0x53, 0x77, 0x4f, 0x64, - 0x30, 0x67, 0x30, 0x65, 0x56, 0x55, 0x30, 0x48, - 0x4d, 0x59, 0x72, 0x59, 0x71, 0x62, 0x48, 0x48, - 0x49, 0x32, 0x6e, 0x42, 0x77, 0x33, 0x0a, 0x37, - 0x55, 0x36, 0x67, 0x77, 0x4f, 0x2f, 0x76, 0x65, - 0x45, 0x6b, 0x30, 0x2f, 0x45, 0x45, 0x68, 0x37, - 0x56, 0x72, 0x75, 0x52, 0x5a, 0x6c, 0x7a, 0x79, - 0x72, 0x79, 0x53, 0x35, 0x6a, 0x37, 0x69, 0x6b, - 0x43, 0x54, 0x47, 0x7a, 0x69, 0x55, 0x68, 0x67, - 0x79, 0x53, 0x37, 0x33, 0x55, 0x2f, 0x39, 0x48, - 0x63, 0x6a, 0x50, 0x57, 0x6c, 0x4e, 0x38, 0x53, - 0x73, 0x4f, 0x75, 0x49, 0x72, 0x2b, 0x30, 0x0a, - 0x74, 0x35, 0x57, 0x68, 0x45, 0x56, 0x73, 0x6c, - 0x75, 0x50, 0x7a, 0x6e, 0x70, 0x6a, 0x45, 0x46, - 0x37, 0x49, 0x76, 0x70, 0x47, 0x32, 0x70, 0x36, - 0x56, 0x54, 0x53, 0x56, 0x5a, 0x71, 0x6b, 0x37, - 0x55, 0x76, 0x71, 0x76, 0x78, 0x63, 0x6d, 0x4c, - 0x37, 0x36, 0x39, 0x54, 0x61, 0x56, 0x39, 0x44, - 0x6e, 0x50, 0x77, 0x4f, 0x52, 0x39, 0x68, 0x32, - 0x45, 0x4f, 0x6e, 0x2b, 0x6a, 0x39, 0x35, 0x37, - 0x0a, 0x79, 0x64, 0x74, 0x69, 0x44, 0x6c, 0x36, - 0x43, 0x48, 0x44, 0x59, 0x79, 0x4e, 0x52, 0x5a, - 0x69, 0x6d, 0x31, 0x39, 0x7a, 0x53, 0x52, 0x33, - 0x72, 0x52, 0x31, 0x37, 0x63, 0x6d, 0x53, 0x6c, - 0x33, 0x48, 0x36, 0x59, 0x73, 0x35, 0x59, 0x37, - 0x44, 0x62, 0x32, 0x33, 0x33, 0x37, 0x43, 0x2b, - 0x72, 0x63, 0x4d, 0x59, 0x34, 0x77, 0x6b, 0x64, - 0x79, 0x58, 0x56, 0x4b, 0x6a, 0x39, 0x63, 0x52, - 0x41, 0x0a, 0x6e, 0x72, 0x71, 0x43, 0x77, 0x54, - 0x4d, 0x35, 0x41, 0x67, 0x4d, 0x42, 0x41, 0x41, - 0x45, 0x43, 0x67, 0x67, 0x45, 0x41, 0x46, 0x4f, - 0x44, 0x2b, 0x58, 0x46, 0x4a, 0x5a, 0x65, 0x44, - 0x44, 0x78, 0x47, 0x6d, 0x72, 0x4c, 0x42, 0x48, - 0x73, 0x52, 0x4b, 0x52, 0x6c, 0x4d, 0x70, 0x56, - 0x4d, 0x45, 0x66, 0x51, 0x61, 0x6e, 0x38, 0x33, - 0x54, 0x55, 0x34, 0x7a, 0x52, 0x74, 0x5a, 0x74, - 0x52, 0x37, 0x0a, 0x4d, 0x73, 0x44, 0x76, 0x49, - 0x72, 0x74, 0x31, 0x64, 0x72, 0x59, 0x51, 0x44, - 0x46, 0x4b, 0x4c, 0x62, 0x49, 0x6e, 0x44, 0x52, - 0x7a, 0x62, 0x64, 0x76, 0x34, 0x4d, 0x32, 0x66, - 0x46, 0x46, 0x38, 0x2b, 0x32, 0x7a, 0x45, 0x72, - 0x6d, 0x4c, 0x4f, 0x5a, 0x2f, 0x4a, 0x72, 0x78, - 0x79, 0x52, 0x6a, 0x33, 0x4d, 0x66, 0x42, 0x47, - 0x4e, 0x50, 0x33, 0x42, 0x4c, 0x47, 0x45, 0x63, - 0x61, 0x79, 0x34, 0x0a, 0x65, 0x37, 0x58, 0x59, - 0x44, 0x78, 0x47, 0x42, 0x59, 0x4e, 0x32, 0x57, - 0x52, 0x67, 0x4b, 0x37, 0x2b, 0x6b, 0x39, 0x70, - 0x48, 0x45, 0x6f, 0x2f, 0x71, 0x47, 0x76, 0x52, - 0x32, 0x65, 0x4f, 0x43, 0x2f, 0x77, 0x38, 0x69, - 0x76, 0x69, 0x72, 0x51, 0x71, 0x31, 0x6a, 0x4b, - 0x47, 0x66, 0x52, 0x79, 0x7a, 0x4b, 0x4c, 0x4d, - 0x6c, 0x4a, 0x36, 0x64, 0x38, 0x51, 0x6b, 0x37, - 0x4f, 0x79, 0x78, 0x5a, 0x0a, 0x6e, 0x30, 0x75, - 0x33, 0x76, 0x32, 0x45, 0x4a, 0x39, 0x43, 0x57, - 0x6f, 0x4e, 0x44, 0x67, 0x55, 0x48, 0x34, 0x65, - 0x78, 0x43, 0x69, 0x6c, 0x2f, 0x4f, 0x65, 0x34, - 0x68, 0x35, 0x57, 0x41, 0x35, 0x39, 0x78, 0x54, - 0x35, 0x4e, 0x41, 0x6b, 0x78, 0x34, 0x52, 0x55, - 0x6f, 0x6a, 0x73, 0x4a, 0x69, 0x45, 0x78, 0x57, - 0x5a, 0x70, 0x7a, 0x54, 0x2f, 0x56, 0x58, 0x31, - 0x64, 0x32, 0x31, 0x6d, 0x4e, 0x0a, 0x57, 0x4d, - 0x62, 0x35, 0x45, 0x4f, 0x38, 0x65, 0x79, 0x69, - 0x36, 0x46, 0x79, 0x5a, 0x6c, 0x41, 0x63, 0x62, - 0x39, 0x4d, 0x49, 0x44, 0x30, 0x6b, 0x4d, 0x46, - 0x36, 0x51, 0x33, 0x68, 0x55, 0x76, 0x2b, 0x6a, - 0x54, 0x77, 0x2b, 0x58, 0x39, 0x79, 0x69, 0x67, - 0x2b, 0x33, 0x42, 0x39, 0x62, 0x67, 0x32, 0x5a, - 0x30, 0x49, 0x2b, 0x49, 0x4b, 0x48, 0x6c, 0x39, - 0x49, 0x6e, 0x53, 0x68, 0x6b, 0x43, 0x0a, 0x6e, - 0x64, 0x59, 0x6e, 0x34, 0x61, 0x64, 0x30, 0x7a, - 0x64, 0x2f, 0x67, 0x67, 0x4d, 0x56, 0x6b, 0x6c, - 0x6f, 0x6f, 0x6d, 0x68, 0x34, 0x75, 0x61, 0x53, - 0x71, 0x5a, 0x78, 0x55, 0x69, 0x33, 0x79, 0x77, - 0x74, 0x73, 0x7a, 0x5a, 0x6b, 0x52, 0x62, 0x7a, - 0x51, 0x4b, 0x42, 0x67, 0x51, 0x44, 0x37, 0x50, - 0x76, 0x78, 0x31, 0x45, 0x72, 0x4b, 0x6d, 0x35, - 0x6c, 0x5a, 0x44, 0x41, 0x53, 0x32, 0x62, 0x0a, - 0x62, 0x34, 0x72, 0x6c, 0x74, 0x7a, 0x71, 0x4a, - 0x52, 0x55, 0x45, 0x4b, 0x79, 0x45, 0x71, 0x6a, - 0x71, 0x7a, 0x50, 0x7a, 0x67, 0x61, 0x73, 0x4f, - 0x61, 0x30, 0x6a, 0x57, 0x45, 0x71, 0x2f, 0x66, - 0x78, 0x75, 0x47, 0x63, 0x2f, 0x62, 0x69, 0x78, - 0x67, 0x2f, 0x45, 0x42, 0x61, 0x51, 0x38, 0x79, - 0x79, 0x54, 0x47, 0x59, 0x64, 0x49, 0x59, 0x79, - 0x72, 0x37, 0x44, 0x4b, 0x59, 0x59, 0x6a, 0x43, - 0x0a, 0x30, 0x41, 0x47, 0x56, 0x6e, 0x42, 0x43, - 0x68, 0x30, 0x2b, 0x54, 0x46, 0x55, 0x44, 0x42, - 0x31, 0x6b, 0x66, 0x77, 0x6b, 0x62, 0x65, 0x66, - 0x32, 0x62, 0x38, 0x79, 0x75, 0x66, 0x51, 0x2f, - 0x76, 0x4a, 0x77, 0x63, 0x4f, 0x4a, 0x2b, 0x35, - 0x6b, 0x42, 0x58, 0x51, 0x5a, 0x78, 0x38, 0x2b, - 0x4c, 0x38, 0x55, 0x39, 0x69, 0x57, 0x4b, 0x41, - 0x4e, 0x58, 0x78, 0x6b, 0x45, 0x65, 0x43, 0x58, - 0x32, 0x0a, 0x69, 0x57, 0x50, 0x5a, 0x50, 0x7a, - 0x35, 0x32, 0x70, 0x54, 0x54, 0x59, 0x6c, 0x66, - 0x39, 0x30, 0x50, 0x4c, 0x7a, 0x45, 0x57, 0x36, - 0x51, 0x79, 0x44, 0x77, 0x4b, 0x42, 0x67, 0x51, - 0x43, 0x35, 0x43, 0x4b, 0x79, 0x66, 0x55, 0x77, - 0x78, 0x33, 0x42, 0x61, 0x32, 0x69, 0x58, 0x74, - 0x66, 0x49, 0x72, 0x65, 0x79, 0x50, 0x71, 0x44, - 0x6f, 0x62, 0x62, 0x79, 0x62, 0x79, 0x54, 0x45, - 0x59, 0x6b, 0x0a, 0x61, 0x79, 0x41, 0x32, 0x6f, - 0x45, 0x6c, 0x53, 0x64, 0x65, 0x6a, 0x67, 0x56, - 0x6b, 0x57, 0x77, 0x4a, 0x2b, 0x71, 0x37, 0x37, - 0x67, 0x77, 0x72, 0x6e, 0x46, 0x35, 0x50, 0x65, - 0x39, 0x7a, 0x62, 0x70, 0x55, 0x42, 0x6f, 0x63, - 0x37, 0x56, 0x4a, 0x6a, 0x72, 0x52, 0x68, 0x55, - 0x6f, 0x6a, 0x49, 0x37, 0x4c, 0x4f, 0x79, 0x53, - 0x79, 0x74, 0x6f, 0x33, 0x57, 0x59, 0x59, 0x6f, - 0x63, 0x7a, 0x58, 0x0a, 0x4c, 0x70, 0x72, 0x7a, - 0x50, 0x6e, 0x6a, 0x32, 0x79, 0x45, 0x56, 0x65, - 0x56, 0x32, 0x6c, 0x72, 0x54, 0x53, 0x36, 0x6c, - 0x4b, 0x4e, 0x70, 0x64, 0x72, 0x61, 0x4f, 0x38, - 0x51, 0x5a, 0x63, 0x53, 0x44, 0x37, 0x6d, 0x55, - 0x55, 0x6d, 0x69, 0x4e, 0x52, 0x5a, 0x6e, 0x6f, - 0x50, 0x4b, 0x31, 0x36, 0x4d, 0x6d, 0x39, 0x71, - 0x6a, 0x6b, 0x6b, 0x32, 0x39, 0x48, 0x6e, 0x59, - 0x37, 0x4d, 0x73, 0x71, 0x0a, 0x70, 0x6b, 0x69, - 0x4f, 0x67, 0x34, 0x68, 0x75, 0x4e, 0x77, 0x4b, - 0x42, 0x67, 0x51, 0x43, 0x6b, 0x68, 0x32, 0x48, - 0x42, 0x74, 0x4f, 0x58, 0x6a, 0x48, 0x2f, 0x47, - 0x62, 0x58, 0x56, 0x6b, 0x6c, 0x63, 0x63, 0x30, - 0x4f, 0x6b, 0x34, 0x65, 0x30, 0x76, 0x76, 0x4a, - 0x53, 0x41, 0x6b, 0x6e, 0x47, 0x6c, 0x6d, 0x57, - 0x6c, 0x37, 0x2b, 0x4d, 0x35, 0x78, 0x51, 0x33, - 0x6b, 0x69, 0x6b, 0x59, 0x38, 0x0a, 0x44, 0x37, - 0x78, 0x4e, 0x46, 0x32, 0x58, 0x73, 0x63, 0x59, - 0x2f, 0x51, 0x73, 0x61, 0x44, 0x76, 0x54, 0x41, - 0x75, 0x37, 0x58, 0x34, 0x74, 0x47, 0x42, 0x41, - 0x47, 0x4d, 0x39, 0x6f, 0x51, 0x64, 0x74, 0x79, - 0x4e, 0x69, 0x65, 0x74, 0x6e, 0x31, 0x62, 0x35, - 0x4a, 0x66, 0x6d, 0x42, 0x79, 0x7a, 0x30, 0x55, - 0x37, 0x42, 0x2b, 0x47, 0x73, 0x76, 0x32, 0x5a, - 0x53, 0x37, 0x4b, 0x31, 0x44, 0x55, 0x0a, 0x39, - 0x73, 0x54, 0x4c, 0x41, 0x32, 0x45, 0x38, 0x68, - 0x4d, 0x6d, 0x37, 0x33, 0x44, 0x70, 0x51, 0x31, - 0x55, 0x78, 0x38, 0x42, 0x62, 0x65, 0x43, 0x4b, - 0x69, 0x56, 0x79, 0x35, 0x4d, 0x39, 0x50, 0x66, - 0x44, 0x63, 0x7a, 0x33, 0x42, 0x4f, 0x6d, 0x6c, - 0x4a, 0x64, 0x66, 0x77, 0x68, 0x4b, 0x51, 0x5a, - 0x76, 0x6e, 0x69, 0x79, 0x48, 0x52, 0x6c, 0x42, - 0x77, 0x4b, 0x42, 0x67, 0x51, 0x43, 0x48, 0x0a, - 0x2f, 0x73, 0x41, 0x68, 0x4f, 0x63, 0x44, 0x6e, - 0x6d, 0x64, 0x7a, 0x4d, 0x67, 0x6a, 0x6a, 0x47, - 0x33, 0x6b, 0x34, 0x49, 0x4a, 0x2f, 0x54, 0x4e, - 0x52, 0x52, 0x79, 0x79, 0x36, 0x53, 0x79, 0x45, - 0x68, 0x39, 0x66, 0x64, 0x54, 0x6d, 0x47, 0x56, - 0x6f, 0x65, 0x50, 0x50, 0x50, 0x70, 0x6c, 0x70, - 0x70, 0x32, 0x7a, 0x33, 0x51, 0x7a, 0x62, 0x65, - 0x74, 0x73, 0x62, 0x36, 0x56, 0x47, 0x63, 0x33, - 0x0a, 0x61, 0x48, 0x57, 0x32, 0x54, 0x35, 0x54, - 0x6d, 0x77, 0x32, 0x51, 0x41, 0x51, 0x39, 0x45, - 0x56, 0x48, 0x43, 0x50, 0x57, 0x33, 0x7a, 0x6a, - 0x41, 0x6b, 0x6a, 0x6a, 0x2f, 0x30, 0x61, 0x76, - 0x6b, 0x57, 0x2f, 0x53, 0x32, 0x34, 0x79, 0x75, - 0x30, 0x39, 0x65, 0x31, 0x47, 0x4d, 0x61, 0x6a, - 0x68, 0x6e, 0x4a, 0x43, 0x30, 0x41, 0x78, 0x71, - 0x37, 0x7a, 0x32, 0x75, 0x51, 0x61, 0x67, 0x54, - 0x47, 0x0a, 0x32, 0x5a, 0x66, 0x6b, 0x55, 0x38, - 0x31, 0x55, 0x52, 0x39, 0x75, 0x65, 0x76, 0x54, - 0x6f, 0x6a, 0x6e, 0x66, 0x34, 0x56, 0x71, 0x77, - 0x35, 0x55, 0x76, 0x63, 0x72, 0x77, 0x6a, 0x4e, - 0x6d, 0x6d, 0x4e, 0x79, 0x45, 0x4d, 0x33, 0x63, - 0x2f, 0x67, 0x63, 0x51, 0x4b, 0x42, 0x67, 0x48, - 0x61, 0x32, 0x64, 0x54, 0x35, 0x73, 0x76, 0x7a, - 0x4d, 0x31, 0x6a, 0x52, 0x65, 0x69, 0x4f, 0x33, - 0x56, 0x74, 0x0a, 0x64, 0x41, 0x55, 0x44, 0x7a, - 0x74, 0x47, 0x4b, 0x55, 0x45, 0x33, 0x63, 0x6c, - 0x50, 0x56, 0x33, 0x35, 0x4c, 0x32, 0x78, 0x6d, - 0x4a, 0x65, 0x4a, 0x44, 0x58, 0x50, 0x4f, 0x71, - 0x43, 0x4c, 0x33, 0x71, 0x6f, 0x5a, 0x39, 0x41, - 0x36, 0x68, 0x48, 0x6d, 0x44, 0x77, 0x36, 0x67, - 0x6d, 0x67, 0x38, 0x32, 0x67, 0x51, 0x44, 0x51, - 0x65, 0x4a, 0x62, 0x4c, 0x2f, 0x2b, 0x6a, 0x4b, - 0x6b, 0x6f, 0x6e, 0x0a, 0x65, 0x36, 0x61, 0x74, - 0x48, 0x2f, 0x44, 0x66, 0x72, 0x2b, 0x4d, 0x34, - 0x6e, 0x50, 0x66, 0x74, 0x39, 0x4c, 0x74, 0x34, - 0x66, 0x4f, 0x41, 0x57, 0x4f, 0x51, 0x33, 0x74, - 0x44, 0x73, 0x44, 0x75, 0x43, 0x6b, 0x4f, 0x4d, - 0x6a, 0x53, 0x54, 0x6e, 0x38, 0x63, 0x4c, 0x4d, - 0x5a, 0x4c, 0x47, 0x63, 0x77, 0x54, 0x32, 0x48, - 0x31, 0x48, 0x32, 0x76, 0x42, 0x6f, 0x63, 0x4d, - 0x2b, 0x55, 0x54, 0x64, 0x0a, 0x68, 0x6c, 0x6a, - 0x41, 0x56, 0x6e, 0x42, 0x39, 0x76, 0x36, 0x4e, - 0x4d, 0x66, 0x63, 0x52, 0x45, 0x52, 0x54, 0x78, - 0x31, 0x30, 0x53, 0x55, 0x63, 0x0a, 0x2d, 0x2d, - 0x2d, 0x2d, 0x2d, 0x45, 0x4e, 0x44, 0x20, 0x50, - 0x52, 0x49, 0x56, 0x41, 0x54, 0x45, 0x20, 0x4b, - 0x45, 0x59, 0x2d, 0x2d, 0x2d, 0x2d, 0x2d, 0x0a + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x42, + 0x45, + 0x47, + 0x49, + 0x4e, + 0x20, + 0x50, + 0x52, + 0x49, + 0x56, + 0x41, + 0x54, + 0x45, + 0x20, + 0x4b, + 0x45, + 0x59, + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x0a, + 0x4d, + 0x49, + 0x49, + 0x45, + 0x76, + 0x67, + 0x49, + 0x42, + 0x41, + 0x44, + 0x41, + 0x4e, + 0x42, + 0x67, + 0x6b, + 0x71, + 0x68, + 0x6b, + 0x69, + 0x47, + 0x39, + 0x77, + 0x30, + 0x42, + 0x41, + 0x51, + 0x45, + 0x46, + 0x41, + 0x41, + 0x53, + 0x43, + 0x42, + 0x4b, + 0x67, + 0x77, + 0x67, + 0x67, + 0x53, + 0x6b, + 0x41, + 0x67, + 0x45, + 0x41, + 0x41, + 0x6f, + 0x49, + 0x42, + 0x41, + 0x51, + 0x43, + 0x31, + 0x6d, + 0x51, + 0x66, + 0x54, + 0x4c, + 0x57, + 0x72, + 0x4e, + 0x46, + 0x66, + 0x55, + 0x73, + 0x0a, + 0x6d, + 0x76, + 0x6c, + 0x49, + 0x52, + 0x47, + 0x6d, + 0x38, + 0x4d, + 0x37, + 0x4e, + 0x78, + 0x4b, + 0x4a, + 0x66, + 0x76, + 0x7a, + 0x49, + 0x63, + 0x46, + 0x42, + 0x56, + 0x69, + 0x42, + 0x61, + 0x36, + 0x2f, + 0x4c, + 0x56, + 0x63, + 0x6d, + 0x4c, + 0x34, + 0x50, + 0x46, + 0x37, + 0x50, + 0x79, + 0x70, + 0x77, + 0x74, + 0x6c, + 0x57, + 0x68, + 0x4b, + 0x5a, + 0x78, + 0x4a, + 0x62, + 0x51, + 0x54, + 0x53, + 0x32, + 0x6a, + 0x67, + 0x41, + 0x32, + 0x52, + 0x6c, + 0x4c, + 0x6c, + 0x38, + 0x38, + 0x2b, + 0x0a, + 0x52, + 0x47, + 0x33, + 0x48, + 0x47, + 0x39, + 0x6f, + 0x74, + 0x66, + 0x49, + 0x49, + 0x62, + 0x7a, + 0x41, + 0x31, + 0x2b, + 0x61, + 0x44, + 0x73, + 0x41, + 0x41, + 0x49, + 0x6e, + 0x53, + 0x39, + 0x37, + 0x62, + 0x2b, + 0x70, + 0x59, + 0x66, + 0x50, + 0x31, + 0x62, + 0x6f, + 0x2f, + 0x4c, + 0x61, + 0x53, + 0x77, + 0x4f, + 0x64, + 0x30, + 0x67, + 0x30, + 0x65, + 0x56, + 0x55, + 0x30, + 0x48, + 0x4d, + 0x59, + 0x72, + 0x59, + 0x71, + 0x62, + 0x48, + 0x48, + 0x49, + 0x32, + 0x6e, + 0x42, + 0x77, + 0x33, + 0x0a, + 0x37, + 0x55, + 0x36, + 0x67, + 0x77, + 0x4f, + 0x2f, + 0x76, + 0x65, + 0x45, + 0x6b, + 0x30, + 0x2f, + 0x45, + 0x45, + 0x68, + 0x37, + 0x56, + 0x72, + 0x75, + 0x52, + 0x5a, + 0x6c, + 0x7a, + 0x79, + 0x72, + 0x79, + 0x53, + 0x35, + 0x6a, + 0x37, + 0x69, + 0x6b, + 0x43, + 0x54, + 0x47, + 0x7a, + 0x69, + 0x55, + 0x68, + 0x67, + 0x79, + 0x53, + 0x37, + 0x33, + 0x55, + 0x2f, + 0x39, + 0x48, + 0x63, + 0x6a, + 0x50, + 0x57, + 0x6c, + 0x4e, + 0x38, + 0x53, + 0x73, + 0x4f, + 0x75, + 0x49, + 0x72, + 0x2b, + 0x30, + 0x0a, + 0x74, + 0x35, + 0x57, + 0x68, + 0x45, + 0x56, + 0x73, + 0x6c, + 0x75, + 0x50, + 0x7a, + 0x6e, + 0x70, + 0x6a, + 0x45, + 0x46, + 0x37, + 0x49, + 0x76, + 0x70, + 0x47, + 0x32, + 0x70, + 0x36, + 0x56, + 0x54, + 0x53, + 0x56, + 0x5a, + 0x71, + 0x6b, + 0x37, + 0x55, + 0x76, + 0x71, + 0x76, + 0x78, + 0x63, + 0x6d, + 0x4c, + 0x37, + 0x36, + 0x39, + 0x54, + 0x61, + 0x56, + 0x39, + 0x44, + 0x6e, + 0x50, + 0x77, + 0x4f, + 0x52, + 0x39, + 0x68, + 0x32, + 0x45, + 0x4f, + 0x6e, + 0x2b, + 0x6a, + 0x39, + 0x35, + 0x37, + 0x0a, + 0x79, + 0x64, + 0x74, + 0x69, + 0x44, + 0x6c, + 0x36, + 0x43, + 0x48, + 0x44, + 0x59, + 0x79, + 0x4e, + 0x52, + 0x5a, + 0x69, + 0x6d, + 0x31, + 0x39, + 0x7a, + 0x53, + 0x52, + 0x33, + 0x72, + 0x52, + 0x31, + 0x37, + 0x63, + 0x6d, + 0x53, + 0x6c, + 0x33, + 0x48, + 0x36, + 0x59, + 0x73, + 0x35, + 0x59, + 0x37, + 0x44, + 0x62, + 0x32, + 0x33, + 0x33, + 0x37, + 0x43, + 0x2b, + 0x72, + 0x63, + 0x4d, + 0x59, + 0x34, + 0x77, + 0x6b, + 0x64, + 0x79, + 0x58, + 0x56, + 0x4b, + 0x6a, + 0x39, + 0x63, + 0x52, + 0x41, + 0x0a, + 0x6e, + 0x72, + 0x71, + 0x43, + 0x77, + 0x54, + 0x4d, + 0x35, + 0x41, + 0x67, + 0x4d, + 0x42, + 0x41, + 0x41, + 0x45, + 0x43, + 0x67, + 0x67, + 0x45, + 0x41, + 0x46, + 0x4f, + 0x44, + 0x2b, + 0x58, + 0x46, + 0x4a, + 0x5a, + 0x65, + 0x44, + 0x44, + 0x78, + 0x47, + 0x6d, + 0x72, + 0x4c, + 0x42, + 0x48, + 0x73, + 0x52, + 0x4b, + 0x52, + 0x6c, + 0x4d, + 0x70, + 0x56, + 0x4d, + 0x45, + 0x66, + 0x51, + 0x61, + 0x6e, + 0x38, + 0x33, + 0x54, + 0x55, + 0x34, + 0x7a, + 0x52, + 0x74, + 0x5a, + 0x74, + 0x52, + 0x37, + 0x0a, + 0x4d, + 0x73, + 0x44, + 0x76, + 0x49, + 0x72, + 0x74, + 0x31, + 0x64, + 0x72, + 0x59, + 0x51, + 0x44, + 0x46, + 0x4b, + 0x4c, + 0x62, + 0x49, + 0x6e, + 0x44, + 0x52, + 0x7a, + 0x62, + 0x64, + 0x76, + 0x34, + 0x4d, + 0x32, + 0x66, + 0x46, + 0x46, + 0x38, + 0x2b, + 0x32, + 0x7a, + 0x45, + 0x72, + 0x6d, + 0x4c, + 0x4f, + 0x5a, + 0x2f, + 0x4a, + 0x72, + 0x78, + 0x79, + 0x52, + 0x6a, + 0x33, + 0x4d, + 0x66, + 0x42, + 0x47, + 0x4e, + 0x50, + 0x33, + 0x42, + 0x4c, + 0x47, + 0x45, + 0x63, + 0x61, + 0x79, + 0x34, + 0x0a, + 0x65, + 0x37, + 0x58, + 0x59, + 0x44, + 0x78, + 0x47, + 0x42, + 0x59, + 0x4e, + 0x32, + 0x57, + 0x52, + 0x67, + 0x4b, + 0x37, + 0x2b, + 0x6b, + 0x39, + 0x70, + 0x48, + 0x45, + 0x6f, + 0x2f, + 0x71, + 0x47, + 0x76, + 0x52, + 0x32, + 0x65, + 0x4f, + 0x43, + 0x2f, + 0x77, + 0x38, + 0x69, + 0x76, + 0x69, + 0x72, + 0x51, + 0x71, + 0x31, + 0x6a, + 0x4b, + 0x47, + 0x66, + 0x52, + 0x79, + 0x7a, + 0x4b, + 0x4c, + 0x4d, + 0x6c, + 0x4a, + 0x36, + 0x64, + 0x38, + 0x51, + 0x6b, + 0x37, + 0x4f, + 0x79, + 0x78, + 0x5a, + 0x0a, + 0x6e, + 0x30, + 0x75, + 0x33, + 0x76, + 0x32, + 0x45, + 0x4a, + 0x39, + 0x43, + 0x57, + 0x6f, + 0x4e, + 0x44, + 0x67, + 0x55, + 0x48, + 0x34, + 0x65, + 0x78, + 0x43, + 0x69, + 0x6c, + 0x2f, + 0x4f, + 0x65, + 0x34, + 0x68, + 0x35, + 0x57, + 0x41, + 0x35, + 0x39, + 0x78, + 0x54, + 0x35, + 0x4e, + 0x41, + 0x6b, + 0x78, + 0x34, + 0x52, + 0x55, + 0x6f, + 0x6a, + 0x73, + 0x4a, + 0x69, + 0x45, + 0x78, + 0x57, + 0x5a, + 0x70, + 0x7a, + 0x54, + 0x2f, + 0x56, + 0x58, + 0x31, + 0x64, + 0x32, + 0x31, + 0x6d, + 0x4e, + 0x0a, + 0x57, + 0x4d, + 0x62, + 0x35, + 0x45, + 0x4f, + 0x38, + 0x65, + 0x79, + 0x69, + 0x36, + 0x46, + 0x79, + 0x5a, + 0x6c, + 0x41, + 0x63, + 0x62, + 0x39, + 0x4d, + 0x49, + 0x44, + 0x30, + 0x6b, + 0x4d, + 0x46, + 0x36, + 0x51, + 0x33, + 0x68, + 0x55, + 0x76, + 0x2b, + 0x6a, + 0x54, + 0x77, + 0x2b, + 0x58, + 0x39, + 0x79, + 0x69, + 0x67, + 0x2b, + 0x33, + 0x42, + 0x39, + 0x62, + 0x67, + 0x32, + 0x5a, + 0x30, + 0x49, + 0x2b, + 0x49, + 0x4b, + 0x48, + 0x6c, + 0x39, + 0x49, + 0x6e, + 0x53, + 0x68, + 0x6b, + 0x43, + 0x0a, + 0x6e, + 0x64, + 0x59, + 0x6e, + 0x34, + 0x61, + 0x64, + 0x30, + 0x7a, + 0x64, + 0x2f, + 0x67, + 0x67, + 0x4d, + 0x56, + 0x6b, + 0x6c, + 0x6f, + 0x6f, + 0x6d, + 0x68, + 0x34, + 0x75, + 0x61, + 0x53, + 0x71, + 0x5a, + 0x78, + 0x55, + 0x69, + 0x33, + 0x79, + 0x77, + 0x74, + 0x73, + 0x7a, + 0x5a, + 0x6b, + 0x52, + 0x62, + 0x7a, + 0x51, + 0x4b, + 0x42, + 0x67, + 0x51, + 0x44, + 0x37, + 0x50, + 0x76, + 0x78, + 0x31, + 0x45, + 0x72, + 0x4b, + 0x6d, + 0x35, + 0x6c, + 0x5a, + 0x44, + 0x41, + 0x53, + 0x32, + 0x62, + 0x0a, + 0x62, + 0x34, + 0x72, + 0x6c, + 0x74, + 0x7a, + 0x71, + 0x4a, + 0x52, + 0x55, + 0x45, + 0x4b, + 0x79, + 0x45, + 0x71, + 0x6a, + 0x71, + 0x7a, + 0x50, + 0x7a, + 0x67, + 0x61, + 0x73, + 0x4f, + 0x61, + 0x30, + 0x6a, + 0x57, + 0x45, + 0x71, + 0x2f, + 0x66, + 0x78, + 0x75, + 0x47, + 0x63, + 0x2f, + 0x62, + 0x69, + 0x78, + 0x67, + 0x2f, + 0x45, + 0x42, + 0x61, + 0x51, + 0x38, + 0x79, + 0x79, + 0x54, + 0x47, + 0x59, + 0x64, + 0x49, + 0x59, + 0x79, + 0x72, + 0x37, + 0x44, + 0x4b, + 0x59, + 0x59, + 0x6a, + 0x43, + 0x0a, + 0x30, + 0x41, + 0x47, + 0x56, + 0x6e, + 0x42, + 0x43, + 0x68, + 0x30, + 0x2b, + 0x54, + 0x46, + 0x55, + 0x44, + 0x42, + 0x31, + 0x6b, + 0x66, + 0x77, + 0x6b, + 0x62, + 0x65, + 0x66, + 0x32, + 0x62, + 0x38, + 0x79, + 0x75, + 0x66, + 0x51, + 0x2f, + 0x76, + 0x4a, + 0x77, + 0x63, + 0x4f, + 0x4a, + 0x2b, + 0x35, + 0x6b, + 0x42, + 0x58, + 0x51, + 0x5a, + 0x78, + 0x38, + 0x2b, + 0x4c, + 0x38, + 0x55, + 0x39, + 0x69, + 0x57, + 0x4b, + 0x41, + 0x4e, + 0x58, + 0x78, + 0x6b, + 0x45, + 0x65, + 0x43, + 0x58, + 0x32, + 0x0a, + 0x69, + 0x57, + 0x50, + 0x5a, + 0x50, + 0x7a, + 0x35, + 0x32, + 0x70, + 0x54, + 0x54, + 0x59, + 0x6c, + 0x66, + 0x39, + 0x30, + 0x50, + 0x4c, + 0x7a, + 0x45, + 0x57, + 0x36, + 0x51, + 0x79, + 0x44, + 0x77, + 0x4b, + 0x42, + 0x67, + 0x51, + 0x43, + 0x35, + 0x43, + 0x4b, + 0x79, + 0x66, + 0x55, + 0x77, + 0x78, + 0x33, + 0x42, + 0x61, + 0x32, + 0x69, + 0x58, + 0x74, + 0x66, + 0x49, + 0x72, + 0x65, + 0x79, + 0x50, + 0x71, + 0x44, + 0x6f, + 0x62, + 0x62, + 0x79, + 0x62, + 0x79, + 0x54, + 0x45, + 0x59, + 0x6b, + 0x0a, + 0x61, + 0x79, + 0x41, + 0x32, + 0x6f, + 0x45, + 0x6c, + 0x53, + 0x64, + 0x65, + 0x6a, + 0x67, + 0x56, + 0x6b, + 0x57, + 0x77, + 0x4a, + 0x2b, + 0x71, + 0x37, + 0x37, + 0x67, + 0x77, + 0x72, + 0x6e, + 0x46, + 0x35, + 0x50, + 0x65, + 0x39, + 0x7a, + 0x62, + 0x70, + 0x55, + 0x42, + 0x6f, + 0x63, + 0x37, + 0x56, + 0x4a, + 0x6a, + 0x72, + 0x52, + 0x68, + 0x55, + 0x6f, + 0x6a, + 0x49, + 0x37, + 0x4c, + 0x4f, + 0x79, + 0x53, + 0x79, + 0x74, + 0x6f, + 0x33, + 0x57, + 0x59, + 0x59, + 0x6f, + 0x63, + 0x7a, + 0x58, + 0x0a, + 0x4c, + 0x70, + 0x72, + 0x7a, + 0x50, + 0x6e, + 0x6a, + 0x32, + 0x79, + 0x45, + 0x56, + 0x65, + 0x56, + 0x32, + 0x6c, + 0x72, + 0x54, + 0x53, + 0x36, + 0x6c, + 0x4b, + 0x4e, + 0x70, + 0x64, + 0x72, + 0x61, + 0x4f, + 0x38, + 0x51, + 0x5a, + 0x63, + 0x53, + 0x44, + 0x37, + 0x6d, + 0x55, + 0x55, + 0x6d, + 0x69, + 0x4e, + 0x52, + 0x5a, + 0x6e, + 0x6f, + 0x50, + 0x4b, + 0x31, + 0x36, + 0x4d, + 0x6d, + 0x39, + 0x71, + 0x6a, + 0x6b, + 0x6b, + 0x32, + 0x39, + 0x48, + 0x6e, + 0x59, + 0x37, + 0x4d, + 0x73, + 0x71, + 0x0a, + 0x70, + 0x6b, + 0x69, + 0x4f, + 0x67, + 0x34, + 0x68, + 0x75, + 0x4e, + 0x77, + 0x4b, + 0x42, + 0x67, + 0x51, + 0x43, + 0x6b, + 0x68, + 0x32, + 0x48, + 0x42, + 0x74, + 0x4f, + 0x58, + 0x6a, + 0x48, + 0x2f, + 0x47, + 0x62, + 0x58, + 0x56, + 0x6b, + 0x6c, + 0x63, + 0x63, + 0x30, + 0x4f, + 0x6b, + 0x34, + 0x65, + 0x30, + 0x76, + 0x76, + 0x4a, + 0x53, + 0x41, + 0x6b, + 0x6e, + 0x47, + 0x6c, + 0x6d, + 0x57, + 0x6c, + 0x37, + 0x2b, + 0x4d, + 0x35, + 0x78, + 0x51, + 0x33, + 0x6b, + 0x69, + 0x6b, + 0x59, + 0x38, + 0x0a, + 0x44, + 0x37, + 0x78, + 0x4e, + 0x46, + 0x32, + 0x58, + 0x73, + 0x63, + 0x59, + 0x2f, + 0x51, + 0x73, + 0x61, + 0x44, + 0x76, + 0x54, + 0x41, + 0x75, + 0x37, + 0x58, + 0x34, + 0x74, + 0x47, + 0x42, + 0x41, + 0x47, + 0x4d, + 0x39, + 0x6f, + 0x51, + 0x64, + 0x74, + 0x79, + 0x4e, + 0x69, + 0x65, + 0x74, + 0x6e, + 0x31, + 0x62, + 0x35, + 0x4a, + 0x66, + 0x6d, + 0x42, + 0x79, + 0x7a, + 0x30, + 0x55, + 0x37, + 0x42, + 0x2b, + 0x47, + 0x73, + 0x76, + 0x32, + 0x5a, + 0x53, + 0x37, + 0x4b, + 0x31, + 0x44, + 0x55, + 0x0a, + 0x39, + 0x73, + 0x54, + 0x4c, + 0x41, + 0x32, + 0x45, + 0x38, + 0x68, + 0x4d, + 0x6d, + 0x37, + 0x33, + 0x44, + 0x70, + 0x51, + 0x31, + 0x55, + 0x78, + 0x38, + 0x42, + 0x62, + 0x65, + 0x43, + 0x4b, + 0x69, + 0x56, + 0x79, + 0x35, + 0x4d, + 0x39, + 0x50, + 0x66, + 0x44, + 0x63, + 0x7a, + 0x33, + 0x42, + 0x4f, + 0x6d, + 0x6c, + 0x4a, + 0x64, + 0x66, + 0x77, + 0x68, + 0x4b, + 0x51, + 0x5a, + 0x76, + 0x6e, + 0x69, + 0x79, + 0x48, + 0x52, + 0x6c, + 0x42, + 0x77, + 0x4b, + 0x42, + 0x67, + 0x51, + 0x43, + 0x48, + 0x0a, + 0x2f, + 0x73, + 0x41, + 0x68, + 0x4f, + 0x63, + 0x44, + 0x6e, + 0x6d, + 0x64, + 0x7a, + 0x4d, + 0x67, + 0x6a, + 0x6a, + 0x47, + 0x33, + 0x6b, + 0x34, + 0x49, + 0x4a, + 0x2f, + 0x54, + 0x4e, + 0x52, + 0x52, + 0x79, + 0x79, + 0x36, + 0x53, + 0x79, + 0x45, + 0x68, + 0x39, + 0x66, + 0x64, + 0x54, + 0x6d, + 0x47, + 0x56, + 0x6f, + 0x65, + 0x50, + 0x50, + 0x50, + 0x70, + 0x6c, + 0x70, + 0x70, + 0x32, + 0x7a, + 0x33, + 0x51, + 0x7a, + 0x62, + 0x65, + 0x74, + 0x73, + 0x62, + 0x36, + 0x56, + 0x47, + 0x63, + 0x33, + 0x0a, + 0x61, + 0x48, + 0x57, + 0x32, + 0x54, + 0x35, + 0x54, + 0x6d, + 0x77, + 0x32, + 0x51, + 0x41, + 0x51, + 0x39, + 0x45, + 0x56, + 0x48, + 0x43, + 0x50, + 0x57, + 0x33, + 0x7a, + 0x6a, + 0x41, + 0x6b, + 0x6a, + 0x6a, + 0x2f, + 0x30, + 0x61, + 0x76, + 0x6b, + 0x57, + 0x2f, + 0x53, + 0x32, + 0x34, + 0x79, + 0x75, + 0x30, + 0x39, + 0x65, + 0x31, + 0x47, + 0x4d, + 0x61, + 0x6a, + 0x68, + 0x6e, + 0x4a, + 0x43, + 0x30, + 0x41, + 0x78, + 0x71, + 0x37, + 0x7a, + 0x32, + 0x75, + 0x51, + 0x61, + 0x67, + 0x54, + 0x47, + 0x0a, + 0x32, + 0x5a, + 0x66, + 0x6b, + 0x55, + 0x38, + 0x31, + 0x55, + 0x52, + 0x39, + 0x75, + 0x65, + 0x76, + 0x54, + 0x6f, + 0x6a, + 0x6e, + 0x66, + 0x34, + 0x56, + 0x71, + 0x77, + 0x35, + 0x55, + 0x76, + 0x63, + 0x72, + 0x77, + 0x6a, + 0x4e, + 0x6d, + 0x6d, + 0x4e, + 0x79, + 0x45, + 0x4d, + 0x33, + 0x63, + 0x2f, + 0x67, + 0x63, + 0x51, + 0x4b, + 0x42, + 0x67, + 0x48, + 0x61, + 0x32, + 0x64, + 0x54, + 0x35, + 0x73, + 0x76, + 0x7a, + 0x4d, + 0x31, + 0x6a, + 0x52, + 0x65, + 0x69, + 0x4f, + 0x33, + 0x56, + 0x74, + 0x0a, + 0x64, + 0x41, + 0x55, + 0x44, + 0x7a, + 0x74, + 0x47, + 0x4b, + 0x55, + 0x45, + 0x33, + 0x63, + 0x6c, + 0x50, + 0x56, + 0x33, + 0x35, + 0x4c, + 0x32, + 0x78, + 0x6d, + 0x4a, + 0x65, + 0x4a, + 0x44, + 0x58, + 0x50, + 0x4f, + 0x71, + 0x43, + 0x4c, + 0x33, + 0x71, + 0x6f, + 0x5a, + 0x39, + 0x41, + 0x36, + 0x68, + 0x48, + 0x6d, + 0x44, + 0x77, + 0x36, + 0x67, + 0x6d, + 0x67, + 0x38, + 0x32, + 0x67, + 0x51, + 0x44, + 0x51, + 0x65, + 0x4a, + 0x62, + 0x4c, + 0x2f, + 0x2b, + 0x6a, + 0x4b, + 0x6b, + 0x6f, + 0x6e, + 0x0a, + 0x65, + 0x36, + 0x61, + 0x74, + 0x48, + 0x2f, + 0x44, + 0x66, + 0x72, + 0x2b, + 0x4d, + 0x34, + 0x6e, + 0x50, + 0x66, + 0x74, + 0x39, + 0x4c, + 0x74, + 0x34, + 0x66, + 0x4f, + 0x41, + 0x57, + 0x4f, + 0x51, + 0x33, + 0x74, + 0x44, + 0x73, + 0x44, + 0x75, + 0x43, + 0x6b, + 0x4f, + 0x4d, + 0x6a, + 0x53, + 0x54, + 0x6e, + 0x38, + 0x63, + 0x4c, + 0x4d, + 0x5a, + 0x4c, + 0x47, + 0x63, + 0x77, + 0x54, + 0x32, + 0x48, + 0x31, + 0x48, + 0x32, + 0x76, + 0x42, + 0x6f, + 0x63, + 0x4d, + 0x2b, + 0x55, + 0x54, + 0x64, + 0x0a, + 0x68, + 0x6c, + 0x6a, + 0x41, + 0x56, + 0x6e, + 0x42, + 0x39, + 0x76, + 0x36, + 0x4e, + 0x4d, + 0x66, + 0x63, + 0x52, + 0x45, + 0x52, + 0x54, + 0x78, + 0x31, + 0x30, + 0x53, + 0x55, + 0x63, + 0x0a, + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x45, + 0x4e, + 0x44, + 0x20, + 0x50, + 0x52, + 0x49, + 0x56, + 0x41, + 0x54, + 0x45, + 0x20, + 0x4b, + 0x45, + 0x59, + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x2d, + 0x0a, }; +#endif #ifndef OPENSSL_NO_EC +#ifndef OPENSSL_NO_DEPRECATED_3_0 /* -----BEGIN EC PRIVATE KEY----- MHcCAQEEIJLyl7hJjpQL/RhP1x2zS79xdiPJQB683gWeqcqHPeZkoAoGCCqGSM49 @@ -493,6 +3143,7 @@ static const char ECDSAPrivateKeyPEM[] = { 0x4e, 0x44, 0x20, 0x45, 0x43, 0x20, 0x50, 0x52, 0x49, 0x56, 0x41, 0x54, 0x45, 0x20, 0x4b, 0x45, 0x59, 0x2d, 0x2d, 0x2d, 0x2d, 0x2d, 0x0a }; +#endif /* -----BEGIN CERTIFICATE----- @@ -555,7 +3206,7 @@ static const char ECDSACertPEM[] = { }; #endif -#ifndef OPENSSL_NO_DSA +#if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0) /* -----BEGIN DSA PRIVATE KEY----- MIIBuwIBAAKBgQDdkFKzNABLOha7Eqj7004+p5fhtR6bxpujToMmSZTYi8igVVXP @@ -775,109 +3426,121 @@ time_t time(time_t *t) TIME_IMPL(t) return 1; } -static int use_pem_privkey(SSL_CTX *ctx, const void *pem, size_t pem_len) -{ - BIO *bio_buf; - EVP_PKEY *pkey; - int rv = 0; - - bio_buf = BIO_new(BIO_s_mem()); - if (bio_buf == NULL) - return 0; - if ((size_t)BIO_write(bio_buf, pem, (int)pem_len) != pem_len) { - BIO_free(bio_buf); - return 0; - } - pkey = PEM_read_bio_PrivateKey(bio_buf, NULL, NULL, NULL); - BIO_free(bio_buf); - if (pkey == NULL) - return 0; - if (SSL_CTX_use_PrivateKey(ctx, pkey) == 1) - rv = 1; - EVP_PKEY_free(pkey); - return rv; -} - -static int use_pem_cert(SSL_CTX *ctx, const void *pem, size_t pem_len) -{ - BIO *bio_buf; - X509 *cert; - int rv = 0; - - bio_buf = BIO_new(BIO_s_mem()); - if (bio_buf == NULL) - return 0; - if ((size_t)BIO_write(bio_buf, pem, (int)pem_len) != pem_len) { - BIO_free(bio_buf); - return 0; - } - cert = PEM_read_bio_X509(bio_buf, NULL, NULL, NULL); - BIO_free(bio_buf); - if (cert == NULL) - return 0; - if (SSL_CTX_use_certificate(ctx, cert) == 1) - rv = 1; - X509_free(cert); - return rv; -} - int FuzzerTestOneInput(const uint8_t *buf, size_t len) { - SSL *server = NULL; + SSL *server; BIO *in; BIO *out; + BIO *bio_buf; SSL_CTX *ctx; + int ret; +#ifndef OPENSSL_NO_DEPRECATED_3_0 + RSA *privkey; +#endif +#if !defined(OPENSSL_NO_DEPRECATED_3_0) + EVP_PKEY *pkey; +#endif + X509 *cert; +#ifndef OPENSSL_NO_DEPRECATED_3_0 +#ifndef OPENSSL_NO_EC + EC_KEY *ecdsakey = NULL; +#endif +#endif +#if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0) + DSA *dsakey = NULL; +#endif if (len < 2 || len > INT_MAX) return 0; + /* This only fuzzes the initial flow from the client so far. */ ctx = SSL_CTX_new(DTLS_server_method()); - if (ctx == NULL) - return 0; - if (SSL_CTX_set_min_proto_version(ctx, 0) != 1) - goto end; - if (SSL_CTX_set_cipher_list(ctx, "ALL:eNULL:@SECLEVEL=0") != 1) - goto end; + ret = SSL_CTX_set_min_proto_version(ctx, 0); + OPENSSL_assert(ret == 1); + ret = SSL_CTX_set_cipher_list(ctx, "ALL:eNULL:@SECLEVEL=0"); + OPENSSL_assert(ret == 1); +#ifndef OPENSSL_NO_DEPRECATED_3_0 /* RSA */ - if (!use_pem_privkey(ctx, RSAPrivateKeyPEM, sizeof(RSAPrivateKeyPEM))) - goto end; - if (!use_pem_cert(ctx, RSACertificatePEM, sizeof(RSACertificatePEM))) - goto end; - -#ifndef OPENSSL_NO_EC - /* ECDSA */ - if (!use_pem_privkey(ctx, ECDSAPrivateKeyPEM, sizeof(ECDSAPrivateKeyPEM))) - goto end; - if (!use_pem_cert(ctx, ECDSACertPEM, sizeof(ECDSACertPEM))) - goto end; + bio_buf = BIO_new(BIO_s_mem()); + OPENSSL_assert((size_t)BIO_write(bio_buf, RSAPrivateKeyPEM, sizeof(RSAPrivateKeyPEM)) == sizeof(RSAPrivateKeyPEM)); + privkey = PEM_read_bio_RSAPrivateKey(bio_buf, NULL, NULL, NULL); + ERR_print_errors_fp(stderr); + OPENSSL_assert(privkey != NULL); + BIO_free(bio_buf); + pkey = EVP_PKEY_new(); + EVP_PKEY_assign_RSA(pkey, privkey); + ret = SSL_CTX_use_PrivateKey(ctx, pkey); + OPENSSL_assert(ret == 1); + EVP_PKEY_free(pkey); #endif -#ifndef OPENSSL_NO_DSA + bio_buf = BIO_new(BIO_s_mem()); + OPENSSL_assert((size_t)BIO_write(bio_buf, RSACertificatePEM, sizeof(RSACertificatePEM)) == sizeof(RSACertificatePEM)); + cert = PEM_read_bio_X509(bio_buf, NULL, NULL, NULL); + BIO_free(bio_buf); + OPENSSL_assert(cert != NULL); + ret = SSL_CTX_use_certificate(ctx, cert); + OPENSSL_assert(ret == 1); + X509_free(cert); + +#ifndef OPENSSL_NO_EC +#ifndef OPENSSL_NO_DEPRECATED_3_0 + /* ECDSA */ + bio_buf = BIO_new(BIO_s_mem()); + OPENSSL_assert((size_t)BIO_write(bio_buf, ECDSAPrivateKeyPEM, sizeof(ECDSAPrivateKeyPEM)) == sizeof(ECDSAPrivateKeyPEM)); + ecdsakey = PEM_read_bio_ECPrivateKey(bio_buf, NULL, NULL, NULL); + ERR_print_errors_fp(stderr); + OPENSSL_assert(ecdsakey != NULL); + BIO_free(bio_buf); + pkey = EVP_PKEY_new(); + EVP_PKEY_assign_EC_KEY(pkey, ecdsakey); + ret = SSL_CTX_use_PrivateKey(ctx, pkey); + OPENSSL_assert(ret == 1); + EVP_PKEY_free(pkey); +#endif + bio_buf = BIO_new(BIO_s_mem()); + OPENSSL_assert((size_t)BIO_write(bio_buf, ECDSACertPEM, sizeof(ECDSACertPEM)) == sizeof(ECDSACertPEM)); + cert = PEM_read_bio_X509(bio_buf, NULL, NULL, NULL); + OPENSSL_assert(cert != NULL); + BIO_free(bio_buf); + ret = SSL_CTX_use_certificate(ctx, cert); + OPENSSL_assert(ret == 1); + X509_free(cert); +#endif + +#if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0) /* DSA */ - if (!use_pem_privkey(ctx, DSAPrivateKeyPEM, sizeof(DSAPrivateKeyPEM))) - goto end; - if (!use_pem_cert(ctx, DSACertPEM, sizeof(DSACertPEM))) - goto end; + bio_buf = BIO_new(BIO_s_mem()); + OPENSSL_assert((size_t)BIO_write(bio_buf, DSAPrivateKeyPEM, sizeof(DSAPrivateKeyPEM)) == sizeof(DSAPrivateKeyPEM)); + dsakey = PEM_read_bio_DSAPrivateKey(bio_buf, NULL, NULL, NULL); + ERR_print_errors_fp(stderr); + OPENSSL_assert(dsakey != NULL); + BIO_free(bio_buf); + pkey = EVP_PKEY_new(); + EVP_PKEY_assign_DSA(pkey, dsakey); + ret = SSL_CTX_use_PrivateKey(ctx, pkey); + OPENSSL_assert(ret == 1); + EVP_PKEY_free(pkey); + + bio_buf = BIO_new(BIO_s_mem()); + OPENSSL_assert((size_t)BIO_write(bio_buf, DSACertPEM, sizeof(DSACertPEM)) == sizeof(DSACertPEM)); + cert = PEM_read_bio_X509(bio_buf, NULL, NULL, NULL); + OPENSSL_assert(cert != NULL); + BIO_free(bio_buf); + ret = SSL_CTX_use_certificate(ctx, cert); + OPENSSL_assert(ret == 1); + X509_free(cert); #endif server = SSL_new(ctx); - if (server == NULL) - goto end; in = BIO_new(BIO_s_mem()); - if (in == NULL) - goto end; out = BIO_new(BIO_s_mem()); - if (out == NULL) { - BIO_free(in); - goto end; - } SSL_set_bio(server, in, out); SSL_set_accept_state(server); - if ((size_t)BIO_write(in, buf, (int)len) != len) - goto end; + OPENSSL_assert((size_t)BIO_write(in, buf, (int)len) == len); if (SSL_do_handshake(server) == 1) { /* Keep reading application data until error or EOF. */ @@ -888,7 +3551,6 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) } } } -end: SSL_free(server); ERR_clear_error(); SSL_CTX_free(ctx); diff --git a/fuzz/echconfiglist_parser.c b/fuzz/echconfiglist_parser.c deleted file mode 100644 index fce416ec4d..0000000000 --- a/fuzz/echconfiglist_parser.c +++ /dev/null @@ -1,88 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * https://www.openssl.org/source/license.html - * or in the file LICENSE in the source distribution. - */ -#include -#include -#include -#include -#include -#include -#include -#include "fuzzer.h" - -static void parse_one(const uint8_t *buf, int len) -{ - OSSL_ECHSTORE *es; - BIO *in; - - es = OSSL_ECHSTORE_new(NULL, NULL); - if (es == NULL) - return; - - in = BIO_new_mem_buf(buf, len); - if (in == NULL) { - OSSL_ECHSTORE_free(es); - return; - } - - OSSL_ECHSTORE_read_echconfiglist(es, in); - - OSSL_ECHSTORE_free(es); - BIO_free(in); -} - -int FuzzerInitialize(int *argc, char ***argv) -{ - return 1; -} - -int FuzzerTestOneInput(const uint8_t *buf, size_t len) -{ - uint8_t *fixed_buf = NULL; - int bio_len; - uint16_t outer_len, inner_len; - - if (len > INT_MAX) - return 0; - bio_len = (int)len; - - /* Target raw without any fixup */ - parse_one(buf, bio_len); - - /* - * ech_decode_and_flatten has a strict size check: - * OSSL_ECH_MIN_ECHCONFIG_LEN = 32 - * OSSL_ECH_MAX_ECHCONFIG_LEN = 1500 - */ - if (len < OSSL_ECH_MIN_ECHCONFIG_LEN || len >= OSSL_ECH_MAX_ECHCONFIG_LEN) - goto end; - outer_len = (uint16_t)(len - 2); - inner_len = (uint16_t)(len - 6); - - fixed_buf = OPENSSL_memdup(buf, len); - if (fixed_buf == NULL) - goto end; - - /* Fix up to pass initial checks*/ - OPENSSL_store_u16_be(fixed_buf, outer_len); - OPENSSL_store_u16_be(fixed_buf + 2, OSSL_ECH_RFC9849_VERSION); - OPENSSL_store_u16_be(fixed_buf + 4, inner_len); - - parse_one(fixed_buf, bio_len); - -end: - OPENSSL_free(fixed_buf); - ERR_clear_error(); - - return 0; -} - -void FuzzerCleanup(void) -{ -} diff --git a/fuzz/hashtable.c b/fuzz/hashtable.c index 9eb81c0a9e..9e9519b865 100644 --- a/fuzz/hashtable.c +++ b/fuzz/hashtable.c @@ -162,11 +162,22 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) /* set the proper key value */ HT_SET_KEY_FIELD(&key, fuzzkey, keyval); - memcpy(&valptr->value, &buf[3], sizeof(uint64_t)); - /* lock the table */ ossl_ht_write_lock(fuzzer_table); + /* + * If the value to insert is already allocated + * then we expect a conflict in the insert + * i.e. we predict a return code of 0 instead + * of 1. On replacement, we expect it to succeed + * always + */ + if (valptr->flags & FZ_FLAG_ALLOCATED) { + if (!IS_REPLACE(op_flags)) + rc_prediction = 0; + } + + memcpy(&valptr->value, &buf[3], sizeof(uint64_t)); /* * do the insert/replace */ @@ -177,18 +188,30 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) rc = ossl_ht_fz_FUZZER_VALUE_insert(fuzzer_table, TO_HT_KEY(&key), valptr, NULL); + if (rc == -1) + /* failed to grow the hash table due to too many collisions */ + break; + + /* + * mark the entry as being allocated + */ + valptr->flags |= FZ_FLAG_ALLOCATED; + /* * unlock the table */ ossl_ht_write_unlock(fuzzer_table); /* - * mark the entry as being allocated + * Now check to make sure we did the right thing */ - if (rc == 1) { - valptr->flags |= FZ_FLAG_ALLOCATED; + OPENSSL_assert(rc == rc_prediction); + + /* + * successful insertion if there wasn't a conflict + */ + if (rc_prediction == 1) IS_REPLACE(op_flags) ? replacements++ : inserts++; - } break; case OP_DELETE: @@ -203,6 +226,15 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) /* lock the table */ ossl_ht_write_lock(fuzzer_table); + /* + * If the value to delete is not already allocated + * then we expect a miss in the delete + * i.e. we predict a return code of 0 instead + * of 1 + */ + if (!(valptr->flags & FZ_FLAG_ALLOCATED)) + rc_prediction = 0; + /* * do the delete */ @@ -213,10 +245,22 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) */ ossl_ht_write_unlock(fuzzer_table); + /* + * Now check to make sure we did the right thing + */ + OPENSSL_assert(rc == rc_prediction); + + /* + * once the unlock is done, the table rcu will have synced + * meaning the free function has run, so we can confirm now + * that the valptr is no longer allocated + */ + OPENSSL_assert(!(valptr->flags & FZ_FLAG_ALLOCATED)); + /* * successful deletion if there wasn't a conflict */ - if (rc == 1) + if (rc_prediction == 1) deletes++; break; @@ -257,23 +301,25 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) /* * Now check to make sure we did the right thing */ - if (valptr == NULL) - OPENSSL_assert(lval == NULL); - else - OPENSSL_assert(lval == NULL || lval == valptr); + OPENSSL_assert(lval == valptr); /* * if we expect a positive lookup, make sure that * we can use the _type and to_value functions */ - if (valptr != NULL && lval != NULL) { + if (valptr != NULL) { OPENSSL_assert(ossl_ht_fz_FUZZER_VALUE_type(v) == 1); v = ossl_ht_fz_FUZZER_VALUE_to_value(lval, &tv); OPENSSL_assert(v->value == lval); - lookups++; } + /* + * successful lookup if we didn't expect a miss + */ + if (valptr != NULL) + lookups++; + break; case OP_FLUSH: @@ -290,17 +336,17 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) * lock the table */ ossl_ht_write_lock(fuzzer_table); - rc = ossl_ht_flush(fuzzer_table); + ossl_ht_flush(fuzzer_table); ossl_ht_write_unlock(fuzzer_table); /* * now check to make sure everything is free */ - if (rc == 1) { - for (i = 0; i < USHRT_MAX; i++) - OPENSSL_assert((prediction_table[i].flags & FZ_FLAG_ALLOCATED) == 0); - flushes++; - } + for (i = 0; i < USHRT_MAX; i++) + OPENSSL_assert((prediction_table[i].flags & FZ_FLAG_ALLOCATED) == 0); + + /* good flush */ + flushes++; break; case OP_FOREACH: @@ -326,11 +372,11 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) rc_prediction = 1; htvlist = ossl_ht_filter(fuzzer_table, 1, filter_iterator, &keyval); - if (htvlist != NULL) { - OPENSSL_assert(htvlist->list_len == (size_t)rc_prediction); - ossl_ht_value_list_free(htvlist); - filters++; - } + + OPENSSL_assert(htvlist->list_len == (size_t)rc_prediction); + + ossl_ht_value_list_free(htvlist); + filters++; break; default: diff --git a/fuzz/ml-dsa.c b/fuzz/ml-dsa.c index e56a023e46..094af9096a 100644 --- a/fuzz/ml-dsa.c +++ b/fuzz/ml-dsa.c @@ -254,10 +254,6 @@ static int keygen_ml_dsa_real_key_helper(uint8_t **buf, size_t *len, ret = 1; err: - if (!ret) { - EVP_PKEY_free(*key); - *key = NULL; - } EVP_PKEY_CTX_free(ctx); return ret; } @@ -663,7 +659,7 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) /* And run our setup/doit/cleanup sequence */ if (ops[operation].setup != NULL) ops[operation].setup(&buffer_cursor, &len, &in1, &in2); - if (ops[operation].doit != NULL && in1 != NULL) + if (ops[operation].doit != NULL) ops[operation].doit(&buffer_cursor, &len, in1, in2, &out1, &out2); if (ops[operation].cleanup != NULL) ops[operation].cleanup(in1, in2, out1, out2); diff --git a/fuzz/ml-kem.c b/fuzz/ml-kem.c index dfd4faf6dc..6e3aed8b23 100644 --- a/fuzz/ml-kem.c +++ b/fuzz/ml-kem.c @@ -650,7 +650,7 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) */ if (ops[operation].setup != NULL) ops[operation].setup(&buffer_cursor, &len, &in1, &in2); - if (ops[operation].doit != NULL && in1 != NULL) + if (ops[operation].doit != NULL) ops[operation].doit(&buffer_cursor, &len, in1, in2, &out1, &out2); if (ops[operation].cleanup != NULL) ops[operation].cleanup(in1, in2, out1, out2); diff --git a/fuzz/oids.txt b/fuzz/oids.txt index 5fac3e1c88..b299cc2d64 100644 --- a/fuzz/oids.txt +++ b/fuzz/oids.txt @@ -1,7 +1,7 @@ # WARNING: do not edit! # Generated by fuzz/mkfuzzoids.pl # -# Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -1349,4 +1349,3 @@ OBJ_HKDF_SHA384="\x2A\x86\x48\x86\xF7\x0D\x01\x09\x10\x03\x1D" OBJ_HKDF_SHA512="\x2A\x86\x48\x86\xF7\x0D\x01\x09\x10\x03\x1E" OBJ_id_smime_ori="\x2A\x86\x48\x86\xF7\x0D\x01\x09\x10\x0D" OBJ_id_smime_ori_kem="\x2A\x86\x48\x86\xF7\x0D\x01\x09\x10\x0D\x03" -OBJ_id_alg_hss_lms_hashsig="\x2A\x86\x48\x86\xF7\x0D\x01\x09\x10\x03\x11" diff --git a/fuzz/pem.c b/fuzz/pem.c index a2da9820a7..a8a1d810f0 100644 --- a/fuzz/pem.c +++ b/fuzz/pem.c @@ -31,15 +31,7 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) return 0; in = BIO_new(BIO_s_mem()); - if (in == NULL) { - ERR_clear_error(); - return 0; - } - if ((size_t)BIO_write(in, buf + 1, (int)(len - 1)) != len - 1) { - BIO_free(in); - ERR_clear_error(); - return 0; - } + OPENSSL_assert((size_t)BIO_write(in, buf + 1, (int)(len - 1)) == len - 1); if (PEM_read_bio_ex(in, &name, &header, &data, &outlen, buf[0]) == 1) { /* Try to read all the data we get to see if allocated properly. */ BIO_write(in, name, (int)strlen(name)); diff --git a/fuzz/pkcs12.c b/fuzz/pkcs12.c deleted file mode 100644 index 74e2b6dd8a..0000000000 --- a/fuzz/pkcs12.c +++ /dev/null @@ -1,80 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"); - * you may not use this file except in compliance with the License. - * You may obtain a copy of the License at - * https://www.openssl.org/source/license.html - * or in the file LICENSE in the source distribution. - */ - -/* - * Test PKCS12 parsing with fuzzed input. - */ - -#include -#include -#include -#include -#include "fuzzer.h" - -int FuzzerInitialize(int *argc, char ***argv) -{ - OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CRYPTO_STRINGS, NULL); - ERR_clear_error(); - CRYPTO_free_ex_index(0, -1); - - return 1; -} - -int FuzzerTestOneInput(const uint8_t *buf, size_t len) -{ - PKCS12 *p12; - BIO *in; - EVP_PKEY *pkey = NULL; - X509 *cert = NULL; - STACK_OF(X509) *ca = NULL; - - if (len == 0 || len > INT_MAX) - return 0; - - in = BIO_new(BIO_s_mem()); - if (in == NULL) { - ERR_clear_error(); - return 0; - } - if ((size_t)BIO_write(in, buf, (int)len) != len) { - BIO_free(in); - ERR_clear_error(); - return 0; - } - p12 = d2i_PKCS12_bio(in, NULL); - if (p12 != NULL) { - PKCS12_verify_mac(p12, NULL, 0); - PKCS12_verify_mac(p12, "", 0); - - PKCS12_parse(p12, NULL, &pkey, &cert, &ca); - EVP_PKEY_free(pkey); - X509_free(cert); - OSSL_STACK_OF_X509_free(ca); - - pkey = NULL; - cert = NULL; - ca = NULL; - PKCS12_parse(p12, "", &pkey, &cert, &ca); - EVP_PKEY_free(pkey); - X509_free(cert); - OSSL_STACK_OF_X509_free(ca); - - PKCS12_free(p12); - } - - BIO_free(in); - ERR_clear_error(); - - return 0; -} - -void FuzzerCleanup(void) -{ -} diff --git a/fuzz/provider.c b/fuzz/provider.c index bc45489a2f..45f639a71b 100644 --- a/fuzz/provider.c +++ b/fuzz/provider.c @@ -1,5 +1,5 @@ /* - * Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -32,11 +32,8 @@ { \ STACK_OF(evp) *obj_stack = stack; \ \ - if (!evp##_up_ref(obj)) \ - return; \ - \ - if (sk_##evp##_push(obj_stack, obj) <= 0) \ - evp##_free(obj); \ + if (sk_##evp##_push(obj_stack, obj) > 0) \ + evp##_up_ref(obj); \ } \ static void init_##name(OSSL_LIB_CTX *libctx) \ { \ @@ -115,10 +112,6 @@ static int read_uint(const uint8_t **buf, size_t *len, uint64_t **res) } *res = OPENSSL_malloc(sizeof(uint64_t)); - if (*res == NULL) { - r = 0; - goto end; - } **res = (uint64_t)**buf; *buf += sizeof(uint64_t); @@ -137,10 +130,6 @@ static int read_int(const uint8_t **buf, size_t *len, int64_t **res) } *res = OPENSSL_malloc(sizeof(int64_t)); - if (*res == NULL) { - r = 0; - goto end; - } **res = (int64_t)**buf; *buf += sizeof(int64_t); @@ -159,10 +148,6 @@ static int read_double(const uint8_t **buf, size_t *len, double **res) } *res = OPENSSL_malloc(sizeof(double)); - if (*res == NULL) { - r = 0; - goto end; - } **res = (double)**buf; *buf += sizeof(double); @@ -285,8 +270,6 @@ static OSSL_PARAM *fuzz_params(OSSL_PARAM *param, const uint8_t **buf, size_t *l p_num++; fuzzed_parameters = OPENSSL_calloc(p_num + 1, sizeof(OSSL_PARAM)); - if (fuzzed_parameters == NULL) - return NULL; p = fuzzed_parameters; for (; param != NULL && param->key != NULL; param++) { @@ -303,11 +286,6 @@ static OSSL_PARAM *fuzz_params(OSSL_PARAM *param, const uint8_t **buf, size_t *l if (!read_int(buf, len, &use_param)) { use_param = OPENSSL_malloc(sizeof(uint64_t)); - if (use_param == NULL) { - free_params(fuzzed_parameters); - OPENSSL_free(fuzzed_parameters); - return NULL; - } *use_param = 0; } @@ -315,48 +293,18 @@ static OSSL_PARAM *fuzz_params(OSSL_PARAM *param, const uint8_t **buf, size_t *l case OSSL_PARAM_INTEGER: if (strcmp(param->key, OSSL_KDF_PARAM_ITER) == 0) { p_value_int = OPENSSL_malloc(sizeof(ITERS)); - if (p_value_int == NULL) { - free_params(fuzzed_parameters); - OPENSSL_free(fuzzed_parameters); - OPENSSL_free(use_param); - return NULL; - } *p_value_int = ITERS; } else if (strcmp(param->key, OSSL_KDF_PARAM_SCRYPT_N) == 0) { p_value_int = OPENSSL_malloc(sizeof(ITERS)); - if (p_value_int == NULL) { - free_params(fuzzed_parameters); - OPENSSL_free(fuzzed_parameters); - OPENSSL_free(use_param); - return NULL; - } *p_value_int = ITERS; } else if (strcmp(param->key, OSSL_KDF_PARAM_SCRYPT_R) == 0) { p_value_int = OPENSSL_malloc(sizeof(BLOCKSIZE)); - if (p_value_int == NULL) { - free_params(fuzzed_parameters); - OPENSSL_free(fuzzed_parameters); - OPENSSL_free(use_param); - return NULL; - } *p_value_int = BLOCKSIZE; } else if (strcmp(param->key, OSSL_KDF_PARAM_SCRYPT_P) == 0) { p_value_int = OPENSSL_malloc(sizeof(BLOCKSIZE)); - if (p_value_int == NULL) { - free_params(fuzzed_parameters); - OPENSSL_free(fuzzed_parameters); - OPENSSL_free(use_param); - return NULL; - } *p_value_int = BLOCKSIZE; } else if (!*use_param || !read_int(buf, len, &p_value_int)) { p_value_int = OPENSSL_malloc(sizeof(int64_t)); - if (p_value_int == NULL) { - free_params(fuzzed_parameters); - OPENSSL_free(fuzzed_parameters); - OPENSSL_free(use_param); - return NULL; - } *p_value_int = 0; } @@ -367,48 +315,18 @@ static OSSL_PARAM *fuzz_params(OSSL_PARAM *param, const uint8_t **buf, size_t *l case OSSL_PARAM_UNSIGNED_INTEGER: if (strcmp(param->key, OSSL_KDF_PARAM_ITER) == 0) { p_value_uint = OPENSSL_malloc(sizeof(UITERS)); - if (p_value_uint == NULL) { - free_params(fuzzed_parameters); - OPENSSL_free(fuzzed_parameters); - OPENSSL_free(use_param); - return NULL; - } *p_value_uint = UITERS; } else if (strcmp(param->key, OSSL_KDF_PARAM_SCRYPT_N) == 0) { p_value_uint = OPENSSL_malloc(sizeof(UITERS)); - if (p_value_uint == NULL) { - free_params(fuzzed_parameters); - OPENSSL_free(fuzzed_parameters); - OPENSSL_free(use_param); - return NULL; - } *p_value_uint = UITERS; } else if (strcmp(param->key, OSSL_KDF_PARAM_SCRYPT_R) == 0) { p_value_uint = OPENSSL_malloc(sizeof(UBLOCKSIZE)); - if (p_value_uint == NULL) { - free_params(fuzzed_parameters); - OPENSSL_free(fuzzed_parameters); - OPENSSL_free(use_param); - return NULL; - } *p_value_uint = UBLOCKSIZE; } else if (strcmp(param->key, OSSL_KDF_PARAM_SCRYPT_P) == 0) { p_value_uint = OPENSSL_malloc(sizeof(UBLOCKSIZE)); - if (p_value_uint == NULL) { - free_params(fuzzed_parameters); - OPENSSL_free(fuzzed_parameters); - OPENSSL_free(use_param); - return NULL; - } *p_value_uint = UBLOCKSIZE; } else if (!*use_param || !read_uint(buf, len, &p_value_uint)) { p_value_uint = OPENSSL_malloc(sizeof(uint64_t)); - if (p_value_uint == NULL) { - free_params(fuzzed_parameters); - OPENSSL_free(fuzzed_parameters); - OPENSSL_free(use_param); - return NULL; - } *p_value_uint = 0; } @@ -419,12 +337,6 @@ static OSSL_PARAM *fuzz_params(OSSL_PARAM *param, const uint8_t **buf, size_t *l case OSSL_PARAM_REAL: if (!*use_param || !read_double(buf, len, &p_value_double)) { p_value_double = OPENSSL_malloc(sizeof(double)); - if (p_value_double == NULL) { - free_params(fuzzed_parameters); - OPENSSL_free(fuzzed_parameters); - OPENSSL_free(use_param); - return NULL; - } *p_value_double = 0; } @@ -478,57 +390,42 @@ static int do_evp_cipher(const EVP_CIPHER *evp_cipher, const OSSL_PARAM param[]) { unsigned char outbuf[1024]; int outlen, tmplen; - int key_len = EVP_CIPHER_get_key_length(evp_cipher); - int iv_len = EVP_CIPHER_get_iv_length(evp_cipher); - unsigned char *key = NULL, *iv = NULL; + unsigned char key[] = { 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15 }; + unsigned char iv[] = { 1, 2, 3, 4, 5, 6, 7, 8 }; const char intext[] = "text"; - EVP_CIPHER_CTX *ctx = NULL; - int i; - - if (key_len <= 0) - key_len = 16; - if (iv_len <= 0) - iv_len = 16; - - key = OPENSSL_zalloc(key_len); - iv = OPENSSL_zalloc(iv_len); - if (key == NULL || iv == NULL) - goto err; - for (i = 0; i < key_len; i++) - key[i] = (unsigned char)i; - for (i = 0; i < iv_len; i++) - iv[i] = (unsigned char)(i + 1); + EVP_CIPHER_CTX *ctx; ctx = EVP_CIPHER_CTX_new(); - if (ctx == NULL) - goto err; - if (!EVP_EncryptInit_ex2(ctx, evp_cipher, key, iv, NULL)) - goto err; + if (!EVP_CIPHER_CTX_set_params(ctx, param)) { + EVP_CIPHER_CTX_free(ctx); + return 0; + } - if (!EVP_CIPHER_CTX_set_params(ctx, param)) - goto err; + if (!EVP_EncryptInit_ex2(ctx, evp_cipher, key, iv, NULL)) { + /* Error */ + EVP_CIPHER_CTX_free(ctx); + return 0; + } if (!EVP_EncryptUpdate(ctx, outbuf, &outlen, (const unsigned char *)intext, - (int)strlen(intext))) - goto err; + (int)strlen(intext))) { + /* Error */ + EVP_CIPHER_CTX_free(ctx); + return 0; + } /* * Buffer passed to EVP_EncryptFinal() must be after data just * encrypted to avoid overwriting it. */ - if (!EVP_EncryptFinal_ex(ctx, outbuf + outlen, &tmplen)) - goto err; + if (!EVP_EncryptFinal_ex(ctx, outbuf + outlen, &tmplen)) { + /* Error */ + EVP_CIPHER_CTX_free(ctx); + return 0; + } outlen += tmplen; EVP_CIPHER_CTX_free(ctx); - OPENSSL_free(key); - OPENSSL_free(iv); return 1; - -err: - EVP_CIPHER_CTX_free(ctx); - OPENSSL_free(key); - OPENSSL_free(iv); - return 0; } static int do_evp_kdf(EVP_KDF *evp_kdf, const OSSL_PARAM params[]) @@ -658,12 +555,12 @@ static int do_evp_md(EVP_MD *evp_md, const OSSL_PARAM params[]) goto end; } - if (!EVP_DigestInit_ex2(mdctx, evp_md, NULL)) { + if (!EVP_MD_CTX_set_params(mdctx, params)) { r = 0; goto end; } - if (!EVP_MD_CTX_set_params(mdctx, params)) { + if (!EVP_DigestInit_ex2(mdctx, evp_md, NULL)) { r = 0; goto end; } diff --git a/fuzz/quic-client.c b/fuzz/quic-client.c index e75390ad60..851ecc5cc9 100644 --- a/fuzz/quic-client.c +++ b/fuzz/quic-client.c @@ -77,8 +77,6 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) if (client == NULL) goto end; - allstreams[0] = stream = client; - fake_now = ossl_ms2time(1); if (!ossl_quic_set_override_now_cb(client, fake_now_cb, NULL)) goto end; @@ -92,8 +90,7 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) if (!BIO_ADDR_rawmake(peer_addr, AF_INET, &ina, sizeof(ina), htons(4433))) goto end; - if (SSL_set_tlsext_host_name(client, "localhost") != 1) - goto end; + SSL_set_tlsext_host_name(client, "localhost"); in = BIO_new(BIO_s_dgram_mem()); if (in == NULL) goto end; @@ -119,6 +116,7 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) 0)) goto end; + allstreams[0] = stream = client; for (;;) { size_t size; uint64_t nxtpktms = 0; diff --git a/fuzz/quic-srtm.c b/fuzz/quic-srtm.c index 9eb4117adc..a7897da710 100644 --- a/fuzz/quic-srtm.c +++ b/fuzz/quic-srtm.c @@ -77,9 +77,9 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) sizeof(arg_token.token))) continue; /* just stop */ - if (ossl_quic_srtm_add(srtm, (void *)(uintptr_t)arg_opaque, - arg_seq_num, &arg_token)) - ossl_quic_srtm_check(srtm); + ossl_quic_srtm_add(srtm, (void *)(uintptr_t)arg_opaque, + arg_seq_num, &arg_token); + ossl_quic_srtm_check(srtm); break; case CMD_REMOVE: @@ -87,17 +87,17 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) || !PACKET_get_net_8(&pkt, &arg_seq_num)) continue; /* just stop */ - if (ossl_quic_srtm_remove(srtm, (void *)(uintptr_t)arg_opaque, - arg_seq_num, NULL)) - ossl_quic_srtm_check(srtm); + ossl_quic_srtm_remove(srtm, (void *)(uintptr_t)arg_opaque, + arg_seq_num); + ossl_quic_srtm_check(srtm); break; case CMD_CULL: if (!PACKET_get_net_8(&pkt, &arg_opaque)) continue; /* just stop */ - if (ossl_quic_srtm_cull(srtm, (void *)(uintptr_t)arg_opaque)) - ossl_quic_srtm_check(srtm); + ossl_quic_srtm_cull(srtm, (void *)(uintptr_t)arg_opaque); + ossl_quic_srtm_check(srtm); break; case CMD_LOOKUP: @@ -106,9 +106,9 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) || !PACKET_get_net_8(&pkt, &arg_idx)) continue; /* just stop */ - if (ossl_quic_srtm_lookup(srtm, &arg_token, (size_t)arg_idx, - NULL, NULL)) - ossl_quic_srtm_check(srtm); + ossl_quic_srtm_lookup(srtm, &arg_token, (size_t)arg_idx, + NULL, NULL); + ossl_quic_srtm_check(srtm); break; default: diff --git a/fuzz/server.c b/fuzz/server.c index 740ade8513..a9ff6c5e1c 100644 --- a/fuzz/server.c +++ b/fuzz/server.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -25,262 +25,1980 @@ #include #include "fuzzer.h" -#ifndef OPENSSL_NO_DEPRECATED_3_0 static const uint8_t kCertificateDER[] = { - 0x30, 0x82, 0x02, 0xff, 0x30, 0x82, 0x01, 0xe7, - 0xa0, 0x03, 0x02, 0x01, 0x02, 0x02, 0x11, 0x00, - 0xb1, 0x84, 0xee, 0x34, 0x99, 0x98, 0x76, 0xfb, - 0x6f, 0xb2, 0x15, 0xc8, 0x47, 0x79, 0x05, 0x9b, - 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, - 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x30, - 0x12, 0x31, 0x10, 0x30, 0x0e, 0x06, 0x03, 0x55, - 0x04, 0x0a, 0x13, 0x07, 0x41, 0x63, 0x6d, 0x65, - 0x20, 0x43, 0x6f, 0x30, 0x1e, 0x17, 0x0d, 0x31, - 0x35, 0x31, 0x31, 0x30, 0x37, 0x30, 0x30, 0x32, - 0x34, 0x35, 0x36, 0x5a, 0x17, 0x0d, 0x31, 0x36, - 0x31, 0x31, 0x30, 0x36, 0x30, 0x30, 0x32, 0x34, - 0x35, 0x36, 0x5a, 0x30, 0x12, 0x31, 0x10, 0x30, - 0x0e, 0x06, 0x03, 0x55, 0x04, 0x0a, 0x13, 0x07, - 0x41, 0x63, 0x6d, 0x65, 0x20, 0x43, 0x6f, 0x30, - 0x82, 0x01, 0x22, 0x30, 0x0d, 0x06, 0x09, 0x2a, - 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x01, - 0x05, 0x00, 0x03, 0x82, 0x01, 0x0f, 0x00, 0x30, - 0x82, 0x01, 0x0a, 0x02, 0x82, 0x01, 0x01, 0x00, - 0xce, 0x47, 0xcb, 0x11, 0xbb, 0xd2, 0x9d, 0x8e, - 0x9e, 0xd2, 0x1e, 0x14, 0xaf, 0xc7, 0xea, 0xb6, - 0xc9, 0x38, 0x2a, 0x6f, 0xb3, 0x7e, 0xfb, 0xbc, - 0xfc, 0x59, 0x42, 0xb9, 0x56, 0xf0, 0x4c, 0x3f, - 0xf7, 0x31, 0x84, 0xbe, 0xac, 0x03, 0x9e, 0x71, - 0x91, 0x85, 0xd8, 0x32, 0xbd, 0x00, 0xea, 0xac, - 0x65, 0xf6, 0x03, 0xc8, 0x0f, 0x8b, 0xfd, 0x6e, - 0x58, 0x88, 0x04, 0x41, 0x92, 0x74, 0xa6, 0x57, - 0x2e, 0x8e, 0x88, 0xd5, 0x3d, 0xda, 0x14, 0x3e, - 0x63, 0x88, 0x22, 0xe3, 0x53, 0xe9, 0xba, 0x39, - 0x09, 0xac, 0xfb, 0xd0, 0x4c, 0xf2, 0x3c, 0x20, - 0xd6, 0x97, 0xe6, 0xed, 0xf1, 0x62, 0x1e, 0xe5, - 0xc9, 0x48, 0xa0, 0xca, 0x2e, 0x3c, 0x14, 0x5a, - 0x82, 0xd4, 0xed, 0xb1, 0xe3, 0x43, 0xc1, 0x2a, - 0x59, 0xa5, 0xb9, 0xc8, 0x48, 0xa7, 0x39, 0x23, - 0x74, 0xa7, 0x37, 0xb0, 0x6f, 0xc3, 0x64, 0x99, - 0x6c, 0xa2, 0x82, 0xc8, 0xf6, 0xdb, 0x86, 0x40, - 0xce, 0xd1, 0x85, 0x9f, 0xce, 0x69, 0xf4, 0x15, - 0x2a, 0x23, 0xca, 0xea, 0xb7, 0x7b, 0xdf, 0xfb, - 0x43, 0x5f, 0xff, 0x7a, 0x49, 0x49, 0x0e, 0xe7, - 0x02, 0x51, 0x45, 0x13, 0xe8, 0x90, 0x64, 0x21, - 0x0c, 0x26, 0x2b, 0x5d, 0xfc, 0xe4, 0xb5, 0x86, - 0x89, 0x43, 0x22, 0x4c, 0xf3, 0x3b, 0xf3, 0x09, - 0xc4, 0xa4, 0x10, 0x80, 0xf2, 0x46, 0xe2, 0x46, - 0x8f, 0x76, 0x50, 0xbf, 0xaf, 0x2b, 0x90, 0x1b, - 0x78, 0xc7, 0xcf, 0xc1, 0x77, 0xd0, 0xfb, 0xa9, - 0xfb, 0xc9, 0x66, 0x5a, 0xc5, 0x9b, 0x31, 0x41, - 0x67, 0x01, 0xbe, 0x33, 0x10, 0xba, 0x05, 0x58, - 0xed, 0x76, 0x53, 0xde, 0x5d, 0xc1, 0xe8, 0xbb, - 0x9f, 0xf1, 0xcd, 0xfb, 0xdf, 0x64, 0x7f, 0xd7, - 0x18, 0xab, 0x0f, 0x94, 0x28, 0x95, 0x4a, 0xcc, - 0x6a, 0xa9, 0x50, 0xc7, 0x05, 0x47, 0x10, 0x41, - 0x02, 0x03, 0x01, 0x00, 0x01, 0xa3, 0x50, 0x30, - 0x4e, 0x30, 0x0e, 0x06, 0x03, 0x55, 0x1d, 0x0f, - 0x01, 0x01, 0xff, 0x04, 0x04, 0x03, 0x02, 0x05, - 0xa0, 0x30, 0x13, 0x06, 0x03, 0x55, 0x1d, 0x25, - 0x04, 0x0c, 0x30, 0x0a, 0x06, 0x08, 0x2b, 0x06, - 0x01, 0x05, 0x05, 0x07, 0x03, 0x01, 0x30, 0x0c, - 0x06, 0x03, 0x55, 0x1d, 0x13, 0x01, 0x01, 0xff, - 0x04, 0x02, 0x30, 0x00, 0x30, 0x19, 0x06, 0x03, - 0x55, 0x1d, 0x11, 0x04, 0x12, 0x30, 0x10, 0x82, - 0x0e, 0x66, 0x75, 0x7a, 0x7a, 0x2e, 0x62, 0x6f, - 0x72, 0x69, 0x6e, 0x67, 0x73, 0x73, 0x6c, 0x30, - 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, - 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x03, 0x82, - 0x01, 0x01, 0x00, 0x92, 0xde, 0xef, 0x96, 0x06, - 0x7b, 0xff, 0x71, 0x7d, 0x4e, 0xa0, 0x7d, 0xae, - 0xb8, 0x22, 0xb4, 0x2c, 0xf7, 0x96, 0x9c, 0x37, - 0x1d, 0x8f, 0xe7, 0xd9, 0x47, 0xff, 0x3f, 0xe9, - 0x35, 0x95, 0x0e, 0xdd, 0xdc, 0x7f, 0xc8, 0x8a, - 0x1e, 0x36, 0x1d, 0x38, 0x47, 0xfc, 0x76, 0xd2, - 0x1f, 0x98, 0xa1, 0x36, 0xac, 0xc8, 0x70, 0x38, - 0x0a, 0x3d, 0x51, 0x8d, 0x0f, 0x03, 0x1b, 0xef, - 0x62, 0xa1, 0xcb, 0x2b, 0x4a, 0x8c, 0x12, 0x2b, - 0x54, 0x50, 0x9a, 0x6b, 0xfe, 0xaf, 0xd9, 0xf6, - 0xbf, 0x58, 0x11, 0x58, 0x5e, 0xe5, 0x86, 0x1e, - 0x3b, 0x6b, 0x30, 0x7e, 0x72, 0x89, 0xe8, 0x6b, - 0x7b, 0xb7, 0xaf, 0xef, 0x8b, 0xa9, 0x3e, 0xb0, - 0xcd, 0x0b, 0xef, 0xb0, 0x0c, 0x96, 0x2b, 0xc5, - 0x3b, 0xd5, 0xf1, 0xc2, 0xae, 0x3a, 0x60, 0xd9, - 0x0f, 0x75, 0x37, 0x55, 0x4d, 0x62, 0xd2, 0xed, - 0x96, 0xac, 0x30, 0x6b, 0xda, 0xa1, 0x48, 0x17, - 0x96, 0x23, 0x85, 0x9a, 0x57, 0x77, 0xe9, 0x22, - 0xa2, 0x37, 0x03, 0xba, 0x49, 0x77, 0x40, 0x3b, - 0x76, 0x4b, 0xda, 0xc1, 0x04, 0x57, 0x55, 0x34, - 0x22, 0x83, 0x45, 0x29, 0xab, 0x2e, 0x11, 0xff, - 0x0d, 0xab, 0x55, 0xb1, 0xa7, 0x58, 0x59, 0x05, - 0x25, 0xf9, 0x1e, 0x3d, 0xb7, 0xac, 0x04, 0x39, - 0x2c, 0xf9, 0xaf, 0xb8, 0x68, 0xfb, 0x8e, 0x35, - 0x71, 0x32, 0xff, 0x70, 0xe9, 0x46, 0x6d, 0x5c, - 0x06, 0x90, 0x88, 0x23, 0x48, 0x0c, 0x50, 0xeb, - 0x0a, 0xa9, 0xae, 0xe8, 0xfc, 0xbe, 0xa5, 0x76, - 0x94, 0xd7, 0x64, 0x22, 0x38, 0x98, 0x17, 0xa4, - 0x3a, 0xa7, 0x59, 0x9f, 0x1d, 0x3b, 0x75, 0x90, - 0x1a, 0x81, 0xef, 0x19, 0xfb, 0x2b, 0xb7, 0xa7, - 0x64, 0x61, 0x22, 0xa4, 0x6f, 0x7b, 0xfa, 0x58, - 0xbb, 0x8c, 0x4e, 0x77, 0x67, 0xd0, 0x5d, 0x58, - 0x76, 0x8a, 0xbb + 0x30, + 0x82, + 0x02, + 0xff, + 0x30, + 0x82, + 0x01, + 0xe7, + 0xa0, + 0x03, + 0x02, + 0x01, + 0x02, + 0x02, + 0x11, + 0x00, + 0xb1, + 0x84, + 0xee, + 0x34, + 0x99, + 0x98, + 0x76, + 0xfb, + 0x6f, + 0xb2, + 0x15, + 0xc8, + 0x47, + 0x79, + 0x05, + 0x9b, + 0x30, + 0x0d, + 0x06, + 0x09, + 0x2a, + 0x86, + 0x48, + 0x86, + 0xf7, + 0x0d, + 0x01, + 0x01, + 0x0b, + 0x05, + 0x00, + 0x30, + 0x12, + 0x31, + 0x10, + 0x30, + 0x0e, + 0x06, + 0x03, + 0x55, + 0x04, + 0x0a, + 0x13, + 0x07, + 0x41, + 0x63, + 0x6d, + 0x65, + 0x20, + 0x43, + 0x6f, + 0x30, + 0x1e, + 0x17, + 0x0d, + 0x31, + 0x35, + 0x31, + 0x31, + 0x30, + 0x37, + 0x30, + 0x30, + 0x32, + 0x34, + 0x35, + 0x36, + 0x5a, + 0x17, + 0x0d, + 0x31, + 0x36, + 0x31, + 0x31, + 0x30, + 0x36, + 0x30, + 0x30, + 0x32, + 0x34, + 0x35, + 0x36, + 0x5a, + 0x30, + 0x12, + 0x31, + 0x10, + 0x30, + 0x0e, + 0x06, + 0x03, + 0x55, + 0x04, + 0x0a, + 0x13, + 0x07, + 0x41, + 0x63, + 0x6d, + 0x65, + 0x20, + 0x43, + 0x6f, + 0x30, + 0x82, + 0x01, + 0x22, + 0x30, + 0x0d, + 0x06, + 0x09, + 0x2a, + 0x86, + 0x48, + 0x86, + 0xf7, + 0x0d, + 0x01, + 0x01, + 0x01, + 0x05, + 0x00, + 0x03, + 0x82, + 0x01, + 0x0f, + 0x00, + 0x30, + 0x82, + 0x01, + 0x0a, + 0x02, + 0x82, + 0x01, + 0x01, + 0x00, + 0xce, + 0x47, + 0xcb, + 0x11, + 0xbb, + 0xd2, + 0x9d, + 0x8e, + 0x9e, + 0xd2, + 0x1e, + 0x14, + 0xaf, + 0xc7, + 0xea, + 0xb6, + 0xc9, + 0x38, + 0x2a, + 0x6f, + 0xb3, + 0x7e, + 0xfb, + 0xbc, + 0xfc, + 0x59, + 0x42, + 0xb9, + 0x56, + 0xf0, + 0x4c, + 0x3f, + 0xf7, + 0x31, + 0x84, + 0xbe, + 0xac, + 0x03, + 0x9e, + 0x71, + 0x91, + 0x85, + 0xd8, + 0x32, + 0xbd, + 0x00, + 0xea, + 0xac, + 0x65, + 0xf6, + 0x03, + 0xc8, + 0x0f, + 0x8b, + 0xfd, + 0x6e, + 0x58, + 0x88, + 0x04, + 0x41, + 0x92, + 0x74, + 0xa6, + 0x57, + 0x2e, + 0x8e, + 0x88, + 0xd5, + 0x3d, + 0xda, + 0x14, + 0x3e, + 0x63, + 0x88, + 0x22, + 0xe3, + 0x53, + 0xe9, + 0xba, + 0x39, + 0x09, + 0xac, + 0xfb, + 0xd0, + 0x4c, + 0xf2, + 0x3c, + 0x20, + 0xd6, + 0x97, + 0xe6, + 0xed, + 0xf1, + 0x62, + 0x1e, + 0xe5, + 0xc9, + 0x48, + 0xa0, + 0xca, + 0x2e, + 0x3c, + 0x14, + 0x5a, + 0x82, + 0xd4, + 0xed, + 0xb1, + 0xe3, + 0x43, + 0xc1, + 0x2a, + 0x59, + 0xa5, + 0xb9, + 0xc8, + 0x48, + 0xa7, + 0x39, + 0x23, + 0x74, + 0xa7, + 0x37, + 0xb0, + 0x6f, + 0xc3, + 0x64, + 0x99, + 0x6c, + 0xa2, + 0x82, + 0xc8, + 0xf6, + 0xdb, + 0x86, + 0x40, + 0xce, + 0xd1, + 0x85, + 0x9f, + 0xce, + 0x69, + 0xf4, + 0x15, + 0x2a, + 0x23, + 0xca, + 0xea, + 0xb7, + 0x7b, + 0xdf, + 0xfb, + 0x43, + 0x5f, + 0xff, + 0x7a, + 0x49, + 0x49, + 0x0e, + 0xe7, + 0x02, + 0x51, + 0x45, + 0x13, + 0xe8, + 0x90, + 0x64, + 0x21, + 0x0c, + 0x26, + 0x2b, + 0x5d, + 0xfc, + 0xe4, + 0xb5, + 0x86, + 0x89, + 0x43, + 0x22, + 0x4c, + 0xf3, + 0x3b, + 0xf3, + 0x09, + 0xc4, + 0xa4, + 0x10, + 0x80, + 0xf2, + 0x46, + 0xe2, + 0x46, + 0x8f, + 0x76, + 0x50, + 0xbf, + 0xaf, + 0x2b, + 0x90, + 0x1b, + 0x78, + 0xc7, + 0xcf, + 0xc1, + 0x77, + 0xd0, + 0xfb, + 0xa9, + 0xfb, + 0xc9, + 0x66, + 0x5a, + 0xc5, + 0x9b, + 0x31, + 0x41, + 0x67, + 0x01, + 0xbe, + 0x33, + 0x10, + 0xba, + 0x05, + 0x58, + 0xed, + 0x76, + 0x53, + 0xde, + 0x5d, + 0xc1, + 0xe8, + 0xbb, + 0x9f, + 0xf1, + 0xcd, + 0xfb, + 0xdf, + 0x64, + 0x7f, + 0xd7, + 0x18, + 0xab, + 0x0f, + 0x94, + 0x28, + 0x95, + 0x4a, + 0xcc, + 0x6a, + 0xa9, + 0x50, + 0xc7, + 0x05, + 0x47, + 0x10, + 0x41, + 0x02, + 0x03, + 0x01, + 0x00, + 0x01, + 0xa3, + 0x50, + 0x30, + 0x4e, + 0x30, + 0x0e, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x0f, + 0x01, + 0x01, + 0xff, + 0x04, + 0x04, + 0x03, + 0x02, + 0x05, + 0xa0, + 0x30, + 0x13, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x25, + 0x04, + 0x0c, + 0x30, + 0x0a, + 0x06, + 0x08, + 0x2b, + 0x06, + 0x01, + 0x05, + 0x05, + 0x07, + 0x03, + 0x01, + 0x30, + 0x0c, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x13, + 0x01, + 0x01, + 0xff, + 0x04, + 0x02, + 0x30, + 0x00, + 0x30, + 0x19, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x11, + 0x04, + 0x12, + 0x30, + 0x10, + 0x82, + 0x0e, + 0x66, + 0x75, + 0x7a, + 0x7a, + 0x2e, + 0x62, + 0x6f, + 0x72, + 0x69, + 0x6e, + 0x67, + 0x73, + 0x73, + 0x6c, + 0x30, + 0x0d, + 0x06, + 0x09, + 0x2a, + 0x86, + 0x48, + 0x86, + 0xf7, + 0x0d, + 0x01, + 0x01, + 0x0b, + 0x05, + 0x00, + 0x03, + 0x82, + 0x01, + 0x01, + 0x00, + 0x92, + 0xde, + 0xef, + 0x96, + 0x06, + 0x7b, + 0xff, + 0x71, + 0x7d, + 0x4e, + 0xa0, + 0x7d, + 0xae, + 0xb8, + 0x22, + 0xb4, + 0x2c, + 0xf7, + 0x96, + 0x9c, + 0x37, + 0x1d, + 0x8f, + 0xe7, + 0xd9, + 0x47, + 0xff, + 0x3f, + 0xe9, + 0x35, + 0x95, + 0x0e, + 0xdd, + 0xdc, + 0x7f, + 0xc8, + 0x8a, + 0x1e, + 0x36, + 0x1d, + 0x38, + 0x47, + 0xfc, + 0x76, + 0xd2, + 0x1f, + 0x98, + 0xa1, + 0x36, + 0xac, + 0xc8, + 0x70, + 0x38, + 0x0a, + 0x3d, + 0x51, + 0x8d, + 0x0f, + 0x03, + 0x1b, + 0xef, + 0x62, + 0xa1, + 0xcb, + 0x2b, + 0x4a, + 0x8c, + 0x12, + 0x2b, + 0x54, + 0x50, + 0x9a, + 0x6b, + 0xfe, + 0xaf, + 0xd9, + 0xf6, + 0xbf, + 0x58, + 0x11, + 0x58, + 0x5e, + 0xe5, + 0x86, + 0x1e, + 0x3b, + 0x6b, + 0x30, + 0x7e, + 0x72, + 0x89, + 0xe8, + 0x6b, + 0x7b, + 0xb7, + 0xaf, + 0xef, + 0x8b, + 0xa9, + 0x3e, + 0xb0, + 0xcd, + 0x0b, + 0xef, + 0xb0, + 0x0c, + 0x96, + 0x2b, + 0xc5, + 0x3b, + 0xd5, + 0xf1, + 0xc2, + 0xae, + 0x3a, + 0x60, + 0xd9, + 0x0f, + 0x75, + 0x37, + 0x55, + 0x4d, + 0x62, + 0xd2, + 0xed, + 0x96, + 0xac, + 0x30, + 0x6b, + 0xda, + 0xa1, + 0x48, + 0x17, + 0x96, + 0x23, + 0x85, + 0x9a, + 0x57, + 0x77, + 0xe9, + 0x22, + 0xa2, + 0x37, + 0x03, + 0xba, + 0x49, + 0x77, + 0x40, + 0x3b, + 0x76, + 0x4b, + 0xda, + 0xc1, + 0x04, + 0x57, + 0x55, + 0x34, + 0x22, + 0x83, + 0x45, + 0x29, + 0xab, + 0x2e, + 0x11, + 0xff, + 0x0d, + 0xab, + 0x55, + 0xb1, + 0xa7, + 0x58, + 0x59, + 0x05, + 0x25, + 0xf9, + 0x1e, + 0x3d, + 0xb7, + 0xac, + 0x04, + 0x39, + 0x2c, + 0xf9, + 0xaf, + 0xb8, + 0x68, + 0xfb, + 0x8e, + 0x35, + 0x71, + 0x32, + 0xff, + 0x70, + 0xe9, + 0x46, + 0x6d, + 0x5c, + 0x06, + 0x90, + 0x88, + 0x23, + 0x48, + 0x0c, + 0x50, + 0xeb, + 0x0a, + 0xa9, + 0xae, + 0xe8, + 0xfc, + 0xbe, + 0xa5, + 0x76, + 0x94, + 0xd7, + 0x64, + 0x22, + 0x38, + 0x98, + 0x17, + 0xa4, + 0x3a, + 0xa7, + 0x59, + 0x9f, + 0x1d, + 0x3b, + 0x75, + 0x90, + 0x1a, + 0x81, + 0xef, + 0x19, + 0xfb, + 0x2b, + 0xb7, + 0xa7, + 0x64, + 0x61, + 0x22, + 0xa4, + 0x6f, + 0x7b, + 0xfa, + 0x58, + 0xbb, + 0x8c, + 0x4e, + 0x77, + 0x67, + 0xd0, + 0x5d, + 0x58, + 0x76, + 0x8a, + 0xbb, }; +#ifndef OPENSSL_NO_DEPRECATED_3_0 static const uint8_t kRSAPrivateKeyDER[] = { - 0x30, 0x82, 0x04, 0xa5, 0x02, 0x01, 0x00, 0x02, - 0x82, 0x01, 0x01, 0x00, 0xce, 0x47, 0xcb, 0x11, - 0xbb, 0xd2, 0x9d, 0x8e, 0x9e, 0xd2, 0x1e, 0x14, - 0xaf, 0xc7, 0xea, 0xb6, 0xc9, 0x38, 0x2a, 0x6f, - 0xb3, 0x7e, 0xfb, 0xbc, 0xfc, 0x59, 0x42, 0xb9, - 0x56, 0xf0, 0x4c, 0x3f, 0xf7, 0x31, 0x84, 0xbe, - 0xac, 0x03, 0x9e, 0x71, 0x91, 0x85, 0xd8, 0x32, - 0xbd, 0x00, 0xea, 0xac, 0x65, 0xf6, 0x03, 0xc8, - 0x0f, 0x8b, 0xfd, 0x6e, 0x58, 0x88, 0x04, 0x41, - 0x92, 0x74, 0xa6, 0x57, 0x2e, 0x8e, 0x88, 0xd5, - 0x3d, 0xda, 0x14, 0x3e, 0x63, 0x88, 0x22, 0xe3, - 0x53, 0xe9, 0xba, 0x39, 0x09, 0xac, 0xfb, 0xd0, - 0x4c, 0xf2, 0x3c, 0x20, 0xd6, 0x97, 0xe6, 0xed, - 0xf1, 0x62, 0x1e, 0xe5, 0xc9, 0x48, 0xa0, 0xca, - 0x2e, 0x3c, 0x14, 0x5a, 0x82, 0xd4, 0xed, 0xb1, - 0xe3, 0x43, 0xc1, 0x2a, 0x59, 0xa5, 0xb9, 0xc8, - 0x48, 0xa7, 0x39, 0x23, 0x74, 0xa7, 0x37, 0xb0, - 0x6f, 0xc3, 0x64, 0x99, 0x6c, 0xa2, 0x82, 0xc8, - 0xf6, 0xdb, 0x86, 0x40, 0xce, 0xd1, 0x85, 0x9f, - 0xce, 0x69, 0xf4, 0x15, 0x2a, 0x23, 0xca, 0xea, - 0xb7, 0x7b, 0xdf, 0xfb, 0x43, 0x5f, 0xff, 0x7a, - 0x49, 0x49, 0x0e, 0xe7, 0x02, 0x51, 0x45, 0x13, - 0xe8, 0x90, 0x64, 0x21, 0x0c, 0x26, 0x2b, 0x5d, - 0xfc, 0xe4, 0xb5, 0x86, 0x89, 0x43, 0x22, 0x4c, - 0xf3, 0x3b, 0xf3, 0x09, 0xc4, 0xa4, 0x10, 0x80, - 0xf2, 0x46, 0xe2, 0x46, 0x8f, 0x76, 0x50, 0xbf, - 0xaf, 0x2b, 0x90, 0x1b, 0x78, 0xc7, 0xcf, 0xc1, - 0x77, 0xd0, 0xfb, 0xa9, 0xfb, 0xc9, 0x66, 0x5a, - 0xc5, 0x9b, 0x31, 0x41, 0x67, 0x01, 0xbe, 0x33, - 0x10, 0xba, 0x05, 0x58, 0xed, 0x76, 0x53, 0xde, - 0x5d, 0xc1, 0xe8, 0xbb, 0x9f, 0xf1, 0xcd, 0xfb, - 0xdf, 0x64, 0x7f, 0xd7, 0x18, 0xab, 0x0f, 0x94, - 0x28, 0x95, 0x4a, 0xcc, 0x6a, 0xa9, 0x50, 0xc7, - 0x05, 0x47, 0x10, 0x41, 0x02, 0x03, 0x01, 0x00, - 0x01, 0x02, 0x82, 0x01, 0x01, 0x00, 0xa8, 0x47, - 0xb9, 0x4a, 0x06, 0x47, 0x93, 0x71, 0x3d, 0xef, - 0x7b, 0xca, 0xb4, 0x7c, 0x0a, 0xe6, 0x82, 0xd0, - 0xe7, 0x0d, 0xa9, 0x08, 0xf6, 0xa4, 0xfd, 0xd8, - 0x73, 0xae, 0x6f, 0x56, 0x29, 0x5e, 0x25, 0x72, - 0xa8, 0x30, 0x44, 0x73, 0xcf, 0x56, 0x26, 0xb9, - 0x61, 0xde, 0x42, 0x81, 0xf4, 0xf0, 0x1f, 0x5d, - 0xcb, 0x47, 0xf2, 0x26, 0xe9, 0xe0, 0x93, 0x28, - 0xa3, 0x10, 0x3b, 0x42, 0x1e, 0x51, 0x11, 0x12, - 0x06, 0x5e, 0xaf, 0xce, 0xb0, 0xa5, 0x14, 0xdd, - 0x82, 0x58, 0xa1, 0xa4, 0x12, 0xdf, 0x65, 0x1d, - 0x51, 0x70, 0x64, 0xd5, 0x58, 0x68, 0x11, 0xa8, - 0x6a, 0x23, 0xc2, 0xbf, 0xa1, 0x25, 0x24, 0x47, - 0xb3, 0xa4, 0x3c, 0x83, 0x96, 0xb7, 0x1f, 0xf4, - 0x44, 0xd4, 0xd1, 0xe9, 0xfc, 0x33, 0x68, 0x5e, - 0xe2, 0x68, 0x99, 0x9c, 0x91, 0xe8, 0x72, 0xc9, - 0xd7, 0x8c, 0x80, 0x20, 0x8e, 0x77, 0x83, 0x4d, - 0xe4, 0xab, 0xf9, 0x74, 0xa1, 0xdf, 0xd3, 0xc0, - 0x0d, 0x5b, 0x05, 0x51, 0xc2, 0x6f, 0xb2, 0x91, - 0x02, 0xec, 0xc0, 0x02, 0x1a, 0x5c, 0x91, 0x05, - 0xf1, 0xe3, 0xfa, 0x65, 0xc2, 0xad, 0x24, 0xe6, - 0xe5, 0x3c, 0xb6, 0x16, 0xf1, 0xa1, 0x67, 0x1a, - 0x9d, 0x37, 0x56, 0xbf, 0x01, 0xd7, 0x3b, 0x35, - 0x30, 0x57, 0x73, 0xf4, 0xf0, 0x5e, 0xa7, 0xe8, - 0x0a, 0xc1, 0x94, 0x17, 0xcf, 0x0a, 0xbd, 0xf5, - 0x31, 0xa7, 0x2d, 0xf7, 0xf5, 0xd9, 0x8c, 0xc2, - 0x01, 0xbd, 0xda, 0x16, 0x8e, 0xb9, 0x30, 0x40, - 0xa6, 0x6e, 0xbd, 0xcd, 0x4d, 0x84, 0x67, 0x4e, - 0x0b, 0xce, 0xd5, 0xef, 0xf8, 0x08, 0x63, 0x02, - 0xc6, 0xc7, 0xf7, 0x67, 0x92, 0xe2, 0x23, 0x9d, - 0x27, 0x22, 0x1d, 0xc6, 0x67, 0x5e, 0x66, 0xbf, - 0x03, 0xb8, 0xa9, 0x67, 0xd4, 0x39, 0xd8, 0x75, - 0xfa, 0xe8, 0xed, 0x56, 0xb8, 0x81, 0x02, 0x81, - 0x81, 0x00, 0xf7, 0x46, 0x68, 0xc6, 0x13, 0xf8, - 0xba, 0x0f, 0x83, 0xdb, 0x05, 0xa8, 0x25, 0x00, - 0x70, 0x9c, 0x9e, 0x8b, 0x12, 0x34, 0x0d, 0x96, - 0xcf, 0x0d, 0x98, 0x9b, 0x8d, 0x9c, 0x96, 0x78, - 0xd1, 0x3c, 0x01, 0x8c, 0xb9, 0x35, 0x5c, 0x20, - 0x42, 0xb4, 0x38, 0xe3, 0xd6, 0x54, 0xe7, 0x55, - 0xd6, 0x26, 0x8a, 0x0c, 0xf6, 0x1f, 0xe0, 0x04, - 0xc1, 0x22, 0x42, 0x19, 0x61, 0xc4, 0x94, 0x7c, - 0x07, 0x2e, 0x80, 0x52, 0xfe, 0x8d, 0xe6, 0x92, - 0x3a, 0x91, 0xfe, 0x72, 0x99, 0xe1, 0x2a, 0x73, - 0x76, 0xb1, 0x24, 0x20, 0x67, 0xde, 0x28, 0xcb, - 0x0e, 0xe6, 0x52, 0xb5, 0xfa, 0xfb, 0x8b, 0x1e, - 0x6a, 0x1d, 0x09, 0x26, 0xb9, 0xa7, 0x61, 0xba, - 0xf8, 0x79, 0xd2, 0x66, 0x57, 0x28, 0xd7, 0x31, - 0xb5, 0x0b, 0x27, 0x19, 0x1e, 0x6f, 0x46, 0xfc, - 0x54, 0x95, 0xeb, 0x78, 0x01, 0xb6, 0xd9, 0x79, - 0x5a, 0x4d, 0x02, 0x81, 0x81, 0x00, 0xd5, 0x8f, - 0x16, 0x53, 0x2f, 0x57, 0x93, 0xbf, 0x09, 0x75, - 0xbf, 0x63, 0x40, 0x3d, 0x27, 0xfd, 0x23, 0x21, - 0xde, 0x9b, 0xe9, 0x73, 0x3f, 0x49, 0x02, 0xd2, - 0x38, 0x96, 0xcf, 0xc3, 0xba, 0x92, 0x07, 0x87, - 0x52, 0xa9, 0x35, 0xe3, 0x0c, 0xe4, 0x2f, 0x05, - 0x7b, 0x37, 0xa5, 0x40, 0x9c, 0x3b, 0x94, 0xf7, - 0xad, 0xa0, 0xee, 0x3a, 0xa8, 0xfb, 0x1f, 0x11, - 0x1f, 0xd8, 0x9a, 0x80, 0x42, 0x3d, 0x7f, 0xa4, - 0xb8, 0x9a, 0xaa, 0xea, 0x72, 0xc1, 0xe3, 0xed, - 0x06, 0x60, 0x92, 0x37, 0xf9, 0xba, 0xfb, 0x9e, - 0xed, 0x05, 0xa6, 0xd4, 0x72, 0x68, 0x4f, 0x63, - 0xfe, 0xd6, 0x10, 0x0d, 0x4f, 0x0a, 0x93, 0xc6, - 0xb9, 0xd7, 0xaf, 0xfd, 0xd9, 0x57, 0x7d, 0xcb, - 0x75, 0xe8, 0x93, 0x2b, 0xae, 0x4f, 0xea, 0xd7, - 0x30, 0x0b, 0x58, 0x44, 0x82, 0x0f, 0x84, 0x5d, - 0x62, 0x11, 0x78, 0xea, 0x5f, 0xc5, 0x02, 0x81, - 0x81, 0x00, 0x82, 0x0c, 0xc1, 0xe6, 0x0b, 0x72, - 0xf1, 0x48, 0x5f, 0xac, 0xbd, 0x98, 0xe5, 0x7d, - 0x09, 0xbd, 0x15, 0x95, 0x47, 0x09, 0xa1, 0x6c, - 0x03, 0x91, 0xbf, 0x05, 0x70, 0xc1, 0x3e, 0x52, - 0x64, 0x99, 0x0e, 0xa7, 0x98, 0x70, 0xfb, 0xf6, - 0xeb, 0x9e, 0x25, 0x9d, 0x8e, 0x88, 0x30, 0xf2, - 0xf0, 0x22, 0x6c, 0xd0, 0xcc, 0x51, 0x8f, 0x5c, - 0x70, 0xc7, 0x37, 0xc4, 0x69, 0xab, 0x1d, 0xfc, - 0xed, 0x3a, 0x03, 0xbb, 0xa2, 0xad, 0xb6, 0xea, - 0x89, 0x6b, 0x67, 0x4b, 0x96, 0xaa, 0xd9, 0xcc, - 0xc8, 0x4b, 0xfa, 0x18, 0x21, 0x08, 0xb2, 0xa3, - 0xb9, 0x3e, 0x61, 0x99, 0xdc, 0x5a, 0x97, 0x9c, - 0x73, 0x6a, 0xb9, 0xf9, 0x68, 0x03, 0x24, 0x5f, - 0x55, 0x77, 0x9c, 0xb4, 0xbe, 0x7a, 0x78, 0x53, - 0x68, 0x48, 0x69, 0x53, 0xc8, 0xb1, 0xf5, 0xbf, - 0x98, 0x2d, 0x11, 0x1e, 0x98, 0xa8, 0x36, 0x50, - 0xa0, 0xb1, 0x02, 0x81, 0x81, 0x00, 0x90, 0x88, - 0x30, 0x71, 0xc7, 0xfe, 0x9b, 0x6d, 0x95, 0x37, - 0x6d, 0x79, 0xfc, 0x85, 0xe7, 0x44, 0x78, 0xbc, - 0x79, 0x6e, 0x47, 0x86, 0xc9, 0xf3, 0xdd, 0xc6, - 0xec, 0xa9, 0x94, 0x9f, 0x40, 0xeb, 0x87, 0xd0, - 0xdb, 0xee, 0xcd, 0x1b, 0x87, 0x23, 0xff, 0x76, - 0xd4, 0x37, 0x8a, 0xcd, 0xb9, 0x6e, 0xd1, 0x98, - 0xf6, 0x97, 0x8d, 0xe3, 0x81, 0x6d, 0xc3, 0x4e, - 0xd1, 0xa0, 0xc4, 0x9f, 0xbd, 0x34, 0xe5, 0xe8, - 0x53, 0x4f, 0xca, 0x10, 0xb5, 0xed, 0xe7, 0x16, - 0x09, 0x54, 0xde, 0x60, 0xa7, 0xd1, 0x16, 0x6e, - 0x2e, 0xb7, 0xbe, 0x7a, 0xd5, 0x9b, 0x26, 0xef, - 0xe4, 0x0e, 0x77, 0xfa, 0xa9, 0xdd, 0xdc, 0xb9, - 0x88, 0x19, 0x23, 0x70, 0xc7, 0xe1, 0x60, 0xaf, - 0x8c, 0x73, 0x04, 0xf7, 0x71, 0x17, 0x81, 0x36, - 0x75, 0xbb, 0x97, 0xd7, 0x75, 0xb6, 0x8e, 0xbc, - 0xac, 0x9c, 0x6a, 0x9b, 0x24, 0x89, 0x02, 0x81, - 0x80, 0x5a, 0x2b, 0xc7, 0x6b, 0x8c, 0x65, 0xdb, - 0x04, 0x73, 0xab, 0x25, 0xe1, 0x5b, 0xbc, 0x3c, - 0xcf, 0x5a, 0x3c, 0x04, 0xae, 0x97, 0x2e, 0xfd, - 0xa4, 0x97, 0x1f, 0x05, 0x17, 0x27, 0xac, 0x7c, - 0x30, 0x85, 0xb4, 0x82, 0x3f, 0x5b, 0xb7, 0x94, - 0x3b, 0x7f, 0x6c, 0x0c, 0xc7, 0x16, 0xc6, 0xa0, - 0xbd, 0x80, 0xb0, 0x81, 0xde, 0xa0, 0x23, 0xa6, - 0xf6, 0x75, 0x33, 0x51, 0x35, 0xa2, 0x75, 0x55, - 0x70, 0x4d, 0x42, 0xbb, 0xcf, 0x54, 0xe4, 0xdb, - 0x2d, 0x88, 0xa0, 0x7a, 0xf2, 0x17, 0xa7, 0xdd, - 0x13, 0x44, 0x9f, 0x5f, 0x6b, 0x2c, 0x42, 0x42, - 0x8b, 0x13, 0x4d, 0xf9, 0x5b, 0xf8, 0x33, 0x42, - 0xd9, 0x9e, 0x50, 0x1c, 0x7c, 0xbc, 0xfa, 0x62, - 0x85, 0x0b, 0xcf, 0x99, 0xda, 0x9e, 0x04, 0x90, - 0xb2, 0xc6, 0xb2, 0x0a, 0x2a, 0x7c, 0x6d, 0x6a, - 0x40, 0xfc, 0xf5, 0x50, 0x98, 0x46, 0x89, 0x82, - 0x40 + 0x30, + 0x82, + 0x04, + 0xa5, + 0x02, + 0x01, + 0x00, + 0x02, + 0x82, + 0x01, + 0x01, + 0x00, + 0xce, + 0x47, + 0xcb, + 0x11, + 0xbb, + 0xd2, + 0x9d, + 0x8e, + 0x9e, + 0xd2, + 0x1e, + 0x14, + 0xaf, + 0xc7, + 0xea, + 0xb6, + 0xc9, + 0x38, + 0x2a, + 0x6f, + 0xb3, + 0x7e, + 0xfb, + 0xbc, + 0xfc, + 0x59, + 0x42, + 0xb9, + 0x56, + 0xf0, + 0x4c, + 0x3f, + 0xf7, + 0x31, + 0x84, + 0xbe, + 0xac, + 0x03, + 0x9e, + 0x71, + 0x91, + 0x85, + 0xd8, + 0x32, + 0xbd, + 0x00, + 0xea, + 0xac, + 0x65, + 0xf6, + 0x03, + 0xc8, + 0x0f, + 0x8b, + 0xfd, + 0x6e, + 0x58, + 0x88, + 0x04, + 0x41, + 0x92, + 0x74, + 0xa6, + 0x57, + 0x2e, + 0x8e, + 0x88, + 0xd5, + 0x3d, + 0xda, + 0x14, + 0x3e, + 0x63, + 0x88, + 0x22, + 0xe3, + 0x53, + 0xe9, + 0xba, + 0x39, + 0x09, + 0xac, + 0xfb, + 0xd0, + 0x4c, + 0xf2, + 0x3c, + 0x20, + 0xd6, + 0x97, + 0xe6, + 0xed, + 0xf1, + 0x62, + 0x1e, + 0xe5, + 0xc9, + 0x48, + 0xa0, + 0xca, + 0x2e, + 0x3c, + 0x14, + 0x5a, + 0x82, + 0xd4, + 0xed, + 0xb1, + 0xe3, + 0x43, + 0xc1, + 0x2a, + 0x59, + 0xa5, + 0xb9, + 0xc8, + 0x48, + 0xa7, + 0x39, + 0x23, + 0x74, + 0xa7, + 0x37, + 0xb0, + 0x6f, + 0xc3, + 0x64, + 0x99, + 0x6c, + 0xa2, + 0x82, + 0xc8, + 0xf6, + 0xdb, + 0x86, + 0x40, + 0xce, + 0xd1, + 0x85, + 0x9f, + 0xce, + 0x69, + 0xf4, + 0x15, + 0x2a, + 0x23, + 0xca, + 0xea, + 0xb7, + 0x7b, + 0xdf, + 0xfb, + 0x43, + 0x5f, + 0xff, + 0x7a, + 0x49, + 0x49, + 0x0e, + 0xe7, + 0x02, + 0x51, + 0x45, + 0x13, + 0xe8, + 0x90, + 0x64, + 0x21, + 0x0c, + 0x26, + 0x2b, + 0x5d, + 0xfc, + 0xe4, + 0xb5, + 0x86, + 0x89, + 0x43, + 0x22, + 0x4c, + 0xf3, + 0x3b, + 0xf3, + 0x09, + 0xc4, + 0xa4, + 0x10, + 0x80, + 0xf2, + 0x46, + 0xe2, + 0x46, + 0x8f, + 0x76, + 0x50, + 0xbf, + 0xaf, + 0x2b, + 0x90, + 0x1b, + 0x78, + 0xc7, + 0xcf, + 0xc1, + 0x77, + 0xd0, + 0xfb, + 0xa9, + 0xfb, + 0xc9, + 0x66, + 0x5a, + 0xc5, + 0x9b, + 0x31, + 0x41, + 0x67, + 0x01, + 0xbe, + 0x33, + 0x10, + 0xba, + 0x05, + 0x58, + 0xed, + 0x76, + 0x53, + 0xde, + 0x5d, + 0xc1, + 0xe8, + 0xbb, + 0x9f, + 0xf1, + 0xcd, + 0xfb, + 0xdf, + 0x64, + 0x7f, + 0xd7, + 0x18, + 0xab, + 0x0f, + 0x94, + 0x28, + 0x95, + 0x4a, + 0xcc, + 0x6a, + 0xa9, + 0x50, + 0xc7, + 0x05, + 0x47, + 0x10, + 0x41, + 0x02, + 0x03, + 0x01, + 0x00, + 0x01, + 0x02, + 0x82, + 0x01, + 0x01, + 0x00, + 0xa8, + 0x47, + 0xb9, + 0x4a, + 0x06, + 0x47, + 0x93, + 0x71, + 0x3d, + 0xef, + 0x7b, + 0xca, + 0xb4, + 0x7c, + 0x0a, + 0xe6, + 0x82, + 0xd0, + 0xe7, + 0x0d, + 0xa9, + 0x08, + 0xf6, + 0xa4, + 0xfd, + 0xd8, + 0x73, + 0xae, + 0x6f, + 0x56, + 0x29, + 0x5e, + 0x25, + 0x72, + 0xa8, + 0x30, + 0x44, + 0x73, + 0xcf, + 0x56, + 0x26, + 0xb9, + 0x61, + 0xde, + 0x42, + 0x81, + 0xf4, + 0xf0, + 0x1f, + 0x5d, + 0xcb, + 0x47, + 0xf2, + 0x26, + 0xe9, + 0xe0, + 0x93, + 0x28, + 0xa3, + 0x10, + 0x3b, + 0x42, + 0x1e, + 0x51, + 0x11, + 0x12, + 0x06, + 0x5e, + 0xaf, + 0xce, + 0xb0, + 0xa5, + 0x14, + 0xdd, + 0x82, + 0x58, + 0xa1, + 0xa4, + 0x12, + 0xdf, + 0x65, + 0x1d, + 0x51, + 0x70, + 0x64, + 0xd5, + 0x58, + 0x68, + 0x11, + 0xa8, + 0x6a, + 0x23, + 0xc2, + 0xbf, + 0xa1, + 0x25, + 0x24, + 0x47, + 0xb3, + 0xa4, + 0x3c, + 0x83, + 0x96, + 0xb7, + 0x1f, + 0xf4, + 0x44, + 0xd4, + 0xd1, + 0xe9, + 0xfc, + 0x33, + 0x68, + 0x5e, + 0xe2, + 0x68, + 0x99, + 0x9c, + 0x91, + 0xe8, + 0x72, + 0xc9, + 0xd7, + 0x8c, + 0x80, + 0x20, + 0x8e, + 0x77, + 0x83, + 0x4d, + 0xe4, + 0xab, + 0xf9, + 0x74, + 0xa1, + 0xdf, + 0xd3, + 0xc0, + 0x0d, + 0x5b, + 0x05, + 0x51, + 0xc2, + 0x6f, + 0xb2, + 0x91, + 0x02, + 0xec, + 0xc0, + 0x02, + 0x1a, + 0x5c, + 0x91, + 0x05, + 0xf1, + 0xe3, + 0xfa, + 0x65, + 0xc2, + 0xad, + 0x24, + 0xe6, + 0xe5, + 0x3c, + 0xb6, + 0x16, + 0xf1, + 0xa1, + 0x67, + 0x1a, + 0x9d, + 0x37, + 0x56, + 0xbf, + 0x01, + 0xd7, + 0x3b, + 0x35, + 0x30, + 0x57, + 0x73, + 0xf4, + 0xf0, + 0x5e, + 0xa7, + 0xe8, + 0x0a, + 0xc1, + 0x94, + 0x17, + 0xcf, + 0x0a, + 0xbd, + 0xf5, + 0x31, + 0xa7, + 0x2d, + 0xf7, + 0xf5, + 0xd9, + 0x8c, + 0xc2, + 0x01, + 0xbd, + 0xda, + 0x16, + 0x8e, + 0xb9, + 0x30, + 0x40, + 0xa6, + 0x6e, + 0xbd, + 0xcd, + 0x4d, + 0x84, + 0x67, + 0x4e, + 0x0b, + 0xce, + 0xd5, + 0xef, + 0xf8, + 0x08, + 0x63, + 0x02, + 0xc6, + 0xc7, + 0xf7, + 0x67, + 0x92, + 0xe2, + 0x23, + 0x9d, + 0x27, + 0x22, + 0x1d, + 0xc6, + 0x67, + 0x5e, + 0x66, + 0xbf, + 0x03, + 0xb8, + 0xa9, + 0x67, + 0xd4, + 0x39, + 0xd8, + 0x75, + 0xfa, + 0xe8, + 0xed, + 0x56, + 0xb8, + 0x81, + 0x02, + 0x81, + 0x81, + 0x00, + 0xf7, + 0x46, + 0x68, + 0xc6, + 0x13, + 0xf8, + 0xba, + 0x0f, + 0x83, + 0xdb, + 0x05, + 0xa8, + 0x25, + 0x00, + 0x70, + 0x9c, + 0x9e, + 0x8b, + 0x12, + 0x34, + 0x0d, + 0x96, + 0xcf, + 0x0d, + 0x98, + 0x9b, + 0x8d, + 0x9c, + 0x96, + 0x78, + 0xd1, + 0x3c, + 0x01, + 0x8c, + 0xb9, + 0x35, + 0x5c, + 0x20, + 0x42, + 0xb4, + 0x38, + 0xe3, + 0xd6, + 0x54, + 0xe7, + 0x55, + 0xd6, + 0x26, + 0x8a, + 0x0c, + 0xf6, + 0x1f, + 0xe0, + 0x04, + 0xc1, + 0x22, + 0x42, + 0x19, + 0x61, + 0xc4, + 0x94, + 0x7c, + 0x07, + 0x2e, + 0x80, + 0x52, + 0xfe, + 0x8d, + 0xe6, + 0x92, + 0x3a, + 0x91, + 0xfe, + 0x72, + 0x99, + 0xe1, + 0x2a, + 0x73, + 0x76, + 0xb1, + 0x24, + 0x20, + 0x67, + 0xde, + 0x28, + 0xcb, + 0x0e, + 0xe6, + 0x52, + 0xb5, + 0xfa, + 0xfb, + 0x8b, + 0x1e, + 0x6a, + 0x1d, + 0x09, + 0x26, + 0xb9, + 0xa7, + 0x61, + 0xba, + 0xf8, + 0x79, + 0xd2, + 0x66, + 0x57, + 0x28, + 0xd7, + 0x31, + 0xb5, + 0x0b, + 0x27, + 0x19, + 0x1e, + 0x6f, + 0x46, + 0xfc, + 0x54, + 0x95, + 0xeb, + 0x78, + 0x01, + 0xb6, + 0xd9, + 0x79, + 0x5a, + 0x4d, + 0x02, + 0x81, + 0x81, + 0x00, + 0xd5, + 0x8f, + 0x16, + 0x53, + 0x2f, + 0x57, + 0x93, + 0xbf, + 0x09, + 0x75, + 0xbf, + 0x63, + 0x40, + 0x3d, + 0x27, + 0xfd, + 0x23, + 0x21, + 0xde, + 0x9b, + 0xe9, + 0x73, + 0x3f, + 0x49, + 0x02, + 0xd2, + 0x38, + 0x96, + 0xcf, + 0xc3, + 0xba, + 0x92, + 0x07, + 0x87, + 0x52, + 0xa9, + 0x35, + 0xe3, + 0x0c, + 0xe4, + 0x2f, + 0x05, + 0x7b, + 0x37, + 0xa5, + 0x40, + 0x9c, + 0x3b, + 0x94, + 0xf7, + 0xad, + 0xa0, + 0xee, + 0x3a, + 0xa8, + 0xfb, + 0x1f, + 0x11, + 0x1f, + 0xd8, + 0x9a, + 0x80, + 0x42, + 0x3d, + 0x7f, + 0xa4, + 0xb8, + 0x9a, + 0xaa, + 0xea, + 0x72, + 0xc1, + 0xe3, + 0xed, + 0x06, + 0x60, + 0x92, + 0x37, + 0xf9, + 0xba, + 0xfb, + 0x9e, + 0xed, + 0x05, + 0xa6, + 0xd4, + 0x72, + 0x68, + 0x4f, + 0x63, + 0xfe, + 0xd6, + 0x10, + 0x0d, + 0x4f, + 0x0a, + 0x93, + 0xc6, + 0xb9, + 0xd7, + 0xaf, + 0xfd, + 0xd9, + 0x57, + 0x7d, + 0xcb, + 0x75, + 0xe8, + 0x93, + 0x2b, + 0xae, + 0x4f, + 0xea, + 0xd7, + 0x30, + 0x0b, + 0x58, + 0x44, + 0x82, + 0x0f, + 0x84, + 0x5d, + 0x62, + 0x11, + 0x78, + 0xea, + 0x5f, + 0xc5, + 0x02, + 0x81, + 0x81, + 0x00, + 0x82, + 0x0c, + 0xc1, + 0xe6, + 0x0b, + 0x72, + 0xf1, + 0x48, + 0x5f, + 0xac, + 0xbd, + 0x98, + 0xe5, + 0x7d, + 0x09, + 0xbd, + 0x15, + 0x95, + 0x47, + 0x09, + 0xa1, + 0x6c, + 0x03, + 0x91, + 0xbf, + 0x05, + 0x70, + 0xc1, + 0x3e, + 0x52, + 0x64, + 0x99, + 0x0e, + 0xa7, + 0x98, + 0x70, + 0xfb, + 0xf6, + 0xeb, + 0x9e, + 0x25, + 0x9d, + 0x8e, + 0x88, + 0x30, + 0xf2, + 0xf0, + 0x22, + 0x6c, + 0xd0, + 0xcc, + 0x51, + 0x8f, + 0x5c, + 0x70, + 0xc7, + 0x37, + 0xc4, + 0x69, + 0xab, + 0x1d, + 0xfc, + 0xed, + 0x3a, + 0x03, + 0xbb, + 0xa2, + 0xad, + 0xb6, + 0xea, + 0x89, + 0x6b, + 0x67, + 0x4b, + 0x96, + 0xaa, + 0xd9, + 0xcc, + 0xc8, + 0x4b, + 0xfa, + 0x18, + 0x21, + 0x08, + 0xb2, + 0xa3, + 0xb9, + 0x3e, + 0x61, + 0x99, + 0xdc, + 0x5a, + 0x97, + 0x9c, + 0x73, + 0x6a, + 0xb9, + 0xf9, + 0x68, + 0x03, + 0x24, + 0x5f, + 0x55, + 0x77, + 0x9c, + 0xb4, + 0xbe, + 0x7a, + 0x78, + 0x53, + 0x68, + 0x48, + 0x69, + 0x53, + 0xc8, + 0xb1, + 0xf5, + 0xbf, + 0x98, + 0x2d, + 0x11, + 0x1e, + 0x98, + 0xa8, + 0x36, + 0x50, + 0xa0, + 0xb1, + 0x02, + 0x81, + 0x81, + 0x00, + 0x90, + 0x88, + 0x30, + 0x71, + 0xc7, + 0xfe, + 0x9b, + 0x6d, + 0x95, + 0x37, + 0x6d, + 0x79, + 0xfc, + 0x85, + 0xe7, + 0x44, + 0x78, + 0xbc, + 0x79, + 0x6e, + 0x47, + 0x86, + 0xc9, + 0xf3, + 0xdd, + 0xc6, + 0xec, + 0xa9, + 0x94, + 0x9f, + 0x40, + 0xeb, + 0x87, + 0xd0, + 0xdb, + 0xee, + 0xcd, + 0x1b, + 0x87, + 0x23, + 0xff, + 0x76, + 0xd4, + 0x37, + 0x8a, + 0xcd, + 0xb9, + 0x6e, + 0xd1, + 0x98, + 0xf6, + 0x97, + 0x8d, + 0xe3, + 0x81, + 0x6d, + 0xc3, + 0x4e, + 0xd1, + 0xa0, + 0xc4, + 0x9f, + 0xbd, + 0x34, + 0xe5, + 0xe8, + 0x53, + 0x4f, + 0xca, + 0x10, + 0xb5, + 0xed, + 0xe7, + 0x16, + 0x09, + 0x54, + 0xde, + 0x60, + 0xa7, + 0xd1, + 0x16, + 0x6e, + 0x2e, + 0xb7, + 0xbe, + 0x7a, + 0xd5, + 0x9b, + 0x26, + 0xef, + 0xe4, + 0x0e, + 0x77, + 0xfa, + 0xa9, + 0xdd, + 0xdc, + 0xb9, + 0x88, + 0x19, + 0x23, + 0x70, + 0xc7, + 0xe1, + 0x60, + 0xaf, + 0x8c, + 0x73, + 0x04, + 0xf7, + 0x71, + 0x17, + 0x81, + 0x36, + 0x75, + 0xbb, + 0x97, + 0xd7, + 0x75, + 0xb6, + 0x8e, + 0xbc, + 0xac, + 0x9c, + 0x6a, + 0x9b, + 0x24, + 0x89, + 0x02, + 0x81, + 0x80, + 0x5a, + 0x2b, + 0xc7, + 0x6b, + 0x8c, + 0x65, + 0xdb, + 0x04, + 0x73, + 0xab, + 0x25, + 0xe1, + 0x5b, + 0xbc, + 0x3c, + 0xcf, + 0x5a, + 0x3c, + 0x04, + 0xae, + 0x97, + 0x2e, + 0xfd, + 0xa4, + 0x97, + 0x1f, + 0x05, + 0x17, + 0x27, + 0xac, + 0x7c, + 0x30, + 0x85, + 0xb4, + 0x82, + 0x3f, + 0x5b, + 0xb7, + 0x94, + 0x3b, + 0x7f, + 0x6c, + 0x0c, + 0xc7, + 0x16, + 0xc6, + 0xa0, + 0xbd, + 0x80, + 0xb0, + 0x81, + 0xde, + 0xa0, + 0x23, + 0xa6, + 0xf6, + 0x75, + 0x33, + 0x51, + 0x35, + 0xa2, + 0x75, + 0x55, + 0x70, + 0x4d, + 0x42, + 0xbb, + 0xcf, + 0x54, + 0xe4, + 0xdb, + 0x2d, + 0x88, + 0xa0, + 0x7a, + 0xf2, + 0x17, + 0xa7, + 0xdd, + 0x13, + 0x44, + 0x9f, + 0x5f, + 0x6b, + 0x2c, + 0x42, + 0x42, + 0x8b, + 0x13, + 0x4d, + 0xf9, + 0x5b, + 0xf8, + 0x33, + 0x42, + 0xd9, + 0x9e, + 0x50, + 0x1c, + 0x7c, + 0xbc, + 0xfa, + 0x62, + 0x85, + 0x0b, + 0xcf, + 0x99, + 0xda, + 0x9e, + 0x04, + 0x90, + 0xb2, + 0xc6, + 0xb2, + 0x0a, + 0x2a, + 0x7c, + 0x6d, + 0x6a, + 0x40, + 0xfc, + 0xf5, + 0x50, + 0x98, + 0x46, + 0x89, + 0x82, + 0x40, }; #endif #ifndef OPENSSL_NO_EC +#ifndef OPENSSL_NO_DEPRECATED_3_0 /* * -----BEGIN EC PRIVATE KEY----- * MHcCAQEEIJLyl7hJjpQL/RhP1x2zS79xdiPJQB683gWeqcqHPeZkoAoGCCqGSM49 @@ -309,6 +2027,7 @@ static const char ECDSAPrivateKeyPEM[] = { 0x4e, 0x44, 0x20, 0x45, 0x43, 0x20, 0x50, 0x52, 0x49, 0x56, 0x41, 0x54, 0x45, 0x20, 0x4b, 0x45, 0x59, 0x2d, 0x2d, 0x2d, 0x2d, 0x2d, 0x0a }; +#endif /* * -----BEGIN CERTIFICATE----- @@ -371,7 +2090,7 @@ static const char ECDSACertPEM[] = { }; #endif -#ifndef OPENSSL_NO_DSA +#if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0) /* * -----BEGIN DSA PRIVATE KEY----- * MIIBuwIBAAKBgQDdkFKzNABLOha7Eqj7004+p5fhtR6bxpujToMmSZTYi8igVVXP @@ -591,155 +2310,139 @@ time_t time(time_t *t) TIME_IMPL(t) return 1; } -#if !defined(OPENSSL_NO_EC) || !defined(OPENSSL_NO_DSA) -static int use_pem_privkey(SSL_CTX *ctx, const void *pem, size_t pem_len) -{ - BIO *bio_buf; - EVP_PKEY *pkey; - int rv = 0; - - bio_buf = BIO_new(BIO_s_mem()); - if (bio_buf == NULL) - return 0; - if ((size_t)BIO_write(bio_buf, pem, (int)pem_len) != pem_len) { - BIO_free(bio_buf); - return 0; - } - pkey = PEM_read_bio_PrivateKey(bio_buf, NULL, NULL, NULL); - BIO_free(bio_buf); - if (pkey == NULL) - return 0; - if (SSL_CTX_use_PrivateKey(ctx, pkey) == 1) - rv = 1; - EVP_PKEY_free(pkey); - return rv; -} - -static int use_pem_cert(SSL_CTX *ctx, const void *pem, size_t pem_len) -{ - BIO *bio_buf; - X509 *cert; - int rv = 0; - - bio_buf = BIO_new(BIO_s_mem()); - if (bio_buf == NULL) - return 0; - if ((size_t)BIO_write(bio_buf, pem, (int)pem_len) != pem_len) { - BIO_free(bio_buf); - return 0; - } - cert = PEM_read_bio_X509(bio_buf, NULL, NULL, NULL); - BIO_free(bio_buf); - if (cert == NULL) - return 0; - if (SSL_CTX_use_certificate(ctx, cert) == 1) - rv = 1; - X509_free(cert); - return rv; -} -#endif - int FuzzerTestOneInput(const uint8_t *buf, size_t len) { - SSL *server = NULL; + SSL *server; BIO *in; BIO *out; +#if !defined(OPENSSL_NO_EC) \ + || (!defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0)) + BIO *bio_buf; +#endif SSL_CTX *ctx; + int ret; #ifndef OPENSSL_NO_DEPRECATED_3_0 + RSA *privkey; +#endif const uint8_t *bufp; - RSA *privkey = NULL; - EVP_PKEY *pkey = NULL; - X509 *cert = NULL; +#if !defined(OPENSSL_NO_DEPRECATED_3_0) + EVP_PKEY *pkey; +#endif + X509 *cert; +#ifndef OPENSSL_NO_DEPRECATED_3_0 +#ifndef OPENSSL_NO_EC + EC_KEY *ecdsakey = NULL; +#endif +#endif +#if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0) + DSA *dsakey = NULL; #endif uint8_t opt; - int ret; if (len < 2 || len > INT_MAX) return 0; - ctx = SSL_CTX_new(TLS_method()); - if (ctx == NULL) - return 0; - if (SSL_CTX_set_min_proto_version(ctx, 0) != 1) - goto end; - if (SSL_CTX_set_cipher_list(ctx, "ALL:eNULL:@SECLEVEL=0") != 1) - goto end; + /* This only fuzzes the initial flow from the client so far. */ + ctx = SSL_CTX_new(SSLv23_method()); + OPENSSL_assert(ctx != NULL); + ret = SSL_CTX_set_min_proto_version(ctx, 0); + OPENSSL_assert(ret == 1); + ret = SSL_CTX_set_cipher_list(ctx, "ALL:eNULL:@SECLEVEL=0"); + OPENSSL_assert(ret == 1); #ifndef OPENSSL_NO_DEPRECATED_3_0 /* RSA */ bufp = kRSAPrivateKeyDER; privkey = d2i_RSAPrivateKey(NULL, &bufp, sizeof(kRSAPrivateKeyDER)); - if (privkey == NULL) - goto end; + OPENSSL_assert(privkey != NULL); pkey = EVP_PKEY_new(); - if (pkey == NULL) { - RSA_free(privkey); - goto end; - } - if (!EVP_PKEY_assign_RSA(pkey, privkey)) { - /* assignment failed; pkey doesn't own privkey, clean both */ - RSA_free(privkey); - EVP_PKEY_free(pkey); - goto end; - } + OPENSSL_assert(pkey != NULL); + EVP_PKEY_assign_RSA(pkey, privkey); ret = SSL_CTX_use_PrivateKey(ctx, pkey); + OPENSSL_assert(ret == 1); EVP_PKEY_free(pkey); - if (ret != 1) - goto end; +#endif bufp = kCertificateDER; cert = d2i_X509(NULL, &bufp, sizeof(kCertificateDER)); - if (cert == NULL) - goto end; + OPENSSL_assert(cert != NULL); ret = SSL_CTX_use_certificate(ctx, cert); + OPENSSL_assert(ret == 1); X509_free(cert); - if (ret != 1) - goto end; -#endif #ifndef OPENSSL_NO_EC +#ifndef OPENSSL_NO_DEPRECATED_3_0 /* ECDSA */ - if (!use_pem_privkey(ctx, ECDSAPrivateKeyPEM, sizeof(ECDSAPrivateKeyPEM))) - goto end; - if (!use_pem_cert(ctx, ECDSACertPEM, sizeof(ECDSACertPEM))) - goto end; + bio_buf = BIO_new(BIO_s_mem()); + OPENSSL_assert(bio_buf != NULL); + OPENSSL_assert((size_t)BIO_write(bio_buf, ECDSAPrivateKeyPEM, sizeof(ECDSAPrivateKeyPEM)) == sizeof(ECDSAPrivateKeyPEM)); + ecdsakey = PEM_read_bio_ECPrivateKey(bio_buf, NULL, NULL, NULL); + ERR_print_errors_fp(stderr); + OPENSSL_assert(ecdsakey != NULL); + BIO_free(bio_buf); + pkey = EVP_PKEY_new(); + OPENSSL_assert(pkey != NULL); + EVP_PKEY_assign_EC_KEY(pkey, ecdsakey); + ret = SSL_CTX_use_PrivateKey(ctx, pkey); + OPENSSL_assert(ret == 1); + EVP_PKEY_free(pkey); +#endif + bio_buf = BIO_new(BIO_s_mem()); + OPENSSL_assert(bio_buf != NULL); + OPENSSL_assert((size_t)BIO_write(bio_buf, ECDSACertPEM, sizeof(ECDSACertPEM)) == sizeof(ECDSACertPEM)); + cert = PEM_read_bio_X509(bio_buf, NULL, NULL, NULL); + OPENSSL_assert(cert != NULL); + BIO_free(bio_buf); + ret = SSL_CTX_use_certificate(ctx, cert); + OPENSSL_assert(ret == 1); + X509_free(cert); #endif -#ifndef OPENSSL_NO_DSA +#if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_DEPRECATED_3_0) /* DSA */ - if (!use_pem_privkey(ctx, DSAPrivateKeyPEM, sizeof(DSAPrivateKeyPEM))) - goto end; - if (!use_pem_cert(ctx, DSACertPEM, sizeof(DSACertPEM))) - goto end; + bio_buf = BIO_new(BIO_s_mem()); + OPENSSL_assert(bio_buf != NULL); + OPENSSL_assert((size_t)BIO_write(bio_buf, DSAPrivateKeyPEM, sizeof(DSAPrivateKeyPEM)) == sizeof(DSAPrivateKeyPEM)); + dsakey = PEM_read_bio_DSAPrivateKey(bio_buf, NULL, NULL, NULL); + ERR_print_errors_fp(stderr); + OPENSSL_assert(dsakey != NULL); + BIO_free(bio_buf); + pkey = EVP_PKEY_new(); + OPENSSL_assert(pkey != NULL); + EVP_PKEY_assign_DSA(pkey, dsakey); + ret = SSL_CTX_use_PrivateKey(ctx, pkey); + OPENSSL_assert(ret == 1); + EVP_PKEY_free(pkey); + + bio_buf = BIO_new(BIO_s_mem()); + OPENSSL_assert(bio_buf != NULL); + OPENSSL_assert((size_t)BIO_write(bio_buf, DSACertPEM, sizeof(DSACertPEM)) == sizeof(DSACertPEM)); + cert = PEM_read_bio_X509(bio_buf, NULL, NULL, NULL); + OPENSSL_assert(cert != NULL); + BIO_free(bio_buf); + ret = SSL_CTX_use_certificate(ctx, cert); + OPENSSL_assert(ret == 1); + X509_free(cert); #endif server = SSL_new(ctx); - if (server == NULL) - goto end; in = BIO_new(BIO_s_mem()); - if (in == NULL) - goto end; + OPENSSL_assert(in != NULL); out = BIO_new(BIO_s_mem()); - if (out == NULL) { - BIO_free(in); - goto end; - } + OPENSSL_assert(out != NULL); SSL_set_bio(server, in, out); SSL_set_accept_state(server); opt = (uint8_t)buf[len - 1]; len--; - if ((size_t)BIO_write(in, buf, (int)len) != len) - goto end; + OPENSSL_assert((size_t)BIO_write(in, buf, (int)len) == len); if ((opt & 0x01) != 0) { do { char early_buf[16384]; size_t early_len; - - ret = SSL_read_early_data(server, early_buf, sizeof(early_buf), - &early_len); + ret = SSL_read_early_data(server, early_buf, sizeof(early_buf), &early_len); if (ret != SSL_READ_EARLY_DATA_SUCCESS) break; @@ -755,7 +2458,6 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) } } } -end: SSL_free(server); ERR_clear_error(); SSL_CTX_free(ctx); diff --git a/fuzz/slh-dsa.c b/fuzz/slh-dsa.c index 0f78a01da8..17238bcf8b 100644 --- a/fuzz/slh-dsa.c +++ b/fuzz/slh-dsa.c @@ -63,32 +63,26 @@ static EVP_PKEY *slh_dsa_gen_key(const char *name, uint32_t keysize, { EVP_PKEY_CTX *ctx; EVP_PKEY *new = NULL; + int rc; ctx = EVP_PKEY_CTX_new_from_name(NULL, name, NULL); - if (ctx == NULL) - return NULL; + OPENSSL_assert(ctx != NULL); if (params != NULL) { new = EVP_PKEY_new(); - if (new == NULL) - goto out; - if (!EVP_PKEY_fromdata_init(ctx)) { - EVP_PKEY_free(new); - new = NULL; - goto out; - } - if (EVP_PKEY_fromdata(ctx, &new, EVP_PKEY_KEYPAIR, params) != 1) { + OPENSSL_assert(EVP_PKEY_fromdata_init(ctx)); + if (*param_broken) { + rc = EVP_PKEY_fromdata(ctx, &new, EVP_PKEY_KEYPAIR, params); + OPENSSL_assert(rc == 0); EVP_PKEY_free(new); new = NULL; + } else { + OPENSSL_assert(EVP_PKEY_fromdata(ctx, &new, EVP_PKEY_KEYPAIR, params) == 1); } goto out; } - if (!EVP_PKEY_keygen_init(ctx)) - goto out; - if (!EVP_PKEY_generate(ctx, &new)) { - EVP_PKEY_free(new); - new = NULL; - } + OPENSSL_assert(EVP_PKEY_keygen_init(ctx)); + OPENSSL_assert(EVP_PKEY_generate(ctx, &new)); out: EVP_PKEY_CTX_free(ctx); @@ -227,10 +221,9 @@ static void slh_dsa_gen_key_with_params(uint8_t **buf, size_t *len, *buf = consume_uint8t(*buf, len, &selector); keytype = select_keytype(selector, &keysize); - if (!RAND_bytes(pubbuf, PARAM_BUF_SZ) - || !RAND_bytes(prvbuf, PARAM_BUF_SZ) - || !RAND_bytes(sdbuf, PARAM_BUF_SZ)) - return; + RAND_bytes(pubbuf, PARAM_BUF_SZ); + RAND_bytes(prvbuf, PARAM_BUF_SZ); + RAND_bytes(sdbuf, PARAM_BUF_SZ); /* * select an invalid length if the buffer 0th bit is one @@ -267,6 +260,11 @@ static void slh_dsa_gen_key_with_params(uint8_t **buf, size_t *len, params[2] = OSSL_PARAM_construct_end(); *out1 = (void *)slh_dsa_gen_key(keytype, keysize, params, &broken); + + if (broken) + OPENSSL_assert(*out1 == NULL); + else + OPENSSL_assert(*out1 != NULL); return; } @@ -321,6 +319,7 @@ static void slh_dsa_sign_verify(uint8_t **buf, size_t *len, void *key1, OSSL_PARAM params[4]; int paramidx = 0; int intval1, intval2; + int expect_init_rc = 1; *buf = consume_uint8t(*buf, len, &selector); if (*buf == NULL) @@ -341,6 +340,10 @@ static void slh_dsa_sign_verify(uint8_t **buf, size_t *len, void *key1, msg = (unsigned char *)*buf; msg_len = *len; + /* if msg_len > 255, sign_message_init will fail */ + if (msg_len > 255 && (selector & 0x1) != 0) + expect_init_rc = 0; + *len = 0; if (selector & 0x1) @@ -362,39 +365,33 @@ static void slh_dsa_sign_verify(uint8_t **buf, size_t *len, void *key1, params[paramidx] = OSSL_PARAM_construct_end(); key = (void *)slh_dsa_gen_key(keytype, keylen, NULL, 0); - if (key == NULL) - return; + OPENSSL_assert(key != NULL); *out1 = key; /* for cleanup */ ctx = EVP_PKEY_CTX_new_from_pkey(NULL, key, NULL); - if (ctx == NULL) - goto out; + OPENSSL_assert(ctx != NULL); sig_alg = EVP_SIGNATURE_fetch(NULL, keytype, NULL); - if (sig_alg == NULL) - goto out; + OPENSSL_assert(sig_alg != NULL); + OPENSSL_assert(EVP_PKEY_sign_message_init(ctx, sig_alg, params) == expect_init_rc); /* * the context_string parameter can be no more than 255 bytes, so if - * our random input buffer is greater than that, sign_message_init will - * fail, in which case there's nothing more we can do here so bail out + * our random input buffer is greater than that, we expect failure above, + * which we check for. In that event, there's nothing more we can do here + * so bail out */ - if (EVP_PKEY_sign_message_init(ctx, sig_alg, params) != 1) + if (expect_init_rc == 0) goto out; - if (EVP_PKEY_sign(ctx, NULL, &sig_len, msg, msg_len) != 1) - goto out; + OPENSSL_assert(EVP_PKEY_sign(ctx, NULL, &sig_len, msg, msg_len)); sig = OPENSSL_zalloc(sig_len); - if (sig == NULL) - goto out; + OPENSSL_assert(sig != NULL); - if (EVP_PKEY_sign(ctx, sig, &sig_len, msg, msg_len) != 1) - goto out; + OPENSSL_assert(EVP_PKEY_sign(ctx, sig, &sig_len, msg, msg_len)); - if (EVP_PKEY_verify_message_init(ctx, sig_alg, params) != 1) - goto out; - if (EVP_PKEY_verify(ctx, sig, sig_len, msg, msg_len) != 1) - fprintf(stderr, "Failed to verify message\n"); + OPENSSL_assert(EVP_PKEY_verify_message_init(ctx, sig_alg, params)); + OPENSSL_assert(EVP_PKEY_verify(ctx, sig, sig_len, msg, msg_len)); out: OPENSSL_free(sig); @@ -420,34 +417,32 @@ out: static void slh_dsa_export_import(uint8_t **buf, size_t *len, void *key1, void *key2, void **out1, void **out2) { + int rc; EVP_PKEY *alice = (EVP_PKEY *)key1; EVP_PKEY *bob = (EVP_PKEY *)key2; EVP_PKEY *new = NULL; EVP_PKEY_CTX *ctx = NULL; OSSL_PARAM *params = NULL; - if (alice == NULL || bob == NULL) - return; - - if (!EVP_PKEY_todata(alice, EVP_PKEY_KEYPAIR, ¶ms)) - goto alice_done; + OPENSSL_assert(EVP_PKEY_todata(alice, EVP_PKEY_KEYPAIR, ¶ms) == 1); ctx = EVP_PKEY_CTX_new_from_pkey(NULL, alice, NULL); - if (ctx == NULL) - goto alice_done; + OPENSSL_assert(ctx != NULL); - if (!EVP_PKEY_fromdata_init(ctx)) - goto alice_done; + OPENSSL_assert(EVP_PKEY_fromdata_init(ctx)); new = EVP_PKEY_new(); - if (new == NULL) - goto alice_done; - if (EVP_PKEY_fromdata(ctx, &new, EVP_PKEY_KEYPAIR, params) != 1) - goto alice_done; + OPENSSL_assert(new != NULL); + OPENSSL_assert(EVP_PKEY_fromdata(ctx, &new, EVP_PKEY_KEYPAIR, params) == 1); - (void)EVP_PKEY_eq(alice, new); - -alice_done: + /* + * EVP_PKEY returns: + * 1 if the keys are equivalent + * 0 if the keys are not equivalent + * -1 if the key types are different + * -2 if the operation is not supported + */ + OPENSSL_assert(EVP_PKEY_eq(alice, new) == 1); EVP_PKEY_free(new); EVP_PKEY_CTX_free(ctx); OSSL_PARAM_free(params); @@ -455,26 +450,26 @@ alice_done: ctx = NULL; new = NULL; - if (!EVP_PKEY_todata(bob, EVP_PKEY_KEYPAIR, ¶ms)) - goto bob_done; + OPENSSL_assert(EVP_PKEY_todata(bob, EVP_PKEY_KEYPAIR, ¶ms) == 1); ctx = EVP_PKEY_CTX_new_from_pkey(NULL, bob, NULL); - if (ctx == NULL) - goto bob_done; + OPENSSL_assert(ctx != NULL); - if (!EVP_PKEY_fromdata_init(ctx)) - goto bob_done; + OPENSSL_assert(EVP_PKEY_fromdata_init(ctx)); new = EVP_PKEY_new(); - if (new == NULL) - goto bob_done; - if (EVP_PKEY_fromdata(ctx, &new, EVP_PKEY_KEYPAIR, params) != 1) - goto bob_done; + OPENSSL_assert(new != NULL); + OPENSSL_assert(EVP_PKEY_fromdata(ctx, &new, EVP_PKEY_KEYPAIR, params) == 1); - (void)EVP_PKEY_eq(bob, new); - (void)EVP_PKEY_eq(alice, new); + OPENSSL_assert(EVP_PKEY_eq(bob, new) == 1); + + /* + * Depending on the types of eys that get generated + * we might get a simple non-equivalence or a type mismatch here + */ + rc = EVP_PKEY_eq(alice, new); + OPENSSL_assert(rc == 0 || rc == -1); -bob_done: EVP_PKEY_CTX_free(ctx); EVP_PKEY_free(new); OSSL_PARAM_free(params); @@ -594,7 +589,7 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) */ if (ops[operation].setup != NULL) ops[operation].setup(&buffer_cursor, &len, &in1, &in2); - if (ops[operation].doit != NULL && in1 != NULL) + if (ops[operation].doit != NULL) ops[operation].doit(&buffer_cursor, &len, in1, in2, &out1, &out2); if (ops[operation].cleanup != NULL) ops[operation].cleanup(in1, in2, out1, out2); diff --git a/fuzz/smime.c b/fuzz/smime.c index ab68cb0165..b55a1ef74b 100644 --- a/fuzz/smime.c +++ b/fuzz/smime.c @@ -21,18 +21,8 @@ int FuzzerInitialize(int *argc, char ***argv) int FuzzerTestOneInput(const uint8_t *buf, size_t len) { - BIO *b; - PKCS7 *p7; - - if (len > INT_MAX) - return 0; - - b = BIO_new_mem_buf(buf, (int)len); - if (b == NULL) { - ERR_clear_error(); - return 0; - } - p7 = SMIME_read_PKCS7(b, NULL); + BIO *b = BIO_new_mem_buf(buf, (int)len); + PKCS7 *p7 = SMIME_read_PKCS7(b, NULL); if (p7 != NULL) { STACK_OF(PKCS7_SIGNER_INFO) *p7si = PKCS7_get_signer_info(p7); diff --git a/fuzz/test-corpus.c b/fuzz/test-corpus.c index a908f69644..783df1a076 100644 --- a/fuzz/test-corpus.c +++ b/fuzz/test-corpus.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2020 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -17,13 +17,10 @@ #include #include #include -#include #include #include -#include #include "fuzzer.h" #include "internal/o_dir.h" -#include "mfail.h" #if defined(_WIN32) && defined(_MAX_PATH) && !defined(PATH_MAX) #define PATH_MAX _MAX_PATH @@ -37,45 +34,7 @@ #define S_ISREG(m) ((m) & S_IFREG) #endif -static double secs_since(clock_t start) -{ - return (double)(clock() - start) / CLOCKS_PER_SEC; -} - -static void run_baseline(const unsigned char *buf, size_t s) -{ - FuzzerTestOneInput(buf, s); -} - -static void run_mfail(const unsigned char *buf, size_t s, - const char *path, int file_idx) -{ - mfail_init(file_idx, MFAIL_FLAG_COUNT); - while (mfail_has_next()) { - if (mfail_get_phase() == MFAIL_PHASE_COUNTING) - fprintf(stderr, - "# MFAIL_BEGIN file_idx=%d phase=count\n", file_idx); - else - fprintf(stderr, - "# MFAIL_BEGIN file_idx=%d point=%d/%d\n", - file_idx, mfail_get_point(), mfail_get_total()); - - mfail_start(); - FuzzerTestOneInput(buf, s); - mfail_end(); - - if (mfail_get_phase() == MFAIL_PHASE_COUNTING) { - fprintf(stderr, "# %s: %d allocations\n", path, mfail_get_count()); - } else { - fprintf(stderr, "# %s: point %d/%d %s\n", path, - mfail_get_point(), mfail_get_total(), - mfail_was_triggered() ? "hit" : "unreached"); - } - ERR_clear_error(); - } -} - -static void testfile(const char *pathname, int file_idx) +static void testfile(const char *pathname) { struct stat st; FILE *f; @@ -84,52 +43,26 @@ static void testfile(const char *pathname, int file_idx) if (stat(pathname, &st) < 0 || !S_ISREG(st.st_mode)) return; - - fprintf(stderr, "# CORPUS_FILE file_idx=%d size=%lld path=%s\n", - file_idx, (long long)st.st_size, pathname); + printf("# %s\n", pathname); + fflush(stdout); f = fopen(pathname, "rb"); if (f == NULL) return; buf = malloc(st.st_size); - if (buf == NULL) { - fclose(f); - return; + if (buf != NULL) { + s = fread(buf, 1, st.st_size, f); + OPENSSL_assert(s == (size_t)st.st_size); + FuzzerTestOneInput(buf, s); + free(buf); } - s = fread(buf, 1, st.st_size, f); - OPENSSL_assert(s == (size_t)st.st_size); - - if (mfail_is_installed()) - run_mfail(buf, s, pathname, file_idx); - else - run_baseline(buf, s); - - free(buf); fclose(f); } int main(int argc, char **argv) { - int n, mfi_rc; - int file_idx = 0; - clock_t corpus_start; + int n; - mfi_rc = mfail_install(1); - if (mfi_rc < 0) { - fprintf(stderr, "mfail: failed to install allocator hooks\n"); - return 1; - } else if (mfi_rc > 0) { - /* Disable buffering for better crash analysis */ - setvbuf(stdout, NULL, _IOLBF, 0); - setvbuf(stderr, NULL, _IOLBF, 0); - } - - if (FuzzerInitialize(&argc, &argv) < 0) { - if (mfail_is_installed()) - return 0; /* init failure under mfail is expected */ - return 1; - } - - corpus_start = clock(); + FuzzerInitialize(&argc, &argv); for (n = 1; n < argc; ++n) { size_t dirname_len = strlen(argv[n]); @@ -155,20 +88,18 @@ int main(int argc, char **argv) pathname[dirname_len] = '\0'; } strcpy(pathname + dirname_len, filename); - testfile(pathname, file_idx++); + testfile(pathname); } OPENSSL_DIR_end(&ctx); /* If it wasn't a directory, treat it as a file instead */ if (!wasdir) - testfile(argv[n], file_idx++); + testfile(argv[n]); free(pathname); } - if (!mfail_is_installed() || mfail_is_count_only()) - fprintf(stderr, "# corpus_time: %.6f\n", secs_since(corpus_start)); - FuzzerCleanup(); + return 0; } diff --git a/fuzz/v3name.c b/fuzz/v3name.c index 87fd8c1471..9a525e6f48 100644 --- a/fuzz/v3name.c +++ b/fuzz/v3name.c @@ -9,7 +9,6 @@ #include #include -#include #include #include #include "internal/nelem.h" @@ -24,11 +23,8 @@ int FuzzerTestOneInput(const uint8_t *data, size_t size) { GENERAL_NAME *namesa; GENERAL_NAME *namesb; + const unsigned char *derp = data; - - if (size > LONG_MAX) - return 0; - /* * We create two versions of each GENERAL_NAME so that we ensure when * we compare them they are always different pointers. @@ -36,11 +32,11 @@ int FuzzerTestOneInput(const uint8_t *data, size_t size) namesa = d2i_GENERAL_NAME(NULL, &derp, (long)size); derp = data; namesb = d2i_GENERAL_NAME(NULL, &derp, (long)size); - if (namesa != NULL && namesb != NULL) - GENERAL_NAME_cmp(namesa, namesb); - GENERAL_NAME_free(namesa); - GENERAL_NAME_free(namesb); - ERR_clear_error(); + GENERAL_NAME_cmp(namesa, namesb); + if (namesa != NULL) + GENERAL_NAME_free(namesa); + if (namesb != NULL) + GENERAL_NAME_free(namesb); return 0; } diff --git a/fuzz/x509.c b/fuzz/x509.c index a10e8c0067..68249b48db 100644 --- a/fuzz/x509.c +++ b/fuzz/x509.c @@ -99,8 +99,7 @@ int FuzzerTestOneInput(const uint8_t *buf, size_t len) if (ctx == NULL) goto err; - if (!X509_STORE_CTX_init(ctx, store, x509_1, NULL)) - goto err; + X509_STORE_CTX_init(ctx, store, x509_1, NULL); if (crl != NULL) { crls = sk_X509_CRL_new_null(); diff --git a/include/crypto/aes_platform.h b/include/crypto/aes_platform.h index 36ba2665ee..496b08f46d 100644 --- a/include/crypto/aes_platform.h +++ b/include/crypto/aes_platform.h @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -13,12 +13,6 @@ #include -typedef int (*aes_set_encrypt_key_fn)(const unsigned char *key, - int bits, AES_KEY *ks); - -typedef void (*aes_block128_f)(const unsigned char in[16], - unsigned char out[16], const AES_KEY *key); - #ifdef VPAES_ASM int vpaes_set_encrypt_key(const unsigned char *userKey, int bits, AES_KEY *key); @@ -67,7 +61,7 @@ void AES_xts_decrypt(const unsigned char *inp, unsigned char *out, size_t len, #if defined(OPENSSL_CPUID_OBJ) #if (defined(__powerpc__) || defined(__POWERPC__) || defined(_ARCH_PPC)) -#include "arch/ppc_arch.h" +#include "crypto/ppc_arch.h" #ifdef VPAES_ASM #define VPAES_CAPABLE (OPENSSL_ppccap_P & PPC_ALTIVEC) #endif @@ -83,24 +77,22 @@ void AES_xts_decrypt(const unsigned char *inp, unsigned char *out, size_t len, #define HWAES_xts_decrypt aes_p8_xts_decrypt #endif /* OPENSSL_SYS_MACOSX */ #if !defined(OPENSSL_SYS_AIX) && !defined(OPENSSL_SYS_MACOSX) -#if defined(__BYTE_ORDER__) && __BYTE_ORDER__ == __ORDER_LITTLE_ENDIAN__ #define PPC_AES_GCM_CAPABLE (OPENSSL_ppccap_P & PPC_MADD300) -#endif #define AES_GCM_ENC_BYTES 128 #define AES_GCM_DEC_BYTES 128 size_t ppc_aes_gcm_encrypt(const unsigned char *in, unsigned char *out, size_t len, const void *key, unsigned char ivec[16], - uint64_t *Xi); + u64 *Xi); size_t ppc_aes_gcm_decrypt(const unsigned char *in, unsigned char *out, size_t len, const void *key, unsigned char ivec[16], - uint64_t *Xi); + u64 *Xi); #define AES_GCM_ASM_PPC(gctx) ((gctx)->ctr == aes_p8_ctr32_encrypt_blocks && (gctx)->gcm.funcs.ghash == gcm_ghash_p8) -void gcm_ghash_p8(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp, size_t len); +void gcm_ghash_p8(u64 Xi[2], const u128 Htable[16], const u8 *inp, size_t len); #endif /* OPENSSL_SYS_AIX || OPENSSL_SYS_MACOSX */ #endif /* PPC */ #if (defined(__arm__) || defined(__arm) || defined(__aarch64__) || defined(_M_ARM64)) -#include "arch/arm_arch.h" +#include "crypto/arm_arch.h" #if __ARM_MAX_ARCH__ >= 7 #if defined(BSAES_ASM) #define BSAES_CAPABLE (OPENSSL_armcap_P & ARMV7_NEON) @@ -163,10 +155,10 @@ size_t unroll8_eor3_aes_gcm_dec_192_kernel(const uint8_t *ciphertext, uint64_t p size_t unroll8_eor3_aes_gcm_dec_256_kernel(const uint8_t *ciphertext, uint64_t plaintext_length, uint8_t *plaintext, uint64_t *Xi, unsigned char ivec[16], const void *key); size_t armv8_aes_gcm_encrypt(const unsigned char *in, unsigned char *out, size_t len, const void *key, - unsigned char ivec[16], uint64_t *Xi); + unsigned char ivec[16], u64 *Xi); size_t armv8_aes_gcm_decrypt(const unsigned char *in, unsigned char *out, size_t len, const void *key, - unsigned char ivec[16], uint64_t *Xi); -void gcm_ghash_v8(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp, size_t len); + unsigned char ivec[16], u64 *Xi); +void gcm_ghash_v8(u64 Xi[2], const u128 Htable[16], const u8 *inp, size_t len); #endif #endif #endif @@ -178,7 +170,7 @@ void gcm_ghash_v8(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp, siz #endif #if defined(__loongarch__) || defined(__loongarch64) -#include "arch/loongarch_arch.h" +#include "loongarch_arch.h" #if defined(VPAES_ASM) #define VPAES_CAPABLE (OPENSSL_loongarch_hwcap_P & LOONGARCH_HWCAP_LSX) #endif @@ -292,10 +284,10 @@ void aesni_ccm64_decrypt_blocks(const unsigned char *in, #if defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64) size_t aesni_gcm_encrypt(const unsigned char *in, unsigned char *out, size_t len, - const void *key, unsigned char ivec[16], uint64_t *Xi); + const void *key, unsigned char ivec[16], u64 *Xi); size_t aesni_gcm_decrypt(const unsigned char *in, unsigned char *out, size_t len, - const void *key, unsigned char ivec[16], uint64_t *Xi); -void gcm_ghash_avx(uint64_t Xi[2], const u128 Htable[16], const uint8_t *in, size_t len); + const void *key, unsigned char ivec[16], u64 *Xi); +void gcm_ghash_avx(u64 Xi[2], const u128 Htable[16], const u8 *in, size_t len); #define AES_gcm_encrypt aesni_gcm_encrypt #define AES_gcm_decrypt aesni_gcm_decrypt @@ -305,7 +297,7 @@ void gcm_ghash_avx(uint64_t Xi[2], const u128 Htable[16], const uint8_t *in, siz #elif defined(AES_ASM) && (defined(__sparc) || defined(__sparc__)) /* Fujitsu SPARC64 X support */ -#include "arch/sparc_arch.h" +#include "crypto/sparc_arch.h" #define SPARC_AES_CAPABLE (OPENSSL_sparcv9cap_P[1] & CFR_AES) #define HWAES_CAPABLE (OPENSSL_sparcv9cap_P[0] & SPARCV9_FJAESX) @@ -375,7 +367,7 @@ void aes256_t4_xts_decrypt(const unsigned char *in, unsigned char *out, #elif defined(OPENSSL_CPUID_OBJ) && defined(__s390__) /* IBM S390X support */ -#include "arch/s390x_arch.h" +#include "s390x_arch.h" /* Convert key size to function code: [16,24,32] -> [18,19,20]. */ #define S390X_AES_FC(keylen) (S390X_AES_128 + ((((keylen) << 3) - 128) >> 6)) @@ -439,7 +431,7 @@ void aes256_t4_xts_decrypt(const unsigned char *in, unsigned char *out, #define S390X_AES_FC(keylen) (S390X_AES_128 + ((((keylen) << 3) - 128) >> 6)) #elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 /* RISC-V 64 support */ -#include "arch/riscv_arch.h" +#include "riscv_arch.h" /* Zkne and Zknd extensions (scalar crypto AES). */ int rv64i_zkne_set_encrypt_key(const unsigned char *userKey, const int bits, @@ -484,12 +476,12 @@ void rv64i_zvkb_zvkned_ctr32_encrypt_blocks(const unsigned char *in, size_t rv64i_zvkb_zvkg_zvkned_aes_gcm_encrypt(const unsigned char *in, unsigned char *out, size_t len, const void *key, - unsigned char ivec[16], uint64_t *Xi); + unsigned char ivec[16], u64 *Xi); size_t rv64i_zvkb_zvkg_zvkned_aes_gcm_decrypt(const unsigned char *in, unsigned char *out, size_t len, const void *key, - unsigned char ivec[16], uint64_t *Xi); + unsigned char ivec[16], u64 *Xi); void rv64i_zvbb_zvkg_zvkned_aes_xts_encrypt(const unsigned char *in, unsigned char *out, size_t length, @@ -503,7 +495,7 @@ void rv64i_zvbb_zvkg_zvkned_aes_xts_decrypt(const unsigned char *in, const AES_KEY *key2, const unsigned char iv[16]); -void gcm_ghash_rv64i_zvkg(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp, +void gcm_ghash_rv64i_zvkg(u64 Xi[2], const u128 Htable[16], const u8 *inp, size_t len); #define AES_GCM_ENC_BYTES 64 @@ -515,7 +507,7 @@ void gcm_ghash_rv64i_zvkg(uint64_t Xi[2], const u128 Htable[16], const uint8_t * #elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 32 /* RISC-V 32 support */ -#include "arch/riscv_arch.h" +#include "riscv_arch.h" int rv32i_zkne_set_encrypt_key(const unsigned char *userKey, const int bits, AES_KEY *key); diff --git a/include/crypto/asn1.h b/include/crypto/asn1.h index bc556588d0..558764869c 100644 --- a/include/crypto/asn1.h +++ b/include/crypto/asn1.h @@ -1,5 +1,5 @@ /* - * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -20,45 +20,6 @@ #include -#define ASN1_STRING_FLAG_BITS_LEFT 0x08 /* Set if 0x07 has bits left value */ -/* - * This indicates that the ASN1_STRING is not a real value but just a place - * holder for the location where indefinite length constructed data should be - * inserted in the memory buffer - */ -#define ASN1_STRING_FLAG_NDEF 0x010 - -/* - * This flag is used by the CMS code to indicate that a string is not - * complete and is a place holder for content when it had all been accessed. - * The flag will be reset when content has been written to it. - */ - -#define ASN1_STRING_FLAG_CONT 0x020 -/* - * This flag is used by ASN1 code to indicate an ASN1_STRING is an MSTRING - * type. - */ -#define ASN1_STRING_FLAG_MSTRING 0x040 -/* String is embedded and only content should be freed */ -#define ASN1_STRING_FLAG_EMBED 0x080 - -/* Data is static and should not be freed. */ -#define ASN1_STRING_FLAG_DATA_NOT_OWNED 0x100 - -/* This is the base type that holds just about everything :-) */ -struct asn1_string_st { - int length; - int type; - unsigned char *data; - /* - * The value of the following field depends on the type being held. It - * is mostly being used for BIT_STRING so if the input data has a - * non-zero 'unused bits' value, it will be handled correctly - */ - long flags; -}; - struct evp_pkey_asn1_method_st { int pkey_id; int pkey_base_id; @@ -186,8 +147,7 @@ EVP_PKEY *ossl_d2i_PrivateKey_legacy(int keytype, EVP_PKEY **a, OSSL_LIB_CTX *libctx, const char *propq); X509_ALGOR *ossl_X509_ALGOR_from_nid(int nid, int ptype, void *pval); -void ossl_asn1_bit_string_clear_unused_bits(ASN1_STRING *str); -void ossl_asn1_bit_string_set_unused_bits(ASN1_STRING *str, unsigned int num); +void ossl_asn1_string_set_bits_left(ASN1_STRING *str, unsigned int num); int asn1_item_embed_d2i(ASN1_VALUE **pval, const unsigned char **in, long len, const ASN1_ITEM *it, int tag, int aclass, @@ -196,7 +156,4 @@ int asn1_item_embed_d2i(ASN1_VALUE **pval, const unsigned char **in, ASN1_TIME *ossl_asn1_time_from_tm(ASN1_TIME *s, struct tm *ts, int type); -int ossl_utf8_getc_internal(const unsigned char *str, int len, uint32_t *val); -int ossl_utf8_putc_internal(unsigned char *str, int len, uint32_t value); - #endif /* ndef OSSL_CRYPTO_ASN1_H */ diff --git a/include/crypto/bn_dh.h b/include/crypto/bn_dh.h index 89175dfac2..a634a6f8f8 100644 --- a/include/crypto/bn_dh.h +++ b/include/crypto/bn_dh.h @@ -7,11 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_CRYPTO_BN_DH_H) -#define OSSL_CRYPTO_BN_DH_H - -#include - #define declare_dh_bn(x) \ extern const BIGNUM ossl_bignum_dh##x##_p; \ extern const BIGNUM ossl_bignum_dh##x##_q; \ @@ -46,5 +41,3 @@ extern const BIGNUM ossl_bignum_modp_3072_q; extern const BIGNUM ossl_bignum_modp_4096_q; extern const BIGNUM ossl_bignum_modp_6144_q; extern const BIGNUM ossl_bignum_modp_8192_q; - -#endif /* !defined(OSSL_CRYPTO_BN_DH_H) */ diff --git a/include/crypto/bn_srp.h b/include/crypto/bn_srp.h index 7e3dade0bd..00b160aad1 100644 --- a/include/crypto/bn_srp.h +++ b/include/crypto/bn_srp.h @@ -6,13 +6,9 @@ * in the file LICENSE in the source distribution or at * https://www.openssl.org/source/license.html */ -#if !defined(OPENSSL_CRYPTO_BN_SRP_H) -#define OPENSSL_CRYPTO_BN_SRP_H #ifndef OPENSSL_NO_SRP -#include - extern const BIGNUM ossl_bn_group_1024; extern const BIGNUM ossl_bn_group_1536; @@ -34,4 +30,3 @@ extern const BIGNUM ossl_bn_generator_5; extern const BIGNUM ossl_bn_generator_2; #endif -#endif /* !defined(OPENSSL_CRYPTO_BN_SRP_H) */ diff --git a/include/crypto/cmll_platform.h b/include/crypto/cmll_platform.h index 207084b123..02ed385c05 100644 --- a/include/crypto/cmll_platform.h +++ b/include/crypto/cmll_platform.h @@ -14,7 +14,7 @@ #if defined(CMLL_ASM) && (defined(__sparc) || defined(__sparc__)) /* Fujitsu SPARC64 X support */ -#include "arch/sparc_arch.h" +#include "crypto/sparc_arch.h" #ifndef OPENSSL_NO_CAMELLIA #define SPARC_CMLL_CAPABLE (OPENSSL_sparcv9cap_P[1] & CFR_CAMELLIA) diff --git a/include/crypto/context.h b/include/crypto/context.h index d84b4879a6..199df30726 100644 --- a/include/crypto/context.h +++ b/include/crypto/context.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_CRYPTO_CONTEXT_H) -#define OSSL_CRYPTO_CONTEXT_H - #include void *ossl_provider_store_new(OSSL_LIB_CTX *); @@ -51,5 +48,3 @@ void ossl_release_default_drbg_ctx(void); #if defined(OPENSSL_THREADS) void ossl_threads_ctx_free(void *); #endif - -#endif /* !defined(OSSL_CRYPTO_CONTEXT_H) */ diff --git a/include/crypto/decoder.h b/include/crypto/decoder.h index dafb143593..fcb914faeb 100644 --- a/include/crypto/decoder.h +++ b/include/crypto/decoder.h @@ -20,7 +20,7 @@ * (provider-object(7)). */ void *ossl_decoder_from_algorithm(int id, const OSSL_ALGORITHM *algodef, - OSSL_PROVIDER *prov, int no_store); + OSSL_PROVIDER *prov); OSSL_DECODER_INSTANCE * ossl_decoder_instance_new_forprov(OSSL_DECODER *decoder, void *provctx, diff --git a/include/crypto/des_platform.h b/include/crypto/des_platform.h index 660d1b6a18..e0210c664f 100644 --- a/include/crypto/des_platform.h +++ b/include/crypto/des_platform.h @@ -14,7 +14,7 @@ #if defined(DES_ASM) && (defined(__sparc) || defined(__sparc__)) /* Fujitsu SPARC64 X support */ -#include "arch/sparc_arch.h" +#include "crypto/sparc_arch.h" #ifndef OPENSSL_NO_DES #define SPARC_DES_CAPABLE (OPENSSL_sparcv9cap_P[1] & CFR_DES) diff --git a/include/crypto/dh.h b/include/crypto/dh.h index fb7430cfba..66dab801b9 100644 --- a/include/crypto/dh.h +++ b/include/crypto/dh.h @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -18,7 +18,6 @@ DH *ossl_dh_new_by_nid_ex(OSSL_LIB_CTX *libctx, int nid); DH *ossl_dh_new_ex(OSSL_LIB_CTX *libctx); -OSSL_LIB_CTX *ossl_dh_get0_libctx(const DH *dh); void ossl_dh_set0_libctx(DH *d, OSSL_LIB_CTX *libctx); int ossl_dh_generate_ffc_parameters(DH *dh, int type, int pbits, int qbits, BN_GENCB *cb); diff --git a/include/crypto/dsa.h b/include/crypto/dsa.h index c8272a0047..73a61e7a88 100644 --- a/include/crypto/dsa.h +++ b/include/crypto/dsa.h @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2022 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -25,7 +25,6 @@ #define DSA_PARAMGEN_TYPE_FIPS_DEFAULT 2 DSA *ossl_dsa_new(OSSL_LIB_CTX *libctx); -OSSL_LIB_CTX *ossl_dsa_get0_libctx(const DSA *d); void ossl_dsa_set0_libctx(DSA *d, OSSL_LIB_CTX *libctx); int ossl_dsa_generate_ffc_parameters(DSA *dsa, int type, int pbits, int qbits, diff --git a/include/crypto/encodererr.h b/include/crypto/encodererr.h index 71fddeb50c..db930a5dc2 100644 --- a/include/crypto/encodererr.h +++ b/include/crypto/encodererr.h @@ -1,6 +1,6 @@ /* * Generated by util/mkerr.pl DO NOT EDIT - * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy diff --git a/include/crypto/ess.h b/include/crypto/ess.h index cc5bb7febc..c29752117e 100644 --- a/include/crypto/ess.h +++ b/include/crypto/ess.h @@ -11,10 +11,6 @@ #define OSSL_CRYPTO_ESS_H #pragma once -#include -#include -#include - /*- * IssuerSerial ::= SEQUENCE { * issuer GeneralNames, diff --git a/include/crypto/evp.h b/include/crypto/evp.h index eca29a7438..805ae38ff9 100644 --- a/include/crypto/evp.h +++ b/include/crypto/evp.h @@ -1,5 +1,5 @@ /* - * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -119,12 +119,16 @@ struct evp_pkey_ctx_st { /* EVP_PKEY identity */ int legacy_keytype; + /* Method associated with this operation */ + const EVP_PKEY_METHOD *pmeth; /* Key: may be NULL */ EVP_PKEY *pkey; /* Peer key for key agreement, may be NULL */ EVP_PKEY *peerkey; /* Algorithm specific data */ void *data; + /* Indicator if digest_custom needs to be called */ + unsigned int flag_call_digest_custom : 1; /* * Used to support taking custody of memory in the case of a provider being * used with the deprecated EVP_PKEY_CTX_set_rsa_keygen_pubexp() API. This @@ -136,12 +140,74 @@ struct evp_pkey_ctx_st { #define EVP_PKEY_FLAG_DYNAMIC 1 +struct evp_pkey_method_st { + int pkey_id; + int flags; + int (*init)(EVP_PKEY_CTX *ctx); + int (*copy)(EVP_PKEY_CTX *dst, const EVP_PKEY_CTX *src); + void (*cleanup)(EVP_PKEY_CTX *ctx); + int (*paramgen_init)(EVP_PKEY_CTX *ctx); + int (*paramgen)(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey); + int (*keygen_init)(EVP_PKEY_CTX *ctx); + int (*keygen)(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey); + int (*sign_init)(EVP_PKEY_CTX *ctx); + int (*sign)(EVP_PKEY_CTX *ctx, unsigned char *sig, size_t *siglen, + const unsigned char *tbs, size_t tbslen); + int (*verify_init)(EVP_PKEY_CTX *ctx); + int (*verify)(EVP_PKEY_CTX *ctx, + const unsigned char *sig, size_t siglen, + const unsigned char *tbs, size_t tbslen); + int (*verify_recover_init)(EVP_PKEY_CTX *ctx); + int (*verify_recover)(EVP_PKEY_CTX *ctx, + unsigned char *rout, size_t *routlen, + const unsigned char *sig, size_t siglen); + int (*signctx_init)(EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx); + int (*signctx)(EVP_PKEY_CTX *ctx, unsigned char *sig, size_t *siglen, + EVP_MD_CTX *mctx); + int (*verifyctx_init)(EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx); + int (*verifyctx)(EVP_PKEY_CTX *ctx, const unsigned char *sig, int siglen, + EVP_MD_CTX *mctx); + int (*encrypt_init)(EVP_PKEY_CTX *ctx); + int (*encrypt)(EVP_PKEY_CTX *ctx, unsigned char *out, size_t *outlen, + const unsigned char *in, size_t inlen); + int (*decrypt_init)(EVP_PKEY_CTX *ctx); + int (*decrypt)(EVP_PKEY_CTX *ctx, unsigned char *out, size_t *outlen, + const unsigned char *in, size_t inlen); + int (*derive_init)(EVP_PKEY_CTX *ctx); + int (*derive)(EVP_PKEY_CTX *ctx, unsigned char *key, size_t *keylen); + int (*ctrl)(EVP_PKEY_CTX *ctx, int type, int p1, void *p2); + int (*ctrl_str)(EVP_PKEY_CTX *ctx, const char *type, const char *value); + int (*digestsign)(EVP_MD_CTX *ctx, unsigned char *sig, size_t *siglen, + const unsigned char *tbs, size_t tbslen); + int (*digestverify)(EVP_MD_CTX *ctx, const unsigned char *sig, + size_t siglen, const unsigned char *tbs, + size_t tbslen); + int (*check)(EVP_PKEY *pkey); + int (*public_check)(EVP_PKEY *pkey); + int (*param_check)(EVP_PKEY *pkey); + + int (*digest_custom)(EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx); +} /* EVP_PKEY_METHOD */; + +DEFINE_STACK_OF_CONST(EVP_PKEY_METHOD) + void evp_pkey_set_cb_translate(BN_GENCB *cb, EVP_PKEY_CTX *ctx); +const EVP_PKEY_METHOD *ossl_dh_pkey_method(void); +const EVP_PKEY_METHOD *ossl_dhx_pkey_method(void); +const EVP_PKEY_METHOD *ossl_dsa_pkey_method(void); +const EVP_PKEY_METHOD *ossl_ec_pkey_method(void); +const EVP_PKEY_METHOD *ossl_ecx25519_pkey_method(void); +const EVP_PKEY_METHOD *ossl_ecx448_pkey_method(void); +const EVP_PKEY_METHOD *ossl_ed25519_pkey_method(void); +const EVP_PKEY_METHOD *ossl_ed448_pkey_method(void); +const EVP_PKEY_METHOD *ossl_rsa_pkey_method(void); +const EVP_PKEY_METHOD *ossl_rsa_pss_pkey_method(void); + struct evp_mac_st { OSSL_PROVIDER *prov; int name_id; - int no_store; + int origin; char *type_name; const char *description; @@ -165,7 +231,7 @@ struct evp_mac_st { struct evp_kdf_st { OSSL_PROVIDER *prov; int name_id; - int no_store; + int origin; char *type_name; const char *description; CRYPTO_REF_COUNT refcnt; @@ -187,17 +253,30 @@ struct evp_kdf_st { #define EVP_ORIG_DYNAMIC 0 #define EVP_ORIG_GLOBAL 1 +#define EVP_ORIG_METH 2 +#define EVP_ORIG_FROZEN 3 struct evp_md_st { /* nid */ int type; + /* Legacy structure members */ int pkey_type; int md_size; unsigned long flags; int origin; + int (*init)(EVP_MD_CTX *ctx); + int (*update)(EVP_MD_CTX *ctx, const void *data, size_t count); + int (*final)(EVP_MD_CTX *ctx, unsigned char *md); + int (*copy)(EVP_MD_CTX *to, const EVP_MD_CTX *from); + int (*cleanup)(EVP_MD_CTX *ctx); int block_size; + int ctx_size; /* how big does the ctx->md_data need to be */ + /* control function */ + int (*md_ctrl)(EVP_MD_CTX *ctx, int cmd, int p1, void *p2); + /* New structure members */ + /* Above comment to be removed when legacy has gone */ int name_id; char *type_name; const char *description; @@ -218,8 +297,7 @@ struct evp_md_st { OSSL_FUNC_digest_gettable_params_fn *gettable_params; OSSL_FUNC_digest_settable_ctx_params_fn *settable_ctx_params; OSSL_FUNC_digest_gettable_ctx_params_fn *gettable_ctx_params; - OSSL_FUNC_digest_serialize_fn *serialize; - OSSL_FUNC_digest_deserialize_fn *deserialize; + } /* EVP_MD */; struct evp_cipher_st { @@ -230,11 +308,32 @@ struct evp_cipher_st { int key_len; int iv_len; + /* Legacy structure members */ /* Various flags */ unsigned long flags; /* How the EVP_CIPHER was created. */ int origin; + /* init key */ + int (*init)(EVP_CIPHER_CTX *ctx, const unsigned char *key, + const unsigned char *iv, int enc); + /* encrypt/decrypt data */ + int (*do_cipher)(EVP_CIPHER_CTX *ctx, unsigned char *out, + const unsigned char *in, size_t inl); + /* cleanup ctx */ + int (*cleanup)(EVP_CIPHER_CTX *); + /* how big ctx->cipher_data needs to be */ + int ctx_size; + /* Populate a ASN1_TYPE with parameters */ + int (*set_asn1_parameters)(EVP_CIPHER_CTX *, ASN1_TYPE *); + /* Get parameters from a ASN1_TYPE */ + int (*get_asn1_parameters)(EVP_CIPHER_CTX *, ASN1_TYPE *); + /* Miscellaneous operations */ + int (*ctrl)(EVP_CIPHER_CTX *, int type, int arg, void *ptr); + /* Application data */ + void *app_data; + /* New structure members */ + /* Above comment to be removed when legacy has gone */ int name_id; char *type_name; const char *description; @@ -262,56 +361,225 @@ struct evp_cipher_st { OSSL_FUNC_cipher_decrypt_skey_init_fn *dinit_skey; } /* EVP_CIPHER */; +/* Macros to code block cipher wrappers */ + +/* Wrapper functions for each cipher mode */ + +#define EVP_C_DATA(kstruct, ctx) \ + ((kstruct *)EVP_CIPHER_CTX_get_cipher_data(ctx)) + +#define BLOCK_CIPHER_ecb_loop() \ + size_t i, bl; \ + bl = EVP_CIPHER_CTX_get0_cipher(ctx)->block_size; \ + if (inl < bl) \ + return 1; \ + inl -= bl; \ + for (i = 0; i <= inl; i += bl) + +#define BLOCK_CIPHER_func_ecb(cname, cprefix, kstruct, ksched) \ + static int cname##_ecb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out, const unsigned char *in, size_t inl) \ + { \ + BLOCK_CIPHER_ecb_loop() \ + cprefix##_ecb_encrypt(in + i, out + i, &EVP_C_DATA(kstruct, ctx)->ksched, EVP_CIPHER_CTX_is_encrypting(ctx)); \ + return 1; \ + } + #define EVP_MAXCHUNK ((size_t)1 << 30) +#define BLOCK_CIPHER_func_ofb(cname, cprefix, cbits, kstruct, ksched) \ + static int cname##_ofb_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out, const unsigned char *in, size_t inl) \ + { \ + while (inl >= EVP_MAXCHUNK) { \ + int num = EVP_CIPHER_CTX_get_num(ctx); \ + cprefix##_ofb##cbits##_encrypt(in, out, (long)EVP_MAXCHUNK, &EVP_C_DATA(kstruct, ctx)->ksched, ctx->iv, &num); \ + EVP_CIPHER_CTX_set_num(ctx, num); \ + inl -= EVP_MAXCHUNK; \ + in += EVP_MAXCHUNK; \ + out += EVP_MAXCHUNK; \ + } \ + if (inl) { \ + int num = EVP_CIPHER_CTX_get_num(ctx); \ + cprefix##_ofb##cbits##_encrypt(in, out, (long)inl, &EVP_C_DATA(kstruct, ctx)->ksched, ctx->iv, &num); \ + EVP_CIPHER_CTX_set_num(ctx, num); \ + } \ + return 1; \ + } + +#define BLOCK_CIPHER_func_cbc(cname, cprefix, kstruct, ksched) \ + static int cname##_cbc_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out, const unsigned char *in, size_t inl) \ + { \ + while (inl >= EVP_MAXCHUNK) { \ + cprefix##_cbc_encrypt(in, out, (long)EVP_MAXCHUNK, &EVP_C_DATA(kstruct, ctx)->ksched, ctx->iv, EVP_CIPHER_CTX_is_encrypting(ctx)); \ + inl -= EVP_MAXCHUNK; \ + in += EVP_MAXCHUNK; \ + out += EVP_MAXCHUNK; \ + } \ + if (inl) \ + cprefix##_cbc_encrypt(in, out, (long)inl, &EVP_C_DATA(kstruct, ctx)->ksched, ctx->iv, EVP_CIPHER_CTX_is_encrypting(ctx)); \ + return 1; \ + } + +#define BLOCK_CIPHER_func_cfb(cname, cprefix, cbits, kstruct, ksched) \ + static int cname##_cfb##cbits##_cipher(EVP_CIPHER_CTX *ctx, unsigned char *out, const unsigned char *in, size_t inl) \ + { \ + size_t chunk = EVP_MAXCHUNK; \ + if (cbits == 1) \ + chunk >>= 3; \ + if (inl < chunk) \ + chunk = inl; \ + while (inl && inl >= chunk) { \ + int num = EVP_CIPHER_CTX_get_num(ctx); \ + cprefix##_cfb##cbits##_encrypt(in, out, (long)((cbits == 1) && !EVP_CIPHER_CTX_test_flags(ctx, EVP_CIPH_FLAG_LENGTH_BITS) ? chunk * 8 : chunk), \ + &EVP_C_DATA(kstruct, ctx)->ksched, ctx->iv, \ + &num, EVP_CIPHER_CTX_is_encrypting(ctx)); \ + EVP_CIPHER_CTX_set_num(ctx, num); \ + inl -= chunk; \ + in += chunk; \ + out += chunk; \ + if (inl < chunk) \ + chunk = inl; \ + } \ + return 1; \ + } + +#define BLOCK_CIPHER_all_funcs(cname, cprefix, cbits, kstruct, ksched) \ + BLOCK_CIPHER_func_cbc(cname, cprefix, kstruct, ksched) \ + BLOCK_CIPHER_func_cfb(cname, cprefix, cbits, kstruct, ksched) \ + BLOCK_CIPHER_func_ecb(cname, cprefix, kstruct, ksched) \ + BLOCK_CIPHER_func_ofb(cname, cprefix, cbits, kstruct, ksched) + #define BLOCK_CIPHER_def1(cname, nmode, mode, MODE, kstruct, nid, block_size, \ - key_len, iv_len, flags) \ + key_len, iv_len, flags, init_key, cleanup, \ + set_asn1, get_asn1, ctrl) \ static const EVP_CIPHER cname##_##mode = { \ nid##_##nmode, block_size, key_len, iv_len, \ flags | EVP_CIPH_##MODE##_MODE, \ - EVP_ORIG_GLOBAL \ + EVP_ORIG_GLOBAL, \ + init_key, \ + cname##_##mode##_cipher, \ + cleanup, \ + sizeof(kstruct), \ + set_asn1, get_asn1, \ + ctrl, \ + NULL \ }; \ const EVP_CIPHER *EVP_##cname##_##mode(void) { return &cname##_##mode; } #define BLOCK_CIPHER_def_cbc(cname, kstruct, nid, block_size, key_len, \ - iv_len, flags) \ + iv_len, flags, init_key, cleanup, set_asn1, \ + get_asn1, ctrl) \ BLOCK_CIPHER_def1(cname, cbc, cbc, CBC, kstruct, nid, block_size, key_len, \ - iv_len, flags) + iv_len, flags, init_key, cleanup, set_asn1, get_asn1, ctrl) #define BLOCK_CIPHER_def_cfb(cname, kstruct, nid, key_len, \ - iv_len, cbits, flags) \ + iv_len, cbits, flags, init_key, cleanup, \ + set_asn1, get_asn1, ctrl) \ BLOCK_CIPHER_def1(cname, cfb##cbits, cfb##cbits, CFB, kstruct, nid, 1, \ - key_len, iv_len, flags) + key_len, iv_len, flags, init_key, cleanup, set_asn1, \ + get_asn1, ctrl) #define BLOCK_CIPHER_def_ofb(cname, kstruct, nid, key_len, \ - iv_len, cbits, flags) \ + iv_len, cbits, flags, init_key, cleanup, \ + set_asn1, get_asn1, ctrl) \ BLOCK_CIPHER_def1(cname, ofb##cbits, ofb, OFB, kstruct, nid, 1, \ - key_len, iv_len, flags) + key_len, iv_len, flags, init_key, cleanup, set_asn1, \ + get_asn1, ctrl) #define BLOCK_CIPHER_def_ecb(cname, kstruct, nid, block_size, key_len, \ - flags) \ + flags, init_key, cleanup, set_asn1, \ + get_asn1, ctrl) \ BLOCK_CIPHER_def1(cname, ecb, ecb, ECB, kstruct, nid, block_size, key_len, \ - 0, flags) + 0, flags, init_key, cleanup, set_asn1, get_asn1, ctrl) -#define BLOCK_CIPHER_defs(cname, kstruct, \ - nid, block_size, key_len, iv_len, cbits, flags) \ - BLOCK_CIPHER_def_cbc(cname, kstruct, nid, block_size, key_len, iv_len, flags) \ - BLOCK_CIPHER_def_cfb(cname, kstruct, nid, key_len, iv_len, cbits, \ - flags) \ - BLOCK_CIPHER_def_ofb(cname, kstruct, nid, key_len, iv_len, cbits, \ - flags) \ - BLOCK_CIPHER_def_ecb(cname, kstruct, nid, block_size, key_len, flags) +#define BLOCK_CIPHER_defs(cname, kstruct, \ + nid, block_size, key_len, iv_len, cbits, flags, \ + init_key, cleanup, set_asn1, get_asn1, ctrl) \ + BLOCK_CIPHER_def_cbc(cname, kstruct, nid, block_size, key_len, iv_len, flags, \ + init_key, cleanup, set_asn1, get_asn1, ctrl) \ + BLOCK_CIPHER_def_cfb(cname, kstruct, nid, key_len, iv_len, cbits, \ + flags, init_key, cleanup, set_asn1, get_asn1, ctrl) \ + BLOCK_CIPHER_def_ofb(cname, kstruct, nid, key_len, iv_len, cbits, \ + flags, init_key, cleanup, set_asn1, get_asn1, ctrl) \ + BLOCK_CIPHER_def_ecb(cname, kstruct, nid, block_size, key_len, flags, \ + init_key, cleanup, set_asn1, get_asn1, ctrl) -#define IMPLEMENT_BLOCK_CIPHER(cname, ksched, cprefix, kstruct, nid, \ - block_size, key_len, iv_len, cbits, \ - flags) \ - BLOCK_CIPHER_defs(cname, kstruct, nid, block_size, key_len, iv_len, \ - cbits, flags) +/*- +#define BLOCK_CIPHER_defs(cname, kstruct, \ + nid, block_size, key_len, iv_len, flags,\ + init_key, cleanup, set_asn1, get_asn1, ctrl)\ +static const EVP_CIPHER cname##_cbc = {\ + nid##_cbc, block_size, key_len, iv_len, \ + flags | EVP_CIPH_CBC_MODE,\ + EVP_ORIG_GLOBAL,\ + init_key,\ + cname##_cbc_cipher,\ + cleanup,\ + sizeof(EVP_CIPHER_CTX)-sizeof((((EVP_CIPHER_CTX *)NULL)->c))+\ + sizeof((((EVP_CIPHER_CTX *)NULL)->c.kstruct)),\ + set_asn1, get_asn1,\ + ctrl, \ + NULL \ +};\ +const EVP_CIPHER *EVP_##cname##_cbc(void) { return &cname##_cbc; }\ +static const EVP_CIPHER cname##_cfb = {\ + nid##_cfb64, 1, key_len, iv_len, \ + flags | EVP_CIPH_CFB_MODE,\ + EVP_ORIG_GLOBAL,\ + init_key,\ + cname##_cfb_cipher,\ + cleanup,\ + sizeof(EVP_CIPHER_CTX)-sizeof((((EVP_CIPHER_CTX *)NULL)->c))+\ + sizeof((((EVP_CIPHER_CTX *)NULL)->c.kstruct)),\ + set_asn1, get_asn1,\ + ctrl,\ + NULL \ +};\ +const EVP_CIPHER *EVP_##cname##_cfb(void) { return &cname##_cfb; }\ +static const EVP_CIPHER cname##_ofb = {\ + nid##_ofb64, 1, key_len, iv_len, \ + flags | EVP_CIPH_OFB_MODE,\ + EVP_ORIG_GLOBAL,\ + init_key,\ + cname##_ofb_cipher,\ + cleanup,\ + sizeof(EVP_CIPHER_CTX)-sizeof((((EVP_CIPHER_CTX *)NULL)->c))+\ + sizeof((((EVP_CIPHER_CTX *)NULL)->c.kstruct)),\ + set_asn1, get_asn1,\ + ctrl,\ + NULL \ +};\ +const EVP_CIPHER *EVP_##cname##_ofb(void) { return &cname##_ofb; }\ +static const EVP_CIPHER cname##_ecb = {\ + nid##_ecb, block_size, key_len, iv_len, \ + flags | EVP_CIPH_ECB_MODE,\ + EVP_ORIG_GLOBAL,\ + init_key,\ + cname##_ecb_cipher,\ + cleanup,\ + sizeof(EVP_CIPHER_CTX)-sizeof((((EVP_CIPHER_CTX *)NULL)->c))+\ + sizeof((((EVP_CIPHER_CTX *)NULL)->c.kstruct)),\ + set_asn1, get_asn1,\ + ctrl,\ + NULL \ +};\ +const EVP_CIPHER *EVP_##cname##_ecb(void) { return &cname##_ecb; } +*/ + +#define IMPLEMENT_BLOCK_CIPHER(cname, ksched, cprefix, kstruct, nid, \ + block_size, key_len, iv_len, cbits, \ + flags, init_key, \ + cleanup, set_asn1, get_asn1, ctrl) \ + BLOCK_CIPHER_all_funcs(cname, cprefix, cbits, kstruct, ksched) \ + BLOCK_CIPHER_defs(cname, kstruct, nid, block_size, key_len, iv_len, \ + cbits, flags, init_key, cleanup, set_asn1, \ + get_asn1, ctrl) #define IMPLEMENT_CFBR(cipher, cprefix, kstruct, ksched, keysize, cbits, iv_len, fl) \ - BLOCK_CIPHER_def_cfb(cipher##_##keysize, kstruct, \ - NID_##cipher##_##keysize, keysize / 8, iv_len, cbits, \ - (fl) | EVP_CIPH_FLAG_DEFAULT_ASN1) + BLOCK_CIPHER_func_cfb(cipher##_##keysize, cprefix, cbits, kstruct, ksched) \ + BLOCK_CIPHER_def_cfb(cipher##_##keysize, kstruct, \ + NID_##cipher##_##keysize, keysize / 8, iv_len, cbits, \ + (fl) | EVP_CIPH_FLAG_DEFAULT_ASN1, \ + cipher##_init_key, NULL, NULL, NULL, NULL) typedef struct { unsigned char iv[EVP_MAX_IV_LENGTH]; @@ -501,6 +769,7 @@ struct evp_skey_st { void openssl_add_all_ciphers_int(void); void openssl_add_all_digests_int(void); void evp_cleanup_int(void); +void evp_app_cleanup_int(void); void *evp_pkey_export_to_provider(EVP_PKEY *pk, OSSL_LIB_CTX *libctx, EVP_KEYMGMT **keymgmt, const char *propquery); @@ -537,7 +806,7 @@ void *evp_keymgmt_util_export_to_provider(EVP_PKEY *pk, EVP_KEYMGMT *keymgmt, OP_CACHE_ELEM *evp_keymgmt_util_find_operation_cache(EVP_PKEY *pk, EVP_KEYMGMT *keymgmt, int selection); -void evp_keymgmt_util_clear_operation_cache(EVP_PKEY *pk); +int evp_keymgmt_util_clear_operation_cache(EVP_PKEY *pk); int evp_keymgmt_util_cache_keydata(EVP_PKEY *pk, EVP_KEYMGMT *keymgmt, void *keydata, int selection); void evp_keymgmt_util_cache_keyinfo(EVP_PKEY *pk); @@ -557,7 +826,7 @@ const char *evp_keymgmt_util_query_operation_name(EVP_KEYMGMT *keymgmt, /* * KEYMGMT provider interface functions */ -void *evp_keymgmt_newdata(const EVP_KEYMGMT *keymgmt, const OSSL_PARAM params[]); +void *evp_keymgmt_newdata(const EVP_KEYMGMT *keymgmt); void evp_keymgmt_freedata(const EVP_KEYMGMT *keymgmt, void *keyddata); int evp_keymgmt_get_params(const EVP_KEYMGMT *keymgmt, void *keydata, OSSL_PARAM params[]); @@ -731,14 +1000,4 @@ int evp_pkey_decrypt_alloc(EVP_PKEY_CTX *ctx, unsigned char **outp, int ossl_md2hmacnid(int mdnid); int ossl_hmac2mdnid(int hmac_nid); -const EVP_PKEY_ASN1_METHOD *evp_pkey_asn1_find(int type); -const EVP_PKEY_ASN1_METHOD *evp_pkey_asn1_find_str(const char *str, int len); -int evp_pkey_asn1_get_count(void); -const EVP_PKEY_ASN1_METHOD *evp_pkey_asn1_get0(int idx); -int evp_pkey_asn1_get0_info(int *ppkey_id, int *ppkey_base_id, - int *ppkey_flags, const char **pinfo, - const char **ppem_str, - const EVP_PKEY_ASN1_METHOD *ameth); -const EVP_PKEY_ASN1_METHOD *evp_pkey_get0_asn1(const EVP_PKEY *pkey); - #endif /* OSSL_CRYPTO_EVP_H */ diff --git a/include/crypto/evperr.h b/include/crypto/evperr.h index afe136c816..1a91b62fce 100644 --- a/include/crypto/evperr.h +++ b/include/crypto/evperr.h @@ -1,6 +1,6 @@ /* * Generated by util/mkerr.pl DO NOT EDIT - * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy diff --git a/include/crypto/httperr.h b/include/crypto/httperr.h index 94d812295c..f5550aa167 100644 --- a/include/crypto/httperr.h +++ b/include/crypto/httperr.h @@ -1,6 +1,6 @@ /* * Generated by util/mkerr.pl DO NOT EDIT - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy diff --git a/include/crypto/lms.h b/include/crypto/lms.h index e36ddb63cc..6fd2835c29 100644 --- a/include/crypto/lms.h +++ b/include/crypto/lms.h @@ -1,5 +1,5 @@ /* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -117,7 +117,6 @@ typedef struct lms_params_st { const char *digestname; /* One of SHA256, SHA256-192, or SHAKE256 */ uint32_t n; /* The Digest size (either 24 or 32), Useful for setting up SHAKE */ uint32_t h; /* The height of a LMS tree which is one of 5, 10, 15, 20, 25) */ - size_t bit_strength; } LMS_PARAMS; typedef struct lms_pub_key_st { @@ -157,10 +156,5 @@ int ossl_lms_pubkey_decode(const unsigned char *pub, size_t publen, LMS_KEY *lmskey); size_t ossl_lms_pubkey_length(const unsigned char *data, size_t datalen); -const uint8_t *ossl_lms_key_get_pub(const LMS_KEY *key); -size_t ossl_lms_key_get_pub_len(const LMS_KEY *key); -size_t ossl_lms_key_get_collision_strength_bits(const LMS_KEY *key); -size_t ossl_lms_key_get_sig_len(const LMS_KEY *key); - #endif /* OPENSSL_NO_LMS */ #endif /* OSSL_CRYPTO_LMS_H */ diff --git a/include/crypto/lms_util.h b/include/crypto/lms_util.h index 54aa51e17a..6bd6cfec81 100644 --- a/include/crypto/lms_util.h +++ b/include/crypto/lms_util.h @@ -9,16 +9,11 @@ /* @brief Internal LMS helper functions */ -#if !defined(OSSL_CRYPTO_LMS_UTIL_H) -#define OSSL_CRYPTO_LMS_UTIL_H - #include "internal/packet.h" #include #include #include -#include "crypto/lms.h" - /* * This LMS implementation assumes that the hash algorithm must be the same for * LMS params and OTS params. Since OpenSSL does not have a "SHAKE256-192" @@ -32,7 +27,9 @@ * See RFC 8554 Section 3.1.3: Strings of w-bit Elements * w: Is one of {1,2,4,8} */ -static ossl_unused ossl_inline uint8_t lms_ots_coef(const unsigned char *S, uint16_t i, uint8_t w) +static ossl_unused ossl_inline + uint8_t + lms_ots_coef(const unsigned char *S, uint16_t i, uint8_t w) { uint8_t bitmask = (1 << w) - 1; uint8_t shift = 8 - (w * (i % (8 / w)) + w); @@ -55,5 +52,3 @@ static ossl_unused ossl_inline int lms_evp_md_ctx_init(EVP_MD_CTX *ctx, const EV } return EVP_DigestInit_ex2(ctx, md, p); } - -#endif /* !defined(OSSL_CRYPTO_LMS_UTIL_H) */ diff --git a/include/crypto/md32_common.inc b/include/crypto/md32_common.h similarity index 86% rename from include/crypto/md32_common.inc rename to include/crypto/md32_common.h index 3dea481c56..9ad2e328bd 100644 --- a/include/crypto/md32_common.inc +++ b/include/crypto/md32_common.h @@ -1,5 +1,5 @@ /* - * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -104,7 +104,7 @@ #define ROTATE(a, n) (((a) << (n)) | (((a) & 0xffffffff) >> (32 - (n)))) #ifndef PEDANTIC -#if defined(__GNUC__) && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM) +#if defined(__GNUC__) && __GNUC__ >= 2 && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM) #if defined(__riscv_zbb) || defined(__riscv_zbkb) #if __riscv_xlen == 64 #undef ROTATE @@ -154,16 +154,8 @@ * Time for some action :-) */ -#ifdef HASH_UPDATE_THUNK -int HASH_UPDATE(void *cp, const unsigned char *data_, size_t len); -int HASH_UPDATE(void *cp, const unsigned char *data_, size_t len) -#else int HASH_UPDATE(HASH_CTX *c, const void *data_, size_t len) -#endif { -#ifdef HASH_UPDATE_THUNK - HASH_CTX *c = (HASH_CTX *)cp; -#endif const unsigned char *data = data_; unsigned char *p; HASH_LONG l; @@ -181,14 +173,9 @@ int HASH_UPDATE(HASH_CTX *c, const void *data_, size_t len) n = c->num; if (ossl_likely(n != 0)) { - /* Gets here if we already have buffered input data */ p = (unsigned char *)c->data; if (len >= HASH_CBLOCK || len + n >= HASH_CBLOCK) { - /* - * If there is enough input to fill the buffer then fill the - * buffer and process a single chunk. - */ memcpy(p + n, data, HASH_CBLOCK - n); HASH_BLOCK_DATA_ORDER(c, p, 1); n = HASH_CBLOCK - n; @@ -203,22 +190,20 @@ int HASH_UPDATE(HASH_CTX *c, const void *data_, size_t len) */ memset(p, 0, HASH_CBLOCK); /* keep it zeroed */ } else { - /* Otherwise just keep filling the buffer */ memcpy(p + n, data, len); c->num += (unsigned int)len; return 1; } } - n = len / HASH_CBLOCK; /* Get number of input chunks (e.g. multiple of 512 bits for SHA256) */ + n = len / HASH_CBLOCK; if (n > 0) { - /* Process chunks */ HASH_BLOCK_DATA_ORDER(c, data, n); n *= HASH_CBLOCK; data += n; len -= n; } - /* Buffer any left over data */ + if (len != 0) { p = (unsigned char *)c->data; c->num = (unsigned int)len; @@ -229,7 +214,7 @@ int HASH_UPDATE(HASH_CTX *c, const void *data_, size_t len) void HASH_TRANSFORM(HASH_CTX *c, const unsigned char *data) { - HASH_BLOCK_DATA_ORDER(c, data, 1); /* Process a single chunk */ + HASH_BLOCK_DATA_ORDER(c, data, 1); } int HASH_FINAL(unsigned char *md, HASH_CTX *c) @@ -237,26 +222,16 @@ int HASH_FINAL(unsigned char *md, HASH_CTX *c) unsigned char *p = (unsigned char *)c->data; size_t n = c->num; - /* - * Pad the input by adding a 1 bit + K zero bits + input length (L) - * as a 64 bit value. K must align the data to a chunk boundary. - */ p[n] = 0x80; /* there is always room for one */ n++; if (n > (HASH_CBLOCK - 8)) { - /* - * If there is not enough room in the buffer to add L, then fill the - * current buffer with zeros, and process the chunk - */ memset(p + n, 0, HASH_CBLOCK - n); n = 0; HASH_BLOCK_DATA_ORDER(c, p, 1); } - /* Add zero padding - but leave enough room for L */ memset(p + n, 0, HASH_CBLOCK - 8 - n); - /* Add the 64 bit L value to the end of the buffer */ p += HASH_CBLOCK - 8; #if defined(DATA_ORDER_IS_BIG_ENDIAN) (void)HOST_l2c(c->Nh, p); @@ -266,7 +241,6 @@ int HASH_FINAL(unsigned char *md, HASH_CTX *c) (void)HOST_l2c(c->Nh, p); #endif p -= HASH_CBLOCK; - /* Process the final padded chunk */ HASH_BLOCK_DATA_ORDER(c, p, 1); c->num = 0; OPENSSL_cleanse(p, HASH_CBLOCK); diff --git a/include/crypto/ml_dsa.h b/include/crypto/ml_dsa.h index 831a6740a1..41a882c76d 100644 --- a/include/crypto/ml_dsa.h +++ b/include/crypto/ml_dsa.h @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -80,7 +80,6 @@ __owur ML_DSA_KEY *ossl_ml_dsa_key_new(OSSL_LIB_CTX *libctx, const char *propq, int evp_type); /* Factory reset for keys that fail initialisation */ void ossl_ml_dsa_key_reset(ML_DSA_KEY *key); -__owur int ossl_ml_dsa_key_fetch_digests(ML_DSA_KEY *key, const char *propq); __owur int ossl_ml_dsa_key_pub_alloc(ML_DSA_KEY *key); __owur int ossl_ml_dsa_key_priv_alloc(ML_DSA_KEY *key); void ossl_ml_dsa_key_free(ML_DSA_KEY *key); @@ -110,11 +109,7 @@ __owur int ossl_ml_dsa_key_public_from_private(ML_DSA_KEY *key); __owur int ossl_ml_dsa_pk_decode(ML_DSA_KEY *key, const uint8_t *in, size_t in_len); __owur int ossl_ml_dsa_sk_decode(ML_DSA_KEY *key, const uint8_t *in, size_t in_len); -__owur EVP_MD_CTX *ossl_ml_dsa_mu_init(const ML_DSA_KEY *key, int encode, - const uint8_t *ctx, size_t ctx_len); - -__owur EVP_MD_CTX *ossl_ml_dsa_mu_init_int(EVP_MD *shake256_md, - const uint8_t *tr, size_t tr_len, int encode, int prehash, +EVP_MD_CTX *ossl_ml_dsa_mu_init(const ML_DSA_KEY *key, int encode, const uint8_t *ctx, size_t ctx_len); __owur int ossl_ml_dsa_mu_update(EVP_MD_CTX *md_ctx, const uint8_t *msg, size_t msg_len); __owur int ossl_ml_dsa_mu_finalize(EVP_MD_CTX *md_ctx, uint8_t *mu, size_t mu_len); diff --git a/include/crypto/ml_kem.h b/include/crypto/ml_kem.h index 7d1f3cd602..390144a473 100644 --- a/include/crypto/ml_kem.h +++ b/include/crypto/ml_kem.h @@ -231,8 +231,6 @@ void ossl_ml_kem_key_free(ML_KEM_KEY *key); */ ML_KEM_KEY *ossl_ml_kem_key_dup(const ML_KEM_KEY *key, int selection); -__owur int ossl_ml_kem_key_fetch_digest(ML_KEM_KEY *key, const char *propq); - /* * ----- Import or generate key material. */ diff --git a/include/crypto/modes.h b/include/crypto/modes.h index baa0f3a6c1..918d4e04b5 100644 --- a/include/crypto/modes.h +++ b/include/crypto/modes.h @@ -8,21 +8,25 @@ */ /* This header can move into provider when legacy support is removed */ -#if !defined(OSSL_CRYPTO_MODES_H) -#define OSSL_CRYPTO_MODES_H - -#include - #include #if (defined(_WIN32) || defined(_WIN64)) && !defined(__MINGW32__) +typedef __int64 i64; +typedef unsigned __int64 u64; #define U64(C) C##UI64 #elif defined(__arch64__) +typedef long i64; +typedef unsigned long u64; #define U64(C) C##UL #else +typedef long long i64; +typedef unsigned long long u64; #define U64(C) C##ULL #endif +typedef unsigned int u32; +typedef unsigned char u8; + #define STRICT_ALIGNMENT 1 #ifndef PEDANTIC #if defined(__i386) || defined(__i386__) || defined(__x86_64) || defined(__x86_64__) || defined(_M_IX86) || defined(_M_AMD64) || defined(_M_X64) || defined(__aarch64__) || defined(__s390__) || defined(__s390x__) @@ -31,45 +35,45 @@ #endif #if !defined(PEDANTIC) && !defined(OPENSSL_NO_ASM) && !defined(OPENSSL_NO_INLINE_ASM) -#if defined(__GNUC__) +#if defined(__GNUC__) && __GNUC__ >= 2 #if defined(__x86_64) || defined(__x86_64__) -#define BSWAP8(x) ({ uint64_t ret_=(x); \ +#define BSWAP8(x) ({ u64 ret_=(x); \ asm ("bswapq %0" \ : "+r"(ret_)); ret_; }) -#define BSWAP4(x) ({ uint32_t ret_=(x); \ +#define BSWAP4(x) ({ u32 ret_=(x); \ asm ("bswapl %0" \ : "+r"(ret_)); ret_; }) #elif (defined(__i386) || defined(__i386__)) && !defined(I386_ONLY) -#define BSWAP8(x) ({ uint32_t lo_=(uint64_t)(x)>>32,hi_=(x); \ +#define BSWAP8(x) ({ u32 lo_=(u64)(x)>>32,hi_=(x); \ asm ("bswapl %0; bswapl %1" \ : "+r"(hi_),"+r"(lo_)); \ - (uint64_t)hi_<<32|lo_; }) -#define BSWAP4(x) ({ uint32_t ret_=(x); \ + (u64)hi_<<32|lo_; }) +#define BSWAP4(x) ({ u32 ret_=(x); \ asm ("bswapl %0" \ : "+r"(ret_)); ret_; }) #elif defined(__aarch64__) #if defined(__BYTE_ORDER__) && defined(__ORDER_LITTLE_ENDIAN__) && __BYTE_ORDER__ == __ORDER_LITTLE_ENDIAN__ -#define BSWAP8(x) ({ uint64_t ret_; \ +#define BSWAP8(x) ({ u64 ret_; \ asm ("rev %0,%1" \ : "=r"(ret_) : "r"(x)); ret_; }) -#define BSWAP4(x) ({ uint32_t ret_; \ +#define BSWAP4(x) ({ u32 ret_; \ asm ("rev %w0,%w1" \ : "=r"(ret_) : "r"(x)); ret_; }) #endif #elif (defined(__arm__) || defined(__arm)) && !defined(STRICT_ALIGNMENT) -#define BSWAP8(x) ({ uint32_t lo_=(uint64_t)(x)>>32,hi_=(x); \ +#define BSWAP8(x) ({ u32 lo_=(u64)(x)>>32,hi_=(x); \ asm ("rev %0,%0; rev %1,%1" \ : "+r"(hi_),"+r"(lo_)); \ - (uint64_t)hi_<<32|lo_; }) -#define BSWAP4(x) ({ uint32_t ret_; \ + (u64)hi_<<32|lo_; }) +#define BSWAP4(x) ({ u32 ret_; \ asm ("rev %0,%1" \ - : "=r"(ret_) : "r"((uint32_t)(x))); \ + : "=r"(ret_) : "r"((u32)(x))); \ ret_; }) #elif (defined(__riscv_zbb) || defined(__riscv_zbkb)) && __riscv_xlen == 64 -#define BSWAP8(x) ({ uint64_t ret_=(x); \ +#define BSWAP8(x) ({ u64 ret_=(x); \ asm ("rev8 %0,%0" \ : "+r"(ret_)); ret_; }) -#define BSWAP4(x) ({ uint32_t ret_=(x); \ +#define BSWAP4(x) ({ u32 ret_=(x); \ asm ("rev8 %0,%0; srli %0,%0,32"\ : "+&r"(ret_)); ret_; }) #endif @@ -77,10 +81,10 @@ #if _MSC_VER >= 1300 #include #pragma intrinsic(_byteswap_uint64, _byteswap_ulong) -#define BSWAP8(x) _byteswap_uint64((uint64_t)(x)) -#define BSWAP4(x) _byteswap_ulong((uint32_t)(x)) +#define BSWAP8(x) _byteswap_uint64((u64)(x)) +#define BSWAP4(x) _byteswap_ulong((u32)(x)) #elif defined(_M_IX86) -__inline uint32_t _bswap4(uint32_t val) { +__inline u32 _bswap4(u32 val) { _asm mov eax, val _asm bswap eax } #define BSWAP4(x) _bswap4(x) @@ -88,19 +92,19 @@ __inline uint32_t _bswap4(uint32_t val) { #endif #endif #if defined(BSWAP4) && !defined(STRICT_ALIGNMENT) -#define GETU32(p) BSWAP4(*(const uint32_t *)(p)) -#define PUTU32(p, v) *(uint32_t *)(p) = BSWAP4(v) +#define GETU32(p) BSWAP4(*(const u32 *)(p)) +#define PUTU32(p, v) *(u32 *)(p) = BSWAP4(v) #else -#define GETU32(p) ((uint32_t)(p)[0] << 24 | (uint32_t)(p)[1] << 16 | (uint32_t)(p)[2] << 8 | (uint32_t)(p)[3]) -#define PUTU32(p, v) ((p)[0] = (uint8_t)((v) >> 24), (p)[1] = (uint8_t)((v) >> 16), (p)[2] = (uint8_t)((v) >> 8), (p)[3] = (uint8_t)(v)) +#define GETU32(p) ((u32)(p)[0] << 24 | (u32)(p)[1] << 16 | (u32)(p)[2] << 8 | (u32)(p)[3]) +#define PUTU32(p, v) ((p)[0] = (u8)((v) >> 24), (p)[1] = (u8)((v) >> 16), (p)[2] = (u8)((v) >> 8), (p)[3] = (u8)(v)) #endif /*- GCM definitions */ typedef struct { - uint64_t hi, lo; + u64 hi, lo; } u128; -typedef void (*gcm_init_fn)(u128 Htable[16], const uint64_t H[2]); -typedef void (*gcm_ghash_fn)(uint64_t Xi[2], const u128 Htable[16], const uint8_t *inp, size_t len); -typedef void (*gcm_gmult_fn)(uint64_t Xi[2], const u128 Htable[16]); +typedef void (*gcm_init_fn)(u128 Htable[16], const u64 H[2]); +typedef void (*gcm_ghash_fn)(u64 Xi[2], const u128 Htable[16], const u8 *inp, size_t len); +typedef void (*gcm_gmult_fn)(u64 Xi[2], const u128 Htable[16]); struct gcm_funcs_st { gcm_init_fn ginit; gcm_ghash_fn ghash; @@ -110,9 +114,9 @@ struct gcm_funcs_st { struct gcm128_context { /* Following 6 names follow names in GCM specification */ union { - uint64_t u[2]; - uint32_t d[4]; - uint8_t c[16]; + u64 u[2]; + u32 d[4]; + u8 c[16]; size_t t[16 / sizeof(size_t)]; } Yi, EKi, EK0, len, Xi, H; /* @@ -130,10 +134,10 @@ struct gcm128_context { }; /* GHASH functions */ -void ossl_gcm_init_4bit(u128 Htable[16], const uint64_t H[2]); -void ossl_gcm_ghash_4bit(uint64_t Xi[2], const u128 Htable[16], - const uint8_t *inp, size_t len); -void ossl_gcm_gmult_4bit(uint64_t Xi[2], const u128 Htable[16]); +void ossl_gcm_init_4bit(u128 Htable[16], const u64 H[2]); +void ossl_gcm_ghash_4bit(u64 Xi[2], const u128 Htable[16], + const u8 *inp, size_t len); +void ossl_gcm_gmult_4bit(u64 Xi[2], const u128 Htable[16]); /* * The maximum permitted number of cipher blocks per data unit in XTS mode. @@ -154,10 +158,10 @@ int ossl_crypto_xts128gb_encrypt(const XTS128_CONTEXT *ctx, struct ccm128_context { union { - uint64_t u[2]; - uint8_t c[16]; + u64 u[2]; + u8 c[16]; } nonce, cmac; - uint64_t blocks; + u64 blocks; block128_f block; void *key; }; @@ -165,7 +169,7 @@ struct ccm128_context { #ifndef OPENSSL_NO_OCB typedef union { - uint64_t a[2]; + u64 a[2]; unsigned char c[16]; } OCB_BLOCK; #define ocb_block16_xor(in1, in2, out) \ @@ -193,8 +197,8 @@ struct ocb128_context { OCB_BLOCK *l; /* Must be reset for each session */ struct { - uint64_t blocks_hashed; - uint64_t blocks_processed; + u64 blocks_hashed; + u64 blocks_processed; OCB_BLOCK offset_aad; OCB_BLOCK sum; OCB_BLOCK offset; @@ -225,5 +229,3 @@ struct siv128_context { }; #endif /* OPENSSL_NO_SIV */ - -#endif /* !defined(OSSL_CRYPTO_MODES_H) */ diff --git a/include/crypto/objects.h b/include/crypto/objects.h index 499c769dd0..f22e928772 100644 --- a/include/crypto/objects.h +++ b/include/crypto/objects.h @@ -7,11 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_CRYPTO_OBJECTS_H) -#define OSSL_CRYPTO_OBJECTS_H - #include void ossl_obj_cleanup_int(void); - -#endif /* !defined(OSSL_CRYPTO_OBJECTS_H) */ diff --git a/include/crypto/pkcs7.h b/include/crypto/pkcs7.h index 8d999fd44f..bf0e6bf607 100644 --- a/include/crypto/pkcs7.h +++ b/include/crypto/pkcs7.h @@ -11,8 +11,6 @@ #define OSSL_CRYPTO_PKCS7_H #pragma once -#include - void ossl_pkcs7_resolve_libctx(PKCS7 *p7); void ossl_pkcs7_set0_libctx(PKCS7 *p7, OSSL_LIB_CTX *ctx); diff --git a/include/arch/ppc_arch.h b/include/crypto/ppc_arch.h similarity index 100% rename from include/arch/ppc_arch.h rename to include/crypto/ppc_arch.h diff --git a/include/crypto/rand.h b/include/crypto/rand.h index 357ce885b7..4845c84a94 100644 --- a/include/crypto/rand.h +++ b/include/crypto/rand.h @@ -39,16 +39,6 @@ /* * Defines related to seed sources */ - -/* Name of the seed source used to seed the primary DRBG. */ -#ifndef OPENSSL_NO_FIPS_JITTER -#define OPENSSL_SEED_SRC_NAME "JITTER" -#elif defined(OPENSSL_DEFAULT_SEED_SRC) -#define OPENSSL_SEED_SRC_NAME OPENSSL_MSTR(OPENSSL_DEFAULT_SEED_SRC) -#else -#define OPENSSL_SEED_SRC_NAME "SEED-SRC" -#endif - #ifndef DEVRANDOM /* * set this to a comma-separated list of 'random' device files to try out. By diff --git a/include/arch/riscv_arch.def b/include/crypto/riscv_arch.def similarity index 100% rename from include/arch/riscv_arch.def rename to include/crypto/riscv_arch.def diff --git a/include/arch/riscv_arch.h b/include/crypto/riscv_arch.h similarity index 98% rename from include/arch/riscv_arch.h rename to include/crypto/riscv_arch.h index ddc36e58f1..9894b714d7 100644 --- a/include/arch/riscv_arch.h +++ b/include/crypto/riscv_arch.h @@ -11,7 +11,6 @@ #define OSSL_CRYPTO_RISCV_ARCH_H #include -#include #include #if defined(OPENSSL_SYS_LINUX) && !defined(FIPS_MODULE) @@ -28,7 +27,7 @@ extern unsigned int OPENSSL_riscv_hwcap_P; #define VECTOR_CAPABLE (OPENSSL_riscv_hwcap_P & COMPAT_HWCAP_ISA_V) #define ZVX_MIN 15 #define ZVX_MAX 23 -#define IS_IN_DEPEND_VECTOR(offset) ((ZVX_MIN <= offset) && (offset <= ZVX_MAX)) +#define IS_IN_DEPEND_VECTOR(offset) ((ZVX_MIN >= offset) && (offset <= ZVX_MAX)) #endif #endif #endif diff --git a/include/crypto/rsa.h b/include/crypto/rsa.h index 0b853f9a80..0c3fa8f895 100644 --- a/include/crypto/rsa.h +++ b/include/crypto/rsa.h @@ -137,7 +137,7 @@ int ossl_rsa_acvp_test_get_params(RSA *r, OSSL_PARAM params[]); typedef struct rsa_acvp_test_st RSA_ACVP_TEST; void ossl_rsa_acvp_test_free(RSA_ACVP_TEST *t); #else -typedef void RSA_ACVP_TEST; +#define RSA_ACVP_TEST void #endif int ossl_rsa_check_factors(RSA *r); diff --git a/include/crypto/security_bits.h b/include/crypto/security_bits.h index 8b42338a4d..56fe8d2573 100644 --- a/include/crypto/security_bits.h +++ b/include/crypto/security_bits.h @@ -11,8 +11,6 @@ #define OSSL_SECURITY_BITS_H #pragma once -#include - uint16_t ossl_ifc_ffc_compute_security_bits(int n); #endif diff --git a/include/crypto/sha.h b/include/crypto/sha.h index f2be474f9e..fed23f1a66 100644 --- a/include/crypto/sha.h +++ b/include/crypto/sha.h @@ -1,5 +1,5 @@ /* - * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2018-2023 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2018, Oracle and/or its affiliates. All rights reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -14,25 +14,10 @@ #include -#ifndef OPENSSL_NO_DEPRECATED_3_0 -/* This is inside a deprecated block because SHA256_CTX was marked deprecated */ int ossl_sha256_192_init(SHA256_CTX *c); int sha512_224_init(SHA512_CTX *); int sha512_256_init(SHA512_CTX *); int ossl_sha1_ctrl(SHA_CTX *ctx, int cmd, int mslen, void *ms); -#endif - unsigned char *ossl_sha1(const unsigned char *d, size_t n, unsigned char *md); -int ossl_sp800_185_right_encode(unsigned char *out, - size_t out_max_len, size_t *out_len, - size_t bits); -int ossl_sp800_185_encode_string(unsigned char *out, - size_t out_max_len, size_t *out_len, - const unsigned char *in, size_t in_len); -int ossl_sp800_185_bytepad(unsigned char *out, size_t out_len_max, size_t *out_len, - const unsigned char *in1, size_t in1_len, - const unsigned char *in2, size_t in2_len, - size_t w); - #endif diff --git a/include/crypto/siphash.h b/include/crypto/siphash.h index cb2f6de68f..3ffdc055e6 100644 --- a/include/crypto/siphash.h +++ b/include/crypto/siphash.h @@ -12,7 +12,6 @@ #pragma once #include -#include #define SIPHASH_BLOCK_SIZE 8 #define SIPHASH_KEY_SIZE 16 diff --git a/include/crypto/siv.h b/include/crypto/siv.h index d842baae49..b4f04a80c8 100644 --- a/include/crypto/siv.h +++ b/include/crypto/siv.h @@ -6,15 +6,9 @@ * in the file LICENSE in the source distribution or at * https://www.openssl.org/source/license.html */ -#if !defined(OPENSSL_CRYPTO_SIV_H) -#define OPENSSL_CRYPTO_SIV_H #ifndef OPENSSL_NO_SIV -#include - -#include - typedef struct siv128_context SIV128_CONTEXT; SIV128_CONTEXT *ossl_siv128_new(const unsigned char *key, int klen, @@ -37,4 +31,3 @@ int ossl_siv128_cleanup(SIV128_CONTEXT *ctx); int ossl_siv128_speed(SIV128_CONTEXT *ctx, int arg); #endif /* OPENSSL_NO_SIV */ -#endif /* !defined (OPENSSL_CRYPTO_SIV_H) */ diff --git a/include/crypto/slh_dsa.h b/include/crypto/slh_dsa.h index 041991bdcc..b8ad91fda2 100644 --- a/include/crypto/slh_dsa.h +++ b/include/crypto/slh_dsa.h @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -57,8 +57,6 @@ __owur int ossl_slh_dsa_key_type_matches(const SLH_DSA_KEY *key, const char *alg __owur SLH_DSA_HASH_CTX *ossl_slh_dsa_hash_ctx_new(const SLH_DSA_KEY *key); void ossl_slh_dsa_hash_ctx_free(SLH_DSA_HASH_CTX *ctx); __owur SLH_DSA_HASH_CTX *ossl_slh_dsa_hash_ctx_dup(const SLH_DSA_HASH_CTX *src); -__owur int ossl_slh_dsa_hash_ctx_prehash_pk_seed(SLH_DSA_HASH_CTX *ctx, - const uint8_t *pkseed, size_t n); __owur int ossl_slh_dsa_sign(SLH_DSA_HASH_CTX *slh_ctx, const uint8_t *msg, size_t msg_len, diff --git a/include/crypto/sm2.h b/include/crypto/sm2.h index 2830cf97d5..246d644c27 100644 --- a/include/crypto/sm2.h +++ b/include/crypto/sm2.h @@ -1,5 +1,5 @@ /* - * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2017-2021 The OpenSSL Project Authors. All Rights Reserved. * Copyright 2017 Ribose Inc. All Rights Reserved. * Ported from Ribose contributions from Botan. * @@ -22,6 +22,9 @@ int ossl_sm2_key_private_check(const EC_KEY *eckey); +/* The default user id as specified in GM/T 0009-2012 */ +#define SM2_DEFAULT_USERID "1234567812345678" + int ossl_sm2_compute_z_digest(uint8_t *out, const EVP_MD *digest, const uint8_t *id, diff --git a/include/crypto/sm4_platform.h b/include/crypto/sm4_platform.h index 48c9ff93cf..56e8604fd7 100644 --- a/include/crypto/sm4_platform.h +++ b/include/crypto/sm4_platform.h @@ -13,7 +13,7 @@ #if defined(OPENSSL_CPUID_OBJ) #if defined(__aarch64__) || defined(_M_ARM64) -#include "arch/arm_arch.h" +#include "arm_arch.h" extern unsigned int OPENSSL_arm_midr; static inline int vpsm4_capable(void) { @@ -37,7 +37,7 @@ static inline int vpsm4_ex_capable(void) #define HWSM4_ctr32_encrypt_blocks sm4_v8_ctr32_encrypt_blocks #elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 /* RV64 support */ -#include "arch/riscv_arch.h" +#include "riscv_arch.h" /* Zvksed extension (vector crypto SM4). */ int rv64i_zvksed_sm4_set_encrypt_key(const unsigned char *userKey, SM4_KEY *key); diff --git a/include/arch/sparc_arch.h b/include/crypto/sparc_arch.h similarity index 93% rename from include/arch/sparc_arch.h rename to include/crypto/sparc_arch.h index 6d47505ae9..8e72c3504f 100644 --- a/include/arch/sparc_arch.h +++ b/include/crypto/sparc_arch.h @@ -1,5 +1,5 @@ /* - * Copyright 2012-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2012-2021 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -79,14 +79,10 @@ #if defined(__arch64__) -/* clang-format off */ #define SPARC_LOAD_ADDRESS(SYM, reg) \ - setx SYM, %o7, reg; -/* clang-format on */ + setx SYM, % o7, reg; #define LDPTR ldx -/* clang-format off */ -#define SIZE_T_CC %xcc -/* clang-format on */ +#define SIZE_T_CC % xcc #define STACK_FRAME 192 #define STACK_BIAS 2047 #define STACK_7thARG (STACK_BIAS + 176) @@ -96,9 +92,7 @@ #define SPARC_LOAD_ADDRESS(SYM, reg) \ set SYM, reg; #define LDPTR ld -/* clang-format off */ -#define SIZE_T_CC %icc -/* clang-format on */ +#define SIZE_T_CC % icc #define STACK_FRAME 112 #define STACK_BIAS 0 #define STACK_7thARG 92 diff --git a/include/crypto/sparse_array.h b/include/crypto/sparse_array.h index d77a46ebfa..d2629000ee 100644 --- a/include/crypto/sparse_array.h +++ b/include/crypto/sparse_array.h @@ -22,8 +22,6 @@ extern "C" { #define DEFINE_SPARSE_ARRAY_OF_INTERNAL(type, ctype) \ SPARSE_ARRAY_OF(type); \ - typedef void (*sa_##type##_leaffunc)(ossl_uintmax_t idx, type *t); \ - typedef void (*sa_##type##_leaffunc_arg)(ossl_uintmax_t idx, type *t, void *arg); \ static ossl_unused ossl_inline SPARSE_ARRAY_OF(type) * ossl_sa_##type##_new(void) \ { \ return (SPARSE_ARRAY_OF(type) *)ossl_sa_new(); \ @@ -43,40 +41,20 @@ extern "C" { { \ return ossl_sa_num((OPENSSL_SA *)sa); \ } \ - static ossl_unused void \ - ossl_sa_##type##_doall_thunk(ossl_uintmax_t idx, void *leaf, void *arg) \ - { \ - sa_##type##_leaffunc fn = *(sa_##type##_leaffunc *)arg; \ - (*fn)(idx, (type *)leaf); \ - } \ static ossl_unused ossl_inline void \ ossl_sa_##type##_doall(const SPARSE_ARRAY_OF(type) * sa, \ void (*leaf)(ossl_uintmax_t, type *)) \ { \ - ossl_sa_doall_arg((OPENSSL_SA *)sa, ossl_sa_##type##_doall_thunk, &leaf); \ - } \ - struct ossl_sa_##type##_doall_thunk { \ - sa_##type##_leaffunc_arg fn; \ - void *arg; \ - }; \ - static ossl_unused void \ - ossl_sa_##type##_doall_arg_thunk(ossl_uintmax_t idx, void *leaf, void *arg) \ - { \ - struct ossl_sa_##type##_doall_thunk *t = arg; \ - \ - (*t->fn)(idx, (type *)leaf, t->arg); \ + ossl_sa_doall((OPENSSL_SA *)sa, \ + (void (*)(ossl_uintmax_t, void *))leaf); \ } \ static ossl_unused ossl_inline void \ ossl_sa_##type##_doall_arg(const SPARSE_ARRAY_OF(type) * sa, \ void (*leaf)(ossl_uintmax_t, type *, void *), \ void *arg) \ { \ - struct ossl_sa_##type##_doall_thunk t; \ - \ - t.fn = leaf; \ - t.arg = arg; \ ossl_sa_doall_arg((OPENSSL_SA *)sa, \ - ossl_sa_##type##_doall_arg_thunk, &t); \ + (void (*)(ossl_uintmax_t, void *, void *))leaf, arg); \ } \ static ossl_unused ossl_inline ctype *ossl_sa_##type##_get(const SPARSE_ARRAY_OF(type) * sa, ossl_uintmax_t n) \ { \ @@ -84,7 +62,7 @@ extern "C" { } \ static ossl_unused ossl_inline int \ ossl_sa_##type##_set(SPARSE_ARRAY_OF(type) * sa, \ - ossl_uintmax_t n, ctype *val) \ + ossl_uintmax_t n, ctype * val) \ { \ return ossl_sa_set((OPENSSL_SA *)sa, n, (void *)val); \ } \ diff --git a/include/crypto/x509.h b/include/crypto/x509.h index 4925131180..608b78dc15 100644 --- a/include/crypto/x509.h +++ b/include/crypto/x509.h @@ -1,5 +1,5 @@ /* - * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -14,12 +14,9 @@ #include "internal/refcount.h" #include #include -#include #include #include "crypto/types.h" -#include - /* Internal X509 structures and functions: not for application use */ /* Note: unless otherwise stated a field pointer is mandatory and should @@ -219,7 +216,7 @@ struct x509_store_ctx_st { /* X509_STORE_CTX */ X509_STORE *store; /* The following are set by the caller */ /* The cert to check */ - X509 *cert; /* XXX should really be made const */ + X509 *cert; /* chain of X509s - untrusted - passed in */ STACK_OF(X509) *untrusted; /* set of CRLs passed in */ @@ -234,9 +231,9 @@ struct x509_store_ctx_st { /* X509_STORE_CTX */ /* error callback */ int (*verify_cb)(int ok, X509_STORE_CTX *ctx); /* get issuers cert from ctx */ - X509_STORE_CTX_get_issuer_fn get_issuer; + int (*get_issuer)(X509 **issuer, X509_STORE_CTX *ctx, X509 *x); /* check issued */ - X509_STORE_CTX_check_issued_fn check_issued; + int (*check_issued)(X509_STORE_CTX *ctx, X509 *x, X509 *issuer); /* Check revocation status of chain */ int (*check_revocation)(X509_STORE_CTX *ctx); /* retrieve CRL */ @@ -247,7 +244,7 @@ struct x509_store_ctx_st { /* X509_STORE_CTX */ int (*cert_crl)(X509_STORE_CTX *ctx, X509_CRL *crl, X509 *x); /* Check policy status of the chain */ int (*check_policy)(X509_STORE_CTX *ctx); - STACK_OF(X509) *(*lookup_certs)(const X509_STORE_CTX *ctx, + STACK_OF(X509) *(*lookup_certs)(X509_STORE_CTX *ctx, const X509_NAME *nm); /* cannot constify 'ctx' param due to lookup_certs_sk() in x509_vfy.c */ STACK_OF(X509_CRL) *(*lookup_crls)(const X509_STORE_CTX *ctx, @@ -267,7 +264,7 @@ struct x509_store_ctx_st { /* X509_STORE_CTX */ /* When something goes wrong, this is why */ int error_depth; int error; - X509 *current_cert; /* XXX should really be made const */ + X509 *current_cert; /* cert currently being tested as valid issuer */ X509 *current_issuer; /* current CRL */ @@ -315,9 +312,9 @@ struct x509_object_st { int ossl_a2i_ipadd(unsigned char *ipout, const char *ipasc); int ossl_x509_set1_time(int *modified, ASN1_TIME **ptm, const ASN1_TIME *tm); -int ossl_x509_print_ex_brief(BIO *bio, const X509 *cert, unsigned long neg_cflags); -int ossl_x509v3_cache_extensions(const X509 *x); -int ossl_x509_init_sig_info(const X509 *x, X509_SIG_INFO *info); +int ossl_x509_print_ex_brief(BIO *bio, X509 *cert, unsigned long neg_cflags); +int ossl_x509v3_cache_extensions(X509 *x); +int ossl_x509_init_sig_info(X509 *x); int ossl_x509_set0_libctx(X509 *x, OSSL_LIB_CTX *libctx, const char *propq); int ossl_x509_crl_set0_libctx(X509_CRL *x, OSSL_LIB_CTX *libctx, @@ -327,12 +324,11 @@ int ossl_x509_req_set0_libctx(X509_REQ *x, OSSL_LIB_CTX *libctx, int ossl_asn1_item_digest_ex(const ASN1_ITEM *it, const EVP_MD *type, void *data, unsigned char *md, unsigned int *len, OSSL_LIB_CTX *libctx, const char *propq); -int ossl_x509_add_cert_new(STACK_OF(X509) **sk, const X509 *cert, int flags); -int ossl_x509_add_certs_new(STACK_OF(X509) **p_sk, const STACK_OF(X509) *certs, int flags); +int ossl_x509_add_cert_new(STACK_OF(X509) **sk, X509 *cert, int flags); +int ossl_x509_add_certs_new(STACK_OF(X509) **p_sk, STACK_OF(X509) *certs, + int flags); STACK_OF(X509_ATTRIBUTE) *ossl_x509at_dup(const STACK_OF(X509_ATTRIBUTE) *x); -STACK_OF(X509_EXTENSION) * -ossl_x509_req_get1_extensions_by_nid(const X509_REQ *req, int nid); int ossl_x509_PUBKEY_get0_libctx(OSSL_LIB_CTX **plibctx, const char **ppropq, const X509_PUBKEY *key); @@ -403,14 +399,12 @@ int ossl_serial_number_print(BIO *out, const ASN1_INTEGER *bs, int indent); int ossl_bio_print_hex(BIO *out, unsigned char *buf, int len); int ossl_x509_compare_asn1_time(const X509_VERIFY_PARAM *vpm, const ASN1_TIME *time, int *comparison); +int ossl_x509_check_certificate_times(const X509_VERIFY_PARAM *vpm, X509 *x, + int *error); /* No error callback if depth < 0 */ int ossl_x509_check_cert_time(X509_STORE_CTX *ctx, X509 *x, int depth); int ossl_x509_check_crl_time(X509_STORE_CTX *ctx, X509_CRL *crl, int notify); int ossl_posix_to_asn1_time(int64_t posix_time, ASN1_TIME **out_time); void ossl_x509_verify_param_set_time_posix(X509_VERIFY_PARAM *param, int64_t t); -int ossl_x509_check_host(const X509 *x, const char *chk, size_t chklen, - unsigned int flags, char **peername); -int ossl_x509_check_ip(const X509 *x, const unsigned char *chk, size_t chklen, - unsigned int flags); #endif /* OSSL_CRYPTO_X509_H */ diff --git a/include/crypto/x509_acert.h b/include/crypto/x509_acert.h index 0ee38db4cf..083133c8e3 100644 --- a/include/crypto/x509_acert.h +++ b/include/crypto/x509_acert.h @@ -1,5 +1,5 @@ /* - * Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -13,8 +13,6 @@ #include -#include - #define OSSL_ODI_TYPE_PUBLIC_KEY 0 #define OSSL_ODI_TYPE_PUBLIC_KEY_CERT 1 #define OSSL_ODI_TYPE_OTHER 2 diff --git a/include/crypto/x509err.h b/include/crypto/x509err.h index 45e62fa7da..4d4572861b 100644 --- a/include/crypto/x509err.h +++ b/include/crypto/x509err.h @@ -1,6 +1,6 @@ /* * Generated by util/mkerr.pl DO NOT EDIT - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2022 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy diff --git a/include/internal/bio.h b/include/internal/bio.h index 91a27b2218..1b71b24f51 100644 --- a/include/internal/bio.h +++ b/include/internal/bio.h @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2022 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -44,16 +44,6 @@ int bread_conv(BIO *bio, char *data, size_t datal, size_t *read); #define BIO_CTRL_CLEAR_KTLS_TX_CTRL_MSG 75 #define BIO_CTRL_SET_KTLS_TX_ZEROCOPY_SENDFILE 90 -/* Internal BIO flags */ - -#define BIO_FLAGS_AUTO_EOF 0x80 - -/* - * This is used with memory BIOs: - * BIO_FLAGS_MEM_LEGACY_EOF means legacy behaviour of BIO_eof() - */ -#define BIO_FLAGS_MEM_LEGACY_EOF 0x1000 - /* * This is used with socket BIOs: * BIO_FLAGS_KTLS_TX means we are using ktls with this BIO for sending. @@ -107,7 +97,7 @@ int ossl_core_bio_vprintf(OSSL_CORE_BIO *cb, const char *format, va_list args); int ossl_bio_init_core(OSSL_LIB_CTX *libctx, const OSSL_DISPATCH *fns); -#ifdef _MSC_VER +#ifdef _WIN32 int ossl_BIO_snprintf_msvc(char *buf, size_t n, const char *fmt, ...); #endif diff --git a/include/internal/bio_tfo.h b/include/internal/bio_tfo.h index 68b85b0ecc..bfce90afaf 100644 --- a/include/internal/bio_tfo.h +++ b/include/internal/bio_tfo.h @@ -13,9 +13,6 @@ */ /* If a supported OS is added here, update test/bio_tfo_test.c */ -#if !defined(OSSL_INTERNAL_BIO_TFO_H) -#define OSSL_INTERNAL_BIO_TFO_H - #if defined(TCP_FASTOPEN) && !defined(OPENSSL_NO_TFO) #if defined(OPENSSL_SYS_MACOSX) || defined(__FreeBSD__) @@ -152,5 +149,3 @@ #endif #endif - -#endif /* !defined(OSSL_INTERNAL_BIO_TFO_H) */ diff --git a/include/internal/common.h b/include/internal/common.h index 6e72a7ecec..d709b78c22 100644 --- a/include/internal/common.h +++ b/include/internal/common.h @@ -27,15 +27,12 @@ #endif #if defined(__GNUC__) || defined(__clang__) -#define ALIGN16 __attribute((aligned(16))) #define ALIGN32 __attribute((aligned(32))) #define ALIGN64 __attribute((aligned(64))) #elif defined(_MSC_VER) -#define ALIGN16 __declspec(align(16)) #define ALIGN32 __declspec(align(32)) #define ALIGN64 __declspec(align(64)) #else -#define ALIGN16 #define ALIGN32 #define ALIGN64 #endif @@ -109,6 +106,7 @@ __owur static ossl_inline int ossl_assert_int(int expr, const char *exprstr, l |= (((unsigned long)(*((c)++))) << 16), \ l |= (((unsigned long)(*((c)++))) << 24)) +/* NOTE - c is not incremented as per c2l */ #define c2ln(c, l1, l2, n) \ { \ c += n; \ @@ -116,25 +114,18 @@ __owur static ossl_inline int ossl_assert_int(int expr, const char *exprstr, switch (n) { \ case 8: \ l2 = ((unsigned long)(*(--(c)))) << 24; \ - /* fall through */ \ case 7: \ l2 |= ((unsigned long)(*(--(c)))) << 16; \ - /* fall through */ \ case 6: \ l2 |= ((unsigned long)(*(--(c)))) << 8; \ - /* fall through */ \ case 5: \ l2 |= ((unsigned long)(*(--(c)))); \ - /* fall through */ \ case 4: \ l1 = ((unsigned long)(*(--(c)))) << 24; \ - /* fall through */ \ case 3: \ l1 |= ((unsigned long)(*(--(c)))) << 16; \ - /* fall through */ \ case 2: \ l1 |= ((unsigned long)(*(--(c)))) << 8; \ - /* fall through */ \ case 1: \ l1 |= ((unsigned long)(*(--(c)))); \ } \ @@ -159,37 +150,6 @@ __owur static ossl_inline int ossl_assert_int(int expr, const char *exprstr, l |= ((uint64_t)(*((c)++))) << 8, \ l |= ((uint64_t)(*((c)++)))) -#define n2ln(c, l1, l2, n) \ - { \ - c += n; \ - l1 = l2 = 0; \ - switch (n) { \ - case 8: \ - l2 = ((unsigned long)(*(--(c)))); \ - /* fall through */ \ - case 7: \ - l2 |= ((unsigned long)(*(--(c)))) << 8; \ - /* fall through */ \ - case 6: \ - l2 |= ((unsigned long)(*(--(c)))) << 16; \ - /* fall through */ \ - case 5: \ - l2 |= ((unsigned long)(*(--(c)))) << 24; \ - /* fall through */ \ - case 4: \ - l1 = ((unsigned long)(*(--(c)))); \ - /* fall through */ \ - case 3: \ - l1 |= ((unsigned long)(*(--(c)))) << 8; \ - /* fall through */ \ - case 2: \ - l1 |= ((unsigned long)(*(--(c)))) << 16; \ - /* fall through */ \ - case 1: \ - l1 |= ((unsigned long)(*(--(c)))) << 24; \ - } \ - } - #define l2n(l, c) (*((c)++) = (unsigned char)(((l) >> 24) & 0xff), \ *((c)++) = (unsigned char)(((l) >> 16) & 0xff), \ *((c)++) = (unsigned char)(((l) >> 8) & 0xff), \ @@ -204,62 +164,25 @@ __owur static ossl_inline int ossl_assert_int(int expr, const char *exprstr, *((c)++) = (unsigned char)(((l) >> 8) & 0xff), \ *((c)++) = (unsigned char)(((l)) & 0xff)) -/* NOTE - c is not incremented as per l2n */ -#define l2nn(l1, l2, c, n) \ - { \ - c += n; \ - switch (n) { \ - case 8: \ - *(--(c)) = (unsigned char)(((l2)) & 0xff); \ - /* fall through */ \ - case 7: \ - *(--(c)) = (unsigned char)(((l2) >> 8) & 0xff); \ - /* fall through */ \ - case 6: \ - *(--(c)) = (unsigned char)(((l2) >> 16) & 0xff); \ - /* fall through */ \ - case 5: \ - *(--(c)) = (unsigned char)(((l2) >> 24) & 0xff); \ - /* fall through */ \ - case 4: \ - *(--(c)) = (unsigned char)(((l1)) & 0xff); \ - /* fall through */ \ - case 3: \ - *(--(c)) = (unsigned char)(((l1) >> 8) & 0xff); \ - /* fall through */ \ - case 2: \ - *(--(c)) = (unsigned char)(((l1) >> 16) & 0xff); \ - /* fall through */ \ - case 1: \ - *(--(c)) = (unsigned char)(((l1) >> 24) & 0xff); \ - } \ - } - +/* NOTE - c is not incremented as per l2c */ #define l2cn(l1, l2, c, n) \ { \ c += n; \ switch (n) { \ case 8: \ *(--(c)) = (unsigned char)(((l2) >> 24) & 0xff); \ - /* fall through */ \ case 7: \ *(--(c)) = (unsigned char)(((l2) >> 16) & 0xff); \ - /* fall through */ \ case 6: \ *(--(c)) = (unsigned char)(((l2) >> 8) & 0xff); \ - /* fall through */ \ case 5: \ *(--(c)) = (unsigned char)(((l2)) & 0xff); \ - /* fall through */ \ case 4: \ *(--(c)) = (unsigned char)(((l1) >> 24) & 0xff); \ - /* fall through */ \ case 3: \ *(--(c)) = (unsigned char)(((l1) >> 16) & 0xff); \ - /* fall through */ \ case 2: \ *(--(c)) = (unsigned char)(((l1) >> 8) & 0xff); \ - /* fall through */ \ case 1: \ *(--(c)) = (unsigned char)(((l1)) & 0xff); \ } \ diff --git a/include/internal/constant_time.h b/include/internal/constant_time.h index ddb15d7b6f..34f2b78329 100644 --- a/include/internal/constant_time.h +++ b/include/internal/constant_time.h @@ -146,7 +146,7 @@ static ossl_inline uint64_t constant_time_lt_64(uint64_t a, uint64_t b) return constant_time_msb_64(a ^ ((a ^ b) | ((a - b) ^ b))); } -#ifdef BN_BYTES +#ifdef BN_ULONG static ossl_inline BN_ULONG value_barrier_bn(BN_ULONG a) { #if !defined(OPENSSL_NO_ASM) && defined(__GNUC__) @@ -477,73 +477,4 @@ static ossl_inline void constant_time_lookup(void *out, */ void err_clear_last_constant_time(int clear); -/* - * Return whether a value that can only be 0 or 1 is non-zero, in constant time - * in practice! The return value is a mask that is all ones if true, and all - * zeros otherwise (twos-complement arithmetic assumed for unsigned values). - * - * Although this is used in constant-time selects, we omit a value barrier - * here. Value barriers impede auto-vectorization (likely because it forces - * the value to transit through a general-purpose register). On AArch64, this - * is a difference of 2x. - * - * We usually add value barriers to selects because Clang turns consecutive - * selects with the same condition into a branch instead of CMOV/CSEL. - * Omitting it seems to be safe so far (David Benjamin, Chromium). This is - * used in the |reduce_once| functions in ML-KEM and ML-DSA in BoringSSL, and - * is now also used in OpenSSL. Any use in new contexts requires careful prior - * evaluation and should otherwise be avoided. - */ -#if 0 -#define constish_time_true(b) (~constant_time_is_zero(b)); -#else -#define constish_time_true(b) (0u - (b)) -#endif - -/* - * Valgrind-based constant-time validation helpers. - * - * CONSTTIME_SECRET marks a region of memory as secret. Valgrind's memcheck - * tool will then flag any control-flow branch or memory index that depends on - * those bytes as an error, because the branch/index would vary with the secret - * and could therefore leak it via a timing side-channel. - * - * CONSTTIME_DECLASSIFY marks a region as no longer secret. Call this: - * - on values that are derived from, but do not expose, secret data (e.g. - * the rejection decision in ML-DSA, or the public outputs of a KEM), and - * - on all secret regions before returning from a function, so that callers - * do not inherit spurious "uninitialised" state from Valgrind's perspective. - * - * Both macros are no-ops unless the library is built with - * enable-ct-validation (which defines OPENSSL_CONSTANT_TIME_VALIDATION and - * requires valgrind headers at build time). - */ -#if defined(OPENSSL_CONSTANT_TIME_VALIDATION) -#include -#define CONSTTIME_SECRET(ptr, len) VALGRIND_MAKE_MEM_UNDEFINED((ptr), (len)) -#define CONSTTIME_DECLASSIFY(ptr, len) VALGRIND_MAKE_MEM_DEFINED((ptr), (len)) -#else -#define CONSTTIME_SECRET(ptr, len) -#define CONSTTIME_DECLASSIFY(ptr, len) -#endif - -static ossl_inline uint32_t constant_time_declassify_u32(uint32_t v) -{ - /* - * Return |v| through a value barrier to be safe. Valgrind-based - * constant-time validation is partly to check the compiler has not undone - * any constant-time work. Any place |OPENSSL_CONSTANT_TIME_VALIDATION| - * influences optimizations, this validation is inaccurate. - * - * However, by sending pointers through valgrind, we likely inhibit escape - * analysis. On local variables, particularly booleans, we likely - * significantly impact optimizations. - * - * Thus, to be safe, stick a value barrier, in hopes of comparably - * inhibiting compiler analysis. - */ - CONSTTIME_DECLASSIFY(&v, sizeof(v)); - return value_barrier_32(v); -} - #endif /* OSSL_INTERNAL_CONSTANT_TIME_H */ diff --git a/include/internal/core.h b/include/internal/core.h index 33a16395e2..98fc4681d8 100644 --- a/include/internal/core.h +++ b/include/internal/core.h @@ -12,7 +12,6 @@ #pragma once #include -#include /* * namespaces: @@ -44,7 +43,7 @@ typedef struct ossl_method_construct_method_st { const char *name, const char *propdef, void *data); /* Construct a new method */ void *(*construct)(const OSSL_ALGORITHM *algodef, OSSL_PROVIDER *prov, - void *data, int no_store); + void *data); /* Destruct a method */ void (*destruct)(void *method, void *data); } OSSL_METHOD_CONSTRUCT_METHOD; diff --git a/include/internal/cryptlib.h b/include/internal/cryptlib.h index 0dcc6b6acd..a21172f86f 100644 --- a/include/internal/cryptlib.h +++ b/include/internal/cryptlib.h @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -46,6 +46,7 @@ int openssl_get_fork_id(void); char *ossl_safe_getenv(const char *name); +extern CRYPTO_RWLOCK *memdbg_lock; int openssl_strerror_r(int errnum, char *buf, size_t buflen); #if !defined(OPENSSL_NO_STDIO) FILE *openssl_fopen(const char *filename, const char *mode); @@ -117,12 +118,11 @@ typedef struct ossl_ex_data_global_st { #define OSSL_LIB_CTX_DECODER_CACHE_INDEX 20 #define OSSL_LIB_CTX_COMP_METHODS 21 #define OSSL_LIB_CTX_INDICATOR_CB_INDEX 22 +#define OSSL_LIB_CTX_MAX_INDEXES 22 #define OSSL_LIB_CTX_SSL_CONF_IMODULE 23 -#define OSSL_LIB_CTX_MAX_INDEXES 23 OSSL_LIB_CTX *ossl_lib_ctx_get_concrete(OSSL_LIB_CTX *ctx); int ossl_lib_ctx_is_default(OSSL_LIB_CTX *ctx); -int ossl_lib_ctx_is_default_nocreate(OSSL_LIB_CTX *ctx); int ossl_lib_ctx_is_global_default(OSSL_LIB_CTX *ctx); /* Functions to retrieve pointers to data by index */ @@ -133,6 +133,7 @@ OSSL_EX_DATA_GLOBAL *ossl_lib_ctx_get_ex_data_global(OSSL_LIB_CTX *ctx); const char *ossl_lib_ctx_get_descriptor(OSSL_LIB_CTX *libctx); +OSSL_LIB_CTX *ossl_crypto_ex_data_get_ossl_lib_ctx(const CRYPTO_EX_DATA *ad); int ossl_crypto_new_ex_data_ex(OSSL_LIB_CTX *ctx, int class_index, void *obj, CRYPTO_EX_DATA *ad); int ossl_crypto_get_ex_new_index_ex(OSSL_LIB_CTX *ctx, int class_index, @@ -151,12 +152,11 @@ int ossl_crypto_free_ex_index_ex(OSSL_LIB_CTX *ctx, int class_index, int idx); const void *ossl_bsearch(const void *key, const void *base, int num, int size, int (*cmp)(const void *, const void *), - int (*cmp_thunk)(int (*real_cmp_fn)(const void *, const void *), const void *, const void *), int flags); char *ossl_sk_ASN1_UTF8STRING2text(STACK_OF(ASN1_UTF8STRING) *text, const char *sep, size_t max_len); -char *ossl_ipaddr_to_asc(const unsigned char *p, int len); +char *ossl_ipaddr_to_asc(unsigned char *p, int len); char *ossl_buf2hexstr_sep(const unsigned char *buf, long buflen, char sep); unsigned char *ossl_hexstr2buf_sep(const char *str, long *buflen, diff --git a/include/internal/dane.h b/include/internal/dane.h index 8df761facf..9c040eedc6 100644 --- a/include/internal/dane.h +++ b/include/internal/dane.h @@ -11,7 +11,6 @@ #define OSSL_INTERNAL_DANE_H #pragma once -#include #include /*- diff --git a/include/internal/e_os.h b/include/internal/e_os.h index 444f888674..d287d91055 100644 --- a/include/internal/e_os.h +++ b/include/internal/e_os.h @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -83,41 +83,31 @@ #endif #ifdef WINDOWS -#if !defined(_WIN32_WINNT) +#if !defined(_WIN32_WCE) && !defined(_WIN32_WINNT) /* - * The _WIN32_WINNT is described here: - * https://learn.microsoft.com/en-us/cpp/porting/modifying-winver-and-win32-winnt?view=msvc-170 - * In a nutshell the macro defines minimal required Windows version where - * the resulting application is guaranteed to run on. If left undefined here, - * then the definition is provided by the Windows SDK found on host where - * application is being built. - * - * OpenSSL defaults to version 0x501, which matches Windows XP, meaning the - * compiled library will use APIs available on Windows XP and later. User may - * override the version specified here at build time using command as - * follows: - * perl ./Configure "-D_WIN32_WINNT=0x...." ... - * - * The list of recognized constants (as found in the link above) is as follows: - * 0x0400 // Windows NT 4.0 - * 0x0500 // Windows 2000 - * 0x0501 // Windows XP - * 0x0502 // Windows Server 2003 - * 0x0600 // Windows Vista, Windows Server 2008, Windows Vista - * 0x0601 // Windows 7 - * 0x0602 // Windows 8 - * 0x0603 // Windows 8.1 - * 0x0A00 // Windows 10 + * Defining _WIN32_WINNT here in e_os.h implies certain "discipline." + * Most notably we ought to check for availability of each specific + * routine that was introduced after denoted _WIN32_WINNT with + * GetProcAddress(). Normally newer functions are masked with higher + * _WIN32_WINNT in SDK headers. So that if you wish to use them in + * some module, you'd need to override _WIN32_WINNT definition in + * the target module in order to "reach for" prototypes, but replace + * calls to new functions with indirect calls. Alternatively it + * might be possible to achieve the goal by /DELAYLOAD-ing .DLLs + * and check for current OS version instead. */ -#define _WIN32_WINNT 0x0600 +#define _WIN32_WINNT 0x0501 #endif #include #include #include #include +#if defined(_WIN32_WCE) && !defined(EACCES) +#define EACCES 13 +#endif #include #include -#if defined(_MSC_VER) && !defined(_DLL) && defined(stdin) +#if defined(_MSC_VER) && !defined(_WIN32_WCE) && !defined(_DLL) && defined(stdin) #if _MSC_VER >= 1300 && _MSC_VER < 1600 #undef stdin #undef stdout @@ -133,6 +123,10 @@ FILE *__iob_func(void); #include #include +#ifdef OPENSSL_SYS_WINCE +#define OPENSSL_NO_POSIX_IO +#endif + #define EXIT(n) exit(n) #define LIST_SEPARATOR_CHAR ';' #ifndef W_OK @@ -141,7 +135,11 @@ FILE *__iob_func(void); #ifndef R_OK #define R_OK 4 #endif +#ifdef OPENSSL_SYS_WINCE +#define DEFAULT_HOME "" +#else #define DEFAULT_HOME "C:" +#endif /* Avoid Visual Studio 13 GetVersion deprecated problems */ #if defined(_MSC_VER) && _MSC_VER >= 1800 @@ -221,7 +219,7 @@ FILE *__iob_func(void); /***********************************************/ #if defined(OPENSSL_SYS_WINDOWS) -#if defined(_MSC_VER) && (_MSC_VER >= 1310) +#if defined(_MSC_VER) && (_MSC_VER >= 1310) && !defined(_WIN32_WCE) #define open _open #define fdopen _fdopen #define close _close @@ -245,7 +243,7 @@ FILE *__iob_func(void); #include #include -typedef int TTY_STRUCT; +#define TTY_STRUCT int #define sleep(a) taskDelay((a) * sysClkRateGet()) /* @@ -341,7 +339,7 @@ inline int nssgetpid(void) * There is no locale_t on NONSTOP. */ #if defined(OPENSSL_SYS_WINDOWS) -typedef _locale_t locale_t; +#define locale_t _locale_t #define freelocale _free_locale #define strcasecmp_l _stricmp_l #define strncasecmp_l _strnicmp_l @@ -355,48 +353,3 @@ typedef _locale_t locale_t; #endif #endif - -/* - * Can we use a global destructor? We can use a global destructor via - * __attribute__ on anything like a modern gcc/clang. We can also use - * it via dllmain on anything win32/win64. - * - * Older things may not do this. - * The assumption here is then if you don't have destructor support, - * it is safe to call OPENSSL_cleanup before an application exits - * because no library it is linked with will run code in a destructor - * that will call into OpenSSL after exit() happens. - * - */ -#if defined(OPENSSL_SYS_WIN32) || defined(OPENSSL_SYS_WIN64) -#define OSSL_CLEANUP_USING_DESTRUCTOR -#define OSSL_DLLMAIN_DESTRUCTOR -/* - * destructor will be installed in libcrypto's dllmain.c - * This means effectively anything not win16 or dos will handle - * this. - */ -void ossl_cleanup_destructor(void); -#else -#if defined(__has_attribute) -#if __has_attribute(destructor) -/* - * This seems to have been a thing with any gcc or clang since the - * early 2000's. So this could pretty much instead be just unconditional - * on __GNUC__ or __clang__. - */ -#define OSSL_CLEANUP_USING_DESTRUCTOR -/* destructor is installed by compiler */ -void ossl_cleanup_destructor(void) __attribute__((destructor)); -#else -/* We are not using a destructor */ -/* - * So we are on something that is not close to Windows or being - * compiled with a modern GCC/Clang derivative. either way - * this probably means something like a toolchain that is - * more than 20 years old. - */ -void ossl_cleanup_destructor(void); -#endif /* defined (__has_attribute(destructor) */ -#endif /* defined (__has_attribute) */ -#endif /* defined(OPENSSL_SYS_WIN32) || defined(OPENSSL_SYS_WIN64) */ diff --git a/include/internal/e_winsock.h b/include/internal/e_winsock.h index 1ea7383348..c2a08ebed1 100644 --- a/include/internal/e_winsock.h +++ b/include/internal/e_winsock.h @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -12,35 +12,22 @@ #pragma once #ifdef WINDOWS -#if !defined(_WIN32_WINNT) +#if !defined(_WIN32_WCE) && !defined(_WIN32_WINNT) /* - * The _WIN32_WINNT is described here: - * https://learn.microsoft.com/en-us/cpp/porting/modifying-winver-and-win32-winnt?view=msvc-170 - * In a nutshell the macro defines minimal required Windows version where - * the resulting application is guaranteed to run on. If left undefined here, - * then the definition is provided by the Windows SDK found on host where - * application is being built. - * - * OpenSSL defaults to version 0x501, which matches Windows XP, meaning the - * compiled library will use APIs available on Windows XP and later. User may - * override the version specified here at build time using command as - * follows: - * perl ./Configure "-D_WIN32_WINNT=0x...." ... - * - * The list of recognized constants (as found in the link above) is as follows: - * 0x0400 // Windows NT 4.0 - * 0x0500 // Windows 2000 - * 0x0501 // Windows XP - * 0x0502 // Windows Server 2003 - * 0x0600 // Windows Vista, Windows Server 2008, Windows Vista - * 0x0601 // Windows 7 - * 0x0602 // Windows 8 - * 0x0603 // Windows 8.1 - * 0x0A00 // Windows 10 + * Defining _WIN32_WINNT here in e_winsock.h implies certain "discipline." + * Most notably we ought to check for availability of each specific + * routine that was introduced after denoted _WIN32_WINNT with + * GetProcAddress(). Normally newer functions are masked with higher + * _WIN32_WINNT in SDK headers. So that if you wish to use them in + * some module, you'd need to override _WIN32_WINNT definition in + * the target module in order to "reach for" prototypes, but replace + * calls to new functions with indirect calls. Alternatively it + * might be possible to achieve the goal by /DELAYLOAD-ing .DLLs + * and check for current OS version instead. */ #define _WIN32_WINNT 0x0501 #endif -#if defined(_WIN32_WINNT) +#if defined(_WIN32_WINNT) || defined(_WIN32_WCE) /* * Just like defining _WIN32_WINNT including winsock2.h implies * certain "discipline" for maintaining [broad] binary compatibility. diff --git a/include/internal/ech_helpers.h b/include/internal/ech_helpers.h deleted file mode 100644 index 00053eed6a..0000000000 --- a/include/internal/ech_helpers.h +++ /dev/null @@ -1,61 +0,0 @@ -/* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. - * Licensed under the OpenSSL license (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* - * These functions are ECH helpers that are used within the library but - * also by ECH test code. - */ - -#ifndef OPENSSL_ECH_HELPERS_H -#define OPENSSL_ECH_HELPERS_H -#pragma once - -#include -#include - -#ifndef OPENSSL_NO_ECH - -/* - * the max HPKE 'info' we'll process is the max ECHConfig size - * (OSSL_ECH_MAX_ECHCONFIG_LEN) plus OSSL_ECH_CONTEXT_STRING(len=7) + 1 - */ -#define OSSL_ECH_MAX_INFO_LEN (OSSL_ECH_MAX_ECHCONFIG_LEN + 8) - -int ossl_ech_make_enc_info(const unsigned char *encoding, - size_t encoding_length, - unsigned char *info, size_t *info_len); - -/* - * Given a CH find the offsets of the session id, extensions and ECH - * ch is the encoded client hello - * ch_len is the length of ch - * sessid_off returns offset of session_id length - * exts_off points to offset of extensions - * exts_len returns length of extensions - * ech_off returns offset of ECH - * echtype returns the ext type of the ECH - * ech_len returns the length of the ECH - * sni_off returns offset of (outer) SNI - * sni_len returns the length of the SNI - * inner 1 if the ECH is marked as an inner, 0 for outer - * return 1 for success, other otherwise - * - * Offsets are set to zero if relevant thing not found. - * Offsets are returned to the type or length field in question. - * - * Note: input here is untrusted! - */ -int ossl_ech_helper_get_ch_offsets(const unsigned char *ch, size_t ch_len, - size_t *sessid_off, size_t *exts_off, - size_t *exts_len, - size_t *ech_off, uint16_t *echtype, - size_t *ech_len, size_t *sni_off, - size_t *sni_len, int *inner); - -#endif -#endif diff --git a/include/internal/err.h b/include/internal/err.h index 51a8d87693..41b28ac473 100644 --- a/include/internal/err.h +++ b/include/internal/err.h @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2021 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -11,8 +11,6 @@ #define OSSL_INTERNAL_ERR_H #pragma once -#define ERR_NUM_ERRORS 16 - void err_free_strings_int(void); #endif diff --git a/include/internal/fips.h b/include/internal/fips.h index 47d1213007..956a88cdbb 100644 --- a/include/internal/fips.h +++ b/include/internal/fips.h @@ -1,5 +1,5 @@ /* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -11,132 +11,46 @@ #define OSSL_INTERNAL_FIPS_H #pragma once -#include - #ifdef FIPS_MODULE /* Return 1 if the FIPS self tests are running and 0 otherwise */ int ossl_fips_self_testing(void); +/* Deferred KAT tests categories */ + /* - * Each enum here corresponds to a test in the st_all_tests array - * in self_test_data.c, any change done here requires tests to be - * adjusted accordingly. + * The Integrity category is used to run test that are required by the + * integrity check and are a special category that can therefore never + * really be deferred. Keep it commented here as a reminder. + * # define FIPS_DEFERRED_KAT_INTEGRITY 0 */ -typedef enum { - ST_ID_DRBG_HASH, - ST_ID_DRBG_CTR, - ST_ID_DRBG_HMAC, - ST_ID_CIPHER_AES_256_GCM, - ST_ID_CIPHER_AES_128_ECB, -#ifndef OPENSSL_NO_DES - ST_ID_CIPHER_DES_EDE3_ECB, -#endif -#ifndef OPENSSL_NO_ML_KEM - ST_ID_ASYM_KEYGEN_ML_KEM, -#endif -#ifndef OPENSSL_NO_ML_DSA - ST_ID_ASYM_KEYGEN_ML_DSA, -#endif -#ifndef OPENSSL_NO_SLH_DSA - ST_ID_ASYM_KEYGEN_SLH_DSA, -#endif - ST_ID_SIG_RSA_SHA256, -#ifndef OPENSSL_NO_EC - ST_ID_SIG_ECDSA_SHA256, -#ifndef OPENSSL_NO_HMAC_DRBG_KDF - ST_ID_SIG_DET_ECDSA_SHA256, -#endif -#ifndef OPENSSL_NO_EC2M - ST_ID_SIG_E2CM_ECDSA_SHA256, -#endif -#ifndef OPENSSL_NO_ECX - ST_ID_SIG_ED448, - ST_ID_SIG_ED25519, -#endif -#endif -#ifndef OPENSSL_NO_DSA - ST_ID_SIG_DSA_SHA256, -#endif -#ifndef OPENSSL_NO_ML_DSA - ST_ID_SIG_ML_DSA_65, -#endif -#ifndef OPENSSL_NO_SLH_DSA - ST_ID_SIG_SLH_DSA_SHA2_128F, - ST_ID_SIG_SLH_DSA_SHAKE_128F, -#endif /* OPENSSL_NO_SLH_DSA */ -#ifndef OPENSSL_NO_LMS - ST_ID_SIG_LMS, -#endif -#ifndef OPENSSL_NO_ML_KEM - ST_ID_KEM_ML_KEM, -#endif - ST_ID_ASYM_CIPHER_RSA_ENC, - ST_ID_ASYM_CIPHER_RSA_DEC, - ST_ID_ASYM_CIPHER_RSA_DEC_CRT, -#ifndef OPENSSL_NO_DH - ST_ID_KA_DH, -#endif -#ifndef OPENSSL_NO_EC - ST_ID_KA_ECDH, -#endif - ST_ID_KDF_TLS13_EXTRACT, - ST_ID_KDF_TLS13_EXPAND, - ST_ID_KDF_TLS12_PRF, - ST_ID_KDF_PBKDF2, -#ifndef OPENSSL_NO_KBKDF - ST_ID_KDF_KBKDF, - ST_ID_KDF_KBKDF_KMAC, -#endif - ST_ID_KDF_HKDF, -#ifndef OPENSSL_NO_IKEV2KDF - ST_ID_KDF_IKEV2KDF_GEN, - ST_ID_KDF_IKEV2KDF_DKM1, - ST_ID_KDF_IKEV2KDF_DKM2, - ST_ID_KDF_IKEV2KDF_DKM3, - ST_ID_KDF_IKEV2KDF_REKEY, -#endif -#ifndef OPENSSL_NO_SNMPKDF - ST_ID_KDF_SNMPKDF, -#endif -#ifndef OPENSSL_NO_SRTPKDF - ST_ID_KDF_SRTPKDF, -#endif -#ifndef OPENSSL_NO_SSKDF - ST_ID_KDF_SSKDF, -#endif -#ifndef OPENSSL_NO_X963KDF - ST_ID_KDF_X963KDF, -#endif -#ifndef OPENSSL_NO_X942KDF - ST_ID_KDF_X942KDF, -#endif - ST_ID_MAC_HMAC, - ST_ID_DIGEST_SHA1, - ST_ID_DIGEST_SHA256, - ST_ID_DIGEST_SHA512, - ST_ID_DIGEST_SHA3_256, - ST_ID_MAX -} self_test_id_t; +#define FIPS_DEFERRED_KAT_CIPHER 1 +#define FIPS_DEFERRED_KAT_ASYM_CIPHER 2 +#define FIPS_DEFERRED_KAT_ASYM_KEYGEN 3 +#define FIPS_DEFERRED_KAT_KEM 4 +#define FIPS_DEFERRED_KAT_DIGEST 5 +#define FIPS_DEFERRED_KAT_SIGNATURE 6 +#define FIPS_DEFERRED_KAT_KDF 7 +#define FIPS_DEFERRED_KAT_KA 8 +/* Currently unused because all MAC tests are satisfied through other tests */ +#define FIPS_DEFERRED_KAT_MAC 9 +#define FIPS_DEFERRED_DRBG 10 +#define FIPS_DEFERRED_MAX 11 -int ossl_deferred_self_test(OSSL_LIB_CTX *libctx, self_test_id_t id); -int ossl_self_test_in_progress(self_test_id_t id); +struct fips_deferred_test_st { + const char *algorithm; + int category; + int state; +}; -/* Helper definitions to keep some of the ciphercommon.h macros simple */ -#define ST_ID_CIPHER_aes ST_ID_CIPHER_AES_128_ECB -#define ST_ID_CIPHER_AES_128_CCM ST_ID_CIPHER_AES_128_ECB -#define ST_ID_CIPHER_AES_128_OCB ST_ID_CIPHER_AES_128_ECB -#define ST_ID_CIPHER_AES_128_WRP ST_ID_CIPHER_AES_128_ECB -#define ST_ID_CIPHER_AES_128_XTS ST_ID_CIPHER_AES_128_ECB -/* Helper definitions to keep some of the digestcommon.h macros simple */ -#define ST_ID_DIGEST_sha1 ST_ID_DIGEST_SHA1 -#define ST_ID_DIGEST_sha224 ST_ID_DIGEST_SHA256 -#define ST_ID_DIGEST_sha256 ST_ID_DIGEST_SHA256 -#define ST_ID_DIGEST_sha256_192_internal ST_ID_DIGEST_SHA256 -#define ST_ID_DIGEST_sha384 ST_ID_DIGEST_SHA512 -#define ST_ID_DIGEST_sha512 ST_ID_DIGEST_SHA512 -#define ST_ID_DIGEST_sha512_224 ST_ID_DIGEST_SHA512 -#define ST_ID_DIGEST_sha512_256 ST_ID_DIGEST_SHA512 +#define FIPS_DEFERRED_TEST_INIT 0 +#define FIPS_DEFERRED_TEST_IN_PROGRESS 1 +#define FIPS_DEFERRED_TEST_PASSED 2 +#define FIPS_DEFERRED_TEST_FAILED 3 + +typedef struct fips_deferred_test_st FIPS_DEFERRED_TEST; + +int FIPS_deferred_self_tests(OSSL_LIB_CTX *libctx, FIPS_DEFERRED_TEST tests[]); #endif /* FIPS_MODULE */ diff --git a/include/internal/hashtable.h b/include/internal/hashtable.h index 9aad653097..92d1254eac 100644 --- a/include/internal/hashtable.h +++ b/include/internal/hashtable.h @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -13,7 +13,6 @@ #include #include -#include #include #include #include "crypto/context.h" @@ -24,9 +23,7 @@ typedef struct ht_internal_st HT; * Represents a key to a hashtable */ typedef struct ht_key_header_st { - uint64_t cached_hash; size_t keysize; - size_t bufsize; uint8_t *keybuf; } HT_KEY; @@ -110,90 +107,17 @@ typedef struct ht_config_st { /* * Initializes a key */ -#define HT_INIT_KEY(key) \ - do { \ - memset((key), 0, sizeof(*(key))); \ - (key)->key_header.keysize = (key)->key_header.bufsize = (sizeof(*(key)) - sizeof(HT_KEY)); \ - (key)->key_header.keybuf = (((uint8_t *)key) + sizeof(HT_KEY)); \ +#define HT_INIT_KEY(key) \ + do { \ + memset((key), 0, sizeof(*(key))); \ + (key)->key_header.keysize = (sizeof(*(key)) - sizeof(HT_KEY)); \ + (key)->key_header.keybuf = (((uint8_t *)key) + sizeof(HT_KEY)); \ } while (0) -/* - * Initializes a key as a raw buffer - * This operates identically to HT_INIT_KEY - * but it treats the provided key as a raw buffer - * and iteratively accounts the running amount of - * data copied into the key from the caller. - * - * This MUST be used with the RAW macros below: - * HT_COPY_RAW_KEY - * HT_COPY_RAW_KEY_CASE - */ -#define HT_INIT_RAW_KEY(key) \ - do { \ - HT_INIT_KEY((key)); \ - (key)->key_header.keysize = 0; \ - } while (0) - -/* - * Helper function to copy raw data into a key - * This should not be called independently - * use the HT_COPY_RAW_KEY macro instead - */ -static ossl_inline ossl_unused int ossl_key_raw_copy(HT_KEY *key, const uint8_t *buf, size_t len) -{ - if (key->keysize + len > key->bufsize) - return 0; - memcpy(&key->keybuf[key->keysize], buf, len); - key->keysize += len; - return 1; -} - -/* - * Copy data directly into a key - * When initialized with HT_INIT_RAW_KEY, this macro - * can be used to copy packed data into a key for hashtable usage - * It is advantageous as it limits the amount of data that needs to - * be hashed when doing inserts/lookups/deletes, as it tracks how much - * key data is actually valid - */ -#define HT_COPY_RAW_KEY(key, buf, len) ossl_key_raw_copy(key, buf, len) - -/* - * Similar to HT_COPY_RAW_KEY but accepts a character buffer, and copies - * data while converting case for case insensitive matches - */ -#define HT_COPY_RAW_KEY_CASE(key, buf, len) \ - do { \ - size_t tmplen = (size_t)(len); \ - if (tmplen > (key)->bufsize - (key)->keysize) \ - tmplen = (key)->bufsize - (key)->keysize; \ - ossl_ht_strcase((key), (char *)&((key)->keybuf[(key)->keysize]), buf, tmplen); \ - (key)->keysize += tmplen; \ - } while (0) - -#define HT_INIT_KEY_CACHED(key, hash) \ - do { \ - HT_INIT_KEY((key)); \ - (key)->key_header.cached_hash = hash; \ - } while (0) - -#define HT_INIT_KEY_EXTERNAL(key, buf, len) \ - do { \ - HT_INIT_KEY((key)); \ - (key)->key_header.keybuf = (buf); \ - (key)->key_header.keysize = (len); \ - } while (0) - -#define HT_KEY_GET_HASH(key) (key)->key_header.cached_hash - /* * Resets a hash table key to a known state */ -#define HT_KEY_RESET(key) \ - do { \ - memset((key)->key_header.keybuf, 0, (key)->key_header.keysize); \ - (key)->key_header.cached_hash = 0; \ - } while (0) +#define HT_KEY_RESET(key) memset((key)->key_header.keybuf, 0, (key)->key_header.keysize) /* * Sets a scalar field in a hash table key @@ -216,9 +140,9 @@ static ossl_inline ossl_unused int ossl_key_raw_copy(HT_KEY *key, const uint8_t * This is useful for instances in which we want upper and lower case * key value to hash to the same entry */ -#define HT_SET_KEY_STRING_CASE(key, member, value) \ - do { \ - ossl_ht_strcase(NULL, (key)->keyfields.member, value, sizeof((key)->keyfields.member) - 1); \ +#define HT_SET_KEY_STRING_CASE(key, member, value) \ + do { \ + ossl_ht_strcase((key)->keyfields.member, value, sizeof((key)->keyfields.member) - 1); \ } while (0) /* @@ -235,12 +159,12 @@ static ossl_inline ossl_unused int ossl_key_raw_copy(HT_KEY *key, const uint8_t } while (0) /* Same as HT_SET_KEY_STRING_CASE but also takes length of the string. */ -#define HT_SET_KEY_STRING_CASE_N(key, member, value, len) \ - do { \ - if ((size_t)len < sizeof((key)->keyfields.member)) \ - ossl_ht_strcase(NULL, (key)->keyfields.member, value, len); \ - else \ - ossl_ht_strcase(NULL, (key)->keyfields.member, value, sizeof((key)->keyfields.member) - 1); \ +#define HT_SET_KEY_STRING_CASE_N(key, member, value, len) \ + do { \ + if ((size_t)len < sizeof((key)->keyfields.member)) \ + ossl_ht_strcase((key)->keyfields.member, value, len); \ + else \ + ossl_ht_strcase((key)->keyfields.member, value, sizeof((key)->keyfields.member) - 1); \ } while (0) /* @@ -337,9 +261,9 @@ static ossl_inline ossl_unused int ossl_key_raw_copy(HT_KEY *key, const uint8_t /* * Helper function to construct case insensitive keys */ -static ossl_inline ossl_unused void ossl_ht_strcase(HT_KEY *key, char *tgt, const char *src, size_t len) +static void ossl_unused ossl_ht_strcase(char *tgt, const char *src, int len) { - size_t i; + int i; #if defined(CHARSET_EBCDIC) && !defined(CHARSET_EBCDIC_TEST) const long int case_adjust = ~0x40; #else @@ -349,15 +273,7 @@ static ossl_inline ossl_unused void ossl_ht_strcase(HT_KEY *key, char *tgt, cons if (src == NULL) return; - /* - * If we're passed a key, we're doing raw key copies - * so check that we don't overflow here, and truncate if - * we copy more space than we have available - */ - if (key != NULL && key->keysize + len > key->bufsize) - len = (size_t)(key->bufsize - key->keysize); - - for (i = 0; i < len && src[i] != '\0'; i++) + for (i = 0; src[i] != '\0' && i < len; i++) tgt[i] = case_adjust & src[i]; } @@ -399,9 +315,7 @@ int ossl_ht_flush(HT *htable); /* * Inserts an element to a hash table, optionally returning * replaced data to caller - * Returns 1 if the insert was successful, 0 on duplicate without - * replacement, invalid input, or another non-allocation failure, and -1 - * on allocation failure or if the table could not be grown. + * Returns 1 if the insert was successful, 0 on error */ int ossl_ht_insert(HT *htable, HT_KEY *key, HT_VALUE *data, HT_VALUE **olddata); diff --git a/include/internal/hpke_util.h b/include/internal/hpke_util.h index 152c3213ed..9c52ba4693 100644 --- a/include/internal/hpke_util.h +++ b/include/internal/hpke_util.h @@ -11,11 +11,6 @@ #define OSSL_INTERNAL_HPKE_UTIL_H #pragma once -#include - -#include -#include - /* Constants from RFC 9180 Section 7.1 and 7.3 */ #define OSSL_HPKE_MAX_SECRET 64 #define OSSL_HPKE_MAX_PUBLIC 133 diff --git a/include/internal/ktls.h b/include/internal/ktls.h index d358481999..8c9b12cfe2 100644 --- a/include/internal/ktls.h +++ b/include/internal/ktls.h @@ -1,5 +1,5 @@ /* - * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -97,8 +97,8 @@ static ossl_inline int ktls_enable_tx_zerocopy_sendfile(int fd) * the entire record is pushed to TCP. It is impossible to send a partial * record using this control message. */ -static ossl_inline int ktls_send_ctrl_message(int fd, - unsigned char record_type, const void *data, size_t lengthi, int flags) +static ossl_inline int ktls_send_ctrl_message(int fd, unsigned char record_type, + const void *data, size_t length) { struct msghdr msg = { 0 }; int cmsg_len = sizeof(record_type); @@ -120,7 +120,7 @@ static ossl_inline int ktls_send_ctrl_message(int fd, msg.msg_iov = &msg_iov; msg.msg_iovlen = 1; - return sendmsg(fd, &msg, flags); + return sendmsg(fd, &msg, 0); } #ifdef OPENSSL_NO_KTLS_RX @@ -201,10 +201,16 @@ static ossl_inline int ktls_read_record(int fd, void *data, size_t length) * KTLS enables the sendfile system call to send data from a file over * TLS. */ -static ossl_inline int ktls_sendfile(int s, int fd, off_t off, size_t size, - ossl_ssize_t *sbytes, int flags) +static ossl_inline ossl_ssize_t ktls_sendfile(int s, int fd, off_t off, + size_t size, int flags) { - return sendfile(fd, s, off, size, NULL, sbytes, flags); + off_t sbytes = 0; + int ret; + + ret = sendfile(fd, s, off, size, NULL, &sbytes, flags); + if (ret == -1 && sbytes == 0) + return -1; + return sbytes; } #endif /* __FreeBSD__ */ @@ -334,8 +340,8 @@ static ossl_inline int ktls_enable_tx_zerocopy_sendfile(int fd) * the entire record is pushed to TCP. It is impossible to send a partial * record using this control message. */ -static ossl_inline int ktls_send_ctrl_message(int fd, - unsigned char record_type, const void *data, size_t length, int flags) +static ossl_inline int ktls_send_ctrl_message(int fd, unsigned char record_type, + const void *data, size_t length) { struct msghdr msg; int cmsg_len = sizeof(record_type); @@ -361,25 +367,16 @@ static ossl_inline int ktls_send_ctrl_message(int fd, msg.msg_iov = &msg_iov; msg.msg_iovlen = 1; - return sendmsg(fd, &msg, flags); + return sendmsg(fd, &msg, 0); } /* * KTLS enables the sendfile system call to send data from a file over TLS. * @flags are ignored on Linux. (placeholder for FreeBSD sendfile) * */ -static ossl_inline int ktls_sendfile(int s, int fd, off_t off, size_t size, ossl_ssize_t *sbytes, int flags) +static ossl_inline ossl_ssize_t ktls_sendfile(int s, int fd, off_t off, size_t size, int flags) { - ossl_ssize_t sent; - - sent = sendfile(s, fd, &off, size); - if (sent >= 0) { - *sbytes = sent; - return 0; - } else { - *sbytes = 0; - return -1; - } + return sendfile(s, fd, &off, size); } #ifdef OPENSSL_NO_KTLS_RX diff --git a/include/internal/namemap.h b/include/internal/namemap.h index bea96857dc..70c6930543 100644 --- a/include/internal/namemap.h +++ b/include/internal/namemap.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_INTERNAL_NAMEMAP_H) -#define OSSL_INTERNAL_NAMEMAP_H - #include "internal/cryptlib.h" typedef struct ossl_namemap_st OSSL_NAMEMAP; @@ -42,5 +39,3 @@ int ossl_namemap_doall_names(const OSSL_NAMEMAP *namemap, int number, */ int ossl_namemap_add_names(OSSL_NAMEMAP *namemap, int number, const char *names, const char separator); - -#endif /* !defined(OSSL_INTERNAL_NAMEMAP_H) */ diff --git a/include/internal/packet.h b/include/internal/packet.h index 44b63c5aa1..19331463d7 100644 --- a/include/internal/packet.h +++ b/include/internal/packet.h @@ -1,5 +1,5 @@ /* - * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -22,8 +22,6 @@ typedef struct { /* Pointer to where we are currently reading from */ const unsigned char *curr; - /* Pointer to the start of the message */ - const unsigned char *msgstart; /* Number of bytes remaining */ size_t remaining; } PACKET; @@ -54,15 +52,6 @@ static ossl_inline const unsigned char *PACKET_end(const PACKET *pkt) return pkt->curr + pkt->remaining; } -/* - * Returns a pointer to the very start of the buffer. If this is a sub packet - * this will be the start of the buffer for the top of the PACKET tree. - */ -static ossl_inline const unsigned char *PACKET_msg_start(const PACKET *pkt) -{ - return pkt->msgstart; -} - /* * Returns a pointer to the PACKET's current position. * For use in non-PACKETized APIs. @@ -85,7 +74,7 @@ __owur static ossl_inline int PACKET_buf_init(PACKET *pkt, if (len > (size_t)(SIZE_MAX / 2)) return 0; - pkt->curr = pkt->msgstart = buf; + pkt->curr = buf; pkt->remaining = len; return 1; } @@ -93,7 +82,7 @@ __owur static ossl_inline int PACKET_buf_init(PACKET *pkt, /* Initialize a PACKET to hold zero bytes. */ static ossl_inline void PACKET_null_init(PACKET *pkt) { - pkt->curr = pkt->msgstart = NULL; + pkt->curr = NULL; pkt->remaining = 0; } @@ -121,11 +110,7 @@ __owur static ossl_inline int PACKET_peek_sub_packet(const PACKET *pkt, if (PACKET_remaining(pkt) < len) return 0; - if (!PACKET_buf_init(subpkt, pkt->curr, len)) - return 0; - - subpkt->msgstart = pkt->msgstart; - return 1; + return PACKET_buf_init(subpkt, pkt->curr, len); } /* @@ -556,7 +541,6 @@ __owur static ossl_inline int PACKET_get_length_prefixed_1(PACKET *pkt, *pkt = tmp; subpkt->curr = data; - subpkt->msgstart = pkt->msgstart; subpkt->remaining = length; return 1; @@ -578,7 +562,6 @@ __owur static ossl_inline int PACKET_as_length_prefixed_1(PACKET *pkt, *pkt = tmp; subpkt->curr = data; - subpkt->msgstart = pkt->msgstart; subpkt->remaining = length; return 1; @@ -604,7 +587,6 @@ __owur static ossl_inline int PACKET_get_length_prefixed_2(PACKET *pkt, *pkt = tmp; subpkt->curr = data; - subpkt->msgstart = pkt->msgstart; subpkt->remaining = length; return 1; @@ -627,7 +609,6 @@ __owur static ossl_inline int PACKET_as_length_prefixed_2(PACKET *pkt, *pkt = tmp; subpkt->curr = data; - subpkt->msgstart = pkt->msgstart; subpkt->remaining = length; return 1; @@ -652,7 +633,6 @@ __owur static ossl_inline int PACKET_get_length_prefixed_3(PACKET *pkt, *pkt = tmp; subpkt->curr = data; - subpkt->msgstart = pkt->msgstart; subpkt->remaining = length; return 1; diff --git a/include/internal/params.h b/include/internal/params.h index b5b423351f..fa948eb69c 100644 --- a/include/internal/params.h +++ b/include/internal/params.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_INTERNAL_PARAMS_H) -#define OSSL_INTERNAL_PARAMS_H - #include #include @@ -42,5 +39,3 @@ int ossl_param_get1_octet_string(const OSSL_PARAM *params, const char *name, */ int ossl_param_get1_concat_octet_string(size_t n, OSSL_PARAM *params[], unsigned char **out, size_t *out_len); - -#endif /* !defined(OSSL_INTERNAL_PARAMS_H) */ diff --git a/include/internal/passphrase.h b/include/internal/passphrase.h index b7cbaa1057..803622867b 100644 --- a/include/internal/passphrase.h +++ b/include/internal/passphrase.h @@ -11,8 +11,6 @@ #define OSSL_INTERNAL_PASSPHRASE_H #pragma once -#include - /* * This is a passphrase reader bridge with bells and whistles. * diff --git a/include/internal/priority_queue.h b/include/internal/priority_queue.h index 9f4a636165..067c881596 100644 --- a/include/internal/priority_queue.h +++ b/include/internal/priority_queue.h @@ -16,56 +16,56 @@ #define PRIORITY_QUEUE_OF(type) OSSL_PRIORITY_QUEUE_##type -#define DEFINE_PRIORITY_QUEUE_OF_INTERNAL(type, ctype) \ - typedef struct ossl_priority_queue_st_##type PRIORITY_QUEUE_OF(type); \ - static ossl_unused ossl_inline PRIORITY_QUEUE_OF(type) * ossl_pqueue_##type##_new(int (*compare)(const void *, const void *)) \ - { \ - return (PRIORITY_QUEUE_OF(type) *)ossl_pqueue_new( \ - compare); \ - } \ - static ossl_unused ossl_inline void \ - ossl_pqueue_##type##_free(PRIORITY_QUEUE_OF(type) * pq) \ - { \ - ossl_pqueue_free((OSSL_PQUEUE *)pq); \ - } \ - static ossl_unused ossl_inline void \ - ossl_pqueue_##type##_pop_free(PRIORITY_QUEUE_OF(type) * pq, \ - void (*freefunc)(void *)) \ - { \ - ossl_pqueue_pop_free((OSSL_PQUEUE *)pq, freefunc); \ - } \ - static ossl_unused ossl_inline int \ - ossl_pqueue_##type##_reserve(PRIORITY_QUEUE_OF(type) * pq, size_t n) \ - { \ - return ossl_pqueue_reserve((OSSL_PQUEUE *)pq, n); \ - } \ - static ossl_unused ossl_inline size_t \ - ossl_pqueue_##type##_num(const PRIORITY_QUEUE_OF(type) * pq) \ - { \ - return ossl_pqueue_num((OSSL_PQUEUE *)pq); \ - } \ - static ossl_unused ossl_inline int \ - ossl_pqueue_##type##_push(PRIORITY_QUEUE_OF(type) * pq, \ - ctype * data, size_t *elem) \ - { \ - return ossl_pqueue_push((OSSL_PQUEUE *)pq, (void *)data, elem); \ - } \ - static ossl_unused ossl_inline ctype * \ - ossl_pqueue_##type##_peek(const PRIORITY_QUEUE_OF(type) * pq) \ - { \ - return (type *)ossl_pqueue_peek((OSSL_PQUEUE *)pq); \ - } \ - static ossl_unused ossl_inline ctype * \ - ossl_pqueue_##type##_pop(PRIORITY_QUEUE_OF(type) * pq) \ - { \ - return (type *)ossl_pqueue_pop((OSSL_PQUEUE *)pq); \ - } \ - static ossl_unused ossl_inline ctype * \ - ossl_pqueue_##type##_remove(PRIORITY_QUEUE_OF(type) * pq, \ - size_t elem) \ - { \ - return (type *)ossl_pqueue_remove((OSSL_PQUEUE *)pq, elem); \ - } \ +#define DEFINE_PRIORITY_QUEUE_OF_INTERNAL(type, ctype) \ + typedef struct ossl_priority_queue_st_##type PRIORITY_QUEUE_OF(type); \ + static ossl_unused ossl_inline PRIORITY_QUEUE_OF(type) * ossl_pqueue_##type##_new(int (*compare)(const ctype *, const ctype *)) \ + { \ + return (PRIORITY_QUEUE_OF(type) *)ossl_pqueue_new( \ + (int (*)(const void *, const void *))compare); \ + } \ + static ossl_unused ossl_inline void \ + ossl_pqueue_##type##_free(PRIORITY_QUEUE_OF(type) * pq) \ + { \ + ossl_pqueue_free((OSSL_PQUEUE *)pq); \ + } \ + static ossl_unused ossl_inline void \ + ossl_pqueue_##type##_pop_free(PRIORITY_QUEUE_OF(type) * pq, \ + void (*freefunc)(ctype *)) \ + { \ + ossl_pqueue_pop_free((OSSL_PQUEUE *)pq, (void (*)(void *))freefunc); \ + } \ + static ossl_unused ossl_inline int \ + ossl_pqueue_##type##_reserve(PRIORITY_QUEUE_OF(type) * pq, size_t n) \ + { \ + return ossl_pqueue_reserve((OSSL_PQUEUE *)pq, n); \ + } \ + static ossl_unused ossl_inline size_t \ + ossl_pqueue_##type##_num(const PRIORITY_QUEUE_OF(type) * pq) \ + { \ + return ossl_pqueue_num((OSSL_PQUEUE *)pq); \ + } \ + static ossl_unused ossl_inline int \ + ossl_pqueue_##type##_push(PRIORITY_QUEUE_OF(type) * pq, \ + ctype * data, size_t *elem) \ + { \ + return ossl_pqueue_push((OSSL_PQUEUE *)pq, (void *)data, elem); \ + } \ + static ossl_unused ossl_inline ctype * \ + ossl_pqueue_##type##_peek(const PRIORITY_QUEUE_OF(type) * pq) \ + { \ + return (type *)ossl_pqueue_peek((OSSL_PQUEUE *)pq); \ + } \ + static ossl_unused ossl_inline ctype * \ + ossl_pqueue_##type##_pop(PRIORITY_QUEUE_OF(type) * pq) \ + { \ + return (type *)ossl_pqueue_pop((OSSL_PQUEUE *)pq); \ + } \ + static ossl_unused ossl_inline ctype * \ + ossl_pqueue_##type##_remove(PRIORITY_QUEUE_OF(type) * pq, \ + size_t elem) \ + { \ + return (type *)ossl_pqueue_remove((OSSL_PQUEUE *)pq, elem); \ + } \ struct ossl_priority_queue_st_##type #define DEFINE_PRIORITY_QUEUE_OF(type) \ diff --git a/include/internal/property.h b/include/internal/property.h index b63634c678..2c7b5034ea 100644 --- a/include/internal/property.h +++ b/include/internal/property.h @@ -59,7 +59,9 @@ int ossl_method_unlock_store(OSSL_METHOD_STORE *store); int ossl_method_store_add(OSSL_METHOD_STORE *store, const OSSL_PROVIDER *prov, int nid, const char *properties, void *method, int (*method_up_ref)(void *), - void (*method_destruct)(void *)); + void (*method_destruct)(void *), + void *(*method_dup)(void *), + void (*free_frozen)(void *)); int ossl_method_store_remove(OSSL_METHOD_STORE *store, int nid, const void *method); void ossl_method_store_do_all(OSSL_METHOD_STORE *store, @@ -81,7 +83,9 @@ int ossl_method_store_cache_get(OSSL_METHOD_STORE *store, OSSL_PROVIDER *prov, int ossl_method_store_cache_set(OSSL_METHOD_STORE *store, OSSL_PROVIDER *prov, int nid, const char *prop_query, void *result, int (*method_up_ref)(void *), - void (*method_destruct)(void *)); + void (*method_destruct)(void *), + void *(*method_dup)(void *), + void (*free_frozen)(void *)); __owur int ossl_method_store_cache_flush_all(OSSL_METHOD_STORE *store); @@ -96,4 +100,12 @@ size_t ossl_property_list_to_string(OSSL_LIB_CTX *ctx, int ossl_global_properties_no_mirrored(OSSL_LIB_CTX *libctx); void ossl_global_properties_stop_mirroring(OSSL_LIB_CTX *libctx); +int ossl_method_store_freeze_cache(OSSL_METHOD_STORE *store, const char *propq); +int ossl_frozen_method_store_cache_get(OSSL_METHOD_STORE *store, + const char *name, const char *prop_query, unsigned int operation_id, + void **result); + +int ossl_method_store_is_frozen(OSSL_METHOD_STORE *store); +const char *ossl_method_store_frozen_propq(OSSL_METHOD_STORE *store); + #endif diff --git a/include/internal/qlog.h b/include/internal/qlog.h index ecabe942f2..eb68570e60 100644 --- a/include/internal/qlog.h +++ b/include/internal/qlog.h @@ -21,11 +21,10 @@ typedef struct qlog_st QLOG; enum { QLOG_EVENT_TYPE_NONE, -/* clang-format off */ + #define QLOG_EVENT(cat, name) QLOG_EVENT_TYPE_##cat##_##name, -#include "internal/qlog_events.inc" +#include "internal/qlog_events.h" #undef QLOG_EVENT - /* clang-format on */ QLOG_EVENT_TYPE_NUM }; diff --git a/include/internal/qlog_events.inc b/include/internal/qlog_events.h similarity index 99% rename from include/internal/qlog_events.inc rename to include/internal/qlog_events.h index 8d2ef1b349..6dd44bf365 100644 --- a/include/internal/qlog_events.inc +++ b/include/internal/qlog_events.h @@ -6,7 +6,6 @@ * in the file LICENSE in the source distribution or at * https://www.openssl.org/source/license.html */ - QLOG_EVENT(connectivity, connection_started) QLOG_EVENT(connectivity, connection_state_updated) QLOG_EVENT(connectivity, connection_closed) diff --git a/include/internal/quic_cfq.h b/include/internal/quic_cfq.h index 96c8d89eb6..0b2a3a4cb2 100644 --- a/include/internal/quic_cfq.h +++ b/include/internal/quic_cfq.h @@ -149,7 +149,6 @@ QUIC_CFQ_ITEM *ossl_quic_cfq_get_priority_head(const QUIC_CFQ *cfq, QUIC_CFQ_ITEM *ossl_quic_cfq_item_get_priority_next(const QUIC_CFQ_ITEM *item, uint32_t pn_space); -int ossl_quic_cfq_discard_unreliable(QUIC_CFQ *cfq, QUIC_CFQ_ITEM *item); #endif #endif diff --git a/include/internal/quic_channel.h b/include/internal/quic_channel.h index cfe7a6005c..26b23b1fa2 100644 --- a/include/internal/quic_channel.h +++ b/include/internal/quic_channel.h @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -128,20 +128,6 @@ typedef struct quic_channel_args_st { /* Title to use for the qlog session, or NULL. */ const char *qlog_title; - - /* Transport parameter values for the channel. */ - uint64_t max_idle_timeout; - uint64_t max_udp_payload_size; - uint64_t init_max_data; - uint64_t init_max_stream_data_bidi_local; - uint64_t init_max_stream_data_bidi_remote; - uint64_t init_max_stream_data_uni; - uint64_t init_max_streams_bidi; - uint64_t init_max_streams_uni; - uint64_t max_ack_delay; - uint64_t active_conn_id_limit; - unsigned char ack_delay_exponent; - unsigned char disable_active_migration; } QUIC_CHANNEL_ARGS; /* Represents the cause for a connection's termination. */ @@ -297,6 +283,7 @@ void ossl_quic_channel_on_new_conn_id(QUIC_CHANNEL *ch, /* Temporarily exposed during QUIC_PORT transition. */ int ossl_quic_channel_on_new_conn(QUIC_CHANNEL *ch, const BIO_ADDR *peer, + const QUIC_CONN_ID *peer_scid, const QUIC_CONN_ID *peer_dcid); /* For use by QUIC_PORT. You should not need to call this directly. */ @@ -474,79 +461,20 @@ uint64_t ossl_quic_channel_get_remote_stream_count_avail(const QUIC_CHANNEL *ch, int ossl_quic_channel_have_generated_transport_params(const QUIC_CHANNEL *ch); /* Configures the idle timeout to request from peer (milliseconds, 0=no timeout). */ -int ossl_quic_channel_set_max_idle_timeout_request(QUIC_CHANNEL *ch, uint64_t ms); -/* Gets the configured idle timeout to request from peer. */ +void ossl_quic_channel_set_max_idle_timeout_request(QUIC_CHANNEL *ch, uint64_t ms); +/* Get the configured idle timeout to request from peer. */ uint64_t ossl_quic_channel_get_max_idle_timeout_request(const QUIC_CHANNEL *ch); -/* Gets the idle timeout requested by the peer. */ +/* Get the idle timeout requested by the peer. */ uint64_t ossl_quic_channel_get_max_idle_timeout_peer_request(const QUIC_CHANNEL *ch); -/* Gets the idle timeout actually negotiated. */ +/* Get the idle timeout actually negotiated. */ uint64_t ossl_quic_channel_get_max_idle_timeout_actual(const QUIC_CHANNEL *ch); -/* Configures the maximum UDP payload size to advertise to the peer (bytes). */ -int ossl_quic_channel_set_max_udp_payload_size_request(QUIC_CHANNEL *ch, uint64_t size); -/* Gets the configured maximum UDP payload size to advertise to the peer. */ -uint64_t ossl_quic_channel_get_max_udp_payload_size_request(const QUIC_CHANNEL *ch); -/* Gets the maximum UDP payload size advertised by the peer. */ -uint64_t ossl_quic_channel_get_max_udp_payload_size_peer_request(const QUIC_CHANNEL *ch); - -/* Configures the maximum data to advertise to the peer (bytes). */ -int ossl_quic_channel_set_max_data_request(QUIC_CHANNEL *ch, uint64_t max_data); -/* Gets the configured maximum data to advertise to the peer. */ -uint64_t ossl_quic_channel_get_max_data_request(const QUIC_CHANNEL *ch); -/* Gets the maximum data advertised by the peer. */ -uint64_t ossl_quic_channel_get_max_data_peer_request(const QUIC_CHANNEL *ch); - -/* Configures the maximum stream data for a bidi/uni remote/local stream to advertise to the peer (bytes). */ -int ossl_quic_channel_set_max_stream_data_request(QUIC_CHANNEL *ch, uint64_t max_data, int is_uni, int is_remote); -/* Gets the configured maximum stream data for a bidi/uni remote/local stream to advertise to the peer. */ -uint64_t ossl_quic_channel_get_max_stream_data_request(const QUIC_CHANNEL *ch, int is_uni, int is_remote); -/* Gets the maximum stream data for a bidi/uni remote/local stream advertised by the peer. */ -uint64_t ossl_quic_channel_get_max_stream_data_peer_request(const QUIC_CHANNEL *ch, int is_uni, int is_remote); - -/* Configures the maximum bidi/uni streams to advertise to the peer. */ -int ossl_quic_channel_set_max_streams_request(QUIC_CHANNEL *ch, uint64_t max_streams, int is_uni); -/* Gets the configured maximum bidi/uni streams to advertise to the peer. */ -uint64_t ossl_quic_channel_get_max_streams_request(const QUIC_CHANNEL *ch, int is_uni); -/* Gets the maximum bidi/uni streams advertised by the peer. */ -uint64_t ossl_quic_channel_get_max_streams_peer_request(const QUIC_CHANNEL *ch, int is_uni); - -/* Configures the ACK delay exponent to advertise to the peer. */ -int ossl_quic_channel_set_ack_delay_exponent_request(QUIC_CHANNEL *ch, uint64_t exp); -/* Gets the configured ACK delay exponent to advertise to the peer. */ -uint64_t ossl_quic_channel_get_ack_delay_exponent_request(const QUIC_CHANNEL *ch); -/* Gets the ACK delay exponent advertised by the peer. */ -uint64_t ossl_quic_channel_get_ack_delay_exponent_peer_request(const QUIC_CHANNEL *ch); - -/* Configures the maximum ACK delay to advertise to the peer (milliseconds). */ -int ossl_quic_channel_set_max_ack_delay_request(QUIC_CHANNEL *ch, uint64_t ms); -/* Gets the configured maximum ACK delay to advertise to the peer. */ -uint64_t ossl_quic_channel_get_max_ack_delay_request(const QUIC_CHANNEL *ch); -/* Gets the maximum ACK delay advertised by the peer. */ -uint64_t ossl_quic_channel_get_max_ack_delay_peer_request(const QUIC_CHANNEL *ch); - -/* Configures the disable active migration flag to advertise to the peer. */ -int ossl_quic_channel_set_disable_active_migration_request(QUIC_CHANNEL *ch, uint64_t disable); -/* Gets the configured disable active migration flag to advertise to the peer. */ -uint64_t ossl_quic_channel_get_disable_active_migration_request(const QUIC_CHANNEL *ch); -/* Gets the disable active migration flag advertised by the peer. */ -uint64_t ossl_quic_channel_get_disable_active_migration_peer_request(const QUIC_CHANNEL *ch); - -/* Configures the active connection ID limit to advertise to the peer. */ -int ossl_quic_channel_set_active_conn_id_limit_request(QUIC_CHANNEL *ch, uint64_t limit); -/* Gets the configured active connection ID limit to advertise to the peer. */ -uint64_t ossl_quic_channel_get_active_conn_id_limit_request(const QUIC_CHANNEL *ch); -/* Gets the active connection ID limit advertised by the peer. */ -uint64_t ossl_quic_channel_get_active_conn_id_limit_peer_request(const QUIC_CHANNEL *ch); - int ossl_quic_bind_channel(QUIC_CHANNEL *ch, const BIO_ADDR *peer, - const QUIC_CONN_ID *dcid, const QUIC_CONN_ID *odcid); + const QUIC_CONN_ID *scid, const QUIC_CONN_ID *dcid, + const QUIC_CONN_ID *odcid); void ossl_quic_channel_set_tcause(QUIC_CHANNEL *ch, uint64_t app_error_code, const char *app_reason); - -void ossl_ch_reset_rx_state(QUIC_CHANNEL *ch); -uint64_t ossl_quic_channel_get_path_challenge_count(const QUIC_CHANNEL *ch); -uint64_t ossl_quic_channel_get_path_response_count(const QUIC_CHANNEL *ch); #endif #endif diff --git a/include/internal/quic_fifd.h b/include/internal/quic_fifd.h index afa330cbc4..4ea7a2e0d2 100644 --- a/include/internal/quic_fifd.h +++ b/include/internal/quic_fifd.h @@ -83,7 +83,6 @@ int ossl_quic_fifd_pkt_commit(QUIC_FIFD *fifd, QUIC_TXPIM_PKT *pkt); void ossl_quic_fifd_set_qlog_cb(QUIC_FIFD *fifd, QLOG *(*get_qlog_cb)(void *arg), void *arg); -void ossl_quic_fifd_pkt_discard_unreliable(QUIC_FIFD *fifd, QUIC_TXPIM_PKT *tpkt); #endif #endif diff --git a/include/internal/quic_lcidm.h b/include/internal/quic_lcidm.h index 079dacd597..66421e8ac1 100644 --- a/include/internal/quic_lcidm.h +++ b/include/internal/quic_lcidm.h @@ -254,7 +254,7 @@ int ossl_quic_lcidm_debug_add(QUIC_LCIDM *lcidm, void *opaque, /* * Obtain a local connection id which is not used yet. - * Returns 1 on success, 0 on failure. + * Returns 1 on succes, 0 on failure. */ int ossl_quic_lcidm_get_unused_cid(QUIC_LCIDM *lcidm, QUIC_CONN_ID *cid); diff --git a/include/internal/quic_port.h b/include/internal/quic_port.h index 0ce54dea97..ad3ba738ae 100644 --- a/include/internal/quic_port.h +++ b/include/internal/quic_port.h @@ -1,5 +1,5 @@ /* - * Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -47,8 +47,8 @@ typedef struct quic_port_args_st { * connection object for the incoming channel * user_ssl_arg is expected to point to a quic listener object */ - SSL *(*get_conn_user_ssl)(QUIC_CHANNEL *ch, QUIC_LISTENER *ql); - QUIC_LISTENER *ql; + SSL *(*get_conn_user_ssl)(QUIC_CHANNEL *ch, void *arg); + void *user_ssl_arg; /* * This SSL_CTX will be used when constructing the handshake layer object @@ -140,51 +140,6 @@ OSSL_TIME ossl_quic_port_get_time(QUIC_PORT *port); int ossl_quic_port_get_rx_short_dcid_len(const QUIC_PORT *port); int ossl_quic_port_get_tx_init_dcid_len(const QUIC_PORT *port); -/* Configures the idle timeout to request from peer (milliseconds, 0=no timeout). */ -void ossl_quic_port_set_max_idle_timeout(QUIC_PORT *port, uint64_t ms); -/* Gets the configured idle timeout to request from peer. */ -uint64_t ossl_quic_port_get_max_idle_timeout(const QUIC_PORT *port); - -/* Configures the maximum UDP payload size to advertise to the peer (bytes). */ -void ossl_quic_port_set_max_udp_payload_size(QUIC_PORT *port, uint64_t size); -/* Gets the configured maximum UDP payload size to advertise to the peer. */ -uint64_t ossl_quic_port_get_max_udp_payload_size(const QUIC_PORT *port); - -/* Configures the maximum data to advertise to the peer (bytes). */ -void ossl_quic_port_set_init_max_data(QUIC_PORT *port, uint64_t max_data); -/* Gets the configured maximum data to advertise to the peer. */ -uint64_t ossl_quic_port_get_init_max_data(const QUIC_PORT *port); - -/* Configures the maximum stream data for a bidi/uni remote/local stream to advertise to the peer (bytes). */ -void ossl_quic_port_set_init_max_stream_data(QUIC_PORT *port, uint64_t max_data, int is_uni, int is_remote); -/* Gets the configured maximum stream data for a bidi/uni remote/local stream to advertise to the peer. */ -uint64_t ossl_quic_port_get_init_max_stream_data(const QUIC_PORT *port, int is_uni, int is_remote); - -/* Configures the maximum bidi/uni streams to advertise to the peer. */ -void ossl_quic_port_set_init_max_streams(QUIC_PORT *port, uint64_t max_streams, int is_uni); -/* Gets the configured maximum bidi/uni streams to advertise to the peer. */ -uint64_t ossl_quic_port_get_init_max_streams(const QUIC_PORT *port, int is_uni); - -/* Configures the ACK delay exponent to advertise to the peer. */ -void ossl_quic_port_set_ack_delay_exponent(QUIC_PORT *port, uint64_t exp); -/* Gets the configured ACK delay exponent to advertise to the peer. */ -uint64_t ossl_quic_port_get_ack_delay_exponent(const QUIC_PORT *port); - -/* Configures the maximum ACK delay to advertise to the peer (milliseconds). */ -void ossl_quic_port_set_max_ack_delay(QUIC_PORT *port, uint64_t ms); -/* Gets the configured maximum ACK delay to advertise to the peer. */ -uint64_t ossl_quic_port_get_max_ack_delay(const QUIC_PORT *port); - -/* Configures the disable active migration flag to advertise to the peer. */ -void ossl_quic_port_set_disable_active_migration(QUIC_PORT *port, uint64_t disable); -/* Gets the configured disable active migration flag to advertise to the peer. */ -uint64_t ossl_quic_port_get_disable_active_migration(const QUIC_PORT *port); - -/* Configures the active connection ID limit to advertise to the peer. */ -void ossl_quic_port_set_active_conn_id_limit(QUIC_PORT *port, uint64_t limit); -/* Gets the configured active connection ID limit to advertise to the peer. */ -uint64_t ossl_quic_port_get_active_conn_id_limit(const QUIC_PORT *port); - /* Returns 1 if the port is running/healthy, 0 if it has failed. */ int ossl_quic_port_is_running(const QUIC_PORT *port); diff --git a/include/internal/quic_record_tx.h b/include/internal/quic_record_tx.h index d983d8bc79..b2be046f8c 100644 --- a/include/internal/quic_record_tx.h +++ b/include/internal/quic_record_tx.h @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -306,9 +306,6 @@ size_t ossl_qtx_get_unflushed_pkt_count(OSSL_QTX *qtx); */ void ossl_qtx_set_bio(OSSL_QTX *qtx, BIO *bio); -/* Changes the MTU in bytes we use to send datagrams. */ -int ossl_qtx_set_mtu(OSSL_QTX *qtx, unsigned int mtu); - /* Changes the MDPL. */ int ossl_qtx_set_mdpl(OSSL_QTX *qtx, size_t mdpl); diff --git a/include/internal/quic_srtm.h b/include/internal/quic_srtm.h index 77c0af6ac4..1a8f55da5d 100644 --- a/include/internal/quic_srtm.h +++ b/include/internal/quic_srtm.h @@ -11,7 +11,6 @@ #define OSSL_INTERNAL_QUIC_SRTM_H #pragma once -#include #include "internal/e_os.h" #include "internal/time.h" #include "internal/quic_types.h" @@ -70,22 +69,11 @@ void ossl_quic_srtm_free(QUIC_SRTM *srtm); int ossl_quic_srtm_add(QUIC_SRTM *srtm, void *opaque, uint64_t seq_num, const QUIC_STATELESS_RESET_TOKEN *token); -/** - * \brief Removes an entry identified by its (opaque, seq_num) tuple. - * - * The absence of a matching entry is not an error. - * - * \param srtm SRTM instance to remove the entry from. - * \param opaque Opaque pointer identifying the entry. - * \param seq_num Sequence number identifying the entry. - * \param match If non-NULL, \c *match is set to 1 if a matching entry was - * found or to 0 if not. May be NULL if this information is not - * required. - * - * \return 1 on success and 0 on internal error. +/* + * Removes an entry by identifying it via its (opaque, seq_num) tuple. + * Returns 1 if the entry was found and removed, and 0 if it was not found. */ -int ossl_quic_srtm_remove(QUIC_SRTM *srtm, void *opaque, uint64_t seq_num, - uint8_t *match); +int ossl_quic_srtm_remove(QUIC_SRTM *srtm, void *opaque, uint64_t seq_num); /* * Removes all entries (opaque, *) with the given opaque pointer. diff --git a/include/internal/quic_ssl.h b/include/internal/quic_ssl.h index 45b8e090ed..88168d169c 100644 --- a/include/internal/quic_ssl.h +++ b/include/internal/quic_ssl.h @@ -107,6 +107,8 @@ __owur int ossl_quic_get_stream_type(SSL *s); __owur uint64_t ossl_quic_get_stream_id(SSL *s); __owur int ossl_quic_is_stream_local(SSL *s); __owur int ossl_quic_set_default_stream_mode(SSL *s, uint32_t mode); +__owur SSL *ossl_quic_detach_stream(SSL *s); +__owur int ossl_quic_attach_stream(SSL *conn, SSL *stream); __owur int ossl_quic_set_incoming_stream_policy(SSL *s, int policy, uint64_t aec); __owur SSL *ossl_quic_accept_stream(SSL *s, uint64_t flags); diff --git a/include/internal/quic_stream_map.h b/include/internal/quic_stream_map.h index 36753d7196..925f516a09 100644 --- a/include/internal/quic_stream_map.h +++ b/include/internal/quic_stream_map.h @@ -299,7 +299,7 @@ struct quic_stream_st { * STOP_SENDING.] * * TODO(QUIC FUTURE): Implement the latter case (currently we - * just always do STOP_SENDING). + just always do STOP_SENDING). * * and; * @@ -315,7 +315,6 @@ struct quic_stream_st { unsigned int ready_for_gc : 1; /* Set to 1 if this is currently counted in the shutdown flush stream count. */ unsigned int shutdown_flush : 1; - unsigned int have_final_size : 1; }; #define QUIC_STREAM_INITIATOR_CLIENT 0 diff --git a/include/internal/quic_thread_assist.h b/include/internal/quic_thread_assist.h index 152c84663d..fbfac146da 100644 --- a/include/internal/quic_thread_assist.h +++ b/include/internal/quic_thread_assist.h @@ -11,8 +11,6 @@ #define OSSL_QUIC_THREAD_ASSIST_H #include - -#include "internal/quic_channel.h" #include "internal/thread.h" #include "internal/time.h" diff --git a/include/internal/quic_trace.h b/include/internal/quic_trace.h index bddb9823c2..f462ce0c00 100644 --- a/include/internal/quic_trace.h +++ b/include/internal/quic_trace.h @@ -12,10 +12,6 @@ #ifndef OPENSSL_NO_QUIC -#include - -#include - int ossl_quic_trace(int write_p, int version, int content_type, const void *buf, size_t msglen, SSL *ssl, void *arg); diff --git a/include/internal/quic_txp.h b/include/internal/quic_txp.h index ef1faff547..d94a79620d 100644 --- a/include/internal/quic_txp.h +++ b/include/internal/quic_txp.h @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -155,10 +155,6 @@ int ossl_quic_tx_packetiser_set_cur_scid(OSSL_QUIC_TX_PACKETISER *txp, int ossl_quic_tx_packetiser_set_peer(OSSL_QUIC_TX_PACKETISER *txp, const BIO_ADDR *peer); -/* Change the ACK delay exponent the TXP uses to encode ACK frames. */ -int ossl_quic_tx_packetiser_set_ack_delay_exponent(OSSL_QUIC_TX_PACKETISER *txp, - uint32_t exp); - /* * Change the QLOG instance retrieval function in use after instantiation. */ diff --git a/include/internal/quic_types.h b/include/internal/quic_types.h index 984a9774da..8636912cd9 100644 --- a/include/internal/quic_types.h +++ b/include/internal/quic_types.h @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -96,17 +96,16 @@ int ossl_quic_gen_rand_conn_id(OSSL_LIB_CTX *libctx, size_t len, #define QUIC_MIN_INITIAL_DGRAM_LEN 1200 -#define QUIC_MAX_MAX_UDP_PAYLOAD_SIZE 65527 /* RFC 9000 s. 18.2 */ -#define QUIC_DEFAULT_MAX_UDP_PAYLOAD_SIZE QUIC_MAX_MAX_UDP_PAYLOAD_SIZE - #define QUIC_DEFAULT_ACK_DELAY_EXP 3 #define QUIC_MAX_ACK_DELAY_EXP 20 #define QUIC_DEFAULT_MAX_ACK_DELAY 25 -#define QUIC_MAX_MAX_ACK_DELAY 16383 /* RFC 9000 s. 18.2 */ #define QUIC_MIN_ACTIVE_CONN_ID_LIMIT 2 +/* Arbitrary choice of default idle timeout (not an RFC value). */ +#define QUIC_DEFAULT_IDLE_TIMEOUT 30000 + #define QUIC_STATELESS_RESET_TOKEN_LEN 16 typedef struct { diff --git a/include/internal/quic_vlint.h b/include/internal/quic_vlint.h index c8b056909d..ff015eb127 100644 --- a/include/internal/quic_vlint.h +++ b/include/internal/quic_vlint.h @@ -54,7 +54,7 @@ static ossl_unused ossl_inline size_t ossl_quic_vlint_encode_len(uint64_t v) } /* - * This function writes a QUIC variable-length encoded integer to buf. + * This function writes a QUIC varable-length encoded integer to buf. * The smallest usable representation is used. * * It is the caller's responsibility to ensure that the buffer is big enough by diff --git a/include/internal/quic_wire.h b/include/internal/quic_wire.h index 06ae9ca677..f2efabaeba 100644 --- a/include/internal/quic_wire.h +++ b/include/internal/quic_wire.h @@ -424,7 +424,7 @@ int ossl_quic_wire_encode_frame_conn_close(WPACKET *pkt, /* * Encodes a QUIC HANDSHAKE_DONE frame to the packet writer. This frame type - * takes no arguments. + * takes no arguiments. */ int ossl_quic_wire_encode_frame_handshake_done(WPACKET *pkt); diff --git a/include/internal/rcu.h b/include/internal/rcu.h index 7090e5b256..c6fdc93e9d 100644 --- a/include/internal/rcu.h +++ b/include/internal/rcu.h @@ -17,8 +17,6 @@ typedef void (*rcu_cb_fn)(void *data); typedef struct rcu_lock_st CRYPTO_RCU_LOCK; -typedef struct rcu_cb_item CRYPTO_RCU_CB_ITEM; - CRYPTO_RCU_LOCK *ossl_rcu_lock_new(int num_writers, OSSL_LIB_CTX *ctx); void ossl_rcu_lock_free(CRYPTO_RCU_LOCK *lock); int ossl_rcu_read_lock(CRYPTO_RCU_LOCK *lock); @@ -26,10 +24,7 @@ void ossl_rcu_write_lock(CRYPTO_RCU_LOCK *lock); void ossl_rcu_write_unlock(CRYPTO_RCU_LOCK *lock); void ossl_rcu_read_unlock(CRYPTO_RCU_LOCK *lock); void ossl_synchronize_rcu(CRYPTO_RCU_LOCK *lock); -CRYPTO_RCU_CB_ITEM *ossl_rcu_cb_item_new(void); -void ossl_rcu_cb_item_free(CRYPTO_RCU_CB_ITEM *item); -void ossl_rcu_call(CRYPTO_RCU_LOCK *lock, CRYPTO_RCU_CB_ITEM *item, - rcu_cb_fn cb, void *data); +int ossl_rcu_call(CRYPTO_RCU_LOCK *lock, rcu_cb_fn cb, void *data); void *ossl_rcu_uptr_deref(void **p); void ossl_rcu_assign_uptr(void **p, void **v); #define ossl_rcu_deref(p) ossl_rcu_uptr_deref((void **)p) diff --git a/include/internal/recordmethod.h b/include/internal/recordmethod.h index 15e16c0026..eedded636c 100644 --- a/include/internal/recordmethod.h +++ b/include/internal/recordmethod.h @@ -132,6 +132,8 @@ struct ossl_record_method_st { BIO *prev, BIO *transport, BIO *next, + BIO_ADDR *local, + BIO_ADDR *peer, const OSSL_PARAM *settings, const OSSL_PARAM *options, const OSSL_DISPATCH *fns, diff --git a/include/internal/refcount.h b/include/internal/refcount.h index 8bbb11e3fc..61eb78ae41 100644 --- a/include/internal/refcount.h +++ b/include/internal/refcount.h @@ -14,8 +14,6 @@ #include #include -#include - #if defined(OPENSSL_THREADS) && !defined(OPENSSL_DEV_NO_ATOMICS) #if defined(__STDC_VERSION__) && __STDC_VERSION__ >= 201112L \ && !defined(__STDC_NO_ATOMICS__) @@ -38,10 +36,10 @@ typedef struct { _Atomic int val; } CRYPTO_REF_COUNT; -static inline bool CRYPTO_UP_REF(CRYPTO_REF_COUNT *refcnt, int *ret) +static inline int CRYPTO_UP_REF(CRYPTO_REF_COUNT *refcnt, int *ret) { *ret = atomic_fetch_add_explicit(&refcnt->val, 1, memory_order_relaxed) + 1; - return true; + return 1; } /* @@ -70,6 +68,12 @@ static inline int CRYPTO_DOWN_REF(CRYPTO_REF_COUNT *refcnt, int *ret) return 1; } +static inline int CRYPTO_GET_REF(CRYPTO_REF_COUNT *refcnt, int *ret) +{ + *ret = atomic_load_explicit(&refcnt->val, memory_order_acquire); + return 1; +} + #elif defined(__GNUC__) && defined(__ATOMIC_RELAXED) && __GCC_ATOMIC_INT_LOCK_FREE > 0 #define HAVE_ATOMICS 1 @@ -78,10 +82,10 @@ typedef struct { int val; } CRYPTO_REF_COUNT; -static __inline__ bool CRYPTO_UP_REF(CRYPTO_REF_COUNT *refcnt, int *ret) +static __inline__ int CRYPTO_UP_REF(CRYPTO_REF_COUNT *refcnt, int *ret) { *ret = __atomic_fetch_add(&refcnt->val, 1, __ATOMIC_RELAXED) + 1; - return true; + return 1; } static __inline__ int CRYPTO_DOWN_REF(CRYPTO_REF_COUNT *refcnt, int *ret) @@ -92,6 +96,12 @@ static __inline__ int CRYPTO_DOWN_REF(CRYPTO_REF_COUNT *refcnt, int *ret) return 1; } +static __inline__ int CRYPTO_GET_REF(CRYPTO_REF_COUNT *refcnt, int *ret) +{ + *ret = __atomic_load_n(&refcnt->val, __ATOMIC_RELAXED); + return 1; +} + #elif defined(__ICL) && defined(_WIN32) #define HAVE_ATOMICS 1 @@ -99,10 +109,10 @@ typedef struct { volatile int val; } CRYPTO_REF_COUNT; -static __inline bool CRYPTO_UP_REF(CRYPTO_REF_COUNT *refcnt, int *ret) +static __inline int CRYPTO_UP_REF(CRYPTO_REF_COUNT *refcnt, int *ret) { *ret = _InterlockedExchangeAdd((void *)&refcnt->val, 1) + 1; - return true; + return 1; } static __inline int CRYPTO_DOWN_REF(CRYPTO_REF_COUNT *refcnt, int *ret) @@ -111,6 +121,12 @@ static __inline int CRYPTO_DOWN_REF(CRYPTO_REF_COUNT *refcnt, int *ret) return 1; } +static __inline int CRYPTO_GET_REF(CRYPTO_REF_COUNT *refcnt, int *ret) +{ + *ret = _InterlockedExchangeAdd((void *)&refcnt->val, 0); + return 1; +} + #elif defined(_MSC_VER) && _MSC_VER >= 1200 #define HAVE_ATOMICS 1 @@ -119,16 +135,16 @@ typedef struct { volatile int val; } CRYPTO_REF_COUNT; -#if (defined(_M_ARM) && _M_ARM >= 7) || defined(_M_ARM64) +#if (defined(_M_ARM) && _M_ARM >= 7 && !defined(_WIN32_WCE)) || defined(_M_ARM64) #include #if defined(_M_ARM64) && !defined(_ARM_BARRIER_ISH) #define _ARM_BARRIER_ISH _ARM64_BARRIER_ISH #endif -static __inline bool CRYPTO_UP_REF(CRYPTO_REF_COUNT *refcnt, int *ret) +static __inline int CRYPTO_UP_REF(CRYPTO_REF_COUNT *refcnt, int *ret) { *ret = _InterlockedExchangeAdd_nf(&refcnt->val, 1) + 1; - return true; + return 1; } static __inline int CRYPTO_DOWN_REF(CRYPTO_REF_COUNT *refcnt, int *ret) @@ -137,13 +153,29 @@ static __inline int CRYPTO_DOWN_REF(CRYPTO_REF_COUNT *refcnt, int *ret) return 1; } -#else -#pragma intrinsic(_InterlockedExchangeAdd) +static __inline int CRYPTO_GET_REF(CRYPTO_REF_COUNT *refcnt, int *ret) +{ + *ret = _InterlockedExchangeAdd_acq((void *)&refcnt->val, 0); + return 1; +} -static __inline bool CRYPTO_UP_REF(CRYPTO_REF_COUNT *refcnt, int *ret) +#else +#if !defined(_WIN32_WCE) +#pragma intrinsic(_InterlockedExchangeAdd) +#else +#if _WIN32_WCE >= 0x600 +extern long __cdecl _InterlockedExchangeAdd(long volatile *, long); +#else +/* under Windows CE we still have old-style Interlocked* functions */ +extern long __cdecl InterlockedExchangeAdd(long volatile *, long); +#define _InterlockedExchangeAdd InterlockedExchangeAdd +#endif +#endif + +static __inline int CRYPTO_UP_REF(CRYPTO_REF_COUNT *refcnt, int *ret) { *ret = _InterlockedExchangeAdd(&refcnt->val, 1) + 1; - return true; + return 1; } static __inline int CRYPTO_DOWN_REF(CRYPTO_REF_COUNT *refcnt, int *ret) @@ -152,6 +184,12 @@ static __inline int CRYPTO_DOWN_REF(CRYPTO_REF_COUNT *refcnt, int *ret) return 1; } +static __inline int CRYPTO_GET_REF(CRYPTO_REF_COUNT *refcnt, int *ret) +{ + *ret = _InterlockedExchangeAdd(&refcnt->val, 0); + return 1; +} + #endif #endif @@ -173,10 +211,10 @@ typedef struct { #ifdef OPENSSL_THREADS -static ossl_unused ossl_inline bool CRYPTO_UP_REF(CRYPTO_REF_COUNT *refcnt, +static ossl_unused ossl_inline int CRYPTO_UP_REF(CRYPTO_REF_COUNT *refcnt, int *ret) { - return CRYPTO_atomic_add(&refcnt->val, 1, ret, refcnt->lock) ? true : false; + return CRYPTO_atomic_add(&refcnt->val, 1, ret, refcnt->lock); } static ossl_unused ossl_inline int CRYPTO_DOWN_REF(CRYPTO_REF_COUNT *refcnt, @@ -185,6 +223,12 @@ static ossl_unused ossl_inline int CRYPTO_DOWN_REF(CRYPTO_REF_COUNT *refcnt, return CRYPTO_atomic_add(&refcnt->val, -1, ret, refcnt->lock); } +static ossl_unused ossl_inline int CRYPTO_GET_REF(CRYPTO_REF_COUNT *refcnt, + int *ret) +{ + return CRYPTO_atomic_load_int(&refcnt->val, ret, refcnt->lock); +} + #define CRYPTO_NEW_FREE_DEFINED 1 static ossl_unused ossl_inline int CRYPTO_NEW_REF(CRYPTO_REF_COUNT *refcnt, int n) { @@ -205,12 +249,12 @@ static ossl_unused ossl_inline void CRYPTO_FREE_REF(CRYPTO_REF_COUNT *refcnt) #else /* OPENSSL_THREADS */ -static ossl_unused ossl_inline bool CRYPTO_UP_REF(CRYPTO_REF_COUNT *refcnt, +static ossl_unused ossl_inline int CRYPTO_UP_REF(CRYPTO_REF_COUNT *refcnt, int *ret) { refcnt->val++; *ret = refcnt->val; - return true; + return 1; } static ossl_unused ossl_inline int CRYPTO_DOWN_REF(CRYPTO_REF_COUNT *refcnt, @@ -221,6 +265,13 @@ static ossl_unused ossl_inline int CRYPTO_DOWN_REF(CRYPTO_REF_COUNT *refcnt, return 1; } +static ossl_unused ossl_inline int CRYPTO_GET_REF(CRYPTO_REF_COUNT *refcnt, + int *ret) +{ + *ret = refcnt->val; + return 1; +} + #endif /* OPENSSL_THREADS */ #endif diff --git a/include/internal/ring_buf.h b/include/internal/ring_buf.h index 19c13817fd..cc70bfaeac 100644 --- a/include/internal/ring_buf.h +++ b/include/internal/ring_buf.h @@ -11,12 +11,7 @@ #define OSSL_INTERNAL_RING_BUF_H #pragma once -#include -#include - #include /* For 'ossl_inline' */ -#include - #include "internal/safe_math.h" /* diff --git a/include/internal/sha3.h b/include/internal/sha3.h index 0e0ab76fb5..d67aa1e19f 100644 --- a/include/internal/sha3.h +++ b/include/internal/sha3.h @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -17,14 +17,14 @@ #define KECCAK1600_WIDTH 1600 #define SHA3_MDSIZE(bitlen) (bitlen / 8) -#define CSHAKE_KECCAK_MDSIZE(bitlen) 2 * (bitlen / 8) +#define KMAC_MDSIZE(bitlen) 2 * (bitlen / 8) #define SHA3_BLOCKSIZE(bitlen) (KECCAK1600_WIDTH - bitlen * 2) / 8 typedef struct keccak_st KECCAK1600_CTX; -typedef size_t(sha3_absorb_fn)(KECCAK1600_CTX *vctx, const unsigned char *in, size_t inlen); -typedef int(sha3_final_fn)(KECCAK1600_CTX *vctx, unsigned char *out, size_t outlen); -typedef int(sha3_squeeze_fn)(KECCAK1600_CTX *vctx, unsigned char *out, size_t outlen); +typedef size_t(sha3_absorb_fn)(void *vctx, const void *in, size_t inlen); +typedef int(sha3_final_fn)(void *vctx, unsigned char *out, size_t outlen); +typedef int(sha3_squeeze_fn)(void *vctx, unsigned char *out, size_t outlen); typedef struct prov_sha3_meth_st { sha3_absorb_fn *absorb; @@ -48,92 +48,15 @@ struct keccak_st { int xof_state; }; -KECCAK1600_CTX *ossl_shake256_new(void); void ossl_sha3_reset(KECCAK1600_CTX *ctx); int ossl_sha3_init(KECCAK1600_CTX *ctx, unsigned char pad, size_t bitlen); int ossl_keccak_init(KECCAK1600_CTX *ctx, unsigned char pad, size_t typelen, size_t mdlen); - -int ossl_sha3_absorb(KECCAK1600_CTX *ctx, const unsigned char *in, size_t len); +int ossl_sha3_update(KECCAK1600_CTX *ctx, const void *_inp, size_t len); int ossl_sha3_final(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen); int ossl_sha3_squeeze(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen); -size_t ossl_sha3_absorb_default(KECCAK1600_CTX *ctx, const unsigned char *inp, size_t len); -int ossl_sha3_final_default(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen); -int ossl_shake_squeeze_default(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen); - size_t SHA3_absorb(uint64_t A[5][5], const unsigned char *inp, size_t len, size_t r); -/* Multi-buffer (x4) Keccak-f[1600] context and API */ -#if defined(KECCAK1600_ASM) \ - && (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)) \ - && !defined(OPENSSL_NO_ASM) - -/* Runtime capability check for AVX512VL */ -int SHA3_avx512vl_capable(void); - -/* Context for 4-way parallel SHAKE operations */ -typedef struct { - /* 4 interleaved Keccak states (800 bytes) - plus 8 bytes to store the number of - already absorbed or not yet squeezed bytes */ - uint64_t A[(25 * 4) + 1]; - size_t rate; /* Rate in bytes: 168 (SHAKE-128) or 136 (SHAKE-256) */ - unsigned finalized; /* Has finalize been called? 0=no, 1=yes */ -} KECCAK1600_X4_AVX512VL_CTX; - -/* SHAKE-128 x4 incremental API */ -void ossl_sha3_shake128_x4_inc_init_avx512vl(KECCAK1600_X4_AVX512VL_CTX *ctx); - -void ossl_sha3_shake128_x4_inc_absorb_avx512vl( - KECCAK1600_X4_AVX512VL_CTX *ctx, - const void *in0, const void *in1, - const void *in2, const void *in3, - size_t inlen); - -void ossl_sha3_shake128_x4_inc_cleanup_avx512vl(KECCAK1600_X4_AVX512VL_CTX *ctx); - -void ossl_sha3_shake128_x4_inc_squeeze_avx512vl( - void *out0, void *out1, - void *out2, void *out3, - size_t outlen, - KECCAK1600_X4_AVX512VL_CTX *ctx); - -/* SHAKE-256 x4 incremental API */ -void ossl_sha3_shake256_x4_inc_init_avx512vl(KECCAK1600_X4_AVX512VL_CTX *ctx); - -void ossl_sha3_shake256_x4_inc_absorb_avx512vl( - KECCAK1600_X4_AVX512VL_CTX *ctx, - const void *in0, const void *in1, - const void *in2, const void *in3, - size_t inlen); - -void ossl_sha3_shake256_x4_inc_cleanup_avx512vl(KECCAK1600_X4_AVX512VL_CTX *ctx); - -void ossl_sha3_shake256_x4_inc_squeeze_avx512vl( - void *out0, void *out1, - void *out2, void *out3, - size_t outlen, - KECCAK1600_X4_AVX512VL_CTX *ctx); - -/* Single-call SHAKE x4 APIs (wrapper functions) */ -void ossl_sha3_shake128_x4_avx512vl( - void *out0, void *out1, - void *out2, void *out3, - size_t outlen, - const void *in0, const void *in1, - const void *in2, const void *in3, - size_t inlen); - -void ossl_sha3_shake256_x4_avx512vl( - void *out0, void *out1, - void *out2, void *out3, - size_t outlen, - const void *in0, const void *in1, - const void *in2, const void *in3, - size_t inlen); - -#endif /* KECCAK1600_ASM && x86_64 && !OPENSSL_NO_ASM */ - #endif /* OSSL_INTERNAL_SHA3_H */ diff --git a/include/internal/skey.h b/include/internal/skey.h index b511af8c32..a4b6c6e6a9 100644 --- a/include/internal/skey.h +++ b/include/internal/skey.h @@ -10,10 +10,6 @@ #ifndef OSSL_CRYPTO_SKEY_H #define OSSL_CRYPTO_SKEY_H -#include - -#include - /* Known symmetric key type definitions */ #define SKEY_TYPE_GENERIC 1 /* generic bytes container unknown key types */ #define SKEY_TYPE_AES 2 /* AES keys */ diff --git a/include/internal/sm3.h b/include/internal/sm3.h index 0faf544942..32a05ae9ef 100644 --- a/include/internal/sm3.h +++ b/include/internal/sm3.h @@ -13,8 +13,6 @@ #define OSSL_INTERNAL_SM3_H #pragma once -#include - #include #ifdef OPENSSL_NO_SM3 @@ -22,7 +20,7 @@ #endif #define SM3_DIGEST_LENGTH 32 -typedef unsigned int SM3_WORD; +#define SM3_WORD unsigned int #define SM3_CBLOCK 64 #define SM3_LBLOCK (SM3_CBLOCK / 4) diff --git a/include/internal/sockets.h b/include/internal/sockets.h index 1da34aa7b0..877bbd7145 100644 --- a/include/internal/sockets.h +++ b/include/internal/sockets.h @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -37,11 +37,18 @@ #include #include #include +#elif defined(_WIN32_WCE) && _WIN32_WCE < 410 +#define getservbyname _masked_declaration_getservbyname #endif #if !defined(IPPROTO_IP) /* winsock[2].h was included already? */ #include "internal/e_winsock.h" #endif +#ifdef getservbyname +/* this is used to be wcecompat/include/winsock_extras.h */ +#undef getservbyname +struct servent *PASCAL getservbyname(const char *, const char *); +#endif #ifdef _WIN64 /* @@ -66,15 +73,6 @@ #define SHUT_RDWR SD_BOTH #endif -/* - * Recent MINGW versions use Windows-style unsigned INVALID_SOCKET. - * Since OpenSSL uses int, this only silences an already-ignored warning. - */ -#if defined(__MINGW32__) && defined(INVALID_SOCKET) -#undef INVALID_SOCKET -#define INVALID_SOCKET (INT_PTR)(~0) -#endif - #else #if defined(__APPLE__) /* @@ -178,40 +176,23 @@ typedef size_t socklen_t; /* Currently appears to be missing on VMS */ #define get_last_socket_error_is_eintr() (get_last_socket_error() == WSAEINTR) #define readsocket(s, b, n) recv((s), (b), (n), 0) #define writesocket(s, b, n) send((s), (b), (n), 0) -#define writesocket_ex(s, b, n, f) send((s), (b), (n), (f)) #elif defined(__DJGPP__) #define closesocket(s) close_s(s) #define readsocket(s, b, n) read_s(s, b, n) #define writesocket(s, b, n) send(s, b, n, 0) -#define writesocket_ex(s, b, n, f) send(s, b, n, f) #elif defined(OPENSSL_SYS_VMS) #define ioctlsocket(a, b, c) ioctl(a, b, c) #define closesocket(s) close(s) #define readsocket(s, b, n) recv((s), (b), (n), 0) #define writesocket(s, b, n) send((s), (b), (n), 0) -#define writesocket_ex(s, b, n, f) send((s), (b), (n), (f)) #elif defined(OPENSSL_SYS_VXWORKS) #define ioctlsocket(a, b, c) ioctl((a), (b), (int)(c)) #define closesocket(s) close(s) #define readsocket(s, b, n) read((s), (b), (n)) #define writesocket(s, b, n) write((s), (char *)(b), (n)) -static ossl_inline int writesocket_ex(int s, char *b, int n, int f) -{ - if (f == 0) - return writesocket(s, b, n); - errno = EINVAL; - return -1; -} #elif defined(OPENSSL_SYS_TANDEM) #define readsocket(s, b, n) read((s), (b), (n)) #define writesocket(s, b, n) write((s), (b), (n)) -static ossl_inline int writesocket_ex(int s, const void *b, int n, int f) -{ - if (f == 0) - return writesocket(s, b, n); - errno = EINVAL; - return -1; -} #define ioctlsocket(a, b, c) ioctl(a, b, c) #define closesocket(s) close(s) #else @@ -219,11 +200,10 @@ static ossl_inline int writesocket_ex(int s, const void *b, int n, int f) #define closesocket(s) close(s) #define readsocket(s, b, n) read((s), (b), (n)) #define writesocket(s, b, n) write((s), (b), (n)) -#define writesocket_ex(s, b, n, f) ((f) == 0) ? write((s), (b), (n)) : send((s), (b), (n), (f)) #endif /* also in apps/include/apps.h */ -#if defined(OPENSSL_SYS_WIN32) +#if defined(OPENSSL_SYS_WIN32) || defined(OPENSSL_SYS_WINCE) #define openssl_fdset(a, b) FD_SET((unsigned int)(a), b) #else #define openssl_fdset(a, b) FD_SET(a, b) diff --git a/include/internal/ssl.h b/include/internal/ssl.h index 5de1399a98..d56ed6e6dd 100644 --- a/include/internal/ssl.h +++ b/include/internal/ssl.h @@ -1,5 +1,5 @@ /* - * Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -23,9 +23,4 @@ int ossl_ssl_get_error(const SSL *s, int i, int check_err); /* Set if this is our QUIC handshake layer */ #define TLS1_FLAGS_QUIC_INTERNAL 0x4000 -/* We limit the number of key shares sent */ -#ifndef OPENSSL_CLIENT_MAX_KEY_SHARES -#define OPENSSL_CLIENT_MAX_KEY_SHARES 4 -#endif - #endif diff --git a/include/internal/ssl3_cbc.h b/include/internal/ssl3_cbc.h index 84c2ccb813..4c102693a0 100644 --- a/include/internal/ssl3_cbc.h +++ b/include/internal/ssl3_cbc.h @@ -7,12 +7,16 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_INTERNAL_SSL3_CBC_H) -#define OSSL_INTERNAL_SSL3_CBC_H - #include /* tls_pad.c */ +int ssl3_cbc_remove_padding_and_mac(size_t *reclen, + size_t origreclen, + unsigned char *recdata, + unsigned char **mac, + int *alloced, + size_t block_size, size_t mac_size, + OSSL_LIB_CTX *libctx); int tls1_cbc_remove_padding_and_mac(size_t *reclen, size_t origreclen, @@ -33,6 +37,4 @@ __owur int ssl3_cbc_digest_record(const EVP_MD *md, size_t data_size, size_t data_plus_mac_plus_padding_size, const unsigned char *mac_secret, - size_t mac_secret_length); - -#endif /* !defined(OSSL_INTERNAL_SSL3_CBC_H) */ + size_t mac_secret_length, char is_sslv3); diff --git a/include/internal/sslconf.h b/include/internal/sslconf.h index a016613a57..49da923059 100644 --- a/include/internal/sslconf.h +++ b/include/internal/sslconf.h @@ -11,10 +11,6 @@ #define OSSL_INTERNAL_SSLCONF_H #pragma once -#include - -#include - typedef struct ssl_conf_cmd_st SSL_CONF_CMD; /* diff --git a/include/internal/statem.h b/include/internal/statem.h index 990100c4dc..a41ed32270 100644 --- a/include/internal/statem.h +++ b/include/internal/statem.h @@ -1,5 +1,5 @@ /* - * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -9,11 +9,6 @@ #ifndef OSSL_INTERNAL_STATEM_H #define OSSL_INTERNAL_STATEM_H -#include - -#include -#include - /***************************************************************************** * * * These enums should be considered PRIVATE to the state machine. No * @@ -86,12 +81,6 @@ typedef enum { CON_FUNC_DONT_SEND } CON_FUNC_RETURN; -typedef enum { - ERROR_STATE_NOERROR = 0, - ERROR_STATE_SSL, - ERROR_STATE_SYSCALL -} ERROR_STATE; - typedef int (*ossl_statem_mutate_handshake_cb)(const unsigned char *msgin, size_t inlen, unsigned char **msgout, @@ -117,7 +106,6 @@ struct ossl_statem_st { OSSL_HANDSHAKE_STATE hand_state; /* The handshake state requested by an API call (e.g. HelloRequest) */ OSSL_HANDSHAKE_STATE request_state; - ERROR_STATE error_state; int in_init; int read_state_first_init; /* true when we are actually in SSL_accept() or SSL_connect() */ diff --git a/include/internal/thread_arch.h b/include/internal/thread_arch.h index 73e6e0d1e7..d7fc08a8af 100644 --- a/include/internal/thread_arch.h +++ b/include/internal/thread_arch.h @@ -11,9 +11,12 @@ #define OSSL_INTERNAL_THREAD_ARCH_H #include #include -#include "internal/e_os.h" #include "internal/time.h" +#if defined(_WIN32) +#include +#endif + #if defined(OPENSSL_THREADS) && defined(OPENSSL_SYS_UNIX) #define OPENSSL_THREADS_POSIX #elif defined(OPENSSL_THREADS) && defined(OPENSSL_SYS_VMS) diff --git a/include/internal/threads_common.h b/include/internal/threads_common.h index e32257d630..660fb1e5c6 100644 --- a/include/internal/threads_common.h +++ b/include/internal/threads_common.h @@ -1,5 +1,5 @@ /* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -10,24 +10,6 @@ #ifndef _CRYPTO_THREADS_COMMON_H_ #define _CRYPTO_THREADS_COMMON_H_ -#include - -#if defined(__clang__) && defined(__has_feature) -#if __has_feature(thread_sanitizer) -#define __SANITIZE_THREAD__ -#endif -#endif - -#if defined(__SANITIZE_THREAD__) -#include -extern void AnnotateBenignRaceSized(const char *f, int l, - const volatile void *mem, unsigned int size, const char *desc); -#define TSAN_BENIGN(x, desc) \ - AnnotateBenignRaceSized(__FILE__, __LINE__, (x), sizeof(*(x)), desc); -#else -#define TSAN_BENIGN(x, desc) -#endif - typedef enum { CRYPTO_THREAD_LOCAL_RCU_KEY = 0, CRYPTO_THREAD_LOCAL_DRBG_PRIV_KEY, @@ -50,46 +32,4 @@ int CRYPTO_THREAD_set_local_ex(CRYPTO_THREAD_LOCAL_KEY_ID id, void CRYPTO_THREAD_clean_local(void); -/* Do atomics work? */ - -#if defined(__apple_build_version__) && __apple_build_version__ < 6000000 -/* - * OS/X 10.7 and 10.8 had a weird version of clang which has __ATOMIC_ACQUIRE and - * __ATOMIC_ACQ_REL but which expects only one parameter for __atomic_is_lock_free() - * rather than two which has signature __atomic_is_lock_free(sizeof(_Atomic(T))). - * All of this makes impossible to use __atomic_is_lock_free here. - * - * See: https://github.com/llvm/llvm-project/commit/a4c2602b714e6c6edb98164550a5ae829b2de760 - */ -#define BROKEN_CLANG_ATOMICS -#endif - -/* - * VC++ 2008 or earlier x86 compilers do not have an inline implementation - * of InterlockedOr64 for 32bit and will fail to run on Windows XP 32bit. - * https://docs.microsoft.com/en-us/cpp/intrinsics/interlockedor-intrinsic-functions#requirements - * To work around this problem, we implement a manual locking mechanism for - * only VC++ 2008 or earlier x86 compilers. - */ - -#if defined(_MSC_VER) -#if (!defined(_M_IX86) || _MSC_VER > 1600) -#define OSSL_USE_INTERLOCKEDOR64 -#endif -#elif defined(__MINGW64__) -#define OSSL_USE_INTERLOCKEDOR64 -#endif - -#if defined(__GNUC__) && defined(__ATOMIC_ACQUIRE) && !defined(BROKEN_CLANG_ATOMICS) \ - && !defined(USE_ATOMIC_FALLBACKS) -#define OSSL_USE_GCC_ATOMICS -#elif defined(__sun) && (defined(__SunOS_5_10) || defined(__SunOS_5_11)) -#define OSSL_USE_SOLARIS_ATOMICS -#endif - -/* Allow us to know if atomics will be implemented with a fallback lock or not. */ -#if defined(OSSL_USE_GCC_ATOMICS) || defined(OSSL_USE_SOLARIS_ATOMICS) || defined(OSSL_USE_INTERLOCKEDOR64) -#define OSSL_ATOMICS_LOCKLESS -#endif - #endif diff --git a/include/internal/time.h b/include/internal/time.h index c6f4c63335..2a54c491f1 100644 --- a/include/internal/time.h +++ b/include/internal/time.h @@ -54,7 +54,9 @@ typedef struct { OSSL_SAFE_MATH_UNSIGNED(time, uint64_t) /* Convert a tick count into a time */ -static ossl_unused ossl_inline OSSL_TIME ossl_ticks2time(uint64_t ticks) +static ossl_unused ossl_inline + OSSL_TIME + ossl_ticks2time(uint64_t ticks) { OSSL_TIME r; @@ -63,7 +65,9 @@ static ossl_unused ossl_inline OSSL_TIME ossl_ticks2time(uint64_t ticks) } /* Convert a time to a tick count */ -static ossl_unused ossl_inline uint64_t ossl_time2ticks(OSSL_TIME t) +static ossl_unused ossl_inline + uint64_t + ossl_time2ticks(OSSL_TIME t) { return t.t; } @@ -72,12 +76,16 @@ static ossl_unused ossl_inline uint64_t ossl_time2ticks(OSSL_TIME t) OSSL_TIME ossl_time_now(void); /* The beginning and end of the time range */ -static ossl_unused ossl_inline OSSL_TIME ossl_time_zero(void) +static ossl_unused ossl_inline + OSSL_TIME + ossl_time_zero(void) { return ossl_ticks2time(0); } -static ossl_unused ossl_inline OSSL_TIME ossl_time_infinite(void) +static ossl_unused ossl_inline + OSSL_TIME + ossl_time_infinite(void) { return ossl_ticks2time(~(uint64_t)0); } @@ -106,7 +114,9 @@ static ossl_unused ossl_inline struct timeval ossl_time_to_timeval(OSSL_TIME t) } /* Convert timeval to time */ -static ossl_unused ossl_inline OSSL_TIME ossl_time_from_timeval(struct timeval tv) +static ossl_unused ossl_inline + OSSL_TIME + ossl_time_from_timeval(struct timeval tv) { OSSL_TIME t; @@ -119,13 +129,17 @@ static ossl_unused ossl_inline OSSL_TIME ossl_time_from_timeval(struct timeval t } /* Convert OSSL_TIME to time_t */ -static ossl_unused ossl_inline time_t ossl_time_to_time_t(OSSL_TIME t) +static ossl_unused ossl_inline + time_t + ossl_time_to_time_t(OSSL_TIME t) { return (time_t)(t.t / OSSL_TIME_SECOND); } /* Convert time_t to OSSL_TIME */ -static ossl_unused ossl_inline OSSL_TIME ossl_time_from_time_t(time_t t) +static ossl_unused ossl_inline + OSSL_TIME + ossl_time_from_time_t(time_t t) { OSSL_TIME ot; @@ -156,7 +170,9 @@ static ossl_unused ossl_inline int ossl_time_is_infinite(OSSL_TIME t) return ossl_time_compare(t, ossl_time_infinite()) == 0; } -static ossl_unused ossl_inline OSSL_TIME ossl_time_add(OSSL_TIME a, OSSL_TIME b) +static ossl_unused ossl_inline + OSSL_TIME + ossl_time_add(OSSL_TIME a, OSSL_TIME b) { OSSL_TIME r; int err = 0; @@ -165,7 +181,9 @@ static ossl_unused ossl_inline OSSL_TIME ossl_time_add(OSSL_TIME a, OSSL_TIME b) return err ? ossl_time_infinite() : r; } -static ossl_unused ossl_inline OSSL_TIME ossl_time_subtract(OSSL_TIME a, OSSL_TIME b) +static ossl_unused ossl_inline + OSSL_TIME + ossl_time_subtract(OSSL_TIME a, OSSL_TIME b) { OSSL_TIME r; int err = 0; @@ -175,13 +193,17 @@ static ossl_unused ossl_inline OSSL_TIME ossl_time_subtract(OSSL_TIME a, OSSL_TI } /* Returns |a - b|. */ -static ossl_unused ossl_inline OSSL_TIME ossl_time_abs_difference(OSSL_TIME a, OSSL_TIME b) +static ossl_unused ossl_inline + OSSL_TIME + ossl_time_abs_difference(OSSL_TIME a, OSSL_TIME b) { return a.t > b.t ? ossl_time_subtract(a, b) : ossl_time_subtract(b, a); } -static ossl_unused ossl_inline OSSL_TIME ossl_time_multiply(OSSL_TIME a, uint64_t b) +static ossl_unused ossl_inline + OSSL_TIME + ossl_time_multiply(OSSL_TIME a, uint64_t b) { OSSL_TIME r; int err = 0; @@ -190,7 +212,9 @@ static ossl_unused ossl_inline OSSL_TIME ossl_time_multiply(OSSL_TIME a, uint64_ return err ? ossl_time_infinite() : r; } -static ossl_unused ossl_inline OSSL_TIME ossl_time_divide(OSSL_TIME a, uint64_t b) +static ossl_unused ossl_inline + OSSL_TIME + ossl_time_divide(OSSL_TIME a, uint64_t b) { OSSL_TIME r; int err = 0; @@ -199,7 +223,9 @@ static ossl_unused ossl_inline OSSL_TIME ossl_time_divide(OSSL_TIME a, uint64_t return err ? ossl_time_zero() : r; } -static ossl_unused ossl_inline OSSL_TIME ossl_time_muldiv(OSSL_TIME a, uint64_t b, uint64_t c) +static ossl_unused ossl_inline + OSSL_TIME + ossl_time_muldiv(OSSL_TIME a, uint64_t b, uint64_t c) { OSSL_TIME r; int err = 0; @@ -209,13 +235,17 @@ static ossl_unused ossl_inline OSSL_TIME ossl_time_muldiv(OSSL_TIME a, uint64_t } /* Return higher of the two given time values. */ -static ossl_unused ossl_inline OSSL_TIME ossl_time_max(OSSL_TIME a, OSSL_TIME b) +static ossl_unused ossl_inline + OSSL_TIME + ossl_time_max(OSSL_TIME a, OSSL_TIME b) { return a.t > b.t ? a : b; } /* Return the lower of the two given time values. */ -static ossl_unused ossl_inline OSSL_TIME ossl_time_min(OSSL_TIME a, OSSL_TIME b) +static ossl_unused ossl_inline + OSSL_TIME + ossl_time_min(OSSL_TIME a, OSSL_TIME b) { return a.t < b.t ? a : b; } diff --git a/include/internal/tlsgroups.h b/include/internal/tlsgroups.h index f12e142b9a..1fd41993ea 100644 --- a/include/internal/tlsgroups.h +++ b/include/internal/tlsgroups.h @@ -1,5 +1,5 @@ /* - * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -11,10 +11,6 @@ #define OSSL_INTERNAL_TLSGROUPS_H #pragma once -#include - -#include /* For 'ossl_inline' */ - #define OSSL_TLS_GROUP_ID_sect163k1 0x0001 #define OSSL_TLS_GROUP_ID_sect163r1 0x0002 #define OSSL_TLS_GROUP_ID_sect163r2 0x0003 @@ -55,7 +51,6 @@ #define OSSL_TLS_GROUP_ID_gc512A 0x0026 #define OSSL_TLS_GROUP_ID_gc512B 0x0027 #define OSSL_TLS_GROUP_ID_gc512C 0x0028 -#define OSSL_TLS_GROUP_ID_curveSM2 0x0029 #define OSSL_TLS_GROUP_ID_ffdhe2048 0x0100 #define OSSL_TLS_GROUP_ID_ffdhe3072 0x0101 #define OSSL_TLS_GROUP_ID_ffdhe4096 0x0102 @@ -67,25 +62,5 @@ #define OSSL_TLS_GROUP_ID_SecP256r1MLKEM768 0x11EB #define OSSL_TLS_GROUP_ID_X25519MLKEM768 0x11EC #define OSSL_TLS_GROUP_ID_SecP384r1MLKEM1024 0x11ED -#define OSSL_TLS_GROUP_ID_curveSM2MLKEM768 0x11EE - -/* - * RFC 7919: "Codepoints ... between 256 and 511, inclusive ... are set aside - * for FFDHE groups" - */ -#define OSSL_TLS_GROUP_ID_FFDHE_START 0x0100 /* inclusive */ -#define OSSL_TLS_GROUP_ID_FFDHE_END 0x01FF /* inclusive */ - -static ossl_inline int is_ecdhe_group(const uint16_t group_id) -{ - /* This includes the usual EC groups, and also ECX, GOST ... */ - return group_id < OSSL_TLS_GROUP_ID_FFDHE_START; -} - -static ossl_inline int is_ffdhe_group(const uint16_t group_id) -{ - return group_id >= OSSL_TLS_GROUP_ID_FFDHE_START - && group_id <= OSSL_TLS_GROUP_ID_FFDHE_END; -} #endif diff --git a/include/internal/tlssigalgs.h b/include/internal/tlssigalgs.h deleted file mode 100644 index f5aea80f64..0000000000 --- a/include/internal/tlssigalgs.h +++ /dev/null @@ -1,121 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#ifndef OSSL_INTERNAL_TLSSIGALGS_H -#define OSSL_INTERNAL_TLSSIGALGS_H -#pragma once - -/* Sigalgs values */ -#define TLSEXT_SIGALG_ecdsa_secp256r1_sha256 0x0403 -#define TLSEXT_SIGALG_ecdsa_secp384r1_sha384 0x0503 -#define TLSEXT_SIGALG_ecdsa_secp521r1_sha512 0x0603 -#define TLSEXT_SIGALG_ecdsa_sha224 0x0303 -#define TLSEXT_SIGALG_ecdsa_sha1 0x0203 -#define TLSEXT_SIGALG_rsa_pss_rsae_sha256 0x0804 -#define TLSEXT_SIGALG_rsa_pss_rsae_sha384 0x0805 -#define TLSEXT_SIGALG_rsa_pss_rsae_sha512 0x0806 -#define TLSEXT_SIGALG_rsa_pss_pss_sha256 0x0809 -#define TLSEXT_SIGALG_rsa_pss_pss_sha384 0x080a -#define TLSEXT_SIGALG_rsa_pss_pss_sha512 0x080b -#define TLSEXT_SIGALG_rsa_pkcs1_sha256 0x0401 -#define TLSEXT_SIGALG_rsa_pkcs1_sha384 0x0501 -#define TLSEXT_SIGALG_rsa_pkcs1_sha512 0x0601 -#define TLSEXT_SIGALG_rsa_pkcs1_sha224 0x0301 -#define TLSEXT_SIGALG_rsa_pkcs1_sha1 0x0201 -#define TLSEXT_SIGALG_dsa_sha256 0x0402 -#define TLSEXT_SIGALG_dsa_sha384 0x0502 -#define TLSEXT_SIGALG_dsa_sha512 0x0602 -#define TLSEXT_SIGALG_dsa_sha224 0x0302 -#define TLSEXT_SIGALG_dsa_sha1 0x0202 -#define TLSEXT_SIGALG_gostr34102012_256_intrinsic 0x0840 -#define TLSEXT_SIGALG_gostr34102012_512_intrinsic 0x0841 -#define TLSEXT_SIGALG_gostr34102012_256_gostr34112012_256 0xeeee -#define TLSEXT_SIGALG_gostr34102012_512_gostr34112012_512 0xefef -#define TLSEXT_SIGALG_gostr34102001_gostr3411 0xeded - -#define TLSEXT_SIGALG_sm2sig_sm3 0x0708 -#define TLSEXT_SIGALG_ed25519 0x0807 -#define TLSEXT_SIGALG_ed448 0x0808 -#define TLSEXT_SIGALG_ecdsa_brainpoolP256r1_sha256 0x081a -#define TLSEXT_SIGALG_ecdsa_brainpoolP384r1_sha384 0x081b -#define TLSEXT_SIGALG_ecdsa_brainpoolP512r1_sha512 0x081c -#define TLSEXT_SIGALG_mldsa44 0x0904 -#define TLSEXT_SIGALG_mldsa65 0x0905 -#define TLSEXT_SIGALG_mldsa87 0x0906 - -#define TLSEXT_SIGALG_slhdsa_sha2_128s 0x0911 -#define TLSEXT_SIGALG_slhdsa_sha2_128f 0x0912 -#define TLSEXT_SIGALG_slhdsa_sha2_192s 0x0913 -#define TLSEXT_SIGALG_slhdsa_sha2_192f 0x0914 -#define TLSEXT_SIGALG_slhdsa_sha2_256s 0x0915 -#define TLSEXT_SIGALG_slhdsa_sha2_256f 0x0916 -#define TLSEXT_SIGALG_slhdsa_shake_128s 0x0917 -#define TLSEXT_SIGALG_slhdsa_shake_128f 0x0918 -#define TLSEXT_SIGALG_slhdsa_shake_192s 0x0919 -#define TLSEXT_SIGALG_slhdsa_shake_192f 0x091a -#define TLSEXT_SIGALG_slhdsa_shake_256s 0x091b -#define TLSEXT_SIGALG_slhdsa_shake_256f 0x091c - -/* Sigalgs names */ -#define TLSEXT_SIGALG_ecdsa_secp256r1_sha256_name "ecdsa_secp256r1_sha256" -#define TLSEXT_SIGALG_ecdsa_secp384r1_sha384_name "ecdsa_secp384r1_sha384" -#define TLSEXT_SIGALG_ecdsa_secp521r1_sha512_name "ecdsa_secp521r1_sha512" -#define TLSEXT_SIGALG_ecdsa_sha224_name "ecdsa_sha224" -#define TLSEXT_SIGALG_ecdsa_sha1_name "ecdsa_sha1" -#define TLSEXT_SIGALG_rsa_pss_rsae_sha256_name "rsa_pss_rsae_sha256" -#define TLSEXT_SIGALG_rsa_pss_rsae_sha384_name "rsa_pss_rsae_sha384" -#define TLSEXT_SIGALG_rsa_pss_rsae_sha512_name "rsa_pss_rsae_sha512" -#define TLSEXT_SIGALG_rsa_pss_pss_sha256_name "rsa_pss_pss_sha256" -#define TLSEXT_SIGALG_rsa_pss_pss_sha384_name "rsa_pss_pss_sha384" -#define TLSEXT_SIGALG_rsa_pss_pss_sha512_name "rsa_pss_pss_sha512" -#define TLSEXT_SIGALG_rsa_pkcs1_sha256_name "rsa_pkcs1_sha256" -#define TLSEXT_SIGALG_rsa_pkcs1_sha384_name "rsa_pkcs1_sha384" -#define TLSEXT_SIGALG_rsa_pkcs1_sha512_name "rsa_pkcs1_sha512" -#define TLSEXT_SIGALG_rsa_pkcs1_sha224_name "rsa_pkcs1_sha224" -#define TLSEXT_SIGALG_rsa_pkcs1_sha1_name "rsa_pkcs1_sha1" -#define TLSEXT_SIGALG_dsa_sha256_name "dsa_sha256" -#define TLSEXT_SIGALG_dsa_sha384_name "dsa_sha384" -#define TLSEXT_SIGALG_dsa_sha512_name "dsa_sha512" -#define TLSEXT_SIGALG_dsa_sha224_name "dsa_sha224" -#define TLSEXT_SIGALG_dsa_sha1_name "dsa_sha1" -#define TLSEXT_SIGALG_gostr34102012_256_intrinsic_name "gostr34102012_256" -#define TLSEXT_SIGALG_gostr34102012_512_intrinsic_name "gostr34102012_512" -#define TLSEXT_SIGALG_gostr34102012_256_intrinsic_alias "gost2012_256" -#define TLSEXT_SIGALG_gostr34102012_512_intrinsic_alias "gost2012_512" -#define TLSEXT_SIGALG_gostr34102012_256_gostr34112012_256_name "gost2012_256" -#define TLSEXT_SIGALG_gostr34102012_512_gostr34112012_512_name "gost2012_512" -#define TLSEXT_SIGALG_gostr34102001_gostr3411_name "gost2001_gost94" - -#define TLSEXT_SIGALG_sm2sig_sm3_name "sm2sig_sm3" -#define TLSEXT_SIGALG_ed25519_name "ed25519" -#define TLSEXT_SIGALG_ed448_name "ed448" -#define TLSEXT_SIGALG_ecdsa_brainpoolP256r1_sha256_name "ecdsa_brainpoolP256r1tls13_sha256" -#define TLSEXT_SIGALG_ecdsa_brainpoolP384r1_sha384_name "ecdsa_brainpoolP384r1tls13_sha384" -#define TLSEXT_SIGALG_ecdsa_brainpoolP512r1_sha512_name "ecdsa_brainpoolP512r1tls13_sha512" -#define TLSEXT_SIGALG_ecdsa_brainpoolP256r1_sha256_alias "ecdsa_brainpoolP256r1_sha256" -#define TLSEXT_SIGALG_ecdsa_brainpoolP384r1_sha384_alias "ecdsa_brainpoolP384r1_sha384" -#define TLSEXT_SIGALG_ecdsa_brainpoolP512r1_sha512_alias "ecdsa_brainpoolP512r1_sha512" -#define TLSEXT_SIGALG_mldsa44_name "mldsa44" -#define TLSEXT_SIGALG_mldsa65_name "mldsa65" -#define TLSEXT_SIGALG_mldsa87_name "mldsa87" - -#define TLSEXT_SIGALG_slhdsa_sha2_128s_name "slhdsa_sha2_128s" -#define TLSEXT_SIGALG_slhdsa_sha2_128f_name "slhdsa_sha2_128f" -#define TLSEXT_SIGALG_slhdsa_sha2_192s_name "slhdsa_sha2_192s" -#define TLSEXT_SIGALG_slhdsa_sha2_192f_name "slhdsa_sha2_192f" -#define TLSEXT_SIGALG_slhdsa_sha2_256s_name "slhdsa_sha2_256s" -#define TLSEXT_SIGALG_slhdsa_sha2_256f_name "slhdsa_sha2_256f" -#define TLSEXT_SIGALG_slhdsa_shake_128s_name "slhdsa_shake_128s" -#define TLSEXT_SIGALG_slhdsa_shake_128f_name "slhdsa_shake_128f" -#define TLSEXT_SIGALG_slhdsa_shake_192s_name "slhdsa_shake_192s" -#define TLSEXT_SIGALG_slhdsa_shake_192f_name "slhdsa_shake_192f" -#define TLSEXT_SIGALG_slhdsa_shake_256s_name "slhdsa_shake_256s" -#define TLSEXT_SIGALG_slhdsa_shake_256f_name "slhdsa_shake_256f" - -#endif diff --git a/include/internal/to_hex.h b/include/internal/to_hex.h index 4b3940800f..36f4671c66 100644 --- a/include/internal/to_hex.h +++ b/include/internal/to_hex.h @@ -11,8 +11,6 @@ #define OSSL_INTERNAL_TO_HEX_H #pragma once -#include - static ossl_inline size_t to_hex(char *buf, uint8_t n, const char hexdig[17]) { *buf++ = hexdig[(n >> 4) & 0xf]; diff --git a/include/internal/tsan_assist.h b/include/internal/tsan_assist.h index a4e87504a1..998c45170e 100644 --- a/include/internal/tsan_assist.h +++ b/include/internal/tsan_assist.h @@ -1,5 +1,5 @@ /* - * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2018-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -78,7 +78,7 @@ #endif #elif defined(_MSC_VER) && _MSC_VER >= 1200 \ - && (defined(_M_IX86) || defined(_M_AMD64) || defined(_M_X64) || defined(_M_ARM64) || (defined(_M_ARM) && _M_ARM >= 7)) + && (defined(_M_IX86) || defined(_M_AMD64) || defined(_M_X64) || defined(_M_ARM64) || (defined(_M_ARM) && _M_ARM >= 7 && !defined(_WIN32_WCE))) /* * There is subtle dependency on /volatile: command-line option. * "ms" implies same semantic as memory_order_acquire for loads and @@ -137,25 +137,7 @@ #define tsan_load(ptr) (*(ptr)) #define tsan_store(ptr, val) (*(ptr) = (val)) - -static ossl_inline ossl_unused int64_t tsan_add_fallback64(int64_t *ptr, int64_t n) -{ - int64_t old = *ptr; - *ptr = old + n; - return old; -} - -static ossl_inline ossl_unused int32_t tsan_add_fallback32(int32_t *ptr, int32_t n) -{ - int32_t old = *ptr; - *ptr = old + n; - return old; -} - -#define tsan_add(ptr, n) \ - (sizeof(*(ptr)) == 8 ? tsan_add_fallback64((int64_t *)(ptr), (n)) \ - : tsan_add_fallback32((int32_t *)(ptr), (n))) - +#define tsan_add(ptr, n) (*(ptr) += (n)) /* * Lack of tsan_ld_acq and tsan_ld_rel means that compiler support is not * sophisticated enough to support them. Code that relies on them should be diff --git a/include/internal/unicode.h b/include/internal/unicode.h index f09bfc7320..4ef53cd69c 100644 --- a/include/internal/unicode.h +++ b/include/internal/unicode.h @@ -11,13 +11,10 @@ #define OSSL_INTERNAL_UNICODE_H #pragma once -#include -#include - typedef enum { - SURROGATE_MIN = UINT32_C(0xd800), - SURROGATE_MAX = UINT32_C(0xdfff), - UNICODE_MAX = UINT32_C(0x10ffff), + SURROGATE_MIN = 0xd800UL, + SURROGATE_MAX = 0xdfffUL, + UNICODE_MAX = 0x10ffffUL, UNICODE_LIMIT } UNICODE_CONSTANTS; diff --git a/include/internal/zeroization.h b/include/internal/zeroization.h deleted file mode 100644 index d30baa869a..0000000000 --- a/include/internal/zeroization.h +++ /dev/null @@ -1,50 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* - * Utility functions for handling OPENSSL_PEDANTIC_ZEROIZATION. - * - * ISO 19790:2012/Cor.1:2015 7.9 requires cryptographic module to provide - * methods to zeroise all unprotected security sensitive parameters - * (which includes both Critical/Private and Public security parameters). - * - * To comply with these (arguably, unnecessarily onerous) requirements, - * freeing of public parameters is done via ossl_public_security_param_free() - * and ossl_public_security_param_bn_free() functions, and those implement - * the required behaviour if OPENSSL_PEDANTIC_ZEROIZATION is defined. - */ - -#ifndef OSSL_INTERNAL_ZEROIZATION_H -#define OSSL_INTERNAL_ZEROIZATION_H - -#include -#include -#include - -static ossl_unused ossl_inline void -ossl_public_param_free(void *ptr, size_t size) -{ -#ifdef OPENSSL_PEDANTIC_ZEROIZATION - OPENSSL_clear_free(ptr, size); -#else - OPENSSL_free(ptr); -#endif -} - -static ossl_unused ossl_inline void -ossl_public_bn_free(BIGNUM *bn) -{ -#ifdef OPENSSL_PEDANTIC_ZEROIZATION - BN_clear_free(bn); -#else - BN_free(bn); -#endif -} - -#endif /* OSSL_INTERNAL_ZEROIZATION_H */ diff --git a/include/openssl/aes.h b/include/openssl/aes.h index cb00f4b504..2b6c683988 100644 --- a/include/openssl/aes.h +++ b/include/openssl/aes.h @@ -1,5 +1,5 @@ /* - * Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2002-2020 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -47,10 +47,10 @@ typedef struct aes_key_st AES_KEY; #ifndef OPENSSL_NO_DEPRECATED_3_0 OSSL_DEPRECATEDIN_3_0 const char *AES_options(void); OSSL_DEPRECATEDIN_3_0 -int AES_set_encrypt_key(const unsigned char *userKey, int bits, +int AES_set_encrypt_key(const unsigned char *userKey, const int bits, AES_KEY *key); OSSL_DEPRECATEDIN_3_0 -int AES_set_decrypt_key(const unsigned char *userKey, int bits, +int AES_set_decrypt_key(const unsigned char *userKey, const int bits, AES_KEY *key); OSSL_DEPRECATEDIN_3_0 void AES_encrypt(const unsigned char *in, unsigned char *out, @@ -60,23 +60,23 @@ void AES_decrypt(const unsigned char *in, unsigned char *out, const AES_KEY *key); OSSL_DEPRECATEDIN_3_0 void AES_ecb_encrypt(const unsigned char *in, unsigned char *out, - const AES_KEY *key, int enc); + const AES_KEY *key, const int enc); OSSL_DEPRECATEDIN_3_0 void AES_cbc_encrypt(const unsigned char *in, unsigned char *out, size_t length, const AES_KEY *key, - unsigned char *ivec, int enc); + unsigned char *ivec, const int enc); OSSL_DEPRECATEDIN_3_0 void AES_cfb128_encrypt(const unsigned char *in, unsigned char *out, size_t length, const AES_KEY *key, - unsigned char *ivec, int *num, int enc); + unsigned char *ivec, int *num, const int enc); OSSL_DEPRECATEDIN_3_0 void AES_cfb1_encrypt(const unsigned char *in, unsigned char *out, size_t length, const AES_KEY *key, - unsigned char *ivec, int *num, int enc); + unsigned char *ivec, int *num, const int enc); OSSL_DEPRECATEDIN_3_0 void AES_cfb8_encrypt(const unsigned char *in, unsigned char *out, size_t length, const AES_KEY *key, - unsigned char *ivec, int *num, int enc); + unsigned char *ivec, int *num, const int enc); OSSL_DEPRECATEDIN_3_0 void AES_ofb128_encrypt(const unsigned char *in, unsigned char *out, size_t length, const AES_KEY *key, @@ -86,12 +86,12 @@ void AES_ofb128_encrypt(const unsigned char *in, unsigned char *out, OSSL_DEPRECATEDIN_3_0 void AES_ige_encrypt(const unsigned char *in, unsigned char *out, size_t length, const AES_KEY *key, - unsigned char *ivec, int enc); + unsigned char *ivec, const int enc); /* NB: the IV is _four_ blocks long */ OSSL_DEPRECATEDIN_3_0 void AES_bi_ige_encrypt(const unsigned char *in, unsigned char *out, size_t length, const AES_KEY *key, const AES_KEY *key2, - const unsigned char *ivec, int enc); + const unsigned char *ivec, const int enc); OSSL_DEPRECATEDIN_3_0 int AES_wrap_key(AES_KEY *key, const unsigned char *iv, unsigned char *out, const unsigned char *in, diff --git a/include/openssl/asn1.h.in b/include/openssl/asn1.h.in index 440a6b3766..72c20f76d7 100644 --- a/include/openssl/asn1.h.in +++ b/include/openssl/asn1.h.in @@ -1,7 +1,7 @@ /* * {- join("\n * ", @autowarntext) -} * - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -138,8 +138,42 @@ extern "C" { -} /* clang-format on */ +#define ASN1_STRING_FLAG_BITS_LEFT 0x08 /* Set if 0x07 has bits left value */ +/* + * This indicates that the ASN1_STRING is not a real value but just a place + * holder for the location where indefinite length constructed data should be + * inserted in the memory buffer + */ +#define ASN1_STRING_FLAG_NDEF 0x010 + +/* + * This flag is used by the CMS code to indicate that a string is not + * complete and is a place holder for content when it had all been accessed. + * The flag will be reset when content has been written to it. + */ + +#define ASN1_STRING_FLAG_CONT 0x020 +/* + * This flag is used by ASN1 code to indicate an ASN1_STRING is an MSTRING + * type. + */ +#define ASN1_STRING_FLAG_MSTRING 0x040 +/* String is embedded and only content should be freed */ +#define ASN1_STRING_FLAG_EMBED 0x080 +/* String should be parsed in RFC 5280's time format */ +#define ASN1_STRING_FLAG_X509_TIME 0x100 /* This is the base type that holds just about everything :-) */ -struct asn1_string_st; +struct asn1_string_st { + int length; + int type; + unsigned char *data; + /* + * The value of the following field depends on the type being held. It + * is mostly being used for BIT_STRING so if the input data has a + * non-zero 'unused bits' value, it will be handled correctly + */ + long flags; +}; /* * ASN1_ENCODING structure: this is used to save the received encoding of an @@ -199,10 +233,7 @@ struct asn1_string_table_st { */ typedef struct ASN1_TEMPLATE_st ASN1_TEMPLATE; typedef struct ASN1_TLC_st ASN1_TLC; -/* - * This is deliberately used as an opaque pointer to a structure that - * is never defined. In other words it will behave like void * - */ +/* This is just an opaque pointer */ typedef struct ASN1_VALUE_st ASN1_VALUE; /* Declare ASN1 functions: the implement macro is in asn1t.h */ @@ -521,11 +552,7 @@ void *ASN1_TYPE_unpack_sequence(const ASN1_ITEM *it, const ASN1_TYPE *t); -} /* clang-format on */ -#ifndef OPENSSL_NO_DEPRECATED_4_0 -OSSL_DEPRECATEDIN_4_0 ASN1_OBJECT *ASN1_OBJECT_new(void); -#endif /* OPENSSL_NO_DEPRECATED_4_0 */ -void ASN1_OBJECT_free(ASN1_OBJECT *a); -DECLARE_ASN1_ENCODE_FUNCTIONS_name_attr(extern, ASN1_OBJECT, ASN1_OBJECT) +DECLARE_ASN1_FUNCTIONS(ASN1_OBJECT) ASN1_STRING *ASN1_STRING_new(void); void ASN1_STRING_free(ASN1_STRING *a); @@ -533,23 +560,14 @@ void ASN1_STRING_clear_free(ASN1_STRING *a); int ASN1_STRING_copy(ASN1_STRING *dst, const ASN1_STRING *str); DECLARE_ASN1_DUP_FUNCTION(ASN1_STRING) ASN1_STRING *ASN1_STRING_type_new(int type); -ASN1_STRING *ASN1_STRING_new_not_owned(int type, const uint8_t *data, - size_t length); int ASN1_STRING_cmp(const ASN1_STRING *a, const ASN1_STRING *b); /* * Since this is used to store all sorts of things, via macros, for now, * make its data void * */ -#if !defined(OPENSSL_NO_DEPRECATED_4_1) -OSSL_DEPRECATEDIN_4_1_FOR(" Use ASN1_STRING_set_data() or ASN1_STRING_set_string() instead.") int ASN1_STRING_set(ASN1_STRING *str, const void *data, int len); -OSSL_DEPRECATEDIN_4_1_FOR(" Use ASN1_STRING_length_ex() instead.") -int ASN1_STRING_length(const ASN1_STRING *x); -#endif /* !defined(OPENSSL_NO_DEPRECATED_4_1) */ void ASN1_STRING_set0(ASN1_STRING *str, void *data, int len); -int ASN1_STRING_set_data(ASN1_STRING *str, const uint8_t *data, size_t len); -int ASN1_STRING_set_string(ASN1_STRING *str, const char *cstring); -size_t ASN1_STRING_length_ex(const ASN1_STRING *x); +int ASN1_STRING_length(const ASN1_STRING *x); #ifndef OPENSSL_NO_DEPRECATED_3_0 OSSL_DEPRECATEDIN_3_0 void ASN1_STRING_length_set(ASN1_STRING *x, int n); #endif @@ -557,27 +575,17 @@ int ASN1_STRING_type(const ASN1_STRING *x); const unsigned char *ASN1_STRING_get0_data(const ASN1_STRING *x); DECLARE_ASN1_FUNCTIONS(ASN1_BIT_STRING) -#ifndef OPENSSL_NO_DEPRECATED_4_1 -OSSL_DEPRECATEDIN_4_1_FOR("use ASN1_BIT_STRING_set1()") -int ASN1_BIT_STRING_set(ASN1_BIT_STRING *a, - unsigned char *d, int length); -#endif +int ASN1_BIT_STRING_set(ASN1_BIT_STRING *a, unsigned char *d, int length); int ASN1_BIT_STRING_set_bit(ASN1_BIT_STRING *a, int n, int value); int ASN1_BIT_STRING_get_bit(const ASN1_BIT_STRING *a, int n); int ASN1_BIT_STRING_check(const ASN1_BIT_STRING *a, const unsigned char *flags, int flags_len); -#if !defined(OPENSSL_NO_DEPRECATED_4_1) -OSSL_DEPRECATEDIN_4_1 int ASN1_BIT_STRING_name_print(BIO *out, ASN1_BIT_STRING *bs, +int ASN1_BIT_STRING_name_print(BIO *out, ASN1_BIT_STRING *bs, BIT_STRING_BITNAME *tbl, int indent); -OSSL_DEPRECATEDIN_4_1 int ASN1_BIT_STRING_num_asc(const char *name, BIT_STRING_BITNAME *tbl); -OSSL_DEPRECATEDIN_4_1 int ASN1_BIT_STRING_set_asc(ASN1_BIT_STRING *bs, const char *name, int value, +int ASN1_BIT_STRING_num_asc(const char *name, BIT_STRING_BITNAME *tbl); +int ASN1_BIT_STRING_set_asc(ASN1_BIT_STRING *bs, const char *name, int value, BIT_STRING_BITNAME *tbl); -#endif /* !defined(OPENSSL_NO_DEPRECATED_4_1) */ -int ASN1_BIT_STRING_get_length(const ASN1_BIT_STRING *abs, size_t *length, - int *unused_bits); -int ASN1_BIT_STRING_set1(ASN1_BIT_STRING *abs, const uint8_t *data, - size_t length, int unused_bits); /* clang-format off */ {- @@ -630,10 +638,8 @@ DECLARE_ASN1_FUNCTIONS(ASN1_UTF8STRING) DECLARE_ASN1_FUNCTIONS(ASN1_NULL) DECLARE_ASN1_FUNCTIONS(ASN1_BMPSTRING) -#if !defined(OPENSSL_NO_DEPRECATED_4_1) -OSSL_DEPRECATEDIN_4_1 int UTF8_getc(const unsigned char *str, int len, unsigned long *val); -OSSL_DEPRECATEDIN_4_1 int UTF8_putc(unsigned char *str, int len, unsigned long value); -#endif /* !defined(OPENSSL_NO_DEPRECATED_4_1) */ +int UTF8_getc(const unsigned char *str, int len, unsigned long *val); +int UTF8_putc(unsigned char *str, int len, unsigned long value); /* clang-format off */ {- diff --git a/include/openssl/bio.h.in b/include/openssl/bio.h.in index c2990efde4..ba8e81e708 100644 --- a/include/openssl/bio.h.in +++ b/include/openssl/bio.h.in @@ -1,7 +1,7 @@ /* * {- join("\n * ", @autowarntext) -} * - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -230,17 +230,6 @@ extern "C" { #define BIO_FLAGS_UPLINK 0 #endif -/* the BIO FLAGS values 0x10 to 0x80 are reserved for internal use */ - -/* - * BIO FLAGS in the range 0x0100..0x8000 are BIO-type specific. - * Their meaning is defined by the particular BIO implementation and - * is not shared across different BIO types. The same bit value may - * have a different meaning or no meaning at all in other BIOs. - * Such flags may be part of the public API or internal to the BIO. - */ - -/* This is used with base64 BIO */ #define BIO_FLAGS_BASE64_NO_NL 0x100 /* @@ -252,6 +241,8 @@ extern "C" { #define BIO_FLAGS_NONCLEAR_RST 0x400 #define BIO_FLAGS_IN_EOF 0x800 +/* the BIO FLAGS values 0x1000 to 0x8000 are reserved for internal KTLS flags */ + typedef union bio_addr_st BIO_ADDR; typedef struct bio_addrinfo_st BIO_ADDRINFO; @@ -484,7 +475,6 @@ typedef struct bio_poll_descriptor_st { #define BIO_C_SET_SOCK_TYPE 157 #define BIO_C_GET_SOCK_TYPE 158 #define BIO_C_GET_DGRAM_BIO 159 -#define BIO_C_SET_SEND_FLAGS 160 #define BIO_set_app_data(s, arg) BIO_set_ex_data(s, 0, arg) #define BIO_get_app_data(s) BIO_get_ex_data(s, 0) @@ -617,6 +607,7 @@ int BIO_read_filename(BIO *b, const char *name); #define BIO_dup_state(b, ret) BIO_ctrl(b, BIO_CTRL_DUP, 0, (char *)(ret)) #define BIO_reset(b) (int)BIO_ctrl(b, BIO_CTRL_RESET, 0, NULL) +#define BIO_eof(b) (int)BIO_ctrl(b, BIO_CTRL_EOF, 0, NULL) #define BIO_set_close(b, c) (int)BIO_ctrl(b, BIO_CTRL_SET_CLOSE, (c), NULL) #define BIO_get_close(b) (int)BIO_ctrl(b, BIO_CTRL_GET_CLOSE, 0, NULL) #define BIO_pending(b) (int)BIO_ctrl(b, BIO_CTRL_PENDING, 0, NULL) @@ -742,7 +733,6 @@ __owur int BIO_get_wpoll_descriptor(BIO *b, BIO_POLL_DESCRIPTOR *desc); int BIO_puts(BIO *bp, const char *buf); int BIO_indent(BIO *b, int indent, int max); long BIO_ctrl(BIO *bp, int cmd, long larg, void *parg); -int BIO_eof(BIO *b); long BIO_callback_ctrl(BIO *b, int cmd, BIO_info_cb *fp); void *BIO_ptr_ctrl(BIO *bp, int cmd, long larg); long BIO_int_ctrl(BIO *bp, int cmd, long larg, int iarg); @@ -807,7 +797,6 @@ int BIO_sock_non_fatal_error(int error); int BIO_err_is_non_fatal(unsigned int errcode); int BIO_socket_wait(int fd, int for_read, time_t max_time); #endif -long BIO_set_send_flags(BIO *b, int flags); int BIO_wait(BIO *bio, time_t max_time, unsigned int nap_milliseconds); int BIO_do_connect_retry(BIO *bio, int timeout, int nap_milliseconds); @@ -932,20 +921,33 @@ void BIO_copy_next_retry(BIO *b); */ #define ossl_bio__attr__(x) -#if defined(__GNUC__) && !defined(__MINGW32__) && !defined(__MINGW64__) \ +#if defined(__GNUC__) && defined(__STDC_VERSION__) \ + && !defined(__MINGW32__) && !defined(__MINGW64__) \ && !defined(__APPLE__) +/* + * Because we support the 'z' modifier, which made its appearance in C99, + * we can't use __attribute__ with pre C99 dialects. + */ +#if __STDC_VERSION__ >= 199901L #undef ossl_bio__attr__ #define ossl_bio__attr__ __attribute__ +#if __GNUC__ * 10 + __GNUC_MINOR__ >= 44 +#define ossl_bio__printf__ __gnu_printf__ +#else +#define ossl_bio__printf__ __printf__ +#endif +#endif #endif int BIO_printf(BIO *bio, const char *format, ...) - ossl_bio__attr__((__format__(__printf__, 2, 3))); + ossl_bio__attr__((__format__(ossl_bio__printf__, 2, 3))); int BIO_vprintf(BIO *bio, const char *format, va_list args) - ossl_bio__attr__((__format__(__printf__, 2, 0))); + ossl_bio__attr__((__format__(ossl_bio__printf__, 2, 0))); int BIO_snprintf(char *buf, size_t n, const char *format, ...) - ossl_bio__attr__((__format__(__printf__, 3, 4))); + ossl_bio__attr__((__format__(ossl_bio__printf__, 3, 4))); int BIO_vsnprintf(char *buf, size_t n, const char *format, va_list args) - ossl_bio__attr__((__format__(__printf__, 3, 0))); + ossl_bio__attr__((__format__(ossl_bio__printf__, 3, 0))); #undef ossl_bio__attr__ +#undef ossl_bio__printf__ BIO_METHOD *BIO_meth_new(int type, const char *name); void BIO_meth_free(BIO_METHOD *biom); diff --git a/include/openssl/blowfish.h b/include/openssl/blowfish.h index a1f678855b..49c74e946c 100644 --- a/include/openssl/blowfish.h +++ b/include/openssl/blowfish.h @@ -36,7 +36,7 @@ extern "C" { * ! BF_LONG has to be at least 32 bits wide. ! * !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! */ -typedef unsigned int BF_LONG; +#define BF_LONG unsigned int #define BF_ROUNDS 16 diff --git a/include/openssl/bn.h b/include/openssl/bn.h index 5d7e5ce83f..d210b8bddd 100644 --- a/include/openssl/bn.h +++ b/include/openssl/bn.h @@ -34,7 +34,7 @@ extern "C" { * 64-bit processor with LP64 ABI */ #ifdef SIXTY_FOUR_BIT_LONG -typedef unsigned long BN_ULONG; +#define BN_ULONG unsigned long #define BN_BYTES 8 #endif @@ -42,12 +42,12 @@ typedef unsigned long BN_ULONG; * 64-bit processor other than LP64 ABI */ #ifdef SIXTY_FOUR_BIT -typedef unsigned long long BN_ULONG; +#define BN_ULONG unsigned long long #define BN_BYTES 8 #endif #ifdef THIRTY_TWO_BIT -typedef unsigned int BN_ULONG; +#define BN_ULONG unsigned int #define BN_BYTES 4 #endif @@ -273,8 +273,8 @@ int BN_is_negative(const BIGNUM *b); int BN_div(BIGNUM *dv, BIGNUM *rem, const BIGNUM *m, const BIGNUM *d, BN_CTX *ctx); -#define BN_mod(rem, a, m, ctx) BN_div(NULL, (rem), (a), (m), (ctx)) -int BN_nnmod(BIGNUM *r, const BIGNUM *a, const BIGNUM *m, BN_CTX *ctx); +#define BN_mod(rem, m, d, ctx) BN_div(NULL, (rem), (m), (d), (ctx)) +int BN_nnmod(BIGNUM *r, const BIGNUM *m, const BIGNUM *d, BN_CTX *ctx); int BN_mod_add(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, const BIGNUM *m, BN_CTX *ctx); int BN_mod_add_quick(BIGNUM *r, const BIGNUM *a, const BIGNUM *b, diff --git a/include/openssl/camellia.h b/include/openssl/camellia.h index e03b8efe2d..aec94e4efc 100644 --- a/include/openssl/camellia.h +++ b/include/openssl/camellia.h @@ -1,5 +1,5 @@ /* - * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2006-2020 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -56,7 +56,7 @@ typedef struct camellia_key_st CAMELLIA_KEY; #endif /* OPENSSL_NO_DEPRECATED_3_0 */ #ifndef OPENSSL_NO_DEPRECATED_3_0 OSSL_DEPRECATEDIN_3_0 int Camellia_set_key(const unsigned char *userKey, - int bits, + const int bits, CAMELLIA_KEY *key); OSSL_DEPRECATEDIN_3_0 void Camellia_encrypt(const unsigned char *in, unsigned char *out, @@ -67,34 +67,34 @@ OSSL_DEPRECATEDIN_3_0 void Camellia_decrypt(const unsigned char *in, OSSL_DEPRECATEDIN_3_0 void Camellia_ecb_encrypt(const unsigned char *in, unsigned char *out, const CAMELLIA_KEY *key, - int enc); + const int enc); OSSL_DEPRECATEDIN_3_0 void Camellia_cbc_encrypt(const unsigned char *in, unsigned char *out, size_t length, const CAMELLIA_KEY *key, unsigned char *ivec, - int enc); + const int enc); OSSL_DEPRECATEDIN_3_0 void Camellia_cfb128_encrypt(const unsigned char *in, unsigned char *out, size_t length, const CAMELLIA_KEY *key, unsigned char *ivec, int *num, - int enc); + const int enc); OSSL_DEPRECATEDIN_3_0 void Camellia_cfb1_encrypt(const unsigned char *in, unsigned char *out, size_t length, const CAMELLIA_KEY *key, unsigned char *ivec, int *num, - int enc); + const int enc); OSSL_DEPRECATEDIN_3_0 void Camellia_cfb8_encrypt(const unsigned char *in, unsigned char *out, size_t length, const CAMELLIA_KEY *key, unsigned char *ivec, int *num, - int enc); + const int enc); OSSL_DEPRECATEDIN_3_0 void Camellia_ofb128_encrypt(const unsigned char *in, unsigned char *out, size_t length, diff --git a/include/openssl/cast.h b/include/openssl/cast.h index 7babdb66fe..af94312482 100644 --- a/include/openssl/cast.h +++ b/include/openssl/cast.h @@ -31,7 +31,7 @@ extern "C" { #define CAST_ENCRYPT 1 #define CAST_DECRYPT 0 -typedef unsigned int CAST_LONG; +#define CAST_LONG unsigned int typedef struct cast_key_st { CAST_LONG data[32]; diff --git a/include/openssl/cmp.h.in b/include/openssl/cmp.h.in index 6ae08e1872..b600aa6bbd 100644 --- a/include/openssl/cmp.h.in +++ b/include/openssl/cmp.h.in @@ -1,7 +1,7 @@ /* * {- join("\n * ", @autowarntext) -} * - * Copyright 2007-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2007-2024 The OpenSSL Project Authors. All Rights Reserved. * Copyright Nokia 2007-2019 * Copyright Siemens AG 2015-2019 * @@ -197,8 +197,6 @@ typedef ASN1_BIT_STRING OSSL_CMP_PKIFAILUREINFO; * -- CertReqMsg * } */ -#define OSSL_CMP_PKISTATUS_rejected_by_client -5 -#define OSSL_CMP_PKISTATUS_checking_response -4 #define OSSL_CMP_PKISTATUS_request -3 #define OSSL_CMP_PKISTATUS_trans -2 #define OSSL_CMP_PKISTATUS_unspecified -1 @@ -376,7 +374,6 @@ const char *OSSL_CMP_CTX_get0_propq(const OSSL_CMP_CTX *ctx); #define OSSL_CMP_OPT_IGNORE_KEYUSAGE 35 #define OSSL_CMP_OPT_PERMIT_TA_IN_EXTRACERTS_FOR_IR 36 #define OSSL_CMP_OPT_NO_CACHE_EXTRACERTS 37 -#define OSSL_CMP_OPT_NONMATCHED_ERROR_NONCES 38 int OSSL_CMP_CTX_set_option(OSSL_CMP_CTX *ctx, int opt, int val); int OSSL_CMP_CTX_get_option(const OSSL_CMP_CTX *ctx, int opt); /* CMP-specific callback for logging and outputting the error queue: */ @@ -510,9 +507,8 @@ OSSL_CMP_MSG *OSSL_CMP_CTX_server_perform(OSSL_CMP_CTX *client_ctx, const OSSL_CMP_MSG *req); OSSL_CMP_SRV_CTX *OSSL_CMP_SRV_CTX_new(OSSL_LIB_CTX *libctx, const char *propq); void OSSL_CMP_SRV_CTX_free(OSSL_CMP_SRV_CTX *srv_ctx); -typedef OSSL_CMP_PKISI *(*OSSL_CMP_SRV_cert_request_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx, - const OSSL_CMP_MSG *req, int certReqId, - const OSSL_CRMF_MSG *crm, const X509_REQ *p10, +typedef OSSL_CMP_PKISI *(*OSSL_CMP_SRV_cert_request_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx, const OSSL_CMP_MSG *req, int certReqId, + const OSSL_CRMF_MSG *crm, const X509_REQ *p10cr, X509 **certOut, STACK_OF(X509) **chainOut, STACK_OF(X509) **caPubs); typedef OSSL_CMP_PKISI *(*OSSL_CMP_SRV_rr_cb_t)(OSSL_CMP_SRV_CTX *srv_ctx, const OSSL_CMP_MSG *req, diff --git a/include/openssl/cms.h.in b/include/openssl/cms.h.in index 20af42015c..cf96c712b4 100644 --- a/include/openssl/cms.h.in +++ b/include/openssl/cms.h.in @@ -1,7 +1,7 @@ /* * {- join("\n * ", @autowarntext) -} * - * Copyright 2008-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2008-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -137,13 +137,16 @@ int CMS_final_digest(CMS_ContentInfo *cms, unsigned int flags); CMS_ContentInfo *CMS_sign(X509 *signcert, EVP_PKEY *pkey, - const STACK_OF(X509) *certs, BIO *data, unsigned int flags); + STACK_OF(X509) *certs, BIO *data, + unsigned int flags); CMS_ContentInfo *CMS_sign_ex(X509 *signcert, EVP_PKEY *pkey, - const STACK_OF(X509) *certs, BIO *data, - unsigned int flags, OSSL_LIB_CTX *libctx, const char *propq); + STACK_OF(X509) *certs, BIO *data, + unsigned int flags, OSSL_LIB_CTX *libctx, + const char *propq); -CMS_ContentInfo *CMS_sign_receipt(CMS_SignerInfo *si, X509 *signcert, - EVP_PKEY *pkey, const STACK_OF(X509) *certs, unsigned int flags); +CMS_ContentInfo *CMS_sign_receipt(CMS_SignerInfo *si, + X509 *signcert, EVP_PKEY *pkey, + STACK_OF(X509) *certs, unsigned int flags); int CMS_data(CMS_ContentInfo *cms, BIO *out, unsigned int flags); CMS_ContentInfo *CMS_data_create(BIO *in, unsigned int flags); @@ -173,17 +176,18 @@ CMS_ContentInfo *CMS_EncryptedData_encrypt_ex(BIO *in, const EVP_CIPHER *cipher, int CMS_EncryptedData_set1_key(CMS_ContentInfo *cms, const EVP_CIPHER *ciph, const unsigned char *key, size_t keylen); -int CMS_verify(CMS_ContentInfo *cms, const STACK_OF(X509) *certs, +int CMS_verify(CMS_ContentInfo *cms, STACK_OF(X509) *certs, X509_STORE *store, BIO *dcont, BIO *out, unsigned int flags); int CMS_verify_receipt(CMS_ContentInfo *rcms, CMS_ContentInfo *ocms, - const STACK_OF(X509) *certs, X509_STORE *store, unsigned int flags); + STACK_OF(X509) *certs, + X509_STORE *store, unsigned int flags); STACK_OF(X509) *CMS_get0_signers(CMS_ContentInfo *cms); -CMS_ContentInfo *CMS_encrypt(const STACK_OF(X509) *certs, BIO *in, +CMS_ContentInfo *CMS_encrypt(STACK_OF(X509) *certs, BIO *in, const EVP_CIPHER *cipher, unsigned int flags); -CMS_ContentInfo *CMS_encrypt_ex(const STACK_OF(X509) *certs, BIO *in, +CMS_ContentInfo *CMS_encrypt_ex(STACK_OF(X509) *certs, BIO *in, const EVP_CIPHER *cipher, unsigned int flags, OSSL_LIB_CTX *libctx, const char *propq); @@ -293,7 +297,7 @@ int CMS_SignerInfo_get0_signer_id(CMS_SignerInfo *si, ASN1_OCTET_STRING **keyid, X509_NAME **issuer, ASN1_INTEGER **sno); int CMS_SignerInfo_cert_cmp(CMS_SignerInfo *si, X509 *cert); -int CMS_set1_signers_certs(CMS_ContentInfo *cms, const STACK_OF(X509) *certs, +int CMS_set1_signers_certs(CMS_ContentInfo *cms, STACK_OF(X509) *certs, unsigned int flags); void CMS_SignerInfo_get0_algs(CMS_SignerInfo *si, EVP_PKEY **pk, X509 **signer, X509_ALGOR **pdig, @@ -304,8 +308,8 @@ int CMS_SignerInfo_verify(CMS_SignerInfo *si); int CMS_SignerInfo_verify_content(CMS_SignerInfo *si, BIO *chain); int CMS_SignerInfo_verify_ex(CMS_SignerInfo *si, BIO *chain, BIO *data); BIO *CMS_SignedData_verify(CMS_SignedData *sd, BIO *detached_data, - const STACK_OF(X509) *scerts, X509_STORE *store, - const STACK_OF(X509) *extra, const STACK_OF(X509_CRL) *crls, + STACK_OF(X509) *scerts, X509_STORE *store, + STACK_OF(X509) *extra, STACK_OF(X509_CRL) *crls, unsigned int flags, OSSL_LIB_CTX *libctx, const char *propq); @@ -331,7 +335,7 @@ int CMS_signed_add1_attr_by_NID(CMS_SignerInfo *si, int CMS_signed_add1_attr_by_txt(CMS_SignerInfo *si, const char *attrname, int type, const void *bytes, int len); -const void *CMS_signed_get0_data_by_OBJ(const CMS_SignerInfo *si, +void *CMS_signed_get0_data_by_OBJ(const CMS_SignerInfo *si, const ASN1_OBJECT *oid, int lastpos, int type); @@ -352,7 +356,7 @@ int CMS_unsigned_add1_attr_by_NID(CMS_SignerInfo *si, int CMS_unsigned_add1_attr_by_txt(CMS_SignerInfo *si, const char *attrname, int type, const void *bytes, int len); -const void *CMS_unsigned_get0_data_by_OBJ(CMS_SignerInfo *si, ASN1_OBJECT *oid, +void *CMS_unsigned_get0_data_by_OBJ(CMS_SignerInfo *si, ASN1_OBJECT *oid, int lastpos, int type); int CMS_get1_ReceiptRequest(CMS_SignerInfo *si, CMS_ReceiptRequest **prr); diff --git a/include/openssl/core_dispatch.h b/include/openssl/core_dispatch.h index 1bab83d792..8f6278070e 100644 --- a/include/openssl/core_dispatch.h +++ b/include/openssl/core_dispatch.h @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -162,16 +162,16 @@ OSSL_CORE_MAKE_FUNC(void, OSSL_CORE_MAKE_FUNC(OSSL_CORE_BIO *, BIO_new_file, (const char *filename, const char *mode)) OSSL_CORE_MAKE_FUNC(OSSL_CORE_BIO *, BIO_new_membuf, (const void *buf, int len)) -OSSL_CORE_MAKE_FUNC(int, BIO_read_ex, (OSSL_CORE_BIO *bio, void *data, size_t data_len, size_t *bytes_read)) -OSSL_CORE_MAKE_FUNC(int, BIO_write_ex, (OSSL_CORE_BIO *bio, const void *data, size_t data_len, size_t *written)) -OSSL_CORE_MAKE_FUNC(int, BIO_gets, (OSSL_CORE_BIO *bio, char *buf, int size)) -OSSL_CORE_MAKE_FUNC(int, BIO_puts, (OSSL_CORE_BIO *bio, const char *str)) -OSSL_CORE_MAKE_FUNC(int, BIO_up_ref, (OSSL_CORE_BIO *bio)) -OSSL_CORE_MAKE_FUNC(int, BIO_free, (OSSL_CORE_BIO *bio)) -OSSL_CORE_MAKE_FUNC(int, BIO_vprintf, (OSSL_CORE_BIO *bio, const char *format, va_list args)) +OSSL_CORE_MAKE_FUNC(int, BIO_read_ex, (OSSL_CORE_BIO * bio, void *data, size_t data_len, size_t *bytes_read)) +OSSL_CORE_MAKE_FUNC(int, BIO_write_ex, (OSSL_CORE_BIO * bio, const void *data, size_t data_len, size_t *written)) +OSSL_CORE_MAKE_FUNC(int, BIO_gets, (OSSL_CORE_BIO * bio, char *buf, int size)) +OSSL_CORE_MAKE_FUNC(int, BIO_puts, (OSSL_CORE_BIO * bio, const char *str)) +OSSL_CORE_MAKE_FUNC(int, BIO_up_ref, (OSSL_CORE_BIO * bio)) +OSSL_CORE_MAKE_FUNC(int, BIO_free, (OSSL_CORE_BIO * bio)) +OSSL_CORE_MAKE_FUNC(int, BIO_vprintf, (OSSL_CORE_BIO * bio, const char *format, va_list args)) OSSL_CORE_MAKE_FUNC(int, BIO_vsnprintf, (char *buf, size_t n, const char *fmt, va_list args)) -OSSL_CORE_MAKE_FUNC(int, BIO_ctrl, (OSSL_CORE_BIO *bio, int cmd, long num, void *ptr)) +OSSL_CORE_MAKE_FUNC(int, BIO_ctrl, (OSSL_CORE_BIO * bio, int cmd, long num, void *ptr)) /* New seeding functions prototypes with the 101-104 series */ #define OSSL_FUNC_CLEANUP_USER_ENTROPY 96 @@ -180,9 +180,9 @@ OSSL_CORE_MAKE_FUNC(int, BIO_ctrl, (OSSL_CORE_BIO *bio, int cmd, long num, void #define OSSL_FUNC_GET_USER_NONCE 99 #define OSSL_FUNC_INDICATOR_CB 95 -OSSL_CORE_MAKE_FUNC(void, indicator_cb, (OPENSSL_CORE_CTX *ctx, OSSL_INDICATOR_CALLBACK **cb)) +OSSL_CORE_MAKE_FUNC(void, indicator_cb, (OPENSSL_CORE_CTX * ctx, OSSL_INDICATOR_CALLBACK **cb)) #define OSSL_FUNC_SELF_TEST_CB 100 -OSSL_CORE_MAKE_FUNC(void, self_test_cb, (OPENSSL_CORE_CTX *ctx, OSSL_CALLBACK **cb, void **cbarg)) +OSSL_CORE_MAKE_FUNC(void, self_test_cb, (OPENSSL_CORE_CTX * ctx, OSSL_CALLBACK **cb, void **cbarg)) /* Functions to get seed material from the operating system */ #define OSSL_FUNC_GET_ENTROPY 101 @@ -257,26 +257,26 @@ OSSL_CORE_MAKE_FUNC(int, provider_random_bytes, (void *provctx, int which, void /* Libssl related functions */ #define OSSL_FUNC_SSL_QUIC_TLS_CRYPTO_SEND 2001 OSSL_CORE_MAKE_FUNC(int, SSL_QUIC_TLS_crypto_send, - (SSL *s, const unsigned char *buf, size_t buf_len, + (SSL * s, const unsigned char *buf, size_t buf_len, size_t *consumed, void *arg)) #define OSSL_FUNC_SSL_QUIC_TLS_CRYPTO_RECV_RCD 2002 OSSL_CORE_MAKE_FUNC(int, SSL_QUIC_TLS_crypto_recv_rcd, - (SSL *s, const unsigned char **buf, size_t *bytes_read, + (SSL * s, const unsigned char **buf, size_t *bytes_read, void *arg)) #define OSSL_FUNC_SSL_QUIC_TLS_CRYPTO_RELEASE_RCD 2003 OSSL_CORE_MAKE_FUNC(int, SSL_QUIC_TLS_crypto_release_rcd, - (SSL *s, size_t bytes_read, void *arg)) + (SSL * s, size_t bytes_read, void *arg)) #define OSSL_FUNC_SSL_QUIC_TLS_YIELD_SECRET 2004 OSSL_CORE_MAKE_FUNC(int, SSL_QUIC_TLS_yield_secret, - (SSL *s, uint32_t prot_level, int direction, + (SSL * s, uint32_t prot_level, int direction, const unsigned char *secret, size_t secret_len, void *arg)) #define OSSL_FUNC_SSL_QUIC_TLS_GOT_TRANSPORT_PARAMS 2005 OSSL_CORE_MAKE_FUNC(int, SSL_QUIC_TLS_got_transport_params, - (SSL *s, const unsigned char *params, size_t params_len, + (SSL * s, const unsigned char *params, size_t params_len, void *arg)) #define OSSL_FUNC_SSL_QUIC_TLS_ALERT 2006 OSSL_CORE_MAKE_FUNC(int, SSL_QUIC_TLS_alert, - (SSL *s, unsigned char alert_code, void *arg)) + (SSL * s, unsigned char alert_code, void *arg)) /* Operations */ @@ -315,8 +315,6 @@ OSSL_CORE_MAKE_FUNC(int, SSL_QUIC_TLS_alert, #define OSSL_FUNC_DIGEST_GETTABLE_CTX_PARAMS 13 #define OSSL_FUNC_DIGEST_SQUEEZE 14 #define OSSL_FUNC_DIGEST_COPYCTX 15 -#define OSSL_FUNC_DIGEST_SERIALIZE 16 -#define OSSL_FUNC_DIGEST_DESERIALIZE 17 OSSL_CORE_MAKE_FUNC(void *, digest_newctx, (void *provctx)) OSSL_CORE_MAKE_FUNC(int, digest_init, (void *dctx, const OSSL_PARAM params[])) @@ -347,10 +345,6 @@ OSSL_CORE_MAKE_FUNC(const OSSL_PARAM *, digest_settable_ctx_params, (void *dctx, void *provctx)) OSSL_CORE_MAKE_FUNC(const OSSL_PARAM *, digest_gettable_ctx_params, (void *dctx, void *provctx)) -OSSL_CORE_MAKE_FUNC(int, digest_serialize, - (void *dctx, unsigned char *out, size_t *outl)) -OSSL_CORE_MAKE_FUNC(int, digest_deserialize, - (void *dctx, const unsigned char *in, size_t inl)) /* Symmetric Ciphers */ @@ -663,8 +657,6 @@ OSSL_CORE_MAKE_FUNC(void, rand_clear_seed, /* Basic key object creation */ #define OSSL_FUNC_KEYMGMT_NEW 1 OSSL_CORE_MAKE_FUNC(void *, keymgmt_new, (void *provctx)) -#define OSSL_FUNC_KEYMGMT_NEW_EX 17 -OSSL_CORE_MAKE_FUNC(void *, keymgmt_new_ex, (void *provctx, const OSSL_PARAM params[])) /* Generation, a more complex constructor */ #define OSSL_FUNC_KEYMGMT_GEN_INIT 2 diff --git a/include/openssl/core_names.h.in b/include/openssl/core_names.h.in index 7d8080f59e..e0a4c5e632 100644 --- a/include/openssl/core_names.h.in +++ b/include/openssl/core_names.h.in @@ -1,7 +1,7 @@ /* * {- join("\n * ", @autowarntext) -} * - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -71,13 +71,11 @@ extern "C" { #define OSSL_KDF_NAME_HKDF_SHA256 "HKDF-SHA256" #define OSSL_KDF_NAME_HKDF_SHA384 "HKDF-SHA384" #define OSSL_KDF_NAME_HKDF_SHA512 "HKDF-SHA512" -#define OSSL_KDF_NAME_IKEV2KDF "IKEV2KDF" #define OSSL_KDF_NAME_TLS1_3_KDF "TLS13-KDF" #define OSSL_KDF_NAME_PBKDF1 "PBKDF1" #define OSSL_KDF_NAME_PBKDF2 "PBKDF2" #define OSSL_KDF_NAME_SCRYPT "SCRYPT" #define OSSL_KDF_NAME_SNMPKDF "SNMPKDF" -#define OSSL_KDF_NAME_SRTPKDF "SRTPKDF" #define OSSL_KDF_NAME_SSHKDF "SSHKDF" #define OSSL_KDF_NAME_SSKDF "SSKDF" #define OSSL_KDF_NAME_TLS1_PRF "TLS1-PRF" diff --git a/include/openssl/crmf.h.in b/include/openssl/crmf.h.in index c327b07a87..3d9cbf4320 100644 --- a/include/openssl/crmf.h.in +++ b/include/openssl/crmf.h.in @@ -1,7 +1,7 @@ /*- * {- join("\n * ", @autowarntext) -} * - * Copyright 2007-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright Nokia 2007-2019 * Copyright Siemens AG 2015-2019 * @@ -196,7 +196,7 @@ EVP_PKEY *OSSL_CRMF_ENCRYPTEDKEY_get1_pkey(const OSSL_CRMF_ENCRYPTEDKEY *encrypt X509_STORE *ts, STACK_OF(X509) *extra, EVP_PKEY *pkey, X509 *cert, ASN1_OCTET_STRING *secret, OSSL_LIB_CTX *libctx, const char *propq); -int OSSL_CRMF_MSG_centralkeygen_requested(const OSSL_CRMF_MSG *crm, const X509_REQ *p10); +int OSSL_CRMF_MSG_centralkeygen_requested(const OSSL_CRMF_MSG *crm, const X509_REQ *p10cr); #ifndef OPENSSL_NO_CMS OSSL_CRMF_ENCRYPTEDKEY *OSSL_CRMF_ENCRYPTEDKEY_init_envdata(CMS_EnvelopedData *envdata); #endif diff --git a/include/openssl/crypto.h.in b/include/openssl/crypto.h.in index a9ade25b15..7a6d1d7c94 100644 --- a/include/openssl/crypto.h.in +++ b/include/openssl/crypto.h.in @@ -1,7 +1,7 @@ /* * {- join("\n * ", @autowarntext) -} * - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -97,11 +97,6 @@ int CRYPTO_atomic_or(uint64_t *val, uint64_t op, uint64_t *ret, int CRYPTO_atomic_load(uint64_t *val, uint64_t *ret, CRYPTO_RWLOCK *lock); int CRYPTO_atomic_load_int(int *val, int *ret, CRYPTO_RWLOCK *lock); int CRYPTO_atomic_store(uint64_t *dst, uint64_t val, CRYPTO_RWLOCK *lock); -int CRYPTO_atomic_store_int(int *dst, int val, CRYPTO_RWLOCK *lock); -int CRYPTO_atomic_load_ptr(void **ptr, void **ret, CRYPTO_RWLOCK *lock); -int CRYPTO_atomic_store_ptr(void **dst, void **val, CRYPTO_RWLOCK *lock); -int CRYPTO_atomic_cmp_exch_ptr(void **ptr, void **expect, void *desire, CRYPTO_RWLOCK *lock, - int *lock_failed); /* No longer needed, so this is a no-op */ #define OPENSSL_malloc_init() \ @@ -521,6 +516,7 @@ int CRYPTO_memcmp(const void *in_a, const void *in_b, size_t len); /* Library initialisation functions */ void OPENSSL_cleanup(void); int OPENSSL_init_crypto(uint64_t opts, const OPENSSL_INIT_SETTINGS *settings); +int OPENSSL_atexit(void (*handler)(void)); void OPENSSL_thread_stop(void); void OPENSSL_thread_stop_ex(OSSL_LIB_CTX *ctx); @@ -590,6 +586,7 @@ OSSL_LIB_CTX *OSSL_LIB_CTX_get0_global_default(void); OSSL_LIB_CTX *OSSL_LIB_CTX_set0_default(OSSL_LIB_CTX *libctx); int OSSL_LIB_CTX_get_conf_diagnostics(OSSL_LIB_CTX *ctx); void OSSL_LIB_CTX_set_conf_diagnostics(OSSL_LIB_CTX *ctx, int value); +int OSSL_LIB_CTX_freeze(OSSL_LIB_CTX *ctx, const char *propq); void OSSL_sleep(uint64_t millis); diff --git a/include/openssl/ct.h.in b/include/openssl/ct.h.in index 8c83f53a26..a6103980d4 100644 --- a/include/openssl/ct.h.in +++ b/include/openssl/ct.h.in @@ -499,14 +499,6 @@ CTLOG_STORE *CTLOG_STORE_new(void); */ void CTLOG_STORE_free(CTLOG_STORE *store); -/* - * Adds a CT log to a CTLOG_STORE. - * Takes ownership of the CTLOG on success - the caller must not free it after - * a successful call. On failure, the caller retains ownership. - * Returns 1 on success, 0 on failure. - */ -__owur int CTLOG_STORE_add0_log(CTLOG_STORE *store, CTLOG *log); - /* * Finds a CT log in the store based on its log ID. * Returns the CT log, or NULL if no match is found. diff --git a/include/openssl/e_os2.h b/include/openssl/e_os2.h index f3cda73da1..86a572bb12 100644 --- a/include/openssl/e_os2.h +++ b/include/openssl/e_os2.h @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -72,11 +72,14 @@ extern "C" { #if defined(OPENSSL_SYS_WINNT) #undef OPENSSL_SYS_UNIX #endif +#if defined(OPENSSL_SYS_WINCE) +#undef OPENSSL_SYS_UNIX +#endif #endif #endif /* Anything that tries to look like Microsoft is "Windows" */ -#if defined(OPENSSL_SYS_WIN32) || defined(OPENSSL_SYS_WIN64) || defined(OPENSSL_SYS_WINNT) +#if defined(OPENSSL_SYS_WIN32) || defined(OPENSSL_SYS_WIN64) || defined(OPENSSL_SYS_WINNT) || defined(OPENSSL_SYS_WINCE) #undef OPENSSL_SYS_UNIX #define OPENSSL_SYS_WINDOWS #ifndef OPENSSL_SYS_MSDOS @@ -181,6 +184,33 @@ extern "C" { #define OPENSSL_EXTERN extern #endif +#ifdef _WIN32 +#ifdef _WIN64 +#define ossl_ssize_t __int64 +#define OSSL_SSIZE_MAX _I64_MAX +#else +#define ossl_ssize_t int +#define OSSL_SSIZE_MAX INT_MAX +#endif +#endif + +#if defined(OPENSSL_SYS_UEFI) && !defined(ossl_ssize_t) +#define ossl_ssize_t INTN +#define OSSL_SSIZE_MAX MAX_INTN +#endif + +#ifndef ossl_ssize_t +#include +#define ossl_ssize_t ssize_t +#if defined(SSIZE_MAX) +#define OSSL_SSIZE_MAX SSIZE_MAX +#elif defined(_POSIX_SSIZE_MAX) +#define OSSL_SSIZE_MAX _POSIX_SSIZE_MAX +#else +#define OSSL_SSIZE_MAX ((ssize_t)(SIZE_MAX >> 1)) +#endif +#endif + #if defined(UNUSEDRESULT_DEBUG) #define __owur __attribute__((__warn_unused_result__)) #else @@ -200,15 +230,24 @@ typedef UINT32 uint32_t; typedef INT64 int64_t; typedef UINT64 uint64_t; typedef UINTN uintptr_t; -#ifndef OSSL_SSIZE_MAX -typedef INTN ossl_ssize_t; -#define OSSL_SSIZE_MAX MAX_INTN -#endif #elif (defined(__STDC_VERSION__) && __STDC_VERSION__ >= 199901L) || defined(__osf__) || defined(__sgi) || defined(__hpux) || defined(OPENSSL_SYS_VMS) || defined(__OpenBSD__) #include #undef OPENSSL_NO_INTTYPES_H /* Because the specs say that inttypes.h includes stdint.h if present */ #undef OPENSSL_NO_STDINT_H +#elif defined(_MSC_VER) && _MSC_VER < 1600 +/* + * minimally required typdefs for systems not supporting inttypes.h or + * stdint.h: currently just older VC++ + */ +typedef signed char int8_t; +typedef unsigned char uint8_t; +typedef short int16_t; +typedef unsigned short uint16_t; +typedef int int32_t; +typedef unsigned int uint32_t; +typedef __int64 int64_t; +typedef unsigned __int64 uint64_t; #elif defined(OPENSSL_SYS_TANDEM) #include #include @@ -216,29 +255,6 @@ typedef INTN ossl_ssize_t; #include #undef OPENSSL_NO_STDINT_H #endif - -#ifdef _WIN32 -#ifdef _WIN64 -typedef int64_t ossl_ssize_t; -#define OSSL_SSIZE_MAX INT64_MAX -#else -typedef int ossl_ssize_t; -#define OSSL_SSIZE_MAX INT_MAX -#endif -#endif - -#ifndef OSSL_SSIZE_MAX -#include -typedef ssize_t ossl_ssize_t; -#if defined(SSIZE_MAX) -#define OSSL_SSIZE_MAX SSIZE_MAX -#elif defined(_POSIX_SSIZE_MAX) -#define OSSL_SSIZE_MAX _POSIX_SSIZE_MAX -#else -#define OSSL_SSIZE_MAX ((ssize_t)(SIZE_MAX >> 1)) -#endif -#endif - #if defined(__STDC_VERSION__) && __STDC_VERSION__ >= 199901L && defined(INTMAX_MAX) && defined(UINTMAX_MAX) typedef intmax_t ossl_intmax_t; typedef uintmax_t ossl_uintmax_t; @@ -253,7 +269,7 @@ typedef uint64_t ossl_uintmax_t; #if defined(__STDC_VERSION__) && __STDC_VERSION__ >= 199901L /* just use inline */ #define ossl_inline inline -#elif defined(__GNUC__) +#elif defined(__GNUC__) && __GNUC__ >= 2 #define ossl_inline __inline__ #elif defined(_MSC_VER) /* @@ -271,7 +287,7 @@ typedef uint64_t ossl_uintmax_t; #if defined(__STDC_VERSION__) && __STDC_VERSION__ >= 201112L && !defined(__cplusplus) #define ossl_noreturn _Noreturn -#elif defined(__GNUC__) +#elif defined(__GNUC__) && __GNUC__ >= 2 #define ossl_noreturn __attribute__((noreturn)) #else #define ossl_noreturn diff --git a/include/openssl/e_ostime.h b/include/openssl/e_ostime.h index 21022eb206..c0f1c547db 100644 --- a/include/openssl/e_ostime.h +++ b/include/openssl/e_ostime.h @@ -21,7 +21,6 @@ * substantial set of headers on some platforms (e.g. on Win32). */ -/* IWYU pragma: begin_exports */ #if defined(OPENSSL_SYS_WINDOWS) #if !defined(_WINSOCKAPI_) /* @@ -35,6 +34,5 @@ #else #include #endif -/* IWYU pragma: end_exports */ #endif diff --git a/include/openssl/ec.h b/include/openssl/ec.h index 2119a9b85f..4ea2c36321 100644 --- a/include/openssl/ec.h +++ b/include/openssl/ec.h @@ -1,5 +1,5 @@ /* - * Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2002-2023 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -20,6 +20,8 @@ #include #include +#include + #ifdef __cplusplus extern "C" { #endif @@ -251,14 +253,6 @@ const BIGNUM *EC_GROUP_get0_order(const EC_GROUP *group); */ int EC_GROUP_order_bits(const EC_GROUP *group); -/** Gets the symmetric-equivalent security bit size an EC_GROUP. - * This is rounded down to one of the standard sizes, (80, 112, - * 128, 192, 256) or reported as-is when smaller than 80. - * \param group EC_GROUP object - * \return symmetric-equivalent security bits. - */ -int EC_GROUP_security_bits(const EC_GROUP *group); - /** Gets the cofactor of a EC_GROUP * \param group EC_GROUP object * \param cofactor BIGNUM to which the cofactor is copied @@ -1548,6 +1542,8 @@ OSSL_DEPRECATEDIN_3_0 void EC_KEY_METHOD_get_verify(const EC_KEY_METHOD *meth, EC_KEY *eckey)); #endif /* OPENSSL_NO_DEPRECATED_3_0 */ +#define EVP_EC_gen(curve) \ + EVP_PKEY_Q_keygen(NULL, NULL, "EC", (char *)(strstr(curve, ""))) /* strstr is used to enable type checking for the variadic string arg */ #define ECParameters_dup(x) ASN1_dup_of(EC_KEY, i2d_ECParameters, \ d2i_ECParameters, x) diff --git a/include/openssl/ecdh.h b/include/openssl/ecdh.h index 3781b82cfa..56bd4cc2ce 100644 --- a/include/openssl/ecdh.h +++ b/include/openssl/ecdh.h @@ -7,9 +7,4 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_OPENSSL_ECDH_H) -#define OSSL_OPENSSL_ECDH_H - #include - -#endif /* !defined(OSSL_OPENSSL_ECDH_H) */ diff --git a/include/openssl/ecdsa.h b/include/openssl/ecdsa.h index e84dc60ed7..56bd4cc2ce 100644 --- a/include/openssl/ecdsa.h +++ b/include/openssl/ecdsa.h @@ -7,9 +7,4 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_OPENSSL_ECDSA_H) -#define OSSL_OPENSSL_ECDSA_H - #include - -#endif /* !defined(OSSL_OPENSSL_ECDSA_H) */ diff --git a/include/openssl/ech.h b/include/openssl/ech.h deleted file mode 100644 index 10417be60f..0000000000 --- a/include/openssl/ech.h +++ /dev/null @@ -1,134 +0,0 @@ -/* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the OpenSSL license (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* - * Externally-visible data structures and prototypes for handling - * shared-mode Encrypted ClientHello (ECH). - */ -#ifndef OPENSSL_ECH_H -#define OPENSSL_ECH_H -#pragma once - -#ifdef __cplusplus -extern "C" { -#endif - -#include -#include - -#ifndef OPENSSL_NO_ECH - -/* - * Some externally visible limits - most used for sanity checks that could be - * bigger if needed, but that work for now - */ -#define OSSL_ECH_MAX_PAYLOAD_LEN 1500 /* max ECH ciphertext to en/decode */ -#define OSSL_ECH_MIN_ECHCONFIG_LEN 32 /* min for all encodings */ -#define OSSL_ECH_MAX_ECHCONFIG_LEN 1500 /* max for all encodings */ -#define OSSL_ECH_MAX_ECHCONFIGEXT_LEN 512 /* ECHConfig extension max */ -#define OSSL_ECH_MAX_MAXNAMELEN 255 /* ECHConfig max for max name length */ -#define OSSL_ECH_MAX_PUBLICNAME 255 /* max ECHConfig public name length */ -#define OSSL_ECH_MAX_ALPNLEN 255 /* max alpn length */ -#define OSSL_ECH_OUTERS_MAX 20 /* max extensions we compress via outer-exts */ -#define OSSL_ECH_ALLEXTS_MAX 32 /* max total number of extension we allow */ - -/* - * ECH version. We only support RFC 9849 as of now. As/if new ECHConfig - * versions are added, those will be noted here. - */ -#define OSSL_ECH_RFC9849_VERSION 0xfe0d /* official ECHConfig version */ -/* latest version from an RFC */ -#define OSSL_ECH_CURRENT_VERSION OSSL_ECH_RFC9849_VERSION - -/* Return codes from SSL_ech_get1_status */ -#define SSL_ECH_STATUS_BACKEND 4 /* ECH backend: saw an ech_is_inner */ -#define SSL_ECH_STATUS_GREASE_ECH 3 /* GREASEd and got an ECH in return */ -#define SSL_ECH_STATUS_GREASE 2 /* ECH GREASE happened */ -#define SSL_ECH_STATUS_SUCCESS 1 /* Success */ -#define SSL_ECH_STATUS_FAILED 0 /* Some internal or protocol error */ -#define SSL_ECH_STATUS_BAD_CALL -100 /* Some in/out arguments were NULL */ -#define SSL_ECH_STATUS_NOT_TRIED -101 /* ECH wasn't attempted */ -#define SSL_ECH_STATUS_BAD_NAME -102 /* ECH ok but server cert bad */ -#define SSL_ECH_STATUS_NOT_CONFIGURED -103 /* ECH wasn't configured */ -#define SSL_ECH_STATUS_FAILED_ECH -105 /* Tried, failed, got an ECH, from a good name */ -#define SSL_ECH_STATUS_FAILED_ECH_BAD_NAME -106 /* Tried, failed, got an ECH, from a bad name */ - -/* if a caller wants to index the last entry in the store */ -#define OSSL_ECHSTORE_LAST -1 -/* if a caller wants all entries in the store, e.g. to print public values */ -#define OSSL_ECHSTORE_ALL -2 - -/* Values for the for_retry inputs */ -#define OSSL_ECH_FOR_RETRY 1 -#define OSSL_ECH_NO_RETRY 0 - -/* - * API calls built around OSSL_ECHSTORE - */ -OSSL_ECHSTORE *OSSL_ECHSTORE_new(OSSL_LIB_CTX *libctx, const char *propq); -void OSSL_ECHSTORE_free(OSSL_ECHSTORE *es); -int OSSL_ECHSTORE_new_config(OSSL_ECHSTORE *es, - uint16_t echversion, uint8_t max_name_length, - const char *public_name, OSSL_HPKE_SUITE suite); -int OSSL_ECHSTORE_write_pem(OSSL_ECHSTORE *es, int index, BIO *out); -int OSSL_ECHSTORE_read_echconfiglist(OSSL_ECHSTORE *es, BIO *in); -int OSSL_ECHSTORE_get1_info(OSSL_ECHSTORE *es, int index, time_t *loaded_secs, - char **public_name, char **echconfig, - int *has_private, int *for_retry); -int OSSL_ECHSTORE_downselect(OSSL_ECHSTORE *es, int index); -int OSSL_ECHSTORE_set1_key_and_read_pem(OSSL_ECHSTORE *es, EVP_PKEY *priv, - BIO *in, int for_retry); -int OSSL_ECHSTORE_read_pem(OSSL_ECHSTORE *es, BIO *in, int for_retry); -int OSSL_ECHSTORE_num_entries(const OSSL_ECHSTORE *es, int *numentries); -int OSSL_ECHSTORE_num_keys(OSSL_ECHSTORE *es, int *numkeys); -int OSSL_ECHSTORE_flush_keys(OSSL_ECHSTORE *es, time_t age); - -/* - * APIs relating OSSL_ECHSTORE to SSL/SSL_CTX - */ -int SSL_CTX_set1_echstore(SSL_CTX *ctx, OSSL_ECHSTORE *es); -int SSL_set1_echstore(SSL *s, OSSL_ECHSTORE *es); - -OSSL_ECHSTORE *SSL_CTX_get1_echstore(const SSL_CTX *ctx); -OSSL_ECHSTORE *SSL_get1_echstore(const SSL *s); - -int SSL_ech_set1_server_names(SSL *s, const char *inner_name, - const char *outer_name, int no_outer); -int SSL_ech_set1_outer_server_name(SSL *s, const char *outer_name, int no_outer); -/* - * Note that this function returns 1 for success and 0 for error. This - * contrasts with SSL_set1_alpn_protos() which (unusually for OpenSSL) - * returns 0 for success and 1 on error. - */ -int SSL_ech_set1_outer_alpn_protos(SSL *s, const unsigned char *protos, - const size_t protos_len); - -int SSL_ech_get1_status(SSL *s, char **inner_sni, char **outer_sni); -int SSL_ech_set1_grease_suite(SSL *s, const char *suite); -int SSL_ech_set_grease_type(SSL *s, uint16_t type); -typedef unsigned int (*SSL_ech_cb_func)(SSL *s, const char *str); -void SSL_ech_set_callback(SSL *s, SSL_ech_cb_func f); -int SSL_ech_get1_retry_config(SSL *s, unsigned char **ec, size_t *eclen); - -/* - * Note that this function returns 1 for success and 0 for error. This - * contrasts with SSL_set1_alpn_protos() which (unusually for OpenSSL) - * returns 0 for success and 1 on error. - */ -int SSL_CTX_ech_set1_outer_alpn_protos(SSL_CTX *s, const unsigned char *protos, - const size_t protos_len); -void SSL_CTX_ech_set_callback(SSL_CTX *ctx, SSL_ech_cb_func f); -int SSL_set1_ech_config_list(SSL *ssl, const uint8_t *ecl, size_t ecl_len); - -#ifdef __cplusplus -} -#endif - -#endif -#endif diff --git a/include/openssl/encoder.h b/include/openssl/encoder.h index 20545309be..9138c07276 100644 --- a/include/openssl/encoder.h +++ b/include/openssl/encoder.h @@ -50,8 +50,6 @@ const OSSL_PARAM *OSSL_ENCODER_settable_ctx_params(OSSL_ENCODER *encoder); OSSL_ENCODER_CTX *OSSL_ENCODER_CTX_new(void); int OSSL_ENCODER_CTX_set_params(OSSL_ENCODER_CTX *ctx, const OSSL_PARAM params[]); -int OSSL_ENCODER_CTX_ctrl_string(OSSL_ENCODER_CTX *ctx, - const char *name, const char *val); void OSSL_ENCODER_CTX_free(OSSL_ENCODER_CTX *ctx); /* Utilities that help set specific parameters */ diff --git a/include/openssl/encodererr.h b/include/openssl/encodererr.h index b895b6be32..e07174c3ac 100644 --- a/include/openssl/encodererr.h +++ b/include/openssl/encodererr.h @@ -1,6 +1,6 @@ /* * Generated by util/mkerr.pl DO NOT EDIT - * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -19,10 +19,8 @@ /* * OSSL_ENCODER reason codes. */ -#define OSSL_ENCODER_R_BAD_PARAMETER_VALUE 103 #define OSSL_ENCODER_R_ENCODER_NOT_FOUND 101 #define OSSL_ENCODER_R_INCORRECT_PROPERTY_QUERY 100 #define OSSL_ENCODER_R_MISSING_GET_PARAMS 102 -#define OSSL_ENCODER_R_UNKNOWN_PARAMETER_NAME 104 #endif diff --git a/include/openssl/engine.h b/include/openssl/engine.h index b9d97e2083..929aca52d0 100644 --- a/include/openssl/engine.h +++ b/include/openssl/engine.h @@ -39,27 +39,27 @@ #define ENGINE_FUNC(ret_type, name, args, default_val) \ OSSL_DEPRECATED_MESSAGE(#name ENGINE_INFO_MSG) \ - static ossl_inline ret_type name args \ + static inline ret_type name args \ { \ return default_val; /* stub return */ \ } #define ENGINE_FUNC_NOARGS(ret_type, name, default_val) \ OSSL_DEPRECATED_MESSAGE(#name ENGINE_INFO_MSG) \ - static ossl_inline ret_type name(void) \ + static inline ret_type name(void) \ { \ return default_val; /* stub return */ \ } #define ENGINE_VOID_FUNC(name, args) \ OSSL_DEPRECATED_MESSAGE(#name ENGINE_INFO_MSG) \ - static ossl_inline void name args \ + static inline void name args \ { \ } #define ENGINE_VOID_FUNC_NOARGS(name) \ OSSL_DEPRECATED_MESSAGE(#name ENGINE_INFO_MSG) \ - static ossl_inline void name(void) \ + static inline void name(void) \ { \ } #else /* OPENSSL_ENGINE_STUBS */ @@ -399,21 +399,21 @@ ENGINE_FUNC_NOARGS(ENGINE *, ENGINE_get_last, NULL) /* Iterate to the next/previous "ENGINE" type (NULL = end of the list). */ #ifndef OPENSSL_NO_DEPRECATED_3_0 /* OSSL_DEPRECATEDIN_3_0 ENGINE *ENGINE_get_next(ENGINE *e); */ -ENGINE_FUNC(ENGINE *, ENGINE_get_next, (ENGINE *e), NULL) +ENGINE_FUNC(ENGINE *, ENGINE_get_next, (ENGINE * e), NULL) /* OSSL_DEPRECATEDIN_3_0 ENGINE *ENGINE_get_prev(ENGINE *e); */ -ENGINE_FUNC(ENGINE *, ENGINE_get_prev, (ENGINE *e), NULL) +ENGINE_FUNC(ENGINE *, ENGINE_get_prev, (ENGINE * e), NULL) #endif /* Add another "ENGINE" type into the array. */ #ifndef OPENSSL_NO_DEPRECATED_3_0 /* OSSL_DEPRECATEDIN_3_0 int ENGINE_add(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_add, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_add, (ENGINE * e), 0) #endif /* Remove an existing "ENGINE" type from the array. */ #ifndef OPENSSL_NO_DEPRECATED_3_0 /* OSSL_DEPRECATEDIN_3_0 int ENGINE_remove(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_remove, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_remove, (ENGINE * e), 0) #endif /* Retrieve an engine from the list by its unique "id" value. */ #ifndef OPENSSL_NO_DEPRECATED_3_0 @@ -458,57 +458,57 @@ ENGINE_VOID_FUNC(ENGINE_set_table_flags, (unsigned int flags)) */ #ifndef OPENSSL_NO_DEPRECATED_3_0 /* OSSL_DEPRECATEDIN_3_0 int ENGINE_register_RSA(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_register_RSA, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_register_RSA, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_unregister_RSA(ENGINE *e); */ -ENGINE_VOID_FUNC(ENGINE_unregister_RSA, (ENGINE *e)) +ENGINE_VOID_FUNC(ENGINE_unregister_RSA, (ENGINE * e)) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_register_all_RSA(void); */ ENGINE_VOID_FUNC_NOARGS(ENGINE_register_all_RSA) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_register_DSA(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_register_DSA, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_register_DSA, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_unregister_DSA(ENGINE *e); */ -ENGINE_VOID_FUNC(ENGINE_unregister_DSA, (ENGINE *e)) +ENGINE_VOID_FUNC(ENGINE_unregister_DSA, (ENGINE * e)) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_register_all_DSA(void); */ ENGINE_VOID_FUNC_NOARGS(ENGINE_register_all_DSA) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_register_EC(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_register_EC, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_register_EC, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_unregister_EC(ENGINE *e); */ -ENGINE_VOID_FUNC(ENGINE_unregister_EC, (ENGINE *e)) +ENGINE_VOID_FUNC(ENGINE_unregister_EC, (ENGINE * e)) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_register_all_EC(void); */ -ENGINE_VOID_FUNC_NOARGS(ENGINE_register_all_EC) +ENGINE_VOID_FUNC_NOARGS(ENGINE_unregister_all_EC) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_register_DH(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_register_DH, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_register_DH, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_unregister_DH(ENGINE *e); */ -ENGINE_VOID_FUNC(ENGINE_unregister_DH, (ENGINE *e)) +ENGINE_VOID_FUNC(ENGINE_unregister_DH, (ENGINE * e)) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_register_all_DH(void); */ ENGINE_VOID_FUNC_NOARGS(ENGINE_register_all_DH) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_register_RAND(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_register_RAND, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_register_RAND, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_unregister_RAND(ENGINE *e); */ -ENGINE_VOID_FUNC(ENGINE_unregister_RAND, (ENGINE *e)) +ENGINE_VOID_FUNC(ENGINE_unregister_RAND, (ENGINE * e)) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_register_all_RAND(void); */ ENGINE_VOID_FUNC_NOARGS(ENGINE_register_all_RAND) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_register_ciphers(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_register_ciphers, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_register_ciphers, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_unregister_ciphers(ENGINE *e); */ -ENGINE_VOID_FUNC(ENGINE_unregister_ciphers, (ENGINE *e)) +ENGINE_VOID_FUNC(ENGINE_unregister_ciphers, (ENGINE * e)) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_register_all_ciphers(void); */ ENGINE_VOID_FUNC_NOARGS(ENGINE_register_all_ciphers) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_register_digests(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_register_digests, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_register_digests, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_unregister_digests(ENGINE *e); */ -ENGINE_VOID_FUNC(ENGINE_unregister_digests, (ENGINE *e)) +ENGINE_VOID_FUNC(ENGINE_unregister_digests, (ENGINE * e)) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_register_all_digests(void); */ ENGINE_VOID_FUNC_NOARGS(ENGINE_register_all_digests) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_register_pkey_meths(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_register_pkey_meths, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_register_pkey_meths, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_unregister_pkey_meths(ENGINE *e); */ -ENGINE_VOID_FUNC(ENGINE_unregister_pkey_meths, (ENGINE *e)) +ENGINE_VOID_FUNC(ENGINE_unregister_pkey_meths, (ENGINE * e)) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_register_all_pkey_meths(void); */ ENGINE_VOID_FUNC_NOARGS(ENGINE_register_all_pkey_meths) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_register_pkey_asn1_meths(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_register_pkey_asn1_meths, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_register_pkey_asn1_meths, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_unregister_pkey_asn1_meths(ENGINE *e); */ -ENGINE_VOID_FUNC(ENGINE_unregister_pkey_asn1_meths, (ENGINE *e)) +ENGINE_VOID_FUNC(ENGINE_unregister_pkey_asn1_meths, (ENGINE * e)) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_register_all_pkey_asn1_meths(void); */ ENGINE_VOID_FUNC_NOARGS(ENGINE_register_all_pkey_asn1_meths) #endif @@ -521,7 +521,7 @@ ENGINE_VOID_FUNC_NOARGS(ENGINE_register_all_pkey_asn1_meths) */ #ifndef OPENSSL_NO_DEPRECATED_3_0 /* OSSL_DEPRECATEDIN_3_0 int ENGINE_register_complete(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_register_complete, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_register_complete, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_register_all_complete(void); */ ENGINE_FUNC_NOARGS(int, ENGINE_register_all_complete, 0) #endif @@ -541,7 +541,7 @@ ENGINE_FUNC_NOARGS(int, ENGINE_register_all_complete, 0) * OSSL_DEPRECATEDIN_3_0 int ENGINE_ctrl(ENGINE *e, int cmd, long i, void *p, * void (*f) (void)); */ -ENGINE_FUNC(int, ENGINE_ctrl, (ENGINE *e, int cmd, long i, void *p, void (*f)(void)), 0) +ENGINE_FUNC(int, ENGINE_ctrl, (ENGINE * e, int cmd, long i, void *p, void (*f)(void)), 0) #endif /* @@ -552,7 +552,7 @@ ENGINE_FUNC(int, ENGINE_ctrl, (ENGINE *e, int cmd, long i, void *p, void (*f)(vo */ #ifndef OPENSSL_NO_DEPRECATED_3_0 /* OSSL_DEPRECATEDIN_3_0 int ENGINE_cmd_is_executable(ENGINE *e, int cmd); */ -ENGINE_FUNC(int, ENGINE_cmd_is_executable, (ENGINE *e, int cmd), 0) +ENGINE_FUNC(int, ENGINE_cmd_is_executable, (ENGINE * e, int cmd), 0) #endif /* @@ -567,7 +567,7 @@ ENGINE_FUNC(int, ENGINE_cmd_is_executable, (ENGINE *e, int cmd), 0) * long i, void *p, void (*f) (void), * int cmd_optional); */ -ENGINE_FUNC(int, ENGINE_ctrl_cmd, (ENGINE *e, const char *cmd_name, long i, void *p, void (*f)(void), int cmd_optional), 0) +ENGINE_FUNC(int, ENGINE_ctrl_cmd, (ENGINE * e, const char *cmd_name, long i, void *p, void (*f)(void), int cmd_optional), 0) #endif /* @@ -599,7 +599,7 @@ ENGINE_FUNC(int, ENGINE_ctrl_cmd, (ENGINE *e, const char *cmd_name, long i, void * int cmd_optional); */ ENGINE_FUNC(int, ENGINE_ctrl_cmd_string, - (ENGINE *e, const char *cmd_name, const char *arg, int cmd_optional), 0) + (ENGINE * e, const char *cmd_name, const char *arg, int cmd_optional), 0) #endif /* @@ -614,111 +614,111 @@ ENGINE_FUNC(int, ENGINE_ctrl_cmd_string, /* OSSL_DEPRECATEDIN_3_0 ENGINE *ENGINE_new(void); */ ENGINE_FUNC_NOARGS(ENGINE *, ENGINE_new, NULL) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_free(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_free, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_free, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_up_ref(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_up_ref, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_up_ref, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_set_id(ENGINE *e, const char *id); */ -ENGINE_FUNC(int, ENGINE_set_id, (ENGINE *e, const char *id), 0) +ENGINE_FUNC(int, ENGINE_set_id, (ENGINE * e, const char *id), 0) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_set_name(ENGINE *e, const char *name); */ -ENGINE_FUNC(int, ENGINE_set_name, (ENGINE *e, const char *name), 0) +ENGINE_FUNC(int, ENGINE_set_name, (ENGINE * e, const char *name), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_RSA(ENGINE *e, const RSA_METHOD *rsa_meth); */ -ENGINE_FUNC(int, ENGINE_set_RSA, (ENGINE *e, const RSA_METHOD *rsa_meth), 0) +ENGINE_FUNC(int, ENGINE_set_RSA, (ENGINE * e, const RSA_METHOD *rsa_meth), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_DSA(ENGINE *e, const DSA_METHOD *dsa_meth); */ -ENGINE_FUNC(int, ENGINE_set_DSA, (ENGINE *e, const DSA_METHOD *dsa_meth), 0) +ENGINE_FUNC(int, ENGINE_set_DSA, (ENGINE * e, const DSA_METHOD *dsa_meth), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_EC(ENGINE *e, const EC_KEY_METHOD *ecdsa_meth); */ -ENGINE_FUNC(int, ENGINE_set_EC, (ENGINE *e, const EC_KEY_METHOD *ecdsa_meth), 0) +ENGINE_FUNC(int, ENGINE_set_EC, (ENGINE * e, const EC_KEY_METHOD *ecdsa_meth), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_DH(ENGINE *e, const DH_METHOD *dh_meth); */ -ENGINE_FUNC(int, ENGINE_set_DH, (ENGINE *e, const DH_METHOD *dh_meth), 0) +ENGINE_FUNC(int, ENGINE_set_DH, (ENGINE * e, const DH_METHOD *dh_meth), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_RAND(ENGINE *e, const RAND_METHOD *rand_meth); */ -ENGINE_FUNC(int, ENGINE_set_RAND, (ENGINE *e, const RAND_METHOD *rand_meth), 0) +ENGINE_FUNC(int, ENGINE_set_RAND, (ENGINE * e, const RAND_METHOD *rand_meth), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_destroy_function(ENGINE *e, ENGINE_GEN_INT_FUNC_PTR destroy_f); */ ENGINE_FUNC(int, ENGINE_set_destroy_function, - (ENGINE *e, ENGINE_GEN_INT_FUNC_PTR destroy_f), 0) + (ENGINE * e, ENGINE_GEN_INT_FUNC_PTR destroy_f), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_init_function(ENGINE *e, ENGINE_GEN_INT_FUNC_PTR init_f); */ ENGINE_FUNC(int, ENGINE_set_init_function, - (ENGINE *e, ENGINE_GEN_INT_FUNC_PTR init_f), 0) + (ENGINE * e, ENGINE_GEN_INT_FUNC_PTR init_f), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_finish_function(ENGINE *e, ENGINE_GEN_INT_FUNC_PTR finish_f); */ ENGINE_FUNC(int, ENGINE_set_finish_function, - (ENGINE *e, ENGINE_GEN_INT_FUNC_PTR finish_f), 0) + (ENGINE * e, ENGINE_GEN_INT_FUNC_PTR finish_f), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_ctrl_function(ENGINE *e, ENGINE_CTRL_FUNC_PTR ctrl_f); */ ENGINE_FUNC(int, ENGINE_set_ctrl_function, - (ENGINE *e, ENGINE_CTRL_FUNC_PTR ctrl_f), 0) + (ENGINE * e, ENGINE_CTRL_FUNC_PTR ctrl_f), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_load_privkey_function(ENGINE *e, ENGINE_LOAD_KEY_PTR loadpriv_f); */ ENGINE_FUNC(int, ENGINE_set_load_privkey_function, - (ENGINE *e, ENGINE_LOAD_KEY_PTR loadpriv_f), 0) + (ENGINE * e, ENGINE_LOAD_KEY_PTR loadpriv_f), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_load_pubkey_function(ENGINE *e, ENGINE_LOAD_KEY_PTR loadpub_f); */ ENGINE_FUNC(int, ENGINE_set_load_pubkey_function, - (ENGINE *e, ENGINE_LOAD_KEY_PTR loadpub_f), 0) + (ENGINE * e, ENGINE_LOAD_KEY_PTR loadpub_f), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_load_ssl_client_cert_function(ENGINE *e, * ENGINE_SSL_CLIENT_CERT_PTR loadssl_f); */ ENGINE_FUNC(int, ENGINE_set_load_ssl_client_cert_function, - (ENGINE *e, ENGINE_SSL_CLIENT_CERT_PTR loadssl_f), 0) + (ENGINE * e, ENGINE_SSL_CLIENT_CERT_PTR loadssl_f), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_ciphers(ENGINE *e, ENGINE_CIPHERS_PTR f); */ -ENGINE_FUNC(int, ENGINE_set_ciphers, (ENGINE *e, ENGINE_CIPHERS_PTR f), 0) +ENGINE_FUNC(int, ENGINE_set_ciphers, (ENGINE * e, ENGINE_CIPHERS_PTR f), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_digests(ENGINE *e, ENGINE_DIGESTS_PTR f); */ -ENGINE_FUNC(int, ENGINE_set_digests, (ENGINE *e, ENGINE_DIGESTS_PTR f), 0) +ENGINE_FUNC(int, ENGINE_set_digests, (ENGINE * e, ENGINE_DIGESTS_PTR f), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_pkey_meths(ENGINE *e, ENGINE_PKEY_METHS_PTR f); */ -ENGINE_FUNC(int, ENGINE_set_pkey_meths, (ENGINE *e, ENGINE_PKEY_METHS_PTR f), 0) +ENGINE_FUNC(int, ENGINE_set_pkey_meths, (ENGINE * e, ENGINE_PKEY_METHS_PTR f), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_pkey_asn1_meths(ENGINE *e, ENGINE_PKEY_ASN1_METHS_PTR f); */ -ENGINE_FUNC(int, ENGINE_set_pkey_asn1_meths, (ENGINE *e, ENGINE_PKEY_ASN1_METHS_PTR f), +ENGINE_FUNC(int, ENGINE_set_pkey_asn1_meths, (ENGINE * e, ENGINE_PKEY_ASN1_METHS_PTR f), 0) /* * OSSL_DEPRECATEDIN_3_0 int ENGINE_set_flags(ENGINE *e, int flags); */ -ENGINE_FUNC(int, ENGINE_set_flags, (ENGINE *e, int flags), 0) +ENGINE_FUNC(int, ENGINE_set_flags, (ENGINE * e, int flags), 0) /* * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_cmd_defns(ENGINE *e, const ENGINE_CMD_DEFN *defns); */ -ENGINE_FUNC(int, ENGINE_set_cmd_defns, (ENGINE *e, const ENGINE_CMD_DEFN *defns), 0) +ENGINE_FUNC(int, ENGINE_set_cmd_defns, (ENGINE * e, const ENGINE_CMD_DEFN *defns), 0) #endif /* These functions allow control over any per-structure ENGINE data. */ #ifndef OPENSSL_ENGINE_STUBS @@ -732,9 +732,9 @@ ENGINE_FUNC(int, ENGINE_get_ex_new_index, (long l, void *p, CRYPTO_EX_new *newf, * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_ex_data(ENGINE *e, int idx, void *arg); */ -ENGINE_FUNC(int, ENGINE_set_ex_data, (ENGINE *e, int idx, void *arg), 0) +ENGINE_FUNC(int, ENGINE_set_ex_data, (ENGINE * e, int idx, void *arg), 0) /* OSSL_DEPRECATEDIN_3_0 void *ENGINE_get_ex_data(const ENGINE *e, int idx); */ -ENGINE_FUNC(void *, ENGINE_get_ex_data, (ENGINE *e, int idx), NULL) +ENGINE_FUNC(void *, ENGINE_get_ex_data, (ENGINE * e, int idx), NULL) #endif #ifndef OPENSSL_NO_DEPRECATED_1_1_0 @@ -839,39 +839,39 @@ ENGINE_FUNC(ENGINE_PKEY_ASN1_METHS_PTR, ENGINE_get_pkey_asn1_meths, * const EVP_CIPHER *ENGINE_get_cipher(ENGINE *e, int nid); */ ENGINE_FUNC(const EVP_CIPHER *, ENGINE_get_cipher, - (ENGINE *e, int nid), NULL) + (ENGINE * e, int nid), NULL) /* * OSSL_DEPRECATEDIN_3_0 * const EVP_MD *ENGINE_get_digest(ENGINE *e, int nid); */ ENGINE_FUNC(const EVP_MD *, ENGINE_get_digest, - (ENGINE *e, int nid), NULL) + (ENGINE * e, int nid), NULL) /* * OSSL_DEPRECATEDIN_3_0 * const EVP_PKEY_METHOD *ENGINE_get_pkey_meth(ENGINE *e, int nid); */ ENGINE_FUNC(const EVP_PKEY_METHOD *, ENGINE_get_pkey_meth, - (ENGINE *e, int nid), NULL) + (ENGINE * e, int nid), NULL) /* * OSSL_DEPRECATEDIN_3_0 * const EVP_PKEY_ASN1_METHOD *ENGINE_get_pkey_asn1_meth(ENGINE *e, int nid); */ ENGINE_FUNC(const EVP_PKEY_ASN1_METHOD *, ENGINE_get_pkey_asn1_meth, - (ENGINE *e, int nid), NULL) + (ENGINE * e, int nid), NULL) /* * OSSL_DEPRECATEDIN_3_0 * const EVP_PKEY_ASN1_METHOD *ENGINE_get_pkey_asn1_meth_str(ENGINE *e, * const char *str, int len); */ ENGINE_FUNC(const EVP_PKEY_ASN1_METHOD *, ENGINE_get_pkey_asn1_meth_str, - (ENGINE *e, const char *str, int len), NULL) + (ENGINE * e, const char *str, int len), NULL) /* * OSSL_DEPRECATEDIN_3_0 * const EVP_PKEY_ASN1_METHOD *ENGINE_pkey_asn1_find_str(ENGINE **pe, * const char *str, int len); */ ENGINE_FUNC(const EVP_PKEY_ASN1_METHOD *, ENGINE_pkey_asn1_find_str, - (ENGINE **pe, const char *str, int len), NULL) + (ENGINE * *pe, const char *str, int len), NULL) /* * OSSL_DEPRECATEDIN_3_0 * const ENGINE_CMD_DEFN *ENGINE_get_cmd_defns(const ENGINE *e); @@ -902,7 +902,7 @@ ENGINE_FUNC(int, ENGINE_get_flags, (const ENGINE *e), 0) */ #ifndef OPENSSL_NO_DEPRECATED_3_0 /* OSSL_DEPRECATEDIN_3_0 int ENGINE_init(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_init, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_init, (ENGINE * e), 0) #endif /* * Free a functional reference to an engine type. This does not require a @@ -911,7 +911,7 @@ ENGINE_FUNC(int, ENGINE_init, (ENGINE *e), 0) */ #ifndef OPENSSL_NO_DEPRECATED_3_0 /* OSSL_DEPRECATEDIN_3_0 int ENGINE_finish(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_finish, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_finish, (ENGINE * e), 0) #endif /* @@ -926,7 +926,7 @@ ENGINE_FUNC(int, ENGINE_finish, (ENGINE *e), 0) * UI_METHOD *ui_method, void *callback_data); */ ENGINE_FUNC(EVP_PKEY *, ENGINE_load_private_key, - (ENGINE *e, const char *key_id, UI_METHOD *ui_method, + (ENGINE * e, const char *key_id, UI_METHOD *ui_method, void *callback_data), NULL) /* @@ -935,7 +935,7 @@ ENGINE_FUNC(EVP_PKEY *, ENGINE_load_private_key, * UI_METHOD *ui_method, void *callback_data); */ ENGINE_FUNC(EVP_PKEY *, ENGINE_load_public_key, - (ENGINE *e, const char *key_id, UI_METHOD *ui_method, + (ENGINE * e, const char *key_id, UI_METHOD *ui_method, void *callback_data), NULL) /* @@ -946,7 +946,7 @@ ENGINE_FUNC(EVP_PKEY *, ENGINE_load_public_key, * UI_METHOD *ui_method, void *callback_data); */ ENGINE_FUNC(int, ENGINE_load_ssl_client_cert, - (ENGINE *e, SSL *s, STACK_OF(X509_NAME) *ca_dn, X509 **pcert, + (ENGINE * e, SSL *s, STACK_OF(X509_NAME) *ca_dn, X509 **pcert, EVP_PKEY **ppkey, STACK_OF(X509) **pother, UI_METHOD *ui_method, void *callback_data), 0) @@ -996,31 +996,31 @@ ENGINE_FUNC(ENGINE *, ENGINE_get_pkey_asn1_meth_engine, (int nid), NULL) */ #ifndef OPENSSL_NO_DEPRECATED_3_0 /* OSSL_DEPRECATEDIN_3_0 int ENGINE_set_default_RSA(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_set_default_RSA, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_set_default_RSA, (ENGINE * e), 0) /* * OSSL_DEPRECATEDIN_3_0 int ENGINE_set_default_string(ENGINE *e, * const char *def_list); */ -ENGINE_FUNC(int, ENGINE_set_default_string, (ENGINE *e, const char *def_list), 0) +ENGINE_FUNC(int, ENGINE_set_default_string, (ENGINE * e, const char *def_list), 0) #endif /* Same for the other "methods" */ #ifndef OPENSSL_NO_DEPRECATED_3_0 /* OSSL_DEPRECATEDIN_3_0 int ENGINE_set_default_DSA(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_set_default_DSA, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_set_default_DSA, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_set_default_EC(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_set_default_EC, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_set_default_EC, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_set_default_DH(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_set_default_DH, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_set_default_DH, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_set_default_RAND(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_set_default_RAND, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_set_default_RAND, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_set_default_ciphers(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_set_default_ciphers, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_set_default_ciphers, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_set_default_digests(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_set_default_digests, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_set_default_digests, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_set_default_pkey_meths(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_set_default_pkey_meths, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_set_default_pkey_meths, (ENGINE * e), 0) /* OSSL_DEPRECATEDIN_3_0 int ENGINE_set_default_pkey_asn1_meths(ENGINE *e); */ -ENGINE_FUNC(int, ENGINE_set_default_pkey_asn1_meths, (ENGINE *e), 0) +ENGINE_FUNC(int, ENGINE_set_default_pkey_asn1_meths, (ENGINE * e), 0) #endif /* @@ -1035,7 +1035,7 @@ ENGINE_FUNC(int, ENGINE_set_default_pkey_asn1_meths, (ENGINE *e), 0) * OSSL_DEPRECATEDIN_3_0 * int ENGINE_set_default(ENGINE *e, unsigned int flags); */ -ENGINE_FUNC(int, ENGINE_set_default, (ENGINE *e, unsigned int flags), 0) +ENGINE_FUNC(int, ENGINE_set_default, (ENGINE * e, unsigned int flags), 0) /* OSSL_DEPRECATEDIN_3_0 void ENGINE_add_conf_module(void); */ ENGINE_VOID_FUNC_NOARGS(ENGINE_add_conf_module) #endif @@ -1148,21 +1148,23 @@ ENGINE_VOID_FUNC_NOARGS(ENGINE_setup_bsd_cryptodev) * from other headers. */ -#ifndef OPENSSL_NO_DEPRECATED_3_0 +/* int ossl_err_load_ENGINE_strings(void); */ +ENGINE_FUNC_NOARGS(int, ossl_err_load_ENGINE_strings, 1) + /* int EVP_PKEY_set1_engine(EVP_PKEY *pkey, ENGINE *e); */ -ENGINE_FUNC(int, EVP_PKEY_set1_engine, (EVP_PKEY *pkey, ENGINE *e), 0) +ENGINE_FUNC(int, EVP_PKEY_set1_engine, (EVP_PKEY * pkey, ENGINE *e), 0) /* ENGINE *EVP_PKEY_get0_engine(const EVP_PKEY *pkey); */ ENGINE_FUNC(ENGINE *, EVP_PKEY_get0_engine, (const EVP_PKEY *pkey), NULL) /* ENGINE *DH_get0_engine(DH *d); */ -ENGINE_FUNC(ENGINE *, DH_get0_engine, (DH *d), NULL) +ENGINE_FUNC(ENGINE *, DH_get0_engine, (DH * d), NULL) /* ENGINE *RSA_get0_engine(const RSA *r); */ ENGINE_FUNC(ENGINE *, RSA_get0_engine, (const RSA *r), NULL) /* ENGINE *DSA_get0_engine(DSA *d); */ -ENGINE_FUNC(ENGINE *, DSA_get0_engine, (DSA *d), NULL) +ENGINE_FUNC(ENGINE *, DSA_get0_engine, (DSA * d), NULL) /* ENGINE *EC_KEY_get0_engine(const EC_KEY *eckey); */ ENGINE_FUNC(ENGINE *, EC_KEY_get0_engine, (const EC_KEY *eckey), NULL) @@ -1172,24 +1174,23 @@ ENGINE_FUNC(const ENGINE *, OSSL_STORE_LOADER_get0_engine, (const OSSL_STORE_LOA NULL) /* int RAND_set_rand_engine(ENGINE *engine); */ -ENGINE_FUNC(int, RAND_set_rand_engine, (ENGINE *engine), 0) - -/* int ERR_load_ENGINE_strings(void); */ -ENGINE_FUNC_NOARGS(int, ERR_load_ENGINE_strings, 1) -#endif +ENGINE_FUNC(int, RAND_set_rand_engine, (ENGINE * engine), 0) /* * int TS_CONF_set_crypto_device(CONF *conf, const char *section, * const char *device); */ ENGINE_FUNC(int, TS_CONF_set_crypto_device, - (CONF *conf, const char *section, const char *device), 0) + (CONF * conf, const char *section, const char *device), 0) /* int TS_CONF_set_default_engine(const char *name); */ ENGINE_FUNC(int, TS_CONF_set_default_engine, (const char *name), 0) +/* int ERR_load_ENGINE_strings(void); */ +ENGINE_FUNC_NOARGS(int, ERR_load_ENGINE_strings, 1) + /* int SSL_CTX_set_client_cert_engine(SSL_CTX *ctx, ENGINE *e); */ -ENGINE_FUNC(int, SSL_CTX_set_client_cert_engine, (SSL_CTX *ctx, ENGINE *e), 0) +ENGINE_FUNC(int, SSL_CTX_set_client_cert_engine, (SSL_CTX * ctx, ENGINE *e), 0) #ifdef __cplusplus } diff --git a/include/openssl/err.h.in b/include/openssl/err.h.in index de27183c00..d451f82eca 100644 --- a/include/openssl/err.h.in +++ b/include/openssl/err.h.in @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -52,6 +52,25 @@ extern "C" { #define ERR_TXT_MALLOCED 0x01 #define ERR_TXT_STRING 0x02 +#if !defined(OPENSSL_NO_DEPRECATED_3_0) || defined(OSSL_FORCE_ERR_STATE) +#define ERR_FLAG_MARK 0x01 +#define ERR_FLAG_CLEAR 0x02 + +#define ERR_NUM_ERRORS 16 +struct err_state_st { + int err_flags[ERR_NUM_ERRORS]; + int err_marks[ERR_NUM_ERRORS]; + unsigned long err_buffer[ERR_NUM_ERRORS]; + char *err_data[ERR_NUM_ERRORS]; + size_t err_data_size[ERR_NUM_ERRORS]; + int err_data_flags[ERR_NUM_ERRORS]; + char *err_file[ERR_NUM_ERRORS]; + int err_line[ERR_NUM_ERRORS]; + char *err_func[ERR_NUM_ERRORS]; + int top, bottom; +}; +#endif + /* library */ #define ERR_LIB_NONE 1 #define ERR_LIB_SYS 2 @@ -263,6 +282,34 @@ static ossl_unused ossl_inline int ERR_COMMON_ERROR(unsigned long errcode) #define ERR_PACK(lib, func, reason) \ ((((unsigned long)(lib) & ERR_LIB_MASK) << ERR_LIB_OFFSET) | (((unsigned long)(reason) & ERR_REASON_MASK))) +#ifndef OPENSSL_NO_DEPRECATED_3_0 +#define SYS_F_FOPEN 0 +#define SYS_F_CONNECT 0 +#define SYS_F_GETSERVBYNAME 0 +#define SYS_F_SOCKET 0 +#define SYS_F_IOCTLSOCKET 0 +#define SYS_F_BIND 0 +#define SYS_F_LISTEN 0 +#define SYS_F_ACCEPT 0 +#define SYS_F_WSASTARTUP 0 +#define SYS_F_OPENDIR 0 +#define SYS_F_FREAD 0 +#define SYS_F_GETADDRINFO 0 +#define SYS_F_GETNAMEINFO 0 +#define SYS_F_SETSOCKOPT 0 +#define SYS_F_GETSOCKOPT 0 +#define SYS_F_GETSOCKNAME 0 +#define SYS_F_GETHOSTBYNAME 0 +#define SYS_F_FFLUSH 0 +#define SYS_F_OPEN 0 +#define SYS_F_CLOSE 0 +#define SYS_F_IOCTL 0 +#define SYS_F_STAT 0 +#define SYS_F_FCNTL 0 +#define SYS_F_FSTAT 0 +#define SYS_F_SENDFILE 0 +#endif + /* * All ERR_R_ codes must be combined with ERR_RFLAG_COMMON. */ @@ -428,6 +475,15 @@ int ERR_unload_strings(int lib, ERR_STRING_DATA *str); while (0) \ continue #endif +#ifndef OPENSSL_NO_DEPRECATED_1_1_0 +OSSL_DEPRECATEDIN_1_1_0 void ERR_remove_thread_state(void *); +#endif +#ifndef OPENSSL_NO_DEPRECATED_1_0_0 +OSSL_DEPRECATEDIN_1_0_0 void ERR_remove_state(unsigned long pid); +#endif +#ifndef OPENSSL_NO_DEPRECATED_3_0 +OSSL_DEPRECATEDIN_3_0 ERR_STATE *ERR_get_state(void); +#endif int ERR_get_next_error_library(void); diff --git a/include/openssl/ess.h.in b/include/openssl/ess.h.in index 096ba45b3a..62aaec1726 100644 --- a/include/openssl/ess.h.in +++ b/include/openssl/ess.h.in @@ -1,7 +1,7 @@ /* * {- join("\n * ", @autowarntext) -} * - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2021 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -77,12 +77,7 @@ int OSSL_ESS_check_signing_certs(const ESS_SIGNING_CERT *ss, const ESS_SIGNING_CERT_V2 *ssv2, const STACK_OF(X509) *chain, int require_signing_cert); -int OSSL_ESS_check_signing_certs_ex(const ESS_SIGNING_CERT *ss, - const ESS_SIGNING_CERT_V2 *ssv2, - const STACK_OF(X509) *chain, - OSSL_LIB_CTX *libctx, - const char *propq, - int require_signing_cert); + #ifdef __cplusplus } #endif diff --git a/include/openssl/evp.h b/include/openssl/evp.h index dcbc5b26d3..6c05d9a913 100644 --- a/include/openssl/evp.h +++ b/include/openssl/evp.h @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -17,7 +17,6 @@ #endif #include -#include #ifndef OPENSSL_NO_STDIO #include @@ -99,7 +98,6 @@ #define EVP_PKEY_SLH_DSA_SHAKE_192F NID_SLH_DSA_SHAKE_192f #define EVP_PKEY_SLH_DSA_SHAKE_256S NID_SLH_DSA_SHAKE_256s #define EVP_PKEY_SLH_DSA_SHAKE_256F NID_SLH_DSA_SHAKE_256f -#define EVP_PKEY_HSS_LMS NID_id_alg_hss_lms_hashsig /* Special indicator that the object is uniquely provider side */ #define EVP_PKEY_KEYMGMT -1 @@ -122,7 +120,6 @@ int EVP_set_default_properties(OSSL_LIB_CTX *libctx, const char *propq); char *EVP_get1_default_properties(OSSL_LIB_CTX *libctx); int EVP_default_properties_is_fips_enabled(OSSL_LIB_CTX *libctx); int EVP_default_properties_enable_fips(OSSL_LIB_CTX *libctx, int enable); -#define FIPS_mode() EVP_default_properties_is_fips_enabled(NULL) #define EVP_PKEY_MO_SIGN 0x0001 #define EVP_PKEY_MO_VERIFY 0x0002 @@ -130,6 +127,51 @@ int EVP_default_properties_enable_fips(OSSL_LIB_CTX *libctx, int enable); #define EVP_PKEY_MO_DECRYPT 0x0008 #ifndef EVP_MD +#ifndef OPENSSL_NO_DEPRECATED_3_0 +OSSL_DEPRECATEDIN_3_0 EVP_MD *EVP_MD_meth_new(int md_type, int pkey_type); +OSSL_DEPRECATEDIN_3_0 EVP_MD *EVP_MD_meth_dup(const EVP_MD *md); +OSSL_DEPRECATEDIN_3_0 void EVP_MD_meth_free(EVP_MD *md); +OSSL_DEPRECATEDIN_3_0 +int EVP_MD_meth_set_input_blocksize(EVP_MD *md, int blocksize); +OSSL_DEPRECATEDIN_3_0 +int EVP_MD_meth_set_result_size(EVP_MD *md, int resultsize); +OSSL_DEPRECATEDIN_3_0 +int EVP_MD_meth_set_app_datasize(EVP_MD *md, int datasize); +OSSL_DEPRECATEDIN_3_0 +int EVP_MD_meth_set_flags(EVP_MD *md, unsigned long flags); +OSSL_DEPRECATEDIN_3_0 +int EVP_MD_meth_set_init(EVP_MD *md, int (*init)(EVP_MD_CTX *ctx)); +OSSL_DEPRECATEDIN_3_0 +int EVP_MD_meth_set_update(EVP_MD *md, int (*update)(EVP_MD_CTX *ctx, const void *data, size_t count)); +OSSL_DEPRECATEDIN_3_0 +int EVP_MD_meth_set_final(EVP_MD *md, int (*final)(EVP_MD_CTX *ctx, unsigned char *md)); +OSSL_DEPRECATEDIN_3_0 +int EVP_MD_meth_set_copy(EVP_MD *md, int (*copy)(EVP_MD_CTX *to, const EVP_MD_CTX *from)); +OSSL_DEPRECATEDIN_3_0 +int EVP_MD_meth_set_cleanup(EVP_MD *md, int (*cleanup)(EVP_MD_CTX *ctx)); +OSSL_DEPRECATEDIN_3_0 +int EVP_MD_meth_set_ctrl(EVP_MD *md, int (*ctrl)(EVP_MD_CTX *ctx, int cmd, int p1, void *p2)); +OSSL_DEPRECATEDIN_3_0 int EVP_MD_meth_get_input_blocksize(const EVP_MD *md); +OSSL_DEPRECATEDIN_3_0 int EVP_MD_meth_get_result_size(const EVP_MD *md); +OSSL_DEPRECATEDIN_3_0 int EVP_MD_meth_get_app_datasize(const EVP_MD *md); +OSSL_DEPRECATEDIN_3_0 unsigned long EVP_MD_meth_get_flags(const EVP_MD *md); +OSSL_DEPRECATEDIN_3_0 +int (*EVP_MD_meth_get_init(const EVP_MD *md))(EVP_MD_CTX *ctx); +OSSL_DEPRECATEDIN_3_0 +int (*EVP_MD_meth_get_update(const EVP_MD *md))(EVP_MD_CTX *ctx, + const void *data, size_t count); +OSSL_DEPRECATEDIN_3_0 +int (*EVP_MD_meth_get_final(const EVP_MD *md))(EVP_MD_CTX *ctx, + unsigned char *md); +OSSL_DEPRECATEDIN_3_0 +int (*EVP_MD_meth_get_copy(const EVP_MD *md))(EVP_MD_CTX *to, + const EVP_MD_CTX *from); +OSSL_DEPRECATEDIN_3_0 +int (*EVP_MD_meth_get_cleanup(const EVP_MD *md))(EVP_MD_CTX *ctx); +OSSL_DEPRECATEDIN_3_0 +int (*EVP_MD_meth_get_ctrl(const EVP_MD *md))(EVP_MD_CTX *ctx, int cmd, + int p1, void *p2); +#endif /* digest can only handle a single block */ #define EVP_MD_FLAG_ONESHOT 0x0001 @@ -155,8 +197,6 @@ int EVP_default_properties_enable_fips(OSSL_LIB_CTX *libctx, int enable); /* Note if suitable for use in FIPS mode */ #define EVP_MD_FLAG_FIPS 0x0400 -#define EVP_MD_FLAG_NO_STORE 0x0800 - /* Digest ctrls */ #define EVP_MD_CTRL_DIGALGID 0x1 @@ -206,6 +246,63 @@ int EVP_default_properties_enable_fips(OSSL_LIB_CTX *libctx, int enable); #define EVP_MD_CTX_FLAG_FINALISE 0x0200 /* NOTE: 0x0400 and 0x0800 are reserved for internal usage */ +#ifndef OPENSSL_NO_DEPRECATED_3_0 +OSSL_DEPRECATEDIN_3_0 +EVP_CIPHER *EVP_CIPHER_meth_new(int cipher_type, int block_size, int key_len); +OSSL_DEPRECATEDIN_3_0 +EVP_CIPHER *EVP_CIPHER_meth_dup(const EVP_CIPHER *cipher); +OSSL_DEPRECATEDIN_3_0 +void EVP_CIPHER_meth_free(EVP_CIPHER *cipher); +OSSL_DEPRECATEDIN_3_0 +int EVP_CIPHER_meth_set_iv_length(EVP_CIPHER *cipher, int iv_len); +OSSL_DEPRECATEDIN_3_0 +int EVP_CIPHER_meth_set_flags(EVP_CIPHER *cipher, unsigned long flags); +OSSL_DEPRECATEDIN_3_0 +int EVP_CIPHER_meth_set_impl_ctx_size(EVP_CIPHER *cipher, int ctx_size); +OSSL_DEPRECATEDIN_3_0 +int EVP_CIPHER_meth_set_init(EVP_CIPHER *cipher, + int (*init)(EVP_CIPHER_CTX *ctx, + const unsigned char *key, + const unsigned char *iv, + int enc)); +OSSL_DEPRECATEDIN_3_0 +int EVP_CIPHER_meth_set_do_cipher(EVP_CIPHER *cipher, + int (*do_cipher)(EVP_CIPHER_CTX *ctx, + unsigned char *out, + const unsigned char *in, + size_t inl)); +OSSL_DEPRECATEDIN_3_0 +int EVP_CIPHER_meth_set_cleanup(EVP_CIPHER *cipher, + int (*cleanup)(EVP_CIPHER_CTX *)); +OSSL_DEPRECATEDIN_3_0 +int EVP_CIPHER_meth_set_set_asn1_params(EVP_CIPHER *cipher, + int (*set_asn1_parameters)(EVP_CIPHER_CTX *, + ASN1_TYPE *)); +OSSL_DEPRECATEDIN_3_0 +int EVP_CIPHER_meth_set_get_asn1_params(EVP_CIPHER *cipher, + int (*get_asn1_parameters)(EVP_CIPHER_CTX *, + ASN1_TYPE *)); +OSSL_DEPRECATEDIN_3_0 +int EVP_CIPHER_meth_set_ctrl(EVP_CIPHER *cipher, + int (*ctrl)(EVP_CIPHER_CTX *, int type, + int arg, void *ptr)); +OSSL_DEPRECATEDIN_3_0 int (*EVP_CIPHER_meth_get_init(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *ctx, + const unsigned char *key, + const unsigned char *iv, + int enc); +OSSL_DEPRECATEDIN_3_0 int (*EVP_CIPHER_meth_get_do_cipher(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *ctx, + unsigned char *out, + const unsigned char *in, + size_t inl); +OSSL_DEPRECATEDIN_3_0 int (*EVP_CIPHER_meth_get_cleanup(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *); +OSSL_DEPRECATEDIN_3_0 int (*EVP_CIPHER_meth_get_set_asn1_params(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *, + ASN1_TYPE *); +OSSL_DEPRECATEDIN_3_0 int (*EVP_CIPHER_meth_get_get_asn1_params(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *, + ASN1_TYPE *); +OSSL_DEPRECATEDIN_3_0 int (*EVP_CIPHER_meth_get_ctrl(const EVP_CIPHER *cipher))(EVP_CIPHER_CTX *, int type, + int arg, void *ptr); +#endif + /* Values for cipher flags */ /* Modes for ciphers */ @@ -269,8 +366,6 @@ int EVP_default_properties_enable_fips(OSSL_LIB_CTX *libctx, int enable); #define EVP_CIPH_FLAG_GET_WRAP_CIPHER 0x4000000 #define EVP_CIPH_FLAG_INVERSE_CIPHER 0x8000000 #define EVP_CIPH_FLAG_ENC_THEN_MAC 0x10000000 -/* flag to indicate that this cipher isn't cached, and so should be refcounted*/ -#define EVP_CIPH_FLAG_NO_STORE 0x20000000 /* * Cipher context flag to indicate we can handle wrap mode: if allowed in @@ -480,7 +575,13 @@ EVP_MD *EVP_MD_CTX_get1_md(EVP_MD_CTX *ctx); #ifndef OPENSSL_NO_DEPRECATED_3_0 OSSL_DEPRECATEDIN_3_0 const EVP_MD *EVP_MD_CTX_md(const EVP_MD_CTX *ctx); - +OSSL_DEPRECATEDIN_3_0 +int (*EVP_MD_CTX_update_fn(EVP_MD_CTX *ctx))(EVP_MD_CTX *ctx, + const void *data, size_t count); +OSSL_DEPRECATEDIN_3_0 +void EVP_MD_CTX_set_update_fn(EVP_MD_CTX *ctx, + int (*update)(EVP_MD_CTX *ctx, + const void *data, size_t count)); #endif int EVP_MD_CTX_get_size_ex(const EVP_MD_CTX *ctx); @@ -494,11 +595,8 @@ int EVP_MD_CTX_get_size_ex(const EVP_MD_CTX *ctx); EVP_PKEY_CTX *EVP_MD_CTX_get_pkey_ctx(const EVP_MD_CTX *ctx); #define EVP_MD_CTX_pkey_ctx EVP_MD_CTX_get_pkey_ctx void EVP_MD_CTX_set_pkey_ctx(EVP_MD_CTX *ctx, EVP_PKEY_CTX *pctx); -#ifndef OPENSSL_NO_DEPRECATED_4_0 -OSSL_DEPRECATEDIN_4_0 void *EVP_MD_CTX_get0_md_data(const EVP_MD_CTX *ctx); #define EVP_MD_CTX_md_data EVP_MD_CTX_get0_md_data -#endif int EVP_CIPHER_get_nid(const EVP_CIPHER *cipher); #define EVP_CIPHER_nid EVP_CIPHER_get_nid @@ -558,12 +656,9 @@ int EVP_CIPHER_CTX_get_original_iv(EVP_CIPHER_CTX *ctx, void *buf, size_t len); OSSL_DEPRECATEDIN_3_0 unsigned char *EVP_CIPHER_CTX_buf_noconst(EVP_CIPHER_CTX *ctx); #endif -#ifndef OPENSSL_NO_DEPRECATED_4_1 -OSSL_DEPRECATEDIN_4_1 int EVP_CIPHER_CTX_get_num(const EVP_CIPHER_CTX *ctx); +int EVP_CIPHER_CTX_get_num(const EVP_CIPHER_CTX *ctx); #define EVP_CIPHER_CTX_num EVP_CIPHER_CTX_get_num -OSSL_DEPRECATEDIN_4_1 int EVP_CIPHER_CTX_set_num(EVP_CIPHER_CTX *ctx, int num); -#endif - +int EVP_CIPHER_CTX_set_num(EVP_CIPHER_CTX *ctx, int num); EVP_CIPHER_CTX *EVP_CIPHER_CTX_dup(const EVP_CIPHER_CTX *in); int EVP_CIPHER_CTX_copy(EVP_CIPHER_CTX *out, const EVP_CIPHER_CTX *in); void *EVP_CIPHER_CTX_get_app_data(const EVP_CIPHER_CTX *ctx); @@ -579,7 +674,7 @@ void *EVP_CIPHER_CTX_set_cipher_data(EVP_CIPHER_CTX *ctx, void *cipher_data); #define EVP_CIPHER_CTX_get_mode(c) EVP_CIPHER_get_mode(EVP_CIPHER_CTX_get0_cipher(c)) #define EVP_CIPHER_CTX_mode EVP_CIPHER_CTX_get_mode -#define EVP_ENCODE_LENGTH(l) (((((size_t)(l)) + 2) / 3 * 4) + (((size_t)(l)) / 48 + 1) * 2 + 80) +#define EVP_ENCODE_LENGTH(l) ((((l) + 2) / 3 * 4) + ((l) / 48 + 1) * 2 + 80) #define EVP_DECODE_LENGTH(l) (((l) + 3) / 4 * 3 + 80) #define EVP_SignInit_ex(a, b, c) EVP_DigestInit_ex(a, b, c) @@ -658,10 +753,6 @@ __owur int EVP_DigestFinalXOF(EVP_MD_CTX *ctx, unsigned char *out, size_t outlen); __owur int EVP_DigestSqueeze(EVP_MD_CTX *ctx, unsigned char *out, size_t outlen); -__owur int EVP_MD_CTX_serialize(EVP_MD_CTX *ctx, unsigned char *out, - size_t *outlen); -__owur int EVP_MD_CTX_deserialize(EVP_MD_CTX *ctx, const unsigned char *in, - size_t inlen); __owur EVP_MD *EVP_MD_fetch(OSSL_LIB_CTX *ctx, const char *algorithm, const char *properties); @@ -855,6 +946,7 @@ int EVP_CIPHER_CTX_get_algor(EVP_CIPHER_CTX *ctx, X509_ALGOR **alg); const BIO_METHOD *BIO_f_md(void); const BIO_METHOD *BIO_f_base64(void); const BIO_METHOD *BIO_f_cipher(void); +const BIO_METHOD *BIO_f_reliable(void); __owur int BIO_set_cipher(BIO *b, const EVP_CIPHER *c, const unsigned char *k, const unsigned char *i, int enc); @@ -1522,6 +1614,138 @@ int EVP_PBE_get(int *ptype, int *ppbe_nid, size_t num); #define ASN1_PKEY_CTRL_GET1_TLS_ENCPT 0xa #define ASN1_PKEY_CTRL_CMS_IS_RI_TYPE_SUPPORTED 0xb +#ifndef OPENSSL_NO_DEPRECATED_3_6 +OSSL_DEPRECATEDIN_3_6 int EVP_PKEY_asn1_get_count(void); +OSSL_DEPRECATEDIN_3_6 const EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_get0(int idx); +OSSL_DEPRECATEDIN_3_6 +const EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_find(ENGINE **pe, int type); +OSSL_DEPRECATEDIN_3_6 +const EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_find_str(ENGINE **pe, + const char *str, int len); +OSSL_DEPRECATEDIN_3_6 int EVP_PKEY_asn1_add0(const EVP_PKEY_ASN1_METHOD *ameth); +OSSL_DEPRECATEDIN_3_6 int EVP_PKEY_asn1_add_alias(int to, int from); +OSSL_DEPRECATEDIN_3_6 +int EVP_PKEY_asn1_get0_info(int *ppkey_id, int *pkey_base_id, + int *ppkey_flags, const char **pinfo, + const char **ppem_str, + const EVP_PKEY_ASN1_METHOD *ameth); + +OSSL_DEPRECATEDIN_3_6 const EVP_PKEY_ASN1_METHOD *EVP_PKEY_get0_asn1(const EVP_PKEY *pkey); +OSSL_DEPRECATEDIN_3_6 EVP_PKEY_ASN1_METHOD *EVP_PKEY_asn1_new(int id, int flags, + const char *pem_str, + const char *info); +OSSL_DEPRECATEDIN_3_6 void EVP_PKEY_asn1_copy(EVP_PKEY_ASN1_METHOD *dst, + const EVP_PKEY_ASN1_METHOD *src); +OSSL_DEPRECATEDIN_3_6 void EVP_PKEY_asn1_free(EVP_PKEY_ASN1_METHOD *ameth); +OSSL_DEPRECATEDIN_3_6 +void EVP_PKEY_asn1_set_public(EVP_PKEY_ASN1_METHOD *ameth, + int (*pub_decode)(EVP_PKEY *pk, + const X509_PUBKEY *pub), + int (*pub_encode)(X509_PUBKEY *pub, + const EVP_PKEY *pk), + int (*pub_cmp)(const EVP_PKEY *a, + const EVP_PKEY *b), + int (*pub_print)(BIO *out, + const EVP_PKEY *pkey, + int indent, ASN1_PCTX *pctx), + int (*pkey_size)(const EVP_PKEY *pk), + int (*pkey_bits)(const EVP_PKEY *pk)); +OSSL_DEPRECATEDIN_3_6 +void EVP_PKEY_asn1_set_private(EVP_PKEY_ASN1_METHOD *ameth, + int (*priv_decode)(EVP_PKEY *pk, + const PKCS8_PRIV_KEY_INFO + *p8inf), + int (*priv_encode)(PKCS8_PRIV_KEY_INFO *p8, + const EVP_PKEY *pk), + int (*priv_print)(BIO *out, + const EVP_PKEY *pkey, + int indent, + ASN1_PCTX *pctx)); +OSSL_DEPRECATEDIN_3_6 +void EVP_PKEY_asn1_set_param(EVP_PKEY_ASN1_METHOD *ameth, + int (*param_decode)(EVP_PKEY *pkey, + const unsigned char **pder, + int derlen), + int (*param_encode)(const EVP_PKEY *pkey, + unsigned char **pder), + int (*param_missing)(const EVP_PKEY *pk), + int (*param_copy)(EVP_PKEY *to, + const EVP_PKEY *from), + int (*param_cmp)(const EVP_PKEY *a, + const EVP_PKEY *b), + int (*param_print)(BIO *out, + const EVP_PKEY *pkey, + int indent, + ASN1_PCTX *pctx)); + +OSSL_DEPRECATEDIN_3_6 +void EVP_PKEY_asn1_set_free(EVP_PKEY_ASN1_METHOD *ameth, + void (*pkey_free)(EVP_PKEY *pkey)); +OSSL_DEPRECATEDIN_3_6 +void EVP_PKEY_asn1_set_ctrl(EVP_PKEY_ASN1_METHOD *ameth, + int (*pkey_ctrl)(EVP_PKEY *pkey, int op, + long arg1, void *arg2)); +OSSL_DEPRECATEDIN_3_6 +void EVP_PKEY_asn1_set_item(EVP_PKEY_ASN1_METHOD *ameth, + int (*item_verify)(EVP_MD_CTX *ctx, + const ASN1_ITEM *it, + const void *data, + const X509_ALGOR *a, + const ASN1_BIT_STRING *sig, + EVP_PKEY *pkey), + int (*item_sign)(EVP_MD_CTX *ctx, + const ASN1_ITEM *it, + const void *data, + X509_ALGOR *alg1, + X509_ALGOR *alg2, + ASN1_BIT_STRING *sig)); + +OSSL_DEPRECATEDIN_3_6 +void EVP_PKEY_asn1_set_siginf(EVP_PKEY_ASN1_METHOD *ameth, + int (*siginf_set)(X509_SIG_INFO *siginf, + const X509_ALGOR *alg, + const ASN1_STRING *sig)); + +OSSL_DEPRECATEDIN_3_6 +void EVP_PKEY_asn1_set_check(EVP_PKEY_ASN1_METHOD *ameth, + int (*pkey_check)(const EVP_PKEY *pk)); + +OSSL_DEPRECATEDIN_3_6 +void EVP_PKEY_asn1_set_public_check(EVP_PKEY_ASN1_METHOD *ameth, + int (*pkey_pub_check)(const EVP_PKEY *pk)); + +OSSL_DEPRECATEDIN_3_6 +void EVP_PKEY_asn1_set_param_check(EVP_PKEY_ASN1_METHOD *ameth, + int (*pkey_param_check)(const EVP_PKEY *pk)); + +OSSL_DEPRECATEDIN_3_6 +void EVP_PKEY_asn1_set_set_priv_key(EVP_PKEY_ASN1_METHOD *ameth, + int (*set_priv_key)(EVP_PKEY *pk, + const unsigned char + *priv, + size_t len)); +OSSL_DEPRECATEDIN_3_6 +void EVP_PKEY_asn1_set_set_pub_key(EVP_PKEY_ASN1_METHOD *ameth, + int (*set_pub_key)(EVP_PKEY *pk, + const unsigned char *pub, + size_t len)); +OSSL_DEPRECATEDIN_3_6 +void EVP_PKEY_asn1_set_get_priv_key(EVP_PKEY_ASN1_METHOD *ameth, + int (*get_priv_key)(const EVP_PKEY *pk, + unsigned char *priv, + size_t *len)); +OSSL_DEPRECATEDIN_3_6 +void EVP_PKEY_asn1_set_get_pub_key(EVP_PKEY_ASN1_METHOD *ameth, + int (*get_pub_key)(const EVP_PKEY *pk, + unsigned char *pub, + size_t *len)); + +OSSL_DEPRECATEDIN_3_6 +void EVP_PKEY_asn1_set_security_bits(EVP_PKEY_ASN1_METHOD *ameth, + int (*pkey_security_bits)(const EVP_PKEY + *pk)); +#endif /* OPENSSL_NO_DEPRECATED_3_6 */ + int EVP_PKEY_CTX_get_signature_md(EVP_PKEY_CTX *ctx, const EVP_MD **md); int EVP_PKEY_CTX_set_signature_md(EVP_PKEY_CTX *ctx, const EVP_MD *md); @@ -1607,6 +1831,19 @@ int EVP_PKEY_CTX_set_mac_key(EVP_PKEY_CTX *ctx, const unsigned char *key, * Method handles all operations: don't assume any digest related defaults. */ #define EVP_PKEY_FLAG_SIGCTX_CUSTOM 4 +#ifndef OPENSSL_NO_DEPRECATED_3_0 +OSSL_DEPRECATEDIN_3_0 const EVP_PKEY_METHOD *EVP_PKEY_meth_find(int type); +OSSL_DEPRECATEDIN_3_0 EVP_PKEY_METHOD *EVP_PKEY_meth_new(int id, int flags); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get0_info(int *ppkey_id, int *pflags, + const EVP_PKEY_METHOD *meth); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_copy(EVP_PKEY_METHOD *dst, + const EVP_PKEY_METHOD *src); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_free(EVP_PKEY_METHOD *pmeth); +OSSL_DEPRECATEDIN_3_0 int EVP_PKEY_meth_add0(const EVP_PKEY_METHOD *pmeth); +OSSL_DEPRECATEDIN_3_0 int EVP_PKEY_meth_remove(const EVP_PKEY_METHOD *pmeth); +OSSL_DEPRECATEDIN_3_0 size_t EVP_PKEY_meth_get_count(void); +OSSL_DEPRECATEDIN_3_0 const EVP_PKEY_METHOD *EVP_PKEY_meth_get0(size_t idx); +#endif EVP_KEYMGMT *EVP_KEYMGMT_fetch(OSSL_LIB_CTX *ctx, const char *algorithm, const char *properties); @@ -1900,6 +2137,103 @@ void EVP_PKEY_CTX_set_cb(EVP_PKEY_CTX *ctx, EVP_PKEY_gen_cb *cb); EVP_PKEY_gen_cb *EVP_PKEY_CTX_get_cb(EVP_PKEY_CTX *ctx); int EVP_PKEY_CTX_get_keygen_info(EVP_PKEY_CTX *ctx, int idx); +#ifndef OPENSSL_NO_DEPRECATED_3_0 +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_init(EVP_PKEY_METHOD *pmeth, + int (*init)(EVP_PKEY_CTX *ctx)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_copy(EVP_PKEY_METHOD *pmeth, int (*copy)(EVP_PKEY_CTX *dst, const EVP_PKEY_CTX *src)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_cleanup(EVP_PKEY_METHOD *pmeth, void (*cleanup)(EVP_PKEY_CTX *ctx)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_paramgen(EVP_PKEY_METHOD *pmeth, int (*paramgen_init)(EVP_PKEY_CTX *ctx), + int (*paramgen)(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_keygen(EVP_PKEY_METHOD *pmeth, int (*keygen_init)(EVP_PKEY_CTX *ctx), + int (*keygen)(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_sign(EVP_PKEY_METHOD *pmeth, int (*sign_init)(EVP_PKEY_CTX *ctx), + int (*sign)(EVP_PKEY_CTX *ctx, unsigned char *sig, size_t *siglen, + const unsigned char *tbs, size_t tbslen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_verify(EVP_PKEY_METHOD *pmeth, int (*verify_init)(EVP_PKEY_CTX *ctx), + int (*verify)(EVP_PKEY_CTX *ctx, const unsigned char *sig, size_t siglen, + const unsigned char *tbs, size_t tbslen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_verify_recover(EVP_PKEY_METHOD *pmeth, int (*verify_recover_init)(EVP_PKEY_CTX *ctx), + int (*verify_recover)(EVP_PKEY_CTX *ctx, unsigned char *sig, + size_t *siglen, const unsigned char *tbs, + size_t tbslen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_signctx(EVP_PKEY_METHOD *pmeth, int (*signctx_init)(EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx), + int (*signctx)(EVP_PKEY_CTX *ctx, unsigned char *sig, size_t *siglen, + EVP_MD_CTX *mctx)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_verifyctx(EVP_PKEY_METHOD *pmeth, int (*verifyctx_init)(EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx), + int (*verifyctx)(EVP_PKEY_CTX *ctx, const unsigned char *sig, int siglen, + EVP_MD_CTX *mctx)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_encrypt(EVP_PKEY_METHOD *pmeth, int (*encrypt_init)(EVP_PKEY_CTX *ctx), + int (*encryptfn)(EVP_PKEY_CTX *ctx, unsigned char *out, size_t *outlen, + const unsigned char *in, size_t inlen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_decrypt(EVP_PKEY_METHOD *pmeth, int (*decrypt_init)(EVP_PKEY_CTX *ctx), + int (*decrypt)(EVP_PKEY_CTX *ctx, unsigned char *out, size_t *outlen, + const unsigned char *in, size_t inlen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_derive(EVP_PKEY_METHOD *pmeth, int (*derive_init)(EVP_PKEY_CTX *ctx), + int (*derive)(EVP_PKEY_CTX *ctx, unsigned char *key, size_t *keylen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_ctrl(EVP_PKEY_METHOD *pmeth, int (*ctrl)(EVP_PKEY_CTX *ctx, int type, int p1, void *p2), + int (*ctrl_str)(EVP_PKEY_CTX *ctx, const char *type, const char *value)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_digestsign(EVP_PKEY_METHOD *pmeth, + int (*digestsign)(EVP_MD_CTX *ctx, unsigned char *sig, size_t *siglen, + const unsigned char *tbs, size_t tbslen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_digestverify(EVP_PKEY_METHOD *pmeth, + int (*digestverify)(EVP_MD_CTX *ctx, const unsigned char *sig, + size_t siglen, const unsigned char *tbs, + size_t tbslen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_check(EVP_PKEY_METHOD *pmeth, int (*check)(EVP_PKEY *pkey)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_public_check(EVP_PKEY_METHOD *pmeth, int (*check)(EVP_PKEY *pkey)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_param_check(EVP_PKEY_METHOD *pmeth, int (*check)(EVP_PKEY *pkey)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_set_digest_custom(EVP_PKEY_METHOD *pmeth, int (*digest_custom)(EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_init(const EVP_PKEY_METHOD *pmeth, int (**pinit)(EVP_PKEY_CTX *ctx)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_copy(const EVP_PKEY_METHOD *pmeth, int (**pcopy)(EVP_PKEY_CTX *dst, const EVP_PKEY_CTX *src)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_cleanup(const EVP_PKEY_METHOD *pmeth, void (**pcleanup)(EVP_PKEY_CTX *ctx)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_paramgen(const EVP_PKEY_METHOD *pmeth, int (**pparamgen_init)(EVP_PKEY_CTX *ctx), + int (**pparamgen)(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_keygen(const EVP_PKEY_METHOD *pmeth, int (**pkeygen_init)(EVP_PKEY_CTX *ctx), + int (**pkeygen)(EVP_PKEY_CTX *ctx, EVP_PKEY *pkey)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_sign(const EVP_PKEY_METHOD *pmeth, int (**psign_init)(EVP_PKEY_CTX *ctx), + int (**psign)(EVP_PKEY_CTX *ctx, unsigned char *sig, size_t *siglen, + const unsigned char *tbs, size_t tbslen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_verify(const EVP_PKEY_METHOD *pmeth, int (**pverify_init)(EVP_PKEY_CTX *ctx), + int (**pverify)(EVP_PKEY_CTX *ctx, const unsigned char *sig, + size_t siglen, const unsigned char *tbs, size_t tbslen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_verify_recover(const EVP_PKEY_METHOD *pmeth, + int (**pverify_recover_init)(EVP_PKEY_CTX *ctx), + int (**pverify_recover)(EVP_PKEY_CTX *ctx, unsigned char *sig, + size_t *siglen, const unsigned char *tbs, + size_t tbslen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_signctx(const EVP_PKEY_METHOD *pmeth, + int (**psignctx_init)(EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx), + int (**psignctx)(EVP_PKEY_CTX *ctx, unsigned char *sig, size_t *siglen, + EVP_MD_CTX *mctx)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_verifyctx(const EVP_PKEY_METHOD *pmeth, + int (**pverifyctx_init)(EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx), + int (**pverifyctx)(EVP_PKEY_CTX *ctx, const unsigned char *sig, + int siglen, EVP_MD_CTX *mctx)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_encrypt(const EVP_PKEY_METHOD *pmeth, int (**pencrypt_init)(EVP_PKEY_CTX *ctx), + int (**pencryptfn)(EVP_PKEY_CTX *ctx, unsigned char *out, size_t *outlen, + const unsigned char *in, size_t inlen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_decrypt(const EVP_PKEY_METHOD *pmeth, int (**pdecrypt_init)(EVP_PKEY_CTX *ctx), + int (**pdecrypt)(EVP_PKEY_CTX *ctx, unsigned char *out, size_t *outlen, + const unsigned char *in, size_t inlen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_derive(const EVP_PKEY_METHOD *pmeth, int (**pderive_init)(EVP_PKEY_CTX *ctx), + int (**pderive)(EVP_PKEY_CTX *ctx, unsigned char *key, size_t *keylen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_ctrl(const EVP_PKEY_METHOD *pmeth, + int (**pctrl)(EVP_PKEY_CTX *ctx, int type, int p1, void *p2), + int (**pctrl_str)(EVP_PKEY_CTX *ctx, const char *type, + const char *value)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_digestsign(const EVP_PKEY_METHOD *pmeth, + int (**digestsign)(EVP_MD_CTX *ctx, unsigned char *sig, size_t *siglen, + const unsigned char *tbs, size_t tbslen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_digestverify(const EVP_PKEY_METHOD *pmeth, + int (**digestverify)(EVP_MD_CTX *ctx, const unsigned char *sig, + size_t siglen, const unsigned char *tbs, + size_t tbslen)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_check(const EVP_PKEY_METHOD *pmeth, int (**pcheck)(EVP_PKEY *pkey)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_public_check(const EVP_PKEY_METHOD *pmeth, int (**pcheck)(EVP_PKEY *pkey)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_param_check(const EVP_PKEY_METHOD *pmeth, int (**pcheck)(EVP_PKEY *pkey)); +OSSL_DEPRECATEDIN_3_0 void EVP_PKEY_meth_get_digest_custom(const EVP_PKEY_METHOD *pmeth, + int (**pdigest_custom)(EVP_PKEY_CTX *ctx, EVP_MD_CTX *mctx)); +#endif void EVP_KEYEXCH_free(EVP_KEYEXCH *exchange); int EVP_KEYEXCH_up_ref(EVP_KEYEXCH *exchange); @@ -1951,19 +2285,6 @@ const char *EVP_SKEY_get0_provider_name(const EVP_SKEY *skey); EVP_SKEY *EVP_SKEY_to_provider(EVP_SKEY *skey, OSSL_LIB_CTX *libctx, OSSL_PROVIDER *prov, const char *propquery); -/* - * The seemingly redundant expression (char *)(strstr(curve, "")) serves to - * cast const char * to char *, while avoiding accidental casting of improper - * (non-string) types. - * The direct cast of the result of strstr() to char * is necessary in C++, - * where strstr can return const char *. - */ -#define EVP_EC_gen(curve) \ - EVP_PKEY_Q_keygen(NULL, NULL, "EC", \ - (curve) ? (char *)(strstr(curve, "")) : NULL) -int EVP_EC_affine2oct(const BIGNUM *x, const BIGNUM *y, size_t field_len, - unsigned char **pbuf, size_t *pbsize); - #ifdef __cplusplus } #endif diff --git a/include/openssl/evperr.h b/include/openssl/evperr.h index b3d2cb04ef..23e4a9796a 100644 --- a/include/openssl/evperr.h +++ b/include/openssl/evperr.h @@ -33,7 +33,6 @@ #define EVP_R_CIPHER_PARAMETER_ERROR 122 #define EVP_R_COMMAND_NOT_SUPPORTED 147 #define EVP_R_CONFLICTING_ALGORITHM_NAME 201 -#define EVP_R_CONTEXT_FINALIZED 239 #define EVP_R_COPY_ERROR 173 #define EVP_R_CTRL_NOT_IMPLEMENTED 132 #define EVP_R_CTRL_OPERATION_NOT_IMPLEMENTED 133 diff --git a/include/openssl/fips_names.h b/include/openssl/fips_names.h index 22ffdf5a2c..3e310bb4a8 100644 --- a/include/openssl/fips_names.h +++ b/include/openssl/fips_names.h @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -38,12 +38,6 @@ extern "C" { */ #define OSSL_PROV_FIPS_PARAM_CONDITIONAL_ERRORS "conditional-errors" -/* - * A boolean that determines if all the FIPS conditional self-test are executed - * at module startup or deferred and run only when an algorithm is invoked - */ -#define OSSL_PROV_FIPS_PARAM_DEFER_TESTS "defer-tests" - /* The following are provided for backwards compatibility */ #define OSSL_PROV_FIPS_PARAM_SECURITY_CHECKS OSSL_PROV_PARAM_SECURITY_CHECKS #define OSSL_PROV_FIPS_PARAM_TLS1_PRF_EMS_CHECK OSSL_PROV_PARAM_TLS1_PRF_EMS_CHECK diff --git a/include/openssl/httperr.h b/include/openssl/httperr.h index 4c1cc6ad6b..adac950186 100644 --- a/include/openssl/httperr.h +++ b/include/openssl/httperr.h @@ -1,6 +1,6 @@ /* * Generated by util/mkerr.pl DO NOT EDIT - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -21,7 +21,6 @@ */ #define HTTP_R_ASN1_LEN_EXCEEDS_MAX_RESP_LEN 108 #define HTTP_R_CONNECT_FAILURE 100 -#define HTTP_R_CONTENT_TYPE_MISMATCH 131 #define HTTP_R_ERROR_PARSING_ASN1_LENGTH 109 #define HTTP_R_ERROR_PARSING_CONTENT_LENGTH 119 #define HTTP_R_ERROR_PARSING_URL 101 diff --git a/include/openssl/kdf.h b/include/openssl/kdf.h index d49b22373e..f3267eae38 100644 --- a/include/openssl/kdf.h +++ b/include/openssl/kdf.h @@ -37,13 +37,7 @@ const char *EVP_KDF_get0_description(const EVP_KDF *kdf); int EVP_KDF_is_a(const EVP_KDF *kdf, const char *name); const char *EVP_KDF_get0_name(const EVP_KDF *kdf); const OSSL_PROVIDER *EVP_KDF_get0_provider(const EVP_KDF *kdf); -const EVP_KDF *EVP_KDF_CTX_get0_kdf(const EVP_KDF_CTX *ctx); -EVP_KDF *EVP_KDF_CTX_get1_kdf(const EVP_KDF_CTX *ctx); - -#if !defined(OPENSSL_NO_DEPRECATED_4_1) -OSSL_DEPRECATEDIN_4_1_FOR("Use EVP_KDF_CTX_get0_kdf") -const EVP_KDF *EVP_KDF_CTX_kdf(const EVP_KDF_CTX *ctx); -#endif /* !OPENSSL_NO_DEPRECATED_4_1 */ +const EVP_KDF *EVP_KDF_CTX_kdf(EVP_KDF_CTX *ctx); void EVP_KDF_CTX_reset(EVP_KDF_CTX *ctx); size_t EVP_KDF_CTX_get_kdf_size(EVP_KDF_CTX *ctx); @@ -73,10 +67,6 @@ int EVP_KDF_names_do_all(const EVP_KDF *kdf, #define EVP_KDF_HKDF_MODE_EXTRACT_ONLY 1 #define EVP_KDF_HKDF_MODE_EXPAND_ONLY 2 -#define EVP_KDF_IKEV2_MODE_GEN 0 -#define EVP_KDF_IKEV2_MODE_DKM 1 -#define EVP_KDF_IKEV2_MODE_REKEY 2 - #define EVP_KDF_SSHKDF_TYPE_INITIAL_IV_CLI_TO_SRV 65 #define EVP_KDF_SSHKDF_TYPE_INITIAL_IV_SRV_TO_CLI 66 #define EVP_KDF_SSHKDF_TYPE_ENCRYPTION_KEY_CLI_TO_SRV 67 diff --git a/include/openssl/macros.h b/include/openssl/macros.h index 7e820875e2..e149a27f6e 100644 --- a/include/openssl/macros.h +++ b/include/openssl/macros.h @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -11,7 +11,7 @@ #define OPENSSL_MACROS_H #pragma once -#include +#include #include /* Helper macros for CPP string composition */ @@ -49,29 +49,28 @@ #define OSSL_DEPRECATED_FOR(since, message) __declspec(deprecated) #define OSSL_DEPRECATED_MESSAGE(message) __declspec(deprecated) #endif -#define OSSL_BEGIN_ALLOW_DEPRECATED \ - __pragma(warning(push)) __pragma(warning(disable : 4996)) -#define OSSL_END_ALLOW_DEPRECATED __pragma(warning(pop)) #elif defined(__GNUC__) +/* + * According to GCC documentation, deprecations with message appeared in + * GCC 4.5.0 + */ +#if __GNUC__ > 4 || (__GNUC__ == 4 && __GNUC_MINOR__ >= 5) #define OSSL_DEPRECATED(since) \ __attribute__((deprecated("Since OpenSSL " #since))) #define OSSL_DEPRECATED_FOR(since, message) \ __attribute__((deprecated("Since OpenSSL " #since ";" message))) #define OSSL_DEPRECATED_MESSAGE(message) __attribute__((deprecated(message))) -#define OSSL_BEGIN_ALLOW_DEPRECATED \ - _Pragma("GCC diagnostic push") \ - _Pragma("GCC diagnostic ignored \"-Wdeprecated-declarations\"") -#define OSSL_END_ALLOW_DEPRECATED _Pragma("GCC diagnostic pop") +#elif __GNUC__ > 3 || (__GNUC__ == 3 && __GNUC_MINOR__ > 0) +#define OSSL_DEPRECATED(since) __attribute__((deprecated)) +#define OSSL_DEPRECATED_FOR(since, message) __attribute__((deprecated)) +#define OSSL_DEPRECATED_MESSAGE(message) __attribute__((deprecated)) +#endif #elif defined(__SUNPRO_C) #if (__SUNPRO_C >= 0x5130) #define OSSL_DEPRECATED(since) __attribute__((deprecated)) #define OSSL_DEPRECATED_FOR(since, message) __attribute__((deprecated)) #define OSSL_DEPRECATED_MESSAGE(message) __attribute__((deprecated)) #endif -#define OSSL_BEGIN_ALLOW_DEPRECATED \ - #pragma error_messages(off, E_DEPRECATED_ATT, E_DEPRECATED_ATT_MESS) -#define OSSL_END_ALLOW_DEPRECATED \ - #pragma error_messages(on, E_DEPRECATED_ATT, E_DEPRECATED_ATT_MESS) #endif #endif #endif @@ -84,8 +83,6 @@ #define OSSL_DEPRECATED(since) extern #define OSSL_DEPRECATED_FOR(since, message) extern #define OSSL_DEPRECATED_MESSAGE(message) -#define OSSL_BEGIN_ALLOW_DEPRECATED -#define OSSL_END_ALLOW_DEPRECATED #endif /* @@ -177,10 +174,8 @@ * 'no-deprecated'. */ -#undef OPENSSL_NO_DEPRECATED_4_1 #undef OPENSSL_NO_DEPRECATED_4_0 #undef OPENSSL_NO_DEPRECATED_3_6 -#undef OPENSSL_NO_DEPRECATED_3_5 #undef OPENSSL_NO_DEPRECATED_3_4 #undef OPENSSL_NO_DEPRECATED_3_1 #undef OPENSSL_NO_DEPRECATED_3_0 @@ -191,17 +186,6 @@ #undef OPENSSL_NO_DEPRECATED_1_0_0 #undef OPENSSL_NO_DEPRECATED_0_9_8 -#if OPENSSL_API_LEVEL >= 40100 -#ifndef OPENSSL_NO_DEPRECATED -#define OSSL_DEPRECATEDIN_4_1 OSSL_DEPRECATED(4.1) -#define OSSL_DEPRECATEDIN_4_1_FOR(msg) OSSL_DEPRECATED_FOR(4.1, msg) -#else -#define OPENSSL_NO_DEPRECATED_4_1 -#endif -#else -#define OSSL_DEPRECATEDIN_4_1 -#define OSSL_DEPRECATEDIN_4_1_FOR(msg) -#endif #if OPENSSL_API_LEVEL >= 40000 #ifndef OPENSSL_NO_DEPRECATED #define OSSL_DEPRECATEDIN_4_0 OSSL_DEPRECATED(4.0) @@ -366,7 +350,7 @@ #if defined(__STDC_VERSION__) #if __STDC_VERSION__ >= 199901L #define OPENSSL_FUNC __func__ -#elif defined(__GNUC__) +#elif defined(__GNUC__) && __GNUC__ >= 2 #define OPENSSL_FUNC __FUNCTION__ #endif #elif defined(_MSC_VER) diff --git a/include/openssl/md4.h b/include/openssl/md4.h index 06993aaa54..d60fe4a667 100644 --- a/include/openssl/md4.h +++ b/include/openssl/md4.h @@ -34,7 +34,7 @@ extern "C" { * ! MD4_LONG has to be at least 32 bits wide. ! * !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! */ -typedef unsigned int MD4_LONG; +#define MD4_LONG unsigned int #define MD4_CBLOCK 64 #define MD4_LBLOCK (MD4_CBLOCK / 4) diff --git a/include/openssl/md5.h b/include/openssl/md5.h index 9f65778104..0ec3d1ce95 100644 --- a/include/openssl/md5.h +++ b/include/openssl/md5.h @@ -33,7 +33,7 @@ extern "C" { * ! MD5_LONG has to be at least 32 bits wide. ! * !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! */ -typedef unsigned int MD5_LONG; +#define MD5_LONG unsigned int #define MD5_CBLOCK 64 #define MD5_LBLOCK (MD5_CBLOCK / 4) diff --git a/include/openssl/obj_mac.h b/include/openssl/obj_mac.h index fd43b9077a..236e88fdfc 100644 --- a/include/openssl/obj_mac.h +++ b/include/openssl/obj_mac.h @@ -2,7 +2,7 @@ * WARNING: do not edit! * Generated by crypto/objects/objects.pl * - * Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved. * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy * in the file LICENSE in the source distribution or at @@ -10,10 +10,9 @@ */ #ifndef OPENSSL_OBJ_MAC_H -#define OPENSSL_OBJ_MAC_H -#pragma once +# define OPENSSL_OBJ_MAC_H +# pragma once -/* clang-format off */ #define SN_undef "UNDEF" #define LN_undef "undefined" #define NID_undef 0 @@ -1067,10 +1066,6 @@ #define NID_id_alg_PWRI_KEK 893 #define OBJ_id_alg_PWRI_KEK OBJ_id_smime_alg,9L -#define SN_id_alg_hss_lms_hashsig "id-alg-hss-lms-hashsig" -#define NID_id_alg_hss_lms_hashsig 1501 -#define OBJ_id_alg_hss_lms_hashsig OBJ_id_smime_alg,17L - #define SN_HKDF_SHA256 "id-alg-hkdf-with-sha256" #define LN_HKDF_SHA256 "HKDF-SHA256" #define NID_HKDF_SHA256 1496 @@ -6650,7 +6645,6 @@ #define LN_ML_KEM_1024 "ML-KEM-1024" #define NID_ML_KEM_1024 1456 #define OBJ_ML_KEM_1024 OBJ_nistKems,3L -/* clang-format on */ #endif /* OPENSSL_OBJ_MAC_H */ diff --git a/include/openssl/ocsp.h.in b/include/openssl/ocsp.h.in index ce33a4d8fc..d2cfd9c116 100644 --- a/include/openssl/ocsp.h.in +++ b/include/openssl/ocsp.h.in @@ -1,7 +1,7 @@ /* * {- join("\n * ", @autowarntext) -} * - * Copyright 2000-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -144,13 +144,9 @@ typedef struct ocsp_service_locator_st OCSP_SERVICELOC; #define PEM_STRING_OCSP_REQUEST "OCSP REQUEST" #define PEM_STRING_OCSP_RESPONSE "OCSP RESPONSE" -#define d2i_OCSP_REQUEST_bio(bp, p) \ - ((OCSP_REQUEST *)ASN1_item_d2i_bio(ASN1_ITEM_rptr(OCSP_REQUEST), \ - (bp), CHECKED_PPTR_OF(OCSP_REQUEST, p))) +#define d2i_OCSP_REQUEST_bio(bp, p) ASN1_d2i_bio_of(OCSP_REQUEST, OCSP_REQUEST_new, d2i_OCSP_REQUEST, bp, p) -#define d2i_OCSP_RESPONSE_bio(bp, p) \ - ((OCSP_RESPONSE *)ASN1_item_d2i_bio(ASN1_ITEM_rptr(OCSP_RESPONSE), \ - (bp), CHECKED_PPTR_OF(OCSP_RESPONSE, p))) +#define d2i_OCSP_RESPONSE_bio(bp, p) ASN1_d2i_bio_of(OCSP_RESPONSE, OCSP_RESPONSE_new, d2i_OCSP_RESPONSE, bp, p) #define PEM_read_bio_OCSP_REQUEST(bp, x, cb) (OCSP_REQUEST *)PEM_ASN1_read_bio( \ (d2i_of_void *)d2i_OCSP_REQUEST, PEM_STRING_OCSP_REQUEST, \ @@ -168,13 +164,9 @@ typedef struct ocsp_service_locator_st OCSP_SERVICELOC; PEM_ASN1_write_bio((i2d_of_void *)i2d_OCSP_RESPONSE, PEM_STRING_OCSP_RESPONSE, \ bp, (char *)(o), NULL, NULL, 0, NULL, NULL) -#define i2d_OCSP_RESPONSE_bio(bp, o) \ - ASN1_item_i2d_bio(ASN1_ITEM_rptr(OCSP_RESPONSE), \ - (bp), CHECKED_PTR_OF(const OCSP_RESPONSE, o)) +#define i2d_OCSP_RESPONSE_bio(bp, o) ASN1_i2d_bio_of(OCSP_RESPONSE, i2d_OCSP_RESPONSE, bp, o) -#define i2d_OCSP_REQUEST_bio(bp, o) \ - ASN1_item_i2d_bio(ASN1_ITEM_rptr(OCSP_REQUEST), \ - (bp), CHECKED_PTR_OF(const OCSP_REQUEST, o)) +#define i2d_OCSP_REQUEST_bio(bp, o) ASN1_i2d_bio_of(OCSP_REQUEST, i2d_OCSP_REQUEST, bp, o) #define ASN1_BIT_STRING_digest(data, type, md, len) \ ASN1_item_digest(ASN1_ITEM_rptr(ASN1_BIT_STRING), type, data, md, len) @@ -232,7 +224,7 @@ int OCSP_request_sign(OCSP_REQUEST *req, X509 *signer, EVP_PKEY *key, const EVP_MD *dgst, - const STACK_OF(X509) *certs, unsigned long flags); + STACK_OF(X509) *certs, unsigned long flags); int OCSP_response_status(OCSP_RESPONSE *resp); OCSP_BASICRESP *OCSP_response_get1_basic(OCSP_RESPONSE *resp); @@ -241,7 +233,7 @@ const ASN1_OCTET_STRING *OCSP_resp_get0_signature(const OCSP_BASICRESP *bs); const X509_ALGOR *OCSP_resp_get0_tbs_sigalg(const OCSP_BASICRESP *bs); const OCSP_RESPDATA *OCSP_resp_get0_respdata(const OCSP_BASICRESP *bs); int OCSP_resp_get0_signer(OCSP_BASICRESP *bs, X509 **signer, - const STACK_OF(X509) *extra_certs); + STACK_OF(X509) *extra_certs); int OCSP_resp_count(OCSP_BASICRESP *bs); OCSP_SINGLERESP *OCSP_resp_get0(OCSP_BASICRESP *bs, int idx); @@ -267,7 +259,7 @@ int OCSP_resp_find_status(OCSP_BASICRESP *bs, OCSP_CERTID *id, int *status, int OCSP_check_validity(ASN1_GENERALIZEDTIME *thisupd, ASN1_GENERALIZEDTIME *nextupd, long sec, long maxsec); -int OCSP_request_verify(OCSP_REQUEST *req, const STACK_OF(X509) *certs, +int OCSP_request_verify(OCSP_REQUEST *req, STACK_OF(X509) *certs, X509_STORE *store, unsigned long flags); #define OCSP_parse_url(url, host, port, path, ssl) \ @@ -293,10 +285,10 @@ OCSP_SINGLERESP *OCSP_basic_add1_status(OCSP_BASICRESP *rsp, int OCSP_basic_add1_cert(OCSP_BASICRESP *resp, X509 *cert); int OCSP_basic_sign(OCSP_BASICRESP *brsp, X509 *signer, EVP_PKEY *key, const EVP_MD *dgst, - const STACK_OF(X509) *certs, unsigned long flags); + STACK_OF(X509) *certs, unsigned long flags); int OCSP_basic_sign_ctx(OCSP_BASICRESP *brsp, X509 *signer, EVP_MD_CTX *ctx, - const STACK_OF(X509) *certs, unsigned long flags); + STACK_OF(X509) *certs, unsigned long flags); int OCSP_RESPID_set_by_name(OCSP_RESPID *respid, X509 *cert); int OCSP_RESPID_set_by_key_ex(OCSP_RESPID *respid, X509 *cert, OSSL_LIB_CTX *libctx, const char *propq); @@ -318,24 +310,24 @@ int OCSP_REQUEST_get_ext_by_NID(OCSP_REQUEST *x, int nid, int lastpos); int OCSP_REQUEST_get_ext_by_OBJ(OCSP_REQUEST *x, const ASN1_OBJECT *obj, int lastpos); int OCSP_REQUEST_get_ext_by_critical(OCSP_REQUEST *x, int crit, int lastpos); -const X509_EXTENSION *OCSP_REQUEST_get_ext(OCSP_REQUEST *x, int loc); +X509_EXTENSION *OCSP_REQUEST_get_ext(OCSP_REQUEST *x, int loc); X509_EXTENSION *OCSP_REQUEST_delete_ext(OCSP_REQUEST *x, int loc); void *OCSP_REQUEST_get1_ext_d2i(OCSP_REQUEST *x, int nid, int *crit, int *idx); int OCSP_REQUEST_add1_ext_i2d(OCSP_REQUEST *x, int nid, void *value, int crit, unsigned long flags); -int OCSP_REQUEST_add_ext(OCSP_REQUEST *x, const X509_EXTENSION *ex, int loc); +int OCSP_REQUEST_add_ext(OCSP_REQUEST *x, X509_EXTENSION *ex, int loc); int OCSP_ONEREQ_get_ext_count(OCSP_ONEREQ *x); int OCSP_ONEREQ_get_ext_by_NID(OCSP_ONEREQ *x, int nid, int lastpos); int OCSP_ONEREQ_get_ext_by_OBJ(OCSP_ONEREQ *x, const ASN1_OBJECT *obj, int lastpos); int OCSP_ONEREQ_get_ext_by_critical(OCSP_ONEREQ *x, int crit, int lastpos); -const X509_EXTENSION *OCSP_ONEREQ_get_ext(OCSP_ONEREQ *x, int loc); +X509_EXTENSION *OCSP_ONEREQ_get_ext(OCSP_ONEREQ *x, int loc); X509_EXTENSION *OCSP_ONEREQ_delete_ext(OCSP_ONEREQ *x, int loc); void *OCSP_ONEREQ_get1_ext_d2i(OCSP_ONEREQ *x, int nid, int *crit, int *idx); int OCSP_ONEREQ_add1_ext_i2d(OCSP_ONEREQ *x, int nid, void *value, int crit, unsigned long flags); -int OCSP_ONEREQ_add_ext(OCSP_ONEREQ *x, const X509_EXTENSION *ex, int loc); +int OCSP_ONEREQ_add_ext(OCSP_ONEREQ *x, X509_EXTENSION *ex, int loc); int OCSP_BASICRESP_get_ext_count(OCSP_BASICRESP *x); int OCSP_BASICRESP_get_ext_by_NID(OCSP_BASICRESP *x, int nid, int lastpos); @@ -343,13 +335,13 @@ int OCSP_BASICRESP_get_ext_by_OBJ(OCSP_BASICRESP *x, const ASN1_OBJECT *obj, int lastpos); int OCSP_BASICRESP_get_ext_by_critical(OCSP_BASICRESP *x, int crit, int lastpos); -const X509_EXTENSION *OCSP_BASICRESP_get_ext(OCSP_BASICRESP *x, int loc); +X509_EXTENSION *OCSP_BASICRESP_get_ext(OCSP_BASICRESP *x, int loc); X509_EXTENSION *OCSP_BASICRESP_delete_ext(OCSP_BASICRESP *x, int loc); void *OCSP_BASICRESP_get1_ext_d2i(OCSP_BASICRESP *x, int nid, int *crit, int *idx); int OCSP_BASICRESP_add1_ext_i2d(OCSP_BASICRESP *x, int nid, void *value, int crit, unsigned long flags); -int OCSP_BASICRESP_add_ext(OCSP_BASICRESP *x, const X509_EXTENSION *ex, int loc); +int OCSP_BASICRESP_add_ext(OCSP_BASICRESP *x, X509_EXTENSION *ex, int loc); int OCSP_SINGLERESP_get_ext_count(OCSP_SINGLERESP *x); int OCSP_SINGLERESP_get_ext_by_NID(OCSP_SINGLERESP *x, int nid, int lastpos); @@ -357,13 +349,13 @@ int OCSP_SINGLERESP_get_ext_by_OBJ(OCSP_SINGLERESP *x, const ASN1_OBJECT *obj, int lastpos); int OCSP_SINGLERESP_get_ext_by_critical(OCSP_SINGLERESP *x, int crit, int lastpos); -const X509_EXTENSION *OCSP_SINGLERESP_get_ext(OCSP_SINGLERESP *x, int loc); +X509_EXTENSION *OCSP_SINGLERESP_get_ext(OCSP_SINGLERESP *x, int loc); X509_EXTENSION *OCSP_SINGLERESP_delete_ext(OCSP_SINGLERESP *x, int loc); void *OCSP_SINGLERESP_get1_ext_d2i(OCSP_SINGLERESP *x, int nid, int *crit, int *idx); int OCSP_SINGLERESP_add1_ext_i2d(OCSP_SINGLERESP *x, int nid, void *value, int crit, unsigned long flags); -int OCSP_SINGLERESP_add_ext(OCSP_SINGLERESP *x, const X509_EXTENSION *ex, int loc); +int OCSP_SINGLERESP_add_ext(OCSP_SINGLERESP *x, X509_EXTENSION *ex, int loc); const OCSP_CERTID *OCSP_SINGLERESP_get0_id(const OCSP_SINGLERESP *x); DECLARE_ASN1_FUNCTIONS(OCSP_SINGLERESP) @@ -389,7 +381,7 @@ const char *OCSP_crl_reason_str(long s); int OCSP_REQUEST_print(BIO *bp, OCSP_REQUEST *a, unsigned long flags); int OCSP_RESPONSE_print(BIO *bp, OCSP_RESPONSE *o, unsigned long flags); -int OCSP_basic_verify(OCSP_BASICRESP *bs, const STACK_OF(X509) *certs, +int OCSP_basic_verify(OCSP_BASICRESP *bs, STACK_OF(X509) *certs, X509_STORE *st, unsigned long flags); #ifdef __cplusplus diff --git a/include/openssl/ossl_typ.h b/include/openssl/ossl_typ.h index c3899c97dc..a562299b9f 100644 --- a/include/openssl/ossl_typ.h +++ b/include/openssl/ossl_typ.h @@ -13,9 +13,4 @@ * This header file only exists for compatibility reasons with older * applications which #include . */ -#if !defined(OSSL_OPENSSL_OSSL_TYP_H) -#define OSSL_OPENSSL_OSSL_TYP_H - #include - -#endif /* !defined(OSSL_OPENSSL_OSSL_TYP_H) */ diff --git a/include/openssl/pem.h b/include/openssl/pem.h index 115c8f2733..fa64aaf4ca 100644 --- a/include/openssl/pem.h +++ b/include/openssl/pem.h @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -60,7 +60,6 @@ extern "C" { #define PEM_STRING_SM2PRIVATEKEY "SM2 PRIVATE KEY" #define PEM_STRING_SM2PARAMETERS "SM2 PARAMETERS" #define PEM_STRING_ACERT "ATTRIBUTE CERTIFICATE" -#define PEM_STRING_ECHCONFIG "ECHCONFIG" #define PEM_TYPE_ENCRYPTED 10 #define PEM_TYPE_MIC_ONLY 20 @@ -117,26 +116,8 @@ extern "C" { #define IMPLEMENT_PEM_read_fp(name, type, str, asn1) \ type *PEM_read_##name(FILE *fp, type **x, pem_password_cb *cb, void *u) \ { \ - BIO *b; \ - const unsigned char *p = NULL; \ - unsigned char *data = NULL; \ - long len; \ - type *ret = NULL; \ - \ - if ((b = BIO_new(BIO_s_file())) == NULL) { \ - ERR_raise(ERR_LIB_PEM, ERR_R_BUF_LIB); \ - return NULL; \ - } \ - BIO_set_fp(b, fp, BIO_NOCLOSE); \ - if (PEM_bytes_read_bio(&data, &len, NULL, str, b, cb, u)) { \ - p = data; \ - ret = d2i_##asn1(x, &p, len); \ - if (ret == NULL) \ - ERR_raise(ERR_LIB_PEM, ERR_R_ASN1_LIB); \ - } \ - BIO_free(b); \ - OPENSSL_free(data); \ - return ret; \ + return PEM_ASN1_read((d2i_of_void *)d2i_##asn1, str, fp, \ + (void **)x, cb, u); \ } #define IMPLEMENT_PEM_write_fp(name, type, str, asn1) \ @@ -164,24 +145,12 @@ extern "C" { #endif #endif -#define IMPLEMENT_PEM_read_bio(name, type, str, asn1) \ - type *PEM_read_bio_##name(BIO *bp, type **x, \ - pem_password_cb *cb, void *u) \ - { \ - const unsigned char *p = NULL; \ - unsigned char *data = NULL; \ - long len; \ - type *ret = NULL; \ - \ - if (!PEM_bytes_read_bio(&data, &len, NULL, str, \ - bp, cb, u)) \ - return NULL; \ - p = data; \ - ret = d2i_##asn1(x, &p, len); \ - if (ret == NULL) \ - ERR_raise(ERR_LIB_PEM, ERR_R_ASN1_LIB); \ - OPENSSL_free(data); \ - return ret; \ +#define IMPLEMENT_PEM_read_bio(name, type, str, asn1) \ + type *PEM_read_bio_##name(BIO *bp, type **x, \ + pem_password_cb *cb, void *u) \ + { \ + return PEM_ASN1_read_bio((d2i_of_void *)d2i_##asn1, str, bp, \ + (void **)x, cb, u); \ } #define IMPLEMENT_PEM_write_bio(name, type, str, asn1) \ diff --git a/include/openssl/pkcs12.h.in b/include/openssl/pkcs12.h.in index 6555322be3..f810bde759 100644 --- a/include/openssl/pkcs12.h.in +++ b/include/openssl/pkcs12.h.in @@ -1,7 +1,7 @@ /* * {- join("\n * ", @autowarntext) -} * - * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -101,11 +101,11 @@ typedef struct pkcs12_bag_st PKCS12_BAGS; #endif #ifndef OPENSSL_NO_DEPRECATED_1_1_0 -OSSL_DEPRECATEDIN_1_1_0 const ASN1_TYPE *PKCS12_get_attr(const PKCS12_SAFEBAG *bag, +OSSL_DEPRECATEDIN_1_1_0 ASN1_TYPE *PKCS12_get_attr(const PKCS12_SAFEBAG *bag, int attr_nid); #endif -const ASN1_TYPE *PKCS8_get_attr(PKCS8_PRIV_KEY_INFO *p8, int attr_nid); +ASN1_TYPE *PKCS8_get_attr(PKCS8_PRIV_KEY_INFO *p8, int attr_nid); int PKCS12_mac_present(const PKCS12 *p12); void PKCS12_get0_mac(const ASN1_OCTET_STRING **pmac, const X509_ALGOR **pmacalg, @@ -191,7 +191,7 @@ STACK_OF(PKCS12_SAFEBAG) *PKCS12_unpack_p7encdata(PKCS7 *p7, const char *pass, int PKCS12_pack_authsafes(PKCS12 *p12, STACK_OF(PKCS7) *safes); STACK_OF(PKCS7) *PKCS12_unpack_authsafes(const PKCS12 *p12); -int PKCS12_add_localkeyid(PKCS12_SAFEBAG *bag, const unsigned char *name, +int PKCS12_add_localkeyid(PKCS12_SAFEBAG *bag, unsigned char *name, int namelen); int PKCS12_add_friendlyname_asc(PKCS12_SAFEBAG *bag, const char *name, int namelen); @@ -206,7 +206,7 @@ int PKCS12_add1_attr_by_NID(PKCS12_SAFEBAG *bag, int nid, int type, int PKCS12_add1_attr_by_txt(PKCS12_SAFEBAG *bag, const char *attrname, int type, const unsigned char *bytes, int len); int PKCS8_add_keyusage(PKCS8_PRIV_KEY_INFO *p8, int usage); -const ASN1_TYPE *PKCS12_get_attr_gen(const STACK_OF(X509_ATTRIBUTE) *attrs, +ASN1_TYPE *PKCS12_get_attr_gen(const STACK_OF(X509_ATTRIBUTE) *attrs, int attr_nid); char *PKCS12_get_friendlyname(PKCS12_SAFEBAG *bag); const STACK_OF(X509_ATTRIBUTE) * diff --git a/include/openssl/pkcs7.h.in b/include/openssl/pkcs7.h.in index e922bf6d4a..1d57255ae7 100644 --- a/include/openssl/pkcs7.h.in +++ b/include/openssl/pkcs7.h.in @@ -1,7 +1,7 @@ /* * {- join("\n * ", @autowarntext) -} * - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -284,7 +284,7 @@ int PKCS7_content_new(PKCS7 *p7, int nid); int PKCS7_dataVerify(X509_STORE *cert_store, X509_STORE_CTX *ctx, BIO *bio, PKCS7 *p7, PKCS7_SIGNER_INFO *si); int PKCS7_signatureVerify(BIO *bio, PKCS7 *p7, PKCS7_SIGNER_INFO *si, - const X509 *signer); + X509 *signer); BIO *PKCS7_dataInit(PKCS7 *p7, BIO *bio); int PKCS7_dataFinal(PKCS7 *p7, BIO *bio); @@ -307,33 +307,36 @@ int PKCS7_stream(unsigned char ***boundary, PKCS7 *p7); PKCS7_ISSUER_AND_SERIAL *PKCS7_get_issuer_and_serial(PKCS7 *p7, int idx); ASN1_OCTET_STRING *PKCS7_get_octet_string(PKCS7 *p7); -const ASN1_OCTET_STRING *PKCS7_digest_from_attributes(STACK_OF(X509_ATTRIBUTE) *sk); +ASN1_OCTET_STRING *PKCS7_digest_from_attributes(STACK_OF(X509_ATTRIBUTE) *sk); int PKCS7_add_signed_attribute(PKCS7_SIGNER_INFO *p7si, int nid, int type, void *data); int PKCS7_add_attribute(PKCS7_SIGNER_INFO *p7si, int nid, int atrtype, void *value); -const ASN1_TYPE *PKCS7_get_attribute(const PKCS7_SIGNER_INFO *si, int nid); -const ASN1_TYPE *PKCS7_get_signed_attribute(const PKCS7_SIGNER_INFO *si, int nid); +ASN1_TYPE *PKCS7_get_attribute(const PKCS7_SIGNER_INFO *si, int nid); +ASN1_TYPE *PKCS7_get_signed_attribute(const PKCS7_SIGNER_INFO *si, int nid); int PKCS7_set_signed_attributes(PKCS7_SIGNER_INFO *p7si, STACK_OF(X509_ATTRIBUTE) *sk); int PKCS7_set_attributes(PKCS7_SIGNER_INFO *p7si, STACK_OF(X509_ATTRIBUTE) *sk); -PKCS7 *PKCS7_sign(X509 *signcert, EVP_PKEY *pkey, const STACK_OF(X509) *certs, +PKCS7 *PKCS7_sign(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs, BIO *data, int flags); -PKCS7 *PKCS7_sign_ex(X509 *signcert, EVP_PKEY *pkey, const STACK_OF(X509) *certs, - BIO *data, int flags, OSSL_LIB_CTX *libctx, const char *propq); +PKCS7 *PKCS7_sign_ex(X509 *signcert, EVP_PKEY *pkey, STACK_OF(X509) *certs, + BIO *data, int flags, OSSL_LIB_CTX *libctx, + const char *propq); PKCS7_SIGNER_INFO *PKCS7_sign_add_signer(PKCS7 *p7, X509 *signcert, EVP_PKEY *pkey, const EVP_MD *md, int flags); int PKCS7_final(PKCS7 *p7, BIO *data, int flags); -int PKCS7_verify(PKCS7 *p7, const STACK_OF(X509) *certs, X509_STORE *store, +int PKCS7_verify(PKCS7 *p7, STACK_OF(X509) *certs, X509_STORE *store, BIO *indata, BIO *out, int flags); -STACK_OF(X509) *PKCS7_get0_signers(PKCS7 *p7, const STACK_OF(X509) *certs, int flags); -PKCS7 *PKCS7_encrypt(const STACK_OF(X509) *certs, BIO *in, const EVP_CIPHER *cipher, int flags); -PKCS7 *PKCS7_encrypt_ex(const STACK_OF(X509) *certs, BIO *in, +STACK_OF(X509) *PKCS7_get0_signers(PKCS7 *p7, STACK_OF(X509) *certs, + int flags); +PKCS7 *PKCS7_encrypt(STACK_OF(X509) *certs, BIO *in, const EVP_CIPHER *cipher, + int flags); +PKCS7 *PKCS7_encrypt_ex(STACK_OF(X509) *certs, BIO *in, const EVP_CIPHER *cipher, int flags, OSSL_LIB_CTX *libctx, const char *propq); int PKCS7_decrypt(PKCS7 *p7, EVP_PKEY *pkey, X509 *cert, BIO *data, diff --git a/include/openssl/proverr.h b/include/openssl/proverr.h index 0db3a82b47..fdfa8916a2 100644 --- a/include/openssl/proverr.h +++ b/include/openssl/proverr.h @@ -1,6 +1,6 @@ /* * Generated by util/mkerr.pl DO NOT EDIT - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -56,7 +56,6 @@ #define PROV_R_INSUFFICIENT_DRBG_STRENGTH 181 #define PROV_R_INVALID_AAD 108 #define PROV_R_INVALID_AEAD 231 -#define PROV_R_INVALID_CIPHER 260 #define PROV_R_INVALID_CONFIG_DATA 211 #define PROV_R_INVALID_CONSTANT_LENGTH 157 #define PROV_R_INVALID_CURVE 176 @@ -66,28 +65,21 @@ #define PROV_R_INVALID_DIGEST_LENGTH 166 #define PROV_R_INVALID_DIGEST_SIZE 218 #define PROV_R_INVALID_EDDSA_INSTANCE_FOR_ATTEMPTED_OPERATION 243 -#define PROV_R_INVALID_FUNCTION_NAME 258 -#define PROV_R_INVALID_INDEX_LENGTH 259 #define PROV_R_INVALID_INPUT_LENGTH 230 #define PROV_R_INVALID_ITERATION_COUNT 123 #define PROV_R_INVALID_IV_LENGTH 109 #define PROV_R_INVALID_KDF 232 -#define PROV_R_INVALID_KDR 256 #define PROV_R_INVALID_KEY 158 #define PROV_R_INVALID_KEY_LENGTH 105 -#define PROV_R_INVALID_LABEL 257 #define PROV_R_INVALID_MAC 151 #define PROV_R_INVALID_MEMORY_SIZE 235 #define PROV_R_INVALID_MGF1_MD 167 #define PROV_R_INVALID_MODE 125 -#define PROV_R_INVALID_NONCE_LENGTH 264 #define PROV_R_INVALID_OUTPUT_LENGTH 217 #define PROV_R_INVALID_PADDING_MODE 168 -#define PROV_R_INVALID_PARAMETERS_FOR_DKM 261 #define PROV_R_INVALID_PREHASHED_DIGEST_LENGTH 241 #define PROV_R_INVALID_PUBINFO 198 #define PROV_R_INVALID_SALT_LENGTH 112 -#define PROV_R_INVALID_SECRET_LENGTH 265 #define PROV_R_INVALID_SEED_LENGTH 154 #define PROV_R_INVALID_SIGNATURE_SIZE 179 #define PROV_R_INVALID_STATE 212 @@ -97,7 +89,6 @@ #define PROV_R_INVALID_UKM_LENGTH 200 #define PROV_R_INVALID_X931_DIGEST 170 #define PROV_R_IN_ERROR_STATE 192 -#define PROV_R_KEY_IMMUTABLE_ONCE_SET 266 #define PROV_R_KEY_SETUP_FAILED 101 #define PROV_R_KEY_SIZE_TOO_SMALL 171 #define PROV_R_LENGTH_TOO_LARGE 202 @@ -106,12 +97,10 @@ #define PROV_R_MISSING_CIPHER 155 #define PROV_R_MISSING_CONFIG_DATA 213 #define PROV_R_MISSING_CONSTANT 156 -#define PROV_R_MISSING_DKM 262 #define PROV_R_MISSING_EID 255 #define PROV_R_MISSING_KEY 128 #define PROV_R_MISSING_MAC 150 #define PROV_R_MISSING_MESSAGE_DIGEST 129 -#define PROV_R_MISSING_NONCE 263 #define PROV_R_MISSING_OID 209 #define PROV_R_MISSING_PASS 130 #define PROV_R_MISSING_SALT 131 diff --git a/include/openssl/rc5.h b/include/openssl/rc5.h index e13cf9c8d4..2e91e98540 100644 --- a/include/openssl/rc5.h +++ b/include/openssl/rc5.h @@ -30,7 +30,7 @@ extern "C" { #define RC5_ENCRYPT 1 #define RC5_DECRYPT 0 -typedef unsigned int RC5_32_INT; +#define RC5_32_INT unsigned int /* * This are the only values supported. Tweak the code if you want more The diff --git a/include/openssl/ripemd.h b/include/openssl/ripemd.h index e0bab4d374..a72d1dad0a 100644 --- a/include/openssl/ripemd.h +++ b/include/openssl/ripemd.h @@ -29,7 +29,7 @@ extern "C" { #endif #if !defined(OPENSSL_NO_DEPRECATED_3_0) -typedef unsigned int RIPEMD160_LONG; +#define RIPEMD160_LONG unsigned int #define RIPEMD160_CBLOCK 64 #define RIPEMD160_LBLOCK (RIPEMD160_CBLOCK / 4) diff --git a/include/openssl/rsa.h b/include/openssl/rsa.h index d9ae71b383..ef1e7d06c8 100644 --- a/include/openssl/rsa.h +++ b/include/openssl/rsa.h @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2021 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -333,13 +333,13 @@ struct rsa_pss_params_st { DECLARE_ASN1_FUNCTIONS(RSA_PSS_PARAMS) DECLARE_ASN1_DUP_FUNCTION(RSA_PSS_PARAMS) -struct rsa_oaep_params_st { +typedef struct rsa_oaep_params_st { X509_ALGOR *hashFunc; X509_ALGOR *maskGenFunc; X509_ALGOR *pSourceFunc; /* Decoded hash algorithm from maskGenFunc */ X509_ALGOR *maskHash; -}; +} RSA_OAEP_PARAMS; DECLARE_ASN1_FUNCTIONS(RSA_OAEP_PARAMS) diff --git a/include/openssl/rsaerr.h b/include/openssl/rsaerr.h index 781e333132..8432f5f655 100644 --- a/include/openssl/rsaerr.h +++ b/include/openssl/rsaerr.h @@ -88,6 +88,7 @@ #define RSA_R_RSA_OPERATIONS_NOT_SUPPORTED 130 #define RSA_R_SLEN_CHECK_FAILED 136 #define RSA_R_SLEN_RECOVERY_FAILED 135 +#define RSA_R_SSLV3_ROLLBACK_ATTACK 115 #define RSA_R_THE_ASN1_OBJECT_IDENTIFIER_IS_NOT_KNOWN_FOR_THIS_MD 116 #define RSA_R_UNKNOWN_ALGORITHM_TYPE 117 #define RSA_R_UNKNOWN_DIGEST 166 diff --git a/include/openssl/safestack.h.in b/include/openssl/safestack.h.in index 64ac28be04..5d556e2061 100644 --- a/include/openssl/safestack.h.in +++ b/include/openssl/safestack.h.in @@ -1,7 +1,7 @@ /* * {- join("\n * ", @autowarntext) -} * - * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -36,52 +36,39 @@ extern "C" { #define STACK_OF(type) struct stack_st_##type /* Helper macro for internal use */ -#define SKM_DEFINE_STACK_OF_INTERNAL(t1, t2, t3) \ - STACK_OF(t1); \ - typedef int (*sk_##t1##_compfunc)(const t3 *const *a, const t3 *const *b); \ - typedef void (*sk_##t1##_freefunc)(t3 * a); \ - typedef t3 *(*sk_##t1##_copyfunc)(const t3 *a); \ - static ossl_inline void sk_##t1##_freefunc_thunk(OPENSSL_sk_freefunc freefunc_arg, void *ptr) \ - { \ - sk_##t1##_freefunc freefunc = (sk_##t1##_freefunc)freefunc_arg; \ - freefunc((t3 *)ptr); \ - } \ - static ossl_inline void *sk_##t1##_copyfunc_thunk(OPENSSL_sk_copyfunc copyfunc_arg, const void *ptr) \ - { \ - sk_##t1##_copyfunc copyfunc = (sk_##t1##_copyfunc)copyfunc_arg; \ - return (void *)copyfunc((const t3 *)ptr); \ - } \ - static ossl_inline int sk_##t1##_cmpfunc_thunk(int (*cmp)(const void *, const void *), const void *a, const void *b) \ - { \ - int (*realcmp)(const t3 *const *a, const t3 *const *b) = (int (*)(const t3 *const *a, const t3 *const *b))(cmp); \ - const t3 *const *at = (const t3 *const *)a; \ - const t3 *const *bt = (const t3 *const *)b; \ - \ - return realcmp(at, bt); \ - } \ - static ossl_unused ossl_inline t2 *ossl_check_##t1##_type(t2 *ptr) \ - { \ - return ptr; \ - } \ - static ossl_unused ossl_inline const OPENSSL_STACK *ossl_check_const_##t1##_sk_type(const STACK_OF(t1) *sk) \ - { \ - return (const OPENSSL_STACK *)sk; \ - } \ - static ossl_unused ossl_inline OPENSSL_STACK *ossl_check_##t1##_sk_type(STACK_OF(t1) *sk) \ - { \ - return (OPENSSL_STACK *)sk; \ - } \ - static ossl_unused ossl_inline OPENSSL_sk_compfunc ossl_check_##t1##_compfunc_type(sk_##t1##_compfunc cmp) \ - { \ - return (OPENSSL_sk_compfunc)cmp; \ - } \ - static ossl_unused ossl_inline OPENSSL_sk_copyfunc ossl_check_##t1##_copyfunc_type(sk_##t1##_copyfunc cpy) \ - { \ - return (OPENSSL_sk_copyfunc)cpy; \ - } \ - static ossl_unused ossl_inline OPENSSL_sk_freefunc ossl_check_##t1##_freefunc_type(sk_##t1##_freefunc fr) \ - { \ - return (OPENSSL_sk_freefunc)fr; \ +#define SKM_DEFINE_STACK_OF_INTERNAL(t1, t2, t3) \ + STACK_OF(t1); \ + typedef int (*sk_##t1##_compfunc)(const t3 *const *a, const t3 *const *b); \ + typedef void (*sk_##t1##_freefunc)(t3 * a); \ + typedef t3 *(*sk_##t1##_copyfunc)(const t3 *a); \ + static ossl_inline void sk_##t1##_freefunc_thunk(OPENSSL_sk_freefunc freefunc_arg, void *ptr) \ + { \ + sk_##t1##_freefunc freefunc = (sk_##t1##_freefunc)freefunc_arg; \ + freefunc((t3 *)ptr); \ + } \ + static ossl_unused ossl_inline t2 *ossl_check_##t1##_type(t2 *ptr) \ + { \ + return ptr; \ + } \ + static ossl_unused ossl_inline const OPENSSL_STACK *ossl_check_const_##t1##_sk_type(const STACK_OF(t1) *sk) \ + { \ + return (const OPENSSL_STACK *)sk; \ + } \ + static ossl_unused ossl_inline OPENSSL_STACK *ossl_check_##t1##_sk_type(STACK_OF(t1) *sk) \ + { \ + return (OPENSSL_STACK *)sk; \ + } \ + static ossl_unused ossl_inline OPENSSL_sk_compfunc ossl_check_##t1##_compfunc_type(sk_##t1##_compfunc cmp) \ + { \ + return (OPENSSL_sk_compfunc)cmp; \ + } \ + static ossl_unused ossl_inline OPENSSL_sk_copyfunc ossl_check_##t1##_copyfunc_type(sk_##t1##_copyfunc cpy) \ + { \ + return (OPENSSL_sk_copyfunc)cpy; \ + } \ + static ossl_unused ossl_inline OPENSSL_sk_freefunc ossl_check_##t1##_freefunc_type(sk_##t1##_freefunc fr) \ + { \ + return (OPENSSL_sk_freefunc)fr; \ } #define SKM_DEFINE_STACK_OF(t1, t2, t3) \ @@ -94,19 +81,6 @@ extern "C" { sk_##t1##_freefunc freefunc = (sk_##t1##_freefunc)freefunc_arg; \ freefunc((t3 *)ptr); \ } \ - static ossl_inline void *sk_##t1##_copyfunc_thunk(OPENSSL_sk_copyfunc copyfunc_arg, const void *ptr) \ - { \ - sk_##t1##_copyfunc copyfunc = (sk_##t1##_copyfunc)copyfunc_arg; \ - return (void *)copyfunc((const t3 *)ptr); \ - } \ - static ossl_inline int sk_##t1##_cmpfunc_thunk(int (*cmp)(const void *, const void *), const void *a, const void *b) \ - { \ - int (*realcmp)(const t3 *const *a, const t3 *const *b) = (int (*)(const t3 *const *a, const t3 *const *b))(cmp); \ - const t3 *const *at = (const t3 *const *)a; \ - const t3 *const *bt = (const t3 *const *)b; \ - \ - return realcmp(at, bt); \ - } \ static ossl_unused ossl_inline int sk_##t1##_num(const STACK_OF(t1) *sk) \ { \ return OPENSSL_sk_num((const OPENSSL_STACK *)sk); \ @@ -121,19 +95,11 @@ extern "C" { OPENSSL_sk_freefunc_thunk f_thunk; \ \ f_thunk = (OPENSSL_sk_freefunc_thunk)sk_##t1##_freefunc_thunk; \ - OPENSSL_sk_set_cmp_thunks(ret, sk_##t1##_cmpfunc_thunk); \ - OPENSSL_sk_set_copy_thunks(ret, sk_##t1##_copyfunc_thunk); \ return (STACK_OF(t1) *)OPENSSL_sk_set_thunks(ret, f_thunk); \ } \ static ossl_unused ossl_inline STACK_OF(t1) *sk_##t1##_new_null(void) \ { \ - OPENSSL_STACK *ret = OPENSSL_sk_new_null(); \ - OPENSSL_sk_freefunc_thunk f_thunk; \ - \ - f_thunk = (OPENSSL_sk_freefunc_thunk)sk_##t1##_freefunc_thunk; \ - OPENSSL_sk_set_cmp_thunks(ret, sk_##t1##_cmpfunc_thunk); \ - OPENSSL_sk_set_copy_thunks(ret, sk_##t1##_copyfunc_thunk); \ - return (STACK_OF(t1) *)OPENSSL_sk_set_thunks(ret, f_thunk); \ + return (STACK_OF(t1) *)OPENSSL_sk_new_null(); \ } \ static ossl_unused ossl_inline STACK_OF(t1) *sk_##t1##_new_reserve(sk_##t1##_compfunc compare, int n) \ { \ @@ -141,8 +107,6 @@ extern "C" { OPENSSL_sk_freefunc_thunk f_thunk; \ \ f_thunk = (OPENSSL_sk_freefunc_thunk)sk_##t1##_freefunc_thunk; \ - OPENSSL_sk_set_cmp_thunks(ret, sk_##t1##_cmpfunc_thunk); \ - OPENSSL_sk_set_copy_thunks(ret, sk_##t1##_copyfunc_thunk); \ return (STACK_OF(t1) *)OPENSSL_sk_set_thunks(ret, f_thunk); \ } \ static ossl_unused ossl_inline int sk_##t1##_reserve(STACK_OF(t1) *sk, int n) \ @@ -222,27 +186,15 @@ extern "C" { } \ static ossl_unused ossl_inline STACK_OF(t1) *sk_##t1##_dup(const STACK_OF(t1) *sk) \ { \ - OPENSSL_STACK *ret = OPENSSL_sk_dup((const OPENSSL_STACK *)sk); \ - OPENSSL_sk_freefunc_thunk f_thunk; \ - \ - f_thunk = (OPENSSL_sk_freefunc_thunk)sk_##t1##_freefunc_thunk; \ - OPENSSL_sk_set_cmp_thunks(ret, sk_##t1##_cmpfunc_thunk); \ - OPENSSL_sk_set_copy_thunks(ret, sk_##t1##_copyfunc_thunk); \ - return (STACK_OF(t1) *)OPENSSL_sk_set_thunks(ret, f_thunk); \ + return (STACK_OF(t1) *)OPENSSL_sk_dup((const OPENSSL_STACK *)sk); \ } \ static ossl_unused ossl_inline STACK_OF(t1) *sk_##t1##_deep_copy(const STACK_OF(t1) *sk, \ sk_##t1##_copyfunc copyfunc, \ sk_##t1##_freefunc freefunc) \ { \ - OPENSSL_STACK *ret = OPENSSL_sk_deep_copy((const OPENSSL_STACK *)sk, \ + return (STACK_OF(t1) *)OPENSSL_sk_deep_copy((const OPENSSL_STACK *)sk, \ (OPENSSL_sk_copyfunc)copyfunc, \ (OPENSSL_sk_freefunc)freefunc); \ - OPENSSL_sk_freefunc_thunk f_thunk; \ - \ - f_thunk = (OPENSSL_sk_freefunc_thunk)sk_##t1##_freefunc_thunk; \ - OPENSSL_sk_set_cmp_thunks(ret, sk_##t1##_cmpfunc_thunk); \ - OPENSSL_sk_set_copy_thunks(ret, sk_##t1##_copyfunc_thunk); \ - return (STACK_OF(t1) *)OPENSSL_sk_set_thunks(ret, f_thunk); \ } \ static ossl_unused ossl_inline sk_##t1##_compfunc sk_##t1##_set_cmp_func(STACK_OF(t1) *sk, sk_##t1##_compfunc compare) \ { \ diff --git a/include/openssl/self_test.h b/include/openssl/self_test.h index 02c8f9ba1d..8dab9b6f99 100644 --- a/include/openssl/self_test.h +++ b/include/openssl/self_test.h @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -38,7 +38,6 @@ extern "C" { #define OSSL_SELF_TEST_TYPE_KAT_ASYM_KEYGEN "KAT_AsymmetricKeyGeneration" #define OSSL_SELF_TEST_TYPE_KAT_KEM "KAT_KEM" #define OSSL_SELF_TEST_TYPE_KAT_DIGEST "KAT_Digest" -#define OSSL_SELF_TEST_TYPE_KAT_MAC "KAT_Mac" #define OSSL_SELF_TEST_TYPE_KAT_SIGNATURE "KAT_Signature" #define OSSL_SELF_TEST_TYPE_PCT_SIGNATURE "PCT_Signature" #define OSSL_SELF_TEST_TYPE_KAT_KDF "KAT_KDF" @@ -80,17 +79,11 @@ extern "C" { #define OSSL_SELF_TEST_DESC_KA_DH "DH" #define OSSL_SELF_TEST_DESC_KA_ECDH "ECDH" #define OSSL_SELF_TEST_DESC_KDF_HKDF "HKDF" -#define OSSL_SELF_TEST_DESC_KDF_IKEV2KDF_GEN "IKEV2KDF_GEN" -#define OSSL_SELF_TEST_DESC_KDF_IKEV2KDF_DKM1 "IKEV2KDF_DKM" -#define OSSL_SELF_TEST_DESC_KDF_IKEV2KDF_DKM2 "IKEV2KDF_DKM(Child_SA)" -#define OSSL_SELF_TEST_DESC_KDF_IKEV2KDF_DKM3 "IKEV2KDF_DKM(Child_DH)" -#define OSSL_SELF_TEST_DESC_KDF_IKEV2KDF_REKEY "IKEV2KDF_REKEY" #define OSSL_SELF_TEST_DESC_KDF_SSKDF "SSKDF" #define OSSL_SELF_TEST_DESC_KDF_X963KDF "X963KDF" #define OSSL_SELF_TEST_DESC_KDF_X942KDF "X942KDF" #define OSSL_SELF_TEST_DESC_KDF_PBKDF2 "PBKDF2" #define OSSL_SELF_TEST_DESC_KDF_SNMPKDF "SNMPKDF" -#define OSSL_SELF_TEST_DESC_KDF_SRTPKDF "SRTPKDF" #define OSSL_SELF_TEST_DESC_KDF_SSHKDF "SSHKDF" #define OSSL_SELF_TEST_DESC_KDF_TLS12_PRF "TLS12_PRF" #define OSSL_SELF_TEST_DESC_KDF_KBKDF "KBKDF" diff --git a/include/openssl/sha.h b/include/openssl/sha.h index fec107d13f..52b02661f6 100644 --- a/include/openssl/sha.h +++ b/include/openssl/sha.h @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -31,7 +31,7 @@ extern "C" { * ! SHA_LONG has to be at least 32 bits wide. ! * !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! */ -typedef unsigned int SHA_LONG; +#define SHA_LONG unsigned int #define SHA_LBLOCK 16 #define SHA_CBLOCK (SHA_LBLOCK * 4) /* SHA treats input data as a \ @@ -60,11 +60,10 @@ unsigned char *SHA1(const unsigned char *d, size_t n, unsigned char *md); * big-endian values. */ typedef struct SHA256state_st { - SHA_LONG h[8]; /* Hash values (32 bytes) */ - SHA_LONG Nl, Nh; /* The length of the message in bits is stored into 64 bits */ - SHA_LONG data[SHA_LBLOCK]; /* Buffer used to store input less than 512 bits */ - unsigned int num; /* The size of the partial buffered input in data[] */ - unsigned int md_len; /* The output size (used for truncation) */ + SHA_LONG h[8]; + SHA_LONG Nl, Nh; + SHA_LONG data[SHA_LBLOCK]; + unsigned int num, md_len; } SHA256_CTX; OSSL_DEPRECATEDIN_3_0 int SHA224_Init(SHA256_CTX *c); @@ -101,11 +100,11 @@ unsigned char *SHA256(const unsigned char *d, size_t n, unsigned char *md); */ #define SHA512_CBLOCK (SHA_LBLOCK * 8) #if (defined(_WIN32) || defined(_WIN64)) && !defined(__MINGW32__) -typedef unsigned __int64 SHA_LONG64; +#define SHA_LONG64 unsigned __int64 #elif defined(__arch64__) -typedef unsigned long SHA_LONG64; +#define SHA_LONG64 unsigned long #else -typedef unsigned long long SHA_LONG64; +#define SHA_LONG64 unsigned long long #endif typedef struct SHA512state_st { diff --git a/include/openssl/ssl.h.in b/include/openssl/ssl.h.in index b010a6e677..6b7d8c0d16 100644 --- a/include/openssl/ssl.h.in +++ b/include/openssl/ssl.h.in @@ -1,7 +1,7 @@ /* * {- join("\n * ", @autowarntext) -} * - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * Copyright 2005 Nokia. All rights reserved. * @@ -46,9 +46,6 @@ use OpenSSL::stackhash qw(generate_stack_macros generate_const_stack_macros); #include #include #include -#ifndef OPENSSL_NO_ECH -#include -#endif #ifndef OPENSSL_NO_STDIO #include #endif @@ -81,6 +78,7 @@ extern "C" { #define SSL_TXT_LOW "LOW" #define SSL_TXT_MEDIUM "MEDIUM" #define SSL_TXT_HIGH "HIGH" +#define SSL_TXT_FIPS "FIPS" #define SSL_TXT_aNULL "aNULL" #define SSL_TXT_eNULL "eNULL" @@ -165,6 +163,7 @@ extern "C" { #define SSL_TXT_SHA256 "SHA256" #define SSL_TXT_SHA384 "SHA384" +#define SSL_TXT_SSLV3 "SSLv3" #define SSL_TXT_TLSV1 "TLSv1" #define SSL_TXT_TLSV1_1 "TLSv1.1" #define SSL_TXT_TLSV1_2 "TLSv1.2" @@ -346,7 +345,7 @@ typedef int (*SSL_async_callback_fn)(SSL *s, void *arg); /* In TLSv1.3 allow a non-(ec)dhe based kex_mode */ #define SSL_OP_ALLOW_NO_DHE_KEX SSL_OP_BIT(10) /* - * Disable TLS 1.0 CBC vulnerability workaround that was added + * Disable SSL 3.0/TLS 1.0 CBC vulnerability workaround that was added * in OpenSSL 0.9.6d. Usually (depending on the application protocol) * the workaround is not needed. Unfortunately some broken SSL/TLS * implementations cannot handle it at all, which is why we include it @@ -432,30 +431,6 @@ typedef int (*SSL_async_callback_fn)(SSL *s, void *arg); #define SSL_OP_PREFER_NO_DHE_KEX SSL_OP_BIT(35) #define SSL_OP_LEGACY_EC_POINT_FORMATS SSL_OP_BIT(36) -#ifndef OPENSSL_NO_ECH -/* Set this to tell client to emit greased ECH values */ -#define SSL_OP_ECH_GREASE SSL_OP_BIT(37) -/* - * If this is set then the server side will attempt trial decryption - * of ECHs even if there is no matching ECH config_id. That's a bit - * inefficient, but more privacy friendly. - */ -#define SSL_OP_ECH_TRIALDECRYPT SSL_OP_BIT(38) -/* - * If set, clients will ignore the supplied ECH config_id and replace - * that with a random value. - */ -#define SSL_OP_ECH_IGNORE_CID SSL_OP_BIT(39) -/* - * If set, servers will add GREASEy ECHConfig values to those sent - * in retry_configs. - */ -#define SSL_OP_ECH_GREASE_RETRY_CONFIG SSL_OP_BIT(40) -#endif - -/* RFC 8701: Send GREASE values in ClientHello */ -#define SSL_OP_GREASE SSL_OP_BIT(41) - /* * Option "collections." */ @@ -851,10 +826,6 @@ void SSL_CTX_set_alpn_select_cb(SSL_CTX *ctx, void *arg); void SSL_get0_alpn_selected(const SSL *ssl, const unsigned char **data, unsigned int *len); -void SSL_CTX_get0_alpn_protos(SSL_CTX *ctx, const unsigned char **protos, - unsigned int *protos_len); -void SSL_get0_alpn_protos(SSL *ssl, const unsigned char **protos, - unsigned int *protos_len); #ifndef OPENSSL_NO_PSK /* @@ -1224,9 +1195,6 @@ DECLARE_PEM_rw(SSL_SESSION, SSL_SESSION) #define SSL_AD_NO_RENEGOTIATION TLS1_AD_NO_RENEGOTIATION #define SSL_AD_MISSING_EXTENSION TLS13_AD_MISSING_EXTENSION #define SSL_AD_CERTIFICATE_REQUIRED TLS13_AD_CERTIFICATE_REQUIRED -#ifndef OPENSSL_NO_ECH -#define SSL_AD_ECH_REQUIRED TLS1_AD_ECH_REQUIRED -#endif #define SSL_AD_UNSUPPORTED_EXTENSION TLS1_AD_UNSUPPORTED_EXTENSION #define SSL_AD_CERTIFICATE_UNOBTAINABLE TLS1_AD_CERTIFICATE_UNOBTAINABLE #define SSL_AD_UNRECOGNIZED_NAME TLS1_AD_UNRECOGNIZED_NAME @@ -1864,7 +1832,6 @@ int SSL_is_dtls(const SSL *s); int SSL_is_tls(const SSL *s); int SSL_is_quic(const SSL *s); int SSL_CTX_is_quic(const SSL_CTX *c); -int SSL_CTX_is_server(const SSL_CTX *c); __owur int SSL_set_session_id_context(SSL *ssl, const unsigned char *sid_ctx, unsigned int sid_ctx_len); @@ -1874,14 +1841,8 @@ __owur int SSL_set_purpose(SSL *ssl, int purpose); __owur int SSL_CTX_set_trust(SSL_CTX *ctx, int trust); __owur int SSL_set_trust(SSL *ssl, int trust); -#ifndef OPENSSL_NO_DEPRECATED_4_0 -OSSL_DEPRECATEDIN_4_0 __owur int SSL_set1_host(SSL *s, const char *host); -OSSL_DEPRECATEDIN_4_0 __owur int SSL_add1_host(SSL *s, const char *host); -#endif /* OPENSSL_NO_DEPRECATED_4_0 */ -__owur int SSL_set1_dnsname(SSL *s, const char *dnsname); -__owur int SSL_add1_dnsname(SSL *s, const char *dnsname); -__owur int SSL_set1_ipaddr(SSL *s, const char *ipaddr); -__owur int SSL_add1_ipaddr(SSL *s, const char *ipaddr); +__owur int SSL_set1_host(SSL *s, const char *host); +__owur int SSL_add1_host(SSL *s, const char *host); __owur const char *SSL_get0_peername(SSL *s); void SSL_set_hostflags(SSL *s, unsigned int flags); @@ -1961,9 +1922,7 @@ typedef int (*SSL_new_pending_conn_cb_fn)(SSL_CTX *ctx, SSL *new_ssl, void SSL_CTX_set_new_pending_conn_cb(SSL_CTX *c, SSL_new_pending_conn_cb_fn cb, void *arg); -#ifndef OPENSSL_NO_DEPRECATED_4_0 -OSSL_DEPRECATEDIN_4_0 int SSL_client_hello_isv2(SSL *s); -#endif +int SSL_client_hello_isv2(SSL *s); unsigned int SSL_client_hello_get0_legacy_version(SSL *s); size_t SSL_client_hello_get0_random(SSL *s, const unsigned char **out); size_t SSL_client_hello_get0_session_id(SSL *s, const unsigned char **out); @@ -2041,6 +2000,14 @@ OSSL_DEPRECATEDIN_3_0 __owur int SSL_CTX_set_ssl_version(SSL_CTX *ctx, const SSL_METHOD *meth); #endif +#ifndef OPENSSL_NO_SSL3_METHOD +#ifndef OPENSSL_NO_DEPRECATED_1_1_0 +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *SSLv3_method(void); /* SSLv3 */ +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *SSLv3_server_method(void); +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *SSLv3_client_method(void); +#endif +#endif + #define SSLv23_method TLS_method #define SSLv23_server_method TLS_server_method #define SSLv23_client_method TLS_client_method @@ -2050,6 +2017,47 @@ __owur const SSL_METHOD *TLS_method(void); __owur const SSL_METHOD *TLS_server_method(void); __owur const SSL_METHOD *TLS_client_method(void); +#ifndef OPENSSL_NO_TLS1_METHOD +#ifndef OPENSSL_NO_DEPRECATED_1_1_0 +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *TLSv1_method(void); /* TLSv1.0 */ +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *TLSv1_server_method(void); +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *TLSv1_client_method(void); +#endif +#endif + +#ifndef OPENSSL_NO_TLS1_1_METHOD +#ifndef OPENSSL_NO_DEPRECATED_1_1_0 +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *TLSv1_1_method(void); /* TLSv1.1 */ +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *TLSv1_1_server_method(void); +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *TLSv1_1_client_method(void); +#endif +#endif + +#ifndef OPENSSL_NO_TLS1_2_METHOD +#ifndef OPENSSL_NO_DEPRECATED_1_1_0 +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *TLSv1_2_method(void); /* TLSv1.2 */ +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *TLSv1_2_server_method(void); +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *TLSv1_2_client_method(void); +#endif +#endif + +#ifndef OPENSSL_NO_DTLS1_METHOD +#ifndef OPENSSL_NO_DEPRECATED_1_1_0 +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *DTLSv1_method(void); /* DTLSv1.0 */ +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *DTLSv1_server_method(void); +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *DTLSv1_client_method(void); +#endif +#endif + +#ifndef OPENSSL_NO_DTLS1_2_METHOD +/* DTLSv1.2 */ +#ifndef OPENSSL_NO_DEPRECATED_1_1_0 +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *DTLSv1_2_method(void); +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *DTLSv1_2_server_method(void); +OSSL_DEPRECATEDIN_1_1_0 __owur const SSL_METHOD *DTLSv1_2_client_method(void); +#endif +#endif + __owur const SSL_METHOD *DTLS_method(void); /* DTLS 1.0 and 1.2 */ __owur const SSL_METHOD *DTLS_server_method(void); /* DTLS 1.0 and 1.2 */ __owur const SSL_METHOD *DTLS_client_method(void); /* DTLS 1.0 and 1.2 */ @@ -2440,12 +2448,6 @@ __owur int SSL_get_conn_close_info(SSL *ssl, #define SSL_VALUE_STREAM_WRITE_BUF_SIZE 7 #define SSL_VALUE_STREAM_WRITE_BUF_USED 8 #define SSL_VALUE_STREAM_WRITE_BUF_AVAIL 9 -#define SSL_VALUE_QUIC_UDP_PAYLOAD_SIZE_MAX 10 -#define SSL_VALUE_QUIC_WINDOWCON 11 -#define SSL_VALUE_QUIC_WINDOWBSTR 12 -#define SSL_VALUE_QUIC_WINDOWUSTR 13 -#define SSL_VALUE_QUIC_ACK_DELAY_EXPONENT 14 -#define SSL_VALUE_QUIC_ACK_DELAY_MAX 15 #define SSL_VALUE_EVENT_HANDLING_MODE_INHERIT 0 #define SSL_VALUE_EVENT_HANDLING_MODE_IMPLICIT 1 @@ -2556,7 +2558,7 @@ SSL_as_poll_descriptor(SSL *s) __owur int SSL_session_reused(const SSL *s); __owur int SSL_is_server(const SSL *s); -__owur SSL_CONF_CTX *SSL_CONF_CTX_new(void); +__owur __owur SSL_CONF_CTX *SSL_CONF_CTX_new(void); int SSL_CONF_CTX_finish(SSL_CONF_CTX *cctx); void SSL_CONF_CTX_free(SSL_CONF_CTX *cctx); unsigned int SSL_CONF_CTX_set_flags(SSL_CONF_CTX *cctx, unsigned int flags); @@ -2695,18 +2697,8 @@ const CTLOG_STORE *SSL_CTX_get0_ctlog_store(const SSL_CTX *ctx); #define SSL_SECOP_OTHER_SIGALG (5 << 16) #define SSL_SECOP_OTHER_CERT (6 << 16) -/* - * Unused values - these do nothing and are never set. - * They are retained because of API. They should - * be removed next major - */ +/* Indicated operation refers to peer key or certificate */ #define SSL_SECOP_PEER 0x1000 -/* Peer EE key in certificate */ -#define SSL_SECOP_PEER_EE_KEY (SSL_SECOP_EE_KEY | SSL_SECOP_PEER) -/* Peer CA key in certificate */ -#define SSL_SECOP_PEER_CA_KEY (SSL_SECOP_CA_KEY | SSL_SECOP_PEER) -/* Peer CA digest algorithm in certificate */ -#define SSL_SECOP_PEER_CA_MD (SSL_SECOP_CA_MD | SSL_SECOP_PEER) /* Values for "op" parameter in security callback */ @@ -2745,6 +2737,12 @@ const CTLOG_STORE *SSL_CTX_get0_ctlog_store(const SSL_CTX *ctx); #define SSL_SECOP_CA_KEY (17 | SSL_SECOP_OTHER_CERT) /* CA digest algorithm in certificate */ #define SSL_SECOP_CA_MD (18 | SSL_SECOP_OTHER_CERT) +/* Peer EE key in certificate */ +#define SSL_SECOP_PEER_EE_KEY (SSL_SECOP_EE_KEY | SSL_SECOP_PEER) +/* Peer CA key in certificate */ +#define SSL_SECOP_PEER_CA_KEY (SSL_SECOP_CA_KEY | SSL_SECOP_PEER) +/* Peer CA digest algorithm in certificate */ +#define SSL_SECOP_PEER_CA_MD (SSL_SECOP_CA_MD | SSL_SECOP_PEER) void SSL_set_security_level(SSL *s, int level); __owur int SSL_get_security_level(const SSL *s); @@ -2784,11 +2782,8 @@ __owur void *SSL_CTX_get0_security_ex_data(const SSL_CTX *ctx); int OPENSSL_init_ssl(uint64_t opts, const OPENSSL_INIT_SETTINGS *settings); #ifndef OPENSSL_NO_UNIT_TEST -#ifndef OPENSSL_NO_DEPRECATED_4_1 -OSSL_DEPRECATEDIN_4_1 __owur const struct openssl_ssl_test_functions *SSL_test_functions(void); #endif -#endif __owur int SSL_free_buffers(SSL *ssl); __owur int SSL_alloc_buffers(SSL *ssl); diff --git a/include/openssl/sslerr.h b/include/openssl/sslerr.h index 6ae701dba0..6993255b19 100644 --- a/include/openssl/sslerr.h +++ b/include/openssl/sslerr.h @@ -1,6 +1,6 @@ /* * Generated by util/mkerr.pl DO NOT EDIT - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -34,7 +34,6 @@ #define SSL_R_BAD_DIGEST_LENGTH 111 #define SSL_R_BAD_EARLY_DATA 233 #define SSL_R_BAD_ECC_CERT 304 -#define SSL_R_BAD_ECHCONFIG_EXTENSION 425 #define SSL_R_BAD_ECPOINT 306 #define SSL_R_BAD_EXTENSION 110 #define SSL_R_BAD_HANDSHAKE_LENGTH 332 @@ -112,8 +111,6 @@ #define SSL_R_DUPLICATE_COMPRESSION_ID 309 #define SSL_R_ECC_CERT_NOT_FOR_SIGNING 318 #define SSL_R_ECDH_REQUIRED_FOR_SUITEB_MODE 374 -#define SSL_R_ECH_DECODE_ERROR 426 -#define SSL_R_ECH_REQUIRED 424 #define SSL_R_EE_KEY_TOO_SMALL 399 #define SSL_R_EMPTY_RAW_PUBLIC_KEY 349 #define SSL_R_EMPTY_SRTP_PROTECTION_PROFILE_LIST 354 @@ -269,6 +266,21 @@ #define SSL_R_SRTP_COULD_NOT_ALLOCATE_PROFILES 362 #define SSL_R_SRTP_PROTECTION_PROFILE_LIST_TOO_LONG 363 #define SSL_R_SRTP_UNKNOWN_PROTECTION_PROFILE 364 +#define SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH 232 +#define SSL_R_SSL3_EXT_INVALID_SERVERNAME 319 +#define SSL_R_SSL3_EXT_INVALID_SERVERNAME_TYPE 320 +#define SSL_R_SSL3_SESSION_ID_TOO_LONG 300 +#define SSL_R_SSLV3_ALERT_BAD_CERTIFICATE 1042 +#define SSL_R_SSLV3_ALERT_BAD_RECORD_MAC 1020 +#define SSL_R_SSLV3_ALERT_CERTIFICATE_EXPIRED 1045 +#define SSL_R_SSLV3_ALERT_CERTIFICATE_REVOKED 1044 +#define SSL_R_SSLV3_ALERT_CERTIFICATE_UNKNOWN 1046 +#define SSL_R_SSLV3_ALERT_DECOMPRESSION_FAILURE 1030 +#define SSL_R_SSLV3_ALERT_HANDSHAKE_FAILURE 1040 +#define SSL_R_SSLV3_ALERT_ILLEGAL_PARAMETER 1047 +#define SSL_R_SSLV3_ALERT_NO_CERTIFICATE 1041 +#define SSL_R_SSLV3_ALERT_UNEXPECTED_MESSAGE 1010 +#define SSL_R_SSLV3_ALERT_UNSUPPORTED_CERTIFICATE 1043 #define SSL_R_SSL_COMMAND_SECTION_EMPTY 117 #define SSL_R_SSL_COMMAND_SECTION_NOT_FOUND 125 #define SSL_R_SSL_CTX_HAS_NO_DEFAULT_SSL_VERSION 228 @@ -311,28 +323,15 @@ #define SSL_R_TLSV1_CERTIFICATE_UNOBTAINABLE 1111 #define SSL_R_TLSV1_UNRECOGNIZED_NAME 1112 #define SSL_R_TLSV1_UNSUPPORTED_EXTENSION 1110 -#define SSL_R_TLS_ALERT_BAD_CERTIFICATE 1042 -#define SSL_R_TLS_ALERT_BAD_RECORD_MAC 1020 -#define SSL_R_TLS_ALERT_CERTIFICATE_EXPIRED 1045 -#define SSL_R_TLS_ALERT_CERTIFICATE_REVOKED 1044 -#define SSL_R_TLS_ALERT_CERTIFICATE_UNKNOWN 1046 -#define SSL_R_TLS_ALERT_DECOMPRESSION_FAILURE 1030 -#define SSL_R_TLS_ALERT_HANDSHAKE_FAILURE 1040 -#define SSL_R_TLS_ALERT_ILLEGAL_PARAMETER 1047 -#define SSL_R_TLS_ALERT_NO_CERTIFICATE 1041 -#define SSL_R_TLS_ALERT_UNEXPECTED_MESSAGE 1010 -#define SSL_R_TLS_ALERT_UNSUPPORTED_CERTIFICATE 1043 -#define SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH 232 -#define SSL_R_TLS_EXT_INVALID_SERVERNAME 319 -#define SSL_R_TLS_EXT_INVALID_SERVERNAME_TYPE 320 #define SSL_R_TLS_ILLEGAL_EXPORTER_LABEL 367 #define SSL_R_TLS_INVALID_ECPOINTFORMAT_LIST 157 -#define SSL_R_TLS_SESSION_ID_TOO_LONG 300 #define SSL_R_TOO_MANY_KEY_UPDATES 132 #define SSL_R_TOO_MANY_WARN_ALERTS 409 #define SSL_R_TOO_MUCH_EARLY_DATA 164 #define SSL_R_UNABLE_TO_FIND_ECDH_PARAMETERS 314 #define SSL_R_UNABLE_TO_FIND_PUBLIC_KEY_PARAMETERS 239 +#define SSL_R_UNABLE_TO_LOAD_SSL3_MD5_ROUTINES 242 +#define SSL_R_UNABLE_TO_LOAD_SSL3_SHA1_ROUTINES 243 #define SSL_R_UNEXPECTED_CCS_MESSAGE 262 #define SSL_R_UNEXPECTED_END_OF_EARLY_DATA 178 #define SSL_R_UNEXPECTED_EOF_WHILE_READING 294 diff --git a/include/openssl/sslerr_legacy.h b/include/openssl/sslerr_legacy.h index fd3453e413..8cf1ebd7b0 100644 --- a/include/openssl/sslerr_legacy.h +++ b/include/openssl/sslerr_legacy.h @@ -461,26 +461,6 @@ OSSL_DEPRECATEDIN_3_0 int ERR_load_SSL_strings(void); #define SSL_F_WRITE_STATE_MACHINE 0 #endif -#ifndef OPENSSL_NO_DEPRECATED_4_0 - -#define SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH 232 -#define SSL_R_SSL3_EXT_INVALID_SERVERNAME 319 -#define SSL_R_SSL3_EXT_INVALID_SERVERNAME_TYPE 320 -#define SSL_R_SSL3_SESSION_ID_TOO_LONG 300 -#define SSL_R_SSLV3_ALERT_BAD_CERTIFICATE 1042 -#define SSL_R_SSLV3_ALERT_BAD_RECORD_MAC 1020 -#define SSL_R_SSLV3_ALERT_CERTIFICATE_EXPIRED 1045 -#define SSL_R_SSLV3_ALERT_CERTIFICATE_REVOKED 1044 -#define SSL_R_SSLV3_ALERT_CERTIFICATE_UNKNOWN 1046 -#define SSL_R_SSLV3_ALERT_DECOMPRESSION_FAILURE 1030 -#define SSL_R_SSLV3_ALERT_HANDSHAKE_FAILURE 1040 -#define SSL_R_SSLV3_ALERT_ILLEGAL_PARAMETER 1047 -#define SSL_R_SSLV3_ALERT_NO_CERTIFICATE 1041 -#define SSL_R_SSLV3_ALERT_UNEXPECTED_MESSAGE 1010 -#define SSL_R_SSLV3_ALERT_UNSUPPORTED_CERTIFICATE 1043 - -#endif - #ifdef __cplusplus } #endif diff --git a/include/openssl/stack.h b/include/openssl/stack.h index 7cab36c4f6..d8e818a258 100644 --- a/include/openssl/stack.h +++ b/include/openssl/stack.h @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -26,7 +26,6 @@ typedef int (*OPENSSL_sk_compfunc)(const void *, const void *); typedef void (*OPENSSL_sk_freefunc)(void *); typedef void (*OPENSSL_sk_freefunc_thunk)(OPENSSL_sk_freefunc, void *); typedef void *(*OPENSSL_sk_copyfunc)(const void *); -typedef void *(*OPENSSL_sk_copyfunc_thunk)(OPENSSL_sk_copyfunc, const void *); int OPENSSL_sk_num(const OPENSSL_STACK *); void *OPENSSL_sk_value(const OPENSSL_STACK *, int); @@ -37,8 +36,6 @@ OPENSSL_STACK *OPENSSL_sk_new(OPENSSL_sk_compfunc cmp); OPENSSL_STACK *OPENSSL_sk_new_null(void); OPENSSL_STACK *OPENSSL_sk_new_reserve(OPENSSL_sk_compfunc c, int n); OPENSSL_STACK *OPENSSL_sk_set_thunks(OPENSSL_STACK *st, OPENSSL_sk_freefunc_thunk f_thunk); -OPENSSL_STACK *OPENSSL_sk_set_cmp_thunks(OPENSSL_STACK *st, int (*c_thunk)(int (*)(const void *, const void *), const void *, const void *)); -OPENSSL_STACK *OPENSSL_sk_set_copy_thunks(OPENSSL_STACK *st, OPENSSL_sk_copyfunc_thunk cp_thunk); int OPENSSL_sk_reserve(OPENSSL_STACK *st, int n); void OPENSSL_sk_free(OPENSSL_STACK *); void OPENSSL_sk_pop_free(OPENSSL_STACK *st, OPENSSL_sk_freefunc func); diff --git a/include/openssl/store.h b/include/openssl/store.h index 980971aa0e..5c25d0f852 100644 --- a/include/openssl/store.h +++ b/include/openssl/store.h @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -227,8 +227,8 @@ int OSSL_STORE_supports_search(OSSL_STORE_CTX *ctx, int search_type); * The input is considered to be owned by the caller, and must therefore * remain present throughout the lifetime of the returned OSSL_STORE_SEARCH */ -OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_name(const X509_NAME *name); -OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_issuer_serial(const X509_NAME *name, +OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_name(X509_NAME *name); +OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_issuer_serial(X509_NAME *name, const ASN1_INTEGER *serial); OSSL_STORE_SEARCH *OSSL_STORE_SEARCH_by_key_fingerprint(const EVP_MD *digest, @@ -242,7 +242,7 @@ void OSSL_STORE_SEARCH_free(OSSL_STORE_SEARCH *search); /* Search term accessors */ int OSSL_STORE_SEARCH_get_type(const OSSL_STORE_SEARCH *criterion); -const X509_NAME *OSSL_STORE_SEARCH_get0_name(const OSSL_STORE_SEARCH *criterion); +X509_NAME *OSSL_STORE_SEARCH_get0_name(const OSSL_STORE_SEARCH *criterion); const ASN1_INTEGER *OSSL_STORE_SEARCH_get0_serial(const OSSL_STORE_SEARCH *criterion); const unsigned char *OSSL_STORE_SEARCH_get0_bytes(const OSSL_STORE_SEARCH diff --git a/include/openssl/tls1.h b/include/openssl/tls1.h index f43dedc5ad..34d376863a 100644 --- a/include/openssl/tls1.h +++ b/include/openssl/tls1.h @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * Copyright 2005 Nokia. All rights reserved. * @@ -78,9 +78,6 @@ extern "C" { #define TLS1_AD_BAD_CERTIFICATE_HASH_VALUE 114 #define TLS1_AD_UNKNOWN_PSK_IDENTITY 115 /* fatal */ #define TLS1_AD_NO_APPLICATION_PROTOCOL 120 /* fatal */ -#ifndef OPENSSL_NO_ECH -#define TLS1_AD_ECH_REQUIRED 121 /* fatal */ -#endif /* ExtensionType values from RFC3546 / RFC4366 / RFC6066 */ #define TLSEXT_TYPE_server_name 0 @@ -170,11 +167,6 @@ extern "C" { #define TLSEXT_TYPE_next_proto_neg 13172 #endif -#ifndef OPENSSL_NO_ECH -#define TLSEXT_TYPE_ech 0xfe0d -#define TLSEXT_TYPE_outer_extensions 0xfd00 -#endif - /* NameType value from RFC3546 */ #define TLSEXT_NAMETYPE_host_name 0 /* status request value from RFC3546 */ @@ -255,7 +247,7 @@ int SSL_set_tlsext_max_fragment_length(SSL *ssl, uint8_t mode); #define TLSEXT_MAXLEN_host_name 255 -__owur const char *SSL_get_servername(const SSL *s, int type); +__owur const char *SSL_get_servername(const SSL *s, const int type); __owur int SSL_get_servername_type(const SSL *s); /* * SSL_export_keying_material exports a value derived from the master secret, @@ -285,11 +277,6 @@ __owur int SSL_export_keying_material_early(SSL *s, unsigned char *out, int SSL_get_peer_signature_type_nid(const SSL *s, int *pnid); int SSL_get_signature_type_nid(const SSL *s, int *pnid); -int SSL_get0_sigalg(SSL *s, int idx, unsigned int *codepoint, - const char **name); -int SSL_get0_shared_sigalg(SSL *s, int idx, unsigned int *codepoint, - const char **name); - int SSL_get_sigalgs(SSL *s, int idx, int *psign, int *phash, int *psignandhash, unsigned char *rsig, unsigned char *rhash); @@ -674,10 +661,6 @@ int SSL_CTX_set_tlsext_ticket_key_evp_cb(SSL_CTX *ctx, int (*fp)(SSL *, unsigned #define TLS1_CK_RSA_PSK_WITH_ARIA_128_GCM_SHA256 0x0300C06E #define TLS1_CK_RSA_PSK_WITH_ARIA_256_GCM_SHA384 0x0300C06F -/* SM ciphersuites from RFC8998 */ -#define TLS1_3_CK_SM4_GCM_SM3 0x030000C6 -#define TLS1_3_CK_SM4_CCM_SM3 0x030000C7 - /* a bundle of RFC standard cipher names, generated from ssl3_ciphers[] */ #define TLS1_RFC_RSA_WITH_AES_128_SHA "TLS_RSA_WITH_AES_128_CBC_SHA" #define TLS1_RFC_DHE_DSS_WITH_AES_128_SHA "TLS_DHE_DSS_WITH_AES_128_CBC_SHA" @@ -870,8 +853,6 @@ int SSL_CTX_set_tlsext_ticket_key_evp_cb(SSL_CTX *ctx, int (*fp)(SSL *, unsigned #define TLS1_RFC_DHE_PSK_WITH_ARIA_256_GCM_SHA384 "TLS_DHE_PSK_WITH_ARIA_256_GCM_SHA384" #define TLS1_RFC_RSA_PSK_WITH_ARIA_128_GCM_SHA256 "TLS_RSA_PSK_WITH_ARIA_128_GCM_SHA256" #define TLS1_RFC_RSA_PSK_WITH_ARIA_256_GCM_SHA384 "TLS_RSA_PSK_WITH_ARIA_256_GCM_SHA384" -#define TLS1_3_RFC_SM4_GCM_SM3 "TLS_SM4_GCM_SM3" -#define TLS1_3_RFC_SM4_CCM_SM3 "TLS_SM4_CCM_SM3" /* * XXX Backward compatibility alert: Older versions of OpenSSL gave some DHE @@ -1103,6 +1084,10 @@ int SSL_CTX_set_tlsext_ticket_key_evp_cb(SSL_CTX *ctx, int (*fp)(SSL *, unsigned #define TLS1_TXT_ECDH_RSA_WITH_AES_128_GCM_SHA256 "ECDH-RSA-AES128-GCM-SHA256" #define TLS1_TXT_ECDH_RSA_WITH_AES_256_GCM_SHA384 "ECDH-RSA-AES256-GCM-SHA384" +/* TLS v1.2 PSK GCM ciphersuites from RFC5487 */ +#define TLS1_TXT_PSK_WITH_AES_128_GCM_SHA256 "PSK-AES128-GCM-SHA256" +#define TLS1_TXT_PSK_WITH_AES_256_GCM_SHA384 "PSK-AES256-GCM-SHA384" + /* ECDHE PSK ciphersuites from RFC 5489 */ #define TLS1_TXT_ECDHE_PSK_WITH_RC4_128_SHA "ECDHE-PSK-RC4-SHA" #define TLS1_TXT_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA "ECDHE-PSK-3DES-EDE-CBC-SHA" @@ -1212,6 +1197,9 @@ int SSL_CTX_set_tlsext_ticket_key_evp_cb(SSL_CTX *ctx, int (*fp)(SSL *, unsigned /* ASCII: "client write key", in hex for EBCDIC compatibility */ #define TLS_MD_CLIENT_WRITE_KEY_CONST "\x63\x6c\x69\x65\x6e\x74\x20\x77\x72\x69\x74\x65\x20\x6b\x65\x79" #define TLS_MD_CLIENT_WRITE_KEY_CONST_SIZE 16 +/* ASCII: "server write key", in hex for EBCDIC compatibility */ +#define TLS_MD_SERVER_WRITE_KEY_CONST "\x73\x65\x72\x76\x65\x72\x20\x77\x72\x69\x74\x65\x20\x6b\x65\x79" +#define TLS_MD_SERVER_WRITE_KEY_CONST_SIZE 16 /* ASCII: "IV block", in hex for EBCDIC compatibility */ #define TLS_MD_IV_BLOCK_CONST "\x49\x56\x20\x62\x6c\x6f\x63\x6b" #define TLS_MD_IV_BLOCK_CONST_SIZE 8 diff --git a/include/openssl/ts.h b/include/openssl/ts.h index 93c7dce4b6..1d5110b1b7 100644 --- a/include/openssl/ts.h +++ b/include/openssl/ts.h @@ -1,5 +1,5 @@ /* - * Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2006-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -155,7 +155,7 @@ int TS_REQ_get_ext_count(TS_REQ *a); int TS_REQ_get_ext_by_NID(TS_REQ *a, int nid, int lastpos); int TS_REQ_get_ext_by_OBJ(TS_REQ *a, const ASN1_OBJECT *obj, int lastpos); int TS_REQ_get_ext_by_critical(TS_REQ *a, int crit, int lastpos); -const X509_EXTENSION *TS_REQ_get_ext(TS_REQ *a, int loc); +X509_EXTENSION *TS_REQ_get_ext(TS_REQ *a, int loc); X509_EXTENSION *TS_REQ_delete_ext(TS_REQ *a, int loc); int TS_REQ_add_ext(TS_REQ *a, X509_EXTENSION *ex, int loc); void *TS_REQ_get_ext_d2i(TS_REQ *a, int nid, int *crit, int *idx); @@ -217,7 +217,7 @@ int TS_TST_INFO_get_ext_by_NID(TS_TST_INFO *a, int nid, int lastpos); int TS_TST_INFO_get_ext_by_OBJ(TS_TST_INFO *a, const ASN1_OBJECT *obj, int lastpos); int TS_TST_INFO_get_ext_by_critical(TS_TST_INFO *a, int crit, int lastpos); -const X509_EXTENSION *TS_TST_INFO_get_ext(TS_TST_INFO *a, int loc); +X509_EXTENSION *TS_TST_INFO_get_ext(TS_TST_INFO *a, int loc); X509_EXTENSION *TS_TST_INFO_delete_ext(TS_TST_INFO *a, int loc); int TS_TST_INFO_add_ext(TS_TST_INFO *a, X509_EXTENSION *ex, int loc); void *TS_TST_INFO_get_ext_d2i(TS_TST_INFO *a, int nid, int *crit, int *idx); @@ -358,7 +358,7 @@ TS_RESP *TS_RESP_create_response(TS_RESP_CTX *ctx, BIO *req_bio); * they are defined in ts/ts_resp_verify.c. */ -int TS_RESP_verify_signature(PKCS7 *token, const STACK_OF(X509) *certs, +int TS_RESP_verify_signature(PKCS7 *token, STACK_OF(X509) *certs, X509_STORE *store, X509 **signer_out); /* Context structure for the generic verify method. */ diff --git a/include/openssl/types.h b/include/openssl/types.h index cfc021ef1a..f8bb853229 100644 --- a/include/openssl/types.h +++ b/include/openssl/types.h @@ -1,5 +1,5 @@ /* - * Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2001-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -11,7 +11,6 @@ * Unfortunate workaround to avoid symbol conflict with wincrypt.h * See https://github.com/openssl/openssl/issues/9981 */ - #ifdef _WIN32 #define WINCRYPT_USE_SYMBOL_PREFIX #undef X509_NAME @@ -37,23 +36,23 @@ extern "C" { typedef struct ossl_provider_st OSSL_PROVIDER; /* Provider Object */ #ifdef NO_ASN1_TYPEDEFS -typedef ASN1_STRING ASN1_INTEGER; -typedef ASN1_STRING ASN1_ENUMERATED; -typedef ASN1_STRING ASN1_BIT_STRING; -typedef ASN1_STRING ASN1_OCTET_STRING; -typedef ASN1_STRING ASN1_PRINTABLESTRING; -typedef ASN1_STRING ASN1_T61STRING; -typedef ASN1_STRING ASN1_IA5STRING; -typedef ASN1_STRING ASN1_UTCTIME; -typedef ASN1_STRING ASN1_GENERALIZEDTIME; -typedef ASN1_STRING ASN1_TIME; -typedef ASN1_STRING ASN1_GENERALSTRING; -typedef ASN1_STRING ASN1_UNIVERSALSTRING; -typedef ASN1_STRING ASN1_BMPSTRING; -typedef ASN1_STRING ASN1_VISIBLESTRING; -typedef ASN1_STRING ASN1_UTF8STRING; -typedef int ASN1_BOOLEAN; -typedef int ASN1_NULL; +#define ASN1_INTEGER ASN1_STRING +#define ASN1_ENUMERATED ASN1_STRING +#define ASN1_BIT_STRING ASN1_STRING +#define ASN1_OCTET_STRING ASN1_STRING +#define ASN1_PRINTABLESTRING ASN1_STRING +#define ASN1_T61STRING ASN1_STRING +#define ASN1_IA5STRING ASN1_STRING +#define ASN1_UTCTIME ASN1_STRING +#define ASN1_GENERALIZEDTIME ASN1_STRING +#define ASN1_TIME ASN1_STRING +#define ASN1_GENERALSTRING ASN1_STRING +#define ASN1_UNIVERSALSTRING ASN1_STRING +#define ASN1_BMPSTRING ASN1_STRING +#define ASN1_VISIBLESTRING ASN1_STRING +#define ASN1_UTF8STRING ASN1_STRING +#define ASN1_BOOLEAN int +#define ASN1_NULL int #else typedef struct asn1_string_st ASN1_INTEGER; typedef struct asn1_string_st ASN1_ENUMERATED; @@ -150,9 +149,7 @@ typedef struct dsa_method DSA_METHOD; typedef struct rsa_st RSA; typedef struct rsa_meth_st RSA_METHOD; #endif - typedef struct rsa_pss_params_st RSA_PSS_PARAMS; -typedef struct rsa_oaep_params_st RSA_OAEP_PARAMS; #ifndef OPENSSL_NO_DEPRECATED_3_0 typedef struct ec_key_st EC_KEY; @@ -160,6 +157,7 @@ typedef struct ec_key_method_st EC_KEY_METHOD; #endif typedef struct rand_meth_st RAND_METHOD; +typedef struct rand_drbg_st RAND_DRBG; typedef struct ssl_dane_st SSL_DANE; typedef struct x509_st X509; @@ -238,11 +236,6 @@ typedef struct ossl_decoder_ctx_st OSSL_DECODER_CTX; typedef struct ossl_self_test_st OSSL_SELF_TEST; -#ifndef OPENSSL_NO_ECH -/* opaque type for ECH related information */ -typedef struct ossl_echstore_st OSSL_ECHSTORE; -#endif - #ifdef __cplusplus } #endif diff --git a/include/openssl/x509.h.in b/include/openssl/x509.h.in index cb556ecbe8..a0e17b862b 100644 --- a/include/openssl/x509.h.in +++ b/include/openssl/x509.h.in @@ -1,7 +1,7 @@ /* * {- join("\n * ", @autowarntext) -} * - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -327,8 +327,8 @@ void *X509_CRL_get_meth_data(X509_CRL *crl); const char *X509_verify_cert_error_string(long n); -int X509_verify(const X509 *a, EVP_PKEY *r); -int X509_self_signed(const X509 *cert, int verify_signature); +int X509_verify(X509 *a, EVP_PKEY *r); +int X509_self_signed(X509 *cert, int verify_signature); int X509_REQ_verify_ex(X509_REQ *a, EVP_PKEY *r, OSSL_LIB_CTX *libctx, const char *propq); @@ -488,25 +488,20 @@ int X509_ALGOR_set0(X509_ALGOR *alg, ASN1_OBJECT *aobj, int ptype, void *pval); void X509_ALGOR_get0(const ASN1_OBJECT **paobj, int *pptype, const void **ppval, const X509_ALGOR *algor); -int X509_ALGOR_set_md(X509_ALGOR *alg, const EVP_MD *md); +void X509_ALGOR_set_md(X509_ALGOR *alg, const EVP_MD *md); int X509_ALGOR_cmp(const X509_ALGOR *a, const X509_ALGOR *b); int X509_ALGOR_copy(X509_ALGOR *dest, const X509_ALGOR *src); DECLARE_ASN1_DUP_FUNCTION(X509_NAME) DECLARE_ASN1_DUP_FUNCTION(X509_NAME_ENTRY) -#ifndef OPENSSL_NO_DEPRECATED_4_0 -OSSL_DEPRECATEDIN_4_0 int X509_cmp_time(const ASN1_TIME *s, const time_t *t); -OSSL_DEPRECATEDIN_4_0 int X509_cmp_current_time(const ASN1_TIME *s); -OSSL_DEPRECATEDIN_4_0 int X509_cmp_timeframe(const X509_VERIFY_PARAM *vpm, - const ASN1_TIME *start, - const ASN1_TIME *end); -#endif -int X509_check_certificate_times(const X509_VERIFY_PARAM *vpm, const X509 *x, - int *error); -ASN1_TIME *X509_time_adj(ASN1_TIME *s, long adj, const time_t *t); +int X509_cmp_time(const ASN1_TIME *s, time_t *t); +int X509_cmp_current_time(const ASN1_TIME *s); +int X509_cmp_timeframe(const X509_VERIFY_PARAM *vpm, + const ASN1_TIME *start, const ASN1_TIME *end); +ASN1_TIME *X509_time_adj(ASN1_TIME *s, long adj, time_t *t); ASN1_TIME *X509_time_adj_ex(ASN1_TIME *s, - int offset_day, long offset_sec, const time_t *t); + int offset_day, long offset_sec, time_t *t); ASN1_TIME *X509_gmtime_adj(ASN1_TIME *s, long adj); const char *X509_get_default_cert_area(void); @@ -516,8 +511,8 @@ const char *X509_get_default_cert_dir_env(void); const char *X509_get_default_cert_file_env(void); const char *X509_get_default_private_dir(void); -X509_REQ *X509_to_X509_REQ(const X509 *x, EVP_PKEY *pkey, const EVP_MD *md); -X509 *X509_REQ_to_X509(const X509_REQ *r, int days, EVP_PKEY *pkey); +X509_REQ *X509_to_X509_REQ(X509 *x, EVP_PKEY *pkey, const EVP_MD *md); +X509 *X509_REQ_to_X509(X509_REQ *r, int days, EVP_PKEY *pkey); DECLARE_ASN1_FUNCTIONS(X509_ALGOR) DECLARE_ASN1_ENCODE_FUNCTIONS(X509_ALGORS, X509_ALGORS, X509_ALGORS) @@ -529,8 +524,8 @@ X509_PUBKEY *X509_PUBKEY_new_ex(OSSL_LIB_CTX *libctx, const char *propq); int X509_PUBKEY_set(X509_PUBKEY **x, EVP_PKEY *pkey); EVP_PKEY *X509_PUBKEY_get0(const X509_PUBKEY *key); EVP_PKEY *X509_PUBKEY_get(const X509_PUBKEY *key); -int X509_get_pubkey_parameters(EVP_PKEY *pkey, const STACK_OF(X509) *chain); -long X509_get_pathlen(const X509 *x); +int X509_get_pubkey_parameters(EVP_PKEY *pkey, STACK_OF(X509) *chain); +long X509_get_pathlen(X509 *x); DECLARE_ASN1_ENCODE_FUNCTIONS_only(EVP_PKEY, PUBKEY) EVP_PKEY *d2i_PUBKEY_ex(EVP_PKEY **a, const unsigned char **pp, long length, OSSL_LIB_CTX *libctx, const char *propq); @@ -588,7 +583,7 @@ int X509_SIG_INFO_get(const X509_SIG_INFO *siginf, int *mdnid, int *pknid, void X509_SIG_INFO_set(X509_SIG_INFO *siginf, int mdnid, int pknid, int secbits, uint32_t flags); -int X509_get_signature_info(const X509 *x, int *mdnid, int *pknid, int *secbits, +int X509_get_signature_info(X509 *x, int *mdnid, int *pknid, int *secbits, uint32_t *flags); void X509_get0_signature(const ASN1_BIT_STRING **psig, @@ -596,14 +591,14 @@ void X509_get0_signature(const ASN1_BIT_STRING **psig, int X509_get_signature_nid(const X509 *x); void X509_set0_distinguishing_id(X509 *x, ASN1_OCTET_STRING *d_id); -const ASN1_OCTET_STRING *X509_get0_distinguishing_id(const X509 *x); +ASN1_OCTET_STRING *X509_get0_distinguishing_id(X509 *x); void X509_REQ_set0_distinguishing_id(X509_REQ *x, ASN1_OCTET_STRING *d_id); ASN1_OCTET_STRING *X509_REQ_get0_distinguishing_id(X509_REQ *x); int X509_alias_set1(X509 *x, const unsigned char *name, int len); int X509_keyid_set1(X509 *x, const unsigned char *id, int len); -const unsigned char *X509_alias_get0(const X509 *x, int *len); -const unsigned char *X509_keyid_get0(const X509 *x, int *len); +unsigned char *X509_alias_get0(const X509 *x, int *len); +unsigned char *X509_keyid_get0(const X509 *x, int *len); DECLARE_ASN1_FUNCTIONS(X509_REVOKED) DECLARE_ASN1_FUNCTIONS(X509_CRL_INFO) @@ -613,7 +608,7 @@ X509_CRL *X509_CRL_new_ex(OSSL_LIB_CTX *libctx, const char *propq); int X509_CRL_add0_revoked(X509_CRL *crl, X509_REVOKED *rev); int X509_CRL_get0_by_serial(X509_CRL *crl, X509_REVOKED **ret, const ASN1_INTEGER *serial); -int X509_CRL_get0_by_cert(X509_CRL *crl, X509_REVOKED **ret, const X509 *x); +int X509_CRL_get0_by_cert(X509_CRL *crl, X509_REVOKED **ret, X509 *x); X509_PKEY *X509_PKEY_new(void); void X509_PKEY_free(X509_PKEY *a); @@ -663,14 +658,14 @@ int X509_set_serialNumber(X509 *x, ASN1_INTEGER *serial); ASN1_INTEGER *X509_get_serialNumber(X509 *x); const ASN1_INTEGER *X509_get0_serialNumber(const X509 *x); int X509_set_issuer_name(X509 *x, const X509_NAME *name); -const X509_NAME *X509_get_issuer_name(const X509 *a); +X509_NAME *X509_get_issuer_name(const X509 *a); int X509_set_subject_name(X509 *x, const X509_NAME *name); -const X509_NAME *X509_get_subject_name(const X509 *a); +X509_NAME *X509_get_subject_name(const X509 *a); const ASN1_TIME *X509_get0_notBefore(const X509 *x); -ASN1_TIME *X509_getm_notBefore(X509 *x); +ASN1_TIME *X509_getm_notBefore(const X509 *x); int X509_set1_notBefore(X509 *x, const ASN1_TIME *tm); const ASN1_TIME *X509_get0_notAfter(const X509 *x); -ASN1_TIME *X509_getm_notAfter(X509 *x); +ASN1_TIME *X509_getm_notAfter(const X509 *x); int X509_set1_notAfter(X509 *x, const ASN1_TIME *tm); int X509_up_ref(X509 *x); int X509_get_signature_type(const X509 *x); @@ -683,25 +678,25 @@ int X509_get_signature_type(const X509 *x); #endif int X509_set_pubkey(X509 *x, EVP_PKEY *pkey); -EVP_PKEY *X509_get_pubkey(const X509 *x); /* deprecated */ +EVP_PKEY *X509_get_pubkey(X509 *x); /* deprecated */ EVP_PKEY *X509_get0_pubkey(const X509 *x); /* * This one is only used so that a binary form can output, as in * i2d_X509_PUBKEY(X509_get_X509_PUBKEY(x), &buf) */ -const X509_PUBKEY *X509_get_X509_PUBKEY(const X509 *x); +X509_PUBKEY *X509_get_X509_PUBKEY(const X509 *x); const STACK_OF(X509_EXTENSION) *X509_get0_extensions(const X509 *x); void X509_get0_uids(const X509 *x, const ASN1_BIT_STRING **piuid, const ASN1_BIT_STRING **psuid); const X509_ALGOR *X509_get0_tbs_sigalg(const X509 *x); -const ASN1_BIT_STRING *X509_get0_pubkey_bitstr(const X509 *x); +ASN1_BIT_STRING *X509_get0_pubkey_bitstr(const X509 *x); #define X509_REQ_VERSION_1 0 long X509_REQ_get_version(const X509_REQ *req); int X509_REQ_set_version(X509_REQ *x, long version); -const X509_NAME *X509_REQ_get_subject_name(const X509_REQ *req); +X509_NAME *X509_REQ_get_subject_name(const X509_REQ *req); int X509_REQ_set_subject_name(X509_REQ *req, const X509_NAME *name); void X509_REQ_get0_signature(const X509_REQ *req, const ASN1_BIT_STRING **psig, const X509_ALGOR **palg); @@ -759,7 +754,7 @@ const ASN1_TIME *X509_CRL_get0_nextUpdate(const X509_CRL *crl); OSSL_DEPRECATEDIN_1_1_0 ASN1_TIME *X509_CRL_get_lastUpdate(X509_CRL *crl); OSSL_DEPRECATEDIN_1_1_0 ASN1_TIME *X509_CRL_get_nextUpdate(X509_CRL *crl); #endif -const X509_NAME *X509_CRL_get_issuer(const X509_CRL *crl); +X509_NAME *X509_CRL_get_issuer(const X509_CRL *crl); const STACK_OF(X509_EXTENSION) *X509_CRL_get0_extensions(const X509_CRL *crl); STACK_OF(X509_REVOKED) *X509_CRL_get_REVOKED(const X509_CRL *crl); const X509_ALGOR *X509_CRL_get0_tbs_sigalg(const X509_CRL *crl); @@ -782,24 +777,24 @@ int X509_REQ_check_private_key(const X509_REQ *req, EVP_PKEY *pkey); int X509_check_private_key(const X509 *cert, const EVP_PKEY *pkey); int X509_chain_check_suiteb(int *perror_depth, - const X509 *x, STACK_OF(X509) *chain, + X509 *x, STACK_OF(X509) *chain, unsigned long flags); int X509_CRL_check_suiteb(X509_CRL *crl, EVP_PKEY *pk, unsigned long flags); void OSSL_STACK_OF_X509_free(STACK_OF(X509) *certs); STACK_OF(X509) *X509_chain_up_ref(STACK_OF(X509) *chain); int X509_issuer_and_serial_cmp(const X509 *a, const X509 *b); -unsigned long X509_issuer_and_serial_hash(const X509 *a); +unsigned long X509_issuer_and_serial_hash(X509 *a); int X509_issuer_name_cmp(const X509 *a, const X509 *b); -unsigned long X509_issuer_name_hash(const X509 *a); +unsigned long X509_issuer_name_hash(X509 *a); int X509_subject_name_cmp(const X509 *a, const X509 *b); -unsigned long X509_subject_name_hash(const X509 *x); +unsigned long X509_subject_name_hash(X509 *x); #ifndef OPENSSL_NO_MD5 -unsigned long X509_issuer_name_hash_old(const X509 *a); -unsigned long X509_subject_name_hash_old(const X509 *x); +unsigned long X509_issuer_name_hash_old(X509 *a); +unsigned long X509_subject_name_hash_old(X509 *x); #endif #define X509_ADD_FLAG_DEFAULT 0 @@ -807,8 +802,8 @@ unsigned long X509_subject_name_hash_old(const X509 *x); #define X509_ADD_FLAG_PREPEND 0x2 #define X509_ADD_FLAG_NO_DUP 0x4 #define X509_ADD_FLAG_NO_SS 0x8 -int X509_add_cert(STACK_OF(X509) *sk, const X509 *cert, int flags); -int X509_add_certs(STACK_OF(X509) *sk, const STACK_OF(X509) *certs, int flags); +int X509_add_cert(STACK_OF(X509) *sk, X509 *cert, int flags); +int X509_add_certs(STACK_OF(X509) *sk, STACK_OF(X509) *certs, int flags); int X509_cmp(const X509 *a, const X509 *b); int X509_NAME_cmp(const X509_NAME *a, const X509_NAME *b); @@ -825,8 +820,8 @@ int X509_CRL_cmp(const X509_CRL *a, const X509_CRL *b); int X509_CRL_match(const X509_CRL *a, const X509_CRL *b); int X509_aux_print(BIO *out, const X509 *x, int indent); #ifndef OPENSSL_NO_STDIO -int X509_print_ex_fp(FILE *bp, const X509 *x, unsigned long nmflag, unsigned long cflag); -int X509_print_fp(FILE *bp, const X509 *x); +int X509_print_ex_fp(FILE *bp, X509 *x, unsigned long nmflag, unsigned long cflag); +int X509_print_fp(FILE *bp, X509 *x); int X509_CRL_print_fp(FILE *bp, X509_CRL *x); int X509_REQ_print_fp(FILE *bp, const X509_REQ *req); int X509_NAME_print_ex_fp(FILE *fp, const X509_NAME *nm, int indent, unsigned long flags); @@ -843,12 +838,10 @@ int X509_REQ_print_ex(BIO *bp, const X509_REQ *x, unsigned long nmflag, unsigned int X509_REQ_print(BIO *bp, const X509_REQ *req); int X509_NAME_entry_count(const X509_NAME *name); -#if !defined(OPENSSL_NO_DEPRECATED_4_0) -OSSL_DEPRECATEDIN_4_0 int X509_NAME_get_text_by_NID(const X509_NAME *name, - int nid, char *buf, int len); -OSSL_DEPRECATEDIN_4_0 int X509_NAME_get_text_by_OBJ(const X509_NAME *name, - const ASN1_OBJECT *obj, char *buf, int len); -#endif /* !defined(OPENSSL_NO_DEPRECATED_4_0) */ +int X509_NAME_get_text_by_NID(const X509_NAME *name, int nid, + char *buf, int len); +int X509_NAME_get_text_by_OBJ(const X509_NAME *name, const ASN1_OBJECT *obj, + char *buf, int len); /* * NOTE: you should be passing -1, not 0 as lastpos. The functions that use @@ -857,7 +850,7 @@ OSSL_DEPRECATEDIN_4_0 int X509_NAME_get_text_by_OBJ(const X509_NAME *name, int X509_NAME_get_index_by_NID(const X509_NAME *name, int nid, int lastpos); int X509_NAME_get_index_by_OBJ(const X509_NAME *name, const ASN1_OBJECT *obj, int lastpos); -const X509_NAME_ENTRY *X509_NAME_get_entry(const X509_NAME *name, int loc); +X509_NAME_ENTRY *X509_NAME_get_entry(const X509_NAME *name, int loc); X509_NAME_ENTRY *X509_NAME_delete_entry(X509_NAME *name, int loc); int X509_NAME_add_entry(X509_NAME *name, const X509_NAME_ENTRY *ne, int loc, int set); @@ -885,8 +878,8 @@ X509_NAME_ENTRY *X509_NAME_ENTRY_create_by_OBJ(X509_NAME_ENTRY **ne, int X509_NAME_ENTRY_set_object(X509_NAME_ENTRY *ne, const ASN1_OBJECT *obj); int X509_NAME_ENTRY_set_data(X509_NAME_ENTRY *ne, int type, const unsigned char *bytes, int len); -const ASN1_OBJECT *X509_NAME_ENTRY_get_object(const X509_NAME_ENTRY *ne); -const ASN1_STRING *X509_NAME_ENTRY_get_data(const X509_NAME_ENTRY *ne); +ASN1_OBJECT *X509_NAME_ENTRY_get_object(const X509_NAME_ENTRY *ne); +ASN1_STRING *X509_NAME_ENTRY_get_data(const X509_NAME_ENTRY *ne); int X509_NAME_ENTRY_set(const X509_NAME_ENTRY *ne); int X509_NAME_get0_der(const X509_NAME *nm, const unsigned char **pder, @@ -899,11 +892,10 @@ int X509v3_get_ext_by_OBJ(const STACK_OF(X509_EXTENSION) *x, const ASN1_OBJECT *obj, int lastpos); int X509v3_get_ext_by_critical(const STACK_OF(X509_EXTENSION) *x, int crit, int lastpos); -const X509_EXTENSION *X509v3_get_ext(const STACK_OF(X509_EXTENSION) *x, int loc); +X509_EXTENSION *X509v3_get_ext(const STACK_OF(X509_EXTENSION) *x, int loc); X509_EXTENSION *X509v3_delete_ext(STACK_OF(X509_EXTENSION) *x, int loc); -X509_EXTENSION *X509v3_delete_extension(STACK_OF(X509_EXTENSION) **x, int loc); STACK_OF(X509_EXTENSION) *X509v3_add_ext(STACK_OF(X509_EXTENSION) **x, - const X509_EXTENSION *ex, int loc); + X509_EXTENSION *ex, int loc); STACK_OF(X509_EXTENSION) *X509v3_add_extensions(STACK_OF(X509_EXTENSION) **target, const STACK_OF(X509_EXTENSION) *exts); @@ -911,9 +903,9 @@ int X509_get_ext_count(const X509 *x); int X509_get_ext_by_NID(const X509 *x, int nid, int lastpos); int X509_get_ext_by_OBJ(const X509 *x, const ASN1_OBJECT *obj, int lastpos); int X509_get_ext_by_critical(const X509 *x, int crit, int lastpos); -const X509_EXTENSION *X509_get_ext(const X509 *x, int loc); +X509_EXTENSION *X509_get_ext(const X509 *x, int loc); X509_EXTENSION *X509_delete_ext(X509 *x, int loc); -int X509_add_ext(X509 *x, const X509_EXTENSION *ex, int loc); +int X509_add_ext(X509 *x, X509_EXTENSION *ex, int loc); void *X509_get_ext_d2i(const X509 *x, int nid, int *crit, int *idx); int X509_add1_ext_i2d(X509 *x, int nid, void *value, int crit, unsigned long flags); @@ -923,9 +915,9 @@ int X509_CRL_get_ext_by_NID(const X509_CRL *x, int nid, int lastpos); int X509_CRL_get_ext_by_OBJ(const X509_CRL *x, const ASN1_OBJECT *obj, int lastpos); int X509_CRL_get_ext_by_critical(const X509_CRL *x, int crit, int lastpos); -const X509_EXTENSION *X509_CRL_get_ext(const X509_CRL *x, int loc); +X509_EXTENSION *X509_CRL_get_ext(const X509_CRL *x, int loc); X509_EXTENSION *X509_CRL_delete_ext(X509_CRL *x, int loc); -int X509_CRL_add_ext(X509_CRL *x, const X509_EXTENSION *ex, int loc); +int X509_CRL_add_ext(X509_CRL *x, X509_EXTENSION *ex, int loc); void *X509_CRL_get_ext_d2i(const X509_CRL *x, int nid, int *crit, int *idx); int X509_CRL_add1_ext_i2d(X509_CRL *x, int nid, void *value, int crit, unsigned long flags); @@ -936,7 +928,7 @@ int X509_REVOKED_get_ext_by_OBJ(const X509_REVOKED *x, const ASN1_OBJECT *obj, int lastpos); int X509_REVOKED_get_ext_by_critical(const X509_REVOKED *x, int crit, int lastpos); -const X509_EXTENSION *X509_REVOKED_get_ext(const X509_REVOKED *x, int loc); +X509_EXTENSION *X509_REVOKED_get_ext(const X509_REVOKED *x, int loc); X509_EXTENSION *X509_REVOKED_delete_ext(X509_REVOKED *x, int loc); int X509_REVOKED_add_ext(X509_REVOKED *x, X509_EXTENSION *ex, int loc); void *X509_REVOKED_get_ext_d2i(const X509_REVOKED *x, int nid, int *crit, @@ -952,9 +944,9 @@ X509_EXTENSION *X509_EXTENSION_create_by_OBJ(X509_EXTENSION **ex, ASN1_OCTET_STRING *data); int X509_EXTENSION_set_object(X509_EXTENSION *ex, const ASN1_OBJECT *obj); int X509_EXTENSION_set_critical(X509_EXTENSION *ex, int crit); -int X509_EXTENSION_set_data(X509_EXTENSION *ex, const ASN1_OCTET_STRING *data); -const ASN1_OBJECT *X509_EXTENSION_get_object(const X509_EXTENSION *ex); -const ASN1_OCTET_STRING *X509_EXTENSION_get_data(const X509_EXTENSION *ne); +int X509_EXTENSION_set_data(X509_EXTENSION *ex, ASN1_OCTET_STRING *data); +ASN1_OBJECT *X509_EXTENSION_get_object(X509_EXTENSION *ex); +ASN1_OCTET_STRING *X509_EXTENSION_get_data(X509_EXTENSION *ne); int X509_EXTENSION_get_critical(const X509_EXTENSION *ex); int X509at_get_attr_count(const STACK_OF(X509_ATTRIBUTE) *x); @@ -983,7 +975,7 @@ STACK_OF(X509_ATTRIBUTE) *X509at_add1_attr_by_txt(STACK_OF(X509_ATTRIBUTE) int type, const unsigned char *bytes, int len); -const void *X509at_get0_data_by_OBJ(const STACK_OF(X509_ATTRIBUTE) *x, +void *X509at_get0_data_by_OBJ(const STACK_OF(X509_ATTRIBUTE) *x, const ASN1_OBJECT *obj, int lastpos, int type); X509_ATTRIBUTE *X509_ATTRIBUTE_create_by_NID(X509_ATTRIBUTE **attr, int nid, int atrtype, const void *data, @@ -999,11 +991,11 @@ X509_ATTRIBUTE *X509_ATTRIBUTE_create_by_txt(X509_ATTRIBUTE **attr, int X509_ATTRIBUTE_set1_object(X509_ATTRIBUTE *attr, const ASN1_OBJECT *obj); int X509_ATTRIBUTE_set1_data(X509_ATTRIBUTE *attr, int attrtype, const void *data, int len); -const void *X509_ATTRIBUTE_get0_data(const X509_ATTRIBUTE *attr, int idx, - int atrtype, void *data); +void *X509_ATTRIBUTE_get0_data(X509_ATTRIBUTE *attr, int idx, int atrtype, + void *data); int X509_ATTRIBUTE_count(const X509_ATTRIBUTE *attr); -const ASN1_OBJECT *X509_ATTRIBUTE_get0_object(const X509_ATTRIBUTE *attr); -const ASN1_TYPE *X509_ATTRIBUTE_get0_type(const X509_ATTRIBUTE *attr, int idx); +ASN1_OBJECT *X509_ATTRIBUTE_get0_object(X509_ATTRIBUTE *attr); +ASN1_TYPE *X509_ATTRIBUTE_get0_type(X509_ATTRIBUTE *attr, int idx); int EVP_PKEY_get_attr_count(const EVP_PKEY *key); int EVP_PKEY_get_attr_by_NID(const EVP_PKEY *key, int nid, int lastpos); @@ -1023,9 +1015,9 @@ int EVP_PKEY_add1_attr_by_txt(EVP_PKEY *key, const unsigned char *bytes, int len); /* lookup a cert from a X509 STACK */ -X509 *X509_find_by_issuer_and_serial(const STACK_OF(X509) *sk, const X509_NAME *name, +X509 *X509_find_by_issuer_and_serial(STACK_OF(X509) *sk, const X509_NAME *name, const ASN1_INTEGER *serial); -X509 *X509_find_by_subject(const STACK_OF(X509) *sk, const X509_NAME *name); +X509 *X509_find_by_subject(STACK_OF(X509) *sk, const X509_NAME *name); DECLARE_ASN1_FUNCTIONS(PBEPARAM) DECLARE_ASN1_FUNCTIONS(PBE2PARAM) diff --git a/include/openssl/x509_acert.h.in b/include/openssl/x509_acert.h.in index d00b95c781..e136de04dc 100644 --- a/include/openssl/x509_acert.h.in +++ b/include/openssl/x509_acert.h.in @@ -23,10 +23,6 @@ use OpenSSL::stackhash qw(generate_stack_macros); #include #include -#ifdef __cplusplus -extern "C" { -#endif - typedef struct X509_acert_st X509_ACERT; typedef struct X509_acert_info_st X509_ACERT_INFO; typedef struct ossl_object_digest_info_st OSSL_OBJECT_DIGEST_INFO; @@ -210,8 +206,4 @@ DECLARE_ASN1_FUNCTIONS(OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX) -} /* clang-format on */ -#ifdef __cplusplus -} -#endif - #endif diff --git a/include/openssl/x509_vfy.h.in b/include/openssl/x509_vfy.h.in index e6d19ff14c..17faf310b1 100644 --- a/include/openssl/x509_vfy.h.in +++ b/include/openssl/x509_vfy.h.in @@ -1,7 +1,7 @@ /* * {- join("\n * ", @autowarntext) -} * - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -83,7 +83,7 @@ typedef enum { typedef struct x509_trust_st { int trust; int flags; - int (*check_trust)(struct x509_trust_st *, const X509 *, int); + int (*check_trust)(struct x509_trust_st *, X509 *, int); char *name; int arg1; void *arg2; @@ -127,7 +127,7 @@ int X509_TRUST_set(int *t, int trust); int X509_TRUST_get_count(void); X509_TRUST *X509_TRUST_get0(int idx); int X509_TRUST_get_by_id(int id); -int X509_TRUST_add(int id, int flags, int (*ck)(X509_TRUST *, const X509 *, int), +int X509_TRUST_add(int id, int flags, int (*ck)(X509_TRUST *, X509 *, int), const char *name, int arg1, void *arg2); void X509_TRUST_cleanup(void); int X509_TRUST_get_flags(const X509_TRUST *xp); @@ -139,16 +139,16 @@ int X509_add1_trust_object(X509 *x, const ASN1_OBJECT *obj); int X509_add1_reject_object(X509 *x, const ASN1_OBJECT *obj); void X509_trust_clear(X509 *x); void X509_reject_clear(X509 *x); -const STACK_OF(ASN1_OBJECT) *X509_get0_trust_objects(const X509 *x); -const STACK_OF(ASN1_OBJECT) *X509_get0_reject_objects(const X509 *x); +STACK_OF(ASN1_OBJECT) *X509_get0_trust_objects(const X509 *x); +STACK_OF(ASN1_OBJECT) *X509_get0_reject_objects(const X509 *x); -int (*X509_TRUST_set_default(int (*trust)(int, const X509 *, int)))(int, const X509 *, +int (*X509_TRUST_set_default(int (*trust)(int, X509 *, int)))(int, X509 *, int); -int X509_check_trust(const X509 *x, int id, int flags); +int X509_check_trust(X509 *x, int id, int flags); int X509_verify_cert(X509_STORE_CTX *ctx); int X509_STORE_CTX_verify(X509_STORE_CTX *ctx); -STACK_OF(X509) *X509_build_chain(const X509 *target, STACK_OF(X509) *certs, +STACK_OF(X509) *X509_build_chain(X509 *target, STACK_OF(X509) *certs, X509_STORE *store, int with_self_signed, OSSL_LIB_CTX *libctx, const char *propq); @@ -158,9 +158,9 @@ typedef int (*X509_STORE_CTX_verify_cb)(int, X509_STORE_CTX *); int X509_STORE_CTX_print_verify_cb(int ok, X509_STORE_CTX *ctx); typedef int (*X509_STORE_CTX_verify_fn)(X509_STORE_CTX *); typedef int (*X509_STORE_CTX_get_issuer_fn)(X509 **issuer, - X509_STORE_CTX *ctx, const X509 *x); + X509_STORE_CTX *ctx, X509 *x); typedef int (*X509_STORE_CTX_check_issued_fn)(X509_STORE_CTX *ctx, - const X509 *x, const X509 *issuer); + X509 *x, X509 *issuer); typedef int (*X509_STORE_CTX_check_revocation_fn)(X509_STORE_CTX *ctx); typedef int (*X509_STORE_CTX_get_crl_fn)(X509_STORE_CTX *ctx, X509_CRL **crl, X509 *x); @@ -169,7 +169,7 @@ typedef int (*X509_STORE_CTX_cert_crl_fn)(X509_STORE_CTX *ctx, X509_CRL *crl, X509 *x); typedef int (*X509_STORE_CTX_check_policy_fn)(X509_STORE_CTX *ctx); typedef STACK_OF(X509) - *(*X509_STORE_CTX_lookup_certs_fn)(const X509_STORE_CTX *ctx, + *(*X509_STORE_CTX_lookup_certs_fn)(X509_STORE_CTX *ctx, const X509_NAME *nm); typedef STACK_OF(X509_CRL) *(*X509_STORE_CTX_lookup_crls_fn)(const X509_STORE_CTX *ctx, @@ -333,12 +333,6 @@ void X509_STORE_CTX_set_depth(X509_STORE_CTX *ctx, int depth); #define X509_V_ERR_OCSP_NO_RESPONSE 100 #define X509_V_ERR_CRL_VERIFY_FAILED 101 -/* additional AKID errors */ -#define X509_V_ERR_EMPTY_AUTHORITY_KEY_IDENTIFIER 102 -#define X509_V_ERR_AKID_ISSUER_SERIAL_NOT_PAIRED 103 - -#define X509_V_ERR_DUPLICATE_EXTENSION 104 - /* Certificate verify flags */ #ifndef OPENSSL_NO_DEPRECATED_1_1_0 #define X509_V_FLAG_CB_ISSUER_CHECK 0x0 /* Deprecated */ @@ -433,7 +427,7 @@ STACK_OF(X509_OBJECT) *X509_STORE_get0_objects(const X509_STORE *xs); #endif STACK_OF(X509_OBJECT) *X509_STORE_get1_objects(X509_STORE *xs); STACK_OF(X509) *X509_STORE_get1_all_certs(X509_STORE *xs); -STACK_OF(X509) *X509_STORE_CTX_get1_certs(const X509_STORE_CTX *xs, +STACK_OF(X509) *X509_STORE_CTX_get1_certs(X509_STORE_CTX *xs, const X509_NAME *nm); STACK_OF(X509_CRL) *X509_STORE_CTX_get1_crls(const X509_STORE_CTX *st, const X509_NAME *nm); @@ -496,11 +490,11 @@ void *X509_STORE_get_ex_data(const X509_STORE *xs, int idx); X509_STORE_CTX *X509_STORE_CTX_new_ex(OSSL_LIB_CTX *libctx, const char *propq); X509_STORE_CTX *X509_STORE_CTX_new(void); -int X509_STORE_CTX_get1_issuer(X509 **issuer, X509_STORE_CTX *ctx, const X509 *x); +int X509_STORE_CTX_get1_issuer(X509 **issuer, X509_STORE_CTX *ctx, X509 *x); void X509_STORE_CTX_free(X509_STORE_CTX *ctx); int X509_STORE_CTX_init(X509_STORE_CTX *ctx, X509_STORE *trust_store, - const X509 *target, STACK_OF(X509) *untrusted); + X509 *target, STACK_OF(X509) *untrusted); int X509_STORE_CTX_init_rpk(X509_STORE_CTX *ctx, X509_STORE *trust_store, EVP_PKEY *rpk); void X509_STORE_CTX_set0_trusted_stack(X509_STORE_CTX *ctx, STACK_OF(X509) *sk); @@ -621,7 +615,7 @@ int X509_LOOKUP_meth_set_get_by_alias(X509_LOOKUP_METHOD *method, X509_LOOKUP_get_by_alias_fn X509_LOOKUP_meth_get_get_by_alias( const X509_LOOKUP_METHOD *method); -int X509_STORE_add_cert(X509_STORE *xs, const X509 *x); +int X509_STORE_add_cert(X509_STORE *xs, X509 *x); int X509_STORE_add_crl(X509_STORE *xs, X509_CRL *x); int X509_STORE_CTX_get_by_subject(const X509_STORE_CTX *vs, @@ -764,8 +758,6 @@ int X509_VERIFY_PARAM_set1_host(X509_VERIFY_PARAM *param, const char *name, size_t namelen); int X509_VERIFY_PARAM_add1_host(X509_VERIFY_PARAM *param, const char *name, size_t namelen); -void X509_VERIFY_PARAM_set1_host_input_validation(X509_VERIFY_PARAM *param, - int (*validate_host)(const char *name, size_t len)); void X509_VERIFY_PARAM_set_hostflags(X509_VERIFY_PARAM *param, unsigned int flags); unsigned int X509_VERIFY_PARAM_get_hostflags(const X509_VERIFY_PARAM *param); @@ -774,29 +766,11 @@ void X509_VERIFY_PARAM_move_peername(X509_VERIFY_PARAM *, X509_VERIFY_PARAM *); char *X509_VERIFY_PARAM_get0_email(X509_VERIFY_PARAM *param); int X509_VERIFY_PARAM_set1_email(X509_VERIFY_PARAM *param, const char *email, size_t emaillen); -int X509_VERIFY_PARAM_set1_rfc822(X509_VERIFY_PARAM *param, - const char *email, size_t emaillen); -int X509_VERIFY_PARAM_add1_rfc822(X509_VERIFY_PARAM *param, - const char *email, size_t len); -void X509_VERIFY_PARAM_set1_rfc822_input_validation(X509_VERIFY_PARAM *param, - int (*validate_rfc822)(const char *name, size_t len)); -int X509_VERIFY_PARAM_set1_smtputf8(X509_VERIFY_PARAM *param, - const char *email, size_t emaillen); -int X509_VERIFY_PARAM_add1_smtputf8(X509_VERIFY_PARAM *param, - const char *email, size_t len); -void X509_VERIFY_PARAM_set1_smtputf8_input_validation(X509_VERIFY_PARAM *param, - int (*validate_smtputf8)(const char *name, size_t len)); char *X509_VERIFY_PARAM_get1_ip_asc(X509_VERIFY_PARAM *param); int X509_VERIFY_PARAM_set1_ip(X509_VERIFY_PARAM *param, - const uint8_t *ip, size_t iplen); -void X509_VERIFY_PARAM_set1_ip_input_validation(X509_VERIFY_PARAM *param, - int (*validate_ip)(const uint8_t *name, size_t len)); + const unsigned char *ip, size_t iplen); int X509_VERIFY_PARAM_set1_ip_asc(X509_VERIFY_PARAM *param, const char *ipasc); -int X509_VERIFY_PARAM_add1_ip(X509_VERIFY_PARAM *param, - const uint8_t *ip, size_t len); -int X509_VERIFY_PARAM_add1_ip_asc(X509_VERIFY_PARAM *param, - const char *ipasc); int X509_VERIFY_PARAM_get_depth(const X509_VERIFY_PARAM *param); int X509_VERIFY_PARAM_get_auth_level(const X509_VERIFY_PARAM *param); diff --git a/include/openssl/x509err.h b/include/openssl/x509err.h index fa00e4143f..7123a725e8 100644 --- a/include/openssl/x509err.h +++ b/include/openssl/x509err.h @@ -1,6 +1,6 @@ /* * Generated by util/mkerr.pl DO NOT EDIT - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -27,7 +27,6 @@ #define X509_R_CERTIFICATE_VERIFICATION_FAILED 139 #define X509_R_CERT_ALREADY_IN_HASH_TABLE 101 #define X509_R_CRL_ALREADY_DELTA 127 -#define X509_R_CRL_SIGNATURE_ALGORITHM_MISMATCH 147 #define X509_R_CRL_VERIFY_FAILURE 131 #define X509_R_DUPLICATE_ATTRIBUTE 140 #define X509_R_ERROR_GETTING_MD_BY_NID 141 @@ -36,7 +35,6 @@ #define X509_R_INVALID_ATTRIBUTES 138 #define X509_R_INVALID_DIRECTORY 113 #define X509_R_INVALID_DISTPOINT 143 -#define X509_R_INVALID_EXTENSION 146 #define X509_R_INVALID_FIELD_NAME 119 #define X509_R_INVALID_TRUST 123 #define X509_R_ISSUER_MISMATCH 129 diff --git a/include/openssl/x509v3.h.in b/include/openssl/x509v3.h.in index 21def64b94..29231d22de 100644 --- a/include/openssl/x509v3.h.in +++ b/include/openssl/x509v3.h.in @@ -1,7 +1,7 @@ /* * {- join("\n * ", @autowarntext) -} * - * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -443,20 +443,11 @@ struct ISSUING_DIST_POINT_st { #define EXFLAG_FRESHEST 0x1000 #define EXFLAG_SS 0x2000 /* cert is apparently self-signed */ -#define EXFLAG_NO_FINGERPRINT 0x100000 - -/* - * The following flags are no longer used. On X509_V_FLAG_X509_STRICT they were - * previously enforced as checks on critical extensions but this behavior has - * been removed. - */ #define EXFLAG_BCONS_CRITICAL 0x10000 #define EXFLAG_AKID_CRITICAL 0x20000 #define EXFLAG_SKID_CRITICAL 0x40000 #define EXFLAG_SAN_CRITICAL 0x80000 - -/* A certificate MUST NOT include more than one instance of an extension. */ -#define EXFLAG_DUPLICATE 0x200000 +#define EXFLAG_NO_FINGERPRINT 0x100000 /* https://datatracker.ietf.org/doc/html/rfc5280#section-4.2.1.3 */ #define KU_DIGITAL_SIGNATURE X509v3_KU_DIGITAL_SIGNATURE @@ -630,8 +621,8 @@ DECLARE_ASN1_FUNCTIONS(ISSUING_DIST_POINT) int DIST_POINT_set_dpname(DIST_POINT_NAME *dpn, const X509_NAME *iname); -int NAME_CONSTRAINTS_check(const X509 *x, NAME_CONSTRAINTS *nc); -int NAME_CONSTRAINTS_check_CN(const X509 *x, NAME_CONSTRAINTS *nc); +int NAME_CONSTRAINTS_check(X509 *x, NAME_CONSTRAINTS *nc); +int NAME_CONSTRAINTS_check_CN(X509 *x, NAME_CONSTRAINTS *nc); DECLARE_ASN1_FUNCTIONS(ACCESS_DESCRIPTION) DECLARE_ASN1_FUNCTIONS(AUTHORITY_INFO_ACCESS) @@ -724,11 +715,11 @@ int X509V3_EXT_add_list(X509V3_EXT_METHOD *extlist); int X509V3_EXT_add_alias(int nid_to, int nid_from); void X509V3_EXT_cleanup(void); -const X509V3_EXT_METHOD *X509V3_EXT_get(const X509_EXTENSION *ext); +const X509V3_EXT_METHOD *X509V3_EXT_get(X509_EXTENSION *ext); const X509V3_EXT_METHOD *X509V3_EXT_get_nid(int nid); int X509V3_add_standard_extensions(void); STACK_OF(CONF_VALUE) *X509V3_parse_list(const char *line); -void *X509V3_EXT_d2i(const X509_EXTENSION *ext); +void *X509V3_EXT_d2i(X509_EXTENSION *ext); void *X509V3_get_d2i(const STACK_OF(X509_EXTENSION) *x, int nid, int *crit, int *idx); @@ -744,31 +735,31 @@ int X509V3_add1_i2d(STACK_OF(X509_EXTENSION) **x, int nid, void *value, void X509V3_EXT_val_prn(BIO *out, STACK_OF(CONF_VALUE) *val, int indent, int ml); -int X509V3_EXT_print(BIO *out, const X509_EXTENSION *ext, unsigned long flag, +int X509V3_EXT_print(BIO *out, X509_EXTENSION *ext, unsigned long flag, int indent); #ifndef OPENSSL_NO_STDIO -int X509V3_EXT_print_fp(FILE *out, const X509_EXTENSION *ext, int flag, int indent); +int X509V3_EXT_print_fp(FILE *out, X509_EXTENSION *ext, int flag, int indent); #endif int X509V3_extensions_print(BIO *out, const char *title, const STACK_OF(X509_EXTENSION) *exts, unsigned long flag, int indent); -int X509_check_ca(const X509 *x); -int X509_check_purpose(const X509 *x, int id, int ca); -int X509_supported_extension(const X509_EXTENSION *ex); -int X509_check_issued(const X509 *issuer, const X509 *subject); +int X509_check_ca(X509 *x); +int X509_check_purpose(X509 *x, int id, int ca); +int X509_supported_extension(X509_EXTENSION *ex); +int X509_check_issued(X509 *issuer, X509 *subject); int X509_check_akid(const X509 *issuer, const AUTHORITY_KEYID *akid); void X509_set_proxy_flag(X509 *x); void X509_set_proxy_pathlen(X509 *x, long l); -long X509_get_proxy_pathlen(const X509 *x); +long X509_get_proxy_pathlen(X509 *x); -uint32_t X509_get_extension_flags(const X509 *x); -uint32_t X509_get_key_usage(const X509 *x); -uint32_t X509_get_extended_key_usage(const X509 *x); -const ASN1_OCTET_STRING *X509_get0_subject_key_id(const X509 *x); -const ASN1_OCTET_STRING *X509_get0_authority_key_id(const X509 *x); -const GENERAL_NAMES *X509_get0_authority_issuer(const X509 *x); -const ASN1_INTEGER *X509_get0_authority_serial(const X509 *x); +uint32_t X509_get_extension_flags(X509 *x); +uint32_t X509_get_key_usage(X509 *x); +uint32_t X509_get_extended_key_usage(X509 *x); +const ASN1_OCTET_STRING *X509_get0_subject_key_id(X509 *x); +const ASN1_OCTET_STRING *X509_get0_authority_key_id(X509 *x); +const GENERAL_NAMES *X509_get0_authority_issuer(X509 *x); +const ASN1_INTEGER *X509_get0_authority_serial(X509 *x); int X509_PURPOSE_get_count(void); int X509_PURPOSE_get_unused_id(OSSL_LIB_CTX *libctx); @@ -786,10 +777,10 @@ char *X509_PURPOSE_get0_sname(const X509_PURPOSE *xp); int X509_PURPOSE_get_trust(const X509_PURPOSE *xp); int X509_PURPOSE_set(int *p, int purpose); -STACK_OF(OPENSSL_STRING) *X509_get1_email(const X509 *x); -STACK_OF(OPENSSL_STRING) *X509_REQ_get1_email(const X509_REQ *x); +STACK_OF(OPENSSL_STRING) *X509_get1_email(X509 *x); +STACK_OF(OPENSSL_STRING) *X509_REQ_get1_email(X509_REQ *x); void X509_email_free(STACK_OF(OPENSSL_STRING) *sk); -STACK_OF(OPENSSL_STRING) *X509_get1_ocsp(const X509 *x); +STACK_OF(OPENSSL_STRING) *X509_get1_ocsp(X509 *x); /* Flags for X509_check_* functions */ @@ -814,15 +805,13 @@ STACK_OF(OPENSSL_STRING) *X509_get1_ocsp(const X509 *x); */ #define _X509_CHECK_FLAG_DOT_SUBDOMAINS 0x8000 -#if !defined(OPENSSL_NO_DEPRECATED_4_1) -OSSL_DEPRECATEDIN_4_1 int X509_check_host(const X509 *x, const char *chk, size_t chklen, +int X509_check_host(X509 *x, const char *chk, size_t chklen, unsigned int flags, char **peername); -OSSL_DEPRECATEDIN_4_1 int X509_check_email(const X509 *x, const char *chk, size_t chklen, +int X509_check_email(X509 *x, const char *chk, size_t chklen, unsigned int flags); -OSSL_DEPRECATEDIN_4_1 int X509_check_ip(const X509 *x, const unsigned char *chk, size_t chklen, +int X509_check_ip(X509 *x, const unsigned char *chk, size_t chklen, unsigned int flags); -OSSL_DEPRECATEDIN_4_1 int X509_check_ip_asc(const X509 *x, const char *ipasc, unsigned int flags); -#endif /* !defined(OPENSSL_NO_DEPRECATED_4_1) */ +int X509_check_ip_asc(X509 *x, const char *ipasc, unsigned int flags); ASN1_OCTET_STRING *a2i_IPADDRESS(const char *ipasc); ASN1_OCTET_STRING *a2i_IPADDRESS_NC(const char *ipasc); @@ -933,7 +922,7 @@ DECLARE_ASN1_FUNCTIONS(IPAddressChoice) DECLARE_ASN1_FUNCTIONS(IPAddressFamily) /* - * API tag for elements of the ASIdentifier SEQUENCE. + * API tag for elements of the ASIdentifer SEQUENCE. */ #define V3_ASID_ASNUM 0 #define V3_ASID_RDI 1 @@ -956,17 +945,17 @@ int X509v3_asid_add_inherit(ASIdentifiers *asid, int which); int X509v3_asid_add_id_or_range(ASIdentifiers *asid, int which, ASN1_INTEGER *min, ASN1_INTEGER *max); int X509v3_addr_add_inherit(IPAddrBlocks *addr, - unsigned afi, const unsigned *safi); + const unsigned afi, const unsigned *safi); int X509v3_addr_add_prefix(IPAddrBlocks *addr, - unsigned afi, const unsigned *safi, + const unsigned afi, const unsigned *safi, unsigned char *a, const int prefixlen); int X509v3_addr_add_range(IPAddrBlocks *addr, - unsigned afi, const unsigned *safi, + const unsigned afi, const unsigned *safi, unsigned char *min, unsigned char *max); unsigned X509v3_addr_get_afi(const IPAddressFamily *f); -int X509v3_addr_get_range(IPAddressOrRange *aor, unsigned afi, +int X509v3_addr_get_range(IPAddressOrRange *aor, const unsigned afi, unsigned char *min, unsigned char *max, - int length); + const int length); /* * Canonical forms. @@ -989,10 +978,10 @@ int X509v3_addr_subset(IPAddrBlocks *a, IPAddrBlocks *b); */ int X509v3_asid_validate_path(X509_STORE_CTX *); int X509v3_addr_validate_path(X509_STORE_CTX *); -int X509v3_asid_validate_resource_set(const STACK_OF(X509) *chain, +int X509v3_asid_validate_resource_set(STACK_OF(X509) *chain, ASIdentifiers *ext, int allow_inheritance); -int X509v3_addr_validate_resource_set(const STACK_OF(X509) *chain, +int X509v3_addr_validate_resource_set(STACK_OF(X509) *chain, IPAddrBlocks *ext, int allow_inheritance); #endif /* OPENSSL_NO_RFC3779 */ diff --git a/ms/applink.c b/ms/applink.c index 242b0bed74..40aa946675 100644 --- a/ms/applink.c +++ b/ms/applink.c @@ -35,12 +35,6 @@ #ifndef APPMACROS_ONLY -#ifdef __GNUC__ -#pragma GCC diagnostic push -#pragma GCC diagnostic ignored "-Wpedantic" -#pragma GCC diagnostic ignored "-Wmissing-prototypes" -#endif - /* * Normally, do not define APPLINK_NO_INCLUDES. Define it if you are using * symbol preprocessing and do not want the preprocessing to affect the @@ -103,14 +97,6 @@ static int app_fsetmod(FILE *fp, char mod) extern "C" { #endif -/* - * The AppLink table exposes the legacy CRT signatures used by ms/uplink.h. - */ -#if defined(_MSC_VER) -#pragma warning(push) -#pragma warning(disable : 4996) -#endif - __declspec(dllexport) void ** #if defined(__BORLANDC__) /* @@ -159,14 +145,6 @@ __declspec(dllexport) void ** return OPENSSL_ApplinkTable; } -#if defined(_MSC_VER) -#pragma warning(pop) -#endif - -#ifdef __GNUC__ -#pragma GCC diagnostic pop -#endif - #ifdef __cplusplus } #endif diff --git a/ms/uplink-ia64.pl b/ms/uplink-ia64.pl new file mode 100755 index 0000000000..757e77d29f --- /dev/null +++ b/ms/uplink-ia64.pl @@ -0,0 +1,60 @@ +#! /usr/bin/env perl +# Copyright 2008-2016 The OpenSSL Project Authors. All Rights Reserved. +# +# Licensed under the Apache License 2.0 (the "License"). You may not use +# this file except in compliance with the License. You can obtain a copy +# in the file LICENSE in the source distribution or at +# https://www.openssl.org/source/license.html + +$output = pop and open STDOUT,">$output"; + +$0 =~ m/(.*[\/\\])[^\/\\]+$/; $dir=$1; +push(@INC,"${dir}."); + +require "uplink-common.pl"; + +local $V=8; # max number of args uplink functions may accept... +my $loc0 = "r".(32+$V); +print <<___; +.text +.global OPENSSL_Uplink# +.type OPENSSL_Uplink#,\@function + +___ +for ($i=1;$i<=$N;$i++) { +print <<___; +.proc lazy$i# +lazy$i: + .prologue +{ .mii; .save ar.pfs,$loc0 + alloc loc0=ar.pfs,$V,3,2,0 + .save b0,loc1 + mov loc1=b0 + addl loc2=\@ltoff(OPENSSL_UplinkTable#),gp };; + .body +{ .mmi; ld8 out0=[loc2] + mov out1=$i };; +{ .mib; add loc2=8*$i,out0 + br.call.sptk.many b0=OPENSSL_Uplink# };; +{ .mmi; ld8 r31=[loc2];; + ld8 r30=[r31],8 };; +{ .mii; ld8 gp=[r31] + mov b6=r30 + mov b0=loc1 };; +{ .mib; mov ar.pfs=loc0 + br.many b6 };; +.endp lazy$i# + +___ +} +print <<___; +.data +.global OPENSSL_UplinkTable# +OPENSSL_UplinkTable: data8 $N // amount of following entries +___ +for ($i=1;$i<=$N;$i++) { print " data8 \@fptr(lazy$i#)\n"; } +print <<___; +.size OPENSSL_UplinkTable,.-OPENSSL_UplinkTable# +___ + +close STDOUT; diff --git a/ms/uplink.c b/ms/uplink.c index c2d1bef80a..4fc52f4991 100644 --- a/ms/uplink.c +++ b/ms/uplink.c @@ -7,7 +7,7 @@ * https://www.openssl.org/source/license.html */ -#if defined(_WIN64) && !defined(UNICODE) +#if (defined(_WIN64) || defined(_WIN32_WCE)) && !defined(UNICODE) #define UNICODE #endif #if defined(UNICODE) && !defined(_UNICODE) @@ -17,19 +17,12 @@ #define UNICODE #endif -#ifdef __GNUC__ -#pragma GCC diagnostic ignored "-Wpedantic" -#pragma GCC diagnostic ignored "-Wcast-function-type" -#pragma GCC diagnostic ignored "-Wstrict-prototypes" -#endif - #include #include #include #include #include "uplink.h" void OPENSSL_showfatal(const char *, ...); -void OPENSSL_Uplink(volatile void **table, int index); static TCHAR msg[128]; @@ -80,6 +73,7 @@ void OPENSSL_Uplink(volatile void **table, int index) if (applinktable == NULL) { void **(*applink)(); + applink = (void **(*)())GetProcAddress(h, "OPENSSL_Applink"); if (applink == NULL) { apphandle = (HMODULE)-1; diff --git a/ms/uplink.h b/ms/uplink.h index 7e33f72df4..06825b68ad 100644 --- a/ms/uplink.h +++ b/ms/uplink.h @@ -12,27 +12,27 @@ extern void *OPENSSL_UplinkTable[]; -#define UP_stdin (*(void *(*)(void))(uintptr_t)OPENSSL_UplinkTable[APPLINK_STDIN])() -#define UP_stdout (*(void *(*)(void))(uintptr_t)OPENSSL_UplinkTable[APPLINK_STDOUT])() -#define UP_stderr (*(void *(*)(void))(uintptr_t)OPENSSL_UplinkTable[APPLINK_STDERR])() -#define UP_fprintf (*(int (*)(void *, const char *, ...))(uintptr_t)OPENSSL_UplinkTable[APPLINK_FPRINTF]) -#define UP_fgets (*(char *(*)(char *, int, void *))(uintptr_t)OPENSSL_UplinkTable[APPLINK_FGETS]) -#define UP_fread (*(size_t (*)(void *, size_t, size_t, void *))(uintptr_t)OPENSSL_UplinkTable[APPLINK_FREAD]) -#define UP_fwrite (*(size_t (*)(const void *, size_t, size_t, void *))(uintptr_t)OPENSSL_UplinkTable[APPLINK_FWRITE]) -#define UP_fsetmod (*(int (*)(void *, char))(uintptr_t)OPENSSL_UplinkTable[APPLINK_FSETMOD]) -#define UP_feof (*(int (*)(void *))(uintptr_t)OPENSSL_UplinkTable[APPLINK_FEOF]) -#define UP_fclose (*(int (*)(void *))(uintptr_t)OPENSSL_UplinkTable[APPLINK_FCLOSE]) +#define UP_stdin (*(void *(*)(void))OPENSSL_UplinkTable[APPLINK_STDIN])() +#define UP_stdout (*(void *(*)(void))OPENSSL_UplinkTable[APPLINK_STDOUT])() +#define UP_stderr (*(void *(*)(void))OPENSSL_UplinkTable[APPLINK_STDERR])() +#define UP_fprintf (*(int (*)(void *, const char *, ...))OPENSSL_UplinkTable[APPLINK_FPRINTF]) +#define UP_fgets (*(char *(*)(char *, int, void *))OPENSSL_UplinkTable[APPLINK_FGETS]) +#define UP_fread (*(size_t (*)(void *, size_t, size_t, void *))OPENSSL_UplinkTable[APPLINK_FREAD]) +#define UP_fwrite (*(size_t (*)(const void *, size_t, size_t, void *))OPENSSL_UplinkTable[APPLINK_FWRITE]) +#define UP_fsetmod (*(int (*)(void *, char))OPENSSL_UplinkTable[APPLINK_FSETMOD]) +#define UP_feof (*(int (*)(void *))OPENSSL_UplinkTable[APPLINK_FEOF]) +#define UP_fclose (*(int (*)(void *))OPENSSL_UplinkTable[APPLINK_FCLOSE]) -#define UP_fopen (*(void *(*)(const char *, const char *))(uintptr_t)OPENSSL_UplinkTable[APPLINK_FOPEN]) -#define UP_fseek (*(int (*)(void *, long, int))(uintptr_t)OPENSSL_UplinkTable[APPLINK_FSEEK]) -#define UP_ftell (*(long (*)(void *))(uintptr_t)OPENSSL_UplinkTable[APPLINK_FTELL]) -#define UP_fflush (*(int (*)(void *))(uintptr_t)OPENSSL_UplinkTable[APPLINK_FFLUSH]) -#define UP_ferror (*(int (*)(void *))(uintptr_t)OPENSSL_UplinkTable[APPLINK_FERROR]) -#define UP_clearerr (*(void (*)(void *))(uintptr_t)OPENSSL_UplinkTable[APPLINK_CLEARERR]) -#define UP_fileno (*(int (*)(void *))(uintptr_t)OPENSSL_UplinkTable[APPLINK_FILENO]) +#define UP_fopen (*(void *(*)(const char *, const char *))OPENSSL_UplinkTable[APPLINK_FOPEN]) +#define UP_fseek (*(int (*)(void *, long, int))OPENSSL_UplinkTable[APPLINK_FSEEK]) +#define UP_ftell (*(long (*)(void *))OPENSSL_UplinkTable[APPLINK_FTELL]) +#define UP_fflush (*(int (*)(void *))OPENSSL_UplinkTable[APPLINK_FFLUSH]) +#define UP_ferror (*(int (*)(void *))OPENSSL_UplinkTable[APPLINK_FERROR]) +#define UP_clearerr (*(void (*)(void *))OPENSSL_UplinkTable[APPLINK_CLEARERR]) +#define UP_fileno (*(int (*)(void *))OPENSSL_UplinkTable[APPLINK_FILENO]) -#define UP_open (*(int (*)(const char *, int, ...))(uintptr_t)OPENSSL_UplinkTable[APPLINK_OPEN]) -#define UP_read (*(ossl_ssize_t (*)(int, void *, size_t))(uintptr_t)OPENSSL_UplinkTable[APPLINK_READ]) -#define UP_write (*(ossl_ssize_t (*)(int, const void *, size_t))(uintptr_t)OPENSSL_UplinkTable[APPLINK_WRITE]) -#define UP_lseek (*(long (*)(int, long, int))(uintptr_t)OPENSSL_UplinkTable[APPLINK_LSEEK]) -#define UP_close (*(int (*)(int))(uintptr_t)OPENSSL_UplinkTable[APPLINK_CLOSE]) +#define UP_open (*(int (*)(const char *, int, ...))OPENSSL_UplinkTable[APPLINK_OPEN]) +#define UP_read (*(ossl_ssize_t (*)(int, void *, size_t))OPENSSL_UplinkTable[APPLINK_READ]) +#define UP_write (*(ossl_ssize_t (*)(int, const void *, size_t))OPENSSL_UplinkTable[APPLINK_WRITE]) +#define UP_lseek (*(long (*)(int, long, int))OPENSSL_UplinkTable[APPLINK_LSEEK]) +#define UP_close (*(int (*)(int))OPENSSL_UplinkTable[APPLINK_CLOSE]) diff --git a/oqs-provider b/oqs-provider index c5fb439e4f..7bc597c04b 160000 --- a/oqs-provider +++ b/oqs-provider @@ -1 +1 @@ -Subproject commit c5fb439e4ffd947f24c139232fb04fd71fe3c29e +Subproject commit 7bc597c04b534ddea9b6654481deb31ded8e1bbc diff --git a/pkcs11-provider b/pkcs11-provider index 5dcc876263..663dea335c 160000 --- a/pkcs11-provider +++ b/pkcs11-provider @@ -1 +1 @@ -Subproject commit 5dcc876263c083d44944d84e6425497529f8ff54 +Subproject commit 663dea335c80bec7fd96d544ff875af08d6461a9 diff --git a/providers/baseprov.c b/providers/baseprov.c index f517e5ae81..16d2f91bb1 100644 --- a/providers/baseprov.c +++ b/providers/baseprov.c @@ -29,6 +29,10 @@ static OSSL_FUNC_provider_gettable_params_fn base_gettable_params; static OSSL_FUNC_provider_get_params_fn base_get_params; static OSSL_FUNC_provider_query_operation_fn base_query; +/* Functions provided by the core */ +static OSSL_FUNC_core_gettable_params_fn *c_gettable_params = NULL; +static OSSL_FUNC_core_get_params_fn *c_get_params = NULL; + /* Parameters we provide to the core */ static const OSSL_PARAM base_param_types[] = { OSSL_PARAM_DEFN(OSSL_PROV_PARAM_NAME, OSSL_PARAM_UTF8_PTR, NULL, 0), @@ -135,13 +139,15 @@ int ossl_base_provider_init(const OSSL_CORE_HANDLE *handle, void **provctx) { OSSL_FUNC_core_get_libctx_fn *c_get_libctx = NULL; - OSSL_FUNC_core_get_params_fn *c_get_params = NULL; BIO_METHOD *corebiometh; if (!ossl_prov_bio_from_dispatch(in)) return 0; for (; in->function_id != 0; in++) { switch (in->function_id) { + case OSSL_FUNC_CORE_GETTABLE_PARAMS: + c_gettable_params = OSSL_FUNC_core_gettable_params(in); + break; case OSSL_FUNC_CORE_GET_PARAMS: c_get_params = OSSL_FUNC_core_get_params(in); break; diff --git a/providers/common/capabilities.c b/providers/common/capabilities.c index f461ec222a..eb96627a67 100644 --- a/providers/common/capabilities.c +++ b/providers/common/capabilities.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -16,7 +16,6 @@ #include #include "internal/nelem.h" #include "internal/tlsgroups.h" -#include "internal/tlssigalgs.h" #include "prov/providercommon.h" #include "internal/e_os.h" #include "crypto/ml_kem.h" @@ -92,8 +91,6 @@ static const TLS_GROUP_CONSTANTS group_list[] = { /* 41 */ { OSSL_TLS_GROUP_ID_X25519MLKEM768, ML_KEM_768_SECBITS, TLS1_3_VERSION, 0, -1, -1, 1 }, /* 42 */ { OSSL_TLS_GROUP_ID_SecP256r1MLKEM768, ML_KEM_768_SECBITS, TLS1_3_VERSION, 0, -1, -1, 1 }, /* 43 */ { OSSL_TLS_GROUP_ID_SecP384r1MLKEM1024, ML_KEM_1024_SECBITS, TLS1_3_VERSION, 0, -1, -1, 1 }, - /* 44 */ { OSSL_TLS_GROUP_ID_curveSM2, 128, TLS1_3_VERSION, 0, -1, -1, 0 }, - /* 45 */ { OSSL_TLS_GROUP_ID_curveSM2MLKEM768, ML_KEM_768_SECBITS, TLS1_3_VERSION, 0, -1, -1, 1 }, }; #define TLS_GROUP_ENTRY(tlsname, realname, algorithm, idx) \ @@ -190,12 +187,6 @@ static const OSSL_PARAM param_group_list[][11] = { TLS_GROUP_ENTRY("brainpoolP256r1tls13", "brainpoolP256r1", "EC", 30), TLS_GROUP_ENTRY("brainpoolP384r1tls13", "brainpoolP384r1", "EC", 31), TLS_GROUP_ENTRY("brainpoolP512r1tls13", "brainpoolP512r1", "EC", 32), -#ifndef OPENSSL_NO_SM2 - TLS_GROUP_ENTRY("curveSM2", "SM2", "curveSM2", 44), -#if !defined(OPENSSL_NO_ML_KEM) - TLS_GROUP_ENTRY("curveSM2MLKEM768", "", "curveSM2MLKEM768", 45), -#endif -#endif #endif #ifndef OPENSSL_NO_ML_KEM TLS_GROUP_ENTRY("SecP256r1MLKEM768", "", "SecP256r1MLKEM768", 42), @@ -281,8 +272,7 @@ static int tls_group_capability(OSSL_CALLBACK *cb, void *arg) /* --------------------------------------------------------------- */ -#if !defined(OPENSSL_NO_ML_DSA) || !defined(OPENSSL_NO_SLH_DSA) \ - || (!defined(FIPS_MODULE) && !defined(OPENSSL_NO_SM2) && !defined(OPENSSL_NO_SM3)) +#if !defined(OPENSSL_NO_ML_DSA) typedef struct tls_sigalg_constants_st { unsigned int code_point; @@ -293,23 +283,10 @@ typedef struct tls_sigalg_constants_st { int max_dtls; /* Maximum DTLS version (or 0 for undefined) */ } TLS_SIGALG_CONSTANTS; -static const TLS_SIGALG_CONSTANTS sigalg_constants_list[] = { - { TLSEXT_SIGALG_mldsa44, 128, TLS1_3_VERSION, 0, -1, -1 }, - { TLSEXT_SIGALG_mldsa65, 192, TLS1_3_VERSION, 0, -1, -1 }, - { TLSEXT_SIGALG_mldsa87, 256, TLS1_3_VERSION, 0, -1, -1 }, - { TLSEXT_SIGALG_slhdsa_sha2_128s, 128, TLS1_3_VERSION, 0, -1, -1 }, - { TLSEXT_SIGALG_slhdsa_sha2_128f, 128, TLS1_3_VERSION, 0, -1, -1 }, - { TLSEXT_SIGALG_slhdsa_sha2_192s, 192, TLS1_3_VERSION, 0, -1, -1 }, - { TLSEXT_SIGALG_slhdsa_sha2_192f, 192, TLS1_3_VERSION, 0, -1, -1 }, - { TLSEXT_SIGALG_slhdsa_sha2_256s, 256, TLS1_3_VERSION, 0, -1, -1 }, - { TLSEXT_SIGALG_slhdsa_sha2_256f, 256, TLS1_3_VERSION, 0, -1, -1 }, - { TLSEXT_SIGALG_slhdsa_shake_128s, 128, TLS1_3_VERSION, 0, -1, -1 }, - { TLSEXT_SIGALG_slhdsa_shake_128f, 128, TLS1_3_VERSION, 0, -1, -1 }, - { TLSEXT_SIGALG_slhdsa_shake_192s, 192, TLS1_3_VERSION, 0, -1, -1 }, - { TLSEXT_SIGALG_slhdsa_shake_192f, 192, TLS1_3_VERSION, 0, -1, -1 }, - { TLSEXT_SIGALG_slhdsa_shake_256s, 256, TLS1_3_VERSION, 0, -1, -1 }, - { TLSEXT_SIGALG_slhdsa_shake_256f, 256, TLS1_3_VERSION, 0, -1, -1 }, - { TLSEXT_SIGALG_sm2sig_sm3, 128, TLS1_3_VERSION, 0, -1, -1 }, +static const TLS_SIGALG_CONSTANTS sigalg_constants_list[3] = { + { 0x0904, 128, TLS1_3_VERSION, 0, -1, -1 }, + { 0x0905, 192, TLS1_3_VERSION, 0, -1, -1 }, + { 0x0906, 256, TLS1_3_VERSION, 0, -1, -1 }, }; #define TLS_SIGALG_ENTRY(tlsname, algorithm, oid, idx) \ @@ -336,34 +313,15 @@ static const TLS_SIGALG_CONSTANTS sigalg_constants_list[] = { } static const OSSL_PARAM param_sigalg_list[][10] = { -#ifndef OPENSSL_NO_ML_DSA TLS_SIGALG_ENTRY("mldsa44", "ML-DSA-44", "2.16.840.1.101.3.4.3.17", 0), TLS_SIGALG_ENTRY("mldsa65", "ML-DSA-65", "2.16.840.1.101.3.4.3.18", 1), TLS_SIGALG_ENTRY("mldsa87", "ML-DSA-87", "2.16.840.1.101.3.4.3.19", 2), -#endif -#ifndef OPENSSL_NO_SLH_DSA - TLS_SIGALG_ENTRY("slhdsa_sha2_128s", "SLH-DSA-SHA2-128s", "2.16.840.1.101.3.4.3.20", 3), - TLS_SIGALG_ENTRY("slhdsa_sha2_128f", "SLH-DSA-SHA2-128f", "2.16.840.1.101.3.4.3.21", 4), - TLS_SIGALG_ENTRY("slhdsa_sha2_192s", "SLH-DSA-SHA2-192s", "2.16.840.1.101.3.4.3.22", 5), - TLS_SIGALG_ENTRY("slhdsa_sha2_192f", "SLH-DSA-SHA2-192f", "2.16.840.1.101.3.4.3.23", 6), - TLS_SIGALG_ENTRY("slhdsa_sha2_256s", "SLH-DSA-SHA2-256s", "2.16.840.1.101.3.4.3.24", 7), - TLS_SIGALG_ENTRY("slhdsa_sha2_256f", "SLH-DSA-SHA2-256f", "2.16.840.1.101.3.4.3.25", 8), - TLS_SIGALG_ENTRY("slhdsa_shake_128s", "SLH-DSA-SHAKE-128s", "2.16.840.1.101.3.4.3.26", 9), - TLS_SIGALG_ENTRY("slhdsa_shake_128f", "SLH-DSA-SHAKE-128f", "2.16.840.1.101.3.4.3.27", 10), - TLS_SIGALG_ENTRY("slhdsa_shake_192s", "SLH-DSA-SHAKE-192s", "2.16.840.1.101.3.4.3.28", 11), - TLS_SIGALG_ENTRY("slhdsa_shake_192f", "SLH-DSA-SHAKE-192f", "2.16.840.1.101.3.4.3.29", 12), - TLS_SIGALG_ENTRY("slhdsa_shake_256s", "SLH-DSA-SHAKE-256s", "2.16.840.1.101.3.4.3.30", 13), - TLS_SIGALG_ENTRY("slhdsa_shake_256f", "SLH-DSA-SHAKE-256f", "2.16.840.1.101.3.4.3.31", 14), -#endif -#if !defined(FIPS_MODULE) && !defined(OPENSSL_NO_SM2) && !defined(OPENSSL_NO_SM3) - TLS_SIGALG_ENTRY("sm2sig_sm3", "SM2", "1.2.156.10197.1 501", 15), -#endif }; -#endif +#endif /* OPENSSL_NO_ML_DSA */ static int tls_sigalg_capability(OSSL_CALLBACK *cb, void *arg) { -#if defined(TLS_SIGALG_ENTRY) +#if !defined(OPENSSL_NO_ML_DSA) size_t i; for (i = 0; i < OSSL_NELEM(param_sigalg_list); i++) diff --git a/providers/common/der/build.info b/providers/common/der/build.info index efa34700d1..a24a8c3635 100644 --- a/providers/common/der/build.info +++ b/providers/common/der/build.info @@ -81,7 +81,7 @@ IF[{- !$disabled{'ml-dsa'} -}] DEPEND[$DER_ML_DSA_GEN]=oids_to_c.pm ML_DSA.asn1 DEPEND[${DER_ML_DSA_GEN/.c/.o}]=$DER_ML_DSA_H - DEPEND[${DER_ML_DSA_AUX/.c/.o}]=$DER_ML_DSA_H $DER_DIGESTS_H + DEPEND[${DER_ML_DSA_AUX/.c/.o}]=$DER_ML_DSA_H GENERATE[$DER_ML_DSA_H]=$INCDIR/der_ml_dsa.h.in DEPEND[$DER_ML_DSA_H]=oids_to_c.pm ML_DSA.asn1 ENDIF diff --git a/providers/common/der/der_ml_dsa_key.c b/providers/common/der/der_ml_dsa_key.c index e2d55a6d1d..a042f634e7 100644 --- a/providers/common/der/der_ml_dsa_key.c +++ b/providers/common/der/der_ml_dsa_key.c @@ -1,5 +1,5 @@ /* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -12,67 +12,30 @@ * internal use. */ #include "internal/deprecated.h" -#include -#include + #include "internal/packet.h" #include "prov/der_ml_dsa.h" -#include "prov/der_pq_dsa.h" -#include "prov/der_digests.h" - -#define SET_OID(oid, oidlen, oidname) \ - (oid) = ossl_der_oid_id_##oidname; \ - (oidlen) = sizeof(ossl_der_oid_id_##oidname) - -#define SET_DIGEST_OID(oidname, digestsz) \ - SET_OID(*oid, *oidlen, oidname); \ - *sz = digestsz int ossl_DER_w_algorithmIdentifier_ML_DSA(WPACKET *pkt, int tag, ML_DSA_KEY *key) { - const uint8_t *oid; - size_t oidlen; + const uint8_t *alg; + size_t len; const char *name = ossl_ml_dsa_key_get_name(key); if (OPENSSL_strcasecmp(name, "ML-DSA-44") == 0) { - SET_OID(oid, oidlen, ml_dsa_44); + alg = ossl_der_oid_id_ml_dsa_44; + len = sizeof(ossl_der_oid_id_ml_dsa_44); } else if (OPENSSL_strcasecmp(name, "ML-DSA-65") == 0) { - SET_OID(oid, oidlen, ml_dsa_65); + alg = ossl_der_oid_id_ml_dsa_65; + len = sizeof(ossl_der_oid_id_ml_dsa_65); } else if (OPENSSL_strcasecmp(name, "ML-DSA-87") == 0) { - SET_OID(oid, oidlen, ml_dsa_87); + alg = ossl_der_oid_id_ml_dsa_87; + len = sizeof(ossl_der_oid_id_ml_dsa_87); } else { return 0; } return ossl_DER_w_begin_sequence(pkt, tag) /* No parameters */ - && ossl_DER_w_precompiled(pkt, -1, oid, oidlen) + && ossl_DER_w_precompiled(pkt, -1, alg, len) && ossl_DER_w_end_sequence(pkt, tag); } - -int ossl_der_oid_pq_dsa_prehash_digest(const char *oid_digest_name, - const uint8_t **oid, size_t *oidlen, size_t *sz) -{ - if (OPENSSL_strcasecmp(oid_digest_name, "SHAKE-256") == 0) { - SET_DIGEST_OID(shake256, 64); - } else if (OPENSSL_strcasecmp(oid_digest_name, "SHAKE-128") == 0) { - SET_DIGEST_OID(shake128, 32); - } else if (OPENSSL_strcasecmp(oid_digest_name, "SHA-224") == 0) { - SET_DIGEST_OID(sha224, 28); - } else if (OPENSSL_strcasecmp(oid_digest_name, "SHA-256") == 0) { - SET_DIGEST_OID(sha256, 32); - } else if (OPENSSL_strcasecmp(oid_digest_name, "SHA-384") == 0) { - SET_DIGEST_OID(sha384, 48); - } else if (OPENSSL_strcasecmp(oid_digest_name, "SHA-512") == 0) { - SET_DIGEST_OID(sha512, 64); - } else if (OPENSSL_strcasecmp(oid_digest_name, "SHA3-224") == 0) { - SET_DIGEST_OID(sha3_224, 28); - } else if (OPENSSL_strcasecmp(oid_digest_name, "SHA3-256") == 0) { - SET_DIGEST_OID(sha3_256, 32); - } else if (OPENSSL_strcasecmp(oid_digest_name, "SHA3-384") == 0) { - SET_DIGEST_OID(sha3_384, 48); - } else if (OPENSSL_strcasecmp(oid_digest_name, "SHA3-512") == 0) { - SET_DIGEST_OID(sha3_512, 64); - } else { - return 0; - } - return 1; -} diff --git a/providers/common/der/oids_to_c.pm b/providers/common/der/oids_to_c.pm index c5137065a3..6f57df09b9 100644 --- a/providers/common/der/oids_to_c.pm +++ b/providers/common/der/oids_to_c.pm @@ -80,7 +80,7 @@ sub _process { # print STDERR "-----BEGIN DEBUG-----\n"; # print STDERR $text; # print STDERR "-----END DEBUG-----\n"; - use re 'debug'; + use re 'debugcolor'; while ($text =~ m/${OID_def_re}/sg) { my $comment = $&; my $name = $1; diff --git a/providers/common/include/prov/bio.h b/providers/common/include/prov/bio.h index 72fe6b0d7a..2441995248 100644 --- a/providers/common/include/prov/bio.h +++ b/providers/common/include/prov/bio.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_COMMON_INCLUDE_PROV_BIO_H) -#define OSSL_PROVIDERS_COMMON_INCLUDE_PROV_BIO_H - #include #include #include @@ -33,5 +30,3 @@ int ossl_prov_bio_printf(OSSL_CORE_BIO *bio, const char *format, ...); BIO_METHOD *ossl_bio_prov_init_bio_method(void); BIO *ossl_bio_new_from_core_bio(PROV_CTX *provctx, OSSL_CORE_BIO *corebio); - -#endif /* !defined(OSSL_PROVIDERS_COMMON_INCLUDE_PROV_BIO_H) */ diff --git a/providers/common/include/prov/der_pq_dsa.h b/providers/common/include/prov/der_pq_dsa.h deleted file mode 100644 index 1ac4d80bf5..0000000000 --- a/providers/common/include/prov/der_pq_dsa.h +++ /dev/null @@ -1,19 +0,0 @@ -/* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#if !defined(OSSL_PROVIDERS_COMMON_INCLUDE_PROV_DER_PQ_DSA_H) -#define OSSL_PROVIDERS_COMMON_INCLUDE_PROV_DER_PQ_DSA_H - -#include -#include - -int ossl_der_oid_pq_dsa_prehash_digest(const char *oid_digest_name, - const uint8_t **oid, size_t *oidlen, size_t *sz); - -#endif /* !defined(OSSL_PROVIDERS_COMMON_INCLUDE_PROV_DER_PQ_DSA_H) */ diff --git a/providers/common/include/prov/proverr.h b/providers/common/include/prov/proverr.h index 573bb212eb..a2829caed0 100644 --- a/providers/common/include/prov/proverr.h +++ b/providers/common/include/prov/proverr.h @@ -1,6 +1,6 @@ /* * Generated by util/mkerr.pl DO NOT EDIT - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy diff --git a/providers/common/include/prov/provider_util.h b/providers/common/include/prov/provider_util.h index 1072fb1ad0..814eb4acfd 100644 --- a/providers/common/include/prov/provider_util.h +++ b/providers/common/include/prov/provider_util.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_COMMON_INCLUDE_PROV_PROVIDER_UTIL_H) -#define OSSL_PROVIDERS_COMMON_INCLUDE_PROV_PROVIDER_UTIL_H - #include #include @@ -112,5 +109,3 @@ void ossl_prov_cache_exported_algorithms(const OSSL_ALGORITHM_CAPABLE *in, /* Duplicate a lump of memory safely */ int ossl_prov_memdup(const void *src, size_t src_len, unsigned char **dest, size_t *dest_len); - -#endif /* !defined(OSSL_PROVIDERS_COMMON_INCLUDE_PROV_PROVIDER_UTIL_H) */ diff --git a/providers/common/include/prov/providercommon.h b/providers/common/include/prov/providercommon.h index e470a49d69..f29182a2c1 100644 --- a/providers/common/include/prov/providercommon.h +++ b/providers/common/include/prov/providercommon.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_COMMON_INCLUDE_PROV_PROVIDERCOMMON_H) -#define OSSL_PROVIDERS_COMMON_INCLUDE_PROV_PROVIDERCOMMON_H - #include #include @@ -33,5 +30,3 @@ static ossl_inline int ossl_param_is_empty(const OSSL_PARAM params[]) { return params == NULL || params->key == NULL; } - -#endif /* !defined(OSSL_PROVIDERS_COMMON_INCLUDE_PROV_PROVIDERCOMMON_H) */ diff --git a/providers/common/include/prov/securitycheck.h b/providers/common/include/prov/securitycheck.h index e36c77c218..29a2b7fbf8 100644 --- a/providers/common/include/prov/securitycheck.h +++ b/providers/common/include/prov/securitycheck.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_COMMON_INCLUDE_PROV_SECURITYCHECK_H) -#define OSSL_PROVIDERS_COMMON_INCLUDE_PROV_SECURITYCHECK_H - #include "crypto/types.h" #include @@ -39,5 +36,4 @@ int ossl_digest_get_approved_nid(const EVP_MD *md); /* Functions that have different implementations for the FIPS_MODULE */ int ossl_digest_rsa_sign_get_md_nid(const EVP_MD *md); - -#endif /* !defined(OSSL_PROVIDERS_COMMON_INCLUDE_PROV_SECURITYCHECK_H) */ +int ossl_fips_config_securitycheck_enabled(OSSL_LIB_CTX *libctx); diff --git a/providers/common/provider_err.c b/providers/common/provider_err.c index 33e7edb454..6cdb728333 100644 --- a/providers/common/provider_err.c +++ b/providers/common/provider_err.c @@ -1,6 +1,6 @@ /* * Generated by util/mkerr.pl DO NOT EDIT - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -78,7 +78,6 @@ static const ERR_STRING_DATA PROV_str_reasons[] = { "insufficient drbg strength" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_AAD), "invalid aad" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_AEAD), "invalid aead" }, - { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_CIPHER), "invalid cipher" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_CONFIG_DATA), "invalid config data" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_CONSTANT_LENGTH), @@ -94,41 +93,29 @@ static const ERR_STRING_DATA PROV_str_reasons[] = { "invalid digest size" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_EDDSA_INSTANCE_FOR_ATTEMPTED_OPERATION), "invalid eddsa instance for attempted operation" }, - { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_FUNCTION_NAME), - "invalid function name" }, - { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_INDEX_LENGTH), - "invalid index length" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_INPUT_LENGTH), "invalid input length" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_ITERATION_COUNT), "invalid iteration count" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_IV_LENGTH), "invalid iv length" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_KDF), "invalid kdf" }, - { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_KDR), "invalid kdr" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_KEY), "invalid key" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_KEY_LENGTH), "invalid key length" }, - { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_LABEL), "invalid label" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_MAC), "invalid mac" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_MEMORY_SIZE), "invalid memory size" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_MGF1_MD), "invalid mgf1 md" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_MODE), "invalid mode" }, - { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_NONCE_LENGTH), - "invalid nonce length" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_OUTPUT_LENGTH), "invalid output length" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_PADDING_MODE), "invalid padding mode" }, - { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_PARAMETERS_FOR_DKM), - "invalid parameters for dkm" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_PREHASHED_DIGEST_LENGTH), "invalid prehashed digest length" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_PUBINFO), "invalid pubinfo" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_SALT_LENGTH), "invalid salt length" }, - { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_SECRET_LENGTH), - "invalid secret length" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_SEED_LENGTH), "invalid seed length" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_SIGNATURE_SIZE), @@ -144,8 +131,6 @@ static const ERR_STRING_DATA PROV_str_reasons[] = { { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_INVALID_X931_DIGEST), "invalid x931 digest" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_IN_ERROR_STATE), "in error state" }, - { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_KEY_IMMUTABLE_ONCE_SET), - "key immutable once set" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_KEY_SETUP_FAILED), "key setup failed" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_KEY_SIZE_TOO_SMALL), "key size too small" }, @@ -157,13 +142,11 @@ static const ERR_STRING_DATA PROV_str_reasons[] = { { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_MISSING_CONFIG_DATA), "missing config data" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_MISSING_CONSTANT), "missing constant" }, - { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_MISSING_DKM), "missing dkm" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_MISSING_EID), "missing eid" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_MISSING_KEY), "missing key" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_MISSING_MAC), "missing mac" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_MISSING_MESSAGE_DIGEST), "missing message digest" }, - { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_MISSING_NONCE), "missing nonce" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_MISSING_OID), "missing OID" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_MISSING_PASS), "missing pass" }, { ERR_PACK(ERR_LIB_PROV, 0, PROV_R_MISSING_SALT), "missing salt" }, diff --git a/providers/common/provider_util.c b/providers/common/provider_util.c index e66b101a35..6cf5e5634a 100644 --- a/providers/common/provider_util.c +++ b/providers/common/provider_util.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -58,8 +58,23 @@ int ossl_prov_cipher_load(PROV_CIPHER *pc, const OSSL_PARAM *cipher, return 0; EVP_CIPHER_free(pc->alloc_cipher); + ERR_set_mark(); pc->cipher = pc->alloc_cipher = EVP_CIPHER_fetch(ctx, cipher->data, propquery); +#ifndef FIPS_MODULE /* Inside the FIPS module, we don't support legacy ciphers */ + if (pc->cipher == NULL) { + const EVP_CIPHER *evp_cipher; + + evp_cipher = EVP_get_cipherbyname(cipher->data); + /* Do not use global EVP_CIPHERs */ + if (evp_cipher != NULL && evp_cipher->origin != EVP_ORIG_GLOBAL) + pc->cipher = evp_cipher; + } +#endif + if (pc->cipher != NULL) + ERR_pop_to_mark(); + else + ERR_clear_last_mark(); return pc->cipher != NULL; } @@ -106,7 +121,22 @@ int ossl_prov_digest_load(PROV_DIGEST *pd, const OSSL_PARAM *digest, if (digest->data_type != OSSL_PARAM_UTF8_STRING) return 0; + ERR_set_mark(); ossl_prov_digest_fetch(pd, ctx, digest->data, propquery); +#ifndef FIPS_MODULE /* Inside the FIPS module, we don't support legacy digests */ + if (pd->md == NULL) { + const EVP_MD *md; + + md = EVP_get_digestbyname(digest->data); + /* Do not use global EVP_MDs */ + if (md != NULL && md->origin != EVP_ORIG_GLOBAL) + pd->md = md; + } +#endif + if (pd->md != NULL) + ERR_pop_to_mark(); + else + ERR_clear_last_mark(); return pd->md != NULL; } diff --git a/providers/common/securitycheck_default.c b/providers/common/securitycheck_default.c index ca8f0b497d..42823ffe14 100644 --- a/providers/common/securitycheck_default.c +++ b/providers/common/securitycheck_default.c @@ -16,6 +16,12 @@ #include "prov/securitycheck.h" #include "internal/nelem.h" +/* Disable the security checks in the default provider */ +int ossl_fips_config_securitycheck_enabled(OSSL_LIB_CTX *libctx) +{ + return 0; +} + int ossl_digest_rsa_sign_get_md_nid(const EVP_MD *md) { int mdnid; diff --git a/providers/common/securitycheck_fips.c b/providers/common/securitycheck_fips.c index aa9136ef09..a83320b72b 100644 --- a/providers/common/securitycheck_fips.c +++ b/providers/common/securitycheck_fips.c @@ -19,6 +19,15 @@ #include #include "prov/securitycheck.h" +int ossl_fips_config_securitycheck_enabled(OSSL_LIB_CTX *libctx) +{ +#if !defined(OPENSSL_NO_FIPS_SECURITYCHECKS) + return ossl_fips_config_security_checks(libctx); +#else + return 0; +#endif /* OPENSSL_NO_FIPS_SECURITYCHECKS */ +} + int ossl_digest_rsa_sign_get_md_nid(const EVP_MD *md) { return ossl_digest_get_approved_nid(md); @@ -32,7 +41,7 @@ int ossl_fips_ind_rsa_key_check(OSSL_FIPS_IND *ind, int id, if (!key_approved) { if (!ossl_FIPS_IND_on_unapproved(ind, id, libctx, desc, "Key size", - FIPS_CONFIG_SECURITY_CHECKS)) { + ossl_fips_config_securitycheck_enabled)) { ERR_raise_data(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH, "operation: %s", desc); return 0; @@ -57,7 +66,7 @@ int ossl_fips_ind_ec_key_check(OSSL_FIPS_IND *ind, int id, if (!strength_allowed || !curve_allowed) { if (!ossl_FIPS_IND_on_unapproved(ind, id, libctx, desc, "EC Key", - FIPS_CONFIG_SECURITY_CHECKS)) { + ossl_fips_config_securitycheck_enabled)) { if (!curve_allowed) ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_CURVE); if (!strength_allowed) @@ -78,7 +87,7 @@ int ossl_fips_ind_digest_exch_check(OSSL_FIPS_IND *ind, int id, if (!approved) { if (!ossl_FIPS_IND_on_unapproved(ind, id, libctx, desc, "Digest", - FIPS_CONFIG_SECURITY_CHECKS)) { + ossl_fips_config_securitycheck_enabled)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_DIGEST); return 0; } @@ -91,7 +100,7 @@ int ossl_fips_ind_digest_sign_check(OSSL_FIPS_IND *ind, int id, int nid, int sha1_allowed, int sha512_trunc_allowed, const char *desc, - enum fips_config_id config_id) + OSSL_FIPS_IND_CHECK_CB *config_check_f) { int approved; const char *op = "none"; @@ -115,7 +124,8 @@ int ossl_fips_ind_digest_sign_check(OSSL_FIPS_IND *ind, int id, } if (!approved) { - if (!ossl_FIPS_IND_on_unapproved(ind, id, libctx, desc, op, config_id)) { + if (!ossl_FIPS_IND_on_unapproved(ind, id, libctx, desc, op, + config_check_f)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_DIGEST); return 0; } diff --git a/providers/decoders.inc b/providers/decoders.inc index 767df65997..eab36ba65c 100644 --- a/providers/decoders.inc +++ b/providers/decoders.inc @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -25,117 +25,111 @@ #define DECODER_STRUCTURE_RSA "rsa" /* Arguments are prefixed with '_' to avoid build breaks on certain platforms */ -#define DECODER(_name, _input, _output, _fips, desc) \ +#define DECODER(_name, _input, _output, _fips) \ { _name, \ "provider=" DECODER_PROVIDER ",fips=" #_fips ",input=" #_input, \ - (ossl_##_input##_to_##_output##_decoder_functions), desc } -#define DECODER_w_structure(_name, _input, _structure, _output, _fips, desc) \ + (ossl_##_input##_to_##_output##_decoder_functions) } +#define DECODER_w_structure(_name, _input, _structure, _output, _fips) \ { _name, \ "provider=" DECODER_PROVIDER ",fips=" #_fips ",input=" #_input \ ",structure=" DECODER_STRUCTURE_##_structure, \ - (ossl_##_structure##_##_input##_to_##_output##_decoder_functions),\ - desc } + (ossl_##_structure##_##_input##_to_##_output##_decoder_functions) } #ifndef OPENSSL_NO_DH -DECODER_w_structure("DH", der, PrivateKeyInfo, dh, yes, "PKItoDH-DER"), -DECODER_w_structure("DH", der, SubjectPublicKeyInfo, dh, yes, "SPKItoDH-DER"), -DECODER_w_structure("DH", der, type_specific_params, dh, yes, "TStoDH-DER"), -DECODER_w_structure("DH", der, DH, dh, yes, "DERtoDH"), -DECODER_w_structure("DHX", der, PrivateKeyInfo, dhx, yes,"PKItoDHX-DER"), -DECODER_w_structure("DHX", der, SubjectPublicKeyInfo, dhx, yes, "SPKItoDHX-DER"), -DECODER_w_structure("DHX", der, type_specific_params, dhx, yes, "TStoDHX-DER"), -DECODER_w_structure("DHX", der, DHX, dhx, yes, "DERtoDHX"), +DECODER_w_structure("DH", der, PrivateKeyInfo, dh, yes), +DECODER_w_structure("DH", der, SubjectPublicKeyInfo, dh, yes), +DECODER_w_structure("DH", der, type_specific_params, dh, yes), +DECODER_w_structure("DH", der, DH, dh, yes), +DECODER_w_structure("DHX", der, PrivateKeyInfo, dhx, yes), +DECODER_w_structure("DHX", der, SubjectPublicKeyInfo, dhx, yes), +DECODER_w_structure("DHX", der, type_specific_params, dhx, yes), +DECODER_w_structure("DHX", der, DHX, dhx, yes), #endif #ifndef OPENSSL_NO_DSA -DECODER_w_structure("DSA", der, PrivateKeyInfo, dsa, yes, "PKItoDSA-DER"), -DECODER_w_structure("DSA", der, SubjectPublicKeyInfo, dsa, yes, "SPKItoDSA-DER"), -DECODER_w_structure("DSA", der, type_specific, dsa, yes, "TStoDSA-DER"), -DECODER_w_structure("DSA", der, DSA, dsa, yes, "DERtoDSA"), -DECODER("DSA", msblob, dsa, yes, "MSBLOBtoDSA"), -DECODER("DSA", pvk, dsa, yes, "PVKtoDSA"), +DECODER_w_structure("DSA", der, PrivateKeyInfo, dsa, yes), +DECODER_w_structure("DSA", der, SubjectPublicKeyInfo, dsa, yes), +DECODER_w_structure("DSA", der, type_specific, dsa, yes), +DECODER_w_structure("DSA", der, DSA, dsa, yes), +DECODER("DSA", msblob, dsa, yes), +DECODER("DSA", pvk, dsa, yes), #endif #ifndef OPENSSL_NO_EC -DECODER_w_structure("EC", der, PrivateKeyInfo, ec, yes, "PKItoEC-DER"), -DECODER_w_structure("EC", der, SubjectPublicKeyInfo, ec, yes, "SPKItoEC-DER"), -DECODER_w_structure("EC", der, type_specific_no_pub, ec, yes, "TStoEC-DER"), -DECODER_w_structure("EC", der, EC, ec, yes, "DERtoEC"), +DECODER_w_structure("EC", der, PrivateKeyInfo, ec, yes), +DECODER_w_structure("EC", der, SubjectPublicKeyInfo, ec, yes), +DECODER_w_structure("EC", der, type_specific_no_pub, ec, yes), +DECODER_w_structure("EC", der, EC, ec, yes), # ifndef OPENSSL_NO_ECX -DECODER_w_structure("ED25519", der, PrivateKeyInfo, ed25519, yes, "PKItoED25519-DER"), -DECODER_w_structure("ED25519", der, SubjectPublicKeyInfo, ed25519, yes, "SPKItoED25519-DER"), -DECODER_w_structure("ED448", der, PrivateKeyInfo, ed448, yes, "PKItoED448-DER"), -DECODER_w_structure("ED448", der, SubjectPublicKeyInfo, ed448, yes, "SPKItoED448-DER"), -DECODER_w_structure("X25519", der, PrivateKeyInfo, x25519, yes, "PKItoX25519-DER"), -DECODER_w_structure("X25519", der, SubjectPublicKeyInfo, x25519, yes, "SPKItoX25519-DER"), -DECODER_w_structure("X448", der, PrivateKeyInfo, x448, yes, "PKItoX448-DER"), -DECODER_w_structure("X448", der, SubjectPublicKeyInfo, x448, yes, "SPKItoX448-DER"), +DECODER_w_structure("ED25519", der, PrivateKeyInfo, ed25519, yes), +DECODER_w_structure("ED25519", der, SubjectPublicKeyInfo, ed25519, yes), +DECODER_w_structure("ED448", der, PrivateKeyInfo, ed448, yes), +DECODER_w_structure("ED448", der, SubjectPublicKeyInfo, ed448, yes), +DECODER_w_structure("X25519", der, PrivateKeyInfo, x25519, yes), +DECODER_w_structure("X25519", der, SubjectPublicKeyInfo, x25519, yes), +DECODER_w_structure("X448", der, PrivateKeyInfo, x448, yes), +DECODER_w_structure("X448", der, SubjectPublicKeyInfo, x448, yes), # endif # ifndef OPENSSL_NO_SM2 -DECODER_w_structure("SM2", der, PrivateKeyInfo, sm2, no, "PKItoSM2-DER"), -DECODER_w_structure("SM2", der, SubjectPublicKeyInfo, sm2, no, "SPKItoSM2-DER"), -DECODER_w_structure("SM2", der, type_specific_no_pub, sm2, no, "TStoSM2-DER"), +DECODER_w_structure("SM2", der, PrivateKeyInfo, sm2, no), +DECODER_w_structure("SM2", der, SubjectPublicKeyInfo, sm2, no), +DECODER_w_structure("SM2", der, type_specific_no_pub, sm2, no), # endif #endif #ifndef OPENSSL_NO_ML_KEM -DECODER_w_structure("ML-KEM-512", der, PrivateKeyInfo, ml_kem_512, yes, "PKItoML-KEM-512-DER"), -DECODER_w_structure("ML-KEM-512", der, SubjectPublicKeyInfo, ml_kem_512, yes, "SPKItoML-KEM-512-DER"), -DECODER_w_structure("ML-KEM-768", der, PrivateKeyInfo, ml_kem_768, yes, "PKItoML-KEM-768-DER"), -DECODER_w_structure("ML-KEM-768", der, SubjectPublicKeyInfo, ml_kem_768, yes, "SPKItoML-KEM-768-DER"), -DECODER_w_structure("ML-KEM-1024", der, PrivateKeyInfo, ml_kem_1024, yes, "PKItoML-KEM-1024-DER"), -DECODER_w_structure("ML-KEM-1024", der, SubjectPublicKeyInfo, ml_kem_1024, yes, "SPKItoML-KEM-1024-DER"), +DECODER_w_structure("ML-KEM-512", der, PrivateKeyInfo, ml_kem_512, yes), +DECODER_w_structure("ML-KEM-512", der, SubjectPublicKeyInfo, ml_kem_512, yes), +DECODER_w_structure("ML-KEM-768", der, PrivateKeyInfo, ml_kem_768, yes), +DECODER_w_structure("ML-KEM-768", der, SubjectPublicKeyInfo, ml_kem_768, yes), +DECODER_w_structure("ML-KEM-1024", der, PrivateKeyInfo, ml_kem_1024, yes), +DECODER_w_structure("ML-KEM-1024", der, SubjectPublicKeyInfo, ml_kem_1024, yes), #endif #ifndef OPENSSL_NO_SLH_DSA -DECODER_w_structure( "SLH-DSA-SHA2-128s", der, PrivateKeyInfo, slh_dsa_sha2_128s, yes, "PKItoSLH-DSA-SHA2-128s"), -DECODER_w_structure( "SLH-DSA-SHA2-128f", der, PrivateKeyInfo, slh_dsa_sha2_128f, yes, "PKItoSLH-DSA-SHA2-128f"), -DECODER_w_structure( "SLH-DSA-SHA2-192s", der, PrivateKeyInfo, slh_dsa_sha2_192s, yes, "PKItoSLH-DSA-SHA2-192s"), -DECODER_w_structure( "SLH-DSA-SHA2-192f", der, PrivateKeyInfo, slh_dsa_sha2_192f, yes, "PKItoSLH-DSA-SHA2-192f"), -DECODER_w_structure( "SLH-DSA-SHA2-256s", der, PrivateKeyInfo, slh_dsa_sha2_256s, yes, "PKItoSLH-DSA-SHA2-256s"), -DECODER_w_structure( "SLH-DSA-SHA2-256f", der, PrivateKeyInfo, slh_dsa_sha2_256f, yes, "PKItoSLH-DSA-SHA2-256f"), -DECODER_w_structure("SLH-DSA-SHAKE-128s", der, PrivateKeyInfo, slh_dsa_shake_128s, yes, "PKItoSLH-DSA-SHAKE-128s"), -DECODER_w_structure("SLH-DSA-SHAKE-128f", der, PrivateKeyInfo, slh_dsa_shake_128f, yes, "PKItoSLH-DSA-SHAKE-128f"), -DECODER_w_structure("SLH-DSA-SHAKE-192s", der, PrivateKeyInfo, slh_dsa_shake_192s, yes, "PKItoSLH-DSA-SHAKE-192s"), -DECODER_w_structure("SLH-DSA-SHAKE-192f", der, PrivateKeyInfo, slh_dsa_shake_192f, yes, "PKItoSLH-DSA-SHAKE-192f"), -DECODER_w_structure("SLH-DSA-SHAKE-256s", der, PrivateKeyInfo, slh_dsa_shake_256s, yes, "PKItoSLH-DSA-SHAKE-256s"), -DECODER_w_structure("SLH-DSA-SHAKE-256f", der, PrivateKeyInfo, slh_dsa_shake_256f, yes, "PKItoSLH-DSA-SHAKE-256f"), -DECODER_w_structure( "SLH-DSA-SHA2-128s", der, SubjectPublicKeyInfo, slh_dsa_sha2_128s, yes, "SPKItoSLH-DSA-SHA2-128s"), -DECODER_w_structure( "SLH-DSA-SHA2-128f", der, SubjectPublicKeyInfo, slh_dsa_sha2_128f, yes, "SPKItoSLH-DSA-SHA2-128f"), -DECODER_w_structure( "SLH-DSA-SHA2-192s", der, SubjectPublicKeyInfo, slh_dsa_sha2_192s, yes, "SPKItoSLH-DSA-SHA2-192s"), -DECODER_w_structure( "SLH-DSA-SHA2-192f", der, SubjectPublicKeyInfo, slh_dsa_sha2_192f, yes, "SPKItoSLH-DSA-SHA2-192f"), -DECODER_w_structure( "SLH-DSA-SHA2-256s", der, SubjectPublicKeyInfo, slh_dsa_sha2_256s, yes, "SPKItoSLH-DSA-SHA2-256s"), -DECODER_w_structure( "SLH-DSA-SHA2-256f", der, SubjectPublicKeyInfo, slh_dsa_sha2_256f, yes, "SPKItoSLH-DSA-SHA2-256f"), -DECODER_w_structure("SLH-DSA-SHAKE-128s", der, SubjectPublicKeyInfo, slh_dsa_shake_128s, yes, "SPKItoSLH-DSA-SHAKE-128s"), -DECODER_w_structure("SLH-DSA-SHAKE-128f", der, SubjectPublicKeyInfo, slh_dsa_shake_128f, yes, "SPKItoSLH-DSA-SHAKE-128f"), -DECODER_w_structure("SLH-DSA-SHAKE-192s", der, SubjectPublicKeyInfo, slh_dsa_shake_192s, yes, "SPKItoSLH-DSA-SHAKE-192s"), -DECODER_w_structure("SLH-DSA-SHAKE-192f", der, SubjectPublicKeyInfo, slh_dsa_shake_192f, yes, "SPKItoSLH-DSA-SHAKE-192f"), -DECODER_w_structure("SLH-DSA-SHAKE-256s", der, SubjectPublicKeyInfo, slh_dsa_shake_256s, yes, "SPKItoSLH-DSA-SHAKE-256s"), -DECODER_w_structure("SLH-DSA-SHAKE-256f", der, SubjectPublicKeyInfo, slh_dsa_shake_256f, yes, "SPKItoSLH-DSA-SHAKE-256f"), +DECODER_w_structure( "SLH-DSA-SHA2-128s", der, PrivateKeyInfo, slh_dsa_sha2_128s, yes), +DECODER_w_structure( "SLH-DSA-SHA2-128f", der, PrivateKeyInfo, slh_dsa_sha2_128f, yes), +DECODER_w_structure( "SLH-DSA-SHA2-192s", der, PrivateKeyInfo, slh_dsa_sha2_192s, yes), +DECODER_w_structure( "SLH-DSA-SHA2-192f", der, PrivateKeyInfo, slh_dsa_sha2_192f, yes), +DECODER_w_structure( "SLH-DSA-SHA2-256s", der, PrivateKeyInfo, slh_dsa_sha2_256s, yes), +DECODER_w_structure( "SLH-DSA-SHA2-256f", der, PrivateKeyInfo, slh_dsa_sha2_256f, yes), +DECODER_w_structure("SLH-DSA-SHAKE-128s", der, PrivateKeyInfo, slh_dsa_shake_128s, yes), +DECODER_w_structure("SLH-DSA-SHAKE-128f", der, PrivateKeyInfo, slh_dsa_shake_128f, yes), +DECODER_w_structure("SLH-DSA-SHAKE-192s", der, PrivateKeyInfo, slh_dsa_shake_192s, yes), +DECODER_w_structure("SLH-DSA-SHAKE-192f", der, PrivateKeyInfo, slh_dsa_shake_192f, yes), +DECODER_w_structure("SLH-DSA-SHAKE-256s", der, PrivateKeyInfo, slh_dsa_shake_256s, yes), +DECODER_w_structure("SLH-DSA-SHAKE-256f", der, PrivateKeyInfo, slh_dsa_shake_256f, yes), +DECODER_w_structure( "SLH-DSA-SHA2-128s", der, SubjectPublicKeyInfo, slh_dsa_sha2_128s, yes), +DECODER_w_structure( "SLH-DSA-SHA2-128f", der, SubjectPublicKeyInfo, slh_dsa_sha2_128f, yes), +DECODER_w_structure( "SLH-DSA-SHA2-192s", der, SubjectPublicKeyInfo, slh_dsa_sha2_192s, yes), +DECODER_w_structure( "SLH-DSA-SHA2-192f", der, SubjectPublicKeyInfo, slh_dsa_sha2_192f, yes), +DECODER_w_structure( "SLH-DSA-SHA2-256s", der, SubjectPublicKeyInfo, slh_dsa_sha2_256s, yes), +DECODER_w_structure( "SLH-DSA-SHA2-256f", der, SubjectPublicKeyInfo, slh_dsa_sha2_256f, yes), +DECODER_w_structure("SLH-DSA-SHAKE-128s", der, SubjectPublicKeyInfo, slh_dsa_shake_128s, yes), +DECODER_w_structure("SLH-DSA-SHAKE-128f", der, SubjectPublicKeyInfo, slh_dsa_shake_128f, yes), +DECODER_w_structure("SLH-DSA-SHAKE-192s", der, SubjectPublicKeyInfo, slh_dsa_shake_192s, yes), +DECODER_w_structure("SLH-DSA-SHAKE-192f", der, SubjectPublicKeyInfo, slh_dsa_shake_192f, yes), +DECODER_w_structure("SLH-DSA-SHAKE-256s", der, SubjectPublicKeyInfo, slh_dsa_shake_256s, yes), +DECODER_w_structure("SLH-DSA-SHAKE-256f", der, SubjectPublicKeyInfo, slh_dsa_shake_256f, yes), #endif /* OPENSSL_NO_SLH_DSA */ -DECODER_w_structure("RSA", der, PrivateKeyInfo, rsa, yes, "PKItoRSA-DER"), -DECODER_w_structure("RSA", der, SubjectPublicKeyInfo, rsa, yes, "SPKItoRSA-DER"), -DECODER_w_structure("RSA", der, type_specific_keypair, rsa, yes, "TStoKEYPAIRtoRSA-DER"), -DECODER_w_structure("RSA", der, RSA, rsa, yes, "DERtoRSA"), -DECODER_w_structure("RSA-PSS", der, PrivateKeyInfo, rsapss, yes, "PKItoRSA-PSS-DER"), -DECODER_w_structure("RSA-PSS", der, SubjectPublicKeyInfo, rsapss, yes, "SPKItoRSA-PSS-DER"), -DECODER("RSA", msblob, rsa, yes, "MSBLOBtoRSA"), -DECODER("RSA", pvk, rsa, yes, "PVKtoRSA"), +DECODER_w_structure("RSA", der, PrivateKeyInfo, rsa, yes), +DECODER_w_structure("RSA", der, SubjectPublicKeyInfo, rsa, yes), +DECODER_w_structure("RSA", der, type_specific_keypair, rsa, yes), +DECODER_w_structure("RSA", der, RSA, rsa, yes), +DECODER_w_structure("RSA-PSS", der, PrivateKeyInfo, rsapss, yes), +DECODER_w_structure("RSA-PSS", der, SubjectPublicKeyInfo, rsapss, yes), +DECODER("RSA", msblob, rsa, yes), +DECODER("RSA", pvk, rsa, yes), #ifndef OPENSSL_NO_ML_DSA -DECODER_w_structure("ML-DSA-44", der, PrivateKeyInfo, ml_dsa_44, yes, "PKItoML-DSA-44-DER"), -DECODER_w_structure("ML-DSA-65", der, PrivateKeyInfo, ml_dsa_65, yes, "PKItoML-DSA-65-DER"), -DECODER_w_structure("ML-DSA-87", der, PrivateKeyInfo, ml_dsa_87, yes, "PKItoML-DSA-87-DER"), -DECODER_w_structure("ML-DSA-44", der, SubjectPublicKeyInfo, ml_dsa_44, yes, "SPKItoML-DSA-44-DER"), -DECODER_w_structure("ML-DSA-65", der, SubjectPublicKeyInfo, ml_dsa_65, yes, "SPKItoML-DSA-65-DER"), -DECODER_w_structure("ML-DSA-87", der, SubjectPublicKeyInfo, ml_dsa_87, yes, "SPKItoML-DSA-87-DER"), +DECODER_w_structure("ML-DSA-44", der, PrivateKeyInfo, ml_dsa_44, yes), +DECODER_w_structure("ML-DSA-65", der, PrivateKeyInfo, ml_dsa_65, yes), +DECODER_w_structure("ML-DSA-87", der, PrivateKeyInfo, ml_dsa_87, yes), +DECODER_w_structure("ML-DSA-44", der, SubjectPublicKeyInfo, ml_dsa_44, yes), +DECODER_w_structure("ML-DSA-65", der, SubjectPublicKeyInfo, ml_dsa_65, yes), +DECODER_w_structure("ML-DSA-87", der, SubjectPublicKeyInfo, ml_dsa_87, yes), #endif /* OPENSSL_NO_ML_DSA */ -#ifndef OPENSSL_NO_LMS -DECODER("LMS", xdr, lms, yes, "XDRtoLMS"), -DECODER_w_structure("LMS", der, SubjectPublicKeyInfo, lms, yes, "SPKItoLMS-DER"), -#endif - /* * A decoder that takes a SubjectPublicKeyInfo and figures out the types of key * that it contains. The output is the same SubjectPublicKeyInfo. */ -DECODER_w_structure("DER", der, SubjectPublicKeyInfo, der, yes, "SPKItoDER"), +DECODER_w_structure("DER", der, SubjectPublicKeyInfo, der, yes), /* * General-purpose PEM to DER decoder. When the user-specified data structure * is a possibly encrypted PKCS#8 PrivateKeyInfo or a SubjectPublicKeyInfo @@ -144,10 +138,14 @@ DECODER_w_structure("DER", der, SubjectPublicKeyInfo, der, yes, "SPKItoDER"), * algorithm name or OID, and delegates further decoding in DER form to the * identified algorithm. */ -DECODER("DER", pem, der, yes, "PEMtoDER"), +DECODER("DER", pem, der, yes), /* * A decoder that recognises PKCS#8 EncryptedPrivateKeyInfo structure and * decrypts it, obtaining the algorithm name or OID, and delegates the * unencrypted PrivateKeyInfo in DER form to the identified algorithm. */ -DECODER_w_structure("DER", der, EncryptedPrivateKeyInfo, der, yes, "EPKItoDER"), +DECODER_w_structure("DER", der, EncryptedPrivateKeyInfo, der, yes), + +#ifndef OPENSSL_NO_LMS +DECODER("LMS", xdr, lms, yes), +#endif diff --git a/providers/defltprov.c b/providers/defltprov.c index 1f39b34d6e..50397f2189 100644 --- a/providers/defltprov.c +++ b/providers/defltprov.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -34,6 +34,10 @@ static OSSL_FUNC_provider_query_operation_fn deflt_query; #define ALGC(NAMES, FUNC, CHECK) { { NAMES, "provider=default", FUNC }, CHECK } #define ALG(NAMES, FUNC) ALGC(NAMES, FUNC, NULL) +/* Functions provided by the core */ +static OSSL_FUNC_core_gettable_params_fn *c_gettable_params = NULL; +static OSSL_FUNC_core_get_params_fn *c_get_params = NULL; + /* Parameters we provide to the core */ static const OSSL_PARAM deflt_param_types[] = { OSSL_PARAM_DEFN(OSSL_PROV_PARAM_NAME, OSSL_PARAM_UTF8_PTR, NULL, 0), @@ -120,18 +124,15 @@ static const OSSL_ALGORITHM deflt_digests[] = { * KECCAK-KMAC-128 and KECCAK-KMAC-256 as hashes are mostly useful for * the KMAC-128 and KMAC-256. */ - { PROV_NAMES_CSHAKE_KECCAK_128, "provider=default", - ossl_cshake_keccak_128_functions }, - { PROV_NAMES_CSHAKE_KECCAK_256, "provider=default", - ossl_cshake_keccak_256_functions }, + { PROV_NAMES_KECCAK_KMAC_128, "provider=default", + ossl_keccak_kmac_128_functions }, + { PROV_NAMES_KECCAK_KMAC_256, "provider=default", + ossl_keccak_kmac_256_functions }, /* Our primary name:NIST name */ { PROV_NAMES_SHAKE_128, "provider=default", ossl_shake_128_functions }, { PROV_NAMES_SHAKE_256, "provider=default", ossl_shake_256_functions }, - { PROV_NAMES_CSHAKE_128, "provider=default", ossl_cshake_128_functions }, - { PROV_NAMES_CSHAKE_256, "provider=default", ossl_cshake_256_functions }, - #ifndef OPENSSL_NO_BLAKE2 /* * https://blake2.net/ doesn't specify size variants, @@ -158,9 +159,6 @@ static const OSSL_ALGORITHM deflt_digests[] = { #endif /* OPENSSL_NO_RMD160 */ { PROV_NAMES_NULL, "provider=default", ossl_nullmd_functions }, -#ifndef OPENSSL_NO_ML_DSA - { PROV_NAMES_ML_DSA_MU, "provider=default", ossl_ml_dsa_mu_functions }, -#endif { NULL, NULL, NULL } }; @@ -365,43 +363,21 @@ static const OSSL_ALGORITHM deflt_kdfs[] = { { PROV_NAMES_HKDF_SHA512, "provider=default", ossl_kdf_hkdf_sha512_functions }, { PROV_NAMES_TLS1_3_KDF, "provider=default", ossl_kdf_tls1_3_kdf_functions }, - { PROV_NAMES_TLS1_PRF, "provider=default", ossl_kdf_tls1_prf_functions }, + { PROV_NAMES_SSKDF, "provider=default", ossl_kdf_sskdf_functions }, { PROV_NAMES_PBKDF2, "provider=default", ossl_kdf_pbkdf2_functions }, { PROV_NAMES_PKCS12KDF, "provider=default", ossl_kdf_pkcs12_functions }, -#ifndef OPENSSL_NO_IKEV2KDF - { PROV_NAMES_IKEV2KDF, "provider=default", ossl_kdf_ikev2kdf_functions }, -#endif -#ifndef OPENSSL_NO_SSKDF - { PROV_NAMES_SSKDF, "provider=default", ossl_kdf_sskdf_functions }, -#endif -#ifndef OPENSSL_NO_SNMPKDF { PROV_NAMES_SNMPKDF, "provider=default", ossl_kdf_snmpkdf_functions }, -#endif -#ifndef OPENSSL_NO_SRTPKDF - { PROV_NAMES_SRTPKDF, "provider=default", ossl_kdf_srtpkdf_functions }, -#endif -#ifndef OPENSSL_NO_SSHKDF { PROV_NAMES_SSHKDF, "provider=default", ossl_kdf_sshkdf_functions }, -#endif -#ifndef OPENSSL_NO_X963KDF { PROV_NAMES_X963KDF, "provider=default", ossl_kdf_x963_kdf_functions }, -#endif -#ifndef OPENSSL_NO_KBKDF + { PROV_NAMES_TLS1_PRF, "provider=default", ossl_kdf_tls1_prf_functions }, { PROV_NAMES_KBKDF, "provider=default", ossl_kdf_kbkdf_functions }, -#endif -#ifndef OPENSSL_NO_X942KDF { PROV_NAMES_X942KDF_ASN1, "provider=default", ossl_kdf_x942_kdf_functions }, -#endif #ifndef OPENSSL_NO_SCRYPT { PROV_NAMES_SCRYPT, "provider=default", ossl_kdf_scrypt_functions }, #endif -#ifndef OPENSSL_NO_KRB5KDF { PROV_NAMES_KRB5KDF, "provider=default", ossl_kdf_krb5kdf_functions }, -#endif -#ifndef OPENSSL_NO_HMAC_DRBG_KDF { PROV_NAMES_HMAC_DRBG_KDF, "provider=default", ossl_kdf_hmac_drbg_functions }, -#endif #ifndef OPENSSL_NO_ARGON2 { PROV_NAMES_ARGON2I, "provider=default", ossl_kdf_argon2i_functions }, { PROV_NAMES_ARGON2D, "provider=default", ossl_kdf_argon2d_functions }, @@ -423,10 +399,8 @@ static const OSSL_ALGORITHM deflt_keyexch[] = { #endif { PROV_NAMES_TLS1_PRF, "provider=default", ossl_kdf_tls1_prf_keyexch_functions }, { PROV_NAMES_HKDF, "provider=default", ossl_kdf_hkdf_keyexch_functions }, -#ifndef OPENSSL_NO_SCRYPT { PROV_NAMES_SCRYPT, "provider=default", ossl_kdf_scrypt_keyexch_functions }, -#endif { NULL, NULL, NULL } }; @@ -501,10 +475,8 @@ static const OSSL_ALGORITHM deflt_signature[] = { { PROV_NAMES_ML_DSA_87, "provider=default", ossl_ml_dsa_87_signature_functions }, #endif { PROV_NAMES_HMAC, "provider=default", ossl_mac_legacy_hmac_signature_functions }, -#ifndef OPENSSL_NO_SIPHASH { PROV_NAMES_SIPHASH, "provider=default", ossl_mac_legacy_siphash_signature_functions }, -#endif #ifndef OPENSSL_NO_POLY1305 { PROV_NAMES_POLY1305, "provider=default", ossl_mac_legacy_poly1305_signature_functions }, @@ -566,15 +538,12 @@ static const OSSL_ALGORITHM deflt_asym_kem[] = { { PROV_NAMES_ML_KEM_768, "provider=default", ossl_ml_kem_asym_kem_functions }, { PROV_NAMES_ML_KEM_1024, "provider=default", ossl_ml_kem_asym_kem_functions }, #if !defined(OPENSSL_NO_ECX) - { PROV_NAMES_X25519MLKEM768, "provider=default", ossl_mlx_kem_asym_kem_functions }, - { PROV_NAMES_X448MLKEM1024, "provider=default", ossl_mlx_kem_asym_kem_functions }, + { "X25519MLKEM768", "provider=default", ossl_mlx_kem_asym_kem_functions }, + { "X448MLKEM1024", "provider=default", ossl_mlx_kem_asym_kem_functions }, #endif #if !defined(OPENSSL_NO_EC) - { PROV_NAMES_SecP256r1MLKEM768, "provider=default", ossl_mlx_kem_asym_kem_functions }, - { PROV_NAMES_SecP384r1MLKEM1024, "provider=default", ossl_mlx_kem_asym_kem_functions }, -#endif -#if !defined(OPENSSL_NO_SM2) - { PROV_NAMES_curveSM2MLKEM768, "provider=default", ossl_mlx_kem_asym_kem_functions }, + { "SecP256r1MLKEM768", "provider=default", ossl_mlx_kem_asym_kem_functions }, + { "SecP384r1MLKEM1024", "provider=default", ossl_mlx_kem_asym_kem_functions }, #endif #endif { NULL, NULL, NULL } @@ -621,16 +590,12 @@ static const OSSL_ALGORITHM deflt_keymgmt[] = { PROV_DESCS_TLS1_PRF_SIGN }, { PROV_NAMES_HKDF, "provider=default", ossl_kdf_keymgmt_functions, PROV_DESCS_HKDF_SIGN }, -#ifndef OPENSSL_NO_SCRYPT { PROV_NAMES_SCRYPT, "provider=default", ossl_kdf_keymgmt_functions, PROV_DESCS_SCRYPT_SIGN }, -#endif { PROV_NAMES_HMAC, "provider=default", ossl_mac_legacy_keymgmt_functions, PROV_DESCS_HMAC_SIGN }, -#ifndef OPENSSL_NO_SIPHASH { PROV_NAMES_SIPHASH, "provider=default", ossl_mac_legacy_keymgmt_functions, PROV_DESCS_SIPHASH_SIGN }, -#endif #ifndef OPENSSL_NO_POLY1305 { PROV_NAMES_POLY1305, "provider=default", ossl_mac_legacy_keymgmt_functions, PROV_DESCS_POLY1305_SIGN }, @@ -642,8 +607,6 @@ static const OSSL_ALGORITHM deflt_keymgmt[] = { #ifndef OPENSSL_NO_SM2 { PROV_NAMES_SM2, "provider=default", ossl_sm2_keymgmt_functions, PROV_DESCS_SM2 }, - { PROV_NAMES_curveSM2, "provider=default", ossl_curve_sm2_keymgmt_functions, - PROV_DESCS_curveSM2 }, #endif #ifndef OPENSSL_NO_LMS { PROV_NAMES_LMS, "provider=default", ossl_lms_keymgmt_functions, @@ -668,10 +631,6 @@ static const OSSL_ALGORITHM deflt_keymgmt[] = { { PROV_NAMES_SecP384r1MLKEM1024, "provider=default", ossl_mlx_p384_kem_kmgmt_functions, PROV_DESCS_SecP384r1MLKEM1024 }, #endif -#if !defined(OPENSSL_NO_SM2) - { PROV_NAMES_curveSM2MLKEM768, "provider=default", ossl_mlx_curve_sm2_kem_kmgmt_functions, - PROV_DESCS_curveSM2MLKEM768 }, -#endif #endif #ifndef OPENSSL_NO_SLH_DSA { PROV_NAMES_SLH_DSA_SHA2_128S, "provider=default", ossl_slh_dsa_sha2_128s_keymgmt_functions, @@ -795,7 +754,6 @@ int ossl_default_provider_init(const OSSL_CORE_HANDLE *handle, void **provctx) { OSSL_FUNC_core_get_libctx_fn *c_get_libctx = NULL; - OSSL_FUNC_core_get_params_fn *c_get_params = NULL; BIO_METHOD *corebiometh; if (!ossl_prov_bio_from_dispatch(in) @@ -803,6 +761,9 @@ int ossl_default_provider_init(const OSSL_CORE_HANDLE *handle, return 0; for (; in->function_id != 0; in++) { switch (in->function_id) { + case OSSL_FUNC_CORE_GETTABLE_PARAMS: + c_gettable_params = OSSL_FUNC_core_gettable_params(in); + break; case OSSL_FUNC_CORE_GET_PARAMS: c_get_params = OSSL_FUNC_core_get_params(in); break; diff --git a/providers/encoders.inc b/providers/encoders.inc index 1ab0d3a75d..5257536d7d 100644 --- a/providers/encoders.inc +++ b/providers/encoders.inc @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -91,9 +91,6 @@ ENCODER_TEXT("SLH-DSA-SHAKE-192f", slh_dsa_shake_192f, yes), ENCODER_TEXT("SLH-DSA-SHAKE-256s", slh_dsa_shake_256s, yes), ENCODER_TEXT("SLH-DSA-SHAKE-256f", slh_dsa_shake_256f, yes), #endif -#ifndef OPENSSL_NO_LMS -ENCODER_TEXT("LMS", lms, yes), -#endif /* * Entries for key type specific output formats. The structure name on these @@ -425,8 +422,3 @@ ENCODER_w_structure("DHX", dhx, yes, pem, X9_42), ENCODER_w_structure("EC", ec, yes, der, X9_62), ENCODER_w_structure("EC", ec, yes, pem, X9_62), #endif - -#ifndef OPENSSL_NO_LMS -ENCODER_w_structure("LMS", lms, yes, der, SubjectPublicKeyInfo), -ENCODER_w_structure("LMS", lms, yes, pem, SubjectPublicKeyInfo), -#endif /* OPENSSL_NO_LMS */ diff --git a/providers/fips-sources.checksums b/providers/fips-sources.checksums index 598c3bb44d..00575a3be1 100644 --- a/providers/fips-sources.checksums +++ b/providers/fips-sources.checksums @@ -1,600 +1,596 @@ -1adbe13eff4750e389446101753e40402977dacf1493eb7ba053654bb37bd0e8 crypto/aes/aes_cbc.c -170697bf22866d22f25a886a2f3c7206139c34bfab56fb1d57564995ae57a38c crypto/aes/aes_core.c +0e22ea0cf34ef3871e30df0bc302dc29352d38001d1622ddb78a27a374b6aee8 crypto/aes/aes_cbc.c +c049a936d74100fcced225f575d46662792a6a0039777d2d4df0cf61eff90a68 crypto/aes/aes_core.c 3fac41ce96acb9189eac2d5571425c3ff33a34c884ae7e275e1fd3068b5fc662 crypto/aes/aes_ecb.c -da4942231014063d9e4fe1db91b6eb1b8f233904d169f3f1b8be7c6a59728d2e crypto/aes/aes_local.h -7414fa4526ba20ee966125e8f7e428e4c75cd9021a79f1151a4bacb28d2f10da crypto/aes/aes_misc.c +c1e674d08683a25bc053f6233f73a0d0b3a90aafe591ff57b702c7da1582e4a5 crypto/aes/aes_local.h +a2466f18da5847c7d9fbced17524633c10ce024671a72f53f9c9c55b9b9923dd crypto/aes/aes_misc.c 793c1af13d28ec05895c2d33e2882df4cda6361004a9e0c6025447353ae86331 crypto/aes/asm/aes-586.pl -bbab787ebab9385502f5dd10ef63fd99e7bcca4e786d8a16981fe830581fc8db crypto/aes/asm/aes-armv4.pl -96e1ce4849089b7a467a4f622aec668a63624876a8b40cba26e84e7b471261ae crypto/aes/asm/aes-c64xplus.pl -4371307ab7dc22934dc206174fbe53bacbc28b54edc30544d53d637d3c0ebc8b crypto/aes/asm/aes-cfb-avx512.pl +d69b7db0cab72360f4cbe9e412f5b2e49b2a8b31647646f3789fc97171805e44 crypto/aes/asm/aes-armv4.pl +579c923246d72d5ef0b9a56319c7922361fdb47a519362e2e60eb98d1ef47af5 crypto/aes/asm/aes-c64xplus.pl +ac0b7ef8dab43049f6c3325f585fc6c0f35f48c34601e5533687f3d103d0f2ac crypto/aes/asm/aes-cfb-avx512.pl d0fa153afa8b6d86f5dd5e8b472458913d25a553425b0d4189e405eeca65b313 crypto/aes/asm/aes-ia64.S -b4ef595194fe1692e1ab2b561f385da01b277cf004902e8fc99e8ac5389bbd35 crypto/aes/asm/aes-mips.pl -aec8e840e21399d82a8727e9e1b545c78e5672bfeaa43209399ff5d802a281af crypto/aes/asm/aes-parisc.pl -37236228f6414d932fada6e5a7dca7d711c1de754672064e2aff79ec9e15fc72 crypto/aes/asm/aes-ppc.pl -e169a64f92b984f51792bf9bc491e54fbf1af52da76610c5ef1da0cd72893250 crypto/aes/asm/aes-riscv32-zkn.pl -5718962a86f1d737b410366280416a0595c7d8df96bd2e58c4c0d7289389d200 crypto/aes/asm/aes-riscv64-zkn.pl -8179f94715211cf8d69f17b5a785e4243f96d0728f31038e0016ad4fd860630c crypto/aes/asm/aes-riscv64-zvbb-zvkg-zvkned.pl -6a252373a3c20ab39b9e343b924af2182a1804a2c426b952d655c373927befe9 crypto/aes/asm/aes-riscv64-zvkb-zvkned.pl -3d185c92a25ba0815e05c3b55f6667c510703ed74dabd6e2f41238968e69cb31 crypto/aes/asm/aes-riscv64-zvkned.pl -ff7c8f37bbbdb7e1d3620506ee289651db8d8eda0675afb49de5ff3f6aeba6ab crypto/aes/asm/aes-riscv64.pl -79db6f8ca2c6aa40206fdd9882bbe67d5dd4089af8fe709dbee7d1ed6a0e89ff crypto/aes/asm/aes-s390x.pl -1d1fc6fc586d4f7268e7896729a37dec7bf2d7a5cbc13fe4a6654d31d6776688 crypto/aes/asm/aes-sha1-armv8.pl -442ace59e2f9a017fb0501a6e87cf78f2e90dd95e1d5406537730f1657b7872f crypto/aes/asm/aes-sha256-armv8.pl -67474f4cb9afe42c29d22400115ef5b900c4c30862681e26c4ff567edae0fdbb crypto/aes/asm/aes-sha512-armv8.pl -133ba35d77002abcd430414749c4e98c4a319630da898e45ff8dbc5800176df1 crypto/aes/asm/aes-sparcv9.pl -e507d1be7b7a1b2c35f8309f195de9edbf1f30891b99684c834b32f950f51970 crypto/aes/asm/aes-x86_64.pl -28dfb1a91d8b71287957960ee8d573a8f00065c96a9ee8af3f625ab4af769541 crypto/aes/asm/aesfx-sparcv9.pl -ab94a27e533e164bcf09898a6f6019f43609d51a3b374cf75482dcf2914d464e crypto/aes/asm/aesni-mb-x86_64.pl -a4ad4aa82414421416d416f58eb57a2a607c8d08c0ddd393450043f15415c35c crypto/aes/asm/aesni-sha1-x86_64.pl -c4b89a809a7796dede1b1937e53e892a891afc74901a1c963b960c1e3f9281f0 crypto/aes/asm/aesni-sha256-x86_64.pl +88b6f8396cd9d86004743d5c3b0f72b7b8c3d5a2b00b0bbb761ba91ae5a7cdc8 crypto/aes/asm/aes-mips.pl +a8c16bb38388f8344dd32ef3186147c2c45f5943f0db6a323d1656e539ba229c crypto/aes/asm/aes-parisc.pl +47a648f58f6cc46a64be579b1a1499645699bd55ff348fb814ac72459714e87e crypto/aes/asm/aes-ppc.pl +538ce0e80698d773c9419a9ca8892d61bc5b3cd1b071c5fc5f315d7f5573e96d crypto/aes/asm/aes-riscv32-zkn.pl +b5cdd6858b1eff7d17b29b78ac8c4a7642c0a74710f8b50821a6265328845aaf crypto/aes/asm/aes-riscv64-zkn.pl +e1f3805332eb811d9d0c9377b67fe0681063364f1af84d8598f7daa30da65b4d crypto/aes/asm/aes-riscv64-zvbb-zvkg-zvkned.pl +ecd9bdfaf25cdd3d8ec0c50cb4306d98374da1c6056e27e0cf31a057dc5ee150 crypto/aes/asm/aes-riscv64-zvkb-zvkned.pl +6af05e5604a93a8b89451e06d266b510f0d3024f24b135ec4cf2963b1fa30af9 crypto/aes/asm/aes-riscv64-zvkned.pl +f0388e17ba4268ed0b562da60e0780072180a824a379b79fafb60e25b8da3b52 crypto/aes/asm/aes-riscv64.pl +a83eec44f443a88a858e5fc8ff871e3e7bda4173ef1e8616bcf8436754682858 crypto/aes/asm/aes-s390x.pl +69257c7eb9bcfd69c9b0cd2dbf18a9465dacf7fba2261fec8791f2184056c69b crypto/aes/asm/aes-sha1-armv8.pl +cabeb213ba4c01dc1e978bca9143d15b4cfb5c7675d5e22c18f9b3748fee8a7e crypto/aes/asm/aes-sha256-armv8.pl +dce3141dfe78dcf134052bdca2e292dfb6a218441b5c7a5baf4ac14edf3eae24 crypto/aes/asm/aes-sha512-armv8.pl +ee4e8cacef972942d2a89c1a83c984df9cad87c61a54383403c5c4864c403ba1 crypto/aes/asm/aes-sparcv9.pl +3c8b598fa1926f0aefb38ce99b30b08fcf40a09302376a8e2cf80e21e3d3dc75 crypto/aes/asm/aes-x86_64.pl +cdc42ff8d1b1435449ef813dd6803bf928fdc26a4fa9bfde4bab1b5a384787be crypto/aes/asm/aesfx-sparcv9.pl +14359dc32b7f4e5c08227fb9ac8f9232c1287399463b233fec4a2ab0c19f68d1 crypto/aes/asm/aesni-mb-x86_64.pl +b78dbc32647dd47083e3dd635d5053a08ea92efb6d985b6212a7d812c2e3cd04 crypto/aes/asm/aesni-sha1-x86_64.pl +9eb48ba9553778129f54253dab3f8a9ee8a602a3342349d29fb3d6000be4946c crypto/aes/asm/aesni-sha256-x86_64.pl a95ee8f58a6751e6e8375e62fb6fcd4cf79a2c96f328e634f5a03a787d0ce267 crypto/aes/asm/aesni-x86.pl -9d2628c860be50612f05c99ee3f8db2c2d127c50cb0ba85875b28522d6c76bc2 crypto/aes/asm/aesni-x86_64.pl -2977888731a429f7f0f73a4e8fb6898da954586dfabfc6c8cb31b7668d8c25a3 crypto/aes/asm/aesni-xts-avx512.pl -f5f0702f3c439df07dc5912ebf5232e17d4ece52ca87e99217851aac091d404d crypto/aes/asm/aesp8-ppc.pl -a5807ed92ec8a16d123061487c385bf1f65e50878cee95c8e8096844454129f8 crypto/aes/asm/aest4-sparcv9.pl -adc65ef913056df715ca0581d6946d83a032e0e24d7617a2ff67efd7fa872501 crypto/aes/asm/aesv8-armx.pl -1a9c4dd478dd825d258c989cd6861a74b46cf1a6ea00cca71e306d9a369e930e crypto/aes/asm/bsaes-armv7.pl +546a90333079f279d39091b6d6837893999d49a879bdabaa28b5920e43931a06 crypto/aes/asm/aesni-x86_64.pl +5d03d59af5d77979bed0662a2e971951899d407d11dcf6a8e174453aaebecea2 crypto/aes/asm/aesni-xts-avx512.pl +e51ae9b43503a53bf30b096e4823330d09edbdd87dc4fa1922f046c499cc68f5 crypto/aes/asm/aesp8-ppc.pl +e397a5781893e97dd90a5a52049633be12a43f379ec5751bca2a6350c39444c8 crypto/aes/asm/aest4-sparcv9.pl +578142d03bc47353952fca2027eb63ec97ce9a1379c0f3c7ac0fdf110eb3378b crypto/aes/asm/aesv8-armx.pl +b326e093c0156c112911376d9e904ee1149b77b1877e25bbdb047bd9db20585c crypto/aes/asm/bsaes-armv7.pl 12cd3c8a9ce7153c577ff6238d81ec1947dfc43ee80cb15ee886cdf811969417 crypto/aes/asm/bsaes-armv8.pl -c22a4a276257db7c7a44ae8ddae3575f46dfdf65f14893985c73173294946c2a crypto/aes/asm/bsaes-x86_64.pl -6778dab09a2f6d65aea9af93079d81b5cd6f0a7ca11568f465e20dd50e6aed33 crypto/aes/asm/vpaes-armv8.pl -11e17be338aa5b5548902b84b7100156e2ab5492b6b2ba8df48c4390a410fe5a crypto/aes/asm/vpaes-loongarch64.pl -ef0f2fdd6a0b21d7aa594c2a1f83d2e6bc0f3c61655a1571c2ecb1d2eb193542 crypto/aes/asm/vpaes-ppc.pl +c72f6cbf3b9900d956e05003ec8df758b29b43519c7801d677c3f992bc589d4e crypto/aes/asm/bsaes-x86_64.pl +41e737a3c2985564dd7f7a56fbf3e6ea9c93f1e27e2b64ed13767faaac71a11a crypto/aes/asm/vpaes-armv8.pl +7ec25456a8ad4127c3bec83550d8ec411a12b506dfcbd4f1dadac2c66e468c22 crypto/aes/asm/vpaes-loongarch64.pl +608b2531cdbf7818c5e3aec5228aedde2eecba79f3c08148d4d1e479d3270682 crypto/aes/asm/vpaes-ppc.pl 3ec24185750a995377516bc2fb2eae8b1c52094c6fff093bff591837fc12d6c3 crypto/aes/asm/vpaes-x86.pl -0bdd2083d4454e46ec8d8ddd667a304684411f4d2ea9549237ae02260e13f009 crypto/aes/asm/vpaes-x86_64.pl -132c91241e571ea360250d28f8ae368a9efa07cd11afe014e316be07da38de8f crypto/aligned_alloc.c -46fe58bf9bd1b4a3e4b7688abc85fdd38328fe6baaf1db85bfd84cb0710d5914 crypto/alphacpuid.pl -92ce22da9063dc3ca88b5ef643b9ca02b72ec08bfe713b982370c1290a043f93 crypto/arm64cpuid.pl -3254c173f9dc41cf8b7163f1e09ba17fbe8420a8422b936c1b0e7af197c4a912 crypto/armcap.c -22888bce076f22f4a196e282ddbba01f03e5a53c759ba950c8679073de4b338d crypto/armv4cpuid.pl +c6935d2ab7925022cb3d76446536ff01b1a1b8eb7eac619d034a29aad17ed45f crypto/aes/asm/vpaes-x86_64.pl +d1df86b2e1ed3ecb59db54b89927973a7573e8395cfc26a9836a5b229e951ff5 crypto/alphacpuid.pl +269e52f8867c13ca75d2f88ec1f89b692cb8c6c3ee89abe2fd3c1821925191d8 crypto/arm64cpuid.pl +38b8ffe6b9bec260adc8cf05d528d6ddf07fc5d77ca00705bf7a1ece42e05792 crypto/armcap.c +06ce5501588170ec07832715113ea2db9abbe4127985789617e6de2a19115b2e crypto/armv4cpuid.pl 779ea664cd73b8bf2e286cd4d01bfa04ff1543dbed821c79978b98fb80f76576 crypto/array_alloc.c -e886d814c34492504cc9a2451c67fd8c0b4e83e8618f931632400cfe522b6e4d crypto/asn1_dsa.c -0a9477f2b8dfef0c34e5c215894605ea5860bd6fccad0f2c46f7575fc0a8bfec crypto/bn/asm/alpha-mont.pl -c06c6f3591131cb3532e07a17374689ba26dfe10f1566e8b0a739bea2ac9d25b crypto/bn/asm/armv4-gf2m.pl -c1d0e9e4e583a907e381303550290cfc0835cb29ef27521a8eb167468c2eb41c crypto/bn/asm/armv4-mont.pl -30e78a46dced48933cfd59d0ac96fa5d4063a3c5025d307c13c21f30865d165f crypto/bn/asm/armv8-mont.pl +16739d54200fb81ca7835b5814f965022a2ab41589c7787e2697e3ea72d4fafa crypto/asn1_dsa.c +64e34983cef730efd470b3db8b8127db11a7a3925e072092829474b7a67fbd72 crypto/bn/asm/alpha-mont.pl +97e961bd2b49682d2039840e356c0a7b52d801c27e74e6ca2fcedfc542885b8b crypto/bn/asm/armv4-gf2m.pl +2d3d2bbb8fabbc007958ac091c610b4d9db9c7911db6fa569a71009353d5d37e crypto/bn/asm/armv4-mont.pl +bb5b33660fa9d01441fc596d6af2eb4891ef2cbc9cc680310266706307ab5a6d crypto/bn/asm/armv8-mont.pl cb4ad7b7461fcb8e2a0d52881158d0211b79544842d4eae36fc566869a2d62c8 crypto/bn/asm/bn-586.pl -10fb73a6cc1bc064ebdcf6d7fe3c7407ea1c28b0d65ad0123046f8b1518fa75a crypto/bn/asm/c64xplus-gf2m.pl +636da7e2a66272a81f9c99e90b36c6f132ad6236c739e8b9f2e7315f30b72edd crypto/bn/asm/c64xplus-gf2m.pl c86664fb974362ee52a454c83c2c4b23fd5b7d64b3c9e23ef1e0dfd130a46ee5 crypto/bn/asm/co-586.pl -03b0fd6b7d0d5eda5f247ad16031e0475a9cd29231322b88adc21ea1c2e52963 crypto/bn/asm/ia64-mont.pl +ff2c606de5f1bad97eb7a5d25a856d5b6596c4c66b99710ec38501c187eab9d9 crypto/bn/asm/ia64-mont.pl f73e00dd24d22d664390e2d25397a45410094eb39e07f0c9ba9a421c6bb53358 crypto/bn/asm/ia64.S -dba7618bffdde638576c5e4f31d1fcabfaf67b89d028eb8ff04f0c8aa54fcc5d crypto/bn/asm/mips-mont.pl -29cbd1deb5f29bd4196755a74896b73ddd80bae23e79ff36e1ff42c596e70fca crypto/bn/asm/mips.pl -9a46c5171d34dbdf4b1605c41ded9503d92ae7ce8413ddb7b538b76defcfc150 crypto/bn/asm/parisc-mont.pl -37d90121a9026f8c21c21a1c3c817a27a21b643b357f31c40039ac8e54955bfe crypto/bn/asm/ppc-mont.pl -1c057083546fa1a3bb1b9819dc5110f5a3b11b7bf5a2fb275012323bd7412403 crypto/bn/asm/ppc.pl -04c9b5d2494c06e6f8a47c35274ddf53ae46b65e6abc297bd41e5beb735a3e8e crypto/bn/asm/ppc64-mont-fixed.pl -38820581b2ee29de8a88a5e3e7a6760d72174366452c1c6dfdf2bb2993e0df87 crypto/bn/asm/ppc64-mont.pl -eae1d6954ab3a5c2bcc17b3159755b81e80ea46ff2144ad5e6b6cc4bbfd63ef4 crypto/bn/asm/riscv64-mont.pl -4be4daa0a7873ea499e96fb3ce1a62c82e60228d0fad1d11b254308f051c35f2 crypto/bn/asm/rsaz-2k-avx512.pl -8ab49ff8b1ab9eae207112309c84f19e87f7d1140b3008164dfd46cc56b51a5c crypto/bn/asm/rsaz-2k-avxifma.pl -687ac0e5dc5cbd3e98af5ac54a79d659286a1104b984bb70825ed63d34184b99 crypto/bn/asm/rsaz-3k-avx512.pl -e75ea7d99334a9717b5db9c492ab6102d287f9de806772dad87fa2944499ce7f crypto/bn/asm/rsaz-3k-avxifma.pl -8ec08dd277ba252a4f28f2b664599526ce7d709dbcc01840780882f1ab19c46a crypto/bn/asm/rsaz-4k-avx512.pl -fd787df8d3e7c778e0f067fb22a049460ddf7f992678f908adccfcacc3677530 crypto/bn/asm/rsaz-4k-avxifma.pl -d9c8e45377eff220f0eca3e830f042423ed99e92b3c900e7b6e58685f27d69c0 crypto/bn/asm/rsaz-avx2.pl -f44e49a24a21d38ec415bdeaa7f8a2e33ada51ebe7a7ff7dd3fca52ddd25e1ce crypto/bn/asm/rsaz-x86_64.pl -3228692b32bdf96be6e033e6c24ee3610eb72dc6e28c3e8582857bcf3f0d2134 crypto/bn/asm/s390x-gf2m.pl -eaf166b509d192ac662d47f9d8c34a11e1c557e5c774256d96cfeb22a8cf78f0 crypto/bn/asm/s390x-mont.pl +07423ecaf7d0c1ae41a5e8f782bd778c81bad7dfe81eff94c6c3ef40a7fcc2f0 crypto/bn/asm/mips-mont.pl +23d4d3cd26a1d13e88b844e7417f75c4107946a944e4a4e0b65439de7cdebe6b crypto/bn/asm/mips.pl +7899ad1b52b4986f8c241e200e02d9971f860c10590162d68b459a6fb4222900 crypto/bn/asm/parisc-mont.pl +cc89f4e101bdd25964b27f9c18e00690e0d1006831a2c86c2ce92f580839849c crypto/bn/asm/ppc-mont.pl +59cd27e1e10c4984b7fb684b27f491e7634473b1bcff197a07e0ca653124aa9a crypto/bn/asm/ppc.pl +0b3350f56d423a4df918a08e90c7c66227c4449a9f9c44096eacc254ebc65f9f crypto/bn/asm/ppc64-mont-fixed.pl +042fba38f786a505eaf10831719b5bebd55c627e348740b0b8a3170302ba8b10 crypto/bn/asm/ppc64-mont.pl +a6982e91f35fbcefe897106b3f5c8957359fb58b74beac12bdcb8d3b7daa15f5 crypto/bn/asm/rsaz-2k-avx512.pl +1b059fa9056c6b476f036ffa5dc74092d9366ee94a98f8f3e57e9b452a695232 crypto/bn/asm/rsaz-2k-avxifma.pl +df7268cd5461269db0d8d1ef62c2d9ff6608eb0c071e798b06ad9ddfcbef1a31 crypto/bn/asm/rsaz-3k-avx512.pl +b8424d830f41a038f3c98d8664c6cf7d2d3e1748cdce260db41fa3c74f1d88d9 crypto/bn/asm/rsaz-3k-avxifma.pl +9ae9cf7a926eea6543237eb4c537860a36e6373e9091e2c581868871ba84fd74 crypto/bn/asm/rsaz-4k-avx512.pl +afcf51a732c80eadae1650e22e4af34904112a8b95467087a16d9d2394934730 crypto/bn/asm/rsaz-4k-avxifma.pl +6e47bf041e51d8086c4933c2a5da3ce6d1b136592984754461d59aa81e4995a6 crypto/bn/asm/rsaz-avx2.pl +149842bf63d1ef1895a251a83d9941fc3ed744dab359b42d635d04cc8d2f2864 crypto/bn/asm/rsaz-x86_64.pl +6049dd721f4663b94272bffcf8e6c872ae82fe7cd23c7b315170f8f2897d3b8a crypto/bn/asm/s390x-gf2m.pl +69bc9bc58b9f6ef8d8fe9ef459a7d01480de2e05749d166a76070ee20074f056 crypto/bn/asm/s390x-mont.pl aa02597f3dc09cfbc190aedb75711859ba0f3efff87067ebfba1ec78ebee40d7 crypto/bn/asm/s390x.S -87d49e83a7df467097fdfc577aa206be9ee622c40fcbbbe5133b35d9783b7816 crypto/bn/asm/sparct4-mont.pl +2f7cbc2c3d93b1bbc4953dda38b9ae0ab3a0a8331a0418d94d9b286183736c9e crypto/bn/asm/sparct4-mont.pl f3b3f3ec50e38d02a82fb51d823d4449446f954a9ae8e5beb5874b907bdaa437 crypto/bn/asm/sparcv8.S 3c42b4fb3697b347f13dfdf556b3c209c10738b6234406f552af7519b4637750 crypto/bn/asm/sparcv8plus.S -503ea6aef1109b7dc0053e02e3b0b0541e3a133b956e17ef10671d97cc7ece22 crypto/bn/asm/sparcv9-gf2m.pl -07992e066b99f924373295585c10a1799cdb956d6ee92ab0f8c3fb2be639a6cd crypto/bn/asm/sparcv9-mont.pl -ad9d64c670c7d89d7c9de2772bb08478ed5efad1744876075e1eabf1b9f5bace crypto/bn/asm/sparcv9a-mont.pl +9148be08fe1574e1d6c4d6062e37426a04ab39110eaf8ce6d9194a676faecd07 crypto/bn/asm/sparcv9-gf2m.pl +e24b45e43d908c2c87c1093e76f6069d8a4c1e34d893290369a6aadcc992cf3f crypto/bn/asm/sparcv9-mont.pl +7848a266ed540652ea4db4d3127207fe6b5755ebde7476b622385b21ad522029 crypto/bn/asm/sparcv9a-mont.pl bf3336df4063c29118961f411852df79b46c1a3981cdf055382f501339eeabb4 crypto/bn/asm/via-mont.pl -721b1bb921d8e8b82043df25348d45fea9a190cd7834b2bfa0661be0a9b6c460 crypto/bn/asm/vis3-mont.pl +45f97d9a5a0913abaa01342b496c4743976cc3006c2b52e6a3ae075895fe80c5 crypto/bn/asm/vis3-mont.pl fcdb8846dd6fb1b8297a8a2dc75915a2c5608434c7bc05e68a8b637b06961575 crypto/bn/asm/x86-gf2m.pl 0ed86280d18597b4a933609efffe1df991d0a0fc82e3cbe88f6ef06f947d7e55 crypto/bn/asm/x86-mont.pl -0e3e572cd864bcb9222cdad7ca4e8dae4250f6f76c2b66e1f0e46df1cc0cf371 crypto/bn/asm/x86_64-gcc.c -8dc17b03325a13540db8a40bd2f92a7ce8244e04daf0d59775596f376895c718 crypto/bn/asm/x86_64-gf2m.pl -d9abee54e5bee2a180d4215659c7f49fdc818e660d39029bfe906e6a0d84a972 crypto/bn/asm/x86_64-mont.pl -9dfeb5a18330e9c67060cc3de8dd5ec0236a0742b7874a3b7f80657907ad2a67 crypto/bn/asm/x86_64-mont5.pl +d444ca73875e97e0ea88b20e4c02f2fcf3850e8b9311e3b67a2d04fe2796d543 crypto/bn/asm/x86_64-gcc.c +6699333579a63579f58842d1c400ca9fc7dcfb07e9217f32876be8bafcc5f05c crypto/bn/asm/x86_64-gf2m.pl +54617ae5bc69c636feb8f53a1aacecd61119c8795dfa0c63e80860f8e3900e3e crypto/bn/asm/x86_64-mont.pl +0170820111a5f6c60603c925b6bcfc5e1d267d4920731b4f350b2b993611e068 crypto/bn/asm/x86_64-mont5.pl 78dc1d8e7a63aa41cf837a2a4f9994cb6847fda1a24194caa44778e825639ec0 crypto/bn/bn_add.c -15e79a49cb16ceb28b33f1a06e5d4cd05b7899c8a92819cab72937212aa6639b crypto/bn/bn_asm.c -cd5922b43407173e1331dede5a6d8d94f2d519a0d9f39b6017199392621c2ecc crypto/bn/bn_blind.c -d3b5f02a17ba1c71261f6dad0d4785846567c8a03368d41fc1a6ee7c45aaff78 crypto/bn/bn_const.c +964c7eecef99ef56997cbb90b6560d41e0e90bb1f87dcc5e2a1bf177851c005f crypto/bn/bn_asm.c +e7492799c30753a8b2e10dcf4c9d986226c9e81508616fc66e43cff807243014 crypto/bn/bn_blind.c +7b761d541e3b7f6a3f2b14a09b2b3836a079a845cf67a54db4853e3fd38277c6 crypto/bn/bn_const.c eee3d2710144b0e860c57e84f5adc6b2bf64fc27cbd202a8ca2630aefed3b84c crypto/bn/bn_conv.c -33458c8fe9a56103f678a40d8cdc8cd2e222c229c1e079326403683872cea5a2 crypto/bn/bn_ctx.c -b1b1c5fb8a45fde5755dfd5da62b68100b94f8c492c950719c108c384ea7f3c4 crypto/bn/bn_dh.c -4824f271f0ddc487b5991fbd92f7f7695aeeac234e076078f37da027999cdd88 crypto/bn/bn_div.c -a701560a4226e14f3a3de5f9ad125ae9e484d23fe9594622245e616ac791663d crypto/bn/bn_exp.c -ce5219203bf869561297978d6d416357a441864cd801865503dfd455c481960c crypto/bn/bn_exp2.c -c335361ed40e46f29641a99a9de6554fc45af07ef0697ee7e8b49f5bfb137537 crypto/bn/bn_gcd.c -6a2e8b4771ba9b2774483004c4777608cc32f455bfb4f6268922451bd8bc9781 crypto/bn/bn_gf2m.c +3dd1fe87a2eed65b1ba90b312689e8dfc66ec06f05ed3a1ad64480a38c41cf2a crypto/bn/bn_ctx.c +d94295953ab91469fe2b9da2a542b8ea11ac38551ecde8f8202b7f645c2dea16 crypto/bn/bn_dh.c +74b63a4515894592b7241fb30b91b21510beaa3d397809e3d74bc9a73e879d18 crypto/bn/bn_div.c +a14183415e8de385964b0045af6d155a0c9dfbc5f0bd11cb4b848c31eac086af crypto/bn/bn_exp.c +ec2b6e3af6df473a23e7f1a8522f2554cb0eb5d34e3282458c4a66d242278434 crypto/bn/bn_exp2.c +b171cb4f895a74b5c785d0254bade1ed1f5add5e0e69b32f238bfa3dd84aafdd crypto/bn/bn_gcd.c +31c6702f1c6ea02ebf1aea45c4d66bcb3fa77dbe2daf91887e50026f22458b60 crypto/bn/bn_gf2m.c 4fbb1dd8a5230cde13e59a8fe618c7cb371b197f21f8a4a3b8ae58dc2635a760 crypto/bn/bn_intern.c -ff147e5e032cc7c772b73a91fc6e24d8d9516e642d29354445d1f82d64b1d924 crypto/bn/bn_kron.c -a80481da8f1af0c19c6248f34ab9494dd4905d1781f63adfe290aee61e978b1b crypto/bn/bn_lib.c -21e080b81ed0fed6b4128068712b54e7854da7b621fd1298eeb0d3169ce75311 crypto/bn/bn_local.h -0d6e0928003c6d9f9ce153048370e94eb838c6840d207e09fc98b76aebed86b7 crypto/bn/bn_mod.c -6c438d456aec5940cac77381cdd2f0abc9436749a5201c3fe08eef9bc1b7781e crypto/bn/bn_mont.c -c2a5230efbda6844b7b2eb10447b054496ae5029130d332536de6c3b12dc58a3 crypto/bn/bn_mpi.c -4d1aaebf3ca938895ec2f42e24e06ab4d296a835ed75dbeff7168eec21631fd8 crypto/bn/bn_mul.c -e80177361897632ac9f013415dee8f6d2d942a8b51a4daf84fc7ba51d9d75270 crypto/bn/bn_nist.c -92e8043b4fa716b8f2fc5734b7225ce1121727f6112339df1735f76568dea557 crypto/bn/bn_prime.c +602ed46fbfe12c899dfb7d9d99ff0dbfff96b454fce3cd02817f3e2488dd9192 crypto/bn/bn_kron.c +58e1b9b5a8e044f03261e926918d69bb4c036395f62aabedb537342c8f33596e crypto/bn/bn_lib.c +523ced8a82a33cb0b2a77341cfab281052ce02f5f943b4e46a5d002121a32b07 crypto/bn/bn_local.h +26f0521e07a485306fde6751d0beb87fc9d71e266502284cb08661e317d956f2 crypto/bn/bn_mod.c +5fdcf81ae8b55953fa7d8d9c16f736050f87130d37621208448eac585f09b4c1 crypto/bn/bn_mont.c +2da73a76b746a47d8cf8ec8b3e0708c2a34e810abde4b4f1241a49e7f5bb2b60 crypto/bn/bn_mpi.c +76982b18b0803d59b33168b260677e7412970757d3b9513de5c80025290f211d crypto/bn/bn_mul.c +6bf1d67ea493401f7765647828d3f426305fd0686cc89956c9d205922b7ab4db crypto/bn/bn_nist.c +9775b4de50cd7a28d5ac3ece67faa4aeb26adbd625793ac5efbd403dad46f5fd crypto/bn/bn_prime.c c56ad3073108a0de21c5820a48beae2bccdbf5aa8075ec21738878222eb9adc3 crypto/bn/bn_prime.h -af5af7057643ee8d35e3a2d5f7b55e37647db46700f2818edc295d727450d521 crypto/bn/bn_rand.c +4e1f3e71cdb05d41608224d1837da6f261d5f60a570be1045c10738e1e6646ff crypto/bn/bn_rand.c b5cc902624b3af2149c9ea91f9d18bea56302144e87dfe49105ec6789b73764b crypto/bn/bn_recp.c -d21093afc3d81b0ae37dc81717ba73229bf678ffe67283c83eb74f9cffd85df9 crypto/bn/bn_rsa_fips186_5.c +669a157968afe07588507a2e9e35c1c4df9c2b0a95cd9c21404b0bfa21be0d37 crypto/bn/bn_rsa_fips186_4.c e04f7460a2ab3b3bd9db332d99afbf8c7a3919866ad4314a5a5ad95b23ec6399 crypto/bn/bn_shift.c -1a92d0701a7b7660eab9bf861f63b831232896b88cf2b64e56a6713fc6ce34a9 crypto/bn/bn_sqr.c -c748baddfec6734bb50facbadf151a1f22f8a885c677acfb08b4f814e96f0d52 crypto/bn/bn_sqrt.c -f42996cdd94f18fe0858552be7123e75cb3ced0ebd7dcb90a0c73740090dcac9 crypto/bn/bn_word.c -2f048ca8e8ddc5e2b8b82775197f79334381dd90bab417b2855bfeee07b99db8 crypto/bn/rsaz_exp.c -45f7212a616e33db1310126e213fdaded8e3dc8a200b0520306cf423c485e58d crypto/bn/rsaz_exp.h -40a6f24c3575238dbb47958b613684d46c8c442f203cf07ef02f6cadcbebc31d crypto/bn/rsaz_exp_x2.c -72b85ca219bfdc7f990e07cc15decd9f46a12fd71cdc7c2331916c5009e5f48e crypto/bsearch.c +622e90766b29e0d25f46474429aebda8eba2246835b9e85dc26da7cdbd49334f crypto/bn/bn_sqr.c +42c8ce944c889abcfcf089d0ad2744b7587696d8d7785efa91b3f7ec53dc062a crypto/bn/bn_sqrt.c +24e62baa56e02f2db6454e10168b7c7fa7638db9221b9acda1803d43f38f36e0 crypto/bn/bn_word.c +ec684bfc01a74492150e930fe6d6cc5586be48b9674bbd7a492efa517d04c340 crypto/bn/rsaz_exp.c +84cf160d7832489ed3379b9051b143e195b984462bd67b35852ddbaf353696fa crypto/bn/rsaz_exp.h +ad80d38930e576afdf55dfd88c3c7ddfa390cb474b9b1b72d8a37fa0dde177db crypto/bn/rsaz_exp_x2.c +834db8ff36006e5cb53e09ca6c44290124bd23692f4341ea6563b66fcade4cea crypto/bsearch.c 82117f6a7cfc31fc86ecd9629bd3bf614126b8e8b2c23717a03ff5c1db7c3c5c crypto/buffer/buffer.c -b99af1c5b04b34af14774966372dd90651c462797753b5f0576822671cd5c40f crypto/c64xpluscpuid.pl -63835e57e16d3e463dc3ec8d1dbf907aa0824b59cbbc309983ff62546655d644 crypto/cmac/cmac.c -d2f9fcf7459b0c2b8a0de1a8c7c74e0f9ccd67fa664d9b32885f7c254ce65bba crypto/context.c -ce92403350443d08cab02566b928013eabaf2d5ff5e2947f7e6d322cb8ec82fc crypto/core_algorithm.c +06f0928291412621c133631da83ca200d60478897ccc2cfa4583cfeca6f823a0 crypto/c64xpluscpuid.pl +e880207cb7eb76ff544200d1b3b1ecec087290ce332c299e4674c42576217940 crypto/cmac/cmac.c +701efdd81776c0419141b35a832e3e99fb700a4bed3c909cf33c0fc8428e4b39 crypto/context.c +67c2367871b9350a7f7af5be903d6bcca9ebdbff0e9a9bd9f61b56bef5b76696 crypto/core_algorithm.c ab29529cca1308302d852999f2790c404a4dc0ef8cd6653260739f70b2f22758 crypto/core_fetch.c -a0637b8e324fc0970cec4f332fe07f7fd953f23586de8179dfeeebb4a7849433 crypto/core_namemap.c -a62f653b8a6ee765be704980425617e04e1d242f9735efaf35fc6e00815ff2a7 crypto/cpuid.c -3864c2bef2acf9d6fc7fa2486521236c382dfab4e813e49bf598ede68a6ff171 crypto/cryptlib.c +f120f190e12505d0fba0f42727eef47aca621cb173fac9a7c59abc0de1a7b0c6 crypto/core_namemap.c +819f75bcb1cbd6633381ec9ad043152ae2ec1f71471650864f2cb8c88612cab5 crypto/cpuid.c +4d3f6ddae2d761f0f799ae83f6e5196fbb504fe1fd166834989b127e9b12c976 crypto/cryptlib.c 66dbfc58916709d5a6913777346083247942a8d9458ee9b2bf443f0ea4988d64 crypto/ctype.c -b9fabcf8480b8c9c7847a0c9af0fcc13b6c4b4a4558d5e445e6409221e6f8113 crypto/der_writer.c -135ef65f7602432f8c87ad18fdd90b867f1c46b1c631522d56181fbed2106b05 crypto/des/des_enc.c -7c2cea4c850398158b4aff172b242de0cc436b66f62fc701ccca3fe5489925a5 crypto/des/des_local.h +51e56541daea6d4a26d5bae2ea458414063bf08b045bab8df370f6695903e0a5 crypto/der_writer.c +fea3ba4225df97aee90690adf387625b746d8edfdc5af2357ee65151a3d236ac crypto/des/des_enc.c +3c5e1c156ebc771701f0adbcfcd099d700796255991c1bf79bd2ca78fc009c87 crypto/des/des_local.h eeef5722ad56bf1af2ff71681bcc8b8525bc7077e973c98cee920ce9bcc66c81 crypto/des/ecb3_enc.c -c1e015556147b40c854bf0ab275c54235f99001d04c6d49f158fba6865eb5439 crypto/des/fcrypt_b.c +04d4cc355200b57f1e7d265a2cebdf094df1eb6e96621b533adddc3d60d31fbe crypto/des/fcrypt_b.c 499513b3ad386fe694c4e04b3c8a9fd4c4e18fc44bb6c4f94d6bf2d9362a3a5a crypto/des/ncbc_enc.c -dc2e7899593032fdf0fcab18f5549c52f12bad2225aac9a08c4622ffee34b193 crypto/des/set_key.c -41b7fc5e67814311b878684e3f29cff60e228f1516f670d81bf43130f2668ae8 crypto/des/spr.h +9549901d6f0f96cd17bd76c2b6cb33fb25641707bfdb8ed34aab250c34f7f4f6 crypto/des/set_key.c +8344811b14d151f6cd40a7bc45c8f4a1106252b119c1d5e6a589a023f39b107d crypto/des/spr.h 82b6cd90a74f0249bbf7e93c035d649d91fe3aef39cc8d507e61f4802ac652ce crypto/deterministic_nonce.c -3a852fcc48213f90caddcffd219a7f955be93eff519fe8b28086c68926314ce7 crypto/dh/dh_backend.c -091ec05b6316cce34305ae8f8014043c7c9b72098aa1abe9c35dcbcdb4b77cd0 crypto/dh/dh_check.c +a54b1b60cf48ca89dfb3f71d299794dd6c2e462c576b0fe583d1448f819c80ea crypto/dh/dh_backend.c +9db32c052fb3cf7c36ab8e642f4852c2fa68a7b6bae0e3b1746522f826827068 crypto/dh/dh_check.c c117ac4fd24369c7813ac9dc9685640700a82bb32b0f7e038e85afd6c8db75c7 crypto/dh/dh_gen.c -1149e214ed664540434912e284730a3c87385172e4c6d1c944ea56659e2dd762 crypto/dh/dh_group_params.c +6b17861887b2535159b9e6ca4f927767dad3e71b6e8be50055bc784f78e92d64 crypto/dh/dh_group_params.c a539a8930035fee3b723d74a1d13e931ff69a2b523c83d4a2d0d9db6c78ba902 crypto/dh/dh_kdf.c -c9cb930fe7894703c1332af2d9fecbd515ff97ee1094c8ce9a705a8d916a0b70 crypto/dh/dh_key.c -3c364fa8d944a5f2d51af4377a7a07f3d8636dc04ffe63143e8d12ab66f6a019 crypto/dh/dh_lib.c -a9166c3cc60f4281e9d471c64145e0a78fc9dc43b8bc9e5de96d91eb7d277da3 crypto/dh/dh_local.h -5dd3bc53fc951a30eb3c5cb8be7121032d3f4f482ce48e7cddb05d571956fd20 crypto/dsa/dsa_backend.c +f859562a78e4bce1ef75398d1f215e48fe9223e8dddb7c76c495fa3eb67fdb33 crypto/dh/dh_key.c +7eae94965827bc5b0178269e85c77d6671c85255dc1f05e90b0f14500c765cce crypto/dh/dh_lib.c +8300775d88db0a1aa26a77eb49d6c4f7252e7fee69e1440de4c40edadc9da044 crypto/dh/dh_local.h +bbcf4fc3067ac462a27d7277973180b7dc140df9262a686c7fbe4318ca01f7b8 crypto/dsa/dsa_backend.c 786d6c65ced7ee4e25f5dd7c3150259ec95b6aa321a7590d905757b8139f8230 crypto/dsa/dsa_check.c ae727bf6319eb57e682de35d75ea357921987953b3688365c710e7fba51c7c58 crypto/dsa/dsa_gen.c -dee83cb278b3f712a62bd3477bdecf7b83e6df38ada2f3e1ca043d37327e2da4 crypto/dsa/dsa_key.c -daf1ed6345b83a416710c513b0258fe2382e23083ea17b51b1d6690390d55163 crypto/dsa/dsa_lib.c -02bd367be746e72268cc4df4adb069fe1b3bd570fc8e4fcd645ffbed56003132 crypto/dsa/dsa_local.h -602654e9894b3a4b7a1b48d93845338870543d6090eba1f6cbc2c1584afcba76 crypto/dsa/dsa_ossl.c +9978d27e9fc8ff152830ebb781f71338e56a5e116f29c1c2d59a5a112d86362a crypto/dsa/dsa_key.c +7d44106570c0ff9a44de874ea2daeaa87ea4c814fef6af0a26f655120a54f529 crypto/dsa/dsa_lib.c +f261f9d4f83ecc51ab58de89083e9af4ba4a4c922ccd06b0d628f4b60fc104ec crypto/dsa/dsa_local.h +d270b56fd894090319c9491ef745c34bc43add82daecf742916c64a4e956c765 crypto/dsa/dsa_ossl.c 3a38575de4b1409653f330f241848e6c7b554dec44c2415a5ae1baf90fb47ac0 crypto/dsa/dsa_sign.c 53fa10cc87ac63e35df661882852dc46ae68e6fee83b842f1aeefe00b8900ee1 crypto/dsa/dsa_vrf.c -103a3693afd8b1a9ba78f7e62a93442a87734419c9bb4a445590f675e86fcd7e crypto/ec/asm/ecp_nistp384-ppc64.pl -786779d7014bc04846832f80638743784a3850c7ee36e4a8062fe8eb7ac31c9b crypto/ec/asm/ecp_nistp521-ppc64.pl -1682a682f1e7d4c568dcfae1e24a01cb9ebfe4c4833b962090e0fd088027a684 crypto/ec/asm/ecp_nistz256-armv4.pl -41331cfcaa5c9c989fc7162e7d3af9e91779bd36d16de4d12b8f924437fad531 crypto/ec/asm/ecp_nistz256-armv8.pl -1dfc8df4833dd357544da06c6f846decb02dbcf53b61ffb365de868db77de669 crypto/ec/asm/ecp_nistz256-ppc64.pl -3c1c7b681ba3ea85b0fc78007a86ecedb7adc072ba1f0afdcf65dcdd95b8cd0d crypto/ec/asm/ecp_nistz256-sparcv9.pl +5335741d0f6c1afac107c9ec66e6b5436bd2164535f114c23cdc2a199560c28a crypto/ec/asm/ecp_nistp384-ppc64.pl +d9722ad8c6b6e209865a921f3cda831d09bf54a55cacd1edd9802edb6559190a crypto/ec/asm/ecp_nistp521-ppc64.pl +ce930c11deb991d6965b532e06f9354b3d8310d5b6db778a97c49acd85833eed crypto/ec/asm/ecp_nistz256-armv4.pl +c56ae5aeb89cc6158a30b953629b78c4d82c2379d8b05c0a6aaeb74505d20664 crypto/ec/asm/ecp_nistz256-armv8.pl +96c2348e134d17aa4b54016c58dcf1ebf3b6afd958298b704777163d776b4648 crypto/ec/asm/ecp_nistz256-ppc64.pl +1a099fff67ec42bd817d47b24f0f174198f7161f06770fd826d6bb7a0909e72c crypto/ec/asm/ecp_nistz256-sparcv9.pl 66064bb1a2cf6491b05c90dbfbf124298fc6a85db2c020dc65348bb9b7b52755 crypto/ec/asm/ecp_nistz256-x86.pl -c429416028457285cef0c24c5d07d4804eccef29b3be4efda37e8194c3fa9eb9 crypto/ec/asm/ecp_nistz256-x86_64.pl -e806141073aa3792e2748f6feeee6d3017124b3bc6059a9eca0d53a2f5785346 crypto/ec/asm/x25519-ppc64.pl -ce997e335e9c76f736434177907207b6799f7c161f54fad5d8be0a77b4bb77f3 crypto/ec/asm/x25519-x86_64.pl -2e7b5d2a3eff0b8a90c1de3f28a7bf59b1057e7694c0e36909e774343cef609f crypto/ec/curve25519.c -784c03c3f81fd0c363cd0500fbd95f3e49c65f47a249f7ba25fad42a41d3eea2 crypto/ec/curve448/arch_32/f_impl32.c -8e75602d4d492316d318bac147eaa09d87b0eeda0d450e18683d935673ab61b0 crypto/ec/curve448/arch_64/arch_intrinsics.h -4cccf81b42c6b8caff7a641280b2b01400c5ca94f8124eeca774569c19e155e3 crypto/ec/curve448/arch_64/f_impl.h -fc28c768e210c98e8d77c7c57c48eacede226083b95c58dd0bdfdc4efb12cbfb crypto/ec/curve448/arch_64/f_impl64.c -385a8c6b68b212ab7ea8acd47cd2e0601a0b3ce7356e28b84842aa9acc1437fe crypto/ec/curve448/curve448.c -92a1cca23f4c139e679f61726d17d475a5eae016460b9cdaaf5b2d996d940ca5 crypto/ec/curve448/curve448_local.h -6bc188cae67754cfdc9e4420ca2a208292f34c0c3aa5a25930146b92111e9640 crypto/ec/curve448/curve448_tables.c -8d6546f15baec96755625593a9bc7f781092fa4dde846ba6b488a31585b47a8e crypto/ec/curve448/curve448utils.h -490496e1c06d1f3ba9474ddd98e07fe11cac2838dd3937f35541f69ae798e67a crypto/ec/curve448/ed448.h -b65aa613ee9f74bfc7fd00be16087c431bdf092a7e6943238eee9e54ca3adf00 crypto/ec/curve448/eddsa.c -5aa20e2a4a9ae3a30d7400f3d666238f890004c3dfb66933873e7daa0026fe3e crypto/ec/curve448/f_generic.c -81ab2c5bcf5b036f649804f494e1b2ee5d5b2f900dd56b5dc55bac04a63a57ad crypto/ec/curve448/field.h -77bc6dd8c7d14a21760eb5e0dbf336eecc78835faa2f6f846824798303109d41 crypto/ec/curve448/point_448.h -6d007474cb42b16f98059f6eea6c09ef23552049207558fe46d071a613c8a314 crypto/ec/curve448/scalar.c -c0b5e93f120c7a5e0c0aba9877a445d0f5db85440491853b182266ee5f323361 crypto/ec/curve448/word.h -1f0ae0a59de6141ac9dc1b294444807555e3b6e747c7fef7314f90fba77dd322 crypto/ec/ec2_oct.c -5d3567b3b6d3922fd82641acff29ed12b1028e83eb0c175132ce7f3470b9db6c crypto/ec/ec2_smpl.c +afa4497cfbf9ef7805e42ae6a61c7d983e8a789b270d498a07785570ab85a9fa crypto/ec/asm/ecp_nistz256-x86_64.pl +cc727533130f5f1a29229929b3d4e8454585d647be25d6344f3c6a0240998368 crypto/ec/asm/x25519-ppc64.pl +192e5848fa0fb9e2902ffccccb3ad791c64832ed0f6ca6d335f0ad6325a1fa7b crypto/ec/asm/x25519-x86_64.pl +d0e81e6185fd589094e06854460cce0d070cc10901ff993c36312fd58420908a crypto/ec/curve25519.c +5daf9f524cd63dd95a2136535b27f2b3d90966562ea5766f4b2d1cd4fccf2502 crypto/ec/curve448/arch_32/f_impl32.c +063dac1e4a9573c47532123e9e03e3532a7473cc3e146521ba9ec6f486ddf3b1 crypto/ec/curve448/arch_64/arch_intrinsics.h +43423b7ee85a5c740c1d81499ee06f4a17732c7731a598e7429d5e402ee77cf4 crypto/ec/curve448/arch_64/f_impl.h +75c8103fddef2b6a1b43245e7b4fa2fc8507aacc61dd8916d1a28e1c28c86623 crypto/ec/curve448/arch_64/f_impl64.c +242421aa2568931f2d175a0cfd1ca3927fddbc31e89187417cce50ad6376a344 crypto/ec/curve448/curve448.c +a6c70707c520234ccd111562f012e1abf83c43b20b3b36c339ef1ea0369a9e5f crypto/ec/curve448/curve448_local.h +178fb9863c33174b633c2e7607160b1bedb506d66cc06d53382d87431441f306 crypto/ec/curve448/curve448_tables.c +f30e13bba5a136ab9ba5225c98b9b94c2cd73fb3aef60f9dcde3cd471cfa1ca4 crypto/ec/curve448/curve448utils.h +4a45e7828831fbe9f282f933cda54b12cd393ec9bffe5c0ace8e4d1c4d5d6358 crypto/ec/curve448/ed448.h +de75ada19d49a0943cc1badf4b258c4d827e6c33921a1a412f9a0e37f2728d0c crypto/ec/curve448/eddsa.c +9f712e7397b10f1dc88a6d18ff38dcda13d09c02775f3682f2b8698715b1095a crypto/ec/curve448/f_generic.c +070daafb9a532ebb8bc0af8b1341254f0cd3e8932a8c8a2dca7baeef6678768b crypto/ec/curve448/field.h +514014f9fa7835056aab1e6df5511fd7de8ecef3cfcada8e0eadec9b727b419c crypto/ec/curve448/point_448.h +1ff6e467d72530c71d21c310180d04a24f0a9cb41168fba94b43309ecdda3888 crypto/ec/curve448/scalar.c +3052a044afae2e91b677542fc8b34b3ec9d033e0c6562b0d43098cfb34ab3c9d crypto/ec/curve448/word.h +cfa94283c08faec8e030044c62ea083328cfde0e1b26089068dc772ae02ad129 crypto/ec/ec2_oct.c +9965a95c878438eb94bb0c21876b5a971f47b91f9d22f9c93cf7209a184cd1d1 crypto/ec/ec2_smpl.c a1f22814f501780591da20de5e724895438094824fce440fd026850c46ad8149 crypto/ec/ec_asn1.c -51e017af328480fb77119b92a2dca1a69dda90218ecbe05025f58efe3a89728b crypto/ec/ec_backend.c -3a3c4f4767513b4fbbabdea2918d7c7d105eb573334a7fd893b866989463c4d2 crypto/ec/ec_check.c -236f02fe2602088a3ffdb3fcd6a8211db4f2014246bc90c134ce472b80a15208 crypto/ec/ec_curve.c +805c42cf4deff93ceb8553c9d572f46e08d148a4de3ed8695a6db290b00b92f1 crypto/ec/ec_backend.c +7f19cebad4a94db291464b0d93006a87d15ccec93b94f725052a1037107a96be crypto/ec/ec_check.c +feb9d5ed7391d2d5a3096a0efc4188b5864737fa0eed35ce6894ba5118ec9026 crypto/ec/ec_curve.c 8cfd0dcfb5acbf6105691a2d5e2826dba1ff3906707bc9dd6ff9bffcc306468f crypto/ec/ec_cvt.c -c103eb5935688efb30a2112a29c069616268cd89e1aa74dec60ec95c53bba28b crypto/ec/ec_key.c -4518f19f669d02a25b757f54a7279fccf25bf86c0096734ce294e5d9b2d4b90a crypto/ec/ec_kmeth.c -bdeb873969ac1510e5361a3175e1cf7ac4aa0e23930348890264cc139c9fcf8c crypto/ec/ec_lib.c -aca82be16179cee0d452476e15e589cb9cde9492f44ace7c6f7038bea5ddcd58 crypto/ec/ec_local.h -34236e0035edf263c174c56cb5ac7066acedc0579521aaf60229794473cc1ed3 crypto/ec/ec_mult.c -c2a81f5f56d304038183ba6b02fdcba8767833f61773ec483e73b330b67ae59b crypto/ec/ec_oct.c +a0131da85d629419ef0763e98ac3377d0b92e6fbac26b1943a70de379818e2b9 crypto/ec/ec_key.c +97abe94cbfdc7857b421f75671b3d692d65a1df3312fc5b509d5765d584b3b52 crypto/ec/ec_kmeth.c +4c5e0cd2b6db049b41098ca7ea1f5c920926392f9fe356d076eae35002b69298 crypto/ec/ec_lib.c +9f86576ca885dd5523879dfdf928c5781bd13d2dbe626a90a785d04184c7a8bc crypto/ec/ec_local.h +652004a23a58c188a117dfd4b86e42cdb4f7cdda45fae0d675a6a3b718973bd9 crypto/ec/ec_mult.c +7a777b96560b44bbb9965f099ebc31ee6c8057b9778e854b0f9f3b4125f8dcda crypto/ec/ec_oct.c c7fba2f2c33f67dafa23caef8c3abd12f5336274a9a07d412b83be0366969ee6 crypto/ec/ecdh_kdf.c b86a943ae62145438a7214539ceb3e0de5a30e17a6e59742c6e30991db730ab6 crypto/ec/ecdh_ossl.c -f698d8d3f57b38e1ecd96ee06e76c503b4b7d52b07cd6927c0fdedc7b86036f8 crypto/ec/ecdsa_ossl.c -927661d7d67d93209ce21691d4604c25a3f643eef924e8bf1c03d29f196bef22 crypto/ec/ecdsa_sign.c +4f0865e8bd345bf8934d9002c059e4245b90ab4e34be46cf9616cc89c28c249b crypto/ec/ecdsa_ossl.c +b6baa42b16e8df69a12e0ab101033100cddc808ec2682ba1574373e6ec86ae93 crypto/ec/ecdsa_sign.c f686cea8c8a3259d95c1e6142813d9da47b6d624c62f26c7e4a16d5607cddb35 crypto/ec/ecdsa_vrf.c 141cfc1459214555b623517a054a9e8d5e4065a11301237b7247be2c6f397a0a crypto/ec/ecp_mont.c 13b30f34aeeb0c98747239bfe91b5f0f14e91b2c1f11db62ebb5950c7219daa0 crypto/ec/ecp_nist.c -27b2a6a86c24c044f354d4e09aa2217985e7e886aa0efdf7c1027d1d15357e22 crypto/ec/ecp_nistz256.c -d6e604cb04490bd604fbfca00a5095d62b1763ce0812fec7d3fad122a226e741 crypto/ec/ecp_oct.c -eaea07825ffaf1c7b6d0bf8c6e0786134ffb60f25ef2fffb5b5008b55980c4fd crypto/ec/ecp_smpl.c +32538e784c9cee98c9d876a994611d38d3cfa30cc4d9f1dd76410a746f7c0ec9 crypto/ec/ecp_nistz256.c +e007861f1fa98aa4e69c378f795e343bbff5efecdb5a5c4f817b655641587f2d crypto/ec/ecp_oct.c +45397ec2ff0138a831b1a1beb77159152d33fee2f1a727adc73b620ed1f44bba crypto/ec/ecp_smpl.c f58e722dfcbe74a1ed28ca0716685ce9dd3c49ca0e585d10adda3e7f273968c6 crypto/ec/ecx_backend.c 5ee19c357c318b2948ff5d9118a626a6207af2b2eade7d8536051d4a522668d3 crypto/ec/ecx_backend.h -8e50fd1e60ad1ac824e704375096e41f4ae535e533a3334d78c481e34d9d0fb8 crypto/ec/ecx_key.c -69635b077fb305700ef8e81dc91bcbd19feeaa978c6c8b57fb56ee07b0071069 crypto/evp/asymcipher.c -1f64d4752074f954af4f290788e4332e3874ba3282bd03d3e1d1f5ce4b0888bc crypto/evp/dh_support.c -51bf6d42b6c7bc1d423b2da6d94b8f91d6a4dd3d0a8694447dd48321cf4fd8b2 crypto/evp/digest.c -4ffc3fc5ee5f0dcadf1516f1cc29338f0f4d85c59881c06d5a777cf4e47a6d5f crypto/evp/ec_support.c -505690bb2efd19d6010ff4589d52d4cdc8d604d293a694469738bd600d1847e8 crypto/evp/evp_enc.c -a8e92e692a901523e9b0a3d4fdfd300d7f771e134ed48194a27bdcdaeac03efe crypto/evp/evp_fetch.c -49f272f4c8e59d2f031855786372e76c1c78a675eabbe9b43c686665183df3df crypto/evp/evp_lib.c -f19c24925525de7c5b08ed4e9689522b3d6c140501d6c5013f08384f8ee7794e crypto/evp/evp_local.h -dff5f95e7ce972915f260b6e0bb542b57c8a7771e1db9376b2fe8181915d2a35 crypto/evp/evp_pkey_type.c -bf235d15f96ec1b3a6a8f5857c4a1f74d14287e314a7bd2251ab5f9a71a0420c crypto/evp/evp_rand.c -0bdae4714221662282dccd5b1f2485370d24e463c11bdbb71a310f34616954fe crypto/evp/evp_utils.c -b6e8b49611bf8d04a703698ff44428fa4bbc6b4e3b5e1fd1078eb90d7e7b26f8 crypto/evp/exchange.c -0a2e5c9a4079fa408b6ff00b7c8b57f93f331de343c5898e240a136452404ecc crypto/evp/kdf_lib.c -aa0755dae61191c420032d7a4f2a5d753715d547c0e011e9e20a07c40fd7aad1 crypto/evp/kdf_meth.c -4e60c9e37106b9c28d646f7234d857e8520da953ed7d319531467d334b77a72e crypto/evp/kem.c -1cd1fdb9e1d569ecacdfa40e69e671538402933fd6fc9b78d16608ae12bf53e0 crypto/evp/keymgmt_lib.c -8b4c50066f33fe5006a23f220c43c387b9138fc183390623e8eea222ea304fca crypto/evp/keymgmt_meth.c -b68fa4796b20a4735f4779371859b27b5d55f145f791d7cade8ef90c7d85bca7 crypto/evp/mac_lib.c -8f9d191eda167c24fb579818d432dc12321fc559ba59b9be96ab4c9c3953911c crypto/evp/mac_meth.c -7b4d2ae311b377c5ddedf45db5212ef5a35fec717406316a18aad478b9c50cbc crypto/evp/p_lib.c -eb7ad84686854874250101adf52a3498c7e08ea63e5de17845d35f2a66461148 crypto/evp/pmeth_check.c -05c6934d0d8befa8f551323db31a9a908bba7e9cfebe1161a2bfb0eb4c3b36a5 crypto/evp/pmeth_gn.c -10de135d3bf315ea2f1e97a2aff46e0911dd074a3af5fd429a437192ea72f2c3 crypto/evp/pmeth_lib.c +2be4ca60082891bdc99f8c6ebc5392c1f0a7a53f0bcf18dcf5497a7aee0b9c84 crypto/ec/ecx_key.c +c1f04d877f96f2d0852290e34b1994dd48222650ac1121903cee9c259fe3ebf2 crypto/evp/asymcipher.c +80da494704c8fc54fea36e5de7100a6c2fdcc5f8c50f43ac477df5f56fa57e58 crypto/evp/dh_support.c +d72bcde40c4d3ab7d0db542242536e74c389a25dedd6910c7c006a1f75fc534f crypto/evp/digest.c +838277f228cd3025cf95a9cd435e5606ad1fb5d207bbb057aa29892e6a657c55 crypto/evp/ec_support.c +86a6ae91ec4cb6107a44ff67d149afa10f382277337a9db896d53d6b6a6fa311 crypto/evp/evp_enc.c +baccbd623a94ba350c07e0811033ad66a2c892ef51ccb051b4a65bf2ba625a85 crypto/evp/evp_fetch.c +ae6cbff7282d19441f660417b7308165bcd47a3db4341ebd107b6247fc6af052 crypto/evp/evp_lib.c +2716c6bec51ceea0ac4fe87a0d38cdee06127d8419b54b16deb5e9cf33136de5 crypto/evp/evp_local.h +9e833e8919a1589a519c7c6cfad4ef3d24cd7e57a5d2eb89286853796e79bbfa crypto/evp/evp_pkey_type.c +9b8346eeff6041d254b6284be0bebd21a4fe2d5143a3edea1b55c64506a258d2 crypto/evp/evp_rand.c +2a128617ec0178e9eeacbe41d75a5530755f41ea524cd124607543cf73456a0c crypto/evp/evp_utils.c +04893844daea9714b0925f39a76852b6d65094f4cab5240c191abb87690aa347 crypto/evp/exchange.c +03fa174160cac5a119963ed467b615c3557a127adf2aa8ac1b34366cfb62c1b7 crypto/evp/kdf_lib.c +c4534f118b93a22c496acf1545b301666ab02ff86422b91b705f638da627faf1 crypto/evp/kdf_meth.c +948f7904e81008588288a1ba7969b9de83546c687230ffe2a3fd0be1651bce8f crypto/evp/kem.c +611c918a4fe292b66f7f61cd00225eb439d3a3b3121d8cb1f355d0d49a89e586 crypto/evp/keymgmt_lib.c +d57908a9473d2af324f32549649016f7a3c196b5ac8b54d6ca3c82f84cab5d48 crypto/evp/keymgmt_meth.c +9e44d1ffb52fee194b12c50962907c8637e7d92f08339345ec9fd3bd4a248e69 crypto/evp/mac_lib.c +cd611921dc773b47207c036b9108ec820ab39d67780ba4adc9ccb9dc8da58627 crypto/evp/mac_meth.c +4f0a9a7baa72c6984edb53c46101b6ff774543603bec1e1d3a6123adf27e41db crypto/evp/p_lib.c +3b4228b92eebd04616ecc3ee58684095313dd5ffd1b43cf698a7d6c202cb4622 crypto/evp/pmeth_check.c +759573aea2a4cc7b6f763b440e6868bfcfcb7ca94d812fa61ab24a194be2cb36 crypto/evp/pmeth_gn.c +c2c8f6d17dc3d85ffcced051047c0b00ce99d119635f4626c5c6db3d59d86fbb crypto/evp/pmeth_lib.c d6489744c04a80c3a8610db90a1b02bf1f4f672b877de3d4ddfa733c0baee8e3 crypto/evp/s_lib.c -58fdb0b2219c8ee148189574ea99307d0ebd45f6f0c502fc23b1b25b013387bb crypto/evp/signature.c +3c003fa01341a69c461b75cffd93cf31a1899373d7e95a1ef3754ea1bfbb77fe crypto/evp/signature.c 30af153213f8b008955486000c5a92507dc694c4af9ac6ed6fef3f290efa3e52 crypto/evp/skeymgmt_meth.c -d40ee57a311a8aed79b1995e4667c6191d4a6d073eec343a6d9ce432830e9a16 crypto/ex_data.c +cbad05b50fee47a8e7b1e28fa16ba773b600568644a2767759e469ea3697a592 crypto/ex_data.c d986ec74995b05ff65a68df320ab45894ba35d7be4906f8d78ca5fca294a4e6c crypto/ffc/ffc_backend.c -f4f84cade98907fa9905334b6c3c046b430b12b1460edac0617d82ca763620ab crypto/ffc/ffc_dh.c +a12af33e605315cdddd6d759e70cd9632f0f33682b9aa7103ed1ecd354fc7e55 crypto/ffc/ffc_dh.c 854378f57707e31ad02cca6eec94369f91f327288d3665713e249c12f7b13211 crypto/ffc/ffc_key_generate.c 4e973d956d4ec2087994de8e963be1a512da1441f22e6e7b9cd7ee536e3ff834 crypto/ffc/ffc_key_validate.c -06f7749102b9917dc9c28e46055c5066acb0fdb2ee5b53cceb828d292d1c5542 crypto/ffc/ffc_params.c -9d56d969bb1f1aa6f85d52339588f0f4a92ea4de24db697b2a8af67b0bf754a4 crypto/ffc/ffc_params_generate.c -e9a500ddbe96cb5b302fd2db74fac0924a6ac45732df5ee1c09e82b19d06ccfd crypto/ffc/ffc_params_validate.c +e032f3d46830d31cd957e1f3917a6a663c5ad3b9d79fc3d661f025822318d0de crypto/ffc/ffc_params.c +b403411e8a3e1f9689c87c84362949e47df352587f678796186474d854d9ef4d crypto/ffc/ffc_params_generate.c +73dac805abab36cd9df53a421221c71d06a366a4ce479fa788be777f11b47159 crypto/ffc/ffc_params_validate.c f172c8c2112ee82716a7bc3a3e05d5cc26188c66b9d768ac1ff906845063d2cc crypto/hashtable/hashfunc.c -49599084eb85f841718d3b3821b794c9fa44566397fb2812d3b7f1795b8c66b9 crypto/hashtable/hashtable.c -4349fd4b1b6cb4f19a43e25346aa4f3372351822cad753fb1884d9de911e4c14 crypto/hmac/hmac.c -f1e386f65db354b5a0c4248d3df6ee690881aaa3fd4049fdc443f9eeb635f8e7 crypto/hmac/hmac_local.h +00bd8766d2ee687c37616887595c59ed40636a2543a50814785a82c97e878bd7 crypto/hashtable/hashtable.c +7a9af0b14f1463b36de0689bc434a318adcb7990bb23862bf1d2a0adf510583a crypto/hmac/hmac.c +df7ed80c3c2c0df4bf6a3d5379655d0ba9147d4f4e9f7509672bc9273f163bb8 crypto/hmac/hmac_local.h f9743f1646fbd8b61a2dd0422f42934912c1bfc95f6dcc38fa0a567e3e6b4e95 crypto/ia64cpuid.S -99727373714d17bfaadf837581cb82b95100604fabb5926c22dc68e4fda08d57 crypto/initthread.c -863a23d7441e71e065c4d1a29c17eb2e575bbb03ab31407ead9e7ad2c16a2c9a crypto/lhash/lhash.c +62010f74754e83128cd0c5c73608102e8079dd1fed5d7a9136f8aaa2524292e1 crypto/initthread.c +7dc60e4bcde1aa77f58e497a0a2a44cb250c09011698c2afe218dd8d09cf5dae crypto/lhash/lhash.c 22261096a117533e78012f5f18586b6a81edb3e09ae8b206b5eb9a0a5c054adc crypto/lhash/lhash_local.h -f66ff2d5e6fcf5c858b46bce16ee991126d362df0bc0ebe26213272c7f02db7f crypto/loongarch64cpuid.pl +899ba6a9049a61d5b175637907f747f58863cd8950409cefac8fbc8f574f970c crypto/loongarch64cpuid.pl 460a7af09cde89a820b091522ada1310cfcec99c60aee505f94c48c35e9a29e8 crypto/loongarchcap.c f866aafae928db1b439ac950dc90744a2397dfe222672fe68b3798396190c8b0 crypto/mem_clr.c -5e33547e2f6775a89701b311712e6a3ee6e2a64a8f283eae9e61a4a01c392e69 crypto/ml_dsa/asm/ml_dsa_ntt-x86_64.pl -3d0191bba6c23ae191f7a63fe7c2229a00de3f9aaf0128f5503d4e20bd2d1cda crypto/ml_dsa/ml_dsa_encoders.c +aab72268e228e80fe800a72f78a7a1df5dbfa1a03271d518377d127ae07e56d7 crypto/ml_dsa/ml_dsa_encoders.c 825105b0a2c4844b2b4229001650ff7e61e1348e52f1072210f70b97cd4adb71 crypto/ml_dsa/ml_dsa_hash.h -24455e1918d8efd3d99b6ff77f50c2df5d156cc645e80eb8e56960b3429b9769 crypto/ml_dsa/ml_dsa_key.c +026458ffad6db0d983a87a34524125dd2cfe35978ced4000dbdf6c5ec15d67f4 crypto/ml_dsa/ml_dsa_key.c 579c1a12a5c5f014476a6bf695dc271f63074fb187e23ffc3f9ccb5b7ea044f1 crypto/ml_dsa/ml_dsa_key.h 3f98eb0467033d0a40867ef1c1036dcfea5d231eeac2321196f7d7c7243edace crypto/ml_dsa/ml_dsa_key_compress.c -01d9ba6431280512b96b0344780cee9fbbfa7c6744b7535491165cda4223f7fe crypto/ml_dsa/ml_dsa_local.h +88235d31a02cfe21955e10ae2df70d50937ade5eea5e0c26810d9c285520c227 crypto/ml_dsa/ml_dsa_local.h 0490a89372b79d98c2fdc294f836fddd7a54a148202ffbd50c2d4371816a94d8 crypto/ml_dsa/ml_dsa_matrix.c ff65c82c56e341f47df03d0c74de7fb537de0e68a4fa23fa07a9fdb51c511f1c crypto/ml_dsa/ml_dsa_matrix.h -3cd70debaa737f8edc87fd636545b9fdbb973a631688b273dd7986dadf12b651 crypto/ml_dsa/ml_dsa_ntt.c -3e0980e67842c4d8637fa449ac41e9d650c614c1074c29f1021605d229a4f73d crypto/ml_dsa/ml_dsa_params.c +5367cefcf6cdfc4f301e719ce884910f86b31c84b27e2a7337aae43af8623205 crypto/ml_dsa/ml_dsa_ntt.c +5927088185ecfdbfec666fb252162e11e7dbccb67320683b14349a189b770f8d crypto/ml_dsa/ml_dsa_params.c 10e37ab3ee09a45d99007665e073efb2b062c819f30af8694c6b0f411eb33822 crypto/ml_dsa/ml_dsa_poly.h -26be5266a9f1a33999a5a68c96cffc7932ba64521d9554dabe7397591611c852 crypto/ml_dsa/ml_dsa_sample.c -9e57d844f2acedb490b6e8f32e125240078ddab380a7faa533baa9c447dee262 crypto/ml_dsa/ml_dsa_sample_hw_x86_64.inc -2127303173eff12cb2b71f92179d10370b555c26e7a305e87ce7066580d57689 crypto/ml_dsa/ml_dsa_sign.c +672a4ff05096f5253afd0f4d8447c298299c1901a1d052e64e41daa5c8ddcd27 crypto/ml_dsa/ml_dsa_sample.c +28e2ed9d2b3b59e62f24f17a64067fd9d52fe803fae0bf0ae09de456375f4beb crypto/ml_dsa/ml_dsa_sign.c 5217ef237e21872205703b95577290c34898423466a465c7bd609b2eb4627964 crypto/ml_dsa/ml_dsa_sign.h -e3ef4cf1598420c94eee4f53d13491ff0f9dc8cfb1fe1cacd3a1225e2073fa56 crypto/ml_dsa/ml_dsa_vector.h -15e663f9d706812e7e89207fd0c4050ff82d02e06a868585f1e77dee431424c5 crypto/ml_kem/ml_kem.c -6906e197c84ae0d828748d47c47d565fd912076c35a65ea304e306fee4a17157 crypto/modes/asm/aes-gcm-armv8-unroll8_64.pl -a1d87ada629d7c1e487524f475b9c2b01a700d981e092ef6895e3f32d2dd79e8 crypto/modes/asm/aes-gcm-armv8_64.pl -6b98d90b233d87f4d99f54a553b242199cd621f9c09b5cf64923831cd98ba054 crypto/modes/asm/aes-gcm-avx512.pl -7ec48551ef004c2f48a51c46b31c1a5f5b88c1075da4e7860def699a58b2a000 crypto/modes/asm/aes-gcm-ppc.pl -b7104ee749d555127a08609c7df5056b56d9aee19c90f3c42b42d69cf7caba03 crypto/modes/asm/aes-gcm-riscv64-zvkb-zvkg-zvkned.pl -85574283333dcd839873770c4d7fb309afc978059c623dcab1a4a40e9b697312 crypto/modes/asm/aesni-gcm-x86_64.pl -0d10ce3c9ee1016312ba124de3beb8740bc13d5a1bc06dd6c4693a22df05e954 crypto/modes/asm/ghash-alpha.pl -9b523f96aa97bbb50c0102caee46d5b07d68aabd8b606bfb148aec88e125681c crypto/modes/asm/ghash-armv4.pl -326b715e289adc979840d8037cce526e6ec4d0917495c75ffc53e78ed39d8ed0 crypto/modes/asm/ghash-c64xplus.pl -4fa4a0dc1a96252f6c2369ee55ad753e6c41402d3e8cbe7afeea71a7e35c9cc1 crypto/modes/asm/ghash-ia64.pl -175c15708f8749fdd8f85f729ced44e8c2bd1d42528f5f1fbd908c71213a07ae crypto/modes/asm/ghash-parisc.pl -9140d35aa157dae5c98b2c950248d15dffddd16c11a0f092c4a79b0a460b2d54 crypto/modes/asm/ghash-riscv64-zvkb-zvbc.pl -c786210922836f2ee9f7806b6cb7a5749511285004cf7eed95b3979bf5685bb7 crypto/modes/asm/ghash-riscv64-zvkg.pl -b353c76f30ed3bcde79e1280a53acbd7172d1924124c33bf2fd5830396e7ac0f crypto/modes/asm/ghash-riscv64.pl -03269b327d5055e7c37992e989b75e1e6cbdf3878a6709f8ffd8e3e13d171e07 crypto/modes/asm/ghash-s390x.pl -920385de6904c52e69d093d5abb75774964e46f96d343262b88a58aa8e7f64d7 crypto/modes/asm/ghash-sparcv9.pl +4e4eeb5260a576bc0f88038519a520e5ce471dbfdd96d854ef619092ec61db7e crypto/ml_dsa/ml_dsa_vector.h +fcc024d468a5cf5f591e84eeff31a54093aa5409eb59c3fbc5ec02199ab206fb crypto/ml_kem/ml_kem.c +36e24eae5d38cc9666ae40e4e8a2dc12328e1159fea68447cb19dab174d25adf crypto/modes/asm/aes-gcm-armv8-unroll8_64.pl +eb5b284f4c855fdfdefd96ce90280f53e5975c962fb783f8691bec278c9523c0 crypto/modes/asm/aes-gcm-armv8_64.pl +bcc09bdb474f045d04c983fa09c31a010c5a25513f53a5d3653ade91304f0f96 crypto/modes/asm/aes-gcm-avx512.pl +400a202abf66c6a3430965c38f7164ac297c856e8585862f59e3ff188bb35a6b crypto/modes/asm/aes-gcm-ppc.pl +dd0de5ca8913a941cfff781a42fba43227e133976a24d0fddebf63909f7e010a crypto/modes/asm/aes-gcm-riscv64-zvkb-zvkg-zvkned.pl +e323e10e5b5faeed773d066dc5e726344cd34fc4b4b266060b42d81a96c4eefb crypto/modes/asm/aesni-gcm-x86_64.pl +6d5d8d7d3cb1c7378156129b19d36633e845d1d15de73e45a407e45ebd06bc3c crypto/modes/asm/ghash-alpha.pl +2aa73edaaeabaf8d8fa6941d496ed872a1afb0eaa3cce15b3d1602ef7ac5b997 crypto/modes/asm/ghash-armv4.pl +bf7553a03c9fd058a7432c4790e661de464ebf9ff26e303af4dd0dc52c5df478 crypto/modes/asm/ghash-c64xplus.pl +2934a53c930f252539fc114615ac34f9145d2c92abc936095e9afe2e811a218b crypto/modes/asm/ghash-ia64.pl +65bc6d4c2405e1b51dc3a498eb4557436536f041cbd6c28d8ae7f6816ec1e02e crypto/modes/asm/ghash-parisc.pl +e6d6ce559210aee1e97f098683e290c221cc90f6f4f8047b331e8071a8387559 crypto/modes/asm/ghash-riscv64-zvkb-zvbc.pl +4c960949a5b7688f9019e177c24382dd1e78f6d343f3c4326bebbc065eb3a9f2 crypto/modes/asm/ghash-riscv64-zvkg.pl +494b4b36fd7c7d0e464be76f723c46ae7ad173593ff0556525edfdc974e66c32 crypto/modes/asm/ghash-riscv64.pl +6f80fefd05ed63ae57510c37ea0061186909805d1f5a098c2c5baf7316b29453 crypto/modes/asm/ghash-s390x.pl +03d95074b4c669291b15c7100a56800201c270a8481307fcd284dd51974671fd crypto/modes/asm/ghash-sparcv9.pl f41a5e32029807f239a10f39573033149266564bab65c0e460b2b4dbe75e1ea7 crypto/modes/asm/ghash-x86.pl -b2351b8097fec165e8d467b395b6334283857f04817e0960bb11a3dd0baaf732 crypto/modes/asm/ghash-x86_64.pl -270757e9893c605162a1f96db1927aa2a98b758a640a6f69cbd124433c9e603a crypto/modes/asm/ghashp8-ppc.pl -6046fa0334247fa4a2d57dcfb5a7df4ad3b4208b74f4ee9b94f168556a59531c crypto/modes/asm/ghashv8-armx.pl -ca4be187fc1805d498f2adb823509f0519e214644029c18d331b5b01a0891a9d crypto/modes/cbc128.c -979ec7af2df2bd6cad5218ba1dac44316e04447c0a1420bf849ad2ee3402a373 crypto/modes/ccm128.c -00d68c071ecc99c471ec0af7e393f5b5ad38bd89483227291cf4cab08ad74964 crypto/modes/cfb128.c -2a0ab07286b70ce4aa0caf3b5b4be2c00eed3a6d855e9542ae94d0e1f586b1e3 crypto/modes/ctr128.c -59be0f955b16434efc2618109a01571884c6876af785f1db5dad69786124b341 crypto/modes/gcm128.c -b431ff38c3a85943f71be0d76b063dbe2930967629b8721465b8152ab7867296 crypto/modes/ofb128.c -79e5e7f10d5b0709f119d1a0a9ed26e35649e0ce087ecfadc269be027b62c11e crypto/modes/wrap128.c -0a10e0cae6f4ac164afe97a64df09c8412145c8a25f387ff3a53ff7495572cbc crypto/modes/xts128.c -9a34ad9ae361f689b0b98c454092e89567d0bfc969c08a14c8001e60976920b2 crypto/modes/xts128gb.c -8bb331184f903c84f6959abc106c4ca13acd6d461f8cf6bf0ff454224510fa94 crypto/o_str.c -44594139dab6ada1f34f9c6887c97e258c1204b833a6c20f58097f17d0f1645e crypto/packet.c -2041b36f24c4a9dd2bd5626a49638f00f473867654692be64c836f30d6c6a70a crypto/param_build.c +54a5a37c8cf154cec47d5441ae20913f3b4045900308bd972b38a0ac99155a46 crypto/modes/asm/ghash-x86_64.pl +a19f8e9e1c1a45a4052df6d87c1a1acec56af7676428b7b3e306e89b5c5f603c crypto/modes/asm/ghashp8-ppc.pl +844cc3ca1763b368d206dd5466b9ac132aeb66b0a39cfe6c4651e8f4e7bf3a3b crypto/modes/asm/ghashv8-armx.pl +65112dfe63cd59487e7bdb1706b44acfcf48ecede12cc3ae51daa5b661f41f06 crypto/modes/cbc128.c +1611e73dc1e01b5c2201f51756a7405b7673aa0bb872e2957d1ec80c3530486f crypto/modes/ccm128.c +d8c2f256532a4b94db6d03aea5cb609cccc938069f644b2fc77c5015648d148d crypto/modes/cfb128.c +af1c034152d82b29cb7c938c8516cfd136b62bac0908c1d40eb50790d23b288c crypto/modes/ctr128.c +d4ddb087eb4dd54b8e37a414e32d8a2d4e42a7cf2766fc2051e4e31acdf3419c crypto/modes/gcm128.c +bdf25257b15eca206be4d950d2dd807ca5f058f91f54edbd7a0d312ed83eef8e crypto/modes/ofb128.c +6f0cb7b070020b861c7f0ded294db96842d8bd8d47e084383f55450f71844634 crypto/modes/wrap128.c +608a04f387be2a509b4d4ad414b7015ab833e56b85020e692e193160f36883a2 crypto/modes/xts128.c +fb874ea18e9754dde11ef1c2993818074ff7cd8a74a981598745f7e11317bb91 crypto/modes/xts128gb.c +e5cd64c7f3c7cb356e3f8bffad74c0db6c2e7e94bc59bd3f44bc683a25e9b806 crypto/o_str.c +b0decda3aae1d3e07cf3cbe9153cdde9deafe65fae346cd208951b4d7dec512e crypto/packet.c +60e6d32dc11056774e9ee4a90e12ebf704ce5ac70430a2748b455ea34044198d crypto/param_build.c cae7bd4973d36edbdc3bdd8d2c8d157f2c4fcfae00fdf821b67aebb789bc8aa6 crypto/param_build_set.c -d880778d542d5d4d1788ac54df26bb842726d3344d8f1b83254c9e36bac20ab7 crypto/params.c -538c45b8c28e54a0ccc7c3ca446ff5cedbf8ed711b69d67dba7e1acc3327fc80 crypto/params_dup.c -6c193cfc31c3ba5d6234a09d32198a15ab8a40258824ad7d79ac9fed8faf54e7 crypto/params_from_text.c -f30334eb0a8679a4b605ac74d65c479535475b4fb6749db9153215cbaa8ab741 crypto/ppccap.c -bc316512d4f520323fdda48c5236799b7438db66d1743924ee731df68964ba11 crypto/ppccpuid.pl -42eff8da564cd8004f2d17fb01686d24977d931c37c7e6de693e7d414c2d7914 crypto/property/defn_cache.c -384339a8b418f2a773eaa6aa6d030f2f09ba519627b6a228ada125e905fb8431 crypto/property/property.c -7f936270992015923e5f6e81b1afad0148b9034693d3cf4665465f839a28c81f crypto/property/property_local.h -71ccd54b74799afe44ec12e1ec8b6b7ece60bc25a00b9b49044ade025a2c39f8 crypto/property/property_parse.c -fce93d3e7da046501120573317248945945845a7aca1344e36a386d44504f441 crypto/property/property_query.c -5b35510efa119157e9e217996870778d1ab5f69612cc1bcc8a6df372a625e875 crypto/property/property_string.c -f2bcb311e4725e4b8262c2c9d4670b2891882d8eec8b3a4cb458bda17356ed8b crypto/provider_core.c -aa58d7800d3ccf2989b0de3c2e2710dfac36c88dc51659129897b0dfd2162527 crypto/provider_local.h +ea01893e8b4feda1a4b74f0de1e6b4c0da0c5c4c1bc1890b563a8e33e6a02005 crypto/params.c +385863ddba305bea8e4a36c7860cbf6609d4a0017107c3d628214b4219860504 crypto/params_dup.c +ca9bb61d232c61d9a43fdfb92c1103f50d1abbaad7c1182e732aeefd601d6906 crypto/params_from_text.c +a15ee1e11dd899f7e6075aa570de983f756be530230576551542716c9a8122cf crypto/ppccap.c +56699c7486998cb6c4979eaf79affafe528aa0d7e3b9ec38d7f52091c447a4e6 crypto/ppccpuid.pl +467c416422ecf61e3b713c5eb259fdbcb4aa73ae8dee61804d0b85cfd3fff4f7 crypto/property/defn_cache.c +6e168862d94654433c6194fc63956a229ab941f6008bf85b3b1ec3357e64693e crypto/property/property.c +66da4f28d408133fb544b14aeb9ad4913e7c5c67e2826e53f0dc5bf4d8fada26 crypto/property/property_local.h +d32105cb087d708d0504a787f74bc163cc398c299faf2e98d6bb5ae02f5ce9b7 crypto/property/property_parse.c +a7cefda6a117550e2c76e0f307565ce1e11640b11ba10c80e469a837fd1212a3 crypto/property/property_query.c +20e69b9d594dfc443075eddbb0e6bcc0ed36ca51993cd50cc5a4f86eb31127f8 crypto/property/property_string.c +d991d3c4386c30e2896ecfea5de9933df0e26b14616faf531b9f87526c3c3293 crypto/provider_core.c +d0af10d4091b2032aac1b7db80f8c2e14fa7176592716b25b9437ab6b53c0a89 crypto/provider_local.h 5ba2e1c74ddcd0453d02e32612299d1eef18eff8493a7606c15d0dc3738ad1d9 crypto/provider_predefined.c -082be396f304ad23859ac18c819661958825a7e4e181e8fba20a4df654ea3cd2 crypto/rand/rand_lib.c -9e162caba63741e3df4d0f1c49a7555263ebc120cfb643546ea7e34d3f5eb862 crypto/rand/rand_local.h -dce7413b4c4e588c9a099c6fd7c6c9a397e034f259a2027d4ea8bdfe149164fa crypto/rcu_internal.h -6ff9cac4f1fe14d1b588f952391bfdb8c982d97c32d21a1894c26537ad76ca0b crypto/riscv32cpuid.pl -b7c97c6ae3468d0d86005adb0939263164d37281406cca031a120a21e506dece crypto/riscv64cpuid.pl -576bff6e8284f6102ab5affc6dd9c4fa518febb1e5dee482f55a9bf37a0d94da crypto/riscvcap.c +ea24a6609ab1e568bd54705cb34d9d95fdfce4bfcec194b3e0b463c05d5ac1a6 crypto/rand/rand_lib.c +fd03b9bb2c23470fa40880ed3bf9847bb17d50592101a78c0ad7a0f121209788 crypto/rand/rand_local.h +426ba915ca65a770f8264129f8ac47db7aaf06c6ae51517c5d775eacdf91b9f6 crypto/rcu_internal.h +48f6a98e3d7e9ae79f2d2b8ea9965d0c4ec3b1a4473adbceb47fe1e7930dc3c1 crypto/riscv32cpuid.pl +f6c5a1440de995a115dbba5f732b294e2e6d94aa520687afd1e776af1ba48cf8 crypto/riscv64cpuid.pl +f7f02baccd013f5d59907ac4efd03b5b64476a57ff6ea635c1a68ee8c473fe6a crypto/riscvcap.c f0c8792a99132e0b9c027cfa7370f45594a115934cdc9e8f23bdd64abecaf7fd crypto/rsa/rsa_acvp_test_params.c -f6d0ddac7d1402595de729dc80b39a4f7e7970be177e3732218dc7f28f0638b7 crypto/rsa/rsa_backend.c +1b828f428f0e78b591378f7b780164c4574620c68f9097de041cbd576f811bf6 crypto/rsa/rsa_backend.c 38a102cd1da1f6ca5a46e6a22f018237964336274385f5c70cbedcaa6997647e crypto/rsa/rsa_chk.c 793fbad15585312a0a1452eaea2c7590c6bdb4a8d8083eaa0ed0539b5021f913 crypto/rsa/rsa_crpt.c -ca8d150835c483801a06c347a5f90ae798183b5cdf552f3c8bd45fedb0d176de crypto/rsa/rsa_gen.c -fe5ed26c0481b13b499fc2db1768e732f0f50bfe20ba98e8f12efed9ce3579e1 crypto/rsa/rsa_lib.c -47b04c9ec369f85037f78a5f84f281180eb99c91518f8576fe92c7a3b21e1181 crypto/rsa/rsa_local.h +82b6e51e49e428121c2021861eb864d481d75d462f068e3525fa98f1f31facd5 crypto/rsa/rsa_gen.c +d6d6c2857f53466ede80f60b5ef7127f3132b0d93fc929936070f315792adb18 crypto/rsa/rsa_lib.c +160b227a515bd9fce0236d9b319cd33288353c0fdb615a5bf83c88aad1a69b46 crypto/rsa/rsa_local.h cf0b75cd54b61b9b9a290ef18d0ddce9fb26a029a54eb3f720d9b25188440f00 crypto/rsa/rsa_mp_names.c 5c60f6e05db82e13178d805deb1947b8eee4a905e6e77523d3b288da70a46bb5 crypto/rsa/rsa_none.c cf7e95467a6e6681069ba0c6a0befeb631b499d9b2ab12db0e93967746686f11 crypto/rsa/rsa_oaep.c -9127300e1cf79310b44463ded80e5bc6c22a7abb3e58f187c0945b373b37aa94 crypto/rsa/rsa_ossl.c -a7e1d7e68d93c1956d69547e2ccf7052965832a2254b2181cdb80580cb76059a crypto/rsa/rsa_pk1.c -1ab7069966decfbd479179f137d6d33be2b48eaf4aca5a44c996e86df7aee7d2 crypto/rsa/rsa_pss.c +5ae10535cbef84f64799a434509e466837120a6e30ba0b7919e437accb47c3ed crypto/rsa/rsa_ossl.c +54446a41065d85d22ed521285196bf285427a071d32d00d070b2248723c2a914 crypto/rsa/rsa_pk1.c +b0fbf0b55d2afac9b1a1e871bf8cc6f0a41b34cf695c393d97e716536928931a crypto/rsa/rsa_pss.c bf6d300b7e7e9e512a47c5bd1f8713806ae3033a140d83dfae4a16ad58d11170 crypto/rsa/rsa_schemes.c 58db0509f34d970a2f206d468f718c17513970315d5d5ec92822fe6f4b6523fa crypto/rsa/rsa_sign.c -5ded8ea2bfd59110420f865699a2036e59ea5d2c547d02d751b20aa415fb3050 crypto/rsa/rsa_sp800_56b_check.c -05a1b9e1ab8b456d6b1ee35dd28a535e3bfa00ae23b87ffe5ba62109a391e670 crypto/rsa/rsa_sp800_56b_gen.c +83529424639f77832d2c189c0134ce514b35a296567ac1a2936a9c4ed6407239 crypto/rsa/rsa_sp800_56b_check.c +dc0af42319118811e1fa250f1647634f510f9ffcd720ea5141db4fd090938c46 crypto/rsa/rsa_sp800_56b_gen.c 1c1c2aeeb18bf1d69e8f134315b7e50d8f43d30eb1aa5bf42983eec9136a2fdc crypto/rsa/rsa_x931.c -230546c5b027d30d42d90f5143014a158daf007a9e113fde56c3ff60555ee36a crypto/s390xcap.c -e754a236fe8a7b90f3280d9e22301571ed337c81a2fc120e2355d7d89a0bbd21 crypto/s390xcpuid.pl -5208fa95788e28d0ce9a22a6199329bf235a203bc70c3bc4c5aa0ba1052d56ae crypto/self_test_core.c -3e5ee4eb747472c88551edd6a48eb7b4330a4fc452eea263ad8aa4255df0000c crypto/sha/asm/keccak1600-armv4.pl -87ef49f2f47357c1f0912b22eca1305641a5873a4d959379140e92a7432832b1 crypto/sha/asm/keccak1600-armv8.pl -7c27d9c9da79214ccecb240629019f4e2debdba27210f5170a6f3a3857bbe94c crypto/sha/asm/keccak1600-avx2.pl -143130638124b6d07f3bc4f8677a286db31d524a71625152629eb1f9bd434a53 crypto/sha/asm/keccak1600-avx512.pl -b7f1f4e69d41812dba39226aea0942fb2e3a638308c3130b0c83bb636a258ce6 crypto/sha/asm/keccak1600-avx512vl.pl -18e5996c0a32335587b2f06bc0c6071acd2c1f9e94d9ea284d02dcffc7879dcb crypto/sha/asm/keccak1600-c64x.pl +b0bf39f5c40876240fb1b553cf169f7584292914db4f128af66b21e4eaa6d2b6 crypto/s390xcap.c +8baded2ec53fbd665a580287a7f29ae91490a552a4f39c747b95a54e57e6413a crypto/s390xcpuid.pl +c865dba12debe9ad4a0f0b8c078b5c3e614c83a851cf9666cd3c4c7a9992f319 crypto/self_test_core.c +380cdede57f70da1a0e22ed0be1ebd88c10d59bd8e0e426df0e856c677ca8fba crypto/sha/asm/keccak1600-armv4.pl +d97807a176b406e544d24747b785ea4224bcdd4f04a3fab7e3347c4c6cac52c7 crypto/sha/asm/keccak1600-armv8.pl +d56474cae546601c705ea1bc4638c75b3d8e6d88907a59fb4bdff56c2980352e crypto/sha/asm/keccak1600-avx2.pl +c9b0255759ec71ce0ba8943663971889f1cb95d6d0285061a30d91f530485edb crypto/sha/asm/keccak1600-avx512.pl +4b8c44211d1d9262e992a2acba093a5358c166628facf168600ac943d2620de9 crypto/sha/asm/keccak1600-avx512vl.pl +964e9cc9f3eecc272e540a1435834d6ad337314c840f65a87bb656acd05b585b crypto/sha/asm/keccak1600-c64x.pl 2395b8b2e66dcfe8edcb402275000f6e0b2ef360f702c9af6b9bc94d7f1dc159 crypto/sha/asm/keccak1600-mmx.pl -520154ccd4914696da01fa63c0edc814ae31ad3d61dc8923fea4dd87d8ba776b crypto/sha/asm/keccak1600-ppc64.pl -82a84e6ae5ffe90e76530de560f6261c5004c23923fa9fd9aa2aae3852976426 crypto/sha/asm/keccak1600-s390x.pl -e485942ed7f7bf1f376059ed2e5e194907348f44a4308dfc4bbc2d8be05fed99 crypto/sha/asm/keccak1600-x86_64.pl -af173b53537e18453705a3843e0629334b37e8ca03483a2b164fd48252289da3 crypto/sha/asm/keccak1600p8-ppc.pl -d27078e0478f34536f596e037887ad673b05537d9cd4b79376e902774a4c8340 crypto/sha/asm/keccak1600x4-avx512vl.pl +e00d9184904272baa04ab3102e8317afe607316ddc78db5c855889e3d672b689 crypto/sha/asm/keccak1600-ppc64.pl +79b73441ae0313c64a07d9d93552a85dd0df557105ac4feef3120e3920267a07 crypto/sha/asm/keccak1600-s390x.pl +76af6d6e11c85785a3f18bf3c0752720a0f4dd06a446bce727f497c7433e830c crypto/sha/asm/keccak1600-x86_64.pl +477aad2b2a0c2c37a7c77954ac57bf689083849fb4ce08775d142194811082a5 crypto/sha/asm/keccak1600p8-ppc.pl 3dd5e288f70b684d337f4054119935ab46af4042a40dffdca203868fe943bae0 crypto/sha/asm/sha1-586.pl -58378cb694b61022d70956ab344331d7577f9a26431acd00a60bed91229b29eb crypto/sha/asm/sha1-alpha.pl -8576b406e8596c8ac56a351a92175accfcf4121dd3dbffc59bae7d0ece0b0dab crypto/sha/asm/sha1-armv4-large.pl -45e94fb91cc4b4a620bc6f7e1f402d2d2ec174f0e95052b7aee903e8ae43cbd5 crypto/sha/asm/sha1-armv8.pl -790680438c562a88df6c6f57414f61e2f1de696aae564c82e6ff833bd5a6d7b3 crypto/sha/asm/sha1-c64xplus.pl -9e898aa25b009746ae1b6d59bd3bb250e845b96c0c2c0de47262f36e3bdb8030 crypto/sha/asm/sha1-ia64.pl -ac3a51a60944aacb1f5254af491bc0d2afa1a8d8c47ba810fb38f322c3f2eaf9 crypto/sha/asm/sha1-mb-x86_64.pl -bac612ad4f4468d37029e28668226145bc91b0ea5de0c01fe01a7699d3b155c1 crypto/sha/asm/sha1-mips.pl -c7ab165675d451820ebb0779eb127ec7e1292019d067ac9695688097156a6c5d crypto/sha/asm/sha1-parisc.pl -901ba1ccd75ae6cfdc8332ff2365540a652a214317be28178e6a9791dfdfdb0d crypto/sha/asm/sha1-ppc.pl -94bdf0d13c27f5e0fb326903bef2a98569a884b7e5f5d51e55854276c91105ad crypto/sha/asm/sha1-s390x.pl -68db366f13e563ee846b44803a83e47e5909f77ffa75d12ae75daf6c19250219 crypto/sha/asm/sha1-sparcv9.pl -13276a3511fc0ff4ca0ae0f2c9bd8823f95ed88ac336528ba112329d845a1e29 crypto/sha/asm/sha1-sparcv9a.pl -2f22676d49707cedff20a3a3cff21934b93da164ff2849c5eeff1caf85672bdb crypto/sha/asm/sha1-thumb.pl -877a6147742f47ffe46d7da5a0c84b73428d6872b08f25fa50c67c3be6a9d7e9 crypto/sha/asm/sha1-x86_64.pl +7f39b1520b56fd73c12816c5c77a7ea6135f2d7ef89f554da3051e1940231624 crypto/sha/asm/sha1-alpha.pl +23eaec582218b72ca10ffd5bef1049497fae3340f8385e3aaaaa70cb33245d75 crypto/sha/asm/sha1-armv4-large.pl +ae1fefa737649be615fa5b551d8769886e37245f5891fb015e6bf3ef640d7336 crypto/sha/asm/sha1-armv8.pl +6381f1889846bdaa24f75e1185f4c97ec5ac5dfff626597faff236eef9e63788 crypto/sha/asm/sha1-c64xplus.pl +d176b9e6afa31d78fcb8e4910c47470ab64147905c07f4c5fb9fc213069b715c crypto/sha/asm/sha1-ia64.pl +fa0f655302810b47b46ff54aee80e6bd45c0673a9a74abf47b9710f404ffe582 crypto/sha/asm/sha1-mb-x86_64.pl +73bff1666153ff6af6296adca50d76edb9e87b3e7a473c65c8696a3f7fc5960a crypto/sha/asm/sha1-mips.pl +ca4e704100b80846d8d9d2d32eb93771a92017caa232132c6327e62f75091940 crypto/sha/asm/sha1-parisc.pl +25a2fc55400d704949791b7d8228e3df55a9776a1babb21dc4223a041119fa76 crypto/sha/asm/sha1-ppc.pl +7da0d3f296a62e39dea31b189b9c0498ab765048a0ef5dc6fa1ab4bd18734345 crypto/sha/asm/sha1-s390x.pl +035e5a43eb5ec02bcc940b94fcdeb784e18e31141d885c92fea97992f2ecd9a1 crypto/sha/asm/sha1-sparcv9.pl +df6b90dae6339b4dcc0e352b76709a46011cf595ed608ebab19cafbcb368424d crypto/sha/asm/sha1-sparcv9a.pl +eb2dfd8215310afcaa691bc2a46f81b8db8290ebc4e6f54cda8c2d32848fed61 crypto/sha/asm/sha1-thumb.pl +3ef4c9fd99de1ab796bfe9f01b7a7f4176b88f834cc5cc8a650b381631c74514 crypto/sha/asm/sha1-x86_64.pl 36347a3d023cb843df237bce38d853b9c707d7220b60cac92a0314f39aa1e2f3 crypto/sha/asm/sha256-586.pl -0863e4bc9abcff3ddb85366b85aeb96a0ed55f4cedb3d02ccbbf01f670e553ea crypto/sha/asm/sha256-armv4.pl -6b8967b077d436936ed35edff401f3849a0ee9584d72eaa0fa5b14b838584827 crypto/sha/asm/sha256-c64xplus.pl -70a60ee1dd87d63def18ce29e852371815d8160504d12cff56bd7d1c05ef7cbd crypto/sha/asm/sha256-loongarch64.pl -8c481dac264c04b8bd238e13906846469ce6a3acfa0d22e7535c5f8928d534d8 crypto/sha/asm/sha256-mb-x86_64.pl -9df59c692cf3fe82c9fee5ca6ceb7841380e1afa0d79d68d96dd9d38be509211 crypto/sha/asm/sha256-riscv64-zbb.pl -8bd86c98b6ca967d351582bad71f0a6586f7e084ed337c78c6e7d7d927fdf078 crypto/sha/asm/sha256-riscv64-zvkb-zvknha_or_zvknhb.pl +aef93172abceddd2ee89a0bd28bf0d2f34ce82734c527bbe3505b1396e062e37 crypto/sha/asm/sha256-armv4.pl +a86031a4bbf6331d12ab0e907acdadf5aabd37414cd45090ef81854775f25aec crypto/sha/asm/sha256-c64xplus.pl +4a916a9c03e2fa53d44c3df44240c89c3df059fe9a599636f73d69a12a1ecea0 crypto/sha/asm/sha256-loongarch64.pl +69624727ce7b282459b4d5a8fd93145e872845e26053a792096cf78e3932ae93 crypto/sha/asm/sha256-mb-x86_64.pl +54d7834e65765333506ba40456c1a137d76cfef5a1a4b371633f031bbfe12903 crypto/sha/asm/sha256-riscv64-zbb.pl +b14670492f24cd0d2fedf8780e981b7da123203395c085334d4571b619b0a610 crypto/sha/asm/sha256-riscv64-zvkb-zvknha_or_zvknhb.pl 6023a473eafb92cd4bc0584d0e85f92c2bf57b4cde6cc2f6d2a930e3955d7d7d crypto/sha/asm/sha512-586.pl -5ff8a22efdbb049af001804fe788ab3718e387aad8a98e533e52f7f3f18f82b2 crypto/sha/asm/sha512-armv4.pl -2ebb034955ff154a8432c5c21d414bb9781232559eddd14edcc135ad72e712e4 crypto/sha/asm/sha512-armv8.pl -b620385bb40853156a1a0e4ad1169eb45c66583c7fb045c818d388f54e5a2b20 crypto/sha/asm/sha512-c64xplus.pl -feb4283e1bb2a36f0a98d4cd7b43ac78c40b72efeab8d58b4f0aad8b65a1d2ba crypto/sha/asm/sha512-ia64.pl -03302cb8fd3d580ae9dbad2eb65fd6d542893a86e481caef2286d42fbcd0b5fc crypto/sha/asm/sha512-loongarch64.pl -25c2bbaf0da5fe56c663ff7b926cf3284a2845df9911172316a8384e15ab7ef5 crypto/sha/asm/sha512-mips.pl -3b9ba893f84e56bd26e40907ad178884aa61ee529133691d87b7746c9ad13ed3 crypto/sha/asm/sha512-parisc.pl -952ef1b10e8bbe3f638cc798b91ab9c5b47b66ed8fe94647b1beec9874f2e71e crypto/sha/asm/sha512-ppc.pl -97d3701a260bdd16c26633dfe8c00d3f4fafe09a0fc8fd3d667098d1e2a94066 crypto/sha/asm/sha512-riscv64-zbb.pl -901cc96f156549f4ecca65d0315aa7d1c2c108f911aef3c4884cbaebbac2bc08 crypto/sha/asm/sha512-riscv64-zvkb-zvknhb.pl -648db5b748d07367579dd60cb551526081fd45c5dfaac989c5b1496d8af631e9 crypto/sha/asm/sha512-s390x.pl -58ed1513cd35553f83424bb0441a77af0efd467165a190b91990b124ecdb9b84 crypto/sha/asm/sha512-sparcv9.pl -93202a363880831a69bd3833be729645cfedfa97acbf27d4e3147cbc9b55e234 crypto/sha/asm/sha512-x86_64.pl -16ecc37bb09a47ad590fe8d8bbb4c9f583812348464bc83e1eaf117a05f50fec crypto/sha/asm/sha512p8-ppc.pl -93858e3b530333a129127b8df8cd3326cf55b770238b4fff2474c4e6e3def1dd crypto/sha/keccak1600.c +1d1549fa85de29305761c95bffaa4d16cca3e742986e2d01373208d954359be8 crypto/sha/asm/sha512-armv4.pl +be196152dce71802b80e9722100020fdde2c511ac687184f573e255d3ed8e224 crypto/sha/asm/sha512-armv8.pl +78baa4f179ca31cc7c9960d23cb5859c1c77f1b9a8cbaef899d834fab9ce81c7 crypto/sha/asm/sha512-c64xplus.pl +514a52bf4480f30b0f481be60bacedf24c8459785acf407e00ea78ca459bda92 crypto/sha/asm/sha512-ia64.pl +7f23a743cbd1f2fe31fcbe59587e1eddac92205ca80a26bc0387e771b5a14359 crypto/sha/asm/sha512-loongarch64.pl +1197a68bea31567fb8c5324c8ebc8fd649820d06b41f44041395413ea86f0357 crypto/sha/asm/sha512-mips.pl +52a73a7fd9d02e7cf46be05d4f643d427f20e47897fdd657607e8eb698882f96 crypto/sha/asm/sha512-parisc.pl +7c0c490ce6bb11a228853aecad5e164ce84e5bdabb8a6658ae7184782076c7d3 crypto/sha/asm/sha512-ppc.pl +e9241b71795c6c0ccc767c5a5fd1025e72396b6c693f4c3bf66d41f265ee8e28 crypto/sha/asm/sha512-riscv64-zbb.pl +07804b96dda856cffaef291641c4ae7f59288ed1e65e38823cfdcb74f8ac5295 crypto/sha/asm/sha512-riscv64-zvkb-zvknhb.pl +ee5e3e10a86dbfeac0c70909849f8cd07b9a31d2023d8f93cdd653946af9254c crypto/sha/asm/sha512-s390x.pl +6e0b7b081a4e23d44ef96ff255e45fdff3f708825e5e528539fff83803318819 crypto/sha/asm/sha512-sparcv9.pl +8c1a9c3fb0d77d26ccc23e60f2d95ff78842d4e406ff100462b132268e1d056a crypto/sha/asm/sha512-x86_64.pl +a2fcc3bf2a0604e15c5ba12b068e4417fa1f9f494b9c23b7ca155e1cd439d422 crypto/sha/asm/sha512p8-ppc.pl +e10cd2ff1fb57f3a3b5a9264878910627de989284ed4f78483e5863285f7f26e crypto/sha/keccak1600.c 306cacd3f86e5cacaca74c58ef862516515e5c0cafaff48636d537fd84f1c2fb crypto/sha/sha1dgst.c -f6021e6e5f4694579ba5a014e2aba44b6d436b2fd25c18ecd474a7383042b027 crypto/sha/sha256.c -ed6049496d9786296d011a4582ffcfe0859a609b37f1f4ce57cee36136ee526c crypto/sha/sha3.c -db0f16a4cb9c86f971b4defbee9dccd77345766f64efc45e0f1bc8d448bfb3e3 crypto/sha/sha3_encode.c -8def0b2e5996f2a2e187abcb7443e5e98edd4be0f71ff918a1b8c717cb97eb27 crypto/sha/sha3_x4_avx512vl.c -833e0990a4b8590a40990bfe1cfe59542ece6923fde37d3dd6faddfe1b9418fc crypto/sha/sha512.c -7b99b3c9fa26c5e58a56cbbb62b6e2bfe62542a662799f910387e76e5688a13a crypto/sha/sha_local.h +65ca7d67f3e3fc0314ccb179b734530bf1cdbde3d3cf428adc4c402f52e4b394 crypto/sha/sha256.c +ac714ce14a0b1fe1c0cb5fea9e0e76a188048649c43f3b3a527945ab8554cba4 crypto/sha/sha3.c +aef204d50f96b636576d8a52f8858fb5a4b2eb14bb60ebc14eb533df7a210e33 crypto/sha/sha512.c +6c6f0e6069ac98e407a5810b84deace2d1396d252c584703bcd154d1a015c3ea crypto/sha/sha_local.h dfd99e02830973ab349409ac6ba0ee901ba7736216030965bd7e5a54356abd7c crypto/slh_dsa/slh_adrs.c -c9b270de1259d9fa71a4d352786357bcf1dd3d22075edab84501e2f8e550b271 crypto/slh_dsa/slh_adrs.h -2aa41787214996542778a42eaf1bc754809f7d4d31185ac77424a3c686d6759c crypto/slh_dsa/slh_dsa.c -a48a4d00db9002872b1e45614a5e6f07b414c35875e8ba97ad63d0f9ff0134d7 crypto/slh_dsa/slh_dsa_hash_ctx.c -19700f0e69d6cee82fd9431321c9b0b1306ec50bf3ec65639199cfd5422f2768 crypto/slh_dsa/slh_dsa_key.c -c2958f29237fa77b3f3ab37aa716caf836e4b38815701155fa86c831b3532e9b crypto/slh_dsa/slh_dsa_key.h -43c6339d529f80b0a92292c5bb5dfa81a8203cdbbf52082dbc8fe84b78f0f09b crypto/slh_dsa/slh_dsa_local.h +1a2e505ac8ef45ff46f36ab89f5fb1d6a6888b2123a7cb75cf0eae849ee5de70 crypto/slh_dsa/slh_adrs.h +11d3895ea104d1238999f00b2beee4de71f35eea79065ac7b4536ee79d61d2dd crypto/slh_dsa/slh_dsa.c +ab7b580b1cba302c5675918b457794a3b3d00aac42297312d9447bc6f6a40b09 crypto/slh_dsa/slh_dsa_hash_ctx.c +f1cbfeb16276ddb05763005d836bbd8bcab2596560fe93d102f31519a2473c75 crypto/slh_dsa/slh_dsa_key.c +4c7981f7db69025f52495c549fb3b3a76be62b9e13072c3f3b7f1dedeaf8cc91 crypto/slh_dsa/slh_dsa_key.h +5dcb631891eb6afcd27a6b19d2de4d493c71dab159e53620d86d9b96642e97e8 crypto/slh_dsa/slh_dsa_local.h adb3f4dea52396935b8442df7b36ed99324d3f3e8ce3fdf714d6dfd683e1f9f0 crypto/slh_dsa/slh_fors.c -36b2968d2e79dcb9314fddecd9c4618247bd4fe3bf1d63d5c7572c430eedafe2 crypto/slh_dsa/slh_hash.c -5877632817d6950b75a0670153bad3c9c844216e387e0cd8eeefc22e056050f3 crypto/slh_dsa/slh_hash.h +e0f24425e22d257c5e1316b1f5879dadfefa827961813b1776223ac56598d4e7 crypto/slh_dsa/slh_hash.c +a146cdf01b4b6e20127f0e48b30ed5e8820bec0fca2d9423c7b63eddf0f19af3 crypto/slh_dsa/slh_hash.h 6402664fbb259808a6f7b5a5d6be2b4a3cc8a905399d97b160cdb3e4a97c02c4 crypto/slh_dsa/slh_hypertree.c -1ce9b4f4f90a6f82005c9cdc0ea1f6b6876556c76f8bfd95f4c003a1c195a266 crypto/slh_dsa/slh_params.c +98ba100862bb45d13bcddff79bc55e44eadd95f528dd49accb4da3ca85fcc52d crypto/slh_dsa/slh_params.c 86b16a2c36d708cb880ba49648bb3051c2997188c8ea6aec9292534b97232c7f crypto/slh_dsa/slh_params.h -c84761d4e089bbb5bf2a42a9e4dc2b5ea380e1cf95c6b97528ae2a4d98e9b7f2 crypto/slh_dsa/slh_wots.c +46e008e8d27e0193ab105fd7ae9c08c45ffbd59a5f683f661fa1f85a127a6b16 crypto/slh_dsa/slh_wots.c 59db81a3342c0c89b030756168b9a7f09c938b2cd3498335108e0a32c041b6e7 crypto/slh_dsa/slh_xmss.c 8701465c481b58fc7420ed577332586aec4c6696a5daecb2ff5071c7a6056245 crypto/sparccpuid.S -b462d1efe0acd798e1ec5f37fd1c824a587e1773e6a6f984d5a332581573ecbc crypto/sparcv9cap.c -51b5a944b67582044afc852e2d16135f382835c3b519271f820878a933ebe348 crypto/sparse_array.c -6704975a0f11799e82e6e136ba52c610e4930fb95ecff7e10e29ba07ce698994 crypto/stack/stack.c +5056b14a55665ffa342a9a1bb32c1c36886add5d0819869193427f33cee028f7 crypto/sparcv9cap.c +0145058086d2890f58078d5b01053ac02ebb5e4764847f13209c15d033b58d81 crypto/sparse_array.c +60b1b6765e3376778dbcd376f0e23b223fc6f7d96174037685c9fbd4b012406b crypto/stack/stack.c c0c4fd0f112465c6766072e25268c2f9019430e2c08c3c0a4271603d24d79f04 crypto/thread/api.c e298c753be277ad9a2ac0132d9897cb4c85607dbb2d11cfefd0c98e0f6a723d9 crypto/thread/arch.c 5c02ff77d290ca0deb19672c1ed6fc0f47a0d630f61398a204a2684a7d418f0a crypto/thread/arch/thread_none.c -cb214ad206ea69ab98d24a727a47d3a4c614fce709e6b7fe6997dbaeed92f0fc crypto/thread/arch/thread_posix.c -5db84d4b3c5799051df8e8db85322b156c7e696e23544422479735156e29d6cc crypto/thread/arch/thread_win.c -55953eb5a84d03e8d915ee867ddf8ec8be8c5eb444ea0b21b12a040a57e2c2c1 crypto/thread/internal.c -828d68c5fb820f4e270954ad940b60ff194d361eefd87f581bc56a3c4461174a crypto/threads_common.c -2e5955d706b96c487e4875ffbe208fac15bdca06b33cee916d5343978c14efa1 crypto/threads_lib.c -483ac173f53acb89035ff1fc7a3c54fe3aa5b22b00517194d59ee9357bd2b8c0 crypto/threads_none.c -bc684682c5b4669abfe8798ab05583b96d8d1b95c046b1043a11c48e6fef7def crypto/threads_pthread.c -698baaded1a5f1d3430e1b5cbd75cadba173a969f83de67850090bfaa52b7a42 crypto/threads_win.c -93f8fe09f96492a6be6772ddbf0cc37912fc2a90acb7faea378da1735fe20f6f crypto/time.c -7bb1345172689dabc21287a5775ab95062c33634064796631efde07e8b75f035 crypto/x86_64cpuid.pl +1506ddf108b99cd192b70dbb00154fbb5e632527fa0ef56796bda4c68f833464 crypto/thread/arch/thread_posix.c +0c391b7898e34836441628571e0585e6d53ebb9142a2153f3a81aec687d32117 crypto/thread/arch/thread_win.c +27ec0090f4243c96e4fbe1babfd4320c2a16615ffa368275433217d50a1ef76c crypto/thread/internal.c +6241e8bb88c186e9df8a861636a95d2da3545233fa9d714329ed7df9bbed1b45 crypto/threads_common.c +67ba8d87fbbb7c9a9e438018e7ecfd1cedd4d00224be05755580d044f5f1317a crypto/threads_lib.c +e0226148a992a1b97de95adf98023e05a47e0af2fe66dee69da763a0c77c1787 crypto/threads_none.c +68a6816c5ee43d923f07d19904643ee7d2e124b701ee83d007a05ad9cf812f10 crypto/threads_pthread.c +c23ada60f5763eba3a8a288b9b856fc1bc66f202f55dbcf4ad15ef50c67ff76a crypto/threads_win.c +7edd638df588b14711a50c98d458c4fc83f223ed03bc6c39c7c8edf7915b7cfa crypto/time.c +b8629f0cac4c70c42aa6c117d9bfec29f5fb6f37341ecdb528fb99f3b57bb994 crypto/x86_64cpuid.pl e2c6e8ade621e4b0fbeacef2908d042ae93bd7bbb916bb1ff25a4d11e917faf0 crypto/x86cpuid.pl -68dc7e15fbf2193f2d8e1138721f7f80c34578b5025465cc99270d796b537bf1 include/crypto/aes_platform.h -0cf9115128d082e5cbe94b3f961dabd045c1dff339fefe3aa5066d48517a1aa1 include/crypto/asn1.h -9acd69adc80fbf9fa88fed4bcc7b3c0ba87e2add98d7ba311d8b092a2d5a0d2c include/crypto/asn1_dsa.h -3bf019778a3cde9d296c4e400e23aa6ccd14b12f42b6a5d9e18ba987b28ee3da include/crypto/bn.h +b04619bbfdae16775955b0cd225b371a0a035d5ebbf32aba445d328c4da13822 include/crypto/aes_platform.h +44222ee3dbcc71acf0fc40fcb5f700d307eb843b3d456e11d04539d9613e920b include/crypto/asn1.h +8c6f308c1ca774e6127e325c3b80511dbcdc99631f032694d8db53a5c02364ee include/crypto/asn1_dsa.h +ea4283995b1aea3ab8f4a07aab0025cd1b09078d59ecfed0cc1dba087bf7b34f include/crypto/bn.h +1c46818354d42bd1b1c4e5fdae9e019814936e775fd8c918ca49959c2a6416df include/crypto/bn_conf.h.in 7a43a4898fcc8446065e6c99249bcc14e475716e8c1d40d50408c0ab179520e6 include/crypto/bn_dh.h -8ca9d3c460dfcc437cf99b9412208a555d2dbdc01081c327765729c94ac133c1 include/crypto/cmac.h +76cec717df68b4cbe33cf6fb557c9724ab027a1ab5e06b27eb0294fef2edd75b include/crypto/cmac.h 7e45c76bfb2ff324d39442439077fdbf5edfc45e2e0ecd2fd80f664be0be9abb include/crypto/context.h -273da25316489e04e5dd0675a5e8baf2f9e51080de06bfcd85b29ebbbd7c063d include/crypto/cryptlib.h -8a55e7d62cd241e1f37e48ebc0deee22ed793ccfe094c46138a41d856f26e015 include/crypto/ctype.h -fb109231b7f7fc2e83dd39ec6ef14d88f6ee60cc91ef1efd0c49fa7eeaa50ace include/crypto/decoder.h -96632debc11dad16535e48708a3d89df7c2c0cef9843e4bee271071bcd3d15d9 include/crypto/des_platform.h -1f94e0ce9b3e4b3bf80e8777261d22fe6d5bbecfc79fb3be805daba738b7551a include/crypto/dh.h -07da49c53dab98e3a50b3d8a21953227ead3aedae570c80584b9c2ce5988d20b include/crypto/dsa.h -2a146319aa6f2788d0c072fcf197b23fd394910a11366df34c1dc4fa2d896e0f include/crypto/ec.h -8eef8896afdccc8c90c548e0d11b290c004df3231a1777e8205b88c04645c4b5 include/crypto/ecx.h -4af06cb0219605fdbb606b0b6de51e34aa0503b42457a424f80c7c0c39dcc985 include/crypto/evp.h -fc22d8a6d80875c8c45c51a449069b936eadb9621aa9c0bcc8c5d493eed1e52c include/crypto/lhash.h -0651a33eb67395c48ca64650dc2912326b7c0b7b47832e0c59bc4139e7f271c6 include/crypto/md32_common.inc -47a92e596adaf252ed86d3c363e1b7d1893445aaef302eb50cf18473c3c08541 include/crypto/ml_dsa.h -60b558f2990b9f390dee864dbd15372a98dc2dd95c4701c088a5a804198e7421 include/crypto/ml_kem.h -b7a00f7e37fb4054d371438f270e67eb584eacb9b13fe29536dac90e8371436d include/crypto/modes.h -f20e5cd691a360e9d12a7d41fb33b7f1639922543271d642534532edf85564b8 include/crypto/rand.h -b4fc407f0ed2c4a1795bcdbef3ccdc68be327ae40bd401fcb1066df0a63bda7b include/crypto/rand_pool.h -9724de5c6aca5a2ad2f95f137543eef5070d76a9b6775913b00242fd6e338d1d include/crypto/rsa.h -3f28391ed526d791a578e76a40961592e15ae2bf62b81d5924525e1f21684659 include/crypto/security_bits.h -95904882055bb9a1732c38b99ec45a2895d41e6009ab952e36264bef5389ba45 include/crypto/sha.h -169800966e382419cdcb30265fe786708f9b9ccc4fbb1b8c17641a7fbf4cb369 include/crypto/slh_dsa.h -df915f569207111cdb011e85ee0f40bcd169ac0a413cc858ccee0b5001cefbb5 include/crypto/sparse_array.h -eb1f4f50bafdd357aa15b54f60f5ecde10876253038f00bf518fbf60840addc1 include/crypto/types.h -fb45d44ba49848c67551f008f97d3686628c3c59641a727eac99ac2e28cfba4a include/internal/bio.h -63ae5eec130d8cc15d19bc6b1e655023a0e4590b3a2054230e58dd1e107fa4f6 include/internal/common.h -fe75a08a48dec0ec0bfa02875b21d20ac3a0e9e8d05cdbbd5d5299978495385e include/internal/conf.h -31a4cb7ee45d243fcf71673fa22c9b6e93456e6ffc5b0a0460531db68e040e44 include/internal/constant_time.h -306412e987e63cf2354268c3dbf9e9e19f8253d577561a3cb77f48ba74100e11 include/internal/core.h -f08179621d19535c0fe8a5aff3525b75de61f883b8bd80b8dfab4a68b5615b2e include/internal/cryptlib.h -cd215e01800987b008be87ccf85823fc98be0c578262a7720cbb6e9ac3dd81fa include/internal/deprecated.h -178940dc972f22a8a481a16fd63a86e7468e88cbaa1db5fd68c2b1ae64cb6865 include/internal/der.h -0dba4a6565caebfef82a8dc90d6ba208b2c61445123724769d5ee84ebbb0a610 include/internal/deterministic_nonce.h -984b04ad2f0a2036fa157099c3b1ed5300c079a665c8d26d3451eefd06fc1e25 include/internal/dso.h -e5fcc33def2500935c7706ab8dc1b5d44a4a4135ec8135b9bde55f4d8a4c191a include/internal/dsoerr.h -97baa18b5dece75e7445a80494b2db2462e012287fa3b9454a74750363b757bd include/internal/e_os.h -4c6d7d437065e39b8609d10aee66855a7820b25569fa06477ec5db818cd2d406 include/internal/e_winsock.h -f799af7ba63ccbe14c468625c4bf3669cb9405825ffea57435eee7e7973f2fbe include/internal/encoder.h -b41a5d9a7bdf60df169e327b41f16489830b82393dd663d1f89f81da4483eaa7 include/internal/endian.h -18007208e049b62e62a416543c37c4b64f81ef6e00188ec0b2016f206e260a2f include/internal/ffc.h -09d5d6683c1d688409d1619dd303f938f02b2e2b9e3a2d5186c54f73ca49b114 include/internal/fips.h -923d4fb14a08f9b251b9bf9727bc50930d0279e8b63243faf85374bdcbbfc4e0 include/internal/hashfunc.h -65bc8c144bec1e91f6126ca8c0e5e39a520970c4fe1dcf36f2a3817d06a7f2d6 include/internal/hashtable.h -e93523559408ad5ded0fc87ccbc43213f4dd449ad98c2df3d3b6116f2d3a217c include/internal/mem_alloc_utils.h +e69b2b20fb415e24b970941c84a62b752b5d0175bc68126e467f7cc970495504 include/crypto/cryptlib.h +6c72cfa9e59d276c1debcfd36a0aff277539b43d2272267147fad4165d72747c include/crypto/ctype.h +f69643f16687c5a290b2ce6b846c6d1dddabfaf7e4d26fde8b1181955de32833 include/crypto/decoder.h +89693e0a7528a9574e1d2f80644b29e3b895d3684111dd07c18cc5bed28b45b7 include/crypto/des_platform.h +48d133a1eb8c3b3198cfe1cafda47f9abe8050d53004f3874f258a78f29b9e48 include/crypto/dh.h +679f6e52d9becdf51fde1649478083d18fa4f5a6ece21eeb1decf70f739f49d5 include/crypto/dsa.h +c7aafee54cc3ace0c563f15aa5af2cdce13e2cfc4f9a9a133952825fb7c8faf5 include/crypto/ec.h +1126f9292eddbaf326421b6666967e229477b69e9643f8fe068797d4c60f5c6a include/crypto/ecx.h +c9c884647b61d7111bb99a7ec12cf1abb2389e1ba6b56289c7ae3d46ac671586 include/crypto/evp.h +bbe5e52d84e65449a13e42cd2d6adce59b8ed6e73d6950917aa77dc1f3f5dff6 include/crypto/lhash.h +b9786b3738202bc7a90dead26e7317090f88973a155c3d7909e4865dc3fbc524 include/crypto/md32_common.h +e94e76f4e26c54291a8a283a2a5534ffa3907472a15fa4efef18ff2390d6628e include/crypto/ml_dsa.h +62642e5ae502a3971c5f77404b9bca18473b7cfcf09030601779543efd9b9587 include/crypto/ml_kem.h +6e7762e7fb63f56d25b24f70209f4dc834c59a87f74467531ec81646f565dbe3 include/crypto/modes.h +fcd25208c143488432229b64c42c6ebda6c7c03dac0812d6434fff232e822bc1 include/crypto/rand.h +71f23915ea74e93971fb0205901031be3abea7ffef2c52e4cc4848515079f68d include/crypto/rand_pool.h +b1df067691f9741ef9c42b2e5f12461bcd87b745514fc5701b9c9402fb10b224 include/crypto/rsa.h +32f0149ab1d82fddbdfbbc44e3078b4a4cc6936d35187e0f8d02cc0bc19f2401 include/crypto/security_bits.h +80338f3865b7c74aab343879432a6399507b834e2f55dd0e9ee7a5eeba11242a include/crypto/sha.h +fef74bf1524b5bfa1c190fba9eef284ce6b321caffc83e4b4d87fbcb776202ed include/crypto/slh_dsa.h +7676b02824b2d68df6bddeb251e9b8a8fa2e35a95dad9a7ebeca53f9ab8d2dad include/crypto/sparse_array.h +d6d1cd1ec7581046f5a84359a32ed41caad9e7c1b4d1eb9665ea4763de10e6b3 include/crypto/types.h +27d13538d9303b1c2f0b2ce9b6d376097ce7661354fbefbde24b7ef07206ea45 include/internal/bio.h +7c8bdf83fc61de37027111c24c41049debb2c9f856fa97bf6ac93319cfef1f35 include/internal/common.h +77616e7546ed1bae9df366327663261282b16664a616725436715df9ff99b598 include/internal/constant_time.h +c5bb97f654984130c8b44c09a52395bce0b22985d5dbc9c4d9377d86283f11f8 include/internal/core.h +58082dbbf4ecc415265822398d62c0eae6217e15cf4d6409b48faff4a9625b2b include/internal/cryptlib.h +9571cfd3d5666749084b354a6d65adee443deeb5713a58c098c7b03bc69dbc63 include/internal/deprecated.h +dc5afb955d810feb5af9f8d25cd8a92118abef320fee95c07b04f301c4e0d96c include/internal/der.h +8059e715f981fbe02b5731610ed24bb6ae617a55e90b03f4260cbb6ccd71e8de include/internal/deterministic_nonce.h +fd1722d6b79520ee4ac477280d5131eb1b744c3b422fd15f5e737ef966a97c3b include/internal/dso.h +f144daebef828a5bd4416466257a50f06b894e0ce0adf1601aa381f34f25a9e7 include/internal/dsoerr.h +924fddff69e5ee237e38d48dd55d4c5f6d6ef8b6443bbe217c760009bbcc87c4 include/internal/e_os.h +6e33d1c6f82a4483a0e52ee3c9713e123efc5aba0601e7f13078aa45910cd70a include/internal/e_winsock.h +c9cb7a25ba2c1a451ba7cca7e165606f891ee8d3e927c06a2e4f84db7f7622eb include/internal/encoder.h +70d3e0d5a1bd8db58dcc57bea4d1c3ed816c735fe0e6b2f4b07073712d2dc5ef include/internal/endian.h +4838a68ff626825c261df6a1fd21e156e25d8365af45552f29054d7038a7db3d include/internal/ffc.h +4c9c4b7fc19615fb480fe18c86521d57313d24a8de556681741054abc2e3a690 include/internal/fips.h +45e1f3a274ddce17d62681f3150eeb522ef9716b0b41bfdc33327cf72c4356d2 include/internal/hashfunc.h +86a49bb77470e35f2b9150b8321588599fefe4ff1e619fad5fdbab821376c19b include/internal/hashtable.h +59a42c0009da205633201936f8562d39688890c2b7e8d908b47eff37971f30b2 include/internal/mem_alloc_utils.h 14cbf044dbf0f4052c74f14954042a8b8ddf90b56123fa0f2b1264f77baddc75 include/internal/namemap.h -c367e6120d26a2b629f4db7e179973e33fb095e1102d5c7a69c744b88ebe4469 include/internal/nelem.h -f95b3f0ef8a5c47b8be185f4f4ec3baaa6304ed3f7a608fa3aec3c99af0e10d6 include/internal/numbers.h -2287c91ae739fea5178768cc3376d59f730fca046fb71c3432037e061e569ad4 include/internal/packet.h -52686e2cd1049e7b0cd6c6a4085952bb83a04823215c42b1b8e6da19b2511d83 include/internal/param_build_set.h +b02701592960eb4608bb83b297eed90184004828c7fc03ea81568062f347623d include/internal/nelem.h +c2bc157fe33360e33c55c9dd871734b4c87d1d90ff17770770f213143b20ffe2 include/internal/numbers.h +3e3c394fa557e6ad13a91315ec4562f9c8b0127cadc63709b567b3695f8cc8b3 include/internal/packet.h +f42d4a6108a18ade3eb99682c072adf83889b6ba3fc80ee3e20929ed8d0f7137 include/internal/param_build_set.h 677c7271c8bb9c2a9ed1b79aefc7a06b8746f71afa8557833167da62eee205f2 include/internal/params.h -ee75ecd35b3ae90c51ace957ab7ce06de3c7d5064b97a878241ff65cc943a6db include/internal/property.h -7aeac9a78efb9ea5147f639cd474e6c2538acc1b9d255ba19dc661fe22bcd94d include/internal/propertyerr.h -5b108c19f064ec47fffe1b3fe310d4693b6db3920b8cc2e5dc05595751ab0f3b include/internal/provider.h -3f476694478c1125574dfb2e75c4c0c0d04c7d3d763176686a4730028513fcd5 include/internal/rcu.h -b6e33da6011b2b74d27e39f27cf98e6f123fe47826562b6479d0dbd5c758c4c2 include/internal/refcount.h -f77c0844cc44bd92965647cd8cb6addb210f0300a8d1090da8c26e4382e87c2c include/internal/safe_math.h -17f6585bc81ad324d00aaacd558e0176dbe22cc7cbdb353c8c9072fa40000a58 include/internal/sha3.h -8e672cc0620606b044f63b8446125f5233d64e3eea59df54c1fcca6bc90ba537 include/internal/sizes.h -188be736ff23a2202fe594e6d49a7ccf4c23a7baa86e2dac5d58360f21d9c986 include/internal/skey.h +d4ac19b28ea61f03383364cfad1e941cac44fc36787d80882c5b76ecc9d34e29 include/internal/property.h +727326afb3d33fdffdf26471e313f27892708318c0934089369e4b28267e2635 include/internal/propertyerr.h +f3ac89b2eaaa7f83d7d2606be65aff28136aec5b961884c45f79bf8540ad6f34 include/internal/provider.h +8f6de3f89987ae8fb25df77b01fcba53bd3f6174ae3745c6ce2b726b6c3637ca include/internal/rcu.h +baf5df9b8b91cb5b821ee27348a47364c9dfc86144c9573403e9d54fa970f81f include/internal/refcount.h +a01805714966e6de536ee182d5476cb1708d019631f016f331a034cf3b2b3158 include/internal/safe_math.h +d11b69bed0965e47c3be0e0f44a812a7eb69ae91d7ca8f148a91d6ef6d255a47 include/internal/sha3.h +9a2db71c880a62946d7c4ed259c5069d689a364a23fc275d97b638517bca8f01 include/internal/sizes.h +d44d03310e0af9aaf33f2f8552f7ef84ba7612d55ceec48b53bf86d774bbb149 include/internal/skey.h abf03dc8635f2925bdc2299feabe115f8d5d6eaa450b421172ded222872386ba include/internal/ssl3_cbc.h -780bf5e9a5852e8776a3b9984993a91f27f3f7b1501e1b2185f5a8f448b0d848 include/internal/symhacks.h -fb5bdada32614d7214569dc111b8bbc43592886799f0536b844a64a2541727cb include/internal/thread.h -a8fa7ddc1e54ca296bda9ee05a7a39bb7e803eb0567cc75a9b949b80cada7552 include/internal/thread_arch.h -1cc86957e734ce34acd949b9e9e9d588a6c82afb68a09c787fb69f5e4cb20b1a include/internal/thread_once.h -fe4d85ab26d1a6f0933c28044b0f6b62d67ef1c30fea336a5446da88f646a14a include/internal/threads_common.h -e9f51092f519bcd826942a5310c05c9f943fd63a92c5d0053d49a2489531be33 include/internal/time.h -30045240c1f070530b8360e3ae4b372bf1eddb4e7bbd51649cc86193857f6217 include/internal/tlsgroups.h -ea4e067f1b4cb0f896f0f8b7e2ff9e1161c528f5038d84f52c7c96b25488ce9d include/internal/tlssigalgs.h -79db205cd380711f09748b4ab020442050acaa0a8a940e2be38c4916e23dd1ff include/internal/to_hex.h -426c2eccbb31696175b2680b91bed727e0bf6e632657bd9e6c25fce7c8375d92 include/internal/tsan_assist.h -3e6bbff5295764bfee6fec91a8807e9fa345a7dcba70d55062df1a8d6f98758c include/openssl/aes.h -945f6d797dbebe5738e549d814f71222a20a070a062fdb4c33650a45aa611e93 include/openssl/asn1.h.in -0e28b492fc1f2da095ea42267480c9961a4f8cde3314e409f90395af8c65357e include/openssl/asn1err.h -77a9f9595cee6448c6217a8388127593a34a0d0a585197a5f8100fcb792f76ec include/openssl/asn1t.h.in -598935a01d51a1d74401e12c5f4717f86b5c085afe4835a0878619ec09af2e95 include/openssl/bio.h.in -40491414172d977a4667589fa2f269d7deaae675555b8348d96f315d1a6253bb include/openssl/bioerr.h -e58f86e76a8b46ea7ea2cf4bc5641023b7199572a77d0ab243b845545f3c40d3 include/openssl/bn.h -c506c9bfbac7368335fb2a8a627755ce2b8547a251d885242a89c9f8ff3bf079 include/openssl/bnerr.h -c70499c9109b083beb69d1b17807266b041d0ff28694d5bc1ab7cf2a59331c39 include/openssl/buffer.h -5bce6559638266f060eaa16b3b90738bbd5292d62230b6b3b1e22b88836a5030 include/openssl/buffererr.h -2a83e38101abb3c2da0e07f9bf7012d8167a3c1588df65c36652c4f72aeafc27 include/openssl/byteorder.h -0d499118db0c65974b768a048460a5ce2aa9b80154763856571fbfa6490703a6 include/openssl/cmac.h -c5b95f844eaa367cc6f608b51c2b1f6ffebcdcb8ca6c3ec2fc2bd355d000f2ba include/openssl/cms.h.in -e99dccb7d94349e8b4431df4be60a93c2698f59a3101698985acb640b61a5efc include/openssl/cmserr.h -1cd9648cc536f25cff10656096ebb1d9353adf3ad855d1c25a22b142ec1705e0 include/openssl/conf.h.in -3517c480b3211d384d4b36fa48d8dce8923fcccd99fefae68635b3f82eb0acb6 include/openssl/conferr.h -4e195b6f7a734756e21c4269cc245b292e1a563aaec5644402929d0eac423c41 include/openssl/configuration.h.in -f76830b31c947d86c2e6a302ab8df6b83076f8d29120bce9a58195551eb48e1a include/openssl/conftypes.h -a013fca5cc6b5cc26eb1c76eaeba31e99408e88fe89c343a44cc0b22f8e63eab include/openssl/core.h -834f08e9531aa5ccfdd34e5fa8bc759d6ee4a3f91ce42de9877ce5bd71840d87 include/openssl/core_dispatch.h -13dd8d11be44ba25e9a0e362d5ce8b797bfafaa271661b1c7e866faf72b0a4dd include/openssl/core_names.h.in -d4ac103754c2ee212d0f97823d7f4237baa32b2acd66875aef4aad12d0884963 include/openssl/crypto.h.in -128ef415305b704d51461ab98c688c69fde868acb5f5f74c92b2d0517823e71a include/openssl/cryptoerr.h -2e5b0109741b7d37a0d1a5c0c8ae9b9320bc9b0e71c3e05093d27f14f598295e include/openssl/cryptoerr_legacy.h -a147bf48583b902b3db0d30dd2a9565f1c9f3ec94dd57652e31be4c67b7d2593 include/openssl/decoder.h -8d8a2f1286cf40264a80e090d377edaabfa4b040dc0e5314ac41406e0dcb0fdc include/openssl/decodererr.h -402c76d3a33378f6dad64778503581e4f80e2ec46ac24c84646234a06acac5dc include/openssl/des.h -148f89bd4ce3a7e24d70b7ee459b666961f1a43e961bb6936f41026f6ed7c278 include/openssl/dh.h -5658c7f5cd57d74c7644c63c6328e80469fab9d3e29dd734f1433cf3019dd4ab include/openssl/dherr.h -181833ed01a0ddd7ee9977c65e34c6aaedf63afbed74e7340c0faca42ee7b3ec include/openssl/dsa.h -d526f8def9e4bb31ff85dbc9494e6b3fe1ab15f424a8e53b3b8fff9dcc40c803 include/openssl/dsaerr.h -9a6478f1536f171dc1478eb39cede4d8834ed01447ce50e06030426697a68a7e include/openssl/e_os2.h -fcb8e2174725eef1279ba8ed046e56c99805796a13eb789ff78aadf7a73e6c76 include/openssl/ebcdic.h -64a56b81cdc7a45bca5bc3d24ecc8db22839d90b8d843318cd79306aeae94811 include/openssl/ec.h -9c56b594bfde630c9b8df2fe0c691c74cf79fffb1c1b5e2034ade844e6e3c7d3 include/openssl/ecerr.h -07d47054034660f93646c0aa86aaa1314e8c973ea4eb0642e5b09820359a5571 include/openssl/encoder.h -165f96bd4637e057b6500b91b99667b9095b8c3bf53caa28e5fb9fd74e748a29 include/openssl/encodererr.h -d6ca2a3ad4ded065bcfd8cb8de68215186662c277631bd17bd7b542b7fefd1e5 include/openssl/err.h.in -5adfaf02d7051e5513e90b921c2cf1731661d34a50960559af9b80f1bfbc28e8 include/openssl/evp.h -b353076927c4273840c8f72377f7b9c6f28730e3f8a353c69d7ac3215532d738 include/openssl/evperr.h -0399e15a86163ebe1bd31da2de617d4455f63fce42da741ceca0c1df08066b80 include/openssl/fips_names.h -f29f8b7f23486e11b5307234d0f3efc56afc9a1321ac9792429493fadeb4a08e include/openssl/fipskey.h.in -24d2351e5cd9ff4608b4262519cbd806d267f62c2f480adc4169a150d6355f34 include/openssl/hmac.h -a7c65894dd0f3730769d56a46bc6e4777c9bd7c8826998373d2ccdd9a346f840 include/openssl/http.h -1dc0dce58de44226fc0afb51073c39933fb65dfd3a0131c4eff17bcb93018665 include/openssl/indicator.h -972e54ea69ac234315ad4616ee0546f47fb61afed727eb3a1c2e718a3b5d6999 include/openssl/kdf.h -f4a6b9adcd0158222878f5c55e3b40c620361d328bc624ce22d4937c0c054fbf include/openssl/lhash.h.in -d862fa698982ba613990fd4da07598a32d0fdef091a71dc39a280218a780b7c5 include/openssl/macros.h -0da95b5743f5c12ba1a30c1ef84f9fe57ccd5816febb1b5fd3a4f573ec885cd8 include/openssl/ml_kem.h -06f0d4621c344401f280a4e69e48ba987a0600b7f52ee16b25c4620277b081f9 include/openssl/modes.h -fae2bcfa44744276acdec4693badd9663904a0e60311e968aa912f4f167162e7 include/openssl/obj_mac.h -a4127bd23a35828e90addb54b6a1cdfa6a1864038690fcc63053604629fb6f3f include/openssl/objects.h -884f19dffa0b6e0f03fb565cc61cf800993eafe7fc9df0ca2feef67e3b199963 include/openssl/objectserr.h -429571177fe9a2ce5fffce21697ecf197bd9b645bdbc578a146418ce8286e9eb include/openssl/opensslconf.h -76386f806a801eba4c0172c52dc0e04e2deb192aa867f9d3e9d98a4d5a932d4a include/openssl/opensslv.h.in -4c4640740b5de9debbc82bcb5b3e02282c145e440e40dea478a804b8c3498065 include/openssl/param_build.h -3a9bfb4f64a2cba78546c02aa1b6f4593ce7adfd8ed7b37e007916bcc954e8cc include/openssl/params.h -86abdfafc2b5a9467eb20830b96dd7cd9a95c72aec7dd3a798dd70541853f3c3 include/openssl/pkcs7.h.in -2b25ec134dace5f5e1b0d52650d72c61c2243720358c0b3e645ad956b27d897b include/openssl/pkcs7err.h -a15b0b69bc1e31d0091ad32f04021d4fba9750cf9e3c9c0d2509358543cac380 include/openssl/prov_ssl.h -e783f0de83be4c120573090c646281d25f3eb3cd3475f7f2e9d78afe28b63629 include/openssl/proverr.h -d0fffeeaf8a20f6c86e8a6bfaeb1eab7c00188b1844c109ead4232c8dfb3705b include/openssl/provider.h -c712b7eeca499c968893efbc2964e100d257fb5add90152f6c35403192744040 include/openssl/rand.h -23d76dfea708747bdc2ffac41e25b156a22d2d0cb744323a3b9859c54bfbb98a include/openssl/randerr.h -4c93d2209b91002ed5f0e4abd4591e6949e60ff044a37da03172a13cc9067151 include/openssl/rsa.h -8ce33ec31a1652646286f921726e3da41be0a06ffe2e348a00b29887a8061a4f include/openssl/rsaerr.h -f123ff856086475f6147a89f3ce27ff646143f91bba1da45d4419db2b2731108 include/openssl/safestack.h.in -a7acbdc844ca0bcaef392ff3e9b0c5b40c906b0b69477cfa57f8503a96d3daaa include/openssl/self_test.h -1e5408273c5d453a35b00bbff90c899f31acef09da52f63e80b0ad7f93c7f1e7 include/openssl/sha.h -d01e26cccbd89ad20196b83ebaf9dde1ebeeb7344e9d4cec52786f54121ef3c5 include/openssl/stack.h -d381d0b4113f0fa18b3e421eae303fc84daf84eacb1236cb6e9976409a2d33a9 include/openssl/symhacks.h -fc527427bafa6862d9e3847c961dd6cbbcccc39d25762c65ad3b99fae9599e2e include/openssl/thread.h -2f0b0b7d7384d901bd5a6f161f821cdd4a4d0db07148431fc3d549aa553d129f include/openssl/trace.h -52c3892ddc32bb44bda1e41f659f8bb94e946dd677323d96ee39935176659167 include/openssl/types.h -76683d46aba0e790ba708d2eacb751a8bbff0796091d30dcd2b344f3f1e8461f include/openssl/x509.h.in -32abce4cd052c706f5efbe803044807f27b87d61797fb023d811ddc2162974e9 include/openssl/x509_vfy.h.in -2b2f987b082a69f1eeb7c56e11ffab485a9203a2aaba9d50004a67fb029db729 include/openssl/x509err.h -aa3a3001c8d92e5b5376a40fa599eb58bb9536d06494a2a6e2f0e35bb6d49cba include/openssl/x509v3.h.in -16b57e962c0b6c35f16f6c0790ab72c279e1c5743024546ef5830d8f5acc0ad8 include/openssl/x509v3err.h +24f41a1985fa305833c3f58030c494d2563d15fc922cdf3eeb6a7ea8c135a880 include/internal/symhacks.h +6b186bc71a3a41681c94b5bf0a201741f15ee5e6e6a3973d5e878ea3de22e6db include/internal/thread.h +8a14b0e830da8ace10e661d7b1bca301a9bf2662f0c55e07aef3ff7344142b53 include/internal/thread_arch.h +640cc6a2aae208073a7f495c08b4c5006a69e8ac1c2d9aaaafd56b0e74d5f859 include/internal/thread_once.h +9028af85a254df456e0c0dd0781e38bf6e1cc469c3e45deef1e11a69b563c166 include/internal/threads_common.h +634148b5dffee774f7c3e271885cfc69219d403526936e390d4925f209f09630 include/internal/time.h +d7930b6d7f59dda7b6c39adb76d0be05db90ae7448dde7eae52ed9230ed93e3b include/internal/tlsgroups.h +0b41d6646786c16083fa071b788dd9fec0da1c8f715a7e2ad3a05d77520b162d include/internal/to_hex.h +b5c93adc67bbac950f865ad30f46788287e39920bf88cb456c5946e3e3680468 include/internal/tsan_assist.h +2b38fb6e65d549aca3b2c76907daf67124f395251c0261dec26faa54da8d6d73 include/openssl/aes.h +8edd30869dcc93e7452d6443b1757383e06f92ee7ade59c6f5c698783f334266 include/openssl/asn1.h.in +8bc93f8b980835aff9b8e788c3cd6654a8fc5f1405d3934b968118c4b56c282a include/openssl/asn1err.h +1550474ee05423896ec4abfb6346f1bc44c7be22329efac9ea25de10e81d549c include/openssl/asn1t.h.in +73ff02a145387accef5b019f77f2611c12a70fdc0c0826e34322ac4b65d05326 include/openssl/bio.h.in +fe5ab4bc904b7c77e5411c4b7dda6d29595eb60a87f00e30ab32f48391f98b44 include/openssl/bioerr.h +9caa80699882befcce556446a45e5ffde5aa938aa2aae0e8ecd46c9c6a3fe419 include/openssl/bn.h +9ad8b04764797f5138f01f549ba18b44cf698ffc7fe795fef42c1822d84a6ff4 include/openssl/bnerr.h +93954e6c450716e158948d67f64736a451ea9473d02f3a908f3bc8a96cf049a5 include/openssl/buffer.h +9d48e6cab2ee98ae94d7113e4c65f000d97e125fdb3445642865ace3f34d06ac include/openssl/buffererr.h +c1f6110f5f8d5faa3805215d8e5877e81e4108cd6d04f73b06d43ba5661d1a1a include/openssl/byteorder.h +8e772c24b051e59d2f65339f54584e3e44165a3eaf997d497faea764990130f5 include/openssl/cmac.h +9bac6fa73182aa34eb714622386cf0d5625d07d739110dd3c6d8b1d8ea0f6367 include/openssl/cms.h.in +5d44cd9e996542a660a0eb4d46cef357c14df745065593944b082ec181978b3b include/openssl/cmserr.h +1342636127f3d365ac538115e706ea1aea43ab8fa79e86756e818b30a72789c7 include/openssl/conf.h.in +bb45de4eafdd89c14096e9af9b0aee12b09adcee43b9313a3a373294dec99142 include/openssl/conferr.h +69d98c5230b1c2a1b70c3e6b244fcfd8460a80ebf548542ea43bb1a57fe6cf57 include/openssl/configuration.h.in +6b3810dac6c9d6f5ee36a10ad6d895a5e4553afdfb9641ce9b7dc5db7eef30b7 include/openssl/conftypes.h +28c6f0ede39c821dcf4abeeb4e41972038ebb3e3c9d0a43ffdf28edb559470e1 include/openssl/core.h +fd6788e755c203029851fcf076067522303e751c8d3ece50964e2ee14282dff0 include/openssl/core_dispatch.h +5dae643c3149f0b750844d2b8453e150c148806242ee6d3f08ab90bcef139b6c include/openssl/core_names.h.in +6b94bd310814be2753238c595ee89288da8e52dc9c40e40001b31491ebca1f7f include/openssl/crypto.h.in +628e2a9e67412e2903ecb75efb27b262db1f266b805c07ece6b85bf7ffa19dac include/openssl/cryptoerr.h +bbc82260cbcadd406091f39b9e3b5ea63146d9a4822623ead16fa12c43ab9fc6 include/openssl/cryptoerr_legacy.h +83af275af84cf88c4e420030a9ea07c38d1887009c8f471874ed1458a4b1cda7 include/openssl/decoder.h +503b45367b035ddf6e54587125c2100ceec324d646e6f3df92c12513185e977c include/openssl/decodererr.h +fa3e6b6c2e6222424b9cd7005e3c5499a2334c831cd5d6a29256ce945be8cb1d include/openssl/des.h +0837b1ec7074b37d2e1d5ac46d6003c3fc4f1ff10f2e44c64b5709b0bacec4e8 include/openssl/dh.h +b74a54335bb2f55caacd5c3fd10db3575166fc35077dc5740059243f70e0b179 include/openssl/dherr.h +3cfb7211419c5dcc98b9a20713e2245befa0182a10615edb89a5ce0a0725a787 include/openssl/dsa.h +276d1f6e111ba933bc708e6a0670047cbe0d0b67aabe31807abbbc231de4d8cf include/openssl/dsaerr.h +25bcf84a034502eaa16354c61bb9a2f2f3d607b2f343bbe7fa1f1e810a353db0 include/openssl/e_os2.h +bc9ec2be442a4f49980ba2c63c8f0da701de1f6e23d7db35d781658f833dd7b9 include/openssl/ebcdic.h +49e8a9d226d543ac482cecdc01c83b7ccdfbfca6ad92d690aad75a245148e2ab include/openssl/ec.h +7aa8c5bee779af59d4733f6a50f7f6be39f1eb43409e5b3357440f9a7d0ca115 include/openssl/ecerr.h +61c76ee3f12ed0e42503a56421ca00f1cb9a0f4caa5f9c4421c374bcd45917d7 include/openssl/encoder.h +69dd983f45b8ccd551f084796519446552963a18c52b70470d978b597c81b2dc include/openssl/encodererr.h +aa02455482d744418123266f581b9b4310ba678c7d28c10fffc5eec74ce3c8ef include/openssl/err.h.in +1b69b729f14255bb17c917b95692e1b1b8b2004b4d177754bc8a4e576a615e26 include/openssl/evp.h +b2a8058dd51abe6c1ac4a0f32175f550a308efd31607a9cf1620aa032b1f7e55 include/openssl/evperr.h +f37c13a7cc0b05a734efcafb7da321dcc366090c255da8ee532e5f2be2eaa152 include/openssl/fips_names.h +fef2b79b4de2cd74b02f12f1c0515cb2eaca742b8ded67fce722fb417e818e25 include/openssl/fipskey.h.in +47a088c98ad536ea99f2c6a9333e372507cb61b9bdffb930c586ed52f8f261eb include/openssl/hmac.h +aef20807146a62481c0dbd6c86b818a84fdfd877601738b4e51afc944ec3d59a include/openssl/http.h +3644c7094fd5310a103aa9adff947ad9aa87e0a48432471a4ca10b4885d215d3 include/openssl/indicator.h +af3d4c826ccade672d6915ab7fd8ab5b47ef506e55adf95a139857851d8ffa6b include/openssl/kdf.h +625258d115ddc5117eaa2ff126e548e25fb81336abead079e6f2028f4bce4e92 include/openssl/lhash.h.in +6f0c735a6c29cf0d507864a0f45df16cbd9ea9197b5dabbf9c8e3be7b74a3be0 include/openssl/macros.h +a8a45996fd21411cb7ed610bc202dbd06570cdfa0a2d14f7dfc8bfadc820e636 include/openssl/ml_kem.h +9184207c562fd1fa7bd3a4f1fadcb984130561279818f0cdfcf3e9c55be8a7d1 include/openssl/modes.h +b45bcbd54b434c5e85e58d4878fd307a83a4f0b76037414d38c61b8a2e25a8b7 include/openssl/obj_mac.h +cb6bca3913c60a57bac39583eee0f789d49c3d29be3ecde9aecc7f3287117aa5 include/openssl/objects.h +d25537af264684dff033dd8ae62b0348f868fcfec4aa51fa8f07bcfa4bd807ad include/openssl/objectserr.h +fe6acd42c3e90db31aaafc2236a7d30ebfa53c4c07ea4d8265064c7fcb951970 include/openssl/opensslconf.h +fc914a750d798ac9fc9287e6359cfa1da214b91651deaaaa7e1a46b595cd0425 include/openssl/opensslv.h.in +767d9d7d5051c937a3ce8a268c702902fda93eeaa210a94dfde1f45c23277d20 include/openssl/param_build.h +dfae08484b61be22286a6932c805379334a1b848f03729766176eff015fb4362 include/openssl/params.h +dbd765ae06944e0674007000a161dd03b4bd72a0bca8efca615831e067f82eec include/openssl/pem.h +10188e669e2416c1567b99155e6ed1f79c072c9dff8d02e3e0b3fea38c14316b include/openssl/pemerr.h +44f178176293c6ce8142890ff9dc2d466364c734e4e811f56bd62010c5403183 include/openssl/pkcs7.h.in +8394828da6fd7a794777320c955d27069bfef694356c25c62b7a9eb47cd55832 include/openssl/pkcs7err.h +ed785c451189aa5f7299f9f32a841e7f25b67c4ee937c8de8491a39240f5bd9d include/openssl/prov_ssl.h +86e7ce680dfc8a2cf4bc340a32b7297a247fa2eacf0dc7b8a26e22344638202e include/openssl/proverr.h +01ecfa6add534dfe98c23382e0f2faf86f627c21ce16c5b49bf90333fb4cac9f include/openssl/provider.h +765846563fbd69411aff6ce00bcc22f577f6407f5a80d592edb1dc10b580a145 include/openssl/rand.h +1c135b1e5ef06e052f554d52a744a9a807a8c371c848389ad836f9e4a923dd8e include/openssl/randerr.h +2f4f0106e9b2db6636491dbe3ef81b80dbf01aefe6f73d19663423b7fcd54466 include/openssl/rsa.h +2f339ba2f22b8faa406692289a6e51fdbbb04b03f85cf3ca849835e58211ad23 include/openssl/rsaerr.h +e6e086ef229db1b48b30e72e6e3a2c97c9f3f8271fddd7c5b2334b6f60fb2a5a include/openssl/safestack.h.in +01c9b7f240d02a89b64a44d0890fda9549031e2164500135db5873fcafd6a1e6 include/openssl/self_test.h +a435cb5d87a37c05921afb2d68f581018ec9f62fd9b3194ab651139b24f616d2 include/openssl/sha.h +ffce0e38d7d24466e9b2d2be7241eda7d9eded7d3cd662c63e2e58ada7262555 include/openssl/stack.h +22d7584ad609e30e818b54dca1dfae8dea38913fffedd25cd540c550372fb9a6 include/openssl/symhacks.h +8acd8147402a816c835b4240e18972072bab41d3fb6ee364fc17e543d6a854f6 include/openssl/thread.h +f09bc8a337d80f65dafb281a1c129a258e51ec320bd35f82b8baff780f22dadb include/openssl/trace.h +164a4df1283504b2a08a0682e722ebced269ad0660382f6cba74063b013a2165 include/openssl/types.h +f37b0da67078c8c220c442499e02f92dfe240f6d77ec942f2a562a18f338284a include/openssl/ui.h.in +558433ae747ebf3d9a71d583b7a7ee8c5476f3bef38d97a1f88bdcace4c2f311 include/openssl/uierr.h +122374eca21c37d88c7a32d02eee35a606506d3a3adc7bb41a1670a1c9c6ade8 include/openssl/x509.h.in +d9c9d32070b40fc95d9b9f93b1b47c8fcc255a3602222dee586fde4ac54b3863 include/openssl/x509_vfy.h.in +ef9e7c7a2176cf1b3f2d0c52b7cc1f47ad0666fbbd8a9479cbb39b7bf0dfe06b include/openssl/x509err.h +3afb55225a5725bd1837735e6b8d8d99183b17310078b1f14db99ec30e7fcb30 include/openssl/x509v3.h.in +51696276aa9b3dc1f03d2ff28c6b72360936de2a83ee4630297c9f3f7c235f2e include/openssl/x509v3err.h c0a9551efccf43f3dd748d4fd8ec897ddaabbc629c00ec1ad76ce983e1195a13 providers/common/bio_prov.c -aacfd1289e0fecd66a3fecb28c0870752bf1bc375084d7d1ec018db032cfe955 providers/common/capabilities.c +4786999b1fd6933b05f21abd7033451fbd56e1d842c620cf65160ac22d03791f providers/common/capabilities.c f94b7435d4ec888ec30df1c611afa8b9eedbb59e905a2c7cb17cfc8c4b9b85b8 providers/common/der/der_digests_gen.c.in 424d7b2ece984a0904b80c73e541400c6e2d50a285c397dd323b440a4f2a8d8e providers/common/der/der_dsa_gen.c.in 27ff361a5fbfc97cd41690ab26639708961d0507b60912f55f5919649842c6ae providers/common/der/der_dsa_key.c @@ -606,9 +602,9 @@ b8f2f94daeaf20c636c90e386284c246cfded0c8275411fa02fe68b534520b95 providers/comm f3b089fd3dcccc8e3ebfbbdbf87c47d58330f82bd0e2a1223da74977930cccf1 providers/common/der/der_ecx_key.c 4572df6882ddee3c00a72b7a13e39e0c6a26251394aceaa25378b79c5c12b48c providers/common/der/der_hkdf_gen.c.in 4132ea0bbb9dcdc44d90ca072b7a8d715dca0875d426aa12d770e60d5f0d46cc providers/common/der/der_ml_dsa_gen.c.in -28bfca8e235b00fb9c5c5a564a5d6a5d390e31f1437d8fe3cdfa558aa79e6183 providers/common/der/der_ml_dsa_key.c +341a74d94c93a9fbe663e489801fa586d8ff306615e230d2b1c74354003c90e0 providers/common/der/der_ml_dsa_key.c 5b3b0ae8da0fad1f7ba8b5fba2206210884728bf69a8aa00644036eb51953467 providers/common/der/der_rsa_gen.c.in -6faa11a45867a626a8d9b63fc737867625cb1d15010bfe05ae6ae167be491e63 providers/common/der/der_rsa_key.c +029aec80a45b477f7c8bd8d24d48e36de92f8056b421e9f128c336dc246dbc4e providers/common/der/der_rsa_key.c 7e8d579986f53eaf1875d677e5cf4adfd4ccf79db0275368f6cac580ab6007ca providers/common/der/der_rsa_sig.c 3c0fa8fb3050077f82176790b0a06ac88891ae236fbc918b18d1ae7e75c0da94 providers/common/der/der_slh_dsa_gen.c.in 5d0e18a680f82632bda6ee9fb9ef61993ce0f2bc9884451e946a25130f27fc99 providers/common/der/der_slh_dsa_key.c @@ -621,148 +617,145 @@ c0a020765feb7ededc7e6f20b2b140dca09f347cc72404a5c7971df82b2f9ad0 providers/comm 5b6b7d8d12011c48195b7db8f65bc4bc4a48fb753763a3ce5006dc227b5139d7 providers/common/include/prov/der_ecx.h.in d0bdefe8353562f61c8c58cdba46b67e6a1fa5cc3b9b21605f619f7605fbeb60 providers/common/include/prov/der_hkdf.h.in ceea7616712e6ec4ff475a806998d66354d228f634e733a75e345bf78da32958 providers/common/include/prov/der_ml_dsa.h.in -b9c85795c2c45fbf301ec8077df54ff9d570cfa82407eb07420c366dd7ff2486 providers/common/include/prov/der_pq_dsa.h ce605f32413b09d33ce5795de9498a08183895c3347f33344f9ae5d31c29ccac providers/common/include/prov/der_rsa.h.in a36d6762f74d9ac4f437e634e60f2b4de1ff5416bb6dd5d2cffe2e4556556b1b providers/common/include/prov/der_slh_dsa.h.in 6c1fa3f229c6f049c3ac152c4c265f3eb056d94221b82df95a15400649690e93 providers/common/include/prov/der_wrap.h.in -e5c7da25b919ac4d2d84f21c9d552f29c2b06ba4445401bd4e361be45f4f8d30 providers/common/include/prov/proverr.h -dff610c91cb41d9d6ea4084119d496a7e1d7973fc7831323d4b353f2b57acdfb providers/common/include/prov/provider_ctx.h -7c41320b73d85db6f07dec1e11bce0bd8ff620c8f1d81cd9c0ec4926f902f597 providers/common/include/prov/provider_util.h +76087f04f4de6414c240f88807659fb2a04af914108f0c5f2515a4cb5482f655 providers/common/include/prov/proverr.h +59786e2e358912d977ba792fb387d2df0156cac16267e399a1c93b3b0b65f725 providers/common/include/prov/provider_ctx.h +098ed4905f97b5b3e03ef193bb4d095a2c0a5f721a3a9475af532dd188f9f460 providers/common/include/prov/provider_util.h 5bfd27719e282266273a4a2eb63d79833d3e0b94c2fd683ba1ccf565be0072d7 providers/common/include/prov/providercommon.h -bc0f539ef10023aa818ba2cfaed31e2be9cb80141fce89d3d2c23f0906711677 providers/common/include/prov/securitycheck.h -f3e31bd6776b55c924bbba8ad0f0727096b1d407b1d8b22f1f1a0f969a03fc4f providers/common/provider_ctx.c -4b46687c8d14d7ff4227d03f6fdff5e25cc1a3e7d74a76473d87ffaf182f2181 providers/common/provider_err.c -9c835f67256a6657b04ad7c2bb7e724aa40cc8b636a06e9409026758bede799f providers/common/provider_seeding.c -bf6193d6a5ff6222e2382f0d0c3321ffeb1534a9ad78fe594aa838761aad3162 providers/common/provider_util.c -b10730f4d302344579c09f43d5f9c5538bb6b4acd60de7430c24269fc522d5a5 providers/common/securitycheck.c -b8550dadf2f12a98b30ae39eba026f5f959e8f889df39fcf9eea0cbe7f4a3244 providers/common/securitycheck_fips.c +4a6e35be7600e78633324422f019443747a62777eba4987efc50f900c43fda25 providers/common/include/prov/securitycheck.h +ba12773ee7d5afbd55e240798a0e36a2b0bdb4472f3aa3984bb8059f68cfba25 providers/common/provider_ctx.c +5dc4c4e3c3c0468c06125572fa6860d2c95eb565debbcca24c91a85a8ba504aa providers/common/provider_err.c +c4032b7cb033b588c6eb0585b8dfbed029d5b112a74ddd134dbcb1d78b0f9684 providers/common/provider_seeding.c +0ccf38f9fc93c1d888e14ccd6a547eb4bf70fbf52c2c18f6149b587a39e75067 providers/common/provider_util.c +bde6107744cf6840a4c350a48265ed000c49b0524fa60b0d68d6d7b33df5fce6 providers/common/securitycheck.c +8ea192553b423e881d85118c70bcb26a40fbdee4e110f230c966939c76f4aa7e providers/common/securitycheck_fips.c abd5997bc33b681a4ab275978b92aebca0806a4a3f0c2f41dacf11b3b6f4e101 providers/fips/fips_entry.c -8b07ece9ea02de5648f95719668e0e7d2167c9162ae68c8c35be66db20c1fa8b providers/fips/fipsindicator.c -8759568b4f3882131913739090f9638109b36e686a5f3b68f167398d61247fc9 providers/fips/fipsprov.c -8f4f57148aec16d44948b21f21f7eaa7145cc296e3c4201451d6a783aa4f8e4d providers/fips/include/fips/fipsindicator.h -c35c84f9c7033fc44ce7942b63a94e2619bc4cd8c7fda0d6024c3af4febfebd1 providers/fips/include/fipscommon.h -b757e583f8bbd767f8c59bbb788c30e3c6ab8ec94f98430fdce3d73ad565f952 providers/fips/self_test.c -5d313319a66425f0b54076570807961d5f433a73674f4300fd34b43ea9d4c232 providers/fips/self_test.h -bcb310a409affe057f9785e2a5a3e1ba5ddec65fcf7ecdf0ff7b2420d884c857 providers/fips/self_test_data.c -56fc365c9f73990b826d4b1dedc6e62f28f67d7d986af4651bf4ab3a587c0ad6 providers/fips/self_test_kats.c -775b222ef65c2ef3d877356f65ba4c7f12a4b7ec17f45524b716c966bebe8871 providers/implementations/asymciphers/rsa_enc.c +5afa41d44a7f5078c94fc41f4ae7f4761176888992b3d705b7fdf29021a08bb7 providers/fips/fipsindicator.c +a992a4e61f07fefbe703151fb9c40935a1a00f4daf0374c2b73ca61713b9a9e2 providers/fips/fipsprov.c +be79e98437046079c3a587c4ea768e9dc6487aa84affa213d3bc4d2876542d70 providers/fips/include/fips/fipsindicator.h +ef204adc49776214dbb299265bc4f2c40b48848cbea4c25b8029f2b46a5c9797 providers/fips/include/fips_indicator_params.inc +f2581d7b4e105f2bb6d30908f3c2d9959313be08cec6dbeb49030c125a7676d3 providers/fips/include/fips_selftest_params.inc +669f76f742bcaaf28846b057bfab97da7c162d69da244de71b7c743bf16e430f providers/fips/include/fipscommon.h +51a435b16cfc040635df4522f7a2c01b0330a052f15d64eabbb7c851c33b9876 providers/fips/self_test.c +5c2c6c2f69e2eb01b88fa35630f27948e00dd2c2fd351735c74f34ccb2005cbe providers/fips/self_test.h +8424bf995ffea196562dbd4ba7e87ae5da097786a45e10d849ca8baeb45ad686 providers/fips/self_test_data.inc +7e0abef196ac08cbd94de7e82346a29b9ce3075705781ba920cff88256eaab87 providers/fips/self_test_kats.c +4b8b89f0bf3932863c28a5411705e367fcc6cd9cad8acb30eb689d3e89c33aec providers/implementations/asymciphers/rsa_enc.c 6cbd516c15416a32a4ddf6d3b96e8abe0facf675ba78c6299443fdc44b7af5f5 providers/implementations/ciphers/cipher_aes.c 72d028079f13774171668297bba0072208450c4fb82fc9585aebd8ead793c8a8 providers/implementations/ciphers/cipher_aes.h -cdfba3a1512d8e358daf681bec9dc3d00450d279bf47fe41aaf0fdf62f96554d providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.c -1b4f19be0c2bbea99e5fce0f93189c687a03cac634f0e37a51466ee7e3510735 providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.h -348e680f78849c37cb87bf0c95212f73e364165958c8c6aa7c947d9d0dbd6a57 providers/implementations/ciphers/cipher_aes_cbc_hmac_sha1_etm_hw.c -b2375518a1eb4e6427ca38c7df19e71fb3a15c6d66d1a2ee564bc973a95a743e providers/implementations/ciphers/cipher_aes_cbc_hmac_sha1_hw.c -56a70eed1965425cf9dd6b3b693679359b56127d3e9e7eff50f4bed8491095a8 providers/implementations/ciphers/cipher_aes_cbc_hmac_sha256_etm_hw.c -faedf7c0941640a56664ccbfb53c2803bdcc674e8d955a5bd386806930b4ce88 providers/implementations/ciphers/cipher_aes_cbc_hmac_sha256_hw.c -6fd920324e43b2ac621dc96a9a2973e3d652cb50f85e7e480050fc499a1a8e43 providers/implementations/ciphers/cipher_aes_cbc_hmac_sha512_etm_hw.c -6d8486d3448471b046ab5ad75fa99620c20707d270edc7a833240c3bc4e335a1 providers/implementations/ciphers/cipher_aes_cbc_hmac_sha_etm.c -6293f6028f2c79cf1a16d3407f3d96ec47cbf7adaae9233885a2bc5ee38dc29c providers/implementations/ciphers/cipher_aes_cbc_hmac_sha_etm.h -dbde94765165b5ba43ab2f9a58499c7b08f85403fc0be5606ffcbd299e2dfbcc providers/implementations/ciphers/cipher_aes_ccm.c +398ba2921083e6a6135e1539ff07c8ae940be4c3af2ad7b70a90d4003f53f084 providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.c +7668e5c1cac474ad7b0f28aa78ca885edf44815fe4a606a6cd328b3c02fac25a providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.h +5661d6b77890b92d179caabea59b1da8aa74c311850bc17f977fc85031be3692 providers/implementations/ciphers/cipher_aes_cbc_hmac_sha1_etm_hw.c +6974e9a18b48cd075d51794e1ab4571c71ee7473959bcb5ba691bab1fdf63354 providers/implementations/ciphers/cipher_aes_cbc_hmac_sha1_hw.c +5c296bfabef94e9735101e106af0d3034114266fbb5ca9bac34d7d0aabb1287b providers/implementations/ciphers/cipher_aes_cbc_hmac_sha256_etm_hw.c +82bd8a906a520f847d15f7631e60e2719c3fc91e6949f2dbe74d087f77f1d5dc providers/implementations/ciphers/cipher_aes_cbc_hmac_sha256_hw.c +e9d3206a882e77e8868bffd6de8e563ff3e93947f488601f816271be8c240c33 providers/implementations/ciphers/cipher_aes_cbc_hmac_sha512_etm_hw.c +2dd49cef2377544fa246a41e47698bd675cf4dd990c27948001c9fa58de4886a providers/implementations/ciphers/cipher_aes_cbc_hmac_sha_etm.c +cc45a491c5d7174a12d43d7108d253ee5e19dd6af1af77d0c04b5586df0a306f providers/implementations/ciphers/cipher_aes_cbc_hmac_sha_etm.h +1b6d31811a6729f0c75c7c7ccfb7d3a75ab6001605b229593187918a592da789 providers/implementations/ciphers/cipher_aes_ccm.c 00f36bf48e522dbb5ec71df0ec13e387955fa3672e6ff90e8a412ae95c4a642f providers/implementations/ciphers/cipher_aes_ccm.h -5df10f5f682b706d562516aca5efd2ffbaab29b9e877a43713341a6fb341c8ab providers/implementations/ciphers/cipher_aes_ccm_hw.c +f5869d48e456232dab54ec111d47f934bbac048fef10c49d13e05ec56b6ef0f8 providers/implementations/ciphers/cipher_aes_ccm_hw.c 302b3819ff9fdfed750185421616b248b0e1233d75b45a065490fe4762b42f55 providers/implementations/ciphers/cipher_aes_ccm_hw_aesni.inc 1b8172b09f87b743bc7fa256f875ac0e98271311e4952ad2beac2a08d4b760c6 providers/implementations/ciphers/cipher_aes_cfb.h -68e666bc49149b5cbfe480d88a6ec503d111aca110d842466d82cc9626863ac1 providers/implementations/ciphers/cipher_aes_cfb_hw.c -55a80c4153eb94907e08bf6d99c7dfa564d338a61ce07bb57cf24df0950648ef providers/implementations/ciphers/cipher_aes_cfb_hw_aesni.inc +35e4551c4a54b6b6d59c07b8099624f3addfe5684ef0d33e23e2cedcd2dd33ac providers/implementations/ciphers/cipher_aes_cfb_hw.c +351620294e97374eb5cdf688574d37f0f6112edb6c17bd6af9de2b6d538f7d6b providers/implementations/ciphers/cipher_aes_cfb_hw_aesni.inc a8eaca99a71521ff8ac4ffcf08315e59220f7e0b7f505ecddad04fadd021ec14 providers/implementations/ciphers/cipher_aes_cts.inc -a80320d377d8dd8ba8d82c99b144401a03329ba157e62171813da72bee0ce88e providers/implementations/ciphers/cipher_aes_gcm.c +14de031ae6a95653f7d819bfdb2abaf873f884b8313901bee4c2ec3ffc286712 providers/implementations/ciphers/cipher_aes_gcm.c 79f5a732820d2512a7f4fc2a99ece7e6e2523a51e62561eb67a4b70d5538b0c4 providers/implementations/ciphers/cipher_aes_gcm.h -68fcbf7b1a8e801fcd2f5bbc2ed1f834feeb5572cac83c1f8aae82ccfb2815ab providers/implementations/ciphers/cipher_aes_gcm_hw.c +c6f091629dadb1b0b55e45636a28c31268fea4abfd3c068917c6c94b9aab704d providers/implementations/ciphers/cipher_aes_gcm_hw.c be18c20e0197f25fe7b9e0268657a2271a69d216b89cb100f082fa5fcaad1e07 providers/implementations/ciphers/cipher_aes_gcm_hw_aesni.inc 470538c167d9345acc52d027459b8b28f59a82972e6436644d3154d3ba5fe949 providers/implementations/ciphers/cipher_aes_gcm_hw_vaes_avx512.inc -4004f50a151cdf089e918aeec42b44cda97b4547454383cb79f9b7746f384df0 providers/implementations/ciphers/cipher_aes_hw.c +06f73fad35649c2d07b069a298c0f5a2bcb8bc872489295e36d4a9f47f1a9239 providers/implementations/ciphers/cipher_aes_hw.c d8bd5a78bfd52e6623d5a7b1764487b7a1ab828caa11ce41f8cca3c96b6339cd providers/implementations/ciphers/cipher_aes_hw_aesni.inc -b848fad5d9973e2cda10f83d0937e095a3df39ee3db610d828a0cb1d4a1eeebc providers/implementations/ciphers/cipher_aes_ocb.c +ff6e62d95466b724a79efa39216b9ff52dd501ee476fe2acacc65a408edba4fe providers/implementations/ciphers/cipher_aes_ocb.c 88138a1aff9705e608c0557653be92eb4de65b152555a2b79ec8b2a8fae73e8f providers/implementations/ciphers/cipher_aes_ocb.h -b9cb159602c57cf06a8eeecb9f301aa3673dac0a9154dcc60dc24e8e4bd55df8 providers/implementations/ciphers/cipher_aes_ocb_hw.c -d89e435abb8cfaa8f3a6aea4b21cd25b8cae05c44a1887562e4ad19b2b0690da providers/implementations/ciphers/cipher_aes_wrp.c -3d4b18b18fe894922ae7cb6243f07754e56ae3011a8dbfe1b1fc5d2d1e5bc43b providers/implementations/ciphers/cipher_aes_xts.c +329a8daf6c4d117ac4b9f244b6d09a83e90e3f3825c7a4610074a15d4d508ca9 providers/implementations/ciphers/cipher_aes_ocb_hw.c +f30ad0ecc54b9a6dc2df3fd768e67ef523d94308db56da8f65df470b3a6601af providers/implementations/ciphers/cipher_aes_wrp.c +8ee40234d051dfd9557439001d5d9f43d86623e23188a05ae00df99553cb4dca providers/implementations/ciphers/cipher_aes_xts.c ff870fcdc063e2e9f99693e4dad5f2128130591b05928bb5395f60ddcf81b1cf providers/implementations/ciphers/cipher_aes_xts.h 281157d1da4d7285d878978e6d42d0d33b3a6bc16e3bc5b6879e39093a7d70da providers/implementations/ciphers/cipher_aes_xts_fips.c -f2fc918672bc9b9d3b696934cdbac486832625953595e26943d94c8c8a30fa71 providers/implementations/ciphers/cipher_aes_xts_hw.c +3161aa7c62595214551a32911e7550207570a899b8a5159006d1f3643a0c908f providers/implementations/ciphers/cipher_aes_xts_hw.c dc4626becaabc3990549483d9ef5f05c7dd9a9c2cf9be96ade3ba6a6e203f7f5 providers/implementations/ciphers/cipher_cts.c -83c892e95bb3f0e0d0824f92d9792033265de1a224d8a92f119abb94994552d9 providers/implementations/ciphers/cipher_cts.h -1fce446497c98a84043257700ff02bb8ba04cdbb8ac92b15ca09404490e48016 providers/implementations/ciphers/cipher_tdes.c -9cfdcc860a03b6e7ced8cc21bcbbc1c070c89aefab04b07f213c7a3db1895553 providers/implementations/ciphers/cipher_tdes.h -79e01dad1d0144c9e908e29584797aa6a8d76754bf0ce9403e68b3bdd37ae180 providers/implementations/ciphers/cipher_tdes_common.c -cca34f1c7baf3a98964f7ce19a59e06d1eaf2ada121a0d4a438f4078a072b325 providers/implementations/ciphers/cipher_tdes_hw.c -d1eca5f5d0eb4886f4aa9fafc9f458be97819d7f7d83641712a567d615750d4e providers/implementations/ciphers/ciphercommon.c +57ee5e4d0af6d6006b04e60c5727b43a71ed37b67aa2410e03ec8932ad4a69e4 providers/implementations/ciphers/cipher_cts.h +fcc3bb0637864252402aaa9d543209909df9a39611127f777b168bc888498dc0 providers/implementations/ciphers/cipher_tdes.c +ccd6cc0ba06a8ecd8ce50019a6a62f8a185125d9ee045fd68a3c16e71c7a7794 providers/implementations/ciphers/cipher_tdes.h +b4a90dd37517d545986dc84c75fa7f7315b227f9f29a9543057fa707d0789480 providers/implementations/ciphers/cipher_tdes_common.c +50645122f08ef4891cd96cace833bd550be7f5278ab785515fd61fe8993c8c25 providers/implementations/ciphers/cipher_tdes_hw.c +ef10bea663cc5fbf5aae57bd203f1a2386bc888f1f22574819f8f1aaa1542f11 providers/implementations/ciphers/ciphercommon.c ab9a2edb23aa61cf31da6addd8674a6028f93399eceeeee35a56ee770338fd6c providers/implementations/ciphers/ciphercommon_block.c -cd95d8dc7e87578afa5ba62c157fc5adc92a98aeef096e11ecca15eda7d6c3b3 providers/implementations/ciphers/ciphercommon_ccm.c -6632a555d5bcd5af67d0355ce46c2906bb3a0dcdf1651595b29189c40a5ca675 providers/implementations/ciphers/ciphercommon_ccm_hw.c -fe8a53b6667537f72d5a352d7f795cc26f24a5d4b26dd09c5f1d7a1fd338e986 providers/implementations/ciphers/ciphercommon_gcm.c +cacf93da46c59324acdeb5546f5c5b593edbe847dac38bdd256355046e4a1003 providers/implementations/ciphers/ciphercommon_ccm.c +8b6828f188c2590c7d9c6cac13fa0eb6d38a522b0f2859e7c8a766580fa9b66e providers/implementations/ciphers/ciphercommon_ccm_hw.c +f5e31a3e651031015384367ed7a36672fd3a1cdce84a8240a600ad672ca91d71 providers/implementations/ciphers/ciphercommon_gcm.c bb67eaa7a98494ca938726f9218213870fc97dd87b56bda950626cc794baf20b providers/implementations/ciphers/ciphercommon_gcm_hw.c -8bf2b4bef8167740ae3fffc9f0cf73327a1b4ee361e63da22c257cca0e1e2971 providers/implementations/ciphers/ciphercommon_hw.c +23fd89e3239e596c325a8c5d23eb1fe157a8d23aa4d90ed2c574bf06dfabd693 providers/implementations/ciphers/ciphercommon_hw.c c4b1cb143de15acc396ce2e03fdd165defd25ebc831de9cdfacf408ea883c666 providers/implementations/ciphers/ciphercommon_local.h -a639cb1b3285e41fa4372bda7b74c66a358a0b7a038cfc9a9c171e5f15beb932 providers/implementations/digests/cshake_prov.c -cc9b9d6515fecfe2170b256c424e1eecb53a9849e49b1ac324c081a07d004b39 providers/implementations/digests/digestcommon.c -ff74278756bc06d7719f27e7a313c482b7d548c6eb41032b37b3383cfc332ded providers/implementations/digests/ml_dsa_mu_prov.c -794505a44c44f8d835d8e5232691ccc809ab1eb03ebcd62a2432b6c75ab0c1af providers/implementations/digests/sha2_prov.c -110a47f50d1606e49c67b236ed432f05301eb22d6b9e4eaf11d3b3e3f26761b9 providers/implementations/digests/sha3_prov.c -85c7b5945cc335871b291f38f3b9902784645323a63c44a4a38a45d6d3222ed7 providers/implementations/exchange/dh_exch.c -eb00f306a98ac77fc6f2fe7f34d2ae5766e72c37b76145e892793173a879c590 providers/implementations/exchange/ecdh_exch.c -85d51569b5fcd2b341d86b1f4eb78174812a02d4c00e6d4983b4453d0796fd40 providers/implementations/exchange/ecx_exch.c +e1a2c940b1e393321d8e1cc3b6dd7eb29808dfe2c240f5be27afc256fe3d67e5 providers/implementations/digests/digestcommon.c +51ac78c43d477aa78c8a1a19a1b64ea563fa23e7312a41388004cdbdbf7234e1 providers/implementations/digests/sha2_prov.c +826660d9767a1b4362a6a5b29d7e47a3bf74bab06b7224e2a420087648fdafe2 providers/implementations/digests/sha3_prov.c +0631f193c581bde7641560765ee1defbf1f014f59eb34b81f65c94e4024f5cc0 providers/implementations/exchange/dh_exch.c +071bbefdcb6f15cb4389356bf4010b3681d4335275cbb5a59a32196b3c7140aa providers/implementations/exchange/ecdh_exch.c +b9ce8cf2eda64173d55c7dcb92e06514b4f149ed7994e0736b9f2f0dbbd814c8 providers/implementations/exchange/ecx_exch.c b1115636f53bf70f417b183cafeb6d38e230d11d8de731e6896ba60cc850d931 providers/implementations/exchange/kdf_exch.c -2af71a41c00247bd6414362816f3045e138074ec563e92640c422d1c94d9f3c3 providers/implementations/include/prov/ciphercommon.h -138b7525ad6c672dd0aefd3badcd683f5dbe36414031c99d893e19b0a2a3fc9f providers/implementations/include/prov/ciphercommon_aead.h -86eea720369a305488118de7bea8424802cd8bfa0641d26f4a81c24ad928b116 providers/implementations/include/prov/ciphercommon_ccm.h -97bfe62d6d191818d924575b36e2222de0c86b788b691e8c2e0253b191fcb976 providers/implementations/include/prov/ciphercommon_gcm.h -927be1df476263ba84e1561cf848e1723f9d57bb7b5bd27242db79abd028e145 providers/implementations/include/prov/digestcommon.h -92e66fb2825009f9b64051109ea40e6822b10893e3712462533547f67d1f810b providers/implementations/include/prov/drbg.h +f59db431bc0ce19cd40233577ab0f2a8ac987dc95e52da8b84853ab53f489356 providers/implementations/include/prov/ciphercommon.h +e6f756d9469a0eae4c14fa23a71f1cd055f3de3b870c1df3e3f6de9befe6913c providers/implementations/include/prov/ciphercommon_aead.h +2d6ce3a0479ffa2acf9212c7120e2e30ad158a6714bb4b97b3dd09ae18e08a94 providers/implementations/include/prov/ciphercommon_ccm.h +da884dcdbb19ca9cacb7e5c26bebbe63789078c0403a803c27198c9b4032816e providers/implementations/include/prov/ciphercommon_gcm.h +b2f4aa477c3a2731dfbb5720ce87df653c55df24947c95d50a229be23e108661 providers/implementations/include/prov/digestcommon.h +b2eb44c5f95633eee9a173cd190e0a65200683aa84b458ce8f9fc7d4a425de49 providers/implementations/include/prov/drbg.h 1baf1c06b20a0eb8ec271452544922d67c1cc168dbe9853b259191de4bd99918 providers/implementations/include/prov/ecx.h -b0d1f6fc3c9220fe6d4656e487bad8df16b6f840054018b95b2752ea9aef822d providers/implementations/include/prov/hmac_drbg.h -e6cdbc04157b3009a6a478670d2ba7ca8dc896967031040f104d7d0fb30c2896 providers/implementations/include/prov/implementations.h +062b49fc5cfa405fbcb184b1b48c9141db22531493bf828ba8543d24b0b72692 providers/implementations/include/prov/hmac_drbg.h +47c1bc8d13b5a9e2c483cc0c32872c4e8587c8bc4a3525fa37345085ad230544 providers/implementations/include/prov/implementations.h 05eedab6b16c80025f72281fa619d9480c437b800cb821b761fe4c05bc9d3af0 providers/implementations/include/prov/kdfexchange.h 4014246d44fa3f34aad5372c75d3f7eea528f1cf1798e30d5627e7620a356631 providers/implementations/include/prov/macsignature.h b41c9a4e90d951a2d0e796b1cbbdbe8cb6fc18306d9b70be7a489249c11c294a providers/implementations/include/prov/ml_dsa.h 511ad835639f071e99eaff6dcbf516999d108ea8b3f5f3f027e0982a916cf3c3 providers/implementations/include/prov/ml_kem.h -8b678d26c077e9135171aa27a8038041f320aa17a3441240865c54859c864ebb providers/implementations/include/prov/mlx_kem.h -31615d056bbab02da153cc408071640af27978eb0e4cd8bbf448a01c4a32b86f providers/implementations/include/prov/names.h +190f66af533067b80f18d7a12ba5440927e3e93b218f67473b4dea7dd9db88a6 providers/implementations/include/prov/mlx_kem.h +908dca7148941b873b18d398e0a7f72565e5d0bbe0a6f6de7928f5e60c9b3d69 providers/implementations/include/prov/names.h b9f8781167f274ccd8b643b3bb6c4e1108fb27b2aae588518261af9415228dae providers/implementations/include/prov/seeding.h -194f0a3fd18f87467a1c311970155cf2668f1abcbbc8c16a96765bc5b152d5a6 providers/implementations/include/prov/skeymgmt_lcl.h -ab4c9694d2d918304991ca85772e6ac65cdc33e44ae6de3efbdc45bd49d9f706 providers/implementations/kdfs/hkdf.c -e8b4e8ebd10872ee42beeeffff7458b1d2991833edbc763e2275ce4060867b0c providers/implementations/kdfs/hmacdrbg_kdf.c -84a83391cd7215a0d3d822f59cd08a465f82467b0e7ab4c369a266a248a99e27 providers/implementations/kdfs/kbkdf.c -80197ea75099756e7e2c66ddf2a69792a8b89942a23c60a8c21e9d87a1e1a8db providers/implementations/kdfs/pbkdf2.c -2993dfc00659a85dfad152a0ce2fea0d457213fe60e03922a0dcd6a89c6827b4 providers/implementations/kdfs/snmpkdf.c -b1b79d9d728c6d2c61e9d895c341d5f0ae882948ac6628e2cb732b3933048c92 providers/implementations/kdfs/srtpkdf.c -4f70b937d163759b713335a194ca44ca084ce2e58c8a6d15c27e5f1bc61b17c3 providers/implementations/kdfs/sshkdf.c -ecac95b5cfe9864793c0d9339acbdd2f0c07938a3e3ab7a007fcf5120f57ff83 providers/implementations/kdfs/sskdf.c -85d950d15affed86179aaae679c13cef87c35261922227bf6599b53703f54a1e providers/implementations/kdfs/tls1_prf.c -384b45edc8246a7d43a8bb6c80b55374fd0e597c7d8fb42648d30cf47104e2e2 providers/implementations/kdfs/x942kdf.c -d46253d805193b2b05fb7389178ac2479505b327b8ed383543cdd800c6532964 providers/implementations/kem/ml_kem_kem.c -35549cec7031452bb5b46aa8a86028abc7a3a2b39f9f6564fa4bd402451bc647 providers/implementations/kem/mlx_kem.c -dc82a1648da73e5b4317b3e9923da2ed9f7eb1419383b562cd9ff5613b72af5e providers/implementations/kem/rsa_kem.c -6e7674572b3824a76270bf51d528c79ecea8e7867aefcda06fcc7d6b75db35b6 providers/implementations/keymgmt/dh_kmgmt.c -d34296ae8595aa1ed90b5652ab7e8fb7e2c5131f5dac7b69eeed7f0fdc2cb6ad providers/implementations/keymgmt/dsa_kmgmt.c -036ef3ffd9452f3079aa07792ce9ad0fcc28d8e66c9fec429e1015c749c81ba7 providers/implementations/keymgmt/ec_kmgmt.c -c3035535ca629fc9a85f64f62412b550b5c8185e57e6382937dc6de374fc5972 providers/implementations/keymgmt/ec_kmgmt_imexport.inc -4f549f95a1781038b107c11c0f961f7e95fe5e002812fb291ecf1ab45a45a20f providers/implementations/keymgmt/ecx_kmgmt.c +0a04040c0c4ee06b61944fea6a1d75592dc7b389a7f2d768e8074d55cc1ed8ba providers/implementations/include/prov/skeymgmt_lcl.h +14f2e7e9601326fd9189abea801b9f7065c4f2659adc1348b996d2bb885860ba providers/implementations/kdfs/hkdf.c +e8b3d0f1c30c586c74de83269d1eb6ca06162d650bab137cb197654094983c25 providers/implementations/kdfs/hmacdrbg_kdf.c +c8f57a189bc32accbd093310f70037fad1092f24c71a91644951097d7abc25a8 providers/implementations/kdfs/kbkdf.c +64e77d99bab659b73935e314c668de386a96740d5a966179b17a8f5f15bd7444 providers/implementations/kdfs/pbkdf2.c +f932249134d558850b996ce0cc9c626b29675f8f6f375d388dc1b536ddd133ab providers/implementations/kdfs/sshkdf.c +06d709ffd6ef22ef24a9db825bb7de0eb511db64e4e79c2a5a3c893cddd3a584 providers/implementations/kdfs/sskdf.c +5cc5da200830aa45a30bc534d635c34e0bd1a3796c7d96a1248047244ed667e3 providers/implementations/kdfs/tls1_prf.c +cf5f16d1f4e347ea6ea770a097f76e4b6842693e6cc9ca0d616b691bfb76e7b7 providers/implementations/kdfs/x942kdf.c +0f03112b2841a3ced4ca7365cfcc4d0e6c8212441847b4f7ed9108193c686c09 providers/implementations/kem/ml_kem_kem.c +a2e2b44064ef44b880b89ab6adc83686936acaa906313a37e5ec69d632912034 providers/implementations/kem/mlx_kem.c +6eb65141e7adc7dee84cef8327c1dab2304149f542673042917e31f3cf41576d providers/implementations/kem/rsa_kem.c +28bc9546d783cfaf0bdb0eeb95008aabac927c36586493d33dca49820474dea2 providers/implementations/keymgmt/dh_kmgmt.c +9310fe4960486ad243ac0a53c7a8999aa10106e6608bbfaaebf3cc5f929c47c5 providers/implementations/keymgmt/dsa_kmgmt.c +061cb77edf258d7197e718e15a032fa65c26221f9ad3df117f6d85a8aebd37b1 providers/implementations/keymgmt/ec_kmgmt.c +258ae17bb2dd87ed1511a8eb3fe99eed9b77f5c2f757215ff6b3d0e8791fc251 providers/implementations/keymgmt/ec_kmgmt_imexport.inc +075b8a594791333ccecd9056a3791f16e6d7d96bbc918b3358500f8289ee2e0e providers/implementations/keymgmt/ecx_kmgmt.c daf35a7ab961ef70aefca981d80407935904c5da39dca6692432d6e6bc98759d providers/implementations/keymgmt/kdf_legacy_kmgmt.c -487f2b99c0dd9c51c63df758884c3f9bff45cc52b302c402df1fda578f4851ef providers/implementations/keymgmt/mac_legacy_kmgmt.c -bdf5f65254440afed4386c7a9cc8f94db6807b5c38c65bde58bd4e73dec61ba8 providers/implementations/keymgmt/ml_dsa_kmgmt.c -623db74c37a81db77e2d6449a79d72f59eec739465210df468696b597e35efa2 providers/implementations/keymgmt/ml_kem_kmgmt.c -6266925c99fa47f502aedef4403a6f93dbb4db2459d84babd347176939af45fe providers/implementations/keymgmt/mlx_kmgmt.c -e9e85e25dbb14f835947cfa53c10e7f1aa9868bbc8f1c43827365a39733ecbb0 providers/implementations/keymgmt/rsa_kmgmt.c -fe6c78fb84507d912c506f1553f85145212ce0fdc0828eaafeb5f277d3b9539b providers/implementations/keymgmt/slh_dsa_kmgmt.c -d090dc16657b4de57feef133d21f1f5f9892352f8fb30b905b9ac7c1271ddc72 providers/implementations/macs/cmac_prov.c -2183fc7defac5ae173b1fc449dbeb2a4ffcbe510631e525acbf3e2be6b2baf61 providers/implementations/macs/gmac_prov.c -0187e76d4b6a8528f9b8b056c6e175186e650c9007c46a0f772d963c8fd539aa providers/implementations/macs/hmac_prov.c -ce7866f670bb5b80b8fec42c79ed439e3f1f7edbab561f9a10042ccdbec2e855 providers/implementations/macs/kmac_prov.c -9a796599b6aa54cd7851a04e4929b47f172b9818259b5debd22858a1faee6e2e providers/implementations/rands/drbg.c -8e970f917e4e9a9327130181de6949324634101f942ef3c74ad8dc479c2696eb providers/implementations/rands/drbg_ctr.c -8f78fc29274a8f702eea977dc1dd0d250de3346714ef4ae2d104b0200538518e providers/implementations/rands/drbg_hash.c -d8320cb81503fb2a80fb96a65eac4c36a5d43a1ef0f05cf6dd91d72306a5b8ff providers/implementations/rands/drbg_hmac.c -5fd5e9999104c827c7df524cad88309d28ea01c376096a23ba7e227af936dde6 providers/implementations/rands/fips_crng_test.c -dffbf7811597d68635e811915c76f3a85c351a482692f029a2e01f21cad377b3 providers/implementations/rands/test_rng.c -a4e24f5472d4c39a8e490e36164dc43a70d8aaaa49b21f892d20c070d5d6f36b providers/implementations/signature/dsa_sig.c -66475b29b483968ecab15e5f909f7bd506d47283d039e5784a63bba5eb7ad538 providers/implementations/signature/ecdsa_sig.c -1a58e66cb9bc1815dc1d0523792f92119a24a5900d35fe93e97022613e93b867 providers/implementations/signature/eddsa_sig.c -c0fc1e0349777e063b477026e8d3086b6f81956256258c2c35ee8f32d628e60a providers/implementations/signature/mac_legacy_sig.c -f5c756422350efb6f67001ac52585c05f57cca2c24a3c9ae8d91d63d11617aea providers/implementations/signature/ml_dsa_sig.c -5ebef1095f95ad836bd679f2453bb3f762321f45104d2f2632846172e89634bb providers/implementations/signature/rsa_sig.c -7695ad423763b51abfbdfd1d04a902df2ec9c137e2b7a30ea214d82025840b68 providers/implementations/signature/slh_dsa_sig.c +d97d7c8d3410b3e560ef2becaea2a47948e22205be5162f964c5e51a7eef08cb providers/implementations/keymgmt/mac_legacy_kmgmt.c +4c1ee748786aee7ab7ccb4ce1892bc5c01eba3c44dda0b4577eb4a814d9c20e2 providers/implementations/keymgmt/ml_dsa_kmgmt.c +7970dc355dbfec2b4ba97fad2bb474a1b3c70f23aa8efd3d3f682d01108901b9 providers/implementations/keymgmt/ml_kem_kmgmt.c +d016400fed399cf33309466bee92969cbbd547c59641c78a949289e40ecadc59 providers/implementations/keymgmt/mlx_kmgmt.c +013aeaaeb1595a006c131623720cc7d6e9dfa6d4d012fd8bf33746b0be674e16 providers/implementations/keymgmt/rsa_kmgmt.c +58f822039db3f0d5c14021979074f8782955b9843c490010521f85d61ccdfa2e providers/implementations/keymgmt/slh_dsa_kmgmt.c +3347dd12a0ac90242850e90a0f99900f519b05315421528d71985fc96e7b656f providers/implementations/macs/cmac_prov.c +9b7d458a8b1dacda4c385a278b7abe41f5b8735a7b776b3d03706594b7539e6f providers/implementations/macs/gmac_prov.c +173a83d102583b2b9f6115e5cae659d71c2f9249100b34fd4f39d4886cfb666b providers/implementations/macs/hmac_prov.c +75f44ca4db9391cd6b3e3627393b1286349caffb103a44df07fa86884911f8a3 providers/implementations/macs/kmac_prov.c +4e7fe2014595dcb6eaf88e30100067ad5c5f2ef3dd9a157d28c43e75fd2ab97e providers/implementations/rands/drbg.c +5f7b8131b75082e5f16db7cd19db14fe0b5be01edd53e6977e7736f73bf624be providers/implementations/rands/drbg_ctr.c +a2a54896288a301d381367983dc7639da783c738c05e14ddf750bfd7b1e191ea providers/implementations/rands/drbg_hash.c +b25f130aaa088424e1d36af44de9e011a8a0504097b418c7f2657f7be77aaa08 providers/implementations/rands/drbg_hmac.c +8a2986f5f5c0246273af0a117a1ad7bb867753e076a6a74f0e311f58603cb937 providers/implementations/rands/fips_crng_test.c +1167a0ea0c61cfd90f4a3345591b62570825d9ab2c4e907947f968f3ec9c90d4 providers/implementations/rands/test_rng.c +6e138784e658cdba20177a5e708f52cbc8a152af931129584ebbb5d8067269bf providers/implementations/signature/dsa_sig.c +cabfdb9478587ab1d4ff927d77de4c5cc10be5f5bc572ba8f3276388d3300a6d providers/implementations/signature/ecdsa_sig.c +44afbc83fa74c09cd277dbee7b1960d43b2cb06d7cc1bc387fb0069e83cb53cd providers/implementations/signature/eddsa_sig.c +24f2fa01396370c95c1909a310dda63968da9aedf1341ddaf6f3792d9a478c70 providers/implementations/signature/mac_legacy_sig.c +4244c5a7248ec4d63b3b5b9bcbd680b7cb431969db82e3eb0ab394b14dda2d1c providers/implementations/signature/ml_dsa_sig.c +84e1ce5bee4aec7f518565e0e1cfcae2fd2638e5e9c96080c6a77238186718f7 providers/implementations/signature/rsa_sig.c +f462324cd5cb56b2aa4faf07cfe3eb4a7cd55a306d283133fa6e6730cf080998 providers/implementations/signature/slh_dsa_sig.c 7f5472f4ff5f4394844edb9c189a740cd98d083d828b80b5d7bb8bf08f0271de providers/implementations/skeymgmt/aes_skmgmt.c -7c72db8df7e8caa9c995d92f8c27a62655f3ddb885d6ddf3946fd199e982371f providers/implementations/skeymgmt/generic.c -d57ca33b29da0658c130128363f3c005e915e9ae8ecfe2c4e355416900ebe828 ssl/record/methods/ssl3_cbc.c -f8fb441366e59328f29ccecdb2e1e978b9eeb9e7aeb793b9a8b547c741534a7f ssl/record/methods/tls_pad.c +d51a498cd9c89c996b959f017d07773ae85d6f6442d85ead5b2249d0a2da102f providers/implementations/skeymgmt/generic.c +0b73a04f8a03106e2a0fea10978f9888158046c29c3993ca6557f5a6403d5580 ssl/record/methods/ssl3_cbc.c +9050bea375a8943c97725f8a3b9e8a7c262325ac56c327f8384b964c04161f4b ssl/record/methods/tls_pad.c diff --git a/providers/fips.checksum b/providers/fips.checksum index 2c7bab5eab..ec47006c1a 100644 --- a/providers/fips.checksum +++ b/providers/fips.checksum @@ -1 +1 @@ -864d3535e188440ca60b8268ce8137e0cffb870be990531fd9f68a23f0ffa898 providers/fips-sources.checksums +7fa38f7a9245cceb1d6e431f8e54a34b20253ba72aa231cc8a54e28f66623e36 providers/fips-sources.checksums diff --git a/providers/fips.module.sources b/providers/fips.module.sources index 5358458573..799073c2c6 100644 --- a/providers/fips.module.sources +++ b/providers/fips.module.sources @@ -41,7 +41,6 @@ crypto/aes/asm/vpaes-loongarch64.pl crypto/aes/asm/vpaes-ppc.pl crypto/aes/asm/vpaes-x86.pl crypto/aes/asm/vpaes-x86_64.pl -crypto/aligned_alloc.c crypto/alphacpuid.pl crypto/arm64cpuid.pl crypto/armcap.c @@ -64,7 +63,6 @@ crypto/bn/asm/ppc-mont.pl crypto/bn/asm/ppc.pl crypto/bn/asm/ppc64-mont-fixed.pl crypto/bn/asm/ppc64-mont.pl -crypto/bn/asm/riscv64-mont.pl crypto/bn/asm/rsaz-2k-avx512.pl crypto/bn/asm/rsaz-2k-avxifma.pl crypto/bn/asm/rsaz-3k-avx512.pl @@ -115,7 +113,7 @@ crypto/bn/bn_prime.c crypto/bn/bn_prime.h crypto/bn/bn_rand.c crypto/bn/bn_recp.c -crypto/bn/bn_rsa_fips186_5.c +crypto/bn/bn_rsa_fips186_4.c crypto/bn/bn_shift.c crypto/bn/bn_sqr.c crypto/bn/bn_sqrt.c @@ -257,7 +255,6 @@ crypto/lhash/lhash_local.h crypto/loongarch64cpuid.pl crypto/loongarchcap.c crypto/mem_clr.c -crypto/ml_dsa/asm/ml_dsa_ntt-x86_64.pl crypto/ml_dsa/ml_dsa_encoders.c crypto/ml_dsa/ml_dsa_hash.h crypto/ml_dsa/ml_dsa_key.c @@ -270,7 +267,6 @@ crypto/ml_dsa/ml_dsa_ntt.c crypto/ml_dsa/ml_dsa_params.c crypto/ml_dsa/ml_dsa_poly.h crypto/ml_dsa/ml_dsa_sample.c -crypto/ml_dsa/ml_dsa_sample_hw_x86_64.inc crypto/ml_dsa/ml_dsa_sign.c crypto/ml_dsa/ml_dsa_sign.h crypto/ml_dsa/ml_dsa_vector.h @@ -360,7 +356,6 @@ crypto/sha/asm/keccak1600-ppc64.pl crypto/sha/asm/keccak1600-s390x.pl crypto/sha/asm/keccak1600-x86_64.pl crypto/sha/asm/keccak1600p8-ppc.pl -crypto/sha/asm/keccak1600x4-avx512vl.pl crypto/sha/asm/sha1-586.pl crypto/sha/asm/sha1-alpha.pl crypto/sha/asm/sha1-armv4-large.pl @@ -402,8 +397,6 @@ crypto/sha/keccak1600.c crypto/sha/sha1dgst.c crypto/sha/sha256.c crypto/sha/sha3.c -crypto/sha/sha3_encode.c -crypto/sha/sha3_x4_avx512vl.c crypto/sha/sha512.c crypto/sha/sha_local.h crypto/slh_dsa/slh_adrs.c @@ -443,6 +436,7 @@ include/crypto/aes_platform.h include/crypto/asn1.h include/crypto/asn1_dsa.h include/crypto/bn.h +include/crypto/bn_conf.h.in include/crypto/bn_dh.h include/crypto/cmac.h include/crypto/context.h @@ -456,7 +450,7 @@ include/crypto/ec.h include/crypto/ecx.h include/crypto/evp.h include/crypto/lhash.h -include/crypto/md32_common.inc +include/crypto/md32_common.h include/crypto/ml_dsa.h include/crypto/ml_kem.h include/crypto/modes.h @@ -470,7 +464,6 @@ include/crypto/sparse_array.h include/crypto/types.h include/internal/bio.h include/internal/common.h -include/internal/conf.h include/internal/constant_time.h include/internal/core.h include/internal/cryptlib.h @@ -511,7 +504,6 @@ include/internal/thread_once.h include/internal/threads_common.h include/internal/time.h include/internal/tlsgroups.h -include/internal/tlssigalgs.h include/internal/to_hex.h include/internal/tsan_assist.h include/openssl/aes.h @@ -571,8 +563,11 @@ include/openssl/opensslconf.h include/openssl/opensslv.h.in include/openssl/param_build.h include/openssl/params.h +include/openssl/pem.h +include/openssl/pemerr.h include/openssl/pkcs7.h.in include/openssl/pkcs7err.h +include/openssl/posix_time.h include/openssl/prov_ssl.h include/openssl/proverr.h include/openssl/provider.h @@ -588,6 +583,8 @@ include/openssl/symhacks.h include/openssl/thread.h include/openssl/trace.h include/openssl/types.h +include/openssl/ui.h.in +include/openssl/uierr.h include/openssl/x509.h.in include/openssl/x509_vfy.h.in include/openssl/x509err.h @@ -621,7 +618,6 @@ providers/common/include/prov/der_ec.h.in providers/common/include/prov/der_ecx.h.in providers/common/include/prov/der_hkdf.h.in providers/common/include/prov/der_ml_dsa.h.in -providers/common/include/prov/der_pq_dsa.h providers/common/include/prov/der_rsa.h.in providers/common/include/prov/der_slh_dsa.h.in providers/common/include/prov/der_wrap.h.in @@ -638,21 +634,20 @@ providers/common/securitycheck.c providers/common/securitycheck_fips.c providers/fips/fips_entry.c providers/fips/fipsindicator.c -providers/fips/fipsparams.inc.in providers/fips/fipsprov.c providers/fips/include/fips/fipsindicator.h +providers/fips/include/fips_indicator_params.inc +providers/fips/include/fips_selftest_params.inc providers/fips/include/fipscommon.h providers/fips/self_test.c providers/fips/self_test.h -providers/fips/self_test_data.c +providers/fips/self_test_data.inc providers/fips/self_test_kats.c providers/implementations/asymciphers/rsa_enc.c -providers/implementations/asymciphers/rsa_enc.inc.in providers/implementations/ciphers/cipher_aes.c providers/implementations/ciphers/cipher_aes.h providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.c providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.h -providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.inc.in providers/implementations/ciphers/cipher_aes_cbc_hmac_sha1_etm_hw.c providers/implementations/ciphers/cipher_aes_cbc_hmac_sha1_hw.c providers/implementations/ciphers/cipher_aes_cbc_hmac_sha256_etm_hw.c @@ -663,33 +658,24 @@ providers/implementations/ciphers/cipher_aes_cbc_hmac_sha_etm.h providers/implementations/ciphers/cipher_aes_ccm.c providers/implementations/ciphers/cipher_aes_ccm.h providers/implementations/ciphers/cipher_aes_ccm_hw.c +providers/implementations/ciphers/cipher_aes_ccm_hw_aesni.inc +providers/implementations/ciphers/cipher_aes_cfb.h +providers/implementations/ciphers/cipher_aes_cfb_hw.c +providers/implementations/ciphers/cipher_aes_cfb_hw_aesni.inc providers/implementations/ciphers/cipher_aes_cts.inc providers/implementations/ciphers/cipher_aes_gcm.c providers/implementations/ciphers/cipher_aes_gcm.h providers/implementations/ciphers/cipher_aes_gcm_hw.c -providers/implementations/ciphers/cipher_aes_gcm_hw_aesni.c -providers/implementations/ciphers/cipher_aes_gcm_hw_s390x.c -providers/implementations/ciphers/cipher_aes_gcm_hw_armv8.c -providers/implementations/ciphers/cipher_aes_gcm_hw_ppc.c -providers/implementations/ciphers/cipher_aes_gcm_hw_rv32i.c -providers/implementations/ciphers/cipher_aes_gcm_hw_rv64i.c -providers/implementations/ciphers/cipher_aes_gcm_hw_t4.c -providers/implementations/ciphers/cipher_aes_hw_aesni.c -providers/implementations/ciphers/cipher_aes_hw_armv8.c -providers/implementations/ciphers/cipher_aes_hw_rv32i.c -providers/implementations/ciphers/cipher_aes_hw_rv64i.c -providers/implementations/ciphers/cipher_aes_hw_s390x.c -providers/implementations/ciphers/cipher_aes_hw_t4.c +providers/implementations/ciphers/cipher_aes_gcm_hw_aesni.inc +providers/implementations/ciphers/cipher_aes_gcm_hw_vaes_avx512.inc providers/implementations/ciphers/cipher_aes_hw.c +providers/implementations/ciphers/cipher_aes_hw_aesni.inc providers/implementations/ciphers/cipher_aes_ocb.c providers/implementations/ciphers/cipher_aes_ocb.h -providers/implementations/ciphers/cipher_aes_ocb.inc.in providers/implementations/ciphers/cipher_aes_ocb_hw.c providers/implementations/ciphers/cipher_aes_wrp.c -providers/implementations/ciphers/cipher_aes_wrp.inc.in providers/implementations/ciphers/cipher_aes_xts.c providers/implementations/ciphers/cipher_aes_xts.h -providers/implementations/ciphers/cipher_aes_xts.inc.in providers/implementations/ciphers/cipher_aes_xts_fips.c providers/implementations/ciphers/cipher_aes_xts_hw.c providers/implementations/ciphers/cipher_cts.c @@ -699,32 +685,19 @@ providers/implementations/ciphers/cipher_tdes.h providers/implementations/ciphers/cipher_tdes_common.c providers/implementations/ciphers/cipher_tdes_hw.c providers/implementations/ciphers/ciphercommon.c -providers/implementations/ciphers/ciphercommon.inc.in providers/implementations/ciphers/ciphercommon_block.c providers/implementations/ciphers/ciphercommon_ccm.c -providers/implementations/ciphers/ciphercommon_ccm.inc.in providers/implementations/ciphers/ciphercommon_ccm_hw.c providers/implementations/ciphers/ciphercommon_gcm.c -providers/implementations/ciphers/ciphercommon_gcm.inc.in providers/implementations/ciphers/ciphercommon_gcm_hw.c providers/implementations/ciphers/ciphercommon_hw.c providers/implementations/ciphers/ciphercommon_local.h -providers/implementations/digests/cshake_prov.c -providers/implementations/digests/cshake_prov.inc.in providers/implementations/digests/digestcommon.c -providers/implementations/digests/digestcommon.inc.in -providers/implementations/digests/ml_dsa_mu_prov.c -providers/implementations/digests/ml_dsa_mu_prov.inc.in providers/implementations/digests/sha2_prov.c -providers/implementations/digests/sha2_prov.inc.in providers/implementations/digests/sha3_prov.c -providers/implementations/digests/sha3_prov.inc.in providers/implementations/exchange/dh_exch.c -providers/implementations/exchange/dh_exch.inc.in providers/implementations/exchange/ecdh_exch.c -providers/implementations/exchange/ecdh_exch.inc.in providers/implementations/exchange/ecx_exch.c -providers/implementations/exchange/ecx_exch.inc.in providers/implementations/exchange/kdf_exch.c providers/implementations/include/prov/ciphercommon.h providers/implementations/include/prov/ciphercommon_aead.h @@ -744,85 +717,46 @@ providers/implementations/include/prov/names.h providers/implementations/include/prov/seeding.h providers/implementations/include/prov/skeymgmt_lcl.h providers/implementations/kdfs/hkdf.c -providers/implementations/kdfs/hkdf.inc.in providers/implementations/kdfs/hmacdrbg_kdf.c -providers/implementations/kdfs/hmacdrbg_kdf.inc.in providers/implementations/kdfs/kbkdf.c -providers/implementations/kdfs/kbkdf.inc.in providers/implementations/kdfs/pbkdf2.c -providers/implementations/kdfs/pbkdf2.inc.in -providers/implementations/kdfs/snmpkdf.c -providers/implementations/kdfs/snmpkdf.inc.in -providers/implementations/kdfs/srtpkdf.c -providers/implementations/kdfs/srtpkdf.inc.in providers/implementations/kdfs/sshkdf.c -providers/implementations/kdfs/sshkdf.inc.in providers/implementations/kdfs/sskdf.c -providers/implementations/kdfs/sskdf.inc.in providers/implementations/kdfs/tls1_prf.c -providers/implementations/kdfs/tls1_prf.inc.in providers/implementations/kdfs/x942kdf.c -providers/implementations/kdfs/x942kdf.inc.in -providers/implementations/kdfs/x963kdf.inc.in providers/implementations/kem/ml_kem_kem.c -providers/implementations/kem/ml_kem_kem.inc.in providers/implementations/kem/mlx_kem.c providers/implementations/kem/rsa_kem.c -providers/implementations/kem/rsa_kem.inc.in providers/implementations/keymgmt/dh_kmgmt.c -providers/implementations/keymgmt/dh_kmgmt.inc.in providers/implementations/keymgmt/dsa_kmgmt.c -providers/implementations/keymgmt/dsa_kmgmt.inc.in providers/implementations/keymgmt/ec_kmgmt.c providers/implementations/keymgmt/ec_kmgmt_imexport.inc providers/implementations/keymgmt/ecx_kmgmt.c -providers/implementations/keymgmt/ecx_kmgmt.inc.in providers/implementations/keymgmt/kdf_legacy_kmgmt.c providers/implementations/keymgmt/mac_legacy_kmgmt.c -providers/implementations/keymgmt/mac_legacy_kmgmt.inc.in providers/implementations/keymgmt/ml_dsa_kmgmt.c -providers/implementations/keymgmt/ml_dsa_kmgmt.inc.in providers/implementations/keymgmt/ml_kem_kmgmt.c -providers/implementations/keymgmt/ml_kem_kmgmt.inc.in providers/implementations/keymgmt/mlx_kmgmt.c -providers/implementations/keymgmt/mlx_kmgmt.inc.in providers/implementations/keymgmt/rsa_kmgmt.c providers/implementations/keymgmt/slh_dsa_kmgmt.c -providers/implementations/keymgmt/slh_dsa_kmgmt.inc.in providers/implementations/macs/cmac_prov.c -providers/implementations/macs/cmac_prov.inc.in providers/implementations/macs/gmac_prov.c -providers/implementations/macs/gmac_prov.inc.in providers/implementations/macs/hmac_prov.c -providers/implementations/macs/hmac_prov.inc.in providers/implementations/macs/kmac_prov.c -providers/implementations/macs/kmac_prov.inc.in providers/implementations/rands/drbg.c providers/implementations/rands/drbg_ctr.c -providers/implementations/rands/drbg_ctr.inc.in providers/implementations/rands/drbg_hash.c -providers/implementations/rands/drbg_hash.inc.in providers/implementations/rands/drbg_hmac.c -providers/implementations/rands/drbg_hmac.inc.in providers/implementations/rands/fips_crng_test.c -providers/implementations/rands/fips_crng_test.inc.in providers/implementations/rands/test_rng.c -providers/implementations/rands/test_rng.inc.in providers/implementations/signature/dsa_sig.c -providers/implementations/signature/dsa_sig.inc.in providers/implementations/signature/ecdsa_sig.c -providers/implementations/signature/ecdsa_sig.inc.in providers/implementations/signature/eddsa_sig.c -providers/implementations/signature/eddsa_sig.inc.in providers/implementations/signature/mac_legacy_sig.c providers/implementations/signature/ml_dsa_sig.c -providers/implementations/signature/ml_dsa_sig.inc.in providers/implementations/signature/rsa_sig.c -providers/implementations/signature/rsa_sig.inc.in providers/implementations/signature/slh_dsa_sig.c -providers/implementations/signature/slh_dsa_sig.inc.in providers/implementations/skeymgmt/aes_skmgmt.c providers/implementations/skeymgmt/generic.c -providers/implementations/skeymgmt/generic.inc.in ssl/record/methods/ssl3_cbc.c ssl/record/methods/tls_pad.c diff --git a/providers/fips/build.info b/providers/fips/build.info index 895c5e9d99..9756ad3f79 100644 --- a/providers/fips/build.info +++ b/providers/fips/build.info @@ -1,10 +1,6 @@ # We include the provider implementation into ../libfips.a, so that all # platforms can resolve symbols in other members of that library. -SOURCE[../libfips.a]=fipsprov.c self_test.c self_test_data.c self_test_kats.c fipsindicator.c +SOURCE[../libfips.a]=fipsprov.c self_test.c self_test_kats.c fipsindicator.c # It is necessary to have an explicit entry point SOURCE[../fips]=fips_entry.c - -DEPEND[]=fipsparams.inc -DEPEND[fipsparams.inc]=../../util/perl|OpenSSL/fipsparams.pm -GENERATE[fipsparams.inc]=fipsparams.inc.in diff --git a/providers/fips/fipsindicator.c b/providers/fips/fipsindicator.c index 55f287324b..38323c5d5d 100644 --- a/providers/fips/fipsindicator.c +++ b/providers/fips/fipsindicator.c @@ -58,7 +58,7 @@ int ossl_FIPS_IND_get_settable(const OSSL_FIPS_IND *ind, int id) int ossl_FIPS_IND_on_unapproved(OSSL_FIPS_IND *ind, int id, OSSL_LIB_CTX *libctx, const char *algname, const char *opname, - enum fips_config_id config_id) + OSSL_FIPS_IND_CHECK_CB *config_check_fn) { /* Set to unapproved. Once unapproved mode is set this will not be reset */ ind->approved = 0; @@ -69,7 +69,8 @@ int ossl_FIPS_IND_on_unapproved(OSSL_FIPS_IND *ind, int id, * assumed to be strict. */ if (ossl_FIPS_IND_get_settable(ind, id) == OSSL_FIPS_IND_STATE_TOLERANT - || (ossl_fips_config(libctx, config_id) == OSSL_FIPS_IND_STATE_TOLERANT)) { + || (config_check_fn != NULL + && config_check_fn(libctx) == OSSL_FIPS_IND_STATE_TOLERANT)) { return ossl_FIPS_IND_callback(libctx, algname, opname); } /* Strict mode gets here: This returns an error */ diff --git a/providers/fips/fipsparams.inc.in b/providers/fips/fipsparams.inc.in deleted file mode 100644 index e898c93ee4..0000000000 --- a/providers/fips/fipsparams.inc.in +++ /dev/null @@ -1,63 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* - * Handles the loading of FIPS algorithm conditional options from a config file - * passed from the core using OSSL_PARAM. - * - * The perl function produce_fips_params() generates code that: - * - Defines the FIPS_PARAMS structure with fields for each item. - * - Creates a function init_fips_params() to initialize the structure with default values. - * - Creates a function fips_get_params_from_core() to retrieve values from the core. - * - Defines a macro OSSL_FIPS_PARAMS_DEFN_TYPES listing the parameters. - * - Creates a function return_fips_params() to return values to the core. - * - Creates accessor functions for parameters marked as 'indicator'. - * - * The fields of the table below are: - * 1. field: The name of the field in the FIPS_PARAMS structure. - * 2. name: The OSSL_PARAM name used to identify the parameter. - * 3. type: The C type of the field (e.g., "unsigned char" or "const char *"). - * 4. default: The default value for the field. - * 5. description: A tag indicating usage. If set to 'indicator', an accessor function - * ossl_fips_config_() is generated. - */ -{- use OpenSSL::fipsparams qw(produce_fips_params); -} -{- produce_fips_params( - [ 'security_checks', 'SECURITY_CHECKS', 'unsigned char', '1', 'indicator' ], - [ 'tls1_prf_ems_check', 'TLS1_PRF_EMS_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'no_short_mac', 'NO_SHORT_MAC', 'unsigned char', '1', 'indicator' ], - [ 'hmac_key_check', 'HMAC_KEY_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'kmac_key_check', 'KMAC_KEY_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'restricted_drbg_digests', 'DRBG_TRUNC_DIGEST', 'unsigned char', '0', 'indicator' ], - [ 'signature_digest_check', 'SIGNATURE_DIGEST_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'hkdf_digest_check', 'HKDF_DIGEST_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'tls13_kdf_digest_check', 'TLS13_KDF_DIGEST_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'tls1_prf_digest_check', 'TLS1_PRF_DIGEST_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'sshkdf_digest_check', 'SSHKDF_DIGEST_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'sskdf_digest_check', 'SSKDF_DIGEST_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'x963kdf_digest_check', 'X963KDF_DIGEST_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'dsa_sign_disallowed', 'DSA_SIGN_DISABLED', 'unsigned char', '0', 'indicator' ], - [ 'tdes_encrypt_disallowed', 'TDES_ENCRYPT_DISABLED', 'unsigned char', '0', 'indicator' ], - [ 'rsa_pkcs15_padding_disabled', 'RSA_PKCS15_PAD_DISABLED', 'unsigned char', '0', 'indicator' ], - [ 'rsa_pss_saltlen_check', 'RSA_PSS_SALTLEN_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'rsa_sign_x931_disallowed', 'RSA_SIGN_X931_PAD_DISABLED', 'unsigned char', '0', 'indicator' ], - [ 'hkdf_key_check', 'HKDF_KEY_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'kbkdf_key_check', 'KBKDF_KEY_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'tls13_kdf_key_check', 'TLS13_KDF_KEY_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'tls1_prf_key_check', 'TLS1_PRF_KEY_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'sshkdf_key_check', 'SSHKDF_KEY_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'sskdf_key_check', 'SSKDF_KEY_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'x963kdf_key_check', 'X963KDF_KEY_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'x942kdf_key_check', 'X942KDF_KEY_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'pbkdf2_lower_bound_check', 'PBKDF2_LOWER_BOUND_CHECK', 'unsigned char', '1', 'indicator' ], - [ 'ecdh_cofactor_check', 'ECDH_COFACTOR_CHECK', 'unsigned char', '0', 'indicator' ], - [ 'module_filename', 'OSSL_PROV_PARAM_CORE_MODULE_FILENAME', 'const char *', 'NULL', 'selftest' ], - [ 'module_checksum_data', 'OSSL_PROV_FIPS_PARAM_MODULE_MAC', 'const char *', 'NULL', 'selftest' ], - [ 'conditional_error_check', 'OSSL_PROV_FIPS_PARAM_CONDITIONAL_ERRORS', 'unsigned char', '1', 'selftest' ], - [ 'defer_tests', 'OSSL_PROV_FIPS_PARAM_DEFER_TESTS', 'unsigned char', '0', 'selftest' ]) -} diff --git a/providers/fips/fipsprov.c b/providers/fips/fipsprov.c index 5f331920ba..8967a21e9a 100644 --- a/providers/fips/fipsprov.c +++ b/providers/fips/fipsprov.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -49,10 +49,8 @@ static OSSL_FUNC_provider_query_operation_fn fips_query; static OSSL_FUNC_provider_query_operation_fn fips_query_internal; static OSSL_FUNC_provider_random_bytes_fn fips_random_bytes; -#define ALGC(NAMES, FUNC, CHECK) \ - { \ - { NAMES, FIPS_DEFAULT_PROPERTIES, FUNC }, CHECK \ - } +#define ALGC(NAMES, FUNC, CHECK) \ + { { NAMES, FIPS_DEFAULT_PROPERTIES, FUNC }, CHECK } #define ALG(NAMES, FUNC) ALGC(NAMES, FUNC, NULL) extern OSSL_FUNC_core_thread_start_fn *c_thread_start; @@ -63,6 +61,7 @@ extern OSSL_FUNC_core_thread_start_fn *c_thread_start; */ /* Functions provided by the core */ +static OSSL_FUNC_core_gettable_params_fn *c_gettable_params; static OSSL_FUNC_core_get_params_fn *c_get_params; OSSL_FUNC_core_thread_start_fn *c_thread_start; static OSSL_FUNC_core_new_error_fn *c_new_error; @@ -88,22 +87,26 @@ static OSSL_FUNC_self_test_cb_fn *c_stcbfn = NULL; static OSSL_FUNC_indicator_cb_fn *c_indcbfn = NULL; static OSSL_FUNC_core_get_libctx_fn *c_get_libctx = NULL; -#include "providers/fips/fipsparams.inc" +typedef struct { + const char *option; + unsigned char enabled; +} FIPS_OPTION; typedef struct fips_global_st { const OSSL_CORE_HANDLE *handle; SELF_TEST_POST_PARAMS selftest_params; - FIPS_PARAMS fips_params; - - /* Guards access to deferred self-test */ - CRYPTO_RWLOCK *deferred_lock; +#define OSSL_FIPS_PARAM(structname, paramname, initvalue) \ + FIPS_OPTION fips_##structname; +#include "fips_indicator_params.inc" +#undef OSSL_FIPS_PARAM } FIPS_GLOBAL; -static inline FIPS_PARAMS *get_fips_params(FIPS_GLOBAL *fgbl) +static void init_fips_option(FIPS_OPTION *opt, int enabled) { - return &fgbl->fips_params; + opt->enabled = enabled; + opt->option = enabled ? "1" : "0"; } void *ossl_fips_prov_ossl_ctx_new(OSSL_LIB_CTX *libctx) @@ -113,15 +116,20 @@ void *ossl_fips_prov_ossl_ctx_new(OSSL_LIB_CTX *libctx) if (fgbl == NULL) return NULL; - init_fips_params(&fgbl->fips_params); +#define OSSL_FIPS_PARAM(structname, paramname, initvalue) \ + init_fips_option(&fgbl->fips_##structname, initvalue); +#include "fips_indicator_params.inc" +#undef OSSL_FIPS_PARAM return fgbl; } +static void deferred_deinit(void); + void ossl_fips_prov_ossl_ctx_free(void *fgbl) { - if (((FIPS_GLOBAL *)fgbl)->deferred_lock) - CRYPTO_THREAD_lock_free(((FIPS_GLOBAL *)fgbl)->deferred_lock); + /* Also free deferred variables when the FIPS Global context is killed */ + deferred_deinit(); OPENSSL_free(fgbl); } @@ -139,6 +147,43 @@ static int fips_random_bytes(ossl_unused void *vprov, int which, return RAND_bytes_ex(libctx, buf, n, strength); } +/* + * Parameters to retrieve from the core provider + * NOTE: inside core_get_params() these will be loaded from config items + * stored inside prov->parameters + */ +static int fips_get_params_from_core(FIPS_GLOBAL *fgbl) +{ + OSSL_PARAM core_params[32], *p = core_params; + +#define OSSL_FIPS_PARAM(structname, paramname) \ + *p++ = OSSL_PARAM_construct_utf8_ptr( \ + paramname, (char **)&fgbl->selftest_params.structname, \ + sizeof(fgbl->selftest_params.structname)); + +/* Parameters required for self testing */ +#include "fips_selftest_params.inc" +#undef OSSL_FIPS_PARAM + +/* FIPS indicator options can be enabled or disabled independently */ +#define OSSL_FIPS_PARAM(structname, paramname, initvalue) \ + *p++ = OSSL_PARAM_construct_utf8_ptr( \ + OSSL_PROV_PARAM_##paramname, \ + (char **)&fgbl->fips_##structname.option, \ + sizeof(fgbl->fips_##structname.option)); +#include "fips_indicator_params.inc" +#undef OSSL_FIPS_PARAM + + *p = OSSL_PARAM_construct_end(); + + if (!c_get_params(fgbl->handle, core_params)) { + ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_GET_PARAMETER); + return 0; + } + + return 1; +} + static const OSSL_PARAM *fips_gettable_params(void *provctx) { /* Parameters we provide to the core */ @@ -147,7 +192,12 @@ static const OSSL_PARAM *fips_gettable_params(void *provctx) OSSL_PARAM_DEFN(OSSL_PROV_PARAM_VERSION, OSSL_PARAM_UTF8_PTR, NULL, 0), OSSL_PARAM_DEFN(OSSL_PROV_PARAM_BUILDINFO, OSSL_PARAM_UTF8_PTR, NULL, 0), OSSL_PARAM_DEFN(OSSL_PROV_PARAM_STATUS, OSSL_PARAM_INTEGER, NULL, 0), - OSSL_FIPS_PARAMS_DEFN_TYPES, + +#define OSSL_FIPS_PARAM(structname, paramname, initvalue) \ + OSSL_PARAM_DEFN(OSSL_PROV_PARAM_##paramname, OSSL_PARAM_INTEGER, NULL, 0), +#include "fips_indicator_params.inc" +#undef OSSL_FIPS_PARAM + OSSL_PARAM_END }; return fips_param_types; @@ -172,7 +222,14 @@ static int fips_get_params(void *provctx, OSSL_PARAM params[]) if (p != NULL && !OSSL_PARAM_set_int(p, ossl_prov_is_running())) return 0; - return return_fips_params(params, &fgbl->fips_params); +#define OSSL_FIPS_PARAM(structname, paramname, initvalue) \ + p = OSSL_PARAM_locate(params, OSSL_PROV_PARAM_##paramname); \ + if (p != NULL && !OSSL_PARAM_set_int(p, fgbl->fips_##structname.enabled)) \ + return 0; +#include "fips_indicator_params.inc" +#undef OSSL_FIPS_PARAM + + return 1; } static void set_self_test_cb(FIPS_GLOBAL *fgbl) @@ -194,7 +251,7 @@ static int fips_self_test(void *provctx) OSSL_LIB_CTX_FIPS_PROV_INDEX); set_self_test_cb(fgbl); - return SELF_TEST_post(&fgbl->selftest_params, fgbl, 1) ? 1 : 0; + return SELF_TEST_post(&fgbl->selftest_params, 1) ? 1 : 0; } /* @@ -222,32 +279,27 @@ static int fips_self_test(void *provctx) * we have used historically. */ -#define FIPS_DIGESTS_COMMON() \ - { PROV_NAMES_SHA1, FIPS_DEFAULT_PROPERTIES, ossl_sha1_functions }, \ - { PROV_NAMES_SHA2_224, FIPS_DEFAULT_PROPERTIES, ossl_sha224_functions }, \ - { PROV_NAMES_SHA2_256, FIPS_DEFAULT_PROPERTIES, ossl_sha256_functions }, \ - { PROV_NAMES_SHA2_384, FIPS_DEFAULT_PROPERTIES, ossl_sha384_functions }, \ - { PROV_NAMES_SHA2_512, FIPS_DEFAULT_PROPERTIES, ossl_sha512_functions }, \ - { PROV_NAMES_SHA2_512_224, FIPS_DEFAULT_PROPERTIES, \ - ossl_sha512_224_functions }, \ - { PROV_NAMES_SHA2_512_256, FIPS_DEFAULT_PROPERTIES, \ - ossl_sha512_256_functions }, \ - { PROV_NAMES_SHA3_224, FIPS_DEFAULT_PROPERTIES, ossl_sha3_224_functions }, \ - { PROV_NAMES_SHA3_256, FIPS_DEFAULT_PROPERTIES, ossl_sha3_256_functions }, \ - { PROV_NAMES_SHA3_384, FIPS_DEFAULT_PROPERTIES, ossl_sha3_384_functions }, \ - { PROV_NAMES_SHA3_512, FIPS_DEFAULT_PROPERTIES, ossl_sha3_512_functions }, \ - { PROV_NAMES_SHAKE_128, FIPS_DEFAULT_PROPERTIES, ossl_shake_128_functions }, \ - { PROV_NAMES_SHAKE_256, FIPS_DEFAULT_PROPERTIES, ossl_shake_256_functions }, \ - { PROV_NAMES_CSHAKE_128, FIPS_DEFAULT_PROPERTIES, ossl_cshake_128_functions }, \ - { \ - PROV_NAMES_CSHAKE_256, FIPS_DEFAULT_PROPERTIES, ossl_cshake_256_functions \ +#define FIPS_DIGESTS_COMMON() \ + { PROV_NAMES_SHA1, FIPS_DEFAULT_PROPERTIES, ossl_sha1_functions }, \ + { PROV_NAMES_SHA2_224, FIPS_DEFAULT_PROPERTIES, ossl_sha224_functions }, \ + { PROV_NAMES_SHA2_256, FIPS_DEFAULT_PROPERTIES, ossl_sha256_functions }, \ + { PROV_NAMES_SHA2_384, FIPS_DEFAULT_PROPERTIES, ossl_sha384_functions }, \ + { PROV_NAMES_SHA2_512, FIPS_DEFAULT_PROPERTIES, ossl_sha512_functions }, \ + { PROV_NAMES_SHA2_512_224, FIPS_DEFAULT_PROPERTIES, \ + ossl_sha512_224_functions }, \ + { PROV_NAMES_SHA2_512_256, FIPS_DEFAULT_PROPERTIES, \ + ossl_sha512_256_functions }, \ + { PROV_NAMES_SHA3_224, FIPS_DEFAULT_PROPERTIES, ossl_sha3_224_functions }, \ + { PROV_NAMES_SHA3_256, FIPS_DEFAULT_PROPERTIES, ossl_sha3_256_functions }, \ + { PROV_NAMES_SHA3_384, FIPS_DEFAULT_PROPERTIES, ossl_sha3_384_functions }, \ + { PROV_NAMES_SHA3_512, FIPS_DEFAULT_PROPERTIES, ossl_sha3_512_functions }, \ + { PROV_NAMES_SHAKE_128, FIPS_DEFAULT_PROPERTIES, ossl_shake_128_functions }, \ + { \ + PROV_NAMES_SHAKE_256, FIPS_DEFAULT_PROPERTIES, ossl_shake_256_functions \ } static const OSSL_ALGORITHM fips_digests[] = { FIPS_DIGESTS_COMMON(), -#ifndef OPENSSL_NO_ML_DSA - { PROV_NAMES_ML_DSA_MU, FIPS_DEFAULT_PROPERTIES, ossl_ml_dsa_mu_functions }, -#endif { NULL, NULL, NULL } }; static const OSSL_ALGORITHM fips_digests_internal[] = { @@ -255,10 +307,14 @@ static const OSSL_ALGORITHM fips_digests_internal[] = { /* Used by LMS/HSS */ { PROV_NAMES_SHA2_256_192, FIPS_DEFAULT_PROPERTIES, ossl_sha256_192_internal_functions }, - { PROV_NAMES_CSHAKE_KECCAK_128, FIPS_DEFAULT_PROPERTIES, - ossl_cshake_keccak_128_functions }, - { PROV_NAMES_CSHAKE_KECCAK_256, FIPS_DEFAULT_PROPERTIES, - ossl_cshake_keccak_256_functions }, + /* + * KECCAK-KMAC-128 and KECCAK-KMAC-256 as hashes are mostly useful for + * KMAC128 and KMAC256. + */ + { PROV_NAMES_KECCAK_KMAC_128, FIPS_DEFAULT_PROPERTIES, + ossl_keccak_kmac_128_functions }, + { PROV_NAMES_KECCAK_KMAC_256, FIPS_DEFAULT_PROPERTIES, + ossl_keccak_kmac_256_functions }, { NULL, NULL, NULL } }; @@ -363,83 +419,36 @@ static const OSSL_ALGORITHM fips_macs_internal[] = { { NULL, NULL, NULL } }; -/* clang-format off */ -#define FIPS_KDFS_COMMON() \ - { PROV_NAMES_HKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_hkdf_functions }, \ - { PROV_NAMES_HKDF_SHA256, FIPS_DEFAULT_PROPERTIES, ossl_kdf_hkdf_sha256_functions }, \ - { PROV_NAMES_HKDF_SHA384, FIPS_DEFAULT_PROPERTIES, ossl_kdf_hkdf_sha384_functions }, \ - { PROV_NAMES_HKDF_SHA512, FIPS_DEFAULT_PROPERTIES, ossl_kdf_hkdf_sha512_functions }, \ - { PROV_NAMES_TLS1_3_KDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_tls1_3_kdf_functions }, \ - { PROV_NAMES_PBKDF2, FIPS_DEFAULT_PROPERTIES, ossl_kdf_pbkdf2_functions }, \ - { PROV_NAMES_TLS1_PRF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_tls1_prf_functions } -/* clang-format on */ +#define FIPS_KDFS_COMMON() \ + { PROV_NAMES_HKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_hkdf_functions }, \ + { PROV_NAMES_HKDF_SHA256, FIPS_DEFAULT_PROPERTIES, ossl_kdf_hkdf_sha256_functions }, \ + { PROV_NAMES_HKDF_SHA384, FIPS_DEFAULT_PROPERTIES, ossl_kdf_hkdf_sha384_functions }, \ + { PROV_NAMES_HKDF_SHA512, FIPS_DEFAULT_PROPERTIES, ossl_kdf_hkdf_sha512_functions }, \ + { PROV_NAMES_TLS1_3_KDF, FIPS_DEFAULT_PROPERTIES, \ + ossl_kdf_tls1_3_kdf_functions }, \ + { PROV_NAMES_SSKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_sskdf_functions }, \ + { PROV_NAMES_PBKDF2, FIPS_DEFAULT_PROPERTIES, ossl_kdf_pbkdf2_functions }, \ + { PROV_NAMES_SNMPKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_snmpkdf_functions }, \ + { PROV_NAMES_SSHKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_sshkdf_functions }, \ + { PROV_NAMES_X963KDF, FIPS_DEFAULT_PROPERTIES, \ + ossl_kdf_x963_kdf_functions }, \ + { PROV_NAMES_X942KDF_ASN1, FIPS_DEFAULT_PROPERTIES, \ + ossl_kdf_x942_kdf_functions }, \ + { PROV_NAMES_TLS1_PRF, FIPS_DEFAULT_PROPERTIES, \ + ossl_kdf_tls1_prf_functions }, \ + { \ + PROV_NAMES_KBKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_kbkdf_functions \ + } -/* - * NOTE: - * Any algorithms added to this table need to be copied to fips_kdfs_internal[]. - */ static const OSSL_ALGORITHM fips_kdfs[] = { FIPS_KDFS_COMMON(), -#ifndef OPENSSL_NO_IKEV2KDF - { PROV_NAMES_IKEV2KDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_ikev2kdf_functions }, -#endif -#ifndef OPENSSL_NO_SSKDF - { PROV_NAMES_SSKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_sskdf_functions }, -#endif -#ifndef OPENSSL_NO_SNMPKDF - { PROV_NAMES_SNMPKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_snmpkdf_functions }, -#endif -#ifndef OPENSSL_NO_SRTPKDF - { PROV_NAMES_SRTPKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_srtpkdf_functions }, -#endif -#ifndef OPENSSL_NO_SSHKDF - { PROV_NAMES_SSHKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_sshkdf_functions }, -#endif -#ifndef OPENSSL_NO_KBKDF - { PROV_NAMES_KBKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_kbkdf_functions }, -#endif -#ifndef OPENSSL_NO_X942KDF - { PROV_NAMES_X942KDF_ASN1, FIPS_DEFAULT_PROPERTIES, - ossl_kdf_x942_kdf_functions }, -#endif -#ifndef OPENSSL_NO_X963KDF - { PROV_NAMES_X963KDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_x963_kdf_functions }, -#endif { NULL, NULL, NULL } }; static const OSSL_ALGORITHM fips_kdfs_internal[] = { FIPS_KDFS_COMMON(), -#ifndef OPENSSL_NO_IKEV2KDF - { PROV_NAMES_IKEV2KDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_ikev2kdf_functions }, -#endif -#ifndef OPENSSL_NO_SSKDF - { PROV_NAMES_SSKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_sskdf_functions }, -#endif -#ifndef OPENSSL_NO_SNMPKDF - { PROV_NAMES_SNMPKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_snmpkdf_functions }, -#endif -#ifndef OPENSSL_NO_SRTPKDF - { PROV_NAMES_SRTPKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_srtpkdf_functions }, -#endif -#ifndef OPENSSL_NO_SSHKDF - { PROV_NAMES_SSHKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_sshkdf_functions }, -#endif -#ifndef OPENSSL_NO_KBKDF - { PROV_NAMES_KBKDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_kbkdf_functions }, -#endif -#ifndef OPENSSL_NO_X942KDF - { PROV_NAMES_X942KDF_ASN1, FIPS_DEFAULT_PROPERTIES, - ossl_kdf_x942_kdf_functions }, -#endif -#ifndef OPENSSL_NO_X963KDF - { PROV_NAMES_X963KDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_x963_kdf_functions }, -#endif - -#ifndef OPENSSL_NO_HMAC_DRBG_KDF /* For deterministic ECDSA */ { PROV_NAMES_HMAC_DRBG_KDF, FIPS_DEFAULT_PROPERTIES, ossl_kdf_hmac_drbg_functions }, -#endif { NULL, NULL, NULL } }; @@ -585,12 +594,12 @@ static const OSSL_ALGORITHM fips_asym_kem[] = { { PROV_NAMES_ML_KEM_768, FIPS_DEFAULT_PROPERTIES, ossl_ml_kem_asym_kem_functions }, { PROV_NAMES_ML_KEM_1024, FIPS_DEFAULT_PROPERTIES, ossl_ml_kem_asym_kem_functions }, #if !defined(OPENSSL_NO_ECX) - { PROV_NAMES_X25519MLKEM768, FIPS_DEFAULT_PROPERTIES, ossl_mlx_kem_asym_kem_functions }, - { PROV_NAMES_X448MLKEM1024, FIPS_UNAPPROVED_PROPERTIES, ossl_mlx_kem_asym_kem_functions }, + { "X25519MLKEM768", FIPS_DEFAULT_PROPERTIES, ossl_mlx_kem_asym_kem_functions }, + { "X448MLKEM1024", FIPS_DEFAULT_PROPERTIES, ossl_mlx_kem_asym_kem_functions }, #endif #if !defined(OPENSSL_NO_EC) - { PROV_NAMES_SecP256r1MLKEM768, FIPS_DEFAULT_PROPERTIES, ossl_mlx_kem_asym_kem_functions }, - { PROV_NAMES_SecP384r1MLKEM1024, FIPS_DEFAULT_PROPERTIES, ossl_mlx_kem_asym_kem_functions }, + { "SecP256r1MLKEM768", FIPS_DEFAULT_PROPERTIES, ossl_mlx_kem_asym_kem_functions }, + { "SecP384r1MLKEM1024", FIPS_DEFAULT_PROPERTIES, ossl_mlx_kem_asym_kem_functions }, #endif #endif { NULL, NULL, NULL } @@ -761,7 +770,6 @@ static const OSSL_ALGORITHM *fips_query_internal(void *provctx, int operation_id static void fips_teardown(void *provctx) { - /* Also free deferred variables when the FIPS Global context is killed */ OSSL_LIB_CTX_free(PROV_LIBCTX_OF(provctx)); ossl_prov_ctx_free(provctx); } @@ -839,6 +847,9 @@ int OSSL_provider_init_int(const OSSL_CORE_HANDLE *handle, case OSSL_FUNC_CORE_GET_LIBCTX: set_func(c_get_libctx, OSSL_FUNC_core_get_libctx(in)); break; + case OSSL_FUNC_CORE_GETTABLE_PARAMS: + set_func(c_gettable_params, OSSL_FUNC_core_gettable_params(in)); + break; case OSSL_FUNC_CORE_GET_PARAMS: set_func(c_get_params, OSSL_FUNC_core_get_params(in)); break; @@ -966,45 +977,45 @@ int OSSL_provider_init_int(const OSSL_CORE_HANDLE *handle, if (!ossl_provider_activate_fallbacks(libctx)) goto err; - /* Retrieve all FIPS parameters from core so they can be used later */ - if (!fips_get_params_from_core(fgbl->handle, &fgbl->fips_params)) { - ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_GET_PARAMETER); - goto err; - } - - /* disable security_checks if needed */ -#ifdef OPENSSL_NO_FIPS_SECURITYCHECKS - fgbl->fips_params.security_checks = 0; -#endif - /* * We did initial set up of selftest_params in a local copy, because we * could not create fgbl until c_CRYPTO_zalloc was defined in the loop * above. */ fgbl->selftest_params = selftest_params; - fgbl->selftest_params.module_filename = fgbl->fips_params.module_filename; - fgbl->selftest_params.module_checksum_data = fgbl->fips_params.module_checksum_data; - fgbl->selftest_params.defer_tests = fgbl->fips_params.defer_tests; + fgbl->selftest_params.libctx = libctx; set_self_test_cb(fgbl); + + if (!fips_get_params_from_core(fgbl)) { + /* Error already raised */ + goto err; + } /* * Disable the conditional error check if it's disabled in the fips config * file. */ - if (fgbl->fips_params.conditional_error_check == 0) + if (fgbl->selftest_params.conditional_error_check != NULL + && strcmp(fgbl->selftest_params.conditional_error_check, "0") == 0) SELF_TEST_disable_conditional_error_state(); + /* Enable or disable FIPS provider options */ +#define OSSL_FIPS_PARAM(structname, paramname, unused) \ + if (fgbl->fips_##structname.option != NULL) { \ + if (strcmp(fgbl->fips_##structname.option, "1") == 0) \ + fgbl->fips_##structname.enabled = 1; \ + else if (strcmp(fgbl->fips_##structname.option, "0") == 0) \ + fgbl->fips_##structname.enabled = 0; \ + else \ + goto err; \ + } +#include "fips_indicator_params.inc" +#undef OSSL_FIPS_PARAM + ossl_prov_cache_exported_algorithms(fips_ciphers, exported_fips_ciphers); - /* initialize deferred self-test infrastructure */ - if ((fgbl->deferred_lock = CRYPTO_THREAD_lock_new()) == NULL) { - ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_CREATE_LOCK); - goto err; - } - - if (!SELF_TEST_post(&fgbl->selftest_params, fgbl, 0)) { + if (!SELF_TEST_post(&fgbl->selftest_params, 0)) { ERR_raise(ERR_LIB_PROV, PROV_R_SELF_TEST_POST_FAILURE); goto err; } @@ -1201,6 +1212,16 @@ int BIO_snprintf(char *buf, size_t n, const char *format, ...) return ret; } +#define OSSL_FIPS_PARAM(structname, paramname, unused) \ + int ossl_fips_config_##structname(OSSL_LIB_CTX *libctx) \ + { \ + FIPS_GLOBAL *fgbl = ossl_lib_ctx_get_data(libctx, OSSL_LIB_CTX_FIPS_PROV_INDEX); \ + \ + return fgbl->fips_##structname.enabled; \ + } +#include "fips_indicator_params.inc" +#undef OSSL_FIPS_PARAM + void OSSL_SELF_TEST_get_callback(OSSL_LIB_CTX *libctx, OSSL_CALLBACK **cb, void **cbarg) { @@ -1231,48 +1252,34 @@ void OSSL_INDICATOR_get_callback(OSSL_LIB_CTX *libctx, } } -/* These functions should only ever be called from SELF_TEST_post() - * otherwise deadlocks may arise */ -int SELF_TEST_lock_deferred(void *fips_global) +/* Deferred test infrastructure */ + +/* Guards access to deferred self-test */ +static CRYPTO_RWLOCK *deferred_lock; + +static CRYPTO_ONCE deferred_once = CRYPTO_ONCE_STATIC_INIT; +static void deferred_init(void) { - FIPS_GLOBAL *fgbl = (FIPS_GLOBAL *)fips_global; - int ret = 0; - - /* First get the lock */ - if (CRYPTO_THREAD_write_lock(fgbl->deferred_lock)) - /* then mark that we are executing tests on this thread */ - if (CRYPTO_THREAD_set_local_ex(CRYPTO_THREAD_LOCAL_FIPS_DEFERRED_KEY, - fgbl->selftest_params.libctx, (void *)0xC001)) - ret = 1; - else - CRYPTO_THREAD_unlock(fgbl->deferred_lock); - else - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_STATE); - - return ret; + if ((deferred_lock = CRYPTO_THREAD_lock_new()) == NULL) + ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_CREATE_LOCK); } - -void SELF_TEST_unlock_deferred(void *fips_global) +static void deferred_deinit(void) { - FIPS_GLOBAL *fgbl = (FIPS_GLOBAL *)fips_global; - - /* clear thread local mark before exiting block */ - CRYPTO_THREAD_set_local_ex(CRYPTO_THREAD_LOCAL_FIPS_DEFERRED_KEY, - fgbl->selftest_params.libctx, NULL); - /* release lock before returning */ - CRYPTO_THREAD_unlock(fgbl->deferred_lock); -} - -static int FIPS_kat_deferred(OSSL_LIB_CTX *libctx, self_test_id_t id) -{ - FIPS_GLOBAL *fgbl = ossl_lib_ctx_get_data(libctx, - OSSL_LIB_CTX_FIPS_PROV_INDEX); - int ret = 0; - - if (fgbl == NULL) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_STATE); - return 0; + if (deferred_lock) { + CRYPTO_THREAD_lock_free(deferred_lock); + deferred_lock = NULL; } +} + +static int FIPS_kat_deferred(OSSL_LIB_CTX *libctx, FIPS_DEFERRED_TEST *test) +{ + int ret = FIPS_DEFERRED_TEST_FAILED; + + if (!CRYPTO_THREAD_run_once(&deferred_once, deferred_init)) + return FIPS_DEFERRED_TEST_FAILED; + + if (deferred_lock == NULL) + return FIPS_DEFERRED_TEST_FAILED; /* * before we do anything, make sure a local test is not already in @@ -1280,54 +1287,28 @@ static int FIPS_kat_deferred(OSSL_LIB_CTX *libctx, self_test_id_t id) */ if (CRYPTO_THREAD_get_local_ex(CRYPTO_THREAD_LOCAL_FIPS_DEFERRED_KEY, libctx) - != NULL) { - enum st_test_state state; - /* - * record this test as invoked by the original test, for marking - * it later as also satisfied - */ - if (!ossl_get_self_test_state(id, &state)) - return 0; - if (state == SELF_TEST_STATE_DEFER) - /* ignore errors, worst case we do additional testing */ - ossl_set_self_test_state(id, SELF_TEST_STATE_IMPLICIT); - /* - * A self test is in progress for this thread so we let this - * thread continue and perform the test while all other - * threads wait for it to complete. - */ - return 1; - } + != NULL) + return FIPS_DEFERRED_TEST_IN_PROGRESS; - if (CRYPTO_THREAD_write_lock(fgbl->deferred_lock)) { - OSSL_SELF_TEST *st = NULL; + if (CRYPTO_THREAD_write_lock(deferred_lock)) { + OSSL_SELF_TEST *ev = NULL; bool unset_key = false; OSSL_CALLBACK *cb = NULL; void *cb_arg = NULL; /* * check again as another thread may have just performed this - * test and marked it as passed. - * NOTE: SELF_TEST_STATE_INIT is not a vald state here, - * deferred testing is only valid when SELF_TEST_post - * marks tests with SELF_TEST_STATE_DEFER, under lock. - * - * NOTE: we do not need an atomic read, because writes are - * guaranteed to happen only with the deferred_lock held + * test and marked it as passed */ - switch (st_all_tests[id].state) { - case SELF_TEST_STATE_DEFER: - break; - case SELF_TEST_STATE_PASSED: - ret = 1; - goto done; - default: - /* something is broken */ - ret = 0; + if (test->state == FIPS_DEFERRED_TEST_PASSED) { + ret = FIPS_DEFERRED_TEST_PASSED; goto done; } - /* mark that we are executing a test on the local thread */ + /* + * mark that we are executing a test on the local thread, does not + * matter what value, as long as it is not NULL, Cool? + */ if (!CRYPTO_THREAD_set_local_ex(CRYPTO_THREAD_LOCAL_FIPS_DEFERRED_KEY, libctx, (void *)0xC001)) goto done; @@ -1337,17 +1318,26 @@ static int FIPS_kat_deferred(OSSL_LIB_CTX *libctx, self_test_id_t id) if (c_stcbfn != NULL && c_get_libctx != NULL) c_stcbfn(c_get_libctx(FIPS_get_core_handle(libctx)), &cb, &cb_arg); - if ((st = OSSL_SELF_TEST_new(cb, cb_arg)) == NULL) + if ((ev = OSSL_SELF_TEST_new(cb, cb_arg)) == NULL) goto done; - ret = SELF_TEST_kats_execute(st, libctx, id, 1); + /* Mark test as in progress */ + test->state = FIPS_DEFERRED_TEST_IN_PROGRESS; + + /* execute test */ + if (SELF_TEST_kats_single(ev, libctx, test->category, test->algorithm)) + ret = FIPS_DEFERRED_TEST_PASSED; done: - OSSL_SELF_TEST_free(st); + /* Mark test as pass or fail */ + test->state = ret; + + if (ev) + OSSL_SELF_TEST_free(ev); if (unset_key) CRYPTO_THREAD_set_local_ex(CRYPTO_THREAD_LOCAL_FIPS_DEFERRED_KEY, libctx, NULL); - CRYPTO_THREAD_unlock(fgbl->deferred_lock); + CRYPTO_THREAD_unlock(deferred_lock); } return ret; } @@ -1357,69 +1347,72 @@ static void deferred_test_error(int category) const char *category_name = "Unknown Category Test"; switch (category) { - case SELF_TEST_KAT_CIPHER: + case FIPS_DEFERRED_KAT_CIPHER: category_name = OSSL_SELF_TEST_TYPE_KAT_CIPHER; break; - case SELF_TEST_KAT_ASYM_CIPHER: + case FIPS_DEFERRED_KAT_ASYM_CIPHER: category_name = OSSL_SELF_TEST_TYPE_KAT_ASYM_CIPHER; break; - case SELF_TEST_KAT_ASYM_KEYGEN: + case FIPS_DEFERRED_KAT_ASYM_KEYGEN: category_name = OSSL_SELF_TEST_TYPE_KAT_ASYM_KEYGEN; break; - case SELF_TEST_KAT_KEM: + case FIPS_DEFERRED_KAT_KEM: category_name = OSSL_SELF_TEST_TYPE_KAT_KEM; break; - case SELF_TEST_KAT_DIGEST: + case FIPS_DEFERRED_KAT_DIGEST: category_name = OSSL_SELF_TEST_TYPE_KAT_DIGEST; break; - case SELF_TEST_KAT_SIGNATURE: + case FIPS_DEFERRED_KAT_SIGNATURE: category_name = OSSL_SELF_TEST_TYPE_KAT_SIGNATURE; break; - case SELF_TEST_KAT_KDF: + case FIPS_DEFERRED_KAT_KDF: category_name = OSSL_SELF_TEST_TYPE_KAT_KDF; break; - case SELF_TEST_KAT_KAS: + case FIPS_DEFERRED_KAT_KA: category_name = OSSL_SELF_TEST_TYPE_KAT_KA; break; - case SELF_TEST_DRBG: + case FIPS_DEFERRED_DRBG: category_name = OSSL_SELF_TEST_TYPE_DRBG; break; } ossl_set_error_state(category_name); } -int ossl_deferred_self_test(OSSL_LIB_CTX *libctx, self_test_id_t id) +int FIPS_deferred_self_tests(OSSL_LIB_CTX *libctx, FIPS_DEFERRED_TEST tests[]) { - enum st_test_state state; - int ret; - - if (id >= ST_ID_MAX) { - ossl_set_error_state(NULL); - return 0; - } + int i; /* - * Return immediately if the test is marked as passed. - * - * NOTE: This would normally call for an atomic read, however we want - * to avoid contention in the general case where the test is always in - * PASSED state. This is true 100% of the time when tests are not deferred, - * and true 99% of the time when tests are deferred. For the remaining 1% of - * the time, if we race and do not read a PASSED value, the worst case is - * that this function continues until it obtains a lock in FIPS_deferred() - * and then it will recheck this value and immediately exit. + * NOTE: that the order in which we check the 'state' here is not important, + * if multiple threads are racing to check it the worst case scenario is + * that they will all try to run the tests. Proper locking for preventing + * concurrent tests runs and saving state from multiple threads is handled + * in FIPS_kat_deferred() so this race is of no real consequence. */ + for (i = 0; tests[i].algorithm != NULL; i++) { + if (tests[i].state != FIPS_DEFERRED_TEST_PASSED) { + int state; - TSAN_BENIGN(&st_all_tests[id].state, "Fails safe, avoids contention") - if (st_all_tests[id].state == SELF_TEST_STATE_PASSED) - return 1; - - ret = FIPS_kat_deferred(libctx, id); - if (!ossl_get_self_test_state(id, &state)) { - ossl_set_error_state(NULL); - return 0; + /* any other threads that request a self test will lock and wait */ + state = FIPS_kat_deferred(libctx, &tests[i]); + switch (state) { + case FIPS_DEFERRED_TEST_IN_PROGRESS: + /* + * A self test is in progress for this thread so we let this + * thread continue and perform the test while all other + * threads wait for it to complete. + */ + return 1; + case FIPS_DEFERRED_TEST_PASSED: + /* success, move on to the next */ + break; + default: + deferred_test_error(tests[i].category); + return 0; + } + } } - if (!ret || state == SELF_TEST_STATE_FAILED) - deferred_test_error(st_all_tests[id].category); - return ret; + + /* all tests passed */ + return 1; } diff --git a/providers/fips/include/fips/fipsindicator.h b/providers/fips/include/fips/fipsindicator.h index 1c1846b1a7..d32e7a1542 100644 --- a/providers/fips/include/fips/fipsindicator.h +++ b/providers/fips/include/fips/fipsindicator.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_FIPS_INCLUDE_FIPS_FIPSINDICATOR_H) -#define OSSL_PROVIDERS_FIPS_INCLUDE_FIPS_FIPSINDICATOR_H - #ifdef FIPS_MODULE #include /* OSSL_CALLBACK, OSSL_LIB_CTX */ @@ -70,7 +67,8 @@ void ossl_FIPS_IND_set_approved(OSSL_FIPS_IND *ind); void ossl_FIPS_IND_set_settable(OSSL_FIPS_IND *ind, int id, int enable); int ossl_FIPS_IND_get_settable(const OSSL_FIPS_IND *ind, int id); int ossl_FIPS_IND_on_unapproved(OSSL_FIPS_IND *ind, int id, OSSL_LIB_CTX *libctx, - const char *algname, const char *opname, enum fips_config_id config_id); + const char *algname, const char *opname, + OSSL_FIPS_IND_CHECK_CB *config_check_fn); int ossl_FIPS_IND_set_ctx_param(OSSL_FIPS_IND *ind, int id, const OSSL_PARAM *p); int ossl_FIPS_IND_set_ctx_param_locate(OSSL_FIPS_IND *ind, int id, const OSSL_PARAM params[], @@ -102,8 +100,8 @@ void ossl_FIPS_IND_copy(OSSL_FIPS_IND *dst, const OSSL_FIPS_IND *src); * If there is more than 1 strict check flag per algorithm ctx, the id represents * the index. */ -#define OSSL_FIPS_IND_ON_UNAPPROVED(ctx, id, libctx, algname, opname, config_id) \ - ossl_FIPS_IND_on_unapproved(&ctx->indicator, id, libctx, algname, opname, config_id) +#define OSSL_FIPS_IND_ON_UNAPPROVED(ctx, id, libctx, algname, opname, config_check_fn) \ + ossl_FIPS_IND_on_unapproved(&ctx->indicator, id, libctx, algname, opname, config_check_fn) #define OSSL_FIPS_IND_SETTABLE_CTX_PARAM(name) \ OSSL_PARAM_int(name, NULL), @@ -148,7 +146,7 @@ int ossl_fips_ind_digest_sign_check(OSSL_FIPS_IND *ind, int id, int nid, int sha1_allowed, int sha512_trunc_allowed, const char *desc, - enum fips_config_id config_id); + OSSL_FIPS_IND_CHECK_CB *config_check_f); #else #define OSSL_FIPS_IND_DECLARE @@ -164,5 +162,3 @@ int ossl_fips_ind_digest_sign_check(OSSL_FIPS_IND *ind, int id, #define OSSL_FIPS_IND_COPY(dst, src) #endif - -#endif /* !defined(OSSL_PROVIDERS_FIPS_INCLUDE_FIPS_FIPSINDICATOR_H) */ diff --git a/providers/fips/include/fips_indicator_params.inc b/providers/fips/include/fips_indicator_params.inc new file mode 100644 index 0000000000..78f9fc0655 --- /dev/null +++ b/providers/fips/include/fips_indicator_params.inc @@ -0,0 +1,28 @@ +OSSL_FIPS_PARAM(security_checks, SECURITY_CHECKS, 1) +OSSL_FIPS_PARAM(tls1_prf_ems_check, TLS1_PRF_EMS_CHECK, 0) +OSSL_FIPS_PARAM(no_short_mac, NO_SHORT_MAC, 1) +OSSL_FIPS_PARAM(hmac_key_check, HMAC_KEY_CHECK, 0) +OSSL_FIPS_PARAM(kmac_key_check, KMAC_KEY_CHECK, 0) +OSSL_FIPS_PARAM(restricted_drbg_digests, DRBG_TRUNC_DIGEST, 0) +OSSL_FIPS_PARAM(signature_digest_check, SIGNATURE_DIGEST_CHECK, 0) +OSSL_FIPS_PARAM(hkdf_digest_check, HKDF_DIGEST_CHECK, 0) +OSSL_FIPS_PARAM(tls13_kdf_digest_check, TLS13_KDF_DIGEST_CHECK, 0) +OSSL_FIPS_PARAM(tls1_prf_digest_check, TLS1_PRF_DIGEST_CHECK, 0) +OSSL_FIPS_PARAM(sshkdf_digest_check, SSHKDF_DIGEST_CHECK, 0) +OSSL_FIPS_PARAM(sskdf_digest_check, SSKDF_DIGEST_CHECK, 0) +OSSL_FIPS_PARAM(x963kdf_digest_check, X963KDF_DIGEST_CHECK, 0) +OSSL_FIPS_PARAM(dsa_sign_disallowed, DSA_SIGN_DISABLED, 0) +OSSL_FIPS_PARAM(tdes_encrypt_disallowed, TDES_ENCRYPT_DISABLED, 0) +OSSL_FIPS_PARAM(rsa_pkcs15_padding_disabled, RSA_PKCS15_PAD_DISABLED, 0) +OSSL_FIPS_PARAM(rsa_pss_saltlen_check, RSA_PSS_SALTLEN_CHECK, 0) +OSSL_FIPS_PARAM(rsa_sign_x931_disallowed, RSA_SIGN_X931_PAD_DISABLED, 0) +OSSL_FIPS_PARAM(hkdf_key_check, HKDF_KEY_CHECK, 0) +OSSL_FIPS_PARAM(kbkdf_key_check, KBKDF_KEY_CHECK, 0) +OSSL_FIPS_PARAM(tls13_kdf_key_check, TLS13_KDF_KEY_CHECK, 0) +OSSL_FIPS_PARAM(tls1_prf_key_check, TLS1_PRF_KEY_CHECK, 0) +OSSL_FIPS_PARAM(sshkdf_key_check, SSHKDF_KEY_CHECK, 0) +OSSL_FIPS_PARAM(sskdf_key_check, SSKDF_KEY_CHECK, 0) +OSSL_FIPS_PARAM(x963kdf_key_check, X963KDF_KEY_CHECK, 0) +OSSL_FIPS_PARAM(x942kdf_key_check, X942KDF_KEY_CHECK, 0) +OSSL_FIPS_PARAM(pbkdf2_lower_bound_check, PBKDF2_LOWER_BOUND_CHECK, 1) +OSSL_FIPS_PARAM(ecdh_cofactor_check, ECDH_COFACTOR_CHECK, 0) diff --git a/providers/fips/include/fips_selftest_params.inc b/providers/fips/include/fips_selftest_params.inc new file mode 100644 index 0000000000..df942d9cea --- /dev/null +++ b/providers/fips/include/fips_selftest_params.inc @@ -0,0 +1,3 @@ +OSSL_FIPS_PARAM(module_filename, OSSL_PROV_PARAM_CORE_MODULE_FILENAME) +OSSL_FIPS_PARAM(module_checksum_data, OSSL_PROV_FIPS_PARAM_MODULE_MAC) +OSSL_FIPS_PARAM(conditional_error_check, OSSL_PROV_FIPS_PARAM_CONDITIONAL_ERRORS) diff --git a/providers/fips/include/fipscommon.h b/providers/fips/include/fipscommon.h index 61d4adef53..c8df9a8ac4 100644 --- a/providers/fips/include/fipscommon.h +++ b/providers/fips/include/fipscommon.h @@ -7,18 +7,12 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_FIPS_INCLUDE_FIPSCOMMON_H) -#define OSSL_PROVIDERS_FIPS_INCLUDE_FIPSCOMMON_H - #ifdef FIPS_MODULE #include -#define FIPSPARAMS_AS_HEADER -#include "providers/fips/fipsparams.inc" -#undef FIPSPARAMS_AS_HEADER - -int ossl_fips_config(OSSL_LIB_CTX *libctx, enum fips_config_id id); +#define OSSL_FIPS_PARAM(structname, paramname, unused) \ + int ossl_fips_config_##structname(OSSL_LIB_CTX *libctx); +#include "fips_indicator_params.inc" +#undef OSSL_FIPS_PARAM #endif - -#endif /* !defined(OSSL_PROVIDERS_FIPS_INCLUDE_FIPSCOMMON_H) */ diff --git a/providers/fips/self_test.c b/providers/fips/self_test.c index 364fd0ef65..e9f88140a6 100644 --- a/providers/fips/self_test.c +++ b/providers/fips/self_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -69,27 +69,6 @@ DEFINE_RUN_ONCE_STATIC(do_fips_self_test_init) return self_test_lock != NULL; } -static CRYPTO_RWLOCK *self_test_states_lock = NULL; -static CRYPTO_ONCE fips_self_test_states_lock_init = CRYPTO_ONCE_STATIC_INIT; - -DEFINE_RUN_ONCE_STATIC(do_fips_self_test_states_lock_init) -{ - self_test_states_lock = CRYPTO_THREAD_lock_new(); - return self_test_states_lock != NULL; -} - -int ossl_get_self_test_state(self_test_id_t id, enum st_test_state *state) -{ - return CRYPTO_atomic_load_int((int *)&st_all_tests[id].state, (int *)state, - self_test_states_lock); -} - -int ossl_set_self_test_state(self_test_id_t id, enum st_test_state state) -{ - return CRYPTO_atomic_store_int((int *)&st_all_tests[id].state, state, - self_test_states_lock); -} - /* * Declarations for the DEP entry/exit points. * Ones not required or incorrect need to be undefined or redefined respectively. @@ -123,9 +102,7 @@ BOOL WINAPI DllMain(HINSTANCE hinstDLL, DWORD fdwReason, LPVOID lpvReserved) init(); break; case DLL_PROCESS_DETACH: -#ifndef __CYGWIN__ cleanup(); -#endif break; default: break; @@ -204,6 +181,64 @@ DEP_FINI_ATTRIBUTE void cleanup(void) #endif #if !defined(OPENSSL_NO_FIPS_POST) +/* + * We need an explicit HMAC-SHA-256 KAT even though it is also + * checked as part of the KDF KATs. Refer IG 10.3. + */ +static const unsigned char hmac_kat_pt[] = { + 0xdd, 0x0c, 0x30, 0x33, 0x35, 0xf9, 0xe4, 0x2e, + 0xc2, 0xef, 0xcc, 0xbf, 0x07, 0x95, 0xee, 0xa2 +}; +static const unsigned char hmac_kat_key[] = { + 0xf4, 0x55, 0x66, 0x50, 0xac, 0x31, 0xd3, 0x54, + 0x61, 0x61, 0x0b, 0xac, 0x4e, 0xd8, 0x1b, 0x1a, + 0x18, 0x1b, 0x2d, 0x8a, 0x43, 0xea, 0x28, 0x54, + 0xcb, 0xae, 0x22, 0xca, 0x74, 0x56, 0x08, 0x13 +}; +static const unsigned char hmac_kat_digest[] = { + 0xf5, 0xf5, 0xe5, 0xf2, 0x66, 0x49, 0xe2, 0x40, + 0xfc, 0x9e, 0x85, 0x7f, 0x2b, 0x9a, 0xbe, 0x28, + 0x20, 0x12, 0x00, 0x92, 0x82, 0x21, 0x3e, 0x51, + 0x44, 0x5d, 0xe3, 0x31, 0x04, 0x01, 0x72, 0x6b +}; + +static int integrity_self_test(OSSL_SELF_TEST *ev, OSSL_LIB_CTX *libctx) +{ + int ok = 0; + unsigned char out[EVP_MAX_MD_SIZE]; + size_t out_len = 0; + + OSSL_PARAM params[2]; + EVP_MAC *mac = EVP_MAC_fetch(libctx, MAC_NAME, NULL); + EVP_MAC_CTX *ctx = EVP_MAC_CTX_new(mac); + + OSSL_SELF_TEST_onbegin(ev, OSSL_SELF_TEST_TYPE_KAT_INTEGRITY, + OSSL_SELF_TEST_DESC_INTEGRITY_HMAC); + + params[0] = OSSL_PARAM_construct_utf8_string("digest", DIGEST_NAME, 0); + params[1] = OSSL_PARAM_construct_end(); + + if (ctx == NULL + || mac == NULL + || !EVP_MAC_init(ctx, hmac_kat_key, sizeof(hmac_kat_key), params) + || !EVP_MAC_update(ctx, hmac_kat_pt, sizeof(hmac_kat_pt)) + || !EVP_MAC_final(ctx, out, &out_len, MAX_MD_SIZE)) + goto err; + + /* Optional corruption */ + OSSL_SELF_TEST_oncorrupt_byte(ev, out); + + if (out_len != sizeof(hmac_kat_digest) + || memcmp(out, hmac_kat_digest, out_len) != 0) + goto err; + ok = 1; +err: + OSSL_SELF_TEST_onend(ev, ok); + EVP_MAC_free(mac); + EVP_MAC_CTX_free(ctx); + return ok; +} + /* * Calculate the HMAC SHA256 of data read using a BIO and read_cb, and verify * the result matches the expected value. @@ -222,7 +257,7 @@ static int verify_integrity(OSSL_CORE_BIO *bio, OSSL_FUNC_BIO_read_ex_fn read_ex EVP_MAC_CTX *ctx = NULL; OSSL_PARAM params[2], *p = params; - if (!SELF_TEST_kats_execute(ev, libctx, ST_ID_MAC_HMAC, 0)) + if (!integrity_self_test(ev, libctx)) goto err; OSSL_SELF_TEST_onbegin(ev, event_type, OSSL_SELF_TEST_DESC_INTEGRITY_HMAC); @@ -278,8 +313,7 @@ int ossl_fips_self_testing(void) } /* This API is triggered either on loading of the FIPS module or on demand */ -int SELF_TEST_post(SELF_TEST_POST_PARAMS *st, void *fips_global, - int on_demand_test) +int SELF_TEST_post(SELF_TEST_POST_PARAMS *st, int on_demand_test) { int loclstate; #if !defined(OPENSSL_NO_FIPS_POST) @@ -295,9 +329,6 @@ int SELF_TEST_post(SELF_TEST_POST_PARAMS *st, void *fips_global, if (!RUN_ONCE(&fips_self_test_init, do_fips_self_test_init)) return 0; - if (!RUN_ONCE(&fips_self_test_states_lock_init, do_fips_self_test_states_lock_init)) - return 0; - loclstate = tsan_load(&FIPS_state); if (loclstate == FIPS_STATE_RUNNING) { @@ -343,56 +374,17 @@ int SELF_TEST_post(SELF_TEST_POST_PARAMS *st, void *fips_global, } bio_module = (*st->bio_new_file_cb)(st->module_filename, "rb"); - /* This section can be called on demand and that could race with deferred - * tests being executed in another thread, so we use helpers to get - * proper locking around this critical section */ + /* Always check the integrity of the fips module */ + if (bio_module == NULL + || !verify_integrity(bio_module, st->bio_read_ex_cb, + module_checksum, checksum_len, st->libctx, + ev, OSSL_SELF_TEST_TYPE_MODULE_INTEGRITY)) { + ERR_raise(ERR_LIB_PROV, PROV_R_MODULE_INTEGRITY_FAILURE); + goto end; + } - if (SELF_TEST_lock_deferred(fips_global)) { - int errored = 0; - - /* Always check the integrity of the fips module */ - if (bio_module == NULL - || !verify_integrity(bio_module, st->bio_read_ex_cb, - module_checksum, checksum_len, st->libctx, - ev, OSSL_SELF_TEST_TYPE_MODULE_INTEGRITY)) { - ERR_raise(ERR_LIB_PROV, PROV_R_MODULE_INTEGRITY_FAILURE); - errored = 1; - goto locked_end; - } - - if (st->defer_tests == 1) { - /* Mark all non executed tests as deferred */ - for (int i = 0; i < ST_ID_MAX; i++) { - if (st_all_tests[i].state == SELF_TEST_STATE_INIT) { - if (!ossl_set_self_test_state(i, SELF_TEST_STATE_DEFER)) { - errored = 1; - goto locked_end; - } - } - } - } - - if (on_demand_test) { - /* ensure all states are cleared so all tests are forcibly - * repeated */ - for (int i = 0; i < ST_ID_MAX; i++) { - if (!ossl_set_self_test_state(i, SELF_TEST_STATE_INIT)) { - errored = 1; - goto locked_end; - } - } - } - - if (!SELF_TEST_kats(ev, st->libctx)) { - ERR_raise(ERR_LIB_PROV, PROV_R_SELF_TEST_KAT_FAILURE); - errored = 1; - } - - locked_end: - SELF_TEST_unlock_deferred(fips_global); - if (errored) - goto end; - } else { + if (!SELF_TEST_kats(ev, st->libctx, on_demand_test)) { + ERR_raise(ERR_LIB_PROV, PROV_R_SELF_TEST_KAT_FAILURE); goto end; } diff --git a/providers/fips/self_test.h b/providers/fips/self_test.h index 05c5285e54..92ef767b86 100644 --- a/providers/fips/self_test.h +++ b/providers/fips/self_test.h @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -7,21 +7,17 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_FIPS_SELF_TEST_H) -#define OSSL_PROVIDERS_FIPS_SELF_TEST_H - #include #include #include -#include "internal/fips.h" typedef struct self_test_post_params_st { /* FIPS module integrity check parameters */ const char *module_filename; /* Module file to perform MAC on */ const char *module_checksum_data; /* Expected module MAC integrity */ - /* Used to decide whether to defer tests or not */ - unsigned char defer_tests; + /* Used for continuous tests */ + const char *conditional_error_check; /* BIO callbacks supplied to the FIPS provider */ OSSL_FUNC_BIO_new_file_fn *bio_new_file_cb; @@ -34,151 +30,9 @@ typedef struct self_test_post_params_st { } SELF_TEST_POST_PARAMS; -int SELF_TEST_post(SELF_TEST_POST_PARAMS *st, void *fips_global, - int on_demand_test); -int SELF_TEST_kats_execute(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, - self_test_id_t id, int switch_rand); -int SELF_TEST_kats(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx); -int SELF_TEST_lock_deferred(void *fips_global); -void SELF_TEST_unlock_deferred(void *fips_global); +int SELF_TEST_post(SELF_TEST_POST_PARAMS *st, int on_demand_test); +int SELF_TEST_kats(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, int do_deferred); +int SELF_TEST_kats_single(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, + int type, const char *alg_name); void SELF_TEST_disable_conditional_error_state(void); - -/* KAT tests categories */ -enum st_test_category { - SELF_TEST_INTEGRITY = 0, /* currently unused */ - SELF_TEST_KAT_DIGEST, - SELF_TEST_KAT_CIPHER, - SELF_TEST_KAT_SIGNATURE, - SELF_TEST_KAT_KDF, - SELF_TEST_DRBG, - SELF_TEST_KAT_KAS, - SELF_TEST_KAT_ASYM_KEYGEN, - SELF_TEST_KAT_KEM, - SELF_TEST_KAT_ASYM_CIPHER, - SELF_TEST_KAT_MAC, -}; - -enum st_test_state { - SELF_TEST_STATE_INIT = 0, /* Test has not been execute yet */ - SELF_TEST_STATE_IN_PROGRESS, /* Test is currently being executed */ - SELF_TEST_STATE_PASSED, /* Test is marked as passed */ - SELF_TEST_STATE_FAILED, /* Test failed */ - SELF_TEST_STATE_IMPLICIT, /* Marks test as implicitly handled */ - SELF_TEST_STATE_DEFER, /* Like INIT, but mark test as deferred */ -}; - -/* used to store raw parameters for keys and algorithms */ -typedef struct st_kat_param_st { - const char *name; /* an OSSL_PARAM name */ - size_t type; /* the type associated with the data */ - const void *data; /* unsigned char [], or char [] depending on the type */ - size_t data_len; /* the length of the data */ -} ST_KAT_PARAM; - -typedef struct st_const_buffer_st { - const unsigned char *buf; - size_t len; -} ST_BUFFER; - -#define CIPHER_MODE_ENCRYPT 1 -#define CIPHER_MODE_DECRYPT 2 -#define CIPHER_MODE_ALL (CIPHER_MODE_ENCRYPT | CIPHER_MODE_DECRYPT) - -typedef struct st_kat_cipher_st { - int mode; - ST_BUFFER key; - ST_BUFFER iv; - ST_BUFFER aad; - ST_BUFFER tag; -} ST_KAT_CIPHER; - -typedef struct st_kat_asym_cipher_st { - int encrypt; - const ST_KAT_PARAM *key; - const ST_KAT_PARAM *postinit; -} ST_KAT_ASYM_CIPHER; - -typedef struct st_kat_keygen_st { - const ST_KAT_PARAM *keygen_params; - const ST_KAT_PARAM *expected_params; -} ST_KAT_ASYM_KEYGEN; - -typedef struct st_kat_kem_st { - const ST_KAT_PARAM *key; - ST_BUFFER cipher_text; - ST_BUFFER entropy; - ST_BUFFER secret; - ST_BUFFER reject_secret; -} ST_KAT_KEM; - -/* FIPS 140-3 only allows DSA verification for legacy purposes */ -#define SIGNATURE_MODE_VERIFY_ONLY 1 -#define SIGNATURE_MODE_SIGN_ONLY 2 -#define SIGNATURE_MODE_DIGESTED 4 -#define SIGNATURE_MODE_SIG_DIGESTED 8 - -typedef struct st_kat_sign_st { - const char *keytype; - int mode; - const ST_KAT_PARAM *key; - ST_BUFFER entropy; - ST_BUFFER nonce; - ST_BUFFER persstr; - const ST_KAT_PARAM *init; - const ST_KAT_PARAM *verify; -} ST_KAT_SIGN; - -typedef struct st_kat_kdf_st { - const ST_KAT_PARAM *params; -} ST_KAT_KDF; - -typedef struct st_kat_kas_st { - const ST_KAT_PARAM *key_group; - const ST_KAT_PARAM *key_host_data; - const ST_KAT_PARAM *key_peer_data; -} ST_KAT_KAS; - -typedef struct st_kat_drbg_st { - const char *param_name; - const char *param_value; - ST_BUFFER entropyin; - ST_BUFFER nonce; - ST_BUFFER persstr; - ST_BUFFER entropyinpr1; - ST_BUFFER entropyinpr2; - ST_BUFFER entropyaddin1; - ST_BUFFER entropyaddin2; -} ST_KAT_DRBG; - -typedef struct st_kat_mac_st { - const ST_KAT_PARAM *params; -} ST_KAT_MAC; - -typedef struct self_test_st { - self_test_id_t id; - const char *algorithm; - const char *desc; - enum st_test_category category; - enum st_test_state state; - ST_BUFFER pt; - ST_BUFFER expected; /* Set to NULL if this value changes */ - union { - ST_KAT_CIPHER cipher; - ST_KAT_ASYM_CIPHER ac; - ST_KAT_ASYM_KEYGEN akgen; - ST_KAT_KEM kem; - ST_KAT_SIGN sig; - ST_KAT_KDF kdf; - ST_KAT_KAS kas; - ST_KAT_DRBG drbg; - ST_KAT_MAC mac; - } u; - const self_test_id_t *depends_on; -} ST_DEFINITION; - -extern ST_DEFINITION st_all_tests[ST_ID_MAX]; -int ossl_get_self_test_state(self_test_id_t id, enum st_test_state *state); -int ossl_set_self_test_state(self_test_id_t id, enum st_test_state state); - -#endif /* !defined(OSSL_PROVIDERS_FIPS_SELF_TEST_H) */ diff --git a/providers/fips/self_test_data.c b/providers/fips/self_test_data.inc similarity index 70% rename from providers/fips/self_test_data.c rename to providers/fips/self_test_data.inc index dcb7552952..2442038eb1 100644 --- a/providers/fips/self_test_data.c +++ b/providers/fips/self_test_data.inc @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -16,32 +16,166 @@ * they are tested as part of a higher level algorithm (such as HMAC). */ -#include -#include -#include "self_test.h" -#include "crypto/ml_kem.h" -#include "internal/nelem.h" - /* Macros to build Self test data */ -#define ITM(x) ((const void *)&x), sizeof(x) -#define ITM_STR(x) ((const void *)&x), (sizeof(x) - 1) -#define ITM_BUF(x) \ - { ((const unsigned char *)&x), sizeof(x) } -#define ITM_BUF_STR(x) \ - { ((const unsigned char *)&x), (sizeof(x) - 1) } +#define ITM(x) ((void *)&x), sizeof(x) +#define ITM_STR(x) ((void *)&x), (sizeof(x) - 1) #define ST_KAT_PARAM_END() { "", 0, NULL, 0 } -#define ST_KAT_PARAM_BIGNUM(name, data) \ +#define ST_KAT_PARAM_BIGNUM(name, data) \ { name, OSSL_PARAM_UNSIGNED_INTEGER, ITM(data) } -#define ST_KAT_PARAM_OCTET(name, data) \ +#define ST_KAT_PARAM_OCTET(name, data) \ { name, OSSL_PARAM_OCTET_STRING, ITM(data) } -#define ST_KAT_PARAM_UTF8STRING(name, data) \ +#define ST_KAT_PARAM_UTF8STRING(name, data) \ { name, OSSL_PARAM_UTF8_STRING, ITM_STR(data) } -#define ST_KAT_PARAM_UTF8CHAR(name, data) \ +#define ST_KAT_PARAM_UTF8CHAR(name, data) \ { name, OSSL_PARAM_UTF8_STRING, ITM(data) } -#define ST_KAT_PARAM_INT(name, i) \ +#define ST_KAT_PARAM_INT(name, i) \ { name, OSSL_PARAM_INTEGER, ITM(i) } +/* used to store raw parameters for keys and algorithms */ +typedef struct st_kat_param_st { + const char *name; /* an OSSL_PARAM name */ + size_t type; /* the type associated with the data */ + const void *data; /* unsigned char [], or char [] depending on the type */ + size_t data_len; /* the length of the data */ +} ST_KAT_PARAM; + +typedef struct st_kat_st { + const char *desc; + const char *algorithm; + int deferred; + const unsigned char *pt; + size_t pt_len; + const unsigned char *expected; + size_t expected_len; +} ST_KAT; + +#define CIPHER_MODE_ENCRYPT 1 +#define CIPHER_MODE_DECRYPT 2 +#define CIPHER_MODE_ALL (CIPHER_MODE_ENCRYPT | CIPHER_MODE_DECRYPT) + +/* FIPS 140-3 only allows DSA verification for legacy purposes */ +#define SIGNATURE_MODE_VERIFY_ONLY 1 +#define SIGNATURE_MODE_SIGN_ONLY 2 +#define SIGNATURE_MODE_DIGESTED 4 +#define SIGNATURE_MODE_SIG_DIGESTED 8 + +typedef ST_KAT ST_KAT_DIGEST; +typedef struct st_kat_cipher_st { + ST_KAT base; + int mode; + const unsigned char *key; + size_t key_len; + const unsigned char *iv; + size_t iv_len; + const unsigned char *aad; + size_t aad_len; + const unsigned char *tag; + size_t tag_len; +} ST_KAT_CIPHER; + +typedef struct st_kat_kdf_st { + const char *desc; + const char *algorithm; + int deferred; + const ST_KAT_PARAM *params; + const unsigned char *expected; + size_t expected_len; +} ST_KAT_KDF; + +typedef struct st_kat_drbg_st { + const char *desc; + const char *algorithm; + int deferred; + const char *param_name; + char *param_value; + const unsigned char *entropyin; + size_t entropyinlen; + const unsigned char *nonce; + size_t noncelen; + const unsigned char *persstr; + size_t persstrlen; + const unsigned char *entropyinpr1; + size_t entropyinpr1len; + const unsigned char *entropyinpr2; + size_t entropyinpr2len; + const unsigned char *entropyaddin1; + size_t entropyaddin1len; + const unsigned char *entropyaddin2; + size_t entropyaddin2len; + const unsigned char *expected; + size_t expectedlen; +} ST_KAT_DRBG; + +typedef struct st_kat_kas_st { + const char *desc; + const char *algorithm; + int deferred; + + const ST_KAT_PARAM *key_group; + const ST_KAT_PARAM *key_host_data; + const ST_KAT_PARAM *key_peer_data; + + const unsigned char *expected; + size_t expected_len; +} ST_KAT_KAS; + +typedef struct st_kat_sign_st { + const char *desc; + const char *keytype; + const char *sigalgorithm; + int deferred; + int mode; + const ST_KAT_PARAM *key; + const unsigned char *msg; + size_t msg_len; + const unsigned char *entropy; + size_t entropy_len; + const unsigned char *nonce; + size_t nonce_len; + const unsigned char *persstr; + size_t persstr_len; + const unsigned char *sig_expected; /* Set to NULL if this value changes */ + size_t sig_expected_len; + const ST_KAT_PARAM *init; + const ST_KAT_PARAM *verify; +} ST_KAT_SIGN; + +typedef struct st_kat_asym_cipher_st { + const char *desc; + const char *algorithm; + int deferred; + int encrypt; + const ST_KAT_PARAM *key; + const ST_KAT_PARAM *postinit; + const unsigned char *in; + size_t in_len; + const unsigned char *expected; + size_t expected_len; +} ST_KAT_ASYM_CIPHER; + +typedef struct st_kat_keygen_st { + const char *desc; + const char *algorithm; + int deferred; + const ST_KAT_PARAM *keygen_params; + const ST_KAT_PARAM *expected_params; +} ST_KAT_ASYM_KEYGEN; + +typedef struct st_kat_kem_st { + const char *desc; + const char *algorithm; + int deferred; + const ST_KAT_PARAM *key; + const unsigned char *cipher_text; + size_t cipher_text_len; + const unsigned char *entropy; + size_t entropy_len; + const unsigned char *secret; + size_t secret_len; + const unsigned char *reject_secret; +} ST_KAT_KEM; + /*- DIGEST SELF TEST DATA */ static const unsigned char sha1_pt[] = "abc"; static const unsigned char sha1_digest[] = { @@ -49,13 +183,6 @@ static const unsigned char sha1_digest[] = { 0xBA, 0x3E, 0x25, 0x71, 0x78, 0x50, 0xC2, 0x6C, 0x9C, 0xD0, 0xD8, 0x9D }; -static const unsigned char sha256_pt[] = "abc"; -static const unsigned char sha256_digest[] = { - 0xBA, 0x78, 0x16, 0xBF, 0x8F, 0x01, 0xCF, 0xEA, - 0x41, 0x41, 0x40, 0xDE, 0x5D, 0xAE, 0x22, 0x23, - 0xB0, 0x03, 0x61, 0xA3, 0x96, 0x17, 0x7A, 0x9C, - 0xB4, 0x10, 0xFF, 0x61, 0xF2, 0x00, 0x15, 0xAD -}; static const unsigned char sha512_pt[] = "abc"; static const unsigned char sha512_digest[] = { 0xDD, 0xAF, 0x35, 0xA1, 0x93, 0x61, 0x7A, 0xBA, 0xCC, 0x41, 0x73, 0x49, @@ -72,6 +199,36 @@ static const unsigned char sha3_256_digest[] = { 0x89, 0x77, 0x7f, 0x05, 0x1e, 0x40, 0x46, 0xae }; +/* + * Note: + * SHA256 is tested by higher level algorithms so a + * CAST is not needed. + */ +static const ST_KAT_DIGEST st_kat_digest_tests[] = +{ + { + OSSL_SELF_TEST_DESC_MD_SHA1, + "SHA1", + 0, + ITM_STR(sha1_pt), + ITM(sha1_digest), + }, + { + OSSL_SELF_TEST_DESC_MD_SHA2, + "SHA512", + 0, + ITM_STR(sha512_pt), + ITM(sha512_digest), + }, + { + OSSL_SELF_TEST_DESC_MD_SHA3, + "SHA3-256", + 0, + ITM(sha3_256_pt), + ITM(sha3_256_digest), + }, +}; + /*- CIPHER TEST DATA */ /* AES-256 GCM test data */ @@ -116,11 +273,6 @@ static const unsigned char aes_128_ecb_ct[] = { 0x4e, 0xaa, 0x6f, 0xb4, 0xdb, 0xf7, 0x84, 0x65 }; -static const self_test_id_t aes_ecb_depends_on[] = { - ST_ID_CIPHER_AES_256_GCM, - ST_ID_MAX -}; - #ifndef OPENSSL_NO_DES /* * TDES-ECB test data from @@ -140,7 +292,58 @@ static const unsigned char tdes_pt[] = { }; #endif +static const ST_KAT_CIPHER st_kat_cipher_tests[] = { + { + { + OSSL_SELF_TEST_DESC_CIPHER_AES_GCM, + "AES-256-GCM", + 0, + ITM(aes_256_gcm_pt), + ITM(aes_256_gcm_ct) + }, + CIPHER_MODE_ENCRYPT | CIPHER_MODE_DECRYPT, + ITM(aes_256_gcm_key), + ITM(aes_256_gcm_iv), + ITM(aes_256_gcm_aad), + ITM(aes_256_gcm_tag) + }, + { + { + OSSL_SELF_TEST_DESC_CIPHER_AES_ECB, + "AES-128-ECB", + 0, + ITM(aes_128_ecb_pt), + ITM(aes_128_ecb_ct) + }, + CIPHER_MODE_DECRYPT, + ITM(aes_128_ecb_key) + }, +#ifndef OPENSSL_NO_DES + { + { + OSSL_SELF_TEST_DESC_CIPHER_TDES, + "DES-EDE3-ECB", + 0, + ITM(tdes_pt), + ITM(tdes_ct) + }, + CIPHER_MODE_DECRYPT, + ITM(tdes_key) + } +#endif +}; + #ifndef OPENSSL_NO_LMS +typedef struct st_kat_lms_s { + int deferred; + const unsigned char *pub; + size_t publen; + const unsigned char *msg; + size_t msglen; + const unsigned char *sig; + size_t siglen; +} ST_KAT_LMS; + /* * Test vector from * https://datatracker.ietf.org/doc/html/draft-fluhrer-lms-more-parm-sets-15#name-test-cases @@ -266,11 +469,13 @@ static const unsigned char sha256_192_sig[] = { 0xd3, 0x4b, 0x40, 0xb6, 0x9d, 0xd9, 0xf3, 0xc1 }; -static const ST_KAT_PARAM lms_key[] = { - ST_KAT_PARAM_OCTET(OSSL_PKEY_PARAM_PUB_KEY, sha256_192_pub), - ST_KAT_PARAM_END() +static const ST_KAT_LMS st_kat_lms_test = { + 0, + ITM(sha256_192_pub), + ITM(sha256_192_msg), + ITM(sha256_192_sig) }; -#endif /* OPENSSL_NO_LMS */ +#endif /* OPENSSL_NO_LMS */ static const char hkdf_digest[] = "SHA256"; /* @@ -307,238 +512,17 @@ static const ST_KAT_PARAM hkdf_params[] = { ST_KAT_PARAM_END() }; -#ifndef OPENSSL_NO_IKEV2KDF -static const char ikev2kdf_digest[] = "SHA256"; - -static const unsigned char ikev2kdf_ni[] = { - 0x36, 0x51, 0xfe, 0xf5, 0xc9, 0xc3, 0x5e, 0x93 -}; - -static const unsigned char ikev2kdf_nr[] = { - 0xc0, 0x9a, 0x8b, 0x90, 0xa3, 0xf0, 0x4d, 0x59 -}; - -static const unsigned char ikev2kdf_spi_init[] = { - 0x8e, 0x5c, 0x3a, 0xe5, 0x07, 0x22, 0x16, 0x84 -}; - -static const unsigned char ikev2kdf_spi_resp[] = { - 0xb1, 0xf2, 0x01, 0xbb, 0x15, 0x5c, 0x3a, 0xcd -}; - -static const unsigned char ikev2kdf_gir[] = { - 0xd0, 0x84, 0xa3, 0x01, 0x66, 0xa5, 0x0f, 0xb7, 0x32, 0x5c, 0x39, 0x60, - 0x87, 0x4a, 0x83, 0x94, 0x49, 0xef, 0x97, 0x41, 0xc2, 0xf4, 0xf9, 0x47, - 0xd0, 0x20, 0x1d, 0xd8, 0xc1, 0x26, 0x92, 0x73, 0xd7, 0x95, 0x09, 0xf3, - 0x7e, 0x3c, 0xa3, 0xeb, 0x4f, 0xa2, 0xfe, 0x2a, 0x28, 0x25, 0x4e, 0x28, - 0x9c, 0xd3, 0xf3, 0x4d, 0xad, 0x4e, 0xb4, 0xdf, 0x1a, 0x07, 0x68, 0x5a, - 0x4b, 0x8a, 0x94, 0xfa, 0x61, 0xe2, 0x49, 0x1f, 0x75, 0x98, 0xb3, 0xce, - 0x65, 0x54, 0x7f, 0xf1, 0x33, 0xb3, 0xf6, 0x3d, 0x1a, 0xc4, 0x17, 0x5e, - 0xaa, 0x69, 0x50, 0x33, 0xf3, 0xce, 0xdb, 0x02, 0x6a, 0x68, 0x73, 0xa3, - 0x64, 0x55, 0x17, 0x2a, 0x85, 0x40, 0xb8, 0xa5, 0xd2, 0x3a, 0x01, 0x43, - 0xbe, 0xd0, 0x39, 0x0e, 0xe4, 0x9b, 0x16, 0x82, 0x69, 0xd7, 0x5f, 0xff, - 0xee, 0x9f, 0xb6, 0x2b, 0xe9, 0x65, 0x99, 0x3c -}; - -static const unsigned char ikev2kdf_new_gir[] = { - 0x52, 0xf0, 0x0a, 0xb1, 0x74, 0xc2, 0x5d, 0x5b, 0x71, 0x39, 0xae, 0x5f, - 0xf4, 0xe8, 0xe9, 0xed, 0xde, 0xe5, 0x99, 0x2d, 0x2e, 0x36, 0xad, 0xf8, - 0xa5, 0x59, 0xff, 0xd9, 0x0d, 0xab, 0x14, 0x42, 0xe4, 0xfb, 0xe4, 0x29, - 0xd3, 0x20, 0xc0, 0xf3, 0x35, 0x52, 0xa1, 0x7d, 0x15, 0x57, 0xfa, 0x41, - 0xea, 0x70, 0xe8, 0xfb, 0x91, 0x6c, 0x4f, 0xa2, 0x7e, 0xd5, 0x2b, 0x5f, - 0x8e, 0xbd, 0x84, 0x61, 0xaf, 0xa7, 0x8f, 0x11, 0x59, 0x15, 0x9a, 0x64, - 0x05, 0x5a, 0xc5, 0xf6, 0x31, 0x9e, 0x29, 0xc2, 0x8e, 0xae, 0x58, 0xcb, - 0xc6, 0x84, 0x77, 0x70, 0xf3, 0x2c, 0x3f, 0xed, 0x1d, 0x04, 0x75, 0x04, - 0x84, 0xf8, 0x54, 0x79, 0x0f, 0x95, 0xe9, 0xec, 0x01, 0xbc, 0x5b, 0xc4, - 0x61, 0xf2, 0x49, 0x66, 0x46, 0x2e, 0x35, 0x95, 0x11, 0x32, 0x93, 0x05, - 0x03, 0x8e, 0x94, 0xde, 0xb6, 0xdd, 0x42, 0xc2 -}; - -static const unsigned char ikev2kdf_expected_seedkey[] = { - 0xEF, 0xAA, 0x7A, 0xB0, 0xEA, 0xA8, 0x5A, 0x3D, - 0x0B, 0xE2, 0x10, 0x0C, 0xD4, 0xB6, 0xFE, 0x00, - 0xFF, 0x50, 0x25, 0xA9, 0xEA, 0xFD, 0xDB, 0x3E, - 0xF5, 0x18, 0xE9, 0xF0, 0xD3, 0xFE, 0x60, 0xE6 -}; - -static const unsigned char ikev2kdf_expected_dkm[] = { - 0x46, 0x2B, 0x9D, 0xD5, 0x25, 0xD4, 0xFD, 0x71, - 0x16, 0x91, 0x74, 0x27, 0x27, 0x79, 0xE7, 0x04, - 0xBA, 0xF6, 0x2C, 0x62, 0x31, 0x77, 0x9A, 0xE9, - 0xEF, 0xE8, 0xC5, 0x8B, 0x21, 0x91, 0x6B, 0x42, - 0x01, 0x01, 0x64, 0xAF, 0x21, 0x11, 0xEB, 0xD7, - 0x62, 0xF6, 0x91, 0x6C, 0xA9, 0xA6, 0xF0, 0xEE, - 0x05, 0xC8, 0xB3, 0x20, 0xE4, 0xEE, 0x27, 0x70, - 0x55, 0x21, 0xDE, 0x25, 0x89, 0xAD, 0xEA, 0x18, - 0x78, 0xF1, 0xA5, 0x51, 0x73, 0x8A, 0xF7, 0xC8, - 0x8D, 0xC4, 0xF0, 0xBB, 0x0C, 0x09, 0x6A, 0x3F, - 0x7D, 0x1F, 0x1A, 0x67, 0x0F, 0xC7, 0x9F, 0x49, - 0xF6, 0x78, 0xD6, 0x0D, 0x66, 0x5B, 0xB3, 0x71, - 0x0C, 0x86, 0x57, 0xF0, 0x3B, 0xA9, 0xF6, 0x2B, - 0x9A, 0x81, 0x8D, 0x7A, 0x22, 0x89, 0x68, 0xC5, - 0x06, 0xE2, 0x37, 0xAE, 0x95, 0x02, 0xAA, 0x6D, - 0xB3, 0x95, 0xC6, 0x1E, 0xA6, 0xA3, 0xE7, 0x95, - 0x04, 0xF8, 0x6B, 0x73, 0x68, 0xBF, 0xB5, 0x42, - 0x3D, 0xF7, 0x9E, 0x48, 0x80, 0x9B, 0xBC, 0xCD, - 0x49, 0xFD, 0x82, 0x6D, 0x02, 0x4F, 0x63, 0xD7, - 0xC2, 0xA5, 0x56, 0x64, 0x00, 0xA1, 0x2E, 0x73, - 0x6A, 0xA0, 0x34, 0x51, 0x04, 0x28, 0xF5, 0xEA, - 0x00, 0x8F, 0xE2, 0xFC, 0x16, 0x88, 0x6F, 0xA3, - 0x88, 0x27, 0x4E, 0xA6, 0xC2, 0xB4, 0xFC, 0xFC, - 0x61, 0x41, 0xBF, 0x04, 0xF8, 0x20, 0x7E, 0xF8, - 0xAF, 0xC2, 0x24, 0xEA, 0x10, 0x59, 0xCB, 0x22, - 0x0D, 0xC0, 0xB2, 0x3A, 0xC0, 0xE4, 0xCC, 0xDA, - 0x49, 0x5A, 0x4E, 0x13, 0x1B, 0x1D, 0x56, 0xE2, - 0x23, 0xAB, 0xA5, 0xA4, 0x8E, 0x8E, 0xD1, 0xF5 -}; - -/* sk_d = the first 32 bytes (SHA256) of ikev2kdf_expected_dkm */ -static const unsigned char ikev2kdf_sk_d[] = { - 0x46, 0x2B, 0x9D, 0xD5, 0x25, 0xD4, 0xFD, 0x71, - 0x16, 0x91, 0x74, 0x27, 0x27, 0x79, 0xE7, 0x04, - 0xBA, 0xF6, 0x2C, 0x62, 0x31, 0x77, 0x9A, 0xE9, - 0xEF, 0xE8, 0xC5, 0x8B, 0x21, 0x91, 0x6B, 0x42 -}; - -static const unsigned char ikev2kdf_expected_dkm_sa[] = { - 0x23, 0x64, 0x76, 0x77, 0xE7, 0xD4, 0x03, 0xFA, - 0x1E, 0x30, 0x06, 0xF1, 0x98, 0x40, 0xAE, 0xE1, - 0x8A, 0xD9, 0xFE, 0xCC, 0x42, 0x15, 0x81, 0x4C, - 0x41, 0x31, 0xBD, 0xEB, 0xA9, 0x84, 0x33, 0xD8, - 0xB0, 0xE3, 0x1B, 0xFB, 0xBD, 0xDF, 0x82, 0x2A, - 0xBC, 0xCE, 0x5E, 0x06, 0x48, 0x6A, 0xA3, 0x88, - 0x02, 0x2B, 0x75, 0xE2, 0x7E, 0x1E, 0x68, 0xAA, - 0x59, 0x83, 0x02, 0x8B, 0x65, 0x28, 0x2C, 0x73, - 0x0C, 0x5D, 0x49, 0xEF, 0x76, 0x06, 0x77, 0x03, - 0x76, 0xCF, 0xDE, 0xC4, 0x1F, 0x7C, 0xC4, 0x35, - 0xD8, 0x16, 0x02, 0x99, 0x89, 0xBC, 0x35, 0x3D, - 0x3B, 0x67, 0xB9, 0xFD, 0x11, 0x68, 0xDD, 0xCB, - 0x89, 0x78, 0x85, 0x0D, 0xA9, 0xB7, 0x52, 0xAE, - 0xE6, 0xA3, 0x0D, 0x00, 0x86, 0xD2, 0xC4, 0xD7, - 0x4E, 0xC0, 0xE0, 0x36, 0x48, 0xA0, 0xDA, 0xD3, - 0x34, 0xFA, 0xF5, 0xFE, 0x88, 0x08, 0x4E, 0x67, - 0xB0, 0xF3, 0xE8, 0xFE, 0xE8, 0xB5, 0xE1, 0xBD, - 0x38, 0x50, 0xDB, 0x54, 0x0F, 0x1F, 0xB8, 0xCF, - 0xFE, 0x23, 0xC9, 0xE9, 0x2C, 0xDA, 0x20, 0x93, - 0x73, 0xF3, 0x54, 0x88, 0x0C, 0x24, 0x6C, 0x75, - 0x3E, 0x2A, 0x0E, 0xCA, 0x9C, 0xB7, 0x3B, 0x99, - 0x10, 0xA8, 0x53, 0x1C, 0x40, 0x10, 0xE6, 0x76, - 0x8F, 0xA2, 0x9F, 0x90, 0x9E, 0x60, 0xAF, 0x77, - 0x7F, 0xED, 0x6E, 0x73, 0x9C, 0x3C, 0xFD, 0xA0, - 0x34, 0x67, 0xE9, 0x15, 0xD6, 0xF0, 0x3F, 0xCE, - 0x9C, 0x41, 0xF5, 0xF9, 0xD5, 0x78, 0xF8, 0x91, - 0x2D, 0x66, 0xA7, 0x54, 0x57, 0xE7, 0x9E, 0xE1, - 0xD5, 0xBC, 0xC2, 0xBE, 0x5C, 0x2F, 0x9B, 0xAE -}; - -static const unsigned char ikev2kdf_expected_dkm_dh[] = { - 0x6A, 0x91, 0x93, 0x87, 0xA5, 0xFA, 0x28, 0x35, - 0xFE, 0x8A, 0x82, 0x37, 0xE4, 0xA1, 0x48, 0x45, - 0xBD, 0x2B, 0x99, 0x30, 0xDB, 0x87, 0xEF, 0xF7, - 0xAD, 0xF2, 0x68, 0xF6, 0x21, 0x86, 0x00, 0x49, - 0x02, 0xDB, 0xA9, 0xAA, 0x94, 0x2D, 0x02, 0x59, - 0xA0, 0xED, 0xC4, 0x12, 0x0B, 0x93, 0x2A, 0x50, - 0x38, 0x65, 0xB5, 0x7B, 0xA8, 0xFB, 0x88, 0x11, - 0x7E, 0xF5, 0xDF, 0x7B, 0x26, 0x79, 0x9C, 0xD8, - 0xBA, 0x37, 0xAA, 0x54, 0x38, 0x10, 0x8C, 0xB1, - 0xA4, 0xFE, 0x11, 0x79, 0x07, 0xC9, 0xD0, 0x59, - 0x7B, 0x70, 0x8C, 0x3F, 0x11, 0x15, 0x1F, 0xEF, - 0xD6, 0x24, 0xD2, 0x31, 0x72, 0x02, 0xB7, 0xC8, - 0x14, 0x30, 0x60, 0x0E, 0x6F, 0xCB, 0xB6, 0xE1, - 0xA8, 0xDF, 0x2B, 0x48, 0x61, 0xEF, 0x23, 0x63, - 0xD5, 0x3D, 0xE1, 0xBE, 0x69, 0x05, 0x7B, 0x0C, - 0xF6, 0x63, 0x4A, 0x7E, 0x7B, 0xFA, 0x97, 0xB3, - 0xC2, 0x81, 0x06, 0x23, 0xE2, 0xBD, 0x67, 0x57, - 0x73, 0x87, 0x77, 0x17, 0x70, 0x36, 0xE9, 0xC3, - 0xA3, 0x97, 0x94, 0x45, 0x69, 0x54, 0xBD, 0x41, - 0xFC, 0x44, 0x4A, 0x12, 0x50, 0x7A, 0xB9, 0xCA, - 0xC6, 0x9A, 0x05, 0x40, 0xD1, 0x3C, 0x29, 0xDB, - 0x85, 0x10, 0xF5, 0x66, 0xA6, 0x91, 0x69, 0x1B, - 0xAA, 0x2D, 0x95, 0x69, 0xDA, 0xCC, 0x99, 0x0D, - 0x56, 0xA4, 0x54, 0xBB, 0x44, 0x4B, 0xCB, 0xBE, - 0x87, 0x51, 0xB0, 0x55, 0x0A, 0x52, 0x78, 0x81, - 0x2F, 0xC5, 0xAB, 0x4F, 0x28, 0x99, 0x0D, 0xD6, - 0xD6, 0x08, 0x53, 0x8D, 0x7D, 0xDD, 0xE2, 0x4D, - 0xC8, 0x1B, 0xDA, 0xAC, 0xA7, 0x75, 0x1F, 0xDE -}; - -static const unsigned char ikev2kdf_expected_rekey[] = { - 0x90, 0x72, 0x2C, 0x42, 0xBD, 0x84, 0x9E, 0x9B, - 0x72, 0xD2, 0x40, 0xFC, 0x25, 0x41, 0x74, 0x27, - 0x0F, 0xA8, 0x29, 0x5D, 0xE6, 0xF0, 0x33, 0x8D, - 0xAF, 0xC3, 0x03, 0xA9, 0xEC, 0x10, 0x4F, 0x12 -}; - -static const int ikev2kdf_mode_gen = EVP_KDF_IKEV2_MODE_GEN; -static const ST_KAT_PARAM ikev2kdf_gen_params[] = { - ST_KAT_PARAM_UTF8STRING(OSSL_KDF_PARAM_DIGEST, ikev2kdf_digest), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_IKEV2KDF_NI, ikev2kdf_ni), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_IKEV2KDF_NR, ikev2kdf_nr), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_SECRET, ikev2kdf_gir), - ST_KAT_PARAM_INT(OSSL_KDF_PARAM_MODE, ikev2kdf_mode_gen), - ST_KAT_PARAM_END() -}; - -static const int ikev2kdf_mode_dkm = EVP_KDF_IKEV2_MODE_DKM; -static const ST_KAT_PARAM ikev2kdf_dkm_params_dkm[] = { - ST_KAT_PARAM_UTF8STRING(OSSL_KDF_PARAM_DIGEST, ikev2kdf_digest), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_IKEV2KDF_NI, ikev2kdf_ni), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_IKEV2KDF_NR, ikev2kdf_nr), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_IKEV2KDF_SPII, ikev2kdf_spi_init), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_IKEV2KDF_SPIR, ikev2kdf_spi_resp), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_SEED, ikev2kdf_expected_seedkey), - ST_KAT_PARAM_INT(OSSL_KDF_PARAM_MODE, ikev2kdf_mode_dkm), - ST_KAT_PARAM_END() -}; - -static const ST_KAT_PARAM ikev2kdf_dkm_params_sa[] = { - ST_KAT_PARAM_UTF8STRING(OSSL_KDF_PARAM_DIGEST, ikev2kdf_digest), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_IKEV2KDF_NI, ikev2kdf_ni), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_IKEV2KDF_NR, ikev2kdf_nr), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_KEY, ikev2kdf_sk_d), - ST_KAT_PARAM_INT(OSSL_KDF_PARAM_MODE, ikev2kdf_mode_dkm), - ST_KAT_PARAM_END() -}; - -static const ST_KAT_PARAM ikev2kdf_dkm_params_dh[] = { - ST_KAT_PARAM_UTF8STRING(OSSL_KDF_PARAM_DIGEST, ikev2kdf_digest), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_IKEV2KDF_NI, ikev2kdf_ni), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_IKEV2KDF_NR, ikev2kdf_nr), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_KEY, ikev2kdf_sk_d), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_SECRET, ikev2kdf_new_gir), - ST_KAT_PARAM_INT(OSSL_KDF_PARAM_MODE, ikev2kdf_mode_dkm), - ST_KAT_PARAM_END() -}; - -static const int ikev2kdf_mode_rekey = EVP_KDF_IKEV2_MODE_REKEY; - -static const ST_KAT_PARAM ikev2kdf_rekey_params[] = { - ST_KAT_PARAM_UTF8STRING(OSSL_KDF_PARAM_DIGEST, ikev2kdf_digest), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_IKEV2KDF_NI, ikev2kdf_ni), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_IKEV2KDF_NR, ikev2kdf_nr), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_SECRET, ikev2kdf_new_gir), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_KEY, ikev2kdf_sk_d), - ST_KAT_PARAM_INT(OSSL_KDF_PARAM_MODE, ikev2kdf_mode_rekey), - ST_KAT_PARAM_END() -}; -#endif - -#ifndef OPENSSL_NO_SNMPKDF -static const char snmpkdf_digest[] = "SHA256"; +static const char snmpkdf_digest[] = "SHA1"; static const unsigned char snmpkdf_eid[] = { 0x80, 0x00, 0x02, 0xb8, 0x05, 0x12, 0x34, 0x56, 0x78, 0x9a, 0xbc, 0xde, 0xf0, 0x12, 0x34, 0x56, 0x78, 0x9a, 0xbc, 0xde, 0xf0, 0x12, 0x34, 0x56, 0x78, 0x9a, 0xbc, 0xde, 0xf0, 0x12, 0x34, 0x56 }; -static const unsigned char snmpkdf_password[] = { - 0x74, 0x63, 0x6f, 0x54, 0x49, 0x48, 0x6d, 0x77, 0x63, 0x46, 0x6c, 0x50, - 0x52, 0x65, 0x52, 0x4a -}; +static const unsigned char snmpkdf_password[] = { 0x74, 0x63, 0x6f, 0x54, 0x49, 0x48, 0x6d, 0x77, + 0x63, 0x46, 0x6c, 0x50, 0x52, 0x65, 0x52, 0x4a }; static const unsigned char snmpkdf_expected[] = { - 0xE2, 0x3C, 0xCD, 0xA8, 0xCE, 0x93, 0x51, 0x79, - 0xA9, 0xF0, 0x38, 0xAA, 0xEA, 0x08, 0xA0, 0xFA, - 0x03, 0x11, 0x9D, 0x80, 0xA8, 0xCF, 0x2E, 0x98, - 0x9F, 0xAD, 0x33, 0x2C, 0x20, 0x77, 0xE0, 0x52 + 0x3c, 0xd1, 0x21, 0xcb, 0xf3, 0xe8, 0xbf, 0x9e, 0x6d, 0x80, 0xf5, 0xf0, + 0x53, 0x83, 0x5b, 0x3c, 0x24, 0x1c, 0xd2, 0x1e }; static const ST_KAT_PARAM snmpkdf_params[] = { ST_KAT_PARAM_UTF8STRING(OSSL_KDF_PARAM_DIGEST, snmpkdf_digest), @@ -546,47 +530,7 @@ static const ST_KAT_PARAM snmpkdf_params[] = { ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_PASSWORD, snmpkdf_password), ST_KAT_PARAM_END() }; -#endif -#ifndef OPENSSL_NO_SRTPKDF -static const char srtpkdf_cipher[] = "AES-256-CTR"; -static const int srtpkdf_kdr = 0x100; - -static const unsigned char srtpkdf_key[] = { - 0x4b, 0x26, 0xfa, 0xdc, 0x0a, 0x9b, 0xe8, 0x23, - 0xdc, 0xd6, 0xab, 0xc8, 0x2c, 0x04, 0x39, 0x75, - 0xa6, 0x03, 0xf0, 0x05, 0x87, 0xb8, 0x75, 0x34, - 0x60, 0xba, 0xf0, 0x50, 0x2e, 0xee, 0x66, 0xbb -}; - -static const unsigned char srtpkdf_salt[] = { - 0x99, 0x74, 0xa3, 0x00, 0x33, 0x28, 0x84, 0xfb, - 0xfa, 0x03, 0x71, 0x8c, 0xe0, 0xe0 -}; - -static const unsigned char srtpkdf_index[] = { - 0x6e, 0xe6, 0x30, 0x14 -}; - -static const int srtpkdf_label = 5; - -static const unsigned char srtpkdf_expected[] = { - 0x5c, 0x4e, 0x98, 0xd3, 0x29, 0x6e, 0x00, 0x9b, - 0x45, 0x38, 0x09, 0x6d, 0x72, 0xe4 -}; - -static const ST_KAT_PARAM srtpkdf_params[] = { - ST_KAT_PARAM_UTF8STRING(OSSL_KDF_PARAM_CIPHER, srtpkdf_cipher), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_KEY, srtpkdf_key), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_SALT, srtpkdf_salt), - ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_SRTPKDF_INDEX, srtpkdf_index), - ST_KAT_PARAM_INT(OSSL_KDF_PARAM_SRTPKDF_KDR, srtpkdf_kdr), - ST_KAT_PARAM_INT(OSSL_KDF_PARAM_SRTPKDF_LABEL, srtpkdf_label), - ST_KAT_PARAM_END() -}; -#endif - -#ifndef OPENSSL_NO_SSKDF static const char sskdf_digest[] = "SHA256"; static const unsigned char sskdf_secret[] = { 0x6d, 0xbd, 0xc2, 0x3f, 0x04, 0x54, 0x88, 0xe4, @@ -615,9 +559,7 @@ static const ST_KAT_PARAM sskdf_params[] = { ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_INFO, sskdf_otherinfo), ST_KAT_PARAM_END() }; -#endif /* OPENSSL_NO_SSKDF */ -#ifndef OPENSSL_NO_X942KDF static const char x942kdf_digest[] = "SHA256"; static const char x942kdf_cekalg[] = "AES-128-WRAP"; static const unsigned char x942kdf_secret[] = { @@ -635,9 +577,7 @@ static const ST_KAT_PARAM x942kdf_params[] = { ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_KEY, x942kdf_secret), ST_KAT_PARAM_END() }; -#endif /* OPENSSL_NO_X942KDF */ -#ifndef OPENSSL_NO_X963KDF static const char x963kdf_digest[] = "SHA256"; static const unsigned char x963kdf_otherinfo[] = { 0x75, 0xee, 0xf8, 0x1a, 0xa3, 0x04, 0x1e, 0x33, @@ -660,7 +600,6 @@ static const ST_KAT_PARAM x963kdf_params[] = { ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_INFO, x963kdf_otherinfo), ST_KAT_PARAM_END() }; -#endif /* OPENSSL_NO_X963KDF */ static const char pbkdf2_digest[] = "SHA256"; /* @@ -708,7 +647,7 @@ static const unsigned char tls12prf_secret[] = { 0x11, 0x76, 0x45, 0x55, 0x39, 0xe7, 0x05, 0xbe, 0x73, 0x08, 0x90, 0x60, 0x2c, 0x28, 0x9a, 0x50, 0x01, 0xe3, 0x4e, 0xeb, 0x3a, 0x04, 0x3e, 0x5d, - 0x52, 0xa6, 0x5e, 0x66, 0x12, 0x51, 0x88, 0xbf + 0x52, 0xa6, 0x5e, 0x66, 0x12, 0x51, 0x88, 0xbf, }; static const unsigned char tls12prf_seed[] = { 'k', 'e', 'y', ' ', 'e', 'x', 'p', 'a', 'n', 's', 'i', 'o', 'n', @@ -719,8 +658,8 @@ static const unsigned char tls12prf_seed[] = { 0x62, 0xe1, 0xfd, 0x91, 0xf2, 0x3f, 0x55, 0x8a, 0x60, 0x5f, 0x28, 0x47, 0x8c, 0x58, 0xcf, 0x72, 0x63, 0x7b, 0x89, 0x78, 0x4d, 0x95, 0x9d, 0xf7, - 0xe9, 0x46, 0xd3, 0xf0, 0x7b, 0xd1, 0xb6, 0x16 -}; + 0xe9, 0x46, 0xd3, 0xf0, 0x7b, 0xd1, 0xb6, 0x16, + }; static const unsigned char tls12prf_expected[] = { 0xd0, 0x61, 0x39, 0x88, 0x9f, 0xff, 0xac, 0x1e, 0x3a, 0x71, 0x86, 0x5f, 0x50, 0x4a, 0xa5, 0xd0, @@ -737,7 +676,7 @@ static const unsigned char tls12prf_expected[] = { 0x1a, 0xd6, 0xf6, 0x8b, 0x43, 0x49, 0x5b, 0x10, 0xa6, 0x83, 0x75, 0x5e, 0xa2, 0xb8, 0x58, 0xd7, 0x0c, 0xca, 0xc7, 0xec, 0x8b, 0x05, 0x3c, 0x6b, - 0xd4, 0x1c, 0xa2, 0x99, 0xd4, 0xe5, 0x19, 0x28 + 0xd4, 0x1c, 0xa2, 0x99, 0xd4, 0xe5, 0x19, 0x28, }; static const ST_KAT_PARAM tls12prf_params[] = { ST_KAT_PARAM_UTF8STRING(OSSL_KDF_PARAM_DIGEST, tls12prf_digest), @@ -746,20 +685,19 @@ static const ST_KAT_PARAM tls12prf_params[] = { ST_KAT_PARAM_END() }; -#ifndef OPENSSL_NO_KBKDF static const char kbkdf_digest[] = "SHA256"; static const char kbkdf_mac[] = "HMAC"; static const unsigned char kbkdf_salt[] = { 'p', 'r', 'f' }; static const unsigned char kbkdf_prfinput[] = { 't', 'e', 's', 't' }; static unsigned char kbkdf_key[] = { 0x37, 0x05, 0xD9, 0x60, 0x80, 0xC1, 0x77, 0x28, - 0xA0, 0xE8, 0x00, 0xEA, 0xB6, 0xE0, 0xD2, 0x3C + 0xA0, 0xE8, 0x00, 0xEA, 0xB6, 0xE0, 0xD2, 0x3C, }; static unsigned char kbkdf_expected[] = { 0x9D, 0x18, 0x86, 0x16, 0xF6, 0x38, 0x52, 0xFE, 0x86, 0x91, 0x5B, 0xB8, 0x40, 0xB4, 0xA8, 0x86, 0xFF, 0x3E, 0x6B, 0xB0, 0xF8, 0x19, 0xB4, 0x9B, - 0x89, 0x33, 0x93, 0xD3, 0x93, 0x85, 0x42, 0x95 + 0x89, 0x33, 0x93, 0xD3, 0x93, 0x85, 0x42, 0x95, }; static const ST_KAT_PARAM kbkdf_params[] = { ST_KAT_PARAM_UTF8STRING(OSSL_KDF_PARAM_DIGEST, kbkdf_digest), @@ -773,21 +711,21 @@ static const ST_KAT_PARAM kbkdf_params[] = { static const char kbkdf_kmac_mac[] = "KMAC128"; static unsigned char kbkdf_kmac_label[] = { 0xB5, 0xB5, 0xF3, 0x71, 0x9F, 0xBE, 0x5B, 0x3D, - 0x7B, 0x8D, 0x05, 0xA1, 0xD3, 0x25, 0x19, 0x50 + 0x7B, 0x8D, 0x05, 0xA1, 0xD3, 0x25, 0x19, 0x50, }; static unsigned char kbkdf_kmac_context[] = { 0x36, 0x60, 0x0E, 0xF3, 0xC3, 0x70, 0xB5, 0xEF, - 0x58, 0xBE, 0xF1, 0xBA, 0x1C, 0xF2, 0x74, 0xCB + 0x58, 0xBE, 0xF1, 0xBA, 0x1C, 0xF2, 0x74, 0xCB, }; static unsigned char kbkdf_kmac_key[] = { 0xB2, 0x51, 0x4C, 0xC1, 0xD5, 0xCD, 0x7B, 0x6B, - 0xA3, 0x3C, 0x90, 0x05, 0xBD, 0xAC, 0x32, 0x2A + 0xA3, 0x3C, 0x90, 0x05, 0xBD, 0xAC, 0x32, 0x2A, }; static unsigned char kbkdf_kmac_expected[] = { 0xB1, 0x58, 0xEE, 0xB1, 0x34, 0xA4, 0xDD, 0x9D, 0xAC, 0x52, 0xBD, 0x9E, 0x30, 0xE8, 0x0D, 0x76, 0x42, 0x57, 0x01, 0x89, 0x5F, 0x82, 0x74, 0xB9, - 0xEB, 0x3E, 0x84, 0xD8, 0xA5, 0xDE, 0x6E, 0x54 + 0xEB, 0x3E, 0x84, 0xD8, 0xA5, 0xDE, 0x6E, 0x54, }; static const ST_KAT_PARAM kbkdf_kmac_params[] = { ST_KAT_PARAM_UTF8STRING(OSSL_KDF_PARAM_MAC, kbkdf_kmac_mac), @@ -797,22 +735,15 @@ static const ST_KAT_PARAM kbkdf_kmac_params[] = { ST_KAT_PARAM_END() }; -static const self_test_id_t kbkdf_depends_on[] = { - ST_ID_KDF_KBKDF, - ST_ID_KDF_KBKDF_KMAC, - ST_ID_MAX -}; -#endif /* OPENSSL_NO_KBKDF */ - static const char tls13_kdf_digest[] = "SHA256"; static int tls13_kdf_extract_mode = EVP_KDF_HKDF_MODE_EXTRACT_ONLY; static int tls13_kdf_expand_mode = EVP_KDF_HKDF_MODE_EXPAND_ONLY; static const unsigned char tls13_kdf_prefix[] = { - 0x74, 0x6C, 0x73, 0x31, 0x33, 0x20 /* "tls13 " */ + 0x74, 0x6C, 0x73, 0x31, 0x33, 0x20 /* "tls13 " */ }; static const unsigned char tls13_kdf_client_early_secret_label[] = { 0x63, 0x20, 0x65, 0x20, 0x74, 0x72, 0x61, 0x66, - 0x66, 0x69, 0x63 /* "c e traffic"*/ + 0x66, 0x69, 0x63 /* "c e traffic"*/ }; static const unsigned char tls13_kdf_psk[] = { 0xF8, 0xAF, 0x6A, 0xEA, 0x2D, 0x39, 0x7B, 0xAF, @@ -852,29 +783,102 @@ static const ST_KAT_PARAM tls13_kdf_client_early_secret_params[] = { ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_DATA, tls13_kdf_client_hello_hash), ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_PREFIX, tls13_kdf_prefix), ST_KAT_PARAM_OCTET(OSSL_KDF_PARAM_LABEL, - tls13_kdf_client_early_secret_label), + tls13_kdf_client_early_secret_label), ST_KAT_PARAM_END() }; /* - * When calling the HKDF newctx function we do not necessarily know which of - * the variants will be used, so we just test them all at once + * NOTES: + * According to FIPS 140-3 10.3.A Note18: SSH KDF is not required, since it is + * sufficient to self-test the underlying SHA hash functions. */ -static const self_test_id_t hkdf_depends_on[] = { -#ifndef OPENSSL_NO_KBKDF - ST_ID_KDF_KBKDF, -#endif - ST_ID_KDF_TLS13_EXTRACT, - ST_ID_KDF_TLS13_EXPAND, - ST_ID_MAX +static const ST_KAT_KDF st_kat_kdf_tests[] = +{ + { + OSSL_SELF_TEST_DESC_KDF_TLS13_EXTRACT, + OSSL_KDF_NAME_TLS1_3_KDF, + 0, + tls13_kdf_early_secret_params, + ITM(tls13_kdf_early_secret) + }, + { + OSSL_SELF_TEST_DESC_KDF_TLS13_EXPAND, + OSSL_KDF_NAME_TLS1_3_KDF, + 0, + tls13_kdf_client_early_secret_params, + ITM(tls13_kdf_client_early_traffic_secret) + }, + { + OSSL_SELF_TEST_DESC_KDF_TLS12_PRF, + OSSL_KDF_NAME_TLS1_PRF, + 0, + tls12prf_params, + ITM(tls12prf_expected) + }, + { + OSSL_SELF_TEST_DESC_KDF_PBKDF2, + OSSL_KDF_NAME_PBKDF2, + 0, + pbkdf2_params, + ITM(pbkdf2_expected) + }, + { + OSSL_SELF_TEST_DESC_KDF_KBKDF, + OSSL_KDF_NAME_KBKDF, + 0, + kbkdf_params, + ITM(kbkdf_expected) + }, + { + OSSL_SELF_TEST_DESC_KDF_KBKDF_KMAC, + OSSL_KDF_NAME_KBKDF, + 0, + kbkdf_kmac_params, + ITM(kbkdf_kmac_expected) + }, + { + OSSL_SELF_TEST_DESC_KDF_HKDF, + OSSL_KDF_NAME_HKDF, + 0, + hkdf_params, + ITM(hkdf_expected) + }, + { + OSSL_SELF_TEST_DESC_KDF_SNMPKDF, + OSSL_KDF_NAME_SNMPKDF, + 0, + snmpkdf_params, + ITM(snmpkdf_expected) + }, + { + OSSL_SELF_TEST_DESC_KDF_SSKDF, + OSSL_KDF_NAME_SSKDF, + 0, + sskdf_params, + ITM(sskdf_expected) + }, + { + OSSL_SELF_TEST_DESC_KDF_X963KDF, + OSSL_KDF_NAME_X963KDF, + 0, + x963kdf_params, + ITM(x963kdf_expected) + }, + { + OSSL_SELF_TEST_DESC_KDF_X942KDF, + OSSL_KDF_NAME_X942KDF_ASN1, + 0, + x942kdf_params, + ITM(x942kdf_expected) + }, }; /*- - * DRBG test vectors are a small subset of - * https://csrc.nist.rip/groups/STM/cavp/documents/drbg/drbgtestvectors.zip - * Using the folder drbgvectors_pr_true - * Generated for CAVS 14.3. - */ +* DRBG test vectors are a small subset of +* https://csrc.nist.rip/groups/STM/cavp/documents/drbg/drbgtestvectors.zip +* Using the folder drbgvectors_pr_true +* Generated for CAVS 14.3. +*/ /* * Hash_DRBG.rsp @@ -1058,118 +1062,165 @@ static const unsigned char drbg_hmac_sha2_pr_expected[] = { 0x8e, 0x30, 0x05, 0x0e, 0x04, 0x97, 0xfb, 0x0a }; +static const ST_KAT_DRBG st_kat_drbg_tests[] = +{ + { + OSSL_SELF_TEST_DESC_DRBG_HASH, + "HASH-DRBG", + 0, + "digest", "SHA256", + ITM(drbg_hash_sha256_pr_entropyin), + ITM(drbg_hash_sha256_pr_nonce), + ITM(drbg_hash_sha256_pr_persstr), + ITM(drbg_hash_sha256_pr_entropyinpr0), + ITM(drbg_hash_sha256_pr_entropyinpr1), + ITM(drbg_hash_sha256_pr_addin0), + ITM(drbg_hash_sha256_pr_addin1), + ITM(drbg_hash_sha256_pr_expected) + }, + { + OSSL_SELF_TEST_DESC_DRBG_CTR, + "CTR-DRBG", + 0, + "cipher", "AES-128-CTR", + ITM(drbg_ctr_aes128_pr_df_entropyin), + ITM(drbg_ctr_aes128_pr_df_nonce), + ITM(drbg_ctr_aes128_pr_df_persstr), + ITM(drbg_ctr_aes128_pr_df_entropyinpr0), + ITM(drbg_ctr_aes128_pr_df_entropyinpr1), + ITM(drbg_ctr_aes128_pr_df_addin0), + ITM(drbg_ctr_aes128_pr_df_addin1), + ITM(drbg_ctr_aes128_pr_df_expected) + }, + { + OSSL_SELF_TEST_DESC_DRBG_HMAC, + "HMAC-DRBG", + 0, + "digest", "SHA256", + ITM(drbg_hmac_sha2_pr_entropyin), + ITM(drbg_hmac_sha2_pr_nonce), + ITM(drbg_hmac_sha2_pr_persstr), + ITM(drbg_hmac_sha2_pr_entropyinpr0), + ITM(drbg_hmac_sha2_pr_entropyinpr1), + ITM(drbg_hmac_sha2_pr_addin0), + ITM(drbg_hmac_sha2_pr_addin1), + ITM(drbg_hmac_sha2_pr_expected) + } +}; + /* KEY EXCHANGE TEST DATA */ #ifndef OPENSSL_NO_DH /* DH KAT */ static const unsigned char dh_priv[] = { - 0x01, 0x14, 0xf7, 0x53, 0x7a, 0x2e, 0xc7, 0x08, - 0x2e, 0x36, 0xf7, 0x38, 0x7a, 0xc9, 0xe4, 0x5b, - 0xac, 0x68, 0xc7, 0xf7, 0x20, 0x8d, 0xf0, 0x8a, - 0xee, 0x96, 0x67, 0x92, 0x8a + 0x14, 0x33, 0xe0, 0xb5, 0xa9, 0x17, 0xb6, 0x0a, + 0x30, 0x23, 0xf2, 0xf8, 0xaa, 0x2c, 0x2d, 0x70, + 0xd2, 0x96, 0x8a, 0xba, 0x9a, 0xea, 0xc8, 0x15, + 0x40, 0xb8, 0xfc, 0xe6 }; static const unsigned char dh_pub[] = { - 0x07, 0x21, 0x4b, 0x8d, 0x23, 0x75, 0x50, 0x84, - 0xaa, 0xec, 0x2f, 0xac, 0xae, 0x2a, 0xf4, 0xc1, - 0x25, 0xca, 0x0b, 0xee, 0x20, 0xaf, 0x3a, 0x2f, - 0xda, 0xf9, 0x5f, 0xce, 0x01, 0xb9, 0xd9, 0xc4, - 0x5f, 0x7c, 0xba, 0xd8, 0x46, 0xc6, 0xee, 0x0a, - 0x53, 0x80, 0x9d, 0x5c, 0x22, 0x75, 0xa9, 0xe5, - 0x3d, 0xfe, 0x31, 0x60, 0x4a, 0xe6, 0xd5, 0x18, - 0x02, 0x19, 0x0a, 0x80, 0xcd, 0x38, 0x35, 0x71, - 0x63, 0xe3, 0x1d, 0xe8, 0x96, 0xdb, 0x5e, 0x5b, - 0x23, 0x2f, 0x70, 0x5f, 0x4a, 0xf0, 0xf7, 0xf4, - 0xe8, 0x1f, 0x44, 0x5a, 0x4f, 0x22, 0xc5, 0x8b, - 0xc3, 0xc6, 0x48, 0x93, 0x50, 0xe1, 0x0f, 0x2f, - 0x73, 0xb9, 0xeb, 0xba, 0xe4, 0x8e, 0x35, 0x5c, - 0x67, 0xcf, 0xf8, 0xb0, 0x83, 0x19, 0xf3, 0xdb, - 0xb8, 0x80, 0xbc, 0x65, 0xcb, 0x8f, 0x91, 0x69, - 0x76, 0x06, 0xd9, 0xd7, 0xc1, 0x2b, 0xf9, 0x15, - 0x6b, 0x71, 0x76, 0x1e, 0xc8, 0x29, 0xb2, 0xc2, - 0x02, 0xc7, 0xef, 0x75, 0x74, 0x0f, 0xe6, 0x74, - 0x4a, 0x0b, 0x67, 0xbd, 0xa9, 0x44, 0x27, 0xa9, - 0x67, 0xf9, 0xbf, 0x6c, 0x97, 0xcf, 0xa3, 0x8b, - 0x1b, 0x74, 0x02, 0x45, 0x10, 0xf4, 0x0d, 0x6c, - 0x7b, 0x9d, 0x6c, 0xb9, 0xf9, 0xc9, 0xf5, 0x1a, - 0xb9, 0xe4, 0xc9, 0x44, 0xff, 0xaa, 0x20, 0xf2, - 0x73, 0xd0, 0x2e, 0xc9, 0xeb, 0xba, 0x19, 0x1a, - 0x22, 0xe8, 0x82, 0x3d, 0x15, 0x24, 0xa5, 0x39, - 0x9d, 0x9b, 0x1b, 0xf5, 0xb0, 0x4f, 0x06, 0xc0, - 0x87, 0x90, 0x8d, 0xcf, 0x19, 0xb5, 0xd5, 0xad, - 0xd4, 0x17, 0x9a, 0x94, 0x75, 0x42, 0xa1, 0xf3, - 0x35, 0x99, 0x3a, 0x1f, 0x68, 0x1c, 0x40, 0x52, - 0x7b, 0x5e, 0x39, 0xd5, 0x76, 0xdd, 0x18, 0x49, - 0xfc, 0xf2, 0x3c, 0x9c, 0x0e, 0x44, 0xa5, 0xc1, - 0x5a, 0x06, 0x46, 0x90, 0x13, 0x34, 0x04, 0x4f + 0x00, 0x8f, 0x81, 0x67, 0x68, 0xce, 0x97, 0x99, + 0x7e, 0x11, 0x5c, 0xad, 0x5b, 0xe1, 0x0c, 0xd4, + 0x15, 0x44, 0xdf, 0xc2, 0x47, 0xe7, 0x06, 0x27, + 0x5e, 0xf3, 0x9d, 0x5c, 0x4b, 0x2e, 0x35, 0x05, + 0xfd, 0x3c, 0x8f, 0x35, 0x85, 0x1b, 0x82, 0xdd, + 0x49, 0xc9, 0xa8, 0x7e, 0x3a, 0x5f, 0x33, 0xdc, + 0x8f, 0x5e, 0x32, 0x76, 0xe1, 0x52, 0x1b, 0x88, + 0x85, 0xda, 0xa9, 0x1d, 0x5f, 0x1c, 0x05, 0x3a, + 0xd4, 0x8d, 0xbb, 0xe7, 0x46, 0x46, 0x1e, 0x29, + 0x4b, 0x5a, 0x02, 0x88, 0x46, 0x94, 0xd0, 0x68, + 0x7d, 0xb2, 0x9f, 0x3a, 0x3d, 0x82, 0x05, 0xe5, + 0xa7, 0xbe, 0x6c, 0x7e, 0x24, 0x35, 0x25, 0x14, + 0xf3, 0x45, 0x08, 0x90, 0xfc, 0x55, 0x2e, 0xa8, + 0xb8, 0xb1, 0x89, 0x15, 0x94, 0x51, 0x44, 0xa9, + 0x9f, 0x68, 0xcb, 0x90, 0xbc, 0xd3, 0xae, 0x02, + 0x37, 0x26, 0xe4, 0xe9, 0x1a, 0x90, 0x95, 0x7e, + 0x1d, 0xac, 0x0c, 0x91, 0x97, 0x83, 0x24, 0x83, + 0xb9, 0xa1, 0x40, 0x72, 0xac, 0xf0, 0x55, 0x32, + 0x18, 0xab, 0xb8, 0x90, 0xda, 0x13, 0x4a, 0xc8, + 0x4b, 0x7c, 0x18, 0xbc, 0x33, 0xbf, 0x99, 0x85, + 0x39, 0x3e, 0xc6, 0x95, 0x9b, 0x48, 0x8e, 0xbe, + 0x46, 0x59, 0x48, 0x41, 0x0d, 0x37, 0x25, 0x94, + 0xbe, 0x8d, 0xf5, 0x81, 0x52, 0xf6, 0xdc, 0xeb, + 0x98, 0xd7, 0x3b, 0x44, 0x61, 0x6f, 0xa3, 0xef, + 0x7b, 0xfe, 0xbb, 0xc2, 0x8e, 0x46, 0x63, 0xbc, + 0x52, 0x65, 0xf9, 0xf8, 0x85, 0x41, 0xdf, 0x82, + 0x4a, 0x10, 0x2a, 0xe3, 0x0c, 0xb7, 0xad, 0x84, + 0xa6, 0x6f, 0x4e, 0x8e, 0x96, 0x1e, 0x04, 0xf7, + 0x57, 0x39, 0xca, 0x58, 0xd4, 0xef, 0x5a, 0xf1, + 0xf5, 0x69, 0xc2, 0xb1, 0x5c, 0x0a, 0xce, 0xbe, + 0x38, 0x01, 0xb5, 0x3f, 0x07, 0x8a, 0x72, 0x90, + 0x10, 0xac, 0x51, 0x3a, 0x96, 0x43, 0xdf, 0x6f, + 0xea }; static const unsigned char dh_peer_pub[] = { - 0x82, 0x32, 0x3a, 0x03, 0x60, 0x05, 0x11, 0xce, - 0x4b, 0xb3, 0xb6, 0x69, 0x0a, 0x75, 0x88, 0x73, - 0x42, 0x74, 0x8e, 0x54, 0xc9, 0x7c, 0xcf, 0xe9, - 0xfd, 0x85, 0x42, 0x33, 0xc1, 0x8a, 0x1b, 0x07, - 0x82, 0x26, 0x13, 0x1f, 0xe1, 0x74, 0x8c, 0x10, - 0x45, 0x9e, 0xf2, 0x50, 0xdf, 0x39, 0x55, 0x58, - 0x0b, 0xea, 0xc9, 0x1f, 0xae, 0x3e, 0xfb, 0xec, - 0x52, 0x5c, 0x4e, 0x69, 0x85, 0x83, 0x8d, 0x04, - 0x23, 0xaf, 0x6e, 0x33, 0x73, 0x96, 0x5e, 0xf8, - 0x05, 0xa3, 0x5b, 0xee, 0xe4, 0xf2, 0x8c, 0x03, - 0x59, 0xd2, 0x98, 0x78, 0xb3, 0xe3, 0xf5, 0x44, - 0xb6, 0x3d, 0x2a, 0x51, 0xf0, 0xcb, 0x29, 0x29, - 0x1b, 0x0e, 0xbc, 0xb1, 0xb4, 0x80, 0x8c, 0xbc, - 0xdf, 0x9c, 0x32, 0xcf, 0xbc, 0xe8, 0x18, 0x27, - 0xd7, 0x74, 0x9e, 0xa8, 0xed, 0x87, 0xb9, 0x4d, - 0x0b, 0x06, 0xad, 0x0e, 0x15, 0x83, 0x71, 0xcd, - 0x53, 0xd0, 0x54, 0x86, 0x03, 0xe4, 0x1e, 0x30, - 0x49, 0xaf, 0xec, 0x75, 0xe1, 0x6c, 0xa1, 0xad, - 0xee, 0x78, 0xf1, 0x4b, 0xf7, 0x70, 0x42, 0xbb, - 0x2f, 0xab, 0xc4, 0xa7, 0x31, 0x76, 0x77, 0x07, - 0x69, 0x73, 0xc0, 0xb2, 0xbf, 0x9b, 0x8b, 0xad, - 0xe7, 0x14, 0xe4, 0x28, 0x75, 0xef, 0x8f, 0x71, - 0x09, 0x7d, 0x87, 0xb1, 0x0e, 0x4f, 0xf5, 0xb1, - 0xd9, 0xdd, 0xe3, 0xd0, 0xe3, 0xa7, 0x93, 0x2c, - 0x81, 0x26, 0x9a, 0x71, 0x6d, 0x29, 0x63, 0x5b, - 0x63, 0x5c, 0x36, 0xd9, 0x56, 0x32, 0xfb, 0xaf, - 0x49, 0x97, 0x0c, 0xb8, 0x45, 0xa4, 0x40, 0x7d, - 0x25, 0x89, 0x9b, 0x71, 0xc2, 0x50, 0x8c, 0x35, - 0x63, 0xbc, 0x4f, 0x5c, 0x2f, 0x6d, 0x20, 0x7f, - 0xeb, 0x59, 0xce, 0x06, 0x69, 0xcd, 0x25, 0xe8, - 0x7b, 0x6e, 0x10, 0x88, 0x14, 0x72, 0x6f, 0x19, - 0x11, 0x1e, 0x36, 0xae, 0xaa, 0x54, 0xf9, 0xb4 + 0x1f, 0xc1, 0xda, 0x34, 0x1d, 0x1a, 0x84, 0x6a, + 0x96, 0xb7, 0xbe, 0x24, 0x34, 0x0f, 0x87, 0x7d, + 0xd0, 0x10, 0xaa, 0x03, 0x56, 0xd5, 0xad, 0x58, + 0xaa, 0xe9, 0xc7, 0xb0, 0x8f, 0x74, 0x9a, 0x32, + 0x23, 0x51, 0x10, 0xb5, 0xd8, 0x8e, 0xb5, 0xdb, + 0xfa, 0x97, 0x8d, 0x27, 0xec, 0xc5, 0x30, 0xf0, + 0x2d, 0x31, 0x14, 0x00, 0x5b, 0x64, 0xb1, 0xc0, + 0xe0, 0x24, 0xcb, 0x8a, 0xe2, 0x16, 0x98, 0xbc, + 0xa9, 0xe6, 0x0d, 0x42, 0x80, 0x86, 0x22, 0xf1, + 0x81, 0xc5, 0x6e, 0x1d, 0xe7, 0xa9, 0x6e, 0x6e, + 0xfe, 0xe9, 0xd6, 0x65, 0x67, 0xe9, 0x1b, 0x97, + 0x70, 0x42, 0xc7, 0xe3, 0xd0, 0x44, 0x8f, 0x05, + 0xfb, 0x77, 0xf5, 0x22, 0xb9, 0xbf, 0xc8, 0xd3, + 0x3c, 0xc3, 0xc3, 0x1e, 0xd3, 0xb3, 0x1f, 0x0f, + 0xec, 0xb6, 0xdb, 0x4f, 0x6e, 0xa3, 0x11, 0xe7, + 0x7a, 0xfd, 0xbc, 0xd4, 0x7a, 0xee, 0x1b, 0xb1, + 0x50, 0xf2, 0x16, 0x87, 0x35, 0x78, 0xfb, 0x96, + 0x46, 0x8e, 0x8f, 0x9f, 0x3d, 0xe8, 0xef, 0xbf, + 0xce, 0x75, 0x62, 0x4b, 0x1d, 0xf0, 0x53, 0x22, + 0xa3, 0x4f, 0x14, 0x63, 0xe8, 0x39, 0xe8, 0x98, + 0x4c, 0x4a, 0xd0, 0xa9, 0x6e, 0x1a, 0xc8, 0x42, + 0xe5, 0x31, 0x8c, 0xc2, 0x3c, 0x06, 0x2a, 0x8c, + 0xa1, 0x71, 0xb8, 0xd5, 0x75, 0x98, 0x0d, 0xde, + 0x7f, 0xc5, 0x6f, 0x15, 0x36, 0x52, 0x38, 0x20, + 0xd4, 0x31, 0x92, 0xbf, 0xd5, 0x1e, 0x8e, 0x22, + 0x89, 0x78, 0xac, 0xa5, 0xb9, 0x44, 0x72, 0xf3, + 0x39, 0xca, 0xeb, 0x99, 0x31, 0xb4, 0x2b, 0xe3, + 0x01, 0x26, 0x8b, 0xc9, 0x97, 0x89, 0xc9, 0xb2, + 0x55, 0x71, 0xc3, 0xc0, 0xe4, 0xcb, 0x3f, 0x00, + 0x7f, 0x1a, 0x51, 0x1c, 0xbb, 0x53, 0xc8, 0x51, + 0x9c, 0xdd, 0x13, 0x02, 0xab, 0xca, 0x6c, 0x0f, + 0x34, 0xf9, 0x67, 0x39, 0xf1, 0x7f, 0xf4, 0x8b }; static const unsigned char dh_secret_expected[256] = { - 0x79, 0x29, 0x11, 0x03, 0x5f, 0x31, 0xbb, 0x8d, - 0x6c, 0xeb, 0xc1, 0x46, 0xc7, 0x7d, 0xb9, 0x2b, - 0xf7, 0xde, 0x68, 0xb7, 0xd0, 0x2e, 0x18, 0xb9, - 0x5e, 0xfb, 0x67, 0x0f, 0x4a, 0x71, 0x9c, 0x33, - 0x2b, 0x64, 0xb9, 0x43, 0x1d, 0x5f, 0x9f, 0xb4, - 0xa2, 0xa7, 0x1a, 0xa5, 0x49, 0xf5, 0x53, 0x17, - 0xcd, 0x28, 0x28, 0x55, 0xe7, 0x85, 0xcb, 0xe4, - 0xca, 0x66, 0xe4, 0x8c, 0x55, 0xbc, 0xd7, 0x1c, - 0x15, 0xa0, 0xa5, 0xa4, 0x4c, 0xca, 0x2b, 0x37, - 0x4a, 0x5c, 0xda, 0xab, 0xc4, 0x1d, 0x8a, 0x78, - 0x2f, 0xc5, 0x99, 0xab, 0x13, 0x8a, 0xad, 0xf5, - 0xbb, 0x83, 0x45, 0x6d, 0xb4, 0x40, 0x64, 0x2f, - 0x6a, 0xeb, 0xf3, 0xc7, 0x6a, 0xf7, 0x35, 0xf5, - 0xf7, 0x06, 0xd5, 0x65, 0xf2, 0xe4, 0x93, 0x80, - 0xa1, 0x59, 0x79, 0x1f, 0x05, 0x6b, 0x24, 0xf0, - 0xbd, 0xcf, 0xa5, 0xa5, 0xcf, 0x43, 0x78, 0xbb, - 0x78, 0xb1, 0xed, 0x63, 0x01, 0x85, 0x48, 0x58, - 0xd3, 0x9f, 0xd9, 0xdc, 0xc6, 0x4a, 0x10, 0x19, - 0x78, 0x94, 0x8a, 0x95, 0x9b, 0xeb, 0xc4, 0x39, - 0xa7, 0xe8, 0xbe, 0x21, 0x9e, 0xcc, 0xc6, 0x6e, - 0x11, 0xc8, 0x57, 0x96, 0x47, 0xf7, 0x4f, 0xca, - 0x50, 0xc9, 0xeb, 0x1a, 0x8f, 0xad, 0xd6, 0x89, - 0x3c, 0xf3, 0xc3, 0x16, 0xdd, 0x30, 0x9b, 0xcb, - 0xbb, 0x53, 0x1a, 0xbb, 0x22, 0x6f, 0xf0, 0x57, - 0x3b, 0x2c, 0x04, 0xb1, 0x1d, 0x5d, 0x0e, 0xbc, - 0x2b, 0xec, 0x38, 0xc1, 0x46, 0x89, 0x57, 0x15, - 0xfb, 0x89, 0xe0, 0x09, 0xb0, 0x67, 0x58, 0xab, - 0x1a, 0x9f, 0x0b, 0x0a, 0x51, 0xc9, 0x8b, 0xdf, - 0x42, 0xd5, 0x35, 0xc2, 0x19, 0xc2, 0xb9, 0xcc, - 0x66, 0x2f, 0x61, 0x91, 0xbc, 0x42, 0x2d, 0x95, - 0xb9, 0x64, 0x29, 0x35, 0x8e, 0xcd, 0xda, 0xa3, - 0x8f, 0x85, 0x16, 0x52, 0x78, 0x0f, 0x48, 0xf5 + 0xa0, 0x38, 0x64, 0x37, 0xdf, 0x2d, 0x2c, 0x78, + 0x49, 0xb9, 0xa7, 0x77, 0xfb, 0xc1, 0x69, 0x94, + 0x85, 0xc5, 0x5a, 0xbc, 0x8d, 0x43, 0x32, 0x23, + 0x94, 0xf5, 0xba, 0xb4, 0x5f, 0x22, 0x4b, 0x4e, + 0xc4, 0xfd, 0x89, 0x41, 0x56, 0x41, 0xe8, 0x9f, + 0x2d, 0x0d, 0x26, 0x33, 0x60, 0x13, 0x8a, 0x20, + 0xf1, 0x7e, 0xb3, 0x76, 0x38, 0x03, 0x0e, 0x48, + 0x4f, 0x27, 0x8c, 0x32, 0xdb, 0x66, 0x5c, 0xbf, + 0x7f, 0xc7, 0xeb, 0xc6, 0x2d, 0xfd, 0x00, 0x08, + 0xb0, 0x98, 0x4e, 0xad, 0x68, 0x65, 0xca, 0x9e, + 0x78, 0xe1, 0xaa, 0xb7, 0x8e, 0x08, 0x4d, 0x67, + 0xa6, 0x15, 0x16, 0xbb, 0x41, 0xac, 0x15, 0xb5, + 0x08, 0x92, 0x5d, 0x25, 0x1d, 0x7f, 0xf3, 0x1b, + 0x5c, 0xea, 0x21, 0x6b, 0xe5, 0x00, 0x4d, 0xb6, + 0x8e, 0xae, 0x84, 0xb4, 0xee, 0xf7, 0xcc, 0xdd, + 0x64, 0x19, 0x4e, 0x25, 0xce, 0x37, 0x4f, 0xde, + 0xb6, 0x21, 0xba, 0xd9, 0xc0, 0x7a, 0x87, 0xc7, + 0x90, 0x0a, 0x78, 0x8b, 0xdd, 0xbc, 0x68, 0x77, + 0x2d, 0xa6, 0xdf, 0x4d, 0x2e, 0xca, 0xdc, 0x86, + 0xb6, 0x1e, 0x54, 0x2b, 0x3a, 0xa9, 0x52, 0x67, + 0xf3, 0x1a, 0x35, 0xb7, 0x5a, 0xcd, 0x99, 0x59, + 0xe9, 0x07, 0x6f, 0xd7, 0xd7, 0x96, 0x8a, 0x47, + 0xdf, 0x9f, 0x51, 0x1b, 0x04, 0xa9, 0x45, 0x30, + 0x89, 0x8a, 0x3f, 0x7e, 0xca, 0xfc, 0x05, 0x2d, + 0x18, 0x77, 0x8f, 0x45, 0x25, 0x39, 0xdb, 0xf2, + 0x13, 0x36, 0x31, 0xdb, 0x50, 0x65, 0x63, 0x4a, + 0xae, 0x3e, 0xd1, 0x3e, 0xde, 0xc1, 0x32, 0x4b, + 0x78, 0x19, 0x03, 0x70, 0x0a, 0xc2, 0xa2, 0x6f, + 0x9b, 0xd4, 0xa6, 0x1d, 0x47, 0xf2, 0xa6, 0x91, + 0x61, 0x4a, 0x74, 0xf8, 0x70, 0x39, 0x42, 0x72, + 0xd5, 0x58, 0x7f, 0xcd, 0x16, 0xeb, 0x82, 0x0c, + 0x2c, 0xf4, 0xd0, 0x95, 0x22, 0xf9, 0xbe, 0x99, }; static const char dh_ffdhe2048[] = "ffdhe2048"; @@ -1192,6 +1243,7 @@ static const ST_KAT_PARAM dh_peer_key[] = { }; #endif /* OPENSSL_NO_DH */ + #ifndef OPENSSL_NO_EC static const char ecdh_curve_name[] = "prime256v1"; static const unsigned char ecdh_privd[] = { @@ -1244,6 +1296,34 @@ static const unsigned char ecdh_secret_expected[] = { }; #endif /* OPENSSL_NO_EC */ +#if !defined(OPENSSL_NO_DH) || !defined(OPENSSL_NO_EC) +static const ST_KAT_KAS st_kat_kas_tests[] = +{ +# ifndef OPENSSL_NO_DH + { + OSSL_SELF_TEST_DESC_KA_DH, + "DH", + 0, + dh_group, + dh_host_key, + dh_peer_key, + ITM(dh_secret_expected) + }, +# endif /* OPENSSL_NO_DH */ +# ifndef OPENSSL_NO_EC + { + OSSL_SELF_TEST_DESC_KA_ECDH, + "EC", + 0, + ecdh_group, + ecdh_host_key, + ecdh_peer_key, + ITM(ecdh_secret_expected) + }, +# endif /* OPENSSL_NO_EC */ +}; +#endif /* !defined(OPENSSL_NO_DH) || !defined(OPENSSL_NO_EC) */ + /* RSA key data */ static const unsigned char rsa_n[] = { 0xDB, 0x10, 0x1A, 0xC2, 0xA3, 0xF1, 0xDC, 0xFF, @@ -1480,8 +1560,8 @@ static const unsigned char rsa_expected_sig[256] = { }; static const unsigned char rsa_asym_plaintext_encrypt[256] = { - 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, - 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10 + 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, + 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10, }; static const unsigned char rsa_asym_expected_encrypt[256] = { 0x54, 0xac, 0x23, 0x96, 0x1d, 0x82, 0x5d, 0x8b, @@ -1515,60 +1595,48 @@ static const unsigned char rsa_asym_expected_encrypt[256] = { 0x4f, 0x0f, 0xad, 0xc7, 0xd0, 0xaa, 0x47, 0xd9, 0x9f, 0x85, 0x1b, 0x2e, 0x6c, 0x3c, 0x57, 0x04, 0x29, 0xf4, 0xf5, 0x66, 0x7d, 0x93, 0x4a, 0xaa, - 0x05, 0x52, 0x55, 0xc1, 0xc6, 0x06, 0x90, 0xab -}; - -static const self_test_id_t rsaenc_depends_on[] = { - ST_ID_ASYM_CIPHER_RSA_ENC, - ST_ID_ASYM_CIPHER_RSA_DEC, - ST_ID_ASYM_CIPHER_RSA_DEC_CRT, - ST_ID_MAX + 0x05, 0x52, 0x55, 0xc1, 0xc6, 0x06, 0x90, 0xab, }; #ifndef OPENSSL_NO_EC /* ECDSA key data */ -static const char ecd_prime_curve_name[] = "prime256v1"; +static const char ecd_prime_curve_name[] = "secp224r1"; static const unsigned char ecd_prime_priv[] = { - 0x9a, 0x98, 0xc3, 0x61, 0x56, 0xee, 0xe8, 0x27, - 0xc3, 0x9c, 0x3d, 0xfc, 0x27, 0x05, 0x7a, 0x0d, - 0x5a, 0x99, 0xd8, 0x24, 0xd9, 0xc5, 0x34, 0xff, - 0xe1, 0xc1, 0x5d, 0x40, 0x1c, 0x66, 0x00, 0x17 + 0x98, 0x1f, 0xb5, 0xf1, 0xfc, 0x87, 0x1d, 0x7d, + 0xde, 0x1e, 0x01, 0x64, 0x09, 0x9b, 0xe7, 0x1b, + 0x9f, 0xad, 0x63, 0xdd, 0x33, 0x01, 0xd1, 0x50, + 0x80, 0x93, 0x50, 0x30 }; static const unsigned char ecd_prime_pub[] = { - 0x04, 0x17, 0xcc, 0x94, 0xc3, 0x83, 0x0b, 0xb9, - 0x59, 0xbc, 0xf3, 0x09, 0x20, 0x05, 0xdf, 0x5e, - 0x45, 0x5f, 0x1e, 0x5e, 0x5b, 0x57, 0x19, 0xb3, - 0x47, 0x2e, 0xc7, 0x29, 0x43, 0xef, 0x17, 0xe2, - 0x7c, 0xdc, 0x18, 0xf5, 0xc3, 0xf7, 0x77, 0xb5, - 0x0c, 0xff, 0x44, 0x12, 0x8b, 0x44, 0x33, 0x5f, - 0x87, 0x17, 0xb2, 0x55, 0xd8, 0x9e, 0xb2, 0xb8, - 0x85, 0x19, 0x12, 0x99, 0x5b, 0xcf, 0x73, 0x80, - 0xdf + 0x04, 0x95, 0x47, 0x99, 0x44, 0x29, 0x8f, 0x51, + 0x39, 0xe2, 0x53, 0xec, 0x79, 0xb0, 0x4d, 0xde, + 0x87, 0x1a, 0x76, 0x54, 0xd5, 0x96, 0xb8, 0x7a, + 0x6d, 0xf4, 0x1c, 0x2c, 0x87, 0x91, 0x5f, 0xd5, + 0x31, 0xdd, 0x24, 0xe5, 0x78, 0xd9, 0x08, 0x24, + 0x8a, 0x49, 0x99, 0xec, 0x55, 0xf2, 0x82, 0xb3, + 0xc4, 0xb7, 0x33, 0x68, 0xe4, 0x24, 0xa9, 0x12, + 0x82 }; static const unsigned char ecdsa_prime_expected_sig[] = { - 0x30, 0x46, 0x02, 0x21, 0000, 0xa8, 0x6b, 0xdb, - 0x4e, 0xed, 0x9f, 0xd5, 0x5f, 0x62, 0x34, 0xd3, - 0xd1, 0x4e, 0xed, 0xdf, 0x17, 0xaa, 0x9a, 0xd5, - 0x6c, 0xa1, 0xee, 0x29, 0x39, 0x34, 0x03, 0x82, - 0x83, 0x93, 0x6e, 0x4a, 0xc9, 0x02, 0x21, 0000, - 0xd2, 0xed, 0x1e, 0x76, 0x75, 0x51, 0xa4, 0x38, - 0x78, 0x98, 0xec, 0x9d, 0x03, 0x34, 0xae, 0xe8, - 0x0f, 0x94, 0x8c, 0xc3, 0x68, 0xdb, 0xf1, 0xa8, - 0x40, 0xde, 0x71, 0x07, 0x8b, 0x42, 0x14, 0xd9 + 0x30, 0x3d, 0x02, 0x1c, 0x48, 0x4f, 0x3c, 0x97, + 0x5b, 0xfa, 0x40, 0x6c, 0xdb, 0xd6, 0x70, 0xb5, + 0xbd, 0x2d, 0xd0, 0xc6, 0x22, 0x93, 0x5a, 0x88, + 0x56, 0xd0, 0xaf, 0x0a, 0x94, 0x92, 0x20, 0x01, + 0x02, 0x1d, 0x00, 0xa4, 0x80, 0xe0, 0x47, 0x88, + 0x8a, 0xef, 0x2a, 0x47, 0x9d, 0x81, 0x9a, 0xbf, + 0x45, 0xc3, 0x6f, 0x9e, 0x2e, 0xc1, 0x44, 0x9f, + 0xfd, 0x79, 0xdb, 0x90, 0x3e, 0xb9, 0xb2 }; -#ifndef OPENSSL_NO_HMAC_DRBG_KDF static const unsigned char ecdsa_prime_expected_detsig[] = { - 0x30, 0x44, 0x02, 0x20, 0x7f, 0x21, 0x74, 0x46, - 0x56, 0x3b, 0x20, 0x19, 0xae, 0xd1, 0x0f, 0xa1, - 0xef, 0x01, 0x76, 0xaf, 0x9b, 0x77, 0xe0, 0x7e, - 0xef, 0xbb, 0x5e, 0x22, 0x37, 0xdd, 0x91, 0x27, - 0xfe, 0x96, 0x5a, 0x54, 0x02, 0x20, 0x68, 0x0a, - 0xb2, 0xe3, 0x84, 0xe2, 0x09, 0x08, 0x4b, 0x1a, - 0x81, 0x7d, 0xdc, 0xb6, 0xcd, 0x95, 0x03, 0x9c, - 0xc3, 0x9d, 0xbe, 0x49, 0xc3, 0x97, 0x22, 0xe6, - 0x8e, 0xb4, 0x34, 0xfd, 0x79, 0xa8 + 0x30, 0x3c, 0x02, 0x1c, 0x6a, 0x6d, 0x2c, 0x88, + 0x2b, 0xe5, 0x6b, 0xe6, 0xb1, 0x28, 0xe7, 0xa8, + 0xbd, 0xca, 0x2e, 0xad, 0x22, 0x22, 0x8d, 0xe0, + 0xd6, 0x83, 0x5b, 0xc9, 0x5b, 0x5f, 0x06, 0x2e, + 0x02, 0x1c, 0x71, 0xec, 0x10, 0x8e, 0x31, 0x5d, + 0xfc, 0x16, 0xed, 0x9d, 0x7d, 0x9b, 0x42, 0x5e, + 0xf9, 0x16, 0xe6, 0x06, 0xa5, 0xf0, 0x94, 0x2f, + 0x57, 0xf1, 0x7e, 0xf2, 0x16, 0x76 }; -#endif static const ST_KAT_PARAM ecdsa_prime_key[] = { ST_KAT_PARAM_UTF8STRING(OSSL_PKEY_PARAM_GROUP_NAME, ecd_prime_curve_name), ST_KAT_PARAM_OCTET(OSSL_PKEY_PARAM_PUB_KEY, ecd_prime_pub), @@ -1582,38 +1650,34 @@ static const ST_KAT_PARAM ecdsa_sig_params[] = { ST_KAT_PARAM_END() }; -#ifndef OPENSSL_NO_EC2M -static const char ecd_bin_curve_name[] = "sect283r1"; +# ifndef OPENSSL_NO_EC2M +static const char ecd_bin_curve_name[] = "sect233r1"; static const unsigned char ecd_bin_priv[] = { - 0x03, 0x6f, 0x76, 0x1e, 0x13, 0x62, 0xee, 0x8f, - 0xd0, 0x86, 0x5e, 0x9c, 0xbc, 0x00, 0x19, 0xbd, - 0x11, 0x73, 0xc7, 0xec, 0x46, 0x1f, 0xea, 0x11, - 0x97, 0x24, 0x06, 0xfe, 0x63, 0xf5, 0xd6, 0x2d, - 0xa7, 0x67, 0xc3, 0xec + 0x00, 0x6d, 0xd6, 0x39, 0x9d, 0x2a, 0xa2, 0xc8, + 0x8c, 0xfc, 0x7b, 0x80, 0x66, 0xaa, 0xe1, 0xaa, + 0xba, 0xee, 0xcb, 0xfd, 0xc9, 0xe5, 0x36, 0x38, + 0x2e, 0xf7, 0x37, 0x6d, 0xd3, 0x20 }; static const unsigned char ecd_bin_pub[] = { - 0x04, 0x06, 0x2c, 0xfb, 0xb6, 0xce, 0xcc, 0x78, - 0xc3, 0xb1, 0xb0, 0xbc, 0xe9, 0xf9, 0x3c, 0xbb, - 0xd0, 0x59, 0x75, 0x89, 0x0c, 0x22, 0xa2, 0xa6, - 0xfe, 0x40, 0x09, 0x79, 0x73, 0x61, 0000, 0x93, - 0x49, 0x43, 0x43, 0xb6, 0xe2, 0x07, 0xc7, 0x20, - 0x67, 0x76, 0x2b, 0x9d, 0x1e, 0x92, 0x3c, 0x7d, - 0x95, 0x22, 0x87, 0xa0, 0x90, 0x1a, 0xd3, 0x7c, - 0xd8, 0x37, 0x3e, 0x61, 0x41, 0x3c, 0x8a, 0x7c, - 0x8d, 0x9a, 0x14, 0x71, 0xaa, 0xa0, 0xad, 0x4a, - 0xc7 + 0x04, 0x00, 0x06, 0xe2, 0x56, 0xf7, 0x37, 0xf9, + 0xea, 0xb6, 0xd1, 0x0f, 0x59, 0xfa, 0x23, 0xc3, + 0x93, 0xa8, 0xb2, 0x26, 0xe2, 0x5c, 0x08, 0xbe, + 0x63, 0x49, 0x26, 0xdc, 0xc7, 0x1e, 0x6f, 0x01, + 0x32, 0x3b, 0xe6, 0x54, 0x8d, 0xc1, 0x13, 0x3e, + 0x54, 0xb2, 0x66, 0x89, 0xb2, 0x82, 0x0a, 0x72, + 0x02, 0xa8, 0xe9, 0x6f, 0x54, 0xfd, 0x3a, 0x6b, + 0x99, 0xb6, 0x8f, 0x80, 0x46 }; static const unsigned char ecdsa_bin_expected_sig[] = { - 0x30, 0x4c, 0x02, 0x24, 0x02, 0xc5, 0x63, 0xe8, - 0x01, 0x6d, 0x1d, 0xa6, 0xf3, 0x14, 0x01, 0x54, - 0x50, 0xe0, 0x65, 0x65, 0x55, 0xb6, 0x3c, 0xc1, - 0xf1, 0xfa, 0x27, 0xfd, 0x97, 0xfd, 0x6e, 0x57, - 0xa6, 0x17, 0x6d, 0xf9, 0xf5, 0x1c, 0xdc, 0x49, - 0x02, 0x24, 0x01, 0xa5, 0xfb, 0x75, 0x5e, 0xc4, - 0xd3, 0xeb, 0x1a, 0xad, 0xb7, 0x08, 0xc3, 0x1e, - 0xb8, 0xe3, 0x1c, 0x94, 0x5a, 0xd6, 0x50, 0xb8, - 0x77, 0x0b, 0xd7, 0xad, 0x1d, 0x06, 0x64, 0x15, - 0xca, 0x20, 0xae, 0xf3, 0x4d, 0x54 + 0x30, 0x3f, 0x02, 0x1d, 0x58, 0xe9, 0xd0, 0x84, + 0x5c, 0xad, 0x29, 0x03, 0xf6, 0xa6, 0xbc, 0xe0, + 0x24, 0x6d, 0x9e, 0x79, 0x5d, 0x1e, 0xe8, 0x5a, + 0xc3, 0x31, 0x0a, 0xa9, 0xfb, 0xe3, 0x99, 0x54, + 0x11, 0x02, 0x1e, 0x00, 0xa3, 0x44, 0x28, 0xa3, + 0x70, 0x97, 0x98, 0x17, 0xd7, 0xa6, 0xad, 0x91, + 0xaf, 0x41, 0x69, 0xb6, 0x06, 0x99, 0x39, 0xc7, + 0x63, 0xa4, 0x6a, 0x81, 0xe4, 0x9a, 0x9d, 0x15, + 0x8b }; static const ST_KAT_PARAM ecdsa_bin_key[] = { ST_KAT_PARAM_UTF8STRING(OSSL_PKEY_PARAM_GROUP_NAME, ecd_bin_curve_name), @@ -1621,21 +1685,9 @@ static const ST_KAT_PARAM ecdsa_bin_key[] = { ST_KAT_PARAM_BIGNUM(OSSL_PKEY_PARAM_PRIV_KEY, ecd_bin_priv), ST_KAT_PARAM_END() }; -#endif /* OPENSSL_NO_EC2M */ +# endif /* OPENSSL_NO_EC2M */ -/* - * ECDSA has 3 tests to run, so we use dependencies to cause - * all of them to be run if needed by simply calling one of them - */ -static const self_test_id_t ecdsa_depends_on[] = { - ST_ID_SIG_DET_ECDSA_SHA256, -#ifndef OPENSSL_NO_EC2M - ST_ID_SIG_E2CM_ECDSA_SHA256, -#endif - ST_ID_MAX -}; - -#ifndef OPENSSL_NO_ECX +# ifndef OPENSSL_NO_ECX static const unsigned char ecx_sig_msg[] = { 0x64, 0xa6, 0x5f, 0x3c, 0xde, 0xdc, 0xdd, 0x66, 0x81, 0x1e, 0x29, 0x15 @@ -1679,14 +1731,14 @@ static const unsigned char ed448_pub[] = { 0x80 }; static const unsigned char ed448_priv[] = { - 0x25, 0x8c, 0xdd, 0x4a, 0xda, 0x32, 0xed, 0x9c, - 0x9f, 0xf5, 0x4e, 0x63, 0x75, 0x6a, 0xe5, 0x82, - 0xfb, 0x8f, 0xab, 0x2a, 0xc7, 0x21, 0xf2, 0xc8, - 0xe6, 0x76, 0xa7, 0x27, 0x68, 0x51, 0x3d, 0x93, - 0x9f, 0x63, 0xdd, 0xdb, 0x55, 0x60, 0x91, 0x33, - 0xf2, 0x9a, 0xdf, 0x86, 0xec, 0x99, 0x29, 0xdc, - 0xcb, 0x52, 0xc1, 0xc5, 0xfd, 0x2f, 0xf7, 0xe2, - 0x1b + 0x25, 0x8c, 0xdd, 0x4a, 0xda, 0x32, 0xed, 0x9c, + 0x9f, 0xf5, 0x4e, 0x63, 0x75, 0x6a, 0xe5, 0x82, + 0xfb, 0x8f, 0xab, 0x2a, 0xc7, 0x21, 0xf2, 0xc8, + 0xe6, 0x76, 0xa7, 0x27, 0x68, 0x51, 0x3d, 0x93, + 0x9f, 0x63, 0xdd, 0xdb, 0x55, 0x60, 0x91, 0x33, + 0xf2, 0x9a, 0xdf, 0x86, 0xec, 0x99, 0x29, 0xdc, + 0xcb, 0x52, 0xc1, 0xc5, 0xfd, 0x2f, 0xf7, 0xe2, + 0x1b }; static const ST_KAT_PARAM ed448_key[] = { ST_KAT_PARAM_OCTET(OSSL_PKEY_PARAM_PUB_KEY, ed448_pub), @@ -1694,23 +1746,23 @@ static const ST_KAT_PARAM ed448_key[] = { ST_KAT_PARAM_END() }; static const unsigned char ed448_expected_sig[] = { - 0x7e, 0xee, 0xab, 0x7c, 0x4e, 0x50, 0xfb, 0x79, - 0x9b, 0x41, 0x8e, 0xe5, 0xe3, 0x19, 0x7f, 0xf6, - 0xbf, 0x15, 0xd4, 0x3a, 0x14, 0xc3, 0x43, 0x89, - 0xb5, 0x9d, 0xd1, 0xa7, 0xb1, 0xb8, 0x5b, 0x4a, - 0xe9, 0x04, 0x38, 0xac, 0xa6, 0x34, 0xbe, 0xa4, - 0x5e, 0x3a, 0x26, 0x95, 0xf1, 0x27, 0x0f, 0x07, - 0xfd, 0xcd, 0xf7, 0xc6, 0x2b, 0x8e, 0xfe, 0xaf, - 0x00, 0xb4, 0x5c, 0x2c, 0x96, 0xba, 0x45, 0x7e, - 0xb1, 0xa8, 0xbf, 0x07, 0x5a, 0x3d, 0xb2, 0x8e, - 0x5c, 0x24, 0xf6, 0xb9, 0x23, 0xed, 0x4a, 0xd7, - 0x47, 0xc3, 0xc9, 0xe0, 0x3c, 0x70, 0x79, 0xef, - 0xb8, 0x7c, 0xb1, 0x10, 0xd3, 0xa9, 0x98, 0x61, - 0xe7, 0x20, 0x03, 0xcb, 0xae, 0x6d, 0x6b, 0x8b, - 0x82, 0x7e, 0x4e, 0x6c, 0x14, 0x30, 0x64, 0xff, - 0x3c, 0x00 + 0x7e, 0xee, 0xab, 0x7c, 0x4e, 0x50, 0xfb, 0x79, + 0x9b, 0x41, 0x8e, 0xe5, 0xe3, 0x19, 0x7f, 0xf6, + 0xbf, 0x15, 0xd4, 0x3a, 0x14, 0xc3, 0x43, 0x89, + 0xb5, 0x9d, 0xd1, 0xa7, 0xb1, 0xb8, 0x5b, 0x4a, + 0xe9, 0x04, 0x38, 0xac, 0xa6, 0x34, 0xbe, 0xa4, + 0x5e, 0x3a, 0x26, 0x95, 0xf1, 0x27, 0x0f, 0x07, + 0xfd, 0xcd, 0xf7, 0xc6, 0x2b, 0x8e, 0xfe, 0xaf, + 0x00, 0xb4, 0x5c, 0x2c, 0x96, 0xba, 0x45, 0x7e, + 0xb1, 0xa8, 0xbf, 0x07, 0x5a, 0x3d, 0xb2, 0x8e, + 0x5c, 0x24, 0xf6, 0xb9, 0x23, 0xed, 0x4a, 0xd7, + 0x47, 0xc3, 0xc9, 0xe0, 0x3c, 0x70, 0x79, 0xef, + 0xb8, 0x7c, 0xb1, 0x10, 0xd3, 0xa9, 0x98, 0x61, + 0xe7, 0x20, 0x03, 0xcb, 0xae, 0x6d, 0x6b, 0x8b, + 0x82, 0x7e, 0x4e, 0x6c, 0x14, 0x30, 0x64, 0xff, + 0x3c, 0x00 }; -#endif /* OPENSSL_NO_ECX */ +# endif /* OPENSSL_NO_ECX */ #endif /* OPENSSL_NO_EC */ #ifndef OPENSSL_NO_DSA @@ -1844,255 +1896,252 @@ static const ST_KAT_PARAM dsa_key[] = { #endif /* OPENSSL_NO_DSA */ #ifndef OPENSSL_NO_ML_DSA -/* - * currently unused - * static const unsigned char ml_dsa_65_pub_key[] = { - * 0x3b, 0x5c, 0xb0, 0x79, 0xd2, 0xce, 0x76, 0x2b, - * 0x3b, 0x95, 0x7c, 0x26, 0x69, 0x8f, 0xe7, 0x01, - * 0xb9, 0x6b, 0x50, 0xa3, 0x2c, 0x73, 0x67, 0xcf, - * 0x9e, 0xf4, 0xb8, 0x7d, 0xe3, 0xaf, 0x27, 0x77, - * 0xc6, 0x7c, 0x34, 0xb7, 0x30, 0x4d, 0x01, 0xa4, - * 0xaa, 0xce, 0x16, 0x7c, 0x13, 0x2b, 0x30, 0x6c, - * 0x88, 0x31, 0xe4, 0x90, 0xf5, 0xc2, 0x80, 0xf5, - * 0xe8, 0xb9, 0x2d, 0x7a, 0x83, 0x17, 0xfc, 0xbb, - * 0x13, 0x6f, 0x18, 0x75, 0x5b, 0x40, 0x39, 0x2d, - * 0x47, 0x56, 0x15, 0xc7, 0x1c, 0x6e, 0x9a, 0x95, - * 0x7b, 0x6b, 0x77, 0x9f, 0x86, 0x38, 0x0e, 0xee, - * 0xc0, 0x82, 0x6c, 0x3c, 0xae, 0xc0, 0xcf, 0x5a, - * 0x85, 0x49, 0xb1, 0x0c, 0x2d, 0x0e, 0x51, 0x73, - * 0xf0, 0xe7, 0xad, 0x3b, 0xa7, 0x3f, 0xf5, 0x75, - * 0xb9, 0xb4, 0x63, 0xb9, 0xf0, 0x0a, 0xf4, 0x29, - * 0x90, 0x20, 0x72, 0x46, 0x8c, 0x7a, 0xaa, 0x86, - * 0xb7, 0x4e, 0xa7, 0x65, 0x23, 0xef, 0xec, 0x46, - * 0x67, 0x02, 0xf1, 0xbb, 0x88, 0xc7, 0xa4, 0xfc, - * 0x66, 0x52, 0x07, 0x67, 0x68, 0xa2, 0x72, 0xe8, - * 0x8a, 0x53, 0x97, 0xe6, 0x89, 0x96, 0x95, 0x9e, - * 0x6a, 0xe9, 0xa4, 0x7d, 0x19, 0x19, 0x5f, 0xb4, - * 0x77, 0x52, 0x17, 0xd6, 0xf2, 0xea, 0x7f, 0xfc, - * 0x5c, 0xd5, 0x18, 0x16, 0x8c, 0xc2, 0x2e, 0x31, - * 0xf8, 0x98, 0x4b, 0x72, 0xa1, 0x80, 0xb6, 0x5c, - * 0x32, 0x19, 0x2f, 0xe0, 0xae, 0x74, 0xf4, 0xc4, - * 0x0a, 0xe0, 0x54, 0x52, 0x46, 0x9e, 0xf3, 0xb9, - * 0x6c, 0x56, 0xd1, 0xe8, 0x99, 0x29, 0x39, 0x95, - * 0x30, 0xa2, 0x6a, 0xc6, 0x32, 0x8a, 0xa6, 0x02, - * 0x6a, 0x39, 0x2e, 0x13, 0x20, 0xbc, 0xf8, 0x7a, - * 0x09, 0xb6, 0xa7, 0xd1, 0x39, 0xa5, 0x12, 0x02, - * 0x81, 0x47, 0x8c, 0xc0, 0x1e, 0xfd, 0xf3, 0x28, - * 0xe5, 0x34, 0xec, 0xf0, 0xfc, 0x3f, 0x22, 0x16, - * 0xd2, 0xfe, 0xf0, 0xca, 0xaa, 0x6f, 0x82, 0xdd, - * 0xd6, 0x83, 0xaf, 0xf9, 0xeb, 0x1d, 0xa8, 0x45, - * 0x39, 0x63, 0xa5, 0xde, 0xee, 0x7d, 0x91, 0xe3, - * 0xaa, 0xcc, 0x07, 0x92, 0xce, 0x50, 0xfd, 0xe4, - * 0xa8, 0x50, 0x91, 0xd5, 0xec, 0xc1, 0x1b, 0x57, - * 0x92, 0x37, 0x68, 0xf8, 0xd6, 0x32, 0x55, 0xba, - * 0x65, 0xae, 0xb6, 0xc3, 0x9f, 0x6c, 0x18, 0xc5, - * 0x12, 0x17, 0x9a, 0x04, 0x29, 0xab, 0x14, 0x94, - * 0xbb, 0x13, 0x79, 0x5e, 0xb9, 0xf0, 0x62, 0x03, - * 0xe0, 0xa4, 0x91, 0xba, 0x81, 0x4b, 0xaa, 0xf1, - * 0x82, 0x47, 0x83, 0x43, 0x5f, 0x1e, 0x2d, 0x48, - * 0x40, 0x56, 0xe4, 0x29, 0x79, 0x01, 0xd5, 0x89, - * 0xaf, 0xa4, 0x56, 0x9e, 0x38, 0x62, 0x03, 0xa0, - * 0xe7, 0x9f, 0x08, 0x1f, 0xca, 0xd4, 0x31, 0x48, - * 0xf6, 0x68, 0xe0, 0xcc, 0x28, 0xff, 0x06, 0x97, - * 0x67, 0x4b, 0x70, 0x78, 0xa0, 0x2a, 0xf9, 0x46, - * 0x80, 0x6d, 0x37, 0xfb, 0xb3, 0x17, 0x12, 0xf0, - * 0x95, 0xc7, 0xee, 0x31, 0x54, 0x75, 0xdf, 0x2a, - * 0xa8, 0x7d, 0xff, 0x97, 0xbb, 0x45, 0x49, 0x55, - * 0xd5, 0xac, 0x9c, 0x6f, 0x0e, 0xc3, 0x94, 0x96, - * 0xc4, 0x9e, 0x9c, 0x45, 0x31, 0xcb, 0x23, 0xed, - * 0x21, 0xf1, 0xfe, 0xe9, 0xf9, 0x8c, 0xb6, 0x8e, - * 0x72, 0x6e, 0xdd, 0x37, 0x1c, 0xc7, 0xd6, 0x6b, - * 0x36, 0x35, 0xa0, 0x67, 0x54, 0x00, 0x65, 0x2c, - * 0xc8, 0xa4, 0xa0, 0x9e, 0x72, 0xd7, 0xc9, 0x3c, - * 0x8c, 0x78, 0x1a, 0xf8, 0x80, 0xad, 0xc4, 0x99, - * 0xc7, 0x35, 0x4e, 0x89, 0x3b, 0x4f, 0xa6, 0x9d, - * 0x5d, 0xce, 0x66, 0x4d, 0x82, 0xef, 0x47, 0x73, - * 0xa8, 0xc5, 0x14, 0x20, 0xdd, 0x57, 0x92, 0x10, - * 0x95, 0x8a, 0xe1, 0xac, 0x82, 0xec, 0x39, 0xe7, - * 0x2c, 0xa6, 0xfd, 0x50, 0x68, 0x0c, 0x3e, 0xcf, - * 0xbc, 0xc5, 0x12, 0xfe, 0x30, 0xc8, 0xb7, 0xb4, - * 0x84, 0xd8, 0x1d, 0x67, 0x54, 0x9d, 0x20, 0x49, - * 0xa5, 0xfd, 0xf9, 0x18, 0xef, 0xc2, 0xd2, 0xcd, - * 0xb7, 0x54, 0x2b, 0x31, 0x12, 0xf9, 0xaa, 0x8e, - * 0x0a, 0x29, 0x0c, 0x37, 0xd2, 0x7c, 0xcd, 0xc5, - * 0x0b, 0x98, 0x25, 0x97, 0x0b, 0x5a, 0xf7, 0x07, - * 0x91, 0x98, 0xd1, 0x42, 0xdf, 0xc4, 0xf9, 0x42, - * 0x97, 0xda, 0x20, 0xf4, 0x88, 0xe1, 0x6b, 0xd4, - * 0x85, 0xf5, 0x1d, 0xca, 0x2a, 0xba, 0x30, 0xc5, - * 0xdf, 0x9d, 0x4d, 0xb8, 0xb0, 0x30, 0x54, 0x61, - * 0xcf, 0x91, 0x6f, 0x90, 0xa5, 0x25, 0x05, 0x9b, - * 0x2b, 0x3e, 0x13, 0xcd, 0xcd, 0x40, 0x59, 0x7c, - * 0x92, 0x9b, 0x51, 0x81, 0x0d, 0x58, 0x32, 0x0a, - * 0x43, 0xbd, 0x01, 0xb4, 0xb8, 0x0b, 0xd5, 0xee, - * 0x0d, 0x67, 0x70, 0x59, 0xd7, 0x47, 0x4f, 0xe5, - * 0x84, 0x07, 0x75, 0x3e, 0x54, 0xfb, 0x5d, 0xd1, - * 0x3f, 0x72, 0x6e, 0xae, 0xf9, 0x4b, 0x7b, 0x57, - * 0xe0, 0xde, 0x8b, 0x8b, 0x12, 0x1b, 0x10, 0x3b, - * 0x5e, 0x17, 0xd1, 0x72, 0x18, 0x3d, 0xff, 0xc6, - * 0x83, 0xa5, 0xaf, 0xf9, 0x30, 0xae, 0xb7, 0x47, - * 0x46, 0x5d, 0xac, 0xba, 0x35, 0x04, 0x35, 0x0b, - * 0x42, 0x48, 0x7c, 0xa1, 0x00, 0x1a, 0xea, 0xea, - * 0x5f, 0x93, 0x2b, 0xb7, 0xe5, 0x8f, 0x91, 0x3c, - * 0x00, 0x98, 0x51, 0x40, 0xee, 0x11, 0x50, 0x70, - * 0x40, 0xe4, 0x28, 0xd4, 0x79, 0x2d, 0xcd, 0x82, - * 0xaf, 0x3f, 0xb2, 0xfc, 0x96, 0x8d, 0xbe, 0x79, - * 0xa3, 0xcd, 0xac, 0x35, 0x4b, 0x5e, 0xb4, 0x81, - * 0x0e, 0x6a, 0xde, 0x1f, 0x7e, 0xb0, 0x37, 0x3e, - * 0xdc, 0xe0, 0x21, 0xcc, 0x9f, 0x90, 0x26, 0xb6, - * 0x8a, 0x1d, 0xb3, 0x1e, 0xec, 0x7a, 0x88, 0x28, - * 0x95, 0xe2, 0xc2, 0x1d, 0x07, 0xb1, 0xfa, 0xc6, - * 0x21, 0x1b, 0x5e, 0x54, 0x7b, 0x37, 0x0e, 0x63, - * 0xff, 0xdd, 0x70, 0xf9, 0xea, 0x2f, 0x2d, 0x98, - * 0xe1, 0xbe, 0x37, 0xd0, 0x1f, 0x45, 0x5a, 0x63, - * 0xad, 0x44, 0xbc, 0x5f, 0xc6, 0x23, 0x8a, 0xac, - * 0x12, 0x71, 0xd5, 0xa2, 0x8b, 0xfc, 0x97, 0xbb, - * 0x00, 0x4b, 0xd7, 0x09, 0xa6, 0xaf, 0x40, 0x08, - * 0x6c, 0x8d, 0x10, 0x4a, 0x01, 0x34, 0xc1, 0x2c, - * 0x92, 0x30, 0x0a, 0x85, 0x8f, 0x3f, 0x08, 0xdd, - * 0xff, 0x9c, 0x10, 0xd1, 0x03, 0x03, 0x84, 0x1f, - * 0xf8, 0x4e, 0xf2, 0xe3, 0xd1, 0xd3, 0xb9, 0xdf, - * 0xfc, 0x97, 0x1c, 0xcf, 0x8a, 0x29, 0xe6, 0x59, - * 0x04, 0xe2, 0x87, 0x27, 0xbb, 0xb9, 0x96, 0xd0, - * 0x20, 0x2e, 0x91, 0x48, 0xaa, 0xbf, 0x53, 0x4a, - * 0x34, 0xb5, 0x0e, 0x11, 0xce, 0xf8, 0x65, 0xa6, - * 0x0d, 0x45, 0xda, 0xbf, 0x6a, 0xfb, 0x81, 0xe4, - * 0x7c, 0x8c, 0xa0, 0x4b, 0x00, 0x1b, 0xd7, 0x73, - * 0x61, 0x80, 0xc0, 0x6b, 0x60, 0xde, 0xf3, 0x32, - * 0xae, 0x62, 0x35, 0x66, 0xdd, 0xde, 0x53, 0x61, - * 0x86, 0xe9, 0x44, 0xf3, 0x01, 0x7b, 0xaa, 0xe7, - * 0x31, 0xd4, 0x5b, 0x06, 0x52, 0x0f, 0xf4, 0x90, - * 0x5c, 0x82, 0x3e, 0x12, 0x28, 0x88, 0x7f, 0xfc, - * 0xb8, 0xee, 0x17, 0x34, 0x4e, 0xc3, 0x2a, 0xfb, - * 0x84, 0x1b, 0x0f, 0xba, 0x51, 0x64, 0x96, 0x22, - * 0x0d, 0x88, 0x9b, 0xf2, 0x72, 0x04, 0x55, 0x44, - * 0x6a, 0x14, 0x2b, 0xa0, 0xc2, 0xbe, 0x9e, 0x7b, - * 0x48, 0x32, 0xa7, 0xf6, 0x11, 0xae, 0x60, 0xfb, - * 0xf8, 0x38, 0x67, 0x16, 0xdf, 0xdf, 0x46, 0x96, - * 0xd7, 0x6c, 0x39, 0xa2, 0xad, 0xf7, 0xb7, 0x78, - * 0x32, 0x2c, 0xba, 0xae, 0x33, 0x5a, 0x88, 0x4b, - * 0x40, 0x1f, 0x88, 0xcd, 0xe7, 0x8f, 0x50, 0x5e, - * 0xd8, 0x80, 0x82, 0x7b, 0x46, 0xc7, 0x07, 0x71, - * 0x4f, 0x3b, 0xca, 0x9d, 0x73, 0x7c, 0xdb, 0xeb, - * 0x4c, 0x37, 0xdd, 0xb4, 0xb8, 0x61, 0xf3, 0xdf, - * 0xb2, 0xb5, 0x34, 0x27, 0xec, 0xeb, 0xba, 0xcc, - * 0xdc, 0xe9, 0xde, 0x47, 0x2e, 0xe9, 0x3b, 0xa1, - * 0x36, 0xf1, 0x66, 0xdf, 0xc8, 0x70, 0x7f, 0x39, - * 0x82, 0xb3, 0x8c, 0x47, 0x9a, 0x45, 0x59, 0x2e, - * 0x30, 0x9b, 0xaf, 0x7c, 0xad, 0x43, 0x38, 0x6e, - * 0x05, 0x7d, 0x8b, 0xac, 0x5f, 0x70, 0x63, 0xeb, - * 0x85, 0xee, 0xab, 0xa4, 0x57, 0x1d, 0x63, 0xac, - * 0x48, 0x45, 0x74, 0xca, 0x0c, 0xa8, 0x65, 0x05, - * 0x1a, 0x47, 0xa1, 0x2f, 0x4b, 0x96, 0x26, 0x9e, - * 0xee, 0xec, 0x37, 0x57, 0xbf, 0xa0, 0x2b, 0x75, - * 0xf5, 0x9b, 0xb5, 0x1d, 0x12, 0x8a, 0x61, 0x9c, - * 0x8d, 0x2a, 0x7e, 0xee, 0x05, 0x2b, 0x85, 0x7c, - * 0x6f, 0x34, 0xc4, 0xcd, 0xd5, 0xd0, 0xac, 0xf9, - * 0x79, 0x24, 0xe7, 0x0f, 0x41, 0x95, 0xe2, 0x9a, - * 0x22, 0x32, 0xa5, 0x98, 0x2e, 0x82, 0xc0, 0x07, - * 0xf4, 0x74, 0x68, 0x00, 0xf9, 0x35, 0x5e, 0x12, - * 0xfe, 0xa2, 0x0e, 0x15, 0x96, 0x83, 0x84, 0x31, - * 0xc4, 0x25, 0xda, 0x7a, 0xec, 0x07, 0x15, 0xe4, - * 0x7d, 0xc5, 0xf5, 0xe1, 0xc5, 0xba, 0x9a, 0x59, - * 0x76, 0xae, 0x4e, 0x54, 0x27, 0x5e, 0xa9, 0x0d, - * 0xa0, 0xd3, 0xcd, 0x99, 0x39, 0x76, 0x6d, 0x58, - * 0xdf, 0x8a, 0xa9, 0x9e, 0x21, 0x22, 0x48, 0x7c, - * 0x0c, 0x13, 0xfa, 0x86, 0x63, 0x74, 0x92, 0xf4, - * 0xe5, 0x5d, 0xbf, 0xe4, 0x2d, 0xd7, 0xa1, 0xe3, - * 0x0f, 0xc6, 0x3e, 0x82, 0xa0, 0xcc, 0xfa, 0x38, - * 0x55, 0x36, 0x9b, 0x22, 0xd0, 0xb8, 0x7f, 0x3f, - * 0x0f, 0x35, 0x01, 0xf9, 0x6f, 0xa6, 0x51, 0x77, - * 0x21, 0xb7, 0x7a, 0x81, 0xca, 0x83, 0x6b, 0xec, - * 0xa7, 0x71, 0x12, 0x6d, 0x22, 0x78, 0xb1, 0xc8, - * 0x37, 0xda, 0x1d, 0xd1, 0x9c, 0xa5, 0x6c, 0xfa, - * 0xd3, 0x4b, 0x87, 0x39, 0x6f, 0x59, 0xe1, 0xec, - * 0x4a, 0xe5, 0x0e, 0x72, 0x2b, 0x31, 0x18, 0xd9, - * 0x54, 0x6a, 0x4c, 0xc3, 0xe0, 0x58, 0x3b, 0xd8, - * 0xe8, 0x65, 0xc1, 0x98, 0xed, 0x64, 0x7b, 0xb1, - * 0xee, 0xa9, 0x54, 0x95, 0x37, 0x98, 0x68, 0xca, - * 0x83, 0xef, 0xc5, 0x1b, 0x23, 0x71, 0x5c, 0x1a, - * 0xe6, 0xc0, 0xce, 0x2e, 0x16, 0x59, 0x79, 0xf4, - * 0x94, 0x43, 0xd8, 0xb1, 0x2e, 0xe3, 0xb9, 0xa0, - * 0x95, 0x80, 0x66, 0xdd, 0x1d, 0xdd, 0x0d, 0x78, - * 0x9d, 0xc3, 0x91, 0x60, 0x16, 0x8b, 0xc5, 0x39, - * 0xad, 0xdb, 0xa3, 0xc1, 0xd2, 0x8d, 0xa0, 0x78, - * 0x75, 0x68, 0xa6, 0xb9, 0x15, 0x57, 0x0b, 0x06, - * 0x64, 0x55, 0xd7, 0x07, 0x53, 0xf9, 0x8b, 0xd9, - * 0x97, 0x46, 0xca, 0x04, 0x95, 0xd4, 0x3c, 0xd3, - * 0x8f, 0x0a, 0x53, 0x27, 0xe6, 0xd4, 0xb4, 0x7b, - * 0x70, 0x12, 0x12, 0xc5, 0x14, 0xa0, 0x53, 0xe5, - * 0xd4, 0x30, 0xaa, 0xcc, 0xec, 0x03, 0x0a, 0x36, - * 0x21, 0x9f, 0x81, 0x16, 0x6d, 0x1d, 0x53, 0x6e, - * 0x08, 0xae, 0xf7, 0x05, 0xd9, 0x73, 0x5a, 0x45, - * 0x3a, 0x52, 0x3e, 0xeb, 0x67, 0x49, 0xe1, 0x1a, - * 0x8a, 0x4c, 0xd9, 0x83, 0x64, 0xd8, 0x16, 0x37, - * 0x1c, 0x6b, 0x1c, 0x0d, 0x8f, 0x6a, 0xbf, 0x21, - * 0xf1, 0x4f, 0x4c, 0x55, 0x6f, 0xe0, 0x5c, 0xa7, - * 0xb1, 0x7b, 0x57, 0xa9, 0xa2, 0xb4, 0x9d, 0x53, - * 0x7f, 0x0f, 0xb0, 0x21, 0x95, 0x70, 0x3a, 0x0d, - * 0xa2, 0xc1, 0x52, 0x26, 0xad, 0xa7, 0x48, 0x66, - * 0x2a, 0xfc, 0xaa, 0xaf, 0x25, 0x02, 0x58, 0x80, - * 0xbe, 0xe7, 0xe4, 0x2a, 0x50, 0xe5, 0x46, 0x13, - * 0xaa, 0x57, 0x0e, 0x6e, 0xee, 0xa9, 0x9e, 0x19, - * 0xa3, 0x92, 0x8e, 0xc6, 0x3d, 0x76, 0xbb, 0x12, - * 0xe2, 0x78, 0x77, 0x99, 0x6a, 0x06, 0xc4, 0x45, - * 0x1f, 0x45, 0xe1, 0xf6, 0x65, 0x1f, 0xba, 0xe4, - * 0xf6, 0xca, 0xa9, 0x62, 0xa9, 0x2c, 0x3a, 0x2d, - * 0x8d, 0x34, 0xe2, 0x32, 0x6e, 0x4a, 0x52, 0x9f, - * 0x3d, 0xcf, 0xab, 0xe8, 0x63, 0x66, 0x3f, 0x06, - * 0xa3, 0xaa, 0xd5, 0xcb, 0x5d, 0x41, 0xb8, 0xe7, - * 0x0a, 0x6b, 0x45, 0x90, 0x3a, 0xf0, 0xe5, 0x7f, - * 0x7e, 0xde, 0x68, 0x20, 0x5e, 0x5a, 0x31, 0x3a, - * 0x5c, 0x25, 0xb3, 0x82, 0xc7, 0x1e, 0x7d, 0x4d, - * 0xd0, 0x23, 0x9f, 0x22, 0x1a, 0x54, 0x0b, 0xe4, - * 0x3c, 0x1c, 0xc5, 0x24, 0x39, 0x4d, 0x96, 0x90, - * 0xce, 0xc9, 0x3a, 0x07, 0x45, 0x01, 0x9e, 0xb6, - * 0x55, 0x1b, 0xdc, 0xe0, 0x3b, 0xe8, 0x92, 0x57, - * 0x43, 0x12, 0x9b, 0x11, 0x3f, 0x81, 0x5a, 0xca, - * 0xc5, 0x85, 0x39, 0x25, 0x6d, 0xe4, 0x30, 0xef, - * 0x83, 0x21, 0xed, 0x9c, 0xb3, 0xcf, 0x10, 0xe6, - * 0xa1, 0x46, 0x10, 0x9a, 0x7b, 0xaf, 0x5f, 0x75, - * 0x99, 0x62, 0xc1, 0xf4, 0x2c, 0x28, 0x0a, 0x8a, - * 0xc7, 0xd2, 0xb4, 0x75, 0xb9, 0x66, 0x70, 0x9a, - * 0xaf, 0xe3, 0xf1, 0x2f, 0xf2, 0xb0, 0x59, 0x9c, - * 0x1e, 0x1a, 0xbd, 0xa9, 0x15, 0x55, 0x95, 0x4c, - * 0x5b, 0x78, 0x0b, 0x2c, 0x00, 0xbb, 0xf9, 0x8b, - * 0xeb, 0x72, 0x4f, 0xfb, 0xa4, 0x3a, 0xa0, 0x04, - * 0x45, 0x32, 0x02, 0x6c, 0x16, 0x52, 0x3f, 0x4a, - * 0x0a, 0x77, 0x64, 0xf4, 0x74, 0xed, 0x60, 0x6b, - * 0x5e, 0x43, 0xa7, 0xe3, 0x84, 0x7e, 0xda, 0xf0, - * 0xb1, 0x9e, 0x6d, 0x90, 0x9c, 0x32, 0xae, 0xba, - * 0x7c, 0xfb, 0x72, 0x22, 0x27, 0x9c, 0xe1, 0x85, - * 0xe1, 0xf6, 0x22, 0x4c, 0x3c, 0x4a, 0xd6, 0xed, - * 0x4c, 0xa7, 0x79, 0x59, 0xb5, 0x5b, 0x91, 0x65, - * 0x3f, 0x93, 0x97, 0x8d, 0xd7, 0xd0, 0xab, 0x17, - * 0x2f, 0x13, 0x74, 0x53, 0x69, 0x74, 0xf8, 0x6b, - * 0x39, 0x5c, 0x64, 0x5b, 0x3d, 0x75, 0xca, 0x85, - * 0x0e, 0xda, 0x0f, 0x01, 0x34, 0xa3, 0x67, 0x8e, - * 0x26, 0x6f, 0x26, 0x3c, 0xd0, 0xd9, 0xae, 0xe8, - * 0x52, 0x13, 0x7f, 0xf8, 0x69, 0x62, 0xfc, 0x9a, - * 0xc0, 0x0c, 0x66, 0x2e, 0x57, 0x21, 0x75, 0xb0, - * 0xb3, 0x8c, 0xf6, 0x97, 0x44, 0x46, 0x65, 0x15, - * 0x79, 0xd5, 0x6b, 0x68, 0x96, 0x47, 0xc1, 0xba, - * 0x75, 0x46, 0x87, 0x76, 0x7d, 0x2d, 0xac, 0xf3, - * 0x16, 0xae, 0xfb, 0x7e, 0x41, 0xe4, 0xae, 0x15, - * 0xc2, 0x51, 0x69, 0x71, 0x0b, 0x63, 0x20, 0x6a, - * 0xbd, 0xad, 0xce, 0x2a, 0x94, 0xac, 0xcf, 0x15, - * 0x4e, 0xdc, 0x8e, 0x2a, 0x48, 0xed, 0xb3, 0x48, - * 0x95, 0xf4, 0x41, 0xf3, 0x52, 0xef, 0x62, 0x90, - * 0x10, 0x30, 0x42, 0xec, 0xf9, 0x30, 0x25, 0xc3, - * 0xc5, 0x47, 0x76, 0xb5, 0x37, 0xeb, 0x9e, 0x87, - * 0xbe, 0x5c, 0x24, 0xa5, 0x34, 0xdd, 0x92, 0xa1, - * 0x20, 0x7d, 0xa7, 0x94, 0xa2, 0x67, 0x26, 0x70, - * 0xfe, 0xc9, 0x3f, 0x21, 0xd1, 0xc2, 0x5a, 0xb1, - * 0xaa, 0xac, 0x14, 0x1a, 0xe4, 0xdb, 0x71, 0x7e, - * 0x9c, 0xc2, 0x52, 0x59, 0xc9, 0x58, 0xca, 0x88, - * 0x71, 0x4f, 0x90, 0xb1, 0xbb, 0xac, 0x80, 0x53, - * 0x21, 0xfb, 0xff, 0xfd, 0x1e, 0x9f, 0xc0, 0x59, - * 0x8d, 0x80, 0x8e, 0x85, 0xa9, 0x3b, 0xd3, 0x20, - * 0x3b, 0x91, 0x16, 0x49, 0xb2, 0x2a, 0xa4, 0xe2, - * 0x30, 0xb2, 0x76, 0xf6, 0x92, 0x71, 0x37, 0x1b - * }; - */ +static const unsigned char ml_dsa_65_pub_key[] = { + 0x3b, 0x5c, 0xb0, 0x79, 0xd2, 0xce, 0x76, 0x2b, + 0x3b, 0x95, 0x7c, 0x26, 0x69, 0x8f, 0xe7, 0x01, + 0xb9, 0x6b, 0x50, 0xa3, 0x2c, 0x73, 0x67, 0xcf, + 0x9e, 0xf4, 0xb8, 0x7d, 0xe3, 0xaf, 0x27, 0x77, + 0xc6, 0x7c, 0x34, 0xb7, 0x30, 0x4d, 0x01, 0xa4, + 0xaa, 0xce, 0x16, 0x7c, 0x13, 0x2b, 0x30, 0x6c, + 0x88, 0x31, 0xe4, 0x90, 0xf5, 0xc2, 0x80, 0xf5, + 0xe8, 0xb9, 0x2d, 0x7a, 0x83, 0x17, 0xfc, 0xbb, + 0x13, 0x6f, 0x18, 0x75, 0x5b, 0x40, 0x39, 0x2d, + 0x47, 0x56, 0x15, 0xc7, 0x1c, 0x6e, 0x9a, 0x95, + 0x7b, 0x6b, 0x77, 0x9f, 0x86, 0x38, 0x0e, 0xee, + 0xc0, 0x82, 0x6c, 0x3c, 0xae, 0xc0, 0xcf, 0x5a, + 0x85, 0x49, 0xb1, 0x0c, 0x2d, 0x0e, 0x51, 0x73, + 0xf0, 0xe7, 0xad, 0x3b, 0xa7, 0x3f, 0xf5, 0x75, + 0xb9, 0xb4, 0x63, 0xb9, 0xf0, 0x0a, 0xf4, 0x29, + 0x90, 0x20, 0x72, 0x46, 0x8c, 0x7a, 0xaa, 0x86, + 0xb7, 0x4e, 0xa7, 0x65, 0x23, 0xef, 0xec, 0x46, + 0x67, 0x02, 0xf1, 0xbb, 0x88, 0xc7, 0xa4, 0xfc, + 0x66, 0x52, 0x07, 0x67, 0x68, 0xa2, 0x72, 0xe8, + 0x8a, 0x53, 0x97, 0xe6, 0x89, 0x96, 0x95, 0x9e, + 0x6a, 0xe9, 0xa4, 0x7d, 0x19, 0x19, 0x5f, 0xb4, + 0x77, 0x52, 0x17, 0xd6, 0xf2, 0xea, 0x7f, 0xfc, + 0x5c, 0xd5, 0x18, 0x16, 0x8c, 0xc2, 0x2e, 0x31, + 0xf8, 0x98, 0x4b, 0x72, 0xa1, 0x80, 0xb6, 0x5c, + 0x32, 0x19, 0x2f, 0xe0, 0xae, 0x74, 0xf4, 0xc4, + 0x0a, 0xe0, 0x54, 0x52, 0x46, 0x9e, 0xf3, 0xb9, + 0x6c, 0x56, 0xd1, 0xe8, 0x99, 0x29, 0x39, 0x95, + 0x30, 0xa2, 0x6a, 0xc6, 0x32, 0x8a, 0xa6, 0x02, + 0x6a, 0x39, 0x2e, 0x13, 0x20, 0xbc, 0xf8, 0x7a, + 0x09, 0xb6, 0xa7, 0xd1, 0x39, 0xa5, 0x12, 0x02, + 0x81, 0x47, 0x8c, 0xc0, 0x1e, 0xfd, 0xf3, 0x28, + 0xe5, 0x34, 0xec, 0xf0, 0xfc, 0x3f, 0x22, 0x16, + 0xd2, 0xfe, 0xf0, 0xca, 0xaa, 0x6f, 0x82, 0xdd, + 0xd6, 0x83, 0xaf, 0xf9, 0xeb, 0x1d, 0xa8, 0x45, + 0x39, 0x63, 0xa5, 0xde, 0xee, 0x7d, 0x91, 0xe3, + 0xaa, 0xcc, 0x07, 0x92, 0xce, 0x50, 0xfd, 0xe4, + 0xa8, 0x50, 0x91, 0xd5, 0xec, 0xc1, 0x1b, 0x57, + 0x92, 0x37, 0x68, 0xf8, 0xd6, 0x32, 0x55, 0xba, + 0x65, 0xae, 0xb6, 0xc3, 0x9f, 0x6c, 0x18, 0xc5, + 0x12, 0x17, 0x9a, 0x04, 0x29, 0xab, 0x14, 0x94, + 0xbb, 0x13, 0x79, 0x5e, 0xb9, 0xf0, 0x62, 0x03, + 0xe0, 0xa4, 0x91, 0xba, 0x81, 0x4b, 0xaa, 0xf1, + 0x82, 0x47, 0x83, 0x43, 0x5f, 0x1e, 0x2d, 0x48, + 0x40, 0x56, 0xe4, 0x29, 0x79, 0x01, 0xd5, 0x89, + 0xaf, 0xa4, 0x56, 0x9e, 0x38, 0x62, 0x03, 0xa0, + 0xe7, 0x9f, 0x08, 0x1f, 0xca, 0xd4, 0x31, 0x48, + 0xf6, 0x68, 0xe0, 0xcc, 0x28, 0xff, 0x06, 0x97, + 0x67, 0x4b, 0x70, 0x78, 0xa0, 0x2a, 0xf9, 0x46, + 0x80, 0x6d, 0x37, 0xfb, 0xb3, 0x17, 0x12, 0xf0, + 0x95, 0xc7, 0xee, 0x31, 0x54, 0x75, 0xdf, 0x2a, + 0xa8, 0x7d, 0xff, 0x97, 0xbb, 0x45, 0x49, 0x55, + 0xd5, 0xac, 0x9c, 0x6f, 0x0e, 0xc3, 0x94, 0x96, + 0xc4, 0x9e, 0x9c, 0x45, 0x31, 0xcb, 0x23, 0xed, + 0x21, 0xf1, 0xfe, 0xe9, 0xf9, 0x8c, 0xb6, 0x8e, + 0x72, 0x6e, 0xdd, 0x37, 0x1c, 0xc7, 0xd6, 0x6b, + 0x36, 0x35, 0xa0, 0x67, 0x54, 0x00, 0x65, 0x2c, + 0xc8, 0xa4, 0xa0, 0x9e, 0x72, 0xd7, 0xc9, 0x3c, + 0x8c, 0x78, 0x1a, 0xf8, 0x80, 0xad, 0xc4, 0x99, + 0xc7, 0x35, 0x4e, 0x89, 0x3b, 0x4f, 0xa6, 0x9d, + 0x5d, 0xce, 0x66, 0x4d, 0x82, 0xef, 0x47, 0x73, + 0xa8, 0xc5, 0x14, 0x20, 0xdd, 0x57, 0x92, 0x10, + 0x95, 0x8a, 0xe1, 0xac, 0x82, 0xec, 0x39, 0xe7, + 0x2c, 0xa6, 0xfd, 0x50, 0x68, 0x0c, 0x3e, 0xcf, + 0xbc, 0xc5, 0x12, 0xfe, 0x30, 0xc8, 0xb7, 0xb4, + 0x84, 0xd8, 0x1d, 0x67, 0x54, 0x9d, 0x20, 0x49, + 0xa5, 0xfd, 0xf9, 0x18, 0xef, 0xc2, 0xd2, 0xcd, + 0xb7, 0x54, 0x2b, 0x31, 0x12, 0xf9, 0xaa, 0x8e, + 0x0a, 0x29, 0x0c, 0x37, 0xd2, 0x7c, 0xcd, 0xc5, + 0x0b, 0x98, 0x25, 0x97, 0x0b, 0x5a, 0xf7, 0x07, + 0x91, 0x98, 0xd1, 0x42, 0xdf, 0xc4, 0xf9, 0x42, + 0x97, 0xda, 0x20, 0xf4, 0x88, 0xe1, 0x6b, 0xd4, + 0x85, 0xf5, 0x1d, 0xca, 0x2a, 0xba, 0x30, 0xc5, + 0xdf, 0x9d, 0x4d, 0xb8, 0xb0, 0x30, 0x54, 0x61, + 0xcf, 0x91, 0x6f, 0x90, 0xa5, 0x25, 0x05, 0x9b, + 0x2b, 0x3e, 0x13, 0xcd, 0xcd, 0x40, 0x59, 0x7c, + 0x92, 0x9b, 0x51, 0x81, 0x0d, 0x58, 0x32, 0x0a, + 0x43, 0xbd, 0x01, 0xb4, 0xb8, 0x0b, 0xd5, 0xee, + 0x0d, 0x67, 0x70, 0x59, 0xd7, 0x47, 0x4f, 0xe5, + 0x84, 0x07, 0x75, 0x3e, 0x54, 0xfb, 0x5d, 0xd1, + 0x3f, 0x72, 0x6e, 0xae, 0xf9, 0x4b, 0x7b, 0x57, + 0xe0, 0xde, 0x8b, 0x8b, 0x12, 0x1b, 0x10, 0x3b, + 0x5e, 0x17, 0xd1, 0x72, 0x18, 0x3d, 0xff, 0xc6, + 0x83, 0xa5, 0xaf, 0xf9, 0x30, 0xae, 0xb7, 0x47, + 0x46, 0x5d, 0xac, 0xba, 0x35, 0x04, 0x35, 0x0b, + 0x42, 0x48, 0x7c, 0xa1, 0x00, 0x1a, 0xea, 0xea, + 0x5f, 0x93, 0x2b, 0xb7, 0xe5, 0x8f, 0x91, 0x3c, + 0x00, 0x98, 0x51, 0x40, 0xee, 0x11, 0x50, 0x70, + 0x40, 0xe4, 0x28, 0xd4, 0x79, 0x2d, 0xcd, 0x82, + 0xaf, 0x3f, 0xb2, 0xfc, 0x96, 0x8d, 0xbe, 0x79, + 0xa3, 0xcd, 0xac, 0x35, 0x4b, 0x5e, 0xb4, 0x81, + 0x0e, 0x6a, 0xde, 0x1f, 0x7e, 0xb0, 0x37, 0x3e, + 0xdc, 0xe0, 0x21, 0xcc, 0x9f, 0x90, 0x26, 0xb6, + 0x8a, 0x1d, 0xb3, 0x1e, 0xec, 0x7a, 0x88, 0x28, + 0x95, 0xe2, 0xc2, 0x1d, 0x07, 0xb1, 0xfa, 0xc6, + 0x21, 0x1b, 0x5e, 0x54, 0x7b, 0x37, 0x0e, 0x63, + 0xff, 0xdd, 0x70, 0xf9, 0xea, 0x2f, 0x2d, 0x98, + 0xe1, 0xbe, 0x37, 0xd0, 0x1f, 0x45, 0x5a, 0x63, + 0xad, 0x44, 0xbc, 0x5f, 0xc6, 0x23, 0x8a, 0xac, + 0x12, 0x71, 0xd5, 0xa2, 0x8b, 0xfc, 0x97, 0xbb, + 0x00, 0x4b, 0xd7, 0x09, 0xa6, 0xaf, 0x40, 0x08, + 0x6c, 0x8d, 0x10, 0x4a, 0x01, 0x34, 0xc1, 0x2c, + 0x92, 0x30, 0x0a, 0x85, 0x8f, 0x3f, 0x08, 0xdd, + 0xff, 0x9c, 0x10, 0xd1, 0x03, 0x03, 0x84, 0x1f, + 0xf8, 0x4e, 0xf2, 0xe3, 0xd1, 0xd3, 0xb9, 0xdf, + 0xfc, 0x97, 0x1c, 0xcf, 0x8a, 0x29, 0xe6, 0x59, + 0x04, 0xe2, 0x87, 0x27, 0xbb, 0xb9, 0x96, 0xd0, + 0x20, 0x2e, 0x91, 0x48, 0xaa, 0xbf, 0x53, 0x4a, + 0x34, 0xb5, 0x0e, 0x11, 0xce, 0xf8, 0x65, 0xa6, + 0x0d, 0x45, 0xda, 0xbf, 0x6a, 0xfb, 0x81, 0xe4, + 0x7c, 0x8c, 0xa0, 0x4b, 0x00, 0x1b, 0xd7, 0x73, + 0x61, 0x80, 0xc0, 0x6b, 0x60, 0xde, 0xf3, 0x32, + 0xae, 0x62, 0x35, 0x66, 0xdd, 0xde, 0x53, 0x61, + 0x86, 0xe9, 0x44, 0xf3, 0x01, 0x7b, 0xaa, 0xe7, + 0x31, 0xd4, 0x5b, 0x06, 0x52, 0x0f, 0xf4, 0x90, + 0x5c, 0x82, 0x3e, 0x12, 0x28, 0x88, 0x7f, 0xfc, + 0xb8, 0xee, 0x17, 0x34, 0x4e, 0xc3, 0x2a, 0xfb, + 0x84, 0x1b, 0x0f, 0xba, 0x51, 0x64, 0x96, 0x22, + 0x0d, 0x88, 0x9b, 0xf2, 0x72, 0x04, 0x55, 0x44, + 0x6a, 0x14, 0x2b, 0xa0, 0xc2, 0xbe, 0x9e, 0x7b, + 0x48, 0x32, 0xa7, 0xf6, 0x11, 0xae, 0x60, 0xfb, + 0xf8, 0x38, 0x67, 0x16, 0xdf, 0xdf, 0x46, 0x96, + 0xd7, 0x6c, 0x39, 0xa2, 0xad, 0xf7, 0xb7, 0x78, + 0x32, 0x2c, 0xba, 0xae, 0x33, 0x5a, 0x88, 0x4b, + 0x40, 0x1f, 0x88, 0xcd, 0xe7, 0x8f, 0x50, 0x5e, + 0xd8, 0x80, 0x82, 0x7b, 0x46, 0xc7, 0x07, 0x71, + 0x4f, 0x3b, 0xca, 0x9d, 0x73, 0x7c, 0xdb, 0xeb, + 0x4c, 0x37, 0xdd, 0xb4, 0xb8, 0x61, 0xf3, 0xdf, + 0xb2, 0xb5, 0x34, 0x27, 0xec, 0xeb, 0xba, 0xcc, + 0xdc, 0xe9, 0xde, 0x47, 0x2e, 0xe9, 0x3b, 0xa1, + 0x36, 0xf1, 0x66, 0xdf, 0xc8, 0x70, 0x7f, 0x39, + 0x82, 0xb3, 0x8c, 0x47, 0x9a, 0x45, 0x59, 0x2e, + 0x30, 0x9b, 0xaf, 0x7c, 0xad, 0x43, 0x38, 0x6e, + 0x05, 0x7d, 0x8b, 0xac, 0x5f, 0x70, 0x63, 0xeb, + 0x85, 0xee, 0xab, 0xa4, 0x57, 0x1d, 0x63, 0xac, + 0x48, 0x45, 0x74, 0xca, 0x0c, 0xa8, 0x65, 0x05, + 0x1a, 0x47, 0xa1, 0x2f, 0x4b, 0x96, 0x26, 0x9e, + 0xee, 0xec, 0x37, 0x57, 0xbf, 0xa0, 0x2b, 0x75, + 0xf5, 0x9b, 0xb5, 0x1d, 0x12, 0x8a, 0x61, 0x9c, + 0x8d, 0x2a, 0x7e, 0xee, 0x05, 0x2b, 0x85, 0x7c, + 0x6f, 0x34, 0xc4, 0xcd, 0xd5, 0xd0, 0xac, 0xf9, + 0x79, 0x24, 0xe7, 0x0f, 0x41, 0x95, 0xe2, 0x9a, + 0x22, 0x32, 0xa5, 0x98, 0x2e, 0x82, 0xc0, 0x07, + 0xf4, 0x74, 0x68, 0x00, 0xf9, 0x35, 0x5e, 0x12, + 0xfe, 0xa2, 0x0e, 0x15, 0x96, 0x83, 0x84, 0x31, + 0xc4, 0x25, 0xda, 0x7a, 0xec, 0x07, 0x15, 0xe4, + 0x7d, 0xc5, 0xf5, 0xe1, 0xc5, 0xba, 0x9a, 0x59, + 0x76, 0xae, 0x4e, 0x54, 0x27, 0x5e, 0xa9, 0x0d, + 0xa0, 0xd3, 0xcd, 0x99, 0x39, 0x76, 0x6d, 0x58, + 0xdf, 0x8a, 0xa9, 0x9e, 0x21, 0x22, 0x48, 0x7c, + 0x0c, 0x13, 0xfa, 0x86, 0x63, 0x74, 0x92, 0xf4, + 0xe5, 0x5d, 0xbf, 0xe4, 0x2d, 0xd7, 0xa1, 0xe3, + 0x0f, 0xc6, 0x3e, 0x82, 0xa0, 0xcc, 0xfa, 0x38, + 0x55, 0x36, 0x9b, 0x22, 0xd0, 0xb8, 0x7f, 0x3f, + 0x0f, 0x35, 0x01, 0xf9, 0x6f, 0xa6, 0x51, 0x77, + 0x21, 0xb7, 0x7a, 0x81, 0xca, 0x83, 0x6b, 0xec, + 0xa7, 0x71, 0x12, 0x6d, 0x22, 0x78, 0xb1, 0xc8, + 0x37, 0xda, 0x1d, 0xd1, 0x9c, 0xa5, 0x6c, 0xfa, + 0xd3, 0x4b, 0x87, 0x39, 0x6f, 0x59, 0xe1, 0xec, + 0x4a, 0xe5, 0x0e, 0x72, 0x2b, 0x31, 0x18, 0xd9, + 0x54, 0x6a, 0x4c, 0xc3, 0xe0, 0x58, 0x3b, 0xd8, + 0xe8, 0x65, 0xc1, 0x98, 0xed, 0x64, 0x7b, 0xb1, + 0xee, 0xa9, 0x54, 0x95, 0x37, 0x98, 0x68, 0xca, + 0x83, 0xef, 0xc5, 0x1b, 0x23, 0x71, 0x5c, 0x1a, + 0xe6, 0xc0, 0xce, 0x2e, 0x16, 0x59, 0x79, 0xf4, + 0x94, 0x43, 0xd8, 0xb1, 0x2e, 0xe3, 0xb9, 0xa0, + 0x95, 0x80, 0x66, 0xdd, 0x1d, 0xdd, 0x0d, 0x78, + 0x9d, 0xc3, 0x91, 0x60, 0x16, 0x8b, 0xc5, 0x39, + 0xad, 0xdb, 0xa3, 0xc1, 0xd2, 0x8d, 0xa0, 0x78, + 0x75, 0x68, 0xa6, 0xb9, 0x15, 0x57, 0x0b, 0x06, + 0x64, 0x55, 0xd7, 0x07, 0x53, 0xf9, 0x8b, 0xd9, + 0x97, 0x46, 0xca, 0x04, 0x95, 0xd4, 0x3c, 0xd3, + 0x8f, 0x0a, 0x53, 0x27, 0xe6, 0xd4, 0xb4, 0x7b, + 0x70, 0x12, 0x12, 0xc5, 0x14, 0xa0, 0x53, 0xe5, + 0xd4, 0x30, 0xaa, 0xcc, 0xec, 0x03, 0x0a, 0x36, + 0x21, 0x9f, 0x81, 0x16, 0x6d, 0x1d, 0x53, 0x6e, + 0x08, 0xae, 0xf7, 0x05, 0xd9, 0x73, 0x5a, 0x45, + 0x3a, 0x52, 0x3e, 0xeb, 0x67, 0x49, 0xe1, 0x1a, + 0x8a, 0x4c, 0xd9, 0x83, 0x64, 0xd8, 0x16, 0x37, + 0x1c, 0x6b, 0x1c, 0x0d, 0x8f, 0x6a, 0xbf, 0x21, + 0xf1, 0x4f, 0x4c, 0x55, 0x6f, 0xe0, 0x5c, 0xa7, + 0xb1, 0x7b, 0x57, 0xa9, 0xa2, 0xb4, 0x9d, 0x53, + 0x7f, 0x0f, 0xb0, 0x21, 0x95, 0x70, 0x3a, 0x0d, + 0xa2, 0xc1, 0x52, 0x26, 0xad, 0xa7, 0x48, 0x66, + 0x2a, 0xfc, 0xaa, 0xaf, 0x25, 0x02, 0x58, 0x80, + 0xbe, 0xe7, 0xe4, 0x2a, 0x50, 0xe5, 0x46, 0x13, + 0xaa, 0x57, 0x0e, 0x6e, 0xee, 0xa9, 0x9e, 0x19, + 0xa3, 0x92, 0x8e, 0xc6, 0x3d, 0x76, 0xbb, 0x12, + 0xe2, 0x78, 0x77, 0x99, 0x6a, 0x06, 0xc4, 0x45, + 0x1f, 0x45, 0xe1, 0xf6, 0x65, 0x1f, 0xba, 0xe4, + 0xf6, 0xca, 0xa9, 0x62, 0xa9, 0x2c, 0x3a, 0x2d, + 0x8d, 0x34, 0xe2, 0x32, 0x6e, 0x4a, 0x52, 0x9f, + 0x3d, 0xcf, 0xab, 0xe8, 0x63, 0x66, 0x3f, 0x06, + 0xa3, 0xaa, 0xd5, 0xcb, 0x5d, 0x41, 0xb8, 0xe7, + 0x0a, 0x6b, 0x45, 0x90, 0x3a, 0xf0, 0xe5, 0x7f, + 0x7e, 0xde, 0x68, 0x20, 0x5e, 0x5a, 0x31, 0x3a, + 0x5c, 0x25, 0xb3, 0x82, 0xc7, 0x1e, 0x7d, 0x4d, + 0xd0, 0x23, 0x9f, 0x22, 0x1a, 0x54, 0x0b, 0xe4, + 0x3c, 0x1c, 0xc5, 0x24, 0x39, 0x4d, 0x96, 0x90, + 0xce, 0xc9, 0x3a, 0x07, 0x45, 0x01, 0x9e, 0xb6, + 0x55, 0x1b, 0xdc, 0xe0, 0x3b, 0xe8, 0x92, 0x57, + 0x43, 0x12, 0x9b, 0x11, 0x3f, 0x81, 0x5a, 0xca, + 0xc5, 0x85, 0x39, 0x25, 0x6d, 0xe4, 0x30, 0xef, + 0x83, 0x21, 0xed, 0x9c, 0xb3, 0xcf, 0x10, 0xe6, + 0xa1, 0x46, 0x10, 0x9a, 0x7b, 0xaf, 0x5f, 0x75, + 0x99, 0x62, 0xc1, 0xf4, 0x2c, 0x28, 0x0a, 0x8a, + 0xc7, 0xd2, 0xb4, 0x75, 0xb9, 0x66, 0x70, 0x9a, + 0xaf, 0xe3, 0xf1, 0x2f, 0xf2, 0xb0, 0x59, 0x9c, + 0x1e, 0x1a, 0xbd, 0xa9, 0x15, 0x55, 0x95, 0x4c, + 0x5b, 0x78, 0x0b, 0x2c, 0x00, 0xbb, 0xf9, 0x8b, + 0xeb, 0x72, 0x4f, 0xfb, 0xa4, 0x3a, 0xa0, 0x04, + 0x45, 0x32, 0x02, 0x6c, 0x16, 0x52, 0x3f, 0x4a, + 0x0a, 0x77, 0x64, 0xf4, 0x74, 0xed, 0x60, 0x6b, + 0x5e, 0x43, 0xa7, 0xe3, 0x84, 0x7e, 0xda, 0xf0, + 0xb1, 0x9e, 0x6d, 0x90, 0x9c, 0x32, 0xae, 0xba, + 0x7c, 0xfb, 0x72, 0x22, 0x27, 0x9c, 0xe1, 0x85, + 0xe1, 0xf6, 0x22, 0x4c, 0x3c, 0x4a, 0xd6, 0xed, + 0x4c, 0xa7, 0x79, 0x59, 0xb5, 0x5b, 0x91, 0x65, + 0x3f, 0x93, 0x97, 0x8d, 0xd7, 0xd0, 0xab, 0x17, + 0x2f, 0x13, 0x74, 0x53, 0x69, 0x74, 0xf8, 0x6b, + 0x39, 0x5c, 0x64, 0x5b, 0x3d, 0x75, 0xca, 0x85, + 0x0e, 0xda, 0x0f, 0x01, 0x34, 0xa3, 0x67, 0x8e, + 0x26, 0x6f, 0x26, 0x3c, 0xd0, 0xd9, 0xae, 0xe8, + 0x52, 0x13, 0x7f, 0xf8, 0x69, 0x62, 0xfc, 0x9a, + 0xc0, 0x0c, 0x66, 0x2e, 0x57, 0x21, 0x75, 0xb0, + 0xb3, 0x8c, 0xf6, 0x97, 0x44, 0x46, 0x65, 0x15, + 0x79, 0xd5, 0x6b, 0x68, 0x96, 0x47, 0xc1, 0xba, + 0x75, 0x46, 0x87, 0x76, 0x7d, 0x2d, 0xac, 0xf3, + 0x16, 0xae, 0xfb, 0x7e, 0x41, 0xe4, 0xae, 0x15, + 0xc2, 0x51, 0x69, 0x71, 0x0b, 0x63, 0x20, 0x6a, + 0xbd, 0xad, 0xce, 0x2a, 0x94, 0xac, 0xcf, 0x15, + 0x4e, 0xdc, 0x8e, 0x2a, 0x48, 0xed, 0xb3, 0x48, + 0x95, 0xf4, 0x41, 0xf3, 0x52, 0xef, 0x62, 0x90, + 0x10, 0x30, 0x42, 0xec, 0xf9, 0x30, 0x25, 0xc3, + 0xc5, 0x47, 0x76, 0xb5, 0x37, 0xeb, 0x9e, 0x87, + 0xbe, 0x5c, 0x24, 0xa5, 0x34, 0xdd, 0x92, 0xa1, + 0x20, 0x7d, 0xa7, 0x94, 0xa2, 0x67, 0x26, 0x70, + 0xfe, 0xc9, 0x3f, 0x21, 0xd1, 0xc2, 0x5a, 0xb1, + 0xaa, 0xac, 0x14, 0x1a, 0xe4, 0xdb, 0x71, 0x7e, + 0x9c, 0xc2, 0x52, 0x59, 0xc9, 0x58, 0xca, 0x88, + 0x71, 0x4f, 0x90, 0xb1, 0xbb, 0xac, 0x80, 0x53, + 0x21, 0xfb, 0xff, 0xfd, 0x1e, 0x9f, 0xc0, 0x59, + 0x8d, 0x80, 0x8e, 0x85, 0xa9, 0x3b, 0xd3, 0x20, + 0x3b, 0x91, 0x16, 0x49, 0xb2, 0x2a, 0xa4, 0xe2, + 0x30, 0xb2, 0x76, 0xf6, 0x92, 0x71, 0x37, 0x1b +}; static const unsigned char ml_dsa_65_priv_key[] = { 0x3b, 0x5c, 0xb0, 0x79, 0xd2, 0xce, 0x76, 0x2b, @@ -3073,15 +3122,15 @@ static const uint8_t slh_dsa_sha2_128f_keygen_pub[] = { static const ST_KAT_PARAM slh_dsa_sha2_128f_keygen_init_params[] = { ST_KAT_PARAM_OCTET(OSSL_PKEY_PARAM_SLH_DSA_SEED, - slh_dsa_sha2_128f_keygen_entropy), + slh_dsa_sha2_128f_keygen_entropy), ST_KAT_PARAM_END() }; static const ST_KAT_PARAM slh_dsa_128f_keygen_expected_params[] = { ST_KAT_PARAM_OCTET(OSSL_PKEY_PARAM_PRIV_KEY, - slh_dsa_sha2_128f_keygen_priv_pub), + slh_dsa_sha2_128f_keygen_priv_pub), ST_KAT_PARAM_OCTET(OSSL_PKEY_PARAM_PUB_KEY, - slh_dsa_sha2_128f_keygen_pub), + slh_dsa_sha2_128f_keygen_pub), ST_KAT_PARAM_END() }; @@ -3115,7 +3164,7 @@ static const unsigned char slh_dsa_shake_128f_priv_pub[] = { 0xbb, 0xc7, 0x43, 0x06, 0xf7, 0x5d, 0xc2, 0xda, 0xf7, 0x37, 0x2b, 0x3c, 0x98, 0x41, 0xa4, 0xd6, 0x85, 0x2c, 0x17, 0xb4, 0x59, 0xf1, 0x69, 0x2b, 0x8e, 0x9a, 0x1a, 0x0d, 0xac, 0xe5, 0xba, 0x26, 0x38, 0x0c, 0x99, 0x30, 0x4a, 0x0d, 0xdd, 0x32, 0xf3, 0x44, 0xb9, 0x51, 0x44, 0xe1, 0xfd, 0xef, - 0x60, 0xbb, 0xc2, 0x34, 0x0e, 0x08, 0x77, 0x0f, 0xb4, 0x1a, 0x80, 0xa7, 0x6c, 0xb0, 0x8e, 0x34 + 0x60, 0xbb, 0xc2, 0x34, 0x0e, 0x08, 0x77, 0x0f, 0xb4, 0x1a, 0x80, 0xa7, 0x6c, 0xb0, 0x8e, 0x34, }; static const ST_KAT_PARAM slh_dsa_shake_128f_key_params[] = { @@ -3134,7 +3183,7 @@ static const unsigned char slh_dsa_shake_128f_sig_digest[] = { 0xb7, 0xeb, 0x1f, 0x00, 0x33, 0x41, 0xff, 0x11, 0x3f, 0xc7, 0x4d, 0xce, 0x90, 0x6c, 0x55, 0xf7, 0x4a, 0x54, 0x8b, 0x86, 0xc1, 0xb1, 0x08, 0x48, - 0x89, 0x77, 0x00, 0x72, 0x03, 0x92, 0xd1, 0xa6 + 0x89, 0x77, 0x00, 0x72, 0x03, 0x92, 0xd1, 0xa6, }; #endif /* OPENSSL_NO_SLH_DSA */ @@ -3154,6 +3203,129 @@ static const unsigned char sig_kat_persstr[] = { 0xac, 0x54, 0x4f, 0xce, 0x57, 0xf1, 0x5e, 0x11 }; +static const ST_KAT_SIGN st_kat_sign_tests[] = { + { + OSSL_SELF_TEST_DESC_SIGN_RSA, + "RSA", "RSA-SHA256", 0, 0, + rsa_crt_key, + ITM_STR(rsa_sig_msg), + ITM(sig_kat_entropyin), + ITM(sig_kat_nonce), + ITM(sig_kat_persstr), + ITM(rsa_expected_sig) + }, +#ifndef OPENSSL_NO_EC + { + OSSL_SELF_TEST_DESC_SIGN_ECDSA, + "EC", "ECDSA-SHA256", 0, 0, + ecdsa_prime_key, + ITM_STR(rsa_sig_msg), + ITM(sig_kat_entropyin), + ITM(sig_kat_nonce), + ITM(sig_kat_persstr), + ITM(ecdsa_prime_expected_sig) + }, + { + OSSL_SELF_TEST_DESC_SIGN_DetECDSA, + "EC", "ECDSA-SHA256", 0, 0, + ecdsa_prime_key, + ITM_STR(rsa_sig_msg), + NULL, 0, NULL, 0, NULL, 0, + ITM(ecdsa_prime_expected_detsig), + ecdsa_sig_params + }, +# ifndef OPENSSL_NO_EC2M + { + OSSL_SELF_TEST_DESC_SIGN_ECDSA, + "EC", "ECDSA-SHA256", 0, 0, + ecdsa_bin_key, + ITM_STR(rsa_sig_msg), + ITM(sig_kat_entropyin), + ITM(sig_kat_nonce), + ITM(sig_kat_persstr), + ITM(ecdsa_bin_expected_sig) + }, +# endif +# ifndef OPENSSL_NO_ECX + { + OSSL_SELF_TEST_DESC_SIGN_EDDSA, + "ED448", "ED448", 0, 0, + ed448_key, + ITM(ecx_sig_msg), + NULL, 0, NULL, 0, NULL, 0, + ITM(ed448_expected_sig), + }, + { + OSSL_SELF_TEST_DESC_SIGN_EDDSA, + "ED25519", "ED25519", 0, 0, + ed25519_key, + ITM(ecx_sig_msg), + NULL, 0, NULL, 0, NULL, 0, + ITM(ed25519_expected_sig), + }, +# endif /* OPENSSL_NO_ECX */ +#endif /* OPENSSL_NO_EC */ +#ifndef OPENSSL_NO_DSA + { + OSSL_SELF_TEST_DESC_SIGN_DSA, + "DSA", "DSA-SHA256", 0, SIGNATURE_MODE_VERIFY_ONLY, + dsa_key, + ITM_STR(rsa_sig_msg), + ITM(sig_kat_entropyin), + ITM(sig_kat_nonce), + ITM(sig_kat_persstr), + ITM(dsa_expected_sig) + }, +#endif /* OPENSSL_NO_DSA */ + +#ifndef OPENSSL_NO_ML_DSA + { + OSSL_SELF_TEST_DESC_SIGN_ML_DSA, + "ML-DSA-65", "ML-DSA-65", 0, 0, + ml_dsa_key, + ITM(ml_dsa_65_msg), + NULL, 0, + NULL, 0, + NULL, 0, + ITM(ml_dsa_65_sig), + ml_dsa_sig_init, + ml_dsa_sig_init + }, +#endif /* OPENSSL_NO_ML_DSA */ +#ifndef OPENSSL_NO_SLH_DSA + /* + * FIPS 140-3 IG 10.3.A.16 Note 29 says: + * + * It is recommended (but not required) that if the module implements + * both "s" and "f" algorithms, the module self-test at least one of + * each "s" and "f" algorithm. + * + * Because the "s" version is so slow, we only test the "f" versions + * here. + */ + { + OSSL_SELF_TEST_DESC_SIGN_SLH_DSA, + "SLH-DSA-SHA2-128f", "SLH-DSA-SHA2-128f", + 1, SIGNATURE_MODE_SIG_DIGESTED, + slh_dsa_sha2_128f_key_params, + ITM(slh_dsa_sha2_sig_msg), + NULL, 0, NULL, 0, NULL, 0, + ITM(slh_dsa_sha2_128f_sig_digest), + slh_dsa_sig_params, slh_dsa_sig_params + }, + { + OSSL_SELF_TEST_DESC_SIGN_SLH_DSA, + "SLH-DSA-SHAKE-128f", "SLH-DSA-SHAKE-128f", + 1, SIGNATURE_MODE_SIG_DIGESTED, + slh_dsa_shake_128f_key_params, + ITM(slh_dsa_shake_sig_msg), + NULL, 0, NULL, 0, NULL, 0, + ITM(slh_dsa_shake_128f_sig_digest), + slh_dsa_sig_params, slh_dsa_sig_params + }, +#endif /* OPENSSL_NO_SLH_DSA */ +}; + #if !defined(OPENSSL_NO_ML_DSA) static const ST_KAT_PARAM ml_dsa_keygen_params[] = { ST_KAT_PARAM_OCTET(OSSL_PKEY_PARAM_ML_DSA_SEED, sig_kat_entropyin), @@ -3520,729 +3692,79 @@ static const ST_KAT_PARAM ml_kem_key[] = { ST_KAT_PARAM_OCTET(OSSL_PKEY_PARAM_PRIV_KEY, ml_kem_512_private_key), ST_KAT_PARAM_END() }; + +static const ST_KAT_KEM st_kat_kem_tests[] = { + { + OSSL_SELF_TEST_DESC_KEM, + "ML-KEM-512", 0, + ml_kem_key, + ITM(ml_kem_512_cipher_text), + ITM(ml_kem_512_entropy), + ITM(ml_kem_512_secret), + ml_kem_512_reject_secret /* No length because same as _secret's */ + }, +}; #endif /* OPENSSL_NO_ML_KEM */ -/* - * We need an explicit HMAC-SHA-256 KAT even though it is also - * checked as part of the KDF KATs. Refer IG 10.3. - */ -static const char hmac_kat_digest[] = "SHA256"; -static const unsigned char hmac_kat_pt[] = { - 0xdd, 0x0c, 0x30, 0x33, 0x35, 0xf9, 0xe4, 0x2e, - 0xc2, 0xef, 0xcc, 0xbf, 0x07, 0x95, 0xee, 0xa2 -}; -static const unsigned char hmac_kat_key[] = { - 0xf4, 0x55, 0x66, 0x50, 0xac, 0x31, 0xd3, 0x54, - 0x61, 0x61, 0x0b, 0xac, 0x4e, 0xd8, 0x1b, 0x1a, - 0x18, 0x1b, 0x2d, 0x8a, 0x43, 0xea, 0x28, 0x54, - 0xcb, 0xae, 0x22, 0xca, 0x74, 0x56, 0x08, 0x13 -}; -static const unsigned char hmac_kat_expected[] = { - 0xf5, 0xf5, 0xe5, 0xf2, 0x66, 0x49, 0xe2, 0x40, - 0xfc, 0x9e, 0x85, 0x7f, 0x2b, 0x9a, 0xbe, 0x28, - 0x20, 0x12, 0x00, 0x92, 0x82, 0x21, 0x3e, 0x51, - 0x44, 0x5d, 0xe3, 0x31, 0x04, 0x01, 0x72, 0x6b -}; -static const ST_KAT_PARAM hmac_kat_params[] = { - ST_KAT_PARAM_UTF8STRING(OSSL_KDF_PARAM_DIGEST, hmac_kat_digest), - ST_KAT_PARAM_OCTET(OSSL_MAC_PARAM_KEY, hmac_kat_key), - ST_KAT_PARAM_END() -}; - -ST_DEFINITION st_all_tests[ST_ID_MAX] = { - { - ST_ID_DRBG_HASH, - "HASH-DRBG", - OSSL_SELF_TEST_DESC_DRBG_HASH, - SELF_TEST_DRBG, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(drbg_hash_sha256_pr_expected), - .u.drbg = { - "digest", - "SHA256", - ITM_BUF(drbg_hash_sha256_pr_entropyin), - ITM_BUF(drbg_hash_sha256_pr_nonce), - ITM_BUF(drbg_hash_sha256_pr_persstr), - ITM_BUF(drbg_hash_sha256_pr_entropyinpr0), - ITM_BUF(drbg_hash_sha256_pr_entropyinpr1), - ITM_BUF(drbg_hash_sha256_pr_addin0), - ITM_BUF(drbg_hash_sha256_pr_addin1), - }, - }, - { - ST_ID_DRBG_CTR, - "CTR-DRBG", - OSSL_SELF_TEST_DESC_DRBG_CTR, - SELF_TEST_DRBG, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(drbg_ctr_aes128_pr_df_expected), - .u.drbg = { - "cipher", - "AES-128-CTR", - ITM_BUF(drbg_ctr_aes128_pr_df_entropyin), - ITM_BUF(drbg_ctr_aes128_pr_df_nonce), - ITM_BUF(drbg_ctr_aes128_pr_df_persstr), - ITM_BUF(drbg_ctr_aes128_pr_df_entropyinpr0), - ITM_BUF(drbg_ctr_aes128_pr_df_entropyinpr1), - ITM_BUF(drbg_ctr_aes128_pr_df_addin0), - ITM_BUF(drbg_ctr_aes128_pr_df_addin1), - }, - }, - { - ST_ID_DRBG_HMAC, - "HMAC-DRBG", - OSSL_SELF_TEST_DESC_DRBG_HMAC, - SELF_TEST_DRBG, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(drbg_hmac_sha2_pr_expected), - .u.drbg = { - "digest", - "SHA256", - ITM_BUF(drbg_hmac_sha2_pr_entropyin), - ITM_BUF(drbg_hmac_sha2_pr_nonce), - ITM_BUF(drbg_hmac_sha2_pr_persstr), - ITM_BUF(drbg_hmac_sha2_pr_entropyinpr0), - ITM_BUF(drbg_hmac_sha2_pr_entropyinpr1), - ITM_BUF(drbg_hmac_sha2_pr_addin0), - ITM_BUF(drbg_hmac_sha2_pr_addin1), - }, - }, - { - ST_ID_CIPHER_AES_256_GCM, - "AES-256-GCM", - OSSL_SELF_TEST_DESC_CIPHER_AES_GCM, - SELF_TEST_KAT_CIPHER, - SELF_TEST_STATE_INIT, - ITM_BUF(aes_256_gcm_pt), - ITM_BUF(aes_256_gcm_ct), - .u.cipher = { - CIPHER_MODE_ENCRYPT | CIPHER_MODE_DECRYPT, - ITM_BUF(aes_256_gcm_key), - ITM_BUF(aes_256_gcm_iv), - ITM_BUF(aes_256_gcm_aad), - ITM_BUF(aes_256_gcm_tag), - }, - }, - { - ST_ID_CIPHER_AES_128_ECB, - "AES-128-ECB", - OSSL_SELF_TEST_DESC_CIPHER_AES_ECB, - SELF_TEST_KAT_CIPHER, - SELF_TEST_STATE_INIT, - ITM_BUF(aes_128_ecb_pt), - ITM_BUF(aes_128_ecb_ct), - .u.cipher = { - CIPHER_MODE_DECRYPT, - ITM_BUF(aes_128_ecb_key), - }, - .depends_on = aes_ecb_depends_on, - }, -#ifndef OPENSSL_NO_DES - { - ST_ID_CIPHER_DES_EDE3_ECB, - "DES-EDE3-ECB", - OSSL_SELF_TEST_DESC_CIPHER_TDES, - SELF_TEST_KAT_CIPHER, - SELF_TEST_STATE_INIT, - ITM_BUF(tdes_pt), - ITM_BUF(tdes_ct), - .u.cipher = { - CIPHER_MODE_DECRYPT, - ITM_BUF(tdes_key), - }, - }, -#endif -#ifndef OPENSSL_NO_ML_KEM +#if !defined(OPENSSL_NO_ML_KEM) || !defined(OPENSSL_NO_ML_DSA) || !defined(OPENSSL_NO_SLH_DSA) +static const ST_KAT_ASYM_KEYGEN st_kat_asym_keygen_tests[] = { +# if !defined(OPENSSL_NO_ML_KEM) /* * FIPS 140-3 IG 10.3.A resolution 14 mandates a CAST for ML-KEM * key generation. */ { - ST_ID_ASYM_KEYGEN_ML_KEM, - "ML-KEM-512", OSSL_SELF_TEST_DESC_KEYGEN_ML_KEM, - SELF_TEST_KAT_ASYM_KEYGEN, - SELF_TEST_STATE_INIT, - .u.akgen = { - ml_kem_keygen_params, - ml_kem_key, - }, + "ML-KEM-512", 0, + ml_kem_keygen_params, + ml_kem_key }, -#endif -#ifndef OPENSSL_NO_ML_DSA +# endif +# if !defined(OPENSSL_NO_ML_DSA) { - ST_ID_ASYM_KEYGEN_ML_DSA, - "ML-DSA-65", OSSL_SELF_TEST_DESC_KEYGEN_ML_DSA, - SELF_TEST_KAT_ASYM_KEYGEN, - SELF_TEST_STATE_INIT, - .u.akgen = { - ml_dsa_keygen_params, - ml_dsa_key, - }, + "ML-DSA-65", 0, + ml_dsa_keygen_params, + ml_dsa_key }, -#endif -#ifndef OPENSSL_NO_SLH_DSA +# endif +# if !defined(OPENSSL_NO_SLH_DSA) { - ST_ID_ASYM_KEYGEN_SLH_DSA, - "SLH-DSA-SHA2-128f", OSSL_SELF_TEST_DESC_KEYGEN_SLH_DSA, - SELF_TEST_KAT_ASYM_KEYGEN, - SELF_TEST_STATE_INIT, - .u.akgen = { - slh_dsa_sha2_128f_keygen_init_params, - slh_dsa_128f_keygen_expected_params, - }, + "SLH-DSA-SHA2-128f", 1, + slh_dsa_sha2_128f_keygen_init_params, + slh_dsa_128f_keygen_expected_params }, -#endif +# endif +}; +#endif /* !OPENSSL_NO_ML_DSA || !OPENSSL_NO_SLH_DSA */ + +static const ST_KAT_ASYM_CIPHER st_kat_asym_cipher_tests[] = { { - ST_ID_SIG_RSA_SHA256, - "RSA-SHA256", - OSSL_SELF_TEST_DESC_SIGN_RSA, - SELF_TEST_KAT_SIGNATURE, - SELF_TEST_STATE_INIT, - ITM_BUF_STR(rsa_sig_msg), - ITM_BUF(rsa_expected_sig), - .u.sig = { - "RSA", - 0, - rsa_crt_key, - ITM_BUF(sig_kat_entropyin), - ITM_BUF(sig_kat_nonce), - ITM_BUF(sig_kat_persstr), - }, - }, -#ifndef OPENSSL_NO_EC - { - ST_ID_SIG_ECDSA_SHA256, - "ECDSA-SHA256", - OSSL_SELF_TEST_DESC_SIGN_ECDSA, - SELF_TEST_KAT_SIGNATURE, - SELF_TEST_STATE_INIT, - ITM_BUF_STR(rsa_sig_msg), - ITM_BUF(ecdsa_prime_expected_sig), - .u.sig = { - "EC", - 0, - ecdsa_prime_key, - ITM_BUF(sig_kat_entropyin), - ITM_BUF(sig_kat_nonce), - ITM_BUF(sig_kat_persstr), - }, - .depends_on = ecdsa_depends_on, - }, -#ifndef OPENSSL_NO_HMAC_DRBG_KDF - { - ST_ID_SIG_DET_ECDSA_SHA256, - "ECDSA-SHA256", - OSSL_SELF_TEST_DESC_SIGN_DetECDSA, - SELF_TEST_KAT_SIGNATURE, - SELF_TEST_STATE_INIT, - ITM_BUF_STR(rsa_sig_msg), - ITM_BUF(ecdsa_prime_expected_detsig), - .u.sig = { - "EC", - 0, - ecdsa_prime_key, - .init = ecdsa_sig_params, - }, - }, -#endif -#ifndef OPENSSL_NO_EC2M - { - ST_ID_SIG_E2CM_ECDSA_SHA256, - "ECDSA-SHA256", - OSSL_SELF_TEST_DESC_SIGN_ECDSA, - SELF_TEST_KAT_SIGNATURE, - SELF_TEST_STATE_INIT, - ITM_BUF_STR(rsa_sig_msg), - ITM_BUF(ecdsa_bin_expected_sig), - .u.sig = { - "EC", - 0, - ecdsa_bin_key, - ITM_BUF(sig_kat_entropyin), - ITM_BUF(sig_kat_nonce), - ITM_BUF(sig_kat_persstr), - }, - }, -#endif -#ifndef OPENSSL_NO_ECX - { - ST_ID_SIG_ED448, - "ED448", - OSSL_SELF_TEST_DESC_SIGN_EDDSA, - SELF_TEST_KAT_SIGNATURE, - SELF_TEST_STATE_INIT, - ITM_BUF(ecx_sig_msg), - ITM_BUF(ed448_expected_sig), - .u.sig = { - "ED448", - 0, - ed448_key, - }, - }, - { - ST_ID_SIG_ED25519, - "ED25519", - OSSL_SELF_TEST_DESC_SIGN_EDDSA, - SELF_TEST_KAT_SIGNATURE, - SELF_TEST_STATE_INIT, - ITM_BUF(ecx_sig_msg), - ITM_BUF(ed25519_expected_sig), - .u.sig = { - "ED25519", - 0, - ed25519_key, - }, - }, -#endif /* OPENSSL_NO_ECX */ -#endif /* OPENSSL_NO_EC */ -#ifndef OPENSSL_NO_DSA - { - ST_ID_SIG_DSA_SHA256, - "DSA-SHA256", - OSSL_SELF_TEST_DESC_SIGN_DSA, - SELF_TEST_KAT_SIGNATURE, - SELF_TEST_STATE_INIT, - ITM_BUF_STR(rsa_sig_msg), - ITM_BUF(dsa_expected_sig), - .u.sig = { - "DSA", - SIGNATURE_MODE_VERIFY_ONLY, - dsa_key, - ITM_BUF(sig_kat_entropyin), - ITM_BUF(sig_kat_nonce), - ITM_BUF(sig_kat_persstr), - }, - }, -#endif /* OPENSSL_NO_DSA */ -#ifndef OPENSSL_NO_ML_DSA - { - ST_ID_SIG_ML_DSA_65, - "ML-DSA-65", - OSSL_SELF_TEST_DESC_SIGN_ML_DSA, - SELF_TEST_KAT_SIGNATURE, - SELF_TEST_STATE_INIT, - ITM_BUF(ml_dsa_65_msg), - ITM_BUF(ml_dsa_65_sig), - .u.sig = { - "ML-DSA-65", - 0, - ml_dsa_key, - .init = ml_dsa_sig_init, - .verify = ml_dsa_sig_init, - }, - }, -#endif /* OPENSSL_NO_ML_DSA */ -#ifndef OPENSSL_NO_SLH_DSA - /* - * FIPS 140-3 IG 10.3.A.16 Note 29 says: - * - * It is recommended (but not required) that if the module implements - * both "s" and "f" algorithms, the module self-test at least one of - * each "s" and "f" algorithm. - * - * Because the "s" version is so slow, we only test the "f" versions - * here. - */ - { - ST_ID_SIG_SLH_DSA_SHA2_128F, - "SLH-DSA-SHA2-128f", - OSSL_SELF_TEST_DESC_SIGN_SLH_DSA, - SELF_TEST_KAT_SIGNATURE, - SELF_TEST_STATE_INIT, - ITM_BUF(slh_dsa_sha2_sig_msg), - ITM_BUF(slh_dsa_sha2_128f_sig_digest), - .u.sig = { - "SLH-DSA-SHA2-128f", - SIGNATURE_MODE_SIG_DIGESTED, - slh_dsa_sha2_128f_key_params, - .init = slh_dsa_sig_params, - .verify = slh_dsa_sig_params, - }, - }, - { - ST_ID_SIG_SLH_DSA_SHAKE_128F, - "SLH-DSA-SHAKE-128f", - OSSL_SELF_TEST_DESC_SIGN_SLH_DSA, - SELF_TEST_KAT_SIGNATURE, - SELF_TEST_STATE_INIT, - ITM_BUF(slh_dsa_shake_sig_msg), - ITM_BUF(slh_dsa_shake_128f_sig_digest), - .u.sig = { - "SLH-DSA-SHAKE-128f", - SIGNATURE_MODE_SIG_DIGESTED, - slh_dsa_shake_128f_key_params, - .init = slh_dsa_sig_params, - .verify = slh_dsa_sig_params, - }, - }, -#endif /* OPENSSL_NO_SLH_DSA */ -/* - * FIPS 140-3 IG 10.3.A Note 5 mandates a CAST for LMS. - * - * It permits this to be omitted if HSS is also implemented and has - * the relevant self tests. Once HSS is implemented, this test can be - * removed. This IG permits the digest's CAST to be subsumed into this - * test, however, because this will be removed, the underlying digest - * test has been retained elsewhere lest it is accidentally omitted. - */ -#ifndef OPENSSL_NO_LMS - { - ST_ID_SIG_LMS, - "LMS", - OSSL_SELF_TEST_DESC_SIGN_LMS, - SELF_TEST_KAT_SIGNATURE, - SELF_TEST_STATE_INIT, - ITM_BUF(sha256_192_msg), - ITM_BUF(sha256_192_sig), - .u.sig = { - "LMS", - SIGNATURE_MODE_VERIFY_ONLY, - lms_key, - }, - }, -#endif -#ifndef OPENSSL_NO_ML_KEM - { - ST_ID_KEM_ML_KEM, - "ML-KEM-512", - OSSL_SELF_TEST_DESC_KEM, - SELF_TEST_KAT_KEM, - SELF_TEST_STATE_INIT, - .u.kem = { - ml_kem_key, - ITM_BUF(ml_kem_512_cipher_text), - ITM_BUF(ml_kem_512_entropy), - ITM_BUF(ml_kem_512_secret), - ITM_BUF(ml_kem_512_reject_secret), - }, - }, -#endif - { - ST_ID_ASYM_CIPHER_RSA_ENC, - "RSA", OSSL_SELF_TEST_DESC_ASYM_RSA_ENC, - SELF_TEST_KAT_ASYM_CIPHER, - SELF_TEST_STATE_INIT, - ITM_BUF(rsa_asym_plaintext_encrypt), - ITM_BUF(rsa_asym_expected_encrypt), - .u.ac = { - 1, - rsa_pub_key, - rsa_enc_params, - }, - .depends_on = rsaenc_depends_on, + "RSA", 0, + 1, + rsa_pub_key, + rsa_enc_params, + ITM(rsa_asym_plaintext_encrypt), + ITM(rsa_asym_expected_encrypt), }, { - ST_ID_ASYM_CIPHER_RSA_DEC, - "RSA", OSSL_SELF_TEST_DESC_ASYM_RSA_DEC, - SELF_TEST_KAT_ASYM_CIPHER, - SELF_TEST_STATE_INIT, - ITM_BUF(rsa_asym_expected_encrypt), - ITM_BUF(rsa_asym_plaintext_encrypt), - .u.ac = { - 0, - rsa_priv_key, - rsa_enc_params, - }, - .depends_on = rsaenc_depends_on, + "RSA", 0, + 0, + rsa_priv_key, + rsa_enc_params, + ITM(rsa_asym_expected_encrypt), + ITM(rsa_asym_plaintext_encrypt), }, { - ST_ID_ASYM_CIPHER_RSA_DEC_CRT, - "RSA", OSSL_SELF_TEST_DESC_ASYM_RSA_DEC, - SELF_TEST_KAT_ASYM_CIPHER, - SELF_TEST_STATE_INIT, - ITM_BUF(rsa_asym_expected_encrypt), - ITM_BUF(rsa_asym_plaintext_encrypt), - .u.ac = { - 0, - rsa_crt_key, - rsa_enc_params, - }, - .depends_on = rsaenc_depends_on, - }, -#ifndef OPENSSL_NO_DH - { - ST_ID_KA_DH, - "DH", - OSSL_SELF_TEST_DESC_KA_DH, - SELF_TEST_KAT_KAS, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(dh_secret_expected), - .u.kas = { - dh_group, - dh_host_key, - dh_peer_key, - }, - }, -#endif -#ifndef OPENSSL_NO_EC - { - ST_ID_KA_ECDH, - "EC", - OSSL_SELF_TEST_DESC_KA_ECDH, - SELF_TEST_KAT_KAS, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(ecdh_secret_expected), - .u.kas = { - ecdh_group, - ecdh_host_key, - ecdh_peer_key, - }, - }, -#endif - { - ST_ID_KDF_TLS13_EXTRACT, - OSSL_KDF_NAME_TLS1_3_KDF, - OSSL_SELF_TEST_DESC_KDF_TLS13_EXTRACT, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(tls13_kdf_early_secret), - .u.kdf = { - tls13_kdf_early_secret_params, - }, - .depends_on = hkdf_depends_on, - }, - { - ST_ID_KDF_TLS13_EXPAND, - OSSL_KDF_NAME_TLS1_3_KDF, - OSSL_SELF_TEST_DESC_KDF_TLS13_EXPAND, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(tls13_kdf_client_early_traffic_secret), - .u.kdf = { - tls13_kdf_client_early_secret_params, - }, - .depends_on = hkdf_depends_on, - }, - { - ST_ID_KDF_TLS12_PRF, - OSSL_KDF_NAME_TLS1_PRF, - OSSL_SELF_TEST_DESC_KDF_TLS12_PRF, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(tls12prf_expected), - .u.kdf = { - tls12prf_params, - }, - }, - { - ST_ID_KDF_PBKDF2, - OSSL_KDF_NAME_PBKDF2, - OSSL_SELF_TEST_DESC_KDF_PBKDF2, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(pbkdf2_expected), - .u.kdf = { - pbkdf2_params, - }, - }, -#ifndef OPENSSL_NO_KBKDF - { - ST_ID_KDF_KBKDF, - OSSL_KDF_NAME_KBKDF, - OSSL_SELF_TEST_DESC_KDF_KBKDF, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(kbkdf_expected), - .u.kdf = { - kbkdf_params, - }, - .depends_on = kbkdf_depends_on, - }, - { - ST_ID_KDF_KBKDF_KMAC, - OSSL_KDF_NAME_KBKDF, - OSSL_SELF_TEST_DESC_KDF_KBKDF_KMAC, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(kbkdf_kmac_expected), - .u.kdf = { - kbkdf_kmac_params, - }, - .depends_on = kbkdf_depends_on, - }, -#endif - { - ST_ID_KDF_HKDF, - OSSL_KDF_NAME_HKDF, - OSSL_SELF_TEST_DESC_KDF_HKDF, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(hkdf_expected), - .u.kdf = { - hkdf_params, - }, - .depends_on = hkdf_depends_on, - }, -#ifndef OPENSSL_NO_IKEV2KDF - { - ST_ID_KDF_IKEV2KDF_GEN, - OSSL_KDF_NAME_IKEV2KDF, - OSSL_SELF_TEST_DESC_KDF_IKEV2KDF_GEN, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(ikev2kdf_expected_seedkey), - .u.kdf = { - ikev2kdf_gen_params, - }, - }, - { - ST_ID_KDF_IKEV2KDF_DKM1, - OSSL_KDF_NAME_IKEV2KDF, - OSSL_SELF_TEST_DESC_KDF_IKEV2KDF_DKM1, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(ikev2kdf_expected_dkm), - .u.kdf = { - ikev2kdf_dkm_params_dkm, - }, - }, - { - ST_ID_KDF_IKEV2KDF_DKM2, - OSSL_KDF_NAME_IKEV2KDF, - OSSL_SELF_TEST_DESC_KDF_IKEV2KDF_DKM2, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(ikev2kdf_expected_dkm_sa), - .u.kdf = { - ikev2kdf_dkm_params_sa, - }, - }, - { - ST_ID_KDF_IKEV2KDF_DKM3, - OSSL_KDF_NAME_IKEV2KDF, - OSSL_SELF_TEST_DESC_KDF_IKEV2KDF_DKM3, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(ikev2kdf_expected_dkm_dh), - .u.kdf = { - ikev2kdf_dkm_params_dh, - }, - }, - { - ST_ID_KDF_IKEV2KDF_REKEY, - OSSL_KDF_NAME_IKEV2KDF, - OSSL_SELF_TEST_DESC_KDF_IKEV2KDF_REKEY, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(ikev2kdf_expected_rekey), - .u.kdf = { - ikev2kdf_rekey_params, - }, - }, -#endif -#ifndef OPENSSL_NO_SNMPKDF - { - ST_ID_KDF_SNMPKDF, - OSSL_KDF_NAME_SNMPKDF, - OSSL_SELF_TEST_DESC_KDF_SNMPKDF, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(snmpkdf_expected), - .u.kdf = { - snmpkdf_params, - }, - }, -#endif -#ifndef OPENSSL_NO_SRTPKDF - { - ST_ID_KDF_SRTPKDF, - OSSL_KDF_NAME_SRTPKDF, - OSSL_SELF_TEST_DESC_KDF_SRTPKDF, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(srtpkdf_expected), - .u.kdf = { - srtpkdf_params, - }, - }, -#endif -#ifndef OPENSSL_NO_SSKDF - { - ST_ID_KDF_SSKDF, - OSSL_KDF_NAME_SSKDF, - OSSL_SELF_TEST_DESC_KDF_SSKDF, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(sskdf_expected), - .u.kdf = { sskdf_params }, - }, -#endif -#ifndef OPENSSL_NO_X963KDF - { - ST_ID_KDF_X963KDF, - OSSL_KDF_NAME_X963KDF, - OSSL_SELF_TEST_DESC_KDF_X963KDF, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(x963kdf_expected), - .u.kdf = { x963kdf_params }, - }, -#endif -#ifndef OPENSSL_NO_X942KDF - { - ST_ID_KDF_X942KDF, - OSSL_KDF_NAME_X942KDF_ASN1, - OSSL_SELF_TEST_DESC_KDF_X942KDF, - SELF_TEST_KAT_KDF, - SELF_TEST_STATE_INIT, - .expected = ITM_BUF(x942kdf_expected), - .u.kdf = { - x942kdf_params, - }, - }, -#endif - { - ST_ID_MAC_HMAC, - "HMAC", - OSSL_SELF_TEST_DESC_INTEGRITY_HMAC, - SELF_TEST_KAT_MAC, - SELF_TEST_STATE_INIT, - ITM_BUF(hmac_kat_pt), - ITM_BUF(hmac_kat_expected), - .u.mac = { - hmac_kat_params, - }, - }, - { - ST_ID_DIGEST_SHA1, - "SHA1", - OSSL_SELF_TEST_DESC_MD_SHA1, - SELF_TEST_KAT_DIGEST, - SELF_TEST_STATE_INIT, - ITM_BUF_STR(sha1_pt), - ITM_BUF(sha1_digest), - }, - { - ST_ID_DIGEST_SHA256, - "SHA256", - OSSL_SELF_TEST_DESC_MD_SHA2, - SELF_TEST_KAT_DIGEST, - SELF_TEST_STATE_INIT, - ITM_BUF_STR(sha256_pt), - ITM_BUF(sha256_digest), - }, - { - ST_ID_DIGEST_SHA512, - "SHA512", - OSSL_SELF_TEST_DESC_MD_SHA2, - SELF_TEST_KAT_DIGEST, - SELF_TEST_STATE_INIT, - ITM_BUF_STR(sha512_pt), - ITM_BUF(sha512_digest), - }, - { - ST_ID_DIGEST_SHA3_256, - "SHA3-256", - OSSL_SELF_TEST_DESC_MD_SHA3, - SELF_TEST_KAT_DIGEST, - SELF_TEST_STATE_INIT, - ITM_BUF(sha3_256_pt), - ITM_BUF(sha3_256_digest), + "RSA", 0, + 0, + rsa_crt_key, + rsa_enc_params, + ITM(rsa_asym_expected_encrypt), + ITM(rsa_asym_plaintext_encrypt), }, }; diff --git a/providers/fips/self_test_kats.c b/providers/fips/self_test_kats.c index f2d5c439d9..12e49a2f1b 100644 --- a/providers/fips/self_test_kats.c +++ b/providers/fips/self_test_kats.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -12,24 +12,15 @@ #include #include #include -#include #include #include "crypto/ml_dsa.h" #include "crypto/rand.h" #include "internal/cryptlib.h" +#include "internal/nelem.h" #include "self_test.h" - -#if !defined(OPENSSL_NO_DH) || !defined(OPENSSL_NO_EC) -#define SELF_TEST_KA_ENABLED 1 -#endif - -#if !defined(OPENSSL_NO_ML_DSA) || !defined(OPENSSL_NO_SLH_DSA) -#define SELF_TEST_ASYM_KEYGEN_ENABLED 1 -#endif - -#if !defined(OPENSSL_NO_ML_KEM) -#define SELF_TEST_KEM_ENABLED 1 -#endif +#include "crypto/ml_kem.h" +#include "self_test_data.inc" +#include "internal/fips.h" static int set_kat_drbg(OSSL_LIB_CTX *ctx, const unsigned char *entropy, size_t entropy_len, @@ -37,7 +28,7 @@ static int set_kat_drbg(OSSL_LIB_CTX *ctx, const unsigned char *persstr, size_t persstr_len); static int reset_main_drbg(OSSL_LIB_CTX *ctx); -static int self_test_digest(const ST_DEFINITION *t, OSSL_SELF_TEST *st, +static int self_test_digest(const ST_KAT_DIGEST *t, OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx) { int ok = 0; @@ -51,15 +42,15 @@ static int self_test_digest(const ST_DEFINITION *t, OSSL_SELF_TEST *st, if (ctx == NULL || md == NULL || !EVP_DigestInit_ex(ctx, md, NULL) - || !EVP_DigestUpdate(ctx, t->pt.buf, t->pt.len) + || !EVP_DigestUpdate(ctx, t->pt, t->pt_len) || !EVP_DigestFinal(ctx, out, &out_len)) goto err; /* Optional corruption */ OSSL_SELF_TEST_oncorrupt_byte(st, out); - if (out_len != t->expected.len - || memcmp(out, t->expected.buf, out_len) != 0) + if (out_len != t->expected_len + || memcmp(out, t->expected, out_len) != 0) goto err; ok = 1; err: @@ -81,29 +72,29 @@ static int cipher_init(EVP_CIPHER_CTX *ctx, const EVP_CIPHER *cipher, /* Flag required for Key wrapping */ EVP_CIPHER_CTX_set_flags(ctx, EVP_CIPHER_CTX_FLAG_WRAP_ALLOW); - if (t->tag.buf == NULL) { + if (t->tag == NULL) { /* Use a normal cipher init */ - return EVP_CipherInit_ex(ctx, cipher, NULL, t->key.buf, t->iv.buf, enc) + return EVP_CipherInit_ex(ctx, cipher, NULL, t->key, t->iv, enc) && EVP_CIPHER_CTX_set_padding(ctx, pad); } /* The authenticated cipher init */ if (!enc) - in_tag = (unsigned char *)t->tag.buf; + in_tag = (unsigned char *)t->tag; return EVP_CipherInit_ex(ctx, cipher, NULL, NULL, NULL, enc) - && (EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_IVLEN, (int)t->iv.len, NULL) > 0) + && (EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_IVLEN, (int)t->iv_len, NULL) > 0) && (in_tag == NULL - || EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, (int)t->tag.len, + || EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, (int)t->tag_len, in_tag) > 0) - && EVP_CipherInit_ex(ctx, NULL, NULL, t->key.buf, t->iv.buf, enc) + && EVP_CipherInit_ex(ctx, NULL, NULL, t->key, t->iv, enc) && EVP_CIPHER_CTX_set_padding(ctx, pad) - && EVP_CipherUpdate(ctx, NULL, &tmp, t->aad.buf, (int)t->aad.len); + && EVP_CipherUpdate(ctx, NULL, &tmp, t->aad, (int)t->aad_len); } /* Test a single KAT for encrypt/decrypt */ -static int self_test_cipher(const ST_DEFINITION *t, OSSL_SELF_TEST *st, +static int self_test_cipher(const ST_KAT_CIPHER *t, OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx) { int ret = 0, encrypt = 1, len = 0, ct_len = 0, pt_len = 0; @@ -112,51 +103,51 @@ static int self_test_cipher(const ST_DEFINITION *t, OSSL_SELF_TEST *st, unsigned char ct_buf[256] = { 0 }; unsigned char pt_buf[256] = { 0 }; - OSSL_SELF_TEST_onbegin(st, OSSL_SELF_TEST_TYPE_KAT_CIPHER, t->desc); + OSSL_SELF_TEST_onbegin(st, OSSL_SELF_TEST_TYPE_KAT_CIPHER, t->base.desc); ctx = EVP_CIPHER_CTX_new(); if (ctx == NULL) goto err; - cipher = EVP_CIPHER_fetch(libctx, t->algorithm, NULL); + cipher = EVP_CIPHER_fetch(libctx, t->base.algorithm, NULL); if (cipher == NULL) goto err; /* Encrypt plain text message */ - if ((t->u.cipher.mode & CIPHER_MODE_ENCRYPT) != 0) { - if (!cipher_init(ctx, cipher, &t->u.cipher, encrypt) - || !EVP_CipherUpdate(ctx, ct_buf, &len, t->pt.buf, - (int)t->pt.len) + if ((t->mode & CIPHER_MODE_ENCRYPT) != 0) { + if (!cipher_init(ctx, cipher, t, encrypt) + || !EVP_CipherUpdate(ctx, ct_buf, &len, t->base.pt, + (int)t->base.pt_len) || !EVP_CipherFinal_ex(ctx, ct_buf + len, &ct_len)) goto err; OSSL_SELF_TEST_oncorrupt_byte(st, ct_buf); ct_len += len; - if (ct_len != (int)t->expected.len - || memcmp(t->expected.buf, ct_buf, ct_len) != 0) + if (ct_len != (int)t->base.expected_len + || memcmp(t->base.expected, ct_buf, ct_len) != 0) goto err; - if (t->u.cipher.tag.buf != NULL) { + if (t->tag != NULL) { unsigned char tag[16] = { 0 }; - if (EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_GET_TAG, - (int)t->u.cipher.tag.len, tag) + if (EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_GET_TAG, (int)t->tag_len, + tag) <= 0 - || memcmp(tag, t->u.cipher.tag.buf, t->u.cipher.tag.len) != 0) + || memcmp(tag, t->tag, t->tag_len) != 0) goto err; } } /* Decrypt cipher text */ - if ((t->u.cipher.mode & CIPHER_MODE_DECRYPT) != 0) { - if (!(cipher_init(ctx, cipher, &t->u.cipher, !encrypt) + if ((t->mode & CIPHER_MODE_DECRYPT) != 0) { + if (!(cipher_init(ctx, cipher, t, !encrypt) && EVP_CipherUpdate(ctx, pt_buf, &len, - t->expected.buf, (int)t->expected.len) + t->base.expected, (int)t->base.expected_len) && EVP_CipherFinal_ex(ctx, pt_buf + len, &pt_len))) goto err; OSSL_SELF_TEST_oncorrupt_byte(st, pt_buf); pt_len += len; - if (pt_len != (int)t->pt.len - || memcmp(pt_buf, t->pt.buf, pt_len) != 0) + if (pt_len != (int)t->base.pt_len + || memcmp(pt_buf, t->base.pt, pt_len) != 0) goto err; } @@ -213,7 +204,7 @@ err: return ret; } -#if defined(__GNUC__) +#if defined(__GNUC__) && __GNUC__ >= 4 #define SENTINEL __attribute__((sentinel)) #endif @@ -256,11 +247,11 @@ err: return params; } -static int self_test_kdf(const ST_DEFINITION *t, OSSL_SELF_TEST *st, +static int self_test_kdf(const ST_KAT_KDF *t, OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx) { int ret = 0; - unsigned char out[256]; + unsigned char out[128]; EVP_KDF *kdf = NULL; EVP_KDF_CTX *ctx = NULL; OSSL_PARAM *params = NULL; @@ -275,18 +266,18 @@ static int self_test_kdf(const ST_DEFINITION *t, OSSL_SELF_TEST *st, if (ctx == NULL) goto err; - params = kat_params_to_ossl_params(libctx, t->u.kdf.params, NULL); + params = kat_params_to_ossl_params(libctx, t->params, NULL); if (params == NULL) goto err; - if (t->expected.len > sizeof(out)) + if (t->expected_len > sizeof(out)) goto err; - if (EVP_KDF_derive(ctx, out, t->expected.len, params) <= 0) + if (EVP_KDF_derive(ctx, out, t->expected_len, params) <= 0) goto err; OSSL_SELF_TEST_oncorrupt_byte(st, out); - if (memcmp(out, t->expected.buf, t->expected.len) != 0) + if (memcmp(out, t->expected, t->expected_len) != 0) goto err; ret = 1; @@ -294,14 +285,11 @@ err: EVP_KDF_free(kdf); EVP_KDF_CTX_free(ctx); OSSL_PARAM_free(params); -#ifdef OPENSSL_PEDANTIC_ZEROIZATION - OPENSSL_cleanse(out, 256); -#endif OSSL_SELF_TEST_onend(st, ret); return ret; } -static int self_test_drbg(const ST_DEFINITION *t, OSSL_SELF_TEST *st, +static int self_test_drbg(const ST_KAT_DRBG *t, OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx) { int ret = 0; @@ -341,38 +329,36 @@ static int self_test_drbg(const ST_DEFINITION *t, OSSL_SELF_TEST *st, strength = EVP_RAND_get_strength(drbg); - drbg_params[0] = OSSL_PARAM_construct_utf8_string(t->u.drbg.param_name, - (char *)t->u.drbg.param_value, 0); + drbg_params[0] = OSSL_PARAM_construct_utf8_string(t->param_name, + t->param_value, 0); if (!EVP_RAND_CTX_set_params(drbg, drbg_params)) goto err; drbg_params[0] = OSSL_PARAM_construct_octet_string(OSSL_RAND_PARAM_TEST_ENTROPY, - (void *)t->u.drbg.entropyin.buf, - t->u.drbg.entropyin.len); + (void *)t->entropyin, + t->entropyinlen); drbg_params[1] = OSSL_PARAM_construct_octet_string(OSSL_RAND_PARAM_TEST_NONCE, - (void *)t->u.drbg.nonce.buf, - t->u.drbg.nonce.len); + (void *)t->nonce, t->noncelen); if (!EVP_RAND_instantiate(test, strength, 0, NULL, 0, drbg_params)) goto err; - if (!EVP_RAND_instantiate(drbg, strength, 0, t->u.drbg.persstr.buf, - t->u.drbg.persstr.len, NULL)) + if (!EVP_RAND_instantiate(drbg, strength, 0, t->persstr, t->persstrlen, + NULL)) goto err; drbg_params[0] = OSSL_PARAM_construct_octet_string(OSSL_RAND_PARAM_TEST_ENTROPY, - (void *)t->u.drbg.entropyinpr1.buf, - t->u.drbg.entropyinpr1.len); + (void *)t->entropyinpr1, + t->entropyinpr1len); if (!EVP_RAND_CTX_set_params(test, drbg_params)) goto err; - if (!EVP_RAND_generate(drbg, out, t->expected.len, strength, + if (!EVP_RAND_generate(drbg, out, t->expectedlen, strength, prediction_resistance, - t->u.drbg.entropyaddin1.buf, - t->u.drbg.entropyaddin1.len)) + t->entropyaddin1, t->entropyaddin1len)) goto err; drbg_params[0] = OSSL_PARAM_construct_octet_string(OSSL_RAND_PARAM_TEST_ENTROPY, - (void *)t->u.drbg.entropyinpr2.buf, - t->u.drbg.entropyinpr2.len); + (void *)t->entropyinpr2, + t->entropyinpr2len); if (!EVP_RAND_CTX_set_params(test, drbg_params)) goto err; @@ -380,15 +366,14 @@ static int self_test_drbg(const ST_DEFINITION *t, OSSL_SELF_TEST *st, * This calls ossl_prov_drbg_reseed() internally when * prediction_resistance = 1 */ - if (!EVP_RAND_generate(drbg, out, t->expected.len, strength, + if (!EVP_RAND_generate(drbg, out, t->expectedlen, strength, prediction_resistance, - t->u.drbg.entropyaddin2.buf, - t->u.drbg.entropyaddin2.len)) + t->entropyaddin2, t->entropyaddin2len)) goto err; OSSL_SELF_TEST_oncorrupt_byte(st, out); - if (memcmp(out, t->expected.buf, t->expected.len) != 0) + if (memcmp(out, t->expected, t->expectedlen) != 0) goto err; if (!EVP_RAND_uninstantiate(drbg)) @@ -408,8 +393,8 @@ err: return ret; } -#if defined(SELF_TEST_KA_ENABLED) -static int self_test_ka(const ST_DEFINITION *t, +#if !defined(OPENSSL_NO_DH) || !defined(OPENSSL_NO_EC) +static int self_test_ka(const ST_KAT_KAS *t, OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx) { int ret = 0; @@ -418,17 +403,17 @@ static int self_test_ka(const ST_DEFINITION *t, OSSL_PARAM *params = NULL; OSSL_PARAM *params_peer = NULL; unsigned char secret[256]; - size_t secret_len = t->expected.len; + size_t secret_len = t->expected_len; OSSL_SELF_TEST_onbegin(st, OSSL_SELF_TEST_TYPE_KAT_KA, t->desc); if (secret_len > sizeof(secret)) goto err; - params = kat_params_to_ossl_params(libctx, t->u.kas.key_group, - t->u.kas.key_host_data, NULL); - params_peer = kat_params_to_ossl_params(libctx, t->u.kas.key_group, - t->u.kas.key_peer_data, NULL); + params = kat_params_to_ossl_params(libctx, t->key_group, + t->key_host_data, NULL); + params_peer = kat_params_to_ossl_params(libctx, t->key_group, + t->key_peer_data, NULL); if (params == NULL || params_peer == NULL) goto err; @@ -455,8 +440,8 @@ static int self_test_ka(const ST_DEFINITION *t, OSSL_SELF_TEST_oncorrupt_byte(st, secret); - if (secret_len != t->expected.len - || memcmp(secret, t->expected.buf, t->expected.len) != 0) + if (secret_len != t->expected_len + || memcmp(secret, t->expected, t->expected_len) != 0) goto err; ret = 1; err: @@ -469,7 +454,7 @@ err: OSSL_SELF_TEST_onend(st, ret); return ret; } -#endif /* defined(SELF_TEST_KA_ENABLED) */ +#endif /* !defined(OPENSSL_NO_DH) || !defined(OPENSSL_NO_EC) */ static int digest_signature(const uint8_t *sig, size_t sig_len, uint8_t *out, size_t *out_len, @@ -491,7 +476,54 @@ static int digest_signature(const uint8_t *sig, size_t sig_len, return ret; } -static int self_test_digest_sign(const ST_DEFINITION *t, +#ifndef OPENSSL_NO_LMS +static int self_test_LMS(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx) +{ + int ret = 0; + OSSL_PARAM pm[2]; + const ST_KAT_LMS *t = &st_kat_lms_test; + EVP_PKEY_CTX *ctx = NULL; + EVP_PKEY *pkey = NULL; + EVP_SIGNATURE *sig = NULL; + + OSSL_SELF_TEST_onbegin(st, OSSL_SELF_TEST_TYPE_KAT_SIGNATURE, + OSSL_SELF_TEST_DESC_SIGN_LMS); + + pm[0] = OSSL_PARAM_construct_octet_string(OSSL_PKEY_PARAM_PUB_KEY, + (unsigned char *)t->pub, + t->publen); + pm[1] = OSSL_PARAM_construct_end(); + + ctx = EVP_PKEY_CTX_new_from_name(libctx, "LMS", ""); + if (ctx == NULL + || EVP_PKEY_fromdata_init(ctx) <= 0 + || EVP_PKEY_fromdata(ctx, &pkey, EVP_PKEY_PUBLIC_KEY, pm) <= 0) + goto err; + EVP_PKEY_CTX_free(ctx); + ctx = EVP_PKEY_CTX_new_from_pkey(libctx, pkey, ""); + if (ctx == NULL) + goto err; + + sig = EVP_SIGNATURE_fetch(libctx, "LMS", NULL); + if (sig == NULL + || EVP_PKEY_verify_message_init(ctx, sig, NULL) <= 0 + || EVP_PKEY_verify(ctx, t->sig, t->siglen, + t->msg, t->msglen) + <= 0) + goto err; + + ret = 1; +err: + EVP_PKEY_free(pkey); + EVP_PKEY_CTX_free(ctx); + EVP_SIGNATURE_free(sig); + + OSSL_SELF_TEST_onend(st, ret); + return ret; +} +#endif /* OPENSSL_NO_LMS */ + +static int self_test_digest_sign(const ST_KAT_SIGN *t, OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx) { int ret = 0; @@ -505,26 +537,25 @@ static int self_test_digest_sign(const ST_DEFINITION *t, int digested = 0; const char *typ = OSSL_SELF_TEST_TYPE_KAT_SIGNATURE; - if (t->expected.len > sizeof(sig)) + if (t->sig_expected_len > sizeof(sig)) goto err; - if (t->expected.buf == NULL) + if (t->sig_expected == NULL) typ = OSSL_SELF_TEST_TYPE_PCT_SIGNATURE; OSSL_SELF_TEST_onbegin(st, typ, t->desc); - if (t->u.sig.entropy.buf != NULL) { - if (!set_kat_drbg(libctx, t->u.sig.entropy.buf, t->u.sig.entropy.len, - t->u.sig.nonce.buf, t->u.sig.nonce.len, - t->u.sig.persstr.buf, t->u.sig.persstr.len)) + if (t->entropy != NULL) { + if (!set_kat_drbg(libctx, t->entropy, t->entropy_len, + t->nonce, t->nonce_len, t->persstr, t->persstr_len)) goto err; } - paramskey = kat_params_to_ossl_params(libctx, t->u.sig.key, NULL); - paramsinit = kat_params_to_ossl_params(libctx, t->u.sig.init, NULL); - paramsverify = kat_params_to_ossl_params(libctx, t->u.sig.verify, NULL); + paramskey = kat_params_to_ossl_params(libctx, t->key, NULL); + paramsinit = kat_params_to_ossl_params(libctx, t->init, NULL); + paramsverify = kat_params_to_ossl_params(libctx, t->verify, NULL); - fromctx = EVP_PKEY_CTX_new_from_name(libctx, t->u.sig.keytype, NULL); + fromctx = EVP_PKEY_CTX_new_from_name(libctx, t->keytype, NULL); if (fromctx == NULL || paramskey == NULL || paramsinit == NULL @@ -534,18 +565,18 @@ static int self_test_digest_sign(const ST_DEFINITION *t, || EVP_PKEY_fromdata(fromctx, &pkey, EVP_PKEY_KEYPAIR, paramskey) <= 0) goto err; - sigalg = EVP_SIGNATURE_fetch(libctx, t->algorithm, NULL); + sigalg = EVP_SIGNATURE_fetch(libctx, t->sigalgorithm, NULL); if (sigalg == NULL) goto err; ctx = EVP_PKEY_CTX_new_from_pkey(libctx, pkey, NULL); if (ctx == NULL) goto err; - digested = ((t->u.sig.mode & SIGNATURE_MODE_DIGESTED) != 0); + digested = ((t->mode & SIGNATURE_MODE_DIGESTED) != 0); - if ((t->u.sig.mode & SIGNATURE_MODE_VERIFY_ONLY) != 0) { - siglen = t->expected.len; - memcpy(psig, t->expected.buf, siglen); + if ((t->mode & SIGNATURE_MODE_VERIFY_ONLY) != 0) { + siglen = t->sig_expected_len; + memcpy(psig, t->sig_expected, siglen); } else { if (digested) { if (EVP_PKEY_sign_init_ex2(ctx, sigalg, paramsinit) <= 0) @@ -555,8 +586,8 @@ static int self_test_digest_sign(const ST_DEFINITION *t, goto err; } siglen = sizeof(sig); - if ((t->u.sig.mode & SIGNATURE_MODE_SIG_DIGESTED) != 0) { - if (EVP_PKEY_sign(ctx, NULL, &siglen, t->pt.buf, t->pt.len) <= 0) + if ((t->mode & SIGNATURE_MODE_SIG_DIGESTED) != 0) { + if (EVP_PKEY_sign(ctx, NULL, &siglen, t->msg, t->msg_len) <= 0) goto err; if (siglen > sizeof(sig)) { psig = OPENSSL_malloc(siglen); @@ -564,28 +595,28 @@ static int self_test_digest_sign(const ST_DEFINITION *t, goto err; } } - if (EVP_PKEY_sign(ctx, psig, &siglen, t->pt.buf, t->pt.len) <= 0) + if (EVP_PKEY_sign(ctx, psig, &siglen, t->msg, t->msg_len) <= 0) goto err; - if (t->expected.buf != NULL) { - if ((t->u.sig.mode & SIGNATURE_MODE_SIG_DIGESTED) != 0) { + if (t->sig_expected != NULL) { + if ((t->mode & SIGNATURE_MODE_SIG_DIGESTED) != 0) { uint8_t digested_sig[EVP_MAX_MD_SIZE]; size_t digested_sig_len = 0; if (!digest_signature(psig, siglen, digested_sig, &digested_sig_len, libctx) - || digested_sig_len != t->expected.len - || memcmp(digested_sig, t->expected.buf, t->expected.len) != 0) + || digested_sig_len != t->sig_expected_len + || memcmp(digested_sig, t->sig_expected, t->sig_expected_len) != 0) goto err; } else { - if (siglen != t->expected.len - || memcmp(psig, t->expected.buf, t->expected.len) != 0) + if (siglen != t->sig_expected_len + || memcmp(psig, t->sig_expected, t->sig_expected_len) != 0) goto err; } } } - if ((t->u.sig.mode & SIGNATURE_MODE_SIGN_ONLY) == 0) { + if ((t->mode & SIGNATURE_MODE_SIGN_ONLY) == 0) { if (digested) { if (EVP_PKEY_verify_init_ex2(ctx, sigalg, paramsverify) <= 0) goto err; @@ -594,7 +625,7 @@ static int self_test_digest_sign(const ST_DEFINITION *t, goto err; } OSSL_SELF_TEST_oncorrupt_byte(st, psig); - if (EVP_PKEY_verify(ctx, psig, siglen, t->pt.buf, t->pt.len) <= 0) + if (EVP_PKEY_verify(ctx, psig, siglen, t->msg, t->msg_len) <= 0) goto err; } ret = 1; @@ -608,7 +639,7 @@ err: OSSL_PARAM_free(paramskey); OSSL_PARAM_free(paramsinit); OSSL_PARAM_free(paramsverify); - if (t->u.sig.entropy.buf != NULL) { + if (t->entropy != NULL) { if (!reset_main_drbg(libctx)) ret = 0; } @@ -616,11 +647,11 @@ err: return ret; } -#if defined(SELF_TEST_ASYM_KEYGEN_ENABLED) +#if !defined(OPENSSL_NO_ML_DSA) || !defined(OPENSSL_NO_SLH_DSA) /* * Test that a deterministic key generation produces the correct key */ -static int self_test_asym_keygen(const ST_DEFINITION *t, OSSL_SELF_TEST *st, +static int self_test_asym_keygen(const ST_KAT_ASYM_KEYGEN *t, OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx) { int ret = 0; @@ -636,9 +667,8 @@ static int self_test_asym_keygen(const ST_DEFINITION *t, OSSL_SELF_TEST *st, key_ctx = EVP_PKEY_CTX_new_from_name(libctx, t->algorithm, NULL); if (key_ctx == NULL) goto err; - if (t->u.akgen.keygen_params != NULL) { - key_params = kat_params_to_ossl_params(libctx, t->u.akgen.keygen_params, - NULL); + if (t->keygen_params != NULL) { + key_params = kat_params_to_ossl_params(libctx, t->keygen_params, NULL); if (key_params == NULL) goto err; } @@ -647,7 +677,7 @@ static int self_test_asym_keygen(const ST_DEFINITION *t, OSSL_SELF_TEST *st, || EVP_PKEY_generate(key_ctx, &key) != 1) goto err; - for (expected = t->u.akgen.expected_params; expected->data != NULL; ++expected) { + for (expected = t->expected_params; expected->data != NULL; ++expected) { if (expected->type != OSSL_PARAM_OCTET_STRING || !EVP_PKEY_get_octet_string_param(key, expected->name, out, sizeof(out), &out_len)) @@ -666,9 +696,9 @@ err: OSSL_SELF_TEST_onend(st, ret); return ret; } -#endif /* defined(SELF_TEST_ASYM_KEYGEN_ENABLED) */ +#endif /* OPENSSL_NO_ML_DSA */ -#if defined(SELF_TEST_KEM_ENABLED) +#ifndef OPENSSL_NO_ML_KEM /* * FIPS 140-3 IG 10.3.A resolution 14 mandates a CAST for ML-KEM * encapsulation. @@ -679,7 +709,7 @@ static int self_test_kem_encapsulate(const ST_KAT_KEM *t, OSSL_SELF_TEST *st, int ret = 0; EVP_PKEY_CTX *ctx; unsigned char *wrapped = NULL, *secret = NULL; - size_t wrappedlen = t->cipher_text.len, secretlen = t->secret.len; + size_t wrappedlen = t->cipher_text_len, secretlen = t->secret_len; OSSL_PARAM params[2] = { OSSL_PARAM_END, OSSL_PARAM_END }; OSSL_SELF_TEST_onbegin(st, OSSL_SELF_TEST_TYPE_KAT_KEM, @@ -690,8 +720,8 @@ static int self_test_kem_encapsulate(const ST_KAT_KEM *t, OSSL_SELF_TEST *st, goto err; *params = OSSL_PARAM_construct_octet_string(OSSL_KEM_PARAM_IKME, - (unsigned char *)t->entropy.buf, - t->entropy.len); + (unsigned char *)t->entropy, + t->entropy_len); if (EVP_PKEY_encapsulate_init(ctx, params) <= 0) goto err; @@ -707,13 +737,13 @@ static int self_test_kem_encapsulate(const ST_KAT_KEM *t, OSSL_SELF_TEST *st, /* Compare outputs */ OSSL_SELF_TEST_oncorrupt_byte(st, wrapped); - if (wrappedlen != t->cipher_text.len - || memcmp(wrapped, t->cipher_text.buf, t->cipher_text.len) != 0) + if (wrappedlen != t->cipher_text_len + || memcmp(wrapped, t->cipher_text, t->cipher_text_len) != 0) goto err; OSSL_SELF_TEST_oncorrupt_byte(st, secret); - if (secretlen != t->secret.len - || memcmp(secret, t->secret.buf, t->secret.len) != 0) + if (secretlen != t->secret_len + || memcmp(secret, t->secret, t->secret_len) != 0) goto err; ret = 1; @@ -736,19 +766,19 @@ static int self_test_kem_decapsulate(const ST_KAT_KEM *t, OSSL_SELF_TEST *st, int ret = 0; EVP_PKEY_CTX *ctx = NULL; unsigned char *secret = NULL, *alloced = NULL; - const unsigned char *test_secret = t->secret.buf; - const unsigned char *cipher_text = t->cipher_text.buf; - size_t secretlen = t->secret.len; + const unsigned char *test_secret = t->secret; + const unsigned char *cipher_text = t->cipher_text; + size_t secretlen = t->secret_len; OSSL_SELF_TEST_onbegin(st, OSSL_SELF_TEST_TYPE_KAT_KEM, reject ? OSSL_SELF_TEST_DESC_DECAP_KEM_FAIL : OSSL_SELF_TEST_DESC_DECAP_KEM); if (reject) { - cipher_text = alloced = OPENSSL_zalloc(t->cipher_text.len); + cipher_text = alloced = OPENSSL_zalloc(t->cipher_text_len); if (alloced == NULL) goto err; - test_secret = t->reject_secret.buf; + test_secret = t->reject_secret; } ctx = EVP_PKEY_CTX_new_from_pkey(libctx, pkey, ""); @@ -765,14 +795,14 @@ static int self_test_kem_decapsulate(const ST_KAT_KEM *t, OSSL_SELF_TEST *st, /* Decapsulate */ if (EVP_PKEY_decapsulate(ctx, secret, &secretlen, - cipher_text, t->cipher_text.len) + cipher_text, t->cipher_text_len) <= 0) goto err; /* Compare output */ OSSL_SELF_TEST_oncorrupt_byte(st, secret); - if (secretlen != t->secret.len - || memcmp(secret, test_secret, t->secret.len) != 0) + if (secretlen != t->secret_len + || memcmp(secret, test_secret, t->secret_len) != 0) goto err; ret = 1; @@ -793,7 +823,7 @@ err: * 2b ML-KEM decapsulation implicit rejection path * 3 ML-KEM key generation */ -static int self_test_kem(const ST_DEFINITION *t, OSSL_SELF_TEST *st, +static int self_test_kem(const ST_KAT_KEM *t, OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx) { int ret = 0; @@ -804,7 +834,7 @@ static int self_test_kem(const ST_DEFINITION *t, OSSL_SELF_TEST *st, ctx = EVP_PKEY_CTX_new_from_name(libctx, t->algorithm, NULL); if (ctx == NULL) goto err; - params = kat_params_to_ossl_params(libctx, t->u.kem.key, NULL); + params = kat_params_to_ossl_params(libctx, t->key, NULL); if (params == NULL) goto err; @@ -812,9 +842,9 @@ static int self_test_kem(const ST_DEFINITION *t, OSSL_SELF_TEST *st, || EVP_PKEY_fromdata(ctx, &pkey, EVP_PKEY_KEYPAIR, params) <= 0) goto err; - if (!self_test_kem_encapsulate(&t->u.kem, st, libctx, pkey) - || !self_test_kem_decapsulate(&t->u.kem, st, libctx, pkey, 0) - || !self_test_kem_decapsulate(&t->u.kem, st, libctx, pkey, 1)) + if (!self_test_kem_encapsulate(t, st, libctx, pkey) + || !self_test_kem_decapsulate(t, st, libctx, pkey, 0) + || !self_test_kem_decapsulate(t, st, libctx, pkey, 1)) goto err; ret = 1; @@ -824,7 +854,7 @@ err: OSSL_PARAM_free(params); return ret; } -#endif /* defined(SELF_TEST_KEM_ENABLED) */ +#endif /* * Test an encrypt or decrypt KAT.. @@ -832,7 +862,7 @@ err: * FIPS 140-2 IG D.9 states that separate KAT tests are needed for encrypt * and decrypt.. */ -static int self_test_asym_cipher(const ST_DEFINITION *t, OSSL_SELF_TEST *st, +static int self_test_asym_cipher(const ST_KAT_ASYM_CIPHER *t, OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx) { int ret = 0; @@ -853,7 +883,7 @@ static int self_test_asym_cipher(const ST_DEFINITION *t, OSSL_SELF_TEST *st, /* Load a public or private key from data */ keybld = OSSL_PARAM_BLD_new(); if (keybld == NULL - || !add_params(keybld, t->u.ac.key, bnctx)) + || !add_params(keybld, t->key, bnctx)) goto err; keyparams = OSSL_PARAM_BLD_to_param(keybld); keyctx = EVP_PKEY_CTX_new_from_name(libctx, t->algorithm, NULL); @@ -866,16 +896,16 @@ static int self_test_asym_cipher(const ST_DEFINITION *t, OSSL_SELF_TEST *st, /* Create a EVP_PKEY_CTX to use for the encrypt or decrypt operation */ encctx = EVP_PKEY_CTX_new_from_pkey(libctx, key, NULL); if (encctx == NULL - || (t->u.ac.encrypt && EVP_PKEY_encrypt_init(encctx) <= 0) - || (!t->u.ac.encrypt && EVP_PKEY_decrypt_init(encctx) <= 0)) + || (t->encrypt && EVP_PKEY_encrypt_init(encctx) <= 0) + || (!t->encrypt && EVP_PKEY_decrypt_init(encctx) <= 0)) goto err; /* Add any additional parameters such as padding */ - if (t->u.ac.postinit != NULL) { + if (t->postinit != NULL) { initbld = OSSL_PARAM_BLD_new(); if (initbld == NULL) goto err; - if (!add_params(initbld, t->u.ac.postinit, bnctx)) + if (!add_params(initbld, t->postinit, bnctx)) goto err; initparams = OSSL_PARAM_BLD_to_param(initbld); if (initparams == NULL) @@ -884,21 +914,21 @@ static int self_test_asym_cipher(const ST_DEFINITION *t, OSSL_SELF_TEST *st, goto err; } - if (t->u.ac.encrypt) { + if (t->encrypt) { if (EVP_PKEY_encrypt(encctx, out, &outlen, - t->pt.buf, t->pt.len) + t->in, t->in_len) <= 0) goto err; } else { if (EVP_PKEY_decrypt(encctx, out, &outlen, - t->pt.buf, t->pt.len) + t->in, t->in_len) <= 0) goto err; } /* Check the KAT */ OSSL_SELF_TEST_oncorrupt_byte(st, out); - if (outlen != t->expected.len - || memcmp(out, t->expected.buf, t->expected.len) != 0) + if (outlen != t->expected_len + || memcmp(out, t->expected, t->expected_len) != 0) goto err; ret = 1; @@ -915,52 +945,127 @@ err: return ret; } -/* Test MAC algorithms */ -static int self_test_mac(const ST_DEFINITION *t, OSSL_SELF_TEST *st, - OSSL_LIB_CTX *libctx) +/* + * Test a data driven list of KAT's for digest algorithms. + * All tests are run regardless of if they fail or not. + * Return 0 if any test fails. + */ +static int self_test_digests(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, + int do_deferred) { - int ret = 0; - unsigned char out[EVP_MAX_MD_SIZE]; - size_t out_len = 0; - EVP_MAC *mac = NULL; - EVP_MAC_CTX *ctx = NULL; - OSSL_PARAM *params = NULL; + int i, ret = 1; - /* Currently used for integrity */ - OSSL_SELF_TEST_onbegin(st, OSSL_SELF_TEST_TYPE_KAT_MAC, t->desc); + for (i = 0; i < (int)OSSL_NELEM(st_kat_digest_tests); ++i) { + if (st_kat_digest_tests[i].deferred && !do_deferred) + continue; + if (!self_test_digest(&st_kat_digest_tests[i], st, libctx)) + ret = 0; + } + return ret; +} - mac = EVP_MAC_fetch(libctx, t->algorithm, ""); - if (mac == NULL) - goto err; +static int self_test_ciphers(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, + int do_deferred) +{ + int i, ret = 1; - ctx = EVP_MAC_CTX_new(mac); - if (ctx == NULL) - goto err; + for (i = 0; i < (int)OSSL_NELEM(st_kat_cipher_tests); ++i) { + if (st_kat_cipher_tests[i].base.deferred && !do_deferred) + continue; + if (!self_test_cipher(&st_kat_cipher_tests[i], st, libctx)) + ret = 0; + } + return ret; +} - params = kat_params_to_ossl_params(libctx, t->u.mac.params, NULL); - if (params == NULL) - goto err; +static int self_test_kems(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, + int do_deferred) +{ + int ret = 1; +#ifndef OPENSSL_NO_ML_KEM + int i; - if (t->expected.len > sizeof(out)) - goto err; + for (i = 0; i < (int)OSSL_NELEM(st_kat_kem_tests); ++i) { + if (st_kat_kem_tests[i].deferred && !do_deferred) + continue; + if (!self_test_kem(&st_kat_kem_tests[i], st, libctx)) + ret = 0; + } +#endif + return ret; +} - if (!EVP_MAC_init(ctx, NULL, 0, params) - || !EVP_MAC_update(ctx, t->pt.buf, t->pt.len) - || !EVP_MAC_final(ctx, out, &out_len, EVP_MAX_MD_SIZE)) - goto err; +static int self_test_asym_ciphers(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, + int do_deferred) +{ + int i, ret = 1; - OSSL_SELF_TEST_oncorrupt_byte(st, out); + for (i = 0; i < (int)OSSL_NELEM(st_kat_asym_cipher_tests); ++i) { + if (st_kat_asym_cipher_tests[i].deferred && !do_deferred) + continue; + if (!self_test_asym_cipher(&st_kat_asym_cipher_tests[i], st, libctx)) + ret = 0; + } + return ret; +} - if ((out_len != t->expected.len) - || memcmp(out, t->expected.buf, t->expected.len) != 0) - goto err; +static int self_test_kdfs(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, + int do_deferred) +{ + int i, ret = 1; - ret = 1; -err: - EVP_MAC_free(mac); - EVP_MAC_CTX_free(ctx); - OSSL_PARAM_free(params); - OSSL_SELF_TEST_onend(st, ret); + for (i = 0; i < (int)OSSL_NELEM(st_kat_kdf_tests); ++i) { + if (st_kat_kdf_tests[i].deferred && !do_deferred) + continue; + if (!self_test_kdf(&st_kat_kdf_tests[i], st, libctx)) + ret = 0; + } + return ret; +} + +static int self_test_drbgs(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, + int do_deferred) +{ + int i, ret = 1; + + for (i = 0; i < (int)OSSL_NELEM(st_kat_drbg_tests); ++i) { + if (st_kat_drbg_tests[i].deferred && !do_deferred) + continue; + if (!self_test_drbg(&st_kat_drbg_tests[i], st, libctx)) + ret = 0; + } + return ret; +} + +static int self_test_kas(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, + int do_deferred) +{ + int ret = 1; +#if !defined(OPENSSL_NO_DH) || !defined(OPENSSL_NO_EC) + int i; + + for (i = 0; i < (int)OSSL_NELEM(st_kat_kas_tests); ++i) { + if (st_kat_kas_tests[i].deferred && !do_deferred) + continue; + if (!self_test_ka(&st_kat_kas_tests[i], st, libctx)) + ret = 0; + } +#endif + + return ret; +} + +static int self_test_signatures(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, + int do_deferred) +{ + int i, ret = 1; + + for (i = 0; i < (int)OSSL_NELEM(st_kat_sign_tests); ++i) { + if (st_kat_sign_tests[i].deferred && !do_deferred) + continue; + if (!self_test_digest_sign(&st_kat_sign_tests[i], st, libctx)) + ret = 0; + } return ret; } @@ -990,8 +1095,6 @@ static int set_kat_drbg(OSSL_LIB_CTX *ctx, EVP_RAND *rand; unsigned int strength = 256; EVP_RAND_CTX *parent_rand = NULL; - int reseed_time_interval = 0; - unsigned int reseed_requests = 0; OSSL_PARAM drbg_params[3] = { OSSL_PARAM_END, OSSL_PARAM_END, OSSL_PARAM_END }; @@ -1038,12 +1141,7 @@ static int set_kat_drbg(OSSL_LIB_CTX *ctx, EVP_RAND_CTX_free(parent_rand); parent_rand = NULL; - /* Disable time/request based reseeding to make selftests deterministic */ - drbg_params[0] = OSSL_PARAM_construct_int(OSSL_DRBG_PARAM_RESEED_TIME_INTERVAL, - &reseed_time_interval); - drbg_params[1] = OSSL_PARAM_construct_uint(OSSL_DRBG_PARAM_RESEED_REQUESTS, - &reseed_requests); - if (!EVP_RAND_instantiate(kat_rand, strength, 0, persstr, persstr_len, drbg_params)) + if (!EVP_RAND_instantiate(kat_rand, strength, 0, persstr, persstr_len, NULL)) goto err; /* When we set the new private generator this one is freed, so upref it */ @@ -1108,198 +1206,37 @@ static int setup_main_random(OSSL_LIB_CTX *libctx) return 1; err: EVP_RAND_CTX_free(main_rand); - /* Ensure this global variable does not reference freed memory */ - main_rand = NULL; return 0; } -static int SELF_TEST_kats_single(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, - self_test_id_t id) +static int self_test_asym_keygens(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, + int do_deferred) { - int ret; +#if !defined(OPENSSL_NO_ML_DSA) || !defined(OPENSSL_NO_SLH_DSA) + int i, ret = 1; - switch (st_all_tests[id].category) { - case SELF_TEST_KAT_DIGEST: - ret = self_test_digest(&st_all_tests[id], st, libctx); - break; - case SELF_TEST_KAT_CIPHER: - ret = self_test_cipher(&st_all_tests[id], st, libctx); - break; - case SELF_TEST_KAT_SIGNATURE: - ret = self_test_digest_sign(&st_all_tests[id], st, libctx); - break; - case SELF_TEST_KAT_KDF: - ret = self_test_kdf(&st_all_tests[id], st, libctx); - break; - case SELF_TEST_DRBG: - ret = self_test_drbg(&st_all_tests[id], st, libctx); - break; -#if defined(SELF_TEST_KA_ENABLED) - case SELF_TEST_KAT_KAS: - ret = self_test_ka(&st_all_tests[id], st, libctx); - break; -#endif -#if defined(SELF_TEST_ASYM_KEYGEN_ENABLED) - case SELF_TEST_KAT_ASYM_KEYGEN: - ret = self_test_asym_keygen(&st_all_tests[id], st, libctx); - break; -#endif -#if defined(SELF_TEST_KEM_ENABLED) - case SELF_TEST_KAT_KEM: - ret = self_test_kem(&st_all_tests[id], st, libctx); - break; -#endif - case SELF_TEST_KAT_ASYM_CIPHER: - ret = self_test_asym_cipher(&st_all_tests[id], st, libctx); - break; - case SELF_TEST_KAT_MAC: - ret = self_test_mac(&st_all_tests[id], st, libctx); - break; - default: - ret = 0; - break; - } - if (ret) { - if (!ossl_set_self_test_state(id, SELF_TEST_STATE_PASSED)) - return 0; - } else { - ossl_set_self_test_state(id, SELF_TEST_STATE_FAILED); - ERR_raise(ERR_LIB_PROV, PROV_R_SELF_TEST_KAT_FAILURE); - } - - return ret; -} - -static int SELF_TEST_kat_deps(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, - ST_DEFINITION *test) -{ - if (test->depends_on == NULL) - return 0; - - for (int i = 0; test->depends_on[i] != ST_ID_MAX; i++) - if (!SELF_TEST_kats_execute(st, libctx, test->depends_on[i], 0)) - return 0; - - return 1; -} - -/* - * Run a single algorithm KAT, and its dependencies. - * Return 1 if successful, otherwise return 0. - */ -int SELF_TEST_kats_execute(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, - self_test_id_t id, int switch_rand) -{ - EVP_RAND_CTX *saved_rand = NULL; - int ret; - - if (id >= ST_ID_MAX || st_all_tests[id].id != id) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_CONFIG_DATA); - return 0; - } - - /* - * Dependency chains may cause a test to be referenced multiple times, - * immediately return if not in initial state. - * NOTE: In this function state can be read w/o atomics because this - * function is always executed under lock. However we need to use - * atomics to set the state so that other threads reading state always - * read a correct value. - */ - switch (st_all_tests[id].state) { - case SELF_TEST_STATE_INIT: - case SELF_TEST_STATE_DEFER: - break; - case SELF_TEST_STATE_FAILED: - return 0; - case SELF_TEST_STATE_IN_PROGRESS: - case SELF_TEST_STATE_PASSED: - case SELF_TEST_STATE_IMPLICIT: - return 1; - } - - if (switch_rand) { - saved_rand = ossl_rand_get0_private_noncreating(libctx); - if (saved_rand != NULL && !EVP_RAND_CTX_up_ref(saved_rand)) - return 0; - if (!setup_main_random(libctx) - || !RAND_set0_private(libctx, main_rand)) { - /* Decrement saved_rand reference counter */ - EVP_RAND_CTX_free(saved_rand); - EVP_RAND_CTX_free(main_rand); - /* Ensure this global variable does not reference freed memory */ - main_rand = NULL; - return 0; - } - } - - /* Mark test as in progress */ - if (!ossl_set_self_test_state(id, SELF_TEST_STATE_IN_PROGRESS)) - return 0; - - /* check if there are dependent tests to run */ - if (st_all_tests[id].depends_on) { - if (!SELF_TEST_kat_deps(st, libctx, &st_all_tests[id])) { + for (i = 0; i < (int)OSSL_NELEM(st_kat_asym_keygen_tests); ++i) { + if (st_kat_asym_keygen_tests[i].deferred && !do_deferred) + continue; + if (!self_test_asym_keygen(&st_kat_asym_keygen_tests[i], st, libctx)) ret = 0; - goto done; - } - } - - /* may have already been run through dependency chains */ - switch (st_all_tests[id].state) { - case SELF_TEST_STATE_IN_PROGRESS: - ret = SELF_TEST_kats_single(st, libctx, id); - break; - case SELF_TEST_STATE_PASSED: - ret = 1; - break; - default: - /* ensure all states are set to failed if we get here */ - ossl_set_self_test_state(id, SELF_TEST_STATE_FAILED); - ret = 0; - } - - /* - * if an implicit algorithm has explicit dependencies we want to - * ensure they are all executed as well otherwise we could not - * mark it as passed. - */ - if (st_all_tests[id].state == SELF_TEST_STATE_PASSED) - for (int i = 0; i < ST_ID_MAX; i++) { - if (st_all_tests[i].state == SELF_TEST_STATE_IMPLICIT - && st_all_tests[i].depends_on != NULL) - if (!(ret = SELF_TEST_kat_deps(st, libctx, &st_all_tests[i]))) - break; - } - -done: - /* - * now mark (pass or fail) all the algorithm tests that have been marked - * by this test implicitly tested. - */ - for (int i = 0; i < ST_ID_MAX; i++) { - if (st_all_tests[i].state == SELF_TEST_STATE_IMPLICIT) - ossl_set_self_test_state(i, st_all_tests[id].state); - } - - if (switch_rand) { - RAND_set0_private(libctx, saved_rand); - /* The above call will cause main_rand to be freed */ - main_rand = NULL; } return ret; +#else + return 1; +#endif /* OPENSSL_NO_ML_DSA */ } /* * Run the algorithm KAT's. * Return 1 is successful, otherwise return 0. - * This runs all the tests regardless of if any fail, but it will not forcibly - * run tests that have been implicitly satisfied. + * This runs all the tests regardless of if any fail. + * when do_deferred is 1 also run deferred tests, they are normally skipped */ -int SELF_TEST_kats(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx) +int SELF_TEST_kats(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, int do_deferred) { EVP_RAND_CTX *saved_rand = ossl_rand_get0_private_noncreating(libctx); - int i, ret = 1; + int ret = 1; if (saved_rand != NULL && !EVP_RAND_CTX_up_ref(saved_rand)) return 0; @@ -1308,34 +1245,199 @@ int SELF_TEST_kats(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx) /* Decrement saved_rand reference counter */ EVP_RAND_CTX_free(saved_rand); EVP_RAND_CTX_free(main_rand); - /* Ensure this global variable does not reference freed memory */ - main_rand = NULL; return 0; } - for (i = 0; i < ST_ID_MAX; i++) { - if (st_all_tests[i].state == SELF_TEST_STATE_INIT) - if (!SELF_TEST_kats_execute(st, libctx, i, 0)) - ret = 0; - } + if (!self_test_digests(st, libctx, do_deferred)) + ret = 0; + if (!self_test_ciphers(st, libctx, do_deferred)) + ret = 0; +#ifndef OPENSSL_NO_LMS + /* + * FIPS 140-3 IG 10.3.A Note 5 mandates a CAST for LMS. + * + * It permits this to be omitted if HSS is also implemented and has + * the relevant self tests. Once HSS is implemented, this test can be + * removed. This IG permits the digest's CAST to be subsumed into this + * test, however, because this will be removed, the underlying digest + * test has been retained elsewhere lest it is accidentally omitted. + */ + if (!self_test_LMS(st, libctx)) + ret = 0; +#endif /* OPENSSL_NO_LMS */ + if (!self_test_signatures(st, libctx, do_deferred)) + ret = 0; + if (!self_test_kdfs(st, libctx, do_deferred)) + ret = 0; + if (!self_test_drbgs(st, libctx, do_deferred)) + ret = 0; + if (!self_test_kas(st, libctx, do_deferred)) + ret = 0; + if (!self_test_asym_keygens(st, libctx, do_deferred)) + ret = 0; + if (!self_test_kems(st, libctx, do_deferred)) + ret = 0; + if (!self_test_asym_ciphers(st, libctx, do_deferred)) + ret = 0; RAND_set0_private(libctx, saved_rand); - /* The above call will cause main_rand to be freed */ - main_rand = NULL; return ret; } -int ossl_self_test_in_progress(self_test_id_t id) +/* + * Run a single algorithm KAT. + * This is similar to SELF_TEST_kats() but only runs the test for a single + * algorithm. + * Return 1 is successful, otherwise return 0. If no test is found for the + * algorithm it also returns 0. + * This runs all the tests for the given algorithm regardless of if any fail. + * + * NOTE: currently tests that require the TEST RNG will not work, as we can't + * replace the working DRBG with the TEST DRB after initialization. + */ +int SELF_TEST_kats_single(OSSL_SELF_TEST *st, OSSL_LIB_CTX *libctx, + int type, const char *alg_name) { - enum st_test_state state; + int ret = 1; + int i, found = 0; - if (id >= ST_ID_MAX) + if (alg_name == NULL) return 0; - if (!ossl_get_self_test_state(id, &state)) - return 0; + switch (type) { + case FIPS_DEFERRED_KAT_DIGEST: + for (i = 0; i < (int)OSSL_NELEM(st_kat_digest_tests); ++i) { + if (strcmp(st_kat_digest_tests[i].algorithm, alg_name) == 0) { + found = 1; + if (!self_test_digest(&st_kat_digest_tests[i], st, libctx)) { + ret = 0; + goto done; + } + } + } + break; - if (state == SELF_TEST_STATE_IN_PROGRESS) - return 1; - return 0; + case FIPS_DEFERRED_KAT_CIPHER: + for (i = 0; i < (int)OSSL_NELEM(st_kat_cipher_tests); ++i) { + if (strcmp(st_kat_cipher_tests[i].base.algorithm, alg_name) == 0) { + found = 1; + if (!self_test_cipher(&st_kat_cipher_tests[i], st, libctx)) { + ret = 0; + goto done; + } + } + } + break; + + case FIPS_DEFERRED_KAT_SIGNATURE: + +#ifndef OPENSSL_NO_LMS + if (strcmp("LMS", alg_name) == 0) { + found = 1; + if (!self_test_LMS(st, libctx)) { + ret = 0; + goto done; + } + break; + } +#endif /* OPENSSL_NO_LMS */ + + for (i = 0; i < (int)OSSL_NELEM(st_kat_sign_tests); ++i) { + if (strcmp(st_kat_sign_tests[i].sigalgorithm, alg_name) == 0 + || strcmp(st_kat_sign_tests[i].keytype, alg_name) == 0) { + found = 1; + if (!self_test_digest_sign(&st_kat_sign_tests[i], st, libctx)) { + ret = 0; + goto done; + } + } + } + break; + + case FIPS_DEFERRED_KAT_KDF: + for (i = 0; i < (int)OSSL_NELEM(st_kat_kdf_tests); ++i) { + if (strcmp(st_kat_kdf_tests[i].algorithm, alg_name) == 0) { + found = 1; + if (!self_test_kdf(&st_kat_kdf_tests[i], st, libctx)) { + ret = 0; + goto done; + } + } + } + break; + +#if !defined(OPENSSL_NO_DH) || !defined(OPENSSL_NO_EC) + case FIPS_DEFERRED_KAT_KA: + for (i = 0; i < (int)OSSL_NELEM(st_kat_kas_tests); ++i) { + if (strcmp(st_kat_kas_tests[i].algorithm, alg_name) == 0) { + found = 1; + if (!self_test_ka(&st_kat_kas_tests[i], st, libctx)) { + ret = 0; + goto done; + } + } + } + break; +#endif + +#if !defined(OPENSSL_NO_ML_DSA) || !defined(OPENSSL_NO_SLH_DSA) + case FIPS_DEFERRED_KAT_ASYM_KEYGEN: + for (i = 0; i < (int)OSSL_NELEM(st_kat_asym_keygen_tests); ++i) { + if (strcmp(st_kat_asym_keygen_tests[i].algorithm, alg_name) == 0) { + found = 1; + if (!self_test_asym_keygen(&st_kat_asym_keygen_tests[i], st, libctx)) { + ret = 0; + goto done; + } + } + } + break; +#endif /* OPENSSL_NO_ML_DSA */ + +#ifndef OPENSSL_NO_ML_KEM + case FIPS_DEFERRED_KAT_KEM: + for (i = 0; i < (int)OSSL_NELEM(st_kat_kem_tests); ++i) { + if (strcmp(st_kat_kem_tests[i].algorithm, alg_name) == 0) { + found = 1; + if (!self_test_kem(&st_kat_kem_tests[i], st, libctx)) { + ret = 0; + goto done; + } + } + } + break; +#endif + + case FIPS_DEFERRED_KAT_ASYM_CIPHER: + for (i = 0; i < (int)OSSL_NELEM(st_kat_asym_cipher_tests); ++i) { + if (strcmp(st_kat_asym_cipher_tests[i].algorithm, alg_name) == 0) { + found = 1; + if (!self_test_asym_cipher(&st_kat_asym_cipher_tests[i], st, libctx)) { + ret = 0; + goto done; + } + } + } + break; + + case FIPS_DEFERRED_DRBG: + for (i = 0; i < (int)OSSL_NELEM(st_kat_drbg_tests); ++i) { + if (strcmp(st_kat_drbg_tests[i].algorithm, alg_name) == 0) { + found = 1; + if (!self_test_drbg(&st_kat_drbg_tests[i], st, libctx)) { + ret = 0; + goto done; + } + } + } + break; + + default: + /* not tests yet, or bad type */ + break; + } + +done: + /* If no test was found for alg_name, it is considered a failure */ + return ret && found; } diff --git a/providers/implementations/asymciphers/rsa_enc.c b/providers/implementations/asymciphers/rsa_enc.c index 6baf553408..c2768c5931 100644 --- a/providers/implementations/asymciphers/rsa_enc.c +++ b/providers/implementations/asymciphers/rsa_enc.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -25,7 +25,6 @@ #include #include "internal/constant_time.h" #include "internal/cryptlib.h" -#include "internal/fips.h" #include "internal/sizes.h" #include "crypto/rsa.h" #include "prov/provider_ctx.h" @@ -87,13 +86,6 @@ static void *rsa_newctx(void *provctx) if (!ossl_prov_is_running()) return NULL; - -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_ASYM_CIPHER_RSA_ENC)) - return NULL; -#endif - prsactx = OPENSSL_zalloc(sizeof(PROV_RSA_CTX)); if (prsactx == NULL) return NULL; @@ -173,7 +165,7 @@ static int rsa_encrypt(void *vprsactx, unsigned char *out, size_t *outlen, && !OSSL_FIPS_IND_ON_UNAPPROVED(prsactx, OSSL_FIPS_IND_SETTABLE1, prsactx->libctx, "RSA Encrypt", "PKCS#1 v1.5 padding", - FIPS_CONFIG_RSA_PKCS15_PAD_DISABLED)) { + ossl_fips_config_rsa_pkcs15_padding_disabled)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_PADDING_MODE); return 0; } @@ -369,12 +361,6 @@ static void *rsa_dupctx(void *vprsactx) return NULL; } - if (dstctx->oaep_label != NULL - && (dstctx->oaep_label = OPENSSL_memdup(dstctx->oaep_label, dstctx->oaep_labellen)) == NULL) { - rsa_freectx(dstctx); - return NULL; - } - return dstctx; } @@ -458,12 +444,9 @@ static int rsa_set_ctx_params(void *vprsactx, const OSSL_PARAM params[]) char mdname[OSSL_MAX_NAME_SIZE]; char mdprops[OSSL_MAX_PROPQUERY_SIZE] = { '\0' }; char *str = NULL; - int count = 0; - if (prsactx == NULL || !rsa_set_ctx_params_decoder(params, &p, &count)) + if (prsactx == NULL || !rsa_set_ctx_params_decoder(params, &p)) return 0; - if (count == 0) - return 1; if (!OSSL_FIPS_IND_SET_CTX_FROM_PARAM(prsactx, OSSL_FIPS_IND_SETTABLE0, p.ind_k)) return 0; diff --git a/providers/implementations/asymciphers/rsa_enc.inc.in b/providers/implementations/asymciphers/rsa_enc.inc.in index cdf38828a0..baa9bdc8c6 100644 --- a/providers/implementations/asymciphers/rsa_enc.inc.in +++ b/providers/implementations/asymciphers/rsa_enc.inc.in @@ -1,5 +1,5 @@ /* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the \"License\"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -8,7 +8,7 @@ */ {- -use OpenSSL::paramnames qw(produce_param_decoder produce_param_decoder_with_count); +use OpenSSL::paramnames qw(produce_param_decoder); -} {- produce_param_decoder('rsa_get_ctx_params', @@ -23,7 +23,7 @@ use OpenSSL::paramnames qw(produce_param_decoder produce_param_decoder_with_coun ['OSSL_ASYM_CIPHER_PARAM_FIPS_APPROVED_INDICATOR', 'ind', 'int', 'fips'], )); -} -{- produce_param_decoder_with_count('rsa_set_ctx_params', +{- produce_param_decoder('rsa_set_ctx_params', (['OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST', 'oaep', 'utf8_string'], ['OSSL_ASYM_CIPHER_PARAM_OAEP_DIGEST_PROPS', 'oaep_pq', 'utf8_string'], ['OSSL_ASYM_CIPHER_PARAM_PAD_MODE', 'pad', 'utf8_string'], diff --git a/providers/implementations/ciphers/build.info b/providers/implementations/ciphers/build.info index 2460b0183d..dc43b8980c 100644 --- a/providers/implementations/ciphers/build.info +++ b/providers/implementations/ciphers/build.info @@ -103,12 +103,10 @@ SOURCE[$NULL_GOAL]=\ cipher_null.c SOURCE[$AES_GOAL]=\ - cipher_aes.c cipher_aes_hw.c cipher_aes_hw_aesni.c \ - cipher_aes_hw_armv8.c cipher_aes_hw_rv32i.c cipher_aes_hw_rv64i.c \ - cipher_aes_hw_s390x.c cipher_aes_hw_t4.c \ + cipher_aes.c cipher_aes_hw.c \ cipher_aes_xts.c cipher_aes_xts_hw.c \ + cipher_aes_cfb_hw.c \ cipher_aes_gcm.c cipher_aes_gcm_hw.c \ - cipher_aes_gcm_hw_ppc.c \ cipher_aes_ccm.c cipher_aes_ccm_hw.c \ cipher_aes_wrp.c \ cipher_aes_cbc_hmac_sha.c \ diff --git a/providers/implementations/ciphers/cipher_aes.c b/providers/implementations/ciphers/cipher_aes.c index 3638919aeb..3444888082 100644 --- a/providers/implementations/ciphers/cipher_aes.c +++ b/providers/implementations/ciphers/cipher_aes.c @@ -19,6 +19,7 @@ #include "cipher_aes.h" #include "prov/implementations.h" #include "prov/providercommon.h" +#include "cipher_aes_cfb.h" static OSSL_FUNC_cipher_freectx_fn aes_freectx; static OSSL_FUNC_cipher_dupctx_fn aes_dupctx; diff --git a/providers/implementations/ciphers/cipher_aes.h b/providers/implementations/ciphers/cipher_aes.h index 4e71678fd1..f051c5cba6 100644 --- a/providers/implementations/ciphers/cipher_aes.h +++ b/providers/implementations/ciphers/cipher_aes.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_H - #include #include "prov/ciphercommon.h" #include "crypto/aes_platform.h" @@ -53,51 +50,8 @@ typedef struct prov_aes_ctx_st { } PROV_AES_CTX; -/* Note that XTS, CCM and GCM modes are handled with separate abstractions - * so they are not listed here */ -enum aes_modes { - AES_MODE_ECB = 1, - AES_MODE_CBC, - AES_MODE_CFB128, - AES_MODE_CFB8, - AES_MODE_CFB1, - AES_MODE_OFB128, - AES_MODE_CTR, -}; - +#define ossl_prov_cipher_hw_aes_ofb ossl_prov_cipher_hw_aes_ofb128 const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_ecb(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_cbc(size_t keybits); -#define ossl_prov_cipher_hw_aes_cfb ossl_prov_cipher_hw_aes_cfb128 -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_cfb128(size_t keybits); -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_cfb8(size_t keybits); -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_cfb1(size_t keybits); -#define ossl_prov_cipher_hw_aes_ofb ossl_prov_cipher_hw_aes_ofb128 const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_ofb128(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_ctr(size_t keybits); - -int ossl_cipher_set_aes_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen, - aes_set_encrypt_key_fn fn_set_key, aes_block128_f fn_block, - ecb128_f fn_ecb, cbc128_f fn_cbc, ctr128_f fn_ctr); - -int ossl_cipher_hw_aes_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen); - -void ossl_cipher_aes_copyctx(PROV_CIPHER_CTX *dst, const PROV_CIPHER_CTX *src); - -#if defined(AESNI_CAPABLE) -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aesni(enum aes_modes mode); -#elif defined(ARMv8_HWAES_CAPABLE) -const PROV_CIPHER_HW *ossl_prov_cipher_hw_arm(enum aes_modes mode); -#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 32 -const PROV_CIPHER_HW *ossl_prov_cipher_hw_rv32i(enum aes_modes mode); -#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 -const PROV_CIPHER_HW *ossl_prov_cipher_hw_rv64i(enum aes_modes mode); -#elif defined(S390X_aes_128_CAPABLE) -const PROV_CIPHER_HW *ossl_prov_cipher_hw_s390x(enum aes_modes mode, - size_t keybits); -#elif defined(SPARC_AES_CAPABLE) -const PROV_CIPHER_HW *ossl_prov_cipher_hw_t4(enum aes_modes mode); -#endif - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_H) */ diff --git a/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.c b/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.c index 747a30f287..9fe1c99dac 100644 --- a/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.c +++ b/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -176,7 +176,8 @@ static int aes_set_ctx_params(void *vctx, const OSSL_PARAM params[]) ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_GET_PARAMETER); return 0; } - if (ctx->base.tlsversion == TLS1_VERSION) { + if (ctx->base.tlsversion == SSL3_VERSION + || ctx->base.tlsversion == TLS1_VERSION) { if (!ossl_assert(ctx->base.removetlsfixed >= AES_BLOCK_SIZE)) { ERR_raise(ERR_LIB_PROV, ERR_R_INTERNAL_ERROR); return 0; @@ -286,15 +287,6 @@ static void *aes_cbc_hmac_sha1_newctx(void *provctx, size_t kbits, if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_CIPHER_AES_128_ECB)) - return NULL; - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_DIGEST_SHA1)) - return NULL; -#endif - ctx = OPENSSL_zalloc(sizeof(*ctx)); if (ctx != NULL) base_init(provctx, &ctx->base_ctx, @@ -335,15 +327,6 @@ static void *aes_cbc_hmac_sha256_newctx(void *provctx, size_t kbits, if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_CIPHER_AES_128_ECB)) - return NULL; - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_DIGEST_SHA256)) - return NULL; -#endif - ctx = OPENSSL_zalloc(sizeof(*ctx)); if (ctx != NULL) base_init(provctx, &ctx->base_ctx, diff --git a/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.h b/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.h index b2cd2d4019..97831da9e7 100644 --- a/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.h +++ b/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_CBC_HMAC_SHA_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_CBC_HMAC_SHA_H - #include "prov/ciphercommon.h" #include "crypto/aes_platform.h" @@ -66,5 +63,3 @@ typedef struct prov_aes_hmac_sha256_ctx_st { #define NO_PAYLOAD_LENGTH ((size_t)-1) #endif /* AES_CBC_HMAC_SHA_CAPABLE */ - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_CBC_HMAC_SHA_H) */ diff --git a/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha1_hw.c b/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha1_hw.c index 47ab95d6fa..c3acebf278 100644 --- a/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha1_hw.c +++ b/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha1_hw.c @@ -112,7 +112,7 @@ typedef struct { const unsigned char *inp; unsigned char *out; int blocks; - uint64_t iv[2]; + u64 iv[2]; } CIPH_DESC; void sha1_multi_block(SHA1_MB_CTX *, const HASH_DESC *, int); @@ -129,17 +129,17 @@ static size_t tls1_multi_block_encrypt(void *vctx, CIPH_DESC ciph_d[8]; unsigned char storage[sizeof(SHA1_MB_CTX) + 32]; union { - uint64_t q[16]; - uint32_t d[32]; - uint8_t c[128]; + u64 q[16]; + u32 d[32]; + u8 c[128]; } blocks[8]; SHA1_MB_CTX *mctx; unsigned int frag, last, packlen, i; unsigned int x4 = 4 * n4x, minblocks, processed = 0; size_t ret = 0; - uint8_t *IVs; + u8 *IVs; #if defined(BSWAP8) - uint64_t seqnum; + u64 seqnum; #endif /* ask for IVs in bulk */ @@ -195,16 +195,16 @@ static size_t tls1_multi_block_encrypt(void *vctx, blocks[i].q[0] = BSWAP8(seqnum + i); #else for (carry = i, j = 8; j--;) { - blocks[i].c[j] = ((uint8_t *)sctx->md.data)[j] + carry; + blocks[i].c[j] = ((u8 *)sctx->md.data)[j] + carry; carry = (blocks[i].c[j] - carry) >> (sizeof(carry) * 8 - 1); } #endif - blocks[i].c[8] = ((uint8_t *)sctx->md.data)[8]; - blocks[i].c[9] = ((uint8_t *)sctx->md.data)[9]; - blocks[i].c[10] = ((uint8_t *)sctx->md.data)[10]; + blocks[i].c[8] = ((u8 *)sctx->md.data)[8]; + blocks[i].c[9] = ((u8 *)sctx->md.data)[9]; + blocks[i].c[10] = ((u8 *)sctx->md.data)[10]; /* fix length */ - blocks[i].c[11] = (uint8_t)(len >> 8); - blocks[i].c[12] = (uint8_t)(len); + blocks[i].c[11] = (u8)(len >> 8); + blocks[i].c[12] = (u8)(len); memcpy(blocks[i].c + 13, hash_d[i].ptr, 64 - 13); hash_d[i].ptr += 64 - 13; @@ -349,11 +349,11 @@ static size_t tls1_multi_block_encrypt(void *vctx, len += 16; /* account for explicit iv */ /* arrange header */ - out0[0] = ((uint8_t *)sctx->md.data)[8]; - out0[1] = ((uint8_t *)sctx->md.data)[9]; - out0[2] = ((uint8_t *)sctx->md.data)[10]; - out0[3] = (uint8_t)(len >> 8); - out0[4] = (uint8_t)(len); + out0[0] = ((u8 *)sctx->md.data)[8]; + out0[1] = ((u8 *)sctx->md.data)[9]; + out0[2] = ((u8 *)sctx->md.data)[10]; + out0[3] = (u8)(len >> 8); + out0[4] = (u8)(len); ret += len + 5; inp += frag; diff --git a/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha256_hw.c b/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha256_hw.c index 15d75d6372..b51e6d2809 100644 --- a/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha256_hw.c +++ b/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha256_hw.c @@ -116,7 +116,7 @@ typedef struct { const unsigned char *inp; unsigned char *out; int blocks; - uint64_t iv[2]; + u64 iv[2]; } CIPH_DESC; void sha256_multi_block(SHA256_MB_CTX *, const HASH_DESC *, int); @@ -133,17 +133,17 @@ static size_t tls1_multi_block_encrypt(void *vctx, CIPH_DESC ciph_d[8]; unsigned char storage[sizeof(SHA256_MB_CTX) + 32]; union { - uint64_t q[16]; - uint32_t d[32]; - uint8_t c[128]; + u64 q[16]; + u32 d[32]; + u8 c[128]; } blocks[8]; SHA256_MB_CTX *mctx; unsigned int frag, last, packlen, i; unsigned int x4 = 4 * n4x, minblocks, processed = 0; size_t ret = 0; - uint8_t *IVs; + u8 *IVs; #if defined(BSWAP8) - uint64_t seqnum; + u64 seqnum; #endif /* ask for IVs in bulk */ @@ -203,16 +203,16 @@ static size_t tls1_multi_block_encrypt(void *vctx, blocks[i].q[0] = BSWAP8(seqnum + i); #else for (carry = i, j = 8; j--;) { - blocks[i].c[j] = ((uint8_t *)sctx->md.data)[j] + carry; + blocks[i].c[j] = ((u8 *)sctx->md.data)[j] + carry; carry = (blocks[i].c[j] - carry) >> (sizeof(carry) * 8 - 1); } #endif - blocks[i].c[8] = ((uint8_t *)sctx->md.data)[8]; - blocks[i].c[9] = ((uint8_t *)sctx->md.data)[9]; - blocks[i].c[10] = ((uint8_t *)sctx->md.data)[10]; + blocks[i].c[8] = ((u8 *)sctx->md.data)[8]; + blocks[i].c[9] = ((u8 *)sctx->md.data)[9]; + blocks[i].c[10] = ((u8 *)sctx->md.data)[10]; /* fix length */ - blocks[i].c[11] = (uint8_t)(len >> 8); - blocks[i].c[12] = (uint8_t)(len); + blocks[i].c[11] = (u8)(len >> 8); + blocks[i].c[12] = (u8)(len); memcpy(blocks[i].c + 13, hash_d[i].ptr, 64 - 13); hash_d[i].ptr += 64 - 13; @@ -372,11 +372,11 @@ static size_t tls1_multi_block_encrypt(void *vctx, len += 16; /* account for explicit iv */ /* arrange header */ - out0[0] = ((uint8_t *)sctx->md.data)[8]; - out0[1] = ((uint8_t *)sctx->md.data)[9]; - out0[2] = ((uint8_t *)sctx->md.data)[10]; - out0[3] = (uint8_t)(len >> 8); - out0[4] = (uint8_t)(len); + out0[0] = ((u8 *)sctx->md.data)[8]; + out0[1] = ((u8 *)sctx->md.data)[9]; + out0[2] = ((u8 *)sctx->md.data)[10]; + out0[3] = (u8)(len >> 8); + out0[4] = (u8)(len); ret += len + 5; inp += frag; diff --git a/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha_etm.h b/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha_etm.h index fb28056f8c..8c4e70d40f 100644 --- a/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha_etm.h +++ b/providers/implementations/ciphers/cipher_aes_cbc_hmac_sha_etm.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_CBC_HMAC_SHA_ETM_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_CBC_HMAC_SHA_ETM_H - #include #include "prov/ciphercommon.h" #include "crypto/aes_platform.h" @@ -72,5 +69,3 @@ typedef struct { } CIPH_DIGEST; #endif /* AES_CBC_HMAC_SHA_ETM_CAPABLE */ - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_CBC_HMAC_SHA_ETM_H) */ diff --git a/providers/implementations/ciphers/cipher_aes_ccm.c b/providers/implementations/ciphers/cipher_aes_ccm.c index f245703fae..34d6bf468d 100644 --- a/providers/implementations/ciphers/cipher_aes_ccm.c +++ b/providers/implementations/ciphers/cipher_aes_ccm.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -24,7 +24,9 @@ static void *aes_ccm_newctx(void *provctx, size_t keybits) { PROV_AES_CCM_CTX *ctx; - CIPHER_PROV_CHECK(provctx, AES_128_CCM); + if (!ossl_prov_is_running()) + return NULL; + ctx = OPENSSL_zalloc(sizeof(*ctx)); if (ctx != NULL) ossl_ccm_initctx(&ctx->base, keybits, ossl_prov_aes_hw_ccm(keybits)); diff --git a/providers/implementations/ciphers/cipher_aes_ccm.h b/providers/implementations/ciphers/cipher_aes_ccm.h index 9fe8ba2e07..089792ee8a 100644 --- a/providers/implementations/ciphers/cipher_aes_ccm.h +++ b/providers/implementations/ciphers/cipher_aes_ccm.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_CCM_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_CCM_H - #include #include "prov/ciphercommon.h" #include "prov/ciphercommon_ccm.h" @@ -48,27 +45,4 @@ typedef struct prov_aes_ccm_ctx_st { } ccm; } PROV_AES_CCM_CTX; -int ossl_cipher_set_ccm_aes_initkey(PROV_CCM_CTX *ctx, - const unsigned char *key, size_t keylen, - aes_set_encrypt_key_fn fn_set_key, aes_block128_f fn_block, - ccm128_f fn_ccm_enc, ccm128_f fn_ccm_dec); - const PROV_CCM_HW *ossl_prov_aes_hw_ccm(size_t keylen); - -#if defined(AESNI_CAPABLE) -const PROV_CCM_HW *ossl_prov_aes_hw_ccm_aesni(void); -#endif -#if defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 32 -const PROV_CCM_HW *ossl_prov_aes_hw_ccm_rv32i(void); -#endif -#if defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 -const PROV_CCM_HW *ossl_prov_aes_hw_ccm_rv64i(void); -#endif -#if defined(S390X_aes_128_CAPABLE) -const PROV_CCM_HW *ossl_prov_aes_hw_ccm_s390x(size_t keybits); -#endif -#if defined(SPARC_AES_CAPABLE) -const PROV_CCM_HW *ossl_prov_aes_hw_ccm_t4(void); -#endif - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_CCM_H) */ diff --git a/providers/implementations/ciphers/cipher_aes_ccm_hw.c b/providers/implementations/ciphers/cipher_aes_ccm_hw.c index 6387157740..8bc7586adc 100644 --- a/providers/implementations/ciphers/cipher_aes_ccm_hw.c +++ b/providers/implementations/ciphers/cipher_aes_ccm_hw.c @@ -14,50 +14,37 @@ * non-internal use) in order to implement provider AES ciphers. */ #include "internal/deprecated.h" -#include + #include "cipher_aes_ccm.h" -int ossl_cipher_set_ccm_aes_initkey(PROV_CCM_CTX *ctx, - const unsigned char *key, size_t keylen, - aes_set_encrypt_key_fn fn_set_key, aes_block128_f fn_block, - ccm128_f fn_ccm_enc, ccm128_f fn_ccm_dec) -{ - PROV_AES_CCM_CTX *actx = (PROV_AES_CCM_CTX *)ctx; - AES_KEY *ks = &actx->ccm.ks.ks; - - int ret = fn_set_key(key, (int)(keylen * 8), ks); - if (ret < 0) { - ERR_raise(ERR_LIB_PROV, PROV_R_KEY_SETUP_FAILED); - return 0; - } - CRYPTO_ccm128_init(&ctx->ccm_ctx, (unsigned int)ctx->m, - (unsigned int)ctx->l, ks, (block128_f)fn_block); - - ctx->str = ctx->enc ? fn_ccm_enc : fn_ccm_dec; +#define AES_HW_CCM_SET_KEY_FN(fn_set_enc_key, fn_blk, fn_ccm_enc, fn_ccm_dec) \ + fn_set_enc_key(key, (int)(keylen * 8), &actx->ccm.ks.ks); \ + CRYPTO_ccm128_init(&ctx->ccm_ctx, (unsigned int)ctx->m, \ + (unsigned int)ctx->l, &actx->ccm.ks.ks, \ + (block128_f)fn_blk); \ + ctx->str = ctx->enc ? (ccm128_f)fn_ccm_enc : (ccm128_f)fn_ccm_dec; \ ctx->key_set = 1; - return 1; -} - static int ccm_generic_aes_initkey(PROV_CCM_CTX *ctx, const unsigned char *key, size_t keylen) { + PROV_AES_CCM_CTX *actx = (PROV_AES_CCM_CTX *)ctx; + #ifdef HWAES_CAPABLE if (HWAES_CAPABLE) { - return ossl_cipher_set_ccm_aes_initkey(ctx, key, keylen, - HWAES_set_encrypt_key, HWAES_encrypt, NULL, NULL); - } -#endif + AES_HW_CCM_SET_KEY_FN(HWAES_set_encrypt_key, HWAES_encrypt, NULL, NULL); + } else +#endif /* HWAES_CAPABLE */ #ifdef VPAES_CAPABLE - if (VPAES_CAPABLE) { - return ossl_cipher_set_ccm_aes_initkey(ctx, key, keylen, - vpaes_set_encrypt_key, vpaes_encrypt, NULL, NULL); - } + if (VPAES_CAPABLE) { + AES_HW_CCM_SET_KEY_FN(vpaes_set_encrypt_key, vpaes_encrypt, NULL, NULL); + } else #endif - - return ossl_cipher_set_ccm_aes_initkey(ctx, key, keylen, - AES_set_encrypt_key, AES_encrypt, NULL, NULL); + { + AES_HW_CCM_SET_KEY_FN(AES_set_encrypt_key, AES_encrypt, NULL, NULL) + } + return 1; } static const PROV_CCM_HW aes_ccm = { @@ -69,21 +56,19 @@ static const PROV_CCM_HW aes_ccm = { ossl_ccm_generic_gettag }; +#if defined(S390X_aes_128_CAPABLE) +#include "cipher_aes_ccm_hw_s390x.inc" +#elif defined(AESNI_CAPABLE) +#include "cipher_aes_ccm_hw_aesni.inc" +#elif defined(SPARC_AES_CAPABLE) +#include "cipher_aes_ccm_hw_t4.inc" +#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 +#include "cipher_aes_ccm_hw_rv64i.inc" +#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 32 +#include "cipher_aes_ccm_hw_rv32i.inc" +#else const PROV_CCM_HW *ossl_prov_aes_hw_ccm(size_t keybits) { - const PROV_CCM_HW *aes_ccm_hw = NULL; -#if defined(AESNI_CAPABLE) - aes_ccm_hw = ossl_prov_aes_hw_ccm_aesni(); -#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 32 - aes_ccm_hw = ossl_prov_aes_hw_ccm_rv32i(); -#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 - aes_ccm_hw = ossl_prov_aes_hw_ccm_rv64i(); -#elif defined(S390X_aes_128_CAPABLE) - aes_ccm_hw = ossl_prov_aes_hw_ccm_s390x(keybits); -#elif defined(SPARC_AES_CAPABLE) - aes_ccm_hw = ossl_prov_aes_hw_ccm_t4(); -#endif - if (aes_ccm_hw != NULL) - return aes_ccm_hw; return &aes_ccm; } +#endif diff --git a/providers/implementations/ciphers/cipher_aes_ccm_hw_aesni.inc b/providers/implementations/ciphers/cipher_aes_ccm_hw_aesni.inc new file mode 100644 index 0000000000..579e5a3d4f --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_ccm_hw_aesni.inc @@ -0,0 +1,38 @@ +/* + * Copyright 2001-2021 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * AES-NI support for AES CCM. + * This file is included by cipher_aes_ccm_hw.c + */ + +static int ccm_aesni_initkey(PROV_CCM_CTX *ctx, const unsigned char *key, + size_t keylen) +{ + PROV_AES_CCM_CTX *actx = (PROV_AES_CCM_CTX *)ctx; + + AES_HW_CCM_SET_KEY_FN(aesni_set_encrypt_key, aesni_encrypt, + aesni_ccm64_encrypt_blocks, + aesni_ccm64_decrypt_blocks); + return 1; +} + +static const PROV_CCM_HW aesni_ccm = { + ccm_aesni_initkey, + ossl_ccm_generic_setiv, + ossl_ccm_generic_setaad, + ossl_ccm_generic_auth_encrypt, + ossl_ccm_generic_auth_decrypt, + ossl_ccm_generic_gettag +}; + +const PROV_CCM_HW *ossl_prov_aes_hw_ccm(size_t keybits) +{ + return AESNI_CAPABLE ? &aesni_ccm : &aes_ccm; +} diff --git a/providers/implementations/ciphers/cipher_aes_ccm_hw_rv32i.inc b/providers/implementations/ciphers/cipher_aes_ccm_hw_rv32i.inc new file mode 100644 index 0000000000..7cfe0fc4ce --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_ccm_hw_rv32i.inc @@ -0,0 +1,60 @@ +/* + * Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * RISC-V 32 ZKND ZKNE support for AES CCM. + * This file is included by cipher_aes_ccm_hw.c + */ + +static int ccm_rv32i_zknd_zkne_initkey(PROV_CCM_CTX *ctx, const unsigned char *key, + size_t keylen) +{ + PROV_AES_CCM_CTX *actx = (PROV_AES_CCM_CTX *)ctx; + + AES_HW_CCM_SET_KEY_FN(rv32i_zkne_set_encrypt_key, rv32i_zkne_encrypt, + NULL, NULL); + return 1; +} + +static int ccm_rv32i_zbkb_zknd_zkne_initkey(PROV_CCM_CTX *ctx, const unsigned char *key, + size_t keylen) +{ + PROV_AES_CCM_CTX *actx = (PROV_AES_CCM_CTX *)ctx; + + AES_HW_CCM_SET_KEY_FN(rv32i_zbkb_zkne_set_encrypt_key, rv32i_zkne_encrypt, + NULL, NULL); + return 1; +} + +static const PROV_CCM_HW rv32i_zknd_zkne_ccm = { + ccm_rv32i_zknd_zkne_initkey, + ossl_ccm_generic_setiv, + ossl_ccm_generic_setaad, + ossl_ccm_generic_auth_encrypt, + ossl_ccm_generic_auth_decrypt, + ossl_ccm_generic_gettag +}; + +static const PROV_CCM_HW rv32i_zbkb_zknd_zkne_ccm = { + ccm_rv32i_zbkb_zknd_zkne_initkey, + ossl_ccm_generic_setiv, + ossl_ccm_generic_setaad, + ossl_ccm_generic_auth_encrypt, + ossl_ccm_generic_auth_decrypt, + ossl_ccm_generic_gettag +}; + +const PROV_CCM_HW *ossl_prov_aes_hw_ccm(size_t keybits) +{ + if (RISCV_HAS_ZBKB_AND_ZKND_AND_ZKNE()) + return &rv32i_zbkb_zknd_zkne_ccm; + if (RISCV_HAS_ZKND_AND_ZKNE()) + return &rv32i_zknd_zkne_ccm; + return &aes_ccm; +} diff --git a/providers/implementations/ciphers/cipher_aes_ccm_hw_rv64i.inc b/providers/implementations/ciphers/cipher_aes_ccm_hw_rv64i.inc new file mode 100644 index 0000000000..f2353bb3b8 --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_ccm_hw_rv64i.inc @@ -0,0 +1,71 @@ +/* + * Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * RISC-V 64 ZKND ZKNE support for AES CCM. + * This file is included by cipher_aes_ccm_hw.c + */ + +static int ccm_rv64i_zknd_zkne_initkey(PROV_CCM_CTX *ctx, const unsigned char *key, + size_t keylen) +{ + PROV_AES_CCM_CTX *actx = (PROV_AES_CCM_CTX *)ctx; + + AES_HW_CCM_SET_KEY_FN(rv64i_zkne_set_encrypt_key, rv64i_zkne_encrypt, + NULL, NULL); + return 1; +} + +static const PROV_CCM_HW rv64i_zknd_zkne_ccm = { + ccm_rv64i_zknd_zkne_initkey, + ossl_ccm_generic_setiv, + ossl_ccm_generic_setaad, + ossl_ccm_generic_auth_encrypt, + ossl_ccm_generic_auth_decrypt, + ossl_ccm_generic_gettag +}; + +/*- + * RISC-V RV64 ZVKNED support for AES CCM. + * This file is included by cipher_aes_ccm_hw.c + */ + +static int ccm_rv64i_zvkned_initkey(PROV_CCM_CTX *ctx, const unsigned char *key, + size_t keylen) +{ + PROV_AES_CCM_CTX *actx = (PROV_AES_CCM_CTX *)ctx; + + /* Zvkned only supports 128 and 256 bit keys for key schedule generation. */ + if (keylen * 8 == 128 || keylen * 8 == 256) { + AES_HW_CCM_SET_KEY_FN(rv64i_zvkned_set_encrypt_key, rv64i_zvkned_encrypt, + NULL, NULL); + } else { + AES_HW_CCM_SET_KEY_FN(AES_set_encrypt_key, rv64i_zvkned_encrypt, NULL, NULL) + } + return 1; +} + +static const PROV_CCM_HW rv64i_zvkned_ccm = { + ccm_rv64i_zvkned_initkey, + ossl_ccm_generic_setiv, + ossl_ccm_generic_setaad, + ossl_ccm_generic_auth_encrypt, + ossl_ccm_generic_auth_decrypt, + ossl_ccm_generic_gettag +}; + +const PROV_CCM_HW *ossl_prov_aes_hw_ccm(size_t keybits) +{ + if (RISCV_HAS_ZVKNED() && riscv_vlen() >= 128) + return &rv64i_zvkned_ccm; + else if (RISCV_HAS_ZKND_AND_ZKNE()) + return &rv64i_zknd_zkne_ccm; + else + return &aes_ccm; +} diff --git a/providers/implementations/ciphers/cipher_aes_ccm_hw_s390x.inc b/providers/implementations/ciphers/cipher_aes_ccm_hw_s390x.inc new file mode 100644 index 0000000000..7253f03a7e --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_ccm_hw_s390x.inc @@ -0,0 +1,268 @@ +/* + * Copyright 2001-2020 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * S390X support for AES CCM. + * This file is included by cipher_aes_ccm_hw.c + */ + +#define S390X_CCM_AAD_FLAG 0x40 + +static int s390x_aes_ccm_initkey(PROV_CCM_CTX *ctx, + const unsigned char *key, size_t keylen) +{ + PROV_AES_CCM_CTX *sctx = (PROV_AES_CCM_CTX *)ctx; + + sctx->ccm.s390x.fc = S390X_AES_FC(keylen); + memcpy(&sctx->ccm.s390x.kmac.k, key, keylen); + /* Store encoded m and l. */ + sctx->ccm.s390x.nonce.b[0] = ((ctx->l - 1) & 0x7) + | (((ctx->m - 2) >> 1) & 0x7) << 3; + memset(sctx->ccm.s390x.nonce.b + 1, 0, sizeof(sctx->ccm.s390x.nonce.b)); + sctx->ccm.s390x.blocks = 0; + ctx->key_set = 1; + return 1; +} + +static int s390x_aes_ccm_setiv(PROV_CCM_CTX *ctx, + const unsigned char *nonce, size_t noncelen, + size_t mlen) +{ + PROV_AES_CCM_CTX *sctx = (PROV_AES_CCM_CTX *)ctx; + + sctx->ccm.s390x.nonce.b[0] &= ~S390X_CCM_AAD_FLAG; + sctx->ccm.s390x.nonce.g[1] = mlen; + memcpy(sctx->ccm.s390x.nonce.b + 1, nonce, 15 - ctx->l); + return 1; +} + +/*- + * Process additional authenticated data. Code is big-endian. + */ +static int s390x_aes_ccm_setaad(PROV_CCM_CTX *ctx, + const unsigned char *aad, size_t alen) +{ + PROV_AES_CCM_CTX *sctx = (PROV_AES_CCM_CTX *)ctx; + unsigned char *ptr; + int i, rem; + + if (!alen) + return 1; + + sctx->ccm.s390x.nonce.b[0] |= S390X_CCM_AAD_FLAG; + + /* Suppress 'type-punned pointer dereference' warning. */ + ptr = sctx->ccm.s390x.buf.b; + + if (alen < ((1 << 16) - (1 << 8))) { + *(uint16_t *)ptr = alen; + i = 2; + } else if (sizeof(alen) == 8 + && alen >= (size_t)1 << (32 % (sizeof(alen) * 8))) { + *(uint16_t *)ptr = 0xffff; + *(uint64_t *)(ptr + 2) = alen; + i = 10; + } else { + *(uint16_t *)ptr = 0xfffe; + *(uint32_t *)(ptr + 2) = alen; + i = 6; + } + + while (i < 16 && alen) { + sctx->ccm.s390x.buf.b[i] = *aad; + ++aad; + --alen; + ++i; + } + while (i < 16) { + sctx->ccm.s390x.buf.b[i] = 0; + ++i; + } + + sctx->ccm.s390x.kmac.icv.g[0] = 0; + sctx->ccm.s390x.kmac.icv.g[1] = 0; + s390x_kmac(sctx->ccm.s390x.nonce.b, 32, sctx->ccm.s390x.fc, + &sctx->ccm.s390x.kmac); + sctx->ccm.s390x.blocks += 2; + + rem = alen & 0xf; + alen &= ~(size_t)0xf; + if (alen) { + s390x_kmac(aad, alen, sctx->ccm.s390x.fc, &sctx->ccm.s390x.kmac); + sctx->ccm.s390x.blocks += alen >> 4; + aad += alen; + } + if (rem) { + for (i = 0; i < rem; i++) + sctx->ccm.s390x.kmac.icv.b[i] ^= aad[i]; + + s390x_km(sctx->ccm.s390x.kmac.icv.b, 16, + sctx->ccm.s390x.kmac.icv.b, sctx->ccm.s390x.fc, + sctx->ccm.s390x.kmac.k); + sctx->ccm.s390x.blocks++; + } + return 1; +} + +/*- + * En/de-crypt plain/cipher-text. Compute tag from plaintext. Returns 1 for + * success. + */ +static int s390x_aes_ccm_auth_encdec(PROV_CCM_CTX *ctx, + const unsigned char *in, + unsigned char *out, size_t len, int enc) +{ + PROV_AES_CCM_CTX *sctx = (PROV_AES_CCM_CTX *)ctx; + size_t n, rem; + unsigned int i, l, num; + unsigned char flags; + + flags = sctx->ccm.s390x.nonce.b[0]; + if (!(flags & S390X_CCM_AAD_FLAG)) { + s390x_km(sctx->ccm.s390x.nonce.b, 16, sctx->ccm.s390x.kmac.icv.b, + sctx->ccm.s390x.fc, sctx->ccm.s390x.kmac.k); + sctx->ccm.s390x.blocks++; + } + l = flags & 0x7; + sctx->ccm.s390x.nonce.b[0] = l; + + /*- + * Reconstruct length from encoded length field + * and initialize it with counter value. + */ + n = 0; + for (i = 15 - l; i < 15; i++) { + n |= sctx->ccm.s390x.nonce.b[i]; + sctx->ccm.s390x.nonce.b[i] = 0; + n <<= 8; + } + n |= sctx->ccm.s390x.nonce.b[15]; + sctx->ccm.s390x.nonce.b[15] = 1; + + if (n != len) + return 0; /* length mismatch */ + + if (enc) { + /* Two operations per block plus one for tag encryption */ + sctx->ccm.s390x.blocks += (((len + 15) >> 4) << 1) + 1; + if (sctx->ccm.s390x.blocks > (1ULL << 61)) + return 0; /* too much data */ + } + + num = 0; + rem = len & 0xf; + len &= ~(size_t)0xf; + + if (enc) { + /* mac-then-encrypt */ + if (len) + s390x_kmac(in, len, sctx->ccm.s390x.fc, &sctx->ccm.s390x.kmac); + if (rem) { + for (i = 0; i < rem; i++) + sctx->ccm.s390x.kmac.icv.b[i] ^= in[len + i]; + + s390x_km(sctx->ccm.s390x.kmac.icv.b, 16, + sctx->ccm.s390x.kmac.icv.b, + sctx->ccm.s390x.fc, sctx->ccm.s390x.kmac.k); + } + + CRYPTO_ctr128_encrypt_ctr32(in, out, len + rem, &sctx->ccm.ks.ks, + sctx->ccm.s390x.nonce.b, sctx->ccm.s390x.buf.b, + &num, (ctr128_f)AES_ctr32_encrypt); + } else { + /* decrypt-then-mac */ + CRYPTO_ctr128_encrypt_ctr32(in, out, len + rem, &sctx->ccm.ks.ks, + sctx->ccm.s390x.nonce.b, sctx->ccm.s390x.buf.b, + &num, (ctr128_f)AES_ctr32_encrypt); + + if (len) + s390x_kmac(out, len, sctx->ccm.s390x.fc, &sctx->ccm.s390x.kmac); + if (rem) { + for (i = 0; i < rem; i++) + sctx->ccm.s390x.kmac.icv.b[i] ^= out[len + i]; + + s390x_km(sctx->ccm.s390x.kmac.icv.b, 16, + sctx->ccm.s390x.kmac.icv.b, + sctx->ccm.s390x.fc, sctx->ccm.s390x.kmac.k); + } + } + /* encrypt tag */ + for (i = 15 - l; i < 16; i++) + sctx->ccm.s390x.nonce.b[i] = 0; + + s390x_km(sctx->ccm.s390x.nonce.b, 16, sctx->ccm.s390x.buf.b, + sctx->ccm.s390x.fc, sctx->ccm.s390x.kmac.k); + sctx->ccm.s390x.kmac.icv.g[0] ^= sctx->ccm.s390x.buf.g[0]; + sctx->ccm.s390x.kmac.icv.g[1] ^= sctx->ccm.s390x.buf.g[1]; + + sctx->ccm.s390x.nonce.b[0] = flags; /* restore flags field */ + return 1; +} + + +static int s390x_aes_ccm_gettag(PROV_CCM_CTX *ctx, + unsigned char *tag, size_t tlen) +{ + PROV_AES_CCM_CTX *sctx = (PROV_AES_CCM_CTX *)ctx; + + if (tlen > ctx->m) + return 0; + memcpy(tag, sctx->ccm.s390x.kmac.icv.b, tlen); + return 1; +} + +static int s390x_aes_ccm_auth_encrypt(PROV_CCM_CTX *ctx, + const unsigned char *in, + unsigned char *out, size_t len, + unsigned char *tag, size_t taglen) +{ + int rv; + + rv = s390x_aes_ccm_auth_encdec(ctx, in, out, len, 1); + if (rv && tag != NULL) + rv = s390x_aes_ccm_gettag(ctx, tag, taglen); + return rv; +} + +static int s390x_aes_ccm_auth_decrypt(PROV_CCM_CTX *ctx, + const unsigned char *in, + unsigned char *out, size_t len, + unsigned char *expected_tag, + size_t taglen) +{ + int rv = 0; + PROV_AES_CCM_CTX *sctx = (PROV_AES_CCM_CTX *)ctx; + + rv = s390x_aes_ccm_auth_encdec(ctx, in, out, len, 0); + if (rv) { + if (CRYPTO_memcmp(sctx->ccm.s390x.kmac.icv.b, expected_tag, ctx->m) != 0) + rv = 0; + } + if (rv == 0) + OPENSSL_cleanse(out, len); + return rv; +} + +static const PROV_CCM_HW s390x_aes_ccm = { + s390x_aes_ccm_initkey, + s390x_aes_ccm_setiv, + s390x_aes_ccm_setaad, + s390x_aes_ccm_auth_encrypt, + s390x_aes_ccm_auth_decrypt, + s390x_aes_ccm_gettag +}; + +const PROV_CCM_HW *ossl_prov_aes_hw_ccm(size_t keybits) +{ + if ((keybits == 128 && S390X_aes_128_ccm_CAPABLE) + || (keybits == 192 && S390X_aes_192_ccm_CAPABLE) + || (keybits == 256 && S390X_aes_256_ccm_CAPABLE)) + return &s390x_aes_ccm; + return &aes_ccm; +} diff --git a/providers/implementations/ciphers/cipher_aes_ccm_hw_t4.inc b/providers/implementations/ciphers/cipher_aes_ccm_hw_t4.inc new file mode 100644 index 0000000000..a676d411b5 --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_ccm_hw_t4.inc @@ -0,0 +1,36 @@ +/* + * Copyright 2001-2021 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * Fujitsu SPARC64 X support for AES CCM. + * This file is included by cipher_aes_ccm_hw.c + */ + +static int ccm_t4_aes_initkey(PROV_CCM_CTX *ctx, const unsigned char *key, + size_t keylen) +{ + PROV_AES_CCM_CTX *actx = (PROV_AES_CCM_CTX *)ctx; + + AES_HW_CCM_SET_KEY_FN(aes_t4_set_encrypt_key, aes_t4_encrypt, NULL, NULL); + return 1; +} + +static const PROV_CCM_HW t4_aes_ccm = { + ccm_t4_aes_initkey, + ossl_ccm_generic_setiv, + ossl_ccm_generic_setaad, + ossl_ccm_generic_auth_encrypt, + ossl_ccm_generic_auth_decrypt, + ossl_ccm_generic_gettag +}; + +const PROV_CCM_HW *ossl_prov_aes_hw_ccm(size_t keybits) +{ + return SPARC_AES_CAPABLE ? &t4_aes_ccm : &aes_ccm; +} diff --git a/providers/implementations/ciphers/cipher_aes_cfb.h b/providers/implementations/ciphers/cipher_aes_cfb.h new file mode 100644 index 0000000000..7e05c78b7a --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_cfb.h @@ -0,0 +1,16 @@ +/* + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +#include "prov/ciphercommon.h" + +#define ossl_prov_cipher_hw_aes_cfb ossl_prov_cipher_hw_aes_cfb128 + +const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_cfb128(size_t keybits); +const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_cfb1(size_t keybits); +const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_cfb8(size_t keybits); diff --git a/providers/implementations/ciphers/cipher_aes_cfb_hw.c b/providers/implementations/ciphers/cipher_aes_cfb_hw.c new file mode 100644 index 0000000000..a0399bcdc2 --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_cfb_hw.c @@ -0,0 +1,98 @@ +/* + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/* + * This file uses the low level AES functions (which are deprecated for + * non-internal use) in order to implement provider AES ciphers. + */ +#include "internal/deprecated.h" + +#include +#include "cipher_aes.h" +#include "cipher_aes_cfb.h" + +static int cipher_hw_aes_initkey(PROV_CIPHER_CTX *dat, + const unsigned char *key, size_t keylen) +{ + int ret; + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + AES_KEY *ks = &adat->ks.ks; + + dat->ks = ks; + +#ifdef HWAES_CAPABLE + if (HWAES_CAPABLE) { + ret = HWAES_set_encrypt_key(key, (int)(keylen * 8), ks); + dat->block = (block128_f)HWAES_encrypt; + dat->stream.cbc = NULL; + } else { +#endif +#ifdef VPAES_CAPABLE + if (VPAES_CAPABLE) { + ret = vpaes_set_encrypt_key(key, (int)(keylen * 8), ks); + dat->block = (block128_f)vpaes_encrypt; + dat->stream.cbc = NULL; + } else { +#endif + { + ret = AES_set_encrypt_key(key, (int)(keylen * 8), ks); + dat->block = (block128_f)AES_encrypt; + dat->stream.cbc = NULL; + } +#ifdef VPAES_CAPABLE + } +#endif +#ifdef HWAES_CAPABLE + } +#endif + + if (ret < 0) { + ERR_raise(ERR_LIB_PROV, PROV_R_KEY_SETUP_FAILED); + return 0; + } + + return 1; +} + +IMPLEMENT_CIPHER_HW_COPYCTX(cipher_hw_aes_copyctx, PROV_AES_CTX) + +#define PROV_CIPHER_HW_aes_mode(mode) \ + static const PROV_CIPHER_HW aes_##mode = { \ + cipher_hw_aes_initkey, \ + ossl_cipher_hw_generic_##mode, \ + cipher_hw_aes_copyctx \ + }; \ + PROV_CIPHER_HW_declare(mode) \ + const PROV_CIPHER_HW * \ + ossl_prov_cipher_hw_aes_##mode(size_t keybits) \ + { \ + PROV_CIPHER_HW_select(mode) return &aes_##mode; \ + } + +#if defined(AESNI_CAPABLE) +#include "cipher_aes_cfb_hw_aesni.inc" +#elif defined(SPARC_AES_CAPABLE) +#include "cipher_aes_hw_t4.inc" +#elif defined(S390X_aes_128_CAPABLE) +#include "cipher_aes_cfb_hw_s390x.inc" +#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 +#include "cipher_aes_hw_rv64i.inc" +#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 32 +#include "cipher_aes_hw_rv32i.inc" +#elif defined(ARMv8_HWAES_CAPABLE) +#include "cipher_aes_hw_armv8.inc" +#else +/* The generic case */ +#define PROV_CIPHER_HW_declare(mode) +#define PROV_CIPHER_HW_select(mode) +#endif + +PROV_CIPHER_HW_aes_mode(cfb128) + PROV_CIPHER_HW_aes_mode(cfb1) + PROV_CIPHER_HW_aes_mode(cfb8) diff --git a/providers/implementations/ciphers/cipher_aes_cfb_hw_aesni.inc b/providers/implementations/ciphers/cipher_aes_cfb_hw_aesni.inc new file mode 100644 index 0000000000..eb8e0164ac --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_cfb_hw_aesni.inc @@ -0,0 +1,101 @@ +/* + * Copyright 2001-2025 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * AES-NI and VAES support for AES CFB mode. + * This file is included by cipher_aes_cfb_hw.c + */ + +#if (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)) + #define cipher_hw_vaes_cfb128 aes_cfb128_vaes_encdec_wrapper +#else + #define cipher_hw_vaes_cfb128 ossl_cipher_hw_generic_cfb128 + int ossl_aes_cfb128_vaes_eligible() { + return 0; + } +#endif +#define cipher_hw_vaes_cfb8 ossl_cipher_hw_generic_cfb8 +#define cipher_hw_vaes_cfb1 ossl_cipher_hw_generic_cfb1 + +#define cipher_hw_aesni_cfb128 ossl_cipher_hw_generic_cfb128 +#define cipher_hw_aesni_cfb8 ossl_cipher_hw_generic_cfb8 +#define cipher_hw_aesni_cfb1 ossl_cipher_hw_generic_cfb1 + +static int ossl_aes_cfb8_vaes_eligible(void) { return 0; } +static int ossl_aes_cfb1_vaes_eligible(void) { return 0; } + +#if (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)) +/* active in 64-bit builds when AES-NI, AVX512F, and VAES are detected */ +static int aes_cfb128_vaes_encdec_wrapper( + PROV_CIPHER_CTX* dat, + unsigned char *out, + const unsigned char *in, + size_t len) +{ + ossl_ssize_t num; + + num = (ossl_ssize_t)dat->num; + + if (num < 0) { + /* behavior from CRYPTO_cfb128_encrypt */ + dat->num = -1; + return 1; + } + + if (dat->enc) + ossl_aes_cfb128_vaes_enc(in, out, len, dat->ks, dat->iv, &num); + else + ossl_aes_cfb128_vaes_dec(in, out, len, dat->ks, dat->iv, &num); + + dat->num = (int)num; + + return 1; +} +#endif + +/* generates AES round keys for AES-NI and VAES implementations */ +static int cipher_hw_aesni_initkey(PROV_CIPHER_CTX *dat, + const unsigned char *key, size_t keylen) +{ + int ret; + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + AES_KEY *ks = &adat->ks.ks; + + dat->ks = ks; + + ret = aesni_set_encrypt_key(key, (int)(keylen * 8), ks); + + dat->block = (block128_f) aesni_encrypt; + dat->stream.cbc = NULL; + + if (ret < 0) { + ERR_raise(ERR_LIB_PROV, PROV_R_KEY_SETUP_FAILED); + return 0; + } + + return 1; +} + +#define PROV_CIPHER_HW_declare(mode) \ +static const PROV_CIPHER_HW aesni_##mode = { \ + cipher_hw_aesni_initkey, \ + cipher_hw_aesni_##mode, \ + cipher_hw_aes_copyctx \ +}; \ +static const PROV_CIPHER_HW vaes_##mode = { \ + cipher_hw_aesni_initkey, \ + cipher_hw_vaes_##mode, \ + cipher_hw_aes_copyctx \ +}; +#define PROV_CIPHER_HW_select(mode) \ +if (AESNI_CAPABLE) { \ + if (ossl_aes_##mode##_vaes_eligible()) \ + return &vaes_##mode; \ + return &aesni_##mode; \ +} diff --git a/providers/implementations/ciphers/cipher_aes_cfb_hw_s390x.inc b/providers/implementations/ciphers/cipher_aes_cfb_hw_s390x.inc new file mode 100644 index 0000000000..98d60809c4 --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_cfb_hw_s390x.inc @@ -0,0 +1,122 @@ +/* + * Copyright 2001-2025 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/* + * IBM S390X support for AES mode cfb. + * This file is included by cipher_aes_cfb_hw.c + */ + +#include "s390x_arch.h" + +#include + +#define s390x_aes_cfb1_initkey cipher_hw_aes_initkey +#define s390x_aes_cfb1_cipher_hw ossl_cipher_hw_generic_cfb1 + +#define S390X_aes_128_cfb128_CAPABLE S390X_aes_128_cfb_CAPABLE +#define S390X_aes_192_cfb128_CAPABLE S390X_aes_192_cfb_CAPABLE +#define S390X_aes_256_cfb128_CAPABLE S390X_aes_256_cfb_CAPABLE + +static int s390x_aes_cfb128_initkey(PROV_CIPHER_CTX *dat, + const unsigned char *key, size_t keylen) +{ + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + + adat->plat.s390x.fc = S390X_AES_FC(keylen); + adat->plat.s390x.fc |= 16 << 24; /* 16 bytes cipher feedback */ + memcpy(adat->plat.s390x.param.kmo_kmf.k, key, keylen); + return 1; +} + +static int s390x_aes_cfb128_cipher_hw(PROV_CIPHER_CTX *dat, unsigned char *out, + const unsigned char *in, size_t len) +{ + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + unsigned int modifier = adat->base.enc ? 0 : S390X_DECRYPT; + int n = dat->num; + int rem; + unsigned char tmp; + + memcpy(adat->plat.s390x.param.kmo_kmf.cv, dat->iv, dat->ivlen); + while (n && len) { + tmp = *in; + *out = adat->plat.s390x.param.kmo_kmf.cv[n] ^ tmp; + adat->plat.s390x.param.kmo_kmf.cv[n] = dat->enc ? *out : tmp; + n = (n + 1) & 0xf; + --len; + ++in; + ++out; + } + + rem = len & 0xf; + + len &= ~(size_t)0xf; + if (len) { + s390x_kmf(in, len, out, adat->plat.s390x.fc | modifier, + &adat->plat.s390x.param.kmo_kmf); + + out += len; + in += len; + } + + if (rem) { + s390x_km(adat->plat.s390x.param.kmo_kmf.cv, 16, + adat->plat.s390x.param.kmo_kmf.cv, + S390X_AES_FC(dat->keylen), + adat->plat.s390x.param.kmo_kmf.k); + + while (rem--) { + tmp = in[n]; + out[n] = adat->plat.s390x.param.kmo_kmf.cv[n] ^ tmp; + adat->plat.s390x.param.kmo_kmf.cv[n] = dat->enc ? out[n] : tmp; + ++n; + } + } + + memcpy(dat->iv, adat->plat.s390x.param.kmo_kmf.cv, dat->ivlen); + dat->num = n; + return 1; +} + +static int s390x_aes_cfb8_initkey(PROV_CIPHER_CTX *dat, + const unsigned char *key, size_t keylen) +{ + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + + adat->plat.s390x.fc = S390X_AES_FC(keylen); + adat->plat.s390x.fc |= 1 << 24; /* 1 byte cipher feedback */ + memcpy(adat->plat.s390x.param.kmo_kmf.k, key, keylen); + return 1; +} + +static int s390x_aes_cfb8_cipher_hw(PROV_CIPHER_CTX *dat, unsigned char *out, + const unsigned char *in, size_t len) +{ + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + unsigned int modifier = adat->base.enc ? 0 : S390X_DECRYPT; + + memcpy(adat->plat.s390x.param.kmo_kmf.cv, dat->iv, dat->ivlen); + s390x_kmf(in, len, out, adat->plat.s390x.fc | modifier, + &adat->plat.s390x.param.kmo_kmf); + memcpy(dat->iv, adat->plat.s390x.param.kmo_kmf.cv, dat->ivlen); + return 1; +} + +#define PROV_CIPHER_HW_declare(mode) \ +static const PROV_CIPHER_HW s390x_aes_##mode = { \ + s390x_aes_##mode##_initkey, \ + s390x_aes_##mode##_cipher_hw, \ + cipher_hw_aes_copyctx \ +}; +#define PROV_CIPHER_HW_select(mode) \ +if ((keybits == 128 && S390X_aes_128_##mode##_CAPABLE) \ + || (keybits == 192 && S390X_aes_192_##mode##_CAPABLE) \ + || (keybits == 256 && S390X_aes_256_##mode##_CAPABLE)) \ + return &s390x_aes_##mode; + diff --git a/providers/implementations/ciphers/cipher_aes_gcm.c b/providers/implementations/ciphers/cipher_aes_gcm.c index a83b39b421..0a813de47a 100644 --- a/providers/implementations/ciphers/cipher_aes_gcm.c +++ b/providers/implementations/ciphers/cipher_aes_gcm.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -24,7 +24,9 @@ static void *aes_gcm_newctx(void *provctx, size_t keybits) { PROV_AES_GCM_CTX *ctx; - CIPHER_PROV_CHECK(provctx, AES_256_GCM); + if (!ossl_prov_is_running()) + return NULL; + ctx = OPENSSL_zalloc(sizeof(*ctx)); if (ctx != NULL) ossl_gcm_initctx(provctx, &ctx->base, keybits, diff --git a/providers/implementations/ciphers/cipher_aes_gcm.h b/providers/implementations/ciphers/cipher_aes_gcm.h index b041248b3c..0cd1d5a1ad 100644 --- a/providers/implementations/ciphers/cipher_aes_gcm.h +++ b/providers/implementations/ciphers/cipher_aes_gcm.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_GCM_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_GCM_H - #include #include "prov/ciphercommon.h" #include "prov/ciphercommon_gcm.h" @@ -45,34 +42,4 @@ typedef struct prov_aes_gcm_ctx_st { } plat; } PROV_AES_GCM_CTX; -int ossl_aes_gcm_hw_initkey(PROV_GCM_CTX *ctx, const unsigned char *key, - size_t keylen, aes_set_encrypt_key_fn fn_set_key, - aes_block128_f fn_block, ctr128_f fn_ctr); - -int ossl_generic_aes_gcm_cipher_update(PROV_GCM_CTX *ctx, - const unsigned char *in, size_t len, unsigned char *out); - const PROV_GCM_HW *ossl_prov_aes_hw_gcm(size_t keybits); -#if defined(AESNI_CAPABLE) -const PROV_GCM_HW *ossl_prov_aes_hw_gcm_aesni(void); -#endif -#if defined(AES_PMULL_CAPABLE) && defined(AES_GCM_ASM) -const PROV_GCM_HW *ossl_prov_aes_hw_gcm_armv8(void); -#endif -#if defined(PPC_AES_GCM_CAPABLE) && defined(_ARCH_PPC64) -const PROV_GCM_HW *ossl_prov_aes_hw_gcm_ppc(size_t keybits); -#endif -#if defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 32 -const PROV_GCM_HW *ossl_prov_aes_hw_gcm_rv32i(void); -#endif -#if defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 -const PROV_GCM_HW *ossl_prov_aes_hw_gcm_rv64i(void); -#endif -#if defined(S390X_aes_128_CAPABLE) -const PROV_GCM_HW *ossl_prov_aes_hw_gcm_s390x(size_t keybits); -#endif -#if defined(SPARC_AES_CAPABLE) -const PROV_GCM_HW *ossl_prov_aes_hw_gcm_t4(void); -#endif - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_GCM_H) */ diff --git a/providers/implementations/ciphers/cipher_aes_gcm_hw.c b/providers/implementations/ciphers/cipher_aes_gcm_hw.c index bbb7e21c31..d2b7437cde 100644 --- a/providers/implementations/ciphers/cipher_aes_gcm_hw.c +++ b/providers/implementations/ciphers/cipher_aes_gcm_hw.c @@ -14,71 +14,52 @@ * non-internal use) in order to implement provider AES ciphers. */ #include "internal/deprecated.h" -#include + #include "cipher_aes_gcm.h" -int ossl_aes_gcm_hw_initkey(PROV_GCM_CTX *ctx, const unsigned char *key, - size_t keylen, aes_set_encrypt_key_fn fn_set_key, - aes_block128_f fn_block, ctr128_f fn_ctr) -{ - PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; - AES_KEY *ks = &actx->ks.ks; - - int ret = fn_set_key(key, (int)(keylen * 8), ks); - if (ret < 0) { - ERR_raise(ERR_LIB_PROV, PROV_R_KEY_SETUP_FAILED); - return 0; - } - - CRYPTO_gcm128_init(&ctx->gcm, ks, (block128_f)fn_block); - ctx->ctr = fn_ctr; - ctx->key_set = 1; - - return 1; -} - static int aes_gcm_initkey(PROV_GCM_CTX *ctx, const unsigned char *key, size_t keylen) { + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + AES_KEY *ks = &actx->ks.ks; + #ifdef HWAES_CAPABLE if (HWAES_CAPABLE) { #ifdef HWAES_ctr32_encrypt_blocks - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, HWAES_set_encrypt_key, - HWAES_encrypt, HWAES_ctr32_encrypt_blocks); + GCM_HW_SET_KEY_CTR_FN(ks, HWAES_set_encrypt_key, HWAES_encrypt, + HWAES_ctr32_encrypt_blocks); #else - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, HWAES_set_encrypt_key, - HWAES_encrypt, NULL); + GCM_HW_SET_KEY_CTR_FN(ks, HWAES_set_encrypt_key, HWAES_encrypt, NULL); #endif /* HWAES_ctr32_encrypt_blocks */ } else #endif /* HWAES_CAPABLE */ #ifdef BSAES_CAPABLE if (BSAES_CAPABLE) { - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, AES_set_encrypt_key, - AES_encrypt, (ctr128_f)ossl_bsaes_ctr32_encrypt_blocks); + GCM_HW_SET_KEY_CTR_FN(ks, AES_set_encrypt_key, AES_encrypt, + ossl_bsaes_ctr32_encrypt_blocks); } else #endif /* BSAES_CAPABLE */ #ifdef VPAES_CAPABLE if (VPAES_CAPABLE) { - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, vpaes_set_encrypt_key, - vpaes_encrypt, NULL); + GCM_HW_SET_KEY_CTR_FN(ks, vpaes_set_encrypt_key, vpaes_encrypt, NULL); } else #endif /* VPAES_CAPABLE */ { #ifdef AES_CTR_ASM - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, AES_set_encrypt_key, - AES_encrypt, (ctr128_f)AES_ctr32_encrypt); + GCM_HW_SET_KEY_CTR_FN(ks, AES_set_encrypt_key, AES_encrypt, + AES_ctr32_encrypt); #else - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, AES_set_encrypt_key, - AES_encrypt, NULL); + GCM_HW_SET_KEY_CTR_FN(ks, AES_set_encrypt_key, AES_encrypt, NULL); #endif /* AES_CTR_ASM */ } + return 1; } -int ossl_generic_aes_gcm_cipher_update(PROV_GCM_CTX *ctx, - const unsigned char *in, size_t len, unsigned char *out) +static int generic_aes_gcm_cipher_update(PROV_GCM_CTX *ctx, const unsigned char *in, + size_t len, unsigned char *out) { if (ctx->enc) { if (ctx->ctr != NULL) { @@ -146,33 +127,28 @@ static const PROV_GCM_HW aes_gcm = { aes_gcm_initkey, ossl_gcm_setiv, ossl_gcm_aad_update, - ossl_generic_aes_gcm_cipher_update, + generic_aes_gcm_cipher_update, ossl_gcm_cipher_final, ossl_gcm_one_shot }; +#if defined(S390X_aes_128_CAPABLE) +#include "cipher_aes_gcm_hw_s390x.inc" +#elif defined(AESNI_CAPABLE) +#include "cipher_aes_gcm_hw_aesni.inc" +#elif defined(SPARC_AES_CAPABLE) +#include "cipher_aes_gcm_hw_t4.inc" +#elif defined(AES_PMULL_CAPABLE) && defined(AES_GCM_ASM) +#include "cipher_aes_gcm_hw_armv8.inc" +#elif defined(PPC_AES_GCM_CAPABLE) && defined(_ARCH_PPC64) +#include "cipher_aes_gcm_hw_ppc.inc" +#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 +#include "cipher_aes_gcm_hw_rv64i.inc" +#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 32 +#include "cipher_aes_gcm_hw_rv32i.inc" +#else const PROV_GCM_HW *ossl_prov_aes_hw_gcm(size_t keybits) { - const PROV_GCM_HW *aes_gcm_hw = NULL; - -#if defined(AESNI_CAPABLE) - aes_gcm_hw = ossl_prov_aes_hw_gcm_aesni(); -#elif defined(AES_PMULL_CAPABLE) && defined(AES_GCM_ASM) - aes_gcm_hw = ossl_prov_aes_hw_gcm_armv8(); -#elif defined(PPC_AES_GCM_CAPABLE) && defined(_ARCH_PPC64) - aes_gcm_hw = ossl_prov_aes_hw_gcm_ppc(keybits); -#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 32 - aes_gcm_hw = ossl_prov_aes_hw_gcm_rv32i(); -#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 - aes_gcm_hw = ossl_prov_aes_hw_gcm_rv64i(); -#elif defined(S390X_aes_128_CAPABLE) - aes_gcm_hw = ossl_prov_aes_hw_gcm_s390x(keybits); -#elif defined(SPARC_AES_CAPABLE) - aes_gcm_hw = ossl_prov_aes_hw_gcm_t4(); -#endif - - if (aes_gcm_hw == NULL) - aes_gcm_hw = &aes_gcm; - - return aes_gcm_hw; + return &aes_gcm; } +#endif diff --git a/providers/implementations/ciphers/cipher_aes_gcm_hw_aesni.inc b/providers/implementations/ciphers/cipher_aes_gcm_hw_aesni.inc new file mode 100644 index 0000000000..92f41b8cd6 --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_gcm_hw_aesni.inc @@ -0,0 +1,47 @@ +/* + * Copyright 2001-2022 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * AES-NI support for AES GCM. + * This file is included by cipher_aes_gcm_hw.c + */ + +static int aesni_gcm_initkey(PROV_GCM_CTX *ctx, const unsigned char *key, + size_t keylen) +{ + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + AES_KEY *ks = &actx->ks.ks; + GCM_HW_SET_KEY_CTR_FN(ks, aesni_set_encrypt_key, aesni_encrypt, + aesni_ctr32_encrypt_blocks); + return 1; +} + +static const PROV_GCM_HW aesni_gcm = { + aesni_gcm_initkey, + ossl_gcm_setiv, + ossl_gcm_aad_update, + generic_aes_gcm_cipher_update, + ossl_gcm_cipher_final, + ossl_gcm_one_shot +}; + +#include "cipher_aes_gcm_hw_vaes_avx512.inc" + +const PROV_GCM_HW *ossl_prov_aes_hw_gcm(size_t keybits) +{ +#ifdef VAES_GCM_ENABLED + if (ossl_vaes_vpclmulqdq_capable()) + return &vaes_gcm; + else +#endif + if (AESNI_CAPABLE) + return &aesni_gcm; + else + return &aes_gcm; +} diff --git a/providers/implementations/ciphers/cipher_aes_gcm_hw_armv8.inc b/providers/implementations/ciphers/cipher_aes_gcm_hw_armv8.inc new file mode 100644 index 0000000000..60fff493d8 --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_gcm_hw_armv8.inc @@ -0,0 +1,108 @@ +/* + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/* + * Crypto extension support for AES GCM. + * This file is included by cipher_aes_gcm_hw.c + */ + +size_t armv8_aes_gcm_encrypt(const unsigned char *in, unsigned char *out, size_t len, + const void *key, unsigned char ivec[16], u64 *Xi) +{ + AES_KEY *aes_key = (AES_KEY *)key; + size_t align_bytes = len - len % 16; + + switch(aes_key->rounds) { + case 10: + if (IS_CPU_SUPPORT_UNROLL8_EOR3()) { + unroll8_eor3_aes_gcm_enc_128_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); + } else { + aes_gcm_enc_128_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); + } + break; + case 12: + if (IS_CPU_SUPPORT_UNROLL8_EOR3()) { + unroll8_eor3_aes_gcm_enc_192_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); + } else { + aes_gcm_enc_192_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); + } + break; + case 14: + if (IS_CPU_SUPPORT_UNROLL8_EOR3()) { + unroll8_eor3_aes_gcm_enc_256_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); + } else { + aes_gcm_enc_256_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); + } + break; + } + return align_bytes; +} + +size_t armv8_aes_gcm_decrypt(const unsigned char *in, unsigned char *out, size_t len, + const void *key, unsigned char ivec[16], u64 *Xi) +{ + AES_KEY *aes_key = (AES_KEY *)key; + size_t align_bytes = len - len % 16; + + switch(aes_key->rounds) { + case 10: + if (IS_CPU_SUPPORT_UNROLL8_EOR3()) { + unroll8_eor3_aes_gcm_dec_128_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); + } else { + aes_gcm_dec_128_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); + } + break; + case 12: + if (IS_CPU_SUPPORT_UNROLL8_EOR3()) { + unroll8_eor3_aes_gcm_dec_192_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); + } else { + aes_gcm_dec_192_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); + } + break; + case 14: + if (IS_CPU_SUPPORT_UNROLL8_EOR3()) { + unroll8_eor3_aes_gcm_dec_256_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); + } else { + aes_gcm_dec_256_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); + } + break; + } + return align_bytes; +} + +static int armv8_aes_gcm_initkey(PROV_GCM_CTX *ctx, const unsigned char *key, + size_t keylen) +{ + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + AES_KEY *ks = &actx->ks.ks; + + if (AES_UNROLL12_EOR3_CAPABLE) { + GCM_HW_SET_KEY_CTR_FN(ks, aes_v8_set_encrypt_key, aes_v8_encrypt, + aes_v8_ctr32_encrypt_blocks_unroll12_eor3); + } else { + GCM_HW_SET_KEY_CTR_FN(ks, aes_v8_set_encrypt_key, aes_v8_encrypt, + aes_v8_ctr32_encrypt_blocks); + } + return 1; +} + + +static const PROV_GCM_HW armv8_aes_gcm = { + armv8_aes_gcm_initkey, + ossl_gcm_setiv, + ossl_gcm_aad_update, + generic_aes_gcm_cipher_update, + ossl_gcm_cipher_final, + ossl_gcm_one_shot +}; + +const PROV_GCM_HW *ossl_prov_aes_hw_gcm(size_t keybits) +{ + return AES_PMULL_CAPABLE ? &armv8_aes_gcm : &aes_gcm; +} diff --git a/providers/implementations/ciphers/cipher_aes_gcm_hw_ppc.c b/providers/implementations/ciphers/cipher_aes_gcm_hw_ppc.inc similarity index 64% rename from providers/implementations/ciphers/cipher_aes_gcm_hw_ppc.c rename to providers/implementations/ciphers/cipher_aes_gcm_hw_ppc.inc index c5d8d27c94..153eb79891 100644 --- a/providers/implementations/ciphers/cipher_aes_gcm_hw_ppc.c +++ b/providers/implementations/ciphers/cipher_aes_gcm_hw_ppc.inc @@ -9,53 +9,53 @@ /*- * PPC support for AES GCM. - * This file is used by cipher_aes_gcm_hw.c + * This file is included by cipher_aes_gcm_hw.c */ -#include "internal/deprecated.h" -#include "cipher_aes_gcm.h" - -#if defined(PPC_AES_GCM_CAPABLE) && defined(_ARCH_PPC64) static int aes_ppc_gcm_initkey(PROV_GCM_CTX *ctx, const unsigned char *key, - size_t keylen) + size_t keylen) { - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, aes_p8_set_encrypt_key, - aes_p8_encrypt, aes_p8_ctr32_encrypt_blocks); + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + AES_KEY *ks = &actx->ks.ks; + + GCM_HW_SET_KEY_CTR_FN(ks, aes_p8_set_encrypt_key, aes_p8_encrypt, + aes_p8_ctr32_encrypt_blocks); + return 1; } -static inline uint32_t UTO32(unsigned char *buf) +static inline u32 UTO32(unsigned char *buf) { - return ((uint32_t)buf[0] << 24) | ((uint32_t)buf[1] << 16) | ((uint32_t)buf[2] << 8) | ((uint32_t)buf[3]); + return ((u32) buf[0] << 24) | ((u32) buf[1] << 16) | ((u32) buf[2] << 8) | ((u32) buf[3]); } -static inline uint32_t add32TOU(unsigned char buf[4], uint32_t n) +static inline u32 add32TOU(unsigned char buf[4], u32 n) { - uint32_t r; + u32 r; r = UTO32(buf); r += n; - buf[0] = (unsigned char)(r >> 24) & 0xFF; - buf[1] = (unsigned char)(r >> 16) & 0xFF; - buf[2] = (unsigned char)(r >> 8) & 0xFF; - buf[3] = (unsigned char)r & 0xFF; + buf[0] = (unsigned char) (r >> 24) & 0xFF; + buf[1] = (unsigned char) (r >> 16) & 0xFF; + buf[2] = (unsigned char) (r >> 8) & 0xFF; + buf[3] = (unsigned char) r & 0xFF; return r; } static size_t ppc_aes_gcm_crypt(const unsigned char *in, unsigned char *out, size_t len, - const void *key, unsigned char ivec[16], uint64_t *Xi, int encrypt) + const void *key, unsigned char ivec[16], u64 *Xi, int encrypt) { - size_t s = 0; - size_t ndone = 0; + int s = 0; + int ndone = 0; int ctr_reset = 0; - uint64_t blocks_unused; - uint64_t nb = len / 16; - uint64_t next_ctr = 0; + u64 blocks_unused; + u64 nb = len / 16; + u64 next_ctr = 0; unsigned char ctr_saved[12]; memcpy(ctr_saved, ivec, 12); while (nb) { - blocks_unused = (uint64_t)0xffffffffU + 1 - (uint64_t)UTO32(ivec + 12); + blocks_unused = (u64) 0xffffffffU + 1 - (u64) UTO32 (ivec + 12); if (nb > blocks_unused) { len = blocks_unused * 16; nb -= blocks_unused; @@ -71,7 +71,7 @@ static size_t ppc_aes_gcm_crypt(const unsigned char *in, unsigned char *out, siz : ppc_aes_gcm_decrypt(in, out, len, key, ivec, Xi); /* add counter to ivec */ - add32TOU(ivec + 12, (uint32_t)next_ctr); + add32TOU(ivec + 12, (u32) next_ctr); if (ctr_reset) { ctr_reset = 0; in += len; @@ -85,7 +85,7 @@ static size_t ppc_aes_gcm_crypt(const unsigned char *in, unsigned char *out, siz } static int ppc_aes_gcm_cipher_update(PROV_GCM_CTX *ctx, const unsigned char *in, - size_t len, unsigned char *out) + size_t len, unsigned char *out) { if (ctx->enc) { if (ctx->ctr != NULL) { @@ -98,14 +98,14 @@ static int ppc_aes_gcm_cipher_update(PROV_GCM_CTX *ctx, const unsigned char *in, return 0; bulk = ppc_aes_gcm_crypt(in + res, out + res, len - res, - ctx->gcm.key, - ctx->gcm.Yi.c, ctx->gcm.Xi.u, 1); + ctx->gcm.key, + ctx->gcm.Yi.c, ctx->gcm.Xi.u, 1); ctx->gcm.len.u[1] += bulk; bulk += res; } if (CRYPTO_gcm128_encrypt_ctr32(&ctx->gcm, in + bulk, out + bulk, - len - bulk, ctx->ctr)) + len - bulk, ctx->ctr)) return 0; } else { if (CRYPTO_gcm128_encrypt(&ctx->gcm, in, out, len)) @@ -119,17 +119,17 @@ static int ppc_aes_gcm_cipher_update(PROV_GCM_CTX *ctx, const unsigned char *in, size_t res = (16 - ctx->gcm.mres) % 16; if (CRYPTO_gcm128_decrypt(&ctx->gcm, in, out, res)) - return 0; + return -1; bulk = ppc_aes_gcm_crypt(in + res, out + res, len - res, - ctx->gcm.key, - ctx->gcm.Yi.c, ctx->gcm.Xi.u, 0); + ctx->gcm.key, + ctx->gcm.Yi.c, ctx->gcm.Xi.u, 0); ctx->gcm.len.u[1] += bulk; bulk += res; } if (CRYPTO_gcm128_decrypt_ctr32(&ctx->gcm, in + bulk, out + bulk, - len - bulk, ctx->ctr)) + len - bulk, ctx->ctr)) return 0; } else { if (CRYPTO_gcm128_decrypt(&ctx->gcm, in, out, len)) @@ -148,9 +148,8 @@ static const PROV_GCM_HW aes_ppc_gcm = { ossl_gcm_one_shot }; -const PROV_GCM_HW *ossl_prov_aes_hw_gcm_ppc(size_t keybits) +const PROV_GCM_HW *ossl_prov_aes_hw_gcm(size_t keybits) { - return PPC_AES_GCM_CAPABLE ? &aes_ppc_gcm : NULL; + return PPC_AES_GCM_CAPABLE ? &aes_ppc_gcm : &aes_gcm; } -#endif diff --git a/providers/implementations/ciphers/cipher_aes_gcm_hw_rv32i.inc b/providers/implementations/ciphers/cipher_aes_gcm_hw_rv32i.inc new file mode 100644 index 0000000000..bf3f98df16 --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_gcm_hw_rv32i.inc @@ -0,0 +1,63 @@ +/* + * Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * RISC-V 32 ZKND ZKNE support for AES GCM. + * This file is included by cipher_aes_gcm_hw.c + */ + +static int rv32i_zknd_zkne_gcm_initkey(PROV_GCM_CTX *ctx, const unsigned char *key, + size_t keylen) +{ + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + AES_KEY *ks = &actx->ks.ks; + + GCM_HW_SET_KEY_CTR_FN(ks, rv32i_zkne_set_encrypt_key, rv32i_zkne_encrypt, + NULL); + return 1; +} + +static int rv32i_zbkb_zknd_zkne_gcm_initkey(PROV_GCM_CTX *ctx, + const unsigned char *key, + size_t keylen) +{ + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + AES_KEY *ks = &actx->ks.ks; + + GCM_HW_SET_KEY_CTR_FN(ks, rv32i_zbkb_zkne_set_encrypt_key, rv32i_zkne_encrypt, + NULL); + return 1; +} + +static const PROV_GCM_HW rv32i_zknd_zkne_gcm = { + rv32i_zknd_zkne_gcm_initkey, + ossl_gcm_setiv, + ossl_gcm_aad_update, + generic_aes_gcm_cipher_update, + ossl_gcm_cipher_final, + ossl_gcm_one_shot +}; + +static const PROV_GCM_HW rv32i_zbkb_zknd_zkne_gcm = { + rv32i_zbkb_zknd_zkne_gcm_initkey, + ossl_gcm_setiv, + ossl_gcm_aad_update, + generic_aes_gcm_cipher_update, + ossl_gcm_cipher_final, + ossl_gcm_one_shot +}; + +const PROV_GCM_HW *ossl_prov_aes_hw_gcm(size_t keybits) +{ + if (RISCV_HAS_ZBKB_AND_ZKND_AND_ZKNE()) + return &rv32i_zbkb_zknd_zkne_gcm; + if (RISCV_HAS_ZKND_AND_ZKNE()) + return &rv32i_zknd_zkne_gcm; + return &aes_gcm; +} diff --git a/providers/implementations/ciphers/cipher_aes_gcm_hw_rv64i.inc b/providers/implementations/ciphers/cipher_aes_gcm_hw_rv64i.inc new file mode 100644 index 0000000000..105ca58fd3 --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_gcm_hw_rv64i.inc @@ -0,0 +1,118 @@ +/* + * Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * RISC-V 64 support for AES GCM. + * This file is included by cipher_aes_gcm_hw.c + */ + +/*- + * RISC-V 64 ZKND and ZKNE support for AES GCM. + */ +static int rv64i_zknd_zkne_gcm_initkey(PROV_GCM_CTX *ctx, const unsigned char *key, + size_t keylen) +{ + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + AES_KEY *ks = &actx->ks.ks; + GCM_HW_SET_KEY_CTR_FN(ks, rv64i_zkne_set_encrypt_key, rv64i_zkne_encrypt, + NULL); + return 1; +} + +static const PROV_GCM_HW rv64i_zknd_zkne_gcm = { + rv64i_zknd_zkne_gcm_initkey, + ossl_gcm_setiv, + ossl_gcm_aad_update, + generic_aes_gcm_cipher_update, + ossl_gcm_cipher_final, + ossl_gcm_one_shot +}; + +/*- + * RISC-V RV64 ZVKNED support for AES GCM. + */ +static int rv64i_zvkned_gcm_initkey(PROV_GCM_CTX *ctx, const unsigned char *key, + size_t keylen) +{ + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + AES_KEY *ks = &actx->ks.ks; + + /* + * Zvkned only supports 128 and 256 bit keys for key schedule generation. + * For AES-192 case, we could fallback to `AES_set_encrypt_key`. + */ + if (keylen * 8 == 128 || keylen * 8 == 256) { + GCM_HW_SET_KEY_CTR_FN(ks, rv64i_zvkned_set_encrypt_key, + rv64i_zvkned_encrypt, NULL); + } else { + GCM_HW_SET_KEY_CTR_FN(ks, AES_set_encrypt_key, + rv64i_zvkned_encrypt, NULL); + } + + return 1; +} + +static const PROV_GCM_HW rv64i_zvkned_gcm = { + rv64i_zvkned_gcm_initkey, + ossl_gcm_setiv, + ossl_gcm_aad_update, + generic_aes_gcm_cipher_update, + ossl_gcm_cipher_final, + ossl_gcm_one_shot +}; + +/*- + * RISC-V RV64 ZVKB, ZVKG and ZVKNED support for AES GCM. + */ +static int rv64i_zvkb_zvkg_zvkned_gcm_initkey(PROV_GCM_CTX *ctx, + const unsigned char *key, + size_t keylen) { + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + AES_KEY *ks = &actx->ks.ks; + + /* + * Zvkned only supports 128 and 256 bit keys for key schedule generation. + * For AES-192 case, we could fallback to `AES_set_encrypt_key`. + */ + if (keylen * 8 == 128 || keylen * 8 == 256) { + GCM_HW_SET_KEY_CTR_FN(ks, rv64i_zvkned_set_encrypt_key, + rv64i_zvkned_encrypt, + rv64i_zvkb_zvkned_ctr32_encrypt_blocks); + } else { + GCM_HW_SET_KEY_CTR_FN(ks, AES_set_encrypt_key, + rv64i_zvkned_encrypt, + rv64i_zvkb_zvkned_ctr32_encrypt_blocks); + } + + return 1; +} + +static const PROV_GCM_HW rv64i_zvkb_zvkg_zvkned_gcm = { + rv64i_zvkb_zvkg_zvkned_gcm_initkey, + ossl_gcm_setiv, + ossl_gcm_aad_update, + generic_aes_gcm_cipher_update, + ossl_gcm_cipher_final, + ossl_gcm_one_shot +}; + +const PROV_GCM_HW *ossl_prov_aes_hw_gcm(size_t keybits) { + if (RISCV_HAS_ZVKNED()) { + if (RISCV_HAS_ZVKB() && RISCV_HAS_ZVKG() && riscv_vlen() >= 128) { + return &rv64i_zvkb_zvkg_zvkned_gcm; + } + return &rv64i_zvkned_gcm; + } + + if (RISCV_HAS_ZKND_AND_ZKNE()) { + return &rv64i_zknd_zkne_gcm; + } + + return &aes_gcm; +} diff --git a/providers/implementations/ciphers/cipher_aes_gcm_hw_s390x.inc b/providers/implementations/ciphers/cipher_aes_gcm_hw_s390x.inc new file mode 100644 index 0000000000..a36c48e3ec --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_gcm_hw_s390x.inc @@ -0,0 +1,312 @@ +/* + * Copyright 2001-2021 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * IBM S390X support for AES GCM. + * This file is included by cipher_aes_gcm_hw.c + */ + +/* iv + padding length for iv lengths != 12 */ +#define S390X_gcm_ivpadlen(i) ((((i) + 15) >> 4 << 4) + 16) + +/* Additional flag or'ed to fc for decryption */ +#define S390X_gcm_decrypt_flag(ctx) (((ctx)->enc) ? 0 : S390X_DECRYPT) + +#define S390X_gcm_fc(A,C) ((A)->plat.s390x.fc | (A)->plat.s390x.hsflag |\ + S390X_gcm_decrypt_flag((C))) + +static int s390x_aes_gcm_initkey(PROV_GCM_CTX *ctx, + const unsigned char *key, size_t keylen) +{ + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + + ctx->key_set = 1; + memcpy(&actx->plat.s390x.param.kma.k, key, keylen); + actx->plat.s390x.fc = S390X_AES_FC(keylen); + return 1; +} + +static int s390x_aes_gcm_setiv(PROV_GCM_CTX *ctx, const unsigned char *iv, + size_t ivlen) +{ + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + S390X_KMA_PARAMS *kma = &actx->plat.s390x.param.kma; + + kma->t.g[0] = 0; + kma->t.g[1] = 0; + kma->tpcl = 0; + kma->taadl = 0; + actx->plat.s390x.mreslen = 0; + actx->plat.s390x.areslen = 0; + actx->plat.s390x.kreslen = 0; + + if (ivlen == GCM_IV_DEFAULT_SIZE) { + memcpy(&kma->j0, iv, ivlen); + kma->j0.w[3] = 1; + kma->cv.w = 1; + actx->plat.s390x.hsflag = 0; + } else { + unsigned long long ivbits = ivlen << 3; + size_t len = S390X_gcm_ivpadlen(ivlen); + unsigned char iv_zero_pad[S390X_gcm_ivpadlen(GCM_IV_MAX_SIZE)]; + /* + * The IV length needs to be zero padded to be a multiple of 16 bytes + * followed by 8 bytes of zeros and 8 bytes for the IV length. + * The GHASH of this value can then be calculated. + */ + memcpy(iv_zero_pad, iv, ivlen); + memset(iv_zero_pad + ivlen, 0, len - ivlen); + memcpy(iv_zero_pad + len - sizeof(ivbits), &ivbits, sizeof(ivbits)); + /* + * Calculate the ghash of the iv - the result is stored into the tag + * param. + */ + s390x_kma(iv_zero_pad, len, NULL, 0, NULL, actx->plat.s390x.fc, kma); + actx->plat.s390x.hsflag = S390X_KMA_HS; /* The hash subkey is set */ + + /* Copy the 128 bit GHASH result into J0 and clear the tag */ + kma->j0.g[0] = kma->t.g[0]; + kma->j0.g[1] = kma->t.g[1]; + kma->t.g[0] = 0; + kma->t.g[1] = 0; + /* Set the 32 bit counter */ + kma->cv.w = kma->j0.w[3]; + } + return 1; +} + +static int s390x_aes_gcm_cipher_final(PROV_GCM_CTX *ctx, unsigned char *tag) +{ + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + S390X_KMA_PARAMS *kma = &actx->plat.s390x.param.kma; + unsigned char out[AES_BLOCK_SIZE]; + unsigned int fc; + int rc; + + kma->taadl <<= 3; + kma->tpcl <<= 3; + fc = S390X_gcm_fc(actx, ctx) | S390X_KMA_LAAD | S390X_KMA_LPC; + s390x_kma(actx->plat.s390x.ares, actx->plat.s390x.areslen, + actx->plat.s390x.mres, actx->plat.s390x.mreslen, out, + fc, kma); + + /* gctx->mres already returned to the caller */ + OPENSSL_cleanse(out, actx->plat.s390x.mreslen); + + if (ctx->enc) { + ctx->taglen = GCM_TAG_MAX_SIZE; + memcpy(tag, kma->t.b, ctx->taglen); + rc = 1; + } else { + rc = (CRYPTO_memcmp(tag, kma->t.b, ctx->taglen) == 0); + } + return rc; +} + +static int s390x_aes_gcm_one_shot(PROV_GCM_CTX *ctx, + unsigned char *aad, size_t aad_len, + const unsigned char *in, size_t in_len, + unsigned char *out, + unsigned char *tag, size_t taglen) +{ + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + S390X_KMA_PARAMS *kma = &actx->plat.s390x.param.kma; + unsigned int fc; + int rc; + + kma->taadl = aad_len << 3; + kma->tpcl = in_len << 3; + fc = S390X_gcm_fc(actx, ctx) | S390X_KMA_LAAD | S390X_KMA_LPC; + s390x_kma(aad, aad_len, in, in_len, out, fc, kma); + + if (ctx->enc) { + memcpy(tag, kma->t.b, taglen); + rc = 1; + } else { + rc = (CRYPTO_memcmp(tag, kma->t.b, taglen) == 0); + } + return rc; +} + +/* + * Process additional authenticated data. Returns 1 on success. Code is + * big-endian. + */ +static int s390x_aes_gcm_aad_update(PROV_GCM_CTX *ctx, + const unsigned char *aad, size_t len) +{ + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + S390X_KMA_PARAMS *kma = &actx->plat.s390x.param.kma; + unsigned long long alen; + unsigned int fc; + int n, rem; + + /* If already processed pt/ct then error */ + if (kma->tpcl != 0) + return 0; + + /* update the total aad length */ + alen = kma->taadl + len; + if (alen > (U64(1) << 61) || (sizeof(len) == 8 && alen < len)) + return 0; + kma->taadl = alen; + + /* check if there is any existing aad data from a previous add */ + n = actx->plat.s390x.areslen; + if (n) { + /* add additional data to a buffer until it has 16 bytes */ + while (n && len) { + actx->plat.s390x.ares[n] = *aad; + ++aad; + --len; + n = (n + 1) & 0xf; + } + /* ctx->ares contains a complete block if offset has wrapped around */ + if (!n) { + fc = S390X_gcm_fc(actx, ctx); + s390x_kma(actx->plat.s390x.ares, 16, NULL, 0, NULL, fc, kma); + actx->plat.s390x.hsflag = S390X_KMA_HS; + } + actx->plat.s390x.areslen = n; + } + + /* If there are leftover bytes (< 128 bits) save them for next time */ + rem = len & 0xf; + /* Add any remaining 16 byte blocks (128 bit each) */ + len &= ~(size_t)0xf; + if (len) { + fc = S390X_gcm_fc(actx, ctx); + s390x_kma(aad, len, NULL, 0, NULL, fc, kma); + actx->plat.s390x.hsflag = S390X_KMA_HS; + aad += len; + } + + if (rem) { + actx->plat.s390x.areslen = rem; + + do { + --rem; + actx->plat.s390x.ares[rem] = aad[rem]; + } while (rem); + } + return 1; +} + +/*- + * En/de-crypt plain/cipher-text and authenticate ciphertext. Returns 1 for + * success. Code is big-endian. + */ +static int s390x_aes_gcm_cipher_update(PROV_GCM_CTX *ctx, + const unsigned char *in, size_t len, + unsigned char *out) +{ + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + S390X_KMA_PARAMS *kma = &actx->plat.s390x.param.kma; + const unsigned char *inptr; + unsigned long long mlen; + unsigned int fc; + union { + unsigned int w[4]; + unsigned char b[16]; + } buf; + size_t inlen; + int n, rem, i; + + mlen = kma->tpcl + len; + if (mlen > ((U64(1) << 36) - 32) || (sizeof(len) == 8 && mlen < len)) + return 0; + kma->tpcl = mlen; + + fc = S390X_gcm_fc(actx, ctx) | S390X_KMA_LAAD; + n = actx->plat.s390x.mreslen; + if (n) { + inptr = in; + inlen = len; + while (n && inlen) { + actx->plat.s390x.mres[n] = *inptr; + n = (n + 1) & 0xf; + ++inptr; + --inlen; + } + /* ctx->mres contains a complete block if offset has wrapped around */ + if (!n) { + s390x_kma(actx->plat.s390x.ares, actx->plat.s390x.areslen, + actx->plat.s390x.mres, 16, buf.b, fc, kma); + actx->plat.s390x.hsflag = S390X_KMA_HS; + fc |= S390X_KMA_HS; + actx->plat.s390x.areslen = 0; + + /* previous call already encrypted/decrypted its remainder, + * see comment below */ + n = actx->plat.s390x.mreslen; + while (n) { + *out = buf.b[n]; + n = (n + 1) & 0xf; + ++out; + ++in; + --len; + } + actx->plat.s390x.mreslen = 0; + } + } + + rem = len & 0xf; + + len &= ~(size_t)0xf; + if (len) { + s390x_kma(actx->plat.s390x.ares, actx->plat.s390x.areslen, in, len, out, + fc, kma); + in += len; + out += len; + actx->plat.s390x.hsflag = S390X_KMA_HS; + actx->plat.s390x.areslen = 0; + } + + /*- + * If there is a remainder, it has to be saved such that it can be + * processed by kma later. However, we also have to do the for-now + * unauthenticated encryption/decryption part here and now... + */ + if (rem) { + if (!actx->plat.s390x.mreslen) { + buf.w[0] = kma->j0.w[0]; + buf.w[1] = kma->j0.w[1]; + buf.w[2] = kma->j0.w[2]; + buf.w[3] = kma->cv.w + 1; + s390x_km(buf.b, 16, actx->plat.s390x.kres, + fc & 0x1f, &kma->k); + } + + n = actx->plat.s390x.mreslen; + for (i = 0; i < rem; i++) { + actx->plat.s390x.mres[n + i] = in[i]; + out[i] = in[i] ^ actx->plat.s390x.kres[n + i]; + } + actx->plat.s390x.mreslen += rem; + } + return 1; +} + +static const PROV_GCM_HW s390x_aes_gcm = { + s390x_aes_gcm_initkey, + s390x_aes_gcm_setiv, + s390x_aes_gcm_aad_update, + s390x_aes_gcm_cipher_update, + s390x_aes_gcm_cipher_final, + s390x_aes_gcm_one_shot +}; + +const PROV_GCM_HW *ossl_prov_aes_hw_gcm(size_t keybits) +{ + if ((keybits == 128 && S390X_aes_128_gcm_CAPABLE) + || (keybits == 192 && S390X_aes_192_gcm_CAPABLE) + || (keybits == 256 && S390X_aes_256_gcm_CAPABLE)) + return &s390x_aes_gcm; + return &aes_gcm; +} diff --git a/providers/implementations/ciphers/cipher_aes_gcm_hw_t4.inc b/providers/implementations/ciphers/cipher_aes_gcm_hw_t4.inc new file mode 100644 index 0000000000..2b3a6d1d5e --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_gcm_hw_t4.inc @@ -0,0 +1,52 @@ +/* + * Copyright 2001-2021 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * Fujitsu SPARC64 X support for AES GCM. + * This file is included by cipher_aes_gcm_hw.c + */ + +static int t4_aes_gcm_initkey(PROV_GCM_CTX *ctx, const unsigned char *key, + size_t keylen) +{ + ctr128_f ctr; + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + AES_KEY *ks = &actx->ks.ks; + + + switch (keylen) { + case 16: + ctr = (ctr128_f)aes128_t4_ctr32_encrypt; + break; + case 24: + ctr = (ctr128_f)aes192_t4_ctr32_encrypt; + break; + case 32: + ctr = (ctr128_f)aes256_t4_ctr32_encrypt; + break; + default: + return 0; + } + + GCM_HW_SET_KEY_CTR_FN(ks, aes_t4_set_encrypt_key, aes_t4_encrypt, ctr); + return 1; +} + +static const PROV_GCM_HW t4_aes_gcm = { + t4_aes_gcm_initkey, + ossl_gcm_setiv, + ossl_gcm_aad_update, + generic_aes_gcm_cipher_update, + ossl_gcm_cipher_final, + ossl_gcm_one_shot +}; +const PROV_GCM_HW *ossl_prov_aes_hw_gcm(size_t keybits) +{ + return SPARC_AES_CAPABLE ? &t4_aes_gcm : &aes_gcm; +} diff --git a/providers/implementations/ciphers/cipher_aes_gcm_hw_vaes_avx512.inc b/providers/implementations/ciphers/cipher_aes_gcm_hw_vaes_avx512.inc new file mode 100644 index 0000000000..df98cdec50 --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_gcm_hw_vaes_avx512.inc @@ -0,0 +1,204 @@ +/* + * Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. + * Copyright (c) 2021, Intel Corporation. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * AVX512 VAES + VPCLMULDQD support for AES GCM. + * This file is included by cipher_aes_gcm_hw_aesni.inc + */ + +#undef VAES_GCM_ENABLED +#if (defined(__x86_64) || defined(__x86_64__) || \ + defined(_M_AMD64) || defined(_M_X64)) +# define VAES_GCM_ENABLED + +/* Returns non-zero when AVX512F + VAES + VPCLMULDQD combination is available */ +int ossl_vaes_vpclmulqdq_capable(void); + +# define OSSL_AES_GCM_UPDATE(direction) \ + void ossl_aes_gcm_ ## direction ## _avx512(const void *ks, \ + void *gcm128ctx, \ + unsigned int *pblocklen, \ + const unsigned char *in, \ + size_t len, \ + unsigned char *out); + +OSSL_AES_GCM_UPDATE(encrypt) +OSSL_AES_GCM_UPDATE(decrypt) + +void ossl_aes_gcm_init_avx512(const void *ks, void *gcm128ctx); +void ossl_aes_gcm_setiv_avx512(const void *ks, void *gcm128ctx, + const unsigned char *iv, size_t ivlen); +void ossl_aes_gcm_update_aad_avx512(void *gcm128ctx, const unsigned char *aad, + size_t aadlen); +void ossl_aes_gcm_finalize_avx512(void *gcm128ctx, unsigned int pblocklen); + +void ossl_gcm_gmult_avx512(u64 Xi[2], const void *gcm128ctx); + +static int vaes_gcm_setkey(PROV_GCM_CTX *ctx, const unsigned char *key, + size_t keylen) +{ + GCM128_CONTEXT *gcmctx = &ctx->gcm; + PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; + AES_KEY *ks = &actx->ks.ks; + + aesni_set_encrypt_key(key, (int)(keylen * 8), ks); + memset(gcmctx, 0, sizeof(*gcmctx)); + gcmctx->key = ks; + ctx->key_set = 1; + + ossl_aes_gcm_init_avx512(ks, gcmctx); + + return 1; +} + +static int vaes_gcm_setiv(PROV_GCM_CTX *ctx, const unsigned char *iv, + size_t ivlen) +{ + GCM128_CONTEXT *gcmctx = &ctx->gcm; + + gcmctx->Yi.u[0] = 0; /* Current counter */ + gcmctx->Yi.u[1] = 0; + gcmctx->Xi.u[0] = 0; /* AAD hash */ + gcmctx->Xi.u[1] = 0; + gcmctx->len.u[0] = 0; /* AAD length */ + gcmctx->len.u[1] = 0; /* Message length */ + gcmctx->ares = 0; + gcmctx->mres = 0; + + /* IV is limited by 2^64 bits, thus 2^61 bytes */ + if (ivlen > (U64(1) << 61)) + return 0; + + ossl_aes_gcm_setiv_avx512(gcmctx->key, gcmctx, iv, ivlen); + + return 1; +} + +static int vaes_gcm_aadupdate(PROV_GCM_CTX *ctx, + const unsigned char *aad, + size_t aad_len) +{ + GCM128_CONTEXT *gcmctx = &ctx->gcm; + u64 alen = gcmctx->len.u[0]; + unsigned int ares; + size_t i, lenBlks; + + /* Bad sequence: call of AAD update after message processing */ + if (gcmctx->len.u[1] > 0) + return 0; + + alen += aad_len; + /* AAD is limited by 2^64 bits, thus 2^61 bytes */ + if ((alen > (U64(1) << 61)) || (alen < aad_len)) + return 0; + + gcmctx->len.u[0] = alen; + + ares = gcmctx->ares; + /* Partial AAD block left from previous AAD update calls */ + if (ares > 0) { + /* + * Fill partial block buffer till full block + * (note, the hash is stored reflected) + */ + while (ares > 0 && aad_len > 0) { + gcmctx->Xi.c[15 - ares] ^= *(aad++); + --aad_len; + ares = (ares + 1) % AES_BLOCK_SIZE; + } + /* Full block gathered */ + if (ares == 0) { + ossl_gcm_gmult_avx512(gcmctx->Xi.u, gcmctx); + } else { /* no more AAD */ + gcmctx->ares = ares; + return 1; + } + } + + /* Bulk AAD processing */ + lenBlks = aad_len & ((size_t)(-AES_BLOCK_SIZE)); + if (lenBlks > 0) { + ossl_aes_gcm_update_aad_avx512(gcmctx, aad, lenBlks); + aad += lenBlks; + aad_len -= lenBlks; + } + + /* Add remaining AAD to the hash (note, the hash is stored reflected) */ + if (aad_len > 0) { + ares = (unsigned int)aad_len; + for (i = 0; i < aad_len; i++) + gcmctx->Xi.c[15 - i] ^= aad[i]; + } + + gcmctx->ares = ares; + + return 1; +} + +static int vaes_gcm_cipherupdate(PROV_GCM_CTX *ctx, const unsigned char *in, + size_t len, unsigned char *out) +{ + GCM128_CONTEXT *gcmctx = &ctx->gcm; + u64 mlen = gcmctx->len.u[1]; + + mlen += len; + if (mlen > ((U64(1) << 36) - 32) || (mlen < len)) + return 0; + + gcmctx->len.u[1] = mlen; + + /* Finalize GHASH(AAD) if AAD partial blocks left unprocessed */ + if (gcmctx->ares > 0) { + ossl_gcm_gmult_avx512(gcmctx->Xi.u, gcmctx); + gcmctx->ares = 0; + } + + if (ctx->enc) + ossl_aes_gcm_encrypt_avx512(gcmctx->key, gcmctx, &gcmctx->mres, in, len, out); + else + ossl_aes_gcm_decrypt_avx512(gcmctx->key, gcmctx, &gcmctx->mres, in, len, out); + + return 1; +} + +static int vaes_gcm_cipherfinal(PROV_GCM_CTX *ctx, unsigned char *tag) +{ + GCM128_CONTEXT *gcmctx = &ctx->gcm; + unsigned int *res = &gcmctx->mres; + + /* Finalize AAD processing */ + if (gcmctx->ares > 0) + res = &gcmctx->ares; + + ossl_aes_gcm_finalize_avx512(gcmctx, *res); + + if (ctx->enc) { + ctx->taglen = GCM_TAG_MAX_SIZE; + memcpy(tag, gcmctx->Xi.c, + ctx->taglen <= sizeof(gcmctx->Xi.c) ? ctx->taglen : + sizeof(gcmctx->Xi.c)); + *res = 0; + } else { + return !CRYPTO_memcmp(gcmctx->Xi.c, tag, ctx->taglen); + } + + return 1; +} + +static const PROV_GCM_HW vaes_gcm = { + vaes_gcm_setkey, + vaes_gcm_setiv, + vaes_gcm_aadupdate, + vaes_gcm_cipherupdate, + vaes_gcm_cipherfinal, + ossl_gcm_one_shot +}; + +#endif diff --git a/providers/implementations/ciphers/cipher_aes_gcm_siv.c b/providers/implementations/ciphers/cipher_aes_gcm_siv.c index 2f4a86dc56..1fd97fe3d1 100644 --- a/providers/implementations/ciphers/cipher_aes_gcm_siv.c +++ b/providers/implementations/ciphers/cipher_aes_gcm_siv.c @@ -182,11 +182,8 @@ static int ossl_aes_gcm_siv_get_ctx_params(void *vctx, OSSL_PARAM params[]) return 0; if (p.tag != NULL && p.tag->data_type == OSSL_PARAM_OCTET_STRING) { - if (!ctx->enc || !ctx->generated_tag) { - ERR_raise(ERR_LIB_PROV, PROV_R_TAG_NOT_SET); - return 0; - } - if (p.tag->data_size != sizeof(ctx->tag) + if (!ctx->enc || !ctx->generated_tag + || p.tag->data_size != sizeof(ctx->tag) || !OSSL_PARAM_set_octet_string(p.tag, ctx->tag, sizeof(ctx->tag))) { ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_SET_PARAMETER); @@ -230,9 +227,6 @@ static int ossl_aes_gcm_siv_set_ctx_params(void *vctx, const OSSL_PARAM params[] if (!ctx->enc) { memcpy(ctx->user_tag, p.tag->data, sizeof(ctx->tag)); ctx->have_user_tag = 1; - } else if (p.tag->data != NULL) { - ERR_raise(ERR_LIB_PROV, PROV_R_TAG_NOT_NEEDED); - return 0; } } diff --git a/providers/implementations/ciphers/cipher_aes_gcm_siv.h b/providers/implementations/ciphers/cipher_aes_gcm_siv.h index 7333c39b0b..dbee05beda 100644 --- a/providers/implementations/ciphers/cipher_aes_gcm_siv.h +++ b/providers/implementations/ciphers/cipher_aes_gcm_siv.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_GCM_SIV_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_GCM_SIV_H - #include #include "prov/ciphercommon.h" #include "crypto/aes_platform.h" @@ -77,5 +74,3 @@ static ossl_inline uint64_t GSWAP8(uint64_t n) result <<= 32; return result | GSWAP4(n >> 32); } - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_GCM_SIV_H) */ diff --git a/providers/implementations/ciphers/cipher_aes_gcm_siv_hw.c b/providers/implementations/ciphers/cipher_aes_gcm_siv_hw.c index 9622c2dcca..d0b6ae4b07 100644 --- a/providers/implementations/ciphers/cipher_aes_gcm_siv_hw.c +++ b/providers/implementations/ciphers/cipher_aes_gcm_siv_hw.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -15,7 +15,6 @@ #include "internal/deprecated.h" #include -#include #include #include #include "cipher_aes_gcm_siv.h" @@ -59,9 +58,6 @@ static int aes_gcm_siv_initkey(void *vctx) memset(&data, 0, sizeof(data)); memcpy(&data.block[sizeof(data.counter)], ctx->nonce, NONCE_SIZE); - ctx->generated_tag = 0; - memset(ctx->tag, 0, TAG_SIZE); - /* msg_auth_key is always 16 bytes in size, regardless of AES128/AES256 */ /* counter is stored little-endian */ for (i = 0; i < BLOCK_SIZE; i += 8) { @@ -138,6 +134,17 @@ static int aes_gcm_siv_aad(PROV_AES_GCM_SIV_CTX *ctx, return 1; } +static int aes_gcm_siv_finish(PROV_AES_GCM_SIV_CTX *ctx) +{ + int ret = 0; + + if (ctx->enc) + return ctx->generated_tag; + ret = !CRYPTO_memcmp(ctx->tag, ctx->user_tag, sizeof(ctx->tag)); + ret &= ctx->have_user_tag; + return ret; +} + static int aes_gcm_siv_encrypt(PROV_AES_GCM_SIV_CTX *ctx, const unsigned char *in, unsigned char *out, size_t len) { @@ -152,6 +159,8 @@ static int aes_gcm_siv_encrypt(PROV_AES_GCM_SIV_CTX *ctx, const unsigned char *i DECLARE_IS_ENDIAN; ctx->generated_tag = 0; + if (!ctx->speed && ctx->used_enc) + return 0; /* need to check the size of the input! */ if (len64 > ((int64_t)1 << 36)) return 0; @@ -171,7 +180,7 @@ static int aes_gcm_siv_encrypt(PROV_AES_GCM_SIV_CTX *ctx, const unsigned char *i ossl_polyval_ghash_hash(ctx->Htable, S_s, ctx->aad, UP16(ctx->aad_len)); } if (DOWN16(len) > 0) - ossl_polyval_ghash_hash(ctx->Htable, S_s, in, DOWN16(len)); + ossl_polyval_ghash_hash(ctx->Htable, S_s, (uint8_t *)in, DOWN16(len)); if (!IS16(len)) { /* deal with padding - probably easier to memset the padding first rather than calculate */ memset(padding, 0, sizeof(padding)); @@ -211,6 +220,8 @@ static int aes_gcm_siv_decrypt(PROV_AES_GCM_SIV_CTX *ctx, const unsigned char *i DECLARE_IS_ENDIAN; ctx->generated_tag = 0; + if (!ctx->speed && ctx->used_dec) + return 0; /* need to check the size of the input! */ if (len64 > ((int64_t)1 << 36)) return 0; @@ -260,19 +271,6 @@ static int aes_gcm_siv_decrypt(PROV_AES_GCM_SIV_CTX *ctx, const unsigned char *i return !error; } -static int aes_gcm_siv_finish(PROV_AES_GCM_SIV_CTX *ctx) -{ - int ret = 0; - - if (ctx->enc) - return ctx->generated_tag; - if (!ctx->generated_tag) - aes_gcm_siv_decrypt(ctx, NULL, NULL, 0); - ret = !CRYPTO_memcmp(ctx->tag, ctx->user_tag, sizeof(ctx->tag)); - ret &= ctx->have_user_tag; - return ret; -} - static int aes_gcm_siv_cipher(void *vctx, unsigned char *out, const unsigned char *in, size_t len) { @@ -282,18 +280,6 @@ static int aes_gcm_siv_cipher(void *vctx, unsigned char *out, if (in == NULL) return aes_gcm_siv_finish(ctx); - /* - * SIV derives the CTR IV from the tag, which depends on the whole plaintext, - * so the payload cannot be streamed. - * Payload must arrive in a single update, after which the tag is fixed. - * Any later AAD or payload update is therefore out of order and errors out. - * The speed benchmark test is exempt. - */ - if (!ctx->speed && (ctx->used_enc || ctx->used_dec)) { - ERR_raise(ERR_LIB_PROV, PROV_R_UPDATE_CALL_OUT_OF_ORDER); - return 0; - } - /* Deal with associated data */ if (out == NULL) return aes_gcm_siv_aad(ctx, in, len); diff --git a/providers/implementations/ciphers/cipher_aes_gcm_siv_polyval.c b/providers/implementations/ciphers/cipher_aes_gcm_siv_polyval.c index 08188c8aaf..5c9988cabf 100644 --- a/providers/implementations/ciphers/cipher_aes_gcm_siv_polyval.c +++ b/providers/implementations/ciphers/cipher_aes_gcm_siv_polyval.c @@ -71,7 +71,7 @@ void ossl_polyval_ghash_init(u128 Htable[16], const uint64_t H[2]) tmp[1] = GSWAP8(tmp[1]); } - ossl_gcm_init_4bit(Htable, (uint64_t *)tmp); + ossl_gcm_init_4bit(Htable, (u64 *)tmp); } /* Implementation of POLYVAL via existing GHASH implementation */ @@ -89,7 +89,7 @@ void ossl_polyval_ghash_hash(const u128 Htable[16], uint8_t *tag, const uint8_t */ for (i = 0; i < len; i += 16) { byte_reverse16((uint8_t *)tmp, &inp[i]); - ossl_gcm_ghash_4bit((uint64_t *)out, Htable, (uint8_t *)tmp, 16); + ossl_gcm_ghash_4bit((u64 *)out, Htable, (uint8_t *)tmp, 16); } byte_reverse16(tag, (uint8_t *)out); } diff --git a/providers/implementations/ciphers/cipher_aes_hw.c b/providers/implementations/ciphers/cipher_aes_hw.c index 03ddb46947..da9a6729d0 100644 --- a/providers/implementations/ciphers/cipher_aes_hw.c +++ b/providers/implementations/ciphers/cipher_aes_hw.c @@ -1,5 +1,5 @@ /* - * Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2001-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -16,273 +16,149 @@ #include #include "cipher_aes.h" -int ossl_cipher_set_aes_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen, - aes_set_encrypt_key_fn fn_set_key, aes_block128_f fn_block, - ecb128_f fn_ecb, cbc128_f fn_cbc, ctr128_f fn_ctr) +static int cipher_hw_aes_initkey(PROV_CIPHER_CTX *dat, + const unsigned char *key, size_t keylen) { - PROV_AES_CTX *actx = (PROV_AES_CTX *)ctx; - AES_KEY *ks = &actx->ks.ks; + int ret; + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + AES_KEY *ks = &adat->ks.ks; + + dat->ks = ks; + + if ((dat->mode == EVP_CIPH_ECB_MODE || dat->mode == EVP_CIPH_CBC_MODE) + && !dat->enc) { +#ifdef HWAES_CAPABLE + if (HWAES_CAPABLE) { + ret = HWAES_set_decrypt_key(key, keylen * 8, ks); + dat->block = (block128_f)HWAES_decrypt; + dat->stream.cbc = NULL; +#ifdef HWAES_cbc_encrypt + if (dat->mode == EVP_CIPH_CBC_MODE) + dat->stream.cbc = (cbc128_f)HWAES_cbc_encrypt; +#endif +#ifdef HWAES_ecb_encrypt + if (dat->mode == EVP_CIPH_ECB_MODE) + dat->stream.ecb = (ecb128_f)HWAES_ecb_encrypt; +#endif + } else +#endif +#ifdef BSAES_CAPABLE + if (BSAES_CAPABLE && dat->mode == EVP_CIPH_CBC_MODE) { + ret = AES_set_decrypt_key(key, (int)(keylen * 8), ks); + dat->block = (block128_f)AES_decrypt; + dat->stream.cbc = (cbc128_f)ossl_bsaes_cbc_encrypt; + } else +#endif +#ifdef VPAES_CAPABLE + if (VPAES_CAPABLE) { + ret = vpaes_set_decrypt_key(key, (int)(keylen * 8), ks); + dat->block = (block128_f)vpaes_decrypt; + dat->stream.cbc = (dat->mode == EVP_CIPH_CBC_MODE) + ? (cbc128_f)vpaes_cbc_encrypt + : NULL; + } else +#endif + { + ret = AES_set_decrypt_key(key, (int)(keylen * 8), ks); + dat->block = (block128_f)AES_decrypt; + dat->stream.cbc = (dat->mode == EVP_CIPH_CBC_MODE) + ? (cbc128_f)AES_cbc_encrypt + : NULL; + } + } else +#ifdef HWAES_CAPABLE + if (HWAES_CAPABLE) { + ret = HWAES_set_encrypt_key(key, keylen * 8, ks); + dat->block = (block128_f)HWAES_encrypt; + dat->stream.cbc = NULL; +#ifdef HWAES_cbc_encrypt + if (dat->mode == EVP_CIPH_CBC_MODE) + dat->stream.cbc = (cbc128_f)HWAES_cbc_encrypt; + else +#endif +#ifdef HWAES_ecb_encrypt + if (dat->mode == EVP_CIPH_ECB_MODE) + dat->stream.ecb = (ecb128_f)HWAES_ecb_encrypt; + else +#endif +#ifdef HWAES_ctr32_encrypt_blocks + if (dat->mode == EVP_CIPH_CTR_MODE) + dat->stream.ctr = (ctr128_f)HWAES_ctr32_encrypt_blocks; + else +#endif + (void)0; /* terminate potentially open 'else' */ + } else +#endif +#ifdef BSAES_CAPABLE + if (BSAES_CAPABLE && dat->mode == EVP_CIPH_CTR_MODE) { + ret = AES_set_encrypt_key(key, (int)(keylen * 8), ks); + dat->block = (block128_f)AES_encrypt; + dat->stream.ctr = (ctr128_f)ossl_bsaes_ctr32_encrypt_blocks; + } else +#endif +#ifdef VPAES_CAPABLE + if (VPAES_CAPABLE) { + ret = vpaes_set_encrypt_key(key, (int)(keylen * 8), ks); + dat->block = (block128_f)vpaes_encrypt; + dat->stream.cbc = (dat->mode == EVP_CIPH_CBC_MODE) + ? (cbc128_f)vpaes_cbc_encrypt + : NULL; + } else +#endif + { + ret = AES_set_encrypt_key(key, (int)(keylen * 8), ks); + dat->block = (block128_f)AES_encrypt; + dat->stream.cbc = (dat->mode == EVP_CIPH_CBC_MODE) + ? (cbc128_f)AES_cbc_encrypt + : NULL; +#ifdef AES_CTR_ASM + if (dat->mode == EVP_CIPH_CTR_MODE) + dat->stream.ctr = (ctr128_f)AES_ctr32_encrypt; +#endif + } - int ret = fn_set_key(key, (int)(keylen * 8), ks); if (ret < 0) { ERR_raise(ERR_LIB_PROV, PROV_R_KEY_SETUP_FAILED); return 0; } - ctx->ks = ks; - - ctx->block = (block128_f)fn_block; - - switch (ctx->mode) { - case EVP_CIPH_ECB_MODE: - ctx->stream.ecb = fn_ecb; - break; - case EVP_CIPH_CBC_MODE: - ctx->stream.cbc = fn_cbc; - break; - case EVP_CIPH_CTR_MODE: - ctx->stream.ctr = fn_ctr; - break; - default: - memset(&ctx->stream, 0, sizeof(ctx->stream)); - break; - } return 1; } -#ifdef HWAES_CAPABLE -static int hwaes_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - if (HWAES_CAPABLE) { - ecb128_f fn_ecb = NULL; - cbc128_f fn_cbc = NULL; - ctr128_f fn_ctr = NULL; -#ifdef HWAES_ecb_encrypt - fn_ecb = (ecb128_f)HWAES_ecb_encrypt; -#endif -#ifdef HWAES_cbc_encrypt - fn_cbc = (cbc128_f)HWAES_cbc_encrypt; -#endif -#ifdef HWAES_ctr32_encrypt_blocks - fn_ctr = (ctr128_f)HWAES_ctr32_encrypt_blocks; -#endif - if ((ctx->mode == EVP_CIPH_ECB_MODE || ctx->mode == EVP_CIPH_CBC_MODE) - && !ctx->enc) - return ossl_cipher_set_aes_initkey(ctx, key, keylen, - HWAES_set_decrypt_key, HWAES_decrypt, fn_ecb, fn_cbc, fn_ctr); - else - return ossl_cipher_set_aes_initkey(ctx, key, keylen, - HWAES_set_encrypt_key, HWAES_encrypt, fn_ecb, fn_cbc, fn_ctr); +IMPLEMENT_CIPHER_HW_COPYCTX(cipher_hw_aes_copyctx, PROV_AES_CTX) + +#define PROV_CIPHER_HW_aes_mode(mode) \ + static const PROV_CIPHER_HW aes_##mode = { \ + cipher_hw_aes_initkey, \ + ossl_cipher_hw_generic_##mode, \ + cipher_hw_aes_copyctx \ + }; \ + PROV_CIPHER_HW_declare(mode) \ + const PROV_CIPHER_HW * \ + ossl_prov_cipher_hw_aes_##mode(size_t keybits) \ + { \ + PROV_CIPHER_HW_select(mode) return &aes_##mode; \ } - return -1; -} -#endif /* HWAES_CAPABLE */ - -#ifdef BSAES_CAPABLE -static int bsaes_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - if (BSAES_CAPABLE) { - if (ctx->mode == EVP_CIPH_CBC_MODE && !ctx->enc) - return ossl_cipher_set_aes_initkey(ctx, key, keylen, - AES_set_decrypt_key, AES_decrypt, NULL, - (cbc128_f)ossl_bsaes_cbc_encrypt, NULL); - else if (ctx->mode == EVP_CIPH_CTR_MODE) - return ossl_cipher_set_aes_initkey(ctx, key, keylen, - AES_set_encrypt_key, AES_encrypt, NULL, NULL, - (ctr128_f)ossl_bsaes_ctr32_encrypt_blocks); - } - return -1; -} -#endif /* BSAES_CAPABLE */ - -#ifdef VPAES_CAPABLE -static int vpaes_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - if (VPAES_CAPABLE) { - if ((ctx->mode == EVP_CIPH_ECB_MODE || ctx->mode == EVP_CIPH_CBC_MODE) - && !ctx->enc) { - return ossl_cipher_set_aes_initkey(ctx, key, keylen, - vpaes_set_decrypt_key, vpaes_decrypt, NULL, - (cbc128_f)vpaes_cbc_encrypt, NULL); - } else { - return ossl_cipher_set_aes_initkey(ctx, key, keylen, - vpaes_set_encrypt_key, vpaes_encrypt, NULL, - (cbc128_f)vpaes_cbc_encrypt, NULL); - } - } - return -1; -} -#endif /* VPAES_CAPABLE */ - -int ossl_cipher_hw_aes_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - int ret = 0; - -#ifdef HWAES_CAPABLE - ret = hwaes_initkey(ctx, key, keylen); - if (ret >= 0) - return ret; -#endif - -#ifdef BSAES_CAPABLE - ret = bsaes_initkey(ctx, key, keylen); - if (ret >= 0) - return ret; -#endif - -#ifdef VPAES_CAPABLE - ret = vpaes_initkey(ctx, key, keylen); - if (ret >= 0) - return ret; -#endif - - if ((ctx->mode == EVP_CIPH_ECB_MODE || ctx->mode == EVP_CIPH_CBC_MODE) - && !ctx->enc) { - ret = ossl_cipher_set_aes_initkey(ctx, key, keylen, - AES_set_decrypt_key, AES_decrypt, NULL, (cbc128_f)AES_cbc_encrypt, - NULL); - } else { - ctr128_f fn_ctr = NULL; -#ifdef AES_CTR_ASM - fn_ctr = (ctr128_f)AES_ctr32_encrypt; -#endif - ret = ossl_cipher_set_aes_initkey(ctx, key, keylen, - AES_set_encrypt_key, AES_encrypt, NULL, (cbc128_f)AES_cbc_encrypt, - fn_ctr); - } - - return ret; -} - -void ossl_cipher_aes_copyctx(PROV_CIPHER_CTX *dst, - const PROV_CIPHER_CTX *src) -{ - PROV_AES_CTX *sctx = (PROV_AES_CTX *)src; - PROV_AES_CTX *dctx = (PROV_AES_CTX *)dst; - - *dctx = *sctx; - dst->ks = &dctx->ks.ks; -} - -static const PROV_CIPHER_HW aes_ecb = { - ossl_cipher_hw_aes_initkey, - ossl_cipher_hw_generic_ecb, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aes_cbc = { - ossl_cipher_hw_aes_initkey, - ossl_cipher_hw_generic_cbc, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aes_cfb128 = { - ossl_cipher_hw_aes_initkey, - ossl_cipher_hw_generic_cfb128, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aes_cfb8 = { - ossl_cipher_hw_aes_initkey, - ossl_cipher_hw_generic_cfb8, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aes_cfb1 = { - ossl_cipher_hw_aes_initkey, - ossl_cipher_hw_generic_cfb1, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aes_ofb128 = { - ossl_cipher_hw_aes_initkey, - ossl_cipher_hw_generic_ofb128, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aes_ctr = { - ossl_cipher_hw_aes_initkey, - ossl_cipher_hw_generic_ctr, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_mode(enum aes_modes mode, - size_t keybits) -{ - const PROV_CIPHER_HW *aes_hw_mode = NULL; #if defined(AESNI_CAPABLE) - aes_hw_mode = ossl_prov_cipher_hw_aesni(mode); -#elif defined(ARMv8_HWAES_CAPABLE) - aes_hw_mode = ossl_prov_cipher_hw_arm(mode); -#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 32 - aes_hw_mode = ossl_prov_cipher_hw_rv32i(mode); -#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 - aes_hw_mode = ossl_prov_cipher_hw_rv64i(mode); -#elif defined(S390X_aes_128_CAPABLE) - aes_hw_mode = ossl_prov_cipher_hw_s390x(mode, keybits); +#include "cipher_aes_hw_aesni.inc" #elif defined(SPARC_AES_CAPABLE) - aes_hw_mode = ossl_prov_cipher_hw_t4(mode); +#include "cipher_aes_hw_t4.inc" +#elif defined(S390X_aes_128_CAPABLE) +#include "cipher_aes_hw_s390x.inc" +#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 +#include "cipher_aes_hw_rv64i.inc" +#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 32 +#include "cipher_aes_hw_rv32i.inc" +#elif defined(ARMv8_HWAES_CAPABLE) +#include "cipher_aes_hw_armv8.inc" +#else +/* The generic case */ +#define PROV_CIPHER_HW_declare(mode) +#define PROV_CIPHER_HW_select(mode) #endif - if (aes_hw_mode == NULL) { - switch (mode) { - case AES_MODE_ECB: - return &aes_ecb; - case AES_MODE_CBC: - return &aes_cbc; - case AES_MODE_CFB128: - return &aes_cfb128; - case AES_MODE_CFB8: - return &aes_cfb8; - case AES_MODE_CFB1: - return &aes_cfb1; - case AES_MODE_OFB128: - return &aes_ofb128; - case AES_MODE_CTR: - return &aes_ctr; - } - } - - return aes_hw_mode; -} - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_ecb(size_t keybits) -{ - return ossl_prov_cipher_hw_aes_mode(AES_MODE_ECB, keybits); -} - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_cbc(size_t keybits) -{ - return ossl_prov_cipher_hw_aes_mode(AES_MODE_CBC, keybits); -} - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_cfb128(size_t keybits) -{ - return ossl_prov_cipher_hw_aes_mode(AES_MODE_CFB128, keybits); -} - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_cfb8(size_t keybits) -{ - return ossl_prov_cipher_hw_aes_mode(AES_MODE_CFB8, keybits); -} - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_cfb1(size_t keybits) -{ - return ossl_prov_cipher_hw_aes_mode(AES_MODE_CFB1, keybits); -} - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_ofb128(size_t keybits) -{ - return ossl_prov_cipher_hw_aes_mode(AES_MODE_OFB128, keybits); -} - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_ctr(size_t keybits) -{ - return ossl_prov_cipher_hw_aes_mode(AES_MODE_CTR, keybits); -} +PROV_CIPHER_HW_aes_mode(cbc) + PROV_CIPHER_HW_aes_mode(ecb) + PROV_CIPHER_HW_aes_mode(ofb128) + PROV_CIPHER_HW_aes_mode(ctr) diff --git a/providers/implementations/ciphers/cipher_aes_hw_aesni.c b/providers/implementations/ciphers/cipher_aes_hw_aesni.c deleted file mode 100644 index f8ae45129b..0000000000 --- a/providers/implementations/ciphers/cipher_aes_hw_aesni.c +++ /dev/null @@ -1,464 +0,0 @@ -/* - * Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/*- - * AES-NI support for all hardware accelerated AES modes. - */ - -#include "internal/deprecated.h" -#include "cipher_aes.h" -#include "cipher_aes_gcm.h" -#include "cipher_aes_ccm.h" -#include "cipher_aes_xts.h" - -#if defined(AESNI_CAPABLE) - -/* MODES: ecb, cbc, cfb, ofb, ctr */ - -/* generates AES round keys for AES-NI and VAES implementations */ -static int cipher_hw_aesni_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - if ((ctx->mode == EVP_CIPH_ECB_MODE || ctx->mode == EVP_CIPH_CBC_MODE) - && !ctx->enc) { - return ossl_cipher_set_aes_initkey(ctx, key, keylen, - aesni_set_decrypt_key, aesni_decrypt, NULL, - (cbc128_f)aesni_cbc_encrypt, NULL); - } else { - return ossl_cipher_set_aes_initkey(ctx, key, keylen, - aesni_set_encrypt_key, aesni_encrypt, NULL, - (cbc128_f)aesni_cbc_encrypt, (ctr128_f)aesni_ctr32_encrypt_blocks); - } -} - -static int cipher_hw_aesni_ecb(PROV_CIPHER_CTX *ctx, unsigned char *out, - const unsigned char *in, size_t len) -{ - if (len < ctx->blocksize) - return 1; - - aesni_ecb_encrypt(in, out, len, ctx->ks, ctx->enc); - - return 1; -} - -static const PROV_CIPHER_HW aesni_ecb = { - cipher_hw_aesni_initkey, - cipher_hw_aesni_ecb, - ossl_cipher_aes_copyctx -}; - -static int cipher_hw_aesni_cbc(PROV_CIPHER_CTX *ctx, unsigned char *out, - const unsigned char *in, size_t len) -{ - aesni_cbc_encrypt(in, out, len, ctx->ks, ctx->iv, ctx->enc); - - return 1; -} - -static const PROV_CIPHER_HW aesni_cbc = { - cipher_hw_aesni_initkey, - cipher_hw_aesni_cbc, - ossl_cipher_aes_copyctx -}; - -#if (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)) -/* active in 64-bit builds when AES-NI, AVX512F, and VAES are detected */ -#define VAES_CFB128_ELIGIBLE 1 -#else -#define VAES_CFB128_ELIGIBLE 0 -#endif - -#if VAES_CFB128_ELIGIBLE -static int aes_cfb128_vaes_encdec_wrapper( - PROV_CIPHER_CTX *ctx, - unsigned char *out, - const unsigned char *in, - size_t len) -{ - ossl_ssize_t num; - - num = (ossl_ssize_t)ctx->num; - - if (num < 0) { - /* behavior from CRYPTO_cfb128_encrypt */ - ctx->num = -1; - return 1; - } - - if (ctx->enc) - ossl_aes_cfb128_vaes_enc(in, out, len, ctx->ks, ctx->iv, &num); - else - ossl_aes_cfb128_vaes_dec(in, out, len, ctx->ks, ctx->iv, &num); - - ctx->num = (int)num; - - return 1; -} - -static const PROV_CIPHER_HW aesni_vaes_cfb128 = { - cipher_hw_aesni_initkey, - aes_cfb128_vaes_encdec_wrapper, - ossl_cipher_aes_copyctx -}; -#endif /* VAES_CFB128_ELIGIBLE */ - -static const PROV_CIPHER_HW aesni_cfb128 = { - cipher_hw_aesni_initkey, - ossl_cipher_hw_generic_cfb128, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aesni_cfb8 = { - cipher_hw_aesni_initkey, - ossl_cipher_hw_generic_cfb8, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aesni_cfb1 = { - cipher_hw_aesni_initkey, - ossl_cipher_hw_generic_cfb1, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aesni_ofb128 = { - cipher_hw_aesni_initkey, - ossl_cipher_hw_generic_ofb128, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aesni_ctr = { - cipher_hw_aesni_initkey, - ossl_cipher_hw_generic_ctr, - ossl_cipher_aes_copyctx -}; - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aesni(enum aes_modes mode) -{ - if (AESNI_CAPABLE) { - switch (mode) { - case AES_MODE_ECB: - return &aesni_ecb; - case AES_MODE_CBC: - return &aesni_cbc; - case AES_MODE_CFB128: -#if VAES_CFB128_ELIGIBLE - if (ossl_aes_cfb128_vaes_eligible()) - return &aesni_vaes_cfb128; -#endif - return &aesni_cfb128; - case AES_MODE_CFB8: - return &aesni_cfb8; - case AES_MODE_CFB1: - return &aesni_cfb1; - case AES_MODE_OFB128: - return &aesni_ofb128; - case AES_MODE_CTR: - return &aesni_ctr; - default: - return NULL; - } - } - return NULL; -} - -/* MODES: GCM */ - -static int aesni_gcm_initkey(PROV_GCM_CTX *ctx, const unsigned char *key, - size_t keylen) -{ - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, aesni_set_encrypt_key, - aesni_encrypt, aesni_ctr32_encrypt_blocks); -} - -static const PROV_GCM_HW aesni_gcm = { - aesni_gcm_initkey, - ossl_gcm_setiv, - ossl_gcm_aad_update, - ossl_generic_aes_gcm_cipher_update, - ossl_gcm_cipher_final, - ossl_gcm_one_shot -}; - -/*- - * AVX512 VAES + VPCLMULDQD support for AES GCM. - */ - -#undef VAES_GCM_ENABLED -#if (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)) -#define VAES_GCM_ENABLED - -/* Returns non-zero when AVX512F + VAES + VPCLMULDQD combination is available */ -int ossl_vaes_vpclmulqdq_capable(void); - -void ossl_aes_gcm_encrypt_avx512(const void *ks, void *gcm128ctx, - unsigned int *pblocklen, const unsigned char *in, size_t len, - unsigned char *out); -void ossl_aes_gcm_decrypt_avx512(const void *ks, void *gcm128ctx, - unsigned int *pblocklen, const unsigned char *in, size_t len, - unsigned char *out); - -void ossl_aes_gcm_init_avx512(const void *ks, void *gcm128ctx); -void ossl_aes_gcm_setiv_avx512(const void *ks, void *gcm128ctx, - const unsigned char *iv, size_t ivlen); -void ossl_aes_gcm_update_aad_avx512(void *gcm128ctx, const unsigned char *aad, - size_t aadlen); -void ossl_aes_gcm_finalize_avx512(void *gcm128ctx, unsigned int pblocklen); - -void ossl_gcm_gmult_avx512(uint64_t Xi[2], const void *gcm128ctx); - -static int vaes_gcm_setkey(PROV_GCM_CTX *ctx, const unsigned char *key, - size_t keylen) -{ - GCM128_CONTEXT *gcmctx = &ctx->gcm; - PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; - AES_KEY *ks = &actx->ks.ks; - - aesni_set_encrypt_key(key, (int)(keylen * 8), ks); - memset(gcmctx, 0, sizeof(*gcmctx)); - gcmctx->key = ks; - ctx->key_set = 1; - - ossl_aes_gcm_init_avx512(ks, gcmctx); - - return 1; -} - -static int vaes_gcm_setiv(PROV_GCM_CTX *ctx, const unsigned char *iv, - size_t ivlen) -{ - GCM128_CONTEXT *gcmctx = &ctx->gcm; - - gcmctx->Yi.u[0] = 0; /* Current counter */ - gcmctx->Yi.u[1] = 0; - gcmctx->Xi.u[0] = 0; /* AAD hash */ - gcmctx->Xi.u[1] = 0; - gcmctx->len.u[0] = 0; /* AAD length */ - gcmctx->len.u[1] = 0; /* Message length */ - gcmctx->ares = 0; - gcmctx->mres = 0; - - /* IV is limited by 2^64 bits, thus 2^61 bytes */ - if (ivlen > (U64(1) << 61)) - return 0; - - ossl_aes_gcm_setiv_avx512(gcmctx->key, gcmctx, iv, ivlen); - - return 1; -} - -static int vaes_gcm_aadupdate(PROV_GCM_CTX *ctx, - const unsigned char *aad, - size_t aad_len) -{ - GCM128_CONTEXT *gcmctx = &ctx->gcm; - uint64_t alen = gcmctx->len.u[0]; - unsigned int ares; - size_t i, lenBlks; - - /* Bad sequence: call of AAD update after message processing */ - if (gcmctx->len.u[1] > 0) - return 0; - - alen += aad_len; - /* AAD is limited by 2^64 bits, thus 2^61 bytes */ - if ((alen > (U64(1) << 61)) || (alen < aad_len)) - return 0; - - gcmctx->len.u[0] = alen; - - ares = gcmctx->ares; - /* Partial AAD block left from previous AAD update calls */ - if (ares > 0) { - /* - * Fill partial block buffer till full block - * (note, the hash is stored reflected) - */ - while (ares > 0 && aad_len > 0) { - gcmctx->Xi.c[15 - ares] ^= *(aad++); - --aad_len; - ares = (ares + 1) % AES_BLOCK_SIZE; - } - /* Full block gathered */ - if (ares == 0) { - ossl_gcm_gmult_avx512(gcmctx->Xi.u, gcmctx); - } else { /* no more AAD */ - gcmctx->ares = ares; - return 1; - } - } - - /* Bulk AAD processing */ - lenBlks = aad_len & ((size_t)(-AES_BLOCK_SIZE)); - if (lenBlks > 0) { - ossl_aes_gcm_update_aad_avx512(gcmctx, aad, lenBlks); - aad += lenBlks; - aad_len -= lenBlks; - } - - /* Add remaining AAD to the hash (note, the hash is stored reflected) */ - if (aad_len > 0) { - ares = (unsigned int)aad_len; - for (i = 0; i < aad_len; i++) - gcmctx->Xi.c[15 - i] ^= aad[i]; - } - - gcmctx->ares = ares; - - return 1; -} - -static int vaes_gcm_cipherupdate(PROV_GCM_CTX *ctx, const unsigned char *in, - size_t len, unsigned char *out) -{ - GCM128_CONTEXT *gcmctx = &ctx->gcm; - uint64_t mlen = gcmctx->len.u[1]; - - mlen += len; - if (mlen > ((U64(1) << 36) - 32) || (mlen < len)) - return 0; - - gcmctx->len.u[1] = mlen; - - /* Finalize GHASH(AAD) if AAD partial blocks left unprocessed */ - if (gcmctx->ares > 0) { - ossl_gcm_gmult_avx512(gcmctx->Xi.u, gcmctx); - gcmctx->ares = 0; - } - - if (ctx->enc) - ossl_aes_gcm_encrypt_avx512(gcmctx->key, gcmctx, &gcmctx->mres, in, len, out); - else - ossl_aes_gcm_decrypt_avx512(gcmctx->key, gcmctx, &gcmctx->mres, in, len, out); - - return 1; -} - -static int vaes_gcm_cipherfinal(PROV_GCM_CTX *ctx, unsigned char *tag) -{ - GCM128_CONTEXT *gcmctx = &ctx->gcm; - unsigned int *res = &gcmctx->mres; - - /* Finalize AAD processing */ - if (gcmctx->ares > 0) - res = &gcmctx->ares; - - ossl_aes_gcm_finalize_avx512(gcmctx, *res); - - if (ctx->enc) { - ctx->taglen = GCM_TAG_MAX_SIZE; - memcpy(tag, gcmctx->Xi.c, - ctx->taglen <= sizeof(gcmctx->Xi.c) ? ctx->taglen : sizeof(gcmctx->Xi.c)); - *res = 0; - } else { - return !CRYPTO_memcmp(gcmctx->Xi.c, tag, ctx->taglen); - } - - return 1; -} - -static const PROV_GCM_HW vaes_gcm = { - vaes_gcm_setkey, - vaes_gcm_setiv, - vaes_gcm_aadupdate, - vaes_gcm_cipherupdate, - vaes_gcm_cipherfinal, - ossl_gcm_one_shot -}; - -#endif - -const PROV_GCM_HW *ossl_prov_aes_hw_gcm_aesni(void) -{ -#ifdef VAES_GCM_ENABLED - if (ossl_vaes_vpclmulqdq_capable()) - return &vaes_gcm; -#endif - if (AESNI_CAPABLE) - return &aesni_gcm; - - return NULL; -} - -/* MODES: CCM */ - -static int ccm_aesni_initkey(PROV_CCM_CTX *ctx, const unsigned char *key, - size_t keylen) -{ - return ossl_cipher_set_ccm_aes_initkey(ctx, key, keylen, - aesni_set_encrypt_key, aesni_encrypt, aesni_ccm64_encrypt_blocks, - aesni_ccm64_decrypt_blocks); -} - -static const PROV_CCM_HW aesni_ccm = { - ccm_aesni_initkey, - ossl_ccm_generic_setiv, - ossl_ccm_generic_setaad, - ossl_ccm_generic_auth_encrypt, - ossl_ccm_generic_auth_decrypt, - ossl_ccm_generic_gettag -}; - -const PROV_CCM_HW *ossl_prov_aes_hw_ccm_aesni(void) -{ - if (AESNI_CAPABLE) - return &aesni_ccm; - return NULL; -} - -/* MODES: XTS */ - -static int cipher_hw_aesni_xts_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - void (*aesni_xts_enc)(const unsigned char *in, - unsigned char *out, - size_t length, - const AES_KEY *key1, const AES_KEY *key2, - const unsigned char iv[16]); - void (*aesni_xts_dec)(const unsigned char *in, - unsigned char *out, - size_t length, - const AES_KEY *key1, const AES_KEY *key2, - const unsigned char iv[16]); - - aesni_xts_enc = aesni_xts_encrypt; - aesni_xts_dec = aesni_xts_decrypt; - -#if (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)) - if (aesni_xts_avx512_eligible()) { - if (keylen == 64) { - aesni_xts_enc = aesni_xts_256_encrypt_avx512; - aesni_xts_dec = aesni_xts_256_decrypt_avx512; - } else if (keylen == 32) { - aesni_xts_enc = aesni_xts_128_encrypt_avx512; - aesni_xts_dec = aesni_xts_128_decrypt_avx512; - } - } -#endif - - return ossl_cipher_set_aes_xts_initkey(ctx, key, keylen, - aesni_set_encrypt_key, aesni_set_decrypt_key, - aesni_encrypt, aesni_decrypt, aesni_xts_enc, aesni_xts_dec); -} - -static const PROV_CIPHER_HW aesni_xts = { - cipher_hw_aesni_xts_initkey, - NULL, - ossl_cipher_hw_aes_xts_copyctx -}; - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_xts_aesni(void) -{ - if (AESNI_CAPABLE) - return &aesni_xts; - return NULL; -} - -#endif diff --git a/providers/implementations/ciphers/cipher_aes_hw_aesni.inc b/providers/implementations/ciphers/cipher_aes_hw_aesni.inc new file mode 100644 index 0000000000..7b7084aea7 --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_hw_aesni.inc @@ -0,0 +1,81 @@ +/* + * Copyright 2001-2025 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * AES-NI support for AES modes ecb, cbc, ofb, ctr. + * This file is included by cipher_aes_hw.c + */ + +#define cipher_hw_aesni_ofb128 ossl_cipher_hw_generic_ofb128 +#define cipher_hw_aesni_ctr ossl_cipher_hw_generic_ctr + +static int cipher_hw_aesni_initkey(PROV_CIPHER_CTX *dat, + const unsigned char *key, size_t keylen) +{ + int ret; + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + AES_KEY *ks = &adat->ks.ks; + + dat->ks = ks; + + if ((dat->mode == EVP_CIPH_ECB_MODE || dat->mode == EVP_CIPH_CBC_MODE) + && !dat->enc) { + ret = aesni_set_decrypt_key(key, (int)(keylen * 8), ks); + dat->block = (block128_f) aesni_decrypt; + dat->stream.cbc = dat->mode == EVP_CIPH_CBC_MODE ? + (cbc128_f) aesni_cbc_encrypt : NULL; + } else { + ret = aesni_set_encrypt_key(key, (int)(keylen * 8), ks); + dat->block = (block128_f) aesni_encrypt; + if (dat->mode == EVP_CIPH_CBC_MODE) + dat->stream.cbc = (cbc128_f) aesni_cbc_encrypt; + else if (dat->mode == EVP_CIPH_CTR_MODE) + dat->stream.ctr = (ctr128_f) aesni_ctr32_encrypt_blocks; + else + dat->stream.cbc = NULL; + } + + if (ret < 0) { + ERR_raise(ERR_LIB_PROV, PROV_R_KEY_SETUP_FAILED); + return 0; + } + + return 1; +} + +static int cipher_hw_aesni_cbc(PROV_CIPHER_CTX *ctx, unsigned char *out, + const unsigned char *in, size_t len) +{ + const AES_KEY *ks = ctx->ks; + + aesni_cbc_encrypt(in, out, len, ks, ctx->iv, ctx->enc); + + return 1; +} + +static int cipher_hw_aesni_ecb(PROV_CIPHER_CTX *ctx, unsigned char *out, + const unsigned char *in, size_t len) +{ + if (len < ctx->blocksize) + return 1; + + aesni_ecb_encrypt(in, out, len, ctx->ks, ctx->enc); + + return 1; +} + +#define PROV_CIPHER_HW_declare(mode) \ +static const PROV_CIPHER_HW aesni_##mode = { \ + cipher_hw_aesni_initkey, \ + cipher_hw_aesni_##mode, \ + cipher_hw_aes_copyctx \ +}; +#define PROV_CIPHER_HW_select(mode) \ +if (AESNI_CAPABLE) \ + return &aesni_##mode; diff --git a/providers/implementations/ciphers/cipher_aes_hw_armv8.c b/providers/implementations/ciphers/cipher_aes_hw_armv8.c deleted file mode 100644 index 673206b6d2..0000000000 --- a/providers/implementations/ciphers/cipher_aes_hw_armv8.c +++ /dev/null @@ -1,145 +0,0 @@ -/* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* - * ARMv8 support for all hardware accelerated AES modes. - */ - -#include "internal/deprecated.h" -#include "cipher_aes.h" -#include "cipher_aes_gcm.h" - -#if defined(ARMv8_HWAES_CAPABLE) - -/* MODES: ctr */ - -static int cipher_hw_aes_arm_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - if (!ossl_cipher_hw_aes_initkey(ctx, key, keylen)) - return 0; - - if (AES_UNROLL12_EOR3_CAPABLE && ctx->mode == EVP_CIPH_CTR_MODE) - ctx->stream.ctr = (ctr128_f)HWAES_ctr32_encrypt_blocks_unroll12_eor3; - - return 1; -} - -static const PROV_CIPHER_HW arm_ctr = { - cipher_hw_aes_arm_initkey, - ossl_cipher_hw_generic_ctr, - ossl_cipher_aes_copyctx -}; - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_arm(enum aes_modes mode) -{ - if (ARMv8_HWAES_CAPABLE && mode == AES_MODE_CTR) - return &arm_ctr; - return NULL; -} - -#endif - -/* MODES: GCM */ - -#if defined(AES_PMULL_CAPABLE) && defined(AES_GCM_ASM) - -size_t armv8_aes_gcm_encrypt(const unsigned char *in, unsigned char *out, size_t len, - const void *key, unsigned char ivec[16], uint64_t *Xi) -{ - AES_KEY *aes_key = (AES_KEY *)key; - size_t align_bytes = len - len % 16; - - switch (aes_key->rounds) { - case 10: - if (IS_CPU_SUPPORT_UNROLL8_EOR3()) { - unroll8_eor3_aes_gcm_enc_128_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); - } else { - aes_gcm_enc_128_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); - } - break; - case 12: - if (IS_CPU_SUPPORT_UNROLL8_EOR3()) { - unroll8_eor3_aes_gcm_enc_192_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); - } else { - aes_gcm_enc_192_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); - } - break; - case 14: - if (IS_CPU_SUPPORT_UNROLL8_EOR3()) { - unroll8_eor3_aes_gcm_enc_256_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); - } else { - aes_gcm_enc_256_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); - } - break; - } - return align_bytes; -} - -size_t armv8_aes_gcm_decrypt(const unsigned char *in, unsigned char *out, size_t len, - const void *key, unsigned char ivec[16], uint64_t *Xi) -{ - AES_KEY *aes_key = (AES_KEY *)key; - size_t align_bytes = len - len % 16; - - switch (aes_key->rounds) { - case 10: - if (IS_CPU_SUPPORT_UNROLL8_EOR3()) { - unroll8_eor3_aes_gcm_dec_128_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); - } else { - aes_gcm_dec_128_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); - } - break; - case 12: - if (IS_CPU_SUPPORT_UNROLL8_EOR3()) { - unroll8_eor3_aes_gcm_dec_192_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); - } else { - aes_gcm_dec_192_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); - } - break; - case 14: - if (IS_CPU_SUPPORT_UNROLL8_EOR3()) { - unroll8_eor3_aes_gcm_dec_256_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); - } else { - aes_gcm_dec_256_kernel(in, align_bytes * 8, out, (uint64_t *)Xi, ivec, key); - } - break; - } - return align_bytes; -} - -static int armv8_aes_gcm_initkey(PROV_GCM_CTX *ctx, const unsigned char *key, - size_t keylen) -{ - if (AES_UNROLL12_EOR3_CAPABLE) { - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, - aes_v8_set_encrypt_key, aes_v8_encrypt, - aes_v8_ctr32_encrypt_blocks_unroll12_eor3); - } else { - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, - aes_v8_set_encrypt_key, aes_v8_encrypt, - aes_v8_ctr32_encrypt_blocks); - } -} - -static const PROV_GCM_HW armv8_aes_gcm = { - armv8_aes_gcm_initkey, - ossl_gcm_setiv, - ossl_gcm_aad_update, - ossl_generic_aes_gcm_cipher_update, - ossl_gcm_cipher_final, - ossl_gcm_one_shot -}; - -const PROV_GCM_HW *ossl_prov_aes_hw_gcm_armv8(void) -{ - return AES_PMULL_CAPABLE ? &armv8_aes_gcm : NULL; -} - -#endif diff --git a/providers/implementations/ciphers/cipher_aes_hw_armv8.inc b/providers/implementations/ciphers/cipher_aes_hw_armv8.inc new file mode 100644 index 0000000000..3f73c79290 --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_hw_armv8.inc @@ -0,0 +1,34 @@ +/* + * Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/* + * Crypto extension support for AES modes ecb, cbc, ofb, cfb, ctr. + * This file is included by cipher_aes_hw.c + */ + +static int cipher_hw_aes_arm_initkey(PROV_CIPHER_CTX *dat, + const unsigned char *key, + size_t keylen) +{ + int ret = cipher_hw_aes_initkey(dat, key, keylen); + if (AES_UNROLL12_EOR3_CAPABLE && dat->mode == EVP_CIPH_CTR_MODE) + dat->stream.ctr = (ctr128_f)HWAES_ctr32_encrypt_blocks_unroll12_eor3; + + return ret; +} + +#define PROV_CIPHER_HW_declare(mode) \ +static const PROV_CIPHER_HW aes_arm_##mode = { \ + cipher_hw_aes_arm_initkey, \ + ossl_cipher_hw_generic_##mode, \ + cipher_hw_aes_copyctx \ +}; +#define PROV_CIPHER_HW_select(mode) \ +if (ARMv8_HWAES_CAPABLE) \ + return &aes_arm_##mode; diff --git a/providers/implementations/ciphers/cipher_aes_hw_rv32i.c b/providers/implementations/ciphers/cipher_aes_hw_rv32i.c deleted file mode 100644 index eeb26a8948..0000000000 --- a/providers/implementations/ciphers/cipher_aes_hw_rv32i.c +++ /dev/null @@ -1,211 +0,0 @@ -/* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/*- - * RISC-V 32 ZKND ZKNE support for all hardware accelerated AES modes. - */ - -#include "internal/deprecated.h" -#include "cipher_aes.h" -#include "cipher_aes_gcm.h" -#include "cipher_aes_ccm.h" -#include "cipher_aes_xts.h" - -#if defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 32 - -/* MODES: ecb, cbc, cfb, ofb, ctr */ - -static int cipher_hw_rv32i_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - if ((ctx->mode == EVP_CIPH_ECB_MODE || ctx->mode == EVP_CIPH_CBC_MODE) - && !ctx->enc) { - if (RISCV_HAS_ZBKB_AND_ZKND_AND_ZKNE()) - return ossl_cipher_set_aes_initkey(ctx, key, keylen, - rv32i_zbkb_zknd_zkne_set_decrypt_key, rv32i_zknd_decrypt, - NULL, NULL, NULL); - else - return ossl_cipher_set_aes_initkey(ctx, key, keylen, - rv32i_zknd_zkne_set_decrypt_key, rv32i_zknd_decrypt, - NULL, NULL, NULL); - } else { - if (RISCV_HAS_ZBKB_AND_ZKND_AND_ZKNE()) - return ossl_cipher_set_aes_initkey(ctx, key, keylen, - rv32i_zbkb_zkne_set_encrypt_key, rv32i_zkne_encrypt, - NULL, NULL, NULL); - else - return ossl_cipher_set_aes_initkey(ctx, key, keylen, - rv32i_zkne_set_encrypt_key, rv32i_zkne_encrypt, - NULL, NULL, NULL); - } -} - -static const PROV_CIPHER_HW rv32i_ecb = { - cipher_hw_rv32i_initkey, - ossl_cipher_hw_generic_ecb, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW rv32i_cbc = { - cipher_hw_rv32i_initkey, - ossl_cipher_hw_generic_cbc, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW rv32i_cfb128 = { - cipher_hw_rv32i_initkey, - ossl_cipher_hw_generic_cfb128, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW rv32i_cfb8 = { - cipher_hw_rv32i_initkey, - ossl_cipher_hw_generic_cfb8, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW rv32i_cfb1 = { - cipher_hw_rv32i_initkey, - ossl_cipher_hw_generic_cfb1, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW rv32i_ofb128 = { - cipher_hw_rv32i_initkey, - ossl_cipher_hw_generic_ofb128, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW rv32i_ctr = { - cipher_hw_rv32i_initkey, - ossl_cipher_hw_generic_ctr, - ossl_cipher_aes_copyctx -}; - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_rv32i(enum aes_modes mode) -{ - if (RISCV_HAS_ZKND_AND_ZKNE()) { - switch (mode) { - case AES_MODE_ECB: - return &rv32i_ecb; - case AES_MODE_CBC: - return &rv32i_cbc; - case AES_MODE_CFB128: - return &rv32i_cfb128; - case AES_MODE_CFB8: - return &rv32i_cfb8; - case AES_MODE_CFB1: - return &rv32i_cfb1; - case AES_MODE_OFB128: - return &rv32i_ofb128; - case AES_MODE_CTR: - return &rv32i_ctr; - default: - return NULL; - } - } - return NULL; -} - -/* MODES: GCM */ - -static int aes_gcm_rv32i_initkey(PROV_GCM_CTX *ctx, - const unsigned char *key, - size_t keylen) -{ - if (RISCV_HAS_ZBKB_AND_ZKND_AND_ZKNE()) { - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, - rv32i_zbkb_zkne_set_encrypt_key, rv32i_zkne_encrypt, NULL); - } else if (RISCV_HAS_ZKND_AND_ZKNE()) { - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, - rv32i_zkne_set_encrypt_key, rv32i_zkne_encrypt, NULL); - } - return 0; -} - -static const PROV_GCM_HW aes_gcm_rv32i = { - aes_gcm_rv32i_initkey, - ossl_gcm_setiv, - ossl_gcm_aad_update, - ossl_generic_aes_gcm_cipher_update, - ossl_gcm_cipher_final, - ossl_gcm_one_shot -}; - -const PROV_GCM_HW *ossl_prov_aes_hw_gcm_rv32i(void) -{ - if (RISCV_HAS_ZKND_AND_ZKNE()) - return &aes_gcm_rv32i; - return NULL; -} - -/* MODES: CCM */ - -static int aes_ccm_rv32i_initkey(PROV_CCM_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - if (RISCV_HAS_ZBKB_AND_ZKND_AND_ZKNE()) { - return ossl_cipher_set_ccm_aes_initkey(ctx, key, keylen, - rv32i_zbkb_zkne_set_encrypt_key, rv32i_zkne_encrypt, NULL, NULL); - } else if (RISCV_HAS_ZKND_AND_ZKNE()) { - return ossl_cipher_set_ccm_aes_initkey(ctx, key, keylen, - rv32i_zkne_set_encrypt_key, rv32i_zkne_encrypt, NULL, NULL); - } - return 0; -} - -static const PROV_CCM_HW aes_ccm_rv32i = { - aes_ccm_rv32i_initkey, - ossl_ccm_generic_setiv, - ossl_ccm_generic_setaad, - ossl_ccm_generic_auth_encrypt, - ossl_ccm_generic_auth_decrypt, - ossl_ccm_generic_gettag -}; - -const PROV_CCM_HW *ossl_prov_aes_hw_ccm_rv32i(void) -{ - if (RISCV_HAS_ZKND_AND_ZKNE()) - return &aes_ccm_rv32i; - return NULL; -} - -/* MODES: XTS */ - -static int cipher_hw_aes_xts_rv32i_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - if (RISCV_HAS_ZBKB_AND_ZKND_AND_ZKNE()) - return ossl_cipher_set_aes_xts_initkey(ctx, key, keylen, - rv32i_zbkb_zkne_set_encrypt_key, - rv32i_zbkb_zknd_zkne_set_decrypt_key, - rv32i_zkne_encrypt, rv32i_zknd_decrypt, NULL, NULL); - - if (RISCV_HAS_ZKND_AND_ZKNE()) - return ossl_cipher_set_aes_xts_initkey(ctx, key, keylen, - rv32i_zkne_set_encrypt_key, rv32i_zknd_zkne_set_decrypt_key, - rv32i_zkne_encrypt, rv32i_zknd_decrypt, NULL, NULL); - - return 0; -} - -static const PROV_CIPHER_HW aes_xts_rv32i = { - cipher_hw_aes_xts_rv32i_initkey, - NULL, - ossl_cipher_hw_aes_xts_copyctx -}; - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_xts_rv32i(void) -{ - if (RISCV_HAS_ZKND_AND_ZKNE()) - return &aes_xts_rv32i; - return NULL; -} - -#endif diff --git a/providers/implementations/ciphers/cipher_aes_hw_rv32i.inc b/providers/implementations/ciphers/cipher_aes_hw_rv32i.inc new file mode 100644 index 0000000000..f6c652c32d --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_hw_rv32i.inc @@ -0,0 +1,102 @@ +/* + * Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * RISC-V 32 ZKND ZKNE support for AES modes ecb, cbc, ofb, cfb, ctr. + * This file is included by cipher_aes_hw.c + */ + +#define cipher_hw_rv32i_zknd_zkne_cbc ossl_cipher_hw_generic_cbc +#define cipher_hw_rv32i_zknd_zkne_ecb ossl_cipher_hw_generic_ecb +#define cipher_hw_rv32i_zknd_zkne_ofb128 ossl_cipher_hw_generic_ofb128 +#define cipher_hw_rv32i_zknd_zkne_cfb128 ossl_cipher_hw_generic_cfb128 +#define cipher_hw_rv32i_zknd_zkne_cfb8 ossl_cipher_hw_generic_cfb8 +#define cipher_hw_rv32i_zknd_zkne_cfb1 ossl_cipher_hw_generic_cfb1 +#define cipher_hw_rv32i_zknd_zkne_ctr ossl_cipher_hw_generic_ctr + +#define cipher_hw_rv32i_zbkb_zknd_zkne_cbc ossl_cipher_hw_generic_cbc +#define cipher_hw_rv32i_zbkb_zknd_zkne_ecb ossl_cipher_hw_generic_ecb +#define cipher_hw_rv32i_zbkb_zknd_zkne_ofb128 ossl_cipher_hw_generic_ofb128 +#define cipher_hw_rv32i_zbkb_zknd_zkne_cfb128 ossl_cipher_hw_generic_cfb128 +#define cipher_hw_rv32i_zbkb_zknd_zkne_cfb8 ossl_cipher_hw_generic_cfb8 +#define cipher_hw_rv32i_zbkb_zknd_zkne_cfb1 ossl_cipher_hw_generic_cfb1 +#define cipher_hw_rv32i_zbkb_zknd_zkne_ctr ossl_cipher_hw_generic_ctr + +static int cipher_hw_rv32i_zknd_zkne_initkey(PROV_CIPHER_CTX *dat, + const unsigned char *key, size_t keylen) +{ + int ret; + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + AES_KEY *ks = &adat->ks.ks; + + dat->ks = ks; + + if ((dat->mode == EVP_CIPH_ECB_MODE || dat->mode == EVP_CIPH_CBC_MODE) + && !dat->enc) { + ret = rv32i_zknd_zkne_set_decrypt_key(key, keylen * 8, ks); + dat->block = (block128_f) rv32i_zknd_decrypt; + dat->stream.cbc = NULL; + } else { + ret = rv32i_zkne_set_encrypt_key(key, keylen * 8, ks); + dat->block = (block128_f) rv32i_zkne_encrypt; + dat->stream.cbc = NULL; + } + + if (ret < 0) { + ERR_raise(ERR_LIB_PROV, PROV_R_KEY_SETUP_FAILED); + return 0; + } + + return 1; +} + +static int cipher_hw_rv32i_zbkb_zknd_zkne_initkey(PROV_CIPHER_CTX *dat, + const unsigned char *key, size_t keylen) +{ + int ret; + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + AES_KEY *ks = &adat->ks.ks; + + dat->ks = ks; + + if ((dat->mode == EVP_CIPH_ECB_MODE || dat->mode == EVP_CIPH_CBC_MODE) + && !dat->enc) { + ret = rv32i_zbkb_zknd_zkne_set_decrypt_key(key, keylen * 8, ks); + dat->block = (block128_f) rv32i_zknd_decrypt; + dat->stream.cbc = NULL; + } else { + ret = rv32i_zbkb_zkne_set_encrypt_key(key, keylen * 8, ks); + dat->block = (block128_f) rv32i_zkne_encrypt; + dat->stream.cbc = NULL; + } + + if (ret < 0) { + ERR_raise(ERR_LIB_PROV, PROV_R_KEY_SETUP_FAILED); + return 0; + } + + return 1; +} + +#define PROV_CIPHER_HW_declare(mode) \ +static const PROV_CIPHER_HW rv32i_zknd_zkne_##mode = { \ + cipher_hw_rv32i_zknd_zkne_initkey, \ + cipher_hw_rv32i_zknd_zkne_##mode, \ + cipher_hw_aes_copyctx \ +}; \ +static const PROV_CIPHER_HW rv32i_zbkb_zknd_zkne_##mode = { \ + cipher_hw_rv32i_zbkb_zknd_zkne_initkey, \ + cipher_hw_rv32i_zbkb_zknd_zkne_##mode, \ + cipher_hw_aes_copyctx \ +}; +#define PROV_CIPHER_HW_select(mode) \ +if (RISCV_HAS_ZBKB_AND_ZKND_AND_ZKNE()) \ + return &rv32i_zbkb_zknd_zkne_##mode; \ +if (RISCV_HAS_ZKND_AND_ZKNE()) \ + return &rv32i_zknd_zkne_##mode; diff --git a/providers/implementations/ciphers/cipher_aes_hw_rv64i.c b/providers/implementations/ciphers/cipher_aes_hw_rv64i.c deleted file mode 100644 index fa1e3f2b2a..0000000000 --- a/providers/implementations/ciphers/cipher_aes_hw_rv64i.c +++ /dev/null @@ -1,348 +0,0 @@ -/* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/*- - * RISC-V 64 ZKND ZKNE / ZVKNED support for all hardware accelerated AES modes. - */ - -#include "internal/deprecated.h" -#include "cipher_aes.h" -#include "cipher_aes_gcm.h" -#include "cipher_aes_ccm.h" -#include "cipher_aes_xts.h" - -#if defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 - -static int zvkned_key_schedule_supported(size_t keylen) -{ - if (keylen * 8 == 128 || keylen * 8 == 256) { - return 1; - } - return 0; -} - -/* MODES: ecb, cbc, cfb, ofb, ctr */ - -static int cipher_hw_rv64i_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - if (RISCV_HAS_ZVKNED() && riscv_vlen() >= 128) { - /* - * Zvkned only supports 128 and 256 bit keys for key schedule - * generation. For the AES-192 case, we fallback to the generic - * `AES_set_encrypt_key`. All Zvkned-based implementations use the - * same `encrypt-key` scheduling for both encryption and decryption. - */ - aes_set_encrypt_key_fn fn_set_key = AES_set_encrypt_key; - aes_block128_f fn_block = NULL; - - if (zvkned_key_schedule_supported(keylen)) { - fn_set_key = rv64i_zvkned_set_encrypt_key; - } - ecb128_f fn_ecb = ctx->enc ? (ecb128_f)rv64i_zvkned_ecb_encrypt : (ecb128_f)rv64i_zvkned_ecb_decrypt; - cbc128_f fn_cbc = ctx->enc ? (cbc128_f)rv64i_zvkned_cbc_encrypt : (cbc128_f)rv64i_zvkned_cbc_decrypt; - ctr128_f fn_ctr = RISCV_HAS_ZVKB() ? (ctr128_f)rv64i_zvkb_zvkned_ctr32_encrypt_blocks : NULL; - - /* Zvkned supports aes-128/192/256 encryption and decryption. */ - if ((ctx->mode == EVP_CIPH_ECB_MODE || ctx->mode == EVP_CIPH_CBC_MODE) - && !ctx->enc) { - fn_block = rv64i_zvkned_decrypt; - } else { - fn_block = rv64i_zvkned_encrypt; - } - return ossl_cipher_set_aes_initkey(ctx, key, keylen, fn_set_key, - fn_block, fn_ecb, fn_cbc, fn_ctr); - } else if (RISCV_HAS_ZKND_AND_ZKNE()) { - if ((ctx->mode == EVP_CIPH_ECB_MODE || ctx->mode == EVP_CIPH_CBC_MODE) - && !ctx->enc) { - return ossl_cipher_set_aes_initkey(ctx, key, keylen, - rv64i_zknd_set_decrypt_key, rv64i_zknd_decrypt, - NULL, NULL, NULL); - } else { - return ossl_cipher_set_aes_initkey(ctx, key, keylen, - rv64i_zkne_set_encrypt_key, rv64i_zkne_encrypt, - NULL, NULL, NULL); - } - } - return 0; -} - -static const PROV_CIPHER_HW rv64i_ecb = { - cipher_hw_rv64i_initkey, - ossl_cipher_hw_generic_ecb, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW rv64i_cbc = { - cipher_hw_rv64i_initkey, - ossl_cipher_hw_generic_cbc, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW rv64i_cfb128 = { - cipher_hw_rv64i_initkey, - ossl_cipher_hw_generic_cfb128, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW rv64i_cfb8 = { - cipher_hw_rv64i_initkey, - ossl_cipher_hw_generic_cfb8, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW rv64i_cfb1 = { - cipher_hw_rv64i_initkey, - ossl_cipher_hw_generic_cfb1, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW rv64i_ofb128 = { - cipher_hw_rv64i_initkey, - ossl_cipher_hw_generic_ofb128, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW rv64i_ctr = { - cipher_hw_rv64i_initkey, - ossl_cipher_hw_generic_ctr, - ossl_cipher_aes_copyctx -}; - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_rv64i(enum aes_modes mode) -{ - if ((RISCV_HAS_ZVKNED() && riscv_vlen() >= 128) - || RISCV_HAS_ZKND_AND_ZKNE()) { - switch (mode) { - case AES_MODE_ECB: - return &rv64i_ecb; - case AES_MODE_CBC: - return &rv64i_cbc; - case AES_MODE_CFB128: - return &rv64i_cfb128; - case AES_MODE_CFB8: - return &rv64i_cfb8; - case AES_MODE_CFB1: - return &rv64i_cfb1; - case AES_MODE_OFB128: - return &rv64i_ofb128; - case AES_MODE_CTR: - return &rv64i_ctr; - default: - return NULL; - } - } - return NULL; -} - -/* MODES: GCM */ - -/*- - * RISC-V 64 ZKND and ZKNE support for AES GCM. - */ -static int rv64i_zknd_zkne_gcm_initkey(PROV_GCM_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, - rv64i_zkne_set_encrypt_key, rv64i_zkne_encrypt, NULL); -} - -static const PROV_GCM_HW rv64i_zknd_zkne_gcm = { - rv64i_zknd_zkne_gcm_initkey, - ossl_gcm_setiv, - ossl_gcm_aad_update, - ossl_generic_aes_gcm_cipher_update, - ossl_gcm_cipher_final, - ossl_gcm_one_shot -}; - -/*- - * RISC-V RV64 ZVKNED support for AES GCM. - */ -static int rv64i_zvkned_gcm_initkey(PROV_GCM_CTX *ctx, const unsigned char *key, - size_t keylen) -{ - /* - * Zvkned only supports 128 and 256 bit keys for key schedule generation. - * For AES-192 case, we could fallback to `AES_set_encrypt_key`. - */ - if (zvkned_key_schedule_supported(keylen)) { - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, - rv64i_zvkned_set_encrypt_key, rv64i_zvkned_encrypt, NULL); - } else { - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, - AES_set_encrypt_key, rv64i_zvkned_encrypt, NULL); - } -} - -static const PROV_GCM_HW rv64i_zvkned_gcm = { - rv64i_zvkned_gcm_initkey, - ossl_gcm_setiv, - ossl_gcm_aad_update, - ossl_generic_aes_gcm_cipher_update, - ossl_gcm_cipher_final, - ossl_gcm_one_shot -}; - -/*- - * RISC-V RV64 ZVKB, ZVKG and ZVKNED support for AES GCM. - */ -static int rv64i_zvkb_zvkg_zvkned_gcm_initkey(PROV_GCM_CTX *ctx, - const unsigned char *key, - size_t keylen) -{ - /* - * Zvkned only supports 128 and 256 bit keys for key schedule generation. - * For AES-192 case, we could fallback to `AES_set_encrypt_key`. - */ - if (zvkned_key_schedule_supported(keylen)) { - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, - rv64i_zvkned_set_encrypt_key, rv64i_zvkned_encrypt, - rv64i_zvkb_zvkned_ctr32_encrypt_blocks); - } else { - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, - AES_set_encrypt_key, rv64i_zvkned_encrypt, - rv64i_zvkb_zvkned_ctr32_encrypt_blocks); - } -} - -static const PROV_GCM_HW rv64i_zvkb_zvkg_zvkned_gcm = { - rv64i_zvkb_zvkg_zvkned_gcm_initkey, - ossl_gcm_setiv, - ossl_gcm_aad_update, - ossl_generic_aes_gcm_cipher_update, - ossl_gcm_cipher_final, - ossl_gcm_one_shot -}; - -const PROV_GCM_HW *ossl_prov_aes_hw_gcm_rv64i(void) -{ - if (RISCV_HAS_ZVKNED() && riscv_vlen() >= 128) { - if (RISCV_HAS_ZVKB() && RISCV_HAS_ZVKG()) - return &rv64i_zvkb_zvkg_zvkned_gcm; - return &rv64i_zvkned_gcm; - } - - if (RISCV_HAS_ZKND_AND_ZKNE()) { - return &rv64i_zknd_zkne_gcm; - } - - return NULL; -} - -/* MODES: CCM */ - -static int ccm_rv64i_zknd_zkne_initkey(PROV_CCM_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - return ossl_cipher_set_ccm_aes_initkey(ctx, key, keylen, - rv64i_zkne_set_encrypt_key, rv64i_zkne_encrypt, NULL, NULL); -} - -static const PROV_CCM_HW rv64i_zknd_zkne_ccm = { - ccm_rv64i_zknd_zkne_initkey, - ossl_ccm_generic_setiv, - ossl_ccm_generic_setaad, - ossl_ccm_generic_auth_encrypt, - ossl_ccm_generic_auth_decrypt, - ossl_ccm_generic_gettag -}; - -/*- - * RISC-V RV64 ZVKNED support for AES CCM. - * This file is included by cipher_aes_ccm_hw.c - */ - -static int ccm_rv64i_zvkned_initkey(PROV_CCM_CTX *ctx, const unsigned char *key, - size_t keylen) -{ - /* Zvkned only supports 128 and 256 bit keys for key schedule generation. */ - if (zvkned_key_schedule_supported(keylen)) { - return ossl_cipher_set_ccm_aes_initkey(ctx, key, keylen, - rv64i_zvkned_set_encrypt_key, rv64i_zvkned_encrypt, NULL, NULL); - } else { - return ossl_cipher_set_ccm_aes_initkey(ctx, key, keylen, - AES_set_encrypt_key, rv64i_zvkned_encrypt, NULL, NULL); - } -} - -static const PROV_CCM_HW rv64i_zvkned_ccm = { - ccm_rv64i_zvkned_initkey, - ossl_ccm_generic_setiv, - ossl_ccm_generic_setaad, - ossl_ccm_generic_auth_encrypt, - ossl_ccm_generic_auth_decrypt, - ossl_ccm_generic_gettag -}; - -const PROV_CCM_HW *ossl_prov_aes_hw_ccm_rv64i(void) -{ - if (RISCV_HAS_ZVKNED() && riscv_vlen() >= 128) - return &rv64i_zvkned_ccm; - else if (RISCV_HAS_ZKND_AND_ZKNE()) - return &rv64i_zknd_zkne_ccm; - else - return NULL; -} - -/* MODES: XTS */ - -static int cipher_hw_aes_xts_rv64i_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - if (RISCV_HAS_ZVBB() && RISCV_HAS_ZVKG() && RISCV_HAS_ZVKNED() && riscv_vlen() >= 128) { - /* Zvkned only supports 128 and 256 bit keys. */ - if (zvkned_key_schedule_supported(keylen / 2)) { - return ossl_cipher_set_aes_xts_initkey(ctx, key, keylen, - rv64i_zvkned_set_encrypt_key, rv64i_zvkned_set_decrypt_key, - rv64i_zvkned_encrypt, rv64i_zvkned_decrypt, - rv64i_zvbb_zvkg_zvkned_aes_xts_encrypt, - rv64i_zvbb_zvkg_zvkned_aes_xts_decrypt); - } - return ossl_cipher_set_aes_xts_initkey(ctx, key, keylen, - AES_set_encrypt_key, AES_set_encrypt_key, - rv64i_zvkned_encrypt, rv64i_zvkned_decrypt, NULL, NULL); - } - - if (RISCV_HAS_ZVKNED() && riscv_vlen() >= 128) { - /* Zvkned only supports 128 and 256 bit keys. */ - if (zvkned_key_schedule_supported(keylen / 2)) { - return ossl_cipher_set_aes_xts_initkey(ctx, key, keylen, - rv64i_zvkned_set_encrypt_key, rv64i_zvkned_set_decrypt_key, - rv64i_zvkned_encrypt, rv64i_zvkned_decrypt, NULL, NULL); - } - return ossl_cipher_set_aes_xts_initkey(ctx, key, keylen, - AES_set_encrypt_key, AES_set_encrypt_key, - rv64i_zvkned_encrypt, rv64i_zvkned_decrypt, NULL, NULL); - } - - if (RISCV_HAS_ZKND_AND_ZKNE()) { - return ossl_cipher_set_aes_xts_initkey(ctx, key, keylen, - rv64i_zkne_set_encrypt_key, rv64i_zknd_set_decrypt_key, - rv64i_zkne_encrypt, rv64i_zknd_decrypt, NULL, NULL); - } - - return 0; -} - -static const PROV_CIPHER_HW aes_xts_rv64i = { - cipher_hw_aes_xts_rv64i_initkey, - NULL, - ossl_cipher_hw_aes_xts_copyctx -}; - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_xts_rv64i(void) -{ - if ((RISCV_HAS_ZVKNED() && riscv_vlen() >= 128) - || RISCV_HAS_ZKND_AND_ZKNE()) - return &aes_xts_rv64i; - return NULL; -} - -#endif diff --git a/providers/implementations/ciphers/cipher_aes_hw_rv64i.inc b/providers/implementations/ciphers/cipher_aes_hw_rv64i.inc new file mode 100644 index 0000000000..07d479303d --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_hw_rv64i.inc @@ -0,0 +1,135 @@ +/* + * Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * RISC-V 64 ZKND ZKNE support for AES modes ecb, cbc, ofb, cfb, ctr. + * This file is included by cipher_aes_hw.c + */ + +#define cipher_hw_rv64i_zknd_zkne_cbc ossl_cipher_hw_generic_cbc +#define cipher_hw_rv64i_zknd_zkne_ecb ossl_cipher_hw_generic_ecb +#define cipher_hw_rv64i_zknd_zkne_ofb128 ossl_cipher_hw_generic_ofb128 +#define cipher_hw_rv64i_zknd_zkne_cfb128 ossl_cipher_hw_generic_cfb128 +#define cipher_hw_rv64i_zknd_zkne_cfb8 ossl_cipher_hw_generic_cfb8 +#define cipher_hw_rv64i_zknd_zkne_cfb1 ossl_cipher_hw_generic_cfb1 +#define cipher_hw_rv64i_zknd_zkne_ctr ossl_cipher_hw_generic_ctr + +static int cipher_hw_rv64i_zknd_zkne_initkey(PROV_CIPHER_CTX *dat, + const unsigned char *key, size_t keylen) +{ + int ret; + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + AES_KEY *ks = &adat->ks.ks; + + dat->ks = ks; + + if ((dat->mode == EVP_CIPH_ECB_MODE || dat->mode == EVP_CIPH_CBC_MODE) + && !dat->enc) { + ret = rv64i_zknd_set_decrypt_key(key, keylen * 8, ks); + dat->block = (block128_f) rv64i_zknd_decrypt; + dat->stream.cbc = NULL; + } else { + ret = rv64i_zkne_set_encrypt_key(key, keylen * 8, ks); + dat->block = (block128_f) rv64i_zkne_encrypt; + dat->stream.cbc = NULL; + } + + if (ret < 0) { + ERR_raise(ERR_LIB_PROV, PROV_R_KEY_SETUP_FAILED); + return 0; + } + + return 1; +} + +/*- + * RISC-V RV64 ZVKNED support for AES modes ecb, cbc, ofb, cfb, ctr. + * This file is included by cipher_aes_hw.c + */ + +#define cipher_hw_rv64i_zvkned_cbc ossl_cipher_hw_generic_cbc +#define cipher_hw_rv64i_zvkned_ecb ossl_cipher_hw_generic_ecb +#define cipher_hw_rv64i_zvkned_ofb128 ossl_cipher_hw_generic_ofb128 +#define cipher_hw_rv64i_zvkned_cfb128 ossl_cipher_hw_generic_cfb128 +#define cipher_hw_rv64i_zvkned_cfb8 ossl_cipher_hw_generic_cfb8 +#define cipher_hw_rv64i_zvkned_cfb1 ossl_cipher_hw_generic_cfb1 +#define cipher_hw_rv64i_zvkned_ctr ossl_cipher_hw_generic_ctr + +static int cipher_hw_rv64i_zvkned_initkey(PROV_CIPHER_CTX *dat, + const unsigned char *key, + size_t keylen) +{ + int ret; + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + AES_KEY *ks = &adat->ks.ks; + + dat->ks = ks; + + /* + * Zvkned only supports 128 and 256 bit keys for key schedule generation. + * For AES-192 case, we could fallback to `AES_set_encrypt_key`. + * All Zvkned-based implementations use the same `encrypt-key` scheduling + * for both encryption and decryption. + */ + if (keylen * 8 == 128 || keylen * 8 == 256) { + ret = rv64i_zvkned_set_encrypt_key(key, keylen * 8, ks); + } else { + ret = AES_set_encrypt_key(key, keylen * 8, ks); + } + + if (dat->mode == EVP_CIPH_CBC_MODE) { + if (dat->enc) { + dat->stream.cbc = (cbc128_f) rv64i_zvkned_cbc_encrypt; + } else { + dat->stream.cbc = (cbc128_f) rv64i_zvkned_cbc_decrypt; + } + } else if (dat->mode == EVP_CIPH_CTR_MODE) { + if (RISCV_HAS_ZVKB()) { + dat->stream.ctr = (ctr128_f) rv64i_zvkb_zvkned_ctr32_encrypt_blocks; + } + } else if (dat->mode == EVP_CIPH_ECB_MODE) { + if (dat->enc) { + dat->stream.ecb = (ecb128_f) rv64i_zvkned_ecb_encrypt; + } else { + dat->stream.ecb = (ecb128_f) rv64i_zvkned_ecb_decrypt; + } + } + + /* Zvkned supports aes-128/192/256 encryption and decryption. */ + if ((dat->mode == EVP_CIPH_ECB_MODE || dat->mode == EVP_CIPH_CBC_MODE) && + !dat->enc) { + dat->block = (block128_f) rv64i_zvkned_decrypt; + } else { + dat->block = (block128_f) rv64i_zvkned_encrypt; + } + + if (ret < 0) { + ERR_raise(ERR_LIB_PROV, PROV_R_KEY_SETUP_FAILED); + return 0; + } + + return 1; +} + +#define PROV_CIPHER_HW_declare(mode) \ +static const PROV_CIPHER_HW rv64i_zknd_zkne_##mode = { \ + cipher_hw_rv64i_zknd_zkne_initkey, \ + cipher_hw_rv64i_zknd_zkne_##mode, \ + cipher_hw_aes_copyctx \ +}; \ +static const PROV_CIPHER_HW rv64i_zvkned_##mode = { \ + cipher_hw_rv64i_zvkned_initkey, \ + cipher_hw_rv64i_zvkned_##mode, \ + cipher_hw_aes_copyctx \ +}; +#define PROV_CIPHER_HW_select(mode) \ +if (RISCV_HAS_ZVKNED() && riscv_vlen() >= 128) \ + return &rv64i_zvkned_##mode; \ +else if (RISCV_HAS_ZKND_AND_ZKNE()) \ + return &rv64i_zknd_zkne_##mode; diff --git a/providers/implementations/ciphers/cipher_aes_hw_s390x.c b/providers/implementations/ciphers/cipher_aes_hw_s390x.c deleted file mode 100644 index e9e81f4746..0000000000 --- a/providers/implementations/ciphers/cipher_aes_hw_s390x.c +++ /dev/null @@ -1,947 +0,0 @@ -/* - * Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* - * IBM S390X support for all hardware accelerated AES modes. - */ - -#include "internal/deprecated.h" -#include -#include "cipher_aes.h" -#include "cipher_aes_gcm.h" -#include "cipher_aes_ccm.h" -#include "cipher_aes_xts.h" -#include - -#if defined(S390X_aes_128_CAPABLE) - -/* MODES: ecb, cfb, ofb */ - -static int s390x_aes_ecb_initkey(PROV_CIPHER_CTX *dat, - const unsigned char *key, size_t keylen) -{ - PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; - - adat->plat.s390x.fc = S390X_AES_FC(keylen); - memcpy(adat->plat.s390x.param.km.k, key, keylen); - return 1; -} - -static int s390x_aes_ecb_cipher_hw(PROV_CIPHER_CTX *dat, unsigned char *out, - const unsigned char *in, size_t len) -{ - PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; - unsigned int modifier = adat->base.enc ? 0 : S390X_DECRYPT; - - s390x_km(in, len, out, adat->plat.s390x.fc | modifier, - &adat->plat.s390x.param.km); - return 1; -} - -static const PROV_CIPHER_HW s390x_aes_ecb = { - s390x_aes_ecb_initkey, - s390x_aes_ecb_cipher_hw, - ossl_cipher_aes_copyctx -}; - -static int s390x_aes_ofb128_initkey(PROV_CIPHER_CTX *dat, - const unsigned char *key, size_t keylen) -{ - PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; - - memcpy(adat->plat.s390x.param.kmo_kmf.k, key, keylen); - adat->plat.s390x.fc = S390X_AES_FC(keylen); - return 1; -} - -static int s390x_aes_ofb128_cipher_hw(PROV_CIPHER_CTX *dat, unsigned char *out, - const unsigned char *in, size_t len) -{ - PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; - int n = dat->num; - int rem; - - memcpy(adat->plat.s390x.param.kmo_kmf.cv, dat->iv, dat->ivlen); - while (n && len) { - *out = *in ^ adat->plat.s390x.param.kmo_kmf.cv[n]; - n = (n + 1) & 0xf; - --len; - ++in; - ++out; - } - - rem = len & 0xf; - - len &= ~(size_t)0xf; - if (len) { - s390x_kmo(in, len, out, adat->plat.s390x.fc, - &adat->plat.s390x.param.kmo_kmf); - - out += len; - in += len; - } - - if (rem) { - s390x_km(adat->plat.s390x.param.kmo_kmf.cv, 16, - adat->plat.s390x.param.kmo_kmf.cv, - adat->plat.s390x.fc, - adat->plat.s390x.param.kmo_kmf.k); - - while (rem--) { - out[n] = in[n] ^ adat->plat.s390x.param.kmo_kmf.cv[n]; - ++n; - } - } - - memcpy(dat->iv, adat->plat.s390x.param.kmo_kmf.cv, dat->ivlen); - dat->num = n; - return 1; -} - -static const PROV_CIPHER_HW s390x_aes_ofb128 = { - s390x_aes_ofb128_initkey, - s390x_aes_ofb128_cipher_hw, - ossl_cipher_aes_copyctx -}; - -static int s390x_aes_cfb128_initkey(PROV_CIPHER_CTX *dat, - const unsigned char *key, size_t keylen) -{ - PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; - - adat->plat.s390x.fc = S390X_AES_FC(keylen); - adat->plat.s390x.fc |= 16 << 24; /* 16 bytes cipher feedback */ - memcpy(adat->plat.s390x.param.kmo_kmf.k, key, keylen); - return 1; -} - -static int s390x_aes_cfb128_cipher_hw(PROV_CIPHER_CTX *dat, unsigned char *out, - const unsigned char *in, size_t len) -{ - PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; - unsigned int modifier = adat->base.enc ? 0 : S390X_DECRYPT; - int n = dat->num; - int rem; - unsigned char tmp; - - memcpy(adat->plat.s390x.param.kmo_kmf.cv, dat->iv, dat->ivlen); - while (n && len) { - tmp = *in; - *out = adat->plat.s390x.param.kmo_kmf.cv[n] ^ tmp; - adat->plat.s390x.param.kmo_kmf.cv[n] = dat->enc ? *out : tmp; - n = (n + 1) & 0xf; - --len; - ++in; - ++out; - } - - rem = len & 0xf; - - len &= ~(size_t)0xf; - if (len) { - s390x_kmf(in, len, out, adat->plat.s390x.fc | modifier, - &adat->plat.s390x.param.kmo_kmf); - - out += len; - in += len; - } - - if (rem) { - s390x_km(adat->plat.s390x.param.kmo_kmf.cv, 16, - adat->plat.s390x.param.kmo_kmf.cv, - S390X_AES_FC(dat->keylen), - adat->plat.s390x.param.kmo_kmf.k); - - while (rem--) { - tmp = in[n]; - out[n] = adat->plat.s390x.param.kmo_kmf.cv[n] ^ tmp; - adat->plat.s390x.param.kmo_kmf.cv[n] = dat->enc ? out[n] : tmp; - ++n; - } - } - - memcpy(dat->iv, adat->plat.s390x.param.kmo_kmf.cv, dat->ivlen); - dat->num = n; - return 1; -} - -static const PROV_CIPHER_HW s390x_aes_cfb128 = { - s390x_aes_cfb128_initkey, - s390x_aes_cfb128_cipher_hw, - ossl_cipher_aes_copyctx -}; - -static int s390x_aes_cfb8_initkey(PROV_CIPHER_CTX *dat, - const unsigned char *key, size_t keylen) -{ - PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; - - adat->plat.s390x.fc = S390X_AES_FC(keylen); - adat->plat.s390x.fc |= 1 << 24; /* 1 byte cipher feedback */ - memcpy(adat->plat.s390x.param.kmo_kmf.k, key, keylen); - return 1; -} - -static int s390x_aes_cfb8_cipher_hw(PROV_CIPHER_CTX *dat, unsigned char *out, - const unsigned char *in, size_t len) -{ - PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; - unsigned int modifier = adat->base.enc ? 0 : S390X_DECRYPT; - - memcpy(adat->plat.s390x.param.kmo_kmf.cv, dat->iv, dat->ivlen); - s390x_kmf(in, len, out, adat->plat.s390x.fc | modifier, - &adat->plat.s390x.param.kmo_kmf); - memcpy(dat->iv, adat->plat.s390x.param.kmo_kmf.cv, dat->ivlen); - return 1; -} - -static const PROV_CIPHER_HW s390x_aes_cfb8 = { - s390x_aes_cfb8_initkey, - s390x_aes_cfb8_cipher_hw, - ossl_cipher_aes_copyctx -}; - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_s390x(enum aes_modes mode, - size_t keybits) -{ - switch (mode) { - case AES_MODE_ECB: - if ((keybits == 128 && S390X_aes_128_ecb_CAPABLE) - || (keybits == 192 && S390X_aes_192_ecb_CAPABLE) - || (keybits == 256 && S390X_aes_256_ecb_CAPABLE)) - return &s390x_aes_ecb; - break; - case AES_MODE_CFB128: - if ((keybits == 128 && S390X_aes_128_cfb_CAPABLE) - || (keybits == 192 && S390X_aes_192_cfb_CAPABLE) - || (keybits == 256 && S390X_aes_256_cfb_CAPABLE)) - return &s390x_aes_cfb128; - break; - case AES_MODE_CFB8: - if ((keybits == 128 && S390X_aes_128_cfb8_CAPABLE) - || (keybits == 192 && S390X_aes_192_cfb8_CAPABLE) - || (keybits == 256 && S390X_aes_256_cfb8_CAPABLE)) - return &s390x_aes_cfb8; - break; - case AES_MODE_OFB128: - if ((keybits == 128 && S390X_aes_128_ofb_CAPABLE) - || (keybits == 192 && S390X_aes_192_ofb_CAPABLE) - || (keybits == 256 && S390X_aes_256_ofb_CAPABLE)) - return &s390x_aes_ofb128; - break; - default: - break; - } - return NULL; -} - -/* MODES: GCM */ - -/* iv + padding length for iv lengths != 12 */ -#define S390X_gcm_ivpadlen(i) ((((i) + 15) >> 4 << 4) + 16) - -/* Additional flag or'ed to fc for decryption */ -#define S390X_gcm_decrypt_flag(ctx) (((ctx)->enc) ? 0 : S390X_DECRYPT) - -#define S390X_gcm_fc(A, C) ((A)->plat.s390x.fc | (A)->plat.s390x.hsflag | S390X_gcm_decrypt_flag((C))) - -static int s390x_aes_gcm_initkey(PROV_GCM_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; - - ctx->key_set = 1; - memcpy(&actx->plat.s390x.param.kma.k, key, keylen); - actx->plat.s390x.fc = S390X_AES_FC(keylen); - return 1; -} - -static int s390x_aes_gcm_setiv(PROV_GCM_CTX *ctx, const unsigned char *iv, - size_t ivlen) -{ - PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; - S390X_KMA_PARAMS *kma = &actx->plat.s390x.param.kma; - - kma->t.g[0] = 0; - kma->t.g[1] = 0; - kma->tpcl = 0; - kma->taadl = 0; - actx->plat.s390x.mreslen = 0; - actx->plat.s390x.areslen = 0; - actx->plat.s390x.kreslen = 0; - - if (ivlen == GCM_IV_DEFAULT_SIZE) { - memcpy(&kma->j0, iv, ivlen); - kma->j0.w[3] = 1; - kma->cv.w = 1; - actx->plat.s390x.hsflag = 0; - } else { - unsigned long long ivbits = ivlen << 3; - size_t len = S390X_gcm_ivpadlen(ivlen); - unsigned char iv_zero_pad[S390X_gcm_ivpadlen(GCM_IV_MAX_SIZE)]; - /* - * The IV length needs to be zero padded to be a multiple of 16 bytes - * followed by 8 bytes of zeros and 8 bytes for the IV length. - * The GHASH of this value can then be calculated. - */ - memcpy(iv_zero_pad, iv, ivlen); - memset(iv_zero_pad + ivlen, 0, len - ivlen); - memcpy(iv_zero_pad + len - sizeof(ivbits), &ivbits, sizeof(ivbits)); - /* - * Calculate the ghash of the iv - the result is stored into the tag - * param. - */ - s390x_kma(iv_zero_pad, len, NULL, 0, NULL, actx->plat.s390x.fc, kma); - actx->plat.s390x.hsflag = S390X_KMA_HS; /* The hash subkey is set */ - - /* Copy the 128 bit GHASH result into J0 and clear the tag */ - kma->j0.g[0] = kma->t.g[0]; - kma->j0.g[1] = kma->t.g[1]; - kma->t.g[0] = 0; - kma->t.g[1] = 0; - /* Set the 32 bit counter */ - kma->cv.w = kma->j0.w[3]; - } - return 1; -} - -static int s390x_aes_gcm_cipher_final(PROV_GCM_CTX *ctx, unsigned char *tag) -{ - PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; - S390X_KMA_PARAMS *kma = &actx->plat.s390x.param.kma; - unsigned char out[AES_BLOCK_SIZE]; - unsigned int fc; - int rc; - - kma->taadl <<= 3; - kma->tpcl <<= 3; - fc = S390X_gcm_fc(actx, ctx) | S390X_KMA_LAAD | S390X_KMA_LPC; - s390x_kma(actx->plat.s390x.ares, actx->plat.s390x.areslen, - actx->plat.s390x.mres, actx->plat.s390x.mreslen, out, - fc, kma); - - /* gctx->mres already returned to the caller */ - OPENSSL_cleanse(out, actx->plat.s390x.mreslen); - - if (ctx->enc) { - ctx->taglen = GCM_TAG_MAX_SIZE; - memcpy(tag, kma->t.b, ctx->taglen); - rc = 1; - } else { - rc = (CRYPTO_memcmp(tag, kma->t.b, ctx->taglen) == 0); - } - return rc; -} - -static int s390x_aes_gcm_one_shot(PROV_GCM_CTX *ctx, - unsigned char *aad, size_t aad_len, - const unsigned char *in, size_t in_len, - unsigned char *out, - unsigned char *tag, size_t taglen) -{ - PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; - S390X_KMA_PARAMS *kma = &actx->plat.s390x.param.kma; - unsigned int fc; - int rc; - - kma->taadl = aad_len << 3; - kma->tpcl = in_len << 3; - fc = S390X_gcm_fc(actx, ctx) | S390X_KMA_LAAD | S390X_KMA_LPC; - s390x_kma(aad, aad_len, in, in_len, out, fc, kma); - - if (ctx->enc) { - memcpy(tag, kma->t.b, taglen); - rc = 1; - } else { - rc = (CRYPTO_memcmp(tag, kma->t.b, taglen) == 0); - } - return rc; -} - -/* - * Process additional authenticated data. Returns 1 on success. Code is - * big-endian. - */ -static int s390x_aes_gcm_aad_update(PROV_GCM_CTX *ctx, - const unsigned char *aad, size_t len) -{ - PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; - S390X_KMA_PARAMS *kma = &actx->plat.s390x.param.kma; - unsigned long long alen; - unsigned int fc; - int n, rem; - - /* If already processed pt/ct then error */ - if (kma->tpcl != 0) - return 0; - - /* update the total aad length */ - alen = kma->taadl + len; - if (alen > (U64(1) << 61) || (sizeof(len) == 8 && alen < len)) - return 0; - kma->taadl = alen; - - /* check if there is any existing aad data from a previous add */ - n = actx->plat.s390x.areslen; - if (n) { - /* add additional data to a buffer until it has 16 bytes */ - while (n && len) { - actx->plat.s390x.ares[n] = *aad; - ++aad; - --len; - n = (n + 1) & 0xf; - } - /* ctx->ares contains a complete block if offset has wrapped around */ - if (!n) { - fc = S390X_gcm_fc(actx, ctx); - s390x_kma(actx->plat.s390x.ares, 16, NULL, 0, NULL, fc, kma); - actx->plat.s390x.hsflag = S390X_KMA_HS; - } - actx->plat.s390x.areslen = n; - } - - /* If there are leftover bytes (< 128 bits) save them for next time */ - rem = len & 0xf; - /* Add any remaining 16 byte blocks (128 bit each) */ - len &= ~(size_t)0xf; - if (len) { - fc = S390X_gcm_fc(actx, ctx); - s390x_kma(aad, len, NULL, 0, NULL, fc, kma); - actx->plat.s390x.hsflag = S390X_KMA_HS; - aad += len; - } - - if (rem) { - actx->plat.s390x.areslen = rem; - - do { - --rem; - actx->plat.s390x.ares[rem] = aad[rem]; - } while (rem); - } - return 1; -} - -/*- - * En/de-crypt plain/cipher-text and authenticate ciphertext. Returns 1 for - * success. Code is big-endian. - */ -static int s390x_aes_gcm_cipher_update(PROV_GCM_CTX *ctx, - const unsigned char *in, size_t len, - unsigned char *out) -{ - PROV_AES_GCM_CTX *actx = (PROV_AES_GCM_CTX *)ctx; - S390X_KMA_PARAMS *kma = &actx->plat.s390x.param.kma; - const unsigned char *inptr; - unsigned long long mlen; - unsigned int fc; - union { - unsigned int w[4]; - unsigned char b[16]; - } buf; - size_t inlen; - int n, rem, i; - - mlen = kma->tpcl + len; - if (mlen > ((U64(1) << 36) - 32) || (sizeof(len) == 8 && mlen < len)) - return 0; - kma->tpcl = mlen; - - fc = S390X_gcm_fc(actx, ctx) | S390X_KMA_LAAD; - n = actx->plat.s390x.mreslen; - if (n) { - inptr = in; - inlen = len; - while (n && inlen) { - actx->plat.s390x.mres[n] = *inptr; - n = (n + 1) & 0xf; - ++inptr; - --inlen; - } - /* ctx->mres contains a complete block if offset has wrapped around */ - if (!n) { - s390x_kma(actx->plat.s390x.ares, actx->plat.s390x.areslen, - actx->plat.s390x.mres, 16, buf.b, fc, kma); - actx->plat.s390x.hsflag = S390X_KMA_HS; - fc |= S390X_KMA_HS; - actx->plat.s390x.areslen = 0; - - /* previous call already encrypted/decrypted its remainder, - * see comment below */ - n = actx->plat.s390x.mreslen; - while (n) { - *out = buf.b[n]; - n = (n + 1) & 0xf; - ++out; - ++in; - --len; - } - actx->plat.s390x.mreslen = 0; - } - } - - rem = len & 0xf; - - len &= ~(size_t)0xf; - if (len) { - s390x_kma(actx->plat.s390x.ares, actx->plat.s390x.areslen, in, len, out, - fc, kma); - in += len; - out += len; - actx->plat.s390x.hsflag = S390X_KMA_HS; - actx->plat.s390x.areslen = 0; - } - - /*- - * If there is a remainder, it has to be saved such that it can be - * processed by kma later. However, we also have to do the for-now - * unauthenticated encryption/decryption part here and now... - */ - if (rem) { - if (!actx->plat.s390x.mreslen) { - buf.w[0] = kma->j0.w[0]; - buf.w[1] = kma->j0.w[1]; - buf.w[2] = kma->j0.w[2]; - buf.w[3] = kma->cv.w + 1; - s390x_km(buf.b, 16, actx->plat.s390x.kres, - fc & 0x1f, &kma->k); - } - - n = actx->plat.s390x.mreslen; - for (i = 0; i < rem; i++) { - actx->plat.s390x.mres[n + i] = in[i]; - out[i] = in[i] ^ actx->plat.s390x.kres[n + i]; - } - actx->plat.s390x.mreslen += rem; - } - return 1; -} - -static const PROV_GCM_HW s390x_aes_gcm = { - s390x_aes_gcm_initkey, - s390x_aes_gcm_setiv, - s390x_aes_gcm_aad_update, - s390x_aes_gcm_cipher_update, - s390x_aes_gcm_cipher_final, - s390x_aes_gcm_one_shot -}; - -const PROV_GCM_HW *ossl_prov_aes_hw_gcm_s390x(size_t keybits) -{ - if ((keybits == 128 && S390X_aes_128_gcm_CAPABLE) - || (keybits == 192 && S390X_aes_192_gcm_CAPABLE) - || (keybits == 256 && S390X_aes_256_gcm_CAPABLE)) - return &s390x_aes_gcm; - return NULL; -} - -/* MODES: CCM */ - -#define S390X_CCM_AAD_FLAG 0x40 - -static int s390x_aes_ccm_initkey(PROV_CCM_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - PROV_AES_CCM_CTX *sctx = (PROV_AES_CCM_CTX *)ctx; - - sctx->ccm.s390x.fc = S390X_AES_FC(keylen); - memcpy(&sctx->ccm.s390x.kmac.k, key, keylen); - /* Store encoded m and l. */ - sctx->ccm.s390x.nonce.b[0] = ((ctx->l - 1) & 0x7) - | (((ctx->m - 2) >> 1) & 0x7) << 3; - memset(sctx->ccm.s390x.nonce.b + 1, 0, sizeof(sctx->ccm.s390x.nonce.b)); - sctx->ccm.s390x.blocks = 0; - ctx->key_set = 1; - return 1; -} - -static int s390x_aes_ccm_setiv(PROV_CCM_CTX *ctx, - const unsigned char *nonce, size_t noncelen, - size_t mlen) -{ - PROV_AES_CCM_CTX *sctx = (PROV_AES_CCM_CTX *)ctx; - - sctx->ccm.s390x.nonce.b[0] &= ~S390X_CCM_AAD_FLAG; - sctx->ccm.s390x.nonce.g[1] = mlen; - memcpy(sctx->ccm.s390x.nonce.b + 1, nonce, 15 - ctx->l); - return 1; -} - -/*- - * Process additional authenticated data. Code is big-endian. - */ -static int s390x_aes_ccm_setaad(PROV_CCM_CTX *ctx, - const unsigned char *aad, size_t alen) -{ - PROV_AES_CCM_CTX *sctx = (PROV_AES_CCM_CTX *)ctx; - unsigned char *ptr; - int i, rem; - - if (!alen) - return 1; - - sctx->ccm.s390x.nonce.b[0] |= S390X_CCM_AAD_FLAG; - - /* Suppress 'type-punned pointer dereference' warning. */ - ptr = sctx->ccm.s390x.buf.b; - - if (alen < ((1 << 16) - (1 << 8))) { - *(uint16_t *)ptr = alen; - i = 2; - } else if (sizeof(alen) == 8 - && alen >= (size_t)1 << (32 % (sizeof(alen) * 8))) { - *(uint16_t *)ptr = 0xffff; - *(uint64_t *)(ptr + 2) = alen; - i = 10; - } else { - *(uint16_t *)ptr = 0xfffe; - *(uint32_t *)(ptr + 2) = alen; - i = 6; - } - - while (i < 16 && alen) { - sctx->ccm.s390x.buf.b[i] = *aad; - ++aad; - --alen; - ++i; - } - while (i < 16) { - sctx->ccm.s390x.buf.b[i] = 0; - ++i; - } - - sctx->ccm.s390x.kmac.icv.g[0] = 0; - sctx->ccm.s390x.kmac.icv.g[1] = 0; - s390x_kmac(sctx->ccm.s390x.nonce.b, 32, sctx->ccm.s390x.fc, - &sctx->ccm.s390x.kmac); - sctx->ccm.s390x.blocks += 2; - - rem = alen & 0xf; - alen &= ~(size_t)0xf; - if (alen) { - s390x_kmac(aad, alen, sctx->ccm.s390x.fc, &sctx->ccm.s390x.kmac); - sctx->ccm.s390x.blocks += alen >> 4; - aad += alen; - } - if (rem) { - for (i = 0; i < rem; i++) - sctx->ccm.s390x.kmac.icv.b[i] ^= aad[i]; - - s390x_km(sctx->ccm.s390x.kmac.icv.b, 16, - sctx->ccm.s390x.kmac.icv.b, sctx->ccm.s390x.fc, - sctx->ccm.s390x.kmac.k); - sctx->ccm.s390x.blocks++; - } - return 1; -} - -/*- - * En/de-crypt plain/cipher-text. Compute tag from plaintext. Returns 1 for - * success. - */ -static int s390x_aes_ccm_auth_encdec(PROV_CCM_CTX *ctx, - const unsigned char *in, - unsigned char *out, size_t len, int enc) -{ - PROV_AES_CCM_CTX *sctx = (PROV_AES_CCM_CTX *)ctx; - size_t n, rem; - unsigned int i, l, num; - unsigned char flags; - - flags = sctx->ccm.s390x.nonce.b[0]; - if (!(flags & S390X_CCM_AAD_FLAG)) { - s390x_km(sctx->ccm.s390x.nonce.b, 16, sctx->ccm.s390x.kmac.icv.b, - sctx->ccm.s390x.fc, sctx->ccm.s390x.kmac.k); - sctx->ccm.s390x.blocks++; - } - l = flags & 0x7; - sctx->ccm.s390x.nonce.b[0] = l; - - /*- - * Reconstruct length from encoded length field - * and initialize it with counter value. - */ - n = 0; - for (i = 15 - l; i < 15; i++) { - n |= sctx->ccm.s390x.nonce.b[i]; - sctx->ccm.s390x.nonce.b[i] = 0; - n <<= 8; - } - n |= sctx->ccm.s390x.nonce.b[15]; - sctx->ccm.s390x.nonce.b[15] = 1; - - if (n != len) - return 0; /* length mismatch */ - - if (enc) { - /* Two operations per block plus one for tag encryption */ - sctx->ccm.s390x.blocks += (((len + 15) >> 4) << 1) + 1; - if (sctx->ccm.s390x.blocks > (1ULL << 61)) - return 0; /* too much data */ - } - - num = 0; - rem = len & 0xf; - len &= ~(size_t)0xf; - - if (enc) { - /* mac-then-encrypt */ - if (len) - s390x_kmac(in, len, sctx->ccm.s390x.fc, &sctx->ccm.s390x.kmac); - if (rem) { - for (i = 0; i < rem; i++) - sctx->ccm.s390x.kmac.icv.b[i] ^= in[len + i]; - - s390x_km(sctx->ccm.s390x.kmac.icv.b, 16, - sctx->ccm.s390x.kmac.icv.b, - sctx->ccm.s390x.fc, sctx->ccm.s390x.kmac.k); - } - - CRYPTO_ctr128_encrypt_ctr32(in, out, len + rem, &sctx->ccm.ks.ks, - sctx->ccm.s390x.nonce.b, sctx->ccm.s390x.buf.b, - &num, (ctr128_f)AES_ctr32_encrypt); - } else { - /* decrypt-then-mac */ - CRYPTO_ctr128_encrypt_ctr32(in, out, len + rem, &sctx->ccm.ks.ks, - sctx->ccm.s390x.nonce.b, sctx->ccm.s390x.buf.b, - &num, (ctr128_f)AES_ctr32_encrypt); - - if (len) - s390x_kmac(out, len, sctx->ccm.s390x.fc, &sctx->ccm.s390x.kmac); - if (rem) { - for (i = 0; i < rem; i++) - sctx->ccm.s390x.kmac.icv.b[i] ^= out[len + i]; - - s390x_km(sctx->ccm.s390x.kmac.icv.b, 16, - sctx->ccm.s390x.kmac.icv.b, - sctx->ccm.s390x.fc, sctx->ccm.s390x.kmac.k); - } - } - /* encrypt tag */ - for (i = 15 - l; i < 16; i++) - sctx->ccm.s390x.nonce.b[i] = 0; - - s390x_km(sctx->ccm.s390x.nonce.b, 16, sctx->ccm.s390x.buf.b, - sctx->ccm.s390x.fc, sctx->ccm.s390x.kmac.k); - sctx->ccm.s390x.kmac.icv.g[0] ^= sctx->ccm.s390x.buf.g[0]; - sctx->ccm.s390x.kmac.icv.g[1] ^= sctx->ccm.s390x.buf.g[1]; - - sctx->ccm.s390x.nonce.b[0] = flags; /* restore flags field */ - return 1; -} - -static int s390x_aes_ccm_gettag(PROV_CCM_CTX *ctx, - unsigned char *tag, size_t tlen) -{ - PROV_AES_CCM_CTX *sctx = (PROV_AES_CCM_CTX *)ctx; - - if (tlen > ctx->m) - return 0; - memcpy(tag, sctx->ccm.s390x.kmac.icv.b, tlen); - return 1; -} - -static int s390x_aes_ccm_auth_encrypt(PROV_CCM_CTX *ctx, - const unsigned char *in, - unsigned char *out, size_t len, - unsigned char *tag, size_t taglen) -{ - int rv; - - rv = s390x_aes_ccm_auth_encdec(ctx, in, out, len, 1); - if (rv && tag != NULL) - rv = s390x_aes_ccm_gettag(ctx, tag, taglen); - return rv; -} - -static int s390x_aes_ccm_auth_decrypt(PROV_CCM_CTX *ctx, - const unsigned char *in, - unsigned char *out, size_t len, - unsigned char *expected_tag, - size_t taglen) -{ - int rv = 0; - PROV_AES_CCM_CTX *sctx = (PROV_AES_CCM_CTX *)ctx; - - rv = s390x_aes_ccm_auth_encdec(ctx, in, out, len, 0); - if (rv) { - if (CRYPTO_memcmp(sctx->ccm.s390x.kmac.icv.b, expected_tag, ctx->m) != 0) - rv = 0; - } - if (rv == 0) - OPENSSL_cleanse(out, len); - return rv; -} - -static const PROV_CCM_HW s390x_aes_ccm = { - s390x_aes_ccm_initkey, - s390x_aes_ccm_setiv, - s390x_aes_ccm_setaad, - s390x_aes_ccm_auth_encrypt, - s390x_aes_ccm_auth_decrypt, - s390x_aes_ccm_gettag -}; - -const PROV_CCM_HW *ossl_prov_aes_hw_ccm_s390x(size_t keybits) -{ - if ((keybits == 128 && S390X_aes_128_ccm_CAPABLE) - || (keybits == 192 && S390X_aes_192_ccm_CAPABLE) - || (keybits == 256 && S390X_aes_256_ccm_CAPABLE)) - return &s390x_aes_ccm; - return NULL; -} - -#endif - -/* MODES: XTS */ - -#if defined(AES_XTS_S390X) - -int s390x_aes_xts_cipher_stream(PROV_AES_XTS_CTX *xctx, - unsigned char *out, size_t *outl, - const unsigned char *in, size_t inl) -{ - S390X_KM_XTS_PARAMS *km = &xctx->plat.s390x.param.km; - unsigned char *param = (unsigned char *)km + xctx->plat.s390x.offset; - unsigned int fc = xctx->plat.s390x.fc; - unsigned char tmp[2][AES_BLOCK_SIZE]; - unsigned char nap_n1[AES_BLOCK_SIZE]; - unsigned char drop[AES_BLOCK_SIZE]; - size_t len_incomplete, len_complete; - - len_incomplete = inl % AES_BLOCK_SIZE; - len_complete = (len_incomplete == 0) ? inl : (inl / AES_BLOCK_SIZE - 1) * AES_BLOCK_SIZE; - - if (len_complete > 0) - s390x_km(in, len_complete, out, fc, param); - if (len_incomplete == 0) - goto out; - - memcpy(tmp, in + len_complete, AES_BLOCK_SIZE + len_incomplete); - /* swap NAP for decrypt */ - if (fc & S390X_DECRYPT) { - memcpy(nap_n1, km->nap, AES_BLOCK_SIZE); - s390x_km(tmp[0], AES_BLOCK_SIZE, drop, fc, param); - } - s390x_km(tmp[0], AES_BLOCK_SIZE, tmp[0], fc, param); - if (fc & S390X_DECRYPT) - memcpy(km->nap, nap_n1, AES_BLOCK_SIZE); - - memcpy(tmp[1] + len_incomplete, tmp[0] + len_incomplete, - AES_BLOCK_SIZE - len_incomplete); - s390x_km(tmp[1], AES_BLOCK_SIZE, out + len_complete, fc, param); - memcpy(out + len_complete + AES_BLOCK_SIZE, tmp[0], len_incomplete); - - /* do not expose temporary data */ - OPENSSL_cleanse(tmp, sizeof(tmp)); -out: - memcpy(xctx->base.iv, km->tweak, AES_BLOCK_SIZE); - *outl = inl; - - return 1; -} - -static int cipher_hw_aes_xts_s390x_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - PROV_AES_XTS_CTX *xctx = (PROV_AES_XTS_CTX *)ctx; - S390X_KM_XTS_PARAMS *km = &xctx->plat.s390x.param.km; - unsigned int fc, offs; - unsigned int dec = 0; - int supported = 0; - - if (key != NULL) { - switch (keylen) { - case 128 / 8 * 2: - fc = S390X_XTS_AES_128_MSA10; - offs = 32; - break; - case 256 / 8 * 2: - fc = S390X_XTS_AES_256_MSA10; - offs = 0; - break; - default: - fc = 0; - break; - } - } else { - fc = xctx->plat.s390x.fc & ~S390X_DECRYPT; - offs = xctx->plat.s390x.offset; - } - - if (fc != 0) - supported = (OPENSSL_s390xcap_P.km[1] && S390X_CAPBIT(fc)); - if (!supported) { - xctx->plat.s390x.fc = 0; - xctx->plat.s390x.offset = 0; - return 0; - } - - if (xctx->base.iv_set) { - if (xctx->base.ivlen > sizeof(km->tweak)) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_IV_LENGTH); - return 0; - } - memcpy(km->tweak, xctx->base.iv, xctx->base.ivlen); - xctx->plat.s390x.iv_set = 1; - } - - if (key != NULL) { - memcpy(km->key + offs, key, keylen); - xctx->plat.s390x.key_set = 1; - } - - if (xctx->base.enc == 0) - dec = S390X_DECRYPT; - - xctx->plat.s390x.fc = fc | dec; - xctx->plat.s390x.offset = offs; - - memset(km->nap, 0, sizeof(km->nap)); - km->nap[0] = 0x1; - - return 1; -} - -static void cipher_hw_aes_xts_s390x_copyctx(PROV_CIPHER_CTX *dst, - const PROV_CIPHER_CTX *src) -{ - PROV_AES_XTS_CTX *sctx = (PROV_AES_XTS_CTX *)src; - PROV_AES_XTS_CTX *dctx = (PROV_AES_XTS_CTX *)dst; - - *dctx = *sctx; - dctx->xts.key1 = NULL; - dctx->xts.key2 = NULL; -} - -static const PROV_CIPHER_HW aes_xts_s390x = { - cipher_hw_aes_xts_s390x_initkey, - NULL, - cipher_hw_aes_xts_s390x_copyctx -}; - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_xts_s390x(size_t keybits) -{ - switch (keybits) { - case (128 * 2): - if (OPENSSL_s390xcap_P.km[1] && S390X_CAPBIT(S390X_XTS_AES_128_MSA10)) - return &aes_xts_s390x; - break; - case (256 * 2): - if (OPENSSL_s390xcap_P.km[1] && S390X_CAPBIT(S390X_XTS_AES_256_MSA10)) - return &aes_xts_s390x; - break; - default: - break; - } - - return NULL; -} - -#endif diff --git a/providers/implementations/ciphers/cipher_aes_hw_s390x.inc b/providers/implementations/ciphers/cipher_aes_hw_s390x.inc new file mode 100644 index 0000000000..ed69f1709f --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_hw_s390x.inc @@ -0,0 +1,113 @@ +/* + * Copyright 2001-2025 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/* + * IBM S390X support for AES modes ecb, cbc, ofb, cfb, ctr. + * This file is included by cipher_aes_hw.c + */ + +#include "s390x_arch.h" + +#include + +#define s390x_aes_cbc_initkey cipher_hw_aes_initkey +#define s390x_aes_ctr_initkey cipher_hw_aes_initkey +#define s390x_aes_cbc_cipher_hw ossl_cipher_hw_generic_cbc +#define s390x_aes_ctr_cipher_hw ossl_cipher_hw_generic_ctr + +#define S390X_aes_128_ofb128_CAPABLE S390X_aes_128_ofb_CAPABLE +#define S390X_aes_192_ofb128_CAPABLE S390X_aes_192_ofb_CAPABLE +#define S390X_aes_256_ofb128_CAPABLE S390X_aes_256_ofb_CAPABLE + +static int s390x_aes_ecb_initkey(PROV_CIPHER_CTX *dat, + const unsigned char *key, size_t keylen) +{ + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + + adat->plat.s390x.fc = S390X_AES_FC(keylen); + memcpy(adat->plat.s390x.param.km.k, key, keylen); + return 1; +} + +static int s390x_aes_ecb_cipher_hw(PROV_CIPHER_CTX *dat, unsigned char *out, + const unsigned char *in, size_t len) +{ + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + unsigned int modifier = adat->base.enc ? 0 : S390X_DECRYPT; + + s390x_km(in, len, out, adat->plat.s390x.fc | modifier, + &adat->plat.s390x.param.km); + return 1; +} + +static int s390x_aes_ofb128_initkey(PROV_CIPHER_CTX *dat, + const unsigned char *key, size_t keylen) +{ + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + + memcpy(adat->plat.s390x.param.kmo_kmf.k, key, keylen); + adat->plat.s390x.fc = S390X_AES_FC(keylen); + return 1; +} + +static int s390x_aes_ofb128_cipher_hw(PROV_CIPHER_CTX *dat, unsigned char *out, + const unsigned char *in, size_t len) +{ + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + int n = dat->num; + int rem; + + memcpy(adat->plat.s390x.param.kmo_kmf.cv, dat->iv, dat->ivlen); + while (n && len) { + *out = *in ^ adat->plat.s390x.param.kmo_kmf.cv[n]; + n = (n + 1) & 0xf; + --len; + ++in; + ++out; + } + + rem = len & 0xf; + + len &= ~(size_t)0xf; + if (len) { + s390x_kmo(in, len, out, adat->plat.s390x.fc, + &adat->plat.s390x.param.kmo_kmf); + + out += len; + in += len; + } + + if (rem) { + s390x_km(adat->plat.s390x.param.kmo_kmf.cv, 16, + adat->plat.s390x.param.kmo_kmf.cv, + adat->plat.s390x.fc, + adat->plat.s390x.param.kmo_kmf.k); + + while (rem--) { + out[n] = in[n] ^ adat->plat.s390x.param.kmo_kmf.cv[n]; + ++n; + } + } + + memcpy(dat->iv, adat->plat.s390x.param.kmo_kmf.cv, dat->ivlen); + dat->num = n; + return 1; +} + +#define PROV_CIPHER_HW_declare(mode) \ +static const PROV_CIPHER_HW s390x_aes_##mode = { \ + s390x_aes_##mode##_initkey, \ + s390x_aes_##mode##_cipher_hw, \ + cipher_hw_aes_copyctx \ +}; +#define PROV_CIPHER_HW_select(mode) \ +if ((keybits == 128 && S390X_aes_128_##mode##_CAPABLE) \ + || (keybits == 192 && S390X_aes_192_##mode##_CAPABLE) \ + || (keybits == 256 && S390X_aes_256_##mode##_CAPABLE)) \ + return &s390x_aes_##mode; diff --git a/providers/implementations/ciphers/cipher_aes_hw_t4.c b/providers/implementations/ciphers/cipher_aes_hw_t4.c deleted file mode 100644 index 514a7a737f..0000000000 --- a/providers/implementations/ciphers/cipher_aes_hw_t4.c +++ /dev/null @@ -1,252 +0,0 @@ -/* - * Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/*- - * Sparc t4 support for all hardware accelerated AES modes. - */ - -#include "internal/deprecated.h" -#include -#include "cipher_aes.h" -#include "cipher_aes_gcm.h" -#include "cipher_aes_ccm.h" -#include "cipher_aes_xts.h" - -#if defined(SPARC_AES_CAPABLE) - -/* MODES: ecb, cbc, cfb, ofb, ctr */ - -static int t4_set_encrypt_key(const unsigned char *key, int bits, AES_KEY *ks) -{ - aes_t4_set_encrypt_key(key, bits, ks); - return 0; -} - -static int t4_set_decrypt_key(const unsigned char *key, int bits, AES_KEY *ks) -{ - aes_t4_set_decrypt_key(key, bits, ks); - return 0; -} - -static int cipher_hw_aes_t4_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - cbc128_f fn_cbc = NULL; - if ((ctx->mode == EVP_CIPH_ECB_MODE || ctx->mode == EVP_CIPH_CBC_MODE) - && !ctx->enc) { - switch (keylen) { - case 16: - fn_cbc = (cbc128_f)aes128_t4_cbc_decrypt; - break; - case 24: - fn_cbc = (cbc128_f)aes192_t4_cbc_decrypt; - break; - case 32: - fn_cbc = (cbc128_f)aes256_t4_cbc_decrypt; - break; - default: - ERR_raise(ERR_LIB_PROV, PROV_R_KEY_SETUP_FAILED); - return 0; - } - return ossl_cipher_set_aes_initkey(ctx, key, keylen, t4_set_decrypt_key, - aes_t4_decrypt, NULL, fn_cbc, NULL); - } else { - ctr128_f fn_ctr = NULL; - switch (keylen) { - case 16: - fn_cbc = (cbc128_f)aes128_t4_cbc_encrypt; - fn_ctr = (ctr128_f)aes128_t4_ctr32_encrypt; - break; - case 24: - fn_cbc = (cbc128_f)aes192_t4_cbc_encrypt; - fn_ctr = (ctr128_f)aes192_t4_ctr32_encrypt; - break; - case 32: - fn_cbc = (cbc128_f)aes256_t4_cbc_encrypt; - fn_ctr = (ctr128_f)aes256_t4_ctr32_encrypt; - break; - default: - ERR_raise(ERR_LIB_PROV, PROV_R_KEY_SETUP_FAILED); - return 0; - } - return ossl_cipher_set_aes_initkey(ctx, key, keylen, t4_set_encrypt_key, - aes_t4_encrypt, NULL, fn_cbc, fn_ctr); - } -} - -static const PROV_CIPHER_HW aes_t4_ecb = { - cipher_hw_aes_t4_initkey, - ossl_cipher_hw_generic_ecb, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aes_t4_cbc = { - cipher_hw_aes_t4_initkey, - ossl_cipher_hw_generic_cbc, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aes_t4_cfb128 = { - cipher_hw_aes_t4_initkey, - ossl_cipher_hw_generic_cfb128, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aes_t4_cfb8 = { - cipher_hw_aes_t4_initkey, - ossl_cipher_hw_generic_cfb8, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aes_t4_cfb1 = { - cipher_hw_aes_t4_initkey, - ossl_cipher_hw_generic_cfb1, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aes_t4_ofb128 = { - cipher_hw_aes_t4_initkey, - ossl_cipher_hw_generic_ofb128, - ossl_cipher_aes_copyctx -}; - -static const PROV_CIPHER_HW aes_t4_ctr = { - cipher_hw_aes_t4_initkey, - ossl_cipher_hw_generic_ctr, - ossl_cipher_aes_copyctx -}; - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_t4(enum aes_modes mode) -{ - if (SPARC_AES_CAPABLE) { - switch (mode) { - case AES_MODE_ECB: - return &aes_t4_ecb; - case AES_MODE_CBC: - return &aes_t4_cbc; - case AES_MODE_CFB128: - return &aes_t4_cfb128; - case AES_MODE_CFB8: - return &aes_t4_cfb8; - case AES_MODE_CFB1: - return &aes_t4_cfb1; - case AES_MODE_OFB128: - return &aes_t4_ofb128; - case AES_MODE_CTR: - return &aes_t4_ctr; - default: - return NULL; - } - } - return NULL; -} - -/* MODES: GCM */ - -static int t4_aes_gcm_initkey(PROV_GCM_CTX *ctx, const unsigned char *key, - size_t keylen) -{ - switch (keylen) { - case 16: - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, - t4_set_encrypt_key, aes_t4_encrypt, - (ctr128_f)aes128_t4_ctr32_encrypt); - case 24: - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, - t4_set_encrypt_key, aes_t4_encrypt, - (ctr128_f)aes192_t4_ctr32_encrypt); - case 32: - return ossl_aes_gcm_hw_initkey(ctx, key, keylen, - t4_set_encrypt_key, aes_t4_encrypt, - (ctr128_f)aes256_t4_ctr32_encrypt); - default: - return 0; - } -} - -static const PROV_GCM_HW t4_aes_gcm = { - t4_aes_gcm_initkey, - ossl_gcm_setiv, - ossl_gcm_aad_update, - ossl_generic_aes_gcm_cipher_update, - ossl_gcm_cipher_final, - ossl_gcm_one_shot -}; - -const PROV_GCM_HW *ossl_prov_aes_hw_gcm_t4(void) -{ - return SPARC_AES_CAPABLE ? &t4_aes_gcm : NULL; -} - -/* MODES: CCM */ - -static int ccm_t4_aes_initkey(PROV_CCM_CTX *ctx, const unsigned char *key, - size_t keylen) -{ - return ossl_cipher_set_ccm_aes_initkey(ctx, key, keylen, - t4_set_encrypt_key, aes_t4_encrypt, NULL, NULL); -} - -static const PROV_CCM_HW t4_aes_ccm = { - ccm_t4_aes_initkey, - ossl_ccm_generic_setiv, - ossl_ccm_generic_setaad, - ossl_ccm_generic_auth_encrypt, - ossl_ccm_generic_auth_decrypt, - ossl_ccm_generic_gettag -}; - -const PROV_CCM_HW *ossl_prov_aes_hw_ccm_t4(void) -{ - if (SPARC_AES_CAPABLE) - return &t4_aes_ccm; - return NULL; -} - -/* MODES: XTS */ - -static int cipher_hw_aes_xts_t4_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen) -{ - OSSL_xts_stream_fn stream_enc = NULL; - OSSL_xts_stream_fn stream_dec = NULL; - - /* Note: keylen is the size of 2 keys */ - switch (keylen) { - case 32: - stream_enc = aes128_t4_xts_encrypt; - stream_dec = aes128_t4_xts_decrypt; - break; - case 64: - stream_enc = aes256_t4_xts_encrypt; - stream_dec = aes256_t4_xts_decrypt; - break; - default: - return 0; - } - - return ossl_cipher_set_aes_xts_initkey(ctx, key, keylen, - t4_set_encrypt_key, t4_set_decrypt_key, - aes_t4_encrypt, aes_t4_decrypt, stream_enc, stream_dec); -} - -static const PROV_CIPHER_HW aes_xts_t4 = { - cipher_hw_aes_xts_t4_initkey, - NULL, - ossl_cipher_hw_aes_xts_copyctx -}; - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_xts_t4(void) -{ - if (SPARC_AES_CAPABLE) - return &aes_xts_t4; - return NULL; -} - -#endif diff --git a/providers/implementations/ciphers/cipher_aes_hw_t4.inc b/providers/implementations/ciphers/cipher_aes_hw_t4.inc new file mode 100644 index 0000000000..28454fc508 --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_hw_t4.inc @@ -0,0 +1,96 @@ +/* + * Copyright 2001-2021 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/*- + * Sparc t4 support for AES modes ecb, cbc, ofb, cfb, ctr. + * This file is included by cipher_aes_hw.c + */ + +static int cipher_hw_aes_t4_initkey(PROV_CIPHER_CTX *dat, + const unsigned char *key, size_t keylen) +{ + int ret, bits; + PROV_AES_CTX *adat = (PROV_AES_CTX *)dat; + AES_KEY *ks = &adat->ks.ks; + + dat->ks = (const void *)ks; /* used by cipher_hw_generic_XXX */ + + bits = keylen * 8; + if ((dat->mode == EVP_CIPH_ECB_MODE || dat->mode == EVP_CIPH_CBC_MODE) + && !dat->enc) { + ret = 0; + aes_t4_set_decrypt_key(key, bits, ks); + dat->block = (block128_f)aes_t4_decrypt; + switch (bits) { + case 128: + dat->stream.cbc = dat->mode == EVP_CIPH_CBC_MODE ? + (cbc128_f)aes128_t4_cbc_decrypt : NULL; + break; + case 192: + dat->stream.cbc = dat->mode == EVP_CIPH_CBC_MODE ? + (cbc128_f)aes192_t4_cbc_decrypt : NULL; + break; + case 256: + dat->stream.cbc = dat->mode == EVP_CIPH_CBC_MODE ? + (cbc128_f)aes256_t4_cbc_decrypt : NULL; + break; + default: + ret = -1; + } + } else { + ret = 0; + aes_t4_set_encrypt_key(key, bits, ks); + dat->block = (block128_f)aes_t4_encrypt; + switch (bits) { + case 128: + if (dat->mode == EVP_CIPH_CBC_MODE) + dat->stream.cbc = (cbc128_f)aes128_t4_cbc_encrypt; + else if (dat->mode == EVP_CIPH_CTR_MODE) + dat->stream.ctr = (ctr128_f)aes128_t4_ctr32_encrypt; + else + dat->stream.cbc = NULL; + break; + case 192: + if (dat->mode == EVP_CIPH_CBC_MODE) + dat->stream.cbc = (cbc128_f)aes192_t4_cbc_encrypt; + else if (dat->mode == EVP_CIPH_CTR_MODE) + dat->stream.ctr = (ctr128_f)aes192_t4_ctr32_encrypt; + else + dat->stream.cbc = NULL; + break; + case 256: + if (dat->mode == EVP_CIPH_CBC_MODE) + dat->stream.cbc = (cbc128_f)aes256_t4_cbc_encrypt; + else if (dat->mode == EVP_CIPH_CTR_MODE) + dat->stream.ctr = (ctr128_f)aes256_t4_ctr32_encrypt; + else + dat->stream.cbc = NULL; + break; + default: + ret = -1; + } + } + + if (ret < 0) { + ERR_raise(ERR_LIB_PROV, PROV_R_KEY_SETUP_FAILED); + return 0; + } + + return 1; +} + +#define PROV_CIPHER_HW_declare(mode) \ +static const PROV_CIPHER_HW aes_t4_##mode = { \ + cipher_hw_aes_t4_initkey, \ + ossl_cipher_hw_generic_##mode, \ + cipher_hw_aes_copyctx \ +}; +#define PROV_CIPHER_HW_select(mode) \ + if (SPARC_AES_CAPABLE) \ + return &aes_t4_##mode; diff --git a/providers/implementations/ciphers/cipher_aes_ocb.c b/providers/implementations/ciphers/cipher_aes_ocb.c index 1bd5281cc2..64706941e0 100644 --- a/providers/implementations/ciphers/cipher_aes_ocb.c +++ b/providers/implementations/ciphers/cipher_aes_ocb.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -28,7 +28,7 @@ #define OCB_MIN_IV_LEN 1 #define OCB_MAX_IV_LEN 15 -PROV_CIPHER_FUNC(int, ocb_cipher, (PROV_AES_OCB_CTX *ctx, const unsigned char *in, unsigned char *out, size_t nextblock)); +PROV_CIPHER_FUNC(int, ocb_cipher, (PROV_AES_OCB_CTX * ctx, const unsigned char *in, unsigned char *out, size_t nextblock)); /* forward declarations */ static OSSL_FUNC_cipher_encrypt_init_fn aes_ocb_einit; static OSSL_FUNC_cipher_decrypt_init_fn aes_ocb_dinit; @@ -307,7 +307,9 @@ static void *aes_ocb_newctx(void *provctx, size_t kbits, size_t blkbits, { PROV_AES_OCB_CTX *ctx; - CIPHER_PROV_CHECK(provctx, AES_128_OCB); + if (!ossl_prov_is_running()) + return NULL; + ctx = OPENSSL_zalloc(sizeof(*ctx)); if (ctx != NULL) { ossl_cipher_generic_initkey(ctx, kbits, blkbits, ivbits, mode, flags, @@ -376,7 +378,7 @@ static int aes_ocb_set_ctx_params(void *vctx, const OSSL_PARAM params[]) ctx->taglen = p.tag->data_size; } else { if (ctx->base.enc) { - ERR_raise(ERR_LIB_PROV, PROV_R_TAG_NOT_NEEDED); + ERR_raise(ERR_LIB_PROV, ERR_R_PASSED_INVALID_ARGUMENT); return 0; } if (p.tag->data_size != ctx->taglen) { @@ -476,11 +478,7 @@ static int aes_ocb_get_ctx_params(void *vctx, OSSL_PARAM params[]) ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_GET_PARAMETER); return 0; } - if (!ctx->base.enc) { - ERR_raise(ERR_LIB_PROV, PROV_R_TAG_NOT_SET); - return 0; - } - if (p.tag->data_size != ctx->taglen) { + if (!ctx->base.enc || p.tag->data_size != ctx->taglen) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_TAG_LENGTH); return 0; } @@ -502,19 +500,6 @@ static int aes_ocb_cipher(void *vctx, unsigned char *out, size_t *outl, return 0; } - /* - * Mirror the streaming handler: refuse if the key has not been set, - * and push the buffered IV into the OCB context before any data is - * processed. Without this, CRYPTO_ocb128_encrypt/decrypt runs with - * Offset_0 = 0 regardless of the caller's IV -- catastrophic - * (key, nonce) reuse, and a subsequent EVP_*Final_ex() emits a tag - * that is a function of (key, iv) only. - */ - if (!ctx->key_set || !update_iv(ctx)) { - ERR_raise(ERR_LIB_PROV, PROV_R_CIPHER_OPERATION_FAILED); - return 0; - } - if (!aes_generic_ocb_cipher(ctx, in, out, inl)) { ERR_raise(ERR_LIB_PROV, PROV_R_CIPHER_OPERATION_FAILED); return 0; diff --git a/providers/implementations/ciphers/cipher_aes_ocb.h b/providers/implementations/ciphers/cipher_aes_ocb.h index dfea8a1fc8..b034825603 100644 --- a/providers/implementations/ciphers/cipher_aes_ocb.h +++ b/providers/implementations/ciphers/cipher_aes_ocb.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_OCB_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_OCB_H - #include #include "prov/ciphercommon.h" #include "crypto/aes_platform.h" @@ -40,5 +37,3 @@ typedef struct prov_aes_ocb_ctx_st { } PROV_AES_OCB_CTX; const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_ocb(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_OCB_H) */ diff --git a/providers/implementations/ciphers/cipher_aes_siv.c b/providers/implementations/ciphers/cipher_aes_siv.c index f67c015f86..38f6977bf7 100644 --- a/providers/implementations/ciphers/cipher_aes_siv.c +++ b/providers/implementations/ciphers/cipher_aes_siv.c @@ -193,7 +193,6 @@ static int aes_siv_set_ctx_params(void *vctx, const OSSL_PARAM params[]) PROV_AES_SIV_CTX *ctx = (PROV_AES_SIV_CTX *)vctx; struct aes_siv_set_ctx_params_st p; unsigned int speed = 0; - SIV128_CONTEXT *sctx = &ctx->siv; if (ctx == NULL || !aes_siv_set_ctx_params_decoder(params, &p)) return 0; @@ -227,8 +226,6 @@ static int aes_siv_set_ctx_params(void *vctx, const OSSL_PARAM params[]) if (keylen != ctx->keylen) return 0; } - sctx->final_ret = -1; - return 1; } diff --git a/providers/implementations/ciphers/cipher_aes_siv.h b/providers/implementations/ciphers/cipher_aes_siv.h index cd1ce9c06b..28f6668a29 100644 --- a/providers/implementations/ciphers/cipher_aes_siv.h +++ b/providers/implementations/ciphers/cipher_aes_siv.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_SIV_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_SIV_H - #include "prov/ciphercommon.h" #include "crypto/aes_platform.h" #include "crypto/siv.h" @@ -37,5 +34,3 @@ typedef struct prov_siv_ctx_st { } PROV_AES_SIV_CTX; const PROV_CIPHER_HW_AES_SIV *ossl_prov_cipher_hw_aes_siv(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_SIV_H) */ diff --git a/providers/implementations/ciphers/cipher_aes_wrp.c b/providers/implementations/ciphers/cipher_aes_wrp.c index c1dc05e3a9..10284d2d2f 100644 --- a/providers/implementations/ciphers/cipher_aes_wrp.c +++ b/providers/implementations/ciphers/cipher_aes_wrp.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -44,17 +44,18 @@ typedef struct prov_aes_wrap_ctx_st { AES_KEY ks; } ks; aeswrap_fn wrapfn; - int updated; } PROV_AES_WRAP_CTX; -static void *aes_wrap_newctx(void *provctx, size_t kbits, size_t blkbits, +static void *aes_wrap_newctx(size_t kbits, size_t blkbits, size_t ivbits, unsigned int mode, uint64_t flags) { PROV_AES_WRAP_CTX *wctx; PROV_CIPHER_CTX *ctx; - CIPHER_PROV_CHECK(provctx, AES_128_WRP); + if (!ossl_prov_is_running()) + return NULL; + wctx = OPENSSL_zalloc(sizeof(*wctx)); ctx = (PROV_CIPHER_CTX *)wctx; if (ctx != NULL) { @@ -106,7 +107,6 @@ static int aes_wrap_init(void *vctx, const unsigned char *key, if (!ossl_prov_is_running()) return 0; - wctx->updated = 0; ctx->enc = enc; if (ctx->pad) wctx->wrapfn = enc ? CRYPTO_128_wrap_pad : CRYPTO_128_unwrap_pad; @@ -144,7 +144,6 @@ static int aes_wrap_init(void *vctx, const unsigned char *key, AES_set_decrypt_key(key, (int)(keylen * 8), &wctx->ks.ks); ctx->block = (block128_f)AES_decrypt; } - ctx->key_set = 1; } return aes_wrap_set_ctx_params(ctx, params); } @@ -210,20 +209,6 @@ static int aes_wrap_cipher_internal(void *vctx, unsigned char *out, } } - /* - * Multiple calls to update are not allowed, since the algorithm - * relies on all fields being present. - */ - if (wctx->updated) { - ERR_raise(ERR_LIB_PROV, PROV_R_UPDATE_CALL_OUT_OF_ORDER); - return -1; - } - if (!ctx->key_set) { - ERR_raise(ERR_LIB_PROV, PROV_R_NO_KEY_SET); - return -1; - } - wctx->updated = 1; - rv = wctx->wrapfn(&wctx->ks.ks, ctx->iv_set ? ctx->iv : NULL, out, in, inlen, ctx->block); if (!rv) { @@ -252,7 +237,7 @@ static int aes_wrap_cipher(void *vctx, const unsigned char *in, size_t inl) { PROV_AES_WRAP_CTX *ctx = (PROV_AES_WRAP_CTX *)vctx; - int len; + size_t len; if (!ossl_prov_is_running()) return 0; @@ -271,7 +256,7 @@ static int aes_wrap_cipher(void *vctx, if (len <= 0) return 0; - *outl = (size_t)len; + *outl = len; return 1; } @@ -313,7 +298,7 @@ static int aes_wrap_set_ctx_params(void *vctx, const OSSL_PARAM params[]) static OSSL_FUNC_cipher_newctx_fn aes_##kbits##fname##_newctx; \ static void *aes_##kbits##fname##_newctx(void *provctx) \ { \ - return aes_##mode##_newctx(provctx, kbits, blkbits, ivbits, \ + return aes_##mode##_newctx(kbits, blkbits, ivbits, \ EVP_CIPH_##UCMODE##_MODE, flags); \ } \ const OSSL_DISPATCH ossl_##aes##kbits##fname##_functions[] = { \ diff --git a/providers/implementations/ciphers/cipher_aes_xts.c b/providers/implementations/ciphers/cipher_aes_xts.c index 54820469a9..464b641210 100644 --- a/providers/implementations/ciphers/cipher_aes_xts.c +++ b/providers/implementations/ciphers/cipher_aes_xts.c @@ -1,6 +1,6 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -63,6 +63,10 @@ static int aes_xts_check_keys_differ(const unsigned char *key, size_t bytes, return 1; } +#ifdef AES_XTS_S390X +#include "cipher_aes_xts_s390x.inc" +#endif + /*- * Provider dispatch functions */ @@ -92,13 +96,6 @@ static int aes_xts_init(void *vctx, const unsigned char *key, size_t keylen, if (!ctx->hw->init(ctx, key, keylen)) return 0; } -#ifdef AES_XTS_S390X - else if (xctx->plat.s390x.fc && ctx->iv_set) { - /* special handle iv-only update */ - if (!ctx->hw->init(ctx, NULL, 0)) - return 0; - } -#endif return aes_xts_set_ctx_params(ctx, params); } @@ -106,6 +103,10 @@ static int aes_xts_einit(void *vctx, const unsigned char *key, size_t keylen, const unsigned char *iv, size_t ivlen, const OSSL_PARAM params[]) { +#ifdef AES_XTS_S390X + if (s390x_aes_xts_einit(vctx, key, keylen, iv, ivlen, params) == 1) + return 1; +#endif return aes_xts_init(vctx, key, keylen, iv, ivlen, params, 1); } @@ -113,6 +114,10 @@ static int aes_xts_dinit(void *vctx, const unsigned char *key, size_t keylen, const unsigned char *iv, size_t ivlen, const OSSL_PARAM params[]) { +#ifdef AES_XTS_S390X + if (s390x_aes_xts_dinit(vctx, key, keylen, iv, ivlen, params) == 1) + return 1; +#endif return aes_xts_init(vctx, key, keylen, iv, ivlen, params, 0); } @@ -121,7 +126,9 @@ static void *aes_xts_newctx(void *provctx, unsigned int mode, uint64_t flags, { PROV_AES_XTS_CTX *ctx; - CIPHER_PROV_CHECK(provctx, AES_128_XTS); + if (!ossl_prov_is_running()) + return NULL; + ctx = OPENSSL_zalloc(sizeof(*ctx)); if (ctx != NULL) { ossl_cipher_generic_initkey(&ctx->base, kbits, blkbits, ivbits, mode, @@ -147,6 +154,11 @@ static void *aes_xts_dupctx(void *vctx) if (!ossl_prov_is_running()) return NULL; +#ifdef AES_XTS_S390X + if (in->plat.s390x.fc) + return s390x_aes_xts_dupctx(vctx); +#endif + if (in->xts.key1 != NULL) { if (in->xts.key1 != &in->ks1) return NULL; @@ -167,23 +179,19 @@ static int aes_xts_cipher(void *vctx, unsigned char *out, size_t *outl, { PROV_AES_XTS_CTX *ctx = (PROV_AES_XTS_CTX *)vctx; - if (!ossl_prov_is_running() - || inl < AES_BLOCK_SIZE - || in == NULL - || out == NULL) - return 0; - #ifdef AES_XTS_S390X - if (ctx->plat.s390x.fc) { - if (!ctx->plat.s390x.iv_set || !ctx->plat.s390x.key_set) - return 0; - } else + if (ctx->plat.s390x.fc) + return s390x_aes_xts_cipher(vctx, out, outl, outsize, in, inl); #endif - { - if (ctx->xts.key1 == NULL || ctx->xts.key2 == NULL - || !ctx->base.iv_set) - return 0; - } + + if (!ossl_prov_is_running() + || ctx->xts.key1 == NULL + || ctx->xts.key2 == NULL + || !ctx->base.iv_set + || out == NULL + || in == NULL + || inl < AES_BLOCK_SIZE) + return 0; /* * Impose a limit of 2^20 blocks per data unit as specified by @@ -196,11 +204,6 @@ static int aes_xts_cipher(void *vctx, unsigned char *out, size_t *outl, return 0; } -#ifdef AES_XTS_S390X - if (ctx->plat.s390x.fc) - return s390x_aes_xts_cipher_stream(ctx, out, outl, in, inl); -#endif - if (ctx->stream != NULL) (*ctx->stream)(in, out, inl, ctx->xts.key1, ctx->xts.key2, ctx->base.iv); else if (CRYPTO_xts128_encrypt(&ctx->xts, ctx->base.iv, in, out, inl, diff --git a/providers/implementations/ciphers/cipher_aes_xts.h b/providers/implementations/ciphers/cipher_aes_xts.h index 49ee66ac88..2ffc143f21 100644 --- a/providers/implementations/ciphers/cipher_aes_xts.h +++ b/providers/implementations/ciphers/cipher_aes_xts.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_XTS_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_XTS_H - #include #include "prov/ciphercommon.h" #include "crypto/aes_platform.h" @@ -60,39 +57,4 @@ typedef struct prov_aes_xts_ctx_st { } plat; } PROV_AES_XTS_CTX; -int ossl_cipher_set_aes_xts_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen, - aes_set_encrypt_key_fn fn_set_enc_key, - aes_set_encrypt_key_fn fn_set_dec_key, - aes_block128_f fn_block_enc, aes_block128_f fn_block_dec, - OSSL_xts_stream_fn fn_stream_enc, OSSL_xts_stream_fn fn_stream_dec); - -void ossl_cipher_hw_aes_xts_copyctx(PROV_CIPHER_CTX *dst, - const PROV_CIPHER_CTX *src); - -#if defined(AESNI_CAPABLE) -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_xts_aesni(void); -#endif - -#if defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 32 -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_xts_rv32i(void); -#endif - -#if defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_xts_rv64i(void); -#endif - -#ifdef AES_XTS_S390X -int s390x_aes_xts_cipher_stream(PROV_AES_XTS_CTX *xctx, - unsigned char *out, size_t *outl, - const unsigned char *in, size_t inl); -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_xts_s390x(size_t keybits); -#endif - -#if defined(SPARC_AES_CAPABLE) -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_xts_t4(void); -#endif - const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_xts(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_AES_XTS_H) */ diff --git a/providers/implementations/ciphers/cipher_aes_xts_hw.c b/providers/implementations/ciphers/cipher_aes_xts_hw.c index 162f8e4593..022fbc7ff0 100644 --- a/providers/implementations/ciphers/cipher_aes_xts_hw.c +++ b/providers/implementations/ciphers/cipher_aes_xts_hw.c @@ -15,37 +15,32 @@ #include "cipher_aes_xts.h" -int ossl_cipher_set_aes_xts_initkey(PROV_CIPHER_CTX *ctx, - const unsigned char *key, size_t keylen, - aes_set_encrypt_key_fn fn_set_enc_key, - aes_set_encrypt_key_fn fn_set_dec_key, - aes_block128_f fn_block_enc, aes_block128_f fn_block_dec, - OSSL_xts_stream_fn fn_stream_enc, OSSL_xts_stream_fn fn_stream_dec) -{ - PROV_AES_XTS_CTX *xctx = (PROV_AES_XTS_CTX *)ctx; - size_t bytes = keylen / 2; - size_t bits = bytes * 8; - - if (ctx->enc) { - fn_set_enc_key(key, (int)bits, &xctx->ks1.ks); - xctx->xts.block1 = (block128_f)fn_block_enc; - } else { - fn_set_dec_key(key, (int)bits, &xctx->ks1.ks); - xctx->xts.block1 = (block128_f)fn_block_dec; +#define XTS_SET_KEY_FN(fn_set_enc_key, fn_set_dec_key, \ + fn_block_enc, fn_block_dec, \ + fn_stream_enc, fn_stream_dec) \ + { \ + size_t bytes = keylen / 2; \ + size_t bits = bytes * 8; \ + \ + if (ctx->enc) { \ + fn_set_enc_key(key, (int)bits, &xctx->ks1.ks); \ + xctx->xts.block1 = (block128_f)fn_block_enc; \ + } else { \ + fn_set_dec_key(key, (int)bits, &xctx->ks1.ks); \ + xctx->xts.block1 = (block128_f)fn_block_dec; \ + } \ + fn_set_enc_key(key + bytes, (int)bits, &xctx->ks2.ks); \ + xctx->xts.block2 = (block128_f)fn_block_enc; \ + xctx->xts.key1 = &xctx->ks1; \ + xctx->xts.key2 = &xctx->ks2; \ + xctx->stream = ctx->enc ? fn_stream_enc : fn_stream_dec; \ } - fn_set_enc_key(key + bytes, (int)bits, &xctx->ks2.ks); - xctx->xts.block2 = (block128_f)fn_block_enc; - xctx->xts.key1 = &xctx->ks1; - xctx->xts.key2 = &xctx->ks2; - xctx->stream = ctx->enc ? fn_stream_enc : fn_stream_dec; - - return 1; -} static int cipher_hw_aes_xts_generic_initkey(PROV_CIPHER_CTX *ctx, const unsigned char *key, size_t keylen) { + PROV_AES_XTS_CTX *xctx = (PROV_AES_XTS_CTX *)ctx; OSSL_xts_stream_fn stream_enc = NULL; OSSL_xts_stream_fn stream_dec = NULL; @@ -62,36 +57,37 @@ static int cipher_hw_aes_xts_generic_initkey(PROV_CIPHER_CTX *ctx, #ifdef HWAES_xts_decrypt stream_dec = HWAES_xts_decrypt; #endif /* HWAES_xts_decrypt */ - return ossl_cipher_set_aes_xts_initkey(ctx, key, keylen, - HWAES_set_encrypt_key, HWAES_set_decrypt_key, - HWAES_encrypt, HWAES_decrypt, stream_enc, stream_dec); - } + XTS_SET_KEY_FN(HWAES_set_encrypt_key, HWAES_set_decrypt_key, + HWAES_encrypt, HWAES_decrypt, + stream_enc, stream_dec); + return 1; + } else #endif /* HWAES_CAPABLE */ #ifdef BSAES_CAPABLE - if (BSAES_CAPABLE) { + if (BSAES_CAPABLE) { stream_enc = ossl_bsaes_xts_encrypt; stream_dec = ossl_bsaes_xts_decrypt; - return ossl_cipher_set_aes_xts_initkey(ctx, key, keylen, - AES_set_encrypt_key, AES_set_decrypt_key, + } else +#endif /* BSAES_CAPABLE */ +#ifdef VPAES_CAPABLE + if (VPAES_CAPABLE) { + XTS_SET_KEY_FN(vpaes_set_encrypt_key, vpaes_set_decrypt_key, + vpaes_encrypt, vpaes_decrypt, stream_enc, stream_dec); + return 1; + } else +#endif /* VPAES_CAPABLE */ + { + (void)0; + } + { + XTS_SET_KEY_FN(AES_set_encrypt_key, AES_set_decrypt_key, AES_encrypt, AES_decrypt, stream_enc, stream_dec); } -#endif /* BSAES_CAPABLE */ - -#ifdef VPAES_CAPABLE - if (VPAES_CAPABLE) { - return ossl_cipher_set_aes_xts_initkey(ctx, key, keylen, - vpaes_set_encrypt_key, vpaes_set_decrypt_key, - vpaes_encrypt, vpaes_decrypt, stream_enc, stream_dec); - } -#endif /* VPAES_CAPABLE */ - - return ossl_cipher_set_aes_xts_initkey(ctx, key, keylen, - AES_set_encrypt_key, AES_set_decrypt_key, - AES_encrypt, AES_decrypt, stream_enc, stream_dec); + return 1; } -void ossl_cipher_hw_aes_xts_copyctx(PROV_CIPHER_CTX *dst, +static void cipher_hw_aes_xts_copyctx(PROV_CIPHER_CTX *dst, const PROV_CIPHER_CTX *src) { PROV_AES_XTS_CTX *sctx = (PROV_AES_XTS_CTX *)src; @@ -102,30 +98,234 @@ void ossl_cipher_hw_aes_xts_copyctx(PROV_CIPHER_CTX *dst, dctx->xts.key2 = &dctx->ks2.ks; } +#if defined(AESNI_CAPABLE) + +static int cipher_hw_aesni_xts_initkey(PROV_CIPHER_CTX *ctx, + const unsigned char *key, size_t keylen) +{ + PROV_AES_XTS_CTX *xctx = (PROV_AES_XTS_CTX *)ctx; + + void (*aesni_xts_enc)(const unsigned char *in, + unsigned char *out, + size_t length, + const AES_KEY *key1, const AES_KEY *key2, + const unsigned char iv[16]); + void (*aesni_xts_dec)(const unsigned char *in, + unsigned char *out, + size_t length, + const AES_KEY *key1, const AES_KEY *key2, + const unsigned char iv[16]); + + aesni_xts_enc = aesni_xts_encrypt; + aesni_xts_dec = aesni_xts_decrypt; + +#if (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)) + if (aesni_xts_avx512_eligible()) { + if (keylen == 64) { + aesni_xts_enc = aesni_xts_256_encrypt_avx512; + aesni_xts_dec = aesni_xts_256_decrypt_avx512; + } else if (keylen == 32) { + aesni_xts_enc = aesni_xts_128_encrypt_avx512; + aesni_xts_dec = aesni_xts_128_decrypt_avx512; + } + } +#endif + + XTS_SET_KEY_FN(aesni_set_encrypt_key, aesni_set_decrypt_key, + aesni_encrypt, aesni_decrypt, + aesni_xts_enc, aesni_xts_dec); + return 1; +} + +#define PROV_CIPHER_HW_declare_xts() \ + static const PROV_CIPHER_HW aesni_xts = { \ + cipher_hw_aesni_xts_initkey, \ + NULL, \ + cipher_hw_aes_xts_copyctx \ + }; +#define PROV_CIPHER_HW_select_xts() \ + if (AESNI_CAPABLE) \ + return &aesni_xts; + +#elif defined(SPARC_AES_CAPABLE) + +static int cipher_hw_aes_xts_t4_initkey(PROV_CIPHER_CTX *ctx, + const unsigned char *key, size_t keylen) +{ + PROV_AES_XTS_CTX *xctx = (PROV_AES_XTS_CTX *)ctx; + OSSL_xts_stream_fn stream_enc = NULL; + OSSL_xts_stream_fn stream_dec = NULL; + + /* Note: keylen is the size of 2 keys */ + switch (keylen) { + case 32: + stream_enc = aes128_t4_xts_encrypt; + stream_dec = aes128_t4_xts_decrypt; + break; + case 64: + stream_enc = aes256_t4_xts_encrypt; + stream_dec = aes256_t4_xts_decrypt; + break; + default: + return 0; + } + + XTS_SET_KEY_FN(aes_t4_set_encrypt_key, aes_t4_set_decrypt_key, + aes_t4_encrypt, aes_t4_decrypt, + stream_enc, stream_dec); + return 1; +} + +#define PROV_CIPHER_HW_declare_xts() \ + static const PROV_CIPHER_HW aes_xts_t4 = { \ + cipher_hw_aes_xts_t4_initkey, \ + NULL, \ + cipher_hw_aes_xts_copyctx \ + }; +#define PROV_CIPHER_HW_select_xts() \ + if (SPARC_AES_CAPABLE) \ + return &aes_xts_t4; + +#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 + +static int cipher_hw_aes_xts_rv64i_zknd_zkne_initkey(PROV_CIPHER_CTX *ctx, + const unsigned char *key, + size_t keylen) +{ + PROV_AES_XTS_CTX *xctx = (PROV_AES_XTS_CTX *)ctx; + OSSL_xts_stream_fn stream_enc = NULL; + OSSL_xts_stream_fn stream_dec = NULL; + + XTS_SET_KEY_FN(rv64i_zkne_set_encrypt_key, rv64i_zknd_set_decrypt_key, + rv64i_zkne_encrypt, rv64i_zknd_decrypt, + stream_enc, stream_dec); + return 1; +} + +static int cipher_hw_aes_xts_rv64i_zvbb_zvkg_zvkned_initkey( + PROV_CIPHER_CTX *ctx, const unsigned char *key, size_t keylen) +{ + PROV_AES_XTS_CTX *xctx = (PROV_AES_XTS_CTX *)ctx; + OSSL_xts_stream_fn stream_enc = NULL; + OSSL_xts_stream_fn stream_dec = NULL; + + /* Zvkned only supports 128 and 256 bit keys. */ + if (keylen * 8 == 128 * 2 || keylen * 8 == 256 * 2) { + XTS_SET_KEY_FN(rv64i_zvkned_set_encrypt_key, + rv64i_zvkned_set_decrypt_key, rv64i_zvkned_encrypt, + rv64i_zvkned_decrypt, + rv64i_zvbb_zvkg_zvkned_aes_xts_encrypt, + rv64i_zvbb_zvkg_zvkned_aes_xts_decrypt); + } else { + XTS_SET_KEY_FN(AES_set_encrypt_key, AES_set_encrypt_key, + rv64i_zvkned_encrypt, rv64i_zvkned_decrypt, + stream_enc, stream_dec); + } + return 1; +} + +static int cipher_hw_aes_xts_rv64i_zvkned_initkey(PROV_CIPHER_CTX *ctx, + const unsigned char *key, + size_t keylen) +{ + PROV_AES_XTS_CTX *xctx = (PROV_AES_XTS_CTX *)ctx; + OSSL_xts_stream_fn stream_enc = NULL; + OSSL_xts_stream_fn stream_dec = NULL; + + /* Zvkned only supports 128 and 256 bit keys. */ + if (keylen * 8 == 128 * 2 || keylen * 8 == 256 * 2) { + XTS_SET_KEY_FN(rv64i_zvkned_set_encrypt_key, + rv64i_zvkned_set_decrypt_key, + rv64i_zvkned_encrypt, rv64i_zvkned_decrypt, + stream_enc, stream_dec); + } else { + XTS_SET_KEY_FN(AES_set_encrypt_key, AES_set_encrypt_key, + rv64i_zvkned_encrypt, rv64i_zvkned_decrypt, + stream_enc, stream_dec); + } + return 1; +} + +#define PROV_CIPHER_HW_declare_xts() \ + static const PROV_CIPHER_HW aes_xts_rv64i_zknd_zkne = { \ + cipher_hw_aes_xts_rv64i_zknd_zkne_initkey, \ + NULL, \ + cipher_hw_aes_xts_copyctx \ + }; \ + static const PROV_CIPHER_HW aes_xts_rv64i_zvkned = { \ + cipher_hw_aes_xts_rv64i_zvkned_initkey, \ + NULL, \ + cipher_hw_aes_xts_copyctx \ + }; \ + static const PROV_CIPHER_HW aes_xts_rv64i_zvbb_zvkg_zvkned = { \ + cipher_hw_aes_xts_rv64i_zvbb_zvkg_zvkned_initkey, \ + NULL, \ + cipher_hw_aes_xts_copyctx \ + }; + +#define PROV_CIPHER_HW_select_xts() \ + if (RISCV_HAS_ZVBB() && RISCV_HAS_ZVKG() && RISCV_HAS_ZVKNED() && riscv_vlen() >= 128) \ + return &aes_xts_rv64i_zvbb_zvkg_zvkned; \ + if (RISCV_HAS_ZVKNED() && riscv_vlen() >= 128) \ + return &aes_xts_rv64i_zvkned; \ + else if (RISCV_HAS_ZKND_AND_ZKNE()) \ + return &aes_xts_rv64i_zknd_zkne; + +#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 32 + +static int cipher_hw_aes_xts_rv32i_zknd_zkne_initkey(PROV_CIPHER_CTX *ctx, + const unsigned char *key, + size_t keylen) +{ + PROV_AES_XTS_CTX *xctx = (PROV_AES_XTS_CTX *)ctx; + + XTS_SET_KEY_FN(rv32i_zkne_set_encrypt_key, rv32i_zknd_zkne_set_decrypt_key, + rv32i_zkne_encrypt, rv32i_zknd_decrypt, + NULL, NULL); + return 1; +} + +static int cipher_hw_aes_xts_rv32i_zbkb_zknd_zkne_initkey(PROV_CIPHER_CTX *ctx, + const unsigned char *key, + size_t keylen) +{ + PROV_AES_XTS_CTX *xctx = (PROV_AES_XTS_CTX *)ctx; + + XTS_SET_KEY_FN(rv32i_zbkb_zkne_set_encrypt_key, rv32i_zbkb_zknd_zkne_set_decrypt_key, + rv32i_zkne_encrypt, rv32i_zknd_decrypt, + NULL, NULL); + return 1; +} + +#define PROV_CIPHER_HW_declare_xts() \ + static const PROV_CIPHER_HW aes_xts_rv32i_zknd_zkne = { \ + cipher_hw_aes_xts_rv32i_zknd_zkne_initkey, \ + NULL, \ + cipher_hw_aes_xts_copyctx \ + }; \ + static const PROV_CIPHER_HW aes_xts_rv32i_zbkb_zknd_zkne = { \ + cipher_hw_aes_xts_rv32i_zbkb_zknd_zkne_initkey, \ + NULL, \ + cipher_hw_aes_xts_copyctx \ + }; +#define PROV_CIPHER_HW_select_xts() \ + if (RISCV_HAS_ZBKB_AND_ZKND_AND_ZKNE()) \ + return &aes_xts_rv32i_zbkb_zknd_zkne; \ + if (RISCV_HAS_ZKND_AND_ZKNE()) \ + return &aes_xts_rv32i_zknd_zkne; +#else +/* The generic case */ +#define PROV_CIPHER_HW_declare_xts() +#define PROV_CIPHER_HW_select_xts() +#endif + static const PROV_CIPHER_HW aes_generic_xts = { cipher_hw_aes_xts_generic_initkey, NULL, - ossl_cipher_hw_aes_xts_copyctx + cipher_hw_aes_xts_copyctx }; - -const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_xts(size_t keybits) +PROV_CIPHER_HW_declare_xts() + const PROV_CIPHER_HW *ossl_prov_cipher_hw_aes_xts(size_t keybits) { - const PROV_CIPHER_HW *aes_xts_hw = NULL; - -#if defined(AESNI_CAPABLE) - aes_xts_hw = ossl_prov_cipher_hw_aes_xts_aesni(); -#elif defined(SPARC_AES_CAPABLE) - aes_xts_hw = ossl_prov_cipher_hw_aes_xts_t4(); -#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 32 - aes_xts_hw = ossl_prov_cipher_hw_aes_xts_rv32i(); -#elif defined(OPENSSL_CPUID_OBJ) && defined(__riscv) && __riscv_xlen == 64 - aes_xts_hw = ossl_prov_cipher_hw_aes_xts_rv64i(); -#elif defined(AES_XTS_S390X) - aes_xts_hw = ossl_prov_cipher_hw_aes_xts_s390x(keybits); -#endif - - if (aes_xts_hw == NULL) - return &aes_generic_xts; - - return aes_xts_hw; + PROV_CIPHER_HW_select_xts() return &aes_generic_xts; } diff --git a/providers/implementations/ciphers/cipher_aes_xts_s390x.inc b/providers/implementations/ciphers/cipher_aes_xts_s390x.inc new file mode 100644 index 0000000000..77341b3bbd --- /dev/null +++ b/providers/implementations/ciphers/cipher_aes_xts_s390x.inc @@ -0,0 +1,167 @@ +/* + * Copyright 2024 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +#include "crypto/s390x_arch.h" + +static OSSL_FUNC_cipher_encrypt_init_fn s390x_aes_xts_einit; +static OSSL_FUNC_cipher_decrypt_init_fn s390x_aes_xts_dinit; +static OSSL_FUNC_cipher_cipher_fn s390x_aes_xts_cipher; +static OSSL_FUNC_cipher_dupctx_fn s390x_aes_xts_dupctx; + +static int s390x_aes_xts_init(void *vctx, const unsigned char *key, + size_t keylen, const unsigned char *iv, + size_t ivlen, const OSSL_PARAM params[], + unsigned int dec) +{ + PROV_AES_XTS_CTX *xctx = (PROV_AES_XTS_CTX *)vctx; + S390X_KM_XTS_PARAMS *km = &xctx->plat.s390x.param.km; + unsigned int fc, offs; + + switch (xctx->base.keylen) { + case 128 / 8 * 2: + fc = S390X_XTS_AES_128_MSA10; + offs = 32; + break; + case 256 / 8 * 2: + fc = S390X_XTS_AES_256_MSA10; + offs = 0; + break; + default: + goto not_supported; + } + + if (!(OPENSSL_s390xcap_P.km[1] && S390X_CAPBIT(fc))) + goto not_supported; + + if (iv != NULL) { + if (ivlen != xctx->base.ivlen + || ivlen > sizeof(km->tweak)) { + ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_IV_LENGTH); + return 0; + } + memcpy(km->tweak, iv, ivlen); + xctx->plat.s390x.iv_set = 1; + } + + if (key != NULL) { + if (keylen != xctx->base.keylen) { + ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); + return 0; + } + if (!aes_xts_check_keys_differ(key, keylen / 2, !dec)) + return 0; + + memcpy(km->key + offs, key, keylen); + xctx->plat.s390x.key_set = 1; + } + + xctx->plat.s390x.fc = fc | dec; + xctx->plat.s390x.offset = offs; + + memset(km->nap, 0, sizeof(km->nap)); + km->nap[0] = 0x1; + + return aes_xts_set_ctx_params(xctx, params); + +not_supported: + xctx->plat.s390x.fc = 0; + xctx->plat.s390x.offset = 0; + return 0; +} + +static int s390x_aes_xts_einit(void *vctx, const unsigned char *key, + size_t keylen, const unsigned char *iv, + size_t ivlen, const OSSL_PARAM params[]) +{ + return s390x_aes_xts_init(vctx, key, keylen, iv, ivlen, params, 0); +} + +static int s390x_aes_xts_dinit(void *vctx, const unsigned char *key, + size_t keylen, const unsigned char *iv, + size_t ivlen, const OSSL_PARAM params[]) +{ + return s390x_aes_xts_init(vctx, key, keylen, iv, ivlen, params, + S390X_DECRYPT); +} + +static void *s390x_aes_xts_dupctx(void *vctx) +{ + PROV_AES_XTS_CTX *in = (PROV_AES_XTS_CTX *)vctx; + PROV_AES_XTS_CTX *ret = OPENSSL_zalloc(sizeof(*in)); + + if (ret != NULL) + *ret = *in; + + return ret; +} + +static int s390x_aes_xts_cipher(void *vctx, unsigned char *out, size_t *outl, + size_t outsize, const unsigned char *in, + size_t inl) +{ + PROV_AES_XTS_CTX *xctx = (PROV_AES_XTS_CTX *)vctx; + S390X_KM_XTS_PARAMS *km = &xctx->plat.s390x.param.km; + unsigned char *param = (unsigned char *)km + xctx->plat.s390x.offset; + unsigned int fc = xctx->plat.s390x.fc; + unsigned char tmp[2][AES_BLOCK_SIZE]; + unsigned char nap_n1[AES_BLOCK_SIZE]; + unsigned char drop[AES_BLOCK_SIZE]; + size_t len_incomplete, len_complete; + + if (!ossl_prov_is_running() + || inl < AES_BLOCK_SIZE + || in == NULL + || out == NULL + || !xctx->plat.s390x.iv_set + || !xctx->plat.s390x.key_set) + return 0; + + /* + * Impose a limit of 2^20 blocks per data unit as specified by + * IEEE Std 1619-2018. The earlier and obsolete IEEE Std 1619-2007 + * indicated that this was a SHOULD NOT rather than a MUST NOT. + * NIST SP 800-38E mandates the same limit. + */ + if (inl > XTS_MAX_BLOCKS_PER_DATA_UNIT * AES_BLOCK_SIZE) { + ERR_raise(ERR_LIB_PROV, PROV_R_XTS_DATA_UNIT_IS_TOO_LARGE); + return 0; + } + + len_incomplete = inl % AES_BLOCK_SIZE; + len_complete = (len_incomplete == 0) ? inl : + (inl / AES_BLOCK_SIZE - 1) * AES_BLOCK_SIZE; + + if (len_complete > 0) + s390x_km(in, len_complete, out, fc, param); + if (len_incomplete == 0) + goto out; + + memcpy(tmp, in + len_complete, AES_BLOCK_SIZE + len_incomplete); + /* swap NAP for decrypt */ + if (fc & S390X_DECRYPT) { + memcpy(nap_n1, km->nap, AES_BLOCK_SIZE); + s390x_km(tmp[0], AES_BLOCK_SIZE, drop, fc, param); + } + s390x_km(tmp[0], AES_BLOCK_SIZE, tmp[0], fc, param); + if (fc & S390X_DECRYPT) + memcpy(km->nap, nap_n1, AES_BLOCK_SIZE); + + memcpy(tmp[1] + len_incomplete, tmp[0] + len_incomplete, + AES_BLOCK_SIZE - len_incomplete); + s390x_km(tmp[1], AES_BLOCK_SIZE, out + len_complete, fc, param); + memcpy(out + len_complete + AES_BLOCK_SIZE, tmp[0], len_incomplete); + + /* do not expose temporary data */ + OPENSSL_cleanse(tmp, sizeof(tmp)); +out: + memcpy(xctx->base.iv, km->tweak, AES_BLOCK_SIZE); + *outl = inl; + + return 1; +} diff --git a/providers/implementations/ciphers/cipher_aria.h b/providers/implementations/ciphers/cipher_aria.h index 61f2f1b459..563262aee8 100644 --- a/providers/implementations/ciphers/cipher_aria.h +++ b/providers/implementations/ciphers/cipher_aria.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_ARIA_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_ARIA_H - #include "crypto/aria.h" #include "prov/ciphercommon.h" @@ -30,5 +27,3 @@ const PROV_CIPHER_HW *ossl_prov_cipher_hw_aria_cfb128(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_aria_cfb1(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_aria_cfb8(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_aria_ctr(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_ARIA_H) */ diff --git a/providers/implementations/ciphers/cipher_aria_ccm.h b/providers/implementations/ciphers/cipher_aria_ccm.h index 51b084e65e..7de71e7c00 100644 --- a/providers/implementations/ciphers/cipher_aria_ccm.h +++ b/providers/implementations/ciphers/cipher_aria_ccm.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_ARIA_CCM_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_ARIA_CCM_H - #include "crypto/aria.h" #include "prov/ciphercommon.h" #include "prov/ciphercommon_ccm.h" @@ -23,5 +20,3 @@ typedef struct prov_aria_ccm_ctx_st { } PROV_ARIA_CCM_CTX; const PROV_CCM_HW *ossl_prov_aria_hw_ccm(size_t keylen); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_ARIA_CCM_H) */ diff --git a/providers/implementations/ciphers/cipher_aria_gcm.h b/providers/implementations/ciphers/cipher_aria_gcm.h index 984d2b8396..622053a559 100644 --- a/providers/implementations/ciphers/cipher_aria_gcm.h +++ b/providers/implementations/ciphers/cipher_aria_gcm.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_ARIA_GCM_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_ARIA_GCM_H - #include "crypto/aria.h" #include "prov/ciphercommon.h" #include "prov/ciphercommon_gcm.h" @@ -23,5 +20,3 @@ typedef struct prov_aria_gcm_ctx_st { } PROV_ARIA_GCM_CTX; const PROV_GCM_HW *ossl_prov_aria_hw_gcm(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_ARIA_GCM_H) */ diff --git a/providers/implementations/ciphers/cipher_aria_gcm_hw.c b/providers/implementations/ciphers/cipher_aria_gcm_hw.c index 35f3257d89..f4c8646103 100644 --- a/providers/implementations/ciphers/cipher_aria_gcm_hw.c +++ b/providers/implementations/ciphers/cipher_aria_gcm_hw.c @@ -19,11 +19,7 @@ static int aria_gcm_initkey(PROV_GCM_CTX *ctx, const unsigned char *key, PROV_ARIA_GCM_CTX *actx = (PROV_ARIA_GCM_CTX *)ctx; ARIA_KEY *ks = &actx->ks.ks; - ossl_aria_set_encrypt_key(key, (int)(keylen * 8), ks); - CRYPTO_gcm128_init(&ctx->gcm, ks, (block128_f)ossl_aria_encrypt); - ctx->ctr = NULL; - ctx->key_set = 1; - + GCM_HW_SET_KEY_CTR_FN(ks, ossl_aria_set_encrypt_key, ossl_aria_encrypt, NULL); return 1; } diff --git a/providers/implementations/ciphers/cipher_aria_hw.c b/providers/implementations/ciphers/cipher_aria_hw.c index ec515295b0..ae77425255 100644 --- a/providers/implementations/ciphers/cipher_aria_hw.c +++ b/providers/implementations/ciphers/cipher_aria_hw.c @@ -44,9 +44,9 @@ IMPLEMENT_CIPHER_HW_COPYCTX(cipher_hw_aria_copyctx, PROV_ARIA_CTX) } PROV_CIPHER_HW_aria_mode(cbc) -PROV_CIPHER_HW_aria_mode(ecb) -PROV_CIPHER_HW_aria_mode(ofb128) -PROV_CIPHER_HW_aria_mode(cfb128) -PROV_CIPHER_HW_aria_mode(cfb1) -PROV_CIPHER_HW_aria_mode(cfb8) -PROV_CIPHER_HW_aria_mode(ctr) + PROV_CIPHER_HW_aria_mode(ecb) + PROV_CIPHER_HW_aria_mode(ofb128) + PROV_CIPHER_HW_aria_mode(cfb128) + PROV_CIPHER_HW_aria_mode(cfb1) + PROV_CIPHER_HW_aria_mode(cfb8) + PROV_CIPHER_HW_aria_mode(ctr) diff --git a/providers/implementations/ciphers/cipher_blowfish.h b/providers/implementations/ciphers/cipher_blowfish.h index 8c3366866f..18c824fed1 100644 --- a/providers/implementations/ciphers/cipher_blowfish.h +++ b/providers/implementations/ciphers/cipher_blowfish.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_BLOWFISH_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_BLOWFISH_H - #include #include "prov/ciphercommon.h" @@ -25,5 +22,3 @@ const PROV_CIPHER_HW *ossl_prov_cipher_hw_blowfish_cbc(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_blowfish_ecb(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_blowfish_ofb64(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_blowfish_cfb64(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_BLOWFISH_H) */ diff --git a/providers/implementations/ciphers/cipher_camellia.h b/providers/implementations/ciphers/cipher_camellia.h index 1ef9106823..2c1156ae92 100644 --- a/providers/implementations/ciphers/cipher_camellia.h +++ b/providers/implementations/ciphers/cipher_camellia.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_CAMELLIA_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_CAMELLIA_H - #include #include "prov/ciphercommon.h" #include "crypto/cmll_platform.h" @@ -31,5 +28,3 @@ const PROV_CIPHER_HW *ossl_prov_cipher_hw_camellia_cfb128(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_camellia_cfb1(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_camellia_cfb8(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_camellia_ctr(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_CAMELLIA_H) */ diff --git a/providers/implementations/ciphers/cipher_camellia_hw.c b/providers/implementations/ciphers/cipher_camellia_hw.c index e8dfbe1517..0fe032a36e 100644 --- a/providers/implementations/ciphers/cipher_camellia_hw.c +++ b/providers/implementations/ciphers/cipher_camellia_hw.c @@ -64,9 +64,9 @@ IMPLEMENT_CIPHER_HW_COPYCTX(cipher_hw_camellia_copyctx, PROV_CAMELLIA_CTX) } PROV_CIPHER_HW_camellia_mode(cbc) -PROV_CIPHER_HW_camellia_mode(ecb) -PROV_CIPHER_HW_camellia_mode(ofb128) -PROV_CIPHER_HW_camellia_mode(cfb128) -PROV_CIPHER_HW_camellia_mode(cfb1) -PROV_CIPHER_HW_camellia_mode(cfb8) -PROV_CIPHER_HW_camellia_mode(ctr) + PROV_CIPHER_HW_camellia_mode(ecb) + PROV_CIPHER_HW_camellia_mode(ofb128) + PROV_CIPHER_HW_camellia_mode(cfb128) + PROV_CIPHER_HW_camellia_mode(cfb1) + PROV_CIPHER_HW_camellia_mode(cfb8) + PROV_CIPHER_HW_camellia_mode(ctr) diff --git a/providers/implementations/ciphers/cipher_cast.h b/providers/implementations/ciphers/cipher_cast.h index 11164f543f..d0451861e3 100644 --- a/providers/implementations/ciphers/cipher_cast.h +++ b/providers/implementations/ciphers/cipher_cast.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_CAST_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_CAST_H - #include #include "prov/ciphercommon.h" @@ -25,5 +22,3 @@ const PROV_CIPHER_HW *ossl_prov_cipher_hw_cast5_cbc(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_cast5_ecb(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_cast5_ofb64(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_cast5_cfb64(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_CAST_H) */ diff --git a/providers/implementations/ciphers/cipher_chacha20.h b/providers/implementations/ciphers/cipher_chacha20.h index 5338ad949c..ed531d7933 100644 --- a/providers/implementations/ciphers/cipher_chacha20.h +++ b/providers/implementations/ciphers/cipher_chacha20.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_CHACHA20_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_CHACHA20_H - #include "include/crypto/chacha.h" #include "prov/ciphercommon.h" @@ -35,5 +32,3 @@ const PROV_CIPHER_HW *ossl_prov_cipher_hw_chacha20(size_t keybits); OSSL_FUNC_cipher_encrypt_init_fn ossl_chacha20_einit; OSSL_FUNC_cipher_decrypt_init_fn ossl_chacha20_dinit; void ossl_chacha20_initctx(PROV_CHACHA20_CTX *ctx); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_CHACHA20_H) */ diff --git a/providers/implementations/ciphers/cipher_chacha20_hw.c b/providers/implementations/ciphers/cipher_chacha20_hw.c index 644b4e540a..4d55f9bf82 100644 --- a/providers/implementations/ciphers/cipher_chacha20_hw.c +++ b/providers/implementations/ciphers/cipher_chacha20_hw.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -119,5 +119,5 @@ static const PROV_CIPHER_HW_CHACHA20 chacha20_hw = { const PROV_CIPHER_HW *ossl_prov_cipher_hw_chacha20(size_t keybits) { - return (const PROV_CIPHER_HW *)&chacha20_hw; + return (PROV_CIPHER_HW *)&chacha20_hw; } diff --git a/providers/implementations/ciphers/cipher_chacha20_poly1305.c b/providers/implementations/ciphers/cipher_chacha20_poly1305.c index a48b9c3725..e95289598a 100644 --- a/providers/implementations/ciphers/cipher_chacha20_poly1305.c +++ b/providers/implementations/ciphers/cipher_chacha20_poly1305.c @@ -36,6 +36,7 @@ static OSSL_FUNC_cipher_final_fn chacha20_poly1305_final; static OSSL_FUNC_cipher_gettable_ctx_params_fn chacha20_poly1305_gettable_ctx_params; static OSSL_FUNC_cipher_settable_ctx_params_fn chacha20_poly1305_settable_ctx_params; #define chacha20_poly1305_gettable_params ossl_cipher_generic_gettable_params +#define chacha20_poly1305_update chacha20_poly1305_cipher static void *chacha20_poly1305_newctx(void *provctx) { @@ -189,7 +190,6 @@ static int chacha20_poly1305_set_ctx_params(void *vctx, ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_IV_LENGTH); return 0; } - ctx->iv_state = IV_STATE_UNINITIALISED; } if (p.tag != NULL) { @@ -249,11 +249,9 @@ static int chacha20_poly1305_einit(void *vctx, const unsigned char *key, ret = ossl_cipher_generic_einit(vctx, key, keylen, iv, ivlen, NULL); if (ret && iv != NULL) { PROV_CIPHER_CTX *ctx = (PROV_CIPHER_CTX *)vctx; - PROV_CHACHA20_POLY1305_CTX *cctx = (PROV_CHACHA20_POLY1305_CTX *)vctx; PROV_CIPHER_HW_CHACHA20_POLY1305 *hw = (PROV_CIPHER_HW_CHACHA20_POLY1305 *)ctx->hw; hw->initiv(ctx); - cctx->iv_state = IV_STATE_BUFFERED; } if (ret && !chacha20_poly1305_set_ctx_params(vctx, params)) ret = 0; @@ -270,11 +268,9 @@ static int chacha20_poly1305_dinit(void *vctx, const unsigned char *key, ret = ossl_cipher_generic_dinit(vctx, key, keylen, iv, ivlen, NULL); if (ret && iv != NULL) { PROV_CIPHER_CTX *ctx = (PROV_CIPHER_CTX *)vctx; - PROV_CHACHA20_POLY1305_CTX *cctx = (PROV_CHACHA20_POLY1305_CTX *)vctx; PROV_CIPHER_HW_CHACHA20_POLY1305 *hw = (PROV_CIPHER_HW_CHACHA20_POLY1305 *)ctx->hw; hw->initiv(ctx); - cctx->iv_state = IV_STATE_BUFFERED; } if (ret && !chacha20_poly1305_set_ctx_params(vctx, params)) ret = 0; @@ -307,18 +303,6 @@ static int chacha20_poly1305_cipher(void *vctx, unsigned char *out, return 1; } -static int chacha20_poly1305_update(void *vctx, unsigned char *out, - size_t *outl, size_t outsize, - const unsigned char *in, size_t inl) -{ - PROV_CHACHA20_POLY1305_CTX *ctx = (PROV_CHACHA20_POLY1305_CTX *)vctx; - - if (ctx->iv_state == IV_STATE_FINISHED) - return 0; - - return chacha20_poly1305_cipher(vctx, out, outl, outsize, in, inl); -} - static int chacha20_poly1305_final(void *vctx, unsigned char *out, size_t *outl, size_t outsize) { @@ -338,9 +322,6 @@ static int chacha20_poly1305_final(void *vctx, unsigned char *out, size_t *outl, return 0; *outl = 0; - - /* Don't reuse the IV */ - ctx->iv_state = IV_STATE_FINISHED; return 1; } diff --git a/providers/implementations/ciphers/cipher_chacha20_poly1305.h b/providers/implementations/ciphers/cipher_chacha20_poly1305.h index 6914966f6e..2e82fdb947 100644 --- a/providers/implementations/ciphers/cipher_chacha20_poly1305.h +++ b/providers/implementations/ciphers/cipher_chacha20_poly1305.h @@ -9,9 +9,6 @@ /* Dispatch functions for chacha20_poly1305 cipher */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_CHACHA20_POLY1305_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_CHACHA20_POLY1305_H - #include "include/crypto/poly1305.h" #include "cipher_chacha20.h" @@ -33,7 +30,6 @@ typedef struct { size_t tag_len; size_t tls_payload_length; size_t tls_aad_pad_sz; - unsigned int iv_state; /* set to one of IV_STATE_XXX */ } PROV_CHACHA20_POLY1305_CTX; typedef struct prov_cipher_hw_chacha_aead_st { @@ -47,5 +43,3 @@ typedef struct prov_cipher_hw_chacha_aead_st { } PROV_CIPHER_HW_CHACHA20_POLY1305; const PROV_CIPHER_HW *ossl_prov_cipher_hw_chacha20_poly1305(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_CHACHA20_POLY1305_H) */ diff --git a/providers/implementations/ciphers/cipher_chacha20_poly1305_hw.c b/providers/implementations/ciphers/cipher_chacha20_poly1305_hw.c index 31a163e57e..733547a7e7 100644 --- a/providers/implementations/ciphers/cipher_chacha20_poly1305_hw.c +++ b/providers/implementations/ciphers/cipher_chacha20_poly1305_hw.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -9,7 +9,6 @@ /* chacha20_poly1305 cipher implementation */ -#include #include "internal/endian.h" #include "cipher_chacha20_poly1305.h" @@ -302,10 +301,6 @@ static int chacha20_poly1305_aead_cipher(PROV_CIPHER_CTX *bctx, if (in != NULL) { /* aad or text */ if (out == NULL) { /* aad */ - if (ctx->len.text != 0) { - ERR_raise(ERR_LIB_PROV, PROV_R_UPDATE_CALL_OUT_OF_ORDER); - goto err; - } Poly1305_Update(poly, in, inl); ctx->len.aad += inl; ctx->aad = 1; @@ -411,5 +406,5 @@ static const PROV_CIPHER_HW_CHACHA20_POLY1305 chacha20poly1305_hw = { const PROV_CIPHER_HW *ossl_prov_cipher_hw_chacha20_poly1305(size_t keybits) { - return (const PROV_CIPHER_HW *)&chacha20poly1305_hw; + return (PROV_CIPHER_HW *)&chacha20poly1305_hw; } diff --git a/providers/implementations/ciphers/cipher_cts.h b/providers/implementations/ciphers/cipher_cts.h index 8bae4f8d3b..b3a677b6aa 100644 --- a/providers/implementations/ciphers/cipher_cts.h +++ b/providers/implementations/ciphers/cipher_cts.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_CTS_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_CTS_H - #include "crypto/evp.h" /* NOTE: The underlying block cipher is CBC so we reuse most of the code */ @@ -53,5 +50,3 @@ OSSL_FUNC_cipher_final_fn ossl_cipher_cbc_cts_block_final; const char *ossl_cipher_cbc_cts_mode_id2name(unsigned int id); int ossl_cipher_cbc_cts_mode_name2id(const char *name); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_CTS_H) */ diff --git a/providers/implementations/ciphers/cipher_des.h b/providers/implementations/ciphers/cipher_des.h index afbb665662..9fd72f0068 100644 --- a/providers/implementations/ciphers/cipher_des.h +++ b/providers/implementations/ciphers/cipher_des.h @@ -7,12 +7,8 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_DES_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_DES_H - #include #include "crypto/des_platform.h" -#include "prov/ciphercommon.h" #define TDES_FLAGS 0 @@ -35,5 +31,3 @@ const PROV_CIPHER_HW *ossl_prov_cipher_hw_des_ofb64(void); const PROV_CIPHER_HW *ossl_prov_cipher_hw_des_cfb64(void); const PROV_CIPHER_HW *ossl_prov_cipher_hw_des_cfb1(void); const PROV_CIPHER_HW *ossl_prov_cipher_hw_des_cfb8(void); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_DES_H) */ diff --git a/providers/implementations/ciphers/cipher_des_hw.c b/providers/implementations/ciphers/cipher_des_hw.c index a36118260c..724cda6920 100644 --- a/providers/implementations/ciphers/cipher_des_hw.c +++ b/providers/implementations/ciphers/cipher_des_hw.c @@ -187,8 +187,8 @@ static int cipher_hw_des_cfb8_cipher(PROV_CIPHER_CTX *ctx, unsigned char *out, } PROV_CIPHER_HW_des_mode(ecb) -PROV_CIPHER_HW_des_mode(cbc) -PROV_CIPHER_HW_des_mode(ofb64) -PROV_CIPHER_HW_des_mode(cfb64) -PROV_CIPHER_HW_des_mode(cfb1) -PROV_CIPHER_HW_des_mode(cfb8) + PROV_CIPHER_HW_des_mode(cbc) + PROV_CIPHER_HW_des_mode(ofb64) + PROV_CIPHER_HW_des_mode(cfb64) + PROV_CIPHER_HW_des_mode(cfb1) + PROV_CIPHER_HW_des_mode(cfb8) diff --git a/providers/implementations/ciphers/cipher_idea.h b/providers/implementations/ciphers/cipher_idea.h index dbb5c332c1..44f9571ff3 100644 --- a/providers/implementations/ciphers/cipher_idea.h +++ b/providers/implementations/ciphers/cipher_idea.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_IDEA_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_IDEA_H - #include #include "prov/ciphercommon.h" @@ -25,5 +22,3 @@ const PROV_CIPHER_HW *ossl_prov_cipher_hw_idea_cbc(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_idea_ecb(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_idea_ofb64(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_idea_cfb64(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_IDEA_H) */ diff --git a/providers/implementations/ciphers/cipher_rc2.h b/providers/implementations/ciphers/cipher_rc2.h index 025f331507..bfb1d45495 100644 --- a/providers/implementations/ciphers/cipher_rc2.h +++ b/providers/implementations/ciphers/cipher_rc2.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_RC2_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_RC2_H - #include #include "prov/ciphercommon.h" @@ -29,5 +26,3 @@ const PROV_CIPHER_HW *ossl_prov_cipher_hw_rc2_cbc(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_rc2_ecb(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_rc2_ofb64(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_rc2_cfb64(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_RC2_H) */ diff --git a/providers/implementations/ciphers/cipher_rc4.h b/providers/implementations/ciphers/cipher_rc4.h index ed7ffe2339..8bb6f22652 100644 --- a/providers/implementations/ciphers/cipher_rc4.h +++ b/providers/implementations/ciphers/cipher_rc4.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_RC4_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_RC4_H - #include #include "prov/ciphercommon.h" @@ -22,5 +19,3 @@ typedef struct prov_rc4_ctx_st { } PROV_RC4_CTX; const PROV_CIPHER_HW *ossl_prov_cipher_hw_rc4(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_RC4_H) */ diff --git a/providers/implementations/ciphers/cipher_rc4_hmac_md5.c b/providers/implementations/ciphers/cipher_rc4_hmac_md5.c index f3fbf2e1c4..4b7dbb7458 100644 --- a/providers/implementations/ciphers/cipher_rc4_hmac_md5.c +++ b/providers/implementations/ciphers/cipher_rc4_hmac_md5.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -29,7 +29,7 @@ #define RC4_HMAC_MD5_IV_BITS 0 #define RC4_HMAC_MD5_MODE 0 -#define GET_HW(ctx) ((const PROV_CIPHER_HW_RC4_HMAC_MD5 *)ctx->base.hw) +#define GET_HW(ctx) ((PROV_CIPHER_HW_RC4_HMAC_MD5 *)ctx->base.hw) static OSSL_FUNC_cipher_encrypt_init_fn rc4_hmac_md5_einit; static OSSL_FUNC_cipher_decrypt_init_fn rc4_hmac_md5_dinit; diff --git a/providers/implementations/ciphers/cipher_rc4_hmac_md5.h b/providers/implementations/ciphers/cipher_rc4_hmac_md5.h index ad243cd0a3..87fa8e060d 100644 --- a/providers/implementations/ciphers/cipher_rc4_hmac_md5.h +++ b/providers/implementations/ciphers/cipher_rc4_hmac_md5.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_RC4_HMAC_MD5_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_RC4_HMAC_MD5_H - #include #include #include "prov/ciphercommon.h" @@ -37,5 +34,3 @@ const PROV_CIPHER_HW *ossl_prov_cipher_hw_rc4_hmac_md5(size_t keybits); void rc4_md5_enc(RC4_KEY *key, const void *in0, void *out, MD5_CTX *ctx, const void *inp, size_t blocks); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_RC4_HMAC_MD5_H) */ diff --git a/providers/implementations/ciphers/cipher_rc4_hmac_md5_hw.c b/providers/implementations/ciphers/cipher_rc4_hmac_md5_hw.c index e25782ed8b..c3fae599dd 100644 --- a/providers/implementations/ciphers/cipher_rc4_hmac_md5_hw.c +++ b/providers/implementations/ciphers/cipher_rc4_hmac_md5_hw.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -227,5 +227,5 @@ static const PROV_CIPHER_HW_RC4_HMAC_MD5 rc4_hmac_md5_hw = { const PROV_CIPHER_HW *ossl_prov_cipher_hw_rc4_hmac_md5(size_t keybits) { - return (const PROV_CIPHER_HW *)&rc4_hmac_md5_hw; + return (PROV_CIPHER_HW *)&rc4_hmac_md5_hw; } diff --git a/providers/implementations/ciphers/cipher_rc5.h b/providers/implementations/ciphers/cipher_rc5.h index 131c34f520..0662937f68 100644 --- a/providers/implementations/ciphers/cipher_rc5.h +++ b/providers/implementations/ciphers/cipher_rc5.h @@ -7,10 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_RC5_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_RC5_H - -#if !defined(OPENSSL_NO_RC5) #include #include "prov/ciphercommon.h" @@ -27,6 +23,3 @@ const PROV_CIPHER_HW *ossl_prov_cipher_hw_rc5_cbc(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_rc5_ecb(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_rc5_ofb64(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_rc5_cfb64(size_t keybits); - -#endif /* defined(OPENSSL_NO_RC5) */ -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_RC5_H) */ diff --git a/providers/implementations/ciphers/cipher_seed.h b/providers/implementations/ciphers/cipher_seed.h index 50460d1fa7..750ab8deac 100644 --- a/providers/implementations/ciphers/cipher_seed.h +++ b/providers/implementations/ciphers/cipher_seed.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_SEED_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_SEED_H - #include #include "prov/ciphercommon.h" @@ -25,5 +22,3 @@ const PROV_CIPHER_HW *ossl_prov_cipher_hw_seed_cbc(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_seed_ecb(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_seed_ofb128(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_seed_cfb128(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_SEED_H) */ diff --git a/providers/implementations/ciphers/cipher_sm4.h b/providers/implementations/ciphers/cipher_sm4.h index e11ad45e1f..b061022411 100644 --- a/providers/implementations/ciphers/cipher_sm4.h +++ b/providers/implementations/ciphers/cipher_sm4.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_SM4_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_SM4_H - #include "prov/ciphercommon.h" #include "crypto/sm4.h" #include "crypto/sm4_platform.h" @@ -27,5 +24,3 @@ const PROV_CIPHER_HW *ossl_prov_cipher_hw_sm4_ecb(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_sm4_ctr(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_sm4_ofb128(size_t keybits); const PROV_CIPHER_HW *ossl_prov_cipher_hw_sm4_cfb128(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_SM4_H) */ diff --git a/providers/implementations/ciphers/cipher_sm4_ccm.h b/providers/implementations/ciphers/cipher_sm4_ccm.h index 2409f862de..61d4466132 100644 --- a/providers/implementations/ciphers/cipher_sm4_ccm.h +++ b/providers/implementations/ciphers/cipher_sm4_ccm.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_SM4_CCM_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_SM4_CCM_H - #include "crypto/sm4.h" #include "prov/ciphercommon.h" #include "prov/ciphercommon_ccm.h" @@ -24,5 +21,3 @@ typedef struct prov_sm4_ccm_ctx_st { } PROV_SM4_CCM_CTX; const PROV_CCM_HW *ossl_prov_sm4_hw_ccm(size_t keylen); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_SM4_CCM_H) */ diff --git a/providers/implementations/ciphers/cipher_sm4_gcm.h b/providers/implementations/ciphers/cipher_sm4_gcm.h index cd38a75a65..6bc9a4d34b 100644 --- a/providers/implementations/ciphers/cipher_sm4_gcm.h +++ b/providers/implementations/ciphers/cipher_sm4_gcm.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_SM4_GCM_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_SM4_GCM_H - #include "crypto/sm4.h" #include "prov/ciphercommon.h" #include "prov/ciphercommon_gcm.h" @@ -23,5 +20,3 @@ typedef struct prov_sm4_gcm_ctx_st { } PROV_SM4_GCM_CTX; const PROV_GCM_HW *ossl_prov_sm4_hw_gcm(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_SM4_GCM_H) */ diff --git a/providers/implementations/ciphers/cipher_sm4_hw.c b/providers/implementations/ciphers/cipher_sm4_hw.c index 2c9fdd9f0b..af197d9a34 100644 --- a/providers/implementations/ciphers/cipher_sm4_hw.c +++ b/providers/implementations/ciphers/cipher_sm4_hw.c @@ -145,7 +145,7 @@ IMPLEMENT_CIPHER_HW_COPYCTX(cipher_hw_sm4_copyctx, PROV_SM4_CTX) #endif PROV_CIPHER_HW_sm4_mode(cbc) -PROV_CIPHER_HW_sm4_mode(ecb) -PROV_CIPHER_HW_sm4_mode(ofb128) -PROV_CIPHER_HW_sm4_mode(cfb128) -PROV_CIPHER_HW_sm4_mode(ctr) + PROV_CIPHER_HW_sm4_mode(ecb) + PROV_CIPHER_HW_sm4_mode(ofb128) + PROV_CIPHER_HW_sm4_mode(cfb128) + PROV_CIPHER_HW_sm4_mode(ctr) diff --git a/providers/implementations/ciphers/cipher_sm4_xts.h b/providers/implementations/ciphers/cipher_sm4_xts.h index 3693eaa4df..57dcdb6ccf 100644 --- a/providers/implementations/ciphers/cipher_sm4_xts.h +++ b/providers/implementations/ciphers/cipher_sm4_xts.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_SM4_XTS_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_SM4_XTS_H - #include #include "prov/ciphercommon.h" #include "crypto/sm4_platform.h" @@ -47,5 +44,3 @@ typedef struct prov_sm4_xts_ctx_st { } PROV_SM4_XTS_CTX; const PROV_CIPHER_HW *ossl_prov_cipher_hw_sm4_xts(size_t keybits); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_SM4_XTS_H) */ diff --git a/providers/implementations/ciphers/cipher_tdes.h b/providers/implementations/ciphers/cipher_tdes.h index d3c383506f..7aa4532688 100644 --- a/providers/implementations/ciphers/cipher_tdes.h +++ b/providers/implementations/ciphers/cipher_tdes.h @@ -7,13 +7,8 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_TDES_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_TDES_H - #include -#include #include -#include "prov/ciphercommon.h" #include "prov/securitycheck.h" #include "crypto/des_platform.h" @@ -113,5 +108,3 @@ int ossl_cipher_hw_tdes_ecb(PROV_CIPHER_CTX *ctx, unsigned char *out, const PROV_CIPHER_HW *ossl_prov_cipher_hw_tdes_ede3_cbc(void); const PROV_CIPHER_HW *ossl_prov_cipher_hw_tdes_ede3_ecb(void); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_TDES_H) */ diff --git a/providers/implementations/ciphers/cipher_tdes_common.c b/providers/implementations/ciphers/cipher_tdes_common.c index 20dc77f32c..328b58dc2e 100644 --- a/providers/implementations/ciphers/cipher_tdes_common.c +++ b/providers/implementations/ciphers/cipher_tdes_common.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -25,7 +25,8 @@ void *ossl_tdes_newctx(void *provctx, int mode, size_t kbits, size_t blkbits, { PROV_TDES_CTX *tctx; - CIPHER_PROV_CHECK(provctx, DES_EDE3_ECB); + if (!ossl_prov_is_running()) + return NULL; tctx = OPENSSL_zalloc(sizeof(*tctx)); if (tctx != NULL) { @@ -65,10 +66,7 @@ void ossl_tdes_freectx(void *vctx) static int tdes_encrypt_check_approved(PROV_TDES_CTX *ctx, int enc) { /* Triple-DES encryption is not approved in FIPS 140-3 */ - if (enc - && !OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE0, - ctx->base.libctx, "Triple-DES", "Encryption", - FIPS_CONFIG_TDES_ENCRYPT_DISABLED)) + if (enc && !OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE0, ctx->base.libctx, "Triple-DES", "Encryption", ossl_fips_config_tdes_encrypt_disallowed)) return 0; return 1; } diff --git a/providers/implementations/ciphers/cipher_tdes_default.h b/providers/implementations/ciphers/cipher_tdes_default.h index adc3af7b3b..dc8458b5da 100644 --- a/providers/implementations/ciphers/cipher_tdes_default.h +++ b/providers/implementations/ciphers/cipher_tdes_default.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_TDES_DEFAULT_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_TDES_DEFAULT_H - #include "prov/ciphercommon.h" #include "cipher_tdes.h" @@ -26,5 +23,3 @@ const PROV_CIPHER_HW *ossl_prov_cipher_hw_tdes_ede2_cfb(void); const PROV_CIPHER_HW *ossl_prov_cipher_hw_tdes_desx_cbc(void); const PROV_CIPHER_HW *ossl_prov_cipher_hw_tdes_wrap_cbc(void); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHER_TDES_DEFAULT_H) */ diff --git a/providers/implementations/ciphers/ciphercommon.c b/providers/implementations/ciphers/ciphercommon.c index a6320d2d81..9e6f386e02 100644 --- a/providers/implementations/ciphers/ciphercommon.c +++ b/providers/implementations/ciphers/ciphercommon.c @@ -276,9 +276,15 @@ int ossl_cipher_generic_block_update(void *vctx, unsigned char *out, return 0; } padval = (unsigned char)(padnum - 1); - /* we need to add 'padnum' padding bytes of value padval */ - for (loop = inl; loop < inl + padnum; loop++) - out[loop] = padval; + if (ctx->tlsversion == SSL3_VERSION) { + if (padnum > 1) + memset(out + inl, 0, padnum - 1); + *(out + inl + padnum - 1) = padval; + } else { + /* we need to add 'padnum' padding bytes of value padval */ + for (loop = inl; loop < inl + padnum; loop++) + out[loop] = padval; + } inl += padnum; } @@ -644,10 +650,6 @@ int ossl_cipher_common_set_ctx_params(PROV_CIPHER_CTX *ctx, const struct ossl_ci ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_GET_PARAMETER); return 0; } - if (ctx->blocksize > 0 && num >= (unsigned int)ctx->blocksize) { - ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_GET_PARAMETER); - return 0; - } ctx->num = num; } return 1; diff --git a/providers/implementations/ciphers/ciphercommon_block.c b/providers/implementations/ciphers/ciphercommon_block.c index 8ce491ddca..634bae4c1c 100644 --- a/providers/implementations/ciphers/ciphercommon_block.c +++ b/providers/implementations/ciphers/ciphercommon_block.c @@ -123,7 +123,7 @@ int ossl_cipher_unpadblock(unsigned char *buf, size_t *buflen, size_t blocksize) * time. * * libctx: Our library context - * tlsversion: The TLS version in use, e.g. TLS1_VERSION, etc + * tlsversion: The TLS version in use, e.g. SSL3_VERSION, TLS1_VERSION, etc * buf: The decrypted TLS record data * buflen: The length of the decrypted TLS record data. Updated with the new * length after the padding is removed @@ -147,6 +147,11 @@ int ossl_cipher_tlsunpadblock(OSSL_LIB_CTX *libctx, unsigned int tlsversion, int ret; switch (tlsversion) { + case SSL3_VERSION: + return ssl3_cbc_remove_padding_and_mac(buflen, *buflen, buf, mac, + alloced, blocksize, macsize, + libctx); + case TLS1_2_VERSION: case DTLS1_2_VERSION: case TLS1_1_VERSION: diff --git a/providers/implementations/ciphers/ciphercommon_gcm.c b/providers/implementations/ciphers/ciphercommon_gcm.c index c93b0767b0..d9be50f513 100644 --- a/providers/implementations/ciphers/ciphercommon_gcm.c +++ b/providers/implementations/ciphers/ciphercommon_gcm.c @@ -215,7 +215,7 @@ int ossl_gcm_get_ctx_params(void *vctx, OSSL_PARAM params[]) if (p.tag != NULL) { sz = p.tag->data_size; if (!ctx->enc || ctx->taglen == UNINITIALISED_SIZET) { - ERR_raise(ERR_LIB_PROV, PROV_R_TAG_NOT_SET); + ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_TAG); return 0; } if (p.tag->data != NULL && (sz > EVP_GCM_TLS_TAG_LEN || sz == 0)) { @@ -263,11 +263,7 @@ int ossl_gcm_set_ctx_params(void *vctx, const OSSL_PARAM params[]) ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_GET_PARAMETER); return 0; } - if (ctx->enc) { - ERR_raise(ERR_LIB_PROV, PROV_R_TAG_NOT_NEEDED); - return 0; - } - if (sz == 0) { + if (sz == 0 || ctx->enc) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_TAG); return 0; } diff --git a/providers/implementations/ciphers/ciphercommon_local.h b/providers/implementations/ciphers/ciphercommon_local.h index 05ada2dd17..f142722f28 100644 --- a/providers/implementations/ciphers/ciphercommon_local.h +++ b/providers/implementations/ciphers/ciphercommon_local.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHERCOMMON_LOCAL_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHERCOMMON_LOCAL_H - #include "prov/ciphercommon.h" void ossl_cipher_padblock(unsigned char *buf, size_t *buflen, size_t blocksize); @@ -17,5 +14,3 @@ int ossl_cipher_unpadblock(unsigned char *buf, size_t *buflen, size_t blocksize) int ossl_cipher_tlsunpadblock(OSSL_LIB_CTX *libctx, unsigned int tlsversion, unsigned char *buf, size_t *buflen, size_t blocksize, unsigned char **mac, int *alloced, size_t macsize, int aead); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_CIPHERS_CIPHERCOMMON_LOCAL_H) */ diff --git a/providers/implementations/digests/blake2_impl.h b/providers/implementations/digests/blake2_impl.h index 389f2473a6..dd10beae40 100644 --- a/providers/implementations/digests/blake2_impl.h +++ b/providers/implementations/digests/blake2_impl.h @@ -14,13 +14,7 @@ * can be found at https://blake2.net. */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_DIGESTS_BLAKE2_IMPL_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_DIGESTS_BLAKE2_IMPL_H - #include - -#include - #include "internal/endian.h" static ossl_inline uint32_t load32(const uint8_t *src) @@ -122,5 +116,3 @@ static ossl_inline uint64_t rotr64(const uint64_t w, const unsigned int c) { return (w >> c) | (w << (64 - c)); } - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_DIGESTS_BLAKE2_IMPL_H) */ diff --git a/providers/implementations/digests/build.info b/providers/implementations/digests/build.info index 8da0e80829..d30975028e 100644 --- a/providers/implementations/digests/build.info +++ b/providers/implementations/digests/build.info @@ -10,7 +10,6 @@ $BLAKE2_GOAL=../../libdefault.a $SM3_GOAL=../../libdefault.a $MD5_GOAL=../../libdefault.a $NULL_GOAL=../../libdefault.a -$ML_DSA_MU_GOAL=../../libdefault.a ../../libfips.a $MD2_GOAL=../../liblegacy.a $MD4_GOAL=../../liblegacy.a @@ -26,7 +25,7 @@ ENDIF SOURCE[$COMMON_GOAL]=digestcommon.c SOURCE[$SHA2_GOAL]=sha2_prov.c -SOURCE[$SHA3_GOAL]=sha3_prov.c cshake_prov.c +SOURCE[$SHA3_GOAL]=sha3_prov.c SOURCE[$NULL_GOAL]=null_prov.c @@ -61,7 +60,3 @@ ENDIF IF[{- !$disabled{rmd160} -}] SOURCE[$RIPEMD_GOAL]=ripemd_prov.c ENDIF - -IF[{- !$disabled{'ml-dsa'} -}] - SOURCE[$ML_DSA_MU_GOAL]=ml_dsa_mu_prov.c -ENDIF diff --git a/providers/implementations/digests/cshake_prov.c b/providers/implementations/digests/cshake_prov.c deleted file mode 100644 index 7dd9c58940..0000000000 --- a/providers/implementations/digests/cshake_prov.c +++ /dev/null @@ -1,504 +0,0 @@ -/* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* including crypto/sha.h requires this for SHA256_CTX */ -#include "internal/deprecated.h" -/* - * NOTE: By default CSHAKE sets secure xof lengths (OSSL_DIGEST_PARAM_XOFLEN) - * that are used by EVP_DigestFinal_ex(). This differs from SHAKE where the - * xof length MUST be set (since the initial implementation shipped with BAD - * defaults - and the only safe way to fix it was to make the user set the value) - */ -#include -#include -#include -#include -#include -#include "crypto/sha.h" -#include "prov/provider_ctx.h" -#include "prov/digestcommon.h" -#include "prov/implementations.h" -#include "internal/common.h" -#include "internal/sha3.h" -#include "providers/implementations/digests/cshake_prov.inc" - -/* - * Length encoding will be a 1 byte size + length in bits (3 bytes max) - * This gives a range of 0..0XFFFFFF bits = 2097151 bytes). - */ -#define CSHAKE_MAX_ENCODED_HEADER_LEN (1 + 3) - -/* - * Restrict the maximum length of the custom strings N & S. - * This must not exceed 64 bits = 8k bytes. - */ -#define CSHAKE_MAX_STRING 512 - -/* Maximum size of both the encoded strings (N and S) */ -#define CSHAKE_MAX_ENCODED_STRING (CSHAKE_MAX_STRING + CSHAKE_MAX_ENCODED_HEADER_LEN) -#define CSHAKE_FLAGS (PROV_DIGEST_FLAG_XOF | PROV_DIGEST_FLAG_ALGID_ABSENT) - -typedef struct cshake_ctx_st { - OSSL_LIB_CTX *libctx; - char *propq; - EVP_MD_CTX *mdctx; - EVP_MD *md; - const uint8_t *func; /* encoded N */ - uint8_t custom[CSHAKE_MAX_ENCODED_STRING]; /* encoded S */ - size_t funclen; - size_t customlen; - size_t bitlen; - size_t xoflen; - int inited; -} CSHAKE_CTX; - -static OSSL_FUNC_digest_freectx_fn cshake_freectx; -static OSSL_FUNC_digest_dupctx_fn cshake_dupctx; -static OSSL_FUNC_digest_init_fn cshake_init; -static OSSL_FUNC_digest_update_fn cshake_update; -static OSSL_FUNC_digest_final_fn cshake_final; -static OSSL_FUNC_digest_squeeze_fn cshake_squeeze; -static OSSL_FUNC_digest_set_ctx_params_fn cshake_set_ctx_params; -static OSSL_FUNC_digest_settable_ctx_params_fn cshake_settable_ctx_params; -static OSSL_FUNC_digest_get_ctx_params_fn cshake_get_ctx_params; -static OSSL_FUNC_digest_gettable_ctx_params_fn cshake_gettable_ctx_params; - -typedef struct name_encode_map_st { - const char *name; - const uint8_t *encoding; - size_t encodinglen; -} NAME_ENCODE_MAP; - -/* Fixed value of encode_string("") */ -static const unsigned char empty_encoded_string[] = { - 0x01, 0x00 -}; - -/* Fixed value of encode_string("KMAC") */ -static const unsigned char kmac_encoded_string[] = { - 0x01, 0x20, 0x4B, 0x4D, 0x41, 0x43 -}; - -/* Fixed value of encode_string("TupleHash") */ -static const unsigned char tuplehash_encoded_string[] = { - 0x01, 0x48, 0x54, 0x75, 0x70, 0x6C, 0x65, 0x48, 0x61, 0x73, 0x68 -}; - -/* Fixed value of encode_string("ParallelHash") */ -static const unsigned char parallelhash_encoded_string[] = { - 0x01, 0x60, 0x50, 0x61, 0x72, 0x61, 0x6C, 0x6C, 0x65, 0x6C, 0x48, 0x61, 0x73, 0x68 -}; - -static int cshake_set_func_encode_string(const char *in, - const uint8_t **out, size_t *outlen) -{ - /* - * A list of valid function names to encoded string mappings - * See NIST SP800-185 Section 3.4 - */ - static NAME_ENCODE_MAP functionNameMap[] = { - { "", empty_encoded_string, sizeof(empty_encoded_string) }, - { "KMAC", kmac_encoded_string, sizeof(kmac_encoded_string) }, - { "TupleHash", tuplehash_encoded_string, sizeof(tuplehash_encoded_string) }, - { "ParallelHash", parallelhash_encoded_string, sizeof(parallelhash_encoded_string) }, - { NULL, NULL, 0 } - }; - - *out = NULL; - *outlen = 0; - /* - * Don't encode an empty string here - this is done manually later only when - * one of the strings is not empty. If both are empty then we don't want it - * to encode at all. - */ - if (in == NULL || in[0] == 0) - return 1; - for (int i = 1; functionNameMap[i].name != NULL; ++i) { - if (functionNameMap[i].name[0] == in[0]) { - if (OPENSSL_strcasecmp(functionNameMap[i].name, in) == 0) { - *out = functionNameMap[i].encoding; - *outlen = functionNameMap[i].encodinglen; - return 1; - } - return 0; /* Name does not match a known name */ - } - } - return 0; /* Name not found */ -} - -static int cshake_set_encode_string(const char *in, - uint8_t *out, size_t outmax, size_t *outlen) -{ - size_t inlen; - - if (*outlen != 0) - OPENSSL_cleanse(out, outmax); - *outlen = 0; - if (in == NULL) - return 1; - - inlen = strlen(in); - /* - * Don't encode an empty string here - this is done manually later only when - * one of the strings is not empty. If both are empty then we don't want it - * to encode at all. - */ - if (inlen == 0) - return 1; - if (inlen >= CSHAKE_MAX_STRING) - return 0; - return ossl_sp800_185_encode_string(out, outmax, outlen, - (const unsigned char *)in, inlen); -} - -/* - * Set the xof length, note that if the digest has not been fetched yet then - * it is just set into a variable and deferred to later. - */ -static int cshake_set_xoflen(CSHAKE_CTX *ctx, size_t xoflen) -{ - OSSL_PARAM params[2]; - - params[0] = OSSL_PARAM_construct_size_t(OSSL_DIGEST_PARAM_XOFLEN, &xoflen); - params[1] = OSSL_PARAM_construct_end(); - - ctx->xoflen = xoflen; - if (ctx->md != NULL) - return EVP_MD_CTX_set_params(ctx->mdctx, params); - return 1; -} - -/* - * Fetch a digest for SHAKE or KECCAK, set its xof len and init it - * into an mdctx. - */ -static int cshake_set_shake_mode(CSHAKE_CTX *ctx, int shake) -{ - OSSL_PARAM params[2]; - const char *name; - - if (shake) - name = (ctx->bitlen == 128 ? "SHAKE128" : "SHAKE256"); - else - name = (ctx->bitlen == 128 ? "CSHAKE-KECCAK-128" : "CSHAKE-KECCAK-256"); - - if (ctx->md == NULL || !EVP_MD_is_a(ctx->md, name)) { - ctx->md = EVP_MD_fetch(ctx->libctx, name, ctx->propq); - if (ctx->md == NULL) - return 0; - } - params[0] = OSSL_PARAM_construct_size_t(OSSL_DIGEST_PARAM_XOFLEN, - &ctx->xoflen); - params[1] = OSSL_PARAM_construct_end(); - return EVP_DigestInit_ex2(ctx->mdctx, ctx->md, params); -} - -static void *cshake_newctx(void *provctx, size_t bitlen) -{ - CSHAKE_CTX *ctx; - - if (ossl_unlikely(!ossl_prov_is_running())) - return NULL; - ctx = OPENSSL_zalloc(sizeof(*ctx)); - if (ctx != NULL) { - ctx->mdctx = EVP_MD_CTX_create(); - if (ctx->mdctx == NULL) { - OPENSSL_free(ctx); - return NULL; - } - ctx->bitlen = bitlen; - ctx->libctx = PROV_LIBCTX_OF(provctx); - } - return ctx; -} - -static void cshake_freectx(void *vctx) -{ - CSHAKE_CTX *ctx = (CSHAKE_CTX *)vctx; - - OPENSSL_free(ctx->propq); - EVP_MD_free(ctx->md); - EVP_MD_CTX_destroy(ctx->mdctx); - OPENSSL_clear_free(ctx, sizeof(*ctx)); -} - -static void *cshake_dupctx(void *ctx) -{ - CSHAKE_CTX *src = (CSHAKE_CTX *)ctx; - CSHAKE_CTX *ret = ossl_prov_is_running() ? OPENSSL_malloc(sizeof(*ret)) - : NULL; - - if (ret != NULL) { - *ret = *src; - ret->md = NULL; - ret->mdctx = NULL; - ret->propq = NULL; - - if (src->md != NULL && !EVP_MD_up_ref(src->md)) - goto err; - ret->md = src->md; - - if (src->mdctx != NULL) { - ret->mdctx = EVP_MD_CTX_new(); - if (ret->mdctx == NULL - || !EVP_MD_CTX_copy_ex(ret->mdctx, src->mdctx)) - goto err; - } - if (src->propq != NULL) { - ret->propq = OPENSSL_strdup(src->propq); - if (ret->propq == NULL) - goto err; - } - } - return ret; -err: - cshake_freectx(ret); - return NULL; -} - -static int cshake_init(void *vctx, const OSSL_PARAM params[]) -{ - CSHAKE_CTX *ctx = (CSHAKE_CTX *)vctx; - - if (ossl_unlikely(!ossl_prov_is_running())) - return 0; - ctx->inited = 0; - ctx->xoflen = (ctx->bitlen == 128) ? 32 : 64; /* Set default values here */ - cshake_set_func_encode_string(NULL, &ctx->func, &ctx->funclen); - cshake_set_encode_string(NULL, ctx->custom, sizeof(ctx->custom), &ctx->customlen); - return cshake_set_ctx_params(vctx, params); -} - -static const OSSL_PARAM *cshake_settable_ctx_params(ossl_unused void *ctx, - ossl_unused void *provctx) -{ - return cshake_set_ctx_params_list; -} - -static int set_property_query(CSHAKE_CTX *ctx, const char *propq) -{ - OPENSSL_free(ctx->propq); - ctx->propq = NULL; - if (propq != NULL) { - ctx->propq = OPENSSL_strdup(propq); - if (ctx->propq == NULL) - return 0; - } - return 1; -} - -static int cshake_set_ctx_params(void *vctx, const OSSL_PARAM params[]) -{ - CSHAKE_CTX *ctx = (CSHAKE_CTX *)vctx; - struct cshake_set_ctx_params_st p; - - if (ctx == NULL || !cshake_set_ctx_params_decoder(params, &p)) - return 0; - - if (p.xoflen != NULL) { - size_t xoflen; - - if (!OSSL_PARAM_get_size_t(p.xoflen, &xoflen) - || !cshake_set_xoflen(ctx, xoflen)) { - ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_GET_PARAMETER); - return 0; - } - } - if (p.func != NULL) { - if (p.func->data_type != OSSL_PARAM_UTF8_STRING) - return 0; - if (!cshake_set_func_encode_string(p.func->data, &ctx->func, &ctx->funclen)) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_FUNCTION_NAME); - return 0; - } - } - if (p.custom != NULL) { - if (p.custom->data_type != OSSL_PARAM_UTF8_STRING) - return 0; - if (!cshake_set_encode_string(p.custom->data, ctx->custom, sizeof(ctx->custom), &ctx->customlen)) - return 0; - } - if (p.propq != NULL) { - if (p.propq->data_type != OSSL_PARAM_UTF8_STRING - || !set_property_query(ctx, p.propq->data)) - return 0; - } - return 1; -} - -/* - * bytepad(encode_string(N) || encode_string(S), w) - * See SP800-185 Section 2.3.3 Padding. - * - * Rather than build an array and do a single keccak operation, we use the - * internal keccak buffer to simplify the process. - * Note that if the strings are large enough to fill the buffer, it will handle - * this internally by absorbing full blocks. The zero padding is also simple - * as we just fill the buffer with zeros to make it a multiple of the blocksize. - */ -static int cshake_absorb_bytepad_strings(CSHAKE_CTX *ctx) -{ - const uint8_t zeros[SHA3_BLOCKSIZE(128)] = { 0 }; - uint8_t bytepad_header[2] = { 0x01, 0x00 }; - const uint8_t *n = ctx->func, *s = ctx->custom; - size_t nlen = ctx->funclen, slen = ctx->customlen; - size_t zlen; - size_t w = SHA3_BLOCKSIZE(ctx->bitlen); /* w = 168 or 136 */ - - bytepad_header[1] = (uint8_t)w; - - /* Empty strings are still encoded */ - if (nlen == 0) { - n = empty_encoded_string; - nlen = sizeof(empty_encoded_string); - } - if (slen == 0) { - s = empty_encoded_string; - slen = sizeof(empty_encoded_string); - } - /* Calculate the number of padding zeros to fill up the block */ - zlen = ((sizeof(bytepad_header) + nlen + slen) % w); - if (zlen != 0) - zlen = w - zlen; - - /* left encoded(w) || encodestring(n) || encodestring(s) || zero_padding */ - return EVP_DigestUpdate(ctx->mdctx, bytepad_header, sizeof(bytepad_header)) - && EVP_DigestUpdate(ctx->mdctx, n, nlen) - && EVP_DigestUpdate(ctx->mdctx, s, slen) - && EVP_DigestUpdate(ctx->mdctx, zeros, zlen); -} - -/* - * The setup of the EVP_MD gets deferred until after the set_ctx_params - * which means that we need to defer to the functions that may be called - * afterwards (i.e. The update(), final() or squeeze()). - * - */ -static int check_init(CSHAKE_CTX *ctx) -{ - /* - * We have to defer choosing the mode EVP_MD object (SHAKE or KECCAK) - * until the first call to either update(), final() or squeeze() - * since the strings can be set at any time before this point. - */ - if (ctx->inited == 0) { - if (ctx->funclen != 0 || ctx->customlen != 0) { - if (!cshake_set_shake_mode(ctx, 0) - || !cshake_absorb_bytepad_strings(ctx)) - return 0; - } else { - /* Use SHAKE if N and S are both empty strings */ - if (!cshake_set_shake_mode(ctx, 1)) - return 0; - } - ctx->inited = 1; - } - return 1; -} - -static int cshake_update(void *vctx, const unsigned char *in, size_t inlen) -{ - CSHAKE_CTX *ctx = (CSHAKE_CTX *)vctx; - - return check_init(ctx) - && EVP_DigestUpdate(ctx->mdctx, in, inlen); -} - -static int cshake_final(void *vctx, uint8_t *out, size_t *outl, size_t outsz) -{ - CSHAKE_CTX *ctx = (CSHAKE_CTX *)vctx; - unsigned int der = (unsigned int)(*outl); - int ret = 1; - - if (ossl_unlikely(!ossl_prov_is_running())) - return 0; - - if (outsz > 0) - ret = check_init(ctx) && EVP_DigestFinal_ex(ctx->mdctx, out, &der); - *outl = der; - return ret; -} - -static int cshake_squeeze(void *vctx, uint8_t *out, size_t *outl, size_t outsz) -{ - CSHAKE_CTX *ctx = (CSHAKE_CTX *)vctx; - int ret = 1; - - if (ossl_unlikely(!ossl_prov_is_running())) - return 0; - - if (outsz > 0) - ret = check_init(ctx) && EVP_DigestSqueeze(ctx->mdctx, out, outsz); - if (ret && outl != NULL) - *outl = outsz; - return ret; -} - -static const OSSL_PARAM *cshake_gettable_ctx_params(ossl_unused void *ctx, - ossl_unused void *provctx) -{ - return cshake_get_ctx_params_list; -} - -static int cshake_get_ctx_params(void *vctx, OSSL_PARAM params[]) -{ - CSHAKE_CTX *ctx = (CSHAKE_CTX *)vctx; - struct cshake_get_ctx_params_st p; - - if (ctx == NULL || !cshake_get_ctx_params_decoder(params, &p)) - return 0; - - /* Size is an alias of xoflen */ - if (p.xoflen != NULL || p.size != NULL) { - size_t xoflen = ctx->xoflen; - - if (ctx->md != NULL) - xoflen = EVP_MD_CTX_get_size_ex(ctx->mdctx); - - if (p.size != NULL && !OSSL_PARAM_set_size_t(p.size, xoflen)) { - ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_GET_PARAMETER); - return 0; - } - if (p.xoflen != NULL && !OSSL_PARAM_set_size_t(p.xoflen, xoflen)) { - ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_GET_PARAMETER); - return 0; - } - } - return 1; -} - -#define IMPLEMENT_CSHAKE_functions(bitlen) \ - static OSSL_FUNC_digest_newctx_fn cshake_##bitlen##_newctx; \ - static void *cshake_##bitlen##_newctx(void *provctx) \ - { \ - return cshake_newctx(provctx, bitlen); \ - } \ - PROV_FUNC_DIGEST_GET_PARAM(cshake_##bitlen, SHA3_BLOCKSIZE(bitlen), \ - CSHAKE_KECCAK_MDSIZE(bitlen), CSHAKE_FLAGS) \ - const OSSL_DISPATCH ossl_cshake_##bitlen##_functions[] = { \ - { OSSL_FUNC_DIGEST_NEWCTX, (void (*)(void))cshake_##bitlen##_newctx }, \ - { OSSL_FUNC_DIGEST_INIT, (void (*)(void))cshake_init }, \ - { OSSL_FUNC_DIGEST_UPDATE, (void (*)(void))cshake_update }, \ - { OSSL_FUNC_DIGEST_FINAL, (void (*)(void))cshake_final }, \ - { OSSL_FUNC_DIGEST_SQUEEZE, (void (*)(void))cshake_squeeze }, \ - { OSSL_FUNC_DIGEST_FREECTX, (void (*)(void))cshake_freectx }, \ - { OSSL_FUNC_DIGEST_DUPCTX, (void (*)(void))cshake_dupctx }, \ - { OSSL_FUNC_DIGEST_SET_CTX_PARAMS, (void (*)(void))cshake_set_ctx_params }, \ - { OSSL_FUNC_DIGEST_SETTABLE_CTX_PARAMS, \ - (void (*)(void))cshake_settable_ctx_params }, \ - { OSSL_FUNC_DIGEST_GET_CTX_PARAMS, (void (*)(void))cshake_get_ctx_params }, \ - { OSSL_FUNC_DIGEST_GETTABLE_CTX_PARAMS, \ - (void (*)(void))cshake_gettable_ctx_params }, \ - PROV_DISPATCH_FUNC_DIGEST_GET_PARAMS(cshake_##bitlen), \ - PROV_DISPATCH_FUNC_DIGEST_CONSTRUCT_END - -/* ossl_cshake_128_functions */ -IMPLEMENT_CSHAKE_functions(128) - /* ossl_cshake_256_functions */ - IMPLEMENT_CSHAKE_functions(256) diff --git a/providers/implementations/digests/cshake_prov.inc.in b/providers/implementations/digests/cshake_prov.inc.in deleted file mode 100644 index 42ed97f2c3..0000000000 --- a/providers/implementations/digests/cshake_prov.inc.in +++ /dev/null @@ -1,24 +0,0 @@ -/* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ -{- -use OpenSSL::paramnames qw(produce_param_decoder); --} - -{- produce_param_decoder('cshake_set_ctx_params', - (['OSSL_DIGEST_PARAM_XOFLEN', 'xoflen', 'size_t'], - ['OSSL_DIGEST_PARAM_SIZE', 'xoflen', 'size_t'], - ['OSSL_DIGEST_PARAM_FUNCTION_NAME', 'func', 'utf8_string'], - ['OSSL_DIGEST_PARAM_CUSTOMIZATION', 'custom', 'utf8_string'], - ['OSSL_DIGEST_PARAM_PROPERTIES', 'propq', 'utf8_string'], - )); -} - -{- produce_param_decoder('cshake_get_ctx_params', - (['OSSL_DIGEST_PARAM_XOFLEN', 'xoflen', 'size_t'], - ['OSSL_DIGEST_PARAM_SIZE', 'size', 'size_t'], - )); -} diff --git a/providers/implementations/digests/ml_dsa_mu_prov.c b/providers/implementations/digests/ml_dsa_mu_prov.c deleted file mode 100644 index e2857c056d..0000000000 --- a/providers/implementations/digests/ml_dsa_mu_prov.c +++ /dev/null @@ -1,345 +0,0 @@ -/* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* - * mu is the value: - * mu = SHAKE256(tr || M', 64) - * - * where tr is the hash of the public key - * And M' is one of the following: - * (1) Pure: M' = 00 || ctx_len || ctx || in (where in = message) - * (2) PreHash: M' = 01 || ctx_len || ctx || OID || in (where in = hashed(msg)) - */ - -#include "internal/deprecated.h" /* including crypto/sha.h requires this */ - -#include -#include -#include -#include -#include -#include "crypto/ml_dsa.h" -#include "prov/provider_ctx.h" -#include "prov/digestcommon.h" -#include "prov/der_pq_dsa.h" -#include "prov/implementations.h" -#include "internal/common.h" -#include "internal/sha3.h" -#include "providers/implementations/digests/ml_dsa_mu_prov.inc" - -#define SHAKE256_SIZE 64 -#define SHAKE_FLAGS (PROV_DIGEST_FLAG_ALGID_ABSENT) -#define ML_DSA_MAX_CONTEXT_STRING_LEN 255 - -typedef struct mu_ctx_st { - OSSL_LIB_CTX *libctx; - char *propq; - EVP_MD_CTX *mdctx; - EVP_MD *md; - uint8_t context[ML_DSA_MAX_CONTEXT_STRING_LEN]; - size_t context_len; - uint8_t tr[SHAKE256_SIZE]; /* Pre-cached public key Hash */ - size_t keylen; - const uint8_t *oid; - size_t oid_len; - size_t digest_len; - size_t remaining; -} MU_CTX; - -static OSSL_FUNC_digest_newctx_fn mu_newctx; -static OSSL_FUNC_digest_freectx_fn mu_freectx; -static OSSL_FUNC_digest_get_params_fn mu_get_params; -static OSSL_FUNC_digest_dupctx_fn mu_dupctx; -static OSSL_FUNC_digest_init_fn mu_init; -static OSSL_FUNC_digest_update_fn mu_update; -static OSSL_FUNC_digest_final_fn mu_final; -static OSSL_FUNC_digest_set_ctx_params_fn mu_set_ctx_params; -static OSSL_FUNC_digest_settable_ctx_params_fn mu_settable_ctx_params; -static OSSL_FUNC_digest_get_ctx_params_fn mu_get_ctx_params; -static OSSL_FUNC_digest_gettable_ctx_params_fn mu_gettable_ctx_params; - -static void *mu_newctx(void *provctx) -{ - MU_CTX *ctx; - - if (ossl_unlikely(!ossl_prov_is_running())) - return NULL; - ctx = OPENSSL_zalloc(sizeof(*ctx)); - if (ctx != NULL) - ctx->libctx = PROV_LIBCTX_OF(provctx); - return ctx; -} - -static void mu_freectx(void *vctx) -{ - MU_CTX *ctx = (MU_CTX *)vctx; - - OPENSSL_free(ctx->propq); - EVP_MD_free(ctx->md); - EVP_MD_CTX_free(ctx->mdctx); - OPENSSL_free(ctx); -} - -static void *mu_dupctx(void *ctx) -{ - MU_CTX *src = (MU_CTX *)ctx; - MU_CTX *dst = ossl_prov_is_running() ? OPENSSL_malloc(sizeof(*dst)) : NULL; - - if (dst == NULL) - return NULL; - *dst = *src; - dst->mdctx = NULL; - dst->propq = NULL; - dst->md = NULL; - if (src->md != NULL) { - if (!EVP_MD_up_ref(src->md)) - goto err; - dst->md = src->md; - } - if (src->mdctx != NULL) { - dst->mdctx = EVP_MD_CTX_new(); - if (dst->mdctx == NULL - || !EVP_MD_CTX_copy_ex(dst->mdctx, src->mdctx)) - goto err; - } - if (src->propq != NULL) { - dst->propq = OPENSSL_strdup(src->propq); - if (dst->propq == NULL) - goto err; - } - return dst; -err: - mu_freectx(dst); - return NULL; -} - -static int mu_init(void *vctx, const OSSL_PARAM params[]) -{ - MU_CTX *ctx = (MU_CTX *)vctx; - - if (ossl_unlikely(!ossl_prov_is_running())) - return 0; - - if (ctx->mdctx != NULL && !EVP_MD_CTX_reset(ctx->mdctx)) - return 0; - ctx->remaining = ctx->digest_len; - return mu_set_ctx_params(vctx, params); -} - -static int mu_get_params(OSSL_PARAM params[]) -{ - return ossl_digest_default_get_params(params, SHA3_BLOCKSIZE(256), - SHAKE256_SIZE, SHAKE_FLAGS); -} - -static const OSSL_PARAM *mu_settable_ctx_params(ossl_unused void *ctx, - ossl_unused void *provctx) -{ - return ml_dsa_mu_set_ctx_params_list; -} - -static int set_property_query(MU_CTX *ctx, const char *propq) -{ - OPENSSL_free(ctx->propq); - ctx->propq = NULL; - if (propq != NULL) { - ctx->propq = OPENSSL_strdup(propq); - if (ctx->propq == NULL) - return 0; - } - return 1; -} - -static EVP_MD *shake_digest(MU_CTX *ctx) -{ - if (ctx->md == NULL) - ctx->md = EVP_MD_fetch(ctx->libctx, "SHAKE256", ctx->propq); - return ctx->md; -} - -static int digest_public_key(MU_CTX *ctx, const uint8_t *pub, size_t publen) -{ - int ret; - EVP_MD *md; - EVP_MD_CTX *mdctx; - - if (publen != ML_DSA_44_PUB_LEN - && publen != ML_DSA_65_PUB_LEN - && publen != ML_DSA_87_PUB_LEN) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); - return 0; - } - - md = shake_digest(ctx); - if (md == NULL) - return 0; - mdctx = EVP_MD_CTX_new(); - if (mdctx == NULL) - return 0; - ret = EVP_DigestInit_ex(mdctx, md, NULL) - && EVP_DigestUpdate(mdctx, pub, publen) - && EVP_DigestFinalXOF(mdctx, ctx->tr, sizeof(ctx->tr)); - EVP_MD_CTX_free(mdctx); - - return ret; -} - -static int mu_set_ctx_params(void *vctx, const OSSL_PARAM params[]) -{ - MU_CTX *ctx = (MU_CTX *)vctx; - struct ml_dsa_mu_set_ctx_params_st p; - - if (ctx == NULL || !ml_dsa_mu_set_ctx_params_decoder(params, &p)) - return 0; - - if (p.ctx != NULL) { - void *vp = ctx->context; - - if (!OSSL_PARAM_get_octet_string(p.ctx, &vp, sizeof(ctx->context), - &(ctx->context_len))) { - ctx->context_len = 0; - return 0; - } - } - if (p.propq != NULL) { - if (p.propq->data_type != OSSL_PARAM_UTF8_STRING - || !set_property_query(ctx, p.propq->data)) - return 0; - } - if (p.pubkey != NULL) { - if (p.pubkey->data_type != OSSL_PARAM_OCTET_STRING) - return 0; - if (!digest_public_key(ctx, p.pubkey->data, p.pubkey->data_size)) - return 0; - ctx->keylen = p.pubkey->data_size; - } - if (p.digestname != NULL) { - int ret; - - if (p.digestname->data_type != OSSL_PARAM_UTF8_STRING) - return 0; - ret = ossl_der_oid_pq_dsa_prehash_digest(p.digestname->data, - &ctx->oid, &ctx->oid_len, &ctx->digest_len); - if (ret) - ctx->remaining = ctx->digest_len; - else - ERR_raise_data(ERR_LIB_PROV, PROV_R_INVALID_DIGEST, - "%s is not supported", p.digestname->data); - return ret; - } - return 1; -} - -static const OSSL_PARAM *mu_gettable_ctx_params(ossl_unused void *ctx, - ossl_unused void *provctx) -{ - return ml_dsa_mu_get_ctx_params_list; -} - -static int mu_get_ctx_params(void *vctx, OSSL_PARAM params[]) -{ - MU_CTX *ctx = (MU_CTX *)vctx; - struct ml_dsa_mu_get_ctx_params_st p; - - if (ctx == NULL || !ml_dsa_mu_get_ctx_params_decoder(params, &p)) - return 0; - - /* Size is an alias of xoflen */ - if (p.xoflen != NULL || p.size != NULL) { - size_t xoflen = SHAKE256_SIZE; - - if (p.size != NULL && !OSSL_PARAM_set_size_t(p.size, xoflen)) { - ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_GET_PARAMETER); - return 0; - } - if (p.xoflen != NULL && !OSSL_PARAM_set_size_t(p.xoflen, xoflen)) { - ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_GET_PARAMETER); - return 0; - } - } - return 1; -} - -static int check_init(MU_CTX *ctx) -{ - if (ctx->mdctx == NULL) { - EVP_MD *md = shake_digest(ctx); - - if (md == NULL) - return 0; - if (ctx->keylen == 0) { - ERR_raise(ERR_LIB_PROV, PROV_R_MISSING_KEY); - return 0; - } - ctx->mdctx = ossl_ml_dsa_mu_init_int(md, ctx->tr, sizeof(ctx->tr), 1, - ctx->oid_len != 0, ctx->context, ctx->context_len); - if (ctx->mdctx == NULL) - return 0; - if (!ossl_ml_dsa_mu_update(ctx->mdctx, ctx->oid, ctx->oid_len)) - return 0; - } - return 1; -} - -static int mu_update(void *vctx, const unsigned char *in, size_t inlen) -{ - MU_CTX *ctx = (MU_CTX *)vctx; - int ret; - - if (ctx->oid_len > 0) { - /* For the HASH-ML-DSA case we expect the input to be the size of the digest */ - if (inlen > ctx->remaining) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_DATA); - return 0; - } - ctx->remaining -= inlen; - } - ret = check_init(ctx) - && ossl_ml_dsa_mu_update(ctx->mdctx, in, inlen); - return ret; -} - -static int mu_final(void *vctx, uint8_t *out, size_t *outl, size_t outsz) -{ - MU_CTX *ctx = (MU_CTX *)vctx; - size_t len = SHAKE256_SIZE; - - if (ossl_unlikely(!ossl_prov_is_running())) - return 0; - if (out == NULL) { - if (outl == NULL) - return 0; - } else if (outsz > 0) { - if (outsz < len) - return 0; - - if (ctx->remaining != 0) - return 0; - if (!ossl_ml_dsa_mu_finalize(ctx->mdctx, out, len)) - return 0; - } - *outl = len; - return 1; -} - -const OSSL_DISPATCH ossl_ml_dsa_mu_functions[] = { - { OSSL_FUNC_DIGEST_NEWCTX, (void (*)(void))mu_newctx }, - { OSSL_FUNC_DIGEST_INIT, (void (*)(void))mu_init }, - { OSSL_FUNC_DIGEST_UPDATE, (void (*)(void))mu_update }, - { OSSL_FUNC_DIGEST_FINAL, (void (*)(void))mu_final }, - { OSSL_FUNC_DIGEST_FREECTX, (void (*)(void))mu_freectx }, - { OSSL_FUNC_DIGEST_DUPCTX, (void (*)(void))mu_dupctx }, - { OSSL_FUNC_DIGEST_SET_CTX_PARAMS, (void (*)(void))mu_set_ctx_params }, - { OSSL_FUNC_DIGEST_SETTABLE_CTX_PARAMS, - (void (*)(void))mu_settable_ctx_params }, - { OSSL_FUNC_DIGEST_GET_CTX_PARAMS, (void (*)(void))mu_get_ctx_params }, - { OSSL_FUNC_DIGEST_GETTABLE_CTX_PARAMS, - (void (*)(void))mu_gettable_ctx_params }, - PROV_DISPATCH_FUNC_DIGEST_GET_PARAMS(mu), - PROV_DISPATCH_FUNC_DIGEST_CONSTRUCT_END diff --git a/providers/implementations/digests/ml_dsa_mu_prov.inc.in b/providers/implementations/digests/ml_dsa_mu_prov.inc.in deleted file mode 100644 index f2a978fc3e..0000000000 --- a/providers/implementations/digests/ml_dsa_mu_prov.inc.in +++ /dev/null @@ -1,24 +0,0 @@ -/* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the \"License\"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -{- -use OpenSSL::paramnames qw(produce_param_decoder); --} - -{- produce_param_decoder('ml_dsa_mu_get_ctx_params', - (['OSSL_DIGEST_PARAM_SIZE', 'size', 'uint'], - ['OSSL_DIGEST_PARAM_XOFLEN', 'xoflen', 'size_t'], - )); -} - -{- produce_param_decoder('ml_dsa_mu_set_ctx_params', - (['OSSL_DIGEST_PARAM_MU_CONTEXT_STRING', 'ctx', 'octet_string'], - ['OSSL_DIGEST_PARAM_MU_PROPERTIES', 'propq', 'utf8_string'], - ['OSSL_DIGEST_PARAM_MU_PUB_KEY', 'pubkey', 'octet_string'], - ['OSSL_DIGEST_PARAM_MU_DIGEST', 'digestname', 'utf8_string'] - )); -} diff --git a/providers/implementations/digests/sha2_prov.c b/providers/implementations/digests/sha2_prov.c index fe232e9f10..2ea2ee6ac9 100644 --- a/providers/implementations/digests/sha2_prov.c +++ b/providers/implementations/digests/sha2_prov.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -13,322 +13,84 @@ */ #include "internal/deprecated.h" -#include #include #include #include -#include #include #include -#include #include #include "prov/digestcommon.h" #include "prov/implementations.h" #include "crypto/sha.h" -#include "internal/common.h" -#include "providers/implementations/digests/sha2_prov.inc" #define SHA2_FLAGS PROV_DIGEST_FLAG_ALGID_ABSENT -extern int SHA1_Update_thunk(void *ctx, const unsigned char *data, size_t sz); -extern int SHA256_Update_thunk(void *ctx, const unsigned char *data, size_t sz); -extern int SHA512_Update_thunk(void *ctx, const unsigned char *data, size_t sz); +static OSSL_FUNC_digest_set_ctx_params_fn sha1_set_ctx_params; +static OSSL_FUNC_digest_settable_ctx_params_fn sha1_settable_ctx_params; + +static const OSSL_PARAM known_sha1_settable_ctx_params[] = { + { OSSL_DIGEST_PARAM_SSL3_MS, OSSL_PARAM_OCTET_STRING, NULL, 0, 0 }, + OSSL_PARAM_END +}; +static const OSSL_PARAM *sha1_settable_ctx_params(ossl_unused void *ctx, + ossl_unused void *provctx) +{ + return known_sha1_settable_ctx_params; +} /* Special set_params method for SSL3 */ static int sha1_set_ctx_params(void *vctx, const OSSL_PARAM params[]) { - struct sha1_set_ctx_params_st p; + const OSSL_PARAM *p; SHA_CTX *ctx = (SHA_CTX *)vctx; - if (ossl_unlikely(ctx == NULL || !sha1_set_ctx_params_decoder(params, &p))) + if (ctx == NULL) return 0; + if (ossl_param_is_empty(params)) + return 1; - if (p.ssl3_ms != NULL) + p = OSSL_PARAM_locate_const(params, OSSL_DIGEST_PARAM_SSL3_MS); + if (p != NULL && p->data_type == OSSL_PARAM_OCTET_STRING) return ossl_sha1_ctrl(ctx, EVP_CTRL_SSL3_MASTER_SECRET, - (int)p.ssl3_ms->data_size, p.ssl3_ms->data); - - return 1; -} - -static const OSSL_PARAM *sha1_settable_ctx_params(ossl_unused void *ctx, - ossl_unused void *provctx) -{ - return sha1_set_ctx_params_list; -} - -static const unsigned char sha256magic[] = "SHA256v1"; -#define SHA256MAGIC_LEN (sizeof(sha256magic) - 1) -#define SHA256_SERIALIZATION_LEN \ - ( \ - SHA256MAGIC_LEN /* magic */ \ - + sizeof(uint32_t) /* c->md_len */ \ - + sizeof(uint32_t) /* c->num */ \ - + sizeof(uint32_t) * 8 /* c->h */ \ - + sizeof(uint32_t) * 2 /* c->Nl + c->Nh */ \ - + sizeof(uint32_t) * SHA_LBLOCK /* c->data */ \ - ) - -static int SHA256_Serialize(SHA256_CTX *c, unsigned char *out, - size_t *outlen) -{ - unsigned char *p; - unsigned long i; - - if (out == NULL) { - if (outlen == NULL) - return 0; - - *outlen = SHA256_SERIALIZATION_LEN; - return 1; - } - - if (outlen != NULL && *outlen < SHA256_SERIALIZATION_LEN) - return 0; - - p = out; - - /* Magic code */ - memcpy(p, sha256magic, SHA256MAGIC_LEN); - p += SHA256MAGIC_LEN; - - /* md_len */ - p = OPENSSL_store_u32_le(p, c->md_len); - - /* num */ - p = OPENSSL_store_u32_le(p, c->num); - - /* h */ - for (i = 0; i < sizeof(c->h) / sizeof(SHA_LONG); i++) - p = OPENSSL_store_u32_le(p, c->h[i]); - - /* Nl, Nh */ - p = OPENSSL_store_u32_le(p, c->Nl); - p = OPENSSL_store_u32_le(p, c->Nh); - - /* data */ - for (i = 0; i < SHA_LBLOCK; i++) - p = OPENSSL_store_u32_le(p, c->data[i]); - - if (outlen != NULL) - *outlen = SHA256_SERIALIZATION_LEN; - - return 1; -} - -/* - * This function only performs basic input sanity checks and is not - * built to handle malicious input data. Only trusted input should be - * fed to this function - */ -static int SHA256_Deserialize(SHA256_CTX *c, const unsigned char *in, - size_t inlen) -{ - const unsigned char *p; - uint32_t val; - unsigned long i; - - if (c == NULL || in == NULL || inlen != SHA256_SERIALIZATION_LEN) - return 0; - - /* Magic code check */ - if (memcmp(in, sha256magic, SHA256MAGIC_LEN) != 0) - return 0; - - p = in + SHA256MAGIC_LEN; - - /* md_len check */ - p = OPENSSL_load_u32_le(&val, p); - if ((unsigned int)val != c->md_len) { - return 0; - } - - /* num check */ - p = OPENSSL_load_u32_le(&val, p); - if (val >= sizeof(c->data)) - return 0; - c->num = (unsigned int)val; - - /* h */ - for (i = 0; i < (sizeof(c->h) / sizeof(SHA_LONG)); i++) { - p = OPENSSL_load_u32_le(&val, p); - c->h[i] = (SHA_LONG)val; - } - - /* Nl, Nh */ - p = OPENSSL_load_u32_le(&val, p); - c->Nl = (SHA_LONG)val; - p = OPENSSL_load_u32_le(&val, p); - c->Nh = (SHA_LONG)val; - - /* data */ - for (i = 0; i < SHA_LBLOCK; i++) { - p = OPENSSL_load_u32_le(&val, p); - c->data[i] = (SHA_LONG)val; - } - - return 1; -} - -static const unsigned char sha512magic[] = "SHA512v1"; -#define SHA512MAGIC_LEN (sizeof(sha512magic) - 1) -#define SHA512_SERIALIZATION_LEN \ - ( \ - SHA512MAGIC_LEN /* magic */ \ - + sizeof(uint32_t) /* c->md_len */ \ - + sizeof(uint32_t) /* c->num */ \ - + sizeof(uint64_t) * 8 /* c->h */ \ - + sizeof(uint64_t) * 2 /* c->Nl + c->Nh */ \ - + SHA512_CBLOCK /* c->u.d/c->u.p */ \ - ) - -static int SHA512_Serialize(SHA512_CTX *c, unsigned char *out, - size_t *outlen) -{ - unsigned char *p; - unsigned long i; - - if (out == NULL) { - if (outlen == NULL) - return 0; - - *outlen = SHA512_SERIALIZATION_LEN; - return 1; - } - - if (outlen != NULL && *outlen < SHA512_SERIALIZATION_LEN) - return 0; - - p = out; - - /* Magic code */ - memcpy(p, sha512magic, SHA512MAGIC_LEN); - p += SHA512MAGIC_LEN; - - /* md_len */ - p = OPENSSL_store_u32_le(p, c->md_len); - - /* num */ - p = OPENSSL_store_u32_le(p, c->num); - - /* h */ - for (i = 0; i < sizeof(c->h) / sizeof(SHA_LONG64); i++) - p = OPENSSL_store_u64_le(p, c->h[i]); - - /* Nl, Nh */ - p = OPENSSL_store_u64_le(p, c->Nl); - p = OPENSSL_store_u64_le(p, c->Nh); - - /* data */ - memcpy(p, c->u.p, SHA512_CBLOCK); - p += SHA512_CBLOCK; - - if (outlen != NULL) - *outlen = SHA512_SERIALIZATION_LEN; - - return 1; -} - -/* - * This function only performs basic input sanity checks and is not - * built to handle malicious input data. Only trusted input should be - * fed to this function - */ -static int SHA512_Deserialize(SHA512_CTX *c, const unsigned char *in, - size_t inlen) -{ - const unsigned char *p; - uint32_t val32; - uint64_t val; - unsigned long i; - - if (c == NULL || in == NULL || inlen != SHA512_SERIALIZATION_LEN) - return 0; - - /* Magic code */ - if (memcmp(in, sha512magic, SHA512MAGIC_LEN) != 0) - return 0; - - p = in + SHA512MAGIC_LEN; - - /* md_len check */ - p = OPENSSL_load_u32_le(&val32, p); - if ((unsigned int)val32 != c->md_len) - return 0; - - /* num check */ - p = OPENSSL_load_u32_le(&val32, p); - if (val32 >= sizeof(c->u.d)) - return 0; - c->num = (unsigned int)val32; - - /* h */ - for (i = 0; i < (sizeof(c->h) / sizeof(SHA_LONG64)); i++) { - p = OPENSSL_load_u64_le(&val, p); - c->h[i] = (SHA_LONG64)val; - } - - /* Nl, Nh */ - p = OPENSSL_load_u64_le(&val, p); - c->Nl = (SHA_LONG64)val; - p = OPENSSL_load_u64_le(&val, p); - c->Nh = (SHA_LONG64)val; - - /* data */ - memcpy(c->u.p, p, SHA512_CBLOCK); - p += SHA512_CBLOCK; - + (int)p->data_size, p->data); return 1; } /* ossl_sha1_functions */ IMPLEMENT_digest_functions_with_settable_ctx( sha1, SHA_CTX, SHA_CBLOCK, SHA_DIGEST_LENGTH, SHA2_FLAGS, - SHA1_Init, SHA1_Update_thunk, SHA1_Final, + SHA1_Init, SHA1_Update, SHA1_Final, sha1_settable_ctx_params, sha1_set_ctx_params) /* ossl_sha224_functions */ -IMPLEMENT_digest_functions_with_serialize(sha224, SHA256_CTX, - SHA256_CBLOCK, SHA224_DIGEST_LENGTH, - SHA2_FLAGS, SHA224_Init, - SHA256_Update_thunk, SHA224_Final, - SHA256_Serialize, SHA256_Deserialize) +IMPLEMENT_digest_functions(sha224, SHA256_CTX, + SHA256_CBLOCK, SHA224_DIGEST_LENGTH, SHA2_FLAGS, + SHA224_Init, SHA224_Update, SHA224_Final) /* ossl_sha256_functions */ -IMPLEMENT_digest_functions_with_serialize(sha256, SHA256_CTX, - SHA256_CBLOCK, SHA256_DIGEST_LENGTH, - SHA2_FLAGS, SHA256_Init, - SHA256_Update_thunk, SHA256_Final, - SHA256_Serialize, SHA256_Deserialize) +IMPLEMENT_digest_functions(sha256, SHA256_CTX, + SHA256_CBLOCK, SHA256_DIGEST_LENGTH, SHA2_FLAGS, + SHA256_Init, SHA256_Update, SHA256_Final) /* ossl_sha256_192_internal_functions */ -IMPLEMENT_digest_functions_with_serialize(sha256_192_internal, SHA256_CTX, - SHA256_CBLOCK, SHA256_192_DIGEST_LENGTH, - SHA2_FLAGS, ossl_sha256_192_init, - SHA256_Update_thunk, SHA256_Final, - SHA256_Serialize, SHA256_Deserialize) +IMPLEMENT_digest_functions(sha256_192_internal, SHA256_CTX, + SHA256_CBLOCK, SHA256_192_DIGEST_LENGTH, SHA2_FLAGS, + ossl_sha256_192_init, SHA256_Update, SHA256_Final) /* ossl_sha384_functions */ -IMPLEMENT_digest_functions_with_serialize(sha384, SHA512_CTX, - SHA512_CBLOCK, SHA384_DIGEST_LENGTH, - SHA2_FLAGS, SHA384_Init, - SHA512_Update_thunk, SHA384_Final, - SHA512_Serialize, SHA512_Deserialize) +IMPLEMENT_digest_functions(sha384, SHA512_CTX, + SHA512_CBLOCK, SHA384_DIGEST_LENGTH, SHA2_FLAGS, + SHA384_Init, SHA384_Update, SHA384_Final) /* ossl_sha512_functions */ -IMPLEMENT_digest_functions_with_serialize(sha512, SHA512_CTX, - SHA512_CBLOCK, SHA512_DIGEST_LENGTH, - SHA2_FLAGS, SHA512_Init, - SHA512_Update_thunk, SHA512_Final, - SHA512_Serialize, SHA512_Deserialize) +IMPLEMENT_digest_functions(sha512, SHA512_CTX, + SHA512_CBLOCK, SHA512_DIGEST_LENGTH, SHA2_FLAGS, + SHA512_Init, SHA512_Update, SHA512_Final) /* ossl_sha512_224_functions */ -IMPLEMENT_digest_functions_with_serialize(sha512_224, SHA512_CTX, - SHA512_CBLOCK, SHA224_DIGEST_LENGTH, - SHA2_FLAGS, sha512_224_init, - SHA512_Update_thunk, SHA512_Final, - SHA512_Serialize, SHA512_Deserialize) +IMPLEMENT_digest_functions(sha512_224, SHA512_CTX, + SHA512_CBLOCK, SHA224_DIGEST_LENGTH, SHA2_FLAGS, + sha512_224_init, SHA512_Update, SHA512_Final) /* ossl_sha512_256_functions */ -IMPLEMENT_digest_functions_with_serialize(sha512_256, SHA512_CTX, - SHA512_CBLOCK, SHA256_DIGEST_LENGTH, - SHA2_FLAGS, sha512_256_init, - SHA512_Update_thunk, SHA512_Final, - SHA512_Serialize, SHA512_Deserialize) +IMPLEMENT_digest_functions(sha512_256, SHA512_CTX, + SHA512_CBLOCK, SHA256_DIGEST_LENGTH, SHA2_FLAGS, + sha512_256_init, SHA512_Update, SHA512_Final) diff --git a/providers/implementations/digests/sha2_prov.inc.in b/providers/implementations/digests/sha2_prov.inc.in deleted file mode 100644 index 33b2931a25..0000000000 --- a/providers/implementations/digests/sha2_prov.inc.in +++ /dev/null @@ -1,18 +0,0 @@ -/* - * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the \"License\"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -{- -use OpenSSL::paramnames qw(produce_param_decoder); --} - -{- -produce_param_decoder('sha1_set_ctx_params', - ([ 'OSSL_DIGEST_PARAM_SSL3_MS', 'ssl3_ms', 'octet_string' ], - )); --} diff --git a/providers/implementations/digests/sha3_prov.c b/providers/implementations/digests/sha3_prov.c index cae88b1d63..2b342b1ca8 100644 --- a/providers/implementations/digests/sha3_prov.c +++ b/providers/implementations/digests/sha3_prov.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -8,7 +8,6 @@ */ #include -#include #include #include #include @@ -25,45 +24,7 @@ #define SHA3_FLAGS PROV_DIGEST_FLAG_ALGID_ABSENT #define SHAKE_FLAGS (PROV_DIGEST_FLAG_XOF | PROV_DIGEST_FLAG_ALGID_ABSENT) -#define CSHAKE_KECCAK_FLAGS PROV_DIGEST_FLAG_XOF - -/* - * FIPS 202 Section 5.1 Specifies a padding mode that is added to the last - * block that consists of a 1 bit followed by padding zero bits and a trailing - * 1 bit (where the bits are in LSB order) - * - * For a given input message special algorithm context bits are appended: - * i.e. - * KECCAK[c] = (No tag is used) - * SHA3 = 01 - * SHAKE = 1111 - * CSHAKE_KECCAK = 00 (See NIST SP800-185 3.3 : i.e. it has 2 trailing zero bits) - * Note that KMAC and TupleHash use CSHAKE_KECCAK. - * The OpenSSL implementation only allows input messages that are in bytes, - * so the above concatenated bits will start on a byte boundary. - * Following these bits will be a 1 bit then the padding zeros which gives - * - * KECCAK[c] = 1000 - * SHA3 = 0110 - * SHAKE = 11111000 - * CSHAKE_KECCAK = 0010 (See NIST SP800-185 3.3 : i.e. KMAC uses cSHAKE with a fixed string) - * - * Which gives the following padding values as bytes. - */ -#define KECCAK_PADDING 0x01 -#define SHA3_PADDING 0x06 -#define SHAKE_PADDING 0x1f -#define CSHAKE_KECCAK_PADDING 0x04 - -#if defined(OPENSSL_CPUID_OBJ) && defined(__s390__) && defined(KECCAK1600_ASM) -/* - * IBM S390X support - */ -#include "arch/s390x_arch.h" -#define S390_SHA3 1 -#define S390_SHA3_CAPABLE(name) \ - ((OPENSSL_s390xcap_P.kimd[0] & S390X_CAPBIT(S390X_##name)) && (OPENSSL_s390xcap_P.klmd[0] & S390X_CAPBIT(S390X_##name))) -#endif +#define KMAC_FLAGS PROV_DIGEST_FLAG_XOF /* * Forward declaration of any unique methods implemented here. This is not strictly @@ -78,23 +39,24 @@ static OSSL_FUNC_digest_freectx_fn keccak_freectx; static OSSL_FUNC_digest_copyctx_fn keccak_copyctx; static OSSL_FUNC_digest_dupctx_fn keccak_dupctx; static OSSL_FUNC_digest_squeeze_fn shake_squeeze; - static OSSL_FUNC_digest_get_ctx_params_fn shake_get_ctx_params; static OSSL_FUNC_digest_gettable_ctx_params_fn shake_gettable_ctx_params; static OSSL_FUNC_digest_set_ctx_params_fn shake_set_ctx_params; static OSSL_FUNC_digest_settable_ctx_params_fn shake_settable_ctx_params; +static sha3_absorb_fn generic_sha3_absorb; +static sha3_final_fn generic_sha3_final; +static sha3_squeeze_fn generic_sha3_squeeze; -static PROV_SHA3_METHOD sha3_generic_md = { - ossl_sha3_absorb_default, - ossl_sha3_final_default, - NULL -}; +#if defined(OPENSSL_CPUID_OBJ) && defined(__s390__) && defined(KECCAK1600_ASM) +/* + * IBM S390X support + */ +#include "s390x_arch.h" +#define S390_SHA3 1 +#define S390_SHA3_CAPABLE(name) \ + ((OPENSSL_s390xcap_P.kimd[0] & S390X_CAPBIT(S390X_##name)) && (OPENSSL_s390xcap_P.klmd[0] & S390X_CAPBIT(S390X_##name))) -static PROV_SHA3_METHOD shake_generic_md = { - ossl_sha3_absorb_default, - ossl_sha3_final_default, - ossl_shake_squeeze_default -}; +#endif static int keccak_init(void *vctx, ossl_unused const OSSL_PARAM params[]) { @@ -113,7 +75,39 @@ static int keccak_init_params(void *vctx, const OSSL_PARAM params[]) static int keccak_update(void *vctx, const unsigned char *inp, size_t len) { - return ossl_sha3_absorb((KECCAK1600_CTX *)vctx, inp, len); + KECCAK1600_CTX *ctx = vctx; + const size_t bsz = ctx->block_size; + size_t num, rem; + + if (ossl_unlikely(len == 0)) + return 1; + + /* Is there anything in the buffer already ? */ + if (ossl_likely((num = ctx->bufsz) != 0)) { + /* Calculate how much space is left in the buffer */ + rem = bsz - num; + /* If the new input does not fill the buffer then just add it */ + if (len < rem) { + memcpy(ctx->buf + num, inp, len); + ctx->bufsz += len; + return 1; + } + /* otherwise fill up the buffer and absorb the buffer */ + memcpy(ctx->buf + num, inp, rem); + /* Update the input pointer */ + inp += rem; + len -= rem; + ctx->meth.absorb(ctx, ctx->buf, bsz); + ctx->bufsz = 0; + } + /* Absorb the input - rem = leftover part of the input < blocksize) */ + rem = ctx->meth.absorb(ctx, inp, len); + /* Copy the leftover bit of the input into the buffer */ + if (ossl_likely(rem)) { + memcpy(ctx->buf, inp + len - rem, rem); + ctx->bufsz = rem; + } + return 1; } static int keccak_final(void *vctx, unsigned char *out, size_t *outl, @@ -128,7 +122,9 @@ static int keccak_final(void *vctx, unsigned char *out, size_t *outl, ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_DIGEST_LENGTH); return 0; } - ret = ossl_sha3_final(ctx, out, ctx->md_size); + if (ossl_likely(outlen > 0)) + ret = ctx->meth.final(ctx, out, ctx->md_size); + *outl = ctx->md_size; return ret; } @@ -144,12 +140,47 @@ static int shake_squeeze(void *vctx, unsigned char *out, size_t *outl, if (ctx->meth.squeeze == NULL) return 0; if (outlen > 0) - ret = ossl_sha3_squeeze(ctx, out, outlen); - if (outl != NULL) - *outl = outlen; + ret = ctx->meth.squeeze(ctx, out, outlen); + + *outl = outlen; return ret; } +/*- + * Generic software version of the absorb() and final(). + */ +static size_t generic_sha3_absorb(void *vctx, const void *inp, size_t len) +{ + KECCAK1600_CTX *ctx = vctx; + + if (!(ctx->xof_state == XOF_STATE_INIT || ctx->xof_state == XOF_STATE_ABSORB)) + return 0; + ctx->xof_state = XOF_STATE_ABSORB; + return SHA3_absorb(ctx->A, inp, len, ctx->block_size); +} + +static int generic_sha3_final(void *vctx, unsigned char *out, size_t outlen) +{ + return ossl_sha3_final((KECCAK1600_CTX *)vctx, out, outlen); +} + +static int generic_sha3_squeeze(void *vctx, unsigned char *out, size_t outlen) +{ + return ossl_sha3_squeeze((KECCAK1600_CTX *)vctx, out, outlen); +} + +static PROV_SHA3_METHOD sha3_generic_md = { + generic_sha3_absorb, + generic_sha3_final, + NULL +}; + +static PROV_SHA3_METHOD shake_generic_md = { + generic_sha3_absorb, + generic_sha3_final, + generic_sha3_squeeze +}; + #if defined(S390_SHA3) static sha3_absorb_fn s390x_sha3_absorb; @@ -159,56 +190,79 @@ static sha3_final_fn s390x_shake_final; /*- * The platform specific parts of the absorb() and final() for S390X. */ -static size_t s390x_sha3_absorb(KECCAK1600_CTX *ctx, const unsigned char *inp, size_t len) +static size_t s390x_sha3_absorb(void *vctx, const void *inp, size_t len) { + KECCAK1600_CTX *ctx = vctx; size_t rem = len % ctx->block_size; unsigned int fc; + if (!(ctx->xof_state == XOF_STATE_INIT || ctx->xof_state == XOF_STATE_ABSORB)) + return 0; if (len - rem > 0) { fc = ctx->pad; fc |= ctx->xof_state == XOF_STATE_INIT ? S390X_KIMD_NIP : 0; + ctx->xof_state = XOF_STATE_ABSORB; s390x_kimd(inp, len - rem, fc, ctx->A); } return rem; } -static int s390x_sha3_final(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen) +static int s390x_sha3_final(void *vctx, unsigned char *out, size_t outlen) { + KECCAK1600_CTX *ctx = vctx; unsigned int fc; + if (!ossl_prov_is_running()) + return 0; + if (!(ctx->xof_state == XOF_STATE_INIT || ctx->xof_state == XOF_STATE_ABSORB)) + return 0; fc = ctx->pad | S390X_KLMD_DUFOP; fc |= ctx->xof_state == XOF_STATE_INIT ? S390X_KLMD_NIP : 0; + ctx->xof_state = XOF_STATE_FINAL; s390x_klmd(ctx->buf, ctx->bufsz, NULL, 0, fc, ctx->A); memcpy(out, ctx->A, outlen); return 1; } -static int s390x_shake_final(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen) +static int s390x_shake_final(void *vctx, unsigned char *out, size_t outlen) { + KECCAK1600_CTX *ctx = vctx; unsigned int fc; + if (!ossl_prov_is_running()) + return 0; + if (!(ctx->xof_state == XOF_STATE_INIT || ctx->xof_state == XOF_STATE_ABSORB)) + return 0; fc = ctx->pad | S390X_KLMD_DUFOP; fc |= ctx->xof_state == XOF_STATE_INIT ? S390X_KLMD_NIP : 0; + ctx->xof_state = XOF_STATE_FINAL; s390x_klmd(ctx->buf, ctx->bufsz, out, outlen, fc, ctx->A); return 1; } -static int s390x_shake_squeeze(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen) +static int s390x_shake_squeeze(void *vctx, unsigned char *out, size_t outlen) { + KECCAK1600_CTX *ctx = vctx; unsigned int fc; size_t len; + if (!ossl_prov_is_running()) + return 0; + if (ctx->xof_state == XOF_STATE_FINAL) + return 0; /* * On the first squeeze call, finish the absorb process (incl. padding). */ if (ctx->xof_state != XOF_STATE_SQUEEZE) { fc = ctx->pad; fc |= ctx->xof_state == XOF_STATE_INIT ? S390X_KLMD_NIP : 0; + ctx->xof_state = XOF_STATE_SQUEEZE; s390x_klmd(ctx->buf, ctx->bufsz, out, outlen, fc, ctx->A); ctx->bufsz = outlen % ctx->block_size; /* reuse ctx->bufsz to count bytes squeezed from current sponge */ return 1; } + ctx->xof_state = XOF_STATE_SQUEEZE; if (ctx->bufsz != 0) { len = ctx->block_size - ctx->bufsz; if (outlen < len) @@ -228,16 +282,22 @@ static int s390x_shake_squeeze(KECCAK1600_CTX *ctx, unsigned char *out, size_t o return 1; } -static int s390x_keccakc_final(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen, +static int s390x_keccakc_final(void *vctx, unsigned char *out, size_t outlen, int padding) { + KECCAK1600_CTX *ctx = vctx; size_t bsz = ctx->block_size; size_t num = ctx->bufsz; size_t needed = outlen; unsigned int fc; + if (!ossl_prov_is_running()) + return 0; + if (!(ctx->xof_state == XOF_STATE_INIT || ctx->xof_state == XOF_STATE_ABSORB)) + return 0; fc = ctx->pad; fc |= ctx->xof_state == XOF_STATE_INIT ? S390X_KIMD_NIP : 0; + ctx->xof_state = XOF_STATE_FINAL; if (outlen == 0) return 1; memset(ctx->buf + num, 0, bsz - num); @@ -254,22 +314,27 @@ static int s390x_keccakc_final(KECCAK1600_CTX *ctx, unsigned char *out, size_t o return 1; } -static int s390x_keccak_final(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen) +static int s390x_keccak_final(void *vctx, unsigned char *out, size_t outlen) { - return s390x_keccakc_final(ctx, out, outlen, 0x01); + return s390x_keccakc_final(vctx, out, outlen, 0x01); } -static int s390x_cshake_keccak_final(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen) +static int s390x_kmac_final(void *vctx, unsigned char *out, size_t outlen) { - return s390x_keccakc_final(ctx, out, outlen, 0x04); + return s390x_keccakc_final(vctx, out, outlen, 0x04); } -static int s390x_keccakc_squeeze(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen, +static int s390x_keccakc_squeeze(void *vctx, unsigned char *out, size_t outlen, int padding) { + KECCAK1600_CTX *ctx = vctx; size_t len; unsigned int fc; + if (!ossl_prov_is_running()) + return 0; + if (ctx->xof_state == XOF_STATE_FINAL) + return 0; /* * On the first squeeze call, finish the absorb process * by adding the trailing padding and then doing @@ -297,6 +362,7 @@ static int s390x_keccakc_squeeze(KECCAK1600_CTX *ctx, unsigned char *out, size_t if (ctx->bufsz == ctx->block_size) ctx->bufsz = 0; } + ctx->xof_state = XOF_STATE_SQUEEZE; if (outlen == 0) return 1; s390x_klmd(NULL, 0, out, outlen, ctx->pad | S390X_KLMD_PS, ctx->A); @@ -305,14 +371,14 @@ static int s390x_keccakc_squeeze(KECCAK1600_CTX *ctx, unsigned char *out, size_t return 1; } -static int s390x_keccak_squeeze(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen) +static int s390x_keccak_squeeze(void *vctx, unsigned char *out, size_t outlen) { - return s390x_keccakc_squeeze(ctx, out, outlen, KECCAK_PADDING); + return s390x_keccakc_squeeze(vctx, out, outlen, 0x01); } -static int s390x_cshake_keccak_squeeze(KECCAK1600_CTX *ctx, unsigned char *out, size_t outlen) +static int s390x_kmac_squeeze(void *vctx, unsigned char *out, size_t outlen) { - return s390x_keccakc_squeeze(ctx, out, outlen, CSHAKE_KECCAK_PADDING); + return s390x_keccakc_squeeze(vctx, out, outlen, 0x04); } static PROV_SHA3_METHOD sha3_s390x_md = { @@ -333,10 +399,10 @@ static PROV_SHA3_METHOD shake_s390x_md = { s390x_shake_squeeze, }; -static PROV_SHA3_METHOD cshake_keccak_s390x_md = { +static PROV_SHA3_METHOD kmac_s390x_md = { s390x_sha3_absorb, - s390x_cshake_keccak_final, - s390x_cshake_keccak_squeeze, + s390x_kmac_final, + s390x_kmac_squeeze, }; #define SHAKE_SET_MD(uname, typ) \ @@ -354,15 +420,15 @@ static PROV_SHA3_METHOD cshake_keccak_s390x_md = { } else { \ ctx->meth = sha3_generic_md; \ } -#define CSHAKE_KECCAK_SET_MD(bitlen) \ +#define KMAC_SET_MD(bitlen) \ if (S390_SHA3_CAPABLE(SHAKE_##bitlen)) { \ ctx->pad = S390X_SHAKE_##bitlen; \ - ctx->meth = cshake_keccak_s390x_md; \ + ctx->meth = kmac_s390x_md; \ } else { \ - ctx->meth = shake_generic_md; \ + ctx->meth = sha3_generic_md; \ } #elif defined(__aarch64__) && defined(KECCAK1600_ASM) -#include "arch/arm_arch.h" +#include "arm_arch.h" static sha3_absorb_fn armsha3_sha3_absorb; @@ -371,20 +437,21 @@ size_t SHA3_absorb_cext(uint64_t A[5][5], const unsigned char *inp, size_t len, /*- * Hardware-assisted ARMv8.2 SHA3 extension version of the absorb() */ -static size_t armsha3_sha3_absorb(KECCAK1600_CTX *ctx, const unsigned char *inp, size_t len) +static size_t armsha3_sha3_absorb(void *vctx, const void *inp, size_t len) { + KECCAK1600_CTX *ctx = vctx; + return SHA3_absorb_cext(ctx->A, inp, len, ctx->block_size); } static PROV_SHA3_METHOD sha3_ARMSHA3_md = { armsha3_sha3_absorb, - ossl_sha3_final_default, - NULL + generic_sha3_final }; static PROV_SHA3_METHOD shake_ARMSHA3_md = { armsha3_sha3_absorb, - ossl_sha3_final_default, - ossl_shake_squeeze_default + generic_sha3_final, + generic_sha3_squeeze }; #define SHAKE_SET_MD(uname, typ) \ if (OPENSSL_armcap_P & ARMV8_HAVE_SHA3_AND_WORTH_USING) { \ @@ -399,87 +466,71 @@ static PROV_SHA3_METHOD shake_ARMSHA3_md = { } else { \ ctx->meth = sha3_generic_md; \ } -#define CSHAKE_KECCAK_SET_MD(bitlen) \ +#define KMAC_SET_MD(bitlen) \ if (OPENSSL_armcap_P & ARMV8_HAVE_SHA3_AND_WORTH_USING) { \ - ctx->meth = shake_ARMSHA3_md; \ + ctx->meth = sha3_ARMSHA3_md; \ } else { \ - ctx->meth = shake_generic_md; \ + ctx->meth = sha3_generic_md; \ } #else #define SHA3_SET_MD(uname, typ) ctx->meth = sha3_generic_md; -#define CSHAKE_KECCAK_SET_MD(bitlen) ctx->meth = shake_generic_md; +#define KMAC_SET_MD(bitlen) ctx->meth = sha3_generic_md; #define SHAKE_SET_MD(uname, typ) ctx->meth = shake_generic_md; #endif /* S390_SHA3 */ -#define SHA3_newctx(typ, uname, name, bitlen, pad) \ - static OSSL_FUNC_digest_newctx_fn name##_newctx; \ - static void *name##_newctx(void *provctx) \ - { \ - KECCAK1600_CTX *ctx; \ - \ - DIGEST_PROV_CHECK(provctx, SHA3_256); \ - if ((ctx = OPENSSL_zalloc(sizeof(*ctx))) == NULL) \ - return NULL; \ - ossl_sha3_init(ctx, pad, bitlen); \ - SHA3_SET_MD(uname, typ) \ - return ctx; \ +#define SHA3_newctx(typ, uname, name, bitlen, pad) \ + static OSSL_FUNC_digest_newctx_fn name##_newctx; \ + static void *name##_newctx(void *provctx) \ + { \ + KECCAK1600_CTX *ctx = ossl_prov_is_running() ? OPENSSL_zalloc(sizeof(*ctx)) \ + : NULL; \ + \ + if (ctx == NULL) \ + return NULL; \ + ossl_sha3_init(ctx, pad, bitlen); \ + SHA3_SET_MD(uname, typ) \ + return ctx; \ } -#define SHAKE_newctx(typ, uname, name, bitlen, mdlen, pad) \ - static OSSL_FUNC_digest_newctx_fn name##_newctx; \ - static void *name##_newctx(void *provctx) \ - { \ - KECCAK1600_CTX *ctx; \ - \ - DIGEST_PROV_CHECK(provctx, SHA3_256); \ - if ((ctx = OPENSSL_zalloc(sizeof(*ctx))) == NULL) \ - return NULL; \ - ossl_keccak_init(ctx, pad, bitlen, mdlen); \ - if (mdlen == 0) \ - ctx->md_size = SIZE_MAX; \ - SHAKE_SET_MD(uname, typ) \ - return ctx; \ +#define SHAKE_newctx(typ, uname, name, bitlen, mdlen, pad) \ + static OSSL_FUNC_digest_newctx_fn name##_newctx; \ + static void *name##_newctx(void *provctx) \ + { \ + KECCAK1600_CTX *ctx = ossl_prov_is_running() ? OPENSSL_zalloc(sizeof(*ctx)) \ + : NULL; \ + \ + if (ctx == NULL) \ + return NULL; \ + ossl_keccak_init(ctx, pad, bitlen, mdlen); \ + if (mdlen == 0) \ + ctx->md_size = SIZE_MAX; \ + SHAKE_SET_MD(uname, typ) \ + return ctx; \ } -#define CSHAKE_KECCAK_newctx(uname, bitlen, pad) \ - static OSSL_FUNC_digest_newctx_fn uname##_newctx; \ - static void *uname##_newctx(void *provctx) \ - { \ - KECCAK1600_CTX *ctx; \ - \ - DIGEST_PROV_CHECK(provctx, SHA3_256); \ - if ((ctx = OPENSSL_zalloc(sizeof(*ctx))) == NULL) \ - return NULL; \ - ossl_keccak_init(ctx, pad, bitlen, 2 * bitlen); \ - CSHAKE_KECCAK_SET_MD(bitlen) \ - return ctx; \ +#define KMAC_newctx(uname, bitlen, pad) \ + static OSSL_FUNC_digest_newctx_fn uname##_newctx; \ + static void *uname##_newctx(void *provctx) \ + { \ + KECCAK1600_CTX *ctx = ossl_prov_is_running() ? OPENSSL_zalloc(sizeof(*ctx)) \ + : NULL; \ + \ + if (ctx == NULL) \ + return NULL; \ + ossl_keccak_init(ctx, pad, bitlen, 2 * bitlen); \ + KMAC_SET_MD(bitlen) \ + return ctx; \ } -#define KMAC_newctx(uname, bitlen, pad) \ - static OSSL_FUNC_digest_newctx_fn uname##_newctx; \ - static void *uname##_newctx(void *provctx) \ - { \ - KECCAK1600_CTX *ctx; \ - \ - DIGEST_PROV_CHECK(provctx, SHA3_256); \ - if ((ctx = OPENSSL_zalloc(sizeof(*ctx))) == NULL) \ - return NULL; \ - ossl_keccak_init(ctx, pad, bitlen, 2 * bitlen); \ - KMAC_SET_MD(bitlen) \ - return ctx; \ - } - -#define PROV_FUNC_SHA3_DIGEST_COMMON(name, bitlen, blksize, dgstsize, flags) \ - PROV_FUNC_DIGEST_GET_PARAM(name, blksize, dgstsize, flags) \ - const OSSL_DISPATCH ossl_##name##_functions[] = { \ - { OSSL_FUNC_DIGEST_NEWCTX, (void (*)(void))name##_newctx }, \ - { OSSL_FUNC_DIGEST_UPDATE, (void (*)(void))keccak_update }, \ - { OSSL_FUNC_DIGEST_FINAL, (void (*)(void))keccak_final }, \ - { OSSL_FUNC_DIGEST_FREECTX, (void (*)(void))keccak_freectx }, \ - { OSSL_FUNC_DIGEST_DUPCTX, (void (*)(void))keccak_dupctx }, \ - { OSSL_FUNC_DIGEST_COPYCTX, (void (*)(void))keccak_copyctx }, \ - { OSSL_FUNC_DIGEST_SERIALIZE, (void (*)(void))name##_serialize }, \ - { OSSL_FUNC_DIGEST_DESERIALIZE, (void (*)(void))name##_deserialize }, \ +#define PROV_FUNC_SHA3_DIGEST_COMMON(name, bitlen, blksize, dgstsize, flags) \ + PROV_FUNC_DIGEST_GET_PARAM(name, blksize, dgstsize, flags) \ + const OSSL_DISPATCH ossl_##name##_functions[] = { \ + { OSSL_FUNC_DIGEST_NEWCTX, (void (*)(void))name##_newctx }, \ + { OSSL_FUNC_DIGEST_UPDATE, (void (*)(void))keccak_update }, \ + { OSSL_FUNC_DIGEST_FINAL, (void (*)(void))keccak_final }, \ + { OSSL_FUNC_DIGEST_FREECTX, (void (*)(void))keccak_freectx }, \ + { OSSL_FUNC_DIGEST_DUPCTX, (void (*)(void))keccak_dupctx }, \ + { OSSL_FUNC_DIGEST_COPYCTX, (void (*)(void))keccak_copyctx }, \ PROV_DISPATCH_FUNC_DIGEST_GET_PARAMS(name) #define PROV_FUNC_SHA3_DIGEST(name, bitlen, blksize, dgstsize, flags) \ @@ -525,137 +576,6 @@ static void *keccak_dupctx(void *ctx) return ret; } -static const unsigned char keccakmagic[] = "KECCAKv1"; -#define KECCAKMAGIC_LEN (sizeof(keccakmagic) - 1) -#define KECCAK_SERIALIZATION_LEN \ - ( \ - KECCAKMAGIC_LEN /* magic string */ \ - + sizeof(uint64_t) /* impl-ID */ \ - + sizeof(uint64_t) /* c->md_size */ \ - + (sizeof(uint64_t) * 4) /* c->block_size, c->bufsz, c->pad, c->xof_state */ \ - + (sizeof(uint64_t) * 5 * 5) /* c->A */ \ - + (KECCAK1600_WIDTH / 8 - 32) /* c->buf */ \ - ) - -static int KECCAK_Serialize(KECCAK1600_CTX *c, int impl_id, - unsigned char *output, size_t *outlen) -{ - unsigned char *p; - int i, j; - - if (output == NULL) { - if (outlen == NULL) - return 0; - - *outlen = KECCAK_SERIALIZATION_LEN; - return 1; - } - - if (outlen != NULL && *outlen < KECCAK_SERIALIZATION_LEN) - return 0; - - p = output; - - /* Magic code */ - memcpy(p, keccakmagic, KECCAKMAGIC_LEN); - p += KECCAKMAGIC_LEN; - - /* Additional check data */ - p = OPENSSL_store_u64_le(p, impl_id); - p = OPENSSL_store_u64_le(p, c->md_size); - - p = OPENSSL_store_u64_le(p, c->block_size); - p = OPENSSL_store_u64_le(p, c->bufsz); - p = OPENSSL_store_u64_le(p, c->pad); - p = OPENSSL_store_u64_le(p, c->xof_state); - - /* A matrix */ - for (i = 0; i < 5; i++) { - for (j = 0; j < 5; j++) - p = OPENSSL_store_u64_le(p, c->A[i][j]); - } - - if (outlen != NULL) - *outlen = KECCAK_SERIALIZATION_LEN; - - /* buf */ - memcpy(p, c->buf, sizeof(c->buf)); - - return 1; -} - -/* - * This function only performs basic input sanity checks and is not - * built to handle malicious input data. Only trusted input should be - * fed to this function - */ -static int KECCAK_Deserialize(KECCAK1600_CTX *c, int impl_id, - const unsigned char *input, size_t len) -{ - const unsigned char *p; - uint64_t val; - int i, j; - - if (c == NULL || input == NULL || len != KECCAK_SERIALIZATION_LEN) - return 0; - - /* Magic code */ - if (memcmp(input, keccakmagic, KECCAKMAGIC_LEN) != 0) - return 0; - - p = input + KECCAKMAGIC_LEN; - - /* Check for matching Impl ID */ - p = OPENSSL_load_u64_le(&val, p); - if (val != (uint64_t)impl_id) - return 0; - - /* Check for matching md_size */ - p = OPENSSL_load_u64_le(&val, p); - if (val != (uint64_t)c->md_size) - return 0; - - /* check that block_size is congruent with the initialized value */ - p = OPENSSL_load_u64_le(&val, p); - if (val != c->block_size) - return 0; - /* check that bufsz does not exceed block_size */ - p = OPENSSL_load_u64_le(&val, p); - if (val > c->block_size) - return 0; - c->bufsz = (size_t)val; - p = OPENSSL_load_u64_le(&val, p); - if (val != c->pad) - return 0; - p = OPENSSL_load_u64_le(&val, p); - c->xof_state = (int)val; - - /* A matrix */ - for (i = 0; i < 5; i++) { - for (j = 0; j < 5; j++) { - p = OPENSSL_load_u64_le(&val, p); - c->A[i][j] = val; - } - } - - /* buf */ - memcpy(c->buf, p, sizeof(c->buf)); - - return 1; -} - -#define IMPLEMENT_SERIALIZE_FNS(name, id) \ - static int name##_serialize(void *vctx, unsigned char *out, \ - size_t *outlen) \ - { \ - return KECCAK_Serialize(vctx, id, out, outlen); \ - } \ - static int name##_deserialize(void *vctx, const unsigned char *in, \ - size_t inlen) \ - { \ - return KECCAK_Deserialize(vctx, id, in, inlen); \ - } - static const OSSL_PARAM *shake_gettable_ctx_params(ossl_unused void *ctx, ossl_unused void *provctx) { @@ -704,40 +624,30 @@ static int shake_set_ctx_params(void *vctx, const OSSL_PARAM params[]) return 1; } -#define KECCAK_SER_ID 0x010000 -#define SHAKE_SER_ID 0x020000 -#define SHA3_SER_ID 0x040000 -#define CSHAKE_KECCAK_SER_ID 0x080000 +#define IMPLEMENT_SHA3_functions(bitlen) \ + SHA3_newctx(sha3, SHA3_##bitlen, sha3_##bitlen, bitlen, '\x06') \ + PROV_FUNC_SHA3_DIGEST(sha3_##bitlen, bitlen, \ + SHA3_BLOCKSIZE(bitlen), SHA3_MDSIZE(bitlen), \ + SHA3_FLAGS) -#define IMPLEMENT_SHA3_functions(bitlen) \ - SHA3_newctx(sha3, SHA3_##bitlen, sha3_##bitlen, bitlen, (uint8_t)SHA3_PADDING) \ - IMPLEMENT_SERIALIZE_FNS(sha3_##bitlen, SHA3_SER_ID + bitlen) \ - PROV_FUNC_SHA3_DIGEST(sha3_##bitlen, bitlen, \ - SHA3_BLOCKSIZE(bitlen), SHA3_MDSIZE(bitlen), \ - SHA3_FLAGS) +#define IMPLEMENT_KECCAK_functions(bitlen) \ + SHA3_newctx(keccak, KECCAK_##bitlen, keccak_##bitlen, bitlen, '\x01') \ + PROV_FUNC_SHA3_DIGEST(keccak_##bitlen, bitlen, \ + SHA3_BLOCKSIZE(bitlen), SHA3_MDSIZE(bitlen), \ + SHA3_FLAGS) -#define IMPLEMENT_KECCAK_functions(bitlen) \ - SHA3_newctx(keccak, KECCAK_##bitlen, keccak_##bitlen, bitlen, (uint8_t)KECCAK_PADDING) \ - IMPLEMENT_SERIALIZE_FNS(keccak_##bitlen, KECCAK_SER_ID + bitlen) \ - PROV_FUNC_SHA3_DIGEST(keccak_##bitlen, bitlen, \ - SHA3_BLOCKSIZE(bitlen), SHA3_MDSIZE(bitlen), \ - SHA3_FLAGS) +#define IMPLEMENT_SHAKE_functions(bitlen) \ + SHAKE_newctx(shake, SHAKE_##bitlen, shake_##bitlen, bitlen, \ + 0 /* no default md length */, '\x1f') \ + PROV_FUNC_SHAKE_DIGEST(shake_##bitlen, bitlen, \ + SHA3_BLOCKSIZE(bitlen), 0, \ + SHAKE_FLAGS) -#define IMPLEMENT_SHAKE_functions(bitlen) \ - SHAKE_newctx(shake, SHAKE_##bitlen, shake_##bitlen, bitlen, \ - 0 /* no default md length */, (uint8_t)SHAKE_PADDING) \ - IMPLEMENT_SERIALIZE_FNS(shake_##bitlen, SHAKE_SER_ID + bitlen) \ - PROV_FUNC_SHAKE_DIGEST(shake_##bitlen, bitlen, \ - SHA3_BLOCKSIZE(bitlen), 0, \ - SHAKE_FLAGS) - -#define IMPLEMENT_CSHAKE_KECCAK_functions(bitlen) \ - CSHAKE_KECCAK_newctx(cshake_keccak_##bitlen, bitlen, (uint8_t)CSHAKE_KECCAK_PADDING) \ - IMPLEMENT_SERIALIZE_FNS(cshake_keccak_##bitlen, CSHAKE_KECCAK_SER_ID + bitlen) \ - PROV_FUNC_SHAKE_DIGEST(cshake_keccak_##bitlen, bitlen, \ - SHA3_BLOCKSIZE(bitlen), \ - CSHAKE_KECCAK_MDSIZE(bitlen), \ - CSHAKE_KECCAK_FLAGS) +#define IMPLEMENT_KMAC_functions(bitlen) \ + KMAC_newctx(keccak_kmac_##bitlen, bitlen, '\x04') \ + PROV_FUNC_SHAKE_DIGEST(keccak_kmac_##bitlen, bitlen, \ + SHA3_BLOCKSIZE(bitlen), KMAC_MDSIZE(bitlen), \ + KMAC_FLAGS) /* ossl_sha3_224_functions */ IMPLEMENT_SHA3_functions(224) @@ -759,7 +669,7 @@ IMPLEMENT_KECCAK_functions(512) IMPLEMENT_SHAKE_functions(128) /* ossl_shake_256_functions */ IMPLEMENT_SHAKE_functions(256) -/* ossl_cshake_keccak_128_functions */ -IMPLEMENT_CSHAKE_KECCAK_functions(128) - /* ossl_cshake_keccak_256_functions */ - IMPLEMENT_CSHAKE_KECCAK_functions(256) +/* ossl_keccak_kmac_128_functions */ +IMPLEMENT_KMAC_functions(128) +/* ossl_keccak_kmac_256_functions */ +IMPLEMENT_KMAC_functions(256) diff --git a/providers/implementations/encode_decode/build.info b/providers/implementations/encode_decode/build.info index 2347ef865f..09c2d8c435 100644 --- a/providers/implementations/encode_decode/build.info +++ b/providers/implementations/encode_decode/build.info @@ -20,7 +20,7 @@ ENDIF DEPEND[encode_key2any.o]=../../common/include/prov/der_rsa.h IF[{- !$disabled{lms} -}] - SOURCE[$DECODER_GOAL]=decode_lmsxdr2key.c lms_codecs.c + SOURCE[$DECODER_GOAL]=decode_lmsxdr2key.c ENDIF IF[{- !$disabled{'ml-dsa'} -}] diff --git a/providers/implementations/encode_decode/decode_der2key.c b/providers/implementations/encode_decode/decode_der2key.c index 6ed99e68fa..b75d73b0fd 100644 --- a/providers/implementations/encode_decode/decode_der2key.c +++ b/providers/implementations/encode_decode/decode_der2key.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -44,7 +44,6 @@ #include "internal/nelem.h" #include "prov/ml_dsa_codecs.h" #include "prov/ml_kem_codecs.h" -#include "prov/lms_codecs.h" #include "providers/implementations/encode_decode/decode_der2key.inc" #ifndef OPENSSL_NO_SLH_DSA @@ -404,16 +403,11 @@ static int der2key_export_object(void *vctx, /* ---------------------------------------------------------------------- */ #ifndef OPENSSL_NO_DH -static void dh_free_key(void *key) -{ - DH_free(key); -} - #define dh_evp_type EVP_PKEY_DH #define dh_d2i_private_key NULL #define dh_d2i_public_key NULL #define dh_d2i_key_params (d2i_of_void *)d2i_DHparams -#define dh_free dh_free_key +#define dh_free (free_key_fn *)DH_free #define dh_check NULL static void *dh_d2i_PKCS8(const unsigned char **der, long der_len, @@ -436,7 +430,7 @@ static void dh_adjust(void *key, struct der2key_ctx_st *ctx) #define dhx_d2i_public_key NULL #define dhx_d2i_key_params (d2i_of_void *)d2i_DHxparams #define dhx_d2i_PKCS8 dh_d2i_PKCS8 -#define dhx_free dh_free_key +#define dhx_free (free_key_fn *)DH_free #define dhx_check NULL #define dhx_adjust dh_adjust #endif @@ -444,16 +438,11 @@ static void dh_adjust(void *key, struct der2key_ctx_st *ctx) /* ---------------------------------------------------------------------- */ #ifndef OPENSSL_NO_DSA -static void dsa_free_key(void *key) -{ - DSA_free(key); -} - #define dsa_evp_type EVP_PKEY_DSA #define dsa_d2i_private_key (d2i_of_void *)d2i_DSAPrivateKey #define dsa_d2i_public_key (d2i_of_void *)d2i_DSAPublicKey #define dsa_d2i_key_params (d2i_of_void *)d2i_DSAparams -#define dsa_free dsa_free_key +#define dsa_free (free_key_fn *)DSA_free #define dsa_check NULL static void *dsa_d2i_PKCS8(const unsigned char **der, long der_len, @@ -474,16 +463,11 @@ static void dsa_adjust(void *key, struct der2key_ctx_st *ctx) /* ---------------------------------------------------------------------- */ #ifndef OPENSSL_NO_EC -static void ec_free_key(void *key) -{ - EC_KEY_free(key); -} - #define ec_evp_type EVP_PKEY_EC #define ec_d2i_private_key (d2i_of_void *)d2i_ECPrivateKey #define ec_d2i_public_key NULL #define ec_d2i_key_params (d2i_of_void *)d2i_ECParameters -#define ec_free ec_free_key +#define ec_free (free_key_fn *)EC_KEY_free static void *ec_d2i_PKCS8(const unsigned char **der, long der_len, struct der2key_ctx_st *ctx) @@ -537,17 +521,12 @@ static void ecx_key_adjust(void *key, struct der2key_ctx_st *ctx) ossl_ecx_key_set0_libctx(key, PROV_LIBCTX_OF(ctx->provctx)); } -static void ecx_free_key(void *key) -{ - ossl_ecx_key_free(key); -} - #define ed25519_evp_type EVP_PKEY_ED25519 #define ed25519_d2i_private_key NULL #define ed25519_d2i_public_key NULL #define ed25519_d2i_key_params NULL #define ed25519_d2i_PKCS8 ecx_d2i_PKCS8 -#define ed25519_free ecx_free_key +#define ed25519_free (free_key_fn *)ossl_ecx_key_free #define ed25519_check NULL #define ed25519_adjust ecx_key_adjust @@ -556,7 +535,7 @@ static void ecx_free_key(void *key) #define ed448_d2i_public_key NULL #define ed448_d2i_key_params NULL #define ed448_d2i_PKCS8 ecx_d2i_PKCS8 -#define ed448_free ecx_free_key +#define ed448_free (free_key_fn *)ossl_ecx_key_free #define ed448_check NULL #define ed448_adjust ecx_key_adjust @@ -565,7 +544,7 @@ static void ecx_free_key(void *key) #define x25519_d2i_public_key NULL #define x25519_d2i_key_params NULL #define x25519_d2i_PKCS8 ecx_d2i_PKCS8 -#define x25519_free ecx_free_key +#define x25519_free (free_key_fn *)ossl_ecx_key_free #define x25519_check NULL #define x25519_adjust ecx_key_adjust @@ -574,7 +553,7 @@ static void ecx_free_key(void *key) #define x448_d2i_public_key NULL #define x448_d2i_key_params NULL #define x448_d2i_PKCS8 ecx_d2i_PKCS8 -#define x448_free ecx_free_key +#define x448_free (free_key_fn *)ossl_ecx_key_free #define x448_check NULL #define x448_adjust ecx_key_adjust #endif /* OPENSSL_NO_ECX */ @@ -585,7 +564,7 @@ static void ecx_free_key(void *key) #define sm2_d2i_public_key NULL #define sm2_d2i_key_params (d2i_of_void *)d2i_ECParameters #define sm2_d2i_PUBKEY ec_d2i_PUBKEY -#define sm2_free ec_free_key +#define sm2_free (free_key_fn *)EC_KEY_free #define sm2_check ec_check #define sm2_adjust ec_adjust @@ -627,18 +606,13 @@ ml_kem_d2i_PUBKEY(const uint8_t **der, long der_len, return key; } -static void ml_kem_free_key(void *key) -{ - ossl_ml_kem_key_free(key); -} - #define ml_kem_512_evp_type EVP_PKEY_ML_KEM_512 #define ml_kem_512_d2i_private_key NULL #define ml_kem_512_d2i_public_key NULL #define ml_kem_512_d2i_key_params NULL #define ml_kem_512_d2i_PUBKEY ml_kem_d2i_PUBKEY #define ml_kem_512_d2i_PKCS8 ml_kem_d2i_PKCS8 -#define ml_kem_512_free ml_kem_free_key +#define ml_kem_512_free (free_key_fn *)ossl_ml_kem_key_free #define ml_kem_512_check NULL #define ml_kem_512_adjust NULL @@ -648,7 +622,7 @@ static void ml_kem_free_key(void *key) #define ml_kem_768_d2i_key_params NULL #define ml_kem_768_d2i_PUBKEY ml_kem_d2i_PUBKEY #define ml_kem_768_d2i_PKCS8 ml_kem_d2i_PKCS8 -#define ml_kem_768_free ml_kem_free_key +#define ml_kem_768_free (free_key_fn *)ossl_ml_kem_key_free #define ml_kem_768_check NULL #define ml_kem_768_adjust NULL @@ -658,18 +632,13 @@ static void ml_kem_free_key(void *key) #define ml_kem_1024_d2i_PUBKEY ml_kem_d2i_PUBKEY #define ml_kem_1024_d2i_PKCS8 ml_kem_d2i_PKCS8 #define ml_kem_1024_d2i_key_params NULL -#define ml_kem_1024_free ml_kem_free_key +#define ml_kem_1024_free (free_key_fn *)ossl_ml_kem_key_free #define ml_kem_1024_check NULL #define ml_kem_1024_adjust NULL #endif #ifndef OPENSSL_NO_SLH_DSA -static void slh_dsa_free_key(void *key) -{ - ossl_slh_dsa_key_free(key); -} - static void * slh_dsa_d2i_PKCS8(const uint8_t **der, long der_len, struct der2key_ctx_st *ctx) { @@ -798,7 +767,7 @@ err: #define slh_dsa_sha2_128s_d2i_key_params NULL #define slh_dsa_sha2_128s_d2i_PKCS8 slh_dsa_d2i_PKCS8 #define slh_dsa_sha2_128s_d2i_PUBKEY slh_dsa_d2i_PUBKEY -#define slh_dsa_sha2_128s_free slh_dsa_free_key +#define slh_dsa_sha2_128s_free (free_key_fn *)ossl_slh_dsa_key_free #define slh_dsa_sha2_128s_check NULL #define slh_dsa_sha2_128s_adjust NULL @@ -808,7 +777,7 @@ err: #define slh_dsa_sha2_128f_d2i_key_params NULL #define slh_dsa_sha2_128f_d2i_PKCS8 slh_dsa_d2i_PKCS8 #define slh_dsa_sha2_128f_d2i_PUBKEY slh_dsa_d2i_PUBKEY -#define slh_dsa_sha2_128f_free slh_dsa_free_key +#define slh_dsa_sha2_128f_free (free_key_fn *)ossl_slh_dsa_key_free #define slh_dsa_sha2_128f_check NULL #define slh_dsa_sha2_128f_adjust NULL @@ -818,7 +787,7 @@ err: #define slh_dsa_sha2_192s_d2i_key_params NULL #define slh_dsa_sha2_192s_d2i_PKCS8 slh_dsa_d2i_PKCS8 #define slh_dsa_sha2_192s_d2i_PUBKEY slh_dsa_d2i_PUBKEY -#define slh_dsa_sha2_192s_free slh_dsa_free_key +#define slh_dsa_sha2_192s_free (free_key_fn *)ossl_slh_dsa_key_free #define slh_dsa_sha2_192s_check NULL #define slh_dsa_sha2_192s_adjust NULL @@ -828,7 +797,7 @@ err: #define slh_dsa_sha2_192f_d2i_key_params NULL #define slh_dsa_sha2_192f_d2i_PKCS8 slh_dsa_d2i_PKCS8 #define slh_dsa_sha2_192f_d2i_PUBKEY slh_dsa_d2i_PUBKEY -#define slh_dsa_sha2_192f_free slh_dsa_free_key +#define slh_dsa_sha2_192f_free (free_key_fn *)ossl_slh_dsa_key_free #define slh_dsa_sha2_192f_check NULL #define slh_dsa_sha2_192f_adjust NULL @@ -838,7 +807,7 @@ err: #define slh_dsa_sha2_256s_d2i_key_params NULL #define slh_dsa_sha2_256s_d2i_PKCS8 slh_dsa_d2i_PKCS8 #define slh_dsa_sha2_256s_d2i_PUBKEY slh_dsa_d2i_PUBKEY -#define slh_dsa_sha2_256s_free slh_dsa_free_key +#define slh_dsa_sha2_256s_free (free_key_fn *)ossl_slh_dsa_key_free #define slh_dsa_sha2_256s_check NULL #define slh_dsa_sha2_256s_adjust NULL @@ -848,7 +817,7 @@ err: #define slh_dsa_sha2_256f_d2i_key_params NULL #define slh_dsa_sha2_256f_d2i_PKCS8 slh_dsa_d2i_PKCS8 #define slh_dsa_sha2_256f_d2i_PUBKEY slh_dsa_d2i_PUBKEY -#define slh_dsa_sha2_256f_free slh_dsa_free_key +#define slh_dsa_sha2_256f_free (free_key_fn *)ossl_slh_dsa_key_free #define slh_dsa_sha2_256f_check NULL #define slh_dsa_sha2_256f_adjust NULL @@ -858,7 +827,7 @@ err: #define slh_dsa_shake_128s_d2i_key_params NULL #define slh_dsa_shake_128s_d2i_PKCS8 slh_dsa_d2i_PKCS8 #define slh_dsa_shake_128s_d2i_PUBKEY slh_dsa_d2i_PUBKEY -#define slh_dsa_shake_128s_free slh_dsa_free_key +#define slh_dsa_shake_128s_free (free_key_fn *)ossl_slh_dsa_key_free #define slh_dsa_shake_128s_check NULL #define slh_dsa_shake_128s_adjust NULL @@ -868,7 +837,7 @@ err: #define slh_dsa_shake_128f_d2i_key_params NULL #define slh_dsa_shake_128f_d2i_PKCS8 slh_dsa_d2i_PKCS8 #define slh_dsa_shake_128f_d2i_PUBKEY slh_dsa_d2i_PUBKEY -#define slh_dsa_shake_128f_free slh_dsa_free_key +#define slh_dsa_shake_128f_free (free_key_fn *)ossl_slh_dsa_key_free #define slh_dsa_shake_128f_check NULL #define slh_dsa_shake_128f_adjust NULL @@ -878,7 +847,7 @@ err: #define slh_dsa_shake_192s_d2i_key_params NULL #define slh_dsa_shake_192s_d2i_PKCS8 slh_dsa_d2i_PKCS8 #define slh_dsa_shake_192s_d2i_PUBKEY slh_dsa_d2i_PUBKEY -#define slh_dsa_shake_192s_free slh_dsa_free_key +#define slh_dsa_shake_192s_free (free_key_fn *)ossl_slh_dsa_key_free #define slh_dsa_shake_192s_check NULL #define slh_dsa_shake_192s_adjust NULL @@ -888,7 +857,7 @@ err: #define slh_dsa_shake_192f_d2i_key_params NULL #define slh_dsa_shake_192f_d2i_PKCS8 slh_dsa_d2i_PKCS8 #define slh_dsa_shake_192f_d2i_PUBKEY slh_dsa_d2i_PUBKEY -#define slh_dsa_shake_192f_free slh_dsa_free_key +#define slh_dsa_shake_192f_free (free_key_fn *)ossl_slh_dsa_key_free #define slh_dsa_shake_192f_check NULL #define slh_dsa_shake_192f_adjust NULL @@ -898,7 +867,7 @@ err: #define slh_dsa_shake_256s_d2i_key_params NULL #define slh_dsa_shake_256s_d2i_PKCS8 slh_dsa_d2i_PKCS8 #define slh_dsa_shake_256s_d2i_PUBKEY slh_dsa_d2i_PUBKEY -#define slh_dsa_shake_256s_free slh_dsa_free_key +#define slh_dsa_shake_256s_free (free_key_fn *)ossl_slh_dsa_key_free #define slh_dsa_shake_256s_check NULL #define slh_dsa_shake_256s_adjust NULL @@ -908,23 +877,18 @@ err: #define slh_dsa_shake_256f_d2i_key_params NULL #define slh_dsa_shake_256f_d2i_PKCS8 slh_dsa_d2i_PKCS8 #define slh_dsa_shake_256f_d2i_PUBKEY slh_dsa_d2i_PUBKEY -#define slh_dsa_shake_256f_free slh_dsa_free_key +#define slh_dsa_shake_256f_free (free_key_fn *)ossl_slh_dsa_key_free #define slh_dsa_shake_256f_check NULL #define slh_dsa_shake_256f_adjust NULL #endif /* OPENSSL_NO_SLH_DSA */ /* ---------------------------------------------------------------------- */ -static void rsa_free_key(void *key) -{ - RSA_free(key); -} - #define rsa_evp_type EVP_PKEY_RSA #define rsa_d2i_private_key (d2i_of_void *)d2i_RSAPrivateKey #define rsa_d2i_public_key (d2i_of_void *)d2i_RSAPublicKey #define rsa_d2i_key_params NULL -#define rsa_free rsa_free_key +#define rsa_free (free_key_fn *)RSA_free static void *rsa_d2i_PKCS8(const unsigned char **der, long der_len, struct der2key_ctx_st *ctx) @@ -972,18 +936,13 @@ static void rsa_adjust(void *key, struct der2key_ctx_st *ctx) #define rsapss_d2i_key_params NULL #define rsapss_d2i_PKCS8 rsa_d2i_PKCS8 #define rsapss_d2i_PUBKEY rsa_d2i_PUBKEY -#define rsapss_free rsa_free_key +#define rsapss_free (free_key_fn *)RSA_free #define rsapss_check rsa_check #define rsapss_adjust rsa_adjust /* ---------------------------------------------------------------------- */ #ifndef OPENSSL_NO_ML_DSA -static void ml_dsa_free_key(void *key) -{ - ossl_ml_dsa_key_free(key); -} - static void * ml_dsa_d2i_PKCS8(const uint8_t **der, long der_len, struct der2key_ctx_st *ctx) { @@ -1014,7 +973,7 @@ static ossl_inline void *ml_dsa_d2i_PUBKEY(const uint8_t **der, long der_len, #define ml_dsa_44_d2i_key_params NULL #define ml_dsa_44_d2i_PUBKEY ml_dsa_d2i_PUBKEY #define ml_dsa_44_d2i_PKCS8 ml_dsa_d2i_PKCS8 -#define ml_dsa_44_free ml_dsa_free_key +#define ml_dsa_44_free (free_key_fn *)ossl_ml_dsa_key_free #define ml_dsa_44_check NULL #define ml_dsa_44_adjust NULL @@ -1024,7 +983,7 @@ static ossl_inline void *ml_dsa_d2i_PUBKEY(const uint8_t **der, long der_len, #define ml_dsa_65_d2i_key_params NULL #define ml_dsa_65_d2i_PUBKEY ml_dsa_d2i_PUBKEY #define ml_dsa_65_d2i_PKCS8 ml_dsa_d2i_PKCS8 -#define ml_dsa_65_free ml_dsa_free_key +#define ml_dsa_65_free (free_key_fn *)ossl_ml_dsa_key_free #define ml_dsa_65_check NULL #define ml_dsa_65_adjust NULL @@ -1034,7 +993,7 @@ static ossl_inline void *ml_dsa_d2i_PUBKEY(const uint8_t **der, long der_len, #define ml_dsa_87_d2i_PUBKEY ml_dsa_d2i_PUBKEY #define ml_dsa_87_d2i_PKCS8 ml_dsa_d2i_PKCS8 #define ml_dsa_87_d2i_key_params NULL -#define ml_dsa_87_free ml_dsa_free_key +#define ml_dsa_87_free (free_key_fn *)ossl_ml_dsa_key_free #define ml_dsa_87_check NULL #define ml_dsa_87_adjust NULL @@ -1042,30 +1001,6 @@ static ossl_inline void *ml_dsa_d2i_PUBKEY(const uint8_t **der, long der_len, /* ---------------------------------------------------------------------- */ -#ifndef OPENSSL_NO_LMS -static void lms_free_key(void *key) -{ - ossl_lms_key_free(key); -} - -#define lms_evp_type EVP_PKEY_HSS_LMS -#define lms_free lms_free_key -#define lms_check NULL -#define lms_adjust NULL - -static ossl_inline void *lms_d2i_PUBKEY(const uint8_t **der, long der_len, - struct der2key_ctx_st *ctx) -{ - LMS_KEY *key; - - key = ossl_lms_d2i_PUBKEY(*der, der_len, ctx->provctx); - if (key != NULL) - *der += der_len; - return key; -} -#endif -/* ---------------------------------------------------------------------- */ - /* * The DO_ macros help define the selection mask and the method functions * for each kind of object we want to decode. @@ -1368,7 +1303,3 @@ MAKE_DECODER("ML-DSA-65", ml_dsa_65, ml_dsa_65, SubjectPublicKeyInfo); MAKE_DECODER("ML-DSA-87", ml_dsa_87, ml_dsa_87, PrivateKeyInfo); MAKE_DECODER("ML-DSA-87", ml_dsa_87, ml_dsa_87, SubjectPublicKeyInfo); #endif - -#ifndef OPENSSL_NO_LMS -MAKE_DECODER("LMS", lms, lms, SubjectPublicKeyInfo); -#endif diff --git a/providers/implementations/encode_decode/decode_epki2pki.c b/providers/implementations/encode_decode/decode_epki2pki.c index 46a62295a2..94b9adb52d 100644 --- a/providers/implementations/encode_decode/decode_epki2pki.c +++ b/providers/implementations/encode_decode/decode_epki2pki.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -26,8 +26,6 @@ #include "prov/endecoder_local.h" #include "providers/implementations/encode_decode/decode_epki2pki.inc" -#include - static OSSL_FUNC_decoder_newctx_fn epki2pki_newctx; static OSSL_FUNC_decoder_freectx_fn epki2pki_freectx; static OSSL_FUNC_decoder_decode_fn epki2pki_decode; diff --git a/providers/implementations/encode_decode/decode_spki2typespki.c b/providers/implementations/encode_decode/decode_spki2typespki.c index 6fd680c23f..ad1fd0ea3e 100644 --- a/providers/implementations/encode_decode/decode_spki2typespki.c +++ b/providers/implementations/encode_decode/decode_spki2typespki.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -122,29 +122,14 @@ int ossl_spki2typespki_der_decode(unsigned char *der, long len, int selection, goto end; X509_ALGOR_get0(&oid, NULL, NULL, algor); - /* - * Resolve the SPKI AlgorithmIdentifier OID to the key type name expected - * by the downstream provider decoder. Most OIDs map one-to-one to a key - * type via OBJ_obj2txt(), but a few need special handling: - * - * - SM2 abuses id-ecPublicKey, so the EC parameters must be inspected - * to tell EC and SM2 apart. - * - TPM 1.2 Endorsement Key certificates use NID_rsaesOaep with a - * plain RSAPublicKey body per TCG Credential Profiles V1.2 section - * 3.2.7; the OAEP AlgorithmIdentifier parameters are not interpreted - * here. Keep this in sync with x509_pubkey_decode() and - * x509_pubkey_ex_d2i_ex() in crypto/x509/x_pubkey.c. - */ - dataname[0] = '\0'; #ifndef OPENSSL_NO_EC + /* SM2 abuses the EC oid, so this could actually be SM2 */ if (OBJ_obj2nid(oid) == NID_X9_62_id_ecPublicKey && ossl_x509_algor_is_sm2(algor)) - OPENSSL_strlcpy(dataname, "SM2", sizeof(dataname)); + strcpy(dataname, "SM2"); + else #endif - if (dataname[0] == '\0' && OBJ_obj2nid(oid) == NID_rsaesOaep) - OPENSSL_strlcpy(dataname, "RSA", sizeof(dataname)); - if (dataname[0] == '\0' - && OBJ_obj2txt(dataname, sizeof(dataname), oid, 0) <= 0) + if (OBJ_obj2txt(dataname, sizeof(dataname), oid, 0) <= 0) goto end; ossl_X509_PUBKEY_INTERNAL_free(xpub); diff --git a/providers/implementations/encode_decode/encode_key2any.c b/providers/implementations/encode_decode/encode_key2any.c index 1d12bf1e9e..963c223cb3 100644 --- a/providers/implementations/encode_decode/encode_key2any.c +++ b/providers/implementations/encode_decode/encode_key2any.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -41,11 +41,8 @@ #include "prov/endecoder_local.h" #include "prov/ml_dsa_codecs.h" #include "prov/ml_kem_codecs.h" -#include "prov/lms_codecs.h" #include "providers/implementations/encode_decode/encode_key2any.inc" -#include - #if defined(OPENSSL_NO_DH) && defined(OPENSSL_NO_DSA) && defined(OPENSSL_NO_EC) #define OPENSSL_NO_KEYPARAMS #endif @@ -1108,19 +1105,6 @@ static int slh_dsa_pki_priv_to_der(const void *vkey, unsigned char **pder, #define slh_dsa_shake_256f_pem_type "SLH-DSA-SHAKE-256f" #endif /* OPENSSL_NO_SLH_DSA */ -#ifndef OPENSSL_NO_LMS -static int lms_spki_pub_to_der(const void *vkey, unsigned char **pder, - ossl_unused void *ctx) -{ - return ossl_lms_i2d_pubkey(vkey, pder); -} - -#define prepare_lms_params NULL -#define lms_check_key_type NULL -#define lms_evp_type EVP_PKEY_HSS_LMS -#define lms_pem_type "LMS" -#endif /* OPENSSL_NO_LMS */ - /* ---------------------------------------------------------------------- */ static OSSL_FUNC_decoder_newctx_fn key2any_newctx; @@ -1782,8 +1766,3 @@ MAKE_ENCODER(ml_dsa_87, ml_dsa, PrivateKeyInfo, pem); MAKE_ENCODER(ml_dsa_87, ml_dsa, SubjectPublicKeyInfo, der); MAKE_ENCODER(ml_dsa_87, ml_dsa, SubjectPublicKeyInfo, pem); #endif /* OPENSSL_NO_ML_DSA */ - -#ifndef OPENSSL_NO_LMS -MAKE_ENCODER(lms, lms, SubjectPublicKeyInfo, der); -MAKE_ENCODER(lms, lms, SubjectPublicKeyInfo, pem); -#endif diff --git a/providers/implementations/encode_decode/encode_key2ms.c b/providers/implementations/encode_decode/encode_key2ms.c index 87b4242923..8ae4022e51 100644 --- a/providers/implementations/encode_decode/encode_key2ms.c +++ b/providers/implementations/encode_decode/encode_key2ms.c @@ -68,11 +68,10 @@ static int write_pvk(struct key2ms_ctx_st *ctx, OSSL_CORE_BIO *cout, return ret; } -static OSSL_FUNC_encoder_newctx_fn key2ms_newctx; static OSSL_FUNC_encoder_freectx_fn key2ms_freectx; static OSSL_FUNC_encoder_does_selection_fn key2ms_does_selection; -static void *key2ms_newctx(void *provctx) +static struct key2ms_ctx_st *key2ms_newctx(void *provctx) { struct key2ms_ctx_st *ctx = OPENSSL_zalloc(sizeof(*ctx)); diff --git a/providers/implementations/encode_decode/encode_key2text.c b/providers/implementations/encode_decode/encode_key2text.c index 965113426b..026929275c 100644 --- a/providers/implementations/encode_decode/encode_key2text.c +++ b/providers/implementations/encode_decode/encode_key2text.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -33,7 +33,6 @@ #include "prov/endecoder_local.h" #include "prov/ml_dsa_codecs.h" #include "prov/ml_kem_codecs.h" -#include "prov/lms_codecs.h" DEFINE_SPECIAL_STACK_OF_CONST(BIGNUM_const, BIGNUM) @@ -363,9 +362,8 @@ static int ec_to_text(BIO *out, const void *key, int selection) } if (type_label != NULL - && BIO_printf(out, "%s: (%d bit field, %d bit security level)\n", - type_label, EC_GROUP_get_degree(group), - EC_GROUP_security_bits(group)) + && BIO_printf(out, "%s: (%d bit)\n", type_label, + EC_GROUP_order_bits(group)) <= 0) goto err; if (priv != NULL @@ -444,7 +442,7 @@ static int ecx_to_text(BIO *out, const void *key, int selection) #ifndef OPENSSL_NO_ML_KEM static int ml_kem_to_text(BIO *out, const void *vkey, int selection) { - return ossl_ml_kem_key_to_text(out, (const ML_KEM_KEY *)vkey, selection); + return ossl_ml_kem_key_to_text(out, (ML_KEM_KEY *)vkey, selection); } #endif @@ -453,7 +451,7 @@ static int ml_kem_to_text(BIO *out, const void *vkey, int selection) #ifndef OPENSSL_NO_SLH_DSA static int slh_dsa_to_text(BIO *out, const void *key, int selection) { - return ossl_slh_dsa_key_to_text(out, (const SLH_DSA_KEY *)key, selection); + return ossl_slh_dsa_key_to_text(out, (SLH_DSA_KEY *)key, selection); } #endif /* OPENSSL_NO_SLH_DSA */ @@ -619,17 +617,9 @@ err: #ifndef OPENSSL_NO_ML_DSA static int ml_dsa_to_text(BIO *out, const void *key, int selection) { - return ossl_ml_dsa_key_to_text(out, (const ML_DSA_KEY *)key, selection); + return ossl_ml_dsa_key_to_text(out, (ML_DSA_KEY *)key, selection); } #endif /* OPENSSL_NO_ML_DSA */ - -#ifndef OPENSSL_NO_LMS -static int lms_to_text(BIO *out, const void *key, int selection) -{ - return ossl_lms_key_to_text(out, (LMS_KEY *)key, selection); -} -#endif /* OPENSSL_NO_LMS */ - /* ---------------------------------------------------------------------- */ static void *key2text_newctx(void *provctx) @@ -752,7 +742,3 @@ MAKE_TEXT_ENCODER(slh_dsa_shake_192f, slh_dsa); MAKE_TEXT_ENCODER(slh_dsa_shake_256s, slh_dsa); MAKE_TEXT_ENCODER(slh_dsa_shake_256f, slh_dsa); #endif - -#ifndef OPENSSL_NO_LMS -MAKE_TEXT_ENCODER(lms, lms); -#endif diff --git a/providers/implementations/encode_decode/lms_codecs.c b/providers/implementations/encode_decode/lms_codecs.c deleted file mode 100644 index f07fa49294..0000000000 --- a/providers/implementations/encode_decode/lms_codecs.c +++ /dev/null @@ -1,194 +0,0 @@ -/* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include -#include -#include -#include -#include -#include "internal/encoder.h" -#include "internal/nelem.h" -#include "internal/packet.h" -#include "prov/lms_codecs.h" - -/*- - * The DER ASN.1 encoding of LMS public keys prepends 20 bytes - * to the encoded public key: - * - * - 2 byte outer sequence tag and length - * - 2 byte algorithm sequence tag and length - * - 2 byte algorithm OID tag and length - * - 11 byte algorithm OID (from NIST CSOR OID arc) - * - 2 byte bit string tag and length - * - 1 bitstring lead byte - * - * A HSS key with a single tree also represents LMS public key. - * This has 4 extra bytes after the above data with the value 0x00, 0x00, 0x00, 0x01 - * - * The LMS public key consists of - * 4 byte LMS type - * 4 byte OTS type - * 16 byte Id - * n bytes of K where n = 32 or 24. - * i.e. 24 + n bytes - */ - -#define LMS_SPKI_OVERHEAD 20 -#define HSS_HEADER 4 -#define HSS_LMS_SPKI_OVERHEAD (LMS_SPKI_OVERHEAD + HSS_HEADER) -#define HSS_LMS_HEADER(n) { \ - 0x30, 0x2E + n, 0x30, 0x0d, \ - 0x06, 0x0b, \ - 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x09, 0x10, 0x03, 0x11, \ - 0x03, 0x1D + n, \ - 0x00, \ - 0x00, 0x00, 0x00, 0x01 \ -} - -typedef struct { - const uint8_t header[HSS_LMS_SPKI_OVERHEAD]; -} LMS_SPKI_FMT; - -static const LMS_SPKI_FMT hss_lms_32_spkifmt = { - HSS_LMS_HEADER(32) -}; -static const LMS_SPKI_FMT hss_lms_24_spkifmt = { - HSS_LMS_HEADER(24) -}; - -typedef struct { - const LMS_SPKI_FMT *spkifmt; -} LMS_CODEC; - -static const LMS_CODEC codecs[2] = { - { &hss_lms_32_spkifmt }, - { &hss_lms_24_spkifmt } -}; - -static const LMS_SPKI_FMT *find_spkifmt(const uint8_t *pk, int pk_len) -{ - size_t i; - - if (pk_len <= HSS_LMS_SPKI_OVERHEAD) - return NULL; - - for (i = 0; i < OSSL_NELEM(codecs); ++i) { - if (memcmp(pk, codecs[i].spkifmt->header, HSS_LMS_SPKI_OVERHEAD) == 0) - return codecs[i].spkifmt; - } - return NULL; -} - -LMS_KEY * -ossl_lms_d2i_PUBKEY(const uint8_t *pk, int pk_len, PROV_CTX *provctx) -{ - OSSL_LIB_CTX *libctx = PROV_LIBCTX_OF(provctx); - LMS_KEY *ret; - const LMS_SPKI_FMT *spkifmt; - - spkifmt = find_spkifmt(pk, pk_len); - if (spkifmt == NULL) - return NULL; - - if ((ret = ossl_lms_key_new(libctx)) == NULL) - return NULL; - - pk += sizeof(spkifmt->header); - pk_len -= sizeof(spkifmt->header); - - if (!ossl_lms_pubkey_decode(pk, (size_t)pk_len, ret)) { - ERR_raise_data(ERR_LIB_PROV, PROV_R_BAD_ENCODING, - "error parsing LMS public key from input SPKI"); - ossl_lms_key_free(ret); - return NULL; - } - - return ret; -} - -int ossl_lms_i2d_pubkey(const LMS_KEY *key, unsigned char **out) -{ - if (key->pub.encoded == NULL || key->pub.encodedlen == 0) { - ERR_raise_data(ERR_LIB_PROV, PROV_R_NOT_A_PUBLIC_KEY, - "no LMS public key data available"); - return 0; - } - if (out != NULL) { - WPACKET pkt; - size_t sz = HSS_HEADER + key->pub.encodedlen; - uint8_t *buf = OPENSSL_malloc(sz); - int ret; - - if (buf == NULL) - return 0; - ret = WPACKET_init_static_len(&pkt, buf, sz, 0) - /* Output HSS format which has a 4 byte value (L = 1) */ - && WPACKET_memcpy(&pkt, hss_lms_32_spkifmt.header + sizeof(hss_lms_32_spkifmt.header) - HSS_HEADER, HSS_HEADER) - /* Output the LMS encoded public key */ - && WPACKET_memcpy(&pkt, key->pub.encoded, key->pub.encodedlen); - WPACKET_cleanup(&pkt); - if (ret == 0) { - OPENSSL_free(buf); - return 0; - } - *out = buf; - } - return (int)key->pub.encodedlen + HSS_HEADER; -} - -static const char *get_digest(const char *name) -{ - if (strcmp(name, "SHAKE-256") == 0) - return "SHAKE"; - return strcmp(name, "SHA256-192") == 0 ? "SHA256" : name; -} - -int ossl_lms_key_to_text(BIO *out, const LMS_KEY *key, int selection) -{ - const LMS_PARAMS *lms_params; - const LM_OTS_PARAMS *ots_params; - - if (out == NULL || key == NULL) { - ERR_raise(ERR_LIB_PROV, ERR_R_PASSED_NULL_PARAMETER); - return 0; - } - lms_params = key->lms_params; - ots_params = key->ots_params; - - if (key->pub.encoded == NULL || key->pub.encodedlen == 0) { - /* Regardless of the |selection|, there must be a public key */ - ERR_raise_data(ERR_LIB_PROV, PROV_R_MISSING_KEY, - "no LMS key material available"); - return 0; - } - if (BIO_printf(out, "lms-type: %s-N%d-H%d (0x%x)\n", - get_digest(lms_params->digestname), - (int)lms_params->n, (int)lms_params->h, (int)lms_params->lms_type) - <= 0) - return 0; - if (BIO_printf(out, "lm-ots-type: %s-N%d-W%d (0x%x)\n", - get_digest(ots_params->digestname), - (int)ots_params->n, (int)ots_params->w, (int)ots_params->lm_ots_type) - <= 0) - return 0; - if (!ossl_bio_print_labeled_buf(out, "Id:", key->Id, 16)) - return 0; - if ((selection & OSSL_KEYMGMT_SELECT_PRIVATE_KEY) != 0) { - /* Private keys are not supported */ - } else if ((selection & OSSL_KEYMGMT_SELECT_PUBLIC_KEY) != 0) { - if (BIO_printf(out, "LMS Public-Key:\n") <= 0) - return 0; - } - if (!ossl_bio_print_labeled_buf(out, "pub:", key->pub.encoded, key->pub.encodedlen)) - return 0; - if (!ossl_bio_print_labeled_buf(out, "K:", key->pub.K, lms_params->n)) - return 0; - return 1; -} diff --git a/providers/implementations/encode_decode/ml_dsa_codecs.c b/providers/implementations/encode_decode/ml_dsa_codecs.c index 8d84a098ee..c78a1ac102 100644 --- a/providers/implementations/encode_decode/ml_dsa_codecs.c +++ b/providers/implementations/encode_decode/ml_dsa_codecs.c @@ -27,17 +27,103 @@ * Private key bytes: 2560 (0x0a00) */ static const ML_COMMON_SPKI_FMT ml_dsa_44_spkifmt = { - { 0x30, 0x82, 0x05, 0x32, 0x30, 0x0b, 0x06, 0x09, 0x60, 0x86, - 0x48, 0x01, 0x65, 0x03, 0x04, 0x03, 0x11, 0x03, 0x82, 0x05, - 0x21, 0x00 } + { + 0x30, + 0x82, + 0x05, + 0x32, + 0x30, + 0x0b, + 0x06, + 0x09, + 0x60, + 0x86, + 0x48, + 0x01, + 0x65, + 0x03, + 0x04, + 0x03, + 0x11, + 0x03, + 0x82, + 0x05, + 0x21, + 0x00, + } }; static const ML_COMMON_PKCS8_FMT ml_dsa_44_p8fmt[NUM_PKCS8_FORMATS] = { - { "seed-priv", 0x0a2a, 0, 0x30820a26, 0x0420, 6, 0x20, 0x04820a00, 0x2a, 0x0a00, 0, 0 }, - { "priv-only", 0x0a04, 0, 0x04820a00, 0, 0, 0, 0, 0x04, 0x0a00, 0, 0 }, + { + "seed-priv", + 0x0a2a, + 0, + 0x30820a26, + 0x0420, + 6, + 0x20, + 0x04820a00, + 0x2a, + 0x0a00, + 0, + 0, + }, + { + "priv-only", + 0x0a04, + 0, + 0x04820a00, + 0, + 0, + 0, + 0, + 0x04, + 0x0a00, + 0, + 0, + }, { "oqskeypair", 0x0f24, 0, 0x04820f20, 0, 0, 0, 0, 0x04, 0x0a00, 0x0a04, 0x0520 }, - { "seed-only", 0x0022, 2, 0x8020, 0, 2, 0x20, 0, 0, 0, 0, 0 }, - { "bare-priv", 0x0a00, 4, 0, 0, 0, 0, 0, 0, 0x0a00, 0, 0 }, - { "bare-seed", 0x0020, 4, 0, 0, 0, 0x20, 0, 0, 0, 0, 0 }, + { + "seed-only", + 0x0022, + 2, + 0x8020, + 0, + 2, + 0x20, + 0, + 0, + 0, + 0, + 0, + }, + { + "bare-priv", + 0x0a00, + 4, + 0, + 0, + 0, + 0, + 0, + 0, + 0x0a00, + 0, + 0, + }, + { + "bare-seed", + 0x0020, + 4, + 0, + 0, + 0, + 0x20, + 0, + 0, + 0, + 0, + 0, + }, }; /* @@ -46,17 +132,103 @@ static const ML_COMMON_PKCS8_FMT ml_dsa_44_p8fmt[NUM_PKCS8_FORMATS] = { * Private key bytes: 4032 (0x0fc0) */ static const ML_COMMON_SPKI_FMT ml_dsa_65_spkifmt = { - { 0x30, 0x82, 0x07, 0xb2, 0x30, 0x0b, 0x06, 0x09, 0x60, 0x86, - 0x48, 0x01, 0x65, 0x03, 0x04, 0x03, 0x12, 0x03, 0x82, 0x07, - 0xa1, 0x00 } + { + 0x30, + 0x82, + 0x07, + 0xb2, + 0x30, + 0x0b, + 0x06, + 0x09, + 0x60, + 0x86, + 0x48, + 0x01, + 0x65, + 0x03, + 0x04, + 0x03, + 0x12, + 0x03, + 0x82, + 0x07, + 0xa1, + 0x00, + } }; static const ML_COMMON_PKCS8_FMT ml_dsa_65_p8fmt[NUM_PKCS8_FORMATS] = { - { "seed-priv", 0x0fea, 0, 0x30820fe6, 0x0420, 6, 0x20, 0x04820fc0, 0x2a, 0x0fc0, 0, 0 }, - { "priv-only", 0x0fc4, 0, 0x04820fc0, 0, 0, 0, 0, 0x04, 0x0fc0, 0, 0 }, + { + "seed-priv", + 0x0fea, + 0, + 0x30820fe6, + 0x0420, + 6, + 0x20, + 0x04820fc0, + 0x2a, + 0x0fc0, + 0, + 0, + }, + { + "priv-only", + 0x0fc4, + 0, + 0x04820fc0, + 0, + 0, + 0, + 0, + 0x04, + 0x0fc0, + 0, + 0, + }, { "oqskeypair", 0x1764, 0, 0x04821760, 0, 0, 0, 0, 0x04, 0x0fc0, 0x0fc4, 0x07a0 }, - { "seed-only", 0x0022, 2, 0x8020, 0, 2, 0x20, 0, 0, 0, 0, 0 }, - { "bare-priv", 0x0fc0, 4, 0, 0, 0, 0, 0, 0, 0x0fc0, 0, 0 }, - { "bare-seed", 0x0020, 4, 0, 0, 0, 0x20, 0, 0, 0, 0, 0 }, + { + "seed-only", + 0x0022, + 2, + 0x8020, + 0, + 2, + 0x20, + 0, + 0, + 0, + 0, + 0, + }, + { + "bare-priv", + 0x0fc0, + 4, + 0, + 0, + 0, + 0, + 0, + 0, + 0x0fc0, + 0, + 0, + }, + { + "bare-seed", + 0x0020, + 4, + 0, + 0, + 0, + 0x20, + 0, + 0, + 0, + 0, + 0, + }, }; /*- @@ -65,17 +237,103 @@ static const ML_COMMON_PKCS8_FMT ml_dsa_65_p8fmt[NUM_PKCS8_FORMATS] = { * Private key bytes: 4896 (0x1320) */ static const ML_COMMON_SPKI_FMT ml_dsa_87_spkifmt = { - { 0x30, 0x82, 0x0a, 0x32, 0x30, 0x0b, 0x06, 0x09, 0x60, 0x86, - 0x48, 0x01, 0x65, 0x03, 0x04, 0x03, 0x13, 0x03, 0x82, 0x0a, - 0x21, 0x00 } + { + 0x30, + 0x82, + 0x0a, + 0x32, + 0x30, + 0x0b, + 0x06, + 0x09, + 0x60, + 0x86, + 0x48, + 0x01, + 0x65, + 0x03, + 0x04, + 0x03, + 0x13, + 0x03, + 0x82, + 0x0a, + 0x21, + 0x00, + } }; static const ML_COMMON_PKCS8_FMT ml_dsa_87_p8fmt[NUM_PKCS8_FORMATS] = { - { "seed-priv", 0x134a, 0, 0x30821346, 0x0420, 6, 0x20, 0x04821320, 0x2a, 0x1320, 0, 0 }, - { "priv-only", 0x1324, 0, 0x04821320, 0, 0, 0, 0, 0x04, 0x1320, 0, 0 }, + { + "seed-priv", + 0x134a, + 0, + 0x30821346, + 0x0420, + 6, + 0x20, + 0x04821320, + 0x2a, + 0x1320, + 0, + 0, + }, + { + "priv-only", + 0x1324, + 0, + 0x04821320, + 0, + 0, + 0, + 0, + 0x04, + 0x1320, + 0, + 0, + }, { "oqskeypair", 0x1d44, 0, 0x04821d40, 0, 0, 0, 0, 0x04, 0x1320, 0x1324, 0x0a20 }, - { "seed-only", 0x0022, 2, 0x8020, 0, 2, 0x20, 0, 0, 0, 0, 0 }, - { "bare-priv", 0x1320, 4, 0, 0, 0, 0, 0, 0, 0x1320, 0, 0 }, - { "bare-seed", 0x0020, 4, 0, 0, 0, 0x20, 0, 0, 0, 0, 0 }, + { + "seed-only", + 0x0022, + 2, + 0x8020, + 0, + 2, + 0x20, + 0, + 0, + 0, + 0, + 0, + }, + { + "bare-priv", + 0x1320, + 4, + 0, + 0, + 0, + 0, + 0, + 0, + 0x1320, + 0, + 0, + }, + { + "bare-seed", + 0x0020, + 4, + 0, + 0, + 0, + 0x20, + 0, + 0, + 0, + 0, + 0, + }, }; /* Indices of slots in the codec table below */ diff --git a/providers/implementations/encode_decode/ml_kem_codecs.c b/providers/implementations/encode_decode/ml_kem_codecs.c index 21bff4174f..a08587fbf5 100644 --- a/providers/implementations/encode_decode/ml_kem_codecs.c +++ b/providers/implementations/encode_decode/ml_kem_codecs.c @@ -23,18 +23,39 @@ * Public key bytes: 800 (0x0320) * Private key bytes: 1632 (0x0660) */ -/* clang-format off */ static const ML_COMMON_SPKI_FMT ml_kem_512_spkifmt = { - { 0x30, 0x82, 0x03, 0x32, 0x30, 0x0b, 0x06, 0x09, 0x60, 0x86, 0x48, - 0x01, 0x65, 0x03, 0x04, 0x04, 0x01, 0x03, 0x82, 0x03, 0x21, 0x00 } + { + 0x30, + 0x82, + 0x03, + 0x32, + 0x30, + 0x0b, + 0x06, + 0x09, + 0x60, + 0x86, + 0x48, + 0x01, + 0x65, + 0x03, + 0x04, + 0x04, + 0x01, + 0x03, + 0x82, + 0x03, + 0x21, + 0x00, + } }; static const ML_COMMON_PKCS8_FMT ml_kem_512_p8fmt[NUM_PKCS8_FORMATS] = { - { "seed-priv", 0x06aa, 0, 0x308206a6, 0x0440, 6, 0x40, 0x04820660, 0x4a, 0x0660, 0, 0 }, - { "priv-only", 0x0664, 0, 0x04820660, 0, 0, 0, 0, 0x04, 0x0660, 0, 0 }, - { "oqskeypair", 0x0984, 0, 0x04820980, 0, 0, 0, 0, 0x04, 0x0660, 0x0664, 0x0320 }, - { "seed-only", 0x0042, 2, 0x8040, 0, 2, 0x40, 0, 0, 0, 0, 0 }, - { "bare-priv", 0x0660, 4, 0, 0, 0, 0, 0, 0, 0x0660, 0, 0 }, - { "bare-seed", 0x0040, 4, 0, 0, 0, 0x40, 0, 0, 0, 0, 0 }, + { "seed-priv", 0x06aa, 0, 0x308206a6, 0x0440, 6, 0x40, 0x04820660, 0x4a, 0x0660, 0, 0 }, + { "priv-only", 0x0664, 0, 0x04820660, 0, 0, 0, 0, 0x04, 0x0660, 0, 0 }, + { "oqskeypair", 0x0984, 0, 0x04820980, 0, 0, 0, 0, 0x04, 0x0660, 0x0664, 0x0320 }, + { "seed-only", 0x0042, 2, 0x8040, 0, 2, 0x40, 0, 0, 0, 0, 0 }, + { "bare-priv", 0x0660, 4, 0, 0, 0, 0, 0, 0, 0x0660, 0, 0 }, + { "bare-seed", 0x0040, 4, 0, 0, 0, 0x40, 0, 0, 0, 0, 0 }, }; /*- @@ -43,16 +64,103 @@ static const ML_COMMON_PKCS8_FMT ml_kem_512_p8fmt[NUM_PKCS8_FORMATS] = { * Private key bytes: 2400 (0x0960) */ static const ML_COMMON_SPKI_FMT ml_kem_768_spkifmt = { - { 0x30, 0x82, 0x04, 0xb2, 0x30, 0x0b, 0x06, 0x09, 0x60, 0x86, 0x48, - 0x01, 0x65, 0x03, 0x04, 0x04, 0x02, 0x03, 0x82, 0x04, 0xa1, 0x00 } + { + 0x30, + 0x82, + 0x04, + 0xb2, + 0x30, + 0x0b, + 0x06, + 0x09, + 0x60, + 0x86, + 0x48, + 0x01, + 0x65, + 0x03, + 0x04, + 0x04, + 0x02, + 0x03, + 0x82, + 0x04, + 0xa1, + 0x00, + } }; static const ML_COMMON_PKCS8_FMT ml_kem_768_p8fmt[NUM_PKCS8_FORMATS] = { - { "seed-priv", 0x09aa, 0, 0x308209a6, 0x0440, 6, 0x40, 0x04820960, 0x4a, 0x0960, 0, 0 }, - { "priv-only", 0x0964, 0, 0x04820960, 0, 0, 0, 0, 0x04, 0x0960, 0, 0 }, - { "oqskeypair", 0x0e04, 0, 0x04820e00, 0, 0, 0, 0, 0x04, 0x0960, 0x0964, 0x04a0 }, - { "seed-only", 0x0042, 2, 0x8040, 0, 2, 0x40, 0, 0, 0, 0, 0 }, - { "bare-priv", 0x0960, 4, 0, 0, 0, 0, 0, 0, 0x0960, 0, 0 }, - { "bare-seed", 0x0040, 4, 0, 0, 0, 0x40, 0, 0, 0, 0, 0 }, + { + "seed-priv", + 0x09aa, + 0, + 0x308209a6, + 0x0440, + 6, + 0x40, + 0x04820960, + 0x4a, + 0x0960, + 0, + 0, + }, + { + "priv-only", + 0x0964, + 0, + 0x04820960, + 0, + 0, + 0, + 0, + 0x04, + 0x0960, + 0, + 0, + }, + { "oqskeypair", 0x0e04, 0, 0x04820e00, 0, 0, 0, 0, 0x04, 0x0960, 0x0964, 0x04a0 }, + { + "seed-only", + 0x0042, + 2, + 0x8040, + 0, + 2, + 0x40, + 0, + 0, + 0, + 0, + 0, + }, + { + "bare-priv", + 0x0960, + 4, + 0, + 0, + 0, + 0, + 0, + 0, + 0x0960, + 0, + 0, + }, + { + "bare-seed", + 0x0040, + 4, + 0, + 0, + 0, + 0x40, + 0, + 0, + 0, + 0, + 0, + }, }; /*- @@ -61,18 +169,39 @@ static const ML_COMMON_PKCS8_FMT ml_kem_768_p8fmt[NUM_PKCS8_FORMATS] = { * Public key bytes: 1568 (0x0620) */ static const ML_COMMON_SPKI_FMT ml_kem_1024_spkifmt = { - { 0x30, 0x82, 0x06, 0x32, 0x30, 0x0b, 0x06, 0x09, 0x60, 0x86, 0x48, - 0x01, 0x65, 0x03, 0x04, 0x04, 0x03, 0x03, 0x82, 0x06, 0x21, 0x00 } + { + 0x30, + 0x82, + 0x06, + 0x32, + 0x30, + 0x0b, + 0x06, + 0x09, + 0x60, + 0x86, + 0x48, + 0x01, + 0x65, + 0x03, + 0x04, + 0x04, + 0x03, + 0x03, + 0x82, + 0x06, + 0x21, + 0x00, + } }; static const ML_COMMON_PKCS8_FMT ml_kem_1024_p8fmt[NUM_PKCS8_FORMATS] = { - { "seed-priv", 0x0caa, 0, 0x30820ca6, 0x0440, 6, 0x40, 0x04820c60, 0x4a, 0x0c60, 0, 0 }, - { "priv-only", 0x0c64, 0, 0x04820c60, 0, 0, 0, 0, 0x04, 0x0c60, 0, 0 }, - { "oqskeypair", 0x1284, 0, 0x04821280, 0, 0, 0, 0, 0x04, 0x0c60, 0x0c64, 0x0620 }, - { "seed-only", 0x0042, 2, 0x8040, 0, 2, 0x40, 0, 0, 0, 0, 0 }, - { "bare-priv", 0x0c60, 4, 0, 0, 0, 0, 0, 0, 0x0c60, 0, 0 }, - { "bare-seed", 0x0040, 4, 0, 0, 0, 0x40, 0, 0, 0, 0, 0 }, + { "seed-priv", 0x0caa, 0, 0x30820ca6, 0x0440, 6, 0x40, 0x04820c60, 0x4a, 0x0c60, 0, 0 }, + { "priv-only", 0x0c64, 0, 0x04820c60, 0, 0, 0, 0, 0x04, 0x0c60, 0, 0 }, + { "oqskeypair", 0x1284, 0, 0x04821280, 0, 0, 0, 0, 0x04, 0x0c60, 0x0c64, 0x0620 }, + { "seed-only", 0x0042, 2, 0x8040, 0, 2, 0x40, 0, 0, 0, 0, 0 }, + { "bare-priv", 0x0c60, 4, 0, 0, 0, 0, 0, 0, 0x0c60, 0, 0 }, + { "bare-seed", 0x0040, 4, 0, 0, 0, 0x40, 0, 0, 0, 0, 0 }, }; -/* clang-format on */ /* Indices of slots in the `codecs` table below */ #define ML_KEM_512_CODEC 0 @@ -85,7 +214,7 @@ static const ML_COMMON_PKCS8_FMT ml_kem_1024_p8fmt[NUM_PKCS8_FORMATS] = { static const ML_COMMON_CODEC codecs[3] = { { &ml_kem_512_spkifmt, ml_kem_512_p8fmt }, { &ml_kem_768_spkifmt, ml_kem_768_p8fmt }, - { &ml_kem_1024_spkifmt, ml_kem_1024_p8fmt }, + { &ml_kem_1024_spkifmt, ml_kem_1024_p8fmt } }; /* Retrieve the parameters of one of the ML-KEM variants */ @@ -288,7 +417,8 @@ int ossl_ml_kem_i2d_pubkey(const ML_KEM_KEY *key, unsigned char **out) } publen = key->vinfo->pubkey_bytes; - if ((*out = OPENSSL_malloc(publen)) == NULL) + if (out != NULL + && (*out = OPENSSL_malloc(publen)) == NULL) return 0; if (!ossl_ml_kem_encode_public_key(*out, publen, key)) { ERR_raise_data(ERR_LIB_OSSL_ENCODER, ERR_R_INTERNAL_ERROR, diff --git a/providers/implementations/exchange/dh_exch.c b/providers/implementations/exchange/dh_exch.c index b7c2152659..209023ab0e 100644 --- a/providers/implementations/exchange/dh_exch.c +++ b/providers/implementations/exchange/dh_exch.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -22,7 +22,6 @@ #include #include #include "internal/cryptlib.h" -#include "internal/fips.h" #include "prov/providercommon.h" #include "prov/implementations.h" #include "prov/provider_ctx.h" @@ -89,12 +88,6 @@ static void *dh_newctx(void *provctx) if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_KA_DH)) - return NULL; -#endif - pdhctx = OPENSSL_zalloc(sizeof(PROV_DH_CTX)); if (pdhctx == NULL) return NULL; @@ -112,7 +105,7 @@ static int dh_check_key(PROV_DH_CTX *ctx) if (!key_approved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE0, ctx->libctx, "DH Init", "DH Key", - FIPS_CONFIG_SECURITY_CHECKS)) { + ossl_fips_config_securitycheck_enabled)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); return 0; } @@ -155,15 +148,12 @@ static int dh_init(void *vpdhctx, void *vdh, const OSSL_PARAM params[]) static int dh_match_params(DH *priv, DH *peer) { int ret; - int ignore_q = 1; FFC_PARAMS *dhparams_priv = ossl_dh_get0_params(priv); FFC_PARAMS *dhparams_peer = ossl_dh_get0_params(peer); - if (dhparams_priv != NULL && dhparams_priv->q != NULL) - ignore_q = 0; ret = dhparams_priv != NULL && dhparams_peer != NULL - && ossl_ffc_params_cmp(dhparams_priv, dhparams_peer, ignore_q); + && ossl_ffc_params_cmp(dhparams_priv, dhparams_peer, 1); if (!ret) ERR_raise(ERR_LIB_PROV, PROV_R_MISMATCHING_DOMAIN_PARAMETERS); return ret; diff --git a/providers/implementations/exchange/ecdh_exch.c b/providers/implementations/exchange/ecdh_exch.c index 0355807624..400f0d5ba6 100644 --- a/providers/implementations/exchange/ecdh_exch.c +++ b/providers/implementations/exchange/ecdh_exch.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -23,7 +23,6 @@ #include #include #include "internal/cryptlib.h" -#include "internal/fips.h" #include "prov/provider_ctx.h" #include "prov/providercommon.h" #include "prov/implementations.h" @@ -91,12 +90,6 @@ static void *ecdh_newctx(void *provctx) if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_KA_ECDH)) - return NULL; -#endif - pectx = OPENSSL_zalloc(sizeof(*pectx)); if (pectx == NULL) return NULL; @@ -507,7 +500,7 @@ static ossl_inline int ecdh_plain_derive(void *vpecdhctx, unsigned char *secret, if (has_cofactor && !cofactor_approved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(pecdhctx, OSSL_FIPS_IND_SETTABLE2, pecdhctx->libctx, "ECDH", "Cofactor", - FIPS_CONFIG_ECDH_COFACTOR_CHECK)) { + ossl_fips_config_ecdh_cofactor_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_COFACTOR_REQUIRED); goto end; } diff --git a/providers/implementations/include/prov/ciphercommon.h b/providers/implementations/include/prov/ciphercommon.h index 39f3c36397..3583a65afd 100644 --- a/providers/implementations/include/prov/ciphercommon.h +++ b/providers/implementations/include/prov/ciphercommon.h @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -191,42 +191,26 @@ void ossl_cipher_generic_initkey(void *vctx, size_t kbits, size_t blkbits, OSSL_DISPATCH_END \ }; -#if defined(FIPS_MODULE) -#include "internal/fips.h" -#include "prov/provider_ctx.h" -#define CIPHER_PROV_CHECK(provctx, name) \ - if (!ossl_prov_is_running()) \ - return NULL; \ - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), \ - ST_ID_CIPHER_##name)) \ - return NULL -#else -#define CIPHER_PROV_CHECK(_provtcx, _name) \ - if (!ossl_prov_is_running()) \ - return NULL -#endif /* FIPS_MODULE && CIPHER_IS_FIPS */ - -#define IMPLEMENT_generic_cipher_genfn(alg, UCALG, lcmode, UCMODE, flags, \ - kbits, blkbits, ivbits, typ) \ - static OSSL_FUNC_cipher_get_params_fn alg##_##kbits##_##lcmode##_get_params; \ - static int alg##_##kbits##_##lcmode##_get_params(OSSL_PARAM params[]) \ - { \ - return ossl_cipher_generic_get_params(params, EVP_CIPH_##UCMODE##_MODE, \ - flags, kbits, blkbits, ivbits); \ - } \ - static OSSL_FUNC_cipher_newctx_fn alg##_##kbits##_##lcmode##_newctx; \ - static void *alg##_##kbits##_##lcmode##_newctx(void *provctx) \ - { \ - PROV_##UCALG##_CTX *ctx; \ - CIPHER_PROV_CHECK(provctx, alg); \ - ctx = OPENSSL_zalloc(sizeof(*ctx)); \ - if (ctx != NULL) { \ - ossl_cipher_generic_initkey(ctx, kbits, blkbits, ivbits, \ - EVP_CIPH_##UCMODE##_MODE, flags, \ - ossl_prov_cipher_hw_##alg##_##lcmode(kbits), \ - provctx); \ - } \ - return ctx; \ +#define IMPLEMENT_generic_cipher_genfn(alg, UCALG, lcmode, UCMODE, flags, \ + kbits, blkbits, ivbits, typ) \ + static OSSL_FUNC_cipher_get_params_fn alg##_##kbits##_##lcmode##_get_params; \ + static int alg##_##kbits##_##lcmode##_get_params(OSSL_PARAM params[]) \ + { \ + return ossl_cipher_generic_get_params(params, EVP_CIPH_##UCMODE##_MODE, \ + flags, kbits, blkbits, ivbits); \ + } \ + static OSSL_FUNC_cipher_newctx_fn alg##_##kbits##_##lcmode##_newctx; \ + static void *alg##_##kbits##_##lcmode##_newctx(void *provctx) \ + { \ + PROV_##UCALG##_CTX *ctx = ossl_prov_is_running() ? OPENSSL_zalloc(sizeof(*ctx)) \ + : NULL; \ + if (ctx != NULL) { \ + ossl_cipher_generic_initkey(ctx, kbits, blkbits, ivbits, \ + EVP_CIPH_##UCMODE##_MODE, flags, \ + ossl_prov_cipher_hw_##alg##_##lcmode(kbits), \ + provctx); \ + } \ + return ctx; \ } #define IMPLEMENT_generic_cipher(alg, UCALG, lcmode, UCMODE, flags, kbits, \ diff --git a/providers/implementations/include/prov/ciphercommon_ccm.h b/providers/implementations/include/prov/ciphercommon_ccm.h index 2040eaade7..7e775f5376 100644 --- a/providers/implementations/include/prov/ciphercommon_ccm.h +++ b/providers/implementations/include/prov/ciphercommon_ccm.h @@ -11,10 +11,6 @@ #define OSSL_PROV_CIPHERCOMMON_CCM_H #pragma once -#include -#include - -#include "prov/ciphercommon.h" #include "ciphercommon_aead.h" typedef struct prov_ccm_hw_st PROV_CCM_HW; @@ -52,13 +48,13 @@ typedef struct prov_ccm_st { const PROV_CCM_HW *hw; /* hardware specific methods */ } PROV_CCM_CTX; -PROV_CIPHER_FUNC(int, CCM_cipher, (PROV_CCM_CTX *ctx, unsigned char *out, size_t *padlen, const unsigned char *in, size_t len)); -PROV_CIPHER_FUNC(int, CCM_setkey, (PROV_CCM_CTX *ctx, const unsigned char *key, size_t keylen)); -PROV_CIPHER_FUNC(int, CCM_setiv, (PROV_CCM_CTX *dat, const unsigned char *iv, size_t ivlen, size_t mlen)); -PROV_CIPHER_FUNC(int, CCM_setaad, (PROV_CCM_CTX *ctx, const unsigned char *aad, size_t aadlen)); -PROV_CIPHER_FUNC(int, CCM_auth_encrypt, (PROV_CCM_CTX *ctx, const unsigned char *in, unsigned char *out, size_t len, unsigned char *tag, size_t taglen)); -PROV_CIPHER_FUNC(int, CCM_auth_decrypt, (PROV_CCM_CTX *ctx, const unsigned char *in, unsigned char *out, size_t len, unsigned char *tag, size_t taglen)); -PROV_CIPHER_FUNC(int, CCM_gettag, (PROV_CCM_CTX *ctx, unsigned char *tag, size_t taglen)); +PROV_CIPHER_FUNC(int, CCM_cipher, (PROV_CCM_CTX * ctx, unsigned char *out, size_t *padlen, const unsigned char *in, size_t len)); +PROV_CIPHER_FUNC(int, CCM_setkey, (PROV_CCM_CTX * ctx, const unsigned char *key, size_t keylen)); +PROV_CIPHER_FUNC(int, CCM_setiv, (PROV_CCM_CTX * dat, const unsigned char *iv, size_t ivlen, size_t mlen)); +PROV_CIPHER_FUNC(int, CCM_setaad, (PROV_CCM_CTX * ctx, const unsigned char *aad, size_t aadlen)); +PROV_CIPHER_FUNC(int, CCM_auth_encrypt, (PROV_CCM_CTX * ctx, const unsigned char *in, unsigned char *out, size_t len, unsigned char *tag, size_t taglen)); +PROV_CIPHER_FUNC(int, CCM_auth_decrypt, (PROV_CCM_CTX * ctx, const unsigned char *in, unsigned char *out, size_t len, unsigned char *tag, size_t taglen)); +PROV_CIPHER_FUNC(int, CCM_gettag, (PROV_CCM_CTX * ctx, unsigned char *tag, size_t taglen)); /* * CCM Mode internal method table used to handle hardware specific differences, diff --git a/providers/implementations/include/prov/ciphercommon_gcm.h b/providers/implementations/include/prov/ciphercommon_gcm.h index 08865b7595..cdca3481a0 100644 --- a/providers/implementations/include/prov/ciphercommon_gcm.h +++ b/providers/implementations/include/prov/ciphercommon_gcm.h @@ -12,11 +12,7 @@ #define OSSL_PROV_CIPHERCOMMON_GCM_H #pragma once -#include -#include - #include -#include "prov/ciphercommon.h" #include "ciphercommon_aead.h" typedef struct prov_gcm_hw_st PROV_GCM_HW; @@ -85,12 +81,12 @@ typedef struct prov_gcm_ctx_st { ctr128_f ctr; } PROV_GCM_CTX; -PROV_CIPHER_FUNC(int, GCM_setkey, (PROV_GCM_CTX *ctx, const unsigned char *key, size_t keylen)); -PROV_CIPHER_FUNC(int, GCM_setiv, (PROV_GCM_CTX *dat, const unsigned char *iv, size_t ivlen)); -PROV_CIPHER_FUNC(int, GCM_aadupdate, (PROV_GCM_CTX *ctx, const unsigned char *aad, size_t aadlen)); -PROV_CIPHER_FUNC(int, GCM_cipherupdate, (PROV_GCM_CTX *ctx, const unsigned char *in, size_t len, unsigned char *out)); -PROV_CIPHER_FUNC(int, GCM_cipherfinal, (PROV_GCM_CTX *ctx, unsigned char *tag)); -PROV_CIPHER_FUNC(int, GCM_oneshot, (PROV_GCM_CTX *ctx, unsigned char *aad, size_t aad_len, const unsigned char *in, size_t in_len, unsigned char *out, unsigned char *tag, size_t taglen)); +PROV_CIPHER_FUNC(int, GCM_setkey, (PROV_GCM_CTX * ctx, const unsigned char *key, size_t keylen)); +PROV_CIPHER_FUNC(int, GCM_setiv, (PROV_GCM_CTX * dat, const unsigned char *iv, size_t ivlen)); +PROV_CIPHER_FUNC(int, GCM_aadupdate, (PROV_GCM_CTX * ctx, const unsigned char *aad, size_t aadlen)); +PROV_CIPHER_FUNC(int, GCM_cipherupdate, (PROV_GCM_CTX * ctx, const unsigned char *in, size_t len, unsigned char *out)); +PROV_CIPHER_FUNC(int, GCM_cipherfinal, (PROV_GCM_CTX * ctx, unsigned char *tag)); +PROV_CIPHER_FUNC(int, GCM_oneshot, (PROV_GCM_CTX * ctx, unsigned char *aad, size_t aad_len, const unsigned char *in, size_t in_len, unsigned char *out, unsigned char *tag, size_t taglen)); struct prov_gcm_hw_st { OSSL_GCM_setkey_fn setkey; OSSL_GCM_setiv_fn setiv; @@ -123,4 +119,10 @@ int ossl_gcm_one_shot(PROV_GCM_CTX *ctx, unsigned char *aad, size_t aad_len, int ossl_gcm_cipher_update(PROV_GCM_CTX *ctx, const unsigned char *in, size_t len, unsigned char *out); +#define GCM_HW_SET_KEY_CTR_FN(ks, fn_set_enc_key, fn_block, fn_ctr) \ + fn_set_enc_key(key, (int)(keylen * 8), ks); \ + CRYPTO_gcm128_init(&ctx->gcm, ks, (block128_f)fn_block); \ + ctx->ctr = (ctr128_f)fn_ctr; \ + ctx->key_set = 1; + #endif diff --git a/providers/implementations/include/prov/decoders.h b/providers/implementations/include/prov/decoders.h index 84a822f04e..e38f15b3c2 100644 --- a/providers/implementations/include/prov/decoders.h +++ b/providers/implementations/include/prov/decoders.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_DECODERS_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_DECODERS_H - #include int ossl_epki2pki_der_decode(unsigned char *der, long der_len, int selection, @@ -21,5 +18,3 @@ int ossl_spki2typespki_der_decode(unsigned char *der, long len, int selection, OSSL_CALLBACK *data_cb, void *data_cbarg, OSSL_PASSPHRASE_CALLBACK *pw_cb, void *pw_cbarg, OSSL_LIB_CTX *libctx, const char *propq); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_DECODERS_H) */ diff --git a/providers/implementations/include/prov/digestcommon.h b/providers/implementations/include/prov/digestcommon.h index cc55bd1e87..14adc5507f 100644 --- a/providers/implementations/include/prov/digestcommon.h +++ b/providers/implementations/include/prov/digestcommon.h @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2021 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -49,21 +49,6 @@ extern "C" { return 0; \ } -#if defined(FIPS_MODULE) -#include "internal/fips.h" -#include "prov/provider_ctx.h" -#define DIGEST_PROV_CHECK(provctx, name) \ - if (!ossl_prov_is_running()) \ - return NULL; \ - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), \ - ST_ID_DIGEST_##name)) \ - return NULL -#else -#define DIGEST_PROV_CHECK(_provctx, _name) \ - if (!ossl_prov_is_running()) \ - return NULL -#endif /* FIPS_MODULE && DIGEST_IS_FIPS */ - #define PROV_DISPATCH_FUNC_DIGEST_CONSTRUCT_START( \ name, CTX, blksize, dgstsize, flags, upd, fin) \ static OSSL_FUNC_digest_newctx_fn name##_newctx; \ @@ -71,8 +56,8 @@ extern "C" { static OSSL_FUNC_digest_dupctx_fn name##_dupctx; \ static void *name##_newctx(void *prov_ctx) \ { \ - DIGEST_PROV_CHECK(prov_ctx, name); \ - return OPENSSL_zalloc(sizeof(CTX)); \ + CTX *ctx = ossl_prov_is_running() ? OPENSSL_zalloc(sizeof(*ctx)) : NULL; \ + return ctx; \ } \ static void name##_freectx(void *vctx) \ { \ @@ -141,21 +126,6 @@ extern "C" { { OSSL_FUNC_DIGEST_SET_CTX_PARAMS, (void (*)(void))set_ctx_params }, \ PROV_DISPATCH_FUNC_DIGEST_CONSTRUCT_END -#define IMPLEMENT_digest_functions_with_serialize( \ - name, CTX, blksize, dgstsize, flags, init, upd, fin, \ - serialize, deserialize) \ - static OSSL_FUNC_digest_init_fn name##_internal_init; \ - static int name##_internal_init(void *ctx, const OSSL_PARAM params[]) \ - { \ - return ossl_prov_is_running() && init(ctx); \ - } \ - PROV_DISPATCH_FUNC_DIGEST_CONSTRUCT_START(name, CTX, blksize, dgstsize, flags, \ - upd, fin), \ - { OSSL_FUNC_DIGEST_INIT, (void (*)(void))name##_internal_init }, \ - { OSSL_FUNC_DIGEST_SERIALIZE, (void (*)(void))serialize }, \ - { OSSL_FUNC_DIGEST_DESERIALIZE, (void (*)(void))deserialize }, \ - PROV_DISPATCH_FUNC_DIGEST_CONSTRUCT_END - const OSSL_PARAM *ossl_digest_default_gettable_params(void *provctx); int ossl_digest_default_get_params(OSSL_PARAM params[], size_t blksz, size_t paramsz, unsigned long flags); diff --git a/providers/implementations/include/prov/drbg.h b/providers/implementations/include/prov/drbg.h index 42fd8212ac..c93acba96e 100644 --- a/providers/implementations/include/prov/drbg.h +++ b/providers/implementations/include/prov/drbg.h @@ -23,6 +23,10 @@ /* How many times to read the TSC as a randomness source. */ #define TSC_READ_COUNT 4 +/* Maximum reseed intervals */ +#define MAX_RESEED_INTERVAL (1 << 24) +#define MAX_RESEED_TIME_INTERVAL (1 << 20) /* approx. 12 days */ + /* Default reseed intervals */ #define RESEED_INTERVAL (1 << 8) #define TIME_INTERVAL (60 * 60) /* 1 hour */ @@ -42,6 +46,13 @@ typedef struct prov_drbg_st PROV_DRBG; +/* DRBG status values */ +typedef enum drbg_status_e { + DRBG_UNINITIALISED, + DRBG_READY, + DRBG_ERROR +} DRBG_STATUS; + /* * The state of all types of DRBGs. */ @@ -138,11 +149,7 @@ struct prov_drbg_st { unsigned int parent_reseed_counter; size_t seedlen; - /* - * state is one of: EVP_RAND_STATE_UNINITIALISED, EVP_RAND_STATE_ERROR, - * EVP_RAND_STATE_READY. - */ - int state; + DRBG_STATUS state; /* DRBG specific data */ void *data; diff --git a/providers/implementations/include/prov/eckem.h b/providers/implementations/include/prov/eckem.h index 9fa48323b2..8dedace5f7 100644 --- a/providers/implementations/include/prov/eckem.h +++ b/providers/implementations/include/prov/eckem.h @@ -7,12 +7,7 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_ECKEM_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_ECKEM_H - #define KEM_MODE_UNDEFINED 0 #define KEM_MODE_DHKEM 1 int ossl_eckem_modename2id(const char *name); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_ECKEM_H) */ diff --git a/providers/implementations/include/prov/ecx.h b/providers/implementations/include/prov/ecx.h index 455554a5a4..145f322c05 100644 --- a/providers/implementations/include/prov/ecx.h +++ b/providers/implementations/include/prov/ecx.h @@ -7,14 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_ECX_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_ECX_H - -#include - -#include -#include - #include "crypto/types.h" #ifndef OPENSSL_NO_EC @@ -37,5 +29,3 @@ int ossl_ecx_dhkem_derive_private(ECX_KEY *ecx, unsigned char *privout, int ossl_ec_dhkem_derive_private(EC_KEY *ec, BIGNUM *privout, const unsigned char *ikm, size_t ikmlen); #endif - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_ECX_H) */ diff --git a/providers/implementations/include/prov/endecoder_local.h b/providers/implementations/include/prov/endecoder_local.h index e6c2eaff27..bfdef52455 100644 --- a/providers/implementations/include/prov/endecoder_local.h +++ b/providers/implementations/include/prov/endecoder_local.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_ENDECODER_LOCAL_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_ENDECODER_LOCAL_H - #include #include #include @@ -29,5 +26,3 @@ void *ossl_prov_import_key(const OSSL_DISPATCH *fns, void *provctx, void ossl_prov_free_key(const OSSL_DISPATCH *fns, void *key); int ossl_read_der(PROV_CTX *provctx, OSSL_CORE_BIO *cin, unsigned char **data, long *len); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_ENDECODER_LOCAL_H) */ diff --git a/providers/implementations/include/prov/file_store_local.h b/providers/implementations/include/prov/file_store_local.h index 61047ba2ec..576d8d847f 100644 --- a/providers/implementations/include/prov/file_store_local.h +++ b/providers/implementations/include/prov/file_store_local.h @@ -7,11 +7,4 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_FILE_STORE_LOCAL_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_FILE_STORE_LOCAL_H - -#include - extern const OSSL_ALGORITHM ossl_any_to_obj_algorithm[]; - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_FILE_STORE_LOCAL_H) */ diff --git a/providers/implementations/include/prov/implementations.h b/providers/implementations/include/prov/implementations.h index 2b0782bd0b..70fff1b797 100644 --- a/providers/implementations/include/prov/implementations.h +++ b/providers/implementations/include/prov/implementations.h @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_IMPLEMENTATIONS_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_IMPLEMENTATIONS_H - #include #include @@ -30,12 +27,10 @@ extern const OSSL_DISPATCH ossl_keccak_224_functions[]; extern const OSSL_DISPATCH ossl_keccak_256_functions[]; extern const OSSL_DISPATCH ossl_keccak_384_functions[]; extern const OSSL_DISPATCH ossl_keccak_512_functions[]; +extern const OSSL_DISPATCH ossl_keccak_kmac_128_functions[]; +extern const OSSL_DISPATCH ossl_keccak_kmac_256_functions[]; extern const OSSL_DISPATCH ossl_shake_128_functions[]; extern const OSSL_DISPATCH ossl_shake_256_functions[]; -extern const OSSL_DISPATCH ossl_cshake_keccak_128_functions[]; -extern const OSSL_DISPATCH ossl_cshake_keccak_256_functions[]; -extern const OSSL_DISPATCH ossl_cshake_128_functions[]; -extern const OSSL_DISPATCH ossl_cshake_256_functions[]; extern const OSSL_DISPATCH ossl_blake2s256_functions[]; extern const OSSL_DISPATCH ossl_blake2b512_functions[]; extern const OSSL_DISPATCH ossl_md5_functions[]; @@ -47,7 +42,6 @@ extern const OSSL_DISPATCH ossl_mdc2_functions[]; extern const OSSL_DISPATCH ossl_wp_functions[]; extern const OSSL_DISPATCH ossl_ripemd160_functions[]; extern const OSSL_DISPATCH ossl_nullmd_functions[]; -extern const OSSL_DISPATCH ossl_ml_dsa_mu_functions[]; /* Ciphers */ extern const OSSL_DISPATCH ossl_null_functions[]; @@ -279,9 +273,7 @@ extern const OSSL_DISPATCH ossl_kmac256_internal_functions[]; #endif extern const OSSL_DISPATCH ossl_kmac128_functions[]; extern const OSSL_DISPATCH ossl_kmac256_functions[]; -#ifndef OPENSSL_NO_SIPHASH extern const OSSL_DISPATCH ossl_siphash_functions[]; -#endif extern const OSSL_DISPATCH ossl_poly1305_functions[]; /* KDFs / PRFs */ @@ -297,10 +289,8 @@ extern const OSSL_DISPATCH ossl_kdf_hkdf_functions[]; extern const OSSL_DISPATCH ossl_kdf_hkdf_sha256_functions[]; extern const OSSL_DISPATCH ossl_kdf_hkdf_sha384_functions[]; extern const OSSL_DISPATCH ossl_kdf_hkdf_sha512_functions[]; -extern const OSSL_DISPATCH ossl_kdf_ikev2kdf_functions[]; extern const OSSL_DISPATCH ossl_kdf_tls1_3_kdf_functions[]; extern const OSSL_DISPATCH ossl_kdf_snmpkdf_functions[]; -extern const OSSL_DISPATCH ossl_kdf_srtpkdf_functions[]; extern const OSSL_DISPATCH ossl_kdf_sshkdf_functions[]; extern const OSSL_DISPATCH ossl_kdf_sskdf_functions[]; extern const OSSL_DISPATCH ossl_kdf_x963_kdf_functions[]; @@ -343,7 +333,6 @@ extern const OSSL_DISPATCH ossl_ed448_keymgmt_functions[]; #endif #ifndef OPENSSL_NO_SM2 extern const OSSL_DISPATCH ossl_sm2_keymgmt_functions[]; -extern const OSSL_DISPATCH ossl_curve_sm2_keymgmt_functions[]; #endif #endif #ifndef OPENSSL_NO_LMS @@ -363,9 +352,6 @@ extern const OSSL_DISPATCH ossl_mlx_x448_kem_kmgmt_functions[]; #endif extern const OSSL_DISPATCH ossl_mlx_p256_kem_kmgmt_functions[]; extern const OSSL_DISPATCH ossl_mlx_p384_kem_kmgmt_functions[]; -#ifndef OPENSSL_NO_SM2 -extern const OSSL_DISPATCH ossl_mlx_curve_sm2_kem_kmgmt_functions[]; -#endif #endif #endif #ifndef OPENSSL_NO_SLH_DSA @@ -754,10 +740,6 @@ extern const OSSL_DISPATCH ossl_slh_dsa_shake_192f_to_text_encoder_functions[]; extern const OSSL_DISPATCH ossl_slh_dsa_shake_256s_to_text_encoder_functions[]; extern const OSSL_DISPATCH ossl_slh_dsa_shake_256f_to_text_encoder_functions[]; -extern const OSSL_DISPATCH ossl_lms_to_SubjectPublicKeyInfo_der_encoder_functions[]; -extern const OSSL_DISPATCH ossl_lms_to_SubjectPublicKeyInfo_pem_encoder_functions[]; -extern const OSSL_DISPATCH ossl_lms_to_text_encoder_functions[]; - /* Decoders */ extern const OSSL_DISPATCH ossl_PrivateKeyInfo_der_to_dh_decoder_functions[]; extern const OSSL_DISPATCH ossl_SubjectPublicKeyInfo_der_to_dh_decoder_functions[]; @@ -874,7 +856,6 @@ extern const OSSL_DISPATCH ossl_file_store_functions[]; extern const OSSL_DISPATCH ossl_winstore_store_functions[]; extern const OSSL_DISPATCH ossl_xdr_to_lms_decoder_functions[]; -extern const OSSL_DISPATCH ossl_SubjectPublicKeyInfo_der_to_lms_decoder_functions[]; extern const OSSL_DISPATCH ossl_PrivateKeyInfo_der_to_ml_dsa_44_decoder_functions[]; extern const OSSL_DISPATCH ossl_SubjectPublicKeyInfo_der_to_ml_dsa_44_decoder_functions[]; @@ -887,5 +868,3 @@ extern const OSSL_DISPATCH ossl_SubjectPublicKeyInfo_der_to_ml_dsa_87_decoder_fu extern const OSSL_DISPATCH ossl_generic_skeymgmt_functions[]; extern const OSSL_DISPATCH ossl_aes_skeymgmt_functions[]; - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_IMPLEMENTATIONS_H) */ diff --git a/providers/implementations/include/prov/kdfexchange.h b/providers/implementations/include/prov/kdfexchange.h index 497e4736d2..cf08f785ee 100644 --- a/providers/implementations/include/prov/kdfexchange.h +++ b/providers/implementations/include/prov/kdfexchange.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_KDFEXCHANGE_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_KDFEXCHANGE_H - #include #include #include "internal/refcount.h" @@ -24,5 +21,3 @@ typedef struct kdf_data_st KDF_DATA; KDF_DATA *ossl_kdf_data_new(void *provctx); void ossl_kdf_data_free(KDF_DATA *kdfdata); int ossl_kdf_data_up_ref(KDF_DATA *kdfdata); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_KDFEXCHANGE_H) */ diff --git a/providers/implementations/include/prov/lms_codecs.h b/providers/implementations/include/prov/lms_codecs.h deleted file mode 100644 index 6dfe9dff71..0000000000 --- a/providers/implementations/include/prov/lms_codecs.h +++ /dev/null @@ -1,26 +0,0 @@ -/* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#ifndef PROV_LMS_CODECS_H -#define PROV_LMS_CODECS_H -#pragma once - -#ifndef OPENSSL_NO_LMS -#include -#include "crypto/lms.h" -#include "prov/ciphercommon.h" -#include "prov/provider_ctx.h" - -__owur LMS_KEY * -ossl_lms_d2i_PUBKEY(const uint8_t *pubenc, int publen, PROV_CTX *provctx); -__owur int ossl_lms_i2d_pubkey(const LMS_KEY *key, unsigned char **out); -__owur int ossl_lms_key_to_text(BIO *out, const LMS_KEY *key, int selection); - -#endif /* OPENSSL_NO_LMS */ -#endif /* PROV_LMS_CODECS_H */ diff --git a/providers/implementations/include/prov/macsignature.h b/providers/implementations/include/prov/macsignature.h index d1cebdacf0..e13ff362ce 100644 --- a/providers/implementations/include/prov/macsignature.h +++ b/providers/implementations/include/prov/macsignature.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_MACSIGNATURE_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_MACSIGNATURE_H - #include #include #include "internal/refcount.h" @@ -30,5 +27,3 @@ typedef struct mac_key_st MAC_KEY; MAC_KEY *ossl_mac_key_new(OSSL_LIB_CTX *libctx, int cmac); void ossl_mac_key_free(MAC_KEY *mackey); int ossl_mac_key_up_ref(MAC_KEY *mackey); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_MACSIGNATURE_H) */ diff --git a/providers/implementations/include/prov/ml_dsa.h b/providers/implementations/include/prov/ml_dsa.h index d94dbd55ea..fca8a30625 100644 --- a/providers/implementations/include/prov/ml_dsa.h +++ b/providers/implementations/include/prov/ml_dsa.h @@ -7,13 +7,8 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_ML_DSA_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_ML_DSA_H - #include "crypto/ml_dsa.h" #include "prov/provider_ctx.h" ML_DSA_KEY * ossl_prov_ml_dsa_new(PROV_CTX *provctx, const char *propq, int evp_type); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_ML_DSA_H) */ diff --git a/providers/implementations/include/prov/ml_dsa_codecs.h b/providers/implementations/include/prov/ml_dsa_codecs.h index f440dc3bc1..dd42ac13c0 100644 --- a/providers/implementations/include/prov/ml_dsa_codecs.h +++ b/providers/implementations/include/prov/ml_dsa_codecs.h @@ -24,9 +24,13 @@ __owur ML_DSA_KEY *ossl_ml_dsa_d2i_PKCS8(const uint8_t *prvenc, int prvlen, int evp_type, PROV_CTX *provctx, const char *propq); __owur int ossl_ml_dsa_key_to_text(BIO *out, const ML_DSA_KEY *key, int selection); -__owur int ossl_ml_dsa_i2d_pubkey(const ML_DSA_KEY *key, unsigned char **out); -__owur int ossl_ml_dsa_i2d_prvkey(const ML_DSA_KEY *key, unsigned char **out, - PROV_CTX *provctx, const char *formats); +__owur + __owur int + ossl_ml_dsa_i2d_pubkey(const ML_DSA_KEY *key, unsigned char **out); +__owur + __owur int + ossl_ml_dsa_i2d_prvkey(const ML_DSA_KEY *key, unsigned char **out, + PROV_CTX *provctx, const char *formats); #endif /* OPENSSL_NO_ML_DSA */ #endif /* PROV_ML_DSA_CODECS_H */ diff --git a/providers/implementations/include/prov/ml_kem.h b/providers/implementations/include/prov/ml_kem.h index 33e0efc28b..b82ef1baa0 100644 --- a/providers/implementations/include/prov/ml_kem.h +++ b/providers/implementations/include/prov/ml_kem.h @@ -7,13 +7,8 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_ML_KEM_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_ML_KEM_H - #include "crypto/ml_kem.h" #include "prov/provider_ctx.h" ML_KEM_KEY * ossl_prov_ml_kem_new(PROV_CTX *provctx, const char *propq, int evp_type); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_ML_KEM_H) */ diff --git a/providers/implementations/include/prov/ml_kem_codecs.h b/providers/implementations/include/prov/ml_kem_codecs.h index ad72c9f5d7..a05d9b2dd1 100644 --- a/providers/implementations/include/prov/ml_kem_codecs.h +++ b/providers/implementations/include/prov/ml_kem_codecs.h @@ -24,9 +24,13 @@ __owur ML_KEM_KEY *ossl_ml_kem_d2i_PKCS8(const uint8_t *prvenc, int prvlen, int evp_type, PROV_CTX *provctx, const char *propq); __owur int ossl_ml_kem_key_to_text(BIO *out, const ML_KEM_KEY *key, int selection); -__owur int ossl_ml_kem_i2d_pubkey(const ML_KEM_KEY *key, unsigned char **out); -__owur int ossl_ml_kem_i2d_prvkey(const ML_KEM_KEY *key, unsigned char **out, - PROV_CTX *provctx, const char *formats); +__owur + __owur int + ossl_ml_kem_i2d_pubkey(const ML_KEM_KEY *key, unsigned char **out); +__owur + __owur int + ossl_ml_kem_i2d_prvkey(const ML_KEM_KEY *key, unsigned char **out, + PROV_CTX *provctx, const char *formats); #endif /* OPENSSL_NO_ML_KEM */ #endif /* PROV_ML_KEM_CODECS_H */ diff --git a/providers/implementations/include/prov/names.h b/providers/implementations/include/prov/names.h index 09146dd01e..bc98202879 100644 --- a/providers/implementations/include/prov/names.h +++ b/providers/implementations/include/prov/names.h @@ -1,5 +1,5 @@ /* - * Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -40,9 +40,6 @@ * Symmetric ciphers * ----------------- */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_NAMES_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_NAMES_H - #define PROV_NAMES_AES "AES:2.16.840.1.101.3.4.1" #define PROV_DESCS_AES "OpenSSL AES opaque secret key" #define PROV_NAMES_GENERIC "GENERIC-SECRET" @@ -251,14 +248,12 @@ #define PROV_NAMES_SHAKE_128 "SHAKE-128:SHAKE128:2.16.840.1.101.3.4.2.11" #define PROV_NAMES_SHAKE_256 "SHAKE-256:SHAKE256:2.16.840.1.101.3.4.2.12" -#define PROV_NAMES_CSHAKE_128 "CSHAKE-128:CSHAKE128" -#define PROV_NAMES_CSHAKE_256 "CSHAKE-256:CSHAKE256" - -/* Internal algorithms used by CSHAKE variants */ -#define PROV_NAMES_CSHAKE_KECCAK_128 "CSHAKE-KECCAK-128:KECCAK-KMAC-128:KECCAK-KMAC128" -#define PROV_NAMES_CSHAKE_KECCAK_256 "CSHAKE-KECCAK-256:KECCAK-KMAC-256:KECCAK-KMAC256" -#define PROV_NAMES_KECCAK_KMAC_128 PROV_NAMES_CSHAKE_KECCAK_128 -#define PROV_NAMES_KECCAK_KMAC_256 PROV_NAMES_CSHAKE_KECCAK_256 +/* + * KECCAK-KMAC-128 and KECCAK-KMAC-256 as hashes are mostly useful for + * KMAC128 and KMAC256. + */ +#define PROV_NAMES_KECCAK_KMAC_128 "KECCAK-KMAC-128:KECCAK-KMAC128" +#define PROV_NAMES_KECCAK_KMAC_256 "KECCAK-KMAC-256:KECCAK-KMAC256" /* * https://blake2.net/ doesn't specify size variants, but mentions that * Bouncy Castle uses the names BLAKE2b-160, BLAKE2b-256, BLAKE2b-384, and @@ -276,12 +271,6 @@ #define PROV_NAMES_MDC2 "MDC2:2.5.8.3.101" #define PROV_NAMES_WHIRLPOOL "WHIRLPOOL:1.0.10118.3.0.55" #define PROV_NAMES_RIPEMD_160 "RIPEMD-160:RIPEMD160:RIPEMD:RMD160:1.3.36.3.2.1" -/* - * Name taken from - * https://csrc.nist.gov/csrc/media/Projects/post-quantum-cryptography/documents/faq/fips204-sec6-03192025.pdf - * See ExternalMu-ML-DSA.Prehash - */ -#define PROV_NAMES_ML_DSA_MU "ML-DSA-MU" /*- * KDFs / PRFs @@ -295,14 +284,12 @@ #define PROV_DESCS_HKDF_SHA384_SIGN "OpenSSL HKDF-SHA384 via EVP_PKEY implementation" #define PROV_NAMES_HKDF_SHA512 "HKDF-SHA512:id-alg-hkdf-with-sha512:1.2.840.113549.1.9.16.3.30" #define PROV_DESCS_HKDF_SHA512_SIGN "OpenSSL HKDF-SHA512 via EVP_PKEY implementation" -#define PROV_NAMES_IKEV2KDF "IKEV2KDF" #define PROV_NAMES_TLS1_3_KDF "TLS13-KDF" #define PROV_NAMES_SSKDF "SSKDF" #define PROV_NAMES_PBKDF1 "PBKDF1" #define PROV_NAMES_PBKDF2 "PBKDF2:1.2.840.113549.1.5.12" #define PROV_NAMES_PVKKDF "PVKKDF" #define PROV_NAMES_SNMPKDF "SNMPKDF" -#define PROV_NAMES_SRTPKDF "SRTPKDF" #define PROV_NAMES_SSHKDF "SSHKDF" #define PROV_NAMES_X963KDF "X963KDF:X942KDF-CONCAT" #define PROV_NAMES_X942KDF_ASN1 "X942KDF-ASN1:X942KDF" @@ -418,9 +405,7 @@ #define PROV_DESCS_RSA_PSS "OpenSSL RSA-PSS implementation" #define PROV_NAMES_SM2 "SM2:1.2.156.10197.1.301" #define PROV_DESCS_SM2 "OpenSSL SM2 implementation" -#define PROV_NAMES_curveSM2 "curveSM2" -#define PROV_DESCS_curveSM2 "OpenSSL curveSM2 implementation" -#define PROV_NAMES_LMS "LMS:id-alg-hss-lms-hashsig:1.2.840.113549.1.9.16.3.17" +#define PROV_NAMES_LMS "LMS" #define PROV_DESCS_LMS "OpenSSL LMS implementation" #define PROV_NAMES_ML_DSA_44 "ML-DSA-44:MLDSA44:2.16.840.1.101.3.4.3.17:id-ml-dsa-44" #define PROV_DESCS_ML_DSA_44 "OpenSSL ML-DSA-44 implementation" @@ -442,8 +427,6 @@ #define PROV_DESCS_SecP256r1MLKEM768 "P-256+ML-KEM-768 TLS hybrid implementation" #define PROV_NAMES_SecP384r1MLKEM1024 "SecP384r1MLKEM1024" #define PROV_DESCS_SecP384r1MLKEM1024 "P-384+ML-KEM-1024 TLS hybrid implementation" -#define PROV_NAMES_curveSM2MLKEM768 "curveSM2MLKEM768" -#define PROV_DESCS_curveSM2MLKEM768 "curveSM2+ML-KEM-768 TLS hybrid implementation" #define PROV_NAMES_SLH_DSA_SHA2_128S "SLH-DSA-SHA2-128s:id-slh-dsa-sha2-128s:2.16.840.1.101.3.4.3.20" #define PROV_NAMES_SLH_DSA_SHA2_128F "SLH-DSA-SHA2-128f:id-slh-dsa-sha2-128f:2.16.840.1.101.3.4.3.21" #define PROV_NAMES_SLH_DSA_SHA2_192S "SLH-DSA-SHA2-192s:id-slh-dsa-sha2-192s:2.16.840.1.101.3.4.3.22" @@ -468,5 +451,3 @@ #define PROV_DESCS_SLH_DSA_SHAKE_192F "OpenSSL SLH-DSA-SHAKE-192f implementation" #define PROV_DESCS_SLH_DSA_SHAKE_256S "OpenSSL SLH-DSA-SHAKE-256s implementation" #define PROV_DESCS_SLH_DSA_SHAKE_256F "OpenSSL SLH-DSA-SHAKE-256f implementation" - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_NAMES_H) */ diff --git a/providers/implementations/include/prov/seeding.h b/providers/implementations/include/prov/seeding.h index 7bdc0cbe5d..a6d720dfe4 100644 --- a/providers/implementations/include/prov/seeding.h +++ b/providers/implementations/include/prov/seeding.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_SEEDING_H) -#define OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_SEEDING_H - #include "prov/provider_ctx.h" #include "crypto/rand_pool.h" @@ -31,5 +28,3 @@ size_t ossl_prov_get_nonce(PROV_CTX *prov_ctx, unsigned char **pout, const void *salt, size_t salt_len); void ossl_prov_cleanup_nonce(PROV_CTX *prov_ctx, unsigned char *buf, size_t len); - -#endif /* !defined(OSSL_PROVIDERS_IMPLEMENTATIONS_INCLUDE_PROV_SEEDING_H) */ diff --git a/providers/implementations/kdfs/build.info b/providers/implementations/kdfs/build.info index 1a890cd45d..b41a730e57 100644 --- a/providers/implementations/kdfs/build.info +++ b/providers/implementations/kdfs/build.info @@ -3,7 +3,6 @@ $TLS1_PRF_GOAL=../../libdefault.a ../../libfips.a $HKDF_GOAL=../../libdefault.a ../../libfips.a -$IKEV2_GOAL=../../libdefault.a ../../libfips.a $KBKDF_GOAL=../../libdefault.a ../../libfips.a $KRB5KDF_GOAL=../../libdefault.a $PBKDF1_GOAL=../../liblegacy.a @@ -13,7 +12,6 @@ $PKCS12KDF_GOAL=../../libdefault.a $SSKDF_GOAL=../../libdefault.a ../../libfips.a $SCRYPT_GOAL=../../libdefault.a $SNMPKDF_GOAL=../../libdefault.a ../../libfips.a -$SRTPKDF_GOAL=../../libdefault.a ../../libfips.a $SSHKDF_GOAL=../../libdefault.a ../../libfips.a $X942KDF_GOAL=../../libdefault.a ../../libfips.a $HMAC_DRBG_KDF_GOAL=../../libdefault.a ../../libfips.a @@ -23,54 +21,25 @@ SOURCE[$TLS1_PRF_GOAL]=tls1_prf.c SOURCE[$HKDF_GOAL]=hkdf.c -IF[{- !$disabled{ikev2kdf} -}] - SOURCE[$IKEV2_GOAL]=ikev2kdf.c -ENDIF -IF[{- !$disabled{kbkdf} -}] - SOURCE[$KBKDF_GOAL]=kbkdf.c -ENDIF +SOURCE[$KBKDF_GOAL]=kbkdf.c -IF[{- !$disabled{krb5kdf} -}] - SOURCE[$KRB5KDF_GOAL]=krb5kdf.c -ENDIF +SOURCE[$KRB5KDF_GOAL]=krb5kdf.c SOURCE[$PBKDF1_GOAL]=pbkdf1.c SOURCE[$PBKDF2_GOAL]=pbkdf2.c -IF[{- !$disabled{pvkkdf} -}] - SOURCE[$PVKKDF_GOAL]=pvkkdf.c -ENDIF +SOURCE[$PVKKDF_GOAL]=pvkkdf.c SOURCE[$PKCS12KDF_GOAL]=pkcs12kdf.c -IF[{- !$disabled{sskdf} || !$disabled{x963kdf} -}] - SOURCE[$SSKDF_GOAL]=sskdf.c -ENDIF +SOURCE[$SSKDF_GOAL]=sskdf.c -IF[{- !$disabled{scrypt} -}] - SOURCE[$SCRYPT_GOAL]=scrypt.c -ENDIF - -IF[{- !$disabled{snmpkdf} -}] - SOURCE[$SNMPKDF_GOAL]=snmpkdf.c -ENDIF - -IF[{- !$disabled{srtpkdf} -}] - SOURCE[$SRTPKDF_GOAL]=srtpkdf.c -ENDIF - -IF[{- !$disabled{sshkdf} -}] - SOURCE[$SSHKDF_GOAL]=sshkdf.c -ENDIF - -IF[{- !$disabled{x942kdf} -}] - SOURCE[$X942KDF_GOAL]=x942kdf.c - DEPEND[x942kdf.o]=../../common/include/prov/der_wrap.h -ENDIF - -IF[{- !$disabled{hmac-drbg-kdf} -}] - SOURCE[$HMAC_DRBG_KDF_GOAL]=hmacdrbg_kdf.c -ENDIF +SOURCE[$SCRYPT_GOAL]=scrypt.c +SOURCE[$SNMPKDF_GOAL]=snmpkdf.c +SOURCE[$SSHKDF_GOAL]=sshkdf.c +SOURCE[$X942KDF_GOAL]=x942kdf.c +DEPEND[x942kdf.o]=../../common/include/prov/der_wrap.h +SOURCE[$HMAC_DRBG_KDF_GOAL]=hmacdrbg_kdf.c SOURCE[$ARGON2_GOAL]=argon2.c diff --git a/providers/implementations/kdfs/hkdf.c b/providers/implementations/kdfs/hkdf.c index c1a68f08ed..a3f81019f9 100644 --- a/providers/implementations/kdfs/hkdf.c +++ b/providers/implementations/kdfs/hkdf.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -31,7 +31,6 @@ #include "prov/provider_util.h" #include "prov/securitycheck.h" #include "internal/e_os.h" -#include "internal/fips.h" #include "internal/params.h" #include "internal/sizes.h" @@ -101,12 +100,6 @@ static void *kdf_hkdf_new(void *provctx) if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_KDF_HKDF)) - return NULL; -#endif - if ((ctx = OPENSSL_zalloc(sizeof(*ctx))) != NULL) { ctx->provctx = provctx; OSSL_FIPS_IND_INIT(ctx) @@ -219,7 +212,7 @@ static int fips_hkdf_key_check_passed(KDF_HKDF *ctx) if (!key_approved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE0, libctx, "HKDF", "Key size", - FIPS_CONFIG_HKDF_KEY_CHECK)) { + ossl_fips_config_hkdf_key_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); return 0; } @@ -884,7 +877,7 @@ static int fips_tls1_3_digest_check_passed(KDF_HKDF *ctx, const EVP_MD *md) if (digest_unapproved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE0, libctx, "TLS13 KDF", "Digest", - FIPS_CONFIG_TLS13_KDF_DIGEST_CHECK)) { + ossl_fips_config_tls13_kdf_digest_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_DIGEST_NOT_ALLOWED); return 0; } @@ -920,7 +913,7 @@ static int fips_tls1_3_key_check_passed(KDF_HKDF *ctx) if (!key_approved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE1, libctx, "TLS13 KDF", "Key size", - FIPS_CONFIG_TLS13_KDF_KEY_CHECK)) { + ossl_fips_config_tls13_kdf_key_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); return 0; } diff --git a/providers/implementations/kdfs/hmacdrbg_kdf.c b/providers/implementations/kdfs/hmacdrbg_kdf.c index e411b4ebb7..1984438bdd 100644 --- a/providers/implementations/kdfs/hmacdrbg_kdf.c +++ b/providers/implementations/kdfs/hmacdrbg_kdf.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -15,7 +15,6 @@ #include #include #include "internal/common.h" -#include "internal/fips.h" #include "prov/providercommon.h" #include "prov/implementations.h" #include "prov/hmac_drbg.h" @@ -44,12 +43,6 @@ static void *hmac_drbg_kdf_new(void *provctx) { KDF_HMAC_DRBG *ctx; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_DRBG_HMAC)) - return NULL; -#endif - if (!ossl_prov_is_running()) return NULL; diff --git a/providers/implementations/kdfs/ikev2kdf.c b/providers/implementations/kdfs/ikev2kdf.c deleted file mode 100644 index cd960a8419..0000000000 --- a/providers/implementations/kdfs/ikev2kdf.c +++ /dev/null @@ -1,755 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include -#include -#include -#include "internal/cryptlib.h" -#include "internal/fips.h" -#include "prov/provider_ctx.h" -#include "prov/providercommon.h" -#include "prov/implementations.h" -#include "prov/provider_util.h" -#include "providers/implementations/kdfs/ikev2kdf.inc" - -/* The shared secret length: 28 ~ 1024 bytes */ -#define IKEV2KDF_MIN_SECRET_LENGTH 28 -#define IKEV2KDF_MAX_GROUP19_MODLEN 32 /* ECDH p256 */ -#define IKEV2KDF_MAX_GROUP20_MODLEN 48 /* ECDH p384 */ -#define IKEV2KDF_MAX_GROUP21_MODLEN 66 /* ECDH p521 */ -#define IKEV2KDF_MAX_GROUP2_MODLEN 128 /* DH group 2, no longer secure */ -#define IKEV2KDF_MAX_GROUP14_MODLEN 256 -#define IKEV2KDF_MAX_GROUP15_MODLEN 384 -#define IKEV2KDF_MAX_GROUP16_MODLEN 512 -#define IKEV2KDF_MAX_GROUP17_MODLEN 768 -#define IKEV2KDF_MAX_GROUP18_MODLEN 1024 -#define IKEV2KDF_MIN_NONCE_LENGTH 8 -#define IKEV2KDF_MAX_NONCE_LENGTH 256 -#define IKEV2KDF_MAX_DKM_LENGTH 2048 - -static OSSL_FUNC_kdf_newctx_fn kdf_ikev2kdf_new; -static OSSL_FUNC_kdf_dupctx_fn kdf_ikev2kdf_dup; -static OSSL_FUNC_kdf_freectx_fn kdf_ikev2kdf_free; -static OSSL_FUNC_kdf_reset_fn kdf_ikev2kdf_reset; -static OSSL_FUNC_kdf_derive_fn kdf_ikev2kdf_derive; -static OSSL_FUNC_kdf_settable_ctx_params_fn kdf_ikev2kdf_settable_ctx_params; -static OSSL_FUNC_kdf_set_ctx_params_fn kdf_ikev2kdf_set_ctx_params; -static OSSL_FUNC_kdf_gettable_ctx_params_fn kdf_ikev2kdf_gettable_ctx_params; -static OSSL_FUNC_kdf_get_ctx_params_fn kdf_ikev2kdf_get_ctx_params; - -static int IKEV2_GEN(OSSL_LIB_CTX *libctx, unsigned char *seedkey, const size_t keylen, - char *md_name, const unsigned char *ni, const size_t ni_len, - const unsigned char *nr, const size_t nr_len, - const unsigned char *shared_secret, const size_t shared_secret_len); -static int IKEV2_REKEY(OSSL_LIB_CTX *libctx, unsigned char *seedkey, const size_t keylen, - char *md_name, const unsigned char *ni, const size_t ni_len, - const unsigned char *nr, const size_t nr_len, - const unsigned char *shared_secret, const size_t shared_secret_len, - const unsigned char *sk_d, const size_t skd_len); -static int IKEV2_DKM(OSSL_LIB_CTX *libctx, unsigned char *dkm, const size_t len_out, - const EVP_MD *evp_md, const unsigned char *seedkey, const size_t seedkey_len, - const unsigned char *ni, const size_t ni_len, - const unsigned char *nr, const size_t nr_len, - const unsigned char *spii, const size_t spii_len, - const unsigned char *spir, const size_t spir_len, - const unsigned char *shared_secret, const size_t shared_secret_len); - -typedef struct { - OSSL_LIB_CTX *libctx; - PROV_DIGEST digest; - uint8_t *secret; - size_t secret_len; - uint8_t *seedkey; - size_t seedkey_len; - uint8_t *ni; - size_t ni_len; - uint8_t *nr; - size_t nr_len; - uint8_t *spii; - size_t spii_len; - uint8_t *spir; - size_t spir_len; - uint8_t *sk_d; - size_t sk_d_len; - int mode; -} KDF_IKEV2KDF; - -static void *kdf_ikev2kdf_new(void *provctx) -{ - KDF_IKEV2KDF *ctx; - - if (!ossl_prov_is_running()) - return NULL; - -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_KDF_IKEV2KDF_GEN)) - return NULL; -#endif - - if ((ctx = OPENSSL_zalloc(sizeof(*ctx))) != NULL) - ctx->libctx = PROV_LIBCTX_OF(provctx); - return ctx; -} - -static void *kdf_ikev2kdf_dup(void *vctx) -{ - KDF_IKEV2KDF *src = (KDF_IKEV2KDF *)vctx; - KDF_IKEV2KDF *dest = NULL; - - dest = OPENSSL_zalloc(sizeof(*src)); - if (dest != NULL) { - dest->libctx = src->libctx; - if ((src->secret != NULL) - && (!ossl_prov_memdup(src->secret, src->secret_len, - &dest->secret, &dest->secret_len))) - goto err; - - if ((src->seedkey != NULL) - && (!ossl_prov_memdup(src->seedkey, src->seedkey_len, - &dest->seedkey, &dest->seedkey_len))) - goto err; - - if ((src->ni != NULL) - && (!ossl_prov_memdup(src->ni, src->ni_len, &dest->ni, &dest->ni_len))) - goto err; - - if ((src->nr != NULL) - && (!ossl_prov_memdup(src->nr, src->nr_len, &dest->nr, &dest->nr_len))) - goto err; - if ((src->spii != NULL) - && (!ossl_prov_memdup(src->spii, src->spii_len, &dest->spii, &dest->spii_len))) - goto err; - if ((src->spir != NULL) - && (!ossl_prov_memdup(src->spir, src->spir_len, &dest->spir, &dest->spir_len))) - goto err; - - if ((src->sk_d != NULL) - && (!ossl_prov_memdup(src->sk_d, src->sk_d_len, - &dest->sk_d, &dest->sk_d_len))) - goto err; - - if (!ossl_prov_digest_copy(&dest->digest, &src->digest)) - goto err; - dest->mode = src->mode; - } - return dest; - -err: - kdf_ikev2kdf_free(dest); - return NULL; -} -static void kdf_ikev2kdf_free(void *vctx) -{ - KDF_IKEV2KDF *ctx = (KDF_IKEV2KDF *)vctx; - - if (ctx != NULL) { - kdf_ikev2kdf_reset(ctx); - OPENSSL_free(ctx); - } -} - -static void kdf_ikev2kdf_reset(void *vctx) -{ - KDF_IKEV2KDF *ctx = (KDF_IKEV2KDF *)vctx; - OSSL_LIB_CTX *libctx = ctx->libctx; - - ossl_prov_digest_reset(&ctx->digest); - OPENSSL_clear_free(ctx->secret, ctx->secret_len); - OPENSSL_clear_free(ctx->seedkey, ctx->seedkey_len); - OPENSSL_clear_free(ctx->sk_d, ctx->sk_d_len); - OPENSSL_clear_free(ctx->ni, ctx->ni_len); - OPENSSL_clear_free(ctx->nr, ctx->nr_len); - OPENSSL_clear_free(ctx->spii, ctx->spii_len); - OPENSSL_clear_free(ctx->spir, ctx->spir_len); - memset(ctx, 0, sizeof(*ctx)); - ctx->libctx = libctx; -} - -static int ikev2kdf_set_membuf(unsigned char **dst, size_t *dst_len, - const OSSL_PARAM *p) -{ - OPENSSL_clear_free(*dst, *dst_len); - *dst = NULL; - *dst_len = 0; - return OSSL_PARAM_get_octet_string(p, (void **)dst, 0, dst_len); -} - -static int ikev2_common_check_ctx_params(KDF_IKEV2KDF *ctx) -{ - if (ctx->ni == NULL) { - ERR_raise(ERR_LIB_PROV, PROV_R_MISSING_NONCE); - return 0; - } - - if (ctx->nr == NULL) { - ERR_raise(ERR_LIB_PROV, PROV_R_MISSING_NONCE); - return 0; - } - return 1; -} - -/* - * RFC 7296: section 2.14 - * g^ir is represented as a string of octets in big endian order padded - * with zeros if necessary to make it the length of the modulus. - * The secret length is in range of 28 ~ 1024 bytes, and the padding length - * is determined by the secret length: - * ecdh group 19 32 bytes - * ecdh group 20 48 bytes - * ecdh group 21 66 bytes - * dh group 2 128 bytes (no longer secure, but still supported for interoperability) - * dh group 14 256 bytes - * dh group 15 384 bytes - * dh group 16 512 bytes - * dh group 17 768 bytes - * dh group 18 1024 bytes - * secret is required for GEN, REKEY and DKM(Child_DH). - */ -static int ikev2_check_secret_and_pad(KDF_IKEV2KDF *ctx) -{ - size_t pad_len = 0; - uint8_t *new_secret = NULL; - - if (ctx->secret_len == 0) - return 1; - if ((ctx->secret_len < IKEV2KDF_MIN_SECRET_LENGTH) - || (ctx->secret_len > IKEV2KDF_MAX_GROUP18_MODLEN)) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_SECRET_LENGTH); - return 0; - } - if ((ctx->secret_len == IKEV2KDF_MAX_GROUP19_MODLEN) - || (ctx->secret_len == IKEV2KDF_MAX_GROUP20_MODLEN) - || (ctx->secret_len == IKEV2KDF_MAX_GROUP21_MODLEN) - || (ctx->secret_len == IKEV2KDF_MAX_GROUP2_MODLEN) - || (ctx->secret_len == IKEV2KDF_MAX_GROUP14_MODLEN) - || (ctx->secret_len == IKEV2KDF_MAX_GROUP15_MODLEN) - || (ctx->secret_len == IKEV2KDF_MAX_GROUP16_MODLEN) - || (ctx->secret_len == IKEV2KDF_MAX_GROUP17_MODLEN) - || (ctx->secret_len == IKEV2KDF_MAX_GROUP18_MODLEN)) - /* no padding needed if secret_len is already valid */ - return 1; - - if (ctx->secret_len < IKEV2KDF_MAX_GROUP19_MODLEN) - pad_len = IKEV2KDF_MAX_GROUP19_MODLEN - ctx->secret_len; - else if ((ctx->secret_len > IKEV2KDF_MAX_GROUP19_MODLEN) - && (ctx->secret_len < IKEV2KDF_MAX_GROUP20_MODLEN)) - pad_len = IKEV2KDF_MAX_GROUP20_MODLEN - ctx->secret_len; - else if ((ctx->secret_len > IKEV2KDF_MAX_GROUP20_MODLEN) - && (ctx->secret_len < IKEV2KDF_MAX_GROUP21_MODLEN)) - pad_len = IKEV2KDF_MAX_GROUP21_MODLEN - ctx->secret_len; - else if ((ctx->secret_len > IKEV2KDF_MAX_GROUP21_MODLEN) - && (ctx->secret_len < IKEV2KDF_MAX_GROUP2_MODLEN)) - pad_len = IKEV2KDF_MAX_GROUP2_MODLEN - ctx->secret_len; - else if ((ctx->secret_len > IKEV2KDF_MAX_GROUP2_MODLEN) - && (ctx->secret_len < IKEV2KDF_MAX_GROUP14_MODLEN)) - pad_len = IKEV2KDF_MAX_GROUP14_MODLEN - ctx->secret_len; - else if ((ctx->secret_len > IKEV2KDF_MAX_GROUP14_MODLEN) - && (ctx->secret_len < IKEV2KDF_MAX_GROUP15_MODLEN)) - pad_len = IKEV2KDF_MAX_GROUP15_MODLEN - ctx->secret_len; - else if ((ctx->secret_len > IKEV2KDF_MAX_GROUP15_MODLEN) - && (ctx->secret_len < IKEV2KDF_MAX_GROUP16_MODLEN)) - pad_len = IKEV2KDF_MAX_GROUP16_MODLEN - ctx->secret_len; - else if ((ctx->secret_len > IKEV2KDF_MAX_GROUP16_MODLEN) - && (ctx->secret_len < IKEV2KDF_MAX_GROUP17_MODLEN)) - pad_len = IKEV2KDF_MAX_GROUP17_MODLEN - ctx->secret_len; - else if (ctx->secret_len > IKEV2KDF_MAX_GROUP17_MODLEN) - pad_len = IKEV2KDF_MAX_GROUP18_MODLEN - ctx->secret_len; - - new_secret = OPENSSL_zalloc(ctx->secret_len + pad_len); - if (new_secret == NULL) { - ERR_raise(ERR_LIB_PROV, ERR_R_MALLOC_FAILURE); - return 0; - } - memcpy(new_secret + pad_len, ctx->secret, ctx->secret_len); - OPENSSL_clear_free(ctx->secret, ctx->secret_len); - ctx->secret = new_secret; - ctx->secret_len += pad_len; - return 1; -} - -static int kdf_ikev2kdf_derive(void *vctx, unsigned char *key, size_t keylen, - const OSSL_PARAM params[]) -{ - KDF_IKEV2KDF *ctx = (KDF_IKEV2KDF *)vctx; - const EVP_MD *md; - size_t md_size; - int value = 0; - - if (!ossl_prov_is_running() || !kdf_ikev2kdf_set_ctx_params(ctx, params)) - return 0; - - md = ossl_prov_digest_md(&ctx->digest); - if (md == NULL) { - ERR_raise(ERR_LIB_PROV, PROV_R_MISSING_MESSAGE_DIGEST); - return 0; - } - value = EVP_MD_size(md); - if (value <= 0) - return 0; - md_size = (size_t)value; - - if (!ikev2_common_check_ctx_params(ctx)) - return 0; - - switch (ctx->mode) { - case EVP_KDF_IKEV2_MODE_GEN: - if ((ctx->secret == NULL) || (ctx->secret_len == 0)) { - ERR_raise(ERR_LIB_PROV, PROV_R_MISSING_SECRET); - return 0; - } - if (keylen != md_size) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); - return 0; - } - if (!ikev2_check_secret_and_pad(ctx)) - return 0; - return (IKEV2_GEN(ctx->libctx, key, keylen, (char *)EVP_MD_name(md), - ctx->ni, ctx->ni_len, ctx->nr, ctx->nr_len, - ctx->secret, ctx->secret_len)); - - case EVP_KDF_IKEV2_MODE_DKM: - /* - * if spi_init != NULL and spi_resp != NULL and shared_secret = NULL - * and seedkey != NULL - * calculate DKM - * else if spi_init == NULL and spi_resp == NULL and shared_secret != NULL - * and sk_d != NULL - * calculate DKM(Child_DH) - * else if spi_init == NULL and spi_resp == NULL and shared_secret == NULL - * and sk_d != NULL - * calculate DKM(Child_SA) - * endif - */ - if ((ctx->spii != NULL) && (ctx->spii_len != 0) - && (ctx->spir != NULL) && (ctx->spir_len != 0) - && (ctx->secret == NULL) && (ctx->secret_len == 0)) { - if ((ctx->seedkey == NULL) || (ctx->seedkey_len == 0)) { - ERR_raise(ERR_LIB_PROV, PROV_R_MISSING_KEY); - return 0; - } - if (ctx->seedkey_len != md_size) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); - return 0; - } - if ((keylen < md_size) || (keylen > IKEV2KDF_MAX_DKM_LENGTH)) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); - return 0; - } - /* calculate DKM */ - return (IKEV2_DKM(ctx->libctx, key, keylen, md, ctx->seedkey, ctx->seedkey_len, - ctx->ni, ctx->ni_len, ctx->nr, ctx->nr_len, - ctx->spii, ctx->spii_len, ctx->spir, ctx->spir_len, - NULL, 0)); - } else if ((ctx->spii == NULL) && (ctx->spir == NULL) - && (ctx->spii_len == 0) && (ctx->spir_len == 0)) { - if ((ctx->sk_d == NULL) || (ctx->sk_d_len == 0)) { - ERR_raise(ERR_LIB_PROV, PROV_R_MISSING_DKM); - return 0; - } - if ((keylen < md_size) || (keylen > IKEV2KDF_MAX_DKM_LENGTH)) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); - return 0; - } - /* If Child_DH is intended, require secret_len > 0 */ - if ((ctx->secret != NULL && ctx->secret_len == 0) - || (ctx->secret == NULL && ctx->secret_len != 0)) { - ERR_raise(ERR_LIB_PROV, PROV_R_MISSING_SECRET); - return 0; - } - if (!ikev2_check_secret_and_pad(ctx)) - return 0; - /* calculate DKM(Child_SA) or DKM(Child_DH) */ - return (IKEV2_DKM(ctx->libctx, key, keylen, md, ctx->sk_d, ctx->sk_d_len, - ctx->ni, ctx->ni_len, ctx->nr, ctx->nr_len, - NULL, 0, NULL, 0, - ctx->secret, ctx->secret_len)); - } else { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_PARAMETERS_FOR_DKM); - return 0; - } - case EVP_KDF_IKEV2_MODE_REKEY: - if ((ctx->secret == NULL) || (ctx->secret_len == 0)) { - ERR_raise(ERR_LIB_PROV, PROV_R_MISSING_SECRET); - return 0; - } - if ((ctx->sk_d == NULL) || (ctx->sk_d_len == 0)) { - ERR_raise(ERR_LIB_PROV, PROV_R_MISSING_DKM); - return 0; - } - if (ctx->sk_d_len != md_size) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); - return 0; - } - if (keylen != md_size) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); - return 0; - } - if (!ikev2_check_secret_and_pad(ctx)) - return 0; - return (IKEV2_REKEY(ctx->libctx, key, keylen, (char *)EVP_MD_name(md), - ctx->ni, ctx->ni_len, ctx->nr, ctx->nr_len, - ctx->secret, ctx->secret_len, ctx->sk_d, ctx->sk_d_len)); - default: - /* This error is already checked in set_ctx_params */ - ; - } - return 0; -} - -static int kdf_ikev2kdf_set_ctx_params(void *vctx, const OSSL_PARAM params[]) -{ - struct ikev2_set_ctx_params_st p; - KDF_IKEV2KDF *ctx = vctx; - const EVP_MD *md; - - if (params == NULL) - return 1; - - if (ctx == NULL || !ikev2_set_ctx_params_decoder(params, &p)) - return 0; - - if (p.digest != NULL) { - if (!ossl_prov_digest_load(&ctx->digest, p.digest, p.propq, ctx->libctx)) - return 0; - md = ossl_prov_digest_md(&ctx->digest); - if (md == NULL) { - ERR_raise(ERR_LIB_PROV, PROV_R_MISSING_MESSAGE_DIGEST); - return 0; - } - - if (!EVP_MD_is_a(md, SN_sha1) - && !EVP_MD_is_a(md, SN_sha224) - && !EVP_MD_is_a(md, SN_sha256) - && !EVP_MD_is_a(md, SN_sha384) - && !EVP_MD_is_a(md, SN_sha512)) - return 0; - } - if (p.ni != NULL) { - if (!ikev2kdf_set_membuf(&ctx->ni, &ctx->ni_len, p.ni)) - return 0; - if ((ctx->ni_len < IKEV2KDF_MIN_NONCE_LENGTH) - || (ctx->ni_len > IKEV2KDF_MAX_NONCE_LENGTH)) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_NONCE_LENGTH); - return 0; - } - } - if (p.nr != NULL) { - if (!ikev2kdf_set_membuf(&ctx->nr, &ctx->nr_len, p.nr)) - return 0; - if ((ctx->nr_len < IKEV2KDF_MIN_NONCE_LENGTH) - || (ctx->nr_len > IKEV2KDF_MAX_NONCE_LENGTH)) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_NONCE_LENGTH); - return 0; - } - } - if (p.spii != NULL) - if (!ikev2kdf_set_membuf(&ctx->spii, &ctx->spii_len, p.spii)) - return 0; - if (p.spir != NULL) - if (!ikev2kdf_set_membuf(&ctx->spir, &ctx->spir_len, p.spir)) - return 0; - if (p.secret != NULL) - if (!ikev2kdf_set_membuf(&ctx->secret, &ctx->secret_len, p.secret)) - return 0; - if (p.seedkey != NULL) - if (!ikev2kdf_set_membuf(&ctx->seedkey, &ctx->seedkey_len, p.seedkey)) - return 0; - if (p.sk_d != NULL) - if (!ikev2kdf_set_membuf(&ctx->sk_d, &ctx->sk_d_len, p.sk_d)) - return 0; - if (p.mode != NULL) { - if (!OSSL_PARAM_get_int(p.mode, &ctx->mode)) - return 0; - if ((ctx->mode != EVP_KDF_IKEV2_MODE_GEN) - && (ctx->mode != EVP_KDF_IKEV2_MODE_DKM) - && (ctx->mode != EVP_KDF_IKEV2_MODE_REKEY)) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_MODE); - return 0; - } - } - return 1; -} - -static const OSSL_PARAM *kdf_ikev2kdf_settable_ctx_params(ossl_unused void *ctx, - ossl_unused void *p_ctx) -{ - return ikev2_set_ctx_params_list; -} - -static int kdf_ikev2kdf_get_ctx_params(void *vctx, OSSL_PARAM params[]) -{ - struct ikev2_get_ctx_params_st p; - KDF_IKEV2KDF *ctx = vctx; - - if (ctx == NULL || !ikev2_get_ctx_params_decoder(params, &p)) - return 0; - - if (p.size != NULL) { - int sz = 0; - const EVP_MD *md = NULL; - - md = ossl_prov_digest_md(&ctx->digest); - if (md == NULL) { - ERR_raise(ERR_LIB_PROV, PROV_R_MISSING_MESSAGE_DIGEST); - return 0; - } - sz = EVP_MD_size(md); - if (sz <= 0) - return 0; - if (!OSSL_PARAM_set_size_t(p.size, (size_t)sz)) - return 0; - } - return 1; -} - -static const OSSL_PARAM *kdf_ikev2kdf_gettable_ctx_params(ossl_unused void *ctx, - ossl_unused void *p_ctx) -{ - return ikev2_get_ctx_params_list; -} - -const OSSL_DISPATCH ossl_kdf_ikev2kdf_functions[] = { - { OSSL_FUNC_KDF_NEWCTX, (void (*)(void))kdf_ikev2kdf_new }, - { OSSL_FUNC_KDF_DUPCTX, (void (*)(void))kdf_ikev2kdf_dup }, - { OSSL_FUNC_KDF_FREECTX, (void (*)(void))kdf_ikev2kdf_free }, - { OSSL_FUNC_KDF_RESET, (void (*)(void))kdf_ikev2kdf_reset }, - { OSSL_FUNC_KDF_DERIVE, (void (*)(void))kdf_ikev2kdf_derive }, - { OSSL_FUNC_KDF_SETTABLE_CTX_PARAMS, - (void (*)(void))kdf_ikev2kdf_settable_ctx_params }, - { OSSL_FUNC_KDF_SET_CTX_PARAMS, (void (*)(void))kdf_ikev2kdf_set_ctx_params }, - { OSSL_FUNC_KDF_GETTABLE_CTX_PARAMS, - (void (*)(void))kdf_ikev2kdf_gettable_ctx_params }, - { OSSL_FUNC_KDF_GET_CTX_PARAMS, (void (*)(void))kdf_ikev2kdf_get_ctx_params }, - { 0, NULL } -}; - -/* - * IKEV2_GEN - KDF in compliance with SP800-135 for IKEv2, - * generate the seedkey. - * - * algorithm: HMAC(ni || nr, shared_secret) - * - * Inputs: - * libctx - provider LIB context - * seedkey - pointer to output for seedkey - * keylen - length of seedkey(in bytes) - * md_name - name of the SHA digest - * ni - pointer to initiator nonce input - * ni_len - initiator nonce length(in bytes) - * nr - pointer to responder nonce input - * nr_len - nonce length(in bytes) - * shared_secret - pointer to secret input - * shared_secret_len - secret length(in bytes) - * Outputs: - * return - 1 pass, 0 fail - * seedkey - output seedkey when passing. - */ -static int IKEV2_GEN(OSSL_LIB_CTX *libctx, unsigned char *seedkey, const size_t keylen, - char *md_name, const unsigned char *ni, const size_t ni_len, - const unsigned char *nr, const size_t nr_len, - const unsigned char *shared_secret, const size_t shared_secret_len) -{ - EVP_MAC_CTX *ctx = NULL; - EVP_MAC *mac = NULL; - size_t outl = 0; - int ret = 0; - unsigned char *nonce = NULL; - OSSL_PARAM params[] = { - OSSL_PARAM_construct_utf8_string("digest", md_name, 0), - OSSL_PARAM_construct_end() - }; - - nonce = OPENSSL_malloc(ni_len + nr_len); - if (nonce == NULL) - return ret; - memcpy(nonce, ni, ni_len); - memcpy(nonce + ni_len, nr, nr_len); - - mac = EVP_MAC_fetch(libctx, (char *)"HMAC", NULL); - if ((mac == NULL) - || ((ctx = EVP_MAC_CTX_new(mac)) == NULL) - || (!EVP_MAC_init(ctx, nonce, ni_len + nr_len, params)) - || (!EVP_MAC_update(ctx, shared_secret, shared_secret_len)) - || (!EVP_MAC_final(ctx, seedkey, &outl, keylen)) - || (outl != keylen)) - goto err; - - ret = 1; -err: - OPENSSL_clear_free(nonce, ni_len + nr_len); - EVP_MAC_CTX_free(ctx); - EVP_MAC_free(mac); - return ret; -} - -/* - * IKEV2_REKEY - KDF in compliance with SP800-135 for IKEv2, - * re-generate the seedkey. - * - * algorithm: HMAC(sk_d, new secret || Ni || Nr ) - * - * Inputs: - * libctx - provider LIB context - * seedkey - pointer to output for seedkey - * keylen - length of seedkey(in bytes) - * md_name - name of the SHA digest - * ni - pointer to initiator nonce input - * ni_len - initiator nonce length(in bytes) - * nr - pointer to responder nonce input - * nr_len - responder nonce length(in bytes) - * shared_secret - (new) pointer to secret input - * shared_secret_len - (new)secret length(in bytes) - * sk_d - pointer to sk_d portion of DKM - * skd_len - length of sk_d (in bytes) - * Outputs: - * return = 1 pass, 0 fail - * seedkey - output seedkey when passing. - */ -static int IKEV2_REKEY(OSSL_LIB_CTX *libctx, unsigned char *seedkey, const size_t keylen, - char *md_name, const unsigned char *ni, const size_t ni_len, - const unsigned char *nr, const size_t nr_len, - const unsigned char *shared_secret, const size_t shared_secret_len, - const unsigned char *sk_d, const size_t sk_d_len) -{ - EVP_MAC_CTX *ctx = NULL; - EVP_MAC *mac = NULL; - size_t outl = 0; - int ret = 0; - OSSL_PARAM params[] = { - OSSL_PARAM_construct_utf8_string("digest", md_name, 0), - OSSL_PARAM_construct_end() - }; - - mac = EVP_MAC_fetch(libctx, "HMAC", NULL); - if ((mac == NULL) - || ((ctx = EVP_MAC_CTX_new(mac)) == NULL) - || (!EVP_MAC_init(ctx, sk_d, sk_d_len, params)) - || (!EVP_MAC_update(ctx, shared_secret, shared_secret_len)) - || (!EVP_MAC_update(ctx, ni, ni_len)) - || (!EVP_MAC_update(ctx, nr, nr_len)) - || (!EVP_MAC_final(ctx, seedkey, &outl, keylen)) - || (outl != keylen)) - goto err; - - ret = 1; - -err: - EVP_MAC_CTX_free(ctx); - EVP_MAC_free(mac); - return ret; -} - -/* - * IKEV2_DKM - KDF in compliance with SP800-135 for IKEv2, - * generate the Derived Keying Material(DKM), - * DKM(Child SA) and DKM(Child SA DH). - * algorithm: - * if spii != NULL and spir != NULL and shared_secret == NULL - * and seedkey != NULL - * calculate DKM: - * HMAC(seedkey, ni || nr || spii || spir) - * else if spii == NULL and spir == NULL and shared_secret == NULL - * calculate DKM(Child_SA): - * HMAC(sk_d, ni || nr) - * else if spii == NULL and spir == NULL and shared_secret != NULL - * calculate DKM(Child_DH): - * HMAC(sk_d, ni || nr || new_shared_secret) - * endif - * - * Inputs: - * libctx - provider LIB context - * dkm - pointer to output dkm - * len_out - output length(in bytes) - * evp_md - pointer to SHA digest - * seekkey - pointer to seedkey (seekkey for DKM, sk_d for Child_SA/DH) - * seedkey_len - length of seedkey(in bytes) - * ni - pointer to initiator nonce - * ni_len - initiator nonce length(in bytes) - * nr - pointer to responder nonce - * nr_len - responder nonce length(in bytes) - * shared_secret - pointer to secret input - * shared_secret_len - secret length(in bytes) - * Outputs: - * return - 1 pass, 0 fail - * dkm - output dkm when passing. - */ -static int IKEV2_DKM(OSSL_LIB_CTX *libctx, unsigned char *dkm, const size_t len_out, - const EVP_MD *evp_md, - const unsigned char *seedkey, const size_t seedkey_len, - const unsigned char *ni, const size_t ni_len, - const unsigned char *nr, const size_t nr_len, - const unsigned char *spii, const size_t spii_len, - const unsigned char *spir, const size_t spir_len, - const unsigned char *shared_secret, const size_t shared_secret_len) -{ - EVP_MAC_CTX *ctx = NULL; - EVP_MAC *mac = NULL; - size_t outl = 0, hmac_len = 0, ii; - unsigned char *hmac = NULL; - int ret = 0; - size_t md_size = 0; - int value = 0; - unsigned char counter = 1; - OSSL_PARAM params[] = { - OSSL_PARAM_construct_utf8_string("digest", (char *)EVP_MD_name(evp_md), 0), - OSSL_PARAM_construct_end() - }; - - value = EVP_MD_size(evp_md); - if (value <= 0) - return 0; - md_size = (size_t)value; - /* len_out may not fit the last hmac, round up */ - hmac_len = ((len_out + md_size - 1) / md_size) * md_size; - hmac = OPENSSL_malloc(hmac_len); - if (hmac == NULL) - return 0; - - mac = EVP_MAC_fetch(libctx, "HMAC", NULL); - if ((mac == NULL) - || ((ctx = EVP_MAC_CTX_new(mac)) == NULL)) - goto err; - - /* - * len_out <= IKEV2_MAX_DKM_LEN - * loop count will fit in 1 byte value - */ - for (ii = 0; ii < len_out; ii += md_size) { - if (!EVP_MAC_init(ctx, seedkey, seedkey_len, params)) - goto err; - if (ii != 0) - if (!EVP_MAC_update(ctx, &hmac[ii - md_size], md_size)) - goto err; - if (shared_secret != NULL) - if (!EVP_MAC_update(ctx, shared_secret, shared_secret_len)) - goto err; - if (!EVP_MAC_update(ctx, ni, ni_len) - || !EVP_MAC_update(ctx, nr, nr_len)) - goto err; - if (spii != NULL) - if (!EVP_MAC_update(ctx, spii, spii_len) - || !EVP_MAC_update(ctx, spir, spir_len)) - goto err; - if (!EVP_MAC_update(ctx, &counter, 1)) - goto err; - if (!EVP_MAC_final(ctx, &hmac[ii], &outl, md_size)) - goto err; - counter++; - } - - memcpy(dkm, hmac, len_out); - ret = 1; -err: - OPENSSL_clear_free(hmac, hmac_len); - EVP_MAC_CTX_free(ctx); - EVP_MAC_free(mac); - return ret; -} diff --git a/providers/implementations/kdfs/ikev2kdf.inc.in b/providers/implementations/kdfs/ikev2kdf.inc.in deleted file mode 100644 index 9f1dc5782a..0000000000 --- a/providers/implementations/kdfs/ikev2kdf.inc.in +++ /dev/null @@ -1,29 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the \"License\"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -{- -use OpenSSL::paramnames qw(produce_param_decoder); --} - -{- produce_param_decoder('ikev2_set_ctx_params', - (['OSSL_KDF_PARAM_PROPERTIES', 'propq', 'utf8_string'], - ['OSSL_KDF_PARAM_DIGEST', 'digest', 'utf8_string'], - ['OSSL_KDF_PARAM_IKEV2KDF_NI', 'ni', 'octet_string'], - ['OSSL_KDF_PARAM_IKEV2KDF_NR', 'nr', 'octet_string'], - ['OSSL_KDF_PARAM_IKEV2KDF_SPII', 'spii', 'octet_string'], - ['OSSL_KDF_PARAM_IKEV2KDF_SPIR', 'spir', 'octet_string'], - ['OSSL_KDF_PARAM_SEED', 'seedkey', 'octet_string'], - ['OSSL_KDF_PARAM_KEY', 'sk_d', 'octet_string'], - ['OSSL_KDF_PARAM_SECRET', 'secret', 'octet_string'], - ['OSSL_KDF_PARAM_MODE', 'mode', 'int32'], - )); -} - -{- produce_param_decoder('ikev2_get_ctx_params', - (['OSSL_KDF_PARAM_SIZE', 'size', 'size_t'], - )); -} diff --git a/providers/implementations/kdfs/kbkdf.c b/providers/implementations/kdfs/kbkdf.c index 100d010966..d51fb5d4fc 100644 --- a/providers/implementations/kdfs/kbkdf.c +++ b/providers/implementations/kdfs/kbkdf.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright 2019 Red Hat, Inc. * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -45,7 +45,6 @@ #include "prov/providercommon.h" #include "prov/securitycheck.h" #include "internal/e_os.h" -#include "internal/fips.h" #include "internal/params.h" #define ossl_min(a, b) ((a) < (b)) ? (a) : (b) @@ -123,12 +122,6 @@ static void *kbkdf_new(void *provctx) if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_KDF_KBKDF)) - return NULL; -#endif - ctx = OPENSSL_zalloc(sizeof(*ctx)); if (ctx == NULL) return NULL; @@ -205,7 +198,7 @@ static int fips_kbkdf_key_check_passed(KBKDF *ctx) if (!key_approved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE0, libctx, "KBKDF", "Key size", - FIPS_CONFIG_KBKDF_KEY_CHECK)) { + ossl_fips_config_kbkdf_key_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); return 0; } diff --git a/providers/implementations/kdfs/pbkdf2.c b/providers/implementations/kdfs/pbkdf2.c index e1f67cecbc..7f7b38beb2 100644 --- a/providers/implementations/kdfs/pbkdf2.c +++ b/providers/implementations/kdfs/pbkdf2.c @@ -1,5 +1,5 @@ /* - * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2018-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -22,7 +22,6 @@ #include #include #include "internal/cryptlib.h" -#include "internal/fips.h" #include "internal/numbers.h" #include "crypto/evp.h" #include "prov/provider_ctx.h" @@ -57,7 +56,6 @@ #ifndef KDF_PBKDF2_MIN_PASSWORD_LEN #ifdef FIPS_MODULE #define KDF_PBKDF2_MIN_PASSWORD_LEN (8) -#define KDF_PBKDF2_FIPS_SELF_TEST_ITERATIONS 2 #else #define KDF_PBKDF2_MIN_PASSWORD_LEN (1) #endif @@ -99,12 +97,6 @@ static void *kdf_pbkdf2_new_no_init(void *provctx) if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_KDF_PBKDF2)) - return NULL; -#endif - ctx = OPENSSL_zalloc(sizeof(*ctx)); if (ctx == NULL) return NULL; @@ -218,8 +210,6 @@ static int pbkdf2_lower_bound_check_passed(int saltlen, uint64_t iter, size_t keylen, size_t passlen, int *error, const char **desc) { - uint64_t min_iter = KDF_PBKDF2_MIN_ITERATIONS; - if (passlen < KDF_PBKDF2_MIN_PASSWORD_LEN) { *error = PROV_R_PASSWORD_STRENGTH_TOO_WEAK; if (desc != NULL) @@ -238,13 +228,7 @@ static int pbkdf2_lower_bound_check_passed(int saltlen, uint64_t iter, *desc = "Salt size"; return 0; } -#ifdef FIPS_MODULE - /* Modify this check during self-test. See FIPS 140-3 IG 10.3.A.8 */ - if (ossl_self_test_in_progress(ST_ID_KDF_PBKDF2)) { - min_iter = KDF_PBKDF2_FIPS_SELF_TEST_ITERATIONS; - } -#endif - if (iter < min_iter) { + if (iter < KDF_PBKDF2_MIN_ITERATIONS) { *error = PROV_R_INVALID_ITERATION_COUNT; if (desc != NULL) *desc = "Iteration count"; @@ -268,7 +252,7 @@ static int fips_lower_bound_check_passed(KDF_PBKDF2 *ctx, int saltlen, if (!approved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE0, libctx, "PBKDF2", desc, - FIPS_CONFIG_PBKDF2_LOWER_BOUND_CHECK)) { + ossl_fips_config_pbkdf2_lower_bound_check)) { ERR_raise(ERR_LIB_PROV, error); return 0; } @@ -366,9 +350,7 @@ static int kdf_pbkdf2_set_ctx_params(void *vctx, const OSSL_PARAM params[]) if (p.pw != NULL) { if (ctx->lower_bound_checks != 0 && p.pw->data_size < KDF_PBKDF2_MIN_PASSWORD_LEN) { - ERR_raise_data(ERR_LIB_PROV, PROV_R_PASSWORD_STRENGTH_TOO_WEAK, - "password length %zu should be at least %d", - p.pw->data_size, KDF_PBKDF2_MIN_PASSWORD_LEN); + ERR_raise(ERR_LIB_PROV, PROV_R_PASSWORD_STRENGTH_TOO_WEAK); return 0; } if (!pbkdf2_set_membuf(&ctx->pass, &ctx->pass_len, p.pw)) diff --git a/providers/implementations/kdfs/pkcs12kdf.c b/providers/implementations/kdfs/pkcs12kdf.c index b7e60c7b68..b3e414f7cd 100644 --- a/providers/implementations/kdfs/pkcs12kdf.c +++ b/providers/implementations/kdfs/pkcs12kdf.c @@ -1,5 +1,5 @@ /* - * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -267,15 +267,6 @@ static int kdf_pkcs12_set_ctx_params(void *vctx, const OSSL_PARAM params[]) if (p.iter != NULL && !OSSL_PARAM_get_uint64(p.iter, &ctx->iter)) return 0; -#ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION - /* - * If we're running the fuzzer, limit iteration count to - * 100 so we don't time out running the derivation for - * a really long time - */ - if (getenv("OPENSSL_RUNNING_UNIT_TESTS") == NULL && p.iter != NULL && ctx->iter > 100) - ctx->iter = 100; -#endif return 1; } diff --git a/providers/implementations/kdfs/snmpkdf.c b/providers/implementations/kdfs/snmpkdf.c index e857abc1e8..9a55b90b33 100644 --- a/providers/implementations/kdfs/snmpkdf.c +++ b/providers/implementations/kdfs/snmpkdf.c @@ -1,5 +1,5 @@ /* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -7,13 +7,17 @@ * https://www.openssl.org/source/license.html */ +#include +#include +#include #include #include #include #include #include #include "internal/cryptlib.h" -#include "internal/fips.h" +#include "internal/numbers.h" +#include "crypto/evp.h" #include "prov/provider_ctx.h" #include "prov/providercommon.h" #include "prov/implementations.h" @@ -21,7 +25,7 @@ #include "providers/implementations/kdfs/snmpkdf.inc" #define KDF_SNMP_PASSWORD_HASH_AMOUNT (1024 * 1024) -#define KDF_SNMP_MIN_PASSWORD_LEN 8 +#define KDF_SNMP_MIN_PASSWORD_LEN 8 /* See RFC 3414, Appendix A.2.2 */ /* See NIST SP800-135 Section 6.8 */ @@ -36,9 +40,9 @@ static OSSL_FUNC_kdf_gettable_ctx_params_fn kdf_snmpkdf_gettable_ctx_params; static OSSL_FUNC_kdf_get_ctx_params_fn kdf_snmpkdf_get_ctx_params; static int SNMPKDF(const EVP_MD *evp_md, - const unsigned char *eid, size_t eid_len, - unsigned char *password, size_t password_len, - unsigned char *key, size_t keylen); + const unsigned char *eid, size_t eid_len, + unsigned char *password, size_t password_len, + unsigned char *key, size_t keylen); typedef struct { /* Warning: Any changes to this structure may require you to update kdf_snmpkdf_dup */ @@ -57,12 +61,6 @@ static void *kdf_snmpkdf_new(void *provctx) if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_KDF_SNMPKDF)) - return NULL; -#endif - if ((ctx = OPENSSL_zalloc(sizeof(*ctx))) != NULL) ctx->provctx = provctx; return ctx; @@ -76,15 +74,15 @@ static void *kdf_snmpkdf_dup(void *vctx) dest = kdf_snmpkdf_new(src->provctx); if (dest != NULL) { if (!ossl_prov_memdup(src->eid, src->eid_len, - &dest->eid, &dest->eid_len) - || !ossl_prov_memdup(src->password, src->password_len, - &dest->password, &dest->password_len) - || !ossl_prov_digest_copy(&dest->digest, &src->digest)) + &dest->eid, &dest->eid_len) + || !ossl_prov_memdup(src->password, src->password_len, + &dest->password, &dest->password_len) + || !ossl_prov_digest_copy(&dest->digest, &src->digest)) goto err; } return dest; -err: + err: kdf_snmpkdf_free(dest); return NULL; } @@ -112,7 +110,7 @@ static void kdf_snmpkdf_reset(void *vctx) } static int snmpkdf_set_membuf(unsigned char **dst, size_t *dst_len, - const OSSL_PARAM *p) + const OSSL_PARAM *p) { OPENSSL_clear_free(*dst, *dst_len); *dst = NULL; @@ -121,7 +119,7 @@ static int snmpkdf_set_membuf(unsigned char **dst, size_t *dst_len, } static int kdf_snmpkdf_derive(void *vctx, unsigned char *key, size_t keylen, - const OSSL_PARAM params[]) + const OSSL_PARAM params[]) { KDF_SNMPKDF *ctx = (KDF_SNMPKDF *)vctx; const EVP_MD *md; @@ -144,15 +142,15 @@ static int kdf_snmpkdf_derive(void *vctx, unsigned char *key, size_t keylen, } return SNMPKDF(md, ctx->eid, ctx->eid_len, - ctx->password, ctx->password_len, - key, keylen); + ctx->password, ctx->password_len, + key, keylen); } static int kdf_snmpkdf_set_ctx_params(void *vctx, const OSSL_PARAM params[]) { struct snmp_set_ctx_params_st p; KDF_SNMPKDF *ctx = vctx; - OSSL_LIB_CTX *libctx; + OSSL_LIB_CTX *libctx = PROV_LIBCTX_OF(ctx->provctx); #ifdef FIPS_MODULE const EVP_MD *md = NULL; #endif @@ -163,17 +161,12 @@ static int kdf_snmpkdf_set_ctx_params(void *vctx, const OSSL_PARAM params[]) if (ctx == NULL || !snmp_set_ctx_params_decoder(params, &p)) return 0; - libctx = PROV_LIBCTX_OF(ctx->provctx); if (p.digest != NULL) { if (!ossl_prov_digest_load(&ctx->digest, p.digest, p.propq, libctx)) return 0; #ifdef FIPS_MODULE md = ossl_prov_digest_md(&ctx->digest); - if (!EVP_MD_is_a(md, SN_sha1) - && !EVP_MD_is_a(md, SN_sha224) - && !EVP_MD_is_a(md, SN_sha256) - && !EVP_MD_is_a(md, SN_sha384) - && !EVP_MD_is_a(md, SN_sha512)) + if (!EVP_MD_is_a(md, SN_sha1)) return 0; #endif } @@ -181,7 +174,8 @@ static int kdf_snmpkdf_set_ctx_params(void *vctx, const OSSL_PARAM params[]) if (p.pw != NULL) { if (!snmpkdf_set_membuf(&ctx->password, &ctx->password_len, p.pw)) return 0; - if ((ctx->password_len > KDF_SNMP_PASSWORD_HASH_AMOUNT) || (ctx->password_len < KDF_SNMP_MIN_PASSWORD_LEN)) + if ((ctx->password_len > KDF_SNMP_PASSWORD_HASH_AMOUNT) || + (ctx->password_len < KDF_SNMP_MIN_PASSWORD_LEN)) return 0; } @@ -192,7 +186,7 @@ static int kdf_snmpkdf_set_ctx_params(void *vctx, const OSSL_PARAM params[]) } static const OSSL_PARAM *kdf_snmpkdf_settable_ctx_params(ossl_unused void *ctx, - ossl_unused void *p_ctx) + ossl_unused void *p_ctx) { return snmp_set_ctx_params_list; } @@ -231,23 +225,23 @@ static int kdf_snmpkdf_get_ctx_params(void *vctx, OSSL_PARAM params[]) } static const OSSL_PARAM *kdf_snmpkdf_gettable_ctx_params(ossl_unused void *ctx, - ossl_unused void *p_ctx) + ossl_unused void *p_ctx) { return snmp_get_ctx_params_list; } const OSSL_DISPATCH ossl_kdf_snmpkdf_functions[] = { - { OSSL_FUNC_KDF_NEWCTX, (void (*)(void))kdf_snmpkdf_new }, - { OSSL_FUNC_KDF_DUPCTX, (void (*)(void))kdf_snmpkdf_dup }, - { OSSL_FUNC_KDF_FREECTX, (void (*)(void))kdf_snmpkdf_free }, - { OSSL_FUNC_KDF_RESET, (void (*)(void))kdf_snmpkdf_reset }, - { OSSL_FUNC_KDF_DERIVE, (void (*)(void))kdf_snmpkdf_derive }, + { OSSL_FUNC_KDF_NEWCTX, (void(*)(void))kdf_snmpkdf_new }, + { OSSL_FUNC_KDF_DUPCTX, (void(*)(void))kdf_snmpkdf_dup }, + { OSSL_FUNC_KDF_FREECTX, (void(*)(void))kdf_snmpkdf_free }, + { OSSL_FUNC_KDF_RESET, (void(*)(void))kdf_snmpkdf_reset }, + { OSSL_FUNC_KDF_DERIVE, (void(*)(void))kdf_snmpkdf_derive }, { OSSL_FUNC_KDF_SETTABLE_CTX_PARAMS, - (void (*)(void))kdf_snmpkdf_settable_ctx_params }, - { OSSL_FUNC_KDF_SET_CTX_PARAMS, (void (*)(void))kdf_snmpkdf_set_ctx_params }, + (void(*)(void))kdf_snmpkdf_settable_ctx_params }, + { OSSL_FUNC_KDF_SET_CTX_PARAMS, (void(*)(void))kdf_snmpkdf_set_ctx_params }, { OSSL_FUNC_KDF_GETTABLE_CTX_PARAMS, - (void (*)(void))kdf_snmpkdf_gettable_ctx_params }, - { OSSL_FUNC_KDF_GET_CTX_PARAMS, (void (*)(void))kdf_snmpkdf_get_ctx_params }, + (void(*)(void))kdf_snmpkdf_gettable_ctx_params }, + { OSSL_FUNC_KDF_GET_CTX_PARAMS, (void(*)(void))kdf_snmpkdf_get_ctx_params }, { 0, NULL } }; @@ -271,31 +265,27 @@ const OSSL_DISPATCH ossl_kdf_snmpkdf_functions[] = { * * Shared_key = SHA-1(Derived_password || snmpEngineID || Derived_password). * - * Input: * e_id - engine ID(eid) * e_len - engineID length * password - password * password_len - password length * okey - pointer to key output, FIPS testing limited to SHA-1. - * keylen - key length - * Output: - * okey - filled with derived key - * return - 1 on pass, 0 fail + * okeylen - key output length + * return - 1 pass 0 for error */ static int SNMPKDF(const EVP_MD *evp_md, - const unsigned char *e_id, size_t e_len, - unsigned char *password, size_t password_len, - unsigned char *okey, size_t keylen) + const unsigned char *e_id, size_t e_len, + unsigned char *password, size_t password_len, + unsigned char *okey, size_t okeylen) { EVP_MD_CTX *md = NULL; unsigned char digest[EVP_MAX_MD_SIZE]; size_t mdsize = 0, len = 0; unsigned int md_len = 0; int ret = 0; - int value = 0; /* Limited to SHA-1 and SHA-2 hashes presently */ - if (okey == NULL || keylen == 0) + if (okey == NULL || okeylen == 0) return 0; md = EVP_MD_CTX_new(); @@ -304,10 +294,9 @@ static int SNMPKDF(const EVP_MD *evp_md, goto err; } - value = EVP_MD_get_size(evp_md); - if (value <= 0 || (size_t)value > keylen) + mdsize = EVP_MD_get_size(evp_md); + if (mdsize <= 0 || mdsize < okeylen) goto err; - mdsize = (size_t)value; if (!EVP_DigestInit_ex(md, evp_md, NULL)) goto err; @@ -326,7 +315,7 @@ static int SNMPKDF(const EVP_MD *evp_md, || !EVP_DigestFinal_ex(md, digest, &md_len)) goto err; - memcpy(okey, digest, (keylen < md_len) ? keylen : md_len); + memcpy(okey, digest, okeylen); ret = 1; diff --git a/providers/implementations/kdfs/srtpkdf.c b/providers/implementations/kdfs/srtpkdf.c deleted file mode 100644 index 4ae77aedee..0000000000 --- a/providers/implementations/kdfs/srtpkdf.c +++ /dev/null @@ -1,489 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include -#include -#include -#include -#include -#include "internal/cryptlib.h" -#include "internal/fips.h" -#include "prov/provider_ctx.h" -#include "prov/providercommon.h" -#include "prov/implementations.h" -#include "prov/provider_util.h" -#include "providers/implementations/kdfs/srtpkdf.inc" - -#define KDF_SRTP_AUTH_KEY_LEN 20 -#define KDF_SRTP_SALT_KEY_LEN 14 -#define KDF_SRTCP_AUTH_KEY_LEN KDF_SRTP_AUTH_KEY_LEN -#define KDF_SRTCP_SALT_KEY_LEN KDF_SRTP_SALT_KEY_LEN -#define KDF_SRTP_SALT_LEN 14 -#define KDF_SRTP_KDR_LEN 6 -#define KDF_SRTP_IDX_LEN 6 -#define KDF_SRTCP_IDX_LEN 4 -#define KDF_SRTP_IV_LEN 16 -#define KDF_SRTP_MAX_KDR 24 -#define KDF_SRTP_MAX_LABEL 7 -#define KDF_SRTP_MAX_SALT_LEN (KDF_SRTP_SALT_LEN + 2) - -/* See RFC 3711, Section 4.3.3 */ -static OSSL_FUNC_kdf_newctx_fn kdf_srtpkdf_new; -static OSSL_FUNC_kdf_dupctx_fn kdf_srtpkdf_dup; -static OSSL_FUNC_kdf_freectx_fn kdf_srtpkdf_free; -static OSSL_FUNC_kdf_reset_fn kdf_srtpkdf_reset; -static OSSL_FUNC_kdf_derive_fn kdf_srtpkdf_derive; -static OSSL_FUNC_kdf_settable_ctx_params_fn kdf_srtpkdf_settable_ctx_params; -static OSSL_FUNC_kdf_set_ctx_params_fn kdf_srtpkdf_set_ctx_params; -static OSSL_FUNC_kdf_gettable_ctx_params_fn kdf_srtpkdf_gettable_ctx_params; -static OSSL_FUNC_kdf_get_ctx_params_fn kdf_srtpkdf_get_ctx_params; - -static int SRTPKDF(OSSL_LIB_CTX *provctx, const EVP_CIPHER *cipher, - const uint8_t *mkey, const uint8_t *msalt, - const uint8_t *index, size_t index_len, - const uint32_t kdr, const uint32_t kdr_n, - const uint32_t label, uint8_t *obuffer, const size_t keylen); - -typedef struct { - /* Warning: Any changes to this structure may require you to update kdf_srtpkdf_dup */ - void *provctx; - PROV_CIPHER cipher; - unsigned char *key; - size_t key_len; - unsigned char *salt; - size_t salt_len; - unsigned char *index; - size_t index_len; - uint32_t kdr; - uint32_t kdr_n; /* 2 ** kdr_n = kdr */ - uint32_t label; -} KDF_SRTPKDF; - -static void *kdf_srtpkdf_new(void *provctx) -{ - KDF_SRTPKDF *ctx; - - if (!ossl_prov_is_running()) - return NULL; - -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_KDF_SRTPKDF)) - return NULL; -#endif - - if ((ctx = OPENSSL_zalloc(sizeof(*ctx))) != NULL) - ctx->provctx = provctx; - return ctx; -} - -static void *kdf_srtpkdf_dup(void *vsrc) -{ - const KDF_SRTPKDF *src = (const KDF_SRTPKDF *)vsrc; - KDF_SRTPKDF *dest; - - dest = kdf_srtpkdf_new(src->provctx); - if (dest != NULL) { - if (!ossl_prov_memdup(src->key, src->key_len, - &dest->key, &dest->key_len) - || !ossl_prov_memdup(src->salt, src->salt_len, - &dest->salt, &dest->salt_len) - || !ossl_prov_memdup(src->index, src->index_len, - &dest->index, &dest->index_len) - || !ossl_prov_cipher_copy(&dest->cipher, &src->cipher)) - goto err; - dest->kdr = src->kdr; - dest->kdr_n = src->kdr_n; - dest->label = src->label; - } - return dest; - -err: - kdf_srtpkdf_free(dest); - return NULL; -} - -static void kdf_srtpkdf_free(void *vctx) -{ - KDF_SRTPKDF *ctx = (KDF_SRTPKDF *)vctx; - - if (ctx != NULL) { - kdf_srtpkdf_reset(ctx); - OPENSSL_free(ctx); - } -} - -static void kdf_srtpkdf_reset(void *vctx) -{ - KDF_SRTPKDF *ctx = (KDF_SRTPKDF *)vctx; - void *provctx = ctx->provctx; - - ossl_prov_cipher_reset(&ctx->cipher); - OPENSSL_clear_free(ctx->key, ctx->key_len); - OPENSSL_clear_free(ctx->index, ctx->index_len); - OPENSSL_clear_free(ctx->salt, ctx->salt_len); - memset(ctx, 0, sizeof(*ctx)); - ctx->provctx = provctx; -} - -static int srtpkdf_set_membuf(unsigned char **dst, size_t *dst_len, - const OSSL_PARAM *p) -{ - OPENSSL_clear_free(*dst, *dst_len); - *dst = NULL; - *dst_len = 0; - return OSSL_PARAM_get_octet_string(p, (void **)dst, 0, dst_len); -} - -static int is_power_of_two(uint32_t x, uint32_t *n) -{ - /* Check if we've been given an exact power of two */ - if (x == 0 || (x & (x - 1)) != 0) { - *n = 0; - return 0; - } - /* Count the number of trailing bits in the passed value */ -#ifdef __GNUC__ - *n = __builtin_ctz(x); -#else - { - uint32_t count = 0; - while ((x & 1) == 0) { - count++; - x >>= 1; - } - *n = count; - } -#endif - return 1; -} - -static int kdf_srtpkdf_check_key(KDF_SRTPKDF *ctx) -{ - const EVP_CIPHER *cipher = ossl_prov_cipher_cipher(&ctx->cipher); - - if (cipher != NULL) { - if (ctx->key == NULL) { - ERR_raise(ERR_LIB_PROV, PROV_R_MISSING_KEY); - return 0; - } - if (ctx->key_len != (size_t)EVP_CIPHER_get_key_length(cipher)) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); - return 0; - } - } - return 1; -} - -static int kdf_srtpkdf_derive(void *vctx, unsigned char *key, size_t keylen, - const OSSL_PARAM params[]) -{ - KDF_SRTPKDF *ctx = (KDF_SRTPKDF *)vctx; - const EVP_CIPHER *cipher; - OSSL_LIB_CTX *libctx; - - if (!ossl_prov_is_running() || !kdf_srtpkdf_set_ctx_params(ctx, params)) - return 0; - - libctx = PROV_LIBCTX_OF(ctx->provctx); - - cipher = ossl_prov_cipher_cipher(&ctx->cipher); - if (cipher == NULL) { - ERR_raise(ERR_LIB_PROV, PROV_R_MISSING_CIPHER); - return 0; - } - if (!kdf_srtpkdf_check_key(ctx)) - return 0; - if (ctx->salt == NULL) { - ERR_raise(ERR_LIB_PROV, PROV_R_MISSING_SALT); - return 0; - } - return SRTPKDF(libctx, cipher, ctx->key, ctx->salt, - ctx->index, ctx->index_len, ctx->kdr, ctx->kdr_n, ctx->label, - key, keylen); -} - -static int kdf_srtpkdf_set_ctx_params(void *vctx, const OSSL_PARAM params[]) -{ - struct srtp_set_ctx_params_st p; - KDF_SRTPKDF *ctx = vctx; - OSSL_LIB_CTX *libctx; - - if (params == NULL) - return 1; - - if (ctx == NULL || !srtp_set_ctx_params_decoder(params, &p)) - return 0; - - libctx = PROV_LIBCTX_OF(ctx->provctx); - - if (p.cipher != NULL) { - const EVP_CIPHER *cipher = NULL; - - if (!ossl_prov_cipher_load(&ctx->cipher, p.cipher, p.propq, libctx)) - return 0; - cipher = ossl_prov_cipher_cipher(&ctx->cipher); - if (cipher == NULL) - return 0; - if (!EVP_CIPHER_is_a(cipher, "AES-128-CTR") - && !EVP_CIPHER_is_a(cipher, "AES-192-CTR") - && !EVP_CIPHER_is_a(cipher, "AES-256-CTR")) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_CIPHER); - return 0; - } - } - if (p.key != NULL) { - if (!srtpkdf_set_membuf(&ctx->key, &ctx->key_len, p.key)) - return 0; - if (!kdf_srtpkdf_check_key(ctx)) - return 0; - } - if (p.salt != NULL) { - if (!srtpkdf_set_membuf(&ctx->salt, &ctx->salt_len, p.salt)) - return 0; - if (ctx->salt_len < KDF_SRTP_SALT_LEN) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_SALT_LENGTH); - return 0; - } - } - if (p.kdr != NULL) { - if (!OSSL_PARAM_get_uint32(p.kdr, &ctx->kdr)) - return 0; - if (ctx->kdr > 0) { - uint32_t n = 0; - - if (!is_power_of_two(ctx->kdr, &n) - || n > KDF_SRTP_MAX_KDR) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KDR); - return 0; - } - ctx->kdr_n = n; - } - } - - if (p.label != NULL) { - if (!OSSL_PARAM_get_uint32(p.label, &ctx->label)) - return 0; - if (ctx->label > KDF_SRTP_MAX_LABEL) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_LABEL); - return 0; - } - } - if (p.index != NULL) { - if (!srtpkdf_set_membuf(&ctx->index, &ctx->index_len, p.index)) - return 0; - /* - * Defer checking the index until the derive() since it is dependant - * on values of kdr and label. - */ - } - - return 1; -} - -static const OSSL_PARAM *kdf_srtpkdf_settable_ctx_params(ossl_unused void *ctx, - ossl_unused void *p_ctx) -{ - return srtp_set_ctx_params_list; -} - -static int kdf_srtpkdf_get_ctx_params(void *vctx, OSSL_PARAM params[]) -{ - struct srtp_get_ctx_params_st p; - KDF_SRTPKDF *ctx = vctx; - - if (ctx == NULL || !srtp_get_ctx_params_decoder(params, &p)) - return 0; - - if (p.size != NULL) { - size_t sz = EVP_CIPHER_key_length(ossl_prov_cipher_cipher(&ctx->cipher)); - - if (!OSSL_PARAM_set_size_t(p.size, sz)) - return 0; - } - return 1; -} - -static const OSSL_PARAM *kdf_srtpkdf_gettable_ctx_params(ossl_unused void *ctx, - ossl_unused void *p_ctx) -{ - return srtp_get_ctx_params_list; -} - -const OSSL_DISPATCH ossl_kdf_srtpkdf_functions[] = { - { OSSL_FUNC_KDF_NEWCTX, (void (*)(void))kdf_srtpkdf_new }, - { OSSL_FUNC_KDF_DUPCTX, (void (*)(void))kdf_srtpkdf_dup }, - { OSSL_FUNC_KDF_FREECTX, (void (*)(void))kdf_srtpkdf_free }, - { OSSL_FUNC_KDF_RESET, (void (*)(void))kdf_srtpkdf_reset }, - { OSSL_FUNC_KDF_DERIVE, (void (*)(void))kdf_srtpkdf_derive }, - { OSSL_FUNC_KDF_SETTABLE_CTX_PARAMS, - (void (*)(void))kdf_srtpkdf_settable_ctx_params }, - { OSSL_FUNC_KDF_SET_CTX_PARAMS, - (void (*)(void))kdf_srtpkdf_set_ctx_params }, - { OSSL_FUNC_KDF_GETTABLE_CTX_PARAMS, - (void (*)(void))kdf_srtpkdf_gettable_ctx_params }, - { OSSL_FUNC_KDF_GET_CTX_PARAMS, - (void (*)(void))kdf_srtpkdf_get_ctx_params }, - { 0, NULL } -}; - -static bool is_srtp(uint32_t label) -{ - static const bool strp_table[] = { - true, /* 0 */ - true, /* 1 */ - true, /* 2 */ - false, /* 3 */ - false, /* 4 */ - false, /* 5 */ - true, /* 6 */ - true, /* 7 */ - }; - return strp_table[label]; -} - -/* - * SRTPKDF - In compliance with SP800-135 and RFC3711, calculate - * various keys defined by label using a master key, - * master salt, kdr(if non-zero) and index. - * - * Denote the cryptographic key (encryption key, cipher salt or - * authentication key(HMAC key), etc) to be derived as K. The - * length of K is denoted by L. Below is a description of the KDF. - * - * master_salt: a random non-salt value. - * kdr: the key derivation rate. kdr is a number from the set - * factor of 2. - * index: a 48-bit value in RTP or a 32-bit value in RTCP. - * See Sections 3.2.1 and 4.3.2 of RFC 3711 for details. - * A function, DIV, is defined as followed: - * a and x are non-negative integers. - * a DIV x = a | x (a DIV x) is represented as a bit string whose - * length (in bits) is the same as a. - * label: an 8-bit value represented by two hexadecimal numbers from - * the set of {0x00,0x01, 0x02, 0x03, 0x04, 0x05}. - * https://www.ietf.org/archive/id/draft-ietf-avtcore-srtp-encrypted-header-ext-01.html - * The values 06 and 07 are used. - * key_id = label || (index DIV kdr) - * - * Input: - * cipher - AES cipher - * mkey - pointer to master key - * msalt - pointer to master salt - * index - pointer to index - * idxlen - size of the index buffer - * kdr - key derivation rate - * kdr_n - power of kdr (2**kdr_n = kdr) - * label - 8-bit label - * keylen - size of obuffer - * Output: - * obuffer - filled with derived key - * return - 1 on pass, 0 fail - */ -int SRTPKDF(OSSL_LIB_CTX *provctx, const EVP_CIPHER *cipher, - const uint8_t *mkey, const uint8_t *msalt, - const uint8_t *index, size_t idxlen, - const uint32_t kdr, const uint32_t kdr_n, - const uint32_t label, uint8_t *obuffer, const size_t keylen) -{ - EVP_CIPHER_CTX *ctx = NULL; - int outl, i, index_len = 0, o_len = 0, salt_len = 0; - uint8_t buf[EVP_MAX_KEY_LENGTH]; - uint8_t iv[KDF_SRTP_IV_LEN]; - uint8_t local_salt[KDF_SRTP_MAX_SALT_LEN]; - uint8_t master_salt[KDF_SRTP_MAX_SALT_LEN]; - BIGNUM *bn_index = NULL, *bn_salt = NULL; - int ret, iv_len = KDF_SRTP_IV_LEN, rv = 0; - - if (obuffer == NULL || keylen > INT_MAX) - return rv; - /* get label-specific lengths */ - switch (label) { - case 0: - case 3: - case 6: - o_len = EVP_CIPHER_key_length(cipher); - break; - case 1: - o_len = KDF_SRTP_AUTH_KEY_LEN; - break; - case 4: - o_len = KDF_SRTCP_AUTH_KEY_LEN; - break; - case 2: - case 7: - o_len = KDF_SRTP_SALT_KEY_LEN; - break; - case 5: - o_len = KDF_SRTCP_SALT_KEY_LEN; - break; - default: - return rv; - } - if (o_len > (int)keylen) - return rv; - - /* set up a couple of work areas for the final logic on the salt */ - salt_len = KDF_SRTP_SALT_LEN; - memset(iv, 0, KDF_SRTP_IV_LEN); - memset(master_salt, 0, sizeof(master_salt)); - memcpy(master_salt, msalt, salt_len); - - /* gather some bignums for some math */ - bn_index = BN_new(); - bn_salt = BN_new(); - if ((bn_index == NULL) || (bn_salt == NULL)) { - BN_free(bn_index); - BN_free(bn_salt); - return rv; - } - - index_len = is_srtp(label) ? KDF_SRTP_IDX_LEN : KDF_SRTCP_IDX_LEN; - /* if index is NULL or kdr=0, then index and kdr are not in play */ - if (index != NULL && idxlen > 0 && kdr > 0) { - if ((int)idxlen < index_len) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_INDEX_LENGTH); - goto err; - } - if (!BN_bin2bn(index, index_len, bn_index)) - goto err; - - ret = BN_rshift(bn_salt, bn_index, kdr_n); - if (!ret) - goto err; - iv_len = BN_bn2bin(bn_salt, iv); - for (i = 1; i <= iv_len; i++) - master_salt[salt_len - i] ^= iv[iv_len - i]; - } - - /* take the munged up salt from above and add the label */ - memset(local_salt, 0, KDF_SRTP_MAX_SALT_LEN); - memcpy(local_salt, master_salt, salt_len); - local_salt[((KDF_SRTP_SALT_LEN - 1) - index_len)] ^= label; - - /* perform the AES encryption on the master key and derived salt */ - memset(buf, 0, o_len); - if (!(ctx = EVP_CIPHER_CTX_new()) - || (EVP_EncryptInit_ex(ctx, cipher, NULL, mkey, local_salt) <= 0) - || (EVP_CIPHER_CTX_set_padding(ctx, 0) <= 0) - || (EVP_EncryptUpdate(ctx, (unsigned char *)obuffer, &outl, buf, o_len) <= 0) - || (EVP_EncryptFinal_ex(ctx, (unsigned char *)obuffer, &outl) <= 0)) - goto err; - - rv = 1; -err: - EVP_CIPHER_CTX_free(ctx); - OPENSSL_cleanse(iv, KDF_SRTP_IV_LEN); - OPENSSL_cleanse(local_salt, KDF_SRTP_MAX_SALT_LEN); - OPENSSL_cleanse(master_salt, KDF_SRTP_IV_LEN); - BN_clear_free(bn_index); - BN_clear_free(bn_salt); - return rv; -} diff --git a/providers/implementations/kdfs/srtpkdf.inc.in b/providers/implementations/kdfs/srtpkdf.inc.in deleted file mode 100644 index 0cf5ec15a3..0000000000 --- a/providers/implementations/kdfs/srtpkdf.inc.in +++ /dev/null @@ -1,26 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the \"License\"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -{- -use OpenSSL::paramnames qw(produce_param_decoder); --} - -{- produce_param_decoder('srtp_set_ctx_params', - (['OSSL_KDF_PARAM_PROPERTIES', 'propq', 'utf8_string'], - ['OSSL_KDF_PARAM_CIPHER', 'cipher', 'utf8_string'], - ['OSSL_KDF_PARAM_KEY', 'key', 'octet_string'], - ['OSSL_KDF_PARAM_SALT', 'salt', 'octet_string'], - ['OSSL_KDF_PARAM_SRTPKDF_INDEX', 'index', 'octet_string'], - ['OSSL_KDF_PARAM_SRTPKDF_KDR', 'kdr', 'uint32'], - ['OSSL_KDF_PARAM_LABEL', 'label', 'uint32'], - )); -} - -{- produce_param_decoder('srtp_get_ctx_params', - (['OSSL_KDF_PARAM_SIZE', 'size', 'size_t'], - )); -} diff --git a/providers/implementations/kdfs/sshkdf.c b/providers/implementations/kdfs/sshkdf.c index ee2f75a7c2..b9432d72d5 100644 --- a/providers/implementations/kdfs/sshkdf.c +++ b/providers/implementations/kdfs/sshkdf.c @@ -1,5 +1,5 @@ /* - * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2018-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -15,7 +15,6 @@ #include #include #include "internal/cryptlib.h" -#include "internal/fips.h" #include "internal/numbers.h" #include "crypto/evp.h" #include "prov/provider_ctx.h" @@ -62,16 +61,6 @@ static void *kdf_sshkdf_new(void *provctx) if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - /* - * Normally we'd want a call to ossl_deferred_self_test() here, but - * according to FIPS 140-3 10.3.A Note18: SSH KDF is not required, since - * it is sufficient to self-test the underlying SHA hash functions. - * The underlying hash functions are implicitly tested when the hash is - * instantiated, so we do not need to have an explicit test here. - */ -#endif - if ((ctx = OPENSSL_zalloc(sizeof(*ctx))) != NULL) { ctx->provctx = provctx; OSSL_FIPS_IND_INIT(ctx) @@ -156,7 +145,7 @@ static int fips_digest_check_passed(KDF_SSHKDF *ctx, const EVP_MD *md) if (digest_unapproved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE0, libctx, "SSHKDF", "Digest", - FIPS_CONFIG_SSHKDF_DIGEST_CHECK)) { + ossl_fips_config_sshkdf_digest_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_DIGEST_NOT_ALLOWED); return 0; } @@ -172,7 +161,7 @@ static int fips_key_check_passed(KDF_SSHKDF *ctx) if (!key_approved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE1, libctx, "SSHKDF", "Key size", - FIPS_CONFIG_SSHKDF_KEY_CHECK)) { + ossl_fips_config_sshkdf_key_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); return 0; } diff --git a/providers/implementations/kdfs/sskdf.c b/providers/implementations/kdfs/sskdf.c index 572ef4134f..25b619e248 100644 --- a/providers/implementations/kdfs/sskdf.c +++ b/providers/implementations/kdfs/sskdf.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2019, Oracle and/or its affiliates. All rights reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -44,7 +44,6 @@ #include #include #include "internal/cryptlib.h" -#include "internal/fips.h" #include "internal/numbers.h" #include "crypto/evp.h" #include "prov/provider_ctx.h" @@ -54,9 +53,6 @@ #include "prov/securitycheck.h" #include "internal/params.h" -#define SSKDF_MAX_INLEN (1 << 30) -#define SSKDF_MAX_INFOS 5 - typedef struct { void *provctx; EVP_MAC_CTX *macctx; /* H(x) = HMAC_hash OR H(x) = KMAC */ @@ -72,55 +68,28 @@ typedef struct { OSSL_FIPS_IND_DECLARE } KDF_SSKDF; -struct sskdf_all_set_ctx_params_st { - OSSL_PARAM *secret; - OSSL_PARAM *propq; - OSSL_PARAM *digest; - OSSL_PARAM *mac; - OSSL_PARAM *salt; - OSSL_PARAM *size; -#ifdef FIPS_MODULE - OSSL_PARAM *ind_k; - OSSL_PARAM *ind_d; -#endif - OSSL_PARAM *info[SSKDF_MAX_INFOS]; - int num_info; -}; - -static OSSL_FUNC_kdf_newctx_fn sskdf_common_new; -#ifndef OPENSSL_NO_SSKDF -static OSSL_FUNC_kdf_newctx_fn sskdf_new; -#endif -#ifndef OPENSSL_NO_X963KDF -static OSSL_FUNC_kdf_newctx_fn x963_new; -#endif -static OSSL_FUNC_kdf_dupctx_fn sskdf_dup; -static OSSL_FUNC_kdf_freectx_fn sskdf_free; -static OSSL_FUNC_kdf_reset_fn sskdf_reset; - -#ifndef OPENSSL_NO_SSKDF +#define SSKDF_MAX_INLEN (1 << 30) #define SSKDF_KMAC128_DEFAULT_SALT_SIZE (168 - 4) #define SSKDF_KMAC256_DEFAULT_SALT_SIZE (136 - 4) + +#define SSKDF_MAX_INFOS 5 + /* KMAC uses a Customisation string of 'KDF' */ static const unsigned char kmac_custom_str[] = { 0x4B, 0x44, 0x46 }; +static OSSL_FUNC_kdf_newctx_fn sskdf_new; +static OSSL_FUNC_kdf_dupctx_fn sskdf_dup; +static OSSL_FUNC_kdf_freectx_fn sskdf_free; +static OSSL_FUNC_kdf_reset_fn sskdf_reset; static OSSL_FUNC_kdf_derive_fn sskdf_derive; static OSSL_FUNC_kdf_settable_ctx_params_fn sskdf_settable_ctx_params; static OSSL_FUNC_kdf_set_ctx_params_fn sskdf_set_ctx_params; -static OSSL_FUNC_kdf_gettable_ctx_params_fn sskdf_gettable_ctx_params; -static OSSL_FUNC_kdf_get_ctx_params_fn sskdf_get_ctx_params; -#define sskdf_set_ctx_params_st sskdf_all_set_ctx_params_st -#include "providers/implementations/kdfs/sskdf.inc" -#endif -#ifndef OPENSSL_NO_X963KDF +static OSSL_FUNC_kdf_gettable_ctx_params_fn sskdf_common_gettable_ctx_params; +static OSSL_FUNC_kdf_get_ctx_params_fn sskdf_common_get_ctx_params; static OSSL_FUNC_kdf_derive_fn x963kdf_derive; static OSSL_FUNC_kdf_settable_ctx_params_fn x963kdf_settable_ctx_params; static OSSL_FUNC_kdf_set_ctx_params_fn x963kdf_set_ctx_params; -static OSSL_FUNC_kdf_gettable_ctx_params_fn x963kdf_gettable_ctx_params; -static OSSL_FUNC_kdf_get_ctx_params_fn x963kdf_get_ctx_params; -#define x963kdf_set_ctx_params_st sskdf_all_set_ctx_params_st -#include "providers/implementations/kdfs/x963kdf.inc" -#endif + /* * Refer to https://csrc.nist.gov/publications/detail/sp/800-56c/rev-1/final * Section 4. One-Step Key Derivation using H(x) = hash(x) @@ -195,7 +164,6 @@ end: return ret; } -#ifndef OPENSSL_NO_SSKDF static int kmac_init(EVP_MAC_CTX *ctx, const unsigned char *custom, size_t custom_len, size_t kmac_out_len, size_t derived_key_len, unsigned char **out) @@ -322,9 +290,8 @@ end: EVP_MAC_CTX_free(ctx); return ret; } -#endif /* OPENSSL_NO_SSKDF */ -static void *sskdf_common_new(void *provctx) +static void *sskdf_new(void *provctx) { KDF_SSKDF *ctx; @@ -338,32 +305,6 @@ static void *sskdf_common_new(void *provctx) return ctx; } -#ifndef OPENSSL_NO_SSKDF -static void *sskdf_new(void *provctx) -{ -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_KDF_SSKDF)) - return NULL; -#endif - - return sskdf_common_new(provctx); -} -#endif - -#ifndef OPENSSL_NO_X963KDF -static void *x963_new(void *provctx) -{ -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_KDF_X963KDF)) - return NULL; -#endif - - return sskdf_common_new(provctx); -} -#endif - static void sskdf_reset(void *vctx) { KDF_SSKDF *ctx = (KDF_SSKDF *)vctx; @@ -393,7 +334,7 @@ static void *sskdf_dup(void *vctx) const KDF_SSKDF *src = (const KDF_SSKDF *)vctx; KDF_SSKDF *dest; - dest = sskdf_common_new(src->provctx); + dest = sskdf_new(src->provctx); if (dest != NULL) { if (src->macctx != NULL) { dest->macctx = EVP_MAC_CTX_dup(src->macctx); @@ -436,7 +377,6 @@ static size_t sskdf_size(KDF_SSKDF *ctx) return (len <= 0) ? 0 : (size_t)len; } -#ifndef OPENSSL_NO_SSKDF #ifdef FIPS_MODULE static int fips_sskdf_key_check_passed(KDF_SSKDF *ctx) { @@ -446,14 +386,14 @@ static int fips_sskdf_key_check_passed(KDF_SSKDF *ctx) if (!key_approved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE0, libctx, "SSKDF", "Key size", - FIPS_CONFIG_SSKDF_KEY_CHECK)) { + ossl_fips_config_sskdf_key_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); return 0; } } return 1; } -#endif /* FIPS_MODULE */ +#endif static int sskdf_derive(void *vctx, unsigned char *key, size_t keylen, const OSSL_PARAM params[]) @@ -522,9 +462,7 @@ static int sskdf_derive(void *vctx, unsigned char *key, size_t keylen, ctx->info, ctx->info_len, 0, key, keylen); } } -#endif -#ifndef OPENSSL_NO_X963KDF #ifdef FIPS_MODULE static int fips_x963kdf_digest_check_passed(KDF_SSKDF *ctx, const EVP_MD *md) { @@ -541,7 +479,7 @@ static int fips_x963kdf_digest_check_passed(KDF_SSKDF *ctx, const EVP_MD *md) if (digest_unapproved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE0, libctx, "X963KDF", "Digest", - FIPS_CONFIG_X963KDF_DIGEST_CHECK)) { + ossl_fips_config_x963kdf_digest_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_DIGEST_NOT_ALLOWED); return 0; } @@ -557,14 +495,14 @@ static int fips_x963kdf_key_check_passed(KDF_SSKDF *ctx) if (!key_approved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE1, libctx, "X963KDF", "Key size", - FIPS_CONFIG_X963KDF_KEY_CHECK)) { + ossl_fips_config_x963kdf_key_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); return 0; } } return 1; } -#endif /* FIPS_MODULE */ +#endif static int x963kdf_derive(void *vctx, unsigned char *key, size_t keylen, const OSSL_PARAM params[]) @@ -595,16 +533,48 @@ static int x963kdf_derive(void *vctx, unsigned char *key, size_t keylen, return SSKDF_hash_kdm(md, ctx->secret, ctx->secret_len, ctx->info, ctx->info_len, 1, key, keylen); } -#endif /* OPENSSL_NO_X963KDF */ + +struct sskdf_all_set_ctx_params_st { + OSSL_PARAM *secret; + OSSL_PARAM *propq; + OSSL_PARAM *digest; + OSSL_PARAM *mac; + OSSL_PARAM *salt; + OSSL_PARAM *size; +#ifdef FIPS_MODULE + OSSL_PARAM *ind_k; + OSSL_PARAM *ind_d; +#endif + OSSL_PARAM *info[SSKDF_MAX_INFOS]; + int num_info; +}; + +#define sskdf_set_ctx_params_st sskdf_all_set_ctx_params_st +#define x963kdf_set_ctx_params_st sskdf_all_set_ctx_params_st + +#include "providers/implementations/kdfs/sskdf.inc" static int sskdf_common_set_ctx_params(KDF_SSKDF *ctx, struct sskdf_all_set_ctx_params_st *p, - const OSSL_PARAM *params, OSSL_LIB_CTX *libctx) + const OSSL_PARAM *params) { - + OSSL_LIB_CTX *libctx = PROV_LIBCTX_OF(ctx->provctx); const EVP_MD *md = NULL; size_t sz; int r; + if (!ossl_prov_macctx_load(&ctx->macctx, + p->mac, NULL, p->digest, p->propq, + NULL, NULL, NULL, libctx)) + return 0; + if (ctx->macctx != NULL) { + if (EVP_MAC_is_a(EVP_MAC_CTX_get0_mac(ctx->macctx), + OSSL_MAC_NAME_KMAC128) + || EVP_MAC_is_a(EVP_MAC_CTX_get0_mac(ctx->macctx), + OSSL_MAC_NAME_KMAC256)) { + ctx->is_kmac = 1; + } + } + if (p->digest != NULL) { if (!ossl_prov_digest_load(&ctx->digest, p->digest, p->propq, libctx)) return 0; @@ -626,6 +596,11 @@ static int sskdf_common_set_ctx_params(KDF_SSKDF *ctx, struct sskdf_all_set_ctx_ == 0) return 0; + if (ossl_param_get1_octet_string_from_param(p->salt, &ctx->salt, + &ctx->salt_len) + == 0) + return 0; + if (p->size != NULL) { if (!OSSL_PARAM_get_size_t(p->size, &sz) || sz == 0) return 0; @@ -634,11 +609,9 @@ static int sskdf_common_set_ctx_params(KDF_SSKDF *ctx, struct sskdf_all_set_ctx_ return 1; } -#ifndef OPENSSL_NO_SSKDF static int sskdf_set_ctx_params(void *vctx, const OSSL_PARAM params[]) { KDF_SSKDF *ctx = (KDF_SSKDF *)vctx; - OSSL_LIB_CTX *libctx; struct sskdf_all_set_ctx_params_st p; if (ctx == NULL || !sskdf_set_ctx_params_decoder(params, &p)) @@ -647,24 +620,7 @@ static int sskdf_set_ctx_params(void *vctx, const OSSL_PARAM params[]) if (!OSSL_FIPS_IND_SET_CTX_FROM_PARAM(ctx, OSSL_FIPS_IND_SETTABLE0, p.ind_k)) return 0; - libctx = PROV_LIBCTX_OF(ctx->provctx); - if (!ossl_prov_macctx_load(&ctx->macctx, - p.mac, NULL, p.digest, p.propq, - NULL, NULL, NULL, libctx)) - return 0; - if (ctx->macctx != NULL) { - if (EVP_MAC_is_a(EVP_MAC_CTX_get0_mac(ctx->macctx), - OSSL_MAC_NAME_KMAC128) - || EVP_MAC_is_a(EVP_MAC_CTX_get0_mac(ctx->macctx), - OSSL_MAC_NAME_KMAC256)) { - ctx->is_kmac = 1; - } - } - if (ossl_param_get1_octet_string_from_param(p.salt, &ctx->salt, - &ctx->salt_len) - == 0) - return 0; - if (!sskdf_common_set_ctx_params(ctx, &p, params, libctx)) + if (!sskdf_common_set_ctx_params(ctx, &p, params)) return 0; #ifdef FIPS_MODULE @@ -682,7 +638,7 @@ static const OSSL_PARAM *sskdf_settable_ctx_params(ossl_unused void *ctx, return sskdf_set_ctx_params_list; } -static int sskdf_get_ctx_params(void *vctx, OSSL_PARAM params[]) +static int sskdf_common_get_ctx_params(void *vctx, OSSL_PARAM params[]) { KDF_SSKDF *ctx = (KDF_SSKDF *)vctx; struct sskdf_get_ctx_params_st p; @@ -701,14 +657,11 @@ static int sskdf_get_ctx_params(void *vctx, OSSL_PARAM params[]) return 1; } -static const OSSL_PARAM *sskdf_gettable_ctx_params(ossl_unused void *ctx, ossl_unused void *provctx) +static const OSSL_PARAM *sskdf_common_gettable_ctx_params(ossl_unused void *ctx, ossl_unused void *provctx) { return sskdf_get_ctx_params_list; } -#endif /* OPENSSL_NO_SSKDF */ - -#ifndef OPENSSL_NO_X963KDF static int x963kdf_set_ctx_params(void *vctx, const OSSL_PARAM params[]) { KDF_SSKDF *ctx = (KDF_SSKDF *)vctx; @@ -722,7 +675,7 @@ static int x963kdf_set_ctx_params(void *vctx, const OSSL_PARAM params[]) if (!OSSL_FIPS_IND_SET_CTX_FROM_PARAM(ctx, OSSL_FIPS_IND_SETTABLE1, p.ind_k)) return 0; - if (!sskdf_common_set_ctx_params(ctx, &p, params, PROV_LIBCTX_OF(ctx->provctx))) + if (!sskdf_common_set_ctx_params(ctx, &p, params)) return 0; #ifdef FIPS_MODULE @@ -747,33 +700,6 @@ static const OSSL_PARAM *x963kdf_settable_ctx_params(ossl_unused void *ctx, return x963kdf_set_ctx_params_list; } -static int x963kdf_get_ctx_params(void *vctx, OSSL_PARAM params[]) -{ - KDF_SSKDF *ctx = (KDF_SSKDF *)vctx; - struct x963kdf_get_ctx_params_st p; - - if (ctx == NULL || !x963kdf_get_ctx_params_decoder(params, &p)) - return 0; - - if (p.size != NULL) { - if (!OSSL_PARAM_set_size_t(p.size, sskdf_size(ctx))) - return 0; - } - - if (!OSSL_FIPS_IND_GET_CTX_PARAM(ctx, p.ind)) - return 0; - - return 1; -} - -static const OSSL_PARAM *x963kdf_gettable_ctx_params(ossl_unused void *ctx, ossl_unused void *provctx) -{ - return x963kdf_get_ctx_params_list; -} - -#endif /* OPENSSL_NO_X963KDF */ - -#ifndef OPENSSL_NO_SSKDF const OSSL_DISPATCH ossl_kdf_sskdf_functions[] = { { OSSL_FUNC_KDF_NEWCTX, (void (*)(void))sskdf_new }, { OSSL_FUNC_KDF_DUPCTX, (void (*)(void))sskdf_dup }, @@ -784,15 +710,13 @@ const OSSL_DISPATCH ossl_kdf_sskdf_functions[] = { (void (*)(void))sskdf_settable_ctx_params }, { OSSL_FUNC_KDF_SET_CTX_PARAMS, (void (*)(void))sskdf_set_ctx_params }, { OSSL_FUNC_KDF_GETTABLE_CTX_PARAMS, - (void (*)(void))sskdf_gettable_ctx_params }, - { OSSL_FUNC_KDF_GET_CTX_PARAMS, (void (*)(void))sskdf_get_ctx_params }, + (void (*)(void))sskdf_common_gettable_ctx_params }, + { OSSL_FUNC_KDF_GET_CTX_PARAMS, (void (*)(void))sskdf_common_get_ctx_params }, OSSL_DISPATCH_END }; -#endif -#ifndef OPENSSL_NO_X963KDF const OSSL_DISPATCH ossl_kdf_x963_kdf_functions[] = { - { OSSL_FUNC_KDF_NEWCTX, (void (*)(void))x963_new }, + { OSSL_FUNC_KDF_NEWCTX, (void (*)(void))sskdf_new }, { OSSL_FUNC_KDF_DUPCTX, (void (*)(void))sskdf_dup }, { OSSL_FUNC_KDF_FREECTX, (void (*)(void))sskdf_free }, { OSSL_FUNC_KDF_RESET, (void (*)(void))sskdf_reset }, @@ -801,8 +725,7 @@ const OSSL_DISPATCH ossl_kdf_x963_kdf_functions[] = { (void (*)(void))x963kdf_settable_ctx_params }, { OSSL_FUNC_KDF_SET_CTX_PARAMS, (void (*)(void))x963kdf_set_ctx_params }, { OSSL_FUNC_KDF_GETTABLE_CTX_PARAMS, - (void (*)(void))x963kdf_gettable_ctx_params }, - { OSSL_FUNC_KDF_GET_CTX_PARAMS, (void (*)(void))x963kdf_get_ctx_params }, + (void (*)(void))sskdf_common_gettable_ctx_params }, + { OSSL_FUNC_KDF_GET_CTX_PARAMS, (void (*)(void))sskdf_common_get_ctx_params }, OSSL_DISPATCH_END }; -#endif diff --git a/providers/implementations/kdfs/sskdf.inc.in b/providers/implementations/kdfs/sskdf.inc.in index fdf451acc0..059e179445 100644 --- a/providers/implementations/kdfs/sskdf.inc.in +++ b/providers/implementations/kdfs/sskdf.inc.in @@ -1,5 +1,5 @@ /* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the \"License\"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -27,3 +27,16 @@ use OpenSSL::paramnames qw(produce_param_decoder); (['OSSL_KDF_PARAM_SIZE', 'size', 'size_t'], ['OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR', 'ind', 'int', 'fips'], )); -} + +{- produce_param_decoder('x963kdf_set_ctx_params', + (['OSSL_KDF_PARAM_SECRET', 'secret', 'octet_string'], + ['OSSL_KDF_PARAM_KEY', 'secret', 'octet_string'], + ['OSSL_KDF_PARAM_INFO', 'info', 'octet_string', SSKDF_MAX_INFOS], + ['OSSL_KDF_PARAM_PROPERTIES', 'propq', 'utf8_string'], + ['OSSL_KDF_PARAM_DIGEST', 'digest', 'utf8_string'], + ['OSSL_KDF_PARAM_MAC', 'mac', 'utf8_string'], + ['OSSL_KDF_PARAM_SALT', 'salt', 'octet_string'], + ['OSSL_KDF_PARAM_MAC_SIZE', 'size', 'size_t'], + ['OSSL_KDF_PARAM_FIPS_DIGEST_CHECK', 'ind_d', 'int', 'fips'], + ['OSSL_KDF_PARAM_FIPS_KEY_CHECK', 'ind_k', 'int', 'fips'], + )); -} diff --git a/providers/implementations/kdfs/tls1_prf.c b/providers/implementations/kdfs/tls1_prf.c index 07fcdd058e..13bc4d890a 100644 --- a/providers/implementations/kdfs/tls1_prf.c +++ b/providers/implementations/kdfs/tls1_prf.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -69,7 +69,6 @@ #include "prov/provider_util.h" #include "prov/securitycheck.h" #include "internal/e_os.h" -#include "internal/fips.h" #include "internal/params.h" #include "internal/safe_math.h" @@ -123,12 +122,6 @@ static void *kdf_tls1_prf_new(void *provctx) if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_KDF_TLS12_PRF)) - return NULL; -#endif - if ((ctx = OPENSSL_zalloc(sizeof(*ctx))) != NULL) { ctx->provctx = provctx; OSSL_FIPS_IND_INIT(ctx) @@ -207,7 +200,7 @@ static int fips_ems_check_passed(TLS1_PRF *ctx) if (!ems_approved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE0, libctx, "TLS_PRF", "EMS", - FIPS_CONFIG_TLS1_PRF_EMS_CHECK)) { + ossl_fips_config_tls1_prf_ems_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_EMS_NOT_ENABLED); return 0; } @@ -232,7 +225,7 @@ static int fips_digest_check_passed(TLS1_PRF *ctx, const EVP_MD *md) if (digest_unapproved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE1, libctx, "TLS_PRF", "Digest", - FIPS_CONFIG_TLS1_PRF_DIGEST_CHECK)) { + ossl_fips_config_tls1_prf_digest_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_DIGEST_NOT_ALLOWED); return 0; } @@ -248,7 +241,7 @@ static int fips_key_check_passed(TLS1_PRF *ctx) if (!key_approved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE2, libctx, "TLS_PRF", "Key size", - FIPS_CONFIG_TLS1_PRF_KEY_CHECK)) { + ossl_fips_config_tls1_prf_key_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); return 0; } @@ -332,7 +325,6 @@ static int kdf_tls1_prf_set_ctx_params(void *vctx, const OSSL_PARAM params[]) return 0; } else { EVP_MAC_CTX_free(ctx->P_sha1); - ctx->P_sha1 = NULL; if (!ossl_prov_macctx_load(&ctx->P_hash, NULL, NULL, p.digest, p.propq, OSSL_MAC_NAME_HMAC, NULL, NULL, libctx)) diff --git a/providers/implementations/kdfs/x942kdf.c b/providers/implementations/kdfs/x942kdf.c index 3565243cc9..5d17914e74 100644 --- a/providers/implementations/kdfs/x942kdf.c +++ b/providers/implementations/kdfs/x942kdf.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2019, Oracle and/or its affiliates. All rights reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -18,7 +18,6 @@ #include "internal/common.h" #include "internal/packet.h" #include "internal/der.h" -#include "internal/fips.h" #include "internal/nelem.h" #include "prov/provider_ctx.h" #include "prov/providercommon.h" @@ -340,12 +339,6 @@ static void *x942kdf_new(void *provctx) if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_KDF_X942KDF)) - return NULL; -#endif - ctx = OPENSSL_zalloc(sizeof(*ctx)); if (ctx == NULL) return NULL; @@ -452,7 +445,7 @@ static int fips_x942kdf_key_check_passed(KDF_X942 *ctx) if (!key_approved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE0, libctx, "X942KDF", "Key size", - FIPS_CONFIG_X942KDF_KEY_CHECK)) { + ossl_fips_config_x942kdf_key_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); return 0; } diff --git a/providers/implementations/kdfs/x963kdf.inc.in b/providers/implementations/kdfs/x963kdf.inc.in deleted file mode 100644 index e50efb2bd8..0000000000 --- a/providers/implementations/kdfs/x963kdf.inc.in +++ /dev/null @@ -1,27 +0,0 @@ -/* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the \"License\"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -{- -use OpenSSL::paramnames qw(produce_param_decoder); --} - -{- produce_param_decoder('x963kdf_get_ctx_params', - (['OSSL_KDF_PARAM_SIZE', 'size', 'size_t'], - ['OSSL_KDF_PARAM_FIPS_APPROVED_INDICATOR', 'ind', 'int', 'fips'], - )); -} - -{- produce_param_decoder('x963kdf_set_ctx_params', - (['OSSL_KDF_PARAM_SECRET', 'secret', 'octet_string'], - ['OSSL_KDF_PARAM_KEY', 'secret', 'octet_string'], - ['OSSL_KDF_PARAM_INFO', 'info', 'octet_string', SSKDF_MAX_INFOS], - ['OSSL_KDF_PARAM_PROPERTIES', 'propq', 'utf8_string'], - ['OSSL_KDF_PARAM_DIGEST', 'digest', 'utf8_string'], - ['OSSL_KDF_PARAM_FIPS_DIGEST_CHECK', 'ind_d', 'int', 'fips'], - ['OSSL_KDF_PARAM_FIPS_KEY_CHECK', 'ind_k', 'int', 'fips'], - )); -} diff --git a/providers/implementations/kem/ml_kem_kem.c b/providers/implementations/kem/ml_kem_kem.c index df3bcb5cd8..fea8b5b692 100644 --- a/providers/implementations/kem/ml_kem_kem.c +++ b/providers/implementations/kem/ml_kem_kem.c @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -17,7 +17,6 @@ #include #include "crypto/ml_kem.h" #include "internal/cryptlib.h" -#include "internal/fips.h" #include "prov/provider_ctx.h" #include "prov/implementations.h" #include "prov/securitycheck.h" @@ -47,12 +46,6 @@ static void *ml_kem_newctx(void *provctx) if ((ctx = OPENSSL_malloc(sizeof(*ctx))) == NULL) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_KEM_ML_KEM)) - return NULL; -#endif - ctx->key = NULL; ctx->entropy = NULL; ctx->op = 0; diff --git a/providers/implementations/kem/rsa_kem.c b/providers/implementations/kem/rsa_kem.c index ab28a3a1a2..169cc098c5 100644 --- a/providers/implementations/kem/rsa_kem.c +++ b/providers/implementations/kem/rsa_kem.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -23,7 +23,6 @@ #include #include "crypto/rsa.h" #include "internal/cryptlib.h" -#include "internal/fips.h" #include "prov/provider_ctx.h" #include "prov/providercommon.h" #include "prov/implementations.h" @@ -91,12 +90,6 @@ static void *rsakem_newctx(void *provctx) if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_ASYM_CIPHER_RSA_ENC)) - return NULL; -#endif - prsactx = OPENSSL_zalloc(sizeof(PROV_RSA_CTX)); if (prsactx == NULL) return NULL; @@ -315,17 +308,16 @@ static int rsasve_generate(PROV_RSA_CTX *prsactx, /* Step(3): out = RSAEP((n,e), z) */ ret = RSA_public_encrypt((int)nlen, secret, out, prsactx->rsa, RSA_NO_PADDING); - if (ret <= 0 || ret != (int)nlen) { + if (ret) { + ret = 1; + if (outlen != NULL) + *outlen = nlen; + if (secretlen != NULL) + *secretlen = nlen; + } else { OPENSSL_cleanse(secret, nlen); - return 0; } - - if (outlen != NULL) - *outlen = nlen; - if (secretlen != NULL) - *secretlen = nlen; - - return 1; + return ret; } /** diff --git a/providers/implementations/kem/template_kem.c b/providers/implementations/kem/template_kem.c index 448b1caf4e..509a31e129 100644 --- a/providers/implementations/kem/template_kem.c +++ b/providers/implementations/kem/template_kem.c @@ -166,7 +166,7 @@ static int template_decapsulate(void *vctx, unsigned char *out, size_t *outlen, if (out == NULL) { if (outlen != NULL) - debug_print("decaps outlen set to %zu\n", *outlen); + debug_print("decaps outlen set to %zu \n", *outlen); return 1; } diff --git a/providers/implementations/keymgmt/build.info b/providers/implementations/keymgmt/build.info index 347904c7e7..4522125350 100644 --- a/providers/implementations/keymgmt/build.info +++ b/providers/implementations/keymgmt/build.info @@ -47,7 +47,7 @@ IF[{- !$disabled{'ml-kem'} -}] SOURCE[$TLS_ML_KEM_HYBRID_GOAL]=mlx_kmgmt.c ENDIF SOURCE[$ML_KEM_GOAL]=ml_kem_kmgmt.c - DEPEND[ml_kem_kmgmt.o]=../../common/include/prov/der_hkdf.h ../../common/include/prov/der_wrap.h + DEPEND[ml_kem_kmgmt.o]=../../common/include/prov/der_hkdf.h ENDIF SOURCE[$RSA_GOAL]=rsa_kmgmt.c diff --git a/providers/implementations/keymgmt/dh_kmgmt.c b/providers/implementations/keymgmt/dh_kmgmt.c index 8901f14e31..de42ee8533 100644 --- a/providers/implementations/keymgmt/dh_kmgmt.c +++ b/providers/implementations/keymgmt/dh_kmgmt.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -27,12 +27,8 @@ #include "crypto/dh.h" #include "internal/fips.h" #include "internal/sizes.h" -#include "internal/cryptlib.h" static OSSL_FUNC_keymgmt_new_fn dh_newdata; -static OSSL_FUNC_keymgmt_new_ex_fn dh_newdata_ex; -static OSSL_FUNC_keymgmt_new_fn dhx_newdata; -static OSSL_FUNC_keymgmt_new_ex_fn dhx_newdata_ex; static OSSL_FUNC_keymgmt_free_fn dh_freedata; static OSSL_FUNC_keymgmt_gen_init_fn dh_gen_init; static OSSL_FUNC_keymgmt_gen_init_fn dhx_gen_init; @@ -103,89 +99,30 @@ static int dh_gen_type_name2id_w_default(const char *name, int type) return ossl_dh_gen_type_name2id(name, type); } -/* - * If the application actually created a legacy DH object and assigned it to - * the EVP_PKEY, then we get hold of that object here. We return 0 if we hit - * a fatal error or 1 otherwise. We may return 1 but with *dh set to NULL. - */ -static int get_legacy_dh_object(OSSL_LIB_CTX *libctx, DH **dh, const OSSL_PARAM params[]) -{ -#ifndef FIPS_MODULE - const OSSL_PARAM *p; - - if (params == NULL) - return 1; - p = OSSL_PARAM_locate_const(params, "legacy-object"); - if (p == NULL) - return 1; - /* - * This only works because we are in the default provider. We are not - * normally allowed to pass complex objects across the provider boundary - * like this. - */ - if (OSSL_PARAM_get_octet_ptr(p, (const void **)dh, NULL) && *dh != NULL) { - if (ossl_lib_ctx_get_concrete(ossl_dh_get0_libctx(*dh)) != ossl_lib_ctx_get_concrete(libctx)) { - *dh = NULL; - return 1; - } - if (!DH_up_ref(*dh)) - return 0; - } -#endif - - return 1; -} - -static void *dh_newdata_ex(void *provctx, const OSSL_PARAM params[]) +static void *dh_newdata(void *provctx) { DH *dh = NULL; - if (!ossl_prov_is_running()) - return NULL; - - if (!get_legacy_dh_object(PROV_LIBCTX_OF(provctx), &dh, params)) - return NULL; - - if (dh == NULL) { + if (ossl_prov_is_running()) { dh = ossl_dh_new_ex(PROV_LIBCTX_OF(provctx)); if (dh != NULL) { DH_clear_flags(dh, DH_FLAG_TYPE_MASK); DH_set_flags(dh, DH_FLAG_TYPE_DH); } } - - return dh; -} - -static void *dh_newdata(void *provctx) -{ - return dh_newdata_ex(provctx, NULL); -} - -static void *dhx_newdata_ex(void *provctx, const OSSL_PARAM params[]) -{ - DH *dh = NULL; - - if (!ossl_prov_is_running()) - return NULL; - - if (!get_legacy_dh_object(PROV_LIBCTX_OF(provctx), &dh, params)) - return NULL; - - if (dh == NULL) { - dh = ossl_dh_new_ex(PROV_LIBCTX_OF(provctx)); - if (dh != NULL) { - DH_clear_flags(dh, DH_FLAG_TYPE_MASK); - DH_set_flags(dh, DH_FLAG_TYPE_DHX); - } - } - return dh; } static void *dhx_newdata(void *provctx) { - return dhx_newdata_ex(provctx, NULL); + DH *dh = NULL; + + dh = ossl_dh_new_ex(PROV_LIBCTX_OF(provctx)); + if (dh != NULL) { + DH_clear_flags(dh, DH_FLAG_TYPE_MASK); + DH_set_flags(dh, DH_FLAG_TYPE_DHX); + } + return dh; } static void dh_freedata(void *keydata) @@ -843,8 +780,10 @@ static void *dh_gen(void *genctx, OSSL_CALLBACK *osslcb, void *cbarg) #ifdef FIPS_MODULE if (!ossl_fips_self_testing()) { ret = ossl_dh_check_pairwise(dh, 0); - if (ret <= 0) + if (ret <= 0) { + ossl_set_error_state(OSSL_SELF_TEST_TYPE_PCT); goto end; + } } #endif /* FIPS_MODULE */ } @@ -897,7 +836,6 @@ static void *dh_dup(const void *keydata_from, int selection) const OSSL_DISPATCH ossl_dh_keymgmt_functions[] = { { OSSL_FUNC_KEYMGMT_NEW, (void (*)(void))dh_newdata }, - { OSSL_FUNC_KEYMGMT_NEW_EX, (void (*)(void))dh_newdata_ex }, { OSSL_FUNC_KEYMGMT_GEN_INIT, (void (*)(void))dh_gen_init }, { OSSL_FUNC_KEYMGMT_GEN_SET_TEMPLATE, (void (*)(void))dh_gen_set_template }, { OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS, (void (*)(void))dh_gen_set_params }, @@ -930,7 +868,6 @@ static const char *dhx_query_operation_name(int operation_id) const OSSL_DISPATCH ossl_dhx_keymgmt_functions[] = { { OSSL_FUNC_KEYMGMT_NEW, (void (*)(void))dhx_newdata }, - { OSSL_FUNC_KEYMGMT_NEW_EX, (void (*)(void))dhx_newdata_ex }, { OSSL_FUNC_KEYMGMT_GEN_INIT, (void (*)(void))dhx_gen_init }, { OSSL_FUNC_KEYMGMT_GEN_SET_TEMPLATE, (void (*)(void))dh_gen_set_template }, { OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS, (void (*)(void))dhx_gen_set_params }, diff --git a/providers/implementations/keymgmt/dsa_kmgmt.c b/providers/implementations/keymgmt/dsa_kmgmt.c index 3540706b54..b3cc76a89d 100644 --- a/providers/implementations/keymgmt/dsa_kmgmt.c +++ b/providers/implementations/keymgmt/dsa_kmgmt.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -28,7 +28,6 @@ #include "internal/param_build_set.h" static OSSL_FUNC_keymgmt_new_fn dsa_newdata; -static OSSL_FUNC_keymgmt_new_ex_fn dsa_newdata_ex; static OSSL_FUNC_keymgmt_free_fn dsa_freedata; static OSSL_FUNC_keymgmt_gen_init_fn dsa_gen_init; static OSSL_FUNC_keymgmt_gen_set_template_fn dsa_gen_set_template; @@ -120,42 +119,11 @@ static int dsa_key_todata(DSA *dsa, OSSL_PARAM_BLD *bld, OSSL_PARAM *pubkey, return 1; } -static void *dsa_newdata_ex(void *provctx, const OSSL_PARAM params[]) -{ - DSA *dsa = NULL; - OSSL_LIB_CTX *libctx = PROV_LIBCTX_OF(provctx); - - if (!ossl_prov_is_running()) - return NULL; - -#ifndef FIPS_MODULE - const OSSL_PARAM *p = NULL; - - if (params != NULL) - p = OSSL_PARAM_locate_const(params, "legacy-object"); - - /* - * This only works because we are in the default provider. We are not - * normally allowed to pass complex objects across the provider boundary - * like this. - */ - if (p != NULL && OSSL_PARAM_get_octet_ptr(p, (const void **)&dsa, NULL) && dsa != NULL) { - if (ossl_lib_ctx_get_concrete(ossl_dsa_get0_libctx(dsa)) != ossl_lib_ctx_get_concrete(libctx)) - dsa = NULL; - else if (!DSA_up_ref(dsa)) - return NULL; - } -#endif - - if (dsa == NULL) - dsa = ossl_dsa_new(libctx); - - return dsa; -} - static void *dsa_newdata(void *provctx) { - return dsa_newdata_ex(provctx, NULL); + if (!ossl_prov_is_running()) + return NULL; + return ossl_dsa_new(PROV_LIBCTX_OF(provctx)); } static void dsa_freedata(void *keydata) @@ -626,7 +594,7 @@ static void *dsa_gen(void *genctx, OSSL_CALLBACK *osslcb, void *cbarg) */ if (!OSSL_FIPS_IND_ON_UNAPPROVED(gctx, OSSL_FIPS_IND_SETTABLE0, gctx->libctx, "DSA", "Keygen", - FIPS_CONFIG_DSA_SIGN_DISABLED)) + ossl_fips_config_dsa_sign_disallowed)) return 0; #endif @@ -739,7 +707,6 @@ static void *dsa_dup(const void *keydata_from, int selection) const OSSL_DISPATCH ossl_dsa_keymgmt_functions[] = { { OSSL_FUNC_KEYMGMT_NEW, (void (*)(void))dsa_newdata }, - { OSSL_FUNC_KEYMGMT_NEW_EX, (void (*)(void))dsa_newdata_ex }, { OSSL_FUNC_KEYMGMT_GEN_INIT, (void (*)(void))dsa_gen_init }, { OSSL_FUNC_KEYMGMT_GEN_SET_TEMPLATE, (void (*)(void))dsa_gen_set_template }, { OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS, (void (*)(void))dsa_gen_set_params }, diff --git a/providers/implementations/keymgmt/ec_kmgmt.c b/providers/implementations/keymgmt/ec_kmgmt.c index 28404502eb..cc3cf75cd8 100644 --- a/providers/implementations/keymgmt/ec_kmgmt.c +++ b/providers/implementations/keymgmt/ec_kmgmt.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -37,7 +37,6 @@ #endif static OSSL_FUNC_keymgmt_new_fn ec_newdata; -static OSSL_FUNC_keymgmt_new_ex_fn ec_newdata_ex; static OSSL_FUNC_keymgmt_gen_init_fn ec_gen_init; static OSSL_FUNC_keymgmt_gen_set_template_fn ec_gen_set_template; static OSSL_FUNC_keymgmt_gen_set_params_fn ec_gen_set_params; @@ -71,7 +70,6 @@ static OSSL_FUNC_keymgmt_gettable_params_fn sm2_gettable_params; static OSSL_FUNC_keymgmt_settable_params_fn sm2_settable_params; static OSSL_FUNC_keymgmt_import_fn sm2_import; static OSSL_FUNC_keymgmt_query_operation_name_fn sm2_query_operation_name; -static OSSL_FUNC_keymgmt_query_operation_name_fn curve_sm2_query_operation_name; static OSSL_FUNC_keymgmt_validate_fn sm2_validate; #endif #endif @@ -92,7 +90,8 @@ static const char *ec_query_operation_name(int operation_id) return NULL; } -#if !defined(FIPS_MODULE) && !defined(OPENSSL_NO_SM2) +#ifndef FIPS_MODULE +#ifndef OPENSSL_NO_SM2 static const char *sm2_query_operation_name(int operation_id) { switch (operation_id) { @@ -101,14 +100,7 @@ static const char *sm2_query_operation_name(int operation_id) } return NULL; } -static const char *curve_sm2_query_operation_name(int operation_id) -{ - switch (operation_id) { - case OSSL_OP_KEYEXCH: - return "ECDH"; - } - return NULL; -} +#endif #endif /* @@ -250,10 +242,19 @@ static ossl_inline int otherparams_to_params(const EC_KEY *ec, OSSL_PARAM_BLD *t { int ecdh_cofactor_mode = 0, group_check = 0; const char *name = NULL; + point_conversion_form_t format; if (ec == NULL) return 0; + format = EC_KEY_get_conv_form(ec); + name = ossl_ec_pt_format_id2name((int)format); + if (name != NULL + && !ossl_param_build_set_utf8_string(tmpl, params, + OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT, + name)) + return 0; + group_check = EC_KEY_get_flags(ec) & EC_FLAG_CHECK_NAMED_GROUP_MASK; name = ossl_ec_check_group_type_id2name(group_check); if (name != NULL @@ -273,46 +274,11 @@ static ossl_inline int otherparams_to_params(const EC_KEY *ec, OSSL_PARAM_BLD *t ecdh_cofactor_mode); } -static void *ec_newdata_ex(void *provctx, const OSSL_PARAM params[]) -{ - EC_KEY *eckey = NULL; - OSSL_LIB_CTX *libctx = PROV_LIBCTX_OF(provctx); - - if (!ossl_prov_is_running()) - return NULL; - -#ifndef FIPS_MODULE - const OSSL_PARAM *p = NULL; - - if (params != NULL) - p = OSSL_PARAM_locate_const(params, "legacy-object"); - - /* - * This only works because we are in the default provider. We are not - * normally allowed to pass complex objects across the provider boundary - * like this. - */ - if (p != NULL && OSSL_PARAM_get_octet_ptr(p, (const void **)&eckey, NULL) && eckey != NULL) { -#ifdef OPENSSL_NO_EC_EXPLICIT_CURVES - if (EC_GROUP_check_named_curve(EC_KEY_get0_group(eckey), 0, NULL) == NID_undef) - return NULL; -#endif - if (ossl_lib_ctx_get_concrete(ossl_ec_key_get_libctx(eckey)) != ossl_lib_ctx_get_concrete(libctx)) - eckey = NULL; - else if (!EC_KEY_up_ref(eckey)) - return NULL; - } -#endif - - if (eckey == NULL) - eckey = EC_KEY_new_ex(libctx, NULL); - - return eckey; -} - static void *ec_newdata(void *provctx) { - return ec_newdata_ex(provctx, NULL); + if (!ossl_prov_is_running()) + return NULL; + return EC_KEY_new_ex(PROV_LIBCTX_OF(provctx), NULL); } #ifndef FIPS_MODULE @@ -503,21 +469,19 @@ static int ec_export(void *keydata, int selection, OSSL_CALLBACK *param_cb, && (selection & OSSL_KEYMGMT_SELECT_PUBLIC_KEY) == 0) return 0; - if ((bnctx = BN_CTX_new_ex(ossl_ec_key_get_libctx(ec))) == NULL) + tmpl = OSSL_PARAM_BLD_new(); + if (tmpl == NULL) return 0; - BN_CTX_start(bnctx); - if ((tmpl = OSSL_PARAM_BLD_new()) == NULL) { - ok = 0; - goto end; + if ((selection & OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS) != 0) { + bnctx = BN_CTX_new_ex(ossl_ec_key_get_libctx(ec)); + if (bnctx == NULL) { + ok = 0; + goto end; + } + BN_CTX_start(bnctx); + ok = ok && ossl_ec_group_todata(EC_KEY_get0_group(ec), tmpl, NULL, ossl_ec_key_get_libctx(ec), ossl_ec_key_get0_propq(ec), bnctx, &genbuf); } - /* - * OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT is added based on the group's - * asn1_form by the call below. - */ - ok = ossl_ec_group_todata(EC_KEY_get0_group(ec), tmpl, NULL, - ossl_ec_key_get_libctx(ec), ossl_ec_key_get0_propq(ec), - bnctx, &genbuf); if ((selection & OSSL_KEYMGMT_SELECT_KEYPAIR) != 0) { int include_private = selection & OSSL_KEYMGMT_SELECT_PRIVATE_KEY ? 1 : 0; @@ -683,12 +647,43 @@ static int common_get_params(void *key, OSSL_PARAM params[], int sm2) if ((p = OSSL_PARAM_locate(params, OSSL_PKEY_PARAM_BITS)) != NULL && !OSSL_PARAM_set_int(p, EC_GROUP_order_bits(ecg))) goto err; - if ((p = OSSL_PARAM_locate(params, OSSL_PKEY_PARAM_EC_FIELD_DEGREE)) != NULL - && !OSSL_PARAM_set_int(p, EC_GROUP_get_degree(ecg))) - goto err; - if ((p = OSSL_PARAM_locate(params, OSSL_PKEY_PARAM_SECURITY_BITS)) != NULL - && !OSSL_PARAM_set_int(p, EC_GROUP_security_bits(ecg))) - goto err; + if ((p = OSSL_PARAM_locate(params, OSSL_PKEY_PARAM_SECURITY_BITS)) != NULL) { + int ecbits, sec_bits; + + ecbits = EC_GROUP_order_bits(ecg); + + /* + * The following estimates are based on the values published + * in Table 2 of "NIST Special Publication 800-57 Part 1 Revision 4" + * at http://dx.doi.org/10.6028/NIST.SP.800-57pt1r4 . + * + * Note that the above reference explicitly categorizes algorithms in a + * discrete set of values {80, 112, 128, 192, 256}, and that it is + * relevant only for NIST approved Elliptic Curves, while OpenSSL + * applies the same logic also to other curves. + * + * Classifications produced by other standardazing bodies might differ, + * so the results provided for "bits of security" by this provider are + * to be considered merely indicative, and it is the users' + * responsibility to compare these values against the normative + * references that may be relevant for their intent and purposes. + */ + if (ecbits >= 512) + sec_bits = 256; + else if (ecbits >= 384) + sec_bits = 192; + else if (ecbits >= 256) + sec_bits = 128; + else if (ecbits >= 224) + sec_bits = 112; + else if (ecbits >= 160) + sec_bits = 80; + else + sec_bits = ecbits / 2; + + if (!OSSL_PARAM_set_int(p, sec_bits)) + goto err; + } if ((p = OSSL_PARAM_locate(params, OSSL_PKEY_PARAM_SECURITY_CATEGORY)) != NULL) if (!OSSL_PARAM_set_int(p, 0)) goto err; @@ -741,10 +736,6 @@ static int common_get_params(void *key, OSSL_PARAM params[], int sm2) goto err; } - /* - * OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT is added based on the group's - * asn1_form by ossl_ec_group_todata() below. - */ ret = ec_get_ecm_params(ecg, params) && ossl_ec_group_todata(ecg, NULL, params, libctx, propq, bnctx, &genbuf) @@ -777,7 +768,6 @@ static int ec_get_params(void *key, OSSL_PARAM params[]) static const OSSL_PARAM ec_known_gettable_params[] = { OSSL_PARAM_int(OSSL_PKEY_PARAM_BITS, NULL), - OSSL_PARAM_int(OSSL_PKEY_PARAM_EC_FIELD_DEGREE, NULL), OSSL_PARAM_int(OSSL_PKEY_PARAM_SECURITY_BITS, NULL), OSSL_PARAM_int(OSSL_PKEY_PARAM_MAX_SIZE, NULL), OSSL_PARAM_int(OSSL_PKEY_PARAM_SECURITY_CATEGORY, NULL), @@ -854,7 +844,6 @@ static int sm2_get_params(void *key, OSSL_PARAM params[]) static const OSSL_PARAM sm2_known_gettable_params[] = { OSSL_PARAM_int(OSSL_PKEY_PARAM_BITS, NULL), - OSSL_PARAM_int(OSSL_PKEY_PARAM_EC_FIELD_DEGREE, NULL), OSSL_PARAM_int(OSSL_PKEY_PARAM_SECURITY_BITS, NULL), OSSL_PARAM_int(OSSL_PKEY_PARAM_MAX_SIZE, NULL), OSSL_PARAM_utf8_string(OSSL_PKEY_PARAM_DEFAULT_DIGEST, NULL, 0), @@ -1300,18 +1289,6 @@ static void *ec_gen(void *genctx, OSSL_CALLBACK *osslcb, void *cbarg) /* Whether you want it or not, you get a keypair, not just one half */ if ((gctx->selection & OSSL_KEYMGMT_SELECT_KEYPAIR) != 0) { - /* - * A generated key's public point has been serialised - * in uncompressed form for many releases, regardless - * of anything requested on the ctx or inherited from - * the template -- callers who consume the SPKI, EC - * PKCS#8 or other encodings rely on that. With group - * and key form now consolidated on a single field on - * the group, force it to uncompressed here rather - * than start emitting compressed public points where - * no caller was expecting them. - */ - EC_KEY_set_conv_form(ec, POINT_CONVERSION_UNCOMPRESSED); #ifndef FIPS_MODULE if (gctx->dhkem_ikm != NULL && gctx->dhkem_ikmlen != 0) ret = ret && ossl_ec_generate_key_dhkem(ec, gctx->dhkem_ikm, gctx->dhkem_ikmlen); @@ -1325,8 +1302,22 @@ static void *ec_gen(void *genctx, OSSL_CALLBACK *osslcb, void *cbarg) if (gctx->group_check != NULL) ret = ret && ossl_ec_set_check_group_type_from_name(ec, gctx->group_check); +#ifdef FIPS_MODULE + if (ret > 0 + && !ossl_fips_self_testing() + && EC_KEY_get0_public_key(ec) != NULL + && EC_KEY_get0_private_key(ec) != NULL + && EC_KEY_get0_group(ec) != NULL) { + BN_CTX *bnctx = BN_CTX_new_ex(ossl_ec_key_get_libctx(ec)); - if (ret > 0) + ret = bnctx != NULL && ossl_ec_key_pairwise_check(ec, bnctx); + BN_CTX_free(bnctx); + if (ret <= 0) + ossl_set_error_state(OSSL_SELF_TEST_TYPE_PCT); + } +#endif /* FIPS_MODULE */ + + if (ret) return ec; err: /* Something went wrong, throw the key away */ @@ -1373,21 +1364,8 @@ static void *sm2_gen(void *genctx, OSSL_CALLBACK *osslcb, void *cbarg) ret = ec_gen_assign_group(ec, gctx->gen_group); /* Whether you want it or not, you get a keypair, not just one half */ - if ((gctx->selection & OSSL_KEYMGMT_SELECT_KEYPAIR) != 0) { - /* - * A generated key's public point has been serialised - * in uncompressed form for many releases, regardless - * of anything requested on the ctx or inherited from - * the template -- callers who consume the SPKI, EC - * PKCS#8 or other encodings rely on that. With group - * and key form now consolidated on a single field on - * the group, force it to uncompressed here rather - * than start emitting compressed public points where - * no caller was expecting them. - */ - EC_KEY_set_conv_form(ec, POINT_CONVERSION_UNCOMPRESSED); + if ((gctx->selection & OSSL_KEYMGMT_SELECT_KEYPAIR) != 0) ret = ret && EC_KEY_generate_key(ec); - } if (ret) return ec; @@ -1464,7 +1442,6 @@ static void *ec_dup(const void *keydata_from, int selection) const OSSL_DISPATCH ossl_ec_keymgmt_functions[] = { { OSSL_FUNC_KEYMGMT_NEW, (void (*)(void))ec_newdata }, - { OSSL_FUNC_KEYMGMT_NEW_EX, (void (*)(void))ec_newdata_ex }, { OSSL_FUNC_KEYMGMT_GEN_INIT, (void (*)(void))ec_gen_init }, { OSSL_FUNC_KEYMGMT_GEN_SET_TEMPLATE, (void (*)(void))ec_gen_set_template }, @@ -1497,36 +1474,33 @@ const OSSL_DISPATCH ossl_ec_keymgmt_functions[] = { #ifndef FIPS_MODULE #ifndef OPENSSL_NO_SM2 -#define SM2_FUNCS(variant) \ - const OSSL_DISPATCH ossl_##variant##_keymgmt_functions[] = { \ - { OSSL_FUNC_KEYMGMT_NEW, (void (*)(void))sm2_newdata }, \ - { OSSL_FUNC_KEYMGMT_GEN_INIT, (void (*)(void))sm2_gen_init }, \ - { OSSL_FUNC_KEYMGMT_GEN_SET_TEMPLATE, \ - (void (*)(void))ec_gen_set_template }, \ - { OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS, (void (*)(void))ec_gen_set_params }, \ - { OSSL_FUNC_KEYMGMT_GEN_SETTABLE_PARAMS, \ - (void (*)(void))ec_gen_settable_params }, \ - { OSSL_FUNC_KEYMGMT_GEN, (void (*)(void))sm2_gen }, \ - { OSSL_FUNC_KEYMGMT_GEN_CLEANUP, (void (*)(void))ec_gen_cleanup }, \ - { OSSL_FUNC_KEYMGMT_LOAD, (void (*)(void))sm2_load }, \ - { OSSL_FUNC_KEYMGMT_FREE, (void (*)(void))ec_freedata }, \ - { OSSL_FUNC_KEYMGMT_GET_PARAMS, (void (*)(void))sm2_get_params }, \ - { OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS, (void (*)(void))sm2_gettable_params }, \ - { OSSL_FUNC_KEYMGMT_SET_PARAMS, (void (*)(void))ec_set_params }, \ - { OSSL_FUNC_KEYMGMT_SETTABLE_PARAMS, (void (*)(void))sm2_settable_params }, \ - { OSSL_FUNC_KEYMGMT_HAS, (void (*)(void))ec_has }, \ - { OSSL_FUNC_KEYMGMT_MATCH, (void (*)(void))ec_match }, \ - { OSSL_FUNC_KEYMGMT_VALIDATE, (void (*)(void))sm2_validate }, \ - { OSSL_FUNC_KEYMGMT_IMPORT, (void (*)(void))sm2_import }, \ - { OSSL_FUNC_KEYMGMT_IMPORT_TYPES, (void (*)(void))ec_import_types }, \ - { OSSL_FUNC_KEYMGMT_EXPORT, (void (*)(void))ec_export }, \ - { OSSL_FUNC_KEYMGMT_EXPORT_TYPES, (void (*)(void))ec_export_types }, \ - { OSSL_FUNC_KEYMGMT_QUERY_OPERATION_NAME, \ - (void (*)(void))variant##_query_operation_name }, \ - { OSSL_FUNC_KEYMGMT_DUP, (void (*)(void))ec_dup }, \ - OSSL_DISPATCH_END \ - } -SM2_FUNCS(sm2); -SM2_FUNCS(curve_sm2); +const OSSL_DISPATCH ossl_sm2_keymgmt_functions[] = { + { OSSL_FUNC_KEYMGMT_NEW, (void (*)(void))sm2_newdata }, + { OSSL_FUNC_KEYMGMT_GEN_INIT, (void (*)(void))sm2_gen_init }, + { OSSL_FUNC_KEYMGMT_GEN_SET_TEMPLATE, + (void (*)(void))ec_gen_set_template }, + { OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS, (void (*)(void))ec_gen_set_params }, + { OSSL_FUNC_KEYMGMT_GEN_SETTABLE_PARAMS, + (void (*)(void))ec_gen_settable_params }, + { OSSL_FUNC_KEYMGMT_GEN, (void (*)(void))sm2_gen }, + { OSSL_FUNC_KEYMGMT_GEN_CLEANUP, (void (*)(void))ec_gen_cleanup }, + { OSSL_FUNC_KEYMGMT_LOAD, (void (*)(void))sm2_load }, + { OSSL_FUNC_KEYMGMT_FREE, (void (*)(void))ec_freedata }, + { OSSL_FUNC_KEYMGMT_GET_PARAMS, (void (*)(void))sm2_get_params }, + { OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS, (void (*)(void))sm2_gettable_params }, + { OSSL_FUNC_KEYMGMT_SET_PARAMS, (void (*)(void))ec_set_params }, + { OSSL_FUNC_KEYMGMT_SETTABLE_PARAMS, (void (*)(void))sm2_settable_params }, + { OSSL_FUNC_KEYMGMT_HAS, (void (*)(void))ec_has }, + { OSSL_FUNC_KEYMGMT_MATCH, (void (*)(void))ec_match }, + { OSSL_FUNC_KEYMGMT_VALIDATE, (void (*)(void))sm2_validate }, + { OSSL_FUNC_KEYMGMT_IMPORT, (void (*)(void))sm2_import }, + { OSSL_FUNC_KEYMGMT_IMPORT_TYPES, (void (*)(void))ec_import_types }, + { OSSL_FUNC_KEYMGMT_EXPORT, (void (*)(void))ec_export }, + { OSSL_FUNC_KEYMGMT_EXPORT_TYPES, (void (*)(void))ec_export_types }, + { OSSL_FUNC_KEYMGMT_QUERY_OPERATION_NAME, + (void (*)(void))sm2_query_operation_name }, + { OSSL_FUNC_KEYMGMT_DUP, (void (*)(void))ec_dup }, + OSSL_DISPATCH_END +}; #endif #endif diff --git a/providers/implementations/keymgmt/ecx_kmgmt.c b/providers/implementations/keymgmt/ecx_kmgmt.c index dd9c029a4a..8345f5a7bb 100644 --- a/providers/implementations/keymgmt/ecx_kmgmt.c +++ b/providers/implementations/keymgmt/ecx_kmgmt.c @@ -27,7 +27,7 @@ #include "prov/ecx.h" #include "prov/securitycheck.h" #ifdef S390X_EC_ASM -#include "arch/s390x_arch.h" +#include "s390x_arch.h" #include /* For SHA512_DIGEST_LENGTH */ #endif @@ -35,7 +35,6 @@ static OSSL_FUNC_keymgmt_new_fn x25519_new_key; static OSSL_FUNC_keymgmt_new_fn x448_new_key; static OSSL_FUNC_keymgmt_new_fn ed25519_new_key; static OSSL_FUNC_keymgmt_new_fn ed448_new_key; -static OSSL_FUNC_keymgmt_free_fn ecx_free_key; static OSSL_FUNC_keymgmt_gen_init_fn x25519_gen_init; static OSSL_FUNC_keymgmt_gen_init_fn x448_gen_init; static OSSL_FUNC_keymgmt_gen_init_fn ed25519_gen_init; @@ -797,6 +796,7 @@ static void *ed25519_gen(void *genctx, OSSL_CALLBACK *osslcb, void *cbarg) if (!key || ((gctx->selection & OSSL_KEYMGMT_SELECT_KEYPAIR) == 0)) return key; if (ecd_fips140_pairwise_test(key, ECX_KEY_TYPE_ED25519, 1) != 1) { + ossl_set_error_state(OSSL_SELF_TEST_TYPE_PCT); ossl_ecx_key_free(key); return NULL; } @@ -829,6 +829,7 @@ static void *ed448_gen(void *genctx, OSSL_CALLBACK *osslcb, void *cbarg) if (!key || ((gctx->selection & OSSL_KEYMGMT_SELECT_KEYPAIR) == 0)) return key; if (ecd_fips140_pairwise_test(key, ECX_KEY_TYPE_ED448, 1) != 1) { + ossl_set_error_state(OSSL_SELF_TEST_TYPE_PCT); ossl_ecx_key_free(key); return NULL; } @@ -992,15 +993,10 @@ static int ed448_validate(const void *keydata, int selection, int checktype) return ecx_validate(keydata, selection, ECX_KEY_TYPE_ED448, ED448_KEYLEN); } -static void ecx_free_key(void *keydata) -{ - ossl_ecx_key_free((ECX_KEY *)keydata); -} - #define MAKE_KEYMGMT_FUNCTIONS(alg) \ const OSSL_DISPATCH ossl_##alg##_keymgmt_functions[] = { \ { OSSL_FUNC_KEYMGMT_NEW, (void (*)(void))alg##_new_key }, \ - { OSSL_FUNC_KEYMGMT_FREE, (void (*)(void))ecx_free_key }, \ + { OSSL_FUNC_KEYMGMT_FREE, (void (*)(void))ossl_ecx_key_free }, \ { OSSL_FUNC_KEYMGMT_GET_PARAMS, (void (*)(void))alg##_get_params }, \ { OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS, (void (*)(void))alg##_gettable_params }, \ { OSSL_FUNC_KEYMGMT_SET_PARAMS, (void (*)(void))alg##_set_params }, \ @@ -1029,7 +1025,7 @@ MAKE_KEYMGMT_FUNCTIONS(ed25519) MAKE_KEYMGMT_FUNCTIONS(ed448) #ifdef S390X_EC_ASM -#include "arch/s390x_arch.h" +#include "s390x_arch.h" static void *s390x_ecx_keygen25519(struct ecx_gen_ctx *gctx) { @@ -1150,10 +1146,38 @@ static void *s390x_ecd_keygen25519(struct ecx_gen_ctx *gctx) 0xfe, 0x53, 0x6e, 0xcd, 0xd3, 0x36, 0x69, 0x21 }; static const unsigned char generator_y[] = { - 0x58, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, - 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, - 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, - 0x66, 0x66 + 0x58, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, }; unsigned char x_dst[32], buff[SHA512_DIGEST_LENGTH]; ECX_KEY *key = ossl_ecx_key_new(gctx->libctx, ECX_KEY_TYPE_ED25519, 1, diff --git a/providers/implementations/keymgmt/kdf_legacy_kmgmt.c b/providers/implementations/keymgmt/kdf_legacy_kmgmt.c index 7a772ad017..deb4960006 100644 --- a/providers/implementations/keymgmt/kdf_legacy_kmgmt.c +++ b/providers/implementations/keymgmt/kdf_legacy_kmgmt.c @@ -75,7 +75,8 @@ int ossl_kdf_data_up_ref(KDF_DATA *kdfdata) if (!ossl_prov_is_running()) return 0; - return CRYPTO_UP_REF(&kdfdata->refcnt, &ref); + CRYPTO_UP_REF(&kdfdata->refcnt, &ref); + return 1; } static void *kdf_newdata(void *provctx) diff --git a/providers/implementations/keymgmt/lms_kmgmt.c b/providers/implementations/keymgmt/lms_kmgmt.c index f8297e1146..8d7cfcc6f4 100644 --- a/providers/implementations/keymgmt/lms_kmgmt.c +++ b/providers/implementations/keymgmt/lms_kmgmt.c @@ -1,5 +1,5 @@ /* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -28,8 +28,6 @@ static OSSL_FUNC_keymgmt_export_fn lms_export; static OSSL_FUNC_keymgmt_import_types_fn lms_imexport_types; static OSSL_FUNC_keymgmt_export_types_fn lms_imexport_types; static OSSL_FUNC_keymgmt_load_fn lms_load; -static OSSL_FUNC_keymgmt_gettable_params_fn lms_gettable_params; -static OSSL_FUNC_keymgmt_get_params_fn lms_get_params; #define LMS_POSSIBLE_SELECTIONS (OSSL_KEYMGMT_SELECT_PUBLIC_KEY) @@ -51,7 +49,7 @@ static int lms_has(const void *keydata, int selection) if (!ossl_prov_is_running() || key == NULL) return 0; - if ((selection & OSSL_KEYMGMT_SELECT_KEYPAIR) == 0) + if ((selection & LMS_POSSIBLE_SELECTIONS) == 0) return 1; /* the selection is not missing */ return ossl_lms_key_has(key, selection); @@ -152,50 +150,6 @@ static void *lms_load(const void *reference, size_t reference_sz) return NULL; } -static const OSSL_PARAM *lms_gettable_params(void *provctx) -{ - return lms_get_params_list; -} - -static int lms_get_params(void *keydata, OSSL_PARAM params[]) -{ - LMS_KEY *key = keydata; - const uint8_t *d; - size_t len; - struct lms_get_params_st p; - - if (key == NULL || !lms_get_params_decoder(params, &p)) - return 0; - - if (p.bits != NULL - && !OSSL_PARAM_set_size_t(p.bits, 8 * ossl_lms_key_get_pub_len(key))) - return 0; - - if (p.secbits != NULL - && !OSSL_PARAM_set_size_t(p.secbits, ossl_lms_key_get_collision_strength_bits(key))) - return 0; - - if (p.maxsize != NULL - && !OSSL_PARAM_set_size_t(p.maxsize, ossl_lms_key_get_sig_len(key))) - return 0; - - if (p.pubkey != NULL) { - d = ossl_lms_key_get_pub(key); - if (d != NULL) { - len = ossl_lms_key_get_pub_len(key); - if (!OSSL_PARAM_set_octet_string(p.pubkey, d, len)) - return 0; - } - } - /* - * This allows apps to use an empty digest, so that the old API - * for digest signing can be used. - */ - if (p.dgstp != NULL && !OSSL_PARAM_set_utf8_string(p.dgstp, "")) - return 0; - return 1; -} - const OSSL_DISPATCH ossl_lms_keymgmt_functions[] = { { OSSL_FUNC_KEYMGMT_NEW, (void (*)(void))lms_new_key }, { OSSL_FUNC_KEYMGMT_FREE, (void (*)(void))lms_free_key }, @@ -207,7 +161,5 @@ const OSSL_DISPATCH ossl_lms_keymgmt_functions[] = { { OSSL_FUNC_KEYMGMT_EXPORT, (void (*)(void))lms_export }, { OSSL_FUNC_KEYMGMT_EXPORT_TYPES, (void (*)(void))lms_imexport_types }, { OSSL_FUNC_KEYMGMT_LOAD, (void (*)(void))lms_load }, - { OSSL_FUNC_KEYMGMT_GET_PARAMS, (void (*)(void))lms_get_params }, - { OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS, (void (*)(void))lms_gettable_params }, OSSL_DISPATCH_END }; diff --git a/providers/implementations/keymgmt/lms_kmgmt.inc.in b/providers/implementations/keymgmt/lms_kmgmt.inc.in index 3be81ad30c..59e1ed9f53 100644 --- a/providers/implementations/keymgmt/lms_kmgmt.inc.in +++ b/providers/implementations/keymgmt/lms_kmgmt.inc.in @@ -1,5 +1,5 @@ /* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the \"License\"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -14,11 +14,3 @@ use OpenSSL::paramnames qw(produce_param_decoder); {- produce_param_decoder('lms_import', (['OSSL_PKEY_PARAM_PUB_KEY', 'pub', 'octet_string'], )); -} - -{- produce_param_decoder('lms_get_params', - (['OSSL_PKEY_PARAM_BITS', 'bits', 'int'], - ['OSSL_PKEY_PARAM_SECURITY_BITS', 'secbits', 'int'], - ['OSSL_PKEY_PARAM_MAX_SIZE', 'maxsize', 'int'], - ['OSSL_PKEY_PARAM_MANDATORY_DIGEST', 'dgstp', 'utf8_string'], - ['OSSL_PKEY_PARAM_PUB_KEY', 'pubkey', 'octet_string'], - )); -} diff --git a/providers/implementations/keymgmt/mac_legacy_kmgmt.c b/providers/implementations/keymgmt/mac_legacy_kmgmt.c index 4c2e8d8cd9..d3082ca772 100644 --- a/providers/implementations/keymgmt/mac_legacy_kmgmt.c +++ b/providers/implementations/keymgmt/mac_legacy_kmgmt.c @@ -110,7 +110,8 @@ int ossl_mac_key_up_ref(MAC_KEY *mackey) if (!ossl_prov_is_running()) return 0; - return CRYPTO_UP_REF(&mackey->refcnt, &ref); + CRYPTO_UP_REF(&mackey->refcnt, &ref); + return 1; } static void *mac_new(void *provctx) diff --git a/providers/implementations/keymgmt/ml_dsa_kmgmt.c b/providers/implementations/keymgmt/ml_dsa_kmgmt.c index 24406ac602..e4ac35ff3e 100644 --- a/providers/implementations/keymgmt/ml_dsa_kmgmt.c +++ b/providers/implementations/keymgmt/ml_dsa_kmgmt.c @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -20,9 +20,6 @@ #include "prov/providercommon.h" #include "prov/provider_ctx.h" #include "prov/ml_dsa.h" - -#define ml_dsa_export_params -#define ml_dsa_export_params_decoder #include "providers/implementations/keymgmt/ml_dsa_kmgmt.inc" static OSSL_FUNC_keymgmt_free_fn ml_dsa_free_key; @@ -30,8 +27,8 @@ static OSSL_FUNC_keymgmt_has_fn ml_dsa_has; static OSSL_FUNC_keymgmt_match_fn ml_dsa_match; static OSSL_FUNC_keymgmt_import_fn ml_dsa_import; static OSSL_FUNC_keymgmt_export_fn ml_dsa_export; -static OSSL_FUNC_keymgmt_import_types_fn ml_dsa_import_types; -static OSSL_FUNC_keymgmt_export_types_fn ml_dsa_export_types; +static OSSL_FUNC_keymgmt_import_types_fn ml_dsa_imexport_types; +static OSSL_FUNC_keymgmt_export_types_fn ml_dsa_imexport_types; static OSSL_FUNC_keymgmt_dup_fn ml_dsa_dup_key; static OSSL_FUNC_keymgmt_gettable_params_fn ml_dsa_gettable_params; static OSSL_FUNC_keymgmt_validate_fn ml_dsa_validate; @@ -64,8 +61,7 @@ static int ml_dsa_pairwise_test(const ML_DSA_KEY *key) int ret = 0; if (!ml_dsa_has(key, OSSL_KEYMGMT_SELECT_KEYPAIR) - || ossl_fips_self_testing() - || ossl_self_test_in_progress(ST_ID_ASYM_KEYGEN_ML_DSA)) + || ossl_fips_self_testing()) return 1; /* @@ -111,12 +107,6 @@ ML_DSA_KEY *ossl_prov_ml_dsa_new(PROV_CTX *ctx, const char *propq, int evp_type) if (!ossl_prov_is_running()) return 0; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(ctx), - ST_ID_ASYM_KEYGEN_ML_DSA)) - return NULL; -#endif - key = ossl_ml_dsa_key_new(PROV_LIBCTX_OF(ctx), propq, evp_type); /* * When decoding, if the key ends up "loaded" into the same provider, these @@ -207,15 +197,15 @@ static int ml_dsa_key_fromdata(ML_DSA_KEY *key, const OSSL_PARAM params[], const ML_DSA_PARAMS *key_params = ossl_ml_dsa_key_params(key); const uint8_t *pk = NULL, *sk = NULL, *seed = NULL; size_t pk_len = 0, sk_len = 0, seed_len = 0; - struct ml_dsa_import_params_st p; + struct ml_dsa_key_type_params_st p; - if (!ml_dsa_import_params_decoder(params, &p)) + if (!ml_dsa_key_type_params_decoder(params, &p)) return 0; if (p.pubkey != NULL) { if (!OSSL_PARAM_get_octet_string_ptr(p.pubkey, (const void **)&pk, &pk_len)) return 0; - if (pk_len != 0 && pk_len != key_params->pk_len) { + if (pk != NULL && pk_len != key_params->pk_len) { ERR_raise_data(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH, "Invalid %s public key length", key_params->alg); return 0; @@ -227,7 +217,7 @@ static int ml_dsa_key_fromdata(ML_DSA_KEY *key, const OSSL_PARAM params[], if (!OSSL_PARAM_get_octet_string_ptr(p.seed, (const void **)&seed, &seed_len)) return 0; - if (seed_len != 0 && seed_len != ML_DSA_SEED_BYTES) { + if (seed != NULL && seed_len != ML_DSA_SEED_BYTES) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_SEED_LENGTH); return 0; } @@ -238,7 +228,7 @@ static int ml_dsa_key_fromdata(ML_DSA_KEY *key, const OSSL_PARAM params[], if (!OSSL_PARAM_get_octet_string_ptr(p.privkey, (const void **)&sk, &sk_len)) return 0; - if (sk_len != 0 && sk_len != key_params->sk_len) { + if (sk != NULL && sk_len != key_params->sk_len) { ERR_raise_data(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH, "Invalid %s private key length", key_params->alg); @@ -252,12 +242,6 @@ static int ml_dsa_key_fromdata(ML_DSA_KEY *key, const OSSL_PARAM params[], return 0; } - if (p.propq != NULL) { - if (p.propq->data_type != OSSL_PARAM_UTF8_STRING) - return 0; - if (!ossl_ml_dsa_key_fetch_digests(key, p.propq->data)) - return 0; - } if (seed_len != 0 && (sk_len == 0 || (ossl_ml_dsa_key_get_prov_flags(key) & ML_DSA_KEY_PREFER_SEED))) { @@ -293,18 +277,8 @@ static int ml_dsa_import(void *keydata, int selection, const OSSL_PARAM params[] int include_priv; int res; - /* - * Once a key is fully initialised (has at least a public component), - * further mutation is no longer safe and disallowed. - */ if (!ossl_prov_is_running() || key == NULL) return 0; - if (ossl_ml_dsa_key_has(key, OSSL_KEYMGMT_SELECT_PUBLIC_KEY)) { - /* Invalid attempt to mutate a key. */ - ERR_raise_data(ERR_LIB_PROV, PROV_R_KEY_IMMUTABLE_ONCE_SET, - "Keys are immutable once key material has been loaded or generated"); - return 0; - } if ((selection & OSSL_KEYMGMT_SELECT_KEYPAIR) == 0) return 0; @@ -314,25 +288,20 @@ static int ml_dsa_import(void *keydata, int selection, const OSSL_PARAM params[] #ifdef FIPS_MODULE if (res > 0) { res = ml_dsa_pairwise_test(key); - if (!res) + if (!res) { ossl_ml_dsa_key_reset(key); + ossl_set_error_state(OSSL_SELF_TEST_TYPE_PCT_IMPORT); + } } #endif /* FIPS_MODULE */ return res; } -static const OSSL_PARAM *ml_dsa_import_types(int selection) +static const OSSL_PARAM *ml_dsa_imexport_types(int selection) { if ((selection & OSSL_KEYMGMT_SELECT_KEYPAIR) == 0) return NULL; - return ml_dsa_import_params_list; -} - -static const OSSL_PARAM *ml_dsa_export_types(int selection) -{ - if ((selection & OSSL_KEYMGMT_SELECT_KEYPAIR) == 0) - return NULL; - return ml_dsa_export_params_list; + return ml_dsa_key_type_params_list; } static const OSSL_PARAM *ml_dsa_gettable_params(void *provctx) @@ -516,8 +485,10 @@ static void *ml_dsa_gen(void *genctx, int evp_type) goto err; } #ifdef FIPS_MODULE - if (!ml_dsa_pairwise_test(key)) + if (!ml_dsa_pairwise_test(key)) { + ossl_set_error_state(OSSL_SELF_TEST_TYPE_PCT); goto err; + } #endif return key; err: @@ -594,9 +565,9 @@ static void ml_dsa_gen_cleanup(void *genctx) { OSSL_FUNC_KEYMGMT_HAS, (void (*)(void))ml_dsa_has }, \ { OSSL_FUNC_KEYMGMT_MATCH, (void (*)(void))ml_dsa_match }, \ { OSSL_FUNC_KEYMGMT_IMPORT, (void (*)(void))ml_dsa_import }, \ - { OSSL_FUNC_KEYMGMT_IMPORT_TYPES, (void (*)(void))ml_dsa_import_types }, \ + { OSSL_FUNC_KEYMGMT_IMPORT_TYPES, (void (*)(void))ml_dsa_imexport_types }, \ { OSSL_FUNC_KEYMGMT_EXPORT, (void (*)(void))ml_dsa_export }, \ - { OSSL_FUNC_KEYMGMT_EXPORT_TYPES, (void (*)(void))ml_dsa_export_types }, \ + { OSSL_FUNC_KEYMGMT_EXPORT_TYPES, (void (*)(void))ml_dsa_imexport_types }, \ DISPATCH_LOAD_FN { OSSL_FUNC_KEYMGMT_GET_PARAMS, (void (*)(void))ml_dsa_get_params }, \ { OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS, (void (*)(void))ml_dsa_gettable_params }, \ { OSSL_FUNC_KEYMGMT_VALIDATE, (void (*)(void))ml_dsa_validate }, \ diff --git a/providers/implementations/keymgmt/ml_dsa_kmgmt.inc.in b/providers/implementations/keymgmt/ml_dsa_kmgmt.inc.in index 9ab17f5f65..e23d4cdc9e 100644 --- a/providers/implementations/keymgmt/ml_dsa_kmgmt.inc.in +++ b/providers/implementations/keymgmt/ml_dsa_kmgmt.inc.in @@ -11,17 +11,10 @@ use OpenSSL::paramnames qw(produce_param_decoder); -} -{- produce_param_decoder('ml_dsa_import_params', +{- produce_param_decoder('ml_dsa_key_type_params', (['OSSL_PKEY_PARAM_ML_DSA_SEED', 'seed', 'octet_string'], ['OSSL_PKEY_PARAM_PUB_KEY', 'pubkey', 'octet_string'], ['OSSL_PKEY_PARAM_PRIV_KEY', 'privkey', 'octet_string'], - ['OSSL_PKEY_PARAM_PROPERTIES', 'propq', 'utf8_string'], - )); -} - -{- produce_param_decoder('ml_dsa_export_params', - (['OSSL_PKEY_PARAM_ML_DSA_SEED', 'seed', 'octet_string'], - ['OSSL_PKEY_PARAM_PUB_KEY', 'pubkey', 'octet_string'], - ['OSSL_PKEY_PARAM_PRIV_KEY', 'privkey', 'octet_string'] )); -} {- produce_param_decoder('ml_dsa_get_params', diff --git a/providers/implementations/keymgmt/ml_kem_kmgmt.c b/providers/implementations/keymgmt/ml_kem_kmgmt.c index d7f2d87685..49f26f0dae 100644 --- a/providers/implementations/keymgmt/ml_kem_kmgmt.c +++ b/providers/implementations/keymgmt/ml_kem_kmgmt.c @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -28,14 +28,11 @@ #include "prov/provider_ctx.h" #include "prov/securitycheck.h" #include "prov/ml_kem.h" -#define ml_kem_export_params_st -#define ml_kem_export_params_decoder #include "providers/implementations/keymgmt/ml_kem_kmgmt.inc" static OSSL_FUNC_keymgmt_new_fn ml_kem_512_new; static OSSL_FUNC_keymgmt_new_fn ml_kem_768_new; static OSSL_FUNC_keymgmt_new_fn ml_kem_1024_new; -static OSSL_FUNC_keymgmt_free_fn ml_kem_free_key; static OSSL_FUNC_keymgmt_gen_fn ml_kem_gen; static OSSL_FUNC_keymgmt_gen_init_fn ml_kem_512_gen_init; static OSSL_FUNC_keymgmt_gen_init_fn ml_kem_768_gen_init; @@ -55,8 +52,8 @@ static OSSL_FUNC_keymgmt_match_fn ml_kem_match; static OSSL_FUNC_keymgmt_validate_fn ml_kem_validate; static OSSL_FUNC_keymgmt_import_fn ml_kem_import; static OSSL_FUNC_keymgmt_export_fn ml_kem_export; -static OSSL_FUNC_keymgmt_import_types_fn ml_kem_import_types; -static OSSL_FUNC_keymgmt_export_types_fn ml_kem_export_types; +static OSSL_FUNC_keymgmt_import_types_fn ml_kem_imexport_types; +static OSSL_FUNC_keymgmt_export_types_fn ml_kem_imexport_types; static OSSL_FUNC_keymgmt_dup_fn ml_kem_dup; static const int minimal_selection = OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS @@ -93,9 +90,7 @@ static int ml_kem_pairwise_test(const ML_KEM_KEY *key, int key_flags) return 1; #ifdef FIPS_MODULE /* During self test, it is a waste to do this test */ - if (ossl_fips_self_testing() - || ossl_self_test_in_progress(ST_ID_ASYM_KEYGEN_ML_KEM) - || ossl_self_test_in_progress(ST_ID_KEM_ML_KEM)) + if (ossl_fips_self_testing()) return 1; /* @@ -166,13 +161,6 @@ ML_KEM_KEY *ossl_prov_ml_kem_new(PROV_CTX *ctx, const char *propq, int evp_type) if (!ossl_prov_is_running()) return NULL; - -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(ctx), - ST_ID_ASYM_KEYGEN_ML_KEM)) - return NULL; -#endif - /* * When decoding, if the key ends up "loaded" into the same provider, these * are the correct config settings, otherwise, new values will be assigned @@ -342,17 +330,10 @@ err: return ret; } -static const OSSL_PARAM *ml_kem_import_types(int selection) +static const OSSL_PARAM *ml_kem_imexport_types(int selection) { if ((selection & OSSL_KEYMGMT_SELECT_KEYPAIR) != 0) - return ml_kem_import_params_list; - return NULL; -} - -static const OSSL_PARAM *ml_kem_export_types(int selection) -{ - if ((selection & OSSL_KEYMGMT_SELECT_KEYPAIR) != 0) - return ml_kem_export_params_list; + return ml_kem_key_type_params_list; return NULL; } @@ -393,15 +374,19 @@ static int check_prvenc(const uint8_t *prvenc, ML_KEM_KEY *key) return 0; } -static int ml_kem_key_fromdata(ML_KEM_KEY *key, const OSSL_PARAM params[], +static int ml_kem_key_fromdata(ML_KEM_KEY *key, + const OSSL_PARAM params[], int include_private) { const void *pubenc = NULL, *prvenc = NULL, *seedenc = NULL; size_t publen = 0, prvlen = 0, seedlen = 0, puboff; const ML_KEM_VINFO *v; - struct ml_kem_import_params_st p; + struct ml_kem_key_type_params_st p; - if (!ml_kem_import_params_decoder(params, &p)) + /* Invalid attempt to mutate a key, what is the right error to report? */ + if (key == NULL + || ossl_ml_kem_have_pubkey(key) + || !ml_kem_key_type_params_decoder(params, &p)) return 0; v = ossl_ml_kem_key_vinfo(key); @@ -459,12 +444,6 @@ static int ml_kem_key_fromdata(ML_KEM_KEY *key, const OSSL_PARAM params[], return 0; } } - if (p.propq != NULL) { - if (p.propq->data_type != OSSL_PARAM_UTF8_STRING) - return 0; - if (!ossl_ml_kem_key_fetch_digest(key, p.propq->data)) - return 0; - } if (seedlen != 0 && (prvlen == 0 || (key->prov_flags & ML_KEM_KEY_PREFER_SEED))) { @@ -486,21 +465,19 @@ static int ml_kem_import(void *vkey, int selection, const OSSL_PARAM params[]) int include_private; int res; - if (!ossl_prov_is_running() - || (selection & OSSL_KEYMGMT_SELECT_KEYPAIR) == 0 - || key == NULL) + if (!ossl_prov_is_running() || key == NULL) return 0; - if (ossl_ml_kem_have_pubkey(key)) { - /* Invalid attempt to mutate a key. */ - ERR_raise_data(ERR_LIB_PROV, PROV_R_KEY_IMMUTABLE_ONCE_SET, - "Keys are immutable once key material has been loaded or generated"); + + if ((selection & OSSL_KEYMGMT_SELECT_KEYPAIR) == 0) return 0; - } include_private = selection & OSSL_KEYMGMT_SELECT_PRIVATE_KEY ? 1 : 0; res = ml_kem_key_fromdata(key, params, include_private); if (res > 0 && include_private && !ml_kem_pairwise_test(key, key->prov_flags)) { +#ifdef FIPS_MODULE + ossl_set_error_state(OSSL_SELF_TEST_TYPE_PCT_IMPORT); +#endif ossl_ml_kem_key_reset(key); res = 0; } @@ -688,8 +665,9 @@ static int ml_kem_set_params(void *vkey, const OSSL_PARAM params[]) /* Key mutation is reportedly generally not allowed */ if (ossl_ml_kem_have_pubkey(key)) { - ERR_raise_data(ERR_LIB_PROV, PROV_R_KEY_IMMUTABLE_ONCE_SET, - "Keys are immutable once key material has been loaded or generated"); + ERR_raise_data(ERR_LIB_PROV, + PROV_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE, + "ML-KEM keys cannot be mutated"); return 0; } @@ -790,6 +768,7 @@ static void *ml_kem_gen(void *vgctx, OSSL_CALLBACK *osslcb, void *cbarg) if (genok) { #ifdef FIPS_MODULE if (!ml_kem_pairwise_test(key, ML_KEM_KEY_FIXED_PCT)) { + ossl_set_error_state(OSSL_SELF_TEST_TYPE_PCT); ossl_ml_kem_key_free(key); return NULL; } @@ -809,7 +788,7 @@ static void ml_kem_gen_cleanup(void *vgctx) return; if (gctx->seed != NULL) - OPENSSL_cleanse(gctx->seed, ML_KEM_SEED_BYTES); + OPENSSL_cleanse(gctx->seed, ML_KEM_RANDOM_BYTES); OPENSSL_free(gctx->propq); OPENSSL_free(gctx); } @@ -824,11 +803,6 @@ static void *ml_kem_dup(const void *vkey, int selection) return ossl_ml_kem_key_dup(key, selection); } -static void ml_kem_free_key(void *keydata) -{ - ossl_ml_kem_key_free((ML_KEM_KEY *)keydata); -} - #ifndef FIPS_MODULE #define DISPATCH_LOAD_FN \ { OSSL_FUNC_KEYMGMT_LOAD, (OSSL_FUNC)ml_kem_load }, @@ -851,7 +825,7 @@ static void ml_kem_free_key(void *keydata) } \ const OSSL_DISPATCH ossl_ml_kem_##bits##_keymgmt_functions[] = { \ { OSSL_FUNC_KEYMGMT_NEW, (OSSL_FUNC)ml_kem_##bits##_new }, \ - { OSSL_FUNC_KEYMGMT_FREE, (OSSL_FUNC)ml_kem_free_key }, \ + { OSSL_FUNC_KEYMGMT_FREE, (OSSL_FUNC)ossl_ml_kem_key_free }, \ { OSSL_FUNC_KEYMGMT_GET_PARAMS, (OSSL_FUNC)ml_kem_get_params }, \ { OSSL_FUNC_KEYMGMT_GETTABLE_PARAMS, (OSSL_FUNC)ml_kem_gettable_params }, \ { OSSL_FUNC_KEYMGMT_SET_PARAMS, (OSSL_FUNC)ml_kem_set_params }, \ @@ -866,9 +840,9 @@ static void ml_kem_free_key(void *keydata) { OSSL_FUNC_KEYMGMT_GEN_CLEANUP, (OSSL_FUNC)ml_kem_gen_cleanup }, \ DISPATCH_LOAD_FN { OSSL_FUNC_KEYMGMT_DUP, (OSSL_FUNC)ml_kem_dup }, \ { OSSL_FUNC_KEYMGMT_IMPORT, (OSSL_FUNC)ml_kem_import }, \ - { OSSL_FUNC_KEYMGMT_IMPORT_TYPES, (OSSL_FUNC)ml_kem_import_types }, \ + { OSSL_FUNC_KEYMGMT_IMPORT_TYPES, (OSSL_FUNC)ml_kem_imexport_types }, \ { OSSL_FUNC_KEYMGMT_EXPORT, (OSSL_FUNC)ml_kem_export }, \ - { OSSL_FUNC_KEYMGMT_EXPORT_TYPES, (OSSL_FUNC)ml_kem_export_types }, \ + { OSSL_FUNC_KEYMGMT_EXPORT_TYPES, (OSSL_FUNC)ml_kem_imexport_types }, \ OSSL_DISPATCH_END \ } DECLARE_VARIANT(512); diff --git a/providers/implementations/keymgmt/ml_kem_kmgmt.inc.in b/providers/implementations/keymgmt/ml_kem_kmgmt.inc.in index 76ef7fd571..329685ae2d 100644 --- a/providers/implementations/keymgmt/ml_kem_kmgmt.inc.in +++ b/providers/implementations/keymgmt/ml_kem_kmgmt.inc.in @@ -11,16 +11,10 @@ use OpenSSL::paramnames qw(produce_param_decoder); -} -{- produce_param_decoder('ml_kem_import_params', +{- produce_param_decoder('ml_kem_key_type_params', (['OSSL_PKEY_PARAM_ML_KEM_SEED', 'seed', 'octet_string'], ['OSSL_PKEY_PARAM_PRIV_KEY', 'privkey', 'octet_string'], ['OSSL_PKEY_PARAM_PUB_KEY', 'pubkey', 'octet_string'], - ['OSSL_PKEY_PARAM_PROPERTIES', 'propq', 'utf8_string'] - )); -} -{- produce_param_decoder('ml_kem_export_params', - (['OSSL_PKEY_PARAM_ML_KEM_SEED', 'seed', 'octet_string'], - ['OSSL_PKEY_PARAM_PRIV_KEY', 'privkey', 'octet_string'], - ['OSSL_PKEY_PARAM_PUB_KEY', 'pubkey', 'octet_string'] )); -} {- produce_param_decoder('ml_kem_get_params', diff --git a/providers/implementations/keymgmt/mlx_kmgmt.c b/providers/implementations/keymgmt/mlx_kmgmt.c index 00ac258682..b533468aaa 100644 --- a/providers/implementations/keymgmt/mlx_kmgmt.c +++ b/providers/implementations/keymgmt/mlx_kmgmt.c @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -50,14 +50,6 @@ static const ECDH_VINFO hybrid_vtable[] = { #if !defined(OPENSSL_NO_ECX) { "X25519", NULL, 32, 32, 32, 0, EVP_PKEY_ML_KEM_768 }, { "X448", NULL, 56, 56, 56, 0, EVP_PKEY_ML_KEM_1024 }, -#else - { NULL, NULL, 0, 0, 0, 0, NID_undef }, - { NULL, NULL, 0, 0, 0, 0, NID_undef }, -#endif -#if !defined(FIPS_MODULE) && !defined(OPENSSL_NO_SM2) - { "curveSM2", "SM2", 65, 32, 32, 1, EVP_PKEY_ML_KEM_768 }, -#else - { NULL, NULL, 0, 0, 0, 0, NID_undef }, #endif }; @@ -719,17 +711,15 @@ static void *mlx_kem_dup(const void *vkey, int selection) || (ret = OPENSSL_memdup(key, sizeof(*ret))) == NULL) return NULL; - ret->mkey = ret->xkey = NULL; - - if (key->propq != NULL - && (ret->propq = OPENSSL_strdup(key->propq)) == NULL) { + if (ret->propq != NULL + && (ret->propq = OPENSSL_strdup(ret->propq)) == NULL) { OPENSSL_free(ret); return NULL; } /* Absent key material, nothing left to do */ - if (key->mkey == NULL) { - if (key->xkey == NULL) + if (ret->mkey == NULL) { + if (ret->xkey == NULL) return ret; /* Fail if the source key is an inconsistent state */ OPENSSL_free(ret->propq); @@ -739,6 +729,7 @@ static void *mlx_kem_dup(const void *vkey, int selection) switch (selection & OSSL_KEYMGMT_SELECT_KEYPAIR) { case 0: + ret->xkey = ret->mkey = NULL; ret->state = MLX_HAVE_NOKEYS; return ret; case OSSL_KEYMGMT_SELECT_KEYPAIR: @@ -803,6 +794,3 @@ DECLARE_DISPATCH(p384, 1); DECLARE_DISPATCH(x25519, 2); DECLARE_DISPATCH(x448, 3); #endif -#if !defined(FIPS_MODULE) && !defined(OPENSSL_NO_SM2) -DECLARE_DISPATCH(curve_sm2, 4); -#endif diff --git a/providers/implementations/keymgmt/rsa_kmgmt.c b/providers/implementations/keymgmt/rsa_kmgmt.c index 06b4312998..f8e72b0f19 100644 --- a/providers/implementations/keymgmt/rsa_kmgmt.c +++ b/providers/implementations/keymgmt/rsa_kmgmt.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -29,9 +29,7 @@ #include "internal/param_build_set.h" static OSSL_FUNC_keymgmt_new_fn rsa_newdata; -static OSSL_FUNC_keymgmt_new_ex_fn rsa_newdata_ex; static OSSL_FUNC_keymgmt_new_fn rsapss_newdata; -static OSSL_FUNC_keymgmt_new_ex_fn rsapss_newdata_ex; static OSSL_FUNC_keymgmt_gen_init_fn rsa_gen_init; static OSSL_FUNC_keymgmt_gen_init_fn rsapss_gen_init; static OSSL_FUNC_keymgmt_gen_set_params_fn rsa_gen_set_params; @@ -77,91 +75,36 @@ static int pss_params_fromdata(RSA_PSS_PARAMS_30 *pss_params, int *defaults_set, return 1; } -/* - * If the application actually created a legacy RSA object and assigned it to - * the EVP_PKEY, then we get hold of that object here. We return 0 if we hit - * a fatal error or 1 otherwise. We may return 1 but with *rsa set to NULL. - */ -static int get_legacy_rsa_object(OSSL_LIB_CTX *libctx, RSA **rsa, const OSSL_PARAM params[]) -{ -#ifndef FIPS_MODULE - const OSSL_PARAM *p; - - if (params == NULL) - return 1; - p = OSSL_PARAM_locate_const(params, "legacy-object"); - if (p == NULL) - return 1; - /* - * This only works because we are in the default provider. We are not - * normally allowed to pass complex objects across the provider boundary - * like this. - */ - if (OSSL_PARAM_get_octet_ptr(p, (const void **)rsa, NULL) && *rsa != NULL) { - if (ossl_lib_ctx_get_concrete(ossl_rsa_get0_libctx(*rsa)) != ossl_lib_ctx_get_concrete(libctx)) { - *rsa = NULL; - return 1; - } - if (!RSA_up_ref(*rsa)) - return 0; - } -#endif - - return 1; -} - -static void *rsa_newdata_ex(void *provctx, const OSSL_PARAM params[]) -{ - OSSL_LIB_CTX *libctx = PROV_LIBCTX_OF(provctx); - RSA *rsa = NULL; - - if (!ossl_prov_is_running()) - return NULL; - - if (!get_legacy_rsa_object(libctx, &rsa, params)) - return NULL; - - if (rsa == NULL) { - rsa = ossl_rsa_new_with_ctx(libctx); - if (rsa != NULL) { - RSA_clear_flags(rsa, RSA_FLAG_TYPE_MASK); - RSA_set_flags(rsa, RSA_FLAG_TYPE_RSA); - } - } - - return rsa; -} - static void *rsa_newdata(void *provctx) -{ - return rsa_newdata_ex(provctx, NULL); -} - -static void *rsapss_newdata_ex(void *provctx, const OSSL_PARAM params[]) { OSSL_LIB_CTX *libctx = PROV_LIBCTX_OF(provctx); - RSA *rsa = NULL; + RSA *rsa; if (!ossl_prov_is_running()) return NULL; - if (!get_legacy_rsa_object(libctx, &rsa, params)) - return NULL; - - if (rsa == NULL) { - rsa = ossl_rsa_new_with_ctx(libctx); - if (rsa != NULL) { - RSA_clear_flags(rsa, RSA_FLAG_TYPE_MASK); - RSA_set_flags(rsa, RSA_FLAG_TYPE_RSASSAPSS); - } + rsa = ossl_rsa_new_with_ctx(libctx); + if (rsa != NULL) { + RSA_clear_flags(rsa, RSA_FLAG_TYPE_MASK); + RSA_set_flags(rsa, RSA_FLAG_TYPE_RSA); } - return rsa; } static void *rsapss_newdata(void *provctx) { - return rsapss_newdata_ex(provctx, NULL); + OSSL_LIB_CTX *libctx = PROV_LIBCTX_OF(provctx); + RSA *rsa; + + if (!ossl_prov_is_running()) + return NULL; + + rsa = ossl_rsa_new_with_ctx(libctx); + if (rsa != NULL) { + RSA_clear_flags(rsa, RSA_FLAG_TYPE_MASK); + RSA_set_flags(rsa, RSA_FLAG_TYPE_RSASSAPSS); + } + return rsa; } static void rsa_freedata(void *keydata) @@ -773,7 +716,6 @@ static const char *rsa_query_operation_name(int operation_id) const OSSL_DISPATCH ossl_rsa_keymgmt_functions[] = { { OSSL_FUNC_KEYMGMT_NEW, (void (*)(void))rsa_newdata }, - { OSSL_FUNC_KEYMGMT_NEW_EX, (void (*)(void))rsa_newdata_ex }, { OSSL_FUNC_KEYMGMT_GEN_INIT, (void (*)(void))rsa_gen_init }, { OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS, (void (*)(void))rsa_gen_set_params }, @@ -798,7 +740,6 @@ const OSSL_DISPATCH ossl_rsa_keymgmt_functions[] = { const OSSL_DISPATCH ossl_rsapss_keymgmt_functions[] = { { OSSL_FUNC_KEYMGMT_NEW, (void (*)(void))rsapss_newdata }, - { OSSL_FUNC_KEYMGMT_NEW_EX, (void (*)(void))rsapss_newdata_ex }, { OSSL_FUNC_KEYMGMT_GEN_INIT, (void (*)(void))rsapss_gen_init }, { OSSL_FUNC_KEYMGMT_GEN_SET_PARAMS, (void (*)(void))rsa_gen_set_params }, { OSSL_FUNC_KEYMGMT_GEN_SETTABLE_PARAMS, diff --git a/providers/implementations/keymgmt/slh_dsa_kmgmt.c b/providers/implementations/keymgmt/slh_dsa_kmgmt.c index 766953d265..c1c4ce5383 100644 --- a/providers/implementations/keymgmt/slh_dsa_kmgmt.c +++ b/providers/implementations/keymgmt/slh_dsa_kmgmt.c @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -45,13 +45,22 @@ static OSSL_FUNC_keymgmt_dup_fn slh_dsa_dup_key; #define SLH_DSA_POSSIBLE_SELECTIONS (OSSL_KEYMGMT_SELECT_KEYPAIR) +#ifdef FIPS_MODULE +static FIPS_DEFERRED_TEST slh_key_gen_deferred_tests[] = { + { "SLH-DSA-SHA2-128f", + FIPS_DEFERRED_KAT_ASYM_KEYGEN, + FIPS_DEFERRED_TEST_INIT }, + { NULL, 0, 0 }, +}; +#endif + static int slh_dsa_self_check(OSSL_LIB_CTX *libctx) { if (!ossl_prov_is_running()) return 0; #ifdef FIPS_MODULE - return ossl_deferred_self_test(libctx, ST_ID_ASYM_KEYGEN_SLH_DSA); + return FIPS_deferred_self_tests(libctx, slh_key_gen_deferred_tests); #else return 1; #endif @@ -309,7 +318,7 @@ static int slh_dsa_fips140_pairwise_test(const SLH_DSA_KEY *key, /* During self test, it is a waste to do this test */ if (ossl_fips_self_testing() - || ossl_self_test_in_progress(ST_ID_ASYM_KEYGEN_SLH_DSA)) + || slh_key_gen_deferred_tests[0].state == FIPS_DEFERRED_TEST_IN_PROGRESS) return 1; if (ctx == NULL) { @@ -372,8 +381,10 @@ static void *slh_dsa_gen(void *genctx, const char *alg) gctx->entropy, gctx->entropy_len)) goto err; #ifdef FIPS_MODULE - if (!slh_dsa_fips140_pairwise_test(key, ctx)) + if (!slh_dsa_fips140_pairwise_test(key, ctx)) { + ossl_set_error_state(OSSL_SELF_TEST_TYPE_PCT); goto err; + } #endif /* FIPS_MODULE */ ossl_slh_dsa_hash_ctx_free(ctx); return key; diff --git a/providers/implementations/macs/cmac_prov.c b/providers/implementations/macs/cmac_prov.c index 7e9a3a9c21..9fd6cd8e51 100644 --- a/providers/implementations/macs/cmac_prov.c +++ b/providers/implementations/macs/cmac_prov.c @@ -139,7 +139,7 @@ static int tdes_check_param(struct cmac_data_st *macctx, OSSL_PARAM *p, if (EVP_CIPHER_is_a(cipher, "DES-EDE3-CBC")) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(macctx, OSSL_FIPS_IND_SETTABLE0, libctx, "CMAC", "Triple-DES", - FIPS_CONFIG_TDES_ENCRYPT_DISABLED)) + ossl_fips_config_tdes_encrypt_disallowed)) return 0; OSSL_FIPS_IND_GET_PARAM(macctx, p, state, OSSL_FIPS_IND_SETTABLE0, OSSL_CIPHER_PARAM_FIPS_ENCRYPT_CHECK) @@ -266,7 +266,7 @@ static int cmac_set_ctx_params(void *vmacctx, const OSSL_PARAM params[]) && !EVP_CIPHER_is_a(cipher, "AES-192-CBC") && !EVP_CIPHER_is_a(cipher, "AES-128-CBC") && !EVP_CIPHER_is_a(cipher, "DES-EDE3-CBC")) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_CIPHER); + ERR_raise(ERR_LIB_PROV, EVP_R_UNSUPPORTED_CIPHER); return 0; } } diff --git a/providers/implementations/macs/hmac_prov.c b/providers/implementations/macs/hmac_prov.c index 201d311bfe..388e95ad8a 100644 --- a/providers/implementations/macs/hmac_prov.c +++ b/providers/implementations/macs/hmac_prov.c @@ -171,7 +171,7 @@ static int hmac_setkey(struct hmac_data_st *macctx, if (!approved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(macctx, OSSL_FIPS_IND_SETTABLE0, libctx, "HMAC", "keysize", - FIPS_CONFIG_HMAC_KEY_CHECK)) { + ossl_fips_config_hmac_key_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); return 0; } @@ -239,7 +239,8 @@ static int hmac_update(void *vmacctx, const unsigned char *data, datalen, macctx->tls_data_size, macctx->key, - macctx->keylen); + macctx->keylen, + 0); } return HMAC_Update(macctx->ctx, data, datalen); diff --git a/providers/implementations/macs/kmac_prov.c b/providers/implementations/macs/kmac_prov.c index 97e23261a0..f4726e88ab 100644 --- a/providers/implementations/macs/kmac_prov.c +++ b/providers/implementations/macs/kmac_prov.c @@ -1,5 +1,5 @@ /* - * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2018-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -62,7 +62,6 @@ #include "prov/providercommon.h" #include "internal/cryptlib.h" /* ossl_assert */ #include "providers/implementations/macs/kmac_prov.inc" -#include "crypto/sha.h" /* * Forward declaration of everything implemented here. This is not strictly @@ -140,8 +139,18 @@ struct kmac_data_st { OSSL_FIPS_IND_DECLARE }; +static int encode_string(unsigned char *out, size_t out_max_len, size_t *out_len, + const unsigned char *in, size_t in_len); +static int right_encode(unsigned char *out, size_t out_max_len, size_t *out_len, + size_t bits); +static int bytepad(unsigned char *out, size_t *out_len, + const unsigned char *in1, size_t in1_len, + const unsigned char *in2, size_t in2_len, + size_t w); static int kmac_bytepad_encode_key(unsigned char *out, size_t out_max_len, - size_t *out_len, const unsigned char *in, size_t in_len, size_t w); + size_t *out_len, + const unsigned char *in, size_t in_len, + size_t w); static void kmac_free(void *vmacctx) { @@ -278,7 +287,7 @@ static int kmac_setkey(struct kmac_data_st *kctx, const unsigned char *key, if (!OSSL_FIPS_IND_ON_UNAPPROVED(kctx, OSSL_FIPS_IND_SETTABLE1, PROV_LIBCTX_OF(kctx->provctx), "KMAC", "Key size", - FIPS_CONFIG_KMAC_KEY_CHECK)) { + ossl_fips_config_kmac_key_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); return 0; } @@ -340,7 +349,7 @@ static int kmac_init(void *vmacctx, const unsigned char *key, (void)kmac_set_ctx_params(kctx, cparams); } - if (!ossl_sp800_185_bytepad(NULL, 0, &out_len, kmac_string, sizeof(kmac_string), + if (!bytepad(NULL, &out_len, kmac_string, sizeof(kmac_string), kctx->custom, kctx->custom_len, block_len)) { ERR_raise(ERR_LIB_PROV, ERR_R_INTERNAL_ERROR); return 0; @@ -348,7 +357,7 @@ static int kmac_init(void *vmacctx, const unsigned char *key, out = OPENSSL_malloc(out_len); if (out == NULL) return 0; - res = ossl_sp800_185_bytepad(out, out_len, NULL, kmac_string, sizeof(kmac_string), + res = bytepad(out, NULL, kmac_string, sizeof(kmac_string), kctx->custom, kctx->custom_len, block_len) && EVP_DigestUpdate(ctx, out, out_len) && EVP_DigestUpdate(ctx, kctx->key, kctx->key_len); @@ -379,7 +388,7 @@ static int kmac_final(void *vmacctx, unsigned char *out, size_t *outl, /* KMAC XOF mode sets the encoded length to 0 */ lbits = (kctx->xof_mode ? 0 : (kctx->out_len * 8)); - ok = ossl_sp800_185_right_encode(encoded_outlen, sizeof(encoded_outlen), &len, lbits) + ok = right_encode(encoded_outlen, sizeof(encoded_outlen), &len, lbits) && EVP_DigestUpdate(ctx, encoded_outlen, len) && EVP_DigestFinalXOF(ctx, out, kctx->out_len); *outl = kctx->out_len; @@ -463,7 +472,7 @@ static int kmac_set_ctx_params(void *vmacctx, const OSSL_PARAM *params) if (!OSSL_FIPS_IND_ON_UNAPPROVED(kctx, OSSL_FIPS_IND_SETTABLE0, PROV_LIBCTX_OF(kctx->provctx), "KMAC", "length", - FIPS_CONFIG_NO_SHORT_MAC)) { + ossl_fips_config_no_short_mac)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_OUTPUT_LENGTH); return 0; } @@ -484,8 +493,7 @@ static int kmac_set_ctx_params(void *vmacctx, const OSSL_PARAM *params) ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_CUSTOM_LENGTH); return 0; } - if (!ossl_sp800_185_encode_string(kctx->custom, - sizeof(kctx->custom), &kctx->custom_len, + if (!encode_string(kctx->custom, sizeof(kctx->custom), &kctx->custom_len, p.custom->data, p.custom->data_size)) return 0; } @@ -493,18 +501,156 @@ static int kmac_set_ctx_params(void *vmacctx, const OSSL_PARAM *params) return 1; } +/* Encoding/Padding Methods. */ + +/* Returns the number of bytes required to store 'bits' into a byte array */ +static unsigned int get_encode_size(size_t bits) +{ + unsigned int cnt = 0, sz = sizeof(size_t); + + while (bits && (cnt < sz)) { + ++cnt; + bits >>= 8; + } + /* If bits is zero 1 byte is required */ + if (cnt == 0) + cnt = 1; + return cnt; +} + +/* + * Convert an integer into bytes . The number of bytes is appended + * to the end of the buffer. Returns an array of bytes 'out' of size + * *out_len. + * + * e.g if bits = 32, out[2] = { 0x20, 0x01 } + */ +static int right_encode(unsigned char *out, size_t out_max_len, size_t *out_len, + size_t bits) +{ + unsigned int len = get_encode_size(bits); + int i; + + if (len >= out_max_len) { + ERR_raise(ERR_LIB_PROV, PROV_R_LENGTH_TOO_LARGE); + return 0; + } + + /* MSB's are at the start of the bytes array */ + for (i = len - 1; i >= 0; --i) { + out[i] = (unsigned char)(bits & 0xFF); + bits >>= 8; + } + /* Tack the length onto the end */ + out[len] = (unsigned char)len; + + /* The Returned length includes the tacked on byte */ + *out_len = len + 1; + return 1; +} + +/* + * Encodes a string with a left encoded length added. Note that the + * in_len is converted to bits (*8). + * + * e.g- in="KMAC" gives out[6] = { 0x01, 0x20, 0x4B, 0x4D, 0x41, 0x43 } + * len bits K M A C + */ +static int encode_string(unsigned char *out, size_t out_max_len, size_t *out_len, + const unsigned char *in, size_t in_len) +{ + if (in == NULL) { + *out_len = 0; + } else { + size_t i, bits, len, sz; + + bits = 8 * in_len; + len = get_encode_size(bits); + sz = 1 + len + in_len; + + if (sz > out_max_len) { + ERR_raise(ERR_LIB_PROV, PROV_R_LENGTH_TOO_LARGE); + return 0; + } + + out[0] = (unsigned char)len; + for (i = len; i > 0; --i) { + out[i] = (bits & 0xFF); + bits >>= 8; + } + memcpy(out + len + 1, in, in_len); + *out_len = sz; + } + return 1; +} + +/* + * Returns a zero padded encoding of the inputs in1 and an optional + * in2 (can be NULL). The padded output must be a multiple of the blocksize 'w'. + * The value of w is in bytes (< 256). + * + * The returned output is: + * zero_padded(multiple of w, (left_encode(w) || in1 [|| in2]) + */ +static int bytepad(unsigned char *out, size_t *out_len, + const unsigned char *in1, size_t in1_len, + const unsigned char *in2, size_t in2_len, size_t w) +{ + size_t len; + unsigned char *p = out; + size_t sz = w; + + if (out == NULL) { + if (out_len == NULL) { + ERR_raise(ERR_LIB_PROV, ERR_R_PASSED_NULL_PARAMETER); + return 0; + } + sz = 2 + in1_len + (in2 != NULL ? in2_len : 0); + *out_len = (sz + w - 1) / w * w; + return 1; + } + + if (!ossl_assert(w <= 255)) + return 0; + + /* Left encoded w */ + *p++ = 1; + *p++ = (unsigned char)w; + /* || in1 */ + memcpy(p, in1, in1_len); + p += in1_len; + /* [ || in2 ] */ + if (in2 != NULL && in2_len > 0) { + memcpy(p, in2, in2_len); + p += in2_len; + } + /* Figure out the pad size (divisible by w) */ + len = p - out; + sz = (len + w - 1) / w * w; + /* zero pad the end of the buffer */ + if (sz != len) + memset(p, 0, sz - len); + if (out_len != NULL) + *out_len = sz; + return 1; +} + /* Returns out = bytepad(encode_string(in), w) */ static int kmac_bytepad_encode_key(unsigned char *out, size_t out_max_len, - size_t *out_len, const unsigned char *in, size_t in_len, size_t w) + size_t *out_len, + const unsigned char *in, size_t in_len, + size_t w) { unsigned char tmp[KMAC_MAX_KEY + KMAC_MAX_ENCODED_HEADER_LEN]; size_t tmp_len; - if (!ossl_sp800_185_encode_string(tmp, sizeof(tmp), &tmp_len, in, in_len)) + if (!encode_string(tmp, sizeof(tmp), &tmp_len, in, in_len)) return 0; - if (!ossl_sp800_185_bytepad(NULL, out_max_len, out_len, tmp, tmp_len, NULL, 0, w)) + if (!bytepad(NULL, out_len, tmp, tmp_len, NULL, 0, w)) return 0; - return ossl_sp800_185_bytepad(out, out_max_len, NULL, tmp, tmp_len, NULL, 0, w); + if (!ossl_assert(*out_len <= out_max_len)) + return 0; + return bytepad(out, NULL, tmp, tmp_len, NULL, 0, w); } #define IMPLEMENT_KMAC_TABLE(size, funcname, newname) \ diff --git a/providers/implementations/macs/poly1305_prov.c b/providers/implementations/macs/poly1305_prov.c index a9ca6e4f68..cfa59b2b49 100644 --- a/providers/implementations/macs/poly1305_prov.c +++ b/providers/implementations/macs/poly1305_prov.c @@ -42,7 +42,6 @@ static OSSL_FUNC_mac_final_fn poly1305_final; struct poly1305_data_st { void *provctx; int updated; - int key_set; POLY1305 poly1305; /* Poly1305 data */ }; @@ -86,13 +85,12 @@ static size_t poly1305_size(void) static int poly1305_setkey(struct poly1305_data_st *ctx, const unsigned char *key, size_t keylen) { - if (key == NULL || keylen != POLY1305_KEY_SIZE) { + if (keylen != POLY1305_KEY_SIZE) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); return 0; } Poly1305_Init(&ctx->poly1305, key); ctx->updated = 0; - ctx->key_set = 1; return 1; } @@ -115,10 +113,6 @@ static int poly1305_update(void *vmacctx, const unsigned char *data, { struct poly1305_data_st *ctx = vmacctx; - if (!ctx->key_set) { - ERR_raise(ERR_LIB_PROV, PROV_R_NO_KEY_SET); - return 0; - } ctx->updated = 1; if (datalen == 0) return 1; @@ -135,10 +129,6 @@ static int poly1305_final(void *vmacctx, unsigned char *out, size_t *outl, if (!ossl_prov_is_running()) return 0; - if (!ctx->key_set) { - ERR_raise(ERR_LIB_PROV, PROV_R_NO_KEY_SET); - return 0; - } ctx->updated = 1; Poly1305_Final(&ctx->poly1305, out); *outl = poly1305_size(); diff --git a/providers/implementations/rands/drbg.c b/providers/implementations/rands/drbg.c index 50027b9b0b..9e80ef5b1f 100644 --- a/providers/implementations/rands/drbg.c +++ b/providers/implementations/rands/drbg.c @@ -1010,7 +1010,7 @@ int ossl_drbg_verify_digest(PROV_DRBG *drbg, OSSL_LIB_CTX *libctx, if (!approved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(drbg, OSSL_FIPS_IND_SETTABLE0, libctx, "DRBG", "Digest", - FIPS_CONFIG_DRBG_TRUNC_DIGEST)) { + ossl_fips_config_restricted_drbg_digests)) { ERR_raise(ERR_LIB_PROV, PROV_R_DIGEST_NOT_ALLOWED); return 0; } diff --git a/providers/implementations/rands/drbg_ctr.c b/providers/implementations/rands/drbg_ctr.c index f99f8f198f..0988d126bb 100644 --- a/providers/implementations/rands/drbg_ctr.c +++ b/providers/implementations/rands/drbg_ctr.c @@ -1,5 +1,5 @@ /* - * Copyright 2011-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2011-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -24,7 +24,6 @@ #include "crypto/evp/evp_local.h" #include "internal/provider.h" #include "internal/common.h" -#include "internal/fips.h" #define drbg_ctr_get_ctx_params_st drbg_get_ctx_params_st #define drbg_ctr_set_ctx_params_st drbg_set_ctx_params_st @@ -71,12 +70,12 @@ typedef struct rand_drbg_ctr_st { static void inc_128(PROV_DRBG_CTR *ctr) { unsigned char *p = &ctr->V[0]; - uint32_t n = 16, c = 1; + u32 n = 16, c = 1; do { --n; c += p[n]; - p[n] = (uint8_t)c; + p[n] = (u8)c; c >>= 8; } while (n); } @@ -391,12 +390,12 @@ static int drbg_ctr_reseed_wrapper(void *vdrbg, int prediction_resistance, static void ctr96_inc(unsigned char *counter) { - uint32_t n = 12, c = 1; + u32 n = 12, c = 1; do { --n; c += counter[n]; - counter[n] = (uint8_t)c; + counter[n] = (u8)c; c >>= 8; } while (n); } @@ -647,12 +646,6 @@ static int drbg_ctr_new(PROV_DRBG *drbg) static void *drbg_ctr_new_wrapper(void *provctx, void *parent, const OSSL_DISPATCH *parent_dispatch) { -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_DRBG_CTR)) - return NULL; -#endif - return ossl_rand_drbg_new(provctx, parent, parent_dispatch, &drbg_ctr_new, &drbg_ctr_free, &drbg_ctr_instantiate, &drbg_ctr_uninstantiate, diff --git a/providers/implementations/rands/drbg_hash.c b/providers/implementations/rands/drbg_hash.c index d024336d58..439728a760 100644 --- a/providers/implementations/rands/drbg_hash.c +++ b/providers/implementations/rands/drbg_hash.c @@ -1,5 +1,5 @@ /* - * Copyright 2011-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2011-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -25,7 +25,6 @@ #include "prov/drbg.h" #include "crypto/evp.h" #include "crypto/evp/evp_local.h" -#include "internal/fips.h" #include "internal/provider.h" #define drbg_hash_get_ctx_params_st drbg_get_ctx_params_st @@ -455,12 +454,6 @@ static int drbg_hash_new(PROV_DRBG *ctx) static void *drbg_hash_new_wrapper(void *provctx, void *parent, const OSSL_DISPATCH *parent_dispatch) { -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_DRBG_HASH)) - return NULL; -#endif - return ossl_rand_drbg_new(provctx, parent, parent_dispatch, &drbg_hash_new, &drbg_hash_free, &drbg_hash_instantiate, &drbg_hash_uninstantiate, diff --git a/providers/implementations/rands/drbg_hmac.c b/providers/implementations/rands/drbg_hmac.c index 371767acb2..ec2a6317b1 100644 --- a/providers/implementations/rands/drbg_hmac.c +++ b/providers/implementations/rands/drbg_hmac.c @@ -1,5 +1,5 @@ /* - * Copyright 2011-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2011-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -22,7 +22,6 @@ #include "prov/drbg.h" #include "crypto/evp.h" #include "crypto/evp/evp_local.h" -#include "internal/fips.h" #include "internal/provider.h" #define drbg_hmac_get_ctx_params_st drbg_get_ctx_params_st @@ -347,12 +346,6 @@ static int drbg_hmac_new(PROV_DRBG *drbg) static void *drbg_hmac_new_wrapper(void *provctx, void *parent, const OSSL_DISPATCH *parent_dispatch) { -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_DRBG_HMAC)) - return NULL; -#endif - return ossl_rand_drbg_new(provctx, parent, parent_dispatch, &drbg_hmac_new, &drbg_hmac_free, &drbg_hmac_instantiate, &drbg_hmac_uninstantiate, @@ -443,9 +436,6 @@ static int drbg_fetch_algs_from_prov(const struct drbg_set_ctx_params_st *p, } else { goto done; } - if (!ossl_prov_macctx_load(macctx, NULL, NULL, p->digest, - p->propq, "HMAC", NULL, NULL, libctx)) - goto done; } ret = 1; diff --git a/providers/implementations/rands/seed_src_jitter.c b/providers/implementations/rands/seed_src_jitter.c index e73b1990a6..4b40cdb202 100644 --- a/providers/implementations/rands/seed_src_jitter.c +++ b/providers/implementations/rands/seed_src_jitter.c @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -291,6 +291,24 @@ static size_t jitter_get_seed(void *vseed, unsigned char **pout, return ret; } +#ifndef OPENSSL_NO_FIPS_JITTER +size_t ossl_rand_jitter_get_seed(unsigned char **pout, int entropy, size_t min_len, size_t max_len) +{ + size_t ret = 0; + OSSL_PARAM params[1] = { OSSL_PARAM_END }; + PROV_JITTER *s = jitter_new(NULL, NULL, NULL); + + if (s == NULL) + return ret; + if (!jitter_instantiate(s, 0, 0, NULL, 0, params)) + goto end; + ret = jitter_get_seed(s, pout, entropy, min_len, max_len, 0, NULL, 0); +end: + jitter_free(s); + return ret; +} +#endif + static void jitter_clear_seed(ossl_unused void *vdrbg, unsigned char *out, size_t outlen) { diff --git a/providers/implementations/rands/seeding/rand_cpu_arm64.c b/providers/implementations/rands/seeding/rand_cpu_arm64.c index 083b4826ae..76bbedf119 100644 --- a/providers/implementations/rands/seeding/rand_cpu_arm64.c +++ b/providers/implementations/rands/seeding/rand_cpu_arm64.c @@ -13,7 +13,7 @@ #include "prov/seeding.h" #ifdef OPENSSL_RAND_SEED_RDCPU -#include "arch/arm_arch.h" +#include "crypto/arm_arch.h" size_t OPENSSL_rndrrs_bytes(unsigned char *buf, size_t len); diff --git a/providers/implementations/rands/seeding/rand_unix.c b/providers/implementations/rands/seeding/rand_unix.c index 67b38cb719..47643d3c67 100644 --- a/providers/implementations/rands/seeding/rand_unix.c +++ b/providers/implementations/rands/seeding/rand_unix.c @@ -354,7 +354,7 @@ static ssize_t syscall_random(void *buf, size_t buflen) * internally. So we need to check errno for ENOSYS */ #if !defined(__DragonFly__) && !defined(__NetBSD__) && !defined(__FreeBSD__) -#if defined(__GNUC__) && defined(__ELF__) && !defined(__hpux) +#if defined(__GNUC__) && __GNUC__ >= 2 && defined(__ELF__) && !defined(__hpux) extern int getentropy(void *buffer, size_t length) __attribute__((weak)); if (getentropy != NULL) { @@ -396,7 +396,7 @@ static ssize_t syscall_random(void *buf, size_t buflen) return getrandom(buf, buflen, 0); #elif (defined(__FreeBSD__) || defined(__NetBSD__)) && defined(KERN_ARND) return sysctl_random(buf, buflen); -#elif defined(__wasi__) || defined(__EMSCRIPTEN__) +#elif defined(__wasi__) if (getentropy(buf, buflen) == 0) return (ssize_t)buflen; return -1; @@ -422,6 +422,11 @@ static int keep_random_devices_open = 1; && defined(OPENSSL_RAND_SEED_GETRANDOM) static void *shm_addr; +static void cleanup_shm(void) +{ + shmdt(shm_addr); +} + /* * Ensure that the system randomness source has been adequately seeded. * This is done by having the first start of libcrypto, wait until the device @@ -488,8 +493,8 @@ static int wait_random_seeded(void) * If this call fails, it isn't a big problem. */ shm_addr = shmat(shm_id, NULL, SHM_RDONLY); - if (shm_addr == (void *)-1) - shm_addr = NULL; + if (shm_addr != (void *)-1) + OPENSSL_atexit(&cleanup_shm); } } return seeded; @@ -578,14 +583,6 @@ void ossl_rand_pool_cleanup(void) for (i = 0; i < OSSL_NELEM(random_devices); i++) close_random_device(i); - -#if defined(__linux) && defined(DEVRANDOM_WAIT) \ - && defined(OPENSSL_RAND_SEED_GETRANDOM) - if (shm_addr != NULL) { - shmdt(shm_addr); - shm_addr = NULL; - } -#endif } void ossl_rand_pool_keep_random_devices_open(int keep) diff --git a/providers/implementations/rands/seeding/rand_win.c b/providers/implementations/rands/seeding/rand_win.c index e1350f7d80..63b523b729 100644 --- a/providers/implementations/rands/seeding/rand_win.c +++ b/providers/implementations/rands/seeding/rand_win.c @@ -7,7 +7,6 @@ * https://www.openssl.org/source/license.html */ -#include "internal/e_os.h" /* For windows.h */ #include "internal/cryptlib.h" #include #include "crypto/rand_pool.h" @@ -20,10 +19,10 @@ #error "Unsupported seeding method configured; must be os" #endif +#include /* On Windows Vista or higher use BCrypt instead of the legacy CryptoAPI */ -#if defined(_WIN32_WINNT) && _WIN32_WINNT >= 0x0600 \ - && ((defined(_MSC_VER) && _MSC_VER > 1500) \ - || (defined(__MINGW64_VERSION_MAJOR) && __MINGW64_VERSION_MAJOR >= 2)) +#if defined(_MSC_VER) && _MSC_VER > 1500 /* 1500 = Visual Studio 2008 */ \ + && defined(_WIN32_WINNT) && _WIN32_WINNT >= 0x0600 #define USE_BCRYPTGENRANDOM #endif @@ -71,7 +70,7 @@ size_t ossl_pool_acquire_entropy(RAND_POOL *pool) buffer = ossl_rand_pool_add_begin(pool, bytes_needed); if (buffer != NULL) { size_t bytes = 0; - if (BCryptGenRandom(NULL, buffer, (ULONG)bytes_needed, + if (BCryptGenRandom(NULL, buffer, bytes_needed, BCRYPT_USE_SYSTEM_PREFERRED_RNG) == STATUS_SUCCESS) bytes = bytes_needed; diff --git a/providers/implementations/rands/test_rng.c b/providers/implementations/rands/test_rng.c index c073b3e5bf..9a5f459881 100644 --- a/providers/implementations/rands/test_rng.c +++ b/providers/implementations/rands/test_rng.c @@ -170,9 +170,8 @@ static size_t test_rng_nonce(void *vtest, unsigned char *out, return 0; if (t->generate) { - if (out != NULL) - for (i = 0; i < min_noncelen; i++) - out[i] = gen_byte(t); + for (i = 0; i < min_noncelen; i++) + out[i] = gen_byte(t); return min_noncelen; } @@ -287,7 +286,7 @@ static int test_rng_enable_locking(void *vtest) if (t != NULL && t->lock == NULL) { t->lock = CRYPTO_THREAD_lock_new(); if (t->lock == NULL) { - ERR_raise(ERR_LIB_PROV, PROV_R_FAILED_TO_CREATE_LOCK); + ERR_raise(ERR_LIB_PROV, RAND_R_FAILED_TO_CREATE_LOCK); return 0; } } diff --git a/providers/implementations/signature/dsa_sig.c b/providers/implementations/signature/dsa_sig.c index c68980af76..24244748a7 100644 --- a/providers/implementations/signature/dsa_sig.c +++ b/providers/implementations/signature/dsa_sig.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -23,7 +23,6 @@ #include #include #include -#include "internal/fips.h" #include "internal/nelem.h" #include "internal/sizes.h" #include "internal/cryptlib.h" @@ -133,12 +132,6 @@ static void *dsa_newctx(void *provctx, const char *propq) if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_SIG_DSA_SHA256)) - return NULL; -#endif - pdsactx = OPENSSL_zalloc(sizeof(PROV_DSA_CTX)); if (pdsactx == NULL) return NULL; @@ -202,7 +195,7 @@ static int dsa_setup_md(PROV_DSA_CTX *ctx, OSSL_FIPS_IND_SETTABLE1, ctx->libctx, md_nid, sha1_allowed, 0, desc, - FIPS_CONFIG_SIGNATURE_DIGEST_CHECK)) + ossl_fips_config_signature_digest_check)) goto err; } #endif @@ -260,7 +253,7 @@ static int dsa_sign_check_approved(PROV_DSA_CTX *ctx, int signing, if (signing && !OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE2, ctx->libctx, desc, "DSA", - FIPS_CONFIG_DSA_SIGN_DISABLED)) + ossl_fips_config_dsa_sign_disallowed)) return 0; return 1; } @@ -272,7 +265,7 @@ static int dsa_check_key(PROV_DSA_CTX *ctx, int sign, const char *desc) if (!approved) { if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE0, ctx->libctx, desc, "DSA Key", - FIPS_CONFIG_SIGNATURE_DIGEST_CHECK)) { + ossl_fips_config_signature_digest_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); return 0; } @@ -641,14 +634,13 @@ static void *dsa_dupctx(void *vpdsactx) if (!ossl_prov_is_running()) return NULL; - if ((dstctx = OPENSSL_memdup(srcctx, sizeof(*srcctx))) == NULL) + dstctx = OPENSSL_zalloc(sizeof(*srcctx)); + if (dstctx == NULL) return NULL; + *dstctx = *srcctx; dstctx->dsa = NULL; dstctx->propq = NULL; - dstctx->md = NULL; - dstctx->mdctx = NULL; - dstctx->sig = NULL; if (srcctx->dsa != NULL && !DSA_up_ref(srcctx->dsa)) goto err; @@ -658,15 +650,18 @@ static void *dsa_dupctx(void *vpdsactx) goto err; dstctx->md = srcctx->md; - if (srcctx->mdctx != NULL - && (dstctx->mdctx = EVP_MD_CTX_dup(srcctx->mdctx)) == NULL) - goto err; - if (srcctx->propq != NULL - && ((dstctx->propq = OPENSSL_strdup(srcctx->propq)) == NULL)) - goto err; - if (srcctx->sig != NULL - && ((dstctx->sig = OPENSSL_memdup(srcctx->sig, srcctx->siglen)) == NULL)) - goto err; + if (srcctx->mdctx != NULL) { + dstctx->mdctx = EVP_MD_CTX_new(); + if (dstctx->mdctx == NULL + || !EVP_MD_CTX_copy_ex(dstctx->mdctx, srcctx->mdctx)) + goto err; + } + + if (srcctx->propq != NULL) { + dstctx->propq = OPENSSL_strdup(srcctx->propq); + if (dstctx->propq == NULL) + goto err; + } return dstctx; err: @@ -955,12 +950,6 @@ static int dsa_sigalg_set_ctx_params(void *vpdsactx, const OSSL_PARAM params[]) if (!OSSL_PARAM_get_octet_string(p.sig, (void **)&pdsactx->sig, 0, &pdsactx->siglen)) return 0; - /* The signature must not be empty */ - if (pdsactx->siglen == 0) { - OPENSSL_free(pdsactx->sig); - pdsactx->sig = NULL; - return 0; - } } } return 1; diff --git a/providers/implementations/signature/ecdsa_sig.c b/providers/implementations/signature/ecdsa_sig.c index 3b9773be31..eab82ac4ec 100644 --- a/providers/implementations/signature/ecdsa_sig.c +++ b/providers/implementations/signature/ecdsa_sig.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -32,7 +32,6 @@ #include "prov/securitycheck.h" #include "prov/der_ec.h" #include "crypto/ec.h" -#include "internal/fips.h" struct ecdsa_all_set_ctx_params_st { OSSL_PARAM *digest; /* ecdsa_set_ctx_params */ @@ -167,12 +166,6 @@ static void *ecdsa_newctx(void *provctx, const char *propq) if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_SIG_ECDSA_SHA256)) - return NULL; -#endif - ctx = OPENSSL_zalloc(sizeof(PROV_ECDSA_CTX)); if (ctx == NULL) return NULL; @@ -248,7 +241,7 @@ static int ecdsa_setup_md(PROV_ECDSA_CTX *ctx, OSSL_FIPS_IND_SETTABLE1, ctx->libctx, md_nid, sha1_allowed, 0, desc, - FIPS_CONFIG_SIGNATURE_DIGEST_CHECK)) + ossl_fips_config_signature_digest_check)) goto err; } #endif @@ -657,37 +650,40 @@ static void *ecdsa_dupctx(void *vctx) PROV_ECDSA_CTX *srcctx = (PROV_ECDSA_CTX *)vctx; PROV_ECDSA_CTX *dstctx; - /* Test KATS should not need to be supported */ - if (!ossl_prov_is_running() - || srcctx->kinv != NULL - || srcctx->r != NULL - || (dstctx = OPENSSL_memdup(srcctx, sizeof(*srcctx))) == NULL) + if (!ossl_prov_is_running()) return NULL; + dstctx = OPENSSL_zalloc(sizeof(*srcctx)); + if (dstctx == NULL) + return NULL; + + *dstctx = *srcctx; dstctx->ec = NULL; dstctx->propq = NULL; - dstctx->md = NULL; - dstctx->mdctx = NULL; - dstctx->sig = NULL; if (srcctx->ec != NULL && !EC_KEY_up_ref(srcctx->ec)) goto err; + /* Test KATS should not need to be supported */ + if (srcctx->kinv != NULL || srcctx->r != NULL) + goto err; dstctx->ec = srcctx->ec; if (srcctx->md != NULL && !EVP_MD_up_ref(srcctx->md)) goto err; dstctx->md = srcctx->md; - if (srcctx->mdctx != NULL - && ((dstctx->mdctx = EVP_MD_CTX_new()) == NULL - || !EVP_MD_CTX_copy_ex(dstctx->mdctx, srcctx->mdctx))) - goto err; - if (srcctx->propq != NULL - && (dstctx->propq = OPENSSL_strdup(srcctx->propq)) == NULL) - goto err; - if (srcctx->sig != NULL - && (dstctx->sig = OPENSSL_memdup(srcctx->sig, srcctx->siglen)) == NULL) - goto err; + if (srcctx->mdctx != NULL) { + dstctx->mdctx = EVP_MD_CTX_new(); + if (dstctx->mdctx == NULL + || !EVP_MD_CTX_copy_ex(dstctx->mdctx, srcctx->mdctx)) + goto err; + } + + if (srcctx->propq != NULL) { + dstctx->propq = OPENSSL_strdup(srcctx->propq); + if (dstctx->propq == NULL) + goto err; + } return dstctx; err: @@ -968,12 +964,6 @@ static int ecdsa_sigalg_set_ctx_params(void *vctx, const OSSL_PARAM params[]) if (!OSSL_PARAM_get_octet_string(p.sig, (void **)&ctx->sig, 0, &ctx->siglen)) return 0; - /* The signature must not be empty */ - if (ctx->siglen == 0) { - OPENSSL_free(ctx->sig); - ctx->sig = NULL; - return 0; - } } } return 1; diff --git a/providers/implementations/signature/eddsa_sig.c b/providers/implementations/signature/eddsa_sig.c index 74e9fc11ee..ee5bac44af 100644 --- a/providers/implementations/signature/eddsa_sig.c +++ b/providers/implementations/signature/eddsa_sig.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -23,14 +23,13 @@ #include "prov/provider_ctx.h" #include "prov/der_ecx.h" #include "crypto/ecx.h" -#include "internal/fips.h" #define eddsa_set_variant_ctx_params_st eddsa_set_ctx_params_st #include "providers/implementations/signature/eddsa_sig.inc" #ifdef S390X_EC_ASM -#include "arch/s390x_arch.h" +#include "s390x_arch.h" #define S390X_CAN_SIGN(edtype) \ ((OPENSSL_s390xcap_P.pcc[1] & S390X_CAPBIT(S390X_SCALAR_MULTIPLY_##edtype)) \ @@ -68,8 +67,7 @@ enum ID_EdDSA_INSTANCE { #define EDDSA_MAX_CONTEXT_STRING_LEN 255 #define EDDSA_PREHASH_OUTPUT_LEN 64 -static OSSL_FUNC_signature_newctx_fn ed25519_newctx; -static OSSL_FUNC_signature_newctx_fn ed448_newctx; +static OSSL_FUNC_signature_newctx_fn eddsa_newctx; static OSSL_FUNC_signature_sign_message_init_fn ed25519_signverify_message_init; static OSSL_FUNC_signature_sign_message_init_fn ed25519ph_signverify_message_init; static OSSL_FUNC_signature_sign_message_init_fn ed25519ctx_signverify_message_init; @@ -169,10 +167,13 @@ typedef struct { } PROV_EDDSA_CTX; -static void *eddsa_newctx(void *provctx) +static void *eddsa_newctx(void *provctx, const char *propq_unused) { PROV_EDDSA_CTX *peddsactx; + if (!ossl_prov_is_running()) + return NULL; + peddsactx = OPENSSL_zalloc(sizeof(PROV_EDDSA_CTX)); if (peddsactx == NULL) return NULL; @@ -182,34 +183,6 @@ static void *eddsa_newctx(void *provctx) return peddsactx; } -static void *ed448_newctx(void *provctx, const char *propq_unused) -{ - if (!ossl_prov_is_running()) - return NULL; - -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_SIG_ED448)) - return NULL; -#endif - - return eddsa_newctx(provctx); -} - -static void *ed25519_newctx(void *provctx, const char *propq_unused) -{ - if (!ossl_prov_is_running()) - return NULL; - -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_SIG_ED25519)) - return NULL; -#endif - - return eddsa_newctx(provctx); -} - static int eddsa_setup_instance(void *vpeddsactx, int instance_id, unsigned int instance_id_preset, unsigned int prehash_by_caller) @@ -551,7 +524,7 @@ static int ed448_sign(void *vpeddsactx, /* * s390x_ed448_digestsign() does not yet support context-strings or * pre-hashing. Fall back to non-accelerated sign if a context-string or - * pre-hashing is provided. + * pre-hasing is provided. */ if (S390X_CAN_SIGN(ED448) && peddsactx->context_string_len == 0 @@ -673,7 +646,7 @@ static int ed448_verify(void *vpeddsactx, /* * s390x_ed448_digestverify() does not yet support context-strings or * pre-hashing. Fall back to non-accelerated verify if a context-string or - * pre-hashing is provided. + * pre-hasing is provided. */ if (S390X_CAN_SIGN(ED448) && peddsactx->context_string_len == 0 @@ -1056,7 +1029,7 @@ static int eddsa_set_variant_ctx_params(void *vpeddsactx, /* vn = variant name, bn = base name */ #define IMPL_EDDSA_DISPATCH(vn, bn) \ const OSSL_DISPATCH ossl_##vn##_signature_functions[] = { \ - { OSSL_FUNC_SIGNATURE_NEWCTX, (void (*)(void))bn##_newctx }, \ + { OSSL_FUNC_SIGNATURE_NEWCTX, (void (*)(void))eddsa_newctx }, \ { OSSL_FUNC_SIGNATURE_SIGN_MESSAGE_INIT, \ (void (*)(void))vn##_signverify_message_init }, \ { OSSL_FUNC_SIGNATURE_SIGN, \ diff --git a/providers/implementations/signature/lms_signature.c b/providers/implementations/signature/lms_signature.c index 016d3c420f..d1d605494f 100644 --- a/providers/implementations/signature/lms_signature.c +++ b/providers/implementations/signature/lms_signature.c @@ -1,5 +1,5 @@ /* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -18,14 +18,11 @@ #include "prov/provider_ctx.h" #include "prov/implementations.h" #include "crypto/lms_sig.h" -#include "internal/fips.h" static OSSL_FUNC_signature_newctx_fn lms_newctx; static OSSL_FUNC_signature_freectx_fn lms_freectx; static OSSL_FUNC_signature_verify_message_init_fn lms_verify_msg_init; static OSSL_FUNC_signature_verify_fn lms_verify; -static OSSL_FUNC_signature_digest_verify_init_fn lms_digest_verify_init; -static OSSL_FUNC_signature_digest_verify_fn lms_digest_verify; typedef struct { OSSL_LIB_CTX *libctx; @@ -41,12 +38,6 @@ static void *lms_newctx(void *provctx, const char *propq) if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_SIG_LMS)) - return NULL; -#endif - ctx = OPENSSL_zalloc(sizeof(PROV_LMS_CTX)); if (ctx == NULL) return NULL; @@ -132,37 +123,11 @@ static int lms_verify(void *vctx, const unsigned char *sigbuf, size_t sigbuf_len return ret; } -static int lms_digest_verify_init(void *vctx, const char *mdname, void *vkey, - const OSSL_PARAM params[]) -{ - PROV_LMS_CTX *ctx = (PROV_LMS_CTX *)vctx; - - if (mdname != NULL && mdname[0] != '\0') { - ERR_raise_data(ERR_LIB_PROV, PROV_R_INVALID_DIGEST, - "Explicit digest not supported for LMS operations"); - return 0; - } - if (vkey == NULL && ctx->key != NULL) - return 1; /* lms_set_ctx_params(ctx, params); */ - - return lms_verify_msg_init(vctx, vkey, params); -} - -static int lms_digest_verify(void *vctx, const uint8_t *sig, size_t siglen, - const uint8_t *tbs, size_t tbslen) -{ - return lms_verify(vctx, sig, siglen, tbs, tbslen); -} - const OSSL_DISPATCH ossl_lms_signature_functions[] = { { OSSL_FUNC_SIGNATURE_NEWCTX, (void (*)(void))lms_newctx }, { OSSL_FUNC_SIGNATURE_FREECTX, (void (*)(void))lms_freectx }, { OSSL_FUNC_SIGNATURE_VERIFY_MESSAGE_INIT, (void (*)(void))lms_verify_msg_init }, { OSSL_FUNC_SIGNATURE_VERIFY, (void (*)(void))lms_verify }, - { OSSL_FUNC_SIGNATURE_DIGEST_VERIFY_INIT, - (void (*)(void))lms_digest_verify_init }, - { OSSL_FUNC_SIGNATURE_DIGEST_VERIFY, - (void (*)(void))lms_digest_verify }, OSSL_DISPATCH_END }; diff --git a/providers/implementations/signature/mac_legacy_sig.c b/providers/implementations/signature/mac_legacy_sig.c index cf2eff267d..cef684b80c 100644 --- a/providers/implementations/signature/mac_legacy_sig.c +++ b/providers/implementations/signature/mac_legacy_sig.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -7,7 +7,6 @@ * https://www.openssl.org/source/license.html */ -#include #include #include #include @@ -19,15 +18,6 @@ #include "prov/provider_ctx.h" #include "prov/macsignature.h" #include "prov/providercommon.h" -#include "prov/securitycheck.h" -#include "internal/fips.h" -#include "internal/common.h" - -#ifndef FIPS_MODULE -#define mac_legacy_get_ctx_params_decoder -#define mac_legacy_set_ctx_params_decoder -#endif -#include "providers/implementations/signature/mac_legacy_sig.inc" static OSSL_FUNC_signature_newctx_fn mac_hmac_newctx; static OSSL_FUNC_signature_newctx_fn mac_siphash_newctx; @@ -49,10 +39,6 @@ typedef struct { char *propq; MAC_KEY *key; EVP_MAC_CTX *macctx; -#ifdef FIPS_MODULE - bool hmac_keysize_check; - OSSL_FIPS_IND_DECLARE -#endif } PROV_MAC_CTX; static void *mac_newctx(void *provctx, const char *propq, const char *macname) @@ -80,11 +66,7 @@ static void *mac_newctx(void *provctx, const char *propq, const char *macname) goto err; EVP_MAC_free(mac); -#ifdef FIPS_MODULE - pmacctx->hmac_keysize_check = (strcmp(macname, "HMAC") == 0); - /* Set FIPS indicator to approved */ - OSSL_FIPS_IND_INIT(pmacctx) -#endif + return pmacctx; err: @@ -105,27 +87,6 @@ MAC_NEWCTX(siphash, "SIPHASH") MAC_NEWCTX(poly1305, "POLY1305") MAC_NEWCTX(cmac, "CMAC") -#ifdef FIPS_MODULE -/* - * The fips indicator check is done at this level because HMAC will be created - * as an 'internal' sub-algorithm which will not perform the tests in hmac_prov.c - */ -static int hmac_check_key(PROV_MAC_CTX *macctx, const unsigned char *key, size_t keylen) -{ - int approved = ossl_mac_check_key_size(keylen); - - if (!approved) { - if (!OSSL_FIPS_IND_ON_UNAPPROVED(macctx, OSSL_FIPS_IND_SETTABLE0, - macctx->libctx, "HMAC", "keysize", - FIPS_CONFIG_HMAC_KEY_CHECK)) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_KEY_LENGTH); - return 0; - } - } - return 1; -} -#endif - static int mac_digest_sign_init(void *vpmacctx, const char *mdname, void *vkey, const OSSL_PARAM params[]) { @@ -149,19 +110,14 @@ static int mac_digest_sign_init(void *vpmacctx, const char *mdname, void *vkey, } if (pmacctx->key->cipher.cipher != NULL) - ciphername = EVP_CIPHER_get0_name(pmacctx->key->cipher.cipher); + ciphername = (char *)EVP_CIPHER_get0_name(pmacctx->key->cipher.cipher); if (!ossl_prov_set_macctx(pmacctx->macctx, - ciphername, - mdname, + (char *)ciphername, + (char *)mdname, pmacctx->key->properties, params)) return 0; -#ifdef FIPS_MODULE - if (pmacctx->hmac_keysize_check - && !hmac_check_key(pmacctx, pmacctx->key->priv_key, pmacctx->key->priv_key_len)) - return 0; -#endif if (!EVP_MAC_init(pmacctx->macctx, pmacctx->key->priv_key, pmacctx->key->priv_key_len, NULL)) return 0; @@ -241,22 +197,6 @@ static int mac_set_ctx_params(void *vpmacctx, const OSSL_PARAM params[]) { PROV_MAC_CTX *ctx = (PROV_MAC_CTX *)vpmacctx; -#ifdef FIPS_MODULE - if (ctx->hmac_keysize_check) { - struct mac_legacy_set_ctx_params_st p; - - if (!mac_legacy_set_ctx_params_decoder(params, &p)) - return 0; - if (!OSSL_FIPS_IND_SET_CTX_FROM_PARAM(ctx, OSSL_FIPS_IND_SETTABLE0, p.ind_k)) - return 0; - if (p.key != NULL) { - if (p.key->data_type != OSSL_PARAM_OCTET_STRING) - return 0; - if (!hmac_check_key(ctx, p.key->data, p.key->data_size)) - return 0; - } - } -#endif return EVP_MAC_CTX_set_params(ctx->macctx, params); } @@ -277,33 +217,6 @@ static const OSSL_PARAM *mac_settable_ctx_params(ossl_unused void *ctx, return params; } -static const OSSL_PARAM *mac_gettable_ctx_params(ossl_unused void *vctx, - ossl_unused void *provctx) -{ - return mac_legacy_get_ctx_params_list; -} - -static int mac_get_ctx_params(void *vctx, OSSL_PARAM params[]) -{ - PROV_MAC_CTX *ctx = vctx; - - if (ctx == NULL) - return 0; - -#ifdef FIPS_MODULE - struct mac_legacy_get_ctx_params_st p; - - if (!mac_legacy_get_ctx_params_decoder(params, &p)) - return 0; - if (p.ind != NULL) { - int approved = OSSL_FIPS_IND_GET(ctx)->approved; - if (!OSSL_PARAM_set_int(p.ind, approved)) - return 0; - } -#endif - return 1; -} - #define MAC_SETTABLE_CTX_PARAMS(funcname, macname) \ static const OSSL_PARAM *mac_##funcname##_settable_ctx_params(void *ctx, \ void *provctx) \ @@ -331,10 +244,6 @@ MAC_SETTABLE_CTX_PARAMS(cmac, "CMAC") (void (*)(void))mac_set_ctx_params }, \ { OSSL_FUNC_SIGNATURE_SETTABLE_CTX_PARAMS, \ (void (*)(void))mac_##funcname##_settable_ctx_params }, \ - { OSSL_FUNC_SIGNATURE_GET_CTX_PARAMS, \ - (void (*)(void))mac_get_ctx_params }, \ - { OSSL_FUNC_SIGNATURE_GETTABLE_CTX_PARAMS, \ - (void (*)(void))mac_gettable_ctx_params }, \ OSSL_DISPATCH_END \ }; diff --git a/providers/implementations/signature/mac_legacy_sig.inc.in b/providers/implementations/signature/mac_legacy_sig.inc.in deleted file mode 100644 index 36f98b23db..0000000000 --- a/providers/implementations/signature/mac_legacy_sig.inc.in +++ /dev/null @@ -1,21 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the \"License\"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -{- -use OpenSSL::paramnames qw(produce_param_decoder); --} - -{- produce_param_decoder('mac_legacy_get_ctx_params', - (['OSSL_ALG_PARAM_FIPS_APPROVED_INDICATOR', 'ind', 'int', 'fips'], - )); -} - -{- produce_param_decoder('mac_legacy_set_ctx_params', - (['OSSL_MAC_PARAM_KEY', 'key', 'octet_string'], - ['OSSL_MAC_PARAM_FIPS_KEY_CHECK', 'ind_k', 'int', 'fips'], - )); -} diff --git a/providers/implementations/signature/ml_dsa_sig.c b/providers/implementations/signature/ml_dsa_sig.c index c661ab67b8..766465f839 100644 --- a/providers/implementations/signature/ml_dsa_sig.c +++ b/providers/implementations/signature/ml_dsa_sig.c @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -23,7 +23,6 @@ #include "internal/common.h" #include "internal/packet.h" #include "internal/sizes.h" -#include "internal/fips.h" #define ml_dsa_set_ctx_params_st ml_dsa_verifymsg_set_ctx_params_st #define ml_dsa_set_ctx_params_decoder ml_dsa_verifymsg_set_ctx_params_decoder @@ -89,12 +88,6 @@ static void *ml_dsa_newctx(void *provctx, int evp_type, const char *propq) if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_SIG_ML_DSA_65)) - return NULL; -#endif - ctx = OPENSSL_zalloc(sizeof(PROV_ML_DSA_CTX)); if (ctx == NULL) return NULL; diff --git a/providers/implementations/signature/rsa_sig.c b/providers/implementations/signature/rsa_sig.c index 232414935f..c11b9daaed 100644 --- a/providers/implementations/signature/rsa_sig.c +++ b/providers/implementations/signature/rsa_sig.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -32,7 +32,6 @@ #include "prov/provider_ctx.h" #include "prov/der_rsa.h" #include "prov/securitycheck.h" -#include "internal/fips.h" #define rsa_set_ctx_params_no_digest_st rsa_set_ctx_params_st @@ -237,12 +236,6 @@ static void *rsa_newctx(void *provctx, const char *propq) if (!ossl_prov_is_running()) return NULL; -#ifdef FIPS_MODULE - if (!ossl_deferred_self_test(PROV_LIBCTX_OF(provctx), - ST_ID_SIG_RSA_SHA256)) - return NULL; -#endif - if ((prsactx = OPENSSL_zalloc(sizeof(PROV_RSA_CTX))) == NULL || (propq != NULL && (propq_copy = OPENSSL_strdup(propq)) == NULL)) { @@ -424,7 +417,7 @@ static int rsa_setup_md(PROV_RSA_CTX *ctx, const char *mdname, OSSL_FIPS_IND_SETTABLE1, ctx->libctx, md_nid, sha1_allowed, 1, desc, - FIPS_CONFIG_SIGNATURE_DIGEST_CHECK)) + ossl_fips_config_signature_digest_check)) goto err; } #endif @@ -602,7 +595,7 @@ rsa_signverify_init(PROV_RSA_CTX *prsactx, void *vrsa, break; default: - ERR_raise(ERR_LIB_PROV, PROV_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE); + ERR_raise(ERR_LIB_RSA, PROV_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE); return 0; } @@ -656,7 +649,7 @@ static int rsa_pss_saltlen_check_passed(PROV_RSA_CTX *ctx, const char *algoname, if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE3, ctx->libctx, algoname, "PSS Salt Length", - FIPS_CONFIG_RSA_PSS_SALTLEN_CHECK)) { + ossl_fips_config_rsa_pss_saltlen_check)) { ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_SALT_LENGTH); return 0; } @@ -988,19 +981,8 @@ static int rsa_verify_recover(void *vprsactx, break; case RSA_PKCS1_PADDING: { - int mdsize = EVP_MD_get_size(prsactx->md); size_t sltmp; - if (mdsize <= 0) { - ERR_raise(ERR_LIB_PROV, PROV_R_INVALID_DIGEST_LENGTH); - return 0; - } - if (routsize < (size_t)mdsize) { - ERR_raise_data(ERR_LIB_PROV, PROV_R_OUTPUT_BUFFER_TOO_SMALL, - "buffer size is %d, should be %d", - routsize, mdsize); - return 0; - } ret = ossl_rsa_verify(prsactx->mdnid, NULL, 0, rout, &sltmp, sig, siglen, prsactx->rsa); if (ret <= 0) { @@ -1016,23 +998,9 @@ static int rsa_verify_recover(void *vprsactx, return 0; } } else { - int rsasize = RSA_size(prsactx->rsa); - - if (routsize < (size_t)rsasize) { - ERR_raise_data(ERR_LIB_PROV, PROV_R_OUTPUT_BUFFER_TOO_SMALL, - "buffer size is %d, should be %d", - routsize, rsasize); - return 0; - } ret = RSA_public_decrypt((int)siglen, sig, rout, prsactx->rsa, prsactx->pad_mode); - /* - * RSA_public_decrypt() returns -1 on error and otherwise the number - * of recovered bytes, which may legitimately be zero for a raw - * PKCS#1 v1.5 signature that encodes an empty payload. Treat only - * a negative result as an error. - */ - if (ret < 0) { + if (ret <= 0) { ERR_raise(ERR_LIB_PROV, ERR_R_RSA_LIB); return 0; } @@ -1379,7 +1347,6 @@ static void *rsa_dupctx(void *vprsactx) dstctx->mdctx = NULL; dstctx->tbuf = NULL; dstctx->propq = NULL; - dstctx->sig = NULL; if (srcctx->rsa != NULL && !RSA_up_ref(srcctx->rsa)) goto err; @@ -1406,12 +1373,6 @@ static void *rsa_dupctx(void *vprsactx) goto err; } - if (srcctx->sig != NULL) { - dstctx->sig = OPENSSL_memdup(srcctx->sig, srcctx->siglen); - if (dstctx->sig == NULL) - goto err; - } - return dstctx; err: rsa_freectx(dstctx); @@ -1529,7 +1490,7 @@ static int rsa_x931_padding_allowed(PROV_RSA_CTX *ctx) if (!OSSL_FIPS_IND_ON_UNAPPROVED(ctx, OSSL_FIPS_IND_SETTABLE2, ctx->libctx, "RSA Sign set ctx", "X931 Padding", - FIPS_CONFIG_RSA_SIGN_X931_PAD_DISABLED)) { + ossl_fips_config_rsa_sign_x931_disallowed)) { ERR_raise(ERR_LIB_PROV, PROV_R_ILLEGAL_OR_UNSUPPORTED_PADDING_MODE); return 0; @@ -1545,7 +1506,6 @@ static int rsa_set_ctx_params(void *vprsactx, const OSSL_PARAM params[]) struct rsa_set_ctx_params_st p; int pad_mode; int saltlen; - int count = 0; char mdname[OSSL_MAX_NAME_SIZE] = "", *pmdname = NULL; char mdprops[OSSL_MAX_PROPQUERY_SIZE] = "", *pmdprops = NULL; char mgf1mdname[OSSL_MAX_NAME_SIZE] = "", *pmgf1mdname = NULL; @@ -1558,14 +1518,12 @@ static int rsa_set_ctx_params(void *vprsactx, const OSSL_PARAM params[]) return 1; if (prsactx->flag_allow_md) { - if (!rsa_set_ctx_params_decoder(params, &p, &count)) + if (!rsa_set_ctx_params_decoder(params, &p)) return 0; } else { - if (!rsa_set_ctx_params_no_digest_decoder(params, &p, &count)) + if (!rsa_set_ctx_params_no_digest_decoder(params, &p)) return 0; } - if (count == 0) - return 1; if (!OSSL_FIPS_IND_SET_CTX_FROM_PARAM(prsactx, OSSL_FIPS_IND_SETTABLE0, p.ind_k)) @@ -1909,7 +1867,7 @@ static int rsa_sigalg_signverify_init(void *vprsactx, void *vrsa, /* PSS is currently not supported as a sigalg */ if (prsactx->pad_mode == RSA_PKCS1_PSS_PADDING) { - ERR_raise(ERR_LIB_PROV, PROV_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE); + ERR_raise(ERR_LIB_RSA, PROV_R_OPERATION_NOT_SUPPORTED_FOR_THIS_KEYTYPE); return 0; } diff --git a/providers/implementations/signature/rsa_sig.inc.in b/providers/implementations/signature/rsa_sig.inc.in index 0a6eca3890..e73e26d819 100644 --- a/providers/implementations/signature/rsa_sig.inc.in +++ b/providers/implementations/signature/rsa_sig.inc.in @@ -1,5 +1,5 @@ /* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the \"License\"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -8,7 +8,7 @@ */ {- -use OpenSSL::paramnames qw(produce_param_decoder produce_param_decoder_with_count); +use OpenSSL::paramnames qw(produce_param_decoder); -} {- produce_param_decoder('rsa_get_ctx_params', @@ -23,7 +23,7 @@ use OpenSSL::paramnames qw(produce_param_decoder produce_param_decoder_with_coun ['OSSL_SIGNATURE_PARAM_FIPS_APPROVED_INDICATOR', 'ind', 'int', 'fips'], )); -} -{- produce_param_decoder_with_count('rsa_set_ctx_params', +{- produce_param_decoder('rsa_set_ctx_params', (['OSSL_SIGNATURE_PARAM_DIGEST', 'digest', 'utf8_string'], ['OSSL_SIGNATURE_PARAM_PROPERTIES', 'propq', 'utf8_string'], ['OSSL_SIGNATURE_PARAM_PAD_MODE', 'pad', 'utf8_string'], @@ -38,7 +38,7 @@ use OpenSSL::paramnames qw(produce_param_decoder produce_param_decoder_with_coun ['OSSL_SIGNATURE_PARAM_FIPS_SIGN_X931_PAD_CHECK', 'ind_xpad', 'int', 'fips'], )); -} -{- produce_param_decoder_with_count('rsa_set_ctx_params_no_digest', +{- produce_param_decoder('rsa_set_ctx_params_no_digest', (['OSSL_SIGNATURE_PARAM_PAD_MODE', 'pad', 'utf8_string'], ['OSSL_SIGNATURE_PARAM_PAD_MODE', 'pad', 'int'], ['OSSL_SIGNATURE_PARAM_MGF1_DIGEST', 'mgf1', 'utf8_string'], diff --git a/providers/implementations/signature/slh_dsa_sig.c b/providers/implementations/signature/slh_dsa_sig.c index fa315a7b84..65796b03f9 100644 --- a/providers/implementations/signature/slh_dsa_sig.c +++ b/providers/implementations/signature/slh_dsa_sig.c @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -39,16 +39,25 @@ static OSSL_FUNC_signature_dupctx_fn slh_dsa_dupctx; static OSSL_FUNC_signature_set_ctx_params_fn slh_dsa_set_ctx_params; static OSSL_FUNC_signature_settable_ctx_params_fn slh_dsa_settable_ctx_params; -static int slh_dsa_self_check(OSSL_LIB_CTX *libctx, const char *alg) +#ifdef FIPS_MODULE +static FIPS_DEFERRED_TEST slh_sig_deferred_tests[] = { + { "SLH-DSA-SHA2-128f", + FIPS_DEFERRED_KAT_SIGNATURE, + FIPS_DEFERRED_TEST_INIT }, + { "SLH-DSA-SHAKE-128f", + FIPS_DEFERRED_KAT_SIGNATURE, + FIPS_DEFERRED_TEST_INIT }, + { NULL, 0, 0 }, +}; +#endif + +static int slh_dsa_self_check(OSSL_LIB_CTX *libctx) { if (!ossl_prov_is_running()) return 0; #ifdef FIPS_MODULE - if (strstr(alg, "SLH-DSA-SHAKE")) - return ossl_deferred_self_test(libctx, ST_ID_SIG_SLH_DSA_SHAKE_128F); - else - return ossl_deferred_self_test(libctx, ST_ID_SIG_SLH_DSA_SHA2_128F); + return FIPS_deferred_self_tests(libctx, slh_sig_deferred_tests); #else return 1; #endif @@ -88,7 +97,7 @@ static void *slh_dsa_newctx(void *provctx, const char *alg, const char *propq) { PROV_SLH_DSA_CTX *ctx; - if (!slh_dsa_self_check(PROV_LIBCTX_OF(provctx), alg)) + if (!slh_dsa_self_check(PROV_LIBCTX_OF(provctx))) return NULL; ctx = OPENSSL_zalloc(sizeof(PROV_SLH_DSA_CTX)); @@ -241,9 +250,8 @@ static int slh_dsa_sign(void *vctx, unsigned char *sig, size_t *siglen, ctx->context_string, ctx->context_string_len, opt_rand, ctx->msg_encode, sig, siglen, sigsize); - /* Only cleanse the temporary buffer generated for this signature. */ - if (opt_rand == add_rand) - OPENSSL_cleanse(add_rand, sizeof(add_rand)); + if (opt_rand != add_rand) + OPENSSL_cleanse(opt_rand, n); return ret; } diff --git a/providers/implementations/signature/sm2_sig.c b/providers/implementations/signature/sm2_sig.c index 20ff558605..b79485c52d 100644 --- a/providers/implementations/signature/sm2_sig.c +++ b/providers/implementations/signature/sm2_sig.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -21,7 +21,6 @@ #include #include #include -#include #include #include "internal/nelem.h" #include "internal/sizes.h" @@ -216,12 +215,6 @@ static int sm2sig_digest_signverify_init(void *vpsm2ctx, const char *mdname, int ret = 0; unsigned char *aid = NULL; - /* - * Each EVP_Digest{Sign,Verify}Init_ex(3) starts with fresh content, that - * needs to recompute the "Z" digest. - */ - ctx->flag_compute_z_digest = 1; - if (!sm2sig_signature_init(vpsm2ctx, ec, params) || !sm2sig_set_mdname(ctx, mdname)) return ret; @@ -255,6 +248,8 @@ static int sm2sig_digest_signverify_init(void *vpsm2ctx, const char *mdname, if (!EVP_DigestInit_ex2(ctx->mdctx, ctx->md, params)) goto error; + ctx->flag_compute_z_digest = 1; + ret = 1; error: @@ -433,22 +428,6 @@ static const OSSL_PARAM *sm2sig_gettable_ctx_params(ossl_unused void *vpsm2ctx, static int sm2sig_set_ctx_params(void *vpsm2ctx, const OSSL_PARAM params[]) { - /* - * (https://datatracker.ietf.org/doc/html/rfc8998#section-3.2.1) - * - * The SM2 signature algorithm requests an identifier value when generating - * or verifying a signature. In all uses except when a client of a server - * needs to verify a peer's SM2 certificate in the Certificate message, an - * implementation of this document MUST use the following ASCII string - * value as the SM2 identifier when doing a TLS 1.3 key exchange: - * - * TLSv1.3+GM+Cipher+Suite - */ - static const uint8_t sm2_tls_id[] = { - 0x54, 0x4c, 0x53, 0x76, 0x31, 0x2e, 0x33, 0x2b, - 0x47, 0x4d, 0x2b, 0x43, 0x69, 0x70, 0x68, 0x65, - 0x72, 0x2b, 0x53, 0x75, 0x69, 0x74, 0x65 - }; PROV_SM2_CTX *psm2ctx = (PROV_SM2_CTX *)vpsm2ctx; struct sm2sig_set_ctx_params_st p; size_t mdsize; @@ -466,23 +445,12 @@ static int sm2sig_set_ctx_params(void *vpsm2ctx, const OSSL_PARAM params[]) if (!psm2ctx->flag_compute_z_digest) return 0; - if ((p.distid->data != NULL) + if (p.distid->data_size != 0 && !OSSL_PARAM_get_octet_string(p.distid, &tmp_id, 0, &tmp_idlen)) return 0; OPENSSL_free(psm2ctx->id); psm2ctx->id = tmp_id; psm2ctx->id_len = tmp_idlen; - } else if (p.tlsver != NULL) { - unsigned int ver = 0; - - if (!psm2ctx->flag_compute_z_digest - || !OSSL_PARAM_get_uint(p.tlsver, &ver)) - return 0; - if (ver == TLS1_3_VERSION) { - OPENSSL_free(psm2ctx->id); - psm2ctx->id_len = sizeof(sm2_tls_id); - psm2ctx->id = OPENSSL_memdup(sm2_tls_id, psm2ctx->id_len); - } } /* diff --git a/providers/implementations/signature/sm2_sig.inc.in b/providers/implementations/signature/sm2_sig.inc.in index 6c213301ab..f410d74a47 100644 --- a/providers/implementations/signature/sm2_sig.inc.in +++ b/providers/implementations/signature/sm2_sig.inc.in @@ -1,5 +1,5 @@ /* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the \"License\"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -21,5 +21,4 @@ use OpenSSL::paramnames qw(produce_param_decoder); (['OSSL_SIGNATURE_PARAM_DIGEST_SIZE', 'size', 'size_t'], ['OSSL_SIGNATURE_PARAM_DIGEST', 'digest', 'utf8_string'], ['OSSL_PKEY_PARAM_DIST_ID', 'distid', 'octet_string'], - ['OSSL_SIGNATURE_PARAM_TLS_VERSION', 'tlsver', 'uint'], )); -} diff --git a/providers/implementations/storemgmt/file_store.c b/providers/implementations/storemgmt/file_store.c index 894685ce8c..8493bb4426 100644 --- a/providers/implementations/storemgmt/file_store.c +++ b/providers/implementations/storemgmt/file_store.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -10,19 +10,23 @@ /* This file has quite some overlap with engines/e_loader_attic.c */ #include -#include "internal/e_os.h" /* for stat() */ -#include /* for struct stat */ +#include #include /* isdigit */ #include +#include #include #include +#include +#include #include +#include #include #include /* The OSSL_STORE_INFO type numbers */ #include "internal/cryptlib.h" #include "internal/o_dir.h" #include "crypto/decoder.h" +#include "crypto/ctype.h" /* ossl_isdigit() */ #include "prov/implementations.h" #include "prov/bio.h" #include "prov/providercommon.h" @@ -32,6 +36,10 @@ DEFINE_STACK_OF(OSSL_STORE_INFO) +#ifdef _WIN32 +#define stat _stat +#endif + #ifndef S_ISDIR #define S_ISDIR(a) (((a) & S_IFMT) == S_IFDIR) #endif @@ -98,8 +106,6 @@ struct file_ctx_st { /* Expected object type. May be unspecified */ int expected_type; - /* Fatal error occurred. We should indicate EOF. */ - int fatal_error; }; static void free_file_ctx(struct file_ctx_st *ctx) @@ -134,94 +140,6 @@ static struct file_ctx_st *new_file_ctx(int type, const char *uri, static OSSL_DECODER_CONSTRUCT file_load_construct; static OSSL_DECODER_CLEANUP file_load_cleanup; -#ifdef _WIN32 -#define OSSL_is_drive_letter(c) (((c) >= 'A' && (c) <= 'Z') || ((c) >= 'a' && (c) <= 'z')) -#define OSSL_is_abs_drive_prefix(p) (OSSL_is_drive_letter((p)[0]) && (p)[1] == ':' && (p)[2] == '/') -#endif - -/* - * uri_file_stat() handles URIs that may be interpreted as a reference to a local file. - * It attempts to derive from the given |uri| a file pathname that points to an - * existing file. To this end it takes the full |uri| as a filename (which may be - * an absolute or relative name, such as file.pem) or takes a postfix of |uri|, - * such as path-to-file if |uri| is of the form file:path-to-file - * or /path-to-file if |uri| is of the form file://localhost/path-to-file. - * The returned pathname is a pointer inside |uri|, or NULL on error. - * On success it populates the file stat buffer pointed at by |st| - * (unless |st| is NULL) and returns the derived pathname, otherwise NULL. - */ -static const char *uri_file_stat(const char *uri, struct stat *st) -{ - const char *path = uri, *q; - struct stat local_st; - - ERR_set_mark(); - - if (st == NULL) - st = &local_st; - - /* - * First, unless the URI starts with "file://", - * try and see if the full URI can be taken as a local file path name. - */ - if (!HAS_CASE_PREFIX(uri, "file://")) { - if (stat(path, st) == 0) { - ERR_pop_to_mark(); - return uri; - } - ERR_raise_data(ERR_LIB_SYS, errno, "calling stat(%s)", path); - } - - /* Do a second attempt only if the URI appears to start with the "file" scheme. */ - if (!CHECK_AND_SKIP_CASE_PREFIX(path, "file:")) { - ERR_clear_last_mark(); - return NULL; - } - - /* - * Extract the alternative path to check. - * There's a special case if the URI also contains an authority, - * then the full URI shouldn't be used as a path anywhere. - */ - q = path; - if (CHECK_AND_SKIP_CASE_PREFIX(q, "//")) { - if (CHECK_AND_SKIP_CASE_PREFIX(q, "localhost/") - || CHECK_AND_SKIP_CASE_PREFIX(q, "/")) { - /* - * In these cases, we step back one char to ensure that the - * first slash is preserved, making the path always absolute - */ - path = q - 1; -#ifdef _WIN32 - } else if (OSSL_is_abs_drive_prefix(q)) { - /* Support also "file://" URIs starting with a Windows drive letter not preceded by an extra '/' */ - path = q; -#endif - } else { - const char *p = strchr(q, '/'); - size_t len = p == NULL ? strlen(q) : (size_t)(p - q); - - ERR_raise_data(ERR_LIB_OSSL_STORE, OSSL_STORE_R_URI_AUTHORITY_UNSUPPORTED, - "%.*s", len, q); - ERR_clear_last_mark(); - return NULL; - } - } -#ifdef _WIN32 - /* Windows "file://" URIs with a drive letter are usually required to have an extra '/' before the drive letter, e.g., "file:///C:/path" */ - if (path[0] == '/' && OSSL_is_abs_drive_prefix(path + 1)) - path++; /* Skip past the slash, making the path a normal Windows path */ -#endif - - if (stat(path, st) == 0) { - ERR_pop_to_mark(); - return path; - } - ERR_raise_data(ERR_LIB_SYS, errno, "calling stat(%s)", path); - ERR_clear_last_mark(); - return NULL; -} - /*- * Opening / attaching streams and directories * ------------------------------------------- @@ -279,11 +197,71 @@ static void *file_open(void *provctx, const char *uri) { struct file_ctx_st *ctx = NULL; struct stat st; - const char *path = uri_file_stat(uri, &st); + const char *path_data[2]; + size_t path_data_n = 0, i; + const char *path, *p = uri, *q; BIO *bio; - if (path == NULL) + ERR_set_mark(); + + /* + * First step, just take the URI as is. + */ + path_data[path_data_n++] = uri; + + /* + * Second step, if the URI appears to start with the "file" scheme, + * extract the path and make that the second path to check. + * There's a special case if the URI also contains an authority, then + * the full URI shouldn't be used as a path anywhere. + */ + if (CHECK_AND_SKIP_CASE_PREFIX(p, "file:")) { + q = p; + if (CHECK_AND_SKIP_CASE_PREFIX(q, "//")) { + path_data_n--; /* Invalidate using the full URI */ + if (CHECK_AND_SKIP_CASE_PREFIX(q, "localhost/") + || CHECK_AND_SKIP_CASE_PREFIX(q, "/")) { + /* + * In this case, we step back on char to ensure that the + * first slash is preserved, making the path always absolute + */ + p = q - 1; + } else { + ERR_clear_last_mark(); + ERR_raise(ERR_LIB_PROV, PROV_R_URI_AUTHORITY_UNSUPPORTED); + return NULL; + } + } +#ifdef _WIN32 + /* Windows "file:" URIs with a drive letter start with a '/' */ + if (p[0] == '/' && p[2] == ':' && p[3] == '/') { + char c = tolower((unsigned char)p[1]); + + if (c >= 'a' && c <= 'z') { + /* Skip past the slash, making the path a normal Windows path */ + p++; + } + } +#endif + path_data[path_data_n++] = p; + } + + for (i = 0, path = NULL; path == NULL && i < path_data_n; i++) { + if (stat(path_data[i], &st) < 0) { + ERR_raise_data(ERR_LIB_SYS, errno, + "calling stat(%s)", + path_data[i]); + } else { + path = path_data[i]; + } + } + if (path == NULL) { + ERR_clear_last_mark(); return NULL; + } + + /* Successfully found a working path, clear possible collected errors */ + ERR_pop_to_mark(); if (S_ISDIR(st.st_mode)) ctx = file_open_dir(path, uri, provctx); @@ -505,7 +483,7 @@ static int file_setup_decoders(struct file_ctx_st *ctx) * The decoder doesn't need any identification or to be * attached to any provider, since it's only used locally. */ - to_obj = ossl_decoder_from_algorithm(0, to_algo, NULL, 0); + to_obj = ossl_decoder_from_algorithm(0, to_algo, NULL); if (to_obj != NULL) to_obj_inst = ossl_decoder_instance_new_forprov(to_obj, ctx->provctx, input_structure); @@ -577,10 +555,8 @@ static int file_load_file(struct file_ctx_st *ctx, /* Setup the decoders (one time shot per session */ - if (!file_setup_decoders(ctx)) { - ctx->fatal_error = 1; + if (!file_setup_decoders(ctx)) return 0; - } /* Setup for this object */ @@ -778,9 +754,6 @@ static int file_eof(void *loaderctx) { struct file_ctx_st *ctx = loaderctx; - if (ctx->fatal_error) - return 1; - switch (ctx->type) { case IS_DIR: return ctx->_.dir.end_reached; diff --git a/providers/implementations/storemgmt/file_store_any2obj.c b/providers/implementations/storemgmt/file_store_any2obj.c index 2592ab04ab..67de51d94a 100644 --- a/providers/implementations/storemgmt/file_store_any2obj.c +++ b/providers/implementations/storemgmt/file_store_any2obj.c @@ -306,8 +306,8 @@ err: static OSSL_FUNC_decoder_decode_fn raw2obj_decode; static int raw2obj_decode(void *vctx, OSSL_CORE_BIO *cin, int selection, - OSSL_CALLBACK *data_cb, void *data_cbarg, - OSSL_PASSPHRASE_CALLBACK *pw_cb, void *pw_cbarg) + OSSL_CALLBACK *data_cb, void *data_cbarg, + OSSL_PASSPHRASE_CALLBACK *pw_cb, void *pw_cbarg) { struct any2obj_ctx_st *ctx = vctx; BIO *in = ossl_bio_new_from_core_bio(ctx->provctx, cin); @@ -336,7 +336,6 @@ static int raw2obj_decode(void *vctx, OSSL_CORE_BIO *cin, int selection, } BIO_free(in); - in = NULL; if (BUF_MEM_grow(mem, len) != len) { ERR_raise(ERR_LIB_PEM, ERR_R_BUF_LIB); @@ -345,9 +344,9 @@ static int raw2obj_decode(void *vctx, OSSL_CORE_BIO *cin, int selection, /* any2obj_decode_final() frees |mem| for us */ return any2obj_decode_final(ctx, OSSL_OBJECT_SKEY, "raw", "SKEY", - mem, data_cb, data_cbarg); + mem, data_cb, data_cbarg); -err: + err: BIO_free(in); BUF_MEM_free(mem); return 0; diff --git a/providers/implementations/storemgmt/winstore_store.c b/providers/implementations/storemgmt/winstore_store.c index 59318e7547..32965ba7c6 100644 --- a/providers/implementations/storemgmt/winstore_store.c +++ b/providers/implementations/storemgmt/winstore_store.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -209,7 +209,7 @@ static int setup_decoder(struct winstore_ctx_st *ctx) * The decoder doesn't need any identification or to be * attached to any provider, since it's only used locally. */ - to_obj = ossl_decoder_from_algorithm(0, to_algo, NULL, 0); + to_obj = ossl_decoder_from_algorithm(0, to_algo, NULL); if (to_obj != NULL) to_obj_inst = ossl_decoder_instance_new_forprov(to_obj, ctx->provctx, input_structure); @@ -267,10 +267,8 @@ static int winstore_load_using(struct winstore_ctx_st *ctx, const unsigned char *der_ = der; size_t der_len_ = der_len; - if (setup_decoder(ctx) == 0) { - ctx->state = STATE_EOF; + if (setup_decoder(ctx) == 0) return 0; - } data.object_cb = object_cb; data.object_cbarg = object_cbarg; diff --git a/providers/legacyprov.c b/providers/legacyprov.c index cf3365f4fb..996c412e05 100644 --- a/providers/legacyprov.c +++ b/providers/legacyprov.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -163,9 +163,7 @@ static const OSSL_ALGORITHM legacy_ciphers[] = { static const OSSL_ALGORITHM legacy_kdfs[] = { ALG(PROV_NAMES_PBKDF1, ossl_kdf_pbkdf1_functions), -#ifndef OPENSSL_NO_PVKKDF ALG(PROV_NAMES_PVKKDF, ossl_kdf_pvk_functions), -#endif { NULL, NULL, NULL } }; diff --git a/ssl/bio_ssl.c b/ssl/bio_ssl.c index ebd9c58365..fdf79a98a4 100644 --- a/ssl/bio_ssl.c +++ b/ssl/bio_ssl.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -106,7 +106,6 @@ static int ssl_read(BIO *b, char *buf, size_t size, size_t *readbytes) ssl = sb->ssl; BIO_clear_retry_flags(b); - BIO_clear_flags(b, BIO_FLAGS_IN_EOF); ret = ssl_read_internal(ssl, buf, size, readbytes); @@ -151,11 +150,9 @@ static int ssl_read(BIO *b, char *buf, size_t size, size_t *readbytes) BIO_set_retry_special(b); retry_reason = BIO_RR_CONNECT; break; - case SSL_ERROR_ZERO_RETURN: - BIO_set_flags(b, BIO_FLAGS_IN_EOF); - break; case SSL_ERROR_SYSCALL: case SSL_ERROR_SSL: + case SSL_ERROR_ZERO_RETURN: default: break; } @@ -229,7 +226,7 @@ static int ssl_write(BIO *b, const char *buf, size_t size, size_t *written) static long ssl_ctrl(BIO *b, int cmd, long num, void *ptr) { - SSL **sslp, *ssl, *dupssl; + SSL **sslp, *ssl; BIO_SSL *bs, *dbs; BIO *dbio, *bio; long ret = 1; @@ -299,6 +296,7 @@ static long ssl_ctrl(BIO *b, int cmd, long num, void *ptr) } BIO_set_shutdown(b, num); ssl = (SSL *)ptr; + bs->ssl = ssl; bio = SSL_get_rbio(ssl); if (bio != NULL) { if (!BIO_up_ref(bio)) { @@ -310,7 +308,6 @@ static long ssl_ctrl(BIO *b, int cmd, long num, void *ptr) BIO_set_next(b, bio); } BIO_set_init(b, 1); - bs->ssl = ssl; break; case BIO_C_GET_SSL: if (ptr != NULL) { @@ -385,19 +382,14 @@ static long ssl_ctrl(BIO *b, int cmd, long num, void *ptr) case BIO_CTRL_DUP: dbio = (BIO *)ptr; dbs = BIO_get_data(dbio); - dupssl = SSL_dup(ssl); - if (dupssl == NULL) { - ret = 0; - break; - } SSL_free(dbs->ssl); - dbs->ssl = dupssl; + dbs->ssl = SSL_dup(ssl); dbs->num_renegotiates = bs->num_renegotiates; dbs->renegotiate_count = bs->renegotiate_count; dbs->byte_count = bs->byte_count; dbs->renegotiate_timeout = bs->renegotiate_timeout; dbs->last_time = bs->last_time; - ret = 1; + ret = (dbs->ssl != NULL); break; case BIO_C_GET_FD: ret = BIO_ctrl(SSL_get_rbio(ssl), cmd, num, ptr); @@ -413,11 +405,6 @@ static long ssl_ctrl(BIO *b, int cmd, long num, void *ptr) if (!SSL_get_wpoll_descriptor(ssl, (BIO_POLL_DESCRIPTOR *)ptr)) ret = 0; break; - case BIO_CTRL_EOF: - ret = BIO_test_flags(b, BIO_FLAGS_IN_EOF) - ? 1 - : BIO_ctrl(SSL_get_rbio(ssl), cmd, num, ptr); - break; default: ret = BIO_ctrl(SSL_get_rbio(ssl), cmd, num, ptr); break; diff --git a/ssl/build.info b/ssl/build.info index 1bc57b4320..7f4ecaa68f 100644 --- a/ssl/build.info +++ b/ssl/build.info @@ -2,13 +2,9 @@ SUBDIRS=record rio quic LIBS=../libssl -IF[{- !$disabled{ech} -}] - SUBDIRS=ech -ENDIF - SOURCE[../libssl]=\ pqueue.c \ - statem/statem_srvr.c statem/statem_clnt.c s3_lib.c s3_enc.c \ + statem/statem_srvr.c statem/statem_clnt.c s3_lib.c s3_enc.c \ statem/statem_lib.c statem/extensions.c statem/extensions_srvr.c \ statem/extensions_clnt.c statem/extensions_cust.c s3_msg.c \ methods.c t1_lib.c t1_enc.c tls13_enc.c \ diff --git a/ssl/d1_lib.c b/ssl/d1_lib.c index d7e1d740ca..1f77ede0cb 100644 --- a/ssl/d1_lib.c +++ b/ssl/d1_lib.c @@ -17,7 +17,10 @@ #include "internal/ssl_unwrap.h" static int dtls1_handshake_write(SSL_CONNECTION *s); -static const size_t dtls1_link_min_mtu = 256; +static size_t dtls1_link_min_mtu(void); + +/* XDTLS: figure out the right values */ +static const size_t g_probable_mtu[] = { 1500, 512, 256 }; const SSL3_ENC_METHOD DTLSv1_enc_data = { tls1_setup_key_block, @@ -113,7 +116,6 @@ void dtls1_clear_received_buffer(SSL_CONNECTION *s) dtls1_hm_fragment_free(frag); pitem_free(item); } - s->d1->has_change_cipher_spec = 0; } void dtls1_clear_sent_buffer(SSL_CONNECTION *s) @@ -233,18 +235,18 @@ long dtls1_ctrl(SSL *ssl, int cmd, long larg, void *parg) ret = dtls1_handle_timeout(s); break; case DTLS_CTRL_SET_LINK_MTU: - if (larg < (long)dtls1_link_min_mtu) + if (larg < (long)dtls1_link_min_mtu()) return 0; s->d1->link_mtu = larg; return 1; case DTLS_CTRL_GET_LINK_MIN_MTU: - return (long)dtls1_link_min_mtu; + return (long)dtls1_link_min_mtu(); case SSL_CTRL_SET_MTU: /* * We may not have a BIO set yet so can't call dtls1_min_mtu() - * We'll have to make do with dtls1_link_min_mtu and max overhead + * We'll have to make do with dtls1_link_min_mtu() and max overhead */ - if (larg < (long)dtls1_link_min_mtu - DTLS1_MAX_MTU_OVERHEAD) + if (larg < (long)dtls1_link_min_mtu() - DTLS1_MAX_MTU_OVERHEAD) return 0; s->d1->mtu = larg; return larg; @@ -903,11 +905,16 @@ int dtls1_query_mtu(SSL_CONNECTION *s) return 1; } +static size_t dtls1_link_min_mtu(void) +{ + return (g_probable_mtu[(sizeof(g_probable_mtu) / sizeof(g_probable_mtu[0])) - 1]); +} + size_t dtls1_min_mtu(SSL_CONNECTION *s) { SSL *ssl = SSL_CONNECTION_GET_SSL(s); - return dtls1_link_min_mtu - BIO_dgram_get_mtu_overhead(SSL_get_wbio(ssl)); + return dtls1_link_min_mtu() - BIO_dgram_get_mtu_overhead(SSL_get_wbio(ssl)); } size_t DTLS_get_data_mtu(const SSL *ssl) diff --git a/ssl/ech/build.info b/ssl/ech/build.info deleted file mode 100644 index 7f60fb957c..0000000000 --- a/ssl/ech/build.info +++ /dev/null @@ -1,3 +0,0 @@ -$LIBSSL=../../libssl - -SOURCE[$LIBSSL]=ech_ssl_apis.c ech_store.c ech_internal.c ech_helper.c diff --git a/ssl/ech/ech_helper.c b/ssl/ech/ech_helper.c deleted file mode 100644 index 86cb9dbb88..0000000000 --- a/ssl/ech/ech_helper.c +++ /dev/null @@ -1,152 +0,0 @@ -/* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the OpenSSL license (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include -#include "../ssl_local.h" -#include "ech_local.h" -#include "internal/ech_helpers.h" - -/* used in ECH crypto derivations (odd format for EBCDIC goodness) */ -/* "tls ech" */ -static const char OSSL_ECH_CONTEXT_STRING[] = "\x74\x6c\x73\x20\x65\x63\x68"; - -/* - * Construct HPKE "info" input as per spec - * encoding is the ECHconfig being used - * encoding_length is the length of ECHconfig being used - * info is a caller-allocated buffer for results - * info_len is the buffer size on input, used-length on output - * return 1 for success, zero otherwise - */ -int ossl_ech_make_enc_info(const unsigned char *encoding, - size_t encoding_length, - unsigned char *info, size_t *info_len) -{ - WPACKET ipkt = { 0 }; - - if (encoding == NULL || info == NULL || info_len == NULL) - return 0; - if (!WPACKET_init_static_len(&ipkt, info, *info_len, 0) - || !WPACKET_memcpy(&ipkt, OSSL_ECH_CONTEXT_STRING, - sizeof(OSSL_ECH_CONTEXT_STRING) - 1) - /* - * the zero valued octet is required by the spec, section 7.1 so - * a tiny bit better to add it explicitly rather than depend on - * the context string being NUL terminated - */ - || !WPACKET_put_bytes_u8(&ipkt, 0) - || !WPACKET_memcpy(&ipkt, encoding, encoding_length) - || !WPACKET_get_total_written(&ipkt, info_len)) { - WPACKET_cleanup(&ipkt); - return 0; - } - WPACKET_cleanup(&ipkt); - return 1; -} - -/* - * Given a CH find the offsets of the session id, extensions and ECH - * ch is the encoded client hello - * ch_len is the length of ch - * sessid_off returns offset of session_id length - * exts_off points to offset of extensions - * exts_len returns length of extensions - * ech_off returns offset of ECH - * echtype returns the ext type of the ECH - * ech_len returns the length of the ECH - * sni_off returns offset of (outer) SNI - * sni_len returns the length of the SNI - * inner 1 if the ECH is marked as an inner, 0 for outer - * return 1 for success, other otherwise - * - * Offsets are set to zero if relevant thing not found. - * Offsets are returned to the type or length field in question. - * - * Note: input here is untrusted! - */ -int ossl_ech_helper_get_ch_offsets(const unsigned char *ch, size_t ch_len, - size_t *sessid_off, size_t *exts_off, - size_t *exts_len, - size_t *ech_off, uint16_t *echtype, - size_t *ech_len, size_t *sni_off, - size_t *sni_len, int *inner) -{ - unsigned int elen = 0, etype = 0, pi_tmp = 0; - const unsigned char *pp_tmp = NULL, *chstart = NULL, *estart = NULL; - PACKET pkt; - int done = 0; - - if (ch == NULL || ch_len == 0 || sessid_off == NULL || exts_off == NULL - || ech_off == NULL || echtype == NULL || ech_len == NULL - || sni_off == NULL || inner == NULL || exts_len == NULL) - return 0; - *sessid_off = *exts_off = *ech_off = *sni_off = *sni_len = *ech_len = 0; - *exts_len = 0; - *inner = OSSL_ECH_UNKNOWN_CH_TYPE; - *echtype = 0xffff; - if (!PACKET_buf_init(&pkt, ch, ch_len)) - return 0; - chstart = PACKET_data(&pkt); - if (!PACKET_get_net_2(&pkt, &pi_tmp)) - return 0; - /* if we're not TLSv1.2+ then we can bail, but it's not an error */ - if (pi_tmp != TLS1_2_VERSION) - return 1; - /* chew up the packet to extensions */ - if (!PACKET_get_bytes(&pkt, &pp_tmp, SSL3_RANDOM_SIZE) - || (*sessid_off = PACKET_data(&pkt) - chstart) == 0 - || !PACKET_get_1(&pkt, &pi_tmp) /* sessid len */ - || !PACKET_get_bytes(&pkt, &pp_tmp, pi_tmp) /* sessid */ - || !PACKET_get_net_2(&pkt, &pi_tmp) /* ciphersuite len */ - || !PACKET_get_bytes(&pkt, &pp_tmp, pi_tmp) /* suites */ - || !PACKET_get_1(&pkt, &pi_tmp) /* compression meths */ - || !PACKET_get_bytes(&pkt, &pp_tmp, pi_tmp) /* comp meths */ - || (*exts_off = PACKET_data(&pkt) - chstart) == 0 - || !PACKET_get_net_2(&pkt, &pi_tmp) /* len(extensions) */ - || (*exts_len = (size_t)pi_tmp) == 0) - /* - * unexpectedly, we return 1 here, as doing otherwise will - * break some non-ECH test code that truncates CH messages - * The same is true below when looking through extensions. - * That's ok though, we'll only set those offsets we've - * found. - */ - return 1; - /* no extensions is theoretically ok, if uninteresting */ - if (*exts_len == 0) - return 1; - /* find what we want from extensions */ - estart = PACKET_data(&pkt); - while (PACKET_remaining(&pkt) > 0 - && (size_t)(PACKET_data(&pkt) - estart) < *exts_len - && done < 2) { - if (!PACKET_get_net_2(&pkt, &etype) - || !PACKET_get_net_2(&pkt, &elen)) - return 1; /* see note above */ - if (etype == TLSEXT_TYPE_ech) { - if (elen == 0) - return 0; - *ech_off = PACKET_data(&pkt) - chstart - 4; - *echtype = etype; - *ech_len = elen; - done++; - } - if (etype == TLSEXT_TYPE_server_name) { - *sni_off = PACKET_data(&pkt) - chstart - 4; - *sni_len = elen; - done++; - } - if (!PACKET_get_bytes(&pkt, &pp_tmp, elen)) - return 1; /* see note above */ - if (etype == TLSEXT_TYPE_ech) - *inner = pp_tmp[0]; - } - return 1; -} diff --git a/ssl/ech/ech_internal.c b/ssl/ech/ech_internal.c deleted file mode 100644 index 6186514040..0000000000 --- a/ssl/ech/ech_internal.c +++ /dev/null @@ -1,2257 +0,0 @@ -/* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the OpenSSL license (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include -#include -#include -#include "internal/ech_helpers.h" -#include "internal/ssl_unwrap.h" -#include "../ssl_local.h" -#include "../statem/statem_local.h" -#include "ech_local.h" - -#ifndef OPENSSL_NO_ECH - -/* - * Strings used in ECH crypto derivations (odd format for EBCDIC goodness) - */ -/* "ech accept confirmation" */ -static const char OSSL_ECH_ACCEPT_CONFIRM_STRING[] = "\x65\x63\x68\x20\x61\x63\x63\x65\x70\x74\x20\x63\x6f\x6e\x66\x69\x72\x6d\x61\x74\x69\x6f\x6e"; -/* "hrr ech accept confirmation" */ -static const char OSSL_ECH_HRR_CONFIRM_STRING[] = "\x68\x72\x72\x20\x65\x63\x68\x20\x61\x63\x63\x65\x70\x74\x20\x63\x6f\x6e\x66\x69\x72\x6d\x61\x74\x69\x6f\x6e"; - -/* ECH internal API functions */ - -#ifdef OSSL_ECH_SUPERVERBOSE -/* ascii-hex print a buffer nicely for debug/interop purposes */ -void ossl_ech_pbuf(const char *msg, const unsigned char *buf, const size_t blen) -{ - OSSL_TRACE_BEGIN(TLS) - { - if (msg == NULL) { - BIO_printf(trc_out, "msg is NULL\n"); - } else if (buf == NULL || blen == 0) { - BIO_printf(trc_out, "%s: buf is %p\n", msg, (void *)buf); - BIO_printf(trc_out, "%s: blen is %zu\n", msg, blen); - } else { - BIO_printf(trc_out, "%s (%zu)\n", msg, blen); - BIO_dump_indent(trc_out, buf, (int)blen, 4); - } - } - OSSL_TRACE_END(TLS); - return; -} - -/* trace out transcript */ -static void ossl_ech_ptranscript(SSL_CONNECTION *s, const char *msg) -{ - size_t hdatalen = 0; - unsigned char *hdata = NULL; - unsigned char ddata[EVP_MAX_MD_SIZE]; - size_t ddatalen; - - if (s == NULL) - return; - hdatalen = BIO_get_mem_data(s->s3.handshake_buffer, &hdata); - ossl_ech_pbuf(msg, hdata, hdatalen); - if (s->s3.handshake_dgst != NULL) { - if (ssl_handshake_hash(s, ddata, sizeof(ddata), &ddatalen) == 0) { - OSSL_TRACE(TLS, "ssl_handshake_hash failed\n"); - ossl_ech_pbuf(msg, ddata, ddatalen); - } - } - OSSL_TRACE(TLS, "new transbuf:\n"); - ossl_ech_pbuf(msg, s->ext.ech.transbuf, s->ext.ech.transbuf_len); - return; -} -#endif - -static OSSL_ECHSTORE_ENTRY *ossl_echstore_entry_dup(const OSSL_ECHSTORE_ENTRY *orig) -{ - OSSL_ECHSTORE_ENTRY *ret = NULL; - - if (orig == NULL) - return NULL; - ret = OPENSSL_zalloc(sizeof(*ret)); - if (ret == NULL) - return NULL; - ret->version = orig->version; - if (orig->public_name != NULL) { - ret->public_name = OPENSSL_strdup(orig->public_name); - if (ret->public_name == NULL) - goto err; - } - ret->pub_len = orig->pub_len; - if (orig->pub != NULL) { - ret->pub = OPENSSL_memdup(orig->pub, orig->pub_len); - if (ret->pub == NULL) - goto err; - } - ret->nsuites = orig->nsuites; - ret->suites = OPENSSL_memdup(orig->suites, sizeof(OSSL_HPKE_SUITE) * ret->nsuites); - if (ret->suites == NULL) - goto err; - ret->max_name_length = orig->max_name_length; - ret->config_id = orig->config_id; - if (orig->exts != NULL) { - ret->exts = sk_OSSL_ECHEXT_deep_copy(orig->exts, ossl_echext_dup, - ossl_echext_free); - if (ret->exts == NULL) - goto err; - } - ret->loadtime = orig->loadtime; - if (orig->keyshare != NULL) { - if (!EVP_PKEY_up_ref(orig->keyshare)) - goto err; - ret->keyshare = orig->keyshare; - } - ret->for_retry = orig->for_retry; - if (orig->encoded != NULL) { - ret->encoded_len = orig->encoded_len; - ret->encoded = OPENSSL_memdup(orig->encoded, ret->encoded_len); - if (ret->encoded == NULL) - goto err; - } - return ret; -err: - ossl_echstore_entry_free(ret); - return NULL; -} - -/* duplicate an OSSL_ECHSTORE as needed */ -OSSL_ECHSTORE *ossl_echstore_dup(const OSSL_ECHSTORE *old) -{ - OSSL_ECHSTORE *cp = NULL; - - if (old == NULL) - return NULL; - cp = OPENSSL_zalloc(sizeof(*cp)); - if (cp == NULL) - return NULL; - cp->libctx = old->libctx; - if (old->propq != NULL) { - cp->propq = OPENSSL_strdup(old->propq); - if (cp->propq == NULL) - goto err; - } - if (old->entries != NULL) { - cp->entries = sk_OSSL_ECHSTORE_ENTRY_deep_copy(old->entries, - ossl_echstore_entry_dup, - ossl_echstore_entry_free); - if (cp->entries == NULL) - goto err; - } - return cp; -err: - OSSL_ECHSTORE_free(cp); - return NULL; -} - -void ossl_ech_ctx_clear(OSSL_ECH_CTX *ce) -{ - if (ce == NULL) - return; - OSSL_ECHSTORE_free(ce->es); - OPENSSL_free(ce->alpn_outer); - return; -} - -static void ech_free_stashed_key_shares(OSSL_ECH_CONN *ec) -{ - size_t i; - - if (ec == NULL) - return; - for (i = 0; i != ec->num_ks_pkey; i++) { - EVP_PKEY_free(ec->ks_pkey[i]); - ec->ks_pkey[i] = NULL; - } - ec->num_ks_pkey = 0; - return; -} - -void ossl_ech_conn_clear(OSSL_ECH_CONN *ec) -{ - if (ec == NULL) - return; - OSSL_ECHSTORE_free(ec->es); - OPENSSL_free(ec->outer_hostname); - OPENSSL_free(ec->alpn_outer); - OPENSSL_free(ec->former_inner); - OPENSSL_free(ec->transbuf); - OPENSSL_free(ec->innerch); - OPENSSL_free(ec->grease_suite); - OPENSSL_free(ec->sent); - OPENSSL_free(ec->returned); - OPENSSL_free(ec->pub); - OSSL_HPKE_CTX_free(ec->hpke_ctx); - OPENSSL_free(ec->encoded_inner); - ech_free_stashed_key_shares(ec); - return; -} - -/* called from ssl/ssl_lib.c: ossl_ssl_connection_new_int */ -int ossl_ech_conn_init(SSL_CONNECTION *s, SSL_CTX *ctx, - const SSL_METHOD *method) -{ - memset(&s->ext.ech, 0, sizeof(s->ext.ech)); - if (ctx->ext.ech.es != NULL - && (s->ext.ech.es = ossl_echstore_dup(ctx->ext.ech.es)) == NULL) - goto err; - s->ext.ech.cb = ctx->ext.ech.cb; - if (ctx->ext.ech.alpn_outer != NULL) { - s->ext.ech.alpn_outer = OPENSSL_memdup(ctx->ext.ech.alpn_outer, - ctx->ext.ech.alpn_outer_len); - if (s->ext.ech.alpn_outer == NULL) - goto err; - s->ext.ech.alpn_outer_len = ctx->ext.ech.alpn_outer_len; - } - /* initialise type/cid to unknown */ - s->ext.ech.attempted_type = OSSL_ECH_type_unknown; - s->ext.ech.attempted_cid = OSSL_ECH_config_id_unset; - if (s->ext.ech.es != NULL) - s->ext.ech.attempted = 1; - if ((ctx->options & SSL_OP_ECH_GREASE) != 0) - s->options |= SSL_OP_ECH_GREASE; - return 1; -err: - OSSL_ECHSTORE_free(s->ext.ech.es); - s->ext.ech.es = NULL; - OPENSSL_free(s->ext.ech.alpn_outer); - s->ext.ech.alpn_outer = NULL; - s->ext.ech.alpn_outer_len = 0; - return 0; -} - -/* - * Assemble the set of ECHConfig values to return as retry-configs. - * The caller (stoc ECH extension handler) needs to OPENSSL_free the rcfgs - * The rcfgs itself is missing the outer length to make it an ECHConfigList - * so the caller adds that using WPACKET functions - */ -int ossl_ech_get_retry_configs(SSL_CONNECTION *s, unsigned char **rcfgs, - size_t *rcfgslen) -{ - OSSL_ECHSTORE *es = NULL; - OSSL_ECHSTORE_ENTRY *ee = NULL; - int i, num = 0; - size_t retslen = 0; - unsigned char *tmp = NULL, *rets = NULL; - - if (s == NULL || rcfgs == NULL || rcfgslen == NULL) - return 0; - es = s->ext.ech.es; - if (es != NULL && es->entries != NULL) - num = sk_OSSL_ECHSTORE_ENTRY_num(es->entries); - for (i = 0; i != num; i++) { - ee = sk_OSSL_ECHSTORE_ENTRY_value(es->entries, i); - if (ee != NULL && ee->for_retry == OSSL_ECH_FOR_RETRY) { - if (ee->encoded_len > SIZE_MAX - retslen) - goto err; - tmp = (unsigned char *)OPENSSL_realloc(rets, - retslen + ee->encoded_len); - if (tmp == NULL) - goto err; - rets = tmp; - memcpy(rets + retslen, ee->encoded, ee->encoded_len); - retslen += ee->encoded_len; - } - } - *rcfgs = rets; - *rcfgslen = retslen; - return 1; -err: - OPENSSL_free(rets); - *rcfgs = NULL; - *rcfgslen = 0; - return 0; -} - -/* GREASEy constants */ -#define OSSL_ECH_MAX_GREASE_PUB 0x100 /* buffer size for 'enc' values */ -#define OSSL_ECH_MAX_GREASE_CT 0x200 /* max GREASEy ciphertext we'll emit */ - -/* - * Send a random value that looks like a real ECH. - * - * We do GREASEing as follows: - * - always HKDF-SHA256 - * - always AES-128-GCM - * - random config ID, even for requests to same server in same session - * - random enc - * - random looking payload, randomly 144, 176, 208, 240 bytes, no correlation with server - */ -int ossl_ech_send_grease(SSL_CONNECTION *s, WPACKET *pkt) -{ - OSSL_HPKE_SUITE hpke_suite_in = OSSL_HPKE_SUITE_DEFAULT; - OSSL_HPKE_SUITE *hpke_suite_in_p = NULL; - OSSL_HPKE_SUITE hpke_suite = OSSL_HPKE_SUITE_DEFAULT; - size_t pp_at_start = 0, pp_at_end = 0; - size_t senderpub_len = OSSL_ECH_MAX_GREASE_PUB; - size_t cipher_len = 0, cipher_len_jitter = 0; - unsigned char cid, senderpub[OSSL_ECH_MAX_GREASE_PUB]; - unsigned char cipher[OSSL_ECH_MAX_GREASE_CT]; - SSL_CTX *sctx = SSL_CONNECTION_GET_CTX(s); - - if (!WPACKET_get_total_written(pkt, &pp_at_start)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - /* randomly select cipher_len to be one of 144, 176, 208, 244 */ - if (RAND_bytes_ex(sctx->libctx, &cid, 1, 0) <= 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - cipher_len_jitter = cid % 4; - cipher_len = 144; - cipher_len += 32 * cipher_len_jitter; - /* generate a random (1 octet) client id */ - if (RAND_bytes_ex(sctx->libctx, &cid, 1, 0) <= 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - s->ext.ech.attempted_cid = cid; - hpke_suite_in_p = &hpke_suite; - if (s->ext.ech.grease_suite != NULL) { - if (OSSL_HPKE_str2suite(s->ext.ech.grease_suite, &hpke_suite_in) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - hpke_suite_in_p = &hpke_suite_in; - } - if (OSSL_HPKE_get_grease_value(hpke_suite_in_p, &hpke_suite, - senderpub, &senderpub_len, - cipher, cipher_len, - sctx->libctx, sctx->propq) - != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - if (!WPACKET_put_bytes_u16(pkt, s->ext.ech.attempted_type) - || !WPACKET_start_sub_packet_u16(pkt) - || !WPACKET_put_bytes_u8(pkt, OSSL_ECH_OUTER_CH_TYPE) - || !WPACKET_put_bytes_u16(pkt, hpke_suite.kdf_id) - || !WPACKET_put_bytes_u16(pkt, hpke_suite.aead_id) - || !WPACKET_put_bytes_u8(pkt, cid) - || !WPACKET_sub_memcpy_u16(pkt, senderpub, senderpub_len) - || !WPACKET_sub_memcpy_u16(pkt, cipher, cipher_len) - || !WPACKET_close(pkt)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - /* record the ECH sent so we can re-tx same if we hit an HRR */ - OPENSSL_free(s->ext.ech.sent); - if (!WPACKET_get_total_written(pkt, &pp_at_end)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - s->ext.ech.sent_len = pp_at_end - pp_at_start; - s->ext.ech.sent = OPENSSL_malloc(s->ext.ech.sent_len); - if (s->ext.ech.sent == NULL) { - s->ext.ech.sent_len = 0; - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - memcpy(s->ext.ech.sent, WPACKET_get_curr(pkt) - s->ext.ech.sent_len, - s->ext.ech.sent_len); - s->ext.ech.grease = OSSL_ECH_IS_GREASE; - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "ECH - sending GREASE\n"); - } - OSSL_TRACE_END(TLS); - return 1; -} - -/* - * Search the ECH store for one that's a match. If no outer_name was set via - * API then we just take the 1st match where we locally support the HPKE suite. - * If OTOH, an outer_name was provided via API then we prefer the first that - * matches that. Name comparison is via case-insensitive exact matches. - */ -int ossl_ech_pick_matching_cfg(SSL_CONNECTION *s, OSSL_ECHSTORE_ENTRY **ee, - OSSL_HPKE_SUITE *suite) -{ - int namematch = 0, nameoverride = 0, suitematch = 0, num, cind = 0; - unsigned int csuite = 0, tsuite = 0; - size_t hnlen = 0; - OSSL_ECHSTORE_ENTRY *lee = NULL, *tee = NULL; - OSSL_ECHSTORE *es = NULL; - char *hn = NULL; - - if (s == NULL || s->ext.ech.es == NULL || ee == NULL || suite == NULL) - return 0; - *ee = NULL; - es = s->ext.ech.es; - if (es->entries == NULL) - return 0; - num = sk_OSSL_ECHSTORE_ENTRY_num(es->entries); - /* allow API-set pref to override */ - hn = s->ext.ech.outer_hostname; - hnlen = (hn == NULL ? 0 : (unsigned int)strlen(hn)); - if (hnlen != 0) - nameoverride = 1; - if (s->ext.ech.no_outer == 1) { - hn = NULL; - hnlen = 0; - nameoverride = 1; - } - for (cind = 0; cind < num && (suitematch == 0 || namematch == 0); cind++) { - lee = sk_OSSL_ECHSTORE_ENTRY_value(es->entries, cind); - if (lee == NULL || lee->version != OSSL_ECH_RFC9849_VERSION) - continue; - if (nameoverride == 1 && hnlen == 0) { - namematch = 1; - } else { - namematch = 0; - if (hnlen == 0 - || (lee->public_name != NULL - && strlen(lee->public_name) == hnlen - && OPENSSL_strncasecmp(hn, (char *)lee->public_name, - hnlen) - == 0)) - namematch = 1; - } - suitematch = 0; - for (csuite = 0; csuite != lee->nsuites && suitematch == 0; csuite++) { - if (OSSL_HPKE_suite_check(lee->suites[csuite]) == 1) { - if (tee == NULL) { /* remember 1st suite match for override */ - tee = lee; - tsuite = csuite; - } - suitematch = 1; - if (namematch == 1) { /* pick this one if both "fit" */ - *suite = lee->suites[csuite]; - *ee = lee; - break; - } - } - } - } - if (tee != NULL && nameoverride == 1 - && (namematch == 0 || suitematch == 0)) { - *suite = tee->suites[tsuite]; - *ee = tee; - } else if (namematch == 0 || suitematch == 0) { - /* no joy */ - return 0; - } - if (*ee == NULL || (*ee)->pub_len == 0 || (*ee)->pub == NULL) - return 0; - return 1; -} - -/* Make up the ClientHelloInner and EncodedClientHelloInner buffers */ -int ossl_ech_encode_inner(SSL_CONNECTION *s, unsigned char **encoded, - size_t *encoded_len) -{ - int rv = 0; - size_t nraws = 0, ind = 0, innerlen = 0; - WPACKET inner = { 0 }; /* "fake" pkt for inner */ - BUF_MEM *inner_mem = NULL; - RAW_EXTENSION *raws = NULL; - - /* basic checks */ - if (s == NULL) - return 0; - if (s->ext.ech.es == NULL || s->clienthello == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - if ((inner_mem = BUF_MEM_new()) == NULL - || !WPACKET_init(&inner, inner_mem) - /* We don't add the type and 3-octet header as usually done */ - /* Add ver/rnd/sess-id/suites to buffer */ - || !WPACKET_put_bytes_u16(&inner, s->client_version) - || !WPACKET_memcpy(&inner, s->ext.ech.client_random, SSL3_RANDOM_SIZE) - /* Session ID is forced to zero in the encoded inner */ - || !WPACKET_sub_memcpy_u8(&inner, NULL, 0) - /* Ciphers supported */ - || !WPACKET_start_sub_packet_u16(&inner) - || !ssl_cipher_list_to_bytes(s, SSL_get_ciphers(&s->ssl), &inner) - || !WPACKET_close(&inner) - /* COMPRESSION */ - || !WPACKET_start_sub_packet_u8(&inner) - /* Add the NULL compression method */ - || !WPACKET_put_bytes_u8(&inner, 0) - || !WPACKET_close(&inner)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - /* Now handle extensions */ - if (!WPACKET_start_sub_packet_u16(&inner)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - /* Grab a pointer to the already constructed extensions */ - raws = s->clienthello->pre_proc_exts; - nraws = s->clienthello->pre_proc_exts_len; - if (raws == NULL || nraws < TLSEXT_IDX_num_builtins) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - /* We put ECH-compressed stuff first (if any), because we can */ - if (s->ext.ech.n_outer_only > 0) { - if (!WPACKET_put_bytes_u16(&inner, TLSEXT_TYPE_outer_extensions) - || !WPACKET_start_sub_packet_u16(&inner) - /* redundant encoding of more-or-less the same thing */ - || !WPACKET_start_sub_packet_u8(&inner)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - /* add the types for each of the compressed extensions now */ - for (ind = 0; ind != s->ext.ech.n_outer_only; ind++) { - if (!WPACKET_put_bytes_u16(&inner, s->ext.ech.outer_only[ind])) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - } - /* close the 2 sub-packets with the compressed types */ - if (!WPACKET_close(&inner) || !WPACKET_close(&inner)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - } - /* now copy the rest, as "proper" exts, into encoded inner */ - for (ind = 0; ind < TLSEXT_IDX_num_builtins; ind++) { - if (raws[ind].present == 0 || ossl_ech_2bcompressed((int)ind) == 1) - continue; - if (!WPACKET_put_bytes_u16(&inner, raws[ind].type) - || !WPACKET_sub_memcpy_u16(&inner, PACKET_data(&raws[ind].data), - PACKET_remaining(&raws[ind].data))) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - } - if (!WPACKET_close(&inner) /* close the encoded inner packet */ - || !WPACKET_get_length(&inner, &innerlen)) { /* len for inner CH */ - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - *encoded = (unsigned char *)inner_mem->data; - inner_mem->data = NULL; /* keep BUF_MEM_free happy */ - *encoded_len = innerlen; - /* and clean up */ - rv = 1; -err: - WPACKET_cleanup(&inner); - BUF_MEM_free(inner_mem); - return rv; -} - -/* - * Find ECH acceptance signal in a SH - * hrr is 1 if this is for an HRR, otherwise for SH - * acbuf is (a preallocated) 8 octet buffer - * shbuf is a pointer to the SH buffer - * shlen is the length of the SH buf - * return: 1 for success, 0 otherwise - */ -int ossl_ech_find_confirm(SSL_CONNECTION *s, int hrr, - unsigned char acbuf[OSSL_ECH_SIGNAL_LEN]) -{ - unsigned char *acp = NULL; - - if (hrr == 0) { - acp = s->s3.server_random + SSL3_RANDOM_SIZE - OSSL_ECH_SIGNAL_LEN; - } else { /* was set in extension handler */ - if (s->ext.ech.hrrsignal_p == NULL) - return 0; - acp = s->ext.ech.hrrsignal; - } - memcpy(acbuf, acp, OSSL_ECH_SIGNAL_LEN); - return 1; -} - -/* - * reset the handshake buffer for transcript after ECH is good - * buf is the data to put into the transcript (inner CH if no HRR) - * blen is the length of buf - * return 1 for success - */ -int ossl_ech_reset_hs_buffer(SSL_CONNECTION *s, const unsigned char *buf, - size_t blen) -{ -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("RESET transcript to", buf, blen); -#endif - if (s->s3.handshake_buffer != NULL) { - if (BIO_reset(s->s3.handshake_buffer) < 0) - return 0; - } else { - s->s3.handshake_buffer = BIO_new(BIO_s_mem()); - if (s->s3.handshake_buffer == NULL) - return 0; - (void)BIO_set_close(s->s3.handshake_buffer, BIO_CLOSE); - } - EVP_MD_CTX_free(s->s3.handshake_dgst); - s->s3.handshake_dgst = NULL; - /* providing nothing at all is a real use (mid-HRR) */ - if (buf != NULL && blen > 0) - BIO_write(s->s3.handshake_buffer, (void *)buf, (int)blen); - return 1; -} - -/* - * To control the number of zeros added after an EncodedClientHello - we pad - * to a target number of octets or, if there are naturally more, to a number - * divisible by the defined increment (we also do the spec-recommended SNI - * padding thing first) - */ -#define OSSL_ECH_PADDING_TARGET 128 /* ECH cleartext padded to at least this */ -#define OSSL_ECH_PADDING_INCREMENT 32 /* ECH padded to a multiple of this */ - -/* - * figure out how much padding for cleartext (on client) - * ee is the chosen ECHConfig - * return overall length to use including padding or zero on error - * - * "Recommended" inner SNI padding scheme as per spec (section 6.1.3) - * Might remove the mnl stuff later - overall message padding seems - * better really, BUT... we might want to keep this if others (e.g. - * browsers) do it so as to not stand out compared to them. - * - * The "+ 9" constant below is from the specification and is the - * expansion comparing a string length to an encoded SNI extension. - * Same is true of the 31/32 formula below. - * - * Note that the AEAD tag will be added later, so if we e.g. have - * a padded cleartext of 128 octets, the ciphertext will be 144 - * octets. - */ -size_t ossl_ech_calc_padding(SSL_CONNECTION *s, OSSL_ECHSTORE_ENTRY *ee, - size_t encoded_len) -{ - size_t length_of_padding = 0, length_with_snipadding = 0; - size_t innersnipadding = 0, length_with_padding = 0; - size_t mnl = 0, isnilen = 0; - - if (s == NULL || ee == NULL) - return 0; - mnl = ee->max_name_length; - if (mnl != 0) { - /* do weirder padding if SNI present in inner */ - if (s->ext.hostname != NULL) { - isnilen = strlen(s->ext.hostname) + 9; - innersnipadding = (mnl > isnilen) ? (int)(mnl - isnilen) : 0; - } else { - innersnipadding = (int)mnl + 9; - } - } - /* padding is after the inner client hello has been encoded */ - length_with_snipadding = innersnipadding + (int)encoded_len; - length_of_padding = 31 - ((length_with_snipadding - 1) % 32); - length_with_padding = (int)encoded_len + length_of_padding - + innersnipadding; - /* - * Finally - make sure final result is longer than padding target - * and a multiple of our padding increment. - * This is a local addition - we might want to take it out if it makes - * us stick out; or if we take out the above more (uselessly:-) - * complicated scheme above, we may only need this in the end. - */ - if ((length_with_padding % OSSL_ECH_PADDING_INCREMENT) != 0) - length_with_padding += OSSL_ECH_PADDING_INCREMENT - - (length_with_padding % OSSL_ECH_PADDING_INCREMENT); - while (length_with_padding < OSSL_ECH_PADDING_TARGET) - length_with_padding += OSSL_ECH_PADDING_INCREMENT; - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "EAAE: padding: mnl: %zu, lws: %zu " - "lop: %zu, clear_len (len with padding): %zu, orig: %zu\n", - mnl, length_with_snipadding, length_of_padding, - length_with_padding, encoded_len); - } - OSSL_TRACE_END(TLS); - return length_with_padding; -} - -/* - * Calculate AAD and do ECH encryption - * pkt is the packet to send - * return 1 for success, other otherwise - * - * 1. Make up the AAD: the encoded outer, with ECH ciphertext octets zero'd - * 2. Do the encryption - * 3. Put the ECH back into the encoding - * 4. Encode the outer (again!) - */ -int ossl_ech_aad_and_encrypt(SSL_CONNECTION *s, WPACKET *pkt) -{ - int rv = 0; - size_t cipherlen = 0, aad_len = 0, mypub_len = 0, clear_len = 0; - size_t encoded_inner_len = 0; - unsigned char *clear = NULL, *aad = NULL, *mypub = NULL; - unsigned char *encoded_inner = NULL, *cipher_loc = NULL; - - if (s == NULL) - return 0; - if (s->ext.ech.es == NULL || s->ext.ech.es->entries == NULL - || pkt == NULL || s->ssl.ctx == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - /* values calculated in tls_construct_ctos_ech */ - encoded_inner = s->ext.ech.encoded_inner; - encoded_inner_len = s->ext.ech.encoded_inner_len; - clear_len = s->ext.ech.clearlen; - cipherlen = s->ext.ech.cipherlen; - if (!WPACKET_get_total_written(pkt, &aad_len) || aad_len < 4) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - aad_len -= 4; /* ECH/HPKE aad starts after type + 3-octet len */ - aad = WPACKET_get_curr(pkt) - aad_len; - /* where we'll replace zeros with ciphertext */ - cipher_loc = aad + s->ext.ech.cipher_offset; - /* - * close the extensions of the CH - we skipped doing this - * earlier when encoding extensions, to allow for adding the - * ECH here (when doing ECH) - see tls_construct_extensions() - * towards the end - */ - if (!WPACKET_close(pkt)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("EAAE: aad", aad, aad_len); -#endif - clear = OPENSSL_zalloc(clear_len); /* zeros incl. padding */ - if (clear == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - memcpy(clear, encoded_inner, encoded_inner_len); -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("EAAE: padded clear", clear, clear_len); -#endif - /* we're done with this now */ - OPENSSL_free(s->ext.ech.encoded_inner); - s->ext.ech.encoded_inner = NULL; - rv = OSSL_HPKE_seal(s->ext.ech.hpke_ctx, cipher_loc, - &cipherlen, aad, aad_len, clear, clear_len); - OPENSSL_free(clear); - if (rv != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("EAAE: cipher", cipher_loc, cipherlen); - ossl_ech_pbuf("EAAE: hpke mypub", mypub, mypub_len); - /* re-use aad_len for tracing */ - WPACKET_get_total_written(pkt, &aad_len); - ossl_ech_pbuf("EAAE pkt aftr", WPACKET_get_curr(pkt) - aad_len, aad_len); -#endif - return 1; -err: - return 0; -} - -/* - * print info about the ECH-status of an SSL connection - * out is the BIO to use (e.g. stdout/whatever) - * selector OSSL_ECH_SELECT_ALL or just one of the SSL_ECH values - */ -void ossl_ech_status_print(BIO *out, SSL_CONNECTION *s, int selector) -{ - int num = 0, i, has_priv, for_retry; - size_t j; - time_t secs = 0; - char *pn = NULL, *ec = NULL; - OSSL_ECHSTORE *es = NULL; - -#ifdef OSSL_ECH_SUPERVERBOSE - BIO_printf(out, "ech_status_print\n"); - BIO_printf(out, "s=%p\n", (void *)s); -#endif - BIO_printf(out, "ech_attempted=%d\n", s->ext.ech.attempted); - BIO_printf(out, "ech_attempted_type=0x%4x\n", - s->ext.ech.attempted_type); - if (s->ext.ech.attempted_cid == OSSL_ECH_config_id_unset) - BIO_printf(out, "ech_atttempted_cid is unset\n"); - else - BIO_printf(out, "ech_atttempted_cid=0x%02x\n", - s->ext.ech.attempted_cid); - BIO_printf(out, "ech_done=%d\n", s->ext.ech.done); - BIO_printf(out, "ech_grease=%d\n", s->ext.ech.grease); -#ifdef OSSL_ECH_SUPERVERBOSE - BIO_printf(out, "HRR=%d\n", s->hello_retry_request); -#endif - BIO_printf(out, "ech_backend=%d\n", s->ext.ech.backend); - BIO_printf(out, "ech_success=%d\n", s->ext.ech.success); - es = s->ext.ech.es; - if (es == NULL || es->entries == NULL) { - BIO_printf(out, "ECH cfg=NONE\n"); - } else { - num = sk_OSSL_ECHSTORE_ENTRY_num(es->entries); - BIO_printf(out, "%d ECHConfig values loaded\n", num); - for (i = 0; i != num; i++) { - if (selector != OSSL_ECHSTORE_ALL && selector != i) - continue; - BIO_printf(out, "cfg(%d): ", i); - if (OSSL_ECHSTORE_get1_info(es, i, &secs, &pn, &ec, - &has_priv, &for_retry) - != 1) { - OPENSSL_free(pn); /* just in case */ - OPENSSL_free(ec); - continue; - } - BIO_printf(out, "ECH entry: %d public_name: %s age: %lld%s\n", - i, pn, (long long)secs, has_priv ? " (has private key)" : ""); - BIO_printf(out, "\t%s\n", ec); - OPENSSL_free(pn); - OPENSSL_free(ec); - } - } - if (s->ext.ech.returned) { - BIO_printf(out, "ret="); - for (j = 0; j != s->ext.ech.returned_len; j++) { - if (j != 0 && j % 16 == 0) - BIO_printf(out, "\n "); - BIO_printf(out, "%02x:", (unsigned)(s->ext.ech.returned[j])); - } - BIO_printf(out, "\n"); - } - return; -} - -/* - * Swap the inner and outer after ECH success on the client - * return 0 for error, 1 for success - */ -int ossl_ech_swaperoo(SSL_CONNECTION *s) -{ - unsigned char *curr_buf = NULL; - size_t curr_buflen = 0; - - if (s == NULL) - return 0; -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_ptranscript(s, "ech_swaperoo, b4"); -#endif - /* un-stash inner key share(s) */ - if (ossl_ech_unstash_keyshares(s) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - /* - * When not doing HRR... fix up the transcript to reflect the inner CH. - * If there's a client hello at the start of the buffer, then that's - * the outer CH and we want to replace that with the inner. We need to - * be careful that there could be early data or a server hello following - * and we can't lose that. - * - * For HRR... HRR processing code has already done the necessary. - */ - if (s->hello_retry_request == SSL_HRR_NONE) { - BIO *handbuf = s->s3.handshake_buffer; - PACKET pkt, subpkt; - unsigned int mt; - - s->s3.handshake_buffer = NULL; - if (ssl3_init_finished_mac(s) == 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - BIO_free(handbuf); - return 0; - } - if (ssl3_finish_mac(s, s->ext.ech.innerch, s->ext.ech.innerch_len) == 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - BIO_free(handbuf); - return 0; - } - curr_buflen = BIO_get_mem_data(handbuf, &curr_buf); - if (PACKET_buf_init(&pkt, curr_buf, curr_buflen) - && PACKET_get_1(&pkt, &mt) - && mt == SSL3_MT_CLIENT_HELLO - && PACKET_remaining(&pkt) >= 3) { - if (!PACKET_get_length_prefixed_3(&pkt, &subpkt)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - BIO_free(handbuf); - return 0; - } - if (PACKET_remaining(&pkt) > 0) { - if (ssl3_finish_mac(s, PACKET_data(&pkt), PACKET_remaining(&pkt)) == 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - BIO_free(handbuf); - return 0; - } - } - BIO_free(handbuf); - } - } -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_ptranscript(s, "ech_swaperoo, after"); -#endif - /* Declare victory! */ - s->ext.ech.attempted = 1; - s->ext.ech.success = 1; - s->ext.ech.done = 1; - s->ext.ech.grease = OSSL_ECH_NOT_GREASE; - /* time to call an ECH callback, if there's one */ - if (s->ext.ech.es != NULL && s->ext.ech.done == 1 - && s->hello_retry_request != SSL_HRR_PENDING - && s->ext.ech.cb != NULL) { - char pstr[OSSL_ECH_PBUF_SIZE + 1] = { 0 }; - BIO *biom = BIO_new(BIO_s_mem()); - unsigned int cbrv = 0; - - if (biom == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - ossl_ech_status_print(biom, s, OSSL_ECHSTORE_ALL); - BIO_read(biom, pstr, OSSL_ECH_PBUF_SIZE); - cbrv = s->ext.ech.cb(&s->ssl, pstr); - BIO_free(biom); - if (cbrv != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - } - return 1; -} - -/* - * do the HKDF for ECH acceptance checking - * md is the h/s hash - * for_hrr is 1 if we're doing a HRR - * hashval/hashlen is the transcript hash - * hoval is the output, with the ECH acceptance signal - * return 1 for good, 0 for error - */ -static int ech_hkdf_extract_wrap(SSL_CONNECTION *s, EVP_MD *md, int for_hrr, - unsigned char *hashval, size_t hashlen, - unsigned char hoval[OSSL_ECH_SIGNAL_LEN]) -{ - int rv = 0; - unsigned char notsecret[EVP_MAX_MD_SIZE], zeros[EVP_MAX_MD_SIZE]; - size_t retlen = 0, labellen = 0; - EVP_PKEY_CTX *pctx = NULL; - const char *label = NULL; - unsigned char *p = NULL; - SSL_CTX *sctx = SSL_CONNECTION_GET_CTX(s); - - if (for_hrr == 1) { - label = OSSL_ECH_HRR_CONFIRM_STRING; - labellen = sizeof(OSSL_ECH_HRR_CONFIRM_STRING) - 1; - } else { - label = OSSL_ECH_ACCEPT_CONFIRM_STRING; - labellen = sizeof(OSSL_ECH_ACCEPT_CONFIRM_STRING) - 1; - } -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("cc: label", (unsigned char *)label, labellen); -#endif - memset(zeros, 0, EVP_MAX_MD_SIZE); - /* We don't seem to have an hkdf-extract that's exposed by libcrypto */ - pctx = EVP_PKEY_CTX_new_from_name(sctx->libctx, "HKDF", sctx->propq); - if (pctx == NULL - || EVP_PKEY_derive_init(pctx) != 1 - || EVP_PKEY_CTX_hkdf_mode(pctx, - EVP_PKEY_HKDEF_MODE_EXTRACT_ONLY) - != 1 - || EVP_PKEY_CTX_set_hkdf_md(pctx, md) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - /* pick correct client_random */ - if (s->server) - p = s->s3.client_random; - else - p = s->ext.ech.client_random; -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("cc: client_random", p, SSL3_RANDOM_SIZE); -#endif - if (EVP_PKEY_CTX_set1_hkdf_key(pctx, p, SSL3_RANDOM_SIZE) != 1 - || EVP_PKEY_CTX_set1_hkdf_salt(pctx, zeros, (int)hashlen) != 1 - || EVP_PKEY_derive(pctx, NULL, &retlen) != 1 - || hashlen != retlen - || EVP_PKEY_derive(pctx, notsecret, &retlen) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("cc: notsecret", notsecret, hashlen); -#endif - if (hashlen < OSSL_ECH_SIGNAL_LEN - || !tls13_hkdf_expand(s, md, notsecret, - (const unsigned char *)label, labellen, - hashval, hashlen, hoval, - OSSL_ECH_SIGNAL_LEN, 1)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - rv = 1; -err: - EVP_PKEY_CTX_free(pctx); - return rv; -} - -/* - * ECH accept_confirmation calculation - * for_hrr is 1 if this is for an HRR, otherwise for SH - * acbuf is an 8 octet buffer for the confirmation value - * shlen is the server hello length - * return: 1 for success, 0 otherwise - * - * This is a magic value in the ServerHello.random lower 8 octets - * that is used to signal that the inner worked. - * - * As per spec: - * - * accept_confirmation = HKDF-Expand-Label( - * HKDF-Extract(0, ClientHelloInner.random), - * "ech accept confirmation", - * transcript_ech_conf, - * 8) - * - * transcript_ech_conf = ClientHelloInner..ServerHello - * with last 8 octets of ServerHello.random==0x00 - * - * and with differences due to HRR - */ -int ossl_ech_calc_confirm(SSL_CONNECTION *s, int for_hrr, - unsigned char acbuf[OSSL_ECH_SIGNAL_LEN], - const size_t shlen) -{ - int rv = 0; - EVP_MD_CTX *ctx = NULL; - EVP_MD *md = NULL; - unsigned char *tbuf = NULL, *conf_loc = NULL; - unsigned char *fixedshbuf = NULL; - size_t fixedshbuf_len = 0, tlen = 0, chend = 0; - /* shoffset is: 4 + 2 + 32 - 8 */ - size_t shoffset = SSL3_HM_HEADER_LENGTH + sizeof(uint16_t) - + SSL3_RANDOM_SIZE - OSSL_ECH_SIGNAL_LEN; - unsigned int hashlen = 0; - unsigned char hashval[EVP_MAX_MD_SIZE]; - SSL_CTX *sctx = SSL_CONNECTION_GET_CTX(s); - - if ((md = (EVP_MD *)ssl_handshake_md(s)) == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_ECH_REQUIRED); - goto end; - } - if (ossl_ech_intbuf_fetch(s, &tbuf, &tlen) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_ECH_REQUIRED); - goto end; - } - chend = tlen - shlen - 4; - fixedshbuf_len = shlen + 4; - if (s->server) { - chend = tlen - shlen; - fixedshbuf_len = shlen; - } -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("cx: tbuf b4-b4", tbuf, tlen); -#endif - /* put zeros in correct place */ - if (for_hrr == 0) { /* zap magic octets at fixed place for SH */ - conf_loc = tbuf + chend + shoffset; - } else { - if (s->server == 0 && s->ext.ech.hrrsignal_p == NULL) { - /* No ECH found so we'll exit, but set random output */ - if (RAND_bytes_ex(sctx->libctx, acbuf, OSSL_ECH_SIGNAL_LEN, 0) - <= 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_ECH_REQUIRED); - goto end; - } - rv = 1; - goto end; - } - conf_loc = tbuf + tlen - OSSL_ECH_SIGNAL_LEN; - } - memset(conf_loc, 0, OSSL_ECH_SIGNAL_LEN); -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("cx: tbuf after", tbuf, tlen); -#endif - if ((ctx = EVP_MD_CTX_new()) == NULL - || EVP_DigestInit_ex(ctx, md, NULL) <= 0 - || EVP_DigestUpdate(ctx, tbuf, tlen) <= 0 - || EVP_DigestFinal_ex(ctx, hashval, &hashlen) <= 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto end; - } - EVP_MD_CTX_free(ctx); - ctx = NULL; -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("cx: hashval", hashval, hashlen); -#endif - /* calculate and set the final output */ - if (ech_hkdf_extract_wrap(s, md, for_hrr, hashval, hashlen, acbuf) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto end; - } -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("cx: result", acbuf, OSSL_ECH_SIGNAL_LEN); -#endif - /* put confirm value back into transcript */ - if (s->server == 0 && for_hrr == 1) { /* put back the one we got */ - memcpy(conf_loc, s->ext.ech.hrrsignal, OSSL_ECH_SIGNAL_LEN); - } else { - memcpy(conf_loc, acbuf, OSSL_ECH_SIGNAL_LEN); - } - /* on a server, we need to reset the hs buffer now */ - if (s->server && s->hello_retry_request == SSL_HRR_NONE) - ossl_ech_reset_hs_buffer(s, s->ext.ech.innerch, s->ext.ech.innerch_len); - if (s->server && s->hello_retry_request == SSL_HRR_COMPLETE) - ossl_ech_reset_hs_buffer(s, tbuf, tlen - fixedshbuf_len); - rv = 1; -end: - OPENSSL_free(fixedshbuf); - EVP_MD_CTX_free(ctx); - return rv; -} - -/*! - * Given a CH find the offsets of the session id, extensions and ECH - * pkt is the CH - * sessid_off points to offset of session_id length - * exts_off points to offset of extensions - * ech_off points to offset of ECH - * echtype points to the ext type of the ECH - * inner 1 if the ECH is marked as an inner, 0 for outer - * sni_off points to offset of (outer) SNI - * return 1 for success, other otherwise - * - * Offsets are set to zero if relevant thing not found. - * Offsets are returned to the type or length field in question. - * - * Note: input here is untrusted! - */ -int ossl_ech_get_ch_offsets(SSL_CONNECTION *s, PACKET *pkt, size_t *sessid_off, - size_t *exts_off, size_t *ech_off, uint16_t *echtype, - int *inner, size_t *sni_off) -{ - const unsigned char *ch = NULL; - size_t ch_len = 0, exts_len = 0, sni_len = 0, ech_len = 0; - - if (s == NULL) - return 0; - if (pkt == NULL || sessid_off == NULL || exts_off == NULL - || ech_off == NULL || echtype == NULL || inner == NULL - || sni_off == NULL) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - return 0; - } - /* check if we've already done the work */ - if (s->ext.ech.ch_offsets_done == 1) { - *sessid_off = s->ext.ech.sessid_off; - *exts_off = s->ext.ech.exts_off; - *ech_off = s->ext.ech.ech_off; - *echtype = s->ext.ech.echtype; - *inner = s->ext.ech.inner; - *sni_off = s->ext.ech.sni_off; - return 1; - } - *sessid_off = 0; - *exts_off = 0; - *ech_off = 0; - *echtype = OSSL_ECH_type_unknown; - *sni_off = 0; - /* do the work */ - ch_len = PACKET_remaining(pkt); - if (PACKET_peek_bytes(pkt, &ch, ch_len) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_BAD_EXTENSION); - return 0; - } - if (ossl_ech_helper_get_ch_offsets(ch, ch_len, sessid_off, exts_off, - &exts_len, ech_off, echtype, &ech_len, - sni_off, &sni_len, inner) - != 1) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - return 0; - } -#ifdef OSSL_ECH_SUPERVERBOSE - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "orig CH/ECH type: %4x\n", *echtype); - } - OSSL_TRACE_END(TLS); - ossl_ech_pbuf("orig CH", (unsigned char *)ch, ch_len); - ossl_ech_pbuf("orig CH exts", (unsigned char *)ch + *exts_off, exts_len); - ossl_ech_pbuf("orig CH/ECH", (unsigned char *)ch + *ech_off, ech_len); - ossl_ech_pbuf("orig CH SNI", (unsigned char *)ch + *sni_off, sni_len); -#endif - s->ext.ech.sessid_off = *sessid_off; - s->ext.ech.exts_off = *exts_off; - s->ext.ech.ech_off = *ech_off; - s->ext.ech.echtype = *echtype; - s->ext.ech.inner = *inner; - s->ext.ech.sni_off = *sni_off; - s->ext.ech.ch_offsets_done = 1; - return 1; -} - -static void ossl_ech_encch_free(OSSL_ECH_ENCCH *tbf) -{ - if (tbf == NULL) - return; - OPENSSL_free(tbf->enc); - OPENSSL_free(tbf->payload); - return; -} - -/* - * decode outer sni value so we can trace it - * osni_str is the string-form of the SNI - * opd is the outer CH buffer - * opl is the length of the above - * snioffset is where we find the outer SNI - * - * The caller doesn't have to free the osni_str. - */ -static int ech_get_outer_sni(SSL_CONNECTION *s, char **osni_str, - const unsigned char *opd, size_t opl, - size_t snioffset) -{ - PACKET wrap, osni; - unsigned int type, osnilen; - - if (snioffset >= opl - || !PACKET_buf_init(&wrap, opd + snioffset, opl - snioffset) - || !PACKET_get_net_2(&wrap, &type) - || type != 0 - || !PACKET_get_net_2(&wrap, &osnilen) - || !PACKET_get_sub_packet(&wrap, &osni, osnilen)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - return 0; - } - if (tls_parse_ctos_server_name(s, &osni, 0, NULL, 0) != 1) - /* SSLfatal called already */ - return 0; - OPENSSL_free(s->ext.ech.outer_hostname); - *osni_str = s->ext.ech.outer_hostname = s->ext.hostname; - /* clean up what the ECH-unaware parse func above left behind */ - s->ext.hostname = NULL; - s->servername_done = 0; - return 1; -} - -/* - * decode EncryptedClientHello extension value - * pkt contains the ECH value as a PACKET - * retext is the returned decoded structure - * payload_offset is the offset to the ciphertext - * return 1 for good, 0 for bad - * - * SSLfatal called from inside, as needed - */ -static int ech_decode_inbound_ech(SSL_CONNECTION *s, PACKET *pkt, - OSSL_ECH_ENCCH **retext, - size_t *payload_offset) -{ - unsigned int innerorouter = 0xff; - unsigned int pval_tmp; /* tmp placeholder of value from packet */ - OSSL_ECH_ENCCH *extval = NULL; - const unsigned char *startofech = NULL; - - /* - * Decode the inbound ECH value. - * enum { outer(0), inner(1) } ECHClientHelloType; - * struct { - * ECHClientHelloType type; - * select (ECHClientHello.type) { - * case outer: - * HpkeSymmetricCipherSuite cipher_suite; - * uint8 config_id; - * opaque enc<0..2^16-1>; - * opaque payload<1..2^16-1>; - * case inner: - * Empty; - * }; - * } ECHClientHello; - */ - startofech = PACKET_data(pkt); - extval = OPENSSL_zalloc(sizeof(OSSL_ECH_ENCCH)); - if (extval == NULL) - goto err; - if (!PACKET_get_1(pkt, &innerorouter)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - if (innerorouter != OSSL_ECH_OUTER_CH_TYPE) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto err; - } - if (!PACKET_get_net_2(pkt, &pval_tmp)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - extval->kdf_id = pval_tmp & 0xffff; - if (!PACKET_get_net_2(pkt, &pval_tmp)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - extval->aead_id = pval_tmp & 0xffff; - /* config id */ - if (!PACKET_copy_bytes(pkt, &extval->config_id, 1)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("EARLY config id", &extval->config_id, 1); -#endif - s->ext.ech.attempted_cid = extval->config_id; - /* enc - the client's public share */ - if (!PACKET_get_net_2(pkt, &pval_tmp)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - if (pval_tmp > OSSL_ECH_MAX_GREASE_PUB) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto err; - } - if (pval_tmp > PACKET_remaining(pkt)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - if (pval_tmp == 0 && s->hello_retry_request != SSL_HRR_PENDING) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto err; - } else if (pval_tmp > 0 && s->hello_retry_request == SSL_HRR_PENDING) { - unsigned char *tmpenc = NULL; - - /* - * if doing HRR, client should only send this when GREASEing - * and it should be the same value as 1st time, so we'll check - * that - */ - if (s->ext.ech.success == 1) { - /* first decrypt worked, so enc should be empty */ - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto err; - } - if (s->ext.ech.pub == NULL || s->ext.ech.pub_len == 0) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto err; - } - if (pval_tmp != s->ext.ech.pub_len) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto err; - } - tmpenc = OPENSSL_malloc(pval_tmp); - if (tmpenc == NULL) - goto err; - if (!PACKET_copy_bytes(pkt, tmpenc, pval_tmp)) { - OPENSSL_free(tmpenc); - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - if (memcmp(tmpenc, s->ext.ech.pub, pval_tmp) != 0) { - OPENSSL_free(tmpenc); - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto err; - } - OPENSSL_free(tmpenc); - } else if (pval_tmp == 0 && s->hello_retry_request == SSL_HRR_PENDING) { - if (s->ext.ech.pub == NULL || s->ext.ech.pub_len == 0) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto err; - } - extval->enc_len = s->ext.ech.pub_len; - extval->enc = OPENSSL_malloc(extval->enc_len); - if (extval->enc == NULL) - goto err; - memcpy(extval->enc, s->ext.ech.pub, extval->enc_len); - } else { - extval->enc_len = pval_tmp; - extval->enc = OPENSSL_malloc(pval_tmp); - if (extval->enc == NULL) - goto err; - if (!PACKET_copy_bytes(pkt, extval->enc, pval_tmp)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - /* squirrel away that value in case of future HRR */ - OPENSSL_free(s->ext.ech.pub); - s->ext.ech.pub_len = extval->enc_len; - s->ext.ech.pub = OPENSSL_malloc(extval->enc_len); - if (s->ext.ech.pub == NULL) - goto err; - memcpy(s->ext.ech.pub, extval->enc, extval->enc_len); - } - /* payload - the encrypted CH */ - *payload_offset = PACKET_data(pkt) - startofech; - if (!PACKET_get_net_2(pkt, &pval_tmp)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - if (pval_tmp > OSSL_ECH_MAX_PAYLOAD_LEN) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto err; - } - if (pval_tmp == 0 || pval_tmp > PACKET_remaining(pkt)) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto err; - } - extval->payload_len = pval_tmp; - extval->payload = OPENSSL_malloc(pval_tmp); - if (extval->payload == NULL) - goto err; - if (!PACKET_copy_bytes(pkt, extval->payload, pval_tmp)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - *retext = extval; - return 1; -err: - if (extval != NULL) { - ossl_ech_encch_free(extval); - OPENSSL_free(extval); - extval = NULL; - } - return 0; -} - -/* - * find outers if any, and do initial checks - * pkt is the encoded inner - * outers is the array of outer ext types - * n_outers is the number of outers found - * return 1 for good, 0 for error - * - * recall we're dealing with recovered ECH plaintext here so - * the content must be a TLSv1.3 ECH encoded inner - */ -static int ech_find_outers(SSL_CONNECTION *s, PACKET *pkt, - uint16_t *outers, size_t *n_outers) -{ - const unsigned char *pp_tmp; - unsigned int pi_tmp, extlens, etype, elen, olen; - int outers_found = 0; - size_t i; - PACKET op; - - PACKET_null_init(&op); - /* chew up the packet to extensions */ - if (!PACKET_get_net_2(pkt, &pi_tmp) - || pi_tmp != TLS1_2_VERSION - || !PACKET_get_bytes(pkt, &pp_tmp, SSL3_RANDOM_SIZE) - || !PACKET_get_1(pkt, &pi_tmp) - || pi_tmp != 0x00 /* zero'd session id */ - || !PACKET_get_net_2(pkt, &pi_tmp) /* ciphersuite len */ - || !PACKET_get_bytes(pkt, &pp_tmp, pi_tmp) /* suites */ - || !PACKET_get_1(pkt, &pi_tmp) /* compression meths */ - || pi_tmp != 0x01 /* 1 octet of comressions */ - || !PACKET_get_1(pkt, &pi_tmp) /* compression meths */ - || pi_tmp != 0x00 /* 1 octet of no comressions */ - || !PACKET_get_net_2(pkt, &extlens) /* len(extensions) */ - || extlens == 0) { /* no extensions! */ - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - while (PACKET_remaining(pkt) > 0 && outers_found == 0) { - if (!PACKET_get_net_2(pkt, &etype)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - if (etype == TLSEXT_TYPE_outer_extensions) { - outers_found = 1; - if (!PACKET_get_length_prefixed_2(pkt, &op)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - } else { /* skip over */ - if (!PACKET_get_net_2(pkt, &elen) - || !PACKET_get_bytes(pkt, &pp_tmp, elen)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - } - } - - if (outers_found == 0) { /* which is fine! */ - *n_outers = 0; - return 1; - } - /* - * outers has a silly internal length as well and that better - * be one less than the extension length and an even number - * and we only support a certain max of outers - */ - if (!PACKET_get_1(&op, &olen) - || olen % 2 == 1 - || olen / 2 > OSSL_ECH_OUTERS_MAX) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto err; - } - *n_outers = olen / 2; - for (i = 0; i != *n_outers; i++) { - /* check for ones that are not allowed */ - if (!PACKET_get_net_2(&op, &pi_tmp) - || pi_tmp == TLSEXT_TYPE_outer_extensions - || pi_tmp == TLSEXT_TYPE_ech) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto err; - } - outers[i] = (uint16_t)pi_tmp; - } - return 1; -err: - return 0; -} - -/* - * copy one extension from outer to inner - * di is the reconstituted inner CH - * type2copy is the outer type to copy - * exts is the outer extensions packet (changing as we go) - * return 1 for good 0 for error - */ -static int ech_copy_ext(SSL_CONNECTION *s, WPACKET *di, uint16_t type2copy, - PACKET *exts) -{ - unsigned int etype, elen; - const unsigned char *eval; - - /* Skip until we find the thing to copy */ - while (PACKET_remaining(exts) > 0) { - if (!PACKET_get_net_2(exts, &etype) - || !PACKET_get_net_2(exts, &elen) - || !PACKET_get_bytes(exts, &eval, elen)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - if (etype == type2copy) { - if (!WPACKET_put_bytes_u16(di, etype) - || !WPACKET_put_bytes_u16(di, elen) - || !WPACKET_memcpy(di, eval, elen)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - return 1; - } - } - /* we didn't find such an extension - that's an error */ - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); -err: - return 0; -} - -/* - * reconstitute the inner CH from encoded inner and outers - * di is the reconstituted inner CH - * ei is the encoded inner - * ob is the outer CH as a buffer - * ob_len is the size of the above - * outers is the array of outer ext types - * n_outers is the number of outers found - * return 1 for good, 0 for error - */ -static int ech_reconstitute_inner(SSL_CONNECTION *s, WPACKET *di, PACKET *ei, - const unsigned char *ob, size_t ob_len, - uint16_t *outers, size_t n_outers) -{ - const unsigned char *pp_tmp, *eval, *outer_exts; - unsigned int pi_tmp, etype, elen, outer_extslen; - PACKET outer, session_id; - size_t i; - int outers_done = 0; - - if (PACKET_buf_init(&outer, ob, ob_len) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - /* read/write from encoded inner to decoded inner with help from outer */ - if (/* version */ - !PACKET_get_net_2(&outer, &pi_tmp) - || !PACKET_get_net_2(ei, &pi_tmp) - || !WPACKET_put_bytes_u16(di, pi_tmp) - || pi_tmp != TLS1_2_VERSION - - /* client random */ - || !PACKET_get_bytes(&outer, &pp_tmp, SSL3_RANDOM_SIZE) - || !PACKET_get_bytes(ei, &pp_tmp, SSL3_RANDOM_SIZE) - || !WPACKET_memcpy(di, pp_tmp, SSL3_RANDOM_SIZE) - - /* session ID */ - || !PACKET_get_1(ei, &pi_tmp) - || !PACKET_get_length_prefixed_1(&outer, &session_id) - || !WPACKET_start_sub_packet_u8(di) - || (PACKET_remaining(&session_id) != 0 - && !WPACKET_memcpy(di, PACKET_data(&session_id), - PACKET_remaining(&session_id))) - || !WPACKET_close(di) - - /* ciphersuites */ - || !PACKET_get_net_2(&outer, &pi_tmp) /* ciphersuite len */ - || !PACKET_get_bytes(&outer, &pp_tmp, pi_tmp) /* suites */ - || !PACKET_get_net_2(ei, &pi_tmp) /* ciphersuite len */ - || !PACKET_get_bytes(ei, &pp_tmp, pi_tmp) /* suites */ - || !WPACKET_put_bytes_u16(di, pi_tmp) - || !WPACKET_memcpy(di, pp_tmp, pi_tmp) - - /* compression len & meth */ - || !PACKET_get_net_2(ei, &pi_tmp) - || !PACKET_get_net_2(&outer, &pi_tmp) - || !WPACKET_put_bytes_u16(di, pi_tmp)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - /* handle simple, but unlikely, case first */ - if (n_outers == 0) { - if (PACKET_remaining(ei) == 0) - return 1; /* no exts is theoretically possible */ - if (!PACKET_get_net_2(ei, &pi_tmp) /* len(extensions) */ - || !PACKET_get_bytes(ei, &pp_tmp, pi_tmp) - || !WPACKET_put_bytes_u16(di, pi_tmp) - || !WPACKET_memcpy(di, pp_tmp, pi_tmp)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - WPACKET_close(di); - return 1; - } - /* - * general case, copy one by one from inner, 'till we hit - * the outers extension, then copy one by one from outer - */ - if (!PACKET_get_net_2(ei, &pi_tmp) /* len(extensions) */ - || !PACKET_get_net_2(&outer, &outer_extslen) - || !PACKET_get_bytes(&outer, &outer_exts, outer_extslen) - || !WPACKET_start_sub_packet_u16(di)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - while (PACKET_remaining(ei) > 0) { - if (!PACKET_get_net_2(ei, &etype) - || !PACKET_get_net_2(ei, &elen) - || !PACKET_get_bytes(ei, &eval, elen)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - if (etype == TLSEXT_TYPE_outer_extensions) { - PACKET exts; - - if (outers_done++) { /* just do this once */ - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - if (PACKET_buf_init(&exts, outer_exts, outer_extslen) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - for (i = 0; i != n_outers; i++) { - if (ech_copy_ext(s, di, outers[i], &exts) != 1) - /* SSLfatal called already */ - goto err; - } - } else { - if (!WPACKET_put_bytes_u16(di, etype) - || !WPACKET_put_bytes_u16(di, elen) - || !WPACKET_memcpy(di, eval, elen)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - } - } - WPACKET_close(di); - return 1; -err: - WPACKET_cleanup(di); - return 0; -} - -/* - * After successful ECH decrypt, we decode, decompress etc. - * ob is the outer CH as a buffer - * ob_len is the size of the above - * return 1 for success, error otherwise - * - * We need the outer CH as a buffer (ob, below) so we can - * ECH-decompress. - * The plaintext we start from is in encoded_innerch - * and our final decoded, decompressed buffer will end up - * in innerch (which'll then be further processed). - * That further processing includes all existing decoding - * checks so we should be fine wrt fuzzing without having - * to make all checks here (e.g. we can assume that the - * protocol version, NULL compression etc are correct here - - * if not, those'll be caught later). - * Note: there are a lot of literal values here, but it's - * not clear that changing those to #define'd symbols will - * help much - a change to the length of a type or from a - * 2 octet length to longer would seem unlikely. - */ -static int ech_decode_inner(SSL_CONNECTION *s, const unsigned char *ob, - size_t ob_len, unsigned char *encoded_inner, - size_t encoded_inner_len) -{ - int rv = 0; - PACKET ei; /* encoded inner */ - BUF_MEM *di_mem = NULL; - uint16_t outers[OSSL_ECH_OUTERS_MAX]; /* compressed extension types */ - size_t n_outers = 0; - WPACKET di = { 0 }; /* "fake" pkt for inner */ - - if (encoded_inner == NULL || ob == NULL || ob_len == 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - if ((di_mem = BUF_MEM_new()) == NULL - || !BUF_MEM_grow(di_mem, SSL3_RT_MAX_PLAIN_LENGTH) - || !WPACKET_init(&di, di_mem) - || !WPACKET_put_bytes_u8(&di, SSL3_MT_CLIENT_HELLO) - || !WPACKET_start_sub_packet_u24(&di) - || !PACKET_buf_init(&ei, encoded_inner, encoded_inner_len)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } -#ifdef OSSL_ECH_SUPERVERBOSE - memset(outers, -1, sizeof(outers)); /* fill with known values for debug */ -#endif - - /* 1. check for outers and make initial checks of those */ - if (ech_find_outers(s, &ei, outers, &n_outers) != 1) - goto err; /* SSLfatal called already */ - - /* 2. reconstitute inner CH */ - /* reset ei */ - if (PACKET_buf_init(&ei, encoded_inner, encoded_inner_len) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - if (ech_reconstitute_inner(s, &di, &ei, ob, ob_len, outers, n_outers) != 1) - goto err; /* SSLfatal called already */ - /* 3. store final inner CH in connection */ - WPACKET_close(&di); - if (!WPACKET_get_length(&di, &s->ext.ech.innerch_len)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - OPENSSL_free(s->ext.ech.innerch); - s->ext.ech.innerch = (unsigned char *)di_mem->data; - di_mem->data = NULL; - rv = 1; -err: - WPACKET_cleanup(&di); - BUF_MEM_free(di_mem); - return rv; -} - -/* - * wrapper for hpke_dec just to save code repetition - * ee is the selected ECH_STORE entry - * the_ech is the value sent by the client - * aad_len is the length of the AAD to use - * aad is the AAD to use - * forhrr is 0 if not hrr, 1 if this is for 2nd CH - * innerlen points to the size of the recovered plaintext - * return pointer to plaintext or NULL (if error) - * - * The plaintext returned is allocated here and must - * be freed by the caller later. - */ -static unsigned char *hpke_decrypt_encch(SSL_CONNECTION *s, - OSSL_ECHSTORE_ENTRY *ee, - OSSL_ECH_ENCCH *the_ech, - size_t aad_len, unsigned char *aad, - int forhrr, size_t *innerlen) -{ - size_t cipherlen = 0, zind = 0; - unsigned char *cipher = NULL; - size_t senderpublen = 0; - unsigned char *senderpub = NULL; - size_t clearlen = 0; - unsigned char *clear = NULL; - int hpke_mode = OSSL_HPKE_MODE_BASE; - OSSL_HPKE_SUITE hpke_suite = OSSL_HPKE_SUITE_DEFAULT; - unsigned char info[OSSL_ECH_MAX_INFO_LEN]; - size_t info_len = OSSL_ECH_MAX_INFO_LEN; - int rv = 0; - OSSL_HPKE_CTX *hctx = NULL; - SSL_CTX *sctx = SSL_CONNECTION_GET_CTX(s); -#ifdef OSSL_ECH_SUPERVERBOSE - size_t publen = 0; - unsigned char *pub = NULL; -#endif - - if (ee == NULL || ee->nsuites == 0) - return NULL; - cipherlen = the_ech->payload_len; - cipher = the_ech->payload; - senderpublen = the_ech->enc_len; - senderpub = the_ech->enc; - hpke_suite.aead_id = the_ech->aead_id; - hpke_suite.kdf_id = the_ech->kdf_id; - clearlen = cipherlen; /* small overestimate */ - clear = OPENSSL_malloc(clearlen); - if (clear == NULL) - return NULL; - /* The kem_id will be the same for all suites in the entry */ - hpke_suite.kem_id = ee->suites[0].kem_id; -#ifdef OSSL_ECH_SUPERVERBOSE - publen = ee->pub_len; - pub = ee->pub; - ossl_ech_pbuf("aad", aad, aad_len); - ossl_ech_pbuf("my local pub", pub, publen); - ossl_ech_pbuf("senderpub", senderpub, senderpublen); - ossl_ech_pbuf("cipher", cipher, cipherlen); -#endif - if (ossl_ech_make_enc_info(ee->encoded, ee->encoded_len, - info, &info_len) - != 1) { - OPENSSL_free(clear); - return NULL; - } -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("info", info, info_len); -#endif - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, - "hpke_dec suite: kem: %04x, kdf: %04x, aead: %04x\n", - hpke_suite.kem_id, hpke_suite.kdf_id, hpke_suite.aead_id); - } - OSSL_TRACE_END(TLS); - /* - * We may generate externally visible OpenSSL errors - * if decryption fails (which is normal) but we'll - * ignore those as we might be dealing with a GREASEd - * ECH. To do that we need to now ignore some errors - * so we use ERR_set_mark() then later ERR_pop_to_mark(). - */ - ERR_set_mark(); - /* Use OSSL_HPKE_* APIs */ - hctx = OSSL_HPKE_CTX_new(hpke_mode, hpke_suite, OSSL_HPKE_ROLE_RECEIVER, - sctx->libctx, sctx->propq); - if (hctx == NULL) - goto clearerrs; - rv = OSSL_HPKE_decap(hctx, senderpub, senderpublen, ee->keyshare, - info, info_len); - if (rv != 1) - goto clearerrs; - if (forhrr == 1) { - rv = OSSL_HPKE_CTX_set_seq(hctx, 1); - if (rv != 1) { - /* don't clear this error - GREASE can't cause it */ - ERR_clear_last_mark(); - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto end; - } - } - rv = OSSL_HPKE_open(hctx, clear, &clearlen, aad, aad_len, - cipher, cipherlen); -clearerrs: - /* close off our error handling */ - ERR_pop_to_mark(); -end: - OSSL_HPKE_CTX_free(hctx); - if (rv != 1) { - OSSL_TRACE(TLS, "HPKE decryption failed somehow\n"); - OPENSSL_free(clear); - return NULL; - } -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("padded clear", clear, clearlen); -#endif - /* we need to remove possible (actually, v. likely) padding */ - *innerlen = clearlen; - if (ee->version == OSSL_ECH_RFC9849_VERSION) { - /* RFC 9849 pads after the encoded CH with zeros */ - size_t extsoffset = 0; - size_t extslen = 0; - size_t ch_len = 0; - size_t startofsessid = 0; - size_t echoffset = 0; /* offset of start of ECH within CH */ - uint16_t echtype = OSSL_ECH_type_unknown; /* type of ECH seen */ - size_t outersnioffset = 0; /* offset to SNI in outer */ - int innerflag = OSSL_ECH_UNKNOWN_CH_TYPE; - PACKET innerchpkt; - - if (PACKET_buf_init(&innerchpkt, clear, clearlen) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_BAD_EXTENSION); - goto paderr; - } - /* reset the offsets, as we move from outer to inner CH */ - s->ext.ech.ch_offsets_done = 0; - rv = ossl_ech_get_ch_offsets(s, &innerchpkt, &startofsessid, - &extsoffset, &echoffset, &echtype, - &innerflag, &outersnioffset); - if (rv != 1) { - /* SSLfatal called already */ - goto paderr; - } - /* odd form of check below just for emphasis */ - if ((extsoffset + 2) > clearlen) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto paderr; - } - extslen = (unsigned char)(clear[extsoffset]) * 256 - + (unsigned char)(clear[extsoffset + 1]); - ch_len = extsoffset + 2 + extslen; - /* the check below protects us from bogus data */ - if (ch_len > clearlen) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto paderr; - } - /* The RFC calls for that padding to be all zeros */ - - if (*innerlen < ch_len) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto paderr; - } - for (zind = ch_len; zind != *innerlen; zind++) { - if (clear[zind] != 0x00) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto paderr; - } - } - *innerlen = ch_len; -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("unpadded clear", clear, *innerlen); -#endif - return clear; - } else { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - } -paderr: - OPENSSL_free(clear); - return NULL; -} - -/* - * If an ECH is present, attempt decryption - * outerpkt is the packet with the outer CH - * newpkt is the packet with the decrypted inner CH - * return 1 for success, other otherwise - * - * If decryption succeeds, the caller can swap the inner and outer - * CHs so that all further processing will only take into account - * the inner CH. - * - * The fact that decryption worked is signalled to the caller - * via s->ext.ech.success - * - * This function is called early, (hence the name:-), before - * the outer CH decoding has really started, so we need to be - * careful peeking into the packet - * - * The plan: - * 1. check if there's an ECH - * 2. trial-decrypt or check if config matches one loaded - * 3. if decrypt fails tee-up GREASE - * 4. if decrypt worked, decode and de-compress cleartext to - * make up real inner CH for later processing - */ -int ossl_ech_early_decrypt(SSL_CONNECTION *s, PACKET *outerpkt, PACKET *newpkt) -{ - int num = 0, cfgind = -1, foundcfg = 0, forhrr = 0, innerflag = -1; - OSSL_ECH_ENCCH *extval = NULL; - PACKET echpkt; - const unsigned char *startofech = NULL, *opd = NULL; - size_t echlen = 0, clearlen = 0, aad_len = 0; - unsigned char *clear = NULL, *aad = NULL; - /* offsets of things within CH */ - size_t startofsessid = 0, startofexts = 0, echoffset = 0, opl = 0; - size_t outersnioffset = 0, startofciphertext = 0, lenofciphertext = 0; - uint16_t echtype = OSSL_ECH_type_unknown; /* type of ECH seen */ - char *osni_str = NULL; - OSSL_ECHSTORE *es = NULL; - OSSL_ECHSTORE_ENTRY *ee = NULL; - - if (s == NULL) - return 0; - if (outerpkt == NULL || newpkt == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_BAD_EXTENSION); - return 0; - } - /* find offsets - on success, outputs are safe to use */ - if (ossl_ech_get_ch_offsets(s, outerpkt, &startofsessid, &startofexts, - &echoffset, &echtype, &innerflag, - &outersnioffset) - != 1) { - /* SSLfatal called already */ - return 0; - } - if (echoffset == 0 || echtype != TLSEXT_TYPE_ech) - return 1; /* ECH not present or wrong version */ - if (innerflag == 1) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - return 0; - } - s->ext.ech.attempted = 1; /* Remember that we got an ECH */ - s->ext.ech.attempted_type = echtype; - if (s->hello_retry_request == SSL_HRR_PENDING) - forhrr = 1; /* set forhrr if that's correct */ - opl = PACKET_remaining(outerpkt); - opd = PACKET_data(outerpkt); - s->tmp_session_id_len = opd[startofsessid]; /* grab the session id */ - if (s->tmp_session_id_len > SSL_MAX_SSL_SESSION_ID_LENGTH - || startofsessid + 1 + s->tmp_session_id_len > opl) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto err; - } - memcpy(s->tmp_session_id, &opd[startofsessid + 1], s->tmp_session_id_len); - if (outersnioffset > 0) { /* Grab the outer SNI for tracing */ - if (ech_get_outer_sni(s, &osni_str, opd, opl, outersnioffset) != 1) - /* SSLfatal called already */ - goto err; - if (osni_str == NULL) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto err; - } - OSSL_TRACE1(TLS, "EARLY: outer SNI of %s\n", osni_str); - } else { - OSSL_TRACE(TLS, "EARLY: no sign of an outer SNI\n"); - } - if (echoffset > opl - 4) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - startofech = &opd[echoffset + 4]; - echlen = opd[echoffset + 2] * 256 + opd[echoffset + 3]; - if (echlen > opl - echoffset - 4) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - if (PACKET_buf_init(&echpkt, startofech, echlen) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - if (ech_decode_inbound_ech(s, &echpkt, &extval, &startofciphertext) != 1) - goto err; /* SSLfatal already called if needed */ - /* - * startofciphertext is within the ECH value and after the length of the - * ciphertext, so we need to bump it by the offset of ECH within the CH - * plus the ECH type (2 octets) and length (also 2 octets) and that - * ciphertext length (another 2 octets) for a total of 6 octets - */ - startofciphertext += echoffset + 6; - lenofciphertext = extval->payload_len; - aad_len = opl; - if (aad_len < startofciphertext + lenofciphertext) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - aad = OPENSSL_memdup(opd, aad_len); - if (aad == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - memset(aad + startofciphertext, 0, lenofciphertext); -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("EARLY aad", aad, aad_len); -#endif - s->ext.ech.grease = OSSL_ECH_GREASE_UNKNOWN; - if (s->ext.ech.es == NULL) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - goto err; - } - es = s->ext.ech.es; - num = (es == NULL || es->entries == NULL ? 0 - : sk_OSSL_ECHSTORE_ENTRY_num(es->entries)); - for (cfgind = 0; cfgind != num && foundcfg == 0; cfgind++) { - ee = sk_OSSL_ECHSTORE_ENTRY_value(es->entries, cfgind); - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, - "EARLY: rx'd config id (%x) ==? %d-th configured (%x)\n", - extval->config_id, cfgind, ee->config_id); - } - OSSL_TRACE_END(TLS); - if (extval->config_id == ee->config_id) { - unsigned int suite_id; - - /* check aead and kdf match a loaded suite for the config_id */ - for (suite_id = 0; suite_id != ee->nsuites && foundcfg == 0; suite_id++) { - if (ee->suites[suite_id].kdf_id == extval->kdf_id - && ee->suites[suite_id].aead_id == extval->aead_id) { - foundcfg = 1; - } - } - } - } - if (foundcfg == 1) { - clear = hpke_decrypt_encch(s, ee, extval, aad_len, aad, - forhrr, &clearlen); - if (clear == NULL) - s->ext.ech.grease = OSSL_ECH_IS_GREASE; - } - /* if still needed, trial decryptions */ - if (clear == NULL && (s->options & SSL_OP_ECH_TRIALDECRYPT)) { - foundcfg = 0; /* reset as we're trying again */ - for (cfgind = 0; cfgind != num; cfgind++) { - ee = sk_OSSL_ECHSTORE_ENTRY_value(es->entries, cfgind); - clear = hpke_decrypt_encch(s, ee, extval, - aad_len, aad, forhrr, &clearlen); - if (clear != NULL) { - foundcfg = 1; - s->ext.ech.grease = OSSL_ECH_NOT_GREASE; - break; - } - } - } - OPENSSL_free(aad); - aad = NULL; - s->ext.ech.done = 1; /* decrypting worked or not, but we're done now */ - s->ext.ech.grease = OSSL_ECH_IS_GREASE; /* if decrypt fails tee-up GREASE */ - s->ext.ech.success = 0; - if (clear != NULL) { - s->ext.ech.grease = OSSL_ECH_NOT_GREASE; - s->ext.ech.success = 1; - } - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "EARLY: success: %d, assume_grease: %d, " - "foundcfg: %d, cfgind: %d, clearlen: %zd, clear %p\n", - s->ext.ech.success, s->ext.ech.grease, foundcfg, - cfgind, clearlen, (void *)clear); - } - OSSL_TRACE_END(TLS); -#ifdef OSSL_ECH_SUPERVERBOSE - if (foundcfg == 1 && clear != NULL) { /* Bit more logging */ - ossl_ech_pbuf("local config_id", &ee->config_id, 1); - ossl_ech_pbuf("remote config_id", &extval->config_id, 1); - ossl_ech_pbuf("clear", clear, clearlen); - } -#endif - ossl_ech_encch_free(extval); - OPENSSL_free(extval); - extval = NULL; - if (s->ext.ech.grease == OSSL_ECH_IS_GREASE) { - OPENSSL_free(clear); - return 1; - } - /* 4. if decrypt worked, de-compress cleartext to make up real inner CH */ - if (ech_decode_inner(s, opd, opl, clear, clearlen) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - OPENSSL_free(clear); - clear = NULL; -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("Inner CH (decoded)", s->ext.ech.innerch, - s->ext.ech.innerch_len); -#endif - if (PACKET_buf_init(newpkt, s->ext.ech.innerch, - s->ext.ech.innerch_len) - != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - /* tls_process_client_hello doesn't want the message header, so skip it */ - if (!PACKET_forward(newpkt, SSL3_HM_HEADER_LENGTH)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - if (ossl_ech_intbuf_add(s, s->ext.ech.innerch, - s->ext.ech.innerch_len, 0) - != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - return 1; -err: - OPENSSL_free(aad); - if (extval != NULL) { - ossl_ech_encch_free(extval); - OPENSSL_free(extval); - } - OPENSSL_free(clear); - return 0; -} - -int ossl_ech_intbuf_add(SSL_CONNECTION *s, const unsigned char *buf, - size_t blen, int hash_existing) -{ - EVP_MD_CTX *ctx = NULL; - EVP_MD *md = NULL; - unsigned int rv = 0, hashlen = 0; - unsigned char hashval[EVP_MAX_MD_SIZE], *t1; - size_t tlen; - WPACKET tpkt = { 0 }; - BUF_MEM *tpkt_mem = NULL; - - if (s == NULL || buf == NULL || blen == 0) - goto err; - if (hash_existing == 1) { - /* hash existing buffer, needed during HRR */ - if (s->ext.ech.transbuf == NULL - || (md = (EVP_MD *)ssl_handshake_md(s)) == NULL - || (ctx = EVP_MD_CTX_new()) == NULL - || EVP_DigestInit_ex(ctx, md, NULL) <= 0 - || EVP_DigestUpdate(ctx, s->ext.ech.transbuf, - s->ext.ech.transbuf_len) - <= 0 - || EVP_DigestFinal_ex(ctx, hashval, &hashlen) <= 0 - || (tpkt_mem = BUF_MEM_new()) == NULL - || !WPACKET_init(&tpkt, tpkt_mem) - || !WPACKET_put_bytes_u8(&tpkt, SSL3_MT_MESSAGE_HASH) - || !WPACKET_put_bytes_u24(&tpkt, hashlen) - || !WPACKET_memcpy(&tpkt, hashval, hashlen) - || !WPACKET_get_length(&tpkt, &tlen) - || (t1 = OPENSSL_realloc(s->ext.ech.transbuf, tlen + blen)) == NULL) - goto err; - s->ext.ech.transbuf = t1; - memcpy(s->ext.ech.transbuf, tpkt_mem->data, tlen); - memcpy(s->ext.ech.transbuf + tlen, buf, blen); - s->ext.ech.transbuf_len = tlen + blen; - } else { - /* just add new octets */ - if ((t1 = OPENSSL_realloc(s->ext.ech.transbuf, - s->ext.ech.transbuf_len + blen)) - == NULL) - goto err; - s->ext.ech.transbuf = t1; - memcpy(s->ext.ech.transbuf + s->ext.ech.transbuf_len, buf, blen); - s->ext.ech.transbuf_len += blen; - } - rv = 1; -err: - BUF_MEM_free(tpkt_mem); - WPACKET_cleanup(&tpkt); - EVP_MD_CTX_free(ctx); - return rv; -} - -int ossl_ech_intbuf_fetch(SSL_CONNECTION *s, unsigned char **buf, size_t *blen) -{ - if (s == NULL || buf == NULL || blen == NULL || s->ext.ech.transbuf == NULL) - return 0; - *buf = s->ext.ech.transbuf; - *blen = s->ext.ech.transbuf_len; - return 1; -} - -int ossl_ech_stash_keyshares(SSL_CONNECTION *s) -{ - size_t i; - - ech_free_stashed_key_shares(&s->ext.ech); - for (i = 0; i != s->s3.tmp.num_ks_pkey; i++) { - s->ext.ech.ks_pkey[i] = s->s3.tmp.ks_pkey[i]; - if (EVP_PKEY_up_ref(s->ext.ech.ks_pkey[i]) != 1) - return 0; - s->ext.ech.ks_group_id[i] = s->s3.tmp.ks_group_id[i]; - } - s->ext.ech.num_ks_pkey = s->s3.tmp.num_ks_pkey; - return 1; -} - -int ossl_ech_unstash_keyshares(SSL_CONNECTION *s) -{ - size_t i; - - for (i = 0; i != s->s3.tmp.num_ks_pkey; i++) { - EVP_PKEY_free(s->s3.tmp.ks_pkey[i]); - s->s3.tmp.ks_pkey[i] = NULL; - } - for (i = 0; i != s->ext.ech.num_ks_pkey; i++) { - s->s3.tmp.ks_pkey[i] = s->ext.ech.ks_pkey[i]; - if (EVP_PKEY_up_ref(s->s3.tmp.ks_pkey[i]) != 1) - return 0; - s->s3.tmp.ks_group_id[i] = s->ext.ech.ks_group_id[i]; - } - s->s3.tmp.num_ks_pkey = s->ext.ech.num_ks_pkey; - ech_free_stashed_key_shares(&s->ext.ech); - return 1; -} -#endif diff --git a/ssl/ech/ech_local.h b/ssl/ech/ech_local.h deleted file mode 100644 index dff7a9160b..0000000000 --- a/ssl/ech/ech_local.h +++ /dev/null @@ -1,385 +0,0 @@ -/* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the OpenSSL license (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* - * Internal data structures and prototypes for handling - * Encrypted ClientHello (ECH) - */ -#ifndef OPENSSL_NO_ECH - -#ifndef HEADER_ECH_LOCAL_H -#define HEADER_ECH_LOCAL_H - -#include -#include -#include - -#include -#include -#include - -/* - * Define this to get loads more lines of tracing which is - * very useful for interop. - * This needs tracing enabled at build time, e.g.: - * $ ./config enable-ssl-trace enable-trace - * This added tracing will finally (mostly) disappear once the ECH RFC - * has issued, but is very useful for interop testing so some of it might - * be retained. - */ -#define OSSL_ECH_SUPERVERBOSE - -/* values for s->ext.ech.grease */ -#define OSSL_ECH_GREASE_UNKNOWN -1 /* when we're not yet sure */ -#define OSSL_ECH_NOT_GREASE 0 /* when decryption worked */ -#define OSSL_ECH_IS_GREASE 1 /* when decryption failed or GREASE wanted */ - -/* value for uninitialised ECH version */ -#define OSSL_ECH_type_unknown 0xffff -/* value for not yet set ECH config_id */ -#define OSSL_ECH_config_id_unset -1 - -#define OSSL_ECH_OUTER_CH_TYPE 0 /* outer ECHClientHello enum */ -#define OSSL_ECH_INNER_CH_TYPE 1 /* inner ECHClientHello enum */ -#define OSSL_ECH_UNKNOWN_CH_TYPE -1 /* we don't know yet */ - -#define OSSL_ECH_CIPHER_LEN 4 /* ECHCipher length (2 for kdf, 2 for aead) */ - -#define OSSL_ECH_SIGNAL_LEN 8 /* length of ECH acceptance signal */ - -/* size of string buffer returned via ECH callback */ -#define OSSL_ECH_PBUF_SIZE 8 * 1024 - -#ifndef CLIENT_VERSION_LEN -/* - * This is the legacy version length, i.e. len(0x0303). The same - * label is used in e.g. test/sslapitest.c and elsewhere but not - * defined in a header file I could find. - */ -#define CLIENT_VERSION_LEN 2 -#endif - -/* - * Reminder of what goes in DNS for ECH RFC XXXX - * - * opaque HpkePublicKey<1..2^16-1>; - * uint16 HpkeKemId; // Defined in I-D.irtf-cfrg-hpke - * uint16 HpkeKdfId; // Defined in I-D.irtf-cfrg-hpke - * uint16 HpkeAeadId; // Defined in I-D.irtf-cfrg-hpke - * struct { - * HpkeKdfId kdf_id; - * HpkeAeadId aead_id; - * } HpkeSymmetricCipherSuite; - * struct { - * uint8 config_id; - * HpkeKemId kem_id; - * HpkePublicKey public_key; - * HpkeSymmetricCipherSuite cipher_suites<4..2^16-4>; - * } HpkeKeyConfig; - * struct { - * HpkeKeyConfig key_config; - * uint8 maximum_name_length; - * opaque public_name<1..255>; - * Extension extensions<0..2^16-1>; - * } ECHConfigContents; - * struct { - * uint16 version; - * uint16 length; - * select (ECHConfig.version) { - * case 0xfe0d: ECHConfigContents contents; - * } - * } ECHConfig; - * ECHConfig ECHConfigList<1..2^16-1>; - */ - -typedef struct ossl_echext_st { - uint16_t type; - uint16_t len; - unsigned char *val; -} OSSL_ECHEXT; - -DEFINE_STACK_OF(OSSL_ECHEXT) - -typedef struct ossl_echstore_entry_st { - uint16_t version; /* 0xfe0d for RFC XXXX */ - char *public_name; - size_t pub_len; - unsigned char *pub; - unsigned int nsuites; - OSSL_HPKE_SUITE *suites; - uint8_t max_name_length; - uint8_t config_id; - STACK_OF(OSSL_ECHEXT) *exts; - time_t loadtime; /* time public and private key were loaded from file */ - EVP_PKEY *keyshare; /* long(ish) term ECH private keyshare on a server */ - int for_retry; /* whether to use this ECHConfigList in a retry */ - size_t encoded_len; /* length of overall encoded content */ - unsigned char *encoded; /* overall encoded content */ -} OSSL_ECHSTORE_ENTRY; - -/* - * What we send in the ech CH extension: - * enum { outer(0), inner(1) } ECHClientHelloType; - * struct { - * ECHClientHelloType type; - * select (ECHClientHello.type) { - * case outer: - * HpkeSymmetricCipherSuite cipher_suite; - * uint8 config_id; - * opaque enc<0..2^16-1>; - * opaque payload<1..2^16-1>; - * case inner: - * Empty; - * }; - * } ECHClientHello; - * - */ -typedef struct ech_encch_st { - uint16_t kdf_id; /* ciphersuite */ - uint16_t aead_id; /* ciphersuite */ - uint8_t config_id; /* (maybe) identifies DNS RR value used */ - size_t enc_len; /* public share */ - unsigned char *enc; /* public share for sender */ - size_t payload_len; /* ciphertext */ - unsigned char *payload; /* ciphertext */ -} OSSL_ECH_ENCCH; - -DEFINE_STACK_OF(OSSL_ECHSTORE_ENTRY) - -struct ossl_echstore_st { - STACK_OF(OSSL_ECHSTORE_ENTRY) *entries; - OSSL_LIB_CTX *libctx; - char *propq; -}; - -/* ECH details associated with an SSL_CTX */ -typedef struct ossl_ech_ctx_st { - /* - * We could make es ref-counted, but that seems like a premature - * optimisation, given we don't currently expect many applications - * to have many SSL_CTX/SSL structures using many ECH configurations. - * Could fairly easily be done if experience warrants. - */ - OSSL_ECHSTORE *es; /* ECHConfigList details */ - unsigned char *alpn_outer; - size_t alpn_outer_len; - SSL_ech_cb_func cb; /* callback function for when ECH "done" */ -} OSSL_ECH_CTX; - -/* ECH details associated with an SSL_CONNECTION */ -typedef struct ossl_ech_conn_st { - /* - * We could make es ref-counted, but that seems like a premature - * optimisation, given we don't currently expect many applications - * to have many SSL_CTX/SSL structures using many ECH configurations. - * Could fairly easily be done if experience warrants. - */ - OSSL_ECHSTORE *es; /* ECHConfigList details */ - int no_outer; /* set to 1 if we should send no outer SNI at all */ - char *outer_hostname; - unsigned char *alpn_outer; - size_t alpn_outer_len; - SSL_ech_cb_func cb; /* callback function for when ECH "done" */ - /* - * If ECH fails, then we switch to verifying the cert for the - * outer_hostname, meanwhile we still want to be able to trace - * the value we tried as the inner SNI for debug purposes - */ - char *former_inner; - /* inner CH transcript buffer */ - unsigned char *transbuf; - size_t transbuf_len; - /* inner ClientHello before ECH compression */ - unsigned char *innerch; - size_t innerch_len; - /* encoded inner CH */ - unsigned char *encoded_inner; - size_t encoded_inner_len; - /* lengths calculated early, used when encrypting at end of processing */ - size_t clearlen; - size_t cipherlen; - /* location to put ciphertext, initially filled with zeros */ - size_t cipher_offset; - /* - * Extensions are "outer-only" if the value is only sent in the - * outer CH and only the type is sent in the inner CH. - * We use this array to keep track of the extension types that - * have values only in the outer CH - * Currently, this is basically controlled at compile time, but - * in a way that could be varied, or, in future, put under - * run-time control, so having this isn't so much an overhead. - */ - uint16_t outer_only[OSSL_ECH_OUTERS_MAX]; - size_t n_outer_only; /* the number of outer_only extensions so far */ - /* - * We store/access the index of the extension handler in - * s->ext.ech.ext_ind, as we'd otherwise not know it here. - * Be nice were there a better way to handle that. - * Index of the current extension's entry in ext_defs - this is - * to avoid the need to change a couple of extension APIs. - */ - int ext_ind; - /* ECH status vars */ - int ch_depth; /* set during CH creation, 0: doing outer, 1: doing inner */ - int attempted; /* 1 if ECH was or is being attempted, 0 otherwise */ - int done; /* 1 if we've finished ECH calculations, 0 otherwise */ - uint16_t attempted_type; /* ECH version used */ - int attempted_cid; /* ECH config id sent/rx'd */ - int backend; /* 1 if we're a server backend in split-mode, 0 otherwise */ - /* When using a PSK stash the tick_identity from inner, for outer */ - int tick_identity; - /* - * success is 1 if ECH succeeded, 0 otherwise, on the server this - * is known early, on the client we need to wait for the ECH confirm - * calculation based on the SH (or 2nd SH in case of HRR) - */ - int success; - /* - * we set this when we've gotten to the end of the handshake and - * the only thing that went wrong was ECH - in that case we're - * ok to provide the retry-configs to the client, otherwise better - * not. - */ - int retry_configs_ok; - int inner_ech_seen_ok; /* set if we see inner ECH as expected */ - int grease; /* 1 if we're GREASEing, 0 otherwise */ - char *grease_suite; /* HPKE suite string for GREASEing */ - unsigned char *sent; /* GREASEy ECH value sent, in case needed for re-tx */ - size_t sent_len; - unsigned char *returned; /* binary ECHConfigList retry-configs value */ - size_t returned_len; - unsigned char *pub; /* client ephemeral public kept by server in case HRR */ - size_t pub_len; - OSSL_HPKE_CTX *hpke_ctx; /* HPKE context, needed for HRR */ - /* - * Offsets of various things we need to know about in an inbound - * ClientHello (CH) plus the type of ECH and whether that CH is an inner or - * outer CH. We find these once for the outer CH, by roughly parsing the CH - * so store them for later re-use. We need to re-do this parsing when we - * get the 2nd CH in the case of HRR, and when we move to processing the - * inner CH after successful ECH decyption, so we have a flag to say if - * we've done the work or not. - */ - int ch_offsets_done; - size_t sessid_off; /* offset of session_id length */ - size_t exts_off; /* to offset of extensions */ - size_t ech_off; /* offset of ECH */ - size_t sni_off; /* offset of (outer) SNI */ - int echtype; /* ext type of the ECH */ - int inner; /* 1 if the ECH is marked as an inner, 0 for outer */ - /* - * A pointer to, and copy of, the hrrsignal from an HRR message. - * We need both, as we zero-out the octets when re-calculating and - * may need to put back what the server included so the transcript - * is correct when ECH acceptance failed. - */ - unsigned char *hrrsignal_p; - unsigned char hrrsignal[OSSL_ECH_SIGNAL_LEN]; - /* - * Fields that differ on client between inner and outer that we need to - * keep and swap over IFF ECH has succeeded. Same names chosen as are - * used in SSL_CONNECTION - */ - EVP_PKEY *ks_pkey[OPENSSL_CLIENT_MAX_KEY_SHARES]; - /* The IDs of the keyshare keys */ - uint16_t ks_group_id[OPENSSL_CLIENT_MAX_KEY_SHARES]; - size_t num_ks_pkey; /* how many keyshares are there */ - unsigned char client_random[SSL3_RANDOM_SIZE]; /* CH random */ -} OSSL_ECH_CONN; - -/* Return values from ossl_ech_same_ext */ -#define OSSL_ECH_SAME_EXT_ERR 0 /* bummer something wrong */ -#define OSSL_ECH_SAME_EXT_DONE 1 /* proceed with same value in inner/outer */ -#define OSSL_ECH_SAME_EXT_CONTINUE 2 /* generate a new value for outer CH */ - -/* - * During extension construction (in extensions_clnt.c, and surprisingly also in - * extensions.c), we need to handle inner/outer CH cloning - ossl_ech_same_ext - * will (depending on compile time handling options) copy the value from - * CH.inner to CH.outer or else processing will continue, for a 2nd call, - * likely generating a fresh value for the outer CH. The fresh value could well - * be the same as in the inner. - * - * This macro should be called in each _ctos_ function that doesn't explicitly - * have special ECH handling. There are some _ctos_ functions that are called - * from a server, but we don't want to do anything in such cases. We also - * screen out cases where the context is not handling the ClientHello. - * - * Note that the placement of this macro needs a bit of thought - it has to go - * after declarations (to keep the ansi-c compile happy) and also after any - * checks that result in the extension not being sent but before any relevant - * state changes that would affect a possible 2nd call to the constructor. - * Luckily, that's usually not too hard, but it's not mechanical. - */ -#define ECH_SAME_EXT(s, context, pkt) \ - if (context == SSL_EXT_CLIENT_HELLO && !s->server \ - && s->ext.ech.es != NULL && s->ext.ech.grease == 0) { \ - int ech_iosame_rv = ossl_ech_same_ext(s, pkt); \ - \ - if (ech_iosame_rv == OSSL_ECH_SAME_EXT_ERR) \ - return EXT_RETURN_FAIL; \ - if (ech_iosame_rv == OSSL_ECH_SAME_EXT_DONE) \ - return EXT_RETURN_SENT; \ - /* otherwise continue as normal */ \ - } - -/* Internal ECH APIs */ - -OSSL_ECHSTORE *ossl_echstore_dup(const OSSL_ECHSTORE *old); -void ossl_echstore_entry_free(OSSL_ECHSTORE_ENTRY *ee); -void ossl_ech_ctx_clear(OSSL_ECH_CTX *ce); -int ossl_ech_conn_init(SSL_CONNECTION *s, SSL_CTX *ctx, - const SSL_METHOD *method); -void ossl_ech_conn_clear(OSSL_ECH_CONN *ec); -void ossl_echext_free(OSSL_ECHEXT *e); -OSSL_ECHEXT *ossl_echext_dup(const OSSL_ECHEXT *src); -#ifdef OSSL_ECH_SUPERVERBOSE -void ossl_ech_pbuf(const char *msg, - const unsigned char *buf, const size_t blen); -#endif -int ossl_ech_get_retry_configs(SSL_CONNECTION *s, unsigned char **rcfgs, - size_t *rcfgslen); -int ossl_ech_send_grease(SSL_CONNECTION *s, WPACKET *pkt); -int ossl_ech_pick_matching_cfg(SSL_CONNECTION *s, OSSL_ECHSTORE_ENTRY **ee, - OSSL_HPKE_SUITE *suite); -int ossl_ech_encode_inner(SSL_CONNECTION *s, unsigned char **encoded, - size_t *encoded_len); -int ossl_ech_find_confirm(SSL_CONNECTION *s, int hrr, - unsigned char acbuf[OSSL_ECH_SIGNAL_LEN]); -int ossl_ech_reset_hs_buffer(SSL_CONNECTION *s, const unsigned char *buf, - size_t blen); -int ossl_ech_aad_and_encrypt(SSL_CONNECTION *s, WPACKET *pkt); -int ossl_ech_swaperoo(SSL_CONNECTION *s); -int ossl_ech_calc_confirm(SSL_CONNECTION *s, int for_hrr, - unsigned char acbuf[OSSL_ECH_SIGNAL_LEN], - const size_t shlen); - -/* these are internal but located in ssl/statem/extensions.c */ -int ossl_ech_same_ext(SSL_CONNECTION *s, WPACKET *pkt); -int ossl_ech_same_key_share(void); -int ossl_ech_2bcompressed(size_t ind); -int ossl_ech_copy_inner2outer(SSL_CONNECTION *s, uint16_t ext_type, int ind, - WPACKET *pkt); - -int ossl_ech_get_ch_offsets(SSL_CONNECTION *s, PACKET *pkt, size_t *sessid, - size_t *exts, size_t *echoffset, uint16_t *echtype, - int *inner, size_t *snioffset); -int ossl_ech_early_decrypt(SSL_CONNECTION *s, PACKET *outerpkt, PACKET *newpkt); -void ossl_ech_status_print(BIO *out, SSL_CONNECTION *s, int selector); - -int ossl_ech_intbuf_add(SSL_CONNECTION *s, const unsigned char *buf, - size_t blen, int hash_existing); -int ossl_ech_intbuf_fetch(SSL_CONNECTION *s, unsigned char **buf, size_t *blen); -size_t ossl_ech_calc_padding(SSL_CONNECTION *s, OSSL_ECHSTORE_ENTRY *ee, - size_t encoded_len); -int ossl_ech_stash_keyshares(SSL_CONNECTION *s); -int ossl_ech_unstash_keyshares(SSL_CONNECTION *s); - -#endif -#endif diff --git a/ssl/ech/ech_ssl_apis.c b/ssl/ech/ech_ssl_apis.c deleted file mode 100644 index f79ae947f9..0000000000 --- a/ssl/ech/ech_ssl_apis.c +++ /dev/null @@ -1,431 +0,0 @@ -/* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the OpenSSL license (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include -#include "internal/ssl_unwrap.h" -#include "../ssl_local.h" - -int SSL_CTX_set1_echstore(SSL_CTX *ctx, OSSL_ECHSTORE *es) -{ - if (ctx == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return 0; - } - OSSL_ECHSTORE_free(ctx->ext.ech.es); - ctx->ext.ech.es = NULL; - if (es == NULL) - return 1; - if ((ctx->ext.ech.es = ossl_echstore_dup(es)) == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - return 0; - } - return 1; -} - -int SSL_set1_echstore(SSL *ssl, OSSL_ECHSTORE *es) -{ - SSL_CONNECTION *s; - - s = SSL_CONNECTION_FROM_SSL(ssl); - if (s == NULL) - return 0; - OSSL_ECHSTORE_free(s->ext.ech.es); - s->ext.ech.es = NULL; - if (es == NULL) - return 1; - if ((s->ext.ech.es = ossl_echstore_dup(es)) == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - /* - * Here, and below, if the application calls an API that implies it - * wants to try ECH, then we set attempted to 1 - */ - s->ext.ech.attempted = 1; - return 1; -} - -OSSL_ECHSTORE *SSL_CTX_get1_echstore(const SSL_CTX *ctx) -{ - OSSL_ECHSTORE *dup = NULL; - - if (ctx == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return NULL; - } - if (ctx->ext.ech.es == NULL) - return NULL; - if ((dup = ossl_echstore_dup(ctx->ext.ech.es)) == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - return NULL; - } - return dup; -} - -OSSL_ECHSTORE *SSL_get1_echstore(const SSL *ssl) -{ - SSL_CONNECTION *s; - OSSL_ECHSTORE *dup = NULL; - - s = SSL_CONNECTION_FROM_SSL(ssl); - if (s == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return NULL; - } - if (s->ext.ech.es == NULL) - return NULL; - if ((dup = ossl_echstore_dup(s->ext.ech.es)) == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - return NULL; - } - return dup; -} - -int SSL_ech_set1_server_names(SSL *ssl, const char *inner_name, - const char *outer_name, int no_outer) -{ - SSL_CONNECTION *s; - - s = SSL_CONNECTION_FROM_SSL(ssl); - if (s == NULL) - return 0; - OPENSSL_free(s->ext.hostname); - s->ext.hostname = NULL; - if (inner_name != NULL) { - s->ext.hostname = OPENSSL_strdup(inner_name); - if (s->ext.hostname == NULL) - return 0; - } - OPENSSL_free(s->ext.ech.outer_hostname); - s->ext.ech.outer_hostname = NULL; - if (no_outer == 0 && outer_name != NULL && strlen(outer_name) > 0) { - s->ext.ech.outer_hostname = OPENSSL_strdup(outer_name); - if (s->ext.ech.outer_hostname == NULL) - return 0; - } - s->ext.ech.no_outer = no_outer; - s->ext.ech.attempted = 1; - return 1; -} - -int SSL_ech_set1_outer_server_name(SSL *ssl, const char *outer_name, - int no_outer) -{ - SSL_CONNECTION *s; - - s = SSL_CONNECTION_FROM_SSL(ssl); - if (s == NULL) - return 0; - OPENSSL_free(s->ext.ech.outer_hostname); - s->ext.ech.outer_hostname = NULL; - if (no_outer == 0 && outer_name != NULL && strlen(outer_name) > 0) { - s->ext.ech.outer_hostname = OPENSSL_strdup(outer_name); - if (s->ext.ech.outer_hostname == NULL) - return 0; - } - s->ext.ech.no_outer = no_outer; - s->ext.ech.attempted = 1; - return 1; -} - -/* - * Note that this function returns 1 for success and 0 for error. This - * contrasts with SSL_set1_alpn_protos() which (unusually for OpenSSL) - * returns 0 for success and 1 on error. - */ -int SSL_ech_set1_outer_alpn_protos(SSL *ssl, const unsigned char *protos, - const size_t protos_len) -{ - SSL_CONNECTION *s; - - s = SSL_CONNECTION_FROM_SSL(ssl); - if (s == NULL) - return 0; - OPENSSL_free(s->ext.ech.alpn_outer); - s->ext.ech.alpn_outer = NULL; - if (protos == NULL) - return 1; - if (protos_len == 0) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return 0; - } - s->ext.ech.alpn_outer = OPENSSL_memdup(protos, protos_len); - if (s->ext.ech.alpn_outer == NULL) - return 0; - s->ext.ech.alpn_outer_len = protos_len; - s->ext.ech.attempted = 1; - return 1; -} - -int SSL_ech_get1_status(SSL *ssl, char **inner_sni, char **outer_sni) -{ - char *sinner = NULL; - char *souter = NULL; - SSL_CONNECTION *s = SSL_CONNECTION_FROM_SSL(ssl); - - if (s == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return SSL_ECH_STATUS_FAILED; - } - if (outer_sni == NULL || inner_sni == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - return SSL_ECH_STATUS_FAILED; - } - *outer_sni = NULL; - *inner_sni = NULL; - if (s->ext.ech.grease == OSSL_ECH_IS_GREASE) { - if (s->ext.ech.returned != NULL) - return SSL_ECH_STATUS_GREASE_ECH; - return SSL_ECH_STATUS_GREASE; - } - if ((s->options & SSL_OP_ECH_GREASE) != 0 && s->ext.ech.attempted != 1) - return SSL_ECH_STATUS_GREASE; - if (s->ext.ech.backend == 1) { - if (s->ext.hostname != NULL - && (*inner_sni = OPENSSL_strdup(s->ext.hostname)) == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - return SSL_ECH_STATUS_FAILED; - } - return SSL_ECH_STATUS_BACKEND; - } - if (s->ext.ech.es == NULL) - return SSL_ECH_STATUS_NOT_CONFIGURED; - /* Set output vars - note we may be pointing to NULL which is fine */ - if (s->server == 0) { - sinner = s->ext.hostname; - if (s->ext.ech.attempted == 1 && s->ext.ech.success == 0) - sinner = s->ext.ech.former_inner; - if (s->ext.ech.no_outer == 0) - souter = s->ext.ech.outer_hostname; - else - souter = NULL; - } else { - if (s->ext.ech.es != NULL && s->ext.ech.success == 1) { - sinner = s->ext.hostname; - souter = s->ext.ech.outer_hostname; - } - } - if (s->ext.ech.es != NULL && s->ext.ech.attempted == 1 - && s->ext.ech.attempted_type == TLSEXT_TYPE_ech - && s->ext.ech.grease != OSSL_ECH_IS_GREASE) { - long vr = X509_V_OK; - - vr = SSL_get_verify_result(ssl); - if (sinner != NULL - && (*inner_sni = OPENSSL_strdup(sinner)) == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - return SSL_ECH_STATUS_FAILED; - } - if (souter != NULL - && (*outer_sni = OPENSSL_strdup(souter)) == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - return SSL_ECH_STATUS_FAILED; - } - if (s->ext.ech.success == 1) { - if (vr == X509_V_OK) - return SSL_ECH_STATUS_SUCCESS; - else - return SSL_ECH_STATUS_BAD_NAME; - } else { - if (vr == X509_V_OK && s->ext.ech.returned != NULL) - return SSL_ECH_STATUS_FAILED_ECH; - else if (vr != X509_V_OK && s->ext.ech.returned != NULL) - return SSL_ECH_STATUS_FAILED_ECH_BAD_NAME; - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - return SSL_ECH_STATUS_FAILED; - } - } - return SSL_ECH_STATUS_NOT_TRIED; -} - -int SSL_ech_set1_grease_suite(SSL *ssl, const char *suite) -{ - SSL_CONNECTION *s; - OSSL_HPKE_SUITE hpke_suite_in = OSSL_HPKE_SUITE_DEFAULT; - - s = SSL_CONNECTION_FROM_SSL(ssl); - if (s == NULL) - return 0; - /* check suite makes sense */ - if (OSSL_HPKE_str2suite(suite, &hpke_suite_in) != 1) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - OPENSSL_free(s->ext.ech.grease_suite); - s->ext.ech.grease_suite = NULL; - if (suite == NULL) - return 1; - s->ext.ech.grease_suite = OPENSSL_strdup(suite); - if (s->ext.ech.grease_suite == NULL) - return 0; - s->ext.ech.grease = OSSL_ECH_IS_GREASE; - return 1; -} - -int SSL_ech_set_grease_type(SSL *ssl, uint16_t type) -{ - SSL_CONNECTION *s; - - s = SSL_CONNECTION_FROM_SSL(ssl); - if (s == NULL) - return 0; - s->ext.ech.attempted_type = type; - s->ext.ech.grease = OSSL_ECH_IS_GREASE; - return 1; -} - -void SSL_ech_set_callback(SSL *ssl, SSL_ech_cb_func f) -{ - SSL_CONNECTION *s; - - s = SSL_CONNECTION_FROM_SSL(ssl); - if (s == NULL) - return; - s->ext.ech.cb = f; - return; -} - -int SSL_ech_get1_retry_config(SSL *ssl, unsigned char **ec, size_t *eclen) -{ - SSL_CONNECTION *s; - OSSL_ECHSTORE *ve = NULL; - BIO *in = NULL; - int rv = 0; - OSSL_LIB_CTX *libctx = NULL; - const char *propq = NULL; - - s = SSL_CONNECTION_FROM_SSL(ssl); - if (s == NULL || ec == NULL || eclen == NULL - || s->ext.ech.returned_len > INT_MAX) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - goto err; - } - if (s->ext.ech.returned == NULL) { - *ec = NULL; - *eclen = 0; - return 1; - } - /* - * before returning retry-configs check we're in a good - * state - either the session has worked, or else it - * failed but ECH was the only failure (we only set the - * retry_configs_ok flag when all else worked and we're - * about to send the ECH required alert) - */ - if (SSL_is_init_finished(ssl) != 1 && s->ext.ech.retry_configs_ok != 1) { - ERR_raise(ERR_LIB_SSL, ERR_R_OSSL_STORE_LIB); - goto err; - } - /* - * To not hand rubbish to application, we'll decode the value we have - * so only syntactically good things are passed up. We won't insist - * though that every entry in the retry_config list seems good - it - * could be that e.g. one is a newer version than we support now, - * and letting the application see that might cause someone to do an - * upgrade. - */ - if (s->ext.ech.es != NULL) { - libctx = s->ext.ech.es->libctx; - propq = s->ext.ech.es->propq; - } - if ((in = BIO_new(BIO_s_mem())) == NULL - || BIO_write(in, s->ext.ech.returned, (int)s->ext.ech.returned_len) <= 0 - || (ve = OSSL_ECHSTORE_new(libctx, propq)) == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - if (OSSL_ECHSTORE_read_echconfiglist(ve, in) != 1) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - /* all good, copy and return */ - *ec = OPENSSL_memdup(s->ext.ech.returned, s->ext.ech.returned_len); - if (*ec == NULL) - goto err; - *eclen = s->ext.ech.returned_len; - rv = 1; -err: - OSSL_ECHSTORE_free(ve); - BIO_free_all(in); - return rv; -} - -/* - * Note that this function returns 1 for success and 0 for error. This - * contrasts with SSL_CTX_set1_alpn_protos() which (unusually for OpenSSL) - * returns 0 for success and 1 on error. - */ -int SSL_CTX_ech_set1_outer_alpn_protos(SSL_CTX *ctx, - const unsigned char *protos, - const size_t protos_len) -{ - if (ctx == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return 0; - } - OPENSSL_free(ctx->ext.ech.alpn_outer); - ctx->ext.ech.alpn_outer = NULL; - if (protos == NULL) - return 1; - if (protos_len == 0) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - ctx->ext.ech.alpn_outer = OPENSSL_memdup(protos, protos_len); - if (ctx->ext.ech.alpn_outer == NULL) - return 0; - ctx->ext.ech.alpn_outer_len = protos_len; - return 1; -} - -void SSL_CTX_ech_set_callback(SSL_CTX *ctx, SSL_ech_cb_func f) -{ - if (ctx == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return; - } - ctx->ext.ech.cb = f; - return; -} - -int SSL_set1_ech_config_list(SSL *ssl, const uint8_t *ecl, size_t ecl_len) -{ - int rv = 0; - SSL_CONNECTION *s; - OSSL_ECHSTORE *es = NULL; - BIO *es_in = NULL; - - s = SSL_CONNECTION_FROM_SSL(ssl); - if (s == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - goto err; - } - if (ecl == NULL) { - OSSL_ECHSTORE_free(s->ext.ech.es); - s->ext.ech.es = NULL; - return 1; - } - if (ecl_len == 0 || ecl_len > INT_MAX) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - goto err; - } - if ((es_in = BIO_new_mem_buf(ecl, (int)ecl_len)) == NULL - || (es = OSSL_ECHSTORE_new(NULL, NULL)) == NULL - || OSSL_ECHSTORE_read_echconfiglist(es, es_in) != 1 - || SSL_set1_echstore(ssl, es) != 1) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - rv = 1; -err: - OSSL_ECHSTORE_free(es); - BIO_free_all(es_in); - return rv; -} diff --git a/ssl/ech/ech_store.c b/ssl/ech/ech_store.c deleted file mode 100644 index dd05bf3702..0000000000 --- a/ssl/ech/ech_store.c +++ /dev/null @@ -1,1189 +0,0 @@ -/* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the OpenSSL license (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include -#include "../ssl_local.h" -#include "ech_local.h" -#include -#include -#include - -/* a size for some crypto vars */ -#define OSSL_ECH_CRYPTO_VAR_SIZE 2048 - -/* - * Used for ech_bio2buf, when reading from a BIO we allocate in chunks sized - * as per below, with a max number of chunks as indicated, we don't expect to - * go beyond one chunk in almost all cases - */ -#define OSSL_ECH_BUFCHUNK 512 -#define OSSL_ECH_MAXITER 32 - -/* - * ECHConfigList input to OSSL_ECHSTORE_read_echconfiglist() - * can be either binary encoded ECHConfigList or a base64 - * encoded ECHConfigList. - */ -#define OSSL_ECH_FMT_BIN 1 /* binary ECHConfigList */ -#define OSSL_ECH_FMT_B64TXT 2 /* base64 ECHConfigList */ - -/* - * Telltales we use when guessing which form of encoded input we've - * been given for an RR value or ECHConfig. - * We give these the EBCDIC treatment as well - why not? :-) - */ -static const char B64_alphabet[] = "\x41\x42\x43\x44\x45\x46\x47\x48\x49\x4a\x4b\x4c\x4d\x4e\x4f\x50\x51\x52" - "\x53\x54\x55\x56\x57\x58\x59\x5a\x61\x62\x63\x64\x65\x66\x67\x68\x69\x6a" - "\x6b\x6c\x6d\x6e\x6f\x70\x71\x72\x73\x74\x75\x76\x77\x78\x79\x7a\x30\x31" - "\x32\x33\x34\x35\x36\x37\x38\x39\x2b\x2f\x3d\x3b"; - -#ifndef TLSEXT_MINLEN_host_name -/* The shortest DNS name we allow, e.g. "a.bc" */ -#define TLSEXT_MINLEN_host_name 4 -#endif - -/* - * local functions - public APIs are at the end - */ - -void ossl_echext_free(OSSL_ECHEXT *e) -{ - if (e == NULL) - return; - OPENSSL_free(e->val); - OPENSSL_free(e); - return; -} - -OSSL_ECHEXT *ossl_echext_dup(const OSSL_ECHEXT *src) -{ - OSSL_ECHEXT *ext = OPENSSL_zalloc(sizeof(*src)); - - if (ext == NULL) - return NULL; - *ext = *src; - ext->val = NULL; - if (ext->len != 0) { - ext->val = OPENSSL_memdup(src->val, src->len); - if (ext->val == NULL) { - ossl_echext_free(ext); - return NULL; - } - } - return ext; -} - -void ossl_echstore_entry_free(OSSL_ECHSTORE_ENTRY *ee) -{ - if (ee == NULL) - return; - OPENSSL_free(ee->public_name); - OPENSSL_free(ee->pub); - EVP_PKEY_free(ee->keyshare); - OPENSSL_free(ee->encoded); - OPENSSL_free(ee->suites); - sk_OSSL_ECHEXT_pop_free(ee->exts, ossl_echext_free); - OPENSSL_free(ee); - return; -} - -/* - * @brief Read a buffer from an input 'till eof - * @param in is the BIO input - * @param buf is where to put the buffer, allocated inside here - * @param len is the length of that buffer - * - * This is intended for small inputs, either files or buffers and - * not other kinds of BIO. - */ -static int ech_bio2buf(BIO *in, unsigned char **buf, size_t *len) -{ - unsigned char *lptr = NULL, *lbuf = NULL, *tmp = NULL; - size_t sofar = 0, readbytes = 0; - int done = 0, brv, iter = 0; - - if (buf == NULL || len == NULL) - return 0; - sofar = OSSL_ECH_BUFCHUNK; - lbuf = OPENSSL_zalloc(sofar); - if (lbuf == NULL) - return 0; - lptr = lbuf; - while (!BIO_eof(in) && !done && iter++ < OSSL_ECH_MAXITER) { - brv = BIO_read_ex(in, lptr, OSSL_ECH_BUFCHUNK, &readbytes); - if (brv != 1) - goto err; - if (BIO_eof(in) || readbytes < OSSL_ECH_BUFCHUNK) { - done = 1; - break; - } - sofar += OSSL_ECH_BUFCHUNK; - tmp = OPENSSL_realloc(lbuf, sofar); - if (tmp == NULL) - goto err; - lbuf = tmp; - lptr = lbuf + sofar - OSSL_ECH_BUFCHUNK; - } - if (BIO_eof(in) && done == 1) { - *len = sofar + readbytes - OSSL_ECH_BUFCHUNK; - *buf = lbuf; - return 1; - } -err: - OPENSSL_free(lbuf); - return 0; -} - -/* - * @brief Figure out ECHConfig encoding - * @param val is a buffer with the encoding - * @param len is the length of that buffer - * @param fmt is the detected format - * @return 1 for success, 0 for error - */ -static int ech_check_format(const unsigned char *val, size_t len, int *fmt) -{ - size_t span = 0; - char *copy_with_NUL = NULL; - - if (fmt == NULL || len <= 4 || val == NULL) - return 0; - /* binary encoding starts with two octet length and ECH version */ - if (len == 2 + ((size_t)(val[0]) * 256 + (size_t)(val[1])) - && val[2] == ((OSSL_ECH_RFC9849_VERSION / 256) & 0xff) - && val[3] == ((OSSL_ECH_RFC9849_VERSION % 256) & 0xff)) { - *fmt = OSSL_ECH_FMT_BIN; - return 1; - } - /* ensure we always end with a NUL so strspn is safe */ - copy_with_NUL = OPENSSL_malloc(len + 1); - if (copy_with_NUL == NULL) - return 0; - memcpy(copy_with_NUL, val, len); - copy_with_NUL[len] = '\0'; - span = strspn(copy_with_NUL, B64_alphabet); - OPENSSL_free(copy_with_NUL); - if (len <= span) { - *fmt = OSSL_ECH_FMT_B64TXT; - return 1; - } - return 0; -} - -/* - * @brief helper to decode ECHConfig extensions - * @param ee is the OSSL_ECHSTORE entry for these - * @param exts is the binary form extensions - * @return 1 for good, 0 for error - */ -static int ech_decode_echconfig_exts(OSSL_ECHSTORE_ENTRY *ee, PACKET *exts) -{ - unsigned int exttype = 0; - size_t extlen = 0; - unsigned char *extval = NULL; - OSSL_ECHEXT *oe = NULL; - PACKET ext; - - /* - * reminder: exts is a two-octet length prefixed list of: - * - two octet extension type - * - two octet extension length (can be zero) - * - length octets - * we've consumed the overall length before getting here - */ - while (PACKET_remaining(exts) > 0) { - exttype = 0, extlen = 0; - extval = NULL; - oe = NULL; - if (!PACKET_get_net_2(exts, &exttype) || !PACKET_get_length_prefixed_2(exts, &ext)) { - ERR_raise(ERR_LIB_SSL, SSL_R_BAD_ECHCONFIG_EXTENSION); - goto err; - } - if (PACKET_remaining(&ext) >= OSSL_ECH_MAX_ECHCONFIGEXT_LEN) { - ERR_raise(ERR_LIB_SSL, SSL_R_BAD_ECHCONFIG_EXTENSION); - goto err; - } - if (!PACKET_memdup(&ext, &extval, &extlen)) { - ERR_raise(ERR_LIB_SSL, SSL_R_BAD_ECHCONFIG_EXTENSION); - goto err; - } - oe = OPENSSL_malloc(sizeof(*oe)); - if (oe == NULL) - goto err; - oe->type = (uint16_t)exttype; - oe->val = extval; - extval = NULL; /* avoid double free */ - oe->len = (uint16_t)extlen; - if (ee->exts == NULL) - ee->exts = sk_OSSL_ECHEXT_new_null(); - if (ee->exts == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - if (!sk_OSSL_ECHEXT_push(ee->exts, oe)) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - } - return 1; -err: - sk_OSSL_ECHEXT_pop_free(ee->exts, ossl_echext_free); - ee->exts = NULL; - ossl_echext_free(oe); - OPENSSL_free(extval); - return 0; -} - -/* - * @brief Check entry to see if looks good or bad - * @param ee is the ECHConfig to check - * @return 1 for all good, 0 otherwise - */ -static int ech_final_config_checks(OSSL_ECHSTORE_ENTRY *ee) -{ - OSSL_HPKE_SUITE hpke_suite; - int ind, num, rv = 0, goodsuitefound = 0; - X509_VERIFY_PARAM *vpm = X509_VERIFY_PARAM_new(); - char *lastlabel = NULL; - size_t lllen; - - /* check local support for some suite */ - for (ind = 0; ind != (int)ee->nsuites; ind++) { - /* - * suite_check says yes to the pseudo-aead for export, but we don't - * want to see it here coming from outside in an encoding - */ - hpke_suite = ee->suites[ind]; - if (OSSL_HPKE_suite_check(hpke_suite) == 1 - && hpke_suite.aead_id != OSSL_HPKE_AEAD_ID_EXPORTONLY) { - goodsuitefound = 1; - break; - } - } - if (goodsuitefound == 0) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - goto err; - } - /* check no mandatory exts (with high bit set in type) */ - num = (ee->exts == NULL ? 0 : sk_OSSL_ECHEXT_num(ee->exts)); - for (ind = 0; ind != num; ind++) { - OSSL_ECHEXT *oe = sk_OSSL_ECHEXT_value(ee->exts, (int)ind); - - if (oe->type & 0x8000) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - goto err; - } - } - /* check public_name rules, as per spec section 6.1.7 */ - if (ee->public_name == NULL - || ee->public_name[0] == '\0' - || ee->public_name[0] == '.' - || ee->public_name[strlen(ee->public_name) - 1] == '.' - || strlen(ee->public_name) > 255) - goto err; - /* - * Use X509_VERIFY_PARAM_add1_host to avoid coding same checks twice. - * This checks max 63 octets per label, overall length and some other - * DNS label checks. - */ - if (X509_VERIFY_PARAM_add1_host(vpm, ee->public_name, 0) == 0) - goto err; - /* - * but we still have to check the last label restrictions, which - * are intended to avoid confusion with IP address literals in - * encodings browsers support, as per WHATWG (convincing, eh:-) - */ - lastlabel = strrchr(ee->public_name, '.'); - if (lastlabel == NULL) /* if there are no dots */ - lastlabel = ee->public_name; - lllen = strlen(lastlabel); - if (lllen < 2) - goto err; - if (lastlabel[0] == '.') { - lastlabel++; - lllen--; - } - if (strspn(lastlabel, "0123456789") == lllen) - goto err; - if (lastlabel[0] == '0' && lllen > 2 - && (lastlabel[1] == 'x' || lastlabel[1] == 'X') - && strspn(lastlabel + 2, "0123456789abcdefABCDEF") == (lllen - 2)) - goto err; - rv = 1; -err: - X509_VERIFY_PARAM_free(vpm); - return rv; -} - -/** - * @brief decode one ECHConfig from a packet into an entry - * @param rent ptr to an entry allocated within (on success) - * @param pkt is the encoding - * @param priv is an optional private key (NULL if absent) - * @param for_retry says whether to include in a retry_config (if priv present) - * @return 1 for success, 0 for error - */ -static int ech_decode_one_entry(OSSL_ECHSTORE_ENTRY **rent, PACKET *pkt, - EVP_PKEY *priv, int for_retry) -{ - size_t ech_content_length = 0; - unsigned int tmpi; - const unsigned char *tmpecp = NULL; - size_t tmpeclen = 0, test_publen = 0; - PACKET ver_pkt, pub_pkt, cipher_suites, public_name_pkt, exts; - uint16_t thiskemid; - size_t suiteoctets = 0; - unsigned int ci = 0; - unsigned char cipher[OSSL_ECH_CIPHER_LEN], max_name_len; - unsigned char test_pub[OSSL_ECH_CRYPTO_VAR_SIZE]; - OSSL_ECHSTORE_ENTRY *ee = NULL; - - if (rent == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - return 0; - } - if (pkt == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - ee = OPENSSL_zalloc(sizeof(*ee)); - if (ee == NULL) - goto err; - /* note start of encoding so we can make a copy later */ - tmpeclen = PACKET_remaining(pkt); - if (PACKET_peek_bytes(pkt, &tmpecp, tmpeclen) != 1 - || !PACKET_get_net_2(pkt, &tmpi)) { - ERR_raise(ERR_LIB_SSL, SSL_R_ECH_DECODE_ERROR); - goto err; - } - ee->version = (uint16_t)tmpi; - - /* grab versioned packet data */ - if (!PACKET_get_length_prefixed_2(pkt, &ver_pkt)) { - ERR_raise(ERR_LIB_SSL, SSL_R_ECH_DECODE_ERROR); - goto err; - } - ech_content_length = (unsigned int)PACKET_remaining(&ver_pkt); - switch (ee->version) { - case OSSL_ECH_RFC9849_VERSION: - break; - default: - /* skip over in case we get something we can handle later */ - if (!PACKET_forward(&ver_pkt, ech_content_length)) { - ERR_raise(ERR_LIB_SSL, SSL_R_ECH_DECODE_ERROR); - goto err; - } - /* nothing to return but not a fail */ - ossl_echstore_entry_free(ee); - *rent = NULL; - return 1; - } - if (!PACKET_copy_bytes(&ver_pkt, &ee->config_id, 1) - || !PACKET_get_net_2(&ver_pkt, &tmpi) - || !PACKET_get_length_prefixed_2(&ver_pkt, &pub_pkt) - || !PACKET_memdup(&pub_pkt, &ee->pub, &ee->pub_len) - || !PACKET_get_length_prefixed_2(&ver_pkt, &cipher_suites) - || (suiteoctets = PACKET_remaining(&cipher_suites)) <= 0 - || (suiteoctets % 2) == 1 - || suiteoctets / OSSL_ECH_CIPHER_LEN > UINT_MAX) { - ERR_raise(ERR_LIB_SSL, SSL_R_ECH_DECODE_ERROR); - goto err; - } - thiskemid = (uint16_t)tmpi; - ee->nsuites = (unsigned int)(suiteoctets / OSSL_ECH_CIPHER_LEN); - ee->suites = OPENSSL_malloc_array(ee->nsuites, sizeof(*ee->suites)); - if (ee->suites == NULL) - goto err; - while (PACKET_copy_bytes(&cipher_suites, cipher, - OSSL_ECH_CIPHER_LEN)) { - ee->suites[ci].kem_id = thiskemid; - ee->suites[ci].kdf_id = cipher[0] << 8 | cipher[1]; - ee->suites[ci].aead_id = cipher[2] << 8 | cipher[3]; - if (ci++ >= ee->nsuites) { - ERR_raise(ERR_LIB_SSL, SSL_R_ECH_DECODE_ERROR); - goto err; - } - } - if (PACKET_remaining(&cipher_suites) > 0 - || !PACKET_copy_bytes(&ver_pkt, &max_name_len, 1)) { - ERR_raise(ERR_LIB_SSL, SSL_R_ECH_DECODE_ERROR); - goto err; - } - ee->max_name_length = max_name_len; - if (!PACKET_get_length_prefixed_1(&ver_pkt, &public_name_pkt)) { - ERR_raise(ERR_LIB_SSL, SSL_R_ECH_DECODE_ERROR); - goto err; - } - if (PACKET_contains_zero_byte(&public_name_pkt) - || PACKET_remaining(&public_name_pkt) < TLSEXT_MINLEN_host_name - || !PACKET_strndup(&public_name_pkt, &ee->public_name)) { - ERR_raise(ERR_LIB_SSL, SSL_R_ECH_DECODE_ERROR); - goto err; - } - /* - * We don't really handle ECHConfig extensions as of now, - * (none are well-defined), so we're only skipping over - * whatever we find here. If/when adding real extensions - * then it may be necessary to also check that the set of - * extensions loaded contain no duplicate types. - */ - if (!PACKET_get_length_prefixed_2(&ver_pkt, &exts)) { - ERR_raise(ERR_LIB_SSL, SSL_R_ECH_DECODE_ERROR); - goto err; - } - if (PACKET_remaining(&exts) > 0 - && ech_decode_echconfig_exts(ee, &exts) != 1) { - ERR_raise(ERR_LIB_SSL, SSL_R_ECH_DECODE_ERROR); - goto err; - } - /* set length of encoding of this ECHConfig */ - ee->encoded_len = PACKET_data(&ver_pkt) - tmpecp; - /* copy encoded as it might get free'd if a reduce happens */ - ee->encoded = OPENSSL_memdup(tmpecp, ee->encoded_len); - if (ee->encoded == NULL) - goto err; - if (priv != NULL) { - if (EVP_PKEY_get_octet_string_param(priv, - OSSL_PKEY_PARAM_ENCODED_PUBLIC_KEY, - test_pub, OSSL_ECH_CRYPTO_VAR_SIZE, - &test_publen) - != 1) { - ERR_raise(ERR_LIB_SSL, SSL_R_ECH_DECODE_ERROR); - goto err; - } - if (test_publen == ee->pub_len - && !memcmp(test_pub, ee->pub, ee->pub_len)) { - EVP_PKEY_up_ref(priv); /* associate the private key */ - ee->keyshare = priv; - ee->for_retry = for_retry; - } - } - ee->loadtime = time(0); - *rent = ee; - return 1; -err: - ossl_echstore_entry_free(ee); - *rent = NULL; - return 0; -} - -/* - * @brief decode and flatten a binary encoded ECHConfigList - * @param es an OSSL_ECHSTORE - * @param priv is an optional private key (NULL if absent) - * @param for_retry says whether to include in a retry_config (if priv present) - * @param binbuf binary encoded ECHConfigList (we hope) - * @param binlen length of binbuf - * @return 1 for success, 0 for error - * - * We may only get one ECHConfig per list, but there can be more. We want each - * element of the output to contain exactly one ECHConfig so that a client - * could sensibly down select to the one they prefer later, and so that we have - * the specific encoded value of that ECHConfig for inclusion in the HPKE info - * parameter when finally encrypting or decrypting an inner ClientHello. - * - * If a private value is provided then that'll only be associated with the - * relevant public value, if >1 public value was present in the ECHConfigList. - */ -static int ech_decode_and_flatten(OSSL_ECHSTORE *es, EVP_PKEY *priv, int for_retry, - unsigned char *binbuf, size_t binblen) -{ - int rv = 0; - size_t remaining = 0; - PACKET opkt, pkt; - OSSL_ECHSTORE_ENTRY *ee = NULL; - - if (binbuf == NULL || binblen == 0 || binblen < OSSL_ECH_MIN_ECHCONFIG_LEN - || binblen >= OSSL_ECH_MAX_ECHCONFIG_LEN) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - goto err; - } - if (PACKET_buf_init(&opkt, binbuf, binblen) != 1 - || !PACKET_get_length_prefixed_2(&opkt, &pkt)) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - remaining = PACKET_remaining(&pkt); - while (remaining > 0) { - if (ech_decode_one_entry(&ee, &pkt, priv, for_retry) != 1) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - remaining = PACKET_remaining(&pkt); - /* if unsupported version we can skip over */ - if (ee == NULL) - continue; - /* do final checks on suites, exts, and fail if issues */ - if (ech_final_config_checks(ee) != 1) - goto err; - /* push entry into store */ - if (es->entries == NULL) - es->entries = sk_OSSL_ECHSTORE_ENTRY_new_null(); - if (es->entries == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - if (!sk_OSSL_ECHSTORE_ENTRY_push(es->entries, ee)) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - ee = NULL; - } - rv = 1; -err: - ossl_echstore_entry_free(ee); - return rv; -} - -/* - * @brief check a private matches some public - * @param es is the ECH store - * @param priv is the private value - * @return 1 if we have a match, zero otherwise - */ -static int check_priv_matches(OSSL_ECHSTORE *es, EVP_PKEY *priv) -{ - int num, ent, gotone = 0; - OSSL_ECHSTORE_ENTRY *ee = NULL; - - num = (es->entries == NULL ? 0 : sk_OSSL_ECHSTORE_ENTRY_num(es->entries)); - for (ent = 0; ent != num; ent++) { - ee = sk_OSSL_ECHSTORE_ENTRY_value(es->entries, ent); - if (ee == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - if (EVP_PKEY_eq(ee->keyshare, priv)) { - gotone = 1; - break; - } - } - return gotone; -} - -/* - * @brief decode input ECHConfigList and associate optional private info - * @param es is the OSSL_ECHSTORE - * @param in is the BIO from which we'll get the ECHConfigList - * @param priv is an optional private key - * @param for_retry 1 if the public related to priv ought be in retry_config - */ -static int ech_read_priv_echconfiglist(OSSL_ECHSTORE *es, BIO *in, - EVP_PKEY *priv, int for_retry) -{ - int rv = 0, detfmt, tdeclen = 0; - size_t encodedlen = 0, binlen = 0; - unsigned char *encodedval = NULL, *binbuf = NULL; - BIO *btmp = NULL, *btmp1 = NULL; - - if (es == NULL || in == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return 0; - } - if (ech_bio2buf(in, &encodedval, &encodedlen) != 1) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - return 0; - } - if (encodedlen >= OSSL_ECH_MAX_ECHCONFIG_LEN) { /* sanity check */ - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - if (ech_check_format(encodedval, encodedlen, &detfmt) != 1) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - goto err; - } - if (detfmt == OSSL_ECH_FMT_BIN) { /* copy buffer if binary format */ - binbuf = OPENSSL_memdup(encodedval, encodedlen); - if (binbuf == NULL) - goto err; - binlen = encodedlen; - } - if (detfmt == OSSL_ECH_FMT_B64TXT) { - btmp = BIO_new_mem_buf(encodedval, (int)encodedlen); - if (btmp == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - btmp1 = BIO_new(BIO_f_base64()); - if (btmp1 == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - BIO_set_flags(btmp1, BIO_FLAGS_BASE64_NO_NL); - btmp = BIO_push(btmp1, btmp); - /* overestimate but good enough */ - binbuf = OPENSSL_malloc(encodedlen); - if (binbuf == NULL) - goto err; - tdeclen = BIO_read(btmp, binbuf, (int)encodedlen); - if (tdeclen <= 0) { /* need int for -1 return in failure case */ - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - binlen = tdeclen; - } - if (ech_decode_and_flatten(es, priv, for_retry, binbuf, binlen) != 1) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - if (priv != NULL && check_priv_matches(es, priv) == 0) - goto err; - rv = 1; -err: - BIO_free_all(btmp); - OPENSSL_free(binbuf); - OPENSSL_free(encodedval); - return rv; -} - -/* - * API calls built around OSSL_ECHSSTORE - */ - -OSSL_ECHSTORE *OSSL_ECHSTORE_new(OSSL_LIB_CTX *libctx, const char *propq) -{ - OSSL_ECHSTORE *es = NULL; - - es = OPENSSL_zalloc(sizeof(*es)); - if (es == NULL) - return 0; - es->libctx = libctx; - if (propq != NULL) { - es->propq = OPENSSL_strdup(propq); - if (es->propq == NULL) { - OPENSSL_free(es); - return 0; - } - } - - return es; -} - -void OSSL_ECHSTORE_free(OSSL_ECHSTORE *es) -{ - if (es == NULL) - return; - sk_OSSL_ECHSTORE_ENTRY_pop_free(es->entries, ossl_echstore_entry_free); - OPENSSL_free(es->propq); - OPENSSL_free(es); - return; -} - -int OSSL_ECHSTORE_new_config(OSSL_ECHSTORE *es, - uint16_t echversion, uint8_t max_name_length, - const char *public_name, OSSL_HPKE_SUITE suite) -{ - size_t pnlen = 0, publen = OSSL_ECH_CRYPTO_VAR_SIZE; - unsigned char pub[OSSL_ECH_CRYPTO_VAR_SIZE]; - int rv = 0; - unsigned char *bp = NULL; - size_t bblen = 0; - EVP_PKEY *privp = NULL; - uint8_t config_id = 0; - WPACKET epkt; - BUF_MEM *epkt_mem = NULL; - OSSL_ECHSTORE_ENTRY *ee = NULL; - - /* basic checks */ - if (es == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return 0; - } - pnlen = (public_name == NULL ? 0 : strlen(public_name)); - if (pnlen == 0 || pnlen > OSSL_ECH_MAX_PUBLICNAME) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - /* this used have more versions and will again in future */ - switch (echversion) { - case OSSL_ECH_RFC9849_VERSION: - break; - default: - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - /* - * Reminder, for draft-13 we want this: - * - * opaque HpkePublicKey<1..2^16-1>; - * uint16 HpkeKemId; // Defined in I-D.irtf-cfrg-hpke - * uint16 HpkeKdfId; // Defined in I-D.irtf-cfrg-hpke - * uint16 HpkeAeadId; // Defined in I-D.irtf-cfrg-hpke - * struct { - * HpkeKdfId kdf_id; - * HpkeAeadId aead_id; - * } HpkeSymmetricCipherSuite; - * struct { - * uint8 config_id; - * HpkeKemId kem_id; - * HpkePublicKey public_key; - * HpkeSymmetricCipherSuite cipher_suites<4..2^16-4>; - * } HpkeKeyConfig; - * struct { - * HpkeKeyConfig key_config; - * uint8 maximum_name_length; - * opaque public_name<1..255>; - * Extension extensions<0..2^16-1>; - * } ECHConfigContents; - * struct { - * uint16 version; - * uint16 length; - * select (ECHConfig.version) { - * case 0xfe0d: ECHConfigContents contents; - * } - * } ECHConfig; - * ECHConfig ECHConfigList<1..2^16-1>; - */ - if ((epkt_mem = BUF_MEM_new()) == NULL - || !BUF_MEM_grow(epkt_mem, OSSL_ECH_MAX_ECHCONFIG_LEN) - || !WPACKET_init(&epkt, epkt_mem)) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err_no_epkt; - } - /* random config_id */ - if (RAND_bytes_ex(es->libctx, (unsigned char *)&config_id, 1, 0) <= 0) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - /* key pair */ - if (OSSL_HPKE_keygen(suite, pub, &publen, &privp, NULL, 0, - es->libctx, es->propq) - != 1) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - /* config id, KEM, public, KDF, AEAD, max name len, public_name, exts */ - if ((bp = WPACKET_get_curr(&epkt)) == NULL - || !WPACKET_start_sub_packet_u16(&epkt) - || !WPACKET_put_bytes_u16(&epkt, echversion) - || !WPACKET_start_sub_packet_u16(&epkt) - || !WPACKET_put_bytes_u8(&epkt, config_id) - || !WPACKET_put_bytes_u16(&epkt, suite.kem_id) - || !WPACKET_start_sub_packet_u16(&epkt) - || !WPACKET_memcpy(&epkt, pub, publen) - || !WPACKET_close(&epkt) - || !WPACKET_start_sub_packet_u16(&epkt) - || !WPACKET_put_bytes_u16(&epkt, suite.kdf_id) - || !WPACKET_put_bytes_u16(&epkt, suite.aead_id) - || !WPACKET_close(&epkt) - || !WPACKET_put_bytes_u8(&epkt, max_name_length) - || !WPACKET_start_sub_packet_u8(&epkt) - || !WPACKET_memcpy(&epkt, public_name, pnlen) - || !WPACKET_close(&epkt) - || !WPACKET_start_sub_packet_u16(&epkt) - || !WPACKET_memcpy(&epkt, NULL, 0) /* no extensions */ - || !WPACKET_close(&epkt) - || !WPACKET_close(&epkt) - || !WPACKET_close(&epkt)) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - /* bp, bblen has encoding */ - if (!WPACKET_get_total_written(&epkt, &bblen)) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - if ((ee = OPENSSL_zalloc(sizeof(*ee))) == NULL) - goto err; - ee->suites = OPENSSL_malloc(sizeof(*ee->suites)); - if (ee->suites == NULL) - goto err; - ee->version = echversion; - ee->pub_len = publen; - ee->pub = OPENSSL_memdup(pub, publen); - if (ee->pub == NULL) - goto err; - ee->nsuites = 1; - ee->suites[0] = suite; - ee->public_name = OPENSSL_strdup(public_name); - if (ee->public_name == NULL) - goto err; - ee->max_name_length = max_name_length; - ee->config_id = config_id; - ee->keyshare = privp; - privp = NULL; /* don't free twice */ - /* "steal" the encoding from the memory */ - ee->encoded = (unsigned char *)epkt_mem->data; - ee->encoded_len = bblen; - epkt_mem->data = NULL; - epkt_mem->length = 0; - ee->loadtime = time(0); - if (ech_final_config_checks(ee) != 1) /* check our work */ - goto err; - /* push entry into store */ - if (es->entries == NULL) - es->entries = sk_OSSL_ECHSTORE_ENTRY_new_null(); - if (es->entries == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - if (!sk_OSSL_ECHSTORE_ENTRY_push(es->entries, ee)) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - WPACKET_finish(&epkt); - BUF_MEM_free(epkt_mem); - return 1; - -err: - ossl_echstore_entry_free(ee); - EVP_PKEY_free(privp); - WPACKET_cleanup(&epkt); -err_no_epkt: - BUF_MEM_free(epkt_mem); - return rv; -} - -int OSSL_ECHSTORE_write_pem(OSSL_ECHSTORE *es, int index, BIO *out) -{ - OSSL_ECHSTORE_ENTRY *ee = NULL; - int rv = 0, num = 0, chosen = 0, doall = 0; - WPACKET epkt; /* used if we want to merge ECHConfigs for output */ - BUF_MEM *epkt_mem = NULL; - size_t allencoded_len; - - if (es == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - num = (es->entries == NULL ? 0 : sk_OSSL_ECHSTORE_ENTRY_num(es->entries)); - if (num <= 0) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - if (index >= num) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - if (index == OSSL_ECHSTORE_ALL) - doall = 1; - else if (index == OSSL_ECHSTORE_LAST) - chosen = num - 1; - else - chosen = index; - memset(&epkt, 0, sizeof(epkt)); - if (doall == 0) { - ee = sk_OSSL_ECHSTORE_ENTRY_value(es->entries, chosen); - if (ee == NULL || ee->encoded == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - /* private key first */ - if (ee->keyshare != NULL - && !PEM_write_bio_PrivateKey(out, ee->keyshare, NULL, NULL, 0, - NULL, NULL)) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - if (PEM_write_bio(out, PEM_STRING_ECHCONFIG, NULL, - ee->encoded, (long)ee->encoded_len) - <= 0) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - } else { - /* catenate the encodings into one */ - if ((epkt_mem = BUF_MEM_new()) == NULL - || !BUF_MEM_grow(epkt_mem, OSSL_ECH_MAX_ECHCONFIG_LEN) - || !WPACKET_init(&epkt, epkt_mem) - || !WPACKET_start_sub_packet_u16(&epkt)) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - for (chosen = 0; chosen != num; chosen++) { - ee = sk_OSSL_ECHSTORE_ENTRY_value(es->entries, chosen); - if (ee == NULL || ee->encoded == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - if (!WPACKET_memcpy(&epkt, ee->encoded, ee->encoded_len)) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - } - if (!WPACKET_close(&epkt)) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - if (!WPACKET_get_total_written(&epkt, &allencoded_len)) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - if (PEM_write_bio(out, PEM_STRING_ECHCONFIG, NULL, - (unsigned char *)epkt_mem->data, - (long)allencoded_len) - <= 0) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - } - rv = 1; -err: - WPACKET_cleanup(&epkt); - BUF_MEM_free(epkt_mem); - return rv; -} - -int OSSL_ECHSTORE_read_echconfiglist(OSSL_ECHSTORE *es, BIO *in) -{ - return ech_read_priv_echconfiglist(es, in, NULL, 0); -} - -int OSSL_ECHSTORE_get1_info(OSSL_ECHSTORE *es, int index, time_t *loaded_secs, - char **public_name, char **echconfig, - int *has_private, int *for_retry) -{ - OSSL_ECHSTORE_ENTRY *ee = NULL; - unsigned int j = 0; - int num = 0; - BIO *out = NULL; - time_t now = time(0); - size_t ehlen; - unsigned char *ignore = NULL; - - if (es == NULL || loaded_secs == NULL || public_name == NULL - || echconfig == NULL || has_private == NULL || for_retry == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return 0; - } - num = (es->entries == NULL ? 0 : sk_OSSL_ECHSTORE_ENTRY_num(es->entries)); - if (num == 0 || index < 0 || index >= num) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - ee = sk_OSSL_ECHSTORE_ENTRY_value(es->entries, index); - if (ee == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - *loaded_secs = now - ee->loadtime; - *public_name = NULL; - *echconfig = NULL; - if (ee->public_name != NULL) { - *public_name = OPENSSL_strdup(ee->public_name); - if (*public_name == NULL) - goto err; - } - *has_private = (ee->keyshare == NULL ? 0 : 1); - *for_retry = ee->for_retry; - /* Now "print" the ECHConfigList */ - out = BIO_new(BIO_s_mem()); - if (out == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - if (ee->version != OSSL_ECH_RFC9849_VERSION) { - /* just note we don't support that one today */ - BIO_printf(out, "[Unsupported version (%04x)]", ee->version); - } else { - /* version, config_id, public_name, and kem */ - BIO_printf(out, "[%04x,%02x,%s,[", ee->version, ee->config_id, - ee->public_name != NULL ? (char *)ee->public_name : "NULL"); - /* ciphersuites */ - for (j = 0; j != ee->nsuites; j++) { - BIO_printf(out, "%04x,%04x,%04x", ee->suites[j].kem_id, - ee->suites[j].kdf_id, ee->suites[j].aead_id); - if (j < (ee->nsuites - 1)) - BIO_printf(out, ","); - } - BIO_printf(out, "],"); - /* public key */ - for (j = 0; j != ee->pub_len; j++) - BIO_printf(out, "%02x", ee->pub[j]); - /* max name length and (only) number of extensions */ - BIO_printf(out, ",%02x,%02x]", ee->max_name_length, - ee->exts == NULL ? 0 : sk_OSSL_ECHEXT_num(ee->exts)); - } - ehlen = BIO_get_mem_data(out, &ignore); - if (ehlen > INT_MAX) - goto err; - *echconfig = OPENSSL_malloc(ehlen + 1); - if (*echconfig == NULL) - goto err; - if (BIO_read(out, *echconfig, (int)ehlen) <= 0) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - (*echconfig)[ehlen] = '\0'; - BIO_free(out); - return 1; -err: - BIO_free(out); - OPENSSL_free(*public_name); - *public_name = NULL; - OPENSSL_free(*echconfig); - *echconfig = NULL; - return 0; -} - -int OSSL_ECHSTORE_downselect(OSSL_ECHSTORE *es, int index) -{ - OSSL_ECHSTORE_ENTRY *ee = NULL; - int i, num = 0, chosen = OSSL_ECHSTORE_ALL; - - if (es == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return 0; - } - num = (es->entries == NULL ? 0 : sk_OSSL_ECHSTORE_ENTRY_num(es->entries)); - if (num == 0) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - if (index <= OSSL_ECHSTORE_ALL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - if (index == OSSL_ECHSTORE_LAST) { - chosen = num - 1; - } else if (index >= num) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } else { - chosen = index; - } - for (i = num - 1; i >= 0; i--) { - if (i == chosen) - continue; - ee = sk_OSSL_ECHSTORE_ENTRY_value(es->entries, i); - ossl_echstore_entry_free(ee); - sk_OSSL_ECHSTORE_ENTRY_delete(es->entries, i); - } - return 1; -} - -int OSSL_ECHSTORE_set1_key_and_read_pem(OSSL_ECHSTORE *es, EVP_PKEY *priv, - BIO *in, int for_retry) -{ - unsigned char *b64 = NULL; - long b64len = 0; - BIO *b64bio = NULL; - int rv = 0; - char *pname = NULL, *pheader = NULL; - - /* we allow for a NULL private key */ - if (es == NULL || in == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return 0; - } - if (PEM_read_bio(in, &pname, &pheader, &b64, &b64len) != 1) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - return 0; - } - if (pname == NULL || strcmp(pname, PEM_STRING_ECHCONFIG) != 0) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - b64bio = BIO_new(BIO_s_mem()); - if (b64bio == NULL - || BIO_write(b64bio, b64, b64len) <= 0 - || ech_read_priv_echconfiglist(es, b64bio, priv, for_retry) != 1) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - rv = 1; -err: - OPENSSL_free(pname); - OPENSSL_free(pheader); - BIO_free_all(b64bio); - OPENSSL_free(b64); - return rv; -} - -int OSSL_ECHSTORE_read_pem(OSSL_ECHSTORE *es, BIO *in, int for_retry) -{ - EVP_PKEY *priv = NULL; - int rv = 0; - BIO *fbio = BIO_new(BIO_f_buffer()); - - if (fbio == NULL || es == NULL || in == NULL) { - BIO_free_all(fbio); - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return 0; - } - /* - * Read private key then handoff to set1_key_and_read_pem. - * We allow for no private key as an option, to handle that - * the BIO_f_buffer allows us to seek back to the start. - */ - BIO_push(fbio, in); - if (!PEM_read_bio_PrivateKey_ex(fbio, &priv, NULL, NULL, es->libctx, es->propq) - && BIO_seek(fbio, 0) < 0) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - goto err; - } - rv = OSSL_ECHSTORE_set1_key_and_read_pem(es, priv, fbio, for_retry); -err: - EVP_PKEY_free(priv); - BIO_pop(fbio); - BIO_free_all(fbio); - return rv; -} - -int OSSL_ECHSTORE_num_entries(const OSSL_ECHSTORE *es, int *numentries) -{ - if (es == NULL || numentries == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return 0; - } - *numentries = (es->entries == NULL ? 0 : sk_OSSL_ECHSTORE_ENTRY_num(es->entries)); - return 1; -} - -int OSSL_ECHSTORE_num_keys(OSSL_ECHSTORE *es, int *numkeys) -{ - int i, num = 0, count = 0; - OSSL_ECHSTORE_ENTRY *ee = NULL; - - if (es == NULL || numkeys == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return 0; - } - num = (es->entries == NULL ? 0 : sk_OSSL_ECHSTORE_ENTRY_num(es->entries)); - for (i = 0; i != num; i++) { - ee = sk_OSSL_ECHSTORE_ENTRY_value(es->entries, i); - if (ee == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - return 0; - } - count += (ee->keyshare != NULL); - } - *numkeys = count; - return 1; -} - -int OSSL_ECHSTORE_flush_keys(OSSL_ECHSTORE *es, time_t age) -{ - OSSL_ECHSTORE_ENTRY *ee = NULL; - int i, num = 0; - time_t now = time(0); - - if (es == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); - return 0; - } - num = (es->entries == NULL ? 0 : sk_OSSL_ECHSTORE_ENTRY_num(es->entries)); - if (num == 0) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - for (i = num - 1; i >= 0; i--) { - ee = sk_OSSL_ECHSTORE_ENTRY_value(es->entries, i); - if (ee == NULL) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - if (ee->keyshare != NULL && ee->loadtime + age <= now) { - ossl_echstore_entry_free(ee); - sk_OSSL_ECHSTORE_ENTRY_delete(es->entries, i); - } - } - return 1; -} diff --git a/ssl/methods.c b/ssl/methods.c index 4c7d46efdb..0709883905 100644 --- a/ssl/methods.c +++ b/ssl/methods.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2016 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -13,7 +13,7 @@ #include "ssl_local.h" /*- - * TLS methods + * TLS/SSLv3 methods */ IMPLEMENT_tls_meth_func(TLS_ANY_VERSION, 0, 0, @@ -41,8 +41,11 @@ IMPLEMENT_tls_meth_func(TLS1_VERSION, SSL_METHOD_NO_SUITEB, SSL_OP_NO_TLSv1, tlsv1_method, ossl_statem_accept, ossl_statem_connect, TLSv1_enc_data) #endif +#ifndef OPENSSL_NO_SSL3_METHOD +IMPLEMENT_ssl3_meth_func(sslv3_method, ossl_statem_accept, ossl_statem_connect) +#endif /*- - * TLS server methods + * TLS/SSLv3 server methods */ IMPLEMENT_tls_meth_func(TLS_ANY_VERSION, 0, 0, TLS_server_method, @@ -70,8 +73,12 @@ IMPLEMENT_tls_meth_func(TLS1_VERSION, SSL_METHOD_NO_SUITEB, SSL_OP_NO_TLSv1, ossl_statem_accept, ssl_undefined_function, TLSv1_enc_data) #endif +#ifndef OPENSSL_NO_SSL3_METHOD +IMPLEMENT_ssl3_meth_func(sslv3_server_method, + ossl_statem_accept, ssl_undefined_function) +#endif /*- - * TLS client methods + * TLS/SSLv3 client methods */ IMPLEMENT_tls_meth_func(TLS_ANY_VERSION, 0, 0, TLS_client_method, @@ -99,6 +106,10 @@ IMPLEMENT_tls_meth_func(TLS1_VERSION, SSL_METHOD_NO_SUITEB, SSL_OP_NO_TLSv1, ssl_undefined_function, ossl_statem_connect, TLSv1_enc_data) #endif +#ifndef OPENSSL_NO_SSL3_METHOD +IMPLEMENT_ssl3_meth_func(sslv3_client_method, + ssl_undefined_function, ossl_statem_connect) +#endif /*- * DTLS methods */ @@ -162,3 +173,107 @@ IMPLEMENT_dtls1_meth_func(DTLS_ANY_VERSION, 0, 0, DTLS_client_method, ssl_undefined_function, ossl_statem_connect, DTLSv1_2_enc_data) +#ifndef OPENSSL_NO_DEPRECATED_1_1_0 +#ifndef OPENSSL_NO_TLS1_2_METHOD +const SSL_METHOD *TLSv1_2_method(void) +{ + return tlsv1_2_method(); +} + +const SSL_METHOD *TLSv1_2_server_method(void) +{ + return tlsv1_2_server_method(); +} + +const SSL_METHOD *TLSv1_2_client_method(void) +{ + return tlsv1_2_client_method(); +} +#endif + +#ifndef OPENSSL_NO_TLS1_1_METHOD +const SSL_METHOD *TLSv1_1_method(void) +{ + return tlsv1_1_method(); +} + +const SSL_METHOD *TLSv1_1_server_method(void) +{ + return tlsv1_1_server_method(); +} + +const SSL_METHOD *TLSv1_1_client_method(void) +{ + return tlsv1_1_client_method(); +} +#endif + +#ifndef OPENSSL_NO_TLS1_METHOD +const SSL_METHOD *TLSv1_method(void) +{ + return tlsv1_method(); +} + +const SSL_METHOD *TLSv1_server_method(void) +{ + return tlsv1_server_method(); +} + +const SSL_METHOD *TLSv1_client_method(void) +{ + return tlsv1_client_method(); +} +#endif + +#ifndef OPENSSL_NO_SSL3_METHOD +const SSL_METHOD *SSLv3_method(void) +{ + return sslv3_method(); +} + +const SSL_METHOD *SSLv3_server_method(void) +{ + return sslv3_server_method(); +} + +const SSL_METHOD *SSLv3_client_method(void) +{ + return sslv3_client_method(); +} +#endif + +#ifndef OPENSSL_NO_DTLS1_2_METHOD +const SSL_METHOD *DTLSv1_2_method(void) +{ + return dtlsv1_2_method(); +} + +const SSL_METHOD *DTLSv1_2_server_method(void) +{ + return dtlsv1_2_server_method(); +} + +const SSL_METHOD *DTLSv1_2_client_method(void) +{ + return dtlsv1_2_client_method(); +} +#endif + +#ifndef OPENSSL_NO_DTLS1_METHOD +const SSL_METHOD *DTLSv1_method(void) +{ + return dtlsv1_method(); +} + +const SSL_METHOD *DTLSv1_server_method(void) +{ + return dtlsv1_server_method(); +} + +const SSL_METHOD *DTLSv1_client_method(void) +{ + return dtlsv1_client_method(); +} +#endif + +#endif diff --git a/ssl/quic/qlog.c b/ssl/quic/qlog.c index a09c76ca2a..6f505cf151 100644 --- a/ssl/quic/qlog.c +++ b/ssl/quic/qlog.c @@ -642,14 +642,13 @@ static void filter_apply(size_t *enabled, int add, const char *cat, size_t cat_l, const char *event, size_t event_l) { - /* clang-format off */ - /* Find events which match the given filters. */ -#define QLOG_EVENT(e_cat, e_name) \ - if (filter_match_event(cat, cat_l, event, event_l, #e_cat, #e_name)) \ - bit_set(enabled, QLOG_EVENT_TYPE_##e_cat##_##e_name, add); -#include "internal/qlog_events.inc" + /* Find events which match the given filters. */ +#define QLOG_EVENT(e_cat, e_name) \ + if (filter_match_event(cat, cat_l, event, event_l, \ + #e_cat, #e_name)) \ + bit_set(enabled, QLOG_EVENT_TYPE_##e_cat##_##e_name, add); +#include "internal/qlog_events.h" #undef QLOG_EVENT - /* clang-format on */ } static int lex_fail(struct lexer *lex, const char *msg) diff --git a/ssl/quic/quic_ackm.c b/ssl/quic/quic_ackm.c index 24acb8635c..503a6eae19 100644 --- a/ssl/quic/quic_ackm.c +++ b/ssl/quic/quic_ackm.c @@ -117,8 +117,6 @@ tx_pkt_history_add_actual(struct tx_pkt_history_st *h, return 0; lh_OSSL_ACKM_TX_PKT_insert(h->map, pkt); - if (lh_OSSL_ACKM_TX_PKT_error(h->map)) - return 0; ossl_list_tx_history_insert_tail(&h->packets, pkt); return 1; @@ -1003,7 +1001,6 @@ static void ackm_on_pkts_acked(OSSL_ACKM *ackm, const OSSL_ACKM_TX_PKT *apkt) const OSSL_ACKM_TX_PKT *anext; QUIC_PN last_pn_acked = 0; OSSL_CC_ACK_INFO ainfo = { 0 }; - unsigned int is_inflight; for (; apkt != NULL; apkt = anext) { if (apkt->is_inflight) { @@ -1028,11 +1025,10 @@ static void ackm_on_pkts_acked(OSSL_ACKM *ackm, const OSSL_ACKM_TX_PKT *apkt) ainfo.tx_time = apkt->time; ainfo.tx_size = apkt->num_bytes; - is_inflight = apkt->is_inflight; anext = apkt->anext; apkt->on_acked(apkt->cb_arg); /* may free apkt */ - if (is_inflight) + if (apkt->is_inflight) ackm->cc_method->on_data_acked(ackm->cc_data, &ainfo); } } @@ -1169,21 +1165,8 @@ int ossl_ackm_on_rx_ack_frame(OSSL_ACKM *ackm, const OSSL_QUIC_FRAME_ACK *ack, int pkt_space, OSSL_TIME rx_time) { OSSL_ACKM_TX_PKT *na_pkts, *lost_pkts; - struct tx_pkt_history_st *h = get_tx_history(ackm, pkt_space); int must_set_timer = 0; - /* - * RFC 9000 s. 13.1 recommends treating an acknowledgment for a packet we - * did not send as a PROTOCOL_VIOLATION, where detectable. The largest - * acknowledged PN is ack_ranges[0].end; if it exceeds the highest PN we have - * sent in this space, reject the ACK. Otherwise the peer-controlled value is - * stored into largest_acked_pkt below, which only ever increases and drives - * loss detection, so a single such ACK would permanently force every - * in-flight and subsequently-sent packet to be declared lost. - */ - if (ack->ack_ranges[0].end > h->highest_sent) - return 0; - if (ackm->largest_acked_pkt[pkt_space] == QUIC_PN_INVALID) ackm->largest_acked_pkt[pkt_space] = ack->ack_ranges[0].end; else diff --git a/ssl/quic/quic_cfq.c b/ssl/quic/quic_cfq.c index 889b093dea..3c59234ff0 100644 --- a/ssl/quic/quic_cfq.c +++ b/ssl/quic/quic_cfq.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -7,7 +7,6 @@ * https://www.openssl.org/source/license.html */ -#include "internal/quic_channel.h" #include "internal/quic_cfq.h" #include "internal/numbers.h" @@ -27,42 +26,42 @@ struct quic_cfq_item_ex_st { uint64_t ossl_quic_cfq_item_get_frame_type(const QUIC_CFQ_ITEM *item) { - const QUIC_CFQ_ITEM_EX *ex = (const QUIC_CFQ_ITEM_EX *)item; + QUIC_CFQ_ITEM_EX *ex = (QUIC_CFQ_ITEM_EX *)item; return ex->frame_type; } const unsigned char *ossl_quic_cfq_item_get_encoded(const QUIC_CFQ_ITEM *item) { - const QUIC_CFQ_ITEM_EX *ex = (const QUIC_CFQ_ITEM_EX *)item; + QUIC_CFQ_ITEM_EX *ex = (QUIC_CFQ_ITEM_EX *)item; return ex->encoded; } size_t ossl_quic_cfq_item_get_encoded_len(const QUIC_CFQ_ITEM *item) { - const QUIC_CFQ_ITEM_EX *ex = (const QUIC_CFQ_ITEM_EX *)item; + QUIC_CFQ_ITEM_EX *ex = (QUIC_CFQ_ITEM_EX *)item; return ex->encoded_len; } int ossl_quic_cfq_item_get_state(const QUIC_CFQ_ITEM *item) { - const QUIC_CFQ_ITEM_EX *ex = (const QUIC_CFQ_ITEM_EX *)item; + QUIC_CFQ_ITEM_EX *ex = (QUIC_CFQ_ITEM_EX *)item; return ex->state; } uint32_t ossl_quic_cfq_item_get_pn_space(const QUIC_CFQ_ITEM *item) { - const QUIC_CFQ_ITEM_EX *ex = (const QUIC_CFQ_ITEM_EX *)item; + QUIC_CFQ_ITEM_EX *ex = (QUIC_CFQ_ITEM_EX *)item; return ex->pn_space; } int ossl_quic_cfq_item_is_unreliable(const QUIC_CFQ_ITEM *item) { - const QUIC_CFQ_ITEM_EX *ex = (const QUIC_CFQ_ITEM_EX *)item; + QUIC_CFQ_ITEM_EX *ex = (QUIC_CFQ_ITEM_EX *)item; return (ex->flags & QUIC_CFQ_ITEM_FLAG_UNRELIABLE) != 0; } @@ -308,20 +307,6 @@ void ossl_quic_cfq_mark_lost(QUIC_CFQ *cfq, QUIC_CFQ_ITEM *item, } } -int ossl_quic_cfq_discard_unreliable(QUIC_CFQ *cfq, QUIC_CFQ_ITEM *item) -{ - int discarded; - - if (ossl_quic_cfq_item_is_unreliable(item)) { - ossl_quic_cfq_release(cfq, item); - discarded = 1; - } else { - discarded = 0; - } - - return discarded; -} - /* * Releases a CFQ item. The item may be in either state (NEW or TX) prior to the * call. The QUIC_CFQ_ITEM pointer must not be used following this call. diff --git a/ssl/quic/quic_channel.c b/ssl/quic/quic_channel.c index 99f131cb78..425b0dee1b 100644 --- a/ssl/quic/quic_channel.c +++ b/ssl/quic/quic_channel.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -35,6 +35,14 @@ */ #define MAX_NAT_INTERVAL (ossl_ms2time(25000)) +/* + * Our maximum ACK delay on the TX side. This is up to us to choose. Note that + * this could differ from QUIC_DEFAULT_MAX_DELAY in future as that is a protocol + * value which determines the value of the maximum ACK delay if the + * max_ack_delay transport parameter is not set. + */ +#define DEFAULT_MAX_ACK_DELAY QUIC_DEFAULT_MAX_ACK_DELAY + DEFINE_LIST_OF_IMPL(ch, QUIC_CHANNEL); static void ch_save_err_state(QUIC_CHANNEL *ch); @@ -89,6 +97,8 @@ static void ch_start_terminating(QUIC_CHANNEL *ch, int force_immediate); static void ch_on_txp_ack_tx(const OSSL_QUIC_FRAME_ACK *ack, uint32_t pn_space, void *arg); +static void ch_rx_handle_version_neg(QUIC_CHANNEL *ch, OSSL_QRX_PKT *pkt); +static void ch_raise_version_neg_failure(QUIC_CHANNEL *ch); static void ch_record_state_transition(QUIC_CHANNEL *ch, uint32_t new_state); DEFINE_LHASH_OF_EX(QUIC_SRT_ELEM); @@ -138,10 +148,14 @@ static QLOG *ch_get_qlog_cb(void *arg) * QUIC Channel Initialization and Teardown * ======================================== */ +#define DEFAULT_INIT_CONN_RXFC_WND (768 * 1024) #define DEFAULT_CONN_RXFC_MAX_WND_MUL 20 +#define DEFAULT_INIT_STREAM_RXFC_WND (512 * 1024) #define DEFAULT_STREAM_RXFC_MAX_WND_MUL 12 +#define DEFAULT_INIT_CONN_MAX_STREAMS 100 + static int ch_init(QUIC_CHANNEL *ch) { OSSL_QUIC_TX_PACKETISER_ARGS txp_args = { 0 }; @@ -188,6 +202,20 @@ static int ch_init(QUIC_CHANNEL *ch) if (!ossl_quic_txfc_init(&ch->conn_txfc, NULL)) goto err; + /* + * Note: The TP we transmit governs what the peer can transmit and thus + * applies to the RXFC. + */ + ch->tx_init_max_stream_data_bidi_local = DEFAULT_INIT_STREAM_RXFC_WND; + ch->tx_init_max_stream_data_bidi_remote = DEFAULT_INIT_STREAM_RXFC_WND; + ch->tx_init_max_stream_data_uni = DEFAULT_INIT_STREAM_RXFC_WND; + + if (!ossl_quic_rxfc_init(&ch->conn_rxfc, NULL, + DEFAULT_INIT_CONN_RXFC_WND, + DEFAULT_CONN_RXFC_MAX_WND_MUL * DEFAULT_INIT_CONN_RXFC_WND, + get_time, ch)) + goto err; + for (pn_space = QUIC_PN_SPACE_INITIAL; pn_space < QUIC_PN_SPACE_NUM; ++pn_space) if (!ossl_quic_rxfc_init_standalone(&ch->crypto_rxfc[pn_space], INIT_CRYPTO_RECV_BUF_LEN, @@ -195,12 +223,12 @@ static int ch_init(QUIC_CHANNEL *ch) goto err; if (!ossl_quic_rxfc_init_standalone(&ch->max_streams_bidi_rxfc, - ch->tx_init_max_streams_bidi, + DEFAULT_INIT_CONN_MAX_STREAMS, get_time, ch)) goto err; if (!ossl_quic_rxfc_init_standalone(&ch->max_streams_uni_rxfc, - ch->tx_init_max_streams_uni, + DEFAULT_INIT_CONN_MAX_STREAMS, get_time, ch)) goto err; @@ -230,11 +258,9 @@ static int ch_init(QUIC_CHANNEL *ch) && !ossl_quic_lcidm_generate_initial(ch->lcidm, ch, &ch->init_scid)) goto err; - ch->rx_ack_delay_exp = QUIC_DEFAULT_ACK_DELAY_EXP; - txp_args.cur_scid = ch->init_scid; txp_args.cur_dcid = ch->init_dcid; - txp_args.ack_delay_exponent = ch->tx_ack_delay_exp; + txp_args.ack_delay_exponent = 3; txp_args.qtx = ch->qtx; txp_args.txpim = ch->txpim; txp_args.cfq = ch->cfq; @@ -336,12 +362,16 @@ static int ch_init(QUIC_CHANNEL *ch) if ((ch->qtls = ossl_quic_tls_new(&tls_args)) == NULL) goto err; + ch->tx_max_ack_delay = DEFAULT_MAX_ACK_DELAY; ch->rx_max_ack_delay = QUIC_DEFAULT_MAX_ACK_DELAY; + ch->rx_ack_delay_exp = QUIC_DEFAULT_ACK_DELAY_EXP; ch->rx_active_conn_id_limit = QUIC_MIN_ACTIVE_CONN_ID_LIMIT; ch->tx_enc_level = QUIC_ENC_LEVEL_INITIAL; ch->rx_enc_level = QUIC_ENC_LEVEL_INITIAL; ch->txku_threshold_override = UINT64_MAX; + ch->max_idle_timeout_local_req = QUIC_DEFAULT_IDLE_TIMEOUT; + ch->max_idle_timeout_remote_req = 0; ch->max_idle_timeout = ch->max_idle_timeout_local_req; ossl_ackm_set_tx_max_ack_delay(ch->ackm, ossl_ms2time(ch->tx_max_ack_delay)); @@ -357,11 +387,6 @@ err: return 0; } -/* - * ch_cleanup() is idempotent: every owned pointer is NULL'd after its free, - * and every "have_*" flag is reset after its destructor runs. Calling this - * twice on the same channel is safe. - */ static void ch_cleanup(QUIC_CHANNEL *ch) { uint32_t pn_space; @@ -379,53 +404,33 @@ static void ch_cleanup(QUIC_CHANNEL *ch) ossl_quic_srtm_cull(ch->srtm, ch); ossl_quic_tx_packetiser_free(ch->txp); - ch->txp = NULL; ossl_quic_txpim_free(ch->txpim); - ch->txpim = NULL; ossl_quic_cfq_free(ch->cfq); - ch->cfq = NULL; ossl_qtx_free(ch->qtx); - ch->qtx = NULL; - if (ch->cc_data != NULL) { + if (ch->cc_data != NULL) ch->cc_method->free(ch->cc_data); - ch->cc_data = NULL; - } - if (ch->have_statm) { + if (ch->have_statm) ossl_statm_destroy(&ch->statm); - ch->have_statm = 0; - } ossl_ackm_free(ch->ackm); - ch->ackm = NULL; - if (ch->have_qsm) { + if (ch->have_qsm) ossl_quic_stream_map_cleanup(&ch->qsm); - ch->have_qsm = 0; - } for (pn_space = QUIC_PN_SPACE_INITIAL; pn_space < QUIC_PN_SPACE_NUM; ++pn_space) { ossl_quic_sstream_free(ch->crypto_send[pn_space]); - ch->crypto_send[pn_space] = NULL; ossl_quic_rstream_free(ch->crypto_recv[pn_space]); - ch->crypto_recv[pn_space] = NULL; } ossl_qrx_pkt_release(ch->qrx_pkt); ch->qrx_pkt = NULL; ossl_quic_tls_free(ch->qtls); - ch->qtls = NULL; ossl_qrx_free(ch->qrx); - ch->qrx = NULL; OPENSSL_free(ch->local_transport_params); - ch->local_transport_params = NULL; OPENSSL_free((char *)ch->terminate_cause.reason); - ch->terminate_cause.reason = NULL; OSSL_ERR_STATE_free(ch->err_state); - ch->err_state = NULL; OPENSSL_free(ch->ack_range_scratch); - ch->ack_range_scratch = NULL; OPENSSL_free(ch->pending_new_token); - ch->pending_new_token = NULL; if (ch->on_port_list) { ossl_list_ch_remove(&ch->port->channel_list, ch); @@ -437,9 +442,7 @@ static void ch_cleanup(QUIC_CHANNEL *ch) ossl_qlog_flush(ch->qlog); /* best effort */ OPENSSL_free(ch->qlog_title); - ch->qlog_title = NULL; ossl_qlog_free(ch->qlog); - ch->qlog = NULL; #endif } @@ -461,7 +464,7 @@ void ossl_quic_channel_bind_qrx(QUIC_CHANNEL *tserver_ch, OSSL_QRX *qrx) QUIC_CHANNEL *ossl_quic_channel_alloc(const QUIC_CHANNEL_ARGS *args) { - QUIC_CHANNEL *ch; + QUIC_CHANNEL *ch = NULL; if ((ch = OPENSSL_zalloc(sizeof(*ch))) == NULL) return NULL; @@ -477,39 +480,14 @@ QUIC_CHANNEL *ossl_quic_channel_alloc(const QUIC_CHANNEL_ARGS *args) ch->use_qlog = args->use_qlog; if (ch->use_qlog && args->qlog_title != NULL) { - if ((ch->qlog_title = OPENSSL_strdup(args->qlog_title)) == NULL) - goto err; + if ((ch->qlog_title = OPENSSL_strdup(args->qlog_title)) == NULL) { + OPENSSL_free(ch); + return NULL; + } } #endif - ch->max_idle_timeout_local_req = args->max_idle_timeout; - ch->tx_max_udp_payload_size = args->max_udp_payload_size; - ch->tx_init_max_data = args->init_max_data; - ch->tx_init_max_stream_data_bidi_local = args->init_max_stream_data_bidi_local; - ch->tx_init_max_stream_data_bidi_remote = args->init_max_stream_data_bidi_remote; - ch->tx_init_max_stream_data_uni = args->init_max_stream_data_uni; - ch->tx_init_max_streams_bidi = args->init_max_streams_bidi; - ch->tx_init_max_streams_uni = args->init_max_streams_uni; - ch->tx_ack_delay_exp = args->ack_delay_exponent; - ch->tx_max_ack_delay = args->max_ack_delay; - ch->tx_disable_active_migration = args->disable_active_migration; - ch->tx_active_conn_id_limit = args->active_conn_id_limit; - - if (!ossl_quic_rxfc_init(&ch->conn_rxfc, NULL, - ch->tx_init_max_data, - DEFAULT_CONN_RXFC_MAX_WND_MUL * ch->tx_init_max_data, - get_time, ch)) { - goto err; - } - return ch; - -err: -#ifndef OPENSSL_NO_QLOG - OPENSSL_free(ch->qlog_title); -#endif - OPENSSL_free(ch); - return NULL; } void ossl_quic_channel_free(QUIC_CHANNEL *ch) @@ -1404,6 +1382,7 @@ static int ch_on_transport_params(const unsigned char *params, int got_disable_active_migration = 0; QUIC_CONN_ID cid; const char *reason = "bad transport parameter"; + ossl_unused uint64_t rx_max_idle_timeout = 0; ossl_unused const void *stateless_reset_token_p = NULL; QUIC_PREFERRED_ADDR pfa; SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(ch->tls); @@ -1529,8 +1508,6 @@ static int ch_on_transport_params(const unsigned char *params, goto malformed; } - ch->rx_init_max_data = v; - ossl_quic_txfc_bump_cwm(&ch->conn_txfc, v); got_initial_max_data = 1; break; @@ -1649,7 +1626,6 @@ static int ch_on_transport_params(const unsigned char *params, assert(ch->max_local_streams_bidi == 0); ch->max_local_streams_bidi = v; - ch->rx_init_max_streams_bidi = v; got_initial_max_streams_bidi = 1; break; @@ -1668,7 +1644,6 @@ static int ch_on_transport_params(const unsigned char *params, assert(ch->max_local_streams_uni == 0); ch->max_local_streams_uni = v; - ch->rx_init_max_streams_uni = v; got_initial_max_streams_uni = 1; break; @@ -1691,6 +1666,7 @@ static int ch_on_transport_params(const unsigned char *params, ch_update_idle(ch); got_max_idle_timeout = 1; + rx_max_idle_timeout = v; break; case QUIC_TPARAM_MAX_UDP_PAYLOAD_SIZE: @@ -1701,8 +1677,7 @@ static int ch_on_transport_params(const unsigned char *params, } if (!ossl_quic_wire_decode_transport_param_int(&pkt, &id, &v) - || v < QUIC_MIN_INITIAL_DGRAM_LEN - || v > QUIC_MAX_MAX_UDP_PAYLOAD_SIZE) { + || v < QUIC_MIN_INITIAL_DGRAM_LEN) { reason = TP_REASON_MALFORMED("MAX_UDP_PAYLOAD_SIZE"); goto malformed; } @@ -1810,7 +1785,6 @@ static int ch_on_transport_params(const unsigned char *params, goto malformed; } - ch->rx_disable_active_migration = 1; got_disable_active_migration = 1; break; @@ -1879,10 +1853,10 @@ static int ch_on_transport_params(const unsigned char *params, ch->rx_init_max_stream_data_uni); if (got_initial_max_streams_bidi) QLOG_U64("initial_max_streams_bidi", - ch->rx_init_max_streams_bidi); + ch->max_local_streams_bidi); if (got_initial_max_streams_uni) QLOG_U64("initial_max_streams_uni", - ch->rx_init_max_streams_uni); + ch->max_local_streams_uni); if (got_ack_delay_exp) QLOG_U64("ack_delay_exponent", ch->rx_ack_delay_exp); if (got_max_ack_delay) @@ -1890,7 +1864,7 @@ static int ch_on_transport_params(const unsigned char *params, if (got_max_udp_payload_size) QLOG_U64("max_udp_payload_size", ch->rx_max_udp_payload_size); if (got_max_idle_timeout) - QLOG_U64("max_idle_timeout", ch->max_idle_timeout_remote_req); + QLOG_U64("max_idle_timeout", rx_max_idle_timeout); if (got_active_conn_id_limit) QLOG_U64("active_connection_id_limit", ch->rx_active_conn_id_limit); if (got_stateless_reset_token) @@ -1907,12 +1881,11 @@ static int ch_on_transport_params(const unsigned char *params, QLOG_CID("connection_id", &pfa.cid); QLOG_END() } - QLOG_BOOL("disable_active_migration", ch->rx_disable_active_migration); + QLOG_BOOL("disable_active_migration", got_disable_active_migration); QLOG_EVENT_END() #endif - if (got_initial_max_data - || got_initial_max_stream_data_bidi_remote || got_initial_max_stream_data_uni + if (got_initial_max_data || got_initial_max_stream_data_bidi_remote || got_initial_max_streams_bidi || got_initial_max_streams_uni) /* * If FC credit was bumped, we may now be able to send. Update all @@ -1974,7 +1947,9 @@ static int ch_generate_transport_params(QUIC_CHANNEL *ch) wpkt_valid = 1; - if (ch->tx_disable_active_migration != 0 && ossl_quic_wire_encode_transport_param_bytes(&wpkt, QUIC_TPARAM_DISABLE_ACTIVE_MIGRATION, NULL, 0) == NULL) + if (ossl_quic_wire_encode_transport_param_bytes(&wpkt, QUIC_TPARAM_DISABLE_ACTIVE_MIGRATION, + NULL, 0) + == NULL) goto err; if (ch->is_server) { @@ -2001,16 +1976,11 @@ static int ch_generate_transport_params(QUIC_CHANNEL *ch) goto err; if (!ossl_quic_wire_encode_transport_param_int(&wpkt, QUIC_TPARAM_MAX_UDP_PAYLOAD_SIZE, - ch->tx_max_udp_payload_size)) + QUIC_MIN_INITIAL_DGRAM_LEN)) goto err; if (!ossl_quic_wire_encode_transport_param_int(&wpkt, QUIC_TPARAM_ACTIVE_CONN_ID_LIMIT, - ch->tx_active_conn_id_limit)) - goto err; - - if (ch->tx_ack_delay_exp != QUIC_DEFAULT_ACK_DELAY_EXP - && !ossl_quic_wire_encode_transport_param_int(&wpkt, QUIC_TPARAM_ACK_DELAY_EXP, - ch->tx_ack_delay_exp)) + QUIC_MIN_ACTIVE_CONN_ID_LIMIT)) goto err; if (ch->tx_max_ack_delay != QUIC_DEFAULT_MAX_ACK_DELAY @@ -2061,20 +2031,17 @@ static int ch_generate_transport_params(QUIC_CHANNEL *ch) #ifndef OPENSSL_NO_QLOG QLOG_EVENT_BEGIN(ch_get_qlog(ch), transport, parameters_set) QLOG_STR("owner", "local"); - QLOG_BOOL("disable_active_migration", ch->tx_disable_active_migration); + QLOG_BOOL("disable_active_migration", 1); if (ch->is_server) { QLOG_CID("original_destination_connection_id", &ch->init_dcid); QLOG_CID("initial_source_connection_id", &ch->cur_local_cid); } else { QLOG_STR("initial_source_connection_id", ""); } - QLOG_U64("max_idle_timeout", ch->max_idle_timeout_local_req); - QLOG_U64("max_udp_payload_size", ch->tx_max_udp_payload_size); - QLOG_U64("active_connection_id_limit", ch->tx_active_conn_id_limit); - if (ch->tx_ack_delay_exp != QUIC_DEFAULT_ACK_DELAY_EXP) - QLOG_U64("ack_delay_exponent", ch->tx_ack_delay_exp); - if (ch->tx_max_ack_delay != QUIC_DEFAULT_MAX_ACK_DELAY) - QLOG_U64("max_ack_delay", ch->tx_max_ack_delay); + QLOG_U64("max_idle_timeout", ch->max_idle_timeout); + QLOG_U64("max_udp_payload_size", QUIC_MIN_INITIAL_DGRAM_LEN); + QLOG_U64("active_connection_id_limit", QUIC_MIN_ACTIVE_CONN_ID_LIMIT); + QLOG_U64("max_ack_delay", ch->tx_max_ack_delay); QLOG_U64("initial_max_data", ossl_quic_rxfc_get_cwm(&ch->conn_rxfc)); QLOG_U64("initial_max_stream_data_bidi_local", ch->tx_init_max_stream_data_bidi_local); @@ -2310,12 +2277,6 @@ static void ch_rx_check_forged_pkt_limit(QUIC_CHANNEL *ch) "forgery limit"); } -void ossl_ch_reset_rx_state(QUIC_CHANNEL *ch) -{ - ch->did_crypto_frame = 0; - ch->seen_path_challenge = 0; -} - /* Process queued incoming packets and handle frames, if any. */ static int ch_rx(QUIC_CHANNEL *ch, int channel_only, int *notify_other_threads) { @@ -2695,12 +2656,63 @@ static void ch_rx_handle_packet(QUIC_CHANNEL *ch, int channel_only) break; + case QUIC_PKT_TYPE_VERSION_NEG: + /* + * "A client MUST discard any Version Negotiation packet if it has + * received and successfully processed any other packet." + */ + if (!old_have_processed_any_pkt) + ch_rx_handle_version_neg(ch, ch->qrx_pkt); + + break; + default: assert(0); break; } } +static void ch_rx_handle_version_neg(QUIC_CHANNEL *ch, OSSL_QRX_PKT *pkt) +{ + /* + * We do not support version negotiation at this time. As per RFC 9000 s. + * 6.2., we MUST abandon the connection attempt if we receive a Version + * Negotiation packet, unless we have already successfully processed another + * incoming packet, or the packet lists the QUIC version we want to use. + */ + PACKET vpkt; + unsigned long v; + + if (!PACKET_buf_init(&vpkt, pkt->hdr->data, pkt->hdr->len)) + return; + + while (PACKET_remaining(&vpkt) > 0) { + if (!PACKET_get_net_4(&vpkt, &v)) + break; + + if ((uint32_t)v == QUIC_VERSION_1) + return; + } + + /* No match, this is a failure case. */ + ch_raise_version_neg_failure(ch); +} + +static void ch_raise_version_neg_failure(QUIC_CHANNEL *ch) +{ + QUIC_TERMINATE_CAUSE tcause = { 0 }; + + tcause.error_code = OSSL_QUIC_ERR_CONNECTION_REFUSED; + tcause.reason = "version negotiation failure"; + tcause.reason_len = strlen(tcause.reason); + + /* + * Skip TERMINATING state; this is not considered a protocol error and we do + * not send CONNECTION_CLOSE. + */ + ch_start_terminating(ch, &tcause, 1); +} + /* Try to generate packets and if possible, flush them to the network. */ static int ch_tx(QUIC_CHANNEL *ch, int *notify_other_threads) { @@ -3217,11 +3229,10 @@ static void copy_tcause(QUIC_TERMINATE_CAUSE *dst, * If this fails, dst->reason becomes NULL and we simply do not use a * reason. This ensures termination is infallible. */ - dst->reason = r = OPENSSL_malloc(l + 1); + dst->reason = r = OPENSSL_memdup(src->reason, l + 1); if (r == NULL) return; - memcpy(r, src->reason, l); r[l] = '\0'; dst->reason_len = l; } @@ -3325,8 +3336,7 @@ static int ch_enqueue_retire_conn_id(QUIC_CHANNEL *ch, uint64_t seq_num) WPACKET wpkt; size_t l; - if (!ossl_quic_srtm_remove(ch->srtm, ch, seq_num, NULL)) - goto err; + ossl_quic_srtm_remove(ch->srtm, ch, seq_num); if ((buf_mem = BUF_MEM_new()) == NULL) goto err; @@ -3713,6 +3723,7 @@ static void ch_on_idle_timeout(QUIC_CHANNEL *ch) * @return 1 on success, 0 on failure to set required elements. */ static int ch_on_new_conn_common(QUIC_CHANNEL *ch, const BIO_ADDR *peer, + const QUIC_CONN_ID *peer_scid, const QUIC_CONN_ID *peer_dcid, const QUIC_CONN_ID *peer_odcid) { @@ -3721,6 +3732,7 @@ static int ch_on_new_conn_common(QUIC_CHANNEL *ch, const BIO_ADDR *peer, return 0; ch->init_dcid = *peer_dcid; + ch->cur_remote_dcid = *peer_scid; ch->odcid.id_len = 0; if (peer_odcid != NULL) @@ -3764,6 +3776,7 @@ static int ch_on_new_conn_common(QUIC_CHANNEL *ch, const BIO_ADDR *peer, /* Called when we, as a server, get a new incoming connection. */ int ossl_quic_channel_on_new_conn(QUIC_CHANNEL *ch, const BIO_ADDR *peer, + const QUIC_CONN_ID *peer_scid, const QUIC_CONN_ID *peer_dcid) { if (!ossl_assert(ch->state == QUIC_CHANNEL_STATE_IDLE && ch->is_server)) @@ -3773,7 +3786,7 @@ int ossl_quic_channel_on_new_conn(QUIC_CHANNEL *ch, const BIO_ADDR *peer, if (!ossl_quic_lcidm_generate_initial(ch->lcidm, ch, &ch->cur_local_cid)) return 0; - return ch_on_new_conn_common(ch, peer, peer_dcid, NULL); + return ch_on_new_conn_common(ch, peer, peer_scid, peer_dcid, NULL); } /** @@ -3800,6 +3813,7 @@ int ossl_quic_channel_on_new_conn(QUIC_CHANNEL *ch, const BIO_ADDR *peer, * met (e.g., channel is not idle or not a server, or binding fails). */ int ossl_quic_bind_channel(QUIC_CHANNEL *ch, const BIO_ADDR *peer, + const QUIC_CONN_ID *peer_scid, const QUIC_CONN_ID *peer_dcid, const QUIC_CONN_ID *peer_odcid) { @@ -3818,7 +3832,7 @@ int ossl_quic_bind_channel(QUIC_CHANNEL *ch, const BIO_ADDR *peer, * peer_odcid <=> is initial dst conn id chosen by peer in its * first initial packet we received without token. */ - return ch_on_new_conn_common(ch, peer, peer_dcid, peer_odcid); + return ch_on_new_conn_common(ch, peer, peer_scid, peer_dcid, peer_odcid); } SSL *ossl_quic_channel_get0_ssl(QUIC_CHANNEL *ch) @@ -4134,15 +4148,10 @@ int ossl_quic_channel_have_generated_transport_params(const QUIC_CHANNEL *ch) return ch->got_local_transport_params; } -int ossl_quic_channel_set_max_idle_timeout_request(QUIC_CHANNEL *ch, uint64_t ms) +void ossl_quic_channel_set_max_idle_timeout_request(QUIC_CHANNEL *ch, uint64_t ms) { - if (ossl_quic_channel_have_generated_transport_params(ch)) - return 0; - ch->max_idle_timeout_local_req = ms; - return 1; } - uint64_t ossl_quic_channel_get_max_idle_timeout_request(const QUIC_CHANNEL *ch) { return ch->max_idle_timeout_local_req; @@ -4157,218 +4166,3 @@ uint64_t ossl_quic_channel_get_max_idle_timeout_actual(const QUIC_CHANNEL *ch) { return ch->max_idle_timeout; } - -int ossl_quic_channel_set_max_udp_payload_size_request(QUIC_CHANNEL *ch, uint64_t size) -{ - if (ossl_quic_channel_have_generated_transport_params(ch)) - return 0; - - ch->tx_max_udp_payload_size = size; - return 1; -} - -uint64_t ossl_quic_channel_get_max_udp_payload_size_request(const QUIC_CHANNEL *ch) -{ - return ch->tx_max_udp_payload_size; -} - -uint64_t ossl_quic_channel_get_max_udp_payload_size_peer_request(const QUIC_CHANNEL *ch) -{ - return ch->rx_max_udp_payload_size; -} - -int ossl_quic_channel_set_max_data_request(QUIC_CHANNEL *ch, uint64_t max_data) -{ - if (ossl_quic_channel_have_generated_transport_params(ch)) - return 0; - - if (max_data > UINT64_MAX / DEFAULT_CONN_RXFC_MAX_WND_MUL) - return 0; - - if (!ossl_quic_rxfc_init(&ch->conn_rxfc, NULL, - max_data, DEFAULT_CONN_RXFC_MAX_WND_MUL * max_data, - get_time, ch)) - return 0; - - ch->tx_init_max_data = max_data; - - return 1; -} - -uint64_t ossl_quic_channel_get_max_data_request(const QUIC_CHANNEL *ch) -{ - return ch->tx_init_max_data; -} - -uint64_t ossl_quic_channel_get_max_data_peer_request(const QUIC_CHANNEL *ch) -{ - return ch->rx_init_max_data; -} - -int ossl_quic_channel_set_max_stream_data_request(QUIC_CHANNEL *ch, uint64_t max_data, int is_uni, int is_remote) -{ - if (ossl_quic_channel_have_generated_transport_params(ch)) - return 0; - - /* no need to update fc here since no stream is created yet */ - if (is_uni) { - ch->tx_init_max_stream_data_uni = max_data; - } else { - if (is_remote) - ch->tx_init_max_stream_data_bidi_remote = max_data; - else - ch->tx_init_max_stream_data_bidi_local = max_data; - } - - return 1; -} - -uint64_t ossl_quic_channel_get_max_stream_data_request(const QUIC_CHANNEL *ch, int is_uni, int is_remote) -{ - if (is_uni) - return ch->tx_init_max_stream_data_uni; - else - return is_remote ? ch->tx_init_max_stream_data_bidi_remote : ch->tx_init_max_stream_data_bidi_local; -} - -uint64_t ossl_quic_channel_get_max_stream_data_peer_request(const QUIC_CHANNEL *ch, int is_uni, int is_remote) -{ - if (is_uni) - return ch->rx_init_max_stream_data_uni; - else - return is_remote ? ch->rx_init_max_stream_data_bidi_remote : ch->rx_init_max_stream_data_bidi_local; -} - -int ossl_quic_channel_set_max_streams_request(QUIC_CHANNEL *ch, uint64_t max_streams, int is_uni) -{ - if (ossl_quic_channel_have_generated_transport_params(ch)) - return 0; - - if (is_uni) { - if (!ossl_quic_rxfc_init_standalone(&ch->max_streams_uni_rxfc, - max_streams, get_time, ch)) - return 0; - - ch->tx_init_max_streams_uni = max_streams; - } else { - if (!ossl_quic_rxfc_init_standalone(&ch->max_streams_bidi_rxfc, - max_streams, get_time, ch)) - return 0; - - ch->tx_init_max_streams_bidi = max_streams; - } - - return 1; -} - -uint64_t ossl_quic_channel_get_max_streams_request(const QUIC_CHANNEL *ch, int is_uni) -{ - return is_uni ? ch->tx_init_max_streams_uni : ch->tx_init_max_streams_bidi; -} - -uint64_t ossl_quic_channel_get_max_streams_peer_request(const QUIC_CHANNEL *ch, int is_uni) -{ - return is_uni ? ch->rx_init_max_streams_uni : ch->rx_init_max_streams_bidi; -} - -int ossl_quic_channel_set_ack_delay_exponent_request(QUIC_CHANNEL *ch, uint64_t exp) -{ - if (ossl_quic_channel_have_generated_transport_params(ch)) - return 0; - - /* - * ossl_quic_tx_packetiser_args_st::ack_delay_exponent is uint32_t, - * but quic_channel_st::tx_ack_delay_exp is unsigned char, checking - * against the smaller type. - */ - if (exp > UCHAR_MAX) - return 0; - - if (!ossl_quic_tx_packetiser_set_ack_delay_exponent(ch->txp, (uint32_t)exp)) - return 0; - - ch->tx_ack_delay_exp = (unsigned char)exp; - - return 1; -} - -uint64_t ossl_quic_channel_get_ack_delay_exponent_request(const QUIC_CHANNEL *ch) -{ - return ch->tx_ack_delay_exp; -} - -uint64_t ossl_quic_channel_get_ack_delay_exponent_peer_request(const QUIC_CHANNEL *ch) -{ - return ch->rx_ack_delay_exp; -} - -int ossl_quic_channel_set_max_ack_delay_request(QUIC_CHANNEL *ch, uint64_t ms) -{ - if (ossl_quic_channel_have_generated_transport_params(ch)) - return 0; - - ch->tx_max_ack_delay = ms; - ossl_ackm_set_tx_max_ack_delay(ch->ackm, ossl_ms2time(ch->tx_max_ack_delay)); - return 1; -} - -uint64_t ossl_quic_channel_get_max_ack_delay_request(const QUIC_CHANNEL *ch) -{ - return ch->tx_max_ack_delay; -} - -uint64_t ossl_quic_channel_get_max_ack_delay_peer_request(const QUIC_CHANNEL *ch) -{ - return ch->rx_max_ack_delay; -} - -int ossl_quic_channel_set_disable_active_migration_request(QUIC_CHANNEL *ch, uint64_t disable) -{ - if (ossl_quic_channel_have_generated_transport_params(ch)) - return 0; - - if (disable > UCHAR_MAX) - return 0; - - ch->tx_disable_active_migration = (unsigned char)disable; - return 1; -} - -uint64_t ossl_quic_channel_get_disable_active_migration_request(const QUIC_CHANNEL *ch) -{ - return ch->tx_disable_active_migration; -} - -uint64_t ossl_quic_channel_get_disable_active_migration_peer_request(const QUIC_CHANNEL *ch) -{ - return ch->rx_disable_active_migration; -} - -int ossl_quic_channel_set_active_conn_id_limit_request(QUIC_CHANNEL *ch, uint64_t limit) -{ - if (ossl_quic_channel_have_generated_transport_params(ch)) - return 0; - - ch->tx_active_conn_id_limit = limit; - return 1; -} - -uint64_t ossl_quic_channel_get_active_conn_id_limit_request(const QUIC_CHANNEL *ch) -{ - return ch->tx_active_conn_id_limit; -} - -uint64_t ossl_quic_channel_get_active_conn_id_limit_peer_request(const QUIC_CHANNEL *ch) -{ - return ch->rx_active_conn_id_limit; -} - -uint64_t ossl_quic_channel_get_path_challenge_count(const QUIC_CHANNEL *ch) -{ - return ch->path_challenge_rx; -} - -uint64_t ossl_quic_channel_get_path_response_count(const QUIC_CHANNEL *ch) -{ - return ch->path_response_tx; -} diff --git a/ssl/quic/quic_channel_local.h b/ssl/quic/quic_channel_local.h index 7475f623c9..ae443fccca 100644 --- a/ssl/quic/quic_channel_local.h +++ b/ssl/quic/quic_channel_local.h @@ -1,12 +1,3 @@ -/* - * Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - #ifndef OSSL_QUIC_CHANNEL_LOCAL_H #define OSSL_QUIC_CHANNEL_LOCAL_H @@ -21,28 +12,6 @@ #include "internal/quic_stream_map.h" #include "internal/quic_tls.h" -/* - * This is a part of PATH_CHALLENGE flood [1] mitigation. This limits the - * number of PATH_CHALLENGE frames QUIC stack is willing to process for - * connection. Local QUIC stack creates PATH_RESPONSE frame for PATH_CHALLENGE - * frame it receives from remote peer. The response frame is put Control Frame - * Queue waiting to be dispatched. The PATH_RESPONSE frame is removed from CFQ - * after it is dispatched. The QUIC_PATH_RESPONSE_QLEN limits the number of - * PATH_RESPONSE frames waiting to be dispatched. No new PATH_RESPONSE frames - * are inserted into CFQ if queue limit is exceeded. - * - * QUIC implementations use different limits for PATH_RESPONSE queue lengths: - * quic-go defines maxPathResponses as 256 - * quiche from cloadflare sets DEFAULT_MAX_PATH_CHALLENGE_RX_QUEUE_LEN to 3 - * t-quic from tencent chooses MAX_PATH_CHALS_RECV to be 8 - * - * OpenSSL here introduces QUIC_PATH_RESPONSE_QLEN as 32. - * - * [1] https://www.ietf.org/archive/id/draft-chen-quic-logical-vuln-mitigations-00.txt - * (section 4.2) - */ -#define QUIC_PATH_RESPONSE_QLEN 32 - /* * QUIC Channel Structure * ====================== @@ -179,27 +148,17 @@ struct quic_channel_st { uint64_t cur_retire_prior_to; /* Transport parameter values we send to our peer. */ - uint64_t tx_init_max_data; uint64_t tx_init_max_stream_data_bidi_local; uint64_t tx_init_max_stream_data_bidi_remote; uint64_t tx_init_max_stream_data_uni; - uint64_t tx_init_max_streams_bidi; - uint64_t tx_init_max_streams_uni; uint64_t tx_max_ack_delay; /* ms */ - unsigned char tx_ack_delay_exp; - unsigned char tx_disable_active_migration; - uint64_t tx_active_conn_id_limit; - /* Transport parameter values received from peer. */ - uint64_t rx_init_max_data; + /* Transport parameter values received from server. */ uint64_t rx_init_max_stream_data_bidi_local; uint64_t rx_init_max_stream_data_bidi_remote; uint64_t rx_init_max_stream_data_uni; - uint64_t rx_init_max_streams_bidi; - uint64_t rx_init_max_streams_uni; uint64_t rx_max_ack_delay; /* ms */ unsigned char rx_ack_delay_exp; - unsigned char rx_disable_active_migration; /* Diagnostic counters for testing purposes only. May roll over. */ uint16_t diag_num_rx_ack; /* Number of ACK frames received */ @@ -229,11 +188,6 @@ struct quic_channel_st { * negotiated by transport parameters. */ uint64_t rx_max_udp_payload_size; - /* - * Maximum payload size in bytes for datagrams received from our peer, as - * negotiated by transport parameters. - */ - uint64_t tx_max_udp_payload_size; /* Maximum active CID limit, as negotiated by transport parameters. */ uint64_t rx_active_conn_id_limit; @@ -503,18 +457,6 @@ struct quic_channel_st { /* Has qlog been requested? */ unsigned int is_tserver_ch : 1; - /* - * RFC 9000 Section 9.2.1 says: - * However, an endpoint SHOULD NOT send multiple - * PATH_CHALLENGE frames in a single packet. - * The counter here allows us to detect multiple presence - * of PATH_CHALLENGE frame in packet. We process only the - * first PATH_CHALLENGE frame found in packet. Remaining PATH_CHALLENGE - * frames are ignored. - * seen_path_challenge flag is always reset before - * ossl_quic_handle_frames() gets called. - */ - unsigned int seen_path_challenge : 1; /* Saved error stack in case permanent error was encountered */ ERR_STATE *err_state; @@ -525,15 +467,6 @@ struct quic_channel_st { /* Title for qlog purposes. We own this copy. */ char *qlog_title; - /* - * number of path responses waiting to be dispatched - * from control frame queue (CFQ) - */ - unsigned int path_response_limit; - /* number of path challenge frames received */ - unsigned int path_challenge_rx; - /* number of path response frames sent */ - unsigned int path_response_tx; }; #endif diff --git a/ssl/quic/quic_fifd.c b/ssl/quic/quic_fifd.c index e80483b501..03b8cebd30 100644 --- a/ssl/quic/quic_fifd.c +++ b/ssl/quic/quic_fifd.c @@ -310,46 +310,3 @@ void ossl_quic_fifd_set_qlog_cb(QUIC_FIFD *fifd, QLOG *(*get_qlog_cb)(void *arg) fifd->get_qlog_cb = get_qlog_cb; fifd->get_qlog_cb_arg = get_qlog_cb_arg; } - -static void txpim_pkt_remove_cfq_item(QUIC_TXPIM_PKT *pkt, QUIC_CFQ_ITEM *cfq_item) -{ - QUIC_CFQ_ITEM *prev = cfq_item->pkt_prev; - - if (prev != NULL) { - prev->pkt_next = cfq_item->pkt_next; - } else { - pkt->retx_head = cfq_item->pkt_next; - } - - if (cfq_item->pkt_next != NULL) - cfq_item->pkt_next->pkt_prev = prev; - - cfq_item->pkt_prev = NULL; - cfq_item->pkt_next = NULL; -} - -void ossl_quic_fifd_pkt_discard_unreliable(QUIC_FIFD *fifd, QUIC_TXPIM_PKT *pkt) -{ - QUIC_CFQ_ITEM *cfq_item, *cfq_next; - - /* - * The packet has been written to network. We can discard frames we don't - * retransmit when loss is detected. - */ - cfq_item = pkt->retx_head; - while (cfq_item != NULL) { - /* - * Discarded items are moved to free list. If item - * got moved to free list we must also remove it from - * cfq list kept in pkt, so ACKM does not find it when - * receives an ACK for pkt. - */ - if (ossl_quic_cfq_discard_unreliable(fifd->cfq, cfq_item)) { - cfq_next = cfq_item->pkt_next; - txpim_pkt_remove_cfq_item(pkt, cfq_item); - cfq_item = cfq_next; - } else { - cfq_item = cfq_item->pkt_next; - } - } -} diff --git a/ssl/quic/quic_impl.c b/ssl/quic/quic_impl.c index 99ddfd082e..53bb247e85 100644 --- a/ssl/quic/quic_impl.c +++ b/ssl/quic/quic_impl.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -415,11 +415,6 @@ static int expect_quic_c(const SSL *s, QCTX *ctx) return expect_quic_as(s, ctx, QCTX_C); } -static int expect_quic_cl(const SSL *s, QCTX *ctx) -{ - return expect_quic_as(s, ctx, QCTX_C | QCTX_L); -} - static int expect_quic_csl(const SSL *s, QCTX *ctx) { return expect_quic_as(s, ctx, QCTX_C | QCTX_S | QCTX_L); @@ -691,9 +686,6 @@ static void quic_unref_port_bios(QUIC_PORT *port) { BIO *b; - if (port == NULL) - return; - b = ossl_quic_port_get_net_rbio(port); BIO_free_all(b); @@ -1874,7 +1866,6 @@ static int create_channel(QUIC_CONNECTION *qc, SSL_CTX *ctx) if (qc->port == NULL) { QUIC_RAISE_NON_NORMAL_ERROR(NULL, ERR_R_INTERNAL_ERROR, NULL); ossl_quic_engine_free(qc->engine); - qc->engine = NULL; return 0; } @@ -1882,9 +1873,7 @@ static int create_channel(QUIC_CONNECTION *qc, SSL_CTX *ctx) if (qc->ch == NULL) { QUIC_RAISE_NON_NORMAL_ERROR(NULL, ERR_R_INTERNAL_ERROR, NULL); ossl_quic_port_free(qc->port); - qc->port = NULL; ossl_quic_engine_free(qc->engine); - qc->engine = NULL; return 0; } @@ -3490,6 +3479,83 @@ int ossl_quic_set_default_stream_mode(SSL *s, uint32_t mode) return 1; } +/* + * SSL_detach_stream + * ----------------- + */ +QUIC_TAKES_LOCK +SSL *ossl_quic_detach_stream(SSL *s) +{ + QCTX ctx; + QUIC_XSO *xso = NULL; + + if (!expect_quic_conn_only(s, &ctx)) + return NULL; + + qctx_lock(&ctx); + + /* Calling this function inhibits default XSO autocreation. */ + /* QC ref to any default XSO is transferred to us and to caller. */ + qc_set_default_xso_keep_ref(ctx.qc, NULL, /*touch=*/1, &xso); + + qctx_unlock(&ctx); + + return xso != NULL ? &xso->obj.ssl : NULL; +} + +/* + * SSL_attach_stream + * ----------------- + */ +QUIC_TAKES_LOCK +int ossl_quic_attach_stream(SSL *conn, SSL *stream) +{ + QCTX ctx; + QUIC_XSO *xso; + int nref; + + if (!expect_quic_conn_only(conn, &ctx)) + return 0; + + if (stream == NULL || stream->type != SSL_TYPE_QUIC_XSO) + return QUIC_RAISE_NON_NORMAL_ERROR(&ctx, ERR_R_PASSED_NULL_PARAMETER, + "stream to attach must be a valid QUIC stream"); + + xso = (QUIC_XSO *)stream; + + qctx_lock(&ctx); + + if (ctx.qc->default_xso != NULL) { + qctx_unlock(&ctx); + return QUIC_RAISE_NON_NORMAL_ERROR(&ctx, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED, + "connection already has a default stream"); + } + + /* + * It is a caller error for the XSO being attached as a default XSO to have + * more than one ref. + */ + if (!CRYPTO_GET_REF(&xso->obj.ssl.references, &nref)) { + qctx_unlock(&ctx); + return QUIC_RAISE_NON_NORMAL_ERROR(&ctx, ERR_R_INTERNAL_ERROR, + "ref"); + } + + if (nref != 1) { + qctx_unlock(&ctx); + return QUIC_RAISE_NON_NORMAL_ERROR(&ctx, ERR_R_PASSED_INVALID_ARGUMENT, + "stream being attached must have " + "only 1 reference"); + } + + /* Caller's reference to the XSO is transferred to us. */ + /* Calling this function inhibits default XSO autocreation. */ + qc_set_default_xso(ctx.qc, xso, /*touch=*/1); + + qctx_unlock(&ctx); + return 1; +} + /* * SSL_set_incoming_stream_policy * ------------------------------ @@ -3567,9 +3633,7 @@ static int qc_getset_idle_timeout(QCTX *ctx, uint32_t class_, switch (class_) { case SSL_VALUE_CLASS_FEATURE_REQUEST: - value_out = ctx->is_listener - ? ossl_quic_port_get_max_idle_timeout(ctx->ql->port) - : ossl_quic_channel_get_max_idle_timeout_request(ctx->qc->ch); + value_out = ossl_quic_channel_get_max_idle_timeout_request(ctx->qc->ch); if (p_value_in != NULL) { value_in = *p_value_in; @@ -3579,15 +3643,13 @@ static int qc_getset_idle_timeout(QCTX *ctx, uint32_t class_, goto err; } - if (ctx->is_listener) { - ossl_quic_port_set_max_idle_timeout(ctx->ql->port, value_in); - } else { - if (!ossl_quic_channel_set_max_idle_timeout_request(ctx->qc->ch, value_in)) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_FEATURE_NOT_RENEGOTIABLE, - NULL); - goto err; - } + if (ossl_quic_channel_have_generated_transport_params(ctx->qc->ch)) { + QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_FEATURE_NOT_RENEGOTIABLE, + NULL); + goto err; } + + ossl_quic_channel_set_max_idle_timeout_request(ctx->qc->ch, value_in); } break; @@ -3599,12 +3661,6 @@ static int qc_getset_idle_timeout(QCTX *ctx, uint32_t class_, goto err; } - if (ctx->is_listener) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_OP, - NULL); - goto err; - } - if (!ossl_quic_channel_is_handshake_complete(ctx->qc->ch)) { QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_FEATURE_NEGOTIATION_NOT_COMPLETE, NULL); @@ -3631,366 +3687,6 @@ err: return ret; } -QUIC_TAKES_LOCK -static int qc_getset_max_udp_payload_size(QCTX *ctx, uint32_t class_, - uint64_t *p_value_out, uint64_t *p_value_in) -{ - int ret = 0; - uint64_t value_out = 0, value_in; - - qctx_lock(ctx); - - switch (class_) { - case SSL_VALUE_CLASS_FEATURE_REQUEST: - value_out = ctx->is_listener - ? ossl_quic_port_get_max_udp_payload_size(ctx->ql->port) - : ossl_quic_channel_get_max_udp_payload_size_request(ctx->qc->ch); - - if (p_value_in != NULL) { - value_in = *p_value_in; - if (value_in > QUIC_DEFAULT_MAX_UDP_PAYLOAD_SIZE || value_in < QUIC_MIN_INITIAL_DGRAM_LEN) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, ERR_R_PASSED_INVALID_ARGUMENT, - NULL); - goto err; - } - - if (ctx->is_listener) { - ossl_quic_port_set_max_udp_payload_size(ctx->ql->port, value_in); - } else { - if (!ossl_quic_channel_set_max_udp_payload_size_request(ctx->qc->ch, value_in)) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_FEATURE_NOT_RENEGOTIABLE, - NULL); - goto err; - } - } - } - break; - - case SSL_VALUE_CLASS_FEATURE_PEER_REQUEST: - if (p_value_in != NULL) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_OP, - NULL); - goto err; - } - - if (ctx->is_listener) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_OP, - NULL); - goto err; - } - - if (!ossl_quic_channel_is_handshake_complete(ctx->qc->ch)) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_FEATURE_NEGOTIATION_NOT_COMPLETE, - NULL); - goto err; - } - - value_out = ossl_quic_channel_get_max_udp_payload_size_peer_request(ctx->qc->ch); - break; - - default: - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_CLASS, - NULL); - goto err; - } - - ret = 1; -err: - qctx_unlock(ctx); - if (ret && p_value_out != NULL) - *p_value_out = value_out; - - return ret; -} - -QUIC_TAKES_LOCK -static int qc_getset_max_data(QCTX *ctx, uint32_t class_, - uint64_t *p_value_out, uint64_t *p_value_in) -{ - int ret = 0; - uint64_t value_out = 0, value_in; - - qctx_lock(ctx); - - switch (class_) { - case SSL_VALUE_CLASS_FEATURE_REQUEST: - value_out = ctx->is_listener - ? ossl_quic_port_get_init_max_data(ctx->ql->port) - : ossl_quic_channel_get_max_data_request(ctx->qc->ch); - - if (p_value_in != NULL) { - value_in = *p_value_in; - if (value_in > OSSL_QUIC_VLINT_MAX) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, ERR_R_PASSED_INVALID_ARGUMENT, - NULL); - goto err; - } - - if (ctx->is_listener) { - ossl_quic_port_set_init_max_data(ctx->ql->port, value_in); - } else { - if (!ossl_quic_channel_set_max_data_request(ctx->qc->ch, value_in)) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_FEATURE_NOT_RENEGOTIABLE, - NULL); - goto err; - } - } - } - break; - - case SSL_VALUE_CLASS_FEATURE_PEER_REQUEST: - if (p_value_in != NULL) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_OP, - NULL); - goto err; - } - - if (ctx->is_listener) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_OP, - NULL); - goto err; - } - - if (!ossl_quic_channel_is_handshake_complete(ctx->qc->ch)) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_FEATURE_NEGOTIATION_NOT_COMPLETE, - NULL); - goto err; - } - - value_out = ossl_quic_channel_get_max_data_peer_request(ctx->qc->ch); - break; - - default: - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_CLASS, - NULL); - goto err; - } - - ret = 1; -err: - qctx_unlock(ctx); - if (ret && p_value_out != NULL) - *p_value_out = value_out; - - return ret; -} - -QUIC_TAKES_LOCK -static int qc_getset_max_stream_data(QCTX *ctx, uint32_t class_, - uint64_t *p_value_out, int is_uni, int is_remote, uint64_t *p_value_in) -{ - int ret = 0; - uint64_t value_out = 0, value_in; - - qctx_lock(ctx); - - switch (class_) { - case SSL_VALUE_CLASS_FEATURE_REQUEST: - value_out = ctx->is_listener - ? ossl_quic_port_get_init_max_stream_data(ctx->ql->port, is_uni, is_remote) - : ossl_quic_channel_get_max_stream_data_request(ctx->qc->ch, is_uni, is_remote); - - if (p_value_in != NULL) { - value_in = *p_value_in; - if (value_in > OSSL_QUIC_VLINT_MAX) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, ERR_R_PASSED_INVALID_ARGUMENT, - NULL); - goto err; - } - - if (ctx->is_listener) { - ossl_quic_port_set_init_max_stream_data(ctx->ql->port, value_in, is_uni, is_remote); - } else { - if (!ossl_quic_channel_set_max_stream_data_request(ctx->qc->ch, value_in, is_uni, is_remote)) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_FEATURE_NOT_RENEGOTIABLE, - NULL); - goto err; - } - } - } - break; - - case SSL_VALUE_CLASS_FEATURE_PEER_REQUEST: - if (p_value_in != NULL) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_OP, - NULL); - goto err; - } - - if (ctx->is_listener) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_OP, - NULL); - goto err; - } - - if (!ossl_quic_channel_is_handshake_complete(ctx->qc->ch)) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_FEATURE_NEGOTIATION_NOT_COMPLETE, - NULL); - goto err; - } - - value_out = ossl_quic_channel_get_max_stream_data_peer_request(ctx->qc->ch, is_uni, is_remote); - break; - - default: - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_CLASS, - NULL); - goto err; - } - - ret = 1; -err: - qctx_unlock(ctx); - if (ret && p_value_out != NULL) - *p_value_out = value_out; - - return ret; -} - -QUIC_TAKES_LOCK -static int qc_getset_ack_delay_exponent(QCTX *ctx, uint32_t class_, - uint64_t *p_value_out, uint64_t *p_value_in) -{ - int ret = 0; - uint64_t value_out = 0, value_in; - - qctx_lock(ctx); - - switch (class_) { - case SSL_VALUE_CLASS_FEATURE_REQUEST: - value_out = ctx->is_listener - ? ossl_quic_port_get_ack_delay_exponent(ctx->ql->port) - : ossl_quic_channel_get_ack_delay_exponent_request(ctx->qc->ch); - - if (p_value_in != NULL) { - value_in = *p_value_in; - if (value_in > QUIC_MAX_ACK_DELAY_EXP) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, ERR_R_PASSED_INVALID_ARGUMENT, - NULL); - goto err; - } - - if (ctx->is_listener) { - ossl_quic_port_set_ack_delay_exponent(ctx->ql->port, value_in); - } else { - if (!ossl_quic_channel_set_ack_delay_exponent_request(ctx->qc->ch, value_in)) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_FEATURE_NOT_RENEGOTIABLE, - NULL); - goto err; - } - } - } - break; - - case SSL_VALUE_CLASS_FEATURE_PEER_REQUEST: - if (p_value_in != NULL) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_OP, - NULL); - goto err; - } - - if (ctx->is_listener) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_OP, - NULL); - goto err; - } - - if (!ossl_quic_channel_is_handshake_complete(ctx->qc->ch)) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_FEATURE_NEGOTIATION_NOT_COMPLETE, - NULL); - goto err; - } - - value_out = ossl_quic_channel_get_ack_delay_exponent_peer_request(ctx->qc->ch); - break; - - default: - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_CLASS, - NULL); - goto err; - } - - ret = 1; -err: - qctx_unlock(ctx); - if (ret && p_value_out != NULL) - *p_value_out = value_out; - - return ret; -} - -QUIC_TAKES_LOCK -static int qc_getset_max_ack_delay(QCTX *ctx, uint32_t class_, - uint64_t *p_value_out, uint64_t *p_value_in) -{ - int ret = 0; - uint64_t value_out = 0, value_in; - - qctx_lock(ctx); - - switch (class_) { - case SSL_VALUE_CLASS_FEATURE_REQUEST: - value_out = ctx->is_listener - ? ossl_quic_port_get_max_ack_delay(ctx->ql->port) - : ossl_quic_channel_get_max_ack_delay_request(ctx->qc->ch); - - if (p_value_in != NULL) { - value_in = *p_value_in; - if (value_in > QUIC_MAX_MAX_ACK_DELAY) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, ERR_R_PASSED_INVALID_ARGUMENT, - NULL); - goto err; - } - - if (ctx->is_listener) { - ossl_quic_port_set_max_ack_delay(ctx->ql->port, value_in); - } else { - if (!ossl_quic_channel_set_max_ack_delay_request(ctx->qc->ch, value_in)) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_FEATURE_NOT_RENEGOTIABLE, - NULL); - goto err; - } - } - } - break; - - case SSL_VALUE_CLASS_FEATURE_PEER_REQUEST: - if (p_value_in != NULL) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_OP, - NULL); - goto err; - } - - if (ctx->is_listener) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_OP, - NULL); - goto err; - } - - if (!ossl_quic_channel_is_handshake_complete(ctx->qc->ch)) { - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_FEATURE_NEGOTIATION_NOT_COMPLETE, - NULL); - goto err; - } - - value_out = ossl_quic_channel_get_max_ack_delay_peer_request(ctx->qc->ch); - break; - - default: - QUIC_RAISE_NON_NORMAL_ERROR(ctx, SSL_R_UNSUPPORTED_CONFIG_VALUE_CLASS, - NULL); - goto err; - } - - ret = 1; -err: - qctx_unlock(ctx); - if (ret && p_value_out != NULL) - *p_value_out = value_out; - - return ret; -} - QUIC_TAKES_LOCK static int qc_get_stream_avail(QCTX *ctx, uint32_t class_, int is_uni, int is_remote, @@ -4126,14 +3822,6 @@ static int expect_quic_for_value(SSL *s, QCTX *ctx, uint32_t id) case SSL_VALUE_STREAM_WRITE_BUF_USED: case SSL_VALUE_STREAM_WRITE_BUF_AVAIL: return expect_quic_cs(s, ctx); - case SSL_VALUE_QUIC_IDLE_TIMEOUT: - case SSL_VALUE_QUIC_UDP_PAYLOAD_SIZE_MAX: - case SSL_VALUE_QUIC_WINDOWCON: - case SSL_VALUE_QUIC_WINDOWBSTR: - case SSL_VALUE_QUIC_WINDOWUSTR: - case SSL_VALUE_QUIC_ACK_DELAY_EXPONENT: - case SSL_VALUE_QUIC_ACK_DELAY_MAX: - return expect_quic_cl(s, ctx); default: return expect_quic_conn_only(s, ctx); } @@ -4155,18 +3843,6 @@ int ossl_quic_get_value_uint(SSL *s, uint32_t class_, uint32_t id, switch (id) { case SSL_VALUE_QUIC_IDLE_TIMEOUT: return qc_getset_idle_timeout(&ctx, class_, value, NULL); - case SSL_VALUE_QUIC_UDP_PAYLOAD_SIZE_MAX: - return qc_getset_max_udp_payload_size(&ctx, class_, value, NULL); - case SSL_VALUE_QUIC_WINDOWCON: - return qc_getset_max_data(&ctx, class_, value, NULL); - case SSL_VALUE_QUIC_WINDOWBSTR: - return qc_getset_max_stream_data(&ctx, class_, value, /*uni=*/0, /*remote=*/0, NULL); - case SSL_VALUE_QUIC_WINDOWUSTR: - return qc_getset_max_stream_data(&ctx, class_, value, /*uni=*/1, /*remote=*/1, NULL); - case SSL_VALUE_QUIC_ACK_DELAY_EXPONENT: - return qc_getset_ack_delay_exponent(&ctx, class_, value, NULL); - case SSL_VALUE_QUIC_ACK_DELAY_MAX: - return qc_getset_max_ack_delay(&ctx, class_, value, NULL); case SSL_VALUE_QUIC_STREAM_BIDI_LOCAL_AVAIL: return qc_get_stream_avail(&ctx, class_, /*uni=*/0, /*remote=*/0, value); @@ -4208,23 +3884,11 @@ int ossl_quic_set_value_uint(SSL *s, uint32_t class_, uint32_t id, return 0; switch (id) { - case SSL_VALUE_EVENT_HANDLING_MODE: - return qc_getset_event_handling(&ctx, class_, NULL, &value); - case SSL_VALUE_QUIC_IDLE_TIMEOUT: return qc_getset_idle_timeout(&ctx, class_, NULL, &value); - case SSL_VALUE_QUIC_UDP_PAYLOAD_SIZE_MAX: - return qc_getset_max_udp_payload_size(&ctx, class_, NULL, &value); - case SSL_VALUE_QUIC_WINDOWCON: - return qc_getset_max_data(&ctx, class_, NULL, &value); - case SSL_VALUE_QUIC_WINDOWBSTR: - return qc_getset_max_stream_data(&ctx, class_, NULL, /*uni=*/0, /*remote=*/0, &value); - case SSL_VALUE_QUIC_WINDOWUSTR: - return qc_getset_max_stream_data(&ctx, class_, NULL, /*uni=*/1, /*remote=*/1, &value); - case SSL_VALUE_QUIC_ACK_DELAY_EXPONENT: - return qc_getset_ack_delay_exponent(&ctx, class_, NULL, &value); - case SSL_VALUE_QUIC_ACK_DELAY_MAX: - return qc_getset_max_ack_delay(&ctx, class_, NULL, &value); + + case SSL_VALUE_EVENT_HANDLING_MODE: + return qc_getset_event_handling(&ctx, class_, NULL, &value); default: return QUIC_RAISE_NON_NORMAL_ERROR(&ctx, @@ -4402,14 +4066,14 @@ static void quic_classify_stream(QUIC_CONNECTION *qc, uint64_t *app_error_code) { int local_init; - uint64_t scratch_pad; /* throw away value */ + uint64_t final_size; local_init = (ossl_quic_stream_is_server_init(qs) == qc->as_server); if (app_error_code != NULL) *app_error_code = UINT64_MAX; else - app_error_code = &scratch_pad; + app_error_code = &final_size; /* throw away value */ if (!ossl_quic_stream_is_bidi(qs) && local_init != is_write) { /* @@ -4442,7 +4106,7 @@ static void quic_classify_stream(QUIC_CONNECTION *qc, *app_error_code = !is_write ? qs->peer_reset_stream_aec : qs->peer_stop_sending_aec; - } else if (is_write && qs->have_final_size) { + } else if (is_write && ossl_quic_sstream_get_final_size(qs->sstream, &final_size)) { /* * Stream has been finished. Stream reset takes precedence over this for * the write case as peer may not have received all data. @@ -4661,8 +4325,9 @@ int ossl_quic_get_key_update_type(const SSL *s) * * @return Pointer to the SSL object on success, or NULL on failure. */ -static SSL *alloc_port_user_ssl(QUIC_CHANNEL *ch, QUIC_LISTENER *ql) +static SSL *alloc_port_user_ssl(QUIC_CHANNEL *ch, void *arg) { + QUIC_LISTENER *ql = arg; QUIC_CONNECTION *qc = create_qc_from_incoming_conn(ql, ch); return (qc == NULL) ? NULL : &qc->obj.ssl; @@ -4685,7 +4350,7 @@ SSL *ossl_quic_new_listener(SSL_CTX *ctx, uint64_t flags) if ((ql = OPENSSL_zalloc(sizeof(*ql))) == NULL) { QUIC_RAISE_NON_NORMAL_ERROR(NULL, ERR_R_CRYPTO_LIB, NULL); - return NULL; + goto err; } #if defined(OPENSSL_THREADS) @@ -4712,7 +4377,7 @@ SSL *ossl_quic_new_listener(SSL_CTX *ctx, uint64_t flags) port_args.channel_ctx = ctx; port_args.is_multi_conn = 1; port_args.get_conn_user_ssl = alloc_port_user_ssl; - port_args.ql = ql; + port_args.user_ssl_arg = ql; if ((flags & SSL_LISTENER_FLAG_NO_VALIDATE) == 0) port_args.do_addr_validation = 1; ql->port = ossl_quic_engine_create_port(ql->engine, &port_args); @@ -4733,8 +4398,8 @@ SSL *ossl_quic_new_listener(SSL_CTX *ctx, uint64_t flags) return &ql->obj.ssl; err: - ossl_quic_port_free(ql->port); - ossl_quic_engine_free(ql->engine); + if (ql != NULL) + ossl_quic_engine_free(ql->engine); #if defined(OPENSSL_THREADS) ossl_crypto_mutex_free(&ql->mutex); @@ -4769,7 +4434,7 @@ SSL *ossl_quic_new_listener_from(SSL *ssl, uint64_t flags) port_args.channel_ctx = ssl->ctx; port_args.is_multi_conn = 1; port_args.get_conn_user_ssl = alloc_port_user_ssl; - port_args.ql = ql; + port_args.user_ssl_arg = ql; if ((flags & SSL_LISTENER_FLAG_NO_VALIDATE) == 0) port_args.do_addr_validation = 1; ql->port = ossl_quic_engine_create_port(ctx.qd->engine, &port_args); @@ -4881,7 +4546,7 @@ SSL *ossl_quic_new_from_listener(SSL *ssl, uint64_t flags) #endif /* Create the handshake layer. */ - qc->tls = ossl_ssl_connection_new_int(ql->obj.ssl.ctx, &qc->obj.ssl, TLS_method()); + qc->tls = ossl_ssl_connection_new_int(ql->obj.ssl.ctx, NULL, TLS_method()); if (qc->tls == NULL || (sc = SSL_CONNECTION_FROM_SSL(qc->tls)) == NULL) { QUIC_RAISE_NON_NORMAL_ERROR(NULL, ERR_R_INTERNAL_ERROR, NULL); goto err; @@ -4897,16 +4562,12 @@ SSL *ossl_quic_new_from_listener(SSL *ssl, uint64_t flags) * to grab reference for qc. */ qc->ch = ossl_quic_port_create_outgoing(qc->port, qc->tls); - if (qc->ch == NULL) { - QUIC_RAISE_NON_NORMAL_ERROR(NULL, ERR_R_INTERNAL_ERROR, NULL); - goto err; - } ossl_quic_channel_set_msg_callback(qc->ch, ql->obj.ssl.ctx->msg_callback, &qc->obj.ssl); ossl_quic_channel_set_msg_callback_arg(qc->ch, ql->obj.ssl.ctx->msg_callback_arg); /* - * We deliberately pass NULL for engine and port, because we don't want + * We deliberately pass NULL for engine and port, because we don't want to * to turn QCSO we create here into an event leader, nor port leader. * Both those roles are occupied already by listener (`ssl`) we use * to create a new QCSO here. @@ -5009,21 +4670,9 @@ int ossl_quic_peeloff_conn(SSL *listener, SSL *new_conn) qc = cctx.qc; ql = lctx.ql; - /* - * Need to ensure that we take a reference on our new listener - * so that we don't free it before this connection - */ - if (!SSL_up_ref(&ql->obj.ssl)) - goto out; - ossl_quic_channel_free(qc->ch); ossl_quic_port_free(qc->port); ossl_quic_engine_free(qc->engine); - /* - * Ensure that we point to our listener so we can drop - * the above refcount when this SSL object is freed - */ - qc->listener = ql; qc->obj.engine = ql->engine; qc->engine = ql->engine; qc->port = ql->port; @@ -5075,10 +4724,9 @@ SSL *ossl_quic_accept_connection(SSL *ssl, uint64_t flags) int ret; QCTX ctx; SSL *conn_ssl = NULL; - SSL *conn_ssl_tmp = NULL; SSL_CONNECTION *conn = NULL; QUIC_CHANNEL *new_ch = NULL; - QUIC_CONNECTION *qc = NULL; + QUIC_CONNECTION *qc; int no_block = ((flags & SSL_ACCEPT_CONNECTION_NO_BLOCK) != 0); if (!expect_quic_listener(ssl, &ctx)) @@ -5125,46 +4773,22 @@ SSL *ossl_quic_accept_connection(SSL *ssl, uint64_t flags) * created channel, so once we pop the new channel from the port above * we just need to extract it */ - if (new_ch == NULL) + if (new_ch == NULL + || (conn_ssl = ossl_quic_channel_get0_tls(new_ch)) == NULL + || (conn = SSL_CONNECTION_FROM_SSL(conn_ssl)) == NULL + || (conn_ssl = SSL_CONNECTION_GET_USER_SSL(conn)) == NULL) goto out; - - /* - * All objects below must exist, because new_ch != NULL. The objects are - * bound to new_ch. If channel constructor fails to create any item here - * it just fails to create channel. - */ - if (!ossl_assert((conn_ssl_tmp = ossl_quic_channel_get0_tls(new_ch)) != NULL) - || !ossl_assert((conn = SSL_CONNECTION_FROM_SSL(conn_ssl_tmp)) != NULL) - || !ossl_assert((conn_ssl_tmp = SSL_CONNECTION_GET_USER_SSL(conn)) != NULL)) - goto out; - - qc = (QUIC_CONNECTION *)conn_ssl_tmp; - if (SSL_up_ref(&ctx.ql->obj.ssl)) { - qc->listener = ctx.ql; - conn_ssl = conn_ssl_tmp; - conn_ssl_tmp = NULL; - qc->pending = 0; + qc = (QUIC_CONNECTION *)conn_ssl; + qc->listener = ctx.ql; + qc->pending = 0; + if (!SSL_up_ref(&ctx.ql->obj.ssl)) { + SSL_free(conn_ssl); + SSL_free(ossl_quic_channel_get0_tls(new_ch)); + conn_ssl = NULL; } out: - qctx_unlock(&ctx); - /* - * You might expect ossl_quic_channel_free() to be called here. Be - * assured it happens, The process goes as follows: - * - The SSL_free() here is being handled by ossl_quic_free(). - * - The very last step of ossl_quic_free() is call to qc_cleanup() - * where channel gets freed. - * NOTE: We defer this SSL_free until after the call to qctx_unlock above - * to avoid the deadlock that would occur when ossl_quic_free attempts to - * re-acquire this mutex. We also do the gymnastics with conn_ssl and - * conn_ssl_tmp above so that we only actually do the free on the SSL - * object if the up-ref above fails, in such a way that we don't unbalance - * the listener refcount (i.e. if the up-ref fails above, we don't set the - * listener pointer so that we don't then drop the ref-count erroneously - * during the free operation. - */ - SSL_free(conn_ssl_tmp); return conn_ssl; } @@ -5191,6 +4815,7 @@ static QUIC_CONNECTION *create_qc_from_incoming_conn(QUIC_LISTENER *ql, QUIC_CHA #if defined(OPENSSL_THREADS) qc->mutex = ql->mutex; #endif + qc->tls = ossl_quic_channel_get0_tls(ch); qc->started = 1; qc->as_server = 1; qc->as_server_state = 1; @@ -5199,27 +4824,6 @@ static QUIC_CONNECTION *create_qc_from_incoming_conn(QUIC_LISTENER *ql, QUIC_CHA qc->incoming_stream_policy = SSL_INCOMING_STREAM_POLICY_AUTO; qc->last_error = SSL_ERROR_NONE; qc_update_reject_policy(qc); - - /* - * Detach the channel from the freshly-built qc before handing it back. - * - * qc->ch was set to @p ch above so the in-function initialisers - * (e.g. qc_update_reject_policy()) can reach the channel during setup. - * Once setup is done we clear it again because, at this point, the qc - * does NOT yet own the channel: @p ch is still owned by the caller of - * port_new_handshake_layer(), which only commits ownership (by setting - * qc->ch = ch on the success path) after the rest of channel - * construction has succeeded. - * - * Leaving qc->ch set here would mean any error path that does - * SSL_free(user_ssl) before the commit point cascades into - * qc_cleanup() -> ossl_quic_channel_free(qc->ch) and frees a channel - * the caller is still using -- the use-after-free / double-free class - * of bug we hit before. Resetting to NULL makes SSL_free(user_ssl) - * safe at any point until the caller explicitly hands ch over. - */ - qc->ch = NULL; - return qc; err: @@ -5405,11 +5009,6 @@ int ossl_quic_set_peer_token(SSL_CTX *ctx, BIO_ADDR *peer, ossl_quic_free_peer_token(old); } lh_QUIC_TOKEN_insert(c->cache, tok); - if (lh_QUIC_TOKEN_error(c->cache)) { - ossl_quic_free_peer_token(tok); - ossl_crypto_mutex_unlock(c->mutex); - return 0; - } ossl_crypto_mutex_unlock(c->mutex); return 1; @@ -5433,8 +5032,9 @@ int ossl_quic_get_peer_token(SSL_CTX *ctx, BIO_ADDR *peer, ossl_crypto_mutex_lock(c->mutex); tok = lh_QUIC_TOKEN_retrieve(c->cache, key); - if (tok != NULL && CRYPTO_UP_REF(&tok->references, &ret)) { + if (tok != NULL) { *token = tok; + CRYPTO_UP_REF(&tok->references, &ret); rc = 1; } @@ -5587,6 +5187,7 @@ long ossl_quic_callback_ctrl(SSL *s, int cmd, void (*fp)(void)) &ctx.qc->obj.ssl); /* This callback also needs to be set on the internal SSL object */ return ssl3_callback_ctrl(ctx.qc->tls, cmd, fp); + ; default: /* Probably a TLS related ctrl. Defer to our internal SSL object */ @@ -5609,8 +5210,6 @@ const SSL_CIPHER *ossl_quic_get_cipher_by_char(const unsigned char *p) { const SSL_CIPHER *ciph = ssl3_get_cipher_by_char(p); - if (ciph == NULL) - return NULL; if ((ciph->algorithm2 & SSL_QUIC) == 0) return NULL; diff --git a/ssl/quic/quic_lcidm.c b/ssl/quic/quic_lcidm.c index e23c16ce44..660eb802ba 100644 --- a/ssl/quic/quic_lcidm.c +++ b/ssl/quic/quic_lcidm.c @@ -74,21 +74,15 @@ static unsigned long lcid_hash(const QUIC_LCID *lcid_obj) 0, }; unsigned long hashval = 0; - unsigned char digest[SIPHASH_MIN_DIGEST_SIZE]; - /* Use a supported SipHash digest size (8 or 16); 8 is sufficient here. */ - if (!SipHash_set_hash_size(&siphash, SIPHASH_MIN_DIGEST_SIZE)) + if (!SipHash_set_hash_size(&siphash, sizeof(unsigned long))) goto out; if (!SipHash_Init(&siphash, (uint8_t *)lcid_obj->hash_key, 0, 0)) goto out; SipHash_Update(&siphash, lcid_obj->cid.id, lcid_obj->cid.id_len); - if (!SipHash_Final(&siphash, digest, SIPHASH_MIN_DIGEST_SIZE)) + if (!SipHash_Final(&siphash, (unsigned char *)&hashval, + sizeof(unsigned long))) goto out; - - /* - * Truncate the 64-bit SipHash digest into an unsigned long. - */ - memcpy(&hashval, digest, sizeof(hashval) < sizeof(digest) ? sizeof(hashval) : sizeof(digest)); out: return hashval; } diff --git a/ssl/quic/quic_port.c b/ssl/quic/quic_port.c index 9115143f52..1801ec7169 100644 --- a/ssl/quic/quic_port.c +++ b/ssl/quic/quic_port.c @@ -1,5 +1,5 @@ /* - * Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -93,14 +93,6 @@ typedef struct validation_token { */ #define ENCRYPTED_TOKEN_MAX_LEN (MARSHALLED_TOKEN_MAX_LEN + 16 + 12) -/* Arbitrary choice of default idle timeout (not an RFC value). */ -#define DEFAULT_IDLE_TIMEOUT 30000 - -#define DEFAULT_INIT_CONN_RXFC_WND (768 * 1024) -#define DEFAULT_INIT_STREAM_RXFC_WND (512 * 1024) - -#define DEFAULT_INIT_CONN_MAX_STREAMS 100 - DEFINE_LIST_OF_IMPL(ch, QUIC_CHANNEL); DEFINE_LIST_OF_IMPL(incoming_ch, QUIC_CHANNEL); DEFINE_LIST_OF_IMPL(port, QUIC_PORT); @@ -117,7 +109,7 @@ QUIC_PORT *ossl_quic_port_new(const QUIC_PORT_ARGS *args) port->is_multi_conn = args->is_multi_conn; port->validate_addr = args->do_addr_validation; port->get_conn_user_ssl = args->get_conn_user_ssl; - port->ql = args->ql; + port->user_ssl_arg = args->user_ssl_arg; if (!port_init(port)) { OPENSSL_free(port); @@ -172,33 +164,6 @@ static int port_init(QUIC_PORT *port) port->rx_short_dcid_len = (unsigned char)rx_short_dcid_len; port->tx_init_dcid_len = INIT_DCID_LEN; - - port->max_idle_timeout = DEFAULT_IDLE_TIMEOUT; - - /* - * We tell the peer we can handle at most this many bytes in a datagram payload. - * However, currently the QUIC_DEMUX in the QRX uses the BIO's MTU as upper bound - * on an incoming datagram size. - */ - port->max_udp_payload_size = QUIC_MIN_INITIAL_DGRAM_LEN; - port->init_max_data = DEFAULT_INIT_CONN_RXFC_WND; - port->init_max_stream_data_bidi_local = DEFAULT_INIT_STREAM_RXFC_WND; - port->init_max_stream_data_bidi_remote = DEFAULT_INIT_STREAM_RXFC_WND; - port->init_max_stream_data_uni = DEFAULT_INIT_STREAM_RXFC_WND; - port->init_max_streams_bidi = DEFAULT_INIT_CONN_MAX_STREAMS; - port->init_max_streams_uni = DEFAULT_INIT_CONN_MAX_STREAMS; - port->ack_delay_exponent = QUIC_DEFAULT_ACK_DELAY_EXP; - - /* - * Our maximum ACK delay on the TX side. This is up to us to choose. Note that - * this could differ from QUIC_DEFAULT_MAX_DELAY in future as that is a protocol - * value which determines the value of the maximum ACK delay if the - * max_ack_delay transport parameter is not set. - */ - port->max_ack_delay = QUIC_DEFAULT_MAX_ACK_DELAY; - port->disable_active_migration = 1; - port->active_conn_id_limit = QUIC_MIN_ACTIVE_CONN_ID_LIMIT; - port->state = QUIC_PORT_STATE_RUNNING; ossl_list_port_insert_tail(&port->engine->port_list, port); @@ -492,41 +457,7 @@ SSL_CTX *ossl_quic_port_get_channel_ctx(QUIC_PORT *port) * ============================ */ -/** - * @brief Create the inner TLS handshake layer for a QUIC channel. - * - * After a successful return: - * - @c *user_sslp holds the user_ssl. The caller is expected to also - * stash the returned @c tls in @c ch->tls so the channel can find its - * inner TLS. - * - @c qc->tls and @c qc->ch are both set, so a single - * @c SSL_free(user_ssl) cascades through @c ossl_quic_free() -> - * @c qc_cleanup() to free the inner TLS and the channel together. - * - * Failure semantics (returns @c NULL) - * ----------------------------------- - * - If the callback never returned a user_ssl (callback missing or it - * returned @c NULL), nothing was allocated; @c *user_sslp is left - * untouched and stays whatever the caller initialised it to. - * - Otherwise, this function frees what it allocated and resets - * @c *user_sslp to @c NULL before returning. The caller retains ownership - * of @c ch on failure. - * - * @param port Port supplying the channel @c SSL_CTX and the - * @c get_conn_user_ssl callback. - * @param ch Channel that the new handshake layer is being attached - * to. Borrowed; on success the channel is shared with - * user_ssl via @c qc->ch. - * @param user_sslp In/out parameter. On success, set to the user_ssl - * so the caller can later free the whole graph with - * @c SSL_free(*user_sslp). On failure, set to @c NULL - * if the function actually obtained and freed a - * user_ssl; otherwise left untouched. - * - * @return The inner TLS @c SSL_CONNECTION (also stored as @c qc->tls) - * on success, or @c NULL on failure. - */ -static SSL *port_new_handshake_layer(QUIC_PORT *port, QUIC_CHANNEL *ch, SSL **user_sslp) +static SSL *port_new_handshake_layer(QUIC_PORT *port, QUIC_CHANNEL *ch) { SSL *tls = NULL; SSL_CONNECTION *tls_conn = NULL; @@ -540,30 +471,34 @@ static SSL *port_new_handshake_layer(QUIC_PORT *port, QUIC_CHANNEL *ch, SSL **us */ if (!ossl_assert(port->get_conn_user_ssl != NULL)) return NULL; - user_ssl = port->get_conn_user_ssl(ch, port->ql); + user_ssl = port->get_conn_user_ssl(ch, port->user_ssl_arg); if (user_ssl == NULL) return NULL; qc = (QUIC_CONNECTION *)user_ssl; - ql = port->ql; + ql = (QUIC_LISTENER *)port->user_ssl_arg; /* * We expect the user_ssl to be newly created so it must not have an * existing qc->tls */ - if (!ossl_assert(qc->tls == NULL)) - goto err; + if (!ossl_assert(qc->tls == NULL)) { + SSL_free(user_ssl); + return NULL; + } tls = ossl_ssl_connection_new_int(port->channel_ctx, user_ssl, TLS_method()); - if (tls == NULL || (tls_conn = SSL_CONNECTION_FROM_SSL(tls)) == NULL) - goto err; + qc->tls = tls; + if (tls == NULL || (tls_conn = SSL_CONNECTION_FROM_SSL(tls)) == NULL) { + SSL_free(user_ssl); + return NULL; + } if (ql != NULL && ql->obj.ssl.ctx->new_pending_conn_cb != NULL) if (!ql->obj.ssl.ctx->new_pending_conn_cb(ql->obj.ssl.ctx, user_ssl, - ql->obj.ssl.ctx->new_pending_conn_arg)) - goto err; - qc->tls = tls; - qc->ch = ch; - *user_sslp = user_ssl; + ql->obj.ssl.ctx->new_pending_conn_arg)) { + SSL_free(user_ssl); + return NULL; + } /* Override the user_ssl of the inner connection. */ tls_conn->s3.flags |= TLS1_FLAGS_QUIC | TLS1_FLAGS_QUIC_INTERNAL; @@ -571,15 +506,7 @@ static SSL *port_new_handshake_layer(QUIC_PORT *port, QUIC_CHANNEL *ch, SSL **us /* Restrict options derived from the SSL_CTX. */ tls_conn->options &= OSSL_QUIC_PERMITTED_OPTIONS_CONN; tls_conn->pha_enabled = 0; - - return qc->tls; - -err: - SSL_free(tls); - SSL_free(user_ssl); - *user_sslp = NULL; - - return NULL; + return tls; } static QUIC_CHANNEL *port_make_channel(QUIC_PORT *port, SSL *tls, OSSL_QRX *qrx, @@ -587,7 +514,6 @@ static QUIC_CHANNEL *port_make_channel(QUIC_PORT *port, SSL *tls, OSSL_QRX *qrx, { QUIC_CHANNEL_ARGS args = { 0 }; QUIC_CHANNEL *ch; - SSL *user_ssl = NULL; args.port = port; args.is_server = is_server; @@ -596,19 +522,6 @@ static QUIC_CHANNEL *port_make_channel(QUIC_PORT *port, SSL *tls, OSSL_QRX *qrx, args.qrx = qrx; args.is_tserver_ch = is_tserver; - args.max_idle_timeout = port->max_idle_timeout; - args.max_udp_payload_size = port->max_udp_payload_size; - args.init_max_data = port->init_max_data; - args.init_max_stream_data_bidi_local = port->init_max_stream_data_bidi_local; - args.init_max_stream_data_bidi_remote = port->init_max_stream_data_bidi_remote; - args.init_max_stream_data_uni = port->init_max_stream_data_uni; - args.init_max_streams_bidi = port->init_max_streams_bidi; - args.init_max_streams_uni = port->init_max_streams_uni; - args.ack_delay_exponent = port->ack_delay_exponent; - args.max_ack_delay = port->max_ack_delay; - args.disable_active_migration = port->disable_active_migration; - args.active_conn_id_limit = port->active_conn_id_limit; - /* * Creating a new channel is made a bit tricky here as there is a * bit of a circular dependency. Initializing a channel requires that @@ -631,10 +544,11 @@ static QUIC_CHANNEL *port_make_channel(QUIC_PORT *port, SSL *tls, OSSL_QRX *qrx, /* * We're using the normal SSL_accept_connection_path */ - tls = port_new_handshake_layer(port, ch, &user_ssl); - if (tls == NULL) - goto err; - ch->tls = tls; + ch->tls = port_new_handshake_layer(port, ch); + if (ch->tls == NULL) { + ossl_quic_channel_free(ch); + return NULL; + } } else { /* * We're deferring user ssl creation until SSL_listen_ex is called @@ -648,29 +562,23 @@ static QUIC_CHANNEL *port_make_channel(QUIC_PORT *port, SSL *tls, OSSL_QRX *qrx, */ ch->use_qlog = 1; if (ch->tls != NULL && ch->tls->ctx->qlog_title != NULL) { - OPENSSL_free(ch->qlog_title); - if ((ch->qlog_title = OPENSSL_strdup(ch->tls->ctx->qlog_title)) == NULL) - goto err; + if ((ch->qlog_title = OPENSSL_strdup(ch->tls->ctx->qlog_title)) == NULL) { + OPENSSL_free(ch); + return NULL; + } } #endif /* * And finally init the channel struct */ - if (!ossl_quic_channel_init(ch)) - goto err; + if (!ossl_quic_channel_init(ch)) { + OPENSSL_free(ch); + return NULL; + } ossl_qtx_set_bio(ch->qtx, port->net_wbio); return ch; - -err: - if (user_ssl != NULL) - ((QUIC_CONNECTION *)user_ssl)->ch = NULL; - - ossl_quic_channel_free(ch); - SSL_free(user_ssl); - - return NULL; } QUIC_CHANNEL *ossl_quic_port_create_outgoing(QUIC_PORT *port, SSL *tls) @@ -854,7 +762,7 @@ static void port_rx_pre(QUIC_PORT *port) * to *new_ch. */ static void port_bind_channel(QUIC_PORT *port, const BIO_ADDR *peer, - const QUIC_CONN_ID *dcid, + const QUIC_CONN_ID *scid, const QUIC_CONN_ID *dcid, const QUIC_CONN_ID *odcid, OSSL_QRX *qrx, QUIC_CHANNEL **new_ch) { @@ -894,10 +802,8 @@ static void port_bind_channel(QUIC_PORT *port, const BIO_ADDR *peer, if (!ossl_quic_provide_initial_secret(ch->port->engine->libctx, ch->port->engine->propq, dcid, /* is_server */ 1, - ch->qrx, NULL)) { - ossl_quic_channel_free(ch); + ch->qrx, NULL)) return; - } if (odcid->id_len != 0) { /* @@ -906,7 +812,7 @@ static void port_bind_channel(QUIC_PORT *port, const BIO_ADDR *peer, * See RFC 9000 s. 8.1 */ ossl_quic_tx_packetiser_set_validated(ch->txp); - if (!ossl_quic_bind_channel(ch, peer, dcid, odcid)) { + if (!ossl_quic_bind_channel(ch, peer, scid, dcid, odcid)) { ossl_quic_channel_free(ch); return; } @@ -915,7 +821,7 @@ static void port_bind_channel(QUIC_PORT *port, const BIO_ADDR *peer, * No odcid means we didn't do server validation, so we need to * generate a cid via ossl_quic_channel_on_new_conn */ - if (!ossl_quic_channel_on_new_conn(ch, peer, dcid)) { + if (!ossl_quic_channel_on_new_conn(ch, peer, scid, dcid)) { ossl_quic_channel_free(ch); return; } @@ -959,7 +865,7 @@ static int port_try_handle_stateless_reset(QUIC_PORT *port, const QUIC_URXE *e) for (i = 0;; ++i) { if (!ossl_quic_srtm_lookup(port->srtm, - (const QUIC_STATELESS_RESET_TOKEN *)(data + e->data_len + (QUIC_STATELESS_RESET_TOKEN *)(data + e->data_len - sizeof(QUIC_STATELESS_RESET_TOKEN)), i, &opaque, NULL)) break; @@ -1136,7 +1042,7 @@ static int decrypt_validation_token(const QUIC_PORT *port, goto err; /* Prevent decryption of a buffer that is not within reasonable bounds */ - if (ct_len < (size_t)iv_len + tag_len || ct_len > ENCRYPTED_TOKEN_MAX_LEN) + if (ct_len < (size_t)(iv_len + tag_len) || ct_len > ENCRYPTED_TOKEN_MAX_LEN) goto err; *pt_len = ct_len - iv_len - tag_len; @@ -1462,7 +1368,8 @@ static void port_send_version_negotiation(QUIC_PORT *port, BIO_ADDR *peer, * configurable in the future. */ static int port_validate_token(QUIC_PKT_HDR *hdr, QUIC_PORT *port, - BIO_ADDR *peer, QUIC_CONN_ID *odcid, uint8_t *gen_new_token) + BIO_ADDR *peer, QUIC_CONN_ID *odcid, + QUIC_CONN_ID *scid, uint8_t *gen_new_token) { int ret = 0; QUIC_VALIDATION_TOKEN token = { 0 }; @@ -1522,9 +1429,11 @@ static int port_validate_token(QUIC_PKT_HDR *hdr, QUIC_PORT *port, != 0) goto err; *odcid = token.odcid; + *scid = token.rscid; } else { if (!ossl_quic_lcidm_get_unused_cid(port->lcidm, odcid)) goto err; + *scid = hdr->src_conn_id; } /* @@ -1613,7 +1522,7 @@ static void port_default_packet_handler(QUIC_URXE *e, void *arg, PACKET pkt; QUIC_PKT_HDR hdr; QUIC_CHANNEL *ch = NULL, *new_ch = NULL; - QUIC_CONN_ID odcid; + QUIC_CONN_ID odcid, scid; uint8_t gen_new_token = 0; OSSL_QRX *qrx = NULL; OSSL_QRX *qrx_src = NULL; @@ -1643,13 +1552,6 @@ static void port_default_packet_handler(QUIC_URXE *e, void *arg, if (!port->allow_incoming) goto undesirable; - /* - * packet without destination connection id is invalid/corrupted here. - * stop wasting CPU cycles now. - */ - if (dcid == NULL) - goto undesirable; - /* * We have got a packet for an unknown DCID. This might be an attempt to * open a new connection. @@ -1770,7 +1672,8 @@ static void port_default_packet_handler(QUIC_URXE *e, void *arg, */ if (hdr.token != NULL && port_validate_token(&hdr, port, &e->peer, - &odcid, &gen_new_token) + &odcid, &scid, + &gen_new_token) == 0) { /* * RFC 9000 s 8.1.3 @@ -1799,13 +1702,11 @@ static void port_default_packet_handler(QUIC_URXE *e, void *arg, * forget qrx so channel can create a new one * with valid initial encryption level keys. */ - if (qrx != NULL) { - qrx_src = qrx; - qrx = NULL; - } + qrx_src = qrx; + qrx = NULL; } - port_bind_channel(port, &e->peer, &hdr.dst_conn_id, + port_bind_channel(port, &e->peer, &scid, &hdr.dst_conn_id, &odcid, qrx, &new_ch); /* @@ -1887,107 +1788,3 @@ void ossl_quic_port_restore_err_state(const QUIC_PORT *port) ERR_clear_error(); OSSL_ERR_STATE_restore(port->err_state); } - -void ossl_quic_port_set_max_idle_timeout(QUIC_PORT *port, uint64_t ms) -{ - port->max_idle_timeout = ms; -} - -uint64_t ossl_quic_port_get_max_idle_timeout(const QUIC_PORT *port) -{ - return port->max_idle_timeout; -} - -void ossl_quic_port_set_max_udp_payload_size(QUIC_PORT *port, uint64_t size) -{ - port->max_udp_payload_size = size; -} - -uint64_t ossl_quic_port_get_max_udp_payload_size(const QUIC_PORT *port) -{ - return port->max_udp_payload_size; -} - -void ossl_quic_port_set_init_max_data(QUIC_PORT *port, uint64_t max_data) -{ - port->init_max_data = max_data; -} - -uint64_t ossl_quic_port_get_init_max_data(const QUIC_PORT *port) -{ - return port->init_max_data; -} - -void ossl_quic_port_set_init_max_stream_data(QUIC_PORT *port, uint64_t max_data, int is_uni, int is_remote) -{ - if (is_uni) { - port->init_max_stream_data_uni = max_data; - } else { - if (is_remote) - port->init_max_stream_data_bidi_remote = max_data; - else - port->init_max_stream_data_bidi_local = max_data; - } -} - -uint64_t ossl_quic_port_get_init_max_stream_data(const QUIC_PORT *port, int is_uni, int is_remote) -{ - if (is_uni) - return port->init_max_stream_data_uni; - else - return is_remote ? port->init_max_stream_data_bidi_remote : port->init_max_stream_data_bidi_local; -} - -void ossl_quic_port_set_init_max_streams(QUIC_PORT *port, uint64_t max_streams, int is_uni) -{ - if (is_uni) { - port->init_max_streams_uni = max_streams; - } else { - port->init_max_streams_bidi = max_streams; - } -} - -uint64_t ossl_quic_port_get_init_max_streams(const QUIC_PORT *port, int is_uni) -{ - return is_uni ? port->init_max_streams_uni : port->init_max_streams_bidi; -} - -void ossl_quic_port_set_ack_delay_exponent(QUIC_PORT *port, uint64_t exp) -{ - port->ack_delay_exponent = (unsigned char)exp; -} - -uint64_t ossl_quic_port_get_ack_delay_exponent(const QUIC_PORT *port) -{ - return port->ack_delay_exponent; -} - -void ossl_quic_port_set_max_ack_delay(QUIC_PORT *port, uint64_t ms) -{ - port->max_ack_delay = ms; -} - -uint64_t ossl_quic_port_get_max_ack_delay(const QUIC_PORT *port) -{ - return port->max_ack_delay; -} - -void ossl_quic_port_set_disable_active_migration(QUIC_PORT *port, uint64_t disable) -{ - port->disable_active_migration = (unsigned char)disable; -} - -uint64_t ossl_quic_port_get_disable_active_migration(const QUIC_PORT *port) -{ - return port->disable_active_migration; -} - -void ossl_quic_port_set_active_conn_id_limit(QUIC_PORT *port, uint64_t limit) -{ - port->active_conn_id_limit = limit; -} - -uint64_t ossl_quic_port_get_active_conn_id_limit(const QUIC_PORT *port) -{ - return port->active_conn_id_limit; -} diff --git a/ssl/quic/quic_port_local.h b/ssl/quic/quic_port_local.h index c096210863..521d9b0fe3 100644 --- a/ssl/quic/quic_port_local.h +++ b/ssl/quic/quic_port_local.h @@ -1,5 +1,5 @@ /* - * Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -51,8 +51,8 @@ struct quic_port_st { */ OSSL_LIST_MEMBER(port, QUIC_PORT); - SSL *(*get_conn_user_ssl)(QUIC_CHANNEL *ch, QUIC_LISTENER *ql); - QUIC_LISTENER *ql; + SSL *(*get_conn_user_ssl)(QUIC_CHANNEL *ch, void *arg); + void *user_ssl_arg; /* Used to create handshake layer objects inside newly created channels. */ SSL_CTX *channel_ctx; @@ -121,20 +121,6 @@ struct quic_port_st { /* AES-256 GCM context for token encryption */ EVP_CIPHER_CTX *token_ctx; - - /* Transport parameter values for the port. */ - uint64_t max_idle_timeout; - uint64_t max_udp_payload_size; - uint64_t init_max_data; - uint64_t init_max_stream_data_bidi_local; - uint64_t init_max_stream_data_bidi_remote; - uint64_t init_max_stream_data_uni; - uint64_t init_max_streams_bidi; - uint64_t init_max_streams_uni; - uint64_t max_ack_delay; - uint64_t active_conn_id_limit; - unsigned char ack_delay_exponent; - unsigned char disable_active_migration; }; #endif diff --git a/ssl/quic/quic_rcidm.c b/ssl/quic/quic_rcidm.c index 9a92ec6e35..0d5cb0337b 100644 --- a/ssl/quic/quic_rcidm.c +++ b/ssl/quic/quic_rcidm.c @@ -270,11 +270,8 @@ static void rcidm_check_rcid(QUIC_RCIDM *rcidm, RCID *rcid) assert(rcid->state != RCID_STATE_RETIRING || rcidm->num_retiring > 0); } -static int rcid_cmp(const void *av, const void *bv) +static int rcid_cmp(const RCID *a, const RCID *b) { - const RCID *a = av; - const RCID *b = bv; - if (a->seq_num < b->seq_num) return -1; if (a->seq_num > b->seq_num) diff --git a/ssl/quic/quic_reactor.c b/ssl/quic/quic_reactor.c index c30bc3c595..f54fbcdd96 100644 --- a/ssl/quic/quic_reactor.c +++ b/ssl/quic/quic_reactor.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -11,12 +11,6 @@ #include "internal/thread_arch.h" #include -#if defined(OPENSSL_SYS_WINDOWS) -#include -#include -#include -#endif - /* * Core I/O Reactor Framework * ========================== @@ -75,34 +69,6 @@ void ossl_quic_reactor_cleanup(QUIC_REACTOR *rtor) } } -#if defined(OPENSSL_SYS_WINDOWS) - -/* Work around for MinGW builds. */ -#if defined(__MINGW32__) && !defined(SIO_UDP_NETRESET) -#define SIO_UDP_NETRESET _WSAIOW(IOC_VENDOR, 15) -#endif - -/* - * On Windows recvfrom() may return WSAECONNRESET when destination port - * used in preceding call to sendto() is no longer reachable. The reset - * error received from UDP socket takes the whole port down. This behavior - * must be suppressed for QUIC protocol so QUIC applications may rely on - * QUIC protocol itself to detect network failures. - */ -static void rtor_configure_winsock(BIO_POLL_DESCRIPTOR *bpd) -{ - BOOL bNewBehavior = FALSE; - DWORD dwBytesReturned = 0; - - if (bpd->type == BIO_POLL_DESCRIPTOR_TYPE_SOCK_FD) { - WSAIoctl(bpd->value.fd, SIO_UDP_CONNRESET, &bNewBehavior, - sizeof(bNewBehavior), NULL, 0, &dwBytesReturned, NULL, NULL); - WSAIoctl(bpd->value.fd, SIO_UDP_NETRESET, &bNewBehavior, - sizeof(bNewBehavior), NULL, 0, &dwBytesReturned, NULL, NULL); - } -} -#endif - void ossl_quic_reactor_set_poll_r(QUIC_REACTOR *rtor, const BIO_POLL_DESCRIPTOR *r) { if (r == NULL) @@ -110,10 +76,6 @@ void ossl_quic_reactor_set_poll_r(QUIC_REACTOR *rtor, const BIO_POLL_DESCRIPTOR else rtor->poll_r = *r; -#if defined(OPENSSL_SYS_WINDOWS) - rtor_configure_winsock(&rtor->poll_r); -#endif - rtor->can_poll_r = ossl_quic_reactor_can_support_poll_descriptor(rtor, &rtor->poll_r); } @@ -125,10 +87,6 @@ void ossl_quic_reactor_set_poll_w(QUIC_REACTOR *rtor, const BIO_POLL_DESCRIPTOR else rtor->poll_w = *w; -#if defined(OPENSSL_SYS_WINDOWS) - rtor_configure_winsock(&rtor->poll_w); -#endif - rtor->can_poll_w = ossl_quic_reactor_can_support_poll_descriptor(rtor, &rtor->poll_w); } diff --git a/ssl/quic/quic_record_rx.c b/ssl/quic/quic_record_rx.c index 868650a612..0de2d8c9a2 100644 --- a/ssl/quic/quic_record_rx.c +++ b/ssl/quic/quic_record_rx.c @@ -1031,13 +1031,7 @@ static int qrx_process_pkt(OSSL_QRX *qrx, QUIC_URXE *urxe, */ rxe = qrx_ensure_free_rxe(qrx, PACKET_remaining(pkt)); if (rxe == NULL) - /* - * Allocation failure, treat as malformed as we cannot process this - * packet. The header has not been read yet so we do not know the - * packet size and cannot skip just this packet, so we drop the rest of - * the datagram instead. - */ - goto malformed; + return 0; /* Have we already processed this packet? */ if (pkt_is_marked(&urxe->processed, pkt_idx)) diff --git a/ssl/quic/quic_record_shared.c b/ssl/quic/quic_record_shared.c index 05d4d00b13..29accf602e 100644 --- a/ssl/quic/quic_record_shared.c +++ b/ssl/quic/quic_record_shared.c @@ -87,6 +87,9 @@ static void el_teardown_keyslot(OSSL_QRL_ENC_LEVEL_SET *els, { OSSL_QRL_ENC_LEVEL *el = ossl_qrl_enc_level_set_get(els, enc_level, 0); + if (!ossl_qrl_enc_level_set_has_keyslot(els, enc_level, el->state, keyslot)) + return; + if (el->cctx[keyslot] != NULL) { EVP_CIPHER_CTX_free(el->cctx[keyslot]); el->cctx[keyslot] = NULL; @@ -95,18 +98,26 @@ static void el_teardown_keyslot(OSSL_QRL_ENC_LEVEL_SET *els, OPENSSL_cleanse(el->iv[keyslot], sizeof(el->iv[keyslot])); } -static int el_build_keyslot(OSSL_QRL_ENC_LEVEL *el, - const unsigned char *secret, size_t secret_len, - EVP_CIPHER_CTX **out_cctx, unsigned char *out_iv, size_t *out_iv_len) +static int el_setup_keyslot(OSSL_QRL_ENC_LEVEL_SET *els, + uint32_t enc_level, + unsigned char tgt_state, + size_t keyslot, + const unsigned char *secret, + size_t secret_len) { + OSSL_QRL_ENC_LEVEL *el = ossl_qrl_enc_level_set_get(els, enc_level, 0); unsigned char key[EVP_MAX_KEY_LENGTH]; size_t key_len = 0, iv_len = 0; const char *cipher_name = NULL; EVP_CIPHER *cipher = NULL; EVP_CIPHER_CTX *cctx = NULL; - *out_cctx = NULL; - *out_iv_len = 0; + if (!ossl_assert(el != NULL + && ossl_qrl_enc_level_set_has_keyslot(els, enc_level, + tgt_state, keyslot))) { + ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); + return 0; + } cipher_name = ossl_qrl_get_suite_cipher_name(el->suite_id); iv_len = ossl_qrl_get_suite_cipher_iv_len(el->suite_id); @@ -122,15 +133,25 @@ static int el_build_keyslot(OSSL_QRL_ENC_LEVEL *el, return 0; } - /* Derive "quic iv" into caller's buffer. */ - if (!tls13_hkdf_expand_ex(el->libctx, el->propq, el->md, secret, - quic_v1_iv_label, sizeof(quic_v1_iv_label), NULL, 0, - out_iv, iv_len, 1)) + assert(el->cctx[keyslot] == NULL); + + /* Derive "quic iv" key. */ + if (!tls13_hkdf_expand_ex(el->libctx, el->propq, + el->md, + secret, + quic_v1_iv_label, + sizeof(quic_v1_iv_label), + NULL, 0, + el->iv[keyslot], iv_len, 1)) goto err; - /* Derive "quic key" into local. */ - if (!tls13_hkdf_expand_ex(el->libctx, el->propq, el->md, secret, - quic_v1_key_label, sizeof(quic_v1_key_label), NULL, 0, + /* Derive "quic key" key. */ + if (!tls13_hkdf_expand_ex(el->libctx, el->propq, + el->md, + secret, + quic_v1_key_label, + sizeof(quic_v1_key_label), + NULL, 0, key, key_len, 1)) goto err; @@ -152,13 +173,12 @@ static int el_build_keyslot(OSSL_QRL_ENC_LEVEL *el, } /* IV will be changed on RX/TX so we don't need to use a real value here. */ - if (!EVP_CipherInit_ex(cctx, cipher, NULL, key, out_iv, 0)) { + if (!EVP_CipherInit_ex(cctx, cipher, NULL, key, el->iv[keyslot], 0)) { ERR_raise(ERR_LIB_SSL, ERR_R_EVP_LIB); goto err; } - *out_cctx = cctx; - *out_iv_len = iv_len; + el->cctx[keyslot] = cctx; /* Zeroize intermediate keys. */ OPENSSL_cleanse(key, sizeof(key)); @@ -168,47 +188,11 @@ static int el_build_keyslot(OSSL_QRL_ENC_LEVEL *el, err: EVP_CIPHER_CTX_free(cctx); EVP_CIPHER_free(cipher); + OPENSSL_cleanse(el->iv[keyslot], sizeof(el->iv[keyslot])); OPENSSL_cleanse(key, sizeof(key)); - OPENSSL_cleanse(out_iv, iv_len); return 0; } -static void el_install_keyslot(OSSL_QRL_ENC_LEVEL *el, size_t keyslot, - EVP_CIPHER_CTX *new_cctx, const unsigned char *new_iv, size_t new_iv_len) -{ - assert(el->cctx[keyslot] == NULL); - assert(new_iv_len <= sizeof(el->iv[keyslot])); - - el->cctx[keyslot] = new_cctx; - memcpy(el->iv[keyslot], new_iv, new_iv_len); -} - -static int el_setup_keyslot(OSSL_QRL_ENC_LEVEL_SET *els, uint32_t enc_level, - unsigned char tgt_state, size_t keyslot, const unsigned char *secret, - size_t secret_len) -{ - OSSL_QRL_ENC_LEVEL *el = ossl_qrl_enc_level_set_get(els, enc_level, 0); - EVP_CIPHER_CTX *new_cctx = NULL; - unsigned char new_iv[EVP_MAX_IV_LENGTH]; - size_t new_iv_len = EVP_MAX_IV_LENGTH; - - if (!ossl_assert(el != NULL - && ossl_qrl_enc_level_set_has_keyslot(els, enc_level, - tgt_state, keyslot))) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - - if (!el_build_keyslot(el, secret, secret_len, &new_cctx, new_iv, - &new_iv_len)) - return 0; - - el_install_keyslot(el, keyslot, new_cctx, new_iv, new_iv_len); - - OPENSSL_cleanse(new_iv, sizeof(new_iv)); - return 1; -} - int ossl_qrl_enc_level_set_provide_secret(OSSL_QRL_ENC_LEVEL_SET *els, OSSL_LIB_CTX *libctx, const char *propq, @@ -362,9 +346,6 @@ int ossl_qrl_enc_level_set_key_update(OSSL_QRL_ENC_LEVEL_SET *els, uint32_t enc_level) { OSSL_QRL_ENC_LEVEL *el = ossl_qrl_enc_level_set_get(els, enc_level, 0); - EVP_CIPHER_CTX *new_cctx = NULL; - unsigned char new_iv[EVP_MAX_IV_LENGTH]; - size_t new_iv_len = EVP_MAX_IV_LENGTH; size_t secret_len; unsigned char new_ku[EVP_MAX_KEY_LENGTH]; @@ -402,14 +383,12 @@ int ossl_qrl_enc_level_set_key_update(OSSL_QRL_ENC_LEVEL_SET *els, new_ku, secret_len, 1)) return 0; - /* Build new keyslot first so if it fails, teardown is not done. */ - if (!el_build_keyslot(el, el->ku, secret_len, &new_cctx, new_iv, - &new_iv_len)) - return 0; - el_teardown_keyslot(els, enc_level, 0); - el_install_keyslot(el, 0, new_cctx, new_iv, new_iv_len); - OPENSSL_cleanse(new_iv, sizeof(new_iv)); + + /* Setup keyslot for CURRENT "quic ku" key. */ + if (!el_setup_keyslot(els, enc_level, QRL_EL_STATE_PROV_NORMAL, + 0, el->ku, secret_len)) + return 0; ++el->key_epoch; el->op_count = 0; diff --git a/ssl/quic/quic_record_tx.c b/ssl/quic/quic_record_tx.c index f5bd5b2f83..b8058f900a 100644 --- a/ssl/quic/quic_record_tx.c +++ b/ssl/quic/quic_record_tx.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -15,8 +15,6 @@ #include "internal/list.h" #include "../ssl_local.h" -#define QTX_DEFAULT_MTU 1500 - /* * TXE * === @@ -70,12 +68,6 @@ struct ossl_qtx_st { /* TX maximum datagram payload length. */ size_t mdpl; - /* - * Our current understanding of the upper bound on an outgoing datagram size - * in bytes. - */ - size_t mtu; - /* * List of TXEs which are not currently in use. These are moved to the * pending list (possibly via tx_cons first) as they are filled. @@ -133,8 +125,6 @@ OSSL_QTX *ossl_qtx_new(const OSSL_QTX_ARGS *args) qtx->propq = args->propq; qtx->bio = args->bio; qtx->mdpl = args->mdpl; - /* We update this if possible when we get a BIO. */ - qtx->mtu = QTX_DEFAULT_MTU; qtx->get_qlog_cb = args->get_qlog_cb; qtx->get_qlog_cb_arg = args->get_qlog_cb_arg; @@ -242,49 +232,84 @@ static TXE *qtx_alloc_txe(size_t alloc_len) } /* - * Ensure that qtx->cons has a TXE attached with allocated size of at least - * min_size. Returns pointer to the TXE on success or NULL on failure. + * Ensures there is at least one TXE in the free list, allocating a new entry + * if necessary. The returned TXE is in the free list; it is not popped. + * + * alloc_len is a hint which may be used to determine the TXE size if allocation + * is necessary. Returns NULL on allocation failure. */ -static TXE *qtx_get_cons_txe(OSSL_QTX *qtx, size_t min_size) +static TXE *qtx_ensure_free_txe(OSSL_QTX *qtx, size_t alloc_len) { - if (min_size >= SIZE_MAX - sizeof(TXE)) + TXE *txe; + + txe = ossl_list_txe_head(&qtx->free); + if (txe != NULL) + return txe; + + txe = qtx_alloc_txe(alloc_len); + if (txe == NULL) return NULL; + ossl_list_txe_insert_tail(&qtx->free, txe); + return txe; +} + +/* + * Resize the data buffer attached to an TXE to be n bytes in size. The address + * of the TXE might change; the new address is returned, or NULL on failure, in + * which case the original TXE remains valid. + */ +static TXE *qtx_resize_txe(OSSL_QTX *qtx, TXE_LIST *txl, TXE *txe, size_t n) +{ + TXE *txe2, *p; + + /* Should never happen. */ + if (txe == NULL) + return NULL; + + if (n >= SIZE_MAX - sizeof(TXE)) + return NULL; + + /* Remove the item from the list to avoid accessing freed memory */ + p = ossl_list_txe_prev(txe); + ossl_list_txe_remove(txl, txe); + /* - * If there is no coalescing in progress, try to get a TXE - * from the free list (and remove it from there), or allocate a new one. + * NOTE: We do not clear old memory, although it does contain decrypted + * data. */ - if (qtx->cons == NULL) { - TXE *txe = ossl_list_txe_head(&qtx->free); - - if (txe != NULL) { - ossl_list_txe_remove(&qtx->free, txe); - } else { - if ((txe = qtx_alloc_txe(min_size)) == NULL) - return NULL; - } - - txe->data_len = 0; - qtx->cons = txe; - qtx->cons_count = 0; + txe2 = OPENSSL_realloc(txe, sizeof(TXE) + n); + if (txe2 == NULL) { + if (p == NULL) + ossl_list_txe_insert_head(txl, txe); + else + ossl_list_txe_insert_after(txl, p, txe); + return NULL; } - /* Resize TXE if it's too small. */ - if (qtx->cons->alloc_len < min_size) { - /* - * NOTE: We do not clear old memory, although it does contain decrypted - * data. - */ - TXE *realloc_txe = OPENSSL_realloc(qtx->cons, sizeof(TXE) + min_size); + if (p == NULL) + ossl_list_txe_insert_head(txl, txe2); + else + ossl_list_txe_insert_after(txl, p, txe2); - if (realloc_txe == NULL) - return NULL; + if (qtx->cons == txe) + qtx->cons = txe2; - realloc_txe->alloc_len = min_size; - qtx->cons = realloc_txe; - } + txe2->alloc_len = n; + return txe2; +} - return qtx->cons; +/* + * Ensure the data buffer attached to an TXE is at least n bytes in size. + * Returns NULL on failure. + */ +static TXE *qtx_reserve_txe(OSSL_QTX *qtx, TXE_LIST *txl, + TXE *txe, size_t n) +{ + if (txe->alloc_len >= n) + return txe; + + return qtx_resize_txe(qtx, txl, txe, n); } /* Move a TXE from pending to free. */ @@ -702,6 +727,24 @@ err: return ret; } +static TXE *qtx_ensure_cons(OSSL_QTX *qtx) +{ + TXE *txe = qtx->cons; + + if (txe != NULL) + return txe; + + txe = qtx_ensure_free_txe(qtx, qtx->mdpl); + if (txe == NULL) + return NULL; + + ossl_list_txe_remove(&qtx->free, txe); + qtx->cons = txe; + qtx->cons_count = 0; + txe->data_len = 0; + return txe; +} + static QLOG *qtx_get_qlog(OSSL_QTX *qtx) { if (qtx->get_qlog_cb == NULL) @@ -787,31 +830,17 @@ int ossl_qtx_write_pkt(OSSL_QTX *qtx, const OSSL_QTX_PKT *pkt) * serialize/encrypt the packet. We always encrypt packets as soon as * our caller gives them to us, which relieves the caller of any need to * keep the plaintext around. - * - * the txe can have three distinct states: - * - attached to free list - * - attached to tx list - * - detached. - * - * if txe is detached (not member of free/tx list), then it is kept - * in qtx->cons. The qtx_get_cons_txe() here makes sure that qtx->cons - * points at a (new or existing) detached txe and has at least MDPL - * bytes allocated. */ - txe = qtx_get_cons_txe(qtx, qtx->mdpl); - if (txe == NULL) { - /* - * If realloc of txe has failed. it is still kept in ->cons, - * no memory leak. - * The question is what we should do here to handle error, - * is doing `return 0` enough? or shall we discard ->cons and - * put it back to free list? - * or just stop coalescing the packet and dispatch it to network - * right now so the next packet tx can start from fresh? - * I think this is the problem for another day. - */ + txe = qtx_ensure_cons(qtx); + if (txe == NULL) + return 0; /* allocation failure */ + + /* + * Ensure TXE has at least MDPL bytes allocated. This should only be + * possible if the MDPL has increased. + */ + if (!qtx_reserve_txe(qtx, NULL, txe, qtx->mdpl)) return 0; - } if (!was_coalescing) { /* Set addresses in TXE. */ @@ -838,11 +867,6 @@ int ossl_qtx_write_pkt(OSSL_QTX *qtx, const OSSL_QTX_PKT *pkt) /* * We failed due to insufficient length, so end the current * datagram and try again. - * - * the ossl_qtx_finish_dgram() also puts the txe (-.cons) to - * tx list, so ->cons becomes attached again. The function also - * sets ->cons to NULL so the next loop iteration starts with - * fresh txe (which is also safe to resize). */ ossl_qtx_finish_dgram(qtx); was_coalescing = 0; @@ -994,40 +1018,15 @@ int ossl_qtx_pop_net(OSSL_QTX *qtx, BIO_MSG *msg) void ossl_qtx_set_bio(OSSL_QTX *qtx, BIO *bio) { - unsigned int mtu; - qtx->bio = bio; - - if (bio != NULL) { - /* - * Try to determine our MTU if possible. The BIO is not required to - * support this, in which case we remain at the last known MTU, or our - * initial default. - */ - mtu = BIO_dgram_get_mtu(bio); - if (mtu >= QUIC_MIN_INITIAL_DGRAM_LEN) - ossl_qtx_set_mtu(qtx, mtu); /* best effort */ - } -} - -int ossl_qtx_set_mtu(OSSL_QTX *qtx, unsigned int mtu) -{ - if (mtu < QUIC_MIN_INITIAL_DGRAM_LEN) - return 0; - - qtx->mtu = mtu; - return 1; } int ossl_qtx_set_mdpl(OSSL_QTX *qtx, size_t mdpl) { - size_t mtu_limit; - if (mdpl < QUIC_MIN_INITIAL_DGRAM_LEN) return 0; - mtu_limit = qtx->mtu - BIO_dgram_get_mtu_overhead(qtx->bio); - qtx->mdpl = mdpl > mtu_limit ? mtu_limit : mdpl; + qtx->mdpl = mdpl; return 1; } diff --git a/ssl/quic/quic_rx_depack.c b/ssl/quic/quic_rx_depack.c index 74cfceed05..83f66ef59e 100644 --- a/ssl/quic/quic_rx_depack.c +++ b/ssl/quic/quic_rx_depack.c @@ -125,19 +125,8 @@ static int depack_do_frame_ack(PACKET *pkt, QUIC_CHANNEL *ch, } if (!ossl_ackm_on_rx_ack_frame(ch->ackm, &ack, - packet_space, received)) { - /* - * The ACK manager rejects the frame if it acknowledges a packet number - * we have not sent. RFC 9000 s. 13.1 recommends treating this as a - * PROTOCOL_VIOLATION connection error (distinct from a frame decoding - * error, which is handled at the malformed label below). - */ - ossl_quic_channel_raise_protocol_error(ch, - OSSL_QUIC_ERR_PROTOCOL_VIOLATION, - frame_type, - "ACK for unsent packet number"); - return 0; - } + packet_space, received)) + goto malformed; ++ch->diag_num_rx_ack; return 1; @@ -942,22 +931,6 @@ static int depack_do_frame_retire_conn_id(PACKET *pkt, static void free_path_response(unsigned char *buf, size_t buf_len, void *arg) { - QUIC_CHANNEL *ch = (QUIC_CHANNEL *)arg; - - assert(ch->path_response_limit > 0); - - ch->path_response_limit--; - - /* - * Assume path response frame is being freed on behalf of - * finished TX operation. This is for unit testing purposes - * only. The counter is also bumped when channel is being - * destroyed and CFQ (control frame queue) is freed. - * This currently does not matter for check_pc_flood - * in test/radix/quic_tests.c. - */ - ch->path_response_tx++; - OPENSSL_free(buf); } @@ -978,41 +951,33 @@ static int depack_do_frame_path_challenge(PACKET *pkt, return 0; } - if (ch->seen_path_challenge == 0 - && ch->path_response_limit < QUIC_PATH_RESPONSE_QLEN) { - /* - * RFC 9000 s. 8.2.2: On receiving a PATH_CHALLENGE frame, an endpoint - * MUST respond by echoing the data contained in the PATH_CHALLENGE - * frame in a PATH_RESPONSE frame. - * - * TODO(QUIC FUTURE): We should try to avoid allocation here in the - * future. - */ - encoded_len = sizeof(uint64_t) + 1; - if ((encoded = OPENSSL_malloc(encoded_len)) == NULL) - goto err; + /* + * RFC 9000 s. 8.2.2: On receiving a PATH_CHALLENGE frame, an endpoint MUST + * respond by echoing the data contained in the PATH_CHALLENGE frame in a + * PATH_RESPONSE frame. + * + * TODO(QUIC FUTURE): We should try to avoid allocation here in the future. + */ + encoded_len = sizeof(uint64_t) + 1; + if ((encoded = OPENSSL_malloc(encoded_len)) == NULL) + goto err; - if (!WPACKET_init_static_len(&wpkt, encoded, encoded_len, 0)) - goto err; + if (!WPACKET_init_static_len(&wpkt, encoded, encoded_len, 0)) + goto err; - if (!ossl_quic_wire_encode_frame_path_response(&wpkt, frame_data)) { - WPACKET_cleanup(&wpkt); - goto err; - } - - WPACKET_finish(&wpkt); - - if (!ossl_quic_cfq_add_frame(ch->cfq, 0, QUIC_PN_SPACE_APP, - OSSL_QUIC_FRAME_TYPE_PATH_RESPONSE, - QUIC_CFQ_ITEM_FLAG_UNRELIABLE, - encoded, encoded_len, - free_path_response, ch)) - goto err; - ch->seen_path_challenge = 1; - ch->path_response_limit++; + if (!ossl_quic_wire_encode_frame_path_response(&wpkt, frame_data)) { + WPACKET_cleanup(&wpkt); + goto err; } - ch->path_challenge_rx++; + WPACKET_finish(&wpkt); + + if (!ossl_quic_cfq_add_frame(ch->cfq, 0, QUIC_PN_SPACE_APP, + OSSL_QUIC_FRAME_TYPE_PATH_RESPONSE, + QUIC_CFQ_ITEM_FLAG_UNRELIABLE, + encoded, encoded_len, + free_path_response, NULL)) + goto err; return 1; @@ -1351,7 +1316,6 @@ static int depack_process_frames(QUIC_CHANNEL *ch, PACKET *pkt, OSSL_QUIC_ERR_PROTOCOL_VIOLATION, frame_type, "NEW_CONN_ID valid only in 0/1-RTT"); - return 0; } if (!depack_do_frame_new_conn_id(pkt, ch, ackm_data)) return 0; @@ -1467,7 +1431,7 @@ int ossl_quic_handle_frames(QUIC_CHANNEL *ch, OSSL_QRX_PKT *qpacket) if (ch == NULL) return 0; - ossl_ch_reset_rx_state(ch); + ch->did_crypto_frame = 0; /* Initialize |ackm_data| (and reinitialize |ok|)*/ memset(&ackm_data, 0, sizeof(ackm_data)); diff --git a/ssl/quic/quic_srtm.c b/ssl/quic/quic_srtm.c index 4c8ea10734..405376fc46 100644 --- a/ssl/quic/quic_srtm.c +++ b/ssl/quic/quic_srtm.c @@ -168,11 +168,6 @@ void ossl_quic_srtm_free(QUIC_SRTM *srtm) lh_SRTM_ITEM_free(srtm->items_rev); if (srtm->items_fwd != NULL) { - /* - * We don't need to call lh_SRTM_ITEM_set_down_load(..., 0) - * here because srtm_free_each() callback for _doall() does - * not call to lh_SRTIM_ITEM_delete(). - */ lh_SRTM_ITEM_doall(srtm->items_fwd, srtm_free_each); lh_SRTM_ITEM_free(srtm->items_fwd); } @@ -382,24 +377,16 @@ static int srtm_remove_from_rev(QUIC_SRTM *srtm, SRTM_ITEM *item) return 1; } -int ossl_quic_srtm_remove(QUIC_SRTM *srtm, void *opaque, uint64_t seq_num, - uint8_t *match) +int ossl_quic_srtm_remove(QUIC_SRTM *srtm, void *opaque, uint64_t seq_num) { SRTM_ITEM *item, *prev = NULL; - uint8_t match_sink; - - if (match == NULL) - match = &match_sink; - *match = 0; if (srtm->alloc_failed) return 0; if ((item = srtm_find(srtm, opaque, seq_num, NULL, &prev)) == NULL) /* No match */ - return 1; - - *match = 1; + return 0; /* Remove from forward mapping. */ if (prev == NULL) { diff --git a/ssl/quic/quic_stream_map.c b/ssl/quic/quic_stream_map.c index f707bf71d8..63bfbb205a 100644 --- a/ssl/quic/quic_stream_map.c +++ b/ssl/quic/quic_stream_map.c @@ -67,6 +67,8 @@ static QUIC_STREAM *list_next(QUIC_STREAM_LIST_NODE *l, QUIC_STREAM_LIST_NODE *n offsetof(QUIC_STREAM, active_node)) #define accept_next(l, s) list_next((l), &(s)->accept_node, \ offsetof(QUIC_STREAM, accept_node)) +#define ready_for_gc_next(l, s) list_next((l), &(s)->ready_for_gc_node, \ + offsetof(QUIC_STREAM, ready_for_gc_node)) #define accept_head(l) list_next((l), (l), \ offsetof(QUIC_STREAM, accept_node)) #define ready_for_gc_head(l) list_next((l), (l), \ @@ -94,8 +96,6 @@ int ossl_quic_stream_map_init(QUIC_STREAM_MAP *qsm, QUIC_CHANNEL *ch) { qsm->map = lh_QUIC_STREAM_new(hash_stream, cmp_stream); - if (qsm->map == NULL) - return 0; qsm->active_list.prev = qsm->active_list.next = &qsm->active_list; qsm->accept_list.prev = qsm->accept_list.next = &qsm->accept_list; qsm->ready_for_gc_list.prev = qsm->ready_for_gc_list.next @@ -125,9 +125,6 @@ static void release_each(QUIC_STREAM *stream, void *arg) void ossl_quic_stream_map_cleanup(QUIC_STREAM_MAP *qsm) { - if (qsm->map == NULL) - return; - lh_QUIC_STREAM_set_down_load(qsm->map, 0); ossl_quic_stream_map_visit(qsm, release_each, qsm); lh_QUIC_STREAM_free(qsm->map); @@ -173,10 +170,6 @@ QUIC_STREAM *ossl_quic_stream_map_alloc(QUIC_STREAM_MAP *qsm, s->send_final_size = UINT64_MAX; lh_QUIC_STREAM_insert(qsm->map, s); - if (lh_QUIC_STREAM_error(qsm->map)) { - OPENSSL_free(s); - return NULL; - } return s; } @@ -454,13 +447,6 @@ int ossl_quic_stream_map_notify_totally_acked(QUIC_STREAM_MAP *qsm, case QUIC_SSTREAM_STATE_DATA_SENT: qs->send_state = QUIC_SSTREAM_STATE_DATA_RECVD; - /* - * Remember final size in case SSL_get_stream_write_state() - * gets called. - */ - qs->have_final_size = ossl_quic_sstream_get_final_size(qs->sstream, - NULL); - /* We no longer need a QUIC_SSTREAM in this state. */ ossl_quic_sstream_free(qs->sstream); qs->sstream = NULL; @@ -820,9 +806,13 @@ size_t ossl_quic_stream_map_get_total_accept_queue_len(QUIC_STREAM_MAP *qsm) void ossl_quic_stream_map_gc(QUIC_STREAM_MAP *qsm) { - QUIC_STREAM *qs; + QUIC_STREAM *qs, *qs_head, *qsn = NULL; + + for (qs = qs_head = ready_for_gc_head(&qsm->ready_for_gc_list); + qs != NULL && qs != qs_head; + qs = qsn) { + qsn = ready_for_gc_next(&qsm->ready_for_gc_list, qs); - while ((qs = ready_for_gc_head(&qsm->ready_for_gc_list)) != NULL) { ossl_quic_stream_map_release(qsm, qs); } } diff --git a/ssl/quic/quic_tls.c b/ssl/quic/quic_tls.c index 96adb6299c..587685d0b2 100644 --- a/ssl/quic/quic_tls.c +++ b/ssl/quic/quic_tls.c @@ -105,7 +105,7 @@ quic_new_record_layer(OSSL_LIB_CTX *libctx, const char *propq, int vers, int mactype, const EVP_MD *md, COMP_METHOD *comp, const EVP_MD *kdfdigest, BIO *prev, BIO *transport, - BIO *next, + BIO *next, BIO_ADDR *local, BIO_ADDR *peer, const OSSL_PARAM *settings, const OSSL_PARAM *options, const OSSL_DISPATCH *fns, void *cbarg, void *rlarg, OSSL_RECORD_LAYER **retrl) diff --git a/ssl/quic/quic_txp.c b/ssl/quic/quic_txp.c index bd026af3a4..b8fa50e19d 100644 --- a/ssl/quic/quic_txp.c +++ b/ssl/quic/quic_txp.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -708,18 +708,6 @@ int ossl_quic_tx_packetiser_set_peer(OSSL_QUIC_TX_PACKETISER *txp, return BIO_ADDR_copy(&txp->args.peer, peer); } -int ossl_quic_tx_packetiser_set_ack_delay_exponent(OSSL_QUIC_TX_PACKETISER *txp, - uint32_t exp) -{ - if (exp > QUIC_MAX_ACK_DELAY_EXP) { - ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); - return 0; - } - - txp->args.ack_delay_exponent = exp; - return 1; -} - void ossl_quic_tx_packetiser_set_ack_tx_cb(OSSL_QUIC_TX_PACKETISER *txp, void (*cb)(const OSSL_QUIC_FRAME_ACK *ack, uint32_t pn_space, @@ -1477,7 +1465,7 @@ static int txp_should_try_staging(OSSL_QUIC_TX_PACKETISER *txp, * This is not a major concern for clients, since if a client has a 1-RTT EL * provisioned the server is guaranteed to also have a 1-RTT EL provisioned. * - * TODO(QUIC FUTURE): Revisit this when we have reached a decision on how + * TODO(QUIC FUTURE): Revisit this when when have reached a decision on how * best to implement this */ if (*conn_close_enc_level > enc_level @@ -3145,8 +3133,6 @@ static int txp_pkt_commit(OSSL_QUIC_TX_PACKETISER *txp, --probe_info->pto[pn_space]; } - ossl_quic_fifd_pkt_discard_unreliable(&txp->fifd, tpkt); - return rc; } diff --git a/ssl/quic/quic_wire_pkt.c b/ssl/quic/quic_wire_pkt.c index 368a585072..8a65ac9869 100644 --- a/ssl/quic/quic_wire_pkt.c +++ b/ssl/quic/quic_wire_pkt.c @@ -870,7 +870,7 @@ int ossl_quic_calculate_retry_integrity_tag(OSSL_LIB_CTX *libctx, EVP_CIPHER_CTX *cctx = NULL; int ok = 0, l = 0, l2 = 0, wpkt_valid = 0; WPACKET wpkt; - /* Worst case length of the Retry Pseudo-Packet header is 68 bytes. */ + /* Worst case length of the Retry Psuedo-Packet header is 68 bytes. */ unsigned char buf[128]; QUIC_PKT_HDR hdr2; size_t hdr_enc_len = 0; @@ -892,7 +892,7 @@ int ossl_quic_calculate_retry_integrity_tag(OSSL_LIB_CTX *libctx, hdr2 = *hdr; hdr2.len = 0; - /* Assemble retry pseudo-packet. */ + /* Assemble retry psuedo-packet. */ if (!WPACKET_init_static_len(&wpkt, buf, sizeof(buf), 0)) { ERR_raise(ERR_LIB_SSL, ERR_R_CRYPTO_LIB); goto err; diff --git a/ssl/quic/uint_set.c b/ssl/quic/uint_set.c index b01110a58e..f81148c79a 100644 --- a/ssl/quic/uint_set.c +++ b/ssl/quic/uint_set.c @@ -174,7 +174,6 @@ int ossl_uint_set_insert(UINT_SET *s, const UINT_RANGE *range) for (x = ossl_list_uint_set_next(x); x != NULL; x = xnext) { xnext = ossl_list_uint_set_next(x); ossl_list_uint_set_remove(s, x); - OPENSSL_free(x); } return 1; } @@ -304,8 +303,6 @@ int ossl_uint_set_remove(UINT_SET *s, const UINT_RANGE *range) * handled by the above cases. */ y = create_set_item(end + 1, z->range.end); - if (y == NULL) - return 0; ossl_list_uint_set_insert_after(s, z, y); z->range.end = start - 1; break; diff --git a/ssl/record/methods/build.info b/ssl/record/methods/build.info index 4893ce9212..8b1af5dd5d 100644 --- a/ssl/record/methods/build.info +++ b/ssl/record/methods/build.info @@ -4,7 +4,7 @@ IF[{- !$disabled{ktls} -}] ENDIF SOURCE[../../../libssl]=\ - tls_common.c tls1_meth.c tls13_meth.c tlsany_meth.c \ + tls_common.c ssl3_meth.c tls1_meth.c tls13_meth.c tlsany_meth.c \ dtls_meth.c tls_multib.c $KTLSSRC # For shared builds we need to include the sources needed in providers diff --git a/ssl/record/methods/dtls_meth.c b/ssl/record/methods/dtls_meth.c index 434316507d..910f45cd57 100644 --- a/ssl/record/methods/dtls_meth.c +++ b/ssl/record/methods/dtls_meth.c @@ -637,7 +637,7 @@ dtls_new_record_layer(OSSL_LIB_CTX *libctx, const char *propq, int vers, int mactype, const EVP_MD *md, COMP_METHOD *comp, const EVP_MD *kdfdigest, BIO *prev, BIO *transport, - BIO *next, + BIO *next, BIO_ADDR *local, BIO_ADDR *peer, const OSSL_PARAM *settings, const OSSL_PARAM *options, const OSSL_DISPATCH *fns, void *cbarg, void *rlarg, OSSL_RECORD_LAYER **retrl) diff --git a/ssl/record/methods/ktls_meth.c b/ssl/record/methods/ktls_meth.c index fa29f5a175..bfdcc24687 100644 --- a/ssl/record/methods/ktls_meth.c +++ b/ssl/record/methods/ktls_meth.c @@ -405,7 +405,7 @@ ktls_new_record_layer(OSSL_LIB_CTX *libctx, const char *propq, int vers, int mactype, const EVP_MD *md, COMP_METHOD *comp, const EVP_MD *kdfdigest, BIO *prev, BIO *transport, - BIO *next, + BIO *next, BIO_ADDR *local, BIO_ADDR *peer, const OSSL_PARAM *settings, const OSSL_PARAM *options, const OSSL_DISPATCH *fns, void *cbarg, void *rlarg, OSSL_RECORD_LAYER **retrl) @@ -472,16 +472,11 @@ static int ktls_initialise_write_packets(OSSL_RECORD_LAYER *rl, wb = &bufs[0]; wb->type = templates[0].type; - /* - * Free any internal buffer allocated during a previous write retry - * (see tls_retry_write_records). App buffers are not ours to free. - */ - if (!TLS_BUFFER_is_app_buffer(wb)) - OPENSSL_free(TLS_BUFFER_get_buf(wb)); - /* * ktls doesn't modify the buffer, but to avoid a warning we need * to discard the const qualifier. + * This doesn't leak memory because the buffers have never been allocated + * with KTLS */ TLS_BUFFER_set_buf(wb, (unsigned char *)templates[0].buf); TLS_BUFFER_set_offset(wb, 0); @@ -552,6 +547,15 @@ static int ktls_alloc_buffers(OSSL_RECORD_LAYER *rl) return tls_alloc_buffers(rl); } +static int ktls_free_buffers(OSSL_RECORD_LAYER *rl) +{ + /* We use the application buffer directly for writing */ + if (rl->direction == OSSL_RECORD_DIRECTION_WRITE) + return 1; + + return tls_free_buffers(rl); +} + static struct record_functions_st ossl_ktls_funcs = { ktls_set_crypto_state, ktls_cipher, @@ -598,5 +602,5 @@ const OSSL_RECORD_METHOD ossl_ktls_record_method = { NULL, tls_increment_sequence_ctr, ktls_alloc_buffers, - tls_free_buffers + ktls_free_buffers }; diff --git a/ssl/record/methods/recmethod_local.h b/ssl/record/methods/recmethod_local.h index 1bfea26631..4ffce8d663 100644 --- a/ssl/record/methods/recmethod_local.h +++ b/ssl/record/methods/recmethod_local.h @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_SSL_RECORD_METHODS_RECMETHOD_LOCAL_H) -#define OSSL_SSL_RECORD_METHODS_RECMETHOD_LOCAL_H - #include #include #include @@ -287,7 +284,8 @@ struct ossl_record_layer_st { /* * Do we need to send a prefix empty record before application data as a - * countermeasure against known-IV weakness (necessary for TLSv1.0) + * countermeasure against known-IV weakness (necessary for SSLv3 and + * TLSv1.0) */ int need_empty_fragments; @@ -325,6 +323,9 @@ struct ossl_record_layer_st { size_t block_padding; size_t hs_padding; + /* Only used by SSLv3 */ + unsigned char mac_secret[EVP_MAX_MD_SIZE]; + /* TLSv1.0/TLSv1.1/TLSv1.2 */ int use_etm; @@ -377,6 +378,7 @@ typedef struct dtls_rlayer_record_data_st { TLS_RL_RECORD rrec; } DTLS_RLAYER_RECORD_DATA; +extern const struct record_functions_st ssl_3_0_funcs; extern const struct record_functions_st tls_1_funcs; extern const struct record_functions_st tls_1_3_funcs; extern const struct record_functions_st tls_any_funcs; @@ -456,6 +458,7 @@ int tls_read_record(OSSL_RECORD_LAYER *rl, void **rechandle, int *rversion, uint8_t *type, const unsigned char **data, size_t *datalen, uint16_t *epoch, unsigned char *seq_num); int tls_release_record(OSSL_RECORD_LAYER *rl, void *rechandle, size_t length); +int tls_default_set_protocol_version(OSSL_RECORD_LAYER *rl, int version); int tls_set_protocol_version(OSSL_RECORD_LAYER *rl, int version); void tls_set_plain_alerts(OSSL_RECORD_LAYER *rl, int allow); void tls_set_first_handshake(OSSL_RECORD_LAYER *rl, int first); @@ -532,5 +535,3 @@ int tls_write_records_default(OSSL_RECORD_LAYER *rl, #define TLS_BUFFER_is_app_buffer(b) ((b)->app_buffer) void ossl_tls_buffer_release(TLS_BUFFER *b); - -#endif /* !defined(OSSL_SSL_RECORD_METHODS_RECMETHOD_LOCAL_H) */ diff --git a/ssl/record/methods/ssl3_cbc.c b/ssl/record/methods/ssl3_cbc.c index 133067ab15..3702c03c52 100644 --- a/ssl/record/methods/ssl3_cbc.c +++ b/ssl/record/methods/ssl3_cbc.c @@ -105,7 +105,8 @@ static void tls1_sha512_final_raw(void *ctx, unsigned char *md_out) #define LARGEST_DIGEST_CTX SHA512_CTX /*- - * ssl3_cbc_digest_record computes the MAC of a decrypted, padded TLS record. + * ssl3_cbc_digest_record computes the MAC of a decrypted, padded SSLv3/TLS + * record. * * ctx: the EVP_MD_CTX from which we take the hash function. * ssl3_cbc_record_digest_supported must return true for this EVP_MD_CTX. @@ -117,6 +118,7 @@ static void tls1_sha512_final_raw(void *ctx, unsigned char *md_out) * has been removed. * data_plus_mac_plus_padding_size: the public length of the whole * record, including MAC and padding. + * is_sslv3: non-zero if we are to use SSLv3. Otherwise, TLS. * * On entry: we know that data is data_plus_mac_plus_padding_size in length * Returns 1 on success or 0 on error @@ -129,7 +131,7 @@ int ssl3_cbc_digest_record(const EVP_MD *md, size_t data_size, size_t data_plus_mac_plus_padding_size, const unsigned char *mac_secret, - size_t mac_secret_length) + size_t mac_secret_length, char is_sslv3) { union { OSSL_UNION_ALIGN; @@ -138,8 +140,9 @@ int ssl3_cbc_digest_record(const EVP_MD *md, void (*md_final_raw)(void *ctx, unsigned char *md_out); void (*md_transform)(void *ctx, const unsigned char *block); size_t md_size, md_block_size = 64; - size_t header_length, variance_blocks, len, max_mac_bytes, num_blocks, - num_starting_blocks, k, mac_end_offset, c, index_a, index_b; + size_t sslv3_pad_length = 40, header_length, variance_blocks, + len, max_mac_bytes, num_blocks, + num_starting_blocks, k, mac_end_offset, c, index_a, index_b; size_t bits; /* at most 18 bits */ unsigned char length_bytes[MAX_HASH_BIT_COUNT_BYTES]; /* hmac_pad is the masked HMAC key. */ @@ -173,6 +176,7 @@ int ssl3_cbc_digest_record(const EVP_MD *md, md_final_raw = tls1_md5_final_raw; md_transform = (void (*)(void *ctx, const unsigned char *block))MD5_Transform; md_size = 16; + sslv3_pad_length = 48; length_is_big_endian = 0; #endif } else if (EVP_MD_is_a(md, "SHA1")) { @@ -225,11 +229,22 @@ int ssl3_cbc_digest_record(const EVP_MD *md, return 0; header_length = 13; + if (is_sslv3) { + header_length = mac_secret_length + + sslv3_pad_length + + 8 /* sequence number */ + + 1 /* record type */ + + 2; /* record length */ + } /* * variance_blocks is the number of blocks of the hash that we have to * calculate in constant time because they could be altered by the - * padding value. + * padding value. In SSLv3, the padding must be minimal so the end of + * the plaintext varies by, at most, 15+20 = 35 bytes. (We conservatively + * assume that the MAC size varies from 0..20 bytes.) In case the 9 bytes + * of hash termination (0x80 + 64-bit length) don't fit in the final + * block, we say that the final two blocks can vary based on the padding. * TLSv1 has MACs up to 48 bytes long (SHA-384) and the padding is not * required to be minimal. Therefore we say that the final |variance_blocks| * blocks can @@ -237,11 +252,14 @@ int ssl3_cbc_digest_record(const EVP_MD *md, * short and there obviously cannot be this many blocks then * variance_blocks can be reduced. */ - variance_blocks = ((255 + 1 + md_size + md_block_size - 1) / md_block_size) + 1; - + variance_blocks = is_sslv3 ? 2 + : (((255 + 1 + md_size + md_block_size - 1) + / md_block_size) + + 1); /* * From now on we're dealing with the MAC, which conceptually has 13 - * bytes of `header' before the start of the data (TLS) + * bytes of `header' before the start of the data (TLS) or 71/75 bytes + * (SSLv3) */ len = data_plus_mac_plus_padding_size + header_length; /* @@ -284,30 +302,37 @@ int ssl3_cbc_digest_record(const EVP_MD *md, * in bits. */ index_b = (mac_end_offset + md_length_size) / md_block_size; - - if (num_blocks > variance_blocks) { - num_starting_blocks = num_blocks - variance_blocks; - k = md_block_size * num_starting_blocks; - } - /* * bits is the hash-length in bits. It includes the additional hash block * for the masked HMAC key, or whole of |header| in the case of SSLv3. */ - bits = 8 * mac_end_offset; /* - * Compute the initial HMAC block. + * For SSLv3, if we're going to have any starting blocks then we need at + * least two because the header is larger than a single block. */ - bits += 8 * md_block_size; - memset(hmac_pad, 0, md_block_size); - if (!ossl_assert(mac_secret_length <= sizeof(hmac_pad))) - return 0; - memcpy(hmac_pad, mac_secret, mac_secret_length); - for (i = 0; i < md_block_size; i++) - hmac_pad[i] ^= 0x36; + if (num_blocks > variance_blocks + (is_sslv3 ? 1 : 0)) { + num_starting_blocks = num_blocks - variance_blocks; + k = md_block_size * num_starting_blocks; + } - md_transform(md_state.c, hmac_pad); + bits = 8 * mac_end_offset; + if (!is_sslv3) { + /* + * Compute the initial HMAC block. For SSLv3, the padding and secret + * bytes are included in |header| because they take more than a + * single block. + */ + bits += 8 * md_block_size; + memset(hmac_pad, 0, md_block_size); + if (!ossl_assert(mac_secret_length <= sizeof(hmac_pad))) + return 0; + memcpy(hmac_pad, mac_secret, mac_secret_length); + for (i = 0; i < md_block_size; i++) + hmac_pad[i] ^= 0x36; + + md_transform(md_state.c, hmac_pad); + } if (length_is_big_endian) { memset(length_bytes, 0, md_length_size - 4); @@ -324,12 +349,37 @@ int ssl3_cbc_digest_record(const EVP_MD *md, } if (k > 0) { - /* k is a multiple of md_block_size. */ - memcpy(first_block, header, 13); - memcpy(first_block + 13, data, md_block_size - 13); - md_transform(md_state.c, first_block); - for (i = 1; i < k / md_block_size; i++) - md_transform(md_state.c, data + md_block_size * i - 13); + if (is_sslv3) { + size_t overhang; + + /* + * The SSLv3 header is larger than a single block. overhang is + * the number of bytes beyond a single block that the header + * consumes: either 7 bytes (SHA1) or 11 bytes (MD5). There are no + * ciphersuites in SSLv3 that are not SHA1 or MD5 based and + * therefore we can be confident that the header_length will be + * greater than |md_block_size|. However we add a sanity check just + * in case + */ + if (header_length <= md_block_size) { + /* Should never happen */ + return 0; + } + overhang = header_length - md_block_size; + md_transform(md_state.c, header); + memcpy(first_block, header + md_block_size, overhang); + memcpy(first_block + overhang, data, md_block_size - overhang); + md_transform(md_state.c, first_block); + for (i = 1; i < k / md_block_size - 1; i++) + md_transform(md_state.c, data + md_block_size * i - overhang); + } else { + /* k is a multiple of md_block_size. */ + memcpy(first_block, header, 13); + memcpy(first_block + 13, data, md_block_size - 13); + md_transform(md_state.c, first_block); + for (i = 1; i < k / md_block_size; i++) + md_transform(md_state.c, data + md_block_size * i - 13); + } } memset(mac_out, 0, sizeof(mac_out)); @@ -399,15 +449,23 @@ int ssl3_cbc_digest_record(const EVP_MD *md, if (EVP_DigestInit_ex(md_ctx, md, NULL) <= 0) goto err; + if (is_sslv3) { + /* We repurpose |hmac_pad| to contain the SSLv3 pad2 block. */ + memset(hmac_pad, 0x5c, sslv3_pad_length); - /* Complete the HMAC in the standard manner. */ - for (i = 0; i < md_block_size; i++) - hmac_pad[i] ^= 0x6a; - - if (EVP_DigestUpdate(md_ctx, hmac_pad, md_block_size) <= 0 - || EVP_DigestUpdate(md_ctx, mac_out, md_size) <= 0) - goto err; + if (EVP_DigestUpdate(md_ctx, mac_secret, mac_secret_length) <= 0 + || EVP_DigestUpdate(md_ctx, hmac_pad, sslv3_pad_length) <= 0 + || EVP_DigestUpdate(md_ctx, mac_out, md_size) <= 0) + goto err; + } else { + /* Complete the HMAC in the standard manner. */ + for (i = 0; i < md_block_size; i++) + hmac_pad[i] ^= 0x6a; + if (EVP_DigestUpdate(md_ctx, hmac_pad, md_block_size) <= 0 + || EVP_DigestUpdate(md_ctx, mac_out, md_size) <= 0) + goto err; + } ret = EVP_DigestFinal(md_ctx, md_out, &md_out_size_u); if (ret && md_out_size) *md_out_size = md_out_size_u; diff --git a/ssl/record/methods/ssl3_meth.c b/ssl/record/methods/ssl3_meth.c new file mode 100644 index 0000000000..086d8f94f8 --- /dev/null +++ b/ssl/record/methods/ssl3_meth.c @@ -0,0 +1,331 @@ +/* + * Copyright 2022-2024 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +#include +#include +#include "internal/ssl3_cbc.h" +#include "../../ssl_local.h" +#include "../record_local.h" +#include "recmethod_local.h" + +static int ssl3_set_crypto_state(OSSL_RECORD_LAYER *rl, int level, + unsigned char *key, size_t keylen, + unsigned char *iv, size_t ivlen, + unsigned char *mackey, size_t mackeylen, + const EVP_CIPHER *ciph, + size_t taglen, + int mactype, + const EVP_MD *md, + COMP_METHOD *comp) +{ + EVP_CIPHER_CTX *ciph_ctx; + int enc = (rl->direction == OSSL_RECORD_DIRECTION_WRITE) ? 1 : 0; + + if (md == NULL) { + ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); + return OSSL_RECORD_RETURN_FATAL; + } + + if ((rl->enc_ctx = EVP_CIPHER_CTX_new()) == NULL) { + ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); + return OSSL_RECORD_RETURN_FATAL; + } + ciph_ctx = rl->enc_ctx; + + rl->md_ctx = EVP_MD_CTX_new(); + if (rl->md_ctx == NULL) { + ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); + return OSSL_RECORD_RETURN_FATAL; + } + + if ((md != NULL && EVP_DigestInit_ex(rl->md_ctx, md, NULL) <= 0)) { + ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); + return OSSL_RECORD_RETURN_FATAL; + } + +#ifndef OPENSSL_NO_COMP + if (comp != NULL) { + rl->compctx = COMP_CTX_new(comp); + if (rl->compctx == NULL) { + ERR_raise(ERR_LIB_SSL, SSL_R_COMPRESSION_LIBRARY_ERROR); + return OSSL_RECORD_RETURN_FATAL; + } + } +#endif + + if (!EVP_CipherInit_ex(ciph_ctx, ciph, NULL, key, iv, enc)) { + ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); + return OSSL_RECORD_RETURN_FATAL; + } + + if (EVP_CIPHER_get0_provider(EVP_CIPHER_CTX_get0_cipher(ciph_ctx)) != NULL + && !ossl_set_tls_provider_parameters(rl, ciph_ctx, ciph, md)) { + /* ERR_raise already called */ + return OSSL_RECORD_RETURN_FATAL; + } + + if (mackeylen > sizeof(rl->mac_secret)) { + ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); + return OSSL_RECORD_RETURN_FATAL; + } + memcpy(rl->mac_secret, mackey, mackeylen); + + return OSSL_RECORD_RETURN_SUCCESS; +} + +/* + * ssl3_cipher encrypts/decrypts |n_recs| records in |inrecs|. Calls RLAYERfatal + * on internal error, but not otherwise. It is the responsibility of the caller + * to report a bad_record_mac + * + * Returns: + * 0: if the record is publicly invalid, or an internal error + * 1: Success or Mac-then-encrypt decryption failed (MAC will be randomised) + */ +static int ssl3_cipher(OSSL_RECORD_LAYER *rl, TLS_RL_RECORD *inrecs, + size_t n_recs, int sending, SSL_MAC_BUF *mac, + size_t macsize) +{ + TLS_RL_RECORD *rec; + EVP_CIPHER_CTX *ds; + size_t l, i; + size_t bs; + const EVP_CIPHER *enc; + int provided; + + rec = inrecs; + /* + * We shouldn't ever be called with more than one record in the SSLv3 case + */ + if (n_recs != 1) + return 0; + + ds = rl->enc_ctx; + if (ds == NULL || (enc = EVP_CIPHER_CTX_get0_cipher(ds)) == NULL) + return 0; + + provided = (EVP_CIPHER_get0_provider(enc) != NULL); + + l = rec->length; + bs = EVP_CIPHER_CTX_get_block_size(ds); + + if (bs == 0) + return 0; + + /* COMPRESS */ + + if ((bs != 1) && sending && !provided) { + /* + * We only do this for legacy ciphers. Provided ciphers add the + * padding on the provider side. + */ + i = bs - (l % bs); + + /* we need to add 'i-1' padding bytes */ + l += i; + /* + * the last of these zero bytes will be overwritten with the + * padding length. + */ + memset(&rec->input[rec->length], 0, i); + rec->length += i; + rec->input[l - 1] = (unsigned char)(i - 1); + } + + if (!sending) { + if (l == 0 || l % bs != 0) { + /* Publicly invalid */ + return 0; + } + /* otherwise, rec->length >= bs */ + } + + if (provided) { + int outlen; + + if (!EVP_CipherUpdate(ds, rec->data, &outlen, rec->input, + (unsigned int)l)) + return 0; + rec->length = outlen; + + if (!sending && mac != NULL) { + /* Now get a pointer to the MAC */ + OSSL_PARAM params[2], *p = params; + + /* Get the MAC */ + mac->alloced = 0; + + *p++ = OSSL_PARAM_construct_octet_ptr(OSSL_CIPHER_PARAM_TLS_MAC, + (void **)&mac->mac, + macsize); + *p = OSSL_PARAM_construct_end(); + + if (!EVP_CIPHER_CTX_get_params(ds, params)) { + /* Shouldn't normally happen */ + RLAYERfatal(rl, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + return 0; + } + } + } else { + if (EVP_Cipher(ds, rec->data, rec->input, (unsigned int)l) < 1) { + /* Shouldn't happen */ + RLAYERfatal(rl, SSL_AD_BAD_RECORD_MAC, ERR_R_INTERNAL_ERROR); + return 0; + } + + if (!sending) + return ssl3_cbc_remove_padding_and_mac(&rec->length, + rec->orig_len, + rec->data, + (mac != NULL) ? &mac->mac : NULL, + (mac != NULL) ? &mac->alloced : NULL, + bs, + macsize, + rl->libctx); + } + + return 1; +} + +static const unsigned char ssl3_pad_1[48] = { + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, + 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36, 0x36 +}; + +static const unsigned char ssl3_pad_2[48] = { + 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, + 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, + 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, + 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, + 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, + 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c, 0x5c +}; + +static int ssl3_mac(OSSL_RECORD_LAYER *rl, TLS_RL_RECORD *rec, unsigned char *md, + int sending) +{ + unsigned char *mac_sec, *seq = rl->sequence; + const EVP_MD_CTX *hash; + unsigned char *p, rec_char; + size_t md_size; + size_t npad; + int t; + + mac_sec = &(rl->mac_secret[0]); + hash = rl->md_ctx; + + t = EVP_MD_CTX_get_size(hash); + if (t <= 0) + return 0; + md_size = t; + npad = (48 / md_size) * md_size; + + if (!sending + && EVP_CIPHER_CTX_get_mode(rl->enc_ctx) == EVP_CIPH_CBC_MODE + && ssl3_cbc_record_digest_supported(hash)) { +#ifdef OPENSSL_NO_DEPRECATED_3_0 + return 0; +#else + /* + * This is a CBC-encrypted record. We must avoid leaking any + * timing-side channel information about how many blocks of data we + * are hashing because that gives an attacker a timing-oracle. + */ + + /*- + * npad is, at most, 48 bytes and that's with MD5: + * 16 + 48 + 8 (sequence bytes) + 1 + 2 = 75. + * + * With SHA-1 (the largest hash speced for SSLv3) the hash size + * goes up 4, but npad goes down by 8, resulting in a smaller + * total size. + */ + unsigned char header[75]; + size_t j = 0; + memcpy(header + j, mac_sec, md_size); + j += md_size; + memcpy(header + j, ssl3_pad_1, npad); + j += npad; + memcpy(header + j, seq, 8); + j += 8; + header[j++] = rec->type; + header[j++] = (unsigned char)(rec->length >> 8); + header[j++] = (unsigned char)(rec->length & 0xff); + + /* Final param == is SSLv3 */ + if (ssl3_cbc_digest_record(EVP_MD_CTX_get0_md(hash), + md, &md_size, + header, rec->input, + rec->length, rec->orig_len, + mac_sec, md_size, 1) + <= 0) + return 0; +#endif + } else { + unsigned int md_size_u; + /* Chop the digest off the end :-) */ + EVP_MD_CTX *md_ctx = EVP_MD_CTX_new(); + + if (md_ctx == NULL) + return 0; + + rec_char = rec->type; + p = md; + s2n(rec->length, p); + if (EVP_MD_CTX_copy_ex(md_ctx, hash) <= 0 + || EVP_DigestUpdate(md_ctx, mac_sec, md_size) <= 0 + || EVP_DigestUpdate(md_ctx, ssl3_pad_1, npad) <= 0 + || EVP_DigestUpdate(md_ctx, seq, 8) <= 0 + || EVP_DigestUpdate(md_ctx, &rec_char, 1) <= 0 + || EVP_DigestUpdate(md_ctx, md, 2) <= 0 + || EVP_DigestUpdate(md_ctx, rec->input, rec->length) <= 0 + || EVP_DigestFinal_ex(md_ctx, md, NULL) <= 0 + || EVP_MD_CTX_copy_ex(md_ctx, hash) <= 0 + || EVP_DigestUpdate(md_ctx, mac_sec, md_size) <= 0 + || EVP_DigestUpdate(md_ctx, ssl3_pad_2, npad) <= 0 + || EVP_DigestUpdate(md_ctx, md, md_size) <= 0 + || EVP_DigestFinal_ex(md_ctx, md, &md_size_u) <= 0) { + EVP_MD_CTX_free(md_ctx); + return 0; + } + + EVP_MD_CTX_free(md_ctx); + } + + if (!tls_increment_sequence_ctr(rl)) + return 0; + + return 1; +} + +const struct record_functions_st ssl_3_0_funcs = { + ssl3_set_crypto_state, + ssl3_cipher, + ssl3_mac, + tls_default_set_protocol_version, + tls_default_read_n, + tls_get_more_records, + tls_default_validate_record_header, + tls_default_post_process_record, + tls_get_max_records_default, + tls_write_records_default, + /* These 2 functions are defined in tls1_meth.c */ + tls1_allocate_write_buffers, + tls1_initialise_write_packets, + NULL, + tls_prepare_record_header_default, + NULL, + tls_prepare_for_encryption_default, + tls_post_encryption_processing_default, + NULL +}; diff --git a/ssl/record/methods/tls13_meth.c b/ssl/record/methods/tls13_meth.c index e091d8d382..ade5739622 100644 --- a/ssl/record/methods/tls13_meth.c +++ b/ssl/record/methods/tls13_meth.c @@ -236,7 +236,7 @@ static int tls13_cipher(OSSL_RECORD_LAYER *rl, TLS_RL_RECORD *recs, (unsigned int)rec->length) <= 0 || EVP_CipherFinal_ex(enc_ctx, rec->data + lenu, &lenf) <= 0 - || (size_t)lenu + lenf != rec->length) { + || (size_t)(lenu + lenf) != rec->length) { return 0; } if (sending) { diff --git a/ssl/record/methods/tls1_meth.c b/ssl/record/methods/tls1_meth.c index 717e1ed3ff..b738ede95f 100644 --- a/ssl/record/methods/tls1_meth.c +++ b/ssl/record/methods/tls1_meth.c @@ -186,10 +186,10 @@ static int tls1_cipher(OSSL_RECORD_LAYER *rl, TLS_RL_RECORD *recs, size_t reclen[SSL_MAX_PIPELINES]; unsigned char buf[SSL_MAX_PIPELINES][EVP_AEAD_TLS1_AAD_LEN]; unsigned char *data[SSL_MAX_PIPELINES]; - int pad = 0; - size_t bs, ctr; + int pad = 0, tmpr, provided; + size_t bs, ctr, padnum, loop; + unsigned char padval; const EVP_CIPHER *enc; - int outlen; if (n_recs == 0) { RLAYERfatal(rl, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); @@ -240,6 +240,8 @@ static int tls1_cipher(OSSL_RECORD_LAYER *rl, TLS_RL_RECORD *recs, return 0; } + provided = (EVP_CIPHER_get0_provider(enc) != NULL); + bs = EVP_CIPHER_get_block_size(EVP_CIPHER_CTX_get0_cipher(ds)); if (bs == 0) { @@ -299,6 +301,25 @@ static int tls1_cipher(OSSL_RECORD_LAYER *rl, TLS_RL_RECORD *recs, reclen[ctr] += pad; recs[ctr].length += pad; } + } else if ((bs != 1) && sending && !provided) { + /* + * We only do this for legacy ciphers. Provided ciphers add the + * padding on the provider side. + */ + padnum = bs - (reclen[ctr] % bs); + + /* Add weird padding of up to 256 bytes */ + + if (padnum > MAX_PADDING) { + RLAYERfatal(rl, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + return 0; + } + /* we need to add 'padnum' padding bytes of value padval */ + padval = (unsigned char)(padnum - 1); + for (loop = reclen[ctr]; loop < reclen[ctr] + padnum; loop++) + recs[ctr].input[loop] = padval; + reclen[ctr] += padnum; + recs[ctr].length += padnum; } if (!sending) { @@ -354,56 +375,112 @@ static int tls1_cipher(OSSL_RECORD_LAYER *rl, TLS_RL_RECORD *recs, } } - /* Provided cipher - we do not support pipelining on this path */ - if (n_recs > 1) { - RLAYERfatal(rl, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } + if (provided) { + int outlen; - if (!EVP_CipherUpdate(ds, recs[0].data, &outlen, recs[0].input, - (unsigned int)reclen[0])) - return 0; - recs[0].length = outlen; - - /* - * The length returned from EVP_CipherUpdate above is the actual - * payload length. We need to adjust the data/input ptr to skip over - * any explicit IV - */ - if (!sending) { - if (EVP_CIPHER_get_mode(enc) == EVP_CIPH_GCM_MODE) { - recs[0].data += EVP_GCM_TLS_EXPLICIT_IV_LEN; - recs[0].input += EVP_GCM_TLS_EXPLICIT_IV_LEN; - } else if (EVP_CIPHER_get_mode(enc) == EVP_CIPH_CCM_MODE) { - recs[0].data += EVP_CCM_TLS_EXPLICIT_IV_LEN; - recs[0].input += EVP_CCM_TLS_EXPLICIT_IV_LEN; - } else if (bs != 1 && RLAYER_USE_EXPLICIT_IV(rl)) { - recs[0].data += bs; - recs[0].input += bs; - recs[0].orig_len -= bs; + /* Provided cipher - we do not support pipelining on this path */ + if (n_recs > 1) { + RLAYERfatal(rl, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + return 0; } - /* Now get a pointer to the MAC (if applicable) */ - if (macs != NULL) { - OSSL_PARAM params[2], *p = params; + if (!EVP_CipherUpdate(ds, recs[0].data, &outlen, recs[0].input, + (unsigned int)reclen[0])) + return 0; + recs[0].length = outlen; - /* Get the MAC */ - macs[0].alloced = 0; + /* + * The length returned from EVP_CipherUpdate above is the actual + * payload length. We need to adjust the data/input ptr to skip over + * any explicit IV + */ + if (!sending) { + if (EVP_CIPHER_get_mode(enc) == EVP_CIPH_GCM_MODE) { + recs[0].data += EVP_GCM_TLS_EXPLICIT_IV_LEN; + recs[0].input += EVP_GCM_TLS_EXPLICIT_IV_LEN; + } else if (EVP_CIPHER_get_mode(enc) == EVP_CIPH_CCM_MODE) { + recs[0].data += EVP_CCM_TLS_EXPLICIT_IV_LEN; + recs[0].input += EVP_CCM_TLS_EXPLICIT_IV_LEN; + } else if (bs != 1 && RLAYER_USE_EXPLICIT_IV(rl)) { + recs[0].data += bs; + recs[0].input += bs; + recs[0].orig_len -= bs; + } - *p++ = OSSL_PARAM_construct_octet_ptr(OSSL_CIPHER_PARAM_TLS_MAC, - (void **)&macs[0].mac, - macsize); - *p = OSSL_PARAM_construct_end(); + /* Now get a pointer to the MAC (if applicable) */ + if (macs != NULL) { + OSSL_PARAM params[2], *p = params; - if (!EVP_CIPHER_CTX_get_params(ds, params)) { - /* Shouldn't normally happen */ - RLAYERfatal(rl, SSL_AD_INTERNAL_ERROR, - ERR_R_INTERNAL_ERROR); - return 0; + /* Get the MAC */ + macs[0].alloced = 0; + + *p++ = OSSL_PARAM_construct_octet_ptr(OSSL_CIPHER_PARAM_TLS_MAC, + (void **)&macs[0].mac, + macsize); + *p = OSSL_PARAM_construct_end(); + + if (!EVP_CIPHER_CTX_get_params(ds, params)) { + /* Shouldn't normally happen */ + RLAYERfatal(rl, SSL_AD_INTERNAL_ERROR, + ERR_R_INTERNAL_ERROR); + return 0; + } + } + } + } else { + /* Legacy cipher */ + + tmpr = EVP_Cipher(ds, recs[0].data, recs[0].input, + (unsigned int)reclen[0]); + if ((EVP_CIPHER_get_flags(EVP_CIPHER_CTX_get0_cipher(ds)) + & EVP_CIPH_FLAG_CUSTOM_CIPHER) + != 0 + ? (tmpr < 0) + : (tmpr == 0)) { + /* AEAD can fail to verify MAC */ + return 0; + } + + if (!sending) { + for (ctr = 0; ctr < n_recs; ctr++) { + /* Adjust the record to remove the explicit IV/MAC/Tag */ + if (EVP_CIPHER_get_mode(enc) == EVP_CIPH_GCM_MODE) { + recs[ctr].data += EVP_GCM_TLS_EXPLICIT_IV_LEN; + recs[ctr].input += EVP_GCM_TLS_EXPLICIT_IV_LEN; + recs[ctr].length -= EVP_GCM_TLS_EXPLICIT_IV_LEN; + } else if (EVP_CIPHER_get_mode(enc) == EVP_CIPH_CCM_MODE) { + recs[ctr].data += EVP_CCM_TLS_EXPLICIT_IV_LEN; + recs[ctr].input += EVP_CCM_TLS_EXPLICIT_IV_LEN; + recs[ctr].length -= EVP_CCM_TLS_EXPLICIT_IV_LEN; + } else if (bs != 1 && RLAYER_USE_EXPLICIT_IV(rl)) { + if (recs[ctr].length < bs) + return 0; + recs[ctr].data += bs; + recs[ctr].input += bs; + recs[ctr].length -= bs; + recs[ctr].orig_len -= bs; + } + + /* + * If using Mac-then-encrypt, then this will succeed but + * with a random MAC if padding is invalid + */ + if (!tls1_cbc_remove_padding_and_mac(&recs[ctr].length, + recs[ctr].orig_len, + recs[ctr].data, + (macs != NULL) ? &macs[ctr].mac : NULL, + (macs != NULL) ? &macs[ctr].alloced + : NULL, + bs, + pad ? (size_t)pad : macsize, + (EVP_CIPHER_get_flags(enc) + & EVP_CIPH_FLAG_AEAD_CIPHER) + != 0, + rl->libctx)) + return 0; } } } - return 1; } @@ -414,7 +491,6 @@ static int tls1_mac(OSSL_RECORD_LAYER *rl, TLS_RL_RECORD *rec, unsigned char *md EVP_MD_CTX *hash; size_t md_size; EVP_MD_CTX *hmac = NULL, *mac_ctx; - EVP_PKEY_CTX *pkctx; unsigned char header[13]; int t; int ret = 0; @@ -467,13 +543,8 @@ static int tls1_mac(OSSL_RECORD_LAYER *rl, TLS_RL_RECORD *rec, unsigned char *md &rec->orig_len); *p++ = OSSL_PARAM_construct_end(); - pkctx = EVP_MD_CTX_get_pkey_ctx(mac_ctx); - if (pkctx == NULL) { - RLAYERfatal(rl, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto end; - } - - if (!EVP_PKEY_CTX_set_params(pkctx, tls_hmac_params)) + if (!EVP_PKEY_CTX_set_params(EVP_MD_CTX_get_pkey_ctx(mac_ctx), + tls_hmac_params)) goto end; } @@ -530,6 +601,7 @@ end: #endif /* OPENSSL_NO_COMP */ #endif +/* This function is also used by the SSLv3 implementation */ int tls1_allocate_write_buffers(OSSL_RECORD_LAYER *rl, OSSL_RECORD_TEMPLATE *templates, size_t numtempl, size_t *prefix) @@ -551,6 +623,7 @@ int tls1_allocate_write_buffers(OSSL_RECORD_LAYER *rl, return 1; } +/* This function is also used by the SSLv3 implementation */ int tls1_initialise_write_packets(OSSL_RECORD_LAYER *rl, OSSL_RECORD_TEMPLATE *templates, size_t numtempl, diff --git a/ssl/record/methods/tls_common.c b/ssl/record/methods/tls_common.c index 0363bf23bf..4ddcb21b73 100644 --- a/ssl/record/methods/tls_common.c +++ b/ssl/record/methods/tls_common.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -497,7 +497,7 @@ static int tls_record_app_data_waiting(OSSL_RECORD_LAYER *rl) static int rlayer_early_data_count_ok(OSSL_RECORD_LAYER *rl, size_t length, size_t overhead, int send) { - uint64_t max_early_data = rl->max_early_data; + uint32_t max_early_data = rl->max_early_data; if (max_early_data == 0) { RLAYERfatal(rl, send ? SSL_AD_INTERNAL_ERROR : SSL_AD_UNEXPECTED_MESSAGE, @@ -506,7 +506,7 @@ static int rlayer_early_data_count_ok(OSSL_RECORD_LAYER *rl, size_t length, } /* If we are dealing with ciphertext we need to allow for the overhead */ - max_early_data += overhead; + max_early_data += (uint32_t)overhead; if (rl->early_data_count + length > max_early_data) { RLAYERfatal(rl, send ? SSL_AD_INTERNAL_ERROR : SSL_AD_UNEXPECTED_MESSAGE, @@ -526,6 +526,8 @@ static int rlayer_early_data_count_ok(OSSL_RECORD_LAYER *rl, size_t length, */ #define MAX_EMPTY_RECORDS 32 +#define SSL2_RT_HEADER_LENGTH 2 + /*- * Call this to buffer new input records in rl->rrec. * It will return a OSSL_RECORD_RETURN_* value. @@ -551,7 +553,7 @@ int tls_get_more_records(OSSL_RECORD_LAYER *rl) size_t mac_size = 0; int imac_size; size_t num_recs = 0, max_recs, j; - PACKET pkt; + PACKET pkt, sslv2pkt; SSL_MAC_BUF *macbufs = NULL; int ret = OSSL_RECORD_RETURN_FATAL; @@ -574,6 +576,7 @@ int tls_get_more_records(OSSL_RECORD_LAYER *rl) /* check if we have the header */ if ((rl->rstate != SSL_ST_READ_BODY) || (rl->packet_length < SSL3_RT_HEADER_LENGTH)) { + size_t sslv2len; unsigned int type; rret = rl->funcs->read_n(rl, SSL3_RT_HEADER_LENGTH, @@ -590,33 +593,81 @@ int tls_get_more_records(OSSL_RECORD_LAYER *rl) RLAYERfatal(rl, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); return OSSL_RECORD_RETURN_FATAL; } - - /* Pull apart the header into the TLS_RL_RECORD */ - if (!PACKET_get_1(&pkt, &type) - || !PACKET_get_net_2(&pkt, &version) - || !PACKET_get_net_2_len(&pkt, &thisrr->length)) { - if (rl->msg_callback != NULL) - rl->msg_callback(0, 0, SSL3_RT_HEADER, p, 5, rl->cbarg); + sslv2pkt = pkt; + if (!PACKET_get_net_2_len(&sslv2pkt, &sslv2len) + || !PACKET_get_1(&sslv2pkt, &type)) { RLAYERfatal(rl, SSL_AD_DECODE_ERROR, ERR_R_INTERNAL_ERROR); return OSSL_RECORD_RETURN_FATAL; } - thisrr->type = type; - thisrr->rec_version = version; + /* + * The first record received by the server may be a V2ClientHello. + */ + if (rl->role == OSSL_RECORD_ROLE_SERVER + && rl->is_first_record + && (sslv2len & 0x8000) != 0 + && (type == SSL2_MT_CLIENT_HELLO)) { + /* + * SSLv2 style record + * + * |num_recs| here will actually always be 0 because + * |num_recs > 0| only ever occurs when we are processing + * multiple app data records - which we know isn't the case here + * because it is an SSLv2ClientHello. We keep it using + * |num_recs| for the sake of consistency + */ + thisrr->type = SSL3_RT_HANDSHAKE; + thisrr->rec_version = SSL2_VERSION; - if (rl->msg_callback != NULL) - rl->msg_callback(0, version, SSL3_RT_HEADER, p, 5, rl->cbarg); + thisrr->length = sslv2len & 0x7fff; + + if (thisrr->length > TLS_BUFFER_get_len(rbuf) + - SSL2_RT_HEADER_LENGTH) { + RLAYERfatal(rl, SSL_AD_RECORD_OVERFLOW, + SSL_R_PACKET_LENGTH_TOO_LONG); + return OSSL_RECORD_RETURN_FATAL; + } + } else { + /* SSLv3+ style record */ + + /* Pull apart the header into the TLS_RL_RECORD */ + if (!PACKET_get_1(&pkt, &type) + || !PACKET_get_net_2(&pkt, &version) + || !PACKET_get_net_2_len(&pkt, &thisrr->length)) { + if (rl->msg_callback != NULL) + rl->msg_callback(0, 0, SSL3_RT_HEADER, p, 5, rl->cbarg); + RLAYERfatal(rl, SSL_AD_DECODE_ERROR, ERR_R_INTERNAL_ERROR); + return OSSL_RECORD_RETURN_FATAL; + } + thisrr->type = type; + thisrr->rec_version = version; + + /* + * When we call validate_record_header() only records actually + * received in SSLv2 format should have the record version set + * to SSL2_VERSION. This way validate_record_header() can know + * what format the record was in based on the version. + */ + if (thisrr->rec_version == SSL2_VERSION) { + RLAYERfatal(rl, SSL_AD_PROTOCOL_VERSION, + SSL_R_WRONG_VERSION_NUMBER); + return OSSL_RECORD_RETURN_FATAL; + } + + if (rl->msg_callback != NULL) + rl->msg_callback(0, version, SSL3_RT_HEADER, p, 5, rl->cbarg); + + if (thisrr->length > TLS_BUFFER_get_len(rbuf) - SSL3_RT_HEADER_LENGTH) { + RLAYERfatal(rl, SSL_AD_RECORD_OVERFLOW, + SSL_R_PACKET_LENGTH_TOO_LONG); + return OSSL_RECORD_RETURN_FATAL; + } + } if (!rl->funcs->validate_record_header(rl, thisrr)) { /* RLAYERfatal already called */ return OSSL_RECORD_RETURN_FATAL; } - if (thisrr->length > TLS_BUFFER_get_len(rbuf) - SSL3_RT_HEADER_LENGTH) { - RLAYERfatal(rl, SSL_AD_RECORD_OVERFLOW, - SSL_R_PACKET_LENGTH_TOO_LONG); - return OSSL_RECORD_RETURN_FATAL; - } - /* now rl->rstate == SSL_ST_READ_BODY */ } @@ -624,7 +675,12 @@ int tls_get_more_records(OSSL_RECORD_LAYER *rl) * rl->rstate == SSL_ST_READ_BODY, get and decode the data. Calculate * how much more data we need to read for the rest of the record */ - more = thisrr->length; + if (thisrr->rec_version == SSL2_VERSION) { + more = thisrr->length + SSL2_RT_HEADER_LENGTH + - SSL3_RT_HEADER_LENGTH; + } else { + more = thisrr->length; + } if (more > 0) { /* now rl->packet_length == SSL3_RT_HEADER_LENGTH */ @@ -639,9 +695,13 @@ int tls_get_more_records(OSSL_RECORD_LAYER *rl) /* * At this point, rl->packet_length == SSL3_RT_HEADER_LENGTH + * + thisrr->length, or rl->packet_length == SSL2_RT_HEADER_LENGTH * + thisrr->length and we have that many bytes in rl->packet */ - thisrr->input = &(rl->packet[SSL3_RT_HEADER_LENGTH]); + if (thisrr->rec_version == SSL2_VERSION) + thisrr->input = &(rl->packet[SSL2_RT_HEADER_LENGTH]); + else + thisrr->input = &(rl->packet[SSL3_RT_HEADER_LENGTH]); /* * ok, we can now read from 'rl->packet' data into 'thisrr'. @@ -813,7 +873,7 @@ int tls_get_more_records(OSSL_RECORD_LAYER *rl) } OSSL_TRACE_BEGIN(TLS) { - BIO_printf(trc_out, "dec %zu\n", rr[0].length); + BIO_printf(trc_out, "dec %lu\n", (unsigned long)rr[0].length); BIO_dump_indent(trc_out, rr[0].data, (int)rr[0].length, 4); } OSSL_TRACE_END(TLS); @@ -1338,7 +1398,7 @@ tls_new_record_layer(OSSL_LIB_CTX *libctx, const char *propq, int vers, int mactype, const EVP_MD *md, COMP_METHOD *comp, const EVP_MD *kdfdigest, BIO *prev, BIO *transport, - BIO *next, + BIO *next, BIO_ADDR *local, BIO_ADDR *peer, const OSSL_PARAM *settings, const OSSL_PARAM *options, const OSSL_DISPATCH *fns, void *cbarg, void *rlarg, OSSL_RECORD_LAYER **retrl) @@ -1365,6 +1425,9 @@ tls_new_record_layer(OSSL_LIB_CTX *libctx, const char *propq, int vers, case TLS1_VERSION: (*retrl)->funcs = &tls_1_funcs; break; + case SSL3_VERSION: + (*retrl)->funcs = &ssl_3_0_funcs; + break; default: /* Should not happen */ ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); @@ -1387,7 +1450,7 @@ err: static void tls_int_free(OSSL_RECORD_LAYER *rl) { BIO_free(rl->prev); - BIO_free_all(rl->bio); + BIO_free(rl->bio); BIO_free(rl->next); ossl_tls_buffer_release(&rl->rbuf); @@ -1401,6 +1464,8 @@ static void tls_int_free(OSSL_RECORD_LAYER *rl) #endif OPENSSL_free(rl->iv); OPENSSL_free(rl->nonce); + if (rl->version == SSL3_VERSION) + OPENSSL_cleanse(rl->mac_secret, sizeof(rl->mac_secret)); TLS_RL_RECORD_release(rl->rrec, SSL_MAX_PIPELINES); @@ -1905,28 +1970,6 @@ int tls_retry_write_records(OSSL_RECORD_LAYER *rl) tls_release_write_buffer(rl); return OSSL_RECORD_RETURN_SUCCESS; } else if (i <= 0) { - /* - * If the app buffer is used directly (kTLS) and the caller is - * allowed to move it, copy the unsent data so the original - * buffer can be safely released. - */ - if (TLS_BUFFER_is_app_buffer(thiswb) - && (rl->mode & SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER) != 0) { - size_t left = TLS_BUFFER_get_left(thiswb); - unsigned char *buf; - - buf = OPENSSL_malloc(left); - if (buf == NULL) { - RLAYERfatal(rl, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return OSSL_RECORD_RETURN_FATAL; - } - memcpy(buf, - TLS_BUFFER_get_buf(thiswb) + TLS_BUFFER_get_offset(thiswb), - left); - TLS_BUFFER_set_buf(thiswb, buf); - TLS_BUFFER_set_offset(thiswb, 0); - TLS_BUFFER_set_app_buffer(thiswb, 0); - } if (rl->isdtls) { /* * For DTLS, just drop it. That's kind of the whole point in @@ -1953,7 +1996,7 @@ int tls_set1_bio(OSSL_RECORD_LAYER *rl, BIO *bio) { if (bio != NULL && !BIO_up_ref(bio)) return 0; - BIO_free_all(rl->bio); + BIO_free(rl->bio); rl->bio = bio; return 1; diff --git a/ssl/record/methods/tls_pad.c b/ssl/record/methods/tls_pad.c index a017e9221e..7209506bc4 100644 --- a/ssl/record/methods/tls_pad.c +++ b/ssl/record/methods/tls_pad.c @@ -33,6 +33,51 @@ static int ssl3_cbc_copy_mac(size_t *reclen, size_t good, OSSL_LIB_CTX *libctx); +/*- + * ssl3_cbc_remove_padding removes padding from the decrypted, SSLv3, CBC + * record in |recdata| by updating |reclen| in constant time. It also extracts + * the MAC from the underlying record and places a pointer to it in |mac|. The + * MAC data can either be newly allocated memory, or a pointer inside the + * |recdata| buffer. If allocated then |*alloced| is set to 1, otherwise it is + * set to 0. + * + * origreclen: the original record length before any changes were made + * block_size: the block size of the cipher used to encrypt the record. + * mac_size: the size of the MAC to be extracted + * aead: 1 if an AEAD cipher is in use, or 0 otherwise + * returns: + * 0: if the record is publicly invalid. + * 1: if the record is publicly valid. If the padding removal fails then the + * MAC returned is random. + */ +int ssl3_cbc_remove_padding_and_mac(size_t *reclen, + size_t origreclen, + unsigned char *recdata, + unsigned char **mac, + int *alloced, + size_t block_size, size_t mac_size, + OSSL_LIB_CTX *libctx) +{ + size_t padding_length; + size_t good; + const size_t overhead = 1 /* padding length byte */ + mac_size; + + /* + * These lengths are all public so we can test them in non-constant time. + */ + if (overhead > *reclen) + return 0; + + padding_length = recdata[*reclen - 1]; + good = constant_time_ge_s(*reclen, padding_length + overhead); + /* SSLv3 requires that the padding is minimal. */ + good &= constant_time_ge_s(block_size, padding_length + 1); + *reclen -= good & (padding_length + 1); + + return ssl3_cbc_copy_mac(reclen, origreclen, recdata, mac, alloced, + block_size, mac_size, good, libctx); +} + /*- * tls1_cbc_remove_padding_and_mac removes padding from the decrypted, TLS, CBC * record in |recdata| by updating |reclen| in constant time. It also extracts diff --git a/ssl/record/methods/tlsany_meth.c b/ssl/record/methods/tlsany_meth.c index 2b9a02146e..9961725439 100644 --- a/ssl/record/methods/tlsany_meth.c +++ b/ssl/record/methods/tlsany_meth.c @@ -43,64 +43,75 @@ static int tls_any_cipher(OSSL_RECORD_LAYER *rl, TLS_RL_RECORD *recs, static int tls_validate_record_header(OSSL_RECORD_LAYER *rl, TLS_RL_RECORD *rec) { - if (rl->version == TLS_ANY_VERSION) { - if ((rec->rec_version >> 8) != SSL3_VERSION_MAJOR) { - if (rl->is_first_record) { - unsigned char *p; + if (rec->rec_version == SSL2_VERSION) { + /* SSLv2 format ClientHello */ + if (!ossl_assert(rl->version == TLS_ANY_VERSION)) { + RLAYERfatal(rl, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + return 0; + } + if (rec->length < MIN_SSL2_RECORD_LEN) { + RLAYERfatal(rl, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_TOO_SHORT); + return 0; + } + } else { + if (rl->version == TLS_ANY_VERSION) { + if ((rec->rec_version >> 8) != SSL3_VERSION_MAJOR) { + if (rl->is_first_record) { + unsigned char *p; - /* - * Go back to start of packet, look at the five bytes that - * we have. - */ - p = rl->packet; - if (HAS_PREFIX((char *)p, "GET ") || HAS_PREFIX((char *)p, "POST ") || HAS_PREFIX((char *)p, "HEAD ") || HAS_PREFIX((char *)p, "PATCH") || HAS_PREFIX((char *)p, "OPTIO") || HAS_PREFIX((char *)p, "DELET") || HAS_PREFIX((char *)p, "TRACE") || HAS_PREFIX((char *)p, "PUT ")) { - RLAYERfatal(rl, SSL_AD_NO_ALERT, SSL_R_HTTP_REQUEST); - return 0; - } else if (HAS_PREFIX((char *)p, "CONNE")) { + /* + * Go back to start of packet, look at the five bytes that + * we have. + */ + p = rl->packet; + if (HAS_PREFIX((char *)p, "GET ") || HAS_PREFIX((char *)p, "POST ") || HAS_PREFIX((char *)p, "HEAD ") || HAS_PREFIX((char *)p, "PATCH") || HAS_PREFIX((char *)p, "OPTIO") || HAS_PREFIX((char *)p, "DELET") || HAS_PREFIX((char *)p, "TRACE") || HAS_PREFIX((char *)p, "PUT ")) { + RLAYERfatal(rl, SSL_AD_NO_ALERT, SSL_R_HTTP_REQUEST); + return 0; + } else if (HAS_PREFIX((char *)p, "CONNE")) { + RLAYERfatal(rl, SSL_AD_NO_ALERT, + SSL_R_HTTPS_PROXY_REQUEST); + return 0; + } + + /* Doesn't look like TLS - don't send an alert */ RLAYERfatal(rl, SSL_AD_NO_ALERT, - SSL_R_HTTPS_PROXY_REQUEST); + SSL_R_WRONG_VERSION_NUMBER); + return 0; + } else { + RLAYERfatal(rl, SSL_AD_PROTOCOL_VERSION, + SSL_R_WRONG_VERSION_NUMBER); return 0; } - - /* Doesn't look like TLS - don't send an alert */ - RLAYERfatal(rl, SSL_AD_NO_ALERT, - SSL_R_WRONG_VERSION_NUMBER); - return 0; - } else { - RLAYERfatal(rl, SSL_AD_PROTOCOL_VERSION, - SSL_R_WRONG_VERSION_NUMBER); - return 0; } - } - } else if (rl->version == TLS1_3_VERSION) { - /* - * In this case we know we are going to negotiate TLSv1.3, but we've - * had an HRR, so we haven't actually done so yet. In TLSv1.3 we - * must ignore the legacy record version in plaintext records. - */ - } else if (rec->rec_version != rl->version) { - if ((rl->version & 0xFF00) == (rec->rec_version & 0xFF00)) { - if (rec->type == SSL3_RT_ALERT) { - /* - * The record is using an incorrect version number, - * but what we've got appears to be an alert. We - * haven't read the body yet to check whether its a - * fatal or not - but chances are it is. We probably - * shouldn't send a fatal alert back. We'll just - * end. - */ - RLAYERfatal(rl, SSL_AD_NO_ALERT, - SSL_R_WRONG_VERSION_NUMBER); - return 0; + } else if (rl->version == TLS1_3_VERSION) { + /* + * In this case we know we are going to negotiate TLSv1.3, but we've + * had an HRR, so we haven't actually done so yet. In TLSv1.3 we + * must ignore the legacy record version in plaintext records. + */ + } else if (rec->rec_version != rl->version) { + if ((rl->version & 0xFF00) == (rec->rec_version & 0xFF00)) { + if (rec->type == SSL3_RT_ALERT) { + /* + * The record is using an incorrect version number, + * but what we've got appears to be an alert. We + * haven't read the body yet to check whether its a + * fatal or not - but chances are it is. We probably + * shouldn't send a fatal alert back. We'll just + * end. + */ + RLAYERfatal(rl, SSL_AD_NO_ALERT, + SSL_R_WRONG_VERSION_NUMBER); + return 0; + } + /* Send back error using their minor version number */ + rl->version = (unsigned short)rec->rec_version; } - /* Send back error using their minor version number */ - rl->version = (unsigned short)rec->rec_version; + RLAYERfatal(rl, SSL_AD_PROTOCOL_VERSION, + SSL_R_WRONG_VERSION_NUMBER); + return 0; } - RLAYERfatal(rl, SSL_AD_PROTOCOL_VERSION, - SSL_R_WRONG_VERSION_NUMBER); - return 0; } - if (rec->length > SSL3_RT_MAX_PLAIN_LENGTH) { /* * We use SSL_R_DATA_LENGTH_TOO_LONG instead of diff --git a/ssl/record/rec_layer_s3.c b/ssl/record/rec_layer_s3.c index d87001ad7b..f4b249bf32 100644 --- a/ssl/record/rec_layer_s3.c +++ b/ssl/record/rec_layer_s3.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -150,7 +150,7 @@ static uint32_t ossl_get_max_early_data(SSL_CONNECTION *s) static int ossl_early_data_count_ok(SSL_CONNECTION *s, size_t length, size_t overhead, int send) { - uint64_t max_early_data; + uint32_t max_early_data; max_early_data = ossl_get_max_early_data(s); @@ -161,7 +161,7 @@ static int ossl_early_data_count_ok(SSL_CONNECTION *s, size_t length, } /* If we are dealing with ciphertext we need to allow for the overhead */ - max_early_data += overhead; + max_early_data += (uint32_t)overhead; if (s->early_data_count + length > max_early_data) { SSLfatal(s, send ? SSL_AD_INTERNAL_ERROR : SSL_AD_UNEXPECTED_MESSAGE, @@ -529,18 +529,13 @@ int ossl_tls_handle_rlayer_return(SSL_CONNECTION *s, int writing, int ret, ERR_new(); ERR_set_debug(file, line, 0); ossl_statem_fatal(s, al, SSL_R_RECORD_LAYER_FAILURE, NULL); - } else { - /* - * Some failure but there is no alert code. We don't log an - * error for this. The record layer should have logged an error - * already or, if not, its due to some sys call error which will be - * reported via SSL_ERROR_SYSCALL and errno. We do still set the - * state machine into an error state via ossl_statem_send_fatal(). - * This doesn't actually send an alert because we are using - * SSL_AD_NO_ALERT. - */ - ossl_statem_send_fatal(s, SSL_AD_NO_ALERT); } + /* + * else some failure but there is no alert code. We don't log an + * error for this. The record layer should have logged an error + * already or, if not, its due to some sys call error which will be + * reported via SSL_ERROR_SYSCALL and errno. + */ } /* * The record layer distinguishes the cases of EOF, non-fatal @@ -834,6 +829,20 @@ start: * were actually expecting a CCS). */ + /* + * Lets just double check that we've not got an SSLv2 record + */ + if (rr->version == SSL2_VERSION) { + /* + * Should never happen. ssl3_get_record() should only give us an SSLv2 + * record back if this is the first packet and we are looking for an + * initial ClientHello. Therefore |type| should always be equal to + * |rr->type|. If not then something has gone horribly wrong + */ + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + return -1; + } + if (ssl->method->version == TLS_ANY_VERSION && (s->server || rr->type != SSL3_RT_ALERT)) { /* @@ -842,14 +851,7 @@ start: * with. We shouldn't be receiving anything other than a ClientHello * if we are a server. */ - int min_version, max_version; - - if (ssl_get_min_max_version(s, &min_version, &max_version, NULL) != 0) { - SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE, ERR_R_INTERNAL_ERROR); - return -1; - } - - s->version = min_version; + s->version = rr->version; SSLfatal(s, SSL_AD_UNEXPECTED_MESSAGE, SSL_R_UNEXPECTED_MESSAGE); return -1; } @@ -1120,6 +1122,17 @@ start: } } +/* + * Returns true if the current rrec was sent in SSLv2 backwards compatible + * format and false otherwise. + */ +int RECORD_LAYER_is_sslv2_record(RECORD_LAYER *rl) +{ + if (SSL_CONNECTION_IS_DTLS(rl->s)) + return 0; + return rl->tlsrecs[0].version == SSL2_VERSION; +} + static OSSL_FUNC_rlayer_msg_callback_fn rlayer_msg_callback_wrapper; static void rlayer_msg_callback_wrapper(int write_p, int version, int content_type, const void *buf, @@ -1252,31 +1265,6 @@ int ssl_set_new_record_layer(SSL_CONNECTION *s, int version, uint32_t max_early_data; COMP_METHOD *compm = (comp == NULL) ? NULL : comp->method; - if (direction == OSSL_RECORD_DIRECTION_READ) { - if (SSL_CONNECTION_IS_DTLS(s)) { - if (s->rlayer.curr_rec < s->rlayer.num_recs) { - /* - * We are trying to move to the next epoch, but we've still got - * trailing record data to process. This should not happen in - * normal circumstances. The CCS must have arrived early, but - * this remaining record data is unexpected. - */ - SSLfatal(s, SSL_AD_UNEXPECTED_MESSAGE, SSL_R_UNEXPECTED_MESSAGE); - return 0; - } - } else { - if (!ossl_assert(s->rlayer.curr_rec == s->rlayer.num_recs)) { - /* - * How can this happen? We're trying to change to the next - * record layer - but that should only happen on a record - * boundary. We should never be able to get here. - */ - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - } - } - meth = ssl_select_next_record_layer(s, direction, level); if (direction == OSSL_RECORD_DIRECTION_READ) { @@ -1435,7 +1423,7 @@ int ssl_set_new_record_layer(SSL_CONNECTION *s, int version, secret, secretlen, key, keylen, iv, ivlen, mackey, mackeylen, ciph, taglen, mactype, md, compm, kdfdigest, prev, - thisbio, next, settings, + thisbio, next, NULL, NULL, settings, options, rlayer_dispatch_tmp, s, s->rlayer.rlarg, &newrl); BIO_free(prev); diff --git a/ssl/record/record.h b/ssl/record/record.h index 192052367b..8e7b883845 100644 --- a/ssl/record/record.h +++ b/ssl/record/record.h @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -7,13 +7,8 @@ * https://www.openssl.org/source/license.html */ -#if !defined(OSSL_SSL_RECORD_RECORD_H) -#define OSSL_SSL_RECORD_RECORD_H - #include - #include "internal/recordmethod.h" -#include "internal/statem.h" /***************************************************************************** * * @@ -145,6 +140,7 @@ int RECORD_LAYER_reset(RECORD_LAYER *rl); int RECORD_LAYER_read_pending(const RECORD_LAYER *rl); int RECORD_LAYER_processed_read_pending(const RECORD_LAYER *rl); int RECORD_LAYER_write_pending(const RECORD_LAYER *rl); +int RECORD_LAYER_is_sslv2_record(RECORD_LAYER *rl); __owur size_t ssl3_pending(const SSL *s); __owur int ssl3_write_bytes(SSL *s, uint8_t type, const void *buf, size_t len, size_t *written); @@ -194,5 +190,3 @@ OSSL_CORE_MAKE_FUNC(void, rlayer_msg_callback, (int write_p, int version, int co OSSL_CORE_MAKE_FUNC(int, rlayer_security, (void *cbarg, int op, int bits, int nid, void *other)) #define OSSL_FUNC_RLAYER_PADDING 4 OSSL_CORE_MAKE_FUNC(size_t, rlayer_padding, (void *cbarg, int type, size_t len)) - -#endif /* !defined(OSSL_SSL_RECORD_RECORD_H) */ diff --git a/ssl/record/record_local.h b/ssl/record/record_local.h index 7fa24a14b2..bd7608db53 100644 --- a/ssl/record/record_local.h +++ b/ssl/record/record_local.h @@ -14,9 +14,4 @@ * * *****************************************************************************/ -#if !defined(OSSL_SSL_RECORD_RECORD_LOCAL_H) -#define OSSL_SSL_RECORD_RECORD_LOCAL_H - #define MAX_WARN_ALERT_COUNT 5 - -#endif /* !defined(OSSL_SSL_RECORD_RECORD_LOCAL_H) */ diff --git a/ssl/rio/rio_notifier.c b/ssl/rio/rio_notifier.c index 3f5225db0e..ea40790d62 100644 --- a/ssl/rio/rio_notifier.c +++ b/ssl/rio/rio_notifier.c @@ -10,9 +10,9 @@ #include "internal/sockets.h" #include #include +#include "internal/thread_once.h" #include "internal/rio_notifier.h" -#if !defined(OPENSSL_SYS_WINDOWS) || RIO_NOTIFIER_METHOD == RIO_NOTIFIER_METHOD_SOCKETPAIR /* * Sets a socket as close-on-exec, except that this is a no-op if we are certain * we do not need to do this or the OS does not support the concept. @@ -25,34 +25,35 @@ static int set_cloexec(int fd) return 1; #endif } -#endif #if defined(OPENSSL_SYS_WINDOWS) +static CRYPTO_ONCE ensure_wsa_startup_once = CRYPTO_ONCE_STATIC_INIT; +static int wsa_started; + static void ossl_wsa_cleanup(void) { - WSACleanup(); + if (wsa_started) { + wsa_started = 0; + WSACleanup(); + } } -static int do_wsa_startup(void) +DEFINE_RUN_ONCE_STATIC(do_wsa_startup) { WORD versionreq = 0x0202; /* Version 2.2 */ WSADATA wsadata; if (WSAStartup(versionreq, &wsadata) != 0) return 0; - + wsa_started = 1; + OPENSSL_atexit(ossl_wsa_cleanup); return 1; } static ossl_inline int ensure_wsa_startup(void) { - return do_wsa_startup(); -} - -static void wsa_done(void) -{ - ossl_wsa_cleanup(); + return RUN_ONCE(&ensure_wsa_startup_once, do_wsa_startup); } #endif @@ -339,9 +340,6 @@ void ossl_rio_notifier_cleanup(RIO_NOTIFIER *nfy) BIO_closesocket(nfy->wfd); BIO_closesocket(nfy->rfd); nfy->rfd = nfy->wfd = -1; -#if defined(OPENSSL_SYS_WINDOWS) - wsa_done(); -#endif } int ossl_rio_notifier_signal(RIO_NOTIFIER *nfy) diff --git a/ssl/s3_enc.c b/ssl/s3_enc.c index 2f5a3945fa..bcb833406f 100644 --- a/ssl/s3_enc.c +++ b/ssl/s3_enc.c @@ -11,10 +11,205 @@ #include #include "ssl_local.h" #include +#include #include #include "internal/cryptlib.h" #include "internal/ssl_unwrap.h" +static int ssl3_generate_key_block(SSL_CONNECTION *s, unsigned char *km, int num) +{ + const EVP_MD *md5 = NULL, *sha1 = NULL; + EVP_MD_CTX *m5; + EVP_MD_CTX *s1; + unsigned char buf[16], smd[SHA_DIGEST_LENGTH]; + unsigned char c = 'A'; + unsigned int i, k; + int ret = 0; + SSL_CTX *sctx = SSL_CONNECTION_GET_CTX(s); + +#ifdef CHARSET_EBCDIC + c = os_toascii[c]; /* 'A' in ASCII */ +#endif + k = 0; + md5 = EVP_MD_fetch(sctx->libctx, "MD5", sctx->propq); + sha1 = EVP_MD_fetch(sctx->libctx, "SHA1", sctx->propq); + m5 = EVP_MD_CTX_new(); + s1 = EVP_MD_CTX_new(); + if (md5 == NULL || sha1 == NULL || m5 == NULL || s1 == NULL) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB); + goto err; + } + for (i = 0; (int)i < num; i += MD5_DIGEST_LENGTH) { + k++; + if (k > sizeof(buf)) { + /* bug: 'buf' is too small for this ciphersuite */ + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + goto err; + } + + memset(buf, c, k); + c++; + if (!EVP_DigestInit_ex(s1, sha1, NULL) + || !EVP_DigestUpdate(s1, buf, k) + || !EVP_DigestUpdate(s1, s->session->master_key, + s->session->master_key_length) + || !EVP_DigestUpdate(s1, s->s3.server_random, SSL3_RANDOM_SIZE) + || !EVP_DigestUpdate(s1, s->s3.client_random, SSL3_RANDOM_SIZE) + || !EVP_DigestFinal_ex(s1, smd, NULL) + || !EVP_DigestInit_ex(m5, md5, NULL) + || !EVP_DigestUpdate(m5, s->session->master_key, + s->session->master_key_length) + || !EVP_DigestUpdate(m5, smd, SHA_DIGEST_LENGTH)) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + goto err; + } + if ((int)(i + MD5_DIGEST_LENGTH) > num) { + if (!EVP_DigestFinal_ex(m5, smd, NULL)) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + goto err; + } + memcpy(km, smd, (num - i)); + } else { + if (!EVP_DigestFinal_ex(m5, km, NULL)) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + goto err; + } + } + + km += MD5_DIGEST_LENGTH; + } + OPENSSL_cleanse(smd, sizeof(smd)); + ret = 1; +err: + EVP_MD_CTX_free(m5); + EVP_MD_CTX_free(s1); + ssl_evp_md_free(md5); + ssl_evp_md_free(sha1); + return ret; +} + +int ssl3_change_cipher_state(SSL_CONNECTION *s, int which) +{ + unsigned char *p, *mac_secret; + size_t md_len; + unsigned char *key, *iv; + const EVP_CIPHER *ciph; + const SSL_COMP *comp = NULL; + const EVP_MD *md; + int mdi; + size_t n, iv_len, key_len; + int direction = (which & SSL3_CC_READ) != 0 ? OSSL_RECORD_DIRECTION_READ + : OSSL_RECORD_DIRECTION_WRITE; + + ciph = s->s3.tmp.new_sym_enc; + md = s->s3.tmp.new_hash; + /* m == NULL will lead to a crash later */ + if (!ossl_assert(md != NULL)) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + goto err; + } +#ifndef OPENSSL_NO_COMP + comp = s->s3.tmp.new_compression; +#endif + + p = s->s3.tmp.key_block; + mdi = EVP_MD_get_size(md); + if (mdi <= 0) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + goto err; + } + md_len = (size_t)mdi; + key_len = EVP_CIPHER_get_key_length(ciph); + iv_len = EVP_CIPHER_get_iv_length(ciph); + + if ((which == SSL3_CHANGE_CIPHER_CLIENT_WRITE) || (which == SSL3_CHANGE_CIPHER_SERVER_READ)) { + mac_secret = &(p[0]); + n = md_len + md_len; + key = &(p[n]); + n += key_len + key_len; + iv = &(p[n]); + n += iv_len + iv_len; + } else { + n = md_len; + mac_secret = &(p[n]); + n += md_len + key_len; + key = &(p[n]); + n += key_len + iv_len; + iv = &(p[n]); + n += iv_len; + } + + if (n > s->s3.tmp.key_block_length) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + goto err; + } + + if (!ssl_set_new_record_layer(s, SSL3_VERSION, + direction, + OSSL_RECORD_PROTECTION_LEVEL_APPLICATION, + NULL, 0, key, key_len, iv, iv_len, mac_secret, + md_len, ciph, 0, NID_undef, md, comp, NULL)) { + /* SSLfatal already called */ + goto err; + } + + return 1; +err: + return 0; +} + +int ssl3_setup_key_block(SSL_CONNECTION *s) +{ + unsigned char *p; + const EVP_CIPHER *c; + const EVP_MD *hash; + int num; + int ret = 0; + SSL_COMP *comp; + + if (s->s3.tmp.key_block_length != 0) + return 1; + + if (!ssl_cipher_get_evp(SSL_CONNECTION_GET_CTX(s), s->session, &c, &hash, + NULL, NULL, &comp, 0)) { + /* Error is already recorded */ + SSLfatal_alert(s, SSL_AD_INTERNAL_ERROR); + return 0; + } + + ssl_evp_cipher_free(s->s3.tmp.new_sym_enc); + s->s3.tmp.new_sym_enc = c; + ssl_evp_md_free(s->s3.tmp.new_hash); + s->s3.tmp.new_hash = hash; +#ifdef OPENSSL_NO_COMP + s->s3.tmp.new_compression = NULL; +#else + s->s3.tmp.new_compression = comp; +#endif + + num = EVP_MD_get_size(hash); + if (num <= 0) + return 0; + + num = EVP_CIPHER_get_key_length(c) + num + EVP_CIPHER_get_iv_length(c); + num *= 2; + + ssl3_cleanup_key_block(s); + + if ((p = OPENSSL_malloc(num)) == NULL) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_CRYPTO_LIB); + return 0; + } + + s->s3.tmp.key_block_length = num; + s->s3.tmp.key_block = p; + + /* Calls SSLfatal() as required */ + ret = ssl3_generate_key_block(s, p, num); + + return ret; +} + void ssl3_cleanup_key_block(SSL_CONNECTION *s) { OPENSSL_clear_free(s->s3.tmp.key_block, s->s3.tmp.key_block_length); @@ -112,3 +307,199 @@ int ssl3_digest_cached_records(SSL_CONNECTION *s, int keep) return 1; } + +void ssl3_digest_master_key_set_params(const SSL_SESSION *session, + OSSL_PARAM params[]) +{ + int n = 0; + params[n++] = OSSL_PARAM_construct_octet_string(OSSL_DIGEST_PARAM_SSL3_MS, + (void *)session->master_key, + session->master_key_length); + params[n++] = OSSL_PARAM_construct_end(); +} + +size_t ssl3_final_finish_mac(SSL_CONNECTION *s, const char *sender, size_t len, + unsigned char *p) +{ + int ret; + EVP_MD_CTX *ctx = NULL; + + if (!ssl3_digest_cached_records(s, 0)) { + /* SSLfatal() already called */ + return 0; + } + + if (EVP_MD_CTX_get_type(s->s3.handshake_dgst) != NID_md5_sha1) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_NO_REQUIRED_DIGEST); + return 0; + } + + ctx = EVP_MD_CTX_new(); + if (ctx == NULL) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB); + return 0; + } + if (!EVP_MD_CTX_copy_ex(ctx, s->s3.handshake_dgst)) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + ret = 0; + goto err; + } + + ret = EVP_MD_CTX_get_size(ctx); + if (ret < 0) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + ret = 0; + goto err; + } + + if (sender != NULL) { + OSSL_PARAM digest_cmd_params[3]; + + ssl3_digest_master_key_set_params(s->session, digest_cmd_params); + + if (EVP_DigestUpdate(ctx, sender, len) <= 0 + || EVP_MD_CTX_set_params(ctx, digest_cmd_params) <= 0 + || EVP_DigestFinal_ex(ctx, p, NULL) <= 0) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + ret = 0; + } + } + +err: + EVP_MD_CTX_free(ctx); + + return ret; +} + +int ssl3_generate_master_secret(SSL_CONNECTION *s, unsigned char *out, + unsigned char *p, + size_t len, size_t *secret_size) +{ + static const unsigned char *const salt[3] = { +#ifndef CHARSET_EBCDIC + (const unsigned char *)"A", + (const unsigned char *)"BB", + (const unsigned char *)"CCC", +#else + (const unsigned char *)"\x41", + (const unsigned char *)"\x42\x42", + (const unsigned char *)"\x43\x43\x43", +#endif + }; + unsigned char buf[EVP_MAX_MD_SIZE]; + EVP_MD_CTX *ctx = EVP_MD_CTX_new(); + int i, ret = 1; + unsigned int n; + size_t ret_secret_size = 0; + + if (ctx == NULL) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB); + return 0; + } + for (i = 0; i < 3; i++) { + if (EVP_DigestInit_ex(ctx, SSL_CONNECTION_GET_CTX(s)->sha1, NULL) <= 0 + || EVP_DigestUpdate(ctx, salt[i], + strlen((const char *)salt[i])) + <= 0 + || EVP_DigestUpdate(ctx, p, len) <= 0 + || EVP_DigestUpdate(ctx, &(s->s3.client_random[0]), + SSL3_RANDOM_SIZE) + <= 0 + || EVP_DigestUpdate(ctx, &(s->s3.server_random[0]), + SSL3_RANDOM_SIZE) + <= 0 + || EVP_DigestFinal_ex(ctx, buf, &n) <= 0 + || EVP_DigestInit_ex(ctx, SSL_CONNECTION_GET_CTX(s)->md5, NULL) <= 0 + || EVP_DigestUpdate(ctx, p, len) <= 0 + || EVP_DigestUpdate(ctx, buf, n) <= 0 + || EVP_DigestFinal_ex(ctx, out, &n) <= 0) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + ret = 0; + break; + } + out += n; + ret_secret_size += n; + } + EVP_MD_CTX_free(ctx); + + OPENSSL_cleanse(buf, sizeof(buf)); + if (ret) + *secret_size = ret_secret_size; + return ret; +} + +int ssl3_alert_code(int code) +{ + switch (code) { + case SSL_AD_CLOSE_NOTIFY: + return SSL3_AD_CLOSE_NOTIFY; + case SSL_AD_UNEXPECTED_MESSAGE: + return SSL3_AD_UNEXPECTED_MESSAGE; + case SSL_AD_BAD_RECORD_MAC: + return SSL3_AD_BAD_RECORD_MAC; + case SSL_AD_DECRYPTION_FAILED: + return SSL3_AD_BAD_RECORD_MAC; + case SSL_AD_RECORD_OVERFLOW: + return SSL3_AD_BAD_RECORD_MAC; + case SSL_AD_DECOMPRESSION_FAILURE: + return SSL3_AD_DECOMPRESSION_FAILURE; + case SSL_AD_HANDSHAKE_FAILURE: + return SSL3_AD_HANDSHAKE_FAILURE; + case SSL_AD_NO_CERTIFICATE: + return SSL3_AD_NO_CERTIFICATE; + case SSL_AD_BAD_CERTIFICATE: + return SSL3_AD_BAD_CERTIFICATE; + case SSL_AD_UNSUPPORTED_CERTIFICATE: + return SSL3_AD_UNSUPPORTED_CERTIFICATE; + case SSL_AD_CERTIFICATE_REVOKED: + return SSL3_AD_CERTIFICATE_REVOKED; + case SSL_AD_CERTIFICATE_EXPIRED: + return SSL3_AD_CERTIFICATE_EXPIRED; + case SSL_AD_CERTIFICATE_UNKNOWN: + return SSL3_AD_CERTIFICATE_UNKNOWN; + case SSL_AD_ILLEGAL_PARAMETER: + return SSL3_AD_ILLEGAL_PARAMETER; + case SSL_AD_UNKNOWN_CA: + return SSL3_AD_BAD_CERTIFICATE; + case SSL_AD_ACCESS_DENIED: + return SSL3_AD_HANDSHAKE_FAILURE; + case SSL_AD_DECODE_ERROR: + return SSL3_AD_HANDSHAKE_FAILURE; + case SSL_AD_DECRYPT_ERROR: + return SSL3_AD_HANDSHAKE_FAILURE; + case SSL_AD_EXPORT_RESTRICTION: + return SSL3_AD_HANDSHAKE_FAILURE; + case SSL_AD_PROTOCOL_VERSION: + return SSL3_AD_HANDSHAKE_FAILURE; + case SSL_AD_INSUFFICIENT_SECURITY: + return SSL3_AD_HANDSHAKE_FAILURE; + case SSL_AD_INTERNAL_ERROR: + return SSL3_AD_HANDSHAKE_FAILURE; + case SSL_AD_USER_CANCELLED: + return SSL3_AD_HANDSHAKE_FAILURE; + case SSL_AD_NO_RENEGOTIATION: + return -1; /* Don't send it :-) */ + case SSL_AD_UNSUPPORTED_EXTENSION: + return SSL3_AD_HANDSHAKE_FAILURE; + case SSL_AD_CERTIFICATE_UNOBTAINABLE: + return SSL3_AD_HANDSHAKE_FAILURE; + case SSL_AD_UNRECOGNIZED_NAME: + return SSL3_AD_HANDSHAKE_FAILURE; + case SSL_AD_BAD_CERTIFICATE_STATUS_RESPONSE: + return SSL3_AD_HANDSHAKE_FAILURE; + case SSL_AD_BAD_CERTIFICATE_HASH_VALUE: + return SSL3_AD_HANDSHAKE_FAILURE; + case SSL_AD_UNKNOWN_PSK_IDENTITY: + return TLS1_AD_UNKNOWN_PSK_IDENTITY; + case SSL_AD_INAPPROPRIATE_FALLBACK: + return TLS1_AD_INAPPROPRIATE_FALLBACK; + case SSL_AD_NO_APPLICATION_PROTOCOL: + return TLS1_AD_NO_APPLICATION_PROTOCOL; + case SSL_AD_CERTIFICATE_REQUIRED: + return SSL_AD_HANDSHAKE_FAILURE; + case TLS13_AD_MISSING_EXTENSION: + return SSL_AD_HANDSHAKE_FAILURE; + default: + return -1; + } +} diff --git a/ssl/s3_lib.c b/ssl/s3_lib.c index 1e2b052354..04427e24f3 100644 --- a/ssl/s3_lib.c +++ b/ssl/s3_lib.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * Copyright 2005 Nokia. All rights reserved. * @@ -166,42 +166,6 @@ static SSL_CIPHER tls13_ciphers[] = { 384, }, #endif - { - 1, - TLS1_3_RFC_SM4_GCM_SM3, - TLS1_3_RFC_SM4_GCM_SM3, - TLS1_3_CK_SM4_GCM_SM3, - SSL_kANY, - SSL_aANY, - SSL_SM4GCM, - SSL_AEAD, - TLS1_3_VERSION, - TLS1_3_VERSION, - 0, - 0, - SSL_NOT_DEFAULT | SSL_HIGH, - SSL_HANDSHAKE_MAC_SM3, - 128, - 128, - }, - { - 1, - TLS1_3_RFC_SM4_CCM_SM3, - TLS1_3_RFC_SM4_CCM_SM3, - TLS1_3_CK_SM4_CCM_SM3, - SSL_kANY, - SSL_aANY, - SSL_SM4CCM, - SSL_AEAD, - TLS1_3_VERSION, - TLS1_3_VERSION, - 0, - 0, - SSL_NOT_DEFAULT | SSL_HIGH, - SSL_HANDSHAKE_MAC_SM3, - 128, - 128, - }, }; /* @@ -247,7 +211,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 0, 0, @@ -340,7 +304,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -358,7 +322,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_NOT_DEFAULT | SSL_HIGH, + SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -376,7 +340,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -394,7 +358,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_NOT_DEFAULT | SSL_HIGH, + SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -412,7 +376,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 256, 256, @@ -430,7 +394,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_NOT_DEFAULT | SSL_HIGH, + SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 256, 256, @@ -448,7 +412,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 256, 256, @@ -466,7 +430,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_NOT_DEFAULT | SSL_HIGH, + SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 256, 256, @@ -485,7 +449,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 0, 0, @@ -504,7 +468,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -522,7 +486,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 256, 256, @@ -540,7 +504,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_NOT_DEFAULT | SSL_HIGH, + SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -558,7 +522,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -576,7 +540,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_NOT_DEFAULT | SSL_HIGH, + SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 256, 256, @@ -594,7 +558,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 256, 256, @@ -612,7 +576,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_NOT_DEFAULT | SSL_HIGH, + SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -630,7 +594,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_NOT_DEFAULT | SSL_HIGH, + SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 256, 256, @@ -648,7 +612,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256, 128, 128, @@ -666,7 +630,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 256, 256, @@ -684,7 +648,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256, 128, 128, @@ -702,7 +666,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 256, 256, @@ -720,7 +684,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_NOT_DEFAULT | SSL_HIGH, + SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256, 128, 128, @@ -738,7 +702,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_NOT_DEFAULT | SSL_HIGH, + SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 256, 256, @@ -756,7 +720,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_NOT_DEFAULT | SSL_HIGH, + SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256, 128, 128, @@ -774,7 +738,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_NOT_DEFAULT | SSL_HIGH, + SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 256, 256, @@ -1153,7 +1117,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 0, 0, @@ -1192,7 +1156,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -1210,7 +1174,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 256, 256, @@ -1229,7 +1193,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 0, 0, @@ -1268,7 +1232,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -1286,7 +1250,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 256, 256, @@ -1305,7 +1269,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 0, 0, @@ -1344,7 +1308,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_NOT_DEFAULT | SSL_HIGH, + SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -1362,7 +1326,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_NOT_DEFAULT | SSL_HIGH, + SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 256, 256, @@ -1380,7 +1344,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256, 128, 128, @@ -1398,7 +1362,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 256, 256, @@ -1416,7 +1380,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256, 128, 128, @@ -1434,7 +1398,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 256, 256, @@ -1452,7 +1416,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256, 128, 128, @@ -1470,7 +1434,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 256, 256, @@ -1488,7 +1452,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256, 128, 128, @@ -1506,7 +1470,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 256, 256, @@ -1525,7 +1489,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 0, 0, @@ -1543,7 +1507,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 0, 0, @@ -1561,7 +1525,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 0, 0, @@ -1600,7 +1564,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -1618,7 +1582,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 256, 256, @@ -1656,7 +1620,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -1674,7 +1638,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 256, 256, @@ -1712,7 +1676,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -1730,7 +1694,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 256, 256, @@ -1748,7 +1712,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256, 128, 128, @@ -1766,7 +1730,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 256, 256, @@ -1784,7 +1748,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256, 128, 128, @@ -1802,7 +1766,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 256, 256, @@ -1820,7 +1784,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256, 128, 128, @@ -1838,7 +1802,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 256, 256, @@ -1856,7 +1820,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -1874,7 +1838,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 256, 256, @@ -1893,7 +1857,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 0, 0, @@ -1911,7 +1875,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 0, 0, @@ -1930,7 +1894,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -1948,7 +1912,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 256, 256, @@ -1967,7 +1931,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 0, 0, @@ -1985,7 +1949,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 0, 0, @@ -2004,7 +1968,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -2022,7 +1986,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 256, 256, @@ -2041,7 +2005,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 0, 0, @@ -2059,7 +2023,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 0, 0, @@ -2098,7 +2062,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -2116,7 +2080,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 256, 256, @@ -2134,7 +2098,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 128, 128, @@ -2152,7 +2116,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_HIGH, + SSL_HIGH | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 256, 256, @@ -2171,7 +2135,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 0, 0, @@ -2189,7 +2153,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF, 0, 0, @@ -2207,7 +2171,7 @@ static SSL_CIPHER ssl3_ciphers[] = { TLS1_2_VERSION, DTLS1_BAD_VER, DTLS1_2_VERSION, - SSL_STRONG_NONE, + SSL_STRONG_NONE | SSL_FIPS, SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384, 0, 0, @@ -3771,6 +3735,44 @@ void ssl_sort_cipher_list(void) qsort(ssl3_scsvs, SSL3_NUM_SCSVS, sizeof(ssl3_scsvs[0]), cipher_compare); } +static int sslcon_undefined_function_1(SSL_CONNECTION *sc, unsigned char *r, + size_t s, const char *t, size_t u, + const unsigned char *v, size_t w, int x) +{ + (void)r; + (void)s; + (void)t; + (void)u; + (void)v; + (void)w; + (void)x; + return ssl_undefined_function(SSL_CONNECTION_GET_SSL(sc)); +} + +const SSL3_ENC_METHOD SSLv3_enc_data = { + ssl3_setup_key_block, + ssl3_generate_master_secret, + ssl3_change_cipher_state, + ssl3_final_finish_mac, + SSL3_MD_CLIENT_FINISHED_CONST, 4, + SSL3_MD_SERVER_FINISHED_CONST, 4, + ssl3_alert_code, + sslcon_undefined_function_1, + 0, + ssl3_set_handshake_header, + tls_close_construct_packet, + ssl3_handshake_write +}; + +OSSL_TIME ssl3_default_timeout(void) +{ + /* + * 2 hours, the 24 hours mentioned in the SSLv3 spec is way too long for + * http, the cache would over fill + */ + return ossl_seconds2time(60 * 60 * 2); +} + int ssl3_num_ciphers(void) { return SSL3_NUM_CIPHERS; @@ -3925,7 +3927,7 @@ int ssl3_clear(SSL *s) if (!ssl_free_wbio_buffer(sc)) return 0; - sc->version = TLS1_VERSION; + sc->version = SSL3_VERSION; #if !defined(OPENSSL_NO_NEXTPROTONEG) OPENSSL_free(sc->ext.npn); @@ -4025,7 +4027,8 @@ long ssl3_ctrl(SSL *s, int cmd, long larg, void *parg) * from the server, but we currently allow it to be used on servers * as well, which is a programming error. Currently we just clear * the field in SSL_do_handshake() for server SSLs, but when we can - * make ABI-breaking changes, we may want to return an error in this case. + * make ABI-breaking changes, we may want to make use of this API + * an error on server SSLs. */ if (larg == TLSEXT_NAMETYPE_host_name) { size_t len; @@ -4038,7 +4041,7 @@ long ssl3_ctrl(SSL *s, int cmd, long larg, void *parg) break; len = strlen((char *)parg); if (len == 0 || len > TLSEXT_MAXLEN_host_name) { - ERR_raise(ERR_LIB_SSL, SSL_R_TLS_EXT_INVALID_SERVERNAME); + ERR_raise(ERR_LIB_SSL, SSL_R_SSL3_EXT_INVALID_SERVERNAME); return 0; } if ((sc->ext.hostname = OPENSSL_strdup((char *)parg)) == NULL) { @@ -4046,7 +4049,7 @@ long ssl3_ctrl(SSL *s, int cmd, long larg, void *parg) return 0; } } else { - ERR_raise(ERR_LIB_SSL, SSL_R_TLS_EXT_INVALID_SERVERNAME_TYPE); + ERR_raise(ERR_LIB_SSL, SSL_R_SSL3_EXT_INVALID_SERVERNAME_TYPE); return 0; } break; @@ -4249,7 +4252,7 @@ long ssl3_ctrl(SSL *s, int cmd, long larg, void *parg) parg); case SSL_CTRL_GET_SHARED_GROUP: { - uint16_t id = tls1_shared_group(sc, larg, TLS1_GROUPS_ALL_GROUPS); + uint16_t id = tls1_shared_group(sc, larg); if (larg != -1) return tls1_group_id2nid(id, 1); @@ -4389,7 +4392,7 @@ long ssl3_callback_ctrl(SSL *s, int cmd, void (*fp)(void)) switch (cmd) { #if !defined(OPENSSL_NO_DEPRECATED_3_0) case SSL_CTRL_SET_TMP_DH_CB: - sc->cert->dh_tmp_cb = (DH *(*)(SSL *, int, int))fp; + sc->cert->dh_tmp_cb = (DH * (*)(SSL *, int, int)) fp; ret = 1; break; #endif @@ -4660,7 +4663,7 @@ long ssl3_ctx_callback_ctrl(SSL_CTX *ctx, int cmd, void (*fp)(void)) switch (cmd) { #if !defined(OPENSSL_NO_DEPRECATED_3_0) case SSL_CTRL_SET_TMP_DH_CB: { - ctx->cert->dh_tmp_cb = (DH *(*)(SSL *, int, int))fp; + ctx->cert->dh_tmp_cb = (DH * (*)(SSL *, int, int)) fp; } break; #endif case SSL_CTRL_SET_TLSEXT_SERVERNAME_CB: @@ -4724,32 +4727,18 @@ const SSL_CIPHER *ssl3_get_cipher_by_id(uint32_t id) return OBJ_bsearch_ssl_cipher_id(&c, ssl3_scsvs, SSL3_NUM_SCSVS); } -const SSL_CIPHER *ssl3_get_tls13_cipher_by_std_name(const char *stdname) -{ - SSL_CIPHER *end = &tls13_ciphers[TLS13_NUM_CIPHERS]; - - /* this is not efficient, necessary to optimize this? */ - for (SSL_CIPHER *c = tls13_ciphers; c < end; ++c) { - if (c->stdname == NULL) - continue; - if (OPENSSL_strcasecmp(stdname, c->stdname) == 0) - return c; - } - return NULL; -} - const SSL_CIPHER *ssl3_get_cipher_by_std_name(const char *stdname) { SSL_CIPHER *tbl; - SSL_CIPHER *alltabs[] = { ssl3_ciphers, ssl3_scsvs }; - size_t i, j, tblsize[] = { SSL3_NUM_CIPHERS, SSL3_NUM_SCSVS }; + SSL_CIPHER *alltabs[] = { tls13_ciphers, ssl3_ciphers, ssl3_scsvs }; + size_t i, j, tblsize[] = { TLS13_NUM_CIPHERS, SSL3_NUM_CIPHERS, SSL3_NUM_SCSVS }; /* this is not efficient, necessary to optimize this? */ for (j = 0; j < OSSL_NELEM(alltabs); j++) { for (i = 0, tbl = alltabs[j]; i < tblsize[j]; i++, tbl++) { if (tbl->stdname == NULL) continue; - if (OPENSSL_strcasecmp(stdname, tbl->stdname) == 0) { + if (strcmp(stdname, tbl->stdname) == 0) { return tbl; } } @@ -4941,18 +4930,11 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL_CONNECTION *s, STACK_OF(SSL_CIPHER) *cl "%d:[%08lX:%08lX:%08lX:%08lX]%p:%s\n", ok, alg_k, alg_a, mask_k, mask_a, (void *)c, c->name); - /* - * if we are considering a DHE cipher suite that uses an ephemeral - * FFDHE key check it - */ - if (alg_k & (SSL_kDHE | SSL_kDHEPSK)) - ok = ok && tls1_check_ffdhe_tmp_key(s, c->id); - /* * if we are considering an ECC cipher suite that uses an ephemeral * EC key check it */ - if (alg_k & (SSL_kECDHE | SSL_kECDHEPSK)) + if (alg_k & SSL_kECDHE) ok = ok && tls1_check_ec_tmp_key(s, c->id); if (!ok) @@ -4998,10 +4980,7 @@ const SSL_CIPHER *ssl3_choose_cipher(SSL_CONNECTION *s, STACK_OF(SSL_CIPHER) *cl int ssl3_get_req_cert_type(SSL_CONNECTION *s, WPACKET *pkt) { -#ifndef OPENSSL_NO_GOST - uint32_t alg_k; -#endif - uint32_t alg_a = 0; + uint32_t alg_k, alg_a = 0; /* If we have custom certificate types set, use them */ if (s->cert->ctype) @@ -5009,9 +4988,9 @@ int ssl3_get_req_cert_type(SSL_CONNECTION *s, WPACKET *pkt) /* Get mask of algorithms disabled by signature list */ ssl_set_sig_mask(&alg_a, s, SSL_SECOP_SIGALG_MASK); -#ifndef OPENSSL_NO_GOST alg_k = s->s3.tmp.new_cipher->algorithm_mkey; +#ifndef OPENSSL_NO_GOST if (s->version >= TLS1_VERSION && (alg_k & SSL_kGOST)) if (!WPACKET_put_bytes_u8(pkt, TLS_CT_GOST01_SIGN) || !WPACKET_put_bytes_u8(pkt, TLS_CT_GOST12_IANA_SIGN) @@ -5026,6 +5005,13 @@ int ssl3_get_req_cert_type(SSL_CONNECTION *s, WPACKET *pkt) return 0; #endif + if ((s->version == SSL3_VERSION) && (alg_k & SSL_kDHE)) { + if (!WPACKET_put_bytes_u8(pkt, SSL3_CT_RSA_EPHEMERAL_DH)) + return 0; + if (!(alg_a & SSL_aDSS) + && !WPACKET_put_bytes_u8(pkt, SSL3_CT_DSS_EPHEMERAL_DH)) + return 0; + } if (!(alg_a & SSL_aRSA) && !WPACKET_put_bytes_u8(pkt, SSL3_CT_RSA_SIGN)) return 0; if (!(alg_a & SSL_aDSS) && !WPACKET_put_bytes_u8(pkt, SSL3_CT_DSS_SIGN)) diff --git a/ssl/s3_msg.c b/ssl/s3_msg.c index c1cb8e8bb0..ffe53bfe18 100644 --- a/ssl/s3_msg.c +++ b/ssl/s3_msg.c @@ -51,6 +51,9 @@ int ssl3_send_alert(SSL_CONNECTION *s, int level, int desc) desc = tls13_alert_code(desc); else desc = ssl->method->ssl3_enc->alert_value(desc); + if (s->version == SSL3_VERSION && desc == SSL_AD_PROTOCOL_VERSION) + desc = SSL_AD_HANDSHAKE_FAILURE; /* SSL 3.0 does not have + * protocol_version alerts */ if (desc < 0) return -1; if (s->shutdown & SSL_SENT_SHUTDOWN && desc != SSL_AD_CLOSE_NOTIFY) diff --git a/ssl/ssl_asn1.c b/ssl/ssl_asn1.c index 12cd62d773..5d4ec7e6ed 100644 --- a/ssl/ssl_asn1.c +++ b/ssl/ssl_asn1.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved. * Copyright 2005 Nokia. All rights reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -15,8 +15,6 @@ #include #include -#include - typedef struct { uint32_t version; int32_t ssl_version; @@ -83,7 +81,7 @@ ASN1_SEQUENCE(SSL_SESSION_ASN1) = { ASN1_EXP_OPT(SSL_SESSION_ASN1, peer_rpk, ASN1_OCTET_STRING, 20) } static_ASN1_SEQUENCE_END(SSL_SESSION_ASN1) -IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(SSL_SESSION_ASN1) + IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(SSL_SESSION_ASN1) /* Utility functions for i2d_SSL_SESSION */ diff --git a/ssl/ssl_cert.c b/ssl/ssl_cert.c index 2a51ada2a1..3d21801aa1 100644 --- a/ssl/ssl_cert.c +++ b/ssl/ssl_cert.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -306,7 +306,7 @@ int ssl_cert_set0_chain(SSL_CONNECTION *s, SSL_CTX *ctx, STACK_OF(X509) *chain) for (i = 0; i < sk_X509_num(chain); i++) { X509 *x = sk_X509_value(chain, i); - r = ssl_security_cert(s, ctx, x, 0); + r = ssl_security_cert(s, ctx, x, 0, 0); if (r != 1) { ERR_raise(ERR_LIB_SSL, r); return 0; @@ -340,7 +340,7 @@ int ssl_cert_add0_chain_cert(SSL_CONNECTION *s, SSL_CTX *ctx, X509 *x) if (!cpk) return 0; - r = ssl_security_cert(s, ctx, x, 0); + r = ssl_security_cert(s, ctx, x, 0, 0); if (r != 1) { ERR_raise(ERR_LIB_SSL, r); return 0; @@ -741,8 +741,8 @@ static int xname_cmp(const X509_NAME *a, const X509_NAME *b) /* X509_NAME_cmp() itself casts away constness in this way, so * assume it's safe: */ - alen = i2d_X509_NAME(a, &abuf); - blen = i2d_X509_NAME(b, &bbuf); + alen = i2d_X509_NAME((X509_NAME *)a, &abuf); + blen = i2d_X509_NAME((X509_NAME *)b, &bbuf); if (alen < 0 || blen < 0) ret = -2; @@ -765,7 +765,7 @@ static int xname_sk_cmp(const X509_NAME *const *a, const X509_NAME *const *b) static unsigned long xname_hash(const X509_NAME *a) { /* This returns 0 also if SHA1 is not available */ - return X509_NAME_hash_ex(a, NULL, NULL, NULL); + return X509_NAME_hash_ex((X509_NAME *)a, NULL, NULL, NULL); } STACK_OF(X509_NAME) *SSL_load_client_CA_file_ex(const char *file, @@ -774,7 +774,6 @@ STACK_OF(X509_NAME) *SSL_load_client_CA_file_ex(const char *file, { BIO *in = BIO_new(BIO_s_file()); X509 *x = NULL; - const X509_NAME *cxn = NULL; X509_NAME *xn = NULL; STACK_OF(X509_NAME) *ret = NULL; LHASH_OF(X509_NAME) *name_hash = lh_X509_NAME_new(xname_hash, xname_cmp); @@ -813,10 +812,10 @@ STACK_OF(X509_NAME) *SSL_load_client_CA_file_ex(const char *file, goto err; } } - if ((cxn = X509_get_subject_name(x)) == NULL) + if ((xn = X509_get_subject_name(x)) == NULL) goto err; /* check for duplicates */ - xn = X509_NAME_dup(cxn); + xn = X509_NAME_dup(xn); if (xn == NULL) goto err; if (lh_X509_NAME_retrieve(name_hash, xn) != NULL) { @@ -857,7 +856,6 @@ static int add_file_cert_subjects_to_stack(STACK_OF(X509_NAME) *stack, { BIO *in; X509 *x = NULL; - const X509_NAME *cxn = NULL; X509_NAME *xn = NULL; int ret = 1; @@ -874,9 +872,9 @@ static int add_file_cert_subjects_to_stack(STACK_OF(X509_NAME) *stack, for (;;) { if (PEM_read_bio_X509(in, &x, NULL, NULL) == NULL) break; - if ((cxn = X509_get_subject_name(x)) == NULL) + if ((xn = X509_get_subject_name(x)) == NULL) goto err; - xn = X509_NAME_dup(cxn); + xn = X509_NAME_dup(xn); if (xn == NULL) goto err; if (lh_X509_NAME_retrieve(name_hash, xn) != NULL) { @@ -1025,7 +1023,6 @@ static int add_uris_recursive(STACK_OF(X509_NAME) *stack, int ok = 1; OSSL_STORE_CTX *ctx = NULL; X509 *x = NULL; - const X509_NAME *cxn = NULL; X509_NAME *xn = NULL; OSSL_STORE_INFO *info = NULL; @@ -1049,8 +1046,8 @@ static int add_uris_recursive(STACK_OF(X509_NAME) *stack, depth - 1); } else if (infotype == OSSL_STORE_INFO_CERT) { if ((x = OSSL_STORE_INFO_get0_CERT(info)) == NULL - || (cxn = X509_get_subject_name(x)) == NULL - || (xn = X509_NAME_dup(cxn)) == NULL) + || (xn = X509_get_subject_name(x)) == NULL + || (xn = X509_NAME_dup(xn)) == NULL) goto err; if (sk_X509_NAME_find(stack, xn) >= 0) { /* Duplicate. */ @@ -1175,7 +1172,7 @@ int ssl_build_cert_chain(SSL_CONNECTION *s, SSL_CTX *ctx, int flags) */ for (i = 0; i < sk_X509_num(chain); i++) { x = sk_X509_value(chain, i); - rv = ssl_security_cert(s, ctx, x, 0); + rv = ssl_security_cert(s, ctx, x, 0, 0); if (rv != 1) { ERR_raise(ERR_LIB_SSL, rv); OSSL_STACK_OF_X509_free(chain); diff --git a/ssl/ssl_cert_comp.c b/ssl/ssl_cert_comp.c index d6eadc5365..2c297178e5 100644 --- a/ssl/ssl_cert_comp.c +++ b/ssl/ssl_cert_comp.c @@ -151,7 +151,7 @@ int OSSL_COMP_CERT_up_ref(OSSL_COMP_CERT *cc) { int i; - if (!CRYPTO_UP_REF(&cc->references, &i)) + if (CRYPTO_UP_REF(&cc->references, &i) <= 0) return 0; REF_PRINT_COUNT("OSSL_COMP_CERT", i, cc); diff --git a/ssl/ssl_cert_table.h b/ssl/ssl_cert_table.h index 940ef7a5c9..f7fc9844c9 100644 --- a/ssl/ssl_cert_table.h +++ b/ssl/ssl_cert_table.h @@ -10,13 +10,6 @@ /* * Certificate table information. NB: table entries must match SSL_PKEY indices */ -#if !defined(OSSL_SSL_SSL_CERT_TABLE_H) -#define OSSL_SSL_SSL_CERT_TABLE_H - -#include - -#include "ssl_local.h" - static const SSL_CERT_LOOKUP ssl_cert_info[] = { { EVP_PKEY_RSA, SSL_aRSA }, /* SSL_PKEY_RSA */ { EVP_PKEY_RSA_PSS, SSL_aRSA }, /* SSL_PKEY_RSA_PSS_SIGN */ @@ -28,5 +21,3 @@ static const SSL_CERT_LOOKUP ssl_cert_info[] = { { EVP_PKEY_ED25519, SSL_aECDSA }, /* SSL_PKEY_ED25519 */ { EVP_PKEY_ED448, SSL_aECDSA } /* SSL_PKEY_ED448 */ }; - -#endif /* !defined(OSSL_SSL_SSL_CERT_TABLE_H) */ diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c index 47e3ff4df3..d6f1dd16dc 100644 --- a/ssl/ssl_ciph.c +++ b/ssl/ssl_ciph.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * Copyright 2005 Nokia. All rights reserved. * @@ -59,10 +59,8 @@ static const ssl_cipher_table ssl_cipher_table_cipher[SSL_ENC_NUM_IDX] = { { SSL_CHACHA20POLY1305, NID_chacha20_poly1305 }, /* SSL_ENC_CHACHA_IDX 19 */ { SSL_ARIA128GCM, NID_aria_128_gcm }, /* SSL_ENC_ARIA128GCM_IDX 20 */ { SSL_ARIA256GCM, NID_aria_256_gcm }, /* SSL_ENC_ARIA256GCM_IDX 21 */ - { SSL_MAGMA, NID_magma_ctr_acpkm }, /* SSL_ENC_MAGMA_IDX 22 */ - { SSL_KUZNYECHIK, NID_kuznyechik_ctr_acpkm }, /* SSL_ENC_KUZNYECHIK_IDX 23 */ - { SSL_SM4GCM, NID_sm4_gcm }, /* SSL_ENC_SM4GCM_IDX 24 */ - { SSL_SM4CCM, NID_sm4_ccm }, /* SSL_ENC_SM4CCM_IDX 25 */ + { SSL_MAGMA, NID_magma_ctr_acpkm }, /* SSL_ENC_MAGMA_IDX */ + { SSL_KUZNYECHIK, NID_kuznyechik_ctr_acpkm }, /* SSL_ENC_KUZNYECHIK_IDX */ }; /* NB: make sure indices in this table matches values above */ @@ -79,9 +77,8 @@ static const ssl_cipher_table ssl_cipher_table_mac[SSL_MD_NUM_IDX] = { { 0, NID_md5_sha1 }, /* SSL_MD_MD5_SHA1_IDX 9 */ { 0, NID_sha224 }, /* SSL_MD_SHA224_IDX 10 */ { 0, NID_sha512 }, /* SSL_MD_SHA512_IDX 11 */ - { SSL_MAGMAOMAC, NID_magma_mac }, /* sSL_MD_MAGMAOMAC_IDX 12 */ - { SSL_KUZNYECHIKOMAC, NID_kuznyechik_mac }, /* SSL_MD_KUZNYECHIKOMAC_IDX 13 */ - { 0, NID_sm3 }, /* SSL_MD_SM3_IDX 14 */ + { SSL_MAGMAOMAC, NID_magma_mac }, /* sSL_MD_MAGMAOMAC_IDX */ + { SSL_KUZNYECHIKOMAC, NID_kuznyechik_mac } /* SSL_MD_KUZNYECHIKOMAC_IDX */ }; /* *INDENT-OFF* */ @@ -257,6 +254,7 @@ static const SSL_CIPHER cipher_aliases[] = { { 0, SSL_TXT_GOST12, NULL, 0, 0, 0, 0, SSL_GOST12_256 }, /* protocol version aliases */ + { 0, SSL_TXT_SSLV3, NULL, 0, 0, 0, 0, 0, SSL3_VERSION }, { 0, SSL_TXT_TLSV1, NULL, 0, 0, 0, 0, 0, TLS1_VERSION }, { 0, "TLSv1.0", NULL, 0, 0, 0, 0, 0, TLS1_VERSION }, { 0, SSL_TXT_TLSV1_2, NULL, 0, 0, 0, 0, 0, TLS1_2_VERSION }, @@ -265,15 +263,40 @@ static const SSL_CIPHER cipher_aliases[] = { { 0, SSL_TXT_LOW, NULL, 0, 0, 0, 0, 0, 0, 0, 0, 0, SSL_LOW }, { 0, SSL_TXT_MEDIUM, NULL, 0, 0, 0, 0, 0, 0, 0, 0, 0, SSL_MEDIUM }, { 0, SSL_TXT_HIGH, NULL, 0, 0, 0, 0, 0, 0, 0, 0, 0, SSL_HIGH }, + /* FIPS 140-2 approved ciphersuite */ + { 0, SSL_TXT_FIPS, NULL, 0, 0, 0, ~SSL_eNULL, 0, 0, 0, 0, 0, SSL_FIPS }, /* "EDH-" aliases to "DHE-" labels (for backward compatibility) */ { 0, SSL3_TXT_EDH_DSS_DES_192_CBC3_SHA, NULL, 0, - SSL_kDHE, SSL_aDSS, SSL_3DES, SSL_SHA1, 0, 0, 0, 0, SSL_HIGH }, + SSL_kDHE, SSL_aDSS, SSL_3DES, SSL_SHA1, 0, 0, 0, 0, SSL_HIGH | SSL_FIPS }, { 0, SSL3_TXT_EDH_RSA_DES_192_CBC3_SHA, NULL, 0, - SSL_kDHE, SSL_aRSA, SSL_3DES, SSL_SHA1, 0, 0, 0, 0, SSL_HIGH }, + SSL_kDHE, SSL_aRSA, SSL_3DES, SSL_SHA1, 0, 0, 0, 0, SSL_HIGH | SSL_FIPS }, }; +#ifndef OPENSSL_NO_DEPRECATED_3_6 +/* + * Search for public key algorithm with given name and return its pkey_id if + * it is available. Otherwise return 0 + */ +static int get_optional_pkey_id(const char *pkey_name) +{ + const EVP_PKEY_ASN1_METHOD *ameth; + int pkey_id = 0; + ameth = EVP_PKEY_asn1_find_str(NULL, pkey_name, -1); + if (ameth && EVP_PKEY_asn1_get0_info(&pkey_id, NULL, NULL, NULL, NULL, ameth) > 0) + return pkey_id; + return 0; +} + +#else +static int get_optional_pkey_id(const char *pkey_name) +{ + (void)pkey_name; + return 0; +} +#endif + int ssl_load_ciphers(SSL_CTX *ctx) { size_t i; @@ -362,33 +385,36 @@ int ssl_load_ciphers(SSL_CTX *ctx) memcpy(ctx->ssl_mac_pkey_id, default_mac_pkey_id, sizeof(ctx->ssl_mac_pkey_id)); - ctx->ssl_mac_pkey_id[SSL_MD_GOST89MAC_IDX] = 0; + ctx->ssl_mac_pkey_id[SSL_MD_GOST89MAC_IDX] = get_optional_pkey_id(SN_id_Gost28147_89_MAC); if (ctx->ssl_mac_pkey_id[SSL_MD_GOST89MAC_IDX]) ctx->ssl_mac_secret_size[SSL_MD_GOST89MAC_IDX] = 32; else ctx->disabled_mac_mask |= SSL_GOST89MAC; - ctx->ssl_mac_pkey_id[SSL_MD_GOST89MAC12_IDX] = 0; + ctx->ssl_mac_pkey_id[SSL_MD_GOST89MAC12_IDX] = get_optional_pkey_id(SN_gost_mac_12); if (ctx->ssl_mac_pkey_id[SSL_MD_GOST89MAC12_IDX]) ctx->ssl_mac_secret_size[SSL_MD_GOST89MAC12_IDX] = 32; else ctx->disabled_mac_mask |= SSL_GOST89MAC12; - ctx->ssl_mac_pkey_id[SSL_MD_MAGMAOMAC_IDX] = 0; + ctx->ssl_mac_pkey_id[SSL_MD_MAGMAOMAC_IDX] = get_optional_pkey_id(SN_magma_mac); if (ctx->ssl_mac_pkey_id[SSL_MD_MAGMAOMAC_IDX]) ctx->ssl_mac_secret_size[SSL_MD_MAGMAOMAC_IDX] = 32; else ctx->disabled_mac_mask |= SSL_MAGMAOMAC; - ctx->ssl_mac_pkey_id[SSL_MD_KUZNYECHIKOMAC_IDX] = 0; + ctx->ssl_mac_pkey_id[SSL_MD_KUZNYECHIKOMAC_IDX] = get_optional_pkey_id(SN_kuznyechik_mac); if (ctx->ssl_mac_pkey_id[SSL_MD_KUZNYECHIKOMAC_IDX]) ctx->ssl_mac_secret_size[SSL_MD_KUZNYECHIKOMAC_IDX] = 32; else ctx->disabled_mac_mask |= SSL_KUZNYECHIKOMAC; - ctx->disabled_auth_mask |= SSL_aGOST01 | SSL_aGOST12; - ctx->disabled_auth_mask |= SSL_aGOST12; - ctx->disabled_auth_mask |= SSL_aGOST12; + if (!get_optional_pkey_id(SN_id_GostR3410_2001)) + ctx->disabled_auth_mask |= SSL_aGOST01 | SSL_aGOST12; + if (!get_optional_pkey_id(SN_id_GostR3410_2012_256)) + ctx->disabled_auth_mask |= SSL_aGOST12; + if (!get_optional_pkey_id(SN_id_GostR3410_2012_512)) + ctx->disabled_auth_mask |= SSL_aGOST12; /* * Disable GOST key exchange if no GOST signature algs are available * */ @@ -618,7 +644,7 @@ static void ssl_cipher_collect_ciphers(const SSL_METHOD *ssl_method, /* * We have num_of_ciphers descriptions compiled in, depending on the - * method selected (TLSv1, etc.). + * method selected (SSLv3, TLSv1 etc). * These will later be sorted in a linked list with at most num * entries. */ @@ -1014,17 +1040,17 @@ static int ssl_cipher_process_rulestr(const char *rule_str, * has the correct length. We can save a strlen() call: * just checking for the '\0' at the right place is * sufficient, we have to strncmp() anyway. (We cannot - * use strcasecmp(), because buf is not '\0' terminated.) + * use strcmp(), because buf is not '\0' terminated.) */ j = found = 0; cipher_id = 0; while (ca_list[j]) { - if (OPENSSL_strncasecmp(buf, ca_list[j]->name, buflen) == 0 + if (strncmp(buf, ca_list[j]->name, buflen) == 0 && (ca_list[j]->name[buflen] == '\0')) { found = 1; break; } else if (ca_list[j]->stdname != NULL - && OPENSSL_strncasecmp(buf, ca_list[j]->stdname, buflen) == 0 + && strncmp(buf, ca_list[j]->stdname, buflen) == 0 && ca_list[j]->stdname[buflen] == '\0') { found = 1; break; @@ -1139,10 +1165,9 @@ static int ssl_cipher_process_rulestr(const char *rule_str, */ if (rule == CIPHER_SPECIAL) { /* special command */ ok = 0; - if ((buflen == 8) && HAS_CASE_PREFIX(buf, "STRENGTH")) { + if ((buflen == 8) && HAS_PREFIX(buf, "STRENGTH")) { ok = ssl_cipher_strength_sort(head_p, tail_p); - } else if (buflen == 10 - && CHECK_AND_SKIP_CASE_PREFIX(buf, "SECLEVEL=")) { + } else if (buflen == 10 && CHECK_AND_SKIP_PREFIX(buf, "SECLEVEL=")) { int level = *buf - '0'; if (level < 0 || level > 5) { ERR_raise(ERR_LIB_SSL, SSL_R_INVALID_COMMAND); @@ -1183,14 +1208,14 @@ static int check_suiteb_cipher_list(const SSL_METHOD *meth, CERT *c, const char **prule_str) { unsigned int suiteb_flags = 0, suiteb_comb2 = 0; - if (HAS_CASE_PREFIX(*prule_str, "SUITEB128ONLY")) { + if (HAS_PREFIX(*prule_str, "SUITEB128ONLY")) { suiteb_flags = SSL_CERT_FLAG_SUITEB_128_LOS_ONLY; - } else if (HAS_CASE_PREFIX(*prule_str, "SUITEB128C2")) { + } else if (HAS_PREFIX(*prule_str, "SUITEB128C2")) { suiteb_comb2 = 1; suiteb_flags = SSL_CERT_FLAG_SUITEB_128_LOS; - } else if (HAS_CASE_PREFIX(*prule_str, "SUITEB128")) { + } else if (HAS_PREFIX(*prule_str, "SUITEB128")) { suiteb_flags = SSL_CERT_FLAG_SUITEB_128_LOS; - } else if (HAS_CASE_PREFIX(*prule_str, "SUITEB192")) { + } else if (HAS_PREFIX(*prule_str, "SUITEB192")) { suiteb_flags = SSL_CERT_FLAG_SUITEB_192_LOS; } @@ -1234,10 +1259,6 @@ static int ciphersuite_cb(const char *elem, int len, void *arg) /* Arbitrary sized temp buffer for the cipher name. Should be big enough */ char name[80]; - /* CONF_parse_list signals empty elements with elem == NULL; skip them */ - if (elem == NULL || len == 0) - return 1; - if (len > (int)(sizeof(name) - 1)) /* Anyway return 1 so we can parse rest of the list */ return 1; @@ -1245,16 +1266,11 @@ static int ciphersuite_cb(const char *elem, int len, void *arg) memcpy(name, elem, len); name[len] = '\0'; - cipher = ssl3_get_tls13_cipher_by_std_name(name); + cipher = ssl3_get_cipher_by_std_name(name); if (cipher == NULL) /* Ciphersuite not found but return 1 to parse rest of the list */ return 1; - /* Suppress duplicates */ - for (int i = 0; i < sk_SSL_CIPHER_num(ciphersuites); ++i) - if (sk_SSL_CIPHER_value(ciphersuites, i)->id == cipher->id) - return 1; - if (!sk_SSL_CIPHER_push(ciphersuites, cipher)) { ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); return 0; @@ -1550,7 +1566,7 @@ STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(SSL_CTX *ctx, */ ok = 1; rule_p = rule_str; - if (HAS_CASE_PREFIX(rule_str, "DEFAULT")) { + if (HAS_PREFIX(rule_str, "DEFAULT")) { ok = ssl_cipher_process_rulestr(OSSL_default_cipher_list(), &head, &tail, ca_list, c); rule_p += 7; @@ -1798,12 +1814,6 @@ char *SSL_CIPHER_description(const SSL_CIPHER *cipher, char *buf, int len) case SSL_CHACHA20POLY1305: enc = "CHACHA20/POLY1305(256)"; break; - case SSL_SM4GCM: - enc = "SM4GCM"; - break; - case SSL_SM4CCM: - enc = "SM4CCM"; - break; default: enc = "unknown"; break; @@ -1883,8 +1893,7 @@ const char *OPENSSL_cipher_name(const char *stdname) if (stdname == NULL) return "(NONE)"; - if ((c = ssl3_get_tls13_cipher_by_std_name(stdname)) == NULL) - c = ssl3_get_cipher_by_std_name(stdname); + c = ssl3_get_cipher_by_std_name(stdname); return SSL_CIPHER_get_name(c); } @@ -2221,117 +2230,3 @@ const char *OSSL_default_ciphersuites(void) "TLS_CHACHA20_POLY1305_SHA256:" "TLS_AES_128_GCM_SHA256"; } - -int ssl_cipher_list_to_bytes(SSL_CONNECTION *s, STACK_OF(SSL_CIPHER) *sk, - WPACKET *pkt) -{ - int i; - size_t totlen = 0, len, maxlen, maxverok = 0; - int empty_reneg_info_scsv = !s->renegotiate - && !SSL_CONNECTION_IS_DTLS(s) - && ssl_security(s, SSL_SECOP_VERSION, 0, TLS1_VERSION, NULL) - && s->min_proto_version <= TLS1_VERSION; - SSL *ssl = SSL_CONNECTION_GET_SSL(s); - - /* Set disabled masks for this session */ - if (!ssl_set_client_disabled(s)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_NO_PROTOCOLS_AVAILABLE); - return 0; - } - - if (sk == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - -#ifdef OPENSSL_MAX_TLS1_2_CIPHER_LENGTH -#if OPENSSL_MAX_TLS1_2_CIPHER_LENGTH < 6 -#error Max cipher length too short -#endif - /* - * Some servers hang if client hello > 256 bytes as hack workaround - * chop number of supported ciphers to keep it well below this if we - * use TLS v1.2 - */ - if (TLS1_get_version(ssl) >= TLS1_2_VERSION) - maxlen = OPENSSL_MAX_TLS1_2_CIPHER_LENGTH & ~1; - else -#endif - /* Maximum length that can be stored in 2 bytes. Length must be even */ - maxlen = 0xfffe; - - if (empty_reneg_info_scsv) - maxlen -= 2; - if (s->mode & SSL_MODE_SEND_FALLBACK_SCSV) - maxlen -= 2; - - /* RFC 8701: prepend a GREASE cipher suite value */ - if ((s->options & SSL_OP_GREASE) && !s->server) { - uint16_t grease_cs = ossl_grease_value(s, OSSL_GREASE_CIPHER); - - if (!WPACKET_put_bytes_u16(pkt, grease_cs)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - totlen += 2; - } - - for (i = 0; i < sk_SSL_CIPHER_num(sk) && totlen < maxlen; i++) { - const SSL_CIPHER *c; - - c = sk_SSL_CIPHER_value(sk, i); - /* Skip disabled ciphers */ - if (ssl_cipher_disabled(s, c, SSL_SECOP_CIPHER_SUPPORTED)) - continue; - - if (!ssl->method->put_cipher_by_char(c, pkt, &len)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - - /* Sanity check that the maximum version we offer has ciphers enabled */ - if (!maxverok) { - int minproto = SSL_CONNECTION_IS_DTLS(s) ? c->min_dtls : c->min_tls; - int maxproto = SSL_CONNECTION_IS_DTLS(s) ? c->max_dtls : c->max_tls; - - if (ssl_version_cmp(s, maxproto, s->s3.tmp.max_ver) >= 0 - && ssl_version_cmp(s, minproto, s->s3.tmp.max_ver) <= 0) - maxverok = 1; - } - - totlen += len; - } - - if (totlen == 0 || !maxverok) { - const char *maxvertext = !maxverok - ? "No ciphers enabled for max supported SSL/TLS version" - : NULL; - - SSLfatal_data(s, SSL_AD_INTERNAL_ERROR, SSL_R_NO_CIPHERS_AVAILABLE, - maxvertext); - return 0; - } - - if (totlen != 0) { - if (empty_reneg_info_scsv) { - static const SSL_CIPHER scsv = { - 0, NULL, NULL, SSL3_CK_SCSV, 0, 0, 0, 0, 0, 0, 0, 0, 0 - }; - if (!ssl->method->put_cipher_by_char(&scsv, pkt, &len)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - } - if (s->mode & SSL_MODE_SEND_FALLBACK_SCSV) { - static const SSL_CIPHER scsv = { - 0, NULL, NULL, SSL3_CK_FALLBACK_SCSV, 0, 0, 0, 0, 0, 0, 0, 0, 0 - }; - if (!ssl->method->put_cipher_by_char(&scsv, pkt, &len)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - } - } - - return 1; -} diff --git a/ssl/ssl_conf.c b/ssl/ssl_conf.c index a7293512b9..0d61def3dd 100644 --- a/ssl/ssl_conf.c +++ b/ssl/ssl_conf.c @@ -1,5 +1,5 @@ /* - * Copyright 2012-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2012-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -1123,14 +1123,6 @@ void SSL_CONF_CTX_free(SSL_CONF_CTX *cctx) unsigned int SSL_CONF_CTX_set_flags(SSL_CONF_CTX *cctx, unsigned int flags) { - if ((cctx->flags & SSL_CONF_FLAG_CMDLINE) - && (flags & SSL_CONF_FLAG_FILE)) - flags &= ~SSL_CONF_FLAG_FILE; - - if ((cctx->flags & SSL_CONF_FLAG_FILE) - && (flags & SSL_CONF_FLAG_CMDLINE)) - flags &= ~SSL_CONF_FLAG_CMDLINE; - cctx->flags |= flags; return cctx->flags; } diff --git a/ssl/ssl_init.c b/ssl/ssl_init.c index 634fd39237..1e92658b7a 100644 --- a/ssl/ssl_init.c +++ b/ssl/ssl_init.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -15,6 +15,7 @@ #include #include "ssl_local.h" #include "internal/thread_once.h" +#include "internal/rio_notifier.h" /* for ossl_wsa_cleanup() */ static int stopped; diff --git a/ssl/ssl_lib.c b/ssl/ssl_lib.c index 57d74f9091..a305c8d0d9 100644 --- a/ssl/ssl_lib.c +++ b/ssl/ssl_lib.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * Copyright 2005 Nokia. All rights reserved. * @@ -20,7 +20,6 @@ #include #include #include -#include #include #include #include @@ -495,7 +494,7 @@ static int ssl_check_allowed_versions(int min_version, int max_version) } else { /* Regular TLS version checks. */ if (min_version == 0) - min_version = TLS1_VERSION; + min_version = SSL3_VERSION; if (max_version == 0) max_version = TLS1_3_VERSION; #ifdef OPENSSL_NO_TLS1_3 @@ -510,6 +509,14 @@ static int ssl_check_allowed_versions(int min_version, int max_version) if (max_version == TLS1_1_VERSION) max_version = TLS1_VERSION; #endif +#ifdef OPENSSL_NO_TLS1 + if (max_version == TLS1_VERSION) + max_version = SSL3_VERSION; +#endif +#ifdef OPENSSL_NO_SSL3 + if (min_version == SSL3_VERSION) + min_version = TLS1_VERSION; +#endif #ifdef OPENSSL_NO_TLS1 if (min_version == TLS1_VERSION) min_version = TLS1_1_VERSION; @@ -524,6 +531,9 @@ static int ssl_check_allowed_versions(int min_version, int max_version) #endif /* Done massaging versions; do the check. */ if (0 +#ifdef OPENSSL_NO_SSL3 + || (min_version <= SSL3_VERSION && SSL3_VERSION <= max_version) +#endif #ifdef OPENSSL_NO_TLS1 || (min_version <= TLS1_VERSION && TLS1_VERSION <= max_version) #endif @@ -819,6 +829,15 @@ SSL *ossl_ssl_connection_new_int(SSL_CTX *ctx, SSL *user_ssl, goto err; s->session_ctx = ctx; + if (ctx->ext.ecpointformats != NULL) { + s->ext.ecpointformats = OPENSSL_memdup(ctx->ext.ecpointformats, + ctx->ext.ecpointformats_len); + if (s->ext.ecpointformats == NULL) { + s->ext.ecpointformats_len = 0; + goto err; + } + s->ext.ecpointformats_len = ctx->ext.ecpointformats_len; + } if (ctx->ext.supportedgroups != NULL) { size_t add = 0; @@ -936,11 +955,6 @@ SSL *ossl_ssl_connection_new_int(SSL_CTX *ctx, SSL *user_ssl, goto sslerr; #endif -#ifndef OPENSSL_NO_ECH - if (!ossl_ech_conn_init(s, ctx, method)) - goto sslerr; -#endif - s->ssl_pkey_num = SSL_PKEY_NUM + ctx->sigalg_list_len; return ssl; cerr: @@ -1001,18 +1015,11 @@ int SSL_CTX_is_quic(const SSL_CTX *c) return IS_QUIC_CTX(c); } -int SSL_CTX_is_server(const SSL_CTX *c) -{ - if (c == NULL || c->method == NULL) - return 0; - return (c->method->ssl_accept == ssl_undefined_function) ? 0 : 1; -} - int SSL_up_ref(SSL *s) { int i; - if (!CRYPTO_UP_REF(&s->references, &i)) + if (CRYPTO_UP_REF(&s->references, &i) <= 0) return 0; REF_PRINT_COUNT("SSL", i, s); @@ -1128,47 +1135,6 @@ int SSL_set_trust(SSL *s, int trust) return X509_VERIFY_PARAM_set_trust(sc->param, trust); } -int SSL_set1_dnsname(SSL *s, const char *host) -{ - SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); - - if (sc == NULL) - return 0; - - return X509_VERIFY_PARAM_set1_host(sc->param, host, 0); -} - -int SSL_add1_dnsname(SSL *s, const char *host) -{ - SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); - - if (sc == NULL) - return 0; - - return X509_VERIFY_PARAM_add1_host(sc->param, host, strlen(host)); -} - -int SSL_set1_ipaddr(SSL *s, const char *ipaddr) -{ - SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); - - if (sc == NULL) - return 0; - - return X509_VERIFY_PARAM_set1_ip_asc(sc->param, ipaddr); -} - -int SSL_add1_ipaddr(SSL *s, const char *ipaddr) -{ - SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); - - if (sc == NULL) - return 0; - - return X509_VERIFY_PARAM_add1_ip_asc(sc->param, ipaddr); -} - -#if !defined(OPENSSL_NO_DEPRECATED_4_0) int SSL_set1_host(SSL *s, const char *host) { SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); @@ -1219,7 +1185,6 @@ int SSL_add1_host(SSL *s, const char *host) return X509_VERIFY_PARAM_add1_host(sc->param, host, 0); } -#endif /* !defined(OPENSSL_NO_DEPRECATED_4_0) */ void SSL_set_hostflags(SSL *s, unsigned int flags) { @@ -1518,6 +1483,7 @@ void ossl_ssl_connection_free(SSL *ssl) OPENSSL_free(s->ext.hostname); SSL_CTX_free(s->session_ctx); + OPENSSL_free(s->ext.ecpointformats); OPENSSL_free(s->ext.peer_ecpointformats); OPENSSL_free(s->ext.supportedgroups); OPENSSL_free(s->ext.keyshares); @@ -1578,9 +1544,6 @@ void ossl_ssl_connection_free(SSL *ssl) BIO_free_all(s->rbio); s->rbio = NULL; OPENSSL_free(s->s3.tmp.valid_flags); -#ifndef OPENSSL_NO_ECH - ossl_ech_conn_clear(&s->ext.ech); -#endif } void SSL_set0_rbio(SSL *s, BIO *rbio) @@ -2088,9 +2051,7 @@ int SSL_copy_session_id(SSL *t, const SSL *f) return 0; } - if (!CRYPTO_UP_REF(&fsc->cert->references, &i)) - return 0; - + CRYPTO_UP_REF(&fsc->cert->references, &i); ssl_cert_free(tsc->cert); tsc->cert = fsc->cert; if (!SSL_set_session_id_context(t, fsc->sid_ctx, (int)fsc->sid_ctx_length)) { @@ -2224,60 +2185,13 @@ int SSL_get_async_status(SSL *s, int *status) return 1; } -/* - * Reset the statem error_state to ERROR_STATE_NOERROR to avoid the - * error sticking. - * Designed to be called at the beginning of any function that - * is expected to be followed by a call to SSL_get_error(). - * It returns 0 if the state machine is in the MSG_FLOW_ERROR state, - * in this case the calling function can and should return immediately. - */ -static int ssl_reset_error_state(SSL_CONNECTION *sc) -{ - if (sc == NULL) - return 1; - - if (sc->statem.state == MSG_FLOW_ERROR) { - sc->statem.error_state = ERROR_STATE_SSL; - return 0; - } - - sc->statem.error_state = ERROR_STATE_NOERROR; - return 1; -} - -/* - * Check if the connection failed into the MSG_FLOW_ERROR state during - * the operation, if so, check the error stack and set the error_state - * correspondently. - * Designed to be called at the end of any function that - * is expected to be followed by a call to SSL_get_error(). - */ -static void ssl_update_error_state(SSL_CONNECTION *sc) -{ - unsigned long l; - - if (sc == NULL) - return; - - if (sc->statem.state == MSG_FLOW_ERROR - && sc->statem.error_state == ERROR_STATE_NOERROR) { - l = ERR_peek_error(); - if (l == 0 || ERR_GET_LIB(l) == ERR_LIB_SYS) - sc->statem.error_state = ERROR_STATE_SYSCALL; - else - sc->statem.error_state = ERROR_STATE_SSL; - } -} - int SSL_accept(SSL *s) { SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); #ifndef OPENSSL_NO_QUIC - if (IS_QUIC(s)) { + if (IS_QUIC(s)) return s->method->ssl_accept(s); - } #endif if (sc == NULL) @@ -2296,9 +2210,8 @@ int SSL_connect(SSL *s) SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); #ifndef OPENSSL_NO_QUIC - if (IS_QUIC(s)) { + if (IS_QUIC(s)) return s->method->ssl_connect(s); - } #endif if (sc == NULL) @@ -2352,7 +2265,6 @@ static int ssl_start_async_job(SSL *s, struct ssl_async_args *args, case ASYNC_ERR: sc->rwstate = SSL_NOTHING; ERR_raise(ERR_LIB_SSL, SSL_R_FAILED_TO_INIT_ASYNC); - sc->statem.error_state = ERROR_STATE_SSL; return -1; case ASYNC_PAUSE: sc->rwstate = SSL_ASYNC_PAUSED; @@ -2366,7 +2278,6 @@ static int ssl_start_async_job(SSL *s, struct ssl_async_args *args, default: sc->rwstate = SSL_NOTHING; ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); - sc->statem.error_state = ERROR_STATE_SSL; /* Shouldn't happen */ return -1; } @@ -2400,7 +2311,6 @@ static int ssl_io_intern(void *vargs) int ssl_read_internal(SSL *s, void *buf, size_t num, size_t *readbytes) { - int ret; SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); #ifndef OPENSSL_NO_QUIC @@ -2411,12 +2321,8 @@ int ssl_read_internal(SSL *s, void *buf, size_t num, size_t *readbytes) if (sc == NULL) return -1; - if (ssl_reset_error_state(sc) == 0) - return -1; - if (sc->handshake_func == NULL) { ERR_raise(ERR_LIB_SSL, SSL_R_UNINITIALIZED); - sc->statem.error_state = ERROR_STATE_SSL; return -1; } @@ -2428,7 +2334,6 @@ int ssl_read_internal(SSL *s, void *buf, size_t num, size_t *readbytes) if (sc->early_data_state == SSL_EARLY_DATA_CONNECT_RETRY || sc->early_data_state == SSL_EARLY_DATA_ACCEPT_RETRY) { ERR_raise(ERR_LIB_SSL, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED); - sc->statem.error_state = ERROR_STATE_SSL; return 0; } /* @@ -2440,6 +2345,7 @@ int ssl_read_internal(SSL *s, void *buf, size_t num, size_t *readbytes) if ((sc->mode & SSL_MODE_ASYNC) && ASYNC_get_current_job() == NULL) { struct ssl_async_args args; + int ret; args.s = s; args.buf = buf; @@ -2449,12 +2355,9 @@ int ssl_read_internal(SSL *s, void *buf, size_t num, size_t *readbytes) ret = ssl_start_async_job(s, &args, ssl_io_intern); *readbytes = sc->asyncrw; - ssl_update_error_state(sc); return ret; } else { - ret = s->method->ssl_read(s, buf, num, readbytes); - ssl_update_error_state(sc); - return ret; + return s->method->ssl_read(s, buf, num, readbytes); } } @@ -2462,12 +2365,9 @@ int SSL_read(SSL *s, void *buf, int num) { int ret; size_t readbytes; - SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); if (num < 0) { ERR_raise(ERR_LIB_SSL, SSL_R_BAD_LENGTH); - if (sc != NULL) - sc->statem.error_state = ERROR_STATE_SSL; return -1; } @@ -2485,12 +2385,10 @@ int SSL_read(SSL *s, void *buf, int num) int SSL_read_ex(SSL *s, void *buf, size_t num, size_t *readbytes) { - int ret; + int ret = ssl_read_internal(s, buf, num, readbytes); - ret = ssl_read_internal(s, buf, num, readbytes); if (ret < 0) ret = 0; - return ret; } @@ -2500,25 +2398,15 @@ int SSL_read_early_data(SSL *s, void *buf, size_t num, size_t *readbytes) SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL_ONLY(s); /* TODO(QUIC 0RTT): 0-RTT support */ - if (sc == NULL) { + if (sc == NULL || !sc->server) { ERR_raise(ERR_LIB_SSL, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED); return SSL_READ_EARLY_DATA_ERROR; } - if (ssl_reset_error_state(sc) == 0) - return 0; - - if (!sc->server) { - ERR_raise(ERR_LIB_SSL, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED); - sc->statem.error_state = ERROR_STATE_SSL; - return SSL_READ_EARLY_DATA_ERROR; - } - switch (sc->early_data_state) { case SSL_EARLY_DATA_NONE: if (!SSL_in_before(s)) { ERR_raise(ERR_LIB_SSL, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED); - sc->statem.error_state = ERROR_STATE_SSL; return SSL_READ_EARLY_DATA_ERROR; } /* fall through */ @@ -2555,7 +2443,6 @@ int SSL_read_early_data(SSL *s, void *buf, size_t num, size_t *readbytes) default: ERR_raise(ERR_LIB_SSL, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED); - sc->statem.error_state = ERROR_STATE_SSL; return SSL_READ_EARLY_DATA_ERROR; } } @@ -2573,7 +2460,6 @@ int SSL_get_early_data_status(const SSL *s) static int ssl_peek_internal(SSL *s, void *buf, size_t num, size_t *readbytes) { - int ret; SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); #ifndef OPENSSL_NO_QUIC @@ -2584,12 +2470,8 @@ static int ssl_peek_internal(SSL *s, void *buf, size_t num, size_t *readbytes) if (sc == NULL) return 0; - if (ssl_reset_error_state(sc) == 0) - return -1; - if (sc->handshake_func == NULL) { ERR_raise(ERR_LIB_SSL, SSL_R_UNINITIALIZED); - sc->statem.error_state = ERROR_STATE_SSL; return -1; } @@ -2598,6 +2480,7 @@ static int ssl_peek_internal(SSL *s, void *buf, size_t num, size_t *readbytes) } if ((sc->mode & SSL_MODE_ASYNC) && ASYNC_get_current_job() == NULL) { struct ssl_async_args args; + int ret; args.s = s; args.buf = buf; @@ -2607,12 +2490,9 @@ static int ssl_peek_internal(SSL *s, void *buf, size_t num, size_t *readbytes) ret = ssl_start_async_job(s, &args, ssl_io_intern); *readbytes = sc->asyncrw; - ssl_update_error_state(sc); return ret; } else { - ret = s->method->ssl_peek(s, buf, num, readbytes); - ssl_update_error_state(sc); - return ret; + return s->method->ssl_peek(s, buf, num, readbytes); } } @@ -2620,12 +2500,9 @@ int SSL_peek(SSL *s, void *buf, int num) { int ret; size_t readbytes; - SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); if (num < 0) { ERR_raise(ERR_LIB_SSL, SSL_R_BAD_LENGTH); - if (sc != NULL) - sc->statem.error_state = ERROR_STATE_SSL; return -1; } @@ -2643,19 +2520,16 @@ int SSL_peek(SSL *s, void *buf, int num) int SSL_peek_ex(SSL *s, void *buf, size_t num, size_t *readbytes) { - int ret; + int ret = ssl_peek_internal(s, buf, num, readbytes); - ret = ssl_peek_internal(s, buf, num, readbytes); if (ret < 0) ret = 0; - return ret; } int ssl_write_internal(SSL *s, const void *buf, size_t num, uint64_t flags, size_t *written) { - int ret; SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); #ifndef OPENSSL_NO_QUIC @@ -2666,25 +2540,19 @@ int ssl_write_internal(SSL *s, const void *buf, size_t num, if (sc == NULL) return 0; - if (ssl_reset_error_state(sc) == 0) - return -1; - if (sc->handshake_func == NULL) { ERR_raise(ERR_LIB_SSL, SSL_R_UNINITIALIZED); - sc->statem.error_state = ERROR_STATE_SSL; return -1; } if (sc->shutdown & SSL_SENT_SHUTDOWN) { sc->rwstate = SSL_NOTHING; ERR_raise(ERR_LIB_SSL, SSL_R_PROTOCOL_IS_SHUTDOWN); - sc->statem.error_state = ERROR_STATE_SSL; return -1; } if (flags != 0) { ERR_raise(ERR_LIB_SSL, SSL_R_UNSUPPORTED_WRITE_FLAG); - sc->statem.error_state = ERROR_STATE_SSL; return -1; } @@ -2692,7 +2560,6 @@ int ssl_write_internal(SSL *s, const void *buf, size_t num, || sc->early_data_state == SSL_EARLY_DATA_ACCEPT_RETRY || sc->early_data_state == SSL_EARLY_DATA_READ_RETRY) { ERR_raise(ERR_LIB_SSL, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED); - sc->statem.error_state = ERROR_STATE_SSL; return 0; } /* If we are a client and haven't sent the Finished we better do that */ @@ -2700,6 +2567,7 @@ int ssl_write_internal(SSL *s, const void *buf, size_t num, return -1; if ((sc->mode & SSL_MODE_ASYNC) && ASYNC_get_current_job() == NULL) { + int ret; struct ssl_async_args args; args.s = s; @@ -2710,52 +2578,39 @@ int ssl_write_internal(SSL *s, const void *buf, size_t num, ret = ssl_start_async_job(s, &args, ssl_io_intern); *written = sc->asyncrw; - ssl_update_error_state(sc); return ret; } else { - ret = s->method->ssl_write(s, buf, num, written); - ssl_update_error_state(sc); - return ret; + return s->method->ssl_write(s, buf, num, written); } } ossl_ssize_t SSL_sendfile(SSL *s, int fd, off_t offset, size_t size, int flags) { + ossl_ssize_t ret; SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL_ONLY(s); -#ifndef OPENSSL_NO_KTLS - ossl_ssize_t sbytes; -#endif - int ret; if (sc == NULL) return 0; - if (ssl_reset_error_state(sc) == 0) - return -1; - if (sc->handshake_func == NULL) { ERR_raise(ERR_LIB_SSL, SSL_R_UNINITIALIZED); - sc->statem.error_state = ERROR_STATE_SSL; return -1; } if (sc->shutdown & SSL_SENT_SHUTDOWN) { sc->rwstate = SSL_NOTHING; ERR_raise(ERR_LIB_SSL, SSL_R_PROTOCOL_IS_SHUTDOWN); - sc->statem.error_state = ERROR_STATE_SSL; return -1; } if (!BIO_get_ktls_send(sc->wbio)) { ERR_raise(ERR_LIB_SSL, SSL_R_UNINITIALIZED); - sc->statem.error_state = ERROR_STATE_SSL; return -1; } /* If we have an alert to send, lets send it */ if (sc->s3.alert_dispatch > 0) { ret = (ossl_ssize_t)s->method->ssl_dispatch_alert(s); - ssl_update_error_state(sc); if (ret <= 0) { /* SSLfatal() already called if appropriate */ return ret; @@ -2778,25 +2633,21 @@ ossl_ssize_t SSL_sendfile(SSL *s, int fd, off_t offset, size_t size, int flags) #ifdef OPENSSL_NO_KTLS ERR_raise_data(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR, "can't call ktls_sendfile(), ktls disabled"); - sc->statem.error_state = ERROR_STATE_SSL; return -1; #else - ret = ktls_sendfile(SSL_get_wfd(s), fd, offset, size, &sbytes, flags); - ssl_update_error_state(sc); - BIO_clear_retry_flags(sc->wbio); + ret = ktls_sendfile(SSL_get_wfd(s), fd, offset, size, flags); if (ret < 0) { - if (BIO_sock_should_retry(ret)) { +#if defined(EAGAIN) && defined(EINTR) && defined(EBUSY) + if ((get_last_sys_error() == EAGAIN) || (get_last_sys_error() == EINTR) || (get_last_sys_error() == EBUSY)) BIO_set_retry_write(sc->wbio); - return (sbytes > 0 ? sbytes : ret); - } else { + else +#endif ERR_raise_data(ERR_LIB_SYS, get_last_sys_error(), "ktls_sendfile failure"); - sc->statem.error_state = ERROR_STATE_SYSCALL; - } return ret; } sc->rwstate = SSL_NOTHING; - return sbytes; + return ret; #endif } @@ -2804,12 +2655,9 @@ int SSL_write(SSL *s, const void *buf, int num) { int ret; size_t written; - SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); if (num < 0) { ERR_raise(ERR_LIB_SSL, SSL_R_BAD_LENGTH); - if (sc != NULL) - sc->statem.error_state = ERROR_STATE_SSL; return -1; } @@ -2833,12 +2681,10 @@ int SSL_write_ex(SSL *s, const void *buf, size_t num, size_t *written) int SSL_write_ex2(SSL *s, const void *buf, size_t num, uint64_t flags, size_t *written) { - int ret; + int ret = ssl_write_internal(s, buf, num, flags, written); - ret = ssl_write_internal(s, buf, num, flags, written); if (ret < 0) ret = 0; - return ret; } @@ -2853,9 +2699,6 @@ int SSL_write_early_data(SSL *s, const void *buf, size_t num, size_t *written) if (sc == NULL) return 0; - if (ssl_reset_error_state(sc) == 0) - return 0; - switch (sc->early_data_state) { case SSL_EARLY_DATA_NONE: if (sc->server @@ -2863,7 +2706,6 @@ int SSL_write_early_data(SSL *s, const void *buf, size_t num, size_t *written) || ((sc->session == NULL || sc->session->ext.max_early_data == 0) && (sc->psk_use_session_cb == NULL))) { ERR_raise(ERR_LIB_SSL, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED); - sc->statem.error_state = ERROR_STATE_SSL; return 0; } /* fall through */ @@ -2918,7 +2760,6 @@ int SSL_write_early_data(SSL *s, const void *buf, size_t num, size_t *written) default: ERR_raise(ERR_LIB_SSL, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED); - sc->statem.error_state = ERROR_STATE_SSL; return 0; } } @@ -2932,10 +2773,6 @@ int SSL_shutdown(SSL *s) * (see ssl3_shutdown). */ SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); - int ret; - - if (ssl_reset_error_state(sc) == 0) - return -1; #ifndef OPENSSL_NO_QUIC if (IS_QUIC(s)) @@ -2947,7 +2784,6 @@ int SSL_shutdown(SSL *s) if (sc->handshake_func == NULL) { ERR_raise(ERR_LIB_SSL, SSL_R_UNINITIALIZED); - sc->statem.error_state = ERROR_STATE_SSL; return -1; } @@ -2960,18 +2796,14 @@ int SSL_shutdown(SSL *s) args.type = OTHERFUNC; args.f.func_other = s->method->ssl_shutdown; - ret = ssl_start_async_job(s, &args, ssl_io_intern); + return ssl_start_async_job(s, &args, ssl_io_intern); } else { - ret = s->method->ssl_shutdown(s); + return s->method->ssl_shutdown(s); } } else { ERR_raise(ERR_LIB_SSL, SSL_R_SHUTDOWN_WHILE_IN_INIT); - sc->statem.error_state = ERROR_STATE_SSL; return -1; } - - ssl_update_error_state(sc); - return ret; } int SSL_key_update(SSL *s, int updatetype) @@ -3457,7 +3289,7 @@ STACK_OF(SSL_CIPHER) *SSL_get1_supported_ciphers(SSL *s) return NULL; for (i = 0; i < sk_SSL_CIPHER_num(ciphers); i++) { const SSL_CIPHER *c = sk_SSL_CIPHER_value(ciphers, i); - if (!ssl_cipher_disabled(sc, c, SSL_SECOP_CIPHER_SUPPORTED)) { + if (!ssl_cipher_disabled(sc, c, SSL_SECOP_CIPHER_SUPPORTED, 0)) { if (!sk) sk = sk_SSL_CIPHER_new_null(); if (!sk) @@ -3587,21 +3419,22 @@ char *SSL_get_shared_ciphers(const SSL *s, char *buf, int size) int i; const SSL_CONNECTION *sc = SSL_CONNECTION_FROM_CONST_SSL(s); - if (size < 2 || buf == NULL) + if (sc == NULL) return NULL; - buf[0] = '\0'; - - if (sc == NULL || !sc->server) + if (!sc->server + || sc->peer_ciphers == NULL + || size < 2) return NULL; p = buf; clntsk = sc->peer_ciphers; srvrsk = SSL_get_ciphers(s); + if (clntsk == NULL || srvrsk == NULL) + return NULL; - if (clntsk == NULL || sk_SSL_CIPHER_num(clntsk) == 0 - || srvrsk == NULL || sk_SSL_CIPHER_num(srvrsk) == 0) - return buf; + if (sk_SSL_CIPHER_num(clntsk) == 0 || sk_SSL_CIPHER_num(srvrsk) == 0) + return NULL; for (i = 0; i < sk_SSL_CIPHER_num(clntsk); i++) { int n; @@ -3621,9 +3454,10 @@ char *SSL_get_shared_ciphers(const SSL *s, char *buf, int size) } /* No overlap */ - if (p != buf) - p[-1] = '\0'; + if (p == buf) + return NULL; + p[-1] = '\0'; return buf; } @@ -3637,7 +3471,7 @@ char *SSL_get_shared_ciphers(const SSL *s, char *buf, int size) * * Note that only the host_name type is defined (RFC 3546). */ -const char *SSL_get_servername(const SSL *s, int type) +const char *SSL_get_servername(const SSL *s, const int type) { const SSL_CONNECTION *sc = SSL_CONNECTION_FROM_CONST_SSL(s); int server; @@ -3944,47 +3778,6 @@ int SSL_set_alpn_protos(SSL *ssl, const unsigned char *protos, return 0; } -/* - * SSL_CTX_set_get0_protos gets the ALPN protocol list on |ctx| to |protos|. - */ -void SSL_CTX_get0_alpn_protos(SSL_CTX *ctx, const unsigned char **protos, - unsigned int *protos_len) -{ - unsigned char *p = NULL; - unsigned int len = 0; - - if (ctx != NULL) { - p = ctx->ext.alpn; - len = (unsigned int)ctx->ext.alpn_len; - } - - if (protos != NULL) - *protos = p; - if (protos_len != NULL) - *protos_len = len; -} - -/* - * SSL_get0_alpn_protos gets the ALPN protocol list on |ssl| to |protos|. - */ -void SSL_get0_alpn_protos(SSL *ssl, const unsigned char **protos, - unsigned int *protos_len) -{ - SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(ssl); - unsigned char *p = NULL; - unsigned int len = 0; - - if (sc != NULL) { - p = sc->ext.alpn; - len = (unsigned int)sc->ext.alpn_len; - } - - if (protos != NULL) - *protos = p; - if (protos_len != NULL) - *protos_len = len; -} - /* * SSL_CTX_set_alpn_select_cb sets a callback function on |ctx| that is * called during ClientHello processing in order to select an ALPN protocol @@ -4251,17 +4044,6 @@ SSL_CTX *SSL_CTX_new_ex(OSSL_LIB_CTX *libctx, const char *propq, goto err; } - if ((ret->hmac = EVP_MAC_fetch(libctx, "HMAC", propq)) == NULL) - goto err; - if ((ret->sha256 = EVP_MD_fetch(libctx, "SHA2-256", propq)) == NULL) - goto err; - if ((ret->tktenc = EVP_CIPHER_fetch(libctx, "AES-256-CBC", propq)) == NULL) - goto err; -#if defined(OPENSSL_HAVE_TLS1PRF) - if ((ret->tls1prf = EVP_KDF_fetch(libctx, OSSL_KDF_NAME_TLS1_PRF, propq)) == NULL) - goto err; -#endif - ret->method = meth; ret->min_proto_version = 0; ret->max_proto_version = 0; @@ -4339,6 +4121,15 @@ SSL_CTX *SSL_CTX_new_ex(OSSL_LIB_CTX *libctx, const char *propq, goto err; } + /* + * If these aren't available from the provider we'll get NULL returns. + * That's fine but will cause errors later if SSLv3 is negotiated + */ + ERR_set_mark(); + ret->md5 = EVP_MD_fetch(libctx, "MD5", propq); + ret->sha1 = EVP_MD_fetch(libctx, "SHA1", propq); + ERR_pop_to_mark(); + if ((ret->ca_names = sk_X509_NAME_new_null()) == NULL) { ERR_raise(ERR_LIB_SSL, ERR_R_CRYPTO_LIB); goto err; @@ -4534,7 +4325,7 @@ int SSL_CTX_up_ref(SSL_CTX *ctx) { int i; - if (!CRYPTO_UP_REF(&ctx->references, &i)) + if (CRYPTO_UP_REF(&ctx->references, &i) <= 0) return 0; REF_PRINT_COUNT("SSL_CTX", i, ctx); @@ -4580,13 +4371,6 @@ void SSL_CTX_free(SSL_CTX *a) if (a->sessions != NULL) SSL_CTX_flush_sessions_ex(a, 0); - EVP_MAC_free(a->hmac); - EVP_MD_free(a->sha256); - EVP_CIPHER_free(a->tktenc); -#ifdef OPENSSL_HAVE_TLS1PRF - EVP_KDF_free(a->tls1prf); -#endif - CRYPTO_free_ex_data(CRYPTO_EX_INDEX_SSL_CTX, a, &a->ex_data); lh_SSL_SESSION_free(a->sessions); X509_STORE_free(a->cert_store); @@ -4608,12 +4392,16 @@ void SSL_CTX_free(SSL_CTX *a) ssl_ctx_srp_ctx_free_intern(a); #endif + OPENSSL_free(a->ext.ecpointformats); OPENSSL_free(a->ext.supportedgroups); OPENSSL_free(a->ext.keyshares); OPENSSL_free(a->ext.tuples); OPENSSL_free(a->ext.alpn); OPENSSL_secure_clear_free(a->ext.secure, sizeof(*a->ext.secure)); + ssl_evp_md_free(a->md5); + ssl_evp_md_free(a->sha1); + for (j = 0; j < SSL_ENC_NUM_IDX; j++) ssl_evp_cipher_free(a->ssl_cipher_methods[j]); for (j = 0; j < SSL_MD_NUM_IDX; j++) @@ -4659,10 +4447,6 @@ void SSL_CTX_free(SSL_CTX *a) ossl_quic_free_token_store(a->tokencache); #endif -#ifndef OPENSSL_NO_ECH - ossl_ech_ctx_clear(&a->ext.ech); -#endif - OPENSSL_free(a); } @@ -4774,10 +4558,7 @@ void ssl_set_masks(SSL_CONNECTION *s) dh_tmp = (c->dh_tmp != NULL || c->dh_tmp_cb != NULL - || c->dh_tmp_auto - || tls1_shared_group(s, TLS1_GROUPS_RETURN_TMP_ID, - TLS1_GROUPS_FFDHE_GROUPS) - != 0); + || c->dh_tmp_auto); rsa_enc = pvalid[SSL_PKEY_RSA] & CERT_PKEY_VALID; rsa_sign = pvalid[SSL_PKEY_RSA] & CERT_PKEY_VALID; @@ -4812,13 +4593,10 @@ void ssl_set_masks(SSL_CONNECTION *s) /* * If we only have an RSA-PSS certificate allow RSA authentication - * if TLS 1.2 or DTLS 1.2 and peer supports it. + * if TLS 1.2 and peer supports it. */ - if (rsa_enc || rsa_sign - || (ssl_has_cert(s, SSL_PKEY_RSA_PSS_SIGN) - && pvalid[SSL_PKEY_RSA_PSS_SIGN] & CERT_PKEY_EXPLICIT_SIGN - && (SSL_version(&s->ssl) == XTLS(&s->ssl, 1, 2)))) + if (rsa_enc || rsa_sign || (ssl_has_cert(s, SSL_PKEY_RSA_PSS_SIGN) && pvalid[SSL_PKEY_RSA_PSS_SIGN] & CERT_PKEY_EXPLICIT_SIGN && TLS1_get_version(&s->ssl) == TLS1_2_VERSION)) mask_a |= SSL_aRSA; if (dsa_sign) { @@ -4837,7 +4615,7 @@ void ssl_set_masks(SSL_CONNECTION *s) } if (pvalid[SSL_PKEY_ECC] & CERT_PKEY_RPK) mask_a |= SSL_aECDSA; - if (SSL_version(&s->ssl) == XTLS(&s->ssl, 1, 2)) { + if (TLS1_get_version(&s->ssl) == TLS1_2_VERSION) { if (pvalid[SSL_PKEY_RSA_PSS_SIGN] & CERT_PKEY_RPK) mask_a |= SSL_aRSA; if (pvalid[SSL_PKEY_ED25519] & CERT_PKEY_RPK @@ -4858,16 +4636,16 @@ void ssl_set_masks(SSL_CONNECTION *s) if (ecdsa_ok) mask_a |= SSL_aECDSA; } - /* Allow Ed25519 for TLS 1.2 and DTLS 1.2 if peer supports it */ + /* Allow Ed25519 for TLS 1.2 if peer supports it */ if (!(mask_a & SSL_aECDSA) && ssl_has_cert(s, SSL_PKEY_ED25519) && pvalid[SSL_PKEY_ED25519] & CERT_PKEY_EXPLICIT_SIGN - && (SSL_version(&s->ssl) == XTLS(&s->ssl, 1, 2))) + && TLS1_get_version(&s->ssl) == TLS1_2_VERSION) mask_a |= SSL_aECDSA; - /* Allow Ed448 for TLS 1.2 and DTLS 1.2 if peer supports it */ + /* Allow Ed448 for TLS 1.2 if peer supports it */ if (!(mask_a & SSL_aECDSA) && ssl_has_cert(s, SSL_PKEY_ED448) && pvalid[SSL_PKEY_ED448] & CERT_PKEY_EXPLICIT_SIGN - && (SSL_version(&s->ssl) == XTLS(&s->ssl, 1, 2))) + && TLS1_get_version(&s->ssl) == TLS1_2_VERSION) mask_a |= SSL_aECDSA; mask_k |= SSL_kECDHE; @@ -5036,6 +4814,7 @@ int SSL_get_error(const SSL *s, int i) int ossl_ssl_get_error(const SSL *s, int i, int check_err) { int reason; + unsigned long l; BIO *bio; const SSL_CONNECTION *sc = SSL_CONNECTION_FROM_CONST_SSL(s); @@ -5053,11 +4832,15 @@ int ossl_ssl_get_error(const SSL *s, int i, int check_err) if (sc == NULL) return SSL_ERROR_SSL; - if (check_err != 0) { - if (sc->statem.error_state == ERROR_STATE_SSL) - return SSL_ERROR_SSL; - if (sc->statem.error_state == ERROR_STATE_SYSCALL) + /* + * Make things return SSL_ERROR_SYSCALL when doing SSL_do_handshake etc, + * where we do encode the error + */ + if (check_err && (l = ERR_peek_error()) != 0) { + if (ERR_GET_LIB(l) == ERR_LIB_SYS) return SSL_ERROR_SYSCALL; + else + return SSL_ERROR_SSL; } #ifndef OPENSSL_NO_QUIC @@ -5157,21 +4940,13 @@ int SSL_do_handshake(SSL *s) if (sc == NULL) return -1; - if (ssl_reset_error_state(sc) == 0) - return -1; - - sc->statem.error_state = ERROR_STATE_NOERROR; - if (sc->handshake_func == NULL) { ERR_raise(ERR_LIB_SSL, SSL_R_CONNECTION_TYPE_NOT_SET); - sc->statem.error_state = ERROR_STATE_SSL; return -1; } - if (!ossl_statem_check_finish_init(sc, -1)) { - ssl_update_error_state(sc); + if (!ossl_statem_check_finish_init(sc, -1)) return -1; - } s->method->ssl_renegotiate_check(s, 0); @@ -5188,7 +4963,6 @@ int SSL_do_handshake(SSL *s) } } - ssl_update_error_state(sc); return ret; } @@ -5234,10 +5008,6 @@ void SSL_set_connect_state(SSL *s) int ssl_undefined_function(SSL *s) { - SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); - - if (sc != NULL) - sc->statem.error_state = ERROR_STATE_SSL; ERR_raise(ERR_LIB_SSL, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED); return 0; } @@ -5354,8 +5124,7 @@ SSL *SSL_dup(SSL *s) /* If we're not quiescent, just up_ref! */ if (!SSL_in_init(s) || !SSL_in_before(s)) { - if (!CRYPTO_UP_REF(&s->references, &i)) - return NULL; + CRYPTO_UP_REF(&s->references, &i); return s; } @@ -6963,12 +6732,17 @@ void SSL_CTX_set_new_pending_conn_cb(SSL_CTX *c, SSL_new_pending_conn_cb_fn cb, c->new_pending_conn_arg = arg; } -#ifndef OPENSSL_NO_DEPRECATED_4_0 int SSL_client_hello_isv2(SSL *s) { - return 0; + const SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); + + if (sc == NULL) + return 0; + + if (sc->clienthello == NULL) + return 0; + return sc->clienthello->isv2; } -#endif unsigned int SSL_client_hello_get0_legacy_version(SSL *s) { @@ -7271,14 +7045,20 @@ int ssl_log_secret(SSL_CONNECTION *sc, secret_len); } -int ssl_cache_cipherlist(SSL_CONNECTION *s, PACKET *cipher_suites) +#define SSLV2_CIPHER_LEN 3 + +int ssl_cache_cipherlist(SSL_CONNECTION *s, PACKET *cipher_suites, int sslv2format) { + int n; + + n = sslv2format ? SSLV2_CIPHER_LEN : TLS_CIPHER_LEN; + if (PACKET_remaining(cipher_suites) == 0) { SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_NO_CIPHERS_SPECIFIED); return 0; } - if (PACKET_remaining(cipher_suites) % TLS_CIPHER_LEN != 0) { + if (PACKET_remaining(cipher_suites) % n != 0) { SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_ERROR_IN_RECEIVED_CIPHER_LIST); return 0; } @@ -7287,8 +7067,45 @@ int ssl_cache_cipherlist(SSL_CONNECTION *s, PACKET *cipher_suites) s->s3.tmp.ciphers_raw = NULL; s->s3.tmp.ciphers_rawlen = 0; - if (!PACKET_memdup(cipher_suites, &s->s3.tmp.ciphers_raw, - &s->s3.tmp.ciphers_rawlen)) { + if (sslv2format) { + size_t numciphers = PACKET_remaining(cipher_suites) / n; + PACKET sslv2ciphers = *cipher_suites; + unsigned int leadbyte; + unsigned char *raw; + + /* + * We store the raw ciphers list in SSLv3+ format so we need to do some + * preprocessing to convert the list first. If there are any SSLv2 only + * ciphersuites with a non-zero leading byte then we are going to + * slightly over allocate because we won't store those. But that isn't a + * problem. + */ + raw = OPENSSL_malloc_array(numciphers, TLS_CIPHER_LEN); + s->s3.tmp.ciphers_raw = raw; + if (raw == NULL) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_CRYPTO_LIB); + return 0; + } + for (s->s3.tmp.ciphers_rawlen = 0; + PACKET_remaining(&sslv2ciphers) > 0; + raw += TLS_CIPHER_LEN) { + if (!PACKET_get_1(&sslv2ciphers, &leadbyte) + || (leadbyte == 0 + && !PACKET_copy_bytes(&sslv2ciphers, raw, + TLS_CIPHER_LEN)) + || (leadbyte != 0 + && !PACKET_forward(&sslv2ciphers, TLS_CIPHER_LEN))) { + SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_PACKET); + OPENSSL_free(s->s3.tmp.ciphers_raw); + s->s3.tmp.ciphers_raw = NULL; + s->s3.tmp.ciphers_rawlen = 0; + return 0; + } + if (leadbyte == 0) + s->s3.tmp.ciphers_rawlen += TLS_CIPHER_LEN; + } + } else if (!PACKET_memdup(cipher_suites, &s->s3.tmp.ciphers_raw, + &s->s3.tmp.ciphers_rawlen)) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); return 0; } @@ -7302,24 +7119,27 @@ int SSL_bytes_to_cipher_list(SSL *s, const unsigned char *bytes, size_t len, PACKET pkt; SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); - if (sc == NULL || isv2format) + if (sc == NULL) return 0; if (!PACKET_buf_init(&pkt, bytes, len)) return 0; - return ossl_bytes_to_cipher_list(sc, &pkt, sk, scsvs, 0); + return ossl_bytes_to_cipher_list(sc, &pkt, sk, scsvs, isv2format, 0); } int ossl_bytes_to_cipher_list(SSL_CONNECTION *s, PACKET *cipher_suites, STACK_OF(SSL_CIPHER) **skp, STACK_OF(SSL_CIPHER) **scsvs_out, - int fatal) + int sslv2format, int fatal) { const SSL_CIPHER *c; STACK_OF(SSL_CIPHER) *sk = NULL; STACK_OF(SSL_CIPHER) *scsvs = NULL; - int n = TLS_CIPHER_LEN; - unsigned char cipher[TLS_CIPHER_LEN]; + int n; + /* 3 = SSLV2_CIPHER_LEN > TLS_CIPHER_LEN = 2. */ + unsigned char cipher[SSLV2_CIPHER_LEN]; + + n = sslv2format ? SSLV2_CIPHER_LEN : TLS_CIPHER_LEN; if (PACKET_remaining(cipher_suites) == 0) { if (fatal) @@ -7349,7 +7169,16 @@ int ossl_bytes_to_cipher_list(SSL_CONNECTION *s, PACKET *cipher_suites, } while (PACKET_copy_bytes(cipher_suites, cipher, n)) { - c = ssl_get_cipher_by_char(s, cipher, 1); + /* + * SSLv3 ciphers wrapped in an SSLv2-compatible ClientHello have the + * first byte set to zero, while true SSLv2 ciphers have a non-zero + * first byte. We don't support any true SSLv2 ciphers, so skip them. + */ + if (sslv2format && cipher[0] != '\0') + continue; + + /* For SSLv2-compat, ignore leading 0-byte. */ + c = ssl_get_cipher_by_char(s, sslv2format ? &cipher[1] : cipher, 1); if (c != NULL) { if ((c->valid && !sk_SSL_CIPHER_push(sk, c)) || (!c->valid && !sk_SSL_CIPHER_push(scsvs, c))) { if (fatal) @@ -8337,7 +8166,7 @@ int SSL_add_expected_rpk(SSL *s, EVP_PKEY *rpk) EVP_PKEY *SSL_get0_peer_rpk(const SSL *s) { - const SSL_CONNECTION *sc = SSL_CONNECTION_FROM_CONST_SSL(s); + SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); if (sc == NULL || sc->session == NULL) return NULL; @@ -8346,7 +8175,7 @@ EVP_PKEY *SSL_get0_peer_rpk(const SSL *s) int SSL_get_negotiated_client_cert_type(const SSL *s) { - const SSL_CONNECTION *sc = SSL_CONNECTION_FROM_CONST_SSL(s); + SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); if (sc == NULL) return 0; @@ -8356,7 +8185,7 @@ int SSL_get_negotiated_client_cert_type(const SSL *s) int SSL_get_negotiated_server_cert_type(const SSL *s) { - const SSL_CONNECTION *sc = SSL_CONNECTION_FROM_CONST_SSL(s); + SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); if (sc == NULL) return 0; @@ -8493,37 +8322,3 @@ int SSL_CTX_get0_server_cert_type(const SSL_CTX *ctx, unsigned char **t, size_t *len = ctx->server_cert_type_len; return 1; } - -/* - * RFC 8701 GREASE - returns a GREASE value (0x?A?A pattern) for the given - * index. Seeds are generated lazily on first use and remain stable for the - * lifetime of the connection so that HelloRetryRequest replays get identical - * values. - */ -uint16_t ossl_grease_value(SSL_CONNECTION *s, int index) -{ - uint16_t ret; - - if (index < 0 || index > OSSL_GREASE_LAST_INDEX) - return 0x0A0A; - - if (!s->ext.grease_seeded) { - if (RAND_bytes_ex(SSL_CONNECTION_GET_CTX(s)->libctx, - s->ext.grease_seed, - sizeof(s->ext.grease_seed), 0) - <= 0) - memset(s->ext.grease_seed, 0x42, sizeof(s->ext.grease_seed)); - s->ext.grease_seeded = 1; - } - - /* Map seed byte to 0x?A?A pattern */ - ret = (s->ext.grease_seed[index] & 0xf0) | 0x0a; - ret |= ret << 8; - - /* Ensure EXT2 differs from EXT1 */ - if (index == OSSL_GREASE_EXT2 - && ret == ossl_grease_value(s, OSSL_GREASE_EXT1)) - ret ^= 0x1010; - - return ret; -} diff --git a/ssl/ssl_local.h b/ssl/ssl_local.h index 2cfc5cb815..ca8a8e2aca 100644 --- a/ssl/ssl_local.h +++ b/ssl/ssl_local.h @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * Copyright 2005 Nokia. All rights reserved. * @@ -12,7 +12,6 @@ #ifndef OSSL_SSL_LOCAL_H #define OSSL_SSL_LOCAL_H -#include #include #include #include @@ -32,7 +31,6 @@ #include "internal/packet.h" #include "internal/dane.h" #include "internal/refcount.h" -#include "internal/tlssigalgs.h" #include "internal/tsan_assist.h" #include "internal/bio.h" #include "internal/ktls.h" @@ -43,9 +41,6 @@ #include "record/record.h" #include "internal/quic_predef.h" #include "internal/quic_tls.h" -#ifndef OPENSSL_NO_ECH -#include "ech/ech_local.h" -#endif #ifdef OPENSSL_BUILD_SHLIBSSL #undef OPENSSL_EXTERN @@ -64,8 +59,6 @@ #define DTLS_VERSION_GE(v1, v2) (dtls_ver_ordinal(v1) <= dtls_ver_ordinal(v2)) #define DTLS_VERSION_LT(v1, v2) (dtls_ver_ordinal(v1) > dtls_ver_ordinal(v2)) #define DTLS_VERSION_LE(v1, v2) (dtls_ver_ordinal(v1) >= dtls_ver_ordinal(v2)) -/* TLS/DTLS version for the given SSL object: XTLS(ssl, 1, 2) == TLS 1.2 or DTLS 1.2 */ -#define XTLS(ssl, m, n) (SSL_is_dtls(ssl) ? (((0xFF - m) << 8) | (0xFF - n)) : (((0x02 + m) << 8) | (0x01 + n))) #define SSL_AD_NO_ALERT -1 @@ -158,8 +151,6 @@ #define SSL_ARIA256GCM 0x00200000U #define SSL_MAGMA 0x00400000U #define SSL_KUZNYECHIK 0x00800000U -#define SSL_SM4GCM 0x01000000U -#define SSL_SM4CCM 0x02000000U #define SSL_AESGCM (SSL_AES128GCM | SSL_AES256GCM) #define SSL_AESCCM (SSL_AES128CCM | SSL_AES256CCM | SSL_AES128CCM8 | SSL_AES256CCM8) @@ -207,8 +198,7 @@ #define SSL_MD_SHA512_IDX 11 #define SSL_MD_MAGMAOMAC_IDX 12 #define SSL_MD_KUZNYECHIKOMAC_IDX 13 -#define SSL_MD_SM3_IDX 14 -#define SSL_MAX_DIGEST 15 +#define SSL_MAX_DIGEST 14 #define SSL_MD_NUM_IDX SSL_MAX_DIGEST @@ -222,7 +212,6 @@ #define SSL_HANDSHAKE_MAC_GOST94 SSL_MD_GOST94_IDX #define SSL_HANDSHAKE_MAC_GOST12_256 SSL_MD_GOST12_256_IDX #define SSL_HANDSHAKE_MAC_GOST12_512 SSL_MD_GOST12_512_IDX -#define SSL_HANDSHAKE_MAC_SM3 SSL_MD_SM3_IDX #define SSL_HANDSHAKE_MAC_DEFAULT SSL_HANDSHAKE_MAC_MD5_SHA1 /* Bits 8-15 bits are PRF */ @@ -256,7 +245,7 @@ #define SSL_LOW 0x00000002U #define SSL_MEDIUM 0x00000004U #define SSL_HIGH 0x00000008U -/* #define SSL_FIPS 0x00000010U obsolete FIPS canister remnant */ +#define SSL_FIPS 0x00000010U #define SSL_NOT_DEFAULT 0x00000020U /* we have used 0000003f - 26 bits left to go */ @@ -294,6 +283,12 @@ */ #define SSL_USE_SIGALGS(s) \ (SSL_CONNECTION_GET_SSL(s)->method->ssl3_enc->enc_flags & SSL_ENC_FLAG_SIGALGS) +/* + * Allow TLS 1.2 ciphersuites: applies to DTLS 1.2 as well as TLS 1.2: may + * apply to others in future. + */ +#define SSL_USE_TLS1_2_CIPHERS(s) \ + (SSL_CONNECTION_GET_SSL(s)->method->ssl3_enc->enc_flags & SSL_ENC_FLAG_TLS1_2_CIPHERS) #define IS_MAX_FRAGMENT_LENGTH_EXT_VALID(value) \ (((value) >= TLSEXT_max_fragment_length_512) && ((value) <= TLSEXT_max_fragment_length_4096)) @@ -356,9 +351,7 @@ #define SSL_ENC_ARIA256GCM_IDX 21 #define SSL_ENC_MAGMA_IDX 22 #define SSL_ENC_KUZNYECHIK_IDX 23 -#define SSL_ENC_SM4GCM_IDX 24 -#define SSL_ENC_SM4CCM_IDX 25 -#define SSL_ENC_NUM_IDX 26 +#define SSL_ENC_NUM_IDX 24 /*- * SSL_kRSA <- RSA_ENC @@ -382,7 +375,7 @@ typedef enum { SSL_PHA_REQUESTED /* request received by client, or sent by server */ } SSL_PHA_STATE; -/* CipherSuite value length. */ +/* CipherSuite length. SSLv3 and all TLS versions. */ #define TLS_CIPHER_LEN 2 /* used to hold info on the particular ciphers used */ struct ssl_cipher_st { @@ -442,7 +435,7 @@ struct ssl_method_st { int (*num_ciphers)(void); const SSL_CIPHER *(*get_cipher)(unsigned ncipher); OSSL_TIME (*get_timeout)(void); - const struct ssl3_enc_method *ssl3_enc; /* Extra TLS stuff */ + const struct ssl3_enc_method *ssl3_enc; /* Extra SSLv3/TLS stuff */ int (*ssl_version)(void); long (*ssl_callback_ctrl)(SSL *s, int cb_id, void (*fp)(void)); long (*ssl_ctx_callback_ctrl)(SSL_CTX *s, int cb_id, void (*fp)(void)); @@ -512,21 +505,6 @@ struct ssl_session_st { * to disable session caching and tickets. */ int not_resumable; - /* - * Set when this session's master key was resolved from an external PSK - * identity (psk_find_session_cb(), or the legacy psk_server_callback()) - * rather than from a resumption ticket or session-cache lookup. - * ssl_get_prev_session() uses this to exempt such sessions from sid_ctx - * checks that only make sense for a real cache lookup. - * - * Deliberately not part of the SSL_SESSION ASN.1 encoding: it must not - * survive a real ticket round-trip (a session reconstructed by - * d2i_SSL_SESSION() from a genuine, previously-issued ticket is by - * definition not an external-PSK match, and should get the ordinary - * sid_ctx treatment). ssl_session_dup() resets it to 0 on every copy, - * mirroring not_resumable just above, for the same reason. - */ - int psk_external; /* Peer raw public key, if available */ EVP_PKEY *peer_rpk; /* This is the cert and type for the other end. */ @@ -661,6 +639,7 @@ typedef struct raw_extension_st { } RAW_EXTENSION; typedef struct { + unsigned int isv2; unsigned int legacy_version; unsigned char random[SSL3_RANDOM_SIZE]; size_t session_id_len; @@ -707,25 +686,12 @@ typedef enum tlsext_index_en { TLSEXT_IDX_compress_certificate, TLSEXT_IDX_early_data, TLSEXT_IDX_certificate_authorities, - TLSEXT_IDX_ech, - TLSEXT_IDX_outer_extensions, - TLSEXT_IDX_grease1, - TLSEXT_IDX_grease2, TLSEXT_IDX_padding, TLSEXT_IDX_psk, /* Dummy index - must always be the last entry */ TLSEXT_IDX_num_builtins } TLSEXT_INDEX; -/* RFC 8701 GREASE seed indices */ -#define OSSL_GREASE_CIPHER 0 -#define OSSL_GREASE_GROUP 1 -#define OSSL_GREASE_EXT1 2 -#define OSSL_GREASE_EXT2 3 -#define OSSL_GREASE_VERSION 4 -#define OSSL_GREASE_SIGALG 5 -#define OSSL_GREASE_LAST_INDEX 5 - DEFINE_LHASH_OF_EX(SSL_SESSION); /* Needed in ssl_cert.c */ DEFINE_LHASH_OF_EX(X509_NAME); @@ -752,8 +718,8 @@ typedef struct ssl_hmac_st { #endif } SSL_HMAC; -SSL_HMAC *ssl_hmac_construct(const SSL_CTX *ctx, SSL_HMAC *hctx); -void ssl_hmac_destruct(SSL_HMAC *ctx); +SSL_HMAC *ssl_hmac_new(const SSL_CTX *ctx); +void ssl_hmac_free(SSL_HMAC *ctx); #ifndef OPENSSL_NO_DEPRECATED_3_0 HMAC_CTX *ssl_hmac_get0_HMAC_CTX(SSL_HMAC *ctx); #endif @@ -809,12 +775,19 @@ typedef struct { uint32_t amask; /* authmask corresponding to key type */ } SSL_CERT_LOOKUP; -#if !defined(OPENSSL_NO_TLS1) \ - || !defined(OPENSSL_NO_TLS1_1) \ - || !defined(OPENSSL_NO_TLS1_2) \ - || !defined(OPENSSL_NO_DTLS1) \ - || !defined(OPENSSL_NO_DTLS1_2) -#define OPENSSL_HAVE_TLS1PRF +/* flags values */ +#define TLS_GROUP_TYPE 0x0000000FU /* Mask for group type */ +#define TLS_GROUP_CURVE_PRIME 0x00000001U +#define TLS_GROUP_CURVE_CHAR2 0x00000002U +#define TLS_GROUP_CURVE_CUSTOM 0x00000004U +#define TLS_GROUP_FFDHE 0x00000008U +#define TLS_GROUP_ONLY_FOR_TLS1_3 0x00000010U + +#define TLS_GROUP_FFDHE_FOR_TLS1_3 (TLS_GROUP_FFDHE | TLS_GROUP_ONLY_FOR_TLS1_3) + +/* We limit the number of key shares sent */ +#ifndef OPENSSL_CLIENT_MAX_KEY_SHARES +#define OPENSSL_CLIENT_MAX_KEY_SHARES 4 #endif struct ssl_ctx_st { @@ -828,12 +801,6 @@ struct ssl_ctx_st { STACK_OF(SSL_CIPHER) *tls13_ciphersuites; struct x509_store_st /* X509_STORE */ *cert_store; LHASH_OF(SSL_SESSION) *sessions; - EVP_MAC *hmac; - EVP_MD *sha256; - EVP_CIPHER *tktenc; -#ifdef OPENSSL_HAVE_TLS1PRF - EVP_KDF *tls1prf; -#endif /* * Most session-ids that will be cached, default is * SSL_SESSION_CACHE_MAX_SIZE_DEFAULT. 0 is unlimited. @@ -927,8 +894,11 @@ struct ssl_ctx_st { CRYPTO_EX_DATA ex_data; + const EVP_MD *md5; /* For SSLv3/TLSv1 'ssl3-md5' */ + const EVP_MD *sha1; /* For SSLv3/TLSv1 'ssl3-sha1' */ + STACK_OF(X509) *extra_certs; - STACK_OF(SSL_COMP) *comp_methods; /* stack of SSL_COMP, TLSv1 */ + STACK_OF(SSL_COMP) *comp_methods; /* stack of SSL_COMP, SSLv3/TLSv1 */ /* Default values used when no per-SSL value is defined follow */ @@ -1039,6 +1009,10 @@ struct ssl_ctx_st { /* RFC 4366 Maximum Fragment Length Negotiation */ uint8_t max_fragment_len_mode; + /* EC extension values inherited by SSL structure */ + size_t ecpointformats_len; + unsigned char *ecpointformats; + size_t supportedgroups_len; uint16_t *supportedgroups; @@ -1095,9 +1069,6 @@ struct ssl_ctx_st { #endif unsigned char cookie_hmac_key[SHA256_DIGEST_LENGTH]; -#ifndef OPENSSL_NO_ECH - OSSL_ECH_CTX ech; -#endif } ext; #ifndef OPENSSL_NO_PSK @@ -1272,7 +1243,8 @@ struct ssl_connection_st { SSL *user_ssl; /* - * protocol version (one of TLS1_VERSION, DTLS1_VERSION) + * protocol version (one of SSL2_VERSION, SSL3_VERSION, TLS1_VERSION, + * DTLS1_VERSION) */ int version; /* @@ -1367,7 +1339,7 @@ struct ssl_connection_st { int in_read_app_data; struct { - /* actually only need to be 12 for TLS */ + /* actually only need to be 16+20 for SSLv3 and 12 for TLS */ unsigned char finish_md[EVP_MAX_MD_SIZE * 2]; size_t finish_md_len; unsigned char peer_finish_md[EVP_MAX_MD_SIZE * 2]; @@ -1618,7 +1590,7 @@ struct ssl_connection_st { int first_packet; /* * What was passed in ClientHello.legacy_version. Used for RSA pre-master - * secret and (D)TLS (<=1.2) rollback check + * secret and SSLv3/TLS (<=1.2) rollback check */ int client_version; /* @@ -1649,6 +1621,8 @@ struct ssl_connection_st { unsigned char *scts; /* Length of raw extension data, if seen */ uint16_t scts_len; + /* Expect OCSP CertificateStatus message */ + int status_expected; struct { /* OCSP status request only */ @@ -1660,16 +1634,15 @@ struct ssl_connection_st { STACK_OF(OCSP_RESPONSE) *resp_ex; } ocsp; + /* RFC4507 session ticket expected to be received or sent */ + int ticket_expected; /* TLS 1.3 tickets requested by the application. */ int extra_tickets_expected; - /* - * Peer's advertised ec_point_formats list (TLS 1.2 and below), - * retained as received so SSL_get0_ec_point_formats() can return - * it verbatim. Point format no longer influences cert selection - * or acceptance; the parse hook validates RFC 4492/8422 section - * 5.1.2 ("uncompressed" must be present) inline. - */ + /* our list */ + size_t ecpointformats_len; + unsigned char *ecpointformats; + /* peer's list */ size_t peer_ecpointformats_len; unsigned char *peer_ecpointformats; @@ -1714,12 +1687,19 @@ struct ssl_connection_st { /* The available PSK key exchange modes */ int psk_kex_mode; + /* Set to one if we have negotiated ETM */ + int use_etm; + /* Are we expecting to receive early data? */ int early_data; + /* Is the session suitable for early data? */ + int early_data_ok; /* May be sent by a server in HRR. Must be echoed back in ClientHello */ unsigned char *tls13_cookie; size_t tls13_cookie_len; + /* Have we received a cookie from the client? */ + int cookieok; /* * Maximum Fragment Length as per RFC 4366. @@ -1741,39 +1721,13 @@ struct ssl_connection_st { /* This is the list of algorithms the peer supports that we also support */ int compress_certificate_from_peer[TLSEXT_comp_cert_limit]; + /* indicate that we sent the extension, so we'll accept it */ + int compress_certificate_sent; uint8_t client_cert_type; uint8_t client_cert_type_ctos; uint8_t server_cert_type; uint8_t server_cert_type_ctos; - -#ifndef OPENSSL_NO_ECH - OSSL_ECH_CONN ech; -#endif - - /* RFC 8701 GREASE */ - uint8_t grease_seed[OSSL_GREASE_LAST_INDEX + 1]; - - /* "bool" fields go last, for slightly better packing */ - bool grease_seeded; - - /* Expect OCSP CertificateStatus message */ - bool status_expected; - - /* RFC4507 session ticket expected to be received or sent */ - bool ticket_expected; - - /* Set to one if we have negotiated ETM */ - bool use_etm; - - /* Is the session suitable for early data? */ - bool early_data_ok; - - /* Have we received a cookie from the client? */ - bool cookieok; - - /* indicate that we sent the extension, so we'll accept it */ - bool compress_certificate_sent; } ext; /* @@ -2015,7 +1969,6 @@ typedef struct dtls1_state_st { unsigned int timeout_duration_us; unsigned int retransmitting; - unsigned int has_change_cipher_spec; #ifndef OPENSSL_NO_SCTP int shutdown_received; #endif @@ -2185,7 +2138,8 @@ typedef struct cert_st { } CERT; /* - * This is for the TLSv1.0 differences in crypto/hash stuff. + * This is for the SSLv3/TLSv1.0 differences in crypto/hash stuff It is a bit + * of a mess of functions, but hell, think of it as an opaque structure :-) */ typedef struct ssl3_enc_method { int (*setup_key_block)(SSL_CONNECTION *); @@ -2245,6 +2199,85 @@ typedef enum downgrade_en { */ #define TLSEXT_STATUSTYPE_nothing -1 +/* Sigalgs values */ +#define TLSEXT_SIGALG_ecdsa_secp256r1_sha256 0x0403 +#define TLSEXT_SIGALG_ecdsa_secp384r1_sha384 0x0503 +#define TLSEXT_SIGALG_ecdsa_secp521r1_sha512 0x0603 +#define TLSEXT_SIGALG_ecdsa_sha224 0x0303 +#define TLSEXT_SIGALG_ecdsa_sha1 0x0203 +#define TLSEXT_SIGALG_rsa_pss_rsae_sha256 0x0804 +#define TLSEXT_SIGALG_rsa_pss_rsae_sha384 0x0805 +#define TLSEXT_SIGALG_rsa_pss_rsae_sha512 0x0806 +#define TLSEXT_SIGALG_rsa_pss_pss_sha256 0x0809 +#define TLSEXT_SIGALG_rsa_pss_pss_sha384 0x080a +#define TLSEXT_SIGALG_rsa_pss_pss_sha512 0x080b +#define TLSEXT_SIGALG_rsa_pkcs1_sha256 0x0401 +#define TLSEXT_SIGALG_rsa_pkcs1_sha384 0x0501 +#define TLSEXT_SIGALG_rsa_pkcs1_sha512 0x0601 +#define TLSEXT_SIGALG_rsa_pkcs1_sha224 0x0301 +#define TLSEXT_SIGALG_rsa_pkcs1_sha1 0x0201 +#define TLSEXT_SIGALG_dsa_sha256 0x0402 +#define TLSEXT_SIGALG_dsa_sha384 0x0502 +#define TLSEXT_SIGALG_dsa_sha512 0x0602 +#define TLSEXT_SIGALG_dsa_sha224 0x0302 +#define TLSEXT_SIGALG_dsa_sha1 0x0202 +#define TLSEXT_SIGALG_gostr34102012_256_intrinsic 0x0840 +#define TLSEXT_SIGALG_gostr34102012_512_intrinsic 0x0841 +#define TLSEXT_SIGALG_gostr34102012_256_gostr34112012_256 0xeeee +#define TLSEXT_SIGALG_gostr34102012_512_gostr34112012_512 0xefef +#define TLSEXT_SIGALG_gostr34102001_gostr3411 0xeded + +#define TLSEXT_SIGALG_ed25519 0x0807 +#define TLSEXT_SIGALG_ed448 0x0808 +#define TLSEXT_SIGALG_ecdsa_brainpoolP256r1_sha256 0x081a +#define TLSEXT_SIGALG_ecdsa_brainpoolP384r1_sha384 0x081b +#define TLSEXT_SIGALG_ecdsa_brainpoolP512r1_sha512 0x081c +#define TLSEXT_SIGALG_mldsa44 0x0904 +#define TLSEXT_SIGALG_mldsa65 0x0905 +#define TLSEXT_SIGALG_mldsa87 0x0906 + +/* Sigalgs names */ +#define TLSEXT_SIGALG_ecdsa_secp256r1_sha256_name "ecdsa_secp256r1_sha256" +#define TLSEXT_SIGALG_ecdsa_secp384r1_sha384_name "ecdsa_secp384r1_sha384" +#define TLSEXT_SIGALG_ecdsa_secp521r1_sha512_name "ecdsa_secp521r1_sha512" +#define TLSEXT_SIGALG_ecdsa_sha224_name "ecdsa_sha224" +#define TLSEXT_SIGALG_ecdsa_sha1_name "ecdsa_sha1" +#define TLSEXT_SIGALG_rsa_pss_rsae_sha256_name "rsa_pss_rsae_sha256" +#define TLSEXT_SIGALG_rsa_pss_rsae_sha384_name "rsa_pss_rsae_sha384" +#define TLSEXT_SIGALG_rsa_pss_rsae_sha512_name "rsa_pss_rsae_sha512" +#define TLSEXT_SIGALG_rsa_pss_pss_sha256_name "rsa_pss_pss_sha256" +#define TLSEXT_SIGALG_rsa_pss_pss_sha384_name "rsa_pss_pss_sha384" +#define TLSEXT_SIGALG_rsa_pss_pss_sha512_name "rsa_pss_pss_sha512" +#define TLSEXT_SIGALG_rsa_pkcs1_sha256_name "rsa_pkcs1_sha256" +#define TLSEXT_SIGALG_rsa_pkcs1_sha384_name "rsa_pkcs1_sha384" +#define TLSEXT_SIGALG_rsa_pkcs1_sha512_name "rsa_pkcs1_sha512" +#define TLSEXT_SIGALG_rsa_pkcs1_sha224_name "rsa_pkcs1_sha224" +#define TLSEXT_SIGALG_rsa_pkcs1_sha1_name "rsa_pkcs1_sha1" +#define TLSEXT_SIGALG_dsa_sha256_name "dsa_sha256" +#define TLSEXT_SIGALG_dsa_sha384_name "dsa_sha384" +#define TLSEXT_SIGALG_dsa_sha512_name "dsa_sha512" +#define TLSEXT_SIGALG_dsa_sha224_name "dsa_sha224" +#define TLSEXT_SIGALG_dsa_sha1_name "dsa_sha1" +#define TLSEXT_SIGALG_gostr34102012_256_intrinsic_name "gostr34102012_256" +#define TLSEXT_SIGALG_gostr34102012_512_intrinsic_name "gostr34102012_512" +#define TLSEXT_SIGALG_gostr34102012_256_intrinsic_alias "gost2012_256" +#define TLSEXT_SIGALG_gostr34102012_512_intrinsic_alias "gost2012_512" +#define TLSEXT_SIGALG_gostr34102012_256_gostr34112012_256_name "gost2012_256" +#define TLSEXT_SIGALG_gostr34102012_512_gostr34112012_512_name "gost2012_512" +#define TLSEXT_SIGALG_gostr34102001_gostr3411_name "gost2001_gost94" + +#define TLSEXT_SIGALG_ed25519_name "ed25519" +#define TLSEXT_SIGALG_ed448_name "ed448" +#define TLSEXT_SIGALG_ecdsa_brainpoolP256r1_sha256_name "ecdsa_brainpoolP256r1tls13_sha256" +#define TLSEXT_SIGALG_ecdsa_brainpoolP384r1_sha384_name "ecdsa_brainpoolP384r1tls13_sha384" +#define TLSEXT_SIGALG_ecdsa_brainpoolP512r1_sha512_name "ecdsa_brainpoolP512r1tls13_sha512" +#define TLSEXT_SIGALG_ecdsa_brainpoolP256r1_sha256_alias "ecdsa_brainpoolP256r1_sha256" +#define TLSEXT_SIGALG_ecdsa_brainpoolP384r1_sha384_alias "ecdsa_brainpoolP384r1_sha384" +#define TLSEXT_SIGALG_ecdsa_brainpoolP512r1_sha512_alias "ecdsa_brainpoolP512r1_sha512" +#define TLSEXT_SIGALG_mldsa44_name "mldsa44" +#define TLSEXT_SIGALG_mldsa65_name "mldsa65" +#define TLSEXT_SIGALG_mldsa87_name "mldsa87" + /* Known PSK key exchange modes */ #define TLSEXT_KEX_MODE_KE 0x00 #define TLSEXT_KEX_MODE_KE_DHE 0x01 @@ -2264,6 +2297,9 @@ extern const unsigned char tls12downgrade[8]; extern const SSL3_ENC_METHOD ssl3_undef_enc_method; +__owur const SSL_METHOD *sslv3_method(void); +__owur const SSL_METHOD *sslv3_server_method(void); +__owur const SSL_METHOD *sslv3_client_method(void); __owur const SSL_METHOD *tlsv1_method(void); __owur const SSL_METHOD *tlsv1_server_method(void); __owur const SSL_METHOD *tlsv1_client_method(void); @@ -2288,6 +2324,7 @@ extern const SSL3_ENC_METHOD TLSv1_enc_data; extern const SSL3_ENC_METHOD TLSv1_1_enc_data; extern const SSL3_ENC_METHOD TLSv1_2_enc_data; extern const SSL3_ENC_METHOD TLSv1_3_enc_data; +extern const SSL3_ENC_METHOD SSLv3_enc_data; extern const SSL3_ENC_METHOD DTLSv1_enc_data; extern const SSL3_ENC_METHOD DTLSv1_2_enc_data; @@ -2338,6 +2375,46 @@ extern const SSL3_ENC_METHOD DTLSv1_2_enc_data; return &func_name##_data; \ } +#define IMPLEMENT_ssl3_meth_func(func_name, s_accept, s_connect) \ + const SSL_METHOD *func_name(void) \ + { \ + static const SSL_METHOD func_name##_data = { \ + SSL3_VERSION, \ + SSL_METHOD_NO_FIPS | SSL_METHOD_NO_SUITEB, \ + SSL_OP_NO_SSLv3, \ + ossl_ssl_connection_new, \ + ossl_ssl_connection_free, \ + ossl_ssl_connection_reset, \ + ssl3_new, \ + ssl3_clear, \ + ssl3_free, \ + s_accept, \ + s_connect, \ + ssl3_read, \ + ssl3_peek, \ + ssl3_write, \ + ssl3_shutdown, \ + ssl3_renegotiate, \ + ssl3_renegotiate_check, \ + ssl3_read_bytes, \ + ssl3_write_bytes, \ + ssl3_dispatch_alert, \ + ssl3_ctrl, \ + ssl3_ctx_ctrl, \ + ssl3_get_cipher_by_char, \ + ssl3_put_cipher_by_char, \ + ssl3_pending, \ + ssl3_num_ciphers, \ + ssl3_get_cipher, \ + ssl3_default_timeout, \ + &SSLv3_enc_data, \ + ssl_undefined_void_function, \ + ssl3_callback_ctrl, \ + ssl3_ctx_callback_ctrl, \ + }; \ + return &func_name##_data; \ + } + #define IMPLEMENT_dtls1_meth_func(version, flags, mask, func_name, s_accept, \ s_connect, enc_data) \ const SSL_METHOD *func_name(void) \ @@ -2473,10 +2550,11 @@ __owur STACK_OF(SSL_CIPHER) *ssl_create_cipher_list(SSL_CTX *ctx, STACK_OF(SSL_CIPHER) **cipher_list_by_id, const char *rule_str, CERT *c); -__owur int ssl_cache_cipherlist(SSL_CONNECTION *s, PACKET *cipher_suites); +__owur int ssl_cache_cipherlist(SSL_CONNECTION *s, PACKET *cipher_suites, + int sslv2format); __owur int ossl_bytes_to_cipher_list(SSL_CONNECTION *s, PACKET *cipher_suites, STACK_OF(SSL_CIPHER) **skp, - STACK_OF(SSL_CIPHER) **scsvs, + STACK_OF(SSL_CIPHER) **scsvs, int sslv2format, int fatal); void ssl_update_cache(SSL_CONNECTION *s, int mode); __owur int ssl_cipher_get_evp_cipher(SSL_CTX *ctx, const SSL_CIPHER *sslc, @@ -2507,6 +2585,7 @@ void ssl_cert_set_cert_cb(CERT *c, int (*cb)(SSL *ssl, void *arg), void *arg); __owur int ssl_verify_cert_chain(SSL_CONNECTION *s, STACK_OF(X509) *sk); __owur int ssl_verify_rpk(SSL_CONNECTION *s, EVP_PKEY *rpk); +__owur int ssl_verify_ocsp(SSL *s, STACK_OF(X509) *sk); __owur int ssl_build_cert_chain(SSL_CONNECTION *s, SSL_CTX *ctx, int flags); __owur int ssl_cert_set_cert_store(CERT *c, X509_STORE *store, int chain, int ref); @@ -2534,13 +2613,6 @@ __owur STACK_OF(SSL_CIPHER) *ssl_get_ciphers_by_id(SSL_CONNECTION *sc); __owur int ssl_x509err2alert(int type); void ssl_sort_cipher_list(void); int ssl_load_ciphers(SSL_CTX *ctx); -int ssl_cipher_list_to_bytes(SSL_CONNECTION *s, STACK_OF(SSL_CIPHER) *sk, - WPACKET *pkt); -uint16_t ossl_grease_value(SSL_CONNECTION *s, int index); -static ossl_inline int ossl_is_grease_value(uint16_t val) -{ - return (val & 0x0f0f) == 0x0a0a && (val >> 8) == (val & 0xff); -} __owur int ssl_setup_sigalgs(SSL_CTX *ctx); int ssl_load_groups(SSL_CTX *ctx); int ssl_load_sigalgs(SSL_CTX *ctx); @@ -2569,20 +2641,28 @@ __owur unsigned int ssl_get_split_send_fragment(const SSL_CONNECTION *sc); __owur const SSL_CIPHER *ssl3_get_cipher_by_id(uint32_t id); __owur const SSL_CIPHER *ssl3_get_cipher_by_std_name(const char *stdname); -__owur const SSL_CIPHER *ssl3_get_tls13_cipher_by_std_name(const char *stdname); __owur const SSL_CIPHER *ssl3_get_cipher_by_char(const unsigned char *p); __owur int ssl3_put_cipher_by_char(const SSL_CIPHER *c, WPACKET *pkt, size_t *len); int ssl3_init_finished_mac(SSL_CONNECTION *s); +__owur int ssl3_setup_key_block(SSL_CONNECTION *s); +__owur int ssl3_change_cipher_state(SSL_CONNECTION *s, int which); void ssl3_cleanup_key_block(SSL_CONNECTION *s); __owur int ssl3_do_write(SSL_CONNECTION *s, uint8_t type); int ssl3_send_alert(SSL_CONNECTION *s, int level, int desc); +__owur int ssl3_generate_master_secret(SSL_CONNECTION *s, unsigned char *out, + unsigned char *p, size_t len, + size_t *secret_size); __owur int ssl3_get_req_cert_type(SSL_CONNECTION *s, WPACKET *pkt); __owur int ssl3_num_ciphers(void); __owur const SSL_CIPHER *ssl3_get_cipher(unsigned int u); int ssl3_renegotiate(SSL *ssl); int ssl3_renegotiate_check(SSL *ssl, int initok); +void ssl3_digest_master_key_set_params(const SSL_SESSION *session, + OSSL_PARAM params[]); __owur int ssl3_dispatch_alert(SSL *s); +__owur size_t ssl3_final_finish_mac(SSL_CONNECTION *s, const char *sender, + size_t slen, unsigned char *p); __owur int ssl3_finish_mac(SSL_CONNECTION *s, const unsigned char *buf, size_t len); void ssl3_free_digest_list(SSL_CONNECTION *s); @@ -2605,6 +2685,7 @@ __owur long ssl3_callback_ctrl(SSL *s, int cmd, void (*fp)(void)); __owur long ssl3_ctx_callback_ctrl(SSL_CTX *s, int cmd, void (*fp)(void)); __owur int ssl3_do_change_cipher_spec(SSL_CONNECTION *s); +__owur OSSL_TIME ssl3_default_timeout(void); __owur int ssl3_set_handshake_header(SSL_CONNECTION *s, WPACKET *pkt, int htype); @@ -2742,17 +2823,12 @@ __owur int tls13_export_keying_material_early(SSL_CONNECTION *s, size_t contextlen); __owur int tls1_alert_code(int code); __owur int tls13_alert_code(int code); +__owur int ssl3_alert_code(int code); __owur int ssl_check_srvr_ecc_cert_and_alg(X509 *x, SSL_CONNECTION *s); SSL_COMP *ssl3_comp_find(STACK_OF(SSL_COMP) *sk, int n); -#define TLS1_GROUPS_RETURN_NUMBER -1 -#define TLS1_GROUPS_RETURN_TMP_ID -2 -#define TLS1_GROUPS_FFDHE_GROUPS 0 -#define TLS1_GROUPS_NON_FFDHE_GROUPS 1 -#define TLS1_GROUPS_ALL_GROUPS 2 - __owur const TLS_GROUP_INFO *tls1_group_id_lookup(SSL_CTX *ctx, uint16_t curve_id); __owur const char *tls1_group_id2name(SSL_CTX *ctx, uint16_t group_id); __owur int tls1_group_id2nid(uint16_t group_id, int include_unknown); @@ -2764,7 +2840,7 @@ __owur int tls1_get0_implemented_groups(int min_proto_version, TLS_GROUP_INFO *grps, size_t num, long all, STACK_OF(OPENSSL_CSTRING) *out); -__owur uint16_t tls1_shared_group(SSL_CONNECTION *s, int nmatch, int groups); +__owur uint16_t tls1_shared_group(SSL_CONNECTION *s, int nmatch); __owur int tls1_set_groups(uint16_t **grpext, size_t *grpextlen, uint16_t **ksext, size_t *ksextlen, size_t **tplext, size_t *tplextlen, @@ -2776,11 +2852,10 @@ __owur int tls1_set_groups_list(SSL_CTX *ctx, const char *str); __owur EVP_PKEY *ssl_generate_pkey_group(SSL_CONNECTION *s, uint16_t id); __owur int tls_valid_group(SSL_CONNECTION *s, uint16_t group_id, int minversion, - int maxversion, int *okfortls13, const TLS_GROUP_INFO **giptr); + int maxversion, int isec, int *okfortls13); __owur EVP_PKEY *ssl_generate_param_group(SSL_CONNECTION *s, uint16_t id); void tls1_get_formatlist(SSL_CONNECTION *s, const unsigned char **pformats, size_t *num_formats); -__owur int tls1_check_ffdhe_tmp_key(SSL_CONNECTION *s, unsigned long id); __owur int tls1_check_ec_tmp_key(SSL_CONNECTION *s, unsigned long id); __owur int tls_group_allowed(SSL_CONNECTION *s, uint16_t curve, int op); @@ -2821,16 +2896,17 @@ __owur int ssl_validate_ct(SSL_CONNECTION *s); __owur EVP_PKEY *ssl_get_auto_dh(SSL_CONNECTION *s); -__owur int ssl_security_cert(SSL_CONNECTION *s, SSL_CTX *ctx, X509 *x, int is_ee); +__owur int ssl_security_cert(SSL_CONNECTION *s, SSL_CTX *ctx, X509 *x, int vfy, + int is_ee); __owur int ssl_security_cert_chain(SSL_CONNECTION *s, STACK_OF(X509) *sk, - X509 *ex); + X509 *ex, int vfy); int tls_choose_sigalg(SSL_CONNECTION *s, int fatalerrs); __owur long ssl_get_algorithm2(SSL_CONNECTION *s); __owur int tls12_copy_sigalgs(SSL_CONNECTION *s, WPACKET *pkt, const uint16_t *psig, size_t psiglen); -__owur int tls1_save_u16(PACKET *pkt, uint16_t **pdest, size_t *pdestlen, size_t maxnum); +__owur int tls1_save_u16(PACKET *pkt, uint16_t **pdest, size_t *pdestlen); __owur int tls1_save_sigalgs(SSL_CONNECTION *s, PACKET *pkt, int cert); __owur int tls1_process_sigalgs(SSL_CONNECTION *s); __owur int tls1_set_peer_legacy_sigalg(SSL_CONNECTION *s, const EVP_PKEY *pkey); @@ -2842,7 +2918,7 @@ __owur int tls_check_sigalg_curve(const SSL_CONNECTION *s, int curve); __owur int tls12_check_peer_sigalg(SSL_CONNECTION *s, uint16_t, EVP_PKEY *pkey); __owur int ssl_set_client_disabled(SSL_CONNECTION *s); __owur int ssl_cipher_disabled(const SSL_CONNECTION *s, const SSL_CIPHER *c, - int op); + int op, int echde); __owur int ssl_handshake_hash(SSL_CONNECTION *s, unsigned char *out, size_t outlen, @@ -2938,8 +3014,8 @@ void ssl_evp_cipher_free(const EVP_CIPHER *cipher); int ssl_evp_md_up_ref(const EVP_MD *md); void ssl_evp_md_free(const EVP_MD *md); -SSL_HMAC *ssl_hmac_old_construct(SSL_HMAC *ret); -void ssl_hmac_old_destruct(SSL_HMAC *ctx); +int ssl_hmac_old_new(SSL_HMAC *ret); +void ssl_hmac_old_free(SSL_HMAC *ctx); int ssl_hmac_old_init(SSL_HMAC *ctx, void *key, size_t len, char *md); int ssl_hmac_old_update(SSL_HMAC *ctx, const unsigned char *data, size_t len); int ssl_hmac_old_final(SSL_HMAC *ctx, unsigned char *md, size_t *len); @@ -3012,7 +3088,7 @@ long ossl_ctrl_internal(SSL *s, int cmd, long larg, void *parg, int no_quic); * allowed but ignored under QUIC. */ #define OSSL_TLS1_2_OPTIONS \ - (SSL_OP_CRYPTOPRO_TLSEXT_BUG | SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS | SSL_OP_ALLOW_CLIENT_RENEGOTIATION | SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION | SSL_OP_NO_COMPRESSION | SSL_OP_NO_TLSv1 | SSL_OP_NO_TLSv1_1 | SSL_OP_NO_TLSv1_2 | SSL_OP_NO_DTLSv1 | SSL_OP_NO_DTLSv1_2 | SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION | SSL_OP_CISCO_ANYCONNECT | SSL_OP_NO_RENEGOTIATION | SSL_OP_NO_EXTENDED_MASTER_SECRET | SSL_OP_NO_ENCRYPT_THEN_MAC | SSL_OP_COOKIE_EXCHANGE | SSL_OP_LEGACY_SERVER_CONNECT | SSL_OP_IGNORE_UNEXPECTED_EOF) + (SSL_OP_CRYPTOPRO_TLSEXT_BUG | SSL_OP_DONT_INSERT_EMPTY_FRAGMENTS | SSL_OP_ALLOW_CLIENT_RENEGOTIATION | SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION | SSL_OP_NO_COMPRESSION | SSL_OP_NO_SSLv3 | SSL_OP_NO_TLSv1 | SSL_OP_NO_TLSv1_1 | SSL_OP_NO_TLSv1_2 | SSL_OP_NO_DTLSv1 | SSL_OP_NO_DTLSv1_2 | SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION | SSL_OP_CISCO_ANYCONNECT | SSL_OP_NO_RENEGOTIATION | SSL_OP_NO_EXTENDED_MASTER_SECRET | SSL_OP_NO_ENCRYPT_THEN_MAC | SSL_OP_COOKIE_EXCHANGE | SSL_OP_LEGACY_SERVER_CONNECT | SSL_OP_IGNORE_UNEXPECTED_EOF) /* Total mask of connection-level options permitted or ignored under QUIC. */ #define OSSL_QUIC_PERMITTED_OPTIONS_CONN \ diff --git a/ssl/ssl_mcnf.c b/ssl/ssl_mcnf.c index 2480f527ce..74f07cd945 100644 --- a/ssl/ssl_mcnf.c +++ b/ssl/ssl_mcnf.c @@ -45,8 +45,6 @@ static int ssl_do_config(SSL *s, SSL_CTX *ctx, const char *name, int system) OSSL_LIB_CTX *libctx = NULL, *prev_libctx = NULL; CONF_IMODULE *imod = NULL; - ERR_set_mark(); - if (s == NULL && ctx == NULL) { ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_NULL_PARAMETER); goto err; @@ -115,20 +113,7 @@ static int ssl_do_config(SSL *s, SSL_CTX *ctx, const char *name, int system) err: OSSL_LIB_CTX_set0_default(prev_libctx); SSL_CONF_CTX_free(cctx); - if (err == 0) { - ERR_pop_to_mark(); - return 1; - } - if (system && !conf_diagnostics) { - /* - * Discard errors so that SSL_CTX_new does not return - * success with stale errors on the error stack. - */ - ERR_pop_to_mark(); - return 1; - } - ERR_clear_last_mark(); - return 0; + return err == 0 || (system && !conf_diagnostics); } int SSL_config(SSL *s, const char *name) diff --git a/ssl/ssl_rsa.c b/ssl/ssl_rsa.c index 7cfd59d6d0..b908f4f41d 100644 --- a/ssl/ssl_rsa.c +++ b/ssl/ssl_rsa.c @@ -42,7 +42,7 @@ int SSL_use_certificate(SSL *ssl, X509 *x) return 0; } - rv = ssl_security_cert(sc, NULL, x, 1); + rv = ssl_security_cert(sc, NULL, x, 0, 1); if (rv != 1) { ERR_raise(ERR_LIB_SSL, rv); return 0; @@ -247,7 +247,7 @@ int SSL_CTX_use_certificate(SSL_CTX *ctx, X509 *x) return 0; } - rv = ssl_security_cert(NULL, ctx, x, 1); + rv = ssl_security_cert(NULL, ctx, x, 0, 1); if (rv != 1) { ERR_raise(ERR_LIB_SSL, rv); return 0; @@ -993,13 +993,13 @@ static int ssl_set_cert_and_key(SSL *ssl, SSL_CTX *ctx, X509 *x509, EVP_PKEY *pr c = sc != NULL ? sc->cert : ctx->cert; /* Do all security checks before anything else */ - rv = ssl_security_cert(sc, ctx, x509, 1); + rv = ssl_security_cert(sc, ctx, x509, 0, 1); if (rv != 1) { ERR_raise(ERR_LIB_SSL, rv); goto out; } for (j = 0; j < sk_X509_num(chain); j++) { - rv = ssl_security_cert(sc, ctx, sk_X509_value(chain, j), 0); + rv = ssl_security_cert(sc, ctx, sk_X509_value(chain, j), 0, 0); if (rv != 1) { ERR_raise(ERR_LIB_SSL, rv); goto out; @@ -1039,9 +1039,7 @@ static int ssl_set_cert_and_key(SSL *ssl, SSL_CTX *ctx, X509 *x509, EVP_PKEY *pr goto out; } } - if (ssl_cert_lookup_by_pkey(pubkey, &i, - sc != NULL ? SSL_CONNECTION_GET_CTX(sc) : ctx) - == NULL) { + if (ssl_cert_lookup_by_pkey(pubkey, &i, ctx) == NULL) { ERR_raise(ERR_LIB_SSL, SSL_R_UNKNOWN_CERTIFICATE_TYPE); goto out; } diff --git a/ssl/ssl_sess.c b/ssl/ssl_sess.c index 094ab1a74e..77cf2537be 100644 --- a/ssl/ssl_sess.c +++ b/ssl/ssl_sess.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright 2005 Nokia. All rights reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -22,7 +22,7 @@ static void SSL_SESSION_list_remove(SSL_CTX *ctx, SSL_SESSION *s); static void SSL_SESSION_list_add(SSL_CTX *ctx, SSL_SESSION *s); -static SSL_SESSION *remove_session_locked(SSL_CTX *ctx, SSL_SESSION *c); +static int remove_session_lock(SSL_CTX *ctx, SSL_SESSION *c, int lck); DEFINE_STACK_OF(SSL_SESSION) @@ -61,7 +61,7 @@ void ssl_session_calculate_timeout(SSL_SESSION *ss) SSL_SESSION *SSL_get_session(const SSL *ssl) /* aka SSL_get0_session; gets 0 objects, just returns a copy of the pointer */ { - const SSL_CONNECTION *sc = SSL_CONNECTION_FROM_CONST_SSL(ssl); + const SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(ssl); if (sc == NULL) return NULL; @@ -279,16 +279,8 @@ SSL_SESSION *ssl_session_dup(const SSL_SESSION *src, int ticket) { SSL_SESSION *sess = ssl_session_dup_intern(src, ticket); - if (sess != NULL) { + if (sess != NULL) sess->not_resumable = 0; - /* - * A duplicated session can land in the stateful session cache, and is - * not necessarily a live session just built for an external PSK. The - * caller must explicitly set this field non-zero after duplication as - * needed. - */ - sess->psk_external = 0; - } return sess; } @@ -314,7 +306,7 @@ unsigned int SSL_SESSION_get_compress_id(const SSL_SESSION *s) } /* - * TLSv1 has 32 bytes (256 bits) of session ID space. As such, filling + * SSLv3/TLSv1 has 32 bytes (256 bits) of session ID space. As such, filling * the ID with random junk repeatedly until we have no conflict is going to * complete in one iteration pretty much "most" of the time (btw: * understatement). So, if it takes us 10 iterations and we still can't avoid @@ -359,6 +351,7 @@ int ssl_generate_session_id(SSL_CONNECTION *s, SSL_SESSION *ss) SSL *ssl = SSL_CONNECTION_GET_SSL(s); switch (s->version) { + case SSL3_VERSION: case TLS1_VERSION: case TLS1_1_VERSION: case TLS1_2_VERSION: @@ -656,13 +649,7 @@ int ssl_get_prev_session(SSL_CONNECTION *s, CLIENTHELLO_MSG *hello) goto err; /* treat like cache miss */ } - /* - * sid_ctx exists to keep multiple services that happen to share one - * session cache from resuming each other's sessions. This check is not - * relevant to external PSK sessions that are not restored from a cache. - */ - if (!ret->psk_external - && (s->verify_mode & SSL_VERIFY_PEER) && s->sid_ctx_length == 0) { + if ((s->verify_mode & SSL_VERIFY_PEER) && s->sid_ctx_length == 0) { /* * We can't be sure if this session is being used out of context, * which is especially important for SSL_VERIFY_PEER. The application @@ -692,7 +679,7 @@ int ssl_get_prev_session(SSL_CONNECTION *s, CLIENTHELLO_MSG *hello) if (ret->flags & SSL_SESS_FLAG_EXTMS) { /* If old session includes extms, but new does not: abort handshake */ if (!(s->s3.flags & TLS1_FLAGS_RECEIVED_EXTMS)) { - SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE, SSL_R_INCONSISTENT_EXTMS); + SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_INCONSISTENT_EXTMS); fatal = 1; goto err; } @@ -707,32 +694,6 @@ int ssl_get_prev_session(SSL_CONNECTION *s, CLIENTHELLO_MSG *hello) s->session = ret; } - /* - * Explicit comparison between the session ID the client offered in - * ClientHello and the session ID embedded in the SSL_SESSION returned by - * the external cache. If they do not match, the cached session is released - * and ssl_get_prev_session() returns as a cache miss, forcing a full - * handshake. The check is placed in ssl_get_prev_session() rather than a - * later callback because this is the earliest point where both values are - * available simultaneously, before any ServerHello is composed. - * Catching the mismatch here ensures the server never sends a ServerHello - * that claims resumption of a session ID it cannot legitimately echo. - * - * A mismatch unambiguously indicates one of: - * - a corrupt cache entry - * - an external cache implementation that returned the wrong session - * - an active tampering attempt - * - * Refusing resumption and falling back to a full handshake is the correct - * response. - */ - if (!SSL_CONNECTION_IS_TLS13(s) && hello->session_id_len > 0 - && (s->session->session_id_length != hello->session_id_len - || memcmp(s->session->session_id, hello->session_id, - hello->session_id_len) - != 0)) { - return 0; - } ssl_tsan_counter(s->session_ctx, &s->session_ctx->stats.sess_hit); s->verify_result = s->session->verify_result; return 1; @@ -812,14 +773,6 @@ int SSL_CTX_add_session(SSL_CTX *ctx, SSL_SESSION *c) ssl_session_calculate_timeout(c); } - /* - * evicted_head is a singly-linked list (via the next pointer, which - * SSL_SESSION_list_remove zeroes out) of sessions evicted from the cache - * that need their remove_session_cb called and their reference dropped - * once the lock is released. - */ - SSL_SESSION *evicted_head = NULL; - if (s == NULL) { /* * new cache entry -- remove old ones if cache has become too large @@ -830,19 +783,16 @@ int SSL_CTX_add_session(SSL_CTX *ctx, SSL_SESSION *c) if (SSL_CTX_sess_get_cache_size(ctx) > 0) { while (SSL_CTX_sess_number(ctx) >= SSL_CTX_sess_get_cache_size(ctx)) { - SSL_SESSION *r = remove_session_locked(ctx, ctx->session_cache_tail); - - if (r == NULL) + if (!remove_session_lock(ctx, ctx->session_cache_tail, 0)) break; - ssl_tsan_counter(ctx, &ctx->stats.sess_cache_full); - r->next = evicted_head; - evicted_head = r; + else + ssl_tsan_counter(ctx, &ctx->stats.sess_cache_full); } } - - SSL_SESSION_list_add(ctx, c); } + SSL_SESSION_list_add(ctx, c); + if (s != NULL) { /* * existing cache entry -- decrement previously incremented reference @@ -853,59 +803,41 @@ int SSL_CTX_add_session(SSL_CTX *ctx, SSL_SESSION *c) ret = 0; } CRYPTO_THREAD_unlock(ctx->lock); - - while (evicted_head != NULL) { - SSL_SESSION *next = evicted_head->next; - - evicted_head->next = NULL; - if (ctx->remove_session_cb != NULL) - ctx->remove_session_cb(ctx, evicted_head); - SSL_SESSION_free(evicted_head); - evicted_head = next; - } - return ret; } int SSL_CTX_remove_session(SSL_CTX *ctx, SSL_SESSION *c) { - SSL_SESSION *r; - - if (c == NULL || c->session_id_length == 0) - return 0; - if (!CRYPTO_THREAD_write_lock(ctx->lock)) - return 0; - r = remove_session_locked(ctx, c); - CRYPTO_THREAD_unlock(ctx->lock); - - /* - * The callback is invoked even when the session is not in the internal - * cache so that external caches can be notified. - */ - if (ctx->remove_session_cb != NULL) - ctx->remove_session_cb(ctx, c); - SSL_SESSION_free(r); - return r != NULL; + return remove_session_lock(ctx, c, 1); } -/* - * Removes c from the session cache. Caller must hold ctx->lock. - * Returns the removed session (caller must invoke remove_session_cb and - * SSL_SESSION_free), or NULL if not found. - */ -static SSL_SESSION *remove_session_locked(SSL_CTX *ctx, SSL_SESSION *c) +static int remove_session_lock(SSL_CTX *ctx, SSL_SESSION *c, int lck) { - SSL_SESSION *r = NULL; + SSL_SESSION *r; + int ret = 0; - if (c != NULL && c->session_id_length != 0) { - r = lh_SSL_SESSION_retrieve(ctx->sessions, c); - if (r != NULL) { + if ((c != NULL) && (c->session_id_length != 0)) { + if (lck) { + if (!CRYPTO_THREAD_write_lock(ctx->lock)) + return 0; + } + if ((r = lh_SSL_SESSION_retrieve(ctx->sessions, c)) != NULL) { + ret = 1; r = lh_SSL_SESSION_delete(ctx->sessions, r); SSL_SESSION_list_remove(ctx, r); } c->not_resumable = 1; + + if (lck) + CRYPTO_THREAD_unlock(ctx->lock); + + if (ctx->remove_session_cb != NULL) + ctx->remove_session_cb(ctx, c); + + if (ret) + SSL_SESSION_free(r); } - return r; + return ret; } void SSL_SESSION_free(SSL_SESSION *ss) @@ -946,7 +878,7 @@ int SSL_SESSION_up_ref(SSL_SESSION *ss) { int i; - if (!CRYPTO_UP_REF(&ss->references, &i)) + if (CRYPTO_UP_REF(&ss->references, &i) <= 0) return 0; REF_PRINT_COUNT("SSL_SESSION", i, ss); @@ -1241,24 +1173,30 @@ int SSL_set_session_ticket_ext_cb(SSL *s, tls_session_ticket_ext_cb_fn cb, int SSL_set_session_ticket_ext(SSL *s, void *ext_data, int ext_len) { SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); - if (sc == NULL || ext_len < 0 || ext_len > 0xffff) + + if (sc == NULL) return 0; - OPENSSL_free(sc->ext.session_ticket); - if (ext_data != NULL) { + + if (sc->version >= TLS1_VERSION) { + OPENSSL_free(sc->ext.session_ticket); + sc->ext.session_ticket = NULL; sc->ext.session_ticket = OPENSSL_malloc(sizeof(TLS_SESSION_TICKET_EXT) + ext_len); if (sc->ext.session_ticket == NULL) return 0; - sc->ext.session_ticket->length = ext_len; - sc->ext.session_ticket->data = sc->ext.session_ticket + 1; - memcpy(sc->ext.session_ticket->data, ext_data, ext_len); - } else { - sc->ext.session_ticket = OPENSSL_malloc(sizeof(TLS_SESSION_TICKET_EXT)); - if (sc->ext.session_ticket == NULL) - return 0; - sc->ext.session_ticket->data = NULL; - sc->ext.session_ticket->length = 0; + + if (ext_data != NULL) { + sc->ext.session_ticket->length = ext_len; + sc->ext.session_ticket->data = sc->ext.session_ticket + 1; + memcpy(sc->ext.session_ticket->data, ext_data, ext_len); + } else { + sc->ext.session_ticket->length = 0; + sc->ext.session_ticket->data = NULL; + } + + return 1; } - return 1; + + return 0; } #ifndef OPENSSL_NO_DEPRECATED_3_4 @@ -1285,10 +1223,9 @@ void SSL_CTX_flush_sessions_ex(SSL_CTX *s, time_t t) /* * Iterate over the list from the back (oldest), and stop * when a session can no longer be removed. - * Collect removed sessions on a stack to be processed outside the lock, - * so that remove_session_cb is never invoked while holding ctx->lock. - * If the stack failed to create, or a push fails, free the session - * immediately (without invoking the callback). + * Add the session to a temporary list to be freed outside + * the SSL_CTX lock. + * But still do the remove_session_cb() within the lock. */ while (s->session_cache_tail != NULL) { current = s->session_cache_tail; @@ -1296,6 +1233,15 @@ void SSL_CTX_flush_sessions_ex(SSL_CTX *s, time_t t) lh_SSL_SESSION_delete(s->sessions, current); SSL_SESSION_list_remove(s, current); current->not_resumable = 1; + if (s->remove_session_cb != NULL) + s->remove_session_cb(s, current); + /* + * Throw the session on a stack, it's entirely plausible + * that while freeing outside the critical section, the + * session could be re-added, so avoid using the next/prev + * pointers. If the stack failed to create, or the session + * couldn't be put on the stack, just free it here + */ if (sk == NULL || !sk_SSL_SESSION_push(sk, current)) SSL_SESSION_free(current); } else { @@ -1306,13 +1252,7 @@ void SSL_CTX_flush_sessions_ex(SSL_CTX *s, time_t t) lh_SSL_SESSION_set_down_load(s->sessions, i); CRYPTO_THREAD_unlock(s->lock); - while (sk_SSL_SESSION_num(sk) > 0) { - current = sk_SSL_SESSION_pop(sk); - if (s->remove_session_cb != NULL) - s->remove_session_cb(s, current); - SSL_SESSION_free(current); - } - sk_SSL_SESSION_free(sk); + sk_SSL_SESSION_pop_free(sk, SSL_SESSION_free); } int ssl_clear_bad_session(SSL_CONNECTION *s) diff --git a/ssl/ssl_stat.c b/ssl/ssl_stat.c index 3c6e5d051d..d6ba000c65 100644 --- a/ssl/ssl_stat.c +++ b/ssl/ssl_stat.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright 2005 Nokia. All rights reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -333,10 +333,6 @@ const char *SSL_alert_desc_string(int value) return "BH"; case TLS1_AD_UNKNOWN_PSK_IDENTITY: return "UP"; -#ifndef OPENSSL_NO_ECH - case TLS1_AD_ECH_REQUIRED: - return "RR"; -#endif default: return "UK"; } @@ -407,10 +403,6 @@ const char *SSL_alert_desc_string_long(int value) return "unknown PSK identity"; case TLS1_AD_NO_APPLICATION_PROTOCOL: return "no application protocol"; -#ifndef OPENSSL_NO_ECH - case TLS1_AD_ECH_REQUIRED: - return "ECH required"; -#endif default: return "unknown"; } diff --git a/ssl/ssl_txt.c b/ssl/ssl_txt.c index 0fc3e5a334..aeb03bfeb2 100644 --- a/ssl/ssl_txt.c +++ b/ssl/ssl_txt.c @@ -104,7 +104,7 @@ int SSL_SESSION_print(BIO *bp, const SSL_SESSION *x) #endif if (x->ext.tick_lifetime_hint) { if (BIO_printf(bp, - "\n TLS session ticket lifetime hint: %lu (seconds)", + "\n TLS session ticket lifetime hint: %ld (seconds)", x->ext.tick_lifetime_hint) <= 0) goto err; @@ -123,7 +123,7 @@ int SSL_SESSION_print(BIO *bp, const SSL_SESSION *x) if (!ssl_cipher_get_evp(NULL, x, NULL, NULL, NULL, NULL, &comp, 0)) goto err; if (comp == NULL) { - if (BIO_printf(bp, "\n Compression: %u", x->compress_meth) <= 0) + if (BIO_printf(bp, "\n Compression: %d", x->compress_meth) <= 0) goto err; } else { if (BIO_printf(bp, "\n Compression: %d (%s)", comp->id, diff --git a/ssl/ssl_utst.c b/ssl/ssl_utst.c index 7ff8932e42..91be7398ca 100644 --- a/ssl/ssl_utst.c +++ b/ssl/ssl_utst.c @@ -7,9 +7,6 @@ * https://www.openssl.org/source/license.html */ -/* SSL_test_functions() is deprecated but still needs to be implemented */ -#include "internal/deprecated.h" - #include "ssl_local.h" #ifndef OPENSSL_NO_UNIT_TEST diff --git a/ssl/statem/extensions.c b/ssl/statem/extensions.c index 753402b84f..4c0d819ffe 100644 --- a/ssl/statem/extensions.c +++ b/ssl/statem/extensions.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -21,44 +21,11 @@ #include #include -/* - * values for ext_defs ech_handling field - * exceptionally, we don't conditionally compile that field to avoid a pile of - * ifndefs all over the ext_defs values - */ -#define OSSL_ECH_HANDLING_CALL_BOTH 1 /* call constructor both times */ -#define OSSL_ECH_HANDLING_COMPRESS 2 /* compress outer value into inner */ -#define OSSL_ECH_HANDLING_DUPLICATE 3 /* same value in inner and outer */ -/* - * DUPLICATE isn't really useful other than to show we can, - * and for debugging/tests/coverage so may disappear. Changes mostly - * won't affect the outer CH size, due to padding, but might for some - * larger extensions. - * - * Note there is a co-dependency with test/recipes/75-test_quicapi.t: - * If you change an |ech_handling| value, that may well affect the order - * of extensions in a ClientHello, which is reflected in the test data - * in test/recipes/75-test_quicapi_data/\*.txt files. To fix, you need - * to look in test-runs/test_quicapi for the "new" files and then edit - * (replacing actual octets with "?" in relevant places), and copy the - * result back over to test/recipes/75-test_quicapi_data/. The reason - * this happens is the ECH COMPRESS'd extensions need to be contiguous - * in the ClientHello, so changes to/from COMPRESS affect extension - * order, in inner and outer CH. There doesn't seem to be an easy, - * generic, way to reconcile these compile-time changes with having - * fixed value test files. Likely the best option is to decide on the - * disposition of ECH COMPRESS or not and consider that an at least - * medium-term thing. (But still allow other builds to vary at - * compile time if they need something different.) - */ -#ifndef OPENSSL_NO_ECH -static int init_ech(SSL_CONNECTION *s, unsigned int context); -static int final_ech(SSL_CONNECTION *s, unsigned int context, int sent); -#endif /* OPENSSL_NO_ECH */ - static int final_renegotiate(SSL_CONNECTION *s, unsigned int context, int sent); static int init_server_name(SSL_CONNECTION *s, unsigned int context); static int final_server_name(SSL_CONNECTION *s, unsigned int context, int sent); +static int final_ec_pt_formats(SSL_CONNECTION *s, unsigned int context, + int sent); static int init_session_ticket(SSL_CONNECTION *s, unsigned int context); #ifndef OPENSSL_NO_OCSP static int init_status_request(SSL_CONNECTION *s, unsigned int context); @@ -109,9 +76,6 @@ static EXT_RETURN tls_construct_compress_certificate(SSL_CONNECTION *sc, WPACKET static int tls_parse_compress_certificate(SSL_CONNECTION *sc, PACKET *pkt, unsigned int context, X509 *x, size_t chainidx); -static int tls_parse_ec_pt_formats(SSL_CONNECTION *s, PACKET *pkt, - unsigned int context, - X509 *x, size_t chainidx); /* Structure to define a built-in extension */ typedef struct extensions_definition_st { @@ -122,11 +86,6 @@ typedef struct extensions_definition_st { * protocol versions */ unsigned int context; - /* - * exceptionally, we don't conditionally compile this field to avoid a - * pile of ifndefs all over the ext_defs values - */ - int ech_handling; /* how to handle ECH for this extension type */ /* * Initialise extension before parsing. Always called for relevant contexts * even if extension not present @@ -181,20 +140,17 @@ typedef struct extensions_definition_st { * NOTE: WebSphere Application Server 7+ cannot handle empty extensions at * the end, keep these extensions before signature_algorithm. */ -#define INVALID_EXTENSION { TLSEXT_TYPE_invalid, 0, 0, NULL, NULL, NULL, NULL, NULL, NULL } - +#define INVALID_EXTENSION { TLSEXT_TYPE_invalid, 0, NULL, NULL, NULL, NULL, NULL, NULL } static const EXTENSION_DEFINITION ext_defs[] = { { TLSEXT_TYPE_renegotiate, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_SERVER_HELLO - | SSL_EXT_TLS1_2_AND_BELOW_ONLY, - OSSL_ECH_HANDLING_COMPRESS, + | SSL_EXT_SSL3_ALLOWED | SSL_EXT_TLS1_2_AND_BELOW_ONLY, NULL, tls_parse_ctos_renegotiate, tls_parse_stoc_renegotiate, tls_construct_stoc_renegotiate, tls_construct_ctos_renegotiate, final_renegotiate }, { TLSEXT_TYPE_server_name, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_TLS1_3_ENCRYPTED_EXTENSIONS, - OSSL_ECH_HANDLING_CALL_BOTH, init_server_name, tls_parse_ctos_server_name, tls_parse_stoc_server_name, tls_construct_stoc_server_name, tls_construct_ctos_server_name, @@ -202,14 +158,12 @@ static const EXTENSION_DEFINITION ext_defs[] = { { TLSEXT_TYPE_max_fragment_length, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_TLS1_3_ENCRYPTED_EXTENSIONS, - OSSL_ECH_HANDLING_COMPRESS, NULL, tls_parse_ctos_maxfragmentlen, tls_parse_stoc_maxfragmentlen, tls_construct_stoc_maxfragmentlen, tls_construct_ctos_maxfragmentlen, final_maxfragmentlen }, #ifndef OPENSSL_NO_SRP { TLSEXT_TYPE_srp, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_AND_BELOW_ONLY, - OSSL_ECH_HANDLING_COMPRESS, init_srp, tls_parse_ctos_srp, NULL, NULL, tls_construct_ctos_srp, NULL }, #else INVALID_EXTENSION, @@ -217,10 +171,9 @@ static const EXTENSION_DEFINITION ext_defs[] = { { TLSEXT_TYPE_ec_point_formats, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_TLS1_2_AND_BELOW_ONLY, - OSSL_ECH_HANDLING_COMPRESS, - init_ec_point_formats, tls_parse_ec_pt_formats, tls_parse_ec_pt_formats, + init_ec_point_formats, tls_parse_ctos_ec_pt_formats, tls_parse_stoc_ec_pt_formats, tls_construct_stoc_ec_pt_formats, tls_construct_ctos_ec_pt_formats, - NULL }, + final_ec_pt_formats }, { /* * "supported_groups" is spread across several specifications. * It was originally specified as "elliptic_curves" in RFC 4492, @@ -249,14 +202,12 @@ static const EXTENSION_DEFINITION ext_defs[] = { TLSEXT_TYPE_supported_groups, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_ENCRYPTED_EXTENSIONS | SSL_EXT_TLS1_2_SERVER_HELLO, - OSSL_ECH_HANDLING_COMPRESS, NULL, tls_parse_ctos_supported_groups, NULL, tls_construct_stoc_supported_groups, tls_construct_ctos_supported_groups, NULL }, { TLSEXT_TYPE_session_ticket, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_TLS1_2_AND_BELOW_ONLY, - OSSL_ECH_HANDLING_COMPRESS, init_session_ticket, tls_parse_ctos_session_ticket, tls_parse_stoc_session_ticket, tls_construct_stoc_session_ticket, tls_construct_ctos_session_ticket, NULL }, @@ -264,7 +215,6 @@ static const EXTENSION_DEFINITION ext_defs[] = { { TLSEXT_TYPE_status_request, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_TLS1_3_CERTIFICATE | SSL_EXT_TLS1_3_CERTIFICATE_REQUEST, - OSSL_ECH_HANDLING_COMPRESS, init_status_request, tls_parse_ctos_status_request, tls_parse_stoc_status_request, tls_construct_stoc_status_request, tls_construct_ctos_status_request, NULL }, @@ -275,7 +225,6 @@ static const EXTENSION_DEFINITION ext_defs[] = { { TLSEXT_TYPE_next_proto_neg, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_TLS1_2_AND_BELOW_ONLY, - OSSL_ECH_HANDLING_COMPRESS, init_npn, tls_parse_ctos_npn, tls_parse_stoc_npn, tls_construct_stoc_next_proto_neg, tls_construct_ctos_npn, NULL }, #else @@ -288,14 +237,12 @@ static const EXTENSION_DEFINITION ext_defs[] = { TLSEXT_TYPE_application_layer_protocol_negotiation, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_TLS1_3_ENCRYPTED_EXTENSIONS, - OSSL_ECH_HANDLING_CALL_BOTH, init_alpn, tls_parse_ctos_alpn, tls_parse_stoc_alpn, tls_construct_stoc_alpn, tls_construct_ctos_alpn, final_alpn }, #ifndef OPENSSL_NO_SRTP { TLSEXT_TYPE_use_srtp, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_TLS1_3_ENCRYPTED_EXTENSIONS | SSL_EXT_DTLS_ONLY, - OSSL_ECH_HANDLING_COMPRESS, init_srtp, tls_parse_ctos_use_srtp, tls_parse_stoc_use_srtp, tls_construct_stoc_use_srtp, tls_construct_ctos_use_srtp, NULL }, #else @@ -304,22 +251,12 @@ static const EXTENSION_DEFINITION ext_defs[] = { { TLSEXT_TYPE_encrypt_then_mac, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_TLS1_2_AND_BELOW_ONLY, - /* - * If you want to demonstrate/exercise duplicate, then - * this does that and has no effect on sizes, but it - * will break the quicapi test (see above). Probably - * best done in local tests and not committed to any - * upstream. - * OSSL_ECH_HANDLING_DUPLICATE, - */ - OSSL_ECH_HANDLING_COMPRESS, init_etm, tls_parse_ctos_etm, tls_parse_stoc_etm, tls_construct_stoc_etm, tls_construct_ctos_etm, NULL }, #ifndef OPENSSL_NO_CT { TLSEXT_TYPE_signed_certificate_timestamp, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_TLS1_3_CERTIFICATE | SSL_EXT_TLS1_3_CERTIFICATE_REQUEST, - OSSL_ECH_HANDLING_COMPRESS, NULL, /* * No server side support for this, but can be provided by a custom @@ -333,12 +270,10 @@ static const EXTENSION_DEFINITION ext_defs[] = { { TLSEXT_TYPE_extended_master_secret, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_TLS1_2_AND_BELOW_ONLY, - OSSL_ECH_HANDLING_COMPRESS, init_ems, tls_parse_ctos_ems, tls_parse_stoc_ems, tls_construct_stoc_ems, tls_construct_ctos_ems, final_ems }, { TLSEXT_TYPE_signature_algorithms_cert, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_CERTIFICATE_REQUEST, - OSSL_ECH_HANDLING_COMPRESS, init_sig_algs_cert, tls_parse_ctos_sig_algs_cert, tls_parse_ctos_sig_algs_cert, /* We do not generate signature_algorithms_cert at present. */ @@ -346,7 +281,6 @@ static const EXTENSION_DEFINITION ext_defs[] = { { TLSEXT_TYPE_post_handshake_auth, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_ONLY, - OSSL_ECH_HANDLING_COMPRESS, init_post_handshake_auth, tls_parse_ctos_post_handshake_auth, NULL, @@ -357,7 +291,6 @@ static const EXTENSION_DEFINITION ext_defs[] = { { TLSEXT_TYPE_client_cert_type, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_ENCRYPTED_EXTENSIONS | SSL_EXT_TLS1_2_SERVER_HELLO, - OSSL_ECH_HANDLING_CALL_BOTH, init_client_cert_type, tls_parse_ctos_client_cert_type, tls_parse_stoc_client_cert_type, tls_construct_stoc_client_cert_type, tls_construct_ctos_client_cert_type, @@ -365,21 +298,18 @@ static const EXTENSION_DEFINITION ext_defs[] = { { TLSEXT_TYPE_server_cert_type, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_ENCRYPTED_EXTENSIONS | SSL_EXT_TLS1_2_SERVER_HELLO, - OSSL_ECH_HANDLING_CALL_BOTH, init_server_cert_type, tls_parse_ctos_server_cert_type, tls_parse_stoc_server_cert_type, tls_construct_stoc_server_cert_type, tls_construct_ctos_server_cert_type, NULL }, { TLSEXT_TYPE_signature_algorithms, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_CERTIFICATE_REQUEST, - OSSL_ECH_HANDLING_COMPRESS, init_sig_algs, tls_parse_ctos_sig_algs, tls_parse_ctos_sig_algs, tls_construct_ctos_sig_algs, tls_construct_ctos_sig_algs, final_sig_algs }, { TLSEXT_TYPE_supported_versions, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_SERVER_HELLO | SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST | SSL_EXT_TLS_IMPLEMENTATION_ONLY, - OSSL_ECH_HANDLING_COMPRESS, NULL, /* Processed inline as part of version selection */ NULL, tls_parse_stoc_supported_versions, @@ -388,7 +318,6 @@ static const EXTENSION_DEFINITION ext_defs[] = { { TLSEXT_TYPE_psk_kex_modes, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS_IMPLEMENTATION_ONLY | SSL_EXT_TLS1_3_ONLY, - OSSL_ECH_HANDLING_COMPRESS, init_psk_kex_modes, tls_parse_ctos_psk_kex_modes, NULL, NULL, tls_construct_ctos_psk_kex_modes, NULL }, { /* @@ -399,7 +328,6 @@ static const EXTENSION_DEFINITION ext_defs[] = { SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_SERVER_HELLO | SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST | SSL_EXT_TLS_IMPLEMENTATION_ONLY | SSL_EXT_TLS1_3_ONLY, - OSSL_ECH_HANDLING_COMPRESS, NULL, tls_parse_ctos_key_share, tls_parse_stoc_key_share, tls_construct_stoc_key_share, tls_construct_ctos_key_share, final_key_share }, @@ -407,7 +335,6 @@ static const EXTENSION_DEFINITION ext_defs[] = { TLSEXT_TYPE_cookie, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST | SSL_EXT_TLS_IMPLEMENTATION_ONLY | SSL_EXT_TLS1_3_ONLY, - OSSL_ECH_HANDLING_COMPRESS, NULL, tls_parse_ctos_cookie, tls_parse_stoc_cookie, tls_construct_stoc_cookie, tls_construct_ctos_cookie, NULL }, { /* @@ -418,12 +345,10 @@ static const EXTENSION_DEFINITION ext_defs[] = { TLSEXT_TYPE_cryptopro_bug, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_TLS1_2_AND_BELOW_ONLY, - OSSL_ECH_HANDLING_COMPRESS, NULL, NULL, NULL, tls_construct_stoc_cryptopro_bug, NULL, NULL }, { TLSEXT_TYPE_compress_certificate, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_CERTIFICATE_REQUEST | SSL_EXT_TLS_IMPLEMENTATION_ONLY | SSL_EXT_TLS1_3_ONLY, - OSSL_ECH_HANDLING_COMPRESS, tls_init_compress_certificate, tls_parse_compress_certificate, tls_parse_compress_certificate, tls_construct_compress_certificate, tls_construct_compress_certificate, @@ -431,7 +356,6 @@ static const EXTENSION_DEFINITION ext_defs[] = { { TLSEXT_TYPE_early_data, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_ENCRYPTED_EXTENSIONS | SSL_EXT_TLS1_3_NEW_SESSION_TICKET | SSL_EXT_TLS1_3_ONLY, - OSSL_ECH_HANDLING_CALL_BOTH, NULL, tls_parse_ctos_early_data, tls_parse_stoc_early_data, tls_construct_stoc_early_data, tls_construct_ctos_early_data, final_early_data }, @@ -439,7 +363,6 @@ static const EXTENSION_DEFINITION ext_defs[] = { TLSEXT_TYPE_certificate_authorities, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_CERTIFICATE_REQUEST | SSL_EXT_TLS1_3_ONLY, - OSSL_ECH_HANDLING_COMPRESS, init_certificate_authorities, tls_parse_certificate_authorities, tls_parse_certificate_authorities, @@ -447,41 +370,9 @@ static const EXTENSION_DEFINITION ext_defs[] = { tls_construct_certificate_authorities, NULL, }, -#ifndef OPENSSL_NO_ECH - { TLSEXT_TYPE_ech, - SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_ONLY | SSL_EXT_TLS1_3_ENCRYPTED_EXTENSIONS | SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST, - OSSL_ECH_HANDLING_CALL_BOTH, - init_ech, - tls_parse_ctos_ech, tls_parse_stoc_ech, - tls_construct_stoc_ech, tls_construct_ctos_ech, - final_ech }, - { TLSEXT_TYPE_outer_extensions, - SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_ONLY, - OSSL_ECH_HANDLING_CALL_BOTH, - NULL, - NULL, NULL, - NULL, NULL, - NULL }, -#else /* OPENSSL_NO_ECH */ - INVALID_EXTENSION, - INVALID_EXTENSION, -#endif /* END_OPENSSL_NO_ECH */ - { /* RFC 8701 GREASE extension 1 - type is dynamic */ - TLSEXT_TYPE_grease1, - SSL_EXT_CLIENT_HELLO, - 0, - NULL, - NULL, NULL, NULL, tls_construct_ctos_grease1, NULL }, - { /* RFC 8701 GREASE extension 2 - type is dynamic */ - TLSEXT_TYPE_grease2, - SSL_EXT_CLIENT_HELLO, - 0, - NULL, - NULL, NULL, NULL, tls_construct_ctos_grease2, NULL }, { /* Must be immediately before pre_shared_key */ TLSEXT_TYPE_padding, SSL_EXT_CLIENT_HELLO, - OSSL_ECH_HANDLING_CALL_BOTH, NULL, /* We send this, but don't read it */ NULL, NULL, NULL, tls_construct_ctos_padding, NULL }, @@ -489,142 +380,10 @@ static const EXTENSION_DEFINITION ext_defs[] = { TLSEXT_TYPE_psk, SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_SERVER_HELLO | SSL_EXT_TLS_IMPLEMENTATION_ONLY | SSL_EXT_TLS1_3_ONLY, - OSSL_ECH_HANDLING_CALL_BOTH, NULL, tls_parse_ctos_psk, tls_parse_stoc_psk, tls_construct_stoc_psk, tls_construct_ctos_psk, final_psk } }; -#ifndef OPENSSL_NO_ECH -/* - * Copy an inner extension value to outer. - * inner CH must have been pre-decoded into s->clienthello->pre_proc_exts - * already. - */ -int ossl_ech_copy_inner2outer(SSL_CONNECTION *s, uint16_t ext_type, - int ind, WPACKET *pkt) -{ - RAW_EXTENSION *myext = NULL, *raws = NULL; - - if (s == NULL || s->clienthello == NULL) - return OSSL_ECH_SAME_EXT_ERR; - raws = s->clienthello->pre_proc_exts; - if (raws == NULL) - return OSSL_ECH_SAME_EXT_ERR; - myext = &raws[ind]; - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "inner2outer: Copying ext type %d to outer\n", - ext_type); - } - OSSL_TRACE_END(TLS); - - /* - * copy inner value to outer - */ - if (PACKET_data(&myext->data) != NULL - && PACKET_remaining(&myext->data) > 0) { - if (!WPACKET_put_bytes_u16(pkt, ext_type) - || !WPACKET_sub_memcpy_u16(pkt, PACKET_data(&myext->data), - PACKET_remaining(&myext->data))) - return OSSL_ECH_SAME_EXT_ERR; - } else { - /* empty extension */ - if (!WPACKET_put_bytes_u16(pkt, ext_type) - || !WPACKET_put_bytes_u16(pkt, 0)) - return OSSL_ECH_SAME_EXT_ERR; - } - return 1; -} - -/* - * DUPEMALL is useful for testing - this turns off compression and - * causes two calls to each extension constructor, which'd be the same - * as making all entries in ext_tab use the CALL_BOTH value - */ -#undef DUPEMALL - -/* - * Check if we're using the same/different key shares - * return 1 if same key share in inner and outer, 0 otherwise - */ -int ossl_ech_same_key_share(void) -{ -#ifdef DUPEMALL - return 0; -#endif - return ext_defs[TLSEXT_IDX_key_share].ech_handling - != OSSL_ECH_HANDLING_CALL_BOTH; -} - -/* - * say if extension at index |ind| in ext_defs is to be ECH compressed - * return 1 if this one is to be compressed, 0 if not, -1 for error - */ -int ossl_ech_2bcompressed(size_t ind) -{ - const size_t nexts = OSSL_NELEM(ext_defs); - -#ifdef DUPEMALL - return 0; -#endif - if (ind >= nexts) - return -1; - return ext_defs[ind].ech_handling == OSSL_ECH_HANDLING_COMPRESS; -} - -/* as needed, repeat extension from inner in outer handling compression */ -int ossl_ech_same_ext(SSL_CONNECTION *s, WPACKET *pkt) -{ - unsigned int type = 0; - int tind = 0, nexts = OSSL_NELEM(ext_defs); - -#ifdef DUPEMALL - return OSSL_ECH_SAME_EXT_CONTINUE; -#endif - if (s == NULL || s->ext.ech.es == NULL) - return OSSL_ECH_SAME_EXT_CONTINUE; /* nothing to do */ - /* - * We store/access the index of the extension handler in - * s->ext.ech.ext_ind, as we'd otherwise not know it here. - * Be nice were there a better way to handle that. - */ - tind = s->ext.ech.ext_ind; - /* If this index'd extension won't be compressed, we're done */ - if (tind < 0 || tind >= nexts) - return OSSL_ECH_SAME_EXT_ERR; - type = ext_defs[tind].type; - if (s->ext.ech.ch_depth == 1) { - /* inner CH - just note compression as configured */ - if (ext_defs[tind].ech_handling != OSSL_ECH_HANDLING_COMPRESS) - return OSSL_ECH_SAME_EXT_CONTINUE; - /* mark this one to be "compressed" */ - if (s->ext.ech.n_outer_only >= OSSL_ECH_OUTERS_MAX) - return OSSL_ECH_SAME_EXT_ERR; - s->ext.ech.outer_only[s->ext.ech.n_outer_only] = type; - s->ext.ech.n_outer_only++; - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "ech_same_ext: Marking (type %u, ind %d " - "tot-comp %d) for compression\n", - type, tind, - (int)s->ext.ech.n_outer_only); - } - OSSL_TRACE_END(TLS); - return OSSL_ECH_SAME_EXT_CONTINUE; - } else { - /* Copy value from inner to outer, or indicate a new value needed */ - if (s->clienthello == NULL || pkt == NULL) - return OSSL_ECH_SAME_EXT_ERR; - if (ext_defs[tind].ech_handling == OSSL_ECH_HANDLING_CALL_BOTH) - return OSSL_ECH_SAME_EXT_CONTINUE; - else - return ossl_ech_copy_inner2outer(s, type, tind, pkt); - } - /* just in case - shouldn't happen */ - return OSSL_ECH_SAME_EXT_ERR; -} -#endif - /* Returns a TLSEXT_TYPE for the given index */ unsigned int ossl_get_extension_type(size_t idx) { @@ -723,16 +482,9 @@ static int verify_extension(SSL_CONNECTION *s, unsigned int context, ENDPOINT role = ENDPOINT_BOTH; custom_ext_method *meth = NULL; - if ((context & SSL_EXT_CLIENT_HELLO) != 0) { -#ifndef OPENSSL_NO_ECH - if (s->ext.ech.attempted == 1 && s->ext.ech.ch_depth == 1) - role = ENDPOINT_CLIENT; - else - role = ENDPOINT_SERVER; -#else + if ((context & SSL_EXT_CLIENT_HELLO) != 0) role = ENDPOINT_SERVER; -#endif - } else if ((context & SSL_EXT_TLS1_2_SERVER_HELLO) != 0) + else if ((context & SSL_EXT_TLS1_2_SERVER_HELLO) != 0) role = ENDPOINT_CLIENT; meth = custom_ext_find(meths, role, type, &offset); @@ -749,111 +501,6 @@ static int verify_extension(SSL_CONNECTION *s, unsigned int context, return 1; } -/* - * Parse an ec_point_formats extension off the wire (one function for - * both sides). The peer's list is retained verbatim for - * SSL_get0_ec_point_formats() and for the RFC 4492/8422 section 5.1.2 - * 'uncompressed must be present' check. - * - * The check is gated on the negotiated ciphersuite -- a TLS 1.3 - * handshake or a non-ECC TLS 1.2 ciphersuite makes the extension moot - * and any missing 'uncompressed' codepoint is ignored. On the client - * the chosen ciphersuite is already locked in by the time we parse - * ServerHello, so the check happens inline here. On the server it's - * deferred to tls_construct_stoc_ec_pt_formats(), the first point at - * which s->s3.tmp.new_cipher is set for TLS 1.2. - */ -static int tls_parse_ec_pt_formats(SSL_CONNECTION *s, PACKET *pkt, - unsigned int context, X509 *x, size_t chainidx) -{ - PACKET list; - - if (!PACKET_as_length_prefixed_1(pkt, &list) - || PACKET_remaining(&list) == 0) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - return 0; - } - if (!s->hit - && !PACKET_memdup(&list, &s->ext.peer_ecpointformats, - &s->ext.peer_ecpointformats_len)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - - if (!s->server) { - unsigned long alg_k = s->s3.tmp.new_cipher->algorithm_mkey; - unsigned long alg_a = s->s3.tmp.new_cipher->algorithm_auth; - - if (((alg_k & SSL_kECDHE) || (alg_a & SSL_aECDSA)) - && memchr(PACKET_data(&list), - TLSEXT_ECPOINTFORMAT_uncompressed, - PACKET_remaining(&list)) - == NULL) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, - SSL_R_TLS_INVALID_ECPOINTFORMAT_LIST); - return 0; - } - } - - return 1; -} - -/* - * Verify that all extensions in |packet| are known built-in or custom - * extension types. This is used for TLS 1.3 server extension responses where - * unknown extensions are not ignored. - */ -int tls_validate_no_unknown_extensions(SSL_CONNECTION *s, PACKET *packet, - unsigned int context) -{ - PACKET extensions = *packet; - custom_ext_methods *exts = &s->cert->custext; - ENDPOINT role = ENDPOINT_BOTH; - - if ((context & SSL_EXT_CLIENT_HELLO) != 0) { -#ifndef OPENSSL_NO_ECH - if (s->ext.ech.attempted == 1 && s->ext.ech.ch_depth == 1) - role = ENDPOINT_CLIENT; - else - role = ENDPOINT_SERVER; -#else - role = ENDPOINT_SERVER; -#endif - } else if ((context & SSL_EXT_TLS1_2_SERVER_HELLO) != 0) { - role = ENDPOINT_CLIENT; - } - - while (PACKET_remaining(&extensions) > 0) { - unsigned int type; - size_t i; - PACKET extension; - const EXTENSION_DEFINITION *thisext; - - if (!PACKET_get_net_2(&extensions, &type) - || !PACKET_get_length_prefixed_2(&extensions, &extension)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - return 0; - } - - for (i = 0, thisext = ext_defs; i < OSSL_NELEM(ext_defs); - i++, thisext++) { - if (type == thisext->type) - break; - } - if (i < OSSL_NELEM(ext_defs)) - continue; - - if (exts != NULL && custom_ext_find(exts, role, type, NULL) != NULL) - continue; - - SSLfatal(s, SSL_AD_UNSUPPORTED_EXTENSION, - SSL_R_UNSOLICITED_EXTENSION); - return 0; - } - - return 1; -} - /* * Check whether the context defined for an extension |extctx| means whether * the extension is relevant for the current context |thisctx| or not. Returns @@ -875,6 +522,8 @@ int extension_is_relevant(SSL_CONNECTION *s, unsigned int extctx, if ((SSL_CONNECTION_IS_DTLS(s) && (extctx & SSL_EXT_TLS_IMPLEMENTATION_ONLY) != 0) + || (s->version == SSL3_VERSION + && (extctx & SSL_EXT_SSL3_ALLOWED) == 0) /* * Note that SSL_IS_TLS13() means "TLS 1.3 has been negotiated", * which is never true when generating the ClientHello. @@ -925,13 +574,8 @@ int tls_collect_extensions(SSL_CONNECTION *s, PACKET *packet, * Initialise server side custom extensions. Client side is done during * construction of extensions for the ClientHello. */ -#ifndef OPENSSL_NO_ECH - if ((context & SSL_EXT_CLIENT_HELLO) != 0 && s->ext.ech.attempted == 0) - custom_ext_init(&s->cert->custext); -#else if ((context & SSL_EXT_CLIENT_HELLO) != 0) custom_ext_init(&s->cert->custext); -#endif num_exts = OSSL_NELEM(ext_defs) + (exts != NULL ? exts->meths_count : 0); raw_extensions = OPENSSL_calloc(num_exts, sizeof(*raw_extensions)); @@ -963,10 +607,6 @@ int tls_collect_extensions(SSL_CONNECTION *s, PACKET *packet, SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); goto err; } - /* The server must tolerate the unknown extension and complete. */ - if (thisex == NULL) - continue; - idx = (unsigned int)(thisex - raw_extensions); /*- * Check that we requested this extension (if appropriate). Requests can @@ -997,15 +637,17 @@ int tls_collect_extensions(SSL_CONNECTION *s, PACKET *packet, SSL_R_UNSOLICITED_EXTENSION); goto err; } - thisex->data = extension; - thisex->present = 1; - thisex->type = type; - thisex->received_order = i++; - if (s->ext.debug_cb) - s->ext.debug_cb(SSL_CONNECTION_GET_USER_SSL(s), !s->server, - thisex->type, PACKET_data(&thisex->data), - (int)PACKET_remaining(&thisex->data), - s->ext.debug_arg); + if (thisex != NULL) { + thisex->data = extension; + thisex->present = 1; + thisex->type = type; + thisex->received_order = i++; + if (s->ext.debug_cb) + s->ext.debug_cb(SSL_CONNECTION_GET_USER_SSL(s), !s->server, + thisex->type, PACKET_data(&thisex->data), + (int)PACKET_remaining(&thisex->data), + s->ext.debug_arg); + } } if (init) { @@ -1164,9 +806,6 @@ int tls_construct_extensions(SSL_CONNECTION *s, WPACKET *pkt, int min_version, max_version = 0, reason; const EXTENSION_DEFINITION *thisexd; int for_comp = (context & SSL_EXT_TLS1_3_CERTIFICATE_COMPRESSION) != 0; -#ifndef OPENSSL_NO_ECH - int pass; -#endif if (!WPACKET_start_sub_packet_u16(pkt) /* @@ -1192,90 +831,47 @@ int tls_construct_extensions(SSL_CONNECTION *s, WPACKET *pkt, } /* Add custom extensions first */ -#ifndef OPENSSL_NO_ECH - if ((context & SSL_EXT_CLIENT_HELLO) != 0 && s->ext.ech.attempted == 0) + if ((context & SSL_EXT_CLIENT_HELLO) != 0) { /* On the server side with initialise during ClientHello parsing */ custom_ext_init(&s->cert->custext); -#else - if ((context & SSL_EXT_CLIENT_HELLO) != 0) - /* On the server side with initialise during ClientHello parsing */ - custom_ext_init(&s->cert->custext); -#endif + } if (!custom_ext_add(s, context, pkt, x, chainidx, max_version)) { /* SSLfatal() already called */ return 0; } -#ifndef OPENSSL_NO_ECH - /* - * Two passes if doing real ECH - we first construct the - * to-be-ECH-compressed extensions, and then go around again - * constructing those that aren't to be ECH-compressed. We - * need to ensure this ordering so that all the ECH-compressed - * extensions are contiguous in the encoding. The actual - * compression happens later in ech_encode_inner(). - */ - for (pass = 0; pass <= 1; pass++) -#endif + for (i = 0, thisexd = ext_defs; i < OSSL_NELEM(ext_defs); i++, thisexd++) { + EXT_RETURN (*construct)(SSL_CONNECTION *s, WPACKET *pkt, + unsigned int context, + X509 *x, size_t chainidx); + EXT_RETURN ret; - for (i = 0, thisexd = ext_defs; i < OSSL_NELEM(ext_defs); - i++, thisexd++) { - EXT_RETURN (*construct)(SSL_CONNECTION *s, WPACKET *pkt, - unsigned int context, - X509 *x, size_t chainidx); - EXT_RETURN ret; + /* Skip if not relevant for our context */ + if (!should_add_extension(s, thisexd->context, context, max_version)) + continue; -#ifndef OPENSSL_NO_ECH - /* do compressed in pass 0, non-compressed in pass 1 */ - if (ossl_ech_2bcompressed((int)i) == pass) - continue; - /* stash index - needed for COMPRESS ECH handling */ - s->ext.ech.ext_ind = (int)i; -#endif - /* Skip if not relevant for our context */ - if (!should_add_extension(s, thisexd->context, context, max_version)) - continue; + construct = s->server ? thisexd->construct_stoc + : thisexd->construct_ctos; - construct = s->server ? thisexd->construct_stoc - : thisexd->construct_ctos; + if (construct == NULL) + continue; - if (construct == NULL) - continue; - - ret = construct(s, pkt, context, x, chainidx); - if (ret == EXT_RETURN_FAIL) { - /* SSLfatal() already called */ - return 0; - } - if (ret == EXT_RETURN_SENT - && (context & (SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_CERTIFICATE_REQUEST | SSL_EXT_TLS1_3_NEW_SESSION_TICKET)) != 0) - s->ext.extflags[i] |= SSL_EXT_FLAG_SENT; - } - -#ifndef OPENSSL_NO_ECH - /* - * don't close yet if client in the middle of doing ECH, we'll - * eventually close this in ech_aad_and_encrypt() after we add - * the real ECH extension value - */ - if (s->server - || context != SSL_EXT_CLIENT_HELLO - || s->ext.ech.attempted == 0 - || s->ext.ech.ch_depth == 1 - || s->ext.ech.grease == OSSL_ECH_IS_GREASE) { - if (!WPACKET_close(pkt)) { - if (!for_comp) - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + ret = construct(s, pkt, context, x, chainidx); + if (ret == EXT_RETURN_FAIL) { + /* SSLfatal() already called */ return 0; } + if (ret == EXT_RETURN_SENT + && (context & (SSL_EXT_CLIENT_HELLO | SSL_EXT_TLS1_3_CERTIFICATE_REQUEST | SSL_EXT_TLS1_3_NEW_SESSION_TICKET)) != 0) + s->ext.extflags[i] |= SSL_EXT_FLAG_SENT; } -#else + if (!WPACKET_close(pkt)) { if (!for_comp) SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); return 0; } -#endif + return 1; } @@ -1337,36 +933,6 @@ static int init_server_name(SSL_CONNECTION *s, unsigned int context) return 1; } -#ifndef OPENSSL_NO_ECH -/* - * Just note that ech is not yet done - * return 1 for good, 0 otherwise - */ -static int init_ech(SSL_CONNECTION *s, unsigned int context) -{ - const int nexts = OSSL_NELEM(ext_defs); - - /* we don't need this assert everywhere - anywhere is fine */ - if (!ossl_assert(TLSEXT_IDX_num_builtins == nexts)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - if ((context & SSL_EXT_CLIENT_HELLO) != 0) - s->ext.ech.done = 0; - return 1; -} - -static int final_ech(SSL_CONNECTION *s, unsigned int context, int sent) -{ - if (s->server && s->ext.ech.success == 1 - && s->ext.ech.inner_ech_seen_ok != 1) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_ECH_REQUIRED); - return 0; - } - return 1; -} -#endif /* OPENSSL_NO_ECH */ - static int final_server_name(SSL_CONNECTION *s, unsigned int context, int sent) { int ret = SSL_TLSEXT_ERR_NOACK; @@ -1468,6 +1034,45 @@ static int final_server_name(SSL_CONNECTION *s, unsigned int context, int sent) } } +static int final_ec_pt_formats(SSL_CONNECTION *s, unsigned int context, + int sent) +{ + unsigned long alg_k, alg_a; + + if (s->server) + return 1; + + alg_k = s->s3.tmp.new_cipher->algorithm_mkey; + alg_a = s->s3.tmp.new_cipher->algorithm_auth; + + /* + * If we are client and using an elliptic curve cryptography cipher + * suite, then if server returns an EC point formats lists extension it + * must contain uncompressed. + */ + if (s->ext.ecpointformats != NULL + && s->ext.ecpointformats_len > 0 + && s->ext.peer_ecpointformats != NULL + && s->ext.peer_ecpointformats_len > 0 + && ((alg_k & SSL_kECDHE) || (alg_a & SSL_aECDSA))) { + /* we are using an ECC cipher */ + size_t i; + unsigned char *list = s->ext.peer_ecpointformats; + + for (i = 0; i < s->ext.peer_ecpointformats_len; i++) { + if (*list++ == TLSEXT_ECPOINTFORMAT_uncompressed) + break; + } + if (i == s->ext.peer_ecpointformats_len) { + SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, + SSL_R_TLS_INVALID_ECPOINTFORMAT_LIST); + return 0; + } + } + + return 1; +} + static int init_session_ticket(SSL_CONNECTION *s, unsigned int context) { if (!s->server) @@ -1956,23 +1561,11 @@ int tls_psk_do_binder(SSL_CONNECTION *s, const EVP_MD *md, long hdatalen_l; void *hdata; -#ifndef OPENSSL_NO_ECH - /* handle the hashing as per ECH needs (on client) */ - if (s->ext.ech.attempted == 1 && s->ext.ech.ch_depth == 1) { - if (ossl_ech_intbuf_fetch(s, (unsigned char **)&hdata, &hdatalen) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - } else { -#endif - hdatalen = hdatalen_l = BIO_get_mem_data(s->s3.handshake_buffer, &hdata); - if (hdatalen_l <= 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_BAD_HANDSHAKE_LENGTH); - goto err; - } -#ifndef OPENSSL_NO_ECH + hdatalen = hdatalen_l = BIO_get_mem_data(s->s3.handshake_buffer, &hdata); + if (hdatalen_l <= 0) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_BAD_HANDSHAKE_LENGTH); + goto err; } -#endif /* * For servers the handshake buffer data will include the second @@ -2044,6 +1637,7 @@ err: OPENSSL_cleanse(finishedkey, sizeof(finishedkey)); EVP_PKEY_free(mackey); EVP_MD_CTX_free(mctx); + return ret; } @@ -2170,9 +1764,6 @@ static EXT_RETURN tls_construct_compress_certificate(SSL_CONNECTION *sc, WPACKET if (sc->cert_comp_prefs[0] == TLSEXT_comp_cert_none) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(sc, context, pkt); -#endif if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_compress_certificate) || !WPACKET_start_sub_packet_u16(pkt) diff --git a/ssl/statem/extensions_clnt.c b/ssl/statem/extensions_clnt.c index f17fe2c495..4da3c18117 100644 --- a/ssl/statem/extensions_clnt.c +++ b/ssl/statem/extensions_clnt.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -11,19 +11,7 @@ #include "../ssl_local.h" #include "internal/cryptlib.h" #include "internal/ssl_unwrap.h" -#include "internal/tlsgroups.h" #include "statem_local.h" -#ifndef OPENSSL_NO_ECH -#include -#include "internal/ech_helpers.h" -#endif - -/* Used in the negotiate_dhe function */ -typedef enum { - ffdhe_check, - ecdhe_check, - ptfmt_check -} dhe_check_t; EXT_RETURN tls_construct_ctos_renegotiate(SSL_CONNECTION *s, WPACKET *pkt, unsigned int context, X509 *x, @@ -47,10 +35,6 @@ EXT_RETURN tls_construct_ctos_renegotiate(SSL_CONNECTION *s, WPACKET *pkt, return EXT_RETURN_NOT_SENT; } -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif - if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_renegotiate) || !WPACKET_start_sub_packet_u16(pkt) || !WPACKET_put_bytes_u8(pkt, 0) @@ -62,10 +46,6 @@ EXT_RETURN tls_construct_ctos_renegotiate(SSL_CONNECTION *s, WPACKET *pkt, return EXT_RETURN_SENT; } -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif - /* Add a complete RI extension if renegotiating */ if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_renegotiate) || !WPACKET_start_sub_packet_u16(pkt) @@ -83,31 +63,9 @@ EXT_RETURN tls_construct_ctos_server_name(SSL_CONNECTION *s, WPACKET *pkt, unsigned int context, X509 *x, size_t chainidx) { - char *chosen = s->ext.hostname; -#ifndef OPENSSL_NO_ECH - OSSL_HPKE_SUITE suite; - OSSL_ECHSTORE_ENTRY *ee = NULL; - - if (s->ext.ech.es != NULL) { - if (ossl_ech_pick_matching_cfg(s, &ee, &suite) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_NOT_SENT; - } - /* Don't send outer SNI if external API says so */ - if (s->ext.ech.ch_depth == 0 && s->ext.ech.no_outer == 1) - return EXT_RETURN_NOT_SENT; - if (s->ext.ech.ch_depth == 1) /* inner */ - chosen = s->ext.hostname; - if (s->ext.ech.ch_depth == 0) { /* outer */ - if (s->ext.ech.outer_hostname != NULL) /* prefer API */ - chosen = s->ext.ech.outer_hostname; - else /* use name from ECHConfig */ - chosen = ee->public_name; - } - } -#endif - if (chosen == NULL) + if (s->ext.hostname == NULL) return EXT_RETURN_NOT_SENT; + /* Add TLS extension servername to the Client Hello message */ if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_server_name) /* Sub-packet for server_name extension */ @@ -115,12 +73,14 @@ EXT_RETURN tls_construct_ctos_server_name(SSL_CONNECTION *s, WPACKET *pkt, /* Sub-packet for servername list (always 1 hostname)*/ || !WPACKET_start_sub_packet_u16(pkt) || !WPACKET_put_bytes_u8(pkt, TLSEXT_NAMETYPE_host_name) - || !WPACKET_sub_memcpy_u16(pkt, chosen, strlen(chosen)) + || !WPACKET_sub_memcpy_u16(pkt, s->ext.hostname, + strlen(s->ext.hostname)) || !WPACKET_close(pkt) || !WPACKET_close(pkt)) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); return EXT_RETURN_FAIL; } + return EXT_RETURN_SENT; } @@ -131,9 +91,6 @@ EXT_RETURN tls_construct_ctos_maxfragmentlen(SSL_CONNECTION *s, WPACKET *pkt, { if (s->ext.max_fragment_len_mode == TLSEXT_max_fragment_length_DISABLED) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif /* Add Max Fragment Length extension if client enabled it. */ /*- @@ -160,9 +117,6 @@ EXT_RETURN tls_construct_ctos_srp(SSL_CONNECTION *s, WPACKET *pkt, /* Add SRP username if there is one */ if (s->srp_ctx.login == NULL) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_srp) /* Sub-packet for SRP extension */ @@ -182,82 +136,47 @@ EXT_RETURN tls_construct_ctos_srp(SSL_CONNECTION *s, WPACKET *pkt, } #endif -/* - * With (D)TLS < 1.3 the only negotiated supported key exchange groups are - * FFDHE (RFC7919) and ECDHE/ECX (RFC8422 + legacy). With (D)TLS 1.3, we add - * KEMs, and the supported groups are no longer cipher-dependent. - * - * This function serves two purposes: - * - * - To determine whether to send the supported point formats extension. - * This is no longer applicable with (D)TLS >= 1.3. - * - To determine whether to send the supported groups extension. - * - * In the former case, we only care about whether both ECC ciphers and EC/ECX - * supported groups are configured, and the (D)TLS min version is at most 1.2. - * - * In the latter case, we also admit DHE ciphers with FFDHE groups, or any TLS - * 1.3 cipher, since the extension is effectively mandatory for (D)TLS 1.3, - * with the sole exception of psk-ke resumption, provided the client is sure - * that the server will not want elect a full handshake. The check type then - * indicates whether ECDHE or FFDHE negotiation should be performed. - * - * It returns 1 if negotiation is supported, 0 if it's not and -1 on error. - */ -static int negotiate_dhe(SSL_CONNECTION *s, dhe_check_t check_type, - int min_version, int max_version) +static int use_ecc(SSL_CONNECTION *s, int min_version, int max_version) { int i, end, ret = 0; + unsigned long alg_k, alg_a; STACK_OF(SSL_CIPHER) *cipher_stack = NULL; const uint16_t *pgroups = NULL; size_t num_groups, j; SSL *ssl = SSL_CONNECTION_GET_SSL(s); - int dtls = SSL_CONNECTION_IS_DTLS(s); - /* See if we support any EC or FFDHE ciphersuites */ + /* See if we support any ECC ciphersuites */ + if (s->version == SSL3_VERSION) + return 0; + cipher_stack = SSL_get1_supported_ciphers(ssl); - if (cipher_stack == NULL) - return -1; end = sk_SSL_CIPHER_num(cipher_stack); for (i = 0; i < end; i++) { const SSL_CIPHER *c = sk_SSL_CIPHER_value(cipher_stack, i); - unsigned long alg_k = c->algorithm_mkey; - unsigned long alg_a = c->algorithm_auth; - int is_ffdhe_ciphersuite = (alg_k & (SSL_kDHE | SSL_kDHEPSK)); - int is_ec_ciphersuite = ((alg_k & (SSL_kECDHE | SSL_kECDHEPSK)) - || (alg_a & SSL_aECDSA)); - int is_tls13 = (dtls ? DTLS_VERSION_GT(c->min_dtls, DTLS1_2_VERSION) - : (c->min_tls > TLS1_2_VERSION)); - - if ((check_type == ffdhe_check && (is_ffdhe_ciphersuite || is_tls13)) - || (check_type == ecdhe_check && (is_ec_ciphersuite || is_tls13)) - || (check_type == ptfmt_check && is_ec_ciphersuite)) { + alg_k = c->algorithm_mkey; + alg_a = c->algorithm_auth; + if ((alg_k & (SSL_kECDHE | SSL_kECDHEPSK)) + || (alg_a & SSL_aECDSA) + || c->min_tls >= TLS1_3_VERSION) { ret = 1; break; } } sk_SSL_CIPHER_free(cipher_stack); - if (ret == 0) + if (!ret) return 0; - /* Check we have at least one EC or FFDHE supported group */ + /* Check we have at least one EC supported group */ tls1_get_supported_groups(s, &pgroups, &num_groups); for (j = 0; j < num_groups; j++) { uint16_t ctmp = pgroups[j]; - const TLS_GROUP_INFO *ginfo = NULL; - if (!tls_valid_group(s, ctmp, min_version, max_version, NULL, &ginfo)) - continue; - - if (check_type == ffdhe_check && is_ffdhe_group(ginfo->group_id) - && tls_group_allowed(s, ctmp, SSL_SECOP_CURVE_SUPPORTED)) - return 1; - - if (check_type != ffdhe_check && is_ecdhe_group(ginfo->group_id) + if (tls_valid_group(s, ctmp, min_version, max_version, 1, NULL) && tls_group_allowed(s, ctmp, SSL_SECOP_CURVE_SUPPORTED)) return 1; } + return 0; } @@ -267,29 +186,19 @@ EXT_RETURN tls_construct_ctos_ec_pt_formats(SSL_CONNECTION *s, WPACKET *pkt, { const unsigned char *pformats; size_t num_formats; - int reason, min_version, max_version, dhe_result; + int reason, min_version, max_version; reason = ssl_get_min_max_version(s, &min_version, &max_version, NULL); if (reason != 0) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, reason); return EXT_RETURN_FAIL; } - dhe_result = negotiate_dhe(s, ptfmt_check, min_version, max_version); - if (dhe_result == 0) + if (!use_ecc(s, min_version, max_version)) return EXT_RETURN_NOT_SENT; - if (dhe_result < 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; - } - - tls1_get_formatlist(s, &pformats, &num_formats); - if (num_formats == 0) - return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif /* Add TLS extension ECPointFormats to the ClientHello message */ + tls1_get_formatlist(s, &pformats, &num_formats); + if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_ec_point_formats) /* Sub-packet for formats extension */ || !WPACKET_start_sub_packet_u16(pkt) @@ -309,8 +218,6 @@ EXT_RETURN tls_construct_ctos_supported_groups(SSL_CONNECTION *s, WPACKET *pkt, const uint16_t *pgroups = NULL; size_t num_groups = 0, i, tls13added = 0, added = 0; int min_version, max_version, reason; - int dtls = SSL_CONNECTION_IS_DTLS(s); - int use_ecdhe, use_ffdhe; reason = ssl_get_min_max_version(s, &min_version, &max_version, NULL); if (reason != 0) { @@ -319,21 +226,12 @@ EXT_RETURN tls_construct_ctos_supported_groups(SSL_CONNECTION *s, WPACKET *pkt, } /* - * If we don't support suitable groups, don't send the extension + * We only support EC groups in TLSv1.2 or below, and in DTLS. Therefore + * if we don't have EC support then we don't send this extension. */ - use_ecdhe = negotiate_dhe(s, ecdhe_check, min_version, max_version); - use_ffdhe = negotiate_dhe(s, ffdhe_check, min_version, max_version); - if (use_ecdhe < 0 || use_ffdhe < 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; - } - if (use_ecdhe == 0 && use_ffdhe == 0 - && (dtls ? DTLS_VERSION_LE(max_version, DTLS1_2_VERSION) - : (max_version <= TLS1_2_VERSION))) + if (!use_ecc(s, min_version, max_version) + && (SSL_CONNECTION_IS_DTLS(s) || max_version < TLS1_3_VERSION)) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif /* * Add TLS extension supported_groups to the ClientHello message @@ -348,35 +246,21 @@ EXT_RETURN tls_construct_ctos_supported_groups(SSL_CONNECTION *s, WPACKET *pkt, SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); return EXT_RETURN_FAIL; } - /* RFC 8701: prepend a GREASE group value */ - if ((s->options & SSL_OP_GREASE) && !s->server) { - if (!WPACKET_put_bytes_u16(pkt, - ossl_grease_value(s, OSSL_GREASE_GROUP))) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; - } - } /* Copy group ID if supported */ for (i = 0; i < num_groups; i++) { - const TLS_GROUP_INFO *ginfo = NULL; uint16_t ctmp = pgroups[i]; int okfortls13; - if (!tls_valid_group(s, ctmp, min_version, max_version, &okfortls13, - &ginfo) - || (!use_ecdhe && is_ecdhe_group(ginfo->group_id)) - || (!use_ffdhe && is_ffdhe_group(ginfo->group_id)) - /* Note: SSL_SECOP_CURVE_SUPPORTED covers all key exchange groups */ - || !tls_group_allowed(s, ctmp, SSL_SECOP_CURVE_SUPPORTED)) - continue; - - if (!WPACKET_put_bytes_u16(pkt, ctmp)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; + if (tls_valid_group(s, ctmp, min_version, max_version, 0, &okfortls13) + && tls_group_allowed(s, ctmp, SSL_SECOP_CURVE_SUPPORTED)) { + if (!WPACKET_put_bytes_u16(pkt, ctmp)) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + return EXT_RETURN_FAIL; + } + if (okfortls13 && max_version == TLS1_3_VERSION) + tls13added++; + added++; } - if (okfortls13 && max_version == TLS1_3_VERSION) - tls13added++; - added++; } if (!WPACKET_close(pkt) || !WPACKET_close(pkt)) { if (added == 0) @@ -404,9 +288,6 @@ EXT_RETURN tls_construct_ctos_session_ticket(SSL_CONNECTION *s, WPACKET *pkt, if (!tls_use_ticket(s)) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif if (!s->new_session && s->session != NULL && s->session->ext.tick != NULL @@ -463,29 +344,14 @@ EXT_RETURN tls_construct_ctos_sig_algs(SSL_CONNECTION *s, WPACKET *pkt, return EXT_RETURN_NOT_SENT; } -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif - salglen = tls12_get_psigalgs(s, 1, &salg); if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_signature_algorithms) /* Sub-packet for sig-algs extension */ || !WPACKET_start_sub_packet_u16(pkt) /* Sub-packet for the actual list */ || !WPACKET_start_sub_packet_u16(pkt) - || !tls12_copy_sigalgs(s, pkt, salg, salglen)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; - } - /* RFC 8701: append a GREASE signature algorithm value */ - if ((s->options & SSL_OP_GREASE) && !s->server) { - if (!WPACKET_put_bytes_u16(pkt, - ossl_grease_value(s, OSSL_GREASE_SIGALG))) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; - } - } - if (!WPACKET_close(pkt) + || !tls12_copy_sigalgs(s, pkt, salg, salglen) + || !WPACKET_close(pkt) || !WPACKET_close(pkt)) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); return EXT_RETURN_FAIL; @@ -507,9 +373,6 @@ EXT_RETURN tls_construct_ctos_status_request(SSL_CONNECTION *s, WPACKET *pkt, if (s->ext.status_type != TLSEXT_STATUSTYPE_ocsp) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_status_request) /* Sub-packet for status request extension */ @@ -570,9 +433,6 @@ EXT_RETURN tls_construct_ctos_npn(SSL_CONNECTION *s, WPACKET *pkt, if (SSL_CONNECTION_GET_CTX(s)->ext.npn_select_cb == NULL || !SSL_IS_FIRST_HANDSHAKE(s)) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif /* * The client advertises an empty extension to indicate its support @@ -592,46 +452,22 @@ EXT_RETURN tls_construct_ctos_alpn(SSL_CONNECTION *s, WPACKET *pkt, unsigned int context, X509 *x, size_t chainidx) { - unsigned char *aval = s->ext.alpn; - size_t alen = s->ext.alpn_len; - s->s3.alpn_sent = 0; - if (!SSL_IS_FIRST_HANDSHAKE(s)) - return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - /* - * If we have different alpn and alpn_outer values, then we set - * the appropriate one for inner and outer. - * If no alpn is set (for inner or outer), we don't send any. - * If only an inner is set then we send the same in both. - * Logic above is on the basis that alpn's aren't that sensitive, - * usually, so special action is needed to do better. - * We also don't support a way to send alpn only in the inner. - * If you don't want the inner value in the outer, you have to - * pick what to send in the outer and send that. - */ - if (s->ext.ech.ch_depth == 1 && s->ext.alpn == NULL) /* inner */ - return EXT_RETURN_NOT_SENT; - if (s->ext.ech.ch_depth == 0 && s->ext.alpn == NULL - && s->ext.ech.alpn_outer == NULL) /* outer */ - return EXT_RETURN_NOT_SENT; - if (s->ext.ech.ch_depth == 0 && s->ext.ech.alpn_outer != NULL) { - aval = s->ext.ech.alpn_outer; - alen = s->ext.ech.alpn_outer_len; - } -#endif - if (aval == NULL) + + if (s->ext.alpn == NULL || !SSL_IS_FIRST_HANDSHAKE(s)) return EXT_RETURN_NOT_SENT; + if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_application_layer_protocol_negotiation) /* Sub-packet ALPN extension */ || !WPACKET_start_sub_packet_u16(pkt) - || !WPACKET_sub_memcpy_u16(pkt, aval, alen) + || !WPACKET_sub_memcpy_u16(pkt, s->ext.alpn, s->ext.alpn_len) || !WPACKET_close(pkt)) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); return EXT_RETURN_FAIL; } s->s3.alpn_sent = 1; + return EXT_RETURN_SENT; } @@ -646,9 +482,6 @@ EXT_RETURN tls_construct_ctos_use_srtp(SSL_CONNECTION *s, WPACKET *pkt, if (clnt == NULL) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_use_srtp) /* Sub-packet for SRTP extension */ @@ -686,9 +519,6 @@ EXT_RETURN tls_construct_ctos_etm(SSL_CONNECTION *s, WPACKET *pkt, { if (s->options & SSL_OP_NO_ENCRYPT_THEN_MAC) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_encrypt_then_mac) || !WPACKET_put_bytes_u16(pkt, 0)) { @@ -710,9 +540,6 @@ EXT_RETURN tls_construct_ctos_sct(SSL_CONNECTION *s, WPACKET *pkt, /* Not defined for client Certificates */ if (x != NULL) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_signed_certificate_timestamp) || !WPACKET_put_bytes_u16(pkt, 0)) { @@ -730,9 +557,6 @@ EXT_RETURN tls_construct_ctos_ems(SSL_CONNECTION *s, WPACKET *pkt, { if (s->options & SSL_OP_NO_EXTENDED_MASTER_SECRET) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_extended_master_secret) || !WPACKET_put_bytes_u16(pkt, 0)) { @@ -761,9 +585,6 @@ EXT_RETURN tls_construct_ctos_supported_versions(SSL_CONNECTION *s, WPACKET *pkt */ if (max_version < TLS1_3_VERSION) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_supported_versions) || !WPACKET_start_sub_packet_u16(pkt) @@ -772,14 +593,6 @@ EXT_RETURN tls_construct_ctos_supported_versions(SSL_CONNECTION *s, WPACKET *pkt return EXT_RETURN_FAIL; } - /* RFC 8701: prepend a GREASE version value */ - if ((s->options & SSL_OP_GREASE) && !s->server) { - if (!WPACKET_put_bytes_u16(pkt, - ossl_grease_value(s, OSSL_GREASE_VERSION))) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; - } - } for (currv = max_version; currv >= min_version; currv--) { if (!WPACKET_put_bytes_u16(pkt, currv)) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); @@ -804,10 +617,6 @@ EXT_RETURN tls_construct_ctos_psk_kex_modes(SSL_CONNECTION *s, WPACKET *pkt, #ifndef OPENSSL_NO_TLS1_3 int nodhe = s->options & SSL_OP_ALLOW_NO_DHE_KEX; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif - if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_psk_kex_modes) || !WPACKET_start_sub_packet_u16(pkt) || !WPACKET_start_sub_packet_u8(pkt) @@ -879,6 +688,7 @@ static int add_key_share(SSL_CONNECTION *s, WPACKET *pkt, unsigned int group_id, s->s3.tmp.num_ks_pkey++; OPENSSL_free(encoded_pubkey); + return 1; err: if (key_share_key != s->s3.tmp.ks_pkey[loop_num]) @@ -899,10 +709,6 @@ EXT_RETURN tls_construct_ctos_key_share(SSL_CONNECTION *s, WPACKET *pkt, int add_only_one = 0; size_t valid_keyshare = 0; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif - /* key_share extension */ if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_key_share) /* Extension data sub-packet */ @@ -913,19 +719,6 @@ EXT_RETURN tls_construct_ctos_key_share(SSL_CONNECTION *s, WPACKET *pkt, return EXT_RETURN_FAIL; } - /* RFC 8701: prepend a GREASE key share entry (1 byte of 0x00) */ - if ((s->options & SSL_OP_GREASE) && !s->server) { - uint16_t grease_group = ossl_grease_value(s, OSSL_GREASE_GROUP); - - if (!WPACKET_put_bytes_u16(pkt, grease_group) - || !WPACKET_start_sub_packet_u16(pkt) - || !WPACKET_put_bytes_u8(pkt, 0) - || !WPACKET_close(pkt)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; - } - } - tls1_get_requested_keyshare_groups(s, &pgroups, &num_groups); if (num_groups == 1 && pgroups[0] == 0) { /* Indication that no * prefix was used */ tls1_get_supported_groups(s, &pgroups, &num_groups); @@ -957,7 +750,7 @@ EXT_RETURN tls_construct_ctos_key_share(SSL_CONNECTION *s, WPACKET *pkt, if (!tls_group_allowed(s, pgroups[i], SSL_SECOP_CURVE_SUPPORTED)) continue; if (!tls_valid_group(s, pgroups[i], TLS1_3_VERSION, TLS1_3_VERSION, - NULL, NULL)) + 0, NULL)) continue; group_id = pgroups[i]; @@ -982,14 +775,6 @@ EXT_RETURN tls_construct_ctos_key_share(SSL_CONNECTION *s, WPACKET *pkt, return EXT_RETURN_FAIL; } -#ifndef OPENSSL_NO_ECH - /* stash inner key shares */ - if (s->ext.ech.ch_depth == 1 && ossl_ech_stash_keyshares(s) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; - } -#endif - if (!WPACKET_close(pkt) || !WPACKET_close(pkt)) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); return EXT_RETURN_FAIL; @@ -1009,9 +794,6 @@ EXT_RETURN tls_construct_ctos_cookie(SSL_CONNECTION *s, WPACKET *pkt, /* Should only be set if we've had an HRR */ if (s->ext.tls13_cookie_len == 0) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_cookie) /* Extension data sub-packet */ @@ -1046,33 +828,6 @@ EXT_RETURN tls_construct_ctos_early_data(SSL_CONNECTION *s, WPACKET *pkt, const EVP_MD *handmd = NULL; SSL *ussl = SSL_CONNECTION_GET_USER_SSL(s); -#ifndef OPENSSL_NO_ECH - /* - * If we're attempting ECH and processing the outer CH - * then we only need to check if the extension is to be - * sent or not - any other processing (with side effects) - * happened already for the inner CH. - */ - if (s->ext.ech.es != NULL && s->ext.ech.ch_depth == 0) { - /* - * if we called this for inner and did send then - * the following two things should be set, if so, - * then send again in the outer CH. - */ - if (s->ext.early_data == SSL_EARLY_DATA_REJECTED - && s->ext.early_data_ok == 1) { - if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_early_data) - || !WPACKET_start_sub_packet_u16(pkt) - || !WPACKET_close(pkt)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; - } - return EXT_RETURN_SENT; - } else { - return EXT_RETURN_NOT_SENT; - } - } -#endif if (s->hello_retry_request == SSL_HRR_PENDING) handmd = ssl_handshake_md(s); @@ -1240,9 +995,6 @@ EXT_RETURN tls_construct_ctos_padding(SSL_CONNECTION *s, WPACKET *pkt, if ((s->options & SSL_OP_TLSEXT_PADDING) == 0) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt); -#endif /* * Add padding to workaround bugs in F5 terminators. See RFC7685. @@ -1364,19 +1116,6 @@ EXT_RETURN tls_construct_ctos_psk(SSL_CONNECTION *s, WPACKET *pkt, goto dopsksess; } -#ifndef OPENSSL_NO_ECH - /* - * When doing ECH, we get here twice (for inner then outer). The - * 2nd time (for outer) we can skip some checks as we know how - * those went last time. - */ - if (s->ext.ech.es != NULL && s->ext.ech.ch_depth == 0) { - s->ext.tick_identity = s->ext.ech.tick_identity; - dores = (s->ext.tick_identity > 0); - goto dopsksess; - } -#endif - /* * Technically the C standard just says time() returns a time_t and says * nothing about the encoding of that type. In practice most @@ -1387,7 +1126,6 @@ EXT_RETURN tls_construct_ctos_psk(SSL_CONNECTION *s, WPACKET *pkt, */ t = ossl_time_subtract(ossl_time_now(), s->session->time); agesec = (uint32_t)ossl_time2seconds(t); - /* * We calculate the age in seconds but the server may work in ms. Due to * rounding errors we could overestimate the age by up to 1s. It is @@ -1428,11 +1166,6 @@ EXT_RETURN tls_construct_ctos_psk(SSL_CONNECTION *s, WPACKET *pkt, if (reshashsize <= 0) goto dopsksess; s->ext.tick_identity++; -#ifndef OPENSSL_NO_ECH - /* stash this for re-use in outer CH */ - if (s->ext.ech.es != NULL && s->ext.ech.ch_depth == 1) - s->ext.ech.tick_identity = s->ext.tick_identity; -#endif dores = 1; } @@ -1475,72 +1208,6 @@ dopsksess: return EXT_RETURN_FAIL; } -#ifndef OPENSSL_NO_ECH - /* - * For ECH if we're processing the outer CH and the inner CH - * has a PSK, then we want to send a GREASE PSK in the outer. - * We'll do that by just replacing the ticket value itself - * with random values of the same length. - */ - if (s->ext.ech.es != NULL && s->ext.ech.ch_depth == 0) { - unsigned char *rndbuf = NULL, *rndbufp = NULL; - size_t totalrndsize = 0; - - totalrndsize = s->session->ext.ticklen - + sizeof(agems) - + s->psksession_id_len - + reshashsize - + pskhashsize; - rndbuf = OPENSSL_malloc(totalrndsize); - if (rndbuf == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; - } - /* for outer CH allocate a similar sized random value */ - if (RAND_bytes_ex(sctx->libctx, rndbuf, totalrndsize, 0) <= 0) { - OPENSSL_free(rndbuf); - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; - } - /* set agems from random buffer */ - rndbufp = rndbuf; - memcpy(&agems, rndbufp, sizeof(agems)); - rndbufp += sizeof(agems); - if (dores != 0) { - if (!WPACKET_sub_memcpy_u16(pkt, rndbufp, - s->session->ext.ticklen) - || !WPACKET_put_bytes_u32(pkt, agems)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - OPENSSL_free(rndbuf); - return EXT_RETURN_FAIL; - } - rndbufp += s->session->ext.ticklen; - } - if (s->psksession != NULL) { - if (!WPACKET_sub_memcpy_u16(pkt, rndbufp, s->psksession_id_len) - || !WPACKET_put_bytes_u32(pkt, 0)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - OPENSSL_free(rndbuf); - return EXT_RETURN_FAIL; - } - rndbufp += s->psksession_id_len; - } - if (!WPACKET_close(pkt) - || !WPACKET_start_sub_packet_u16(pkt) - || (dores == 1 - && !WPACKET_sub_memcpy_u8(pkt, rndbufp, reshashsize)) - || (s->psksession != NULL - && !WPACKET_sub_memcpy_u8(pkt, rndbufp, pskhashsize)) - || !WPACKET_close(pkt) - || !WPACKET_close(pkt)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - OPENSSL_free(rndbuf); - return EXT_RETURN_FAIL; - } - OPENSSL_free(rndbuf); - return EXT_RETURN_SENT; - } -#endif /* OPENSSL_NO_ECH */ if (dores) { if (!WPACKET_sub_memcpy_u16(pkt, s->session->ext.tick, s->session->ext.ticklen) @@ -1611,9 +1278,6 @@ EXT_RETURN tls_construct_ctos_post_handshake_auth(SSL_CONNECTION *s, WPACKET *pk #ifndef OPENSSL_NO_TLS1_3 if (!s->pha_enabled) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(s, context, pkt) -#endif /* construct extension - 0 length, no contents */ if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_post_handshake_auth) @@ -1705,7 +1369,7 @@ int tls_parse_stoc_maxfragmentlen(SSL_CONNECTION *s, PACKET *pkt, /* |value| should contains a valid max-fragment-length code. */ if (!IS_MAX_FRAGMENT_LENGTH_EXT_VALID(value)) { SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, - SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH); + SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH); return 0; } @@ -1717,7 +1381,7 @@ int tls_parse_stoc_maxfragmentlen(SSL_CONNECTION *s, PACKET *pkt, */ if (value != s->ext.max_fragment_len_mode) { SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, - SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH); + SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH); return 0; } @@ -1734,32 +1398,68 @@ int tls_parse_stoc_server_name(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, X509 *x, size_t chainidx) { - char *eff_sni = s->ext.hostname; - -#ifndef OPENSSL_NO_ECH - /* if we tried ECH and failed, the outer is what's expected */ - if (s->ext.ech.es != NULL && s->ext.ech.success == 0) - eff_sni = s->ext.ech.outer_hostname; -#endif - if (eff_sni == NULL) { + if (s->ext.hostname == NULL) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); return 0; } + if (PACKET_remaining(pkt) > 0) { SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); return 0; } + if (!s->hit) { if (s->session->ext.hostname != NULL) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); return 0; } - s->session->ext.hostname = OPENSSL_strdup(eff_sni); + s->session->ext.hostname = OPENSSL_strdup(s->ext.hostname); if (s->session->ext.hostname == NULL) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); return 0; } } + + return 1; +} + +int tls_parse_stoc_ec_pt_formats(SSL_CONNECTION *s, PACKET *pkt, + unsigned int context, + X509 *x, size_t chainidx) +{ + size_t ecpointformats_len; + PACKET ecptformatlist; + + if (!PACKET_as_length_prefixed_1(pkt, &ecptformatlist)) { + SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); + return 0; + } + if (!s->hit) { + ecpointformats_len = PACKET_remaining(&ecptformatlist); + if (ecpointformats_len == 0) { + SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_LENGTH); + return 0; + } + + s->ext.peer_ecpointformats_len = 0; + OPENSSL_free(s->ext.peer_ecpointformats); + s->ext.peer_ecpointformats = OPENSSL_malloc(ecpointformats_len); + if (s->ext.peer_ecpointformats == NULL) { + s->ext.peer_ecpointformats_len = 0; + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + return 0; + } + + s->ext.peer_ecpointformats_len = ecpointformats_len; + + if (!PACKET_copy_bytes(&ecptformatlist, + s->ext.peer_ecpointformats, + ecpointformats_len)) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + return 0; + } + } + return 1; } @@ -2187,12 +1887,6 @@ int tls_parse_stoc_key_share(SSL_CONNECTION *s, PACKET *pkt, return 0; } - /* RFC 8701: reject GREASE values selected by the server */ - if (ossl_is_grease_value(group_id)) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_KEY_SHARE); - return 0; - } - if ((context & SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST) != 0) { const uint16_t *pgroups = NULL; size_t num_groups; @@ -2222,7 +1916,7 @@ int tls_parse_stoc_key_share(SSL_CONNECTION *s, PACKET *pkt, if (i >= num_groups || !tls_group_allowed(s, group_id, SSL_SECOP_CURVE_SUPPORTED) || !tls_valid_group(s, group_id, TLS1_3_VERSION, TLS1_3_VERSION, - NULL, NULL)) { + 0, NULL)) { SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_KEY_SHARE); return 0; } @@ -2345,7 +2039,6 @@ int tls_parse_stoc_cookie(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, PACKET cookie; if (!PACKET_as_length_prefixed_2(pkt, &cookie) - || PACKET_remaining(&cookie) == 0 || !PACKET_memdup(&cookie, &s->ext.tls13_cookie, &s->ext.tls13_cookie_len)) { SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_MISMATCH); @@ -2415,7 +2108,6 @@ int tls_parse_stoc_psk(SSL_CONNECTION *s, PACKET *pkt, size_t chainidx) { #ifndef OPENSSL_NO_TLS1_3 - SSL_SESSION *sesstmp; unsigned int identity; if (!PACKET_get_net_2(pkt, &identity) || PACKET_remaining(pkt) != 0) { @@ -2457,25 +2149,6 @@ int tls_parse_stoc_psk(SSL_CONNECTION *s, PACKET *pkt, || s->psksession->ext.max_early_data == 0) memcpy(s->early_secret, s->psksession->early_secret, EVP_MAX_MD_SIZE); - /* - * The psk_use_session_cb()/psk_client_callback() may reuse - * the session across connections we can't mutate it directly. - */ - if ((sesstmp = ssl_session_dup(s->psksession, 0)) == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - SSL_SESSION_free(s->psksession); - s->psksession = sesstmp; - - /* - * s->psksession (now our private copy) was built by the callback, not via - * ssl_get_new_session(), so it was never stamped with our own sid_ctx. Do - * so now, to avoid rejection of the PSK session in tls_process_server_hello(). - */ - memcpy(s->psksession->sid_ctx, s->sid_ctx, s->sid_ctx_length); - s->psksession->sid_ctx_length = s->sid_ctx_length; - SSL_SESSION_free(s->session); s->session = s->psksession; s->psksession = NULL; @@ -2495,9 +2168,6 @@ EXT_RETURN tls_construct_ctos_client_cert_type(SSL_CONNECTION *sc, WPACKET *pkt, sc->ext.client_cert_type_ctos = OSSL_CERT_TYPE_CTOS_NONE; if (sc->client_cert_type == NULL) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(sc, context, pkt) -#endif if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_client_cert_type) || !WPACKET_start_sub_packet_u16(pkt) @@ -2550,9 +2220,6 @@ EXT_RETURN tls_construct_ctos_server_cert_type(SSL_CONNECTION *sc, WPACKET *pkt, sc->ext.server_cert_type_ctos = OSSL_CERT_TYPE_CTOS_NONE; if (sc->server_cert_type == NULL) return EXT_RETURN_NOT_SENT; -#ifndef OPENSSL_NO_ECH - ECH_SAME_EXT(sc, context, pkt) -#endif if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_server_cert_type) || !WPACKET_start_sub_packet_u16(pkt) @@ -2597,316 +2264,3 @@ int tls_parse_stoc_server_cert_type(SSL_CONNECTION *sc, PACKET *pkt, sc->ext.server_cert_type = type; return 1; } - -#ifndef OPENSSL_NO_ECH -EXT_RETURN tls_construct_ctos_ech(SSL_CONNECTION *s, WPACKET *pkt, - unsigned int context, X509 *x, - size_t chainidx) -{ - int rv = 0, hpke_mode = OSSL_HPKE_MODE_BASE; - SSL_CTX *sctx = SSL_CONNECTION_GET_CTX(s); - OSSL_ECHSTORE_ENTRY *ee = NULL; - OSSL_HPKE_SUITE hpke_suite = OSSL_HPKE_SUITE_DEFAULT; - unsigned char config_id_to_use = 0x00, info[OSSL_ECH_MAX_INFO_LEN]; - unsigned char *encoded = NULL, *mypub = NULL; - size_t cipherlen = 0, aad_len = 0, lenclen = 0, mypub_len = 0; - size_t info_len = OSSL_ECH_MAX_INFO_LEN, clear_len = 0, encoded_len = 0; - /* whether or not we've been asked to GREASE, one way or another */ - int grease_opt_set = (s->ext.ech.attempted != 1 - && ((s->ext.ech.grease == OSSL_ECH_IS_GREASE) - || ((s->options & SSL_OP_ECH_GREASE) != 0))); - - /* if we're not doing real ECH and not GREASEing then exit */ - if (s->ext.ech.attempted_type != TLSEXT_TYPE_ech && grease_opt_set == 0) - return EXT_RETURN_NOT_SENT; - /* send grease if not really attempting ECH */ - if (grease_opt_set == 1) { - if (s->hello_retry_request == SSL_HRR_PENDING - && s->ext.ech.sent != NULL) { - /* re-tx already sent GREASEy ECH */ - if (WPACKET_memcpy(pkt, s->ext.ech.sent, - s->ext.ech.sent_len) - != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; - } - return EXT_RETURN_SENT; - } - /* if nobody set a type, use the default */ - if (s->ext.ech.attempted_type == OSSL_ECH_type_unknown) - s->ext.ech.attempted_type = TLSEXT_TYPE_ech; - if (ossl_ech_send_grease(s, pkt) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_NOT_SENT; - } - return EXT_RETURN_SENT; - } - - /* For the inner CH - we simply include one of these saying "inner" */ - if (s->ext.ech.ch_depth == 1) { - if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_ech) - || !WPACKET_start_sub_packet_u16(pkt) - || !WPACKET_put_bytes_u8(pkt, OSSL_ECH_INNER_CH_TYPE) - || !WPACKET_close(pkt)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; - } - return EXT_RETURN_SENT; - } - - /* - * If not GREASEing we prepare sending the outer value - after the - * entire thing has been constructed, putting in zeros for now where - * we'd otherwise include ECH ciphertext, we later encode and encrypt. - * We need to do it that way as we need the rest of the outer CH to - * be known and used as AAD input before we do encryption. - */ - if (s->ext.ech.ch_depth != 0) - return EXT_RETURN_NOT_SENT; - /* Make ClientHelloInner and EncodedClientHelloInner as per spec. */ - if (ossl_ech_encode_inner(s, &encoded, &encoded_len) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - s->ext.ech.encoded_inner = encoded; - s->ext.ech.encoded_inner_len = encoded_len; -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("encoded inner CH", encoded, encoded_len); -#endif - rv = ossl_ech_pick_matching_cfg(s, &ee, &hpke_suite); - if (rv != 1 || ee == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - s->ext.ech.attempted_type = ee->version; - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "EAAE: selected: version: %4x, config %2x\n", - ee->version, ee->config_id); - } - OSSL_TRACE_END(TLS); - config_id_to_use = ee->config_id; /* if requested, use a random config_id instead */ - if ((s->options & SSL_OP_ECH_IGNORE_CID) != 0) { - int max_iters = 1000, i = 0; - - /* rejection sample to get a different but random config_id */ - while (config_id_to_use == ee->config_id) { -#ifdef OSSL_ECH_SUPERVERBOSE - if (i > 0) { - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "EAAE: rejected random-config %02x\n", - config_id_to_use); - } - OSSL_TRACE_END(TLS); - } -#endif - if (RAND_bytes_ex(sctx->libctx, &config_id_to_use, 1, 0) <= 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - if (i++ >= max_iters) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - } -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("EAAE: random config_id", &config_id_to_use, 1); -#endif - } - s->ext.ech.attempted_cid = config_id_to_use; -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("EAAE: peer pub", ee->pub, ee->pub_len); - ossl_ech_pbuf("EAAE: clear", encoded, encoded_len); - ossl_ech_pbuf("EAAE: ECHConfig", ee->encoded, ee->encoded_len); -#endif - /* - * The AAD is the full outer client hello but with the correct number of - * zeros for where the ECH ciphertext octets will later be placed. So we - * add the ECH extension to the |pkt| but with zeros for ciphertext, that - * forms up the AAD, then after we've encrypted, we'll splice in the actual - * ciphertext. - * Watch out for the "4" offsets that remove the type and 3-octet length - * from the encoded CH as per the spec. - */ - clear_len = ossl_ech_calc_padding(s, ee, encoded_len); - if (clear_len == 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - lenclen = OSSL_HPKE_get_public_encap_size(hpke_suite); - if (s->ext.ech.hpke_ctx == NULL) { /* 1st CH */ - if (ossl_ech_make_enc_info(ee->encoded, ee->encoded_len, - info, &info_len) - != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("EAAE info", info, info_len); -#endif - s->ext.ech.hpke_ctx = OSSL_HPKE_CTX_new(hpke_mode, hpke_suite, - OSSL_HPKE_ROLE_SENDER, - sctx->libctx, sctx->propq); - if (s->ext.ech.hpke_ctx == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - mypub = OPENSSL_malloc(lenclen); - if (mypub == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - mypub_len = lenclen; - rv = OSSL_HPKE_encap(s->ext.ech.hpke_ctx, mypub, &mypub_len, - ee->pub, ee->pub_len, info, info_len); - if (rv != 1) { - OPENSSL_free(mypub); - mypub = NULL; - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - s->ext.ech.pub = mypub; - s->ext.ech.pub_len = mypub_len; - } else { /* HRR - retrieve public */ - mypub = s->ext.ech.pub; - mypub_len = s->ext.ech.pub_len; - if (mypub == NULL || mypub_len == 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - } -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("EAAE: mypub", mypub, mypub_len); - WPACKET_get_total_written(pkt, &aad_len); /* use aad_len for tracing */ - ossl_ech_pbuf("EAAE pkt b4", WPACKET_get_curr(pkt) - aad_len, aad_len); -#endif - cipherlen = OSSL_HPKE_get_ciphertext_size(hpke_suite, clear_len); - if (cipherlen <= clear_len || cipherlen > OSSL_ECH_MAX_PAYLOAD_LEN) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - s->ext.ech.clearlen = clear_len; - s->ext.ech.cipherlen = cipherlen; - if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_ech) - || !WPACKET_start_sub_packet_u16(pkt) - || !WPACKET_put_bytes_u8(pkt, OSSL_ECH_OUTER_CH_TYPE) - || !WPACKET_put_bytes_u16(pkt, hpke_suite.kdf_id) - || !WPACKET_put_bytes_u16(pkt, hpke_suite.aead_id) - || !WPACKET_put_bytes_u8(pkt, config_id_to_use) - || (s->hello_retry_request == SSL_HRR_PENDING - && !WPACKET_put_bytes_u16(pkt, 0x00)) /* no pub */ - || (s->hello_retry_request != SSL_HRR_PENDING - && !WPACKET_sub_memcpy_u16(pkt, mypub, mypub_len)) - || !WPACKET_start_sub_packet_u16(pkt) - || !WPACKET_get_total_written(pkt, &s->ext.ech.cipher_offset) - || !WPACKET_memset(pkt, 0, cipherlen) - || !WPACKET_close(pkt) - || !WPACKET_close(pkt)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - /* don't count the type + 3-octet length */ - s->ext.ech.cipher_offset -= 4; - return EXT_RETURN_SENT; -err: - return EXT_RETURN_FAIL; -} - -/* if the server thinks we GREASE'd then we may get an ECHConfigList */ -int tls_parse_stoc_ech(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, - X509 *x, size_t chainidx) -{ - size_t rlen = 0; - const unsigned char *rval = NULL; - unsigned char *srval = NULL; - PACKET rcfgs_pkt; - - /* - * An HRR will have an ECH extension with the 8-octet confirmation value. - * Store it away for when we check it later - */ - if (context == SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST) { - if (PACKET_remaining(pkt) != OSSL_ECH_SIGNAL_LEN) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_MISMATCH); - return 0; - } - s->ext.ech.hrrsignal_p = (unsigned char *)PACKET_data(pkt); - memcpy(s->ext.ech.hrrsignal, s->ext.ech.hrrsignal_p, - OSSL_ECH_SIGNAL_LEN); - return 1; - } - /* otherwise we expect retry-configs */ - if (!PACKET_get_length_prefixed_2(pkt, &rcfgs_pkt)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_MISMATCH); - return 0; - } - rval = PACKET_data(&rcfgs_pkt); - rlen = (unsigned int)PACKET_remaining(&rcfgs_pkt); - OPENSSL_free(s->ext.ech.returned); - s->ext.ech.returned = NULL; - srval = OPENSSL_malloc(rlen + 2); - if (srval == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - srval[0] = (rlen >> 8) & 0xff; - srval[1] = rlen & 0xff; - memcpy(srval + 2, rval, rlen); - s->ext.ech.returned = srval; - s->ext.ech.returned_len = rlen + 2; - return 1; -} -#endif /* END_OPENSSL_NO_ECH */ - -/* - * RFC 8701 GREASE extension constructors. Each writes an empty extension - * whose type is a GREASE value (0x?A?A pattern). - */ -EXT_RETURN tls_construct_ctos_grease1(SSL_CONNECTION *s, WPACKET *pkt, - unsigned int context, X509 *x, - size_t chainidx) -{ - uint16_t grease_type; - - if (!(s->options & SSL_OP_GREASE) || s->server) - return EXT_RETURN_NOT_SENT; - - grease_type = ossl_grease_value(s, OSSL_GREASE_EXT1); - - if (!WPACKET_put_bytes_u16(pkt, grease_type) - || !WPACKET_put_bytes_u16(pkt, 0)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; - } - - return EXT_RETURN_SENT; -} - -EXT_RETURN tls_construct_ctos_grease2(SSL_CONNECTION *s, WPACKET *pkt, - unsigned int context, X509 *x, - size_t chainidx) -{ - uint16_t grease_type; - - if (!(s->options & SSL_OP_GREASE) || s->server) - return EXT_RETURN_NOT_SENT; - - grease_type = ossl_grease_value(s, OSSL_GREASE_EXT2); - - /* - * RFC 8701 recommends "varying length and contents" for GREASE - * extensions. Extension 1 is empty; extension 2 carries one zero byte - * so that servers are tested against both empty and non-empty unknown - * extensions. This mirrors the BoringSSL behaviour. - */ - if (!WPACKET_put_bytes_u16(pkt, grease_type) - || !WPACKET_start_sub_packet_u16(pkt) - || !WPACKET_put_bytes_u8(pkt, 0) - || !WPACKET_close(pkt)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return EXT_RETURN_FAIL; - } - - return EXT_RETURN_SENT; -} diff --git a/ssl/statem/extensions_cust.c b/ssl/statem/extensions_cust.c index 71fb169c31..ce1c69bbdc 100644 --- a/ssl/statem/extensions_cust.c +++ b/ssl/statem/extensions_cust.c @@ -1,5 +1,5 @@ /* - * Copyright 2014-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2014-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -193,74 +193,6 @@ int custom_ext_add(SSL_CONNECTION *s, int context, WPACKET *pkt, X509 *x, if (!(meth->ext_flags & SSL_EXT_FLAG_RECEIVED)) continue; } - -#ifndef OPENSSL_NO_ECH - if ((context & SSL_EXT_CLIENT_HELLO) != 0 - && s->ext.ech.attempted == 1) { - if (s->ext.ech.ch_depth == 1) { - /* mark custom CH ext for ECH compression, if doing ECH */ - if (s->ext.ech.n_outer_only >= OSSL_ECH_OUTERS_MAX) { - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, - "Too many outers to compress (max=%d)\n", - OSSL_ECH_OUTERS_MAX); - } - OSSL_TRACE_END(TLS); - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_BAD_EXTENSION); - return 0; - } - s->ext.ech.outer_only[s->ext.ech.n_outer_only] = meth->ext_type; - s->ext.ech.n_outer_only++; - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "ECH compressing type " - "0x%04x (tot: %d)\n", - (int)meth->ext_type, - (int)s->ext.ech.n_outer_only); - } - OSSL_TRACE_END(TLS); - } - if (s->ext.ech.ch_depth == 0) { - /* - * We store/access the index of the extension handler in - * s->ext.ech.ext_ind, as we'd otherwise not know it here. - * Be nice were there a better way to handle that. - */ - /* copy over the extension octets (if any) to outer */ - int j, tind = -1; - RAW_EXTENSION *raws = NULL; - - /* we gotta find the relevant index to copy over this ext */ - if (s->clienthello == NULL - || s->clienthello->pre_proc_exts == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_BAD_EXTENSION); - return 0; - } - raws = s->clienthello->pre_proc_exts; - for (j = 0; j != (int)s->clienthello->pre_proc_exts_len; j++) { - if (raws[j].type == meth->ext_type) { - tind = j; - break; - } - } - if (tind == -1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_BAD_EXTENSION); - return 0; - } - if (ossl_ech_copy_inner2outer(s, meth->ext_type, tind, - pkt) - != OSSL_ECH_SAME_EXT_DONE) { - /* for custom exts, we really should have found it */ - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_BAD_EXTENSION); - return 0; - } - /* we're done with that one now */ - continue; - } - } -#endif - /* * We skip it if the callback is absent - except for a ClientHello where * we add an empty extension. @@ -411,6 +343,9 @@ int custom_exts_copy_conn(custom_ext_methods *dst, if (methdst == NULL) return 0; + for (i = 0; i < dst->meths_count; i++) + custom_ext_copy_old_cb(&methdst[i], &dst->meths[i], &err); + dst->meths = methdst; methdst += dst->meths_count; @@ -656,10 +591,6 @@ int SSL_extension_supported(unsigned int ext_type) case TLSEXT_TYPE_compress_certificate: case TLSEXT_TYPE_client_cert_type: case TLSEXT_TYPE_server_cert_type: -#ifndef OPENSSL_NO_ECH - case TLSEXT_TYPE_ech: - case TLSEXT_TYPE_outer_extensions: -#endif return 1; default: return 0; diff --git a/ssl/statem/extensions_srvr.c b/ssl/statem/extensions_srvr.c index a597085e1b..c4aef4c939 100644 --- a/ssl/statem/extensions_srvr.c +++ b/ssl/statem/extensions_srvr.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -12,17 +12,9 @@ #include "statem_local.h" #include "internal/cryptlib.h" #include "internal/ssl_unwrap.h" -#ifndef OPENSSL_NO_ECH -#include -#include -#endif #define COOKIE_STATE_FORMAT_VERSION 1 -#define MAX_SUPPORTED_GROUPS 128 -#define MAX_KEY_SHARES 16 -#define MAX_PRE_SHARED_KEYS 16 - /* * 2 bytes for packet length, 2 bytes for format version, 2 bytes for * protocol version, 2 bytes for group id, 2 bytes for cipher id, 1 byte for @@ -196,7 +188,7 @@ int tls_parse_ctos_maxfragmentlen(SSL_CONNECTION *s, PACKET *pkt, /* Received |value| should be a valid max-fragment-length code. */ if (!IS_MAX_FRAGMENT_LENGTH_EXT_VALID(value)) { SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, - SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH); + SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH); return 0; } @@ -245,6 +237,30 @@ int tls_parse_ctos_srp(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, } #endif +int tls_parse_ctos_ec_pt_formats(SSL_CONNECTION *s, PACKET *pkt, + unsigned int context, + X509 *x, size_t chainidx) +{ + PACKET ec_point_format_list; + + if (!PACKET_as_length_prefixed_1(pkt, &ec_point_format_list) + || PACKET_remaining(&ec_point_format_list) == 0) { + SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); + return 0; + } + + if (!s->hit) { + if (!PACKET_memdup(&ec_point_format_list, + &s->ext.peer_ecpointformats, + &s->ext.peer_ecpointformats_len)) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + return 0; + } + } + + return 1; +} + int tls_parse_ctos_session_ticket(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, X509 *x, size_t chainidx) @@ -324,15 +340,6 @@ int tls_parse_ctos_status_request(SSL_CONNECTION *s, PACKET *pkt, if (x != NULL) return 1; - /* - * We only care about this extension if the application - * registered a callback. Otherwise, there is nothing to - * tell us that a response is needed. - */ - SSL_CTX *sctx = SSL_CONNECTION_GET_CTX(s); - if (sctx == NULL || sctx->ext.status_cb == NULL) - return 1; - if (!PACKET_get_1(pkt, (unsigned int *)&s->ext.status_type)) { SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); return 0; @@ -645,42 +652,28 @@ static KS_EXTRACTION_RESULT extract_keyshares(SSL_CONNECTION *s, PACKET *key_sha const uint16_t *clntgroups, size_t clnt_num_groups, const uint16_t *srvrgroups, size_t srvr_num_groups, uint16_t **keyshares_arr, PACKET **encoded_pubkey_arr, - size_t *keyshares_cnt) + size_t *keyshares_cnt, size_t *keyshares_max) { PACKET encoded_pubkey; size_t key_share_pos = 0; size_t previous_key_share_pos = 0; unsigned int group_id = 0; - unsigned int i; - - /* - * Theoretically there is no limit on the number of keyshares as long as - * they are less than 2^16 bytes in total. It costs us something for each - * keyshare to confirm the groups are valid, so we restrict this to a - * sensible number (MAX_KEY_SHARES == 16). Any keyshares over this limit are - * simply ignored. - */ /* Prepare memory to hold the extracted key share groups and related pubkeys */ - *keyshares_arr = OPENSSL_malloc_array(MAX_KEY_SHARES, + *keyshares_arr = OPENSSL_malloc_array(*keyshares_max, sizeof(**keyshares_arr)); if (*keyshares_arr == NULL) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); goto failure; } - *encoded_pubkey_arr = OPENSSL_malloc_array(MAX_KEY_SHARES, + *encoded_pubkey_arr = OPENSSL_malloc_array(*keyshares_max, sizeof(**encoded_pubkey_arr)); if (*encoded_pubkey_arr == NULL) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); goto failure; } - /* - * We limit the number of key shares we are willing to process to - * MAX_KEY_SHARES regardless of whether we include them in keyshares_arr or - * not. - */ - for (i = 0; PACKET_remaining(key_share_list) > 0 && i < MAX_KEY_SHARES; i++) { + while (PACKET_remaining(key_share_list) > 0) { /* Get the group_id for the current share and its encoded_pubkey */ if (!PACKET_get_net_2(key_share_list, &group_id) || !PACKET_get_length_prefixed_2(key_share_list, &encoded_pubkey) @@ -738,7 +731,7 @@ static KS_EXTRACTION_RESULT extract_keyshares(SSL_CONNECTION *s, PACKET *key_sha if (!check_in_list(s, group_id, srvrgroups, srvr_num_groups, 1, NULL) || !tls_group_allowed(s, group_id, SSL_SECOP_CURVE_SUPPORTED) || !tls_valid_group(s, group_id, TLS1_3_VERSION, TLS1_3_VERSION, - NULL, NULL)) { + 0, NULL)) { /* Share not suitable or not supported, check next share */ continue; } @@ -746,6 +739,35 @@ static KS_EXTRACTION_RESULT extract_keyshares(SSL_CONNECTION *s, PACKET *key_sha /* Memorize this key share group ID and its encoded point */ (*keyshares_arr)[*keyshares_cnt] = group_id; (*encoded_pubkey_arr)[(*keyshares_cnt)++] = encoded_pubkey; + + /* + * Memory management (remark: While limiting the client to only allow + * a maximum of OPENSSL_CLIENT_MAX_KEY_SHARES to be sent, the server can + * handle any number of key shares) + */ + if (*keyshares_cnt == *keyshares_max) { + PACKET *tmp_pkt; + uint16_t *tmp = OPENSSL_realloc_array(*keyshares_arr, + *keyshares_max + GROUPLIST_INCREMENT, + sizeof(**keyshares_arr)); + + if (tmp == NULL) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + goto failure; + } + + *keyshares_arr = tmp; + tmp_pkt = OPENSSL_realloc_array(*encoded_pubkey_arr, + *keyshares_max + GROUPLIST_INCREMENT, + sizeof(**encoded_pubkey_arr)); + if (tmp_pkt == NULL) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + goto failure; + } + + *encoded_pubkey_arr = tmp_pkt; + *keyshares_max += GROUPLIST_INCREMENT; + } } return EXTRACTION_SUCCESS; @@ -785,7 +807,7 @@ static void check_overlap(SSL_CONNECTION *s, || !tls_group_allowed(s, candidate_groups[current_group], SSL_SECOP_CURVE_SUPPORTED) || !tls_valid_group(s, candidate_groups[current_group], TLS1_3_VERSION, - TLS1_3_VERSION, NULL, NULL)) + TLS1_3_VERSION, 0, NULL)) /* No overlap or group not suitable, check next group */ continue; @@ -815,6 +837,7 @@ int tls_parse_ctos_key_share(SSL_CONNECTION *s, PACKET *pkt, PACKET *encoded_pubkey_arr = NULL; uint16_t *keyshares_arr = NULL; size_t keyshares_cnt = 0; + size_t keyshares_max = GROUPLIST_INCREMENT; /* We conservatively assume that we did not find a suitable group */ uint16_t group_id_candidate = 0; KS_EXTRACTION_RESULT ks_extraction_result; @@ -869,7 +892,7 @@ int tls_parse_ctos_key_share(SSL_CONNECTION *s, PACKET *pkt, clntgroups, clnt_num_groups, srvrgroups, srvr_num_groups, &keyshares_arr, &encoded_pubkey_arr, - &keyshares_cnt); + &keyshares_cnt, &keyshares_max); if (ks_extraction_result == EXTRACTION_FAILURE) /* Fatal error during tests */ return 0; /* Memory already freed and SSLfatal already called */ @@ -1212,16 +1235,9 @@ int tls_parse_ctos_supported_groups(SSL_CONNECTION *s, PACKET *pkt, OPENSSL_free(s->ext.peer_supportedgroups); s->ext.peer_supportedgroups = NULL; s->ext.peer_supportedgroups_len = 0; - /* - * We only pay attention to the first 128 supported groups and ignore - * any beyond that limit. Theoretically this could cause problems if - * the client also uses one of these groups (say in a key share extension) - * - but why would any valid client be sending such a huge supported - * groups list? - */ if (!tls1_save_u16(&supported_groups_list, &s->ext.peer_supportedgroups, - &s->ext.peer_supportedgroups_len, MAX_SUPPORTED_GROUPS)) { + &s->ext.peer_supportedgroups_len)) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); return 0; } @@ -1316,14 +1332,9 @@ int tls_parse_ctos_psk(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); return 0; } - /* There must always be at least one identity in the list */ - if (PACKET_remaining(&identities) == 0) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } s->ext.ticket_expected = 0; - for (id = 0; PACKET_remaining(&identities) != 0 && id < MAX_PRE_SHARED_KEYS; id++) { + for (id = 0; PACKET_remaining(&identities) != 0; id++) { PACKET identity; unsigned long ticket_agel; size_t idlen; @@ -1335,10 +1346,6 @@ int tls_parse_ctos_psk(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, } idlen = PACKET_remaining(&identity); - if (idlen == 0) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - return 0; - } if (s->psk_find_session_cb != NULL && !s->psk_find_session_cb(ussl, PACKET_data(&identity), idlen, &sess)) { @@ -1397,10 +1404,7 @@ int tls_parse_ctos_psk(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, #endif /* OPENSSL_NO_PSK */ if (sess != NULL) { - /* - * We found an external (not a resumption) PSK - duplicate the - * session, set the session id to our own, and mark it as external. - */ + /* We found a PSK */ SSL_SESSION *sesstmp = ssl_session_dup(sess, 0); if (sesstmp == NULL) { @@ -1416,7 +1420,7 @@ int tls_parse_ctos_psk(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, */ memcpy(sess->sid_ctx, s->sid_ctx, s->sid_ctx_length); sess->sid_ctx_length = s->sid_ctx_length; - sess->psk_external = ext = 1; + ext = 1; if (id == 0) s->ext.early_data_ok = 1; s->ext.ticket_expected = 1; @@ -1440,13 +1444,13 @@ int tls_parse_ctos_psk(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, if (ret == SSL_TICKET_EMPTY) { SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - goto err; + return 0; } if (ret == SSL_TICKET_FATAL_ERR_MALLOC || ret == SSL_TICKET_FATAL_ERR_OTHER) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; + return 0; } if (ret == SSL_TICKET_NONE || ret == SSL_TICKET_NO_DECRYPT) continue; @@ -1487,8 +1491,6 @@ int tls_parse_ctos_psk(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, */ s->ext.early_data_ok = 1; } - /* This PSK is not external, use the correct binder label, ... */ - ext = 0; } md = ssl_md(sctx, sess->cipher->algorithm2); @@ -1503,37 +1505,16 @@ int tls_parse_ctos_psk(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, SSL_SESSION_free(sess); sess = NULL; s->ext.early_data_ok = 0; - /* - * We fall back to a full handshake. The new session ticket will be - * issued to the client with the newly negotiated ciphersuite, - * allowing successful resumption on future connections. - */ - s->ext.ticket_expected = 1; + s->ext.ticket_expected = 0; continue; } break; } - if (sess == NULL) { - size_t j; + if (sess == NULL) + return 1; - for (j = 0; j < s->ssl_pkey_num && !ssl_has_cert(s, (int)j); j++) - ; - if (j < s->ssl_pkey_num) { - /* A certificate exists. Fallback to a full handshake */ - return 1; - } - /* - * decrypt_error here to keep the alert the same as if the binder - * failed. See RFC8446 Appendix E.6. Note we make no attempt to do this - * in constant time compared to verifying the binder. None of this code - * is constant time anyway. - */ - SSLfatal(s, SSL_AD_DECRYPT_ERROR, SSL_R_BAD_EXTENSION); - goto err; - } - - binderoffset = PACKET_data(pkt) - PACKET_msg_start(pkt); + binderoffset = PACKET_data(pkt) - (const unsigned char *)s->init_buf->data; hashsize = EVP_MD_get_size(md); if (hashsize <= 0) goto err; @@ -1554,8 +1535,9 @@ int tls_parse_ctos_psk(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); goto err; } - if (tls_psk_do_binder(s, md, PACKET_msg_start(pkt), binderoffset, - PACKET_data(&binder), NULL, sess, 0, ext) + if (tls_psk_do_binder(s, md, (const unsigned char *)s->init_buf->data, + binderoffset, PACKET_data(&binder), NULL, sess, 0, + ext) != 1) { /* SSLfatal() already called */ goto err; @@ -1666,29 +1648,14 @@ EXT_RETURN tls_construct_stoc_ec_pt_formats(SSL_CONNECTION *s, WPACKET *pkt, { unsigned long alg_k = s->s3.tmp.new_cipher->algorithm_mkey; unsigned long alg_a = s->s3.tmp.new_cipher->algorithm_auth; - int using_ecc = (alg_k & SSL_kECDHE) || (alg_a & SSL_aECDSA); + int using_ecc = ((alg_k & SSL_kECDHE) || (alg_a & SSL_aECDSA)) + && (s->ext.peer_ecpointformats != NULL); const unsigned char *plist; size_t plistlen; - /* - * The extension is irrelevant unless we're negotiating an ECC - * ciphersuite at TLS 1.2 or below, and the peer sent a list. This - * is the first point at which the chosen ciphersuite is known, so - * the RFC 4492/8422 section 5.1.2 check for the required - * 'uncompressed' codepoint also happens here. - */ - if (!using_ecc || s->ext.peer_ecpointformats == NULL) + if (!using_ecc) return EXT_RETURN_NOT_SENT; - if (memchr(s->ext.peer_ecpointformats, - TLSEXT_ECPOINTFORMAT_uncompressed, - s->ext.peer_ecpointformats_len) - == NULL) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, - SSL_R_TLS_INVALID_ECPOINTFORMAT_LIST); - return EXT_RETURN_FAIL; - } - tls1_get_formatlist(s, &plist, &plistlen); if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_ec_point_formats) || !WPACKET_start_sub_packet_u16(pkt) @@ -1725,7 +1692,7 @@ EXT_RETURN tls_construct_stoc_supported_groups(SSL_CONNECTION *s, WPACKET *pkt, for (i = 0; i < numgroups; i++) { uint16_t group = groups[i]; - if (tls_valid_group(s, group, version, version, NULL, NULL) + if (tls_valid_group(s, group, version, version, 0, NULL) && tls_group_allowed(s, group, SSL_SECOP_CURVE_SUPPORTED)) { if (first) { /* @@ -1765,15 +1732,7 @@ EXT_RETURN tls_construct_stoc_session_ticket(SSL_CONNECTION *s, WPACKET *pkt, unsigned int context, X509 *x, size_t chainidx) { - /* - * Don't tell the client to expect a NewSessionTicket when any - * ticket we'd mint would be rejected by ssl_get_prev_session() - * whenever SSL_VERIFY_PEER is set with no sid_ctx configured (see - * the checks there). In TLS 1.2, once promised the ticket MUST - * be sent. - */ - if (!s->ext.ticket_expected || !tls_use_ticket(s) - || ((s->verify_mode & SSL_VERIFY_PEER) != 0 && s->sid_ctx_length == 0)) { + if (!s->ext.ticket_expected || !tls_use_ticket(s)) { s->ext.ticket_expected = 0; return EXT_RETURN_NOT_SENT; } @@ -2481,169 +2440,3 @@ int tls_parse_ctos_server_cert_type(SSL_CONNECTION *sc, PACKET *pkt, SSLfatal(sc, SSL_AD_UNSUPPORTED_CERTIFICATE, SSL_R_BAD_EXTENSION); return 0; } - -#ifndef OPENSSL_NO_ECH -/* - * ECH handling for edge cases (GREASE/inner) and errors. - * return 1 for good, 0 otherwise - * - * Real ECH handling (i.e. decryption) happens before, via - * ech_early_decrypt(), but if that failed (e.g. decryption - * failed, which may be down to GREASE) then we end up here, - * processing the ECH from the outer CH. - * Otherwise, we only expect to see an inner ECH with a fixed - * value here. - */ -int tls_parse_ctos_ech(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, - X509 *x, size_t chainidx) -{ - unsigned int echtype = 0; - - if (s->ext.ech.grease == OSSL_ECH_IS_GREASE) { - /* GREASE is fine */ - return 1; - } - if (s->ext.ech.es == NULL) { - /* If not configured for ECH then we ignore it */ - return 1; - } - if (s->ext.ech.attempted_type != TLSEXT_TYPE_ech) { - /* if/when new versions of ECH are added we'll update here */ - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - return 0; - } - /* - * we only allow "inner" which is one octet, valued 0x01 - * and only if we decrypted ok or are a backend - */ - if (PACKET_get_1(pkt, &echtype) != 1 - || PACKET_remaining(pkt) != 0) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_BAD_EXTENSION); - return 0; - } - if (echtype != OSSL_ECH_INNER_CH_TYPE) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - return 0; - } - s->ext.ech.inner_ech_seen_ok = 1; - if (s->ext.ech.success != 1 && s->ext.ech.backend != 1) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); - return 0; - } - /* yay - we're ok with this */ - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "ECH seen in inner as expected.\n"); - } - OSSL_TRACE_END(TLS); - return 1; -} - -/* - * Answer an ECH, as needed - * return 1 for good, 0 otherwise - * - * Return most-recent ECH config for retry, as needed. - * If doing HRR we include the confirmation value, but - * for now, we'll just add the zeros - the real octets - * will be added later via ech_calc_ech_confirm() which - * is called when constructing the server hello. - */ -EXT_RETURN tls_construct_stoc_ech(SSL_CONNECTION *s, WPACKET *pkt, - unsigned int context, X509 *x, - size_t chainidx) -{ - unsigned char *rcfgs = NULL; - size_t rcfgslen = 0; - SSL_CTX *sctx = SSL_CONNECTION_GET_CTX(s); - - if (context == SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST - && (s->ext.ech.success == 1 || s->ext.ech.backend == 1) - && s->ext.ech.attempted_type == TLSEXT_TYPE_ech) { - unsigned char eightzeros[8] = { 0, 0, 0, 0, 0, 0, 0, 0 }; - - if (!WPACKET_put_bytes_u16(pkt, s->ext.ech.attempted_type) - || !WPACKET_sub_memcpy_u16(pkt, eightzeros, 8)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "set 8 zeros for ECH accept confirm in HRR\n"); - } - OSSL_TRACE_END(TLS); - return EXT_RETURN_SENT; - } - /* GREASE or error => random confirmation in HRR case */ - if (context == SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST - && s->ext.ech.attempted_type == TLSEXT_TYPE_ech - && s->ext.ech.attempted == 1) { - unsigned char randomconf[8]; - - if (RAND_bytes_ex(sctx->libctx, randomconf, 8, - RAND_DRBG_STRENGTH) - <= 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - if (!WPACKET_put_bytes_u16(pkt, s->ext.ech.attempted_type) - || !WPACKET_sub_memcpy_u16(pkt, randomconf, 8)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "set random for ECH acccpt confirm in HRR\n"); - } - OSSL_TRACE_END(TLS); - return EXT_RETURN_SENT; - } - /* in other HRR circumstances: don't set */ - if (context == SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST) - return EXT_RETURN_NOT_SENT; - /* If in some weird state we ignore and send nothing */ - if (s->ext.ech.grease != OSSL_ECH_IS_GREASE - || s->ext.ech.attempted_type != TLSEXT_TYPE_ech) - return EXT_RETURN_NOT_SENT; - /* - * If the client GREASEd, or we think it did, return the - * most-recently loaded ECHConfigList, as the value of the - * extension. Most-recently loaded can be anywhere in the - * list, depending on changing or non-changing file names. - */ - if (s->ext.ech.es == NULL) { - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "ECH - not sending ECHConfigList to client " - "even though they GREASE'd as I've no loaded configs\n"); - } - OSSL_TRACE_END(TLS); - return EXT_RETURN_NOT_SENT; - } - if (ossl_ech_get_retry_configs(s, &rcfgs, &rcfgslen) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - if (rcfgslen == 0) { - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "ECH - not sending ECHConfigList to client " - "even though they GREASE'd and I have configs but " - "I've no configs set to be returned\n"); - } - OSSL_TRACE_END(TLS); - OPENSSL_free(rcfgs); - return EXT_RETURN_NOT_SENT; - } - if (!WPACKET_put_bytes_u16(pkt, TLSEXT_TYPE_ech) - || !WPACKET_start_sub_packet_u16(pkt) - || !WPACKET_sub_memcpy_u16(pkt, rcfgs, rcfgslen) - || !WPACKET_close(pkt)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - OPENSSL_free(rcfgs); - return 0; - } - OPENSSL_free(rcfgs); - return EXT_RETURN_SENT; -} -#endif /* END OPENSSL_NO_ECH */ diff --git a/ssl/statem/statem.c b/ssl/statem/statem.c index 04887bc9d1..d649e38474 100644 --- a/ssl/statem/statem.c +++ b/ssl/statem/statem.c @@ -1,5 +1,5 @@ /* - * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -131,7 +131,6 @@ void ossl_statem_clear(SSL_CONNECTION *s) { s->statem.state = MSG_FLOW_UNINITED; s->statem.hand_state = TLS_ST_BEFORE; - s->statem.error_state = ERROR_STATE_NOERROR; ossl_statem_set_in_init(s, 1); s->statem.no_cert_verify = 0; } @@ -152,7 +151,7 @@ void ossl_statem_send_fatal(SSL_CONNECTION *s, int al) return; ossl_statem_set_in_init(s, 1); s->statem.state = MSG_FLOW_ERROR; - if (al != SSL_AD_NO_ALERT && s->rlayer.wrlmethod != NULL) + if (al != SSL_AD_NO_ALERT) ssl3_send_alert(s, SSL3_AL_FATAL, al); } @@ -289,7 +288,6 @@ void ossl_statem_set_hello_verify_done(SSL_CONNECTION *s) * sensible. */ s->statem.hand_state = TLS_ST_SR_CLNT_HELLO; - s->statem.error_state = ERROR_STATE_NOERROR; } int ossl_statem_connect(SSL *s) @@ -543,6 +541,22 @@ static void init_read_state_machine(SSL_CONNECTION *s) st->read_state = READ_STATE_HEADER; } +static int grow_init_buf(SSL_CONNECTION *s, size_t size) +{ + + size_t msg_offset = (char *)s->init_msg - s->init_buf->data; + + if (!BUF_MEM_grow_clean(s->init_buf, size)) + return 0; + + if (size < msg_offset) + return 0; + + s->init_msg = s->init_buf->data + msg_offset; + + return 1; +} + /* * This function implements the sub-state machine when the message flow is in * MSG_FLOW_READING. The valid sub-states and transitions are: @@ -573,7 +587,7 @@ static SUB_STATE_RETURN read_state_machine(SSL_CONNECTION *s) { OSSL_STATEM *st = &s->statem; int ret, mt; - size_t len = 0, headerlen; + size_t len = 0; int (*transition)(SSL_CONNECTION *s, int mt); PACKET pkt; MSG_PROCESS_RETURN (*process_message)(SSL_CONNECTION *s, PACKET *pkt); @@ -639,6 +653,14 @@ static SUB_STATE_RETURN read_state_machine(SSL_CONNECTION *s) return SUB_STATE_ERROR; } + /* dtls_get_message already did this */ + if (!SSL_CONNECTION_IS_DTLS(s) + && s->s3.tmp.message_size > 0 + && !grow_init_buf(s, s->s3.tmp.message_size + SSL3_HM_HEADER_LENGTH)) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_BUF_LIB); + return SUB_STATE_ERROR; + } + st->read_state = READ_STATE_BODY; /* Fall through */ @@ -658,23 +680,10 @@ static SUB_STATE_RETURN read_state_machine(SSL_CONNECTION *s) } s->first_packet = 0; - /* - * We initialise the buffer including the message header, and - * then skip over header ready to process the message. This - * ensures that calls to PACKET_msg_start() gives us the whole - * message - */ - headerlen = (char *)s->init_msg - s->init_buf->data; - if (!PACKET_buf_init(&pkt, (unsigned char *)s->init_buf->data, - len + headerlen)) { + if (!PACKET_buf_init(&pkt, s->init_msg, len)) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); return SUB_STATE_ERROR; } - if (!PACKET_forward(&pkt, headerlen)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return SUB_STATE_ERROR; - } - ret = process_message(s, &pkt); /* Discard the packet data */ diff --git a/ssl/statem/statem_clnt.c b/ssl/statem/statem_clnt.c index d719ef8a84..a1cbe723b6 100644 --- a/ssl/statem/statem_clnt.c +++ b/ssl/statem/statem_clnt.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * Copyright 2005 Nokia. All rights reserved. * @@ -31,12 +31,14 @@ #include static MSG_PROCESS_RETURN tls_process_as_hello_retry_request(SSL_CONNECTION *s, - RAW_EXTENSION *extensions); + PACKET *pkt); static MSG_PROCESS_RETURN tls_process_encrypted_extensions(SSL_CONNECTION *s, PACKET *pkt); static ossl_inline int cert_req_allowed(SSL_CONNECTION *s); static int key_exchange_expected(SSL_CONNECTION *s); +static int ssl_cipher_list_to_bytes(SSL_CONNECTION *s, STACK_OF(SSL_CIPHER) *sk, + WPACKET *pkt); static ossl_inline int received_server_cert(SSL_CONNECTION *sc) { @@ -53,8 +55,9 @@ static ossl_inline int received_server_cert(SSL_CONNECTION *sc) static ossl_inline int cert_req_allowed(SSL_CONNECTION *s) { /* TLS does not like anon-DH with client cert */ - if ((s->s3.tmp.new_cipher->algorithm_auth & SSL_aNULL) != 0 - || (s->s3.tmp.new_cipher->algorithm_auth & (SSL_aSRP | SSL_aPSK)) != 0) + if ((s->version > SSL3_VERSION + && (s->s3.tmp.new_cipher->algorithm_auth & SSL_aNULL)) + || (s->s3.tmp.new_cipher->algorithm_auth & (SSL_aSRP | SSL_aPSK))) return 0; return 1; @@ -403,6 +406,20 @@ int ossl_statem_client_read_transition(SSL_CONNECTION *s, int mt) err: /* No valid transition found */ + if (SSL_CONNECTION_IS_DTLS(s) && mt == SSL3_MT_CHANGE_CIPHER_SPEC) { + BIO *rbio; + + /* + * CCS messages don't have a message sequence number so this is probably + * because of an out-of-order CCS. We'll just drop it. + */ + s->init_num = 0; + s->rwstate = SSL_READING; + rbio = SSL_get_rbio(SSL_CONNECTION_GET_SSL(s)); + BIO_clear_retry_flags(rbio); + BIO_set_retry_read(rbio); + return 0; + } SSLfatal(s, SSL3_AD_UNEXPECTED_MESSAGE, SSL_R_UNEXPECTED_MESSAGE); return 0; } @@ -1155,233 +1172,7 @@ WORK_STATE ossl_statem_client_post_process_message(SSL_CONNECTION *s, } } -#ifndef OPENSSL_NO_ECH -/* - * Wrap ClientHello construction with ECH code. - * - * As needed, we'll call the CH constructor twice, first for - * inner, and then for outer. - * - * `tls_construct_client_hello_aux` is the pre-ECH code - * and the ECH-aware tls_construct_client_hello just calls - * that if there's no ECH involved, but otherwise does ECH - * things around calls to the _aux variant. - * - * Our basic model is that, when really attempting ECH we - * indicate via the ch_depth field whether we're dealing - * with inner or outer CH (1 for inner, 0 for outer). - * - * After creating the fields for the inner CH, we encode - * those (so we can re-use existing code) then decode again - * (using the existing tls_process_client_hello previously - * only used on servers), again to maximise code re-use. - * - * We next re-encode inner but this time including the - * optimisations for inner CH "compression" (outer exts etc.) - * to produce our plaintext for encrypting. - * - * We then process the outer CH in more or less the - * usual manner. - * - * We lastly form up the AAD etc and encrypt to give us - * the ciphertext for inclusion in the value of the outer - * CH ECH extension. - * - * It may seem odd to form up the outer CH before - * encrypting, but we need to do it that way so we get - * the octets for the AAD used in encryption. - * - * Phew! - */ -static int tls_construct_client_hello_aux(SSL_CONNECTION *s, WPACKET *pkt); - -__owur CON_FUNC_RETURN tls_construct_client_hello(SSL_CONNECTION *s, - WPACKET *pkt) -{ - WPACKET inner; /* "fake" pkt for inner */ - BUF_MEM *inner_mem = NULL; - PACKET rpkt; /* we'll decode back the inner ch to help make the outer */ - SSL_SESSION *sess = NULL; - SSL_CTX *sctx = SSL_CONNECTION_GET_CTX(s); - size_t sess_id_len = 0, innerlen = 0; - int mt = SSL3_MT_CLIENT_HELLO, rv = 0; - OSSL_HPKE_SUITE suite; - OSSL_ECHSTORE_ENTRY *ee = NULL; - /* Work out what SSL/TLS/DTLS version to use */ - int protverr = ssl_set_client_hello_version(s); - - if (protverr != 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, protverr); - return 0; - } - /* If we're not really attempting ECH, just call existing code. */ - if (s->ext.ech.es == NULL) - return tls_construct_client_hello_aux(s, pkt); - /* note version we're attempting and that an attempt is being made */ - if (s->ext.ech.es->entries != NULL) { - if (ossl_ech_pick_matching_cfg(s, &ee, &suite) != 1 || ee == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_UNSUPPORTED); - return 0; - } - if (ee->version != OSSL_ECH_RFC9849_VERSION) { - /* we only support that version for now */ - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_UNSUPPORTED); - return 0; - } - s->ext.ech.attempted_type = TLSEXT_TYPE_ech; - s->ext.ech.attempted_cid = ee->config_id; - s->ext.ech.attempted = 1; - if (s->ext.ech.outer_hostname == NULL && ee->public_name != NULL) { - s->ext.ech.outer_hostname = OPENSSL_strdup((char *)ee->public_name); - if (s->ext.ech.outer_hostname == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - } - } - /* If doing real ECH and application requested GREASE too, over-ride that */ - if (s->ext.ech.grease == OSSL_ECH_IS_GREASE && s->ext.ech.attempted == 1) - s->ext.ech.grease = OSSL_ECH_NOT_GREASE; - /* - * Session ID is handled "oddly" by not being encoded into inner CH (an - * optimisation) so is the same for both inner and outer. - */ - sess = s->session; - if (sess == NULL - || !ssl_version_supported(s, sess->ssl_version, NULL) - || !SSL_SESSION_is_resumable(sess)) { - if (s->hello_retry_request == SSL_HRR_NONE - && !ssl_get_new_session(s, 0)) - return 0; /* SSLfatal() already called */ - } - if (s->new_session || s->session->ssl_version == TLS1_3_VERSION) { - if (s->version == TLS1_3_VERSION - && (s->options & SSL_OP_ENABLE_MIDDLEBOX_COMPAT) != 0) { - sess_id_len = sizeof(s->tmp_session_id); - s->tmp_session_id_len = sess_id_len; - if (s->hello_retry_request == SSL_HRR_NONE - && RAND_bytes_ex(sctx->libctx, s->tmp_session_id, - sess_id_len, 0) - <= 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return 0; - } - memcpy(s->session->session_id, s->tmp_session_id, sess_id_len); - s->session->session_id_length = sess_id_len; - } else { - sess_id_len = 0; - } - } else { - assert(s->session->session_id_length <= sizeof(s->session->session_id)); - sess_id_len = s->session->session_id_length; - if (s->version == TLS1_3_VERSION) { - s->tmp_session_id_len = sess_id_len; - memcpy(s->tmp_session_id, s->session->session_id, sess_id_len); - } - } - if (s->hello_retry_request != SSL_HRR_NONE) - s->ext.ech.n_outer_only = 0; /* reset count of "compressed" exts */ - /* - * Set CH depth flag so that other code (e.g. extension handlers) - * know where we're at: 1 is "inner CH", 0 is "outer CH" - */ - s->ext.ech.ch_depth = 1; - if ((inner_mem = BUF_MEM_new()) == NULL - || !WPACKET_init(&inner, inner_mem) - || !ssl_set_handshake_header(s, &inner, mt) - || tls_construct_client_hello_aux(s, &inner) != 1 - || !WPACKET_close(&inner) - || !WPACKET_get_length(&inner, &innerlen)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - OPENSSL_free(s->ext.ech.innerch); - s->ext.ech.innerch = (unsigned char *)inner_mem->data; - inner_mem->data = NULL; - s->ext.ech.innerch_len = innerlen; - /* add inner to transcript */ - if (ossl_ech_intbuf_add(s, s->ext.ech.innerch, innerlen, 0) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - WPACKET_cleanup(&inner); - BUF_MEM_free(inner_mem); - inner_mem = NULL; -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("inner CH", s->ext.ech.innerch, s->ext.ech.innerch_len); - ossl_ech_pbuf("inner, client_random", s->ext.ech.client_random, - SSL3_RANDOM_SIZE); - ossl_ech_pbuf("inner, session_id", s->session->session_id, - s->session->session_id_length); -#endif - /* Decode inner so that we can make up encoded inner */ - if (!PACKET_buf_init(&rpkt, (unsigned char *)s->ext.ech.innerch + 4, - s->ext.ech.innerch_len - 4)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - /* - * Parse the full inner CH (usually done on server). This gets us - * individually encoded extensions so we can choose to compress - * and/or to re-use the same value in outer. - */ - if (!tls_process_client_hello(s, &rpkt)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - - s->ext.ech.ch_depth = 0; /* set depth for outer CH */ - /* - * If we want different key shares for inner and outer, then - * zap the one for the inner. The inner key_share is stashed - * in s.ext.ech.tmp_pkey already. - */ - if (ossl_ech_same_key_share() == 0) { - EVP_PKEY_free(s->s3.tmp.pkey); - s->s3.tmp.pkey = NULL; - } - /* Make second call into CH construction for outer CH. */ - rv = tls_construct_client_hello_aux(s, pkt); - if (rv != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("outer, client_random", s->s3.client_random, - SSL3_RANDOM_SIZE); - ossl_ech_pbuf("outer, session_id", s->session->session_id, - s->session->session_id_length); -#endif - /* Finally, calculate AAD and encrypt using HPKE */ - if (ossl_ech_aad_and_encrypt(s, pkt) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - /* Free up raw exts as needed (happens like this on real server) */ - if (s->clienthello != NULL - && s->clienthello->pre_proc_exts != NULL) { - OPENSSL_free(s->clienthello->pre_proc_exts); - OPENSSL_free(s->clienthello); - s->clienthello = NULL; - } - return 1; -err: - if (inner_mem != NULL) { - WPACKET_cleanup(&inner); - BUF_MEM_free(inner_mem); - } - if (s->clienthello != NULL) { - OPENSSL_free(s->clienthello->pre_proc_exts); - OPENSSL_free(s->clienthello); - s->clienthello = NULL; - } - return 0; -} - -static int tls_construct_client_hello_aux(SSL_CONNECTION *s, WPACKET *pkt) -#else -__owur CON_FUNC_RETURN tls_construct_client_hello(SSL_CONNECTION *s, WPACKET *pkt) -#endif +CON_FUNC_RETURN tls_construct_client_hello(SSL_CONNECTION *s, WPACKET *pkt) { unsigned char *p; size_t sess_id_len; @@ -1400,28 +1191,18 @@ __owur CON_FUNC_RETURN tls_construct_client_hello(SSL_CONNECTION *s, WPACKET *pk return CON_FUNC_ERROR; } -#ifndef OPENSSL_NO_ECH - /* if we're doing ECH, re-use session ID setup earlier */ - if (s->ext.ech.es == NULL) -#endif - if (sess == NULL - || !ssl_version_supported(s, sess->ssl_version, NULL) - || !SSL_SESSION_is_resumable(sess)) { - if (s->hello_retry_request == SSL_HRR_NONE - && !ssl_get_new_session(s, 0)) { - /* SSLfatal() already called */ - return CON_FUNC_ERROR; - } + if (sess == NULL + || !ssl_version_supported(s, sess->ssl_version, NULL) + || !SSL_SESSION_is_resumable(sess)) { + if (s->hello_retry_request == SSL_HRR_NONE + && !ssl_get_new_session(s, 0)) { + /* SSLfatal() already called */ + return CON_FUNC_ERROR; } + } /* else use the pre-loaded session */ -#ifndef OPENSSL_NO_ECH - /* use different client_random fields for inner and outer */ - if (s->ext.ech.es != NULL && s->ext.ech.ch_depth == 1) - p = s->ext.ech.client_random; - else -#endif - p = s->s3.client_random; + p = s->s3.client_random; /* * for DTLS if client_random is initialized, reuse it, we are @@ -1479,54 +1260,37 @@ __owur CON_FUNC_RETURN tls_construct_client_hello(SSL_CONNECTION *s, WPACKET *pk * supported_versions extension for the real supported versions. */ if (!WPACKET_put_bytes_u16(pkt, s->client_version) - || !WPACKET_memcpy(pkt, p, SSL3_RANDOM_SIZE)) { + || !WPACKET_memcpy(pkt, s->s3.client_random, SSL3_RANDOM_SIZE)) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); return CON_FUNC_ERROR; } /* Session ID */ session_id = s->session->session_id; -#ifndef OPENSSL_NO_ECH - /* same session ID is used for inner/outer when doing ECH */ - if (s->ext.ech.es != NULL) { - if (s->version != TLS1_3_VERSION) { - SSLfatal(s, SSL_AD_PROTOCOL_VERSION, SSL_R_UNSUPPORTED_SSL_VERSION); - return CON_FUNC_ERROR; - } - if ((s->options & SSL_OP_ENABLE_MIDDLEBOX_COMPAT) != 0) + if (s->new_session || s->session->ssl_version == TLS1_3_VERSION) { + if (s->version == TLS1_3_VERSION + && (s->options & SSL_OP_ENABLE_MIDDLEBOX_COMPAT) != 0) { sess_id_len = sizeof(s->tmp_session_id); - else - sess_id_len = 0; - } else { -#endif - if (s->new_session || s->session->ssl_version == TLS1_3_VERSION) { - if (s->version == TLS1_3_VERSION - && (s->options & SSL_OP_ENABLE_MIDDLEBOX_COMPAT) != 0) { - sess_id_len = sizeof(s->tmp_session_id); - s->tmp_session_id_len = sess_id_len; - session_id = s->tmp_session_id; - if (s->hello_retry_request == SSL_HRR_NONE - && RAND_bytes_ex(sctx->libctx, s->tmp_session_id, - sess_id_len, 0) - <= 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return CON_FUNC_ERROR; - } - } else { - sess_id_len = 0; + s->tmp_session_id_len = sess_id_len; + session_id = s->tmp_session_id; + if (s->hello_retry_request == SSL_HRR_NONE + && RAND_bytes_ex(sctx->libctx, s->tmp_session_id, + sess_id_len, 0) + <= 0) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + return CON_FUNC_ERROR; } } else { - assert(s->session->session_id_length <= sizeof(s->session->session_id)); - sess_id_len = s->session->session_id_length; - if (s->version == TLS1_3_VERSION) { - s->tmp_session_id_len = sess_id_len; - memcpy(s->tmp_session_id, s->session->session_id, sess_id_len); - } + sess_id_len = 0; + } + } else { + assert(s->session->session_id_length <= sizeof(s->session->session_id)); + sess_id_len = s->session->session_id_length; + if (s->version == TLS1_3_VERSION) { + s->tmp_session_id_len = sess_id_len; + memcpy(s->tmp_session_id, s->session->session_id, sess_id_len); } -#ifndef OPENSSL_NO_ECH } -#endif - if (!WPACKET_start_sub_packet_u8(pkt) || (sess_id_len != 0 && !WPACKET_memcpy(pkt, session_id, sess_id_len)) || !WPACKET_close(pkt)) { @@ -1639,7 +1403,7 @@ static int set_client_ciphersuite(SSL_CONNECTION *s, * If it is a disabled cipher we either didn't send it in client hello, * or it's not allowed for the selected protocol. So we return an error. */ - if (ssl_cipher_disabled(s, c, SSL_SECOP_CIPHER_CHECK)) { + if (ssl_cipher_disabled(s, c, SSL_SECOP_CIPHER_CHECK, 1)) { SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_WRONG_CIPHER_RETURNED); return 0; } @@ -1714,24 +1478,6 @@ MSG_PROCESS_RETURN tls_process_server_hello(SSL_CONNECTION *s, PACKET *pkt) #ifndef OPENSSL_NO_COMP SSL_COMP *comp; #endif -#ifndef OPENSSL_NO_ECH - const unsigned char *shbuf = NULL; - size_t shlen, alen; - /* - * client and server accept signal buffers, initialise in case of - * e.g. memory fail when calculating, only really applies when - * SUPERVERBOSE is defined and we trace these. - */ - unsigned char c_signal[OSSL_ECH_SIGNAL_LEN] = { 0 }; - unsigned char s_signal[OSSL_ECH_SIGNAL_LEN] = { 0xff }; - unsigned char *abuf = NULL; - - shlen = PACKET_remaining(pkt); - if (PACKET_peek_bytes(pkt, &shbuf, shlen) != 1) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_MISMATCH); - goto err; - } -#endif if (!PACKET_get_net_2(pkt, &sversion)) { SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_MISMATCH); @@ -1773,7 +1519,7 @@ MSG_PROCESS_RETURN tls_process_server_hello(SSL_CONNECTION *s, PACKET *pkt) session_id_len = PACKET_remaining(&session_id); if (session_id_len > sizeof(s->session->session_id) || session_id_len > SSL3_SESSION_ID_SIZE) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_TLS_SESSION_ID_TOO_LONG); + SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_SSL3_SESSION_ID_TOO_LONG); goto err; } @@ -1796,18 +1542,7 @@ MSG_PROCESS_RETURN tls_process_server_hello(SSL_CONNECTION *s, PACKET *pkt) goto err; } - if (hrr) { - if (!tls_collect_extensions(s, &extpkt, SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST, - &extensions, NULL, 1) - || !tls_validate_no_unknown_extensions(s, &extpkt, - SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST) - || !tls_parse_extension(s, TLSEXT_IDX_ech, - SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST, - extensions, NULL, 0)) { - /* SSLfatal() already called */ - goto err; - } - } else { + if (!hrr) { if (!tls_collect_extensions(s, &extpkt, SSL_EXT_TLS1_2_SERVER_HELLO | SSL_EXT_TLS1_3_SERVER_HELLO, @@ -1815,106 +1550,7 @@ MSG_PROCESS_RETURN tls_process_server_hello(SSL_CONNECTION *s, PACKET *pkt) /* SSLfatal() already called */ goto err; } - } -#ifndef OPENSSL_NO_ECH - /* - * If we sent an ECH then check if that worked based on the - * ServerHello.random confirmation trick. If that is good - * then we'll swap over the inner and outer contexts and - * proceed with inner. There are some HRR wrinkles too - * though. - */ - if (s->ext.ech.es != NULL - && s->ext.ech.done != 1 && s->ext.ech.ch_depth == 0 - && s->ext.ech.grease == OSSL_ECH_NOT_GREASE - && s->ext.ech.attempted_type == TLSEXT_TYPE_ech) { - if (!set_client_ciphersuite(s, cipherchars)) { - /* SSLfatal() already called */ - goto err; - } - /* add any SH/HRR to inner transcript if we tried ECH */ - if (s->ext.ech.attempted == 1) { - unsigned char prelude[4]; - - prelude[0] = SSL3_MT_SERVER_HELLO; - prelude[1] = (shlen >> 16) & 0xff; - prelude[2] = (shlen >> 8) & 0xff; - prelude[3] = shlen & 0xff; - if (ossl_ech_intbuf_add(s, prelude, sizeof(prelude), hrr) != 1 - || ossl_ech_intbuf_add(s, shbuf, shlen, 0) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - } - /* check the ECH accept signal */ - if (ossl_ech_calc_confirm(s, hrr, c_signal, shlen) != 1) { - /* SSLfatal() already called */ - OSSL_TRACE(TLS, "ECH calc confirm failed\n"); - goto err; - } - if (ossl_ech_find_confirm(s, hrr, s_signal) != 1 - || memcmp(s_signal, c_signal, sizeof(c_signal)) != 0) { - OSSL_TRACE(TLS, "ECH accept check failed\n"); -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("ECH client accept val:", c_signal, sizeof(c_signal)); - ossl_ech_pbuf("ECH server accept val:", s_signal, sizeof(s_signal)); -#endif - s->ext.ech.success = 0; - } else { /* match, ECH worked */ - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "ECH accept check ok\n"); - BIO_printf(trc_out, "ECH set session hostname to %s\n", - s->ext.hostname ? s->ext.hostname : "NULL"); - } - OSSL_TRACE_END(TLS); - s->ext.ech.success = 1; - } - if (!hrr && s->ext.ech.success == 1) { - if (ossl_ech_swaperoo(s) != 1 - || ossl_ech_intbuf_fetch(s, &abuf, &alen) != 1 - || ossl_ech_reset_hs_buffer(s, abuf, alen) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - } else if (hrr == 1 && s->ext.ech.success == 1) { - OSSL_TRACE(TLS, "ECH HRR accept ok, continuing.\n"); - /* - * If we got retry_configs then we should be validating - * the outer CH, so we better set the hostname for the - * connection accordingly. - */ - } else if (!hrr && s->ext.ech.success == 0 - && s->ext.ech.hrrsignal_p != NULL) { - /* - * we previously saw a good HRR ECH acceptance but now - * the SH.random ECH acceptance signal is bad so that's an - * illegal protocol error - */ - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_ECH_REQUIRED); - goto err; - } else { - OSSL_TRACE1(TLS, "ECH falling back to public_name: %s\n", - s->ext.ech.outer_hostname != NULL ? s->ext.ech.outer_hostname : "NONE"); - s->ext.ech.former_inner = s->ext.hostname; - s->ext.hostname = NULL; - if (s->ext.ech.outer_hostname != NULL) { - s->ext.hostname = OPENSSL_strdup(s->ext.ech.outer_hostname); - if (s->ext.hostname == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - if (SSL_set1_dnsname(ssl, s->ext.ech.outer_hostname) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - } - } - } -#endif - - if (!hrr) { if (!ssl_choose_client_version(s, sversion, extensions)) { /* SSLfatal() already called */ goto err; @@ -1938,17 +1574,12 @@ MSG_PROCESS_RETURN tls_process_server_hello(SSL_CONNECTION *s, PACKET *pkt) } if (hrr) { - int ret; - if (!set_client_ciphersuite(s, cipherchars)) { /* SSLfatal() already called */ goto err; } - ret = tls_process_as_hello_retry_request(s, extensions); - OPENSSL_free(extensions); - - return ret; + return tls_process_as_hello_retry_request(s, &extpkt); } /* @@ -1961,10 +1592,6 @@ MSG_PROCESS_RETURN tls_process_server_hello(SSL_CONNECTION *s, PACKET *pkt) SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_BAD_EXTENSION); goto err; } - if (SSL_CONNECTION_IS_TLS13(s) - && !tls_validate_no_unknown_extensions(s, &extpkt, context)) - /* SSLfatal() already called */ - goto err; s->hit = 0; @@ -2208,8 +1835,10 @@ err: } static MSG_PROCESS_RETURN tls_process_as_hello_retry_request(SSL_CONNECTION *s, - RAW_EXTENSION *extensions) + PACKET *extpkt) { + RAW_EXTENSION *extensions = NULL; + /* * If we were sending early_data then any alerts should not be sent using * the old wrlmethod. @@ -2227,12 +1856,17 @@ static MSG_PROCESS_RETURN tls_process_as_hello_retry_request(SSL_CONNECTION *s, /* We are definitely going to be using TLSv1.3 */ s->rlayer.wrlmethod->set_protocol_version(s->rlayer.wrl, TLS1_3_VERSION); - if (!tls_parse_all_extensions(s, SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST, + if (!tls_collect_extensions(s, extpkt, SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST, + &extensions, NULL, 1) + || !tls_parse_all_extensions(s, SSL_EXT_TLS1_3_HELLO_RETRY_REQUEST, extensions, NULL, 0, 1)) { /* SSLfatal() already called */ goto err; } + OPENSSL_free(extensions); + extensions = NULL; + if (s->ext.tls13_cookie_len == 0 && s->s3.tmp.pkey != NULL) { /* * We didn't receive a cookie or a new key_share so the next @@ -2265,6 +1899,7 @@ static MSG_PROCESS_RETURN tls_process_as_hello_retry_request(SSL_CONNECTION *s, return MSG_PROCESS_FINISHED_READING; err: + OPENSSL_free(extensions); return MSG_PROCESS_ERROR; } @@ -2972,10 +2607,8 @@ MSG_PROCESS_RETURN tls_process_certificate_request(SSL_CONNECTION *s, s->s3.tmp.valid_flags = OPENSSL_calloc(s->ssl_pkey_num, sizeof(uint32_t)); /* Give up for good if allocation didn't work */ - if (s->s3.tmp.valid_flags == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_CRYPTO_LIB); - return MSG_PROCESS_ERROR; - } + if (s->s3.tmp.valid_flags == NULL) + return 0; if (SSL_CONNECTION_IS_TLS13(s)) { PACKET reqctx, extensions; @@ -3096,6 +2729,7 @@ MSG_PROCESS_RETURN tls_process_new_session_ticket(SSL_CONNECTION *s, unsigned int sess_len; RAW_EXTENSION *exts = NULL; PACKET nonce; + EVP_MD *sha256 = NULL; SSL_CTX *sctx = SSL_CONNECTION_GET_CTX(s); PACKET_null_init(&nonce); @@ -3178,14 +2812,6 @@ MSG_PROCESS_RETURN tls_process_new_session_ticket(SSL_CONNECTION *s, if (SSL_CONNECTION_IS_TLS13(s)) { PACKET extpkt; - /* - * Fulfilling RFC8446:4.6.1 requirement: Clients MUST NOT cache - * tickets for longer than 7 days. - */ - if (ticket_lifetime_hint > 604800) { - ticket_lifetime_hint = 604800; - } - if (!PACKET_as_length_prefixed_2(pkt, &extpkt) || PACKET_remaining(pkt) != 0) { SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_MISMATCH); @@ -3213,16 +2839,25 @@ MSG_PROCESS_RETURN tls_process_new_session_ticket(SSL_CONNECTION *s, * We choose the former approach because this fits in with assumptions * elsewhere in OpenSSL. The session ID is set to the SHA256 hash of the * ticket. - * + */ + sha256 = EVP_MD_fetch(sctx->libctx, "SHA2-256", sctx->propq); + if (sha256 == NULL) { + /* Error is already recorded */ + SSLfatal_alert(s, SSL_AD_INTERNAL_ERROR); + goto err; + } + /* * We use sess_len here because EVP_Digest expects an int * but s->session->session_id_length is a size_t */ if (!EVP_Digest(s->session->ext.tick, ticklen, s->session->session_id, &sess_len, - sctx->sha256, NULL)) { + sha256, NULL)) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB); goto err; } + EVP_MD_free(sha256); + sha256 = NULL; s->session->session_id_length = sess_len; s->session->not_resumable = 0; @@ -3261,6 +2896,7 @@ MSG_PROCESS_RETURN tls_process_new_session_ticket(SSL_CONNECTION *s, return MSG_PROCESS_CONTINUE_READING; err: + EVP_MD_free(sha256); OPENSSL_free(exts); return MSG_PROCESS_ERROR; } @@ -3398,18 +3034,6 @@ int tls_process_initial_server_flight(SSL_CONNECTION *s) } #endif -#ifndef OPENSSL_NO_ECH - /* check result of ech and return error if needed */ - if (s->ext.ech.es != NULL - && s->ext.ech.attempted == 1 - && s->ext.ech.success != 1 - && s->ext.ech.grease != OSSL_ECH_IS_GREASE) { - s->ext.ech.retry_configs_ok = 1; /* note those are good */ - SSLfatal(s, SSL_AD_ECH_REQUIRED, SSL_R_ECH_REQUIRED); - return 0; - } -#endif /* OPENSSL_NO_ECH */ - return 1; } @@ -3558,7 +3182,7 @@ static int tls_construct_cke_rsa(SSL_CONNECTION *s, WPACKET *pkt) } /* Fix buf for TLS and beyond */ - if (!WPACKET_start_sub_packet_u16(pkt)) { + if (s->version > SSL3_VERSION && !WPACKET_start_sub_packet_u16(pkt)) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); goto err; } @@ -3578,7 +3202,7 @@ static int tls_construct_cke_rsa(SSL_CONNECTION *s, WPACKET *pkt) pctx = NULL; /* Fix buf for TLS and beyond */ - if (!WPACKET_close(pkt)) { + if (s->version > SSL3_VERSION && !WPACKET_close(pkt)) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); goto err; } @@ -3717,7 +3341,6 @@ static int tls_construct_cke_gost(SSL_CONNECTION *s, WPACKET *pkt) unsigned int md_len; unsigned char shared_ukm[32], tmp[256]; EVP_MD_CTX *ukm_hash = NULL; - EVP_MD *ukm_md = NULL; int dgst_nid = NID_id_GostR3411_94; unsigned char *pms = NULL; size_t pmslen = 0; @@ -3768,10 +3391,8 @@ static int tls_construct_cke_gost(SSL_CONNECTION *s, WPACKET *pkt) * data */ ukm_hash = EVP_MD_CTX_new(); - ukm_md = EVP_MD_fetch(sctx->libctx, OBJ_nid2sn(dgst_nid), sctx->propq); if (ukm_hash == NULL - || ukm_md == NULL - || EVP_DigestInit_ex(ukm_hash, ukm_md, NULL) <= 0 + || EVP_DigestInit(ukm_hash, EVP_get_digestbynid(dgst_nid)) <= 0 || EVP_DigestUpdate(ukm_hash, s->s3.client_random, SSL3_RANDOM_SIZE) <= 0 @@ -3779,12 +3400,9 @@ static int tls_construct_cke_gost(SSL_CONNECTION *s, WPACKET *pkt) SSL3_RANDOM_SIZE) <= 0 || EVP_DigestFinal_ex(ukm_hash, shared_ukm, &md_len) <= 0) { - EVP_MD_free(ukm_md); SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); goto err; } - EVP_MD_free(ukm_md); - ukm_md = NULL; EVP_MD_CTX_free(ukm_hash); ukm_hash = NULL; if (EVP_PKEY_CTX_ctrl(pkey_ctx, -1, EVP_PKEY_OP_ENCRYPT, @@ -4190,11 +3808,18 @@ WORK_STATE tls_prepare_client_certificate(SSL_CONNECTION *s, WORK_STATE wst) if (i && !ssl3_check_client_certificate(s)) i = 0; if (i == 0) { - s->s3.tmp.cert_req = 2; - s->ext.compress_certificate_from_peer[0] = TLSEXT_comp_cert_none; - if (!ssl3_digest_cached_records(s, 0)) - /* SSLfatal() already called */ - return WORK_ERROR; + if (s->version == SSL3_VERSION) { + s->s3.tmp.cert_req = 0; + ssl3_send_alert(s, SSL3_AL_WARNING, SSL_AD_NO_CERTIFICATE); + return WORK_FINISHED_CONTINUE; + } else { + s->s3.tmp.cert_req = 2; + s->ext.compress_certificate_from_peer[0] = TLSEXT_comp_cert_none; + if (!ssl3_digest_cached_records(s, 0)) { + /* SSLfatal() already called */ + return WORK_ERROR; + } + } } if (!SSL_CONNECTION_IS_TLS13(s) @@ -4513,6 +4138,109 @@ int ssl_do_client_cert_cb(SSL_CONNECTION *s, X509 **px509, EVP_PKEY **ppkey) return i; } +int ssl_cipher_list_to_bytes(SSL_CONNECTION *s, STACK_OF(SSL_CIPHER) *sk, + WPACKET *pkt) +{ + int i; + size_t totlen = 0, len, maxlen, maxverok = 0; + int empty_reneg_info_scsv = !s->renegotiate + && !SSL_CONNECTION_IS_DTLS(s) + && ssl_security(s, SSL_SECOP_VERSION, 0, TLS1_VERSION, NULL) + && s->min_proto_version <= TLS1_VERSION; + SSL *ssl = SSL_CONNECTION_GET_SSL(s); + + /* Set disabled masks for this session */ + if (!ssl_set_client_disabled(s)) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_NO_PROTOCOLS_AVAILABLE); + return 0; + } + + if (sk == NULL) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + return 0; + } + +#ifdef OPENSSL_MAX_TLS1_2_CIPHER_LENGTH +#if OPENSSL_MAX_TLS1_2_CIPHER_LENGTH < 6 +#error Max cipher length too short +#endif + /* + * Some servers hang if client hello > 256 bytes as hack workaround + * chop number of supported ciphers to keep it well below this if we + * use TLS v1.2 + */ + if (TLS1_get_version(ssl) >= TLS1_2_VERSION) + maxlen = OPENSSL_MAX_TLS1_2_CIPHER_LENGTH & ~1; + else +#endif + /* Maximum length that can be stored in 2 bytes. Length must be even */ + maxlen = 0xfffe; + + if (empty_reneg_info_scsv) + maxlen -= 2; + if (s->mode & SSL_MODE_SEND_FALLBACK_SCSV) + maxlen -= 2; + + for (i = 0; i < sk_SSL_CIPHER_num(sk) && totlen < maxlen; i++) { + const SSL_CIPHER *c; + + c = sk_SSL_CIPHER_value(sk, i); + /* Skip disabled ciphers */ + if (ssl_cipher_disabled(s, c, SSL_SECOP_CIPHER_SUPPORTED, 0)) + continue; + + if (!ssl->method->put_cipher_by_char(c, pkt, &len)) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + return 0; + } + + /* Sanity check that the maximum version we offer has ciphers enabled */ + if (!maxverok) { + int minproto = SSL_CONNECTION_IS_DTLS(s) ? c->min_dtls : c->min_tls; + int maxproto = SSL_CONNECTION_IS_DTLS(s) ? c->max_dtls : c->max_tls; + + if (ssl_version_cmp(s, maxproto, s->s3.tmp.max_ver) >= 0 + && ssl_version_cmp(s, minproto, s->s3.tmp.max_ver) <= 0) + maxverok = 1; + } + + totlen += len; + } + + if (totlen == 0 || !maxverok) { + const char *maxvertext = !maxverok + ? "No ciphers enabled for max supported SSL/TLS version" + : NULL; + + SSLfatal_data(s, SSL_AD_INTERNAL_ERROR, SSL_R_NO_CIPHERS_AVAILABLE, + maxvertext); + return 0; + } + + if (totlen != 0) { + if (empty_reneg_info_scsv) { + static const SSL_CIPHER scsv = { + 0, NULL, NULL, SSL3_CK_SCSV, 0, 0, 0, 0, 0, 0, 0, 0, 0 + }; + if (!ssl->method->put_cipher_by_char(&scsv, pkt, &len)) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + return 0; + } + } + if (s->mode & SSL_MODE_SEND_FALLBACK_SCSV) { + static const SSL_CIPHER scsv = { + 0, NULL, NULL, SSL3_CK_FALLBACK_SCSV, 0, 0, 0, 0, 0, 0, 0, 0, 0 + }; + if (!ssl->method->put_cipher_by_char(&scsv, pkt, &len)) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + return 0; + } + } + } + + return 1; +} + CON_FUNC_RETURN tls_construct_end_of_early_data(SSL_CONNECTION *s, WPACKET *pkt) { if (s->early_data_state != SSL_EARLY_DATA_WRITE_RETRY diff --git a/ssl/statem/statem_dtls.c b/ssl/statem/statem_dtls.c index 860d4c1c00..4052ef6219 100644 --- a/ssl/statem/statem_dtls.c +++ b/ssl/statem/statem_dtls.c @@ -1,5 +1,5 @@ /* - * Copyright 2005-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2005-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -67,59 +67,6 @@ static void dtls1_set_message_header_int(SSL_CONNECTION *s, unsigned char mt, static int dtls_get_reassembled_message(SSL_CONNECTION *s, int *errtype, size_t *len); -/* - * Check if CCS is expected in current state. - * - * RFC 6347 Section 4.1 states DTLS must handle message reordering since UDP - * does not guarantee in-order delivery. This function determines when a - * buffered CCS should be delivered to the state machine. - * - * Server states where CCS is expected: - * - TLS_ST_SR_KEY_EXCH: After key exchange (anonymous or no_cert_verify) - * - TLS_ST_SR_CERT_VRFY: After certificate verify - * - TLS_ST_SW_FINISHED: Session resumption (abbreviated handshake) - * - * Client states where CCS is expected: - * - TLS_ST_CR_SRVR_HELLO: Abbreviated handshake without ticket - * - TLS_ST_CW_FINISHED: After sending Finished, before server CCS - * - TLS_ST_CR_SESSION_TICKET: After receiving session ticket - */ -static int dtls_ccs_expected(SSL_CONNECTION *s) -{ - OSSL_HANDSHAKE_STATE st = s->statem.hand_state; - - if (s->server) { - switch (st) { - case TLS_ST_SR_KEY_EXCH: - /* Anonymous or no client cert: CCS follows KeyExchange */ - if (s->session->peer == NULL && s->session->peer_rpk == NULL) - return 1; - /* Client cert but no verify message required */ - return s->statem.no_cert_verify; - case TLS_ST_SR_CERT_VRFY: - return 1; - case TLS_ST_SW_FINISHED: - /* Abbreviated handshake: server sends first, then receives CCS */ - return s->hit; - default: - return 0; - } - } else { - switch (st) { - case TLS_ST_CR_SRVR_HELLO: - /* Abbreviated handshake without session ticket */ - return (s->hit && !s->ext.ticket_expected); - case TLS_ST_CW_FINISHED: - /* Full handshake: waiting for server CCS after sending Finished */ - return !s->ext.ticket_expected; - case TLS_ST_CR_SESSION_TICKET: - return 1; - default: - return 0; - } - } -} - static hm_fragment *dtls1_hm_fragment_new(size_t frag_len, int reassembly) { hm_fragment *frag = NULL; @@ -883,28 +830,6 @@ static int dtls_get_reassembled_message(SSL_CONNECTION *s, int *errtype, p = (unsigned char *)s->init_buf->data; redo: - /* Check for buffered CCS */ - if ((s->version == DTLS1_VERSION || s->version == DTLS1_2_VERSION - || s->version == DTLS1_BAD_VER) - && s->d1->has_change_cipher_spec && dtls_ccs_expected(s)) { - size_t extra = (s->version == DTLS1_BAD_VER) ? 2 : 0; - - s->d1->has_change_cipher_spec = 0; - p[0] = SSL3_MT_CCS; - /* - * The extra 2 bytes are never consumed, only checked for - * length -- zero-fill to avoid old init_buf content. - */ - if (extra > 0) - memset(p + 1, 0, extra); - s->init_num = extra; - s->init_msg = p + 1; - s->s3.tmp.message_type = SSL3_MT_CHANGE_CIPHER_SPEC; - s->s3.tmp.message_size = extra; - *len = extra; - return 1; - } - /* see if we have the required fragment already */ ret = dtls1_retrieve_buffered_fragment(s, &frag_len); if (ret < 0) { @@ -932,22 +857,12 @@ redo: goto f_err; } - /* Buffer CCS for reorder tolerance */ - if (s->version == DTLS1_VERSION || s->version == DTLS1_2_VERSION - || s->version == DTLS1_BAD_VER) { - size_t expected = (s->version == DTLS1_BAD_VER) ? 3 : 1; - - if (readbytes != expected) { - SSLfatal(s, SSL_AD_DECODE_ERROR, - SSL_R_BAD_CHANGE_CIPHER_SPEC); - goto f_err; - } - s->d1->has_change_cipher_spec = 1; - goto redo; - } - SSLfatal(s, SSL_AD_UNEXPECTED_MESSAGE, - SSL_R_BAD_CHANGE_CIPHER_SPEC); - goto f_err; + s->init_num = readbytes - 1; + s->init_msg = s->init_buf->data + 1; + s->s3.tmp.message_type = SSL3_MT_CHANGE_CIPHER_SPEC; + s->s3.tmp.message_size = readbytes - 1; + *len = readbytes - 1; + return 1; } /* Handshake fails if message header is incomplete */ @@ -1262,11 +1177,7 @@ int dtls1_buffer_message(SSL_CONNECTION *s, int is_ccs) return 0; } - if (pqueue_insert(s->d1->sent_messages, item) == NULL) { - dtls1_hm_fragment_free(frag); - pitem_free(item); - return 0; - } + pqueue_insert(s->d1->sent_messages, item); return 1; } diff --git a/ssl/statem/statem_lib.c b/ssl/statem/statem_lib.c index 465d2eff33..0a3ddebf36 100644 --- a/ssl/statem/statem_lib.c +++ b/ssl/statem/statem_lib.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -16,7 +16,6 @@ #include "internal/cryptlib.h" #include "internal/ssl_unwrap.h" #include -#include #include #include #include @@ -323,7 +322,6 @@ CON_FUNC_RETURN tls_construct_cert_verify(SSL_CONNECTION *s, WPACKET *pkt) unsigned char tls13tbs[TLS13_TBS_PREAMBLE_SIZE + EVP_MAX_MD_SIZE]; const SIGALG_LOOKUP *lu = s->s3.tmp.sigalg; SSL_CTX *sctx = SSL_CONNECTION_GET_CTX(s); - OSSL_PARAM params[3], *p = params; if (lu == NULL || s->s3.tmp.cert == NULL) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); @@ -353,19 +351,10 @@ CON_FUNC_RETURN tls_construct_cert_verify(SSL_CONNECTION *s, WPACKET *pkt) goto err; } - /* - * To avoid problems with older RSA providers we must also pass the digest - * name when passing any other parameters. - */ - *p++ = OSSL_PARAM_construct_int(OSSL_SIGNATURE_PARAM_TLS_VERSION, &s->version); - if (md != NULL) - *p++ = OSSL_PARAM_construct_utf8_string(OSSL_SIGNATURE_PARAM_DIGEST, - (char *)EVP_MD_get0_name(md), 0); - *p = OSSL_PARAM_construct_end(); - if (EVP_DigestSignInit_ex(mctx, &pctx, md == NULL ? NULL : EVP_MD_get0_name(md), - sctx->libctx, sctx->propq, pkey, params) + sctx->libctx, sctx->propq, pkey, + NULL) <= 0) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB); goto err; @@ -380,20 +369,42 @@ CON_FUNC_RETURN tls_construct_cert_verify(SSL_CONNECTION *s, WPACKET *pkt) goto err; } } + if (s->version == SSL3_VERSION) { + /* + * Here we use EVP_DigestSignUpdate followed by EVP_DigestSignFinal + * in order to add the EVP_CTRL_SSL3_MASTER_SECRET call between them. + */ + if (EVP_DigestSignUpdate(mctx, hdata, hdatalen) <= 0 + || EVP_MD_CTX_ctrl(mctx, EVP_CTRL_SSL3_MASTER_SECRET, + (int)s->session->master_key_length, + s->session->master_key) + <= 0 + || EVP_DigestSignFinal(mctx, NULL, &siglen) <= 0) { - /* - * Here we *must* use EVP_DigestSign() because Ed25519/Ed448 does not - * support streaming via EVP_DigestSignUpdate/EVP_DigestSignFinal - */ - if (EVP_DigestSign(mctx, NULL, &siglen, hdata, hdatalen) <= 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB); - goto err; - } - sig = OPENSSL_malloc(siglen); - if (sig == NULL - || EVP_DigestSign(mctx, sig, &siglen, hdata, hdatalen) <= 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB); - goto err; + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB); + goto err; + } + sig = OPENSSL_malloc(siglen); + if (sig == NULL + || EVP_DigestSignFinal(mctx, sig, &siglen) <= 0) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB); + goto err; + } + } else { + /* + * Here we *must* use EVP_DigestSign() because Ed25519/Ed448 does not + * support streaming via EVP_DigestSignUpdate/EVP_DigestSignFinal + */ + if (EVP_DigestSign(mctx, NULL, &siglen, hdata, hdatalen) <= 0) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB); + goto err; + } + sig = OPENSSL_malloc(siglen); + if (sig == NULL + || EVP_DigestSign(mctx, sig, &siglen, hdata, hdatalen) <= 0) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB); + goto err; + } } #ifndef OPENSSL_NO_GOST @@ -444,7 +455,6 @@ MSG_PROCESS_RETURN tls_process_cert_verify(SSL_CONNECTION *s, PACKET *pkt) EVP_MD_CTX *mctx = EVP_MD_CTX_new(); EVP_PKEY_CTX *pctx = NULL; SSL_CTX *sctx = SSL_CONNECTION_GET_CTX(s); - OSSL_PARAM params[3], *p = params; if (mctx == NULL) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB); @@ -526,19 +536,10 @@ MSG_PROCESS_RETURN tls_process_cert_verify(SSL_CONNECTION *s, PACKET *pkt) OSSL_TRACE1(TLS, "Using client verify alg %s\n", md == NULL ? "n/a" : EVP_MD_get0_name(md)); - /* - * To avoid problems with older RSA providers we must also pass the digest - * name when passing any other parameters. - */ - *p++ = OSSL_PARAM_construct_int(OSSL_SIGNATURE_PARAM_TLS_VERSION, &s->version); - if (md != NULL) - *p++ = OSSL_PARAM_construct_utf8_string(OSSL_SIGNATURE_PARAM_DIGEST, - (char *)EVP_MD_get0_name(md), 0); - *p = OSSL_PARAM_construct_end(); - if (EVP_DigestVerifyInit_ex(mctx, &pctx, md == NULL ? NULL : EVP_MD_get0_name(md), - sctx->libctx, sctx->propq, pkey, params) + sctx->libctx, sctx->propq, pkey, + NULL) <= 0) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB); goto err; @@ -566,16 +567,30 @@ MSG_PROCESS_RETURN tls_process_cert_verify(SSL_CONNECTION *s, PACKET *pkt) goto err; } } - - j = EVP_DigestVerify(mctx, data, len, hdata, hdatalen); + if (s->version == SSL3_VERSION) { + if (EVP_DigestVerifyUpdate(mctx, hdata, hdatalen) <= 0 + || EVP_MD_CTX_ctrl(mctx, EVP_CTRL_SSL3_MASTER_SECRET, + (int)s->session->master_key_length, + s->session->master_key) + <= 0) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB); + goto err; + } + if (EVP_DigestVerifyFinal(mctx, data, len) <= 0) { + SSLfatal(s, SSL_AD_DECRYPT_ERROR, SSL_R_BAD_SIGNATURE); + goto err; + } + } else { + j = EVP_DigestVerify(mctx, data, len, hdata, hdatalen); #ifdef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION - /* Ignore bad signatures when fuzzing */ - if (SSL_IS_QUIC_HANDSHAKE(s)) - j = 1; + /* Ignore bad signatures when fuzzing */ + if (SSL_IS_QUIC_HANDSHAKE(s)) + j = 1; #endif - if (j <= 0) { - SSLfatal(s, SSL_AD_DECRYPT_ERROR, SSL_R_BAD_SIGNATURE); - goto err; + if (j <= 0) { + SSLfatal(s, SSL_AD_DECRYPT_ERROR, SSL_R_BAD_SIGNATURE); + goto err; + } } /* @@ -1056,7 +1071,7 @@ static int ssl_add_cert_chain(SSL_CONNECTION *s, WPACKET *pkt, CERT_PKEY *cpk, i /* Don't leave errors in the queue */ ERR_clear_error(); chain = X509_STORE_CTX_get0_chain(xs_ctx); - i = ssl_security_cert_chain(s, chain, NULL); + i = ssl_security_cert_chain(s, chain, NULL, 0); if (i != 1) { #if 0 /* Dummy error calls so mkerr generates them */ @@ -1081,7 +1096,7 @@ static int ssl_add_cert_chain(SSL_CONNECTION *s, WPACKET *pkt, CERT_PKEY *cpk, i } X509_STORE_CTX_free(xs_ctx); } else { - i = ssl_security_cert_chain(s, extra_certs, x); + i = ssl_security_cert_chain(s, extra_certs, x, 0); if (i != 1) { if (!for_comp) SSLfatal(s, SSL_AD_INTERNAL_ERROR, i); @@ -1313,7 +1328,7 @@ unsigned long tls_output_rpk(SSL_CONNECTION *sc, WPACKET *pkt, CERT_PKEY *cpk) { int pdata_len = 0; unsigned char *pdata = NULL; - const X509_PUBKEY *xpk = NULL; + X509_PUBKEY *xpk = NULL; unsigned long ret = 0; X509 *x509 = NULL; @@ -1535,23 +1550,6 @@ WORK_STATE tls_finish_handshake(SSL_CONNECTION *s, ossl_unused WORK_STATE wst, return WORK_FINISHED_STOP; } -/* - * TLS 1.3 reserves handshake message type 0, so a HelloRequest must reach the - * state machine and be rejected there whenever TLS 1.3 is still possible. - * - * By the time a client reads a server handshake message, s->version is either - * the configured maximum for an initial pre-ServerHello handshake, or the - * already negotiated version after ServerHello or during renegotiation. Skip - * only when that version is below TLS 1.3. - */ -static int should_skip_hello_request(const SSL_CONNECTION *s) -{ - if (SSL_CONNECTION_IS_TLS13(s)) - return 0; - - return s->version > 0 && s->version < TLS1_3_VERSION; -} - int tls_get_message_header(SSL_CONNECTION *s, int *mt) { /* s->init_num < SSL3_HM_HEADER_LENGTH */ @@ -1611,8 +1609,7 @@ int tls_get_message_header(SSL_CONNECTION *s, int *mt) skip_message = 0; if (!s->server) if (s->statem.hand_state != TLS_ST_OK - && p[0] == SSL3_MT_HELLO_REQUEST - && should_skip_hello_request(s)) + && p[0] == SSL3_MT_HELLO_REQUEST) /* * The server may always send 'Hello Request' messages -- * we are doing a handshake anyway now, so ignore them if @@ -1634,39 +1631,39 @@ int tls_get_message_header(SSL_CONNECTION *s, int *mt) *mt = *p; s->s3.tmp.message_type = *(p++); - n2l3(p, l); - /* BUF_MEM_grow takes an 'int' parameter */ - if (l > (INT_MAX - SSL3_HM_HEADER_LENGTH)) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_EXCESSIVE_MESSAGE_SIZE); - return 0; + if (RECORD_LAYER_is_sslv2_record(&s->rlayer)) { + /* + * Only happens with SSLv3+ in an SSLv2 backward compatible + * ClientHello + * + * Total message size is the remaining record bytes to read + * plus the SSL3_HM_HEADER_LENGTH bytes that we already read + */ + l = s->rlayer.tlsrecs[0].length + SSL3_HM_HEADER_LENGTH; + s->s3.tmp.message_size = l; + + s->init_msg = s->init_buf->data; + s->init_num = SSL3_HM_HEADER_LENGTH; + } else { + n2l3(p, l); + /* BUF_MEM_grow takes an 'int' parameter */ + if (l > (INT_MAX - SSL3_HM_HEADER_LENGTH)) { + SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, + SSL_R_EXCESSIVE_MESSAGE_SIZE); + return 0; + } + s->s3.tmp.message_size = l; + + s->init_msg = s->init_buf->data + SSL3_HM_HEADER_LENGTH; + s->init_num = 0; } - s->s3.tmp.message_size = l; - - s->init_msg = s->init_buf->data + SSL3_HM_HEADER_LENGTH; - s->init_num = 0; - - return 1; -} - -static int grow_init_buf(SSL_CONNECTION *s, size_t size) -{ - - size_t msg_offset = (char *)s->init_msg - s->init_buf->data; - - if (!BUF_MEM_grow_clean(s->init_buf, size)) - return 0; - - if (size < msg_offset) - return 0; - - s->init_msg = s->init_buf->data + msg_offset; return 1; } int tls_get_message_body(SSL_CONNECTION *s, size_t *len) { - size_t toread, readbytes; + size_t n, readbytes; unsigned char *p; int i; SSL *ssl = SSL_CONNECTION_GET_SSL(s); @@ -1678,30 +1675,18 @@ int tls_get_message_body(SSL_CONNECTION *s, size_t *len) return 1; } - toread = s->s3.tmp.message_size - s->init_num; - while (toread > 0) { - size_t chunk = toread > SSL3_RT_MAX_PLAIN_LENGTH ? SSL3_RT_MAX_PLAIN_LENGTH : toread; - - /* - * We incrementally allocate the buffer to guard against the peer - * claiming a very large message size and then not sending it. - */ - if (!grow_init_buf(s, s->init_num + chunk + SSL3_HM_HEADER_LENGTH)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_BUF_LIB); - return 0; - } - - /* init_msg location can change after grow_init_buf */ - p = s->init_msg; + p = s->init_msg; + n = s->s3.tmp.message_size - s->init_num; + while (n > 0) { i = ssl->method->ssl_read_bytes(ssl, SSL3_RT_HANDSHAKE, NULL, - &p[s->init_num], chunk, 0, &readbytes); + &p[s->init_num], n, 0, &readbytes); if (i <= 0) { s->rwstate = SSL_READING; *len = 0; return 0; } s->init_num += readbytes; - toread -= readbytes; + n -= readbytes; } /* @@ -1714,35 +1699,48 @@ int tls_get_message_body(SSL_CONNECTION *s, size_t *len) return 0; } - /* - * We defer feeding in the HRR until later. We'll do it as part of - * processing the message - * The TLsv1.3 handshake transcript stops at the ClientFinished - * message. - */ + /* Feed this message into MAC computation. */ + if (RECORD_LAYER_is_sslv2_record(&s->rlayer)) { + if (!ssl3_finish_mac(s, (unsigned char *)s->init_buf->data, + s->init_num)) { + /* SSLfatal() already called */ + *len = 0; + return 0; + } + if (s->msg_callback) + s->msg_callback(0, SSL2_VERSION, 0, s->init_buf->data, + (size_t)s->init_num, ussl, s->msg_callback_arg); + } else { + /* + * We defer feeding in the HRR until later. We'll do it as part of + * processing the message + * The TLsv1.3 handshake transcript stops at the ClientFinished + * message. + */ #define SERVER_HELLO_RANDOM_OFFSET (SSL3_HM_HEADER_LENGTH + 2) - /* KeyUpdate and NewSessionTicket do not need to be added */ - if (!SSL_CONNECTION_IS_TLS13(s) - || (s->s3.tmp.message_type != SSL3_MT_NEWSESSION_TICKET - && s->s3.tmp.message_type != SSL3_MT_KEY_UPDATE)) { - if (s->s3.tmp.message_type != SSL3_MT_SERVER_HELLO - || s->init_num < SERVER_HELLO_RANDOM_OFFSET + SSL3_RANDOM_SIZE - || memcmp(hrrrandom, - s->init_buf->data + SERVER_HELLO_RANDOM_OFFSET, - SSL3_RANDOM_SIZE) - != 0) { - if (!ssl3_finish_mac(s, (unsigned char *)s->init_buf->data, - s->init_num + SSL3_HM_HEADER_LENGTH)) { - /* SSLfatal() already called */ - *len = 0; - return 0; + /* KeyUpdate and NewSessionTicket do not need to be added */ + if (!SSL_CONNECTION_IS_TLS13(s) + || (s->s3.tmp.message_type != SSL3_MT_NEWSESSION_TICKET + && s->s3.tmp.message_type != SSL3_MT_KEY_UPDATE)) { + if (s->s3.tmp.message_type != SSL3_MT_SERVER_HELLO + || s->init_num < SERVER_HELLO_RANDOM_OFFSET + SSL3_RANDOM_SIZE + || memcmp(hrrrandom, + s->init_buf->data + SERVER_HELLO_RANDOM_OFFSET, + SSL3_RANDOM_SIZE) + != 0) { + if (!ssl3_finish_mac(s, (unsigned char *)s->init_buf->data, + s->init_num + SSL3_HM_HEADER_LENGTH)) { + /* SSLfatal() already called */ + *len = 0; + return 0; + } } } + if (s->msg_callback) + s->msg_callback(0, s->version, SSL3_RT_HANDSHAKE, s->init_buf->data, + (size_t)s->init_num + SSL3_HM_HEADER_LENGTH, ussl, + s->msg_callback_arg); } - if (s->msg_callback) - s->msg_callback(0, s->version, SSL3_RT_HANDSHAKE, s->init_buf->data, - (size_t)s->init_num + SSL3_HM_HEADER_LENGTH, ussl, - s->msg_callback_arg); *len = s->init_num; return 1; @@ -1861,6 +1859,11 @@ static const version_info tls_version_table[] = { { TLS1_VERSION, tlsv1_client_method, tlsv1_server_method }, #else { TLS1_VERSION, NULL, NULL }, +#endif +#ifndef OPENSSL_NO_SSL3 + { SSL3_VERSION, sslv3_client_method, sslv3_server_method }, +#else + { SSL3_VERSION, NULL, NULL }, #endif { 0, NULL, NULL }, }; @@ -2083,7 +2086,7 @@ int ssl_set_version_bound(int method_version, int version, int *bound) return 1; } - valid_tls = version > SSL3_VERSION && version <= TLS_MAX_VERSION_INTERNAL; + valid_tls = version >= SSL3_VERSION && version <= TLS_MAX_VERSION_INTERNAL; valid_dtls = /* We support client side pre-standardisation version of DTLS */ (version == DTLS1_BAD_VER) @@ -2206,18 +2209,6 @@ int ssl_choose_server_version(SSL_CONNECTION *s, CLIENTHELLO_MSG *hello, suppversions = &hello->pre_proc_exts[TLSEXT_IDX_supported_versions]; -#ifndef OPENSSL_NO_ECH - /* - * Check we're dealing with a TLSv1.3 connection when ECH has - * succeeded, and not with a smuggled earlier version ClientHello - * (which could be a form of attack). - * This bit checks there is a supported version present, a little - * bit further below, we check that that version is TLSv1.3 - */ - if (!suppversions->present && s->ext.ech.success == 1) - return SSL_R_UNSUPPORTED_PROTOCOL; -#endif - /* If we did an HRR then supported versions is mandatory */ if (!suppversions->present && s->hello_retry_request != SSL_HRR_NONE) return SSL_R_UNSUPPORTED_PROTOCOL; @@ -2259,11 +2250,6 @@ int ssl_choose_server_version(SSL_CONNECTION *s, CLIENTHELLO_MSG *hello, } if (best_vers > 0) { -#ifndef OPENSSL_NO_ECH - /* ECH needs TLSV1.3 also */ - if (s->ext.ech.success == 1 && best_vers != TLS1_3_VERSION) - return SSL_R_UNSUPPORTED_PROTOCOL; -#endif if (s->hello_retry_request != SSL_HRR_NONE) { /* * This is after a HelloRetryRequest so we better check that we @@ -2932,12 +2918,6 @@ MSG_PROCESS_RETURN tls13_process_compressed_certificate(SSL_CONNECTION *sc, goto err; } - /* Prevent excessive pre-decompression allocation */ - if (expected_length > sc->max_cert_list) { - SSLfatal(sc, SSL_AD_BAD_CERTIFICATE, SSL_R_EXCESSIVE_MESSAGE_SIZE); - goto err; - } - if (PACKET_remaining(pkt) != comp_length || comp_length == 0) { SSLfatal(sc, SSL_AD_DECODE_ERROR, SSL_R_BAD_DECOMPRESSION); goto err; diff --git a/ssl/statem/statem_local.h b/ssl/statem/statem_local.h index de9ff299be..0ec4351cfd 100644 --- a/ssl/statem/statem_local.h +++ b/ssl/statem/statem_local.h @@ -1,5 +1,5 @@ /* - * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -14,18 +14,9 @@ * * *****************************************************************************/ -#if !defined(OSSL_SSL_STATEM_STATEM_LOCAL_H) -#define OSSL_SSL_STATEM_STATEM_LOCAL_H - -#include -#include - -#include "../ssl_local.h" - /* Max message length definitions */ /* The spec allows for a longer length than this, but we limit it */ - #define HELLO_VERIFY_REQUEST_MAX_LENGTH 258 #define END_OF_EARLY_DATA_MAX_LENGTH 0 #define HELLO_RETRY_REQUEST_MAX_LENGTH 20000 @@ -52,9 +43,6 @@ /* Invalid extension ID for non-supported extensions */ #define TLSEXT_TYPE_invalid 0x10000 #define TLSEXT_TYPE_out_of_range 0x10001 -/* RFC 8701 GREASE extension placeholders (actual type is dynamic) */ -#define TLSEXT_TYPE_grease1 0x10002 -#define TLSEXT_TYPE_grease2 0x10003 unsigned int ossl_get_extension_type(size_t idx); extern const unsigned char hrrrandom[]; @@ -269,8 +257,6 @@ __owur int tls_validate_all_contexts(SSL_CONNECTION *s, unsigned int thisctx, RAW_EXTENSION *exts); __owur int extension_is_relevant(SSL_CONNECTION *s, unsigned int extctx, unsigned int thisctx); -__owur int tls_validate_no_unknown_extensions(SSL_CONNECTION *s, - PACKET *packet, unsigned int context); __owur int tls_collect_extensions(SSL_CONNECTION *s, PACKET *packet, unsigned int context, RAW_EXTENSION **res, size_t *len, int init); @@ -308,6 +294,9 @@ int tls_parse_ctos_srp(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, int tls_parse_ctos_early_data(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, X509 *x, size_t chainidx); +int tls_parse_ctos_ec_pt_formats(SSL_CONNECTION *s, PACKET *pkt, + unsigned int context, + X509 *x, size_t chainidx); int tls_parse_ctos_supported_groups(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, X509 *x, size_t chainidxl); @@ -489,12 +478,6 @@ EXT_RETURN tls_construct_ctos_psk_kex_modes(SSL_CONNECTION *s, WPACKET *pkt, EXT_RETURN tls_construct_ctos_cookie(SSL_CONNECTION *s, WPACKET *pkt, unsigned int context, X509 *x, size_t chainidx); -EXT_RETURN tls_construct_ctos_grease1(SSL_CONNECTION *s, WPACKET *pkt, - unsigned int context, X509 *x, - size_t chainidx); -EXT_RETURN tls_construct_ctos_grease2(SSL_CONNECTION *s, WPACKET *pkt, - unsigned int context, X509 *x, - size_t chainidx); EXT_RETURN tls_construct_ctos_padding(SSL_CONNECTION *s, WPACKET *pkt, unsigned int context, X509 *x, size_t chainidx); @@ -517,6 +500,9 @@ int tls_parse_stoc_early_data(SSL_CONNECTION *s, PACKET *pkt, int tls_parse_stoc_maxfragmentlen(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, X509 *x, size_t chainidx); +int tls_parse_stoc_ec_pt_formats(SSL_CONNECTION *s, PACKET *pkt, + unsigned int context, + X509 *x, size_t chainidx); int tls_parse_stoc_session_ticket(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, X509 *x, size_t chainidx); @@ -584,17 +570,3 @@ int tls_parse_ctos_server_cert_type(SSL_CONNECTION *sc, PACKET *pkt, int tls_parse_stoc_server_cert_type(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, X509 *x, size_t chainidx); -#ifndef OPENSSL_NO_ECH -EXT_RETURN tls_construct_ctos_ech(SSL_CONNECTION *s, WPACKET *pkt, - unsigned int context, X509 *x, - size_t chainidx); -int tls_parse_ctos_ech(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, - X509 *x, size_t chainidx); -EXT_RETURN tls_construct_stoc_ech(SSL_CONNECTION *s, WPACKET *pkt, - unsigned int context, X509 *x, - size_t chainidx); -int tls_parse_stoc_ech(SSL_CONNECTION *s, PACKET *pkt, unsigned int context, - X509 *x, size_t chainidx); -#endif - -#endif /* !defined(OSSL_SSL_STATEM_STATEM_LOCAL_H) */ diff --git a/ssl/statem/statem_srvr.c b/ssl/statem/statem_srvr.c index fc3769a017..7bf37b0689 100644 --- a/ssl/statem/statem_srvr.c +++ b/ssl/statem/statem_srvr.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * Copyright 2005 Nokia. All rights reserved. * @@ -36,10 +36,6 @@ #define TICKET_NONCE_SIZE 8 -#ifndef OPENSSL_NO_ECH -#include "../ech/ech_local.h" -#endif - typedef struct { ASN1_TYPE *kxBlob; ASN1_TYPE *opaqueBlob; @@ -215,10 +211,30 @@ int ossl_statem_server_read_transition(SSL_CONNECTION *s, int mt) * If we get a CKE message after a ServerDone then either * 1) We didn't request a Certificate * OR - * 2) We did request one and we allow no Certificate to be returned + * 2) If we did request one then + * a) We allow no Certificate to be returned + * AND + * b) We are running SSL3 (in TLS1.0+ the client must return a 0 + * list if we requested a certificate) */ if (mt == SSL3_MT_CLIENT_KEY_EXCHANGE) { - if (!s->s3.tmp.cert_request) { + if (s->s3.tmp.cert_request) { + if (s->version == SSL3_VERSION) { + if ((s->verify_mode & SSL_VERIFY_PEER) + && (s->verify_mode & SSL_VERIFY_FAIL_IF_NO_PEER_CERT)) { + /* + * This isn't an unexpected message as such - we're just + * not going to accept it because we require a client + * cert. + */ + SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE, + SSL_R_PEER_DID_NOT_RETURN_A_CERTIFICATE); + return 0; + } + st->hand_state = TLS_ST_SR_KEY_EXCH; + return 1; + } + } else { st->hand_state = TLS_ST_SR_KEY_EXCH; return 1; } @@ -309,6 +325,20 @@ int ossl_statem_server_read_transition(SSL_CONNECTION *s, int mt) err: /* No valid transition found */ + if (SSL_CONNECTION_IS_DTLS(s) && mt == SSL3_MT_CHANGE_CIPHER_SPEC) { + BIO *rbio; + + /* + * CCS messages don't have a message sequence number so this is probably + * because of an out-of-order CCS. We'll just drop it. + */ + s->init_num = 0; + s->rwstate = SSL_READING; + rbio = SSL_get_rbio(SSL_CONNECTION_GET_SSL(s)); + BIO_clear_retry_flags(rbio); + BIO_set_retry_read(rbio); + return 0; + } SSLfatal(s, SSL3_AD_UNEXPECTED_MESSAGE, SSL_R_UNEXPECTED_MESSAGE); return 0; } @@ -494,8 +524,8 @@ OCSP_RESPONSE *ossl_get_ocsp_response(SSL_CONNECTION *s, int chainidx) * happening because of test cases. */ ERR_set_mark(); - bs = OCSP_response_get1_basic(resp); - if (bs != NULL && (sr = OCSP_resp_get0(bs, 0)) != NULL) { + if (((bs = OCSP_response_get1_basic(resp)) != NULL) + && ((sr = OCSP_resp_get0(bs, 0)) != NULL)) { /* use the first single response to get the algorithm used */ cid = (OCSP_CERTID *)OCSP_SINGLERESP_get0_id(sr); @@ -551,8 +581,6 @@ OCSP_RESPONSE *ossl_get_ocsp_response(SSL_CONNECTION *s, int chainidx) */ if (i == num) resp = NULL; - } else { - OCSP_BASICRESP_free(bs); } /* @@ -688,44 +716,10 @@ static WRITE_TRAN ossl_statem_server13_write_transition(SSL_CONNECTION *s) st->hand_state = TLS_ST_OK; return WRITE_TRAN_CONTINUE; } - /* - * Do not issue TLS 1.3 session tickets if the server has explicitly - * disabled them via SSL_OP_NO_TICKET and also disabled the session - * cache with SSL_SESS_CACHE_OFF. Together, these settings clearly - * indicate an intent to suppress session resumption; sending - * NewSessionTicket messages in this case would be wasteful and - * misleading. - * - * From the server’s perspective, a client that does not advertise - * psk_key_exchange_modes in TLS 1.3, or that sends it with RFC 9149 - * parameters such as new_session_count = 0 or resumption_count = 0, is - * effectively signaling no interest in session tickets or resumption. - * - * RFC 8446 section 4.2.9: Servers MUST NOT select a key exchange mode - * that is not listed by the client. This extension also restricts the - * modes for use with PSK resumption. Servers SHOULD NOT send - * NewSessionTicket with tickets that are not compatible with the - * advertised modes; however, if a server does so, the impact will just - * be that the client's attempts at resumption fail. - * - * Note: Although RFC 9149 allows clients to signal no interest in - * session tickets or resumption (e.g. new_session_count = 0 or - * resumption_count = 0), this implementation does not currently - * interpret or enforce those parameters. - * - * Also skip issuance when SSL_VERIFY_PEER is set with no sid_ctx - * configured: any ticket minted here would be rejected by - * ssl_get_prev_session() in that configuration. - */ - if (s->num_tickets <= s->sent_tickets - || ((s->options & SSL_OP_NO_TICKET) != 0 - && (SSL_CONNECTION_GET_CTX(s)->session_cache_mode & SSL_SESS_CACHE_SERVER) - == 0) - || s->ext.psk_kex_mode == TLSEXT_KEX_MODE_FLAG_NONE - || ((s->verify_mode & SSL_VERIFY_PEER) != 0 && s->sid_ctx_length == 0)) - st->hand_state = TLS_ST_OK; - else + if (s->num_tickets > s->sent_tickets) st->hand_state = TLS_ST_SW_SESSION_TICKET; + else + st->hand_state = TLS_ST_OK; return WRITE_TRAN_CONTINUE; case TLS_ST_SR_KEY_UPDATE: @@ -1241,7 +1235,6 @@ WORK_STATE ossl_statem_server_post_work(SSL_CONNECTION *s, WORK_STATE wst) return WORK_MORE_A; } - ERR_clear_last_mark(); break; } @@ -1654,110 +1647,9 @@ MSG_PROCESS_RETURN tls_process_client_hello(SSL_CONNECTION *s, PACKET *pkt) { /* |cookie| will only be initialized for DTLS. */ PACKET session_id, compression, extensions, cookie; + static const unsigned char null_compression = 0; CLIENTHELLO_MSG *clienthello = NULL; -#ifndef OPENSSL_NO_ECH - /* - * For a split-mode backend we want to have a way to point at the CH octets - * for the accept-confirmation calculation. The split-mode backend does not - * need any ECH secrets, but it does need to see the inner CH and be the TLS - * endpoint with which the ECH encrypting client sets up the TLS session. - * The split-mode backend however does need to do an ECH confirm calculation - * so we need to tee that up. The result of that calculation will be put in - * the ServerHello.random (or ECH extension if HRR) to signal to the client - * that ECH "worked." - */ - if (s->server && PACKET_remaining(pkt) != 0) { - int rv = 0, innerflag = OSSL_ECH_UNKNOWN_CH_TYPE; - size_t startofsessid = 0, startofexts = 0, echoffset = 0; - size_t outersnioffset = 0; /* offset to SNI in outer */ - uint16_t echtype = OSSL_ECH_type_unknown; /* type of ECH seen */ - const unsigned char *pbuf = NULL; - - /* reset needed in case of HRR */ - s->ext.ech.ch_offsets_done = 0; - rv = ossl_ech_get_ch_offsets(s, pkt, &startofsessid, &startofexts, - &echoffset, &echtype, &innerflag, - &outersnioffset); - if (rv != 1) { - /* SSLfatal already called */ - goto err; - } - if (innerflag == OSSL_ECH_INNER_CH_TYPE) { - WPACKET inner; - - OSSL_TRACE(TLS, "Got inner ECH so setting backend\n"); - /* For backend, include msg type & 3 octet length */ - s->ext.ech.backend = 1; - s->ext.ech.attempted_type = TLSEXT_TYPE_ech; - OPENSSL_free(s->ext.ech.innerch); - s->ext.ech.innerch_len = PACKET_remaining(pkt); - if (PACKET_peek_bytes(pkt, &pbuf, s->ext.ech.innerch_len) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - s->ext.ech.innerch_len += SSL3_HM_HEADER_LENGTH; /* 4 */ - s->ext.ech.innerch = OPENSSL_malloc(s->ext.ech.innerch_len); - if (s->ext.ech.innerch == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - if (!WPACKET_init_static_len(&inner, s->ext.ech.innerch, - s->ext.ech.innerch_len, 0)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - if (!WPACKET_put_bytes_u8(&inner, SSL3_MT_CLIENT_HELLO) - || !WPACKET_put_bytes_u24(&inner, s->ext.ech.innerch_len - SSL3_HM_HEADER_LENGTH) - || !WPACKET_memcpy(&inner, pbuf, s->ext.ech.innerch_len - SSL3_HM_HEADER_LENGTH) - || !WPACKET_finish(&inner)) { - WPACKET_cleanup(&inner); - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - if (ossl_ech_intbuf_add(s, s->ext.ech.innerch, - s->ext.ech.innerch_len, 0) - != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - } else if (s->ext.ech.es != NULL) { - PACKET newpkt; - int secondtime = s->ext.ech.success; - - /* - * if ECH decrypt worked first time (success == 1) then fail - * if there's no ECH extension at all 2nd time - */ - if (secondtime == 1 && echoffset == 0) { - SSLfatal(s, SSL_AD_MISSING_EXTENSION, - SSL_R_TLSV13_ALERT_MISSING_EXTENSION); - goto err; - } - if (ossl_ech_early_decrypt(s, pkt, &newpkt) != 1) { - /* SSLfatal() already called */ - goto err; - } - if (s->ext.ech.success == 1) { - /* - * Replace the outer CH with the inner, as long as there's - * space, which there better be! (a bug triggered a bigger - * inner CH once;-) - */ - if (PACKET_remaining(&newpkt) > PACKET_remaining(pkt)) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - *pkt = newpkt; - } else if (secondtime == 1 && s->ext.ech.success == 0) { - /* 2nd time decrypt failed */ - SSLfatal(s, SSL_AD_DECRYPT_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - } - } -#endif - /* Check if this is actually an unexpected renegotiation ClientHello */ if (s->renegotiate == 0 && !SSL_IS_FIRST_HANDSHAKE(s)) { if (!ossl_assert(!SSL_CONNECTION_IS_TLS13(s))) { @@ -1785,65 +1677,156 @@ MSG_PROCESS_RETURN tls_process_client_hello(SSL_CONNECTION *s, PACKET *pkt) /* * First, parse the raw ClientHello data into the CLIENTHELLO_MSG structure. */ + clienthello->isv2 = RECORD_LAYER_is_sslv2_record(&s->rlayer); PACKET_null_init(&cookie); + if (clienthello->isv2) { + unsigned int mt; + + if (!SSL_IS_FIRST_HANDSHAKE(s) + || s->hello_retry_request != SSL_HRR_NONE) { + SSLfatal(s, SSL_AD_UNEXPECTED_MESSAGE, SSL_R_UNEXPECTED_MESSAGE); + goto err; + } + + /*- + * An SSLv3/TLSv1 backwards-compatible CLIENT-HELLO in an SSLv2 + * header is sent directly on the wire, not wrapped as a TLS + * record. Our record layer just processes the message length and passes + * the rest right through. Its format is: + * Byte Content + * 0-1 msg_length - decoded by the record layer + * 2 msg_type - s->init_msg points here + * 3-4 version + * 5-6 cipher_spec_length + * 7-8 session_id_length + * 9-10 challenge_length + * ... ... + */ + + if (!PACKET_get_1(pkt, &mt) + || mt != SSL2_MT_CLIENT_HELLO) { + /* + * Should never happen. We should have tested this in the record + * layer in order to have determined that this is an SSLv2 record + * in the first place + */ + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + goto err; + } + } + if (!PACKET_get_net_2(pkt, &clienthello->legacy_version)) { SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_TOO_SHORT); goto err; } - if (!PACKET_copy_bytes(pkt, clienthello->random, SSL3_RANDOM_SIZE) - || !PACKET_get_length_prefixed_1(pkt, &session_id) - || !PACKET_copy_all(&session_id, clienthello->session_id, - SSL_MAX_SSL_SESSION_ID_LENGTH, - &clienthello->session_id_len)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_MISMATCH); - goto err; - } + /* Parse the message and load client random. */ + if (clienthello->isv2) { + /* + * Handle an SSLv2 backwards compatible ClientHello + * Note, this is only for SSLv3+ using the backward compatible format. + * Real SSLv2 is not supported, and is rejected below. + */ + unsigned int ciphersuite_len, session_id_len, challenge_len; + PACKET challenge; - if (SSL_CONNECTION_IS_DTLS(s)) { - if (!PACKET_get_length_prefixed_1(pkt, &cookie)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_MISMATCH); + if (!PACKET_get_net_2(pkt, &ciphersuite_len) + || !PACKET_get_net_2(pkt, &session_id_len) + || !PACKET_get_net_2(pkt, &challenge_len)) { + SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_RECORD_LENGTH_MISMATCH); goto err; } - if (!PACKET_copy_all(&cookie, clienthello->dtls_cookie, - DTLS1_COOKIE_LENGTH, - &clienthello->dtls_cookie_len)) { + + if (session_id_len > SSL_MAX_SSL_SESSION_ID_LENGTH) { + SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, SSL_R_LENGTH_MISMATCH); + goto err; + } + + if (!PACKET_get_sub_packet(pkt, &clienthello->ciphersuites, + ciphersuite_len) + || !PACKET_copy_bytes(pkt, clienthello->session_id, session_id_len) + || !PACKET_get_sub_packet(pkt, &challenge, challenge_len) + /* No extensions. */ + || PACKET_remaining(pkt) != 0) { + SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_RECORD_LENGTH_MISMATCH); + goto err; + } + clienthello->session_id_len = session_id_len; + + /* Load the client random and compression list. We use SSL3_RANDOM_SIZE + * here rather than sizeof(clienthello->random) because that is the limit + * for SSLv3 and it is fixed. It won't change even if + * sizeof(clienthello->random) does. + */ + challenge_len = challenge_len > SSL3_RANDOM_SIZE + ? SSL3_RANDOM_SIZE + : challenge_len; + memset(clienthello->random, 0, SSL3_RANDOM_SIZE); + if (!PACKET_copy_bytes(&challenge, + clienthello->random + SSL3_RANDOM_SIZE - challenge_len, challenge_len) + /* Advertise only null compression. */ + || !PACKET_buf_init(&compression, &null_compression, 1)) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); goto err; } - /* - * If we require cookies and this ClientHello doesn't contain one, - * just return since we do not want to allocate any memory yet. - * So check cookie length... - */ - if (SSL_get_options(SSL_CONNECTION_GET_SSL(s)) & SSL_OP_COOKIE_EXCHANGE) { - if (clienthello->dtls_cookie_len == 0) { - OPENSSL_free(clienthello); - return MSG_PROCESS_FINISHED_READING; - } - } - } - if (!PACKET_get_length_prefixed_2(pkt, &clienthello->ciphersuites)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_MISMATCH); - goto err; - } - - if (!PACKET_get_length_prefixed_1(pkt, &compression)) { - SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_MISMATCH); - goto err; - } - - /* Could be empty. */ - if (PACKET_remaining(pkt) == 0) { PACKET_null_init(&clienthello->extensions); } else { - if (!PACKET_get_length_prefixed_2(pkt, &clienthello->extensions) - || PACKET_remaining(pkt) != 0) { + /* Regular ClientHello. */ + if (!PACKET_copy_bytes(pkt, clienthello->random, SSL3_RANDOM_SIZE) + || !PACKET_get_length_prefixed_1(pkt, &session_id) + || !PACKET_copy_all(&session_id, clienthello->session_id, + SSL_MAX_SSL_SESSION_ID_LENGTH, + &clienthello->session_id_len)) { SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_MISMATCH); goto err; } + + if (SSL_CONNECTION_IS_DTLS(s)) { + if (!PACKET_get_length_prefixed_1(pkt, &cookie)) { + SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_MISMATCH); + goto err; + } + if (!PACKET_copy_all(&cookie, clienthello->dtls_cookie, + sizeof(clienthello->dtls_cookie), + &clienthello->dtls_cookie_len)) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + goto err; + } + /* + * If we require cookies and this ClientHello doesn't contain one, + * just return since we do not want to allocate any memory yet. + * So check cookie length... + */ + if (SSL_get_options(SSL_CONNECTION_GET_SSL(s)) & SSL_OP_COOKIE_EXCHANGE) { + if (clienthello->dtls_cookie_len == 0) { + OPENSSL_free(clienthello); + return MSG_PROCESS_FINISHED_READING; + } + } + } + + if (!PACKET_get_length_prefixed_2(pkt, &clienthello->ciphersuites)) { + SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_MISMATCH); + goto err; + } + + if (!PACKET_get_length_prefixed_1(pkt, &compression)) { + SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_MISMATCH); + goto err; + } + + /* Could be empty. */ + if (PACKET_remaining(pkt) == 0) { + PACKET_null_init(&clienthello->extensions); + } else { + if (!PACKET_get_length_prefixed_2(pkt, &clienthello->extensions) + || PACKET_remaining(pkt) != 0) { + SSLfatal(s, SSL_AD_DECODE_ERROR, SSL_R_LENGTH_MISMATCH); + goto err; + } + } } if (!PACKET_copy_all(&compression, clienthello->compressions, @@ -1869,12 +1852,6 @@ err: if (clienthello != NULL) OPENSSL_free(clienthello->pre_proc_exts); OPENSSL_free(clienthello); -#ifndef OPENSSL_NO_ECH - s->clienthello = NULL; - OPENSSL_free(s->ext.ech.innerch); - s->ext.ech.innerch = NULL; - s->ext.ech.innerch_len = 0; -#endif return MSG_PROCESS_ERROR; } @@ -1917,14 +1894,26 @@ static int tls_early_post_process_client_hello(SSL_CONNECTION *s) /* Set up the client_random */ memcpy(s->s3.client_random, clienthello->random, SSL3_RANDOM_SIZE); + /* Choose the version */ + + if (clienthello->isv2) { + if (clienthello->legacy_version == SSL2_VERSION + || (clienthello->legacy_version & 0xff00) + != (SSL3_VERSION_MAJOR << 8)) { + /* + * This is real SSLv2 or something completely unknown. We don't + * support it. + */ + SSLfatal(s, SSL_AD_PROTOCOL_VERSION, SSL_R_UNKNOWN_PROTOCOL); + goto err; + } + /* SSLv3/TLS */ + s->client_version = clienthello->legacy_version; + } + /* Choose the server SSL/TLS/DTLS version. */ protverr = ssl_choose_server_version(s, clienthello, &dgrd); -#ifndef OPENSSL_NO_ECH - if (protverr && s->ext.ech.success == 1) { - SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, protverr); - } -#endif if (protverr) { if (SSL_IS_FIRST_HANDSHAKE(s)) { /* like ssl3_get_record, send alert using remote version number */ @@ -1967,8 +1956,10 @@ static int tls_early_post_process_client_hello(SSL_CONNECTION *s) s->hit = 0; - if (!ssl_cache_cipherlist(s, &clienthello->ciphersuites) - || !ossl_bytes_to_cipher_list(s, &clienthello->ciphersuites, &ciphers, &scsvs, 1)) { + if (!ssl_cache_cipherlist(s, &clienthello->ciphersuites, + clienthello->isv2) + || !ossl_bytes_to_cipher_list(s, &clienthello->ciphersuites, &ciphers, + &scsvs, clienthello->isv2, 1)) { /* SSLfatal() already called */ goto err; } @@ -2046,7 +2037,7 @@ static int tls_early_post_process_client_hello(SSL_CONNECTION *s) * SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION setting will be * ignored. */ - if (s->new_session && (s->options & SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION)) { + if (clienthello->isv2 || (s->new_session && (s->options & SSL_OP_NO_SESSION_RESUMPTION_ON_RENEGOTIATION))) { if (!ssl_get_new_session(s, 1)) { /* SSLfatal() already called */ goto err; @@ -2154,25 +2145,12 @@ static int tls_early_post_process_client_hello(SSL_CONNECTION *s) goto err; } - /* - * Unless ECH has worked or not been configured we won't call - * the session_secret_cb now because we'll need to calculate the - * server random later to include the ECH accept value. - * We can't do it now as we don't yet have the SH encoding. - */ - if ( -#ifndef OPENSSL_NO_ECH - ((s->ext.ech.es != NULL && s->ext.ech.success == 1) - || s->ext.ech.es == NULL) - && -#endif - !s->hit + if (!s->hit && s->version >= TLS1_VERSION && !SSL_CONNECTION_IS_TLS13(s) && !SSL_CONNECTION_IS_DTLS(s) && s->ext.session_secret_cb != NULL) { const SSL_CIPHER *pref_cipher = NULL; - /* * s->session->master_key_length is a size_t, but this is an int for * backwards compat reasons @@ -2190,19 +2168,6 @@ static int tls_early_post_process_client_hello(SSL_CONNECTION *s) s->peer_ciphers = ciphers; s->session->verify_result = X509_V_OK; - /* - * Per RFC 4851, Section 3.2.2: - * If the ClientHello contains both a Session ID and a PAC-Opaque in - * the SessionTicket extension, and the server resumes the session - * using the PAC-Opaque, it should echo the same Session ID in the - * ServerHello. - */ - if (clienthello->session_id_len > 0) { - memcpy(s->session->session_id, clienthello->session_id, - clienthello->session_id_len); - s->session->session_id_length = clienthello->session_id_len; - } - ciphers = NULL; /* check if some cipher was preferred by call back */ @@ -2342,8 +2307,7 @@ static int tls_early_post_process_client_hello(SSL_CONNECTION *s) err: sk_SSL_CIPHER_free(ciphers); sk_SSL_CIPHER_free(scsvs); - if (clienthello != NULL) - OPENSSL_free(clienthello->pre_proc_exts); + OPENSSL_free(clienthello->pre_proc_exts); OPENSSL_free(s->clienthello); s->clienthello = NULL; @@ -2553,6 +2517,18 @@ WORK_STATE tls_post_process_client_hello(SSL_CONNECTION *s, WORK_STATE wst) s->s3.tmp.new_cipher = s->session->cipher; } + /*- + * we now have the following setup. + * client_random + * cipher_list - our preferred list of ciphers + * ciphers - the client's preferred list of ciphers + * compression - basically ignored right now + * ssl version is set - sslv3 + * s->session - The ssl session has been setup. + * s->hit - session reuse flag + * s->s3.tmp.new_cipher - the new cipher to use. + */ + /* * Call status_request callback if needed. Has to be done after the * certificate callbacks etc above. @@ -2694,156 +2670,22 @@ CON_FUNC_RETURN tls_construct_server_hello(SSL_CONNECTION *s, WPACKET *pkt) * Re-initialise the Transcript Hash. We're going to prepopulate it with * a synthetic message_hash in place of ClientHello1. */ -#ifndef OPENSSL_NO_ECH - /* - * if we're sending 2nd SH after HRR and we did ECH - * then we want to inject the hash of the inner CH1 - * and not the outer (which is the default) - */ - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "Checking success (%d)/innerCH (%p)\n", - s->ext.ech.success, (void *)s->ext.ech.innerch); - } - OSSL_TRACE_END(TLS); - if ((s->ext.ech.backend == 1 || s->ext.ech.success == 1) - && s->ext.ech.innerch != NULL) { - /* do pre-existing HRR stuff */ - unsigned char hashval[EVP_MAX_MD_SIZE]; - unsigned int hashlen; - EVP_MD_CTX *ctx = EVP_MD_CTX_new(); - const EVP_MD *md = NULL; - - OSSL_TRACE(TLS, "Adding in digest of ClientHello\n"); -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("innerch", s->ext.ech.innerch, - s->ext.ech.innerch_len); -#endif - if (ctx == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return CON_FUNC_ERROR; - } - md = ssl_handshake_md(s); - if (md == NULL) { - EVP_MD_CTX_free(ctx); - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return CON_FUNC_ERROR; - } - if (EVP_DigestInit_ex(ctx, md, NULL) <= 0 - || EVP_DigestUpdate(ctx, s->ext.ech.innerch, - s->ext.ech.innerch_len) - <= 0 - || EVP_DigestFinal_ex(ctx, hashval, &hashlen) <= 0) { - EVP_MD_CTX_free(ctx); - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return CON_FUNC_ERROR; - } -#ifdef OSSL_ECH_SUPERVERBOSE - ossl_ech_pbuf("digested CH", hashval, hashlen); -#endif - EVP_MD_CTX_free(ctx); - if (ossl_ech_reset_hs_buffer(s, NULL, 0) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return CON_FUNC_ERROR; - } - if (!create_synthetic_message_hash(s, hashval, hashlen, NULL, 0)) { - /* SSLfatal() already called */ - return CON_FUNC_ERROR; - } - } else { - if (!create_synthetic_message_hash(s, NULL, 0, NULL, 0)) - return CON_FUNC_ERROR; /* SSLfatal() already called */ - } -#else - if (!create_synthetic_message_hash(s, NULL, 0, NULL, 0)) + if (!create_synthetic_message_hash(s, NULL, 0, NULL, 0)) { /* SSLfatal() already called */ return CON_FUNC_ERROR; -#endif /* OPENSSL_NO_ECH */ + } } else if (!(s->verify_mode & SSL_VERIFY_PEER) && !ssl3_digest_cached_records(s, 0)) { /* SSLfatal() already called */; return CON_FUNC_ERROR; } -#ifndef OPENSSL_NO_ECH - /* - * Calculate the ECH-accept server random to indicate that - * we're accepting ECH, if that's the case - */ - if (s->ext.ech.attempted_type == TLSEXT_TYPE_ech - && (s->ext.ech.backend == 1 - || (s->ext.ech.es != NULL && s->ext.ech.success == 1))) { - unsigned char acbuf[8]; - unsigned char *shbuf = NULL; - size_t shlen = 0; - size_t shoffset = 0; - int hrr = 0; - - if (s->hello_retry_request == SSL_HRR_PENDING) - hrr = 1; - memset(acbuf, 0, 8); - if (WPACKET_get_total_written(pkt, &shlen) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return CON_FUNC_ERROR; - } - shbuf = WPACKET_get_curr(pkt) - shlen; - /* we need to fixup SH length here */ - shbuf[1] = ((shlen - 4)) >> 16 & 0xff; - shbuf[2] = ((shlen - 4)) >> 8 & 0xff; - shbuf[3] = (shlen - 4) & 0xff; - if (ossl_ech_intbuf_add(s, shbuf, shlen, hrr) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return CON_FUNC_ERROR; - } - if (ossl_ech_calc_confirm(s, hrr, acbuf, shlen) != 1) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return CON_FUNC_ERROR; - } - memcpy(s->s3.server_random + SSL3_RANDOM_SIZE - 8, acbuf, 8); - if (hrr == 0) { - /* confirm value hacked into SH.random rightmost octets */ - shoffset = SSL3_HM_HEADER_LENGTH /* 4 */ - + CLIENT_VERSION_LEN /* 2 */ - + SSL3_RANDOM_SIZE /* 32 */ - - 8; - memcpy(shbuf + shoffset, acbuf, 8); - } else { - /* - * confirm value is in extension in HRR case as the SH.random - * is already hacked to be a specific value in a HRR - */ - memcpy(WPACKET_get_curr(pkt) - 8, acbuf, 8); - } - } - /* call ECH callback, if appropriate */ - if (s->ext.ech.attempted == 1 && s->ext.ech.cb != NULL - && s->hello_retry_request != SSL_HRR_PENDING) { - char pstr[OSSL_ECH_PBUF_SIZE + 1]; - BIO *biom = BIO_new(BIO_s_mem()); - unsigned int cbrv = 0; - - if (biom == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return CON_FUNC_ERROR; - } - memset(pstr, 0, OSSL_ECH_PBUF_SIZE + 1); - ossl_ech_status_print(biom, s, OSSL_ECHSTORE_ALL); - BIO_read(biom, pstr, OSSL_ECH_PBUF_SIZE); - cbrv = s->ext.ech.cb(&s->ssl, pstr); - BIO_free(biom); - if (cbrv != 1) { - OSSL_TRACE(TLS, "Error from tls_construct_server_hello/ech_cb\n"); - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - return CON_FUNC_ERROR; - } - } -#endif /* OPENSSL_NO_ECH */ return CON_FUNC_SUCCESS; } CON_FUNC_RETURN tls_construct_server_done(SSL_CONNECTION *s, WPACKET *pkt) { - if (s->s3.tmp.cert_request == 0) { + if (!s->s3.tmp.cert_request) { if (!ssl3_digest_cached_records(s, 0)) { /* SSLfatal() already called */ return CON_FUNC_ERROR; @@ -2858,7 +2700,7 @@ CON_FUNC_RETURN tls_construct_server_key_exchange(SSL_CONNECTION *s, EVP_PKEY *pkdh = NULL; unsigned char *encodedPoint = NULL; size_t encodedlen = 0; - int group_id = 0; + int curve_id = 0; const SIGALG_LOOKUP *lu = s->s3.tmp.sigalg; int i; unsigned long type; @@ -2892,64 +2734,49 @@ CON_FUNC_RETURN tls_construct_server_key_exchange(SSL_CONNECTION *s, CERT *cert = s->cert; EVP_PKEY *pkdhp = NULL; - /* Get NID of appropriate shared FFDHE group */ - group_id = tls1_shared_group(s, TLS1_GROUPS_RETURN_TMP_ID, - TLS1_GROUPS_FFDHE_GROUPS); - if (group_id != 0) { - /* Cache the group used in the SSL_SESSION */ - s->session->kex_group = group_id; - - s->s3.tmp.pkey = ssl_generate_pkey_group(s, group_id); - if (s->s3.tmp.pkey == NULL) { + if (s->cert->dh_tmp_auto) { + pkdh = ssl_get_auto_dh(s); + if (pkdh == NULL) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); goto err; } + pkdhp = pkdh; } else { - - if (s->cert->dh_tmp_auto) { - pkdh = ssl_get_auto_dh(s); - if (pkdh == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - pkdhp = pkdh; - } else { - pkdhp = cert->dh_tmp; - } -#if !defined(OPENSSL_NO_DEPRECATED_3_0) - if ((pkdhp == NULL) && (s->cert->dh_tmp_cb != NULL)) { - pkdh = ssl_dh_to_pkey( - s->cert->dh_tmp_cb(SSL_CONNECTION_GET_USER_SSL(s), 0, 1024)); - if (pkdh == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - pkdhp = pkdh; - } -#endif - if (pkdhp == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_MISSING_TMP_DH_KEY); - goto err; - } - if (!ssl_security(s, SSL_SECOP_TMP_DH, - EVP_PKEY_get_security_bits(pkdhp), 0, pkdhp)) { - SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE, SSL_R_DH_KEY_TOO_SMALL); - goto err; - } - if (s->s3.tmp.pkey != NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - - s->s3.tmp.pkey = ssl_generate_pkey(s, pkdhp); - if (s->s3.tmp.pkey == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - - EVP_PKEY_free(pkdh); - pkdh = NULL; + pkdhp = cert->dh_tmp; } +#if !defined(OPENSSL_NO_DEPRECATED_3_0) + if ((pkdhp == NULL) && (s->cert->dh_tmp_cb != NULL)) { + pkdh = ssl_dh_to_pkey(s->cert->dh_tmp_cb(SSL_CONNECTION_GET_USER_SSL(s), + 0, 1024)); + if (pkdh == NULL) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + goto err; + } + pkdhp = pkdh; + } +#endif + if (pkdhp == NULL) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_MISSING_TMP_DH_KEY); + goto err; + } + if (!ssl_security(s, SSL_SECOP_TMP_DH, + EVP_PKEY_get_security_bits(pkdhp), 0, pkdhp)) { + SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE, SSL_R_DH_KEY_TOO_SMALL); + goto err; + } + if (s->s3.tmp.pkey != NULL) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + goto err; + } + + s->s3.tmp.pkey = ssl_generate_pkey(s, pkdhp); + if (s->s3.tmp.pkey == NULL) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); + goto err; + } + + EVP_PKEY_free(pkdh); + pkdh = NULL; /* These BIGNUMs need to be freed when we're finished */ freer = 1; @@ -2969,18 +2796,17 @@ CON_FUNC_RETURN tls_construct_server_key_exchange(SSL_CONNECTION *s, goto err; } - /* Get NID of appropriate shared ECDHE curve */ - group_id = tls1_shared_group(s, TLS1_GROUPS_RETURN_TMP_ID, - TLS1_GROUPS_NON_FFDHE_GROUPS); - if (group_id == 0) { + /* Get NID of appropriate shared curve */ + curve_id = tls1_shared_group(s, -2); + if (curve_id == 0) { SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE, SSL_R_UNSUPPORTED_ELLIPTIC_CURVE); goto err; } /* Cache the group used in the SSL_SESSION */ - s->session->kex_group = group_id; + s->session->kex_group = curve_id; /* Generate a new key for this curve */ - s->s3.tmp.pkey = ssl_generate_pkey_group(s, group_id); + s->s3.tmp.pkey = ssl_generate_pkey_group(s, curve_id); if (s->s3.tmp.pkey == NULL) { /* SSLfatal() already called */ goto err; @@ -3097,7 +2923,7 @@ CON_FUNC_RETURN tls_construct_server_key_exchange(SSL_CONNECTION *s, * point itself */ if (!WPACKET_put_bytes_u8(pkt, NAMED_CURVE_TYPE) - || !WPACKET_put_bytes_u16(pkt, group_id) + || !WPACKET_put_bytes_u16(pkt, curve_id) || !WPACKET_sub_memcpy_u8(pkt, encodedPoint, encodedlen)) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); goto err; @@ -3328,8 +3154,8 @@ static int tls_process_cke_rsa(SSL_CONNECTION *s, PACKET *pkt) return 0; } - /* pre-standard DTLS omits the length bytes. */ - if (s->version == DTLS1_BAD_VER) { + /* SSLv3 and pre-standard DTLS omit the length bytes. */ + if (s->version == SSL3_VERSION || s->version == DTLS1_BAD_VER) { enc_premaster = *pkt; } else { if (!PACKET_get_length_prefixed_2(pkt, &enc_premaster) @@ -3565,8 +3391,7 @@ static int tls_process_cke_gost(SSL_CONNECTION *s, PACKET *pkt) EVP_PKEY *client_pub_pkey = NULL, *pk = NULL; unsigned char premaster_secret[32]; const unsigned char *start; - size_t outlen = sizeof(premaster_secret); - size_t inlen; + size_t outlen = sizeof(premaster_secret), inlen; unsigned long alg_a; GOST_KX_MESSAGE *pKX = NULL; const unsigned char *ptr; @@ -3632,11 +3457,8 @@ static int tls_process_cke_gost(SSL_CONNECTION *s, PACKET *pkt) goto err; } - inlen = ASN1_STRING_length_ex(pKX->kxBlob->value.sequence); - if (inlen > INT_MAX) - goto err; - - start = ASN1_STRING_get0_data(pKX->kxBlob->value.sequence); + inlen = pKX->kxBlob->value.sequence->length; + start = pKX->kxBlob->value.sequence->data; if (EVP_PKEY_decrypt(pkey_ctx, premaster_secret, &outlen, start, inlen) @@ -4065,8 +3887,14 @@ MSG_PROCESS_RETURN tls_process_client_certificate(SSL_CONNECTION *s, } if (sk_X509_num(sk) <= 0) { - /* Fail only if we required a certificate */ - if ((s->verify_mode & SSL_VERIFY_PEER) && (s->verify_mode & SSL_VERIFY_FAIL_IF_NO_PEER_CERT)) { + /* TLS does not mind 0 certs returned */ + if (s->version == SSL3_VERSION) { + SSLfatal(s, SSL_AD_HANDSHAKE_FAILURE, + SSL_R_NO_CERTIFICATES_RETURNED); + goto err; + } + /* Fail for TLS only if we required a certificate */ + else if ((s->verify_mode & SSL_VERIFY_PEER) && (s->verify_mode & SSL_VERIFY_FAIL_IF_NO_PEER_CERT)) { SSLfatal(s, SSL_AD_CERTIFICATE_REQUIRED, SSL_R_PEER_DID_NOT_RETURN_A_CERTIFICATE); goto err; @@ -4286,7 +4114,7 @@ static CON_FUNC_RETURN construct_stateless_ticket(SSL_CONNECTION *s, { unsigned char *senc = NULL; EVP_CIPHER_CTX *ctx = NULL; - SSL_HMAC hctx, *constructed_hctx = NULL; + SSL_HMAC *hctx = NULL; unsigned char *p, *encdata1, *encdata2, *macdata1, *macdata2; const unsigned char *const_p; int len, slen_full, slen, lenfinal; @@ -4322,7 +4150,8 @@ static CON_FUNC_RETURN construct_stateless_ticket(SSL_CONNECTION *s, SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_EVP_LIB); goto err; } - if ((constructed_hctx = ssl_hmac_construct(tctx, &hctx)) == NULL) { + hctx = ssl_hmac_new(tctx); + if (hctx == NULL) { SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_SSL_LIB); goto err; } @@ -4373,13 +4202,13 @@ static CON_FUNC_RETURN construct_stateless_ticket(SSL_CONNECTION *s, if (tctx->ext.ticket_key_evp_cb != NULL) ret = tctx->ext.ticket_key_evp_cb(ssl, key_name, iv, ctx, - ssl_hmac_get0_EVP_MAC_CTX(&hctx), + ssl_hmac_get0_EVP_MAC_CTX(hctx), 1); #ifndef OPENSSL_NO_DEPRECATED_3_0 else if (tctx->ext.ticket_key_cb != NULL) /* if 0 is returned, write an empty ticket */ ret = tctx->ext.ticket_key_cb(ssl, key_name, iv, ctx, - ssl_hmac_get0_HMAC_CTX(&hctx), 1); + ssl_hmac_get0_HMAC_CTX(hctx), 1); #endif if (ret == 0) { @@ -4400,7 +4229,7 @@ static CON_FUNC_RETURN construct_stateless_ticket(SSL_CONNECTION *s, } OPENSSL_free(senc); EVP_CIPHER_CTX_free(ctx); - ssl_hmac_destruct(constructed_hctx); + ssl_hmac_free(hctx); return CON_FUNC_SUCCESS; } if (ret < 0) { @@ -4413,17 +4242,28 @@ static CON_FUNC_RETURN construct_stateless_ticket(SSL_CONNECTION *s, goto err; } } else { - iv_len = EVP_CIPHER_get_iv_length(sctx->tktenc); + EVP_CIPHER *cipher = EVP_CIPHER_fetch(sctx->libctx, "AES-256-CBC", + sctx->propq); + + if (cipher == NULL) { + /* Error is already recorded */ + SSLfatal_alert(s, SSL_AD_INTERNAL_ERROR); + goto err; + } + + iv_len = EVP_CIPHER_get_iv_length(cipher); if (iv_len < 0 || RAND_bytes_ex(sctx->libctx, iv, iv_len, 0) <= 0 - || !EVP_EncryptInit_ex(ctx, sctx->tktenc, NULL, + || !EVP_EncryptInit_ex(ctx, cipher, NULL, tctx->ext.secure->tick_aes_key, iv) - || !ssl_hmac_init(&hctx, tctx->ext.secure->tick_hmac_key, + || !ssl_hmac_init(hctx, tctx->ext.secure->tick_hmac_key, sizeof(tctx->ext.secure->tick_hmac_key), "SHA256")) { + EVP_CIPHER_free(cipher); SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); goto err; } + EVP_CIPHER_free(cipher); memcpy(key_name, tctx->ext.tick_key_name, sizeof(tctx->ext.tick_key_name)); } @@ -4449,11 +4289,11 @@ static CON_FUNC_RETURN construct_stateless_ticket(SSL_CONNECTION *s, || encdata1 + len != encdata2 || len + lenfinal > slen + EVP_MAX_BLOCK_LENGTH || !WPACKET_get_total_written(pkt, &macendoffset) - || !ssl_hmac_update(&hctx, + || !ssl_hmac_update(hctx, (unsigned char *)s->init_buf->data + macoffset, macendoffset - macoffset) || !WPACKET_reserve_bytes(pkt, EVP_MAX_MD_SIZE, &macdata1) - || !ssl_hmac_final(&hctx, macdata1, &hlen, EVP_MAX_MD_SIZE) + || !ssl_hmac_final(hctx, macdata1, &hlen, EVP_MAX_MD_SIZE) || hlen > EVP_MAX_MD_SIZE || !WPACKET_allocate_bytes(pkt, hlen, &macdata2) || macdata1 != macdata2) { @@ -4471,7 +4311,7 @@ static CON_FUNC_RETURN construct_stateless_ticket(SSL_CONNECTION *s, err: OPENSSL_free(senc); EVP_CIPHER_CTX_free(ctx); - ssl_hmac_destruct(constructed_hctx); + ssl_hmac_free(hctx); return ok; } diff --git a/ssl/t1_enc.c b/ssl/t1_enc.c index bcd3082d6b..b868846bc7 100644 --- a/ssl/t1_enc.c +++ b/ssl/t1_enc.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright 2005 Nokia. All rights reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -33,7 +33,10 @@ static int tls1_PRF(SSL_CONNECTION *s, unsigned char *out, size_t olen, int fatal) { const EVP_MD *md = ssl_prf_md(s); + EVP_KDF *kdf; EVP_KDF_CTX *kctx = NULL; + OSSL_PARAM params[9], *p = params; + const char *mdname; if (md == NULL) { /* Should never happen */ @@ -43,13 +46,16 @@ static int tls1_PRF(SSL_CONNECTION *s, ERR_raise(ERR_LIB_SSL, ERR_R_INTERNAL_ERROR); return 0; } -#ifdef OPENSSL_HAVE_TLS1PRF - kctx = EVP_KDF_CTX_new(SSL_CONNECTION_GET_CTX(s)->tls1prf); + kdf = EVP_KDF_fetch(SSL_CONNECTION_GET_CTX(s)->libctx, + OSSL_KDF_NAME_TLS1_PRF, + SSL_CONNECTION_GET_CTX(s)->propq); + if (kdf == NULL) + goto err; + kctx = EVP_KDF_CTX_new(kdf); + EVP_KDF_free(kdf); if (kctx == NULL) goto err; - - const char *mdname = EVP_MD_get0_name(md); - OSSL_PARAM params[9], *p = params; + mdname = EVP_MD_get0_name(md); *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, (char *)mdname, 0); *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SECRET, @@ -79,7 +85,6 @@ static int tls1_PRF(SSL_CONNECTION *s, } err: -#endif if (fatal) SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); else @@ -464,7 +469,7 @@ int tls1_export_keying_material(SSL_CONNECTION *s, unsigned char *out, if (val == NULL) goto ret; currentvalpos = 0; - memcpy(val + currentvalpos, label, llen); + memcpy(val + currentvalpos, (unsigned char *)label, llen); currentvalpos += llen; memcpy(val + currentvalpos, s->s3.client_random, SSL3_RANDOM_SIZE); currentvalpos += SSL3_RANDOM_SIZE; @@ -595,10 +600,6 @@ int tls1_alert_code(int code) return SSL_AD_HANDSHAKE_FAILURE; case TLS13_AD_MISSING_EXTENSION: return SSL_AD_HANDSHAKE_FAILURE; -#ifndef OPENSSL_NO_ECH - case SSL_AD_ECH_REQUIRED: - return TLS1_AD_ECH_REQUIRED; -#endif default: return -1; } diff --git a/ssl/t1_lib.c b/ssl/t1_lib.c index f8056c82da..9ece318950 100644 --- a/ssl/t1_lib.c +++ b/ssl/t1_lib.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -29,8 +29,6 @@ #include "quic/quic_local.h" #include -#define MAX_SIGALGS 128 - static const SIGALG_LOOKUP *find_sig_alg(SSL_CONNECTION *s, X509 *x, EVP_PKEY *pkey); static int tls12_sigalg_allowed(const SSL_CONNECTION *s, int op, const SIGALG_LOOKUP *lu); @@ -207,12 +205,8 @@ static const unsigned char ecformats_all[] = { /* Group list string of the built-in pseudo group DEFAULT */ #define DEFAULT_GROUP_NAME "DEFAULT" -#define TLS_DEFAULT_GROUP_LIST \ - "?*X25519MLKEM768:?SecP256r1MLKEM768:?curveSM2MLKEM768 / " \ - "?*X25519:?secp256r1 / " \ - "?X448:?secp384r1:?secp521r1 / " \ - "?curveSM2 / " \ - "?ffdhe2048:?ffdhe3072" +#define TLS_DEFAULT_GROUP_LIST \ + "?*X25519MLKEM768 / ?*X25519:?secp256r1 / ?X448:?secp384r1:?secp521r1 / ?ffdhe2048:?ffdhe3072" static const uint16_t suiteb_curves[] = { OSSL_TLS_GROUP_ID_secp256r1, @@ -221,7 +215,7 @@ static const uint16_t suiteb_curves[] = { /* Group list string of the built-in pseudo group DEFAULT_SUITE_B */ #define SUITE_B_GROUP_NAME "DEFAULT_SUITE_B" -#define SUITE_B_GROUP_LIST "?secp256r1:?secp384r1", +#define SUITE_B_GROUP_LIST "secp256r1:secp384r1", struct provider_ctx_data_st { SSL_CTX *ctx; @@ -333,15 +327,6 @@ static int add_provider_groups(const OSSL_PARAM params[], void *data) ERR_raise(ERR_LIB_SSL, ERR_R_PASSED_INVALID_ARGUMENT); goto err; } - - if (ginf->group_id >= OSSL_TLS_GROUP_ID_ffdhe2048 - && ginf->group_id <= OSSL_TLS_GROUP_ID_ffdhe8192) { - if (ginf->mintls > TLS1_2_VERSION) - ginf->mintls = TLS1_VERSION; - if (DTLS_VERSION_GT(ginf->mindtls, DTLS1_2_VERSION)) - ginf->mindtls = DTLS1_VERSION; - } - /* * Now check that the algorithm is actually usable for our property query * string. Regardless of the result we still return success because we have @@ -872,25 +857,25 @@ void tls1_get_group_tuples(SSL_CONNECTION *s, const size_t **ptuples, } int tls_valid_group(SSL_CONNECTION *s, uint16_t group_id, - int minversion, int maxversion, int *okfortls13, - const TLS_GROUP_INFO **giptr) + int minversion, int maxversion, + int isec, int *okfortls13) { const TLS_GROUP_INFO *ginfo = tls1_group_id_lookup(SSL_CONNECTION_GET_CTX(s), group_id); - int ret = 0; + int ret; int group_minversion, group_maxversion; if (okfortls13 != NULL) *okfortls13 = 0; if (ginfo == NULL) - goto end; + return 0; group_minversion = SSL_CONNECTION_IS_DTLS(s) ? ginfo->mindtls : ginfo->mintls; group_maxversion = SSL_CONNECTION_IS_DTLS(s) ? ginfo->maxdtls : ginfo->maxtls; if (group_minversion < 0 || group_maxversion < 0) - goto end; + return 0; if (group_maxversion == 0) ret = 1; else @@ -903,9 +888,11 @@ int tls_valid_group(SSL_CONNECTION *s, uint16_t group_id, *okfortls13 = (group_maxversion == 0) || (group_maxversion >= TLS1_3_VERSION); } -end: - if (giptr != NULL) - *giptr = ginfo; + ret &= !isec + || strcmp(ginfo->algorithm, "EC") == 0 + || strcmp(ginfo->algorithm, "X25519") == 0 + || strcmp(ginfo->algorithm, "X448") == 0; + return ret; } @@ -1014,18 +1001,11 @@ end: /*- * For nmatch >= 0, return the id of the |nmatch|th shared group or 0 * if there is no match. - * For nmatch == TLS1_GROUPS_RETURN_NUMBER, return number of matches - * For nmatch == TLS1_GROUPS_RETURN_TMP_ID, return the id of the group to use - * for a tmp key, or 0 if there is no match. - * If groups == TLS1_GROUPS_FFDHE_GROUPS, only shared groups that are FFDHE - * groups (i.e., between OSSL_TLS_GROUP_ID_FFDHE_START and - * OSSL_TLS_GROUP_ID_FFDHE_END, inclusive) will be included in the search. - * If groups == TLS1_GROUPS_NON_FFDHE_GROUPS, only shared groups that are not - * FFDHE groups will be included in the search. - * If groups == TLS1_GROUPS_ALL_GROUPS, all groups will be included in the - * search. + * For nmatch == -1, return number of matches + * For nmatch == -2, return the id of the group to use for + * a tmp key, or 0 if there is no match. */ -uint16_t tls1_shared_group(SSL_CONNECTION *s, int nmatch, int groups) +uint16_t tls1_shared_group(SSL_CONNECTION *s, int nmatch) { const uint16_t *pref, *supp; size_t num_pref, num_supp, i; @@ -1035,8 +1015,8 @@ uint16_t tls1_shared_group(SSL_CONNECTION *s, int nmatch, int groups) /* Can't do anything on client side */ if (s->server == 0) return 0; - if (nmatch == TLS1_GROUPS_RETURN_TMP_ID) { - if (groups != TLS1_GROUPS_FFDHE_GROUPS && tls1_suiteb(s)) { + if (nmatch == -2) { + if (tls1_suiteb(s)) { /* * For Suite B ciphersuite determines curve: we already know * these are acceptable due to previous checks. @@ -1071,8 +1051,6 @@ uint16_t tls1_shared_group(SSL_CONNECTION *s, int nmatch, int groups) int minversion, maxversion; if (!tls1_in_list(id, supp, num_supp) - || (groups == TLS1_GROUPS_NON_FFDHE_GROUPS && is_ffdhe_group(id)) - || (groups == TLS1_GROUPS_FFDHE_GROUPS && !is_ffdhe_group(id)) || !tls_group_allowed(s, id, SSL_SECOP_CURVE_SHARED)) continue; inf = tls1_group_id_lookup(ctx, id); @@ -1096,7 +1074,7 @@ uint16_t tls1_shared_group(SSL_CONNECTION *s, int nmatch, int groups) return id; k++; } - if (nmatch == TLS1_GROUPS_RETURN_NUMBER) + if (nmatch == -1) return k; /* Out of range (nmatch > k). */ return 0; @@ -1255,17 +1233,6 @@ static const char prefixes[] = { TUPLE_DELIMITER_CHARACTER, * Those callback functions are (indirectly) called by CONF_parse_list with * different separators (nominally ':' or '/'), a variable based on gid_cb_st * is used to keep track of the parsing results between the various calls - * - * Bookkeeping invariants maintained throughout parsing (see gid_cb_st below): - * - gid_arr[0..gidcnt) is the flat list of groups, partitioned into tuples in - * order: tuple t occupies a contiguous run of tuplcnt_arr[t] entries. - * - The per-tuple counts therefore sum to the group count: - * sum(tuplcnt_arr[0..tplcnt]) == gidcnt - * (indices 0..tplcnt-1 are closed tuples, index tplcnt is the active one). - * - ksid_arr[0..ksidcnt) holds keyshare group IDs; each is one of the groups - * in gid_arr and they appear in the same relative order as their groups. - * Every add/remove path must preserve these; an OOB read in the remove path - * (GitHub #31315) was a symptom of the first invariant being violated. */ typedef struct { @@ -1274,21 +1241,15 @@ typedef struct { size_t gidmax; /* The memory allocation chunk size for the group IDs */ size_t gidcnt; /* Number of groups */ uint16_t *gid_arr; /* The IDs of the supported groups (flat list) */ - size_t tplmax; /* Allocated length of tuplcnt_arr */ - /* - * Number of *closed* (fully parsed) tuples. During parsing there is - * always one additional active tuple being built, stored at index tplcnt. - * tuplcnt_arr therefore always needs at least tplcnt + 1 allocated slots. - */ - size_t tplcnt; - size_t *tuplcnt_arr; /* Per-tuple group counts; [0..tplcnt-1] closed, [tplcnt] active */ + size_t tplmax; /* The memory allocation chunk size for the tuple counters */ + size_t tplcnt; /* Number of tuples */ + size_t *tuplcnt_arr; /* The number of groups inside a tuple */ size_t ksidmax; /* The memory allocation chunk size */ size_t ksidcnt; /* Number of key shares */ uint16_t *ksid_arr; /* The IDs of the key share groups (flat list) */ /* Variable to keep state between execution of callback or helper functions */ - int want_keyshare; /* If positive, pending keyshare from unrecognised group */ - int inner; /* Are we expanding a DEFAULT list */ - int first; /* First tuple of possibly nested expansion? */ + size_t tuple_mode; /* Keeps track whether tuple_cb called from 'the top' or from gid_cb */ + int ignore_unknown_default; /* Flag such that unknown groups for DEFAULT[_XYZ] are ignored */ } gid_cb_st; /* Forward declaration of tuple callback function */ @@ -1307,7 +1268,7 @@ static int gid_cb(const char *elem, int len, void *arg) int found_group = 0; char etmp[GROUP_NAME_BUFFER_LENGTH]; int retval = 1; /* We assume success */ - const char *current_prefix; + char *current_prefix; int ignore_unknown = 0; int add_keyshare = 0; int remove_group = 0; @@ -1363,16 +1324,16 @@ static int gid_cb(const char *elem, int len, void *arg) for (i = 0; i < OSSL_NELEM(default_group_strings); i++) { if ((size_t)len == (strlen(default_group_strings[i].list_name)) && OPENSSL_strncasecmp(default_group_strings[i].list_name, elem, len) == 0) { - int saved_first; - /* * We're asked to insert an entire list of groups from a * DEFAULT[_XYZ] 'pseudo group' which we do by * recursively calling this function (indirectly via * CONF_parse_list and tuple_cb); essentially, we treat a DEFAULT * group string like a tuple which is appended to the current tuple - * rather then starting a new tuple. + * rather then starting a new tuple. Variable tuple_mode is the flag which + * controls append tuple vs start new tuple. */ + if (ignore_unknown || remove_group) return -1; /* removal or ignore not allowed here -> syntax error */ @@ -1393,17 +1354,15 @@ static int gid_cb(const char *elem, int len, void *arg) default_group_strings[i].group_string, strlen(default_group_strings[i].group_string)); restored_default_group_string[strlen(default_group_strings[i].group_string) + restored_prefix_index] = '\0'; - /* - * Append first tuple of result to current tuple, and don't - * terminate the last tuple until we return to a top-level - * tuple_cb. - */ - saved_first = garg->first; - garg->inner = garg->first = 1; + /* We execute the recursive call */ + garg->ignore_unknown_default = 1; /* We ignore unknown groups for DEFAULT_XYZ */ + /* we enforce group mode (= append tuple) for DEFAULT_XYZ group lists */ + garg->tuple_mode = 0; + /* We use the tuple_cb callback to process the pseudo group tuple */ retval = CONF_parse_list(restored_default_group_string, TUPLE_DELIMITER_CHARACTER, 1, tuple_cb, garg); - garg->inner = 0; - garg->first = saved_first; + garg->tuple_mode = 1; /* next call to tuple_cb will again start new tuple */ + garg->ignore_unknown_default = 0; /* reset to original value */ /* We don't need the \0-terminated string anymore */ OPENSSL_free(restored_default_group_string); @@ -1423,6 +1382,9 @@ static int gid_cb(const char *elem, int len, void *arg) if (len == 0) return -1; /* Seems we have prefxes without a group name -> syntax error */ + if (garg->ignore_unknown_default == 1) /* Always ignore unknown groups for DEFAULT[_XYZ] */ + ignore_unknown = 1; + /* Memory management in case more groups are present compared to initial allocation */ if (garg->gidcnt == garg->gidmax) { uint16_t *tmp = OPENSSL_realloc_array(garg->gid_arr, @@ -1474,9 +1436,6 @@ static int gid_cb(const char *elem, int len, void *arg) } } if (gid == 0) { /* still not found */ - /* If unknown, next known tuple element gets a keyshare */ - if (add_keyshare && !remove_group && garg->want_keyshare == 0) - garg->want_keyshare = 1; /* Unknown group - ignore if ignore_unknown; trigger error otherwise */ retval = ignore_unknown; goto done; @@ -1496,114 +1455,56 @@ static int gid_cb(const char *elem, int len, void *arg) * ignore_unknown; trigger error otherwise */ if (found_group == 0) { - /* If unknown, next known tuple element gets a keyshare */ - if (add_keyshare && !remove_group && garg->want_keyshare == 0) - garg->want_keyshare = 1; retval = ignore_unknown; goto done; } /* Remove group (and keyshare) from anywhere in the list if present, ignore if not present */ if (remove_group) { - size_t n = 0; /* tuple size */ - size_t tpl_start_idx = 0; /* Index of 1st group in tuple of removed group */ - size_t ks_check_idx = 0; /* Index after last known retained keyshare */ - - j = 0; /* tuple index */ - k = 0; /* keyshare index */ - n = garg->tuplcnt_arr[j]; - - for (i = 0; i < garg->gidcnt; ++i) { - if (garg->gid_arr[i] == gid) + /* Is the current group specified anywhere in the entire list so far? */ + found_group = 0; + for (i = 0; i < garg->gidcnt; i++) + if (garg->gid_arr[i] == gid) { + found_group = 1; break; - /* Skip keyshare slots associated with groups prior to that removed */ - if (k < garg->ksidcnt && garg->gid_arr[i] == garg->ksid_arr[k]) { - ++k; - /* Skip each retained keyshare as we go */ - ks_check_idx = i + 1; } - if (--n == 0) { - if (j < garg->tplcnt) - n = garg->tuplcnt_arr[++j]; - tpl_start_idx = i + 1; - } - } - - /* Nothing to remove? */ - if (i >= garg->gidcnt) - goto done; - - garg->gidcnt--; - garg->tuplcnt_arr[j]--; - memmove(garg->gid_arr + i, garg->gid_arr + i + 1, - (garg->gidcnt - i) * sizeof(gid)); - - /* Handle keyshare removal */ - if (k < garg->ksidcnt && garg->ksid_arr[k] == gid) { - int drop_ks; + /* The group to remove is at position i in the list of (zero indexed) groups */ + if (found_group) { + /* We remove that group from its position (which is at i)... */ + for (j = i; j < (garg->gidcnt - 1); j++) + garg->gid_arr[j] = garg->gid_arr[j + 1]; /* ...shift remaining groups left ... */ + garg->gidcnt--; /* ..and update the book keeping for the number of groups */ /* - * Simply drop the group's keyshare unless it is the last one in a - * still non-empty tuple. - * - * If `ks_check_idx` is larger than the tuple start index at least - * one keyshare belonging to the tuple is retained, so we drop this - * one. Also if the tuple is the current one (isn't closed yet), - * floating is handled at tuple close time. - * - * Otherwise, iterate through the tuple check whether any keyshares - * remain *after* the index of the group we're removing. The first - * of these, if any, is at index `k+1` in the keyshare list, which - * is the only slot we need to check. - * - * If the removal emptied the tuple (tuplcnt_arr[j] == 0 after the - * decrement above) there is no remaining group to float onto: - * gid_arr[tpl_start_idx] would now name a group belonging to the - * next tuple (or be past gid_arr entirely). Drop the keyshare in - * that case too. + * We also must update the number of groups either in a previous tuple (which we + * must identify and check whether it becomes empty due to the deletion) or in + * the current tuple, pending where the deleted group resides */ - drop_ks = ks_check_idx > tpl_start_idx || j >= garg->tplcnt - || garg->tuplcnt_arr[j] == 0; - - if (!drop_ks) { - size_t end; /* End index of affected tuple */ - - /* Removing the first keyshare of an already completed tuple */ - for (end = tpl_start_idx + garg->tuplcnt_arr[j]; i < end; ++i) { - /* Any other keyshares for the same tuple? */ - if (k + 1 < garg->ksidcnt - && garg->gid_arr[i] == garg->ksid_arr[k + 1]) - break; + k = 0; + for (j = 0; j < garg->tplcnt; j++) { + k += garg->tuplcnt_arr[j]; + /* Remark: i is zero-indexed, k is one-indexed */ + if (k > i) { /* remove from one of the previous tuples */ + garg->tuplcnt_arr[j]--; + break; /* We took care not to have group duplicates, hence we can stop here */ } - /* Float keyshare to first group when no others found */ - if (i >= end) - garg->ksid_arr[k] = garg->gid_arr[tpl_start_idx]; - else - drop_ks = 1; } - if (drop_ks) { - garg->ksidcnt--; - memmove(garg->ksid_arr + k, garg->ksid_arr + k + 1, - (garg->ksidcnt - k) * sizeof(gid)); - } - } + if (k <= i) /* remove from current tuple */ + garg->tuplcnt_arr[j]--; - /* - * Adjust closed or current tuple's group count, if a closed tuple - * count reaches zero excise the resulting empty tuple. The current - * (not yet closed) tuple at the end of the list stays even if empty. - * - * The active tuple lives at index tplcnt, so the slots in use are - * tuplcnt_arr[0..tplcnt] (tplcnt + 1 entries). Excising closed tuple - * j must therefore shift the closed tuples j+1..tplcnt-1 *and* the - * active tuple at index tplcnt down by one, i.e. (tplcnt - j) entries - * counted with the pre-decrement tplcnt. Decrement tplcnt only after - * the move so the active-tuple slot is not left behind (which would - * inflate the per-tuple counts and desynchronise them from gid_arr). - */ - if (garg->tuplcnt_arr[j] == 0 && j < garg->tplcnt) { - memmove(garg->tuplcnt_arr + j, garg->tuplcnt_arr + j + 1, - (garg->tplcnt - j) * sizeof(size_t)); - garg->tplcnt--; + /* We also remove the group from the list of keyshares (if present) */ + found_group = 0; + for (i = 0; i < garg->ksidcnt; i++) + if (garg->ksid_arr[i] == gid) { + found_group = 1; + break; + } + if (found_group) { + /* Found, hence we remove that keyshare from its position (which is at i)... */ + for (j = i; j < (garg->ksidcnt - 1); j++) + garg->ksid_arr[j] = garg->ksid_arr[j + 1]; /* shift remaining key shares */ + /* ... and update the book keeping */ + garg->ksidcnt--; + } } } else { /* Processing addition of a single new group */ @@ -1619,76 +1520,15 @@ static int gid_cb(const char *elem, int len, void *arg) /* and update the book keeping for the number of groups in current tuple */ garg->tuplcnt_arr[garg->tplcnt]++; - /* We want to add a key share for the current group */ - if (add_keyshare) { + /* We memorize if needed that we want to add a key share for the current group */ + if (add_keyshare) garg->ksid_arr[garg->ksidcnt++] = gid; - garg->want_keyshare = -1; - } } done: return retval; } -/* - * Ensure tuplcnt_arr has room for at least tplcnt + 2 entries so that - * close_tuple() can safely increment tplcnt and write the new active-tuple - * slot at index tplcnt + 1. Must be called before that increment. - */ -static int grow_tuples(gid_cb_st *garg) -{ - /* - * tplcnt + 1 is the index close_tuple() will write to after incrementing; - * reallocate before it would reach the end of the allocated array. - */ - if (garg->tplcnt + 1 >= garg->tplmax) { - size_t *tmp = OPENSSL_realloc_array(garg->tuplcnt_arr, - garg->tplmax + GROUPLIST_INCREMENT, - sizeof(*garg->tuplcnt_arr)); - - if (tmp == NULL) - return 0; - garg->tplmax += GROUPLIST_INCREMENT; - garg->tuplcnt_arr = tmp; - } - return 1; -} - -/* - * Finalise the active tuple (at index tplcnt) and open a fresh one. - * tplcnt is the count of closed tuples; the active tuple lives at tplcnt - * throughout parsing. After this call tplcnt is incremented and the new - * active tuple at the updated index is initialised to 0. - * Empty tuples (gidcnt == 0) are discarded without advancing tplcnt. - */ -static int close_tuple(gid_cb_st *garg) -{ - size_t gidcnt = garg->tuplcnt_arr[garg->tplcnt]; - - if (gidcnt > 0 && garg->want_keyshare > 0) { - uint16_t gid = garg->gid_arr[garg->gidcnt - gidcnt]; - - /* - * All groups in the tuple that were marked for keyshare prediction - * were unknown (unrecognised); select the first known group instead. - */ - garg->ksid_arr[garg->ksidcnt++] = gid; - } - /* Reset keyshare state for the next tuple */ - garg->want_keyshare = 0; - - if (gidcnt == 0) - return 1; /* Discard empty tuple; no need to open a new slot */ - - /* Grow before the increment: the new active slot will be at tplcnt + 1 */ - if (!grow_tuples(garg)) - return 0; - - /* Promote closed tuple and initialise the new active tuple slot */ - garg->tuplcnt_arr[++garg->tplcnt] = 0; - return 1; -} - /* Extract and process a tuple of groups */ static int tuple_cb(const char *tuple, int len, void *arg) { @@ -1702,9 +1542,17 @@ static int tuple_cb(const char *tuple, int len, void *arg) return 0; } - if (garg->inner && !garg->first && !close_tuple(garg)) - return 0; - garg->first = 0; + /* Memory management for tuples */ + if (garg->tplcnt == garg->tplmax) { + size_t *tmp = OPENSSL_realloc_array(garg->tuplcnt_arr, + garg->tplmax + GROUPLIST_INCREMENT, + sizeof(*garg->tuplcnt_arr)); + + if (tmp == NULL) + return 0; + garg->tplmax += GROUPLIST_INCREMENT; + garg->tuplcnt_arr = tmp; + } /* Convert to \0-terminated string */ restored_tuple_string = OPENSSL_malloc(len + 1 /* \0 */); @@ -1719,8 +1567,15 @@ static int tuple_cb(const char *tuple, int len, void *arg) /* We don't need the \o-terminated string anymore */ OPENSSL_free(restored_tuple_string); - if (!garg->inner && !close_tuple(garg)) - return 0; + if (garg->tuplcnt_arr[garg->tplcnt] > 0) { /* Some valid groups are present in current tuple... */ + if (garg->tuple_mode) { + /* We 'close' the tuple */ + garg->tplcnt++; + garg->tuplcnt_arr[garg->tplcnt] = 0; /* Next tuple is initialized to be empty */ + garg->tuple_mode = 1; /* next call will start a tuple (unless overridden in gid_cb) */ + } + } + return retval; } @@ -1751,6 +1606,8 @@ int tls1_set_groups_list(SSL_CTX *ctx, } memset(&gcb, 0, sizeof(gcb)); + gcb.tuple_mode = 1; /* We prepare to collect the first tuple */ + gcb.ignore_unknown_default = 0; gcb.gidmax = GROUPLIST_INCREMENT; gcb.tplmax = GROUPLIST_INCREMENT; gcb.ksidmax = GROUPLIST_INCREMENT; @@ -1912,7 +1769,13 @@ int tls1_check_group_id(SSL_CONNECTION *s, uint16_t group_id, void tls1_get_formatlist(SSL_CONNECTION *s, const unsigned char **pformats, size_t *num_formats) { - if ((s->options & SSL_OP_LEGACY_EC_POINT_FORMATS) != 0) { + /* + * If we have a custom point format list use it otherwise use default + */ + if (s->ext.ecpointformats) { + *pformats = s->ext.ecpointformats; + *num_formats = s->ext.ecpointformats_len; + } else if ((s->options & SSL_OP_LEGACY_EC_POINT_FORMATS) != 0) { *pformats = ecformats_all; /* For Suite B we don't support char2 fields */ if (tls1_suiteb(s)) @@ -1925,6 +1788,53 @@ void tls1_get_formatlist(SSL_CONNECTION *s, const unsigned char **pformats, } } +/* Check a key is compatible with compression extension */ +static int tls1_check_pkey_comp(SSL_CONNECTION *s, EVP_PKEY *pkey) +{ + unsigned char comp_id; + size_t i; + int point_conv; + + /* If not an EC key nothing to check */ + if (!EVP_PKEY_is_a(pkey, "EC")) + return 1; + + /* Get required compression id */ + point_conv = EVP_PKEY_get_ec_point_conv_form(pkey); + if (point_conv == 0) + return 0; + if (point_conv == POINT_CONVERSION_UNCOMPRESSED) { + comp_id = TLSEXT_ECPOINTFORMAT_uncompressed; + } else if (SSL_CONNECTION_IS_TLS13(s)) { + /* + * ec_point_formats extension is not used in TLSv1.3 so we ignore + * this check. + */ + return 1; + } else { + int field_type = EVP_PKEY_get_field_type(pkey); + + if (field_type == NID_X9_62_prime_field) + comp_id = TLSEXT_ECPOINTFORMAT_ansiX962_compressed_prime; + else if (field_type == NID_X9_62_characteristic_two_field) + comp_id = TLSEXT_ECPOINTFORMAT_ansiX962_compressed_char2; + else + return 0; + } + /* + * If point formats extension present check it, otherwise everything is + * supported (see RFC4492). + */ + if (s->ext.peer_ecpointformats == NULL) + return 1; + + for (i = 0; i < s->ext.peer_ecpointformats_len; i++) { + if (s->ext.peer_ecpointformats[i] == comp_id) + return 1; + } + return 0; +} + /* Return group id of a key */ static uint16_t tls1_get_group_id(EVP_PKEY *pkey) { @@ -1937,7 +1847,7 @@ static uint16_t tls1_get_group_id(EVP_PKEY *pkey) /* * Check cert parameters compatible with extensions: currently just checks EC - * certificates have compatible curves. + * certificates have compatible curves and compression. */ static int tls1_check_cert_param(SSL_CONNECTION *s, X509 *x, int check_ee_md) { @@ -1949,6 +1859,9 @@ static int tls1_check_cert_param(SSL_CONNECTION *s, X509 *x, int check_ee_md) /* If not EC nothing to do */ if (!EVP_PKEY_is_a(pkey, "EC")) return 1; + /* Check compression */ + if (!tls1_check_pkey_comp(s, pkey)) + return 0; group_id = tls1_get_group_id(pkey); /* * For a server we allow the certificate to not be in our list of supported @@ -1980,46 +1893,6 @@ static int tls1_check_cert_param(SSL_CONNECTION *s, X509 *x, int check_ee_md) return 1; } -/* - * tls1_check_ffdhe_tmp_key - Check FFDHE temporary key compatibility - * @s: SSL connection - * @cid: Cipher ID we're considering using - * - * Checks that the kDHE cipher suite we're considering using - * is compatible with the client extensions. - * - * Returns 0 when the cipher can't be used or 1 when it can. - */ -int tls1_check_ffdhe_tmp_key(SSL_CONNECTION *s, unsigned long cid) -{ - const uint16_t *peer_groups; - size_t num_peer_groups; - - /* If we have a shared FFDHE group, we can certainly use it. */ - if (tls1_shared_group(s, 0, TLS1_GROUPS_FFDHE_GROUPS) != 0) - return 1; - - /* - * Otherwise, we follow RFC 7919: - * If a compatible TLS server receives a Supported Groups extension from - * a client that includes any FFDHE group (i.e., any codepoint between - * 256 and 511, inclusive, even if unknown to the server), and if none - * of the client-proposed FFDHE groups are known and acceptable to the - * server, then the server MUST NOT select an FFDHE cipher suite. - */ - tls1_get_peer_groups(s, &peer_groups, &num_peer_groups); - for (size_t i = 0; i < num_peer_groups; i++) { - if (is_ffdhe_group(peer_groups[i])) - return 0; - } - - /* - * The client did not send any FFDHE groups, so we can use this ciphersuite - * using any group we like. - */ - return 1; -} - /* * tls1_check_ec_tmp_key - Check EC temporary key compatibility * @s: SSL connection @@ -2034,7 +1907,7 @@ int tls1_check_ec_tmp_key(SSL_CONNECTION *s, unsigned long cid) { /* If not Suite B just need a shared group */ if (!tls1_suiteb(s)) - return tls1_shared_group(s, 0, TLS1_GROUPS_NON_FFDHE_GROUPS) != 0; + return tls1_shared_group(s, 0) != 0; /* * If Suite B, AES128 MUST use P-256 and AES256 MUST use P-384, no other * curves permitted. @@ -2243,14 +2116,16 @@ static const SIGALG_LOOKUP sigalg_lookup_tbl[] = { TLS1_2_VERSION, TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION }, #ifndef OPENSSL_NO_GOST - { TLSEXT_SIGALG_gostr34102012_256_intrinsic_name, /* RFC9189 */ - NULL, TLSEXT_SIGALG_gostr34102012_256_intrinsic, + { TLSEXT_SIGALG_gostr34102012_256_intrinsic_alias, /* RFC9189 */ + TLSEXT_SIGALG_gostr34102012_256_intrinsic_name, + TLSEXT_SIGALG_gostr34102012_256_intrinsic, NID_id_GostR3411_2012_256, SSL_MD_GOST12_256_IDX, NID_id_GostR3410_2012_256, SSL_PKEY_GOST12_256, NID_undef, NID_undef, 1, 0, TLS1_2_VERSION, TLS1_2_VERSION, DTLS1_2_VERSION, DTLS1_2_VERSION }, - { TLSEXT_SIGALG_gostr34102012_512_intrinsic_name, /* RFC9189 */ - NULL, TLSEXT_SIGALG_gostr34102012_512_intrinsic, + { TLSEXT_SIGALG_gostr34102012_256_intrinsic_alias, /* RFC9189 */ + TLSEXT_SIGALG_gostr34102012_256_intrinsic_name, + TLSEXT_SIGALG_gostr34102012_512_intrinsic, NID_id_GostR3411_2012_512, SSL_MD_GOST12_512_IDX, NID_id_GostR3410_2012_512, SSL_PKEY_GOST12_512, NID_undef, NID_undef, 1, 0, @@ -2499,25 +2374,21 @@ char *SSL_get1_builtin_sigalgs(OSSL_LIB_CTX *libctx) return retval; } -/* Find known TLS signature algorithm */ -static const SIGALG_LOOKUP *tls1_find_sigalg(const SSL_CTX *ctx, - uint16_t sigalg) -{ - const SIGALG_LOOKUP *lu = ctx->sigalg_lookup_cache; - - for (size_t i = 0; i < ctx->sigalg_lookup_cache_len; lu++, i++) - if (lu->sigalg == sigalg) - return lu; - return NULL; -} - -/* Look up available TLS signature algorithm */ +/* Lookup TLS signature algorithm */ static const SIGALG_LOOKUP *tls1_lookup_sigalg(const SSL_CTX *ctx, uint16_t sigalg) { - const SIGALG_LOOKUP *lu = tls1_find_sigalg(ctx, sigalg); + size_t i; + const SIGALG_LOOKUP *lu = ctx->sigalg_lookup_cache; - return (lu != NULL && lu->available) ? lu : NULL; + for (i = 0; i < ctx->sigalg_lookup_cache_len; lu++, i++) { + if (lu->sigalg == sigalg) { + if (!lu->available) + return NULL; + return lu; + } + } + return NULL; } /* Lookup hash: return 0 if invalid or not enabled */ @@ -2887,11 +2758,13 @@ int tls12_check_peer_sigalg(SSL_CONNECTION *s, uint16_t sig, EVP_PKEY *pkey) } if (pkeyid == EVP_PKEY_EC) { - /* - * No point-format check on either the peer's or own cert. - * We accept any form we can decode, and send the cert we - * have. - */ + + /* Check point compression is permitted */ + if (!tls1_check_pkey_comp(s, pkey)) { + SSLfatal(s, SSL_AD_ILLEGAL_PARAMETER, + SSL_R_ILLEGAL_POINT_COMPRESSION); + return 0; + } /* For TLS 1.3 or Suite B check curve matches signature algorithm */ if (SSL_CONNECTION_IS_TLS13(s) || tls1_suiteb(s)) { @@ -3020,11 +2893,12 @@ int ssl_set_client_disabled(SSL_CONNECTION *s) * @s: SSL connection that you want to use the cipher on * @c: cipher to check * @op: Security check that you want to do + * @ecdhe: If set to 1 then TLSv1 ECDHE ciphers are also allowed in SSLv3 * * Returns 1 when it's disabled, 0 when enabled. */ int ssl_cipher_disabled(const SSL_CONNECTION *s, const SSL_CIPHER *c, - int op) + int op, int ecdhe) { int minversion = SSL_CONNECTION_IS_DTLS(s) ? c->min_dtls : c->min_tls; int maxversion = SSL_CONNECTION_IS_DTLS(s) ? c->max_dtls : c->max_tls; @@ -3046,6 +2920,15 @@ int ssl_cipher_disabled(const SSL_CONNECTION *s, const SSL_CIPHER *c, return 1; } + /* + * For historical reasons we will allow ECHDE to be selected by a server + * in SSLv3 if we are a client + */ + if (minversion == TLS1_VERSION + && ecdhe + && (c->algorithm_mkey & (SSL_kECDHE | SSL_kECDHEPSK)) != 0) + minversion = SSL3_VERSION; + if (ssl_version_cmp(s, minversion, s->s3.tmp.max_ver) > 0 || ssl_version_cmp(s, maxversion, s->s3.tmp.min_ver) < 0) return 1; @@ -3188,7 +3071,7 @@ SSL_TICKET_STATUS tls_decrypt_ticket(SSL_CONNECTION *s, SSL_TICKET_STATUS ret = SSL_TICKET_FATAL_ERR_OTHER; size_t mlen; unsigned char tick_hmac[EVP_MAX_MD_SIZE]; - SSL_HMAC hctx, *constructed_hctx = NULL; + SSL_HMAC *hctx = NULL; EVP_CIPHER_CTX *ctx = NULL; SSL_CTX *tctx = s->session_ctx; SSL_CTX *sctx = SSL_CONNECTION_GET_CTX(s); @@ -3219,8 +3102,8 @@ SSL_TICKET_STATUS tls_decrypt_ticket(SSL_CONNECTION *s, } /* Initialize session ticket encryption and HMAC contexts */ - - if ((constructed_hctx = ssl_hmac_construct(tctx, &hctx)) == NULL) { + hctx = ssl_hmac_new(tctx); + if (hctx == NULL) { ret = SSL_TICKET_FATAL_ERR_MALLOC; goto end; } @@ -3243,14 +3126,14 @@ SSL_TICKET_STATUS tls_decrypt_ticket(SSL_CONNECTION *s, nctick, nctick + TLSEXT_KEYNAME_LENGTH, ctx, - ssl_hmac_get0_EVP_MAC_CTX(&hctx), + ssl_hmac_get0_EVP_MAC_CTX(hctx), 0); #ifndef OPENSSL_NO_DEPRECATED_3_0 else if (tctx->ext.ticket_key_cb != NULL) /* if 0 is returned, write an empty ticket */ rv = tctx->ext.ticket_key_cb(SSL_CONNECTION_GET_USER_SSL(s), nctick, nctick + TLSEXT_KEYNAME_LENGTH, - ctx, ssl_hmac_get0_HMAC_CTX(&hctx), 0); + ctx, ssl_hmac_get0_HMAC_CTX(hctx), 0); #endif if (rv < 0) { ret = SSL_TICKET_FATAL_ERR_OTHER; @@ -3263,6 +3146,8 @@ SSL_TICKET_STATUS tls_decrypt_ticket(SSL_CONNECTION *s, if (rv == 2) renew_ticket = 1; } else { + EVP_CIPHER *aes256cbc = NULL; + /* Check key name matches */ if (memcmp(etick, tctx->ext.tick_key_name, TLSEXT_KEYNAME_LENGTH) @@ -3271,16 +3156,22 @@ SSL_TICKET_STATUS tls_decrypt_ticket(SSL_CONNECTION *s, goto end; } - if (ssl_hmac_init(&hctx, tctx->ext.secure->tick_hmac_key, - sizeof(tctx->ext.secure->tick_hmac_key), "SHA256") + aes256cbc = EVP_CIPHER_fetch(sctx->libctx, "AES-256-CBC", + sctx->propq); + if (aes256cbc == NULL + || ssl_hmac_init(hctx, tctx->ext.secure->tick_hmac_key, + sizeof(tctx->ext.secure->tick_hmac_key), + "SHA256") <= 0 - || EVP_DecryptInit_ex(ctx, tctx->tktenc, NULL, + || EVP_DecryptInit_ex(ctx, aes256cbc, NULL, tctx->ext.secure->tick_aes_key, etick + TLSEXT_KEYNAME_LENGTH) <= 0) { + EVP_CIPHER_free(aes256cbc); ret = SSL_TICKET_FATAL_ERR_OTHER; goto end; } + EVP_CIPHER_free(aes256cbc); if (SSL_CONNECTION_IS_TLS13(s)) renew_ticket = 1; } @@ -3288,7 +3179,7 @@ SSL_TICKET_STATUS tls_decrypt_ticket(SSL_CONNECTION *s, * Attempt to process session ticket, first conduct sanity and integrity * checks on ticket. */ - mlen = ssl_hmac_size(&hctx); + mlen = ssl_hmac_size(hctx); if (mlen == 0) { ret = SSL_TICKET_FATAL_ERR_OTHER; goto end; @@ -3307,8 +3198,8 @@ SSL_TICKET_STATUS tls_decrypt_ticket(SSL_CONNECTION *s, } eticklen -= mlen; /* Check HMAC of encrypted ticket */ - if (ssl_hmac_update(&hctx, etick, eticklen) <= 0 - || ssl_hmac_final(&hctx, tick_hmac, NULL, sizeof(tick_hmac)) <= 0) { + if (ssl_hmac_update(hctx, etick, eticklen) <= 0 + || ssl_hmac_final(hctx, tick_hmac, NULL, sizeof(tick_hmac)) <= 0) { ret = SSL_TICKET_FATAL_ERR_OTHER; goto end; } @@ -3370,7 +3261,7 @@ SSL_TICKET_STATUS tls_decrypt_ticket(SSL_CONNECTION *s, end: EVP_CIPHER_CTX_free(ctx); - ssl_hmac_destruct(constructed_hctx); + ssl_hmac_free(hctx); /* * If set, the decrypt_ticket_cb() is called unless a fatal error was @@ -3495,7 +3386,7 @@ static int tls12_sigalg_allowed(const SSL_CONNECTION *s, int op, c = sk_SSL_CIPHER_value(sk, i); /* Skip disabled ciphers */ - if (ssl_cipher_disabled(s, c, SSL_SECOP_CIPHER_SUPPORTED)) + if (ssl_cipher_disabled(s, c, SSL_SECOP_CIPHER_SUPPORTED, 0)) continue; if ((c->algorithm_mkey & (SSL_kGOST | SSL_kGOST18)) != 0) @@ -3647,7 +3538,7 @@ static int tls1_set_shared_sigalgs(SSL_CONNECTION *s) return 1; } -int tls1_save_u16(PACKET *pkt, uint16_t **pdest, size_t *pdestlen, size_t maxnum) +int tls1_save_u16(PACKET *pkt, uint16_t **pdest, size_t *pdestlen) { unsigned int stmp; size_t size, i; @@ -3661,13 +3552,6 @@ int tls1_save_u16(PACKET *pkt, uint16_t **pdest, size_t *pdestlen, size_t maxnum size >>= 1; - /* - * We ignore any entries in the list larger than the maximum number we - * will accept. - */ - if (size > maxnum) - size = maxnum; - if ((buf = OPENSSL_malloc_array(size, sizeof(*buf))) == NULL) return 0; for (i = 0; i < size && PACKET_get_net_2(pkt, &stmp); i++) @@ -3694,16 +3578,12 @@ int tls1_save_sigalgs(SSL_CONNECTION *s, PACKET *pkt, int cert) if (s->cert == NULL) return 0; - /* - * We restrict the number of signature algorithms we are willing to process - * to 128. Any beyond this number are simply ignored. - */ if (cert) return tls1_save_u16(pkt, &s->s3.tmp.peer_cert_sigalgs, - &s->s3.tmp.peer_cert_sigalgslen, MAX_SIGALGS); + &s->s3.tmp.peer_cert_sigalgslen); else return tls1_save_u16(pkt, &s->s3.tmp.peer_sigalgs, - &s->s3.tmp.peer_sigalgslen, MAX_SIGALGS); + &s->s3.tmp.peer_sigalgslen); } /* Set preferred digest for each key type */ @@ -3739,20 +3619,22 @@ int SSL_get_sigalgs(SSL *s, int idx, unsigned char *rsig, unsigned char *rhash) { uint16_t *psig; - int numsigalgs; + size_t numsigalgs; SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); if (sc == NULL) return 0; - /* A TLS peer can't propose more sigalgs than would fit in an int. */ - numsigalgs = (int)sc->s3.tmp.peer_sigalgslen; - if (idx >= numsigalgs || (psig = sc->s3.tmp.peer_sigalgs) == NULL) - return 0; + psig = sc->s3.tmp.peer_sigalgs; + numsigalgs = sc->s3.tmp.peer_sigalgslen; + if (psig == NULL || numsigalgs > INT_MAX) + return 0; if (idx >= 0) { const SIGALG_LOOKUP *lu; + if (idx >= (int)numsigalgs) + return 0; psig += idx; if (rhash != NULL) *rhash = (unsigned char)((*psig >> 8) & 0xff); @@ -3798,57 +3680,6 @@ int SSL_get_shared_sigalgs(SSL *s, int idx, return (int)sc->shared_sigalgslen; } -int SSL_get0_sigalg(SSL *s, int idx, unsigned int *codepoint, - const char **name) -{ - SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); - const SIGALG_LOOKUP *lu; - uint16_t *psig; - int numsigalgs; - - if (sc == NULL) - return 0; - - /* A TLS peer can't propose more sigalgs than would fit in an int. */ - numsigalgs = (int)sc->s3.tmp.peer_sigalgslen; - if (idx >= numsigalgs || (psig = sc->s3.tmp.peer_sigalgs) == NULL) - return 0; - - if (idx >= 0) { - if (codepoint != NULL) - *codepoint = psig[idx]; - lu = tls1_find_sigalg(SSL_CONNECTION_GET_CTX(sc), psig[idx]); - if (name != NULL) - *name = lu == NULL ? NULL : lu->name; - } - return numsigalgs; -} - -int SSL_get0_shared_sigalg(SSL *s, int idx, unsigned int *codepoint, - const char **name) -{ - SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(s); - const SIGALG_LOOKUP *lu; - int numsigalgs; - - if (sc == NULL) - return 0; - - /* A TLS peer can't propose more sigalgs than would fit in an int. */ - numsigalgs = (int)sc->shared_sigalgslen; - if (idx >= numsigalgs || sc->shared_sigalgs == NULL) - return 0; - - if (idx >= 0) { - lu = sc->shared_sigalgs[idx]; - if (codepoint != NULL) - *codepoint = lu->sigalg; - if (name != NULL) - *name = lu->name; - } - return numsigalgs; -} - /* Maximum possible number of unique entries in sigalgs array */ #define TLS_MAX_SIGALGCNT (OSSL_NELEM(sigalg_lookup_tbl) * 2) @@ -4199,6 +4030,8 @@ int tls1_check_chain(SSL_CONNECTION *s, X509 *x, EVP_PKEY *pk, chain = cpk->chain; strict_mode = c->cert_flags & SSL_CERT_FLAGS_CHECK_TLS_STRICT; if (tls12_rpk_and_privkey(s, idx)) { + if (EVP_PKEY_is_a(pk, "EC") && !tls1_check_pkey_comp(s, pk)) + return 0; *pvalid = rv = CERT_PKEY_RPK; return rv; } @@ -4541,29 +4374,51 @@ static int ssl_security_cert_key(SSL_CONNECTION *s, SSL_CTX *ctx, X509 *x, return ssl_ctx_security(ctx, op, secbits, 0, x); } -int ssl_security_cert(SSL_CONNECTION *s, SSL_CTX *ctx, X509 *x, int is_ee) +static int ssl_security_cert_sig(SSL_CONNECTION *s, SSL_CTX *ctx, X509 *x, + int op) { + /* Lookup signature algorithm digest */ + int secbits, nid, pknid; + + /* Don't check signature if self signed */ + if ((X509_get_extension_flags(x) & EXFLAG_SS) != 0) + return 1; + if (!X509_get_signature_info(x, &nid, &pknid, &secbits, NULL)) + secbits = -1; + /* If digest NID not defined use signature NID */ + if (nid == NID_undef) + nid = pknid; + if (s != NULL) + return ssl_security(s, op, secbits, nid, x); + else + return ssl_ctx_security(ctx, op, secbits, nid, x); +} + +int ssl_security_cert(SSL_CONNECTION *s, SSL_CTX *ctx, X509 *x, int vfy, + int is_ee) +{ + if (vfy) + vfy = SSL_SECOP_PEER; if (is_ee) { - if (!ssl_security_cert_key(s, ctx, x, SSL_SECOP_EE_KEY)) + if (!ssl_security_cert_key(s, ctx, x, SSL_SECOP_EE_KEY | vfy)) return SSL_R_EE_KEY_TOO_SMALL; } else { - if (!ssl_security_cert_key(s, ctx, x, SSL_SECOP_CA_KEY)) + if (!ssl_security_cert_key(s, ctx, x, SSL_SECOP_CA_KEY | vfy)) return SSL_R_CA_KEY_TOO_SMALL; } + if (!ssl_security_cert_sig(s, ctx, x, SSL_SECOP_CA_MD | vfy)) + return SSL_R_CA_MD_TOO_WEAK; return 1; } /* - * Call ssl_security_check() on all certificates in a stack. - * If |x| is non NULL it is checked first, before checking the - * certificates in the stack. - * - * Return values: 1 if ok otherwise the error code from the first - * failing ssl_security_check().; + * Check security of a chain, if |sk| includes the end entity certificate then + * |x| is NULL. If |vfy| is 1 then we are verifying a peer chain and not sending + * one to the peer. Return values: 1 if ok otherwise error code to use */ int ssl_security_cert_chain(SSL_CONNECTION *s, STACK_OF(X509) *sk, - X509 *x) + X509 *x, int vfy) { int rv, start_idx, i; @@ -4575,13 +4430,13 @@ int ssl_security_cert_chain(SSL_CONNECTION *s, STACK_OF(X509) *sk, } else start_idx = 0; - rv = ssl_security_cert(s, NULL, x, 1); + rv = ssl_security_cert(s, NULL, x, vfy, 1); if (rv != 1) return rv; for (i = start_idx; i < sk_X509_num(sk); i++) { x = sk_X509_value(sk, i); - rv = ssl_security_cert(s, NULL, x, 0); + rv = ssl_security_cert(s, NULL, x, vfy, 0); if (rv != 1) return rv; } @@ -4924,7 +4779,7 @@ int SSL_CTX_set_tlsext_max_fragment_length(SSL_CTX *ctx, uint8_t mode) { if (mode != TLSEXT_max_fragment_length_DISABLED && !IS_MAX_FRAGMENT_LENGTH_EXT_VALID(mode)) { - ERR_raise(ERR_LIB_SSL, SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH); + ERR_raise(ERR_LIB_SSL, SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH); return 0; } @@ -4942,7 +4797,7 @@ int SSL_set_tlsext_max_fragment_length(SSL *ssl, uint8_t mode) if (mode != TLSEXT_max_fragment_length_DISABLED && !IS_MAX_FRAGMENT_LENGTH_EXT_VALID(mode)) { - ERR_raise(ERR_LIB_SSL, SSL_R_TLS_EXT_INVALID_MAX_FRAGMENT_LENGTH); + ERR_raise(ERR_LIB_SSL, SSL_R_SSL3_EXT_INVALID_MAX_FRAGMENT_LENGTH); return 0; } @@ -4960,28 +4815,41 @@ uint8_t SSL_SESSION_get_max_fragment_length(const SSL_SESSION *session) /* * Helper functions for HMAC access with legacy support included. */ -SSL_HMAC *ssl_hmac_construct(const SSL_CTX *ctx, SSL_HMAC *hctx) +SSL_HMAC *ssl_hmac_new(const SSL_CTX *ctx) { - if (hctx == NULL) + SSL_HMAC *ret = OPENSSL_zalloc(sizeof(*ret)); + EVP_MAC *mac = NULL; + + if (ret == NULL) return NULL; - hctx->ctx = NULL; #ifndef OPENSSL_NO_DEPRECATED_3_0 - hctx->old_ctx = NULL; if (ctx->ext.ticket_key_evp_cb == NULL - && ctx->ext.ticket_key_cb != NULL) - return ssl_hmac_old_construct(hctx); + && ctx->ext.ticket_key_cb != NULL) { + if (!ssl_hmac_old_new(ret)) + goto err; + return ret; + } #endif - hctx->ctx = EVP_MAC_CTX_new(ctx->hmac); - return hctx->ctx != NULL ? hctx : NULL; + mac = EVP_MAC_fetch(ctx->libctx, "HMAC", ctx->propq); + if (mac == NULL || (ret->ctx = EVP_MAC_CTX_new(mac)) == NULL) + goto err; + EVP_MAC_free(mac); + return ret; +err: + EVP_MAC_CTX_free(ret->ctx); + EVP_MAC_free(mac); + OPENSSL_free(ret); + return NULL; } -void ssl_hmac_destruct(SSL_HMAC *ctx) +void ssl_hmac_free(SSL_HMAC *ctx) { if (ctx != NULL) { EVP_MAC_CTX_free(ctx->ctx); #ifndef OPENSSL_NO_DEPRECATED_3_0 - ssl_hmac_old_destruct(ctx); + ssl_hmac_old_free(ctx); #endif + OPENSSL_free(ctx); } } diff --git a/ssl/t1_trce.c b/ssl/t1_trce.c index 0e8ddbb8f8..d29c1918e9 100644 --- a/ssl/t1_trce.c +++ b/ssl/t1_trce.c @@ -1,5 +1,5 @@ /* - * Copyright 2012-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2012-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -63,6 +63,7 @@ static int do_ssl_trace_list(BIO *bio, int indent, /* Version number */ static const ssl_trace_tbl ssl_version_tbl[] = { + { SSL3_VERSION, "SSL 3.0" }, { TLS1_VERSION, "TLS 1.0" }, { TLS1_1_VERSION, "TLS 1.1" }, { TLS1_2_VERSION, "TLS 1.2" }, @@ -109,16 +110,16 @@ static const ssl_trace_tbl ssl_handshake_tbl[] = { /* Cipher suites */ static const ssl_trace_tbl ssl_ciphers_tbl[] = { { 0x0000, "TLS_NULL_WITH_NULL_NULL" }, - { 0x0001, SSL3_RFC_RSA_NULL_MD5 }, - { 0x0002, SSL3_RFC_RSA_NULL_SHA }, + { 0x0001, "TLS_RSA_WITH_NULL_MD5" }, + { 0x0002, "TLS_RSA_WITH_NULL_SHA" }, { 0x0003, "TLS_RSA_EXPORT_WITH_RC4_40_MD5" }, - { 0x0004, SSL3_RFC_RSA_RC4_128_MD5 }, - { 0x0005, SSL3_RFC_RSA_RC4_128_SHA }, + { 0x0004, "TLS_RSA_WITH_RC4_128_MD5" }, + { 0x0005, "TLS_RSA_WITH_RC4_128_SHA" }, { 0x0006, "TLS_RSA_EXPORT_WITH_RC2_CBC_40_MD5" }, - { 0x0007, SSL3_RFC_RSA_IDEA_128_SHA }, + { 0x0007, "TLS_RSA_WITH_IDEA_CBC_SHA" }, { 0x0008, "TLS_RSA_EXPORT_WITH_DES40_CBC_SHA" }, { 0x0009, "TLS_RSA_WITH_DES_CBC_SHA" }, - { 0x000A, SSL3_RFC_RSA_DES_192_CBC3_SHA }, + { 0x000A, "TLS_RSA_WITH_3DES_EDE_CBC_SHA" }, { 0x000B, "TLS_DH_DSS_EXPORT_WITH_DES40_CBC_SHA" }, { 0x000C, "TLS_DH_DSS_WITH_DES_CBC_SHA" }, { 0x000D, "TLS_DH_DSS_WITH_3DES_EDE_CBC_SHA" }, @@ -127,15 +128,15 @@ static const ssl_trace_tbl ssl_ciphers_tbl[] = { { 0x0010, "TLS_DH_RSA_WITH_3DES_EDE_CBC_SHA" }, { 0x0011, "TLS_DHE_DSS_EXPORT_WITH_DES40_CBC_SHA" }, { 0x0012, "TLS_DHE_DSS_WITH_DES_CBC_SHA" }, - { 0x0013, SSL3_RFC_DHE_DSS_DES_192_CBC3_SHA }, + { 0x0013, "TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA" }, { 0x0014, "TLS_DHE_RSA_EXPORT_WITH_DES40_CBC_SHA" }, { 0x0015, "TLS_DHE_RSA_WITH_DES_CBC_SHA" }, - { 0x0016, SSL3_RFC_DHE_RSA_DES_192_CBC3_SHA }, + { 0x0016, "TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA" }, { 0x0017, "TLS_DH_anon_EXPORT_WITH_RC4_40_MD5" }, - { 0x0018, SSL3_RFC_ADH_RC4_128_MD5 }, + { 0x0018, "TLS_DH_anon_WITH_RC4_128_MD5" }, { 0x0019, "TLS_DH_anon_EXPORT_WITH_DES40_CBC_SHA" }, { 0x001A, "TLS_DH_anon_WITH_DES_CBC_SHA" }, - { 0x001B, SSL3_RFC_ADH_DES_192_CBC_SHA }, + { 0x001B, "TLS_DH_anon_WITH_3DES_EDE_CBC_SHA" }, { 0x001D, "SSL_FORTEZZA_KEA_WITH_FORTEZZA_CBC_SHA" }, { 0x001E, "SSL_FORTEZZA_KEA_WITH_RC4_128_SHA" }, { 0x001F, "TLS_KRB5_WITH_3DES_EDE_CBC_SHA" }, @@ -151,110 +152,108 @@ static const ssl_trace_tbl ssl_ciphers_tbl[] = { { 0x0029, "TLS_KRB5_EXPORT_WITH_DES_CBC_40_MD5" }, { 0x002A, "TLS_KRB5_EXPORT_WITH_RC2_CBC_40_MD5" }, { 0x002B, "TLS_KRB5_EXPORT_WITH_RC4_40_MD5" }, - { 0x002C, TLS1_RFC_PSK_WITH_NULL_SHA }, - { 0x002D, TLS1_RFC_DHE_PSK_WITH_NULL_SHA }, - { 0x002E, TLS1_RFC_RSA_PSK_WITH_NULL_SHA }, - { 0x002F, TLS1_RFC_RSA_WITH_AES_128_SHA }, + { 0x002C, "TLS_PSK_WITH_NULL_SHA" }, + { 0x002D, "TLS_DHE_PSK_WITH_NULL_SHA" }, + { 0x002E, "TLS_RSA_PSK_WITH_NULL_SHA" }, + { 0x002F, "TLS_RSA_WITH_AES_128_CBC_SHA" }, { 0x0030, "TLS_DH_DSS_WITH_AES_128_CBC_SHA" }, { 0x0031, "TLS_DH_RSA_WITH_AES_128_CBC_SHA" }, - { 0x0032, TLS1_RFC_DHE_DSS_WITH_AES_128_SHA }, - { 0x0033, TLS1_RFC_DHE_RSA_WITH_AES_128_SHA }, - { 0x0034, TLS1_RFC_ADH_WITH_AES_128_SHA }, - { 0x0035, TLS1_RFC_RSA_WITH_AES_256_SHA }, + { 0x0032, "TLS_DHE_DSS_WITH_AES_128_CBC_SHA" }, + { 0x0033, "TLS_DHE_RSA_WITH_AES_128_CBC_SHA" }, + { 0x0034, "TLS_DH_anon_WITH_AES_128_CBC_SHA" }, + { 0x0035, "TLS_RSA_WITH_AES_256_CBC_SHA" }, { 0x0036, "TLS_DH_DSS_WITH_AES_256_CBC_SHA" }, { 0x0037, "TLS_DH_RSA_WITH_AES_256_CBC_SHA" }, - { 0x0038, TLS1_RFC_DHE_DSS_WITH_AES_256_SHA }, - { 0x0039, TLS1_RFC_DHE_RSA_WITH_AES_256_SHA }, - { 0x003A, TLS1_RFC_ADH_WITH_AES_256_SHA }, - { 0x003B, TLS1_RFC_RSA_WITH_NULL_SHA256 }, - { 0x003C, TLS1_RFC_RSA_WITH_AES_128_SHA256 }, - { 0x003D, TLS1_RFC_RSA_WITH_AES_256_SHA256 }, + { 0x0038, "TLS_DHE_DSS_WITH_AES_256_CBC_SHA" }, + { 0x0039, "TLS_DHE_RSA_WITH_AES_256_CBC_SHA" }, + { 0x003A, "TLS_DH_anon_WITH_AES_256_CBC_SHA" }, + { 0x003B, "TLS_RSA_WITH_NULL_SHA256" }, + { 0x003C, "TLS_RSA_WITH_AES_128_CBC_SHA256" }, + { 0x003D, "TLS_RSA_WITH_AES_256_CBC_SHA256" }, { 0x003E, "TLS_DH_DSS_WITH_AES_128_CBC_SHA256" }, { 0x003F, "TLS_DH_RSA_WITH_AES_128_CBC_SHA256" }, - { 0x0040, TLS1_RFC_DHE_DSS_WITH_AES_128_SHA256 }, - { 0x0041, TLS1_RFC_RSA_WITH_CAMELLIA_128_CBC_SHA }, + { 0x0040, "TLS_DHE_DSS_WITH_AES_128_CBC_SHA256" }, + { 0x0041, "TLS_RSA_WITH_CAMELLIA_128_CBC_SHA" }, { 0x0042, "TLS_DH_DSS_WITH_CAMELLIA_128_CBC_SHA" }, { 0x0043, "TLS_DH_RSA_WITH_CAMELLIA_128_CBC_SHA" }, - { 0x0044, TLS1_RFC_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA }, - { 0x0045, TLS1_RFC_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA }, - { 0x0046, TLS1_RFC_ADH_WITH_CAMELLIA_128_CBC_SHA }, - { 0x0067, TLS1_RFC_DHE_RSA_WITH_AES_128_SHA256 }, + { 0x0044, "TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA" }, + { 0x0045, "TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA" }, + { 0x0046, "TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA" }, + { 0x0067, "TLS_DHE_RSA_WITH_AES_128_CBC_SHA256" }, { 0x0068, "TLS_DH_DSS_WITH_AES_256_CBC_SHA256" }, { 0x0069, "TLS_DH_RSA_WITH_AES_256_CBC_SHA256" }, - { 0x006A, TLS1_RFC_DHE_DSS_WITH_AES_256_SHA256 }, - { 0x006B, TLS1_RFC_DHE_RSA_WITH_AES_256_SHA256 }, - { 0x006C, TLS1_RFC_ADH_WITH_AES_128_SHA256 }, - { 0x006D, TLS1_RFC_ADH_WITH_AES_256_SHA256 }, + { 0x006A, "TLS_DHE_DSS_WITH_AES_256_CBC_SHA256" }, + { 0x006B, "TLS_DHE_RSA_WITH_AES_256_CBC_SHA256" }, + { 0x006C, "TLS_DH_anon_WITH_AES_128_CBC_SHA256" }, + { 0x006D, "TLS_DH_anon_WITH_AES_256_CBC_SHA256" }, { 0x0081, "TLS_GOSTR341001_WITH_28147_CNT_IMIT" }, { 0x0083, "TLS_GOSTR341001_WITH_NULL_GOSTR3411" }, - { 0x0084, TLS1_RFC_RSA_WITH_CAMELLIA_256_CBC_SHA }, + { 0x0084, "TLS_RSA_WITH_CAMELLIA_256_CBC_SHA" }, { 0x0085, "TLS_DH_DSS_WITH_CAMELLIA_256_CBC_SHA" }, { 0x0086, "TLS_DH_RSA_WITH_CAMELLIA_256_CBC_SHA" }, - { 0x0087, TLS1_RFC_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA }, - { 0x0088, TLS1_RFC_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA }, - { 0x0089, TLS1_RFC_ADH_WITH_CAMELLIA_256_CBC_SHA }, - { 0x008A, TLS1_RFC_PSK_WITH_RC4_128_SHA }, - { 0x008B, TLS1_RFC_PSK_WITH_3DES_EDE_CBC_SHA }, - { 0x008C, TLS1_RFC_PSK_WITH_AES_128_CBC_SHA }, - { 0x008D, TLS1_RFC_PSK_WITH_AES_256_CBC_SHA }, - { 0x008E, TLS1_RFC_DHE_PSK_WITH_RC4_128_SHA }, - { 0x008F, TLS1_RFC_DHE_PSK_WITH_3DES_EDE_CBC_SHA }, - { 0x0090, TLS1_RFC_DHE_PSK_WITH_AES_128_CBC_SHA }, - { 0x0091, TLS1_RFC_DHE_PSK_WITH_AES_256_CBC_SHA }, - { 0x0092, TLS1_RFC_RSA_PSK_WITH_RC4_128_SHA }, - { 0x0093, TLS1_RFC_RSA_PSK_WITH_3DES_EDE_CBC_SHA }, - { 0x0094, TLS1_RFC_RSA_PSK_WITH_AES_128_CBC_SHA }, - { 0x0095, TLS1_RFC_RSA_PSK_WITH_AES_256_CBC_SHA }, - { 0x0096, TLS1_RFC_RSA_WITH_SEED_SHA }, + { 0x0087, "TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA" }, + { 0x0088, "TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA" }, + { 0x0089, "TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA" }, + { 0x008A, "TLS_PSK_WITH_RC4_128_SHA" }, + { 0x008B, "TLS_PSK_WITH_3DES_EDE_CBC_SHA" }, + { 0x008C, "TLS_PSK_WITH_AES_128_CBC_SHA" }, + { 0x008D, "TLS_PSK_WITH_AES_256_CBC_SHA" }, + { 0x008E, "TLS_DHE_PSK_WITH_RC4_128_SHA" }, + { 0x008F, "TLS_DHE_PSK_WITH_3DES_EDE_CBC_SHA" }, + { 0x0090, "TLS_DHE_PSK_WITH_AES_128_CBC_SHA" }, + { 0x0091, "TLS_DHE_PSK_WITH_AES_256_CBC_SHA" }, + { 0x0092, "TLS_RSA_PSK_WITH_RC4_128_SHA" }, + { 0x0093, "TLS_RSA_PSK_WITH_3DES_EDE_CBC_SHA" }, + { 0x0094, "TLS_RSA_PSK_WITH_AES_128_CBC_SHA" }, + { 0x0095, "TLS_RSA_PSK_WITH_AES_256_CBC_SHA" }, + { 0x0096, "TLS_RSA_WITH_SEED_CBC_SHA" }, { 0x0097, "TLS_DH_DSS_WITH_SEED_CBC_SHA" }, { 0x0098, "TLS_DH_RSA_WITH_SEED_CBC_SHA" }, - { 0x0099, TLS1_RFC_DHE_DSS_WITH_SEED_SHA }, - { 0x009A, TLS1_RFC_DHE_RSA_WITH_SEED_SHA }, - { 0x009B, TLS1_RFC_ADH_WITH_SEED_SHA }, - { 0x009C, TLS1_RFC_RSA_WITH_AES_128_GCM_SHA256 }, - { 0x009D, TLS1_RFC_RSA_WITH_AES_256_GCM_SHA384 }, - { 0x009E, TLS1_RFC_DHE_RSA_WITH_AES_128_GCM_SHA256 }, - { 0x009F, TLS1_RFC_DHE_RSA_WITH_AES_256_GCM_SHA384 }, + { 0x0099, "TLS_DHE_DSS_WITH_SEED_CBC_SHA" }, + { 0x009A, "TLS_DHE_RSA_WITH_SEED_CBC_SHA" }, + { 0x009B, "TLS_DH_anon_WITH_SEED_CBC_SHA" }, + { 0x009C, "TLS_RSA_WITH_AES_128_GCM_SHA256" }, + { 0x009D, "TLS_RSA_WITH_AES_256_GCM_SHA384" }, + { 0x009E, "TLS_DHE_RSA_WITH_AES_128_GCM_SHA256" }, + { 0x009F, "TLS_DHE_RSA_WITH_AES_256_GCM_SHA384" }, { 0x00A0, "TLS_DH_RSA_WITH_AES_128_GCM_SHA256" }, { 0x00A1, "TLS_DH_RSA_WITH_AES_256_GCM_SHA384" }, - { 0x00A2, TLS1_RFC_DHE_DSS_WITH_AES_128_GCM_SHA256 }, - { 0x00A3, TLS1_RFC_DHE_DSS_WITH_AES_256_GCM_SHA384 }, + { 0x00A2, "TLS_DHE_DSS_WITH_AES_128_GCM_SHA256" }, + { 0x00A3, "TLS_DHE_DSS_WITH_AES_256_GCM_SHA384" }, { 0x00A4, "TLS_DH_DSS_WITH_AES_128_GCM_SHA256" }, { 0x00A5, "TLS_DH_DSS_WITH_AES_256_GCM_SHA384" }, - { 0x00A6, TLS1_RFC_ADH_WITH_AES_128_GCM_SHA256 }, - { 0x00A7, TLS1_RFC_ADH_WITH_AES_256_GCM_SHA384 }, - { 0x00A8, TLS1_RFC_PSK_WITH_AES_128_GCM_SHA256 }, - { 0x00A9, TLS1_RFC_PSK_WITH_AES_256_GCM_SHA384 }, - { 0x00AA, TLS1_RFC_DHE_PSK_WITH_AES_128_GCM_SHA256 }, - { 0x00AB, TLS1_RFC_DHE_PSK_WITH_AES_256_GCM_SHA384 }, - { 0x00AC, TLS1_RFC_RSA_PSK_WITH_AES_128_GCM_SHA256 }, - { 0x00AD, TLS1_RFC_RSA_PSK_WITH_AES_256_GCM_SHA384 }, - { 0x00AE, TLS1_RFC_PSK_WITH_AES_128_CBC_SHA256 }, - { 0x00AF, TLS1_RFC_PSK_WITH_AES_256_CBC_SHA384 }, - { 0x00B0, TLS1_RFC_PSK_WITH_NULL_SHA256 }, - { 0x00B1, TLS1_RFC_PSK_WITH_NULL_SHA384 }, - { 0x00B2, TLS1_RFC_DHE_PSK_WITH_AES_128_CBC_SHA256 }, - { 0x00B3, TLS1_RFC_DHE_PSK_WITH_AES_256_CBC_SHA384 }, - { 0x00B4, TLS1_RFC_DHE_PSK_WITH_NULL_SHA256 }, - { 0x00B5, TLS1_RFC_DHE_PSK_WITH_NULL_SHA384 }, - { 0x00B6, TLS1_RFC_RSA_PSK_WITH_AES_128_CBC_SHA256 }, - { 0x00B7, TLS1_RFC_RSA_PSK_WITH_AES_256_CBC_SHA384 }, - { 0x00B8, TLS1_RFC_RSA_PSK_WITH_NULL_SHA256 }, - { 0x00B9, TLS1_RFC_RSA_PSK_WITH_NULL_SHA384 }, - { 0x00BA, TLS1_RFC_RSA_WITH_CAMELLIA_128_CBC_SHA256 }, + { 0x00A6, "TLS_DH_anon_WITH_AES_128_GCM_SHA256" }, + { 0x00A7, "TLS_DH_anon_WITH_AES_256_GCM_SHA384" }, + { 0x00A8, "TLS_PSK_WITH_AES_128_GCM_SHA256" }, + { 0x00A9, "TLS_PSK_WITH_AES_256_GCM_SHA384" }, + { 0x00AA, "TLS_DHE_PSK_WITH_AES_128_GCM_SHA256" }, + { 0x00AB, "TLS_DHE_PSK_WITH_AES_256_GCM_SHA384" }, + { 0x00AC, "TLS_RSA_PSK_WITH_AES_128_GCM_SHA256" }, + { 0x00AD, "TLS_RSA_PSK_WITH_AES_256_GCM_SHA384" }, + { 0x00AE, "TLS_PSK_WITH_AES_128_CBC_SHA256" }, + { 0x00AF, "TLS_PSK_WITH_AES_256_CBC_SHA384" }, + { 0x00B0, "TLS_PSK_WITH_NULL_SHA256" }, + { 0x00B1, "TLS_PSK_WITH_NULL_SHA384" }, + { 0x00B2, "TLS_DHE_PSK_WITH_AES_128_CBC_SHA256" }, + { 0x00B3, "TLS_DHE_PSK_WITH_AES_256_CBC_SHA384" }, + { 0x00B4, "TLS_DHE_PSK_WITH_NULL_SHA256" }, + { 0x00B5, "TLS_DHE_PSK_WITH_NULL_SHA384" }, + { 0x00B6, "TLS_RSA_PSK_WITH_AES_128_CBC_SHA256" }, + { 0x00B7, "TLS_RSA_PSK_WITH_AES_256_CBC_SHA384" }, + { 0x00B8, "TLS_RSA_PSK_WITH_NULL_SHA256" }, + { 0x00B9, "TLS_RSA_PSK_WITH_NULL_SHA384" }, + { 0x00BA, "TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256" }, { 0x00BB, "TLS_DH_DSS_WITH_CAMELLIA_128_CBC_SHA256" }, { 0x00BC, "TLS_DH_RSA_WITH_CAMELLIA_128_CBC_SHA256" }, - { 0x00BD, TLS1_RFC_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA256 }, - { 0x00BE, TLS1_RFC_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 }, - { 0x00BF, TLS1_RFC_ADH_WITH_CAMELLIA_128_CBC_SHA256 }, - { 0x00C0, TLS1_RFC_RSA_WITH_CAMELLIA_256_CBC_SHA256 }, + { 0x00BD, "TLS_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA256" }, + { 0x00BE, "TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256" }, + { 0x00BF, "TLS_DH_anon_WITH_CAMELLIA_128_CBC_SHA256" }, + { 0x00C0, "TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256" }, { 0x00C1, "TLS_DH_DSS_WITH_CAMELLIA_256_CBC_SHA256" }, { 0x00C2, "TLS_DH_RSA_WITH_CAMELLIA_256_CBC_SHA256" }, - { 0x00C3, TLS1_RFC_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA256 }, - { 0x00C4, TLS1_RFC_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256 }, - { 0x00C5, TLS1_RFC_ADH_WITH_CAMELLIA_256_CBC_SHA256 }, - { 0x00C6, TLS1_3_RFC_SM4_GCM_SM3 }, - { 0x00C7, TLS1_3_RFC_SM4_CCM_SM3 }, + { 0x00C3, "TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA256" }, + { 0x00C4, "TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256" }, + { 0x00C5, "TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA256" }, { 0x00FF, "TLS_EMPTY_RENEGOTIATION_INFO_SCSV" }, { 0x5600, "TLS_FALLBACK_SCSV" }, { 0xC001, "TLS_ECDH_ECDSA_WITH_NULL_SHA" }, @@ -262,60 +261,60 @@ static const ssl_trace_tbl ssl_ciphers_tbl[] = { { 0xC003, "TLS_ECDH_ECDSA_WITH_3DES_EDE_CBC_SHA" }, { 0xC004, "TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA" }, { 0xC005, "TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA" }, - { 0xC006, TLS1_RFC_ECDHE_ECDSA_WITH_NULL_SHA }, - { 0xC007, TLS1_RFC_ECDHE_ECDSA_WITH_RC4_128_SHA }, - { 0xC008, TLS1_RFC_ECDHE_ECDSA_WITH_DES_192_CBC3_SHA }, - { 0xC009, TLS1_RFC_ECDHE_ECDSA_WITH_AES_128_CBC_SHA }, - { 0xC00A, TLS1_RFC_ECDHE_ECDSA_WITH_AES_256_CBC_SHA }, + { 0xC006, "TLS_ECDHE_ECDSA_WITH_NULL_SHA" }, + { 0xC007, "TLS_ECDHE_ECDSA_WITH_RC4_128_SHA" }, + { 0xC008, "TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA" }, + { 0xC009, "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA" }, + { 0xC00A, "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA" }, { 0xC00B, "TLS_ECDH_RSA_WITH_NULL_SHA" }, { 0xC00C, "TLS_ECDH_RSA_WITH_RC4_128_SHA" }, { 0xC00D, "TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA" }, { 0xC00E, "TLS_ECDH_RSA_WITH_AES_128_CBC_SHA" }, { 0xC00F, "TLS_ECDH_RSA_WITH_AES_256_CBC_SHA" }, - { 0xC010, TLS1_RFC_ECDHE_RSA_WITH_NULL_SHA }, - { 0xC011, TLS1_RFC_ECDHE_RSA_WITH_RC4_128_SHA }, - { 0xC012, TLS1_RFC_ECDHE_RSA_WITH_DES_192_CBC3_SHA }, - { 0xC013, TLS1_RFC_ECDHE_RSA_WITH_AES_128_CBC_SHA }, - { 0xC014, TLS1_RFC_ECDHE_RSA_WITH_AES_256_CBC_SHA }, - { 0xC015, TLS1_RFC_ECDH_anon_WITH_NULL_SHA }, - { 0xC016, TLS1_RFC_ECDH_anon_WITH_RC4_128_SHA }, - { 0xC017, TLS1_RFC_ECDH_anon_WITH_DES_192_CBC3_SHA }, - { 0xC018, TLS1_RFC_ECDH_anon_WITH_AES_128_CBC_SHA }, - { 0xC019, TLS1_RFC_ECDH_anon_WITH_AES_256_CBC_SHA }, - { 0xC01A, TLS1_RFC_SRP_SHA_WITH_3DES_EDE_CBC_SHA }, - { 0xC01B, TLS1_RFC_SRP_SHA_RSA_WITH_3DES_EDE_CBC_SHA }, - { 0xC01C, TLS1_RFC_SRP_SHA_DSS_WITH_3DES_EDE_CBC_SHA }, - { 0xC01D, TLS1_RFC_SRP_SHA_WITH_AES_128_CBC_SHA }, - { 0xC01E, TLS1_RFC_SRP_SHA_RSA_WITH_AES_128_CBC_SHA }, - { 0xC01F, TLS1_RFC_SRP_SHA_DSS_WITH_AES_128_CBC_SHA }, - { 0xC020, TLS1_RFC_SRP_SHA_WITH_AES_256_CBC_SHA }, - { 0xC021, TLS1_RFC_SRP_SHA_RSA_WITH_AES_256_CBC_SHA }, - { 0xC022, TLS1_RFC_SRP_SHA_DSS_WITH_AES_256_CBC_SHA }, - { 0xC023, TLS1_RFC_ECDHE_ECDSA_WITH_AES_128_SHA256 }, - { 0xC024, TLS1_RFC_ECDHE_ECDSA_WITH_AES_256_SHA384 }, + { 0xC010, "TLS_ECDHE_RSA_WITH_NULL_SHA" }, + { 0xC011, "TLS_ECDHE_RSA_WITH_RC4_128_SHA" }, + { 0xC012, "TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA" }, + { 0xC013, "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA" }, + { 0xC014, "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA" }, + { 0xC015, "TLS_ECDH_anon_WITH_NULL_SHA" }, + { 0xC016, "TLS_ECDH_anon_WITH_RC4_128_SHA" }, + { 0xC017, "TLS_ECDH_anon_WITH_3DES_EDE_CBC_SHA" }, + { 0xC018, "TLS_ECDH_anon_WITH_AES_128_CBC_SHA" }, + { 0xC019, "TLS_ECDH_anon_WITH_AES_256_CBC_SHA" }, + { 0xC01A, "TLS_SRP_SHA_WITH_3DES_EDE_CBC_SHA" }, + { 0xC01B, "TLS_SRP_SHA_RSA_WITH_3DES_EDE_CBC_SHA" }, + { 0xC01C, "TLS_SRP_SHA_DSS_WITH_3DES_EDE_CBC_SHA" }, + { 0xC01D, "TLS_SRP_SHA_WITH_AES_128_CBC_SHA" }, + { 0xC01E, "TLS_SRP_SHA_RSA_WITH_AES_128_CBC_SHA" }, + { 0xC01F, "TLS_SRP_SHA_DSS_WITH_AES_128_CBC_SHA" }, + { 0xC020, "TLS_SRP_SHA_WITH_AES_256_CBC_SHA" }, + { 0xC021, "TLS_SRP_SHA_RSA_WITH_AES_256_CBC_SHA" }, + { 0xC022, "TLS_SRP_SHA_DSS_WITH_AES_256_CBC_SHA" }, + { 0xC023, "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256" }, + { 0xC024, "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384" }, { 0xC025, "TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256" }, { 0xC026, "TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384" }, - { 0xC027, TLS1_RFC_ECDHE_RSA_WITH_AES_128_SHA256 }, - { 0xC028, TLS1_RFC_ECDHE_RSA_WITH_AES_256_SHA384 }, + { 0xC027, "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256" }, + { 0xC028, "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384" }, { 0xC029, "TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256" }, { 0xC02A, "TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384" }, - { 0xC02B, TLS1_RFC_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 }, - { 0xC02C, TLS1_RFC_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 }, + { 0xC02B, "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256" }, + { 0xC02C, "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384" }, { 0xC02D, "TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256" }, { 0xC02E, "TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384" }, - { 0xC02F, TLS1_RFC_ECDHE_RSA_WITH_AES_128_GCM_SHA256 }, - { 0xC030, TLS1_RFC_ECDHE_RSA_WITH_AES_256_GCM_SHA384 }, + { 0xC02F, "TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256" }, + { 0xC030, "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384" }, { 0xC031, "TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256" }, { 0xC032, "TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384" }, - { 0xC033, TLS1_RFC_ECDHE_PSK_WITH_RC4_128_SHA }, - { 0xC034, TLS1_RFC_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA }, - { 0xC035, TLS1_RFC_ECDHE_PSK_WITH_AES_128_CBC_SHA }, - { 0xC036, TLS1_RFC_ECDHE_PSK_WITH_AES_256_CBC_SHA }, - { 0xC037, TLS1_RFC_ECDHE_PSK_WITH_AES_128_CBC_SHA256 }, - { 0xC038, TLS1_RFC_ECDHE_PSK_WITH_AES_256_CBC_SHA384 }, - { 0xC039, TLS1_RFC_ECDHE_PSK_WITH_NULL_SHA }, - { 0xC03A, TLS1_RFC_ECDHE_PSK_WITH_NULL_SHA256 }, - { 0xC03B, TLS1_RFC_ECDHE_PSK_WITH_NULL_SHA384 }, + { 0xC033, "TLS_ECDHE_PSK_WITH_RC4_128_SHA" }, + { 0xC034, "TLS_ECDHE_PSK_WITH_3DES_EDE_CBC_SHA" }, + { 0xC035, "TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA" }, + { 0xC036, "TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA" }, + { 0xC037, "TLS_ECDHE_PSK_WITH_AES_128_CBC_SHA256" }, + { 0xC038, "TLS_ECDHE_PSK_WITH_AES_256_CBC_SHA384" }, + { 0xC039, "TLS_ECDHE_PSK_WITH_NULL_SHA" }, + { 0xC03A, "TLS_ECDHE_PSK_WITH_NULL_SHA256" }, + { 0xC03B, "TLS_ECDHE_PSK_WITH_NULL_SHA384" }, { 0xC03C, "TLS_RSA_WITH_ARIA_128_CBC_SHA256" }, { 0xC03D, "TLS_RSA_WITH_ARIA_256_CBC_SHA384" }, { 0xC03E, "TLS_DH_DSS_WITH_ARIA_128_CBC_SHA256" }, @@ -336,46 +335,46 @@ static const ssl_trace_tbl ssl_ciphers_tbl[] = { { 0xC04D, "TLS_ECDHE_RSA_WITH_ARIA_256_CBC_SHA384" }, { 0xC04E, "TLS_ECDH_RSA_WITH_ARIA_128_CBC_SHA256" }, { 0xC04F, "TLS_ECDH_RSA_WITH_ARIA_256_CBC_SHA384" }, - { 0xC050, TLS1_RFC_RSA_WITH_ARIA_128_GCM_SHA256 }, - { 0xC051, TLS1_RFC_RSA_WITH_ARIA_256_GCM_SHA384 }, - { 0xC052, TLS1_RFC_DHE_RSA_WITH_ARIA_128_GCM_SHA256 }, - { 0xC053, TLS1_RFC_DHE_RSA_WITH_ARIA_256_GCM_SHA384 }, - { 0xC054, TLS1_RFC_DH_RSA_WITH_ARIA_128_GCM_SHA256 }, - { 0xC055, TLS1_RFC_DH_RSA_WITH_ARIA_256_GCM_SHA384 }, - { 0xC056, TLS1_RFC_DHE_DSS_WITH_ARIA_128_GCM_SHA256 }, - { 0xC057, TLS1_RFC_DHE_DSS_WITH_ARIA_256_GCM_SHA384 }, - { 0xC058, TLS1_RFC_DH_DSS_WITH_ARIA_128_GCM_SHA256 }, - { 0xC059, TLS1_RFC_DH_DSS_WITH_ARIA_256_GCM_SHA384 }, - { 0xC05A, TLS1_RFC_DH_anon_WITH_ARIA_128_GCM_SHA256 }, - { 0xC05B, TLS1_RFC_DH_anon_WITH_ARIA_256_GCM_SHA384 }, - { 0xC05C, TLS1_RFC_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256 }, - { 0xC05D, TLS1_RFC_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384 }, - { 0xC05E, TLS1_RFC_ECDH_ECDSA_WITH_ARIA_128_GCM_SHA256 }, - { 0xC05F, TLS1_RFC_ECDH_ECDSA_WITH_ARIA_256_GCM_SHA384 }, - { 0xC060, TLS1_RFC_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256 }, - { 0xC061, TLS1_RFC_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384 }, - { 0xC062, TLS1_RFC_ECDH_RSA_WITH_ARIA_128_GCM_SHA256 }, - { 0xC063, TLS1_RFC_ECDH_RSA_WITH_ARIA_256_GCM_SHA384 }, + { 0xC050, "TLS_RSA_WITH_ARIA_128_GCM_SHA256" }, + { 0xC051, "TLS_RSA_WITH_ARIA_256_GCM_SHA384" }, + { 0xC052, "TLS_DHE_RSA_WITH_ARIA_128_GCM_SHA256" }, + { 0xC053, "TLS_DHE_RSA_WITH_ARIA_256_GCM_SHA384" }, + { 0xC054, "TLS_DH_RSA_WITH_ARIA_128_GCM_SHA256" }, + { 0xC055, "TLS_DH_RSA_WITH_ARIA_256_GCM_SHA384" }, + { 0xC056, "TLS_DHE_DSS_WITH_ARIA_128_GCM_SHA256" }, + { 0xC057, "TLS_DHE_DSS_WITH_ARIA_256_GCM_SHA384" }, + { 0xC058, "TLS_DH_DSS_WITH_ARIA_128_GCM_SHA256" }, + { 0xC059, "TLS_DH_DSS_WITH_ARIA_256_GCM_SHA384" }, + { 0xC05A, "TLS_DH_anon_WITH_ARIA_128_GCM_SHA256" }, + { 0xC05B, "TLS_DH_anon_WITH_ARIA_256_GCM_SHA384" }, + { 0xC05C, "TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256" }, + { 0xC05D, "TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384" }, + { 0xC05E, "TLS_ECDH_ECDSA_WITH_ARIA_128_GCM_SHA256" }, + { 0xC05F, "TLS_ECDH_ECDSA_WITH_ARIA_256_GCM_SHA384" }, + { 0xC060, "TLS_ECDHE_RSA_WITH_ARIA_128_GCM_SHA256" }, + { 0xC061, "TLS_ECDHE_RSA_WITH_ARIA_256_GCM_SHA384" }, + { 0xC062, "TLS_ECDH_RSA_WITH_ARIA_128_GCM_SHA256" }, + { 0xC063, "TLS_ECDH_RSA_WITH_ARIA_256_GCM_SHA384" }, { 0xC064, "TLS_PSK_WITH_ARIA_128_CBC_SHA256" }, { 0xC065, "TLS_PSK_WITH_ARIA_256_CBC_SHA384" }, { 0xC066, "TLS_DHE_PSK_WITH_ARIA_128_CBC_SHA256" }, { 0xC067, "TLS_DHE_PSK_WITH_ARIA_256_CBC_SHA384" }, { 0xC068, "TLS_RSA_PSK_WITH_ARIA_128_CBC_SHA256" }, { 0xC069, "TLS_RSA_PSK_WITH_ARIA_256_CBC_SHA384" }, - { 0xC06A, TLS1_RFC_PSK_WITH_ARIA_128_GCM_SHA256 }, - { 0xC06B, TLS1_RFC_PSK_WITH_ARIA_256_GCM_SHA384 }, - { 0xC06C, TLS1_RFC_DHE_PSK_WITH_ARIA_128_GCM_SHA256 }, - { 0xC06D, TLS1_RFC_DHE_PSK_WITH_ARIA_256_GCM_SHA384 }, - { 0xC06E, TLS1_RFC_RSA_PSK_WITH_ARIA_128_GCM_SHA256 }, - { 0xC06F, TLS1_RFC_RSA_PSK_WITH_ARIA_256_GCM_SHA384 }, + { 0xC06A, "TLS_PSK_WITH_ARIA_128_GCM_SHA256" }, + { 0xC06B, "TLS_PSK_WITH_ARIA_256_GCM_SHA384" }, + { 0xC06C, "TLS_DHE_PSK_WITH_ARIA_128_GCM_SHA256" }, + { 0xC06D, "TLS_DHE_PSK_WITH_ARIA_256_GCM_SHA384" }, + { 0xC06E, "TLS_RSA_PSK_WITH_ARIA_128_GCM_SHA256" }, + { 0xC06F, "TLS_RSA_PSK_WITH_ARIA_256_GCM_SHA384" }, { 0xC070, "TLS_ECDHE_PSK_WITH_ARIA_128_CBC_SHA256" }, { 0xC071, "TLS_ECDHE_PSK_WITH_ARIA_256_CBC_SHA384" }, - { 0xC072, TLS1_RFC_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256 }, - { 0xC073, TLS1_RFC_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384 }, + { 0xC072, "TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256" }, + { 0xC073, "TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384" }, { 0xC074, "TLS_ECDH_ECDSA_WITH_CAMELLIA_128_CBC_SHA256" }, { 0xC075, "TLS_ECDH_ECDSA_WITH_CAMELLIA_256_CBC_SHA384" }, - { 0xC076, TLS1_RFC_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256 }, - { 0xC077, TLS1_RFC_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384 }, + { 0xC076, "TLS_ECDHE_RSA_WITH_CAMELLIA_128_CBC_SHA256" }, + { 0xC077, "TLS_ECDHE_RSA_WITH_CAMELLIA_256_CBC_SHA384" }, { 0xC078, "TLS_ECDH_RSA_WITH_CAMELLIA_128_CBC_SHA256" }, { 0xC079, "TLS_ECDH_RSA_WITH_CAMELLIA_256_CBC_SHA384" }, { 0xC07A, "TLS_RSA_WITH_CAMELLIA_128_GCM_SHA256" }, @@ -404,53 +403,53 @@ static const ssl_trace_tbl ssl_ciphers_tbl[] = { { 0xC091, "TLS_DHE_PSK_WITH_CAMELLIA_256_GCM_SHA384" }, { 0xC092, "TLS_RSA_PSK_WITH_CAMELLIA_128_GCM_SHA256" }, { 0xC093, "TLS_RSA_PSK_WITH_CAMELLIA_256_GCM_SHA384" }, - { 0xC094, TLS1_RFC_PSK_WITH_CAMELLIA_128_CBC_SHA256 }, - { 0xC095, TLS1_RFC_PSK_WITH_CAMELLIA_256_CBC_SHA384 }, - { 0xC096, TLS1_RFC_DHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 }, - { 0xC097, TLS1_RFC_DHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 }, - { 0xC098, TLS1_RFC_RSA_PSK_WITH_CAMELLIA_128_CBC_SHA256 }, - { 0xC099, TLS1_RFC_RSA_PSK_WITH_CAMELLIA_256_CBC_SHA384 }, - { 0xC09A, TLS1_RFC_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256 }, - { 0xC09B, TLS1_RFC_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384 }, - { 0xC09C, TLS1_RFC_RSA_WITH_AES_128_CCM }, - { 0xC09D, TLS1_RFC_RSA_WITH_AES_256_CCM }, - { 0xC09E, TLS1_RFC_DHE_RSA_WITH_AES_128_CCM }, - { 0xC09F, TLS1_RFC_DHE_RSA_WITH_AES_256_CCM }, - { 0xC0A0, TLS1_RFC_RSA_WITH_AES_128_CCM_8 }, - { 0xC0A1, TLS1_RFC_RSA_WITH_AES_256_CCM_8 }, - { 0xC0A2, TLS1_RFC_DHE_RSA_WITH_AES_128_CCM_8 }, - { 0xC0A3, TLS1_RFC_DHE_RSA_WITH_AES_256_CCM_8 }, - { 0xC0A4, TLS1_RFC_PSK_WITH_AES_128_CCM }, - { 0xC0A5, TLS1_RFC_PSK_WITH_AES_256_CCM }, - { 0xC0A6, TLS1_RFC_DHE_PSK_WITH_AES_128_CCM }, - { 0xC0A7, TLS1_RFC_DHE_PSK_WITH_AES_256_CCM }, - { 0xC0A8, TLS1_RFC_PSK_WITH_AES_128_CCM_8 }, - { 0xC0A9, TLS1_RFC_PSK_WITH_AES_256_CCM_8 }, - { 0xC0AA, TLS1_RFC_DHE_PSK_WITH_AES_128_CCM_8 }, - { 0xC0AB, TLS1_RFC_DHE_PSK_WITH_AES_256_CCM_8 }, - { 0xC0AC, TLS1_RFC_ECDHE_ECDSA_WITH_AES_128_CCM }, - { 0xC0AD, TLS1_RFC_ECDHE_ECDSA_WITH_AES_256_CCM }, - { 0xC0AE, TLS1_RFC_ECDHE_ECDSA_WITH_AES_128_CCM_8 }, - { 0xC0AF, TLS1_RFC_ECDHE_ECDSA_WITH_AES_256_CCM_8 }, + { 0xC094, "TLS_PSK_WITH_CAMELLIA_128_CBC_SHA256" }, + { 0xC095, "TLS_PSK_WITH_CAMELLIA_256_CBC_SHA384" }, + { 0xC096, "TLS_DHE_PSK_WITH_CAMELLIA_128_CBC_SHA256" }, + { 0xC097, "TLS_DHE_PSK_WITH_CAMELLIA_256_CBC_SHA384" }, + { 0xC098, "TLS_RSA_PSK_WITH_CAMELLIA_128_CBC_SHA256" }, + { 0xC099, "TLS_RSA_PSK_WITH_CAMELLIA_256_CBC_SHA384" }, + { 0xC09A, "TLS_ECDHE_PSK_WITH_CAMELLIA_128_CBC_SHA256" }, + { 0xC09B, "TLS_ECDHE_PSK_WITH_CAMELLIA_256_CBC_SHA384" }, + { 0xC09C, "TLS_RSA_WITH_AES_128_CCM" }, + { 0xC09D, "TLS_RSA_WITH_AES_256_CCM" }, + { 0xC09E, "TLS_DHE_RSA_WITH_AES_128_CCM" }, + { 0xC09F, "TLS_DHE_RSA_WITH_AES_256_CCM" }, + { 0xC0A0, "TLS_RSA_WITH_AES_128_CCM_8" }, + { 0xC0A1, "TLS_RSA_WITH_AES_256_CCM_8" }, + { 0xC0A2, "TLS_DHE_RSA_WITH_AES_128_CCM_8" }, + { 0xC0A3, "TLS_DHE_RSA_WITH_AES_256_CCM_8" }, + { 0xC0A4, "TLS_PSK_WITH_AES_128_CCM" }, + { 0xC0A5, "TLS_PSK_WITH_AES_256_CCM" }, + { 0xC0A6, "TLS_DHE_PSK_WITH_AES_128_CCM" }, + { 0xC0A7, "TLS_DHE_PSK_WITH_AES_256_CCM" }, + { 0xC0A8, "TLS_PSK_WITH_AES_128_CCM_8" }, + { 0xC0A9, "TLS_PSK_WITH_AES_256_CCM_8" }, + { 0xC0AA, "TLS_PSK_DHE_WITH_AES_128_CCM_8" }, + { 0xC0AB, "TLS_PSK_DHE_WITH_AES_256_CCM_8" }, + { 0xC0AC, "TLS_ECDHE_ECDSA_WITH_AES_128_CCM" }, + { 0xC0AD, "TLS_ECDHE_ECDSA_WITH_AES_256_CCM" }, + { 0xC0AE, "TLS_ECDHE_ECDSA_WITH_AES_128_CCM_8" }, + { 0xC0AF, "TLS_ECDHE_ECDSA_WITH_AES_256_CCM_8" }, { 0xC102, "IANA-GOST2012-GOST8912-GOST8912" }, - { 0xCCA8, TLS1_RFC_ECDHE_RSA_WITH_CHACHA20_POLY1305 }, - { 0xCCA9, TLS1_RFC_ECDHE_ECDSA_WITH_CHACHA20_POLY1305 }, - { 0xCCAA, TLS1_RFC_DHE_RSA_WITH_CHACHA20_POLY1305 }, - { 0xCCAB, TLS1_RFC_PSK_WITH_CHACHA20_POLY1305 }, - { 0xCCAC, TLS1_RFC_ECDHE_PSK_WITH_CHACHA20_POLY1305 }, - { 0xCCAD, TLS1_RFC_DHE_PSK_WITH_CHACHA20_POLY1305 }, - { 0xCCAE, TLS1_RFC_RSA_PSK_WITH_CHACHA20_POLY1305 }, - { 0x1301, TLS1_3_RFC_AES_128_GCM_SHA256 }, - { 0x1302, TLS1_3_RFC_AES_256_GCM_SHA384 }, - { 0x1303, TLS1_3_RFC_CHACHA20_POLY1305_SHA256 }, - { 0x1304, TLS1_3_RFC_AES_128_CCM_SHA256 }, - { 0x1305, TLS1_3_RFC_AES_128_CCM_8_SHA256 }, + { 0xCCA8, "TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256" }, + { 0xCCA9, "TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256" }, + { 0xCCAA, "TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256" }, + { 0xCCAB, "TLS_PSK_WITH_CHACHA20_POLY1305_SHA256" }, + { 0xCCAC, "TLS_ECDHE_PSK_WITH_CHACHA20_POLY1305_SHA256" }, + { 0xCCAD, "TLS_DHE_PSK_WITH_CHACHA20_POLY1305_SHA256" }, + { 0xCCAE, "TLS_RSA_PSK_WITH_CHACHA20_POLY1305_SHA256" }, + { 0x1301, "TLS_AES_128_GCM_SHA256" }, + { 0x1302, "TLS_AES_256_GCM_SHA384" }, + { 0x1303, "TLS_CHACHA20_POLY1305_SHA256" }, + { 0x1304, "TLS_AES_128_CCM_SHA256" }, + { 0x1305, "TLS_AES_128_CCM_8_SHA256" }, { 0xFEFE, "SSL_RSA_FIPS_WITH_DES_CBC_SHA" }, { 0xFEFF, "SSL_RSA_FIPS_WITH_3DES_EDE_CBC_SHA" }, { 0xFF85, "LEGACY-GOST2012-GOST8912-GOST8912" }, { 0xFF87, "GOST2012-NULL-GOST12" }, - { 0xC0B4, TLS1_3_RFC_SHA256_SHA256 }, - { 0xC0B5, TLS1_3_RFC_SHA384_SHA384 }, + { 0xC0B4, "TLS_SHA256_SHA256" }, + { 0xC0B5, "TLS_SHA384_SHA384" }, { 0xC100, "GOST2012-KUZNYECHIK-KUZNYECHIKOMAC" }, { 0xC101, "GOST2012-MAGMA-MAGMAOMAC" }, }; @@ -501,10 +500,6 @@ static const ssl_trace_tbl ssl_exts_tbl[] = { #ifndef OPENSSL_NO_NEXTPROTONEG { TLSEXT_TYPE_next_proto_neg, "next_proto_neg" }, #endif -#ifndef OPENSSL_NO_ECH - { TLSEXT_TYPE_ech, "encrypted_client_hello" }, - { TLSEXT_TYPE_outer_extensions, "outer_extension" }, -#endif }; static const ssl_trace_tbl ssl_groups_tbl[] = { @@ -548,7 +543,6 @@ static const ssl_trace_tbl ssl_groups_tbl[] = { { 38, "GC512A" }, { 39, "GC512B" }, { 40, "GC512C" }, - { 41, "curveSM2" }, { 256, "ffdhe2048" }, { 257, "ffdhe3072" }, { 258, "ffdhe4096" }, @@ -560,7 +554,6 @@ static const ssl_trace_tbl ssl_groups_tbl[] = { { 4587, "SecP256r1MLKEM768" }, { 4588, "X25519MLKEM768" }, { 4589, "SecP384r1MLKEM1024" }, - { 4590, "curveSM2MLKEM768" }, { 25497, "X25519Kyber768Draft00" }, { 25498, "SecP256r1Kyber768Draft00" }, { 0xFF01, "arbitrary_explicit_prime_curves" }, @@ -586,6 +579,8 @@ static const ssl_trace_tbl ssl_sigalg_tbl[] = { { TLSEXT_SIGALG_ecdsa_secp384r1_sha384, TLSEXT_SIGALG_ecdsa_secp384r1_sha384_name }, { TLSEXT_SIGALG_ecdsa_secp521r1_sha512, TLSEXT_SIGALG_ecdsa_secp521r1_sha512_name }, { TLSEXT_SIGALG_ecdsa_sha224, TLSEXT_SIGALG_ecdsa_sha224_name }, + { TLSEXT_SIGALG_ed25519, TLSEXT_SIGALG_ed25519_name }, + { TLSEXT_SIGALG_ed448, TLSEXT_SIGALG_ed448_name }, { TLSEXT_SIGALG_ecdsa_sha1, TLSEXT_SIGALG_ecdsa_sha1_name }, { TLSEXT_SIGALG_rsa_pss_rsae_sha256, TLSEXT_SIGALG_rsa_pss_rsae_sha256_name }, { TLSEXT_SIGALG_rsa_pss_rsae_sha384, TLSEXT_SIGALG_rsa_pss_rsae_sha384_name }, @@ -608,27 +603,17 @@ static const ssl_trace_tbl ssl_sigalg_tbl[] = { { TLSEXT_SIGALG_gostr34102012_256_gostr34112012_256, TLSEXT_SIGALG_gostr34102012_256_gostr34112012_256_name }, { TLSEXT_SIGALG_gostr34102012_512_gostr34112012_512, TLSEXT_SIGALG_gostr34102012_512_gostr34112012_512_name }, { TLSEXT_SIGALG_gostr34102001_gostr3411, TLSEXT_SIGALG_gostr34102001_gostr3411_name }, - { TLSEXT_SIGALG_sm2sig_sm3, TLSEXT_SIGALG_sm2sig_sm3_name }, - { TLSEXT_SIGALG_ed25519, TLSEXT_SIGALG_ed25519_name }, - { TLSEXT_SIGALG_ed448, TLSEXT_SIGALG_ed448_name }, { TLSEXT_SIGALG_ecdsa_brainpoolP256r1_sha256, TLSEXT_SIGALG_ecdsa_brainpoolP256r1_sha256_name }, { TLSEXT_SIGALG_ecdsa_brainpoolP384r1_sha384, TLSEXT_SIGALG_ecdsa_brainpoolP384r1_sha384_name }, { TLSEXT_SIGALG_ecdsa_brainpoolP512r1_sha512, TLSEXT_SIGALG_ecdsa_brainpoolP512r1_sha512_name }, - { TLSEXT_SIGALG_mldsa44, TLSEXT_SIGALG_mldsa44_name }, - { TLSEXT_SIGALG_mldsa65, TLSEXT_SIGALG_mldsa65_name }, - { TLSEXT_SIGALG_mldsa87, TLSEXT_SIGALG_mldsa87_name }, - { TLSEXT_SIGALG_slhdsa_sha2_128s, TLSEXT_SIGALG_slhdsa_sha2_128s_name }, - { TLSEXT_SIGALG_slhdsa_sha2_128f, TLSEXT_SIGALG_slhdsa_sha2_128f_name }, - { TLSEXT_SIGALG_slhdsa_sha2_192s, TLSEXT_SIGALG_slhdsa_sha2_192s_name }, - { TLSEXT_SIGALG_slhdsa_sha2_192f, TLSEXT_SIGALG_slhdsa_sha2_192f_name }, - { TLSEXT_SIGALG_slhdsa_sha2_256s, TLSEXT_SIGALG_slhdsa_sha2_256s_name }, - { TLSEXT_SIGALG_slhdsa_sha2_256f, TLSEXT_SIGALG_slhdsa_sha2_256f_name }, - { TLSEXT_SIGALG_slhdsa_shake_128s, TLSEXT_SIGALG_slhdsa_shake_128s_name }, - { TLSEXT_SIGALG_slhdsa_shake_128f, TLSEXT_SIGALG_slhdsa_shake_128f_name }, - { TLSEXT_SIGALG_slhdsa_shake_192s, TLSEXT_SIGALG_slhdsa_shake_192s_name }, - { TLSEXT_SIGALG_slhdsa_shake_192f, TLSEXT_SIGALG_slhdsa_shake_192f_name }, - { TLSEXT_SIGALG_slhdsa_shake_256s, TLSEXT_SIGALG_slhdsa_shake_256s_name }, - { TLSEXT_SIGALG_slhdsa_shake_256f, TLSEXT_SIGALG_slhdsa_shake_256f_name }, + /* + * Well known groups that we happen to know about, but only come from + * provider capability declarations (hence no macros for the + * codepoints/names) + */ + { 0x0904, "mldsa44" }, + { 0x0905, "mldsa65" }, + { 0x0906, "mldsa87" } }; static const ssl_trace_tbl ssl_ctype_tbl[] = { @@ -681,7 +666,7 @@ static void ssl_print_hex(BIO *bio, int indent, const char *name, size_t i; BIO_indent(bio, indent, 80); - BIO_printf(bio, "%s (len=%zu): ", name, msglen); + BIO_printf(bio, "%s (len=%d): ", name, (int)msglen); for (i = 0; i < msglen; i++) BIO_printf(bio, "%02X", msg[i]); BIO_puts(bio, "\n"); @@ -776,8 +761,8 @@ static int ssl_print_extension(BIO *bio, int indent, int server, uint32_t max_early_data; BIO_indent(bio, indent, 80); - BIO_printf(bio, "extension_type=%s(%d), length=%zu\n", - ssl_trace_str(extype, ssl_exts_tbl), extype, extlen); + BIO_printf(bio, "extension_type=%s(%d), length=%d\n", + ssl_trace_str(extype, ssl_exts_tbl), extype, (int)extlen); switch (extype) { case TLSEXT_TYPE_compress_certificate: if (extlen < 1) @@ -1003,7 +988,7 @@ static int ssl_print_extensions(BIO *bio, int indent, int server, } if (extslen > msglen) return 0; - BIO_printf(bio, "extensions, length = %zu\n", extslen); + BIO_printf(bio, "extensions, length = %d\n", (int)extslen); msglen -= extslen; while (extslen > 0) { int extype; @@ -1013,8 +998,8 @@ static int ssl_print_extensions(BIO *bio, int indent, int server, extype = (msg[0] << 8) | msg[1]; extlen = (msg[2] << 8) | msg[3]; if (extslen < extlen + 4) { - BIO_printf(bio, "extensions, extype = %d, extlen = %zu\n", extype, - extlen); + BIO_printf(bio, "extensions, extype = %d, extlen = %d\n", extype, + (int)extlen); BIO_dump_indent(bio, (const char *)msg, (int)extslen, indent + 2); return 0; } @@ -1053,7 +1038,7 @@ static int ssl_print_client_hello(BIO *bio, const SSL_CONNECTION *sc, int indent msg += 2; msglen -= 2; BIO_indent(bio, indent, 80); - BIO_printf(bio, "cipher_suites (len=%zu)\n", len); + BIO_printf(bio, "cipher_suites (len=%d)\n", (int)len); if (msglen < len || len & 1) return 0; while (len > 0) { @@ -1073,7 +1058,7 @@ static int ssl_print_client_hello(BIO *bio, const SSL_CONNECTION *sc, int indent if (msglen < len) return 0; BIO_indent(bio, indent, 80); - BIO_printf(bio, "compression_methods (len=%zu)\n", len); + BIO_printf(bio, "compression_methods (len=%d)\n", (int)len); while (len > 0) { BIO_indent(bio, indent + 2, 80); BIO_printf(bio, "%s (0x%02X)\n", @@ -1199,9 +1184,14 @@ static int ssl_print_client_keyex(BIO *bio, int indent, const SSL_CONNECTION *sc case SSL_kRSA: case SSL_kRSAPSK: - if (!ssl_print_hexbuf(bio, indent + 2, - "EncryptedPreMasterSecret", 2, &msg, &msglen)) - return 0; + if (TLS1_get_version(SSL_CONNECTION_GET_SSL(sc)) == SSL3_VERSION) { + ssl_print_hex(bio, indent + 2, + "EncryptedPreMasterSecret", msg, msglen); + } else { + if (!ssl_print_hexbuf(bio, indent + 2, + "EncryptedPreMasterSecret", 2, &msg, &msglen)) + return 0; + } break; case SSL_kDHE: @@ -1313,7 +1303,7 @@ static int ssl_print_certificate(BIO *bio, const SSL_CONNECTION *sc, int indent, return 0; q = p + 3; BIO_indent(bio, indent, 80); - BIO_printf(bio, "ASN.1Cert, length=%zu", clen); + BIO_printf(bio, "ASN.1Cert, length=%d", (int)clen); x = X509_new_ex(ctx->libctx, ctx->propq); if (x != NULL && d2i_X509(&x, &q, (long)clen) == NULL) { X509_free(x); @@ -1337,46 +1327,33 @@ static int ssl_print_certificate(BIO *bio, const SSL_CONNECTION *sc, int indent, return 1; } -static int ssl_print_raw_public_key(BIO *bio, const SSL_CONNECTION *sc, - int server, int indent, const unsigned char **pmsg, size_t *pmsglen) +static int ssl_print_raw_public_key(BIO *bio, const SSL *ssl, int server, + int indent, const unsigned char **pmsg, + size_t *pmsglen) { EVP_PKEY *pkey; size_t clen; const unsigned char *msg = *pmsg; size_t msglen = *pmsglen; - int has_spki_len; - /* - * In TLS 1.2 and prior the SPKI is the entire payload of the extension, - * and does not have a separate length prefix - */ - has_spki_len = SSL_CONNECTION_IS_DTLS(sc) - ? DTLS_VERSION_GT(sc->version, DTLS1_2_VERSION) - : sc->version > TLS1_2_VERSION; - if (has_spki_len) { - if (msglen < 3) - return 0; - clen = (msg[0] << 16) | (msg[1] << 8) | msg[2]; - if (msglen < clen + 3) - return 0; - msg += 3; - *pmsg += clen + 3; - *pmsglen -= clen + 3; - } else { - clen = msglen; - *pmsg += msglen; - *pmsglen -= msglen; - } + if (msglen < 3) + return 0; + clen = (msg[0] << 16) | (msg[1] << 8) | msg[2]; + if (msglen < clen + 3) + return 0; + + msg += 3; BIO_indent(bio, indent, 80); - BIO_printf(bio, "raw_public_key, length=%zu\n", clen); + BIO_printf(bio, "raw_public_key, length=%d\n", (int)clen); - pkey = d2i_PUBKEY_ex(NULL, &msg, (long)clen, - sc->ssl.ctx->libctx, sc->ssl.ctx->propq); + pkey = d2i_PUBKEY_ex(NULL, &msg, (long)clen, ssl->ctx->libctx, ssl->ctx->propq); if (pkey == NULL) return 0; EVP_PKEY_print_public(bio, pkey, indent + 2, NULL); EVP_PKEY_free(pkey); + *pmsg += clen + 3; + *pmsglen -= clen + 3; return 1; } @@ -1398,7 +1375,7 @@ static int ssl_print_certificates(BIO *bio, const SSL_CONNECTION *sc, int server msg += 3; if ((server && sc->ext.server_cert_type == TLSEXT_cert_type_rpk) || (!server && sc->ext.client_cert_type == TLSEXT_cert_type_rpk)) { - if (!ssl_print_raw_public_key(bio, sc, server, indent, &msg, &clen)) + if (!ssl_print_raw_public_key(bio, &sc->ssl, server, indent, &msg, &clen)) return 0; if (SSL_CONNECTION_IS_TLS13(sc) && !ssl_print_extensions(bio, indent + 2, server, @@ -1407,7 +1384,7 @@ static int ssl_print_certificates(BIO *bio, const SSL_CONNECTION *sc, int server return 1; } BIO_indent(bio, indent, 80); - BIO_printf(bio, "certificate_list, length=%zu\n", clen); + BIO_printf(bio, "certificate_list, length=%d\n", (int)clen); while (clen > 0) { if (!ssl_print_certificate(bio, sc, indent + 2, &msg, &clen)) return 0; @@ -1447,12 +1424,12 @@ static int ssl_print_compressed_certificates(BIO *bio, const SSL_CONNECTION *sc, BIO_indent(bio, indent, 80); BIO_printf(bio, "Compression type=%s (0x%04x)\n", ssl_trace_str(alg, ssl_comp_cert_tbl), alg); BIO_indent(bio, indent, 80); - BIO_printf(bio, "Uncompressed length=%zu\n", uclen); + BIO_printf(bio, "Uncompressed length=%d\n", (int)uclen); BIO_indent(bio, indent, 80); if (clen > 0) - BIO_printf(bio, "Compressed length=%zu, Ratio=%f:1\n", clen, (float)uclen / (float)clen); + BIO_printf(bio, "Compressed length=%d, Ratio=%f:1\n", (int)clen, (float)uclen / (float)clen); else - BIO_printf(bio, "Compressed length=%zu, Ratio=unknown\n", clen); + BIO_printf(bio, "Compressed length=%d, Ratio=unknown\n", (int)clen); BIO_dump_indent(bio, (const char *)msg, (int)clen, indent); @@ -1513,7 +1490,7 @@ static int ssl_print_cert_request(BIO *bio, int indent, const SSL_CONNECTION *sc return 0; msg++; BIO_indent(bio, indent, 80); - BIO_printf(bio, "certificate_types (len=%zu)\n", xlen); + BIO_printf(bio, "certificate_types (len=%d)\n", (int)xlen); if (!ssl_trace_list(bio, indent + 2, msg, xlen, 1, ssl_ctype_tbl)) return 0; msg += xlen; @@ -1528,7 +1505,7 @@ static int ssl_print_cert_request(BIO *bio, int indent, const SSL_CONNECTION *sc msg += 2; msglen -= xlen + 2; BIO_indent(bio, indent, 80); - BIO_printf(bio, "signature_algorithms (len=%zu)\n", xlen); + BIO_printf(bio, "signature_algorithms (len=%d)\n", (int)xlen); while (xlen > 0) { BIO_indent(bio, indent + 2, 80); sigalg = (msg[0] << 8) | msg[1]; @@ -1548,7 +1525,7 @@ static int ssl_print_cert_request(BIO *bio, int indent, const SSL_CONNECTION *sc return 0; msg += 2; msglen -= 2 + xlen; - BIO_printf(bio, "certificate_authorities (len=%zu)\n", xlen); + BIO_printf(bio, "certificate_authorities (len=%d)\n", (int)xlen); while (xlen > 0) { size_t dlen; X509_NAME *nm; @@ -1560,7 +1537,7 @@ static int ssl_print_cert_request(BIO *bio, int indent, const SSL_CONNECTION *sc return 0; msg += 2; BIO_indent(bio, indent + 2, 80); - BIO_printf(bio, "DistinguishedName (len=%zu): ", dlen); + BIO_printf(bio, "DistinguishedName (len=%d): ", (int)dlen); p = msg; nm = d2i_X509_NAME(NULL, &p, (long)dlen); if (!nm) { @@ -1641,8 +1618,8 @@ static int ssl_print_handshake(BIO *bio, const SSL_CONNECTION *sc, int server, htype = msg[0]; hlen = (msg[1] << 16) | (msg[2] << 8) | msg[3]; BIO_indent(bio, indent, 80); - BIO_printf(bio, "%s, Length=%zu\n", - ssl_trace_str(htype, ssl_handshake_tbl), hlen); + BIO_printf(bio, "%s, Length=%d\n", + ssl_trace_str(htype, ssl_handshake_tbl), (int)hlen); msg += 4; msglen -= 4; if (SSL_CONNECTION_IS_DTLS(sc)) { diff --git a/ssl/tls13_enc.c b/ssl/tls13_enc.c index ae47f5301c..d42e7dc206 100644 --- a/ssl/tls13_enc.c +++ b/ssl/tls13_enc.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -529,25 +529,10 @@ int tls13_change_cipher_state(SSL_CONNECTION *s, int which) labellen = sizeof(client_early_traffic) - 1; log_label = CLIENT_EARLY_LABEL; -#ifndef OPENSSL_NO_ECH - /* if ECH worked then use the innerch and not the h/s buffer here */ - if (((which & SSL3_CC_SERVER) && s->ext.ech.success == 1) - || ((which & SSL3_CC_CLIENT) && s->ext.ech.attempted == 1)) { - if (s->ext.ech.innerch == NULL) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, ERR_R_INTERNAL_ERROR); - goto err; - } - handlen = (long)s->ext.ech.innerch_len; - hdata = s->ext.ech.innerch; - } else -#endif - { - handlen = BIO_get_mem_data(s->s3.handshake_buffer, &hdata); - if (handlen <= 0) { - SSLfatal(s, SSL_AD_INTERNAL_ERROR, - SSL_R_BAD_HANDSHAKE_LENGTH); - goto err; - } + handlen = BIO_get_mem_data(s->s3.handshake_buffer, &hdata); + if (handlen <= 0) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, SSL_R_BAD_HANDSHAKE_LENGTH); + goto err; } if (s->early_data_state == SSL_EARLY_DATA_CONNECTING diff --git a/ssl/tls_depr.c b/ssl/tls_depr.c index 194e06b33b..71d0c42495 100644 --- a/ssl/tls_depr.c +++ b/ssl/tls_depr.c @@ -22,13 +22,16 @@ * be removed. */ #ifndef OPENSSL_NO_DEPRECATED_3_0 -SSL_HMAC *ssl_hmac_old_construct(SSL_HMAC *ret) +int ssl_hmac_old_new(SSL_HMAC *ret) { ret->old_ctx = HMAC_CTX_new(); - return ret->old_ctx != NULL ? ret : NULL; + if (ret->old_ctx == NULL) + return 0; + + return 1; } -void ssl_hmac_old_destruct(SSL_HMAC *ctx) +void ssl_hmac_old_free(SSL_HMAC *ctx) { HMAC_CTX_free(ctx->old_ctx); } diff --git a/ssl/tls_srp.c b/ssl/tls_srp.c index d493916a2d..51f0950a16 100644 --- a/ssl/tls_srp.c +++ b/ssl/tls_srp.c @@ -1,5 +1,5 @@ /* - * Copyright 2004-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2004-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2004, EdelKey Project. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -193,15 +193,12 @@ int ssl_srp_server_param_with_username_intern(SSL_CONNECTION *s, int *ad) OPENSSL_cleanse(b, sizeof(b)); /* Calculate: B = (kv + g^b) % N */ - s->srp_ctx.B = SRP_Calc_B_ex(s->srp_ctx.b, s->srp_ctx.N, s->srp_ctx.g, - s->srp_ctx.v, sctx->libctx, sctx->propq); - if (s->srp_ctx.B == NULL) { - BN_clear_free(s->srp_ctx.b); - s->srp_ctx.b = NULL; - return SSL3_AL_FATAL; - } - return SSL_ERROR_NONE; + return ((s->srp_ctx.B = SRP_Calc_B_ex(s->srp_ctx.b, s->srp_ctx.N, s->srp_ctx.g, + s->srp_ctx.v, sctx->libctx, sctx->propq)) + != NULL) + ? SSL_ERROR_NONE + : SSL3_AL_FATAL; } int SSL_srp_server_param_with_username(SSL *s, int *ad) @@ -254,7 +251,7 @@ int SSL_set_srp_server_param(SSL *s, const BIGNUM *N, const BIGNUM *g, if (N != NULL) { if (sc->srp_ctx.N != NULL) { - if (BN_copy(sc->srp_ctx.N, N) == NULL) { + if (!BN_copy(sc->srp_ctx.N, N)) { BN_free(sc->srp_ctx.N); sc->srp_ctx.N = NULL; } @@ -263,7 +260,7 @@ int SSL_set_srp_server_param(SSL *s, const BIGNUM *N, const BIGNUM *g, } if (g != NULL) { if (sc->srp_ctx.g != NULL) { - if (BN_copy(sc->srp_ctx.g, g) == NULL) { + if (!BN_copy(sc->srp_ctx.g, g)) { BN_free(sc->srp_ctx.g); sc->srp_ctx.g = NULL; } @@ -272,7 +269,7 @@ int SSL_set_srp_server_param(SSL *s, const BIGNUM *N, const BIGNUM *g, } if (sa != NULL) { if (sc->srp_ctx.s != NULL) { - if (BN_copy(sc->srp_ctx.s, sa) == NULL) { + if (!BN_copy(sc->srp_ctx.s, sa)) { BN_free(sc->srp_ctx.s); sc->srp_ctx.s = NULL; } @@ -281,7 +278,7 @@ int SSL_set_srp_server_param(SSL *s, const BIGNUM *N, const BIGNUM *g, } if (v != NULL) { if (sc->srp_ctx.v != NULL) { - if (BN_copy(sc->srp_ctx.v, v) == NULL) { + if (!BN_copy(sc->srp_ctx.v, v)) { BN_free(sc->srp_ctx.v); sc->srp_ctx.v = NULL; } diff --git a/test/README-external.md b/test/README-external.md index 41994318f3..2d7e71d79b 100644 --- a/test/README-external.md +++ b/test/README-external.md @@ -39,7 +39,7 @@ tests against the local OpenSSL build. You will need a git checkout of krb5 at the top level: - $ git submodule update --init + $ git clone https://github.com/krb5/krb5 krb5's master has to pass this same CI, but a known-good version is krb5-1.15.1-final if you want to be sure. @@ -123,12 +123,6 @@ Test failures and suppressions There are tests for different software tokens - softhsm, nss-softokn and kryoptic. Kryoptic tests will not run at this point. Currently no test fails. -Encrypted Client Hello (ECH) external tests -=========================================== - -ECH external tests versus BoringSSL and NSS exist and are described -in `doc/designs/ech-api.md`. - Updating test suites ==================== diff --git a/test/README.md b/test/README.md index 1575fb69dc..746a0156ce 100644 --- a/test/README.md +++ b/test/README.md @@ -184,74 +184,3 @@ To randomise the test ordering: To run the tests using the order defined by the random seed `42`: $ make OPENSSL_TEST_RAND_ORDER=42 test - -Memory Allocation Failure Tests -------------------------------- - -Some tests use the `ADD_MFAIL_TEST` framework to exhaustively verify that -functions handle every possible allocation failure gracefully. These tests -run repeatedly, failing one allocation later each iteration. The -`ADD_MFAIL_NO_CHECK_TEST` variant relaxes the requirement that the test -return 0 when a failure was triggered. The `ADD_MFAIL_ALL_TESTS` and -`ADD_MFAIL_ALL_NO_CHECK_TESTS` variants apply the same cycle to each index -of a parameterised test, the same way `ADD_ALL_TESTS` does. - -The `ADD_MFAIL_SAMPLED_TEST(fn, cnt)` variant (and its `NO_CHECK` and `ALL` -forms) caps injection at `cnt` points: it injects at every allocation when -there are at most `cnt` of them, and otherwise samples `cnt` points spread -across the run. This keeps tests with very many allocations bounded. On -`no-cached-fetch` builds, where allocation counts explode, non-sampled tests -run the counting phase only and skip injection; sampled tests still run. - -An mfail test returns 1 on success or 0 on failure; under `NO_CHECK` a 0 is -tolerated since a function may legitimately fail when an allocation fails. -Returning -1 forces a failure that is reported even under `NO_CHECK`, for -assertions that must hold regardless of which allocation was made to fail. - -Behavior is controlled with the following environment variables: - - OPENSSL_TEST_MFAIL_DISABLE=1 Disable mfail custom allocator installation. - - OPENSSL_TEST_MFAIL_SKIP_ALL=1 Skip all mfail tests. - - OPENSSL_TEST_MFAIL_SKIP_SLOW=1 Skip mfail tests whose allocation count - exceeds the slow threshold. - - OPENSSL_TEST_MFAIL_SLOW=N Slow threshold (default 1000). - - OPENSSL_TEST_MFAIL_COUNT=N Override the sampled point count, taking - precedence over the per-test value. - - OPENSSL_TEST_MFAIL_COUNT_ONLY=1 Run the counting phase only, never inject. - - OPENSSL_TEST_MFAIL_POINT=N Run only failure point N (0-indexed), - useful for debugging a specific failure. - - OPENSSL_TEST_MFAIL_START=N Start iteration from point N, skipping - earlier points that are already fixed. - - OPENSSL_TEST_MFAIL_BACKTRACE=1 Print a backtrace at each injection point. - -For example, to debug a failure at allocation point 42: - - $ OPENSSL_TEST_MFAIL_POINT=42 ./test/crltest -test test_crl_diff_mfail - -Or to skip already-fixed points and collect remaining failures: - - $ OPENSSL_TEST_MFAIL_START=13 make TESTS=test_crl test - -Running Tests under Valgrind ----------------------------- - -Normally, testing for memory leaks is accomplished by building Openssl with the -enable-asan option, which links the library with the compiler asan library. However -some people prefer to use valgrind to do dynamic instrumentation for memory leak checking. -OpenSSL also offers a suppression file to suppress reachable memory leaks, that are often -inappropriately considered to be true leaks. In order to maintain and test this -suppression file, OpenSSL tests can be run under valgrind automatically. - -To run the test suite under valgrind: - - $ make OSSL_USE_VALGRIND=yes test - -Doing so will create valgrind.log file for each test under the test-runs subdirectory. diff --git a/test/README.ssltest.md b/test/README.ssltest.md index 2b1c327e89..85a6430799 100644 --- a/test/README.ssltest.md +++ b/test/README.ssltest.md @@ -74,7 +74,7 @@ handshake. another alert.) * ExpectedProtocol - expected negotiated protocol. One of - TLSv1, TLSv1.1, TLSv1.2. + SSLv3, TLSv1, TLSv1.1, TLSv1.2. * SessionTicketExpected - whether or not a session ticket is expected - Ignore - do not check for a session ticket (default) @@ -272,8 +272,8 @@ In the above examples, `default` is the provider to use. Note that the test expectations sometimes depend on the Configure settings. For example, the negotiated protocol depends on the set of available (enabled) -protocols: a build with `enable-tls1_3` has different test expectations than a -build with `no-tls1_3`. +protocols: a build with `enable-ssl3` has different test expectations than a +build with `no-ssl3`. The Perl test harness automatically generates expected outputs, so users who just run `make test` do not need any extra steps. diff --git a/test/aeswrap_test.c b/test/aeswrap_test.c deleted file mode 100644 index 1ec763e8f5..0000000000 --- a/test/aeswrap_test.c +++ /dev/null @@ -1,93 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include "testutil.h" -#include "internal/nelem.h" - -/* Test that calling EVP_CipherUpdate() twice fails for AES_WRAP_PAD */ -static int aeswrap_multi_update_fail_test(void) -{ - int ret = 0; - EVP_CIPHER_CTX *ctx = NULL; - EVP_CIPHER *cipher = NULL; - uint8_t in[32] = { 0 }; /* multiple of 8 */ - uint8_t out[64]; - int outlen = sizeof(in) + 8; - uint8_t key[32] = { 0 }; - - if (!TEST_ptr(ctx = EVP_CIPHER_CTX_new()) - || !TEST_ptr(cipher = EVP_CIPHER_fetch(NULL, "AES-256-WRAP-PAD", NULL)) - || !TEST_int_eq(EVP_CipherInit_ex2(ctx, cipher, key, NULL, 1, NULL), 1) - || !TEST_int_eq(EVP_CipherUpdate(ctx, out, &outlen, in, sizeof(in)), 1) - || !TEST_int_eq(EVP_CipherUpdate(ctx, out, &outlen, in, sizeof(in)), 0)) - goto err; - ret = 1; -err: - EVP_CIPHER_free(cipher); - EVP_CIPHER_CTX_free(ctx); - return ret; -} - -/* Test that an invalid input size fails when padding is not enabled */ -static int aeswrap_input_size_fail_test(void) -{ - int ret = 0; - EVP_CIPHER_CTX *ctx = NULL; - EVP_CIPHER *cipher = NULL; - uint8_t in[32] = { 0 }; /* multiple of 8 */ - uint8_t out[64]; - int outlen = sizeof(in) + 8; - uint8_t key[32] = { 0 }; - - if (!TEST_ptr(ctx = EVP_CIPHER_CTX_new()) - || !TEST_ptr(cipher = EVP_CIPHER_fetch(NULL, "AES-256-WRAP", NULL)) - || !TEST_int_eq(EVP_CipherInit_ex2(ctx, cipher, key, NULL, 1, NULL), 1) - || !TEST_int_eq(EVP_CipherUpdate(ctx, out, &outlen, in, 7), 0)) - goto err; - ret = 1; -err: - EVP_CIPHER_free(cipher); - EVP_CIPHER_CTX_free(ctx); - return ret; -} - -static const char *aeswrap_null_key_ciphers[] = { - "AES-256-WRAP", "AES-256-WRAP-PAD", "AES-256-WRAP-INV" -}; - -/* Test that EVP_CipherUpdate fails after EVP_CipherInit_ex2 with NULL key */ -static int aeswrap_null_key_init_fail_test(int idx) -{ - int ret = 0; - EVP_CIPHER_CTX *ctx = NULL; - EVP_CIPHER *cipher = NULL; - uint8_t in[32] = { 0 }; - uint8_t out[64]; - int outlen = sizeof(in) + 8; - - if (!TEST_ptr(ctx = EVP_CIPHER_CTX_new()) - || !TEST_ptr(cipher = EVP_CIPHER_fetch(NULL, aeswrap_null_key_ciphers[idx], NULL)) - || !TEST_int_eq(EVP_CipherInit_ex2(ctx, cipher, NULL, NULL, 1, NULL), 1) - || !TEST_int_eq(EVP_CipherUpdate(ctx, out, &outlen, in, sizeof(in)), 0)) - goto err; - ret = 1; -err: - EVP_CIPHER_free(cipher); - EVP_CIPHER_CTX_free(ctx); - return ret; -} - -int setup_tests(void) -{ - ADD_TEST(aeswrap_input_size_fail_test); - ADD_TEST(aeswrap_multi_update_fail_test); - ADD_ALL_TESTS(aeswrap_null_key_init_fail_test, - OSSL_NELEM(aeswrap_null_key_ciphers)); - return 1; -} diff --git a/test/algorithmid_test.c b/test/algorithmid_test.c index f4732bc30c..09ab73e839 100644 --- a/test/algorithmid_test.c +++ b/test/algorithmid_test.c @@ -20,7 +20,7 @@ static const char *pubkey_filename = NULL; /* For test_spki_file() */ #define ALGORITHMID_NAME "algorithm-id" -static int test_spki_aid(const X509_PUBKEY *pubkey, const char *filename) +static int test_spki_aid(X509_PUBKEY *pubkey, const char *filename) { const ASN1_OBJECT *oid; X509_ALGOR *alg = NULL; @@ -103,7 +103,7 @@ end: static int test_x509_spki_aid(X509 *cert, const char *filename) { - const X509_PUBKEY *pubkey = X509_get_X509_PUBKEY(cert); + X509_PUBKEY *pubkey = X509_get_X509_PUBKEY(cert); return test_spki_aid(pubkey, filename); } diff --git a/test/asn1_decode_test.c b/test/asn1_decode_test.c index 8a9629c21d..7796968c23 100644 --- a/test/asn1_decode_test.c +++ b/test/asn1_decode_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2017-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -14,11 +14,7 @@ #include #include #include -#include -#include -#include #include "internal/numbers.h" -#include "internal/asn1.h" #include "testutil.h" #ifdef __GNUC__ @@ -45,7 +41,7 @@ ASN1_SEQUENCE(ASN1_LONG_DATA) = { ASN1_EMBED(ASN1_LONG_DATA, test_long, LONG), } static_ASN1_SEQUENCE_END(ASN1_LONG_DATA) -IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_LONG_DATA) + IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_LONG_DATA) IMPLEMENT_STATIC_ASN1_ALLOC_FUNCTIONS(ASN1_LONG_DATA) static int test_long(void) @@ -71,7 +67,7 @@ ASN1_SEQUENCE(ASN1_INT32_DATA) = { ASN1_EMBED(ASN1_INT32_DATA, test_int32, INT32), } static_ASN1_SEQUENCE_END(ASN1_INT32_DATA) -IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_INT32_DATA) + IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_INT32_DATA) IMPLEMENT_STATIC_ASN1_ALLOC_FUNCTIONS(ASN1_INT32_DATA) static int test_int32(void) @@ -96,7 +92,7 @@ ASN1_SEQUENCE(ASN1_UINT32_DATA) = { ASN1_EMBED(ASN1_UINT32_DATA, test_uint32, UINT32), } static_ASN1_SEQUENCE_END(ASN1_UINT32_DATA) -IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_UINT32_DATA) + IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_UINT32_DATA) IMPLEMENT_STATIC_ASN1_ALLOC_FUNCTIONS(ASN1_UINT32_DATA) static int test_uint32(void) @@ -121,7 +117,7 @@ ASN1_SEQUENCE(ASN1_INT64_DATA) = { ASN1_EMBED(ASN1_INT64_DATA, test_int64, INT64), } static_ASN1_SEQUENCE_END(ASN1_INT64_DATA) -IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_INT64_DATA) + IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_INT64_DATA) IMPLEMENT_STATIC_ASN1_ALLOC_FUNCTIONS(ASN1_INT64_DATA) static int test_int64(void) @@ -146,7 +142,7 @@ ASN1_SEQUENCE(ASN1_UINT64_DATA) = { ASN1_EMBED(ASN1_UINT64_DATA, test_uint64, UINT64), } static_ASN1_SEQUENCE_END(ASN1_UINT64_DATA) -IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_UINT64_DATA) + IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_UINT64_DATA) IMPLEMENT_STATIC_ASN1_ALLOC_FUNCTIONS(ASN1_UINT64_DATA) static int test_uint64(void) @@ -167,8 +163,21 @@ static int test_gentime(void) { /* Underflowing GeneralizedTime 161208193400Z (YYMMDDHHMMSSZ) */ const unsigned char der[] = { - 0x18, 0x0d, 0x31, 0x36, 0x31, 0x32, 0x30, 0x38, 0x31, 0x39, - 0x33, 0x34, 0x30, 0x30, 0x5a + 0x18, + 0x0d, + 0x31, + 0x36, + 0x31, + 0x32, + 0x30, + 0x38, + 0x31, + 0x39, + 0x33, + 0x34, + 0x30, + 0x30, + 0x5a, }; const unsigned char *p; int der_len, rc = 1; @@ -191,8 +200,19 @@ static int test_utctime(void) { /* Underflowing UTCTime 0205104700Z (MMDDHHMMSSZ) */ const unsigned char der[] = { - 0x17, 0x0b, 0x30, 0x32, 0x30, 0x35, 0x31, 0x30, 0x34, 0x37, - 0x30, 0x30, 0x5a + 0x17, + 0x0b, + 0x30, + 0x32, + 0x30, + 0x35, + 0x31, + 0x30, + 0x34, + 0x37, + 0x30, + 0x30, + 0x5a, }; const unsigned char *p; int der_len, rc = 1; @@ -223,7 +243,7 @@ ASN1_SEQUENCE(INVALIDTEMPLATE) = { ASN1_IMP(INVALIDTEMPLATE, invalidDirString, DIRECTORYSTRING, 12) } static_ASN1_SEQUENCE_END(INVALIDTEMPLATE) -IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(INVALIDTEMPLATE) + IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(INVALIDTEMPLATE) IMPLEMENT_STATIC_ASN1_ALLOC_FUNCTIONS(INVALIDTEMPLATE) /* Empty sequence for invalid template test */ @@ -270,163 +290,6 @@ err: return ret; } -/* - * A minimal, complete DER object: SEQUENCE { INTEGER 0 }. - * asn1_d2i_read_bio() should consume exactly these bytes. - */ -static const unsigned char one_obj[] = { - 0x30, 0x03, /* SEQUENCE, length 3 */ - 0x02, 0x01, 0x00 /* INTEGER 0 */ -}; - -/* - * Reading concatenated DER objects from a BIO must stop cleanly at EOF: - * once the input is exhausted on an object boundary, asn1_d2i_read_bio() - * returns < 0 and must NOT leave an error on the queue. Callers that loop - * over concatenated values (e.g. CPython's ssl module loading the Windows - * certificate store via d2i_X509_bio()) rely on this to detect end-of-input; - * a spurious ASN1_R_NOT_ENOUGH_DATA there is reported as a fatal error. - */ -static int test_d2i_read_bio_clean_eof(void) -{ - unsigned char two_objs[sizeof(one_obj) * 2]; - BIO *bio = NULL; - BUF_MEM *buf = NULL; - int ret = 0; - - memcpy(two_objs, one_obj, sizeof(one_obj)); - memcpy(two_objs + sizeof(one_obj), one_obj, sizeof(one_obj)); - - if (!TEST_ptr(bio = BIO_new_mem_buf(two_objs, sizeof(two_objs)))) - goto err; - ERR_clear_error(); - - /* Both complete objects are read, one per call. */ - if (!TEST_int_eq(asn1_d2i_read_bio(bio, &buf), (int)sizeof(one_obj))) - goto err; - BUF_MEM_free(buf); - buf = NULL; - if (!TEST_int_eq(asn1_d2i_read_bio(bio, &buf), (int)sizeof(one_obj))) - goto err; - BUF_MEM_free(buf); - buf = NULL; - - /* Clean EOF: failure return, but no error must be queued. */ - if (!TEST_int_lt(asn1_d2i_read_bio(bio, &buf), 0)) - goto err; - if (!TEST_ulong_eq(ERR_peek_error(), 0)) - goto err; - - ret = 1; -err: - BUF_MEM_free(buf); - BIO_free(bio); - return ret; -} - -/* - * In contrast, hitting EOF in the middle of an object is genuine truncation - * and must still be reported as ASN1_R_NOT_ENOUGH_DATA. - */ -static int test_d2i_read_bio_truncated(void) -{ - static const unsigned char truncated[] = { - 0x30, 0x05, /* SEQUENCE claims 5 content bytes ... */ - 0x02, 0x01 /* ... but only 2 are present */ - }; - BIO *bio = NULL; - BUF_MEM *buf = NULL; - unsigned long e; - int ret = 0; - - if (!TEST_ptr(bio = BIO_new_mem_buf(truncated, sizeof(truncated)))) - goto err; - ERR_clear_error(); - - if (!TEST_int_lt(asn1_d2i_read_bio(bio, &buf), 0)) - goto err; - e = ERR_peek_last_error(); - if (!TEST_int_eq(ERR_GET_LIB(e), ERR_LIB_ASN1) - || !TEST_int_eq(ERR_GET_REASON(e), ASN1_R_NOT_ENOUGH_DATA)) - goto err; - - ret = 1; -err: - BUF_MEM_free(buf); - BIO_free(bio); - return ret; -} - -/* - * An EOF reached while still inside an indefinite-length constructed value, - * before its end-of-contents octets, is truncation too (not a clean boundary), - * so it must also report ASN1_R_NOT_ENOUGH_DATA rather than an empty queue. - */ -static int test_d2i_read_bio_indefinite_truncated(void) -{ - /* SEQUENCE (indefinite) { INTEGER 0 } with the 00 00 EOC missing */ - static const unsigned char truncated_indefinite[] = { - 0x30, 0x80, /* SEQUENCE, indefinite length */ - 0x02, 0x01, 0x00 /* INTEGER 0; no end-of-contents octets follow */ - }; - BIO *bio = NULL; - BUF_MEM *buf = NULL; - unsigned long e; - int ret = 0; - - bio = BIO_new_mem_buf(truncated_indefinite, sizeof(truncated_indefinite)); - if (!TEST_ptr(bio)) - goto err; - ERR_clear_error(); - - if (!TEST_int_lt(asn1_d2i_read_bio(bio, &buf), 0)) - goto err; - e = ERR_peek_last_error(); - if (!TEST_int_eq(ERR_GET_LIB(e), ERR_LIB_ASN1) - || !TEST_int_eq(ERR_GET_REASON(e), ASN1_R_NOT_ENOUGH_DATA)) - goto err; - - ret = 1; -err: - BUF_MEM_free(buf); - BIO_free(bio); - return ret; -} - -/* - * An EOF reached part-way through an object's header, with some header bytes - * already buffered, is truncation as well. This exercises the "diff != 0" arm - * of the header-read check (distinct from the body read handled elsewhere). - */ -static int test_d2i_read_bio_partial_header(void) -{ - /* SEQUENCE with a 2-byte long-form length, but only one length byte given */ - static const unsigned char partial_header[] = { - 0x30, 0x82, 0x01 /* SEQUENCE, length declared as 2 bytes, 1 present */ - }; - BIO *bio = NULL; - BUF_MEM *buf = NULL; - unsigned long e; - int ret = 0; - - if (!TEST_ptr(bio = BIO_new_mem_buf(partial_header, sizeof(partial_header)))) - goto err; - ERR_clear_error(); - - if (!TEST_int_lt(asn1_d2i_read_bio(bio, &buf), 0)) - goto err; - e = ERR_peek_last_error(); - if (!TEST_int_eq(ERR_GET_LIB(e), ERR_LIB_ASN1) - || !TEST_int_eq(ERR_GET_REASON(e), ASN1_R_NOT_ENOUGH_DATA)) - goto err; - - ret = 1; -err: - BUF_MEM_free(buf); - BIO_free(bio); - return ret; -} - int setup_tests(void) { #ifndef OPENSSL_NO_DEPRECATED_3_0 @@ -440,9 +303,5 @@ int setup_tests(void) ADD_TEST(test_utctime); ADD_TEST(test_invalid_template); ADD_TEST(test_reuse_asn1_object); - ADD_TEST(test_d2i_read_bio_clean_eof); - ADD_TEST(test_d2i_read_bio_truncated); - ADD_TEST(test_d2i_read_bio_indefinite_truncated); - ADD_TEST(test_d2i_read_bio_partial_header); return 1; } diff --git a/test/asn1_encode_test.c b/test/asn1_encode_test.c index 07f6b61c7e..b83e7826b1 100644 --- a/test/asn1_encode_test.c +++ b/test/asn1_encode_test.c @@ -198,7 +198,7 @@ ASN1_SEQUENCE(ASN1_LONG_DATA) = { ASN1_EXP_OPT(ASN1_LONG_DATA, test_zlong, ZLONG, 0) } static_ASN1_SEQUENCE_END(ASN1_LONG_DATA) -IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_LONG_DATA) + IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_LONG_DATA) IMPLEMENT_STATIC_ASN1_ALLOC_FUNCTIONS(ASN1_LONG_DATA) static ASN1_LONG_DATA long_expected_32bit[] = { @@ -292,7 +292,7 @@ ASN1_SEQUENCE(ASN1_INT32_DATA) = { ASN1_EXP_OPT_EMBED(ASN1_INT32_DATA, test_zint32, ZINT32, 0) } static_ASN1_SEQUENCE_END(ASN1_INT32_DATA) -IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_INT32_DATA) + IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_INT32_DATA) IMPLEMENT_STATIC_ASN1_ALLOC_FUNCTIONS(ASN1_INT32_DATA) static ASN1_INT32_DATA int32_expected[] = { @@ -340,7 +340,7 @@ ASN1_SEQUENCE(ASN1_UINT32_DATA) = { ASN1_EXP_OPT_EMBED(ASN1_UINT32_DATA, test_zuint32, ZUINT32, 0) } static_ASN1_SEQUENCE_END(ASN1_UINT32_DATA) -IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_UINT32_DATA) + IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_UINT32_DATA) IMPLEMENT_STATIC_ASN1_ALLOC_FUNCTIONS(ASN1_UINT32_DATA) static ASN1_UINT32_DATA uint32_expected[] = { @@ -388,7 +388,7 @@ ASN1_SEQUENCE(ASN1_INT64_DATA) = { ASN1_EXP_OPT_EMBED(ASN1_INT64_DATA, test_zint64, ZINT64, 0) } static_ASN1_SEQUENCE_END(ASN1_INT64_DATA) -IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_INT64_DATA) + IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_INT64_DATA) IMPLEMENT_STATIC_ASN1_ALLOC_FUNCTIONS(ASN1_INT64_DATA) static ASN1_INT64_DATA int64_expected[] = { @@ -437,7 +437,7 @@ ASN1_SEQUENCE(ASN1_UINT64_DATA) = { ASN1_EXP_OPT_EMBED(ASN1_UINT64_DATA, test_zuint64, ZUINT64, 0) } static_ASN1_SEQUENCE_END(ASN1_UINT64_DATA) -IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_UINT64_DATA) + IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(ASN1_UINT64_DATA) IMPLEMENT_STATIC_ASN1_ALLOC_FUNCTIONS(ASN1_UINT64_DATA) static ASN1_UINT64_DATA uint64_expected[] = { @@ -874,7 +874,7 @@ ASN1_SEQUENCE(INVALIDTEMPLATE) = { ASN1_IMP(INVALIDTEMPLATE, invalidDirString, DIRECTORYSTRING, 12) } static_ASN1_SEQUENCE_END(INVALIDTEMPLATE) -IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(INVALIDTEMPLATE) + IMPLEMENT_STATIC_ASN1_ENCODE_FUNCTIONS(INVALIDTEMPLATE) IMPLEMENT_STATIC_ASN1_ALLOC_FUNCTIONS(INVALIDTEMPLATE) static int test_invalid_template(void) diff --git a/test/asn1_internal_test.c b/test/asn1_internal_test.c index 469daafc4c..e08e2a11be 100644 --- a/test/asn1_internal_test.c +++ b/test/asn1_internal_test.c @@ -1,5 +1,5 @@ /* - * Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1999-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -20,7 +20,6 @@ #include #include -#include #include #include #include "testutil.h" @@ -185,9 +184,9 @@ static int test_unicode_range(void) "\xff\xff\xff\xff"; int ok = 1; - if (!test_unicode(univ_ok, sizeof(univ_ok) - 1, V_ASN1_UTF8STRING)) + if (!test_unicode(univ_ok, sizeof univ_ok - 1, V_ASN1_UTF8STRING)) ok = 0; - if (!test_unicode(univ_bad, sizeof(univ_bad) - 1, -1)) + if (!test_unicode(univ_bad, sizeof univ_bad - 1, -1)) ok = 0; return ok; } @@ -195,9 +194,9 @@ static int test_unicode_range(void) static int test_invalid_utf8(void) { const unsigned char inv_utf8[] = "\xF4\x90\x80\x80"; - uint32_t val; + unsigned long val; - if (!TEST_int_lt(ossl_utf8_getc_internal(inv_utf8, sizeof(inv_utf8), &val), 0)) + if (!TEST_int_lt(UTF8_getc(inv_utf8, sizeof(inv_utf8), &val), 0)) return 0; return 1; } @@ -476,7 +475,7 @@ static int posix_time_test(void) /* * Frequently platform conversions can not deal with one second before the - * Unix epoch, due to inheriting terrible API design and knocking this + * the Unix epoch, due to inheriting terrible API design and knocking this * time value out as an error return. * * We should do better. @@ -555,38 +554,6 @@ err: return ret; } -static int test_mbstring_ncopy(void) -{ - ASN1_STRING *str = NULL; - const unsigned char in[] = { 0xFF, 0xFE, 0xFF, 0xFE }; - int inlen = 4; - int inform = MBSTRING_UNIV; - - if (!TEST_int_eq(ASN1_mbstring_ncopy(&str, in, inlen, inform, B_ASN1_GENERALSTRING, 0, 0), -1) - || !TEST_int_eq(ASN1_mbstring_ncopy(&str, in, inlen, inform, B_ASN1_VISIBLESTRING, 0, 0), -1) - || !TEST_int_eq(ASN1_mbstring_ncopy(&str, in, inlen, inform, B_ASN1_VIDEOTEXSTRING, 0, 0), -1) - || !TEST_int_eq(ASN1_mbstring_ncopy(&str, in, inlen, inform, B_ASN1_GENERALIZEDTIME, 0, 0), -1)) - return 0; - - return 1; -} - -static int test_ossl_uni2utf8(void) -{ - const unsigned char in[] = { 0x21, 0x92 }; /* unicode right arrow */ - int inlen = 2; - char *out = NULL; - int ok = 0; - - /* reproducer for CVE-2025-69419 */ - out = OPENSSL_uni2utf8(in, inlen); - if (TEST_str_eq(out, "\xe2\x86\x92")) - ok = 1; - - OPENSSL_free(out); - return ok; -} - int setup_tests(void) { ADD_TEST(test_tbl_standard); @@ -598,7 +565,5 @@ int setup_tests(void) ADD_TEST(test_obj_nid_undef); ADD_TEST(posix_time_test); ADD_TEST(test_asn1_time_tm_conversions); - ADD_TEST(test_mbstring_ncopy); - ADD_TEST(test_ossl_uni2utf8); return 1; } diff --git a/test/asn1_string_test.c b/test/asn1_string_test.c deleted file mode 100644 index 865003eeb9..0000000000 --- a/test/asn1_string_test.c +++ /dev/null @@ -1,561 +0,0 @@ -/* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* ASN1_STRING tests */ - -#include - -#include -#include "testutil.h" - -struct abs_get_length_test { - const char *descr; - int valid; - const unsigned char der[20]; - int der_len; - size_t length; - int unused_bits; -}; - -static const struct abs_get_length_test abs_get_length_tests[] = { - { - .descr = "zero bits", - .valid = 1, - .der = { 0x03, 0x01, 0x00 }, - .der_len = 3, - .length = 0, - .unused_bits = 0, - }, - { - .descr = "zero bits one unused", - .valid = 0, - .der = { 0x03, 0x01, 0x01 }, - .der_len = 3, - }, - { - .descr = "single zero bit", - .valid = 1, - .der = { 0x03, 0x02, 0x07, 0x00 }, - .der_len = 4, - .length = 1, - .unused_bits = 7, - }, - { - .descr = "single one bit", - .valid = 1, - .der = { 0x03, 0x02, 0x07, 0x80 }, - .der_len = 4, - .length = 1, - .unused_bits = 7, - }, - { - /* XXX - the library pretends this is 03 02 07 80 */ - .descr = "invalid: single one bit, seventh bit set", - .valid = 1, - .der = { 0x03, 0x02, 0x07, 0xc0 }, - .der_len = 4, - .length = 1, - .unused_bits = 7, - }, - { - .descr = "x.690, primitive encoding in example 8.6.4.2", - .valid = 1, - .der = { 0x03, 0x07, 0x04, 0x0A, 0x3b, 0x5F, 0x29, 0x1c, 0xd0 }, - .der_len = 9, - .length = 6, - .unused_bits = 4, - }, - { - /* - * XXX - the library thinks it "decodes" this but gets it - * quite wrong. Looks like it uses the unused bits of the - * first component, and the unused bits octet 04 of the - * second component somehow becomes part of the value. - */ - .descr = "x.690, constructed encoding in example 8.6.4.2", - .valid = 1, - .der = { 0x23, 0x80, 0x03, 0x03, 0x00, 0x0A, 0x3b, 0x03, 0x05, 0x04, - 0x5F, 0x29, 0x1c, 0xd0, 0x00, 0x00 }, - .der_len = 16, - .length = 7, /* XXX - should be 6. */ - .unused_bits = 0, /* XXX - should be 4. */ - }, - { - .descr = "RFC 3779, 2.1.1, IPv4 address 10.5.0.4", - .valid = 1, - .der = { 0x03, 0x05, 0x00, 0x0a, 0x05, 0x00, 0x04 }, - .der_len = 7, - .length = 4, - .unused_bits = 0, - }, - { - .descr = "RFC 3779, 2.1.1, IPv4 prefix 10.5.0/23", - .valid = 1, - .der = { 0x03, 0x04, 0x01, 0x0a, 0x05, 0x00 }, - .der_len = 6, - .length = 3, - .unused_bits = 1, - }, - { - .descr = "RFC 3779, 2.1.1, IPv6 address 2001:0:200:3::1", - .valid = 1, - .der = { 0x03, 0x11, 0x00, 0x20, 0x01, 0x00, 0x00, 0x02, 0x00, 0x00, - 0x00, 0x00, 0x03, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01 }, - .der_len = 19, - .length = 16, - .unused_bits = 0, - }, - { - .descr = "RFC 3779, 2.1.1, IPv6 prefix 2001:0:200/39", - .valid = 1, - .der = { 0x03, 0x06, 0x01, 0x20, 0x01, 0x00, 0x00, 0x02 }, - .der_len = 8, - .length = 5, - .unused_bits = 1, - }, -}; - -static int -abs_get_length_test(const struct abs_get_length_test *tbl, int idx) -{ - const struct abs_get_length_test *test = &tbl[idx]; - ASN1_BIT_STRING *abs = NULL; - const unsigned char *p; - int unused_bits, ret; - size_t length; - int success = 0; - - p = test->der; - if (!TEST_ptr(abs = d2i_ASN1_BIT_STRING(NULL, &p, test->der_len))) { - TEST_info("%s, (idx=%d) - d2i_ASN1_BIT_STRING faled", OPENSSL_FUNC, idx); - goto err; - } - - ret = ASN1_BIT_STRING_get_length(abs, &length, &unused_bits); - if (!TEST_int_eq(test->valid, ret)) { - TEST_info("%s (idx=%d): %s ASN1_BIT_STRING_get_length want %d, got %d\n", - OPENSSL_FUNC, idx, test->descr, test->valid, ret); - goto err; - } - if (!test->valid) - goto done; - - if (!TEST_size_t_eq(length, test->length) - || !TEST_int_eq(unused_bits, test->unused_bits)) { - TEST_info("%s: (idx=%d) %s: want (%zu, %d), got (%zu, %d)\n", OPENSSL_FUNC, - idx, test->descr, test->length, test->unused_bits, length, - unused_bits); - goto err; - } - -done: - success = 1; - -err: - ASN1_STRING_free(abs); - - return success; -} - -static int -asn1_bit_string_get_length_test(int idx) -{ - return abs_get_length_test(abs_get_length_tests, idx); -} - -struct abs_set1_test { - const char *descr; - int valid; - const uint8_t data[20]; - size_t length; - int unused_bits; - const unsigned char der[20]; - int der_len; -}; - -static const struct abs_set1_test abs_set1_tests[] = { - { - .descr = "length too large", - .valid = 0, - .length = (size_t)INT_MAX + 1, - }, - { - .descr = "negative unused bits", - .valid = 0, - .unused_bits = -1, - }, - { - .descr = "8 unused bits", - .valid = 0, - .unused_bits = 8, - }, - { - .descr = "empty with unused bits", - .valid = 0, - .data = { - 0x00 }, - .length = 0, - .unused_bits = 1, - }, - { - .descr = "empty", - .valid = 1, - .data = { 0x00 }, - .length = 0, - .unused_bits = 0, - .der = { 0x03, 0x01, 0x00 }, - .der_len = 3, - }, - { - .descr = "single zero bit", - .valid = 1, - .data = { 0x00 }, - .length = 1, - .unused_bits = 7, - .der = { 0x03, 0x02, 0x07, 0x00 }, - .der_len = 4, - }, - { - .descr = "single zero bit, with non-zero unused bit 6", - .valid = 0, - .data = { 0x40 }, - .length = 1, - .unused_bits = 7, - }, - { - .descr = "single zero bit, with non-zero unused bit 0", - .valid = 0, - .data = { 0x01 }, - .length = 1, - .unused_bits = 7, - }, - { - .descr = "single one bit", - .valid = 1, - .data = { 0x80 }, - .length = 1, - .unused_bits = 7, - .der = { 0x03, 0x02, 0x07, 0x80 }, - .der_len = 4, - }, - { - .descr = "single one bit, with non-zero unused-bit 6", - .valid = 0, - .data = { 0xc0 }, - .length = 1, - .unused_bits = 7, - }, - { - .descr = "single one bit, with non-zero unused-bit 0", - .valid = 0, - .data = { 0x81 }, - .length = 1, - .unused_bits = 7, - }, - { - .descr = "RFC 3779, 2.1.1, IPv4 address 10.5.0.4", - .valid = 1, - .data = { 0x0a, 0x05, 0x00, 0x04 }, - .length = 4, - .unused_bits = 0, - .der = { 0x03, 0x05, 0x00, 0x0a, 0x05, 0x00, 0x04 }, - .der_len = 7, - }, - { - .descr = "RFC 3779, 2.1.1, IPv4 address 10.5.0/23", - .valid = 1, - .data = { 0x0a, 0x05, 0x00 }, - .length = 3, - .unused_bits = 1, - .der = { 0x03, 0x04, 0x01, 0x0a, 0x05, 0x00 }, - .der_len = 6, - }, - { - .descr = "RFC 3779, 2.1.1, IPv4 address 10.5.0/23, unused bit", - .valid = 0, - .data = { 0x0a, 0x05, 0x01 }, - .length = 3, - .unused_bits = 1, - }, - { - .descr = "RFC 3779, IPv4 address 10.5.0/17", - .valid = 1, - .data = { 0x0a, 0x05, 0x00 }, - .length = 3, - .unused_bits = 7, - .der = { 0x03, 0x04, 0x07, 0x0a, 0x05, 0x00 }, - .der_len = 6, - }, - { - .descr = "RFC 3779, IPv4 address 10.5.0/18, unused bit set", - .valid = 0, - .data = { 0x0a, 0x05, 0x20 }, - .length = 3, - .unused_bits = 6, - }, - { - .descr = "RFC 3779, 2.1.1, IPv6 address 2001:0:200:3::1", - .valid = 1, - .data = { 0x20, 0x01, 0x00, 0x00, 0x02, 0x00, 0x00, 0x00, 0x00, 0x03, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01 }, - .length = 16, - .unused_bits = 0, - .der = { 0x03, 0x11, 0x00, 0x20, 0x01, 0x00, 0x00, 0x02, 0x00, 0x00, 0x00, 0x00, 0x03, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01 }, - .der_len = 19, - }, - { - .descr = "RFC 3779, IPv6 address 2001:0:200:3::/127", - .valid = 1, - .data = { 0x20, 0x01, 0x00, 0x00, 0x02, 0x00, 0x00, 0x00, 0x00, 0x03, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 }, - .length = 16, - .unused_bits = 1, - .der = { 0x03, 0x11, 0x01, 0x20, 0x01, 0x00, 0x00, 0x02, 0x00, 0x00, 0x00, 0x00, 0x03, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 }, - .der_len = 19, - }, - { - .descr = "RFC 3779, IPv6 address 2001:0:200:3::/127, unused bit", - .valid = 0, - .data = { 0x20, 0x01, 0x00, 0x00, 0x02, 0x00, 0x00, 0x00, 0x00, 0x03, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01 }, - .length = 16, - .unused_bits = 1, - }, - { - .descr = "RFC 3779, 2.1.1, IPv6 address 2001:0:200:3::/39", - .valid = 1, - .data = { 0x20, 0x01, 0x00, 0x00, 0x02 }, - .length = 5, - .unused_bits = 1, - .der = { 0x03, 0x06, 0x01, 0x20, 0x01, 0x00, 0x00, 0x02 }, - .der_len = 8, - }, -}; - -static int -abs_set1_test(const struct abs_set1_test *tbl, int idx) -{ - const struct abs_set1_test *test = &tbl[idx]; - ASN1_BIT_STRING *abs = NULL; - unsigned char *der = NULL; - int ret, der_len = 0; - int success = 0; - - if (!TEST_ptr(abs = ASN1_BIT_STRING_new())) { - TEST_info("%s: (idx = %d) %s ASN1_BIT_STRING_new()", OPENSSL_FUNC, idx, test->descr); - goto err; - } - - ret = ASN1_BIT_STRING_set1(abs, test->data, test->length, test->unused_bits); - if (!TEST_int_eq(ret, test->valid)) { - TEST_info("%s: (idx = %d) %s ASN1_BIT_STRING_set1(): want %d, got %d", - OPENSSL_FUNC, idx, test->descr, test->valid, ret); - goto err; - } - - if (!test->valid) - goto done; - - der = NULL; - if (!TEST_int_eq((der_len = i2d_ASN1_BIT_STRING(abs, &der)), test->der_len)) { - TEST_info("%s: (idx=%d), %s i2d_ASN1_BIT_STRING(): want %d, got %d", - OPENSSL_FUNC, idx, test->descr, test->der_len, der_len); - if (der_len < 0) - der_len = 0; - goto err; - } - - if (!TEST_mem_eq(der, der_len, test->der, test->der_len)) { - TEST_info("%s: (idx = %d) %s DER mismatch", OPENSSL_FUNC, idx, test->descr); - goto err; - } - -done: - success = 1; - -err: - ASN1_BIT_STRING_free(abs); - OPENSSL_clear_free(der, der_len); - - return success; -} - -static int -asn1_bit_string_set1_test(int idx) -{ - return abs_set1_test(abs_set1_tests, idx); -} - -static int -asn1_string_new_not_owned_test(void) -{ - int success = 0; - ASN1_STRING *tmp = NULL; - char *tmpstring = NULL; - static const uint8_t data[] = { 0xba, 0xdb, 0x0b, 0xba, 0xdb, 0x0b, 0xba, 0xdb, 0x0b }; - static const uint8_t data2[] = { 0xba, 0xdb, 0x0b, 0xba, 0xdb, 0x0b, 0xba, 0xdb, 0x0b }; - - if (!TEST_ptr(tmp = ASN1_STRING_new_not_owned(V_ASN1_OCTET_STRING, data, sizeof(data)))) - goto err; - - ASN1_STRING_clear_free(tmp); - tmp = NULL; - - if (!TEST_mem_eq(data, sizeof(data), data2, sizeof(data2))) - goto err; - - if (!TEST_ptr(tmp = ASN1_STRING_new_not_owned(V_ASN1_OCTET_STRING, data, sizeof(data)))) - goto err; - - if (!TEST_true(ASN1_STRING_set_string(tmp, "muppet"))) - goto err; - - if (!TEST_mem_eq(data, sizeof(data), data2, sizeof(data2))) - goto err; - - if (!TEST_size_t_eq(ASN1_STRING_length_ex(tmp), strlen("muppet"))) - goto err; - - if (!TEST_mem_eq(ASN1_STRING_get0_data(tmp), strlen("muppet"), "muppet", strlen("muppet"))) - goto err; - - ASN1_STRING_clear_free(tmp); - tmp = NULL; - - if (!TEST_ptr(tmp = ASN1_STRING_new_not_owned(V_ASN1_OCTET_STRING, data, sizeof(data)))) - goto err; - - if (!TEST_ptr(tmpstring = OPENSSL_strdup("puppet"))) - goto err; - - ASN1_STRING_set0(tmp, tmpstring, 4); - - if (!TEST_mem_eq(data, sizeof(data), data2, sizeof(data2))) - goto err; - - if (!TEST_size_t_eq(ASN1_STRING_length_ex(tmp), 4)) - goto err; - - if (!TEST_mem_eq(ASN1_STRING_get0_data(tmp), strlen("puppet"), "puppet", strlen("puppet"))) - goto err; - - memset((uint8_t *)ASN1_STRING_get0_data(tmp), 'z', ASN1_STRING_length_ex(tmp)); - - if (!TEST_mem_eq(data, sizeof(data), data2, sizeof(data2))) - goto err; - - if (!TEST_mem_eq(tmpstring, strlen("puppet"), "zzzzet", strlen("puppet"))) - goto err; - - tmpstring = NULL; - ASN1_STRING_clear_free(tmp); - tmp = NULL; - - if (!TEST_ptr_null(tmp = ASN1_STRING_new_not_owned(V_ASN1_BIT_STRING, data, sizeof(data)))) - goto err; - - if (!TEST_ptr_null(tmp = ASN1_STRING_new_not_owned(V_ASN1_OCTET_STRING, NULL, sizeof(data)))) - goto err; - - if (!TEST_ptr_null(tmp = ASN1_STRING_new_not_owned(V_ASN1_OCTET_STRING, data, 0))) - goto err; - - if (!TEST_mem_eq(data, sizeof(data), data2, sizeof(data2))) - goto err; - - success = 1; - -err: - ASN1_STRING_clear_free(tmp); - - return success; -} - -static int -asn1_string_set_data_test(void) -{ - int success = 0; - ASN1_STRING *str = NULL; - const uint8_t *data; - - if (!TEST_ptr(str = ASN1_STRING_new())) - goto err; - - if (!TEST_false(ASN1_STRING_set_data(str, (uint8_t *)"hoobla", -1))) - goto err; - - if (!TEST_false(ASN1_STRING_set_data(str, (uint8_t *)"hoobla", (size_t)INT_MAX + 1))) - goto err; - - if (!TEST_true(ASN1_STRING_set_data(str, NULL, 10))) - goto err; - - if (!TEST_true(ASN1_STRING_set_data(str, (uint8_t *)"hoobla", strlen("hoobla")))) - goto err; - - data = ASN1_STRING_get0_data(str); - - if (!TEST_size_t_eq(ASN1_STRING_length_ex(str), 6)) - goto err; - - if (!TEST_int_eq(memcmp("hoobla", data, strlen("hoobla")), 0)) - goto err; - - if (!TEST_true(ASN1_STRING_set_data(str, (uint8_t *)"hoobla", strlen("hoobla") + 1))) - goto err; - - data = ASN1_STRING_get0_data(str); - - if (!TEST_size_t_eq(ASN1_STRING_length_ex(str), 7)) - goto err; - - if (!TEST_int_eq(strcmp("hoobla", (char *)data), 0)) - goto err; - - success = 1; - -err: - ASN1_STRING_free(str); - return success; -} - -static int -asn1_string_set_string_test(void) -{ - int success = 0; - ASN1_STRING *str = NULL; - - if (!TEST_ptr(str = ASN1_STRING_new())) - goto err; - - if (!TEST_true(ASN1_STRING_set_string(str, "foo"))) - goto err; - - if (!TEST_size_t_eq(ASN1_STRING_length_ex(str), 3)) - goto err; - - if (!TEST_true(ASN1_STRING_set_string(str, "hoob\0la"))) - goto err; - - if (!TEST_size_t_eq(ASN1_STRING_length_ex(str), 4)) - goto err; - - success = 1; - -err: - ASN1_STRING_free(str); - return success; -} - -int setup_tests(void) -{ - ADD_ALL_TESTS(asn1_bit_string_get_length_test, OSSL_NELEM(abs_get_length_tests)); - ADD_ALL_TESTS(asn1_bit_string_set1_test, OSSL_NELEM(abs_set1_tests)); - ADD_TEST(asn1_string_new_not_owned_test); - ADD_TEST(asn1_string_set_data_test); - ADD_TEST(asn1_string_set_string_test); - return 1; -} diff --git a/test/bad_dtls_test.c b/test/bad_dtls_test.c index 368921021d..904f28e2c2 100644 --- a/test/bad_dtls_test.c +++ b/test/bad_dtls_test.c @@ -46,15 +46,6 @@ /* For DTLS1_BAD_VER packets the MAC doesn't include the handshake header */ #define MAC_OFFSET (DTLS1_RT_HEADER_LENGTH + DTLS1_HM_HEADER_LENGTH) -static unsigned int infinite_timer_cb(SSL *s, unsigned int timer_us) -{ - (void)s; - - if (timer_us == 0) - return 999999999; - return timer_us; -} - static unsigned char client_random[SSL3_RANDOM_SIZE]; static unsigned char server_random[SSL3_RANDOM_SIZE]; @@ -110,17 +101,89 @@ static SSL_SESSION *client_session(void) 0x04, 0x20, /* OCTET_STRING, session id */ #define SS_SESSID_OFS 15 /* Session ID goes here */ - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, - 0x04, 0x30, /* OCTET_STRING, master secret */ + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x04, + 0x30, /* OCTET_STRING, master secret */ #define SS_SECRET_OFS 49 /* Master secret goes here */ - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, }; const unsigned char *p = session_asn1; @@ -240,8 +303,26 @@ static int send_hello_verify(BIO *rbio) 0x00, /* DTLS1_BAD_VER */ 0x14, /* Cookie length */ #define HV_COOKIE_OFS 28 /* Cookie goes here */ - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, }; memcpy(hello_verify + HV_COOKIE_OFS, cookie, sizeof(cookie)); @@ -251,7 +332,7 @@ static int send_hello_verify(BIO *rbio) return 1; } -static int send_server_hello(BIO *rbio, int reorder_ccs) +static int send_server_hello(BIO *rbio) { static unsigned char server_hello[] = { 0x16, /* Handshake */ @@ -282,18 +363,75 @@ static int send_server_hello(BIO *rbio, int reorder_ccs) 0x01, 0x00, /* DTLS1_BAD_VER */ #define SH_RANDOM_OFS 27 /* Server random goes here */ - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, 0x20, /* Session ID length */ #define SH_SESSID_OFS 60 /* Session ID goes here */ - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, 0x2f, /* Cipher suite AES128-SHA */ - 0x00 /* Compression null */ + 0x00, /* Compression null */ }; static unsigned char change_cipher_spec[] = { 0x14, /* Change Cipher Spec */ @@ -311,7 +449,7 @@ static int send_server_hello(BIO *rbio, int reorder_ccs) 0x03, /* Length */ 0x01, 0x00, - 0x02 /* Message */ + 0x02, /* Message */ }; memcpy(server_hello + SH_RANDOM_OFS, server_random, sizeof(server_random)); @@ -321,13 +459,8 @@ static int send_server_hello(BIO *rbio, int reorder_ccs) sizeof(server_hello) - MAC_OFFSET)) return 0; - if (reorder_ccs) { - BIO_write(rbio, change_cipher_spec, sizeof(change_cipher_spec)); - BIO_write(rbio, server_hello, sizeof(server_hello)); - } else { - BIO_write(rbio, server_hello, sizeof(server_hello)); - BIO_write(rbio, change_cipher_spec, sizeof(change_cipher_spec)); - } + BIO_write(rbio, server_hello, sizeof(server_hello)); + BIO_write(rbio, change_cipher_spec, sizeof(change_cipher_spec)); return 1; } @@ -532,9 +665,8 @@ static struct { /* The last test should be NODROP, because a DROP wouldn't get tested. */ }; -static int test_bad_dtls(int idx) +static int test_bad_dtls(void) { - int reorder_ccs = idx; SSL_SESSION *sess = NULL; SSL_CTX *ctx = NULL; SSL *con = NULL; @@ -602,8 +734,6 @@ static int test_bad_dtls(int idx) } SSL_set_connect_state(con); - if (reorder_ccs) - DTLS_set_timer_cb(con, infinite_timer_cb); /* Send initial ClientHello */ ret = SSL_do_handshake(con); @@ -617,7 +747,7 @@ static int test_bad_dtls(int idx) if (!TEST_int_le(ret, 0) || !TEST_int_eq(SSL_get_error(con, ret), SSL_ERROR_WANT_READ) || !TEST_int_eq(validate_client_hello(wbio), 2) - || !TEST_true(send_server_hello(rbio, reorder_ccs))) + || !TEST_true(send_server_hello(rbio))) goto end; ret = SSL_do_handshake(con); @@ -678,6 +808,6 @@ end: int setup_tests(void) { - ADD_ALL_TESTS(test_bad_dtls, 2); + ADD_TEST(test_bad_dtls); return 1; } diff --git a/test/base64_simdutf_test.c b/test/base64_simdutf_test.c deleted file mode 100644 index 2842e13cc2..0000000000 --- a/test/base64_simdutf_test.c +++ /dev/null @@ -1,247 +0,0 @@ -/* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include "testutil.h" -#include -#include "internal/cryptlib.h" -#include "crypto/evp.h" -#include "evp_local.h" - -#define MAX_INPUT_LEN 3000 - -static void fuzz_fill_encode_ctx(EVP_ENCODE_CTX *ctx, int max_fill) -{ - static int seeded = 0; - - if (!seeded) { - srand((unsigned)time(NULL)); - seeded = 1; - } - - int num = rand() % (max_fill + 1); - ctx->num = num; - - for (int i = 0; i < num; i++) - ctx->enc_data[i] = (unsigned char)(rand() & 0xFF); - ctx->line_num = rand() % (EVP_ENCODE_B64_LENGTH + 1); -} -static ossl_inline uint32_t next_u32(uint32_t *state) -{ - *state = (*state * 1664525u) + 1013904223u; - return *state; -} - -static const unsigned char data_bin2ascii[65] = "ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/"; -/* SRP uses a different base64 alphabet */ -static const unsigned char srpdata_bin2ascii[65] = "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz./"; - -#ifndef CHARSET_EBCDIC -#define conv_bin2ascii(a, table) ((table)[(a) & 0x3f]) -#else -/* - * We assume that PEM encoded files are EBCDIC files (i.e., printable text - * files). Convert them here while decoding. When encoding, output is EBCDIC - * (text) format again. (No need for conversion in the conv_bin2ascii macro, - * as the underlying textstring data_bin2ascii[] is already EBCDIC) - */ -#define conv_bin2ascii(a, table) ((table)[(a) & 0x3f]) -#endif - -static int evp_encodeblock_int_old(EVP_ENCODE_CTX *ctx, unsigned char *t, - const unsigned char *f, int dlen) -{ - int i, ret = 0; - unsigned long l; - const unsigned char *table; - - if (ctx != NULL && (ctx->flags & EVP_ENCODE_CTX_USE_SRP_ALPHABET) != 0) - table = srpdata_bin2ascii; - else - table = data_bin2ascii; - - for (i = dlen; i > 0; i -= 3) { - if (i >= 3) { - l = (((unsigned long)f[0]) << 16L) | (((unsigned long)f[1]) << 8L) | f[2]; - *(t++) = conv_bin2ascii(l >> 18L, table); - *(t++) = conv_bin2ascii(l >> 12L, table); - *(t++) = conv_bin2ascii(l >> 6L, table); - *(t++) = conv_bin2ascii(l, table); - } else { - l = ((unsigned long)f[0]) << 16L; - if (i == 2) - l |= ((unsigned long)f[1] << 8L); - - *(t++) = conv_bin2ascii(l >> 18L, table); - *(t++) = conv_bin2ascii(l >> 12L, table); - *(t++) = (i == 1) ? '=' : conv_bin2ascii(l >> 6L, table); - *(t++) = '='; - } - ret += 4; - f += 3; - } - - *t = '\0'; - return ret; -} -static int evp_encodeupdate_old(EVP_ENCODE_CTX *ctx, unsigned char *out, int *outl, - const unsigned char *in, int inl) -{ - int i, j; - int total = 0; - - *outl = 0; - if (inl <= 0) - return 0; - OPENSSL_assert(EVP_ENCODE_B64_LENGTH <= (int)sizeof(ctx->enc_data)); - if (EVP_ENCODE_B64_LENGTH - ctx->num > inl) { - memcpy(&(ctx->enc_data[ctx->num]), in, inl); - ctx->num += inl; - return 1; - } - if (ctx->num != 0) { - i = EVP_ENCODE_B64_LENGTH - ctx->num; - memcpy(&(ctx->enc_data[ctx->num]), in, i); - in += i; - inl -= i; - j = evp_encodeblock_int_old(ctx, out, ctx->enc_data, EVP_ENCODE_B64_LENGTH); - ctx->num = 0; - out += j; - total = j; - if ((ctx->flags & EVP_ENCODE_CTX_NO_NEWLINES) == 0) { - *(out++) = '\n'; - total++; - } - *out = '\0'; - } - while (inl >= EVP_ENCODE_B64_LENGTH) { - j = evp_encodeblock_int_old(ctx, out, in, EVP_ENCODE_B64_LENGTH); - in += EVP_ENCODE_B64_LENGTH; - inl -= EVP_ENCODE_B64_LENGTH; - out += j; - total += j; - if ((ctx->flags & EVP_ENCODE_CTX_NO_NEWLINES) == 0) { - *(out++) = '\n'; - total++; - } - *out = '\0'; - } - if (inl != 0) - memcpy(&(ctx->enc_data[0]), in, inl); - ctx->num = inl; - *outl = total; - - return 1; -} - -static void evp_encodefinal_old(EVP_ENCODE_CTX *ctx, unsigned char *out, int *outl) -{ - unsigned int ret = 0; - - if (ctx->num != 0) { - ret = evp_encodeblock_int_old(ctx, out, ctx->enc_data, ctx->num); - if ((ctx->flags & EVP_ENCODE_CTX_NO_NEWLINES) == 0) - out[ret++] = '\n'; - out[ret] = '\0'; - ctx->num = 0; - } - *outl = ret; -} - -static int test_encode_line_length_reinforced(void) -{ - const int trials = 50; - uint32_t seed = 12345; - /* Generous output buffers (Update + Final + newlines), plus a guard byte */ - unsigned char out_simd[9000 * 2 + 1] = { 0 }; - unsigned char out_ref[9000 * 2 + 1] = { 0 }; - EVP_ENCODE_CTX *ctx_simd = NULL; - EVP_ENCODE_CTX *ctx_ref = NULL; - - for (int t = 0; t < trials; t++) { - uint32_t r = next_u32(&seed); - int inl = r % MAX_INPUT_LEN; - /* Fresh random input */ - unsigned char input[MAX_INPUT_LEN]; - - for (int i = 0; i < inl; i++) - input[i] = (unsigned char)(r % 256); - - for (int partial_ctx_fill = 0; partial_ctx_fill <= 80; - partial_ctx_fill += 1) { - ctx_simd = EVP_ENCODE_CTX_new(); - ctx_ref = EVP_ENCODE_CTX_new(); - - if (!TEST_ptr(ctx_simd) || !TEST_ptr(ctx_ref)) - goto fail; - - fuzz_fill_encode_ctx(ctx_simd, partial_ctx_fill); - - memset(out_simd, 0xCC, sizeof(out_simd)); /* poison to catch short writes */ - memset(out_ref, 0xDD, sizeof(out_ref)); - - int outlen_simd = 0, outlen_ref = 0; /* bytes produced by Update */ - int finlen_simd = 0, finlen_ref = 0; /* bytes produced by Final */ - - EVP_EncodeInit(ctx_simd); - EVP_EncodeInit(ctx_ref); - - for (int i = 0; i < 2; i++) { - if (i % 2 == 0) { - /* Turn SRP alphabet OFF */ - ctx_simd->flags &= ~EVP_ENCODE_CTX_USE_SRP_ALPHABET; - ctx_ref->flags &= ~EVP_ENCODE_CTX_USE_SRP_ALPHABET; - } else { - /* Turn SRP alphabet ON */ - ctx_simd->flags |= EVP_ENCODE_CTX_USE_SRP_ALPHABET; - ctx_ref->flags |= EVP_ENCODE_CTX_USE_SRP_ALPHABET; - } - - int ret_simd = EVP_EncodeUpdate(ctx_simd, out_simd, &outlen_simd, - input, (int)inl); - int ret_ref = evp_encodeupdate_old(ctx_ref, out_ref, &outlen_ref, - input, (int)inl); - - if (!TEST_int_eq(ret_simd, ret_ref) - || !TEST_mem_eq(out_ref, outlen_ref, out_simd, outlen_simd) - || !TEST_int_eq(outlen_simd, outlen_ref)) - goto fail; - - EVP_EncodeFinal(ctx_simd, out_simd + outlen_simd, - &finlen_simd); - evp_encodefinal_old(ctx_ref, out_ref + outlen_ref, - &finlen_ref); - - int total_ref = outlen_ref + finlen_ref; - int total_simd = outlen_simd + finlen_simd; - - if (!TEST_int_eq(finlen_simd, finlen_ref) - || !TEST_mem_eq(out_ref, total_ref, out_simd, total_simd)) - goto fail; - } - - EVP_ENCODE_CTX_free(ctx_simd); - EVP_ENCODE_CTX_free(ctx_ref); - } - } - - return 1; - -fail: - EVP_ENCODE_CTX_free(ctx_simd); - EVP_ENCODE_CTX_free(ctx_ref); - return 0; -} - -int setup_tests(void) -{ - ADD_TEST(test_encode_line_length_reinforced); - - return 1; -} diff --git a/test/bftest.c b/test/bftest.c index 3b6d2ee4b6..03c2756d44 100644 --- a/test/bftest.c +++ b/test/bftest.c @@ -267,8 +267,8 @@ static int print_test_data(void) printf("\niv[8] = "); for (j = 0; j < 8; j++) printf("%02X", cbc_iv[j]); - printf("\ndata[%zu] = '%s'", strlen(cbc_data) + 1, cbc_data); - printf("\ndata[%zu] = ", strlen(cbc_data) + 1); + printf("\ndata[%d] = '%s'", (int)strlen(cbc_data) + 1, cbc_data); + printf("\ndata[%d] = ", (int)strlen(cbc_data) + 1); for (j = 0; j < strlen(cbc_data) + 1; j++) printf("%02X", cbc_data[j]); printf("\n"); @@ -279,13 +279,13 @@ static int print_test_data(void) printf("\n"); printf("cfb64 cipher text\n"); - printf("cipher[%zu]= ", strlen(cbc_data) + 1); + printf("cipher[%d]= ", (int)strlen(cbc_data) + 1); for (j = 0; j < strlen(cbc_data) + 1; j++) printf("%02X", cfb64_ok[j]); printf("\n"); printf("ofb64 cipher text\n"); - printf("cipher[%zu]= ", strlen(cbc_data) + 1); + printf("cipher[%d]= ", (int)strlen(cbc_data) + 1); for (j = 0; j < strlen(cbc_data) + 1; j++) printf("%02X", ofb64_ok[j]); printf("\n"); @@ -387,7 +387,7 @@ static int test_bf_cfb64(void) memset(cbc_out, 0, 40); memcpy(iv, cbc_iv, 8); n = 0; - BF_cfb64_encrypt((unsigned char *)cbc_data, cbc_out, 13, + BF_cfb64_encrypt((unsigned char *)cbc_data, cbc_out, (long)13, &key, iv, &n, BF_ENCRYPT); BF_cfb64_encrypt((unsigned char *)&(cbc_data[13]), &(cbc_out[13]), len - 13, &key, iv, &n, BF_ENCRYPT); @@ -419,7 +419,7 @@ static int test_bf_ofb64(void) memset(cbc_out, 0, 40); memcpy(iv, cbc_iv, 8); n = 0; - BF_ofb64_encrypt((unsigned char *)cbc_data, cbc_out, 13, &key, iv, + BF_ofb64_encrypt((unsigned char *)cbc_data, cbc_out, (long)13, &key, iv, &n); BF_ofb64_encrypt((unsigned char *)&(cbc_data[13]), &(cbc_out[13]), len - 13, &key, iv, &n); diff --git a/test/bio_base64_test.c b/test/bio_base64_test.c index 9d9ef4dfa0..6999573a73 100644 --- a/test/bio_base64_test.c +++ b/test/bio_base64_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -182,12 +182,12 @@ static int genb64(char *prefix, char *suffix, unsigned const char *buf, static int test_bio_base64_run(test_case *t, int llen, int wscnt) { - unsigned char *raw = NULL; - unsigned char *out = NULL; + unsigned char *raw; + unsigned char *out; unsigned out_len; char *encoded = NULL; int elen; - BIO *bio = NULL, *b64 = NULL; + BIO *bio, *b64; int n, n1, n2; int ret; @@ -208,17 +208,19 @@ static int test_bio_base64_run(test_case *t, int llen, int wscnt) out_len = t->bytes + 1024; out = OPENSSL_malloc(out_len); if (out == NULL) { + OPENSSL_free(raw); TEST_error("out of memory"); - ret = -1; - goto end; + return -1; } elen = genb64(t->prefix, t->suffix, raw, t->bytes, t->trunc, t->encoded, llen, wscnt, &encoded); if (elen < 0 || (bio = BIO_new(BIO_s_mem())) == NULL) { + OPENSSL_free(raw); + OPENSSL_free(out); + OPENSSL_free(encoded); TEST_error("out of memory"); - ret = -1; - goto end; + return -1; } if (t->retry) BIO_set_mem_eof_return(bio, EOF_RETURN); @@ -227,7 +229,7 @@ static int test_bio_base64_run(test_case *t, int llen, int wscnt) /* * When the input is long enough, and the source bio is retriable, exercise - * retries by writing the input to the underlying BIO in two steps (1024 + * retries by writting the input to the underlying BIO in two steps (1024 * bytes, then the rest) and trying to decode some data after each write. */ n1 = elen; @@ -236,10 +238,7 @@ static int test_bio_base64_run(test_case *t, int llen, int wscnt) if (n1 > 0) BIO_write(bio, encoded, n1); - if (!TEST_ptr(b64 = BIO_new(BIO_f_base64()))) { - ret = -1; - goto end; - } + b64 = BIO_new(BIO_f_base64()); if (t->no_nl) BIO_set_flags(b64, BIO_FLAGS_BASE64_NO_NL); BIO_push(b64, bio); @@ -297,12 +296,11 @@ static int test_bio_base64_run(test_case *t, int llen, int wscnt) ret = -1; } -end: - BIO_free(bio); - BIO_free(b64); - OPENSSL_free(raw); + BIO_free_all(b64); OPENSSL_free(out); + OPENSSL_free(raw); OPENSSL_free(encoded); + return ret; } @@ -428,45 +426,6 @@ static int test_bio_base64_corner_case_bug(int idx) return generic_case(&t, 0); } -#define MEM_CHK "QUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFB" \ - "QUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFB" \ - "QUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFB" - -static int test_bio_base64_no_nl(void) -{ - char msg[120]; - BIO *b64 = NULL; - BIO *mem = NULL; - BIO *b64_chk; - BUF_MEM *bptr = NULL; - int ok = 0; - - memset(msg, 'A', sizeof(msg)); - - b64 = BIO_new(BIO_f_base64()); - if (!TEST_ptr(b64)) - goto done; - - mem = BIO_new(BIO_s_mem()); - if (!TEST_ptr(mem)) - goto done; - - b64_chk = BIO_push(b64, mem); - if (!TEST_ptr_eq(b64, b64_chk)) - goto done; - - BIO_set_flags(b64, BIO_FLAGS_BASE64_NO_NL); - BIO_write(b64, msg, sizeof(msg)); - if (!TEST_true(BIO_flush(b64))) - goto done; - BIO_get_mem_ptr(mem, &bptr); - ok = TEST_mem_eq(MEM_CHK, sizeof(MEM_CHK) - 1, bptr->data, bptr->length); - -done: - BIO_free_all(b64); - return ok; -} - int setup_tests(void) { int numidx; @@ -522,6 +481,5 @@ int setup_tests(void) numidx = 2 * 2; ADD_ALL_TESTS(test_bio_base64_corner_case_bug, numidx); - ADD_TEST(test_bio_base64_no_nl); return 1; } diff --git a/test/bio_callback_test.c b/test/bio_callback_test.c index b0283c78ad..305abe0e1a 100644 --- a/test/bio_callback_test.c +++ b/test/bio_callback_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2018-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -13,7 +13,7 @@ #include "testutil.h" -#define MAXCOUNT 7 +#define MAXCOUNT 5 static int my_param_count; static BIO *my_param_b[MAXCOUNT]; static int my_param_oper[MAXCOUNT]; @@ -138,20 +138,20 @@ static int test_bio_callback_ex(void) my_param_count = 0; i = BIO_read(bio, buf, sizeof(buf)); if (!TEST_int_eq(i, 0) - || !TEST_int_eq(my_param_count, 6) + || !TEST_int_eq(my_param_count, 2) || !TEST_ptr_eq(my_param_b[0], bio) || !TEST_int_eq(my_param_oper[0], BIO_CB_READ) || !TEST_ptr_eq(my_param_argp[0], buf) || !TEST_size_t_eq(my_param_len[0], sizeof(buf)) || !TEST_long_eq(my_param_argl[0], 0L) || !TEST_int_eq((int)my_param_ret[0], 1) - || !TEST_ptr_eq(my_param_b[5], bio) - || !TEST_int_eq(my_param_oper[5], BIO_CB_READ | BIO_CB_RETURN) - || !TEST_ptr_eq(my_param_argp[5], buf) - || !TEST_size_t_eq(my_param_len[5], sizeof(buf)) - || !TEST_long_eq(my_param_argl[5], 0L) - || !TEST_size_t_eq(my_param_processed[5], 0) - || !TEST_int_eq((int)my_param_ret[5], 0)) + || !TEST_ptr_eq(my_param_b[1], bio) + || !TEST_int_eq(my_param_oper[1], BIO_CB_READ | BIO_CB_RETURN) + || !TEST_ptr_eq(my_param_argp[1], buf) + || !TEST_size_t_eq(my_param_len[1], sizeof(buf)) + || !TEST_long_eq(my_param_argl[1], 0L) + || !TEST_size_t_eq(my_param_processed[1], 0) + || !TEST_int_eq((int)my_param_ret[1], 0)) goto err; my_param_count = 0; @@ -291,19 +291,19 @@ static int test_bio_callback(void) my_param_count = 0; i = BIO_read(bio, buf, sizeof(buf)); if (!TEST_int_eq(i, 0) - || !TEST_int_eq(my_param_count, 6) + || !TEST_int_eq(my_param_count, 2) || !TEST_ptr_eq(my_param_b[0], bio) || !TEST_int_eq(my_param_oper[0], BIO_CB_READ) || !TEST_ptr_eq(my_param_argp[0], buf) || !TEST_int_eq(my_param_argi[0], sizeof(buf)) || !TEST_long_eq(my_param_argl[0], 0L) || !TEST_long_eq(my_param_ret[0], 1L) - || !TEST_ptr_eq(my_param_b[5], bio) - || !TEST_int_eq(my_param_oper[5], BIO_CB_READ | BIO_CB_RETURN) - || !TEST_ptr_eq(my_param_argp[5], buf) - || !TEST_int_eq(my_param_argi[5], sizeof(buf)) - || !TEST_long_eq(my_param_argl[5], 0L) - || !TEST_long_eq(my_param_ret[5], 0L)) + || !TEST_ptr_eq(my_param_b[1], bio) + || !TEST_int_eq(my_param_oper[1], BIO_CB_READ | BIO_CB_RETURN) + || !TEST_ptr_eq(my_param_argp[1], buf) + || !TEST_int_eq(my_param_argi[1], sizeof(buf)) + || !TEST_long_eq(my_param_argl[1], 0L) + || !TEST_long_eq(my_param_ret[1], 0L)) goto err; my_param_count = 0; diff --git a/test/bio_core_test.c b/test/bio_core_test.c index 26ff787eec..47705a7fad 100644 --- a/test/bio_core_test.c +++ b/test/bio_core_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -84,7 +84,6 @@ static int test_bio_core(void) || !TEST_ptr((cbio = BIO_new_from_core_bio(libctx, &corebio)))) goto err; - BIO_set_mem_eof_return(cbio, 0); if (!TEST_int_gt(BIO_puts(corebio.bio, msg), 0) /* Test a ctrl via BIO_eof */ || !TEST_false(BIO_eof(cbio)) @@ -108,38 +107,6 @@ err: return testresult; } -static int test_bio_vprintf_boundary(void) -{ - BIO *bio = NULL; - char *data; - long len; - int w; - int testresult = 0; - - /* - * At width 512, vsnprintf() reports 512 bytes excluding the NUL, - * so BIO_vprintf() must use its realloc path. - */ - for (w = 511; w <= 513; w++) { - bio = BIO_new(BIO_s_mem()); - if (!TEST_ptr(bio)) - goto err; - if (!TEST_int_eq(BIO_printf(bio, "%*d", w, 0), w)) - goto err; - len = BIO_get_mem_data(bio, &data); - if (!TEST_long_eq(len, w) - || !TEST_char_eq(data[w - 1], '0') - || !TEST_char_eq(data[0], ' ')) - goto err; - BIO_free(bio); - bio = NULL; - } - testresult = 1; -err: - BIO_free(bio); - return testresult; -} - int setup_tests(void) { if (!test_skip_common_options()) { @@ -148,6 +115,5 @@ int setup_tests(void) } ADD_TEST(test_bio_core); - ADD_TEST(test_bio_vprintf_boundary); return 1; } diff --git a/test/bio_dgram_test.c b/test/bio_dgram_test.c index fab840537c..6d32c1c103 100644 --- a/test/bio_dgram_test.c +++ b/test/bio_dgram_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -471,7 +471,7 @@ static int random_data(const uint32_t *key, uint8_t *data, size_t data_len, size if (cipher == NULL) goto err; - if (EVP_EncryptInit_ex2(ctx, cipher, (const uint8_t *)key, (uint8_t *)counter, NULL) == 0) + if (EVP_EncryptInit_ex2(ctx, cipher, (uint8_t *)key, (uint8_t *)counter, NULL) == 0) goto err; while (data_len > 0) { @@ -776,22 +776,6 @@ err: return testresult; } #endif /* !defined(OPENSSL_NO_CHACHA) */ - -static int test_bio_dgram_mfail(void) -{ - BIO *bio; - - MFAIL_start(); - bio = BIO_new(BIO_s_dgram_mem()); - MFAIL_end(); - - if (bio == NULL) - return 0; - - BIO_free(bio); - return 1; -} - #endif /* !defined(OPENSSL_NO_DGRAM) && !defined(OPENSSL_NO_SOCK) */ int setup_tests(void) @@ -806,7 +790,6 @@ int setup_tests(void) #if !defined(OPENSSL_NO_CHACHA) ADD_ALL_TESTS(test_bio_dgram_pair, 3); #endif - ADD_MFAIL_TEST(test_bio_dgram_mfail); #endif return 1; diff --git a/test/bio_eof_test.c b/test/bio_eof_test.c deleted file mode 100644 index da9b9d1f9e..0000000000 --- a/test/bio_eof_test.c +++ /dev/null @@ -1,264 +0,0 @@ -/* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include "testutil.h" - -#define TEST_FLAG_EOF_BEHAVIOUR 0x1000 - -static int bio_create(BIO *bio) -{ - BIO_set_init(bio, 1); - return 1; -} - -static int bio_destroy(BIO *bio) -{ - BIO_set_init(bio, 0); - return 1; -} - -/* - * Test1 & Test2 read callback (old style): - * returns 0 if TEST_FLAG_EOF_BEHAVIOUR is set, else -1. - */ -static int old_read_returns_0_or_minus1(BIO *bio, char *buf, int len) -{ - (void)buf; - (void)len; - return BIO_test_flags(bio, TEST_FLAG_EOF_BEHAVIOUR) ? 0 : -1; -} - -/* - * Test3 read_ex callback (new style): - * does nothing, always returns 0, sets *readbytes to 0. - */ -static int new_read_ex_always_0(BIO *bio, char *buf, size_t len, size_t *readbytes) -{ - (void)bio; - (void)buf; - (void)len; - if (readbytes != NULL) - *readbytes = 0; - return 0; -} - -/* Test1 ctrl: does nothing */ -static long ctrl_noop(BIO *bio, int cmd, long num, void *ptr) -{ - (void)bio; - (void)cmd; - (void)num; - (void)ptr; - return 0; -} - -/* Test2 ctrl: BIO_CTRL_EOF always returns 1 */ -static long ctrl_eof_always_1(BIO *bio, int cmd, long num, void *ptr) -{ - (void)bio; - (void)num; - (void)ptr; - if (cmd == BIO_CTRL_EOF) - return 1; - return 0; -} - -/* Test3 ctrl: BIO_CTRL_EOF returns 1 if TEST_FLAG_EOF_BEHAVIOUR is set */ -static long ctrl_eof_depends_on_flag(BIO *bio, int cmd, long num, void *ptr) -{ - (void)num; - (void)ptr; - if (cmd == BIO_CTRL_EOF) - return BIO_test_flags(bio, TEST_FLAG_EOF_BEHAVIOUR) ? 1 : 0; - return 0; -} - -static BIO_METHOD *make_meth_oldread(long (*ctrl)(BIO *, int, long, void *), - const char *name) -{ - BIO_METHOD *meth = NULL; - - if (!TEST_ptr(meth = BIO_meth_new(BIO_TYPE_SOURCE_SINK, name))) - goto err; - if (!TEST_int_eq(BIO_meth_set_read(meth, old_read_returns_0_or_minus1), 1)) - goto err; - if (!TEST_int_eq(BIO_meth_set_ctrl(meth, ctrl), 1)) - goto err; - if (!TEST_int_eq(BIO_meth_set_create(meth, bio_create), 1)) - goto err; - if (!TEST_int_eq(BIO_meth_set_destroy(meth, bio_destroy), 1)) - goto err; - return meth; - -err: - BIO_meth_free(meth); - return NULL; -} - -static BIO_METHOD *make_meth_newreadex(long (*ctrl)(BIO *, int, long, void *), - const char *name) -{ - BIO_METHOD *meth = NULL; - - if (!TEST_ptr(meth = BIO_meth_new(BIO_TYPE_SOURCE_SINK, name))) - goto err; - if (!TEST_int_eq(BIO_meth_set_read_ex(meth, new_read_ex_always_0), 1)) - goto err; - if (!TEST_int_eq(BIO_meth_set_ctrl(meth, ctrl), 1)) - goto err; - if (!TEST_int_eq(BIO_meth_set_create(meth, bio_create), 1)) - goto err; - if (!TEST_int_eq(BIO_meth_set_destroy(meth, bio_destroy), 1)) - goto err; - return meth; - -err: - BIO_meth_free(meth); - return NULL; -} - -static int run_subtest(const char *label, BIO_METHOD *meth, - int set_flag, int use_read_ex, - int exp_read_ret, int exp_eof_ret) -{ - BIO *bio = NULL; - char b = 0; - int r, eofr; - size_t n; - - if (!TEST_ptr(bio = BIO_new(meth))) - goto err; - - if (set_flag) - BIO_set_flags(bio, TEST_FLAG_EOF_BEHAVIOUR); - else - BIO_clear_flags(bio, TEST_FLAG_EOF_BEHAVIOUR); - - if (use_read_ex) { - r = BIO_read_ex(bio, &b, 1, &n); - if (!TEST_int_eq(r, exp_read_ret)) { - TEST_info("%s: BIO_read_ex ret=%d expected=%d", label, r, exp_read_ret); - goto err; - } - } else { - r = BIO_read(bio, &b, 1); - if (!TEST_int_eq(r, exp_read_ret)) { - TEST_info("%s: BIO_read ret=%d expected=%d", label, r, exp_read_ret); - goto err; - } - } - - eofr = BIO_eof(bio); - if (!TEST_int_eq(eofr, exp_eof_ret)) { - TEST_info("%s: BIO_eof ret=%d expected=%d", label, eofr, exp_eof_ret); - goto err; - } - - BIO_free(bio); - return 1; - -err: - BIO_free(bio); - return 0; -} - -static int old_style_read_without_eof_ctrl(void) -{ - int ok = 1; - BIO_METHOD *meth = NULL; - - if (!TEST_ptr(meth = make_meth_oldread(ctrl_noop, - "Old-style read without eof ctrl"))) - return 0; - - ok &= run_subtest("BIO_read, eof", meth, 1, 0, 0, 1); - ok &= run_subtest("BIO_read_ex, eof", meth, 1, 1, 0, 1); - ok &= run_subtest("BIO_read, error", meth, 0, 0, -1, 0); - ok &= run_subtest("BIO_read_ex, error", meth, 0, 1, 0, 0); - - BIO_meth_free(meth); - return ok; -} - -static int old_style_read_with_eof_ctrl(void) -{ - int ok = 1; - BIO_METHOD *meth = NULL; - - if (!TEST_ptr(meth = make_meth_oldread(ctrl_eof_always_1, - "Old-stype read with eof ctrl"))) - return 0; - - ok &= run_subtest("BIO_read, eof", meth, 1, 0, 0, 1); - ok &= run_subtest("BIO_read_ex, eof", meth, 1, 1, 0, 1); - ok &= run_subtest("BIO_read, error", meth, 0, 0, -1, 1); - ok &= run_subtest("BIO_read_ex, error", meth, 0, 1, 0, 1); - - BIO_meth_free(meth); - return ok; -} - -static int new_style_read_ex(void) -{ - int ok = 1; - BIO_METHOD *meth = NULL; - - if (!TEST_ptr(meth = make_meth_newreadex(ctrl_eof_depends_on_flag, - "New-style read_ex"))) - return 0; - - ok &= run_subtest("BIO_read, eof", meth, 1, 0, 0, 1); - ok &= run_subtest("BIO_read_ex, eof", meth, 1, 1, 0, 1); - ok &= run_subtest("BIO_read, error", meth, 0, 0, -1, 0); - ok &= run_subtest("BIO_read_ex, error", meth, 0, 1, 0, 0); - - BIO_meth_free(meth); - return ok; -} - -static int test_short_file_write(void) -{ -#if defined(OPENSSL_SYS_MACOSX) - int ok = 0; - char *data = "If you liked it then you should have put a test on it"; - char buf[20]; - FILE *stream = NULL; - BIO *bp = NULL; - - stream = fmemopen(buf, 20, "wb"); - if (!TEST_ptr(stream)) - goto err; - - bp = BIO_new_fp(stream, BIO_NOCLOSE); - if (!TEST_ptr(bp)) - goto err; - - if (!TEST_int_eq(BIO_write(bp, data, strlen(data)), 20)) - goto err; - - ok = 1; - -err: - fclose(stream); - BIO_free(bp); - return ok; -#else - return TEST_skip("short file write test not supported on this platform"); -#endif -} - -int setup_tests(void) -{ - ADD_TEST(old_style_read_without_eof_ctrl); - ADD_TEST(old_style_read_with_eof_ctrl); - ADD_TEST(new_style_read_ex); - ADD_TEST(test_short_file_write); - return 1; -} diff --git a/test/bio_socket_sigpipe_test.c b/test/bio_socket_sigpipe_test.c deleted file mode 100644 index b405136e7b..0000000000 --- a/test/bio_socket_sigpipe_test.c +++ /dev/null @@ -1,141 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#if !defined(OPENSSL_SYS_WINDOWS) && !defined(OPENSSL_NO_SOCK) && !defined(__DJGPP__) - -#include "internal/sockets.h" -#include -#include -#include - -#include "testutil.h" - -#include -#include - -static volatile sig_atomic_t sigpipe_seen = 0; - -static void sigpipe_handler(int sig) -{ - (void)sig; - sigpipe_seen++; -} - -/* - * 0 - normal flow - * 1 - kTLS - * 2 - TFO - */ -static int test_bio_write_triggers_sigpipe(int test) -{ -#if defined(MSG_NOSIGNAL) - int fds[2] = { -1, -1 }; - BIO *b = NULL; - const char c = 'x'; - int ret; - int ok = 0; - struct sigaction sa, oldsa; - - /* Install SIGPIPE handler */ - memset(&sa, 0, sizeof(sa)); - sa.sa_handler = sigpipe_handler; - sigemptyset(&sa.sa_mask); - sa.sa_flags = 0; - if (!TEST_int_eq(sigaction(SIGPIPE, &sa, &oldsa), 0)) - goto end; - - /* Create a pair of connected sockets. */ - if (!TEST_int_eq(socketpair(AF_UNIX, SOCK_STREAM, 0, fds), 0)) - goto end; - - /* Close peer end to make writes hit a broken pipe. */ - if (!TEST_int_eq(closesocket(fds[1]), 0)) - goto end; - fds[1] = -1; - - b = BIO_new_socket(fds[0], BIO_NOCLOSE); - if (!TEST_ptr(b)) - goto end; - /* - * Attempt write. We don't care about return value beyond - * "it attempted", the point is SIGPIPE delivery. - */ - ERR_clear_error(); - errno = 0; - sigpipe_seen = 0; - - if (test == 1) { -#ifndef OPENSSL_NO_KTLS - BIO_set_ktls_ctrl_msg_flag(b); -#else - TEST_skip("OPENSSL_NO_KTLS is defined\n"); - ok = 1; - goto end; -#endif - } - - if (test == 2) { -#ifdef OSSL_TFO_SENDTO - struct in_addr a4; - BIO_ADDR *peer = BIO_ADDR_new(); - if (!TEST_ptr(peer)) - goto end; - inet_pton(AF_INET, "127.0.0.1", &a4); - BIO_ADDR_rawmake(peer, AF_INET, &a4, sizeof(a4), 443); - ret = BIO_ctrl(b, BIO_C_SET_CONNECT, 2, peer); - BIO_ADDR_free(peer); - if (!TEST_int_eq(ret, 1)) - goto end; -#else - TEST_skip("OSSL_TFO_SENDTO is not defined\n"); - ok = 1; - goto end; -#endif - } - - if (!TEST_int_eq(BIO_set_send_flags(b, MSG_NOSIGNAL), 1)) - goto end; - ret = BIO_write(b, &c, 1); - (void)ret; - - /* PASS only if SIGPIPE wasn't delivered. */ - if (!TEST_int_eq((int)sigpipe_seen, 0)) - goto end; - - ok = 1; - -end: - BIO_free(b); - - if (fds[0] >= 0) { - closesocket(fds[0]); - fds[0] = -1; - } - if (fds[1] >= 0) { - closesocket(fds[1]); - fds[1] = -1; - } - - /* Restore previous handler. */ - (void)sigaction(SIGPIPE, &oldsa, NULL); - - return ok; -#else - /* No MSG_NOSIGNAL on this platform -> skip. */ - TEST_skip("MSG_NOSIGNAL is not defined on this platform"); - return 1; -#endif -} - -int setup_tests(void) -{ - ADD_ALL_TESTS(test_bio_write_triggers_sigpipe, 3); - return 1; -} -#endif diff --git a/test/bio_tfo_test.c b/test/bio_tfo_test.c index 6b7b1414a2..33cf635b67 100644 --- a/test/bio_tfo_test.c +++ b/test/bio_tfo_test.c @@ -81,9 +81,6 @@ static int test_bio_tfo(int idx) /* ACCEPT SOCKET */ if (!TEST_ptr(abio = BIO_new_accept("localhost:0")) -#if !OPENSSL_USE_IPV6 - || !TEST_true(BIO_set_accept_ip_family(abio, BIO_FAMILY_IPV4)) -#endif || !TEST_true(BIO_set_nbio_accept(abio, 1)) || !TEST_true(BIO_set_tfo_accept(abio, server_tfo)) || !TEST_int_gt(BIO_do_accept(abio), 0) @@ -96,9 +93,6 @@ static int test_bio_tfo(int idx) /* CLIENT SOCKET */ if (!TEST_ptr(cbio = BIO_new_connect("localhost")) -#if !OPENSSL_USE_IPV6 - || !TEST_long_gt(BIO_set_conn_ip_family(cbio, BIO_FAMILY_IPV4), 0) -#endif || !TEST_long_gt(BIO_set_conn_port(cbio, port), 0) || !TEST_long_gt(BIO_set_nbio(cbio, 1), 0) || !TEST_long_gt(BIO_set_tfo(cbio, client_tfo), 0)) { @@ -242,11 +236,7 @@ static int test_fd_tfo(int idx) /* ADDRESS SETUP */ memset(&hints, 0, sizeof(hints)); -#if OPENSSL_USE_IPV6 hints.ai_family = AF_UNSPEC; -#else - hints.ai_family = AF_INET; -#endif hints.ai_socktype = SOCK_STREAM; if (!TEST_int_eq(getaddrinfo(NULL, "0", &hints, &ai), 0)) goto err; @@ -258,14 +248,12 @@ static int test_fd_tfo(int idx) addrlen = sizeof(((struct sockaddr_in *)ai->ai_addr)->sin_addr); BIO_printf(bio_err, "Using IPv4\n"); break; -#if OPENSSL_USE_IPV6 case AF_INET6: port = ((struct sockaddr_in6 *)ai->ai_addr)->sin6_port; addr = &((struct sockaddr_in6 *)ai->ai_addr)->sin6_addr; addrlen = sizeof(((struct sockaddr_in6 *)ai->ai_addr)->sin6_addr); BIO_printf(bio_err, "Using IPv6\n"); break; -#endif default: BIO_printf(bio_err, "Unknown address family %d\n", ai->ai_family); goto err; @@ -292,13 +280,11 @@ static int test_fd_tfo(int idx) addr = &((struct sockaddr_in *)&sstorage)->sin_addr; addrlen = sizeof(((struct sockaddr_in *)&sstorage)->sin_addr); break; -#if OPENSSL_USE_IPV6 case AF_INET6: port = ((struct sockaddr_in6 *)&sstorage)->sin6_port; addr = &((struct sockaddr_in6 *)&sstorage)->sin6_addr; addrlen = sizeof(((struct sockaddr_in6 *)&sstorage)->sin6_addr); break; -#endif default: goto err; } diff --git a/test/bioprinttest.c b/test/bioprinttest.c new file mode 100644 index 0000000000..fb7d9d82d6 --- /dev/null +++ b/test/bioprinttest.c @@ -0,0 +1,1021 @@ +/* + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +#define TESTUTIL_NO_size_t_COMPARISON + +#include +#if defined(__TANDEM) && defined(__H_Series_RVU) +/* Restrict this block to NonStop J-series (Itanium) only. */ +#if defined(__LP64) +#define PRIdPTR "lld" +#define PRIiPTR "lli" +#define PRIoPTR "llo" +#define PRIuPTR "llu" +#define PRIxPTR "llx" +#define PRIXPTR "llX" +#else +#define PRIdPTR "d" +#define PRIiPTR "i" +#define PRIoPTR "o" +#define PRIuPTR "u" +#define PRIxPTR "x" +#define PRIXPTR "X" +#endif +#endif +#include +#include +#include +#include +#include "internal/nelem.h" +#include "internal/numbers.h" +#include "internal/bio.h" +#include "testutil.h" +#include "testutil/output.h" + +static int justprint = 0; + +static const char *const fpexpected[][11][5] = { + { + /* 0.00 */ { "0.0000e+00", "0.0000", "0", "0.0000E+00", "0" }, + /* 0.01 */ { "6.7000e-01", "0.6700", "0.67", "6.7000E-01", "0.67" }, + /* 0.02 */ { "6.6667e-01", "0.6667", "0.6667", "6.6667E-01", "0.6667" }, + /* 0.03 */ { "6.6667e-04", "0.0007", "0.0006667", "6.6667E-04", "0.0006667" }, + /* 0.04 */ { "6.6667e-05", "0.0001", "6.667e-05", "6.6667E-05", "6.667E-05" }, + /* 0.05 */ { "6.6667e+00", "6.6667", "6.667", "6.6667E+00", "6.667" }, + /* 0.06 */ { "6.6667e+01", "66.6667", "66.67", "6.6667E+01", "66.67" }, + /* 0.07 */ { "6.6667e+02", "666.6667", "666.7", "6.6667E+02", "666.7" }, + /* 0.08 */ { "6.6667e+03", "6666.6667", "6667", "6.6667E+03", "6667" }, + /* 0.09 */ { "6.6667e+04", "66666.6667", "6.667e+04", "6.6667E+04", "6.667E+04" }, + /* 0.10 */ { "-6.6667e+04", "-66666.6667", "-6.667e+04", "-6.6667E+04", "-6.667E+04" }, + }, + { + /* 1.00 */ { "0.00000e+00", "0.00000", "0", "0.00000E+00", "0" }, + /* 1.01 */ { "6.70000e-01", "0.67000", "0.67", "6.70000E-01", "0.67" }, + /* 1.02 */ { "6.66667e-01", "0.66667", "0.66667", "6.66667E-01", "0.66667" }, + /* 1.03 */ { "6.66667e-04", "0.00067", "0.00066667", "6.66667E-04", "0.00066667" }, + /* 1.04 */ { "6.66667e-05", "0.00007", "6.6667e-05", "6.66667E-05", "6.6667E-05" }, + /* 1.05 */ { "6.66667e+00", "6.66667", "6.6667", "6.66667E+00", "6.6667" }, + /* 1.06 */ { "6.66667e+01", "66.66667", "66.667", "6.66667E+01", "66.667" }, + /* 1.07 */ { "6.66667e+02", "666.66667", "666.67", "6.66667E+02", "666.67" }, + /* 1.08 */ { "6.66667e+03", "6666.66667", "6666.7", "6.66667E+03", "6666.7" }, + /* 1.09 */ { "6.66667e+04", "66666.66667", "66667", "6.66667E+04", "66667" }, + /* 1.10 */ { "-6.66667e+04", "-66666.66667", "-66667", "-6.66667E+04", "-66667" }, + }, + { + /* 2.00 */ { " 0.0000e+00", " 0.0000", " 0", " 0.0000E+00", " 0" }, + /* 2.01 */ { " 6.7000e-01", " 0.6700", " 0.67", " 6.7000E-01", " 0.67" }, + /* 2.02 */ { " 6.6667e-01", " 0.6667", " 0.6667", " 6.6667E-01", " 0.6667" }, + /* 2.03 */ { " 6.6667e-04", " 0.0007", " 0.0006667", " 6.6667E-04", " 0.0006667" }, + /* 2.04 */ { " 6.6667e-05", " 0.0001", " 6.667e-05", " 6.6667E-05", " 6.667E-05" }, + /* 2.05 */ { " 6.6667e+00", " 6.6667", " 6.667", " 6.6667E+00", " 6.667" }, + /* 2.06 */ { " 6.6667e+01", " 66.6667", " 66.67", " 6.6667E+01", " 66.67" }, + /* 2.07 */ { " 6.6667e+02", " 666.6667", " 666.7", " 6.6667E+02", " 666.7" }, + /* 2.08 */ { " 6.6667e+03", " 6666.6667", " 6667", " 6.6667E+03", " 6667" }, + /* 2.09 */ { " 6.6667e+04", " 66666.6667", " 6.667e+04", " 6.6667E+04", " 6.667E+04" }, + /* 2.10 */ { " -6.6667e+04", " -66666.6667", " -6.667e+04", " -6.6667E+04", " -6.667E+04" }, + }, + { + /* 3.00 */ { " 0.00000e+00", " 0.00000", " 0", " 0.00000E+00", " 0" }, + /* 3.01 */ { " 6.70000e-01", " 0.67000", " 0.67", " 6.70000E-01", " 0.67" }, + /* 3.02 */ { " 6.66667e-01", " 0.66667", " 0.66667", " 6.66667E-01", " 0.66667" }, + /* 3.03 */ { " 6.66667e-04", " 0.00067", " 0.00066667", " 6.66667E-04", " 0.00066667" }, + /* 3.04 */ { " 6.66667e-05", " 0.00007", " 6.6667e-05", " 6.66667E-05", " 6.6667E-05" }, + /* 3.05 */ { " 6.66667e+00", " 6.66667", " 6.6667", " 6.66667E+00", " 6.6667" }, + /* 3.06 */ { " 6.66667e+01", " 66.66667", " 66.667", " 6.66667E+01", " 66.667" }, + /* 3.07 */ { " 6.66667e+02", " 666.66667", " 666.67", " 6.66667E+02", " 666.67" }, + /* 3.08 */ { " 6.66667e+03", " 6666.66667", " 6666.7", " 6.66667E+03", " 6666.7" }, + /* 3.09 */ { " 6.66667e+04", " 66666.66667", " 66667", " 6.66667E+04", " 66667" }, + /* 3.10 */ { "-6.66667e+04", "-66666.66667", " -66667", "-6.66667E+04", " -66667" }, + }, + { + /* 4.00 */ { "0e+00", "0", "0", "0E+00", "0" }, + /* 4.01 */ { "7e-01", "1", "0.7", "7E-01", "0.7" }, + /* 4.02 */ { "7e-01", "1", "0.7", "7E-01", "0.7" }, + /* 4.03 */ { "7e-04", "0", "0.0007", "7E-04", "0.0007" }, + /* 4.04 */ { "7e-05", "0", "7e-05", "7E-05", "7E-05" }, + /* 4.05 */ { "7e+00", "7", "7", "7E+00", "7" }, + /* 4.06 */ { "7e+01", "67", "7e+01", "7E+01", "7E+01" }, + /* 4.07 */ { "7e+02", "667", "7e+02", "7E+02", "7E+02" }, + /* 4.08 */ { "7e+03", "6667", "7e+03", "7E+03", "7E+03" }, + /* 4.09 */ { "7e+04", "66667", "7e+04", "7E+04", "7E+04" }, + /* 4.10 */ { "-7e+04", "-66667", "-7e+04", "-7E+04", "-7E+04" }, + }, + { + /* 5.00 */ { "0.000000e+00", "0.000000", "0", "0.000000E+00", "0" }, + /* 5.01 */ { "6.700000e-01", "0.670000", "0.67", "6.700000E-01", "0.67" }, + /* 5.02 */ { "6.666667e-01", "0.666667", "0.666667", "6.666667E-01", "0.666667" }, + /* 5.03 */ { "6.666667e-04", "0.000667", "0.000666667", "6.666667E-04", "0.000666667" }, + /* 5.04 */ { "6.666667e-05", "0.000067", "6.66667e-05", "6.666667E-05", "6.66667E-05" }, + /* 5.05 */ { "6.666667e+00", "6.666667", "6.66667", "6.666667E+00", "6.66667" }, + /* 5.06 */ { "6.666667e+01", "66.666667", "66.6667", "6.666667E+01", "66.6667" }, + /* 5.07 */ { "6.666667e+02", "666.666667", "666.667", "6.666667E+02", "666.667" }, + /* 5.08 */ { "6.666667e+03", "6666.666667", "6666.67", "6.666667E+03", "6666.67" }, + /* 5.09 */ { "6.666667e+04", "66666.666667", "66666.7", "6.666667E+04", "66666.7" }, + /* 5.10 */ { "-6.666667e+04", "-66666.666667", "-66666.7", "-6.666667E+04", "-66666.7" }, + }, + { + /* 6.00 */ { "0.0000e+00", "000.0000", "00000000", "0.0000E+00", "00000000" }, + /* 6.01 */ { "6.7000e-01", "000.6700", "00000.67", "6.7000E-01", "00000.67" }, + /* 6.02 */ { "6.6667e-01", "000.6667", "000.6667", "6.6667E-01", "000.6667" }, + /* 6.03 */ { "6.6667e-04", "000.0007", "0.0006667", "6.6667E-04", "0.0006667" }, + /* 6.04 */ { "6.6667e-05", "000.0001", "6.667e-05", "6.6667E-05", "6.667E-05" }, + /* 6.05 */ { "6.6667e+00", "006.6667", "0006.667", "6.6667E+00", "0006.667" }, + /* 6.06 */ { "6.6667e+01", "066.6667", "00066.67", "6.6667E+01", "00066.67" }, + /* 6.07 */ { "6.6667e+02", "666.6667", "000666.7", "6.6667E+02", "000666.7" }, + /* 6.08 */ { "6.6667e+03", "6666.6667", "00006667", "6.6667E+03", "00006667" }, + /* 6.09 */ { "6.6667e+04", "66666.6667", "6.667e+04", "6.6667E+04", "6.667E+04" }, + /* 6.10 */ { "-6.6667e+04", "-66666.6667", "-6.667e+04", "-6.6667E+04", "-6.667E+04" }, + }, +}; + +static int (*test_BIO_snprintf)(char *, size_t, const char *, ...) = BIO_snprintf; + +enum arg_type { + AT_NONE = 0, + AT_CHAR, + AT_SHORT, + AT_INT, + AT_LONG, + AT_LLONG, + /* The ones below are used in n_data only so far */ + AT_SIZE, + AT_PTRDIFF, + AT_STR, +}; + +static const struct int_data { + union { + unsigned char hh; + unsigned short h; + unsigned int i; + unsigned long l; + unsigned long long ll; + } value; + enum arg_type type; + const char *format; + const char *expected; + bool skip_libc_check; + /* Since OpenSSL's snprintf is non-standard on buffer overflow */ + bool skip_libc_ret_check; + int exp_ret; +} int_data[] = { + { { .hh = 0x42 }, AT_CHAR, "%+hhu", "66" }, + { { .hh = 0x88 }, AT_CHAR, "%hhd", "-120" }, + { { .hh = 0x0 }, AT_CHAR, "%hho", "0" }, +#if !defined(__TANDEM) + { { .hh = 0x0 }, AT_CHAR, "%#hho", "0" }, +#endif + { { .hh = 0x1 }, AT_CHAR, "%hho", "1" }, + { { .hh = 0x1 }, AT_CHAR, "%#hho", "01" }, + { { .hh = 0x0 }, AT_CHAR, "%+hhx", "0" }, + { { .hh = 0x0 }, AT_CHAR, "%#hhx", "0" }, + { { .hh = 0xf }, AT_CHAR, "%hhx", "f" }, + { { .hh = 0xe }, AT_CHAR, "%hhX", "E" }, + { { .hh = 0xd }, AT_CHAR, "%#hhx", "0xd" }, + { { .hh = 0xc }, AT_CHAR, "%#hhX", "0XC" }, + { { .hh = 0xb }, AT_CHAR, "%#04hhX", "0X0B" }, + { { .hh = 0xa }, AT_CHAR, "%#-015hhx", "0xa " }, + { { .hh = 0x9 }, AT_CHAR, "%#+01hho", "011" }, + { { .hh = 0x8 }, AT_CHAR, "%#09hho", "000000010" }, + { { .hh = 0x7 }, AT_CHAR, "%#+ 9hhi", " +7" }, + { { .hh = 0x6 }, AT_CHAR, "%# 9hhd", " 6" }, + { { .hh = 0x95 }, AT_CHAR, "%#06hhi", "-00107" }, + { { .hh = 0x4 }, AT_CHAR, "%# hhd", " 4" }, + { { .hh = 0x3 }, AT_CHAR, "%# hhu", "3" }, + { { .hh = 0x0 }, AT_CHAR, "%02hhx", "00" }, + { { .h = 0 }, AT_SHORT, "|%.0hd|", "||" }, + { { .h = 0 }, AT_SHORT, "|%.hu|", "||" }, +#if !defined(__OpenBSD__) + { { .h = 0 }, AT_SHORT, "|%#.ho|", "|0|" }, +#endif + { { .h = 1 }, AT_SHORT, "%4.2hi", " 01" }, + { { .h = 2 }, AT_SHORT, "%-4.3hu", "002 " }, + { { .h = 3 }, AT_SHORT, "%+.3hu", "003" }, + { { .h = 9 }, AT_SHORT, "%#5.2ho", " 011" }, + { { .h = 0xf }, AT_SHORT, "%#-6.2hx", "0x0f " }, + { { .h = 0xaa }, AT_SHORT, "%#8.0hX", " 0XAA" }, + { { .h = 0xdead }, AT_SHORT, "%#hi", "-8531" }, + { { .h = 0xcafe }, AT_SHORT, "%#0.1hX", "0XCAFE" }, + { { .h = 0xbeef }, AT_SHORT, "%#012.8ho", " 00137357" }, + { { .h = 0xbeef }, AT_SHORT, "%#000000000000000000012.ho", " 0137357" }, + { { .h = 0xbeef }, AT_SHORT, "%012.ho", " 137357" }, + { { .h = 0xfade }, AT_SHORT, "%#012ho", "000000175336" }, + { { .h = 0xfaff }, AT_SHORT, "%#-012ho", "0175377 " }, + { { .h = 0xbea7 }, AT_SHORT, "%#-012.8ho", "00137247 " }, + { { .i = 0 }, AT_INT, "-%#+.0u-", "--" }, + { { .i = 0 }, AT_INT, "-%-8.u-", "- -" }, + { { .i = 0xdeadc0de }, AT_INT, "%#+67.65i", + " -0000000000000000000000000000000000000000000000000000000055903", + .skip_libc_ret_check = true, .exp_ret = -1 }, + { { .i = 0xfeedface }, AT_INT, "%#+70.10X", + " 0X00F", + .skip_libc_ret_check = true, .exp_ret = -1 }, + { { .i = 0xdecaffee }, AT_INT, "%76.15o", + " 00", + .skip_libc_ret_check = true, .exp_ret = -1 }, + { { .i = 0x5ad }, AT_INT, "%#67.x", + " 0", + .skip_libc_ret_check = true, .exp_ret = -1 }, + { { .i = 0x1337 }, AT_INT, "|%2147483639.x|", + "| ", + .skip_libc_check = true, .exp_ret = -1 }, +#if !defined(OPENSSL_SYS_WINDOWS) + /* + * those test crash on x86 windows built by VS-2019 + */ + { { .i = 0x1337 }, AT_INT, "|%.2147483639x|", + "|00000000000000000000000000000000000000000000000000000000000000", + .skip_libc_check = true, .exp_ret = -1 }, + /* + * We treat the following three format strings as errneous and bail out + * mid-string. + */ + { { .i = 0x1337 }, AT_INT, "|%2147483647.x|", "|", + .skip_libc_check = true, .exp_ret = -1 }, +#endif + { { .i = 0x1337 }, AT_INT, + "abcdefghijklmnopqrstuvwxyz0123456789ZYXWVUTSRQPONMLKJIHGFEDCBA" + "|%4294967295.x|", + "abcdefghijklmnopqrstuvwxyz0123456789ZYXWVUTSRQPONMLKJIHGFEDCBA|", + .skip_libc_check = true, .exp_ret = -1 }, + { { .i = 0x1337 }, AT_INT, "%4294967302.x", "", + .skip_libc_check = true, .exp_ret = -1 }, + { { .i = 0xbeeface }, AT_INT, "%#+-12.1d", "+200211150 " }, +#if !defined(__OpenBSD__) + { { .l = 0 }, AT_LONG, "%%%#.0lo%%", "%0%" }, +#endif + { { .l = 0 }, AT_LONG, "%%%.0lo%%", "%%" }, + { { .l = 0 }, AT_LONG, "%%%-.0lo%%", "%%" }, + { { .l = 0xfacefed }, AT_LONG, "%#-1.14ld", "00000262991853" }, + { { .l = 0xdefaced }, AT_LONG, "%#+-014.11li", "+00233811181 " }, + { { .l = 0xfacade }, AT_LONG, "%#0.14lo", "00000076545336" }, + { { .l = 0 }, AT_LONG, "%#0.14lo", "00000000000000" }, + { { .l = 0xfacade }, AT_LONG, "%#0.14lx", "0x00000000facade" }, + { { .ll = 0 }, AT_LLONG, "#%#.0llx#", "##" }, + { { .ll = 0 }, AT_LLONG, "#%.0llx#", "##" }, + { { .ll = 0xffffFFFFffffFFFFULL }, AT_LLONG, "%#-032llo", + "01777777777777777777777 " }, + { { .ll = 0xbadc0deddeadfaceULL }, AT_LLONG, "%022lld", + "-004982091772484257074" }, +}; + +static int test_int(int i) +{ + char bio_buf[64]; + int bio_ret; + const struct int_data *data = int_data + i; + const int exp_ret = data->exp_ret ? data->exp_ret + : (int)strlen(data->expected); + + memset(bio_buf, '@', sizeof(bio_buf)); + + switch (data->type) { +#define DO_PRINT(field_) \ + do { \ + bio_ret = test_BIO_snprintf(bio_buf, sizeof(bio_buf), data->format, \ + data->value.field_); \ + } while (0) + case AT_CHAR: + DO_PRINT(hh); + break; + case AT_SHORT: + DO_PRINT(h); + break; + case AT_INT: + DO_PRINT(i); + break; + case AT_LONG: + DO_PRINT(l); + break; + case AT_LLONG: + DO_PRINT(ll); + break; + default: + TEST_error("Unexpected arg type: %d", data->type); + return 0; +#undef DO_PRINT + } + + if (data->skip_libc_check) { + if (strcmp(bio_buf, data->expected) != 0) + TEST_note("%s Result (%s) does not match (%s)", __func__, + bio_buf, data->expected); + } else if (!TEST_str_eq(bio_buf, data->expected) + + !TEST_int_eq(bio_ret, exp_ret)) { + TEST_note("Format: \"%s\"", data->format); + return 0; + } + + return 1; +} + +#ifdef _WIN32 +static int test_int_win32(int i) +{ + int ret; + + test_BIO_snprintf = ossl_BIO_snprintf_msvc; + ret = test_int(i); + test_BIO_snprintf = BIO_snprintf; + + return ret; +} +#endif + +union ptrint { + uintptr_t i; + const char *s; +}; + +static const struct wp_data { + union ptrint value; + const char *format; + const char *expected; + int num_args; + int arg1; + int arg2; + bool skip_libc_check; + /* Since OpenSSL's snprintf is non-standard on buffer overflow */ + bool skip_libc_ret_check; + int exp_ret; +} wp_data[] = { + /* Integer checks with width/precision provided via arguments */ + { { .i = 01234 }, "%#*" PRIoPTR, " 01234", 1, 12 }, + { { .i = 01234 }, "%#.*" PRIxPTR, "0x00000000029c", 1, 12 }, + +#if !defined(__TANDEM) + { { .i = 0 }, "|%#*" PRIoPTR "|", "| 0|", 1, 2 }, +#endif + { { .i = 0 }, "|%#.*" PRIoPTR "|", "|00|", 1, 2 }, +#if !defined(__TANDEM) + { { .i = 0 }, "|%#.*" PRIoPTR "|", "|0|", 1, 1 }, +#endif +#if !defined(__OpenBSD__) + { { .i = 0 }, "|%#.*" PRIoPTR "|", "|0|", 1, 0 }, +#endif + { { .i = 0 }, "|%.*" PRIoPTR "|", "||", 1, 0 }, +#if !defined(__TANDEM) + { { .i = 0 }, "|%#.*" PRIoPTR "|", "|0|", 1, -12 }, +#endif + + { { .i = 0 }, "|%#.*" PRIxPTR "|", "||", 1, 0 }, + { { .i = 0 }, "|%#.*" PRIxPTR "|", "|0|", 1, -12 }, + { { .i = 1 }, "|%#.*" PRIxPTR "|", "|0x1|", 1, -12 }, + + { { .i = 0 }, "|%#*.*" PRIxPTR "|", "| |", 2, 12, 0 }, + { { .i = 1234 }, "|%*.*" PRIuPTR "|", "| 001234|", 2, 12, 6 }, + + /* FreeBSD's libc bails out on the following three */ + { { .i = 1337 }, "|%*" PRIuPTR "|", + "| ", + 1, 2147483647, .skip_libc_check = true, .exp_ret = -1 }, +#if !defined(OPENSSL_SYS_WINDOWS) + { { .i = 1337 }, "|%.*" PRIuPTR "|", + "|00000000000000000000000000000000000000000000000000000000000000", + 1, 2147483647, .skip_libc_check = true, .exp_ret = -1 }, + { { .i = 1337 }, "|%#*.*" PRIoPTR "|", + "| 0", + 2, 2147483647, 2147483586, .skip_libc_check = true, .exp_ret = -1 }, +#endif + + /* String width/precision checks */ + { { .s = "01234" }, "%12s", " 01234" }, + { { .s = "01234" }, "%-12s", "01234 " }, + { { .s = "01234" }, "%.12s", "01234" }, + { { .s = "01234" }, "%.2s", "01" }, + + { { .s = "abc" }, "%*s", " abc", 1, 12 }, + { { .s = "abc" }, "%*s", "abc ", 1, -12 }, + { { .s = "abc" }, "%-*s", "abc ", 1, 12 }, + { { .s = "abc" }, "%-*s", "abc ", 1, -12 }, + + { { .s = "ABC" }, "%*.*s", " ABC", 2, 12, 5 }, + { { .s = "ABC" }, "%*.*s", "AB ", 2, -12, 2 }, + { { .s = "ABC" }, "%-*.*s", "ABC ", 2, 12, -5 }, + { { .s = "ABC" }, "%-*.*s", "ABC ", 2, -12, -2 }, + + { { .s = "def" }, "%.*s", "def", 1, 12 }, + { { .s = "%%s0123456789" }, "%.*s", "%%s01", 1, 5 }, + { { .s = "9876543210" }, "|%-61s|", + "|9876543210 |" }, + { { .s = "0123456789" }, "|%62s|", + "| 0123456789", + .skip_libc_ret_check = true, .exp_ret = -1 }, + + { { .s = "DEF" }, "%-2147483639s", + "DEF ", + .skip_libc_check = true, .exp_ret = -1 }, + { { .s = "DEF" }, "%-2147483640s", "", + .skip_libc_check = true, .exp_ret = -1 }, + { { .s = "DEF" }, "%*s", + " ", + 1, 2147483647, .skip_libc_check = true, .exp_ret = -1 }, +}; + +static int test_width_precision(int i) +{ + char bio_buf[64]; + char std_buf[64]; + int bio_ret; + const struct wp_data *data = wp_data + i; + const int exp_ret = data->exp_ret ? data->exp_ret + : (int)strlen(data->expected); + + memset(bio_buf, '@', sizeof(bio_buf)); + memset(std_buf, '#', sizeof(std_buf)); + + switch (data->num_args) { + case 2: + bio_ret = test_BIO_snprintf(bio_buf, sizeof(bio_buf), data->format, + data->arg1, data->arg2, data->value.i); + break; + + case 1: + bio_ret = test_BIO_snprintf(bio_buf, sizeof(bio_buf), data->format, + data->arg1, data->value.i); + break; + + case 0: + default: + bio_ret = test_BIO_snprintf(bio_buf, sizeof(bio_buf), data->format, + data->value.i); + } + + if (data->skip_libc_check) { + if (strcmp(bio_buf, data->expected) != 0) + TEST_note("%s Result (%s) does not match (%s)", __func__, + bio_buf, data->expected); + } else if (!TEST_str_eq(bio_buf, data->expected) + + !TEST_int_eq(bio_ret, exp_ret)) { + TEST_note("Format: \"%s\"", data->format); + return 0; + } + + return 1; +} + +#ifdef _WIN32 +static int test_width_precision_win32(int i) +{ + int ret; + + test_BIO_snprintf = ossl_BIO_snprintf_msvc; + ret = test_width_precision(i); + test_BIO_snprintf = BIO_snprintf; + + return ret; +} +#endif + +static const struct n_data { + const char *format; + const char *expected; + enum arg_type n_type; + const uint64_t exp_n; + enum arg_type arg1_type; + union ptrint arg1; + enum arg_type arg2_type; + union ptrint arg2; + bool skip_libc_check; + /* Since OpenSSL's snprintf is non-standard on buffer overflow */ + bool skip_libc_ret_check; + int exp_ret; +} n_data[] = { + { "%n", "", AT_INT, 0, AT_NONE }, + { "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz%n", + "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz", + AT_INT, 62, AT_NONE }, + { "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz+=%n", + "0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz+", + AT_INT, 64, AT_NONE, .skip_libc_ret_check = true, .exp_ret = -1 }, + { "%" PRIdPTR "%hhn", "1234567890", + AT_CHAR, 10, AT_INT, { .i = 1234567890 } }, + { "%#.200" PRIXPTR "%hhn", + "0X0000000000000000000000000000000000000000000000000000000000000", + AT_CHAR, -54, AT_INT, { .i = 1234567890 }, + .skip_libc_ret_check = true, .exp_ret = -1 }, + { "%#10000" PRIoPTR "%hhn1234567890", + " ", + /* XXX Should we overflow or saturate? glibc does the former. */ + AT_CHAR, 16, AT_INT, { .i = 1234567890 }, + .skip_libc_ret_check = true, .exp_ret = -1 }, + { "%.0s%hn0987654321", "0987654321", + AT_SHORT, 0, AT_INT, { .s = "1234567890" } }, + { "%-123456s%hn0987654321", + "1234567890 ", + AT_SHORT, -7616, AT_INT, { .s = "1234567890" }, + .skip_libc_ret_check = true, .exp_ret = -1 }, +#if !defined(OPENSSL_SYS_WINDOWS) + { "%1234567898.1234567890" PRIxPTR "%n", + " 0000000000000000000000000000000000000000000000000000000", + AT_INT, 1234567898, AT_INT, { .i = 0xbadc0ded }, + /* MS CRT can't handle this one, snprintf() causes access violation. */ + .skip_libc_ret_check = true, .exp_ret = -1 }, +#endif + { "%s|%n", + "0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ|", + AT_INT, 63, AT_STR, { .s = "0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ" } }, + { "|%#2147483639x|%2147483639s|0123456789abcdef|%ln", + "| ", + AT_LONG, sizeof(long) == 8 ? 4294967298ULL : 2, + AT_INT, { .i = 0x1337 }, AT_STR, { .s = "1EE7" }, + /* glibc caps %n value (1 << 32) - 1 */ + .skip_libc_check = true, .exp_ret = -1 }, + { "|%-2147483638s|0123456789abcdef|%02147483637o|0123456789ABCDEF|%lln", + "|echo test test test ", + AT_LLONG, 4294967312ULL, + AT_STR, { .s = "echo test test test" }, AT_INT, { .i = 0xbad }, + /* glibc caps %n value (1 << 32) - 1 */ + .skip_libc_check = true, .exp_ret = -1 }, + { "|%+2147483639s|2147483639|%.2147483639u|2147483639|%zn", + "| ", + AT_SIZE, sizeof(size_t) == 8 ? 4294967303ULL : 7, + AT_STR, { .s = "according to all known laws of aviation" }, + AT_INT, { .i = 0xbee }, + /* glibc caps %n value (1 << 32) - 1 */ + .skip_libc_check = true, .exp_ret = -1 }, + { "==%2147483639.2147483639s==2147483639.2147483639==%+2147483639d==%tn==", + "== ", + AT_PTRDIFF, sizeof(ptrdiff_t) == 8 ? 4294967307ULL : 11, + AT_STR, { .s = "oh hi there hello" }, AT_INT, { .i = 0x1234 }, + /* glibc caps %n value (1 << 32) - 1 */ + .skip_libc_check = true, .exp_ret = -1 }, + { "=%2147483639s=%888888888X=%tn=", + "= ", + AT_PTRDIFF, sizeof(ptrdiff_t) == 8 ? 3036372530LL : -1258594766LL, + AT_STR, { .s = NULL }, AT_INT, { .i = 0xdead }, + .skip_libc_check = true, .exp_ret = -1 }, +}; + +static int test_n(int i) +{ + const struct n_data *data = n_data + i; + const int exp_ret = data->exp_ret ? data->exp_ret + : (int)strlen(data->expected); + char bio_buf[64]; + char std_buf[64]; + int bio_ret; + union { + uint64_t val; + signed char hh; + short h; + int i; + long int l; + long long int ll; + ossl_ssize_t z; + ptrdiff_t t; + } n = { 0 }; + +#if defined(OPENSSL_SYS_WINDOWS) && !defined(__MINGW32__) + /* + * MS CRT is special and throws an exception when %n is used even + * in non-*_s versions of printf routines, and there is a special function + * to enable %n handling. + */ + _set_printf_count_output(1); + if (_get_printf_count_output() == 0) { + TEST_note("Can't enable %%n handling for snprintf" + ", skipping the checks against libc"); + return 1; + } +#elif defined(__OpenBSD__) + { + static bool note_printed; + + if (!note_printed) { + TEST_note("OpenBSD libc unconditionally aborts a program " + "if %%n is used in a *printf routine" + ", skipping the checks against libc"); + note_printed = true; + } + return 1; + } +#endif /* defined(OPENSSL_SYS_WINDOWS) || defined(__OpenBSD__) */ + + memset(bio_buf, '@', sizeof(bio_buf)); + memset(std_buf, '#', sizeof(std_buf)); + + switch (data->n_type) { +#define DO_PRINT(field_) \ + do { \ + if (data->arg1_type == AT_NONE) { \ + bio_ret = test_BIO_snprintf(bio_buf, sizeof(bio_buf), data->format, \ + &n.field_); \ + } else if (data->arg2_type == AT_NONE) { \ + bio_ret = test_BIO_snprintf(bio_buf, sizeof(bio_buf), data->format, \ + data->arg1.i, &n.field_); \ + } else { \ + bio_ret = test_BIO_snprintf(bio_buf, sizeof(bio_buf), data->format, \ + data->arg1.i, data->arg2.i, &n.field_); \ + } \ + } while (0) + case AT_CHAR: + DO_PRINT(hh); + break; + case AT_SHORT: + DO_PRINT(h); + break; + case AT_INT: + DO_PRINT(i); + break; + case AT_LONG: + DO_PRINT(l); + break; + case AT_LLONG: + DO_PRINT(ll); + break; + case AT_SIZE: + DO_PRINT(z); + break; + case AT_PTRDIFF: + DO_PRINT(t); + break; + default: + TEST_error("Unexpected arg type: %d", data->n_type); + return 0; +#undef DO_PRINT + } + + if (data->skip_libc_check) { + if (strcmp(bio_buf, data->expected) != 0) + TEST_note("%s Result (%s) does not match (%s)", __func__, + bio_buf, data->expected); + } else if (!TEST_str_eq(bio_buf, data->expected) + + !TEST_int_eq(bio_ret, exp_ret)) { + TEST_note("Format: \"%s\"", data->format); + return 0; + } + + return 1; +} + +typedef struct z_data_st { + size_t value; + const char *format; + const char *expected; +} z_data; + +static const z_data zu_data[] = { + { SIZE_MAX, "%zu", (sizeof(size_t) == 4 ? "4294967295" : sizeof(size_t) == 8 ? "18446744073709551615" + : "") }, + /* + * in 2-complement, the unsigned number divided by two plus one becomes the + * smallest possible negative signed number of the corresponding type + */ + { SIZE_MAX / 2 + 1, "%zi", (sizeof(size_t) == 4 ? "-2147483648" : sizeof(size_t) == 8 ? "-9223372036854775808" + : "") }, + { 0, "%zu", "0" }, + { 0, "%zi", "0" }, +}; + +static int test_zu(int i) +{ + char bio_buf[80]; + const z_data *data = &zu_data[i]; + const int exp_ret = (int)strlen(data->expected); + int bio_ret; + + memset(bio_buf, '@', sizeof(bio_buf)); + + bio_ret = test_BIO_snprintf(bio_buf, sizeof(bio_buf), data->format, data->value); + if (!TEST_str_eq(bio_buf, data->expected) + + !TEST_int_eq(bio_ret, exp_ret)) + return 0; + + return 1; +} + +#ifdef _WIN32 +static int test_zu_win32(int i) +{ + int ret; + + test_BIO_snprintf = ossl_BIO_snprintf_msvc; + ret = test_zu(i); + test_BIO_snprintf = BIO_snprintf; + + return ret; +} +#endif + +static const struct t_data { + size_t value; + const char *format; + const char *expected; +} t_data[] = { + { PTRDIFF_MAX, "%+td", + sizeof(ptrdiff_t) == 4 ? "+2147483647" : "+9223372036854775807" }, + { PTRDIFF_MIN, "%+ti", + sizeof(ptrdiff_t) == 4 ? "-2147483648" : "-9223372036854775808" }, + { 0, "%tu", "0" }, + { 0, "%+09ti", "+00000000" }, +}; + +static int test_t(int i) +{ + char bio_buf[64]; + const struct t_data *data = &t_data[i]; + const int exp_ret = (int)strlen(data->expected); + int bio_ret; + + memset(bio_buf, '@', sizeof(bio_buf)); + + bio_ret = test_BIO_snprintf(bio_buf, sizeof(bio_buf), data->format, data->value); + if (!TEST_str_eq(bio_buf, data->expected) + + !TEST_int_eq(bio_ret, exp_ret)) + return 0; + + return 1; +} + +#ifdef _WIN32 +static int test_t_win32(int i) +{ + int ret; + + test_BIO_snprintf = ossl_BIO_snprintf_msvc; + ret = test_t(i); + test_BIO_snprintf = BIO_snprintf; + + return ret; +} +#endif + +typedef struct j_data_st { + uint64_t value; + const char *format; + const char *expected; +} j_data; + +static const j_data jf_data[] = { + { 0xffffffffffffffffULL, "%ju", "18446744073709551615" }, + { 0xffffffffffffffffULL, "%jx", "ffffffffffffffff" }, + { 0x8000000000000000ULL, "%ju", "9223372036854775808" }, + /* + * These tests imply two's complement, but it's the only binary + * representation we support, see test/sanitytest.c... + */ + { 0x8000000000000000ULL, "%ji", "-9223372036854775808" }, +}; + +static int test_j(int i) +{ + const j_data *data = &jf_data[i]; + char bio_buf[80]; + const int exp_ret = (int)strlen(data->expected); + int bio_ret; + + memset(bio_buf, '@', sizeof(bio_buf)); + + bio_ret = test_BIO_snprintf(bio_buf, sizeof(bio_buf), data->format, data->value); + if (!TEST_str_eq(bio_buf, data->expected) + + !TEST_int_eq(bio_ret, exp_ret)) + return 0; + + return 1; +} + +#ifdef _WIN32 +static int test_j_win32(int i) +{ + int ret; + + test_BIO_snprintf = ossl_BIO_snprintf_msvc; + ret = test_j(i); + test_BIO_snprintf = BIO_snprintf; + + return ret; +} +#endif + +/* Precision and width. */ +typedef struct pw_st { + int p; + const char *w; +} pw; + +static const pw pw_params[] = { + { 4, "" }, + { 5, "" }, + { 4, "12" }, + { 5, "12" }, + { 0, "" }, + { -1, "" }, + { 4, "08" } +}; + +static int dofptest(int test, int sub, double val, const char *width, int prec) +{ + static const char *fspecs[] = { + "e", "f", "g", "E", "G" + }; + char format[80], result[80]; + int ret = 1, i; + int exp_ret; + int bio_ret; + + for (i = 0; i < (int)OSSL_NELEM(fspecs); i++) { + const char *fspec = fspecs[i]; + + memset(result, '@', sizeof(result)); + + if (prec >= 0) + test_BIO_snprintf(format, sizeof(format), "%%%s.%d%s", width, prec, + fspec); + else + test_BIO_snprintf(format, sizeof(format), "%%%s%s", width, fspec); + + exp_ret = (int)strlen(fpexpected[test][sub][i]); + bio_ret = test_BIO_snprintf(result, sizeof(result), format, val); + + if (justprint) { + if (i == 0) + printf(" /* %d.%02d */ { \"%s\"", test, sub, result); + else + printf(", \"%s\"", result); + } else { + if (!TEST_str_eq(fpexpected[test][sub][i], result) + + !TEST_int_eq(bio_ret, exp_ret)) { + TEST_info("test %d format=|%s| exp=|%s|, ret=|%s|", + test, format, fpexpected[test][sub][i], result); + ret = 0; + } + } + } + if (justprint) + printf(" },\n"); + return ret; +} + +static int test_fp(int i) +{ + int t = 0, r; + const double frac = 2.0 / 3.0; + const pw *pwp = &pw_params[i]; + + if (justprint) + printf(" {\n"); + r = TEST_true(dofptest(i, t++, 0.0, pwp->w, pwp->p)) + && TEST_true(dofptest(i, t++, 0.67, pwp->w, pwp->p)) + && TEST_true(dofptest(i, t++, frac, pwp->w, pwp->p)) + && TEST_true(dofptest(i, t++, frac / 1000, pwp->w, pwp->p)) + && TEST_true(dofptest(i, t++, frac / 10000, pwp->w, pwp->p)) + && TEST_true(dofptest(i, t++, 6.0 + frac, pwp->w, pwp->p)) + && TEST_true(dofptest(i, t++, 66.0 + frac, pwp->w, pwp->p)) + && TEST_true(dofptest(i, t++, 666.0 + frac, pwp->w, pwp->p)) + && TEST_true(dofptest(i, t++, 6666.0 + frac, pwp->w, pwp->p)) + && TEST_true(dofptest(i, t++, 66666.0 + frac, pwp->w, pwp->p)) + && TEST_true(dofptest(i, t++, -66666.0 - frac, pwp->w, pwp->p)); + if (justprint) + printf(" },\n"); + return r; +} + +#ifdef _WIN32 +static int test_fp_win32(int i) +{ + int ret; + + test_BIO_snprintf = ossl_BIO_snprintf_msvc; + ret = test_fp(i); + test_BIO_snprintf = BIO_snprintf; + + return ret; +} +#endif + +typedef enum OPTION_choice { + OPT_ERR = -1, + OPT_EOF = 0, + OPT_PRINT, + OPT_TEST_ENUM +} OPTION_CHOICE; + +const OPTIONS *test_get_options(void) +{ + static const OPTIONS options[] = { + OPT_TEST_OPTIONS_DEFAULT_USAGE, + { "expected", OPT_PRINT, '-', "Output values" }, + { NULL } + }; + return options; +} + +int setup_tests(void) +{ + OPTION_CHOICE o; + + while ((o = opt_next()) != OPT_EOF) { + switch (o) { + case OPT_PRINT: + justprint = 1; + break; + case OPT_TEST_CASES: + break; + default: + return 0; + } + } + + ADD_ALL_TESTS(test_fp, OSSL_NELEM(pw_params)); + ADD_ALL_TESTS(test_int, OSSL_NELEM(int_data)); + ADD_ALL_TESTS(test_width_precision, OSSL_NELEM(wp_data)); + ADD_ALL_TESTS(test_n, OSSL_NELEM(n_data)); + ADD_ALL_TESTS(test_zu, OSSL_NELEM(zu_data)); + ADD_ALL_TESTS(test_t, OSSL_NELEM(t_data)); + ADD_ALL_TESTS(test_j, OSSL_NELEM(jf_data)); + +#ifdef _WIN32 + /* + * those tests are using _vsnprintf_s() + */ + ADD_ALL_TESTS(test_fp_win32, OSSL_NELEM(pw_params)); + ADD_ALL_TESTS(test_int_win32, OSSL_NELEM(int_data)); + ADD_ALL_TESTS(test_width_precision_win32, OSSL_NELEM(wp_data)); + /* + * test_n() which uses "%n" format string triggers + * an assert 'Incorrect format specifier' found in + * minkernel\crts\ucrt\correct_internal_stdio_output.h + * (line 1690). + * Therefore we don't add test_n() here. + */ + ADD_ALL_TESTS(test_zu_win32, OSSL_NELEM(zu_data)); + ADD_ALL_TESTS(test_t_win32, OSSL_NELEM(t_data)); + ADD_ALL_TESTS(test_j_win32, OSSL_NELEM(jf_data)); +#endif + + return 1; +} + +/* + * Replace testutil output routines. We do this to eliminate possible sources + * of BIO error + */ +BIO *bio_out = NULL; +BIO *bio_err = NULL; + +static int tap_level = 0; + +void test_open_streams(void) +{ +} + +void test_adjust_streams_tap_level(int level) +{ + tap_level = level; +} + +void test_close_streams(void) +{ +} + +/* + * This works out as long as caller doesn't use any "fancy" formats. + * But we are caller's caller, and test_str_eq is the only one called, + * and it uses only "%s", which is not "fancy"... + */ +int test_vprintf_stdout(const char *fmt, va_list ap) +{ + return fprintf(stdout, "%*s# ", tap_level, "") + vfprintf(stdout, fmt, ap); +} + +int test_vprintf_stderr(const char *fmt, va_list ap) +{ + return fprintf(stderr, "%*s# ", tap_level, "") + vfprintf(stderr, fmt, ap); +} + +int test_flush_stdout(void) +{ + return fflush(stdout); +} + +int test_flush_stderr(void) +{ + return fflush(stderr); +} + +int test_vprintf_tapout(const char *fmt, va_list ap) +{ + return fprintf(stdout, "%*s", tap_level, "") + vfprintf(stdout, fmt, ap); +} + +int test_vprintf_taperr(const char *fmt, va_list ap) +{ + return fprintf(stderr, "%*s", tap_level, "") + vfprintf(stderr, fmt, ap); +} + +int test_flush_tapout(void) +{ + return fflush(stdout); +} + +int test_flush_taperr(void) +{ + return fflush(stderr); +} diff --git a/test/bntest.c b/test/bntest.c index d15af9dbe5..aeba02dc0c 100644 --- a/test/bntest.c +++ b/test/bntest.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -1215,71 +1215,6 @@ err: return st; } -typedef struct sum_all_alias_st { - const char *hex; - int negative; -} SUM_ALL_ALIAS; - -static int test_sum_all_alias_helper(const SUM_ALL_ALIAS *test) -{ - BIGNUM *alias = NULL, *orig = NULL, *expected = NULL; - int st = 0; - - if (!TEST_true(BN_hex2bn(&alias, test->hex))) - goto err; - if (test->negative && !BN_is_zero(alias)) - BN_set_negative(alias, 1); - if (!TEST_ptr(orig = BN_dup(alias)) - || !TEST_ptr(expected = BN_new())) - goto err; - - /* BN_add */ - if (!TEST_true(BN_add(expected, orig, orig)) - || !TEST_true(BN_add(alias, alias, alias)) - || !TEST_BN_eq(expected, alias) - || !TEST_ptr(BN_copy(alias, orig)) - /* BN_sub */ - || !TEST_true(BN_sub(expected, orig, orig)) - || !TEST_true(BN_sub(alias, alias, alias)) - || !TEST_BN_eq(expected, alias) - || !TEST_ptr(BN_copy(alias, orig)) - /* BN_uadd */ - || !TEST_true(BN_uadd(expected, orig, orig)) - || !TEST_true(BN_uadd(alias, alias, alias)) - || !TEST_BN_eq(expected, alias) - || !TEST_ptr(BN_copy(alias, orig)) - /* BN_usub */ - || !TEST_true(BN_usub(expected, orig, orig)) - || !TEST_true(BN_usub(alias, alias, alias)) - || !TEST_BN_eq(expected, alias)) - goto err; - - st = 1; -err: - BN_free(alias); - BN_free(orig); - BN_free(expected); - return st; -} - -static int test_sum_all_alias(void) -{ - static const SUM_ALL_ALIAS tests[] = { - { "2A", 0 }, - { "2A", 1 }, - { "0", 0 }, - { "FEDCBA98765432100123456789ABCDEFFEDCBA98765432100123456789ABCDEF", 0 }, - { "FEDCBA98765432100123456789ABCDEFFEDCBA98765432100123456789ABCDEF", 1 } - }; - size_t i; - - for (i = 0; i < OSSL_NELEM(tests); i++) { - if (!test_sum_all_alias_helper(&tests[i])) - return 0; - } - return 1; -} - static int file_sum(STANZA *s) { BIGNUM *a = NULL, *b = NULL, *sum = NULL, *ret = NULL; @@ -1303,6 +1238,7 @@ static int file_sum(STANZA *s) /* * Test that the functions work when |r| and |a| point to the same BIGNUM, * or when |r| and |b| point to the same BIGNUM. + * There is no test for all of |r|, |a|, and |b| pointint to the same BIGNUM. */ if (!TEST_true(BN_copy(ret, a)) || !TEST_true(BN_add(ret, ret, b)) @@ -1341,6 +1277,8 @@ static int file_sum(STANZA *s) /* * Test that the functions work when |r| and |a| point to the same * BIGNUM, or when |r| and |b| point to the same BIGNUM. + * There is no test for all of |r|, |a|, and |b| pointint to the same + * BIGNUM. */ if (!TEST_true(BN_copy(ret, a)) || !TEST_true(BN_uadd(ret, ret, b)) @@ -1726,52 +1664,6 @@ err: return st; } -static int file_modsqr(STANZA *s) -{ - BIGNUM *a = NULL, *m = NULL, *mod_sqr = NULL, *ret = NULL; - int st = 0; - - if (!TEST_ptr(a = getBN(s, "A")) - || !TEST_ptr(m = getBN(s, "M")) - || !TEST_ptr(mod_sqr = getBN(s, "ModSqr")) - || !TEST_ptr(ret = BN_new())) - goto err; - - if (!TEST_true(BN_mod_sqr(ret, a, m, ctx)) - || !equalBN("A^2 (mod M)", mod_sqr, ret)) - goto err; - - if (BN_is_odd(m)) { - /* Reduce |a| and test the Montgomery version. */ - BN_MONT_CTX *mont = BN_MONT_CTX_new(); - BIGNUM *a_tmp = BN_new(); - - if (mont == NULL || a_tmp == NULL - || !TEST_true(BN_MONT_CTX_set(mont, m, ctx)) - || !TEST_true(BN_nnmod(a_tmp, a, m, ctx)) - || !TEST_true(BN_to_montgomery(a_tmp, a_tmp, mont, ctx)) - || !TEST_true(BN_mod_mul_montgomery(ret, a_tmp, a_tmp, - mont, ctx)) - || !TEST_true(BN_from_montgomery(ret, ret, mont, ctx)) - || !equalBN("A^2 (mod M) (mont)", mod_sqr, ret)) - st = 0; - else - st = 1; - BN_MONT_CTX_free(mont); - BN_free(a_tmp); - if (st == 0) - goto err; - } - - st = 1; -err: - BN_free(a); - BN_free(m); - BN_free(mod_sqr); - BN_free(ret); - return st; -} - static int file_modexp(STANZA *s) { BIGNUM *a = NULL, *e = NULL, *m = NULL, *mod_exp = NULL, *ret = NULL; @@ -1800,16 +1692,15 @@ static int file_modexp(STANZA *s) } /* Regression test for carry propagation bug in sqr8x_reduction */ - if (!TEST_true(BN_hex2bn(&a, "050505050505")) - || !TEST_true(BN_hex2bn(&b, "02")) - || !TEST_true(BN_hex2bn(&c, - "4141414141414141414141274141414141414141414141414141414141414141" - "4141414141414141414141414141414141414141414141414141414141414141" - "4141414141414141414141800000000000000000000000000000000000000000" - "0000000000000000000000000000000000000000000000000000000000000000" - "0000000000000000000000000000000000000000000000000000000000000000" - "0000000000000000000000000000000000000000000000000000000001"))) - goto err; + BN_hex2bn(&a, "050505050505"); + BN_hex2bn(&b, "02"); + BN_hex2bn(&c, + "4141414141414141414141274141414141414141414141414141414141414141" + "4141414141414141414141414141414141414141414141414141414141414141" + "4141414141414141414141800000000000000000000000000000000000000000" + "0000000000000000000000000000000000000000000000000000000000000000" + "0000000000000000000000000000000000000000000000000000000000000000" + "0000000000000000000000000000000000000000000000000000000001"); if (!TEST_true(BN_mod_exp(d, a, b, c, ctx)) || !TEST_true(BN_mul(e, a, a, ctx)) || !TEST_BN_eq(d, e)) @@ -3383,7 +3274,6 @@ static int file_test_run(STANZA *s) { "Product", file_product }, { "Quotient", file_quotient }, { "ModMul", file_modmul }, - { "ModSqr", file_modsqr }, { "ModExp", file_modexp }, { "Exp", file_exp }, { "ModSqrt", file_modsqrt }, @@ -3483,7 +3373,6 @@ int setup_tests(void) ADD_ALL_TESTS(test_signed_mod_replace_ab, OSSL_NELEM(signed_mod_tests)); ADD_ALL_TESTS(test_signed_mod_replace_ba, OSSL_NELEM(signed_mod_tests)); ADD_TEST(test_mod); - ADD_TEST(test_sum_all_alias); ADD_TEST(test_mod_inverse); ADD_ALL_TESTS(test_mod_exp_alias, 2); ADD_TEST(test_modexp_mont5); diff --git a/test/build.info b/test/build.info index 4fbe25030f..9eaf1b2b78 100644 --- a/test/build.info +++ b/test/build.info @@ -9,10 +9,6 @@ IF[{- !$disabled{hqinterop} -}] SUBDIRS=quic-openssl-docker ENDIF -IF[{- !$disabled{"unit-tests"} -}] - SUBDIRS=unit -ENDIF - # Auxiliary program source (copied from ../apps/build.info) IF[{- $config{target} =~ /^(?:VC-|mingw|BC-)/ -}] # It's called 'init', but doesn't have much 'init' in it... @@ -36,8 +32,8 @@ IF[{- !$disabled{tests} -}] testutil/test_cleanup.c testutil/main.c testutil/testutil_init.c \ testutil/options.c testutil/test_options.c testutil/provider.c \ testutil/apps_shims.c testutil/random.c testutil/helper.c \ - testutil/compare.c mfail/mfail.c $LIBAPPSSRC - INCLUDE[libtestutil.a]=../include ../apps/include .. mfail + testutil/compare.c $LIBAPPSSRC + INCLUDE[libtestutil.a]=../include ../apps/include .. DEPEND[libtestutil.a]=../libcrypto PROGRAMS{noinst}= \ @@ -53,19 +49,19 @@ IF[{- !$disabled{tests} -}] v3nametest v3ext byteorder_test punycode_test evp_byname_test \ crltest danetest bad_dtls_test lhash_test sparse_array_test \ conf_include_test params_api_test params_conversion_test \ - constant_time_test crypto_memcmp_test safe_math_test verify_extra_test clienthellotest \ + constant_time_test safe_math_test verify_extra_test clienthellotest \ packettest asynctest secmemtest srptest memleaktest stack_test \ dtlsv1listentest ct_test threadstest d2i_test \ ssl_test_ctx_test ssl_test x509aux cipherlist_test asynciotest \ bio_callback_test bio_memleak_test bio_core_test bio_dgram_test param_build_test \ - sslapitest ssl_handshake_rtt_test dtlstest sslcorrupttest \ - bio_base64_test bio_enc_test pkey_meth_kdf_test evp_kdf_test uitest \ + bioprinttest sslapitest ssl_handshake_rtt_test dtlstest sslcorrupttest \ + bio_base64_test bio_enc_test pkey_meth_test pkey_meth_kdf_test evp_kdf_test uitest \ cipherbytes_test threadstest_fips threadpool_test \ asn1_encode_test asn1_decode_test asn1_string_table_test asn1_stable_parse_test \ x509_time_test x509_dup_cert_test x509_check_cert_pkey_test \ recordlentest drbgtest rand_status_test sslbuffertest \ time_offset_test pemtest ssl_cert_table_internal_test ciphername_test \ - servername_test ocspapitest ocsptest fatalerrtest tls13ccstest \ + servername_test ocspapitest fatalerrtest tls13ccstest \ sysdefaulttest errtest ssl_ctx_test build_wincrypt_test \ context_internal_test aesgcmtest params_test evp_pkey_dparams_test \ keymgmt_internal_test hexstr_test provider_status_test defltfips_test \ @@ -74,28 +70,19 @@ IF[{- !$disabled{tests} -}] ca_internals_test bio_tfo_test membio_test bio_dgram_test list_test \ fips_version_test x509_test hpke_test pairwise_fail_test \ nodefltctxtest evp_xof_test x509_load_cert_file_test bio_meth_test \ - x509_acert_test x509_req_test strtoultest bio_pw_callback_test \ - engine_stubs_test base64_simdutf_test bio_eof_test ech_test - - IF[{- !$disabled{'ech'} -}] - PROGRAMS{noinst}=ech_corrupt_test - ENDIF + x509_acert_test x509_req_test strtoultest bio_pw_callback_test IF[{- !$disabled{'rpk'} -}] PROGRAMS{noinst}=rpktest ENDIF IF[{- !$disabled{'allocfail-tests'} -}] - PROGRAMS{noinst}=handshake-memfail x509-memfail load_key_certs_crls_memfail + PROGRAMS{noninst}=handshake-memfail x509-memfail ENDIF IF[{- !$disabled{quic} -}] PROGRAMS{noinst}=priority_queue_test quicfaultstest quicapitest \ - quic_newcid_test quic_srt_gen_test rio_notifier_test - ENDIF - - IF[{- !$disabled{quic} && !$disabled{qlog} -}] - PROGRAMS{noinst}=quic_memfail_test + quic_newcid_test quic_srt_gen_test ENDIF IF[{- !$disabled{qlog} -}] @@ -106,10 +93,6 @@ IF[{- !$disabled{tests} -}] PROGRAMS{noinst}=cert_comp_test ENDIF - IF[{- !$disabled{dtls} -}] - PROGRAMS{noinst}=dtls_ccs_reorder_test - ENDIF - SOURCE[confdump]=confdump.c INCLUDE[confdump]=../include ../apps/include DEPEND[confdump]=../libcrypto @@ -219,9 +202,7 @@ IF[{- !$disabled{tests} -}] DEFINE[evp_test]=NO_LEGACY_MODULE ENDIF - SOURCE[evp_extra_test]=evp_extra_test.c fake_rsaprov.c fake_pipelineprov.c \ - helpers/predefined_dsaparams.c \ - helpers/predefined_dhparams.c + SOURCE[evp_extra_test]=evp_extra_test.c fake_rsaprov.c fake_pipelineprov.c INCLUDE[evp_extra_test]=../include ../apps/include \ ../providers/common/include \ ../providers/implementations/include @@ -244,14 +225,6 @@ IF[{- !$disabled{tests} -}] DEPEND[lms_test]=../libcrypto.a libtestutil.a ENDIF - SOURCE[ech_test]=ech_test.c helpers/ssltestlib.c - INCLUDE[ech_test]=../include ../apps/include - DEPEND[ech_test]=../libssl.a ../libcrypto.a libtestutil.a - - SOURCE[ech_corrupt_test]=ech_corrupt_test.c helpers/ssltestlib.c - INCLUDE[ech_corrupt_test]=../include ../apps/include - DEPEND[ech_corrupt_test]=../libssl.a ../libcrypto.a libtestutil.a - SOURCE[evp_extra_test2]=evp_extra_test2.c $INITSRC tls-provider.c INCLUDE[evp_extra_test2]=../include ../apps/include DEPEND[evp_extra_test2]=../libcrypto libtestutil.a @@ -260,7 +233,7 @@ IF[{- !$disabled{tests} -}] INCLUDE[evp_libctx_test]=../include ../apps/include DEPEND[evp_libctx_test]=../libcrypto.a libtestutil.a - SOURCE[evp_fetch_prov_test]=evp_fetch_prov_test.c fake_cipherprov.c + SOURCE[evp_fetch_prov_test]=evp_fetch_prov_test.c INCLUDE[evp_fetch_prov_test]=../include ../apps/include DEPEND[evp_fetch_prov_test]=../libcrypto libtestutil.a @@ -336,18 +309,8 @@ IF[{- !$disabled{tests} -}] SOURCE[ml_dsa_test]=ml_dsa_test.c INCLUDE[ml_dsa_test]=../include ../apps/include DEPEND[ml_dsa_test]=../libcrypto.a libtestutil.a - - PROGRAMS{noinst}=ml_dsa_internal_test - SOURCE[ml_dsa_internal_test]=ml_dsa_internal_test.c - INCLUDE[ml_dsa_internal_test]=../include ../apps/include - DEPEND[ml_dsa_internal_test]=../libcrypto.a libtestutil.a ENDIF - PROGRAMS{noinst}=aeswrap_test - SOURCE[aeswrap_test]=aeswrap_test.c - INCLUDE[aeswrap_test]=../include ../apps/include - DEPEND[aeswrap_test]=../libcrypto.a libtestutil.a - SOURCE[v3nametest]=v3nametest.c INCLUDE[v3nametest]=../include ../apps/include DEPEND[v3nametest]=../libcrypto libtestutil.a @@ -356,10 +319,6 @@ IF[{- !$disabled{tests} -}] INCLUDE[crltest]=../include ../apps/include DEPEND[crltest]=../libcrypto libtestutil.a - SOURCE[ocsptest]=ocsptest.c - INCLUDE[ocsptest]=../include ../apps/include - DEPEND[ocsptest]=../libcrypto libtestutil.a - SOURCE[v3ext]=v3ext.c INCLUDE[v3ext]=../include ../apps/include DEPEND[v3ext]=../libcrypto libtestutil.a @@ -372,10 +331,6 @@ IF[{- !$disabled{tests} -}] INCLUDE[constant_time_test]=../include ../apps/include DEPEND[constant_time_test]=../libcrypto libtestutil.a - SOURCE[crypto_memcmp_test]=crypto_memcmp_test.c - INCLUDE[crypto_memcmp_test]=../include ../apps/include - DEPEND[crypto_memcmp_test]=../libcrypto libtestutil.a - SOURCE[safe_math_test]=safe_math_test.c INCLUDE[safe_math_test]=../include ../apps/include DEPEND[safe_math_test]=../libcrypto libtestutil.a @@ -397,10 +352,6 @@ IF[{- !$disabled{tests} -}] DEPEND[packettest]=../libcrypto libtestutil.a IF[{- !$disabled{'quic'} -}] - SOURCE[rio_notifier_test]=rio_notifier_test.c - INCLUDE[rio_notifier_test]=.. ../include ../apps/include - DEPEND[rio_notifier_test]=../libcrypto.a ../libssl.a libtestutil.a - SOURCE[quic_wire_test]=quic_wire_test.c INCLUDE[quic_wire_test]=../include ../apps/include DEPEND[quic_wire_test]=../libcrypto.a ../libssl.a libtestutil.a @@ -469,12 +420,6 @@ IF[{- !$disabled{tests} -}] SOURCE[quic_qlog_test]=quic_qlog_test.c INCLUDE[quic_qlog_test]=../include ../apps/include DEPEND[quic_qlog_test]=../libcrypto.a ../libssl.a libtestutil.a - - IF[{- !$disabled{quic} -}] - SOURCE[quic_memfail_test]=quic_memfail_test.c - INCLUDE[quic_memfail_test]=../include ../apps/include - DEPEND[quic_memfail_test]=../libcrypto.a ../libssl.a libtestutil.a - ENDIF ENDIF SOURCE[asynctest]=asynctest.c @@ -594,18 +539,12 @@ IF[{- !$disabled{tests} -}] INCLUDE[bio_meth_test]=../include ../apps/include DEPEND[bio_meth_test]=../libcrypto libtestutil.a - SOURCE[bio_eof_test]=bio_eof_test.c - INCLUDE[bio_eof_test]=../include ../apps/include - DEPEND[bio_eof_test]=../libcrypto libtestutil.a - - IF[{- !$disabled{sock} - && $config{target} !~ /djgpp/i - && $config{target} !~ /^(?:VC-|mingw|BC-|Cygwin)/i - -}] - PROGRAMS{noinst}=bio_socket_sigpipe_test - SOURCE[bio_socket_sigpipe_test]=bio_socket_sigpipe_test.c - INCLUDE[bio_socket_sigpipe_test]=../include ../apps/include - DEPEND[bio_socket_sigpipe_test]=../libcrypto libtestutil.a + SOURCE[bioprinttest]=bioprinttest.c + INCLUDE[bioprinttest]=../include ../apps/include + IF[{- $config{target} =~ /^VC/ -}] + DEPEND[bioprinttest]=../libcrypto.a libtestutil.a + ELSE + DEPEND[bioprinttest]=../libcrypto libtestutil.a ENDIF SOURCE[bio_core_test]=bio_core_test.c @@ -617,15 +556,15 @@ IF[{- !$disabled{tests} -}] DEPEND[bio_dgram_test]=../libcrypto libtestutil.a SOURCE[bio_tfo_test]=bio_tfo_test.c - INCLUDE[bio_tfo_test]=../include ../apps/include + INCLUDE[bio_tfo_test]=../include ../apps/include .. DEPEND[bio_tfo_test]=../libcrypto libtestutil.a SOURCE[membio_test]=membio_test.c - INCLUDE[membio_test]=../include ../apps/include + INCLUDE[membio_test]=../include ../apps/include .. DEPEND[membio_test]=../libcrypto libtestutil.a SOURCE[bio_dgram_test]=bio_dgram_test.c - INCLUDE[bio_dgram_test]=../include ../apps/include + INCLUDE[bio_dgram_test]=../include ../apps/include .. DEPEND[bio_dgram_test]=../libcrypto libtestutil.a SOURCE[params_api_test]=params_api_test.c @@ -652,13 +591,6 @@ IF[{- !$disabled{tests} -}] INCLUDE[x509-memfail]=../include ../apps/include DEPEND[x509-memfail]=../libcrypto.a libtestutil.a - SOURCE[load_key_certs_crls_memfail]=load_key_certs_crls_memfail.c ../apps/lib/apps.c \ - ../apps/lib/app_rand.c ../apps/lib/app_provider.c ../apps/lib/app_libctx.c \ - ../apps/lib/fmt.c ../apps/lib/apps_ui.c ../apps/lib/app_x509.c \ - ../crypto/asn1/a_time.c ../crypto/ctype.c - INCLUDE[load_key_certs_crls_memfail]=.. ../include ../apps/include - DEPEND[load_key_certs_crls_memfail]=libtestutil.a ../libcrypto.a ../libssl.a - SOURCE[ssl_handshake_rtt_test]=ssl_handshake_rtt_test.c helpers/ssltestlib.c INCLUDE[ssl_handshake_rtt_test]=../include ../apps/include .. DEPEND[ssl_handshake_rtt_test]=../libcrypto.a ../libssl.a libtestutil.a @@ -699,12 +631,6 @@ IF[{- !$disabled{tests} -}] INCLUDE[dtlstest]=../include ../apps/include DEPEND[dtlstest]=../libcrypto ../libssl libtestutil.a - IF[{- !$disabled{dtls} -}] - SOURCE[dtls_ccs_reorder_test]=dtls_ccs_reorder_test.c helpers/ssltestlib.c - INCLUDE[dtls_ccs_reorder_test]=../include ../apps/include - DEPEND[dtls_ccs_reorder_test]=../libcrypto ../libssl libtestutil.a - ENDIF - SOURCE[sslcorrupttest]=sslcorrupttest.c helpers/ssltestlib.c INCLUDE[sslcorrupttest]=../include ../apps/include DEPEND[sslcorrupttest]=../libcrypto ../libssl libtestutil.a @@ -713,14 +639,14 @@ IF[{- !$disabled{tests} -}] INCLUDE[bio_base64_test]=../include ../apps/include DEPEND[bio_base64_test]=../libcrypto libtestutil.a - SOURCE[base64_simdutf_test] = base64_simdutf_test.c - INCLUDE[base64_simdutf_test] = ../include ../apps/include ../crypto/include ../crypto/evp/ - DEPEND[base64_simdutf_test] = ../libcrypto libtestutil.a - SOURCE[bio_enc_test]=bio_enc_test.c INCLUDE[bio_enc_test]=../include ../apps/include DEPEND[bio_enc_test]=../libcrypto libtestutil.a + SOURCE[pkey_meth_test]=pkey_meth_test.c + INCLUDE[pkey_meth_test]=../include ../apps/include + DEPEND[pkey_meth_test]=../libcrypto libtestutil.a + SOURCE[pkey_meth_kdf_test]=pkey_meth_kdf_test.c INCLUDE[pkey_meth_kdf_test]=../include ../apps/include DEPEND[pkey_meth_kdf_test]=../libcrypto libtestutil.a @@ -941,8 +867,6 @@ IF[{- !$disabled{tests} -}] PROGRAMS{noinst}=cmactest ENDIF - PROGRAMS{noinst}=sha3_x4_internal_test - SOURCE[poly1305_internal_test]=poly1305_internal_test.c INCLUDE[poly1305_internal_test]=.. ../include ../apps/include DEPEND[poly1305_internal_test]=../libcrypto.a libtestutil.a @@ -951,10 +875,6 @@ IF[{- !$disabled{tests} -}] INCLUDE[chacha_internal_test]=.. ../include ../apps/include DEPEND[chacha_internal_test]=../libcrypto.a libtestutil.a - SOURCE[sha3_x4_internal_test]=sha3_x4_internal_test.c - INCLUDE[sha3_x4_internal_test]=.. ../include ../apps/include - DEPEND[sha3_x4_internal_test]=../libcrypto.a libtestutil.a - SOURCE[asn1_internal_test]=asn1_internal_test.c INCLUDE[asn1_internal_test]=.. ../include ../apps/include DEPEND[asn1_internal_test]=../libcrypto.a libtestutil.a @@ -983,31 +903,10 @@ IF[{- !$disabled{tests} -}] INCLUDE[dsatest]=../include ../apps/include DEPEND[dsatest]=../libcrypto.a libtestutil.a - SOURCE[dsa_no_digest_size_test]=dsa_no_digest_size_test.c helpers/predefined_dsaparams.c + SOURCE[dsa_no_digest_size_test]=dsa_no_digest_size_test.c INCLUDE[dsa_no_digest_size_test]=../include ../apps/include DEPEND[dsa_no_digest_size_test]=../libcrypto.a libtestutil.a - IF[{- !$disabled{ecx} && !$disabled{tls1_2} && !$disabled{tls1_3} -}] - PROGRAMS{noinst}=tls13ticket_test - SOURCE[tls13ticket_test]=tls13tickettest.c helpers/ssltestlib.c - INCLUDE[tls13ticket_test]=../include ../apps/include .. - DEPEND[tls13ticket_test]=../libcrypto ../libssl libtestutil.a - ENDIF - - IF[{- !$disabled{psk} && !$disabled{tls1_2} -}] - PROGRAMS{noinst}=tls12psk_test - SOURCE[tls12psk_test]=tls12psk.c helpers/ssltestlib.c - INCLUDE[tls12psk_test]=.. ../include ../apps/include - DEPEND[tls12psk_test]=../libcrypto.a ../libssl.a libtestutil.a - ENDIF - - IF[{- !$disabled{psk} && !$disabled{dtls1_2} -}] - PROGRAMS{noinst}=dtls12psk_test - SOURCE[dtls12psk_test]=dtls12psk.c helpers/ssltestlib.c - INCLUDE[dtls12psk_test]=.. ../include ../apps/include - DEPEND[dtls12psk_test]=../libcrypto.a ../libssl.a libtestutil.a - ENDIF - SOURCE[tls13encryptiontest]=tls13encryptiontest.c INCLUDE[tls13encryptiontest]=.. ../include ../apps/include DEPEND[tls13encryptiontest]=../libcrypto.a ../libssl.a libtestutil.a @@ -1179,21 +1078,11 @@ IF[{- !$disabled{tests} -}] INCLUDE[ssl_old_test]=.. ../include ../apps/include DEPEND[ssl_old_test]=../libcrypto.a ../libssl.a libtestutil.a - PROGRAMS{noinst}=tls_groups_list_test - SOURCE[tls_groups_list_test]=tls_groups_list_test.c - INCLUDE[tls_groups_list_test]=.. ../include ../apps/include - DEPEND[tls_groups_list_test]=../libcrypto.a ../libssl.a libtestutil.a - PROGRAMS{noinst}=ext_internal_test SOURCE[ext_internal_test]=ext_internal_test.c INCLUDE[ext_internal_test]=.. ../include ../apps/include DEPEND[ext_internal_test]=../libcrypto.a ../libssl.a libtestutil.a - PROGRAMS{noinst}=statem_clnt_construct_test - SOURCE[statem_clnt_construct_test]=statem_clnt_construct_test.c - INCLUDE[statem_clnt_construct_test]=.. ../include ../apps/include - DEPEND[statem_clnt_construct_test]=../libcrypto.a ../libssl.a libtestutil.a - PROGRAMS{noinst}=algorithmid_test SOURCE[algorithmid_test]=algorithmid_test.c INCLUDE[algorithmid_test]=../include ../apps/include @@ -1206,11 +1095,6 @@ IF[{- !$disabled{tests} -}] INCLUDE[asn1_time_test]=../include ../apps/include DEPEND[asn1_time_test]=../libcrypto libtestutil.a - PROGRAMS{noinst}=asn1_string_test - SOURCE[asn1_string_test]=asn1_string_test.c - INCLUDE[asn1_string_test]=../include ../apps/include - DEPEND[asn1_string_test]=../libcrypto libtestutil.a - # We disable this test completely in a shared build because it deliberately # redefines some internal libssl symbols. This doesn't work in a non-shared # build @@ -1236,7 +1120,7 @@ IF[{- !$disabled{tests} -}] DEPEND[errtest]=../libcrypto libtestutil.a SOURCE[aesgcmtest]=aesgcmtest.c - INCLUDE[aesgcmtest]=../include ../apps/include + INCLUDE[aesgcmtest]=../include ../apps/include .. DEPEND[aesgcmtest]=../libcrypto libtestutil.a PROGRAMS{noinst}=context_internal_test @@ -1254,19 +1138,19 @@ IF[{- !$disabled{tests} -}] PROGRAMS{noinst}=provider_internal_test DEFINE[provider_internal_test]=PROVIDER_INIT_FUNCTION_NAME=p_test_init SOURCE[provider_internal_test]=provider_internal_test.c p_test.c - INCLUDE[provider_internal_test]=../include ../apps/include + INCLUDE[provider_internal_test]=../include ../apps/include .. DEPEND[provider_internal_test]=../libcrypto.a libtestutil.a PROGRAMS{noinst}=provider_test DEFINE[provider_test]=PROVIDER_INIT_FUNCTION_NAME=p_test_init SOURCE[provider_test]=provider_test.c p_test.c - INCLUDE[provider_test]=../include ../apps/include + INCLUDE[provider_test]=../include ../apps/include .. DEPEND[provider_test]=../libcrypto libtestutil.a IF[{- !$disabled{module} -}] MODULES{noinst}=p_test p_ossltest SOURCE[p_test]=p_test.c SOURCE[p_ossltest]=p_ossltest.c ../providers/prov_running.c - INCLUDE[p_test]=../include - INCLUDE[p_ossltest]=../include ../crypto ../providers/common/include ../providers/implementations/include ../providers/implementations + INCLUDE[p_test]=../include .. + INCLUDE[p_ossltest]=../include .. ../providers/common/include ../providers/implementations/include ../providers/implementations DEPEND[p_ossltest]=../providers/libcommon.a ../libcrypto IF[{- defined $target{shared_defflag} -}] SOURCE[p_test]=p_test.ld @@ -1275,21 +1159,11 @@ IF[{- !$disabled{tests} -}] ENDIF MODULES{noinst}=p_minimal SOURCE[p_minimal]=p_minimal.c - INCLUDE[p_minimal]=../include + INCLUDE[p_minimal]=../include .. IF[{- defined $target{shared_defflag} -}] SOURCE[p_minimal]=p_minimal.ld GENERATE[p_minimal.ld]=../util/providers.num ENDIF - # Loadable form of the fake cipher provider. - MODULES{noinst}=fake-cipher - SOURCE[fake-cipher]=fake_cipherprov.c - DEFINE[fake-cipher]=FAKE_CIPHER_AS_MODULE - INCLUDE[fake-cipher]=../include - DEPEND[fake-cipher]=../libcrypto - IF[{- defined $target{shared_defflag} -}] - SOURCE[fake-cipher]=fake-cipher.ld - GENERATE[fake-cipher.ld]=../util/providers.num - ENDIF ENDIF IF[{- $disabled{module} || !$target{dso_scheme} -}] DEFINE[provider_test]=NO_PROVIDER_MODULE @@ -1440,10 +1314,6 @@ ENDIF INCLUDE[bio_pw_callback_test]=../include ../apps/include DEPEND[bio_pw_callback_test]=../libcrypto libtestutil.a - SOURCE[engine_stubs_test]=engine_stubs_test.c - INCLUDE[engine_stubs_test]=../include ../apps/include - DEPEND[engine_stubs_test]=../libcrypto libtestutil.a - {- use File::Spec::Functions; use File::Basename; diff --git a/test/ca-and-certs.cnf b/test/ca-and-certs.cnf index 30838831be..58ca0eda64 100644 --- a/test/ca-and-certs.cnf +++ b/test/ca-and-certs.cnf @@ -9,8 +9,6 @@ CN2 = Brother 2 distinguished_name = req_distinguished_name encrypt_rsa_key = no default_md = sha1 -req_extensions = empty -x509_extensions = minimal [ req_distinguished_name ] countryName = Country Name (2 letter code) @@ -35,21 +33,6 @@ organizationName = Dodgy Brothers [ empty ] -[ minimal ] -subjectKeyIdentifier = hash -authorityKeyIdentifier = keyid:nonss - -[ v3_skid ] -subjectKeyIdentifier = hash - -[ v3_akid ] -# With just the AKID, we can't produce keyids for self-signed certs. -authorityKeyIdentifier = keyid:nonss, issuer - -[ v3_askid ] -subjectKeyIdentifier = hash -authorityKeyIdentifier = keyid:always - [ v3_ee ] subjectKeyIdentifier = hash authorityKeyIdentifier = keyid,issuer:always @@ -75,6 +58,7 @@ default_ca = CA_default [ CA_default ] dir = ./demoCA certs = $dir/certs +crl_dir = $dir/crl database = $dir/index.txt new_certs_dir = $dir/newcerts certificate = $dir/cacert.pem @@ -101,7 +85,7 @@ emailAddress = optional [ v3_ca ] subjectKeyIdentifier = hash -authorityKeyIdentifier = keyid:nonss,issuer:nonss +authorityKeyIdentifier = keyid:always,issuer:always basicConstraints = critical,CA:true,pathlen:1 keyUsage = cRLSign, keyCertSign issuerAltName = issuer:copy diff --git a/test/ca_internals_test.c b/test/ca_internals_test.c index 218ec98f52..dccb0f1c82 100644 --- a/test/ca_internals_test.c +++ b/test/ca_internals_test.c @@ -49,13 +49,13 @@ static int test_do_updatedb(void) testdate = test_get_argument(2); if (!test_asn1_string_to_time_t(testdate, &testdateutc)) return 0; - if (!TEST_time_t_ge(testdateutc, 0)) { + if (TEST_time_t_lt(testdateutc, 0)) { return 0; } indexfile = test_get_argument(1); db = load_index(indexfile, NULL); - if (!TEST_ptr(db)) { + if (TEST_ptr_null(db)) { return 0; } diff --git a/test/certs/bad-cert-smtputf8-name-constraints.pem b/test/certs/bad-cert-smtputf8-name-constraints.pem deleted file mode 100644 index 7eb48f1ec7..0000000000 --- a/test/certs/bad-cert-smtputf8-name-constraints.pem +++ /dev/null @@ -1,26 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIETjCCAzagAwIBAgIUAfHYT2xCH+Q2ONGkBpeu1yo4uYAwDQYJKoZIhvcNAQEL -BQAwfzELMAkGA1UEBhMCQ0ExCzAJBgNVBAgMAkFCMSMwIQYDVQQKDBpIb25lc3Qg -Qm9icyBUcnVzdCBTZXJ2aWNlczE+MDwGA1UEAww1Qm9ndXMgQ0EgY2VydCB3aXRo -IEludmFsaWQgU01UUFV0ZjggTmFtZSBDb25zdHJhaW50cy4wIBcNMjYwMzI2MTk0 -MzEwWhgPMjA1MzA4MTAxOTQzMTBaMH8xCzAJBgNVBAYTAkNBMQswCQYDVQQIDAJB -QjEjMCEGA1UECgwaSG9uZXN0IEJvYnMgVHJ1c3QgU2VydmljZXMxPjA8BgNVBAMM -NUJvZ3VzIENBIGNlcnQgd2l0aCBJbnZhbGlkIFNNVFBVdGY4IE5hbWUgQ29uc3Ry -YWludHMuMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA7Gfh95qTUIgQ -8bTQJ9XIw4ZKYawQSL3eydsdZwIoqLPub323BlgExxDW/rkHOiYA+btBnBdKWPMc -WXYcjMMVnHD4/bAwglgtEPSIlPH0GQWITdr9ISZt5BPISt21xzzVxEYwSAnQfIOG -q3wXv2XO3C4lTnz4YRsRhh7Nbg1n6eLSEldi7EEtIx0cUv7RqiPkRhitpAdlhcN4 -hS2WGDtjmuMXOLLkt5kfme2il3i/f/OvOYHcGev8VEbe9ucAse70RjNtsrIGtHRa -U5JNILo3GVRi5tIp56zdnnzW+HMdAyHNeB1KPEdMC7YP1FQEz2u58la6dhT2LPJj -j3y8h1im2QIDAQABo4G/MIG8MBIGA1UdEwEB/wQIMAYBAf8CAQAwDgYDVR0PAQH/ -BAQDAgGGMB0GA1UdDgQWBBQBGPQWxNM5dhZBl0LVtI8EFHlDvjAfBgNVHSMEGDAW -gBQBGPQWxNM5dhZBl0LVtI8EFHlDvjBWBgNVHR4BAf8ETDBKoCMwIaAfBggrBgEF -BQcICaATDBFiZWNrQGxpYnJlc3NsLm9yZ6EjMCGgHwYIKwYBBQUHCAmgEwwRYmVj -a0BsaWJyZXNzbC5vcmcwDQYJKoZIhvcNAQELBQADggEBAMCHstK2G8xzoG2EscY+ -BQVJ3nOuk33/Q7s9sdXFEyrN0F9a1pWE/pKdqplgZTN6buGXym+iSV4mA3+9/Aty -BFa3vZoOnN3Td9gWDpIqyUtgEtjrGpAmPLvymalVlHBDsm67rMO+b3hXz9ioGNWT -ii5JFtcqltTasz7ePXYJxQjBByMOVd/tvb6Nn2QIvr841zOjhC9Bp0OZsWs6qAbw -Dg/yHnrSZOvPV8c+qKco7zqlGpTZtnTU05dIztoQU6RcBjV9nAUQy6LZp3XtF4/h -MIMydgmxi52aUY5NFccfBoZdM4m7caEvwACBhpTNtBrdr16L+0SIPHjr4Vat9ruJ -/8A= ------END CERTIFICATE----- diff --git a/test/certs/cve-2026-28388-ca.pem b/test/certs/cve-2026-28388-ca.pem deleted file mode 100644 index 9e36d11c4b..0000000000 --- a/test/certs/cve-2026-28388-ca.pem +++ /dev/null @@ -1,19 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIDFTCCAf2gAwIBAgIUOl5NN/jfsuLU9JSGLZAfRzviF+owDQYJKoZIhvcNAQEL -BQAwEjEQMA4GA1UEAwwHVGVzdCBDQTAeFw0yNjAzMTcwODE5NDdaFw0yNzAzMTcw -ODE5NDdaMBIxEDAOBgNVBAMMB1Rlc3QgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IB -DwAwggEKAoIBAQD0m4KETjF0c25spNWUiNChWP0GalDL0gVDFbtAoMVF/lvlZEcp -hcg62ifHJRPntWyVAmH70DAI87cWzl/73QYGaOcMVcH5yEM31BoK83FvhsS3RTPO -FSrNCHaZrrWuga+QkBmMcR6qX7GF5eb6ASMBsLuuDqbkCRbTJ2ryhYeWF+VFemBF -pSHpcinSSLvswTVbZiCqmoy0WkK8eiyfLMZA17PgVLQpyPZ3rp5YG5vEZZoqFc/f -1bCHjwQ7fNdLCEMqPvE/I0mg2skRClb1L1Vieud/jmjL8nVd9I12j1eUOcSKtCkW -nj4BFa7TRz13sN3LZOFvV774ZaXRJ1GxoAlnAgMBAAGjYzBhMB0GA1UdDgQWBBSt -UxfaVbV9QMmfwMoImdgi4MZHzTAfBgNVHSMEGDAWgBStUxfaVbV9QMmfwMoImdgi -4MZHzTAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBBjANBgkqhkiG9w0B -AQsFAAOCAQEA84w49n0pPJlqiD1/mn3pUZ66lBP0fFZiCuV/3YatBZcW+xcboW0Q -xImYztjZo0i+sQLZOalI4GoBqD77Dv4Qas0QoJZIp0wM8DjE3YcudCr4cpUhT1XC -ruHVHQA9bY5rW0GsfUBW6/3RbRpiK4SaFG3sUBbXPo0dC2EaLDjpLM7o2UljRrWu -d/vg6ieKuAicexLxqQLdM4SxjyvBpCwHg/dnMxawSj4Xhks1BHJ0hTLKJGDgfVHh -ex8+878u6Gf7fAOZa5idWUgTvdt5WHSW5x+Tm/P6LGG3HkM425ZU6BLTCHONoBud -cOlfWTTuIyweX5TRL5HY3SuO1cpMBpjiAA== ------END CERTIFICATE----- diff --git a/test/certs/cve-2026-28388-crls.pem b/test/certs/cve-2026-28388-crls.pem deleted file mode 100644 index 46cbd7876d..0000000000 --- a/test/certs/cve-2026-28388-crls.pem +++ /dev/null @@ -1,22 +0,0 @@ ------BEGIN X509 CRL----- -MIIBizB1AgEBMA0GCSqGSIb3DQEBCwUAMBIxEDAOBgNVBAMMB1Rlc3QgQ0EXDTI2 -MDMxNzA4MTk0N1oXDTI2MDQxNjA4MTk0N1qgLzAtMB8GA1UdIwQYMBaAFK1TF9pV -tX1AyZ/AygiZ2CLgxkfNMAoGA1UdFAQDAgEBMA0GCSqGSIb3DQEBCwUAA4IBAQBl -3vVknchCNA/oW0ovtnrE+xQs8yAk3uElooQlw88moTcts2YAcKWl49lnNWZk/RbF -Zs8m+MUuNb2W861siuvY3EwnSKVaJB2tKPfCRBP4xt+Q0g/Tn5CWxzpzHjQfLT6l -pvWOwaO7aE6bthX7MQ9XBpnHSPxsbul+MhV5PER11BYZGVh5MH0XxfMI0jDHFh2M -klTamgaao3TkVOI3OQPgzUx/q0Lz/YoCIH0pYGGP6KTGUX2x7UfD1tcIOcUp6tvO -6hG3utMgJOpZJl9yMzhG+ZURjbz4MSbBM0FVIaWnBn2VzY1jHGky0nK83IZhiddf -OohWoSH8tqwrNFZkblAH ------END X509 CRL----- ------BEGIN X509 CRL----- -MIIBjjB4AgEBMA0GCSqGSIb3DQEBCwUAMBIxEDAOBgNVBAMMB1Rlc3QgQ0EXDTI2 -MDEwODEyMDAwMFoXDTI2MDIwODEyMDAwMFqgMjAwMB8GA1UdIwQYMBaAFK1TF9pV -tX1AyZ/AygiZ2CLgxkfNMA0GA1UdGwEB/wQDAgEBMA0GCSqGSIb3DQEBCwUAA4IB -AQCyYxa5iVUFxBpdXgBGSMqkuxJqQzVni8nXK0DiXHfgbTud+HD5Qp/6PX2EQuwK -SrT0yeNJBU1gxxMMsbdA0yVTPa7N2Ny39mjq/27yBXduiljo3Gs4NLEW9grJRnep -WOD1cQe3Fea5HlEfUoQJF1WVekF6CnOSqESaDvTAzqpZd7pxU8cuduiRJPin93ki -1nicQAU/G4Td190+JEAWD3/dJTg2LF6LKrmHiv2ZUTuNsVBfcbhFSoC6FpnjFUAI -kF8EgJpuBEfqV6erIuT1GD+5p1QGNqdcNl7LO9erJaUFnssJBJtj84iXd7RZARNs -njcibOSKC9YWgNmZUy0QV5D8 ------END X509 CRL----- diff --git a/test/certs/cve-2026-28388-leaf.pem b/test/certs/cve-2026-28388-leaf.pem deleted file mode 100644 index 02b22997cd..0000000000 --- a/test/certs/cve-2026-28388-leaf.pem +++ /dev/null @@ -1,19 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIDHTCCAgWgAwIBAgIBATANBgkqhkiG9w0BAQsFADASMRAwDgYDVQQDDAdUZXN0 -IENBMB4XDTI2MDMxNzA4MTk0N1oXDTI3MDMxNzA4MTk0N1owFDESMBAGA1UEAwwJ -VGVzdCBMZWFmMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqx7jpC6+ -nRZ4ol6sShkpv04hGYtt7y+Ns4oIfdQTqo57DItFab8D8cH04zR8NND42MMnsPPn -Ovh9gv2l1mj9ZfwgXI5PvaKc6CoXvXb0ttekdDUS1iw9g04BxIXTDANxsdSXrCDd -Npyr1Pxdo3N2fiH6qN9/Lsh7yg0vJW/aJzdvhLcCTFcr89qmCsh17XfcTR0wZJXP -QdlRib9EK8aa6aKOYmm44SBbuXXyWojhheUaqVuzDj6A0L9opmh/DVXa9bdIN/FX -CKJB+d60Qxy5pKwpzDDxbCdG2vA1U2cPz8yAgelFG5AmXSHF7Id4G6GTCAY6PbTO -Jy2Z4I6NY+mj5wIDAQABo3wwejAdBgNVHQ4EFgQUlf2YZ93MvS4kZm7fshosgp+J -ImkwHwYDVR0jBBgwFoAUrVMX2lW1fUDJn8DKCJnYIuDGR80wCQYDVR0TBAIwADAt -BgNVHS4EJjAkMCKgIKAehhxodHRwOi8vZXhhbXBsZS5jb20vZGVsdGEucGVtMA0G -CSqGSIb3DQEBCwUAA4IBAQDoNAQGLS0Juf3i2fhuVQyWIFvNIMElLexeLnnd/y80 -13nsP68ZGT2D3DoHQSz3SL7sNjLBc2CiUVftdaRQ4dNCz8sBY5BRTS5XEGbbTAFZ -bQUReykuuTy83CGw/JYN6YT/OHcf4gEhUnWtRMCmIz3J/NMRVSRnpV2Ezjltm/Q+ -emFS/QclRhkP6Vu+lwM/nV6uAN8T7Ba68Hym2MN0clozrpoKeqFouB7D0i+iCZMw -zbac5as0hn7Fm+HGTbfTs2/fqUslvE6PmagepceP37pTSSVmYRmdpOD2cyCb30A+ -nJFGQg7PcacGSL1re65W35XzdU8Si8OYD+PxjDaRbPcP ------END CERTIFICATE----- diff --git a/test/certs/delta-crl-as-complete-ca.pem b/test/certs/delta-crl-as-complete-ca.pem deleted file mode 100644 index c7bade031a..0000000000 --- a/test/certs/delta-crl-as-complete-ca.pem +++ /dev/null @@ -1,20 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIDQTCCAimgAwIBAgIUP+A4l1Xr6j1/lQ/bRBdNebfmEHMwDQYJKoZIhvcNAQEL -BQAwKDEmMCQGA1UEAwwdRGVsdGEgQ1JMIGFzIENvbXBsZXRlIFRlc3QgQ0EwHhcN -MjYwNDMwMTQ0NjAyWhcNMzYwNDI3MTQ0NjAyWjAoMSYwJAYDVQQDDB1EZWx0YSBD -UkwgYXMgQ29tcGxldGUgVGVzdCBDQTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC -AQoCggEBAJ6Wr3/CguoFSKWbeAE2Czjp6qFRdZ3xhhz27NuSdnHpoZE7xgzbt3Z2 -cNt+szZXZIgOyMzSOu0r8q0fKp4VJmR9M5KoMduTHRJpwvT79VhJdZED/1akKhgJ -7WttsvK5kNc+1he7gELY3ssuzfw7MmZv+vMpykjNhSSBKpmUy2t9lX/b1mJ+LK6v -gHQ09ntxdIGniRauzf027ugG72oSydk80YG0EHBlI19eYVhBJEWjLq4afLUYRbfm -0OYHJGq5TE0VTww4xa1IzLFt4NpqveYztYN4ujKd95vbHB6EzCs3R15uJwwm/1px -PXFhwp4MF/W422/XxcadU3+0zHDgEScCAwEAAaNjMGEwDwYDVR0TAQH/BAUwAwEB -/zAOBgNVHQ8BAf8EBAMCAQYwHQYDVR0OBBYEFMIh2AkMIUaBjaMHDAOEBAv33XzE -MB8GA1UdIwQYMBaAFMIh2AkMIUaBjaMHDAOEBAv33XzEMA0GCSqGSIb3DQEBCwUA -A4IBAQA6yelNaY6aVomoTwmvNXdfNqlU96HGmEFfKMMFL1CgF5KsBaz4ARCJ+83s -/A0+HufwFYOwUx+dkklatp791leaFjxkFSHmKrE6WVBnOoss7M4a+Hwei13Qrirx -vKFhQde45OFqh8zpl0fru/KdCnbRoM05KVhFqnXR+vyDvghvlIWDFEFdX7KOdVXz -s9v5ECR4kftEalZVq7WNVBS9afVPoQvYj3dcebMH8l8RL5+adV2NRvBKgUKo2kwy -TG6nqWKRr4xqsARLPxYFk1tHbKfIVWy1FrABb5lW8iMA/RZCv6Qzyqbr4nT0WDTa -g3OUp6sSDEhnLYhnW3bsLUdpgRfy ------END CERTIFICATE----- diff --git a/test/certs/delta-crl-as-complete-delta-reasons.pem b/test/certs/delta-crl-as-complete-delta-reasons.pem deleted file mode 100644 index d20bc63f53..0000000000 --- a/test/certs/delta-crl-as-complete-delta-reasons.pem +++ /dev/null @@ -1,12 +0,0 @@ ------BEGIN X509 CRL----- -MIIBxDCBrQIBATANBgkqhkiG9w0BAQsFADAoMSYwJAYDVQQDDB1EZWx0YSBDUkwg -YXMgQ29tcGxldGUgVGVzdCBDQRcNMjYwNDMwMTQ0NjAzWhcNMzYwNDI3MTQ0NjAz -WqBRME8wHwYDVR0jBBgwFoAUwiHYCQwhRoGNowcMA4QEC/fdfMQwDQYDVR0bAQH/ -BAMCAQEwEAYDVR0cAQH/BAYwBIMCBWAwCwYDVR0UBAQCAjAAMA0GCSqGSIb3DQEB -CwUAA4IBAQB735x+EogYnkeL3DHwHBbTKXyWMp9UEdR9DVUVElNISNrLTuOy62Nr -N4OEWtDCESltII739hryz85lg0Jo1jBOYbRdGYIacRzm1WUvtk3aLfGt0gwifFtW -4AiiQZUz3jq0F2V9TythzE0nMQbIiXpG3ACc+HQ5/gwpFEvw9ABjXMp5SVU47fT5 -M2jRk12XR6N/MDJB13uh0EH814CD23Gqhvu2lVL3KSGiwImirbQX18egibBmIykR -jqwaH0giFa5ZbrMcOyBksyZJIZgAOpnzn4M5FlQb4s0AjxYSRjqQWV5qrBVfWT6b -Jy+lW3HgXMYyZt6Gqyayfu7N+6JbqhQ+ ------END X509 CRL----- diff --git a/test/certs/delta-crl-as-complete-delta.pem b/test/certs/delta-crl-as-complete-delta.pem deleted file mode 100644 index 301a6b009a..0000000000 --- a/test/certs/delta-crl-as-complete-delta.pem +++ /dev/null @@ -1,12 +0,0 @@ ------BEGIN X509 CRL----- -MIIBsjCBmwIBATANBgkqhkiG9w0BAQsFADAoMSYwJAYDVQQDDB1EZWx0YSBDUkwg -YXMgQ29tcGxldGUgVGVzdCBDQRcNMjYwNDMwMTQ0NjAzWhcNMzYwNDI3MTQ0NjAz -WqA/MD0wHwYDVR0jBBgwFoAUwiHYCQwhRoGNowcMA4QEC/fdfMQwDQYDVR0bAQH/ -BAMCAQEwCwYDVR0UBAQCAiAAMA0GCSqGSIb3DQEBCwUAA4IBAQADs08Ab6TRWijd -dOsW3wBCzWVi/GYlyPhMZjcPTDuM939rpL7yOONM7OIgekP3BYM7g4Dvp6Q4Caul -yZTtJ87dxqP56e11Q7h5eVcBBWxc1dM7FwMffqXXSEApuKdkRqKNAqtXugkgozdM -YBNIuSP+gyLNt4vrxtQS26pBMYJnbCf7ye5dyJFK3G58o97VknNMrYewPrzj6LVG -abS3eJnDaGtiGkQ16pOsKNRTlQYlXBk/9NMq8N8ntsm2ri3LJ/JQHRIHxxSsKl+f -ZgKmOa160pz+xWNq7edIM0RpwGjLVViE7F22y2JH/VJcqXimsl506QykD9COCzH6 -Lnv//55C ------END X509 CRL----- diff --git a/test/certs/delta-crl-as-complete-leaf.pem b/test/certs/delta-crl-as-complete-leaf.pem deleted file mode 100644 index c8ffebdb64..0000000000 --- a/test/certs/delta-crl-as-complete-leaf.pem +++ /dev/null @@ -1,20 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIDQDCCAiigAwIBAgIUXolrPqGDnGH9gUx2N5WFjfUkXHgwDQYJKoZIhvcNAQEL -BQAwKDEmMCQGA1UEAwwdRGVsdGEgQ1JMIGFzIENvbXBsZXRlIFRlc3QgQ0EwHhcN -MjYwNDMwMTQ0NjAzWhcNMzYwNDI3MTQ0NjAzWjAqMSgwJgYDVQQDDB9EZWx0YSBD -UkwgYXMgQ29tcGxldGUgVGVzdCBMZWFmMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8A -MIIBCgKCAQEA43iL7Otyb0SaPVDmOVBs39LnH9vlO2sV+ZPqV4o1a/JhCOzokMxg -NuPqCamMEufKctaKE8q/LKKEpu3QAG7H1vlsu2qfQLojFuHNKDnHM7RbsRNp9azE -DWpBWs0mXL96LUJzseioIIqFdSH9HkcTyrKXvr8iqaOUC96Vu9F03Ws59FmaTwK6 -JmKThfrIY2edSRyEO6tmVTh0XLW0PyNbSM/2eOKmh92RCbhKDjgCeNhPuJ0WRDAX -zNF+cgRO48epsl6ec03DdBSCFcwc5qL+TkzXjXIQbXhIsvl/OKNG0BUXDeYqH7ln -wEO6d556CF6wJlCd0DqzSzPsoVIo96asKwIDAQABo2AwXjAMBgNVHRMBAf8EAjAA -MA4GA1UdDwEB/wQEAwIHgDAdBgNVHQ4EFgQUFPI2A7WhMsPK15SsH1W+CiEKqA0w -HwYDVR0jBBgwFoAUwiHYCQwhRoGNowcMA4QEC/fdfMQwDQYJKoZIhvcNAQELBQAD -ggEBAGX7FpwNoq62mhlJbksgAJcaw5ci2m1CGFgNfh+f6pdA0mG3ywyM7eEZcr6h -GFslaDsG8m2O0l737Xs7mBpyq0ruxjpvk62VdgwTUkeZzz8gnuBIWg/+zrWyYCI7 -uDX4wKVMma9MF52YUHhNTdxvV0EE4wuUcYMAlWrCCzxkf4eNxyDJGBXli04xSpSj -cG9SsDRyjQKc9lFFqrQ9P/DVL4CDUSovE/2DWdZmS3RmsHjhNdGjpWtpoEsxBHdQ -5lyeGDp0fBf4RNWRsdr8RUsSiDFUproRibZ9/3uzH5yAfivZmWlVRUX/eyyjCrZD -VuW2H/npgPe+QSkwlUXYsZ1vqiM= ------END CERTIFICATE----- diff --git a/test/certs/echdir/ech-b511.pem b/test/certs/echdir/ech-b511.pem deleted file mode 100644 index 2c655740ae..0000000000 --- a/test/certs/echdir/ech-b511.pem +++ /dev/null @@ -1,14 +0,0 @@ ------BEGIN PRIVATE KEY----- -MC4CAQAwBQYDK2VuBCIEIFjwv041TaYyaBLXwW5i3qdRjVfp2jgDt0rjTNW+CEJw ------END PRIVATE KEY----- ------BEGIN ECHCONFIG----- -Af3+DQA6RAAgACBaXlSMpzC72pccyR1s4ggNF6ZcoNMEatXUKlHUMtmebwAEAAIAAwALZXhhbXBs -ZS5jb20AAP4NAEOFACAAIHoLrQGbajMQMAqajIXtnRjjHkAM4xy66Zo7OvfLJnwcAAQAAgADAA5l -eGFtcGxlNTEyLmNvbQAGAAAAAv///g0AOt0AIAAgPj//c1cJ3yIi34Dvp8imA8ItbgXlMS9tOm+c -K79t7U0ABAABAAEAC2V4YW1wbGUuY29tAAD+DQA6rQAgACDVBjfG9x8BtxGxkTZQdZv5cE4k2f2D -QW3MyiVzRAxNSQAEAAIAAgALZXhhbXBsZS5jb20AAP4NADppACAAIKZcX2LKexw85KRYIchUmgZp -HbFTXq15r7qdOgljpTtjAAQAAgADAAtleGFtcGxlLmNvbQAA/g0AukQAIAAgWl5UjKcwu9qXHMkd -bOIIDRemXKDTBGrV1CpR1DLZnm8ABAACAAMAC2V4YW1wbGUuY29tAIAAAAB8AAAAAAAAAAAAAAAA -AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA -AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA== ------END ECHCONFIG----- diff --git a/test/certs/echdir/ech-b512.pem b/test/certs/echdir/ech-b512.pem deleted file mode 100644 index fbb2ee84a4..0000000000 --- a/test/certs/echdir/ech-b512.pem +++ /dev/null @@ -1,14 +0,0 @@ ------BEGIN PRIVATE KEY----- -MC4CAQAwBQYDK2VuBCIEIFjwv041TaYyaBLXwW5i3qdRjVfp2jgDt0rjTNW+CEJw ------END PRIVATE KEY----- ------BEGIN ECHCONFIG----- -Af7+DQA6RAAgACBaXlSMpzC72pccyR1s4ggNF6ZcoNMEatXUKlHUMtmebwAEAAIAAwALZXhhbXBs -ZS5jb20AAP4NAEOFACAAIHoLrQGbajMQMAqajIXtnRjjHkAM4xy66Zo7OvfLJnwcAAQAAgADAA5l -eGFtcGxlNTEyLmNvbQAGAAAAAv///g0AOt0AIAAgPj//c1cJ3yIi34Dvp8imA8ItbgXlMS9tOm+c -K79t7U0ABAABAAEAC2V4YW1wbGUuY29tAAD+DQA6rQAgACDVBjfG9x8BtxGxkTZQdZv5cE4k2f2D -QW3MyiVzRAxNSQAEAAIAAgALZXhhbXBsZS5jb20AAP4NADppACAAIKZcX2LKexw85KRYIchUmgZp -HbFTXq15r7qdOgljpTtjAAQAAgADAAtleGFtcGxlLmNvbQAA/g0Au0QAIAAgWl5UjKcwu9qXHMkd -bOIIDRemXKDTBGrV1CpR1DLZnm8ABAACAAMAC2V4YW1wbGUuY29tAIEAAAB9AAAAAAAAAAAAAAAA -AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA -AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA= ------END ECHCONFIG----- diff --git a/test/certs/echdir/ech-b513.pem b/test/certs/echdir/ech-b513.pem deleted file mode 100644 index 1c1fa9acf7..0000000000 --- a/test/certs/echdir/ech-b513.pem +++ /dev/null @@ -1,14 +0,0 @@ ------BEGIN PRIVATE KEY----- -MC4CAQAwBQYDK2VuBCIEIFjwv041TaYyaBLXwW5i3qdRjVfp2jgDt0rjTNW+CEJw ------END PRIVATE KEY----- ------BEGIN ECHCONFIG----- -Af/+DQA6RAAgACBaXlSMpzC72pccyR1s4ggNF6ZcoNMEatXUKlHUMtmebwAEAAIAAwALZXhhbXBs -ZS5jb20AAP4NAEOFACAAIHoLrQGbajMQMAqajIXtnRjjHkAM4xy66Zo7OvfLJnwcAAQAAgADAA5l -eGFtcGxlNTEyLmNvbQAGAAAAAv///g0AOt0AIAAgPj//c1cJ3yIi34Dvp8imA8ItbgXlMS9tOm+c -K79t7U0ABAABAAEAC2V4YW1wbGUuY29tAAD+DQA6rQAgACDVBjfG9x8BtxGxkTZQdZv5cE4k2f2D -QW3MyiVzRAxNSQAEAAIAAgALZXhhbXBsZS5jb20AAP4NADppACAAIKZcX2LKexw85KRYIchUmgZp -HbFTXq15r7qdOgljpTtjAAQAAgADAAtleGFtcGxlLmNvbQAA/g0AvEQAIAAgWl5UjKcwu9qXHMkd -bOIIDRemXKDTBGrV1CpR1DLZnm8ABAACAAMAC2V4YW1wbGUuY29tAIIAAAB+AAAAAAAAAAAAAAAA -AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA -AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA ------END ECHCONFIG----- diff --git a/test/certs/echdir/ech-big.pem b/test/certs/echdir/ech-big.pem deleted file mode 100644 index 99c9c67bde..0000000000 --- a/test/certs/echdir/ech-big.pem +++ /dev/null @@ -1,25 +0,0 @@ ------BEGIN ECHCONFIG----- -BNj+DQA6uwAgACBix2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQALZXhhbXBs -ZS5jb20AAP4NADq7ACAAIGLHYHvyxf4RCERvEyykM5zxnfFVLlpClg/QLGlzYBY8AAQAAQABAAtl -eGFtcGxlLmNvbQAA/g0AOrsAIAAgYsdge/LF/hEIRG8TLKQznPGd8VUuWkKWD9AsaXNgFjwABAAB -AAEAC2V4YW1wbGUuY29tAAD+DQA6uwAgACBix2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP0Cxpc2AW -PAAEAAEAAQALZXhhbXBsZS5jb20AAP4NADq7ACAAIGLHYHvyxf4RCERvEyykM5zxnfFVLlpClg/Q -LGlzYBY8AAQAAQABAAtleGFtcGxlLmNvbQAA/g0AOrsAIAAgYsdge/LF/hEIRG8TLKQznPGd8VUu -WkKWD9AsaXNgFjwABAABAAEAC2V4YW1wbGUuY29tAAD+DQA6uwAgACBix2B78sX+EQhEbxMspDOc -8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQALZXhhbXBsZS5jb20AAP4NADq7ACAAIGLHYHvyxf4RCERv -EyykM5zxnfFVLlpClg/QLGlzYBY8AAQAAQABAAtleGFtcGxlLmNvbQAA/g0AOrsAIAAgYsdge/LF -/hEIRG8TLKQznPGd8VUuWkKWD9AsaXNgFjwABAABAAEAC2V4YW1wbGUuY29tAAD+DQA6uwAgACBi -x2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQALZXhhbXBsZS5jb20AAP4NADq7 -ACAAIGLHYHvyxf4RCERvEyykM5zxnfFVLlpClg/QLGlzYBY8AAQAAQABAAtleGFtcGxlLmNvbQAA -/g0AOrsAIAAgYsdge/LF/hEIRG8TLKQznPGd8VUuWkKWD9AsaXNgFjwABAABAAEAC2V4YW1wbGUu -Y29tAAD+DQA6uwAgACBix2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQALZXhh -bXBsZS5jb20AAP4NADq7ACAAIGLHYHvyxf4RCERvEyykM5zxnfFVLlpClg/QLGlzYBY8AAQAAQAB -AAtleGFtcGxlLmNvbQAA/g0AOrsAIAAgYsdge/LF/hEIRG8TLKQznPGd8VUuWkKWD9AsaXNgFjwA -BAABAAEAC2V4YW1wbGUuY29tAAD+DQA6uwAgACBix2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP0Cxp -c2AWPAAEAAEAAQALZXhhbXBsZS5jb20AAP4NADq7ACAAIGLHYHvyxf4RCERvEyykM5zxnfFVLlpC -lg/QLGlzYBY8AAQAAQABAAtleGFtcGxlLmNvbQAA/g0AOrsAIAAgYsdge/LF/hEIRG8TLKQznPGd -8VUuWkKWD9AsaXNgFjwABAABAAEAC2V4YW1wbGUuY29tAAD+DQA6uwAgACBix2B78sX+EQhEbxMs -pDOc8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQALZXhhbXBsZS5jb20AAP4NADq7ACAAIGLHYHvyxf4R -CERvEyykM5zxnfFVLlpClg/QLGlzYBY8AAQAAQABAAtleGFtcGxlLmNvbQAA ------END ECHCONFIG----- - diff --git a/test/certs/echdir/ech-eg.pem b/test/certs/echdir/ech-eg.pem deleted file mode 100644 index 4d37f5b17d..0000000000 --- a/test/certs/echdir/ech-eg.pem +++ /dev/null @@ -1,7 +0,0 @@ ------BEGIN PRIVATE KEY----- -MC4CAQAwBQYDK2VuBCIEIKBC3rocwIF5tGY+/TaYQrCxY+ULsch94ja9DojkcvlT ------END PRIVATE KEY----- ------BEGIN ECHCONFIG----- -ADn+DQA1agAgACBtuySC1pphjFlGYKTaSm2KWNg7GQVRS8uAYvLTm5QlGwAEAAEA -AQAGZWcuY29tAAA= ------END ECHCONFIG----- diff --git a/test/certs/echdir/ech-giant.pem b/test/certs/echdir/ech-giant.pem deleted file mode 100644 index d0e5a46c41..0000000000 --- a/test/certs/echdir/ech-giant.pem +++ /dev/null @@ -1,37 +0,0 @@ ------BEGIN ECHCONFIG----- -B8D+DQA6uwAgACBix2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQALZXhhbXBs -ZS5jb20AAP4NADq7ACAAIGLHYHvyxf4RCERvEyykM5zxnfFVLlpClg/QLGlzYBY8AAQAAQABAAtl -eGFtcGxlLmNvbQAA/g0AOrsAIAAgYsdge/LF/hEIRG8TLKQznPGd8VUuWkKWD9AsaXNgFjwABAAB -AAEAC2V4YW1wbGUuY29tAAD+DQA6uwAgACBix2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP0Cxpc2AW -PAAEAAEAAQALZXhhbXBsZS5jb20AAP4NADq7ACAAIGLHYHvyxf4RCERvEyykM5zxnfFVLlpClg/Q -LGlzYBY8AAQAAQABAAtleGFtcGxlLmNvbQAA/g0AOrsAIAAgYsdge/LF/hEIRG8TLKQznPGd8VUu -WkKWD9AsaXNgFjwABAABAAEAC2V4YW1wbGUuY29tAAD+DQA6uwAgACBix2B78sX+EQhEbxMspDOc -8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQALZXhhbXBsZS5jb20AAP4NADq7ACAAIGLHYHvyxf4RCERv -EyykM5zxnfFVLlpClg/QLGlzYBY8AAQAAQABAAtleGFtcGxlLmNvbQAA/g0AOrsAIAAgYsdge/LF -/hEIRG8TLKQznPGd8VUuWkKWD9AsaXNgFjwABAABAAEAC2V4YW1wbGUuY29tAAD+DQA6uwAgACBi -x2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQALZXhhbXBsZS5jb20AAP4NADq7 -ACAAIGLHYHvyxf4RCERvEyykM5zxnfFVLlpClg/QLGlzYBY8AAQAAQABAAtleGFtcGxlLmNvbQAA -/g0AOrsAIAAgYsdge/LF/hEIRG8TLKQznPGd8VUuWkKWD9AsaXNgFjwABAABAAEAC2V4YW1wbGUu -Y29tAAD+DQA6uwAgACBix2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQALZXhh -bXBsZS5jb20AAP4NADq7ACAAIGLHYHvyxf4RCERvEyykM5zxnfFVLlpClg/QLGlzYBY8AAQAAQAB -AAtleGFtcGxlLmNvbQAA/g0AOrsAIAAgYsdge/LF/hEIRG8TLKQznPGd8VUuWkKWD9AsaXNgFjwA -BAABAAEAC2V4YW1wbGUuY29tAAD+DQA6uwAgACBix2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP0Cxp -c2AWPAAEAAEAAQALZXhhbXBsZS5jb20AAP4NADq7ACAAIGLHYHvyxf4RCERvEyykM5zxnfFVLlpC -lg/QLGlzYBY8AAQAAQABAAtleGFtcGxlLmNvbQAA/g0AOrsAIAAgYsdge/LF/hEIRG8TLKQznPGd -8VUuWkKWD9AsaXNgFjwABAABAAEAC2V4YW1wbGUuY29tAAD+DQA6uwAgACBix2B78sX+EQhEbxMs -pDOc8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQALZXhhbXBsZS5jb20AAP4NADq7ACAAIGLHYHvyxf4R -CERvEyykM5zxnfFVLlpClg/QLGlzYBY8AAQAAQABAAtleGFtcGxlLmNvbQAA/g0AOrsAIAAgYsdg -e/LF/hEIRG8TLKQznPGd8VUuWkKWD9AsaXNgFjwABAABAAEAC2V4YW1wbGUuY29tAAD+DQA6uwAg -ACBix2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQALZXhhbXBsZS5jb20AAP4N -ADq7ACAAIGLHYHvyxf4RCERvEyykM5zxnfFVLlpClg/QLGlzYBY8AAQAAQABAAtleGFtcGxlLmNv -bQAA/g0AOrsAIAAgYsdge/LF/hEIRG8TLKQznPGd8VUuWkKWD9AsaXNgFjwABAABAAEAC2V4YW1w -bGUuY29tAAD+DQA6uwAgACBix2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQAL -ZXhhbXBsZS5jb20AAP4NADq7ACAAIGLHYHvyxf4RCERvEyykM5zxnfFVLlpClg/QLGlzYBY8AAQA -AQABAAtleGFtcGxlLmNvbQAA/g0AOrsAIAAgYsdge/LF/hEIRG8TLKQznPGd8VUuWkKWD9AsaXNg -FjwABAABAAEAC2V4YW1wbGUuY29tAAD+DQA6uwAgACBix2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP -0Cxpc2AWPAAEAAEAAQALZXhhbXBsZS5jb20AAP4NADq7ACAAIGLHYHvyxf4RCERvEyykM5zxnfFV -LlpClg/QLGlzYBY8AAQAAQABAAtleGFtcGxlLmNvbQAA/g0AOrsAIAAgYsdge/LF/hEIRG8TLKQz -nPGd8VUuWkKWD9AsaXNgFjwABAABAAEAC2V4YW1wbGUuY29tAAD+DQA6uwAgACBix2B78sX+EQhE -bxMspDOc8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQALZXhhbXBsZS5jb20AAP4NADq7ACAAIGLHYHvy -xf4RCERvEyykM5zxnfFVLlpClg/QLGlzYBY8AAQAAQABAAtleGFtcGxlLmNvbQAA ------END ECHCONFIG-----` diff --git a/test/certs/echdir/ech-mid.pem b/test/certs/echdir/ech-mid.pem deleted file mode 100644 index 7c5aa86e14..0000000000 --- a/test/certs/echdir/ech-mid.pem +++ /dev/null @@ -1,11 +0,0 @@ ------BEGIN ECHCONFIG----- -AfD+DQA6uwAgACBix2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQALZXhhbXBs -ZS5jb20AAP4NADq7ACAAIGLHYHvyxf4RCERvEyykM5zxnfFVLlpClg/QLGlzYBY8AAQAAQABAAtl -eGFtcGxlLmNvbQAA/g0AOrsAIAAgYsdge/LF/hEIRG8TLKQznPGd8VUuWkKWD9AsaXNgFjwABAAB -AAEAC2V4YW1wbGUuY29tAAD+DQA6uwAgACBix2B78sX+EQhEbxMspDOc8Z3xVS5aQpYP0Cxpc2AW -PAAEAAEAAQALZXhhbXBsZS5jb20AAP4NADq7ACAAIGLHYHvyxf4RCERvEyykM5zxnfFVLlpClg/Q -LGlzYBY8AAQAAQABAAtleGFtcGxlLmNvbQAA/g0AOrsAIAAgYsdge/LF/hEIRG8TLKQznPGd8VUu -WkKWD9AsaXNgFjwABAABAAEAC2V4YW1wbGUuY29tAAD+DQA6uwAgACBix2B78sX+EQhEbxMspDOc -8Z3xVS5aQpYP0Cxpc2AWPAAEAAEAAQALZXhhbXBsZS5jb20AAP4NADq7ACAAIGLHYHvyxf4RCERv -EyykM5zxnfFVLlpClg/QLGlzYBY8AAQAAQABAAtleGFtcGxlLmNvbQAA ------END ECHCONFIG----- diff --git a/test/certs/echdir/ech-rsa.pem b/test/certs/echdir/ech-rsa.pem deleted file mode 100644 index 17b23cf04f..0000000000 --- a/test/certs/echdir/ech-rsa.pem +++ /dev/null @@ -1,14 +0,0 @@ ------BEGIN PRIVATE KEY----- -MIIBVQIBADANBgkqhkiG9w0BAQEFAASCAT8wggE7AgEAAkEApeb9fP5SDxyOQZQT -qGg2QeE0ypxY6Th33aDkRCRVB69rDMSA1Thfeyk65IfaPaA3bC4hsqAIBgslcFfk -1/i8KQIDAQABAkAsH3EPizwb1MZo3o8T3ROBFfpKYKas8F3Azgenr9oFfs5kPgya -VDdtZu+UweG5nTo+fZG5ZFmcwWXJTLtiUfABAiEAz2gvTuc0lPTQi3t6RFB5nGCt -h75Ofx/ceusHa2a36QECIQDMxXJQnuWY+bH/wSfPY/ySltQ6U2cy0LHQ37FIfSFr -KQIgUo++hUI0BDeP7HYyrY77WeyCJ07yIFimg6ebRH2XKAECIQCSavhTd1q6qIhD -VMzveRInixvTXMGkzx7mOJzeNUMJCQIhAJjjVdRjUpWPMquRDCddmwegh88ptsFX -T/Ygm1OubAyM ------END PRIVATE KEY----- ------BEGIN ECHCONFIG----- -AD7+DQA6bAAgACCY7B0f/3KvHIFdoqFaObdU8YYU+MdBf4vzbLhAAL2QCwAEAAEA -AQALZXhhbXBsZS5jb20AAA== ------END ECHCONFIG----- diff --git a/test/certs/echdir/echconfig-10.pem b/test/certs/echdir/echconfig-10.pem deleted file mode 100644 index d1d218f9cd..0000000000 --- a/test/certs/echdir/echconfig-10.pem +++ /dev/null @@ -1,6 +0,0 @@ ------BEGIN PRIVATE KEY----- -MC4CAQAwBQYDK2VuBCIEIPiqiukxstIS9ViT4zWlewgPbjN4XVQ1XrcYgxwE6sl1 ------END PRIVATE KEY----- ------BEGIN ECHCONFIG----- -AED+CgA8vwAgACCB9YyilgR2NMLVPOsESVceIrfGpXThGIUMIwGfGClmSgAEAAEAAQAAAAtleGFtcGxlLmNvbQAA ------END ECHCONFIG----- diff --git a/test/certs/echdir/echconfig-256.pem b/test/certs/echdir/echconfig-256.pem deleted file mode 100644 index 44228fa929..0000000000 --- a/test/certs/echdir/echconfig-256.pem +++ /dev/null @@ -1,8 +0,0 @@ ------BEGIN PRIVATE KEY----- -MIGHAgEAMBMGByqGSM49AgEGCCqGSM49AwEHBG0wawIBAQQgfVyqIGiyInH7KDB3 -szOuOFYP41zV2gpA8wESUjpcqrChRANCAAQaLs1qXa+t31TtQeD6hXwWoltwJgL1 -zt9kMsrj1HMScUQ8yIpNt+KUjzuMLbJxG9SpuZqfFW/agXJlyQEmatGE ------END PRIVATE KEY----- ------BEGIN ECHCONFIG----- -AGH+CgBd0QAQAEEEGi7Nal2vrd9U7UHg+oV8FqJbcCYC9c7fZDLK49RzEnFEPMiKTbfilI87jC2ycRvUqbmanxVv2oFyZckBJmrRhAAEAAEAAQAAAAtleGFtcGxlLmNvbQAA ------END ECHCONFIG----- diff --git a/test/certs/echdir/echconfig_bad_fuzz1.pem b/test/certs/echdir/echconfig_bad_fuzz1.pem deleted file mode 100644 index 5174028c32..0000000000 --- a/test/certs/echdir/echconfig_bad_fuzz1.pem +++ /dev/null @@ -1 +0,0 @@ -AD7+DQA6uAAgACAogff+HZbirYdQCfXI01GBPP8AEKYyK/D/0DoeXD84fgAQAAEAAQgLZXhhbUNwbGUuYwYAAAAAQwA= diff --git a/test/certs/echdir/echmaxname.pem b/test/certs/echdir/echmaxname.pem deleted file mode 100644 index c1147e1cde..0000000000 --- a/test/certs/echdir/echmaxname.pem +++ /dev/null @@ -1,7 +0,0 @@ ------BEGIN PRIVATE KEY----- -MC4CAQAwBQYDK2VuBCIEILCwRG3jPpLC4JRINol54Jo8bvua3e1EV3EDbepDCmpi ------END PRIVATE KEY----- ------BEGIN ECHCONFIG----- -AD7+DQA6IwAgACDT+hqR+Atl9LejS6nJrr9oDspGvwWTGOW3WJHdJy+OSQAEAAEA -ASALZXhhbXBsZS5jb20AAA== ------END ECHCONFIG----- diff --git a/test/certs/echdir/echwithexts.pem b/test/certs/echdir/echwithexts.pem deleted file mode 100644 index 921bb0717f..0000000000 --- a/test/certs/echdir/echwithexts.pem +++ /dev/null @@ -1,6 +0,0 @@ ------BEGIN PRIVATE KEY----- -MC4CAQAwBQYDK2VuBCIEIOAOgc22M+RJc5QZdY/ndZSME8akKHon13JITeB899pF ------END PRIVATE KEY----- ------BEGIN ECHCONFIG----- -Ah3+DQIZAAAgACAgiyA/dGsDu4MO8Qn4xriSBhRxhNmfQ5jtBGJg1o5VbQAEAAEAAQALZXhhbXBsZS5jb20B3//KAAD/ywAMaGVsbG8gd29ybGQK/8wBx4lQTkcNChoKAAAADUlIRFIAAAAKAAAABggDAAAAzS7/9AAAAARnQU1BAACxjwv8YQUAAAAgY0hSTQAAeiYAAICEAAD6AAAAgOgAAHUwAADqYAAAOpgAABdwnLpRPAAAAGxQTFRFAwMFAwQHAgMFAgEBDQgIDwkKDQcIEAkJAAABAgICAAECBgUJBgQEAQICAAEBAAAABgUFAgIDCQYHCgcIBgcMAgIEAQEBAQECCAUGBAMDBQMDCAcMBAQHDQgJAgMDBwcMAQIDBQYIAQED////go9xWgAAAAFiS0dEIypibDoAAAAJcEhZcwAAASwAAAEsAHOI6VIAAAAHdElNRQfnBAQMGAw/wJ0bAAAAQ0lEQVQI1wXBiQJAIBQEwJUOuVbo5Qjx/x9pBqhUrY11toFvO9MPI92EMC9rpKRtx6FFndknIS7ejE8hCRFJ4c2f8AdkNAPhOzEsxgAAACV0RVh0ZGF0ZTpjcmVhdGUAMjAyMy0wNC0wNFQxMjoxMTo1OSswMDowMAbaIaMAAAAldEVYdGRhdGU6bW9kaWZ5ADIwMjMtMDQtMDRUMTI6MTE6NTkrMDA6MDB3h5kfAAAAAElFTkSuQmCC ------END ECHCONFIG----- diff --git a/test/certs/echserver.key b/test/certs/echserver.key deleted file mode 100644 index 372878ce57..0000000000 --- a/test/certs/echserver.key +++ /dev/null @@ -1,28 +0,0 @@ ------BEGIN PRIVATE KEY----- -MIIEvAIBADANBgkqhkiG9w0BAQEFAASCBKYwggSiAgEAAoIBAQCJHNs4e27KjdYU -8IgiT539WbEl16Eve6tu1UFpGdkqsHH8+yceoFkMWSdpr+Sh3PYDRk/Ek0qB33uK -y3FKlIejtolxVhBybtja5zYMmVXnRHsB/qe7FgyM/lv0xtO1nfSGFkVZVz1+xWPr -aslJN3U4HPaaL4SGghw5KIRD8FPx174v8FDOBeVhn6pzTK/xpTeqXLvAAxgPhF+Q -HOQ0pTXrOHbaiK4l+8JfVm+0fCJjMnT20mmGuTNjvdWZ4XIgPPYkEQrf1CpdONcU -kiiFcpcYtbVS0YyC91qqJLKFv51eki9STwUQISn5jLWIRQlXkBXhK6aGlkLWnov/ -kqqUWEQTAgMBAAECggEAAah0LDAt7EwfyRwJgWS2E+C4SC1d2R2lOo9gnZ0+54m/ -rx/4XqHwwbn4RIpoeN6bqPl6MHXZgk2KCGkiYxT9uOiVq+WvCDs36xm9qRRXmhbV -Z/ZE3/nJyBCxWvnmiH0y/kYZq5Vm/Hf1l9ywN27wv292OfIWJ6w+HCDVzJ6E3VlK -fuzBFhZmnBjul6Nlo76blNXwn5loWYomkg6nVWzrTjYWosGd0aKpZJR948nWpuEj -fkevLqMMfSuB+cXQ+zB4lttqB5dphFxbNv5gHOd1rllzHFdhK+/7e7ktGYmpQtuH -WRKPD1y173ek5FtvTxtcrL2rST+hoSDWcCQCws/70QKBgQC5QGlldraTs0JXhoH9 -6X+V1mvsAWCItq7JhUvFHFtAxHuYacrlnsJRxv8aRS8AhuNYTtThJQcWzFL2UU7W -CdiB0VZr7phPNOVYsa95V8a8A1CHllfdTzxw1TyiOJ0sdeU7irWo3vnTDxftfySP -lkdPNbItO1RXqeIR6mJf+rVGowKBgQC9egaDDdM2YsMtl61fIRoPMPdJB3fGcL0A -FwUAtGQ1twETykzcUCeAqx0yx7zCAyPeA9WmpHzuz/LR8uA3TP/nDcLlCaQowfeR -VPdS3Q1iAnSyaCsF1THQPvhFsYMXbIn/svSSpddLOrP6ltSr+PORLOXXUmQJnffk -hxKaxK6T0QKBgFzyVm9UGtMMk/K6SCqPpzYUuV1Wa4rsrdHqkVO6oIZkjuav3d9L -wo+pWoFhyO1owFSkaOb13xKvPcjcjsOReRHZaJUKx1ymW5Qewr4NLmdS+mqtIjSl -9tteAegao7GVDYjMVcz+4zXkUssUidGJQwoZFObg57Z8RDNc+DLT5XQlAoGAYaO8 -L1S0ftYuFhSPdvIr56AoDi4W/t+hxaYXIeHTsgp4N6aMLQvxD1EeXsim8KOFnCcF -tjYVW0s1qhMqj9TSGlLxF+379jTeSroqKT1YZCU31afwY7UVUmbgsalkEHISOv4R -InDrnQzHKl8HgQdtHGayml8OxhXtZIpmf/LSs8ECgYBrFbKl8ylhlzw5rC8DuP8n -hzKLOKzipKmHLn4eDBEFyLTyoyYrqx/nxLi3kSIyNP4fJ9vHOXgdjdrp9xRMcFEx -IA2sdywI5VuymxktP8OlORa0NK4eFZXkDNsQlkathYiKqCwGjUWdGk5+Ry5qO/UC -9ua9adjNa108aBzWLYZFCw== ------END PRIVATE KEY----- diff --git a/test/certs/echserver.pem b/test/certs/echserver.pem deleted file mode 100644 index 11e0617e88..0000000000 --- a/test/certs/echserver.pem +++ /dev/null @@ -1,80 +0,0 @@ -Certificate: - Data: - Version: 3 (0x2) - Serial Number: - 18:45:8f:30:1d:fe:dc:22:9d:95:40:8c:e5:36:f9:38:0d:d5:58:a0 - Signature Algorithm: sha256WithRSAEncryption - Issuer: CN=Root CA - Validity - Not Before: Oct 6 18:36:12 2023 GMT - Not After : Sep 12 18:36:12 2123 GMT - Subject: CN=server.example - Subject Public Key Info: - Public Key Algorithm: rsaEncryption - Public-Key: (2048 bit) - Modulus: - 00:89:1c:db:38:7b:6e:ca:8d:d6:14:f0:88:22:4f: - 9d:fd:59:b1:25:d7:a1:2f:7b:ab:6e:d5:41:69:19: - d9:2a:b0:71:fc:fb:27:1e:a0:59:0c:59:27:69:af: - e4:a1:dc:f6:03:46:4f:c4:93:4a:81:df:7b:8a:cb: - 71:4a:94:87:a3:b6:89:71:56:10:72:6e:d8:da:e7: - 36:0c:99:55:e7:44:7b:01:fe:a7:bb:16:0c:8c:fe: - 5b:f4:c6:d3:b5:9d:f4:86:16:45:59:57:3d:7e:c5: - 63:eb:6a:c9:49:37:75:38:1c:f6:9a:2f:84:86:82: - 1c:39:28:84:43:f0:53:f1:d7:be:2f:f0:50:ce:05: - e5:61:9f:aa:73:4c:af:f1:a5:37:aa:5c:bb:c0:03: - 18:0f:84:5f:90:1c:e4:34:a5:35:eb:38:76:da:88: - ae:25:fb:c2:5f:56:6f:b4:7c:22:63:32:74:f6:d2: - 69:86:b9:33:63:bd:d5:99:e1:72:20:3c:f6:24:11: - 0a:df:d4:2a:5d:38:d7:14:92:28:85:72:97:18:b5: - b5:52:d1:8c:82:f7:5a:aa:24:b2:85:bf:9d:5e:92: - 2f:52:4f:05:10:21:29:f9:8c:b5:88:45:09:57:90: - 15:e1:2b:a6:86:96:42:d6:9e:8b:ff:92:aa:94:58: - 44:13 - Exponent: 65537 (0x10001) - X509v3 extensions: - X509v3 Basic Constraints: - CA:FALSE - X509v3 Subject Key Identifier: - 8C:E0:38:04:70:7E:B4:CB:1F:BF:AA:E6:67:42:74:63:46:88:58:74 - X509v3 Authority Key Identifier: - 70:7F:2E:AE:83:68:59:98:04:23:2A:CD:EB:3E:17:CD:24:DD:01:49 - X509v3 Subject Alternative Name: - DNS:*.server.example, DNS:server.example - Signature Algorithm: sha256WithRSAEncryption - Signature Value: - 9b:fe:bc:b1:40:d4:08:91:f6:1f:b4:0f:8c:50:ac:49:36:6f: - 27:93:e8:94:13:bc:fe:1a:2a:cf:93:98:13:b3:b4:85:a5:62: - 4d:58:8f:da:cd:f7:1b:c3:1f:42:ba:2a:89:45:11:33:49:86: - 2c:3a:0a:99:17:4f:0c:f1:1e:35:31:2c:69:f9:15:d5:37:54: - cc:9e:e3:67:9f:d5:6e:ad:b1:26:60:df:aa:84:63:da:a7:31: - c9:69:a0:d8:c2:96:d3:82:b4:99:70:8c:3c:92:a4:c0:f0:7c: - 3f:04:d3:29:4f:6c:c5:fd:39:12:95:65:7f:37:fb:52:5b:12: - 99:d6:d7:b5:ba:44:6e:36:ec:5d:f2:5d:d4:aa:2d:8a:46:ce: - 29:66:c1:ed:36:13:f2:f3:ae:92:4a:97:db:99:ed:8f:4e:4e: - ed:73:1b:fa:3e:64:63:40:5c:c2:03:76:2c:dc:58:01:3f:17: - d0:ae:a6:b2:64:85:47:ba:7d:5a:36:53:e4:90:00:8e:f5:17: - a5:ff:a3:81:ee:ed:25:ca:10:76:75:2d:65:ff:f8:b1:8c:3c: - a3:ff:81:12:72:c7:bc:b5:17:06:d8:c6:13:97:cb:8e:58:51: - 2a:a4:be:91:59:40:4b:07:8d:69:2f:92:ee:ea:9c:bf:eb:42: - b7:62:b8:e3 ------BEGIN CERTIFICATE----- -MIIDNTCCAh2gAwIBAgIUGEWPMB3+3CKdlUCM5Tb5OA3VWKAwDQYJKoZIhvcNAQEL -BQAwEjEQMA4GA1UEAwwHUm9vdCBDQTAgFw0yMzEwMDYxODM2MTJaGA8yMTIzMDkx -MjE4MzYxMlowGTEXMBUGA1UEAwwOc2VydmVyLmV4YW1wbGUwggEiMA0GCSqGSIb3 -DQEBAQUAA4IBDwAwggEKAoIBAQCJHNs4e27KjdYU8IgiT539WbEl16Eve6tu1UFp -GdkqsHH8+yceoFkMWSdpr+Sh3PYDRk/Ek0qB33uKy3FKlIejtolxVhBybtja5zYM -mVXnRHsB/qe7FgyM/lv0xtO1nfSGFkVZVz1+xWPraslJN3U4HPaaL4SGghw5KIRD -8FPx174v8FDOBeVhn6pzTK/xpTeqXLvAAxgPhF+QHOQ0pTXrOHbaiK4l+8JfVm+0 -fCJjMnT20mmGuTNjvdWZ4XIgPPYkEQrf1CpdONcUkiiFcpcYtbVS0YyC91qqJLKF -v51eki9STwUQISn5jLWIRQlXkBXhK6aGlkLWnov/kqqUWEQTAgMBAAGjejB4MAkG -A1UdEwQCMAAwHQYDVR0OBBYEFIzgOARwfrTLH7+q5mdCdGNGiFh0MB8GA1UdIwQY -MBaAFHB/Lq6DaFmYBCMqzes+F80k3QFJMCsGA1UdEQQkMCKCECouc2VydmVyLmV4 -YW1wbGWCDnNlcnZlci5leGFtcGxlMA0GCSqGSIb3DQEBCwUAA4IBAQCb/ryxQNQI -kfYftA+MUKxJNm8nk+iUE7z+GirPk5gTs7SFpWJNWI/azfcbwx9CuiqJRREzSYYs -OgqZF08M8R41MSxp+RXVN1TMnuNnn9VurbEmYN+qhGPapzHJaaDYwpbTgrSZcIw8 -kqTA8Hw/BNMpT2zF/TkSlWV/N/tSWxKZ1te1ukRuNuxd8l3Uqi2KRs4pZsHtNhPy -866SSpfbme2PTk7tcxv6PmRjQFzCA3Ys3FgBPxfQrqayZIVHun1aNlPkkACO9Rel -/6OB7u0lyhB2dS1l//ixjDyj/4EScse8tRcG2MYTl8uOWFEqpL6RWUBLB41pL5Lu -6py/60K3Yrjj ------END CERTIFICATE----- diff --git a/test/certs/ee-cert-dsa-sha384.pem b/test/certs/ee-cert-dsa-sha384.pem deleted file mode 100644 index ab3fe14687..0000000000 --- a/test/certs/ee-cert-dsa-sha384.pem +++ /dev/null @@ -1,26 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIEdjCCBCSgAwIBAgIUNbayaptPn6T0hvP2mKuB8L/W9k8wCwYJYIZIAWUDBAMD -MCgxJjAkBgNVBAMMHU9wZW5TU0wgVGVzdCBEU0EgU0hBLTM4NCBSb290MB4XDTI2 -MDQxMDA3MzMzMFoXDTM2MDQwNzA3MzMzMFowJjEkMCIGA1UEAwwbT3BlblNTTCBU -ZXN0IERTQSBTSEEtMzg0IEVFMIIDQjCCAjUGByqGSM44BAEwggIoAoIBAQDA154m -/UL7G6MMLDAr2BoxQzgT8eNaOV2Ls89BvjF3SS9qgOMQSv9TK8gcb16jpqd6aQ6G -WLedKu3fRUrXCihRaZZaeftJCntAVaDIhtYaYdsua6IDGjWd1SHHmFdQnH3AYLxV -dRmnq3Jjt6oelPQYKDbpWAtT8DsFJ/d6bGpQ6mxW4J1u1FnmKwzuxbR/ZxOV1gQy -D08gfkct7+UtQ5rJUIiIeK2RWsJhF6tdvH+g8VhBXsXo0ZprA/iQHst/aeXSGUBC -+vby1LYog2VFLXD+zl5rzXZUNJLXPt/9Dvs/qYknPlUEboQ8J/afbyuA8S10gsAu -8bnyQ/oTzmA+4Uy5Ah0A0QDXg1zTwGDdtB3OqMZOhhyL+oLzZeFsowwBzwKCAQAs -wjjcjD2G/brbwZuNaZWDHqrpTmmAhvg17+QGp9gaWWb/08TfZ+PbhIL4jV8kf5PZ -kPZVJyocYGduRJsIxiJDlssdaYzgkJ4zJG0A6gYtpBpaD/h6di0E0nzjm+80a9jo -xrgq3jRxkGVHpHvDd4ps0q2UXH44nFCEPWaoebpR4BXCLzXuFw30gUldrClqcMWt -OqQUwf7/ZndhQvLA2PiJEC/5EQFzeMzjl+XAOjW+781rO8BPmniFVXmRGAVWCycL -Qj0pQzvfDDi1M4LZBAw+g6RAa/IAB1mpKNOfsh2wDYS+nJn6q77COZRVn0DZLiVz -M8ENRqH0uRF1osCgqAuBA4IBBQACggEAXj8recOQ2JRABFgypUmG2PA0ibD5z1j3 -Xx7i5UXdwzOMJrtPtzjTmykgg73JpYA38kyqUtaZLKqtR2up+M9Bpj0l8GPZ5brM -E5zJbWukvSw8pnAUvq92izRHlmEK7QUPrkYM2e+NjJKYEOeJ8I1O7mZUBHNsbYGW -jGi0FW+LpcUywCUH7ccxHLFBXJnMUS7zipc6fwBjumFtYTyjsoeE5pyVGs6Cau0o -dzCgR3Ss0gc73qnHv+7t4NP2385AaTKhNeykrtwhrFL6MDGYf0Bs2Y5SE5vEnIZJ -Rb4I+8YnhsxaPGiKy9N6R+1CisnBg+4cx1mEVl3moQtAT6POruJaMqNCMEAwHQYD -VR0OBBYEFNfDDHDjB5VsPYFzEcuRXWZilvyIMB8GA1UdIwQYMBaAFDXj0oV+Bxtx -dRByLwz7g8OjZg/ZMAsGCWCGSAFlAwQDAwM/ADA8AhwezQQknbLR8wtcYnQJLvlv -tILlrOxyRlvUCUGtAhxGW+R77sJNGghc76jH+g3Kkent+0+G3VxrgrOc ------END CERTIFICATE----- diff --git a/test/certs/ee-cert-dsa-sha512.pem b/test/certs/ee-cert-dsa-sha512.pem deleted file mode 100644 index e3741ed0dd..0000000000 --- a/test/certs/ee-cert-dsa-sha512.pem +++ /dev/null @@ -1,26 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIEdzCCBCSgAwIBAgIUG0h9XyzEews1+X1q3CMHaNZuXhkwCwYJYIZIAWUDBAME -MCgxJjAkBgNVBAMMHU9wZW5TU0wgVGVzdCBEU0EgU0hBLTUxMiBSb290MB4XDTI2 -MDQxMDA3MzMzMFoXDTM2MDQwNzA3MzMzMFowJjEkMCIGA1UEAwwbT3BlblNTTCBU -ZXN0IERTQSBTSEEtNTEyIEVFMIIDQjCCAjUGByqGSM44BAEwggIoAoIBAQDA154m -/UL7G6MMLDAr2BoxQzgT8eNaOV2Ls89BvjF3SS9qgOMQSv9TK8gcb16jpqd6aQ6G -WLedKu3fRUrXCihRaZZaeftJCntAVaDIhtYaYdsua6IDGjWd1SHHmFdQnH3AYLxV -dRmnq3Jjt6oelPQYKDbpWAtT8DsFJ/d6bGpQ6mxW4J1u1FnmKwzuxbR/ZxOV1gQy -D08gfkct7+UtQ5rJUIiIeK2RWsJhF6tdvH+g8VhBXsXo0ZprA/iQHst/aeXSGUBC -+vby1LYog2VFLXD+zl5rzXZUNJLXPt/9Dvs/qYknPlUEboQ8J/afbyuA8S10gsAu -8bnyQ/oTzmA+4Uy5Ah0A0QDXg1zTwGDdtB3OqMZOhhyL+oLzZeFsowwBzwKCAQAs -wjjcjD2G/brbwZuNaZWDHqrpTmmAhvg17+QGp9gaWWb/08TfZ+PbhIL4jV8kf5PZ -kPZVJyocYGduRJsIxiJDlssdaYzgkJ4zJG0A6gYtpBpaD/h6di0E0nzjm+80a9jo -xrgq3jRxkGVHpHvDd4ps0q2UXH44nFCEPWaoebpR4BXCLzXuFw30gUldrClqcMWt -OqQUwf7/ZndhQvLA2PiJEC/5EQFzeMzjl+XAOjW+781rO8BPmniFVXmRGAVWCycL -Qj0pQzvfDDi1M4LZBAw+g6RAa/IAB1mpKNOfsh2wDYS+nJn6q77COZRVn0DZLiVz -M8ENRqH0uRF1osCgqAuBA4IBBQACggEADpK5z3E7aC/bPkHbIApYwMui0PlPm9mZ -fJcOUYkUxrGwsVB7MLlFKaYogohKW/6llyTQ9KVv0GhXGBU8KZAwYi2IvEqZWt96 -QWMReZkr85mcfWPPr0nhPaiKPFLuzbrJS5+8pRZ0JZICAs7fWK2ieTFzF5T52+uU -HW3d8hRW0faGy3JVChySx2zKhznax0ugOeO6xpw+GIhh7DtoLN9+WCUD4gHxcT1e -ngH3SPr9kSAc179ZheLPV8K96D6h62xLyDOv66jKqxuEuwKMezKhI8NoWlIjFlwq -qeg+/URRSKaemF7CeEtjfxfyhPyWFBA3ied6v8lgcvm8xEK1fOuWtaNCMEAwHQYD -VR0OBBYEFG70aEHyZTHkRfESJAk59LuyXqj2MB8GA1UdIwQYMBaAFLO3mEJ4Js8i -80dWuZffkE17675DMAsGCWCGSAFlAwQDBANAADA9AhxQI/S0oZhUBxth3amipFkw -px3NJNYZEdKm1x4hAh0AotKopAK/hiDc2IGgHC+L2kjsvg/tqofl54aZ6w== ------END CERTIFICATE----- diff --git a/test/certs/ext-timeSpecification-periodic-no-second.pem b/test/certs/ext-timeSpecification-periodic-no-second.pem deleted file mode 100644 index 9b23ddbb16..0000000000 --- a/test/certs/ext-timeSpecification-periodic-no-second.pem +++ /dev/null @@ -1,14 +0,0 @@ ------BEGIN CERTIFICATE----- -MIICLzCCAhmgAwIBAgIEDCI4TjANBgkqhkiG9w0BAQUFADARMQ8wDQYDVQQDDAZI -aSBtb20wIhgPMjAyMjEyMjExNDQ5NDJaGA8yMDIyMTIyMTE0NDk0MlowETEPMA0G -A1UEAwwGSGkgbW9tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtnjL -m1ts1hC4fNNt3UnQD9y73bDXgioTyWYSI3ca/KNfuTydjFTEYAmqnuGrBOUfgbmH -3PRQ0AmpqljgWTb3d3K8H4UFvDWQTPSS21IMjm8oqd19nE5GxWirGu0oDRzhWLHe -1RZ7ZrohCPg/1Ocsy47QZuK2laFB0rEmrRWBmEYbDl3/wxf5XfqIqpOynJB02thX -rTCcTM7Rz1FqCFt/ZVZB5hKY2S+CTdE9OIVKlr4WHMfuvUYeOj06GkwLFJHNv2tU -+tovI3mYRxUuY4UupkS3MC+Otey7XKm1P+INjWWoegm6iCAt3VuspVz+6pU2xgl3 -nrAVMQHB4fReQPH0pQIDAQABo4GMMIGJMIGGBgNVHSsEfzB9MXUwUaAlMSMwIaAM -MAqgAwIBBaEDAgEroREwD6ADAgEMoQMCASKiAwIBOKEIMQYCAQECAQKiCDEGAgED -AgEEowgxBgIBBQIBBqQKMQgCAgfmAgIH5zAgoQgxBgIBAwIBBKMIMQYCAQcCAQik -CjEIAgIH5wICB+gBAf8CAfswDQYJKoZIhvcNAQEFBQADAQA= ------END CERTIFICATE----- diff --git a/test/certs/leaf-encrypted.key b/test/certs/leaf-encrypted.key index 45b9422941..99a802dbe6 100644 --- a/test/certs/leaf-encrypted.key +++ b/test/certs/leaf-encrypted.key @@ -1,30 +1,30 @@ -----BEGIN ENCRYPTED PRIVATE KEY----- -MIIFNTBfBgkqhkiG9w0BBQ0wUjAxBgkqhkiG9w0BBQwwJAQQY0DiaGymsqdts7Bb -XYDhhgICCAAwDAYIKoZIhvcNAgkFADAdBglghkgBZQMEASoEEA5GTFOk3rHjTDWs -3Tms8YoEggTQrO/4UbxZQij+neSxc2YlkTONPG6N2Ft9ULqK9qSS7To5/xzF/Jgd -Yi0Az62H8haLZZSDfsCwcizTbz2IuOJlCN3+wObWZ226ZGFkRq4e+rMqYq/0pjcL -aj7Bia3ezlmDajLXDgOouMiSPWi/s28/qIppr0ay00jOBfEznJkAeCigl8lU4sPn -jtcZyWAhlkc47xfUrRGRyVVlLuFIoviWSEJoXPJW7dXKLALYgH6ojzJQzfgQBE6E -vrJlkY4Z0pgVN9ualMcUlU835En1mzGOmfqEwsavCUI2Mm51Kb/uaKJbGIJaeVst -jUq/iJatTAL36OViUX7RP0meIxf1zu1pmf5fTQjRBLGdZSbyB3mBv79UpycP968x -EDSCFkqXAAnxI38b0mxncDM+XgKRw1/357yZrkX1Zd6l5Vh5ntQnjWooczplwaem -TyNyo2i9Tjoy2yNZiRoGrhwD3PHM6DSxZh4eQ2HMALqaQBvPGet1f36ieFWufrP0 -TcCbykgID/nCO7nLOuoge8F4L124VggdgmCIFjlfwFjp/6dkx5fna7H1jYqm4E3o -LaxxkGdQOS5xEstbWU72HsDanMp++q9ObLiYO/kayYLFsf7H8tCxXefa118a3cT1 -RXREMQQY2CBW44Okp7yA85hURn5eEHxGYs+gpaJj1o+hZCLdGInx6faolJRCEZXp -887eu/pQTeS9ftCvaLFme0c23JeHBRoFC1c6GUIbxhD7KADtiimE5nT7yI+SWt8Q -QzfNbuoWaQgjEk9euN2/zl+Ov5gidv2mwYrgfJsk/wxmd+zEP+9MogTSyiCjYnKF -WlFoLIQetH/6un9LvC4y/xvSwnNPVG0NdzWmYjiKeQmAyRLhSlD/RRGlbfNsShVf -pt4I8Szz3fhseSyY+V7S0FKTg1YwT/jpTciUWfxVJk2IgMiPcrVYIObN3edkN5bD -HHoq5/b4qc5lW7JEcWyeVdSqiutemBIX/pir/ZURJLtYSRv65GNFGEKOrwczrHPS -xsGjOo0qJV0uJfwpISYdkn/xbDt6r6QscXUgkkRGPXUfGxj/GPWnya5nhKbu27HK -rzioEZaDVfduVgoSFoeiQNelrt4Jg4zeOnTZ3hKZuvSV/f4NMAvALo3O9EeQbROY -dYaJPCmSbQn8+wVZaHoXCS9zcbptXaBvJShFyFoHZoJi80sC6VN/gKECU0zTXc0v -ipGWhlWusX7T87Iw0LG5pXa+Buz6wXCZvC8SQA68AwM5eB5k6A5ATND3QtGwtMu6 -Nq48a9O9xuCMYMREOnIHCDntdr+s3TJrvZKHBG8rJllYT/2LY+DwtllR1lC/6b+B -IORhrJy3no8Vctcp0Foy84KjeV9C4IhAdTRLE5Syg0CryFebZ+9+9xBslJ5isxoA -TWGQwfCsPj5qDw1AEEBQPDH8VHefnhHhAoik/RWbivtahmg5/4eOf8PEyrM/ANqZ -ysD8HZIJID5mT0+p+fVTWTm/qMWoD6klvX3Gql/Ujd07QXzRRC0LhnUsDSwTv+qc -Bg9TqNgUE8MG5SdS8LAPY8hLfkvt0i88vtpyd2lgu0Q4uFzdGKXZuGGVbB/Vc3GE -4VC4Hxd+ZQH0YzWZsJWNHFoG/4GaWabWKl2+XUnRN2PqcfGSFOsPj5s= +MIIFLTBXBgkqhkiG9w0BBQ0wSjApBgkqhkiG9w0BBQwwHAQIEBBNanZFjs8CAggA +MAwGCCqGSIb3DQIJBQAwHQYJYIZIAWUDBAECBBDr8bhquxPf762O3jk0LAtJBIIE +0FQB7c06dpoHn1KBn8jTzsLIdVR0SeKUvq4edZfUPbB/6go97j48BwSzAaXY7BNL +90GRMrNNjKZDLeNf0wwf1+67YX7neGnb+LdxpQdqEjOTGQdwTx9SG6XIqT8x4R67 +rI2DQqI937FSor9292koXQNM9Asoenn6kOCITaa8chsPdKCtFjfVmqZRMaewr5PW +W1rooFuCVAIfgBOOaEeN7OMTJRdAGtWWOJqyLB29gXxwaI1+PnXmkHPgRGXZYz7W +N5lTp1xvFPY+Rp/cK0DfeR5MrMYSVvrXbi6usjteJ2h0Rzcy8SY6Jnvuaoowi+rj +lDUP0K/51tTQBd6bpsvcmc2cBx+7pg4BAkf9SnuKQpYCWPjiwrCiDJIP/o5GYIn2 +m/3K2pLahjOeGZAmhGUi0fZPZhaq37IQKwuzLDuYw1CkR7LhaJcJ9V1vXMPePgCY ++BvjFG5z0mLDwUNvzCHQokav3Z/QT6CfOgTL10qKuBgylT1d5Cw7bfv8Lnc6C/YK +aVXosCaKTJO8r4t7NgJX4PYQP/DZIl5CJIoUzJkrAkShLwcGtXMHVNSWx4LS60QY +lfjz80cWWE6Tx/XjBkae0AQJW8S9nDB8/X80ox8jJ/sdd5XNZqUQhDxBP5/4GiAS +pZlgp/IwssoG5HUnwn/4AUgD7Gdo5QRqFlkXeCFlHgjBrEHBkevHECRHAdWwrK7X +5td662K1B9hm6EfA1R51jiOKBuM0bwYtI+tpmpT5zeDGeaOWuPUYPUFjfo9xt1Lx +cmX3ouBt34uT/cQesPxP8gJwRdo0KqPK+KLjtQazXmHFu+FStZ29gUvhqAw9kcxq +ps9neGAl3DJgYbB1QqqefGqFWBhJzt4toqxcgm6Z0PJSYQlxJEC3yWWs5w5wfLJJ +KGfnpsY1IGYsbw9Caa84XqnzHosGWx724GJeb3YSwwMj311oMi9s8J/d/NpJZHOu +uk/mQWezCfdEFSnkOtIDJWTQUtRtRfIZQp243c25E3/rJySuSoMfn4eolAGurse8 +6r7SEJ6MUjCTd3ZcA+XZAtFxPQnNBYm691hvGE6uclxYy9L6bmws9dosNlpCyvIQ ++OYdB9Mvx9hs0KwAWZ6bnIxa3tc6Ob9mxV7ycMS43d4ShEqzy44DZD02Z0iQIRym +1AoGwgLbc2d9NouUiw2ur5n6ByYCTHwmMSAstVovuBoS2XDF23BzLL7KuCnkHH0y ++M6CRaXW0ceTP4DfEvBphxfj4NNEZpjm8j6ERvnnQvC5tRAaMglhg1WOvUVUtPg5 +cJPIiSn+yVuoFDnLKJ53N9NzDtUKSBQgwNGyVVPTzpfxLmjg00bNQ7eyoRr6uK0l +ezmHemo52JpCaBGV01tnvVKzGouFN/KxP9GxvPQY8UQxVkE+E/p0UjGOpNLIDmzl +/qVKxky9lMBoHc+neeCbOrtgwkyYgpPkKlmTTsi/yUxpbUmobFZJTUbOWrpeRbw3 +Pt9u8NeVmD4Ys/NenHIJwksOqmWxSy7IjJpzQsee1CZXV7McAYsg24tP4Bdj9aGT +hsMyiaiNB+rjkNxhUCm39nJsaN1AoTZ3Br1UYfHrfocif12yNGOEBy2swfjQIGNH +fjGk3px34MZZv3S0bM/ZPi9ankzAZnf8qkHoDVtsP+Gk -----END ENCRYPTED PRIVATE KEY----- diff --git a/test/certs/mkcert.sh b/test/certs/mkcert.sh index 087dc343d7..1cb4a9000c 100755 --- a/test/certs/mkcert.sh +++ b/test/certs/mkcert.sh @@ -257,7 +257,7 @@ genee() { local cakey=$1; shift local ca=$1; shift - exts=$(printf "%s\n%s\n%s\n%s\n%s\n%s\n[alts]\n%s\n" \ + exts=$(printf "%s\n%s\n%s\n%s\n%s\n[alts]\n%s\n" \ "subjectKeyIdentifier = hash" \ "authorityKeyIdentifier = keyid, issuer" \ "basicConstraints = CA:false" \ diff --git a/test/certs/root-cert-dsa-sha384.pem b/test/certs/root-cert-dsa-sha384.pem deleted file mode 100644 index 107e855b42..0000000000 --- a/test/certs/root-cert-dsa-sha384.pem +++ /dev/null @@ -1,27 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIEizCCBDigAwIBAgIUL44kPKEDy7eaEgXNH4xXTuVw77owCwYJYIZIAWUDBAMD -MCgxJjAkBgNVBAMMHU9wZW5TU0wgVGVzdCBEU0EgU0hBLTM4NCBSb290MB4XDTI2 -MDQxMDA3MzMzMFoXDTM2MDQwNzA3MzMzMFowKDEmMCQGA1UEAwwdT3BlblNTTCBU -ZXN0IERTQSBTSEEtMzg0IFJvb3QwggNDMIICNQYHKoZIzjgEATCCAigCggEBAMDX -nib9QvsbowwsMCvYGjFDOBPx41o5XYuzz0G+MXdJL2qA4xBK/1MryBxvXqOmp3pp -DoZYt50q7d9FStcKKFFpllp5+0kKe0BVoMiG1hph2y5rogMaNZ3VIceYV1CcfcBg -vFV1GaercmO3qh6U9BgoNulYC1PwOwUn93psalDqbFbgnW7UWeYrDO7FtH9nE5XW -BDIPTyB+Ry3v5S1DmslQiIh4rZFawmEXq128f6DxWEFexejRmmsD+JAey39p5dIZ -QEL69vLUtiiDZUUtcP7OXmvNdlQ0ktc+3/0O+z+piSc+VQRuhDwn9p9vK4DxLXSC -wC7xufJD+hPOYD7hTLkCHQDRANeDXNPAYN20Hc6oxk6GHIv6gvNl4WyjDAHPAoIB -ACzCONyMPYb9utvBm41plYMequlOaYCG+DXv5Aan2BpZZv/TxN9n49uEgviNXyR/ -k9mQ9lUnKhxgZ25EmwjGIkOWyx1pjOCQnjMkbQDqBi2kGloP+Hp2LQTSfOOb7zRr -2OjGuCreNHGQZUeke8N3imzSrZRcfjicUIQ9Zqh5ulHgFcIvNe4XDfSBSV2sKWpw -xa06pBTB/v9md2FC8sDY+IkQL/kRAXN4zOOX5cA6Nb7vzWs7wE+aeIVVeZEYBVYL -JwtCPSlDO98MOLUzgtkEDD6DpEBr8gAHWako05+yHbANhL6cmfqrvsI5lFWfQNku -JXMzwQ1GofS5EXWiwKCoC4EDggEGAAKCAQEAqBWUzoivwm10KhCOVj4dLJ376hik -coO7wh8szq+0lBCKVQu0XgZdpR67ibiInCslpi4D31QX1ciP8Ds3Tnr92Xq9fp6F -Q9+M94it5BWvXq8uWnsCYRLIXds+8DKnUMTPc0U5Qc/HnfkdgHockBya5ZKRLzgW -THC5n29NjBoIH9TBFddxanUqOqM2a0+0uC23jC/rmsmIXKKLIRnBjDjCfWGkpvDR -V0TmgU+wBN7Fu6/PDdb2h1omgx5iJ0hR9bSQMevPzxKWIIYt3jBa3JWRJVshZbCX -zGSycHIM4IPPEWtDEMR/s/aO5+HcQdV42itClvOQxhVfYTtBCV8TiMYFAKNTMFEw -HQYDVR0OBBYEFDXj0oV+BxtxdRByLwz7g8OjZg/ZMB8GA1UdIwQYMBaAFDXj0oV+ -BxtxdRByLwz7g8OjZg/ZMA8GA1UdEwEB/wQFMAMBAf8wCwYJYIZIAWUDBAMDA0AA -MD0CHQC/zbfFT+FeeYr9PmYtblMAGmtUgM2VyUcargqPAhwnaYxJwO0tJHKZDXOG -38UfhwBTUj0PNyAwbOG/ ------END CERTIFICATE----- diff --git a/test/certs/root-cert-dsa-sha512.pem b/test/certs/root-cert-dsa-sha512.pem deleted file mode 100644 index 5dbe393aea..0000000000 --- a/test/certs/root-cert-dsa-sha512.pem +++ /dev/null @@ -1,27 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIEiTCCBDagAwIBAgITGBs2j74eZNOfebavEYuJJZKVKTALBglghkgBZQMEAwQw -KDEmMCQGA1UEAwwdT3BlblNTTCBUZXN0IERTQSBTSEEtNTEyIFJvb3QwHhcNMjYw -NDEwMDczMzMwWhcNMzYwNDA3MDczMzMwWjAoMSYwJAYDVQQDDB1PcGVuU1NMIFRl -c3QgRFNBIFNIQS01MTIgUm9vdDCCA0IwggI1BgcqhkjOOAQBMIICKAKCAQEAwNee -Jv1C+xujDCwwK9gaMUM4E/HjWjldi7PPQb4xd0kvaoDjEEr/UyvIHG9eo6anemkO -hli3nSrt30VK1wooUWmWWnn7SQp7QFWgyIbWGmHbLmuiAxo1ndUhx5hXUJx9wGC8 -VXUZp6tyY7eqHpT0GCg26VgLU/A7BSf3emxqUOpsVuCdbtRZ5isM7sW0f2cTldYE -Mg9PIH5HLe/lLUOayVCIiHitkVrCYRerXbx/oPFYQV7F6NGaawP4kB7Lf2nl0hlA -Qvr28tS2KINlRS1w/s5ea812VDSS1z7f/Q77P6mJJz5VBG6EPCf2n28rgPEtdILA -LvG58kP6E85gPuFMuQIdANEA14Nc08Bg3bQdzqjGToYci/qC82XhbKMMAc8CggEA -LMI43Iw9hv2628GbjWmVgx6q6U5pgIb4Ne/kBqfYGllm/9PE32fj24SC+I1fJH+T -2ZD2VScqHGBnbkSbCMYiQ5bLHWmM4JCeMyRtAOoGLaQaWg/4enYtBNJ845vvNGvY -6Ma4Kt40cZBlR6R7w3eKbNKtlFx+OJxQhD1mqHm6UeAVwi817hcN9IFJXawpanDF -rTqkFMH+/2Z3YULywNj4iRAv+REBc3jM45flwDo1vu/NazvAT5p4hVV5kRgFVgsn -C0I9KUM73ww4tTOC2QQMPoOkQGvyAAdZqSjTn7IdsA2EvpyZ+qu+wjmUVZ9A2S4l -czPBDUah9LkRdaLAoKgLgQOCAQUAAoIBAAHb5mq9RGf+mLtQi12GnLIlWF45bhHr -0+gNYMzTA7PBzb/E+SfeizOnNuJtNU3LSiNE+sHNMnn/WY4KvjMCryuRxz7b8Y8+ -0nGwN0YfyY/cK5CehRa+lfhahlTorF8VY98gcQJOyKjG0eloZ8H29MhPhYTF0qTS -5dbDb4nf5r5Uqx5/6gBmskpMG+xiXA2I7q2aLW92pZrFWYrkrNgaAAQqSl0whhG6 -EZXP6fAbndJbt706xFlySr/ZHkgWybEAXYO8TbjyDkZP/h9UyR6CnKeb3L6qw8be -8U5scYfx2HjhCv5GLqqauRm+0oJwbXmOWuMpeynGHy24O+wKAX/ePhujUzBRMB0G -A1UdDgQWBBSzt5hCeCbPIvNHVrmX35BNe+u+QzAfBgNVHSMEGDAWgBSzt5hCeCbP -IvNHVrmX35BNe+u+QzAPBgNVHRMBAf8EBTADAQH/MAsGCWCGSAFlAwQDBANAADA9 -AhxgdnguNQoOQZyseelUWc5tD7m/ESvTuAV2aiEwAh0Apmc4SMIg7nKTA2jp7M1E -V7kA7INPUKKx/+iWgA== ------END CERTIFICATE----- diff --git a/test/certs/server-ec-compressed-cert.pem b/test/certs/server-ec-compressed-cert.pem deleted file mode 100644 index 4e97f49af2..0000000000 --- a/test/certs/server-ec-compressed-cert.pem +++ /dev/null @@ -1,12 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIBrzCCATSgAwIBAgIBAjAKBggqhkjOPQQDAjAbMRkwFwYDVQQDDBBFQ0RTQSBQ -LTM4NCByb290MCAXDTI2MDYxOTE4MDA1OFoYDzIxMjYwNTI2MTgwMDU4WjAZMRcw -FQYDVQQDDA5zZXJ2ZXIuZXhhbXBsZTA5MBMGByqGSM49AgEGCCqGSM49AwEHAyIA -A4Mt9T6fKt3APp8/Frw65PDi2eMYdZK98nhBW9pA1Ccho4GIMIGFMB0GA1UdDgQW -BBTozN8kakexZEnc26PUo5K2W9ptbTAfBgNVHSMEGDAWgBQm0I8de1/cHn9BgH1j -yhx1gdaFaTAJBgNVHRMEAjAAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcD -AjAZBgNVHREEEjAQgg5zZXJ2ZXIuZXhhbXBsZTAKBggqhkjOPQQDAgNpADBmAjEA -hvcNLTyL7vamQEJet5uvOXH7NKPHlG8sbfPvGS/AQ0yk6ARdc1Y1gV6FAnmnQUhX -AjEA2HMTkh+h2ZDm68uRnhsNXIxI4dYF/nr5bdxw8XKN4P84Mg4gs37/IPoVN9jG -Y4yh ------END CERTIFICATE----- diff --git a/test/certs/server-ec-compressed-key.pem b/test/certs/server-ec-compressed-key.pem deleted file mode 100644 index 98218fcb3c..0000000000 --- a/test/certs/server-ec-compressed-key.pem +++ /dev/null @@ -1,5 +0,0 @@ ------BEGIN PRIVATE KEY----- -MGcCAQAwEwYHKoZIzj0CAQYIKoZIzj0DAQcETTBLAgEBBCAb1VgxSUhJyh43soLb -FMsebjWSp/Hma3kSyw6lT4txDaEkAyIAA4Mt9T6fKt3APp8/Frw65PDi2eMYdZK9 -8nhBW9pA1Cch ------END PRIVATE KEY----- diff --git a/test/certs/setup.sh b/test/certs/setup.sh index 3056b1f90a..3bee78ec32 100755 --- a/test/certs/setup.sh +++ b/test/certs/setup.sh @@ -497,37 +497,6 @@ OPENSSL_SIGALG="sha3-256" ./mkcert.sh genee server.example ee-key-ec-named-named OPENSSL_SIGALG="sha3-384" ./mkcert.sh genee server.example ee-key-ec-named-named ee-cert-ec-sha3-384 ca-key-ec-named ca-cert-ec-named OPENSSL_SIGALG="sha3-512" ./mkcert.sh genee server.example ee-key-ec-named-named ee-cert-ec-sha3-512 ca-key-ec-named ca-cert-ec-named -# DSA roots and EE certs: id-dsa-with-sha384 / id-dsa-with-sha512 -# (regression for https://github.com/openssl/openssl/issues/30432) -_DSA_CERT_DIR=$(cd "$(dirname "$0")" && pwd) -( - set -e - d=$(mktemp -d) - trap 'rm -rf "$d"' EXIT - cd "$d" - openssl dsaparam -out dsap.pem 2048 - openssl gendsa -out ca384k.pem dsap.pem - openssl req -new -x509 -key ca384k.pem -sha384 -out root-cert-dsa-sha384.pem \ - -days 3650 -subj "/CN=OpenSSL Test DSA SHA-384 Root" -nodes - openssl gendsa -out ee384k.pem dsap.pem - openssl req -new -key ee384k.pem -out ee384.csr \ - -subj "/CN=OpenSSL Test DSA SHA-384 EE" - openssl x509 -req -in ee384.csr -CA root-cert-dsa-sha384.pem -CAkey ca384k.pem \ - -CAcreateserial -out ee-cert-dsa-sha384.pem -days 3650 -sha384 - openssl gendsa -out ca512k.pem dsap.pem - openssl req -new -x509 -key ca512k.pem -sha512 -out root-cert-dsa-sha512.pem \ - -days 3650 -subj "/CN=OpenSSL Test DSA SHA-512 Root" -nodes - openssl gendsa -out ee512k.pem dsap.pem - openssl req -new -key ee512k.pem -out ee512.csr \ - -subj "/CN=OpenSSL Test DSA SHA-512 EE" - openssl x509 -req -in ee512.csr -CA root-cert-dsa-sha512.pem -CAkey ca512k.pem \ - -CAcreateserial -out ee-cert-dsa-sha512.pem -days 3650 -sha512 - cp root-cert-dsa-sha384.pem ee-cert-dsa-sha384.pem \ - root-cert-dsa-sha512.pem ee-cert-dsa-sha512.pem \ - "$_DSA_CERT_DIR" -) -unset _DSA_CERT_DIR - # EC cert seigned RSA intermediate CA OPENSSL_KEYALG=ec OPENSSL_KEYBITS=prime256v1 ./mkcert.sh genee \ "P-256 cert EE issuer" p256-ee-rsa-ca-key \ diff --git a/test/chacha_internal_test.c b/test/chacha_internal_test.c index effdc26b88..d316bfd7b3 100644 --- a/test/chacha_internal_test.c +++ b/test/chacha_internal_test.c @@ -16,9 +16,6 @@ #include #include "testutil.h" #include "crypto/chacha.h" -#if defined(__powerpc64__) && !defined(OPENSSL_SYS_AIX) && !defined(OPENSSL_SYS_MACOSX) -#include "arch/ppc_arch.h" -#endif static const unsigned int key[] = { 0x03020100, 0x07060504, 0x0b0a0908, 0x0f0e0d0c, @@ -182,78 +179,6 @@ static int test_cha_cha_internal(int n) return 1; } -#if defined(__powerpc64__) && !defined(OPENSSL_SYS_AIX) && !defined(OPENSSL_SYS_MACOSX) -/* - * Test that ChaCha20_ctr32_vsx_8x (the POWER10 8-block path, triggered for - * buffers > 255 bytes) preserves callee-saved FPRs f14-f25 as required by - * the ELFv2 ABI. The function uses vxxlor to spill VMX values into - * VSR0-VSR25, which aliases FPR0-FPR25; without explicit saves/restores - * the caller's floating-point state is silently corrupted. - */ -__attribute__((noinline)) static int test_chacha20_p10_fpr_abi(void) -{ - /* - * Use a buffer larger than 255 bytes to ensure the 8x path is taken. - * The input content doesn't matter for this ABI test. - */ - static unsigned char in[512], out[512]; - int ok = 1; - - register double r14 asm("fr14"); - register double r15 asm("fr15"); - register double r16 asm("fr16"); - register double r17 asm("fr17"); - register double r18 asm("fr18"); - register double r19 asm("fr19"); - register double r20 asm("fr20"); - register double r21 asm("fr21"); - register double r22 asm("fr22"); - register double r23 asm("fr23"); - register double r24 asm("fr24"); - register double r25 asm("fr25"); - - r14 = 14.0; - r15 = 15.0; - r16 = 16.0; - r17 = 17.0; - r18 = 18.0; - r19 = 19.0; - r20 = 20.0; - r21 = 21.0; - r22 = 22.0; - r23 = 23.0; - r24 = 24.0; - r25 = 25.0; - - /* Force the values into the actual FPR registers before the call */ - asm volatile("" : "+d"(r14), "+d"(r15), "+d"(r16), "+d"(r17)); - asm volatile("" : "+d"(r18), "+d"(r19), "+d"(r20), "+d"(r21)); - asm volatile("" : "+d"(r22), "+d"(r23), "+d"(r24), "+d"(r25)); - - ChaCha20_ctr32(out, in, sizeof(in), key, ivp); - - /* Read back from the FPR registers after the call */ - asm volatile("" : "+d"(r14), "+d"(r15), "+d"(r16), "+d"(r17)); - asm volatile("" : "+d"(r18), "+d"(r19), "+d"(r20), "+d"(r21)); - asm volatile("" : "+d"(r22), "+d"(r23), "+d"(r24), "+d"(r25)); - - ok &= TEST_double_eq(r14, 14.0); - ok &= TEST_double_eq(r15, 15.0); - ok &= TEST_double_eq(r16, 16.0); - ok &= TEST_double_eq(r17, 17.0); - ok &= TEST_double_eq(r18, 18.0); - ok &= TEST_double_eq(r19, 19.0); - ok &= TEST_double_eq(r20, 20.0); - ok &= TEST_double_eq(r21, 21.0); - ok &= TEST_double_eq(r22, 22.0); - ok &= TEST_double_eq(r23, 23.0); - ok &= TEST_double_eq(r24, 24.0); - ok &= TEST_double_eq(r25, 25.0); - - return ok; -} -#endif - int setup_tests(void) { #ifdef OPENSSL_CPUID_OBJ @@ -261,10 +186,5 @@ int setup_tests(void) #endif ADD_ALL_TESTS(test_cha_cha_internal, sizeof(ref)); -#if defined(__powerpc64__) && !defined(OPENSSL_SYS_AIX) && !defined(OPENSSL_SYS_MACOSX) - /* Only run the ABI test when the POWER10 8x path is available */ - if (OPENSSL_ppccap_P & PPC_BRD31) - ADD_TEST(test_chacha20_p10_fpr_abi); -#endif return 1; } diff --git a/test/cipherbytes_test.c b/test/cipherbytes_test.c index 5f4a59cbd7..3e73781cfe 100644 --- a/test/cipherbytes_test.c +++ b/test/cipherbytes_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2017-2020 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -66,6 +66,38 @@ err: return ret; } +static int test_v2(void) +{ + STACK_OF(SSL_CIPHER) *sk, *scsv; + /* ECDHE-ECDSA-AES256GCM, SSL2_RC4_1238_WITH_MD5, + * ECDHE-ECDSA-CHACHA20-POLY1305 */ + const unsigned char bytes[] = { 0x00, 0x00, 0x35, 0x01, 0x00, 0x80, + 0x00, 0x00, 0x33 }; + int ret = 0; + + if (!TEST_true(SSL_bytes_to_cipher_list(s, bytes, sizeof(bytes), 1, + &sk, &scsv)) + || !TEST_ptr(sk) + || !TEST_int_eq(sk_SSL_CIPHER_num(sk), 2) + || !TEST_ptr(scsv) + || !TEST_int_eq(sk_SSL_CIPHER_num(scsv), 0)) + goto err; + if (strcmp(SSL_CIPHER_get_name(sk_SSL_CIPHER_value(sk, 0)), + "AES256-SHA") + != 0 + || strcmp(SSL_CIPHER_get_name(sk_SSL_CIPHER_value(sk, 1)), + "DHE-RSA-AES128-SHA") + != 0) + goto err; + + ret = 1; + +err: + sk_SSL_CIPHER_free(sk); + sk_SSL_CIPHER_free(scsv); + return ret; +} + static int test_v3(void) { STACK_OF(SSL_CIPHER) *sk = NULL, *scsv = NULL; @@ -107,6 +139,7 @@ int setup_tests(void) ADD_TEST(test_empty); ADD_TEST(test_unsupported); + ADD_TEST(test_v2); ADD_TEST(test_v3); return 1; } diff --git a/test/cipherlist_test.c b/test/cipherlist_test.c index a0e1704d49..9874e6bad6 100644 --- a/test/cipherlist_test.c +++ b/test/cipherlist_test.c @@ -258,66 +258,11 @@ end: return result; } -/* - * SSL_CTX_set_ciphersuites() must not crash on empty list elements. - * CONF_parse_list() signals them with elem=NULL; ciphersuite_cb() must skip - * such entries rather than passing NULL to memcpy(). - */ -#ifndef OPENSSL_NO_TLS1_3 -static int cipher_in_ctx(const SSL_CTX *ctx, uint32_t id) -{ - const STACK_OF(SSL_CIPHER) *sk = SSL_CTX_get_ciphers(ctx); - int i; - - for (i = 0; i < sk_SSL_CIPHER_num(sk); i++) - if (SSL_CIPHER_get_id(sk_SSL_CIPHER_value(sk, i)) == id) - return 1; - return 0; -} - -static int test_set_ciphersuites_empty_elem(void) -{ - SSL_CTX *ctx = NULL; - int result = 0; - - if (!TEST_ptr(ctx = SSL_CTX_new(TLS_method()))) - goto end; - - /* Double colon: both surrounding valid suites must be applied */ - if (!TEST_true(SSL_CTX_set_ciphersuites(ctx, - "TLS_AES_128_GCM_SHA256::TLS_AES_256_GCM_SHA384"))) - goto end; - if (!TEST_true(cipher_in_ctx(ctx, TLS1_3_CK_AES_128_GCM_SHA256)) - || !TEST_true(cipher_in_ctx(ctx, TLS1_3_CK_AES_256_GCM_SHA384))) - goto end; - - /* Leading separator: empty first element, one valid suite must apply */ - if (!TEST_true(SSL_CTX_set_ciphersuites(ctx, ":TLS_AES_128_GCM_SHA256"))) - goto end; - if (!TEST_true(cipher_in_ctx(ctx, TLS1_3_CK_AES_128_GCM_SHA256))) - goto end; - - /* Trailing separator: empty last element, one valid suite must apply */ - if (!TEST_true(SSL_CTX_set_ciphersuites(ctx, "TLS_AES_128_GCM_SHA256:"))) - goto end; - if (!TEST_true(cipher_in_ctx(ctx, TLS1_3_CK_AES_128_GCM_SHA256))) - goto end; - - result = 1; -end: - SSL_CTX_free(ctx); - return result; -} -#endif - int setup_tests(void) { ADD_TEST(test_default_cipherlist_implicit); ADD_TEST(test_default_cipherlist_explicit); ADD_TEST(test_default_cipherlist_clear); -#ifndef OPENSSL_NO_TLS1_3 - ADD_TEST(test_set_ciphersuites_empty_elem); -#endif ADD_TEST(test_stdname_cipherlist); return 1; } diff --git a/test/ciphername_test.c b/test/ciphername_test.c index 3eabdbe7b6..cc29846990 100644 --- a/test/ciphername_test.c +++ b/test/ciphername_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2017-2024 The OpenSSL Project Authors. All Rights Reserved. * Copyright 2017 BaishanCloud. All rights reserved. * * Licensed under the Apache License 2.0 (the "License"); @@ -172,8 +172,6 @@ static CIPHER_ID_NAME cipher_names[] = { { 0x00C3, "TLS_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA256" }, { 0x00C4, "TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256" }, { 0x00C5, "TLS_DH_anon_WITH_CAMELLIA_256_CBC_SHA256" }, - { 0x00C6, "TLS_SM4_GCM_SM3" }, - { 0x00C7, "TLS_SM4_CCM_SM3" }, { 0x00FF, "TLS_EMPTY_RENEGOTIATION_INFO_SCSV" }, { 0x5600, "TLS_FALLBACK_SCSV" }, { 0xC001, "TLS_ECDH_ECDSA_WITH_NULL_SHA" }, diff --git a/test/cmp_client_test.c b/test/cmp_client_test.c index cd51d3d0e7..b0681e8587 100644 --- a/test/cmp_client_test.c +++ b/test/cmp_client_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2007-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright Nokia 2007-2019 * Copyright Siemens AG 2015-2019 * @@ -35,7 +35,7 @@ static EVP_PKEY *server_key = NULL; static X509 *server_cert = NULL; static EVP_PKEY *client_key = NULL; static X509 *client_cert = NULL; -static unsigned char ref[CMP_TEST_REFVALUE_LENGTH]; /* not actually used */ +static unsigned char ref[CMP_TEST_REFVALUE_LENGTH]; /* * For these unit tests, the client abandons message protection, and for @@ -51,30 +51,6 @@ static void tear_down(CMP_SES_TEST_FIXTURE *fixture) OPENSSL_free(fixture); } -static int set_simple_trust(OSSL_CMP_CTX *ctx, X509 *trusted) -{ - X509_STORE *ts = X509_STORE_new(); - X509_VERIFY_PARAM *vpm; - - /* - * not simply using OSSL_CMP_CTX_set1_srvCert() (to pin the server cert) - * in order to make sure that validated server cert gets cached, - * which is needed for the negative test case test_exec_KUR_bad_pkiConf_protection - */ - if (ts == NULL || !X509_STORE_add_cert(ts, trusted)) - goto err; - - vpm = X509_STORE_get0_param(ts); - if (!X509_VERIFY_PARAM_set_flags(vpm, X509_V_FLAG_NO_CHECK_TIME | X509_V_FLAG_PARTIAL_CHAIN) - || !OSSL_CMP_CTX_set0_trusted(ctx, ts)) - goto err; - - return 1; -err: - X509_STORE_free(ts); - return 0; -} - static CMP_SES_TEST_FIXTURE *set_up(const char *const test_case_name) { CMP_SES_TEST_FIXTURE *fixture; @@ -94,15 +70,15 @@ static CMP_SES_TEST_FIXTURE *set_up(const char *const test_case_name) goto err; if (!TEST_ptr(fixture->cmp_ctx = ctx = OSSL_CMP_CTX_new(libctx, NULL)) || !OSSL_CMP_CTX_set_log_cb(fixture->cmp_ctx, print_to_bio_out) - /* using default verbosity: OSSL_CMP_LOG_INFO */ - || !OSSL_CMP_CTX_set_transfer_cb(ctx, ossl_cmp_mock_server_perform) + || !OSSL_CMP_CTX_set_transfer_cb(ctx, OSSL_CMP_CTX_server_perform) || !OSSL_CMP_CTX_set_transfer_cb_arg(ctx, fixture->srv_ctx) || !OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_UNPROTECTED_SEND, 1) + || !OSSL_CMP_CTX_set_option(ctx, OSSL_CMP_OPT_UNPROTECTED_ERRORS, 1) || !OSSL_CMP_CTX_set1_oldCert(ctx, client_cert) || !OSSL_CMP_CTX_set1_pkey(ctx, client_key) /* client_key is by default used also for newPkey */ - || !set_simple_trust(ctx, server_cert) - || !OSSL_CMP_CTX_set1_referenceValue(ctx, ref, sizeof(ref))) /* not actually needed */ + || !OSSL_CMP_CTX_set1_srvCert(ctx, server_cert) + || !OSSL_CMP_CTX_set1_referenceValue(ctx, ref, sizeof(ref))) goto err; fixture->req_type = -1; return fixture; @@ -112,26 +88,13 @@ err: return NULL; } -static void print_errors_PKIStatusInfo(OSSL_CMP_CTX *ctx) -{ - int status = OSSL_CMP_CTX_get_status(ctx); - char buf[1024]; - const char *string = OSSL_CMP_CTX_snprint_PKIStatus(ctx, buf, sizeof(buf)); - - OSSL_CMP_CTX_print_errors(ctx); - if (status > OSSL_CMP_PKISTATUS_accepted && string != NULL) - ossl_cmp_log1(WARN, ctx, "mock server response statusInfo: %s", string); -} - static int execute_exec_RR_ses_test(CMP_SES_TEST_FIXTURE *fixt) { - int ret = TEST_int_eq(OSSL_CMP_CTX_get_status(fixt->cmp_ctx), - OSSL_CMP_PKISTATUS_unspecified) - && (TEST_int_eq(OSSL_CMP_exec_RR_ses(fixt->cmp_ctx), - fixt->expected == OSSL_CMP_PKISTATUS_accepted)); - - print_errors_PKIStatusInfo(fixt->cmp_ctx); - return ret && TEST_int_eq(OSSL_CMP_CTX_get_status(fixt->cmp_ctx), fixt->expected); + return TEST_int_eq(OSSL_CMP_CTX_get_status(fixt->cmp_ctx), + OSSL_CMP_PKISTATUS_unspecified) + && TEST_int_eq(OSSL_CMP_exec_RR_ses(fixt->cmp_ctx), + fixt->expected == OSSL_CMP_PKISTATUS_accepted) + && TEST_int_eq(OSSL_CMP_CTX_get_status(fixt->cmp_ctx), fixt->expected); } static int execute_exec_GENM_ses_test_single(CMP_SES_TEST_FIXTURE *fixture) @@ -143,7 +106,6 @@ static int execute_exec_GENM_ses_test_single(CMP_SES_TEST_FIXTURE *fixture) OSSL_CMP_CTX_push0_genm_ITAV(ctx, itav); itavs = OSSL_CMP_exec_GENM_ses(ctx); - print_errors_PKIStatusInfo(ctx); sk_OSSL_CMP_ITAV_pop_free(itavs, OSSL_CMP_ITAV_free); return TEST_int_eq(OSSL_CMP_CTX_get_status(ctx), fixture->expected) @@ -156,7 +118,6 @@ static int execute_exec_GENM_ses_test(CMP_SES_TEST_FIXTURE *fixture) { return execute_exec_GENM_ses_test_single(fixture) && OSSL_CMP_CTX_reinit(fixture->cmp_ctx) - && ossl_cmp_info(fixture->cmp_ctx, "--- second GENM session after reinit ---") && execute_exec_GENM_ses_test_single(fixture); } @@ -166,8 +127,10 @@ static int execute_exec_certrequest_ses_test(CMP_SES_TEST_FIXTURE *fixture) X509 *res = OSSL_CMP_exec_certreq(ctx, fixture->req_type, NULL); int status = OSSL_CMP_CTX_get_status(ctx); - print_errors_PKIStatusInfo(ctx); - if (!TEST_int_eq(status, fixture->expected)) + OSSL_CMP_CTX_print_errors(ctx); + if (!TEST_int_eq(status, fixture->expected) + && !(fixture->expected == OSSL_CMP_PKISTATUS_waiting + && TEST_int_eq(status, OSSL_CMP_PKISTATUS_trans))) return 0; if (fixture->expected != OSSL_CMP_PKISTATUS_accepted) return TEST_ptr_null(res); @@ -254,9 +217,7 @@ static int test_exec_REQ_ses_poll(int req_type, int check_after, return result; } -static const int checkAfter = 1; -static const int pollCount = 3; - +static int checkAfter = 1; static int test_exec_IR_ses_poll_ok(void) { return test_exec_REQ_ses_poll(OSSL_CMP_PKIBODY_IR, checkAfter, 2, 0, @@ -273,9 +234,9 @@ static int test_exec_IR_ses_poll_no_timeout(void) static int test_exec_IR_ses_poll_total_timeout(void) { - return test_exec_REQ_ses_poll(OSSL_CMP_PKIBODY_IR, checkAfter, - pollCount, (pollCount - 1) * checkAfter, - OSSL_CMP_PKISTATUS_trans); + return !test_exec_REQ_ses_poll(OSSL_CMP_PKIBODY_IR, checkAfter + 1, + 3 /* pollCount */, checkAfter + 6, + OSSL_CMP_PKISTATUS_waiting); } static int test_exec_CR_ses(int implicit_confirm, int granted, int reject) @@ -305,9 +266,7 @@ static int test_exec_CR_ses_implicit_confirm(void) && test_exec_CR_ses(1, 1 /* granted */, 0); } -/* the KUR transactions include certConf/pkiConf */ -static int test_exec_KUR_ses(int transfer_error, int server_use_bad_protection, - int pubkey, int raverified) +static int test_exec_KUR_ses(int transfer_error, int pubkey, int raverified) { SETUP_TEST_FIXTURE(CMP_SES_TEST_FIXTURE, set_up); fixture->req_type = OSSL_CMP_PKIBODY_KUR; @@ -315,8 +274,6 @@ static int test_exec_KUR_ses(int transfer_error, int server_use_bad_protection, if (transfer_error) OSSL_CMP_CTX_set_transfer_cb_arg(fixture->cmp_ctx, NULL); - (void)ossl_cmp_mock_srv_set_useBadProtection(fixture->srv_ctx, server_use_bad_protection); - if (pubkey) { EVP_PKEY *key = raverified /* wrong key */ ? server_key : client_key; @@ -329,8 +286,7 @@ static int test_exec_KUR_ses(int transfer_error, int server_use_bad_protection, if (pubkey || raverified) OSSL_CMP_CTX_set_option(fixture->cmp_ctx, OSSL_CMP_OPT_POPO_METHOD, OSSL_CRMF_POPO_RAVERIFIED); - fixture->expected = transfer_error ? OSSL_CMP_PKISTATUS_trans : raverified ? (pubkey ? OSSL_CMP_PKISTATUS_rejected_by_client : OSSL_CMP_PKISTATUS_rejection) - : server_use_bad_protection != -1 ? OSSL_CMP_PKISTATUS_checking_response + fixture->expected = transfer_error ? OSSL_CMP_PKISTATUS_trans : raverified ? OSSL_CMP_PKISTATUS_rejection : OSSL_CMP_PKISTATUS_accepted; EXECUTE_TEST(execute_exec_certrequest_ses_test, tear_down); return result; @@ -338,23 +294,18 @@ static int test_exec_KUR_ses(int transfer_error, int server_use_bad_protection, static int test_exec_KUR_ses_ok(void) { - return test_exec_KUR_ses(0, -1, 0, 0); + return test_exec_KUR_ses(0, 0, 0); } static int test_exec_KUR_ses_transfer_error(void) { - return test_exec_KUR_ses(1, -1, 0, 0); -} - -static int test_exec_KUR_bad_pkiConf_protection(void) -{ - return test_exec_KUR_ses(0, -1 /* disabled: OSSL_CMP_PKIBODY_PKICONF */, 0, 0); + return test_exec_KUR_ses(1, 0, 0); } static int test_exec_KUR_ses_wrong_popo(void) { #ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION /* cf ossl_cmp_verify_popo() */ - return test_exec_KUR_ses(0, -1, 0, 1); + return test_exec_KUR_ses(0, 0, 1); #else return 1; #endif @@ -362,12 +313,12 @@ static int test_exec_KUR_ses_wrong_popo(void) static int test_exec_KUR_ses_pub(void) { - return test_exec_KUR_ses(0, -1, 1, 0); + return test_exec_KUR_ses(0, 1, 0); } static int test_exec_KUR_ses_wrong_pub(void) { - return test_exec_KUR_ses(0, -1, 1, 1); + return test_exec_KUR_ses(0, 1, 1); } static int test_certConf_cb(OSSL_CMP_CTX *ctx, X509 *cert, int fail_info, @@ -389,7 +340,7 @@ static int test_exec_P10CR_ses(int reject) SETUP_TEST_FIXTURE(CMP_SES_TEST_FIXTURE, set_up); fixture->req_type = OSSL_CMP_PKIBODY_P10CR; - fixture->expected = reject ? OSSL_CMP_PKISTATUS_rejected_by_client + fixture->expected = reject ? OSSL_CMP_PKISTATUS_rejection : OSSL_CMP_PKISTATUS_accepted; ctx = fixture->cmp_ctx; if (!TEST_ptr(csr = load_csr_der(pkcs10_f, libctx)) @@ -483,9 +434,9 @@ static int test_exec_GENM_ses_poll_no_timeout(void) static int test_exec_GENM_ses_poll_total_timeout(void) { - return test_exec_REQ_ses_poll(OSSL_CMP_PKIBODY_GENM, checkAfter, - pollCount, (pollCount - 1) * checkAfter, - OSSL_CMP_PKISTATUS_trans); + return test_exec_REQ_ses_poll(OSSL_CMP_PKIBODY_GENM, checkAfter + 1, + 3 /* pollCount */, checkAfter + 2, + OSSL_CMP_PKISTATUS_waiting); } static int test_exec_GENM_ses(int transfer_error, int total_timeout, int expect) @@ -595,7 +546,7 @@ int setup_tests(void) || !TEST_ptr(server_cert = load_cert_pem(server_cert_f, libctx)) || !TEST_ptr(client_key = load_pkey_pem(client_key_f, libctx)) || !TEST_ptr(client_cert = load_cert_pem(client_cert_f, libctx)) - || !TEST_int_eq(1, RAND_bytes_ex(libctx, ref, sizeof(ref), 0))) { /* not actually used */ + || !TEST_int_eq(1, RAND_bytes_ex(libctx, ref, sizeof(ref), 0))) { cleanup_tests(); return 0; } @@ -611,7 +562,6 @@ int setup_tests(void) ADD_TEST(test_exec_IR_ses_poll_total_timeout); ADD_TEST(test_exec_KUR_ses_ok); ADD_TEST(test_exec_KUR_ses_transfer_error); - ADD_TEST(test_exec_KUR_bad_pkiConf_protection); ADD_TEST(test_exec_KUR_ses_wrong_popo); ADD_TEST(test_exec_KUR_ses_pub); ADD_TEST(test_exec_KUR_ses_wrong_pub); diff --git a/test/cmp_hdr_test.c b/test/cmp_hdr_test.c index 30f19f6238..cbffb87b23 100644 --- a/test/cmp_hdr_test.c +++ b/test/cmp_hdr_test.c @@ -252,7 +252,7 @@ static int execute_HDR_push0_freeText_test(CMP_HDR_TEST_FIXTURE *fixture) if (!TEST_ptr(text)) return 0; - if (!ASN1_STRING_set_string(text, "A free text")) + if (!ASN1_STRING_set(text, "A free text", -1)) goto err; if (!TEST_int_eq(ossl_cmp_hdr_push0_freeText(fixture->hdr, text), 1)) @@ -285,7 +285,7 @@ static int execute_HDR_push1_freeText_test(CMP_HDR_TEST_FIXTURE *fixture) if (!TEST_ptr(text)) goto err; - if (!ASN1_STRING_set_string(text, "A free text")) + if (!ASN1_STRING_set(text, "A free text", -1)) goto err; if (!TEST_int_eq(ossl_cmp_hdr_push1_freeText(fixture->hdr, text), 1)) diff --git a/test/cmp_vfy_test.c b/test/cmp_vfy_test.c index ec7131a861..70d776c0f5 100644 --- a/test/cmp_vfy_test.c +++ b/test/cmp_vfy_test.c @@ -22,7 +22,6 @@ static const char *ir_protected_f; static const char *ir_unprotected_f; static const char *ir_rmprotection_f; static const char *ip_waiting_f; -static const char *error_protected_f; static const char *instacert_f; static const char *instaca_f; static const char *ir_protected_0_extracerts; @@ -82,7 +81,7 @@ static X509 *endentity1 = NULL, *endentity2 = NULL, static X509 *insta_cert = NULL, *instaca_cert = NULL; static unsigned char rand_data[OSSL_CMP_TRANSACTIONID_LENGTH]; -static OSSL_CMP_MSG *ir_unprotected, *ir_rmprotection, *error_protected; +static OSSL_CMP_MSG *ir_unprotected, *ir_rmprotection; /* secret value used for IP_waitingStatus_PBM.der */ static const unsigned char sec_1[] = { @@ -453,9 +452,9 @@ static int execute_msg_check_test(CMP_VFY_TEST_FIXTURE *fixture) if (fixture->expected == 0) /* error expected already during above check */ return 1; - if (OSSL_CMP_CTX_get_option(fixture->cmp_ctx, OSSL_CMP_OPT_NONMATCHED_ERROR_NONCES)) - return 1; - return TEST_int_eq(0, ASN1_OCTET_STRING_cmp(ossl_cmp_hdr_get0_senderNonce(hdr), fixture->cmp_ctx->recipNonce)) + return TEST_int_eq(0, + ASN1_OCTET_STRING_cmp(ossl_cmp_hdr_get0_senderNonce(hdr), + fixture->cmp_ctx->recipNonce)) && TEST_int_eq(0, ASN1_OCTET_STRING_cmp(tid, fixture->cmp_ctx->transactionID)); @@ -469,7 +468,6 @@ static int allow_unprotected(const OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg, static void setup_check_update(CMP_VFY_TEST_FIXTURE **fixture, int expected, ossl_cmp_allow_unprotected_cb_t cb, int arg, - const OSSL_CMP_MSG *msg, const unsigned char *trid_data, const unsigned char *nonce_data) { @@ -479,7 +477,7 @@ static void setup_check_update(CMP_VFY_TEST_FIXTURE **fixture, int expected, (*fixture)->expected = expected; (*fixture)->allow_unprotected_cb = cb; (*fixture)->additional_arg = arg; - (*fixture)->msg = OSSL_CMP_MSG_dup(msg); + (*fixture)->msg = OSSL_CMP_MSG_dup(ir_rmprotection); if ((*fixture)->msg == NULL || (nonce_data != NULL && !ossl_cmp_asn1_octet_string_set1_bytes(&ctx->senderNonce, @@ -504,7 +502,7 @@ static void setup_check_update(CMP_VFY_TEST_FIXTURE **fixture, int expected, static int test_msg_check_no_protection_no_cb(void) { SETUP_TEST_FIXTURE(CMP_VFY_TEST_FIXTURE, set_up); - setup_check_update(&fixture, 0, NULL, 0, ir_rmprotection, NULL, NULL); + setup_check_update(&fixture, 0, NULL, 0, NULL, NULL); EXECUTE_TEST(execute_msg_check_test, tear_down); return result; } @@ -512,7 +510,7 @@ static int test_msg_check_no_protection_no_cb(void) static int test_msg_check_no_protection_restrictive_cb(void) { SETUP_TEST_FIXTURE(CMP_VFY_TEST_FIXTURE, set_up); - setup_check_update(&fixture, 0, allow_unprotected, 0, ir_rmprotection, NULL, NULL); + setup_check_update(&fixture, 0, allow_unprotected, 0, NULL, NULL); EXECUTE_TEST(execute_msg_check_test, tear_down); return result; } @@ -521,7 +519,7 @@ static int test_msg_check_no_protection_restrictive_cb(void) static int test_msg_check_no_protection_permissive_cb(void) { SETUP_TEST_FIXTURE(CMP_VFY_TEST_FIXTURE, set_up); - setup_check_update(&fixture, 1, allow_unprotected, 1, ir_rmprotection, NULL, NULL); + setup_check_update(&fixture, 1, allow_unprotected, 1, NULL, NULL); EXECUTE_TEST(execute_msg_check_test, tear_down); return result; } @@ -535,7 +533,7 @@ static int test_msg_check_transaction_id(void) }; SETUP_TEST_FIXTURE(CMP_VFY_TEST_FIXTURE, set_up); - setup_check_update(&fixture, 1, allow_unprotected, 1, ir_rmprotection, trans_id, NULL); + setup_check_update(&fixture, 1, allow_unprotected, 1, trans_id, NULL); EXECUTE_TEST(execute_msg_check_test, tear_down); return result; } @@ -544,22 +542,12 @@ static int test_msg_check_transaction_id(void) static int test_msg_check_transaction_id_bad(void) { SETUP_TEST_FIXTURE(CMP_VFY_TEST_FIXTURE, set_up); - setup_check_update(&fixture, 0, allow_unprotected, 1, ir_rmprotection, rand_data, NULL); + setup_check_update(&fixture, 0, allow_unprotected, 1, rand_data, NULL); EXECUTE_TEST(execute_msg_check_test, tear_down); return result; } #endif -static int test_msg_check_transaction_id_error(void) -{ - SETUP_TEST_FIXTURE(CMP_VFY_TEST_FIXTURE, set_up); - - (void)OSSL_CMP_CTX_set_option(fixture->cmp_ctx, OSSL_CMP_OPT_NONMATCHED_ERROR_NONCES, 1); - setup_check_update(&fixture, 1, allow_unprotected, 1, error_protected, rand_data, NULL); - EXECUTE_TEST(execute_msg_check_test, tear_down); - return result; -} - static int test_msg_check_recipient_nonce(void) { /* Recipient nonce belonging to CMP_IP_ir_rmprotection.der */ @@ -569,7 +557,7 @@ static int test_msg_check_recipient_nonce(void) }; SETUP_TEST_FIXTURE(CMP_VFY_TEST_FIXTURE, set_up); - setup_check_update(&fixture, 1, allow_unprotected, 1, ir_rmprotection, NULL, rec_nonce); + setup_check_update(&fixture, 1, allow_unprotected, 1, NULL, rec_nonce); EXECUTE_TEST(execute_msg_check_test, tear_down); return result; } @@ -578,23 +566,12 @@ static int test_msg_check_recipient_nonce(void) static int test_msg_check_recipient_nonce_bad(void) { SETUP_TEST_FIXTURE(CMP_VFY_TEST_FIXTURE, set_up); - setup_check_update(&fixture, 0, allow_unprotected, 1, ir_rmprotection, NULL, rand_data); + setup_check_update(&fixture, 0, allow_unprotected, 1, NULL, rand_data); EXECUTE_TEST(execute_msg_check_test, tear_down); return result; } #endif -/* Transaction id belonging to error_protected.der not needed here: */ -/* 0x5D, 0x90, 0x14, 0xB4, 0xBA, 0xAD, 0x6F, 0xCC, 0x36, 0x7B, 0xB8, 0x09, 0xB6, 0x98, 0xBF, 0x21 */ -static int test_msg_check_recipient_nonce_error(void) -{ - SETUP_TEST_FIXTURE(CMP_VFY_TEST_FIXTURE, set_up); - (void)OSSL_CMP_CTX_set_option(fixture->cmp_ctx, OSSL_CMP_OPT_NONMATCHED_ERROR_NONCES, 1); - setup_check_update(&fixture, 1, allow_unprotected, 1, error_protected, NULL, rand_data); - EXECUTE_TEST(execute_msg_check_test, tear_down); - return result; -} - void cleanup_tests(void) { X509_free(srvcert); @@ -607,7 +584,6 @@ void cleanup_tests(void) X509_free(instaca_cert); OSSL_CMP_MSG_free(ir_unprotected); OSSL_CMP_MSG_free(ir_rmprotection); - OSSL_CMP_MSG_free(error_protected); OSSL_PROVIDER_unload(default_null_provider); OSSL_PROVIDER_unload(provider); OSSL_LIB_CTX_free(libctx); @@ -619,7 +595,6 @@ void cleanup_tests(void) "Root_CA.crt Intermediate_CA.crt " \ "CMP_IR_protected.der CMP_IR_unprotected.der " \ "IP_waitingStatus_PBM.der IR_rmprotection.der " \ - "error_protected.der " \ "insta.cert.pem insta_ca.cert.pem " \ "IR_protected_0_extraCerts.der " \ "IR_protected_2_extraCerts.der module_name [module_conf_file]\n" @@ -653,16 +628,15 @@ int setup_tests(void) || !TEST_ptr(ir_unprotected_f = test_get_argument(7)) || !TEST_ptr(ip_waiting_f = test_get_argument(8)) || !TEST_ptr(ir_rmprotection_f = test_get_argument(9)) - || !TEST_ptr(error_protected_f = test_get_argument(10)) - || !TEST_ptr(instacert_f = test_get_argument(11)) - || !TEST_ptr(instaca_f = test_get_argument(12)) - || !TEST_ptr(ir_protected_0_extracerts = test_get_argument(13)) - || !TEST_ptr(ir_protected_2_extracerts = test_get_argument(14))) { + || !TEST_ptr(instacert_f = test_get_argument(10)) + || !TEST_ptr(instaca_f = test_get_argument(11)) + || !TEST_ptr(ir_protected_0_extracerts = test_get_argument(12)) + || !TEST_ptr(ir_protected_2_extracerts = test_get_argument(13))) { TEST_error("usage: cmp_vfy_test %s", USAGE); return 0; } - if (!test_arg_libctx(&libctx, &default_null_provider, &provider, 15, USAGE)) + if (!test_arg_libctx(&libctx, &default_null_provider, &provider, 14, USAGE)) return 0; /* Load certificates for cert chain */ @@ -683,8 +657,8 @@ int setup_tests(void) if (!TEST_int_eq(1, RAND_bytes(rand_data, OSSL_CMP_TRANSACTIONID_LENGTH))) goto err; if (!TEST_ptr(ir_unprotected = load_pkimsg(ir_unprotected_f, libctx)) - || !TEST_ptr(ir_rmprotection = load_pkimsg(ir_rmprotection_f, libctx)) - || !TEST_ptr(error_protected = load_pkimsg(error_protected_f, libctx))) + || !TEST_ptr(ir_rmprotection = load_pkimsg(ir_rmprotection_f, + libctx))) goto err; /* Message validation tests */ @@ -734,12 +708,10 @@ int setup_tests(void) #ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION ADD_TEST(test_msg_check_transaction_id_bad); #endif - ADD_TEST(test_msg_check_transaction_id_error); ADD_TEST(test_msg_check_recipient_nonce); #ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION ADD_TEST(test_msg_check_recipient_nonce_bad); #endif - ADD_TEST(test_msg_check_recipient_nonce_error); return 1; diff --git a/test/cms-msg/make_missing_kdf_der.py b/test/cms-msg/make_missing_kdf_der.py deleted file mode 100755 index 5b3fc0f6ee..0000000000 --- a/test/cms-msg/make_missing_kdf_der.py +++ /dev/null @@ -1,137 +0,0 @@ -#!/usr/bin/env python3 - -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -# This script generates missing-kdf.der - a password-encrypted CMS message -# without the keyDerivationAlgorithm field, which is used in the -# “PWRI missing keyDerivationAlgorithm regression†test. -# -# Usage: python3 make_missing_kdf_der.py valid.der missing-kdf.der - -from __future__ import annotations - -import argparse -import sys -from dataclasses import dataclass -from pathlib import Path - - -@dataclass -class Node: - off: int - tag: int - hdr_len: int - length: int - end: int - children: list["Node"] - - -def read_len(data: bytes, off: int) -> tuple[int, int]: - first = data[off] - if first < 0x80: - return first, 1 - n = first & 0x7F - if n == 0 or n > 4: - raise ValueError(f"unsupported DER length form at {off}") - val = 0 - for b in data[off + 1 : off + 1 + n]: - val = (val << 8) | b - return val, 1 + n - - -def parse_node(data: bytes, off: int) -> Node: - tag = data[off] - length, len_len = read_len(data, off + 1) - hdr_len = 1 + len_len - end = off + hdr_len + length - children: list[Node] = [] - if tag & 0x20: - cur = off + hdr_len - while cur < end: - child = parse_node(data, cur) - children.append(child) - cur = child.end - if cur != end: - raise ValueError(f"child parse ended at {cur}, expected {end}") - return Node(off=off, tag=tag, hdr_len=hdr_len, length=length, end=end, children=children) - - -def encode_len(length: int, existing_len_len: int) -> bytes: - if existing_len_len == 1: - if length >= 0x80: - raise ValueError("new length no longer fits in short-form DER") - return bytes([length]) - payload_len = existing_len_len - 1 - max_len = (1 << (payload_len * 8)) - 1 - if length > max_len: - raise ValueError("new length no longer fits in existing long-form DER") - out = bytearray([0x80 | payload_len]) - for shift in range((payload_len - 1) * 8, -8, -8): - out.append((length >> shift) & 0xFF) - return bytes(out) - - -def patch_length_field(buf: bytearray, node: Node, delta: int) -> None: - new_len = node.length + delta - if new_len < 0: - raise ValueError("negative patched length") - len_bytes = encode_len(new_len, node.hdr_len - 1) - start = node.off + 1 - end = start + len(node.hdr_len.to_bytes(1, "big")) - 1 # unused, kept for clarity - buf[start : start + len(len_bytes)] = len_bytes - - -def main() -> int: - ap = argparse.ArgumentParser(description="Remove PWRI keyDerivationAlgorithm from a CMS DER blob.") - ap.add_argument("input_der") - ap.add_argument("output_der") - args = ap.parse_args() - - data = Path(args.input_der).read_bytes() - root = parse_node(data, 0) - - # CMS structure we expect: - # SEQUENCE { OID envelopedData, [0] SEQUENCE { version, SET recipientInfos, ... } } - ed_wrapper = root.children[1] - env_seq = ed_wrapper.children[0] - recipient_set = env_seq.children[1] - pwri_choice = recipient_set.children[0] # [3] - - if pwri_choice.tag != 0xA3: - raise ValueError(f"expected PWRI choice tag 0xA3, found 0x{pwri_choice.tag:02x}") - if len(pwri_choice.children) < 3: - raise ValueError("unexpected PWRI child count") - - version = pwri_choice.children[0] - maybe_kdf = pwri_choice.children[1] - keyenc = pwri_choice.children[2] - if version.tag != 0x02: - raise ValueError("PWRI version is not INTEGER") - if maybe_kdf.tag != 0xA0: - raise ValueError(f"PWRI child after version is not [0] keyDerivationAlgorithm: 0x{maybe_kdf.tag:02x}") - if keyenc.tag != 0x30: - raise ValueError("PWRI keyEncryptionAlgorithm is not SEQUENCE") - - remove_start = maybe_kdf.off - remove_end = maybe_kdf.end - remove_len = remove_end - remove_start - - out = bytearray(data) - del out[remove_start:remove_end] - - # Adjust ancestors whose length spans the removed field. - for node in [root, ed_wrapper, env_seq, recipient_set, pwri_choice]: - patch_length_field(out, node, -remove_len) - - Path(args.output_der).write_bytes(out) - print(f"removed {remove_len} bytes at [{remove_start}, {remove_end})") - return 0 - - -if __name__ == "__main__": - sys.exit(main()) diff --git a/test/cms-msg/missing-kdf.der b/test/cms-msg/missing-kdf.der deleted file mode 100644 index 3db602e47c..0000000000 Binary files a/test/cms-msg/missing-kdf.der and /dev/null differ diff --git a/test/cmsapitest.c b/test/cmsapitest.c index e583b33f2c..88d519fd14 100644 --- a/test/cmsapitest.c +++ b/test/cmsapitest.c @@ -1,5 +1,5 @@ /* - * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2018-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -9,10 +9,10 @@ #include -#include #include #include #include +#include #include "../crypto/cms/cms_local.h" /* for d.signedData and d.envelopedData */ #include "testutil.h" @@ -20,193 +20,6 @@ static X509 *cert = NULL; static EVP_PKEY *privkey = NULL; static char *derin = NULL; -static char *too_long_iv_cms_in = NULL; -static char *pwri_kek_oob_der_in = NULL; - -/* - * This is our bad cms data, it contains an AuthEnvelopedData field - * with a CIPHER OID set to AES-256-OFB - */ -static const unsigned char bad_cms_der[452] = { - 0x30, 0x82, 0x01, 0xc0, 0x06, 0x0b, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, - 0x01, 0x09, 0x10, 0x01, 0x17, 0xa0, 0x82, 0x01, 0xaf, 0x30, 0x82, 0x01, - 0xab, 0x02, 0x01, 0x00, 0x31, 0x82, 0x01, 0x44, 0x30, 0x82, 0x01, 0x40, - 0x02, 0x01, 0x00, 0x30, 0x28, 0x30, 0x10, 0x31, 0x0e, 0x30, 0x0c, 0x06, - 0x03, 0x55, 0x04, 0x03, 0x0c, 0x05, 0x52, 0x65, 0x63, 0x69, 0x70, 0x02, - 0x14, 0x1a, 0x5c, 0x04, 0x9b, 0x3a, 0x64, 0xff, 0xd4, 0x63, 0xde, 0x4f, - 0x90, 0xe5, 0x76, 0xe2, 0x18, 0xe8, 0x5c, 0x9e, 0xd7, 0x30, 0x0d, 0x06, - 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x01, 0x05, 0x00, - 0x04, 0x82, 0x01, 0x00, 0x18, 0xcf, 0x9f, 0x44, 0x95, 0x79, 0xe9, 0x96, - 0x7d, 0x0f, 0xd1, 0xb4, 0xc2, 0x38, 0xb0, 0xc9, 0x76, 0xd5, 0xba, 0x08, - 0x5c, 0xbf, 0xc3, 0x30, 0xea, 0x3a, 0x68, 0xa4, 0xba, 0x99, 0x4c, 0x70, - 0x97, 0xb8, 0xa9, 0xce, 0x71, 0x4c, 0x54, 0xa3, 0xfd, 0x81, 0x9e, 0x15, - 0x63, 0xb7, 0x23, 0x46, 0x17, 0x69, 0xaf, 0x8f, 0xbd, 0xa3, 0x54, 0x23, - 0xf3, 0xf5, 0x35, 0xa8, 0xd4, 0x9c, 0xec, 0xe1, 0x17, 0x2c, 0x6d, 0x0b, - 0xad, 0xc0, 0xe9, 0x1d, 0xd1, 0x8d, 0x59, 0xd5, 0x29, 0xc6, 0x40, 0xc4, - 0xcd, 0x4e, 0x87, 0x70, 0x19, 0x5d, 0x88, 0x50, 0xbd, 0x4a, 0x13, 0xb3, - 0xef, 0x0c, 0x6d, 0x6a, 0xc5, 0x51, 0xbb, 0x5c, 0x39, 0x17, 0xda, 0xb1, - 0x71, 0x17, 0x88, 0xfb, 0x6a, 0xef, 0x7f, 0x85, 0xa7, 0x04, 0x71, 0xc7, - 0x83, 0x91, 0xb3, 0x30, 0x1b, 0x3d, 0x18, 0x7f, 0x63, 0xbf, 0x42, 0x7c, - 0xae, 0x6f, 0xae, 0xa1, 0x17, 0x84, 0xfd, 0x67, 0x2a, 0x4f, 0x4c, 0xe9, - 0x05, 0x26, 0x2c, 0xd5, 0xab, 0x0c, 0xcf, 0xdc, 0x3f, 0x24, 0xcf, 0x71, - 0x26, 0x7a, 0x1f, 0xf7, 0xc9, 0x92, 0x5e, 0xb6, 0x3d, 0x7f, 0xc3, 0x08, - 0xd3, 0xad, 0xc0, 0xc8, 0x4f, 0x42, 0x0c, 0xf3, 0xac, 0x23, 0x11, 0xdf, - 0x75, 0x84, 0x69, 0x8c, 0xa6, 0x59, 0x43, 0xfb, 0xf7, 0x6b, 0x62, 0xf0, - 0xf7, 0x35, 0x07, 0xc4, 0xf8, 0xd5, 0x12, 0x4a, 0x16, 0x62, 0xbc, 0x04, - 0xaa, 0x9a, 0x2e, 0xb2, 0x1a, 0xfa, 0x4c, 0x82, 0xce, 0x9e, 0xa8, 0x6d, - 0xc1, 0x29, 0x59, 0xe0, 0x33, 0xb5, 0xa6, 0x47, 0x09, 0x2e, 0xbf, 0x60, - 0xa6, 0xb3, 0x21, 0xa0, 0x15, 0xac, 0x92, 0x29, 0xb5, 0xe6, 0xe0, 0xd4, - 0x8b, 0xd8, 0x21, 0xe2, 0x17, 0x98, 0xd1, 0x11, 0x5d, 0xc5, 0xae, 0x24, - 0xe8, 0x92, 0xdb, 0x96, 0xa3, 0x5b, 0x58, 0xa7, 0x30, 0x4c, 0x06, 0x09, - 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x07, 0x01, 0x30, 0x1d, 0x06, - 0x09, 0x60, 0x86, 0x48, 0x01, 0x65, 0x03, 0x04, 0x01, 0x2b, 0x04, 0x10, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x80, 0x20, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, - 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, - 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, 0x41, - 0x41, 0x41, 0x04, 0x10, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 -}; - -/* - * This array represents a der encoded contentinfo structure addressed to - * servercert.pem, with the tag value of the aes-256-gcm cipher used to encrypt - * the contents of the mssages down to 1 byte. Decoding it should fail - */ -static const unsigned char one_byte_mac_cms_der[423] = { - 0x30, 0x82, 0x01, 0xa3, 0x06, 0x0b, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, - 0x01, 0x09, 0x10, 0x01, 0x17, 0xa0, 0x82, 0x01, 0x92, 0x30, 0x82, 0x01, - 0x8e, 0x02, 0x01, 0x00, 0x31, 0x82, 0x01, 0x33, 0x30, 0x82, 0x01, 0x2f, - 0x02, 0x01, 0x00, 0x30, 0x17, 0x30, 0x12, 0x31, 0x10, 0x30, 0x0e, 0x06, - 0x03, 0x55, 0x04, 0x03, 0x0c, 0x07, 0x52, 0x6f, 0x6f, 0x74, 0x20, 0x43, - 0x41, 0x02, 0x01, 0x02, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, - 0xf7, 0x0d, 0x01, 0x01, 0x01, 0x05, 0x00, 0x04, 0x82, 0x01, 0x00, 0x10, - 0x3a, 0x8c, 0xee, 0x4e, 0xe2, 0x1f, 0xfe, 0xcc, 0x28, 0x39, 0x9e, 0x46, - 0xbe, 0xa7, 0xd5, 0x02, 0x2a, 0x53, 0x06, 0x5f, 0x94, 0x6b, 0x69, 0x6d, - 0x2d, 0xe8, 0x44, 0xa6, 0x43, 0x52, 0x82, 0x89, 0x2d, 0xf1, 0x9b, 0xb9, - 0x9e, 0xa4, 0x8d, 0x77, 0xf1, 0xd2, 0x8e, 0x86, 0x79, 0x06, 0x3e, 0x90, - 0xf0, 0xca, 0x9e, 0xb5, 0x35, 0xd5, 0x89, 0xf0, 0x7c, 0x06, 0xa0, 0x91, - 0xbf, 0xf4, 0x61, 0xaa, 0x5c, 0x99, 0xa3, 0x64, 0x15, 0xfd, 0xf9, 0x90, - 0xf0, 0xf3, 0x25, 0x5b, 0x48, 0xa1, 0xfb, 0x7a, 0xce, 0x63, 0xdc, 0xa9, - 0xfe, 0x7c, 0xbe, 0x9c, 0xaa, 0xd3, 0x42, 0x0e, 0x4a, 0xc3, 0x4b, 0x4e, - 0x76, 0x6d, 0x52, 0x54, 0x85, 0x4e, 0xab, 0x50, 0x2c, 0x5f, 0xc2, 0x8b, - 0x9f, 0x1f, 0x0f, 0x8a, 0x7c, 0xb3, 0x0a, 0xde, 0x50, 0x9b, 0xef, 0x89, - 0xf2, 0xea, 0x07, 0xca, 0x11, 0x76, 0x29, 0xaf, 0xe4, 0x59, 0x28, 0x19, - 0x48, 0x96, 0x67, 0xdd, 0xdd, 0x01, 0xf0, 0x14, 0xbe, 0x3d, 0xa5, 0xa3, - 0x83, 0x21, 0x39, 0x29, 0xb7, 0x8f, 0xb7, 0xf4, 0x85, 0x05, 0xee, 0xca, - 0xbb, 0xbd, 0xc0, 0xaf, 0x0d, 0xf1, 0xef, 0x5f, 0x06, 0x05, 0xeb, 0x0e, - 0x55, 0xf0, 0x7e, 0x13, 0x1a, 0x2a, 0x37, 0xd4, 0xba, 0x26, 0xc8, 0x2e, - 0x6b, 0xc3, 0xe1, 0xcf, 0x28, 0xab, 0x0d, 0xab, 0xdd, 0xa7, 0xf4, 0xd3, - 0x59, 0xcd, 0xc7, 0x2d, 0xa1, 0x56, 0x5f, 0x47, 0x77, 0x27, 0x17, 0x71, - 0xae, 0x75, 0xc8, 0x71, 0x58, 0xf9, 0xab, 0x67, 0xda, 0x23, 0x62, 0xa0, - 0x6d, 0xe5, 0x2d, 0x06, 0xb8, 0xc0, 0xac, 0xaa, 0x38, 0xa4, 0x0d, 0xb5, - 0xb2, 0xce, 0xa7, 0x26, 0x0d, 0x3a, 0x88, 0x2f, 0x8d, 0x6c, 0xa0, 0xf6, - 0x94, 0xf2, 0x2c, 0x37, 0x03, 0xaf, 0x67, 0x5c, 0xf3, 0x2c, 0xfb, 0xe8, - 0x16, 0x9e, 0x55, 0x30, 0x4f, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, - 0x0d, 0x01, 0x07, 0x01, 0x30, 0x1e, 0x06, 0x09, 0x60, 0x86, 0x48, 0x01, - 0x65, 0x03, 0x04, 0x01, 0x2e, 0x30, 0x11, 0x04, 0x0c, 0x6b, 0x1d, 0xe5, - 0xb2, 0x38, 0x0e, 0x17, 0x91, 0x9c, 0x9c, 0x40, 0x35, 0x02, 0x01, 0x10, - 0x80, 0x22, 0xa0, 0x90, 0x75, 0x74, 0xdf, 0x2d, 0xba, 0x4f, 0xce, 0x4e, - 0x7e, 0x52, 0xb0, 0x2e, 0x5f, 0xe0, 0x84, 0x01, 0xb1, 0x49, 0x0b, 0x69, - 0xc7, 0x61, 0x63, 0x84, 0x3a, 0xfc, 0xaa, 0x86, 0xfc, 0x96, 0x4e, 0x6c, - 0x04, 0x01, 0x92 -}; - -static int test_short_mac_on_auth_envelope_data(void) -{ - int ret = 0; - const unsigned char *derptr = one_byte_mac_cms_der; - BIO *outmsgbio = BIO_new(BIO_s_mem()); - CMS_ContentInfo *content = d2i_CMS_ContentInfo(NULL, &derptr, OSSL_NELEM(one_byte_mac_cms_der)); - - if (!TEST_ptr(content)) - goto end; - - /* - * We expect this to fail, as the tag value in the authEnvelopedData parameter is - * a single byte - */ - if (!TEST_false(CMS_decrypt(content, privkey, cert, NULL, outmsgbio, CMS_TEXT))) - goto end; - - ret = 1; -end: - BIO_free(outmsgbio); - CMS_ContentInfo_free(content); - return ret; -} - -static int test_non_aead_on_auth_envelope_dec(void) -{ - int ret = 0; - const unsigned char *derptr = bad_cms_der; - BIO *outmsgbio = BIO_new(BIO_s_mem()); - CMS_ContentInfo *content = d2i_CMS_ContentInfo(NULL, &derptr, OSSL_NELEM(bad_cms_der)); - - if (!TEST_ptr(content)) - goto end; - - /* - * We expect this to fail - */ - if (!TEST_false(CMS_decrypt(content, privkey, cert, NULL, outmsgbio, - CMS_TEXT))) - goto end; - - ret = 1; -end: - BIO_free(outmsgbio); - CMS_ContentInfo_free(content); - return ret; -} - -static int test_non_aead_on_auth_envelope_enc(void) -{ - CMS_ContentInfo *content = NULL; - STACK_OF(X509) *certstack = sk_X509_new_null(); - const EVP_CIPHER *cipher = EVP_aes_128_cbc(); - const char *msg = "Hello world"; - BIO *msgbio = BIO_new_mem_buf(msg, (int)strlen(msg)); - BIO *outmsgbio = BIO_new(BIO_s_mem()); - X509 *recip; - int i; - int ret = 0; - - if (!TEST_ptr(certstack) || !TEST_ptr(msgbio) || !TEST_ptr(outmsgbio)) - goto end; - - if (!TEST_int_gt(sk_X509_push(certstack, cert), 0)) - goto end; - - /* - * Emulate CMS_encrypt here, but use a non AEAD cipher - */ - content = CMS_AuthEnvelopedData_create_ex(cipher, NULL, NULL); - - if (!TEST_ptr(content)) - goto end; - - for (i = 0; i < sk_X509_num(certstack); i++) { - recip = sk_X509_value(certstack, i); - if (!TEST_ptr(CMS_add1_recipient_cert(content, recip, CMS_TEXT))) - goto end; - } - - /* - * We expect this to fail as we are using a non-AEAD cipher on - * AuthEnvelopedData - */ - if (!TEST_int_eq(CMS_final(content, msgbio, NULL, CMS_TEXT), 0)) - goto end; - - ret = 1; -end: - sk_X509_free(certstack); - BIO_free(msgbio); - BIO_free(outmsgbio); - CMS_ContentInfo_free(content); - return ret; -} static int test_encrypt_decrypt(const EVP_CIPHER *cipher) { @@ -666,80 +479,7 @@ end: return ret; } -static int test_cms_aesgcm_iv_too_long(void) -{ - int ret = 0; - BIO *cmsbio = NULL, *out = NULL; - CMS_ContentInfo *cms = NULL; - unsigned long err = 0; - - if (!TEST_ptr(cmsbio = BIO_new_file(too_long_iv_cms_in, "r"))) - goto end; - - if (!TEST_ptr(cms = PEM_read_bio_CMS(cmsbio, NULL, NULL, NULL))) - goto end; - - /* Must fail cleanly (no crash) */ - if (!TEST_false(CMS_decrypt(cms, privkey, cert, NULL, out, 0))) - goto end; - err = ERR_peek_last_error(); - if (!TEST_ulong_ne(err, 0)) - goto end; - if (!TEST_int_eq(ERR_GET_LIB(err), ERR_LIB_CMS)) - goto end; - if (!TEST_int_eq(ERR_GET_REASON(err), CMS_R_CIPHER_PARAMETER_INITIALISATION_ERROR)) - goto end; - - ret = 1; -end: - CMS_ContentInfo_free(cms); - BIO_free(cmsbio); - BIO_free(out); - return ret; -} - -/* - * CMS EnvelopedData with a single PasswordRecipientInfo using - * id-alg-PWRI-KEK and an AES-128-CFB key encryption cipher - * (1-byte effective block size). The encryptedKey OCTET STRING is - * only two bytes long, so the wrapped key buffer is shorter than - * the seven octets read by the check-byte test in kek_unwrap_key(). - * Prior to CVE-2026-9076 this triggered an out-of-bounds heap read; - * CMS_decrypt() must now fail cleanly. - */ -static int test_pwri_kek_unwrap_short_encrypted_key(void) -{ - BIO *in = NULL; - CMS_ContentInfo *cms = NULL; - unsigned long err = 0; - int ret = 0; - - if (!TEST_ptr(in = BIO_new_file(pwri_kek_oob_der_in, "rb")) - || !TEST_ptr(cms = d2i_CMS_bio(in, NULL))) - goto end; - - /* - * The unwrap is attempted eagerly inside CMS_decrypt_set1_password(). - * It must fail cleanly (no OOB read) and report CMS_R_UNWRAP_FAILURE. - */ - if (!TEST_false(CMS_decrypt_set1_password(cms, - (unsigned char *)"password", -1))) - goto end; - - err = ERR_peek_last_error(); - if (!TEST_int_eq(ERR_GET_LIB(err), ERR_LIB_CMS) - || !TEST_int_eq(ERR_GET_REASON(err), CMS_R_UNWRAP_FAILURE)) - goto end; - - ERR_clear_error(); - ret = 1; -end: - CMS_ContentInfo_free(cms); - BIO_free(in); - return ret; -} - -OPT_TEST_DECLARE_USAGE("certfile privkeyfile derfile tooLongIVpem pwriKekOobDer\n") +OPT_TEST_DECLARE_USAGE("certfile privkeyfile derfile\n") int setup_tests(void) { @@ -753,9 +493,7 @@ int setup_tests(void) if (!TEST_ptr(certin = test_get_argument(0)) || !TEST_ptr(privkeyin = test_get_argument(1)) - || !TEST_ptr(derin = test_get_argument(2)) - || !TEST_ptr(too_long_iv_cms_in = test_get_argument(3)) - || !TEST_ptr(pwri_kek_oob_der_in = test_get_argument(4))) + || !TEST_ptr(derin = test_get_argument(2))) return 0; certbio = BIO_new_file(certin, "r"); @@ -785,17 +523,12 @@ int setup_tests(void) ADD_TEST(test_encrypt_decrypt_aes_128_gcm); ADD_TEST(test_encrypt_decrypt_aes_192_gcm); ADD_TEST(test_encrypt_decrypt_aes_256_gcm); - ADD_TEST(test_non_aead_on_auth_envelope_enc); - ADD_TEST(test_non_aead_on_auth_envelope_dec); - ADD_TEST(test_short_mac_on_auth_envelope_data); ADD_TEST(test_CMS_add1_cert); ADD_TEST(test_d2i_CMS_bio_NULL); ADD_TEST(test_CMS_set1_key_mem_leak); ADD_TEST(test_encrypted_data); ADD_TEST(test_encrypted_data_aead); ADD_ALL_TESTS(test_d2i_CMS_decode, 2); - ADD_TEST(test_cms_aesgcm_iv_too_long); - ADD_TEST(test_pwri_kek_unwrap_short_encrypted_key); return 1; } diff --git a/test/crltest.c b/test/crltest.c index 15fdef3f3c..d2bbc1d9b8 100644 --- a/test/crltest.c +++ b/test/crltest.c @@ -1,5 +1,5 @@ /* - * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -7,6 +7,8 @@ * https://www.openssl.org/source/license.html */ +#include "internal/nelem.h" +#include #include #include #include @@ -16,370 +18,6 @@ #include "testutil.h" -/* - * Test fixtures for certificate chain and CRL validation. - * - * This dataset contains: - * - a root CA certificate with the corresponding private key - * - a leaf certificate with the corresponding private key - * - several CRLs representing valid, invalid, and malformed revocation data - * - * The availability of the private keys allows additional certificates, CRLs, or - * related artifacts to be generated within the same chain. This makes it - * straightforward to add new test cases or regenerate existing ones if the - * validation logic or expected behavior changes. - * - * Root CA (self-signed, trust anchor) - * └── leaf (signed by Root CA) - * - * The hierarchy is intentionally flat, no intermediate CA. Chain - * building is trivial: the leaf is verified directly against the root, - * and every CRL is issued directly by the root. No -untrusted store or - * additional lookup callbacks are required in the test code. - * - * Root CA: CN=Example Corp Root CA - * RSA-2048, SHA-256, validity 10 years, pathlen:0 - * - * Leaf: CN=www.example.com, serial 0x1000 - * RSA-2048, SHA-256, validity 1 year - * SANs: www.example.com, example.com, api.example.com, 127.0.0.1 - * CRL Distribution Point: http://crl.example.com/root.crl - * - * All CRLs were produced and signed with kRoot. Every malformed CRL carries a - * valid RSA-2048/SHA-256 signature — the defect is structural or semantic, not - * cryptographic. - */ - -/* Verification time. */ -static time_t kVerify = 1775779200; /* 2026-04-10 00:00:00 UTC */ - -static const char *kRoot[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIIEFjCCAv6gAwIBAgIUQR1kHB+/IzJcfAT/HHVPp+wPmxwwDQYJKoZIhvcNAQEL\n", - "BQAwgZAxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRYwFAYDVQQH\n", - "DA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQKDAxFeGFtcGxlIENvcnAxHjAcBgNVBAsM\n", - "FUNlcnRpZmljYXRlIEF1dGhvcml0eTEdMBsGA1UEAwwURXhhbXBsZSBDb3JwIFJv\n", - "b3QgQ0EwHhcNMjYwMzEwMTEzMDUzWhcNMzYwMzA3MTEzMDUzWjCBkDELMAkGA1UE\n", - "BhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWExFjAUBgNVBAcMDVNhbiBGcmFuY2lz\n", - "Y28xFTATBgNVBAoMDEV4YW1wbGUgQ29ycDEeMBwGA1UECwwVQ2VydGlmaWNhdGUg\n", - "QXV0aG9yaXR5MR0wGwYDVQQDDBRFeGFtcGxlIENvcnAgUm9vdCBDQTCCASIwDQYJ\n", - "KoZIhvcNAQEBBQADggEPADCCAQoCggEBALm21ITU+2o6ZHWukCyBw9H270fSABYT\n", - "rl8lhPCcTXynW9tBeHAaV50WMiOxBl+thfv1fGS3t8BbyjEjP3I5LAkBS9dTUI7F\n", - "PSQnngBgKvKrpsnsiJXVhNOISm6GfT/EXj1NWKLXR3MXGIGfiVud5ln9CQxzaq3e\n", - "TzW8X8zsdv6WGaeRIBm48QYe8TkK/TDmvoYZ7fD9lPMk3AUoNasZfuPeGpzh1cBR\n", - "bfvOYEHJQ31+GFzrJFldqoaq/k0If/khwVgjOdmF+R25OCF0jsrMjmZ42Qr2cNrd\n", - "VYEIjQL2R1grCVCGaIagzQuyN0Qvvl5BXsHKI51TpDQlq9SFkCOvRckCAwEAAaNm\n", - "MGQwHQYDVR0OBBYEFP4UDhMbCWfLSg1L2k/z75C1Q9szMB8GA1UdIwQYMBaAFP4U\n", - "DhMbCWfLSg1L2k/z75C1Q9szMBIGA1UdEwEB/wQIMAYBAf8CAQAwDgYDVR0PAQH/\n", - "BAQDAgEGMA0GCSqGSIb3DQEBCwUAA4IBAQBcYi8b4tetG18ElSqF/CJkjm93xS6k\n", - "tk4jia0k+79FSAvy/TlcarBAe3PwlLA7GcLYDUmmM7GCiEMf91+c6dOmKkIdbw1B\n", - "FILQBnghZ9s+xl0+n1P0775dDWc0msXhXci/wcRK3HFqxEOXQUkDYZwrq1gXBESr\n", - "6yjpYe2RFKQUdnW+yrMlY1QyGNhelV7//BbSG8fD1esU7VaBE0wF/b8Ly2ykK5QE\n", - "d6XUwqTT6sIlcyxVGUgEMVj7kSZUQJ2LS/ze/r+a1FeC2I0UljD78UB+I40FafZe\n", - "pLLvkABIXRqtOiZ5YkdEK3Z4xI0yqSZC3og4jHsoCrfWbXasRieYR7dT\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -static const char *kRoot2[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIID+TCCAuGgAwIBAgIBATANBgkqhkiG9w0BAQsFADCBizELMAkGA1UEBhMCVVMx\n", - "DzANBgNVBAgMBk5ldmFkYTENMAsGA1UEBwwEUmVubzEZMBcGA1UECgwQRXhhbXBs\n", - "ZSBBbHQgQ29ycDEeMBwGA1UECwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MSEwHwYD\n", - "VQQDDBhFeGFtcGxlIEFsdCBDb3JwIFJvb3QgQ0EwHhcNMjYwMzEwMTIwMDAwWhcN\n", - "MzYwMzA3MTIwMDAwWjCBizELMAkGA1UEBhMCVVMxDzANBgNVBAgMBk5ldmFkYTEN\n", - "MAsGA1UEBwwEUmVubzEZMBcGA1UECgwQRXhhbXBsZSBBbHQgQ29ycDEeMBwGA1UE\n", - "CwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MSEwHwYDVQQDDBhFeGFtcGxlIEFsdCBD\n", - "b3JwIFJvb3QgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDTXGOg\n", - "+elQT/IKNp8xbArzGmuwLlLMTc1UQNIGzYj8OZc8newhzwIiXltw0ifGYlTZV6Gv\n", - "xP/8V8Xwo0rroGpaizVtUmKwbKKzfisA4Ph3zGdGS2B6nOk1La1eZQJ46KkxabPY\n", - "4QHvZb4No0GKv0par2W/SfjOTl4Dw5hjmx6Q0lLAJVdkiFn+czyLyUZX7a8LdZWe\n", - "WTa24IOJWmNdbubre7U0u199gywuR9gCXP7vEb5vWz2xAQNB5B2JK3smt3QDm9Ob\n", - "6z/VKwa55rk1GVV8TDWrCZPj1VzdHKbjbmH9DnT1fyIibXE/o+gz5pgZq2XFTNp0\n", - "nKwAchvSxkGVK+cTAgMBAAGjZjBkMBIGA1UdEwEB/wQIMAYBAf8CAQAwDgYDVR0P\n", - "AQH/BAQDAgEGMB0GA1UdDgQWBBQPgimZbVczHuIhFVMrP0PefsYhazAfBgNVHSME\n", - "GDAWgBQPgimZbVczHuIhFVMrP0PefsYhazANBgkqhkiG9w0BAQsFAAOCAQEAD0Kx\n", - "6fKrMoOJd8NUAFPaAvtlMpu9cmFDEuIsoXN9waA3FkXeHd/tijktefexvZDz0s/F\n", - "sQBsW6rNOSeHteiROVRdBIm9sok0onA5LrHIXOeEF0CLJTk7RKrUfd8fbVxgEB8U\n", - "VpZjzpTcxES2BMy9qzFyj/lLsoqNBV1GqFVzZY7mTzsze6Xwi80uahIoANVf/wwk\n", - "Zq72Frquut7Ii0QrhExx++wRKZvSHN4T5eKu3se7m2s9Vmw2/dNGejKMp6pnlcCH\n", - "m97X57r4QWOX0BeLm7cp/FW7/4KMPdV4GkDJBWaI5i9ktPlO7MOKHmrKZSUW9xN2\n", - "D+feJXhQmaz8AcFA6Q==\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -/* gitguardian:ignore */ -static const char *kRootPrivateKey[] = { - "-----BEGIN PRIVATE KEY-----\n", - "MIIEuwIBADANBgkqhkiG9w0BAQEFAASCBKUwggShAgEAAoIBAQC5ttSE1PtqOmR1\n", - "rpAsgcPR9u9H0gAWE65fJYTwnE18p1vbQXhwGledFjIjsQZfrYX79Xxkt7fAW8ox\n", - "Iz9yOSwJAUvXU1COxT0kJ54AYCryq6bJ7IiV1YTTiEpuhn0/xF49TVii10dzFxiB\n", - "n4lbneZZ/QkMc2qt3k81vF/M7Hb+lhmnkSAZuPEGHvE5Cv0w5r6GGe3w/ZTzJNwF\n", - "KDWrGX7j3hqc4dXAUW37zmBByUN9fhhc6yRZXaqGqv5NCH/5IcFYIznZhfkduTgh\n", - "dI7KzI5meNkK9nDa3VWBCI0C9kdYKwlQhmiGoM0LsjdEL75eQV7ByiOdU6Q0JavU\n", - "hZAjr0XJAgMBAAECgf9u3uJWatBYcC6JaIL/ZHkDYJMkIrrqcyrRTWo65cAHgI0r\n", - "gxU5LSt2cfR9BQeebHm7cf2mzgdlT2c7mU9yDFpoWzMWhHwTaq1AaGZrfajQ4f6G\n", - "ONqnQ6bd96p3/CfKFJwuUiltuMLEctquiA/4zMuN7az5Qe5DiUoV9TU8TJoTDNo9\n", - "72b4lqv5ptORlcu0JCPedlfXWVue3HfX0RUXr1kz6TWi+TRYRz+t3oPj1f/XyWSJ\n", - "RzmjKgG0orOPfN6XFeS8/vSglE73K1rosYJZ9YIvoxw63ID1eCGY8nlc3Wz99tpt\n", - "dE0qiNht+2O2wt2DR0VQCUhnAmj8l0UDLPUcGbkCgYEA3BTBbCsjwvxiApddPYDx\n", - "rwtxH7evdPPmZ+PofnGEKWL/eghBHy+arMhGt6zbJ6aTUfjmvz+nIpbs4SiGijEx\n", - "NWRyLtUcRCdhSNj/4c4sNT5biRBFaogGVUi/BxO3lXxx43Kw04hLSuch2vAXN4OZ\n", - "eQnWHB3zyijUUzcEayiRiv0CgYEA2AYvfwvpQBPOA8I17qmkXMrjonGnr0NGHzLq\n", - "+PtwTZhxnkR6dCXR9OtOYcvlo8aGb91zETYYR2MU0ArJRBj5gerxfG7/c0gthaAI\n", - "xgmFgNXLTEsj7lY8MGedbxTsahJYiN/U61W1zZQ+B2lW7bBCpD1w8CZjPJkikxFz\n", - "y3KBHb0CgYBLkxEMvQ+twI9DhojtOt9DlfFFzAUDa1HesSPAb+jLcYR7emQqemVq\n", - "Geg24LPtPMVwK8HJQOl69krn0svInrXgONsA/AuV19QPePz9pJgHvJ8gRSchOw65\n", - "sJ5wprOvMKnHSjYwnagFU7OLhFDkrltAdkFBLIPwEu8+mDD7P1YjXQKBgQCxMrG3\n", - "JxAXracp0h7nPGREcXC0CUKhMy/L27p+rdF69PcN+eHwcC1/F51d/yDJbMlN7Xq7\n", - "vYHA3Pdvh8l8gHf6J7wac/o6mBQvLgzEVX8bJUPzuxcoI7iPhA7R1XnvsEjLTb+b\n", - "otzUWytebPwPUKv5iSSg+Pwh8wM3W/N+CNj8iQKBgGQfG/6793AHJ2G+uhotwAv4\n", - "7PCC7qnZ6Cj5n/HwfjMTe+U6EzsRsZ6qmY+cCuXp5xUOFHVJPMQJTzwOG2WoyEdo\n", - "qXVWEwK9CXZlZgvj5BwdA17qKGjj6RejIiiHsJ7K48H82idUixj4M8BLBg0Ff160\n", - "rZXnLhJEdTFhSZGRXJgu\n", - "-----END PRIVATE KEY-----\n", - NULL -}; - -static const char *kLeaf[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIIEajCCA1KgAwIBAgICEAAwDQYJKoZIhvcNAQELBQAwgZAxCzAJBgNVBAYTAlVT\n", - "MRMwEQYDVQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUw\n", - "EwYDVQQKDAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhv\n", - "cml0eTEdMBsGA1UEAwwURXhhbXBsZSBDb3JwIFJvb3QgQ0EwHhcNMjYwMzEwMTE0\n", - "NjUzWhcNMjcwMzEwMTE0NjUzWjBqMQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2Fs\n", - "aWZvcm5pYTEVMBMGA1UECgwMRXhhbXBsZSBDb3JwMRUwEwYDVQQLDAxXZWIgU2Vy\n", - "dmljZXMxGDAWBgNVBAMMD3d3dy5leGFtcGxlLmNvbTCCASIwDQYJKoZIhvcNAQEB\n", - "BQADggEPADCCAQoCggEBAKSuf+LYfmahQUGet4JsLlvfE3WvcHCCtufFZu2hzt1K\n", - "gqvwKWimmCVMlmpuzSoNyLn+xdTYDtXyiP/M52aep3+tgUZvdWv7kxCVu8728RWO\n", - "mSasl+gqXLulP7C7ZIxSG+0APz9Y5ApafL+ykxAK0dprMYkB49S3Phn5uiULjBWc\n", - "Es9gLqzsr/zvRB0qN9Ly3at2XiZJzjfmkXB0OA0VFswxGl6HG3kIzLzs4YJgoOZd\n", - "UZO2jGaOgp+rVPQvuVJVefUrYlyaLGd9Dt/YKPoxhlnvEK3khYz69dPHCwaCZXwz\n", - "sJdaqYE2p7Us26ce3rEnWcz6gUIe//VQRohSEq0fZbUCAwEAAaOB8jCB7zAdBgNV\n", - "HQ4EFgQU7Y2XD9s8Xb5gnFtGbfrjd8ICMZowHwYDVR0jBBgwFoAU/hQOExsJZ8tK\n", - "DUvaT/PvkLVD2zMwDAYDVR0TAQH/BAIwADAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0l\n", - "BBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMD4GA1UdEQQ3MDWCD3d3dy5leGFtcGxl\n", - "LmNvbYILZXhhbXBsZS5jb22CD2FwaS5leGFtcGxlLmNvbYcEfwAAATAwBgNVHR8E\n", - "KTAnMCWgI6Ahhh9odHRwOi8vY3JsLmV4YW1wbGUuY29tL3Jvb3QuY3JsMA0GCSqG\n", - "SIb3DQEBCwUAA4IBAQB2BnaCrEzcEACF0hMx79MFn+6w2qq168mOO1fKKtn78N4i\n", - "Fvdt17J8aJB9A4O7G7Qt+sJc7/g9U4h9vgNZ0d/RruA5qTNiyfOqCpUrZQawfoP7\n", - "ZbGq1owzSNPzC2XDt2W+V3mw7/lnJl29H/799ckd0tL3tdg9exqHYJTWRoO5H1CI\n", - "BCeOSvFxuHr48INiPRAqrI67aTsr9PWtUnPuKfW26eQYAt7M8bkMNu2tzEs01/A7\n", - "HkZXNWRfS6H+P+hshnrNS8TXdonHODbqU8DvGhgtBDIg4VForc4yfxzoCSXfidd/\n", - "/5VYiKF/M+F+UWklBm4ij0xf6o7HkjlfyukN5TjN\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -/* gitguardian:ignore */ -static const char *kLeafPrivateKey[] = { - "-----BEGIN PRIVATE KEY-----\n", - "MIIEvgIBADANBgkqhkiG9w0BAQEFAASCBKgwggSkAgEAAoIBAQCkrn/i2H5moUFB\n", - "nreCbC5b3xN1r3BwgrbnxWbtoc7dSoKr8CloppglTJZqbs0qDci5/sXU2A7V8oj/\n", - "zOdmnqd/rYFGb3Vr+5MQlbvO9vEVjpkmrJfoKly7pT+wu2SMUhvtAD8/WOQKWny/\n", - "spMQCtHaazGJAePUtz4Z+bolC4wVnBLPYC6s7K/870QdKjfS8t2rdl4mSc435pFw\n", - "dDgNFRbMMRpehxt5CMy87OGCYKDmXVGTtoxmjoKfq1T0L7lSVXn1K2JcmixnfQ7f\n", - "2Cj6MYZZ7xCt5IWM+vXTxwsGgmV8M7CXWqmBNqe1LNunHt6xJ1nM+oFCHv/1UEaI\n", - "UhKtH2W1AgMBAAECggEAJouPdF2e7E+nEgBfzH+ctDU4/U00gKkfvYz3Q/yhCiuz\n", - "/SGH165SozxTYpMPo125k0s+K8zsYAhWJ6ViriLJarmGLiHNdppaOEILxOwIzrZj\n", - "Q2mXXqh3rxYFG80owi0/yw/JPf8E1SWL2GSoRlN5/ekkHYDbPkEroHHSr3QN9EqE\n", - "fALsLA1y4Kt3gpTlZ3X9wHrZRhB1WW8/LYbNfA4WGZZDMzYQEdUp5SX0BobVkrAU\n", - "HaCew75jhXtPjT424JjRqmIE+gK04oVx2TXKLQnEHTjPivvfrOuE+ne2syn1tZIS\n", - "tXCZYy0gg2ElyatzhOAGTx0FMWkftVYnJ4BIF3hh8QKBgQDjwn37UmXRPM11J0vT\n", - "LK1MGkMUBCP//yFfH+CyJ5JkTsmsrXoNox182cixIUnlkK3eRm5ilwXYmu+yMv3J\n", - "3hC1KJDUK+BJfIfPw10OIN9bGJdzmOujM6P/kw1KluZQLSDDQ/FI/Rv8KZTxcgmu\n", - "nM807oFQMVbXsFUeHyHEi5xpnQKBgQC5GctGeKG1BJFSKONs1FfjuA8SAosVddVi\n", - "CD8pBmL16ytinnJgUoxdaJBJ58M11unj1x7I7wPVGmgGC2xLadOQM18C+qJbUx/2\n", - "y6VL4kaK5la1Php+OAI1dmCYuggHiBqKd/r1IF7u3Co5WW+Fmtb6Faqk69xS6zBF\n", - "Q3TA2tWc+QKBgQCAGHP4dHg1POgk+qvnohn5Uk/lowqIQPqI4InkSONJrRI6Hvsl\n", - "TlcYT/hSvvErvro66AvPQTcVgtZKt+kKru1gpecGnYKwceyESlE8z/ou5t7PMfNd\n", - "P37+D7uK9uGjuC3UBJNgxJIHuW8+eC+/2AulrnpmGsnH1zGYFlRMkWSv9QKBgBqB\n", - "uBtiYP3UJp9WXaMTEXb5v6a7mIE9O45rUeglEvzWbYMU35otmA40UB1VRB4spZfM\n", - "EYuCttDIlEbxUdPG1tYalSuPCrr7P2OPLB+eyq1PaPFRcGfMy3wudIzKbyXs9qgH\n", - "oHeD6DRacO1/gjnmv4xWl/ZAFHAHYAU7MLgBXn+5AoGBAJIp58yKL03CrXfzQA0y\n", - "D1bbuvbBA902XBuBXaFfBPw8JwcmhmyF/ipYffwQBg7l00JKYC5ASv0zV5LQaaFl\n", - "S672xAaFwhlZXU6FVm6tRFPHTAz4petGVO/o3E3AABl31ABxxOvB3dRUnQJkQ9Eb\n", - "UjtDosbWW3y64bplzfgGZS0n\n", - "-----END PRIVATE KEY-----\n", - NULL -}; - -static const char *kCrlRecovated[] = { - "-----BEGIN X509 CRL-----\n", - "MIICUjCCAToCAQEwDQYJKoZIhvcNAQELBQAwgZAxCzAJBgNVBAYTAlVTMRMwEQYD\n", - "VQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQK\n", - "DAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEd\n", - "MBsGA1UEAwwURXhhbXBsZSBDb3JwIFJvb3QgQ0EXDTI2MDMxMDA4MDAwMFoXDTI2\n", - "MDYwODA4MDAwMFowRDAgAgEBFw0yNjAyMDgwODAwMDBaMAwwCgYDVR0VBAMKAQEw\n", - "IAIBAhcNMjYwMjA4MDgwMDAwWjAMMAoGA1UdFQQDCgEEoC8wLTAfBgNVHSMEGDAW\n", - "gBT+FA4TGwlny0oNS9pP8++QtUPbMzAKBgNVHRQEAwIBAzANBgkqhkiG9w0BAQsF\n", - "AAOCAQEAZAlvLBRuoem3rlI0QbC9SlYe5yKRGRXNYqpe8fQ4vB0IuGp3jqADecxD\n", - "qjuJClAhwijra2FYr6oPZ79EXeqiMKXb3AXYJ0x2WhKFyf4AuaiGjXULHUweSDL1\n", - "F7Rjx/3vX4zRmQMDc/FXm3TK9OUjcNYdOERu7dzHhjUR+c0/nNG9g9Zjg9iAXCyQ\n", - "dgkiRkFuorvnM1xTs7BVy2A+uM3FXfe5wE4plYBnVHOKJPWGmSYJu9PbweHSqaci\n", - "cR5kb5IeDXiIjKYPimaeVxnZdoA8MzasOv9GnDWrNmuq55t3v7apic9x7/L85EDc\n", - "LPVUUd5Y0tewL68R7vM96wGtZ+GLHg==\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kCrlExtensionDuplicate[] = { - "-----BEGIN X509 CRL-----\n", - "MIICPTCCASUCAQEwDQYJKoZIhvcNAQELBQAwgZAxCzAJBgNVBAYTAlVTMRMwEQYD\n", - "VQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQK\n", - "DAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEd\n", - "MBsGA1UEAwwURXhhbXBsZSBDb3JwIFJvb3QgQ0EXDTI2MDMxMDA4MDAwMFoXDTI2\n", - "MDYwODA4MDAwMFowIzAhAgIQABcNMjYwMzA5MDgwMDAwWjAMMAoGA1UdFQQDCgEB\n", - "oDswOTAfBgNVHSMEGDAWgBT+FA4TGwlny0oNS9pP8++QtUPbMzAKBgNVHRQEAwIB\n", - "DDAKBgNVHRQEAwIBYzANBgkqhkiG9w0BAQsFAAOCAQEAGfTawbm18r/wEiCoCNok\n", - "i1dPdoZIm6ZK+NUL09SYmdQm99D3UqaXDkBMu5j524ozKwr+wkRZcAd2Q+mJKXAt\n", - "TAO+geiDrhDRdjC+B04KPhvZnqWQsvLCxhU6kmCM34bHxUHTGltMbQxx96TqEsbn\n", - "1TLn4iN6WPyYyRolIPPy5bPymTCV7vTPeyZhZYNPv2xZwDSS50rFIQFr+H1/PyUY\n", - "OxRqBmdYOwbfNn0L7SOkAzP+OStK+0krtFWSRIp+aBCfDvsdXQFy3P4C8IVwiGQY\n", - "ld2Dcfnr13EzzD2XaNJ2cqPdiSGso9fXwLGpn+9SvqzFwdS2QyV5eolbhe5ZiNjO\n", - "0Q==\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kCrlExtensionDuplicateEntry[] = { - "-----BEGIN X509 CRL-----\n", - "MIICYDCCAUgCAQEwDQYJKoZIhvcNAQELBQAwgZAxCzAJBgNVBAYTAlVTMRMwEQYD\n", - "VQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQK\n", - "DAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEd\n", - "MBsGA1UEAwwURXhhbXBsZSBDb3JwIFJvb3QgQ0EXDTI2MDMxMDA4MDAwMFoXDTI2\n", - "MDYwODA4MDAwMFowUjAtAgIQABcNMjYwMzA5MDgwMDAwWjAYMAoGA1UdFQQDCgEB\n", - "MAoGA1UdFQQDCgEBMCECAhABFw0yNjAzMDkwODAwMDBaMAwwCgYDVR0VBAMKAQSg\n", - "LzAtMB8GA1UdIwQYMBaAFP4UDhMbCWfLSg1L2k/z75C1Q9szMAoGA1UdFAQDAgEL\n", - "MA0GCSqGSIb3DQEBCwUAA4IBAQCRInhKVl+Hz4Ukacr7lSCHyir2cFoOqC5H5pye\n", - "f9CP3M8fa4oIwv0FFAVwHT/E+6ko2id7qqVdADFql+koVY7DBXIqrQ1qcAoGyclm\n", - "n/UEEbs2UdbqJiVzlurh5jupExYSj2uJo8ZYONhnqKnDzPfpyvBmfE7/X/wPla6P\n", - "nSGDg4kYC3mtjrIUBwCqxn3WOG7Ai2WtpRvtCtNzhlEddroOonIS36Bh3c0T+dNT\n", - "lsvIKfqkfZazv26F1vDFEYS+L7yrzRnhD2eHvX+9xYtotnzwUhPCMuXLbp9sttDu\n", - "9SD2VaXnw/5olvv15CSvlw661kh0CQrHydCgRXVxgJX5mfAv\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kCrlExtensionDuplicateSerial[] = { - "-----BEGIN X509 CRL-----\n", - "MIICdzCCAV8CAQEwDQYJKoZIhvcNAQELBQAwgZAxCzAJBgNVBAYTAlVTMRMwEQYD\n", - "VQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQK\n", - "DAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEd\n", - "MBsGA1UEAwwURXhhbXBsZSBDb3JwIFJvb3QgQ0EXDTI2MDMxMDA4MDAwMFoXDTI2\n", - "MDYwODA4MDAwMFowaTAhAgIQABcNMjYwMzA5MDgwMDAwWjAMMAoGA1UdFQQDCgEB\n", - "MCECAhAAFw0yNjAzMDkwODAwMDBaMAwwCgYDVR0VBAMKAQMwIQICEAEXDTI2MDMw\n", - "OTA4MDAwMFowDDAKBgNVHRUEAwoBBKAvMC0wHwYDVR0jBBgwFoAU/hQOExsJZ8tK\n", - "DUvaT/PvkLVD2zMwCgYDVR0UBAMCAQowDQYJKoZIhvcNAQELBQADggEBAAtpEQmD\n", - "QEYmCCPl1948oulVBj4ZeAB3+AK3o96pd/oUY9VKNmP7uMezD/s9ilC7Ip56u2en\n", - "EgrjbSEyrFF7XqXY72Z18EU54xG85dzZv3Ri7SpUoXTL0vNRIvl4/GHZjHzQZTB1\n", - "FGvm10FcFUpgX2EHJVuIWuldqxp4OeJrBIN0wSFciH8PQqs6o5Dw+sYdj2Culnsk\n", - "gi30uB9qfacgppqB3zFf0ayuauO8rupnpSLk+IfapHLWiS5JY6ZX9R/WIKdAc0eR\n", - "6FDo5g9+QvOfhtANWTYJFh8f1Gcnt2BsWGMl8134V3YQ2q+Wb1I9tdli6/4o+dNZ\n", - "ROh6Cs4QAn5WVyc=\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kCrlIDPOnlyCaOnlyAttr[] = { - "-----BEGIN X509 CRL-----\n", - "MIICajCCAVICAQEwDQYJKoZIhvcNAQELBQAwgZAxCzAJBgNVBAYTAlVTMRMwEQYD\n", - "VQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQK\n", - "DAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEd\n", - "MBsGA1UEAwwURXhhbXBsZSBDb3JwIFJvb3QgQ0EXDTI2MDMxMDA4MDAwMFoXDTI2\n", - "MDYwODA4MDAwMFowIzAhAgIQABcNMjYwMzA5MDgwMDAwWjAMMAoGA1UdFQQDCgEB\n", - "oGgwZjAfBgNVHSMEGDAWgBT+FA4TGwlny0oNS9pP8++QtUPbMzAKBgNVHRQEAwIB\n", - "FjA3BgNVHRwBAf8ELTAroCOgIYYfaHR0cDovL2NybC5leGFtcGxlLmNvbS9yb290\n", - "LmNybIIB/4UB/zANBgkqhkiG9w0BAQsFAAOCAQEAHC06Da0jYHaO6pqNpXmZ7WVX\n", - "a/LZgrqJkdr1CPM9OBMYChOOYBy0Gkb6JJaRzMgKpNmXtx+mYhr/WoQ2B03R/FOW\n", - "AL8BuTTgy9XRGGZyyUXzXL9VLRtE23ebk3jkxtB4msqenlY/CfkjGwqrikJcCBwp\n", - "sS/FAO5Z8Sg1V3cg2cvJmnuwqMK6+PDx55hasC0GyWKH620JeK472HbWPgJT0HVR\n", - "GjQo7Z3+iuSOLW+ZXJyZ8bsHKtWI/mpQS1SfP1NXUlOdtjr6ISNBmUrIq7tL6SBR\n", - "5NdHaH/jzW3yMQE8LMFtONafDofXXTRjCOdZjh/5Bx3lVlxgAp8PKlzCYkTERQ==\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kCrlIDPOnlyUserOnlyAttr[] = { - "-----BEGIN X509 CRL-----\n", - "MIICajCCAVICAQEwDQYJKoZIhvcNAQELBQAwgZAxCzAJBgNVBAYTAlVTMRMwEQYD\n", - "VQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQK\n", - "DAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEd\n", - "MBsGA1UEAwwURXhhbXBsZSBDb3JwIFJvb3QgQ0EXDTI2MDMxMDA4MDAwMFoXDTI2\n", - "MDYwODA4MDAwMFowIzAhAgIQABcNMjYwMzA5MDgwMDAwWjAMMAoGA1UdFQQDCgEB\n", - "oGgwZjAfBgNVHSMEGDAWgBT+FA4TGwlny0oNS9pP8++QtUPbMzAKBgNVHRQEAwIB\n", - "FTA3BgNVHRwBAf8ELTAroCOgIYYfaHR0cDovL2NybC5leGFtcGxlLmNvbS9yb290\n", - "LmNybIEB/4UB/zANBgkqhkiG9w0BAQsFAAOCAQEAhx9Zg1b1Y5ITgN9BX15SDjuE\n", - "viYCk+oQpGAcLnTYq8cFKoGUug3mn3vEYh4dg64hxsWX64X8jcD/fQRM3Ot1SHDZ\n", - "hYOG1QBJyMN/bU5kc4zqXoH/bRrEERiE5maF84wqKHr+DvJukpAX6i1uehyLEG7s\n", - "mjSKin54s44lVQsX8I93aTks8LPCjxfhusCKvrWmNWDHgfh4gwKsIj3U5ToYjISr\n", - "nrFBEAAKzCAaxTgxLrg6+uagA3bFGhRwrqBMFLAysKTJnJpp1Gn8PQdEQlLeYYmo\n", - "pDhvJcCx5qWn+SV1jfOar5JhR12G+ulc73aJR8c6zaJzoOp7OYtrMtai1gKvgQ==\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kCrlIDPOnlyUserOnlyCA[] = { - "-----BEGIN X509 CRL-----\n", - "MIICajCCAVICAQEwDQYJKoZIhvcNAQELBQAwgZAxCzAJBgNVBAYTAlVTMRMwEQYD\n", - "VQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQK\n", - "DAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEd\n", - "MBsGA1UEAwwURXhhbXBsZSBDb3JwIFJvb3QgQ0EXDTI2MDMxMDA4MDAwMFoXDTI2\n", - "MDYwODA4MDAwMFowIzAhAgIQABcNMjYwMzA5MDgwMDAwWjAMMAoGA1UdFQQDCgEB\n", - "oGgwZjAfBgNVHSMEGDAWgBT+FA4TGwlny0oNS9pP8++QtUPbMzAKBgNVHRQEAwIB\n", - "FDA3BgNVHRwBAf8ELTAroCOgIYYfaHR0cDovL2NybC5leGFtcGxlLmNvbS9yb290\n", - "LmNybIEB/4IB/zANBgkqhkiG9w0BAQsFAAOCAQEAScvTwUwgBhEANXRN5bL9S3nE\n", - "vuxU/kZR8xtaGqUHTsrvcBxylR5VinF53RJlz0NaMxQRRpE+NLDZaW2tUbt+k/22\n", - "QPWoGFTfZN2GolzuFqu7v/ZPtAM02NNfSoxVu+Xb9ycJWJFP1hOreioOknn7FqjR\n", - "212EypnY5a2D6TVgK11g1brPxVaN1rVt08zhrCj1mq7FWP4M6W2DkTZ6r1ExgIqu\n", - "Kl//1G15cP+k7+SJe91c3cJ/GWzDHOrruLkzsaLAajKr6i5CWBEGEYHLvRf0RZq1\n", - "eucBJgsWxYlHvIHgSA4/EbCq6mK4+m2MUAkOOPfaec8MzGJCm73VWgTnRwIWlg==\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kCrlIDPOnlyUserOnlyCAOnlyAttr[] = { - "-----BEGIN X509 CRL-----\n", - "MIICbTCCAVUCAQEwDQYJKoZIhvcNAQELBQAwgZAxCzAJBgNVBAYTAlVTMRMwEQYD\n", - "VQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQK\n", - "DAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEd\n", - "MBsGA1UEAwwURXhhbXBsZSBDb3JwIFJvb3QgQ0EXDTI2MDMxMDA4MDAwMFoXDTI2\n", - "MDYwODA4MDAwMFowIzAhAgIQABcNMjYwMzA5MDgwMDAwWjAMMAoGA1UdFQQDCgEB\n", - "oGswaTAfBgNVHSMEGDAWgBT+FA4TGwlny0oNS9pP8++QtUPbMzAKBgNVHRQEAwIB\n", - "FzA6BgNVHRwBAf8EMDAuoCOgIYYfaHR0cDovL2NybC5leGFtcGxlLmNvbS9yb290\n", - "LmNybIEB/4IB/4UB/zANBgkqhkiG9w0BAQsFAAOCAQEAQ7OlOy+pMrRHeM1W3d+s\n", - "3Ev/fIEO852mBxy32OV4t3zjHnS+XK0u3U8fWUR6i31FrDQUJDLqNFhWPGHD/MqI\n", - "bqn6zzLy35S5+AK2pChAKOdUxSzy8bjOx0tahpqSKXnijxCzFkEqs65J5yVwJJTN\n", - "jK8ieuqTmsHKwbfPe6x93+7ceygknpeu3rsR2gMGwybNW8Yq7CUQ87sVcI4H3RAU\n", - "6qbenT+eec6Xn6VpFQ1qnUvKxnw2CF6q11V/T9Rxqb0TKLia3NXG2IT6EHf6APJ6\n", - "wN+DQSZq2qLdt3i3pbJQDcpT90a/PfaSlXcjtM6FcpN4bpex3CgLYIoCivDP9UXR\n", - "2Q==\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kCrlCINoIndirectFlag[] = { - "-----BEGIN X509 CRL-----\n", - "MIICrzCCAZcCAQEwDQYJKoZIhvcNAQELBQAwgZAxCzAJBgNVBAYTAlVTMRMwEQYD\n", - "VQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQK\n", - "DAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEd\n", - "MBsGA1UEAwwURXhhbXBsZSBDb3JwIFJvb3QgQ0EXDTI2MDMxMDA4MDAwMFoXDTI2\n", - "MDYwODA4MDAwMFowbjBsAgIQABcNMjYwMzA5MDgwMDAwWjBXMFUGA1UdHQROMEyk\n", - "SjBIMQswCQYDVQQGEwJVUzEVMBMGA1UECgwMRXhhbXBsZSBDb3JwMSIwIAYDVQQD\n", - "DBlFeGFtcGxlIENvcnAgSXNzdWluZyBDQSAyoGIwYDAfBgNVHSMEGDAWgBT+FA4T\n", - "Gwlny0oNS9pP8++QtUPbMzAKBgNVHRQEAwIBKDAxBgNVHRwBAf8EJzAloCOgIYYf\n", - "aHR0cDovL2NybC5leGFtcGxlLmNvbS9yb290LmNybDANBgkqhkiG9w0BAQsFAAOC\n", - "AQEAc2tRh8V2jStk9g78UUUp/v+zI8rGaeU2mS7EIqxyqzH916tj1+aKcH+wY5ed\n", - "YGrsG5ERsdZWVWREpZmoIpqagF1nvU9Ya5unNDVGQZqRXtANX2bI1sdqu0tLZ+ul\n", - "t3Um6jbga/0Ej1rGDjF3Y2/tvQ8q7v42Hk859TQp2xmX7er48ERj9RbL8I7O0AIS\n", - "15dIAIhsFQJruelovjzJ6Y0tKZgJ+ExAItezAVhEPl6dqEYO5zXXXzwKRBG1A2Jh\n", - "dKdLqbcqkFbd8jIr7b1JNrJU1jcIMAm3/X0l+XwH+ychKy4+6wjPiDVFgyDfn1qf\n", - "ZjPymdOBXXH7OvqdCw43/RadaQ==\n", - "-----END X509 CRL-----\n", - NULL -}; - /* * We cannot use old certificates for new tests because the private key * associated with them is no longer available. Therefore, we add kCRLTestLeaf, @@ -628,6 +266,10 @@ static const char *kUnknownCriticalCRL2[] = { NULL }; +static const char **unknown_critical_crls[] = { + kUnknownCriticalCRL, kUnknownCriticalCRL2 +}; + /* * RFC 5280 states that only CRL files with the Indirect CRL flag set to True in * the IDP extension require the certificate_issuer extension. @@ -723,370 +365,19 @@ static const char *kInvalidDateUTC[] = { NULL }; -/* https://github.com/openssl/openssl/issues/27374 */ -static const char *kCrlDeltaIndicatorString[] = { - "-----BEGIN X509 CRL-----\n", - "MIICPzCCAScCAQEwDQYJKoZIhvcNAQELBQAweTELMAkGA1UEBhMCVVMxEzARBgNV\n", - "BAgMCkNhbGlmb3JuaWExFjAUBgNVBAcMDVNhbiBGcmFuY2lzY28xEzARBgNVBAoM\n", - "Ck15IENvbXBhbnkxEzARBgNVBAMMCk15IFJvb3QgQ0ExEzARBgNVBAsMCk15IFJv\n", - "b3QgQ0EXDTI1MDEwMTAwMDAwMFoXDTI1MTIwMTAwMDAwMFowJzAlAhQcgAIu+B8k\n", - "Be6WphLcth/grHAeXhcNMjUwNDE3MTAxNjUxWqBRME8wGAYDVR0UBBECDxnP/97a\n", - "dO3y9qRGDM7hQDAfBgNVHSMEGDAWgBTXYYkfk5aLdlQW6eV33Hy3ZRuAJDASBgNV\n", - "HRsECwQJRzYzMjg3NTEwMA0GCSqGSIb3DQEBCwUAA4IBAQCUvLefNHqdQdJC8gbp\n", - "QME2dQM6C8yLBjcykeNImrW0Ah1fpNTcT3XP+Gc9O5i1OIrCfQ8bDmvBNryrqZfC\n", - "43CsQsW1YBwNIa5oWjgaRwOzqng8Q6ITYpuLDnc7n20ejft8XmgdiTFNflgGM/Hx\n", - "p/a+xhIQAgqfgFH7ocm5DInDS5VFTHTtbPHMPiY4EUy9FnUTenkbFpVA47mswCXd\n", - "5p1QJGrDJR/sx7lmP/W77dhIWNtbmpUUo61AqcO1JdF2RUkc1yg2UBuzkgV1WU3t\n", - "UcQuw9IXm62Io2pRgNeiqOTz5daA1OVlDRaMNEVFvlMs0NgKDx0MGPT9p3KIzSoW\n", - "dbXQ\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kCrlDeltaBase[] = { - "-----BEGIN X509 CRL-----\n", - "MIICQDCCASgCAQEwDQYJKoZIhvcNAQELBQAwgZAxCzAJBgNVBAYTAlVTMRMwEQYD\n", - "VQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQK\n", - "DAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEd\n", - "MBsGA1UEAwwURXhhbXBsZSBDb3JwIFJvb3QgQ0EXDTI2MDMxMDA4MDAwMFoXDTI2\n", - "MDYwODA4MDAwMFqgYzBhMB8GA1UdIwQYMBaAFP4UDhMbCWfLSg1L2k/z75C1Q9sz\n", - "MAsGA1UdFAQEAgIQADAxBgNVHS4EKjAoMCagJKAihiBodHRwOi8vY3JsLmV4YW1w\n", - "bGUuY29tL2RlbHRhLmNybDANBgkqhkiG9w0BAQsFAAOCAQEAIxrY08mNQ1L8+nL9\n", - "H6Wn1ElntRzMLnk6FqgxosA0Tq3EDzRWKHj2Xbk1vGdRdZi7ttYH1+8+5UA8JPmN\n", - "tRyvrm3NieEqW2reDoyFxJYsWQlJCFHjDVeNpoi8fv/qrOYxtuMfyiwho9WjovVi\n", - "AS9/oa/kSbD39RN/wc0UVRBtQn/vBAzlYExehiwnmiXXwbQA+waNlnL58F/34gRh\n", - "sJs0C/HJn9VU4gvSVW1vbpA7Fxt4alUj2NlXSXHi44mXuei4qc3Pxlw2A2Pfca7y\n", - "vcd30ZZdoKFzMViOnLtcM4vLw59ZEENJmz3vIIU6jACBy8/FbdPsH/iJTTvc76Yv\n", - "CjQcgQ==\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kCrlDeltaValid[] = { - "-----BEGIN X509 CRL-----\n", - "MIICNDCCARwCAQEwDQYJKoZIhvcNAQELBQAwgZAxCzAJBgNVBAYTAlVTMRMwEQYD\n", - "VQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQK\n", - "DAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEd\n", - "MBsGA1UEAwwURXhhbXBsZSBDb3JwIFJvb3QgQ0EXDTI2MDMxMDA4MDAwMFoXDTI2\n", - "MDYwODA4MDAwMFowFTATAgIQABcNMjYwMzIwMDAwMDAwWqBAMD4wHwYDVR0jBBgw\n", - "FoAU/hQOExsJZ8tKDUvaT/PvkLVD2zMwCwYDVR0UBAQCAhABMA4GA1UdGwEB/wQE\n", - "AgIQADANBgkqhkiG9w0BAQsFAAOCAQEAjDx5wqkXfcfTtEbMUN1UcKAHQC5Fx/Kq\n", - "wpoDulPh52zmugl9zhEWWuwA0hSJ/qNRo5tatSGvHbIOrwvZ0LKgChHwtdQfAcBY\n", - "xMl8KsVRqgGjJ4NahyAglsnsJ95VvImMJGFm+eS0DxQgGJgvsj/dh3dsJEGIW4Mo\n", - "baF6e6sAYaYjn9QW0uzoc5zqux25/DUR5DG99cbi6NOqCm7U1gvWkZsjx4HInx4r\n", - "CFazu5IQE7gk1qipnROwgfi/QQXZmAueW+XasEqQcQw0WVEmCHq6OBlrelTs165b\n", - "sK0XOqWDfa745ZN0EZwJY6GIVl+KEAC0XkoGZdqudOEQbbWog0OKkQ==\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kCrlNumberString[] = { - "-----BEGIN X509 CRL-----\n", - "MIICJTCCAQ0CAQEwDQYJKoZIhvcNAQELBQAweTELMAkGA1UEBhMCVVMxEzARBgNV\n", - "BAgMCkNhbGlmb3JuaWExFjAUBgNVBAcMDVNhbiBGcmFuY2lzY28xEzARBgNVBAoM\n", - "Ck15IENvbXBhbnkxEzARBgNVBAMMCk15IFJvb3QgQ0ExEzARBgNVBAsMCk15IFJv\n", - "b3QgQ0EXDTI1MDEwMTAwMDAwMFoXDTI1MTIwMTAwMDAwMFowJzAlAhQcgAIu+B8k\n", - "Be6WphLcth/grHAeXhcNMjUwNTI4MDMwOTE4WqA3MDUwEgYDVR0UBAsECUc2MzI4\n", - "NzUxMDAfBgNVHSMEGDAWgBTXYYkfk5aLdlQW6eV33Hy3ZRuAJDANBgkqhkiG9w0B\n", - "AQsFAAOCAQEAU+jupFC7puUTELqIipJuywX2NWiA9kZIGSZM8k7gE8UZicsDy77F\n", - "hnpyY8ATvRXTaFL/QKipowNlGUf9LsS9vo36XKBOb4mJQQRUV2MLBqMacG9/t1/t\n", - "KBbNe+zxE9edfs+gco8K0pR/UWCjo0hKvqohEZ2S2Yl7FjSB6SuPMQA58+CkGdTM\n", - "P9k+LlqnPFl9Csm/2XUt1Fmw9AG2K5RN2fLC1NzMG1COo6g4LX8Sj4d7WW1LQUY5\n", - "cgd8PXFHW27u6F2c+xl5a7depdYKKDeWf01soQjjnT3e9OXZuBDM/vXBjl8T3YLF\n", - "s2kylOJHvGL3sxwWVCpboTmSUTEbf/tbOA==\n", - "-----END X509 CRL-----\n", - NULL -}; - -/* https://github.com/openssl/openssl/issues/27251 */ -static const char *kCrlIDPWrongTag[] = { - "-----BEGIN X509 CRL-----\n", - "MIICZzCCAU8CAQEwDQYJKoZIhvcNAQELBQAweTELMAkGA1UEBhMCVVMxEzARBgNV\n", - "BAgMCkNhbGlmb3JuaWExFjAUBgNVBAcMDVNhbiBGcmFuY2lzY28xEzARBgNVBAoM\n", - "Ck15IENvbXBhbnkxEzARBgNVBAMMCk15IFJvb3QgQ0ExEzARBgNVBAsMCk15IFJv\n", - "b3QgQ0EXDTI1MDEwMTAwMDAwMFoXDTI1MTIwMTAwMDAwMFowJzAlAhQcgAIu+B8k\n", - "Be6WphLcth/grHAeXhcNMjUwNDE3MTAxNjUxWqB5MHcwGAYDVR0UBBECDxnP/97a\n", - "dO3y9qRGDM7hQDAfBgNVHSMEGDAWgBTXYYkfk5aLdlQW6eV33Hy3ZRuAJDA6BgNV\n", - "HRwBAf8EMDAuoCagJKQihiBodHRwOi8vbG9jYWxob3N0OjgwMDAvY2FfY3JsLmRl\n", - "coEB/4IB/zANBgkqhkiG9w0BAQsFAAOCAQEANovDW2ry+y17K8CgjoD6C1Mwf8Je\n", - "uJiSw4kZnbtO/+/Benl3nWumMIH9liV6BSJnWZU3staGQaUyk+qou5udzSwh0Tw/\n", - "iGu/xygDlEBiJ/vFt0Bt6ImHCsNrd7UjNRGRJI7neeJdq6YlMOJ27JvKt9isRJIM\n", - "KsHBuqBs8G8g6XU0TfgoHYAPxtPF9uuFmC7k0Fs7z142C9/Im8m1CqqYet/kd/Hz\n", - "IErMxdvr1NfL7WHBIArW0BqjaR1E05ur8fPIHItVJtPV9V5UbRM1eeQiOfDCyZRJ\n", - "x9A/quodFMH781MsLnTktHqMmbOesiDycl0OehyrfXDEXLWIOH/EvqkyIA==\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kCrlIDPWrongTag2[] = { - "-----BEGIN X509 CRL-----\n", - "MIICZzCCAU8CAQEwDQYJKoZIhvcNAQELBQAweTELMAkGA1UEBhMCVVMxEzARBgNV\n", - "BAgMCkNhbGlmb3JuaWExFjAUBgNVBAcMDVNhbiBGcmFuY2lzY28xEzARBgNVBAoM\n", - "Ck15IENvbXBhbnkxEzARBgNVBAMMCk15IFJvb3QgQ0ExEzARBgNVBAsMCk15IFJv\n", - "b3QgQ0EXDTI1MDEwMTAwMDAwMFoXDTI1MTIwMTAwMDAwMFowJzAlAhQcgAIu+B8k\n", - "Be6WphLcth/grHAeXhcNMjUwNDE3MTAxNjUxWqB5MHcwGAYDVR0UBBECDxnP/97a\n", - "dO3y9qRGDM7hQDAfBgNVHSMEGDAWgBTXYYkfk5aLdlQW6eV33Hy3ZRuAJDA6BgNV\n", - "HRwBAf8EMDAuoCagJKUihiBodHRwOi8vbG9jYWxob3N0OjgwMDAvY2FfY3JsLmRl\n", - "coEB/4IB/zANBgkqhkiG9w0BAQsFAAOCAQEAyLXs3RfVDDjTvvni2EyKRdnpODpY\n", - "hH5Q26NtA0S6/hXUOntR3N6jrqZQNo1Eg2iL9v6IzWnHEeWs4jSzMaOdAHW+iASY\n", - "COMIuNKY51E7dezIyY1Gjl3L9S/laGb0zPsgziAq8PFKP/FBC0uQbLmpbfvFSf0D\n", - "bZQzB0THvc3OjixEeRQPNkEApHPqmZpvr6ysQBpvzSQJhYaVT2JfUjAGBu1B6iIO\n", - "bwfzsFriiMUdnHp6I3mQ0LtzcxuzEDVifcE4dkl2PROsgwxiAbKXCYTDYGSTQ3Li\n", - "4ijLXcQYIZ3ZP6xs6qiYqphBF2ICGtMpD2XUxOSMfO42S2FYs/wZ38lnHg==\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kIndirectCRLIssuer[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIIECjCCAvKgAwIBAgICEAAwDQYJKoZIhvcNAQELBQAwgZAxCzAJBgNVBAYTAlVT\n", - "MRMwEQYDVQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUw\n", - "EwYDVQQKDAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhv\n", - "cml0eTEdMBsGA1UEAwwURXhhbXBsZSBDb3JwIFJvb3QgQ0EwHhcNMjYwMzEwMTIw\n", - "MDAwWhcNMzYwMzA3MTIwMDAwWjCBnDELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNh\n", - "bGlmb3JuaWExFjAUBgNVBAcMDVNhbiBGcmFuY2lzY28xFTATBgNVBAoMDEV4YW1w\n", - "bGUgQ29ycDEeMBwGA1UECwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MSkwJwYDVQQD\n", - "DCBFeGFtcGxlIENvcnAgSW5kaXJlY3QgQ1JMIElzc3VlcjCCASIwDQYJKoZIhvcN\n", - "AQEBBQADggEPADCCAQoCggEBAKgcYFF3+Z/A12AMb3P9Isl959u4QpX/fx4d+A38\n", - "8K8KmdzCAODNA6zjgRKfvhzZwF1sW+5DClcLC9dhClIsL+yNdLNbTm6L+ZZQoO39\n", - "3gExou+jKXMW1Ne8Z1U+g1QWVFmkGmrlcbl8zxx6QmAlKKr6LXQ8LryAzpJM7Fi7\n", - "IttC474U25PC1UWrWet/yfSWLWtcSIsj+Q+gKVIUMpUaM7thTfq9xRhLdoD5rFZG\n", - "crN4x5L7jx4lhf80k4lIdO5MmO84yFen5f1qvl824wtS3vfksXDAKBKZkhuz8tMd\n", - "UggD05zz7V9sa0NdqGC3Srw5O7CIKnGCkfs3UdMba62uxIMCAwEAAaNgMF4wDAYD\n", - "VR0TAQH/BAIwADAOBgNVHQ8BAf8EBAMCAQIwHQYDVR0OBBYEFF9mMI2VQ8+M0l6S\n", - "+cA1RMYGjxuaMB8GA1UdIwQYMBaAFP4UDhMbCWfLSg1L2k/z75C1Q9szMA0GCSqG\n", - "SIb3DQEBCwUAA4IBAQAJul5iFA3un8AyetqtY989Qd9IHKVNVJGrkwaLYPTkUXjb\n", - "iHt8NSPQqPMdCsvluIzAfxfH7Le5taiM0IUZhYXJyQSJenmV7jsNqA0VyUwqa85M\n", - "DfNDGuVyaUji+gHcgV1iQwDBBg2tu9RbOC+T7WnUGyBW7Ats2uVH47q9BcCqsNHZ\n", - "1WseFLfNsmaLXfZaI09MNX3b4S+dimdKucGmkspVNecRNY9ERHIpZUwQX/Q/UgaF\n", - "Oenex/WZQMXCa94fXXcE8F79s0JhLcWwYqg40UolCDuOM4awnJcNwEQAsawXjXjA\n", - "hiTorbY7SaLlB4v77XmnlZd4AaiWzMr0WlPf9dWN\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -static const char *kIndirectLeaf[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIIE/zCCA+egAwIBAgICEAEwDQYJKoZIhvcNAQELBQAwgZAxCzAJBgNVBAYTAlVT\n", - "MRMwEQYDVQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUw\n", - "EwYDVQQKDAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhv\n", - "cml0eTEdMBsGA1UEAwwURXhhbXBsZSBDb3JwIFJvb3QgQ0EwHhcNMjYwMzEwMTIw\n", - "MDAwWhcNMjcwMzEwMTIwMDAwWjBvMQswCQYDVQQGEwJVUzETMBEGA1UECAwKQ2Fs\n", - "aWZvcm5pYTEVMBMGA1UECgwMRXhhbXBsZSBDb3JwMRUwEwYDVQQLDAxXZWIgU2Vy\n", - "dmljZXMxHTAbBgNVBAMMFGluZGlyZWN0LmV4YW1wbGUuY29tMIIBIjANBgkqhkiG\n", - "9w0BAQEFAAOCAQ8AMIIBCgKCAQEAlb+pk71/ZyJEBwIrj/Z0eTOgysfNIikmkxg+\n", - "Fl1OEsX/2wYpvUm+y5mIDqjdVikMBzA0LfFlupG8d2zl46rbDDmClScP0lZAKsmD\n", - "AxSgAVnu0cAFKY9abF+SJkvn3XxlyhZKvd3eVDi4Tep4bC/fWMTvvm51nS5Ek3Ol\n", - "p6gTPFN/yoS6shOrIyiShJyINiXlhGNJP1+eDYdqordmD6AZOOeMSO/yXPbHNIn1\n", - "aa8T40wuUSHZr7ywNEK3K9ct9R6W76anZTO6lPENW+3IYABJZAMtDQyfo7MRv5Uv\n", - "hu5YY9MZ5/O52Zgkhw8vBMZ3W52r9CX4m3TwcBttrKVuLRBKmQIDAQABo4IBgTCC\n", - "AX0wDAYDVR0TAQH/BAIwADAOBgNVHQ8BAf8EBAMCBaAwHQYDVR0lBBYwFAYIKwYB\n", - "BQUHAwEGCCsGAQUFBwMCMB0GA1UdDgQWBBSezaxlDNqlAMxk4EkcLyTW/sV1hzAf\n", - "BgNVHSMEGDAWgBT+FA4TGwlny0oNS9pP8++QtUPbMzAfBgNVHREEGDAWghRpbmRp\n", - "cmVjdC5leGFtcGxlLmNvbTCB3AYDVR0fBIHUMIHRMIHOoCegJYYjaHR0cDovL2Ny\n", - "bC5leGFtcGxlLmNvbS9pbmRpcmVjdC5jcmyigaKkgZ8wgZwxCzAJBgNVBAYTAlVT\n", - "MRMwEQYDVQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUw\n", - "EwYDVQQKDAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhv\n", - "cml0eTEpMCcGA1UEAwwgRXhhbXBsZSBDb3JwIEluZGlyZWN0IENSTCBJc3N1ZXIw\n", - "DQYJKoZIhvcNAQELBQADggEBAB5FgdhZmD2BoeznN+rHg56JkbWV7cmvVH4O6ARn\n", - "ylSsWCJC4ovMnCZhR9mM0N74HAhcdH9REnHBGTTO3ldmMJBoPlZ0GaUUdVJbb03h\n", - "xrto+uBk1ixjuJcRR5qiXnR8uthLCyHKbRHy+ebYFKIlEeGAqfLTHkqUUHeZIFtu\n", - "p2WVCHsyEqx8gpSlHzg14e9ZaIbmRAgl8igmlq5FQo+Wi1fMnDk7L+rrXVNeZ7yC\n", - "iwgMEntM2omJRhVM/4xkYLICiBogdt8xCbM4yPy4ZOJzAdOTPnE/DsjY6p2Qyuqc\n", - "6w/LgbQGKdoAhj/+29YM1sGXUiem0OZj0Surm9XNr+NpBiM=\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -static const char *kCrlIndirect[] = { - "-----BEGIN X509 CRL-----\n", - "MIICKjCCARICAQEwDQYJKoZIhvcNAQELBQAwgZwxCzAJBgNVBAYTAlVTMRMwEQYD\n", - "VQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQK\n", - "DAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEp\n", - "MCcGA1UEAwwgRXhhbXBsZSBDb3JwIEluZGlyZWN0IENSTCBJc3N1ZXIXDTI2MDMx\n", - "MDA4MDAwMFoXDTI2MDYwODA4MDAwMFqgQTA/MB8GA1UdIwQYMBaAFF9mMI2VQ8+M\n", - "0l6S+cA1RMYGjxuaMA8GA1UdHAEB/wQFMAOEAf8wCwYDVR0UBAQCAhAAMA0GCSqG\n", - "SIb3DQEBCwUAA4IBAQA/WGgZvm/ojax+1oOSMG1626PgyIGOC0xcxMJDw/70JuYQ\n", - "mpSbUS6XIYUI+YlzgdHOl1HETV3nxLDYYb4e0CUxlREzurp/WZ2Zotxf7dN7JnDq\n", - "UgkDhjHEnlBcjX7MIJYfQcZCSKaxlRlgJvhPRD19e3n9nVRM7AMlR4rsBo5Iitmt\n", - "xj6hZ4TQBtSTud0RhT/DIs3g9ZoBGIziANZFVBPVIhxkFGzrnW4lweQi1N5TKnnv\n", - "6+d/JmRDeF6q7SLB/+4eQHbUUwxJdQRMkBVD4+eTumqhUfMxk6P11CPQlXCXmSjA\n", - "+PaHNFB8t+O/gVAQ7dWbLSlNB/lngQeMZGG0xLdP\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kCrlIndirectRevoked[] = { - "-----BEGIN X509 CRL-----\n", - "MIIC7TCCAdUCAQEwDQYJKoZIhvcNAQELBQAwgZwxCzAJBgNVBAYTAlVTMRMwEQYD\n", - "VQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQK\n", - "DAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEp\n", - "MCcGA1UEAwwgRXhhbXBsZSBDb3JwIEluZGlyZWN0IENSTCBJc3N1ZXIXDTI2MDMx\n", - "MDA4MDAwMFoXDTI2MDYwODA4MDAwMFowgcAwgb0CAhABFw0yNjAzMDkxMjAwMDBa\n", - "MIGnMIGkBgNVHR0BAf8EgZkwgZakgZMwgZAxCzAJBgNVBAYTAlVTMRMwEQYDVQQI\n", - "DApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQKDAxF\n", - "eGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEdMBsG\n", - "A1UEAwwURXhhbXBsZSBDb3JwIFJvb3QgQ0GgQTA/MB8GA1UdIwQYMBaAFF9mMI2V\n", - "Q8+M0l6S+cA1RMYGjxuaMA8GA1UdHAEB/wQFMAOEAf8wCwYDVR0UBAQCAhABMA0G\n", - "CSqGSIb3DQEBCwUAA4IBAQBZsW13FmSxxDmAr5nzNg8IcRkP+IvoYEHfgUdpUD6A\n", - "A+T8Ktx62BNIv4lE6F5UsWCjUoF0iEpAGNoS3nArlTyWG0Nm2LYAKZcTUyjHAmVK\n", - "DxQR+l/nYFdWTLBzZroXLMmyelqQz8N+EaOwYTugA6U2DQHUraH2Fczb5S5Q3wx6\n", - "DcEkZwb3gkV0M4HG72KzrZvCB4JfXXgmSNwXIfnCoB6KC+OF9IK6aAzNS56iNGLo\n", - "+1DCyrIcNu0uny1I4VuZSPnbjjIPmAIKuJizw7ssazqmZ+6rq64LsFuoxqfM7YD2\n", - "cNGVq3tNAs3PTc4DtSStuGix8BCT1d1EgDcgBUD+yMf1\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kIndirectCRLIssuerAlt[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIIEBTCCAu2gAwIBAgICEAAwDQYJKoZIhvcNAQELBQAwgYsxCzAJBgNVBAYTAlVT\n", - "MQ8wDQYDVQQIDAZOZXZhZGExDTALBgNVBAcMBFJlbm8xGTAXBgNVBAoMEEV4YW1w\n", - "bGUgQWx0IENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEhMB8G\n", - "A1UEAwwYRXhhbXBsZSBBbHQgQ29ycCBSb290IENBMB4XDTI2MDMxMDEyMDAwMFoX\n", - "DTM2MDMwNzEyMDAwMFowgZwxCzAJBgNVBAYTAlVTMRMwEQYDVQQIDApDYWxpZm9y\n", - "bmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQKDAxFeGFtcGxlIENv\n", - "cnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEpMCcGA1UEAwwgRXhh\n", - "bXBsZSBDb3JwIEluZGlyZWN0IENSTCBJc3N1ZXIwggEiMA0GCSqGSIb3DQEBAQUA\n", - "A4IBDwAwggEKAoIBAQDghcroe445U41hW2KihlkXdvw3QnCzwhMyRf2qjQezP1Ld\n", - "Lp8vjIjTZebxEXXGj7xI9Sy9EJFsSfQ79KFjp4txsBSfDsty3NyWxmWnQ3Og/Q6Q\n", - "o9W6Rfjgc3pMLI5K2KDH7CXu0JMedu55aDWe/IIuSNVD+1CPmbEp1cMuI/Jw7G/M\n", - "uQPTXyx9hFWng7YFrzp1zHK9C9JvcYPFJlo/kmcXTbBTX9/9SUIcZC8xKJ3buSZW\n", - "9E3saex6ro4Qm5A3k0X9ijb6AevF6+LvRTkOwPUnSQ/hwE7ljsPdN6osue7pVnBS\n", - "ZdBLDcprxgy/Ywy3GJQCf4bpK4aKq/K9I/1Q/4JnAgMBAAGjYDBeMAwGA1UdEwEB\n", - "/wQCMAAwDgYDVR0PAQH/BAQDAgECMB0GA1UdDgQWBBRE+kGeIcb05GFAL/v6klEx\n", - "hAJyujAfBgNVHSMEGDAWgBQPgimZbVczHuIhFVMrP0PefsYhazANBgkqhkiG9w0B\n", - "AQsFAAOCAQEAZANoU9afzVHLaFEXhK7LAzoQxladrUTL/OFDDMzykKy2iK9FTCO7\n", - "nGwkjL0PvZi0rm9WJy7tWedLNwNNP7O3WulEoZjpxQTJCKk97UG3mIjQkkMiQ6Sx\n", - "E7UGMeZoSriKvPJc628ohj4Hux2pc1xpex1oay9ezQCFud+Bt4UUrxl3AlzlJfo2\n", - "TqOqgpKrTfkREeHdClaZD7Sz+SNmBQY6hj+asRPCFSsFb9SsbsaBePuyP6fp9BWO\n", - "JbiWY2aLBHt7V6k6pSkvb4E41PyoyQZydtB5Gq89X36UfMyik+tFi9ti0xKlgQSB\n", - "Jv1jcqUQRVcKt1J5ifxA/jw6eBn74FKLzA==\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -static const char *kCrlIndirectAlt[] = { - "-----BEGIN X509 CRL-----\n", - "MIICKjCCARICAQEwDQYJKoZIhvcNAQELBQAwgZwxCzAJBgNVBAYTAlVTMRMwEQYD\n", - "VQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQK\n", - "DAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEp\n", - "MCcGA1UEAwwgRXhhbXBsZSBDb3JwIEluZGlyZWN0IENSTCBJc3N1ZXIXDTI2MDMx\n", - "MDA4MDAwMFoXDTI2MDYwODA4MDAwMFqgQTA/MB8GA1UdIwQYMBaAFET6QZ4hxvTk\n", - "YUAv+/qSUTGEAnK6MA8GA1UdHAEB/wQFMAOEAf8wCwYDVR0UBAQCAhAAMA0GCSqG\n", - "SIb3DQEBCwUAA4IBAQA2B0S+8aXt6N1DkdOY3tDq8oHYBkbeeYbLZICz021ZspYl\n", - "AMSVIJi4TI4qNyYkgJs9STdHcRbJ+cDadyTH4XkaAj/zQ1nahQ+9b/JzBu1AoWqJ\n", - "B/Ir05rxR7/S6nVbczCg5X0dTt9LJKjz45XyVkDN0JBZuTM5XXwOHJLUKpgMFGlh\n", - "0TTQqF4c5rmXHqec9lZa1HMHVRJD7b9r+UIl3+HrxXFCpE9WrxWko0M0S9ThGJgH\n", - "oJ8UPXEAm561Yu+AnRW9pRikz1bb5sgr6hxOYMaYQYcQiTIYNJQ6uJDiKgUBQeeI\n", - "jVGFE2NHs4m2vhunkfV2cEEmP4kLdLqf9GxXcxTl\n", - "-----END X509 CRL-----\n", - NULL -}; - -static const char *kIndirectCRLIssuerNoChain[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIIEGjCCAwKgAwIBAgICEAAwDQYJKoZIhvcNAQELBQAwgaAxCzAJBgNVBAYTAlVT\n", - "MRAwDgYDVQQIDAdXeW9taW5nMREwDwYDVQQHDAhDaGV5ZW5uZTEdMBsGA1UECgwU\n", - "RXhhbXBsZSBQaGFudG9tIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhv\n", - "cml0eTEtMCsGA1UEAwwkRXhhbXBsZSBQaGFudG9tIE1pc3NpbmcgSW50ZXJtZWRp\n", - "YXRlMB4XDTI2MDMxMDEyMDAwMFoXDTM2MDMwNzEyMDAwMFowgZwxCzAJBgNVBAYT\n", - "AlVTMRMwEQYDVQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2Nv\n", - "MRUwEwYDVQQKDAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1\n", - "dGhvcml0eTEpMCcGA1UEAwwgRXhhbXBsZSBDb3JwIEluZGlyZWN0IENSTCBJc3N1\n", - "ZXIwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDNi3Mbkqrr+Pn+OSBr\n", - "PccsRxaCSnCk6hXZ9VgE+BH7S9WanAModTstcC4k/EIcbAhL4GbrV98QbGXEUHUd\n", - "HyAnauw4DoDrhWAXwB4miIaNOWMSusOA8SKiLOtDj3Y3gR02wCL9j43keUUSBXiJ\n", - "AXlemQjE27h8lR3kzr6ltyJpNx44X2LOm9H8PsvW1Axh600zBbxBHMZvNqOfnJIU\n", - "R7vNrcjzzMB8Vfxj+AafT3mmThgyjdreC+J5bUkLJ067BG71BdW19gxvSillD7qY\n", - "0jFJt5va70oqTbGc8DgQai/G+YhKLrySWOMuSOEdONvZ73IWhmW6xAfuY06kc+ZH\n", - "FmytAgMBAAGjYDBeMAwGA1UdEwEB/wQCMAAwDgYDVR0PAQH/BAQDAgECMB0GA1Ud\n", - "DgQWBBRFcWkLSgjT/PjhFRBOIMKtY2KVoDAfBgNVHSMEGDAWgBTYK7cenv3KqG8T\n", - "zwvh3DIrr8BIkzANBgkqhkiG9w0BAQsFAAOCAQEAnYV6G1ypPSK9XFVcFKBGft6u\n", - "uxbL/ld8pHaecd/9VtE+A6GT7haPlwM3ZJjfU8rNOHF0BbDOmIevcrjCsaMbdQ0y\n", - "KxAKxxGSHRljSbI286PotISOFghBR8RpZrWSLEXghGV5ixC6MJNGQoVZ2SF0OHlL\n", - "WXJsIXrUtEyx0ZtYegGxv8tb/RaJeOu1kKCQcvKerWhc64XOGkuLuCHQjvqtTM2A\n", - "BCtkcavwOytClDK2hdY1pOR0Y6ms5VUK25pnrTXy+apWQovCsGddNI32QIvghyki\n", - "UNZk/IB5jxCf+upO2/MzEFXievKg7qUOs68r/UiqDNRK43bYoNUYzlsQYE357A==\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -static const char *kCrlIndirectNoChain[] = { - "-----BEGIN X509 CRL-----\n", - "MIICKjCCARICAQEwDQYJKoZIhvcNAQELBQAwgZwxCzAJBgNVBAYTAlVTMRMwEQYD\n", - "VQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUwEwYDVQQK\n", - "DAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhvcml0eTEp\n", - "MCcGA1UEAwwgRXhhbXBsZSBDb3JwIEluZGlyZWN0IENSTCBJc3N1ZXIXDTI2MDMx\n", - "MDA4MDAwMFoXDTI2MDYwODA4MDAwMFqgQTA/MB8GA1UdIwQYMBaAFEVxaQtKCNP8\n", - "+OEVEE4gwq1jYpWgMA8GA1UdHAEB/wQFMAOEAf8wCwYDVR0UBAQCAhAAMA0GCSqG\n", - "SIb3DQEBCwUAA4IBAQDJVHfKcWzjq2/9V8R4LXDNUz+7YjiSUp4Qlb9hMFDpPhHO\n", - "pYRHZrWUom3tcTxG2Yfqc3hroMFGcepQxU32dCT2ZilDnv6UrIOyLjg6xG+4wIsE\n", - "V7MHEcleeGKpaSfEfzSwED7YYj0KuEK1w9qxP5tsUZGe49q2JiYPusi9zVjMdXeC\n", - "7Q8WN6ujoEeGlI1rWyUWeB/ZsV9n48ZVD5oCD1opYSR78tsGpQJNs6PuRdRDoejD\n", - "pOwgf2nyLnjwZG1ldO1g0S/e6D6H6YzINy9vgcFwLcb/QKZYHXU34EmBoD8bP4Ge\n", - "LhEwlP6qap/WGI5GZxQQbVVhqD+wSz/8zZ8xiXAN\n", - "-----END X509 CRL-----\n", - NULL -}; +static X509 *test_root = NULL; +static X509 *test_leaf = NULL; +static X509 *test_root2 = NULL; +static X509 *test_leaf2 = NULL; /* - * A well-formed CRL issued by kRoot (sha256WithRSAEncryption, inner and - * outer signatureAlgorithm identical), used as the positive test case in - * test_crl_sigalg_mismatch. - */ -static const char *kCrlRootCA[] = { - "-----BEGIN X509 CRL-----\n", - "MIIB2jCBwwIBATANBgkqhkiG9w0BAQsFADCBkDELMAkGA1UEBhMCVVMxEzARBgNV\n", - "BAgMCkNhbGlmb3JuaWExFjAUBgNVBAcMDVNhbiBGcmFuY2lzY28xFTATBgNVBAoM\n", - "DEV4YW1wbGUgQ29ycDEeMBwGA1UECwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MR0w\n", - "GwYDVQQDDBRFeGFtcGxlIENvcnAgUm9vdCBDQRcNMjYwMTAxMDAwMDAwWhcNMjcw\n", - "MTAxMDAwMDAwWjANBgkqhkiG9w0BAQsFAAOCAQEAjLDGYBswRZpuaRh9qVXrP4i0\n", - "wttPikYZkkUk07/KU1zN6pS21Dqx1sEofrkqwRnKXq/hsoCz3sd7QFIv30v2iZwM\n", - "ioaksAjcGnaLqe8vuKVtIyiOpDSJR89l84BZr2I9+6osTYnPgroMHQ/7OUt+PKdE\n", - "1VAkA137tLMRw2qGPELdCyHA7LXr0gI6jeyLPLtb1blQrMzznp3y/trNWa+DKq6h\n", - "SflQrixmLeXTMBD/DDUd8Kj9HHmejbJNAsgaNHv9mtIhUVEspRM0020b3AeJyfTP\n", - "3oN/y4fgQ8q5v9i8lDbe8moCo+W0rS4ksWvB6SuYYj/NkUE4EtoIreSVtcz8JA==\n", - "-----END X509 CRL-----\n", - NULL -}; - -/* - * kCrlMismatchedSigAlg is issued by kRoot with a deliberately inconsistent - * pair of signatureAlgorithm fields: the inner (signed) copy inside - * TBSCertList claims ecdsaWithSHA256, while the outer wrapper carries - * sha256WithRSAEncryption -- and the actual signature is a valid RSA-SHA256 - * signature over that TBSCertList. Without the inner/outer comparison, - * X509_CRL_verify() would accept this CRL because the RSA signature checks - * out. RFC 5280 section 5.1.1.2 requires the two fields to be identical. - */ -static const char *kCrlMismatchedSigAlg[] = { - "-----BEGIN X509 CRL-----\n", - "MIIB1zCBwAIBATAKBggqhkjOPQQDAjCBkDELMAkGA1UEBhMCVVMxEzARBgNVBAgM\n", - "CkNhbGlmb3JuaWExFjAUBgNVBAcMDVNhbiBGcmFuY2lzY28xFTATBgNVBAoMDEV4\n", - "YW1wbGUgQ29ycDEeMBwGA1UECwwVQ2VydGlmaWNhdGUgQXV0aG9yaXR5MR0wGwYD\n", - "VQQDDBRFeGFtcGxlIENvcnAgUm9vdCBDQRcNMjYwMTAxMDAwMDAwWhcNMjcwMTAx\n", - "MDAwMDAwWjANBgkqhkiG9w0BAQsFAAOCAQEAcle5SUuN1XIx5amjddTqDPyEm9pP\n", - "sNeBwR+TQi19pWHtQ5anr6PBIAxHC5uxhVpZDScZu0TlodWigo+1bfAJRyrIm/6+\n", - "AbmAyNC4txpNsOHgCFGW7q9T8OutaOhUw+jC6i3bxUQZ64L1sXuy2nZMzU19+Aro\n", - "TxSWYkIJg65SKwM/8ggyd5G7TXkv7w19+W/7Y9JV0c+kPueUZSgEGUG/GJF/Nrrc\n", - "TRfvqz7Qs9H9+hUiQl5K7tF9gj6aU3p1s1IZKR2x0lv4wDRUUgIjrvRzfQSGjhgf\n", - "6rBILI3EIxPN/PoZ3mHLYkhH5IyNj9R2GlMle52isNdW8BiNlePLx0/Jzg==\n", - "-----END X509 CRL-----\n", - NULL -}; - -/* - * Verify |leaf| certificate (chained up to |root|, optionally also |root2|). - * |crls|, if not NULL, is a list of CRLs to include in the verification. It - * is also free'd before returning, which is kinda yucky but convenient. - * |untrusted| sets the list of untrusted certs. |store_root| seeds X509_STORE - * with |root| (and |root2| if non-NULL). + * Verify |leaf| certificate (chained up to |root|). |crls| if + * not NULL, is a list of CRLs to include in the verification. It is + * also free'd before returning, which is kinda yucky but convenient. * Returns a value from X509_V_ERR_xxx or X509_V_OK. */ -static int verify_ex(X509 *leaf, X509 *root, X509 *root2, - STACK_OF(X509) *untrusted, STACK_OF(X509_CRL) *crls, - unsigned long flags, time_t verification_time, int store_root) +static int verify(X509 *leaf, X509 *root, STACK_OF(X509_CRL) *crls, + unsigned long flags, time_t verification_time) { X509_STORE_CTX *ctx = X509_STORE_CTX_new(); X509_STORE *store = X509_STORE_new(); @@ -1100,34 +391,19 @@ static int verify_ex(X509 *leaf, X509 *root, X509 *root2, || !TEST_ptr(roots)) goto err; - /* Create a stack; upref the certs because we free them below. */ + /* Create a stack; upref the cert because we free it below. */ if (!TEST_true(X509_up_ref(root))) goto err; if (!TEST_true(sk_X509_push(roots, root))) { X509_free(root); goto err; } - if (root2 != NULL) { - if (!TEST_true(X509_up_ref(root2))) - goto err; - if (!TEST_true(sk_X509_push(roots, root2))) { - X509_free(root2); - goto err; - } - } - if (store_root) { - if (!TEST_true(X509_STORE_add_cert(store, root))) - goto err; - if (root2 != NULL && !TEST_true(X509_STORE_add_cert(store, root2))) - goto err; - } - if (!TEST_true(X509_STORE_CTX_init(ctx, store, leaf, untrusted))) + if (!TEST_true(X509_STORE_CTX_init(ctx, store, leaf, NULL))) goto err; X509_STORE_CTX_set0_trusted_stack(ctx, roots); X509_STORE_CTX_set0_crls(ctx, crls); X509_VERIFY_PARAM_set_time(param, verification_time); - if (!TEST_long_eq((long)X509_VERIFY_PARAM_get_time(param), - (long)verification_time)) + if (!TEST_long_eq((long)X509_VERIFY_PARAM_get_time(param), (long)verification_time)) goto err; X509_VERIFY_PARAM_set_depth(param, 16); if (flags) @@ -1136,10 +412,8 @@ static int verify_ex(X509 *leaf, X509 *root, X509 *root2, param = NULL; ERR_clear_error(); - MFAIL_start(); status = X509_verify_cert(ctx) == 1 ? X509_V_OK : X509_STORE_CTX_get_error(ctx); - MFAIL_end(); err: OSSL_STACK_OF_X509_free(roots); sk_X509_CRL_pop_free(crls, X509_CRL_free); @@ -1149,16 +423,6 @@ err: return status; } -/* - * Like verify_ex but not using any untrusted certs and does not store root and - * have root2. - */ -static int verify(X509 *leaf, X509 *root, STACK_OF(X509_CRL) *crls, - unsigned long flags, time_t verification_time) -{ - return verify_ex(leaf, root, NULL, NULL, crls, flags, verification_time, 0); -} - /* * Create a stack of CRL's. Upref each one because we call pop_free on * the stack and need to keep the CRL's around until the test exits. @@ -1193,155 +457,106 @@ err: return NULL; } -static int test_crl_basic(void) +static int test_basic_crl(void) { - X509 *root = X509_from_strings(kCRLTestRoot); - X509 *leaf = X509_from_strings(kCRLTestLeaf); X509_CRL *basic_crl = CRL_from_strings(kBasicCRL); X509_CRL *revoked_crl = CRL_from_strings(kRevokedCRL); const X509_ALGOR *alg = NULL, *tbsalg; - int test; + int r; - test = TEST_ptr(root) - && TEST_ptr(leaf) - && TEST_ptr(basic_crl) + r = TEST_ptr(basic_crl) && TEST_ptr(revoked_crl) - && TEST_int_eq(verify(leaf, root, + && TEST_int_eq(verify(test_leaf, test_root, make_CRL_stack(basic_crl, NULL), X509_V_FLAG_CRL_CHECK, PARAM_TIME), X509_V_OK) - && TEST_int_eq(verify(leaf, root, + && TEST_int_eq(verify(test_leaf, test_root, make_CRL_stack(basic_crl, revoked_crl), X509_V_FLAG_CRL_CHECK, PARAM_TIME), X509_V_ERR_CERT_REVOKED) - && TEST_int_eq(verify(leaf, root, + && TEST_int_eq(verify(test_leaf, test_root, make_CRL_stack(basic_crl, revoked_crl), X509_V_FLAG_CRL_CHECK, PARAM_TIME2), X509_V_ERR_CRL_HAS_EXPIRED) - && TEST_int_eq(verify(leaf, root, + && TEST_int_eq(verify(test_leaf, test_root, make_CRL_stack(basic_crl, revoked_crl), X509_V_FLAG_CRL_CHECK, 0), X509_V_ERR_CRL_NOT_YET_VALID); - if (test) { + if (r) { X509_CRL_get0_signature(basic_crl, NULL, &alg); tbsalg = X509_CRL_get0_tbs_sigalg(basic_crl); - test = TEST_ptr(alg) + r = TEST_ptr(alg) && TEST_ptr(tbsalg) && TEST_int_eq(X509_ALGOR_cmp(alg, tbsalg), 0); } X509_CRL_free(basic_crl); X509_CRL_free(revoked_crl); - X509_free(leaf); - X509_free(root); - return test; + return r; } static int test_no_crl(void) { - X509 *root = X509_from_strings(kCRLTestRoot); - X509 *leaf = X509_from_strings(kCRLTestLeaf); - int test; - - test = TEST_ptr(root) - && TEST_ptr(leaf) - && TEST_int_eq(verify(leaf, root, NULL, + return TEST_int_eq(verify(test_leaf, test_root, NULL, X509_V_FLAG_CRL_CHECK, PARAM_TIME), - X509_V_ERR_UNABLE_TO_GET_CRL); - - X509_free(leaf); - X509_free(root); - return test; + X509_V_ERR_UNABLE_TO_GET_CRL); } -static int test_crl_bad_issuer(void) +static int test_bad_issuer_crl(void) { - X509 *root = X509_from_strings(kCRLTestRoot); - X509 *leaf = X509_from_strings(kCRLTestLeaf); - X509_CRL *crl = CRL_from_strings(kBadIssuerCRL); - int test; + X509_CRL *bad_issuer_crl = CRL_from_strings(kBadIssuerCRL); + int r; - test = TEST_ptr(root) - && TEST_ptr(leaf) - && TEST_ptr(crl) - && TEST_int_eq(verify(leaf, root, - make_CRL_stack(crl, NULL), + r = TEST_ptr(bad_issuer_crl) + && TEST_int_eq(verify(test_leaf, test_root, + make_CRL_stack(bad_issuer_crl, NULL), X509_V_FLAG_CRL_CHECK, PARAM_TIME), X509_V_ERR_UNABLE_TO_GET_CRL); - X509_CRL_free(crl); - X509_free(leaf); - X509_free(root); - return test; + X509_CRL_free(bad_issuer_crl); + return r; } static int test_crl_empty_idp(void) { - X509 *root = X509_from_strings(kCRLTestRoot2); - X509 *leaf = X509_from_strings(kCRLTestLeaf2); - X509_CRL *crl = CRL_from_strings(kEmptyIdpCRL); - int test; + X509_CRL *empty_idp_crl = CRL_from_strings(kEmptyIdpCRL); + int r; - test = TEST_ptr(root) - && TEST_ptr(leaf) - && TEST_ptr(crl) - && TEST_int_eq(verify(leaf, root, - make_CRL_stack(crl, NULL), + r = TEST_ptr(empty_idp_crl) + && TEST_int_eq(verify(test_leaf2, test_root2, + make_CRL_stack(empty_idp_crl, NULL), X509_V_FLAG_CRL_CHECK, PARAM_TIME2), X509_V_ERR_UNABLE_TO_GET_CRL); - - X509_CRL_free(crl); - X509_free(leaf); - X509_free(root); - return test; + X509_CRL_free(empty_idp_crl); + return r; } -static int test_crl_critical_known(void) +static int test_known_critical_crl(void) { - X509_CRL *crl = CRL_from_strings(kKnownCriticalCRL); - int test; + X509_CRL *known_critical_crl = CRL_from_strings(kKnownCriticalCRL); + int r; - test = TEST_ptr_null(crl) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_TYPE_NOT_PRIMITIVE) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_ILLEGAL_OBJECT) - && TEST_err_s("CRL: malformed CRL issuing distribution point"); - - X509_CRL_free(crl); - return test; + r = TEST_ptr(known_critical_crl) + && TEST_int_eq(verify(test_leaf, test_root, + make_CRL_stack(known_critical_crl, NULL), + X509_V_FLAG_CRL_CHECK, PARAM_TIME), + X509_V_OK); + X509_CRL_free(known_critical_crl); + return r; } -static int test_crl_critical_unknown1(void) +static int test_unknown_critical_crl(int n) { - X509 *root = X509_from_strings(kCRLTestRoot); - X509 *leaf = X509_from_strings(kCRLTestLeaf); - X509_CRL *crl = CRL_from_strings(kUnknownCriticalCRL); + X509_CRL *unknown_critical_crl = CRL_from_strings(unknown_critical_crls[n]); + int r; - int test; - test = TEST_ptr(root) - && TEST_ptr(leaf) - && TEST_ptr(crl) - && TEST_int_eq(verify(leaf, root, - make_CRL_stack(crl, NULL), + r = TEST_ptr(unknown_critical_crl) + && TEST_int_eq(verify(test_leaf, test_root, + make_CRL_stack(unknown_critical_crl, NULL), X509_V_FLAG_CRL_CHECK, PARAM_TIME), X509_V_ERR_UNHANDLED_CRITICAL_CRL_EXTENSION); - - X509_CRL_free(crl); - X509_free(leaf); - X509_free(root); - return test; -} - -static int test_crl_critical_unknown2(void) -{ - X509_CRL *crl; - int test; - - test = TEST_ptr_null((crl = CRL_from_strings(kUnknownCriticalCRL2))) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_TYPE_NOT_PRIMITIVE) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_ILLEGAL_OBJECT) - && TEST_err_s("CRL: malformed CRL issuing distribution point"); - - return test; + X509_CRL_free(unknown_critical_crl); + return r; } static int test_reuse_crl(int idx) @@ -1413,23 +628,48 @@ static int test_crl_cert_issuer_ext(void) return test; } +/* + * This function clears the error stack before parsing and delegates the actual + * decoding to CRL_from_strings(). + */ +static X509_CRL *crl_clear_err_parse(const char **pem) +{ + ERR_clear_error(); + return CRL_from_strings(pem); +} + +/* + * Checks whether a specific error reason is present in the error stack. + * This function iterates over the current thread's error queue using + * ERR_get_error_all(), extracting all pending errors. If any of them match + * the specified reason code (as returned by ERR_GET_REASON()), the function + * returns 1 to indicate that the corresponding error was found. + */ +static int err_chk(int lib, int reason) +{ +#if defined(OPENSSL_NO_ERR) || defined(OPENSSL_SMALL_FOOTPRINT) || defined(OPENSSL_NO_DEPRECATED_3_0) || defined(OPENSSL_NO_HTTP) + return 1; +#endif + unsigned long e; + + while ((e = ERR_get_error_all(NULL, NULL, NULL, NULL, NULL))) + if (ERR_GET_LIB(e) == lib && ERR_GET_REASON(e) == reason) + return 1; + + return 0; +} + static int test_crl_date_invalid(void) { X509_CRL *tmm = NULL, *tss = NULL, *utc = NULL; - int test; + int test = 0; - test = TEST_ptr_null((tmm = CRL_from_strings(kInvalidDateMM))) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_GENERALIZEDTIME_IS_TOO_SHORT) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_ILLEGAL_TIME_VALUE) - && TEST_err_s("invalidityDate in CRL is not well-formed") - && TEST_ptr_null((tss = CRL_from_strings(kInvalidDateSS))) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_GENERALIZEDTIME_IS_TOO_SHORT) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_ILLEGAL_TIME_VALUE) - && TEST_err_s("invalidityDate in CRL is not well-formed") - && TEST_ptr_null((utc = CRL_from_strings(kInvalidDateUTC))) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_WRONG_TAG) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_ILLEGAL_TIME_VALUE) - && TEST_err_s("invalidityDate in CRL is not well-formed"); + test = TEST_ptr_null((tmm = crl_clear_err_parse(kInvalidDateMM))) + && TEST_true(err_chk(ERR_LIB_ASN1, ASN1_R_GENERALIZEDTIME_IS_TOO_SHORT)) + && TEST_ptr_null((tss = crl_clear_err_parse(kInvalidDateSS))) + && TEST_true(err_chk(ERR_LIB_ASN1, ASN1_R_GENERALIZEDTIME_IS_TOO_SHORT)) + && TEST_ptr_null((utc = crl_clear_err_parse(kInvalidDateUTC))) + && TEST_true(err_chk(ERR_LIB_ASN1, ASN1_R_WRONG_TAG)); X509_CRL_free(tmm); X509_CRL_free(utc); @@ -1448,39 +688,36 @@ static int get_crl_fn(X509_STORE_CTX *ctx, X509_CRL **crl, X509 *x) return 1; } -static int test_crl_get_fn_score(void) +static int test_get_crl_fn_score(void) { - X509 *root = X509_from_strings(kCRLTestRoot); - X509 *leaf = X509_from_strings(kCRLTestLeaf); X509_STORE_CTX *ctx = X509_STORE_CTX_new(); X509_STORE *store = X509_STORE_new(); X509_VERIFY_PARAM *param = X509_VERIFY_PARAM_new(); STACK_OF(X509) *roots = sk_X509_new_null(); + int status = X509_V_ERR_UNSPECIFIED; if (!TEST_ptr(ctx) - || !TEST_ptr(root) - || !TEST_ptr(leaf) || !TEST_ptr(store) || !TEST_ptr(param) || !TEST_ptr(roots)) goto err; /* Create a stack; upref the cert because we free it below. */ - if (!TEST_true(X509_up_ref(root))) + if (!TEST_true(X509_up_ref(test_root))) goto err; - if (!TEST_true(sk_X509_push(roots, root))) { - X509_free(root); - root = NULL; + if (!TEST_true(sk_X509_push(roots, test_root))) { + X509_free(test_root); goto err; } - if (!TEST_true(X509_STORE_CTX_init(ctx, store, leaf, NULL))) + if (!TEST_true(X509_STORE_CTX_init(ctx, store, test_leaf, NULL))) goto err; X509_STORE_CTX_set0_trusted_stack(ctx, roots); X509_STORE_CTX_set_get_crl(ctx, &get_crl_fn); X509_VERIFY_PARAM_set_time(param, PARAM_TIME); - if (!TEST_long_eq((long)X509_VERIFY_PARAM_get_time(param), (long)PARAM_TIME)) + if (!TEST_long_eq((long)X509_VERIFY_PARAM_get_time(param), + (long)PARAM_TIME)) goto err; X509_VERIFY_PARAM_set_depth(param, 16); X509_VERIFY_PARAM_set_flags(param, X509_V_FLAG_CRL_CHECK); @@ -1498,541 +735,35 @@ err: X509_VERIFY_PARAM_free(param); X509_STORE_CTX_free(ctx); X509_STORE_free(store); - X509_free(root); - X509_free(leaf); return status == X509_V_OK; } -static int test_crl_delta_indicator(void) -{ - X509_CRL *crl; - int test; - - test = TEST_ptr_null((crl = CRL_from_strings(kCrlDeltaIndicatorString))) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_WRONG_TAG) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_ILLEGAL_OBJECT) - && TEST_err_s("CRL: malformed Delta CRL Indicator"); - - X509_CRL_free(crl); - return test; -} - -static int test_crl_number(void) -{ - X509_CRL *crl; - int test; - - test = TEST_ptr_null((crl = CRL_from_strings(kCrlNumberString))) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_WRONG_TAG) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_ILLEGAL_OBJECT) - && TEST_err_s("CRL: malformed CRL number extension"); - - X509_CRL_free(crl); - return test; -} - -static int test_crl_idp_asn1_wrong_tag(void) -{ - X509_CRL *crl; - int test; - - test = TEST_ptr_null((crl = CRL_from_strings(kCrlIDPWrongTag))) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_WRONG_TAG) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_ILLEGAL_OBJECT) - && TEST_err_s("CRL: malformed CRL issuing distribution point"); - - X509_CRL_free(crl); - return test; -} - -static int test_crl_idp_asn1_wrong_tag2(void) -{ - X509_CRL *crl; - int test; - - test = TEST_ptr_null((crl = CRL_from_strings(kCrlIDPWrongTag2))) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_WRONG_TAG) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_ILLEGAL_OBJECT) - && TEST_err_s("CRL: malformed CRL issuing distribution point"); - - X509_CRL_free(crl); - return test; -} - -/* - * Verify that the private keys correspond to their certificates. This avoids - * having unused variables while also ensuring the keys are valid and usable, so - * they can serve as a basis for additional test cases in the future. - */ -static int test_private_keys(void) -{ - X509 *root = NULL; - X509 *leaf = NULL; - EVP_PKEY *root_pkey = NULL; - EVP_PKEY *leaf_pkey = NULL; - EVP_PKEY *root_pub = NULL; - EVP_PKEY *leaf_pub = NULL; - int test; - - test = TEST_ptr(root = X509_from_strings(kRoot)) - && TEST_ptr(leaf = X509_from_strings(kLeaf)) - && TEST_ptr(root_pkey = PKEY_from_strings(kRootPrivateKey)) - && TEST_ptr(leaf_pkey = PKEY_from_strings(kLeafPrivateKey)) - && TEST_ptr(root_pub = X509_get_pubkey(root)) - && TEST_ptr(leaf_pub = X509_get_pubkey(leaf)) - && TEST_int_eq(EVP_PKEY_eq(root_pub, root_pkey), 1) - && TEST_int_eq(EVP_PKEY_eq(leaf_pub, leaf_pkey), 1); - - EVP_PKEY_free(root_pkey); - EVP_PKEY_free(leaf_pkey); - EVP_PKEY_free(root_pub); - EVP_PKEY_free(leaf_pub); - X509_free(root); - X509_free(leaf); - return test; -} - -static int test_crl_idp_onlyca_onlyattr(void) -{ - X509 *root = NULL; - X509 *leaf = NULL; - X509_CRL *crl = NULL; - STACK_OF(X509_CRL) *crls; - unsigned int flags = X509_V_FLAG_CRL_CHECK; - unsigned int expect = X509_V_ERR_UNABLE_TO_GET_CRL; - int test; - - test = TEST_ptr(root = X509_from_strings(kRoot)) - && TEST_ptr(leaf = X509_from_strings(kLeaf)) - && TEST_ptr((crl = CRL_from_strings(kCrlIDPOnlyCaOnlyAttr))) - && TEST_ptr((crls = make_CRL_stack(crl, NULL))) - && TEST_int_eq(verify(leaf, root, crls, flags, kVerify), expect); - - X509_CRL_free(crl); - X509_free(root); - X509_free(leaf); - return test; -} - -static int test_crl_idp_onlyuser_onlyattr(void) -{ - X509 *root = NULL; - X509 *leaf = NULL; - X509_CRL *crl = NULL; - STACK_OF(X509_CRL) *crls; - unsigned int flags = X509_V_FLAG_CRL_CHECK; - unsigned int expect = X509_V_ERR_UNABLE_TO_GET_CRL; - int test; - - test = TEST_ptr(root = X509_from_strings(kRoot)) - && TEST_ptr(leaf = X509_from_strings(kLeaf)) - && TEST_ptr((crl = CRL_from_strings(kCrlIDPOnlyUserOnlyAttr))) - && TEST_ptr((crls = make_CRL_stack(crl, NULL))) - && TEST_int_eq(verify(leaf, root, crls, flags, kVerify), expect); - - X509_CRL_free(crl); - X509_free(root); - X509_free(leaf); - return test; -} - -static int test_crl_idp_onlyuser_onlyca(void) -{ - X509 *root = NULL; - X509 *leaf = NULL; - X509_CRL *crl = NULL; - STACK_OF(X509_CRL) *crls; - unsigned int flags = X509_V_FLAG_CRL_CHECK; - unsigned int expect = X509_V_ERR_UNABLE_TO_GET_CRL; - int test; - - test = TEST_ptr(root = X509_from_strings(kRoot)) - && TEST_ptr(leaf = X509_from_strings(kLeaf)) - && TEST_ptr((crl = CRL_from_strings(kCrlIDPOnlyUserOnlyCA))) - && TEST_ptr((crls = make_CRL_stack(crl, NULL))) - && TEST_int_eq(verify(leaf, root, crls, flags, kVerify), expect); - - X509_CRL_free(crl); - X509_free(root); - X509_free(leaf); - return test; -} - -static int test_crl_idp_onlyuser_onlyca_onlyattr(void) -{ - X509 *root = NULL; - X509 *leaf = NULL; - X509_CRL *crl = NULL; - STACK_OF(X509_CRL) *crls; - unsigned int flags = X509_V_FLAG_CRL_CHECK; - unsigned int expect = X509_V_ERR_UNABLE_TO_GET_CRL; - int test; - - test = TEST_ptr(root = X509_from_strings(kRoot)) - && TEST_ptr(leaf = X509_from_strings(kLeaf)) - && TEST_ptr((crl = CRL_from_strings(kCrlIDPOnlyUserOnlyCAOnlyAttr))) - && TEST_ptr((crls = make_CRL_stack(crl, NULL))) - && TEST_int_eq(verify(leaf, root, crls, flags, kVerify), expect); - - X509_CRL_free(crl); - X509_free(root); - X509_free(leaf); - return test; -} - -static int test_crl_idp_cert_issuer_no_indirect_flag(void) -{ - X509_CRL *crl = NULL; - int test; - - test = TEST_ptr_null((crl = CRL_from_strings(kCrlCINoIndirectFlag))) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_INVALID_VALUE) - && TEST_err_s("CRL Certificate Issuer extension requires Indirect CRL flag to be set"); - - X509_CRL_free(crl); - return test; -} - -static int test_crl_revocation(void) -{ - X509 *root = NULL; - X509 *leaf = NULL; - X509_CRL *crl = NULL; - STACK_OF(X509_CRL) *crls; - unsigned int flags = X509_V_FLAG_CRL_CHECK; - int test; - - test = TEST_ptr(root = X509_from_strings(kRoot)) - && TEST_ptr(leaf = X509_from_strings(kLeaf)) - && TEST_ptr((crl = CRL_from_strings(kCrlRecovated))) - && TEST_ptr((crls = make_CRL_stack(crl, NULL))) - && TEST_int_eq(verify(leaf, root, crls, flags, kVerify), X509_V_OK); - - X509_CRL_free(crl); - X509_free(root); - X509_free(leaf); - return test; -} - -static int test_crl_extension_duplicate(void) -{ - X509_CRL *crl = NULL; - int test; - - test = TEST_ptr_null((crl = CRL_from_strings(kCrlExtensionDuplicate))) - && TEST_err_s("CRL: malformed CRL number extension"); - - X509_CRL_free(crl); - return test; -} - -static int test_crl_extension_duplicate_entry(void) -{ - X509 *root = NULL; - X509 *leaf = NULL; - X509_CRL *crl = NULL; - STACK_OF(X509_CRL) *crls; - unsigned int flags = X509_V_FLAG_CRL_CHECK; - unsigned int expect = X509_V_ERR_CERT_REVOKED; - int test; - - test = TEST_ptr(root = X509_from_strings(kRoot)) - && TEST_ptr(leaf = X509_from_strings(kLeaf)) - && TEST_ptr((crl = CRL_from_strings(kCrlExtensionDuplicateEntry))) - && TEST_ptr((crls = make_CRL_stack(crl, NULL))) - && TEST_int_eq(verify(leaf, root, crls, flags, kVerify), expect); - - X509_CRL_free(crl); - X509_free(root); - X509_free(leaf); - return test; -} - -static int test_crl_extension_duplicate_serial(void) -{ - X509 *root = NULL; - X509 *leaf = NULL; - X509_CRL *crl = NULL; - STACK_OF(X509_CRL) *crls; - unsigned int flags = X509_V_FLAG_CRL_CHECK; - unsigned int expect = X509_V_ERR_CERT_REVOKED; - int test; - - test = TEST_ptr(root = X509_from_strings(kRoot)) - && TEST_ptr(leaf = X509_from_strings(kLeaf)) - && TEST_ptr((crl = CRL_from_strings(kCrlExtensionDuplicateSerial))) - && TEST_ptr((crls = make_CRL_stack(crl, NULL))) - && TEST_int_eq(verify(leaf, root, crls, flags, kVerify), expect); - - X509_CRL_free(crl); - X509_free(root); - X509_free(leaf); - return test; -} - -static int test_crl_indirect_mfail(void) -{ - X509 *root = NULL; - X509 *icrl_issuer = NULL; - X509 *leaf = NULL; - X509_CRL *crl = NULL; - STACK_OF(X509) *untrusted = NULL; - STACK_OF(X509_CRL) *crls = NULL; - unsigned long flags = X509_V_FLAG_CRL_CHECK - | X509_V_FLAG_EXTENDED_CRL_SUPPORT; - int test; - - test = TEST_ptr(root = X509_from_strings(kRoot)) - && TEST_ptr(icrl_issuer = X509_from_strings(kIndirectCRLIssuer)) - && TEST_ptr(leaf = X509_from_strings(kIndirectLeaf)) - && TEST_ptr(crl = CRL_from_strings(kCrlIndirect)) - && TEST_ptr(untrusted = sk_X509_new_null()) - && TEST_true(sk_X509_push(untrusted, icrl_issuer)) - && TEST_ptr(crls = make_CRL_stack(crl, NULL)); - - if (test) { - test = verify_ex(leaf, root, NULL, untrusted, crls, flags, kVerify, 1) - == X509_V_OK; - } - - sk_X509_free(untrusted); - X509_CRL_free(crl); - X509_free(icrl_issuer); - X509_free(leaf); - X509_free(root); - return test; -} - -static int test_crl_indirect_revoked(void) -{ - X509 *root = NULL; - X509 *icrl_issuer = NULL; - X509 *leaf = NULL; - X509_CRL *crl = NULL; - STACK_OF(X509) *untrusted = NULL; - STACK_OF(X509_CRL) *crls; - unsigned long flags = X509_V_FLAG_CRL_CHECK - | X509_V_FLAG_EXTENDED_CRL_SUPPORT; - int test; - - test = TEST_ptr(root = X509_from_strings(kRoot)) - && TEST_ptr(icrl_issuer = X509_from_strings(kIndirectCRLIssuer)) - && TEST_ptr(leaf = X509_from_strings(kIndirectLeaf)) - && TEST_ptr(crl = CRL_from_strings(kCrlIndirectRevoked)) - && TEST_ptr(untrusted = sk_X509_new_null()) - && TEST_true(sk_X509_push(untrusted, icrl_issuer)) - && TEST_ptr(crls = make_CRL_stack(crl, NULL)) - && TEST_int_eq(verify_ex(leaf, root, NULL, untrusted, crls, flags, kVerify, 1), - X509_V_ERR_CERT_REVOKED); - - sk_X509_free(untrusted); - X509_CRL_free(crl); - X509_free(icrl_issuer); - X509_free(leaf); - X509_free(root); - return test; -} - -static int test_crl_indirect_wrong_ta(void) -{ - X509 *root = NULL; - X509 *root2 = NULL; - X509 *icrl_issuer = NULL; - X509 *leaf = NULL; - X509_CRL *crl = NULL; - STACK_OF(X509) *untrusted = NULL; - STACK_OF(X509_CRL) *crls; - unsigned long flags = X509_V_FLAG_CRL_CHECK - | X509_V_FLAG_EXTENDED_CRL_SUPPORT; - int test; - - test = TEST_ptr(root = X509_from_strings(kRoot)) - && TEST_ptr(root2 = X509_from_strings(kRoot2)) - && TEST_ptr(icrl_issuer = X509_from_strings(kIndirectCRLIssuerAlt)) - && TEST_ptr(leaf = X509_from_strings(kIndirectLeaf)) - && TEST_ptr(crl = CRL_from_strings(kCrlIndirectAlt)) - && TEST_ptr(untrusted = sk_X509_new_null()) - && TEST_true(sk_X509_push(untrusted, icrl_issuer)) - && TEST_ptr(crls = make_CRL_stack(crl, NULL)) - && TEST_int_eq(verify_ex(leaf, root, root2, untrusted, crls, flags, - kVerify, 1), - X509_V_ERR_CRL_PATH_VALIDATION_ERROR); - - sk_X509_free(untrusted); - X509_CRL_free(crl); - X509_free(icrl_issuer); - X509_free(leaf); - X509_free(root2); - X509_free(root); - return test; -} - -static int test_crl_indirect_no_chain(void) -{ - X509 *root = NULL; - X509 *icrl_issuer = NULL; - X509 *leaf = NULL; - X509_CRL *crl = NULL; - STACK_OF(X509) *untrusted = NULL; - STACK_OF(X509_CRL) *crls; - unsigned long flags = X509_V_FLAG_CRL_CHECK - | X509_V_FLAG_EXTENDED_CRL_SUPPORT; - int test; - - test = TEST_ptr(root = X509_from_strings(kRoot)) - && TEST_ptr(icrl_issuer = X509_from_strings(kIndirectCRLIssuerNoChain)) - && TEST_ptr(leaf = X509_from_strings(kIndirectLeaf)) - && TEST_ptr(crl = CRL_from_strings(kCrlIndirectNoChain)) - && TEST_ptr(untrusted = sk_X509_new_null()) - && TEST_true(sk_X509_push(untrusted, icrl_issuer)) - && TEST_ptr(crls = make_CRL_stack(crl, NULL)) - && TEST_int_eq(verify_ex(leaf, root, NULL, untrusted, crls, flags, - kVerify, 1), - X509_V_ERR_CRL_PATH_VALIDATION_ERROR); - - sk_X509_free(untrusted); - X509_CRL_free(crl); - X509_free(icrl_issuer); - X509_free(leaf); - X509_free(root); - return test; -} - -static int test_crl_diff_mfail(void) -{ - X509_CRL *base_crl = NULL, *newer_crl = NULL, *delta = NULL; - int ret = 0; - - base_crl = CRL_from_strings(kBasicCRL); - newer_crl = CRL_from_strings(kRevokedCRL); - if (!TEST_ptr(base_crl) || !TEST_ptr(newer_crl)) - goto err; - - MFAIL_start(); - delta = X509_CRL_diff(base_crl, newer_crl, NULL, NULL, 0); - MFAIL_end(); - - if (delta == NULL) - goto err; - - ret = 1; -err: - X509_CRL_free(delta); - X509_CRL_free(base_crl); - X509_CRL_free(newer_crl); - return ret; -} - -/* - * Check that X509_CRL_verify() rejects a CRL where the outer - * signatureAlgorithm does not match the inner copy inside TBSCertList. - * RFC 5280 section 5.1.1.2 requires the two to be identical; X509_verify() - * and X509_ACERT_verify() enforce this, and so must X509_CRL_verify(). - * - * Both CRLs are issued by kRoot (RSA-2048). kCrlMismatchedSigAlg carries a - * valid RSA-SHA256 signature over a TBSCertList whose inner signatureAlgorithm - * claims ecdsaWithSHA256, while the outer wrapper carries the correct - * sha256WithRSAEncryption. Without the inner/outer comparison the signature - * would verify and the CRL would be accepted. - */ -static int test_crl_sigalg_mismatch(void) -{ - X509 *root = X509_from_strings(kRoot); - X509_CRL *good = CRL_from_strings(kCrlRootCA); - X509_CRL *bad = CRL_from_strings(kCrlMismatchedSigAlg); - EVP_PKEY *pkey = NULL; - int ret = 0; - - if (!TEST_ptr(root) || !TEST_ptr(good) || !TEST_ptr(bad)) - goto end; - - pkey = X509_get0_pubkey(root); - if (!TEST_ptr(pkey)) - goto end; - - /* Well-formed CRL: inner and outer algorithms match; verify succeeds. */ - if (!TEST_int_eq(X509_CRL_verify(good, pkey), 1)) - goto end; - - /* - * Mismatched CRL: inner signatureAlgorithm is ecdsaWithSHA256, outer is - * sha256WithRSAEncryption, RSA signature is valid. X509_ALGOR_cmp() - * must catch the mismatch before the signature is checked. - */ - if (!TEST_int_eq(X509_CRL_verify(bad, pkey), 0)) - goto end; - - ret = 1; -end: - X509_CRL_free(good); - X509_CRL_free(bad); - X509_free(root); - return ret; -} - -/* - * Exercise the X509_V_FLAG_USE_DELTAS path. kCrlDeltaBase carries a Freshest - * CRL extension and revokes nothing; kCrlDeltaValid is a current delta that - * revokes kLeaf. The delta is in scope, so verification reports kLeaf revoked. - */ -static int test_crl_delta_valid(void) -{ - X509 *root = X509_from_strings(kRoot); - X509 *leaf = X509_from_strings(kLeaf); - X509_CRL *base = CRL_from_strings(kCrlDeltaBase); - X509_CRL *delta = CRL_from_strings(kCrlDeltaValid); - unsigned long flags = X509_V_FLAG_CRL_CHECK - | X509_V_FLAG_EXTENDED_CRL_SUPPORT | X509_V_FLAG_USE_DELTAS; - int test; - - test = TEST_ptr(root) - && TEST_ptr(leaf) - && TEST_ptr(base) - && TEST_ptr(delta) - && TEST_int_eq(verify(leaf, root, make_CRL_stack(base, delta), - flags, kVerify), - X509_V_ERR_CERT_REVOKED); - - X509_CRL_free(base); - X509_CRL_free(delta); - X509_free(leaf); - X509_free(root); - return test; -} - int setup_tests(void) { - ADD_TEST(test_private_keys); + if (!TEST_ptr(test_root = X509_from_strings(kCRLTestRoot)) + || !TEST_ptr(test_leaf = X509_from_strings(kCRLTestLeaf)) + || !TEST_ptr(test_root2 = X509_from_strings(kCRLTestRoot2)) + || !TEST_ptr(test_leaf2 = X509_from_strings(kCRLTestLeaf2))) + return 0; + ADD_TEST(test_no_crl); - ADD_TEST(test_crl_basic); - ADD_TEST(test_crl_bad_issuer); + ADD_TEST(test_basic_crl); + ADD_TEST(test_bad_issuer_crl); ADD_TEST(test_crl_empty_idp); - ADD_TEST(test_crl_critical_known); + ADD_TEST(test_known_critical_crl); ADD_TEST(test_crl_cert_issuer_ext); ADD_TEST(test_crl_date_invalid); - ADD_TEST(test_crl_get_fn_score); - ADD_TEST(test_crl_delta_indicator); - ADD_TEST(test_crl_delta_valid); - ADD_TEST(test_crl_number); - ADD_TEST(test_crl_idp_asn1_wrong_tag); - ADD_TEST(test_crl_idp_asn1_wrong_tag2); - ADD_TEST(test_crl_idp_onlyca_onlyattr); - ADD_TEST(test_crl_idp_onlyuser_onlyattr); - ADD_TEST(test_crl_idp_onlyuser_onlyca); - ADD_TEST(test_crl_idp_onlyuser_onlyca_onlyattr); - ADD_TEST(test_crl_idp_cert_issuer_no_indirect_flag); - ADD_TEST(test_crl_critical_unknown1); - ADD_TEST(test_crl_critical_unknown2); - ADD_TEST(test_crl_revocation); - ADD_TEST(test_crl_extension_duplicate); - ADD_TEST(test_crl_extension_duplicate_entry); - ADD_TEST(test_crl_extension_duplicate_serial); - ADD_MFAIL_NO_CHECK_TEST(test_crl_indirect_mfail); - ADD_TEST(test_crl_indirect_revoked); - ADD_TEST(test_crl_indirect_wrong_ta); - ADD_TEST(test_crl_indirect_no_chain); + ADD_TEST(test_get_crl_fn_score); + ADD_ALL_TESTS(test_unknown_critical_crl, OSSL_NELEM(unknown_critical_crls)); ADD_ALL_TESTS(test_reuse_crl, 6); - ADD_MFAIL_TEST(test_crl_diff_mfail); - ADD_TEST(test_crl_sigalg_mismatch); + return 1; } + +void cleanup_tests(void) +{ + X509_free(test_root); + X509_free(test_leaf); + X509_free(test_root2); + X509_free(test_leaf2); +} diff --git a/test/crypto_memcmp_test.c b/test/crypto_memcmp_test.c deleted file mode 100644 index 479c54cf76..0000000000 --- a/test/crypto_memcmp_test.c +++ /dev/null @@ -1,102 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* - * Functional and constant-time tests for CRYPTO_memcmp(). - * - * CRYPTO_memcmp() must compare its two operands without any control-flow - * branch or memory access that depends on the operand *contents* (only the - * length is public). - * - * When built with enable-ct-validation (OPENSSL_CONSTANT_TIME_VALIDATION), - * CONSTTIME_SECRET marks the operands as "undefined" for Valgrind's memcheck; - * any branch or memory index derived from them then makes Valgrind exit - * non-zero. Because the taint is injected here at the call site, this test - * verifies whichever CRYPTO_memcmp implementation is actually linked -- the - * per-arch assembler version where one exists (x86_64, aarch64, ...), or the - * C fallback in crypto/cpuid.c otherwise. Outside a CT build the macros are - * no-ops and this is an ordinary functional test. - * - * The accumulated comparison result is the function's intended *public* - * output, so it is declassified before being asserted on; the operand buffers - * are declassified too so the (stack) memory does not stay tainted. - */ - -#include - -#include "internal/nelem.h" -#include "internal/constant_time.h" -#include "testutil.h" - -#define MAX_LEN 64 - -/* - * len == 16 exercises the dedicated fast path in several assembler versions - * (e.g. crypto/x86_64cpuid.pl); the other lengths exercise the byte loop and - * the empty-input early return. - */ -static const struct { - /* byte length of buffers to compare; must be <= MAX_LEN */ - size_t len; - /* index at which the second buffer differs, or -1 for equal buffers */ - int diff_pos; -} memcmp_cases[] = { - /* empty: always equal */ - { 0, -1 }, - { 1, -1 }, - { 1, 0 }, - - /* asm fast path (length = 16) */ - { 16, -1 }, - { 16, 0 }, - { 16, 8 }, - { 16, 15 }, - - /* byte loop */ - { 64, -1 }, - { 64, 0 }, - { 64, 31 }, - { 64, 63 }, -}; - -static int test_crypto_memcmp(int idx) -{ - size_t i; - size_t len = memcmp_cases[idx].len; - int diff_pos = memcmp_cases[idx].diff_pos; - /* nonzero result iff buffers differ */ - int expected = diff_pos >= 0; - unsigned char a[MAX_LEN], b[MAX_LEN]; - int result; - - for (i = 0; i < len; i++) - a[i] = b[i] = (unsigned char)(i * 7 + 1); - if (diff_pos >= 0) - b[diff_pos] ^= 0xff; - - CONSTTIME_SECRET(a, len); - CONSTTIME_SECRET(b, len); - - result = CRYPTO_memcmp(a, b, len); - - CONSTTIME_DECLASSIFY(&result, sizeof(result)); - CONSTTIME_DECLASSIFY(a, len); - CONSTTIME_DECLASSIFY(b, len); - - if (!TEST_int_eq(result != 0, expected)) - return 0; - else - return 1; -} - -int setup_tests(void) -{ - ADD_ALL_TESTS(test_crypto_memcmp, OSSL_NELEM(memcmp_cases)); - return 1; -} diff --git a/test/ct_test.c b/test/ct_test.c index 51cad3eaae..183e7d8de6 100644 --- a/test/ct_test.c +++ b/test/ct_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -149,7 +149,7 @@ end: return result; } -static int compare_extension_printout(const X509_EXTENSION *extension, +static int compare_extension_printout(X509_EXTENSION *extension, const char *expected_output) { BIO *text_buffer = NULL; @@ -250,7 +250,7 @@ static int execute_cert_test(CT_TEST_FIXTURE *fixture) if (fixture->certificate_file != NULL) { int sct_extension_index; int i; - const X509_EXTENSION *sct_extension = NULL; + X509_EXTENSION *sct_extension = NULL; if (!TEST_ptr(cert = load_pem_cert(fixture->certs_dir, fixture->certificate_file))) @@ -479,14 +479,10 @@ static int test_default_ct_policy_eval_ctx_time_is_now(void) int success = 0; CT_POLICY_EVAL_CTX *ct_policy_ctx = CT_POLICY_EVAL_CTX_new(); const time_t default_time = (time_t)(CT_POLICY_EVAL_CTX_get_time(ct_policy_ctx) / 1000); - const double time_tolerance = 600; /* 10 minutes */ - double seconds; + const time_t time_tolerance = 600; /* 10 minutes */ - seconds = difftime(time(NULL), default_time); - if (seconds < 0.0) - seconds = -seconds; - - if (!TEST_double_le(seconds, time_tolerance)) + if (!TEST_time_t_le(abs((int)difftime(time(NULL), default_time)), + time_tolerance)) goto end; success = 1; @@ -508,131 +504,6 @@ static int test_ctlog_from_base64(void) return 0; return 1; } - -static int test_ctlog_store_add0_log(void) -{ - CTLOG_STORE *store = NULL; - CTLOG *log = NULL; - const CTLOG *found = NULL; - const uint8_t *log_id = NULL; - size_t log_id_len = 0; - int result = 0; - const char pkey_base64[] = "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEmXg8sUUzwBYaWrRb+V0IopzQ6o3U" - "yEJ04r5ZrRXGdpYM8K+hB0pXrGRLI0eeWz+3skXrS0IO83AhA3GpRL6s6w=="; - const char name[] = "test log"; - - if (!TEST_ptr(store = CTLOG_STORE_new())) - goto end; - if (!TEST_true(CTLOG_new_from_base64(&log, pkey_base64, name))) - goto end; - - CTLOG_get0_log_id(log, &log_id, &log_id_len); - if (!TEST_size_t_eq(log_id_len, CT_V1_HASHLEN)) - goto end; - if (!TEST_ptr_null(CTLOG_STORE_get0_log_by_id(store, log_id, log_id_len))) - goto end; - - if (!TEST_true(CTLOG_STORE_add0_log(store, log))) - goto end; - log = NULL; - - found = CTLOG_STORE_get0_log_by_id(store, log_id, log_id_len); - if (!TEST_ptr(found)) - goto end; - if (!TEST_str_eq(CTLOG_get0_name(found), name)) - goto end; - - result = 1; - -end: - CTLOG_STORE_free(store); - CTLOG_free(log); - return result; -} - -static int test_ctlog_store_add0_log_validates_sct(void) -{ - CTLOG_STORE *store = NULL; - CTLOG *log = NULL; - CT_POLICY_EVAL_CTX *ct_policy_ctx = NULL; - X509 *cert = NULL, *issuer = NULL; - STACK_OF(SCT) *scts = NULL; - const X509_EXTENSION *sct_extension = NULL; - int result = 0; - const char pkey_base64[] = "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEmXg8sUUzwBYaWrRb+V0IopzQ6o3U" - "yEJ04r5ZrRXGdpYM8K+hB0pXrGRLI0eeWz+3skXrS0IO83AhA3GpRL6s6w=="; - - if (!TEST_ptr(store = CTLOG_STORE_new())) - goto end; - if (!TEST_true(CTLOG_new_from_base64(&log, pkey_base64, "test"))) - goto end; - if (!TEST_true(CTLOG_STORE_add0_log(store, log))) - goto end; - log = NULL; - - if (!TEST_ptr(ct_policy_ctx = CT_POLICY_EVAL_CTX_new())) - goto end; - CT_POLICY_EVAL_CTX_set_shared_CTLOG_STORE(ct_policy_ctx, store); - CT_POLICY_EVAL_CTX_set_time(ct_policy_ctx, 1580335307000ULL); - - if (!TEST_ptr(cert = load_pem_cert(certs_dir, "embeddedSCTs1.pem"))) - goto end; - if (!TEST_ptr(issuer = load_pem_cert(certs_dir, "embeddedSCTs1_issuer.pem"))) - goto end; - CT_POLICY_EVAL_CTX_set1_cert(ct_policy_ctx, cert); - CT_POLICY_EVAL_CTX_set1_issuer(ct_policy_ctx, issuer); - - sct_extension = X509_get_ext(cert, - X509_get_ext_by_NID(cert, NID_ct_precert_scts, -1)); - if (!TEST_ptr(sct_extension)) - goto end; - if (!TEST_ptr(scts = X509V3_EXT_d2i(sct_extension))) - goto end; - if (!TEST_int_eq(sk_SCT_num(scts), 1)) - goto end; - if (!TEST_int_ge(SCT_LIST_validate(scts, ct_policy_ctx), 0)) - goto end; - if (!TEST_int_eq(SCT_get_validation_status(sk_SCT_value(scts, 0)), - SCT_VALIDATION_STATUS_VALID)) - goto end; - - result = 1; - -end: - CTLOG_STORE_free(store); - CTLOG_free(log); - CT_POLICY_EVAL_CTX_free(ct_policy_ctx); - X509_free(cert); - X509_free(issuer); - SCT_LIST_free(scts); - return result; -} - -static int test_ctlog_store_add0_log_null(void) -{ - CTLOG_STORE *store = NULL; - CTLOG *log = NULL; - int result = 0; - const char pkey_base64[] = "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEmXg8sUUzwBYaWrRb+V0IopzQ6o3U" - "yEJ04r5ZrRXGdpYM8K+hB0pXrGRLI0eeWz+3skXrS0IO83AhA3GpRL6s6w=="; - - if (!TEST_ptr(store = CTLOG_STORE_new())) - goto end; - if (!TEST_false(CTLOG_STORE_add0_log(store, NULL))) - goto end; - - if (!TEST_true(CTLOG_new_from_base64(&log, pkey_base64, "test"))) - goto end; - if (!TEST_false(CTLOG_STORE_add0_log(NULL, log))) - goto end; - - result = 1; - -end: - CTLOG_STORE_free(store); - CTLOG_free(log); - return result; -} #endif int setup_tests(void) @@ -653,9 +524,6 @@ int setup_tests(void) ADD_TEST(test_encode_tls_sct); ADD_TEST(test_default_ct_policy_eval_ctx_time_is_now); ADD_TEST(test_ctlog_from_base64); - ADD_TEST(test_ctlog_store_add0_log); - ADD_TEST(test_ctlog_store_add0_log_validates_sct); - ADD_TEST(test_ctlog_store_add0_log_null); #else printf("No CT support\n"); #endif diff --git a/test/danetest.c b/test/danetest.c index f9e30388e1..1b0320b28d 100644 --- a/test/danetest.c +++ b/test/danetest.c @@ -370,7 +370,7 @@ static int test_tlsafile(SSL_CTX *ctx, const char *base_name, continue; } if (!TEST_int_eq(mdpth, want_depth)) { - TEST_info("In test %d", testno); + TEST_info("In test test %d", testno); ret = 0; } } diff --git a/test/defltfips_test.c b/test/defltfips_test.c index c962f14385..16d834b020 100644 --- a/test/defltfips_test.c +++ b/test/defltfips_test.c @@ -17,7 +17,7 @@ static int bad_fips; static int test_is_fips_enabled(void) { - int is_fips_enabled, is_fips_loaded, is_fips_legacy; + int is_fips_enabled, is_fips_loaded; EVP_MD *sha256 = NULL; /* @@ -26,19 +26,16 @@ static int test_is_fips_enabled(void) * other function calls have auto-loaded the config file. */ is_fips_enabled = EVP_default_properties_is_fips_enabled(NULL); - is_fips_legacy = FIPS_mode(); is_fips_loaded = OSSL_PROVIDER_available(NULL, "fips"); /* * Check we're in an expected state. EVP_default_properties_is_fips_enabled * can return true even if the FIPS provider isn't loaded - it is only based * on the default properties. However we only set those properties if also - * loading the FIPS provider. Also check that the legacy API matches the - * provider API. + * loading the FIPS provider. */ if (!TEST_int_eq(is_fips || bad_fips, is_fips_enabled) - || !TEST_int_eq(is_fips && !bad_fips, is_fips_loaded) - || !TEST_int_eq(is_fips_legacy, is_fips_enabled)) + || !TEST_int_eq(is_fips && !bad_fips, is_fips_loaded)) return 0; /* diff --git a/test/destest.c b/test/destest.c index a5fa3b51a5..a5ede56364 100644 --- a/test/destest.c +++ b/test/destest.c @@ -195,10 +195,46 @@ static unsigned char cbc_iv[8] = { */ /* static char cbc_data[40]="7654321 Now is the time for \0001"; */ static unsigned char cbc_data[40] = { - 0x37, 0x36, 0x35, 0x34, 0x33, 0x32, 0x31, 0x20, 0x4E, 0x6F, - 0x77, 0x20, 0x69, 0x73, 0x20, 0x74, 0x68, 0x65, 0x20, 0x74, - 0x69, 0x6D, 0x65, 0x20, 0x66, 0x6F, 0x72, 0x20, 0x00, 0x31, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 + 0x37, + 0x36, + 0x35, + 0x34, + 0x33, + 0x32, + 0x31, + 0x20, + 0x4E, + 0x6F, + 0x77, + 0x20, + 0x69, + 0x73, + 0x20, + 0x74, + 0x68, + 0x65, + 0x20, + 0x74, + 0x69, + 0x6D, + 0x65, + 0x20, + 0x66, + 0x6F, + 0x72, + 0x20, + 0x00, + 0x31, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, }; static unsigned char cbc_ok[32] = { @@ -215,17 +251,73 @@ static unsigned char cbc2_key[8] = { 0xf0, 0xe1, 0xd2, 0xc3, 0xb4, 0xa5, 0x96, 0x87 }; static unsigned char xcbc_ok[32] = { - 0x86, 0x74, 0x81, 0x0D, 0x61, 0xA4, 0xA5, 0x48, 0xB9, 0x93, - 0x03, 0xE1, 0xB8, 0xBB, 0xBD, 0xBD, 0x64, 0x30, 0x0B, 0xB9, - 0x06, 0x65, 0x81, 0x76, 0x04, 0x1D, 0x77, 0x62, 0x17, 0xCA, - 0x2B, 0xD2 + 0x86, + 0x74, + 0x81, + 0x0D, + 0x61, + 0xA4, + 0xA5, + 0x48, + 0xB9, + 0x93, + 0x03, + 0xE1, + 0xB8, + 0xBB, + 0xBD, + 0xBD, + 0x64, + 0x30, + 0x0B, + 0xB9, + 0x06, + 0x65, + 0x81, + 0x76, + 0x04, + 0x1D, + 0x77, + 0x62, + 0x17, + 0xCA, + 0x2B, + 0xD2, }; #else static unsigned char xcbc_ok[32] = { - 0x84, 0x6B, 0x29, 0x14, 0x85, 0x1E, 0x9A, 0x29, 0x54, 0x73, - 0x2F, 0x8A, 0xA0, 0xA6, 0x11, 0xC1, 0x15, 0xCD, 0xC2, 0xD7, - 0x95, 0x1B, 0x10, 0x53, 0xA6, 0x3C, 0x5E, 0x03, 0xB2, 0x1A, - 0xA3, 0xC4 + 0x84, + 0x6B, + 0x29, + 0x14, + 0x85, + 0x1E, + 0x9A, + 0x29, + 0x54, + 0x73, + 0x2F, + 0x8A, + 0xA0, + 0xA6, + 0x11, + 0xC1, + 0x15, + 0xCD, + 0xC2, + 0xD7, + 0x95, + 0x1B, + 0x10, + 0x53, + 0xA6, + 0x3C, + 0x5E, + 0x03, + 0xB2, + 0x1A, + 0xA3, + 0xC4, }; #endif @@ -604,7 +696,7 @@ static int test_des_ede_cfb64(void) return 0; memcpy(cfb_tmp, cfb_iv, sizeof(cfb_iv)); n = 0; - DES_ede3_cfb64_encrypt(cfb_buf1, cfb_buf2, 17, &ks, &ks, &ks, + DES_ede3_cfb64_encrypt(cfb_buf1, cfb_buf2, (long)17, &ks, &ks, &ks, &cfb_tmp, &n, DES_DECRYPT); DES_ede3_cfb64_encrypt(&cfb_buf1[17], &cfb_buf2[17], sizeof(plain) - 17, &ks, &ks, &ks, &cfb_tmp, &n, DES_DECRYPT); diff --git a/test/dhkem_test.inc b/test/dhkem_test.inc index 58bcaa55d7..db8016f7e1 100644 --- a/test/dhkem_test.inc +++ b/test/dhkem_test.inc @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -572,7 +572,7 @@ static EVP_PKEY *new_raw_private_key(const char *curvename, if (ecx) { if (!OSSL_PARAM_BLD_push_octet_string(bld, OSSL_PKEY_PARAM_PRIV_KEY, - priv, privlen)) + (char *)priv, privlen)) goto err; } else { privbn = BN_bin2bn(priv, (int)privlen, NULL); @@ -587,7 +587,7 @@ static EVP_PKEY *new_raw_private_key(const char *curvename, if (pub != NULL) { if (!OSSL_PARAM_BLD_push_octet_string(bld, OSSL_PKEY_PARAM_PUB_KEY, - pub, publen)) + (char *)pub, publen)) goto err; } params = OSSL_PARAM_BLD_to_param(bld); diff --git a/test/drbgtest.c b/test/drbgtest.c index 0828ebf7b5..91060cf60a 100644 --- a/test/drbgtest.c +++ b/test/drbgtest.c @@ -182,7 +182,7 @@ static int test_drbg_reseed(int expect_success, time_t reseed_when) { time_t before_reseed, after_reseed; - int expected_state = (expect_success ? EVP_RAND_STATE_READY : EVP_RAND_STATE_ERROR); + int expected_state = (expect_success ? DRBG_READY : DRBG_ERROR); unsigned int primary_reseed, public_reseed, private_reseed; unsigned char dummy[RANDOM_SIZE]; diff --git a/test/dsa_no_digest_size_test.c b/test/dsa_no_digest_size_test.c index a93387c9ae..2b3af3b182 100644 --- a/test/dsa_no_digest_size_test.c +++ b/test/dsa_no_digest_size_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2018-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -24,10 +24,94 @@ #ifndef OPENSSL_NO_DSA #include -#include "helpers/predefined_dsaparams.h" static DSA *dsakey; +/* + * These parameters are from test/recipes/04-test_pem_data/dsaparam.pem, + * converted using dsaparam -C + */ +static DSA *load_dsa_params(void) +{ + static unsigned char dsap_2048[] = { + 0xAE, 0x35, 0x7D, 0x4E, 0x1D, 0x96, 0xE2, 0x9F, 0x00, 0x96, + 0x60, 0x5A, 0x6E, 0x4D, 0x07, 0x8D, 0xA5, 0x7C, 0xBC, 0xF9, + 0xAD, 0xD7, 0x9F, 0xD5, 0xE9, 0xEE, 0xA6, 0x33, 0x51, 0xDE, + 0x7B, 0x72, 0xD2, 0x75, 0xAA, 0x71, 0x77, 0xF1, 0x63, 0xFB, + 0xB6, 0xEC, 0x5A, 0xBA, 0x0D, 0x72, 0xA2, 0x1A, 0x1C, 0x64, + 0xB8, 0xE5, 0x89, 0x09, 0x6D, 0xC9, 0x6F, 0x0B, 0x7F, 0xD2, + 0xCE, 0x9F, 0xEF, 0x87, 0x5A, 0xB6, 0x67, 0x2F, 0xEF, 0xEE, + 0xEB, 0x59, 0xF5, 0x5E, 0xFF, 0xA8, 0x28, 0x84, 0x9E, 0x5B, + 0x37, 0x09, 0x11, 0x80, 0x7C, 0x08, 0x5C, 0xD5, 0xE1, 0x48, + 0x4B, 0xD2, 0x68, 0xFB, 0x3F, 0x9F, 0x2B, 0x6B, 0x6C, 0x0D, + 0x48, 0x1B, 0x1A, 0x80, 0xC2, 0xEB, 0x11, 0x1B, 0x37, 0x79, + 0xD6, 0x8C, 0x8B, 0x72, 0x3E, 0x67, 0xA5, 0x05, 0x0E, 0x41, + 0x8A, 0x9E, 0x35, 0x50, 0xB4, 0xD2, 0x40, 0x27, 0x6B, 0xFD, + 0xE0, 0x64, 0x6B, 0x5B, 0x38, 0x42, 0x94, 0xB5, 0x49, 0xDA, + 0xEF, 0x6E, 0x78, 0x37, 0xCD, 0x30, 0x89, 0xC3, 0x45, 0x50, + 0x7B, 0x9C, 0x8C, 0xE7, 0x1C, 0x98, 0x70, 0x71, 0x5D, 0x79, + 0x5F, 0xEF, 0xE8, 0x94, 0x85, 0x53, 0x3E, 0xEF, 0xA3, 0x2C, + 0xCE, 0x1A, 0xAB, 0x7D, 0xD6, 0x5E, 0x14, 0xCD, 0x51, 0x54, + 0x89, 0x9D, 0x77, 0xE4, 0xF8, 0x22, 0xF0, 0x35, 0x10, 0x75, + 0x05, 0x71, 0x51, 0x4F, 0x8C, 0x4C, 0x5C, 0x0D, 0x2C, 0x2C, + 0xBE, 0x6C, 0x34, 0xEE, 0x12, 0x82, 0x87, 0x03, 0x19, 0x06, + 0x12, 0xA8, 0xAA, 0xF4, 0x0D, 0x3C, 0x49, 0xCC, 0x70, 0x5A, + 0xD8, 0x32, 0xEE, 0x32, 0x50, 0x85, 0x70, 0xE8, 0x18, 0xFD, + 0x74, 0x80, 0x53, 0x32, 0x57, 0xEE, 0x50, 0xC9, 0xAE, 0xEB, + 0xAE, 0xB6, 0x22, 0x32, 0x16, 0x6B, 0x8C, 0x59, 0xDA, 0xEE, + 0x1D, 0x33, 0xDF, 0x4C, 0xA2, 0x3D + }; + static unsigned char dsaq_2048[] = { + 0xAD, 0x2D, 0x6E, 0x17, 0xB0, 0xF3, 0xEB, 0xC7, 0xB8, 0xEE, + 0x95, 0x78, 0xF2, 0x17, 0xF5, 0x33, 0x01, 0x67, 0xBC, 0xDE, + 0x93, 0xFF, 0xEE, 0x40, 0xE8, 0x7F, 0xF1, 0x93, 0x6D, 0x4B, + 0x87, 0x13 + }; + static unsigned char dsag_2048[] = { + 0x66, 0x6F, 0xDA, 0x63, 0xA5, 0x8E, 0xD2, 0x4C, 0xD5, 0x45, + 0x2D, 0x76, 0x5D, 0x5F, 0xCD, 0x4A, 0xB4, 0x1A, 0x42, 0x35, + 0x86, 0x3A, 0x6F, 0xA9, 0xFA, 0x27, 0xAB, 0xDE, 0x03, 0x21, + 0x36, 0x0A, 0x07, 0x29, 0xC9, 0x2F, 0x6D, 0x49, 0xA8, 0xF7, + 0xC6, 0xF4, 0x92, 0xD7, 0x73, 0xC1, 0xD8, 0x76, 0x0E, 0x61, + 0xA7, 0x0B, 0x6E, 0x96, 0xB8, 0xC8, 0xCB, 0x38, 0x35, 0x12, + 0x20, 0x79, 0xA5, 0x08, 0x28, 0x35, 0x5C, 0xBC, 0x52, 0x16, + 0xAF, 0x52, 0xBA, 0x0F, 0xC3, 0xB1, 0x63, 0x12, 0x27, 0x0B, + 0x74, 0xA4, 0x47, 0x43, 0xD6, 0x30, 0xB8, 0x9C, 0x2E, 0x40, + 0x14, 0xCD, 0x99, 0x7F, 0xE8, 0x8E, 0x37, 0xB0, 0xA9, 0x3F, + 0x54, 0xE9, 0x66, 0x22, 0x61, 0x4C, 0xF8, 0x49, 0x03, 0x57, + 0x14, 0x32, 0x1D, 0x37, 0x3D, 0xE2, 0x92, 0xF8, 0x8E, 0xA0, + 0x6A, 0x66, 0x63, 0xF0, 0xB0, 0x6E, 0x07, 0x2B, 0x3D, 0xBF, + 0xD0, 0x84, 0x6A, 0xAA, 0x1F, 0x30, 0x77, 0x65, 0xE5, 0xFC, + 0xF5, 0xEC, 0x55, 0xCE, 0x73, 0xDB, 0xBE, 0xA7, 0x8D, 0x3A, + 0x9F, 0x7A, 0xED, 0x4F, 0xAF, 0xA2, 0x80, 0x4C, 0x30, 0x9E, + 0x28, 0x49, 0x65, 0x40, 0xF0, 0x03, 0x45, 0x56, 0x99, 0xA2, + 0x93, 0x1B, 0x9C, 0x46, 0xDE, 0xBD, 0xA8, 0xAB, 0x5F, 0x90, + 0x3F, 0xB7, 0x3F, 0xD4, 0x6F, 0x8D, 0x5A, 0x30, 0xE1, 0xD4, + 0x63, 0x3A, 0x6A, 0x7C, 0x8F, 0x24, 0xFC, 0xD9, 0x14, 0x28, + 0x09, 0xE4, 0x84, 0x4E, 0x17, 0x43, 0x56, 0xB8, 0xD4, 0x4B, + 0xA2, 0x29, 0x45, 0xD3, 0x13, 0xF0, 0xC2, 0x76, 0x9B, 0x01, + 0xA0, 0x80, 0x6E, 0x93, 0x63, 0x5E, 0x87, 0x24, 0x20, 0x2A, + 0xFF, 0xBB, 0x9F, 0xA8, 0x99, 0x6C, 0xA7, 0x9A, 0x00, 0xB9, + 0x7D, 0xDA, 0x66, 0xC9, 0xC0, 0x72, 0x72, 0x22, 0x0F, 0x1A, + 0xCC, 0x23, 0xD9, 0xB7, 0x5F, 0x1B + }; + DSA *dsa = DSA_new(); + BIGNUM *p, *q, *g; + + if (dsa == NULL) + return NULL; + if (!DSA_set0_pqg(dsa, p = BN_bin2bn(dsap_2048, sizeof(dsap_2048), NULL), + q = BN_bin2bn(dsaq_2048, sizeof(dsaq_2048), NULL), + g = BN_bin2bn(dsag_2048, sizeof(dsag_2048), NULL))) { + DSA_free(dsa); + BN_free(p); + BN_free(q); + BN_free(g); + return NULL; + } + return dsa; +} + static int genkeys(void) { if (!TEST_ptr(dsakey = load_dsa_params())) diff --git a/test/dsatest.c b/test/dsatest.c index 2c739854f3..c4742bc3a4 100644 --- a/test/dsatest.c +++ b/test/dsatest.c @@ -33,26 +33,158 @@ static int dsa_cb(int p, int n, BN_GENCB *arg); static unsigned char out_p[] = { - 0x8d, 0xf2, 0xa4, 0x94, 0x49, 0x22, 0x76, 0xaa, 0x3d, 0x25, - 0x75, 0x9b, 0xb0, 0x68, 0x69, 0xcb, 0xea, 0xc0, 0xd8, 0x3a, - 0xfb, 0x8d, 0x0c, 0xf7, 0xcb, 0xb8, 0x32, 0x4f, 0x0d, 0x78, - 0x82, 0xe5, 0xd0, 0x76, 0x2f, 0xc5, 0xb7, 0x21, 0x0e, 0xaf, - 0xc2, 0xe9, 0xad, 0xac, 0x32, 0xab, 0x7a, 0xac, 0x49, 0x69, - 0x3d, 0xfb, 0xf8, 0x37, 0x24, 0xc2, 0xec, 0x07, 0x36, 0xee, - 0x31, 0xc8, 0x02, 0x91 + 0x8d, + 0xf2, + 0xa4, + 0x94, + 0x49, + 0x22, + 0x76, + 0xaa, + 0x3d, + 0x25, + 0x75, + 0x9b, + 0xb0, + 0x68, + 0x69, + 0xcb, + 0xea, + 0xc0, + 0xd8, + 0x3a, + 0xfb, + 0x8d, + 0x0c, + 0xf7, + 0xcb, + 0xb8, + 0x32, + 0x4f, + 0x0d, + 0x78, + 0x82, + 0xe5, + 0xd0, + 0x76, + 0x2f, + 0xc5, + 0xb7, + 0x21, + 0x0e, + 0xaf, + 0xc2, + 0xe9, + 0xad, + 0xac, + 0x32, + 0xab, + 0x7a, + 0xac, + 0x49, + 0x69, + 0x3d, + 0xfb, + 0xf8, + 0x37, + 0x24, + 0xc2, + 0xec, + 0x07, + 0x36, + 0xee, + 0x31, + 0xc8, + 0x02, + 0x91, }; static unsigned char out_q[] = { - 0xc7, 0x73, 0x21, 0x8c, 0x73, 0x7e, 0xc8, 0xee, 0x99, 0x3b, - 0x4f, 0x2d, 0xed, 0x30, 0xf4, 0x8e, 0xda, 0xce, 0x91, 0x5f + 0xc7, + 0x73, + 0x21, + 0x8c, + 0x73, + 0x7e, + 0xc8, + 0xee, + 0x99, + 0x3b, + 0x4f, + 0x2d, + 0xed, + 0x30, + 0xf4, + 0x8e, + 0xda, + 0xce, + 0x91, + 0x5f, }; static unsigned char out_g[] = { - 0x62, 0x6d, 0x02, 0x78, 0x39, 0xea, 0x0a, 0x13, 0x41, 0x31, - 0x63, 0xa5, 0x5b, 0x4c, 0xb5, 0x00, 0x29, 0x9d, 0x55, 0x22, - 0x95, 0x6c, 0xef, 0xcb, 0x3b, 0xff, 0x10, 0xf3, 0x99, 0xce, - 0x2c, 0x2e, 0x71, 0xcb, 0x9d, 0xe5, 0xfa, 0x24, 0xba, 0xbf, - 0x58, 0xe5, 0xb7, 0x95, 0x21, 0x92, 0x5c, 0x9c, 0xc4, 0x2e, - 0x9f, 0x6f, 0x46, 0x4b, 0x08, 0x8c, 0xc5, 0x72, 0xaf, 0x53, - 0xe6, 0xd7, 0x88, 0x02 + 0x62, + 0x6d, + 0x02, + 0x78, + 0x39, + 0xea, + 0x0a, + 0x13, + 0x41, + 0x31, + 0x63, + 0xa5, + 0x5b, + 0x4c, + 0xb5, + 0x00, + 0x29, + 0x9d, + 0x55, + 0x22, + 0x95, + 0x6c, + 0xef, + 0xcb, + 0x3b, + 0xff, + 0x10, + 0xf3, + 0x99, + 0xce, + 0x2c, + 0x2e, + 0x71, + 0xcb, + 0x9d, + 0xe5, + 0xfa, + 0x24, + 0xba, + 0xbf, + 0x58, + 0xe5, + 0xb7, + 0x95, + 0x21, + 0x92, + 0x5c, + 0x9c, + 0xc4, + 0x2e, + 0x9f, + 0x6f, + 0x46, + 0x4b, + 0x08, + 0x8c, + 0xc5, + 0x72, + 0xaf, + 0x53, + 0xe6, + 0xd7, + 0x88, + 0x02, }; static int dsa_test(void) @@ -70,8 +202,26 @@ static int dsa_test(void) * PUB 186 and also appear in Appendix 5 to FIPS PIB 186-1 */ static unsigned char seed[20] = { - 0xd5, 0x01, 0x4e, 0x4b, 0x60, 0xef, 0x2b, 0xa8, 0xb6, 0x21, - 0x1b, 0x40, 0x62, 0xba, 0x32, 0x24, 0xe0, 0x42, 0x7d, 0xd3 + 0xd5, + 0x01, + 0x4e, + 0x4b, + 0x60, + 0xef, + 0x2b, + 0xa8, + 0xb6, + 0x21, + 0x1b, + 0x40, + 0x62, + 0xba, + 0x32, + 0x24, + 0xe0, + 0x42, + 0x7d, + 0xd3, }; static const unsigned char str1[] = "12345678901234567890"; diff --git a/test/dtls12psk.c b/test/dtls12psk.c deleted file mode 100644 index e784f0660c..0000000000 --- a/test/dtls12psk.c +++ /dev/null @@ -1,309 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include -#include -#include - -#include "helpers/ssltestlib.h" -#include "testutil.h" - -static const char psk_secret[] = "shared-secret"; -static const char psk_identity[] = "identity"; - -static const unsigned char sid_req[] = { - 0xde, 0xad, 0xbe, 0xef, 0x01, 0x02, 0x03, 0x04, - 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c -}; - -static const struct ciphersuites { - char *name; -} css[] = { - { "PSK-AES128-CBC-SHA256" }, - { "PSK-AES256-CBC-SHA384" }, - { "PSK-AES128-GCM-SHA256" }, - { "PSK-AES256-GCM-SHA384" } -}; - -#define HELLO_RANDOM_OFF 6 -#define HELLO_RANDOM_LEN 32 -#define HELLO_SID_LEN_OFF (HELLO_RANDOM_OFF + HELLO_RANDOM_LEN) -#define HELLO_SID_OFF (HELLO_SID_LEN_OFF + 1) -#define HELLO_MIN_LEN (HELLO_SID_LEN_OFF + 1) - -static void hello_session_id(const unsigned char *p, size_t len) -{ - char *str; - size_t sid_len; - - if (len < HELLO_MIN_LEN) - return; - - sid_len = p[HELLO_SID_LEN_OFF]; - if (sid_len == 0 || len < HELLO_SID_OFF + sid_len) - return; - - str = OPENSSL_buf2hexstr(p + HELLO_SID_OFF, (long)sid_len); - TEST_info("session_id(%u): <%s>", (unsigned int)sid_len, str); - OPENSSL_free(str); -} - -static void msg_cb(int write_p, int version, int content_type, - const void *buf, size_t len, SSL *ssl, void *arg) -{ - const unsigned char *p = buf; - - if (content_type != SSL3_RT_HANDSHAKE || len < 1) - return; - - switch (p[0]) { - case SSL3_MT_CLIENT_HELLO: - TEST_info("%p client_hello", (void *)ssl); - hello_session_id(p, len); - break; - - case SSL3_MT_SERVER_HELLO: - TEST_info("%p server_hello", (void *)ssl); - hello_session_id(p, len); - break; - } -} - -static void handshake_finished(const SSL *ssl) -{ - const char *endpoint = SSL_is_server(ssl) ? "server" : "client"; - unsigned int has_ticket = SSL_SESSION_has_ticket(SSL_get_session(ssl)); - - if (SSL_session_reused(ssl)) - TEST_info("%s: Abbreviated handshake finished", endpoint); - else - TEST_info("%s: Full handshake finished", endpoint); - - TEST_info("%s: has_ticket: %u", endpoint, has_ticket); -} - -static void info_cb(const SSL *ssl, int type, int val) -{ - const char *endpoint = SSL_is_server(ssl) ? "server" : "client"; - - if (type & SSL_CB_ALERT) { - const char *dir = (type & SSL_CB_READ) ? "read" : "write"; - - TEST_info("%s: alert %s: %s : %s", endpoint, dir, - SSL_alert_type_string_long(val), - SSL_alert_desc_string_long(val)); - } - if (type & SSL_CB_HANDSHAKE_DONE) - handshake_finished(ssl); -} - -static unsigned int server_psk_cb(SSL *ssl, const char *identity, - unsigned char *psk, unsigned int max) -{ - if (max < (sizeof(psk_secret) - 1)) - return 0; - memcpy(psk, psk_secret, (sizeof(psk_secret) - 1)); - return (unsigned int)(sizeof(psk_secret) - 1); -} - -static unsigned int client_psk_cb(SSL *ssl, const char *hint, - char *identity, unsigned int max_id, - unsigned char *psk, unsigned int max) -{ - if (max < (sizeof(psk_secret) - 1) || max_id < sizeof(psk_identity)) - return 0; - strncpy(identity, psk_identity, max_id); - memcpy(psk, psk_secret, (sizeof(psk_secret) - 1)); - return (unsigned int)(sizeof(psk_secret) - 1); -} - -static SSL_SESSION *sess_cache; -static SSL_SESSION *get_sess_cb(SSL *ssl, const unsigned char *id, int len, int *copy) -{ - *copy = 1; - - if (sess_cache != NULL) { - char *str; - const unsigned char *sid; - unsigned int sid_len; - - sid = SSL_SESSION_get_id(sess_cache, &sid_len); - str = OPENSSL_buf2hexstr(sid, sid_len); - TEST_info("(cached) session_id: <%s>", str); - OPENSSL_free(str); - } - return sess_cache; -} - -static int ctx_set_cache(SSL_CTX *s_ctx, SSL_CTX *c_ctx) -{ - SSL_CTX_set_psk_server_callback(s_ctx, server_psk_cb); - SSL_CTX_set_psk_client_callback(c_ctx, client_psk_cb); - SSL_CTX_set_session_cache_mode(s_ctx, SSL_SESS_CACHE_SERVER); - SSL_CTX_set_session_cache_mode(c_ctx, SSL_SESS_CACHE_CLIENT); - SSL_CTX_set_options(s_ctx, SSL_OP_NO_TICKET); - SSL_CTX_set_verify(c_ctx, SSL_VERIFY_NONE, NULL); - return 1; -} - -static int ctx_set_ticket(SSL_CTX *s_ctx, SSL_CTX *c_ctx) -{ - SSL_CTX_set_psk_server_callback(s_ctx, server_psk_cb); - SSL_CTX_set_psk_client_callback(c_ctx, client_psk_cb); - SSL_CTX_set_session_cache_mode(s_ctx, SSL_SESS_CACHE_SERVER); - SSL_CTX_set_session_cache_mode(c_ctx, SSL_SESS_CACHE_CLIENT); - SSL_CTX_set_verify(c_ctx, SSL_VERIFY_NONE, NULL); - return 1; -} - -static int set_shutdown(SSL *c, SSL *s) -{ - SSL_set_shutdown(c, SSL_SENT_SHUTDOWN | SSL_RECEIVED_SHUTDOWN); - SSL_set_shutdown(s, SSL_SENT_SHUTDOWN | SSL_RECEIVED_SHUTDOWN); - return 1; -} - -static int set_server_cache(SSL_CTX *s_ctx) -{ - unsigned int v = SSL_SESS_CACHE_SERVER | SSL_SESS_CACHE_NO_INTERNAL_STORE; - SSL_CTX_sess_set_get_cb(s_ctx, get_sess_cb); - SSL_CTX_set_session_cache_mode(s_ctx, v); - return 1; -} - -static int set_callbacks(SSL *c, SSL *s) -{ - SSL_set_msg_callback(c, msg_cb); - SSL_set_info_callback(c, info_cb); - SSL_set_msg_callback(s, msg_cb); - SSL_set_info_callback(s, info_cb); - return 1; -} - -static int sessid_matches(SSL *c, SSL *s) -{ - const unsigned char *c_sid, *s_sid; - unsigned int c_len, s_len; - int test; - - test = TEST_ptr(c_sid = SSL_SESSION_get_id(SSL_get0_session(c), &c_len)) - && TEST_ptr(s_sid = SSL_SESSION_get_id(SSL_get0_session(s), &s_len)) - && TEST_uint_eq(c_len, s_len) && TEST_mem_eq(c_sid, c_len, s_sid, s_len); - - return test; -} - -static int test_dtls12_psk_resume_sessid_mismatch(int idx) -{ - const struct ciphersuites *cs = &css[idx]; - SSL_CTX *s_ctx = NULL, *c_ctx = NULL; - SSL *s_ssl = NULL, *c_ssl = NULL, *s = NULL, *c = NULL; - SSL_SESSION *sess = NULL, *r_sess = NULL; - const unsigned char *sid; - unsigned int sid_len; - int test; - - sess_cache = NULL; - - test = TEST_true(create_ssl_ctx_pair(NULL, DTLS_server_method(), DTLS_client_method(), - DTLS1_2_VERSION, DTLS1_2_VERSION, &s_ctx, &c_ctx, NULL, NULL)) - && TEST_true(SSL_CTX_set_cipher_list(s_ctx, cs->name)) - && TEST_true(SSL_CTX_set_cipher_list(c_ctx, cs->name)) - && TEST_true(ctx_set_cache(s_ctx, c_ctx)) - && TEST_true(create_ssl_objects(s_ctx, c_ctx, &s, &c, NULL, NULL)) - && TEST_true(set_callbacks(c, s)) - && TEST_true(create_ssl_connection(s, c, SSL_ERROR_NONE)) - && TEST_ptr(sess = SSL_get1_session(c)) - && TEST_true(set_shutdown(c, s)) - && TEST_ptr(sid = SSL_SESSION_get_id(sess, &sid_len)) - && TEST_uint_eq(sid_len, 32) - && TEST_ptr(r_sess = SSL_SESSION_dup(sess)) - && TEST_true(SSL_SESSION_set1_id(r_sess, sid_req, sizeof(sid_req))) - && TEST_ptr(sess_cache = sess) - && TEST_true(set_server_cache(s_ctx)) - && TEST_true(create_ssl_objects(s_ctx, c_ctx, &s_ssl, &c_ssl, NULL, NULL)) - && TEST_true(set_callbacks(c_ssl, s_ssl)) - && TEST_true(SSL_set_session(c_ssl, r_sess)) - && TEST_true(create_ssl_connection(s_ssl, c_ssl, SSL_ERROR_NONE)) - && TEST_false(SSL_session_reused(s_ssl)); - - sess_cache = NULL; - SSL_free(s_ssl); - SSL_free(c_ssl); - SSL_SESSION_free(r_sess); - SSL_SESSION_free(sess); - SSL_CTX_free(s_ctx); - SSL_CTX_free(c_ctx); - SSL_free(s); - SSL_free(c); - return test; -} - -/* - * RFC 5077 3.4 requires the server to echo the session ID from ClientHello - * in the ServerHello when accepting a session ticket. Some clients rely on - * this echo to confirm that resumption succeeded. The ticket decryption path - * in tls_decrypt_ticket() guarantees the restored SSL_SESSION carries the - * correct session ID, so tls_construct_server_hello() will echo it correctly. - * If the session ID is empty, its length is set to zero as required by the - * RFC. - */ -static int test_dtls12_psk_resume_ticket_mismatch(int idx) -{ - const struct ciphersuites *cs = &css[idx]; - SSL_CTX *s_ctx = NULL, *c_ctx = NULL; - SSL *s_ssl = NULL, *c_ssl = NULL, *s = NULL, *c = NULL; - SSL_SESSION *c_sess = NULL, *r_sess = NULL; - int test; - - test = TEST_true(create_ssl_ctx_pair(NULL, DTLS_server_method(), DTLS_client_method(), - DTLS1_2_VERSION, DTLS1_2_VERSION, &s_ctx, &c_ctx, NULL, NULL)) - && TEST_true(SSL_CTX_set_cipher_list(s_ctx, cs->name)) - && TEST_true(SSL_CTX_set_cipher_list(c_ctx, cs->name)) - && TEST_true(ctx_set_ticket(s_ctx, c_ctx)) - && TEST_true(create_ssl_objects(s_ctx, c_ctx, &s, &c, NULL, NULL)) - && TEST_true(set_callbacks(c, s)) - && TEST_true(create_ssl_connection(s, c, SSL_ERROR_NONE)) - && TEST_ptr(c_sess = SSL_get1_session(c)) - && TEST_true(SSL_SESSION_has_ticket(c_sess)) - && TEST_int_eq(set_shutdown(c, s), 1) - && TEST_ptr(r_sess = SSL_SESSION_dup(c_sess)) - && TEST_true(SSL_SESSION_set1_id(r_sess, sid_req, sizeof(sid_req))) - && TEST_true(create_ssl_objects(s_ctx, c_ctx, &s_ssl, &c_ssl, NULL, NULL)) - && TEST_true(set_callbacks(c_ssl, s_ssl)) - && TEST_true(SSL_set_session(c_ssl, r_sess)) - && TEST_true(create_ssl_connection(s_ssl, c_ssl, SSL_ERROR_NONE)) - && TEST_true(SSL_session_reused(s_ssl)) - && TEST_true(sessid_matches(c_ssl, s_ssl)); - - SSL_free(s_ssl); - SSL_free(c_ssl); - SSL_SESSION_free(r_sess); - SSL_SESSION_free(c_sess); - SSL_CTX_free(s_ctx); - SSL_CTX_free(c_ctx); - SSL_free(s); - SSL_free(c); - return test; -} - -OPT_TEST_DECLARE_USAGE("\n") - -int setup_tests(void) -{ - if (!test_skip_common_options()) { - TEST_error("Error parsing test options\n"); - return 0; - } - - ADD_ALL_TESTS(test_dtls12_psk_resume_sessid_mismatch, OSSL_NELEM(css)); - ADD_ALL_TESTS(test_dtls12_psk_resume_ticket_mismatch, OSSL_NELEM(css)); - return 1; -} diff --git a/test/dtls_ccs_reorder_test.c b/test/dtls_ccs_reorder_test.c deleted file mode 100644 index 45c4a4180b..0000000000 --- a/test/dtls_ccs_reorder_test.c +++ /dev/null @@ -1,548 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* DTLS CCS early-arrival tests */ - -#include -#include -#include -#include -#include -#include - -#include "helpers/ssltestlib.h" -#include "testutil.h" - -static char *cert = NULL; -static char *privkey = NULL; - -static unsigned int infinite_timer_cb(SSL *s, unsigned int timer_us) -{ - (void)s; - - if (timer_us == 0) - return 999999999; - return timer_us; -} - -static int verify_accept_cb(int ok, X509_STORE_CTX *ctx) -{ - (void)ok; - (void)ctx; - - return 1; -} - -static int tick_key_renew_cb(SSL *s, unsigned char key_name[16], - unsigned char iv[EVP_MAX_IV_LENGTH], - EVP_CIPHER_CTX *ctx, EVP_MAC_CTX *hctx, - int enc) -{ - const unsigned char tick_aes_key[16] = { - '0', '1', '2', '3', '4', '5', '6', '7', - '8', '9', 'a', 'b', 'c', 'd', 'e', 'f' - }; - - unsigned char tick_hmac_key[16] = { - '0', '1', '2', '3', '4', '5', '6', '7', - '8', '9', 'a', 'b', 'c', 'd', 'e', 'f' - }; - OSSL_PARAM params[2]; - EVP_CIPHER *aes128cbc = EVP_CIPHER_fetch(NULL, "AES-128-CBC", NULL); - int ret; - - (void)s; - - if (aes128cbc == NULL) - return -1; - - memset(key_name, 0, 16); - memset(iv, 0, AES_BLOCK_SIZE); - params[0] = OSSL_PARAM_construct_utf8_string(OSSL_MAC_PARAM_DIGEST, - "SHA256", 0); - params[1] = OSSL_PARAM_construct_end(); - - if (!EVP_CipherInit_ex(ctx, aes128cbc, NULL, tick_aes_key, iv, enc) - || !EVP_MAC_init(hctx, tick_hmac_key, sizeof(tick_hmac_key), params)) - ret = -1; - else - ret = enc ? 1 : 2; - - EVP_CIPHER_free(aes128cbc); - return ret; -} - -static int verify_data_transfer(SSL *writer, SSL *reader) -{ - const char msg[] = "CCS reorder test"; - char buf[sizeof(msg)]; - - if (!TEST_int_eq(SSL_write(writer, msg, sizeof(msg)), (int)sizeof(msg)) - || !TEST_int_eq(SSL_read(reader, buf, sizeof(buf)), (int)sizeof(msg)) - || !TEST_mem_eq(buf, sizeof(msg), msg, sizeof(msg))) - return 0; - return 1; -} - -/* Move CCS just before the handshake message given by before_hs_msg. */ -static int reorder_ccs(BIO *bio, int before_hs_msg) -{ - int target_pkt = -1, target_rec = -1; - int ccs_pkt = -1, ccs_rec = -1; - int p; - - if (!TEST_true(mempacket_find_record(bio, SSL3_RT_HANDSHAKE, - before_hs_msg, - &target_pkt, &target_rec))) - return 0; - - if (target_rec > 0 - && !TEST_true(mempacket_split_packet_at(bio, target_pkt, target_rec))) - return 0; - - if (!TEST_true(mempacket_find_record(bio, SSL3_RT_CHANGE_CIPHER_SPEC, -1, - &ccs_pkt, &ccs_rec))) - return 0; - - if (ccs_rec > 0 - && !TEST_true(mempacket_split_packet_at(bio, ccs_pkt, ccs_rec))) - return 0; - - if (!TEST_true(mempacket_find_record(bio, SSL3_RT_CHANGE_CIPHER_SPEC, -1, - &ccs_pkt, &ccs_rec)) - || !TEST_int_eq(ccs_rec, 0)) - return 0; - - if (!TEST_true(mempacket_split_packet_at(bio, ccs_pkt, 1))) - return 0; - - if (!TEST_true(mempacket_find_record(bio, SSL3_RT_HANDSHAKE, - before_hs_msg, - &target_pkt, &target_rec)) - || !TEST_int_eq(target_rec, 0)) - return 0; - - if (ccs_pkt == target_pkt) - return 0; - - if (ccs_pkt > target_pkt) { - if (!TEST_true(mempacket_move_packet(bio, target_pkt, ccs_pkt))) - return 0; - } else { - for (p = ccs_pkt; p + 1 < target_pkt; p++) { - if (!TEST_true(mempacket_move_packet(bio, p, p + 1))) - return 0; - } - } - - /* CCS packet should be at position target_pkt - 1 */ - if (!TEST_true(mempacket_find_record(bio, SSL3_RT_CHANGE_CIPHER_SPEC, - -1, &ccs_pkt, &ccs_rec)) - || !TEST_true(mempacket_find_record(bio, SSL3_RT_HANDSHAKE, - before_hs_msg, - &target_pkt, &target_rec)) - || !TEST_int_eq(ccs_pkt + 1, target_pkt) - || !TEST_int_eq(ccs_rec, 0) - || !TEST_int_eq(target_rec, 0)) - return 0; - - return 1; -} - -static const struct { - int mtls; - int reorder_before; - int max_version; -} full_hs_tests[] = { -#ifndef OPENSSL_NO_DTLS1_2 - /* DTLS 1.2: [CKE][CCS][Fin] -> [CCS][CKE][Fin] */ - { 0, SSL3_MT_CLIENT_KEY_EXCHANGE, DTLS1_2_VERSION }, - /* DTLS 1.2 mTLS: [Cert][CKE][CV][CCS][Fin] -> [CCS][Cert]... */ - { 1, SSL3_MT_CERTIFICATE, DTLS1_2_VERSION }, - /* DTLS 1.2 mTLS: [Cert][CKE][CV][CCS][Fin] -> [Cert][CKE][CCS][CV]... */ - { 1, SSL3_MT_CERTIFICATE_VERIFY, DTLS1_2_VERSION }, -#endif -#ifndef OPENSSL_NO_DTLS1 - /* DTLS 1.0: [CKE][CCS][Fin] -> [CCS][CKE][Fin] */ - { 0, SSL3_MT_CLIENT_KEY_EXCHANGE, DTLS1_VERSION }, - /* DTLS 1.0 mTLS: [Cert][CKE][CV][CCS][Fin] -> [CCS][Cert]... */ - { 1, SSL3_MT_CERTIFICATE, DTLS1_VERSION }, - /* DTLS 1.0 mTLS: [Cert][CKE][CV][CCS][Fin] -> [Cert][CKE][CCS][CV]... */ - { 1, SSL3_MT_CERTIFICATE_VERIFY, DTLS1_VERSION }, -#endif -}; - -/* Full handshake, Flight 3 (C->S): early CCS in the client flight. */ -static int test_dtls_ccs_full_hs(int idx) -{ - SSL_CTX *sctx = NULL, *cctx = NULL; - SSL *sssl = NULL, *cssl = NULL; - BIO *bio; - X509 *peer = NULL; - int testresult = 0, ret; - int mtls = full_hs_tests[idx].mtls; - int reorder_before = full_hs_tests[idx].reorder_before; - int max_ver = full_hs_tests[idx].max_version; - - if (!TEST_true(create_ssl_ctx_pair(NULL, DTLS_server_method(), - DTLS_client_method(), - max_ver, max_ver, - &sctx, &cctx, cert, privkey))) - return 0; - - if (max_ver == DTLS1_VERSION) { - SSL_CTX_set_security_level(sctx, 0); - SSL_CTX_set_security_level(cctx, 0); - } - - if (mtls) { - SSL_CTX_set_verify(sctx, - SSL_VERIFY_PEER | SSL_VERIFY_FAIL_IF_NO_PEER_CERT, - verify_accept_cb); - - if (!TEST_true(SSL_CTX_use_certificate_file(cctx, cert, - SSL_FILETYPE_PEM)) - || !TEST_true(SSL_CTX_use_PrivateKey_file(cctx, privkey, - SSL_FILETYPE_PEM))) - goto end; - } - - if (!TEST_true(create_ssl_objects(sctx, cctx, &sssl, &cssl, NULL, NULL))) - goto end; - - DTLS_set_timer_cb(sssl, infinite_timer_cb); - DTLS_set_timer_cb(cssl, infinite_timer_cb); - - if (!TEST_int_le(SSL_connect(cssl), 0)) - goto end; - - if (!TEST_int_le(SSL_accept(sssl), 0)) - goto end; - - if (!TEST_int_le(SSL_connect(cssl), 0)) - goto end; - - bio = SSL_get_wbio(cssl); - if (!TEST_ptr(bio) - || !TEST_true(reorder_ccs(bio, reorder_before))) - goto end; - - ret = SSL_accept(sssl); - if (!TEST_int_gt(ret, 0)) { - TEST_info("SSL_accept: ret=%d err=%d state=%s", - ret, SSL_get_error(sssl, ret), - SSL_state_string_long(sssl)); - goto end; - } - - ret = SSL_connect(cssl); - if (!TEST_int_gt(ret, 0)) { - TEST_info("SSL_connect: ret=%d err=%d state=%s", - ret, SSL_get_error(cssl, ret), - SSL_state_string_long(cssl)); - goto end; - } - - if (mtls) { - peer = SSL_get1_peer_certificate(sssl); - if (!TEST_ptr(peer)) - goto end; - } - - if (!TEST_true(verify_data_transfer(sssl, cssl))) - goto end; - - testresult = 1; -end: - X509_free(peer); - SSL_free(sssl); - SSL_free(cssl); - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - return testresult; -} - -static const int nst_versions[] = { -#ifndef OPENSSL_NO_DTLS1_2 - DTLS1_2_VERSION, -#endif -#ifndef OPENSSL_NO_DTLS1 - DTLS1_VERSION, -#endif -}; - -/* Flight 4 (S->C): [NST][CCS][Finished] -> [CCS][NST][Finished] */ -static int test_dtls_ccs_before_nst(int idx) -{ - SSL_CTX *sctx = NULL, *cctx = NULL; - SSL *sssl = NULL, *cssl = NULL; - BIO *bio; - int testresult = 0, ret; - int max_ver = nst_versions[idx]; - - if (!TEST_true(create_ssl_ctx_pair(NULL, DTLS_server_method(), - DTLS_client_method(), - max_ver, max_ver, - &sctx, &cctx, cert, privkey))) - return 0; - - if (max_ver == DTLS1_VERSION) { - SSL_CTX_set_security_level(sctx, 0); - SSL_CTX_set_security_level(cctx, 0); - } - - if (!TEST_true(create_ssl_objects(sctx, cctx, &sssl, &cssl, NULL, NULL))) - goto end; - - DTLS_set_timer_cb(sssl, infinite_timer_cb); - DTLS_set_timer_cb(cssl, infinite_timer_cb); - - if (!TEST_int_le(SSL_connect(cssl), 0)) - goto end; - - if (!TEST_int_le(SSL_accept(sssl), 0)) - goto end; - - if (!TEST_int_le(SSL_connect(cssl), 0)) - goto end; - - ret = SSL_accept(sssl); - if (!TEST_int_gt(ret, 0)) { - TEST_info("SSL_accept: ret=%d err=%d state=%s", - ret, SSL_get_error(sssl, ret), - SSL_state_string_long(sssl)); - goto end; - } - - bio = SSL_get_wbio(sssl); - if (!TEST_ptr(bio) - || !TEST_true(reorder_ccs(bio, SSL3_MT_NEWSESSION_TICKET))) - goto end; - - ret = SSL_connect(cssl); - if (!TEST_int_gt(ret, 0)) { - TEST_info("SSL_connect: ret=%d err=%d state=%s", - ret, SSL_get_error(cssl, ret), - SSL_state_string_long(cssl)); - goto end; - } - - if (!TEST_true(verify_data_transfer(cssl, sssl))) - goto end; - - testresult = 1; -end: - SSL_free(sssl); - SSL_free(cssl); - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - return testresult; -} - -static const struct { - int use_ticket; - int reorder_before; - int max_version; -} resume_tests[] = { -#ifndef OPENSSL_NO_DTLS1_2 - /* DTLS 1.2 Session ID: [SH][CCS][Fin] -> [CCS][SH][Fin] */ - { 0, SSL3_MT_SERVER_HELLO, DTLS1_2_VERSION }, - /* DTLS 1.2 Ticket renewal: [NST][CCS][Fin] -> [CCS][NST][Fin] */ - { 1, SSL3_MT_NEWSESSION_TICKET, DTLS1_2_VERSION }, -#endif -#ifndef OPENSSL_NO_DTLS1 - /* DTLS 1.0 Session ID: [SH][CCS][Fin] -> [CCS][SH][Fin] */ - { 0, SSL3_MT_SERVER_HELLO, DTLS1_VERSION }, - /* DTLS 1.0 Ticket renewal: [NST][CCS][Fin] -> [CCS][NST][Fin] */ - { 1, SSL3_MT_NEWSESSION_TICKET, DTLS1_VERSION }, -#endif -}; - -/* Resumption, Flight 2 (S->C): early CCS in the server flight. */ -static int test_dtls_ccs_resume(int idx) -{ - SSL_CTX *sctx = NULL, *cctx = NULL; - SSL *sssl = NULL, *cssl = NULL; - SSL_SESSION *sess = NULL; - BIO *bio; - int testresult = 0, ret; - int use_ticket = resume_tests[idx].use_ticket; - int reorder_before = resume_tests[idx].reorder_before; - int max_ver = resume_tests[idx].max_version; - - if (!TEST_true(create_ssl_ctx_pair(NULL, DTLS_server_method(), - DTLS_client_method(), - max_ver, max_ver, - &sctx, &cctx, cert, privkey))) - return 0; - - if (max_ver == DTLS1_VERSION) { - SSL_CTX_set_security_level(sctx, 0); - SSL_CTX_set_security_level(cctx, 0); - } - - if (use_ticket) { - if (!TEST_true(SSL_CTX_set_tlsext_ticket_key_evp_cb(sctx, - tick_key_renew_cb))) - goto end; - } else { - SSL_CTX_set_options(sctx, SSL_OP_NO_TICKET); - } - - if (!TEST_true(create_ssl_objects(sctx, cctx, &sssl, &cssl, NULL, NULL))) - goto end; - - if (!TEST_true(create_ssl_connection(sssl, cssl, SSL_ERROR_NONE))) - goto end; - - sess = SSL_get1_session(cssl); - if (!TEST_ptr(sess)) - goto end; - - shutdown_ssl_connection(sssl, cssl); - sssl = cssl = NULL; - - if (!TEST_true(create_ssl_objects(sctx, cctx, &sssl, &cssl, NULL, NULL))) - goto end; - - DTLS_set_timer_cb(sssl, infinite_timer_cb); - DTLS_set_timer_cb(cssl, infinite_timer_cb); - - if (!TEST_true(SSL_set_session(cssl, sess))) - goto end; - - if (!TEST_int_le(SSL_connect(cssl), 0)) - goto end; - - if (!TEST_int_le(SSL_accept(sssl), 0)) - goto end; - - bio = SSL_get_wbio(sssl); - if (!TEST_ptr(bio) - || !TEST_true(reorder_ccs(bio, reorder_before))) - goto end; - - ret = SSL_connect(cssl); - if (!TEST_int_gt(ret, 0)) { - TEST_info("SSL_connect: ret=%d err=%d state=%s", - ret, SSL_get_error(cssl, ret), - SSL_state_string_long(cssl)); - goto end; - } - - ret = SSL_accept(sssl); - if (!TEST_int_gt(ret, 0)) { - TEST_info("SSL_accept: ret=%d err=%d state=%s", - ret, SSL_get_error(sssl, ret), - SSL_state_string_long(sssl)); - goto end; - } - - if (!TEST_true(SSL_session_reused(cssl))) - goto end; - - if (!TEST_true(verify_data_transfer(cssl, sssl))) - goto end; - - testresult = 1; -end: - SSL_free(sssl); - SSL_free(cssl); - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - SSL_SESSION_free(sess); - return testresult; -} - -#ifndef OPENSSL_NO_DTLS1_2 -static int test_dtls_data_after_ccs(void) -{ - SSL_CTX *sctx = NULL, *cctx = NULL; - SSL *sssl = NULL, *cssl = NULL; - BIO *bio; - int testresult = 0, ret; - int target_pkt, target_rec; - - if (!TEST_true(create_ssl_ctx_pair(NULL, DTLS_server_method(), - DTLS_client_method(), - DTLS1_2_VERSION, DTLS1_2_VERSION, - &sctx, &cctx, cert, privkey))) - return 0; - - if (!TEST_true(create_ssl_objects(sctx, cctx, &sssl, &cssl, NULL, NULL))) - goto end; - - DTLS_set_timer_cb(sssl, infinite_timer_cb); - DTLS_set_timer_cb(cssl, infinite_timer_cb); - - if (!TEST_int_le(SSL_connect(cssl), 0)) - goto end; - - if (!TEST_int_le(SSL_accept(sssl), 0)) - goto end; - - if (!TEST_int_le(SSL_connect(cssl), 0)) - goto end; - - bio = SSL_get_wbio(cssl); - if (!TEST_ptr(bio) - || !TEST_true(reorder_ccs(bio, SSL3_MT_CLIENT_KEY_EXCHANGE))) - goto end; - - if (!TEST_true(mempacket_find_record(bio, SSL3_RT_HANDSHAKE, - SSL3_MT_CLIENT_KEY_EXCHANGE, - &target_pkt, &target_rec))) - goto end; - if (!TEST_true(mempacket_append_to_record(bio, target_pkt, target_rec, - (unsigned char *)"test data", 9))) - goto end; - - ret = SSL_accept(sssl); - if (!TEST_int_le(ret, 0)) - goto end; - if (!TEST_int_eq(SSL_get_error(sssl, ret), SSL_ERROR_SSL)) - goto end; - if (!TEST_int_eq(ERR_GET_REASON(ERR_get_error()), SSL_R_UNEXPECTED_MESSAGE)) - goto end; - - testresult = 1; -end: - SSL_free(sssl); - SSL_free(cssl); - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - return testresult; -} -#endif - -int setup_tests(void) -{ - if (!test_skip_common_options()) { - TEST_error("Error parsing test options\n"); - return 0; - } - - if (!TEST_ptr(cert = test_get_argument(0)) - || !TEST_ptr(privkey = test_get_argument(1))) - return 0; - - ADD_ALL_TESTS(test_dtls_ccs_full_hs, OSSL_NELEM(full_hs_tests)); - ADD_ALL_TESTS(test_dtls_ccs_before_nst, OSSL_NELEM(nst_versions)); - ADD_ALL_TESTS(test_dtls_ccs_resume, OSSL_NELEM(resume_tests)); -#ifndef OPENSSL_NO_DTLS1_2 - ADD_TEST(test_dtls_data_after_ccs); -#endif - - return 1; -} - -void cleanup_tests(void) -{ - bio_s_mempacket_test_free(); -} diff --git a/test/dtls_mtu_test.c b/test/dtls_mtu_test.c index 9a2d8caab0..1e2b988f04 100644 --- a/test/dtls_mtu_test.c +++ b/test/dtls_mtu_test.c @@ -83,9 +83,9 @@ static int mtu_test(SSL_CTX *ctx, const char *cs, int no_etm) SSL_set_mtu(clnt_ssl, 500 + i); mtus[i] = DTLS_get_data_mtu(clnt_ssl); if (debug) - TEST_info("%s%s MTU for record mtu %d = %zu", + TEST_info("%s%s MTU for record mtu %d = %lu", cs, no_etm ? "-noEtM" : "", - 500 + i, mtus[i]); + 500 + i, (unsigned long)mtus[i]); if (!TEST_size_t_ne(mtus[i], 0)) { TEST_info("Cipher %s MTU %d", cs, 500 + i); goto end; @@ -116,8 +116,9 @@ static int mtu_test(SSL_CTX *ctx, const char *cs, int no_etm) * We sent a packet smaller than or equal to mtus[j] and * that made a record *larger* than the record MTU 500+j! */ - TEST_error("%s: s=%zu, mtus[i]=%zu, reclen=%zu, i=%d", - cs, s, mtus[i], reclen, 500 + i); + TEST_error("%s: s=%lu, mtus[i]=%lu, reclen=%lu, i=%d", + cs, (unsigned long)s, (unsigned long)mtus[i], + (unsigned long)reclen, 500 + i); goto end; } if (!TEST_false(s > mtus[i] && reclen <= (size_t)(500 + i))) { @@ -126,8 +127,9 @@ static int mtu_test(SSL_CTX *ctx, const char *cs, int no_etm) * fits within the record MTU 500+i, so DTLS_get_data_mtu() * was overly pessimistic. */ - TEST_error("%s: s=%zu, mtus[i]=%zu, reclen=%zu, i=%d", - cs, s, mtus[i], reclen, 500 + i); + TEST_error("%s: s=%lu, mtus[i]=%lu, reclen=%lu, i=%d", + cs, (unsigned long)s, (unsigned long)mtus[i], + (unsigned long)reclen, 500 + i); goto end; } } diff --git a/test/dtlsv1listentest.c b/test/dtlsv1listentest.c index b4c15fb962..eb08fdb4e0 100644 --- a/test/dtlsv1listentest.c +++ b/test/dtlsv1listentest.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2018 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -312,7 +312,7 @@ static int dtls_listen_test(int i) SSL_set0_wbio(ssl, outbio); /* Set Non-blocking IO behaviour */ - if (!TEST_ptr(inbio = BIO_new_mem_buf(tp->in, tp->inlen))) + if (!TEST_ptr(inbio = BIO_new_mem_buf((char *)tp->in, tp->inlen))) goto err; BIO_set_mem_eof_return(inbio, -1); SSL_set0_rbio(ssl, inbio); diff --git a/test/ecdsatest.c b/test/ecdsatest.c index c4914bdec2..aa81e39f0f 100644 --- a/test/ecdsatest.c +++ b/test/ecdsatest.c @@ -1,5 +1,5 @@ /* - * Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2002-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -96,8 +96,10 @@ static int x9_62_tests(int n) TEST_info("ECDSA KATs for curve %s", OBJ_nid2sn(nid)); - if (OSSL_PROVIDER_available(NULL, "fips") && EC_curve_nid2nist(nid) == NULL) - return TEST_skip("skip non approved curves in FIPS mode"); +#ifdef FIPS_MODULE + if (EC_curve_nid2nist(nid) == NULL) + return TEST_skip("skip non approved curves"); +#endif /* FIPS_MODULE */ if (!TEST_ptr(mctx = EVP_MD_CTX_new()) /* get the message digest */ diff --git a/test/ech_corrupt_test.c b/test/ech_corrupt_test.c deleted file mode 100644 index 79d59844fd..0000000000 --- a/test/ech_corrupt_test.c +++ /dev/null @@ -1,1897 +0,0 @@ -/* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include "helpers/ssltestlib.h" -#include "testutil.h" -#include -#include -#include - -#define OSSL_ECH_MAX_LINELEN 1000 /* for a sanity check */ -#define DEF_CERTS_DIR "test/certs" - -/* the testcase numbers */ -#define TESTCASE_CH 1 -#define TESTCASE_SH 2 -#define TESTCASE_ECH 3 - -static OSSL_LIB_CTX *libctx = NULL; -static char *propq = NULL; -static OSSL_ECHSTORE *es = NULL; -static OSSL_HPKE_SUITE hpke_suite = OSSL_HPKE_SUITE_DEFAULT; -static int verbose = 0; -static int testcase = 0; -static int testiter = 0; -static char *certsdir = NULL; -static char *cert = NULL; -static char *privkey = NULL; -static unsigned char *hpke_info = NULL; -static size_t hpke_infolen = 0; -static int short_test = 0; - -/* - * An x25519 ech key and ECHConfigList with public name example.com - * and the associated base64 encoded and binary forms of that - * ECHConfigList - hardcoding here is ok as we're testing for - * effects of corrupted CH/SH and not for ECHConfig badness. - */ -static const char pem_kp1[] = "-----BEGIN PRIVATE KEY-----\n" - "MC4CAQAwBQYDK2VuBCIEILDIeo9Eqc4K9/uQ0PNAyMaP60qrxiSHT2tNZL3ksIZS\n" - "-----END PRIVATE KEY-----\n" - "-----BEGIN ECHCONFIG-----\n" - "AD7+DQA6bAAgACCY7B0f/3KvHIFdoqFaObdU8YYU+MdBf4vzbLhAAL2QCwAEAAEA\n" - "AQALZXhhbXBsZS5jb20AAA==\n" - "-----END ECHCONFIG-----\n"; -static const char echconfig[] = "AD7+DQA6bAAgACCY7B0f/3KvHIFdoqFaObdU8YYU+MdBf4vzbLhAAL2QCwAEAAEA" - "AQALZXhhbXBsZS5jb20AAA=="; -static size_t echconfiglen = sizeof(echconfig) - 1; - -/* a second ECHConfig for when we want to use the wrong one */ -static const char ec_kp2[] = "AEf+DQBDvQAgACCr9pErR7E/gNeoni+0YpDZaMd7XN+hFnCN+H0Xnm1EHQAEAAEAAQAUZnJvbnQuc2VydmVyLmV4YW1wbGUAAA=="; -static size_t ec_kp2len = sizeof(ec_kp2) - 1; - -static unsigned char bin_echconfig[] = { - 0x00, 0x3e, 0xfe, 0x0d, 0x00, 0x3a, 0x6c, 0x00, - 0x20, 0x00, 0x20, 0x98, 0xec, 0x1d, 0x1f, 0xff, - 0x72, 0xaf, 0x1c, 0x81, 0x5d, 0xa2, 0xa1, 0x5a, - 0x39, 0xb7, 0x54, 0xf1, 0x86, 0x14, 0xf8, 0xc7, - 0x41, 0x7f, 0x8b, 0xf3, 0x6c, 0xb8, 0x40, 0x00, - 0xbd, 0x90, 0x0b, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; -static size_t bin_echconfiglen = sizeof(bin_echconfig); - -/* - * We can grab the CH and SH and manipulate those to check good - * behaviour in the face of various errors. The most important - * thing to test is the server processing of the new combinations - * that result from the EncodedInnerClientHello (basically the raw - * output of ECH decryption). We test that via test vectors for - * those various borked values that we encrypt (via HPKE) and - * inject into the CH. The SH is much simpler since there are - * far fewer things to test with the magic encoding of the ECH - * accept signal into the SH.random or HRR.extension, but we - * can also test with borked versions of those. - * - * We'd like to, but so far cannot, do similarly for the ECH - * retry-config in EncryptedExtensions. Seems like there's no - * good way to get at the plaintext there and replace it with - * a borked value. (QUIC tests seem to have a way to do that - * but I've yet to figure how to replicate that here for the - * retry-config.) - */ - -/* - * For client hello, we use a set of test vectors for each test: - * - encoded inner CH prefix - * - encoded inner CH for borking (esp. outer extensions) - * - encoded inner CH postfix - * - expected result (1 for good, 0 for bad) - * - expected error reason in the case of bad - * - * For each test, we replace the ECH ciphertext with a value - * that's the HPKE seal/enc of an encoded inner-CH made up of - * the three parts above and then see if we get the expected - * error (reason). - * - * Whenever we re-seal we will get an error due to using the - * wrong inner client random, which we don't know. But that - * differs from errors in handling decoding after decryption. - * - * The inner CH is split in 3 variables so we can re-use pre - * and post values, making it easier to understand/manipulate - * a corrupted-or-not value. - * - * Note that the overall length of the encoded inner needs to - * be maintained as otherwise outer length fields that are not - * re-computed will be wrong. (We include a test of that as - * well.) A radical change in the content of encoded inner - * values (e.g. eliminating compression entirely) could break - * these tests, but minor changes should have no effect due to - * padding. (Such a radical change showing up as a fail of - * these tests is arguably a good outcome.) - */ -typedef struct { - const unsigned char *pre; - size_t prelen; - const unsigned char *forbork; - size_t fblen; - const unsigned char *post; - size_t postlen; - int rv_expected; /* expected result */ - int err_expected; /* expected error */ -} TEST_ECHINNER; - -/* a full padded, encoded inner client hello */ -static const unsigned char entire_encoded_inner[] = { - 0x03, 0x03, 0x7b, 0xe8, 0xc1, 0x18, 0xd7, 0xd1, - 0x9c, 0x39, 0xa4, 0xfa, 0xce, 0x75, 0x72, 0x40, - 0xcf, 0x37, 0xbb, 0x4c, 0xcd, 0xa7, 0x62, 0xda, - 0x04, 0xd2, 0xdb, 0xe2, 0x89, 0x33, 0x36, 0x15, - 0x96, 0xc9, 0x00, 0x00, 0x08, 0x13, 0x02, 0x13, - 0x03, 0x13, 0x01, 0x00, 0xff, 0x01, 0x00, 0x00, - 0x32, 0xfd, 0x00, 0x00, 0x11, 0x10, - 0x00, 0x0a, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0x00, 0x0d, 0x00, 0x2b, 0x00, 0x2d, 0x00, 0x33, - 0x00, 0x00, 0x00, 0x14, 0x00, 0x12, 0x00, 0x00, - 0x0f, 0x66, 0x6f, 0x6f, 0x2e, 0x65, 0x78, 0x61, - 0x6d, 0x70, 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, - 0xfe, 0x0d, 0x00, 0x01, 0x01, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00 -}; - -/* a full padded, encoded inner client hello with no extensions */ -static const unsigned char no_ext_encoded_inner[] = { - 0x03, 0x03, 0x7b, 0xe8, 0xc1, 0x18, 0xd7, 0xd1, - 0x9c, 0x39, 0xa4, 0xfa, 0xce, 0x75, 0x72, 0x40, - 0xcf, 0x37, 0xbb, 0x4c, 0xcd, 0xa7, 0x62, 0xda, - 0x04, 0xd2, 0xdb, 0xe2, 0x89, 0x33, 0x36, 0x15, - 0x96, 0xc9, 0x00, 0x00, 0x08, 0x13, 0x02, 0x13, - 0x03, 0x13, 0x01, 0x00, 0xff, 0x01, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 -}; - -/* a too-short, encoded inner client hello */ -static const unsigned char outer_short_encoded_inner[] = { - 0x03, 0x03, 0x7b, 0xe8, 0xc1, 0x18, 0xd7, 0xd1, - 0x9c, 0x39, 0xa4, 0xfa, 0xce, 0x75, 0x72, 0x40, - 0xcf, 0x37, 0xbb, 0x4c, 0xcd, 0xa7, 0x62, 0xda, - 0x04, 0xd2, 0xdb, 0xe2, 0x89, 0x33, 0x36, 0x15, - 0x96, 0xc9, 0x00, 0x00, 0x08, 0x13, 0x02, 0x13, - 0x03, 0x13, 0x01, 0x00, 0xff, 0x01, 0x00, 0x00, - 0x32, 0xfd, 0x00, 0x00, 0x11, 0x10, - 0x00, 0x0a, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0x00, 0x0d, 0x00, 0x2b, 0x00, 0x2d, 0x00, 0x33, - 0x00, 0x00, 0x00, 0x14, 0x00, 0x12, 0x00, 0x00, - 0x0f, 0x66, 0x6f, 0x6f, 0x2e, 0x65, 0x78, 0x61, - 0x6d, 0x70, 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, - 0xfe, 0x0d, 0x00, 0x01, 0x01, 0x00, 0x00 -}; - -/* inner prefix up as far as outer_exts */ -static const unsigned char encoded_inner_pre[] = { - 0x03, 0x03, 0x7b, 0xe8, 0xc1, 0x18, 0xd7, 0xd1, - 0x9c, 0x39, 0xa4, 0xfa, 0xce, 0x75, 0x72, 0x40, - 0xcf, 0x37, 0xbb, 0x4c, 0xcd, 0xa7, 0x62, 0xda, - 0x04, 0xd2, 0xdb, 0xe2, 0x89, 0x33, 0x36, 0x15, - 0x96, 0xc9, 0x00, 0x00, 0x08, 0x13, 0x02, 0x13, - 0x03, 0x13, 0x01, 0x00, 0xff, 0x01, 0x00, 0x00, - 0x32 -}; - -/* inner prefix with mad length of suites (0xDDDD) */ -static const unsigned char badsuites_inner_pre[] = { - 0x03, 0x03, 0x7b, 0xe8, 0xc1, 0x18, 0xd7, 0xd1, - 0x9c, 0x39, 0xa4, 0xfa, 0xce, 0x75, 0x72, 0x40, - 0xcf, 0x37, 0xbb, 0x4c, 0xcd, 0xa7, 0x62, 0xda, - 0x04, 0xd2, 0xdb, 0xe2, 0x89, 0x33, 0x36, 0x15, - 0x96, 0xc9, 0x00, 0xDD, 0xDD, 0x13, 0x02, 0x13, - 0x03, 0x13, 0x01, 0x00, 0xff, 0x01, 0x00, 0x00, - 0x32 -}; - -/* outer extensions - we play with variations of this */ -static const unsigned char encoded_inner_outers[] = { - 0xfd, 0x00, 0x00, 0x11, 0x10, - 0x00, 0x0a, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0x00, 0x0d, 0x00, 0x2b, 0x00, 0x2d, 0x00, 0x33 -}; - -/* outers with repetition of one extension (0x23) */ -static const unsigned char borked_outer1[] = { - 0xfd, 0x00, 0x00, 0x11, 0x10, - 0x00, 0x23, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0x00, 0x0d, 0x00, 0x2b, 0x00, 0x2d, 0x00, 0x33 -}; - -/* outers including a non-used extension (0xFFAB) */ -static const unsigned char borked_outer2[] = { - 0xfd, 0x00, 0x00, 0x11, 0x10, - 0x00, 0x0a, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0xFF, 0xAB, 0x00, 0x2b, 0x00, 0x2d, 0x00, 0x33 -}; - -/* refer to SNI in outers! 2nd-last is 0x0000 */ -static const unsigned char borked_outer3[] = { - 0xfd, 0x00, 0x00, 0x11, 0x10, - 0x00, 0x0a, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0x00, 0x0d, 0x00, 0x2b, 0x00, 0x00, 0x00, 0x33 -}; - -/* refer to ECH (0xfe0d) within outers */ -static const unsigned char borked_outer4[] = { - 0xfd, 0x00, 0x00, 0x11, 0x10, - 0x00, 0x0a, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0xFE, 0x0D, 0x00, 0x2b, 0x00, 0x2d, 0x00, 0x33 -}; - -/* refer to outers (0xfd00) within outers */ -static const unsigned char borked_outer5[] = { - 0xfd, 0x00, 0x00, 0x11, 0x10, - 0x00, 0x0a, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0xFD, 0x00, 0x00, 0x2b, 0x00, 0x2d, 0x00, 0x33 -}; - -/* no outers at all! include unknown ext 0xFF99 instead */ -static const unsigned char borked_outer6[] = { - 0xFF, 0x99, 0x00, 0x11, 0x10, - 0x00, 0x0a, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0x00, 0x0d, 0x00, 0x2b, 0x00, 0x2d, 0x00, 0x33 -}; - -/* - * outer with bad length (even number of octets) - * we add a short bogus extension (0xFFFF) after - * to ensure overall decode succeeds - */ -static const unsigned char borked_outer7[] = { - 0xfd, 0x00, 0x00, 0x0E, 0x10, - 0x00, 0x0a, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0x00, 0x0d, 0x00, 0xFF, 0xFF, 0x00, 0x01, 0x00 -}; - -/* outer with bad inner length (odd number of octets) */ -static const unsigned char borked_outer8[] = { - 0xfd, 0x00, 0x00, 0x11, 0x11, - 0x00, 0x0a, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0x00, 0x0d, 0x00, 0x2b, 0x00, 0x2d, 0x00, 0x33 -}; - -/* outer with HUGE length (0xFF11) */ -static const unsigned char borked_outer9[] = { - 0xfd, 0x00, 0xFF, 0x11, 0x10, - 0x00, 0x0a, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0x00, 0x0d, 0x00, 0x2b, 0x00, 0x2d, 0x00, 0x33 -}; - -/* outer with zero length, followed by bogus ext */ -static const unsigned char borked_outer10[] = { - 0xfd, 0x00, 0x00, 0x00, 0xFF, - 0x0F, 0x00, 0x0D, 0x23, 0x00, 0x16, 0x00, 0x17, - 0x00, 0x0d, 0x00, 0x2b, 0x00, 0x2d, 0x00, 0x33 -}; - -/* refer to key-share 0x00 0x33 (51) twice within outers */ -static const unsigned char borked_outer11[] = { - 0xfd, 0x00, 0x00, 0x11, 0x10, - 0x00, 0x0a, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0x00, 0x33, 0x00, 0x2b, 0x00, 0x2d, 0x00, 0x33 -}; - -/* refer to psk kex mode (0x00 0x2D/45) within outers */ -static const unsigned char borked_outer12[] = { - 0xfd, 0x00, 0x00, 0x11, 0x10, - 0x00, 0x0a, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0x00, 0x2D, 0x00, 0x2b, 0x00, 0x2d, 0x00, 0x33 -}; - -static const unsigned char encoded_inner_post[] = { - 0x00, 0x00, 0x00, 0x14, 0x00, 0x12, 0x00, 0x00, - 0x0f, 0x66, 0x6f, 0x6f, 0x2e, 0x65, 0x78, 0x61, - 0x6d, 0x70, 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, - 0xfe, 0x0d, 0x00, 0x01, 0x01, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00 -}; - -/* muck up the padding by including non-zero stuff */ -static const unsigned char bad_pad_encoded_inner_post[] = { - 0x00, 0x00, 0x00, 0x14, 0x00, 0x12, 0x00, 0x00, - 0x0f, 0x66, 0x6f, 0x6f, 0x2e, 0x65, 0x78, 0x61, - 0x6d, 0x70, 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, - 0xfe, 0x0d, 0x00, 0x01, 0x01, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0xFF, 0xFF, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00 -}; - -/* an encoded inner that's just too short */ -static const unsigned char short_encoded_inner[] = { - 0x03, 0x03, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 -}; - -/* - * too many outer extensions - max is 20 (decimal) - * defined as OSSL_ECH_OUTERS_MAX - */ -static const unsigned char too_many_outers[] = { - 0x03, 0x03, 0x7b, 0xe8, 0xc1, 0x18, 0xd7, 0xd1, - 0x9c, 0x39, 0xa4, 0xfa, 0xce, 0x75, 0x72, 0x40, - 0xcf, 0x37, 0xbb, 0x4c, 0xcd, 0xa7, 0x62, 0xda, - 0x04, 0xd2, 0xdb, 0xe2, 0x89, 0x33, 0x36, 0x15, - 0x96, 0xc9, 0x00, 0x00, 0x08, 0x13, 0x02, 0x13, - 0x03, 0x13, 0x01, 0x00, 0xff, 0x01, 0x00, - 0x00, 0x4c, /* extslen, incl. our added outers */ - 0xfd, 0x00, /* outers */ - 0x00, 0x2b, /* len of outers */ - 0x2a, /* above minus one (42) 21 outers */ - 0x00, 0x0a, /* the 8 'normal' outers */ - 0x00, 0x23, - 0x00, 0x16, - 0x00, 0x17, - 0x00, 0x0d, - 0x00, 0x2b, - 0x00, 0x2d, - 0x00, 0x33, - 0x00, 0x0b, /* point encoding, not actually in outer */ - /* 12 more outers, set 'em all to ALPN (16, 0x10) */ - 0x00, 0x10, 0x00, 0x10, 0x00, 0x10, 0x00, 0x10, - 0x00, 0x10, 0x00, 0x10, 0x00, 0x10, 0x00, 0x10, - 0x00, 0x10, 0x00, 0x10, 0x00, 0x10, 0x00, 0x10, - /* and now the inner SNI, inner ECH and 3 padding octets */ - 0x00, 0x00, 0x00, 0x14, 0x00, 0x12, 0x00, 0x00, - 0x0f, 0x66, 0x6f, 0x6f, 0x2e, 0x65, 0x78, 0x61, - 0x6d, 0x70, 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, - 0xfe, 0x0d, 0x00, 0x01, 0x01, - 0x00, 0x00, 0x00 -}; - -static const unsigned char tlsv12_like_inner[] = { - 0x03, 0x03, /* version, then client-random */ - 0x23, 0xc3, 0xa0, 0x49, 0xea, 0x17, 0x9e, 0x30, - 0x6f, 0x0e, 0xc9, 0x79, 0xd0, 0xd1, 0xfd, 0xea, - 0x63, 0xfd, 0x20, 0x04, 0xaa, 0xb3, 0x2a, 0x29, - 0xf5, 0x96, 0x60, 0x29, 0x42, 0x7e, 0x5c, 0x7b, - 0x00, /* zero'd session ID */ - 0x00, 0x02, /* ciphersuite len, just one */ - 0xc0, 0x2c, /* a TLSv1.2 ciphersuite */ - 0x01, 0x00, /* no compression */ - 0x00, 0x2c, /* extslen */ - 0xfd, 0x00, /* outers */ - 0x00, 0x0b, /* len of outers */ - 0x0a, /* above minus one (10) 5 outers */ - 0x00, 0x0a, /* the 'normal' outers, minus supported_versions */ - 0x00, 0x23, - 0x00, 0x16, - 0x00, 0x17, - 0x00, 0x0d, - /* and now the inner SNI, inner ECH and padding octets */ - 0x00, 0x00, 0x00, 0x14, 0x00, 0x12, 0x00, 0x00, - 0x0f, 0x66, 0x6f, 0x6f, 0x2e, 0x65, 0x78, 0x61, - 0x6d, 0x70, 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, - 0xfe, 0x0d, 0x00, 0x01, 0x01, - 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00 -}; - -/* - * a full padded, encoded inner client hello, but - * without an inner supported extensions, (take - * out the 0x00 0x2b and add some padding zeros, - * adjusting lengths) and hence meaning TLSv1.2 - */ -static const unsigned char no_supported_exts[] = { - 0x03, 0x03, 0x7b, 0xe8, 0xc1, 0x18, 0xd7, 0xd1, - 0x9c, 0x39, 0xa4, 0xfa, 0xce, 0x75, 0x72, 0x40, - 0xcf, 0x37, 0xbb, 0x4c, 0xcd, 0xa7, 0x62, 0xda, - 0x04, 0xd2, 0xdb, 0xe2, 0x89, 0x33, 0x36, 0x15, - 0x96, 0xc9, 0x00, 0x00, 0x08, 0x13, 0x02, 0x13, - 0x03, 0x13, 0x01, 0x00, 0xff, 0x01, 0x00, 0x00, - 0x30, 0xfd, 0x00, 0x00, 0x0f, 0x0e, - 0x00, 0x0a, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0x00, 0x0d, 0x00, 0x2d, 0x00, 0x33, - 0x00, 0x00, 0x00, 0x14, 0x00, 0x12, 0x00, 0x00, - 0x0f, 0x66, 0x6f, 0x6f, 0x2e, 0x65, 0x78, 0x61, - 0x6d, 0x70, 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, - 0xfe, 0x0d, 0x00, 0x01, 0x01, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00 -}; - -static const unsigned char tlsv12_inner[] = { - 0x03, 0x03, /* version, then client-random */ - 0x23, 0xc3, 0xa0, 0x49, 0xea, 0x17, 0x9e, 0x30, - 0x6f, 0x0e, 0xc9, 0x79, 0xd0, 0xd1, 0xfd, 0xea, - 0x63, 0xfd, 0x20, 0x04, 0xaa, 0xb3, 0x2a, 0x29, - 0xf5, 0x96, 0x60, 0x29, 0x42, 0x7e, 0x5c, 0x7b, - 0x00, /* zero'd session ID */ - 0x00, 0x02, /* ciphersuite len, just one */ - 0xc0, 0x2c, /* a TLSv1.2 ciphersuite */ - 0x01, 0x00, /* no compression */ - 0x00, 0x32, /* extslen */ - 0xfd, 0x00, /* outers */ - 0x00, 0x10, /* len of outers */ - 0x0e, /* above minus one (16) 8 outers */ - 0x00, 0x0a, /* the 'normal' outers, minus supported_versions */ - 0x00, 0x23, - 0x00, 0x16, - 0x00, 0x17, - 0x00, 0x0d, - 0x00, 0x2d, - 0x00, 0x33, - /* and now the inner SNI, inner ECH and padding octets */ - 0x00, 0x00, 0x00, 0x14, 0x00, 0x12, 0x00, 0x00, - 0x0f, 0x66, 0x6f, 0x6f, 0x2e, 0x65, 0x78, 0x61, - 0x6d, 0x70, 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, - 0xfe, 0x0d, 0x00, 0x01, 0x01, - 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 -}; - -/* - * a full padded, encoded inner with no inner ECH - * we change 0xfe 0x0d to 0xFF 0xFD in the ext type - */ -static const unsigned char encoded_inner_no_ech[] = { - 0x03, 0x03, 0x7b, 0xe8, 0xc1, 0x18, 0xd7, 0xd1, - 0x9c, 0x39, 0xa4, 0xfa, 0xce, 0x75, 0x72, 0x40, - 0xcf, 0x37, 0xbb, 0x4c, 0xcd, 0xa7, 0x62, 0xda, - 0x04, 0xd2, 0xdb, 0xe2, 0x89, 0x33, 0x36, 0x15, - 0x96, 0xc9, 0x00, 0x00, 0x08, 0x13, 0x02, 0x13, - 0x03, 0x13, 0x01, 0x00, 0xff, 0x01, 0x00, 0x00, - 0x32, 0xfd, 0x00, 0x00, 0x11, 0x10, - 0x00, 0x0a, 0x00, 0x23, 0x00, 0x16, 0x00, 0x17, - 0x00, 0x0d, 0x00, 0x2b, 0x00, 0x2d, 0x00, 0x33, - 0x00, 0x00, 0x00, 0x14, 0x00, 0x12, 0x00, 0x00, - 0x0f, 0x66, 0x6f, 0x6f, 0x2e, 0x65, 0x78, 0x61, - 0x6d, 0x70, 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, - 0xFF, 0xFD, 0x00, 0x01, 0x01, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00 -}; - -/* A set of test vectors */ -static TEST_ECHINNER test_inners[] = { - /* 1. basic case - copy to show test code works with no change */ - { NULL, 0, NULL, 0, NULL, 0, 1, SSL_ERROR_NONE }, - - /* 2. too-short encoded inner */ - { NULL, 0, - outer_short_encoded_inner, sizeof(outer_short_encoded_inner), - NULL, 0, - 0, /* expected result */ - SSL_R_DECRYPTION_FAILED_OR_BAD_RECORD_MAC }, - /* 3. otherwise-correct case that fails only due to client random */ - { NULL, 0, - entire_encoded_inner, sizeof(entire_encoded_inner), - NULL, 0, - 0, /* expected result */ - SSL_R_DECRYPTION_FAILED_OR_BAD_RECORD_MAC }, - /* 4. otherwise-correct case that fails only due to client random */ - { encoded_inner_pre, sizeof(encoded_inner_pre), - encoded_inner_outers, sizeof(encoded_inner_outers), - encoded_inner_post, sizeof(encoded_inner_post), - 0, /* expected result */ - SSL_R_DECRYPTION_FAILED_OR_BAD_RECORD_MAC }, - /* 5. fails HPKE decryption due to bad padding so treated as GREASE */ - { encoded_inner_pre, sizeof(encoded_inner_pre), - encoded_inner_outers, sizeof(encoded_inner_outers), - bad_pad_encoded_inner_post, sizeof(bad_pad_encoded_inner_post), - 0, /* expected result */ - SSL_R_TLS_ALERT_ILLEGAL_PARAMETER }, - /* - * 6. unsupported extension instead of outers - resulting decoded - * inner missing so much it seems to be the wrong protocol - */ - { encoded_inner_pre, sizeof(encoded_inner_pre), - borked_outer6, sizeof(borked_outer6), - encoded_inner_post, sizeof(encoded_inner_post), - 0, /* expected result - error is different with -notls1_2 */ -#ifdef OPENSSL_NO_TLS1_2 - SSL_R_VERSION_TOO_LOW -#else - SSL_R_UNSUPPORTED_PROTOCOL -#endif - }, - - /* 7. madly long ciphersuites in inner */ - { badsuites_inner_pre, sizeof(badsuites_inner_pre), - encoded_inner_outers, sizeof(encoded_inner_outers), - encoded_inner_post, sizeof(bad_pad_encoded_inner_post), - 0, /* expected result */ - SSL_R_TLSV1_ALERT_DECODE_ERROR }, - /* 8. so many padding bytes recovered clear is short */ - { NULL, 0, - short_encoded_inner, sizeof(short_encoded_inner), - NULL, 0, - 0, /* expected result */ - SSL_R_BAD_EXTENSION }, - - /* 9. repeated codepoint inside outers */ - { encoded_inner_pre, sizeof(encoded_inner_pre), - borked_outer1, sizeof(borked_outer1), - encoded_inner_post, sizeof(encoded_inner_post), - 0, /* expected result */ - SSL_R_BAD_EXTENSION }, - /* 10. non-existent codepoint inside outers */ - { encoded_inner_pre, sizeof(encoded_inner_pre), - borked_outer2, sizeof(borked_outer2), - encoded_inner_post, sizeof(encoded_inner_post), - 0, /* expected result */ - SSL_R_BAD_EXTENSION }, - /* 11. include SNI in outers as well as both inner and outer */ - { encoded_inner_pre, sizeof(encoded_inner_pre), - borked_outer3, sizeof(borked_outer3), - encoded_inner_post, sizeof(encoded_inner_post), - 0, /* expected result */ - SSL_R_BAD_EXTENSION }, - /* 12. refer to ECH within outers */ - { encoded_inner_pre, sizeof(encoded_inner_pre), - borked_outer4, sizeof(borked_outer4), - encoded_inner_post, sizeof(encoded_inner_post), - 0, /* expected result */ - SSL_R_BAD_EXTENSION }, - /* 13. refer to outers within outers */ - { encoded_inner_pre, sizeof(encoded_inner_pre), - borked_outer5, sizeof(borked_outer5), - encoded_inner_post, sizeof(encoded_inner_post), - 0, /* expected result */ - SSL_R_BAD_EXTENSION }, - /* 14. bad length of outers */ - { encoded_inner_pre, sizeof(encoded_inner_pre), - borked_outer7, sizeof(borked_outer7), - encoded_inner_post, sizeof(encoded_inner_post), - 0, /* expected result */ - SSL_R_BAD_EXTENSION }, - /* 15. bad inner length in outers */ - { encoded_inner_pre, sizeof(encoded_inner_pre), - borked_outer8, sizeof(borked_outer8), - encoded_inner_post, sizeof(encoded_inner_post), - 0, /* expected result */ - SSL_R_BAD_EXTENSION }, - /* 16. HUGE length in outers */ - { encoded_inner_pre, sizeof(encoded_inner_pre), - borked_outer9, sizeof(borked_outer9), - encoded_inner_post, sizeof(encoded_inner_post), - 0, /* expected result */ - SSL_R_BAD_EXTENSION }, - /* 17. zero length in outers */ - { encoded_inner_pre, sizeof(encoded_inner_pre), - borked_outer10, sizeof(borked_outer10), - encoded_inner_post, sizeof(encoded_inner_post), - 0, /* expected result */ - SSL_R_BAD_EXTENSION }, - /* 18. case with no extensions at all */ - { NULL, 0, - no_ext_encoded_inner, sizeof(no_ext_encoded_inner), - NULL, 0, - 0, /* expected result */ - SSL_R_BAD_EXTENSION }, - /* - * 19. include key-share twice in outers as well as both inner and outer. - * There was a change with this one recently that can/does cause a - * different error message (used to be SSL_R_BAD_EXTENSION, but now - * mostly ERR_R_INTERNAL_ERROR). The issue is that this test repeats the - * key_share in the compressed exts and with PQ kybrid KEMs those are - * so large that instead of detecting the duplicate extension we see - * an earlier error where the inner CH is bigger than the outer. - */ - { encoded_inner_pre, sizeof(encoded_inner_pre), - borked_outer11, sizeof(borked_outer11), - encoded_inner_post, sizeof(encoded_inner_post), - 0, /* expected result */ -#ifdef OPENSSL_NO_ML_KEM - SSL_R_BAD_EXTENSION -#else - ERR_R_INTERNAL_ERROR -#endif - }, - /* 20. include psk key mode ext in outers as well as both inner and outer */ - { encoded_inner_pre, sizeof(encoded_inner_pre), - borked_outer12, sizeof(borked_outer12), - encoded_inner_post, sizeof(encoded_inner_post), - 0, /* expected result */ - SSL_R_BAD_EXTENSION }, - /* 21. too many outers */ - { NULL, 0, - too_many_outers, sizeof(too_many_outers), - NULL, 0, - 0, /* expected result */ - SSL_R_BAD_EXTENSION }, - /* - * 22. no supported_versions hence TLSv1.2, with server set to - * allow max tlsv1.3 - */ - { NULL, 0, - tlsv12_like_inner, sizeof(tlsv12_like_inner), - NULL, 0, - 0, /* expected result */ SSL_R_UNSUPPORTED_PROTOCOL }, - /* - * 23. no supported_versions hence TLSv1.2, with server set to - * allow max tlsv1.2 - */ - { NULL, 0, - no_supported_exts, sizeof(no_supported_exts), - NULL, 0, - 0, /* expected result */ - SSL_R_NO_PROTOCOLS_AVAILABLE }, - /* - * 24. no supported_versions hence TLSv1.2, with server set to - * allow min tlsv1.2 - */ - { NULL, 0, - tlsv12_like_inner, sizeof(tlsv12_like_inner), - NULL, 0, - 0, /* expected result */ SSL_R_UNSUPPORTED_PROTOCOL }, - /* 25. smuggled TLSv1.2 CH */ - { NULL, 0, - tlsv12_inner, sizeof(tlsv12_inner), - NULL, 0, - 0, /* expected result */ SSL_R_BAD_EXTENSION }, - /* 26. otherwise-correct case that fails due to lack of inner ECH */ - { NULL, 0, - encoded_inner_no_ech, sizeof(encoded_inner_no_ech), - NULL, 0, - 0, /* expected result */ SSL_R_ECH_REQUIRED }, -}; - -/* - * For server hello/HRR, we use a set of test vectors for each test: - * - * - borkage encodes what we're breaking and is the OR - * of some #define'd OSSL_ECH_BORK_* flags - * - bork is the value to use instead of the real one (or NULL) - * - blen is the size of bork - * - rv_expected is the return value expected for the connection - * - err_expected is the reason code we expect to see - */ -typedef struct { - int borkage; /* type of borkage */ - unsigned char *bork; /* borked value */ - size_t blen; /* len(bork) */ - int rv_expected; /* expected result */ - int err_expected; /* expected error */ -} TEST_SH; - -#define OSSL_ECH_BORK_NONE 0 -#define OSSL_ECH_BORK_FLIP 1 -#define OSSL_ECH_BORK_HRR (1 << 1) -#define OSSL_ECH_BORK_SHORT_HRR_CONFIRM (1 << 2) -#define OSSL_ECH_BORK_LONG_HRR_CONFIRM (1 << 3) -#define OSSL_ECH_BORK_GREASE (1 << 4) -#define OSSL_ECH_BORK_REPLACE (1 << 5) - -/* a truncated ECH, padded with a known HRR ext to match overall length */ -static unsigned char shortech[] = { - 0xfe, 0x0d, 0x00, 0x04, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x2c, 0x00, 0x00 -}; - -/* a too-long ECH internal length */ -static unsigned char longech[] = { - 0xfe, 0x0d, 0x00, 0x09, 0x00, 0x00, 0x00, 0x00, - 0xdd, 0xdd, 0x00, 0x00 -}; - -static TEST_SH test_shs[] = { - /* 1. no messing about, should succeed */ - { OSSL_ECH_BORK_NONE, NULL, 0, 1, SSL_ERROR_NONE }, - /* 2. trigger HRR but no other borkage */ - { OSSL_ECH_BORK_HRR, NULL, 0, 1, SSL_ERROR_NONE }, - - /* 3. GREASE and trigger HRR */ - { OSSL_ECH_BORK_HRR | OSSL_ECH_BORK_GREASE, - NULL, 0, 1, SSL_ERROR_NONE }, - - /* 4. flip bits in SH.random ECH confirmation value */ - { OSSL_ECH_BORK_FLIP, NULL, 0, 0, - SSL_R_DECRYPTION_FAILED_OR_BAD_RECORD_MAC }, - /* 5. flip bits in HRR.exts ECH confirmation value */ - { OSSL_ECH_BORK_HRR | OSSL_ECH_BORK_FLIP, - NULL, 0, 0, SSL_R_ECH_REQUIRED }, - /* 6. truncate HRR.exts ECH confirmation value */ - { OSSL_ECH_BORK_HRR | OSSL_ECH_BORK_REPLACE, - shortech, sizeof(shortech), 0, SSL_R_LENGTH_MISMATCH }, - /* 7. too-long HRR.exts ECH confirmation value */ - { OSSL_ECH_BORK_HRR | OSSL_ECH_BORK_REPLACE, - longech, sizeof(longech), 0, SSL_R_BAD_EXTENSION }, - -}; - -/* - * Test vectors for badly encoded ECH extension values for - * the outer ClientHelllo. We grab the outbound ClientHello - * and overwrite these values in the appropriate place. That - * will always break the TLS connection, even with a correct - * encoding, as we're breaking the transcript, but we expect - * decoding to catch these and to get 'bad extension' errors - * in most cases. - * - * Note that the code for these tests could be more terse as - * declaring a separate buffer for each bad value is quite - * repetitive, but doing it this way is more readable and more - * easily varied/extended. - */ - -/* an entire correctly encoded ECH (len = 190) */ -static unsigned char entire_encoded_ech[] = { - 0xfe, 0x0d, 0x00, 0xba, /* ext type & length */ - 0x00, /* outer ECH */ - 0x00, 0x01, 0x00, 0x01, /* cipher suite KDF, AEAD */ - 0x7c, /* config id */ - 0x00, 0x20, /* encap len then encap val */ - 0x59, 0x87, 0xbe, 0x13, 0xd0, 0xf1, 0x0e, 0x23, - 0xcb, 0x28, 0x26, 0xc2, 0x88, 0xd0, 0x8f, 0xac, - 0x04, 0x99, 0x54, 0x30, 0xa2, 0x0f, 0xfe, 0x53, - 0xf5, 0xa5, 0x92, 0x01, 0xb1, 0x56, 0xd2, 0x3f, - 0x00, 0x90, /* payload len then payload */ - 0x9e, 0xe6, 0xed, 0x1d, 0xe2, 0xef, 0x30, 0xb0, - 0x91, 0x00, 0xdc, 0x90, 0x21, 0x9e, 0x5e, 0x6f, - 0xcb, 0xb9, 0xb3, 0x05, 0xdd, 0xac, 0x97, 0x71, - 0xf0, 0x2d, 0x48, 0xf7, 0x01, 0xf4, 0x68, 0x0c, - 0xb4, 0xbe, 0x78, 0x3c, 0xa3, 0xcb, 0x6a, 0x16, - 0x7a, 0xfc, 0x33, 0xcd, 0x12, 0xf3, 0x00, 0x2f, - 0x3e, 0xaa, 0xef, 0x7c, 0x26, 0xd3, 0x6f, 0x46, - 0x8e, 0xb8, 0x54, 0x4c, 0x6a, 0xc3, 0x85, 0x92, - 0x44, 0xc1, 0xe2, 0x03, 0xfe, 0xfc, 0xca, 0xff, - 0x3b, 0x03, 0x9a, 0xf0, 0xd8, 0xe7, 0x2d, 0xb0, - 0xe3, 0x64, 0x9f, 0xb9, 0x78, 0xd3, 0xca, 0x4c, - 0xa2, 0xdd, 0x1f, 0x68, 0x9a, 0x9b, 0xcc, 0xb9, - 0x79, 0x59, 0xb4, 0xac, 0x4e, 0x7d, 0xce, 0xa3, - 0xc7, 0x23, 0xe6, 0x1c, 0xcd, 0x8d, 0xaa, 0xaa, - 0xdb, 0x21, 0xa1, 0xec, 0xb8, 0xbe, 0x53, 0x60, - 0x4f, 0xf4, 0x0b, 0xef, 0xad, 0x1d, 0x45, 0x62, - 0x65, 0x88, 0xfe, 0x15, 0x47, 0x25, 0x61, 0xa5, - 0x65, 0x7a, 0x17, 0xaa, 0x08, 0x3f, 0xe8, 0xf2 -}; - -/* overall length too much */ -static unsigned char too_long_ech[] = { - 0xfe, 0x0d, 0xFF, 0xba /* ext type & length */ -}; - -/* overall length too short */ -static unsigned char too_short_ech[] = { - 0xfe, 0x0d, 0x00, 0x00 /* ext type & length */ -}; - -/* no inner/outer value */ -static unsigned char no_innerouter_ech[] = { - 0xfe, 0x0d, 0x00, 0x00, /* ext type & length */ - 0x00 -}; - -/* ECH inner/outer bad value */ -static unsigned char bad_innerouter_ech[] = { - 0xfe, 0x0d, 0x00, 0xba, /* ext type & length */ - 0xFF -}; - -/* too short to get to KDF */ -static unsigned char too_short_kdf[] = { - 0xfe, 0x0d, 0x00, 0x02, /* ext type & length */ - 0x00, - 0x00, 0x01, 0x00, 0x01 /* cipher suite KDF, AEAD */ -}; - -/* too short to get to AEAD */ -static unsigned char too_short_aead[] = { - 0xfe, 0x0d, 0x00, 0x04, /* ext type & length */ - 0x00, - 0x00, 0x01, 0x00, 0x01 /* cipher suite KDF, AEAD */ -}; - -/* too short to get to config_id */ -static unsigned char too_short_cid[] = { - 0xfe, 0x0d, 0x00, 0x05, /* ext type & length */ - 0x00, - 0x00, 0x01, 0x00, 0x01, /* cipher suite KDF, AEAD */ - 0x7c -}; - -/* zero length encap (only ok in HRR) */ -static unsigned char zero_encap_len[] = { - 0xfe, 0x0d, 0x00, 0xba, /* ext type & length */ - 0x00, - 0x00, 0x01, 0x00, 0x01, /* cipher suite KDF, AEAD */ - 0x7c, - 0x00, 0x00 -}; - -/* too short to get to encap_len */ -static unsigned char too_short_encap_len[] = { - 0xfe, 0x0d, 0x00, 0x07, /* ext type & length */ - 0x00, - 0x00, 0x01, 0x00, 0x01, /* cipher suite KDF, AEAD */ - 0x7c, - 0x00 -}; - -/* too long encap len */ -static unsigned char too_long_encap_len[] = { - 0xfe, 0x0d, 0x00, 0xba, /* ext type & length */ - 0x00, - 0x00, 0x01, 0x00, 0x01, /* cipher suite KDF, AEAD */ - 0x7c, - 0xFF, 0xFF -}; - -/* bit long encap len (more than extension) */ -static unsigned char bit_long_encap_len[] = { - 0xfe, 0x0d, 0x00, 0xba, /* ext type & length */ - 0x00, - 0x00, 0x01, 0x00, 0x01, /* cipher suite KDF, AEAD */ - 0x7c, - 0x00, 0xFF -}; - -/* too short to get to payload_len */ -static unsigned char too_short_payload_len[] = { - 0xfe, 0x0d, 0x00, 0x29, /* ext type & length */ - 0x00, - 0x00, 0x01, 0x00, 0x01, /* cipher suite KDF, AEAD */ - 0x7c, - 0x00, 0x20, /* encap len then encap val */ - 0x59, 0x87, 0xbe, 0x13, 0xd0, 0xf1, 0x0e, 0x23, - 0xcb, 0x28, 0x26, 0xc2, 0x88, 0xd0, 0x8f, 0xac, - 0x04, 0x99, 0x54, 0x30, 0xa2, 0x0f, 0xfe, 0x53, - 0xf5, 0xa5, 0x92, 0x01, 0xb1, 0x56, 0xd2, 0x3f, - 0x00, 0x90 /* payload len then payload */ -}; - -/* bit long payload_len */ -static unsigned char bit_long_payload_len[] = { - 0xfe, 0x0d, 0x00, 0xba, /* ext type & length */ - 0x00, - 0x00, 0x01, 0x00, 0x01, /* cipher suite KDF, AEAD */ - 0x7c, - 0x00, 0x20, /* encap len then encap val */ - 0x59, 0x87, 0xbe, 0x13, 0xd0, 0xf1, 0x0e, 0x23, - 0xcb, 0x28, 0x26, 0xc2, 0x88, 0xd0, 0x8f, 0xac, - 0x04, 0x99, 0x54, 0x30, 0xa2, 0x0f, 0xfe, 0x53, - 0xf5, 0xa5, 0x92, 0x01, 0xb1, 0x56, 0xd2, 0x3f, - 0x00, 0xba /* payload len then payload */ -}; - -/* zero payload_len */ -static unsigned char zero_payload_len[] = { - 0xfe, 0x0d, 0x00, 0xba, /* ext type & length */ - 0x00, - 0x00, 0x01, 0x00, 0x01, /* cipher suite KDF, AEAD */ - 0x7c, - 0x00, 0x20, /* encap len then encap val */ - 0x59, 0x87, 0xbe, 0x13, 0xd0, 0xf1, 0x0e, 0x23, - 0xcb, 0x28, 0x26, 0xc2, 0x88, 0xd0, 0x8f, 0xac, - 0x04, 0x99, 0x54, 0x30, 0xa2, 0x0f, 0xfe, 0x53, - 0xf5, 0xa5, 0x92, 0x01, 0xb1, 0x56, 0xd2, 0x3f, - 0x00, 0x00 /* payload len then payload */ -}; - -/* - * Structure for test vectors for ECH in the outer CH - * - value to use to overwrite encoded ECH - * - expected result (1 for good, 0 for bad) - * - expected error reason in the case of bad - * - * For each test, we replace the first |len| octets of the - * ECH extension in the outer CH with the associated |val|. - * - * Note that the overall length of the outer CH needs to - * be maintained as otherwise outer length fields that are not - * re-computed will be wrong. (We include a test of that as - * well.) A radical change in the content of encoded inner - * values (e.g. eliminating compression entirely) could break - * these tests, but minor changes should have no effect due to - * padding. (Such a radical change showing up as a fail of - * these tests is arguably a good outcome.) - */ -typedef struct { - const unsigned char *val; - size_t len; - int rv_expected; /* expected result */ - int err_expected; /* expected error */ -} TEST_ECHOUTER; - -static TEST_ECHOUTER test_echs[] = { - /* 1. basic case - copy to show test code works with no change */ - { NULL, 0, 1, SSL_ERROR_NONE }, - - /* 2. good encoding/length but breaks TLS session integrity */ - { entire_encoded_ech, sizeof(entire_encoded_ech), - 0, /* expected result */ - SSL_R_DECRYPTION_FAILED_OR_BAD_RECORD_MAC }, - /* 3. ECH length too long */ - { too_long_ech, sizeof(too_long_ech), - 0, /* expected result */ SSL_R_BAD_EXTENSION }, - /* 4. ECH length too short */ - { too_short_ech, sizeof(too_short_ech), - 0, /* expected result */ SSL_R_BAD_EXTENSION }, - /* 5. no inner/outer value */ - { no_innerouter_ech, sizeof(no_innerouter_ech), - 0, /* expected result */ SSL_R_BAD_EXTENSION }, - /* 6. inner/outer bad value */ - { bad_innerouter_ech, sizeof(bad_innerouter_ech), - 0, /* expected result */ SSL_R_BAD_EXTENSION }, - /* 7. too_short_kdf value */ - { too_short_kdf, sizeof(too_short_kdf), - 0, /* expected result */ SSL_R_BAD_EXTENSION }, - /* 8. too_short_aead value */ - { too_short_aead, sizeof(too_short_aead), - 0, /* expected result */ SSL_R_BAD_EXTENSION }, - /* 9. too_short_cid value */ - { too_short_cid, sizeof(too_short_cid), - 0, /* expected result */ SSL_R_BAD_EXTENSION }, - /* 10. zero_encap_len value */ - { zero_encap_len, sizeof(zero_encap_len), - 0, /* expected result */ SSL_R_BAD_EXTENSION }, - /* 11. too_short_encap_len value */ - { too_short_encap_len, sizeof(too_short_encap_len), - 0, /* expected result */ SSL_R_BAD_EXTENSION }, - /* 12. too_long_encap_len value */ - { too_long_encap_len, sizeof(too_long_encap_len), - 0, /* expected result */ SSL_R_BAD_EXTENSION }, - /* 13. bit_long_encap_len value */ - { bit_long_encap_len, sizeof(bit_long_encap_len), - 0, /* expected result */ SSL_R_BAD_EXTENSION }, - /* 14. too_short_payload_len value */ - { too_short_payload_len, sizeof(too_short_payload_len), - 0, /* expected result */ SSL_R_BAD_EXTENSION }, - /* 15. bit_long_payload_len value */ - { bit_long_payload_len, sizeof(bit_long_payload_len), - 0, /* expected result */ SSL_R_BAD_EXTENSION }, - /* 16. zero_payload_len value */ - { zero_payload_len, sizeof(zero_payload_len), - 0, /* expected result */ SSL_R_BAD_EXTENSION }, -}; - -/* - * Given a SH (or HRR) find the offsets of the ECH (if any) - * sh is the SH buffer - * sh_len is the length of the SH - * exts points to offset of extensions - * echoffset points to offset of ECH - * echtype points to the ext type of the ECH - * for success, other otherwise - * - * Offsets are returned to the type or length field in question. - * Offsets are set to zero if relevant thing not found. - * - * Note: input here is untrusted! - */ -static int ech_get_sh_offsets(const unsigned char *sh, - size_t sh_len, size_t *exts, - size_t *echoffset, uint16_t *echtype) -{ - unsigned int elen = 0, etype = 0, pi_tmp = 0; - const unsigned char *pp_tmp = NULL, *shstart = NULL, *estart = NULL; - PACKET pkt; - size_t extlens = 0; - int done = 0; -#ifdef OSSL_ECH_SUPERVERBOSE - size_t echlen = 0; /* length of ECH, including type & ECH-internal length */ - size_t sessid_offset = 0; - size_t sessid_len = 0; -#endif - - if (sh == NULL || sh_len == 0 || exts == NULL || echoffset == NULL - || echtype == NULL) - return 0; - *exts = *echoffset = *echtype = 0; - if (!PACKET_buf_init(&pkt, sh, sh_len)) - return 0; - shstart = PACKET_data(&pkt); - if (!PACKET_get_net_2(&pkt, &pi_tmp)) - return 0; - /* if we're not TLSv1.2+ then we can bail, but it's not an error */ - if (pi_tmp != TLS1_2_VERSION) - return 1; - if (!PACKET_get_bytes(&pkt, &pp_tmp, SSL3_RANDOM_SIZE) -#ifdef OSSL_ECH_SUPERVERBOSE - || (sessid_offset = PACKET_data(&pkt) - shstart) == 0 -#endif - || !PACKET_get_1(&pkt, &pi_tmp) /* sessid len */ -#ifdef OSSL_ECH_SUPERVERBOSE - || (sessid_len = (size_t)pi_tmp) == 0 -#endif - || !PACKET_get_bytes(&pkt, &pp_tmp, pi_tmp) /* sessid */ - || !PACKET_get_net_2(&pkt, &pi_tmp) /* ciphersuite */ - || !PACKET_get_1(&pkt, &pi_tmp) /* compression */ - || (*exts = PACKET_data(&pkt) - shstart) == 0 - || !PACKET_get_net_2(&pkt, &pi_tmp)) /* len(extensions) */ - return 0; - extlens = (size_t)pi_tmp; - if (extlens == 0) /* not an error, in theory */ - return 1; - estart = PACKET_data(&pkt); - while (PACKET_remaining(&pkt) > 0 - && (size_t)(PACKET_data(&pkt) - estart) < extlens - && done < 1) { - if (!PACKET_get_net_2(&pkt, &etype) - || !PACKET_get_net_2(&pkt, &elen)) - return 0; - if (etype == TLSEXT_TYPE_ech) { - if (elen == 0) - return 0; - *echoffset = PACKET_data(&pkt) - shstart - 4; - *echtype = etype; -#ifdef OSSL_ECH_SUPERVERBOSE - echlen = elen + 4; /* type and length included */ -#endif - done++; - } - if (!PACKET_get_bytes(&pkt, &pp_tmp, elen)) - return 0; - } -#ifdef OSSL_ECH_SUPERVERBOSE - OSSL_TRACE_BEGIN(TLS) - { - BIO_printf(trc_out, "orig SH/ECH type: %4x\n", *echtype); - } - OSSL_TRACE_END(TLS); - ossl_ech_pbuf("orig SH", (unsigned char *)sh, sh_len); - ossl_ech_pbuf("orig SH session_id", (unsigned char *)sh + sessid_offset, - sessid_len); - ossl_ech_pbuf("orig SH exts", (unsigned char *)sh + *exts, extlens); - ossl_ech_pbuf("orig SH/ECH ", (unsigned char *)sh + *echoffset, echlen); -#endif - return 1; -} - -/* Do a HPKE seal of a padded encoded inner */ -static int seal_encoded_inner(char **out, int *outlen, - unsigned char *ei, size_t eilen, - const char *ch, int chlen, - size_t echoffset, size_t echlen) -{ - int res = 0; - OSSL_HPKE_CTX *hctx = NULL; - unsigned char *mypub = NULL; - static size_t mypublen = 0; - unsigned char *theirpub = NULL; - size_t theirpublen = 0; - unsigned char *ct = NULL; - size_t ctlen = 0; - unsigned char *aad = NULL; - size_t aadlen = 0; - unsigned char *chout = NULL; - size_t choutlen = 0; - - hctx = OSSL_HPKE_CTX_new(OSSL_HPKE_MODE_BASE, hpke_suite, - OSSL_HPKE_ROLE_SENDER, NULL, NULL); - if (!TEST_ptr(hctx)) - goto err; - mypublen = OSSL_HPKE_get_public_encap_size(hpke_suite); - if (!TEST_ptr(mypub = OPENSSL_malloc(mypublen))) - goto err; - theirpub = bin_echconfig + 11; - theirpublen = 0x20; - if (!TEST_true(OSSL_HPKE_encap(hctx, mypub, &mypublen, - theirpub, theirpublen, - hpke_info, hpke_infolen))) - goto err; - /* form up aad which is entire outer CH: zero's instead of ECH ciphertext */ - choutlen = chlen; - if (!TEST_ptr(chout = OPENSSL_malloc(choutlen))) - goto err; - memcpy(chout, ch, chlen); - memcpy(chout + echoffset + 12, mypub, mypublen); - ct = chout + echoffset + 12 + mypublen + 2; - ctlen = OSSL_HPKE_get_ciphertext_size(hpke_suite, eilen); - chout[echoffset + 12 + mypublen] = (ctlen >> 8) & 0xff; - chout[echoffset + 12 + mypublen + 1] = ctlen & 0xff; - /* the 9 skips the record layer header */ - aad = chout + SSL3_RT_HEADER_LENGTH + SSL3_HM_HEADER_LENGTH; - aadlen = chlen - (SSL3_RT_HEADER_LENGTH + SSL3_HM_HEADER_LENGTH); - if (short_test == 0 && ct + ctlen != aad + aadlen) { - TEST_info("length oddity"); - goto err; - } - memset(ct, 0, ctlen); - if (!TEST_true(OSSL_HPKE_seal(hctx, ct, &ctlen, aad, aadlen, ei, eilen))) - goto err; - *out = (char *)chout; - *outlen = (int)choutlen; - res = 1; -err: - OPENSSL_free(mypub); - OSSL_HPKE_CTX_free(hctx); - return res; -} - -/* We'll either corrupt or copy the message based on the test index */ -static int corrupt_or_copy(const char *msg, const int msglen, - char **msgout, int *msgoutlen) -{ - TEST_ECHINNER *ti = NULL; - TEST_SH *ts = NULL; - TEST_ECHOUTER *to = NULL; - int is_ch = 0, is_sh = 0; - unsigned char *encoded_inner = NULL; - size_t prelen, fblen, postlen; - size_t encoded_innerlen = 0; - size_t sessid = 0, exts = 0, extlens = 0, echoffset = 0, echlen = 0; - size_t snioffset = 0, snilen = 0; - uint16_t echtype; - int inner, rv = 0; - - /* is it a ClientHello or not? */ - if (testcase == TESTCASE_CH && msglen > 10 && msg[0] == SSL3_RT_HANDSHAKE - && msg[5] == SSL3_MT_CLIENT_HELLO) - is_ch = 1; - /* is it a ServerHello or not? */ - if (testcase == TESTCASE_SH && msglen > 10 && msg[0] == SSL3_RT_HANDSHAKE - && msg[5] == SSL3_MT_SERVER_HELLO) - is_sh = 1; - if (testcase == TESTCASE_ECH && msglen > 10 && msg[0] == SSL3_RT_HANDSHAKE - && msg[5] == SSL3_MT_CLIENT_HELLO) - is_ch = 1; - - if (testcase == TESTCASE_CH && is_ch == 1) { - if (testiter >= (int)OSSL_NELEM(test_inners)) - return 0; - ti = &test_inners[testiter]; - prelen = ti->pre == NULL ? 0 : ti->prelen; - fblen = ti->forbork == NULL ? 0 : ti->fblen; - postlen = ti->post == NULL ? 0 : ti->postlen; - /* check for editing errors */ - if (testiter != 0 && testiter != 1 - && prelen + fblen + postlen != sizeof(entire_encoded_inner)) { - TEST_info("manual sizing error"); - return 0; - } - if (testiter == 1) /* the only case with a short ciphertext for now */ - short_test = 1; - if (!TEST_true(ossl_ech_helper_get_ch_offsets((const unsigned char *)msg - + SSL3_RT_HEADER_LENGTH - + SSL3_HM_HEADER_LENGTH, - msglen - - SSL3_RT_HEADER_LENGTH - - SSL3_HM_HEADER_LENGTH, - &sessid, &exts, &extlens, - &echoffset, &echtype, &echlen, - &snioffset, &snilen, &inner))) - return 0; - /* that better be an outer ECH :-) */ - if (echoffset > 0 && !TEST_int_eq(inner, 0)) { - TEST_info("better send outer"); - return 0; - } - /* bump offsets by 9 */ - echoffset += 9; - snioffset += 9; - /* - * if it doesn't have an ECH, or if the forbork value in our test - * array is NULL, just copy the entire input to output - */ - if (echoffset == 9 || ti->forbork == NULL) { - if (!TEST_ptr(*msgout = OPENSSL_memdup(msg, msglen))) - return 0; - *msgoutlen = msglen; - return 1; - } - /* in this case, construct the encoded inner, then seal that */ - encoded_innerlen = prelen + fblen + postlen; - if (!TEST_ptr(encoded_inner = OPENSSL_malloc(encoded_innerlen))) - return 0; - if (ti->pre != NULL) /* keep fuzz checker happy */ - memcpy(encoded_inner, ti->pre, prelen); - if (ti->forbork != NULL) - memcpy(encoded_inner + prelen, ti->forbork, fblen); - if (ti->post != NULL) - memcpy(encoded_inner + prelen + fblen, ti->post, postlen); - if (!TEST_true(seal_encoded_inner(msgout, msgoutlen, - encoded_inner, encoded_innerlen, - msg, msglen, echoffset, echlen))) - return 0; - OPENSSL_free(encoded_inner); - return 1; - } - - if (testcase == TESTCASE_ECH && is_ch == 1) { - if (testiter >= (int)OSSL_NELEM(test_echs)) - return 0; - to = &test_echs[testiter]; - if (!TEST_true(ossl_ech_helper_get_ch_offsets((const unsigned char *)msg - + SSL3_RT_HEADER_LENGTH - + SSL3_HM_HEADER_LENGTH, - msglen - - SSL3_RT_HEADER_LENGTH - - SSL3_HM_HEADER_LENGTH, - &sessid, &exts, &extlens, - &echoffset, &echtype, &echlen, - &snioffset, &snilen, &inner))) - return 0; - /* if it doesn't have an ECH just copy the entire input to output */ - if (echoffset == 0) { - if (!TEST_ptr(*msgout = OPENSSL_memdup(msg, msglen))) - return 0; - *msgoutlen = msglen; - return 1; - } - /* check for editing errors, the +4 is for ext type + len */ - if (to->len > (echlen + 4)) { - TEST_info("manual sizing error"); - return 0; - } - if (!TEST_ptr(*msgout = OPENSSL_memdup(msg, msglen))) - return 0; - *msgoutlen = msglen; - /* - * overwrite (some of) the outer ECH, in contrast to - * the above case, here we're overwriting the ECH - * ext type and length as well, the +9 is for record - * layer framing as before - */ - if (to->val != NULL) /* keep fuzz checker happy */ - memcpy(*msgout + echoffset + 9, to->val, to->len); - return 1; - } - - if (testcase == TESTCASE_SH && is_sh == 1) { - if (testiter >= (int)OSSL_NELEM(test_shs)) - return 0; - ts = &test_shs[testiter]; - if (ts->borkage == 0) { - if (!TEST_ptr(*msgout = OPENSSL_memdup(msg, msglen))) - return 0; - *msgoutlen = msglen; - return 1; - } - /* flip bits in ECH confirmation */ - if ((ts->borkage & OSSL_ECH_BORK_FLIP) != 0) { - if (!TEST_ptr(*msgout = OPENSSL_memdup(msg, msglen))) - return 0; - if ((ts->borkage & OSSL_ECH_BORK_HRR) != 0) { - rv = ech_get_sh_offsets((unsigned char *)msg + 9, - msglen - 9, - &exts, &echoffset, - &echtype); - if (!TEST_int_eq(rv, 1)) - return 0; - if (echoffset > 0) { - (*msgout)[9 + echoffset + 4] = (*msgout)[9 + echoffset + 4] ^ 0xaa; - } - } else { - (*msgout)[9 + 2 + SSL3_RANDOM_SIZE - 4] = (*msgout)[9 + 2 + SSL3_RANDOM_SIZE - 4] ^ 0xaa; - } - *msgoutlen = msglen; - return 1; - } - if ((ts->borkage & OSSL_ECH_BORK_REPLACE) != 0 && (ts->borkage & OSSL_ECH_BORK_HRR) != 0) { - if (!TEST_ptr(*msgout = OPENSSL_memdup(msg, msglen))) - return 0; - rv = ech_get_sh_offsets((unsigned char *)msg + 9, - msglen - 9, - &exts, &echoffset, &echtype); - if (!TEST_int_eq(rv, 1)) - return 0; - if (echoffset > 0) - memcpy(&((*msgout)[9 + echoffset]), ts->bork, ts->blen); - *msgoutlen = msglen; - return 1; - } - } - - /* if doing nothing, do that... */ - if (!TEST_ptr(*msgout = OPENSSL_memdup(msg, msglen))) - return 0; - *msgoutlen = msglen; - return 1; -} - -static void copy_flags(BIO *bio) -{ - int flags; - BIO *next = BIO_next(bio); - - flags = BIO_test_flags(next, BIO_FLAGS_SHOULD_RETRY | BIO_FLAGS_RWS); - BIO_clear_flags(bio, BIO_FLAGS_SHOULD_RETRY | BIO_FLAGS_RWS); - BIO_set_flags(bio, flags); -} - -/* - * filter to corrupt or copy messages - this is basically copied - * from the setup in test/sslcorrupttest.c - */ -static int tls_corrupt_write(BIO *bio, const char *in, int inl) -{ - int ret; - BIO *next = BIO_next(bio); - char *copy = NULL; - int copylen = 0; - - ret = corrupt_or_copy(in, inl, ©, ©len); - if (ret == 0) - goto out; - ret = BIO_write(next, copy, inl); - copy_flags(bio); -out: - OPENSSL_free(copy); - return ret; -} - -/* - * This and others below are NOOP filters as we only mess - * with things via the write filter method - */ -static int tls_noop_read(BIO *bio, char *out, int outl) -{ - int ret; - BIO *next = BIO_next(bio); - - ret = BIO_read(next, out, outl); - copy_flags(bio); - - return ret; -} - -static long tls_noop_ctrl(BIO *bio, int cmd, long num, void *ptr) -{ - long ret; - BIO *next = BIO_next(bio); - - if (next == NULL) - return 0; - - switch (cmd) { - case BIO_CTRL_DUP: - ret = 0L; - break; - default: - ret = BIO_ctrl(next, cmd, num, ptr); - break; - } - return ret; -} - -static int tls_noop_gets(BIO *bio, char *buf, int size) -{ - /* We don't support this - not needed anyway */ - return -1; -} - -static int tls_noop_puts(BIO *bio, const char *str) -{ - /* We don't support this - not needed anyway */ - return -1; -} - -static int tls_noop_new(BIO *bio) -{ - BIO_set_init(bio, 1); - - return 1; -} - -static int tls_noop_free(BIO *bio) -{ - BIO_set_init(bio, 0); - - return 1; -} - -#define BIO_TYPE_CUSTOM_CORRUPT (0x80 | BIO_TYPE_FILTER) -#define BIO_TYPE_CUSTOM_SPLIT (0x81 | BIO_TYPE_FILTER) - -static BIO_METHOD *method_tls_corrupt = NULL; - -/* Note: Not thread safe! */ -static const BIO_METHOD *bio_f_tls_corrupt_filter(void) -{ - if (method_tls_corrupt == NULL) { - method_tls_corrupt = BIO_meth_new(BIO_TYPE_CUSTOM_CORRUPT, - "TLS corrupt filter"); - if (method_tls_corrupt == NULL - || !BIO_meth_set_write(method_tls_corrupt, tls_corrupt_write) - || !BIO_meth_set_read(method_tls_corrupt, tls_noop_read) - || !BIO_meth_set_puts(method_tls_corrupt, tls_noop_puts) - || !BIO_meth_set_gets(method_tls_corrupt, tls_noop_gets) - || !BIO_meth_set_ctrl(method_tls_corrupt, tls_noop_ctrl) - || !BIO_meth_set_create(method_tls_corrupt, tls_noop_new) - || !BIO_meth_set_destroy(method_tls_corrupt, tls_noop_free)) - return NULL; - } - return method_tls_corrupt; -} - -static void bio_f_tls_corrupt_filter_free(void) -{ - BIO_meth_free(method_tls_corrupt); -} - -static int test_ch_corrupt(int testidx) -{ - SSL_CTX *sctx = NULL, *cctx = NULL; - SSL *server = NULL, *client = NULL; - BIO *c_to_s_fbio; - int testresult = 0, err = 0, connrv = 0, err_reason = 0; - int exp_err = SSL_ERROR_NONE; - TEST_ECHINNER *ti = NULL; - const char *err_str = NULL; - - testcase = TESTCASE_CH; - testiter = testidx; - ti = &test_inners[testidx]; - if (verbose) - TEST_info("Starting #%d", testidx + 1); - if (!TEST_true(create_ssl_ctx_pair(NULL, TLS_server_method(), - TLS_client_method(), - TLS1_3_VERSION, TLS1_3_VERSION, - &sctx, &cctx, cert, privkey))) - return 0; - /* set server to be willing to only accept TLSv1.2 for test case 23 */ - if (testidx == 22 - && !TEST_true(SSL_CTX_set_max_proto_version(sctx, TLS1_2_VERSION))) - goto end; - /* set server to be willing to accept TLSv1.2 for test case 24 */ - if (testidx == 23 - && !TEST_true(SSL_CTX_set_min_proto_version(sctx, TLS1_2_VERSION))) - goto end; - /* set client/server to be willing to accept TLSv1.2 for test case 25 */ - if (testidx == 24 - && !TEST_true(SSL_CTX_set_min_proto_version(sctx, TLS1_2_VERSION)) - && !TEST_true(SSL_CTX_set_min_proto_version(cctx, TLS1_2_VERSION))) - goto end; - if (!TEST_true(SSL_CTX_set1_echstore(sctx, es))) - goto end; - if (!TEST_ptr(c_to_s_fbio = BIO_new(bio_f_tls_corrupt_filter()))) - goto end; - /* BIO is freed by create_ssl_connection on error */ - if (!TEST_true(create_ssl_objects(sctx, cctx, &server, &client, NULL, - c_to_s_fbio))) - goto end; - if (!TEST_true(SSL_set1_ech_config_list(client, (unsigned char *)echconfig, - echconfiglen))) - goto end; - if (!TEST_true(SSL_set_tlsext_host_name(client, "foo.example.com"))) - goto end; - exp_err = SSL_ERROR_SSL; - if (ti->err_expected == 0) - exp_err = SSL_ERROR_NONE; - connrv = create_ssl_connection(server, client, exp_err); - if (!TEST_int_eq(connrv, ti->rv_expected)) - goto end; - if (verbose) { - err_str = ERR_reason_error_string(ti->err_expected); - err_reason = ERR_GET_REASON(ti->err_expected); - TEST_info("Expected error: %d/%s", err_reason, err_str); - } - if (connrv == 0) { - do { - err = ERR_get_error(); - if (err == 0) { - TEST_error("ECH corruption: Unexpected error"); - goto end; - } - err_reason = ERR_GET_REASON(err); - err_str = ERR_reason_error_string(err); - if (verbose) - TEST_info("Error reason: %d/%s", err_reason, err_str); - } while (err_reason != ti->err_expected); - } - testresult = 1; -end: - SSL_free(server); - SSL_free(client); - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - return testresult; -} - -static int test_sh_corrupt(int testidx) -{ - SSL_CTX *sctx = NULL, *cctx = NULL; - SSL *server = NULL, *client = NULL; - BIO *s_to_c_fbio; - TEST_SH *ts = NULL; - int testresult = 0, err = 0, connrv = 0, err_reason = 0; - int exp_err = SSL_ERROR_NONE; - unsigned char *retryconfig = NULL; - size_t retryconfiglen = 0; - const char *err_str = NULL; - - testcase = TESTCASE_SH; - testiter = testidx; - ts = &test_shs[testidx]; - if (verbose) - TEST_info("Starting #%d", testidx + 1); - if (!TEST_true(create_ssl_ctx_pair(NULL, TLS_server_method(), - TLS_client_method(), - TLS1_3_VERSION, TLS1_3_VERSION, - &sctx, &cctx, cert, privkey))) - return 0; - if (!TEST_true(SSL_CTX_set1_echstore(sctx, es))) - goto end; - if (!TEST_ptr(s_to_c_fbio = BIO_new(bio_f_tls_corrupt_filter()))) - goto end; - /* BIO is freed by create_ssl_connection on error */ - if (!TEST_true(create_ssl_objects(sctx, cctx, &server, &client, - s_to_c_fbio, NULL))) - goto end; - if ((ts->borkage & OSSL_ECH_BORK_GREASE) != 0) { - if (!TEST_true(SSL_set_options(client, SSL_OP_ECH_GREASE))) - goto end; - } else { - if (!TEST_true(SSL_set1_ech_config_list(client, - (unsigned char *)echconfig, - echconfiglen))) - goto end; - } - if (!TEST_true(SSL_set_tlsext_host_name(client, "foo.example.com"))) - goto end; - if ((ts->borkage & OSSL_ECH_BORK_HRR) != 0 - && !TEST_true(SSL_set1_groups_list(server, "P-384"))) - goto end; - exp_err = SSL_ERROR_SSL; - if (ts->err_expected == 0) - exp_err = SSL_ERROR_NONE; - connrv = create_ssl_connection(server, client, exp_err); - if (!TEST_int_eq(connrv, ts->rv_expected)) - goto end; - if (connrv == 1 && (ts->borkage & OSSL_ECH_BORK_GREASE) != 0) { - if (!TEST_true(SSL_ech_get1_retry_config(client, &retryconfig, - &retryconfiglen)) - || !TEST_ptr(retryconfig) - || !TEST_int_ne((int)retryconfiglen, 0)) - goto end; - } - if (verbose) { - err_str = ERR_reason_error_string(ts->err_expected); - err_reason = ERR_GET_REASON(ts->err_expected); - TEST_info("Expected error: %d/%s", err_reason, err_str); - } - if (connrv == 0) { - do { - err = ERR_get_error(); - if (err == 0) { - TEST_error("ECH corruption: Unexpected error"); - goto end; - } - err_reason = ERR_GET_REASON(err); - err_str = ERR_reason_error_string(err); - if (verbose) - TEST_info("Error reason: %d/%s", err_reason, err_str); - } while (err_reason != ts->err_expected); - } - testresult = 1; -end: - OPENSSL_free(retryconfig); - SSL_free(server); - SSL_free(client); - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - return testresult; -} - -typedef enum OPTION_choice { - OPT_ERR = -1, - OPT_EOF = 0, - OPT_VERBOSE, - OPT_TEST_ENUM -} OPTION_CHOICE; - -static int test_ech_corrupt(int testidx) -{ - SSL_CTX *sctx = NULL, *cctx = NULL; - SSL *server = NULL, *client = NULL; - BIO *c_to_s_fbio; - int testresult = 0, err = 0, connrv = 0, err_reason = 0; - int exp_err = SSL_ERROR_NONE; - TEST_ECHOUTER *to = NULL; - const char *err_str = NULL; - - testcase = TESTCASE_ECH; - testiter = testidx; - to = &test_echs[testidx]; - if (verbose) - TEST_info("Starting #%d", testidx + 1); - if (!TEST_true(create_ssl_ctx_pair(NULL, TLS_server_method(), - TLS_client_method(), - TLS1_3_VERSION, TLS1_3_VERSION, - &sctx, &cctx, cert, privkey))) - return 0; - if (!TEST_true(SSL_CTX_set1_echstore(sctx, es))) - goto end; - if (!TEST_ptr(c_to_s_fbio = BIO_new(bio_f_tls_corrupt_filter()))) - goto end; - /* BIO is freed by create_ssl_connection on error */ - if (!TEST_true(create_ssl_objects(sctx, cctx, &server, &client, NULL, - c_to_s_fbio))) - goto end; - if (!TEST_true(SSL_set1_ech_config_list(client, (unsigned char *)echconfig, - echconfiglen))) - goto end; - if (!TEST_true(SSL_set_tlsext_host_name(client, "foo.example.com"))) - goto end; - exp_err = SSL_ERROR_SSL; - if (to->err_expected == 0) - exp_err = SSL_ERROR_NONE; - connrv = create_ssl_connection(server, client, exp_err); - if (!TEST_int_eq(connrv, to->rv_expected)) - goto end; - if (verbose) { - err_str = ERR_reason_error_string(to->err_expected); - err_reason = ERR_GET_REASON(to->err_expected); - TEST_info("Expected error: %d/%s", err_reason, err_str); - } - if (connrv == 0) { - do { - err = ERR_get_error(); - if (err == 0) { - TEST_error("ECH corruption: Unexpected error"); - goto end; - } - err_reason = ERR_GET_REASON(err); - err_str = ERR_reason_error_string(err); - if (verbose) - TEST_info("Error reason: %d/%s", err_reason, err_str); - } while (err_reason != to->err_expected); - } - testresult = 1; -end: - SSL_free(server); - SSL_free(client); - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - return testresult; -} - -/* - * Callback that corrupts a server Finished message. - * This doesn't seem to be documented, but the buffer here is the actual - * message and not a copy just for the callback, so we can corrupt it by - * flipping bits in the last octet of the server Finished. Presumably changing - * lengths would cause other breakage, but the below currently causes the - * `memcmp()` to fail in the client's call of `tls_process_finished()` which - * produces the desired effect of causing the TLS session to fail both because - * of ECH-required and subsequently because of a later handshake failure - * resulting in us not making the retry-configs available to the client. - */ -static void corrupt_server_finished(int write_p, int version, int content_type, - const void *buf, size_t msglen, SSL *ssl, void *arg) -{ - unsigned char *msg = (unsigned char *)buf; - - if (write_p == 0 && content_type == SSL3_RT_HANDSHAKE - && msg[0] == SSL3_MT_FINISHED) - msg[msglen - 1] ^= 0xAA; -} - -/* - * Test roundtrip with wrong ECHConfig, with and without corrupting - * the server Finished to check that retry-configs are not made - * available to the client in the latter case. - */ -static int ech_retry_config_test(int idx) -{ - int res = 0, clientstatus, serverstatus; - SSL_CTX *cctx = NULL, *sctx = NULL; - SSL *clientssl = NULL, *serverssl = NULL; - char *cinner = NULL, *couter = NULL, *sinner = NULL, *souter = NULL; - unsigned char *retryconfig = NULL; - size_t retryconfiglen = 0; - int err = 0, err_reason = 0, exp_err = ERR_R_OSSL_STORE_LIB; - const char *err_str = NULL; - - if (!TEST_true(create_ssl_ctx_pair(libctx, TLS_server_method(), - TLS_client_method(), - TLS1_3_VERSION, TLS1_3_VERSION, - &sctx, &cctx, cert, privkey))) - goto end; - if (!TEST_true(SSL_CTX_set1_echstore(sctx, es))) - goto end; - if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, - &clientssl, NULL, NULL))) - goto end; - if (!TEST_true(SSL_set_tlsext_host_name(clientssl, "foo.example.com"))) - goto end; - /* set a real but wrong ECHConfig */ - if (!TEST_true(SSL_set1_ech_config_list(clientssl, (unsigned char *)ec_kp2, - ec_kp2len))) - goto end; - if (idx == 1) /* corrupt as desired */ - SSL_set_msg_callback(clientssl, corrupt_server_finished); - /* real but wrong => failure, due to ECH */ - if (!TEST_false(create_ssl_connection(serverssl, clientssl, - SSL_R_ECH_REQUIRED))) - goto end; - serverstatus = SSL_ech_get1_status(serverssl, &sinner, &souter); - if (verbose) - TEST_info("ech_retry_config_test: server status %d, %s, %s", - serverstatus, sinner, souter); - if (!TEST_int_eq(serverstatus, SSL_ECH_STATUS_GREASE)) - goto end; - /* override cert verification */ - SSL_set_verify_result(clientssl, X509_V_OK); - clientstatus = SSL_ech_get1_status(clientssl, &cinner, &couter); - if (verbose) - TEST_info("ech_retry_config_test: client status %d, %s, %s", - clientstatus, cinner, couter); - if (!TEST_int_eq(clientstatus, SSL_ECH_STATUS_FAILED_ECH)) - goto end; - if (idx == 0) { /* no corruption, retry-configs made available */ - if (!TEST_true(SSL_ech_get1_retry_config(clientssl, &retryconfig, - &retryconfiglen))) - goto end; - if (!TEST_ptr(retryconfig)) - goto end; - if (!TEST_int_ne((int)retryconfiglen, 0)) - goto end; - if (verbose) - TEST_info("ech_retry_config_test: retryconfglen: %zu\n", retryconfiglen); - /* we kow the size to expect as the configs are hard-coded above */ - if (!TEST_size_t_eq(retryconfiglen, 64)) - goto end; - } else { /* corruption, retry-configs NOT made available */ - if (!TEST_false(SSL_ech_get1_retry_config(clientssl, &retryconfig, - &retryconfiglen))) - goto end; - /* check we got the specific error expected */ - err_str = ERR_reason_error_string(exp_err); - err_reason = ERR_GET_REASON(exp_err); - TEST_info("ech_retry_config_test Expected error: %d/%s", - err_reason, err_str); - do { - err = ERR_get_error(); - if (err == 0) { - TEST_error("ech_retry_config_test: Unexpected error"); - goto end; - } - err_reason = ERR_GET_REASON(err); - err_str = ERR_reason_error_string(err); - if (verbose) - TEST_info("ech_retry_config_test Actual error: %d/%s", - err_reason, err_str); - } while (err_reason != exp_err); - if (verbose) - TEST_info("ech_retry_config_test: retry configs withheld\n"); - } - res = 1; -end: - OPENSSL_free(sinner); - OPENSSL_free(souter); - OPENSSL_free(cinner); - OPENSSL_free(couter); - OPENSSL_free(retryconfig); - SSL_free(clientssl); - SSL_free(serverssl); - SSL_CTX_free(cctx); - SSL_CTX_free(sctx); - return res; -} - -const OPTIONS *test_get_options(void) -{ - static const OPTIONS test_options[] = { - OPT_TEST_OPTIONS_DEFAULT_USAGE, - { "v", OPT_VERBOSE, '-', "Enable verbose mode" }, - { OPT_HELP_STR, 1, '-', "Run ECH Corruption tests\n" }, - { NULL } - }; - return test_options; -} - -int setup_tests(void) -{ - OPTION_CHOICE o; - BIO *in = NULL; - - while ((o = opt_next()) != OPT_EOF) { - switch (o) { - case OPT_VERBOSE: - verbose = 1; - break; - case OPT_TEST_CASES: - break; - default: - return 0; - } - } - if (!test_skip_common_options()) { - TEST_error("Error parsing test options\n"); - return 0; - } - certsdir = test_get_argument(0); - if (certsdir == NULL) - certsdir = DEF_CERTS_DIR; - cert = test_mk_file_path(certsdir, "servercert.pem"); - if (cert == NULL) - goto err; - privkey = test_mk_file_path(certsdir, "serverkey.pem"); - if (privkey == NULL) - goto err; - - /* make an OSSL_ECHSTORE for pem_kp1 */ - if ((in = BIO_new(BIO_s_mem())) == NULL - || BIO_write(in, pem_kp1, (int)strlen(pem_kp1)) <= 0 - || !TEST_ptr(es = OSSL_ECHSTORE_new(libctx, propq)) - || !TEST_true(OSSL_ECHSTORE_read_pem(es, in, OSSL_ECH_FOR_RETRY))) - goto err; - BIO_free_all(in); - in = NULL; - hpke_infolen = bin_echconfiglen + 200; - if (!TEST_ptr(hpke_info = OPENSSL_malloc(hpke_infolen))) - goto err; - /* +/- 2 is to drop the ECHConfigList length at the start */ - if (!TEST_true(ossl_ech_make_enc_info((unsigned char *)bin_echconfig + 2, - bin_echconfiglen - 2, - hpke_info, &hpke_infolen))) - goto err; - ADD_ALL_TESTS(test_ch_corrupt, OSSL_NELEM(test_inners)); - ADD_ALL_TESTS(test_sh_corrupt, OSSL_NELEM(test_shs)); - ADD_ALL_TESTS(test_ech_corrupt, OSSL_NELEM(test_echs)); -#ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION - ADD_ALL_TESTS(ech_retry_config_test, 2); -#else - /* - * It seems fuzz tests cause our corruption to not work so we'll skip doing - * that. There's an ifdef'd code fragment in `tls_process_finished()` for - * when fuzzing that I guess causes that, but it's ok that we only do the - * corruption test when not fuzzing. We still do the (first) non-corrupt - * test to avoid a warning that `ech_retry_config_test()` isn't called. - */ - ADD_ALL_TESTS(ech_retry_config_test, 1); -#endif - return 1; -err: - BIO_free_all(in); - return 0; -} - -void cleanup_tests(void) -{ - bio_f_tls_corrupt_filter_free(); - OPENSSL_free(cert); - OPENSSL_free(privkey); - OPENSSL_free(hpke_info); - OSSL_ECHSTORE_free(es); -} diff --git a/test/ech_test.c b/test/ech_test.c deleted file mode 100644 index b383b4255a..0000000000 --- a/test/ech_test.c +++ /dev/null @@ -1,2091 +0,0 @@ -/* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include -#include "testutil.h" -#include "helpers/ssltestlib.h" -#include "internal/packet.h" - -#ifndef OPENSSL_NO_ECH - -#define DEF_CERTS_DIR "test/certs" - -static OSSL_LIB_CTX *libctx = NULL; -static char *propq = NULL; -static int verbose = 0; -static char *certsdir = NULL; -static char *cert = NULL; -static char *privkey = NULL; -static char *rootcert = NULL; -static int ch_test_cb_ok = 0; - -/* ECH callback */ -static unsigned int ech_test_cb(SSL *s, const char *str) -{ - if (verbose) - TEST_info("ech_test_cb called: str=\n%s", str); - return 1; -} - -/* ClientHello callback */ -static int ch_test_cb(SSL *ssl, int *al, void *arg) -{ - char *servername = NULL; - const unsigned char *pos; - size_t remaining; - unsigned int servname_type; - PACKET pkt, sni, hostname; - - if (verbose) { - TEST_info("ch_test_cb called"); - if (SSL_client_hello_get0_ext(ssl, TLSEXT_TYPE_ech, &pos, &remaining)) { - TEST_info("there is an ECH extension"); - } else { - TEST_info("there is NO ECH extension"); - } - } - if (!SSL_client_hello_get0_ext(ssl, TLSEXT_TYPE_server_name, &pos, - &remaining) - || remaining <= 2) - goto give_up; - if (!PACKET_buf_init(&pkt, pos, remaining) - || !PACKET_as_length_prefixed_2(&pkt, &sni) - || !PACKET_get_1(&sni, &servname_type) - || servname_type != TLSEXT_NAMETYPE_host_name - || !PACKET_as_length_prefixed_2(&sni, &hostname) - || (PACKET_remaining(&hostname) > TLSEXT_MAXLEN_host_name) - || PACKET_contains_zero_byte(&hostname) - || !PACKET_strndup(&hostname, &servername)) - goto give_up; - if (verbose) - TEST_info("servername: %s", servername); - OPENSSL_free(servername); - /* signal to caller all is good */ - ch_test_cb_ok = 1; - return 1; -give_up: - return 0; -} - -/* - * The define/vars below and the 3 callback functions are modified - * from test/sslapitest.c - */ -#define TEST_EXT_TYPE1 0xffab /* custom ext type 1: has 1 octet payload */ -#define TEST_EXT_TYPE2 0xffcd /* custom ext type 2: no payload */ - -/* A well-encoded ECH extension value */ -static const unsigned char encoded_ech_val[] = { - 0x00, 0x00, 0x01, 0x00, 0x01, 0xf7, 0x00, 0x20, - 0xc9, 0x2c, 0x12, 0xc9, 0xc0, 0x4d, 0x11, 0x5d, - 0x09, 0xe1, 0xeb, 0x7a, 0x18, 0xb2, 0x83, 0x28, - 0x35, 0x00, 0x3c, 0x8d, 0x78, 0x09, 0xfd, 0x09, - 0x84, 0xca, 0x94, 0x77, 0xcf, 0x78, 0xd0, 0x04, - 0x00, 0x90, 0x5e, 0xc7, 0xc0, 0x62, 0x84, 0x8d, - 0x4b, 0x85, 0xd5, 0x6a, 0x9a, 0xc1, 0xc6, 0xc2, - 0x28, 0xac, 0x87, 0xb9, 0x2f, 0x36, 0xa0, 0xf7, - 0x5f, 0xd0, 0x23, 0x7b, 0xf4, 0xc1, 0x62, 0x1c, - 0xf1, 0x91, 0xfd, 0x46, 0x35, 0x41, 0xc9, 0x06, - 0xd3, 0x19, 0xd6, 0x34, 0x01, 0xc3, 0xb3, 0x66, - 0x4e, 0x7a, 0x28, 0xac, 0xd4, 0xd2, 0x35, 0x2b, - 0xd0, 0xc6, 0x94, 0x34, 0xc1, 0x94, 0x62, 0x77, - 0x1b, 0x5a, 0x02, 0x3c, 0xdd, 0xa2, 0x4d, 0x33, - 0xa5, 0xd0, 0x59, 0x12, 0xf5, 0x17, 0x03, 0xe5, - 0xab, 0xbd, 0x83, 0x52, 0x40, 0x6c, 0x99, 0xac, - 0x25, 0x07, 0x63, 0x8c, 0x16, 0x5d, 0x93, 0x34, - 0x56, 0x34, 0x60, 0x86, 0x25, 0xa7, 0x0d, 0xac, - 0xb8, 0x5e, 0x87, 0xc6, 0xf7, 0x23, 0xaf, 0xf8, - 0x3e, 0x2a, 0x46, 0x75, 0xa9, 0x5f, 0xaf, 0xd2, - 0x91, 0xe6, 0x44, 0xcb, 0xe7, 0xe0, 0x85, 0x36, - 0x9d, 0xd2, 0xaf, 0xae, 0xb3, 0x0f, 0x70, 0x6a, - 0xaf, 0x42, 0xc0, 0xb3, 0xe4, 0x65, 0x53, 0x01, - 0x75, 0xbf -}; - -static int new_add_cb(SSL *s, unsigned int ext_type, unsigned int context, - const unsigned char **out, size_t *outlen, X509 *x, - size_t chainidx, int *al, void *add_arg) -{ - int *server = (int *)add_arg; - unsigned char *data; - - if (*server != SSL_is_server(s)) - return -1; - if (ext_type == TEST_EXT_TYPE1) { - if ((data = OPENSSL_malloc(sizeof(*data))) == NULL) - return -1; - *data = 1; - *out = data; - *outlen = sizeof(*data); - } else if (ext_type == OSSL_ECH_CURRENT_VERSION) { - /* inject a sample ECH extension value into the CH */ - if ((data = OPENSSL_memdup(encoded_ech_val, - sizeof(encoded_ech_val))) - == NULL) - return -1; - *out = data; - *outlen = sizeof(encoded_ech_val); - } else { - /* inject a TEST_EXT_TYPE2, with a zero-length payload */ - *out = NULL; - *outlen = 0; - } - return 1; -} - -static void new_free_cb(SSL *s, unsigned int ext_type, unsigned int context, - const unsigned char *out, void *add_arg) -{ - OPENSSL_free((unsigned char *)out); -} - -static int new_parse_cb(SSL *s, unsigned int ext_type, unsigned int context, - const unsigned char *in, size_t inlen, X509 *x, - size_t chainidx, int *al, void *parse_arg) -{ - int *server = (int *)parse_arg; - - if (*server != SSL_is_server(s) - || inlen != sizeof(char) || *in != 1) - return -1; - return 1; -} - -/* general test vector values */ - -/* standard x25519 ech key pair with public key example.com */ -static const char pem_kp1[] = "-----BEGIN PRIVATE KEY-----\n" - "MC4CAQAwBQYDK2VuBCIEILDIeo9Eqc4K9/uQ0PNAyMaP60qrxiSHT2tNZL3ksIZS\n" - "-----END PRIVATE KEY-----\n" - "-----BEGIN ECHCONFIG-----\n" - "AD7+DQA6bAAgACCY7B0f/3KvHIFdoqFaObdU8YYU+MdBf4vzbLhAAL2QCwAEAAEA\n" - "AQALZXhhbXBsZS5jb20AAA==\n" - "-----END ECHCONFIG-----\n"; -static const char ec_kp1[] = "AD7+DQA6bAAgACCY7B0f/3KvHIFdoqFaObdU8YYU+MdBf4vzbLhAAL2QCwAEAAEAAQALZXhhbXBsZS5jb20AAA=="; -static size_t ec_kp1len = sizeof(ec_kp1) - 1; - -/* - * x25519 ech key pair with public key front.server.example, used for - * in_out test - */ -static const char pem_kp2[] = "-----BEGIN PRIVATE KEY-----\n" - "MC4CAQAwBQYDK2VuBCIEIEjRn9R/gwDu11v6bLKaf0AGoe5Etl2g6nU1GdQLTHNe\n" - "-----END PRIVATE KEY-----\n" - "-----BEGIN ECHCONFIG-----\n" - "AEf+DQBDvQAgACCr9pErR7E/gNeoni+0YpDZaMd7XN+hFnCN+H0Xnm1EHQAEAAEAAQAUZnJvbnQuc2VydmVyLmV4YW1wbGUAAA==\n" - "-----END ECHCONFIG-----\n"; -static const char ec_kp2[] = "AEf+DQBDvQAgACCr9pErR7E/gNeoni+0YpDZaMd7XN+hFnCN+H0Xnm1EHQAEAAEAAQAUZnJvbnQuc2VydmVyLmV4YW1wbGUAAA=="; -static size_t ec_kp2len = sizeof(ec_kp2) - 1; - -/* another, used in grease/retry-config tests, pn: f1.server.example */ -static const char pem_kp3[] = "-----BEGIN PRIVATE KEY-----\n" - "MC4CAQAwBQYDK2VuBCIEIDDbFFGbdUUQgKJzx6zaqn0rE8Bi9DJQpkfbAL6HHwtu\n" - "-----END PRIVATE KEY-----\n" - "-----BEGIN ECHCONFIG-----\n" - "AET+DQBAYQAgACAUpnXhRlufbhe61F02+NR7xVA3200ujwOp2JLivunoQAAEAAEA\n" - "AQARZjEuc2VydmVyLmV4YW1wbGUAAA==\n" - "-----END ECHCONFIG-----\n"; - -/* standard x25519 ECHConfigList with public key example.com */ -static const char pem_pk1[] = "-----BEGIN ECHCONFIG-----\n" - "AD7+DQA6bAAgACCY7B0f/3KvHIFdoqFaObdU8YYU+MdBf4vzbLhAAL2QCwAEAAEA\n" - "AQALZXhhbXBsZS5jb20AAA==\n" - "-----END ECHCONFIG-----\n"; - -/* an ECDSA private with an x25519 ech public key example.com */ -static const char pem_mismatch_priv[] = "-----BEGIN EC PRIVATE KEY-----\n" - "MHcCAQEEIGKONznbHOMEKT4AKMufc37O9lUEBHO+Nb6ztkXhGXLcoAoGCCqGSM49\n" - "AwEHoUQDQgAEYDznfezvj5ufhQsZOQvSdiNpYKCd8tRI1aI3gc4y7gmdDUKpwzHa\n" - "VS4Qq0xyeG6fDMJv668UCotQANFsifGirQ==\n" - "-----END EC PRIVATE KEY-----\n" - "-----BEGIN ECHCONFIG-----\n" - "AD7+DQA6bAAgACCY7B0f/3KvHIFdoqFaObdU8YYU+MdBf4vzbLhAAL2QCwAEAAEA\n" - "AQALZXhhbXBsZS5jb20AAA==\n" - "-----END ECHCONFIG-----\n"; - -/* - * This ECHConfigList has 4 entries with different versions, - * from drafts: 13,10,13,9 - since our runtime no longer supports - * version 9 or 10, we should see 2 configs loaded. - */ -static const char pem_4_to_2[] = "-----BEGIN ECHCONFIG-----\n" - "APv+DQA6xQAgACBm54KSIPXu+pQq2oY183wt3ybx7CKbBYX0ogPq5u6FegAEAAEA\n" - "AQALZXhhbXBsZS5jb20AAP4KADzSACAAIIP+0Qt0WGBF3H5fz8HuhVRTCEMuHS4K\n" - "hu6ibR/6qER4AAQAAQABAAAAC2V4YW1wbGUuY29tAAD+DQA6QwAgACB3xsNUtSgi\n" - "piYpUkW6OSrrg03I4zIENMFa0JR2+Mm1WwAEAAEAAQALZXhhbXBsZS5jb20AAP4J\n" - "ADsAC2V4YW1wbGUuY29tACCjJCv5w/yaHjbOc6nVuM/GksIGLgDR+222vww9dEk8\n" - "FwAgAAQAAQABAAAAAA==\n" - "-----END ECHCONFIG-----\n"; - -/* mis-spelled PEM string */ -static const char pem_typo[] = "-----BEGIN PRIVATE KEY-----\n" - "MC4CAQAwBQYDK2VuBCIEILDIeo9Eqc4K9/uQ0PNAyMaP60qrxiSHT2tNZL3ksIZS\n" - "-----END PRIVATE KEY-----\n" - "-----BEGIN ExHCOxFIG-----\n" - "AD7+DQA6bAAgACCY7B0f/3KvHIFdoqFaObdU8YYU+MdBf4vzbLhAAL2QCwAEAAEA\n" - "AQALZXhhbXBsZS5jb20AAA==\n" - "-----END ExHCOxFIG-----\n"; - -/* single-line base64(ECHConfigList) form of pem_pk1 */ -static const char b64_pk1[] = "AD7+DQA6bAAgACCY7B0f/3KvHIFdoqFaObdU8YYU+MdBf4vzbLhAAL2QCwAEAAEA" - "AQALZXhhbXBsZS5jb20AAA=="; - -/* single-line base64(ECHConfigList) form of pem_6_to3 */ -static const char b64_6_to_3[] = "AXn+DQA6xQAgACBm54KSIPXu+pQq2oY183wt3ybx7CKbBYX0ogPq5u6FegAEAAE" - "AAQALZXhhbXBsZS5jb20AAP4KADzSACAAIIP+0Qt0WGBF3H5fz8HuhVRTCEMuHS" - "4Khu6ibR/6qER4AAQAAQABAAAAC2V4YW1wbGUuY29tAAD+CQA7AAtleGFtcGxlL" - "mNvbQAgoyQr+cP8mh42znOp1bjPxpLCBi4A0ftttr8MPXRJPBcAIAAEAAEAAQAA" - "AAD+DQA6QwAgACB3xsNUtSgipiYpUkW6OSrrg03I4zIENMFa0JR2+Mm1WwAEAAE" - "AAQALZXhhbXBsZS5jb20AAP4KADwDACAAIH0BoAdiJCX88gv8nYpGVX5BpGBa9y" - "T0Pac3Kwx6i8URAAQAAQABAAAAC2V4YW1wbGUuY29tAAD+DQA6QwAgACDcZIAx7" - "OcOiQuk90VV7/DO4lFQr5I3Zw9tVbK8MGw1dgAEAAEAAQALZXhhbXBsZS5jb20A" - "AA=="; - -/* same as above but binary encoded */ -static const unsigned char bin_6_to_3[] = { - 0x01, 0x79, 0xfe, 0x0d, 0x00, 0x3a, 0xc5, 0x00, - 0x20, 0x00, 0x20, 0x66, 0xe7, 0x82, 0x92, 0x20, - 0xf5, 0xee, 0xfa, 0x94, 0x2a, 0xda, 0x86, 0x35, - 0xf3, 0x7c, 0x2d, 0xdf, 0x26, 0xf1, 0xec, 0x22, - 0x9b, 0x05, 0x85, 0xf4, 0xa2, 0x03, 0xea, 0xe6, - 0xee, 0x85, 0x7a, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00, - 0xfe, 0x0a, 0x00, 0x3c, 0xd2, 0x00, 0x20, 0x00, - 0x20, 0x83, 0xfe, 0xd1, 0x0b, 0x74, 0x58, 0x60, - 0x45, 0xdc, 0x7e, 0x5f, 0xcf, 0xc1, 0xee, 0x85, - 0x54, 0x53, 0x08, 0x43, 0x2e, 0x1d, 0x2e, 0x0a, - 0x86, 0xee, 0xa2, 0x6d, 0x1f, 0xfa, 0xa8, 0x44, - 0x78, 0x00, 0x04, 0x00, 0x01, 0x00, 0x01, 0x00, - 0x00, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00, - 0xfe, 0x09, 0x00, 0x3b, 0x00, 0x0b, 0x65, 0x78, - 0x61, 0x6d, 0x70, 0x6c, 0x65, 0x2e, 0x63, 0x6f, - 0x6d, 0x00, 0x20, 0xa3, 0x24, 0x2b, 0xf9, 0xc3, - 0xfc, 0x9a, 0x1e, 0x36, 0xce, 0x73, 0xa9, 0xd5, - 0xb8, 0xcf, 0xc6, 0x92, 0xc2, 0x06, 0x2e, 0x00, - 0xd1, 0xfb, 0x6d, 0xb6, 0xbf, 0x0c, 0x3d, 0x74, - 0x49, 0x3c, 0x17, 0x00, 0x20, 0x00, 0x04, 0x00, - 0x01, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00, 0xfe, - 0x0d, 0x00, 0x3a, 0x43, 0x00, 0x20, 0x00, 0x20, - 0x77, 0xc6, 0xc3, 0x54, 0xb5, 0x28, 0x22, 0xa6, - 0x26, 0x29, 0x52, 0x45, 0xba, 0x39, 0x2a, 0xeb, - 0x83, 0x4d, 0xc8, 0xe3, 0x32, 0x04, 0x34, 0xc1, - 0x5a, 0xd0, 0x94, 0x76, 0xf8, 0xc9, 0xb5, 0x5b, - 0x00, 0x04, 0x00, 0x01, 0x00, 0x01, 0x00, 0x0b, - 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, 0x2e, - 0x63, 0x6f, 0x6d, 0x00, 0x00, 0xfe, 0x0a, 0x00, - 0x3c, 0x03, 0x00, 0x20, 0x00, 0x20, 0x7d, 0x01, - 0xa0, 0x07, 0x62, 0x24, 0x25, 0xfc, 0xf2, 0x0b, - 0xfc, 0x9d, 0x8a, 0x46, 0x55, 0x7e, 0x41, 0xa4, - 0x60, 0x5a, 0xf7, 0x24, 0xf4, 0x3d, 0xa7, 0x37, - 0x2b, 0x0c, 0x7a, 0x8b, 0xc5, 0x11, 0x00, 0x04, - 0x00, 0x01, 0x00, 0x01, 0x00, 0x00, 0x00, 0x0b, - 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, 0x2e, - 0x63, 0x6f, 0x6d, 0x00, 0x00, 0xfe, 0x0d, 0x00, - 0x3a, 0x43, 0x00, 0x20, 0x00, 0x20, 0xdc, 0x64, - 0x80, 0x31, 0xec, 0xe7, 0x0e, 0x89, 0x0b, 0xa4, - 0xf7, 0x45, 0x55, 0xef, 0xf0, 0xce, 0xe2, 0x51, - 0x50, 0xaf, 0x92, 0x37, 0x67, 0x0f, 0x6d, 0x55, - 0xb2, 0xbc, 0x30, 0x6c, 0x35, 0x76, 0x00, 0x04, - 0x00, 0x01, 0x00, 0x01, 0x00, 0x0b, 0x65, 0x78, - 0x61, 0x6d, 0x70, 0x6c, 0x65, 0x2e, 0x63, 0x6f, - 0x6d, 0x00, 0x00 -}; - -/* base64(ECHConfigList) with corrupt ciphersuite length and public_name */ -static const char b64_bad_cs[] = "AD7+DQA6uAAgACAogff+HZbirYdQCfXI01GBPP8AEKYyK/D/0DoeXD84fgAQAAE" - "AAQgLZXhhbUNwbGUuYwYAAAAAQwA="; - -/* An ECHConfigList with one ECHConfig but of the wrong version */ -static const unsigned char bin_bad_ver[] = { - 0x00, 0x3e, 0xfe, 0xff, 0x00, 0x3a, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; - -/* - * An ECHConflgList with 2 ECHConfig values that are both - * of the wrong version. The versions here are 0xfe03 (we - * currently support only 0xfe0d) - */ -static const unsigned char bin_bad_ver2[] = { - 0x00, 0x80, 0xfe, 0x03, 0x00, 0x3c, 0x00, 0x00, - 0x20, 0x00, 0x20, 0x71, 0xa5, 0xe0, 0xb4, 0x6d, - 0xdf, 0xa4, 0xda, 0xed, 0x69, 0xa5, 0xc7, 0x8b, - 0x9d, 0xa5, 0x13, 0x0c, 0x36, 0x83, 0x7a, 0x03, - 0x72, 0x1d, 0xf6, 0x1e, 0xc5, 0x83, 0x1a, 0x11, - 0x73, 0xce, 0x2d, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0d, 0x70, 0x61, 0x72, 0x74, 0x31, - 0x2e, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, - 0x00, 0x00, 0xfe, 0x03, 0x00, 0x3c, 0x00, 0x00, - 0x20, 0x00, 0x20, 0x69, 0x88, 0xfd, 0x8f, 0xc9, - 0x0b, 0xb7, 0x2d, 0x96, 0x6d, 0xe0, 0x22, 0xf0, - 0xc8, 0x1b, 0x62, 0x2b, 0x1c, 0x94, 0x96, 0xad, - 0xef, 0x55, 0xdb, 0x9f, 0xeb, 0x0d, 0xa1, 0x4b, - 0x0c, 0xd7, 0x36, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0d, 0x70, 0x61, 0x72, 0x74, 0x32, - 0x2e, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, - 0x00, 0x00 -}; - -/* - * An ECHConfigList with one ECHConfig with an all-zero public value. - * That should be ok, for 25519, but hey, just in case:-) - */ -static const unsigned char bin_zero[] = { - 0x00, 0x3e, 0xfe, 0x0d, 0x00, 0x3a, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; - -/* - * The next set of samples are syntactically invalid - * Proper fuzzing is still needed but no harm having - * these too. Generally these are bad version of - * our nominal encoding with some octet(s) replaced - * by 0xFF values. Other hex letters are lowercase - * so you can find the altered octet(s). - */ - -/* wrong overall length (replacing 0x3e with 0xFF) */ -static const unsigned char bin_bad_olen[] = { - 0x00, 0xFF, 0xfe, 0x0d, 0x00, 0x3a, 0xbb, 0x00, - 0x20, 0x00, 0xFF, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; - -/* wrong ECHConfig inner length (replacing 0x3a with 0xFF) */ -static const unsigned char bin_bad_ilen[] = { - 0x00, 0x3e, 0xfe, 0x0d, 0x00, 0xFF, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; - -/* wrong length for public key (replaced 0x20 with 0xFF) */ -static const unsigned char bin_bad_pklen[] = { - 0x00, 0x3e, 0xfe, 0x0d, 0x00, 0x3a, 0xbb, 0x00, - 0x20, 0x00, 0xFF, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; - -/* wrong length for ciphersuites (replaced 0x04 with 0xFF) */ -static const unsigned char bin_bad_cslen[] = { - 0x00, 0x3e, 0xfe, 0x0d, 0x00, 0x3a, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0xFF, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; - -/* wrong length for public name (replaced 0x0b with 0xFF) */ -static const unsigned char bin_bad_pnlen[] = { - 0x00, 0x3e, 0xfe, 0x0d, 0x00, 0x3a, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0xFF, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; - -/* non-zero extension length (0xFF at end) but no extension value */ -static const unsigned char bin_bad_extlen[] = { - 0x00, 0x3e, 0xfe, 0x0d, 0x00, 0x3a, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0xFF -}; - -/* - * The next set have bad kem, kdf or aead values - this time with - * 0xAA as the replacement value - */ - -/* wrong KEM ID (replaced 0x20 with 0xAA) */ -static const unsigned char bin_bad_kemid[] = { - 0x00, 0x3e, 0xfe, 0x0d, 0x00, 0x3a, 0xbb, 0x00, - 0xAA, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; - -/* wrong KDF ID (replaced 0x01 with 0xAA) */ -static const unsigned char bin_bad_kdfid[] = { - 0x00, 0x3e, 0xfe, 0x0d, 0x00, 0x3a, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0xAA, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; - -/* wrong AEAD ID (replaced 0x01 with 0xAA) */ -static const unsigned char bin_bad_aeadid[] = { - 0x00, 0x3e, 0xfe, 0x0d, 0x00, 0x3a, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, - 0xAA, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; - -/* ECHConfig supports two symmetric suites */ -static const unsigned char bin_multi_suite[] = { - 0x00, 0x42, 0xfe, 0x0d, 0x00, 0x3e, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x08, 0x00, 0x01, 0x00, - 0x01, - 0x00, 0x02, 0x00, 0x02, - 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; - -/* - * sorta wrong AEAD ID; replaced 0x0001 with 0xFFFF - * which is the export only pseudo-aead-id - that - * should not work in our test, same as the others, - * but worth a specific test, as it'll fail in a - * different manner - */ -static const unsigned char bin_bad_aeadid_ff[] = { - 0x00, 0x3e, 0xfe, 0x0d, 0x00, 0x3a, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0xFF, - 0xFF, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; - -/* - * An ECHConfigList with a bad ECHConfig - * (aead is 0xFFFF), followed by a good - * one. - */ -static const unsigned char bin_bad_then_good[] = { - 0x00, 0x7c, 0xfe, 0x0d, 0x00, 0x3a, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0xFF, - 0xFF, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00, - 0xfe, 0x0d, 0x00, 0x3a, 0xbb, 0x00, 0x20, 0x00, - 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, 0xc5, 0xfe, - 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, 0xa4, 0x33, - 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, 0x5a, 0x42, - 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, 0x60, 0x16, - 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, 0x01, 0x00, - 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, - 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; - -/* couple of harmless extensions */ -static const unsigned char bin_ok_exts[] = { - 0x00, 0x47, 0xfe, 0x0d, 0x00, 0x43, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x09, - 0x0a, 0x0b, 0x00, 0x00, 0x0c, 0x0d, 0x00, 0x01, - 0x02 -}; - -/* one "mandatory" extension (high bit of type set) */ -static const unsigned char bin_mand_ext[] = { - 0x00, 0x47, 0xfe, 0x0d, 0x00, 0x43, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x09, - 0x0a, 0x0b, 0x00, 0x00, 0xFc, 0x0d, 0x00, 0x01, - 0x02 -}; - -/* extension with bad length (0xFFFF) */ -static const unsigned char bin_bad_inner_extlen[] = { - 0x00, 0x47, 0xfe, 0x0d, 0x00, 0x43, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x09, - 0x0a, 0x0b, 0x00, 0x00, 0x0c, 0x0d, 0x00, 0xFF, - 0x02 -}; - -/* good, other than a NUL inside the public_name */ -static const unsigned char bin_nul_in_pn[] = { - 0x00, 0x3e, 0xfe, 0x0d, 0x00, 0x3a, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x00, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; - -/* good, other than a dot at the end of the public_name */ -static const unsigned char bin_pn_dot_at_end[] = { - 0x00, 0x3e, 0xfe, 0x0d, 0x00, 0x3a, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x2e, 0x00, 0x00 -}; - -/* - * An ECHConfigList with a good ECHConfig followed by a bad - * one with the 1st internal length (0xFFFF) too big - */ -static const unsigned char bin_good_then_bad[] = { - 0x00, 0x7c, 0xfe, 0x0d, 0x00, 0x3a, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00, - 0xfe, 0x0d, 0xFF, 0xFF, 0xbb, 0x00, 0x20, 0x00, - 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, 0xc5, 0xfe, - 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, 0xa4, 0x33, - 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, 0x5a, 0x42, - 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, 0x60, 0x16, - 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, 0x01, 0x00, - 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, 0x6c, 0x65, - 0x2e, 0x63, 0x6f, 0x6d, 0x00, 0x00 -}; - -/* generally very short:-) */ -static const unsigned char bin_short[] = { - 0x00, 0x05, 0xfe, 0x0d, 0x00, 0x01, 0x01 -}; - -/* kind of an empty value */ -static const unsigned char bin_empty[] = { - 0x00, 0x00 -}; - -/* - * An ECHConfigList with an unsupported ECHConfig and - * that's too short. - */ -static const unsigned char bin_ver_short[] = { - 0x00, 0x3e, 0xfe, 0xFF, 0x00, 0x3a, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x20, 0x00, 0x20, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x20, 0x00, 0x20, 0x00, 0x00, 0x00, 0x00, 0x00 -}; - -/* - * too-long extension - OSSL_ECH_MAX_ECHCONFIGEXT_LEN is - * 512, this is 513 (0x0201), end of the 8-th line - * */ -static const unsigned char bin_long_ext[] = { - 0x02, 0x43, 0xfe, 0x0d, 0x02, 0x3f, 0xbb, 0x00, - 0x20, 0x00, 0x20, 0x62, 0xc7, 0x60, 0x7b, 0xf2, - 0xc5, 0xfe, 0x11, 0x08, 0x44, 0x6f, 0x13, 0x2c, - 0xa4, 0x33, 0x9c, 0xf1, 0x9d, 0xf1, 0x55, 0x2e, - 0x5a, 0x42, 0x96, 0x0f, 0xd0, 0x2c, 0x69, 0x73, - 0x60, 0x16, 0x3c, 0x00, 0x04, 0x00, 0x01, 0x00, - 0x01, 0x00, 0x0b, 0x65, 0x78, 0x61, 0x6d, 0x70, - 0x6c, 0x65, 0x2e, 0x63, 0x6f, 0x6d, 0x02, 0x05, - 0xFF, 0xFF, 0x02, 0x01, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00 -}; - -/* struct for ingest test vector and results */ -typedef struct INGEST_TV_T { - char *name; /* name for verbose output */ - const unsigned char *tv; /* test vector */ - size_t len; /* len(tv) - sizeof(tv) if binary, subtract 1 for strings */ - int pemenc; /* whether PEM encoded (1) or not (0) */ - int read; /* result expected from read function on tv */ - int keysb4; /* the number of private keys expected before downselect */ - int entsb4; /* the number of public keys b4 */ - int index; /* the index to use for downselect */ - int expected; /* the result expected from a downselect */ - int keysaftr; /* the number of keys expected after downselect */ - int entsaftr; /* the number of public keys after */ -} ingest_tv_t; - -static ingest_tv_t ingest_tvs[] = { - /* PEM test vectors */ - { "PEM basic/last", (unsigned char *)pem_kp1, sizeof(pem_kp1) - 1, - 1, 1, 1, 1, OSSL_ECHSTORE_LAST, 1, 1, 1 }, - { "PEM basic/0", (unsigned char *)pem_pk1, sizeof(pem_pk1) - 1, - 1, 1, 0, 1, 0, 1, 0, 1 }, - { "PEM basic/2nd", (unsigned char *)pem_pk1, sizeof(pem_pk1) - 1, - 1, 1, 0, 1, 2, 0, 0, 1 }, - { "ECDSA priv + 25519 pub", (unsigned char *)pem_mismatch_priv, - sizeof(pem_mismatch_priv) - 1, - 1, 0, 0, 0, 0, 0, 0, 0 }, - { "PEM string typo", (unsigned char *)pem_typo, sizeof(pem_typo) - 1, - 1, 0, 0, 0, 0, 0, 0, 0 }, - /* downselect from the 2, at each position */ - { "PEM 4->2/0", (unsigned char *)pem_4_to_2, sizeof(pem_4_to_2) - 1, - 1, 1, 0, 2, 0, 1, 0, 1 }, - { "PEM 4->2/1", (unsigned char *)pem_4_to_2, sizeof(pem_4_to_2) - 1, - 1, 1, 0, 2, 1, 1, 0, 1 }, - /* in the next one below, downselect fails, so we still have 2 entries */ - { "PEM 4->2/2", (unsigned char *)pem_4_to_2, sizeof(pem_4_to_2) - 1, - 1, 1, 0, 2, 3, 0, 0, 2 }, - /* b64 test vectors */ - { "B64 basic/last", (unsigned char *)b64_pk1, sizeof(b64_pk1) - 1, - 0, 1, 0, 1, OSSL_ECHSTORE_LAST, 1, 0, 1 }, - { "B64 6->3/2", (unsigned char *)b64_6_to_3, sizeof(b64_6_to_3) - 1, - 0, 1, 0, 3, 2, 1, 0, 1 }, - { "B64 bad suitelen", (unsigned char *)b64_bad_cs, sizeof(b64_bad_cs) - 1, - 0, 0, 0, 0, 0, 0, 0, 0 }, - /* binary test vectors */ - { "bin 6->3/2", (unsigned char *)bin_6_to_3, sizeof(bin_6_to_3), - 0, 1, 0, 3, 2, 1, 0, 1 }, - { "bin 2 symm suites", (unsigned char *)bin_multi_suite, - sizeof(bin_multi_suite), - 0, 1, 0, 1, OSSL_ECHSTORE_LAST, 1, 0, 1 }, - { "bin all-zero pub", (unsigned char *)bin_zero, sizeof(bin_zero), - 0, 1, 0, 1, OSSL_ECHSTORE_LAST, 1, 0, 1 }, - { "bin ok exts", (unsigned char *)bin_ok_exts, sizeof(bin_ok_exts), - 0, 1, 0, 1, OSSL_ECHSTORE_LAST, 1, 0, 1 }, - { "bin bad ver", (unsigned char *)bin_bad_ver, sizeof(bin_bad_ver), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin 2 bad ver", (unsigned char *)bin_bad_ver2, sizeof(bin_bad_ver2), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin bad len", (unsigned char *)bin_bad_olen, sizeof(bin_bad_olen), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin bad inner len", (unsigned char *)bin_bad_ilen, sizeof(bin_bad_ilen), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin bad pk len", (unsigned char *)bin_bad_pklen, sizeof(bin_bad_pklen), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin bad suitelen", (unsigned char *)bin_bad_cslen, sizeof(bin_bad_cslen), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin bad pn len", (unsigned char *)bin_bad_pnlen, sizeof(bin_bad_pnlen), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin bad extlen", (unsigned char *)bin_bad_extlen, sizeof(bin_bad_extlen), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin bad kemid", (unsigned char *)bin_bad_kemid, sizeof(bin_bad_kemid), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin bad kdfid", (unsigned char *)bin_bad_kdfid, sizeof(bin_bad_kdfid), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin bad aeadid", (unsigned char *)bin_bad_aeadid, sizeof(bin_bad_aeadid), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin exp aeadid", (unsigned char *)bin_bad_aeadid_ff, - sizeof(bin_bad_aeadid_ff), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin bad,good", (unsigned char *)bin_bad_then_good, - sizeof(bin_bad_then_good), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin mand ext", (unsigned char *)bin_mand_ext, sizeof(bin_mand_ext), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin bad inner extlen", (unsigned char *)bin_bad_inner_extlen, - sizeof(bin_bad_inner_extlen), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin NUL in PN", (unsigned char *)bin_nul_in_pn, sizeof(bin_nul_in_pn), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin PN ends in dot", (unsigned char *)bin_pn_dot_at_end, - sizeof(bin_pn_dot_at_end), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin short", (unsigned char *)bin_short, sizeof(bin_short), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin empty", (unsigned char *)bin_empty, sizeof(bin_empty), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin ver short", (unsigned char *)bin_ver_short, sizeof(bin_ver_short), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin long ext", (unsigned char *)bin_long_ext, sizeof(bin_long_ext), - 0, 0, 0, 0, 0, 0, 0, 0 }, - { "bin good then bad", (unsigned char *)bin_good_then_bad, - sizeof(bin_good_then_bad), - 0, 0, 0, 0, 0, 0, 0, 0 }, -}; - -/* similar, but slightly simpler setup for file reading tests */ -typedef struct FNT_T { - char *fname; /* relative file name */ - int read; /* expected result from a pem_read of that */ -} fnt_t; - -static fnt_t fnames[] = { - { "echdir/ech-eg.pem", 1 }, - { "echdir/ech-mid.pem", 1 }, - { "echdir/ech-big.pem", 1 }, - { "echdir/ech-giant.pem", 0 }, - { "echdir/ech-rsa.pem", 0 }, -}; - -/* string from which we construct varieties of HPKE suite */ -static const char *kem_str_list[] = { - "P-256", - "P-384", - "P-521", - "x25519", - "x448", -}; -static const char *kdf_str_list[] = { - "hkdf-sha256", - "hkdf-sha384", - "hkdf-sha512", -}; -static const char *aead_str_list[] = { - "aes-128-gcm", - "aes-256-gcm", -#if !defined(OPENSSL_NO_CHACHA) && !defined(OPENSSL_NO_POLY1305) - "chacha20-poly1305", -#endif -}; - -typedef enum OPTION_choice { - OPT_ERR = -1, - OPT_EOF = 0, - OPT_VERBOSE, - OPT_TEST_ENUM -} OPTION_CHOICE; - -const OPTIONS *test_get_options(void) -{ - static const OPTIONS test_options[] = { - OPT_TEST_OPTIONS_DEFAULT_USAGE, - { "v", OPT_VERBOSE, '-', "Enable verbose mode" }, - { OPT_HELP_STR, 1, '-', "Run ECH tests\n" }, - { NULL } - }; - return test_options; -} - -/* - * For the relevant test vector in our array above: - * - try decode - * - if not expected to decode, we're done - * - check we got the right number of keys/ECHConfig values - * - do some calls with getting info, downselecting etc. and - * check results as expected - * - do a write_pem call on the results - * - flush keys 'till now and check they're all gone - */ -static int ech_ingest_test(int run) -{ - OSSL_ECHSTORE *es = NULL; - BIO *in = NULL, *out = NULL; - int i, rv = 0, keysb4, keysaftr, actual_ents = 0, has_priv, for_retry; - ingest_tv_t *tv = &ingest_tvs[run]; - time_t secs = 0, add_time = 0, flush_time = 0; - char *pn = NULL, *ec = NULL; - - if ((in = BIO_new(BIO_s_mem())) == NULL - || BIO_write(in, tv->tv, (int)tv->len) <= 0 - || (out = BIO_new(BIO_s_mem())) == NULL - || (es = OSSL_ECHSTORE_new(NULL, NULL)) == NULL) - goto end; - if (verbose) - TEST_info("Iteration: %d %s", run + 1, tv->name); - /* just in case of bad edits to table */ - if (tv->pemenc != 1 && tv->pemenc != 0) { - TEST_info("Bad test vector entry"); - goto end; - } - add_time = time(0); - if (tv->pemenc == 1 - && !TEST_int_eq(OSSL_ECHSTORE_read_pem(es, in, OSSL_ECH_NO_RETRY), - tv->read)) - goto end; - if (tv->pemenc != 1 - && !TEST_int_eq(OSSL_ECHSTORE_read_echconfiglist(es, in), tv->read)) - goto end; - /* if we provided a deliberately bad tv then we're done */ - if (tv->read != 1) { - rv = 1; - goto end; - } - if (!TEST_true(OSSL_ECHSTORE_num_keys(es, &keysb4)) - || !TEST_true(OSSL_ECHSTORE_num_entries(es, &actual_ents)) - || !TEST_int_eq(keysb4, tv->keysb4) - || !TEST_int_eq(actual_ents, tv->entsb4) - || !TEST_int_eq(OSSL_ECHSTORE_get1_info(es, -1, &secs, &pn, &ec, - &has_priv, &for_retry), - 0)) - goto end; - OPENSSL_free(pn); - pn = NULL; - OPENSSL_free(ec); - ec = NULL; - for (i = 0; i != actual_ents; i++) { - if (!TEST_true(OSSL_ECHSTORE_get1_info(es, i, &secs, &pn, &ec, - &has_priv, &for_retry))) - goto end; - OPENSSL_free(pn); - pn = NULL; - OPENSSL_free(ec); - ec = NULL; - } - /* ensure silly index fails ok */ - if (!TEST_false(OSSL_ECHSTORE_downselect(es, -20)) - || !TEST_int_eq(OSSL_ECHSTORE_downselect(es, tv->index), tv->expected) - || !TEST_true(OSSL_ECHSTORE_num_keys(es, &keysaftr)) - || !TEST_int_eq(keysaftr, tv->keysaftr) - || !TEST_true(OSSL_ECHSTORE_num_entries(es, &actual_ents)) - || !TEST_int_eq(actual_ents, tv->entsaftr) - || !TEST_true(OSSL_ECHSTORE_write_pem(es, OSSL_ECHSTORE_LAST, out)) - || !TEST_true(OSSL_ECHSTORE_write_pem(es, OSSL_ECHSTORE_ALL, out)) - || !TEST_false(OSSL_ECHSTORE_write_pem(es, 100, out))) - goto end; - flush_time = time(0); - /* - * Occasionally, flush_time will be 1 more than add_time. We'll - * check for that as that should catch a few more code paths - * in the flush_keys API. - * When flush_time is 1 more, we may or may not have flushed - * the one and only key (depending on which "side" of the second - * it was generated, so we may be left with 0 or 1 keys. - */ - if (!TEST_true(OSSL_ECHSTORE_flush_keys(es, flush_time - add_time)) - || !TEST_int_eq(OSSL_ECHSTORE_num_keys(es, &keysaftr), 1) - || ((flush_time <= add_time) && !TEST_int_eq(keysaftr, 0)) - || ((flush_time > add_time) && !TEST_int_eq(keysaftr, 1) - && !TEST_int_eq(keysaftr, 0))) { - TEST_info("Flush time: %lld, add_time: %lld", (long long)flush_time, - (long long)add_time); - goto end; - } - rv = 1; -end: - OPENSSL_free(pn); - OPENSSL_free(ec); - OSSL_ECHSTORE_free(es); - BIO_free_all(in); - BIO_free_all(out); - return rv; -} - -/* make a bunch of calls with bad, mostly NULL, arguments */ -static int ech_store_null_calls(void) -{ - int rv = 0, count = 0, has_priv, for_retry; - OSSL_ECHSTORE *es = OSSL_ECHSTORE_new(NULL, NULL); - OSSL_HPKE_SUITE hpke_suite = OSSL_HPKE_SUITE_DEFAULT; - BIO *inout = BIO_new(BIO_s_mem()); - EVP_PKEY *priv = EVP_PKEY_new(); - time_t secs; - char *pn = NULL, *ec = NULL; - - OSSL_ECHSTORE_free(NULL); - if (!TEST_false(OSSL_ECHSTORE_new_config(NULL, OSSL_ECH_CURRENT_VERSION, - 0, "example.com", hpke_suite)) - || !TEST_false(OSSL_ECHSTORE_new_config(es, OSSL_ECH_CURRENT_VERSION, - 0, NULL, hpke_suite)) - || !TEST_false(OSSL_ECHSTORE_new_config(es, 0xffff, 0, - "example.com", hpke_suite))) - goto end; - hpke_suite.kdf_id = 0xAAAA; /* a bad value */ - if (!TEST_false(OSSL_ECHSTORE_new_config(es, OSSL_ECH_CURRENT_VERSION, - 0, "example.com", hpke_suite)) - || !TEST_false(OSSL_ECHSTORE_write_pem(NULL, 0, inout)) - || !TEST_false(OSSL_ECHSTORE_write_pem(es, 0, NULL)) - || !TEST_false(OSSL_ECHSTORE_write_pem(es, 100, inout)) - || !TEST_false(OSSL_ECHSTORE_read_echconfiglist(NULL, inout)) - || !TEST_false(OSSL_ECHSTORE_read_echconfiglist(es, NULL)) - || !TEST_false(OSSL_ECHSTORE_get1_info(NULL, 0, &secs, &pn, &ec, - &has_priv, &for_retry)) - || !TEST_false(OSSL_ECHSTORE_downselect(NULL, 0)) - || !TEST_false(OSSL_ECHSTORE_downselect(es, 100)) - || !TEST_false(OSSL_ECHSTORE_set1_key_and_read_pem(NULL, priv, - inout, 0)) - || !TEST_false(OSSL_ECHSTORE_set1_key_and_read_pem(es, NULL, inout, 0)) - || !TEST_false(OSSL_ECHSTORE_set1_key_and_read_pem(es, priv, NULL, 0)) - || !TEST_false(OSSL_ECHSTORE_set1_key_and_read_pem(es, priv, - inout, 100)) - /* this one fails 'cause priv has no real value, even if non NULL */ - || !TEST_false(OSSL_ECHSTORE_set1_key_and_read_pem(es, priv, inout, - OSSL_ECH_NO_RETRY)) - || !TEST_false(OSSL_ECHSTORE_read_pem(NULL, inout, OSSL_ECH_NO_RETRY)) - || !TEST_false(OSSL_ECHSTORE_read_pem(es, NULL, OSSL_ECH_NO_RETRY)) - || !TEST_false(OSSL_ECHSTORE_read_pem(es, inout, 100)) - || !TEST_false(OSSL_ECHSTORE_num_keys(NULL, &count)) - || !TEST_false(OSSL_ECHSTORE_num_keys(es, NULL)) - || !TEST_false(OSSL_ECHSTORE_flush_keys(NULL, 0)) - || !TEST_false(OSSL_ECHSTORE_flush_keys(es, -1)) - || !TEST_false(OSSL_ECHSTORE_num_entries(es, NULL))) - goto end; - rv = 1; -end: - OSSL_ECHSTORE_free(es); - BIO_free_all(inout); - EVP_PKEY_free(priv); - return rv; -} - -/* read some files, some that work, some that fail */ -static int ech_test_file_read(int run) -{ - int rv = 0; - OSSL_ECHSTORE *es = NULL; - BIO *in = NULL; - fnt_t *ft = &fnames[run]; - char *fullname = NULL; - size_t fnlen = 0; - - es = OSSL_ECHSTORE_new(NULL, NULL); - if (es == NULL) - goto end; - fnlen = strlen(certsdir) + 1 + strlen(ft->fname) + 1; - fullname = OPENSSL_malloc(fnlen); - if (fullname == NULL) - goto end; - BIO_snprintf(fullname, fnlen, "%s/%s", certsdir, ft->fname); - if (verbose) - TEST_info("testing read of %s", fullname); - in = BIO_new_file(fullname, "r"); - if (in == NULL) { - TEST_info("BIO_new_file failed for %s", ft->fname); - goto end; - } - if (!TEST_int_eq(OSSL_ECHSTORE_read_pem(es, in, OSSL_ECH_NO_RETRY), - ft->read)) - goto end; - rv = 1; -end: - OPENSSL_free(fullname); - OSSL_ECHSTORE_free(es); - BIO_free_all(in); - return rv; -} - -/* calls with bad, NULL, and simple, arguments, for generic code coverage */ -static int ech_api_basic_calls(void) -{ - int rv = 0; - SSL_CTX *ctx = NULL; - SSL *s = NULL; - OSSL_ECHSTORE *es = NULL, *es1 = NULL; - char *rinner = NULL, *inner = "inner.example.com"; - char *router = NULL, *outer = "example.com"; - unsigned char alpns[] = { 'h', '2' }; - size_t alpns_len = sizeof(alpns); - char *gsuite = "X25519,hkdf-sha256,aes-256-gcm"; - uint16_t gtype = 0xfe09; - unsigned char *rc = NULL; - size_t rclen = 0; - BIO *in = NULL; - - /* NULL args */ - if (!TEST_false(SSL_CTX_set1_echstore(NULL, NULL)) - || !TEST_false(SSL_set1_echstore(NULL, NULL)) - || !TEST_ptr_eq(SSL_CTX_get1_echstore(NULL), NULL) - || !TEST_ptr_eq(SSL_get1_echstore(NULL), NULL) - || !TEST_false(SSL_ech_set1_server_names(NULL, NULL, NULL, -1)) - || !TEST_false(SSL_ech_set1_outer_server_name(NULL, NULL, -1)) - || !TEST_false(SSL_CTX_ech_set1_outer_alpn_protos(NULL, NULL, -1)) - || !TEST_false(SSL_ech_set1_outer_alpn_protos(NULL, NULL, -1)) - || !TEST_false(SSL_ech_set1_grease_suite(NULL, NULL)) - || !TEST_false(SSL_ech_set_grease_type(NULL, 0))) - goto end; - SSL_CTX_ech_set_callback(NULL, NULL); - SSL_ech_set_callback(NULL, NULL); - if (!TEST_false(SSL_ech_get1_retry_config(NULL, NULL, NULL)) - || !TEST_int_eq(SSL_ech_get1_status(NULL, &rinner, &router), - SSL_ECH_STATUS_FAILED)) - goto end; - - /* add an ECHConfigList with extensions to exercise init code */ - if (!TEST_ptr(es = OSSL_ECHSTORE_new(NULL, NULL)) - || !TEST_ptr(in = BIO_new(BIO_s_mem())) - || !TEST_int_gt(BIO_write(in, bin_ok_exts, sizeof(bin_ok_exts)), 0) - || !TEST_true(OSSL_ECHSTORE_read_echconfiglist(es, in)) - || !TEST_ptr(ctx = SSL_CTX_new_ex(NULL, NULL, TLS_server_method()))) - goto end; - /* check status of SSL connection before OSSL_ECHSTORE set */ - if (!TEST_ptr(s = SSL_new(ctx)) - || !TEST_int_eq(SSL_ech_get1_status(s, NULL, NULL), - SSL_ECH_STATUS_FAILED) - || !TEST_int_eq(SSL_ech_get1_status(s, &rinner, &router), - SSL_ECH_STATUS_NOT_CONFIGURED)) - goto end; - SSL_set_options(s, SSL_OP_ECH_GREASE); - if (!TEST_int_eq(SSL_ech_get1_status(s, &rinner, &router), - SSL_ECH_STATUS_GREASE)) - goto end; - SSL_free(s); - s = NULL; /* for some other tests */ - if (!TEST_true(SSL_CTX_set1_echstore(ctx, es))) - goto end; - if (!TEST_ptr((es1 = SSL_CTX_get1_echstore(ctx)))) - goto end; - OSSL_ECHSTORE_free(es1); - es1 = NULL; - if (!TEST_false(SSL_set1_echstore(s, es))) - goto end; - /* do this one before SSL_new to exercise a bit of init code */ - if (!TEST_true(SSL_CTX_ech_set1_outer_alpn_protos(ctx, alpns, alpns_len))) - goto end; - s = SSL_new(ctx); - if (!TEST_true(SSL_set1_echstore(s, es))) - goto end; - if (!TEST_ptr(es1 = SSL_get1_echstore(s))) - goto end; - OSSL_ECHSTORE_free(es1); - es1 = NULL; - if (!TEST_true(SSL_ech_set1_server_names(s, inner, outer, 0)) - || !TEST_true(SSL_ech_set1_outer_server_name(s, outer, 0)) - || !TEST_true(SSL_ech_set1_outer_alpn_protos(s, alpns, alpns_len)) - || !TEST_true(SSL_ech_set1_grease_suite(s, gsuite)) - || !TEST_true(SSL_ech_set_grease_type(s, gtype)) - || !TEST_true(SSL_ech_get1_retry_config(s, &rc, &rclen)) - || !TEST_false(rclen) - || !TEST_ptr_eq(rc, NULL)) - goto end; - SSL_CTX_ech_set_callback(ctx, ech_test_cb); - SSL_ech_set_callback(s, ech_test_cb); - - /* all good */ - rv = 1; -end: - BIO_free_all(in); - OSSL_ECHSTORE_free(es1); - OSSL_ECHSTORE_free(es); - OPENSSL_free(router); - OPENSSL_free(rinner); - SSL_CTX_free(ctx); - SSL_free(s); - return rv; -} - -/* - * Test boringssl compatibility API. We don't need exhaustive - * tests here as this is a simple enough wrapper on things - * tested elsewhere. - */ -static int ech_boring_compat(void) -{ - int rv = 0; - SSL_CTX *ctx = NULL; - SSL *s = NULL; - - if (!TEST_false(SSL_set1_ech_config_list(NULL, NULL, 0)) - || !TEST_ptr(ctx = SSL_CTX_new_ex(NULL, NULL, TLS_server_method())) - || !TEST_ptr(s = SSL_new(ctx)) - || !TEST_true(SSL_set1_ech_config_list(s, NULL, 0)) - || !TEST_true(SSL_set1_ech_config_list(s, (uint8_t *)b64_pk1, - sizeof(b64_pk1) - 1)) - || !TEST_true(SSL_set1_ech_config_list(s, (uint8_t *)bin_6_to_3, - sizeof(bin_6_to_3))) - /* test a fail */ - || !TEST_false(SSL_set1_ech_config_list(s, (uint8_t *)b64_pk1, - sizeof(b64_pk1) - 2))) - goto end; - rv = 1; -end: - SSL_CTX_free(ctx); - SSL_free(s); - return rv; -} - -/* - * Check whether various public_name values are good or bad according to - * our RFC 9849 checker, which imposes some oddball restrictions on those. - * Read section 6.1.7 of RFC 9849 for details. - */ -static int ech_bad_public_names(void) -{ - int rv = 0, i; - OSSL_ECHSTORE *es = NULL; - OSSL_HPKE_SUITE hpke_suite = OSSL_HPKE_SUITE_DEFAULT; - const char *bad_names[] = { - ".dot.", /* leading dot */ - "dot.", /* trailing dot */ - ".dot", /* check both, why not */ - /* a label > 62 chars (70 in this case) */ - "abcdefghijabcdefghijabcdefghijabcdefghijabcdefghijabcdefghijabcdefghij.org", - /* last label numeric */ - "last.one.is.numeric.456", - "456", - /* last label ascii-hex */ - "last.ah.0x123", - "0x123" - }; - const char *good_names[] = { - "example.com", - "0x123.stuff", - "0x", - "a-b.c", - "example.com.c", - "a.b.0x1234567890abcdefX", - "a.b.1234567890Y" - }; - - if (!TEST_ptr(es = OSSL_ECHSTORE_new(libctx, propq))) - goto end; - for (i = 0; i != OSSL_NELEM(bad_names); i++) { - if (verbose) - TEST_info("checking bad name |%s|", bad_names[i]); - if (!TEST_false(OSSL_ECHSTORE_new_config(es, 0xfe0d, 0, bad_names[i], - hpke_suite))) { - if (verbose) - TEST_info("bad name |%s| erroneously accepted", bad_names[i]); - goto end; - } - } - for (i = 0; i != OSSL_NELEM(good_names); i++) { - if (verbose) - TEST_info("checking good name |%s|", good_names[i]); - if (!TEST_true(OSSL_ECHSTORE_new_config(es, 0xfe0d, 0, good_names[i], - hpke_suite))) { - if (verbose) - TEST_info("good name |%s| erroneously rejected", good_names[i]); - goto end; - } - } - rv = 1; -end: - OSSL_ECHSTORE_free(es); - return rv; -} - -/* values that can be used in helper below */ -#define OSSL_ECH_TEST_BASIC 0 -#define OSSL_ECH_TEST_HRR 1 -#define OSSL_ECH_TEST_EARLY 2 -#define OSSL_ECH_TEST_CUSTOM 3 -#define OSSL_ECH_TEST_ENOE 4 /* early + no-ech */ -#define OSSL_ECH_TEST_CBS 5 /* test callbacks */ -#define OSSL_ECH_TEST_V12 6 /* test TLSv1.2 */ -#define OSSL_ECH_TEST_NO_INNER 7 /* test no inner SNI */ -/* note: early-data is prohibited after HRR so no tests for that */ - -/* - * @brief ECH roundtrip test helper - * @param idx specifies which ciphersuite - * @araam combo specifies which particular test we want to roundtrip - * @return 1 for good, 0 for bad - * - * The idx input here is from 0..44 and is broken down into a - * kem, kdf and aead. If you run in verbose more ("-v") then - * there'll be a "Doing: ..." trace line that says which suite - * is being tested in string form. - * - * The combo input is one of the #define'd OSSL_ECH_TEST_* - * values above. - */ -static int test_ech_roundtrip_helper(int idx, int combo) -{ - int res = 0, kemind, kdfind, aeadind, kemsz, kdfsz, aeadsz; - int clientstatus, serverstatus, server = 1, client = 0; - unsigned int context; - OSSL_ECHSTORE *es = NULL; - OSSL_HPKE_SUITE hpke_suite = OSSL_HPKE_SUITE_DEFAULT; - uint16_t ech_version = OSSL_ECH_CURRENT_VERSION; - uint8_t max_name_length = 0; - char *public_name = "example.com", suitestr[100]; - SSL_CTX *cctx = NULL, *sctx = NULL; - SSL *clientssl = NULL, *serverssl = NULL; - char *cinner = NULL, *couter = NULL, *sinner = NULL, *souter = NULL; - SSL_SESSION *sess = NULL; - size_t written = 0, readbytes = 0; - unsigned char ed[21], buf[1024]; - - /* split idx into kemind, kdfind, aeadind */ - kemsz = OSSL_NELEM(kem_str_list); - kdfsz = OSSL_NELEM(kdf_str_list); - aeadsz = OSSL_NELEM(aead_str_list); - kemind = (idx / (kdfsz * aeadsz)) % kemsz; - kdfind = (idx / aeadsz) % kdfsz; - aeadind = idx % aeadsz; - /* initialise early data stuff, just in case */ - memset(ed, 'A', sizeof(ed)); - BIO_snprintf(suitestr, 100, "%s,%s,%s", kem_str_list[kemind], - kdf_str_list[kdfind], aead_str_list[aeadind]); - if (verbose) - TEST_info("Doing: iter: %d, suite: %s", idx, suitestr); - /* - * Set a max name length just to exercise more code. - * We may as well use the index, just to make it vary:-) - */ - if (combo == OSSL_ECH_TEST_NO_INNER) - max_name_length = (idx % 256); - if (!TEST_true(OSSL_HPKE_str2suite(suitestr, &hpke_suite)) - || !TEST_ptr(es = OSSL_ECHSTORE_new(libctx, propq)) - || !TEST_true(OSSL_ECHSTORE_new_config(es, ech_version, max_name_length, - public_name, hpke_suite)) - || !TEST_true(create_ssl_ctx_pair(libctx, TLS_server_method(), - TLS_client_method(), - TLS1_3_VERSION, TLS1_3_VERSION, - &sctx, &cctx, cert, privkey))) - goto end; - if (combo == OSSL_ECH_TEST_V12) { - /* force client to TLSv1.2 and later fail as expected */ - if (!TEST_true(SSL_CTX_set_max_proto_version(cctx, TLS1_2_VERSION))) - goto end; - if (!TEST_true(SSL_CTX_set_min_proto_version(cctx, TLS1_2_VERSION))) - goto end; - } - if (combo == OSSL_ECH_TEST_EARLY || combo == OSSL_ECH_TEST_ENOE) { - if (!TEST_true(SSL_CTX_set_options(sctx, SSL_OP_NO_ANTI_REPLAY)) - || !TEST_true(SSL_CTX_set_max_early_data(sctx, - SSL3_RT_MAX_PLAIN_LENGTH)) - || !TEST_true(SSL_CTX_set_recv_max_early_data(sctx, - SSL3_RT_MAX_PLAIN_LENGTH))) - goto end; - } - if (combo == OSSL_ECH_TEST_CUSTOM) { - context = SSL_EXT_CLIENT_HELLO; /* add custom CH ext to client/server */ - if (!TEST_true(SSL_CTX_add_custom_ext(cctx, TEST_EXT_TYPE1, context, - new_add_cb, new_free_cb, - &client, new_parse_cb, &client)) - || !TEST_true(SSL_CTX_add_custom_ext(sctx, TEST_EXT_TYPE1, context, - new_add_cb, new_free_cb, - &server, new_parse_cb, &server)) - || !TEST_true(SSL_CTX_add_custom_ext(cctx, TEST_EXT_TYPE2, context, - new_add_cb, NULL, - &client, NULL, &client)) - || !TEST_true(SSL_CTX_add_custom_ext(sctx, TEST_EXT_TYPE2, context, - new_add_cb, NULL, - &server, NULL, &server))) - goto end; - } - if (combo == OSSL_ECH_TEST_CBS) { - SSL_CTX_ech_set_callback(sctx, ech_test_cb); - SSL_CTX_set_client_hello_cb(sctx, ch_test_cb, NULL); - } - if (combo != OSSL_ECH_TEST_ENOE - && !TEST_true(SSL_CTX_set1_echstore(cctx, es))) - goto end; - /* set callback for client, just to exercise code */ - SSL_CTX_ech_set_callback(cctx, ech_test_cb); - if (!TEST_true(SSL_CTX_set1_echstore(sctx, es)) - || !TEST_true(create_ssl_objects(sctx, cctx, &serverssl, - &clientssl, NULL, NULL))) - goto end; - if (combo == OSSL_ECH_TEST_HRR - && !TEST_true(SSL_set1_groups_list(serverssl, "P-384"))) - goto end; - if (combo != OSSL_ECH_TEST_NO_INNER - && !TEST_true(SSL_set_tlsext_host_name(clientssl, "server.example"))) - goto end; - if (combo == OSSL_ECH_TEST_V12) { - if (!TEST_false(create_ssl_connection(serverssl, clientssl, - SSL_ERROR_NONE))) - goto end; - res = 1; - goto end; - } else { - if (!TEST_true(create_ssl_connection(serverssl, clientssl, - SSL_ERROR_NONE))) - goto end; - } - /* override cert verification */ - SSL_set_verify_result(clientssl, X509_V_OK); - clientstatus = SSL_ech_get1_status(clientssl, &cinner, &couter); - if (verbose) - TEST_info("client status %d, %s, %s", clientstatus, cinner, couter); - serverstatus = SSL_ech_get1_status(serverssl, &sinner, &souter); - if (verbose) - TEST_info("server status %d, %s, %s", serverstatus, sinner, souter); - if (combo != OSSL_ECH_TEST_ENOE - && !TEST_int_eq(serverstatus, SSL_ECH_STATUS_SUCCESS)) - goto end; - if (combo == OSSL_ECH_TEST_ENOE - && !TEST_int_eq(serverstatus, SSL_ECH_STATUS_NOT_TRIED)) - goto end; - if (combo != OSSL_ECH_TEST_ENOE - && !TEST_int_eq(clientstatus, SSL_ECH_STATUS_SUCCESS)) - goto end; - if (combo == OSSL_ECH_TEST_ENOE - && !TEST_int_eq(clientstatus, SSL_ECH_STATUS_NOT_CONFIGURED)) - goto end; - if (combo == OSSL_ECH_TEST_CBS && !TEST_int_eq(ch_test_cb_ok, 1)) - goto end; - /* all good */ - if (combo == OSSL_ECH_TEST_BASIC || combo == OSSL_ECH_TEST_HRR - || combo == OSSL_ECH_TEST_CUSTOM || combo == OSSL_ECH_TEST_CBS - || combo == OSSL_ECH_TEST_NO_INNER) { - res = 1; - goto end; - } - /* continue for EARLY test */ - if (combo != OSSL_ECH_TEST_EARLY && combo != OSSL_ECH_TEST_ENOE) - goto end; - /* shutdown for start over */ - sess = SSL_get1_session(clientssl); - OPENSSL_free(sinner); - OPENSSL_free(souter); - OPENSSL_free(cinner); - OPENSSL_free(couter); - sinner = souter = cinner = couter = NULL; - SSL_shutdown(clientssl); - SSL_shutdown(serverssl); - SSL_free(serverssl); - SSL_free(clientssl); - serverssl = clientssl = NULL; - /* second connection */ - if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, - &clientssl, NULL, NULL)) - || !TEST_true(SSL_set_tlsext_host_name(clientssl, "server.example")) - || !TEST_true(SSL_set_session(clientssl, sess)) - || !TEST_true(SSL_write_early_data(clientssl, ed, sizeof(ed), &written)) - || !TEST_size_t_eq(written, sizeof(ed)) - || !TEST_int_eq(SSL_read_early_data(serverssl, buf, sizeof(buf), - &readbytes), - SSL_READ_EARLY_DATA_SUCCESS) - || !TEST_size_t_eq(written, readbytes)) - goto end; - /* - * Server should be able to write data, and client should be able to - * read it. - */ - if (!TEST_true(SSL_write_early_data(serverssl, ed, sizeof(ed), &written)) - || !TEST_size_t_eq(written, sizeof(ed)) - || !TEST_true(SSL_read_ex(clientssl, buf, sizeof(buf), &readbytes)) - || !TEST_mem_eq(buf, readbytes, ed, sizeof(ed))) - goto end; - /* override cert verification */ - SSL_set_verify_result(clientssl, X509_V_OK); - clientstatus = SSL_ech_get1_status(clientssl, &cinner, &couter); - if (verbose) - TEST_info("client status %d, %s, %s", clientstatus, cinner, couter); - serverstatus = SSL_ech_get1_status(serverssl, &sinner, &souter); - if (verbose) - TEST_info("server status %d, %s, %s", serverstatus, sinner, souter); - if (combo != OSSL_ECH_TEST_ENOE - && !TEST_int_eq(serverstatus, SSL_ECH_STATUS_SUCCESS)) - goto end; - if (combo == OSSL_ECH_TEST_ENOE - && !TEST_int_eq(serverstatus, SSL_ECH_STATUS_NOT_TRIED)) - goto end; - if (combo != OSSL_ECH_TEST_ENOE - && !TEST_int_eq(clientstatus, SSL_ECH_STATUS_SUCCESS)) - goto end; - if (combo == OSSL_ECH_TEST_ENOE - && !TEST_int_eq(clientstatus, SSL_ECH_STATUS_NOT_CONFIGURED)) - goto end; - /* all good */ - res = 1; -end: - OSSL_ECHSTORE_free(es); - OPENSSL_free(sinner); - OPENSSL_free(souter); - OPENSSL_free(cinner); - OPENSSL_free(couter); - SSL_SESSION_free(sess); - SSL_free(clientssl); - SSL_free(serverssl); - SSL_CTX_free(cctx); - SSL_CTX_free(sctx); - ch_test_cb_ok = 0; - return res; -} - -/* Test roundtrip with ECH for any suite */ -static int test_ech_suites(int idx) -{ - if (verbose) - TEST_info("Doing: test_ech_suites"); - return test_ech_roundtrip_helper(idx, OSSL_ECH_TEST_BASIC); -} - -/* ECH with HRR for the given suite */ -static int test_ech_hrr(int idx) -{ - if (verbose) - TEST_info("Doing: test_ech_hrr"); - return test_ech_roundtrip_helper(idx, OSSL_ECH_TEST_HRR); -} - -/* ECH with no inner SNI for the given suite */ -static int test_ech_no_inner(int idx) -{ - if (verbose) - TEST_info("Doing: test_ech_no_inner"); - return test_ech_roundtrip_helper(idx, OSSL_ECH_TEST_NO_INNER); -} - -/* ECH with early data for the given suite */ -static int test_ech_early(int idx) -{ - if (verbose) - TEST_info("Doing: test_ech_early"); - return test_ech_roundtrip_helper(idx, OSSL_ECH_TEST_EARLY); -} - -/* Test a roundtrip with ECH, and a custom CH extension */ -static int ech_custom_test(int idx) -{ - if (verbose) - TEST_info("Doing: ech_custom_test"); - return test_ech_roundtrip_helper(idx, OSSL_ECH_TEST_CUSTOM); -} - -/* Test a roundtrip with No ECH, and early data */ -static int ech_enoe_test(int idx) -{ - if (verbose) - TEST_info("Doing: ech_no ech + early test "); - return test_ech_roundtrip_helper(idx, OSSL_ECH_TEST_ENOE); -} - -/* Test a roundtrip with ECH, and callbacks */ -static int ech_cb_test(int idx) -{ - if (verbose) - TEST_info("Doing: ech + callbacks test "); - return test_ech_roundtrip_helper(idx, OSSL_ECH_TEST_CBS); -} - -/* Test a roundtrip (fails) with ECH but a TLSv1.2 SSL_CTX */ -static int ech_v12_test(int idx) -{ - if (verbose) - TEST_info("Doing: ech TLSv1.2 test "); - return test_ech_roundtrip_helper(idx, OSSL_ECH_TEST_V12); -} - -/* - * Test roundtrip with SNI/ALPN variations. - * Inner and outer names can be supplied to SSL_CTX or SSL - * connection via ECH APIs, and inner can be supplied via - * the existing non-ECH API. We can specify that no outer - * SNI at all be sent if we want. If an outer SNI value is - * supplied via the ECH API then that over-rides the - * public_name field from the ECHConfig, which in this - * cases will be example.com. We have the option of setting - * both inner, outer and no_outer setting via eiher: - * - * int SSL_ech_set1_server_names(SSL *s, const char *inner_name, - * const char *outer_name, int no_outer); - * int SSL_ech_set1_outer_server_name(SSL *s, const char *outer_name, - * int no_outer); - * - * So there's a bunch of cases to test, as usual we pick - * between 'em using the idx parameter. - * - * idx : case - * 0 : set no names via ECH APIs; - * set inner to inner.example.com non-ECH API - * expect public_name as outer - * 1 : as for 0, but additionally: - * set NULL and "no_outer" via set_outer API - * 2 : as for 1, but additionally: - * set non-NULL outer and "no_outer" via set_outer API - * 3 : override outer via ECH API - * 4 : like 1, but using set_server_names API - * 5 : like 2, but using set_server_names API - * 6 : like 3, but using set_server_names API - * 7 : like 4, but overriding previous call to non-ECH SNI - * 8 : like 5, but overriding previous call to non-ECH SNI - * 9 : like 6, but overriding previous call to non-ECH SNI - * 10 : like 7, but reversing call order - * 11 : like 8, but reversing call order - * 12 : like 9, but reversing call order - * 13 : like 1, but with a NULL outer input to API - * that's a bit pointless as it's more or less a NO-OP - * but worth checking - */ -static int ech_in_out_test(int idx) -{ - int res = 0, cres = 0, sres = 0, clientstatus, serverstatus; - SSL_CTX *cctx = NULL, *sctx = NULL; - SSL *clientssl = NULL, *serverssl = NULL; - char *non_ech_sni = "trad.server.example"; /* SNI set via non-ECH API */ - char *supplied_inner = "inner.server.example"; /* inner set via ECH API */ - char *supplied_outer = "outer.server.example"; /* outer set via ECH API */ - char *public_name = "front.server.example"; /* we know that's inside pem_kp2 */ - char *cinner = NULL, *couter = NULL, *sinner = NULL, *souter = NULL; - unsigned char alpn_inner[] = { /* "inner, secret, http/1.1" */ - 0x05, 0x69, 0x6e, 0x6e, 0x65, 0x72, - 0x06, 0x73, 0x65, 0x63, 0x72, 0x65, 0x74, - 0x08, 0x68, 0x74, 0x74, 0x70, 0x2f, 0x31, 0x2e, 0x31 - }; - size_t alpn_inner_len = sizeof(alpn_inner); - unsigned char alpn_outer[] = { /* "outer, public, h2" */ - 0x05, 0x6f, 0x75, 0x74, 0x65, 0x72, 0x06, 0x70, - 0x75, 0x62, 0x6c, 0x69, 0x63, 0x02, 0x68, 0x32 - }; - size_t alpn_outer_len = sizeof(alpn_outer); - char *expected_inner = NULL, *expected_outer = NULL; - BIO *in = NULL; - OSSL_ECHSTORE *es = NULL; - - /* make an OSSL_ECHSTORE for pem_kp2 */ - if ((in = BIO_new(BIO_s_mem())) == NULL - || BIO_write(in, pem_kp2, (int)strlen(pem_kp2)) <= 0 - || !TEST_ptr(es = OSSL_ECHSTORE_new(libctx, propq)) - || !TEST_true(OSSL_ECHSTORE_read_pem(es, in, OSSL_ECH_FOR_RETRY)) - || !TEST_true(create_ssl_ctx_pair(libctx, TLS_server_method(), - TLS_client_method(), - TLS1_3_VERSION, TLS1_3_VERSION, - &sctx, &cctx, cert, privkey)) - || !TEST_true(SSL_CTX_set1_echstore(sctx, es)) - || !TEST_false(SSL_CTX_set_alpn_protos(cctx, alpn_inner, - (unsigned int)alpn_inner_len)) - || !TEST_true(SSL_CTX_ech_set1_outer_alpn_protos(cctx, alpn_outer, - alpn_outer_len)) - || !TEST_true(create_ssl_objects(sctx, cctx, &serverssl, - &clientssl, NULL, NULL)) - || !TEST_true(SSL_set1_ech_config_list(clientssl, - (unsigned char *)ec_kp2, - ec_kp2len))) - goto end; - if (idx == 0) { - if (!TEST_true(SSL_set_tlsext_host_name(clientssl, non_ech_sni))) - goto end; - expected_inner = non_ech_sni; - expected_outer = public_name; - } - if (idx == 1) { - if (!TEST_true(SSL_set_tlsext_host_name(clientssl, non_ech_sni)) - || !TEST_true(SSL_ech_set1_outer_server_name(clientssl, NULL, 1))) - goto end; - expected_inner = non_ech_sni; - expected_outer = NULL; - } - if (idx == 2) { - if (!TEST_true(SSL_set_tlsext_host_name(clientssl, non_ech_sni)) - || !TEST_true(SSL_ech_set1_outer_server_name(clientssl, "blah", 1))) - goto end; - expected_inner = non_ech_sni; - expected_outer = NULL; - } - if (idx == 3) { - if (!TEST_true(SSL_set_tlsext_host_name(clientssl, non_ech_sni)) - || !TEST_true(SSL_ech_set1_outer_server_name(clientssl, - supplied_outer, 0)) - || !TEST_true(SSL_ech_set1_outer_alpn_protos(clientssl, alpn_outer, - alpn_outer_len))) - goto end; - expected_inner = non_ech_sni; - expected_outer = supplied_outer; - } - if (idx == 4) { - if (!TEST_true(SSL_ech_set1_server_names(clientssl, - supplied_inner, NULL, 0))) - goto end; - expected_inner = supplied_inner; - expected_outer = public_name; - } - if (idx == 5) { - if (!TEST_true(SSL_ech_set1_server_names(clientssl, supplied_inner, - "blah", 1))) - goto end; - expected_inner = supplied_inner; - expected_outer = NULL; - } - if (idx == 6) { - if (!TEST_true(SSL_ech_set1_server_names(clientssl, supplied_inner, - supplied_outer, 0))) - goto end; - expected_inner = supplied_inner; - expected_outer = supplied_outer; - } - if (idx == 7) { - if (!TEST_true(SSL_set_tlsext_host_name(clientssl, "blah")) - || !TEST_true(SSL_ech_set1_server_names(clientssl, supplied_inner, - NULL, 0))) - goto end; - expected_inner = supplied_inner; - expected_outer = public_name; - } - if (idx == 8) { - if (!TEST_true(SSL_set_tlsext_host_name(clientssl, "blah")) - || !TEST_true(SSL_ech_set1_server_names(clientssl, supplied_inner, - "blah", 1))) - goto end; - expected_inner = supplied_inner; - expected_outer = NULL; - } - if (idx == 9) { - if (!TEST_true(SSL_set_tlsext_host_name(clientssl, "blah")) - || !TEST_true(SSL_ech_set1_server_names(clientssl, supplied_inner, - supplied_outer, 0))) - goto end; - expected_inner = supplied_inner; - expected_outer = supplied_outer; - } - if (idx == 10) { - if (!TEST_true(SSL_ech_set1_server_names(clientssl, - supplied_inner, NULL, 0)) - || !TEST_true(SSL_set_tlsext_host_name(clientssl, non_ech_sni))) - goto end; - expected_inner = non_ech_sni; - expected_outer = public_name; - } - if (idx == 11) { - if (!TEST_true(SSL_ech_set1_server_names(clientssl, supplied_inner, - "blah", 1)) - || !TEST_true(SSL_set_tlsext_host_name(clientssl, non_ech_sni))) - goto end; - expected_inner = non_ech_sni; - expected_outer = NULL; - } - if (idx == 12) { - if (!TEST_true(SSL_ech_set1_server_names(clientssl, supplied_inner, - supplied_outer, 0)) - || !TEST_true(SSL_set_tlsext_host_name(clientssl, non_ech_sni))) - goto end; - expected_inner = non_ech_sni; - expected_outer = supplied_outer; - } - if (idx == 13) { - if (!TEST_true(SSL_set_tlsext_host_name(clientssl, non_ech_sni)) - || !TEST_true(SSL_ech_set1_outer_server_name(clientssl, NULL, 0))) - goto end; - expected_inner = non_ech_sni; - expected_outer = public_name; - } - if (!TEST_true(create_ssl_connection(serverssl, clientssl, - SSL_ERROR_NONE))) - goto end; - serverstatus = SSL_ech_get1_status(serverssl, &sinner, &souter); - if (!TEST_int_eq(serverstatus, SSL_ECH_STATUS_SUCCESS)) - goto end; - SSL_set_verify_result(clientssl, X509_V_OK); /* override cert check */ - clientstatus = SSL_ech_get1_status(clientssl, &cinner, &couter); - if (!TEST_int_eq(clientstatus, SSL_ECH_STATUS_SUCCESS)) - goto end; - cres = sres = 0; /* check result vs. expected */ - if ((expected_inner == NULL && cinner == NULL) - || (expected_inner != NULL && cinner != NULL - && strlen(expected_inner) == strlen(cinner) - && strcmp(expected_inner, cinner) == 0)) - cres = 1; - if (!TEST_int_eq(cres, 1)) - goto end; - if ((expected_inner == NULL && sinner == NULL) - || (expected_inner != NULL && sinner != NULL - && strlen(expected_inner) == strlen(sinner) - && strcmp(expected_inner, sinner) == 0)) - sres = 1; - if (!TEST_int_eq(sres, 1)) - goto end; - cres = sres = 0; - if ((expected_outer == NULL && couter == NULL) - || (expected_outer != NULL && couter != NULL - && strlen(expected_outer) == strlen(couter) - && strcmp(expected_outer, couter) == 0)) - cres = 1; - if (!TEST_int_eq(cres, 1)) - goto end; - if ((expected_outer == NULL && souter == NULL) - || (expected_outer != NULL && souter != NULL - && strlen(expected_outer) == strlen(souter) - && strcmp(expected_outer, souter) == 0)) - sres = 1; - if (!TEST_int_eq(sres, 1)) - goto end; - res = 1; /* all good */ -end: - OSSL_ECHSTORE_free(es); - BIO_free_all(in); - OPENSSL_free(sinner); - OPENSSL_free(souter); - OPENSSL_free(cinner); - OPENSSL_free(couter); - SSL_free(clientssl); - SSL_free(serverssl); - SSL_CTX_free(cctx); - SSL_CTX_free(sctx); - return res; -} - -/* Test roundtrip with GREASE'd ECH, then again with retry-config */ -static int ech_grease_test(int idx) -{ - int res = 0, clientstatus, serverstatus; - SSL_CTX *cctx = NULL, *sctx = NULL; - SSL *clientssl = NULL, *serverssl = NULL; - char *cinner = NULL, *couter = NULL, *sinner = NULL, *souter = NULL; - unsigned char *retryconfig = NULL; - size_t retryconfiglen = 0; - X509_STORE *ch = NULL; - OSSL_ECHSTORE *es = NULL; - BIO *in; - - /* make OSSL_ECHSTORE vars for pem_kp2 */ - if ((in = BIO_new(BIO_s_mem())) == NULL - || BIO_write(in, pem_kp2, (int)strlen(pem_kp2)) <= 0 - || !TEST_ptr(es = OSSL_ECHSTORE_new(libctx, propq)) - || !TEST_true(OSSL_ECHSTORE_read_pem(es, in, OSSL_ECH_FOR_RETRY))) - goto end; - if (idx == 2) { - /* - * In our third test iteration set various other ECH configs, to make - * for a bigger retry-config. (It's ok that we set the same key pair - * a few times here.) - */ - BIO_free_all(in); - in = NULL; - if ((in = BIO_new(BIO_s_mem())) == NULL - || BIO_write(in, pem_kp3, (int)strlen(pem_kp3)) <= 0 - || !TEST_true(OSSL_ECHSTORE_read_pem(es, in, OSSL_ECH_NO_RETRY))) - goto end; - BIO_free_all(in); - in = NULL; - if ((in = BIO_new(BIO_s_mem())) == NULL - || BIO_write(in, pem_kp3, (int)strlen(pem_kp3)) <= 0 - || !TEST_true(OSSL_ECHSTORE_read_pem(es, in, OSSL_ECH_FOR_RETRY))) - goto end; - BIO_free_all(in); - in = NULL; - if ((in = BIO_new(BIO_s_mem())) == NULL - || BIO_write(in, pem_kp3, (int)strlen(pem_kp3)) <= 0 - || !TEST_true(OSSL_ECHSTORE_read_pem(es, in, OSSL_ECH_NO_RETRY))) - goto end; - } - BIO_free_all(in); - in = NULL; - - if (!TEST_true(create_ssl_ctx_pair(libctx, TLS_server_method(), - TLS_client_method(), - TLS1_3_VERSION, TLS1_3_VERSION, - &sctx, &cctx, cert, privkey))) - goto end; - if (!TEST_true(SSL_CTX_set1_echstore(sctx, es))) - goto end; - - /* set the client GREASE flag via SSL_CTX 1st time, and via SSL* 2nd */ - if (idx == 0 && !TEST_true(SSL_CTX_set_options(cctx, SSL_OP_ECH_GREASE))) - goto end; - if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, - &clientssl, NULL, NULL))) - goto end; - if (!TEST_true(SSL_set_tlsext_host_name(clientssl, "back.server.example"))) - goto end; - - /* set the GREASE flag via SSL_CTX 1st time, and via SSL* 2nd & 3rd */ - if (idx >= 1 && !TEST_true(SSL_set_options(clientssl, SSL_OP_ECH_GREASE))) - goto end; - /* 3rd time, fail to set a bad grease suite, then set a good one */ - if (idx == 2 && !TEST_false(SSL_ech_set1_grease_suite(clientssl, "notanhpkesuite"))) - goto end; - if (idx == 2 && !TEST_true(SSL_ech_set1_grease_suite(clientssl, "x25519,hkdf-sha384,aes-256-gcm"))) - goto end; - /* for 4th test, set a real but wrong ECHConfig which'll override GREASE setting */ - if (idx == 3) { - if (!TEST_true(SSL_set1_ech_config_list(clientssl, (unsigned char *)ec_kp1, - ec_kp1len))) - goto end; - /* real but wrong => failure, due to ECH */ - if (!TEST_false(create_ssl_connection(serverssl, clientssl, - SSL_R_ECH_REQUIRED))) - goto end; - } else { - /* asked for GREASE => should work */ - if (!TEST_true(create_ssl_connection(serverssl, clientssl, - SSL_ERROR_NONE))) - goto end; - } - serverstatus = SSL_ech_get1_status(serverssl, &sinner, &souter); - if (verbose) - TEST_info("ech_grease_test: server status %d, %s, %s", - serverstatus, sinner, souter); - if (!TEST_int_eq(serverstatus, SSL_ECH_STATUS_GREASE)) - goto end; - /* override cert verification */ - SSL_set_verify_result(clientssl, X509_V_OK); - clientstatus = SSL_ech_get1_status(clientssl, &cinner, &couter); - if (verbose) - TEST_info("ech_grease_test: client status %d, %s, %s", - clientstatus, cinner, couter); - if (idx != 3 && !TEST_int_eq(clientstatus, SSL_ECH_STATUS_GREASE_ECH)) - goto end; - if (idx == 3 && !TEST_int_eq(clientstatus, SSL_ECH_STATUS_FAILED_ECH)) - goto end; - if (!TEST_true(SSL_ech_get1_retry_config(clientssl, &retryconfig, - &retryconfiglen))) - goto end; - if (!TEST_ptr(retryconfig)) - goto end; - if (!TEST_int_ne((int)retryconfiglen, 0)) - goto end; - if (verbose) - TEST_info("ech_grease_test: retryconfglen: %zu\n", retryconfiglen); - /* we kow the sizes to expect as the configs are hard-coded above */ - if (idx == 2 && !TEST_size_t_eq(retryconfiglen, 141)) - goto end; - if (idx < 2 && !TEST_size_t_eq(retryconfiglen, 73)) - goto end; - /* cleanup */ - OPENSSL_free(sinner); - OPENSSL_free(souter); - OPENSSL_free(cinner); - OPENSSL_free(couter); - sinner = souter = cinner = couter = NULL; - SSL_shutdown(clientssl); - SSL_shutdown(serverssl); - SSL_free(serverssl); - SSL_free(clientssl); - serverssl = clientssl = NULL; - - /* second connection */ - if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, - &clientssl, NULL, NULL))) - goto end; - /* setting an ECHConfig should over-ride GREASE flag */ - if (!TEST_true(SSL_set1_ech_config_list(clientssl, retryconfig, - retryconfiglen))) - goto end; - if (!TEST_true(SSL_set_tlsext_host_name(clientssl, "server.example"))) - goto end; - if (!TEST_true(create_ssl_connection(serverssl, clientssl, - SSL_ERROR_NONE))) - goto end; - serverstatus = SSL_ech_get1_status(serverssl, &sinner, &souter); - if (verbose) - TEST_info("server status %d, %s, %s", serverstatus, sinner, souter); - if (!TEST_int_eq(serverstatus, SSL_ECH_STATUS_SUCCESS)) - goto end; - /* override cert verification */ - SSL_set_verify_result(clientssl, X509_V_OK); - clientstatus = SSL_ech_get1_status(clientssl, &cinner, &couter); - if (verbose) - TEST_info("client status %d, %s, %s", clientstatus, cinner, couter); - if (!TEST_int_eq(clientstatus, SSL_ECH_STATUS_SUCCESS)) - goto end; - /* 3rd connection - this time grease+HRR which had a late fail */ - OPENSSL_free(sinner); - OPENSSL_free(souter); - OPENSSL_free(cinner); - OPENSSL_free(couter); - sinner = souter = cinner = couter = NULL; - SSL_shutdown(clientssl); - SSL_shutdown(serverssl); - SSL_free(serverssl); - SSL_free(clientssl); - serverssl = clientssl = NULL; - if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, - &clientssl, NULL, NULL))) - goto end; - /* force ECH+HRR */ - if (!TEST_true(SSL_set_options(clientssl, SSL_OP_ECH_GREASE))) - goto end; - /* setting an ECHConfig should over-ride GREASE flag */ - if (!TEST_true(SSL_set1_ech_config_list(clientssl, retryconfig, - retryconfiglen))) - goto end; - if (!TEST_true(SSL_set1_groups_list(serverssl, "P-384"))) - goto end; - if (!TEST_true(SSL_set_tlsext_host_name(clientssl, "server.example"))) - goto end; - if (!TEST_true(create_ssl_connection(serverssl, clientssl, - SSL_ERROR_NONE))) - goto end; - serverstatus = SSL_ech_get1_status(serverssl, &sinner, &souter); - if (verbose) - TEST_info("server status %d, %s, %s", serverstatus, sinner, souter); - if (!TEST_int_eq(serverstatus, SSL_ECH_STATUS_SUCCESS)) - goto end; - /* override cert verification */ - SSL_set_verify_result(clientssl, X509_V_OK); - clientstatus = SSL_ech_get1_status(clientssl, &cinner, &couter); - if (verbose) - TEST_info("client status %d, %s, %s", clientstatus, cinner, couter); - if (!TEST_int_eq(clientstatus, SSL_ECH_STATUS_SUCCESS)) - goto end; - /* all good */ - res = 1; -end: - OPENSSL_free(sinner); - OPENSSL_free(souter); - OPENSSL_free(cinner); - OPENSSL_free(couter); - OPENSSL_free(retryconfig); - SSL_free(clientssl); - SSL_free(serverssl); - X509_STORE_free(ch); - SSL_CTX_free(cctx); - SSL_CTX_free(sctx); - OSSL_ECHSTORE_free(es); - BIO_free_all(in); - return res; -} - -#endif - -int setup_tests(void) -{ -#ifndef OPENSSL_NO_ECH - OPTION_CHOICE o; - int suite_combos; - - while ((o = opt_next()) != OPT_EOF) { - switch (o) { - case OPT_VERBOSE: - verbose = 1; - break; - case OPT_TEST_CASES: - break; - default: - return 0; - } - } - certsdir = test_get_argument(0); - if (certsdir == NULL) - certsdir = DEF_CERTS_DIR; - cert = test_mk_file_path(certsdir, "echserver.pem"); - if (cert == NULL) - goto err; - privkey = test_mk_file_path(certsdir, "echserver.key"); - if (privkey == NULL) - goto err; - rootcert = test_mk_file_path(certsdir, "rootcert.pem"); - if (rootcert == NULL) - goto err; - ADD_ALL_TESTS(ech_ingest_test, OSSL_NELEM(ingest_tvs)); - ADD_TEST(ech_store_null_calls); - ADD_ALL_TESTS(ech_test_file_read, OSSL_NELEM(fnames)); - ADD_TEST(ech_api_basic_calls); - ADD_TEST(ech_boring_compat); - ADD_TEST(ech_bad_public_names); - suite_combos = OSSL_NELEM(kem_str_list) * OSSL_NELEM(kdf_str_list) - * OSSL_NELEM(aead_str_list); - ADD_ALL_TESTS(test_ech_suites, suite_combos); - ADD_ALL_TESTS(test_ech_hrr, suite_combos); - ADD_ALL_TESTS(test_ech_early, suite_combos); - ADD_ALL_TESTS(ech_custom_test, suite_combos); - ADD_ALL_TESTS(ech_enoe_test, suite_combos); - ADD_ALL_TESTS(ech_cb_test, suite_combos); - ADD_ALL_TESTS(ech_v12_test, suite_combos); - ADD_ALL_TESTS(ech_in_out_test, 14); - ADD_ALL_TESTS(ech_grease_test, 4); - ADD_ALL_TESTS(test_ech_no_inner, suite_combos); - return 1; -err: - return 0; -#endif - return 1; -} - -void cleanup_tests(void) -{ -#ifndef OPENSSL_NO_ECH - OPENSSL_free(cert); - OPENSSL_free(privkey); - OPENSSL_free(rootcert); -#endif -} diff --git a/test/ectest.c b/test/ectest.c index 363d119c96..9b1c911b5b 100644 --- a/test/ectest.c +++ b/test/ectest.c @@ -1,5 +1,5 @@ /* - * Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2001-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -306,7 +306,6 @@ static int prime_field_tests(void) "3168947d59dcc912042351377ac5fb32")) || !TEST_BN_eq(y, z) || !TEST_int_eq(EC_GROUP_get_degree(group), 160) - || !TEST_int_eq(EC_GROUP_security_bits(group), 80) || !group_order_tests(group) /* Curve P-192 (FIPS PUB 186-2, App. 6) */ @@ -344,7 +343,6 @@ static int prime_field_tests(void) || !TEST_false(EC_POINT_set_affine_coordinates(group, P, x, yplusone, ctx)) || !TEST_int_eq(EC_GROUP_get_degree(group), 192) - || !TEST_int_eq(EC_GROUP_security_bits(group), 80) || !group_order_tests(group) /* Curve P-224 (FIPS PUB 186-2, App. 6) */ @@ -382,7 +380,6 @@ static int prime_field_tests(void) || !TEST_false(EC_POINT_set_affine_coordinates(group, P, x, yplusone, ctx)) || !TEST_int_eq(EC_GROUP_get_degree(group), 224) - || !TEST_int_eq(EC_GROUP_security_bits(group), 112) || !group_order_tests(group) /* Curve P-256 (FIPS PUB 186-2, App. 6) */ @@ -421,7 +418,6 @@ static int prime_field_tests(void) || !TEST_false(EC_POINT_set_affine_coordinates(group, P, x, yplusone, ctx)) || !TEST_int_eq(EC_GROUP_get_degree(group), 256) - || !TEST_int_eq(EC_GROUP_security_bits(group), 128) || !group_order_tests(group) /* Curve P-384 (FIPS PUB 186-2, App. 6) */ @@ -466,7 +462,6 @@ static int prime_field_tests(void) || !TEST_false(EC_POINT_set_affine_coordinates(group, P, x, yplusone, ctx)) || !TEST_int_eq(EC_GROUP_get_degree(group), 384) - || !TEST_int_eq(EC_GROUP_security_bits(group), 192) || !group_order_tests(group) /* Curve P-521 (FIPS PUB 186-2, App. 6) */ @@ -521,7 +516,6 @@ static int prime_field_tests(void) || !TEST_false(EC_POINT_set_affine_coordinates(group, P, x, yplusone, ctx)) || !TEST_int_eq(EC_GROUP_get_degree(group), 521) - || !TEST_int_eq(EC_GROUP_security_bits(group), 256) || !group_order_tests(group) /* more tests using the last curve */ @@ -618,7 +612,6 @@ static struct c2_curve_test { const char *order; const char *cof; int degree; - int security; } char2_curve_tests[] = { /* Curve K-163 (FIPS PUB 186-2, App. 6) */ { @@ -628,7 +621,7 @@ static struct c2_curve_test { "1", "02FE13C0537BBC11ACAA07D793DE4E6D5E5C94EEE8", "0289070FB05D38FF58321F2E800536D538CCDAA3D9", - 1, "04000000000000000000020108A2E0CC0D99F8A5EF", "2", 163, 80 }, + 1, "04000000000000000000020108A2E0CC0D99F8A5EF", "2", 163 }, /* Curve B-163 (FIPS PUB 186-2, App. 6) */ { "NIST curve B-163", @@ -637,7 +630,7 @@ static struct c2_curve_test { "020A601907B8C953CA1481EB10512F78744A3205FD", "03F0EBA16286A2D57EA0991168D4994637E8343E36", "00D51FBC6C71A0094FA2CDD545B11C5C0C797324F1", - 1, "040000000000000000000292FE77E70C12A4234C33", "2", 163, 80 }, + 1, "040000000000000000000292FE77E70C12A4234C33", "2", 163 }, /* Curve K-233 (FIPS PUB 186-2, App. 6) */ { "NIST curve K-233", @@ -648,7 +641,7 @@ static struct c2_curve_test { "01DB537DECE819B7F70F555A67C427A8CD9BF18AEB9B56E0C11056FAE6A3", 0, "008000000000000000000000000000069D5BB915BCD46EFB1AD5F173ABDF", - "4", 233, 112 }, + "4", 233 }, /* Curve B-233 (FIPS PUB 186-2, App. 6) */ { "NIST curve B-233", @@ -659,7 +652,7 @@ static struct c2_curve_test { "01006A08A41903350678E58528BEBF8A0BEFF867A7CA36716F7E01F81052", 1, "01000000000000000000000000000013E974E72F8A6922031D2603CFE0D7", - "2", 233, 112 }, + "2", 233 }, /* Curve K-283 (FIPS PUB 186-2, App. 6) */ { "NIST curve K-283", @@ -674,7 +667,7 @@ static struct c2_curve_test { 0, "01FFFFFF" "FFFFFFFFFFFFFFFFFFFFFFFFFFFFE9AE2ED07577265DFF7F94451E061E163C61", - "4", 283, 128 }, + "4", 283 }, /* Curve B-283 (FIPS PUB 186-2, App. 6) */ { "NIST curve B-283", @@ -691,7 +684,7 @@ static struct c2_curve_test { 1, "03FFFFFF" "FFFFFFFFFFFFFFFFFFFFFFFFFFFFEF90399660FC938A90165B042A7CEFADB307", - "2", 283, 128 }, + "2", 283 }, /* Curve K-409 (FIPS PUB 186-2, App. 6) */ { "NIST curve K-409", @@ -706,7 +699,7 @@ static struct c2_curve_test { 1, "007FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF" "FFFFFFFFFFFFFE5F83B2D4EA20400EC4557D5ED3E3E7CA5B4B5C83B8E01E5FCF", - "4", 409, 192 }, + "4", 409 }, /* Curve B-409 (FIPS PUB 186-2, App. 6) */ { "NIST curve B-409", @@ -723,7 +716,7 @@ static struct c2_curve_test { 1, "0100000000000000000000000000000000000000" "00000000000001E2AAD6A612F33307BE5FA47C3C9E052F838164CD37D9A21173", - "2", 409, 192 }, + "2", 409 }, /* Curve K-571 (FIPS PUB 186-2, App. 6) */ { "NIST curve K-571", @@ -742,7 +735,7 @@ static struct c2_curve_test { "0200000000000000" "00000000000000000000000000000000000000000000000000000000131850E1" "F19A63E4B391A8DB917F4138B630D84BE5D639381E91DEB45CFE778F637C1001", - "4", 571, 256 }, + "4", 571 }, /* Curve B-571 (FIPS PUB 186-2, App. 6) */ { "NIST curve B-571", @@ -765,7 +758,7 @@ static struct c2_curve_test { "03FFFFFFFFFFFFFF" "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFE661CE18" "FF55987308059B186823851EC7DD9CA1161DE93D5174D66E8382E9BB2FE84E47", - "2", 571, 256 } + "2", 571 } }; static int char2_curve_test(int n) @@ -802,22 +795,37 @@ static int char2_curve_test(int n) || !TEST_true(BN_add(yplusone, y, BN_value_one()))) goto err; +/* Change test based on whether binary point compression is enabled or not. */ +#ifdef OPENSSL_EC_BIN_PT_COMP + /* + * When (x, y) is on the curve, (x, y + 1) is, as it happens, not, + * and therefore setting the coordinates should fail. + */ + if (!TEST_false(EC_POINT_set_affine_coordinates(group, P, x, yplusone, ctx)) + || !TEST_true(EC_POINT_set_compressed_coordinates(group, P, x, + test->y_bit, + ctx)) + || !TEST_int_gt(EC_POINT_is_on_curve(group, P, ctx), 0) + || !TEST_true(BN_hex2bn(&z, test->order)) + || !TEST_true(BN_hex2bn(&cof, test->cof)) + || !TEST_true(EC_GROUP_set_generator(group, P, z, cof)) + || !TEST_true(EC_POINT_get_affine_coordinates(group, P, x, y, ctx))) + goto err; + TEST_info("%s -- Generator", test->name); + test_output_bignum("x", x); + test_output_bignum("y", y); + /* G_y value taken from the standard: */ + if (!TEST_true(BN_hex2bn(&z, test->y)) + || !TEST_BN_eq(y, z)) + goto err; +#else /* * When (x, y) is on the curve, (x, y + 1) is, as it happens, not, * and therefore setting the coordinates should fail. - * - * Set the generator point P from its affine coordinates, and - * independently recover the same point Q from x and the y-bit via - * compressed coordinates. The two must agree, which exercises both - * the affine and compressed binary point formats in a single pass. */ if (!TEST_false(EC_POINT_set_affine_coordinates(group, P, x, yplusone, ctx)) || !TEST_true(EC_POINT_set_affine_coordinates(group, P, x, y, ctx)) || !TEST_int_gt(EC_POINT_is_on_curve(group, P, ctx), 0) - || !TEST_true(EC_POINT_set_compressed_coordinates(group, Q, x, - test->ybit, ctx)) - || !TEST_int_gt(EC_POINT_is_on_curve(group, Q, ctx), 0) - || !TEST_int_eq(0, EC_POINT_cmp(group, P, Q, ctx)) || !TEST_true(BN_hex2bn(&z, test->order)) || !TEST_true(BN_hex2bn(&cof, test->cof)) || !TEST_true(EC_GROUP_set_generator(group, P, z, cof))) @@ -825,9 +833,9 @@ static int char2_curve_test(int n) TEST_info("%s -- Generator:", test->name); test_output_bignum("x", x); test_output_bignum("y", y); +#endif if (!TEST_int_eq(EC_GROUP_get_degree(group), test->degree) - || !TEST_int_eq(EC_GROUP_security_bits(group), test->security) || !group_order_tests(group)) goto err; @@ -955,19 +963,26 @@ static int char2_field_tests(void) || !TEST_ptr(cof = BN_new()) || !TEST_ptr(yplusone = BN_new()) || !TEST_true(BN_hex2bn(&x, "6")) +/* Change test based on whether binary point compression is enabled or not. */ +#ifdef OPENSSL_EC_BIN_PT_COMP + || !TEST_true(EC_POINT_set_compressed_coordinates(group, Q, x, 1, ctx)) +#else || !TEST_true(BN_hex2bn(&y, "8")) - || !TEST_true(EC_POINT_set_affine_coordinates(group, Q, x, y, ctx))) + || !TEST_true(EC_POINT_set_affine_coordinates(group, Q, x, y, ctx)) +#endif + ) goto err; if (!TEST_int_gt(EC_POINT_is_on_curve(group, Q, ctx), 0)) { +/* Change test based on whether binary point compression is enabled or not. */ +#ifdef OPENSSL_EC_BIN_PT_COMP + if (!TEST_true(EC_POINT_get_affine_coordinates(group, Q, x, y, ctx))) + goto err; +#endif TEST_info("Point is not on curve"); test_output_bignum("x", x); test_output_bignum("y", y); goto err; } - /* The same point recovered from compressed coordinates must agree. */ - if (!TEST_true(EC_POINT_set_compressed_coordinates(group, R, x, 1, ctx)) - || !TEST_int_eq(0, EC_POINT_cmp(group, R, Q, ctx))) - goto err; TEST_note("A cyclic subgroup:"); k = 100; @@ -995,6 +1010,8 @@ static int char2_field_tests(void) || !TEST_true(EC_POINT_is_at_infinity(group, P))) goto err; +/* Change test based on whether binary point compression is enabled or not. */ +#ifdef OPENSSL_EC_BIN_PT_COMP len = EC_POINT_point2oct(group, Q, POINT_CONVERSION_COMPRESSED, buf, sizeof(buf), ctx); if (!TEST_size_t_ne(len, 0) @@ -1003,6 +1020,7 @@ static int char2_field_tests(void) goto err; test_output_memory("Generator as octet string, compressed form:", buf, len); +#endif len = EC_POINT_point2oct(group, Q, POINT_CONVERSION_UNCOMPRESSED, buf, sizeof(buf), ctx); @@ -1013,6 +1031,8 @@ static int char2_field_tests(void) test_output_memory("Generator as octet string, uncompressed form:", buf, len); +/* Change test based on whether binary point compression is enabled or not. */ +#ifdef OPENSSL_EC_BIN_PT_COMP len = EC_POINT_point2oct(group, Q, POINT_CONVERSION_HYBRID, buf, sizeof(buf), ctx); if (!TEST_size_t_ne(len, 0) @@ -1021,6 +1041,7 @@ static int char2_field_tests(void) goto err; test_output_memory("Generator as octet string, hybrid form:", buf, len); +#endif if (!TEST_true(EC_POINT_invert(group, P, ctx)) || !TEST_int_eq(0, EC_POINT_cmp(group, P, R, ctx))) @@ -1127,18 +1148,16 @@ static int group_field_test(void) EC_GROUP *secp521r1_group = NULL; EC_GROUP *sect163r2_group = NULL; - if (!TEST_true(BN_hex2bn(&secp521r1_field, - "01FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF" - "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF" - "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF" - "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF" - "FFFF")) - || !TEST_true(BN_hex2bn(§163r2_field, - "08000000000000000000000000000000" - "00000000C9"))) { - BN_free(secp521r1_field); - return 0; - } + BN_hex2bn(&secp521r1_field, + "01FFFFFFFFFFFFFFFFFFFFFFFFFFFFFF" + "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF" + "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF" + "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF" + "FFFF"); + + BN_hex2bn(§163r2_field, + "08000000000000000000000000000000" + "00000000C9"); secp521r1_group = EC_GROUP_new_by_curve_name(NID_secp521r1); if (BN_cmp(secp521r1_field, EC_GROUP_get0_field(secp521r1_group))) @@ -1164,7 +1183,6 @@ static int group_field_test(void) struct nistp_test_params { const int nid; int degree; - int security; /* * Qx, Qy and D are taken from * http://csrc.nist.gov/groups/ST/toolkit/documents/Examples/ECDSA_Prime.pdf @@ -1178,7 +1196,6 @@ static const struct nistp_test_params nistp_tests_params[] = { /* P-224 */ NID_secp224r1, 224, - 112, /* p */ "FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000000000000001", /* a */ @@ -1202,7 +1219,6 @@ static const struct nistp_test_params nistp_tests_params[] = { /* P-256 */ NID_X9_62_prime256v1, 256, - 128, /* p */ "ffffffff00000001000000000000000000000000ffffffffffffffffffffffff", /* a */ @@ -1226,7 +1242,6 @@ static const struct nistp_test_params nistp_tests_params[] = { /* P-521 */ NID_secp521r1, 521, - 256, /* p */ "1ff" "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff" @@ -1315,8 +1330,7 @@ static int nistp_single_test(int idx) || !TEST_true(EC_POINT_set_affine_coordinates(NISTP, G, x, y, ctx)) || !TEST_true(BN_hex2bn(&order, test->order)) || !TEST_true(EC_GROUP_set_generator(NISTP, G, order, BN_value_one())) - || !TEST_int_eq(EC_GROUP_get_degree(NISTP), test->degree) - || !TEST_int_eq(EC_GROUP_security_bits(NISTP), test->security)) + || !TEST_int_eq(EC_GROUP_get_degree(NISTP), test->degree)) goto err; TEST_note("NIST test vectors ... "); @@ -1404,56 +1418,471 @@ err: } static const unsigned char p521_named[] = { - 0x06, 0x05, 0x2b, 0x81, 0x04, 0x00, 0x23 + 0x06, + 0x05, + 0x2b, + 0x81, + 0x04, + 0x00, + 0x23, }; static const unsigned char p521_explicit[] = { - 0x30, 0x82, 0x01, 0xc3, 0x02, 0x01, 0x01, 0x30, 0x4d, 0x06, - 0x07, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x01, 0x01, 0x02, 0x42, - 0x01, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0x30, 0x81, 0x9f, 0x04, - 0x42, 0x01, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfc, 0x04, 0x42, 0x00, - 0x51, 0x95, 0x3e, 0xb9, 0x61, 0x8e, 0x1c, 0x9a, 0x1f, 0x92, - 0x9a, 0x21, 0xa0, 0xb6, 0x85, 0x40, 0xee, 0xa2, 0xda, 0x72, - 0x5b, 0x99, 0xb3, 0x15, 0xf3, 0xb8, 0xb4, 0x89, 0x91, 0x8e, - 0xf1, 0x09, 0xe1, 0x56, 0x19, 0x39, 0x51, 0xec, 0x7e, 0x93, - 0x7b, 0x16, 0x52, 0xc0, 0xbd, 0x3b, 0xb1, 0xbf, 0x07, 0x35, - 0x73, 0xdf, 0x88, 0x3d, 0x2c, 0x34, 0xf1, 0xef, 0x45, 0x1f, - 0xd4, 0x6b, 0x50, 0x3f, 0x00, 0x03, 0x15, 0x00, 0xd0, 0x9e, - 0x88, 0x00, 0x29, 0x1c, 0xb8, 0x53, 0x96, 0xcc, 0x67, 0x17, - 0x39, 0x32, 0x84, 0xaa, 0xa0, 0xda, 0x64, 0xba, 0x04, 0x81, - 0x85, 0x04, 0x00, 0xc6, 0x85, 0x8e, 0x06, 0xb7, 0x04, 0x04, - 0xe9, 0xcd, 0x9e, 0x3e, 0xcb, 0x66, 0x23, 0x95, 0xb4, 0x42, - 0x9c, 0x64, 0x81, 0x39, 0x05, 0x3f, 0xb5, 0x21, 0xf8, 0x28, - 0xaf, 0x60, 0x6b, 0x4d, 0x3d, 0xba, 0xa1, 0x4b, 0x5e, 0x77, - 0xef, 0xe7, 0x59, 0x28, 0xfe, 0x1d, 0xc1, 0x27, 0xa2, 0xff, - 0xa8, 0xde, 0x33, 0x48, 0xb3, 0xc1, 0x85, 0x6a, 0x42, 0x9b, - 0xf9, 0x7e, 0x7e, 0x31, 0xc2, 0xe5, 0xbd, 0x66, 0x01, 0x18, - 0x39, 0x29, 0x6a, 0x78, 0x9a, 0x3b, 0xc0, 0x04, 0x5c, 0x8a, - 0x5f, 0xb4, 0x2c, 0x7d, 0x1b, 0xd9, 0x98, 0xf5, 0x44, 0x49, - 0x57, 0x9b, 0x44, 0x68, 0x17, 0xaf, 0xbd, 0x17, 0x27, 0x3e, - 0x66, 0x2c, 0x97, 0xee, 0x72, 0x99, 0x5e, 0xf4, 0x26, 0x40, - 0xc5, 0x50, 0xb9, 0x01, 0x3f, 0xad, 0x07, 0x61, 0x35, 0x3c, - 0x70, 0x86, 0xa2, 0x72, 0xc2, 0x40, 0x88, 0xbe, 0x94, 0x76, - 0x9f, 0xd1, 0x66, 0x50, 0x02, 0x42, 0x01, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, - 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xff, 0xfa, - 0x51, 0x86, 0x87, 0x83, 0xbf, 0x2f, 0x96, 0x6b, 0x7f, 0xcc, - 0x01, 0x48, 0xf7, 0x09, 0xa5, 0xd0, 0x3b, 0xb5, 0xc9, 0xb8, - 0x89, 0x9c, 0x47, 0xae, 0xbb, 0x6f, 0xb7, 0x1e, 0x91, 0x38, - 0x64, 0x09, 0x02, 0x01, 0x01 + 0x30, + 0x82, + 0x01, + 0xc3, + 0x02, + 0x01, + 0x01, + 0x30, + 0x4d, + 0x06, + 0x07, + 0x2a, + 0x86, + 0x48, + 0xce, + 0x3d, + 0x01, + 0x01, + 0x02, + 0x42, + 0x01, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0x30, + 0x81, + 0x9f, + 0x04, + 0x42, + 0x01, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xfc, + 0x04, + 0x42, + 0x00, + 0x51, + 0x95, + 0x3e, + 0xb9, + 0x61, + 0x8e, + 0x1c, + 0x9a, + 0x1f, + 0x92, + 0x9a, + 0x21, + 0xa0, + 0xb6, + 0x85, + 0x40, + 0xee, + 0xa2, + 0xda, + 0x72, + 0x5b, + 0x99, + 0xb3, + 0x15, + 0xf3, + 0xb8, + 0xb4, + 0x89, + 0x91, + 0x8e, + 0xf1, + 0x09, + 0xe1, + 0x56, + 0x19, + 0x39, + 0x51, + 0xec, + 0x7e, + 0x93, + 0x7b, + 0x16, + 0x52, + 0xc0, + 0xbd, + 0x3b, + 0xb1, + 0xbf, + 0x07, + 0x35, + 0x73, + 0xdf, + 0x88, + 0x3d, + 0x2c, + 0x34, + 0xf1, + 0xef, + 0x45, + 0x1f, + 0xd4, + 0x6b, + 0x50, + 0x3f, + 0x00, + 0x03, + 0x15, + 0x00, + 0xd0, + 0x9e, + 0x88, + 0x00, + 0x29, + 0x1c, + 0xb8, + 0x53, + 0x96, + 0xcc, + 0x67, + 0x17, + 0x39, + 0x32, + 0x84, + 0xaa, + 0xa0, + 0xda, + 0x64, + 0xba, + 0x04, + 0x81, + 0x85, + 0x04, + 0x00, + 0xc6, + 0x85, + 0x8e, + 0x06, + 0xb7, + 0x04, + 0x04, + 0xe9, + 0xcd, + 0x9e, + 0x3e, + 0xcb, + 0x66, + 0x23, + 0x95, + 0xb4, + 0x42, + 0x9c, + 0x64, + 0x81, + 0x39, + 0x05, + 0x3f, + 0xb5, + 0x21, + 0xf8, + 0x28, + 0xaf, + 0x60, + 0x6b, + 0x4d, + 0x3d, + 0xba, + 0xa1, + 0x4b, + 0x5e, + 0x77, + 0xef, + 0xe7, + 0x59, + 0x28, + 0xfe, + 0x1d, + 0xc1, + 0x27, + 0xa2, + 0xff, + 0xa8, + 0xde, + 0x33, + 0x48, + 0xb3, + 0xc1, + 0x85, + 0x6a, + 0x42, + 0x9b, + 0xf9, + 0x7e, + 0x7e, + 0x31, + 0xc2, + 0xe5, + 0xbd, + 0x66, + 0x01, + 0x18, + 0x39, + 0x29, + 0x6a, + 0x78, + 0x9a, + 0x3b, + 0xc0, + 0x04, + 0x5c, + 0x8a, + 0x5f, + 0xb4, + 0x2c, + 0x7d, + 0x1b, + 0xd9, + 0x98, + 0xf5, + 0x44, + 0x49, + 0x57, + 0x9b, + 0x44, + 0x68, + 0x17, + 0xaf, + 0xbd, + 0x17, + 0x27, + 0x3e, + 0x66, + 0x2c, + 0x97, + 0xee, + 0x72, + 0x99, + 0x5e, + 0xf4, + 0x26, + 0x40, + 0xc5, + 0x50, + 0xb9, + 0x01, + 0x3f, + 0xad, + 0x07, + 0x61, + 0x35, + 0x3c, + 0x70, + 0x86, + 0xa2, + 0x72, + 0xc2, + 0x40, + 0x88, + 0xbe, + 0x94, + 0x76, + 0x9f, + 0xd1, + 0x66, + 0x50, + 0x02, + 0x42, + 0x01, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xff, + 0xfa, + 0x51, + 0x86, + 0x87, + 0x83, + 0xbf, + 0x2f, + 0x96, + 0x6b, + 0x7f, + 0xcc, + 0x01, + 0x48, + 0xf7, + 0x09, + 0xa5, + 0xd0, + 0x3b, + 0xb5, + 0xc9, + 0xb8, + 0x89, + 0x9c, + 0x47, + 0xae, + 0xbb, + 0x6f, + 0xb7, + 0x1e, + 0x91, + 0x38, + 0x64, + 0x09, + 0x02, + 0x01, + 0x01, }; /* @@ -2113,7 +2542,6 @@ err: return r; } -#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES /*- * random 256-bit explicit parameters curve, cofactor absent * order: 0x0c38d96a9f892b88772ec2e39614a82f4f (132 bit) @@ -2203,7 +2631,6 @@ err: EC_GROUP_free(group); return ret; } -#endif /*- * For named curves, test that: @@ -2447,27 +2874,22 @@ err: static int do_test_custom_explicit_fromdata(EC_GROUP *group, BN_CTX *ctx, unsigned char *gen, size_t gen_size) { - int ret = 0; + int ret = 0, i_out; EVP_PKEY_CTX *pctx = NULL; EVP_PKEY *pkeyparam = NULL; OSSL_PARAM_BLD *bld = NULL; const char *field_name; OSSL_PARAM *params = NULL; + const OSSL_PARAM *gettable; BIGNUM *p, *a, *b; BIGNUM *p_out = NULL, *a_out = NULL, *b_out = NULL; BIGNUM *order_out = NULL, *cofactor_out = NULL; -#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES - const OSSL_PARAM *gettable; - int i_out; char name[80]; unsigned char buf[1024]; size_t buf_len, name_len; -#ifndef OPENSSL_NO_EC2M - const char *basis_name = NULL; -#endif -#endif #ifndef OPENSSL_NO_EC2M unsigned int k1 = 0, k2 = 0, k3 = 0; + const char *basis_name = NULL; #endif p = BN_CTX_get(ctx); @@ -2484,15 +2906,11 @@ static int do_test_custom_explicit_fromdata(EC_GROUP *group, BN_CTX *ctx, field_name = SN_X9_62_characteristic_two_field; #ifndef OPENSSL_NO_EC2M if (EC_GROUP_get_basis_type(group) == NID_X9_62_tpBasis) { -#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES basis_name = SN_X9_62_tpBasis; -#endif if (!TEST_true(EC_GROUP_get_trinomial_basis(group, &k1))) goto err; } else { -#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES basis_name = SN_X9_62_ppBasis; -#endif if (!TEST_true(EC_GROUP_get_pentanomial_basis(group, &k1, &k2, &k3))) goto err; } @@ -2527,19 +2945,11 @@ static int do_test_custom_explicit_fromdata(EC_GROUP *group, BN_CTX *ctx, if (!TEST_ptr(params = OSSL_PARAM_BLD_to_param(bld)) || !TEST_ptr(pctx = EVP_PKEY_CTX_new_from_name(NULL, "EC", NULL)) || !TEST_int_gt(EVP_PKEY_fromdata_init(pctx), 0) -#ifdef OPENSSL_NO_EC_EXPLICIT_CURVES - || !TEST_int_le(EVP_PKEY_fromdata(pctx, &pkeyparam, - EVP_PKEY_KEY_PARAMETERS, params), - 0) -#else || !TEST_int_gt(EVP_PKEY_fromdata(pctx, &pkeyparam, EVP_PKEY_KEY_PARAMETERS, params), - 0) -#endif - ) + 0)) goto err; -#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES /*- Check that all the set values are retrievable -*/ /* There should be no match to a group name since the generator changed */ @@ -2593,11 +3003,6 @@ static int do_test_custom_explicit_fromdata(EC_GROUP *group, BN_CTX *ctx, goto err; } - if (!TEST_true(EVP_PKEY_get_int_param(pkeyparam, - OSSL_PKEY_PARAM_EC_FIELD_DEGREE, &i_out)) - || !TEST_int_eq(EC_GROUP_get_degree(group), i_out)) - goto err; - if (EC_GROUP_get_field_type(group) == NID_X9_62_prime_field) { /* No extra fields should be set for a prime field */ if (!TEST_false(EVP_PKEY_get_int_param(pkeyparam, @@ -2673,7 +3078,6 @@ static int do_test_custom_explicit_fromdata(EC_GROUP *group, BN_CTX *ctx, #endif ) goto err; -#endif ret = 1; err: BN_free(order_out); @@ -2796,15 +3200,12 @@ static int custom_params_test(int id) EC_KEY *eckey1 = NULL, *eckey2 = NULL; EVP_PKEY *pkey1 = NULL, *pkey2 = NULL; EVP_PKEY_CTX *pctx1 = NULL, *pctx2 = NULL, *dctx = NULL; - size_t bsize; + size_t sslen, t, bsize; unsigned char *pub1 = NULL, *pub2 = NULL; OSSL_PARAM_BLD *param_bld = NULL; OSSL_PARAM *params1 = NULL, *params2 = NULL; -#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES const unsigned char *export = NULL; size_t export_size = 0; - size_t sslen, t; -#endif EVP_SKEY *skey = NULL; /* Do some setup */ @@ -2972,16 +3373,6 @@ static int custom_params_test(int id) goto err; eckey2 = NULL; /* ownership passed to pkey2 */ -#ifdef OPENSSL_NO_EC_EXPLICIT_CURVES - /* Compute keyexchange in both directions - fail with custom params */ - if (!TEST_ptr(pctx1 = EVP_PKEY_CTX_new(pkey1, NULL)) - || !TEST_int_le(EVP_PKEY_derive_init(pctx1), 0)) - goto err; - if (!TEST_ptr(pctx2 = EVP_PKEY_CTX_new(pkey2, NULL)) - || !TEST_int_le(EVP_PKEY_derive_init(pctx2), 0)) - goto err; - -#else /* Compute keyexchange in both directions */ if (!TEST_ptr(pctx1 = EVP_PKEY_CTX_new(pkey1, NULL)) || !TEST_int_eq(EVP_PKEY_derive_init(pctx1), 1) @@ -3065,7 +3456,7 @@ static int custom_params_test(int id) /* compare with previous result */ || !TEST_mem_eq(export, export_size, buf2, sslen)) goto err; -#endif + ret = 1; err: @@ -3102,7 +3493,7 @@ static int ec_d2i_publickey_test(void) const unsigned char *pk_enc = pubkey_enc; EVP_PKEY *gen_key = NULL, *decoded_key = NULL; EVP_PKEY_CTX *pctx = NULL; - int pklen, i_out = 0, ret = 0; + int pklen, ret = 0; OSSL_PARAM params[2]; if (!TEST_ptr(gen_key = EVP_EC_gen("P-256"))) @@ -3125,15 +3516,8 @@ static int ec_d2i_publickey_test(void) &pk_enc, pklen))) goto err; - if (!TEST_true(EVP_PKEY_eq(gen_key, decoded_key)) - || !TEST_true(EVP_PKEY_get_int_param(gen_key, - OSSL_PKEY_PARAM_EC_FIELD_DEGREE, &i_out)) - || !TEST_int_eq(i_out, 256) - || !TEST_true(EVP_PKEY_get_int_param(decoded_key, - OSSL_PKEY_PARAM_EC_FIELD_DEGREE, &i_out)) - || !TEST_int_eq(i_out, 256)) + if (!TEST_true(EVP_PKEY_eq(gen_key, decoded_key))) goto err; - ret = 1; err: @@ -3152,9 +3536,7 @@ int setup_tests(void) ADD_TEST(parameter_test); ADD_TEST(ossl_parameter_test); -#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES ADD_TEST(cofactor_range_test); -#endif ADD_ALL_TESTS(cardinality_test, (int)crv_len); ADD_TEST(prime_field_tests); #ifndef OPENSSL_NO_EC2M diff --git a/test/endecode_test.c b/test/endecode_test.c index a2c5d4009d..6081ef5d0b 100644 --- a/test/endecode_test.c +++ b/test/endecode_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -33,8 +33,8 @@ OSSL_provider_init_fn ossl_legacy_provider_init; /* Extended test macros to allow passing file & line number */ #define TEST_FL_ptr(a) test_ptr(file, line, #a, a) #define TEST_FL_mem_eq(a, m, b, n) test_mem_eq(file, line, #a, #b, a, m, b, n) -#define TEST_FL_strn_eq(a, b, n) test_strn_eq(file, line, #a, #b, a, b, n) -#define TEST_FL_size_t_eq(a, b) test_size_t_eq(file, line, #a, #b, a, b) +#define TEST_FL_strn_eq(a, b, n) test_strn_eq(file, line, #a, #b, a, n, b, n) +#define TEST_FL_strn2_eq(a, m, b, n) test_strn_eq(file, line, #a, #b, a, m, b, n) #define TEST_FL_int_eq(a, b) test_int_eq(file, line, #a, #b, a, b) #define TEST_FL_int_ge(a, b) test_int_ge(file, line, #a, #b, a, b) #define TEST_FL_int_gt(a, b) test_int_gt(file, line, #a, #b, a, b) @@ -60,7 +60,6 @@ static OSSL_PROVIDER *keyprov = NULL; #ifndef OPENSSL_NO_EC static BN_CTX *bnctx = NULL; -#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES static OSSL_PARAM_BLD *bld_prime_nc = NULL; static OSSL_PARAM_BLD *bld_prime = NULL; static OSSL_PARAM *ec_explicit_prime_params_nc = NULL; @@ -73,7 +72,6 @@ static OSSL_PARAM *ec_explicit_tri_params_nc = NULL; static OSSL_PARAM *ec_explicit_tri_params_explicit = NULL; #endif #endif -#endif #ifndef OPENSSL_NO_KEYPARAMS static EVP_PKEY *make_template(const char *type, OSSL_PARAM *genparams) @@ -509,8 +507,7 @@ static int test_text(const char *file, const int line, const void *data1, size_t data1_len, const void *data2, size_t data2_len) { - return TEST_FL_size_t_eq(data1_len, data2_len) - && TEST_FL_strn_eq(data1, data2, data1_len); + return TEST_FL_strn2_eq(data1, data1_len, data2, data2_len); } static int test_mem(const char *file, const int line, @@ -832,7 +829,7 @@ static int test_protected_via_legacy_PEM(const char *type, EVP_PKEY *key) dump_pem, 0); } -#if !defined(OPENSSL_NO_RC4) && !defined(OPENSSL_NO_PVKKDF) +#ifndef OPENSSL_NO_RC4 static int test_protected_via_PVK(const char *type, EVP_PKEY *key) { int ret = 0; @@ -914,403 +911,21 @@ static int test_public_via_MSBLOB(const char *type, EVP_PKEY *key) test_mem, check_public_MSBLOB, dump_der, 0); } -/* - * Build a public-only EVP_PKEY of the same algorithm as |src| by - * round-tripping the public component through OSSL_PARAMs. - */ -static EVP_PKEY *make_public_only_copy(EVP_PKEY *src) -{ - OSSL_PARAM *params = NULL; - EVP_PKEY_CTX *cctx = NULL; - EVP_PKEY *pub = NULL; - - if (!EVP_PKEY_todata(src, EVP_PKEY_PUBLIC_KEY, ¶ms)) - goto end; - if ((cctx = EVP_PKEY_CTX_new_from_pkey(NULL, src, NULL)) == NULL - || EVP_PKEY_fromdata_init(cctx) <= 0 - || EVP_PKEY_fromdata(cctx, &pub, EVP_PKEY_PUBLIC_KEY, params) <= 0) { - EVP_PKEY_free(pub); - pub = NULL; - } -end: - OSSL_PARAM_free(params); - EVP_PKEY_CTX_free(cctx); - return pub; -} - -/* - * Build an "embryonic" EVP_PKEY of the same algorithm as |src|: just - * the keymgmt-bound type and (where applicable) domain parameters - * copied across, with no key material. Mirrors the idiom used in - * test/ml_kem_evp_extra_test.c. - */ -static EVP_PKEY *make_embryonic_copy(EVP_PKEY *src) -{ - EVP_PKEY *embryo = EVP_PKEY_new(); - - if (embryo == NULL) - return NULL; - if (EVP_PKEY_copy_parameters(embryo, src) <= 0) { - EVP_PKEY_free(embryo); - return NULL; - } - return embryo; -} - -/* - * Check that EVP_PKEY_dup() works for every supported provider-backed - * key type, and that the duplicate compares equal to the original. - * - * Exercised in three shapes: - * 1. The full keypair |key| (typically pub + priv). - * 2. A public-only key derived from |key|. - * 3. An "embryonic" key (algorithm + domain parameters only, no key - * material) produced with EVP_PKEY_copy_parameters(). - */ -static int test_dup(const char *type, EVP_PKEY *key) -{ - EVP_PKEY *dup = NULL; - EVP_PKEY *pub_only = NULL; - EVP_PKEY *embryo = NULL; - int ok = 0; - - if (!TEST_ptr(key)) { - TEST_info("%s: no source key", type); - return 0; - } - - /* 1. Dup the full keypair. */ - if (!TEST_ptr(dup = EVP_PKEY_dup(key))) { - TEST_info("%s: EVP_PKEY_dup of keypair returned NULL", type); - goto end; - } - if (!TEST_int_eq(EVP_PKEY_eq(key, dup), 1)) { - TEST_info("%s: keypair dup does not compare equal to original", type); - goto end; - } - EVP_PKEY_free(dup); - dup = NULL; - - /* 2. Dup a public-only copy of the same key. */ - if (!TEST_ptr(pub_only = make_public_only_copy(key))) { - TEST_info("%s: could not derive a public-only key", type); - goto end; - } - if (!TEST_ptr(dup = EVP_PKEY_dup(pub_only))) { - TEST_info("%s: EVP_PKEY_dup of public-only key returned NULL", type); - goto end; - } - if (!TEST_int_eq(EVP_PKEY_eq(pub_only, dup), 1)) { - TEST_info("%s: public-only dup does not compare equal to original", - type); - goto end; - } - EVP_PKEY_free(dup); - dup = NULL; - - /* - * 3. Dup an embryonic key (algorithm + domain parameters only, - * no key bits). Some keymgmts (RSA, RSA-PSS) refuse to build - * such a key via EVP_PKEY_copy_parameters(); treat that as a - * graceful skip. Where an embryo can be built we compare via - * EVP_PKEY_parameters_eq() since EVP_PKEY_eq() requires key - * bits to match. Algorithms with no domain parameters may - * legitimately answer -2 ("nothing to compare"). - */ - embryo = make_embryonic_copy(key); - if (embryo != NULL) { - if (!TEST_ptr(dup = EVP_PKEY_dup(embryo))) { - TEST_info("%s: EVP_PKEY_dup of embryonic key returned NULL", - type); - goto end; - } - { - int eq = EVP_PKEY_parameters_eq(embryo, dup); - - if (!TEST_true(eq == 1 || eq == -2)) { - TEST_info("%s: embryonic dup parameters_eq %d (want 1 or -2)", - type, eq); - goto end; - } - } - } else { - TEST_info("%s: skipping embryonic dup (no params-only key shape)", - type); - } - - ok = 1; -end: - EVP_PKEY_free(dup); - EVP_PKEY_free(pub_only); - EVP_PKEY_free(embryo); - return ok; -} - -/* - * Drive EVP_PKEY_fromdata with the supplied OSSL_PARAM[] (NULL = - * empty array) for the given selection. Either outcome is accepted: - * fromdata may reject the input, or it may succeed and yield a key - * with at most algorithm-bound parameters. In the success case a - * battery of common consumer ops must not crash on the resulting - * key; their return values are not asserted. - */ -static int run_empty_fromdata_probe(const char *type, EVP_PKEY_CTX *cctx, - int selection, OSSL_PARAM *params, const char *selname) -{ - EVP_PKEY *pkey = NULL; - OSSL_PARAM empty[1]; - int r; - int ok = 0; - - if (params == NULL) { - empty[0] = OSSL_PARAM_construct_end(); - params = empty; - } - - if (!TEST_int_gt(EVP_PKEY_fromdata_init(cctx), 0)) { - TEST_info("%s: fromdata_init failed (%s)", type, selname); - goto end; - } - r = EVP_PKEY_fromdata(cctx, &pkey, selection, params); - if (r <= 0) { - /* Rejection is fine, but the out-pointer must remain NULL. */ - if (!TEST_ptr_null(pkey)) { - TEST_info("%s: fromdata returned %d but pkey != NULL (%s)", - type, r, selname); - goto end; - } - ok = 1; - goto end; - } - if (!TEST_ptr(pkey)) { - TEST_info("%s: fromdata returned %d but pkey == NULL (%s)", - type, r, selname); - goto end; - } - /* - * Walk a battery of common consumer ops on the resulting key. - * Their return values are not asserted - a contentless key may - * fail every op - only crashing is forbidden. - */ - (void)EVP_PKEY_get_bits(pkey); - (void)EVP_PKEY_get_security_bits(pkey); - (void)EVP_PKEY_get_size(pkey); - (void)EVP_PKEY_eq(pkey, pkey); - (void)EVP_PKEY_parameters_eq(pkey, pkey); - { - OSSL_PARAM *out = NULL; - - if (EVP_PKEY_todata(pkey, selection, &out) > 0) - OSSL_PARAM_free(out); - } - { - EVP_PKEY *clone = EVP_PKEY_dup(pkey); - - EVP_PKEY_free(clone); - } - { - BIO *bio = BIO_new(BIO_s_null()); - - if (bio != NULL) { - (void)EVP_PKEY_print_public(bio, pkey, 0, NULL); - (void)EVP_PKEY_print_private(bio, pkey, 0, NULL); - (void)EVP_PKEY_print_params(bio, pkey, 0, NULL); - BIO_free(bio); - } - } - { - /* The param/public/private/pairwise check family. */ - EVP_PKEY_CTX *vctx = EVP_PKEY_CTX_new_from_pkey(NULL, pkey, NULL); - - if (vctx != NULL) { - (void)EVP_PKEY_param_check(vctx); - (void)EVP_PKEY_param_check_quick(vctx); - (void)EVP_PKEY_public_check(vctx); - (void)EVP_PKEY_public_check_quick(vctx); - (void)EVP_PKEY_private_check(vctx); - (void)EVP_PKEY_pairwise_check(vctx); - EVP_PKEY_CTX_free(vctx); - } - } - ok = 1; -end: - EVP_PKEY_free(pkey); - return ok; -} - -static int probe_empty_fromdata(const char *type, EVP_PKEY *prototype, - int selection, const char *selname) -{ - EVP_PKEY_CTX *cctx = NULL; - int ok = 0; - - if (!TEST_ptr(cctx = EVP_PKEY_CTX_new_from_pkey(NULL, prototype, NULL))) { - TEST_info("%s: CTX alloc failed for empty fromdata (%s)", - type, selname); - goto end; - } - ok = run_empty_fromdata_probe(type, cctx, selection, NULL, selname); -end: - EVP_PKEY_CTX_free(cctx); - return ok; -} - -/* - * Same probe driven from an algorithm name rather than a prototype - * key, for keymgmts without a keygen path (e.g. LMS). Algorithms - * not loadable under the active provider set are silently skipped. - * |params| may be NULL (= empty OSSL_PARAM[]) or a caller-built - * partial array. - */ -static int probe_fromdata_by_name(const char *name, int selection, - OSSL_PARAM *params, const char *selname) -{ - EVP_PKEY_CTX *cctx = NULL; - int ok = 1; - - cctx = EVP_PKEY_CTX_new_from_name(NULL, name, NULL); - if (cctx == NULL) - return 1; - ok = run_empty_fromdata_probe(name, cctx, selection, params, selname); - EVP_PKEY_CTX_free(cctx); - return ok; -} - -/* - * Drive EVP_PKEY_fromdata with an empty OSSL_PARAM[] for both - * EVP_PKEY_PUBLIC_KEY and EVP_PKEY_KEYPAIR selections. Either - * outcome is acceptable: fromdata rejects, or it succeeds and the - * resulting key survives the consumer-op battery without crashing. - */ -static int test_fromdata(const char *type, EVP_PKEY *prototype) -{ - if (!TEST_ptr(prototype)) { - TEST_info("%s: no prototype key", type); - return 0; - } - if (!probe_empty_fromdata(type, prototype, EVP_PKEY_PUBLIC_KEY, - "EVP_PKEY_PUBLIC_KEY")) - return 0; - if (!probe_empty_fromdata(type, prototype, EVP_PKEY_KEYPAIR, - "EVP_PKEY_KEYPAIR")) - return 0; - return 1; -} - -/* - * Companion to test_fromdata for keymgmts without a keygen path - * (LMS and similar verify-only / signature-only algorithms), plus - * named-group-only partial-shape variants for the prototype-matrix - * algorithms. Each entry is one (name, selection, params-builder) - * shape; a NULL builder means "use an empty OSSL_PARAM[]". - * Algorithms not loadable under the active provider set are - * silently skipped. - */ -typedef int (*fromdata_shape_build_fn)(OSSL_PARAM_BLD *bld); - -struct fromdata_shape { - const char *name; /* keymgmt algorithm name */ - int selection; /* EVP_PKEY_PUBLIC_KEY / KEYPAIR / etc. */ - fromdata_shape_build_fn build; /* NULL -> empty OSSL_PARAM[] */ - const char *label; /* diagnostic label */ -}; - -#ifndef OPENSSL_NO_DH -static int build_dh_named_group(OSSL_PARAM_BLD *bld) -{ - return OSSL_PARAM_BLD_push_utf8_string(bld, OSSL_PKEY_PARAM_GROUP_NAME, - "ffdhe2048", 0); -} -#endif - -#ifndef OPENSSL_NO_EC -static int build_ec_named_group(OSSL_PARAM_BLD *bld) -{ - return OSSL_PARAM_BLD_push_utf8_string(bld, OSSL_PKEY_PARAM_GROUP_NAME, - "P-256", 0); -} -#ifndef OPENSSL_NO_SM2 -static int build_sm2_named_group(OSSL_PARAM_BLD *bld) -{ - return OSSL_PARAM_BLD_push_utf8_string(bld, OSSL_PKEY_PARAM_GROUP_NAME, - "SM2", 0); -} -#endif -#endif - -static const struct fromdata_shape no_keygen_shapes[] = { - /* Empty OSSL_PARAM[] for LMS (no keygen path). */ - { "LMS", EVP_PKEY_PUBLIC_KEY, NULL, "LMS / empty / PUBLIC_KEY" }, - { "LMS", EVP_PKEY_KEYPAIR, NULL, "LMS / empty / KEYPAIR" }, -/* Named-group-only partial shapes. */ -#ifndef OPENSSL_NO_DH - { "DH", EVP_PKEY_KEYPAIR, build_dh_named_group, - "DH / named group only / KEYPAIR" }, - { "DH", EVP_PKEY_PUBLIC_KEY, build_dh_named_group, - "DH / named group only / PUBLIC_KEY" }, -#endif -#ifndef OPENSSL_NO_EC - { "EC", EVP_PKEY_KEYPAIR, build_ec_named_group, - "EC / group only / KEYPAIR" }, - { "EC", EVP_PKEY_PUBLIC_KEY, build_ec_named_group, - "EC / group only / PUBLIC_KEY" }, -#ifndef OPENSSL_NO_SM2 - { "SM2", EVP_PKEY_KEYPAIR, build_sm2_named_group, - "SM2 / group only / KEYPAIR" }, -#endif -#endif -}; - -static int test_fromdata_no_keygen(void) -{ - size_t i; - - for (i = 0; i < OSSL_NELEM(no_keygen_shapes); i++) { - const struct fromdata_shape *s = &no_keygen_shapes[i]; - OSSL_PARAM_BLD *bld = NULL; - OSSL_PARAM *params = NULL; - int ok; - - if (s->build != NULL) { - if (!TEST_ptr(bld = OSSL_PARAM_BLD_new())) - return 0; - if (!s->build(bld)) { - TEST_info("%s: builder failed", s->label); - OSSL_PARAM_BLD_free(bld); - return 0; - } - params = OSSL_PARAM_BLD_to_param(bld); - if (!TEST_ptr(params)) { - OSSL_PARAM_BLD_free(bld); - return 0; - } - } - ok = probe_fromdata_by_name(s->name, s->selection, params, s->label); - OSSL_PARAM_free(params); - OSSL_PARAM_BLD_free(bld); - if (!ok) - return 0; - } - return 1; -} - #define KEYS(KEYTYPE) \ static EVP_PKEY *key_##KEYTYPE = NULL #define MAKE_KEYS(KEYTYPE, KEYTYPEstr, params) \ - ok &= TEST_ptr(key_##KEYTYPE = make_key(KEYTYPEstr, NULL, params)) + ok = ok \ + && TEST_ptr(key_##KEYTYPE = make_key(KEYTYPEstr, NULL, params)) #define FREE_KEYS(KEYTYPE) \ EVP_PKEY_free(key_##KEYTYPE); #define DOMAIN_KEYS(KEYTYPE) \ static EVP_PKEY *template_##KEYTYPE = NULL; \ static EVP_PKEY *key_##KEYTYPE = NULL -#define MAKE_DOMAIN_KEYS(KEYTYPE, KEYTYPEstr, params) \ - do { \ - ok &= TEST_ptr(template_##KEYTYPE = make_template(KEYTYPEstr, \ - params)); \ - ok &= TEST_ptr(key_##KEYTYPE = make_key(KEYTYPEstr, \ - template_##KEYTYPE, NULL)); \ - } while (0) +#define MAKE_DOMAIN_KEYS(KEYTYPE, KEYTYPEstr, params) \ + ok = ok \ + && TEST_ptr(template_##KEYTYPE = make_template(KEYTYPEstr, params)) \ + && TEST_ptr(key_##KEYTYPE = make_key(KEYTYPEstr, template_##KEYTYPE, NULL)) #define FREE_DOMAIN_KEYS(KEYTYPE) \ EVP_PKEY_free(template_##KEYTYPE); \ EVP_PKEY_free(key_##KEYTYPE) @@ -1343,30 +958,16 @@ static int test_fromdata_no_keygen(void) static int test_public_##KEYTYPE##_via_PEM(void) \ { \ return test_public_via_PEM(KEYTYPEstr, key_##KEYTYPE, fips); \ - } \ - static int test_dup_##KEYTYPE(void) \ - { \ - return test_dup(KEYTYPEstr, key_##KEYTYPE); \ - } \ - static int test_fromdata_##KEYTYPE(void) \ - { \ - return test_fromdata(KEYTYPEstr, key_##KEYTYPE); \ } -#define ADD_TEST_SUITE(KEYTYPE) \ - do { \ - if (key_##KEYTYPE != NULL) { \ - ADD_TEST(test_unprotected_##KEYTYPE##_via_DER); \ - ADD_TEST(test_unprotected_##KEYTYPE##_via_i2d); \ - ADD_TEST(test_unprotected_##KEYTYPE##_via_PEM); \ - ADD_TEST(test_protected_##KEYTYPE##_via_DER); \ - ADD_TEST(test_protected_##KEYTYPE##_via_PEM); \ - ADD_TEST(test_public_##KEYTYPE##_via_DER); \ - ADD_TEST(test_public_##KEYTYPE##_via_PEM); \ - ADD_TEST(test_dup_##KEYTYPE); \ - ADD_TEST(test_fromdata_##KEYTYPE); \ - } \ - } while (0) +#define ADD_TEST_SUITE(KEYTYPE) \ + ADD_TEST(test_unprotected_##KEYTYPE##_via_DER); \ + ADD_TEST(test_unprotected_##KEYTYPE##_via_i2d); \ + ADD_TEST(test_unprotected_##KEYTYPE##_via_PEM); \ + ADD_TEST(test_protected_##KEYTYPE##_via_DER); \ + ADD_TEST(test_protected_##KEYTYPE##_via_PEM); \ + ADD_TEST(test_public_##KEYTYPE##_via_DER); \ + ADD_TEST(test_public_##KEYTYPE##_via_PEM) #define IMPLEMENT_TEST_SUITE_PARAMS(KEYTYPE, KEYTYPEstr) \ static int test_params_##KEYTYPE##_via_DER(void) \ @@ -1378,13 +979,9 @@ static int test_fromdata_no_keygen(void) return test_params_via_PEM(KEYTYPEstr, key_##KEYTYPE); \ } -#define ADD_TEST_SUITE_PARAMS(KEYTYPE) \ - do { \ - if (key_##KEYTYPE != NULL) { \ - ADD_TEST(test_params_##KEYTYPE##_via_DER); \ - ADD_TEST(test_params_##KEYTYPE##_via_PEM); \ - } \ - } while (0) +#define ADD_TEST_SUITE_PARAMS(KEYTYPE) \ + ADD_TEST(test_params_##KEYTYPE##_via_DER); \ + ADD_TEST(test_params_##KEYTYPE##_via_PEM) #define IMPLEMENT_TEST_SUITE_LEGACY(KEYTYPE, KEYTYPEstr) \ static int test_unprotected_##KEYTYPE##_via_legacy_PEM(void) \ @@ -1396,13 +993,9 @@ static int test_fromdata_no_keygen(void) return test_protected_via_legacy_PEM(KEYTYPEstr, key_##KEYTYPE); \ } -#define ADD_TEST_SUITE_LEGACY(KEYTYPE) \ - do { \ - if (key_##KEYTYPE != NULL) { \ - ADD_TEST(test_unprotected_##KEYTYPE##_via_legacy_PEM); \ - ADD_TEST(test_protected_##KEYTYPE##_via_legacy_PEM); \ - } \ - } while (0) +#define ADD_TEST_SUITE_LEGACY(KEYTYPE) \ + ADD_TEST(test_unprotected_##KEYTYPE##_via_legacy_PEM); \ + ADD_TEST(test_protected_##KEYTYPE##_via_legacy_PEM) #define IMPLEMENT_TEST_SUITE_MSBLOB(KEYTYPE, KEYTYPEstr) \ static int test_unprotected_##KEYTYPE##_via_MSBLOB(void) \ @@ -1414,35 +1007,25 @@ static int test_fromdata_no_keygen(void) return test_public_via_MSBLOB(KEYTYPEstr, key_##KEYTYPE); \ } -#define ADD_TEST_SUITE_MSBLOB(KEYTYPE) \ - do { \ - if (key_##KEYTYPE != NULL) { \ - ADD_TEST(test_unprotected_##KEYTYPE##_via_MSBLOB); \ - ADD_TEST(test_public_##KEYTYPE##_via_MSBLOB); \ - } \ - } while (0) +#define ADD_TEST_SUITE_MSBLOB(KEYTYPE) \ + ADD_TEST(test_unprotected_##KEYTYPE##_via_MSBLOB); \ + ADD_TEST(test_public_##KEYTYPE##_via_MSBLOB) #define IMPLEMENT_TEST_SUITE_UNPROTECTED_PVK(KEYTYPE, KEYTYPEstr) \ static int test_unprotected_##KEYTYPE##_via_PVK(void) \ { \ return test_unprotected_via_PVK(KEYTYPEstr, key_##KEYTYPE); \ } -#define ADD_TEST_SUITE_UNPROTECTED_PVK(KEYTYPE) \ - do { \ - if (key_##KEYTYPE != NULL) \ - ADD_TEST(test_unprotected_##KEYTYPE##_via_PVK); \ - } while (0) -#if !defined(OPENSSL_NO_RC4) && !defined(OPENSSL_NO_PVKKDF) +#define ADD_TEST_SUITE_UNPROTECTED_PVK(KEYTYPE) \ + ADD_TEST(test_unprotected_##KEYTYPE##_via_PVK) +#ifndef OPENSSL_NO_RC4 #define IMPLEMENT_TEST_SUITE_PROTECTED_PVK(KEYTYPE, KEYTYPEstr) \ static int test_protected_##KEYTYPE##_via_PVK(void) \ { \ return test_protected_via_PVK(KEYTYPEstr, key_##KEYTYPE); \ } -#define ADD_TEST_SUITE_PROTECTED_PVK(KEYTYPE) \ - do { \ - if (key_##KEYTYPE != NULL) \ - ADD_TEST(test_protected_##KEYTYPE##_via_PVK); \ - } while (0) +#define ADD_TEST_SUITE_PROTECTED_PVK(KEYTYPE) \ + ADD_TEST(test_protected_##KEYTYPE##_via_PVK) #endif #ifndef OPENSSL_NO_DH @@ -1464,7 +1047,7 @@ IMPLEMENT_TEST_SUITE_PARAMS(DSA, "DSA") IMPLEMENT_TEST_SUITE_LEGACY(DSA, "DSA") IMPLEMENT_TEST_SUITE_MSBLOB(DSA, "DSA") IMPLEMENT_TEST_SUITE_UNPROTECTED_PVK(DSA, "DSA") -#if !defined(OPENSSL_NO_RC4) && !defined(OPENSSL_NO_PVKKDF) +#ifndef OPENSSL_NO_RC4 IMPLEMENT_TEST_SUITE_PROTECTED_PVK(DSA, "DSA") #endif #endif @@ -1473,7 +1056,6 @@ DOMAIN_KEYS(EC); IMPLEMENT_TEST_SUITE(EC, "EC", 1) IMPLEMENT_TEST_SUITE_PARAMS(EC, "EC") IMPLEMENT_TEST_SUITE_LEGACY(EC, "EC") -#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES DOMAIN_KEYS(ECExplicitPrimeNamedCurve); IMPLEMENT_TEST_SUITE(ECExplicitPrimeNamedCurve, "EC", 1) IMPLEMENT_TEST_SUITE_LEGACY(ECExplicitPrimeNamedCurve, "EC") @@ -1488,7 +1070,6 @@ DOMAIN_KEYS(ECExplicitTri2G); IMPLEMENT_TEST_SUITE(ECExplicitTri2G, "EC", 0) IMPLEMENT_TEST_SUITE_LEGACY(ECExplicitTri2G, "EC") #endif -#endif /* OPENSSL_NO_EC_EXPLICIT_CURVES */ #ifndef OPENSSL_NO_SM2 KEYS(SM2); IMPLEMENT_TEST_SUITE(SM2, "SM2", 0) @@ -1557,7 +1138,7 @@ IMPLEMENT_TEST_SUITE(RSA_PSS, "RSA-PSS", 1) */ IMPLEMENT_TEST_SUITE_MSBLOB(RSA, "RSA") IMPLEMENT_TEST_SUITE_UNPROTECTED_PVK(RSA, "RSA") -#if !defined(OPENSSL_NO_RC4) && !defined(OPENSSL_NO_PVKKDF) +#ifndef OPENSSL_NO_RC4 IMPLEMENT_TEST_SUITE_PROTECTED_PVK(RSA, "RSA") #endif @@ -1571,7 +1152,6 @@ IMPLEMENT_TEST_SUITE(ML_DSA_87, "ML-DSA-87", 1) #endif /* OPENSSL_NO_ML_DSA */ #ifndef OPENSSL_NO_EC -#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES /* Explicit parameters that match a named curve */ static int do_create_ec_explicit_prime_params(OSSL_PARAM_BLD *bld, const unsigned char *gen, @@ -1678,9 +1258,36 @@ static int do_create_ec_explicit_trinomial_params(OSSL_PARAM_BLD *bld, BIGNUM *a, *b, *poly, *order, *cofactor; /* sect233k1 characteristic-two-field tpBasis */ static const unsigned char poly_data[] = { - 0x02, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x04, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01 + 0x02, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x04, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x01, }; static const unsigned char a_data[] = { 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, @@ -1752,7 +1359,6 @@ static int create_ec_explicit_trinomial_params(OSSL_PARAM_BLD *bld) return do_create_ec_explicit_trinomial_params(bld, gen2, sizeof(gen2)); } #endif /* OPENSSL_NO_EC2M */ -#endif /* OPENSSL_NO_EC_EXPLICIT_CURVES */ /* * Test that multiple calls to OSSL_ENCODER_to_data() do not cause side effects @@ -1892,10 +1498,8 @@ int setup_tests(void) return 0; #ifndef OPENSSL_NO_EC - if (!TEST_ptr(bnctx = BN_CTX_new_ex(testctx))) - return 0; -#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES - if (!TEST_ptr(bld_prime_nc = OSSL_PARAM_BLD_new()) + if (!TEST_ptr(bnctx = BN_CTX_new_ex(testctx)) + || !TEST_ptr(bld_prime_nc = OSSL_PARAM_BLD_new()) || !TEST_ptr(bld_prime = OSSL_PARAM_BLD_new()) || !create_ec_explicit_prime_params_namedcurve(bld_prime_nc) || !create_ec_explicit_prime_params(bld_prime) @@ -1911,7 +1515,6 @@ int setup_tests(void) #endif ) return 0; -#endif /* OPENSSL_NO_EC_EXPLICIT_CURVES */ #endif TEST_info("Generating keys..."); @@ -1928,14 +1531,12 @@ int setup_tests(void) #ifndef OPENSSL_NO_EC TEST_info("Generating EC keys..."); MAKE_DOMAIN_KEYS(EC, "EC", EC_params); -#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES MAKE_DOMAIN_KEYS(ECExplicitPrimeNamedCurve, "EC", ec_explicit_prime_params_nc); MAKE_DOMAIN_KEYS(ECExplicitPrime2G, "EC", ec_explicit_prime_params_explicit); #ifndef OPENSSL_NO_EC2M MAKE_DOMAIN_KEYS(ECExplicitTriNamedCurve, "EC", ec_explicit_tri_params_nc); MAKE_DOMAIN_KEYS(ECExplicitTri2G, "EC", ec_explicit_tri_params_explicit); #endif -#endif /* OPENSSL_NO_EC_EXPLICIT_CURVES */ #ifndef OPENSSL_NO_SM2 MAKE_KEYS(SM2, "SM2", NULL); #endif @@ -1978,17 +1579,12 @@ int setup_tests(void) #endif /* OPENSSL_NO_SLH_DSA */ TEST_info("Loading RSA key..."); - ok &= TEST_ptr(key_RSA = load_pkey_pem(rsa_file, keyctx)); + ok = ok && TEST_ptr(key_RSA = load_pkey_pem(rsa_file, keyctx)); TEST_info("Loading RSA_PSS key..."); - ok &= TEST_ptr(key_RSA_PSS = load_pkey_pem(rsa_pss_file, keyctx)); + ok = ok && TEST_ptr(key_RSA_PSS = load_pkey_pem(rsa_pss_file, keyctx)); TEST_info("Generating keys done"); - /* - * Register every test whose key was successfully generated. The - * per-algorithm key_##KEYTYPE != NULL guard inside each - * ADD_TEST_SUITE* macro keeps us from referencing missing keys. - */ - { + if (ok) { #ifndef OPENSSL_NO_DH ADD_TEST_SUITE(DH); ADD_TEST_SUITE_PARAMS(DH); @@ -2005,7 +1601,7 @@ int setup_tests(void) ADD_TEST_SUITE_LEGACY(DSA); ADD_TEST_SUITE_MSBLOB(DSA); ADD_TEST_SUITE_UNPROTECTED_PVK(DSA); -#if !defined(OPENSSL_NO_RC4) && !defined(OPENSSL_NO_PVKKDF) +#ifndef OPENSSL_NO_RC4 ADD_TEST_SUITE_PROTECTED_PVK(DSA); #endif #endif @@ -2014,7 +1610,6 @@ int setup_tests(void) ADD_TEST_SUITE(EC); ADD_TEST_SUITE_PARAMS(EC); ADD_TEST_SUITE_LEGACY(EC); -#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES ADD_TEST_SUITE(ECExplicitPrimeNamedCurve); ADD_TEST_SUITE_LEGACY(ECExplicitPrimeNamedCurve); ADD_TEST_SUITE(ECExplicitPrime2G); @@ -2025,7 +1620,6 @@ int setup_tests(void) ADD_TEST_SUITE(ECExplicitTri2G); ADD_TEST_SUITE_LEGACY(ECExplicitTri2G); #endif -#endif /* OPENSSL_NO_EC_EXPLICIT_CURVES */ #ifndef OPENSSL_NO_SM2 if (!is_fips_3_0_0) { /* 3.0.0 FIPS provider imports explicit EC params and then fails. */ @@ -2059,7 +1653,7 @@ int setup_tests(void) */ ADD_TEST_SUITE_MSBLOB(RSA); ADD_TEST_SUITE_UNPROTECTED_PVK(RSA); -#if !defined(OPENSSL_NO_RC4) && !defined(OPENSSL_NO_PVKKDF) +#ifndef OPENSSL_NO_RC4 ADD_TEST_SUITE_PROTECTED_PVK(RSA); #endif @@ -2087,24 +1681,14 @@ int setup_tests(void) ADD_TEST_SUITE(SLH_DSA_SHAKE_256f); } #endif /* OPENSSL_NO_SLH_DSA */ - - /* - * Cover keymgmts that have no keygen path and so don't - * appear in the prototype matrix above (LMS, and any future - * verify-only / signature-only algorithms). The probe is a - * no-op for algorithms not loadable under the active provider - * set (e.g. LMS under FIPS), so the test stays portable. - */ - ADD_TEST(test_fromdata_no_keygen); } - return ok; + return 1; } void cleanup_tests(void) { #ifndef OPENSSL_NO_EC -#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES OSSL_PARAM_free(ec_explicit_prime_params_nc); OSSL_PARAM_free(ec_explicit_prime_params_explicit); OSSL_PARAM_BLD_free(bld_prime_nc); @@ -2115,7 +1699,6 @@ void cleanup_tests(void) OSSL_PARAM_BLD_free(bld_tri_nc); OSSL_PARAM_BLD_free(bld_tri); #endif -#endif /* OPENSSL_NO_EC_EXPLICIT_CURVES */ BN_CTX_free(bnctx); #endif /* OPENSSL_NO_EC */ @@ -2128,14 +1711,12 @@ void cleanup_tests(void) #endif #ifndef OPENSSL_NO_EC FREE_DOMAIN_KEYS(EC); -#ifndef OPENSSL_NO_EC_EXPLICIT_CURVES FREE_DOMAIN_KEYS(ECExplicitPrimeNamedCurve); FREE_DOMAIN_KEYS(ECExplicitPrime2G); #ifndef OPENSSL_NO_EC2M FREE_DOMAIN_KEYS(ECExplicitTriNamedCurve); FREE_DOMAIN_KEYS(ECExplicitTri2G); #endif -#endif /* OPENSSL_NO_EC_EXPLICIT_CURVES */ #ifndef OPENSSL_NO_SM2 FREE_KEYS(SM2); #endif diff --git a/test/endecoder_legacy_test.c b/test/endecoder_legacy_test.c index ef7ce7aedd..04f26174b5 100644 --- a/test/endecoder_legacy_test.c +++ b/test/endecoder_legacy_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -293,8 +293,8 @@ static int test_membio_str_eq(BIO *bio_provided, BIO *bio_legacy) return TEST_long_ge(len_legacy, 0) && TEST_long_ge(len_provided, 0) - && TEST_size_t_eq(len_provided, len_legacy) - && TEST_strn_eq(str_provided, str_legacy, len_provided); + && TEST_strn2_eq(str_provided, len_provided, + str_legacy, len_legacy); } static int test_protected_PEM(const char *keytype, int evp_type, diff --git a/test/engine_stubs_test.c b/test/engine_stubs_test.c deleted file mode 100644 index 49012700e7..0000000000 --- a/test/engine_stubs_test.c +++ /dev/null @@ -1,311 +0,0 @@ -/* - * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#define OPENSSL_SUPPRESS_DEPRECATED -#define OPENSSL_ENGINE_STUBS /* switch on stub macros */ - -#include -#include "testutil.h" - -/* Test stubs for removed ENGINE_* API */ -static int test_engine_stubs(void) -{ -#ifndef OPENSSL_NO_DEPRECATED_3_0 - ENGINE_load_builtin_engines(); - ENGINE_set_table_flags(0); - ENGINE_unregister_RSA(NULL); - ENGINE_register_all_RSA(); - ENGINE_unregister_DSA(NULL); - ENGINE_register_all_DSA(); - ENGINE_unregister_EC(NULL); - ENGINE_register_all_EC(); - ENGINE_unregister_DH(NULL); - ENGINE_register_all_DH(); - ENGINE_unregister_RAND(NULL); - ENGINE_register_all_RAND(); - ENGINE_unregister_digests(NULL); - ENGINE_register_all_digests(); - ENGINE_unregister_pkey_meths(NULL); - ENGINE_register_all_pkey_meths(); - ENGINE_unregister_pkey_asn1_meths(NULL); - ENGINE_register_all_pkey_asn1_meths(); - ENGINE_unregister_ciphers(NULL); - ENGINE_register_all_ciphers(); - ENGINE_add_conf_module(); - - if (!TEST_ptr_null(ENGINE_get_first())) - return 0; - if (!TEST_ptr_null(ENGINE_get_last())) - return 0; - if (!TEST_ptr_null(ENGINE_get_next(NULL))) - return 0; - if (!TEST_ptr_null(ENGINE_get_prev(NULL))) - return 0; - if (!TEST_int_eq(ENGINE_add(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_remove(NULL), 0)) - return 0; - if (!TEST_ptr_null(ENGINE_by_id(NULL))) - return 0; - if (!TEST_int_eq(ENGINE_get_table_flags(), 0)) - return 0; - if (!TEST_int_eq(ENGINE_register_RSA(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_register_DSA(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_register_EC(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_register_DH(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_register_RAND(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_register_ciphers(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_register_digests(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_register_pkey_meths(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_register_pkey_asn1_meths(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_register_complete(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_register_all_complete(), 0)) - return 0; - if (!TEST_int_eq(ENGINE_ctrl(NULL, 0, 0, NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_cmd_is_executable(NULL, 0), 0)) - return 0; - if (!TEST_int_eq(ENGINE_ctrl_cmd(NULL, NULL, 0, NULL, NULL, 0), 0)) - return 0; - if (!TEST_int_eq(ENGINE_ctrl_cmd_string(NULL, NULL, NULL, 0), 0)) - return 0; - if (!TEST_ptr_null(ENGINE_new())) - return 0; - if (!TEST_int_eq(ENGINE_free(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_up_ref(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_id(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_name(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_RSA(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_DSA(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_EC(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_DH(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_RAND(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_destroy_function(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_init_function(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_finish_function(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_ctrl_function(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_load_privkey_function(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_load_pubkey_function(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_load_ssl_client_cert_function(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_ciphers(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_digests(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_pkey_meths(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_pkey_asn1_meths(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_flags(NULL, 0), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_cmd_defns(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_get_ex_new_index(0, NULL, NULL, NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_ex_data(NULL, 0, NULL), 0)) - return 0; - if (!TEST_ptr_null(ENGINE_get_ex_data(NULL, 0))) - return 0; - if (!TEST_ptr_null(ENGINE_get_id(NULL))) - return 0; - if (!TEST_ptr_null(ENGINE_get_name(NULL))) - return 0; - if (!TEST_ptr_null(ENGINE_get_RSA(NULL))) - return 0; - if (!TEST_ptr_null(ENGINE_get_DSA(NULL))) - return 0; - if (!TEST_ptr_null(ENGINE_get_EC(NULL))) - return 0; - if (!TEST_ptr_null(ENGINE_get_DH(NULL))) - return 0; - if (!TEST_ptr_null(ENGINE_get_RAND(NULL))) - return 0; - if (!TEST_true(ENGINE_get_destroy_function(NULL) == (ENGINE_GEN_INT_FUNC_PTR)NULL)) - return 0; - if (!TEST_true(ENGINE_get_init_function(NULL) == (ENGINE_GEN_INT_FUNC_PTR)NULL)) - return 0; - if (!TEST_true(ENGINE_get_finish_function(NULL) == (ENGINE_GEN_INT_FUNC_PTR)NULL)) - return 0; - if (!TEST_true(ENGINE_get_ctrl_function(NULL) == (ENGINE_CTRL_FUNC_PTR)NULL)) - return 0; - if (!TEST_true(ENGINE_get_load_privkey_function(NULL) == (ENGINE_LOAD_KEY_PTR)NULL)) - return 0; - if (!TEST_true(ENGINE_get_load_pubkey_function(NULL) == (ENGINE_LOAD_KEY_PTR)NULL)) - return 0; - if (!TEST_true(ENGINE_get_ssl_client_cert_function(NULL) == (ENGINE_SSL_CLIENT_CERT_PTR)NULL)) - return 0; - if (!TEST_true(ENGINE_get_ciphers(NULL) == (ENGINE_CIPHERS_PTR)NULL)) - return 0; - if (!TEST_true(ENGINE_get_digests(NULL) == (ENGINE_DIGESTS_PTR)NULL)) - return 0; - if (!TEST_true(ENGINE_get_pkey_meths(NULL) == (ENGINE_PKEY_METHS_PTR)NULL)) - return 0; - if (!TEST_true(ENGINE_get_pkey_asn1_meths(NULL) == (ENGINE_PKEY_ASN1_METHS_PTR)NULL)) - return 0; - if (!TEST_ptr_null(ENGINE_get_cipher(NULL, 0))) - return 0; - if (!TEST_ptr_null(ENGINE_get_digest(NULL, 0))) - return 0; - if (!TEST_ptr_null(ENGINE_get_pkey_meth(NULL, 0))) - return 0; - if (!TEST_ptr_null(ENGINE_get_pkey_asn1_meth(NULL, 0))) - return 0; - if (!TEST_ptr_null(ENGINE_get_pkey_asn1_meth_str(NULL, NULL, 0))) - return 0; - if (!TEST_ptr_null(ENGINE_pkey_asn1_find_str(NULL, NULL, 0))) - return 0; - if (!TEST_ptr_null(ENGINE_get_cmd_defns(NULL))) - return 0; - if (!TEST_int_eq(ENGINE_get_flags(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_init(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_finish(NULL), 0)) - return 0; - if (!TEST_ptr_null(ENGINE_load_private_key(NULL, NULL, NULL, NULL))) - return 0; - if (!TEST_ptr_null(ENGINE_load_public_key(NULL, NULL, NULL, NULL))) - return 0; - if (!TEST_int_eq(ENGINE_load_ssl_client_cert(NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL), 0)) - return 0; - if (!TEST_ptr_null(ENGINE_get_default_RSA())) - return 0; - if (!TEST_ptr_null(ENGINE_get_default_DSA())) - return 0; - if (!TEST_ptr_null(ENGINE_get_default_EC())) - return 0; - if (!TEST_ptr_null(ENGINE_get_default_DH())) - return 0; - if (!TEST_ptr_null(ENGINE_get_default_RAND())) - return 0; - if (!TEST_ptr_null(ENGINE_get_cipher_engine(0))) - return 0; - if (!TEST_ptr_null(ENGINE_get_digest_engine(0))) - return 0; - if (!TEST_ptr_null(ENGINE_get_pkey_meth_engine(0))) - return 0; - if (!TEST_ptr_null(ENGINE_get_pkey_asn1_meth_engine(0))) - return 0; - if (!TEST_int_eq(ENGINE_set_default_RSA(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_default_string(NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_default_DSA(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_default_EC(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_default_DH(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_default_RAND(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_default_ciphers(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_default_digests(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_default_pkey_meths(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_default_pkey_asn1_meths(NULL), 0)) - return 0; - if (!TEST_int_eq(ENGINE_set_default(NULL, 0), 0)) - return 0; - if (!TEST_ptr_null(ENGINE_get_static_state())) - return 0; -#endif - -#ifndef OPENSSL_NO_DEPRECATED_1_1_0 - ENGINE_cleanup(); -#if defined(__OpenBSD__) || defined(__FreeBSD__) || defined(__DragonFly__) - ENGINE_setup_bsd_cryptodev(); -#endif - if (!TEST_int_eq(ENGINE_load_openssl(), 0)) - return 0; - if (!TEST_int_eq(ENGINE_load_dynamic(), 0)) - return 0; - if (!TEST_int_eq(ENGINE_load_cryptodev(), 0)) - return 0; - if (!TEST_int_eq(ENGINE_load_rdrand(), 0)) - return 0; -#ifndef OPENSSL_NO_STATIC_ENGINE - if (!TEST_int_eq(ENGINE_load_padlock(), 0)) - return 0; - if (!TEST_int_eq(ENGINE_load_capi(), 0)) - return 0; - if (!TEST_int_eq(ENGINE_load_afalg(), 0)) - return 0; -#endif -#endif - - return 1; -} - -/* Test stubs for other removed API */ -static int test_other_stubs(void) -{ -#ifndef OPENSSL_NO_DEPRECATED_3_0 - if (!TEST_int_eq(ERR_load_ENGINE_strings(), 1)) - return 0; - - if (!TEST_int_eq(EVP_PKEY_set1_engine(NULL, NULL), 0)) - return 0; - if (!TEST_ptr_null(EVP_PKEY_get0_engine(NULL))) - return 0; - if (!TEST_ptr_null(DH_get0_engine(NULL))) - return 0; - if (!TEST_ptr_null(RSA_get0_engine(NULL))) - return 0; - if (!TEST_ptr_null(DSA_get0_engine(NULL))) - return 0; - if (!TEST_ptr_null(EC_KEY_get0_engine(NULL))) - return 0; - if (!TEST_ptr_null(OSSL_STORE_LOADER_get0_engine(NULL))) - return 0; - if (!TEST_int_eq(RAND_set_rand_engine(NULL), 0)) - return 0; -#endif - if (!TEST_int_eq(TS_CONF_set_crypto_device(NULL, NULL, NULL), 0)) - return 0; - if (!TEST_int_eq(TS_CONF_set_default_engine(NULL), 0)) - return 0; - if (!TEST_int_eq(SSL_CTX_set_client_cert_engine(NULL, NULL), 0)) - return 0; - - return 1; -} - -int setup_tests(void) -{ - ADD_TEST(test_engine_stubs); - ADD_TEST(test_other_stubs); - return 1; -} diff --git a/test/errtest.c b/test/errtest.c index 7183548080..323184d93b 100644 --- a/test/errtest.c +++ b/test/errtest.c @@ -1,5 +1,5 @@ /* - * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2018-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -420,36 +420,6 @@ err: return res; } -static int test_error_reason(void) -{ - int test; - - ERR_raise(ERR_LIB_CRYPTO, ERR_R_MALLOC_FAILURE); - ERR_raise(ERR_LIB_CRYPTO, ERR_R_INTERNAL_ERROR); - ERR_raise(ERR_LIB_CRYPTO, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED); - - test = TEST_err_r(ERR_LIB_CRYPTO, ERR_R_MALLOC_FAILURE) - && TEST_err_r(ERR_LIB_CRYPTO, ERR_R_INTERNAL_ERROR) - && TEST_err_r(ERR_LIB_CRYPTO, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED); - - return test; -} - -static int test_error_string(void) -{ - int test; - - ERR_raise_data(ERR_LIB_CRYPTO, ERR_R_MALLOC_FAILURE, "malloc failure"); - ERR_raise_data(ERR_LIB_CRYPTO, ERR_R_INTERNAL_ERROR, "internal error"); - - test = TEST_err_r(ERR_LIB_CRYPTO, ERR_R_MALLOC_FAILURE) - && TEST_err_r(ERR_LIB_CRYPTO, ERR_R_INTERNAL_ERROR) - && TEST_err_s("malloc failure") - && TEST_err_s("internal error"); - - return test; -} - int setup_tests(void) { ADD_TEST(preserves_system_error); @@ -461,7 +431,5 @@ int setup_tests(void) ADD_TEST(test_marks); ADD_ALL_TESTS(test_save_restore, 2); ADD_TEST(test_clear_error); - ADD_TEST(test_error_reason); - ADD_TEST(test_error_string); return 1; } diff --git a/test/evp_extra_test.c b/test/evp_extra_test.c index 00ed62f264..5280007b3d 100644 --- a/test/evp_extra_test.c +++ b/test/evp_extra_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -41,13 +41,6 @@ #include "fake_rsaprov.h" #include "fake_pipelineprov.h" -#ifndef OPENSSL_NO_DSA -#include "helpers/predefined_dsaparams.h" -#endif -#ifndef OPENSSL_NO_DH -#include "helpers/predefined_dhparams.h" -#endif - #ifdef STATIC_LEGACY OSSL_provider_init_fn ossl_legacy_provider_init; #endif @@ -702,6 +695,48 @@ static const unsigned char kExampleED25519PubKeyDER[] = { 0xef, 0x5b, 0x7c, 0x20, 0xe8, 0x66, 0x28, 0x30, 0x3c, 0x8a, 0x82, 0x40, 0x97, 0xa3, 0x08, 0xdc, 0x65, 0x80, 0x39, 0x29 }; + +#ifndef OPENSSL_NO_DEPRECATED_3_0 +static const unsigned char kExampleX25519KeyDER[] = { + 0x30, 0x2e, 0x02, 0x01, 0x00, 0x30, 0x05, 0x06, 0x03, 0x2b, 0x65, 0x6e, + 0x04, 0x22, 0x04, 0x20, 0xa0, 0x24, 0x3a, 0x31, 0x24, 0xc3, 0x3f, 0xf6, + 0x7b, 0x96, 0x0b, 0xd4, 0x8f, 0xd1, 0xee, 0x67, 0xf2, 0x9b, 0x88, 0xac, + 0x50, 0xce, 0x97, 0x36, 0xdd, 0xaf, 0x25, 0xf6, 0x10, 0x34, 0x96, 0x6e +}; +#endif +#endif +#endif + +/* kExampleDHKeyDER is a DH private key in ASN.1, DER format. */ +#ifndef OPENSSL_NO_DEPRECATED_3_0 +#ifndef OPENSSL_NO_DH +static const unsigned char kExampleDHKeyDER[] = { + 0x30, 0x82, 0x01, 0x21, 0x02, 0x01, 0x00, 0x30, 0x81, 0x95, 0x06, 0x09, + 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x03, 0x01, 0x30, 0x81, 0x87, + 0x02, 0x81, 0x81, 0x00, 0xf7, 0x52, 0xc2, 0x68, 0xcc, 0x66, 0xc4, 0x8d, + 0x03, 0x3f, 0xfa, 0x9c, 0x52, 0xd0, 0xd8, 0x33, 0xf2, 0xe1, 0xc9, 0x9e, + 0xb7, 0xe7, 0x6e, 0x90, 0x97, 0xeb, 0x92, 0x91, 0x6a, 0x9a, 0x85, 0x63, + 0x92, 0x79, 0xab, 0xb6, 0x3d, 0x23, 0x58, 0x5a, 0xe8, 0x45, 0x06, 0x81, + 0x97, 0x77, 0xe1, 0xcc, 0x34, 0x4e, 0xae, 0x36, 0x80, 0xf2, 0xc4, 0x7f, + 0x8a, 0x52, 0xb8, 0xdb, 0x58, 0xc8, 0x4b, 0x12, 0x4c, 0xf1, 0x4c, 0x53, + 0xc1, 0x89, 0x39, 0x8d, 0xb6, 0x06, 0xd8, 0xea, 0x7f, 0x2d, 0x36, 0x53, + 0x96, 0x29, 0xbe, 0xb6, 0x75, 0xfc, 0xe7, 0xf3, 0x36, 0xd6, 0xf4, 0x8f, + 0x16, 0xa6, 0xc7, 0xec, 0x7b, 0xce, 0x42, 0x8d, 0x48, 0x2e, 0xb7, 0x74, + 0x00, 0x11, 0x52, 0x61, 0xb4, 0x19, 0x35, 0xec, 0x5c, 0xe4, 0xbe, 0x34, + 0xc6, 0x59, 0x64, 0x5e, 0x42, 0x61, 0x70, 0x54, 0xf4, 0xe9, 0x6b, 0x53, + 0x02, 0x01, 0x02, 0x04, 0x81, 0x83, 0x02, 0x81, 0x80, 0x64, 0xc2, 0xe3, + 0x09, 0x69, 0x37, 0x3c, 0xd2, 0x4a, 0xba, 0xc3, 0x78, 0x6a, 0x9b, 0x8a, + 0x2a, 0xdb, 0xe7, 0xe6, 0xc0, 0xfa, 0x3a, 0xbe, 0x39, 0x67, 0xc0, 0xa9, + 0x2a, 0xf0, 0x0a, 0xc1, 0x53, 0x1c, 0xdb, 0xfa, 0x1a, 0x26, 0x98, 0xb0, + 0x8c, 0xc6, 0x06, 0x4a, 0xa2, 0x48, 0xd3, 0xa4, 0x3b, 0xbd, 0x05, 0x48, + 0xea, 0x59, 0xdb, 0x18, 0xa4, 0xca, 0x66, 0xd9, 0x5d, 0xb8, 0x95, 0xd1, + 0xeb, 0x97, 0x3d, 0x66, 0x97, 0x5c, 0x86, 0x8f, 0x7e, 0x90, 0xd3, 0x43, + 0xd1, 0xa2, 0x0d, 0xcb, 0xe7, 0xeb, 0x90, 0xea, 0x09, 0x40, 0xb1, 0x6f, + 0xf7, 0x4c, 0xf2, 0x41, 0x83, 0x1d, 0xd0, 0x76, 0xef, 0xaf, 0x55, 0x6f, + 0x5d, 0xa9, 0xa3, 0x55, 0x81, 0x2a, 0xd1, 0x5d, 0x9d, 0x22, 0x77, 0x97, + 0x83, 0xde, 0xad, 0xb6, 0x5d, 0x19, 0xc1, 0x53, 0xec, 0xfb, 0xaf, 0x06, + 0x2e, 0x87, 0x2a, 0x0b, 0x7a +}; #endif #endif @@ -1071,6 +1106,30 @@ static int test_ml_dsa_seed_only(int idx) } #endif +#ifndef OPENSSL_NO_DEPRECATED_3_0 +#ifndef OPENSSL_NO_DH +static EVP_PKEY *load_example_dh_key(void) +{ + return load_example_key("DH", kExampleDHKeyDER, + sizeof(kExampleDHKeyDER)); +} +#endif + +#ifndef OPENSSL_NO_ECX +static EVP_PKEY *load_example_ed25519_key(void) +{ + return load_example_key("ED25519", kExampleED25519KeyDER, + sizeof(kExampleED25519KeyDER)); +} + +static EVP_PKEY *load_example_x25519_key(void) +{ + return load_example_key("X25519", kExampleX25519KeyDER, + sizeof(kExampleX25519KeyDER)); +} +#endif +#endif /* OPENSSL_NO_DEPRECATED_3_0 */ + static EVP_PKEY *load_example_hmac_key(void) { EVP_PKEY *pkey = NULL; @@ -1192,9 +1251,6 @@ static int test_selection(EVP_PKEY *pkey, int selection) int ret; BIO *bio = BIO_new(BIO_s_mem()); - if (!TEST_ptr(bio)) - goto err; - ret = PEM_write_bio_PUBKEY(bio, pkey); if ((selection & OSSL_KEYMGMT_SELECT_PUBLIC_KEY) != 0) { if (!TEST_true(ret)) @@ -1421,11 +1477,13 @@ static int test_EC_priv_pub(void) bld = NULL; /* - * ossl_ec_key_fromdata() automatically generates the public key on import - * if one is not provided, so fail the test if a public key is not - * available. + * We indicate only parameters here, in spite of having built a key that + * has a private part, because the PEM_write_bio_PrivateKey_ex call is + * expected to fail because it does not support exporting a private EC + * key without a corresponding public key */ - if (!test_selection(params_and_priv, OSSL_KEYMGMT_SELECT_KEYPAIR)) + if (!test_selection(params_and_priv, OSSL_KEYMGMT_SELECT_ALL_PARAMETERS) + || test_selection(params_and_priv, OSSL_KEYMGMT_SELECT_PUBLIC_KEY)) goto err; /* Test !priv and pub */ @@ -2322,92 +2380,6 @@ out: return ret; } -#ifndef OPENSSL_NO_POLY1305 -/* Test Poly1305 no-key failures and staged key initialization */ -static int test_evp_mac_poly1305_no_key(void) -{ - int ret = 0; - EVP_MAC *mac = NULL; - EVP_MAC_CTX *ctx = NULL; - /* RFC 7539 Poly1305 test vector. */ - static const unsigned char staged_data[] = "Cryptographic Forum Research Group"; - static const unsigned char expected[16] = { - 0xa8, 0x06, 0x1d, 0xc1, 0x30, 0x51, 0x36, 0xc6, - 0xc2, 0x2b, 0x8b, 0xaf, 0x0c, 0x01, 0x27, 0xa9 - }; - unsigned char no_key_data[16] = { 0 }; - unsigned char key[32] = { - 0x85, 0xd6, 0xbe, 0x78, 0x57, 0x55, 0x6d, 0x33, - 0x7f, 0x44, 0x52, 0xfe, 0x42, 0xd5, 0x06, 0xa8, - 0x01, 0x03, 0x80, 0x8a, 0xfb, 0x0d, 0xb2, 0xfd, - 0x4a, 0xbf, 0xf6, 0xaf, 0x41, 0x49, 0xf5, 0x1b - }; - unsigned char out[16]; - OSSL_PARAM key_params[2]; - OSSL_PARAM null_key_params[2]; - size_t outl = 0; - - key_params[0] = OSSL_PARAM_construct_octet_string(OSSL_MAC_PARAM_KEY, - key, sizeof(key)); - key_params[1] = OSSL_PARAM_construct_end(); - null_key_params[0] = OSSL_PARAM_construct_octet_string(OSSL_MAC_PARAM_KEY, - NULL, sizeof(key)); - null_key_params[1] = OSSL_PARAM_construct_end(); - - if (!TEST_ptr(mac = EVP_MAC_fetch(testctx, "Poly1305", testpropq)) - || !TEST_ptr(ctx = EVP_MAC_CTX_new(mac)) - || !TEST_int_eq(EVP_MAC_init(ctx, NULL, 0, NULL), 1)) - goto err; - - ERR_clear_error(); - if (!TEST_int_eq(EVP_MAC_update(ctx, no_key_data, sizeof(no_key_data)), 0) - || !TEST_int_eq(ERR_GET_REASON(ERR_get_error()), PROV_R_NO_KEY_SET)) - goto err; - - /* The failed update must not block staged key initialization. */ - if (!TEST_int_eq(EVP_MAC_CTX_set_params(ctx, key_params), 1) - || !TEST_int_eq(EVP_MAC_update(ctx, staged_data, - sizeof(staged_data) - 1), - 1) - || !TEST_int_eq(EVP_MAC_final(ctx, out, &outl, sizeof(out)), 1) - || !TEST_size_t_eq(outl, sizeof(expected)) - || !TEST_mem_eq(out, outl, expected, sizeof(expected))) - goto err; - - EVP_MAC_CTX_free(ctx); - ctx = NULL; - - if (!TEST_ptr(ctx = EVP_MAC_CTX_new(mac)) - || !TEST_int_eq(EVP_MAC_init(ctx, NULL, 0, NULL), 1)) - goto err; - - ERR_clear_error(); - if (!TEST_int_eq(EVP_MAC_final(ctx, out, &outl, sizeof(out)), 0) - || !TEST_int_eq(ERR_GET_REASON(ERR_get_error()), PROV_R_NO_KEY_SET)) - goto err; - - ERR_clear_error(); - if (!TEST_int_eq(EVP_MAC_init(ctx, NULL, 0, null_key_params), 0) - || !TEST_int_eq(ERR_GET_REASON(ERR_get_error()), - PROV_R_INVALID_KEY_LENGTH)) - goto err; - - ERR_clear_error(); - if (!TEST_int_eq(EVP_MAC_CTX_set_params(ctx, null_key_params), 0) - || !TEST_int_eq(ERR_GET_REASON(ERR_get_error()), - PROV_R_INVALID_KEY_LENGTH)) - goto err; - - EVP_MAC_CTX_free(ctx); - ctx = NULL; - ret = 1; -err: - EVP_MAC_CTX_free(ctx); - EVP_MAC_free(mac); - return ret; -} -#endif - static int test_d2i_AutoPrivateKey(int i) { int ret = 0; @@ -2474,7 +2446,7 @@ static struct ec_der_pub_keys_st { * Tests the range of the decoded EC char2 public point. * See ec_GF2m_simple_oct2point(). */ -static int test_invalid_ec_char2_pub_range_decode(int id) +static int test_invalide_ec_char2_pub_range_decode(int id) { int ret = 0; EVP_PKEY *pkey; @@ -2769,21 +2741,19 @@ static int test_EVP_SM2(void) EVP_MD_CTX *md_ctx_verify = NULL; EVP_PKEY_CTX *cctx = NULL; EVP_MD *check_md = NULL; - uint8_t sm2_id[] = { - 0x01, 0x02, 0x03, 0x04, 0x6c, 0x65, 0x74, 0x74, 0x65, 0x72 - }; -#ifndef OPENSSL_NO_X963KDF + uint8_t ciphertext[128]; size_t ctext_len = sizeof(ciphertext); - size_t ctext_len_param = 0; + uint8_t plaintext[8]; size_t ptext_len = sizeof(plaintext); - size_t ptext_len_param = 0; + + uint8_t sm2_id[] = { 1, 2, 3, 4, 'l', 'e', 't', 't', 'e', 'r' }; + OSSL_PARAM sparams[2] = { OSSL_PARAM_END, OSSL_PARAM_END }; OSSL_PARAM gparams[2] = { OSSL_PARAM_END, OSSL_PARAM_END }; int i; char mdname[OSSL_MAX_NAME_SIZE]; -#endif if (!TEST_ptr(pctx = EVP_PKEY_CTX_new_from_name(testctx, "SM2", testpropq))) @@ -2876,7 +2846,7 @@ static int test_EVP_SM2(void) goto done; /* now check encryption/decryption */ -#ifndef OPENSSL_NO_X963KDF + gparams[0] = OSSL_PARAM_construct_utf8_string(OSSL_ASYM_CIPHER_PARAM_DIGEST, mdname, sizeof(mdname)); for (i = 0; i < 2; i++) { @@ -2906,8 +2876,7 @@ static int test_EVP_SM2(void) if (!TEST_true(EVP_PKEY_CTX_set_params(cctx, sparams))) goto done; - ctext_len_param = ctext_len; - if (!TEST_true(EVP_PKEY_encrypt(cctx, ciphertext, &ctext_len_param, kMsg, + if (!TEST_true(EVP_PKEY_encrypt(cctx, ciphertext, &ctext_len, kMsg, sizeof(kMsg)))) goto done; @@ -2917,9 +2886,8 @@ static int test_EVP_SM2(void) if (!TEST_true(EVP_PKEY_CTX_set_params(cctx, sparams))) goto done; - ptext_len_param = ptext_len; - if (!TEST_int_gt(EVP_PKEY_decrypt(cctx, plaintext, &ptext_len_param, ciphertext, - ctext_len_param), + if (!TEST_int_gt(EVP_PKEY_decrypt(cctx, plaintext, &ptext_len, ciphertext, + ctext_len), 0)) goto done; @@ -2939,13 +2907,13 @@ static int test_EVP_SM2(void) goto done; } - if (!TEST_true(ptext_len_param == sizeof(kMsg))) + if (!TEST_true(ptext_len == sizeof(kMsg))) goto done; if (!TEST_true(memcmp(plaintext, kMsg, sizeof(kMsg)) == 0)) goto done; } -#endif /* OPENSSL_NO_X963KDF */ + ret = 1; done: EVP_PKEY_CTX_free(pctx); @@ -3477,54 +3445,33 @@ static int test_set_get_raw_keys(int tst) && test_set_get_raw_keys_int(tst, 1, 1); } -static int test_set_get_raw_keys_mfail(int idx) +#ifndef OPENSSL_NO_DEPRECATED_3_0 +static int pkey_custom_check(EVP_PKEY *pkey) { - const uint8_t *in; - size_t inlen, len = 0; - EVP_PKEY *pkey = NULL; - unsigned char *buf = NULL; - unsigned char *privalloc = NULL; - const char *name; - int ok = 0; - int ret = 0; - - name = keys[idx].name != NULL ? keys[idx].name : OBJ_nid2sn(keys[idx].type); - inlen = keys[idx].privlen; - in = keys[idx].priv; -#ifndef OPENSSL_NO_ML_KEM - if (in == ml_kem_seed) { - if (!TEST_true(ml_kem_seed_to_priv(name, in, inlen, &privalloc, &inlen))) - goto err; - in = privalloc; - } -#endif - - MFAIL_start(); - pkey = EVP_PKEY_new_raw_private_key_ex(testctx, name, NULL, in, inlen); - if (pkey != NULL - && EVP_PKEY_get_raw_private_key(pkey, NULL, &len) - && (buf = OPENSSL_malloc(len == 0 ? 1 : len)) != NULL - && EVP_PKEY_get_raw_private_key(pkey, buf, &len)) - ok = 1; - MFAIL_end(); - - if (!ok) - goto err; - - ret = TEST_mem_eq(in, inlen, buf, len); - -err: - OPENSSL_free(privalloc); - OPENSSL_free(buf); - EVP_PKEY_free(pkey); - return ret; + return 0xbeef; } +static int pkey_custom_pub_check(EVP_PKEY *pkey) +{ + return 0xbeef; +} + +static int pkey_custom_param_check(EVP_PKEY *pkey) +{ + return 0xbeef; +} + +static EVP_PKEY_METHOD *custom_pmeth; +#endif + static int test_EVP_PKEY_check(int i) { int ret = 0; EVP_PKEY *pkey = NULL; EVP_PKEY_CTX *ctx = NULL; +#ifndef OPENSSL_NO_DEPRECATED_3_0 + EVP_PKEY_CTX *ctx2 = NULL; +#endif const APK_DATA *ak = &keycheckdata[i]; const unsigned char *input = ak->kder; size_t input_len = ak->size; @@ -3552,10 +3499,31 @@ static int test_EVP_PKEY_check(int i) if (!TEST_int_eq(EVP_PKEY_param_check(ctx), expected_param_check)) goto done; +#ifndef OPENSSL_NO_DEPRECATED_3_0 + ctx2 = EVP_PKEY_CTX_new_id(0xdefaced, NULL); + /* assign the pkey directly, as an internal test */ + if (!EVP_PKEY_up_ref(pkey)) + goto done; + + ctx2->pkey = pkey; + + if (!TEST_int_eq(EVP_PKEY_check(ctx2), 0xbeef)) + goto done; + + if (!TEST_int_eq(EVP_PKEY_public_check(ctx2), 0xbeef)) + goto done; + + if (!TEST_int_eq(EVP_PKEY_param_check(ctx2), 0xbeef)) + goto done; +#endif + ret = 1; done: EVP_PKEY_CTX_free(ctx); +#ifndef OPENSSL_NO_DEPRECATED_3_0 + EVP_PKEY_CTX_free(ctx2); +#endif EVP_PKEY_free(pkey); return ret; } @@ -4165,155 +4133,6 @@ err: return ret; } -static int test_RSA_verify_recover_rejects_short_buffer(void) -{ - int ret = 0; - int recovered_cap = 0; - EVP_PKEY *pkey = NULL; - EVP_PKEY_CTX *sign_ctx = NULL, *verify_ctx = NULL; - unsigned char *sig = NULL, *recovered = NULL; - size_t sig_len = 0, recovered_len = 0; - unsigned long err = 0; - unsigned char shortbuf[] = { 0xa5, 0x5a }; - const unsigned char shortbuf_expected[] = { 0xa5, 0x5a }; - unsigned char digest[32]; - size_t i; - - for (i = 0; i < sizeof(digest); i++) - digest[i] = (unsigned char)i; - - if (OSSL_PROVIDER_available(testctx, "fips")) - return TEST_skip("Test skipped for FIPS provider"); - - if (!TEST_ptr(pkey = load_example_rsa_key()) - || !TEST_ptr(sign_ctx = EVP_PKEY_CTX_new_from_pkey(testctx, pkey, NULL)) - || !TEST_int_gt(EVP_PKEY_sign_init(sign_ctx), 0) - || !TEST_int_gt(EVP_PKEY_CTX_set_rsa_padding(sign_ctx, - RSA_PKCS1_PADDING), - 0) - || !TEST_int_gt(EVP_PKEY_CTX_set_signature_md(sign_ctx, EVP_sha256()), - 0) - || !TEST_int_gt(EVP_PKEY_sign(sign_ctx, NULL, &sig_len, digest, - sizeof(digest)), - 0) - || !TEST_ptr(sig = OPENSSL_malloc(sig_len)) - || !TEST_int_gt(EVP_PKEY_sign(sign_ctx, sig, &sig_len, digest, - sizeof(digest)), - 0) - || !TEST_int_gt(recovered_cap = EVP_PKEY_get_size(pkey), 0) - || !TEST_ptr(recovered = OPENSSL_malloc(recovered_cap)) - || !TEST_ptr(verify_ctx = EVP_PKEY_CTX_new_from_pkey(testctx, pkey, - NULL)) - || !TEST_int_gt(EVP_PKEY_verify_recover_init(verify_ctx), 0) - || !TEST_int_gt(EVP_PKEY_CTX_set_rsa_padding(verify_ctx, - RSA_PKCS1_PADDING), - 0) - || !TEST_int_gt(EVP_PKEY_CTX_set_signature_md(verify_ctx, EVP_sha256()), - 0)) - goto done; - - recovered_len = (size_t)recovered_cap; - if (!TEST_int_gt(EVP_PKEY_verify_recover(verify_ctx, recovered, - &recovered_len, sig, sig_len), - 0) - || !TEST_size_t_eq(recovered_len, sizeof(digest)) - || !TEST_mem_eq(recovered, recovered_len, digest, sizeof(digest))) - goto done; - - ERR_clear_error(); - recovered_len = 1; - if (!TEST_int_le(EVP_PKEY_verify_recover(verify_ctx, shortbuf, - &recovered_len, sig, sig_len), - 0)) - goto done; - - err = ERR_peek_error(); - if (!TEST_int_eq(ERR_GET_LIB(err), ERR_LIB_PROV) - || !TEST_int_eq(ERR_GET_REASON(err), PROV_R_OUTPUT_BUFFER_TOO_SMALL) - || !TEST_mem_eq(shortbuf, sizeof(shortbuf), shortbuf_expected, - sizeof(shortbuf_expected))) - goto done; - - ret = 1; -done: - EVP_PKEY_CTX_free(sign_ctx); - EVP_PKEY_CTX_free(verify_ctx); - EVP_PKEY_free(pkey); - OPENSSL_free(sig); - OPENSSL_free(recovered); - return ret; -} - -/* - * A raw RSA PKCS#1 v1.5 signature whose recovered data is empty must be - * recovered successfully with a length of zero, not rejected as an error. - */ -static int test_RSA_verify_recover_empty_payload(void) -{ - int ret = 0; - int recovered_cap = 0; - EVP_PKEY *pkey = NULL; - EVP_PKEY_CTX *sign_ctx = NULL, *verify_ctx = NULL; - unsigned char *sig = NULL, *recovered = NULL; - size_t sig_len = 0, recovered_len = 0; - /* - * The signed input has zero length, but a valid non-null address is still - * passed so the result does not depend on how lower layers treat NULL for - * zero-length data. - */ - const unsigned char empty[] = { 0 }; - - if (OSSL_PROVIDER_available(testctx, "fips")) - return TEST_skip("Test skipped for FIPS provider"); - - if (!TEST_ptr(pkey = load_example_rsa_key()) - || !TEST_ptr(sign_ctx = EVP_PKEY_CTX_new_from_pkey(testctx, pkey, NULL)) - || !TEST_int_gt(EVP_PKEY_sign_init(sign_ctx), 0) - || !TEST_int_gt(EVP_PKEY_CTX_set_rsa_padding(sign_ctx, RSA_PKCS1_PADDING), 0) - /* - * Deliberately do not configure a signature digest so that the raw - * PKCS#1 v1.5 sign and verify-recover paths are exercised. - */ - || !TEST_int_gt(EVP_PKEY_sign(sign_ctx, NULL, &sig_len, empty, 0), 0) - || !TEST_ptr(sig = OPENSSL_malloc(sig_len)) - || !TEST_int_gt(EVP_PKEY_sign(sign_ctx, sig, &sig_len, empty, 0), 0) - || !TEST_int_gt(recovered_cap = EVP_PKEY_get_size(pkey), 0) - || !TEST_ptr(recovered = OPENSSL_malloc(recovered_cap)) - || !TEST_ptr(verify_ctx = EVP_PKEY_CTX_new_from_pkey(testctx, pkey, NULL)) - || !TEST_int_gt(EVP_PKEY_verify_recover_init(verify_ctx), 0) - || !TEST_int_gt(EVP_PKEY_CTX_set_rsa_padding(verify_ctx, RSA_PKCS1_PADDING), - 0)) - goto done; - - /* Size-query call must succeed. */ - recovered_len = (size_t)recovered_cap; - if (!TEST_int_gt(EVP_PKEY_verify_recover(verify_ctx, NULL, - &recovered_len, sig, sig_len), - 0)) - goto done; - - /* - * The actual recovery call is essential: a NULL output buffer would only - * run the size-query path, which never decodes the signature and so would - * not reproduce the regression. - */ - recovered_len = (size_t)recovered_cap; - if (!TEST_int_gt(EVP_PKEY_verify_recover(verify_ctx, recovered, - &recovered_len, sig, sig_len), - 0) - || !TEST_size_t_eq(recovered_len, 0)) - goto done; - - ret = 1; -done: - EVP_PKEY_CTX_free(sign_ctx); - EVP_PKEY_CTX_free(verify_ctx); - EVP_PKEY_free(pkey); - OPENSSL_free(sig); - OPENSSL_free(recovered); - return ret; -} - static int test_RSA_encrypt(void) { int ret = 0; @@ -4573,139 +4392,6 @@ err: return ret; } #endif /* !OPENSSL_NO_DEPRECATED_3_0 */ - -/* Test that DHX (X9.42) rejects a malicious peer key during the - * derivation phase (specifically EVP_PKEY_derive_set_peer) when the - * remote 'q' does not match the local domain parameters but is still - * consistent with the remote key share. - * (CVE-2026-42770) - */ -static int test_dhx_derive_rejects_bad_peer_q(void) -{ - int ret = 0; - EVP_PKEY *local_key = NULL, *remote_key = NULL; - EVP_PKEY_CTX *pctx = NULL, *derive_ctx = NULL; - OSSL_PARAM_BLD *bld = NULL; - OSSL_PARAM *params = NULL; - - BIGNUM *p = NULL, *g = NULL; - BIGNUM *q_valid = NULL, *pub_local = NULL, *priv_local = NULL; - BIGNUM *q_bad = NULL, *pub_bad = NULL; - - const char *hex_p = "87a8e61db4b6663cffbbd19c651959998ceef608660dd0f25d2ceed4435e3b00" - "e00df8f1d61957d4faf7df4561b2aa3016c3d91134096faa3bf4296d830e9a7c" - "209e0c6497517abd5a8a9d306bcf67ed91f9e6725b4758c022e0b1ef4275bf7b" - "6c5bfc11d45f9088b941f54eb1e59bb8bc39a0bf12307f5c4fdb70c581b23f76" - "b63acae1caa6b7902d52526735488a0ef13c6d9a51bfa4ab3ad8347796524d8e" - "f6a167b5a41825d967e144e5140564251ccacb83e6b486f6b3ca3f7971506026" - "c0b857f689962856ded4010abd0be621c3a3960a54e710c375f26375d7014103" - "a4b54330c198af126116d2276e11715f693877fad7ef09cadb094ae91e1a1597"; - const char *hex_g = "3FB32C9B73134D0B2E77506660EDBD484CA7B18F21EF205407F4793A1A0BA125" - "10DBC15077BE463FFF4FED4AAC0BB555BE3A6C1B0C6B47B1BC3773BF7E8C6F62" - "901228F8C28CBB18A55AE31341000A650196F931C77A57F2DDF463E5E9EC144B" - "777DE62AAAB8A8628AC376D282D6ED3864E67982428EBC831D14348F6F2F9193" - "B5045AF2767164E1DFC967C1FB3F2E55A4BD1BFFE83B9C80D052B985D182EA0A" - "DB2A3B7313D3FE14C8484B1E052588B9B7D2BBD2DF016199ECD06E1557CD0915" - "B3353BBB64E0EC377FD028370DF92B52C7891428CDC67EB6184B523D1DB246C3" - "2F63078490F00EF8D647D148D47954515E2327CFEF98C582664B4C0F6CC41659"; - - const char *hex_q_valid = "8CF83642A709A097B447997640129DA299B1A47D1EB3750BA308B0FE64F5FBD3"; - const char *hex_local_pub = "796e15431470ac86fa8a78b8bcdd1f3589dbf15ffe0e0a7a41dd8640887f3cc3" - "f0439e281f4cf3800bac2dbdfcda589b26cc828512085ce0d3e57aa13cd9e7a4" - "66d881bace91ed10c6064ab36e0d66367c4bfed56a9f907e4daec16732fb5c54" - "891cb0d26251fd61c32040774246b3f8bdcd5ef60e6847cdd69bd6d318d1cda0" - "e8a30a716de4dc1a4eb99b0686b77120c4b69b0005f6a8c3ae768d23c08c85bd" - "1d58f40dc0138d6277436137ae69779fdc218c071c14826f471562033e85ffc9" - "9a2147d539e274136a4a1e7f1db97583b51dc0385a52d7383963758d893398a8" - "d013fdbad20ddf30fbe05fbb2249913ae6751b6b246ae5622ba26c4827417c2d"; - const char *hex_local_priv = "1122334455667788990011223344556677889900112233445566778899001122"; - - /* Remote malicious parameters */ - const char *hex_remote_q = "09f5"; - const char *hex_remote_pub = "54c057903d362235a65c03f001d8a3ea252836b3580250abdc0a1083451af012" - "6fd150f9e8d212b384ae0c23aa7c67fe851368114ccc061a661e986bd7e63d25" - "7513339a6914cbfab209ad793ef25704cd532ddfb7e693de701d17e629ef3c18" - "4d40d5fea1f9edb89c5bf8d7aa19e3374f805932159ca7b5d573b9e2f3c94fe7" - "47c4a3b09e31afa3788d35833aaf2ac8ae8bc48500131464e793a2e0352e7c3e" - "d9da9fcf89b121bc1cee83c544214ceb3338b14ac6891968351746eaf62bb517" - "eb98fc633d8d235bac37bc08e47f1851d05501949a6733965adbfe8e43f7c3b9" - "3ca7515cd6ab36d7ef26bb0fd6033abc39613e880fffc8729b03bfeaddf08833"; - - if (!TEST_true(BN_hex2bn(&p, hex_p)) || !TEST_true(BN_hex2bn(&g, hex_g))) - goto err; - - if (!TEST_true(BN_hex2bn(&q_valid, hex_q_valid)) - || !TEST_true(BN_hex2bn(&pub_local, hex_local_pub)) - || !TEST_true(BN_hex2bn(&priv_local, hex_local_priv))) - goto err; - - if (!TEST_ptr(bld = OSSL_PARAM_BLD_new()) - || !TEST_true(OSSL_PARAM_BLD_push_BN(bld, OSSL_PKEY_PARAM_FFC_P, p)) - || !TEST_true(OSSL_PARAM_BLD_push_BN(bld, OSSL_PKEY_PARAM_FFC_Q, q_valid)) - || !TEST_true(OSSL_PARAM_BLD_push_BN(bld, OSSL_PKEY_PARAM_FFC_G, g)) - || !TEST_true(OSSL_PARAM_BLD_push_BN(bld, OSSL_PKEY_PARAM_PUB_KEY, pub_local)) - || !TEST_true(OSSL_PARAM_BLD_push_BN(bld, OSSL_PKEY_PARAM_PRIV_KEY, priv_local)) - || !TEST_ptr(params = OSSL_PARAM_BLD_to_param(bld))) - goto err; - - if (!TEST_ptr(pctx = EVP_PKEY_CTX_new_from_name(testctx, "DHX", testpropq)) - || !TEST_int_gt(EVP_PKEY_fromdata_init(pctx), 0) - || !TEST_int_gt(EVP_PKEY_fromdata(pctx, &local_key, EVP_PKEY_KEYPAIR, params), 0)) - goto err; - - OSSL_PARAM_free(params); - OSSL_PARAM_BLD_free(bld); - EVP_PKEY_CTX_free(pctx); - params = NULL; - bld = NULL; - pctx = NULL; - - if (!TEST_true(BN_hex2bn(&q_bad, hex_remote_q)) - || !TEST_true(BN_hex2bn(&pub_bad, hex_remote_pub))) - goto err; - - if (!TEST_ptr(bld = OSSL_PARAM_BLD_new()) - || !TEST_true(OSSL_PARAM_BLD_push_BN(bld, OSSL_PKEY_PARAM_FFC_P, p)) - || !TEST_true(OSSL_PARAM_BLD_push_BN(bld, OSSL_PKEY_PARAM_FFC_Q, q_bad)) - || !TEST_true(OSSL_PARAM_BLD_push_BN(bld, OSSL_PKEY_PARAM_FFC_G, g)) - || !TEST_true(OSSL_PARAM_BLD_push_BN(bld, OSSL_PKEY_PARAM_PUB_KEY, pub_bad)) - || !TEST_ptr(params = OSSL_PARAM_BLD_to_param(bld))) - goto err; - - if (!TEST_ptr(pctx = EVP_PKEY_CTX_new_from_name(testctx, "DHX", testpropq)) - || !TEST_int_gt(EVP_PKEY_fromdata_init(pctx), 0) - || !TEST_int_gt(EVP_PKEY_fromdata(pctx, &remote_key, EVP_PKEY_PUBLIC_KEY, params), 0)) - goto err; - - if (!TEST_ptr(derive_ctx = EVP_PKEY_CTX_new(local_key, NULL)) - || !TEST_int_gt(EVP_PKEY_derive_init(derive_ctx), 0)) - goto err; - - /* reject the remote key share, even if it is self-consistent, correct - * code needs to use local q, not remote-provided q. */ - if (!TEST_int_le(EVP_PKEY_derive_set_peer(derive_ctx, remote_key), 0)) { - TEST_error("EVP_PKEY_derive_set_peer incorrectly accepted a peer with malicious 'q'"); - goto err; - } - - ret = 1; - -err: - BN_free(p); - BN_free(g); - BN_free(q_valid); - BN_free(pub_local); - BN_free(priv_local); - BN_free(q_bad); - BN_free(pub_bad); - OSSL_PARAM_free(params); - OSSL_PARAM_BLD_free(bld); - EVP_PKEY_CTX_free(pctx); - EVP_PKEY_CTX_free(derive_ctx); - EVP_PKEY_free(local_key); - EVP_PKEY_free(remote_key); - return ret; -} #endif /* !OPENSSL_NO_DH */ /* @@ -5415,1368 +5101,6 @@ err: return res; } -/* - * Dynamically discover all applicable ciphers and verify multi-step - * init works correctly. This test should require zero maintenance when new - * ciphers are added, as the discovery loop handles them. - * This test focuses on verifying that ciphers do not reuse a key when it is - * changed under the same context in different steps. - */ - -/* maximum AEAD tag buffer size, exceeds AES-CBC-HMAC-SHA512 */ -#define EVPTEST_TAG_LEN_MAX EVP_MAX_MD_SIZE - -/* default AEAD tag length for standard modes (GCM, CCM, OCB, etc.) */ -#define EVPTEST_TAG_LEN_DEFAULT 16 - -typedef struct { - const EVP_CIPHER *ciph; - const char *name; - int keylen; - int ivlen; - int mode; - int taglen; -} EVP_CIPHER_TEST_INFO; - -static EVP_CIPHER_TEST_INFO *cipher_list = NULL; -static int cipher_list_n = 0; - -static int seen_name(const char *name) -{ - int i = 0; - - if (name == NULL) { - return 1; - } - for (i = 0; i < cipher_list_n; i++) { - if (OPENSSL_strcasecmp(cipher_list[i].name, name) == 0) - return 1; - } - return 0; -} - -static void collect_cipher_cb(EVP_CIPHER *ciph, void *arg) -{ - EVP_CIPHER_TEST_INFO *info = NULL; - const char *name0 = NULL; - int taglen = 0; - - size_t *allocated = arg; - - if (ciph == NULL) - return; - - name0 = EVP_CIPHER_get0_name(ciph); - taglen = (EVP_CIPHER_get_flags(ciph) & EVP_CIPH_FLAG_AEAD_CIPHER) != 0 - ? EVPTEST_TAG_LEN_DEFAULT - : 0; - - if (name0 == NULL || seen_name(name0)) - return; - if (EVP_CIPHER_get_iv_length(ciph) <= 0) - return; - if (EVP_CIPHER_get_mode(ciph) == EVP_CIPH_SIV_MODE) - return; - - /* - * Exclude ETM ciphers that only exist on ARM. - * - * These are special-purpose TLS ciphers with a different initialization - * order that breaks this test's logic. - */ - if (EVP_CIPHER_is_a(ciph, "AES-128-CBC-HMAC-SHA1-ETM") - || EVP_CIPHER_is_a(ciph, "AES-128-CBC-HMAC-SHA256-ETM") - || EVP_CIPHER_is_a(ciph, "AES-128-CBC-HMAC-SHA512-ETM") - || EVP_CIPHER_is_a(ciph, "AES-192-CBC-HMAC-SHA1-ETM") - || EVP_CIPHER_is_a(ciph, "AES-192-CBC-HMAC-SHA256-ETM") - || EVP_CIPHER_is_a(ciph, "AES-192-CBC-HMAC-SHA512-ETM") - || EVP_CIPHER_is_a(ciph, "AES-256-CBC-HMAC-SHA1-ETM") - || EVP_CIPHER_is_a(ciph, "AES-256-CBC-HMAC-SHA256-ETM") - || EVP_CIPHER_is_a(ciph, "AES-256-CBC-HMAC-SHA512-ETM")) - return; - - /* First pass only counts ciphers to allocate memory */ - if (allocated != NULL) { - (*allocated)++; - return; - } - - info = &cipher_list[cipher_list_n]; - - if (!EVP_CIPHER_up_ref(ciph)) - return; - - info->ciph = ciph; - info->name = name0; - info->keylen = EVP_CIPHER_get_key_length(ciph); - info->ivlen = EVP_CIPHER_get_iv_length(ciph); - info->mode = EVP_CIPHER_get_mode(ciph); - info->taglen = taglen; - - cipher_list_n++; -} - -static int setup_cipher_list(void) -{ - size_t cipher_list_size = 0; - cipher_list = NULL; - cipher_list_n = 0; - - /* first pass goes through counting only for allocating */ - EVP_CIPHER_do_all_provided(NULL, collect_cipher_cb, &cipher_list_size); - - if (!TEST_size_t_gt(cipher_list_size, 0)) - return 0; - - cipher_list = OPENSSL_malloc(cipher_list_size * sizeof(*cipher_list)); - if (!TEST_ptr(cipher_list)) - return 0; - - EVP_CIPHER_do_all_provided(NULL, collect_cipher_cb, NULL); - return TEST_true(cipher_list_n > 0); -} - -static void cleanup_cipher_list(void) -{ - int i; - - if (cipher_list == NULL) - return; - - for (i = 0; i < cipher_list_n; i++) { - if (cipher_list[i].ciph != NULL) - EVP_CIPHER_free((EVP_CIPHER *)cipher_list[i].ciph); - } - - OPENSSL_free(cipher_list); - cipher_list = NULL; - cipher_list_n = 0; -} -/*- - * This test verifies that initializing a cipher with a key and IV in - * different steps is the same as initializing the cipher in a single step - */ -static int test_evp_diff_order_init(int idx) -{ - const EVP_CIPHER_TEST_INFO *info = &cipher_list[idx]; - EVP_CIPHER_CTX *ctx_keyiv = NULL; /* used to test multi step init KEY->IV */ - EVP_CIPHER_CTX *ctx_ivkey = NULL; /* used to test multi step init IV->KEY */ - EVP_CIPHER_CTX *ctx_onestep = NULL; /* base test with single step init */ - - OSSL_PARAM ivparams[2]; - OSSL_PARAM tagparams[2]; - OSSL_PARAM get_tagparams[2]; - - int ivlen = info->ivlen; - unsigned char key[EVP_MAX_KEY_LENGTH] = { 0 }; - unsigned char iv[EVP_MAX_IV_LENGTH] = { 0 }; - - size_t pt_size = 0, j = 0; - unsigned char pt[128] = { 0 }; - - unsigned char ct_keyiv[128] = { 0 }; - int ct_keyiv_len = 0; - int ct_keyiv_fin_len = 0; - - unsigned char ct_ivkey[128] = { 0 }; - int ct_ivkey_len = 0; - int ct_ivkey_fin_len = 0; - - unsigned char ct_onestep[128] = { 0 }; - int ct_onestep_len = 0; - int ct_onestep_fin_len = 0; - - int taglen = info->taglen; - unsigned char tag_keyiv[EVPTEST_TAG_LEN_MAX] = { 0 }; - unsigned char tag_ivkey[EVPTEST_TAG_LEN_MAX] = { 0 }; - unsigned char tag_onestep[EVPTEST_TAG_LEN_MAX] = { 0 }; - - int blocksz = 0, tmplen = 0, testresult = 1, i = 0; - char *errmsg = NULL; - - ivparams[0] = OSSL_PARAM_construct_int(OSSL_CIPHER_PARAM_AEAD_IVLEN, &ivlen); - ivparams[1] = OSSL_PARAM_construct_end(); - tagparams[0] = OSSL_PARAM_construct_int(OSSL_CIPHER_PARAM_AEAD_TAGLEN, &taglen); - tagparams[1] = OSSL_PARAM_construct_end(); - - blocksz = EVP_CIPHER_get_block_size(info->ciph); - pt_size = (blocksz > 1) ? (size_t)blocksz * 2 : 31; - - if (!TEST_ptr(ctx_keyiv = EVP_CIPHER_CTX_new())) { - errmsg = "CTX_KEYIV_ALLOC"; - goto err; - } - - if (!TEST_true(EVP_EncryptInit_ex(ctx_keyiv, info->ciph, - NULL, NULL, NULL))) { - errmsg = "KEYIV_INIT"; - goto err; - } - - if (info->taglen > 0 && info->mode == EVP_CIPH_CCM_MODE) { - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_keyiv, ivparams))) { - errmsg = "CCM_SET_IVLEN"; - goto err; - } - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_keyiv, tagparams))) { - errmsg = "CCM_SET_TAGLEN"; - goto err; - } - } - - for (i = 0; i < info->keylen && i < (int)sizeof(key); i++) - key[i] = (unsigned char)(0xA0 + i); - for (i = 0; i < info->ivlen && i < (int)sizeof(iv); i++) - iv[i] = (unsigned char)(0xB0 + i); - - /* Initialize first with key->IV */ - if (!TEST_true(EVP_EncryptInit_ex(ctx_keyiv, NULL, NULL, key, NULL))) { - errmsg = "INIT_KEY_ONLY"; - goto err; - } - - if (!TEST_true(EVP_EncryptInit_ex(ctx_keyiv, NULL, NULL, NULL, iv))) { - errmsg = "INIT_IV_ONLY"; - goto err; - } - - /* disable padding for non-aead block-aligned pt */ - if (info->taglen == 0 && blocksz > 1) - EVP_CIPHER_CTX_set_padding(ctx_keyiv, 0); - - for (j = 0; j < pt_size; j++) - pt[j] = (unsigned char)(0xA0); - - if (info->taglen > 0 && info->mode == EVP_CIPH_CCM_MODE - && !TEST_true(EVP_EncryptUpdate(ctx_keyiv, NULL, - &tmplen, NULL, (int)pt_size))) { - errmsg = "CCM_DECLARE_PTLEN"; - goto err; - } - - if (!TEST_true(EVP_EncryptUpdate(ctx_keyiv, ct_keyiv, &ct_keyiv_len, - pt, (int)pt_size))) { - errmsg = "ENCRYPT_UPDATE"; - goto err; - } - - if (!TEST_true(EVP_EncryptFinal_ex(ctx_keyiv, ct_keyiv + ct_keyiv_len, - &ct_keyiv_fin_len))) { - errmsg = "ENCRYPT_FINAL"; - goto err; - } - - ct_keyiv_len += ct_keyiv_fin_len; - if (info->taglen > 0) { - /* override taglen from context if available */ - int tl = EVP_CIPHER_CTX_get_tag_length(ctx_keyiv); - - if (tl > 0) - taglen = tl; - - get_tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, - tag_keyiv, taglen); - get_tagparams[1] = OSSL_PARAM_construct_end(); - if (!TEST_true(EVP_CIPHER_CTX_get_params(ctx_keyiv, get_tagparams))) { - errmsg = "AEAD_GET_TAG"; - goto err; - } - } - - /* INIT IV then KEY ctx_ivkey */ - if (!TEST_ptr(ctx_ivkey = EVP_CIPHER_CTX_new())) { - errmsg = "CTX_IVKEY_ALLOC"; - goto err; - } - - if (!TEST_true(EVP_EncryptInit_ex(ctx_ivkey, info->ciph, - NULL, NULL, NULL))) { - errmsg = "IVKEY_INIT"; - goto err; - } - - if (info->taglen > 0 && info->mode == EVP_CIPH_CCM_MODE) { - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_ivkey, ivparams))) { - errmsg = "CCM_SET_IVLEN"; - goto err; - } - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_ivkey, tagparams))) { - errmsg = "CCM_SET_TAGLEN"; - goto err; - } - } - /* Initialize first with IV */ - if (!TEST_true(EVP_EncryptInit_ex(ctx_ivkey, NULL, NULL, NULL, iv))) { - errmsg = "INIT_IV_ONLY"; - goto err; - } - - if (!TEST_true(EVP_EncryptInit_ex(ctx_ivkey, NULL, NULL, key, NULL))) { - errmsg = "INIT_KEY_ONLY"; - goto err; - } - - if (info->taglen == 0 && blocksz > 1) - EVP_CIPHER_CTX_set_padding(ctx_ivkey, 0); - - if (info->taglen > 0 && info->mode == EVP_CIPH_CCM_MODE - && !TEST_true(EVP_EncryptUpdate(ctx_ivkey, NULL, - &tmplen, NULL, (int)pt_size))) { - errmsg = "CCM_DECLARE_PTLEN"; - goto err; - } - - if (!TEST_true(EVP_EncryptUpdate(ctx_ivkey, ct_ivkey, &ct_ivkey_len, - pt, (int)pt_size))) { - errmsg = "ENCRYPT_UPDATE"; - goto err; - } - - if (!TEST_true(EVP_EncryptFinal_ex(ctx_ivkey, ct_ivkey + ct_ivkey_len, - &ct_ivkey_fin_len))) { - errmsg = "ENCRYPT_FINAL"; - goto err; - } - - ct_ivkey_len += ct_ivkey_fin_len; - get_tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, - tag_ivkey, taglen); - - if (info->taglen > 0 - && !TEST_true(EVP_CIPHER_CTX_get_params(ctx_ivkey, get_tagparams))) { - errmsg = "AEAD_GET_TAG"; - goto err; - } - /* single step initialization */ - if (!TEST_ptr(ctx_onestep = EVP_CIPHER_CTX_new())) { - errmsg = "CTX_ONESTEP_ALLOC"; - goto err; - } - - if (!TEST_true(EVP_EncryptInit_ex(ctx_onestep, info->ciph, - NULL, NULL, NULL))) { - errmsg = "ONESTEP_INIT"; - goto err; - } - if (info->taglen > 0 && info->mode == EVP_CIPH_CCM_MODE) { - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_onestep, ivparams))) { - errmsg = "CCM_SET_IVLEN"; - goto err; - } - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_onestep, tagparams))) { - errmsg = "CCM_SET_TAGLEN"; - goto err; - } - } - - /* Initialize in a single step */ - if (!TEST_true(EVP_EncryptInit_ex(ctx_onestep, NULL, NULL, key, iv))) { - errmsg = "SINGLE_STEP_IV"; - goto err; - } - - if (info->taglen == 0 && blocksz > 1) - EVP_CIPHER_CTX_set_padding(ctx_onestep, 0); - - if (info->taglen > 0 && info->mode == EVP_CIPH_CCM_MODE - && !TEST_true(EVP_EncryptUpdate(ctx_onestep, NULL, - &tmplen, NULL, (int)pt_size))) { - errmsg = "CCM_DECLARE_PTLEN"; - goto err; - } - - if (!TEST_true(EVP_EncryptUpdate(ctx_onestep, ct_onestep, - &ct_onestep_len, pt, (int)pt_size))) { - errmsg = "ENCRYPT_UPDATE"; - goto err; - } - - if (!TEST_true(EVP_EncryptFinal_ex(ctx_onestep, ct_onestep + ct_onestep_len, - &ct_onestep_fin_len))) { - errmsg = "ENCRYPT_FINAL_ONE_STEP"; - goto err; - } - - ct_onestep_len += ct_onestep_fin_len; - get_tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, - tag_onestep, taglen); - - if (info->taglen > 0 - && !TEST_true(EVP_CIPHER_CTX_get_params(ctx_onestep, get_tagparams))) { - errmsg = "AEAD_GET_TAG"; - goto err; - } - - /* Compare single-call vs key->iv */ - if (!TEST_int_eq(ct_onestep_len, ct_keyiv_len) - || !TEST_mem_eq(ct_onestep, ct_onestep_len, ct_keyiv, ct_keyiv_len)) { - errmsg = "CT_MISMATCH_SINGLE_vs_KEYIV"; - goto err; - } - - /* Compare single-call vs iv->key */ - if (!TEST_int_eq(ct_onestep_len, ct_ivkey_len) - || !TEST_mem_eq(ct_onestep, ct_onestep_len, ct_ivkey, ct_ivkey_len)) { - errmsg = "CT_MISMATCH_SINGLE_vs_IVKEY"; - goto err; - } - - if (info->taglen > 0 - && !TEST_mem_eq(tag_onestep, taglen, tag_keyiv, taglen)) { - errmsg = "TAG_MISMATCH_SINGLE_vs_KEYIV"; - goto err; - } - - if (info->taglen > 0 - && !TEST_mem_eq(tag_onestep, taglen, tag_ivkey, taglen)) { - errmsg = "TAG_MISMATCH_SINGLE_vs_IVKEY"; - goto err; - } - -err: - if (errmsg != NULL) { - TEST_info("evp_multi_step_integrity_test %d, %s: %s", - idx, errmsg, info->name); - testresult = 0; - } - EVP_CIPHER_CTX_free(ctx_keyiv); - EVP_CIPHER_CTX_free(ctx_ivkey); - EVP_CIPHER_CTX_free(ctx_onestep); - return testresult; -} - -/*- - * A zero-length AEAD message driven through the one-shot EVP_Cipher() interface - * must agree with the streaming EVP_CipherFinal_ex() path. This checks: - * - an empty message yields the same tag via both interfaces - * - the true tag passes verification on decrypt - * - the modified tag fails verification on decrypt - */ -static int test_evp_oneshot_aead_zerolen(int idx) -{ - const EVP_CIPHER_TEST_INFO *info = &cipher_list[idx]; - EVP_CIPHER_CTX *ctx_stream = NULL; /* reference: final only */ - EVP_CIPHER_CTX *ctx_oneshot = NULL; /* encrypt via EVP_Cipher(in == NULL) */ - EVP_CIPHER_CTX *ctx_dec = NULL; /* decrypt via EVP_Cipher(in == NULL) */ - EVP_CIPHER_CTX *ctx_dec_bad = NULL; /* decrypt with a corrupted tag */ - EVP_CIPHER_CTX *ctx_dec_s = NULL; /* streaming decrypt */ - EVP_CIPHER_CTX *ctx_dec_s_bad = NULL; /* streaming decrypt, corrupted tag */ - - OSSL_PARAM get_tagparams[2]; - OSSL_PARAM set_tagparams[2]; - - int taglen = info->taglen; - unsigned char key[EVP_MAX_KEY_LENGTH] = { 0 }; - unsigned char iv[EVP_MAX_IV_LENGTH] = { 0 }; - - unsigned char ct[16] = { 0 }; /* scratch out; AEAD finalize writes no data */ - int finlen = 0, oneshot_flen = 0, dec_flen = 0; - - unsigned char tag_stream[EVPTEST_TAG_LEN_MAX] = { 0 }; - unsigned char tag_oneshot[EVPTEST_TAG_LEN_MAX] = { 0 }; - unsigned char tag_bad[EVPTEST_TAG_LEN_MAX] = { 0 }; - - int i = 0, testresult = 1; - char *errmsg = NULL; - - /* filter out various modes */ - if (info->taglen == 0 - || info->mode == EVP_CIPH_CCM_MODE - || info->mode == EVP_CIPH_OCB_MODE - || info->mode == EVP_CIPH_GCM_SIV_MODE - /* skip TLS stitched MTE cipher */ - || EVP_CIPHER_is_a(info->ciph, "AES-128-CBC-HMAC-SHA1") - /* skip TLS stitched MTE cipher */ - || EVP_CIPHER_is_a(info->ciph, "AES-256-CBC-HMAC-SHA1") - /* skip TLS stitched MTE cipher */ - || EVP_CIPHER_is_a(info->ciph, "AES-128-CBC-HMAC-SHA256") - /* skip TLS stitched MTE cipher */ - || EVP_CIPHER_is_a(info->ciph, "AES-256-CBC-HMAC-SHA256") - || EVP_CIPHER_is_a(info->ciph, "ChaCha20-Poly1305")) - return 1; - - for (i = 0; i < info->keylen && i < (int)sizeof(key); i++) - key[i] = (unsigned char)(0xA0 + i); - for (i = 0; i < info->ivlen && i < (int)sizeof(iv); i++) - iv[i] = (unsigned char)(0xB0 + i); - - /* reference: streaming finalize of an empty message */ - if (!TEST_ptr(ctx_stream = EVP_CIPHER_CTX_new())) { - errmsg = "STREAM_ALLOC"; - goto err; - } - if (!TEST_true(EVP_EncryptInit_ex2(ctx_stream, info->ciph, key, iv, NULL))) { - errmsg = "STREAM_INIT"; - goto err; - } - if (!TEST_true(EVP_EncryptFinal_ex(ctx_stream, ct, &finlen))) { - errmsg = "STREAM_FINAL"; - goto err; - } - - /* clamp to the negotiated tag length if the cipher reports one */ - i = EVP_CIPHER_CTX_get_tag_length(ctx_stream); - if (i > 0) - taglen = i; - - /* bound the memcpy, should never happen but helps static analysis */ - if (taglen > EVPTEST_TAG_LEN_MAX) { - errmsg = "TAGLEN_EXCEEDS_BUF"; - goto err; - } - - get_tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, - tag_stream, taglen); - get_tagparams[1] = OSSL_PARAM_construct_end(); - if (!TEST_true(EVP_CIPHER_CTX_get_params(ctx_stream, get_tagparams))) { - errmsg = "STREAM_GET_TAG"; - goto err; - } - - /* one-shot encrypt: finalize the empty message with in == NULL */ - if (!TEST_ptr(ctx_oneshot = EVP_CIPHER_CTX_new())) { - errmsg = "ONESHOT_ALLOC"; - goto err; - } - if (!TEST_true(EVP_EncryptInit_ex2(ctx_oneshot, info->ciph, key, iv, NULL))) { - errmsg = "ONESHOT_INIT"; - goto err; - } - oneshot_flen = EVP_Cipher(ctx_oneshot, ct, NULL, 0); - if (!TEST_int_ge(oneshot_flen, 0)) { - errmsg = "ONESHOT_FINAL_NULL"; - goto err; - } - - get_tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, - tag_oneshot, taglen); - if (!TEST_true(EVP_CIPHER_CTX_get_params(ctx_oneshot, get_tagparams))) { - errmsg = "ONESHOT_GET_TAG"; - goto err; - } - if (!TEST_mem_eq(tag_oneshot, taglen, tag_stream, taglen)) { - errmsg = "TAG_MISMATCH_ONESHOT_vs_STREAM"; - goto err; - } - - /* one-shot decrypt: the correct tag must verify via in == NULL */ - if (!TEST_ptr(ctx_dec = EVP_CIPHER_CTX_new())) { - errmsg = "DEC_ALLOC"; - goto err; - } - if (!TEST_true(EVP_DecryptInit_ex2(ctx_dec, info->ciph, key, iv, NULL))) { - errmsg = "DEC_INIT"; - goto err; - } - set_tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, - tag_stream, taglen); - set_tagparams[1] = OSSL_PARAM_construct_end(); - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_dec, set_tagparams))) { - errmsg = "DEC_SET_TAG"; - goto err; - } - dec_flen = EVP_Cipher(ctx_dec, ct, NULL, 0); - if (!TEST_int_ge(dec_flen, 0)) { - errmsg = "DEC_VERIFY_NULL"; - goto err; - } - - /* - * ...and a corrupted tag must be rejected. EVP_Cipher() returns < 0 on a - * failed one-shot, so a non-negative result here means verification was - * skipped or wrongly accepted the bad tag. - */ - memcpy(tag_bad, tag_stream, taglen); - tag_bad[0] ^= 0x01; - if (!TEST_ptr(ctx_dec_bad = EVP_CIPHER_CTX_new())) { - errmsg = "DEC_BAD_ALLOC"; - goto err; - } - if (!TEST_true(EVP_DecryptInit_ex2(ctx_dec_bad, info->ciph, key, iv, NULL))) { - errmsg = "DEC_BAD_INIT"; - goto err; - } - set_tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, - tag_bad, taglen); - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_dec_bad, set_tagparams))) { - errmsg = "DEC_BAD_SET_TAG"; - goto err; - } - if (!TEST_int_lt(EVP_Cipher(ctx_dec_bad, ct, NULL, 0), 0)) { - errmsg = "DEC_BADTAG_NOT_REJECTED"; - goto err; - } - - /* streaming decrypt: the correct tag must verify via EVP_DecryptFinal_ex */ - if (!TEST_ptr(ctx_dec_s = EVP_CIPHER_CTX_new())) { - errmsg = "DEC_STREAM_ALLOC"; - goto err; - } - if (!TEST_true(EVP_DecryptInit_ex2(ctx_dec_s, info->ciph, key, iv, NULL))) { - errmsg = "DEC_STREAM_INIT"; - goto err; - } - set_tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, - tag_stream, taglen); - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_dec_s, set_tagparams))) { - errmsg = "DEC_STREAM_SET_TAG"; - goto err; - } - if (!TEST_true(EVP_DecryptFinal_ex(ctx_dec_s, ct, &finlen))) { - errmsg = "DEC_STREAM_VERIFY"; - goto err; - } - - /* streaming decrypt: a corrupted tag must be rejected */ - if (!TEST_ptr(ctx_dec_s_bad = EVP_CIPHER_CTX_new())) { - errmsg = "DEC_STREAM_BAD_ALLOC"; - goto err; - } - if (!TEST_true(EVP_DecryptInit_ex2(ctx_dec_s_bad, info->ciph, key, iv, NULL))) { - errmsg = "DEC_STREAM_BAD_INIT"; - goto err; - } - set_tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, - tag_bad, taglen); - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_dec_s_bad, set_tagparams))) { - errmsg = "DEC_STREAM_BAD_SET_TAG"; - goto err; - } - if (!TEST_false(EVP_DecryptFinal_ex(ctx_dec_s_bad, ct, &finlen))) { - errmsg = "DEC_STREAM_BADTAG_NOT_REJECTED"; - goto err; - } - -err: - if (errmsg != NULL) { - TEST_info("test_evp_oneshot_aead_zerolen %d, %s: %s", - idx, errmsg, info->name); - testresult = 0; - } - EVP_CIPHER_CTX_free(ctx_stream); - EVP_CIPHER_CTX_free(ctx_oneshot); - EVP_CIPHER_CTX_free(ctx_dec); - EVP_CIPHER_CTX_free(ctx_dec_bad); - EVP_CIPHER_CTX_free(ctx_dec_s); - EVP_CIPHER_CTX_free(ctx_dec_s_bad); - return testresult; -} - -/* - * With AEAD ciphers, a tag is an input for decryption (the value to verify) - * and an output of encryption (the generated value). Therefore: - * - supplying a tag value while encrypting must fail - * - reading a tag while decrypting must fail - * - error codes should be consistent across all AEADs - */ -static int test_evp_aead_tag_direction(int idx) -{ - const EVP_CIPHER_TEST_INFO *info = &cipher_list[idx]; - EVP_CIPHER_CTX *ctx_enc = NULL; /* set tag while encrypting: must fail */ - EVP_CIPHER_CTX *ctx_dec = NULL; /* get tag while decrypting: must fail */ - - OSSL_PARAM tagparams[2]; - - unsigned char key[EVP_MAX_KEY_LENGTH] = { 0 }; - unsigned char iv[EVP_MAX_IV_LENGTH] = { 0 }; - unsigned char tag[EVPTEST_TAG_LEN_MAX] = { 0 }; - - int i = 0, testresult = 0, expected = 0; - char *errmsg = NULL; - unsigned long err_code = 0; - - /* filter out various modes */ - if (info->taglen == 0 - /* skip TLS stitched MTE cipher */ - || EVP_CIPHER_is_a(info->ciph, "AES-128-CBC-HMAC-SHA1") - /* skip TLS stitched MTE cipher */ - || EVP_CIPHER_is_a(info->ciph, "AES-256-CBC-HMAC-SHA1") - /* skip TLS stitched MTE cipher */ - || EVP_CIPHER_is_a(info->ciph, "AES-128-CBC-HMAC-SHA256") - /* skip TLS stitched MTE cipher */ - || EVP_CIPHER_is_a(info->ciph, "AES-256-CBC-HMAC-SHA256")) - return 1; - - for (i = 0; i < info->keylen && i < (int)sizeof(key); i++) - key[i] = (unsigned char)(0xA0 + i); - for (i = 0; i < info->ivlen && i < (int)sizeof(iv); i++) - iv[i] = (unsigned char)(0xB0 + i); - - /* - * a tag value supplied while encrypting must be rejected. data is non-NULL - * so this is a value-set, not the data == NULL tag-length query. - */ - if (!TEST_ptr(ctx_enc = EVP_CIPHER_CTX_new())) { - errmsg = "ENC_ALLOC"; - goto err; - } - if (!TEST_true(EVP_EncryptInit_ex2(ctx_enc, info->ciph, key, iv, NULL))) { - errmsg = "ENC_INIT"; - goto err; - } - tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, - tag, info->taglen); - tagparams[1] = OSSL_PARAM_construct_end(); - ERR_set_mark(); - if (!TEST_false(EVP_CIPHER_CTX_set_params(ctx_enc, tagparams))) { - ERR_clear_last_mark(); - errmsg = "ENC_SET_TAG_NOT_REJECTED"; - goto err; - } - err_code = ERR_peek_last_error(); - if (!TEST_int_eq(ERR_GET_LIB(err_code), ERR_LIB_PROV) - || !TEST_int_eq(ERR_GET_REASON(err_code), PROV_R_TAG_NOT_NEEDED)) { - ERR_clear_last_mark(); - expected = PROV_R_TAG_NOT_NEEDED; - errmsg = "ENC_SET_TAG_WRONG_REASON"; - goto err; - } - ERR_pop_to_mark(); - - /* a tag read while decrypting must be rejected */ - if (!TEST_ptr(ctx_dec = EVP_CIPHER_CTX_new())) { - errmsg = "DEC_ALLOC"; - goto err; - } - if (!TEST_true(EVP_DecryptInit_ex2(ctx_dec, info->ciph, key, iv, NULL))) { - errmsg = "DEC_INIT"; - goto err; - } - tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, - tag, info->taglen); - tagparams[1] = OSSL_PARAM_construct_end(); - - /* set a tag so the get below is exercised with one present */ - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_dec, tagparams))) { - errmsg = "DEC_SET_TAG_REJECTED"; - goto err; - } - - /* but a tag must never be readable back while decrypting */ - ERR_set_mark(); - if (!TEST_false(EVP_CIPHER_CTX_get_params(ctx_dec, tagparams))) { - ERR_clear_last_mark(); - errmsg = "DEC_GET_TAG_NOT_REJECTED"; - goto err; - } - err_code = ERR_peek_last_error(); - if (!TEST_int_eq(ERR_GET_LIB(err_code), ERR_LIB_PROV) - || !TEST_int_eq(ERR_GET_REASON(err_code), PROV_R_TAG_NOT_SET)) { - ERR_clear_last_mark(); - expected = PROV_R_TAG_NOT_SET; - errmsg = "DEC_GET_TAG_WRONG_REASON"; - goto err; - } - ERR_pop_to_mark(); - - testresult = 1; - -err: - if (errmsg != NULL) { - if (expected != 0) - TEST_info("test_evp_aead_tag_direction %d, %s: %s" - " (expected reason %d, got %d)", - idx, errmsg, info->name, - expected, ERR_GET_REASON(err_code)); - else - TEST_info("test_evp_aead_tag_direction %d, %s: %s", - idx, errmsg, info->name); - } - EVP_CIPHER_CTX_free(ctx_enc); - EVP_CIPHER_CTX_free(ctx_dec); - return testresult; -} - -/* - * With AEAD ciphers, associated data must precede the payload. Once plaintext - * or ciphertext processing has begun, a further AAD update (out == NULL) must - * be rejected, and the rejection must be reported the same way across every - * AEAD: ERR_LIB_PROV / PROV_R_UPDATE_CALL_OUT_OF_ORDER. The invariant is - * checked in both the encrypt and decrypt directions. - */ -static int test_evp_aead_late_aad(int idx) -{ - const EVP_CIPHER_TEST_INFO *info = &cipher_list[idx]; - EVP_CIPHER_CTX *ctx_enc = NULL; /* late AAD after plaintext: must fail */ - EVP_CIPHER_CTX *ctx_dec = NULL; /* late AAD after ciphertext: must fail */ - - unsigned char key[EVP_MAX_KEY_LENGTH] = { 0 }; - unsigned char iv[EVP_MAX_IV_LENGTH] = { 0 }; - unsigned char aad[] = "aad"; - unsigned char msg[] = "message"; - unsigned char out[sizeof(msg) + EVP_MAX_BLOCK_LENGTH]; - - int i = 0, len = 0, testresult = 0, expected = 0; - char *errmsg = NULL; - unsigned long err_code = 0; - - if (info->taglen == 0 /* skip non-AEAD */ - || info->mode == EVP_CIPH_GCM_MODE /* rejects, raises 102 PROV_R_CIPHER_OPERATION_FAILED */ - || info->mode == EVP_CIPH_CCM_MODE /* fails at first AAD */ - || info->mode == EVP_CIPH_OCB_MODE /* accepts late AAD */ - /* skip TLS stitched MTE cipher */ - || EVP_CIPHER_is_a(info->ciph, "AES-128-CBC-HMAC-SHA1") - /* skip TLS stitched MTE cipher */ - || EVP_CIPHER_is_a(info->ciph, "AES-256-CBC-HMAC-SHA1") - /* skip TLS stitched MTE cipher */ - || EVP_CIPHER_is_a(info->ciph, "AES-128-CBC-HMAC-SHA256") - /* skip TLS stitched MTE cipher */ - || EVP_CIPHER_is_a(info->ciph, "AES-256-CBC-HMAC-SHA256")) - return 1; - - for (i = 0; i < info->keylen && i < (int)sizeof(key); i++) - key[i] = (unsigned char)(0xA0 + i); - for (i = 0; i < info->ivlen && i < (int)sizeof(iv); i++) - iv[i] = (unsigned char)(0xB0 + i); - - /* encrypt: aad, then plaintext, then a late aad update must be rejected */ - if (!TEST_ptr(ctx_enc = EVP_CIPHER_CTX_new())) { - errmsg = "ENC_ALLOC"; - goto err; - } - if (!TEST_true(EVP_EncryptInit_ex2(ctx_enc, info->ciph, key, iv, NULL))) { - errmsg = "ENC_INIT"; - goto err; - } - if (!TEST_true(EVP_EncryptUpdate(ctx_enc, NULL, &len, aad, sizeof(aad)))) { - errmsg = "ENC_AAD"; - goto err; - } - if (!TEST_true(EVP_EncryptUpdate(ctx_enc, out, &len, msg, sizeof(msg)))) { - errmsg = "ENC_PLAINTEXT"; - goto err; - } - ERR_set_mark(); - if (!TEST_false(EVP_EncryptUpdate(ctx_enc, NULL, &len, aad, sizeof(aad)))) { - ERR_clear_last_mark(); - errmsg = "ENC_LATE_AAD_NOT_REJECTED"; - goto err; - } - err_code = ERR_peek_last_error(); - if (!TEST_int_eq(ERR_GET_LIB(err_code), ERR_LIB_PROV) - || !TEST_int_eq(ERR_GET_REASON(err_code), PROV_R_UPDATE_CALL_OUT_OF_ORDER)) { - ERR_clear_last_mark(); - expected = PROV_R_UPDATE_CALL_OUT_OF_ORDER; - errmsg = "ENC_LATE_AAD_WRONG_REASON"; - goto err; - } - ERR_pop_to_mark(); - - /* decrypt: same sequence, late aad after ciphertext must be rejected */ - if (!TEST_ptr(ctx_dec = EVP_CIPHER_CTX_new())) { - errmsg = "DEC_ALLOC"; - goto err; - } - if (!TEST_true(EVP_DecryptInit_ex2(ctx_dec, info->ciph, key, iv, NULL))) { - errmsg = "DEC_INIT"; - goto err; - } - if (!TEST_true(EVP_DecryptUpdate(ctx_dec, NULL, &len, aad, sizeof(aad)))) { - errmsg = "DEC_AAD"; - goto err; - } - /* the ciphertext content is irrelevant; the tag is never finalized here */ - if (!TEST_true(EVP_DecryptUpdate(ctx_dec, out, &len, msg, sizeof(msg)))) { - errmsg = "DEC_CIPHERTEXT"; - goto err; - } - ERR_set_mark(); - if (!TEST_false(EVP_DecryptUpdate(ctx_dec, NULL, &len, aad, sizeof(aad)))) { - ERR_clear_last_mark(); - errmsg = "DEC_LATE_AAD_NOT_REJECTED"; - goto err; - } - err_code = ERR_peek_last_error(); - if (!TEST_int_eq(ERR_GET_LIB(err_code), ERR_LIB_PROV) - || !TEST_int_eq(ERR_GET_REASON(err_code), PROV_R_UPDATE_CALL_OUT_OF_ORDER)) { - ERR_clear_last_mark(); - expected = PROV_R_UPDATE_CALL_OUT_OF_ORDER; - errmsg = "DEC_LATE_AAD_WRONG_REASON"; - goto err; - } - ERR_pop_to_mark(); - - testresult = 1; - -err: - if (errmsg != NULL) { - if (expected != 0) - TEST_info("test_evp_aead_late_aad %d, %s: %s" - " (expected reason %d, got %d)", - idx, errmsg, info->name, - expected, ERR_GET_REASON(err_code)); - else - TEST_info("test_evp_aead_late_aad %d, %s: %s", - idx, errmsg, info->name); - } - EVP_CIPHER_CTX_free(ctx_enc); - EVP_CIPHER_CTX_free(ctx_dec); - return testresult; -} - -/* - * Verify stale key is not being used after providing a new key in multiple steps. - * This test performs a full round of encryption and then changes the - * key and then the IV in a multi-step init. - * This is compared to another context without reinitialization to check - * if the new key is loaded correctly. - */ -static int test_evp_stale_key_reinit(int idx) -{ - const EVP_CIPHER_TEST_INFO *info = &cipher_list[idx]; - EVP_CIPHER_CTX *ctx_reinit = NULL; /* used to test multi step init KEY->IV */ - EVP_CIPHER_CTX *ctx_onestep = NULL; /* base test with single step init */ - - OSSL_PARAM ivparams[2]; - OSSL_PARAM tagparams[2]; - OSSL_PARAM get_tagparams[2]; - - int ivlen = info->ivlen; - unsigned char key[EVP_MAX_KEY_LENGTH] = { 0 }; - unsigned char key2[EVP_MAX_KEY_LENGTH] = { 0 }; - unsigned char iv[EVP_MAX_IV_LENGTH] = { 0 }; - unsigned char iv2[EVP_MAX_IV_LENGTH] = { 0 }; - - size_t pt_size = 0, j = 0; - unsigned char pt[128] = { 0 }; - - unsigned char ct[128] = { 0 }; - int ct_len = 0; - int ct_fin_len = 0; - - unsigned char ct_reinit[128] = { 0 }; - int ct_reinit_len = 0; - int ct_reinit_fin_len = 0; - - unsigned char ct_onestep[128] = { 0 }; - int ct_onestep_len = 0; - int ct_onestep_fin_len = 0; - - int taglen = info->taglen; - unsigned char tag[EVPTEST_TAG_LEN_MAX] = { 0 }; - unsigned char tag_reinit[EVPTEST_TAG_LEN_MAX] = { 0 }; - unsigned char tag_onestep[EVPTEST_TAG_LEN_MAX] = { 0 }; - - int blocksz = 0, tmplen = 0, testresult = 1, i = 0; - char *errmsg = NULL; - - ivparams[0] = OSSL_PARAM_construct_int(OSSL_CIPHER_PARAM_AEAD_IVLEN, &ivlen); - ivparams[1] = OSSL_PARAM_construct_end(); - tagparams[0] = OSSL_PARAM_construct_int(OSSL_CIPHER_PARAM_AEAD_TAGLEN, &taglen); - tagparams[1] = OSSL_PARAM_construct_end(); - - blocksz = EVP_CIPHER_get_block_size(info->ciph); - pt_size = (blocksz > 1) ? (size_t)blocksz * 2 : 31; - - for (i = 0; i < info->keylen && i < (int)sizeof(key); i++) - key[i] = (unsigned char)(0xA0 + i); - for (i = 0; i < info->keylen && i < (int)sizeof(key2); i++) - key2[i] = (unsigned char)(0xF0 + i); - - for (i = 0; i < info->ivlen && i < (int)sizeof(iv); i++) - iv[i] = (unsigned char)(0xB0 + i); - for (i = 0; i < info->ivlen && i < (int)sizeof(iv2); i++) - iv2[i] = (unsigned char)(0xDA + i); - - for (j = 0; j < pt_size; j++) - pt[j] = (unsigned char)(0xA7); - - if (!TEST_ptr(ctx_reinit = EVP_CIPHER_CTX_new())) { - errmsg = "CTX_REINIT_ALLOC"; - goto err; - } - - if (!TEST_true(EVP_EncryptInit_ex(ctx_reinit, info->ciph, - NULL, NULL, NULL))) { - errmsg = "CTX_FIRST_INIT"; - goto err; - } - - if (info->taglen > 0 && info->mode == EVP_CIPH_CCM_MODE) { - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_reinit, ivparams))) { - errmsg = "CCM_SET_IVLEN"; - goto err; - } - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_reinit, tagparams))) { - errmsg = "CCM_SET_TAGLEN"; - goto err; - } - } - - /* Initialize first with key */ - if (!TEST_true(EVP_EncryptInit_ex(ctx_reinit, NULL, NULL, key, iv))) { - errmsg = "FIRST_KEY_INIT"; - goto err; - } - - /* disable padding for non-aead block-aligned pt */ - if (info->taglen == 0 && blocksz > 1) - EVP_CIPHER_CTX_set_padding(ctx_reinit, 0); - - if (info->taglen > 0 && info->mode == EVP_CIPH_CCM_MODE - && !TEST_true(EVP_EncryptUpdate(ctx_reinit, NULL, - &tmplen, NULL, (int)pt_size))) { - errmsg = "CCM_DECLARE_PTLEN"; - goto err; - } - - if (!TEST_true(EVP_EncryptUpdate(ctx_reinit, ct, &ct_len, - pt, (int)pt_size))) { - errmsg = "ENCRYPT_UPDATE"; - goto err; - } - - if (!TEST_true(EVP_EncryptFinal_ex(ctx_reinit, ct + ct_len, - &ct_fin_len))) { - errmsg = "ENCRYPT_FINAL"; - goto err; - } - - ct_len += ct_fin_len; - if (info->taglen > 0) { - /* override taglen from context if available */ - int tl = EVP_CIPHER_CTX_get_tag_length(ctx_reinit); - - if (tl > 0) - taglen = tl; - - get_tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, - tag, taglen); - get_tagparams[1] = OSSL_PARAM_construct_end(); - if (!TEST_true(EVP_CIPHER_CTX_get_params(ctx_reinit, get_tagparams))) { - errmsg = "AEAD_GET_TAG"; - goto err; - } - } - - /* use same context with a different key and iv in multiple steps */ - if (!TEST_true(EVP_EncryptInit_ex(ctx_reinit, NULL, NULL, key2, NULL))) { - errmsg = "REINIT_KEY"; - goto err; - } - if (!TEST_true(EVP_EncryptInit_ex(ctx_reinit, NULL, NULL, NULL, iv2))) { - errmsg = "REINIT_IV"; - goto err; - } - - if (info->taglen > 0 && info->mode == EVP_CIPH_CCM_MODE - && !TEST_true(EVP_EncryptUpdate(ctx_reinit, NULL, - &tmplen, NULL, (int)pt_size))) { - errmsg = "CCM_DECLARE_PTLEN"; - goto err; - } - - if (!TEST_true(EVP_EncryptUpdate(ctx_reinit, ct_reinit, &ct_reinit_len, - pt, (int)pt_size))) { - errmsg = "ENCRYPT_UPDATE"; - goto err; - } - - if (!TEST_true(EVP_EncryptFinal_ex(ctx_reinit, ct_reinit + ct_reinit_len, - &ct_reinit_fin_len))) { - errmsg = "ENCRYPT_FINAL"; - goto err; - } - - ct_reinit_len += ct_reinit_fin_len; - get_tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, - tag_reinit, taglen); - - if (info->taglen > 0 - && !TEST_true(EVP_CIPHER_CTX_get_params(ctx_reinit, get_tagparams))) { - errmsg = "AEAD_GET_TAG"; - goto err; - } - - /* Initialize in a single step */ - if (!TEST_ptr(ctx_onestep = EVP_CIPHER_CTX_new())) { - errmsg = "CTX_ALLOC_BASE_CASE"; - goto err; - } - - if (!TEST_true(EVP_EncryptInit_ex(ctx_onestep, info->ciph, - NULL, NULL, NULL))) { - errmsg = "BASE_CASE_INIT"; - goto err; - } - - if (info->taglen > 0 && info->mode == EVP_CIPH_CCM_MODE) { - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_onestep, ivparams))) { - errmsg = "CCM_SET_IVLEN"; - goto err; - } - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_onestep, tagparams))) { - errmsg = "CCM_SET_TAGLEN"; - goto err; - } - } - - if (!TEST_true(EVP_EncryptInit_ex(ctx_onestep, NULL, NULL, key2, iv2))) { - errmsg = "SINGLE_STEP_INIT"; - goto err; - } - - if (info->taglen == 0 && blocksz > 1) - EVP_CIPHER_CTX_set_padding(ctx_onestep, 0); - - if (info->taglen > 0 && info->mode == EVP_CIPH_CCM_MODE - && !TEST_true(EVP_EncryptUpdate(ctx_onestep, NULL, - &tmplen, NULL, (int)pt_size))) { - errmsg = "CCM_DECLARE_PTLEN"; - goto err; - } - - if (!TEST_true(EVP_EncryptUpdate(ctx_onestep, ct_onestep, - &ct_onestep_len, pt, (int)pt_size))) { - errmsg = "ENCRYPT_UPDATE"; - goto err; - } - - if (!TEST_true(EVP_EncryptFinal_ex(ctx_onestep, ct_onestep + ct_onestep_len, - &ct_onestep_fin_len))) { - errmsg = "ENCRYPT_FINAL_ONE_STEP"; - goto err; - } - - ct_onestep_len += ct_onestep_fin_len; - get_tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, - tag_onestep, taglen); - - if (info->taglen > 0 - && !TEST_true(EVP_CIPHER_CTX_get_params(ctx_onestep, get_tagparams))) { - errmsg = "AEAD_GET_TAG"; - goto err; - } - - /* Compare single-call vs key->iv */ - if (!TEST_int_eq(ct_reinit_len, ct_onestep_len) - || !TEST_mem_eq(ct_reinit, ct_reinit_len, ct_onestep, ct_onestep_len)) { - errmsg = "CT_MISMATCH_SINGLE_vs_REINIT"; - goto err; - } - - if (info->taglen > 0 - && !TEST_mem_eq(tag_onestep, taglen, tag_reinit, taglen)) { - errmsg = "TAG_MISMATCH_SINGLE_vs_REINIT"; - goto err; - } -err: - if (errmsg != NULL) { - TEST_info("evp_stale_key_integrity_test %d, %s: %s", - idx, errmsg, info->name); - testresult = 0; - } - EVP_CIPHER_CTX_free(ctx_onestep); - EVP_CIPHER_CTX_free(ctx_reinit); - - return testresult; -} - -/* - * Decrypt roundtrip: - * Encrypt single-call, decrypt via multi-step init, verify plaintext recovery. - * For AEAD ciphers this also exercises tag verification. - * The goal is to test that EVP behaves the same when initializing the key - * in different steps or in a single one in decryption. - */ -static int test_evp_decrypt_roundtrip_multistep(int idx) -{ - const EVP_CIPHER_TEST_INFO *info = &cipher_list[idx]; - EVP_CIPHER_CTX *ctx_enc = NULL; /* single-call encrypt */ - EVP_CIPHER_CTX *ctx_dec = NULL; /* multi-step decrypt (KEY -> IV) */ - - OSSL_PARAM ivparams[2]; - OSSL_PARAM tagparams[2]; - OSSL_PARAM get_tagparams[2]; - - int ivlen = info->ivlen; - unsigned char key[EVP_MAX_KEY_LENGTH] = { 0 }; - unsigned char iv[EVP_MAX_IV_LENGTH] = { 0 }; - - size_t pt_size = 0, j = 0; - unsigned char pt[128] = { 0 }; - - unsigned char ct[128] = { 0 }; - int ct_len = 0; - int ct_fin_len = 0; - - unsigned char rt[128] = { 0 }; /* recovered plaintext */ - int rt_len = 0; - int rt_fin_len = 0; - - int taglen = info->taglen; - unsigned char tag[EVPTEST_TAG_LEN_MAX] = { 0 }; - - int blocksz = 0, tmplen = 0, testresult = 1, i = 0; - char *errmsg = NULL; - - blocksz = EVP_CIPHER_get_block_size(info->ciph); - pt_size = (blocksz > 1) ? (size_t)blocksz * 2 : 31; - - ivparams[0] = OSSL_PARAM_construct_int(OSSL_CIPHER_PARAM_AEAD_IVLEN, &ivlen); - ivparams[1] = OSSL_PARAM_construct_end(); - tagparams[0] = OSSL_PARAM_construct_int(OSSL_CIPHER_PARAM_AEAD_TAGLEN, &taglen); - tagparams[1] = OSSL_PARAM_construct_end(); - - for (i = 0; i < info->keylen && i < (int)sizeof(key); i++) - key[i] = (unsigned char)(0xA0 + i); - - for (i = 0; i < info->ivlen && i < (int)sizeof(iv); i++) - iv[i] = (unsigned char)(0xB0 + i); - - for (j = 0; j < pt_size; j++) - pt[j] = (unsigned char)(0xA7); - - /* Encrypt: single-call init */ - if (!TEST_ptr(ctx_enc = EVP_CIPHER_CTX_new())) { - errmsg = "CTX_ALLOC_ENC"; - goto err; - } - - if (!TEST_true(EVP_EncryptInit_ex(ctx_enc, info->ciph, NULL, NULL, NULL))) { - errmsg = "ENC_INIT_ALG"; - goto err; - } - - if (info->taglen > 0 && info->mode == EVP_CIPH_CCM_MODE) { - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_enc, ivparams))) { - errmsg = "ENC_CCM_SET_IVLEN"; - goto err; - } - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_enc, tagparams))) { - errmsg = "ENC_CCM_SET_TAGLEN"; - goto err; - } - } - - if (!TEST_true(EVP_EncryptInit_ex(ctx_enc, NULL, NULL, key, iv))) { - errmsg = "ENC_INIT_KEYIV"; - goto err; - } - - /* disable padding for non-aead block-aligned pt */ - if (info->taglen == 0 && blocksz > 1) - EVP_CIPHER_CTX_set_padding(ctx_enc, 0); - - /* CCM requires declaring plaintext length before actual EncryptUpdate */ - if (info->taglen > 0 && info->mode == EVP_CIPH_CCM_MODE - && !TEST_true(EVP_EncryptUpdate(ctx_enc, NULL, - &tmplen, NULL, (int)pt_size))) { - errmsg = "ENC_CCM_DECLARE_PTLEN"; - goto err; - } - - if (!TEST_true(EVP_EncryptUpdate(ctx_enc, ct, &ct_len, pt, (int)pt_size))) { - errmsg = "ENC_UPDATE"; - goto err; - } - - if (!TEST_true(EVP_EncryptFinal_ex(ctx_enc, ct + ct_len, &ct_fin_len))) { - errmsg = "ENC_FINAL"; - goto err; - } - ct_len += ct_fin_len; - - if (info->taglen > 0) { - /* override taglen from context if available */ - int tl = EVP_CIPHER_CTX_get_tag_length(ctx_enc); - - if (tl > 0) - taglen = tl; - get_tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, - tag, taglen); - get_tagparams[1] = OSSL_PARAM_construct_end(); - if (!TEST_true(EVP_CIPHER_CTX_get_params(ctx_enc, get_tagparams))) { - errmsg = "ENC_AEAD_GET_TAG"; - goto err; - } - } - - /* Decrypt: multi-step init (KEY -> IV) */ - if (!TEST_ptr(ctx_dec = EVP_CIPHER_CTX_new())) { - errmsg = "CTX_ALLOC_DEC"; - goto err; - } - - if (!TEST_true(EVP_DecryptInit_ex(ctx_dec, info->ciph, NULL, NULL, NULL))) { - errmsg = "DEC_INIT_ALG"; - goto err; - } - - tagparams[0] = OSSL_PARAM_construct_octet_string(OSSL_CIPHER_PARAM_AEAD_TAG, tag, (size_t)taglen); - /* CCM requires tag before init */ - if (info->taglen > 0 && info->mode == EVP_CIPH_CCM_MODE) { - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_dec, ivparams))) { - errmsg = "DEC_CCM_SET_IVLEN"; - goto err; - } - if (!TEST_true(EVP_CIPHER_CTX_set_params(ctx_dec, tagparams))) { - errmsg = "DEC_CCM_SET_TAG"; - goto err; - } - } - - /* key-only then iv-only */ - if (!TEST_true(EVP_DecryptInit_ex(ctx_dec, NULL, NULL, key, NULL))) { - errmsg = "DEC_INIT_KEY_ONLY"; - goto err; - } - if (!TEST_true(EVP_DecryptInit_ex(ctx_dec, NULL, NULL, NULL, iv))) { - errmsg = "DEC_INIT_IV_ONLY"; - goto err; - } - - /*- - * Non-CCM AEADs: set tag after multi-step init, reinit can clear - * provider tag state (e.g. ETM ciphers). - */ - if (info->taglen > 0 && info->mode != EVP_CIPH_CCM_MODE - && !TEST_true(EVP_CIPHER_CTX_set_params(ctx_dec, tagparams))) { - errmsg = "DEC_AEAD_SET_TAG"; - goto err; - } - - if (info->taglen == 0 && blocksz > 1) - EVP_CIPHER_CTX_set_padding(ctx_dec, 0); - - /* CCM requires declaring ct (or pt) len before DecryptUpdate */ - if (info->taglen > 0 && info->mode == EVP_CIPH_CCM_MODE - && !TEST_true(EVP_DecryptUpdate(ctx_dec, NULL, - &tmplen, NULL, ct_len))) { - errmsg = "DEC_CCM_DECLARE_CTLEN"; - goto err; - } - - if (!TEST_true(EVP_DecryptUpdate(ctx_dec, rt, &rt_len, ct, ct_len))) { - errmsg = "DEC_UPDATE"; - goto err; - } - - if (!TEST_true(EVP_DecryptFinal_ex(ctx_dec, rt + rt_len, &rt_fin_len))) { - /* For AEAD this is where tag verification failure is reported */ - errmsg = "DEC_FINAL_OR_TAG_VERIFY"; - goto err; - } - rt_len += rt_fin_len; - - /* Compare recovered plaintext */ - if (!TEST_size_t_eq((size_t)rt_len, pt_size) - || !TEST_mem_eq(rt, (size_t)rt_len, pt, pt_size)) { - errmsg = "PLAINTEXT_MISMATCH"; - goto err; - } - -err: - if (errmsg != NULL) { - TEST_info("evp_decrypt_roundtrip_multistep %d, %s: %s", - idx, errmsg, info->name); - testresult = 0; - } - EVP_CIPHER_CTX_free(ctx_enc); - EVP_CIPHER_CTX_free(ctx_dec); - return testresult; -} - /* * Test step-wise cipher initialization via EVP_CipherInit_ex where the * arguments are given one at a time and a final adjustment to the enc @@ -7127,8 +5451,7 @@ static int test_evp_final_no_tag(int idx) goto err; ctext_len += len; - if (!TEST_int_gt(EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_GET_TAG, 16, tag), - 0)) + if (!TEST_true(EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_GET_TAG, 16, tag))) goto err; EVP_CIPHER_CTX_free(ctx); @@ -7344,59 +5667,6 @@ err: return res; } -static const char *iv_state_ciphers[] = { - "AES-256-GCM", -#ifndef OPENSSL_NO_OCB - "AES-256-OCB", -#endif -#if !defined(OPENSSL_NO_CHACHA) && !defined(OPENSSL_NO_POLY1305) - "ChaCha20-Poly1305", -#endif -}; - -/* Negative test for IV_STATE_FINISHED (avoid IV reuse) */ -static int test_iv_reuse(int idx) -{ - int outlen; - int res = 0; - unsigned char outbuf[64]; - EVP_CIPHER_CTX *ctx = NULL; - EVP_CIPHER *ciph = NULL; - - if (!TEST_ptr(ctx = EVP_CIPHER_CTX_new())) - goto err; - - if (!TEST_ptr(ciph = EVP_CIPHER_fetch(testctx, iv_state_ciphers[idx], - testpropq))) - goto err; - - /* Use the cipher: Init, Update, Final. */ - if (!TEST_true(EVP_EncryptInit_ex2(ctx, ciph, kGCMDefaultKey, - iGCMDefaultIV, NULL))) - goto err; - if (!TEST_true(EVP_EncryptUpdate(ctx, outbuf, &outlen, gcmDefaultPlaintext, - sizeof(gcmDefaultPlaintext)))) - goto err; - if (!TEST_true(EVP_EncryptFinal_ex(ctx, outbuf, &outlen))) - goto err; - - /* Without IV change, EncryptUpdate must be rejected */ - ERR_set_mark(); - if (!TEST_false(EVP_EncryptUpdate(ctx, outbuf, &outlen, - gcmDefaultPlaintext, - sizeof(gcmDefaultPlaintext)))) { - ERR_clear_last_mark(); - goto err; - } - ERR_pop_to_mark(); - - res = 1; -err: - EVP_CIPHER_CTX_free(ctx); - EVP_CIPHER_free(ciph); - return res; -} - static const char *keylen_change_ciphers[] = { #ifndef OPENSSL_NO_BF "BF-ECB", @@ -7468,6 +5738,464 @@ err: return res; } +#ifndef OPENSSL_NO_DEPRECATED_3_0 +static EVP_PKEY_METHOD *custom_pmeth = NULL; +static const EVP_PKEY_METHOD *orig_pmeth = NULL; + +#define EVP_PKEY_CTRL_MY_COMMAND 9999 + +static int custom_pmeth_init(EVP_PKEY_CTX *ctx) +{ + int (*pinit)(EVP_PKEY_CTX *ctx); + + EVP_PKEY_meth_get_init(orig_pmeth, &pinit); + return pinit(ctx); +} + +static void custom_pmeth_cleanup(EVP_PKEY_CTX *ctx) +{ + void (*pcleanup)(EVP_PKEY_CTX *ctx); + + EVP_PKEY_meth_get_cleanup(orig_pmeth, &pcleanup); + pcleanup(ctx); +} + +static int custom_pmeth_sign(EVP_PKEY_CTX *ctx, unsigned char *out, + size_t *outlen, const unsigned char *in, + size_t inlen) +{ + int (*psign)(EVP_PKEY_CTX *ctx, unsigned char *sig, size_t *siglen, + const unsigned char *tbs, size_t tbslen); + + EVP_PKEY_meth_get_sign(orig_pmeth, NULL, &psign); + return psign(ctx, out, outlen, in, inlen); +} + +static int custom_pmeth_digestsign(EVP_MD_CTX *ctx, unsigned char *sig, + size_t *siglen, const unsigned char *tbs, + size_t tbslen) +{ + int (*pdigestsign)(EVP_MD_CTX *ctx, unsigned char *sig, size_t *siglen, + const unsigned char *tbs, size_t tbslen); + + EVP_PKEY_meth_get_digestsign(orig_pmeth, &pdigestsign); + return pdigestsign(ctx, sig, siglen, tbs, tbslen); +} + +static int custom_pmeth_derive(EVP_PKEY_CTX *ctx, unsigned char *key, + size_t *keylen) +{ + int (*pderive)(EVP_PKEY_CTX *ctx, unsigned char *key, size_t *keylen); + + EVP_PKEY_meth_get_derive(orig_pmeth, NULL, &pderive); + return pderive(ctx, key, keylen); +} + +static int custom_pmeth_copy(EVP_PKEY_CTX *dst, const EVP_PKEY_CTX *src) +{ + int (*pcopy)(EVP_PKEY_CTX *dst, const EVP_PKEY_CTX *src); + + EVP_PKEY_meth_get_copy(orig_pmeth, &pcopy); + return pcopy(dst, src); +} + +static int ctrl_called; + +static int custom_pmeth_ctrl(EVP_PKEY_CTX *ctx, int type, int p1, void *p2) +{ + int (*pctrl)(EVP_PKEY_CTX *ctx, int type, int p1, void *p2); + + EVP_PKEY_meth_get_ctrl(orig_pmeth, &pctrl, NULL); + + if (type == EVP_PKEY_CTRL_MY_COMMAND) { + ctrl_called = 1; + return 1; + } + + return pctrl(ctx, type, p1, p2); +} + +static int test_custom_pmeth(int idx) +{ + EVP_PKEY_CTX *pctx = NULL; + EVP_MD_CTX *ctx = NULL; + EVP_PKEY *pkey = NULL; + int id, orig_id, orig_flags; + int testresult = 0; + size_t reslen; + unsigned char *res = NULL; + unsigned char msg[] = { 'H', 'e', 'l', 'l', 'o' }; + const EVP_MD *md = EVP_sha256(); + int doderive = 0; + + ctrl_called = 0; + + /* We call deprecated APIs so this test doesn't support a custom libctx */ + if (testctx != NULL) + return 1; + + switch (idx) { + case 0: + case 6: + id = EVP_PKEY_RSA; + pkey = load_example_rsa_key(); + break; + case 1: + case 7: +#ifndef OPENSSL_NO_DSA + id = EVP_PKEY_DSA; + pkey = load_example_dsa_key(); + break; +#else + return 1; +#endif + case 2: + case 8: +#ifndef OPENSSL_NO_EC + id = EVP_PKEY_EC; + pkey = load_example_ec_key(); + break; +#else + return 1; +#endif + case 3: + case 9: +#ifndef OPENSSL_NO_ECX + id = EVP_PKEY_ED25519; + md = NULL; + pkey = load_example_ed25519_key(); + break; +#else + return 1; +#endif + case 4: + case 10: +#ifndef OPENSSL_NO_DH + id = EVP_PKEY_DH; + doderive = 1; + pkey = load_example_dh_key(); + break; +#else + return 1; +#endif + case 5: + case 11: +#ifndef OPENSSL_NO_ECX + id = EVP_PKEY_X25519; + doderive = 1; + pkey = load_example_x25519_key(); + break; +#else + return 1; +#endif + default: + TEST_error("Should not happen"); + goto err; + } + + if (!TEST_ptr(pkey)) + goto err; + + if (idx < 6) { + if (!TEST_true(evp_pkey_is_provided(pkey))) + goto err; + } else { + EVP_PKEY *tmp = pkey; + + /* Convert to a legacy key */ + pkey = EVP_PKEY_new(); + if (!TEST_ptr(pkey)) { + pkey = tmp; + goto err; + } + if (!TEST_true(evp_pkey_copy_downgraded(&pkey, tmp))) { + EVP_PKEY_free(tmp); + goto err; + } + EVP_PKEY_free(tmp); + if (!TEST_true(evp_pkey_is_legacy(pkey))) + goto err; + } + + if (!TEST_ptr(orig_pmeth = EVP_PKEY_meth_find(id)) + || !TEST_ptr(pkey)) + goto err; + + EVP_PKEY_meth_get0_info(&orig_id, &orig_flags, orig_pmeth); + if (!TEST_int_eq(orig_id, id) + || !TEST_ptr(custom_pmeth = EVP_PKEY_meth_new(id, orig_flags))) + goto err; + + if (id == EVP_PKEY_ED25519) { + EVP_PKEY_meth_set_digestsign(custom_pmeth, custom_pmeth_digestsign); + } + if (id == EVP_PKEY_DH || id == EVP_PKEY_X25519) { + EVP_PKEY_meth_set_derive(custom_pmeth, NULL, custom_pmeth_derive); + } else { + EVP_PKEY_meth_set_sign(custom_pmeth, NULL, custom_pmeth_sign); + } + if (id != EVP_PKEY_ED25519 && id != EVP_PKEY_X25519) { + EVP_PKEY_meth_set_init(custom_pmeth, custom_pmeth_init); + EVP_PKEY_meth_set_cleanup(custom_pmeth, custom_pmeth_cleanup); + EVP_PKEY_meth_set_copy(custom_pmeth, custom_pmeth_copy); + } + EVP_PKEY_meth_set_ctrl(custom_pmeth, custom_pmeth_ctrl, NULL); + if (!TEST_true(EVP_PKEY_meth_add0(custom_pmeth))) + goto err; + + if (doderive) { + pctx = EVP_PKEY_CTX_new(pkey, NULL); + if (!TEST_ptr(pctx) + || !TEST_int_eq(EVP_PKEY_derive_init(pctx), 1) + || !TEST_int_ge(EVP_PKEY_CTX_ctrl(pctx, -1, -1, + EVP_PKEY_CTRL_MY_COMMAND, 0, NULL), + 1) + || !TEST_int_eq(ctrl_called, 1) + || !TEST_int_ge(EVP_PKEY_derive_set_peer(pctx, pkey), 1) + || !TEST_int_ge(EVP_PKEY_derive(pctx, NULL, &reslen), 1) + || !TEST_ptr(res = OPENSSL_malloc(reslen)) + || !TEST_int_ge(EVP_PKEY_derive(pctx, res, &reslen), 1)) + goto err; + } else { + ctx = EVP_MD_CTX_new(); + reslen = EVP_PKEY_size(pkey); + res = OPENSSL_malloc(reslen); + if (!TEST_ptr(ctx) + || !TEST_ptr(res) + || !TEST_true(EVP_DigestSignInit(ctx, &pctx, md, NULL, pkey)) + || !TEST_int_ge(EVP_PKEY_CTX_ctrl(pctx, -1, -1, + EVP_PKEY_CTRL_MY_COMMAND, 0, NULL), + 1) + || !TEST_int_eq(ctrl_called, 1)) + goto err; + + if (id == EVP_PKEY_ED25519) { + if (!TEST_true(EVP_DigestSign(ctx, res, &reslen, msg, sizeof(msg)))) + goto err; + } else { + if (!TEST_true(EVP_DigestUpdate(ctx, msg, sizeof(msg))) + || !TEST_true(EVP_DigestSignFinal(ctx, res, &reslen))) + goto err; + } + } + + testresult = 1; +err: + OPENSSL_free(res); + EVP_MD_CTX_free(ctx); + if (doderive) + EVP_PKEY_CTX_free(pctx); + EVP_PKEY_free(pkey); + EVP_PKEY_meth_remove(custom_pmeth); + EVP_PKEY_meth_free(custom_pmeth); + custom_pmeth = NULL; + return testresult; +} + +static int test_evp_md_cipher_meth(void) +{ + EVP_MD *md = EVP_MD_meth_dup(EVP_sha256()); + EVP_CIPHER *ciph = EVP_CIPHER_meth_dup(EVP_aes_128_cbc()); + int testresult = 0; + + if (!TEST_ptr(md) || !TEST_ptr(ciph)) + goto err; + + testresult = 1; + +err: + EVP_MD_meth_free(md); + EVP_CIPHER_meth_free(ciph); + + return testresult; +} + +typedef struct { + int data; +} custom_dgst_ctx; + +static int custom_md_init_called = 0; +static int custom_md_cleanup_called = 0; + +static int custom_md_init(EVP_MD_CTX *ctx) +{ + custom_dgst_ctx *p = EVP_MD_CTX_md_data(ctx); + + if (p == NULL) + return 0; + + custom_md_init_called++; + return 1; +} + +static int custom_md_cleanup(EVP_MD_CTX *ctx) +{ + custom_dgst_ctx *p = EVP_MD_CTX_md_data(ctx); + + if (p == NULL) + /* Nothing to do */ + return 1; + + custom_md_cleanup_called++; + return 1; +} + +static int test_custom_md_meth(void) +{ + ASN1_OBJECT *o = NULL; + EVP_MD_CTX *mdctx = NULL; + EVP_MD *tmp = NULL; + char mess[] = "Test Message\n"; + unsigned char md_value[EVP_MAX_MD_SIZE]; + unsigned int md_len; + int testresult = 0; + int nid; + + /* + * We are testing deprecated functions. We don't support a non-default + * library context in this test. + */ + if (testctx != NULL) + return TEST_skip("Non-default libctx"); + + custom_md_init_called = custom_md_cleanup_called = 0; + + nid = OBJ_create("1.3.6.1.4.1.16604.998866.1", "custom-md", "custom-md"); + if (!TEST_int_ne(nid, NID_undef)) + goto err; + if (!TEST_int_eq(OBJ_txt2nid("1.3.6.1.4.1.16604.998866.1"), nid)) + goto err; + tmp = EVP_MD_meth_new(nid, NID_undef); + if (!TEST_ptr(tmp)) + goto err; + + if (!TEST_true(EVP_MD_meth_set_init(tmp, custom_md_init)) + || !TEST_true(EVP_MD_meth_set_cleanup(tmp, custom_md_cleanup)) + || !TEST_true(EVP_MD_meth_set_app_datasize(tmp, + sizeof(custom_dgst_ctx)))) + goto err; + + mdctx = EVP_MD_CTX_new(); + if (!TEST_ptr(mdctx) + /* + * Initing our custom md and then initing another md should + * result in the init and cleanup functions of the custom md + * being called. + */ + || !TEST_true(EVP_DigestInit_ex(mdctx, tmp, NULL)) + || !TEST_true(EVP_DigestInit_ex(mdctx, EVP_sha256(), NULL)) + || !TEST_true(EVP_DigestUpdate(mdctx, mess, strlen(mess))) + || !TEST_true(EVP_DigestFinal_ex(mdctx, md_value, &md_len)) + || !TEST_int_eq(custom_md_init_called, 1) + || !TEST_int_eq(custom_md_cleanup_called, 1)) + goto err; + + if (!TEST_int_eq(OBJ_create("1.3.6.1.4.1.16604.998866.1", + "custom-md", "custom-md"), + NID_undef) + || !TEST_int_eq(ERR_GET_LIB(ERR_peek_error()), ERR_LIB_OBJ) + || !TEST_int_eq(ERR_GET_REASON(ERR_get_error()), OBJ_R_OID_EXISTS)) + goto err; + + o = ASN1_OBJECT_create(nid, (unsigned char *)"\53\6\1\4\1\201\201\134\274\373\122\1", 12, + "custom-md", "custom-md"); + if (!TEST_int_eq(OBJ_add_object(o), nid)) + goto err; + + testresult = 1; +err: + ASN1_OBJECT_free(o); + EVP_MD_CTX_free(mdctx); + EVP_MD_meth_free(tmp); + return testresult; +} + +typedef struct { + int data; +} custom_ciph_ctx; + +static int custom_ciph_init_called = 0; +static int custom_ciph_cleanup_called = 0; + +static int custom_ciph_init(EVP_CIPHER_CTX *ctx, const unsigned char *key, + const unsigned char *iv, int enc) +{ + custom_ciph_ctx *p = EVP_CIPHER_CTX_get_cipher_data(ctx); + + if (p == NULL) + return 0; + + custom_ciph_init_called++; + return 1; +} + +static int custom_ciph_cleanup(EVP_CIPHER_CTX *ctx) +{ + custom_ciph_ctx *p = EVP_CIPHER_CTX_get_cipher_data(ctx); + + if (p == NULL) + /* Nothing to do */ + return 1; + + custom_ciph_cleanup_called++; + return 1; +} + +static int test_custom_ciph_meth(void) +{ + EVP_CIPHER_CTX *ciphctx = NULL; + EVP_CIPHER *tmp = NULL; + int testresult = 0; + int nid; + + /* + * We are testing deprecated functions. We don't support a non-default + * library context in this test. + */ + if (testctx != NULL) + return TEST_skip("Non-default libctx"); + + custom_ciph_init_called = custom_ciph_cleanup_called = 0; + + nid = OBJ_create("1.3.6.1.4.1.16604.998866.2", "custom-ciph", "custom-ciph"); + if (!TEST_int_ne(nid, NID_undef)) + goto err; + if (!TEST_int_eq(OBJ_txt2nid("1.3.6.1.4.1.16604.998866.2"), nid)) + goto err; + tmp = EVP_CIPHER_meth_new(nid, 16, 16); + if (!TEST_ptr(tmp)) + goto err; + + if (!TEST_true(EVP_CIPHER_meth_set_init(tmp, custom_ciph_init)) + || !TEST_true(EVP_CIPHER_meth_set_flags(tmp, EVP_CIPH_ALWAYS_CALL_INIT)) + || !TEST_true(EVP_CIPHER_meth_set_cleanup(tmp, custom_ciph_cleanup)) + || !TEST_true(EVP_CIPHER_meth_set_impl_ctx_size(tmp, + sizeof(custom_ciph_ctx)))) + goto err; + + ciphctx = EVP_CIPHER_CTX_new(); + if (!TEST_ptr(ciphctx) + /* + * Initing our custom cipher and then initing another cipher + * should result in the init and cleanup functions of the custom + * cipher being called. + */ + || !TEST_true(EVP_CipherInit_ex(ciphctx, tmp, NULL, NULL, NULL, 1)) + || !TEST_true(EVP_CipherInit_ex(ciphctx, EVP_aes_128_cbc(), NULL, + NULL, NULL, 1)) + || !TEST_int_eq(custom_ciph_init_called, 1) + || !TEST_int_eq(custom_ciph_cleanup_called, 1)) + goto err; + + testresult = 1; +err: + EVP_CIPHER_CTX_free(ciphctx); + EVP_CIPHER_meth_free(tmp); + return testresult; +} + +#endif /* OPENSSL_NO_DEPRECATED_3_0 */ + #ifndef OPENSSL_NO_ECX static int ecxnids[] = { NID_X25519, @@ -7640,52 +6368,6 @@ end: return testresult; } -#ifndef OPENSSL_NO_EC -/* - * Test that EVP_PKEY_sign_init_ex2() with a mismatched key/signature algorithm - * (e.g. RSA key with ECDSA signature) correctly fails. - */ -static int test_EVP_PKEY_sign_init_mismatched_key_alg(void) -{ - EVP_PKEY *rsa_key = NULL; - EVP_PKEY_CTX *ctx = NULL; - EVP_PKEY_CTX *pkey_ctx = NULL; - EVP_SIGNATURE *ecdsa_sig = NULL; - int testresult = 0; - - /* Generate an RSA key */ - if (!TEST_ptr(pkey_ctx = EVP_PKEY_CTX_new_from_name(testctx, "RSA", NULL)) - || !TEST_int_gt(EVP_PKEY_keygen_init(pkey_ctx), 0) - || !TEST_int_gt(EVP_PKEY_CTX_set_rsa_keygen_bits(pkey_ctx, 2048), 0) - || !TEST_int_gt(EVP_PKEY_keygen(pkey_ctx, &rsa_key), 0)) - goto end; - - EVP_PKEY_CTX_free(pkey_ctx); - pkey_ctx = NULL; - - /* Fetch ECDSA signature algorithm - incompatible with RSA key */ - if (!TEST_ptr(ecdsa_sig = EVP_SIGNATURE_fetch(testctx, "ECDSA", NULL))) - goto end; - - /* Try to init sign with mismatched key/algorithm - this should fail */ - if (!TEST_ptr(ctx = EVP_PKEY_CTX_new_from_pkey(testctx, rsa_key, NULL))) - goto end; - - /* This should fail with -2 (operation not supported for key type) */ - if (!TEST_int_eq(EVP_PKEY_sign_init_ex2(ctx, ecdsa_sig, NULL), -2)) - goto end; - - testresult = 1; - -end: - EVP_PKEY_CTX_free(ctx); - EVP_PKEY_CTX_free(pkey_ctx); - EVP_SIGNATURE_free(ecdsa_sig); - EVP_PKEY_free(rsa_key); - return testresult; -} -#endif - static int aes_gcm_encrypt(const unsigned char *gcm_key, size_t gcm_key_s, const unsigned char *gcm_iv, size_t gcm_ivlen, const unsigned char *gcm_pt, size_t gcm_pt_s, @@ -7943,142 +6625,6 @@ static int test_aes_rc4_keylen_change_cve_2023_5363(void) } #endif -static int test_aes_gcm_siv_empty_data(void) -{ - unsigned char key[16] = { 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, - 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10 }; - unsigned char nonce[12] = { 0xaa, 0xbb, 0xcc, 0xdd, 0xee, 0xff, 0x00, 0x11, - 0x22, 0x33, 0x44, 0x55 }; - unsigned char aad[33] = "this AAD was never authenticated"; - unsigned char zero_tag[16] = { 0 }; - unsigned char real_tag[16]; - unsigned char out[16]; - int outl, ret = 0; - EVP_CIPHER_CTX *ctx = NULL; - EVP_CIPHER *c = EVP_CIPHER_fetch(NULL, "AES-128-GCM-SIV", NULL); - - if (c == NULL) { - return TEST_skip("AES-128-GCM-SIV cipher is not available"); - } - - /* Compute the CORRECT tag for (key,nonce,aad,pt="") via encrypt */ - ctx = EVP_CIPHER_CTX_new(); - if (!TEST_ptr(ctx) - || !TEST_true(EVP_EncryptInit_ex2(ctx, c, key, nonce, NULL)) - || !TEST_true(EVP_EncryptUpdate(ctx, NULL, &outl, aad, sizeof(aad))) /* AAD */ - || !TEST_true(EVP_EncryptUpdate(ctx, out, &outl, aad, 0)) /* empty PT, out!=NULL */ - || !TEST_true(EVP_EncryptFinal_ex(ctx, out, &outl)) - || !TEST_true(EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_GET_TAG, 16, real_tag))) - goto err; - EVP_CIPHER_CTX_free(ctx); - - /* SANITY: decrypt with CORRECT tag and an explicit empty-PT Update */ - ctx = EVP_CIPHER_CTX_new(); - if (!TEST_ptr(ctx) - || !TEST_true(EVP_DecryptInit_ex2(ctx, c, key, nonce, NULL)) - || !TEST_true(EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, 16, real_tag)) - || !TEST_true(EVP_DecryptUpdate(ctx, NULL, &outl, aad, sizeof(aad))) - || !TEST_true(EVP_DecryptUpdate(ctx, out, &outl, aad, 0)) /* force aes_gcm_siv_decrypt(len=0) */ - || !TEST_true(EVP_DecryptFinal_ex(ctx, out, &outl))) - goto err; - EVP_CIPHER_CTX_free(ctx); - - /* FORGERY A: AAD only, NO ciphertext Update, ALL-ZERO tag */ - ctx = EVP_CIPHER_CTX_new(); - if (!TEST_ptr(ctx) - || !TEST_true(EVP_DecryptInit_ex2(ctx, c, key, nonce, NULL)) - || !TEST_true(EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, 16, zero_tag)) - || !TEST_true(EVP_DecryptUpdate(ctx, NULL, &outl, aad, sizeof(aad))) /* AAD only, out==NULL */ - || !TEST_false(EVP_DecryptFinal_ex(ctx, out, &outl))) - goto err; - EVP_CIPHER_CTX_free(ctx); - - /* FORGERY B: no AAD, no Update at all, ALL-ZERO tag */ - ctx = EVP_CIPHER_CTX_new(); - if (!TEST_ptr(ctx) - || !TEST_true(EVP_DecryptInit_ex2(ctx, c, key, nonce, NULL)) - || !TEST_true(EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, 16, zero_tag)) - || !TEST_false(EVP_DecryptFinal_ex(ctx, out, &outl))) - goto err; - EVP_CIPHER_CTX_free(ctx); - - /* CONTROL: AAD only, NO ciphertext Update, CORRECT tag */ - ctx = EVP_CIPHER_CTX_new(); - if (!TEST_ptr(ctx) - || !TEST_true(EVP_DecryptInit_ex2(ctx, c, key, nonce, NULL)) - || !TEST_true(EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, 16, real_tag)) - || !TEST_true(EVP_DecryptUpdate(ctx, NULL, &outl, aad, sizeof(aad))) - || !TEST_true(EVP_DecryptFinal_ex(ctx, out, &outl))) - goto err; - EVP_CIPHER_CTX_free(ctx); - ctx = NULL; - - ret = 1; -err: - EVP_CIPHER_CTX_free(ctx); - - EVP_CIPHER_free(c); - return ret; -} - -/* - * AES-SIV reuse-without-rekey: - * msg1: legit non-empty CT, tag verifies, final_ret=0 - * msg2: no reinit (or reinit with key=NULL), set forged tag, - * AAD only, DecryptFinal -> does stale final_ret leak through? - */ -static int test_aes_siv_ctx_reuse(void) -{ - unsigned char key[32] = { 7 }; /* AES-128-SIV => 2*16 */ - unsigned char pt[9] = "payload!"; - unsigned char ct[9], tagbuf[16], out[16], zero16[16] = { 0 }; - unsigned char aad[14] = "forged header"; - int outl, ret = 0; - EVP_CIPHER_CTX *e = NULL, *d = NULL; - EVP_CIPHER *c = EVP_CIPHER_fetch(NULL, "AES-128-SIV", NULL); - - if (c == NULL) { - return TEST_skip("AES-128-SIV cipher is not available"); - } - - /* produce a valid (ct,tag) for msg1 */ - e = EVP_CIPHER_CTX_new(); - if (!TEST_ptr(e) - || !TEST_true(EVP_EncryptInit_ex2(e, c, key, NULL, NULL)) - || !TEST_true(EVP_EncryptUpdate(e, NULL, &outl, (unsigned char *)"hdr1", 4)) - || !TEST_true(EVP_EncryptUpdate(e, ct, &outl, pt, sizeof(pt))) - || !TEST_true(EVP_EncryptFinal_ex(e, out, &outl)) - || !TEST_true(EVP_CIPHER_CTX_ctrl(e, EVP_CTRL_AEAD_GET_TAG, 16, tagbuf))) { - EVP_CIPHER_CTX_free(e); - goto err; - } - EVP_CIPHER_CTX_free(e); - - /* msg1 decrypt */ - d = EVP_CIPHER_CTX_new(); - if (!TEST_ptr(d) - || !TEST_true(EVP_DecryptInit_ex2(d, c, key, NULL, NULL)) - || !TEST_true(EVP_CIPHER_CTX_ctrl(d, EVP_CTRL_AEAD_SET_TAG, 16, tagbuf)) - || !TEST_true(EVP_DecryptUpdate(d, NULL, &outl, (unsigned char *)"hdr1", 4)) - || !TEST_true(EVP_DecryptUpdate(d, out, &outl, ct, sizeof(ct))) - || !TEST_true(EVP_DecryptFinal_ex(d, out, &outl))) - goto err; - - /* msg2 on SAME ctx, reinit with key=NULL => initkey skipped, final_ret should be reset */ - if (!TEST_true(EVP_DecryptInit_ex2(d, NULL, NULL, NULL, NULL)) - || !TEST_true(EVP_CIPHER_CTX_ctrl(d, EVP_CTRL_AEAD_SET_TAG, 16, zero16)) - || !TEST_true(EVP_DecryptUpdate(d, NULL, &outl, aad, sizeof(aad))) /* forged AAD */ - || !TEST_false(EVP_DecryptFinal_ex(d, out, &outl))) - goto err; - - ret = 1; - -err: - EVP_CIPHER_CTX_free(d); - EVP_CIPHER_free(c); - return ret; -} - static int test_invalid_ctx_for_digest(void) { int ret; @@ -8098,436 +6644,6 @@ static int test_invalid_ctx_for_digest(void) return ret; } -static int test_evp_cipher_negative_length(void) -{ - EVP_CIPHER_CTX *ctx = NULL; - EVP_CIPHER *cipher = NULL; - unsigned char key[16] = { 0 }; - unsigned char iv[16] = { 0 }; - unsigned char buffer[32] = { 0 }; - int outl = 0; - int ret = 0; - - if (!TEST_ptr(ctx = EVP_CIPHER_CTX_new())) - goto end; - - if (!TEST_ptr(cipher = EVP_CIPHER_fetch(testctx, "AES-128-CBC", testpropq))) - goto end; - - /* Initialize encryption context */ - if (!TEST_int_eq(EVP_EncryptInit_ex2(ctx, cipher, key, iv, NULL), 1)) - goto end; - - /* Test EVP_EncryptUpdate with negative length - should fail */ - if (!TEST_int_eq(EVP_EncryptUpdate(ctx, buffer, &outl, (unsigned char *)"test", -1), 0)) - goto end; - - /* Reinitialize for decryption */ - if (!TEST_int_eq(EVP_DecryptInit_ex2(ctx, cipher, key, iv, NULL), 1)) - goto end; - - /* Test EVP_DecryptUpdate with negative length - should fail */ - if (!TEST_int_eq(EVP_DecryptUpdate(ctx, buffer, &outl, (unsigned char *)"test", -1), 0)) - goto end; - - ret = 1; -end: - EVP_CIPHER_free(cipher); - EVP_CIPHER_CTX_free(ctx); - return ret; -} - -static int test_aes_xts_rejects_missing_iv(void) -{ - static const unsigned char key[32] = { - 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, - 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, - 0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17, - 0x18, 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f - }; - static const unsigned char in[32] = { - 0x00, 0x11, 0x22, 0x33, 0x44, 0x55, 0x66, 0x77, - 0x88, 0x99, 0xaa, 0xbb, 0xcc, 0xdd, 0xee, 0xff, - 0xff, 0xee, 0xdd, 0xcc, 0xbb, 0xaa, 0x99, 0x88, - 0x77, 0x66, 0x55, 0x44, 0x33, 0x22, 0x11, 0x00 - }; - static const unsigned char iv[16] = { - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x02 - }; - EVP_CIPHER_CTX *ctx = NULL; - EVP_CIPHER *cipher = NULL; - unsigned char out[sizeof(in)]; - int outl = 0; - int ret = 0; - - if ((cipher = EVP_CIPHER_fetch(testctx, "AES-128-XTS", testpropq)) == NULL) - return TEST_skip("AES-128-XTS cipher is not available"); - - /* Initialize with a valid IV as a positive control */ - if (!TEST_ptr(ctx = EVP_CIPHER_CTX_new()) - || !TEST_true(EVP_EncryptInit_ex2(ctx, cipher, key, iv, NULL)) - || !TEST_true(EVP_EncryptUpdate(ctx, out, &outl, in, sizeof(in))) - || !TEST_int_eq(outl, (int)sizeof(in))) - goto err; - - EVP_CIPHER_CTX_free(ctx); - ctx = NULL; - outl = 0; - - if (!TEST_ptr(ctx = EVP_CIPHER_CTX_new())) - goto err; - - /* Initialize with a NULL IV, which may fail immediately */ - ERR_set_mark(); - if (!EVP_EncryptInit_ex2(ctx, cipher, key, NULL, NULL)) { - ERR_pop_to_mark(); - ret = 1; - goto err; - } - - /* Test EVP_EncryptUpdate after NULL IV initialization, which should fail */ - if (!TEST_false(EVP_EncryptUpdate(ctx, out, &outl, in, sizeof(in)))) { - ERR_clear_last_mark(); - goto err; - } - ERR_pop_to_mark(); - - ret = 1; - -err: - EVP_CIPHER_free(cipher); - EVP_CIPHER_CTX_free(ctx); - return ret; -} - -/* - * Cross-driver round-trip test for AEAD one-shot vs streaming paths. - * - * The streaming path (EVP_CipherUpdate/Final, dispatched to - * OSSL_FUNC_CIPHER_UPDATE/_FINAL) is treated as the oracle. For each - * AEAD configuration we encrypt and decrypt the same (key, iv, aad, pt), - * driving the body in two combinations: - * - * 1. body encrypt via EVP_Cipher() (one-shot, OSSL_FUNC_CIPHER_CIPHER), - * body decrypt via EVP_CipherUpdate (streaming). - * 2. body encrypt via EVP_CipherUpdate, body decrypt via EVP_Cipher(). - * - * Both combinations must recover the plaintext and verify the tag. AAD - * is always fed via EVP_CipherUpdate(NULL, ...): OCB's one-shot is body - * only and the asymmetric "AAD streaming, body one-shot" call shape is - * the natural pattern a caller reaching for EVP_Cipher() for throughput - * would write anyway. - * - * CVE-2026-45445 (AES-OCB EVP_Cipher() ignored IV) was a silent failure - * in this matrix: the one-shot encrypt path produced ciphertext under - * Offset_0 = 0 regardless of IV, which the streaming decrypt path then - * could not verify. Adding this cross-check catches the same class of - * bug for any future AEAD whose one-shot dispatch diverges from its - * streaming dispatch. - */ -typedef struct { - const char *name; /* EVP_CIPHER fetch name */ - size_t keylen; - size_t ivlen; - size_t taglen; - int is_ccm; /* needs length-up-front + tag-before-body dance */ -} AEAD_ONESHOT_CFG; - -static const AEAD_ONESHOT_CFG aead_oneshot_cfgs[] = { - { "AES-128-GCM", 16, 12, 16, 0 }, - { "AES-256-GCM", 32, 12, 16, 0 }, - { "AES-128-CCM", 16, 12, 16, 1 }, - { "AES-256-CCM", 32, 12, 16, 1 }, - { "AES-128-OCB", 16, 12, 16, 0 }, - { "AES-256-OCB", 32, 12, 16, 0 }, - { "ChaCha20-Poly1305", 32, 12, 16, 0 } -}; - -/* - * Drive an encrypt or decrypt operation. AAD always via EVP_CipherUpdate. - * Body via EVP_Cipher() when oneshot_body is non-zero, EVP_CipherUpdate - * otherwise. On encrypt, fills *out and the caller-provided tag buffer. - * On decrypt, reads from in and verifies tag; returns 0 if verification - * fails (the test asserts the expected outcome). - */ -static int aead_oneshot_op(const AEAD_ONESHOT_CFG *cfg, int enc, - int oneshot_body, const unsigned char *key, - const unsigned char *iv, const unsigned char *aad, - size_t aad_len, const unsigned char *in, size_t in_len, - unsigned char *out, unsigned char *tag, const char **why) -{ - EVP_CIPHER_CTX *ctx = NULL; - EVP_CIPHER *cipher = NULL; - int outl = 0, tmpl = 0; - int ok = 0; - int body_rv; - - *why = NULL; - - if (!TEST_ptr(cipher = EVP_CIPHER_fetch(testctx, cfg->name, testpropq))) { - *why = "CIPHER_FETCH"; - goto end; - } - if (!TEST_ptr(ctx = EVP_CIPHER_CTX_new())) { - *why = "CTX_NEW"; - goto end; - } - if (!TEST_true(EVP_CipherInit_ex(ctx, cipher, NULL, NULL, NULL, enc))) { - *why = "INIT_CIPHER"; - goto end; - } - if (!TEST_int_gt(EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_IVLEN, - (int)cfg->ivlen, NULL), - 0)) { - *why = "SET_IVLEN"; - goto end; - } - if (cfg->is_ccm) { - /* Placeholder taglen on encrypt, real tag on decrypt; both before key+iv. */ - if (!TEST_int_gt(EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, - (int)cfg->taglen, enc ? NULL : tag), - 0)) { - *why = "CCM_SET_TAG"; - goto end; - } - } - if (!TEST_true(EVP_CipherInit_ex(ctx, NULL, NULL, key, iv, enc))) { - *why = "INIT_KEY_IV"; - goto end; - } - if (cfg->is_ccm) { - if (!TEST_true(EVP_CipherUpdate(ctx, NULL, &outl, NULL, (int)in_len))) { - *why = "CCM_LEN_DECL"; - goto end; - } - } - if (aad_len > 0 - && !TEST_true(EVP_CipherUpdate(ctx, NULL, &outl, aad, (int)aad_len))) { - *why = "AAD"; - goto end; - } - if (!enc && !cfg->is_ccm - && !TEST_int_gt(EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, - (int)cfg->taglen, tag), - 0)) { - *why = "SET_TAG"; - goto end; - } - - if (oneshot_body) { - body_rv = EVP_Cipher(ctx, out, in, (unsigned int)in_len); - if (cfg->is_ccm && !enc) { - /* CCM decrypt: 0 means tag verify failed, < 0 means error. */ - if (!TEST_int_gt(body_rv, 0)) { - *why = "ONESHOT_DECRYPT"; - goto end; - } - } else { - if (!TEST_int_ge(body_rv, 0)) { - *why = "ONESHOT_BODY"; - goto end; - } - } - outl = (int)in_len; - } else { - if (!TEST_true(EVP_CipherUpdate(ctx, out, &outl, in, (int)in_len))) { - *why = enc ? "STREAM_BODY_ENC" : "STREAM_BODY_DEC"; - goto end; - } - } - - if (!cfg->is_ccm) { - if (!TEST_true(EVP_CipherFinal_ex(ctx, out + outl, &tmpl))) { - *why = enc ? "FINAL_ENC" : "FINAL_DEC"; - goto end; - } - } - - if (enc) { - if (!TEST_int_gt(EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_GET_TAG, - (int)cfg->taglen, tag), - 0)) { - *why = "GET_TAG"; - goto end; - } - } - ok = 1; -end: - EVP_CIPHER_CTX_free(ctx); - EVP_CIPHER_free(cipher); - return ok; -} - -/* - * For each AEAD row we run two AAD modes, and within each AAD mode two - * cross-driver round trips: - * - * aad_mode 0: no AAD. Critical for catching the OCB-style bug: any - * EVP_CipherUpdate(NULL, aad, ...) call before the body - * would itself pass through the (correct) streaming - * handler and apply the buffered IV, masking the one-shot - * handler's failure to do so. With aad_len == 0 we make - * EVP_Cipher() the very first cipher operation on the - * context, which is the shape the bug requires. - * - * aad_mode 1: with AAD via streaming. Catches divergence between the - * drivers when AAD is in play. - * - * leg 0: encrypt-oneshot + decrypt-streaming - * leg 1: encrypt-streaming + decrypt-oneshot - * - * The test index encodes (cipher, aad_mode) so a failure points at both. - */ -static int test_aead_oneshot_roundtrip(int idx) -{ - static const unsigned char fixed_key[32] = { - 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, - 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, - 0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17, - 0x18, 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f - }; - static const unsigned char fixed_iv[12] = { - 0xa0, 0xa1, 0xa2, 0xa3, 0xa4, 0xa5, 0xa6, 0xa7, 0xa8, 0xa9, 0xaa, 0xab - }; - static const unsigned char fixed_aad[] = "extra:context"; - static const unsigned char fixed_pt[] = "THE QUICK BROWN FOX JUMPS OVER LAZY!!"; - const AEAD_ONESHOT_CFG *cfg = &aead_oneshot_cfgs[idx / 2]; - int with_aad = idx % 2; - size_t aad_len = with_aad ? sizeof(fixed_aad) - 1 : 0; - size_t pt_len = sizeof(fixed_pt) - 1; - EVP_CIPHER *probe = NULL; - unsigned char ct[64], pt[64]; - unsigned char tag_oneshot[16], tag_stream[16]; - const char *why = NULL; - int leg, ok = 0; - - /* - * Probe for the cipher: a build with no-ocb / no-chacha / etc. will - * not have it, and we treat that as a pass (nothing to test here). - */ - ERR_set_mark(); - probe = EVP_CIPHER_fetch(testctx, cfg->name, testpropq); - ERR_pop_to_mark(); - if (probe == NULL) { - TEST_info("skipping, '%s' is not available", cfg->name); - return 1; - } - EVP_CIPHER_free(probe); - - for (leg = 0; leg <= 1; leg++) { - int enc_oneshot = (leg == 0); - unsigned char *tag = enc_oneshot ? tag_oneshot : tag_stream; - - memset(ct, 0, sizeof(ct)); - memset(pt, 0, sizeof(pt)); - memset(tag, 0, cfg->taglen); - - if (!aead_oneshot_op(cfg, /*enc=*/1, /*oneshot_body=*/enc_oneshot, - fixed_key, fixed_iv, fixed_aad, aad_len, - fixed_pt, pt_len, ct, tag, &why)) { - TEST_error("%s (%s): encrypt leg %d (%s body) failed at %s", - cfg->name, with_aad ? "with AAD" : "no AAD", - leg, enc_oneshot ? "oneshot" : "stream", - why ? why : "?"); - goto end; - } - if (!aead_oneshot_op(cfg, /*enc=*/0, /*oneshot_body=*/!enc_oneshot, - fixed_key, fixed_iv, fixed_aad, aad_len, - ct, pt_len, pt, tag, &why)) { - TEST_error("%s (%s): decrypt leg %d (%s body) failed at %s", - cfg->name, with_aad ? "with AAD" : "no AAD", - leg, enc_oneshot ? "stream" : "oneshot", - why ? why : "?"); - goto end; - } - if (!TEST_mem_eq(pt, pt_len, fixed_pt, pt_len)) { - TEST_error("%s (%s): leg %d: recovered plaintext differs", - cfg->name, with_aad ? "with AAD" : "no AAD", leg); - goto end; - } - } - - /* - * Both legs share the same (key, iv, aad, pt) and must therefore - * agree on the tag bit-for-bit, regardless of which driver computed - * it. This catches the OCB-style failure where the one-shot path - * silently emits a different ciphertext/tag from the streaming path. - */ - if (!TEST_mem_eq(tag_oneshot, cfg->taglen, tag_stream, cfg->taglen)) { - TEST_error("%s (%s): oneshot-encrypt tag != streaming-encrypt tag", - cfg->name, with_aad ? "with AAD" : "no AAD"); - goto end; - } - ok = 1; -end: - return ok; -} - -#ifndef OPENSSL_NO_DES -static int test_EVP_CIPHER_get_type_des_ede3(void) -{ - const EVP_CIPHER *cipher = NULL; - int base_type, variant_type, nid; - int ret = 0; - - /* Get the base type from CFB64 (should be NID_des_ede3_cfb64) */ - cipher = EVP_des_ede3_cfb64(); - base_type = EVP_CIPHER_get_type(cipher); - - /* Test CFB64 - should map to the same base_type */ - variant_type = EVP_CIPHER_get_type(cipher); - nid = EVP_CIPHER_get_nid(cipher); - - /* Verify the returned type */ - if (!TEST_int_eq(variant_type, base_type)) - goto end; - - /* Verify that variant_type and nid are same for 64-bit variants */ - if (!TEST_int_eq(variant_type, nid)) - goto end; - - if (!TEST_int_eq(NID_des_ede3_cfb64, variant_type)) - goto end; - - /* Test CFB8 - should map to the same base_type */ - cipher = EVP_des_ede3_cfb8(); - variant_type = EVP_CIPHER_get_type(cipher); - nid = EVP_CIPHER_get_nid(cipher); - - /* Verify the returned type */ - if (!TEST_int_eq(variant_type, base_type)) - goto end; - - /* Verify that variant_type and nid are different for variants */ - if (!TEST_int_ne(variant_type, nid)) - goto end; - - if (!TEST_int_eq(NID_des_ede3_cfb64, variant_type)) - goto end; - - /* Test CFB1 - should map to the same base_type */ - cipher = EVP_des_ede3_cfb1(); - variant_type = EVP_CIPHER_get_type(cipher); - nid = EVP_CIPHER_get_nid(cipher); - - /* Verify the returned type */ - if (!TEST_int_eq(variant_type, base_type)) - goto end; - - /* Verify that variant_type and nid are different for variants */ - if (!TEST_int_ne(variant_type, nid)) - goto end; - - if (!TEST_int_eq(NID_des_ede3_cfb64, variant_type)) - goto end; - - ret = 1; -end: - return ret; -} -#endif /*OPENSSL_NO_DES */ - static int test_evp_cipher_pipeline(void) { OSSL_PROVIDER *fake_pipeline = NULL; @@ -8740,470 +6856,6 @@ end: return testresult; } -#ifndef OPENSSL_NO_DEPRECATED_3_0 - -static int sign_hits = 0; -static int encap_hits = 0; -static int flen_ne_ret_hits = 0; - -static int do_sign_with_method(EVP_PKEY *pkey) -{ - const unsigned char msg[] = "Hello, World!"; - unsigned char sig[128]; - unsigned int siglen; - EVP_MD_CTX *ctx = NULL; - int ret = 0; - - sign_hits = 0; - ctx = EVP_MD_CTX_new(); - if (!TEST_ptr(ctx)) - return 0; - if (!TEST_true(EVP_SignInit(ctx, EVP_sha256()))) - goto err; - if (!TEST_true(EVP_SignUpdate(ctx, msg, sizeof(msg) - 1))) - goto err; - if (!TEST_true(EVP_SignFinal(ctx, sig, &siglen, pkey))) - goto err; - /* We expect to see our custom sign function called once */ - if (!TEST_int_eq(sign_hits, 1)) - goto err; - - ret = 1; -err: - EVP_MD_CTX_free(ctx); - return ret; -} - -static int rsa_ex_idx = -1; - -static int (*orig_rsa_priv_enc)(int, const unsigned char *, unsigned char *, RSA *, int); - -static int tst_rsa_priv_enc(int flen, const unsigned char *from, unsigned char *to, - RSA *rsa, int padding) -{ - if (strcmp(RSA_get_ex_data(rsa, rsa_ex_idx), "test") != 0) - return 0; - sign_hits++; - return orig_rsa_priv_enc(flen, from, to, rsa, padding); -} - -static int tst_rsa_pub_enc(int flen, const unsigned char *from, unsigned char *to, - RSA *rsa, int padding) -{ - const char *marker = RSA_get_ex_data(rsa, rsa_ex_idx); - - if (marker == NULL || strcmp(marker, "kem-test") != 0) - return 0; - encap_hits++; - return -1; -} - -static int tst_rsa_pub_enc_flen_ne_ret(int flen, const unsigned char *from, unsigned char *to, - RSA *rsa, int padding) -{ - const char *marker = RSA_get_ex_data(rsa, rsa_ex_idx); - - if (marker == NULL || strcmp(marker, "kem-test-flen-ne-ret") != 0) - return 0; - flen_ne_ret_hits++; - return flen - 1; -} - -/* Test that a low level RSA method still gets used even with a provider */ -static int test_low_level_rsa_method(void) -{ - BIGNUM *e = BN_new(); - RSA *rsa = NULL; - const RSA_METHOD *def = RSA_get_default_method(); - RSA_METHOD *method = RSA_meth_dup(def); - EVP_PKEY *pkey = NULL; - int testresult = 0; - - if (nullprov != NULL) { - testresult = TEST_skip("Test does not support a non-default library context"); - goto err; - } - - if (!TEST_ptr(e) || !TEST_ptr(method)) - goto err; - - rsa_ex_idx = RSA_get_ex_new_index(0, NULL, NULL, NULL, NULL); - - if (!TEST_true(BN_set_word(e, RSA_F4))) - goto err; - - rsa = RSA_new(); - if (!TEST_ptr(rsa)) - goto err; - if (!TEST_true(RSA_set_ex_data(rsa, rsa_ex_idx, (void *)"test"))) - goto err; - if (!TEST_true(RSA_generate_key_ex(rsa, 1024, e, NULL))) - goto err; - - orig_rsa_priv_enc = RSA_meth_get_priv_enc(def); - if (!TEST_true(RSA_meth_set_priv_enc(method, tst_rsa_priv_enc))) - goto err; - if (!TEST_true(RSA_set_method(rsa, method))) - goto err; - - pkey = EVP_PKEY_new(); - if (!TEST_ptr(pkey)) - goto err; - if (!TEST_int_gt(EVP_PKEY_assign_RSA(pkey, rsa), 0)) - goto err; - rsa = NULL; - - if (!do_sign_with_method(pkey)) - goto err; - - testresult = 1; -err: - BN_free(e); - RSA_free(rsa); - EVP_PKEY_free(pkey); - RSA_meth_free(method); - return testresult; -} - -static int test_low_level_rsa_kem_public_encrypt_failure(int idx) -{ - RSA *rsa = NULL; - const RSA_METHOD *def = RSA_get_default_method(); - RSA_METHOD *method = RSA_meth_dup(def); - EVP_PKEY *pkey = NULL; - EVP_PKEY_CTX *ctx = NULL; - unsigned char *ct = NULL; - unsigned char *secret = NULL; - size_t ctlen = 0, secretlen = 0; - int testresult = 0; - - if (nullprov != NULL) { - testresult = TEST_skip("Test does not support a non-default library context"); - goto err; - } - - if (!TEST_ptr(method) - || !TEST_ptr(pkey = load_example_rsa_key())) - goto err; - - rsa_ex_idx = RSA_get_ex_new_index(0, NULL, NULL, NULL, NULL); - if (!TEST_int_ne(rsa_ex_idx, -1) || !TEST_ptr(rsa = EVP_PKEY_get1_RSA(pkey))) - goto err; - - switch (idx) { - case 0: - if (!TEST_true(RSA_set_ex_data(rsa, rsa_ex_idx, (void *)"kem-test")) - || !TEST_true(RSA_meth_set_pub_enc(method, tst_rsa_pub_enc))) - goto err; - break; - case 1: - if (!TEST_true(RSA_set_ex_data(rsa, rsa_ex_idx, (void *)"kem-test-flen-ne-ret")) - || !TEST_true(RSA_meth_set_pub_enc(method, tst_rsa_pub_enc_flen_ne_ret))) - goto err; - break; - default: - goto err; - }; - if (!TEST_true(RSA_set_method(rsa, method)) - || !TEST_int_gt(EVP_PKEY_assign_RSA(pkey, rsa), 0)) - goto err; - rsa = NULL; - - if (!TEST_ptr(ctx = EVP_PKEY_CTX_new_from_pkey(testctx, pkey, NULL)) - || !TEST_int_eq(EVP_PKEY_encapsulate_init(ctx, NULL), 1) - || !TEST_int_eq(EVP_PKEY_CTX_set_kem_op(ctx, "RSASVE"), 1) - || !TEST_int_eq(EVP_PKEY_encapsulate(ctx, NULL, &ctlen, NULL, &secretlen), 1) - || !TEST_ptr(ct = OPENSSL_malloc(ctlen)) - || !TEST_ptr(secret = OPENSSL_malloc(secretlen))) - goto err; - - encap_hits = flen_ne_ret_hits = 0; - if (!TEST_int_eq(EVP_PKEY_encapsulate(ctx, ct, &ctlen, secret, &secretlen), 0)) - goto err; - - switch (idx) { - case 0: - if (!TEST_int_eq(encap_hits, 1)) - goto err; - break; - case 1: - if (!TEST_int_eq(flen_ne_ret_hits, 1)) - goto err; - break; - default: - goto err; - } - testresult = 1; - -err: - OPENSSL_free(secret); - OPENSSL_free(ct); - EVP_PKEY_CTX_free(ctx); - RSA_free(rsa); - EVP_PKEY_free(pkey); - RSA_meth_free(method); - return testresult; -} - -#ifndef OPENSSL_NO_DSA -static int dsa_ex_idx = -1; - -static DSA_SIG *(*orig_dsa_sign)(const unsigned char *, int, DSA *); - -static DSA_SIG *tst_dsa_sign(const unsigned char *buf, int len, DSA *dsa) -{ - if (strcmp(DSA_get_ex_data(dsa, dsa_ex_idx), "test") != 0) - return 0; - sign_hits++; - return orig_dsa_sign(buf, len, dsa); -} - -/* Test that a low level DSA method still gets used even with a provider */ -static int test_low_level_dsa_method(void) -{ - DSA *dsa = NULL; - const DSA_METHOD *def = DSA_get_default_method(); - DSA_METHOD *method = DSA_meth_dup(def); - EVP_PKEY *pkey = NULL; - int testresult = 0; - - if (nullprov != NULL) { - testresult = TEST_skip("Test does not support a non-default library context"); - goto err; - } - - if (!TEST_ptr(method)) - goto err; - - dsa_ex_idx = DSA_get_ex_new_index(0, NULL, NULL, NULL, NULL); - - dsa = load_dsa_params(); - if (!TEST_ptr(dsa)) - goto err; - if (!TEST_true(DSA_set_ex_data(dsa, dsa_ex_idx, (void *)"test"))) - goto err; - if (!TEST_true(DSA_generate_key(dsa))) - goto err; - - orig_dsa_sign = DSA_meth_get_sign(def); - if (!TEST_true(DSA_meth_set_sign(method, tst_dsa_sign))) - goto err; - if (!TEST_true(DSA_set_method(dsa, method))) - goto err; - - pkey = EVP_PKEY_new(); - if (!TEST_ptr(pkey)) - goto err; - if (!TEST_int_gt(EVP_PKEY_assign_DSA(pkey, dsa), 0)) - goto err; - dsa = NULL; - - if (!do_sign_with_method(pkey)) - goto err; - - testresult = 1; -err: - DSA_free(dsa); - EVP_PKEY_free(pkey); - DSA_meth_free(method); - return testresult; -} -#endif /* OPENSSL_NO_DSA */ - -#ifndef OPENSSL_NO_EC -static int ec_ex_idx = -1; - -static int (*orig_ec_sign)(int type, const unsigned char *dgst, - int dlen, unsigned char *sig, - unsigned int *siglen, - const BIGNUM *kinv, const BIGNUM *r, - EC_KEY *eckey); -static int (*orig_ec_sign_setup)(EC_KEY *eckey, BN_CTX *ctx_in, - BIGNUM **kinvp, BIGNUM **rp); -static ECDSA_SIG *(*orig_ec_sign_sig)(const unsigned char *dgst, - int dgst_len, const BIGNUM *in_kinv, const BIGNUM *in_r, EC_KEY *eckey); -static int tst_ec_sign(int type, const unsigned char *dgst, - int dlen, unsigned char *sig, - unsigned int *siglen, - const BIGNUM *kinv, const BIGNUM *r, - EC_KEY *eckey) -{ - if (strcmp(EC_KEY_get_ex_data(eckey, ec_ex_idx), "test") != 0) - return 0; - sign_hits++; - return orig_ec_sign(type, dgst, dlen, sig, siglen, kinv, r, eckey); -} - -/* Test that a low level EC_KEY method still gets used even with a provider */ -static int test_low_level_ec_method(void) -{ - EC_KEY *ec = NULL; - const EC_KEY_METHOD *def = EC_KEY_get_default_method(); - EC_KEY_METHOD *method = EC_KEY_METHOD_new(def); - EVP_PKEY *pkey = NULL; - int testresult = 0; - - if (nullprov != NULL) { - testresult = TEST_skip("Test does not support a non-default library context"); - goto err; - } - - if (!TEST_ptr(method)) - goto err; - - ec_ex_idx = EC_KEY_get_ex_new_index(0, NULL, NULL, NULL, NULL); - - if (!TEST_ptr(ec = EC_KEY_new_by_curve_name_ex(NULL, NULL, NID_X9_62_prime256v1))) - goto err; - if (!TEST_true(EC_KEY_set_ex_data(ec, ec_ex_idx, (void *)"test"))) - goto err; - if (!TEST_true(EC_KEY_generate_key(ec))) - goto err; - - EC_KEY_METHOD_get_sign(def, &orig_ec_sign, &orig_ec_sign_setup, &orig_ec_sign_sig); - EC_KEY_METHOD_set_sign(method, tst_ec_sign, orig_ec_sign_setup, orig_ec_sign_sig); - if (!TEST_true(EC_KEY_set_method(ec, method))) - goto err; - - pkey = EVP_PKEY_new(); - if (!TEST_ptr(pkey)) - goto err; - if (!TEST_int_gt(EVP_PKEY_assign_EC_KEY(pkey, ec), 0)) - goto err; - ec = NULL; - - if (!do_sign_with_method(pkey)) - goto err; - - testresult = 1; -err: - EC_KEY_free(ec); - EVP_PKEY_free(pkey); - EC_KEY_METHOD_free(method); - return testresult; -} -#endif /* OPENSSL_NO_EC */ - -#ifndef OPENSSL_NO_DH -static int dh_ex_idx = -1; - -static int compute_key_hits = 0; - -static int (*orig_dh_compute_key)(unsigned char *key, const BIGNUM *pub_key, - DH *dh); -static int tst_dh_compute_key(unsigned char *key, const BIGNUM *pub_key, - DH *dh) -{ - if (strcmp(DH_get_ex_data(dh, dh_ex_idx), "test") != 0) - return 0; - compute_key_hits++; - return orig_dh_compute_key(key, pub_key, dh); -} - -/* Test that a low level DH method still gets used even with a provider */ -static int test_low_level_dh_method(void) -{ - DH *dh = NULL; - const DH *cdh = NULL; - const DH_METHOD *def = DH_get_default_method(); - DH_METHOD *method = DH_meth_dup(def); - EVP_PKEY *pkey = NULL, *pkeyb = NULL; - int testresult = 0; - EVP_PKEY_CTX *ctx = NULL; - BIGNUM *p = NULL, *g = NULL; - unsigned char *buf = NULL; - size_t len; - - if (nullprov != NULL) { - testresult = TEST_skip("Test does not support a non-default library context"); - goto err; - } - - if (!TEST_ptr(method)) - goto err; - - dh_ex_idx = DH_get_ex_new_index(0, NULL, NULL, NULL, NULL); - - pkey = get_dh512(NULL); - if (!TEST_ptr(pkey)) - goto err; - cdh = EVP_PKEY_get0_DH(pkey); - if (!TEST_ptr(cdh)) - goto err; - dh = DH_new(); - if (!TEST_ptr(dh)) - goto err; - if (!TEST_true(DH_set_ex_data(dh, dh_ex_idx, (void *)"test"))) - goto err; - - orig_dh_compute_key = DH_meth_get_compute_key(def); - if (!TEST_true(DH_meth_set_compute_key(method, tst_dh_compute_key))) - goto err; - if (!TEST_true(DH_set_method(dh, method))) - goto err; - - p = BN_dup(DH_get0_p(cdh)); - g = BN_dup(DH_get0_g(cdh)); - if (!TEST_ptr(p) || !TEST_ptr(g)) - goto err; - if (!TEST_true(DH_set0_pqg(dh, p, NULL, g))) - goto err; - p = g = NULL; - - if (!TEST_true(DH_generate_key(dh))) - goto err; - - ctx = EVP_PKEY_CTX_new_from_pkey(NULL, pkey, NULL); - if (!TEST_int_gt(EVP_PKEY_keygen_init(ctx), 0)) - goto err; - if (!TEST_int_gt(EVP_PKEY_keygen(ctx, &pkeyb), 0)) - goto err; - EVP_PKEY_free(pkey); - pkey = NULL; - - pkey = EVP_PKEY_new(); - if (!TEST_ptr(pkey)) - goto err; - if (!TEST_int_gt(EVP_PKEY_assign_DH(pkey, dh), 0)) - goto err; - dh = NULL; - - compute_key_hits = 0; - EVP_PKEY_CTX_free(ctx); - ctx = EVP_PKEY_CTX_new(pkey, NULL); - if (!TEST_ptr(ctx)) - return 0; - if (!TEST_int_gt(EVP_PKEY_derive_init(ctx), 0)) - goto err; - if (!TEST_int_gt(EVP_PKEY_derive_set_peer(ctx, pkeyb), 0)) - goto err; - if (!TEST_int_gt(EVP_PKEY_derive(ctx, NULL, &len), 0)) - goto err; - buf = OPENSSL_malloc(len); - if (!TEST_ptr(buf)) - goto err; - if (!TEST_int_gt(EVP_PKEY_derive(ctx, buf, &len), 0)) - goto err; - - /* We expect to see our custom compute key function called once */ - if (!TEST_int_eq(compute_key_hits, 1)) - goto err; - - testresult = 1; -err: - BN_free(p); - BN_free(g); - EVP_PKEY_CTX_free(ctx); - EVP_PKEY_free(pkey); - EVP_PKEY_free(pkeyb); - DH_meth_free(method); - DH_free(dh); - OPENSSL_free(buf); - return testresult; -} -#endif /* OPENSSL_NO_DH */ -#endif /* OPENSSL_NO_DEPRECATED_3_0 */ - int setup_tests(void) { char *config_file = NULL; @@ -9260,15 +6912,9 @@ int setup_tests(void) #endif ADD_TEST(test_EVP_Digest); ADD_TEST(test_EVP_md_null); -#ifndef OPENSSL_NO_POLY1305 - ADD_TEST(test_evp_mac_poly1305_no_key); -#endif ADD_ALL_TESTS(test_EVP_PKEY_sign, 3); #ifndef OPENSSL_NO_DEPRECATED_3_0 ADD_ALL_TESTS(test_EVP_PKEY_sign_with_app_method, 2); -#endif -#ifndef OPENSSL_NO_EC - ADD_TEST(test_EVP_PKEY_sign_init_mismatched_key_alg); #endif ADD_ALL_TESTS(test_EVP_Enveloped, 2); ADD_ALL_TESTS(test_d2i_AutoPrivateKey, OSSL_NELEM(keydata)); @@ -9286,7 +6932,16 @@ int setup_tests(void) ADD_TEST(test_EVP_SM2_verify); #endif ADD_ALL_TESTS(test_set_get_raw_keys, OSSL_NELEM(keys)); - ADD_MFAIL_ALL_TESTS(test_set_get_raw_keys_mfail, OSSL_NELEM(keys)); +#ifndef OPENSSL_NO_DEPRECATED_3_0 + custom_pmeth = EVP_PKEY_meth_new(0xdefaced, 0); + if (!TEST_ptr(custom_pmeth)) + return 0; + EVP_PKEY_meth_set_check(custom_pmeth, pkey_custom_check); + EVP_PKEY_meth_set_public_check(custom_pmeth, pkey_custom_pub_check); + EVP_PKEY_meth_set_param_check(custom_pmeth, pkey_custom_param_check); + if (!TEST_int_eq(EVP_PKEY_meth_add0(custom_pmeth), 1)) + return 0; +#endif ADD_ALL_TESTS(test_EVP_PKEY_check, OSSL_NELEM(keycheckdata)); #ifndef OPENSSL_NO_CMAC ADD_TEST(test_CMAC_keygen); @@ -9297,7 +6952,7 @@ int setup_tests(void) #ifndef OPENSSL_NO_EC ADD_TEST(test_X509_PUBKEY_inplace); ADD_TEST(test_X509_PUBKEY_dup); - ADD_ALL_TESTS(test_invalid_ec_char2_pub_range_decode, + ADD_ALL_TESTS(test_invalide_ec_char2_pub_range_decode, OSSL_NELEM(ec_der_pub_keys)); #endif #ifndef OPENSSL_NO_DSA @@ -9307,8 +6962,6 @@ int setup_tests(void) ADD_TEST(test_RSA_get_set_params); ADD_TEST(test_RSA_OAEP_set_get_params); ADD_TEST(test_RSA_OAEP_set_null_label); - ADD_TEST(test_RSA_verify_recover_rejects_short_buffer); - ADD_TEST(test_RSA_verify_recover_empty_payload); ADD_TEST(test_RSA_encrypt); #ifndef OPENSSL_NO_DEPRECATED_3_0 ADD_TEST(test_RSA_legacy); @@ -9321,7 +6974,6 @@ int setup_tests(void) #ifndef OPENSSL_NO_DEPRECATED_3_0 ADD_TEST(test_EVP_PKEY_set1_DH); #endif - ADD_TEST(test_dhx_derive_rejects_bad_peer_q); #endif #ifndef OPENSSL_NO_EC ADD_TEST(test_EC_priv_pub); @@ -9338,8 +6990,7 @@ int setup_tests(void) ADD_ALL_TESTS(test_evp_iv_aes, 13); #ifndef OPENSSL_NO_DES ADD_ALL_TESTS(test_evp_iv_des, 6); - ADD_TEST(test_EVP_CIPHER_get_type_des_ede3); -#endif /* OPENSSL_NO_DES */ +#endif #ifndef OPENSSL_NO_BF ADD_ALL_TESTS(test_evp_bf_default_keylen, 4); #endif @@ -9352,14 +7003,6 @@ int setup_tests(void) ADD_TEST(test_names_do_all); - setup_cipher_list(); - ADD_ALL_TESTS(test_evp_diff_order_init, cipher_list_n); - ADD_ALL_TESTS(test_evp_stale_key_reinit, cipher_list_n); - ADD_ALL_TESTS(test_evp_decrypt_roundtrip_multistep, cipher_list_n); - ADD_ALL_TESTS(test_evp_oneshot_aead_zerolen, cipher_list_n); - ADD_ALL_TESTS(test_evp_aead_tag_direction, cipher_list_n); - ADD_ALL_TESTS(test_evp_aead_late_aad, cipher_list_n); - ADD_ALL_TESTS(test_evp_init_seq, OSSL_NELEM(evp_init_tests)); ADD_ALL_TESTS(test_evp_reset, OSSL_NELEM(evp_reset_tests)); ADD_ALL_TESTS(test_evp_reinit_seq, OSSL_NELEM(evp_reinit_tests)); @@ -9368,10 +7011,16 @@ int setup_tests(void) ADD_ALL_TESTS(test_evp_final_no_tag, OSSL_NELEM(evp_final_no_tag)); ADD_ALL_TESTS(test_ivlen_change, OSSL_NELEM(ivlen_change_ciphers)); - ADD_ALL_TESTS(test_iv_reuse, OSSL_NELEM(iv_state_ciphers)); if (OSSL_NELEM(keylen_change_ciphers) - 1 > 0) ADD_ALL_TESTS(test_keylen_change, OSSL_NELEM(keylen_change_ciphers) - 1); +#ifndef OPENSSL_NO_DEPRECATED_3_0 + ADD_ALL_TESTS(test_custom_pmeth, 12); + ADD_TEST(test_evp_md_cipher_meth); + ADD_TEST(test_custom_md_meth); + ADD_TEST(test_custom_ciph_meth); +#endif + #ifndef OPENSSL_NO_ECX ADD_ALL_TESTS(test_ecx_short_keys, OSSL_NELEM(ecxnids)); ADD_ALL_TESTS(test_ecx_not_private_key, OSSL_NELEM(keys)); @@ -9385,17 +7034,8 @@ int setup_tests(void) ADD_TEST(test_aes_rc4_keylen_change_cve_2023_5363); #endif - ADD_ALL_TESTS(test_aead_oneshot_roundtrip, 2 * OSSL_NELEM(aead_oneshot_cfgs)); - - /* Test cases for CVE-2026-45446 */ - ADD_TEST(test_aes_gcm_siv_empty_data); - ADD_TEST(test_aes_siv_ctx_reuse); - ADD_TEST(test_invalid_ctx_for_digest); - ADD_TEST(test_evp_cipher_negative_length); - ADD_TEST(test_aes_xts_rejects_missing_iv); - ADD_TEST(test_evp_cipher_pipeline); #ifndef OPENSSL_NO_ML_KEM @@ -9405,20 +7045,6 @@ int setup_tests(void) ADD_ALL_TESTS(test_ml_dsa_seed_only, 2); #endif -#ifndef OPENSSL_NO_DEPRECATED_3_0 - ADD_TEST(test_low_level_rsa_method); - ADD_ALL_TESTS(test_low_level_rsa_kem_public_encrypt_failure, 2); -#ifndef OPENSSL_NO_DSA - ADD_TEST(test_low_level_dsa_method); -#endif -#ifndef OPENSSL_NO_EC - ADD_TEST(test_low_level_ec_method); -#endif -#ifndef OPENSSL_NO_DH - ADD_TEST(test_low_level_dh_method); -#endif -#endif /* OPENSSL_NO_DEPRECATED_3_0 */ - return 1; } @@ -9426,7 +7052,6 @@ void cleanup_tests(void) { OSSL_PROVIDER_unload(nullprov); OSSL_PROVIDER_unload(deflprov); - cleanup_cipher_list(); #ifndef OPENSSL_SYS_TANDEM OSSL_PROVIDER_unload(lgcyprov); #endif diff --git a/test/evp_extra_test2.c b/test/evp_extra_test2.c index c9b64bbf26..66fc827db8 100644 --- a/test/evp_extra_test2.c +++ b/test/evp_extra_test2.c @@ -44,67 +44,614 @@ static OSSL_PROVIDER *nullprov = NULL; * should never use this key anywhere but in an example. */ static const unsigned char kExampleRSAKeyDER[] = { - 0x30, 0x82, 0x02, 0x5c, 0x02, 0x01, 0x00, 0x02, 0x81, 0x81, - 0x00, 0xf8, 0xb8, 0x6c, 0x83, 0xb4, 0xbc, 0xd9, 0xa8, 0x57, - 0xc0, 0xa5, 0xb4, 0x59, 0x76, 0x8c, 0x54, 0x1d, 0x79, 0xeb, - 0x22, 0x52, 0x04, 0x7e, 0xd3, 0x37, 0xeb, 0x41, 0xfd, 0x83, - 0xf9, 0xf0, 0xa6, 0x85, 0x15, 0x34, 0x75, 0x71, 0x5a, 0x84, - 0xa8, 0x3c, 0xd2, 0xef, 0x5a, 0x4e, 0xd3, 0xde, 0x97, 0x8a, - 0xdd, 0xff, 0xbb, 0xcf, 0x0a, 0xaa, 0x86, 0x92, 0xbe, 0xb8, - 0x50, 0xe4, 0xcd, 0x6f, 0x80, 0x33, 0x30, 0x76, 0x13, 0x8f, - 0xca, 0x7b, 0xdc, 0xec, 0x5a, 0xca, 0x63, 0xc7, 0x03, 0x25, - 0xef, 0xa8, 0x8a, 0x83, 0x58, 0x76, 0x20, 0xfa, 0x16, 0x77, - 0xd7, 0x79, 0x92, 0x63, 0x01, 0x48, 0x1a, 0xd8, 0x7b, 0x67, - 0xf1, 0x52, 0x55, 0x49, 0x4e, 0xd6, 0x6e, 0x4a, 0x5c, 0xd7, - 0x7a, 0x37, 0x36, 0x0c, 0xde, 0xdd, 0x8f, 0x44, 0xe8, 0xc2, - 0xa7, 0x2c, 0x2b, 0xb5, 0xaf, 0x64, 0x4b, 0x61, 0x07, 0x02, - 0x03, 0x01, 0x00, 0x01, 0x02, 0x81, 0x80, 0x74, 0x88, 0x64, - 0x3f, 0x69, 0x45, 0x3a, 0x6d, 0xc7, 0x7f, 0xb9, 0xa3, 0xc0, - 0x6e, 0xec, 0xdc, 0xd4, 0x5a, 0xb5, 0x32, 0x85, 0x5f, 0x19, - 0xd4, 0xf8, 0xd4, 0x3f, 0x3c, 0xfa, 0xc2, 0xf6, 0x5f, 0xee, - 0xe6, 0xba, 0x87, 0x74, 0x2e, 0xc7, 0x0c, 0xd4, 0x42, 0xb8, - 0x66, 0x85, 0x9c, 0x7b, 0x24, 0x61, 0xaa, 0x16, 0x11, 0xf6, - 0xb5, 0xb6, 0xa4, 0x0a, 0xc9, 0x55, 0x2e, 0x81, 0xa5, 0x47, - 0x61, 0xcb, 0x25, 0x8f, 0xc2, 0x15, 0x7b, 0x0e, 0x7c, 0x36, - 0x9f, 0x3a, 0xda, 0x58, 0x86, 0x1c, 0x5b, 0x83, 0x79, 0xe6, - 0x2b, 0xcc, 0xe6, 0xfa, 0x2c, 0x61, 0xf2, 0x78, 0x80, 0x1b, - 0xe2, 0xf3, 0x9d, 0x39, 0x2b, 0x65, 0x57, 0x91, 0x3d, 0x71, - 0x99, 0x73, 0xa5, 0xc2, 0x79, 0x20, 0x8c, 0x07, 0x4f, 0xe5, - 0xb4, 0x60, 0x1f, 0x99, 0xa2, 0xb1, 0x4f, 0x0c, 0xef, 0xbc, - 0x59, 0x53, 0x00, 0x7d, 0xb1, 0x02, 0x41, 0x00, 0xfc, 0x7e, - 0x23, 0x65, 0x70, 0xf8, 0xce, 0xd3, 0x40, 0x41, 0x80, 0x6a, - 0x1d, 0x01, 0xd6, 0x01, 0xff, 0xb6, 0x1b, 0x3d, 0x3d, 0x59, - 0x09, 0x33, 0x79, 0xc0, 0x4f, 0xde, 0x96, 0x27, 0x4b, 0x18, - 0xc6, 0xd9, 0x78, 0xf1, 0xf4, 0x35, 0x46, 0xe9, 0x7c, 0x42, - 0x7a, 0x5d, 0x9f, 0xef, 0x54, 0xb8, 0xf7, 0x9f, 0xc4, 0x33, - 0x6c, 0xf3, 0x8c, 0x32, 0x46, 0x87, 0x67, 0x30, 0x7b, 0xa7, - 0xac, 0xe3, 0x02, 0x41, 0x00, 0xfc, 0x2c, 0xdf, 0x0c, 0x0d, - 0x88, 0xf5, 0xb1, 0x92, 0xa8, 0x93, 0x47, 0x63, 0x55, 0xf5, - 0xca, 0x58, 0x43, 0xba, 0x1c, 0xe5, 0x9e, 0xb6, 0x95, 0x05, - 0xcd, 0xb5, 0x82, 0xdf, 0xeb, 0x04, 0x53, 0x9d, 0xbd, 0xc2, - 0x38, 0x16, 0xb3, 0x62, 0xdd, 0xa1, 0x46, 0xdb, 0x6d, 0x97, - 0x93, 0x9f, 0x8a, 0xc3, 0x9b, 0x64, 0x7e, 0x42, 0xe3, 0x32, - 0x57, 0x19, 0x1b, 0xd5, 0x6e, 0x85, 0xfa, 0xb8, 0x8d, 0x02, - 0x41, 0x00, 0xbc, 0x3d, 0xde, 0x6d, 0xd6, 0x97, 0xe8, 0xba, - 0x9e, 0x81, 0x37, 0x17, 0xe5, 0xa0, 0x64, 0xc9, 0x00, 0xb7, - 0xe7, 0xfe, 0xf4, 0x29, 0xd9, 0x2e, 0x43, 0x6b, 0x19, 0x20, - 0xbd, 0x99, 0x75, 0xe7, 0x76, 0xf8, 0xd3, 0xae, 0xaf, 0x7e, - 0xb8, 0xeb, 0x81, 0xf4, 0x9d, 0xfe, 0x07, 0x2b, 0x0b, 0x63, - 0x0b, 0x5a, 0x55, 0x90, 0x71, 0x7d, 0xf1, 0xdb, 0xd9, 0xb1, - 0x41, 0x41, 0x68, 0x2f, 0x4e, 0x39, 0x02, 0x40, 0x5a, 0x34, - 0x66, 0xd8, 0xf5, 0xe2, 0x7f, 0x18, 0xb5, 0x00, 0x6e, 0x26, - 0x84, 0x27, 0x14, 0x93, 0xfb, 0xfc, 0xc6, 0x0f, 0x5e, 0x27, - 0xe6, 0xe1, 0xe9, 0xc0, 0x8a, 0xe4, 0x34, 0xda, 0xe9, 0xa2, - 0x4b, 0x73, 0xbc, 0x8c, 0xb9, 0xba, 0x13, 0x6c, 0x7a, 0x2b, - 0x51, 0x84, 0xa3, 0x4a, 0xe0, 0x30, 0x10, 0x06, 0x7e, 0xed, - 0x17, 0x5a, 0x14, 0x00, 0xc9, 0xef, 0x85, 0xea, 0x52, 0x2c, - 0xbc, 0x65, 0x02, 0x40, 0x51, 0xe3, 0xf2, 0x83, 0x19, 0x9b, - 0xc4, 0x1e, 0x2f, 0x50, 0x3d, 0xdf, 0x5a, 0xa2, 0x18, 0xca, - 0x5f, 0x2e, 0x49, 0xaf, 0x6f, 0xcc, 0xfa, 0x65, 0x77, 0x94, - 0xb5, 0xa1, 0x0a, 0xa9, 0xd1, 0x8a, 0x39, 0x37, 0xf4, 0x0b, - 0xa0, 0xd7, 0x82, 0x27, 0x5e, 0xae, 0x17, 0x17, 0xa1, 0x1e, - 0x54, 0x34, 0xbf, 0x6e, 0xc4, 0x8e, 0x99, 0x5d, 0x08, 0xf1, - 0x2d, 0x86, 0x9d, 0xa5, 0x20, 0x1b, 0xe5, 0xdf + 0x30, + 0x82, + 0x02, + 0x5c, + 0x02, + 0x01, + 0x00, + 0x02, + 0x81, + 0x81, + 0x00, + 0xf8, + 0xb8, + 0x6c, + 0x83, + 0xb4, + 0xbc, + 0xd9, + 0xa8, + 0x57, + 0xc0, + 0xa5, + 0xb4, + 0x59, + 0x76, + 0x8c, + 0x54, + 0x1d, + 0x79, + 0xeb, + 0x22, + 0x52, + 0x04, + 0x7e, + 0xd3, + 0x37, + 0xeb, + 0x41, + 0xfd, + 0x83, + 0xf9, + 0xf0, + 0xa6, + 0x85, + 0x15, + 0x34, + 0x75, + 0x71, + 0x5a, + 0x84, + 0xa8, + 0x3c, + 0xd2, + 0xef, + 0x5a, + 0x4e, + 0xd3, + 0xde, + 0x97, + 0x8a, + 0xdd, + 0xff, + 0xbb, + 0xcf, + 0x0a, + 0xaa, + 0x86, + 0x92, + 0xbe, + 0xb8, + 0x50, + 0xe4, + 0xcd, + 0x6f, + 0x80, + 0x33, + 0x30, + 0x76, + 0x13, + 0x8f, + 0xca, + 0x7b, + 0xdc, + 0xec, + 0x5a, + 0xca, + 0x63, + 0xc7, + 0x03, + 0x25, + 0xef, + 0xa8, + 0x8a, + 0x83, + 0x58, + 0x76, + 0x20, + 0xfa, + 0x16, + 0x77, + 0xd7, + 0x79, + 0x92, + 0x63, + 0x01, + 0x48, + 0x1a, + 0xd8, + 0x7b, + 0x67, + 0xf1, + 0x52, + 0x55, + 0x49, + 0x4e, + 0xd6, + 0x6e, + 0x4a, + 0x5c, + 0xd7, + 0x7a, + 0x37, + 0x36, + 0x0c, + 0xde, + 0xdd, + 0x8f, + 0x44, + 0xe8, + 0xc2, + 0xa7, + 0x2c, + 0x2b, + 0xb5, + 0xaf, + 0x64, + 0x4b, + 0x61, + 0x07, + 0x02, + 0x03, + 0x01, + 0x00, + 0x01, + 0x02, + 0x81, + 0x80, + 0x74, + 0x88, + 0x64, + 0x3f, + 0x69, + 0x45, + 0x3a, + 0x6d, + 0xc7, + 0x7f, + 0xb9, + 0xa3, + 0xc0, + 0x6e, + 0xec, + 0xdc, + 0xd4, + 0x5a, + 0xb5, + 0x32, + 0x85, + 0x5f, + 0x19, + 0xd4, + 0xf8, + 0xd4, + 0x3f, + 0x3c, + 0xfa, + 0xc2, + 0xf6, + 0x5f, + 0xee, + 0xe6, + 0xba, + 0x87, + 0x74, + 0x2e, + 0xc7, + 0x0c, + 0xd4, + 0x42, + 0xb8, + 0x66, + 0x85, + 0x9c, + 0x7b, + 0x24, + 0x61, + 0xaa, + 0x16, + 0x11, + 0xf6, + 0xb5, + 0xb6, + 0xa4, + 0x0a, + 0xc9, + 0x55, + 0x2e, + 0x81, + 0xa5, + 0x47, + 0x61, + 0xcb, + 0x25, + 0x8f, + 0xc2, + 0x15, + 0x7b, + 0x0e, + 0x7c, + 0x36, + 0x9f, + 0x3a, + 0xda, + 0x58, + 0x86, + 0x1c, + 0x5b, + 0x83, + 0x79, + 0xe6, + 0x2b, + 0xcc, + 0xe6, + 0xfa, + 0x2c, + 0x61, + 0xf2, + 0x78, + 0x80, + 0x1b, + 0xe2, + 0xf3, + 0x9d, + 0x39, + 0x2b, + 0x65, + 0x57, + 0x91, + 0x3d, + 0x71, + 0x99, + 0x73, + 0xa5, + 0xc2, + 0x79, + 0x20, + 0x8c, + 0x07, + 0x4f, + 0xe5, + 0xb4, + 0x60, + 0x1f, + 0x99, + 0xa2, + 0xb1, + 0x4f, + 0x0c, + 0xef, + 0xbc, + 0x59, + 0x53, + 0x00, + 0x7d, + 0xb1, + 0x02, + 0x41, + 0x00, + 0xfc, + 0x7e, + 0x23, + 0x65, + 0x70, + 0xf8, + 0xce, + 0xd3, + 0x40, + 0x41, + 0x80, + 0x6a, + 0x1d, + 0x01, + 0xd6, + 0x01, + 0xff, + 0xb6, + 0x1b, + 0x3d, + 0x3d, + 0x59, + 0x09, + 0x33, + 0x79, + 0xc0, + 0x4f, + 0xde, + 0x96, + 0x27, + 0x4b, + 0x18, + 0xc6, + 0xd9, + 0x78, + 0xf1, + 0xf4, + 0x35, + 0x46, + 0xe9, + 0x7c, + 0x42, + 0x7a, + 0x5d, + 0x9f, + 0xef, + 0x54, + 0xb8, + 0xf7, + 0x9f, + 0xc4, + 0x33, + 0x6c, + 0xf3, + 0x8c, + 0x32, + 0x46, + 0x87, + 0x67, + 0x30, + 0x7b, + 0xa7, + 0xac, + 0xe3, + 0x02, + 0x41, + 0x00, + 0xfc, + 0x2c, + 0xdf, + 0x0c, + 0x0d, + 0x88, + 0xf5, + 0xb1, + 0x92, + 0xa8, + 0x93, + 0x47, + 0x63, + 0x55, + 0xf5, + 0xca, + 0x58, + 0x43, + 0xba, + 0x1c, + 0xe5, + 0x9e, + 0xb6, + 0x95, + 0x05, + 0xcd, + 0xb5, + 0x82, + 0xdf, + 0xeb, + 0x04, + 0x53, + 0x9d, + 0xbd, + 0xc2, + 0x38, + 0x16, + 0xb3, + 0x62, + 0xdd, + 0xa1, + 0x46, + 0xdb, + 0x6d, + 0x97, + 0x93, + 0x9f, + 0x8a, + 0xc3, + 0x9b, + 0x64, + 0x7e, + 0x42, + 0xe3, + 0x32, + 0x57, + 0x19, + 0x1b, + 0xd5, + 0x6e, + 0x85, + 0xfa, + 0xb8, + 0x8d, + 0x02, + 0x41, + 0x00, + 0xbc, + 0x3d, + 0xde, + 0x6d, + 0xd6, + 0x97, + 0xe8, + 0xba, + 0x9e, + 0x81, + 0x37, + 0x17, + 0xe5, + 0xa0, + 0x64, + 0xc9, + 0x00, + 0xb7, + 0xe7, + 0xfe, + 0xf4, + 0x29, + 0xd9, + 0x2e, + 0x43, + 0x6b, + 0x19, + 0x20, + 0xbd, + 0x99, + 0x75, + 0xe7, + 0x76, + 0xf8, + 0xd3, + 0xae, + 0xaf, + 0x7e, + 0xb8, + 0xeb, + 0x81, + 0xf4, + 0x9d, + 0xfe, + 0x07, + 0x2b, + 0x0b, + 0x63, + 0x0b, + 0x5a, + 0x55, + 0x90, + 0x71, + 0x7d, + 0xf1, + 0xdb, + 0xd9, + 0xb1, + 0x41, + 0x41, + 0x68, + 0x2f, + 0x4e, + 0x39, + 0x02, + 0x40, + 0x5a, + 0x34, + 0x66, + 0xd8, + 0xf5, + 0xe2, + 0x7f, + 0x18, + 0xb5, + 0x00, + 0x6e, + 0x26, + 0x84, + 0x27, + 0x14, + 0x93, + 0xfb, + 0xfc, + 0xc6, + 0x0f, + 0x5e, + 0x27, + 0xe6, + 0xe1, + 0xe9, + 0xc0, + 0x8a, + 0xe4, + 0x34, + 0xda, + 0xe9, + 0xa2, + 0x4b, + 0x73, + 0xbc, + 0x8c, + 0xb9, + 0xba, + 0x13, + 0x6c, + 0x7a, + 0x2b, + 0x51, + 0x84, + 0xa3, + 0x4a, + 0xe0, + 0x30, + 0x10, + 0x06, + 0x7e, + 0xed, + 0x17, + 0x5a, + 0x14, + 0x00, + 0xc9, + 0xef, + 0x85, + 0xea, + 0x52, + 0x2c, + 0xbc, + 0x65, + 0x02, + 0x40, + 0x51, + 0xe3, + 0xf2, + 0x83, + 0x19, + 0x9b, + 0xc4, + 0x1e, + 0x2f, + 0x50, + 0x3d, + 0xdf, + 0x5a, + 0xa2, + 0x18, + 0xca, + 0x5f, + 0x2e, + 0x49, + 0xaf, + 0x6f, + 0xcc, + 0xfa, + 0x65, + 0x77, + 0x94, + 0xb5, + 0xa1, + 0x0a, + 0xa9, + 0xd1, + 0x8a, + 0x39, + 0x37, + 0xf4, + 0x0b, + 0xa0, + 0xd7, + 0x82, + 0x27, + 0x5e, + 0xae, + 0x17, + 0x17, + 0xa1, + 0x1e, + 0x54, + 0x34, + 0xbf, + 0x6e, + 0xc4, + 0x8e, + 0x99, + 0x5d, + 0x08, + 0xf1, + 0x2d, + 0x86, + 0x9d, + 0xa5, + 0x20, + 0x1b, + 0xe5, + 0xdf, }; /* @@ -112,70 +659,640 @@ static const unsigned char kExampleRSAKeyDER[] = { * PrivateKeyInfo. */ static const unsigned char kExampleRSAKeyPKCS8[] = { - 0x30, 0x82, 0x02, 0x76, 0x02, 0x01, 0x00, 0x30, 0x0d, 0x06, - 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x01, - 0x05, 0x00, 0x04, 0x82, 0x02, 0x60, 0x30, 0x82, 0x02, 0x5c, - 0x02, 0x01, 0x00, 0x02, 0x81, 0x81, 0x00, 0xf8, 0xb8, 0x6c, - 0x83, 0xb4, 0xbc, 0xd9, 0xa8, 0x57, 0xc0, 0xa5, 0xb4, 0x59, - 0x76, 0x8c, 0x54, 0x1d, 0x79, 0xeb, 0x22, 0x52, 0x04, 0x7e, - 0xd3, 0x37, 0xeb, 0x41, 0xfd, 0x83, 0xf9, 0xf0, 0xa6, 0x85, - 0x15, 0x34, 0x75, 0x71, 0x5a, 0x84, 0xa8, 0x3c, 0xd2, 0xef, - 0x5a, 0x4e, 0xd3, 0xde, 0x97, 0x8a, 0xdd, 0xff, 0xbb, 0xcf, - 0x0a, 0xaa, 0x86, 0x92, 0xbe, 0xb8, 0x50, 0xe4, 0xcd, 0x6f, - 0x80, 0x33, 0x30, 0x76, 0x13, 0x8f, 0xca, 0x7b, 0xdc, 0xec, - 0x5a, 0xca, 0x63, 0xc7, 0x03, 0x25, 0xef, 0xa8, 0x8a, 0x83, - 0x58, 0x76, 0x20, 0xfa, 0x16, 0x77, 0xd7, 0x79, 0x92, 0x63, - 0x01, 0x48, 0x1a, 0xd8, 0x7b, 0x67, 0xf1, 0x52, 0x55, 0x49, - 0x4e, 0xd6, 0x6e, 0x4a, 0x5c, 0xd7, 0x7a, 0x37, 0x36, 0x0c, - 0xde, 0xdd, 0x8f, 0x44, 0xe8, 0xc2, 0xa7, 0x2c, 0x2b, 0xb5, - 0xaf, 0x64, 0x4b, 0x61, 0x07, 0x02, 0x03, 0x01, 0x00, 0x01, - 0x02, 0x81, 0x80, 0x74, 0x88, 0x64, 0x3f, 0x69, 0x45, 0x3a, - 0x6d, 0xc7, 0x7f, 0xb9, 0xa3, 0xc0, 0x6e, 0xec, 0xdc, 0xd4, - 0x5a, 0xb5, 0x32, 0x85, 0x5f, 0x19, 0xd4, 0xf8, 0xd4, 0x3f, - 0x3c, 0xfa, 0xc2, 0xf6, 0x5f, 0xee, 0xe6, 0xba, 0x87, 0x74, - 0x2e, 0xc7, 0x0c, 0xd4, 0x42, 0xb8, 0x66, 0x85, 0x9c, 0x7b, - 0x24, 0x61, 0xaa, 0x16, 0x11, 0xf6, 0xb5, 0xb6, 0xa4, 0x0a, - 0xc9, 0x55, 0x2e, 0x81, 0xa5, 0x47, 0x61, 0xcb, 0x25, 0x8f, - 0xc2, 0x15, 0x7b, 0x0e, 0x7c, 0x36, 0x9f, 0x3a, 0xda, 0x58, - 0x86, 0x1c, 0x5b, 0x83, 0x79, 0xe6, 0x2b, 0xcc, 0xe6, 0xfa, - 0x2c, 0x61, 0xf2, 0x78, 0x80, 0x1b, 0xe2, 0xf3, 0x9d, 0x39, - 0x2b, 0x65, 0x57, 0x91, 0x3d, 0x71, 0x99, 0x73, 0xa5, 0xc2, - 0x79, 0x20, 0x8c, 0x07, 0x4f, 0xe5, 0xb4, 0x60, 0x1f, 0x99, - 0xa2, 0xb1, 0x4f, 0x0c, 0xef, 0xbc, 0x59, 0x53, 0x00, 0x7d, - 0xb1, 0x02, 0x41, 0x00, 0xfc, 0x7e, 0x23, 0x65, 0x70, 0xf8, - 0xce, 0xd3, 0x40, 0x41, 0x80, 0x6a, 0x1d, 0x01, 0xd6, 0x01, - 0xff, 0xb6, 0x1b, 0x3d, 0x3d, 0x59, 0x09, 0x33, 0x79, 0xc0, - 0x4f, 0xde, 0x96, 0x27, 0x4b, 0x18, 0xc6, 0xd9, 0x78, 0xf1, - 0xf4, 0x35, 0x46, 0xe9, 0x7c, 0x42, 0x7a, 0x5d, 0x9f, 0xef, - 0x54, 0xb8, 0xf7, 0x9f, 0xc4, 0x33, 0x6c, 0xf3, 0x8c, 0x32, - 0x46, 0x87, 0x67, 0x30, 0x7b, 0xa7, 0xac, 0xe3, 0x02, 0x41, - 0x00, 0xfc, 0x2c, 0xdf, 0x0c, 0x0d, 0x88, 0xf5, 0xb1, 0x92, - 0xa8, 0x93, 0x47, 0x63, 0x55, 0xf5, 0xca, 0x58, 0x43, 0xba, - 0x1c, 0xe5, 0x9e, 0xb6, 0x95, 0x05, 0xcd, 0xb5, 0x82, 0xdf, - 0xeb, 0x04, 0x53, 0x9d, 0xbd, 0xc2, 0x38, 0x16, 0xb3, 0x62, - 0xdd, 0xa1, 0x46, 0xdb, 0x6d, 0x97, 0x93, 0x9f, 0x8a, 0xc3, - 0x9b, 0x64, 0x7e, 0x42, 0xe3, 0x32, 0x57, 0x19, 0x1b, 0xd5, - 0x6e, 0x85, 0xfa, 0xb8, 0x8d, 0x02, 0x41, 0x00, 0xbc, 0x3d, - 0xde, 0x6d, 0xd6, 0x97, 0xe8, 0xba, 0x9e, 0x81, 0x37, 0x17, - 0xe5, 0xa0, 0x64, 0xc9, 0x00, 0xb7, 0xe7, 0xfe, 0xf4, 0x29, - 0xd9, 0x2e, 0x43, 0x6b, 0x19, 0x20, 0xbd, 0x99, 0x75, 0xe7, - 0x76, 0xf8, 0xd3, 0xae, 0xaf, 0x7e, 0xb8, 0xeb, 0x81, 0xf4, - 0x9d, 0xfe, 0x07, 0x2b, 0x0b, 0x63, 0x0b, 0x5a, 0x55, 0x90, - 0x71, 0x7d, 0xf1, 0xdb, 0xd9, 0xb1, 0x41, 0x41, 0x68, 0x2f, - 0x4e, 0x39, 0x02, 0x40, 0x5a, 0x34, 0x66, 0xd8, 0xf5, 0xe2, - 0x7f, 0x18, 0xb5, 0x00, 0x6e, 0x26, 0x84, 0x27, 0x14, 0x93, - 0xfb, 0xfc, 0xc6, 0x0f, 0x5e, 0x27, 0xe6, 0xe1, 0xe9, 0xc0, - 0x8a, 0xe4, 0x34, 0xda, 0xe9, 0xa2, 0x4b, 0x73, 0xbc, 0x8c, - 0xb9, 0xba, 0x13, 0x6c, 0x7a, 0x2b, 0x51, 0x84, 0xa3, 0x4a, - 0xe0, 0x30, 0x10, 0x06, 0x7e, 0xed, 0x17, 0x5a, 0x14, 0x00, - 0xc9, 0xef, 0x85, 0xea, 0x52, 0x2c, 0xbc, 0x65, 0x02, 0x40, - 0x51, 0xe3, 0xf2, 0x83, 0x19, 0x9b, 0xc4, 0x1e, 0x2f, 0x50, - 0x3d, 0xdf, 0x5a, 0xa2, 0x18, 0xca, 0x5f, 0x2e, 0x49, 0xaf, - 0x6f, 0xcc, 0xfa, 0x65, 0x77, 0x94, 0xb5, 0xa1, 0x0a, 0xa9, - 0xd1, 0x8a, 0x39, 0x37, 0xf4, 0x0b, 0xa0, 0xd7, 0x82, 0x27, - 0x5e, 0xae, 0x17, 0x17, 0xa1, 0x1e, 0x54, 0x34, 0xbf, 0x6e, - 0xc4, 0x8e, 0x99, 0x5d, 0x08, 0xf1, 0x2d, 0x86, 0x9d, 0xa5, - 0x20, 0x1b, 0xe5, 0xdf + 0x30, + 0x82, + 0x02, + 0x76, + 0x02, + 0x01, + 0x00, + 0x30, + 0x0d, + 0x06, + 0x09, + 0x2a, + 0x86, + 0x48, + 0x86, + 0xf7, + 0x0d, + 0x01, + 0x01, + 0x01, + 0x05, + 0x00, + 0x04, + 0x82, + 0x02, + 0x60, + 0x30, + 0x82, + 0x02, + 0x5c, + 0x02, + 0x01, + 0x00, + 0x02, + 0x81, + 0x81, + 0x00, + 0xf8, + 0xb8, + 0x6c, + 0x83, + 0xb4, + 0xbc, + 0xd9, + 0xa8, + 0x57, + 0xc0, + 0xa5, + 0xb4, + 0x59, + 0x76, + 0x8c, + 0x54, + 0x1d, + 0x79, + 0xeb, + 0x22, + 0x52, + 0x04, + 0x7e, + 0xd3, + 0x37, + 0xeb, + 0x41, + 0xfd, + 0x83, + 0xf9, + 0xf0, + 0xa6, + 0x85, + 0x15, + 0x34, + 0x75, + 0x71, + 0x5a, + 0x84, + 0xa8, + 0x3c, + 0xd2, + 0xef, + 0x5a, + 0x4e, + 0xd3, + 0xde, + 0x97, + 0x8a, + 0xdd, + 0xff, + 0xbb, + 0xcf, + 0x0a, + 0xaa, + 0x86, + 0x92, + 0xbe, + 0xb8, + 0x50, + 0xe4, + 0xcd, + 0x6f, + 0x80, + 0x33, + 0x30, + 0x76, + 0x13, + 0x8f, + 0xca, + 0x7b, + 0xdc, + 0xec, + 0x5a, + 0xca, + 0x63, + 0xc7, + 0x03, + 0x25, + 0xef, + 0xa8, + 0x8a, + 0x83, + 0x58, + 0x76, + 0x20, + 0xfa, + 0x16, + 0x77, + 0xd7, + 0x79, + 0x92, + 0x63, + 0x01, + 0x48, + 0x1a, + 0xd8, + 0x7b, + 0x67, + 0xf1, + 0x52, + 0x55, + 0x49, + 0x4e, + 0xd6, + 0x6e, + 0x4a, + 0x5c, + 0xd7, + 0x7a, + 0x37, + 0x36, + 0x0c, + 0xde, + 0xdd, + 0x8f, + 0x44, + 0xe8, + 0xc2, + 0xa7, + 0x2c, + 0x2b, + 0xb5, + 0xaf, + 0x64, + 0x4b, + 0x61, + 0x07, + 0x02, + 0x03, + 0x01, + 0x00, + 0x01, + 0x02, + 0x81, + 0x80, + 0x74, + 0x88, + 0x64, + 0x3f, + 0x69, + 0x45, + 0x3a, + 0x6d, + 0xc7, + 0x7f, + 0xb9, + 0xa3, + 0xc0, + 0x6e, + 0xec, + 0xdc, + 0xd4, + 0x5a, + 0xb5, + 0x32, + 0x85, + 0x5f, + 0x19, + 0xd4, + 0xf8, + 0xd4, + 0x3f, + 0x3c, + 0xfa, + 0xc2, + 0xf6, + 0x5f, + 0xee, + 0xe6, + 0xba, + 0x87, + 0x74, + 0x2e, + 0xc7, + 0x0c, + 0xd4, + 0x42, + 0xb8, + 0x66, + 0x85, + 0x9c, + 0x7b, + 0x24, + 0x61, + 0xaa, + 0x16, + 0x11, + 0xf6, + 0xb5, + 0xb6, + 0xa4, + 0x0a, + 0xc9, + 0x55, + 0x2e, + 0x81, + 0xa5, + 0x47, + 0x61, + 0xcb, + 0x25, + 0x8f, + 0xc2, + 0x15, + 0x7b, + 0x0e, + 0x7c, + 0x36, + 0x9f, + 0x3a, + 0xda, + 0x58, + 0x86, + 0x1c, + 0x5b, + 0x83, + 0x79, + 0xe6, + 0x2b, + 0xcc, + 0xe6, + 0xfa, + 0x2c, + 0x61, + 0xf2, + 0x78, + 0x80, + 0x1b, + 0xe2, + 0xf3, + 0x9d, + 0x39, + 0x2b, + 0x65, + 0x57, + 0x91, + 0x3d, + 0x71, + 0x99, + 0x73, + 0xa5, + 0xc2, + 0x79, + 0x20, + 0x8c, + 0x07, + 0x4f, + 0xe5, + 0xb4, + 0x60, + 0x1f, + 0x99, + 0xa2, + 0xb1, + 0x4f, + 0x0c, + 0xef, + 0xbc, + 0x59, + 0x53, + 0x00, + 0x7d, + 0xb1, + 0x02, + 0x41, + 0x00, + 0xfc, + 0x7e, + 0x23, + 0x65, + 0x70, + 0xf8, + 0xce, + 0xd3, + 0x40, + 0x41, + 0x80, + 0x6a, + 0x1d, + 0x01, + 0xd6, + 0x01, + 0xff, + 0xb6, + 0x1b, + 0x3d, + 0x3d, + 0x59, + 0x09, + 0x33, + 0x79, + 0xc0, + 0x4f, + 0xde, + 0x96, + 0x27, + 0x4b, + 0x18, + 0xc6, + 0xd9, + 0x78, + 0xf1, + 0xf4, + 0x35, + 0x46, + 0xe9, + 0x7c, + 0x42, + 0x7a, + 0x5d, + 0x9f, + 0xef, + 0x54, + 0xb8, + 0xf7, + 0x9f, + 0xc4, + 0x33, + 0x6c, + 0xf3, + 0x8c, + 0x32, + 0x46, + 0x87, + 0x67, + 0x30, + 0x7b, + 0xa7, + 0xac, + 0xe3, + 0x02, + 0x41, + 0x00, + 0xfc, + 0x2c, + 0xdf, + 0x0c, + 0x0d, + 0x88, + 0xf5, + 0xb1, + 0x92, + 0xa8, + 0x93, + 0x47, + 0x63, + 0x55, + 0xf5, + 0xca, + 0x58, + 0x43, + 0xba, + 0x1c, + 0xe5, + 0x9e, + 0xb6, + 0x95, + 0x05, + 0xcd, + 0xb5, + 0x82, + 0xdf, + 0xeb, + 0x04, + 0x53, + 0x9d, + 0xbd, + 0xc2, + 0x38, + 0x16, + 0xb3, + 0x62, + 0xdd, + 0xa1, + 0x46, + 0xdb, + 0x6d, + 0x97, + 0x93, + 0x9f, + 0x8a, + 0xc3, + 0x9b, + 0x64, + 0x7e, + 0x42, + 0xe3, + 0x32, + 0x57, + 0x19, + 0x1b, + 0xd5, + 0x6e, + 0x85, + 0xfa, + 0xb8, + 0x8d, + 0x02, + 0x41, + 0x00, + 0xbc, + 0x3d, + 0xde, + 0x6d, + 0xd6, + 0x97, + 0xe8, + 0xba, + 0x9e, + 0x81, + 0x37, + 0x17, + 0xe5, + 0xa0, + 0x64, + 0xc9, + 0x00, + 0xb7, + 0xe7, + 0xfe, + 0xf4, + 0x29, + 0xd9, + 0x2e, + 0x43, + 0x6b, + 0x19, + 0x20, + 0xbd, + 0x99, + 0x75, + 0xe7, + 0x76, + 0xf8, + 0xd3, + 0xae, + 0xaf, + 0x7e, + 0xb8, + 0xeb, + 0x81, + 0xf4, + 0x9d, + 0xfe, + 0x07, + 0x2b, + 0x0b, + 0x63, + 0x0b, + 0x5a, + 0x55, + 0x90, + 0x71, + 0x7d, + 0xf1, + 0xdb, + 0xd9, + 0xb1, + 0x41, + 0x41, + 0x68, + 0x2f, + 0x4e, + 0x39, + 0x02, + 0x40, + 0x5a, + 0x34, + 0x66, + 0xd8, + 0xf5, + 0xe2, + 0x7f, + 0x18, + 0xb5, + 0x00, + 0x6e, + 0x26, + 0x84, + 0x27, + 0x14, + 0x93, + 0xfb, + 0xfc, + 0xc6, + 0x0f, + 0x5e, + 0x27, + 0xe6, + 0xe1, + 0xe9, + 0xc0, + 0x8a, + 0xe4, + 0x34, + 0xda, + 0xe9, + 0xa2, + 0x4b, + 0x73, + 0xbc, + 0x8c, + 0xb9, + 0xba, + 0x13, + 0x6c, + 0x7a, + 0x2b, + 0x51, + 0x84, + 0xa3, + 0x4a, + 0xe0, + 0x30, + 0x10, + 0x06, + 0x7e, + 0xed, + 0x17, + 0x5a, + 0x14, + 0x00, + 0xc9, + 0xef, + 0x85, + 0xea, + 0x52, + 0x2c, + 0xbc, + 0x65, + 0x02, + 0x40, + 0x51, + 0xe3, + 0xf2, + 0x83, + 0x19, + 0x9b, + 0xc4, + 0x1e, + 0x2f, + 0x50, + 0x3d, + 0xdf, + 0x5a, + 0xa2, + 0x18, + 0xca, + 0x5f, + 0x2e, + 0x49, + 0xaf, + 0x6f, + 0xcc, + 0xfa, + 0x65, + 0x77, + 0x94, + 0xb5, + 0xa1, + 0x0a, + 0xa9, + 0xd1, + 0x8a, + 0x39, + 0x37, + 0xf4, + 0x0b, + 0xa0, + 0xd7, + 0x82, + 0x27, + 0x5e, + 0xae, + 0x17, + 0x17, + 0xa1, + 0x1e, + 0x54, + 0x34, + 0xbf, + 0x6e, + 0xc4, + 0x8e, + 0x99, + 0x5d, + 0x08, + 0xf1, + 0x2d, + 0x86, + 0x9d, + 0xa5, + 0x20, + 0x1b, + 0xe5, + 0xdf, }; #ifndef OPENSSL_NO_DH @@ -236,19 +1353,127 @@ static const unsigned char kExampleDHPrivateKeyDER[] = { * structure. */ static const unsigned char kExampleECKeyDER[] = { - 0x30, 0x77, 0x02, 0x01, 0x01, 0x04, 0x20, 0x07, 0x0f, 0x08, - 0x72, 0x7a, 0xd4, 0xa0, 0x4a, 0x9c, 0xdd, 0x59, 0xc9, 0x4d, - 0x89, 0x68, 0x77, 0x08, 0xb5, 0x6f, 0xc9, 0x5d, 0x30, 0x77, - 0x0e, 0xe8, 0xd1, 0xc9, 0xce, 0x0a, 0x8b, 0xb4, 0x6a, 0xa0, - 0x0a, 0x06, 0x08, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x03, 0x01, - 0x07, 0xa1, 0x44, 0x03, 0x42, 0x00, 0x04, 0xe6, 0x2b, 0x69, - 0xe2, 0xbf, 0x65, 0x9f, 0x97, 0xbe, 0x2f, 0x1e, 0x0d, 0x94, - 0x8a, 0x4c, 0xd5, 0x97, 0x6b, 0xb7, 0xa9, 0x1e, 0x0d, 0x46, - 0xfb, 0xdd, 0xa9, 0xa9, 0x1e, 0x9d, 0xdc, 0xba, 0x5a, 0x01, - 0xe7, 0xd6, 0x97, 0xa8, 0x0a, 0x18, 0xf9, 0xc3, 0xc4, 0xa3, - 0x1e, 0x56, 0xe2, 0x7c, 0x83, 0x48, 0xdb, 0x16, 0x1a, 0x1c, - 0xf5, 0x1d, 0x7e, 0xf1, 0x94, 0x2d, 0x4b, 0xcf, 0x72, 0x22, - 0xc1 + 0x30, + 0x77, + 0x02, + 0x01, + 0x01, + 0x04, + 0x20, + 0x07, + 0x0f, + 0x08, + 0x72, + 0x7a, + 0xd4, + 0xa0, + 0x4a, + 0x9c, + 0xdd, + 0x59, + 0xc9, + 0x4d, + 0x89, + 0x68, + 0x77, + 0x08, + 0xb5, + 0x6f, + 0xc9, + 0x5d, + 0x30, + 0x77, + 0x0e, + 0xe8, + 0xd1, + 0xc9, + 0xce, + 0x0a, + 0x8b, + 0xb4, + 0x6a, + 0xa0, + 0x0a, + 0x06, + 0x08, + 0x2a, + 0x86, + 0x48, + 0xce, + 0x3d, + 0x03, + 0x01, + 0x07, + 0xa1, + 0x44, + 0x03, + 0x42, + 0x00, + 0x04, + 0xe6, + 0x2b, + 0x69, + 0xe2, + 0xbf, + 0x65, + 0x9f, + 0x97, + 0xbe, + 0x2f, + 0x1e, + 0x0d, + 0x94, + 0x8a, + 0x4c, + 0xd5, + 0x97, + 0x6b, + 0xb7, + 0xa9, + 0x1e, + 0x0d, + 0x46, + 0xfb, + 0xdd, + 0xa9, + 0xa9, + 0x1e, + 0x9d, + 0xdc, + 0xba, + 0x5a, + 0x01, + 0xe7, + 0xd6, + 0x97, + 0xa8, + 0x0a, + 0x18, + 0xf9, + 0xc3, + 0xc4, + 0xa3, + 0x1e, + 0x56, + 0xe2, + 0x7c, + 0x83, + 0x48, + 0xdb, + 0x16, + 0x1a, + 0x1c, + 0xf5, + 0x1d, + 0x7e, + 0xf1, + 0x94, + 0x2d, + 0x4b, + 0xcf, + 0x72, + 0x22, + 0xc1, }; /* P-384 sample EC private key in PKCS8 format (no public key) */ @@ -494,7 +1719,7 @@ static int test_new_keytype(void) unsigned char *out = NULL, *secret = NULL, *secret2 = NULL; /* without tls-provider key should not be create-able */ - if (!TEST_ptr_null(key = EVP_PKEY_Q_keygen(mainctx, NULL, "XOR"))) + if (TEST_ptr(key = EVP_PKEY_Q_keygen(mainctx, NULL, "XOR"))) goto err; /* prepare & load tls-provider */ if (!TEST_true(OSSL_PROVIDER_add_builtin(mainctx, "tls-provider", @@ -916,91 +2141,856 @@ static int do_fromdata_key_is_equal(const OSSL_PARAM params[], * -paramfile dsa_param.pem -pkeyopt type:fips186_4 -out dsa_priv.pem */ static const unsigned char dsa_key[] = { - 0x30, 0x82, 0x03, 0x4e, 0x02, 0x01, 0x00, 0x02, 0x82, 0x01, - 0x01, 0x00, 0xda, 0xb3, 0x46, 0x4d, 0x54, 0x57, 0xc7, 0xb4, - 0x61, 0xa0, 0x6f, 0x66, 0x17, 0xda, 0xeb, 0x90, 0xf0, 0xa3, - 0xd1, 0x29, 0xc9, 0x5f, 0xf2, 0x21, 0x3d, 0x85, 0xa3, 0x4a, - 0xf0, 0xf8, 0x36, 0x39, 0x1b, 0xe3, 0xee, 0x37, 0x70, 0x06, - 0x9b, 0xe8, 0xe3, 0x0a, 0xd2, 0xf1, 0xf6, 0xc4, 0x42, 0x23, - 0x1f, 0x74, 0x78, 0xc2, 0x16, 0xf5, 0xce, 0xd6, 0xab, 0xa0, - 0xc6, 0xe8, 0x99, 0x3d, 0xf8, 0x8b, 0xfb, 0x47, 0xf8, 0x5e, - 0x05, 0x68, 0x6d, 0x8b, 0xa8, 0xad, 0xa1, 0xc2, 0x3a, 0x4e, - 0xe0, 0xad, 0xec, 0x38, 0x75, 0x21, 0x55, 0x22, 0xce, 0xa2, - 0xe9, 0xe5, 0x3b, 0xd7, 0x44, 0xeb, 0x5a, 0x03, 0x59, 0xa0, - 0xc5, 0x7a, 0x92, 0x59, 0x7d, 0x7a, 0x07, 0x80, 0xfc, 0x4e, - 0xf8, 0x56, 0x7e, 0xf1, 0x06, 0xe0, 0xba, 0xb2, 0xe7, 0x5b, - 0x22, 0x55, 0xee, 0x4b, 0x42, 0x61, 0x67, 0x2c, 0x43, 0x9a, - 0x38, 0x2b, 0x17, 0xc2, 0x62, 0x12, 0x8b, 0x0b, 0x22, 0x8c, - 0x0c, 0x1c, 0x1c, 0x92, 0xb1, 0xec, 0x70, 0xce, 0x0f, 0x8c, - 0xff, 0x8d, 0x21, 0xf9, 0x19, 0x68, 0x4d, 0x32, 0x59, 0x78, - 0x42, 0x1d, 0x0c, 0xc5, 0x1a, 0xcb, 0x28, 0xe2, 0xc1, 0x1a, - 0x35, 0xf1, 0x42, 0x0a, 0x19, 0x39, 0xfa, 0x83, 0xd1, 0xb4, - 0xaa, 0x69, 0x0f, 0xc2, 0x8e, 0xf9, 0x59, 0x2c, 0xee, 0x11, - 0xfc, 0x3e, 0x4b, 0x44, 0xfb, 0x9a, 0x32, 0xc8, 0x78, 0x23, - 0x56, 0x85, 0x49, 0x21, 0x43, 0x12, 0x79, 0xbd, 0xa0, 0x70, - 0x47, 0x2f, 0xae, 0xb6, 0xd7, 0x6c, 0xc6, 0x07, 0x76, 0xa9, - 0x8a, 0xa2, 0x16, 0x02, 0x89, 0x1f, 0x1a, 0xd1, 0xa2, 0x96, - 0x56, 0xd1, 0x1f, 0x10, 0xe1, 0xe5, 0x9f, 0x3f, 0xdd, 0x09, - 0x0c, 0x40, 0x90, 0x71, 0xef, 0x14, 0x41, 0x02, 0x82, 0x3a, - 0x6b, 0xe1, 0xf8, 0x2c, 0x5d, 0xbe, 0xfd, 0x1b, 0x02, 0x1d, - 0x00, 0xe0, 0x20, 0xe0, 0x7c, 0x02, 0x16, 0xa7, 0x6c, 0x6a, - 0x19, 0xba, 0xd5, 0x83, 0x73, 0xf3, 0x7d, 0x31, 0xef, 0xa7, - 0xe1, 0x5d, 0x5b, 0x7f, 0xf3, 0xfc, 0xda, 0x84, 0x31, 0x02, - 0x82, 0x01, 0x01, 0x00, 0x83, 0xdb, 0xa1, 0xbc, 0x3e, 0xc7, - 0x29, 0xa5, 0x6a, 0x5c, 0x2c, 0xe8, 0x7a, 0x8c, 0x7e, 0xe8, - 0xb8, 0x3e, 0x13, 0x47, 0xcd, 0x36, 0x7e, 0x79, 0x30, 0x7a, - 0x28, 0x03, 0xd3, 0xd4, 0xd2, 0xe3, 0xee, 0x3b, 0x46, 0xda, - 0xe0, 0x71, 0xe6, 0xcf, 0x46, 0x86, 0x0a, 0x37, 0x57, 0xb6, - 0xe9, 0xcf, 0xa1, 0x78, 0x19, 0xb8, 0x72, 0x9f, 0x30, 0x8c, - 0x2a, 0x04, 0x7c, 0x2f, 0x0c, 0x27, 0xa7, 0xb3, 0x23, 0xe0, - 0x46, 0xf2, 0x75, 0x0c, 0x03, 0x4c, 0xad, 0xfb, 0xc1, 0xcb, - 0x28, 0xcd, 0xa0, 0x63, 0xdb, 0x44, 0x88, 0xe0, 0xda, 0x6c, - 0x5b, 0x89, 0xb2, 0x5b, 0x40, 0x6d, 0xeb, 0x78, 0x7a, 0xd5, - 0xaf, 0x40, 0x52, 0x46, 0x63, 0x92, 0x13, 0x0d, 0xee, 0xee, - 0xf9, 0x53, 0xca, 0x2d, 0x4e, 0x3b, 0x13, 0xd8, 0x0f, 0x50, - 0xd0, 0x44, 0x57, 0x67, 0x0f, 0x45, 0x8f, 0x21, 0x30, 0x97, - 0x9e, 0x80, 0xd9, 0xd0, 0x91, 0xb7, 0xc9, 0x5a, 0x69, 0xda, - 0xeb, 0xd5, 0xea, 0x37, 0xf6, 0xb3, 0xbe, 0x1f, 0x24, 0xf1, - 0x55, 0x14, 0x28, 0x05, 0xb5, 0xd8, 0x84, 0x0f, 0x62, 0x85, - 0xaa, 0xec, 0x77, 0x64, 0xfd, 0x80, 0x7c, 0x41, 0x00, 0x88, - 0xa3, 0x79, 0x7d, 0x4f, 0x6f, 0xe3, 0x76, 0xf4, 0xb5, 0x97, - 0xb7, 0xeb, 0x67, 0x28, 0xba, 0x07, 0x1a, 0x59, 0x32, 0xc1, - 0x53, 0xd9, 0x05, 0x6b, 0x63, 0x93, 0xce, 0xa1, 0xd9, 0x7a, - 0xb2, 0xff, 0x1c, 0x12, 0x0a, 0x9a, 0xe5, 0x51, 0x1e, 0xba, - 0xfc, 0x95, 0x2e, 0x28, 0xa9, 0xfc, 0x4c, 0xed, 0x7b, 0x05, - 0xca, 0x67, 0xe0, 0x2d, 0xd7, 0x54, 0xb3, 0x05, 0x1c, 0x23, - 0x2b, 0x35, 0x2e, 0x19, 0x48, 0x59, 0x0e, 0x58, 0xa8, 0x01, - 0x56, 0xfb, 0x78, 0x90, 0xba, 0x08, 0x77, 0x94, 0x45, 0x05, - 0x13, 0xc7, 0x6b, 0x96, 0xd2, 0xa3, 0xa6, 0x01, 0x9f, 0x34, - 0x02, 0x82, 0x01, 0x00, 0x16, 0x1a, 0xb4, 0x6d, 0x9f, 0x16, - 0x6c, 0xcc, 0x91, 0x66, 0xfe, 0x30, 0xeb, 0x8e, 0x44, 0xba, - 0x2b, 0x7a, 0xc9, 0xa8, 0x95, 0xf2, 0xa6, 0x38, 0xd8, 0xaf, - 0x3e, 0x91, 0x68, 0xe8, 0x52, 0xf3, 0x97, 0x37, 0x70, 0xf2, - 0x47, 0xa3, 0xf4, 0x62, 0x26, 0xf5, 0x3b, 0x71, 0x52, 0x50, - 0x15, 0x9c, 0x6d, 0xa6, 0x6d, 0x92, 0x4c, 0x48, 0x76, 0x31, - 0x54, 0x48, 0xa5, 0x99, 0x7a, 0xd4, 0x61, 0xf7, 0x21, 0x44, - 0xe7, 0xd8, 0x82, 0xc3, 0x50, 0xd3, 0xd9, 0xd4, 0x66, 0x20, - 0xab, 0x70, 0x4c, 0x97, 0x9b, 0x8d, 0xac, 0x1f, 0x78, 0x27, - 0x1e, 0x47, 0xf8, 0x3b, 0xd1, 0x55, 0x73, 0xf3, 0xb4, 0x8e, - 0x6d, 0x45, 0x40, 0x54, 0xc6, 0xd8, 0x95, 0x15, 0x27, 0xb7, - 0x5f, 0x65, 0xaa, 0xcb, 0x24, 0xc9, 0x49, 0x87, 0x32, 0xad, - 0xcb, 0xf8, 0x35, 0x63, 0x56, 0x72, 0x7c, 0x4e, 0x6c, 0xad, - 0x5f, 0x26, 0x8c, 0xd2, 0x80, 0x41, 0xaf, 0x88, 0x23, 0x20, - 0x03, 0xa4, 0xd5, 0x3c, 0x53, 0x54, 0xb0, 0x3d, 0xed, 0x0e, - 0x9e, 0x53, 0x0a, 0x63, 0x5f, 0xfd, 0x28, 0x57, 0x09, 0x07, - 0x73, 0xf4, 0x0c, 0xd4, 0x71, 0x5d, 0x6b, 0xa0, 0xd7, 0x86, - 0x99, 0x29, 0x9b, 0xca, 0xfb, 0xcc, 0xd6, 0x2f, 0xfe, 0xbe, - 0x94, 0xef, 0x1a, 0x0e, 0x55, 0x84, 0xa7, 0xaf, 0x7b, 0xfa, - 0xed, 0x77, 0x61, 0x28, 0x22, 0xee, 0x6b, 0x11, 0xdd, 0xb0, - 0x17, 0x1e, 0x06, 0xe4, 0x29, 0x4c, 0xc2, 0x3f, 0xd6, 0x75, - 0xb6, 0x08, 0x04, 0x55, 0x13, 0x48, 0x4f, 0x44, 0xea, 0x8d, - 0xaf, 0xcb, 0xac, 0x22, 0xc4, 0x6a, 0xb3, 0x86, 0xe5, 0x47, - 0xa9, 0xb5, 0x72, 0x17, 0x23, 0x11, 0x81, 0x7f, 0x00, 0x00, - 0x67, 0x5c, 0xf4, 0x58, 0xcc, 0xe2, 0x46, 0xce, 0xf5, 0x6d, - 0xd8, 0x18, 0x91, 0xc4, 0x20, 0xbf, 0x07, 0x48, 0x45, 0xfd, - 0x02, 0x1c, 0x2f, 0x68, 0x44, 0xcb, 0xfb, 0x6b, 0xcb, 0x8d, - 0x02, 0x49, 0x7c, 0xee, 0xd2, 0xa6, 0xd3, 0x43, 0xb8, 0xa4, - 0x09, 0xb7, 0xc1, 0xd4, 0x4b, 0xc3, 0x66, 0xa7, 0xe0, 0x21 + 0x30, + 0x82, + 0x03, + 0x4e, + 0x02, + 0x01, + 0x00, + 0x02, + 0x82, + 0x01, + 0x01, + 0x00, + 0xda, + 0xb3, + 0x46, + 0x4d, + 0x54, + 0x57, + 0xc7, + 0xb4, + 0x61, + 0xa0, + 0x6f, + 0x66, + 0x17, + 0xda, + 0xeb, + 0x90, + 0xf0, + 0xa3, + 0xd1, + 0x29, + 0xc9, + 0x5f, + 0xf2, + 0x21, + 0x3d, + 0x85, + 0xa3, + 0x4a, + 0xf0, + 0xf8, + 0x36, + 0x39, + 0x1b, + 0xe3, + 0xee, + 0x37, + 0x70, + 0x06, + 0x9b, + 0xe8, + 0xe3, + 0x0a, + 0xd2, + 0xf1, + 0xf6, + 0xc4, + 0x42, + 0x23, + 0x1f, + 0x74, + 0x78, + 0xc2, + 0x16, + 0xf5, + 0xce, + 0xd6, + 0xab, + 0xa0, + 0xc6, + 0xe8, + 0x99, + 0x3d, + 0xf8, + 0x8b, + 0xfb, + 0x47, + 0xf8, + 0x5e, + 0x05, + 0x68, + 0x6d, + 0x8b, + 0xa8, + 0xad, + 0xa1, + 0xc2, + 0x3a, + 0x4e, + 0xe0, + 0xad, + 0xec, + 0x38, + 0x75, + 0x21, + 0x55, + 0x22, + 0xce, + 0xa2, + 0xe9, + 0xe5, + 0x3b, + 0xd7, + 0x44, + 0xeb, + 0x5a, + 0x03, + 0x59, + 0xa0, + 0xc5, + 0x7a, + 0x92, + 0x59, + 0x7d, + 0x7a, + 0x07, + 0x80, + 0xfc, + 0x4e, + 0xf8, + 0x56, + 0x7e, + 0xf1, + 0x06, + 0xe0, + 0xba, + 0xb2, + 0xe7, + 0x5b, + 0x22, + 0x55, + 0xee, + 0x4b, + 0x42, + 0x61, + 0x67, + 0x2c, + 0x43, + 0x9a, + 0x38, + 0x2b, + 0x17, + 0xc2, + 0x62, + 0x12, + 0x8b, + 0x0b, + 0x22, + 0x8c, + 0x0c, + 0x1c, + 0x1c, + 0x92, + 0xb1, + 0xec, + 0x70, + 0xce, + 0x0f, + 0x8c, + 0xff, + 0x8d, + 0x21, + 0xf9, + 0x19, + 0x68, + 0x4d, + 0x32, + 0x59, + 0x78, + 0x42, + 0x1d, + 0x0c, + 0xc5, + 0x1a, + 0xcb, + 0x28, + 0xe2, + 0xc1, + 0x1a, + 0x35, + 0xf1, + 0x42, + 0x0a, + 0x19, + 0x39, + 0xfa, + 0x83, + 0xd1, + 0xb4, + 0xaa, + 0x69, + 0x0f, + 0xc2, + 0x8e, + 0xf9, + 0x59, + 0x2c, + 0xee, + 0x11, + 0xfc, + 0x3e, + 0x4b, + 0x44, + 0xfb, + 0x9a, + 0x32, + 0xc8, + 0x78, + 0x23, + 0x56, + 0x85, + 0x49, + 0x21, + 0x43, + 0x12, + 0x79, + 0xbd, + 0xa0, + 0x70, + 0x47, + 0x2f, + 0xae, + 0xb6, + 0xd7, + 0x6c, + 0xc6, + 0x07, + 0x76, + 0xa9, + 0x8a, + 0xa2, + 0x16, + 0x02, + 0x89, + 0x1f, + 0x1a, + 0xd1, + 0xa2, + 0x96, + 0x56, + 0xd1, + 0x1f, + 0x10, + 0xe1, + 0xe5, + 0x9f, + 0x3f, + 0xdd, + 0x09, + 0x0c, + 0x40, + 0x90, + 0x71, + 0xef, + 0x14, + 0x41, + 0x02, + 0x82, + 0x3a, + 0x6b, + 0xe1, + 0xf8, + 0x2c, + 0x5d, + 0xbe, + 0xfd, + 0x1b, + 0x02, + 0x1d, + 0x00, + 0xe0, + 0x20, + 0xe0, + 0x7c, + 0x02, + 0x16, + 0xa7, + 0x6c, + 0x6a, + 0x19, + 0xba, + 0xd5, + 0x83, + 0x73, + 0xf3, + 0x7d, + 0x31, + 0xef, + 0xa7, + 0xe1, + 0x5d, + 0x5b, + 0x7f, + 0xf3, + 0xfc, + 0xda, + 0x84, + 0x31, + 0x02, + 0x82, + 0x01, + 0x01, + 0x00, + 0x83, + 0xdb, + 0xa1, + 0xbc, + 0x3e, + 0xc7, + 0x29, + 0xa5, + 0x6a, + 0x5c, + 0x2c, + 0xe8, + 0x7a, + 0x8c, + 0x7e, + 0xe8, + 0xb8, + 0x3e, + 0x13, + 0x47, + 0xcd, + 0x36, + 0x7e, + 0x79, + 0x30, + 0x7a, + 0x28, + 0x03, + 0xd3, + 0xd4, + 0xd2, + 0xe3, + 0xee, + 0x3b, + 0x46, + 0xda, + 0xe0, + 0x71, + 0xe6, + 0xcf, + 0x46, + 0x86, + 0x0a, + 0x37, + 0x57, + 0xb6, + 0xe9, + 0xcf, + 0xa1, + 0x78, + 0x19, + 0xb8, + 0x72, + 0x9f, + 0x30, + 0x8c, + 0x2a, + 0x04, + 0x7c, + 0x2f, + 0x0c, + 0x27, + 0xa7, + 0xb3, + 0x23, + 0xe0, + 0x46, + 0xf2, + 0x75, + 0x0c, + 0x03, + 0x4c, + 0xad, + 0xfb, + 0xc1, + 0xcb, + 0x28, + 0xcd, + 0xa0, + 0x63, + 0xdb, + 0x44, + 0x88, + 0xe0, + 0xda, + 0x6c, + 0x5b, + 0x89, + 0xb2, + 0x5b, + 0x40, + 0x6d, + 0xeb, + 0x78, + 0x7a, + 0xd5, + 0xaf, + 0x40, + 0x52, + 0x46, + 0x63, + 0x92, + 0x13, + 0x0d, + 0xee, + 0xee, + 0xf9, + 0x53, + 0xca, + 0x2d, + 0x4e, + 0x3b, + 0x13, + 0xd8, + 0x0f, + 0x50, + 0xd0, + 0x44, + 0x57, + 0x67, + 0x0f, + 0x45, + 0x8f, + 0x21, + 0x30, + 0x97, + 0x9e, + 0x80, + 0xd9, + 0xd0, + 0x91, + 0xb7, + 0xc9, + 0x5a, + 0x69, + 0xda, + 0xeb, + 0xd5, + 0xea, + 0x37, + 0xf6, + 0xb3, + 0xbe, + 0x1f, + 0x24, + 0xf1, + 0x55, + 0x14, + 0x28, + 0x05, + 0xb5, + 0xd8, + 0x84, + 0x0f, + 0x62, + 0x85, + 0xaa, + 0xec, + 0x77, + 0x64, + 0xfd, + 0x80, + 0x7c, + 0x41, + 0x00, + 0x88, + 0xa3, + 0x79, + 0x7d, + 0x4f, + 0x6f, + 0xe3, + 0x76, + 0xf4, + 0xb5, + 0x97, + 0xb7, + 0xeb, + 0x67, + 0x28, + 0xba, + 0x07, + 0x1a, + 0x59, + 0x32, + 0xc1, + 0x53, + 0xd9, + 0x05, + 0x6b, + 0x63, + 0x93, + 0xce, + 0xa1, + 0xd9, + 0x7a, + 0xb2, + 0xff, + 0x1c, + 0x12, + 0x0a, + 0x9a, + 0xe5, + 0x51, + 0x1e, + 0xba, + 0xfc, + 0x95, + 0x2e, + 0x28, + 0xa9, + 0xfc, + 0x4c, + 0xed, + 0x7b, + 0x05, + 0xca, + 0x67, + 0xe0, + 0x2d, + 0xd7, + 0x54, + 0xb3, + 0x05, + 0x1c, + 0x23, + 0x2b, + 0x35, + 0x2e, + 0x19, + 0x48, + 0x59, + 0x0e, + 0x58, + 0xa8, + 0x01, + 0x56, + 0xfb, + 0x78, + 0x90, + 0xba, + 0x08, + 0x77, + 0x94, + 0x45, + 0x05, + 0x13, + 0xc7, + 0x6b, + 0x96, + 0xd2, + 0xa3, + 0xa6, + 0x01, + 0x9f, + 0x34, + 0x02, + 0x82, + 0x01, + 0x00, + 0x16, + 0x1a, + 0xb4, + 0x6d, + 0x9f, + 0x16, + 0x6c, + 0xcc, + 0x91, + 0x66, + 0xfe, + 0x30, + 0xeb, + 0x8e, + 0x44, + 0xba, + 0x2b, + 0x7a, + 0xc9, + 0xa8, + 0x95, + 0xf2, + 0xa6, + 0x38, + 0xd8, + 0xaf, + 0x3e, + 0x91, + 0x68, + 0xe8, + 0x52, + 0xf3, + 0x97, + 0x37, + 0x70, + 0xf2, + 0x47, + 0xa3, + 0xf4, + 0x62, + 0x26, + 0xf5, + 0x3b, + 0x71, + 0x52, + 0x50, + 0x15, + 0x9c, + 0x6d, + 0xa6, + 0x6d, + 0x92, + 0x4c, + 0x48, + 0x76, + 0x31, + 0x54, + 0x48, + 0xa5, + 0x99, + 0x7a, + 0xd4, + 0x61, + 0xf7, + 0x21, + 0x44, + 0xe7, + 0xd8, + 0x82, + 0xc3, + 0x50, + 0xd3, + 0xd9, + 0xd4, + 0x66, + 0x20, + 0xab, + 0x70, + 0x4c, + 0x97, + 0x9b, + 0x8d, + 0xac, + 0x1f, + 0x78, + 0x27, + 0x1e, + 0x47, + 0xf8, + 0x3b, + 0xd1, + 0x55, + 0x73, + 0xf3, + 0xb4, + 0x8e, + 0x6d, + 0x45, + 0x40, + 0x54, + 0xc6, + 0xd8, + 0x95, + 0x15, + 0x27, + 0xb7, + 0x5f, + 0x65, + 0xaa, + 0xcb, + 0x24, + 0xc9, + 0x49, + 0x87, + 0x32, + 0xad, + 0xcb, + 0xf8, + 0x35, + 0x63, + 0x56, + 0x72, + 0x7c, + 0x4e, + 0x6c, + 0xad, + 0x5f, + 0x26, + 0x8c, + 0xd2, + 0x80, + 0x41, + 0xaf, + 0x88, + 0x23, + 0x20, + 0x03, + 0xa4, + 0xd5, + 0x3c, + 0x53, + 0x54, + 0xb0, + 0x3d, + 0xed, + 0x0e, + 0x9e, + 0x53, + 0x0a, + 0x63, + 0x5f, + 0xfd, + 0x28, + 0x57, + 0x09, + 0x07, + 0x73, + 0xf4, + 0x0c, + 0xd4, + 0x71, + 0x5d, + 0x6b, + 0xa0, + 0xd7, + 0x86, + 0x99, + 0x29, + 0x9b, + 0xca, + 0xfb, + 0xcc, + 0xd6, + 0x2f, + 0xfe, + 0xbe, + 0x94, + 0xef, + 0x1a, + 0x0e, + 0x55, + 0x84, + 0xa7, + 0xaf, + 0x7b, + 0xfa, + 0xed, + 0x77, + 0x61, + 0x28, + 0x22, + 0xee, + 0x6b, + 0x11, + 0xdd, + 0xb0, + 0x17, + 0x1e, + 0x06, + 0xe4, + 0x29, + 0x4c, + 0xc2, + 0x3f, + 0xd6, + 0x75, + 0xb6, + 0x08, + 0x04, + 0x55, + 0x13, + 0x48, + 0x4f, + 0x44, + 0xea, + 0x8d, + 0xaf, + 0xcb, + 0xac, + 0x22, + 0xc4, + 0x6a, + 0xb3, + 0x86, + 0xe5, + 0x47, + 0xa9, + 0xb5, + 0x72, + 0x17, + 0x23, + 0x11, + 0x81, + 0x7f, + 0x00, + 0x00, + 0x67, + 0x5c, + 0xf4, + 0x58, + 0xcc, + 0xe2, + 0x46, + 0xce, + 0xf5, + 0x6d, + 0xd8, + 0x18, + 0x91, + 0xc4, + 0x20, + 0xbf, + 0x07, + 0x48, + 0x45, + 0xfd, + 0x02, + 0x1c, + 0x2f, + 0x68, + 0x44, + 0xcb, + 0xfb, + 0x6b, + 0xcb, + 0x8d, + 0x02, + 0x49, + 0x7c, + 0xee, + 0xd2, + 0xa6, + 0xd3, + 0x43, + 0xb8, + 0xa4, + 0x09, + 0xb7, + 0xc1, + 0xd4, + 0x4b, + 0xc3, + 0x66, + 0xa7, + 0xe0, + 0x21, }; static const unsigned char dsa_p[] = { 0x00, 0xda, 0xb3, 0x46, 0x4d, 0x54, 0x57, 0xc7, 0xb4, 0x61, 0xa0, 0x6f, 0x66, 0x17, 0xda, @@ -1439,75 +3429,6 @@ end: return ret; } -static int test_evp_md_ctx_serialize(int tstid) -{ - static const char *algs[] = { - "SHA224", "SHA256", "SHA256-192", - "SHA384", "SHA512", "SHA512-224", "SHA512-256", - "SHA3-224", "SHA3-256", "SHA3-384", "SHA3-512", - "KECCAK-KMAC-128", "KECCAK-KMAC-256" - }; - OSSL_LIB_CTX *ctx = NULL; - EVP_MD_CTX *mdctx1 = NULL, *mdctx2 = NULL; - EVP_MD *md = NULL; - unsigned char *buf = NULL; - size_t buflen; - size_t tmplen; - unsigned char d1[EVP_MAX_MD_SIZE], d2[EVP_MAX_MD_SIZE]; - unsigned int d1_len, d2_len; - int ret = 0; - const char *data1 = "some data"; - const char *data2 = "some more data"; - - if (!TEST_ptr(ctx = OSSL_LIB_CTX_new()) - || !TEST_ptr(md = EVP_MD_fetch(ctx, algs[tstid], NULL))) - goto end; - - mdctx1 = EVP_MD_CTX_new(); - mdctx2 = EVP_MD_CTX_new(); - - /* Initiate a digest with data */ - if (!TEST_ptr(mdctx2) || !TEST_ptr(mdctx1) - || !TEST_true(EVP_DigestInit_ex2(mdctx1, md, NULL)) - || !TEST_true(EVP_DigestUpdate(mdctx1, data1, strlen(data1)))) - goto end; - - /* Get required buffer size and serialize */ - if (!TEST_true(EVP_MD_CTX_serialize(mdctx1, NULL, &buflen)) - || !TEST_ptr(buf = OPENSSL_malloc(buflen)) - || !TEST_true(EVP_MD_CTX_serialize(mdctx1, buf, &buflen))) - goto end; - - /* Deserialize */ - if (!TEST_true(EVP_DigestInit_ex2(mdctx2, md, NULL)) - || !TEST_true(EVP_MD_CTX_deserialize(mdctx2, buf, buflen))) - goto end; - - /* Test that updating in parallel will now yield the same values */ - if (!TEST_true(EVP_DigestUpdate(mdctx1, data2, strlen(data2))) - || !TEST_true(EVP_DigestUpdate(mdctx2, data2, strlen(data2))) - || !TEST_true(EVP_DigestFinal_ex(mdctx1, d1, &d1_len)) - || !TEST_true(EVP_DigestFinal_ex(mdctx2, d2, &d2_len)) - || !TEST_uint_eq(d1_len, d2_len) - || !TEST_mem_eq(d1, d1_len, d2, d2_len)) - goto end; - - /* Check that serialization fails on finalized contexts */ - if (!TEST_false(EVP_MD_CTX_serialize(mdctx1, NULL, &tmplen)) - || !TEST_false(EVP_MD_CTX_deserialize(mdctx1, buf, buflen))) - goto end; - - ret = 1; - -end: - OPENSSL_free(buf); - EVP_MD_CTX_free(mdctx1); - EVP_MD_CTX_free(mdctx2); - EVP_MD_free(md); - OSSL_LIB_CTX_free(ctx); - return ret; -} - #if !defined OPENSSL_NO_DES && !defined OPENSSL_NO_MD5 static int test_evp_pbe_alg_add(void) { @@ -1603,7 +3524,6 @@ int setup_tests(void) ADD_TEST(test_evp_md_ctx_dup); ADD_TEST(test_evp_md_ctx_copy); ADD_TEST(test_evp_md_ctx_copy2); - ADD_ALL_TESTS(test_evp_md_ctx_serialize, 13); ADD_ALL_TESTS(test_provider_unload_effective, 2); #if !defined OPENSSL_NO_DES && !defined OPENSSL_NO_MD5 ADD_TEST(test_evp_pbe_alg_add); diff --git a/test/evp_fetch_prov_test.c b/test/evp_fetch_prov_test.c index bcc7c59eb6..78116e0a32 100644 --- a/test/evp_fetch_prov_test.c +++ b/test/evp_fetch_prov_test.c @@ -17,10 +17,13 @@ #include #include #include +#include +#include #include #include "internal/sizes.h" #include "testutil.h" -#include "fake_cipherprov.h" +#include "crypto/evp.h" +#include "../crypto/evp/evp_local.h" static char *config_file = NULL; static char *alg = "digest"; @@ -220,6 +223,81 @@ err: return ret; } +static int test_EVP_MD_fetch_freeze(void) +{ +#if defined(OPENSSL_NO_CACHED_FETCH) + /* + * Test does not make sense if cached fetch is disabled. + * There's nothing to freeze, and test will fail. + */ + return 1; +#endif + + EVP_MD *md = NULL; + int ret = 0; + OSSL_LIB_CTX *ctx = NULL; + OSSL_LIB_CTX *ctx2 = OSSL_LIB_CTX_new(); + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + if (!TEST_ptr(ctx2) + || !TEST_ptr(md = EVP_MD_fetch(ctx, "SHA256", NULL)) + || !TEST_true(test_md(md)) + || !TEST_int_ne(md->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_MD_free(md); + md = NULL; + + if (!TEST_int_eq(OSSL_LIB_CTX_freeze(ctx, "?fips=true"), 1) + || !TEST_ptr(md = EVP_MD_fetch(ctx, "SHA256", NULL)) + || !TEST_true(test_md(md)) + || !TEST_int_eq(md->origin, EVP_ORIG_FROZEN) + || !TEST_ptr(md = EVP_MD_fetch(ctx, "SHA-256", NULL)) + || !TEST_true(test_md(md)) + || !TEST_int_eq(md->origin, EVP_ORIG_FROZEN) + || !TEST_ptr(md = EVP_MD_fetch(ctx, "2.16.840.1.101.3.4.2.1", NULL)) + || !TEST_true(test_md(md)) + || !TEST_int_eq(md->origin, EVP_ORIG_FROZEN)) + goto err; + /* Technically, frozen version doesn't need to be freed */ + EVP_MD_free(md); + + if (!TEST_ptr(md = EVP_MD_fetch(ctx, "SHA256", "?fips=true")) + || !TEST_true(test_md(md)) + || !TEST_int_eq(md->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_MD_free(md); + + /* Falls back to slow path */ + if (!TEST_ptr(md = EVP_MD_fetch(ctx, "SHA256", "?provider=default")) + || !TEST_true(test_md(md)) + || !TEST_int_ne(md->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_MD_free(md); + + if (!TEST_ptr(md = EVP_MD_fetch(ctx, "SHA1", NULL)) + || !TEST_int_eq(md->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_MD_free(md); + + if (!TEST_ptr(md = EVP_MD_fetch(ctx2, "SHA1", "?fips=true")) + || !TEST_int_ne(md->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_MD_free(md); + if (!TEST_ptr(md = EVP_MD_fetch(ctx2, "SHA1", NULL)) + || !TEST_int_ne(md->origin, EVP_ORIG_FROZEN)) + goto err; + + ret = 1; +err: + unload_providers(&ctx, prov); + OSSL_LIB_CTX_free(ctx2); + EVP_MD_free(md); + return ret; +} + static int test_explicit_EVP_MD_fetch_by_name(void) { return test_explicit_EVP_MD_fetch("SHA256"); @@ -257,6 +335,312 @@ end: return ret; } +static int calculate_mac(const EVP_MAC *mac, const unsigned char *msg, size_t len, + const unsigned char *expected, size_t expected_len) +{ + unsigned char out[EVP_MAX_MD_SIZE]; + const unsigned char key[] = "0123456789abcd"; + EVP_MAC_CTX *ctx = NULL; + OSSL_PARAM params[2], *p = params; + size_t out_len = 0; + int ret = 0; + + *p++ = OSSL_PARAM_construct_utf8_string(OSSL_MAC_PARAM_DIGEST, "SHA256", 0); + *p = OSSL_PARAM_construct_end(); + + if (!TEST_ptr(ctx = EVP_MAC_CTX_new((EVP_MAC *)mac)) + || !TEST_true(EVP_MAC_init(ctx, key, sizeof(key) - 1, params)) + || !TEST_true(EVP_MAC_update(ctx, msg, len)) + || !TEST_true(EVP_MAC_final(ctx, out, &out_len, sizeof(out))) + || !TEST_size_t_eq(out_len, expected_len) + || !TEST_mem_eq(out, out_len, expected, expected_len)) + goto err; + + ret = 1; +err: + EVP_MAC_CTX_free(ctx); + return ret; +} + +static int test_mac(const EVP_MAC *mac) +{ + const unsigned char testmsg[] = "Hello world"; + const unsigned char expected[] = { + 0xf2, 0x71, 0x5a, 0xad, 0x1d, 0x68, 0x3c, 0xdd, + 0xbc, 0xa7, 0x5a, 0x1e, 0x79, 0xed, 0xac, 0x57, + 0xf6, 0xb0, 0xd4, 0xbb, 0x15, 0xe1, 0x7f, 0x6b, + 0x47, 0x62, 0x58, 0xb1, 0xbc, 0x0d, 0xf4, 0x4f + }; + + return TEST_ptr(mac) + && TEST_true(EVP_MAC_is_a(mac, "HMAC")) + && TEST_true(calculate_mac(mac, testmsg, sizeof(testmsg) - 1, + expected, sizeof(expected))); +} + +static int test_EVP_MAC_fetch_freeze(void) +{ +#if defined(OPENSSL_NO_CACHED_FETCH) + /* + * Test does not make sense if cached fetch is disabled. + * There's nothing to freeze, and test will fail. + */ + return 1; +#endif + + EVP_MAC *mac = NULL; + int ret = 0; + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + if (!TEST_ptr(mac = EVP_MAC_fetch(ctx, "HMAC", NULL)) + || !TEST_true(test_mac(mac)) + || !TEST_int_ne(mac->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_MAC_free(mac); + mac = NULL; + + if (!TEST_int_eq(OSSL_LIB_CTX_freeze(ctx, "?fips=true"), 1) + || !TEST_ptr(mac = EVP_MAC_fetch(ctx, "HMAC", NULL)) + || !TEST_true(test_mac(mac)) + || !TEST_int_eq(mac->origin, EVP_ORIG_FROZEN)) + goto err; + /* Technically, frozen version doesn't need to be freed */ + EVP_MAC_free(mac); + mac = NULL; + + if (!TEST_ptr(mac = EVP_MAC_fetch(ctx, "HMAC", "?fips=true")) + || !TEST_true(test_mac(mac)) + || !TEST_int_eq(mac->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_MAC_free(mac); + mac = NULL; + + /* Falls back to slow path */ + if (!TEST_ptr(mac = EVP_MAC_fetch(ctx, "HMAC", "?provider=default")) + || !TEST_true(test_mac(mac)) + || !TEST_int_ne(mac->origin, EVP_ORIG_FROZEN)) + goto err; + + ret = 1; +err: + EVP_MAC_free(mac); + unload_providers(&ctx, prov); + return ret; +} + +static int test_implicit_EVP_MAC_fetch(void) +{ + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + EVP_MAC *mac = NULL; + int ret = 0; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + if (!TEST_ptr(mac = EVP_MAC_fetch(ctx, "HMAC", NULL)) + || !TEST_true(test_mac(mac))) + goto err; + ret = 1; +err: + EVP_MAC_free(mac); + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_MAC_fetch(const char *id) +{ + OSSL_LIB_CTX *ctx = NULL; + EVP_MAC *mac = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + int ret = 0; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + mac = EVP_MAC_fetch(ctx, id, fetch_property); + if (expected_fetch_result != 0) { + if (!test_mac(mac)) + goto err; + + if (!TEST_true(EVP_MAC_up_ref(mac))) + goto err; + /* Ref count should now be 2. Release first one here */ + EVP_MAC_free(mac); + } else { + if (!TEST_ptr_null(mac)) + goto err; + } + ret = 1; +err: + EVP_MAC_free(mac); + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_MAC_fetch_by_name(void) +{ + return test_explicit_EVP_MAC_fetch("HMAC"); +} + +static int derive_pbkdf2(EVP_KDF *kdf) +{ + int ret = 0; + EVP_KDF_CTX *ctx = NULL; + unsigned char out[25]; + static const unsigned char password[] = "passwordPASSWORDpassword"; + static const unsigned char salt[] = "saltSALTsaltSALTsaltSALTsaltSALTsalt"; + unsigned int iterations = 4096; + int mode = 0; + OSSL_PARAM params[6], *p = params; + static const unsigned char expected[sizeof(out)] = { + 0x34, 0x8c, 0x89, 0xdb, 0xcb, 0xd3, 0x2b, 0x2f, + 0x32, 0xd8, 0x14, 0xb8, 0x11, 0x6e, 0x84, 0xcf, + 0x2b, 0x17, 0x34, 0x7e, 0xbc, 0x18, 0x00, 0x18, + 0x1c + }; + + *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_PASSWORD, + (void *)password, + sizeof(password) - 1); + *p++ = OSSL_PARAM_construct_octet_string(OSSL_KDF_PARAM_SALT, + (void *)salt, sizeof(salt) - 1); + *p++ = OSSL_PARAM_construct_uint(OSSL_KDF_PARAM_ITER, &iterations); + *p++ = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_DIGEST, "sha256", 0); + *p++ = OSSL_PARAM_construct_int(OSSL_KDF_PARAM_PKCS5, &mode); + *p = OSSL_PARAM_construct_end(); + + if (!TEST_ptr(ctx = EVP_KDF_CTX_new(kdf)) + || !TEST_int_gt(EVP_KDF_derive(ctx, out, sizeof(out), params), 0) + || !TEST_mem_eq(out, sizeof(out), expected, sizeof(expected))) + goto err; + ret = 1; +err: + EVP_KDF_CTX_free(ctx); + return ret; +} + +static int test_kdf(EVP_KDF *kdf, const char *name) +{ + return TEST_ptr(kdf) + && TEST_ptr(EVP_KDF_get0_provider(kdf)) + && TEST_true(EVP_KDF_is_a(kdf, name)) + && TEST_true(derive_pbkdf2(kdf)); +} + +static int test_implicit_EVP_KDF_fetch(void) +{ + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + EVP_KDF *kdf = NULL; + int ret = 0; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + if (!TEST_ptr(kdf = EVP_KDF_fetch(ctx, OSSL_KDF_NAME_PBKDF2, NULL)) + || !TEST_true(test_kdf(kdf, OSSL_KDF_NAME_PBKDF2))) + goto err; + ret = 1; +err: + EVP_KDF_free(kdf); + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_KDF_fetch(const char *id) +{ + OSSL_LIB_CTX *ctx = NULL; + EVP_KDF *kdf = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + int ret = 0; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + kdf = EVP_KDF_fetch(ctx, id, fetch_property); + if (expected_fetch_result != 0) { + if (!test_kdf(kdf, id)) + goto err; + + if (!TEST_true(EVP_KDF_up_ref(kdf))) + goto err; + /* Ref count should now be 2. Release first one here */ + EVP_KDF_free(kdf); + } else { + if (!TEST_ptr_null(kdf)) + goto err; + } + ret = 1; +err: + EVP_KDF_free(kdf); + unload_providers(&ctx, prov); + return ret; +} + +static int test_EVP_KDF_fetch_freeze(void) +{ +#if defined(OPENSSL_NO_CACHED_FETCH) + /* + * Test does not make sense if cached fetch is disabled. + * There's nothing to freeze, and test will fail. + */ + return 1; +#endif + + EVP_KDF *kdf = NULL; + int ret = 0; + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + if (!TEST_ptr(kdf = EVP_KDF_fetch(ctx, "PBKDF2", NULL)) + || !TEST_true(test_kdf(kdf, "PBKDF2")) + || !TEST_int_ne(kdf->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_KDF_free(kdf); + kdf = NULL; + + if (!TEST_int_eq(OSSL_LIB_CTX_freeze(ctx, "?fips=true"), 1) + || !TEST_ptr(kdf = EVP_KDF_fetch(ctx, "PBKDF2", NULL)) + || !TEST_true(test_kdf(kdf, "PBKDF2")) + || !TEST_int_eq(kdf->origin, EVP_ORIG_FROZEN)) + goto err; + /* Technically, frozen version doesn't need to be freed */ + EVP_KDF_free(kdf); + kdf = NULL; + + if (!TEST_ptr(kdf = EVP_KDF_fetch(ctx, "PBKDF2", "?fips=true")) + || !TEST_true(test_kdf(kdf, "PBKDF2")) + || !TEST_int_eq(kdf->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_KDF_free(kdf); + kdf = NULL; + + /* Falls back to slow path */ + if (!TEST_ptr(kdf = EVP_KDF_fetch(ctx, "PBKDF2", "?provider=default")) + || !TEST_true(test_kdf(kdf, "PBKDF2")) + || !TEST_int_ne(kdf->origin, EVP_ORIG_FROZEN)) + goto err; + + ret = 1; +err: + EVP_KDF_free(kdf); + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_KDF_fetch_by_name(void) +{ + return test_explicit_EVP_KDF_fetch("PBKDF2"); +} + /* * Test EVP_CIPHER_fetch() */ @@ -293,6 +677,539 @@ static int test_cipher(const EVP_CIPHER *cipher) && TEST_true(encrypt_decrypt(cipher, testmsg, sizeof(testmsg))); } +static int test_ec_keyexch(OSSL_LIB_CTX *libctx, const char *propq) +{ + EVP_PKEY_CTX *gctx1 = NULL, *gctx2 = NULL, *dctx = NULL; + EVP_PKEY *key1 = NULL, *key2 = NULL; + unsigned char secret1[256], secret2[256]; + size_t secret1_len = 0, secret2_len = 0; + OSSL_PARAM params[2]; + int ret = 0; + + params[0] = OSSL_PARAM_construct_utf8_string(OSSL_PKEY_PARAM_GROUP_NAME, + "prime256v1", 0); + params[1] = OSSL_PARAM_construct_end(); + + if (!TEST_ptr(gctx1 = EVP_PKEY_CTX_new_from_name(libctx, "EC", propq)) + || !TEST_true(EVP_PKEY_keygen_init(gctx1)) + || !TEST_true(EVP_PKEY_CTX_set_params(gctx1, params)) + || !TEST_true(EVP_PKEY_keygen(gctx1, &key1)) + || !TEST_ptr(gctx2 = EVP_PKEY_CTX_new_from_name(libctx, "EC", propq)) + || !TEST_true(EVP_PKEY_keygen_init(gctx2)) + || !TEST_true(EVP_PKEY_CTX_set_params(gctx2, params)) + || !TEST_true(EVP_PKEY_keygen(gctx2, &key2)) + || !TEST_ptr(dctx = EVP_PKEY_CTX_new_from_pkey(libctx, key1, propq)) + || !TEST_true(EVP_PKEY_derive_init(dctx)) + || !TEST_true(EVP_PKEY_derive_set_peer(dctx, key2)) + || !TEST_true(EVP_PKEY_derive(dctx, NULL, &secret1_len)) + || !TEST_size_t_le(secret1_len, sizeof(secret1)) + || !TEST_true(EVP_PKEY_derive(dctx, secret1, &secret1_len))) + goto end; + + EVP_PKEY_CTX_free(dctx); + dctx = NULL; + + if (!TEST_ptr(dctx = EVP_PKEY_CTX_new_from_pkey(libctx, key2, propq)) + || !TEST_true(EVP_PKEY_derive_init(dctx)) + || !TEST_true(EVP_PKEY_derive_set_peer(dctx, key1)) + || !TEST_true(EVP_PKEY_derive(dctx, NULL, &secret2_len)) + || !TEST_size_t_le(secret2_len, sizeof(secret2)) + || !TEST_true(EVP_PKEY_derive(dctx, secret2, &secret2_len)) + || !TEST_size_t_eq(secret1_len, secret2_len) + || !TEST_mem_eq(secret1, secret1_len, secret2, secret2_len)) + goto end; + + ret = 1; +end: + EVP_PKEY_CTX_free(dctx); + EVP_PKEY_CTX_free(gctx1); + EVP_PKEY_CTX_free(gctx2); + EVP_PKEY_free(key1); + EVP_PKEY_free(key2); + return ret; +} + +static int test_keymgmt(OSSL_LIB_CTX *libctx, const char *propq, + const EVP_KEYMGMT *keymgmt, const char *name) +{ + return TEST_ptr(keymgmt) + && TEST_ptr(EVP_KEYMGMT_get0_provider(keymgmt)) + && TEST_true(EVP_KEYMGMT_is_a(keymgmt, name)) + && test_ec_keyexch(libctx, propq); +} + +static int test_ml_kem_keyexch(OSSL_LIB_CTX *libctx, const char *propq) +{ + int ret = 0; + EVP_PKEY *privkey = NULL; + EVP_PKEY_CTX *pctx = NULL; + unsigned char *ciphertext = NULL, *secret_enc = NULL, *secret_dec = NULL; + size_t ciphertext_len = 0, secret_enc_len = 0, secret_dec_len = 0; + + if (!TEST_ptr(privkey = EVP_PKEY_Q_keygen(libctx, propq, "ML-KEM-768")) + || !TEST_ptr(pctx = EVP_PKEY_CTX_new_from_pkey(libctx, privkey, propq)) + || !TEST_int_eq(EVP_PKEY_encapsulate_init(pctx, NULL), 1) + || !TEST_int_eq(EVP_PKEY_encapsulate(pctx, NULL, &ciphertext_len, NULL, &secret_enc_len), 1)) + goto err; + + ciphertext = OPENSSL_zalloc(ciphertext_len); + secret_enc = OPENSSL_zalloc(secret_enc_len); + if (!TEST_ptr(ciphertext) + || !TEST_ptr(secret_enc) + || !TEST_int_gt(EVP_PKEY_encapsulate(pctx, ciphertext, &ciphertext_len, + secret_enc, &secret_enc_len), + 0)) + goto err; + + EVP_PKEY_CTX_free(pctx); + pctx = NULL; + + if (!TEST_ptr(pctx = EVP_PKEY_CTX_new_from_pkey(libctx, privkey, propq)) + || !TEST_int_eq(EVP_PKEY_decapsulate_init(pctx, NULL), 1) + || !TEST_int_eq(EVP_PKEY_decapsulate(pctx, NULL, &secret_dec_len, ciphertext, ciphertext_len), 1) + || !TEST_size_t_eq(secret_dec_len, secret_enc_len)) + goto err; + + secret_dec = OPENSSL_zalloc(secret_dec_len); + if (!TEST_ptr(secret_dec) + || !TEST_int_gt(EVP_PKEY_decapsulate(pctx, secret_dec, &secret_dec_len, + ciphertext, ciphertext_len), + 0) + || !TEST_size_t_eq(secret_dec_len, secret_enc_len) + || !TEST_mem_eq(secret_dec, secret_dec_len, secret_enc, secret_enc_len)) + goto err; + ret = 1; +err: + EVP_PKEY_free(privkey); + OPENSSL_free(ciphertext); + OPENSSL_free(secret_enc); + OPENSSL_free(secret_dec); + EVP_PKEY_CTX_free(pctx); + + return ret; +} + +static int test_kem(OSSL_LIB_CTX *libctx, const char *propq, + const EVP_KEM *kem, const char *name) +{ + return TEST_ptr(kem) + && TEST_ptr(EVP_KEM_get0_provider(kem)) + && TEST_true(EVP_KEM_is_a(kem, name)) + && test_ml_kem_keyexch(libctx, propq); +} + +static int test_rsa_enc_dec(OSSL_LIB_CTX *libctx, const char *propq) +{ + EVP_PKEY_CTX *ctx = NULL; + EVP_PKEY *pkey = NULL; + unsigned char plaintext[] = "Hello world"; + unsigned char *ciphertext = NULL, *decrypted = NULL; + size_t ciphertext_len, decrypted_len; + int ret = 0; + + /* Encrypt */ + if (!TEST_ptr(pkey = EVP_PKEY_Q_keygen(libctx, propq, "RSA", 4096)) + || !TEST_ptr(ctx = EVP_PKEY_CTX_new_from_pkey(libctx, pkey, propq)) + || !TEST_int_eq(EVP_PKEY_encrypt_init(ctx), 1) + || !TEST_int_eq(EVP_PKEY_CTX_set_rsa_padding(ctx, RSA_PKCS1_OAEP_PADDING), 1) + || !TEST_int_eq(EVP_PKEY_encrypt(ctx, NULL, &ciphertext_len, + plaintext, sizeof(plaintext)), + 1) + || !TEST_ptr(ciphertext = OPENSSL_malloc(ciphertext_len)) + || !TEST_int_eq(EVP_PKEY_encrypt(ctx, ciphertext, &ciphertext_len, + plaintext, sizeof(plaintext)), + 1)) + goto err; + + /* Decrypt */ + if (!TEST_int_eq(EVP_PKEY_decrypt_init(ctx), 1) + || !TEST_int_eq(EVP_PKEY_CTX_set_rsa_padding(ctx, RSA_PKCS1_OAEP_PADDING), 1) + || !TEST_int_eq(EVP_PKEY_decrypt(ctx, NULL, &decrypted_len, ciphertext, + ciphertext_len), + 1) + || !TEST_ptr(decrypted = OPENSSL_malloc(decrypted_len)) + || !TEST_int_eq(EVP_PKEY_decrypt(ctx, decrypted, &decrypted_len, + ciphertext, ciphertext_len), + 1) + || !TEST_int_eq(strcasecmp((const char *)plaintext, (const char *)decrypted), 0)) + goto err; + + ret = 1; +err: + EVP_PKEY_CTX_free(ctx); + EVP_PKEY_free(pkey); + OPENSSL_free(ciphertext); + OPENSSL_free(decrypted); + + return ret; +} + +static int test_asym_cipher(EVP_ASYM_CIPHER *cipher, const char *name, + OSSL_LIB_CTX *ctx, const char *propq) +{ + return TEST_ptr(cipher) + && TEST_ptr(EVP_ASYM_CIPHER_get0_provider(cipher)) + && TEST_true(EVP_ASYM_CIPHER_is_a(cipher, name)) + && TEST_true(test_rsa_enc_dec(ctx, propq)); +} + +static int test_EVP_KEYMGMT_fetch_freeze(void) +{ +#if defined(OPENSSL_NO_CACHED_FETCH) || defined(OPENSSL_NO_EC) + /* + * Test does not make sense if cached fetch is disabled. + * There's nothing to freeze, and test will fail. + */ + return 1; +#endif + + EVP_KEYMGMT *keymgmt = NULL; + int ret = 0; + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + if (!TEST_ptr(keymgmt = EVP_KEYMGMT_fetch(ctx, "EC", NULL)) + || !TEST_true(test_keymgmt(ctx, NULL, keymgmt, "EC")) + || !TEST_int_ne(keymgmt->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_KEYMGMT_free(keymgmt); + keymgmt = NULL; + + if (!TEST_int_eq(OSSL_LIB_CTX_freeze(ctx, "?fips=true"), 1) + || !TEST_ptr(keymgmt = EVP_KEYMGMT_fetch(ctx, "EC", NULL)) + || !TEST_true(test_keymgmt(ctx, NULL, keymgmt, "EC")) + || !TEST_int_eq(keymgmt->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_KEYMGMT_free(keymgmt); + keymgmt = NULL; + + if (!TEST_ptr(keymgmt = EVP_KEYMGMT_fetch(ctx, "EC", "?fips=true")) + || !TEST_true(test_keymgmt(ctx, "?fips=true", keymgmt, "EC")) + || !TEST_int_eq(keymgmt->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_KEYMGMT_free(keymgmt); + keymgmt = NULL; + + if (!TEST_ptr(keymgmt = EVP_KEYMGMT_fetch(ctx, "RSA", "?fips=true")) + || !TEST_int_eq(keymgmt->origin, EVP_ORIG_FROZEN)) + goto err; + if (!TEST_ptr(keymgmt = EVP_KEYMGMT_fetch(ctx, "RSA", NULL)) + || !TEST_int_eq(keymgmt->origin, EVP_ORIG_FROZEN)) + goto err; + + /* + * A mismatched propq should use the regular fetch path rather than the + * frozen fast path. + */ + if (!TEST_ptr(keymgmt = EVP_KEYMGMT_fetch(ctx, "EC", "?provider=default")) + || !TEST_true(test_keymgmt(ctx, "?provider=default", keymgmt, "EC")) + || !TEST_int_ne(keymgmt->origin, EVP_ORIG_FROZEN)) + goto err; + + ret = 1; +err: + EVP_KEYMGMT_free(keymgmt); + unload_providers(&ctx, prov); + return ret; +} + +static int test_implicit_EVP_KEYMGMT_fetch(void) +{ +#if defined(OPENSSL_NO_EC) + return 1; +#endif + + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + int ret = 0; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + ret = test_ec_keyexch(ctx, NULL); +err: + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_KEYMGMT_fetch(const char *id) +{ +#if defined(OPENSSL_NO_EC) + return 1; +#endif + + OSSL_LIB_CTX *ctx = NULL; + EVP_KEYMGMT *keymgmt = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + int ret = 0; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + keymgmt = EVP_KEYMGMT_fetch(ctx, id, fetch_property); + if (expected_fetch_result != 0) { + if (!test_keymgmt(ctx, fetch_property, keymgmt, id)) + goto err; + + if (!TEST_true(EVP_KEYMGMT_up_ref(keymgmt))) + goto err; + /* Ref count should now be 2. Release first one here */ + EVP_KEYMGMT_free(keymgmt); + } else { + if (!TEST_ptr_null(keymgmt)) + goto err; + } + ret = 1; +err: + EVP_KEYMGMT_free(keymgmt); + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_KEYMGMT_fetch_by_name(void) +{ + return test_explicit_EVP_KEYMGMT_fetch("EC"); +} + +static int test_explicit_EVP_KEYMGMT_fetch_by_X509_ALGOR(int idx) +{ +#if defined(OPENSSL_NO_EC) + return 1; +#endif + + int ret = 0; + X509_ALGOR *algor = make_algor(NID_X9_62_id_ecPublicKey); + const ASN1_OBJECT *obj; + char id[OSSL_MAX_NAME_SIZE] = { 0 }; + + if (algor == NULL) + return 0; + + X509_ALGOR_get0(&obj, NULL, NULL, algor); + switch (idx) { + case 0: + if (!TEST_int_gt(OBJ_obj2txt(id, sizeof(id), obj, 0), 0)) + goto end; + break; + case 1: + if (!TEST_int_gt(OBJ_obj2txt(id, sizeof(id), obj, 1), 0)) + goto end; + break; + } + + ret = test_explicit_EVP_KEYMGMT_fetch(id); +end: + X509_ALGOR_free(algor); + return ret; +} + +static int test_EVP_KEM_fetch_freeze(void) +{ +#if defined(OPENSSL_NO_CACHED_FETCH) || defined(OPENSSL_NO_ML_KEM) + /* + * Test does not make sense if cached fetch is disabled. + * There's nothing to freeze, and test will fail. + */ + return 1; +#endif + + EVP_KEM *kem = NULL; + int ret = 0; + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + if (!TEST_ptr(kem = EVP_KEM_fetch(ctx, "ML-KEM-768", NULL)) + || !TEST_true(test_kem(ctx, NULL, kem, "ML-KEM-768")) + || !TEST_int_ne(kem->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_KEM_free(kem); + kem = NULL; + + if (!TEST_int_eq(OSSL_LIB_CTX_freeze(ctx, "?fips=true"), 1) + || !TEST_ptr(kem = EVP_KEM_fetch(ctx, "ML-KEM-768", NULL)) + || !TEST_true(test_kem(ctx, NULL, kem, "ML-KEM-768")) + || !TEST_int_eq(kem->origin, EVP_ORIG_FROZEN)) + goto err; + /* Technically, frozen version doesn't need to be freed */ + EVP_KEM_free(kem); + kem = NULL; + + if (!TEST_ptr(kem = EVP_KEM_fetch(ctx, "ML-KEM-768", "?fips=true")) + || !TEST_true(test_kem(ctx, "?fips=true", kem, "ML-KEM-768")) + || !TEST_int_eq(kem->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_KEM_free(kem); + kem = NULL; + + /* + * A mismatched propq should use the regular fetch path rather than the + * frozen fast path. + */ + if (!TEST_ptr(kem = EVP_KEM_fetch(ctx, "ML-KEM-768", "?provider=default")) + || !TEST_true(test_kem(ctx, "?provider=default", kem, "ML-KEM-768")) + || !TEST_int_ne(kem->origin, EVP_ORIG_FROZEN)) + goto err; + + ret = 1; +err: + EVP_KEM_free(kem); + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_KEM_fetch(const char *id) +{ +#if defined(OPENSSL_NO_ML_KEM) + return 1; +#endif + + OSSL_LIB_CTX *ctx = NULL; + EVP_KEM *kem = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + int ret = 0; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + kem = EVP_KEM_fetch(ctx, id, fetch_property); + if (expected_fetch_result != 0) { + if (!test_kem(ctx, fetch_property, kem, id)) + goto err; + + if (!TEST_true(EVP_KEM_up_ref(kem))) + goto err; + /* Ref count should now be 2. Release first one here */ + EVP_KEM_free(kem); + } else { + if (!TEST_ptr_null(kem)) + goto err; + } + ret = 1; +err: + EVP_KEM_free(kem); + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_KEM_fetch_by_name(void) +{ +#if defined(OPENSSL_NO_ML_KEM) + return 1; +#endif + + return test_explicit_EVP_KEM_fetch("ML-KEM-768"); +} + +/* + * idx 0: Allow names from OBJ_obj2txt() + * idx 1: Force an OID in text form from OBJ_obj2txt() + */ +static int test_explicit_EVP_KEM_fetch_by_X509_ALGOR(int idx) +{ +#if defined(OPENSSL_NO_ML_KEM) + return 1; +#endif + + int ret = 0; + X509_ALGOR *algor = make_algor(NID_ML_KEM_768); + const ASN1_OBJECT *obj; + char id[OSSL_MAX_NAME_SIZE] = { 0 }; + + if (algor == NULL) + return 0; + + X509_ALGOR_get0(&obj, NULL, NULL, algor); + switch (idx) { + case 0: + if (!TEST_int_gt(OBJ_obj2txt(id, sizeof(id), obj, 0), 0)) + goto end; + break; + case 1: + if (!TEST_int_gt(OBJ_obj2txt(id, sizeof(id), obj, 1), 0)) + goto end; + break; + } + + ret = test_explicit_EVP_KEM_fetch(id); +end: + X509_ALGOR_free(algor); + return ret; +} + +static int test_EVP_CIPHER_fetch_freeze(void) +{ +#if defined(OPENSSL_NO_CACHED_FETCH) + /* + * Test does not make sense if cached fetch is disabled. + * There's nothing to freeze, and test will fail. + */ + return 1; +#endif + + EVP_CIPHER *cipher = NULL; + int ret = 0; + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + if (!TEST_ptr(cipher = EVP_CIPHER_fetch(ctx, "AES-128-CBC", NULL)) + || !TEST_true(test_cipher(cipher)) + || !TEST_int_ne(cipher->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_CIPHER_free(cipher); + + if (!TEST_ptr(cipher = EVP_CIPHER_fetch(ctx, "AES-128-CBC", "?provider=default")) + || !TEST_true(test_cipher(cipher)) + || !TEST_int_ne(cipher->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_CIPHER_free(cipher); + cipher = NULL; + + if (!TEST_int_eq(OSSL_LIB_CTX_freeze(ctx, "?fips=true"), 1) + || !TEST_ptr(cipher = EVP_CIPHER_fetch(ctx, "AES-128-CBC", NULL)) + || !TEST_true(test_cipher(cipher)) + || !TEST_int_eq(cipher->origin, EVP_ORIG_FROZEN)) + goto err; + /* Technically, frozen version doesn't need to be freed */ + EVP_CIPHER_free(cipher); + + if (!TEST_ptr(cipher = EVP_CIPHER_fetch(ctx, "AES-128-CBC", "?fips=true")) + || !TEST_true(test_cipher(cipher)) + || !TEST_int_eq(cipher->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_CIPHER_free(cipher); + + if (!TEST_ptr(cipher = EVP_CIPHER_fetch(ctx, "AES-128-CBC", "?provider=default")) + || !TEST_true(test_cipher(cipher)) + || !TEST_int_ne(cipher->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_CIPHER_free(cipher); + + if (!TEST_ptr(cipher = EVP_CIPHER_fetch(ctx, "AES-128-ECB", "?fips=true")) + || !TEST_true(test_cipher(cipher)) + || !TEST_int_eq(cipher->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_CIPHER_free(cipher); + if (!TEST_ptr(cipher = EVP_CIPHER_fetch(ctx, "AES-128-ECB", NULL)) + || !TEST_true(test_cipher(cipher)) + || !TEST_int_eq(cipher->origin, EVP_ORIG_FROZEN)) + goto err; + + ret = 1; +err: + EVP_CIPHER_free(cipher); + unload_providers(&ctx, prov); + return ret; +} + static int test_implicit_EVP_CIPHER_fetch(void) { OSSL_LIB_CTX *ctx = NULL; @@ -341,36 +1258,6 @@ static int test_explicit_EVP_CIPHER_fetch_by_name(void) return test_explicit_EVP_CIPHER_fetch("AES-128-CBC"); } -/* - * Test that a provider cipher without get_params fails to fetch. - */ -static int test_cipher_no_getparams(void) -{ - int ret = 0; - OSSL_LIB_CTX *ctx = NULL; - OSSL_PROVIDER *fake_prov = NULL; - EVP_CIPHER *cipher = NULL; - - ctx = OSSL_LIB_CTX_new(); - if (!TEST_ptr(ctx)) - return 0; - - if (!TEST_ptr(fake_prov = fake_cipher_start(ctx))) - goto end; - - /* Fetch must fail for a cipher that has no get_params */ - cipher = EVP_CIPHER_fetch(ctx, FAKE_CIPHER_NO_GETPARAMS, FAKE_CIPHER_FETCH_PROPS); - if (!TEST_ptr_null(cipher)) - goto end; - - ret = 1; -end: - EVP_CIPHER_free(cipher); - fake_cipher_finish(fake_prov); - OSSL_LIB_CTX_free(ctx); - return ret; -} - /* * idx 0: Allow names from OBJ_obj2txt() * idx 1: Force an OID in text form from OBJ_obj2txt() @@ -403,6 +1290,541 @@ end: return ret; } +static int test_EVP_RAND_fetch_freeze(void) +{ +#if defined(OPENSSL_NO_CACHED_FETCH) + /* + * Test does not make sense if cached fetch is disabled. + * There's nothing to freeze, and test will fail. + */ + return 1; +#endif + + EVP_RAND *rand = NULL; + int ret = 0; + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + if (!TEST_ptr(rand = EVP_RAND_fetch(ctx, "HASH-DRBG", NULL)) + || !TEST_int_ne(rand->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_RAND_free(rand); + rand = NULL; + + if (!TEST_int_eq(OSSL_LIB_CTX_freeze(ctx, "?fips=true"), 1) + || !TEST_ptr(rand = EVP_RAND_fetch(ctx, "HASH-DRBG", NULL)) + || !TEST_int_eq(rand->origin, EVP_ORIG_FROZEN)) + goto err; + /* Technically, frozen version doesn't need to be freed */ + EVP_RAND_free(rand); + rand = NULL; + + if (!TEST_ptr(rand = EVP_RAND_fetch(ctx, "HASH-DRBG", "?fips=true")) + || !TEST_int_eq(rand->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_RAND_free(rand); + rand = NULL; + + /* Falls back to slow path */ + if (!TEST_ptr(rand = EVP_RAND_fetch(ctx, "HASH-DRBG", "?provider=default")) + || !TEST_int_ne(rand->origin, EVP_ORIG_FROZEN)) + goto err; + + ret = 1; +err: + EVP_RAND_free(rand); + unload_providers(&ctx, prov); + return ret; +} + +static int test_implicit_EVP_RAND_fetch(void) +{ + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + EVP_RAND *rand = NULL; + int ret = 0; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + if (!TEST_ptr(rand = EVP_RAND_fetch(ctx, "HASH-DRBG", NULL))) + goto err; + ret = 1; +err: + EVP_RAND_free(rand); + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_RAND_fetch(const char *id) +{ + OSSL_LIB_CTX *ctx = NULL; + EVP_RAND *rand = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + int ret = 0; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + rand = EVP_RAND_fetch(ctx, id, fetch_property); + if (expected_fetch_result != 0) { + if (!TEST_true(EVP_RAND_up_ref(rand))) + goto err; + /* Ref count should now be 2. Release first one here */ + EVP_RAND_free(rand); + } else { + if (!TEST_ptr_null(rand)) + goto err; + } + ret = 1; +err: + EVP_RAND_free(rand); + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_RAND_fetch_by_name(void) +{ + return test_explicit_EVP_RAND_fetch("HASH-DRBG"); +} + +static int test_EVP_ASYM_CIPHER_fetch_freeze(void) +{ +#if defined(OPENSSL_NO_CACHED_FETCH) || defined(OPENSSL_NO_ML_KEM) + /* + * Test does not make sense if cached fetch is disabled. + * There's nothing to freeze, and test will fail. + */ + return 1; +#endif + + EVP_ASYM_CIPHER *cipher = NULL; + int ret = 0; + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + if (!TEST_ptr(cipher = EVP_ASYM_CIPHER_fetch(ctx, "RSA", NULL)) + || !TEST_true(test_asym_cipher(cipher, "RSA", ctx, NULL)) + || !TEST_int_ne(cipher->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_ASYM_CIPHER_free(cipher); + cipher = NULL; + + if (!TEST_int_eq(OSSL_LIB_CTX_freeze(ctx, "?fips=true"), 1) + || !TEST_ptr(cipher = EVP_ASYM_CIPHER_fetch(ctx, "RSA", NULL)) + || !TEST_true(test_asym_cipher(cipher, "RSA", ctx, NULL)) + || !TEST_int_eq(cipher->origin, EVP_ORIG_FROZEN)) + goto err; + /* Technically, frozen version doesn't need to be freed */ + EVP_ASYM_CIPHER_free(cipher); + + if (!TEST_ptr(cipher = EVP_ASYM_CIPHER_fetch(ctx, "RSA", "?fips=true")) + || !TEST_true(test_asym_cipher(cipher, "RSA", ctx, "?fips=true")) + || !TEST_int_eq(cipher->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_ASYM_CIPHER_free(cipher); + + /* + * A mismatched propq should use the regular fetch path rather than the + * frozen fast path. + */ + if (!TEST_ptr(cipher = EVP_ASYM_CIPHER_fetch(ctx, "RSA", "?provider=default")) + || !TEST_true(test_asym_cipher(cipher, "RSA", ctx, "?provider=default")) + || !TEST_int_ne(cipher->origin, EVP_ORIG_FROZEN)) + goto err; + + ret = 1; +err: + EVP_ASYM_CIPHER_free(cipher); + unload_providers(&ctx, prov); + return ret; +} + +static int test_implicit_EVP_ASYM_CIPHER_fetch(void) +{ + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + EVP_ASYM_CIPHER *cipher = NULL; + int ret = 0; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + if (!TEST_ptr(cipher = EVP_ASYM_CIPHER_fetch(ctx, "RSA", NULL))) + goto err; + ret = 1; +err: + EVP_ASYM_CIPHER_free(cipher); + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_ASYM_CIPHER_fetch(const char *id) +{ + OSSL_LIB_CTX *ctx = NULL; + EVP_ASYM_CIPHER *cipher = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + int ret = 0; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + cipher = EVP_ASYM_CIPHER_fetch(ctx, id, fetch_property); + if (expected_fetch_result != 0) { + if (!TEST_true(EVP_ASYM_CIPHER_up_ref(cipher))) + goto err; + /* Ref count should now be 2. Release first one here */ + EVP_ASYM_CIPHER_free(cipher); + } else { + if (!TEST_ptr_null(cipher)) + goto err; + } + ret = 1; +err: + EVP_ASYM_CIPHER_free(cipher); + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_ASYM_CIPHER_fetch_by_name(void) +{ + return test_explicit_EVP_ASYM_CIPHER_fetch("RSA"); +} + +static EVP_PKEY *generate_dh_key(void) +{ + EVP_PKEY_CTX *ctx; + EVP_PKEY *pkey = NULL; + OSSL_PARAM params[] = { + OSSL_PARAM_construct_utf8_string("group", "ffdhe4096", 0), + OSSL_PARAM_construct_end() + }; + + if (!TEST_ptr(ctx = EVP_PKEY_CTX_new_from_name(NULL, "DH", NULL)) + || !TEST_int_eq(EVP_PKEY_keygen_init(ctx), 1) + || !TEST_int_eq(EVP_PKEY_CTX_set_params(ctx, params), 1) + || !TEST_int_eq(EVP_PKEY_keygen(ctx, &pkey), 1)) { + EVP_PKEY_CTX_free(ctx); + return NULL; + } + + EVP_PKEY_CTX_free(ctx); + return pkey; +} + +static int derive_secret(EVP_PKEY *priv, EVP_PKEY *peer, + unsigned char **secret, size_t *secret_len) +{ + EVP_PKEY_CTX *ctx; + int ret = 0; + + *secret = NULL; + if (!TEST_ptr(ctx = EVP_PKEY_CTX_new_from_pkey(NULL, priv, NULL)) + || !TEST_int_eq(EVP_PKEY_derive_init(ctx), 1) + || !TEST_int_eq(EVP_PKEY_derive_set_peer(ctx, peer), 1) + || !TEST_int_eq(EVP_PKEY_derive(ctx, NULL, secret_len), 1) + || !TEST_ptr(*secret = OPENSSL_malloc(*secret_len)) + || !TEST_int_eq(EVP_PKEY_derive(ctx, *secret, secret_len), 1)) { + OPENSSL_free(*secret); + *secret = NULL; + *secret_len = 0; + goto err; + } + + ret = 1; +err: + EVP_PKEY_CTX_free(ctx); + return ret; +} + +static int test_dh_derive(OSSL_LIB_CTX *libctx, const char *propq) +{ + EVP_PKEY *alice = NULL, *bob = NULL; + unsigned char *secret1 = NULL, *secret2 = NULL; + size_t secret1_len = 0, secret2_len = 0; + int ret = 0; + + if (!TEST_ptr(alice = generate_dh_key()) + || !TEST_ptr(bob = generate_dh_key()) + || !TEST_int_eq(derive_secret(alice, bob, &secret1, &secret1_len), 1) + || !TEST_size_t_gt(secret1_len, 0) + || !TEST_int_eq(derive_secret(bob, alice, &secret2, &secret2_len), 1) + || !TEST_size_t_gt(secret2_len, 0) + || !TEST_size_t_eq(secret1_len, secret2_len) + || !TEST_int_eq(memcmp(secret1, secret2, secret1_len), 0)) + goto err; + + ret = 1; +err: + EVP_PKEY_free(alice); + EVP_PKEY_free(bob); + OPENSSL_free(secret1); + OPENSSL_free(secret2); + + return ret; +} + +static int test_keyexch(OSSL_LIB_CTX *ctx, const char *propq, EVP_KEYEXCH *exchange, const char *name) +{ + return TEST_ptr(exchange) + && TEST_ptr(EVP_KEYEXCH_get0_provider(exchange)) + && TEST_true(EVP_KEYEXCH_is_a(exchange, name)) + && TEST_true(test_dh_derive(ctx, propq)); +} + +static int test_EVP_KEYEXCH_fetch_freeze(void) +{ +#if defined(OPENSSL_NO_CACHED_FETCH) || defined(OPENSSL_NO_DH) + /* + * Test does not make sense if cached fetch is disabled. + * There's nothing to freeze, and test will fail. + */ + return 1; +#endif + + EVP_KEYEXCH *exchange = NULL; + int ret = 0; + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + if (!TEST_ptr(exchange = EVP_KEYEXCH_fetch(ctx, "DH", NULL)) + || !TEST_true(test_keyexch(ctx, NULL, exchange, "DH")) + || !TEST_int_ne(exchange->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_KEYEXCH_free(exchange); + exchange = NULL; + + if (!TEST_int_eq(OSSL_LIB_CTX_freeze(ctx, "?fips=true"), 1) + || !TEST_ptr(exchange = EVP_KEYEXCH_fetch(ctx, "DH", NULL)) + || !TEST_true(test_keyexch(ctx, NULL, exchange, "DH")) + || !TEST_int_eq(exchange->origin, EVP_ORIG_FROZEN)) + goto err; + /* Technically, frozen version doesn't need to be freed */ + EVP_KEYEXCH_free(exchange); + + if (!TEST_ptr(exchange = EVP_KEYEXCH_fetch(ctx, "DH", "?fips=true")) + || !TEST_true(test_keyexch(ctx, "?fips=true", exchange, "DH")) + || !TEST_int_eq(exchange->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_KEYEXCH_free(exchange); + + /* + * A mismatched propq should use the regular fetch path rather than the + * frozen fast path. + */ + if (!TEST_ptr(exchange = EVP_KEYEXCH_fetch(ctx, "DH", "?provider=default")) + || !TEST_true(test_keyexch(ctx, "?provider=default", exchange, "DH")) + || !TEST_int_ne(exchange->origin, EVP_ORIG_FROZEN)) + goto err; + + ret = 1; +err: + EVP_KEYEXCH_free(exchange); + unload_providers(&ctx, prov); + return ret; +} + +static int test_implicit_EVP_KEYEXCH_fetch(void) +{ +#if defined(OPENSSL_NO_DH) + return 1; +#endif + + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + EVP_KEYEXCH *exchange = NULL; + int ret = 0; + + if (use_default_ctx == 0 && !TEST_true(load_providers(&ctx, prov))) + goto err; + + if (!TEST_ptr(exchange = EVP_KEYEXCH_fetch(ctx, "DH", NULL))) + goto err; + + ret = 1; +err: + EVP_KEYEXCH_free(exchange); + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_KEYEXCH_fetch(const char *id) +{ + OSSL_LIB_CTX *ctx = NULL; + EVP_KEYEXCH *exchange = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + int ret = 0; + + if (use_default_ctx == 0 && !TEST_true(load_providers(&ctx, prov))) + goto err; + + exchange = EVP_KEYEXCH_fetch(ctx, id, fetch_property); + if (expected_fetch_result != 0) { + if (!TEST_true(EVP_KEYEXCH_up_ref(exchange))) + goto err; + /* Ref count should now be 2. Release first one here */ + EVP_KEYEXCH_free(exchange); + } else { + if (!TEST_ptr_null(exchange)) + goto err; + } + ret = 1; +err: + EVP_KEYEXCH_free(exchange); + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_KEYEXCH_fetch_by_name(void) +{ +#if defined(OPENSSL_NO_DH) + return 1; +#endif + + return test_explicit_EVP_KEYEXCH_fetch("DH"); +} + +static int test_aes_skey(OSSL_LIB_CTX *libctx, const char *propq) +{ + unsigned char raw_key[16] = { 0 }; + EVP_SKEY *skey = NULL; + int ret = 0; + + if (!TEST_ptr(skey = EVP_SKEY_import_raw_key(libctx, "AES", raw_key, + sizeof(raw_key), propq))) + goto err; + + ret = 1; +err: + EVP_SKEY_free(skey); + return ret; +} + +static int test_skeymgmt(OSSL_LIB_CTX *libctx, const char *propq, + EVP_SKEYMGMT *skeymgmt, const char *name) +{ + return TEST_ptr(skeymgmt) + && TEST_ptr(EVP_SKEYMGMT_get0_provider(skeymgmt)) + && TEST_true(EVP_SKEYMGMT_is_a(skeymgmt, name)) + && TEST_true(test_aes_skey(libctx, propq)); +} + +static int test_EVP_SKEYMGMT_fetch_freeze(void) +{ +#if defined(OPENSSL_NO_CACHED_FETCH) + /* + * Test does not make sense if cached fetch is disabled. + * There's nothing to freeze, and test will fail. + */ + return 1; +#endif + + EVP_SKEYMGMT *skeymgmt = NULL; + int ret = 0; + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[2] = { NULL, NULL }; + + if (use_default_ctx == 0 && !load_providers(&ctx, prov)) + goto err; + + if (!TEST_ptr(skeymgmt = EVP_SKEYMGMT_fetch(ctx, "AES", NULL)) + || !TEST_true(test_skeymgmt(ctx, NULL, skeymgmt, "AES")) + || !TEST_int_ne(skeymgmt->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_SKEYMGMT_free(skeymgmt); + skeymgmt = NULL; + + if (!TEST_int_eq(OSSL_LIB_CTX_freeze(ctx, "?fips=true"), 1) + || !TEST_ptr(skeymgmt = EVP_SKEYMGMT_fetch(ctx, "AES", NULL)) + || !TEST_true(test_skeymgmt(ctx, NULL, skeymgmt, "AES")) + || !TEST_int_eq(skeymgmt->origin, EVP_ORIG_FROZEN)) + goto err; + /* Technically, frozen version doesn't need to be freed */ + EVP_SKEYMGMT_free(skeymgmt); + + if (!TEST_ptr(skeymgmt = EVP_SKEYMGMT_fetch(ctx, "AES", "?fips=true")) + || !TEST_true(test_skeymgmt(ctx, "?fips=true", skeymgmt, "AES")) + || !TEST_int_eq(skeymgmt->origin, EVP_ORIG_FROZEN)) + goto err; + EVP_SKEYMGMT_free(skeymgmt); + + /* + * A mismatched propq should use the regular fetch path rather than the + * frozen fast path. + */ + if (!TEST_ptr(skeymgmt = EVP_SKEYMGMT_fetch(ctx, "AES", "?provider=default")) + || !TEST_true(test_skeymgmt(ctx, "?provider=default", skeymgmt, "AES")) + || !TEST_int_ne(skeymgmt->origin, EVP_ORIG_FROZEN)) + goto err; + + ret = 1; +err: + EVP_SKEYMGMT_free(skeymgmt); + unload_providers(&ctx, prov); + return ret; +} + +static int test_implicit_EVP_SKEYMGMT_fetch(void) +{ + OSSL_LIB_CTX *ctx = NULL; + OSSL_PROVIDER *prov[] = { NULL, NULL }; + EVP_SKEYMGMT *skeymgmt = NULL; + int ret = 0; + + if (use_default_ctx == 0 && !TEST_true(load_providers(&ctx, prov))) + goto err; + + if (!TEST_ptr(skeymgmt = EVP_SKEYMGMT_fetch(ctx, "AES", NULL))) + goto err; + + ret = 1; +err: + EVP_SKEYMGMT_free(skeymgmt); + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_SKEYMGMT_fetch(const char *id) +{ + OSSL_LIB_CTX *ctx = NULL; + EVP_SKEYMGMT *skeymgmt = NULL; + OSSL_PROVIDER *prov[] = { NULL, NULL }; + int ret = 0; + + if (use_default_ctx == 0 && !TEST_true(load_providers(&ctx, prov))) + goto err; + + skeymgmt = EVP_SKEYMGMT_fetch(ctx, id, fetch_property); + if (expected_fetch_result != 0) { + if (!TEST_true(EVP_SKEYMGMT_up_ref(skeymgmt))) + goto err; + /* Ref count should now be 2. Release first one here */ + EVP_SKEYMGMT_free(skeymgmt); + } else { + if (!TEST_ptr_null(skeymgmt)) + goto err; + } + ret = 1; +err: + EVP_SKEYMGMT_free(skeymgmt); + unload_providers(&ctx, prov); + return ret; +} + +static int test_explicit_EVP_SKEYMGMT_fetch_by_name(void) +{ + return test_explicit_EVP_SKEYMGMT_fetch("AES"); +} + int setup_tests(void) { OPTION_CHOICE o; @@ -433,14 +1855,51 @@ int setup_tests(void) } ADD_TEST(test_legacy_provider_unloaded); if (strcmp(alg, "digest") == 0) { + ADD_TEST(test_EVP_MD_fetch_freeze); ADD_TEST(test_implicit_EVP_MD_fetch); ADD_TEST(test_explicit_EVP_MD_fetch_by_name); ADD_ALL_TESTS_NOSUBTEST(test_explicit_EVP_MD_fetch_by_X509_ALGOR, 2); - } else { + } else if (strcmp(alg, "cipher") == 0) { + ADD_TEST(test_EVP_CIPHER_fetch_freeze); ADD_TEST(test_implicit_EVP_CIPHER_fetch); ADD_TEST(test_explicit_EVP_CIPHER_fetch_by_name); - ADD_TEST(test_cipher_no_getparams); ADD_ALL_TESTS_NOSUBTEST(test_explicit_EVP_CIPHER_fetch_by_X509_ALGOR, 2); + } else if (strcmp(alg, "kdf") == 0) { + ADD_TEST(test_EVP_KDF_fetch_freeze); + ADD_TEST(test_implicit_EVP_KDF_fetch); + ADD_TEST(test_explicit_EVP_KDF_fetch_by_name); + } else if (strcmp(alg, "rand") == 0) { + ADD_TEST(test_EVP_RAND_fetch_freeze); + ADD_TEST(test_implicit_EVP_RAND_fetch); + ADD_TEST(test_explicit_EVP_RAND_fetch_by_name); + } else if (strcmp(alg, "mac") == 0) { + ADD_TEST(test_EVP_MAC_fetch_freeze); + ADD_TEST(test_implicit_EVP_MAC_fetch); + ADD_TEST(test_explicit_EVP_MAC_fetch_by_name); + } else if (strcmp(alg, "kmgmt") == 0) { + ADD_TEST(test_EVP_KEYMGMT_fetch_freeze); + ADD_TEST(test_implicit_EVP_KEYMGMT_fetch); + ADD_TEST(test_explicit_EVP_KEYMGMT_fetch_by_name); + ADD_ALL_TESTS_NOSUBTEST(test_explicit_EVP_KEYMGMT_fetch_by_X509_ALGOR, 2); + } else if (strcmp(alg, "kem") == 0) { + ADD_TEST(test_EVP_KEM_fetch_freeze); + ADD_TEST(test_explicit_EVP_KEM_fetch_by_name); + ADD_ALL_TESTS_NOSUBTEST(test_explicit_EVP_KEM_fetch_by_X509_ALGOR, 2); + } else if (strcmp(alg, "asymcipher") == 0) { + ADD_TEST(test_EVP_ASYM_CIPHER_fetch_freeze); + ADD_TEST(test_implicit_EVP_ASYM_CIPHER_fetch); + ADD_TEST(test_explicit_EVP_ASYM_CIPHER_fetch_by_name); + } else if (strcmp(alg, "evp_keyexch") == 0) { + ADD_TEST(test_EVP_KEYEXCH_fetch_freeze); + ADD_TEST(test_implicit_EVP_KEYEXCH_fetch); + ADD_TEST(test_explicit_EVP_KEYEXCH_fetch_by_name); + } else if (strcmp(alg, "skeymgmt") == 0) { + ADD_TEST(test_EVP_SKEYMGMT_fetch_freeze); + ADD_TEST(test_implicit_EVP_SKEYMGMT_fetch); + ADD_TEST(test_explicit_EVP_SKEYMGMT_fetch_by_name); + } else { + TEST_error("Unknown fetch type: %s", alg); + return 0; } return 1; } diff --git a/test/evp_kdf_test.c b/test/evp_kdf_test.c index 6d4a55d11e..89e2afb669 100644 --- a/test/evp_kdf_test.c +++ b/test/evp_kdf_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2018-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2018-2020, Oracle and/or its affiliates. All rights reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -988,7 +988,7 @@ static int test_kdf_pbkdf2_large_output(void) int mode = 0; OSSL_PARAM *params; - if (SIZE_MAX > 0xFFFFFFFFU) + if (sizeof(len) > 32) len = SIZE_MAX; params = construct_pbkdf2_params("passwordPASSWORDpassword", "sha256", @@ -1208,7 +1208,6 @@ static int test_kdf_scrypt(void) } #endif /* OPENSSL_NO_SCRYPT */ -#ifndef OPENSSL_NO_SSKDF static int test_kdf_ss_hash(void) { int ret; @@ -1245,9 +1244,7 @@ static int test_kdf_ss_hash(void) EVP_KDF_CTX_free(kctx); return ret; } -#endif /* OPENSSL_NO_SSKDF */ -#ifndef OPENSSL_NO_X963KDF static int test_kdf_x963(void) { int ret; @@ -1299,9 +1296,7 @@ static int test_kdf_x963(void) EVP_KDF_CTX_free(kctx); return ret; } -#endif /* OPENSSL_NO_X963KDF */ -#ifndef OPENSSL_NO_KBKDF #if !defined(OPENSSL_NO_CMAC) && !defined(OPENSSL_NO_CAMELLIA) /* * KBKDF test vectors from RFC 6803 (Camellia Encryption for Kerberos 5) @@ -1313,8 +1308,22 @@ static int test_kdf_kbkdf_6803_128(void) EVP_KDF_CTX *kctx; OSSL_PARAM params[7]; static unsigned char input_key[] = { - 0x57, 0xD0, 0x29, 0x72, 0x98, 0xFF, 0xD9, 0xD3, 0x5D, 0xE5, - 0xA4, 0x7F, 0xB4, 0xBD, 0xE2, 0x4B + 0x57, + 0xD0, + 0x29, + 0x72, + 0x98, + 0xFF, + 0xD9, + 0xD3, + 0x5D, + 0xE5, + 0xA4, + 0x7F, + 0xB4, + 0xBD, + 0xE2, + 0x4B, }; static unsigned char constants[][5] = { { 0x00, 0x00, 0x00, 0x02, 0x99 }, @@ -1369,10 +1378,38 @@ static int test_kdf_kbkdf_6803_256(void) EVP_KDF_CTX *kctx; OSSL_PARAM params[7]; static unsigned char input_key[] = { - 0xB9, 0xD6, 0x82, 0x8B, 0x20, 0x56, 0xB7, 0xBE, 0x65, 0x6D, - 0x88, 0xA1, 0x23, 0xB1, 0xFA, 0xC6, 0x82, 0x14, 0xAC, 0x2B, - 0x72, 0x7E, 0xCF, 0x5F, 0x69, 0xAF, 0xE0, 0xC4, 0xDF, 0x2A, - 0x6D, 0x2C + 0xB9, + 0xD6, + 0x82, + 0x8B, + 0x20, + 0x56, + 0xB7, + 0xBE, + 0x65, + 0x6D, + 0x88, + 0xA1, + 0x23, + 0xB1, + 0xFA, + 0xC6, + 0x82, + 0x14, + 0xAC, + 0x2B, + 0x72, + 0x7E, + 0xCF, + 0x5F, + 0x69, + 0xAF, + 0xE0, + 0xC4, + 0xDF, + 0x2A, + 0x6D, + 0x2C, }; static unsigned char constants[][5] = { { 0x00, 0x00, 0x00, 0x02, 0x99 }, @@ -1380,18 +1417,108 @@ static int test_kdf_kbkdf_6803_256(void) { 0x00, 0x00, 0x00, 0x02, 0x55 }, }; static unsigned char outputs[][32] = { - { 0xE4, 0x67, 0xF9, 0xA9, 0x55, 0x2B, 0xC7, 0xD3, 0x15, 0x5A, - 0x62, 0x20, 0xAF, 0x9C, 0x19, 0x22, 0x0E, 0xEE, 0xD4, 0xFF, - 0x78, 0xB0, 0xD1, 0xE6, 0xA1, 0x54, 0x49, 0x91, 0x46, 0x1A, - 0x9E, 0x50 }, - { 0x41, 0x2A, 0xEF, 0xC3, 0x62, 0xA7, 0x28, 0x5F, 0xC3, 0x96, - 0x6C, 0x6A, 0x51, 0x81, 0xE7, 0x60, 0x5A, 0xE6, 0x75, 0x23, - 0x5B, 0x6D, 0x54, 0x9F, 0xBF, 0xC9, 0xAB, 0x66, 0x30, 0xA4, - 0xC6, 0x04 }, - { 0xFA, 0x62, 0x4F, 0xA0, 0xE5, 0x23, 0x99, 0x3F, 0xA3, 0x88, - 0xAE, 0xFD, 0xC6, 0x7E, 0x67, 0xEB, 0xCD, 0x8C, 0x08, 0xE8, - 0xA0, 0x24, 0x6B, 0x1D, 0x73, 0xB0, 0xD1, 0xDD, 0x9F, 0xC5, - 0x82, 0xB0 }, + { + 0xE4, + 0x67, + 0xF9, + 0xA9, + 0x55, + 0x2B, + 0xC7, + 0xD3, + 0x15, + 0x5A, + 0x62, + 0x20, + 0xAF, + 0x9C, + 0x19, + 0x22, + 0x0E, + 0xEE, + 0xD4, + 0xFF, + 0x78, + 0xB0, + 0xD1, + 0xE6, + 0xA1, + 0x54, + 0x49, + 0x91, + 0x46, + 0x1A, + 0x9E, + 0x50, + }, + { + 0x41, + 0x2A, + 0xEF, + 0xC3, + 0x62, + 0xA7, + 0x28, + 0x5F, + 0xC3, + 0x96, + 0x6C, + 0x6A, + 0x51, + 0x81, + 0xE7, + 0x60, + 0x5A, + 0xE6, + 0x75, + 0x23, + 0x5B, + 0x6D, + 0x54, + 0x9F, + 0xBF, + 0xC9, + 0xAB, + 0x66, + 0x30, + 0xA4, + 0xC6, + 0x04, + }, + { + 0xFA, + 0x62, + 0x4F, + 0xA0, + 0xE5, + 0x23, + 0x99, + 0x3F, + 0xA3, + 0x88, + 0xAE, + 0xFD, + 0xC6, + 0x7E, + 0x67, + 0xEB, + 0xCD, + 0x8C, + 0x08, + 0xE8, + 0xA0, + 0x24, + 0x6B, + 0x1D, + 0x73, + 0xB0, + 0xD1, + 0xDD, + 0x9F, + 0xC5, + 0x82, + 0xB0, + }, }; static unsigned char iv[16] = { 0 }; unsigned char result[32] = { 0 }; @@ -1608,14 +1735,56 @@ static int test_kdf_kbkdf_8009_prf1(void) char *label = "prf", *digest = "sha256", *prf_input = "test", *mac = "HMAC"; static unsigned char input_key[] = { - 0x37, 0x05, 0xD9, 0x60, 0x80, 0xC1, 0x77, 0x28, 0xA0, 0xE8, - 0x00, 0xEA, 0xB6, 0xE0, 0xD2, 0x3C + 0x37, + 0x05, + 0xD9, + 0x60, + 0x80, + 0xC1, + 0x77, + 0x28, + 0xA0, + 0xE8, + 0x00, + 0xEA, + 0xB6, + 0xE0, + 0xD2, + 0x3C, }; static unsigned char output[] = { - 0x9D, 0x18, 0x86, 0x16, 0xF6, 0x38, 0x52, 0xFE, 0x86, 0x91, - 0x5B, 0xB8, 0x40, 0xB4, 0xA8, 0x86, 0xFF, 0x3E, 0x6B, 0xB0, - 0xF8, 0x19, 0xB4, 0x9B, 0x89, 0x33, 0x93, 0xD3, 0x93, 0x85, - 0x42, 0x95 + 0x9D, + 0x18, + 0x86, + 0x16, + 0xF6, + 0x38, + 0x52, + 0xFE, + 0x86, + 0x91, + 0x5B, + 0xB8, + 0x40, + 0xB4, + 0xA8, + 0x86, + 0xFF, + 0x3E, + 0x6B, + 0xB0, + 0xF8, + 0x19, + 0xB4, + 0x9B, + 0x89, + 0x33, + 0x93, + 0xD3, + 0x93, + 0x85, + 0x42, + 0x95, }; unsigned char result[sizeof(output)] = { 0 }; @@ -1648,17 +1817,88 @@ static int test_kdf_kbkdf_8009_prf2(void) char *label = "prf", *digest = "sha384", *prf_input = "test", *mac = "HMAC"; static unsigned char input_key[] = { - 0x6D, 0x40, 0x4D, 0x37, 0xFA, 0xF7, 0x9F, 0x9D, 0xF0, 0xD3, - 0x35, 0x68, 0xD3, 0x20, 0x66, 0x98, 0x00, 0xEB, 0x48, 0x36, - 0x47, 0x2E, 0xA8, 0xA0, 0x26, 0xD1, 0x6B, 0x71, 0x82, 0x46, - 0x0C, 0x52 + 0x6D, + 0x40, + 0x4D, + 0x37, + 0xFA, + 0xF7, + 0x9F, + 0x9D, + 0xF0, + 0xD3, + 0x35, + 0x68, + 0xD3, + 0x20, + 0x66, + 0x98, + 0x00, + 0xEB, + 0x48, + 0x36, + 0x47, + 0x2E, + 0xA8, + 0xA0, + 0x26, + 0xD1, + 0x6B, + 0x71, + 0x82, + 0x46, + 0x0C, + 0x52, }; static unsigned char output[] = { - 0x98, 0x01, 0xF6, 0x9A, 0x36, 0x8C, 0x2B, 0xF6, 0x75, 0xE5, - 0x95, 0x21, 0xE1, 0x77, 0xD9, 0xA0, 0x7F, 0x67, 0xEF, 0xE1, - 0xCF, 0xDE, 0x8D, 0x3C, 0x8D, 0x6F, 0x6A, 0x02, 0x56, 0xE3, - 0xB1, 0x7D, 0xB3, 0xC1, 0xB6, 0x2A, 0xD1, 0xB8, 0x55, 0x33, - 0x60, 0xD1, 0x73, 0x67, 0xEB, 0x15, 0x14, 0xD2 + 0x98, + 0x01, + 0xF6, + 0x9A, + 0x36, + 0x8C, + 0x2B, + 0xF6, + 0x75, + 0xE5, + 0x95, + 0x21, + 0xE1, + 0x77, + 0xD9, + 0xA0, + 0x7F, + 0x67, + 0xEF, + 0xE1, + 0xCF, + 0xDE, + 0x8D, + 0x3C, + 0x8D, + 0x6F, + 0x6A, + 0x02, + 0x56, + 0xE3, + 0xB1, + 0x7D, + 0xB3, + 0xC1, + 0xB6, + 0x2A, + 0xD1, + 0xB8, + 0x55, + 0x33, + 0x60, + 0xD1, + 0x73, + 0x67, + 0xEB, + 0x15, + 0x14, + 0xD2, }; unsigned char result[sizeof(output)] = { 0 }; @@ -1701,22 +1941,103 @@ static int test_kdf_kbkdf_fixedinfo(void) int use_separator = 0; static unsigned char input_key[] = { - 0xc1, 0x0b, 0x15, 0x2e, 0x8c, 0x97, 0xb7, 0x7e, 0x18, 0x70, - 0x4e, 0x0f, 0x0b, 0xd3, 0x83, 0x05 + 0xc1, + 0x0b, + 0x15, + 0x2e, + 0x8c, + 0x97, + 0xb7, + 0x7e, + 0x18, + 0x70, + 0x4e, + 0x0f, + 0x0b, + 0xd3, + 0x83, + 0x05, }; static unsigned char fixed_input[] = { - 0x98, 0xcd, 0x4c, 0xbb, 0xbe, 0xbe, 0x15, 0xd1, - 0x7d, 0xc8, 0x6e, 0x6d, 0xba, 0xd8, 0x00, 0xa2, - 0xdc, 0xbd, 0x64, 0xf7, 0xc7, 0xad, 0x0e, 0x78, - 0xe9, 0xcf, 0x94, 0xff, 0xdb, 0xa8, 0x9d, 0x03, - 0xe9, 0x7e, 0xad, 0xf6, 0xc4, 0xf7, 0xb8, 0x06, - 0xca, 0xf5, 0x2a, 0xa3, 0x8f, 0x09, 0xd0, 0xeb, - 0x71, 0xd7, 0x1f, 0x49, 0x7b, 0xcc, 0x69, 0x06, - 0xb4, 0x8d, 0x36, 0xc4 + 0x98, + 0xcd, + 0x4c, + 0xbb, + 0xbe, + 0xbe, + 0x15, + 0xd1, + 0x7d, + 0xc8, + 0x6e, + 0x6d, + 0xba, + 0xd8, + 0x00, + 0xa2, + 0xdc, + 0xbd, + 0x64, + 0xf7, + 0xc7, + 0xad, + 0x0e, + 0x78, + 0xe9, + 0xcf, + 0x94, + 0xff, + 0xdb, + 0xa8, + 0x9d, + 0x03, + 0xe9, + 0x7e, + 0xad, + 0xf6, + 0xc4, + 0xf7, + 0xb8, + 0x06, + 0xca, + 0xf5, + 0x2a, + 0xa3, + 0x8f, + 0x09, + 0xd0, + 0xeb, + 0x71, + 0xd7, + 0x1f, + 0x49, + 0x7b, + 0xcc, + 0x69, + 0x06, + 0xb4, + 0x8d, + 0x36, + 0xc4, + }; static unsigned char output[] = { - 0x26, 0xfa, 0xf6, 0x19, 0x08, 0xad, 0x9e, 0xe8, 0x81, 0xb8, - 0x30, 0x5c, 0x22, 0x1d, 0xb5, 0x3f + 0x26, + 0xfa, + 0xf6, + 0x19, + 0x08, + 0xad, + 0x9e, + 0xe8, + 0x81, + 0xb8, + 0x30, + 0x5c, + 0x22, + 0x1d, + 0xb5, + 0x3f, }; unsigned char result[sizeof(output)] = { 0 }; @@ -1893,9 +2214,7 @@ static int test_kdf_kbkdf_kmac(void) EVP_KDF_CTX_free(kctx); return ret; } -#endif /* OPENSSL_NO_KBKDF */ -#ifndef OPENSSL_NO_SSKDF static int test_kdf_ss_hmac(void) { int ret; @@ -1986,9 +2305,7 @@ static int test_kdf_ss_kmac(void) EVP_KDF_CTX_free(kctx); return ret; } -#endif /* OPENSSL_NO_SSKDF */ -#ifndef OPENSSL_NO_SSHKDF static int test_kdf_sshkdf(void) { int ret; @@ -2044,7 +2361,6 @@ static int test_kdf_sshkdf(void) EVP_KDF_CTX_free(kctx); return ret; } -#endif /* OPENSSL_NO_SSHKDF */ static int test_kdfs_same(EVP_KDF *kdf1, EVP_KDF *kdf2) { @@ -2097,74 +2413,7 @@ static int test_kdf_get_kdf(void) return ok; } -static int test_kdf_ctx_get_kdf(void) -{ - EVP_KDF *kdf = NULL; - const EVP_KDF *kdf_get0 = NULL; - EVP_KDF *kdf_get1 = NULL; - EVP_KDF_CTX *kctx = NULL; - int ok = 0; - - kdf = EVP_KDF_fetch(NULL, OSSL_KDF_NAME_PBKDF2, NULL); - if (!TEST_ptr(kdf)) - goto out; - - kctx = EVP_KDF_CTX_new(kdf); - if (!TEST_ptr(kdf)) - goto out; - - kdf_get0 = EVP_KDF_CTX_get0_kdf(kctx); - if (!TEST_ptr_eq(kdf, kdf_get0)) - goto out; - - kdf_get1 = EVP_KDF_CTX_get1_kdf(kctx); - if (!TEST_ptr(kdf_get1) - || !TEST_true(EVP_KDF_is_a(kdf_get1, EVP_KDF_get0_name(kdf)))) - goto out; - - ok = 1; - -out: - EVP_KDF_free(kdf_get1); - EVP_KDF_CTX_free(kctx); - EVP_KDF_free(kdf); - - return ok; -} - -#if !defined(OPENSSL_NO_DEPRECATED_4_1) -static int test_kdf_ctx_kdf(void) -{ - EVP_KDF *kdf = NULL; - const EVP_KDF *kdf_get = NULL; - EVP_KDF_CTX *kctx = NULL; - int ok = 0; - - kdf = EVP_KDF_fetch(NULL, OSSL_KDF_NAME_PBKDF2, NULL); - if (!TEST_ptr(kdf)) - goto out; - - kctx = EVP_KDF_CTX_new(kdf); - if (!TEST_ptr(kdf)) - goto out; - - OSSL_BEGIN_ALLOW_DEPRECATED - kdf_get = EVP_KDF_CTX_kdf(kctx); - OSSL_END_ALLOW_DEPRECATED - if (!TEST_ptr_eq(kdf, kdf_get)) - goto out; - - ok = 1; - -out: - EVP_KDF_CTX_free(kctx); - EVP_KDF_free(kdf); - - return ok; -} -#endif /* !OPENSSL_NO_DEPRECATED_4_1 */ - -#if !defined(OPENSSL_NO_CMS) && !defined(OPENSSL_NO_DES) && !defined(OPENSSL_NO_X942KDF) +#if !defined(OPENSSL_NO_CMS) && !defined(OPENSSL_NO_DES) static int test_kdf_x942_asn1(void) { int ret; @@ -2200,7 +2449,6 @@ static int test_kdf_x942_asn1(void) } #endif /* OPENSSL_NO_CMS */ -#ifndef OPENSSL_NO_KRB5KDF static int test_kdf_krb5kdf(void) { int ret; @@ -2234,9 +2482,7 @@ static int test_kdf_krb5kdf(void) EVP_KDF_CTX_free(kctx); return ret; } -#endif /* OPENSSL_NO_KRB5KDF */ -#ifndef OPENSSL_NO_HMAC_DRBG_KDF static int test_kdf_hmac_drbg_settables(void) { int ret = 0, i = 0, j = 0; @@ -2346,9 +2592,7 @@ err: EVP_KDF_CTX_free(kctx); return ret; } -#endif /* OPENSSL_NO_HMAC_DRBG_KDF */ -#ifndef OPENSSL_NO_KBKDF /* Test that changing the KBKDF algorithm from KMAC to HMAC works correctly */ static int test_kbkdf_mac_change(void) { @@ -2406,14 +2650,12 @@ err: EVP_KDF_CTX_free(kctx); return ret; } -#endif /* OPENSSL_NO_KBKDF */ int setup_tests(void) { ADD_TEST(test_kdf_pbkdf1); ADD_TEST(test_kdf_pbkdf1_skey); ADD_TEST(test_kdf_pbkdf1_key_too_long); -#ifndef OPENSSL_NO_KBKDF #if !defined(OPENSSL_NO_CMAC) && !defined(OPENSSL_NO_CAMELLIA) ADD_TEST(test_kdf_kbkdf_6803_128); ADD_TEST(test_kdf_kbkdf_6803_256); @@ -2431,12 +2673,7 @@ int setup_tests(void) #endif if (fips_provider_version_ge(NULL, 3, 1, 0)) ADD_TEST(test_kdf_kbkdf_kmac); -#endif /* OPENSSL_NO_KBKDF */ ADD_TEST(test_kdf_get_kdf); - ADD_TEST(test_kdf_ctx_get_kdf); -#if !defined(OPENSSL_NO_DEPRECATED_4_1) - ADD_TEST(test_kdf_ctx_kdf); -#endif ADD_TEST(test_kdf_tls1_prf); ADD_TEST(test_kdf_tls1_prf_set_skey); ADD_TEST(test_kdf_tls1_prf_derive_skey); @@ -2472,29 +2709,17 @@ int setup_tests(void) #ifndef OPENSSL_NO_SCRYPT ADD_TEST(test_kdf_scrypt); #endif -#ifndef OPENSSL_NO_SSKDF ADD_TEST(test_kdf_ss_hash); ADD_TEST(test_kdf_ss_hmac); ADD_TEST(test_kdf_ss_kmac); -#endif -#ifndef OPENSSL_NO_SSHKDF ADD_TEST(test_kdf_sshkdf); -#endif -#ifndef OPENSSL_NO_X963KDF ADD_TEST(test_kdf_x963); -#endif -#if !defined(OPENSSL_NO_CMS) && !defined(OPENSSL_NO_DES) && !defined(OPENSSL_NO_X942KDF) +#if !defined(OPENSSL_NO_CMS) && !defined(OPENSSL_NO_DES) ADD_TEST(test_kdf_x942_asn1); #endif -#ifndef OPENSSL_NO_KRB5KDF ADD_TEST(test_kdf_krb5kdf); -#endif -#ifndef OPENSSL_NO_HMAC_DRBG_KDF ADD_TEST(test_kdf_hmac_drbg_settables); ADD_TEST(test_kdf_hmac_drbg_gettables); -#endif -#ifndef OPENSSL_NO_KBKDF ADD_TEST(test_kbkdf_mac_change); -#endif return 1; } diff --git a/test/evp_libctx_test.c b/test/evp_libctx_test.c index aa94474ac5..55bf075c57 100644 --- a/test/evp_libctx_test.c +++ b/test/evp_libctx_test.c @@ -359,13 +359,70 @@ static int test_cipher_reinit(int test_id) 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10 }; unsigned char key[64] = { - 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, - 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x01, 0x01, 0x02, 0x03, - 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, - 0x0e, 0x0f, 0x02, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, - 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x03, 0x01, - 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, - 0x0c, 0x0d, 0x0e, 0x0f + 0x00, + 0x01, + 0x02, + 0x03, + 0x04, + 0x05, + 0x06, + 0x07, + 0x08, + 0x09, + 0x0a, + 0x0b, + 0x0c, + 0x0d, + 0x0e, + 0x0f, + 0x01, + 0x01, + 0x02, + 0x03, + 0x04, + 0x05, + 0x06, + 0x07, + 0x08, + 0x09, + 0x0a, + 0x0b, + 0x0c, + 0x0d, + 0x0e, + 0x0f, + 0x02, + 0x01, + 0x02, + 0x03, + 0x04, + 0x05, + 0x06, + 0x07, + 0x08, + 0x09, + 0x0a, + 0x0b, + 0x0c, + 0x0d, + 0x0e, + 0x0f, + 0x03, + 0x01, + 0x02, + 0x03, + 0x04, + 0x05, + 0x06, + 0x07, + 0x08, + 0x09, + 0x0a, + 0x0b, + 0x0c, + 0x0d, + 0x0e, + 0x0f, }; unsigned char iv[48] = { 0x0f, 0x0e, 0x0d, 0x0c, 0x0b, 0x0a, 0x09, 0x08, @@ -446,19 +503,104 @@ static int test_cipher_reinit_partialupdate(int test_id) unsigned char out2[256]; unsigned char out3[256]; static const unsigned char in[32] = { - 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0xba, 0xbe, - 0xba, 0xbe, 0x00, 0x00, 0xba, 0xbe, 0x01, 0x01, 0x02, 0x03, - 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, - 0x0e, 0x0f + 0x08, + 0x09, + 0x0a, + 0x0b, + 0x0c, + 0x0d, + 0x0e, + 0x0f, + 0xba, + 0xbe, + 0xba, + 0xbe, + 0x00, + 0x00, + 0xba, + 0xbe, + 0x01, + 0x01, + 0x02, + 0x03, + 0x04, + 0x05, + 0x06, + 0x07, + 0x08, + 0x09, + 0x0a, + 0x0b, + 0x0c, + 0x0d, + 0x0e, + 0x0f, }; static const unsigned char key[64] = { - 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, - 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x01, 0x01, 0x02, 0x03, - 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, - 0x0e, 0x0f, 0x02, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, - 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x03, 0x01, - 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, - 0x0c, 0x0d, 0x0e, 0x0f + 0x00, + 0x01, + 0x02, + 0x03, + 0x04, + 0x05, + 0x06, + 0x07, + 0x08, + 0x09, + 0x0a, + 0x0b, + 0x0c, + 0x0d, + 0x0e, + 0x0f, + 0x01, + 0x01, + 0x02, + 0x03, + 0x04, + 0x05, + 0x06, + 0x07, + 0x08, + 0x09, + 0x0a, + 0x0b, + 0x0c, + 0x0d, + 0x0e, + 0x0f, + 0x02, + 0x01, + 0x02, + 0x03, + 0x04, + 0x05, + 0x06, + 0x07, + 0x08, + 0x09, + 0x0a, + 0x0b, + 0x0c, + 0x0d, + 0x0e, + 0x0f, + 0x03, + 0x01, + 0x02, + 0x03, + 0x04, + 0x05, + 0x06, + 0x07, + 0x08, + 0x09, + 0x0a, + 0x0b, + 0x0c, + 0x0d, + 0x0e, + 0x0f, }; static const unsigned char iv[48] = { 0x0f, 0x0e, 0x0d, 0x0c, 0x0b, 0x0a, 0x09, 0x08, diff --git a/test/evp_pkey_dhkem_test.c b/test/evp_pkey_dhkem_test.c index b2903a9b95..9833899360 100644 --- a/test/evp_pkey_dhkem_test.c +++ b/test/evp_pkey_dhkem_test.c @@ -394,7 +394,8 @@ err: } /* - * ECX and EC keys autogen the public key if a private key is loaded. + * ECX keys autogen the public key if a private key is loaded, + * So this test passes for ECX, but fails for EC */ static int test_nopublic(int tstid) { @@ -404,6 +405,7 @@ static int test_nopublic(int tstid) int encap = ((tstid & 1) == 0); int keytype = tstid >= TEST_KEM_ENCAP_DECAP; const TEST_ENCAPDATA *t = &ec_encapdata[keytype]; + int expected = (keytype == TEST_KEYTYPE_X25519); TEST_note("%s %s", t->curve, encap ? "Encap" : "Decap"); if (!TEST_ptr(priv = new_raw_private_key(t->curve, t->rpriv, t->rprivlen, @@ -413,12 +415,15 @@ static int test_nopublic(int tstid) goto err; if (encap) { - if (!TEST_int_eq(EVP_PKEY_encapsulate_init(ctx, opparam), 1)) + if (!TEST_int_eq(EVP_PKEY_encapsulate_init(ctx, opparam), expected)) goto err; } else { - if (!TEST_int_eq(EVP_PKEY_decapsulate_init(ctx, opparam), 1)) + if (!TEST_int_eq(EVP_PKEY_decapsulate_init(ctx, opparam), expected)) goto err; } + if (expected == 0 + && !TEST_int_eq(ERR_GET_REASON(ERR_get_error()), PROV_R_NOT_A_PUBLIC_KEY)) + goto err; ret = 1; err: EVP_PKEY_free(priv); @@ -426,10 +431,7 @@ err: return ret; } -/* - * Test that not setting the auth public key does not fail the auth - * encap/decap init - */ +/* Test that not setting the auth public key fails the auth encap/decap init */ static int test_noauthpublic(int tstid) { int ret = 0; @@ -438,23 +440,28 @@ static int test_noauthpublic(int tstid) int keytype = tstid >= TEST_KEM_ENCAP_DECAP; const TEST_ENCAPDATA *t = &ec_encapdata[keytype]; EVP_PKEY_CTX *ctx = rctx[keytype]; + int expected = (keytype == TEST_KEYTYPE_X25519); TEST_note("%s %s", t->curve, encap ? "Encap" : "Decap"); if (!TEST_ptr(auth = new_raw_private_key(t->curve, t->rpriv, - t->rprivlen, NULL, 1))) + t->rprivlen, NULL, expected))) goto err; if (encap) { if (!TEST_int_eq(EVP_PKEY_auth_encapsulate_init(ctx, auth, opparam), - 1)) + expected)) goto err; } else { if (!TEST_int_eq(EVP_PKEY_auth_decapsulate_init(ctx, auth, opparam), - 1)) + expected)) goto err; } + if (expected == 0 + && !TEST_int_eq(ERR_GET_REASON(ERR_get_error()), + PROV_R_NOT_A_PUBLIC_KEY)) + goto err; ret = 1; err: EVP_PKEY_free(auth); diff --git a/test/evp_pkey_provided_test.c b/test/evp_pkey_provided_test.c index 0464d12b7b..f96b6e43ee 100644 --- a/test/evp_pkey_provided_test.c +++ b/test/evp_pkey_provided_test.c @@ -905,9 +905,34 @@ static int test_fromdata_dh_named_group(void) * -pkeyopt priv_len:224 -text */ static const unsigned char priv_data[] = { - 0x88, 0x85, 0xe7, 0x9f, 0xee, 0x6d, 0xc5, 0x7c, 0x78, 0xaf, - 0x63, 0x5d, 0x38, 0x2a, 0xd0, 0xed, 0x56, 0x4b, 0x47, 0x21, - 0x2b, 0xfa, 0x55, 0xfa, 0x87, 0xe8, 0xa9, 0x7b + 0x88, + 0x85, + 0xe7, + 0x9f, + 0xee, + 0x6d, + 0xc5, + 0x7c, + 0x78, + 0xaf, + 0x63, + 0x5d, + 0x38, + 0x2a, + 0xd0, + 0xed, + 0x56, + 0x4b, + 0x47, + 0x21, + 0x2b, + 0xfa, + 0x55, + 0xfa, + 0x87, + 0xe8, + 0xa9, + 0x7b, }; static const unsigned char pub_data[] = { 0x00, 0xd6, 0x2d, 0x77, 0xe0, 0xd3, 0x7d, 0xf8, 0xeb, 0x98, 0x50, 0xa1, @@ -1121,9 +1146,34 @@ static int test_fromdata_dh_fips186_4(void) * -pkeyopt group:ffdhe2048 -pkeyopt priv_len:224 -text */ static const unsigned char priv_data[] = { - 0x88, 0x85, 0xe7, 0x9f, 0xee, 0x6d, 0xc5, 0x7c, 0x78, 0xaf, - 0x63, 0x5d, 0x38, 0x2a, 0xd0, 0xed, 0x56, 0x4b, 0x47, 0x21, - 0x2b, 0xfa, 0x55, 0xfa, 0x87, 0xe8, 0xa9, 0x7b + 0x88, + 0x85, + 0xe7, + 0x9f, + 0xee, + 0x6d, + 0xc5, + 0x7c, + 0x78, + 0xaf, + 0x63, + 0x5d, + 0x38, + 0x2a, + 0xd0, + 0xed, + 0x56, + 0x4b, + 0x47, + 0x21, + 0x2b, + 0xfa, + 0x55, + 0xfa, + 0x87, + 0xe8, + 0xa9, + 0x7b, }; static const unsigned char pub_data[] = { 0xd6, 0x2d, 0x77, 0xe0, 0xd3, 0x7d, 0xf8, 0xeb, 0x98, 0x50, 0xa1, 0x82, @@ -1551,13 +1601,7 @@ err: } #endif /* OPENSSL_NO_ECX */ -/* - * tst uses indexes 0..3 - * 0 = uncompressed format - * 1 = compressed format - * 2 = affine coordinates via EVP_EC_affine2oct() - */ -static int test_fromdata_ec(int tst) +static int test_fromdata_ec(void) { int ret = 0; EVP_PKEY_CTX *ctx = NULL; @@ -1593,19 +1637,6 @@ static int test_fromdata_ec(int tst) 0x02, 0xa5, 0x77, 0x57, 0xc8, 0xa3, 0x47, 0x73, 0x3a, 0x6a, 0x08, 0x28, 0x39, 0xbd, 0xc9, 0xd2 }; - /* SAME IN AFFINE COORDINATES */ - static const unsigned char x_buf[] = { - 0x1b, 0x93, 0x67, 0x55, 0x1c, 0x55, 0x9f, 0x63, - 0xd1, 0x22, 0xa4, 0xd8, 0xd1, 0x0a, 0x60, 0x6d, - 0x02, 0xa5, 0x77, 0x57, 0xc8, 0xa3, 0x47, 0x73, - 0x3a, 0x6a, 0x08, 0x28, 0x39, 0xbd, 0xc9, 0xd2 - }; - static const unsigned char y_buf[] = { - 0x80, 0xec, 0xe9, 0xa7, 0x08, 0x29, 0x71, 0x2f, - 0xc9, 0x56, 0x82, 0xee, 0x9a, 0x85, 0x0f, 0x6d, - 0x7f, 0x59, 0x5f, 0x8c, 0xd1, 0x96, 0x0b, 0xdf, - 0x29, 0x3e, 0x49, 0x07, 0x88, 0x3f, 0x9a, 0x29 - }; static const unsigned char ec_priv_keydata[] = { 0x33, 0xd0, 0x43, 0x83, 0xa9, 0x89, 0x56, 0x03, 0xd2, 0xd7, 0xfe, 0x6b, 0x01, 0x6f, 0xe4, 0x59, @@ -1623,15 +1654,6 @@ static int test_fromdata_ec(int tst) BIGNUM *a = NULL; BIGNUM *b = NULL; BIGNUM *p = NULL; - OSSL_PARAM probe[2] = { - OSSL_PARAM_DEFN(OSSL_PKEY_PARAM_PRIV_KEY, OSSL_PARAM_UNSIGNED_INTEGER, - NULL, 0), - OSSL_PARAM_END - }; - BIGNUM *x = NULL; - BIGNUM *y = NULL; - unsigned char *buf = NULL; - size_t buflen = 0; if (!TEST_ptr(bld = OSSL_PARAM_BLD_new())) goto err; @@ -1651,35 +1673,11 @@ static int test_fromdata_ec(int tst) * `OSSL_PKEY_PARAM_PUB_KEY` and expect to default to uncompressed * format. */ - switch (tst) { - case 0: - if (!TEST_true(OSSL_PARAM_BLD_push_octet_string(bld, - OSSL_PKEY_PARAM_PUB_KEY, - ec_pub_keydata_compressed, - sizeof(ec_pub_keydata_compressed)))) - goto err; - break; - case 1: - if (!TEST_true(OSSL_PARAM_BLD_push_octet_string(bld, - OSSL_PKEY_PARAM_PUB_KEY, - ec_pub_keydata, sizeof(ec_pub_keydata)))) - goto err; - break; - case 2: - if (!TEST_ptr(x = BN_bin2bn(x_buf, sizeof(x_buf), NULL)) - || !TEST_ptr(y = BN_bin2bn(y_buf, sizeof(y_buf), NULL))) - goto err; - if (!TEST_true(EVP_EC_affine2oct(x, y, 32, &buf, &buflen)) - || !TEST_ptr(buf) - || !TEST_size_t_eq(buflen, 65)) - goto err; - if (!TEST_true(OSSL_PARAM_BLD_push_octet_string(bld, - OSSL_PKEY_PARAM_PUB_KEY, buf, buflen))) - goto err; - break; - default: + if (OSSL_PARAM_BLD_push_octet_string(bld, OSSL_PKEY_PARAM_PUB_KEY, + ec_pub_keydata_compressed, + sizeof(ec_pub_keydata_compressed)) + <= 0) goto err; - } if (OSSL_PARAM_BLD_push_BN(bld, OSSL_PKEY_PARAM_PRIV_KEY, ec_priv_bn) <= 0) goto err; if (!TEST_ptr(fromdata_params = OSSL_PARAM_BLD_to_param(bld))) @@ -1744,18 +1742,6 @@ static int test_fromdata_ec(int tst) || !TEST_BN_eq(group_b, b)) goto err; - /* - * Probe the EC private-key BN length via the explicit-params - * path; with NULL data, return_size receives the required - * (padded) buffer size, which equals the byte length of the - * group order. - */ - probe[0].return_size = OSSL_PARAM_UNMODIFIED; - if (!TEST_true(EVP_PKEY_get_params(pk, probe)) - || !TEST_size_t_eq(probe[0].return_size, - BN_num_bytes(EC_GROUP_get0_order(group)))) - goto err; - EC_GROUP_free(group); group = NULL; BN_free(group_p); @@ -1815,15 +1801,11 @@ err: BN_free(p); BN_free(bn_priv); BN_free(ec_priv_bn); - BN_free(x); - BN_free(y); OSSL_PARAM_free(fromdata_params); OSSL_PARAM_BLD_free(bld); EVP_PKEY_free(pk); EVP_PKEY_free(copy_pk); EVP_PKEY_CTX_free(ctx); - if (buf != NULL) - OPENSSL_free(buf); return ret; } @@ -2308,7 +2290,7 @@ int setup_tests(void) #ifndef OPENSSL_NO_ECX ADD_ALL_TESTS(test_fromdata_ecx, 4 * 3); #endif - ADD_ALL_TESTS(test_fromdata_ec, 3); + ADD_TEST(test_fromdata_ec); ADD_TEST(test_ec_dup_no_operation); ADD_TEST(test_ec_dup_keygen_operation); #endif diff --git a/test/evp_skey_test.c b/test/evp_skey_test.c index 631a5a6287..2e24123a49 100644 --- a/test/evp_skey_test.c +++ b/test/evp_skey_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -38,8 +38,22 @@ static int test_skey_cipher(void) EVP_CIPHER *fake_cipher = NULL; EVP_CIPHER_CTX *ctx = NULL; const unsigned char import_key[KEY_SIZE] = { - 0x53, 0x4B, 0x45, 0x59, 0x53, 0x4B, 0x45, 0x59, 0x53, 0x4B, - 0x45, 0x59, 0x53, 0x4B, 0x45, 0x59 + 0x53, + 0x4B, + 0x45, + 0x59, + 0x53, + 0x4B, + 0x45, + 0x59, + 0x53, + 0x4B, + 0x45, + 0x59, + 0x53, + 0x4B, + 0x45, + 0x59, }; OSSL_PARAM params[3]; OSSL_PARAM *export_params = NULL; @@ -99,8 +113,22 @@ static int test_skey_skeymgmt(void) EVP_SKEYMGMT *skeymgmt = NULL; EVP_SKEY *key = NULL; const unsigned char import_key[KEY_SIZE] = { - 0x53, 0x4B, 0x45, 0x59, 0x53, 0x4B, 0x45, 0x59, 0x53, 0x4B, - 0x45, 0x59, 0x53, 0x4B, 0x45, 0x59 + 0x53, + 0x4B, + 0x45, + 0x59, + 0x53, + 0x4B, + 0x45, + 0x59, + 0x53, + 0x4B, + 0x45, + 0x59, + 0x53, + 0x4B, + 0x45, + 0x59, }; OSSL_PARAM params[2]; const OSSL_PARAM *imp_params; @@ -308,91 +336,6 @@ end: } #endif -static int test_skey_to_same_provider(void) -{ - OSSL_PROVIDER *fake_prov = NULL; - EVP_SKEY *key = NULL, *key2 = NULL; - OSSL_PARAM params[3]; - unsigned char import_key[KEY_SIZE] = { - 0x53, 0x4B, 0x45, 0x59, 0x53, 0x4B, 0x45, 0x59, 0x53, 0x4B, - 0x45, 0x59, 0x53, 0x4B, 0x45, 0x59 - }; - int ret = 0; - - if (!TEST_ptr(fake_prov = fake_cipher_start(libctx))) - goto end; - - params[0] = OSSL_PARAM_construct_utf8_string(FAKE_CIPHER_PARAM_KEY_NAME, - "fake key name", 0); - params[1] = OSSL_PARAM_construct_octet_string(OSSL_SKEY_PARAM_RAW_BYTES, - import_key, sizeof(import_key)); - params[2] = OSSL_PARAM_construct_end(); - - if (!TEST_ptr(key = EVP_SKEY_import(libctx, "fake_cipher", - FAKE_CIPHER_FETCH_PROPS, - OSSL_SKEYMGMT_SELECT_ALL, params))) - goto end; - - if (!TEST_ptr(key2 = EVP_SKEY_to_provider(key, libctx, fake_prov, - FAKE_CIPHER_FETCH_PROPS))) - goto end; - - /* Same provider should return same object with bumped refcount */ - if (!TEST_ptr_eq(key2, key)) - goto end; - - ret = 1; -end: - EVP_SKEY_free(key2); - EVP_SKEY_free(key); - fake_cipher_finish(fake_prov); - return ret; -} - -static int test_skey_to_diff_provider(void) -{ - OSSL_PROVIDER *fake_prov = NULL; - EVP_SKEY *key = NULL, *key2 = NULL; - const unsigned char *export_key = NULL; - size_t export_len; - unsigned char import_key[KEY_SIZE] = { - 0x53, 0x4B, 0x45, 0x59, 0x53, 0x4B, 0x45, 0x59, 0x53, 0x4B, - 0x45, 0x59, 0x53, 0x4B, 0x45, 0x59 - }; - int ret = 0; - - deflprov = OSSL_PROVIDER_load(libctx, "default"); - if (!TEST_ptr(deflprov)) - return 0; - - if (!TEST_ptr(fake_prov = fake_cipher_start(libctx))) - goto end; - - if (!TEST_ptr(key = EVP_SKEY_import_raw_key(libctx, OSSL_SKEY_TYPE_GENERIC, - import_key, sizeof(import_key), NULL))) - goto end; - - if (!TEST_ptr(key2 = EVP_SKEY_to_provider(key, libctx, fake_prov, - FAKE_CIPHER_FETCH_PROPS))) - goto end; - - /* Different provider must return a different object */ - if (!TEST_ptr_ne(key2, key)) - goto end; - - if (!TEST_int_gt(EVP_SKEY_get0_raw_key(key2, &export_key, &export_len), 0) - || !TEST_mem_eq(import_key, sizeof(import_key), export_key, export_len)) - goto end; - - ret = 1; -end: - EVP_SKEY_free(key2); - EVP_SKEY_free(key); - fake_cipher_finish(fake_prov); - OSSL_PROVIDER_unload(deflprov); - return ret; -} - int setup_tests(void) { libctx = OSSL_LIB_CTX_new(); @@ -402,8 +345,6 @@ int setup_tests(void) ADD_TEST(test_skey_cipher); ADD_TEST(test_skey_skeymgmt); - ADD_TEST(test_skey_to_same_provider); - ADD_TEST(test_skey_to_diff_provider); ADD_TEST(test_aes_raw_skey); #ifndef OPENSSL_NO_DES ADD_TEST(test_des_raw_skey); diff --git a/test/evp_test.c b/test/evp_test.c index 77029f40db..a780325523 100644 --- a/test/evp_test.c +++ b/test/evp_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -698,7 +698,9 @@ static int parse_bin_chunk(const char *value, size_t offset, size_t max, **/ typedef struct digest_data_st { - EVP_MD *digest; + /* Digest this test is for */ + const EVP_MD *digest; + EVP_MD *fetched_digest; /* Input to digest */ STACK_OF(EVP_TEST_BUFFER) *input; /* Expected output */ @@ -710,13 +712,13 @@ typedef struct digest_data_st { int xof; /* Size for variable output length but non-XOF */ size_t digest_size; - STACK_OF(OPENSSL_STRING) *controls; /* collection of controls */ } DIGEST_DATA; static int digest_test_init(EVP_TEST *t, const char *alg) { DIGEST_DATA *mdat; - EVP_MD *digest; + const EVP_MD *digest; + EVP_MD *fetched_digest; if (is_digest_disabled(alg)) { TEST_info("skipping, '%s' is disabled", alg); @@ -724,18 +726,19 @@ static int digest_test_init(EVP_TEST *t, const char *alg) return 1; } - if ((digest = EVP_MD_fetch(libctx, alg, propquery)) == NULL) + if ((digest = fetched_digest = EVP_MD_fetch(libctx, alg, propquery)) == NULL + && (digest = EVP_get_digestbyname(alg)) == NULL) return 0; if (!TEST_ptr(mdat = OPENSSL_zalloc(sizeof(*mdat)))) { - EVP_MD_free(digest); + EVP_MD_free(fetched_digest); return 0; } t->data = mdat; mdat->digest = digest; + mdat->fetched_digest = fetched_digest; mdat->pad_type = 0; mdat->xof = 0; - mdat->controls = sk_OPENSSL_STRING_new_null(); - if (digest != NULL) + if (fetched_digest != NULL) TEST_info("%s is fetched", alg); return 1; } @@ -746,8 +749,7 @@ static void digest_test_cleanup(EVP_TEST *t) sk_EVP_TEST_BUFFER_pop_free(mdat->input, evp_test_buffer_free); OPENSSL_free(mdat->output); - EVP_MD_free(mdat->digest); - ctrlfree(mdat->controls); + EVP_MD_free(mdat->fetched_digest); } static int digest_test_parse(EVP_TEST *t, @@ -776,8 +778,6 @@ static int digest_test_parse(EVP_TEST *t, mdata->digest_size = sz; return 1; } - if (strcmp(keyword, "Ctrl") == 0) - return ctrladd(mdata->controls, value); return 0; } @@ -815,9 +815,7 @@ static int digest_test_run(EVP_TEST *t) unsigned int got_len; size_t size = 0; int xof = 0; - OSSL_PARAM params[6], *p = ¶ms[0]; - size_t params_n = 0, params_allocated_n = 0; - const OSSL_PARAM *defined_params = EVP_MD_settable_ctx_params(expected->digest); + OSSL_PARAM params[4], *p = ¶ms[0]; t->err = "TEST_FAILURE"; if (!TEST_ptr(mctx = EVP_MD_CTX_new())) @@ -827,13 +825,6 @@ static int digest_test_run(EVP_TEST *t) if (!TEST_ptr(got)) goto err; - if (sk_OPENSSL_STRING_num(expected->controls) > 0) { - if (!ctrl2params(t, expected->controls, defined_params, - params, OSSL_NELEM(params), ¶ms_n)) - goto err; - p = params + params_n; - } - if (expected->xof > 0) { xof |= 1; *p++ = OSSL_PARAM_construct_size_t(OSSL_DIGEST_PARAM_XOFLEN, @@ -905,7 +896,7 @@ static int digest_test_run(EVP_TEST *t) && !inbuf->count_set) { OPENSSL_cleanse(got, got_len); if (!TEST_true(EVP_Q_digest(libctx, - EVP_MD_get0_name(expected->digest), + EVP_MD_get0_name(expected->fetched_digest), NULL, inbuf->buf, inbuf->buflen, got, &size)) || !TEST_mem_eq(got, size, @@ -916,7 +907,6 @@ static int digest_test_run(EVP_TEST *t) } err: - ctrl2params_free(params, params_n, params_allocated_n); OPENSSL_free(got); EVP_MD_CTX_free(mctx); return 1; @@ -935,7 +925,8 @@ static const EVP_TEST_METHOD digest_test_method = { **/ typedef struct cipher_data_st { - EVP_CIPHER *cipher; + const EVP_CIPHER *cipher; + EVP_CIPHER *fetched_cipher; int enc; /* EVP_CIPH_GCM_MODE, EVP_CIPH_CCM_MODE or EVP_CIPH_OCB_MODE if AEAD */ int aead; @@ -987,7 +978,8 @@ static int cipher_test_valid_fragmentation(CIPHER_DATA *cdat) static int cipher_test_init(EVP_TEST *t, const char *alg) { - EVP_CIPHER *cipher; + const EVP_CIPHER *cipher; + EVP_CIPHER *fetched_cipher; CIPHER_DATA *cdat; int m; @@ -998,7 +990,8 @@ static int cipher_test_init(EVP_TEST *t, const char *alg) } ERR_set_mark(); - if ((cipher = EVP_CIPHER_fetch(libctx, alg, propquery)) == NULL) { + if ((cipher = fetched_cipher = EVP_CIPHER_fetch(libctx, alg, propquery)) == NULL + && (cipher = EVP_get_cipherbyname(alg)) == NULL) { /* a stitched cipher might not be available */ if (strstr(alg, "HMAC") != NULL) { ERR_pop_to_mark(); @@ -1016,6 +1009,7 @@ static int cipher_test_init(EVP_TEST *t, const char *alg) cdat->init_controls = sk_OPENSSL_STRING_new_null(); cdat->cipher = cipher; + cdat->fetched_cipher = fetched_cipher; cdat->enc = -1; m = EVP_CIPHER_get_mode(cipher); if (EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_AEAD_CIPHER) @@ -1025,7 +1019,7 @@ static int cipher_test_init(EVP_TEST *t, const char *alg) if (data_chunk_size != 0 && !cipher_test_valid_fragmentation(cdat)) { ERR_pop_to_mark(); - EVP_CIPHER_free(cipher); + EVP_CIPHER_free(fetched_cipher); OPENSSL_free(cdat); t->skip = 1; TEST_info("skipping, '%s' does not support fragmentation", alg); @@ -1033,7 +1027,7 @@ static int cipher_test_init(EVP_TEST *t, const char *alg) } t->data = cdat; - if (cipher != NULL) + if (fetched_cipher != NULL) TEST_info("%s is fetched", alg); return 1; } @@ -1052,7 +1046,7 @@ static void cipher_test_cleanup(EVP_TEST *t) OPENSSL_free(cdat->aad[i]); OPENSSL_free(cdat->tag); OPENSSL_free(cdat->mac_key); - EVP_CIPHER_free(cdat->cipher); + EVP_CIPHER_free(cdat->fetched_cipher); ctrlfree(cdat->init_controls); } @@ -1273,23 +1267,18 @@ static int cipher_test_enc(EVP_TEST *t, int enc, size_t out_misalign, if (expected->iv != NULL) { /* Some (e.g., GCM) tests use IVs longer than EVP_MAX_IV_LENGTH. */ unsigned char iv[128]; - - ERR_set_mark(); if (!TEST_true(EVP_CIPHER_CTX_get_updated_iv(ctx_base, iv, sizeof(iv))) || ((EVP_CIPHER_get_flags(expected->cipher) & EVP_CIPH_CUSTOM_IV) == 0 && !TEST_mem_eq(expected->iv, expected->iv_len, iv, expected->iv_len))) { t->err = "INVALID_IV"; - ERR_clear_last_mark(); goto err; } else { - if (fips_no_silent_error && !TEST_int_eq(ERR_count_to_mark(), 0)) { + if (fips_no_silent_error && !TEST_false(ERR_peek_error())) { t->err = "GET_UPDATED_IV_SILENT_ERROR"; - ERR_clear_last_mark(); goto err; } } - ERR_clear_last_mark(); } /* Test that the cipher dup functions correctly if it is supported */ @@ -1576,21 +1565,17 @@ static int cipher_test_enc(EVP_TEST *t, int enc, size_t out_misalign, if (expected->next_iv != NULL) { /* Some (e.g., GCM) tests use IVs longer than EVP_MAX_IV_LENGTH. */ unsigned char iv[128]; - ERR_set_mark(); if (!TEST_true(EVP_CIPHER_CTX_get_updated_iv(ctx, iv, sizeof(iv))) || !TEST_mem_eq(expected->next_iv, expected->iv_len, iv, expected->iv_len)) { t->err = "INVALID_NEXT_IV"; - ERR_clear_last_mark(); goto err; } else { - if (fips_no_silent_error && !TEST_int_eq(ERR_count_to_mark(), 0)) { + if (fips_no_silent_error && !TEST_false(ERR_peek_error())) { t->err = "GET_UPDATED_IV_SILENT_ERROR"; - ERR_clear_last_mark(); goto err; } } - ERR_clear_last_mark(); } t->err = NULL; @@ -2592,7 +2577,6 @@ typedef struct pkey_data_st { size_t output_len; STACK_OF(OPENSSL_STRING) *init_controls; /* collection of controls */ STACK_OF(OPENSSL_STRING) *controls; /* collection of controls */ - STACK_OF(OPENSSL_STRING) *mu_controls; /* collection of controls */ EVP_PKEY *peer; int validate; } PKEY_DATA; @@ -2651,7 +2635,6 @@ static int pkey_test_init(EVP_TEST *t, const char *name, kdata->keyop = keyop; kdata->init_controls = sk_OPENSSL_STRING_new_null(); kdata->controls = sk_OPENSSL_STRING_new_null(); - kdata->mu_controls = sk_OPENSSL_STRING_new_null(); return 1; } @@ -2696,7 +2679,6 @@ static int pkey_test_init_ex2(EVP_TEST *t, const char *name, } kdata->init_controls = sk_OPENSSL_STRING_new_null(); kdata->controls = sk_OPENSSL_STRING_new_null(); - kdata->mu_controls = sk_OPENSSL_STRING_new_null(); return 1; } @@ -2704,7 +2686,6 @@ static void pkey_test_cleanup(EVP_TEST *t) { PKEY_DATA *kdata = t->data; - ctrlfree(kdata->mu_controls); ctrlfree(kdata->init_controls); ctrlfree(kdata->controls); OPENSSL_free(kdata->input); @@ -2746,7 +2727,7 @@ static int pkey_test_ctrl(EVP_TEST *t, EVP_PKEY_CTX *pctx, static int pkey_add_control(EVP_TEST *t, STACK_OF(OPENSSL_STRING) *controls, const char *value) { - const char *p; + char *p; if (controls == NULL) return 0; @@ -2776,8 +2757,6 @@ static int pkey_test_parse(EVP_TEST *t, return ctrladd(kdata->init_controls, value); if (strcmp(keyword, "Ctrl") == 0) return pkey_add_control(t, kdata->controls, value); - if (strcmp(keyword, "CtrlMu") == 0) - return ctrladd(kdata->mu_controls, value); return 0; } @@ -2826,160 +2805,16 @@ err: return ret; } -/* Calculate ML-DSA-MU.prehash() */ -static int calculate_mu(const uint8_t *pub, size_t publen, - const uint8_t *ctx, size_t ctxlen, const uint8_t *msg, size_t msglen, - const char *digestname, uint8_t *out, size_t outlen) -{ - EVP_MD_CTX *mdctx = NULL; - EVP_MD *md = NULL; - OSSL_PARAM params[4], *p = params; - int ret = 0; - size_t len; - - if (pub == NULL || publen == 0) - return 0; - *p++ = OSSL_PARAM_construct_octet_string(OSSL_DIGEST_PARAM_MU_PUB_KEY, (uint8_t *)pub, publen); - if (ctx != NULL && ctxlen > 0) - *p++ = OSSL_PARAM_construct_octet_string(OSSL_DIGEST_PARAM_MU_CONTEXT_STRING, - (uint8_t *)ctx, ctxlen); - if (digestname != NULL) - *p++ = OSSL_PARAM_construct_utf8_string(OSSL_DIGEST_PARAM_MU_DIGEST, (char *)digestname, 0); - *p = OSSL_PARAM_construct_end(); - - if (!TEST_ptr(mdctx = EVP_MD_CTX_new()) - || !TEST_ptr(md = EVP_MD_fetch(libctx, "ML-DSA-MU", NULL)) - || !TEST_true(EVP_DigestInit_ex2(mdctx, md, params))) - goto err; - /* stream the message */ - while (msglen > 0) { - len = (msglen >= 15 ? 15 : msglen); - if (!TEST_true(EVP_DigestUpdate(mdctx, msg, len))) - goto err; - msg += len; - msglen -= len; - } - if (!TEST_true(EVP_DigestFinalXOF(mdctx, out, outlen))) - goto err; - ret = 1; -err: - EVP_MD_free(md); - EVP_MD_CTX_free(mdctx); - return ret; -} - -static int pkey_calculate_mu(EVP_TEST *t, uint8_t *mu, size_t *mulen) -{ - int ret = 0; - OSSL_PARAM *p = NULL; - static const OSSL_PARAM mu_digest_settable_ctx_params[] = { - OSSL_PARAM_octet_string(OSSL_SIGNATURE_PARAM_CONTEXT_STRING, NULL, 0), - OSSL_PARAM_utf8_string(OSSL_ALG_PARAM_DIGEST, NULL, 0), - OSSL_PARAM_END - }; - OSSL_PARAM params[3] = { - OSSL_PARAM_END, - OSSL_PARAM_END, - OSSL_PARAM_END, - }; - size_t params_n = 0; - uint8_t pub[3 * 1024]; - size_t publen = 0; - uint8_t *ctx = NULL; - size_t ctxlen = 0; - const char *digestname = NULL; - PKEY_DATA *kdata = t->data; - EVP_PKEY *key = EVP_PKEY_CTX_get0_pkey(kdata->ctx); - uint8_t *in = kdata->input; - size_t inlen = kdata->input_len; - uint8_t digest[64]; - EVP_MD_CTX *mdctx = NULL; - EVP_MD *md = NULL; - - if (sk_OPENSSL_STRING_num(kdata->mu_controls) > 0) { - if (!ctrl2params(t, kdata->mu_controls, mu_digest_settable_ctx_params, - params, OSSL_NELEM(params), ¶ms_n)) - goto err; - } - p = OSSL_PARAM_locate(params, OSSL_DIGEST_PARAM_MU_CONTEXT_STRING); - if (p != NULL) { - ctx = p->data; - ctxlen = p->data_size; - } - p = OSSL_PARAM_locate(params, OSSL_DIGEST_PARAM_MU_DIGEST); - if (p != NULL && p->data != NULL) { - /* - * If we are prehashing then calculate the hash of the kdata->input and - * set this as the new input - */ - size_t xoflen = 0; - unsigned int len = 0; - - digestname = p->data; - mdctx = EVP_MD_CTX_new(); - if (mdctx == NULL) - goto err; - md = EVP_MD_fetch(libctx, digestname, NULL); - if (md == NULL) - goto err; - if (!EVP_DigestInit(mdctx, md) - || !EVP_DigestUpdate(mdctx, in, inlen)) - goto err; - /* Deal with the SHAKE algorithm not setting a default xoflen */ - if (EVP_MD_is_a(md, "SHAKE128")) - xoflen = 32; - else if (EVP_MD_is_a(md, "SHAKE256")) - xoflen = 64; - if (xoflen != 0) { - len = (unsigned int)xoflen; - if (!EVP_DigestFinalXOF(mdctx, digest, xoflen)) - goto err; - } else { - if (!EVP_DigestFinal(mdctx, digest, &len)) - goto err; - } - in = digest; - inlen = len; - } - - if (!TEST_true(EVP_PKEY_get_octet_string_param(key, OSSL_PKEY_PARAM_PUB_KEY, - pub, sizeof(pub), &publen))) - goto err; - - if (!TEST_true(calculate_mu(pub, publen, ctx, ctxlen, in, inlen, - digestname, mu, *mulen))) - goto err; - ret = 1; -err: - EVP_MD_free(md); - EVP_MD_CTX_free(mdctx); - ctrl2params_free(params, params_n, 0); - return ret; -} - static int pkey_test_run(EVP_TEST *t) { PKEY_DATA *expected = t->data; unsigned char *got = NULL; size_t got_len; EVP_PKEY_CTX *copy = NULL; - uint8_t mu[64]; - size_t mulen = sizeof(mu); - const uint8_t *in = expected->input; - size_t inlen = expected->input_len; if (!pkey_test_run_init(t)) goto err; - if (sk_OPENSSL_STRING_num(expected->mu_controls) > 0) { - if (!pkey_calculate_mu(t, mu, &mulen)) { - t->err = "KEYOP_MU_ERROR"; - goto err; - } - in = mu; - inlen = mulen; - } - if (!pkey_check_security_category(t, EVP_PKEY_CTX_get0_pkey(expected->ctx))) goto err; @@ -2989,12 +2824,16 @@ static int pkey_test_run(EVP_TEST *t) goto err; } - if (expected->keyop(expected->ctx, NULL, &got_len, in, inlen) <= 0 + if (expected->keyop(expected->ctx, NULL, &got_len, + expected->input, expected->input_len) + <= 0 || !TEST_ptr(got = OPENSSL_malloc(got_len))) { t->err = "KEYOP_LENGTH_ERROR"; goto err; } - if (expected->keyop(expected->ctx, got, &got_len, in, inlen) <= 0) { + if (expected->keyop(expected->ctx, got, &got_len, + expected->input, expected->input_len) + <= 0) { t->err = "KEYOP_ERROR"; goto err; } @@ -3009,12 +2848,16 @@ static int pkey_test_run(EVP_TEST *t) got = NULL; /* Repeat the test on the EVP_PKEY context copy. */ - if (expected->keyop(copy, NULL, &got_len, in, inlen) <= 0 + if (expected->keyop(copy, NULL, &got_len, expected->input, + expected->input_len) + <= 0 || !TEST_ptr(got = OPENSSL_malloc(got_len))) { t->err = "KEYOP_LENGTH_ERROR"; goto err; } - if (expected->keyop(copy, got, &got_len, in, inlen) <= 0) { + if (expected->keyop(copy, got, &got_len, expected->input, + expected->input_len) + <= 0) { t->err = "KEYOP_ERROR"; goto err; } @@ -3541,7 +3384,7 @@ static int pbe_test_run(EVP_TEST *t) { PBE_DATA *expected = t->data; unsigned char *key; - EVP_MD *digest = NULL; + EVP_MD *fetched_digest = NULL; OSSL_LIB_CTX *save_libctx; save_libctx = OSSL_LIB_CTX_set0_default(libctx); @@ -3571,16 +3414,16 @@ static int pbe_test_run(EVP_TEST *t) } #endif } else if (expected->pbe_type == PBE_TYPE_PKCS12) { - digest = EVP_MD_fetch(libctx, EVP_MD_get0_name(expected->md), + fetched_digest = EVP_MD_fetch(libctx, EVP_MD_get0_name(expected->md), propquery); - if (digest == NULL) { + if (fetched_digest == NULL) { t->err = "PKCS12_ERROR"; goto err; } if (PKCS12_key_gen_uni(expected->pass, (int)expected->pass_len, expected->salt, (int)expected->salt_len, expected->id, expected->iter, (int)expected->key_len, - key, digest) + key, fetched_digest) == 0) { t->err = "PKCS12_ERROR"; goto err; @@ -3592,7 +3435,7 @@ static int pbe_test_run(EVP_TEST *t) t->err = NULL; err: - EVP_MD_free(digest); + EVP_MD_free(fetched_digest); OPENSSL_free(key); OSSL_LIB_CTX_set0_default(save_libctx); return 1; @@ -4151,7 +3994,7 @@ static int kdf_test_ctrl(EVP_TEST *t, EVP_KDF_CTX *kctx, KDF_DATA *kdata = t->data; int rv; char *p, *name; - const OSSL_PARAM *defs = EVP_KDF_settable_ctx_params(EVP_KDF_CTX_get0_kdf(kctx)); + const OSSL_PARAM *defs = EVP_KDF_settable_ctx_params(EVP_KDF_CTX_kdf(kctx)); if (!TEST_ptr(name = OPENSSL_strdup(value))) return 0; @@ -5448,16 +5291,8 @@ top: pkey = NULL; start: if (strcmp(pp->key, "PrivateKey") == 0) { - int unsupported = 0; - pkey = PEM_read_bio_PrivateKey_ex(t->s.key, NULL, 0, NULL, libctx, NULL); - if (pkey == NULL) - unsupported = key_unsupported(); -#ifdef OPENSSL_NO_EC_EXPLICIT_CURVES - if (strcmp(pp->value, "EC_EXPLICIT") == 0) - unsupported = 1; -#endif - if (pkey == NULL && !unsupported) { + if (pkey == NULL && !key_unsupported()) { EVP_PKEY_free(pkey); TEST_info("Can't read private key %s", pp->value); TEST_openssl_errors(); diff --git a/test/evp_xof_test.c b/test/evp_xof_test.c index ab86e29a7b..76eb3539dd 100644 --- a/test/evp_xof_test.c +++ b/test/evp_xof_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -13,7 +13,7 @@ #include "testutil.h" #include "internal/nelem.h" -static const uint8_t shake256_input[] = { +static const unsigned char shake256_input[] = { 0x8d, 0x80, 0x01, 0xe2, 0xc0, 0x96, 0xf1, 0xb8, 0x8e, 0x7c, 0x92, 0x24, 0xa0, 0x86, 0xef, 0xd4, 0x79, 0x7f, 0xbf, 0x74, 0xa8, 0x03, 0x3a, 0x2d, @@ -24,7 +24,7 @@ static const uint8_t shake256_input[] = { * This KAT output is 250 bytes, which is more than * the SHAKE256 block size (136 bytes). */ -static const uint8_t shake256_output[] = { +static const unsigned char shake256_output[] = { 0x2e, 0x97, 0x5f, 0x6a, 0x8a, 0x14, 0xf0, 0x70, 0x4d, 0x51, 0xb1, 0x36, 0x67, 0xd8, 0x19, 0x5c, 0x21, 0x9f, 0x71, 0xe6, 0x34, 0x56, 0x96, 0xc4, @@ -59,52 +59,6 @@ static const uint8_t shake256_output[] = { 0x66, 0x6c }; -static const uint8_t cshake256_output[] = { - 0x30, 0xa6, 0x5f, 0xd5, 0xff, 0x3e, 0x49, 0xe8, - 0xa9, 0xef, 0x06, 0xa3, 0x56, 0x4b, 0x4f, 0x55, - 0x93, 0x0f, 0x4a, 0x9e, 0xe9, 0x74, 0x13, 0xf8, - 0x4a, 0x80, 0x44, 0x65, 0xec, 0x62, 0x83, 0x7a, - 0x21, 0xce, 0x96, 0x0e, 0x27, 0x1f, 0x81, 0x26, - 0xcb, 0xd8, 0x42, 0x7b, 0x7d, 0x71, 0x6a, 0xdc, - 0xaf, 0x4d, 0x13, 0x52, 0x28, 0x2b, 0xd9, 0x70, - 0xfb, 0x90, 0x96, 0xfe, 0x24, 0xd2, 0x22, 0x48, - 0x73, 0xae, 0x73, 0x1e, 0x10, 0x07, 0x4b, 0x92, - 0x2a, 0xae, 0x1e, 0x7b, 0x7d, 0x06, 0xe2, 0x0f, - 0x80, 0x08, 0xc3, 0xa5, 0x09, 0x71, 0x57, 0x84, - 0x4a, 0xa8, 0x70, 0xe7, 0x61, 0x6b, 0x0c, 0x3c -}; - -typedef struct test_data_st { - const char *alg; - const uint8_t *in; - size_t inlen; - const uint8_t *out; - size_t outlen; - int default_xoflen; - const char *param_n; - const char *param_s; -} TEST_DATA; - -static const TEST_DATA xof_test_data[] = { - { - "SHAKE256", - shake256_input, - sizeof(shake256_input), - shake256_output, - sizeof(shake256_output), - }, - { "CSHAKE256", - shake256_input, sizeof(shake256_input), - shake256_output, sizeof(shake256_output), - 64 }, - { "CSHAKE256", - shake256_input, sizeof(shake256_input), - cshake256_output, sizeof(cshake256_output), - 64, - "KMAC", - "Custom" }, -}; - static const unsigned char shake256_largemsg_input[] = { 0xb2, 0xd2, 0x38, 0x65, 0xaf, 0x8f, 0x25, 0x6e, 0x64, 0x40, 0xe2, 0x0d, 0x49, 0x8e, 0x3e, 0x64, @@ -195,39 +149,51 @@ static const unsigned char shake256_largemsg_input[] = { }; static const unsigned char shake256_largemsg_output[] = { - 0x64, 0xea, 0x24, 0x6a, 0xab, 0x80, 0x37, 0x9e, - 0x08, 0xe2, 0x19, 0x9e, 0x09, 0x69, 0xe2, 0xee, - 0x1a, 0x5d, 0xd1, 0x68, 0x68, 0xec, 0x8d, 0x42, - 0xd0, 0xf8, 0xb8, 0x44, 0x74, 0x54, 0x87, 0x3e + 0x64, + 0xea, + 0x24, + 0x6a, + 0xab, + 0x80, + 0x37, + 0x9e, + 0x08, + 0xe2, + 0x19, + 0x9e, + 0x09, + 0x69, + 0xe2, + 0xee, + 0x1a, + 0x5d, + 0xd1, + 0x68, + 0x68, + 0xec, + 0x8d, + 0x42, + 0xd0, + 0xf8, + 0xb8, + 0x44, + 0x74, + 0x54, + 0x87, + 0x3e, }; -static const TEST_DATA large_msg_test_data[] = { - { - "SHAKE256", - shake256_largemsg_input, - sizeof(shake256_largemsg_input), - shake256_largemsg_output, - sizeof(shake256_largemsg_output), - }, -}; - -static EVP_MD_CTX *xof_digest_setup(const TEST_DATA *td) +static EVP_MD_CTX *shake_setup(const char *name) { EVP_MD_CTX *ctx = NULL; EVP_MD *md = NULL; - OSSL_PARAM params[3], *p = params; - if (!TEST_ptr(md = EVP_MD_fetch(NULL, td->alg, NULL))) + if (!TEST_ptr(md = EVP_MD_fetch(NULL, name, NULL))) return NULL; if (!TEST_ptr(ctx = EVP_MD_CTX_new())) goto err; - if (td->param_n != NULL) - *p++ = OSSL_PARAM_construct_utf8_string(OSSL_DIGEST_PARAM_FUNCTION_NAME, (char *)td->param_n, 0); - if (td->param_s != NULL) - *p++ = OSSL_PARAM_construct_utf8_string(OSSL_DIGEST_PARAM_CUSTOMIZATION, (char *)td->param_s, 0); - *p = OSSL_PARAM_construct_end(); - if (!TEST_true(EVP_DigestInit_ex2(ctx, md, params))) + if (!TEST_true(EVP_DigestInit_ex2(ctx, md, NULL))) goto err; EVP_MD_free(md); return ctx; @@ -237,24 +203,23 @@ err: return NULL; } -static int xof_kat_test(int tstid) +static int shake_kat_test(void) { - const TEST_DATA *td = xof_test_data + tstid; int ret = 0; EVP_MD_CTX *ctx = NULL; - uint8_t out[2048]; + unsigned char out[sizeof(shake256_output)]; - if (!TEST_size_t_le(td->outlen, sizeof(out))) + if (!TEST_ptr(ctx = shake_setup("SHAKE256"))) return 0; - if (!TEST_ptr(ctx = xof_digest_setup(td))) - return 0; - if (!TEST_true(EVP_DigestUpdate(ctx, td->in, td->inlen)) - || !TEST_true(EVP_DigestFinalXOF(ctx, out, td->outlen)) - || !TEST_mem_eq(out, td->outlen, td->out, td->outlen) + if (!TEST_true(EVP_DigestUpdate(ctx, shake256_input, + sizeof(shake256_input))) + || !TEST_true(EVP_DigestFinalXOF(ctx, out, sizeof(out))) + || !TEST_mem_eq(out, sizeof(out), + shake256_output, sizeof(shake256_output)) /* Test that a second call to EVP_DigestFinalXOF fails */ - || !TEST_false(EVP_DigestFinalXOF(ctx, out, td->outlen)) + || !TEST_false(EVP_DigestFinalXOF(ctx, out, sizeof(out))) /* Test that a call to EVP_DigestSqueeze fails */ - || !TEST_false(EVP_DigestSqueeze(ctx, out, td->outlen))) + || !TEST_false(EVP_DigestSqueeze(ctx, out, sizeof(out)))) goto err; ret = 1; err: @@ -262,52 +227,37 @@ err: return ret; } -static int xof_kat_digestfinal_test(int tstid) +static int shake_kat_digestfinal_test(void) { - const TEST_DATA *td = xof_test_data + tstid; int ret = 0; unsigned int digest_length = 0; EVP_MD_CTX *ctx = NULL; - uint8_t out[2048]; + unsigned char out[sizeof(shake256_output)]; - if (!TEST_size_t_le(td->outlen, sizeof(out))) + /* Test that EVP_DigestFinal without setting XOFLEN fails */ + if (!TEST_ptr(ctx = shake_setup("SHAKE256"))) return 0; - if (!TEST_ptr(ctx = xof_digest_setup(td))) + if (!TEST_true(EVP_DigestUpdate(ctx, shake256_input, + sizeof(shake256_input)))) + return 0; + ERR_set_mark(); + if (!TEST_false(EVP_DigestFinal(ctx, out, &digest_length))) { + ERR_clear_last_mark(); return 0; - if (!TEST_true(EVP_DigestUpdate(ctx, td->in, td->inlen))) - goto err; - if (td->default_xoflen == 0) { - /* - * Test that EVP_DigestFinal without setting XOFLEN fails for SHAKE - * (The original code for SHAKE set the wrong default value which is - * why the XOF needs to be set for this). - */ - ERR_set_mark(); - if (!TEST_false(EVP_DigestFinal(ctx, out, &digest_length))) { - ERR_clear_last_mark(); - goto err; - } - ERR_pop_to_mark(); - } else { - /* - * Test that EVP_DigestFinal without setting XOFLEN passes for CSHAKE - * and correctly returns 2 * 256 = 512 bits (64 bytes) by default. - */ - if (!TEST_true(EVP_DigestFinal(ctx, out, &digest_length)) - || !TEST_uint_eq(digest_length, td->default_xoflen) - || !TEST_mem_eq(out, digest_length, td->out, digest_length)) - goto err; } + ERR_pop_to_mark(); EVP_MD_CTX_free(ctx); - /* EVP_DigestFinalXOF must work */ - if (!TEST_ptr(ctx = xof_digest_setup(td))) + /* However EVP_DigestFinalXOF must work */ + if (!TEST_ptr(ctx = shake_setup("SHAKE256"))) return 0; - if (!TEST_true(EVP_DigestUpdate(ctx, td->in, td->inlen))) - goto err; - if (!TEST_true(EVP_DigestFinalXOF(ctx, out, td->outlen)) - || !TEST_mem_eq(out, td->outlen, td->out, td->outlen) - || !TEST_false(EVP_DigestFinalXOF(ctx, out, td->outlen))) + if (!TEST_true(EVP_DigestUpdate(ctx, shake256_input, + sizeof(shake256_input)))) + return 0; + if (!TEST_true(EVP_DigestFinalXOF(ctx, out, sizeof(out))) + || !TEST_mem_eq(out, sizeof(out), + shake256_output, sizeof(shake256_output)) + || !TEST_false(EVP_DigestFinalXOF(ctx, out, sizeof(out)))) goto err; ret = 1; err: @@ -319,37 +269,35 @@ err: * Test that EVP_DigestFinal() returns the output length * set by the OSSL_DIGEST_PARAM_XOFLEN param. */ -static int xof_kat_digestfinal_xoflen_test(int tstid) +static int shake_kat_digestfinal_xoflen_test(void) { - const TEST_DATA *td = xof_test_data + tstid; int ret = 0; unsigned int digest_length = 0; EVP_MD_CTX *ctx = NULL; const EVP_MD *md; + unsigned char out[sizeof(shake256_output)]; OSSL_PARAM params[2]; size_t sz = 12; - uint8_t out[2048]; - if (!TEST_size_t_le(td->outlen, sizeof(out))) + if (!TEST_ptr(ctx = shake_setup("SHAKE256"))) return 0; - if (!TEST_ptr(ctx = xof_digest_setup(td))) - return 0; - md = EVP_MD_CTX_get0_md(ctx); - memset(out, 0, td->outlen); + memset(out, 0, sizeof(out)); params[0] = OSSL_PARAM_construct_size_t(OSSL_DIGEST_PARAM_XOFLEN, &sz); params[1] = OSSL_PARAM_construct_end(); - if (!TEST_int_eq(EVP_MD_CTX_size(ctx), td->default_xoflen == 0 ? -1 : td->default_xoflen) + if (!TEST_int_eq(EVP_MD_CTX_size(ctx), -1) || !TEST_int_eq(EVP_MD_CTX_set_params(ctx, params), 1) || !TEST_int_eq(EVP_MD_CTX_size(ctx), (int)sz) - || !TEST_int_eq(EVP_MD_get_size(md), td->default_xoflen) + || !TEST_int_eq(EVP_MD_get_size(md), 0) || !TEST_true(EVP_MD_xof(md)) - || !TEST_true(EVP_DigestUpdate(ctx, td->in, td->inlen)) + || !TEST_true(EVP_DigestUpdate(ctx, shake256_input, + sizeof(shake256_input))) || !TEST_true(EVP_DigestFinal(ctx, out, &digest_length)) || !TEST_uint_eq(digest_length, (unsigned int)sz) - || !TEST_mem_eq(out, digest_length, td->out, digest_length) + || !TEST_mem_eq(out, digest_length, + shake256_output, digest_length) || !TEST_uchar_eq(out[digest_length], 0)) goto err; ret = 1; @@ -362,18 +310,15 @@ err: * Test that multiple absorb calls gives the expected result. * This is a nested test that uses multiple strides for the input. */ -static int xof_absorb_test(int tstid) +static int shake_absorb_test(void) { - const TEST_DATA *td = large_msg_test_data + tstid; int ret = 0; EVP_MD_CTX *ctx = NULL; - unsigned char out[2048]; - size_t total = td->inlen; + unsigned char out[sizeof(shake256_largemsg_output)]; + size_t total = sizeof(shake256_largemsg_input); size_t i, stride, sz; - if (!TEST_size_t_le(td->outlen, sizeof(out))) - return 0; - if (!TEST_ptr(ctx = xof_digest_setup(td))) + if (!TEST_ptr(ctx = shake_setup("SHAKE256"))) return 0; for (stride = 1; stride < total; ++stride) { @@ -382,11 +327,14 @@ static int xof_absorb_test(int tstid) sz += stride; if ((i + sz) > total) sz = total - i; - if (!TEST_true(EVP_DigestUpdate(ctx, td->in + i, sz))) + if (!TEST_true(EVP_DigestUpdate(ctx, shake256_largemsg_input + i, + sz))) goto err; } - if (!TEST_true(EVP_DigestFinalXOF(ctx, out, td->outlen)) - || !TEST_mem_eq(out, td->outlen, td->out, td->outlen)) + if (!TEST_true(EVP_DigestFinalXOF(ctx, out, sizeof(out))) + || !TEST_mem_eq(out, sizeof(out), + shake256_largemsg_output, + sizeof(shake256_largemsg_output))) goto err; if (!TEST_true(EVP_DigestInit_ex2(ctx, NULL, NULL))) goto err; @@ -401,11 +349,9 @@ err: * Table containing the size of the output to squeeze for the * initially call, followed by a size for each subsequent call. */ -typedef struct stride_test_data_st { +static const struct { size_t startsz, incsz; -} STRIDE_TEST_DATA; - -static const STRIDE_TEST_DATA stride_test_data[] = { +} stride_tests[] = { { 1, 1 }, { 1, 136 }, { 1, 136 / 2 }, @@ -448,18 +394,17 @@ static const STRIDE_TEST_DATA stride_test_data[] = { * in and inlen represent the input to absorb. expected_out and expected_outlen * represent the expected output. */ -static int do_xof_squeeze_test(const TEST_DATA *td, - const STRIDE_TEST_DATA *stride, - const uint8_t *in, size_t inlen, - const uint8_t *expected_out, +static int do_shake_squeeze_test(int tst, + const unsigned char *in, size_t inlen, + const unsigned char *expected_out, size_t expected_outlen) { int ret = 0; EVP_MD_CTX *ctx = NULL; unsigned char *out = NULL; - size_t i = 0, sz = stride->startsz; + size_t i = 0, sz = stride_tests[tst].startsz; - if (!TEST_ptr(ctx = xof_digest_setup(td))) + if (!TEST_ptr(ctx = shake_setup("SHAKE256"))) return 0; if (!TEST_ptr(out = OPENSSL_malloc(expected_outlen))) goto err; @@ -472,7 +417,7 @@ static int do_xof_squeeze_test(const TEST_DATA *td, if (!TEST_true(EVP_DigestSqueeze(ctx, out + i, sz))) goto err; i += sz; - sz = stride->incsz; + sz = stride_tests[tst].incsz; } if (!TEST_mem_eq(out, expected_outlen, expected_out, expected_outlen)) goto err; @@ -483,12 +428,10 @@ err: return ret; } -static int xof_squeeze_kat_test(int tstid) +static int shake_squeeze_kat_test(int tst) { - const STRIDE_TEST_DATA *sd = stride_test_data + tstid; - const TEST_DATA *td = xof_test_data + (tstid % (OSSL_NELEM(xof_test_data))); - - return do_xof_squeeze_test(td, sd, td->in, td->inlen, td->out, td->outlen); + return do_shake_squeeze_test(tst, shake256_input, sizeof(shake256_input), + shake256_output, sizeof(shake256_output)); } /* @@ -497,42 +440,42 @@ static int xof_squeeze_kat_test(int tstid) * output. Use this to test that multiple squeeze calls * on the same input gives the same output. */ -static int xof_squeeze_large_test(int tstid) +static int shake_squeeze_large_test(int tst) { - const STRIDE_TEST_DATA *sd = stride_test_data + tstid; - const TEST_DATA *td = xof_test_data + (tstid % (OSSL_NELEM(xof_test_data))); int ret = 0; EVP_MD_CTX *ctx = NULL; unsigned char msg[16]; unsigned char out[2000]; if (!TEST_int_gt(RAND_bytes(msg, sizeof(msg)), 0) - || !TEST_ptr(ctx = xof_digest_setup(td)) + || !TEST_ptr(ctx = shake_setup("SHAKE256")) || !TEST_true(EVP_DigestUpdate(ctx, msg, sizeof(msg))) || !TEST_true(EVP_DigestFinalXOF(ctx, out, sizeof(out)))) goto err; - ret = do_xof_squeeze_test(td, sd, msg, sizeof(msg), out, sizeof(out)); + ret = do_shake_squeeze_test(tst, msg, sizeof(msg), out, sizeof(out)); err: EVP_MD_CTX_free(ctx); return ret; } -static const size_t dupoffset_test_data[] = { +static const size_t dupoffset_tests[] = { 1, 135, 136, 137, 136 * 3 - 1, 136 * 3, 136 * 3 + 1 }; /* Helper function to test that EVP_MD_CTX_dup() copies the internal state */ -static int do_xof_squeeze_dup_test(const TEST_DATA *td, size_t dupoffset, - const uint8_t *in, size_t inlen, - const uint8_t *expected_out, size_t expected_outlen) +static int do_shake_squeeze_dup_test(int tst, const char *alg, + const unsigned char *in, size_t inlen, + const unsigned char *expected_out, + size_t expected_outlen) { int ret = 0; EVP_MD_CTX *cur, *ctx = NULL, *dupctx = NULL; unsigned char *out = NULL; size_t i = 0, sz = 10; + size_t dupoffset = dupoffset_tests[tst]; - if (!TEST_ptr(ctx = xof_digest_setup(td))) + if (!TEST_ptr(ctx = shake_setup(alg))) return 0; cur = ctx; if (!TEST_ptr(out = OPENSSL_malloc(expected_outlen))) @@ -564,22 +507,21 @@ err: } /* Test that the internal state can be copied */ -static int xof_squeeze_dup_test(int tstid) +static int shake_squeeze_dup_test(int tst) { - size_t dupoffset = dupoffset_test_data[tstid]; - const TEST_DATA *td = xof_test_data + (tstid % (OSSL_NELEM(xof_test_data))); int ret = 0; EVP_MD_CTX *ctx = NULL; unsigned char msg[16]; unsigned char out[1000]; + const char *alg = "SHAKE128"; if (!TEST_int_gt(RAND_bytes(msg, sizeof(msg)), 0) - || !TEST_ptr(ctx = xof_digest_setup(td)) + || !TEST_ptr(ctx = shake_setup(alg)) || !TEST_true(EVP_DigestUpdate(ctx, msg, sizeof(msg))) || !TEST_true(EVP_DigestFinalXOF(ctx, out, sizeof(out)))) goto err; - ret = do_xof_squeeze_dup_test(td, dupoffset, msg, sizeof(msg), + ret = do_shake_squeeze_dup_test(tst, alg, msg, sizeof(msg), out, sizeof(out)); err: EVP_MD_CTX_free(ctx); @@ -587,29 +529,30 @@ err: } /* Test that a squeeze without a preceding absorb works */ -static int xof_squeeze_no_absorb_test(int tstid) +static int shake_squeeze_no_absorb_test(void) { - const TEST_DATA *td = xof_test_data + tstid; int ret = 0; - EVP_MD_CTX *ctx = NULL, *ctx2 = NULL; + EVP_MD_CTX *ctx = NULL; unsigned char out[1000]; unsigned char out2[1000]; + const char *alg = "SHAKE128"; - memset(out, 0, sizeof(out)); - memset(out2, 0, sizeof(out2)); - if (!TEST_ptr(ctx = xof_digest_setup(td)) - || !TEST_ptr(ctx2 = EVP_MD_CTX_dup(ctx)) - || !TEST_true(EVP_DigestFinalXOF(ctx, out, sizeof(out))) - || !TEST_true(EVP_DigestSqueeze(ctx2, out2, sizeof(out2) / 2)) - || !TEST_true(EVP_DigestSqueeze(ctx2, out2 + sizeof(out2) / 2, - sizeof(out2) / 2)) - || !TEST_mem_eq(out2, sizeof(out2), out, sizeof(out))) + if (!TEST_ptr(ctx = shake_setup(alg)) + || !TEST_true(EVP_DigestFinalXOF(ctx, out, sizeof(out)))) + goto err; + + if (!TEST_true(EVP_DigestInit_ex2(ctx, NULL, NULL)) + || !TEST_true(EVP_DigestSqueeze(ctx, out2, sizeof(out2) / 2)) + || !TEST_true(EVP_DigestSqueeze(ctx, out2 + sizeof(out2) / 2, + sizeof(out2) / 2))) + goto err; + + if (!TEST_mem_eq(out2, sizeof(out2), out, sizeof(out))) goto err; ret = 1; err: EVP_MD_CTX_free(ctx); - EVP_MD_CTX_free(ctx2); return ret; } @@ -626,14 +569,14 @@ static int xof_fail_test(void) int setup_tests(void) { - ADD_ALL_TESTS(xof_kat_test, OSSL_NELEM(xof_test_data)); - ADD_ALL_TESTS(xof_kat_digestfinal_test, OSSL_NELEM(xof_test_data)); - ADD_ALL_TESTS(xof_kat_digestfinal_xoflen_test, OSSL_NELEM(xof_test_data)); - ADD_ALL_TESTS(xof_squeeze_no_absorb_test, OSSL_NELEM(xof_test_data)); - ADD_ALL_TESTS(xof_absorb_test, OSSL_NELEM(large_msg_test_data)); - ADD_ALL_TESTS(xof_squeeze_kat_test, OSSL_NELEM(stride_test_data)); - ADD_ALL_TESTS(xof_squeeze_large_test, OSSL_NELEM(stride_test_data)); - ADD_ALL_TESTS(xof_squeeze_dup_test, OSSL_NELEM(dupoffset_test_data)); + ADD_TEST(shake_kat_test); + ADD_TEST(shake_kat_digestfinal_test); + ADD_TEST(shake_kat_digestfinal_xoflen_test); + ADD_TEST(shake_absorb_test); + ADD_ALL_TESTS(shake_squeeze_kat_test, OSSL_NELEM(stride_tests)); + ADD_ALL_TESTS(shake_squeeze_large_test, OSSL_NELEM(stride_tests)); + ADD_ALL_TESTS(shake_squeeze_dup_test, OSSL_NELEM(dupoffset_tests)); ADD_TEST(xof_fail_test); + ADD_TEST(shake_squeeze_no_absorb_test); return 1; } diff --git a/test/ext_internal_test.c b/test/ext_internal_test.c index c88f026dee..cc354a02e2 100644 --- a/test/ext_internal_test.c +++ b/test/ext_internal_test.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -72,15 +72,6 @@ static EXT_LIST ext_list[] = { EXT_ENTRY(compress_certificate), EXT_ENTRY(early_data), EXT_ENTRY(certificate_authorities), -#ifndef OPENSSL_NO_ECH - EXT_ENTRY(ech), - EXT_ENTRY(outer_extensions), -#else - EXT_EXCEPTION(ech), - EXT_EXCEPTION(outer_extensions), -#endif - EXT_ENTRY(grease1), - EXT_ENTRY(grease2), EXT_ENTRY(padding), EXT_ENTRY(psk), EXT_END(num_builtins) diff --git a/test/fake_cipherprov.c b/test/fake_cipherprov.c index ad28a6b94b..2322a1a812 100644 --- a/test/fake_cipherprov.c +++ b/test/fake_cipherprov.c @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"); * you may not use this file except in compliance with the License. @@ -9,13 +9,13 @@ */ #include -#include #include #include #include #include #include #include +#include "testutil.h" #include "fake_cipherprov.h" #define MAX_KEYNAME 32 @@ -65,7 +65,7 @@ static void *fake_skeymgmt_import(void *provctx, int selection, const OSSL_PARAM { PROV_CIPHER_FAKE_CTX *ctx = NULL; - if ((ctx = OPENSSL_zalloc(sizeof(PROV_CIPHER_FAKE_CTX))) == NULL) + if (!TEST_ptr(ctx = OPENSSL_zalloc(sizeof(PROV_CIPHER_FAKE_CTX)))) return 0; if (ctx_from_key_params(ctx, p) != 1) { @@ -76,26 +76,6 @@ static void *fake_skeymgmt_import(void *provctx, int selection, const OSSL_PARAM return ctx; } -static void *fake_skeymgmt_generate(void *provctx, const OSSL_PARAM *params) -{ - PROV_CIPHER_FAKE_CTX *ctx = NULL; - size_t i; - - if ((ctx = OPENSSL_zalloc(sizeof(PROV_CIPHER_FAKE_CTX))) == NULL) - return NULL; - - if (ctx_from_key_params(ctx, params) != 1) { - OPENSSL_free(ctx); - return NULL; - } - - /* Deterministic fill so the provider doesn't depend on a DRBG. */ - for (i = 0; i < sizeof(ctx->key); i++) - ctx->key[i] = (unsigned char)i; - - return ctx; -} - static int fake_skeymgmt_export(void *keydata, int selection, OSSL_CALLBACK *param_callback, void *cbarg) { @@ -123,7 +103,6 @@ static int fake_skeymgmt_export(void *keydata, int selection, static const OSSL_DISPATCH fake_skeymgmt_funcs[] = { { OSSL_FUNC_SKEYMGMT_FREE, (void (*)(void))fake_skeymgmt_free }, - { OSSL_FUNC_SKEYMGMT_GENERATE, (void (*)(void))fake_skeymgmt_generate }, { OSSL_FUNC_SKEYMGMT_IMPORT, (void (*)(void))fake_skeymgmt_import }, { OSSL_FUNC_SKEYMGMT_EXPORT, (void (*)(void))fake_skeymgmt_export }, OSSL_DISPATCH_END @@ -131,7 +110,6 @@ static const OSSL_DISPATCH fake_skeymgmt_funcs[] = { static const OSSL_ALGORITHM fake_skeymgmt_algs[] = { { "fake_cipher", FAKE_CIPHER_FETCH_PROPS, fake_skeymgmt_funcs, "Fake Cipher Key Management" }, - { OSSL_SKEY_TYPE_GENERIC, FAKE_CIPHER_FETCH_PROPS, fake_skeymgmt_funcs, "Fake Generic Key Management" }, { NULL, NULL, NULL, NULL } }; static OSSL_FUNC_cipher_newctx_fn fake_newctx; @@ -289,18 +267,8 @@ static const OSSL_DISPATCH ossl_fake_functions[] = { OSSL_DISPATCH_END }; -static const OSSL_DISPATCH ossl_fake_no_getparams_functions[] = { - { OSSL_FUNC_CIPHER_NEWCTX, - (void (*)(void))fake_newctx }, - { OSSL_FUNC_CIPHER_FREECTX, (void (*)(void))fake_freectx }, - { OSSL_FUNC_CIPHER_CIPHER, (void (*)(void))fake_cipher }, - OSSL_DISPATCH_END -}; - static const OSSL_ALGORITHM fake_cipher_algs[] = { { "fake_cipher", FAKE_CIPHER_FETCH_PROPS, ossl_fake_functions }, - { FAKE_CIPHER_NO_GETPARAMS, FAKE_CIPHER_FETCH_PROPS, - ossl_fake_no_getparams_functions }, { NULL, NULL, NULL } }; @@ -329,29 +297,19 @@ static int fake_cipher_provider_init(const OSSL_CORE_HANDLE *handle, const OSSL_DISPATCH *in, const OSSL_DISPATCH **out, void **provctx) { - if ((*provctx = OSSL_LIB_CTX_new()) == NULL) + if (!TEST_ptr(*provctx = OSSL_LIB_CTX_new())) return 0; *out = fake_cipher_method; return 1; } -#ifdef FAKE_CIPHER_AS_MODULE -/* Entry point when built as a loadable module (e.g. -provider fake-cipher). */ -int OSSL_provider_init(const OSSL_CORE_HANDLE *handle, - const OSSL_DISPATCH *in, - const OSSL_DISPATCH **out, void **provctx) -{ - return fake_cipher_provider_init(handle, in, out, provctx); -} -#endif - OSSL_PROVIDER *fake_cipher_start(OSSL_LIB_CTX *libctx) { OSSL_PROVIDER *p; - if (!OSSL_PROVIDER_add_builtin(libctx, FAKE_PROV_NAME, - fake_cipher_provider_init) - || (p = OSSL_PROVIDER_try_load(libctx, FAKE_PROV_NAME, 1)) == NULL) + if (!TEST_true(OSSL_PROVIDER_add_builtin(libctx, FAKE_PROV_NAME, + fake_cipher_provider_init)) + || !TEST_ptr(p = OSSL_PROVIDER_try_load(libctx, FAKE_PROV_NAME, 1))) return NULL; return p; diff --git a/test/fake_cipherprov.h b/test/fake_cipherprov.h index 54ccd6face..ea7313a740 100644 --- a/test/fake_cipherprov.h +++ b/test/fake_cipherprov.h @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -16,5 +16,4 @@ void fake_cipher_finish(OSSL_PROVIDER *p); #define FAKE_PROV_NAME "fake-cipher" #define FAKE_CIPHER_FETCH_PROPS "provider=fake-cipher" -#define FAKE_CIPHER_NO_GETPARAMS "fake_cipher_no_getparams" #define FAKE_CIPHER_PARAM_KEY_NAME "key_name" diff --git a/test/fake_rsaprov.c b/test/fake_rsaprov.c index eb9f92af15..b5b9fb2d0a 100644 --- a/test/fake_rsaprov.c +++ b/test/fake_rsaprov.c @@ -776,7 +776,8 @@ ASN1_SEQUENCE(X509_PUBKEY_INTERNAL) = { ASN1_SIMPLE(X509_PUBKEY, public_key, ASN1_BIT_STRING) } static_ASN1_SEQUENCE_END_name(X509_PUBKEY, X509_PUBKEY_INTERNAL) -static X509_PUBKEY *fake_rsa_d2i_X509_PUBKEY_INTERNAL(const unsigned char **pp, long len, OSSL_LIB_CTX *libctx) + static X509_PUBKEY + * fake_rsa_d2i_X509_PUBKEY_INTERNAL(const unsigned char **pp, long len, OSSL_LIB_CTX *libctx) { X509_PUBKEY *xpub = OPENSSL_zalloc(sizeof(*xpub)); diff --git a/test/fatalerrtest.c b/test/fatalerrtest.c index bc2f6cd5ae..c349833b22 100644 --- a/test/fatalerrtest.c +++ b/test/fatalerrtest.c @@ -1,5 +1,5 @@ /* - * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -35,13 +35,10 @@ static int test_fatalerr(void) /* * Deliberately set the cipher lists for client and server to be different - * to force a handshake failure. Also make sure the client and server don't - * accept TLS 1.2 ciphers as TLS 1.3 ciphersuites. + * to force a handshake failure. */ if (!TEST_true(SSL_CTX_set_cipher_list(sctx, "AES128-SHA")) || !TEST_true(SSL_CTX_set_cipher_list(cctx, "AES256-SHA")) - || !TEST_false(SSL_CTX_set_ciphersuites(sctx, "AES128-SHA")) - || !TEST_false(SSL_CTX_set_ciphersuites(cctx, "AES256-SHA")) || !TEST_true(SSL_CTX_set_ciphersuites(sctx, "TLS_AES_128_GCM_SHA256")) || !TEST_true(SSL_CTX_set_ciphersuites(cctx, diff --git a/test/ffc_internal_test.c b/test/ffc_internal_test.c index d08f3b244d..4743279e4c 100644 --- a/test/ffc_internal_test.c +++ b/test/ffc_internal_test.c @@ -690,57 +690,13 @@ err: DH_free(dh); return ret; } -#endif /* OPENSSSL_NO_DH */ - -#ifndef OPENSSL_NO_DSA -static int ffc_params_copy_mfail(void) -{ - int ret = 0; - FFC_PARAMS params, copy; - BIGNUM *p = NULL, *q = NULL, *g = NULL; - - ossl_ffc_params_init(¶ms); - ossl_ffc_params_init(©); - - if (!TEST_ptr(p = BN_bin2bn(dsa_2048_224_sha256_p, - sizeof(dsa_2048_224_sha256_p), NULL)) - || !TEST_ptr(q = BN_bin2bn(dsa_2048_224_sha256_q, - sizeof(dsa_2048_224_sha256_q), NULL)) - || !TEST_ptr(g = BN_bin2bn(dsa_2048_224_sha256_g, - sizeof(dsa_2048_224_sha256_g), NULL))) - goto err; - - ossl_ffc_params_set0_pqg(¶ms, p, q, g); - p = q = g = NULL; - if (!TEST_true(ossl_ffc_params_set_seed(¶ms, dsa_2048_224_sha224_seed, - sizeof(dsa_2048_224_sha224_seed)))) - goto err; - - MFAIL_start(); - ret = ossl_ffc_params_copy(©, ¶ms); - MFAIL_end(); - - if (!ret) - goto err; - - ret = 1; -err: - ossl_ffc_params_cleanup(¶ms); - if (ret) - ossl_ffc_params_cleanup(©); - BN_free(p); - BN_free(q); - BN_free(g); - return ret; -} -#endif /* OPENSSL_NO_DSA */ +#endif /* OPENSSL_NO_DH */ int setup_tests(void) { #ifndef OPENSSL_NO_DSA ADD_TEST(ffc_params_validate_pq_test); ADD_TEST(ffc_params_validate_g_unverified_test); - ADD_MFAIL_TEST(ffc_params_copy_mfail); #endif /* OPENSSL_NO_DSA */ #ifndef OPENSSL_NO_DH ADD_TEST(ffc_params_gen_test); diff --git a/test/handshake-memfail.c b/test/handshake-memfail.c index 7c560806ce..35119c8e93 100644 --- a/test/handshake-memfail.c +++ b/test/handshake-memfail.c @@ -29,11 +29,10 @@ * - rcount: Number of reallocs counted * - fcount: Number of frees counted * - scount: Number of mallocs counted prior to workload - * - srcount: Number of reallocs counted prior to workload */ static char *cert = NULL; static char *privkey = NULL; -static int mcount, rcount, fcount, scount, srcount; +static int mcount, rcount, fcount, scount; /** * @brief Performs an SSL/TLS handshake between a test client and server. @@ -136,16 +135,15 @@ static int test_report_alloc_counts(void) CRYPTO_get_alloc_counts(&mcount, &rcount, &fcount); /* * Report our memory allocations from the count run - * NOTE: We report a number of (re)allocations to skip here - * (the scount + srcount value). These are the allocations - * that took place while the test harness itself was getting - * setup (i.e. calling OPENSSL_init_crypto/etc). We can't fail + * NOTE: We report a number of allocations to skip here + * (the scount value). These are the allocations that took + * place while the test harness itself was getting setup + * (i.e. calling OPENSSL_init_crypto/etc). We can't fail * those allocations as they will cause the test to fail before * we have even run the workload. So report them so we can * allow them to function before we start doing any real testing */ - TEST_info("skip: %d count %d\n", - scount + srcount, mcount + rcount - scount - srcount); + TEST_info("skip: %d count %d\n", scount, mcount - scount); return 1; } @@ -169,7 +167,7 @@ int setup_tests(void) goto err; if (strcmp(opmode, "count") == 0) { - CRYPTO_get_alloc_counts(&scount, &srcount, &fcount); + CRYPTO_get_alloc_counts(&scount, &rcount, &fcount); ADD_TEST(test_record_alloc_counts); ADD_TEST(test_report_alloc_counts); } else { diff --git a/test/helpers/handshake.c b/test/helpers/handshake.c index 6f7f7f9d21..5e5606056f 100644 --- a/test/helpers/handshake.c +++ b/test/helpers/handshake.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -833,7 +833,6 @@ typedef enum { PEER_SUCCESS, PEER_RETRY, PEER_ERROR, - PEER_FINAL_ERROR, PEER_WAITING, PEER_TEST_FAILURE } peer_status_t; @@ -1029,10 +1028,6 @@ static void do_reneg_setup_step(const SSL_TEST_CTX *test_ctx, PEER *peer) */ if (SSL_is_server(peer->ssl)) { ret = SSL_renegotiate(peer->ssl); - if (!ret) { - peer->status = PEER_FINAL_ERROR; - return; - } } else { int full_reneg = 0; @@ -1052,10 +1047,10 @@ static void do_reneg_setup_step(const SSL_TEST_CTX *test_ctx, PEER *peer) ret = SSL_renegotiate(peer->ssl); else ret = SSL_renegotiate_abbreviated(peer->ssl); - if (!ret) { - peer->status = PEER_FINAL_ERROR; - return; - } + } + if (!ret) { + peer->status = PEER_ERROR; + return; } do_handshake_step(peer); /* @@ -1316,7 +1311,6 @@ static handshake_status_t handshake_status(peer_status_t last_status, /* Let the first peer finish. */ return HANDSHAKE_RETRY; case PEER_ERROR: - case PEER_FINAL_ERROR: /* * Second peer succeeded despite the fact that the first peer * already errored. This shouldn't happen. @@ -1328,9 +1322,6 @@ static handshake_status_t handshake_status(peer_status_t last_status, case PEER_RETRY: return HANDSHAKE_RETRY; - case PEER_FINAL_ERROR: - return client_spoke_last ? CLIENT_ERROR : SERVER_ERROR; - case PEER_ERROR: switch (previous_status) { case PEER_TEST_FAILURE: @@ -1345,7 +1336,6 @@ static handshake_status_t handshake_status(peer_status_t last_status, /* We errored; let the peer finish. */ return HANDSHAKE_RETRY; case PEER_ERROR: - case PEER_FINAL_ERROR: /* Both peers errored. Return the one that errored first. */ return client_spoke_last ? SERVER_ERROR : CLIENT_ERROR; } @@ -1819,10 +1809,6 @@ err: if (SSL_get_peer_tmp_key(client.ssl, &tmp_key)) { ret->tmp_key_type = pkey_type(tmp_key); EVP_PKEY_free(tmp_key); - if (ret->tmp_key_type == EVP_PKEY_KEYMGMT) - ret->tmp_key_type = SSL_get_negotiated_group(client.ssl); - } else { - ret->tmp_key_type = SSL_get_negotiated_group(client.ssl); } SSL_get_peer_signature_nid(client.ssl, &ret->server_sign_hash); diff --git a/test/helpers/pkcs12.c b/test/helpers/pkcs12.c index 3ecfd020b6..a50ce6f1df 100644 --- a/test/helpers/pkcs12.c +++ b/test/helpers/pkcs12.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -467,22 +467,22 @@ static int check_asn1_string(const ASN1_TYPE *av, const char *txt) switch (av->type) { case V_ASN1_BMPSTRING: - value = OPENSSL_uni2asc(ASN1_STRING_get0_data(av->value.bmpstring), - (int)ASN1_STRING_length_ex(av->value.bmpstring)); + value = OPENSSL_uni2asc(av->value.bmpstring->data, + av->value.bmpstring->length); if (!TEST_str_eq(txt, (char *)value)) goto err; break; case V_ASN1_UTF8STRING: - if (!TEST_mem_eq(txt, strlen(txt), ASN1_STRING_get0_data(av->value.utf8string), - ASN1_STRING_length_ex(av->value.utf8string))) + if (!TEST_mem_eq(txt, strlen(txt), (char *)av->value.utf8string->data, + av->value.utf8string->length)) goto err; break; case V_ASN1_OCTET_STRING: if (!TEST_mem_eq(txt, strlen(txt), - (char *)ASN1_STRING_get0_data(av->value.octet_string), - ASN1_STRING_length_ex(av->value.octet_string))) + (char *)av->value.octet_string->data, + av->value.octet_string->length)) goto err; break; @@ -500,13 +500,13 @@ static int check_attrs(const STACK_OF(X509_ATTRIBUTE) *bag_attrs, const PKCS12_A { int ret = 0; X509_ATTRIBUTE *attr; - const ASN1_TYPE *av; + ASN1_TYPE *av; int i, j; char attr_txt[100]; for (i = 0; i < sk_X509_ATTRIBUTE_num(bag_attrs); i++) { const PKCS12_ATTR *p_attr = attrs; - const ASN1_OBJECT *attr_obj; + ASN1_OBJECT *attr_obj; attr = sk_X509_ATTRIBUTE_value(bag_attrs, i); attr_obj = X509_ATTRIBUTE_get0_object(attr); diff --git a/test/helpers/predefined_dhparams.c b/test/helpers/predefined_dhparams.c index 0fb7853d5c..2521727f09 100644 --- a/test/helpers/predefined_dhparams.c +++ b/test/helpers/predefined_dhparams.c @@ -72,16 +72,73 @@ err: EVP_PKEY *get_dh512(OSSL_LIB_CTX *libctx) { static unsigned char dh512_p[] = { - 0xCB, 0xC8, 0xE1, 0x86, 0xD0, 0x1F, 0x94, 0x17, 0xA6, 0x99, - 0xF0, 0xC6, 0x1F, 0x0D, 0xAC, 0xB6, 0x25, 0x3E, 0x06, 0x39, - 0xCA, 0x72, 0x04, 0xB0, 0x6E, 0xDA, 0xC0, 0x61, 0xE6, 0x7A, - 0x77, 0x25, 0xE8, 0x3B, 0xB9, 0x5F, 0x9A, 0xB6, 0xB5, 0xFE, - 0x99, 0x0B, 0xA1, 0x93, 0x4E, 0x35, 0x33, 0xB8, 0xE1, 0xF1, - 0x13, 0x4F, 0x59, 0x1A, 0xD2, 0x57, 0xC0, 0x26, 0x21, 0x33, - 0x02, 0xC5, 0xAE, 0x23 + 0xCB, + 0xC8, + 0xE1, + 0x86, + 0xD0, + 0x1F, + 0x94, + 0x17, + 0xA6, + 0x99, + 0xF0, + 0xC6, + 0x1F, + 0x0D, + 0xAC, + 0xB6, + 0x25, + 0x3E, + 0x06, + 0x39, + 0xCA, + 0x72, + 0x04, + 0xB0, + 0x6E, + 0xDA, + 0xC0, + 0x61, + 0xE6, + 0x7A, + 0x77, + 0x25, + 0xE8, + 0x3B, + 0xB9, + 0x5F, + 0x9A, + 0xB6, + 0xB5, + 0xFE, + 0x99, + 0x0B, + 0xA1, + 0x93, + 0x4E, + 0x35, + 0x33, + 0xB8, + 0xE1, + 0xF1, + 0x13, + 0x4F, + 0x59, + 0x1A, + 0xD2, + 0x57, + 0xC0, + 0x26, + 0x21, + 0x33, + 0x02, + 0xC5, + 0xAE, + 0x23, }; static unsigned char dh512_g[] = { - 0x02 + 0x02, }; return get_dh_from_pg(libctx, "DH", dh512_p, sizeof(dh512_p), @@ -91,27 +148,161 @@ EVP_PKEY *get_dh512(OSSL_LIB_CTX *libctx) EVP_PKEY *get_dhx512(OSSL_LIB_CTX *libctx) { static unsigned char dhx512_p[] = { - 0x00, 0xe8, 0x1a, 0xb7, 0x9a, 0x02, 0x65, 0x64, 0x94, 0x7b, - 0xba, 0x09, 0x1c, 0x12, 0x27, 0x1e, 0xea, 0x89, 0x32, 0x64, - 0x78, 0xf8, 0x1c, 0x78, 0x8e, 0x96, 0xc3, 0xc6, 0x9f, 0x41, - 0x05, 0x41, 0x65, 0xae, 0xe3, 0x05, 0xea, 0x66, 0x21, 0xf7, - 0x38, 0xb7, 0x2b, 0x32, 0x40, 0x5a, 0x14, 0x86, 0x51, 0x94, - 0xb1, 0xcf, 0x01, 0xe3, 0x27, 0x28, 0xf6, 0x75, 0xa3, 0x15, - 0xbb, 0x12, 0x4d, 0x99, 0xe7 + 0x00, + 0xe8, + 0x1a, + 0xb7, + 0x9a, + 0x02, + 0x65, + 0x64, + 0x94, + 0x7b, + 0xba, + 0x09, + 0x1c, + 0x12, + 0x27, + 0x1e, + 0xea, + 0x89, + 0x32, + 0x64, + 0x78, + 0xf8, + 0x1c, + 0x78, + 0x8e, + 0x96, + 0xc3, + 0xc6, + 0x9f, + 0x41, + 0x05, + 0x41, + 0x65, + 0xae, + 0xe3, + 0x05, + 0xea, + 0x66, + 0x21, + 0xf7, + 0x38, + 0xb7, + 0x2b, + 0x32, + 0x40, + 0x5a, + 0x14, + 0x86, + 0x51, + 0x94, + 0xb1, + 0xcf, + 0x01, + 0xe3, + 0x27, + 0x28, + 0xf6, + 0x75, + 0xa3, + 0x15, + 0xbb, + 0x12, + 0x4d, + 0x99, + 0xe7, }; static unsigned char dhx512_g[] = { - 0x00, 0x91, 0xc1, 0x43, 0x6d, 0x0d, 0xb0, 0xa4, 0xde, 0x41, - 0xb7, 0x93, 0xad, 0x51, 0x94, 0x1b, 0x43, 0xd8, 0x42, 0xf1, - 0x5e, 0x46, 0x83, 0x5d, 0xf1, 0xd1, 0xf0, 0x41, 0x10, 0xd1, - 0x1c, 0x5e, 0xad, 0x9b, 0x68, 0xb1, 0x6f, 0xf5, 0x8e, 0xaa, - 0x6d, 0x71, 0x88, 0x37, 0xdf, 0x05, 0xf7, 0x6e, 0x7a, 0xb4, - 0x25, 0x10, 0x6c, 0x7f, 0x38, 0xb4, 0xc8, 0xfc, 0xcc, 0x0c, - 0x6a, 0x02, 0x08, 0x61, 0xf6 + 0x00, + 0x91, + 0xc1, + 0x43, + 0x6d, + 0x0d, + 0xb0, + 0xa4, + 0xde, + 0x41, + 0xb7, + 0x93, + 0xad, + 0x51, + 0x94, + 0x1b, + 0x43, + 0xd8, + 0x42, + 0xf1, + 0x5e, + 0x46, + 0x83, + 0x5d, + 0xf1, + 0xd1, + 0xf0, + 0x41, + 0x10, + 0xd1, + 0x1c, + 0x5e, + 0xad, + 0x9b, + 0x68, + 0xb1, + 0x6f, + 0xf5, + 0x8e, + 0xaa, + 0x6d, + 0x71, + 0x88, + 0x37, + 0xdf, + 0x05, + 0xf7, + 0x6e, + 0x7a, + 0xb4, + 0x25, + 0x10, + 0x6c, + 0x7f, + 0x38, + 0xb4, + 0xc8, + 0xfc, + 0xcc, + 0x0c, + 0x6a, + 0x02, + 0x08, + 0x61, + 0xf6, }; static unsigned char dhx512_q[] = { - 0x00, 0xdd, 0xf6, 0x35, 0xad, 0xfa, 0x70, 0xc7, 0xe7, 0xa8, - 0xf0, 0xe3, 0xda, 0x79, 0x34, 0x3f, 0x5b, 0xcf, 0x73, 0x82, - 0x91 + 0x00, + 0xdd, + 0xf6, + 0x35, + 0xad, + 0xfa, + 0x70, + 0xc7, + 0xe7, + 0xa8, + 0xf0, + 0xe3, + 0xda, + 0x79, + 0x34, + 0x3f, + 0x5b, + 0xcf, + 0x73, + 0x82, + 0x91, }; return get_dh_from_pg(libctx, "X9.42 DH", @@ -123,34 +314,264 @@ EVP_PKEY *get_dhx512(OSSL_LIB_CTX *libctx) EVP_PKEY *get_dh1024dsa(OSSL_LIB_CTX *libctx) { static unsigned char dh1024_p[] = { - 0xC8, 0x00, 0xF7, 0x08, 0x07, 0x89, 0x4D, 0x90, 0x53, 0xF3, - 0xD5, 0x00, 0x21, 0x1B, 0xF7, 0x31, 0xA6, 0xA2, 0xDA, 0x23, - 0x9A, 0xC7, 0x87, 0x19, 0x3B, 0x47, 0xB6, 0x8C, 0x04, 0x6F, - 0xFF, 0xC6, 0x9B, 0xB8, 0x65, 0xD2, 0xC2, 0x5F, 0x31, 0x83, - 0x4A, 0xA7, 0x5F, 0x2F, 0x88, 0x38, 0xB6, 0x55, 0xCF, 0xD9, - 0x87, 0x6D, 0x6F, 0x9F, 0xDA, 0xAC, 0xA6, 0x48, 0xAF, 0xFC, - 0x33, 0x84, 0x37, 0x5B, 0x82, 0x4A, 0x31, 0x5D, 0xE7, 0xBD, - 0x52, 0x97, 0xA1, 0x77, 0xBF, 0x10, 0x9E, 0x37, 0xEA, 0x64, - 0xFA, 0xCA, 0x28, 0x8D, 0x9D, 0x3B, 0xD2, 0x6E, 0x09, 0x5C, - 0x68, 0xC7, 0x45, 0x90, 0xFD, 0xBB, 0x70, 0xC9, 0x3A, 0xBB, - 0xDF, 0xD4, 0x21, 0x0F, 0xC4, 0x6A, 0x3C, 0xF6, 0x61, 0xCF, - 0x3F, 0xD6, 0x13, 0xF1, 0x5F, 0xBC, 0xCF, 0xBC, 0x26, 0x9E, - 0xBC, 0x0B, 0xBD, 0xAB, 0x5D, 0xC9, 0x54, 0x39 + 0xC8, + 0x00, + 0xF7, + 0x08, + 0x07, + 0x89, + 0x4D, + 0x90, + 0x53, + 0xF3, + 0xD5, + 0x00, + 0x21, + 0x1B, + 0xF7, + 0x31, + 0xA6, + 0xA2, + 0xDA, + 0x23, + 0x9A, + 0xC7, + 0x87, + 0x19, + 0x3B, + 0x47, + 0xB6, + 0x8C, + 0x04, + 0x6F, + 0xFF, + 0xC6, + 0x9B, + 0xB8, + 0x65, + 0xD2, + 0xC2, + 0x5F, + 0x31, + 0x83, + 0x4A, + 0xA7, + 0x5F, + 0x2F, + 0x88, + 0x38, + 0xB6, + 0x55, + 0xCF, + 0xD9, + 0x87, + 0x6D, + 0x6F, + 0x9F, + 0xDA, + 0xAC, + 0xA6, + 0x48, + 0xAF, + 0xFC, + 0x33, + 0x84, + 0x37, + 0x5B, + 0x82, + 0x4A, + 0x31, + 0x5D, + 0xE7, + 0xBD, + 0x52, + 0x97, + 0xA1, + 0x77, + 0xBF, + 0x10, + 0x9E, + 0x37, + 0xEA, + 0x64, + 0xFA, + 0xCA, + 0x28, + 0x8D, + 0x9D, + 0x3B, + 0xD2, + 0x6E, + 0x09, + 0x5C, + 0x68, + 0xC7, + 0x45, + 0x90, + 0xFD, + 0xBB, + 0x70, + 0xC9, + 0x3A, + 0xBB, + 0xDF, + 0xD4, + 0x21, + 0x0F, + 0xC4, + 0x6A, + 0x3C, + 0xF6, + 0x61, + 0xCF, + 0x3F, + 0xD6, + 0x13, + 0xF1, + 0x5F, + 0xBC, + 0xCF, + 0xBC, + 0x26, + 0x9E, + 0xBC, + 0x0B, + 0xBD, + 0xAB, + 0x5D, + 0xC9, + 0x54, + 0x39, }; static unsigned char dh1024_g[] = { - 0x3B, 0x40, 0x86, 0xE7, 0xF3, 0x6C, 0xDE, 0x67, 0x1C, 0xCC, - 0x80, 0x05, 0x5A, 0xDF, 0xFE, 0xBD, 0x20, 0x27, 0x74, 0x6C, - 0x24, 0xC9, 0x03, 0xF3, 0xE1, 0x8D, 0xC3, 0x7D, 0x98, 0x27, - 0x40, 0x08, 0xB8, 0x8C, 0x6A, 0xE9, 0xBB, 0x1A, 0x3A, 0xD6, - 0x86, 0x83, 0x5E, 0x72, 0x41, 0xCE, 0x85, 0x3C, 0xD2, 0xB3, - 0xFC, 0x13, 0xCE, 0x37, 0x81, 0x9E, 0x4C, 0x1C, 0x7B, 0x65, - 0xD3, 0xE6, 0xA6, 0x00, 0xF5, 0x5A, 0x95, 0x43, 0x5E, 0x81, - 0xCF, 0x60, 0xA2, 0x23, 0xFC, 0x36, 0xA7, 0x5D, 0x7A, 0x4C, - 0x06, 0x91, 0x6E, 0xF6, 0x57, 0xEE, 0x36, 0xCB, 0x06, 0xEA, - 0xF5, 0x3D, 0x95, 0x49, 0xCB, 0xA7, 0xDD, 0x81, 0xDF, 0x80, - 0x09, 0x4A, 0x97, 0x4D, 0xA8, 0x22, 0x72, 0xA1, 0x7F, 0xC4, - 0x70, 0x56, 0x70, 0xE8, 0x20, 0x10, 0x18, 0x8F, 0x2E, 0x60, - 0x07, 0xE7, 0x68, 0x1A, 0x82, 0x5D, 0x32, 0xA2 + 0x3B, + 0x40, + 0x86, + 0xE7, + 0xF3, + 0x6C, + 0xDE, + 0x67, + 0x1C, + 0xCC, + 0x80, + 0x05, + 0x5A, + 0xDF, + 0xFE, + 0xBD, + 0x20, + 0x27, + 0x74, + 0x6C, + 0x24, + 0xC9, + 0x03, + 0xF3, + 0xE1, + 0x8D, + 0xC3, + 0x7D, + 0x98, + 0x27, + 0x40, + 0x08, + 0xB8, + 0x8C, + 0x6A, + 0xE9, + 0xBB, + 0x1A, + 0x3A, + 0xD6, + 0x86, + 0x83, + 0x5E, + 0x72, + 0x41, + 0xCE, + 0x85, + 0x3C, + 0xD2, + 0xB3, + 0xFC, + 0x13, + 0xCE, + 0x37, + 0x81, + 0x9E, + 0x4C, + 0x1C, + 0x7B, + 0x65, + 0xD3, + 0xE6, + 0xA6, + 0x00, + 0xF5, + 0x5A, + 0x95, + 0x43, + 0x5E, + 0x81, + 0xCF, + 0x60, + 0xA2, + 0x23, + 0xFC, + 0x36, + 0xA7, + 0x5D, + 0x7A, + 0x4C, + 0x06, + 0x91, + 0x6E, + 0xF6, + 0x57, + 0xEE, + 0x36, + 0xCB, + 0x06, + 0xEA, + 0xF5, + 0x3D, + 0x95, + 0x49, + 0xCB, + 0xA7, + 0xDD, + 0x81, + 0xDF, + 0x80, + 0x09, + 0x4A, + 0x97, + 0x4D, + 0xA8, + 0x22, + 0x72, + 0xA1, + 0x7F, + 0xC4, + 0x70, + 0x56, + 0x70, + 0xE8, + 0x20, + 0x10, + 0x18, + 0x8F, + 0x2E, + 0x60, + 0x07, + 0xE7, + 0x68, + 0x1A, + 0x82, + 0x5D, + 0x32, + 0xA2, }; return get_dh_from_pg(libctx, "DH", dh1024_p, sizeof(dh1024_p), diff --git a/test/helpers/predefined_dsaparams.c b/test/helpers/predefined_dsaparams.c deleted file mode 100644 index 82a760edab..0000000000 --- a/test/helpers/predefined_dsaparams.c +++ /dev/null @@ -1,107 +0,0 @@ -/* - * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* - * DSA low level APIs are deprecated for public use, but still ok for - * internal use. - */ -#include "internal/deprecated.h" - -#ifndef OPENSSL_NO_DSA -#include -#include -#include "predefined_dsaparams.h" - -/* - * These parameters are from test/recipes/04-test_pem_data/dsaparam.pem, - * converted using dsaparam -C - */ -DSA *load_dsa_params(void) -{ - static unsigned char dsap_2048[] = { - 0xAE, 0x35, 0x7D, 0x4E, 0x1D, 0x96, 0xE2, 0x9F, 0x00, 0x96, - 0x60, 0x5A, 0x6E, 0x4D, 0x07, 0x8D, 0xA5, 0x7C, 0xBC, 0xF9, - 0xAD, 0xD7, 0x9F, 0xD5, 0xE9, 0xEE, 0xA6, 0x33, 0x51, 0xDE, - 0x7B, 0x72, 0xD2, 0x75, 0xAA, 0x71, 0x77, 0xF1, 0x63, 0xFB, - 0xB6, 0xEC, 0x5A, 0xBA, 0x0D, 0x72, 0xA2, 0x1A, 0x1C, 0x64, - 0xB8, 0xE5, 0x89, 0x09, 0x6D, 0xC9, 0x6F, 0x0B, 0x7F, 0xD2, - 0xCE, 0x9F, 0xEF, 0x87, 0x5A, 0xB6, 0x67, 0x2F, 0xEF, 0xEE, - 0xEB, 0x59, 0xF5, 0x5E, 0xFF, 0xA8, 0x28, 0x84, 0x9E, 0x5B, - 0x37, 0x09, 0x11, 0x80, 0x7C, 0x08, 0x5C, 0xD5, 0xE1, 0x48, - 0x4B, 0xD2, 0x68, 0xFB, 0x3F, 0x9F, 0x2B, 0x6B, 0x6C, 0x0D, - 0x48, 0x1B, 0x1A, 0x80, 0xC2, 0xEB, 0x11, 0x1B, 0x37, 0x79, - 0xD6, 0x8C, 0x8B, 0x72, 0x3E, 0x67, 0xA5, 0x05, 0x0E, 0x41, - 0x8A, 0x9E, 0x35, 0x50, 0xB4, 0xD2, 0x40, 0x27, 0x6B, 0xFD, - 0xE0, 0x64, 0x6B, 0x5B, 0x38, 0x42, 0x94, 0xB5, 0x49, 0xDA, - 0xEF, 0x6E, 0x78, 0x37, 0xCD, 0x30, 0x89, 0xC3, 0x45, 0x50, - 0x7B, 0x9C, 0x8C, 0xE7, 0x1C, 0x98, 0x70, 0x71, 0x5D, 0x79, - 0x5F, 0xEF, 0xE8, 0x94, 0x85, 0x53, 0x3E, 0xEF, 0xA3, 0x2C, - 0xCE, 0x1A, 0xAB, 0x7D, 0xD6, 0x5E, 0x14, 0xCD, 0x51, 0x54, - 0x89, 0x9D, 0x77, 0xE4, 0xF8, 0x22, 0xF0, 0x35, 0x10, 0x75, - 0x05, 0x71, 0x51, 0x4F, 0x8C, 0x4C, 0x5C, 0x0D, 0x2C, 0x2C, - 0xBE, 0x6C, 0x34, 0xEE, 0x12, 0x82, 0x87, 0x03, 0x19, 0x06, - 0x12, 0xA8, 0xAA, 0xF4, 0x0D, 0x3C, 0x49, 0xCC, 0x70, 0x5A, - 0xD8, 0x32, 0xEE, 0x32, 0x50, 0x85, 0x70, 0xE8, 0x18, 0xFD, - 0x74, 0x80, 0x53, 0x32, 0x57, 0xEE, 0x50, 0xC9, 0xAE, 0xEB, - 0xAE, 0xB6, 0x22, 0x32, 0x16, 0x6B, 0x8C, 0x59, 0xDA, 0xEE, - 0x1D, 0x33, 0xDF, 0x4C, 0xA2, 0x3D - }; - static unsigned char dsaq_2048[] = { - 0xAD, 0x2D, 0x6E, 0x17, 0xB0, 0xF3, 0xEB, 0xC7, 0xB8, 0xEE, - 0x95, 0x78, 0xF2, 0x17, 0xF5, 0x33, 0x01, 0x67, 0xBC, 0xDE, - 0x93, 0xFF, 0xEE, 0x40, 0xE8, 0x7F, 0xF1, 0x93, 0x6D, 0x4B, - 0x87, 0x13 - }; - static unsigned char dsag_2048[] = { - 0x66, 0x6F, 0xDA, 0x63, 0xA5, 0x8E, 0xD2, 0x4C, 0xD5, 0x45, - 0x2D, 0x76, 0x5D, 0x5F, 0xCD, 0x4A, 0xB4, 0x1A, 0x42, 0x35, - 0x86, 0x3A, 0x6F, 0xA9, 0xFA, 0x27, 0xAB, 0xDE, 0x03, 0x21, - 0x36, 0x0A, 0x07, 0x29, 0xC9, 0x2F, 0x6D, 0x49, 0xA8, 0xF7, - 0xC6, 0xF4, 0x92, 0xD7, 0x73, 0xC1, 0xD8, 0x76, 0x0E, 0x61, - 0xA7, 0x0B, 0x6E, 0x96, 0xB8, 0xC8, 0xCB, 0x38, 0x35, 0x12, - 0x20, 0x79, 0xA5, 0x08, 0x28, 0x35, 0x5C, 0xBC, 0x52, 0x16, - 0xAF, 0x52, 0xBA, 0x0F, 0xC3, 0xB1, 0x63, 0x12, 0x27, 0x0B, - 0x74, 0xA4, 0x47, 0x43, 0xD6, 0x30, 0xB8, 0x9C, 0x2E, 0x40, - 0x14, 0xCD, 0x99, 0x7F, 0xE8, 0x8E, 0x37, 0xB0, 0xA9, 0x3F, - 0x54, 0xE9, 0x66, 0x22, 0x61, 0x4C, 0xF8, 0x49, 0x03, 0x57, - 0x14, 0x32, 0x1D, 0x37, 0x3D, 0xE2, 0x92, 0xF8, 0x8E, 0xA0, - 0x6A, 0x66, 0x63, 0xF0, 0xB0, 0x6E, 0x07, 0x2B, 0x3D, 0xBF, - 0xD0, 0x84, 0x6A, 0xAA, 0x1F, 0x30, 0x77, 0x65, 0xE5, 0xFC, - 0xF5, 0xEC, 0x55, 0xCE, 0x73, 0xDB, 0xBE, 0xA7, 0x8D, 0x3A, - 0x9F, 0x7A, 0xED, 0x4F, 0xAF, 0xA2, 0x80, 0x4C, 0x30, 0x9E, - 0x28, 0x49, 0x65, 0x40, 0xF0, 0x03, 0x45, 0x56, 0x99, 0xA2, - 0x93, 0x1B, 0x9C, 0x46, 0xDE, 0xBD, 0xA8, 0xAB, 0x5F, 0x90, - 0x3F, 0xB7, 0x3F, 0xD4, 0x6F, 0x8D, 0x5A, 0x30, 0xE1, 0xD4, - 0x63, 0x3A, 0x6A, 0x7C, 0x8F, 0x24, 0xFC, 0xD9, 0x14, 0x28, - 0x09, 0xE4, 0x84, 0x4E, 0x17, 0x43, 0x56, 0xB8, 0xD4, 0x4B, - 0xA2, 0x29, 0x45, 0xD3, 0x13, 0xF0, 0xC2, 0x76, 0x9B, 0x01, - 0xA0, 0x80, 0x6E, 0x93, 0x63, 0x5E, 0x87, 0x24, 0x20, 0x2A, - 0xFF, 0xBB, 0x9F, 0xA8, 0x99, 0x6C, 0xA7, 0x9A, 0x00, 0xB9, - 0x7D, 0xDA, 0x66, 0xC9, 0xC0, 0x72, 0x72, 0x22, 0x0F, 0x1A, - 0xCC, 0x23, 0xD9, 0xB7, 0x5F, 0x1B - }; - DSA *dsa = DSA_new(); - BIGNUM *p, *q, *g; - - if (dsa == NULL) - return NULL; - if (!DSA_set0_pqg(dsa, p = BN_bin2bn(dsap_2048, sizeof(dsap_2048), NULL), - q = BN_bin2bn(dsaq_2048, sizeof(dsaq_2048), NULL), - g = BN_bin2bn(dsag_2048, sizeof(dsag_2048), NULL))) { - DSA_free(dsa); - BN_free(p); - BN_free(q); - BN_free(g); - return NULL; - } - return dsa; -} -#else -NON_EMPTY_TRANSLATION_UNIT -#endif /* OPENSSL_NO_DSA */ diff --git a/test/helpers/predefined_dsaparams.h b/test/helpers/predefined_dsaparams.h deleted file mode 100644 index a01314bb15..0000000000 --- a/test/helpers/predefined_dsaparams.h +++ /dev/null @@ -1,12 +0,0 @@ -/* - * Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include - -DSA *load_dsa_params(void); diff --git a/test/helpers/quictestlib.c b/test/helpers/quictestlib.c index 5405df6ebf..a0df212074 100644 --- a/test/helpers/quictestlib.c +++ b/test/helpers/quictestlib.c @@ -930,10 +930,9 @@ int qtest_fault_prepend_frame(QTEST_FAULT *fault, const unsigned char *frame, old_len = fault->pplainio.buf_len; /* Extend the size of the packet by the size of the new frame */ - if (!qtest_fault_resize_plain_packet(fault, old_len + frame_len)) { - TEST_info("Cannot extend packet (%zu + %zu)", old_len, frame_len); + if (!TEST_true(qtest_fault_resize_plain_packet(fault, + old_len + frame_len))) return 0; - } memmove(buf + frame_len, buf, old_len); memcpy(buf, frame, frame_len); diff --git a/test/helpers/ssl_test_ctx.c b/test/helpers/ssl_test_ctx.c index 321d1a378a..98b3ff6d63 100644 --- a/test/helpers/ssl_test_ctx.c +++ b/test/helpers/ssl_test_ctx.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -18,7 +18,6 @@ #include #include "internal/nelem.h" -#include "internal/tlsgroups.h" #include "ssl_test_ctx.h" #include "../testutil.h" @@ -156,6 +155,7 @@ static const test_enum ssl_protocols[] = { { "TLSv1.2", TLS1_2_VERSION }, { "TLSv1.1", TLS1_1_VERSION }, { "TLSv1", TLS1_VERSION }, + { "SSLv3", SSL3_VERSION }, { "DTLSv1", DTLS1_VERSION }, { "DTLSv1.2", DTLS1_2_VERSION }, }; @@ -521,10 +521,19 @@ const char *ssl_max_fragment_len_name(int MFL_mode) __owur static int parse_expected_key_type(int *ptype, const char *value) { int nid; +#ifndef OPENSSL_NO_DEPRECATED_3_6 + const EVP_PKEY_ASN1_METHOD *ameth; +#endif if (value == NULL) return 0; - +#ifndef OPENSSL_NO_DEPRECATED_3_6 + ameth = EVP_PKEY_asn1_find_str(NULL, value, -1); + if (ameth != NULL) + EVP_PKEY_asn1_get0_info(&nid, NULL, NULL, NULL, NULL, ameth); + else + nid = OBJ_sn2nid(value); +#else /* * These functions map the values differently than * EVP_PKEY_asn1_find_str (which was used before) so use this hack @@ -540,20 +549,10 @@ __owur static int parse_expected_key_type(int *ptype, const char *value) nid = OBJ_sn2nid("ED25519"); } else if (strcmp("EC", value) == 0) { nid = OBJ_sn2nid("id-ecPublicKey"); - } else if (strcmp("curveSM2", value) == 0) { - nid = TLSEXT_nid_unknown | OSSL_TLS_GROUP_ID_curveSM2; - } else if (strcmp("X25519MLKEM768", value) == 0) { - nid = TLSEXT_nid_unknown | OSSL_TLS_GROUP_ID_X25519MLKEM768; - } else if (strcmp("SecP256r1MLKEM768", value) == 0) { - nid = TLSEXT_nid_unknown | OSSL_TLS_GROUP_ID_SecP256r1MLKEM768; - } else if (strcmp("SecP384r1MLKEM1024", value) == 0) { - nid = TLSEXT_nid_unknown | OSSL_TLS_GROUP_ID_SecP384r1MLKEM1024; - } else if (strcmp("curveSM2MLKEM768", value) == 0) { - nid = TLSEXT_nid_unknown | OSSL_TLS_GROUP_ID_curveSM2MLKEM768; } else { nid = OBJ_ln2nid(value); } - +#endif if (nid == NID_undef) nid = OBJ_sn2nid(value); #ifndef OPENSSL_NO_EC diff --git a/test/helpers/ssltestlib.c b/test/helpers/ssltestlib.c index 57b8c3e040..471498cfb8 100644 --- a/test/helpers/ssltestlib.c +++ b/test/helpers/ssltestlib.c @@ -525,170 +525,6 @@ int mempacket_move_packet(BIO *bio, int d, int s) return 1; } -/* - * Find the first DTLS record with content type rectype. - * If hs_msg_type >= 0, only match epoch-0 handshake records whose - * first handshake byte equals hs_msg_type. - */ -int mempacket_find_record(BIO *bio, int rectype, int hs_msg_type, - int *pktidx, int *recidx) -{ - MEMPACKET_TEST_CTX *ctx = BIO_get_data(bio); - int numpkts = sk_MEMPACKET_num(ctx->pkts); - int i, j, rem, len, payload_len; - unsigned char *rec; - - for (i = 0; i < numpkts; i++) { - MEMPACKET *thispkt = sk_MEMPACKET_value(ctx->pkts, i); - - if (thispkt == NULL) - continue; - for (j = 0, rem = thispkt->len, rec = thispkt->data; - rem >= DTLS1_RT_HEADER_LENGTH; - j++, rem -= len, rec += len) { - payload_len = (rec[RECORD_LEN_HI] << 8) | rec[RECORD_LEN_LO]; - len = payload_len + DTLS1_RT_HEADER_LENGTH; - if (rem < len) - return 0; - if (rec[RECORD_CONTENT_TYPE] != (unsigned char)rectype) - continue; - if (hs_msg_type >= 0 - && ((rec[RECORD_EPOCH_HI] | rec[RECORD_EPOCH_LO]) != 0 - || payload_len < 1 - || rec[DTLS1_RT_HEADER_LENGTH] - != (unsigned char)hs_msg_type)) - continue; - *pktidx = i; - *recidx = j; - return 1; - } - } - return 0; -} - -/* - * Split packet pktidx before record recidx and insert the tail at pktidx + 1. - * Splitting at either boundary (before record 0 or after the last record) - * is treated as a successful no-op. - */ -int mempacket_split_packet_at(BIO *bio, int pktidx, int recidx) -{ - MEMPACKET_TEST_CTX *ctx = BIO_get_data(bio); - MEMPACKET *srcpkt, *newpkt; - int numpkts = sk_MEMPACKET_num(ctx->pkts); - int rem, len, i, split_off = 0; - unsigned char *rec; - - if (pktidx < 0 || pktidx >= numpkts || recidx < 0) - return 0; - - srcpkt = sk_MEMPACKET_value(ctx->pkts, pktidx); - if (srcpkt == NULL) - return 0; - - for (i = 0, rem = srcpkt->len, rec = srcpkt->data; - rem >= DTLS1_RT_HEADER_LENGTH && i < recidx; - i++, rem -= len, rec += len) { - len = ((rec[RECORD_LEN_HI] << 8) | rec[RECORD_LEN_LO]) - + DTLS1_RT_HEADER_LENGTH; - if (rem < len) - return 0; - split_off += len; - } - - if (i != recidx) - return 0; - - if (split_off == 0 || split_off == srcpkt->len) - return 1; - - newpkt = OPENSSL_malloc(sizeof(*newpkt)); - if (newpkt == NULL) - return 0; - - newpkt->len = srcpkt->len - split_off; - newpkt->data = OPENSSL_malloc(newpkt->len); - if (newpkt->data == NULL) { - OPENSSL_free(newpkt); - return 0; - } - - memcpy(newpkt->data, srcpkt->data + split_off, newpkt->len); - newpkt->type = srcpkt->type; - if (pktidx + 1 < numpkts - && sk_MEMPACKET_value(ctx->pkts, pktidx + 1) != NULL) - newpkt->num = sk_MEMPACKET_value(ctx->pkts, pktidx + 1)->num; - else - newpkt->num = srcpkt->num + 1; - - if (sk_MEMPACKET_insert(ctx->pkts, newpkt, pktidx + 1) <= 0) { - OPENSSL_free(newpkt->data); - OPENSSL_free(newpkt); - return 0; - } - - srcpkt->len = split_off; - - numpkts = sk_MEMPACKET_num(ctx->pkts); - for (i = pktidx + 2; i < numpkts; i++) - sk_MEMPACKET_value(ctx->pkts, i)->num++; - - return 1; -} - -/* - * Append arbitrary data to a given record. The record must be the last record - * in the packet - */ -int mempacket_append_to_record(BIO *bio, int pktidx, int recidx, - unsigned char *data, size_t datalen) -{ - MEMPACKET_TEST_CTX *ctx = BIO_get_data(bio); - MEMPACKET *srcpkt; - size_t rem, len; - int i; - unsigned char *rec, *tmp; - - if (ctx == NULL) - return 0; - srcpkt = sk_MEMPACKET_value(ctx->pkts, pktidx); - if (srcpkt == NULL) - return 0; - - tmp = OPENSSL_realloc(srcpkt->data, srcpkt->len + datalen); - if (tmp == NULL) - return 0; - srcpkt->data = tmp; - - /* Parse the records in the packet looking for the target record index */ - for (i = 0, rem = srcpkt->len, rec = srcpkt->data; - rem >= DTLS1_RT_HEADER_LENGTH && i < recidx; - i++, rem -= len, rec += len) { - len = ((rec[RECORD_LEN_HI] << 8) | rec[RECORD_LEN_LO]) - + DTLS1_RT_HEADER_LENGTH; - if (rem < len) - return 0; - } - - if (i != recidx || rem < DTLS1_RT_HEADER_LENGTH) - return 0; - - len = (rec[RECORD_LEN_HI] << 8) | rec[RECORD_LEN_LO]; - /* We can only append to the last record */ - if (rem != len + DTLS1_RT_HEADER_LENGTH) - return 0; - - /* Check we can fit the extra data in the record */ - if (0xffff - len < datalen) - return 0; - len += datalen; - rec[RECORD_LEN_HI] = (len >> 8) & 0xff; - rec[RECORD_LEN_LO] = len & 0xff; - memcpy(srcpkt->data + srcpkt->len, data, datalen); - srcpkt->len += (int)datalen; - return 1; -} - int mempacket_dup_last_packet(BIO *bio) { MEMPACKET_TEST_CTX *ctx = BIO_get_data(bio); diff --git a/test/helpers/ssltestlib.h b/test/helpers/ssltestlib.h index 68a10b24bd..9477e06b13 100644 --- a/test/helpers/ssltestlib.h +++ b/test/helpers/ssltestlib.h @@ -74,11 +74,6 @@ void bio_s_maybe_retry_free(void); int mempacket_swap_epoch(BIO *bio); int mempacket_move_packet(BIO *bio, int d, int s); -int mempacket_find_record(BIO *bio, int rectype, int hs_msg_type, - int *pktidx, int *recidx); -int mempacket_split_packet_at(BIO *bio, int pktidx, int recidx); -int mempacket_append_to_record(BIO *bio, int pktidx, int recidx, - unsigned char *data, size_t datalen); int mempacket_dup_last_packet(BIO *bio); int mempacket_test_inject(BIO *bio, const char *in, int inl, int pktnum, int type); diff --git a/test/hmactest.c b/test/hmactest.c index 4d75a8d5f4..d3ae8955d8 100644 --- a/test/hmactest.c +++ b/test/hmactest.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -33,7 +33,7 @@ #ifndef OPENSSL_NO_MD5 static struct test_st { - const unsigned char key[16]; + const char key[16]; int key_len; const unsigned char data[64]; int data_len; @@ -47,7 +47,7 @@ static struct test_st { "e9139d1e6ee064ef8cf514fc7dc83e86", }, { - { 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b, 0x0b }, + "\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b\x0b", 16, "Hi There", 8, @@ -61,7 +61,7 @@ static struct test_st { "750c783e6ab0b503eaa86e310a5db738", }, { - { 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa, 0xaa }, + "\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa\xaa", 16, { 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, 0xdd, diff --git a/test/hpke_test.c b/test/hpke_test.c index cd43c0e9a1..b223193858 100644 --- a/test/hpke_test.c +++ b/test/hpke_test.c @@ -287,10 +287,38 @@ static const unsigned char first_ikmr[] = { 0xb7, 0xac, 0xcf, 0xaf, 0xf8, 0x99, 0x50, 0x98 }; static const unsigned char first_ikmepub[] = { - 0x0a, 0xd0, 0x95, 0x0d, 0x9f, 0xb9, 0x58, 0x8e, 0x59, 0x69, - 0x0b, 0x74, 0xf1, 0x23, 0x7e, 0xcd, 0xf1, 0xd7, 0x75, 0xcd, - 0x60, 0xbe, 0x2e, 0xca, 0x57, 0xaf, 0x5a, 0x4b, 0x04, 0x71, - 0xc9, 0x1b + 0x0a, + 0xd0, + 0x95, + 0x0d, + 0x9f, + 0xb9, + 0x58, + 0x8e, + 0x59, + 0x69, + 0x0b, + 0x74, + 0xf1, + 0x23, + 0x7e, + 0xcd, + 0xf1, + 0xd7, + 0x75, + 0xcd, + 0x60, + 0xbe, + 0x2e, + 0xca, + 0x57, + 0xaf, + 0x5a, + 0x4b, + 0x04, + 0x71, + 0xc9, + 0x1b, }; static const unsigned char first_ikmrpub[] = { 0x9f, 0xed, 0x7e, 0x8c, 0x17, 0x38, 0x75, 0x60, @@ -417,10 +445,38 @@ static const unsigned char second_ikme[] = { 0x98, 0x12, 0xe6, 0x67, 0x06, 0xdf, 0x32, 0x34 }; static const unsigned char second_ikmepub[] = { - 0x37, 0xfd, 0xa3, 0x56, 0x7b, 0xdb, 0xd6, 0x28, 0xe8, 0x86, - 0x68, 0xc3, 0xc8, 0xd7, 0xe9, 0x7d, 0x1d, 0x12, 0x53, 0xb6, - 0xd4, 0xea, 0x6d, 0x44, 0xc1, 0x50, 0xf7, 0x41, 0xf1, 0xbf, - 0x44, 0x31 + 0x37, + 0xfd, + 0xa3, + 0x56, + 0x7b, + 0xdb, + 0xd6, + 0x28, + 0xe8, + 0x86, + 0x68, + 0xc3, + 0xc8, + 0xd7, + 0xe9, + 0x7d, + 0x1d, + 0x12, + 0x53, + 0xb6, + 0xd4, + 0xea, + 0x6d, + 0x44, + 0xc1, + 0x50, + 0xf7, + 0x41, + 0xf1, + 0xbf, + 0x44, + 0x31, }; static const unsigned char second_ikmr[] = { 0x6d, 0xb9, 0xdf, 0x30, 0xaa, 0x07, 0xdd, 0x42, @@ -538,13 +594,71 @@ static const unsigned char third_ikme[] = { 0x1f, 0x5a, 0xa2, 0x28, 0x16, 0xce, 0x86, 0x0e }; static const unsigned char third_ikmepub[] = { - 0x04, 0xa9, 0x27, 0x19, 0xc6, 0x19, 0x5d, 0x50, 0x85, 0x10, - 0x4f, 0x46, 0x9a, 0x8b, 0x98, 0x14, 0xd5, 0x83, 0x8f, 0xf7, - 0x2b, 0x60, 0x50, 0x1e, 0x2c, 0x44, 0x66, 0xe5, 0xe6, 0x7b, - 0x32, 0x5a, 0xc9, 0x85, 0x36, 0xd7, 0xb6, 0x1a, 0x1a, 0xf4, - 0xb7, 0x8e, 0x5b, 0x7f, 0x95, 0x1c, 0x09, 0x00, 0xbe, 0x86, - 0x3c, 0x40, 0x3c, 0xe6, 0x5c, 0x9b, 0xfc, 0xb9, 0x38, 0x26, - 0x57, 0x22, 0x2d, 0x18, 0xc4 + 0x04, + 0xa9, + 0x27, + 0x19, + 0xc6, + 0x19, + 0x5d, + 0x50, + 0x85, + 0x10, + 0x4f, + 0x46, + 0x9a, + 0x8b, + 0x98, + 0x14, + 0xd5, + 0x83, + 0x8f, + 0xf7, + 0x2b, + 0x60, + 0x50, + 0x1e, + 0x2c, + 0x44, + 0x66, + 0xe5, + 0xe6, + 0x7b, + 0x32, + 0x5a, + 0xc9, + 0x85, + 0x36, + 0xd7, + 0xb6, + 0x1a, + 0x1a, + 0xf4, + 0xb7, + 0x8e, + 0x5b, + 0x7f, + 0x95, + 0x1c, + 0x09, + 0x00, + 0xbe, + 0x86, + 0x3c, + 0x40, + 0x3c, + 0xe6, + 0x5c, + 0x9b, + 0xfc, + 0xb9, + 0x38, + 0x26, + 0x57, + 0x22, + 0x2d, + 0x18, + 0xc4, }; static const unsigned char third_ikmr[] = { 0x66, 0x8b, 0x37, 0x17, 0x1f, 0x10, 0x72, 0xf3, @@ -949,9 +1063,10 @@ static int test_hpke_modes_suites(void) hpke_suite.kem_id = kem_id; if (hpke_mode == OSSL_HPKE_MODE_AUTH || hpke_mode == OSSL_HPKE_MODE_PSKAUTH) { - if (!TEST_true(OSSL_HPKE_keygen(hpke_suite, authpub, &authpublen, + if (TEST_true(OSSL_HPKE_keygen(hpke_suite, authpub, &authpublen, &authpriv, NULL, 0, - testctx, NULL))) { + testctx, NULL)) + != 1) { overallresult = 0; } authpubp = authpub; @@ -1194,7 +1309,7 @@ static int test_hpke_suite_strs(void) for (aeadind = 0; aeadind != OSSL_NELEM(aead_str_list); aeadind++) { BIO_snprintf(sstr, 128, "%s,%s,%s", kem_str_list[kemind], kdf_str_list[kdfind], aead_str_list[aeadind]); - if (!TEST_true(OSSL_HPKE_str2suite(sstr, &stirred))) { + if (TEST_true(OSSL_HPKE_str2suite(sstr, &stirred)) != 1) { if (verbose) TEST_note("Unexpected str2suite fail for :%s", bogus_suite_strs[sind]); @@ -1204,8 +1319,9 @@ static int test_hpke_suite_strs(void) } } for (sind = 0; sind != OSSL_NELEM(bogus_suite_strs); sind++) { - if (!TEST_false(OSSL_HPKE_str2suite(bogus_suite_strs[sind], - &stirred))) { + if (TEST_false(OSSL_HPKE_str2suite(bogus_suite_strs[sind], + &stirred)) + != 1) { if (verbose) TEST_note("OSSL_HPKE_str2suite didn't fail for bogus[%d]:%s", sind, bogus_suite_strs[sind]); @@ -1248,18 +1364,20 @@ static int test_hpke_grease(void) /* GREASEing */ /* check too short for public value */ g_pub_len = 10; - if (!TEST_false(OSSL_HPKE_get_grease_value(NULL, &g_suite, + if (TEST_false(OSSL_HPKE_get_grease_value(NULL, &g_suite, g_pub, &g_pub_len, g_cipher, g_cipher_len, - testctx, NULL))) { + testctx, NULL)) + != 1) { overallresult = 0; } /* reset to work */ g_pub_len = OSSL_HPKE_TSTSIZE; - if (!TEST_true(OSSL_HPKE_get_grease_value(NULL, &g_suite, + if (TEST_true(OSSL_HPKE_get_grease_value(NULL, &g_suite, g_pub, &g_pub_len, g_cipher, g_cipher_len, - testctx, NULL))) { + testctx, NULL)) + != 1) { overallresult = 0; } /* expansion */ diff --git a/test/http_test.c b/test/http_test.c index d122a45426..e7a402dae6 100644 --- a/test/http_test.c +++ b/test/http_test.c @@ -11,7 +11,6 @@ #include #include #include -#include #include #include "testutil.h" @@ -287,10 +286,8 @@ err: return res; } -static int test_http_url_invalid(const char *url); - -static int test_http_url_frag_ok(const char *url, int exp_ssl, const char *exp_host, - const char *exp_port, const char *exp_path, const char *exp_frag) +static int test_http_url_ok(const char *url, int exp_ssl, const char *exp_host, + const char *exp_port, const char *exp_path) { char *user, *host, *port, *path, *query, *frag; int exp_num, num, ssl; @@ -307,8 +304,8 @@ static int test_http_url_frag_ok(const char *url, int exp_ssl, const char *exp_h && TEST_int_eq(ssl, exp_ssl); if (res && *user != '\0') res = TEST_str_eq(user, "user:pass"); - if (res) - res = TEST_str_eq(frag, exp_frag); + if (res && *frag != '\0') + res = TEST_str_eq(frag, "fr"); if (res && *query != '\0') res = TEST_str_eq(query, "q"); OPENSSL_free(user); @@ -320,12 +317,6 @@ static int test_http_url_frag_ok(const char *url, int exp_ssl, const char *exp_h return res; } -static int test_http_url_ok(const char *url, int exp_ssl, const char *exp_host, - const char *exp_port, const char *exp_path) -{ - return test_http_url_frag_ok(url, exp_ssl, exp_host, exp_port, exp_path, ""); -} - static int test_http_url_path_query_ok(const char *url, const char *exp_path_qu) { char *host, *path; @@ -340,28 +331,11 @@ static int test_http_url_path_query_ok(const char *url, const char *exp_path_qu) return res; } -static int test_http_url_host_ok(const char *url, const char *exp_host) -{ - char *host; - int res; - - res = TEST_true(OSSL_HTTP_parse_url(url, NULL, NULL, &host, NULL, NULL, - NULL, NULL, NULL)) - && TEST_str_eq(host, exp_host); - OPENSSL_free(host); - return res; -} - static int test_http_url_dns(void) { return test_http_url_ok("host:65535/path", 0, "host", "65535", "/path"); } -static int test_http_url_ip(void) -{ - return test_http_url_ok("1.2.3.4:5678//blahblablah", 0, "1.2.3.4", "5678", "//blahblablah"); -} - static int test_http_url_timestamp(void) { return test_http_url_ok("host/p/2017-01-03T00:00:00", 0, "host", "80", @@ -381,16 +355,7 @@ static int test_http_url_path_query(void) static int test_http_url_userinfo_query_fragment(void) { - return test_http_url_frag_ok("user:pass@host/p?q#fr", 0, "host", "80", "/p", "fr") - && test_http_url_frag_ok("host.example.org/some/path#://not-a-scheme/not.a.host:404", 0, - "host.example.org", "80", "/some/path", "://not-a-scheme/not.a.host:404"); -} - -static int test_http_url_at_sign_outside_authority(void) -{ - return test_http_url_host_ok("http://host/p@attacker.test", "host") - && test_http_url_host_ok("http://host/p?q=@attacker.test", "host") - && test_http_url_host_ok("http://host/p?q#fr@attacker.test", "host"); + return test_http_url_ok("user:pass@host/p?q#fr", 0, "host", "80", "/p"); } static int test_http_url_ipv4(void) @@ -400,8 +365,7 @@ static int test_http_url_ipv4(void) static int test_http_url_ipv6(void) { - return test_http_url_ok("http://[FF01::101]:6", 0, "[FF01::101]", "6", "/") - && test_http_url_invalid("http://[FF01::101/path]"); + return test_http_url_ok("http://[FF01::101]:6", 0, "[FF01::101]", "6", "/"); } static int test_http_url_invalid(const char *url) @@ -439,57 +403,6 @@ static int test_http_url_invalid_path(void) return test_http_url_invalid("https://[FF01::101]pkix"); } -static int test_http_crlf_rejected(void) -{ - BIO *wbio = BIO_new(BIO_s_mem()); - BIO *rbio = BIO_new(BIO_s_mem()); - BIO *req = BIO_new(BIO_s_mem()); - BIO *proxy_bio = BIO_new(BIO_s_mem()); - OSSL_HTTP_REQ_CTX *rctx = NULL; - int res = 0; - - if (!TEST_ptr(wbio) - || !TEST_ptr(rbio) - || !TEST_ptr(req) - || !TEST_ptr(proxy_bio) - || !TEST_int_eq(BIO_puts(req, "x"), 1) - || !TEST_ptr(rctx = OSSL_HTTP_REQ_CTX_new(wbio, rbio, 0))) - goto err; - - ERR_clear_error(); - res = TEST_false(OSSL_HTTP_REQ_CTX_set_request_line(rctx, 0 /* GET */, - NULL, NULL, "/path\r\nInjected: value")) - && TEST_false(OSSL_HTTP_REQ_CTX_set_request_line(rctx, 0 /* GET */, - "server\r\nInjected: value", "80", RPATH)) - && TEST_false(OSSL_HTTP_REQ_CTX_set_request_line(rctx, 0 /* GET */, - "server", "80\r\nInjected: value", RPATH)) - && TEST_true(OSSL_HTTP_REQ_CTX_set_request_line(rctx, 0 /* GET */, - NULL, NULL, RPATH)) - && TEST_false(OSSL_HTTP_REQ_CTX_add1_header(rctx, - "X-Test\r\nInjected", "value")) - && TEST_false(OSSL_HTTP_REQ_CTX_add1_header(rctx, - "X-Test", "value\r\nInjected: value")) - && TEST_false(OSSL_HTTP_set1_request(rctx, RPATH, NULL, - "text/plain\r\nInjected: value", req, - NULL, 0 /* expect_asn1 */, 0 /* max_resp_len */, - 0 /* timeout */, 0 /* keep_alive */)) - && TEST_false(OSSL_HTTP_proxy_connect(proxy_bio, - "server\r\nInjected: value", "443", NULL, NULL, - 0 /* timeout */, NULL, NULL)) - && TEST_false(OSSL_HTTP_proxy_connect(proxy_bio, - "server", "443\r\nInjected: value", NULL, NULL, - 0 /* timeout */, NULL, NULL)); - -err: - ERR_clear_error(); - OSSL_HTTP_REQ_CTX_free(rctx); - BIO_free(wbio); - BIO_free(rbio); - BIO_free(req); - BIO_free(proxy_bio); - return res; -} - static int test_http_get_txt(void) { return test_http_method(1 /* GET */, 1, HTTP_STATUS_CODE_OK); @@ -589,7 +502,7 @@ static int test_http_resp_hdr_limit(size_t limit) int res = 0; OSSL_HTTP_REQ_CTX *rctx = NULL; - if (!TEST_ptr(wbio) || !TEST_ptr(rbio)) + if (TEST_ptr(wbio) == 0 || TEST_ptr(rbio) == 0) goto err; mock_args.txt = text1; @@ -601,7 +514,7 @@ static int test_http_resp_hdr_limit(size_t limit) BIO_set_callback_arg(wbio, (char *)&mock_args); rctx = OSSL_HTTP_REQ_CTX_new(wbio, rbio, 8192); - if (!TEST_ptr(rctx)) + if (TEST_ptr(rctx) == 0) goto err; if (!TEST_true(OSSL_HTTP_REQ_CTX_set_request_line(rctx, 0 /* GET */, @@ -635,7 +548,7 @@ static int test_hdr_resp_hdr_limit_none(void) static int test_hdr_resp_hdr_limit_short(void) { - return test_http_resp_hdr_limit(1); + return (test_http_resp_hdr_limit(1)); } static int test_hdr_resp_hdr_limit_256(void) @@ -643,14 +556,6 @@ static int test_hdr_resp_hdr_limit_256(void) return test_http_resp_hdr_limit(256); } -static int test_http_adapt_proxy_empty_server(void) -{ - const char *proxy = "http://proxy.local:8080"; - - return TEST_str_eq(OSSL_HTTP_adapt_proxy(proxy, "abc", "", 0), proxy) - && TEST_str_eq(OSSL_HTTP_adapt_proxy(proxy, "abc", "[]", 0), proxy); -} - void cleanup_tests(void) { X509_free(x509); @@ -668,17 +573,14 @@ int setup_tests(void) return 0; ADD_TEST(test_http_url_dns); - ADD_TEST(test_http_url_ip); ADD_TEST(test_http_url_timestamp); ADD_TEST(test_http_url_path_query); ADD_TEST(test_http_url_userinfo_query_fragment); - ADD_TEST(test_http_url_at_sign_outside_authority); ADD_TEST(test_http_url_ipv4); ADD_TEST(test_http_url_ipv6); ADD_TEST(test_http_url_invalid_prefix); ADD_TEST(test_http_url_invalid_port); ADD_TEST(test_http_url_invalid_path); - ADD_TEST(test_http_crlf_rejected); ADD_TEST(test_http_get_txt); ADD_TEST(test_http_get_txt_redirected); @@ -703,6 +605,5 @@ int setup_tests(void) ADD_TEST(test_hdr_resp_hdr_limit_none); ADD_TEST(test_hdr_resp_hdr_limit_short); ADD_TEST(test_hdr_resp_hdr_limit_256); - ADD_TEST(test_http_adapt_proxy_empty_server); return 1; } diff --git a/test/ideatest.c b/test/ideatest.c index 4ad7f67054..d3f7761b90 100644 --- a/test/ideatest.c +++ b/test/ideatest.c @@ -35,8 +35,22 @@ static unsigned char out[80]; static const unsigned char text[] = "Hello to all people out there"; static const unsigned char cfb_key[16] = { - 0xe1, 0xf0, 0xc3, 0xd2, 0xa5, 0xb4, 0x87, 0x96, 0x69, 0x78, - 0x4b, 0x5a, 0x2d, 0x3c, 0x0f, 0x1e + 0xe1, + 0xf0, + 0xc3, + 0xd2, + 0xa5, + 0xb4, + 0x87, + 0x96, + 0x69, + 0x78, + 0x4b, + 0x5a, + 0x2d, + 0x3c, + 0x0f, + 0x1e, }; static const unsigned char cfb_iv[80] = { 0x34, 0x12, 0x78, 0x56, 0xab, 0x90, 0xef, 0xcd @@ -98,7 +112,7 @@ static int test_idea_cfb64(void) IDEA_set_decrypt_key(&eks, &dks); memcpy(cfb_tmp, cfb_iv, sizeof(cfb_tmp)); n = 0; - IDEA_cfb64_encrypt(plain, cfb_buf1, 12, &eks, + IDEA_cfb64_encrypt(plain, cfb_buf1, (long)12, &eks, cfb_tmp, &n, IDEA_ENCRYPT); IDEA_cfb64_encrypt(&plain[12], &cfb_buf1[12], (long)CFB_TEST_SIZE - 12, &eks, @@ -107,7 +121,7 @@ static int test_idea_cfb64(void) return 0; memcpy(cfb_tmp, cfb_iv, sizeof(cfb_tmp)); n = 0; - IDEA_cfb64_encrypt(cfb_buf1, cfb_buf2, 13, &eks, + IDEA_cfb64_encrypt(cfb_buf1, cfb_buf2, (long)13, &eks, cfb_tmp, &n, IDEA_DECRYPT); IDEA_cfb64_encrypt(&cfb_buf1[13], &cfb_buf2[13], (long)CFB_TEST_SIZE - 13, &eks, diff --git a/test/igetest.c b/test/igetest.c index 7e7ad0606f..d19c116d40 100644 --- a/test/igetest.c +++ b/test/igetest.c @@ -43,7 +43,7 @@ struct ige_test { const int encrypt; }; -static const struct ige_test ige_test_vectors[] = { +static struct ige_test const ige_test_vectors[] = { { { 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f }, /* key */ { 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, @@ -88,7 +88,7 @@ struct bi_ige_test { const int encrypt; }; -static const struct bi_ige_test bi_ige_test_vectors[] = { +static struct bi_ige_test const bi_ige_test_vectors[] = { { { 0x00, 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f }, /* key1 */ { 0x10, 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17, diff --git a/test/json_test.c b/test/json_test.c index d8aa5db051..4741825e71 100644 --- a/test/json_test.c +++ b/test/json_test.c @@ -64,11 +64,11 @@ struct script_word { void (*fp)(void); }; -#define OP_P(x) { (x) } -#define OP_U64(x) { NULL, (x) } -#define OP_I64(x) { NULL, 0, (x) } -#define OP_D(x) { NULL, 0, 0, (x) } -#define OP_FP(x) { NULL, 0, 0, 0, (void (*)(void))(x) } +#define OP_P(x) { (x) }, +#define OP_U64(x) { NULL, (x) }, +#define OP_I64(x) { NULL, 0, (x) }, +#define OP_D(x) { NULL, 0, 0, (x) }, +#define OP_FP(x) { NULL, 0, 0, 0, (void (*)(void))(x) }, struct script_info { const char *name, *title; @@ -102,28 +102,28 @@ typedef void (*fp_d_type)(OSSL_JSON_ENC *, double); typedef void (*fp_pz_type)(OSSL_JSON_ENC *, const void *, size_t); #define OP_END() OP_U64(OPK_END) -#define OP_CALL(f) OP_U64(OPK_CALL), OP_FP(f) -#define OP_CALL_P(f, x) OP_U64(OPK_CALL_P), OP_FP(f), OP_P(x) -#define OP_CALL_I(f, x) OP_U64(OPK_CALL_I), OP_FP(f), OP_I64(x) -#define OP_CALL_U64(f, x) OP_U64(OPK_CALL_U64), OP_FP(f), OP_U64(x) -#define OP_CALL_I64(f, x) OP_U64(OPK_CALL_I64), OP_FP(f), OP_I64(x) -#define OP_CALL_D(f, x) OP_U64(OPK_CALL_D), OP_FP(f), OP_D(x) -#define OP_CALL_PZ(f, x, xl) OP_U64(OPK_CALL_PZ), OP_FP(f), OP_P(x), OP_U64(xl) -#define OP_ASSERT_ERROR(err) OP_U64(OPK_ASSERT_ERROR), OP_U64(err), -#define OP_INIT_FLAGS(flags) OP_U64(OPK_INIT_FLAGS), OP_U64(flags) +#define OP_CALL(f) OP_U64(OPK_CALL) OP_FP(f) +#define OP_CALL_P(f, x) OP_U64(OPK_CALL_P) OP_FP(f) OP_P(x) +#define OP_CALL_I(f, x) OP_U64(OPK_CALL_I) OP_FP(f) OP_I64(x) +#define OP_CALL_U64(f, x) OP_U64(OPK_CALL_U64) OP_FP(f) OP_U64(x) +#define OP_CALL_I64(f, x) OP_U64(OPK_CALL_I64) OP_FP(f) OP_I64(x) +#define OP_CALL_D(f, x) OP_U64(OPK_CALL_D) OP_FP(f) OP_D(x) +#define OP_CALL_PZ(f, x, xl) OP_U64(OPK_CALL_PZ) OP_FP(f) OP_P(x) OP_U64(xl) +#define OP_ASSERT_ERROR(err) OP_U64(OPK_ASSERT_ERROR) OP_U64(err) +#define OP_INIT_FLAGS(flags) OP_U64(OPK_INIT_FLAGS) OP_U64(flags) -#define OPJ_BEGIN_O() OP_CALL(ossl_json_object_begin), -#define OPJ_END_O() OP_CALL(ossl_json_object_end), -#define OPJ_BEGIN_A() OP_CALL(ossl_json_array_begin), -#define OPJ_END_A() OP_CALL(ossl_json_array_end), -#define OPJ_NULL() OP_CALL(ossl_json_null), -#define OPJ_BOOL(x) OP_CALL_I(ossl_json_bool, (x)), -#define OPJ_U64(x) OP_CALL_U64(ossl_json_u64, (x)), -#define OPJ_I64(x) OP_CALL_I64(ossl_json_i64, (x)), -#define OPJ_KEY(x) OP_CALL_P(ossl_json_key, (x)), -#define OPJ_STR(x) OP_CALL_P(ossl_json_str, (x)), -#define OPJ_STR_LEN(x, xl) OP_CALL_PZ(ossl_json_str_len, (x), (xl)), -#define OPJ_STR_HEX(x, xl) OP_CALL_PZ(ossl_json_str_hex, (x), (xl)), +#define OPJ_BEGIN_O() OP_CALL(ossl_json_object_begin) +#define OPJ_END_O() OP_CALL(ossl_json_object_end) +#define OPJ_BEGIN_A() OP_CALL(ossl_json_array_begin) +#define OPJ_END_A() OP_CALL(ossl_json_array_end) +#define OPJ_NULL() OP_CALL(ossl_json_null) +#define OPJ_BOOL(x) OP_CALL_I(ossl_json_bool, (x)) +#define OPJ_U64(x) OP_CALL_U64(ossl_json_u64, (x)) +#define OPJ_I64(x) OP_CALL_I64(ossl_json_i64, (x)) +#define OPJ_KEY(x) OP_CALL_P(ossl_json_key, (x)) +#define OPJ_STR(x) OP_CALL_P(ossl_json_str, (x)) +#define OPJ_STR_LEN(x, xl) OP_CALL_PZ(ossl_json_str_len, (x), (xl)) +#define OPJ_STR_HEX(x, xl) OP_CALL_PZ(ossl_json_str_hex, (x), (xl)) #define BEGIN_SCRIPT(name, title, flags) \ static const struct script_info *get_script_##name(void) \ @@ -132,10 +132,10 @@ typedef void (*fp_pz_type)(OSSL_JSON_ENC *, const void *, size_t); static const char script_title[] = #title; \ \ static const struct script_word script_words[] = { \ - OP_INIT_FLAGS(flags), + OP_INIT_FLAGS(flags) #define END_SCRIPT_EXPECTING(s, slen) \ - OP_END(), \ + OP_END() \ } \ ; \ static const struct script_info script_info = { \ @@ -157,7 +157,7 @@ typedef void (*fp_pz_type)(OSSL_JSON_ENC *, const void *, size_t); #define END_SCRIPT_EXPECTING_S(s) END_SCRIPT_EXPECTING(s, SIZE_MAX) #define END_SCRIPT_EXPECTING_Q(s) END_SCRIPT_EXPECTING(#s, sizeof(#s) - 1) -#define SCRIPT(name) get_script_##name +#define SCRIPT(name) get_script_##name, BEGIN_SCRIPT(null, "serialize a single null", 0) OPJ_NULL() @@ -492,56 +492,56 @@ END_SCRIPT_EXPECTING_S("\x1Enull\n" "\x1E{\"x\":1,\"y\":{}}\n") static const info_func scripts[] = { - SCRIPT(null), - SCRIPT(obj_empty), - SCRIPT(array_empty), - SCRIPT(bool_false), - SCRIPT(bool_true), - SCRIPT(u64_0), - SCRIPT(u64_1), - SCRIPT(u64_10), - SCRIPT(u64_12345), - SCRIPT(u64_18446744073709551615), - SCRIPT(i64_0), - SCRIPT(i64_1), - SCRIPT(i64_2), - SCRIPT(i64_10), - SCRIPT(i64_12345), - SCRIPT(i64_9223372036854775807), - SCRIPT(i64_m1), - SCRIPT(i64_m2), - SCRIPT(i64_m10), - SCRIPT(i64_m12345), - SCRIPT(i64_m9223372036854775807), - SCRIPT(i64_m9223372036854775808), - SCRIPT(str_empty), - SCRIPT(str_a), - SCRIPT(str_abc), - SCRIPT(str_quote), - SCRIPT(str_quote2), - SCRIPT(str_escape), - SCRIPT(str_len), - SCRIPT(str_len0), - SCRIPT(str_len_nul), - SCRIPT(hex_data0), - SCRIPT(hex_data), - SCRIPT(array_nest1), - SCRIPT(array_nest2), - SCRIPT(array_nest3), - SCRIPT(array_nest4), - SCRIPT(obj_nontrivial1), - SCRIPT(obj_nontrivial2), - SCRIPT(obj_nest1), - SCRIPT(err_obj_no_key), - SCRIPT(err_obj_multi_key), - SCRIPT(err_obj_no_value), - SCRIPT(err_utf8), - SCRIPT(utf8_2), - SCRIPT(utf8_3), - SCRIPT(utf8_4), - SCRIPT(ijson_int), - SCRIPT(multi_item), - SCRIPT(seq), + SCRIPT(null) + SCRIPT(obj_empty) + SCRIPT(array_empty) + SCRIPT(bool_false) + SCRIPT(bool_true) + SCRIPT(u64_0) + SCRIPT(u64_1) + SCRIPT(u64_10) + SCRIPT(u64_12345) + SCRIPT(u64_18446744073709551615) + SCRIPT(i64_0) + SCRIPT(i64_1) + SCRIPT(i64_2) + SCRIPT(i64_10) + SCRIPT(i64_12345) + SCRIPT(i64_9223372036854775807) + SCRIPT(i64_m1) + SCRIPT(i64_m2) + SCRIPT(i64_m10) + SCRIPT(i64_m12345) + SCRIPT(i64_m9223372036854775807) + SCRIPT(i64_m9223372036854775808) + SCRIPT(str_empty) + SCRIPT(str_a) + SCRIPT(str_abc) + SCRIPT(str_quote) + SCRIPT(str_quote2) + SCRIPT(str_escape) + SCRIPT(str_len) + SCRIPT(str_len0) + SCRIPT(str_len_nul) + SCRIPT(hex_data0) + SCRIPT(hex_data) + SCRIPT(array_nest1) + SCRIPT(array_nest2) + SCRIPT(array_nest3) + SCRIPT(array_nest4) + SCRIPT(obj_nontrivial1) + SCRIPT(obj_nontrivial2) + SCRIPT(obj_nest1) + SCRIPT(err_obj_no_key) + SCRIPT(err_obj_multi_key) + SCRIPT(err_obj_no_value) + SCRIPT(err_utf8) + SCRIPT(utf8_2) + SCRIPT(utf8_3) + SCRIPT(utf8_4) + SCRIPT(ijson_int) + SCRIPT(multi_item) + SCRIPT(seq) }; /* Test runner. */ @@ -637,7 +637,7 @@ static int run_script(const struct script_info *info) break; } -#define OP_ASSERT_ERROR(err) OP_U64(OPK_ASSERT_ERROR), OP_U64(err), +#define OP_ASSERT_ERROR(err) OP_U64(OPK_ASSERT_ERROR) OP_U64(err) default: TEST_error("unknown opcode"); diff --git a/test/keymgmt_internal_test.c b/test/keymgmt_internal_test.c index 17cea21ed2..c44c44ed73 100644 --- a/test/keymgmt_internal_test.c +++ b/test/keymgmt_internal_test.c @@ -301,7 +301,7 @@ static int test_evp_pkey_export_to_provider(int n) OSSL_PROVIDER *prov = NULL; X509 *cert = NULL; BIO *bio = NULL; - const X509_PUBKEY *pubkey = NULL; + X509_PUBKEY *pubkey = NULL; EVP_KEYMGMT *keymgmt = NULL; EVP_PKEY *pkey = NULL; void *keydata = NULL; diff --git a/test/lhash_test.c b/test/lhash_test.c index 87dc71f829..b42b467d4b 100644 --- a/test/lhash_test.c +++ b/test/lhash_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2017, Oracle and/or its affiliates. All rights reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -32,8 +32,6 @@ DEFINE_LHASH_OF_EX(int); -static void hashtable_intfree(HT_VALUE *v); - static int int_tests[] = { 65537, 13, 1, 3, -5, 6, 7, 4, -10, -12, -14, 22, 9, -17, 16, 17, -23, 35, 37, 173, 11 }; static const size_t n_int_tests = OSSL_NELEM(int_tests); @@ -246,7 +244,6 @@ static int test_int_hashtable(int idx) /* insert */ HT_INIT_KEY(&key); for (i = 0; i < n_int_tests; i++) { - HT_KEY_RESET(&key); HT_SET_KEY_FIELD(&key, mykey, int_tests[i]); if (!TEST_int_eq(ossl_ht_test_int_insert(ht, TO_HT_KEY(&key), &int_tests[i], NULL), @@ -283,7 +280,6 @@ static int test_int_hashtable(int idx) /* delete */ for (i = 0; i < n_dels; i++) { - HT_KEY_RESET(&key); HT_SET_KEY_FIELD(&key, mykey, dels[i].data); todel = ossl_ht_delete(ht, TO_HT_KEY(&key)); if (dels[i].should_del) { @@ -306,84 +302,6 @@ end: return rc; } -/* - * MFAIL coverage for the RCU replacement branch of ossl_ht_insert_locked. - */ -static int test_hashtable_insert_replace_mfail(void) -{ - HT_CONFIG hash_conf = { - .collision_check = 1, - .no_rcu = 0, /* RCU enabled - exercises cbi pre-alloc on replace */ - }; - INTKEY key; - HT *ht = NULL; - int *old = NULL; - int ret = 0; - static int v1 = 100; - static int v2 = 200; - - if (!TEST_ptr(ht = ossl_ht_new(&hash_conf))) - goto end; - - /* Seed the table outside MFAIL for later replacement */ - HT_INIT_KEY(&key); - HT_KEY_RESET(&key); - HT_SET_KEY_FIELD(&key, mykey, int_tests[0]); - if (!TEST_int_eq(ossl_ht_test_int_insert(ht, TO_HT_KEY(&key), &v1, NULL), - 1)) - goto end; - - /* Replacement under MFAIL. */ - MFAIL_start(); - ret = ossl_ht_test_int_insert(ht, TO_HT_KEY(&key), &v2, &old); - MFAIL_end(); - -end: - ossl_ht_free(ht); - return ret > 0 ? 1 : 0; -} - -static int test_hashtable_free_mfail(void) -{ - HT_CONFIG hash_conf = { - .ht_free_fn = hashtable_intfree, - .collision_check = 1, - .no_rcu = 0, - }; - INTKEY key; - HT *ht = NULL; - int *p; - size_t i; - - if (!TEST_ptr(ht = ossl_ht_new(&hash_conf))) - return 0; - - /* Seed values. */ - HT_INIT_KEY(&key); - for (i = 0; i < n_int_tests; i++) { - if (!TEST_ptr(p = OPENSSL_malloc(sizeof(*p)))) - goto end; - *p = int_tests[i]; - HT_KEY_RESET(&key); - HT_SET_KEY_FIELD(&key, mykey, *p); - if (!TEST_int_eq(ossl_ht_test_int_insert(ht, TO_HT_KEY(&key), - p, NULL), - 1)) { - OPENSSL_free(p); - goto end; - } - } - MFAIL_start(); - ossl_ht_free(ht); - MFAIL_end(); - ht = NULL; - - return 1; -end: - ossl_ht_free(ht); - return 0; -} - static unsigned long int stress_hash(const int *p) { return *p; @@ -521,7 +439,6 @@ static int test_hashtable_stress(int idx) goto end; } *p = 3 * i + 1; - HT_KEY_RESET(&key); HT_SET_KEY_FIELD(&key, mykey, *p); if (!TEST_int_eq(ossl_ht_test_int_insert(h, TO_HT_KEY(&key), p, NULL), @@ -538,7 +455,6 @@ static int test_hashtable_stress(int idx) /* delete or get in a different order */ for (i = 0; i < n; i++) { const int j = (7 * i + 4) % n * 3 + 1; - HT_KEY_RESET(&key); HT_SET_KEY_FIELD(&key, mykey, j); switch (idx % 2) { @@ -580,35 +496,7 @@ static HT *m_ht = NULL; #define NUM_WORKERS 16 static struct test_mt_entry test_mt_entries[TEST_MT_POOL_SZ]; -static char **worker_exits; -static thread_t *workers; -static int num_workers = NUM_WORKERS; - -static int setup_num_workers(void) -{ - char *harness_jobs = getenv("HARNESS_JOBS"); - char *lhash_workers = getenv("LHASH_WORKERS"); - /* If we have HARNESS_JOBS set, don't eat more than a quarter */ - if (harness_jobs != NULL) { - int jobs = atoi(harness_jobs); - if (jobs > 0) - num_workers = jobs / 4; - } - /* But if we have explicitly set LHASH_WORKERS use that */ - if (lhash_workers != NULL) { - int jobs = atoi(lhash_workers); - if (jobs > 0) - num_workers = jobs; - } - - TEST_info("using %d workers\n", num_workers); - - free(worker_exits); - free(workers); - worker_exits = calloc(num_workers, sizeof(*worker_exits)); - workers = calloc(num_workers, sizeof(*workers)); - return worker_exits != NULL && workers != NULL; -} +static char *worker_exits[NUM_WORKERS]; HT_START_KEY_DEFN(mtkey) HT_DEF_KEY_FIELD(index, uint32_t) @@ -798,15 +686,15 @@ static int test_hashtable_multithread(int idx) .no_rcu = idx, }; int ret = 0; + thread_t workers[NUM_WORKERS]; int i; #ifdef MEASURE_HASH_PERFORMANCE struct timeval start, end, delta; #endif - if (!TEST_true(setup_num_workers())) - goto end; - + memset(worker_exits, 0, sizeof(char *) * NUM_WORKERS); memset(test_mt_entries, 0, sizeof(TEST_MT_ENTRY) * TEST_MT_POOL_SZ); + memset(workers, 0, sizeof(thread_t) * NUM_WORKERS); m_ht = ossl_ht_new(&hash_conf); @@ -823,13 +711,13 @@ static int test_hashtable_multithread(int idx) gettimeofday(&start, NULL); #endif - for (i = 0; i < num_workers; i++) { + for (i = 0; i < NUM_WORKERS; i++) { if (!run_thread(&workers[i], do_mt_hash_work)) goto shutdown; } shutdown: - for (i = 0; i < num_workers; i++) { + for (--i; i >= 0; i--) { wait_for_thread(workers[i]); } @@ -838,7 +726,7 @@ shutdown: * conditions */ ret = 1; - for (i = 0; i < num_workers; i++) { + for (i = 0; i < NUM_WORKERS; i++) { if (worker_exits[i] != NULL) { TEST_info("Worker %d failed: %s\n", i, worker_exits[i]); ret = 0; @@ -864,10 +752,6 @@ end_free: CRYPTO_THREAD_lock_free(worker_lock); CRYPTO_THREAD_lock_free(testrand_lock); CRYPTO_THREAD_lock_free(no_rcu_lock); - free(workers); - workers = NULL; - free(worker_exits); - worker_exits = NULL; end: return ret; } @@ -879,7 +763,5 @@ int setup_tests(void) ADD_ALL_TESTS(test_int_hashtable, 2); ADD_ALL_TESTS(test_hashtable_stress, 4); ADD_ALL_TESTS(test_hashtable_multithread, 2); - ADD_MFAIL_TEST(test_hashtable_insert_replace_mfail); - ADD_MFAIL_NO_CHECK_TEST(test_hashtable_free_mfail); return 1; } diff --git a/test/lms_test.c b/test/lms_test.c index d86e7ae6d8..579da37276 100644 --- a/test/lms_test.c +++ b/test/lms_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -281,20 +281,15 @@ static int lms_digest_verify_fail_test(void) LMS_ACVP_TEST_DATA *td = &lms_testdata[0]; EVP_PKEY *pub = NULL; EVP_MD_CTX *vctx = NULL; - int expected = 1; if (!TEST_ptr(pub = lms_pubkey_from_data(td->pub, td->publen))) return 0; if (!TEST_ptr(vctx = EVP_MD_CTX_new())) goto err; - /* Prior to 4.0 EVP_DigestVerifyInit_ex is not supported */ - if (OSSL_PROVIDER_available(libctx, "fips") - && fips_provider_version_match(libctx, "<4.0.0")) - expected = 0; - + /* Only one shot mode is supported, streaming fails to initialise */ if (!TEST_int_eq(EVP_DigestVerifyInit_ex(vctx, NULL, NULL, libctx, NULL, pub, NULL), - expected)) + 0)) goto err; ret = 1; err: diff --git a/test/load_key_certs_crls_memfail.c b/test/load_key_certs_crls_memfail.c deleted file mode 100644 index 6d6125c946..0000000000 --- a/test/load_key_certs_crls_memfail.c +++ /dev/null @@ -1,96 +0,0 @@ -/* - * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"); you may not use - * this file except in compliance with the License. You may obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - * - * Regression test for issue #30364: memory leak in load_key_certs_crls() - * when X509_add_cert() or sk_X509_CRL_push() fails. Exercises the add/push - * path under OPENSSL_MALLOC_FAILURES so that with the fix the cert/CRL is - * freed on failure (memory_sanitizer would report a leak without the fix). - */ - -#include -#include - -#include -#include -#include "apps.h" -#include "app_libctx.h" -#include "testutil.h" - -char *default_config_file = NULL; - -static char *certfile = NULL; -static int mcount, rcount, fcount, scount, srcount; - -static int do_load_key_certs_crls(int allow_failure) -{ - STACK_OF(X509) *certs = NULL; - int ret = (allow_failure == 1) ? 0 : 1; - char uri[1024]; - - if (certfile == NULL) - return 0; - - (void)snprintf(uri, sizeof(uri), "file:%s", certfile); - if (!TEST_true(load_key_certs_crls(uri, FORMAT_UNDEF, 0, NULL, "cert", - 1, NULL, NULL, NULL, NULL, &certs, - NULL, NULL, NULL))) - goto err; - - ret = 1; -err: - sk_X509_pop_free(certs, X509_free); - return ret; -} - -static int test_record_alloc_counts(void) -{ - return do_load_key_certs_crls(1); -} - -static int test_alloc_failures(void) -{ - return do_load_key_certs_crls(0); -} - -static int test_report_alloc_counts(void) -{ - CRYPTO_get_alloc_counts(&mcount, &rcount, &fcount); - TEST_info("skip: %d count %d\n", - scount + srcount, mcount + rcount - scount - srcount); - return 1; -} - -int setup_tests(void) -{ - int ret = 0; - char *opmode = NULL; - - if (app_create_libctx() == NULL) - return 0; - - if (!TEST_ptr(opmode = test_get_argument(0))) - goto err; - - if (!TEST_ptr(certfile = test_get_argument(1))) - goto err; - - if (strcmp(opmode, "count") == 0) { - CRYPTO_get_alloc_counts(&scount, &srcount, &fcount); - ADD_TEST(test_record_alloc_counts); - ADD_TEST(test_report_alloc_counts); - } else { - ADD_TEST(test_alloc_failures); - } - ret = 1; -err: - return ret; -} - -void cleanup_tests(void) -{ -} diff --git a/test/localetest.c b/test/localetest.c index 176219f009..63871fa063 100644 --- a/test/localetest.c +++ b/test/localetest.c @@ -95,7 +95,7 @@ int setup_tests(void) char str1[] = "SubjectPublicKeyInfo", str2[] = "subjectpublickeyinfo"; int res; X509 *cert = NULL; - const X509_PUBKEY *cert_pubkey = NULL; + X509_PUBKEY *cert_pubkey = NULL; const unsigned char *p = der_bytes; if (setlocale(LC_ALL, "") == NULL) diff --git a/test/mem_alloc_test.c b/test/mem_alloc_test.c index c6ae139ae1..cef1271f78 100644 --- a/test/mem_alloc_test.c +++ b/test/mem_alloc_test.c @@ -78,7 +78,7 @@ static const struct array_alloc_vector { { 1, 1, EXP_NONNULL, EXP_NONNULL }, - { SQRT_SIZE_T - 1, SQRT_SIZE_T - 1, EXP_OOM, EXP_OOM }, + { SQRT_SIZE_T / 2, SQRT_SIZE_T, EXP_OOM, EXP_OOM }, { SQRT_SIZE_T, SQRT_SIZE_T, EXP_ZERO_SIZE, EXP_INT_OF }, @@ -88,6 +88,8 @@ static const struct array_alloc_vector { #else /* Of course there are no archutectures other than 32- and 64-bit ones */ { 274177, 67280421310721LLU, EXP_NONNULL, EXP_INT_OF }, #endif + + { SIZE_MAX / 4 * 3, SIZE_MAX / 2, EXP_OOM, EXP_INT_OF }, }; static const struct array_realloc_vector { @@ -188,7 +190,7 @@ static int secure_memory_is_secure; static void *my_malloc(const size_t num, const char *const file, const int line) { - void *const p = num > 0 ? malloc(num) : NULL; + void *const p = malloc(num); #if CUSTOM_FN_PRINT_CALLS if (file == test_fn || file == NULL @@ -201,21 +203,13 @@ static void *my_malloc(const size_t num, return p; } - static void *my_realloc(void *const addr, const size_t num, const char *const file, const int line) { #if CUSTOM_FN_PRINT_CALLS const uintptr_t old_addr = (uintptr_t)addr; #endif - void *p = NULL; - - if (addr == NULL && num > 0) - p = malloc(num); - else if (num == 0) - free(addr); - else - p = realloc(addr, num); + void *const p = realloc(addr, num); #if CUSTOM_FN_PRINT_CALLS if (file == test_fn || file == NULL diff --git a/test/membio_test.c b/test/membio_test.c index 642dae4830..eafd4d24fa 100644 --- a/test/membio_test.c +++ b/test/membio_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -10,41 +10,6 @@ #include #include "testutil.h" -static int test_eof(void) -{ - BIO *bio = BIO_new(BIO_s_mem()); - char buf[1]; - int testresult = 0; - - if (!TEST_ptr(bio)) - goto err; - - /* legacy default behaviour */ - if (!TEST_int_eq(BIO_read(bio, buf, 1), -1) - || !TEST_true(BIO_eof(bio)) - || !TEST_true(BIO_should_retry(bio))) - goto err; - - /* manually set eof behaviour */ - BIO_set_mem_eof_return(bio, 0); - if (!TEST_int_eq(BIO_read(bio, buf, 1), 0) - || !TEST_true(BIO_eof(bio)) - || !TEST_false(BIO_should_retry(bio))) - goto err; - - /* manually set retry behaviour */ - BIO_set_mem_eof_return(bio, -1); - if (!TEST_int_eq(BIO_read(bio, buf, 1), -1) - || !TEST_false(BIO_eof(bio)) - || !TEST_true(BIO_should_retry(bio))) - goto err; - - testresult = 1; -err: - BIO_free(bio); - return testresult; -} - #ifndef OPENSSL_NO_DGRAM static int test_dgram(void) { @@ -153,7 +118,6 @@ int setup_tests(void) return 0; } - ADD_TEST(test_eof); #ifndef OPENSSL_NO_DGRAM ADD_TEST(test_dgram); #endif diff --git a/test/mfail/mfail.c b/test/mfail/mfail.c deleted file mode 100644 index ec391c8e85..0000000000 --- a/test/mfail/mfail.c +++ /dev/null @@ -1,396 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include "mfail.h" - -#include -#include -#include -#include - -#if defined(__has_feature) -#if __has_feature(address_sanitizer) -#define MFAIL_HAVE_ASAN 1 -#endif -#endif -#if defined(__SANITIZE_ADDRESS__) && !defined(MFAIL_HAVE_ASAN) -#define MFAIL_HAVE_ASAN 1 -#endif - -#ifdef MFAIL_HAVE_ASAN -extern void __sanitizer_print_stack_trace(void); -#elif defined(__GLIBC__) || defined(__APPLE__) -#include -#define MFAIL_HAVE_BACKTRACE -#define MFAIL_BT_MAX 128 -#endif - -static struct { - int installed; - int skip_all; - int skip_slow; - int single_point; - int start_point; - int env_count; - int count_only; - int count_only_env; - int sample_count; - int slow_threshold; - int print_bt; - int mode; - int phase; - int seq; - int next_point; - int iter_index; - int n; - int total; - int iterations; - int started; - int fail_after; - int alloc_count; - int triggered; - int counting; - int slow_skipped; - int no_check; -} mf; - -static int env_is_true(const char *name) -{ - const char *value = getenv(name); - return value != NULL && *value != '\0' && strcmp(value, "0") != 0; -} - -static int env_int(const char *name, int dflt) -{ - const char *value = getenv(name); - return (value != NULL && *value != '\0') ? atoi(value) : dflt; -} - -static void mfail_print_bt(void) -{ -#ifdef MFAIL_HAVE_ASAN - fprintf(stderr, "# MFAIL_BT (failure injection point)\n"); - __sanitizer_print_stack_trace(); -#elif defined(MFAIL_HAVE_BACKTRACE) - void *buf[MFAIL_BT_MAX]; - char **syms; - int n, i; - - n = backtrace(buf, MFAIL_BT_MAX); - syms = backtrace_symbols(buf, n); - if (syms == NULL) - return; - - fprintf(stderr, "# MFAIL_BT (failure injection point)\n"); - /* Skip frame 0 (this function) */ - for (i = 1; i < n; i++) - fprintf(stderr, "# %s\n", syms[i]); - - free(syms); -#endif -} - -static int should_fail(const char *file) -{ - int idx; - - if (!mf.counting) - return 0; - /* skip if checking errors and file is not set (debug and error parts) */ - if (!mf.no_check && file == NULL) - return 0; - - idx = mf.alloc_count++; - - if (mf.fail_after < 0 || mf.triggered) - return 0; - if (idx == mf.fail_after) { - mf.triggered = 1; - if (mf.print_bt) - mfail_print_bt(); - return 1; - } - return 0; -} - -static void *mf_malloc(size_t num, const char *file, int line) -{ - if (num == 0) - return NULL; - if (should_fail(file)) - return NULL; - return malloc(num); -} - -static void *mf_realloc(void *addr, size_t num, const char *file, int line) -{ - if (addr == NULL) - return mf_malloc(num, file, line); - if (num == 0) { - free(addr); - return NULL; - } - if (should_fail(file)) - return NULL; - return realloc(addr, num); -} - -static void mf_free(void *addr, const char *file, int line) -{ - free(addr); -} - -int mfail_install(int optional) -{ - if (mf.installed) - return 1; - if (env_is_true("OPENSSL_TEST_MFAIL_DISABLE")) - return 0; - - mf.skip_all = env_is_true("OPENSSL_TEST_MFAIL_SKIP_ALL"); - mf.skip_slow = env_is_true("OPENSSL_TEST_MFAIL_SKIP_SLOW"); - mf.single_point = env_int("OPENSSL_TEST_MFAIL_POINT", -1); - mf.start_point = env_int("OPENSSL_TEST_MFAIL_START", 0); - mf.env_count = env_int("OPENSSL_TEST_MFAIL_COUNT", 0); - mf.count_only_env = env_is_true("OPENSSL_TEST_MFAIL_COUNT_ONLY"); - mf.slow_threshold = env_int("OPENSSL_TEST_MFAIL_SLOW", 1000); - mf.print_bt = env_is_true("OPENSSL_TEST_MFAIL_BACKTRACE"); - - /* if optional and nothing configured, then no point installing hooks */ - if (optional && mf.env_count <= 0 && mf.single_point < 0 - && !mf.count_only_env) - return 0; - - if (!CRYPTO_set_mem_functions(mf_malloc, mf_realloc, mf_free)) - return -1; - - mf.installed = 1; - mf.fail_after = -1; - return 1; -} - -int mfail_is_installed(void) -{ - return mf.installed; -} - -int mfail_env_skip_all(void) -{ - return !mf.installed || mf.skip_all; -} - -int mfail_env_skip_slow(void) -{ - return !mf.installed || mf.skip_slow; -} - -/* The i-th of n points distributed over [start, total), rotated by seq */ -static int compute_point(int i, int total, int n, int seq, int start) -{ - int range = total - start; - int stride_int, stride_rem_x2, stride_rnd, offset, p; - - if (range <= 0 || n <= 0) - return start; - - stride_int = range / n; - stride_rem_x2 = (range - stride_int * n) * 2; - stride_rnd = stride_int + (stride_rem_x2 >= n ? 1 : 0); - offset = (stride_rnd > 0) ? (seq % stride_rnd) : 0; - - p = (int)(((long)i * range + n / 2) / n) + offset; - if (p >= range) - p = range - 1; - if (p < 0) - p = 0; - return start + p; -} - -void mfail_init(int seq, int flags) -{ - mfail_init_ex(seq, flags, 0); -} - -void mfail_init_ex(int seq, int flags, int count) -{ - mf.seq = seq; - mf.iter_index = 0; - mf.n = 0; - mf.total = 0; - mf.iterations = 0; - mf.started = 0; - mf.fail_after = -1; - mf.alloc_count = 0; - mf.triggered = 0; - mf.counting = 0; - mf.slow_skipped = 0; - mf.no_check = flags & MFAIL_FLAG_NO_CHECK; - mf.count_only = mf.count_only_env || (flags & MFAIL_FLAG_COUNT_ONLY) != 0; - /* env count overrides the requested per-test sample count */ - mf.sample_count = mf.env_count > 0 ? mf.env_count : count; - - if (mf.single_point >= 0) { - mf.mode = MFAIL_MODE_SINGLE; - } else if ((flags & MFAIL_FLAG_COUNT) && mf.sample_count > 0) { - mf.mode = MFAIL_MODE_SAMPLED; - } else { - mf.mode = MFAIL_MODE_EXHAUSTIVE; - } - mf.phase = MFAIL_PHASE_COUNTING; - mf.next_point = -1; -} - -int mfail_has_next(void) -{ - if (mf.started) { - mf.iterations++; - switch (mf.phase) { - case MFAIL_PHASE_COUNTING: - mf.total = mf.alloc_count; - if (mf.count_only) { - mf.phase = MFAIL_PHASE_DONE; - break; - } - /* sampled runs are bounded, so slow-skip only applies otherwise */ - if (mf.skip_slow && mf.mode != MFAIL_MODE_SAMPLED - && mf.total > mf.slow_threshold) { - mf.slow_skipped = 1; - mf.phase = MFAIL_PHASE_DONE; - break; - } - if (mf.mode == MFAIL_MODE_SINGLE) { - mf.phase = MFAIL_PHASE_INJECTING; - mf.next_point = mf.single_point; - } else if (mf.mode == MFAIL_MODE_EXHAUSTIVE) { - if (mf.total > mf.start_point) { - mf.phase = MFAIL_PHASE_INJECTING; - mf.next_point = mf.start_point; - } else { - mf.phase = MFAIL_PHASE_DONE; - } - } else { /* mf.mode is MFAIL_MODE_SAMPLED */ - mf.n = mf.sample_count; - if (mf.n > mf.total) - mf.n = mf.total; - if (mf.n > 0 && mf.total > mf.start_point) { - mf.phase = MFAIL_PHASE_INJECTING; - mf.iter_index = 0; - mf.next_point = compute_point(0, mf.total, mf.n, mf.seq, - mf.start_point); - } else { - mf.phase = MFAIL_PHASE_DONE; - } - } - break; - case MFAIL_PHASE_INJECTING: - if (mf.mode == MFAIL_MODE_SINGLE) { - mf.phase = MFAIL_PHASE_DONE; - } else if (mf.mode == MFAIL_MODE_EXHAUSTIVE) { - if (++mf.next_point >= mf.total) - mf.phase = MFAIL_PHASE_DONE; - } else { /* SAMPLED */ - if (++mf.iter_index >= mf.n) - mf.phase = MFAIL_PHASE_DONE; - else - mf.next_point = compute_point(mf.iter_index, mf.total, - mf.n, mf.seq, mf.start_point); - } - break; - case MFAIL_PHASE_DONE: - default: - break; - } - } else { - mf.started = 1; - } - - if (mf.phase == MFAIL_PHASE_DONE) - return 0; - - mf.alloc_count = 0; - mf.counting = 0; - mf.triggered = 0; - mf.fail_after = (mf.phase == MFAIL_PHASE_INJECTING) ? mf.next_point : -1; - return 1; -} - -void mfail_start(void) -{ - mf.alloc_count = 0; - mf.counting = 1; -} - -void mfail_end(void) -{ - mf.counting = 0; -} - -void mfail_arm_once(int point) -{ - mf.fail_after = point; - mf.alloc_count = 0; - mf.triggered = 0; -} - -void mfail_disarm(void) -{ - mf.fail_after = -1; - mf.alloc_count = 0; - mf.triggered = 0; -} - -int mfail_was_triggered(void) -{ - return mf.triggered; -} - -int mfail_was_slow_skipped(void) -{ - return mf.slow_skipped; -} - -int mfail_is_count_only(void) -{ - return mf.count_only; -} - -int mfail_get_count(void) -{ - return mf.alloc_count; -} - -int mfail_get_total(void) -{ - return mf.total; -} - -int mfail_get_phase(void) -{ - return mf.phase; -} - -int mfail_get_mode(void) -{ - return mf.mode; -} - -int mfail_iterations(void) -{ - return mf.iterations; -} - -int mfail_get_slow_threshold(void) -{ - return mf.slow_threshold; -} - -int mfail_get_point(void) -{ - return (mf.phase == MFAIL_PHASE_INJECTING) ? mf.next_point : -1; -} diff --git a/test/mfail/mfail.h b/test/mfail/mfail.h deleted file mode 100644 index c93be44fca..0000000000 --- a/test/mfail/mfail.h +++ /dev/null @@ -1,74 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#ifndef OSSL_TEST_MFAIL_H -#define OSSL_TEST_MFAIL_H - -/* Flags for mfail_init(). */ -#define MFAIL_FLAG_COUNT (1 << 0) -#define MFAIL_FLAG_NO_CHECK (1 << 1) -/* Force count-only run for this init */ -#define MFAIL_FLAG_COUNT_ONLY (1 << 2) - -/* Modes */ -#define MFAIL_MODE_EXHAUSTIVE 0 -#define MFAIL_MODE_SAMPLED 1 -#define MFAIL_MODE_SINGLE 2 - -/* Phases */ -#define MFAIL_PHASE_DONE 0 -#define MFAIL_PHASE_COUNTING 1 -#define MFAIL_PHASE_INJECTING 2 - -/* Install mem hooks */ -int mfail_install(int optional); -/* Check if hooks installed */ -int mfail_is_installed(void); -/* Initialize the mfail for test case runs */ -void mfail_init(int seq, int flags); -/* As mfail_init() but caps injection at |count| sampled points */ -void mfail_init_ex(int seq, int flags, int count); -/* Check for the failure loop if another fail execution should be done */ -int mfail_has_next(void); -/* Start the failure triggering block */ -void mfail_start(void); -/* End the failure triggering block */ -void mfail_end(void); -/* Check if the failure was triggered in the block */ -int mfail_was_triggered(void); -/* Check if the inject phase was skipped because it got over slow threshold */ -int mfail_was_slow_skipped(void); -/* Check if mfail counts allocations and not inject */ -int mfail_is_count_only(void); -/* If the counting was executed, get the total number of allocations */ -int mfail_get_count(void); -/* Get the total number of failure points */ -int mfail_get_total(void); -/* Get the number of iterations that run */ -int mfail_iterations(void); -/* Get the current failure point */ -int mfail_get_point(void); -/* Get execution phase */ -int mfail_get_phase(void); -/* Get execution mode */ -int mfail_get_mode(void); -/* Get the configured slow threshold */ -int mfail_get_slow_threshold(void); - -/* Low level arming at specific point (instead of start) */ -void mfail_arm_once(int point); -/* Low level disarming (similar to end) */ -void mfail_disarm(void); - -/* Check whether to skip all tests */ -int mfail_env_skip_all(void); -/* Check whether to skip only slow tests */ -int mfail_env_skip_slow(void); - -#endif /* OSSL_TEST_MFAIL_H */ diff --git a/test/ml_dsa_internal_test.c b/test/ml_dsa_internal_test.c deleted file mode 100644 index b992a2301b..0000000000 --- a/test/ml_dsa_internal_test.c +++ /dev/null @@ -1,114 +0,0 @@ -/* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* - * Internal ML-DSA test exercising the low-level sign/verify path directly. - * - * Primary purpose: constant-time validation. When the library is built with - * enable-ct-validation and the test is run under Valgrind, any control-flow - * branch or memory index that depends on secret key material (other than the - * explicitly declassified rejection decisions) will be reported as an error. - * - * Secondary purpose: a quick sanity check that sign→verify round-trips for - * all three parameter sets using a fully deterministic key and message. - */ - -#include -#include -#include "crypto/ml_dsa.h" -#include "testutil.h" - -/* Fixed 32-byte seed used for all three parameter-set tests. */ -static const uint8_t test_seed[ML_DSA_SEED_BYTES] = { - 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, - 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10, - 0x11, 0x12, 0x13, 0x14, 0x15, 0x16, 0x17, 0x18, - 0x19, 0x1a, 0x1b, 0x1c, 0x1d, 0x1e, 0x1f, 0x20 -}; - -/* A short, fixed test message. */ -static const uint8_t test_msg[] = "ML-DSA constant-time validation test"; - -/* - * Exercise keygen + sign + verify for one ML-DSA parameter set. - * - * The sign call uses rnd=NULL (deterministic mode) so the output is fully - * determined by the seed and message. Correctness against ACVP test vectors - * is verified separately in ml_dsa_test.c; here we only check that the - * round-trip succeeds, giving Valgrind something to instrument. - */ -static int test_sign_verify(int evp_type) -{ - ML_DSA_KEY *key = NULL; - uint8_t *sig = NULL; - size_t sig_len = 0; - const ML_DSA_PARAMS *params; - int ret = 0; - - if (!TEST_ptr(key = ossl_ml_dsa_key_new(NULL, NULL, evp_type))) - goto err; - if (!TEST_true(ossl_ml_dsa_key_fetch_digests(key, NULL))) - goto err; - if (!TEST_ptr(params = ossl_ml_dsa_key_params(key))) - goto err; - - /* Load the fixed seed and expand into a full key pair. */ - if (!TEST_true(ossl_ml_dsa_set_prekey(key, ML_DSA_KEY_PREFER_SEED, - 0, test_seed, sizeof(test_seed), - NULL, 0))) - goto err; - if (!TEST_true(ossl_ml_dsa_generate_key(key))) - goto err; - - sig_len = params->sig_len; - if (!TEST_ptr(sig = OPENSSL_malloc(sig_len))) - goto err; - - /* - * Sign deterministically (rnd=NULL). This exercises the rejection loop - * under Valgrind without relying on external randomness. - */ - if (!TEST_true(ossl_ml_dsa_sign(key, - 0 /* msg_is_mu */, - test_msg, sizeof(test_msg) - 1, - NULL, 0 /* no context */, - NULL, 0 /* deterministic */, - 1 /* encode */, - sig, &sig_len, params->sig_len))) - goto err; - if (!TEST_size_t_eq(sig_len, params->sig_len)) - goto err; - - /* Verify the signature we just produced. */ - if (!TEST_true(ossl_ml_dsa_verify(key, - 0 /* msg_is_mu */, - test_msg, sizeof(test_msg) - 1, - NULL, 0 /* no context */, - 1 /* encode */, - sig, sig_len))) - goto err; - - ret = 1; -err: - ossl_ml_dsa_key_free(key); - OPENSSL_free(sig); - return ret; -} - -static int test_ml_dsa_44(void) { return test_sign_verify(EVP_PKEY_ML_DSA_44); } -static int test_ml_dsa_65(void) { return test_sign_verify(EVP_PKEY_ML_DSA_65); } -static int test_ml_dsa_87(void) { return test_sign_verify(EVP_PKEY_ML_DSA_87); } - -int setup_tests(void) -{ - ADD_TEST(test_ml_dsa_44); - ADD_TEST(test_ml_dsa_65); - ADD_TEST(test_ml_dsa_87); - return 1; -} diff --git a/test/ml_dsa_test.c b/test/ml_dsa_test.c index ca1c1225e2..8c3be48e8d 100644 --- a/test/ml_dsa_test.c +++ b/test/ml_dsa_test.c @@ -8,13 +8,10 @@ */ #include -#include #include -#include #include "internal/nelem.h" #include "testutil.h" #include "ml_dsa.inc" -#include "crypto/evp.h" #include "crypto/ml_dsa.h" typedef enum OPTION_choice { @@ -59,7 +56,7 @@ static int ml_dsa_create_keypair(EVP_PKEY **pkey, const char *name, { int ret = 0, selection = 0; EVP_PKEY_CTX *ctx = NULL; - OSSL_PARAM params[4], *p = params; + OSSL_PARAM params[3], *p = params; if (priv != NULL) { *p++ = OSSL_PARAM_construct_octet_string(OSSL_PKEY_PARAM_PRIV_KEY, @@ -71,7 +68,6 @@ static int ml_dsa_create_keypair(EVP_PKEY **pkey, const char *name, (uint8_t *)pub, pub_len); selection |= OSSL_KEYMGMT_SELECT_PUBLIC_KEY; } - *p++ = OSSL_PARAM_construct_utf8_string(OSSL_PKEY_PARAM_PROPERTIES, "?fips=yes", 0); *p = OSSL_PARAM_construct_end(); if (!TEST_ptr(ctx = EVP_PKEY_CTX_new_from_name(lib_ctx, name, NULL)) @@ -647,108 +643,6 @@ err: return ret; } -/* - * Test that the keymgmt import dispatch refuses to import into a key whose - * public component is already set, i.e. the key is immutable once initialised. - * - * Four sub-cases are exercised: - * 1. public-key-only → re-import public key → must fail - * 2. public-key-only → import keypair → must fail - * 3. full keypair → re-import keypair → must fail - * 4. full keypair → import public key only → must fail - * - * All failures must raise PROV_R_KEY_IMMUTABLE_ONCE_SET. - */ -static int ml_dsa_key_immutable_test(void) -{ - int ret = 0; - EVP_KEYMGMT *keymgmt = NULL; - void *keydata = NULL; - const ML_DSA_KEYGEN_TEST_DATA *tst = &ml_dsa_keygen_testdata[0]; - OSSL_PARAM pub_params[2], keypair_params[3]; - - pub_params[0] = OSSL_PARAM_construct_octet_string( - OSSL_PKEY_PARAM_PUB_KEY, (void *)tst->pub, tst->pub_len); - pub_params[1] = OSSL_PARAM_construct_end(); - - keypair_params[0] = OSSL_PARAM_construct_octet_string( - OSSL_PKEY_PARAM_PRIV_KEY, (void *)tst->priv, tst->priv_len); - keypair_params[1] = OSSL_PARAM_construct_octet_string( - OSSL_PKEY_PARAM_PUB_KEY, (void *)tst->pub, tst->pub_len); - keypair_params[2] = OSSL_PARAM_construct_end(); - - if (!TEST_ptr(keymgmt = EVP_KEYMGMT_fetch(lib_ctx, tst->name, NULL))) - goto end; - - /* Sub-case 1 & 2: start from a public-key-only import */ - if (!TEST_ptr(keydata = evp_keymgmt_newdata(keymgmt, NULL))) - goto end; - - if (!TEST_true(evp_keymgmt_import(keymgmt, keydata, - OSSL_KEYMGMT_SELECT_PUBLIC_KEY, - pub_params))) - goto end; - - /* Re-import of the same public key must fail */ - if (!TEST_false(evp_keymgmt_import(keymgmt, keydata, - OSSL_KEYMGMT_SELECT_PUBLIC_KEY, - pub_params))) - goto end; - if (!TEST_int_eq(ERR_GET_REASON(ERR_peek_last_error()), - PROV_R_KEY_IMMUTABLE_ONCE_SET)) - goto end; - ERR_clear_error(); - - /* Import of a full keypair into a public-key-only key must also fail */ - if (!TEST_false(evp_keymgmt_import(keymgmt, keydata, - OSSL_KEYMGMT_SELECT_KEYPAIR, - keypair_params))) - goto end; - if (!TEST_int_eq(ERR_GET_REASON(ERR_peek_last_error()), - PROV_R_KEY_IMMUTABLE_ONCE_SET)) - goto end; - ERR_clear_error(); - - evp_keymgmt_freedata(keymgmt, keydata); - keydata = NULL; - - /* Sub-case 3 & 4: start from a full keypair import */ - if (!TEST_ptr(keydata = evp_keymgmt_newdata(keymgmt, NULL))) - goto end; - - if (!TEST_true(evp_keymgmt_import(keymgmt, keydata, - OSSL_KEYMGMT_SELECT_KEYPAIR, - keypair_params))) - goto end; - - /* Re-import of the same keypair must fail */ - if (!TEST_false(evp_keymgmt_import(keymgmt, keydata, - OSSL_KEYMGMT_SELECT_KEYPAIR, - keypair_params))) - goto end; - if (!TEST_int_eq(ERR_GET_REASON(ERR_peek_last_error()), - PROV_R_KEY_IMMUTABLE_ONCE_SET)) - goto end; - ERR_clear_error(); - - /* Import of a public-key-only into a full keypair must also fail */ - if (!TEST_false(evp_keymgmt_import(keymgmt, keydata, - OSSL_KEYMGMT_SELECT_PUBLIC_KEY, - pub_params))) - goto end; - if (!TEST_int_eq(ERR_GET_REASON(ERR_peek_last_error()), - PROV_R_KEY_IMMUTABLE_ONCE_SET)) - goto end; - ERR_clear_error(); - - ret = 1; -end: - if (keymgmt != NULL) - evp_keymgmt_freedata(keymgmt, keydata); - EVP_KEYMGMT_free(keymgmt); - return ret; -} - const OPTIONS *test_get_options(void) { static const OPTIONS options[] = { @@ -797,13 +691,6 @@ int setup_tests(void) ADD_TEST(from_data_bad_input_test); ADD_TEST(ml_dsa_digest_sign_verify_test); ADD_TEST(ml_dsa_priv_pub_bad_t0_test); - - /* - * Tested only in the default configuration, with a non-default provider - * configuration this test is expected to fail for some older providers. - */ - if (config_file == NULL) - ADD_TEST(ml_dsa_key_immutable_test); return 1; } diff --git a/test/ml_kem_evp_extra_test.c b/test/ml_kem_evp_extra_test.c index 2aa704427a..def63903e2 100644 --- a/test/ml_kem_evp_extra_test.c +++ b/test/ml_kem_evp_extra_test.c @@ -18,10 +18,8 @@ #include #include #include -#include #include #include -#include "crypto/evp.h" #include "testutil.h" static OSSL_LIB_CTX *testctx = NULL; @@ -403,244 +401,6 @@ static int test_non_derandomised_ml_kem(void) return ret == 0; } -static int test_ml_kem_from_data_propq(void) -{ - int ret = 0; - EVP_PKEY_CTX *ctx = NULL; - EVP_PKEY *pkey = NULL; - OSSL_PARAM params[3]; - - params[0] = OSSL_PARAM_construct_octet_string(OSSL_PKEY_PARAM_ML_KEM_SEED, gen_seed, sizeof(gen_seed)); - params[1] = OSSL_PARAM_construct_utf8_string(OSSL_PKEY_PARAM_PROPERTIES, "fips=no", 0); - params[2] = OSSL_PARAM_construct_end(); - - ret = TEST_ptr(ctx = EVP_PKEY_CTX_new_from_name(testctx, "ML-KEM-768", NULL)) - && TEST_int_eq(EVP_PKEY_fromdata_init(ctx), 1) - && TEST_int_eq(EVP_PKEY_fromdata(ctx, &pkey, OSSL_KEYMGMT_SELECT_KEYPAIR, params), 1); - EVP_PKEY_free(pkey); - EVP_PKEY_CTX_free(ctx); - return ret; -} - -#ifndef OPENSSL_NO_EC -static const char *mlx_kem_algs[] = { -#ifndef OPENSSL_NO_ECX - "X25519MLKEM768", -#endif - "SecP256r1MLKEM768", - "SecP384r1MLKEM1024", -}; -#endif - -/* - * Test that mlx_kem_dup() with partial selection (public-only) does not - * corrupt the original key. Before the fix, the default branch of the - * switch in mlx_kem_dup() would call mlx_kem_key_free() on a shallow copy - * without nulling mkey/xkey first, causing a double-free when the original - * key was later freed. - */ -#ifndef OPENSSL_NO_EC -static int test_mlx_kem_dup_partial_selection(int idx) -{ - const char *alg = mlx_kem_algs[idx]; - EVP_PKEY_CTX *genctx = NULL; - EVP_PKEY_CTX *encctx = NULL; - EVP_PKEY *keypair = NULL; - EVP_PKEY *dest = NULL; - size_t wrpkeylen = 0, genkeylen = 0; - int ret = 0; - - /* Generate an MLX KEM keypair */ - if (!TEST_ptr(genctx = EVP_PKEY_CTX_new_from_name(testctx, alg, NULL)) - || !TEST_int_eq(EVP_PKEY_keygen_init(genctx), 1) - || !TEST_int_eq(EVP_PKEY_keygen(genctx, &keypair), 1)) - goto err; - - /* - * Attempt a partial copy (public-key only). EVP_PKEY_PUBLIC_KEY includes - * OSSL_KEYMGMT_SELECT_PUBLIC_KEY (0x02) but not private, so - * selection & OSSL_KEYMGMT_SELECT_KEYPAIR == 0x02 which hits the default - * branch in mlx_kem_dup(). This should fail gracefully without corrupting - * the source key. - */ - if (!TEST_ptr(dest = EVP_PKEY_new())) - goto err; - /* Expected to fail — partial duplication is not supported for MLX KEM */ - evp_keymgmt_util_copy(dest, keypair, EVP_PKEY_PUBLIC_KEY); - ERR_clear_error(); - - /* - * Verify the original keypair is still intact by performing an - * encapsulate operation. If the partial copy corrupted the key - * (double-freed mkey/xkey), this would crash or trigger ASan. - */ - if (!TEST_ptr(encctx = EVP_PKEY_CTX_new_from_pkey(testctx, keypair, NULL)) - || !TEST_int_gt(EVP_PKEY_encapsulate_init(encctx, NULL), 0) - || !TEST_int_gt(EVP_PKEY_encapsulate(encctx, NULL, &wrpkeylen, - NULL, &genkeylen), - 0) - || !TEST_size_t_gt(wrpkeylen, 0) - || !TEST_size_t_gt(genkeylen, 0)) - goto err; - - ret = 1; -err: - EVP_PKEY_CTX_free(encctx); - EVP_PKEY_free(dest); - EVP_PKEY_free(keypair); - EVP_PKEY_CTX_free(genctx); - return ret; -} -#endif /* OPENSSL_NO_EC */ - -/* - * Test that ML-KEM keys are immutable once key material is set. - * - * Part 1 — keymgmt import dispatch (ml_kem_import): - * Sub-case A: public-key-only first import succeeds; re-import of the - * same public key and any keypair import must fail with - * PROV_R_KEY_IMMUTABLE_ONCE_SET. - * Sub-case B: full keypair first import succeeds; re-import of the - * keypair and public-key-only import must fail with - * PROV_R_KEY_IMMUTABLE_ONCE_SET. - * - * Part 2 — EVP_PKEY_set1_encoded_public_key (ml_kem_set_params): - * The second call on a key that already has a public component must - * also fail with PROV_R_KEY_IMMUTABLE_ONCE_SET.. - */ -static int test_ml_kem_key_immutable(void) -{ - int ret = 0; - EVP_PKEY *akey = NULL, *bkey = NULL; - EVP_KEYMGMT *keymgmt = NULL; - void *keydata = NULL; - uint8_t *rawpub = NULL, *rawprv = NULL; - size_t publen = 0, prvlen = 0; - OSSL_PARAM pub_params[2], keypair_params[3]; - - /* Generate a key pair and extract the raw public and private key bytes. */ - if (!TEST_ptr(akey = EVP_PKEY_Q_keygen(testctx, NULL, "ML-KEM-768"))) - goto end; - if (!TEST_int_eq(EVP_PKEY_get_raw_public_key(akey, NULL, &publen), 1) - || !TEST_ptr(rawpub = OPENSSL_malloc(publen)) - || !TEST_int_eq(EVP_PKEY_get_raw_public_key(akey, rawpub, &publen), 1)) - goto end; - if (!TEST_int_eq(EVP_PKEY_get_raw_private_key(akey, NULL, &prvlen), 1) - || !TEST_ptr(rawprv = OPENSSL_malloc(prvlen)) - || !TEST_int_eq(EVP_PKEY_get_raw_private_key(akey, rawprv, &prvlen), 1)) - goto end; - - pub_params[0] = OSSL_PARAM_construct_octet_string( - OSSL_PKEY_PARAM_PUB_KEY, rawpub, publen); - pub_params[1] = OSSL_PARAM_construct_end(); - - keypair_params[0] = OSSL_PARAM_construct_octet_string( - OSSL_PKEY_PARAM_PRIV_KEY, rawprv, prvlen); - keypair_params[1] = OSSL_PARAM_construct_octet_string( - OSSL_PKEY_PARAM_PUB_KEY, rawpub, publen); - keypair_params[2] = OSSL_PARAM_construct_end(); - - if (!TEST_ptr(keymgmt = EVP_KEYMGMT_fetch(testctx, "ML-KEM-768", NULL))) - goto end; - - /* --- Part 1A: public-key-only import then re-import --- */ - if (!TEST_ptr(keydata = evp_keymgmt_newdata(keymgmt, NULL))) - goto end; - - if (!TEST_true(evp_keymgmt_import(keymgmt, keydata, - OSSL_KEYMGMT_SELECT_PUBLIC_KEY, - pub_params))) - goto end; - - /* Re-import of the same public key must fail */ - if (!TEST_false(evp_keymgmt_import(keymgmt, keydata, - OSSL_KEYMGMT_SELECT_PUBLIC_KEY, - pub_params))) - goto end; - if (!TEST_int_eq(ERR_GET_REASON(ERR_peek_last_error()), - PROV_R_KEY_IMMUTABLE_ONCE_SET)) - goto end; - ERR_clear_error(); - - /* Import of a full keypair into a public-key-only key must also fail */ - if (!TEST_false(evp_keymgmt_import(keymgmt, keydata, - OSSL_KEYMGMT_SELECT_KEYPAIR, - keypair_params))) - goto end; - if (!TEST_int_eq(ERR_GET_REASON(ERR_peek_last_error()), - PROV_R_KEY_IMMUTABLE_ONCE_SET)) - goto end; - ERR_clear_error(); - - evp_keymgmt_freedata(keymgmt, keydata); - keydata = NULL; - - /* --- Part 1B: full keypair import then re-import --- */ - if (!TEST_ptr(keydata = evp_keymgmt_newdata(keymgmt, NULL))) - goto end; - - if (!TEST_true(evp_keymgmt_import(keymgmt, keydata, - OSSL_KEYMGMT_SELECT_KEYPAIR, - keypair_params))) - goto end; - - /* Re-import of the same keypair must fail */ - if (!TEST_false(evp_keymgmt_import(keymgmt, keydata, - OSSL_KEYMGMT_SELECT_KEYPAIR, - keypair_params))) - goto end; - if (!TEST_int_eq(ERR_GET_REASON(ERR_peek_last_error()), - PROV_R_KEY_IMMUTABLE_ONCE_SET)) - goto end; - ERR_clear_error(); - - /* Import of a public-key-only into a full keypair must also fail */ - if (!TEST_false(evp_keymgmt_import(keymgmt, keydata, - OSSL_KEYMGMT_SELECT_PUBLIC_KEY, - pub_params))) - goto end; - if (!TEST_int_eq(ERR_GET_REASON(ERR_peek_last_error()), - PROV_R_KEY_IMMUTABLE_ONCE_SET)) - goto end; - ERR_clear_error(); - - evp_keymgmt_freedata(keymgmt, keydata); - keydata = NULL; - - /* --- Part 2: EVP_PKEY_set1_encoded_public_key immutability --- */ - - /* - * Create an empty typed key (algorithm set, no key material) by - * copying parameters from the generated key. - */ - if (!TEST_ptr(bkey = EVP_PKEY_new()) - || !TEST_int_gt(EVP_PKEY_copy_parameters(bkey, akey), 0)) - goto end; - - /* First call must succeed: the key is still embryonic */ - if (!TEST_int_eq(EVP_PKEY_set1_encoded_public_key(bkey, rawpub, publen), 1)) - goto end; - - /* Second call must fail: the key now has a public component */ - if (!TEST_int_eq(EVP_PKEY_set1_encoded_public_key(bkey, rawpub, publen), 0)) - goto end; - if (!TEST_int_eq(ERR_GET_REASON(ERR_peek_last_error()), - PROV_R_KEY_IMMUTABLE_ONCE_SET)) - goto end; - ERR_clear_error(); - - ret = 1; -end: - if (keymgmt != NULL) - evp_keymgmt_freedata(keymgmt, keydata); - EVP_KEYMGMT_free(keymgmt); - EVP_PKEY_free(akey); - EVP_PKEY_free(bkey); - OPENSSL_free(rawpub); - OPENSSL_free(rawprv); - return ret; -} - int setup_tests(void) { int test_rand = 0; @@ -668,10 +428,5 @@ int setup_tests(void) } ADD_TEST(test_ml_kem); - ADD_TEST(test_ml_kem_from_data_propq); - ADD_TEST(test_ml_kem_key_immutable); -#ifndef OPENSSL_NO_EC - ADD_ALL_TESTS(test_mlx_kem_dup_partial_selection, OSSL_NELEM(mlx_kem_algs)); -#endif return 1; } diff --git a/test/ml_kem_internal_test.c b/test/ml_kem_internal_test.c index 14487dab94..23eeb2aa47 100644 --- a/test/ml_kem_internal_test.c +++ b/test/ml_kem_internal_test.c @@ -242,81 +242,11 @@ err: return ret == 0; } -static int decap_mfail_test(void) -{ - EVP_RAND_CTX *privctx, *pubctx; - OSSL_PARAM params[3]; - uint8_t shared_secret[ML_KEM_SHARED_SECRET_BYTES]; - uint8_t decap_secret[ML_KEM_SHARED_SECRET_BYTES]; - uint8_t *encoded_public_key = NULL; - uint8_t *ciphertext = NULL; - ML_KEM_KEY *private_key = NULL; - ML_KEM_KEY *public_key = NULL; - unsigned int strength = 256; - const ML_KEM_VINFO *v; - int rc, ret = -1; - - if (!TEST_ptr(privctx = RAND_get0_private(NULL)) - || !TEST_ptr(pubctx = RAND_get0_public(NULL))) - return 0; - - params[0] = OSSL_PARAM_construct_octet_string(OSSL_RAND_PARAM_TEST_ENTROPY, - ml_kem_private_entropy, sizeof(ml_kem_private_entropy)); - params[1] = OSSL_PARAM_construct_uint(OSSL_RAND_PARAM_STRENGTH, &strength); - params[2] = OSSL_PARAM_construct_end(); - if (!TEST_true(EVP_RAND_CTX_set_params(privctx, params))) - goto err; - - public_key = ossl_ml_kem_key_new(NULL, NULL, EVP_PKEY_ML_KEM_768); - private_key = ossl_ml_kem_key_new(NULL, NULL, EVP_PKEY_ML_KEM_768); - if (private_key == NULL || public_key == NULL - || (v = ossl_ml_kem_key_vinfo(public_key)) == NULL) - goto err; - - encoded_public_key = OPENSSL_malloc(v->pubkey_bytes); - ciphertext = OPENSSL_malloc(v->ctext_bytes); - if (encoded_public_key == NULL || ciphertext == NULL) - goto err; - - if (!ossl_ml_kem_genkey(encoded_public_key, v->pubkey_bytes, private_key) - || !ossl_ml_kem_parse_public_key(encoded_public_key, v->pubkey_bytes, - public_key)) - goto err; - - params[0] = OSSL_PARAM_construct_octet_string(OSSL_RAND_PARAM_TEST_ENTROPY, - ml_kem_public_entropy, sizeof(ml_kem_public_entropy)); - if (!TEST_true(EVP_RAND_CTX_set_params(pubctx, params))) - goto err; - - if (!ossl_ml_kem_encap_rand(ciphertext, v->ctext_bytes, - shared_secret, sizeof(shared_secret), public_key)) - goto err; - - MFAIL_start(); - rc = ossl_ml_kem_decap(decap_secret, sizeof(decap_secret), - ciphertext, v->ctext_bytes, private_key); - MFAIL_end(); - - if (rc == 1 - && !TEST_mem_eq(decap_secret, sizeof(decap_secret), - shared_secret, sizeof(shared_secret))) - goto err; - - ret = rc; -err: - ossl_ml_kem_key_free(private_key); - ossl_ml_kem_key_free(public_key); - OPENSSL_free(encoded_public_key); - OPENSSL_free(ciphertext); - return ret; -} - int setup_tests(void) { if (!TEST_true(RAND_set_DRBG_type(NULL, "TEST-RAND", "fips=no", NULL, NULL))) return 0; ADD_TEST(sanity_test); - ADD_MFAIL_TEST(decap_mfail_test); return 1; } diff --git a/test/modes_internal_test.c b/test/modes_internal_test.c index c3b8b6cd9f..7e1192265c 100644 --- a/test/modes_internal_test.c +++ b/test/modes_internal_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -36,12 +36,11 @@ typedef struct { ***/ /* cts128 test vectors from RFC 3962 */ -static const unsigned char cts128_test_key[16] = { 'c', 'h', 'i', 'c', 'k', 'e', 'n', ' ', 't', 'e', 'r', 'i', 'y', 'a', 'k', 'i' }; -static const unsigned char cts128_test_input[64] = { 'I', ' ', 'w', 'o', 'u', 'l', 'd', ' ', 'l', 'i', 'k', 'e', ' ', 't', 'h', 'e', - ' ', 'G', 'e', 'n', 'e', 'r', 'a', 'l', ' ', 'G', 'a', 'u', '\'', 's', ' ', 'C', 'h', - 'i', 'c', 'k', 'e', 'n', ',', ' ', 'p', 'l', 'e', 'a', 's', 'e', ',', ' ', 'a', - 'n', 'd', ' ', 'w', 'o', 'n', 't', 'o', 'n', ' ', 's', 'o', 'u', 'p', '.' }; - +static const unsigned char cts128_test_key[16] = "chicken teriyaki"; +static const unsigned char cts128_test_input[64] = "I would like the" + " General Gau's C" + "hicken, please, " + "and wonton soup."; static const unsigned char cts128_test_iv[] = { 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 }; @@ -197,7 +196,7 @@ static int execute_cts128(const CTS128_FIXTURE *fixture, int num) unsigned char cleartext[64], ciphertext[64], vector[64]; size_t tail, size; - TEST_info("%s_vector_%zu", fixture->case_name, len); + TEST_info("%s_vector_%lu", fixture->case_name, (unsigned long)len); tail = fixture->last_blocks_correction(orig_vector, vector, len); @@ -273,8 +272,8 @@ static int test_aes_cts128_nist(int idx) */ /* Test Case 1 */ -static const uint8_t K1[16], P1[] = { 0 }, A1[] = { 0 }, IV1[12], C1[] = { 0 }; -static const uint8_t T1[] = { +static const u8 K1[16], P1[] = { 0 }, A1[] = { 0 }, IV1[12], C1[] = { 0 }; +static const u8 T1[] = { 0x58, 0xe2, 0xfc, 0xce, 0xfa, 0x7e, 0x30, 0x61, 0x36, 0x7f, 0x1d, 0x57, 0xa4, 0xe7, 0x45, 0x5a }; @@ -283,25 +282,25 @@ static const uint8_t T1[] = { #define K2 K1 #define A2 A1 #define IV2 IV1 -static const uint8_t P2[16]; -static const uint8_t C2[] = { +static const u8 P2[16]; +static const u8 C2[] = { 0x03, 0x88, 0xda, 0xce, 0x60, 0xb6, 0xa3, 0x92, 0xf3, 0x28, 0xc2, 0xb9, 0x71, 0xb2, 0xfe, 0x78 }; -static const uint8_t T2[] = { +static const u8 T2[] = { 0xab, 0x6e, 0x47, 0xd4, 0x2c, 0xec, 0x13, 0xbd, 0xf5, 0x3a, 0x67, 0xb2, 0x12, 0x57, 0xbd, 0xdf }; /* Test Case 3 */ #define A3 A2 -static const uint8_t K3[] = { +static const u8 K3[] = { 0xfe, 0xff, 0xe9, 0x92, 0x86, 0x65, 0x73, 0x1c, 0x6d, 0x6a, 0x8f, 0x94, 0x67, 0x30, 0x83, 0x08 }; -static const uint8_t P3[] = { +static const u8 P3[] = { 0xd9, 0x31, 0x32, 0x25, 0xf8, 0x84, 0x06, 0xe5, 0xa5, 0x59, 0x09, 0xc5, 0xaf, 0xf5, 0x26, 0x9a, 0x86, 0xa7, 0xa9, 0x53, 0x15, 0x34, 0xf7, 0xda, @@ -312,12 +311,12 @@ static const uint8_t P3[] = { 0xba, 0x63, 0x7b, 0x39, 0x1a, 0xaf, 0xd2, 0x55 }; -static const uint8_t IV3[] = { +static const u8 IV3[] = { 0xca, 0xfe, 0xba, 0xbe, 0xfa, 0xce, 0xdb, 0xad, 0xde, 0xca, 0xf8, 0x88 }; -static const uint8_t C3[] = { +static const u8 C3[] = { 0x42, 0x83, 0x1e, 0xc2, 0x21, 0x77, 0x74, 0x24, 0x4b, 0x72, 0x21, 0xb7, 0x84, 0xd0, 0xd4, 0x9c, 0xe3, 0xaa, 0x21, 0x2f, 0x2c, 0x02, 0xa4, 0xe0, @@ -328,7 +327,7 @@ static const uint8_t C3[] = { 0x3d, 0x58, 0xe0, 0x91, 0x47, 0x3f, 0x59, 0x85 }; -static const uint8_t T3[] = { +static const u8 T3[] = { 0x4d, 0x5c, 0x2a, 0xf3, 0x27, 0xcd, 0x64, 0xa6, 0x2c, 0xf3, 0x5a, 0xbd, 0x2b, 0xa6, 0xfa, 0xb4 }; @@ -336,7 +335,7 @@ static const uint8_t T3[] = { /* Test Case 4 */ #define K4 K3 #define IV4 IV3 -static const uint8_t P4[] = { +static const u8 P4[] = { 0xd9, 0x31, 0x32, 0x25, 0xf8, 0x84, 0x06, 0xe5, 0xa5, 0x59, 0x09, 0xc5, 0xaf, 0xf5, 0x26, 0x9a, 0x86, 0xa7, 0xa9, 0x53, 0x15, 0x34, 0xf7, 0xda, @@ -347,13 +346,13 @@ static const uint8_t P4[] = { 0xba, 0x63, 0x7b, 0x39 }; -static const uint8_t A4[] = { +static const u8 A4[] = { 0xfe, 0xed, 0xfa, 0xce, 0xde, 0xad, 0xbe, 0xef, 0xfe, 0xed, 0xfa, 0xce, 0xde, 0xad, 0xbe, 0xef, 0xab, 0xad, 0xda, 0xd2 }; -static const uint8_t C4[] = { +static const u8 C4[] = { 0x42, 0x83, 0x1e, 0xc2, 0x21, 0x77, 0x74, 0x24, 0x4b, 0x72, 0x21, 0xb7, 0x84, 0xd0, 0xd4, 0x9c, 0xe3, 0xaa, 0x21, 0x2f, 0x2c, 0x02, 0xa4, 0xe0, @@ -364,7 +363,7 @@ static const uint8_t C4[] = { 0x3d, 0x58, 0xe0, 0x91 }; -static const uint8_t T4[] = { +static const u8 T4[] = { 0x5b, 0xc9, 0x4f, 0xbc, 0x32, 0x21, 0xa5, 0xdb, 0x94, 0xfa, 0xe9, 0x5a, 0xe7, 0x12, 0x1a, 0x47 }; @@ -373,11 +372,11 @@ static const uint8_t T4[] = { #define K5 K4 #define P5 P4 #define A5 A4 -static const uint8_t IV5[] = { +static const u8 IV5[] = { 0xca, 0xfe, 0xba, 0xbe, 0xfa, 0xce, 0xdb, 0xad }; -static const uint8_t C5[] = { +static const u8 C5[] = { 0x61, 0x35, 0x3b, 0x4c, 0x28, 0x06, 0x93, 0x4a, 0x77, 0x7f, 0xf5, 0x1f, 0xa2, 0x2a, 0x47, 0x55, 0x69, 0x9b, 0x2a, 0x71, 0x4f, 0xcd, 0xc6, 0xf8, @@ -388,7 +387,7 @@ static const uint8_t C5[] = { 0xc2, 0x3f, 0x45, 0x98 }; -static const uint8_t T5[] = { +static const u8 T5[] = { 0x36, 0x12, 0xd2, 0xe7, 0x9e, 0x3b, 0x07, 0x85, 0x56, 0x1b, 0xe1, 0x4a, 0xac, 0xa2, 0xfc, 0xcb }; @@ -397,7 +396,7 @@ static const uint8_t T5[] = { #define K6 K5 #define P6 P5 #define A6 A5 -static const uint8_t IV6[] = { +static const u8 IV6[] = { 0x93, 0x13, 0x22, 0x5d, 0xf8, 0x84, 0x06, 0xe5, 0x55, 0x90, 0x9c, 0x5a, 0xff, 0x52, 0x69, 0xaa, 0x6a, 0x7a, 0x95, 0x38, 0x53, 0x4f, 0x7d, 0xa1, @@ -408,7 +407,7 @@ static const uint8_t IV6[] = { 0xa6, 0x37, 0xb3, 0x9b }; -static const uint8_t C6[] = { +static const u8 C6[] = { 0x8c, 0xe2, 0x49, 0x98, 0x62, 0x56, 0x15, 0xb6, 0x03, 0xa0, 0x33, 0xac, 0xa1, 0x3f, 0xb8, 0x94, 0xbe, 0x91, 0x12, 0xa5, 0xc3, 0xa2, 0x11, 0xa8, @@ -419,14 +418,14 @@ static const uint8_t C6[] = { 0x4c, 0x34, 0xae, 0xe5 }; -static const uint8_t T6[] = { +static const u8 T6[] = { 0x61, 0x9c, 0xc5, 0xae, 0xff, 0xfe, 0x0b, 0xfa, 0x46, 0x2a, 0xf4, 0x3c, 0x16, 0x99, 0xd0, 0x50 }; /* Test Case 7 */ -static const uint8_t K7[24], P7[] = { 0 }, A7[] = { 0 }, IV7[12], C7[] = { 0 }; -static const uint8_t T7[] = { +static const u8 K7[24], P7[] = { 0 }, A7[] = { 0 }, IV7[12], C7[] = { 0 }; +static const u8 T7[] = { 0xcd, 0x33, 0xb2, 0x8a, 0xc7, 0x73, 0xf7, 0x4b, 0xa0, 0x0e, 0xd1, 0xf3, 0x12, 0x57, 0x24, 0x35 }; @@ -435,26 +434,26 @@ static const uint8_t T7[] = { #define K8 K7 #define IV8 IV7 #define A8 A7 -static const uint8_t P8[16]; -static const uint8_t C8[] = { +static const u8 P8[16]; +static const u8 C8[] = { 0x98, 0xe7, 0x24, 0x7c, 0x07, 0xf0, 0xfe, 0x41, 0x1c, 0x26, 0x7e, 0x43, 0x84, 0xb0, 0xf6, 0x00 }; -static const uint8_t T8[] = { +static const u8 T8[] = { 0x2f, 0xf5, 0x8d, 0x80, 0x03, 0x39, 0x27, 0xab, 0x8e, 0xf4, 0xd4, 0x58, 0x75, 0x14, 0xf0, 0xfb }; /* Test Case 9 */ #define A9 A8 -static const uint8_t K9[] = { +static const u8 K9[] = { 0xfe, 0xff, 0xe9, 0x92, 0x86, 0x65, 0x73, 0x1c, 0x6d, 0x6a, 0x8f, 0x94, 0x67, 0x30, 0x83, 0x08, 0xfe, 0xff, 0xe9, 0x92, 0x86, 0x65, 0x73, 0x1c }; -static const uint8_t P9[] = { +static const u8 P9[] = { 0xd9, 0x31, 0x32, 0x25, 0xf8, 0x84, 0x06, 0xe5, 0xa5, 0x59, 0x09, 0xc5, 0xaf, 0xf5, 0x26, 0x9a, 0x86, 0xa7, 0xa9, 0x53, 0x15, 0x34, 0xf7, 0xda, @@ -465,12 +464,12 @@ static const uint8_t P9[] = { 0xba, 0x63, 0x7b, 0x39, 0x1a, 0xaf, 0xd2, 0x55 }; -static const uint8_t IV9[] = { +static const u8 IV9[] = { 0xca, 0xfe, 0xba, 0xbe, 0xfa, 0xce, 0xdb, 0xad, 0xde, 0xca, 0xf8, 0x88 }; -static const uint8_t C9[] = { +static const u8 C9[] = { 0x39, 0x80, 0xca, 0x0b, 0x3c, 0x00, 0xe8, 0x41, 0xeb, 0x06, 0xfa, 0xc4, 0x87, 0x2a, 0x27, 0x57, 0x85, 0x9e, 0x1c, 0xea, 0xa6, 0xef, 0xd9, 0x84, @@ -481,7 +480,7 @@ static const uint8_t C9[] = { 0xcc, 0xda, 0x27, 0x10, 0xac, 0xad, 0xe2, 0x56 }; -static const uint8_t T9[] = { +static const u8 T9[] = { 0x99, 0x24, 0xa7, 0xc8, 0x58, 0x73, 0x36, 0xbf, 0xb1, 0x18, 0x02, 0x4d, 0xb8, 0x67, 0x4a, 0x14 }; @@ -489,7 +488,7 @@ static const uint8_t T9[] = { /* Test Case 10 */ #define K10 K9 #define IV10 IV9 -static const uint8_t P10[] = { +static const u8 P10[] = { 0xd9, 0x31, 0x32, 0x25, 0xf8, 0x84, 0x06, 0xe5, 0xa5, 0x59, 0x09, 0xc5, 0xaf, 0xf5, 0x26, 0x9a, 0x86, 0xa7, 0xa9, 0x53, 0x15, 0x34, 0xf7, 0xda, @@ -500,13 +499,13 @@ static const uint8_t P10[] = { 0xba, 0x63, 0x7b, 0x39 }; -static const uint8_t A10[] = { +static const u8 A10[] = { 0xfe, 0xed, 0xfa, 0xce, 0xde, 0xad, 0xbe, 0xef, 0xfe, 0xed, 0xfa, 0xce, 0xde, 0xad, 0xbe, 0xef, 0xab, 0xad, 0xda, 0xd2 }; -static const uint8_t C10[] = { +static const u8 C10[] = { 0x39, 0x80, 0xca, 0x0b, 0x3c, 0x00, 0xe8, 0x41, 0xeb, 0x06, 0xfa, 0xc4, 0x87, 0x2a, 0x27, 0x57, 0x85, 0x9e, 0x1c, 0xea, 0xa6, 0xef, 0xd9, 0x84, @@ -517,7 +516,7 @@ static const uint8_t C10[] = { 0xcc, 0xda, 0x27, 0x10 }; -static const uint8_t T10[] = { +static const u8 T10[] = { 0x25, 0x19, 0x49, 0x8e, 0x80, 0xf1, 0x47, 0x8f, 0x37, 0xba, 0x55, 0xbd, 0x6d, 0x27, 0x61, 0x8c }; @@ -526,9 +525,9 @@ static const uint8_t T10[] = { #define K11 K10 #define P11 P10 #define A11 A10 -static const uint8_t IV11[] = { 0xca, 0xfe, 0xba, 0xbe, 0xfa, 0xce, 0xdb, 0xad }; +static const u8 IV11[] = { 0xca, 0xfe, 0xba, 0xbe, 0xfa, 0xce, 0xdb, 0xad }; -static const uint8_t C11[] = { +static const u8 C11[] = { 0x0f, 0x10, 0xf5, 0x99, 0xae, 0x14, 0xa1, 0x54, 0xed, 0x24, 0xb3, 0x6e, 0x25, 0x32, 0x4d, 0xb8, 0xc5, 0x66, 0x63, 0x2e, 0xf2, 0xbb, 0xb3, 0x4f, @@ -539,7 +538,7 @@ static const uint8_t C11[] = { 0xa0, 0xf0, 0x62, 0xf7 }; -static const uint8_t T11[] = { +static const u8 T11[] = { 0x65, 0xdc, 0xc5, 0x7f, 0xcf, 0x62, 0x3a, 0x24, 0x09, 0x4f, 0xcc, 0xa4, 0x0d, 0x35, 0x33, 0xf8 }; @@ -548,7 +547,7 @@ static const uint8_t T11[] = { #define K12 K11 #define P12 P11 #define A12 A11 -static const uint8_t IV12[] = { +static const u8 IV12[] = { 0x93, 0x13, 0x22, 0x5d, 0xf8, 0x84, 0x06, 0xe5, 0x55, 0x90, 0x9c, 0x5a, 0xff, 0x52, 0x69, 0xaa, 0x6a, 0x7a, 0x95, 0x38, 0x53, 0x4f, 0x7d, 0xa1, @@ -559,7 +558,7 @@ static const uint8_t IV12[] = { 0xa6, 0x37, 0xb3, 0x9b }; -static const uint8_t C12[] = { +static const u8 C12[] = { 0xd2, 0x7e, 0x88, 0x68, 0x1c, 0xe3, 0x24, 0x3c, 0x48, 0x30, 0x16, 0x5a, 0x8f, 0xdc, 0xf9, 0xff, 0x1d, 0xe9, 0xa1, 0xd8, 0xe6, 0xb4, 0x47, 0xef, @@ -570,14 +569,14 @@ static const uint8_t C12[] = { 0xe9, 0xb7, 0x37, 0x3b }; -static const uint8_t T12[] = { +static const u8 T12[] = { 0xdc, 0xf5, 0x66, 0xff, 0x29, 0x1c, 0x25, 0xbb, 0xb8, 0x56, 0x8f, 0xc3, 0xd3, 0x76, 0xa6, 0xd9 }; /* Test Case 13 */ -static const uint8_t K13[32], P13[] = { 0 }, A13[] = { 0 }, IV13[12], C13[] = { 0 }; -static const uint8_t T13[] = { +static const u8 K13[32], P13[] = { 0 }, A13[] = { 0 }, IV13[12], C13[] = { 0 }; +static const u8 T13[] = { 0x53, 0x0f, 0x8a, 0xfb, 0xc7, 0x45, 0x36, 0xb9, 0xa9, 0x63, 0xb4, 0xf1, 0xc4, 0xcb, 0x73, 0x8b }; @@ -585,27 +584,27 @@ static const uint8_t T13[] = { /* Test Case 14 */ #define K14 K13 #define A14 A13 -static const uint8_t P14[16], IV14[12]; -static const uint8_t C14[] = { +static const u8 P14[16], IV14[12]; +static const u8 C14[] = { 0xce, 0xa7, 0x40, 0x3d, 0x4d, 0x60, 0x6b, 0x6e, 0x07, 0x4e, 0xc5, 0xd3, 0xba, 0xf3, 0x9d, 0x18 }; -static const uint8_t T14[] = { +static const u8 T14[] = { 0xd0, 0xd1, 0xc8, 0xa7, 0x99, 0x99, 0x6b, 0xf0, 0x26, 0x5b, 0x98, 0xb5, 0xd4, 0x8a, 0xb9, 0x19 }; /* Test Case 15 */ #define A15 A14 -static const uint8_t K15[] = { +static const u8 K15[] = { 0xfe, 0xff, 0xe9, 0x92, 0x86, 0x65, 0x73, 0x1c, 0x6d, 0x6a, 0x8f, 0x94, 0x67, 0x30, 0x83, 0x08, 0xfe, 0xff, 0xe9, 0x92, 0x86, 0x65, 0x73, 0x1c, 0x6d, 0x6a, 0x8f, 0x94, 0x67, 0x30, 0x83, 0x08 }; -static const uint8_t P15[] = { +static const u8 P15[] = { 0xd9, 0x31, 0x32, 0x25, 0xf8, 0x84, 0x06, 0xe5, 0xa5, 0x59, 0x09, 0xc5, 0xaf, 0xf5, 0x26, 0x9a, 0x86, 0xa7, 0xa9, 0x53, 0x15, 0x34, 0xf7, 0xda, @@ -616,12 +615,12 @@ static const uint8_t P15[] = { 0xba, 0x63, 0x7b, 0x39, 0x1a, 0xaf, 0xd2, 0x55 }; -static const uint8_t IV15[] = { +static const u8 IV15[] = { 0xca, 0xfe, 0xba, 0xbe, 0xfa, 0xce, 0xdb, 0xad, 0xde, 0xca, 0xf8, 0x88 }; -static const uint8_t C15[] = { +static const u8 C15[] = { 0x52, 0x2d, 0xc1, 0xf0, 0x99, 0x56, 0x7d, 0x07, 0xf4, 0x7f, 0x37, 0xa3, 0x2a, 0x84, 0x42, 0x7d, 0x64, 0x3a, 0x8c, 0xdc, 0xbf, 0xe5, 0xc0, 0xc9, @@ -632,7 +631,7 @@ static const uint8_t C15[] = { 0xbc, 0xc9, 0xf6, 0x62, 0x89, 0x80, 0x15, 0xad }; -static const uint8_t T15[] = { +static const u8 T15[] = { 0xb0, 0x94, 0xda, 0xc5, 0xd9, 0x34, 0x71, 0xbd, 0xec, 0x1a, 0x50, 0x22, 0x70, 0xe3, 0xcc, 0x6c }; @@ -640,7 +639,7 @@ static const uint8_t T15[] = { /* Test Case 16 */ #define K16 K15 #define IV16 IV15 -static const uint8_t P16[] = { +static const u8 P16[] = { 0xd9, 0x31, 0x32, 0x25, 0xf8, 0x84, 0x06, 0xe5, 0xa5, 0x59, 0x09, 0xc5, 0xaf, 0xf5, 0x26, 0x9a, 0x86, 0xa7, 0xa9, 0x53, 0x15, 0x34, 0xf7, 0xda, @@ -651,13 +650,13 @@ static const uint8_t P16[] = { 0xba, 0x63, 0x7b, 0x39 }; -static const uint8_t A16[] = { +static const u8 A16[] = { 0xfe, 0xed, 0xfa, 0xce, 0xde, 0xad, 0xbe, 0xef, 0xfe, 0xed, 0xfa, 0xce, 0xde, 0xad, 0xbe, 0xef, 0xab, 0xad, 0xda, 0xd2 }; -static const uint8_t C16[] = { +static const u8 C16[] = { 0x52, 0x2d, 0xc1, 0xf0, 0x99, 0x56, 0x7d, 0x07, 0xf4, 0x7f, 0x37, 0xa3, 0x2a, 0x84, 0x42, 0x7d, 0x64, 0x3a, 0x8c, 0xdc, 0xbf, 0xe5, 0xc0, 0xc9, @@ -668,7 +667,7 @@ static const uint8_t C16[] = { 0xbc, 0xc9, 0xf6, 0x62 }; -static const uint8_t T16[] = { +static const u8 T16[] = { 0x76, 0xfc, 0x6e, 0xce, 0x0f, 0x4e, 0x17, 0x68, 0xcd, 0xdf, 0x88, 0x53, 0xbb, 0x2d, 0x55, 0x1b }; @@ -677,9 +676,9 @@ static const uint8_t T16[] = { #define K17 K16 #define P17 P16 #define A17 A16 -static const uint8_t IV17[] = { 0xca, 0xfe, 0xba, 0xbe, 0xfa, 0xce, 0xdb, 0xad }; +static const u8 IV17[] = { 0xca, 0xfe, 0xba, 0xbe, 0xfa, 0xce, 0xdb, 0xad }; -static const uint8_t C17[] = { +static const u8 C17[] = { 0xc3, 0x76, 0x2d, 0xf1, 0xca, 0x78, 0x7d, 0x32, 0xae, 0x47, 0xc1, 0x3b, 0xf1, 0x98, 0x44, 0xcb, 0xaf, 0x1a, 0xe1, 0x4d, 0x0b, 0x97, 0x6a, 0xfa, @@ -690,7 +689,7 @@ static const uint8_t C17[] = { 0xf4, 0x7c, 0x9b, 0x1f }; -static const uint8_t T17[] = { +static const u8 T17[] = { 0x3a, 0x33, 0x7d, 0xbf, 0x46, 0xa7, 0x92, 0xc4, 0x5e, 0x45, 0x49, 0x13, 0xfe, 0x2e, 0xa8, 0xf2 }; @@ -699,7 +698,7 @@ static const uint8_t T17[] = { #define K18 K17 #define P18 P17 #define A18 A17 -static const uint8_t IV18[] = { +static const u8 IV18[] = { 0x93, 0x13, 0x22, 0x5d, 0xf8, 0x84, 0x06, 0xe5, 0x55, 0x90, 0x9c, 0x5a, 0xff, 0x52, 0x69, 0xaa, 0x6a, 0x7a, 0x95, 0x38, 0x53, 0x4f, 0x7d, 0xa1, @@ -710,7 +709,7 @@ static const uint8_t IV18[] = { 0xa6, 0x37, 0xb3, 0x9b }; -static const uint8_t C18[] = { +static const u8 C18[] = { 0x5a, 0x8d, 0xef, 0x2f, 0x0c, 0x9e, 0x53, 0xf1, 0xf7, 0x5d, 0x78, 0x53, 0x65, 0x9e, 0x2a, 0x20, 0xee, 0xb2, 0xb2, 0x2a, 0xaf, 0xde, 0x64, 0x19, @@ -721,7 +720,7 @@ static const uint8_t C18[] = { 0x44, 0xae, 0x7e, 0x3f }; -static const uint8_t T18[] = { +static const u8 T18[] = { 0xa4, 0x4a, 0x82, 0x66, 0xee, 0x1c, 0x8e, 0xb0, 0xc8, 0xb5, 0xd4, 0xcf, 0x5a, 0xe9, 0xf1, 0x9a }; @@ -731,7 +730,7 @@ static const uint8_t T18[] = { #define P19 P1 #define IV19 IV1 #define C19 C1 -static const uint8_t A19[] = { +static const u8 A19[] = { 0xd9, 0x31, 0x32, 0x25, 0xf8, 0x84, 0x06, 0xe5, 0xa5, 0x59, 0x09, 0xc5, 0xaf, 0xf5, 0x26, 0x9a, 0x86, 0xa7, 0xa9, 0x53, 0x15, 0x34, 0xf7, 0xda, @@ -750,7 +749,7 @@ static const uint8_t A19[] = { 0xbc, 0xc9, 0xf6, 0x62, 0x89, 0x80, 0x15, 0xad }; -static const uint8_t T19[] = { +static const u8 T19[] = { 0x5f, 0xea, 0x79, 0x3a, 0x2d, 0x6f, 0x97, 0x4d, 0x37, 0xe6, 0x8e, 0x0c, 0xb8, 0xff, 0x94, 0x92 }; @@ -759,10 +758,10 @@ static const uint8_t T19[] = { #define K20 K1 #define A20 A1 /* this results in 0xff in counter LSB */ -static const uint8_t IV20[64] = { 0xff, 0xff, 0xff, 0xff }; +static const u8 IV20[64] = { 0xff, 0xff, 0xff, 0xff }; -static const uint8_t P20[288]; -static const uint8_t C20[] = { +static const u8 P20[288]; +static const u8 C20[] = { 0x56, 0xb3, 0x37, 0x3c, 0xa9, 0xef, 0x6e, 0x4a, 0x2b, 0x64, 0xfe, 0x1e, 0x9a, 0x17, 0xb6, 0x14, 0x25, 0xf1, 0x0d, 0x47, 0xa7, 0x5a, 0x5f, 0xce, @@ -801,7 +800,7 @@ static const uint8_t C20[] = { 0x70, 0x8a, 0x70, 0xee, 0x7d, 0x75, 0x16, 0x5c }; -static const uint8_t T20[] = { +static const u8 T20[] = { 0x8b, 0x30, 0x7f, 0x6b, 0x33, 0x28, 0x6d, 0x0a, 0xb0, 0x26, 0xa9, 0xed, 0x3f, 0xe1, 0xe8, 0x5f }; diff --git a/test/namemap_internal_test.c b/test/namemap_internal_test.c index ec5d23d714..c8163f84a3 100644 --- a/test/namemap_internal_test.c +++ b/test/namemap_internal_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -170,27 +170,6 @@ static int test_digest_is_a(void) return rv; } -/* - * Test memory failures for ossl_namemap_add_name. - */ -static int test_namemap_add_name_mfail(void) -{ - OSSL_NAMEMAP *nm = NULL; - int ret = 0; - - nm = ossl_namemap_new(NULL); - if (!TEST_ptr(nm)) - goto err; - - MFAIL_start(); - ret = ossl_namemap_add_name(nm, 0, "mfail_test_name"); - MFAIL_end(); - -err: - ossl_namemap_free(nm); - return ret; -} - int setup_tests(void) { ADD_TEST(test_namemap_empty); @@ -200,6 +179,5 @@ int setup_tests(void) ADD_TEST(test_cipherbyname); ADD_TEST(test_digest_is_a); ADD_TEST(test_cipher_is_a); - ADD_MFAIL_TEST(test_namemap_add_name_mfail); return 1; } diff --git a/test/ocspapitest.c b/test/ocspapitest.c index c4baca4a7d..ce8f172494 100644 --- a/test/ocspapitest.c +++ b/test/ocspapitest.c @@ -84,7 +84,7 @@ static OCSP_BASICRESP *make_dummy_resp(void) || !TEST_true(X509_NAME_add_entry_by_NID(name, NID_commonName, MBSTRING_ASC, namestr, -1, -1, 1)) - || !TEST_true(ASN1_BIT_STRING_set1(key, keybytes, sizeof(keybytes), 0)) + || !TEST_true(ASN1_BIT_STRING_set(key, keybytes, sizeof(keybytes))) || !TEST_true(ASN1_INTEGER_set_uint64(serial, (uint64_t)1))) goto err; cid = OCSP_cert_id_new(EVP_sha256(), name, key, serial); diff --git a/test/ocsptest.c b/test/ocsptest.c deleted file mode 100644 index 96dc07423b..0000000000 --- a/test/ocsptest.c +++ /dev/null @@ -1,408 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include -#include -#include -#include -#include -#include -#ifndef OPENSSL_NO_OCSP -#include -#endif - -#include "testutil.h" - -#ifndef OPENSSL_NO_OCSP - -/* - * Fixtures for the OCSP stapled-response verification path - * (check_cert_ocsp_resp() in x509_vfy.c), reached from X509_verify_cert() - * when X509_V_FLAG_OCSP_RESP_CHECK is set and responses are attached with - * X509_STORE_CTX_set_ocsp_resp(). - * - * Root CA (self-signed trust anchor) - * \-- leaf (signed by the Root CA) - * - * The flat chain makes the root both the trust anchor and the authorized OCSP - * responder for the leaf, and having the root key lets each test build its own - * signed responses at run time. The certificates have a long validity because - * OCSP_check_validity() compares against the wall clock and cannot be pinned - * via X509_VERIFY_PARAM_set_time(). - * - * The arrays below are generated by the test-tools ocsptest command. - */ - -static const char *kOcspTestRoot[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIID+DCCAuCgAwIBAgIBATANBgkqhkiG9w0BAQsFADCBmjELMAkGA1UEBhMCVVMx\n", - "EzARBgNVBAgMCkNhbGlmb3JuaWExFjAUBgNVBAcMDVNhbiBGcmFuY2lzY28xFTAT\n", - "BgNVBAoMDEV4YW1wbGUgQ29ycDEeMBwGA1UECwwVQ2VydGlmaWNhdGUgQXV0aG9y\n", - "aXR5MScwJQYDVQQDDB5FeGFtcGxlIENvcnAgT0NTUCBUZXN0IFJvb3QgQ0EwIBcN\n", - "MjYwMTAxMDAwMDAwWhgPMjEyNjAxMDEwMDAwMDBaMIGaMQswCQYDVQQGEwJVUzET\n", - "MBEGA1UECAwKQ2FsaWZvcm5pYTEWMBQGA1UEBwwNU2FuIEZyYW5jaXNjbzEVMBMG\n", - "A1UECgwMRXhhbXBsZSBDb3JwMR4wHAYDVQQLDBVDZXJ0aWZpY2F0ZSBBdXRob3Jp\n", - "dHkxJzAlBgNVBAMMHkV4YW1wbGUgQ29ycCBPQ1NQIFRlc3QgUm9vdCBDQTCCASIw\n", - "DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKuZRsVUiwQoVlwfXY0nVpvMQiJN\n", - "Su5YfrxzKJ9sMfPI2rEg9d8kW2qsfnCB0isj+SK+CkcfVu5aXcUVUnp08VuKpsI9\n", - "idkeC7bhXkQgBR1p1mBwChc+UUD6qEindJPhFxYur+7gCmpamSHYr8iYmjVe78l8\n", - "vRHVuw8KMsiGegvPsuxIYWdY4mgKSCu3o6DeK4XehXU4Ll5j0fGX5eJgbaI6g8qE\n", - "j71J6G8Y4Ur/WqzTp/GZueTY0wzU8k45HS5uWarGYB2PH8DfM2SRQBw5hYd2xIvS\n", - "jgFYzCXeIZFnHVCMeB//VaUyYGIaw+Dreh+Wb5zBPh9FyJkrOXYyMeFZUScCAwEA\n", - "AaNFMEMwEgYDVR0TAQH/BAgwBgEB/wIBADAOBgNVHQ8BAf8EBAMCAYYwHQYDVR0O\n", - "BBYEFGSeLzT7Ur6wrLpFYVDHmNi/TQp5MA0GCSqGSIb3DQEBCwUAA4IBAQAMMukk\n", - "I0VRfxY1vZngu3LdnBk5If6TbQ6lmWatT4q3BrAID3L9zG/qev6DlyruvnVqoNdU\n", - "WcWXnzFSDInOKM64wU2oxdosMPWuAKKLHgDdCicikJtF+N0qJgOcyD+Gv9t0kwDB\n", - "O094nZUgrkCafJiy5y7KtZvqOjcvfEK+oD7fXX/VURv8NMOxpuassPHnHGvHqwKu\n", - "7jBZMjkOoZH4hJSo5EzZxRZHz6ay7Q8e+6C6PG8CIYXpIqukjVNq9jBb2yog67mW\n", - "lHlfnEENCyQDSmnEXAVNpJS67jmcItoD1utnDINVzu87DY9WiLZB06Y1xSp1ie7s\n", - "FIfS7bZ1cxVkt5wS\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -static const char *kOcspTestRootKey[] = { - "-----BEGIN RSA PRIVATE KEY-----\n", - "MIIEowIBAAKCAQEAq5lGxVSLBChWXB9djSdWm8xCIk1K7lh+vHMon2wx88jasSD1\n", - "3yRbaqx+cIHSKyP5Ir4KRx9W7lpdxRVSenTxW4qmwj2J2R4LtuFeRCAFHWnWYHAK\n", - "Fz5RQPqoSKd0k+EXFi6v7uAKalqZIdivyJiaNV7vyXy9EdW7DwoyyIZ6C8+y7Ehh\n", - "Z1jiaApIK7ejoN4rhd6FdTguXmPR8Zfl4mBtojqDyoSPvUnobxjhSv9arNOn8Zm5\n", - "5NjTDNTyTjkdLm5ZqsZgHY8fwN8zZJFAHDmFh3bEi9KOAVjMJd4hkWcdUIx4H/9V\n", - "pTJgYhrD4Ot6H5ZvnME+H0XImSs5djIx4VlRJwIDAQABAoIBAAj+6w/d47/JtuVI\n", - "xlMSXzRMW/cyYsg7SWxAWT5/oeAW2n1zWJBkdopmv+YkAsw81uBfDWjhwraSHtz9\n", - "xioh8U6MO+ZuQB4VY3soi2mPiCpyPvPP9nzLc9+v2ZydcrtsjxTxnkrWjJU7afsK\n", - "l1nbw3x4HU1McG5RQbzYcFsaJFHJcVdxIYkDfEgnBok1ALaQuRUGfUVYZDVk6Ztg\n", - "fMUh5nfNSHWu6y2i8YCphprIfu/zwadicaYLYljYqgP9J1MOPwuMcoCoWgotBUCZ\n", - "+29qIPn1mK3ReBmYdE8IIEiSLHYJjJ7EVu8IUfSPotBGGC5PjC11HcCXx0xB9AfB\n", - "I8VcDikCgYEA089WizVCWZMxWnCPLDG036vsug3/rrPr/O3W5VXTdpr00CBRzund\n", - "7QnaxUyxw37SOAQUtzcKhC0CF3c7Dbryb8d51koROVlWC8rngoDMxiZkbZZe0kL1\n", - "jHkOHEOoi83uY0tFoRhYtrcOYObNT9JDifdIDYCnxbLW4UQLo/9mFmUCgYEAz2ZH\n", - "hxoxXJ9y3qmIcc2vZTRPdaB4r+qQi5krUgtYg1uKImrvDnnl/4xCnCG9G1s1M/wE\n", - "cvuFG5FWGz6TtS0TsCGUXVWZ9s67JT53l02RIVTog/VRHbKsOnj+d9oXglGcxALT\n", - "qG02lKocNHzrPUXEw/EIMETKR6WvATZCzhM9mpsCgYB9RoKfb27A4Cgun6husS+T\n", - "o3IuUR1KzSvkux+BIRQjcF8fwh3gzb3u9wcn7satJBNeAjvmaW2U47H7AxAwfMPr\n", - "jQXo0oIBc29LJkVrkJaNFCQOFQQcRHJLFUZdPT8xASngHKMgNvAxkW+1rIz+ixRb\n", - "Q6CgK9oPOkmRjtd7thFBaQKBgQCMbt0QBhRWe0D0tCbHqFaTWJBVPYt60oF9hQFo\n", - "VHZiu6EVHQMx8ihimT6hKdc6ps+nm4YHtXez6v07BWxOyW8DXDlx2XyfOexOk7W2\n", - "pbcXsr6eW4XJbipgjX0A+pPgkhJsRt26tfi3QVhH0i4XFx7c7mB1Dp9JVE7jqzIh\n", - "B7Y28QKBgCg93v7zP5GFmOa6zCZreIIfi1dy50otxfqYewcXy4Egt90cE67vY55u\n", - "3B44ySrLkKDuzX2Inrwp5Vao8b9pDQ/AisRzt617eO1H5JtRF3lzZJukYC6j4urU\n", - "24kB2IhZCB6/3pwGiS21ma9E6OF9tO5YaGGYo02ZqkoflN+XgoeZ\n", - "-----END RSA PRIVATE KEY-----\n", - NULL -}; - -static const char *kOcspTestLeaf[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIIEOzCCAyOgAwIBAgICEAAwDQYJKoZIhvcNAQELBQAwgZoxCzAJBgNVBAYTAlVT\n", - "MRMwEQYDVQQIDApDYWxpZm9ybmlhMRYwFAYDVQQHDA1TYW4gRnJhbmNpc2NvMRUw\n", - "EwYDVQQKDAxFeGFtcGxlIENvcnAxHjAcBgNVBAsMFUNlcnRpZmljYXRlIEF1dGhv\n", - "cml0eTEnMCUGA1UEAwweRXhhbXBsZSBDb3JwIE9DU1AgVGVzdCBSb290IENBMCAX\n", - "DTI2MDEwMTAwMDAwMFoYDzIxMjYwMTAxMDAwMDAwWjCBiDELMAkGA1UEBhMCVVMx\n", - "EzARBgNVBAgMCkNhbGlmb3JuaWExFjAUBgNVBAcMDVNhbiBGcmFuY2lzY28xFTAT\n", - "BgNVBAoMDEV4YW1wbGUgQ29ycDEVMBMGA1UECwwMV2ViIFNlcnZpY2VzMR4wHAYD\n", - "VQQDDBVvY3NwLWxlYWYuZXhhbXBsZS5jb20wggEiMA0GCSqGSIb3DQEBAQUAA4IB\n", - "DwAwggEKAoIBAQCoQbsBGnLjATBzU8eWYMeyzu6vy4scpVDdhGnTWMaSIrqoXXge\n", - "JXrMHavT13cv2wNTExA6BNqFZA6YLBXYpDJ5oXyOlY1SYjbapX4M0kry4tBZdGWu\n", - "vnh04Q07SI8JvjtScB3lAIIhGr1WrQNLfEz+O80j4Pp8kLe1fWi0joB1CG4RWiuH\n", - "/2Ls1rSEMTr6dABtQ+zwxRHcFlEAoR9ZEDzfN1hIQEByWJd7TMnv738usyp52wMi\n", - "Gh/sruYHkpsO2tVoLCwm1OMSR1BLdGO1tJWSYN2+Tj2JVleQWcwwCgzDX4OlIdPF\n", - "/CM/6aQA6BkDeMW//tO4Ec4X+530zPiFKcZLAgMBAAGjgZgwgZUwDAYDVR0TAQH/\n", - "BAIwADAOBgNVHQ8BAf8EBAMCBaAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwHQYDVR0O\n", - "BBYEFBEZYONIpHIGBtlfPSlUTcDccGMiMB8GA1UdIwQYMBaAFGSeLzT7Ur6wrLpF\n", - "YVDHmNi/TQp5MCAGA1UdEQQZMBeCFW9jc3AtbGVhZi5leGFtcGxlLmNvbTANBgkq\n", - "hkiG9w0BAQsFAAOCAQEAaFYoQjmWdBBiD/hfSgV34Jf+PVKkecuu60VKDasPLNyV\n", - "ZwZcW8dXF9NOYcebGIEx4rjQTC3xiHUknqfOzc2jmPdU/xBAyRiltQnUh3OFH1qn\n", - "bX0YNUgfluLW+YSwNkriFLuzESBVadGhlX94mQwoqYyQJ+6/Ht2j4P4ZiIDRWfgc\n", - "z9pN8YoCiXh/I/IxVIWunk7Dla+Gr6BDJ762iQMMzPQ5D3cRAe9BDRgGiN0lPeIa\n", - "LMtqDeZZ+dR0KZAr3yZcfyci8SNXwCBbjsoVjmuUj6dlN12pRKxxtBSa23KT6/Dy\n", - "ijXZ+PtyIJz8FVBxO0RoECLimwbUPHfNjAWjuJkugA==\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -/* Load the fixed PKI. Any of the out params may be NULL to skip it. */ -static int load_pki(X509 **root, EVP_PKEY **root_key, X509 **leaf) -{ - if (root != NULL && !TEST_ptr(*root = X509_from_strings(kOcspTestRoot))) - return 0; - if (root_key != NULL - && !TEST_ptr(*root_key = PKEY_from_strings(kOcspTestRootKey))) - return 0; - if (leaf != NULL && !TEST_ptr(*leaf = X509_from_strings(kOcspTestLeaf))) - return 0; - return 1; -} - -/* - * Build a signed OCSP response for |cert| (issued by |issuer|). |resp_status| - * is the outer response status, |cert_status| the single-response certificate - * status. thisUpdate and nextUpdate are the current time offset by - * |this_off_sec| and |next_off_sec| seconds, so callers can also produce - * expired or not-yet-valid responses. The response is signed by - * |signer|/|signer_key|. Returns a response the caller must free, or NULL. - */ -static OCSP_RESPONSE *make_ocsp_response(X509 *cert, X509 *issuer, - int resp_status, int cert_status, int this_off_sec, int next_off_sec, - X509 *signer, EVP_PKEY *signer_key) -{ - OCSP_RESPONSE *resp = NULL; - OCSP_BASICRESP *bs = NULL; - OCSP_CERTID *cid = NULL; - ASN1_TIME *thisupd = NULL, *nextupd = NULL, *revtime = NULL; - - if (cert_status == V_OCSP_CERTSTATUS_REVOKED - && !TEST_ptr(revtime = X509_gmtime_adj(NULL, 0))) - goto end; - - if (!TEST_ptr(bs = OCSP_BASICRESP_new()) - || !TEST_ptr(thisupd = X509_time_adj_ex(NULL, 0, this_off_sec, NULL)) - || !TEST_ptr(nextupd = X509_time_adj_ex(NULL, 0, next_off_sec, NULL)) - || !TEST_ptr(cid = OCSP_cert_to_id(EVP_sha256(), cert, issuer)) - || !TEST_ptr(OCSP_basic_add1_status(bs, cid, cert_status, 0, revtime, - thisupd, nextupd)) - || !TEST_true(OCSP_basic_sign(bs, signer, signer_key, EVP_sha256(), - NULL, OCSP_NOCERTS))) - goto end; - - resp = OCSP_response_create(resp_status, bs); - -end: - ASN1_TIME_free(revtime); - ASN1_TIME_free(thisupd); - ASN1_TIME_free(nextupd); - OCSP_CERTID_free(cid); - OCSP_BASICRESP_free(bs); - return resp; -} - -/* Wrap |resp| into a stack, taking ownership on success. */ -static STACK_OF(OCSP_RESPONSE) *make_ocsp_resp_stack(OCSP_RESPONSE *resp) -{ - STACK_OF(OCSP_RESPONSE) *sk = sk_OCSP_RESPONSE_new_null(); - - if (!TEST_ptr(sk)) - return NULL; - if (!TEST_true(sk_OCSP_RESPONSE_push(sk, resp))) { - sk_OCSP_RESPONSE_free(sk); - return NULL; - } - return sk; -} - -/* - * Verify |leaf| against |root| with the stapled |resps| and |flags|, taking - * ownership of |resps|. Returns X509_V_OK or an X509_V_ERR_xxx code. The - * X509_verify_cert() call is wrapped for malloc-failure injection. - */ -static int verify_ocsp(X509 *leaf, X509 *root, STACK_OF(OCSP_RESPONSE) *resps, - unsigned long flags) -{ - X509_STORE *store = X509_STORE_new(); - X509_STORE_CTX *ctx = X509_STORE_CTX_new(); - X509_VERIFY_PARAM *param = X509_VERIFY_PARAM_new(); - int status = X509_V_ERR_UNSPECIFIED; - - if (!TEST_ptr(store) || !TEST_ptr(ctx) || !TEST_ptr(param)) - goto end; - - if (!TEST_true(X509_STORE_add_cert(store, root)) - || !TEST_true(X509_STORE_CTX_init(ctx, store, leaf, NULL))) - goto end; - - X509_STORE_CTX_set_ocsp_resp(ctx, resps); - - X509_VERIFY_PARAM_set_depth(param, 16); - if (flags != 0) - X509_VERIFY_PARAM_set_flags(param, flags); - X509_STORE_CTX_set0_param(ctx, param); - param = NULL; - - ERR_clear_error(); - MFAIL_start(); - status = X509_verify_cert(ctx) == 1 ? X509_V_OK - : X509_STORE_CTX_get_error(ctx); - MFAIL_end(); - -end: - X509_VERIFY_PARAM_free(param); - X509_STORE_CTX_free(ctx); - X509_STORE_free(store); - sk_OCSP_RESPONSE_pop_free(resps, OCSP_RESPONSE_free); - return status; -} - -/* - * Build a single response for the leaf and verify it, expecting |expected|. - * Every failure inside check_cert_ocsp_resp() surfaces as - * X509_V_ERR_OCSP_VERIFY_FAILED at the X509_verify_cert() level. - */ -static int run_ocsp_verify(int resp_status, int cert_status, int this_off_sec, - int next_off_sec, int expected) -{ - X509 *root = NULL, *leaf = NULL; - EVP_PKEY *root_key = NULL; - OCSP_RESPONSE *resp = NULL; - STACK_OF(OCSP_RESPONSE) *resps = NULL; - int testresult = 0; - - if (!load_pki(&root, &root_key, &leaf)) - goto end; - - if (!TEST_ptr(resp = make_ocsp_response(leaf, root, resp_status, cert_status, - this_off_sec, next_off_sec, root, root_key)) - || !TEST_ptr(resps = make_ocsp_resp_stack(resp))) - goto end; - resp = NULL; /* owned by resps */ - - testresult = TEST_int_eq(verify_ocsp(leaf, root, resps, - X509_V_FLAG_OCSP_RESP_CHECK), - expected); - resps = NULL; /* freed by verify_ocsp */ - -end: - sk_OCSP_RESPONSE_pop_free(resps, OCSP_RESPONSE_free); - OCSP_RESPONSE_free(resp); - EVP_PKEY_free(root_key); - X509_free(leaf); - X509_free(root); - return testresult; -} - -/* - * A good response that expired a moment ago is still accepted, because stapled - * responses are honoured for up to five minutes past nextUpdate. - */ -static int test_ocsp_resp_good(void) -{ - return run_ocsp_verify(OCSP_RESPONSE_STATUS_SUCCESSFUL, - V_OCSP_CERTSTATUS_GOOD, -10 * 60, -2 * 60, X509_V_OK); -} - -/* An outer response status other than successful is rejected. */ -static int test_ocsp_resp_not_successful(void) -{ - return run_ocsp_verify(OCSP_RESPONSE_STATUS_TRYLATER, - V_OCSP_CERTSTATUS_GOOD, 0, 24 * 60 * 60, X509_V_ERR_OCSP_VERIFY_FAILED); -} - -/* A response more than five minutes past nextUpdate is rejected as expired. */ -static int test_ocsp_resp_expired(void) -{ - return run_ocsp_verify(OCSP_RESPONSE_STATUS_SUCCESSFUL, - V_OCSP_CERTSTATUS_GOOD, -20 * 60, -10 * 60, X509_V_ERR_OCSP_VERIFY_FAILED); -} - -/* No response for the leaf's depth: sk_OCSP_RESPONSE_num() <= error_depth. */ -static int test_ocsp_resp_none(void) -{ - X509 *root = NULL, *leaf = NULL; - STACK_OF(OCSP_RESPONSE) *resps = NULL; - int testresult = 0; - - if (!load_pki(&root, NULL, &leaf) - || !TEST_ptr(resps = sk_OCSP_RESPONSE_new_null())) - goto end; - - testresult = TEST_int_eq(verify_ocsp(leaf, root, resps, - X509_V_FLAG_OCSP_RESP_CHECK), - X509_V_ERR_OCSP_VERIFY_FAILED); - resps = NULL; /* freed by verify_ocsp */ - -end: - sk_OCSP_RESPONSE_pop_free(resps, OCSP_RESPONSE_free); - X509_free(leaf); - X509_free(root); - return testresult; -} - -/* - * A well-formed response carrying a single response for a different certificate: - * no CertID matches the leaf, so no status is found for it. - */ -static int test_ocsp_resp_wrong_cert(void) -{ - X509 *root = NULL, *leaf = NULL; - EVP_PKEY *root_key = NULL; - OCSP_RESPONSE *resp = NULL; - STACK_OF(OCSP_RESPONSE) *resps = NULL; - int testresult = 0; - - if (!load_pki(&root, &root_key, &leaf)) - goto end; - - /* the response is about the root, not the leaf being verified */ - if (!TEST_ptr(resp = make_ocsp_response(root, root, - OCSP_RESPONSE_STATUS_SUCCESSFUL, V_OCSP_CERTSTATUS_GOOD, 0, - 24 * 60 * 60, root, root_key)) - || !TEST_ptr(resps = make_ocsp_resp_stack(resp))) - goto end; - resp = NULL; /* owned by resps */ - - testresult = TEST_int_eq(verify_ocsp(leaf, root, resps, - X509_V_FLAG_OCSP_RESP_CHECK), - X509_V_ERR_OCSP_VERIFY_FAILED); - resps = NULL; /* freed by verify_ocsp */ - -end: - sk_OCSP_RESPONSE_pop_free(resps, OCSP_RESPONSE_free); - OCSP_RESPONSE_free(resp); - EVP_PKEY_free(root_key); - X509_free(leaf); - X509_free(root); - return testresult; -} - -/* Exercise the success path under mfail. */ -static int test_ocsp_resp_mfail(void) -{ - X509 *root = NULL, *leaf = NULL; - EVP_PKEY *root_key = NULL; - OCSP_RESPONSE *resp = NULL; - STACK_OF(OCSP_RESPONSE) *resps = NULL; - int testresult = 0; - - if (!load_pki(&root, &root_key, &leaf)) - goto end; - - if (!TEST_ptr(resp = make_ocsp_response(leaf, root, - OCSP_RESPONSE_STATUS_SUCCESSFUL, V_OCSP_CERTSTATUS_GOOD, 0, - 24 * 60 * 60, root, root_key)) - || !TEST_ptr(resps = make_ocsp_resp_stack(resp))) - goto end; - resp = NULL; /* owned by resps */ - - testresult = verify_ocsp(leaf, root, resps, X509_V_FLAG_OCSP_RESP_CHECK) - == X509_V_OK; - resps = NULL; /* freed by verify_ocsp */ - -end: - sk_OCSP_RESPONSE_pop_free(resps, OCSP_RESPONSE_free); - OCSP_RESPONSE_free(resp); - EVP_PKEY_free(root_key); - X509_free(leaf); - X509_free(root); - return testresult; -} - -#endif /* OPENSSL_NO_OCSP */ - -int setup_tests(void) -{ -#ifndef OPENSSL_NO_OCSP - ADD_TEST(test_ocsp_resp_good); - ADD_TEST(test_ocsp_resp_not_successful); - ADD_TEST(test_ocsp_resp_expired); - ADD_TEST(test_ocsp_resp_none); - ADD_TEST(test_ocsp_resp_wrong_cert); - ADD_MFAIL_NO_CHECK_TEST(test_ocsp_resp_mfail); -#endif - return 1; -} diff --git a/test/ossl_store_test.c b/test/ossl_store_test.c index 104ae3ad61..f251313d1a 100644 --- a/test/ossl_store_test.c +++ b/test/ossl_store_test.c @@ -249,12 +249,6 @@ static int test_store_attach_unregistered_scheme(void) return ret; } -static int test_store_delete_null_uri(void) -{ - /* Passing NULL uri must return 0, not crash */ - return TEST_int_eq(OSSL_STORE_delete(NULL, NULL, NULL, NULL, NULL, NULL), 0); -} - const OPTIONS *test_get_options(void) { static const OPTIONS test_options[] = { @@ -309,7 +303,6 @@ int setup_tests(void) ADD_TEST(test_store_open_winstore); #endif ADD_TEST(test_store_search_by_key_fingerprint_fail); - ADD_TEST(test_store_delete_null_uri); ADD_ALL_TESTS(test_store_get_params, 3); if (sm2file != NULL) ADD_TEST(test_store_attach_unregistered_scheme); diff --git a/test/p_ossltest.c b/test/p_ossltest.c index 06bd9bc64c..6d775520ba 100644 --- a/test/p_ossltest.c +++ b/test/p_ossltest.c @@ -695,7 +695,6 @@ static const OSSL_DISPATCH ossl_testaes128_cbc_functions[] = { typedef struct { OSSL_LIB_CTX *libctx; EVP_CIPHER_CTX *sub_ctx; - int tls1_aad; } PROV_EVP_AES128_GCM_CTX; /** @@ -839,16 +838,10 @@ static int ossl_test_aes128gcm_update(void *vprovctx, char *out, size_t *outl, size_t inl) { PROV_EVP_AES128_GCM_CTX *ctx = (PROV_EVP_AES128_GCM_CTX *)vprovctx; - int ret = 0, soutl = 0; - uint8_t *inbuf = NULL; + int ret, soutl; + uint8_t *inbuf; - *outl = 0; - - if (in != NULL && inl > 0) { - inbuf = OPENSSL_memdup(in, inl); - if (inbuf == NULL) - goto end; - } + inbuf = OPENSSL_memdup(in, inl); if (EVP_CIPHER_CTX_is_encrypting(ctx->sub_ctx)) ret = EVP_EncryptUpdate(ctx->sub_ctx, (unsigned char *)out, @@ -856,31 +849,16 @@ static int ossl_test_aes128gcm_update(void *vprovctx, char *out, size_t *outl, else ret = EVP_DecryptUpdate(ctx->sub_ctx, (unsigned char *)out, &soutl, in, (int)inl); + *outl = soutl; /* * Once the cipher is complete, throw it away and use the * plaintext as our output */ - if (ret > 0 && inbuf != NULL && out != NULL) { - if (ctx->tls1_aad && EVP_CIPHER_CTX_is_encrypting(ctx->sub_ctx)) { - if (inl < EVP_GCM_TLS_EXPLICIT_IV_LEN + EVP_GCM_TLS_TAG_LEN) { - ret = 0; - goto end; - } - - memcpy(out + EVP_GCM_TLS_EXPLICIT_IV_LEN, - inbuf + EVP_GCM_TLS_EXPLICIT_IV_LEN, - inl - EVP_GCM_TLS_EXPLICIT_IV_LEN - EVP_GCM_TLS_TAG_LEN); - } else { - memcpy(out, inbuf, inl); - } - } - - *outl = soutl; - -end: - ctx->tls1_aad = 0; + if (inbuf != NULL && out != NULL) + memcpy(out, inbuf, inl); OPENSSL_free(inbuf); + return ret; } @@ -977,15 +955,8 @@ static int ossl_test_aes128gcm_get_ctx_params(void *vprovctx, OSSL_PARAM params[ static int ossl_test_aes128gcm_set_ctx_params(void *vprovctx, const OSSL_PARAM params[]) { PROV_EVP_AES128_GCM_CTX *ctx = (PROV_EVP_AES128_GCM_CTX *)vprovctx; - int tls1_aad; - int ret; - tls1_aad = OSSL_PARAM_locate_const(params, OSSL_CIPHER_PARAM_AEAD_TLS1_AAD) != NULL; - ret = EVP_CIPHER_CTX_set_params(ctx->sub_ctx, params); - if (ret) - ctx->tls1_aad = tls1_aad; - - return ret; + return EVP_CIPHER_CTX_set_params(ctx->sub_ctx, params); } /** @@ -1782,84 +1753,6 @@ static const OSSL_ALGORITHM ossltest_rands[] = { { NULL, NULL, NULL } }; -/* - * The implementations for the p_ossltest provider decoder/encoder/store objects - * are defined below, but they are dummy implementations and do nothing. They exist - * for the sole purpose of returning algorithms from this provider so that we can test if - * object creation and refcounting work when a provider requests no caching of the algorithm. - */ - -static int ossl_test_decode(void *ctx, OSSL_CORE_BIO *in, int selection, - OSSL_CALLBACK *cb, void *cbarg, - OSSL_PASSPHRASE_CALLBACK *pb, void *pbarg) -{ - return 1; -} - -static const OSSL_DISPATCH ossl_test_decoder_functions[] = { - { OSSL_FUNC_DECODER_DECODE, (void (*)(void))ossl_test_decode }, - OSSL_DISPATCH_END -}; - -static const OSSL_ALGORITHM ossl_test_decoders[] = { - ALG("p_ossltest_decoder", ossl_test_decoder_functions), - { NULL, NULL, NULL } -}; - -static int ossl_test_encode(void *ctx, OSSL_CORE_BIO *out, const void *obj, - const OSSL_PARAM obj_abstract[], - int selection, OSSL_PASSPHRASE_CALLBACK *pb, - void *pbarg) -{ - return 1; -} - -static const OSSL_DISPATCH ossl_test_encoder_functions[] = { - { OSSL_FUNC_ENCODER_ENCODE, (void (*)(void))ossl_test_encode }, - OSSL_DISPATCH_END -}; - -static const OSSL_ALGORITHM ossl_test_encoders[] = { - ALG("p_ossltest_encoder", ossl_test_encoder_functions), - { NULL, NULL, NULL } -}; - -static int dummy_store_value = 0; - -static void *ossl_test_store_open(void *provctx, const char *uri) -{ - return (void *)&dummy_store_value; -} - -static int ossl_test_store_load(void *ctx, OSSL_CALLBACK *object_fn, void *cbarg, - OSSL_PASSPHRASE_CALLBACK *pb, void *pbarg) -{ - return 0; -} - -static int ossl_test_store_eof(void *ctx) -{ - return 1; -} - -static int ossl_test_store_close(void *ctx) -{ - return 1; -} - -static const OSSL_DISPATCH ossl_test_store_functions[] = { - { OSSL_FUNC_STORE_OPEN, (void (*)(void))ossl_test_store_open }, - { OSSL_FUNC_STORE_LOAD, (void (*)(void))ossl_test_store_load }, - { OSSL_FUNC_STORE_EOF, (void (*)(void))ossl_test_store_eof }, - { OSSL_FUNC_STORE_CLOSE, (void (*)(void))ossl_test_store_close }, - OSSL_DISPATCH_END -}; - -static const OSSL_ALGORITHM ossl_test_stores[] = { - ALG("p_ossltest_store", ossl_test_store_functions), - { NULL, NULL, NULL } -}; - /** * @brief Implement ossltest query. * @@ -1873,10 +1766,6 @@ static const OSSL_ALGORITHM *ossltest_query(void *provctx, int operation_id, int *no_cache) { *no_cache = 0; - - if (getenv("OSSL_TEST_PROVIDER_NO_CACHE") != NULL) - *no_cache = 1; - switch (operation_id) { case OSSL_OP_DIGEST: return ossltest_digests; @@ -1884,12 +1773,6 @@ static const OSSL_ALGORITHM *ossltest_query(void *provctx, int operation_id, return ossltest_ciphers; case OSSL_OP_RAND: return ossltest_rands; - case OSSL_OP_DECODER: - return ossl_test_decoders; - case OSSL_OP_ENCODER: - return ossl_test_encoders; - case OSSL_OP_STORE: - return ossl_test_stores; } return NULL; } diff --git a/test/p_test.c b/test/p_test.c index 655cb7ce6f..1e38bee717 100644 --- a/test/p_test.c +++ b/test/p_test.c @@ -43,6 +43,7 @@ typedef struct p_test_ctx { OSSL_LIB_CTX *libctx; } P_TEST_CTX; +static OSSL_FUNC_core_gettable_params_fn *c_gettable_params = NULL; static OSSL_FUNC_core_get_params_fn *c_get_params = NULL; static OSSL_FUNC_core_new_error_fn *c_new_error; static OSSL_FUNC_core_set_error_debug_fn *c_set_error_debug; @@ -257,6 +258,9 @@ int OSSL_provider_init(const OSSL_CORE_HANDLE *handle, for (; in->function_id != 0; in++) { switch (in->function_id) { + case OSSL_FUNC_CORE_GETTABLE_PARAMS: + c_gettable_params = OSSL_FUNC_core_gettable_params(in); + break; case OSSL_FUNC_CORE_GET_PARAMS: c_get_params = OSSL_FUNC_core_get_params(in); break; diff --git a/test/packettest.c b/test/packettest.c index 5aa9890ab3..4b0e6f5c63 100644 --- a/test/packettest.c +++ b/test/packettest.c @@ -1,5 +1,5 @@ /* - * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2015-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -569,39 +569,9 @@ static int test_PACKET_get_quic_length_prefixed(void) return 1; } + #endif -static int test_PACKET_msg_start(void) -{ - unsigned char buf[16] = { 0 }; - PACKET pkt, subpkt; - - if (!TEST_true(PACKET_buf_init(&pkt, buf, sizeof(buf)))) - return 0; - - if (!TEST_ptr_eq(PACKET_msg_start(&pkt), buf)) - return 0; - - if (!TEST_true(PACKET_forward(&pkt, 1)) - || !TEST_ptr_eq(PACKET_msg_start(&pkt), buf)) - return 0; - - if (!TEST_true(PACKET_get_sub_packet(&pkt, &subpkt, 1)) - || !TEST_ptr_eq(PACKET_msg_start(&subpkt), buf) - || !TEST_ptr_eq(PACKET_msg_start(&pkt), buf)) - return 0; - - if (!TEST_true(PACKET_forward(&subpkt, 1)) - || !TEST_ptr_eq(PACKET_msg_start(&pkt), buf)) - return 0; - - PACKET_null_init(&pkt); - if (!TEST_ptr_null(PACKET_msg_start(&pkt))) - return 0; - - return 1; -} - int setup_tests(void) { unsigned int i; @@ -636,6 +606,5 @@ int setup_tests(void) ADD_TEST(test_PACKET_get_quic_vlint); ADD_TEST(test_PACKET_get_quic_length_prefixed); #endif - ADD_TEST(test_PACKET_msg_start); return 1; } diff --git a/test/pairwise_fail_test.c b/test/pairwise_fail_test.c index 3446d23166..3173225a0c 100644 --- a/test/pairwise_fail_test.c +++ b/test/pairwise_fail_test.c @@ -99,6 +99,8 @@ static int test_keygen_pairwise_failure(void) if (!TEST_ptr_null(pkey = EVP_PKEY_Q_keygen(libctx, NULL, "RSA", (size_t)2048))) goto err; } else if (strncmp(pairwise_name, "ec", 2) == 0) { + if (strcmp(pairwise_name, "eckat") == 0) + type = OSSL_SELF_TEST_TYPE_PCT_KAT; if (!TEST_true(setup_selftest_pairwise_failure(type))) goto err; if (!TEST_ptr_null(pkey = EVP_PKEY_Q_keygen(libctx, NULL, "EC", "P-256"))) diff --git a/test/param_build_test.c b/test/param_build_test.c index bac0afcb34..3b90a5e829 100644 --- a/test/param_build_test.c +++ b/test/param_build_test.c @@ -117,12 +117,8 @@ static int template_public_test(int tstid) || !TEST_true(OSSL_PARAM_BLD_push_BN(bld, "negativebignumber", nbn)) || !TEST_true(OSSL_PARAM_BLD_push_utf8_string(bld, "utf8_s", "foo", sizeof("foo"))) - || !TEST_true(OSSL_PARAM_BLD_push_octet_string(bld, "octet_s", NULL, - 0)) || !TEST_true(OSSL_PARAM_BLD_push_utf8_ptr(bld, "utf8_p", "bar-boom", 0)) - || !TEST_true(OSSL_PARAM_BLD_push_octet_ptr(bld, "octet_p", NULL, - 0)) || !TEST_true(OSSL_PARAM_BLD_push_int(bld, "i", -6)) || !TEST_ptr(params_blt = OSSL_PARAM_BLD_to_param(bld))) goto err; @@ -193,16 +189,10 @@ static int template_public_test(int tstid) || !TEST_str_eq(p->data, "foo") || !TEST_true(OSSL_PARAM_get_utf8_string(p, &utf, 0)) || !TEST_str_eq(utf, "foo") - /* Check NULL octet string */ - || !TEST_ptr(p = OSSL_PARAM_locate(params, "octet_s")) - || !TEST_size_t_eq(p->data_size, 0) /* Check UTF8 pointer */ || !TEST_ptr(p = OSSL_PARAM_locate(params, "utf8_p")) || !TEST_true(OSSL_PARAM_get_utf8_ptr(p, &cutf)) || !TEST_str_eq(cutf, "bar-boom") - /* Check NULL octet ptr */ - || !TEST_ptr(p = OSSL_PARAM_locate(params, "octet_p")) - || !TEST_size_t_eq(p->data_size, 0) /* Check BN (zero BN becomes unsigned integer) */ || !TEST_ptr(p = OSSL_PARAM_locate(params, "zeronumber")) || !TEST_str_eq(p->key, "zeronumber") diff --git a/test/params_test.c b/test/params_test.c index f5f0623bc9..49a8db7563 100644 --- a/test/params_test.c +++ b/test/params_test.c @@ -82,7 +82,7 @@ struct object_st { "6768696a6b6c6d6e6f70717273747576" \ "7778797a30313233343536373839" #define p4_init "BLAKE2s256" /* Random string */ -#define p5_init "Hellow World" /* Random string */ /* codespell:ignore */ +#define p5_init "Hellow World" /* Random string */ #define p6_init OPENSSL_FULL_VERSION_STR /* Static string */ static void cleanup_object(void *vobj) @@ -648,9 +648,9 @@ static int check_int_from_text(const struct int_from_text_test_st a) return 0; } if (param.data_size != a.expected_bufsize) { - TEST_error("unexpected size for %s \"%s\": %zu != %zu", + TEST_error("unexpected size for %s \"%s\": %d != %d", a.argname, a.strval, - a.expected_bufsize, param.data_size); + (int)a.expected_bufsize, (int)param.data_size); return 0; } diff --git a/test/pbetest.c b/test/pbetest.c index 66c67e603d..ae8292629e 100644 --- a/test/pbetest.c +++ b/test/pbetest.c @@ -8,8 +8,6 @@ */ #include -#include -#include #include "testutil.h" @@ -19,22 +17,49 @@ #include #include #include -#include #if !defined OPENSSL_NO_RC4 && !defined OPENSSL_NO_MD5 \ || !defined OPENSSL_NO_DES && !defined OPENSSL_NO_SHA1 static const char pbe_password[] = "MyVoiceIsMyPassport"; static unsigned char pbe_salt[] = { - 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08 + 0x01, + 0x02, + 0x03, + 0x04, + 0x05, + 0x06, + 0x07, + 0x08, }; static const int pbe_iter = 1000; static unsigned char pbe_plaintext[] = { - 0x57, 0x65, 0x20, 0x61, 0x72, 0x65, 0x20, 0x61, 0x6c, 0x6c, - 0x20, 0x6d, 0x61, 0x64, 0x65, 0x20, 0x6f, 0x66, 0x20, 0x73, - 0x74, 0x61, 0x72, 0x73 + 0x57, + 0x65, + 0x20, + 0x61, + 0x72, + 0x65, + 0x20, + 0x61, + 0x6c, + 0x6c, + 0x20, + 0x6d, + 0x61, + 0x64, + 0x65, + 0x20, + 0x6f, + 0x66, + 0x20, + 0x73, + 0x74, + 0x61, + 0x72, + 0x73, }; #endif @@ -42,18 +67,67 @@ static unsigned char pbe_plaintext[] = { #if !defined OPENSSL_NO_RC4 && !defined OPENSSL_NO_MD5 static const unsigned char pbe_ciphertext_rc4_md5[] = { - 0x21, 0x90, 0xfa, 0xee, 0x95, 0x66, 0x59, 0x45, 0xfa, 0x1e, - 0x9f, 0xe2, 0x25, 0xd2, 0xf9, 0x71, 0x94, 0xe4, 0x3d, 0xc9, - 0x7c, 0xb0, 0x07, 0x23 + 0x21, + 0x90, + 0xfa, + 0xee, + 0x95, + 0x66, + 0x59, + 0x45, + 0xfa, + 0x1e, + 0x9f, + 0xe2, + 0x25, + 0xd2, + 0xf9, + 0x71, + 0x94, + 0xe4, + 0x3d, + 0xc9, + 0x7c, + 0xb0, + 0x07, + 0x23, }; #endif #if !defined OPENSSL_NO_DES && !defined OPENSSL_NO_SHA1 static const unsigned char pbe_ciphertext_des_sha1[] = { - 0xce, 0x4b, 0xb0, 0x0a, 0x7b, 0x48, 0xd7, 0xe3, 0x9a, 0x9f, - 0x46, 0xd6, 0x41, 0x42, 0x4b, 0x44, 0x36, 0x45, 0x5f, 0x60, - 0x8f, 0x3c, 0xd0, 0x55, 0xd0, 0x8d, 0xa9, 0xab, 0x78, 0x5b, - 0x63, 0xaf + 0xce, + 0x4b, + 0xb0, + 0x0a, + 0x7b, + 0x48, + 0xd7, + 0xe3, + 0x9a, + 0x9f, + 0x46, + 0xd6, + 0x41, + 0x42, + 0x4b, + 0x44, + 0x36, + 0x45, + 0x5f, + 0x60, + 0x8f, + 0x3c, + 0xd0, + 0x55, + 0xd0, + 0x8d, + 0xa9, + 0xab, + 0x78, + 0x5b, + 0x63, + 0xaf, }; #endif @@ -128,179 +202,6 @@ static int test_pkcs5_pbe_des_sha1(void) } #endif -/* - * Regression test for negative EVP_CIPHER_get_iv_length() return in - * PKCS5_pbe2_set_scrypt(). - * - * A malicious/buggy provider advertises SIZE_MAX as IV length. - * evp_cipher_cache_constants() casts (size_t)SIZE_MAX to int => -1. - * Without the ivlen > 0 guard, this -1 is implicitly converted to SIZE_MAX - * in the memcpy call, causing a stack buffer overflow. - * - * This test verifies that PKCS5_pbe2_set_scrypt() handles negative IV - * lengths gracefully (returns NULL, no crash). - */ -#ifndef OPENSSL_NO_SCRYPT - -static void *bad_iv_cipher_newctx(void *provctx) -{ - static int dummy; - return &dummy; -} - -static void bad_iv_cipher_freectx(void *vctx) -{ -} - -static int bad_iv_cipher_cipher(void *vctx, - unsigned char *out, size_t *outl, - size_t outsz, - const unsigned char *in, size_t inl) -{ - if (outl != NULL) - *outl = 0; - return 1; -} - -/* - * Advertise SIZE_MAX as IV length. After evp_cipher_cache_constants() - * stores (int)SIZE_MAX, EVP_CIPHER_get_iv_length() returns -1. - */ -static int bad_iv_cipher_get_params(OSSL_PARAM params[]) -{ - OSSL_PARAM *p; - - p = OSSL_PARAM_locate(params, OSSL_CIPHER_PARAM_BLOCK_SIZE); - if (p != NULL && !OSSL_PARAM_set_size_t(p, 16)) - return 0; - p = OSSL_PARAM_locate(params, OSSL_CIPHER_PARAM_KEYLEN); - if (p != NULL && !OSSL_PARAM_set_size_t(p, 32)) - return 0; - p = OSSL_PARAM_locate(params, OSSL_CIPHER_PARAM_MODE); - if (p != NULL && !OSSL_PARAM_set_uint(p, EVP_CIPH_CBC_MODE)) - return 0; - p = OSSL_PARAM_locate(params, OSSL_CIPHER_PARAM_IVLEN); - if (p != NULL && !OSSL_PARAM_set_size_t(p, SIZE_MAX)) - return 0; - p = OSSL_PARAM_locate(params, OSSL_CIPHER_PARAM_AEAD); - if (p != NULL && !OSSL_PARAM_set_int(p, 0)) - return 0; - p = OSSL_PARAM_locate(params, OSSL_CIPHER_PARAM_CUSTOM_IV); - if (p != NULL && !OSSL_PARAM_set_int(p, 0)) - return 0; - p = OSSL_PARAM_locate(params, OSSL_CIPHER_PARAM_CTS); - if (p != NULL && !OSSL_PARAM_set_int(p, 0)) - return 0; - p = OSSL_PARAM_locate(params, OSSL_CIPHER_PARAM_TLS1_MULTIBLOCK); - if (p != NULL && !OSSL_PARAM_set_int(p, 0)) - return 0; - p = OSSL_PARAM_locate(params, OSSL_CIPHER_PARAM_HAS_RAND_KEY); - if (p != NULL && !OSSL_PARAM_set_int(p, 0)) - return 0; - p = OSSL_PARAM_locate(params, OSSL_CIPHER_PARAM_ENCRYPT_THEN_MAC); - if (p != NULL && !OSSL_PARAM_set_int(p, 0)) - return 0; - return 1; -} - -static const OSSL_DISPATCH bad_iv_cipher_fns[] = { - { OSSL_FUNC_CIPHER_NEWCTX, (void (*)(void))bad_iv_cipher_newctx }, - { OSSL_FUNC_CIPHER_FREECTX, (void (*)(void))bad_iv_cipher_freectx }, - { OSSL_FUNC_CIPHER_CIPHER, (void (*)(void))bad_iv_cipher_cipher }, - { OSSL_FUNC_CIPHER_GET_PARAMS, (void (*)(void))bad_iv_cipher_get_params }, - OSSL_DISPATCH_END -}; - -static const OSSL_ALGORITHM bad_iv_cipher_algs[] = { - { "AES-256-CBC:AES256", "provider=bad-iv-prov", bad_iv_cipher_fns, - "Bad IV length cipher for regression testing" }, - { NULL, NULL, NULL, NULL } -}; - -static const OSSL_ALGORITHM *bad_iv_query(void *provctx, - int operation_id, - int *no_cache) -{ - *no_cache = 0; - if (operation_id == OSSL_OP_CIPHER) - return bad_iv_cipher_algs; - return NULL; -} - -static void bad_iv_teardown(void *provctx) { } - -static const OSSL_DISPATCH bad_iv_provider_fns[] = { - { OSSL_FUNC_PROVIDER_TEARDOWN, (void (*)(void))bad_iv_teardown }, - { OSSL_FUNC_PROVIDER_QUERY_OPERATION, (void (*)(void))bad_iv_query }, - OSSL_DISPATCH_END -}; - -static int bad_iv_provider_init(const OSSL_CORE_HANDLE *handle, - const OSSL_DISPATCH *in, - const OSSL_DISPATCH **out, - void **provctx) -{ - static int ctx; - - *provctx = &ctx; - *out = bad_iv_provider_fns; - return 1; -} - -/* - * Test that PKCS5_pbe2_set_scrypt() does not crash when - * EVP_CIPHER_get_iv_length() returns a negative value. - */ -static int test_pkcs5_scrypt_bad_iv_length(void) -{ - int ret = 0; - OSSL_LIB_CTX *libctx = NULL; - OSSL_PROVIDER *bad_prov = NULL; - EVP_CIPHER *cipher = NULL; - X509_ALGOR *alg = NULL; - unsigned char salt[16] = { - 0x01, 0x02, 0x03, 0x04, 0x05, 0x06, 0x07, 0x08, - 0x09, 0x0a, 0x0b, 0x0c, 0x0d, 0x0e, 0x0f, 0x10 - }; - unsigned char iv[16] = { 0xAA }; - - if (!TEST_ptr(libctx = OSSL_LIB_CTX_new())) - goto err; - - if (!TEST_true(OSSL_PROVIDER_add_builtin(libctx, "bad-iv-prov", - bad_iv_provider_init))) - goto err; - - if (!TEST_ptr(bad_prov = OSSL_PROVIDER_load(libctx, "bad-iv-prov"))) - goto err; - - if (!TEST_ptr(cipher = EVP_CIPHER_fetch(libctx, "AES-256-CBC", - "provider=bad-iv-prov"))) - goto err; - - if (!TEST_int_lt(EVP_CIPHER_get_iv_length(cipher), 0)) - goto err; - - /* - * Before the fix, this would trigger memcpy(iv[16], aiv, SIZE_MAX) - * — a stack buffer overflow. After the fix, the function must - * return NULL. - */ - alg = PKCS5_pbe2_set_scrypt(cipher, salt, (int)sizeof(salt), - iv, 1024, 8, 1); - if (!TEST_ptr_null(alg)) - goto err; - - ret = 1; -err: - X509_ALGOR_free(alg); - EVP_CIPHER_free(cipher); - OSSL_PROVIDER_unload(bad_prov); - OSSL_LIB_CTX_free(libctx); - return ret; -} -#endif /* OPENSSL_NO_SCRYPT */ - #ifdef OPENSSL_NO_AUTOLOAD_CONFIG /* * For configurations where we are not autoloading configuration, we need @@ -328,9 +229,6 @@ int setup_tests(void) #if !defined OPENSSL_NO_DES && !defined OPENSSL_NO_SHA1 ADD_TEST(test_pkcs5_pbe_des_sha1); #endif -#ifndef OPENSSL_NO_SCRYPT - ADD_TEST(test_pkcs5_scrypt_bad_iv_length); -#endif return 1; } diff --git a/test/pkcs12_api_test.c b/test/pkcs12_api_test.c index 150a3cf29d..ff32e65b6a 100644 --- a/test/pkcs12_api_test.c +++ b/test/pkcs12_api_test.c @@ -175,7 +175,7 @@ static int pkcs12_create_ex2_test(int test) 0, 0, 0, testctx, NULL, NULL, NULL); - if (!TEST_ptr_null(ptr)) + if (TEST_ptr(ptr)) goto err; /* Can't proceed without a valid cert at least */ @@ -201,7 +201,7 @@ static int pkcs12_create_ex2_test(int test) testctx, NULL, pkcs12_create_cb, (void *)&cb_ret); /* PKCS12 not created */ - if (!TEST_ptr_null(ptr)) + if (TEST_ptr(ptr)) goto err; } else if (test == 2) { /* Specified call back called - return failure */ @@ -280,35 +280,6 @@ err: return ret; } -static int test_PKCS12_set_pbmac1_pbkdf2_invalid_saltlen(void) -{ - int ret = 0; - unsigned char salt[8] = { 0 }; - EVP_PKEY *key = NULL; - X509 *cert = NULL; - STACK_OF(X509) *ca = NULL; - PKCS12 *p12 = NULL; - - if (!TEST_ptr(p12 = PKCS12_load(in_file))) - return 0; - if (!TEST_true(PKCS12_parse(p12, in_pass, &key, &cert, &ca))) - goto err; - PKCS12_free(p12); - - if (!TEST_ptr(p12 = PKCS12_create_ex2("pass", NULL, key, cert, ca, - NID_undef, NID_undef, 0, -1, 0, - testctx, NULL, NULL, NULL))) - goto err; - ret = TEST_false(PKCS12_set_pbmac1_pbkdf2(p12, "pass", -1, - salt, -1, 0, NULL, NULL)); -err: - PKCS12_free(p12); - EVP_PKEY_free(key); - X509_free(cert); - OSSL_STACK_OF_X509_free(ca); - return ret; -} - int setup_tests(void) { OPTION_CHOICE o; @@ -349,7 +320,6 @@ int setup_tests(void) ADD_TEST(pkcs12_parse_test); ADD_ALL_TESTS(pkcs12_create_ex2_test, 3); ADD_TEST(test_PKCS12_set_pbmac1_pbkdf2_saltlen_zero); - ADD_TEST(test_PKCS12_set_pbmac1_pbkdf2_invalid_saltlen); return 1; } diff --git a/test/pkcs12_format_test.c b/test/pkcs12_format_test.c index 4ae4cbfec5..7d6ebd6e22 100644 --- a/test/pkcs12_format_test.c +++ b/test/pkcs12_format_test.c @@ -31,237 +31,2226 @@ static OSSL_PROVIDER *lgcyprov = NULL; */ static const unsigned char CERT1[] = { - 0x30, 0x82, 0x01, 0xed, 0x30, 0x82, 0x01, 0x56, 0xa0, 0x03, - 0x02, 0x01, 0x02, 0x02, 0x09, 0x00, 0x8b, 0x4b, 0x5e, 0x6c, - 0x03, 0x28, 0x4e, 0xe6, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, - 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x30, - 0x19, 0x31, 0x17, 0x30, 0x15, 0x06, 0x03, 0x55, 0x04, 0x03, - 0x0c, 0x0e, 0x50, 0x31, 0x32, 0x54, 0x65, 0x73, 0x74, 0x2d, - 0x52, 0x6f, 0x6f, 0x74, 0x2d, 0x41, 0x30, 0x1e, 0x17, 0x0d, - 0x31, 0x39, 0x30, 0x39, 0x33, 0x30, 0x30, 0x30, 0x34, 0x36, - 0x35, 0x36, 0x5a, 0x17, 0x0d, 0x32, 0x39, 0x30, 0x39, 0x32, - 0x37, 0x30, 0x30, 0x34, 0x36, 0x35, 0x36, 0x5a, 0x30, 0x1b, - 0x31, 0x19, 0x30, 0x17, 0x06, 0x03, 0x55, 0x04, 0x03, 0x0c, - 0x10, 0x50, 0x31, 0x32, 0x54, 0x65, 0x73, 0x74, 0x2d, 0x53, - 0x65, 0x72, 0x76, 0x65, 0x72, 0x2d, 0x31, 0x30, 0x81, 0x9f, - 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, - 0x01, 0x01, 0x01, 0x05, 0x00, 0x03, 0x81, 0x8d, 0x00, 0x30, - 0x81, 0x89, 0x02, 0x81, 0x81, 0x00, 0xbc, 0xdc, 0x6f, 0x8c, - 0x7a, 0x2a, 0x4b, 0xea, 0x66, 0x66, 0x04, 0xa9, 0x05, 0x92, - 0x53, 0xd7, 0x13, 0x3c, 0x49, 0xe1, 0xc8, 0xbb, 0xdf, 0x3d, - 0xcb, 0x88, 0x31, 0x07, 0x20, 0x59, 0x93, 0x24, 0x7f, 0x7d, - 0xc6, 0x84, 0x81, 0x16, 0x64, 0x4a, 0x52, 0xa6, 0x30, 0x44, - 0xdc, 0x1a, 0x30, 0xde, 0xae, 0x29, 0x18, 0xcf, 0xc7, 0xf3, - 0xcf, 0x0c, 0xb7, 0x8e, 0x2b, 0x1e, 0x21, 0x01, 0x0b, 0xfb, - 0xe5, 0xe6, 0xcf, 0x2b, 0x84, 0xe1, 0x33, 0xf8, 0xba, 0x02, - 0xfc, 0x30, 0xfa, 0xc4, 0x33, 0xc7, 0x37, 0xc6, 0x7f, 0x72, - 0x31, 0x92, 0x1d, 0x8f, 0xa0, 0xfb, 0xe5, 0x4a, 0x08, 0x31, - 0x78, 0x80, 0x9c, 0x23, 0xb4, 0xe9, 0x19, 0x56, 0x04, 0xfa, - 0x0d, 0x07, 0x04, 0xb7, 0x43, 0xac, 0x4c, 0x49, 0x7c, 0xc2, - 0xa1, 0x44, 0xc1, 0x48, 0x7d, 0x28, 0xe5, 0x23, 0x66, 0x07, - 0x22, 0xd5, 0xf0, 0xf1, 0x02, 0x03, 0x01, 0x00, 0x01, 0xa3, - 0x3b, 0x30, 0x39, 0x30, 0x1f, 0x06, 0x03, 0x55, 0x1d, 0x23, - 0x04, 0x18, 0x30, 0x16, 0x80, 0x14, 0xdb, 0xbb, 0xb8, 0x92, - 0x4e, 0x24, 0x0b, 0x1b, 0xbb, 0x78, 0x33, 0xf9, 0x01, 0x02, - 0x23, 0x0d, 0x96, 0x18, 0x30, 0x47, 0x30, 0x09, 0x06, 0x03, - 0x55, 0x1d, 0x13, 0x04, 0x02, 0x30, 0x00, 0x30, 0x0b, 0x06, - 0x03, 0x55, 0x1d, 0x0f, 0x04, 0x04, 0x03, 0x02, 0x04, 0xf0, - 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, - 0x01, 0x01, 0x0b, 0x05, 0x00, 0x03, 0x81, 0x81, 0x00, 0x1c, - 0x13, 0xdc, 0x02, 0xf1, 0x44, 0x36, 0x65, 0xa9, 0xbe, 0x30, - 0x1c, 0x66, 0x14, 0x20, 0x86, 0x5a, 0xa8, 0x69, 0x25, 0xf8, - 0x1a, 0xb6, 0x9e, 0x5e, 0xe9, 0x89, 0xb8, 0x67, 0x70, 0x19, - 0x87, 0x60, 0xeb, 0x4b, 0x11, 0x71, 0x85, 0xf8, 0xe9, 0xa7, - 0x3e, 0x20, 0x42, 0xec, 0x43, 0x25, 0x01, 0x03, 0xe5, 0x4d, - 0x83, 0x22, 0xf5, 0x8e, 0x3a, 0x1a, 0x1b, 0xd4, 0x1c, 0xda, - 0x6b, 0x9d, 0x10, 0x1b, 0xee, 0x67, 0x4e, 0x1f, 0x69, 0xab, - 0xbc, 0xaa, 0x62, 0x8e, 0x9e, 0xc6, 0xee, 0xd6, 0x09, 0xc0, - 0xca, 0xe0, 0xaa, 0x9f, 0x07, 0xb2, 0xc2, 0xbb, 0x31, 0x96, - 0xa2, 0x04, 0x62, 0xd3, 0x13, 0x32, 0x29, 0x67, 0x6e, 0xad, - 0x2e, 0x0b, 0xea, 0x04, 0x7c, 0x8c, 0x5a, 0x5d, 0xac, 0x14, - 0xaa, 0x61, 0x7f, 0x28, 0x6c, 0x2d, 0x64, 0x2d, 0xc3, 0xaf, - 0x77, 0x52, 0x90, 0xb4, 0x37, 0xc0, 0x30 + 0x30, + 0x82, + 0x01, + 0xed, + 0x30, + 0x82, + 0x01, + 0x56, + 0xa0, + 0x03, + 0x02, + 0x01, + 0x02, + 0x02, + 0x09, + 0x00, + 0x8b, + 0x4b, + 0x5e, + 0x6c, + 0x03, + 0x28, + 0x4e, + 0xe6, + 0x30, + 0x0d, + 0x06, + 0x09, + 0x2a, + 0x86, + 0x48, + 0x86, + 0xf7, + 0x0d, + 0x01, + 0x01, + 0x0b, + 0x05, + 0x00, + 0x30, + 0x19, + 0x31, + 0x17, + 0x30, + 0x15, + 0x06, + 0x03, + 0x55, + 0x04, + 0x03, + 0x0c, + 0x0e, + 0x50, + 0x31, + 0x32, + 0x54, + 0x65, + 0x73, + 0x74, + 0x2d, + 0x52, + 0x6f, + 0x6f, + 0x74, + 0x2d, + 0x41, + 0x30, + 0x1e, + 0x17, + 0x0d, + 0x31, + 0x39, + 0x30, + 0x39, + 0x33, + 0x30, + 0x30, + 0x30, + 0x34, + 0x36, + 0x35, + 0x36, + 0x5a, + 0x17, + 0x0d, + 0x32, + 0x39, + 0x30, + 0x39, + 0x32, + 0x37, + 0x30, + 0x30, + 0x34, + 0x36, + 0x35, + 0x36, + 0x5a, + 0x30, + 0x1b, + 0x31, + 0x19, + 0x30, + 0x17, + 0x06, + 0x03, + 0x55, + 0x04, + 0x03, + 0x0c, + 0x10, + 0x50, + 0x31, + 0x32, + 0x54, + 0x65, + 0x73, + 0x74, + 0x2d, + 0x53, + 0x65, + 0x72, + 0x76, + 0x65, + 0x72, + 0x2d, + 0x31, + 0x30, + 0x81, + 0x9f, + 0x30, + 0x0d, + 0x06, + 0x09, + 0x2a, + 0x86, + 0x48, + 0x86, + 0xf7, + 0x0d, + 0x01, + 0x01, + 0x01, + 0x05, + 0x00, + 0x03, + 0x81, + 0x8d, + 0x00, + 0x30, + 0x81, + 0x89, + 0x02, + 0x81, + 0x81, + 0x00, + 0xbc, + 0xdc, + 0x6f, + 0x8c, + 0x7a, + 0x2a, + 0x4b, + 0xea, + 0x66, + 0x66, + 0x04, + 0xa9, + 0x05, + 0x92, + 0x53, + 0xd7, + 0x13, + 0x3c, + 0x49, + 0xe1, + 0xc8, + 0xbb, + 0xdf, + 0x3d, + 0xcb, + 0x88, + 0x31, + 0x07, + 0x20, + 0x59, + 0x93, + 0x24, + 0x7f, + 0x7d, + 0xc6, + 0x84, + 0x81, + 0x16, + 0x64, + 0x4a, + 0x52, + 0xa6, + 0x30, + 0x44, + 0xdc, + 0x1a, + 0x30, + 0xde, + 0xae, + 0x29, + 0x18, + 0xcf, + 0xc7, + 0xf3, + 0xcf, + 0x0c, + 0xb7, + 0x8e, + 0x2b, + 0x1e, + 0x21, + 0x01, + 0x0b, + 0xfb, + 0xe5, + 0xe6, + 0xcf, + 0x2b, + 0x84, + 0xe1, + 0x33, + 0xf8, + 0xba, + 0x02, + 0xfc, + 0x30, + 0xfa, + 0xc4, + 0x33, + 0xc7, + 0x37, + 0xc6, + 0x7f, + 0x72, + 0x31, + 0x92, + 0x1d, + 0x8f, + 0xa0, + 0xfb, + 0xe5, + 0x4a, + 0x08, + 0x31, + 0x78, + 0x80, + 0x9c, + 0x23, + 0xb4, + 0xe9, + 0x19, + 0x56, + 0x04, + 0xfa, + 0x0d, + 0x07, + 0x04, + 0xb7, + 0x43, + 0xac, + 0x4c, + 0x49, + 0x7c, + 0xc2, + 0xa1, + 0x44, + 0xc1, + 0x48, + 0x7d, + 0x28, + 0xe5, + 0x23, + 0x66, + 0x07, + 0x22, + 0xd5, + 0xf0, + 0xf1, + 0x02, + 0x03, + 0x01, + 0x00, + 0x01, + 0xa3, + 0x3b, + 0x30, + 0x39, + 0x30, + 0x1f, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x23, + 0x04, + 0x18, + 0x30, + 0x16, + 0x80, + 0x14, + 0xdb, + 0xbb, + 0xb8, + 0x92, + 0x4e, + 0x24, + 0x0b, + 0x1b, + 0xbb, + 0x78, + 0x33, + 0xf9, + 0x01, + 0x02, + 0x23, + 0x0d, + 0x96, + 0x18, + 0x30, + 0x47, + 0x30, + 0x09, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x13, + 0x04, + 0x02, + 0x30, + 0x00, + 0x30, + 0x0b, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x0f, + 0x04, + 0x04, + 0x03, + 0x02, + 0x04, + 0xf0, + 0x30, + 0x0d, + 0x06, + 0x09, + 0x2a, + 0x86, + 0x48, + 0x86, + 0xf7, + 0x0d, + 0x01, + 0x01, + 0x0b, + 0x05, + 0x00, + 0x03, + 0x81, + 0x81, + 0x00, + 0x1c, + 0x13, + 0xdc, + 0x02, + 0xf1, + 0x44, + 0x36, + 0x65, + 0xa9, + 0xbe, + 0x30, + 0x1c, + 0x66, + 0x14, + 0x20, + 0x86, + 0x5a, + 0xa8, + 0x69, + 0x25, + 0xf8, + 0x1a, + 0xb6, + 0x9e, + 0x5e, + 0xe9, + 0x89, + 0xb8, + 0x67, + 0x70, + 0x19, + 0x87, + 0x60, + 0xeb, + 0x4b, + 0x11, + 0x71, + 0x85, + 0xf8, + 0xe9, + 0xa7, + 0x3e, + 0x20, + 0x42, + 0xec, + 0x43, + 0x25, + 0x01, + 0x03, + 0xe5, + 0x4d, + 0x83, + 0x22, + 0xf5, + 0x8e, + 0x3a, + 0x1a, + 0x1b, + 0xd4, + 0x1c, + 0xda, + 0x6b, + 0x9d, + 0x10, + 0x1b, + 0xee, + 0x67, + 0x4e, + 0x1f, + 0x69, + 0xab, + 0xbc, + 0xaa, + 0x62, + 0x8e, + 0x9e, + 0xc6, + 0xee, + 0xd6, + 0x09, + 0xc0, + 0xca, + 0xe0, + 0xaa, + 0x9f, + 0x07, + 0xb2, + 0xc2, + 0xbb, + 0x31, + 0x96, + 0xa2, + 0x04, + 0x62, + 0xd3, + 0x13, + 0x32, + 0x29, + 0x67, + 0x6e, + 0xad, + 0x2e, + 0x0b, + 0xea, + 0x04, + 0x7c, + 0x8c, + 0x5a, + 0x5d, + 0xac, + 0x14, + 0xaa, + 0x61, + 0x7f, + 0x28, + 0x6c, + 0x2d, + 0x64, + 0x2d, + 0xc3, + 0xaf, + 0x77, + 0x52, + 0x90, + 0xb4, + 0x37, + 0xc0, + 0x30, }; static const unsigned char CERT2[] = { - 0x30, 0x82, 0x01, 0xed, 0x30, 0x82, 0x01, 0x56, 0xa0, 0x03, - 0x02, 0x01, 0x02, 0x02, 0x09, 0x00, 0x8b, 0x4b, 0x5e, 0x6c, - 0x03, 0x28, 0x4e, 0xe7, 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, - 0x48, 0x86, 0xf7, 0x0d, 0x01, 0x01, 0x0b, 0x05, 0x00, 0x30, - 0x19, 0x31, 0x17, 0x30, 0x15, 0x06, 0x03, 0x55, 0x04, 0x03, - 0x0c, 0x0e, 0x50, 0x31, 0x32, 0x54, 0x65, 0x73, 0x74, 0x2d, - 0x52, 0x6f, 0x6f, 0x74, 0x2d, 0x41, 0x30, 0x1e, 0x17, 0x0d, - 0x31, 0x39, 0x30, 0x39, 0x33, 0x30, 0x30, 0x30, 0x34, 0x36, - 0x35, 0x36, 0x5a, 0x17, 0x0d, 0x32, 0x39, 0x30, 0x39, 0x32, - 0x37, 0x30, 0x30, 0x34, 0x36, 0x35, 0x36, 0x5a, 0x30, 0x1b, - 0x31, 0x19, 0x30, 0x17, 0x06, 0x03, 0x55, 0x04, 0x03, 0x0c, - 0x10, 0x50, 0x31, 0x32, 0x54, 0x65, 0x73, 0x74, 0x2d, 0x43, - 0x6c, 0x69, 0x65, 0x6e, 0x74, 0x2d, 0x31, 0x30, 0x81, 0x9f, - 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, - 0x01, 0x01, 0x01, 0x05, 0x00, 0x03, 0x81, 0x8d, 0x00, 0x30, - 0x81, 0x89, 0x02, 0x81, 0x81, 0x00, 0xa8, 0x6e, 0x40, 0x86, - 0x9f, 0x98, 0x59, 0xfb, 0x57, 0xbf, 0xc1, 0x55, 0x12, 0x38, - 0xeb, 0xb3, 0x46, 0x34, 0xc9, 0x35, 0x4d, 0xfd, 0x03, 0xe9, - 0x3a, 0x88, 0x9e, 0x97, 0x8f, 0xf4, 0xec, 0x36, 0x7b, 0x3f, - 0xba, 0xb8, 0xa5, 0x96, 0x30, 0x03, 0xc5, 0xc6, 0xd9, 0xa8, - 0x4e, 0xbc, 0x23, 0x51, 0xa1, 0x96, 0xd2, 0x03, 0x98, 0x73, - 0xb6, 0x17, 0x9c, 0x77, 0xd4, 0x95, 0x1e, 0x1b, 0xb3, 0x1b, - 0xc8, 0x71, 0xd1, 0x2e, 0x31, 0xc7, 0x6a, 0x75, 0x57, 0x08, - 0x7f, 0xba, 0x70, 0x76, 0xf7, 0x67, 0xf4, 0x4e, 0xbe, 0xfc, - 0x70, 0x61, 0x41, 0x07, 0x2b, 0x7c, 0x3c, 0x3b, 0xb3, 0xbc, - 0xd5, 0xa8, 0xbd, 0x28, 0xd8, 0x49, 0xd3, 0xe1, 0x78, 0xc8, - 0xc1, 0x42, 0x5e, 0x18, 0x36, 0xa8, 0x41, 0xf7, 0xc8, 0xaa, - 0x35, 0xfe, 0x2d, 0xd1, 0xb4, 0xcc, 0x00, 0x67, 0xae, 0x79, - 0xd3, 0x28, 0xd5, 0x5b, 0x02, 0x03, 0x01, 0x00, 0x01, 0xa3, - 0x3b, 0x30, 0x39, 0x30, 0x1f, 0x06, 0x03, 0x55, 0x1d, 0x23, - 0x04, 0x18, 0x30, 0x16, 0x80, 0x14, 0xdb, 0xbb, 0xb8, 0x92, - 0x4e, 0x24, 0x0b, 0x1b, 0xbb, 0x78, 0x33, 0xf9, 0x01, 0x02, - 0x23, 0x0d, 0x96, 0x18, 0x30, 0x47, 0x30, 0x09, 0x06, 0x03, - 0x55, 0x1d, 0x13, 0x04, 0x02, 0x30, 0x00, 0x30, 0x0b, 0x06, - 0x03, 0x55, 0x1d, 0x0f, 0x04, 0x04, 0x03, 0x02, 0x04, 0xf0, - 0x30, 0x0d, 0x06, 0x09, 0x2a, 0x86, 0x48, 0x86, 0xf7, 0x0d, - 0x01, 0x01, 0x0b, 0x05, 0x00, 0x03, 0x81, 0x81, 0x00, 0x3b, - 0xa6, 0x73, 0xbe, 0xe0, 0x28, 0xed, 0x1f, 0x29, 0x78, 0x4c, - 0xc0, 0x1f, 0xe9, 0x85, 0xc6, 0x8f, 0xe3, 0x87, 0x7c, 0xd9, - 0xe7, 0x0a, 0x37, 0xe8, 0xaa, 0xb5, 0xd2, 0x7f, 0xf8, 0x90, - 0x20, 0x80, 0x35, 0xa7, 0x79, 0x2b, 0x04, 0xa7, 0xbf, 0xe6, - 0x7b, 0x58, 0xcb, 0xec, 0x0e, 0x58, 0xef, 0x2a, 0x70, 0x8a, - 0x56, 0x8a, 0xcf, 0x6b, 0x7a, 0x74, 0x0c, 0xf4, 0x15, 0x37, - 0x93, 0xcd, 0xe6, 0xb2, 0xa1, 0x83, 0x09, 0xdb, 0x9e, 0x4f, - 0xff, 0x6a, 0x17, 0x4f, 0x33, 0xc9, 0xcc, 0x90, 0x2a, 0x67, - 0xff, 0x16, 0x78, 0xa8, 0x2c, 0x10, 0xe0, 0x52, 0x8c, 0xe6, - 0xe9, 0x90, 0x8d, 0xe0, 0x62, 0x04, 0x9a, 0x0f, 0x44, 0x01, - 0x82, 0x14, 0x92, 0x44, 0x25, 0x69, 0x22, 0xb7, 0xb8, 0xc5, - 0x94, 0x4c, 0x4b, 0x1c, 0x9b, 0x92, 0x60, 0x66, 0x90, 0x4e, - 0xb9, 0xa8, 0x4c, 0x89, 0xbb, 0x0f, 0x0b + 0x30, + 0x82, + 0x01, + 0xed, + 0x30, + 0x82, + 0x01, + 0x56, + 0xa0, + 0x03, + 0x02, + 0x01, + 0x02, + 0x02, + 0x09, + 0x00, + 0x8b, + 0x4b, + 0x5e, + 0x6c, + 0x03, + 0x28, + 0x4e, + 0xe7, + 0x30, + 0x0d, + 0x06, + 0x09, + 0x2a, + 0x86, + 0x48, + 0x86, + 0xf7, + 0x0d, + 0x01, + 0x01, + 0x0b, + 0x05, + 0x00, + 0x30, + 0x19, + 0x31, + 0x17, + 0x30, + 0x15, + 0x06, + 0x03, + 0x55, + 0x04, + 0x03, + 0x0c, + 0x0e, + 0x50, + 0x31, + 0x32, + 0x54, + 0x65, + 0x73, + 0x74, + 0x2d, + 0x52, + 0x6f, + 0x6f, + 0x74, + 0x2d, + 0x41, + 0x30, + 0x1e, + 0x17, + 0x0d, + 0x31, + 0x39, + 0x30, + 0x39, + 0x33, + 0x30, + 0x30, + 0x30, + 0x34, + 0x36, + 0x35, + 0x36, + 0x5a, + 0x17, + 0x0d, + 0x32, + 0x39, + 0x30, + 0x39, + 0x32, + 0x37, + 0x30, + 0x30, + 0x34, + 0x36, + 0x35, + 0x36, + 0x5a, + 0x30, + 0x1b, + 0x31, + 0x19, + 0x30, + 0x17, + 0x06, + 0x03, + 0x55, + 0x04, + 0x03, + 0x0c, + 0x10, + 0x50, + 0x31, + 0x32, + 0x54, + 0x65, + 0x73, + 0x74, + 0x2d, + 0x43, + 0x6c, + 0x69, + 0x65, + 0x6e, + 0x74, + 0x2d, + 0x31, + 0x30, + 0x81, + 0x9f, + 0x30, + 0x0d, + 0x06, + 0x09, + 0x2a, + 0x86, + 0x48, + 0x86, + 0xf7, + 0x0d, + 0x01, + 0x01, + 0x01, + 0x05, + 0x00, + 0x03, + 0x81, + 0x8d, + 0x00, + 0x30, + 0x81, + 0x89, + 0x02, + 0x81, + 0x81, + 0x00, + 0xa8, + 0x6e, + 0x40, + 0x86, + 0x9f, + 0x98, + 0x59, + 0xfb, + 0x57, + 0xbf, + 0xc1, + 0x55, + 0x12, + 0x38, + 0xeb, + 0xb3, + 0x46, + 0x34, + 0xc9, + 0x35, + 0x4d, + 0xfd, + 0x03, + 0xe9, + 0x3a, + 0x88, + 0x9e, + 0x97, + 0x8f, + 0xf4, + 0xec, + 0x36, + 0x7b, + 0x3f, + 0xba, + 0xb8, + 0xa5, + 0x96, + 0x30, + 0x03, + 0xc5, + 0xc6, + 0xd9, + 0xa8, + 0x4e, + 0xbc, + 0x23, + 0x51, + 0xa1, + 0x96, + 0xd2, + 0x03, + 0x98, + 0x73, + 0xb6, + 0x17, + 0x9c, + 0x77, + 0xd4, + 0x95, + 0x1e, + 0x1b, + 0xb3, + 0x1b, + 0xc8, + 0x71, + 0xd1, + 0x2e, + 0x31, + 0xc7, + 0x6a, + 0x75, + 0x57, + 0x08, + 0x7f, + 0xba, + 0x70, + 0x76, + 0xf7, + 0x67, + 0xf4, + 0x4e, + 0xbe, + 0xfc, + 0x70, + 0x61, + 0x41, + 0x07, + 0x2b, + 0x7c, + 0x3c, + 0x3b, + 0xb3, + 0xbc, + 0xd5, + 0xa8, + 0xbd, + 0x28, + 0xd8, + 0x49, + 0xd3, + 0xe1, + 0x78, + 0xc8, + 0xc1, + 0x42, + 0x5e, + 0x18, + 0x36, + 0xa8, + 0x41, + 0xf7, + 0xc8, + 0xaa, + 0x35, + 0xfe, + 0x2d, + 0xd1, + 0xb4, + 0xcc, + 0x00, + 0x67, + 0xae, + 0x79, + 0xd3, + 0x28, + 0xd5, + 0x5b, + 0x02, + 0x03, + 0x01, + 0x00, + 0x01, + 0xa3, + 0x3b, + 0x30, + 0x39, + 0x30, + 0x1f, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x23, + 0x04, + 0x18, + 0x30, + 0x16, + 0x80, + 0x14, + 0xdb, + 0xbb, + 0xb8, + 0x92, + 0x4e, + 0x24, + 0x0b, + 0x1b, + 0xbb, + 0x78, + 0x33, + 0xf9, + 0x01, + 0x02, + 0x23, + 0x0d, + 0x96, + 0x18, + 0x30, + 0x47, + 0x30, + 0x09, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x13, + 0x04, + 0x02, + 0x30, + 0x00, + 0x30, + 0x0b, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x0f, + 0x04, + 0x04, + 0x03, + 0x02, + 0x04, + 0xf0, + 0x30, + 0x0d, + 0x06, + 0x09, + 0x2a, + 0x86, + 0x48, + 0x86, + 0xf7, + 0x0d, + 0x01, + 0x01, + 0x0b, + 0x05, + 0x00, + 0x03, + 0x81, + 0x81, + 0x00, + 0x3b, + 0xa6, + 0x73, + 0xbe, + 0xe0, + 0x28, + 0xed, + 0x1f, + 0x29, + 0x78, + 0x4c, + 0xc0, + 0x1f, + 0xe9, + 0x85, + 0xc6, + 0x8f, + 0xe3, + 0x87, + 0x7c, + 0xd9, + 0xe7, + 0x0a, + 0x37, + 0xe8, + 0xaa, + 0xb5, + 0xd2, + 0x7f, + 0xf8, + 0x90, + 0x20, + 0x80, + 0x35, + 0xa7, + 0x79, + 0x2b, + 0x04, + 0xa7, + 0xbf, + 0xe6, + 0x7b, + 0x58, + 0xcb, + 0xec, + 0x0e, + 0x58, + 0xef, + 0x2a, + 0x70, + 0x8a, + 0x56, + 0x8a, + 0xcf, + 0x6b, + 0x7a, + 0x74, + 0x0c, + 0xf4, + 0x15, + 0x37, + 0x93, + 0xcd, + 0xe6, + 0xb2, + 0xa1, + 0x83, + 0x09, + 0xdb, + 0x9e, + 0x4f, + 0xff, + 0x6a, + 0x17, + 0x4f, + 0x33, + 0xc9, + 0xcc, + 0x90, + 0x2a, + 0x67, + 0xff, + 0x16, + 0x78, + 0xa8, + 0x2c, + 0x10, + 0xe0, + 0x52, + 0x8c, + 0xe6, + 0xe9, + 0x90, + 0x8d, + 0xe0, + 0x62, + 0x04, + 0x9a, + 0x0f, + 0x44, + 0x01, + 0x82, + 0x14, + 0x92, + 0x44, + 0x25, + 0x69, + 0x22, + 0xb7, + 0xb8, + 0xc5, + 0x94, + 0x4c, + 0x4b, + 0x1c, + 0x9b, + 0x92, + 0x60, + 0x66, + 0x90, + 0x4e, + 0xb9, + 0xa8, + 0x4c, + 0x89, + 0xbb, + 0x0f, + 0x0b, }; static const unsigned char KEY1[] = { - 0x30, 0x82, 0x02, 0x5d, 0x02, 0x01, 0x00, 0x02, 0x81, 0x81, - 0x00, 0xbc, 0xdc, 0x6f, 0x8c, 0x7a, 0x2a, 0x4b, 0xea, 0x66, - 0x66, 0x04, 0xa9, 0x05, 0x92, 0x53, 0xd7, 0x13, 0x3c, 0x49, - 0xe1, 0xc8, 0xbb, 0xdf, 0x3d, 0xcb, 0x88, 0x31, 0x07, 0x20, - 0x59, 0x93, 0x24, 0x7f, 0x7d, 0xc6, 0x84, 0x81, 0x16, 0x64, - 0x4a, 0x52, 0xa6, 0x30, 0x44, 0xdc, 0x1a, 0x30, 0xde, 0xae, - 0x29, 0x18, 0xcf, 0xc7, 0xf3, 0xcf, 0x0c, 0xb7, 0x8e, 0x2b, - 0x1e, 0x21, 0x01, 0x0b, 0xfb, 0xe5, 0xe6, 0xcf, 0x2b, 0x84, - 0xe1, 0x33, 0xf8, 0xba, 0x02, 0xfc, 0x30, 0xfa, 0xc4, 0x33, - 0xc7, 0x37, 0xc6, 0x7f, 0x72, 0x31, 0x92, 0x1d, 0x8f, 0xa0, - 0xfb, 0xe5, 0x4a, 0x08, 0x31, 0x78, 0x80, 0x9c, 0x23, 0xb4, - 0xe9, 0x19, 0x56, 0x04, 0xfa, 0x0d, 0x07, 0x04, 0xb7, 0x43, - 0xac, 0x4c, 0x49, 0x7c, 0xc2, 0xa1, 0x44, 0xc1, 0x48, 0x7d, - 0x28, 0xe5, 0x23, 0x66, 0x07, 0x22, 0xd5, 0xf0, 0xf1, 0x02, - 0x03, 0x01, 0x00, 0x01, 0x02, 0x81, 0x81, 0x00, 0xa5, 0x6d, - 0xf9, 0x8f, 0xf5, 0x5a, 0xa3, 0x50, 0xd9, 0x0d, 0x37, 0xbb, - 0xce, 0x13, 0x94, 0xb8, 0xea, 0x32, 0x7f, 0x0c, 0xf5, 0x46, - 0x0b, 0x90, 0x17, 0x7e, 0x5e, 0x63, 0xbd, 0xa4, 0x78, 0xcd, - 0x19, 0x97, 0xd4, 0x92, 0x30, 0x78, 0xaa, 0xb4, 0xa7, 0x9c, - 0xc6, 0xdf, 0x2a, 0x65, 0x0e, 0xb5, 0x9f, 0x9c, 0x84, 0x0d, - 0x4d, 0x3a, 0x74, 0xfc, 0xd0, 0xb4, 0x09, 0x74, 0xc4, 0xb8, - 0x24, 0x03, 0xa8, 0xf0, 0xf8, 0x0d, 0x5c, 0x8e, 0xdf, 0x4b, - 0xe1, 0x0a, 0x8f, 0x4f, 0xd5, 0xc7, 0x9b, 0x54, 0x55, 0x8f, - 0x00, 0x5c, 0xea, 0x4c, 0x73, 0xf9, 0x1b, 0xbf, 0xb8, 0x93, - 0x33, 0x20, 0xce, 0x45, 0xd9, 0x03, 0x02, 0xb2, 0x36, 0xc5, - 0x0a, 0x30, 0x50, 0x78, 0x80, 0x66, 0x00, 0x22, 0x38, 0x86, - 0xcf, 0x63, 0x4a, 0x5c, 0xbf, 0x2b, 0xd9, 0x6e, 0xe6, 0xf0, - 0x39, 0xad, 0x12, 0x25, 0x41, 0xb9, 0x02, 0x41, 0x00, 0xf3, - 0x7c, 0x07, 0x99, 0x64, 0x3a, 0x28, 0x8c, 0x8d, 0x05, 0xfe, - 0x32, 0xb5, 0x4c, 0x8c, 0x6d, 0xde, 0x3d, 0x16, 0x08, 0xa0, - 0x01, 0x61, 0x4f, 0x8e, 0xa0, 0xf7, 0x26, 0x26, 0xb5, 0x8e, - 0xc0, 0x7a, 0xce, 0x86, 0x34, 0xde, 0xb8, 0xef, 0x86, 0x01, - 0xbe, 0x24, 0xaa, 0x9b, 0x36, 0x93, 0x72, 0x9b, 0xf9, 0xc6, - 0xcb, 0x76, 0x84, 0x67, 0x06, 0x06, 0x30, 0x50, 0xdf, 0x42, - 0x17, 0xe0, 0xa7, 0x02, 0x41, 0x00, 0xc6, 0x91, 0xa0, 0x41, - 0x34, 0x11, 0x67, 0x4b, 0x08, 0x0f, 0xda, 0xa7, 0x99, 0xec, - 0x58, 0x11, 0xa5, 0x82, 0xdb, 0x50, 0xfe, 0x77, 0xe2, 0xd1, - 0x53, 0x9c, 0x7d, 0xe8, 0xbf, 0xe7, 0x7c, 0xa9, 0x01, 0xb1, - 0x87, 0xc3, 0x52, 0x79, 0x9e, 0x2c, 0xa7, 0x6f, 0x02, 0x37, - 0x32, 0xef, 0x24, 0x31, 0x21, 0x0b, 0x86, 0x05, 0x32, 0x4a, - 0x2e, 0x0b, 0x65, 0x05, 0xd3, 0xd6, 0x30, 0xb2, 0xfc, 0xa7, - 0x02, 0x41, 0x00, 0xc2, 0xed, 0x31, 0xdc, 0x40, 0x9c, 0x3a, - 0xe8, 0x42, 0xe2, 0x60, 0x5e, 0x52, 0x3c, 0xc5, 0x54, 0x14, - 0x0e, 0x8d, 0x7c, 0x3c, 0x34, 0xbe, 0xa6, 0x05, 0x86, 0xa2, - 0x36, 0x5d, 0xd9, 0x0e, 0x3e, 0xd4, 0x52, 0x50, 0xa9, 0x35, - 0x01, 0x93, 0x68, 0x92, 0x2e, 0x9a, 0x86, 0x27, 0x1a, 0xab, - 0x32, 0x9e, 0xe2, 0x79, 0x9f, 0x5b, 0xf3, 0xa5, 0xd2, 0xf1, - 0xd3, 0x6e, 0x7b, 0x3e, 0x1b, 0x85, 0x93, 0x02, 0x40, 0x68, - 0xb8, 0xb6, 0x7e, 0x8c, 0xba, 0x3c, 0xf2, 0x8a, 0x2e, 0xea, - 0x4f, 0x07, 0xd3, 0x68, 0x62, 0xee, 0x1a, 0x04, 0x16, 0x44, - 0x0d, 0xef, 0xf6, 0x1b, 0x95, 0x65, 0xa5, 0xd1, 0x47, 0x81, - 0x2c, 0x14, 0xb3, 0x8e, 0xf9, 0x08, 0xcf, 0x11, 0x07, 0x55, - 0xca, 0x2a, 0xad, 0xf7, 0xd3, 0xbd, 0x0f, 0x97, 0xf0, 0xde, - 0xde, 0x70, 0xb6, 0x44, 0x70, 0x47, 0xf7, 0xf9, 0xcf, 0x75, - 0x61, 0x7f, 0xf3, 0x02, 0x40, 0x38, 0x4a, 0x67, 0xaf, 0xae, - 0xb6, 0xb2, 0x6a, 0x00, 0x25, 0x5a, 0xa4, 0x65, 0x20, 0xb1, - 0x13, 0xbd, 0x83, 0xff, 0xb4, 0xbc, 0xf4, 0xdd, 0xa1, 0xbb, - 0x1c, 0x96, 0x37, 0x35, 0xf4, 0xbf, 0xed, 0x4c, 0xed, 0x92, - 0xe8, 0xac, 0xc9, 0xc1, 0xa5, 0xa3, 0x23, 0x66, 0x40, 0x8a, - 0xa1, 0xe6, 0xe3, 0x95, 0xfe, 0xc4, 0x53, 0xf5, 0x7d, 0x6e, - 0xca, 0x45, 0x42, 0xe4, 0xc2, 0x9f, 0xe5, 0x1e, 0xb5 + 0x30, + 0x82, + 0x02, + 0x5d, + 0x02, + 0x01, + 0x00, + 0x02, + 0x81, + 0x81, + 0x00, + 0xbc, + 0xdc, + 0x6f, + 0x8c, + 0x7a, + 0x2a, + 0x4b, + 0xea, + 0x66, + 0x66, + 0x04, + 0xa9, + 0x05, + 0x92, + 0x53, + 0xd7, + 0x13, + 0x3c, + 0x49, + 0xe1, + 0xc8, + 0xbb, + 0xdf, + 0x3d, + 0xcb, + 0x88, + 0x31, + 0x07, + 0x20, + 0x59, + 0x93, + 0x24, + 0x7f, + 0x7d, + 0xc6, + 0x84, + 0x81, + 0x16, + 0x64, + 0x4a, + 0x52, + 0xa6, + 0x30, + 0x44, + 0xdc, + 0x1a, + 0x30, + 0xde, + 0xae, + 0x29, + 0x18, + 0xcf, + 0xc7, + 0xf3, + 0xcf, + 0x0c, + 0xb7, + 0x8e, + 0x2b, + 0x1e, + 0x21, + 0x01, + 0x0b, + 0xfb, + 0xe5, + 0xe6, + 0xcf, + 0x2b, + 0x84, + 0xe1, + 0x33, + 0xf8, + 0xba, + 0x02, + 0xfc, + 0x30, + 0xfa, + 0xc4, + 0x33, + 0xc7, + 0x37, + 0xc6, + 0x7f, + 0x72, + 0x31, + 0x92, + 0x1d, + 0x8f, + 0xa0, + 0xfb, + 0xe5, + 0x4a, + 0x08, + 0x31, + 0x78, + 0x80, + 0x9c, + 0x23, + 0xb4, + 0xe9, + 0x19, + 0x56, + 0x04, + 0xfa, + 0x0d, + 0x07, + 0x04, + 0xb7, + 0x43, + 0xac, + 0x4c, + 0x49, + 0x7c, + 0xc2, + 0xa1, + 0x44, + 0xc1, + 0x48, + 0x7d, + 0x28, + 0xe5, + 0x23, + 0x66, + 0x07, + 0x22, + 0xd5, + 0xf0, + 0xf1, + 0x02, + 0x03, + 0x01, + 0x00, + 0x01, + 0x02, + 0x81, + 0x81, + 0x00, + 0xa5, + 0x6d, + 0xf9, + 0x8f, + 0xf5, + 0x5a, + 0xa3, + 0x50, + 0xd9, + 0x0d, + 0x37, + 0xbb, + 0xce, + 0x13, + 0x94, + 0xb8, + 0xea, + 0x32, + 0x7f, + 0x0c, + 0xf5, + 0x46, + 0x0b, + 0x90, + 0x17, + 0x7e, + 0x5e, + 0x63, + 0xbd, + 0xa4, + 0x78, + 0xcd, + 0x19, + 0x97, + 0xd4, + 0x92, + 0x30, + 0x78, + 0xaa, + 0xb4, + 0xa7, + 0x9c, + 0xc6, + 0xdf, + 0x2a, + 0x65, + 0x0e, + 0xb5, + 0x9f, + 0x9c, + 0x84, + 0x0d, + 0x4d, + 0x3a, + 0x74, + 0xfc, + 0xd0, + 0xb4, + 0x09, + 0x74, + 0xc4, + 0xb8, + 0x24, + 0x03, + 0xa8, + 0xf0, + 0xf8, + 0x0d, + 0x5c, + 0x8e, + 0xdf, + 0x4b, + 0xe1, + 0x0a, + 0x8f, + 0x4f, + 0xd5, + 0xc7, + 0x9b, + 0x54, + 0x55, + 0x8f, + 0x00, + 0x5c, + 0xea, + 0x4c, + 0x73, + 0xf9, + 0x1b, + 0xbf, + 0xb8, + 0x93, + 0x33, + 0x20, + 0xce, + 0x45, + 0xd9, + 0x03, + 0x02, + 0xb2, + 0x36, + 0xc5, + 0x0a, + 0x30, + 0x50, + 0x78, + 0x80, + 0x66, + 0x00, + 0x22, + 0x38, + 0x86, + 0xcf, + 0x63, + 0x4a, + 0x5c, + 0xbf, + 0x2b, + 0xd9, + 0x6e, + 0xe6, + 0xf0, + 0x39, + 0xad, + 0x12, + 0x25, + 0x41, + 0xb9, + 0x02, + 0x41, + 0x00, + 0xf3, + 0x7c, + 0x07, + 0x99, + 0x64, + 0x3a, + 0x28, + 0x8c, + 0x8d, + 0x05, + 0xfe, + 0x32, + 0xb5, + 0x4c, + 0x8c, + 0x6d, + 0xde, + 0x3d, + 0x16, + 0x08, + 0xa0, + 0x01, + 0x61, + 0x4f, + 0x8e, + 0xa0, + 0xf7, + 0x26, + 0x26, + 0xb5, + 0x8e, + 0xc0, + 0x7a, + 0xce, + 0x86, + 0x34, + 0xde, + 0xb8, + 0xef, + 0x86, + 0x01, + 0xbe, + 0x24, + 0xaa, + 0x9b, + 0x36, + 0x93, + 0x72, + 0x9b, + 0xf9, + 0xc6, + 0xcb, + 0x76, + 0x84, + 0x67, + 0x06, + 0x06, + 0x30, + 0x50, + 0xdf, + 0x42, + 0x17, + 0xe0, + 0xa7, + 0x02, + 0x41, + 0x00, + 0xc6, + 0x91, + 0xa0, + 0x41, + 0x34, + 0x11, + 0x67, + 0x4b, + 0x08, + 0x0f, + 0xda, + 0xa7, + 0x99, + 0xec, + 0x58, + 0x11, + 0xa5, + 0x82, + 0xdb, + 0x50, + 0xfe, + 0x77, + 0xe2, + 0xd1, + 0x53, + 0x9c, + 0x7d, + 0xe8, + 0xbf, + 0xe7, + 0x7c, + 0xa9, + 0x01, + 0xb1, + 0x87, + 0xc3, + 0x52, + 0x79, + 0x9e, + 0x2c, + 0xa7, + 0x6f, + 0x02, + 0x37, + 0x32, + 0xef, + 0x24, + 0x31, + 0x21, + 0x0b, + 0x86, + 0x05, + 0x32, + 0x4a, + 0x2e, + 0x0b, + 0x65, + 0x05, + 0xd3, + 0xd6, + 0x30, + 0xb2, + 0xfc, + 0xa7, + 0x02, + 0x41, + 0x00, + 0xc2, + 0xed, + 0x31, + 0xdc, + 0x40, + 0x9c, + 0x3a, + 0xe8, + 0x42, + 0xe2, + 0x60, + 0x5e, + 0x52, + 0x3c, + 0xc5, + 0x54, + 0x14, + 0x0e, + 0x8d, + 0x7c, + 0x3c, + 0x34, + 0xbe, + 0xa6, + 0x05, + 0x86, + 0xa2, + 0x36, + 0x5d, + 0xd9, + 0x0e, + 0x3e, + 0xd4, + 0x52, + 0x50, + 0xa9, + 0x35, + 0x01, + 0x93, + 0x68, + 0x92, + 0x2e, + 0x9a, + 0x86, + 0x27, + 0x1a, + 0xab, + 0x32, + 0x9e, + 0xe2, + 0x79, + 0x9f, + 0x5b, + 0xf3, + 0xa5, + 0xd2, + 0xf1, + 0xd3, + 0x6e, + 0x7b, + 0x3e, + 0x1b, + 0x85, + 0x93, + 0x02, + 0x40, + 0x68, + 0xb8, + 0xb6, + 0x7e, + 0x8c, + 0xba, + 0x3c, + 0xf2, + 0x8a, + 0x2e, + 0xea, + 0x4f, + 0x07, + 0xd3, + 0x68, + 0x62, + 0xee, + 0x1a, + 0x04, + 0x16, + 0x44, + 0x0d, + 0xef, + 0xf6, + 0x1b, + 0x95, + 0x65, + 0xa5, + 0xd1, + 0x47, + 0x81, + 0x2c, + 0x14, + 0xb3, + 0x8e, + 0xf9, + 0x08, + 0xcf, + 0x11, + 0x07, + 0x55, + 0xca, + 0x2a, + 0xad, + 0xf7, + 0xd3, + 0xbd, + 0x0f, + 0x97, + 0xf0, + 0xde, + 0xde, + 0x70, + 0xb6, + 0x44, + 0x70, + 0x47, + 0xf7, + 0xf9, + 0xcf, + 0x75, + 0x61, + 0x7f, + 0xf3, + 0x02, + 0x40, + 0x38, + 0x4a, + 0x67, + 0xaf, + 0xae, + 0xb6, + 0xb2, + 0x6a, + 0x00, + 0x25, + 0x5a, + 0xa4, + 0x65, + 0x20, + 0xb1, + 0x13, + 0xbd, + 0x83, + 0xff, + 0xb4, + 0xbc, + 0xf4, + 0xdd, + 0xa1, + 0xbb, + 0x1c, + 0x96, + 0x37, + 0x35, + 0xf4, + 0xbf, + 0xed, + 0x4c, + 0xed, + 0x92, + 0xe8, + 0xac, + 0xc9, + 0xc1, + 0xa5, + 0xa3, + 0x23, + 0x66, + 0x40, + 0x8a, + 0xa1, + 0xe6, + 0xe3, + 0x95, + 0xfe, + 0xc4, + 0x53, + 0xf5, + 0x7d, + 0x6e, + 0xca, + 0x45, + 0x42, + 0xe4, + 0xc2, + 0x9f, + 0xe5, + 0x1e, + 0xb5, }; static const unsigned char KEY2[] = { - 0x30, 0x82, 0x02, 0x5c, 0x02, 0x01, 0x00, 0x02, 0x81, 0x81, - 0x00, 0xa8, 0x6e, 0x40, 0x86, 0x9f, 0x98, 0x59, 0xfb, 0x57, - 0xbf, 0xc1, 0x55, 0x12, 0x38, 0xeb, 0xb3, 0x46, 0x34, 0xc9, - 0x35, 0x4d, 0xfd, 0x03, 0xe9, 0x3a, 0x88, 0x9e, 0x97, 0x8f, - 0xf4, 0xec, 0x36, 0x7b, 0x3f, 0xba, 0xb8, 0xa5, 0x96, 0x30, - 0x03, 0xc5, 0xc6, 0xd9, 0xa8, 0x4e, 0xbc, 0x23, 0x51, 0xa1, - 0x96, 0xd2, 0x03, 0x98, 0x73, 0xb6, 0x17, 0x9c, 0x77, 0xd4, - 0x95, 0x1e, 0x1b, 0xb3, 0x1b, 0xc8, 0x71, 0xd1, 0x2e, 0x31, - 0xc7, 0x6a, 0x75, 0x57, 0x08, 0x7f, 0xba, 0x70, 0x76, 0xf7, - 0x67, 0xf4, 0x4e, 0xbe, 0xfc, 0x70, 0x61, 0x41, 0x07, 0x2b, - 0x7c, 0x3c, 0x3b, 0xb3, 0xbc, 0xd5, 0xa8, 0xbd, 0x28, 0xd8, - 0x49, 0xd3, 0xe1, 0x78, 0xc8, 0xc1, 0x42, 0x5e, 0x18, 0x36, - 0xa8, 0x41, 0xf7, 0xc8, 0xaa, 0x35, 0xfe, 0x2d, 0xd1, 0xb4, - 0xcc, 0x00, 0x67, 0xae, 0x79, 0xd3, 0x28, 0xd5, 0x5b, 0x02, - 0x03, 0x01, 0x00, 0x01, 0x02, 0x81, 0x81, 0x00, 0xa6, 0x00, - 0x83, 0xf8, 0x2b, 0x33, 0xac, 0xfb, 0xdb, 0xf0, 0x52, 0x4b, - 0xd6, 0x39, 0xe3, 0x94, 0x3d, 0x8d, 0xa9, 0x01, 0xb0, 0x6b, - 0xbe, 0x7f, 0x10, 0x01, 0xb6, 0xcd, 0x0a, 0x45, 0x0a, 0xca, - 0x67, 0x8e, 0xd8, 0x29, 0x44, 0x8a, 0x51, 0xa8, 0x66, 0x35, - 0x26, 0x30, 0x8b, 0xe9, 0x41, 0xa6, 0x22, 0xec, 0xd2, 0xf0, - 0x58, 0x41, 0x33, 0x26, 0xf2, 0x3f, 0xe8, 0x75, 0x4f, 0xc7, - 0x5d, 0x2e, 0x5a, 0xa8, 0x7a, 0xd2, 0xbf, 0x59, 0xa0, 0x86, - 0x79, 0x0b, 0x92, 0x6c, 0x95, 0x5d, 0x87, 0x63, 0x5c, 0xd6, - 0x1a, 0xc0, 0xf6, 0x7a, 0x15, 0x8d, 0xc7, 0x3c, 0xb6, 0x9e, - 0xa6, 0x58, 0x46, 0x9b, 0xbf, 0x3e, 0x28, 0x8c, 0xdf, 0x1a, - 0x87, 0xaa, 0x7e, 0xf5, 0xf2, 0xcb, 0x5e, 0x84, 0x2d, 0xf6, - 0x82, 0x7e, 0x89, 0x4e, 0xf5, 0xe6, 0x3c, 0x92, 0x80, 0x1e, - 0x98, 0x1c, 0x6a, 0x7b, 0x57, 0x01, 0x02, 0x41, 0x00, 0xdd, - 0x60, 0x95, 0xd7, 0xa1, 0x9d, 0x0c, 0xa1, 0x84, 0xc5, 0x39, - 0xca, 0x67, 0x4c, 0x1c, 0x06, 0x71, 0x5b, 0x5c, 0x2d, 0x8d, - 0xce, 0xcd, 0xe2, 0x79, 0xc8, 0x33, 0xbe, 0x50, 0x37, 0x60, - 0x9f, 0x3b, 0xb9, 0x59, 0x55, 0x22, 0x1f, 0xa5, 0x4b, 0x1d, - 0xca, 0x38, 0xa0, 0xab, 0x87, 0x9c, 0x86, 0x0e, 0xdb, 0x1c, - 0x4f, 0x4f, 0x07, 0xed, 0x18, 0x3f, 0x05, 0x3c, 0xec, 0x78, - 0x11, 0xf6, 0x99, 0x02, 0x41, 0x00, 0xc2, 0xc5, 0xcf, 0xbe, - 0x95, 0x91, 0xeb, 0xcf, 0x47, 0xf3, 0x33, 0x32, 0xc7, 0x7e, - 0x93, 0x56, 0xf7, 0xd8, 0xf9, 0xd4, 0xb6, 0xd6, 0x20, 0xac, - 0xba, 0x8a, 0x20, 0x19, 0x14, 0xab, 0xc5, 0x5d, 0xb2, 0x08, - 0xcc, 0x77, 0x7c, 0x65, 0xa8, 0xdb, 0x66, 0x97, 0x36, 0x44, - 0x2c, 0x63, 0xc0, 0x6a, 0x7e, 0xb0, 0x0b, 0x5c, 0x90, 0x12, - 0x50, 0xb4, 0x36, 0x60, 0xc3, 0x1f, 0x22, 0x0c, 0xc8, 0x13, - 0x02, 0x40, 0x33, 0xc8, 0x7e, 0x04, 0x7c, 0x97, 0x61, 0xf6, - 0xfe, 0x39, 0xac, 0x34, 0xfe, 0x48, 0xbd, 0x5d, 0x7c, 0x72, - 0xa4, 0x73, 0x3b, 0x72, 0x9e, 0x92, 0x55, 0x6e, 0x51, 0x3c, - 0x39, 0x43, 0x5a, 0xe4, 0xa4, 0x71, 0xcc, 0xc5, 0xaf, 0x3f, - 0xbb, 0xc8, 0x80, 0x65, 0x67, 0x2d, 0x9e, 0x32, 0x10, 0x99, - 0x03, 0x2c, 0x99, 0xc8, 0xab, 0x71, 0xed, 0x31, 0xf8, 0xbb, - 0xde, 0xee, 0x69, 0x7f, 0xba, 0x31, 0x02, 0x40, 0x7e, 0xbc, - 0x60, 0x55, 0x4e, 0xd5, 0xc8, 0x6e, 0xf4, 0x0e, 0x57, 0xbe, - 0x2e, 0xf9, 0x39, 0xbe, 0x59, 0x3f, 0xa2, 0x30, 0xbb, 0x57, - 0xd1, 0xa3, 0x13, 0x2e, 0x55, 0x7c, 0x7c, 0x6a, 0xd8, 0xde, - 0x02, 0xbe, 0x9e, 0xed, 0x10, 0xd0, 0xc5, 0x73, 0x1d, 0xea, - 0x3e, 0xb1, 0x55, 0x81, 0x02, 0xef, 0x48, 0xc8, 0x1c, 0x5c, - 0x7a, 0x92, 0xb0, 0x58, 0xd3, 0x19, 0x5b, 0x5d, 0xa2, 0xb6, - 0x56, 0x69, 0x02, 0x40, 0x1e, 0x00, 0x6a, 0x9f, 0xba, 0xee, - 0x46, 0x5a, 0xc5, 0xb5, 0x9f, 0x91, 0x33, 0xdd, 0xc9, 0x96, - 0x75, 0xb7, 0x87, 0xcf, 0x18, 0x1c, 0xb7, 0xb9, 0x3f, 0x04, - 0x10, 0xb8, 0x75, 0xa9, 0xb8, 0xa0, 0x31, 0x35, 0x03, 0x30, - 0x89, 0xc8, 0x37, 0x68, 0x20, 0x30, 0x99, 0x39, 0x96, 0xd6, - 0x2b, 0x3d, 0x5e, 0x45, 0x84, 0xf7, 0xd2, 0x61, 0x50, 0xc9, - 0x50, 0xba, 0x8d, 0x08, 0xaa, 0xd0, 0x08, 0x1e + 0x30, + 0x82, + 0x02, + 0x5c, + 0x02, + 0x01, + 0x00, + 0x02, + 0x81, + 0x81, + 0x00, + 0xa8, + 0x6e, + 0x40, + 0x86, + 0x9f, + 0x98, + 0x59, + 0xfb, + 0x57, + 0xbf, + 0xc1, + 0x55, + 0x12, + 0x38, + 0xeb, + 0xb3, + 0x46, + 0x34, + 0xc9, + 0x35, + 0x4d, + 0xfd, + 0x03, + 0xe9, + 0x3a, + 0x88, + 0x9e, + 0x97, + 0x8f, + 0xf4, + 0xec, + 0x36, + 0x7b, + 0x3f, + 0xba, + 0xb8, + 0xa5, + 0x96, + 0x30, + 0x03, + 0xc5, + 0xc6, + 0xd9, + 0xa8, + 0x4e, + 0xbc, + 0x23, + 0x51, + 0xa1, + 0x96, + 0xd2, + 0x03, + 0x98, + 0x73, + 0xb6, + 0x17, + 0x9c, + 0x77, + 0xd4, + 0x95, + 0x1e, + 0x1b, + 0xb3, + 0x1b, + 0xc8, + 0x71, + 0xd1, + 0x2e, + 0x31, + 0xc7, + 0x6a, + 0x75, + 0x57, + 0x08, + 0x7f, + 0xba, + 0x70, + 0x76, + 0xf7, + 0x67, + 0xf4, + 0x4e, + 0xbe, + 0xfc, + 0x70, + 0x61, + 0x41, + 0x07, + 0x2b, + 0x7c, + 0x3c, + 0x3b, + 0xb3, + 0xbc, + 0xd5, + 0xa8, + 0xbd, + 0x28, + 0xd8, + 0x49, + 0xd3, + 0xe1, + 0x78, + 0xc8, + 0xc1, + 0x42, + 0x5e, + 0x18, + 0x36, + 0xa8, + 0x41, + 0xf7, + 0xc8, + 0xaa, + 0x35, + 0xfe, + 0x2d, + 0xd1, + 0xb4, + 0xcc, + 0x00, + 0x67, + 0xae, + 0x79, + 0xd3, + 0x28, + 0xd5, + 0x5b, + 0x02, + 0x03, + 0x01, + 0x00, + 0x01, + 0x02, + 0x81, + 0x81, + 0x00, + 0xa6, + 0x00, + 0x83, + 0xf8, + 0x2b, + 0x33, + 0xac, + 0xfb, + 0xdb, + 0xf0, + 0x52, + 0x4b, + 0xd6, + 0x39, + 0xe3, + 0x94, + 0x3d, + 0x8d, + 0xa9, + 0x01, + 0xb0, + 0x6b, + 0xbe, + 0x7f, + 0x10, + 0x01, + 0xb6, + 0xcd, + 0x0a, + 0x45, + 0x0a, + 0xca, + 0x67, + 0x8e, + 0xd8, + 0x29, + 0x44, + 0x8a, + 0x51, + 0xa8, + 0x66, + 0x35, + 0x26, + 0x30, + 0x8b, + 0xe9, + 0x41, + 0xa6, + 0x22, + 0xec, + 0xd2, + 0xf0, + 0x58, + 0x41, + 0x33, + 0x26, + 0xf2, + 0x3f, + 0xe8, + 0x75, + 0x4f, + 0xc7, + 0x5d, + 0x2e, + 0x5a, + 0xa8, + 0x7a, + 0xd2, + 0xbf, + 0x59, + 0xa0, + 0x86, + 0x79, + 0x0b, + 0x92, + 0x6c, + 0x95, + 0x5d, + 0x87, + 0x63, + 0x5c, + 0xd6, + 0x1a, + 0xc0, + 0xf6, + 0x7a, + 0x15, + 0x8d, + 0xc7, + 0x3c, + 0xb6, + 0x9e, + 0xa6, + 0x58, + 0x46, + 0x9b, + 0xbf, + 0x3e, + 0x28, + 0x8c, + 0xdf, + 0x1a, + 0x87, + 0xaa, + 0x7e, + 0xf5, + 0xf2, + 0xcb, + 0x5e, + 0x84, + 0x2d, + 0xf6, + 0x82, + 0x7e, + 0x89, + 0x4e, + 0xf5, + 0xe6, + 0x3c, + 0x92, + 0x80, + 0x1e, + 0x98, + 0x1c, + 0x6a, + 0x7b, + 0x57, + 0x01, + 0x02, + 0x41, + 0x00, + 0xdd, + 0x60, + 0x95, + 0xd7, + 0xa1, + 0x9d, + 0x0c, + 0xa1, + 0x84, + 0xc5, + 0x39, + 0xca, + 0x67, + 0x4c, + 0x1c, + 0x06, + 0x71, + 0x5b, + 0x5c, + 0x2d, + 0x8d, + 0xce, + 0xcd, + 0xe2, + 0x79, + 0xc8, + 0x33, + 0xbe, + 0x50, + 0x37, + 0x60, + 0x9f, + 0x3b, + 0xb9, + 0x59, + 0x55, + 0x22, + 0x1f, + 0xa5, + 0x4b, + 0x1d, + 0xca, + 0x38, + 0xa0, + 0xab, + 0x87, + 0x9c, + 0x86, + 0x0e, + 0xdb, + 0x1c, + 0x4f, + 0x4f, + 0x07, + 0xed, + 0x18, + 0x3f, + 0x05, + 0x3c, + 0xec, + 0x78, + 0x11, + 0xf6, + 0x99, + 0x02, + 0x41, + 0x00, + 0xc2, + 0xc5, + 0xcf, + 0xbe, + 0x95, + 0x91, + 0xeb, + 0xcf, + 0x47, + 0xf3, + 0x33, + 0x32, + 0xc7, + 0x7e, + 0x93, + 0x56, + 0xf7, + 0xd8, + 0xf9, + 0xd4, + 0xb6, + 0xd6, + 0x20, + 0xac, + 0xba, + 0x8a, + 0x20, + 0x19, + 0x14, + 0xab, + 0xc5, + 0x5d, + 0xb2, + 0x08, + 0xcc, + 0x77, + 0x7c, + 0x65, + 0xa8, + 0xdb, + 0x66, + 0x97, + 0x36, + 0x44, + 0x2c, + 0x63, + 0xc0, + 0x6a, + 0x7e, + 0xb0, + 0x0b, + 0x5c, + 0x90, + 0x12, + 0x50, + 0xb4, + 0x36, + 0x60, + 0xc3, + 0x1f, + 0x22, + 0x0c, + 0xc8, + 0x13, + 0x02, + 0x40, + 0x33, + 0xc8, + 0x7e, + 0x04, + 0x7c, + 0x97, + 0x61, + 0xf6, + 0xfe, + 0x39, + 0xac, + 0x34, + 0xfe, + 0x48, + 0xbd, + 0x5d, + 0x7c, + 0x72, + 0xa4, + 0x73, + 0x3b, + 0x72, + 0x9e, + 0x92, + 0x55, + 0x6e, + 0x51, + 0x3c, + 0x39, + 0x43, + 0x5a, + 0xe4, + 0xa4, + 0x71, + 0xcc, + 0xc5, + 0xaf, + 0x3f, + 0xbb, + 0xc8, + 0x80, + 0x65, + 0x67, + 0x2d, + 0x9e, + 0x32, + 0x10, + 0x99, + 0x03, + 0x2c, + 0x99, + 0xc8, + 0xab, + 0x71, + 0xed, + 0x31, + 0xf8, + 0xbb, + 0xde, + 0xee, + 0x69, + 0x7f, + 0xba, + 0x31, + 0x02, + 0x40, + 0x7e, + 0xbc, + 0x60, + 0x55, + 0x4e, + 0xd5, + 0xc8, + 0x6e, + 0xf4, + 0x0e, + 0x57, + 0xbe, + 0x2e, + 0xf9, + 0x39, + 0xbe, + 0x59, + 0x3f, + 0xa2, + 0x30, + 0xbb, + 0x57, + 0xd1, + 0xa3, + 0x13, + 0x2e, + 0x55, + 0x7c, + 0x7c, + 0x6a, + 0xd8, + 0xde, + 0x02, + 0xbe, + 0x9e, + 0xed, + 0x10, + 0xd0, + 0xc5, + 0x73, + 0x1d, + 0xea, + 0x3e, + 0xb1, + 0x55, + 0x81, + 0x02, + 0xef, + 0x48, + 0xc8, + 0x1c, + 0x5c, + 0x7a, + 0x92, + 0xb0, + 0x58, + 0xd3, + 0x19, + 0x5b, + 0x5d, + 0xa2, + 0xb6, + 0x56, + 0x69, + 0x02, + 0x40, + 0x1e, + 0x00, + 0x6a, + 0x9f, + 0xba, + 0xee, + 0x46, + 0x5a, + 0xc5, + 0xb5, + 0x9f, + 0x91, + 0x33, + 0xdd, + 0xc9, + 0x96, + 0x75, + 0xb7, + 0x87, + 0xcf, + 0x18, + 0x1c, + 0xb7, + 0xb9, + 0x3f, + 0x04, + 0x10, + 0xb8, + 0x75, + 0xa9, + 0xb8, + 0xa0, + 0x31, + 0x35, + 0x03, + 0x30, + 0x89, + 0xc8, + 0x37, + 0x68, + 0x20, + 0x30, + 0x99, + 0x39, + 0x96, + 0xd6, + 0x2b, + 0x3d, + 0x5e, + 0x45, + 0x84, + 0xf7, + 0xd2, + 0x61, + 0x50, + 0xc9, + 0x50, + 0xba, + 0x8d, + 0x08, + 0xaa, + 0xd0, + 0x08, + 0x1e, }; static const PKCS12_ATTR ATTRS1[] = { @@ -884,67 +2873,615 @@ static int pkcs12_create_test(void) const unsigned char *p; static const unsigned char rsa_key[] = { - 0x30, 0x82, 0x02, 0x5d, 0x02, 0x01, 0x00, 0x02, 0x81, 0x81, - 0x00, 0xbb, 0x24, 0x7a, 0x09, 0x7e, 0x0e, 0xb2, 0x37, 0x32, - 0xcc, 0x39, 0x67, 0xad, 0xf1, 0x9e, 0x3d, 0x6b, 0x82, 0x83, - 0xd1, 0xd0, 0xac, 0xa4, 0xc0, 0x18, 0xbe, 0x8d, 0x98, 0x00, - 0xc0, 0x7b, 0xff, 0x07, 0x44, 0xc9, 0xca, 0x1c, 0xba, 0x36, - 0xe1, 0x27, 0x69, 0xff, 0xb1, 0xe3, 0x8d, 0x8b, 0xee, 0x57, - 0xa9, 0x3a, 0xaa, 0x16, 0x43, 0x39, 0x54, 0x19, 0x7c, 0xae, - 0x69, 0x24, 0x14, 0xf6, 0x64, 0xff, 0xbc, 0x74, 0xc6, 0x67, - 0x6c, 0x4c, 0xf1, 0x02, 0x49, 0x69, 0xc7, 0x2b, 0xe1, 0xe1, - 0xa1, 0xa3, 0x43, 0x14, 0xf4, 0x77, 0x8f, 0xc8, 0xd0, 0x85, - 0x5a, 0x35, 0x95, 0xac, 0x62, 0xa9, 0xc1, 0x21, 0x00, 0x77, - 0xa0, 0x8b, 0x97, 0x30, 0xb4, 0x5a, 0x2c, 0xb8, 0x90, 0x2f, - 0x48, 0xa0, 0x05, 0x28, 0x4b, 0xf2, 0x0f, 0x8d, 0xec, 0x8b, - 0x4d, 0x03, 0x42, 0x75, 0xd6, 0xad, 0x81, 0xc0, 0x11, 0x02, - 0x03, 0x01, 0x00, 0x01, 0x02, 0x81, 0x80, 0x00, 0xfc, 0xb9, - 0x4a, 0x26, 0x07, 0x89, 0x51, 0x2b, 0x53, 0x72, 0x91, 0xe0, - 0x18, 0x3e, 0xa6, 0x5e, 0x31, 0xef, 0x9c, 0x0c, 0x16, 0x24, - 0x42, 0xd0, 0x28, 0x33, 0xf9, 0xfa, 0xd0, 0x3c, 0x54, 0x04, - 0x06, 0xc0, 0x15, 0xf5, 0x1b, 0x9a, 0xb3, 0x24, 0x31, 0xab, - 0x3c, 0x6b, 0x47, 0x43, 0xb0, 0xd2, 0xa9, 0xdc, 0x05, 0xe1, - 0x81, 0x59, 0xb6, 0x04, 0xe9, 0x66, 0x61, 0xaa, 0xd7, 0x0b, - 0x00, 0x8f, 0x3d, 0xe5, 0xbf, 0xa2, 0xf8, 0x5e, 0x25, 0x6c, - 0x1e, 0x22, 0x0f, 0xb4, 0xfd, 0x41, 0xe2, 0x03, 0x31, 0x5f, - 0xda, 0x20, 0xc5, 0xc0, 0xf3, 0x55, 0x0e, 0xe1, 0xc9, 0xec, - 0xd7, 0x3e, 0x2a, 0x0c, 0x01, 0xca, 0x7b, 0x22, 0xcb, 0xac, - 0xf4, 0x2b, 0x27, 0xf0, 0x78, 0x5f, 0xb5, 0xc2, 0xf9, 0xe8, - 0x14, 0x5a, 0x6e, 0x7e, 0x86, 0xbd, 0x6a, 0x9b, 0x20, 0x0c, - 0xba, 0xcc, 0x97, 0x20, 0x11, 0x02, 0x41, 0x00, 0xc9, 0x59, - 0x9f, 0x29, 0x8a, 0x5b, 0x9f, 0xe3, 0x2a, 0xd8, 0x7e, 0xc2, - 0x40, 0x9f, 0xa8, 0x45, 0xe5, 0x3e, 0x11, 0x8d, 0x3c, 0xed, - 0x6e, 0xab, 0xce, 0xd0, 0x65, 0x46, 0xd8, 0xc7, 0x07, 0x63, - 0xb5, 0x23, 0x34, 0xf4, 0x9f, 0x7e, 0x1c, 0xc7, 0xc7, 0xf9, - 0x65, 0xd1, 0xf4, 0x04, 0x42, 0x38, 0xbe, 0x3a, 0x0c, 0x9d, - 0x08, 0x25, 0xfc, 0xa3, 0x71, 0xd9, 0xae, 0x0c, 0x39, 0x61, - 0xf4, 0x89, 0x02, 0x41, 0x00, 0xed, 0xef, 0xab, 0xa9, 0xd5, - 0x39, 0x9c, 0xee, 0x59, 0x1b, 0xff, 0xcf, 0x48, 0x44, 0x1b, - 0xb6, 0x32, 0xe7, 0x46, 0x24, 0xf3, 0x04, 0x7f, 0xde, 0x95, - 0x08, 0x6d, 0x75, 0x9e, 0x67, 0x17, 0xba, 0x5c, 0xa4, 0xd4, - 0xe2, 0xe2, 0x4d, 0x77, 0xce, 0xeb, 0x66, 0x29, 0xc5, 0x96, - 0xe0, 0x62, 0xbb, 0xe5, 0xac, 0xdc, 0x44, 0x62, 0x54, 0x86, - 0xed, 0x64, 0x0c, 0xce, 0xd0, 0x60, 0x03, 0x9d, 0x49, 0x02, - 0x40, 0x54, 0xd9, 0x18, 0x72, 0x27, 0xe4, 0xbe, 0x76, 0xbb, - 0x1a, 0x6a, 0x28, 0x2f, 0x95, 0x58, 0x12, 0xc4, 0x2c, 0xa8, - 0xb6, 0xcc, 0xe2, 0xfd, 0x0d, 0x17, 0x64, 0xc8, 0x18, 0xd7, - 0xc6, 0xdf, 0x3d, 0x4c, 0x1a, 0x9e, 0xf9, 0x2a, 0xb0, 0xb9, - 0x2e, 0x12, 0xfd, 0xec, 0xc3, 0x51, 0xc1, 0xed, 0xa9, 0xfd, - 0xb7, 0x76, 0x93, 0x41, 0xd8, 0xc8, 0x22, 0x94, 0x1a, 0x77, - 0xf6, 0x9c, 0xc3, 0xc3, 0x89, 0x02, 0x41, 0x00, 0x8e, 0xf9, - 0xa7, 0x08, 0xad, 0xb5, 0x2a, 0x04, 0xdb, 0x8d, 0x04, 0xa1, - 0xb5, 0x06, 0x20, 0x34, 0xd2, 0xcf, 0xc0, 0x89, 0xb1, 0x72, - 0x31, 0xb8, 0x39, 0x8b, 0xcf, 0xe2, 0x8e, 0xa5, 0xda, 0x4f, - 0x45, 0x1e, 0x53, 0x42, 0x66, 0xc4, 0x30, 0x4b, 0x29, 0x8e, - 0xc1, 0x69, 0x17, 0x29, 0x8c, 0x8a, 0xe6, 0x0f, 0x82, 0x68, - 0xa1, 0x41, 0xb3, 0xb6, 0x70, 0x99, 0x75, 0xa9, 0x27, 0x18, - 0xe4, 0xe9, 0x02, 0x41, 0x00, 0x89, 0xea, 0x6e, 0x6d, 0x70, - 0xdf, 0x25, 0x5f, 0x18, 0x3f, 0x48, 0xda, 0x63, 0x10, 0x8b, - 0xfe, 0xa8, 0x0c, 0x94, 0x0f, 0xde, 0x97, 0x56, 0x53, 0x89, - 0x94, 0xe2, 0x1e, 0x2c, 0x74, 0x3c, 0x91, 0x81, 0x34, 0x0b, - 0xa6, 0x40, 0xf8, 0xcb, 0x2a, 0x60, 0x8c, 0xe0, 0x02, 0xb7, - 0x89, 0x93, 0xcf, 0x18, 0x9f, 0x49, 0x54, 0xfd, 0x7d, 0x3f, - 0x9a, 0xef, 0xd4, 0xa4, 0x4f, 0xc1, 0x45, 0x99, 0x91 + 0x30, + 0x82, + 0x02, + 0x5d, + 0x02, + 0x01, + 0x00, + 0x02, + 0x81, + 0x81, + 0x00, + 0xbb, + 0x24, + 0x7a, + 0x09, + 0x7e, + 0x0e, + 0xb2, + 0x37, + 0x32, + 0xcc, + 0x39, + 0x67, + 0xad, + 0xf1, + 0x9e, + 0x3d, + 0x6b, + 0x82, + 0x83, + 0xd1, + 0xd0, + 0xac, + 0xa4, + 0xc0, + 0x18, + 0xbe, + 0x8d, + 0x98, + 0x00, + 0xc0, + 0x7b, + 0xff, + 0x07, + 0x44, + 0xc9, + 0xca, + 0x1c, + 0xba, + 0x36, + 0xe1, + 0x27, + 0x69, + 0xff, + 0xb1, + 0xe3, + 0x8d, + 0x8b, + 0xee, + 0x57, + 0xa9, + 0x3a, + 0xaa, + 0x16, + 0x43, + 0x39, + 0x54, + 0x19, + 0x7c, + 0xae, + 0x69, + 0x24, + 0x14, + 0xf6, + 0x64, + 0xff, + 0xbc, + 0x74, + 0xc6, + 0x67, + 0x6c, + 0x4c, + 0xf1, + 0x02, + 0x49, + 0x69, + 0xc7, + 0x2b, + 0xe1, + 0xe1, + 0xa1, + 0xa3, + 0x43, + 0x14, + 0xf4, + 0x77, + 0x8f, + 0xc8, + 0xd0, + 0x85, + 0x5a, + 0x35, + 0x95, + 0xac, + 0x62, + 0xa9, + 0xc1, + 0x21, + 0x00, + 0x77, + 0xa0, + 0x8b, + 0x97, + 0x30, + 0xb4, + 0x5a, + 0x2c, + 0xb8, + 0x90, + 0x2f, + 0x48, + 0xa0, + 0x05, + 0x28, + 0x4b, + 0xf2, + 0x0f, + 0x8d, + 0xec, + 0x8b, + 0x4d, + 0x03, + 0x42, + 0x75, + 0xd6, + 0xad, + 0x81, + 0xc0, + 0x11, + 0x02, + 0x03, + 0x01, + 0x00, + 0x01, + 0x02, + 0x81, + 0x80, + 0x00, + 0xfc, + 0xb9, + 0x4a, + 0x26, + 0x07, + 0x89, + 0x51, + 0x2b, + 0x53, + 0x72, + 0x91, + 0xe0, + 0x18, + 0x3e, + 0xa6, + 0x5e, + 0x31, + 0xef, + 0x9c, + 0x0c, + 0x16, + 0x24, + 0x42, + 0xd0, + 0x28, + 0x33, + 0xf9, + 0xfa, + 0xd0, + 0x3c, + 0x54, + 0x04, + 0x06, + 0xc0, + 0x15, + 0xf5, + 0x1b, + 0x9a, + 0xb3, + 0x24, + 0x31, + 0xab, + 0x3c, + 0x6b, + 0x47, + 0x43, + 0xb0, + 0xd2, + 0xa9, + 0xdc, + 0x05, + 0xe1, + 0x81, + 0x59, + 0xb6, + 0x04, + 0xe9, + 0x66, + 0x61, + 0xaa, + 0xd7, + 0x0b, + 0x00, + 0x8f, + 0x3d, + 0xe5, + 0xbf, + 0xa2, + 0xf8, + 0x5e, + 0x25, + 0x6c, + 0x1e, + 0x22, + 0x0f, + 0xb4, + 0xfd, + 0x41, + 0xe2, + 0x03, + 0x31, + 0x5f, + 0xda, + 0x20, + 0xc5, + 0xc0, + 0xf3, + 0x55, + 0x0e, + 0xe1, + 0xc9, + 0xec, + 0xd7, + 0x3e, + 0x2a, + 0x0c, + 0x01, + 0xca, + 0x7b, + 0x22, + 0xcb, + 0xac, + 0xf4, + 0x2b, + 0x27, + 0xf0, + 0x78, + 0x5f, + 0xb5, + 0xc2, + 0xf9, + 0xe8, + 0x14, + 0x5a, + 0x6e, + 0x7e, + 0x86, + 0xbd, + 0x6a, + 0x9b, + 0x20, + 0x0c, + 0xba, + 0xcc, + 0x97, + 0x20, + 0x11, + 0x02, + 0x41, + 0x00, + 0xc9, + 0x59, + 0x9f, + 0x29, + 0x8a, + 0x5b, + 0x9f, + 0xe3, + 0x2a, + 0xd8, + 0x7e, + 0xc2, + 0x40, + 0x9f, + 0xa8, + 0x45, + 0xe5, + 0x3e, + 0x11, + 0x8d, + 0x3c, + 0xed, + 0x6e, + 0xab, + 0xce, + 0xd0, + 0x65, + 0x46, + 0xd8, + 0xc7, + 0x07, + 0x63, + 0xb5, + 0x23, + 0x34, + 0xf4, + 0x9f, + 0x7e, + 0x1c, + 0xc7, + 0xc7, + 0xf9, + 0x65, + 0xd1, + 0xf4, + 0x04, + 0x42, + 0x38, + 0xbe, + 0x3a, + 0x0c, + 0x9d, + 0x08, + 0x25, + 0xfc, + 0xa3, + 0x71, + 0xd9, + 0xae, + 0x0c, + 0x39, + 0x61, + 0xf4, + 0x89, + 0x02, + 0x41, + 0x00, + 0xed, + 0xef, + 0xab, + 0xa9, + 0xd5, + 0x39, + 0x9c, + 0xee, + 0x59, + 0x1b, + 0xff, + 0xcf, + 0x48, + 0x44, + 0x1b, + 0xb6, + 0x32, + 0xe7, + 0x46, + 0x24, + 0xf3, + 0x04, + 0x7f, + 0xde, + 0x95, + 0x08, + 0x6d, + 0x75, + 0x9e, + 0x67, + 0x17, + 0xba, + 0x5c, + 0xa4, + 0xd4, + 0xe2, + 0xe2, + 0x4d, + 0x77, + 0xce, + 0xeb, + 0x66, + 0x29, + 0xc5, + 0x96, + 0xe0, + 0x62, + 0xbb, + 0xe5, + 0xac, + 0xdc, + 0x44, + 0x62, + 0x54, + 0x86, + 0xed, + 0x64, + 0x0c, + 0xce, + 0xd0, + 0x60, + 0x03, + 0x9d, + 0x49, + 0x02, + 0x40, + 0x54, + 0xd9, + 0x18, + 0x72, + 0x27, + 0xe4, + 0xbe, + 0x76, + 0xbb, + 0x1a, + 0x6a, + 0x28, + 0x2f, + 0x95, + 0x58, + 0x12, + 0xc4, + 0x2c, + 0xa8, + 0xb6, + 0xcc, + 0xe2, + 0xfd, + 0x0d, + 0x17, + 0x64, + 0xc8, + 0x18, + 0xd7, + 0xc6, + 0xdf, + 0x3d, + 0x4c, + 0x1a, + 0x9e, + 0xf9, + 0x2a, + 0xb0, + 0xb9, + 0x2e, + 0x12, + 0xfd, + 0xec, + 0xc3, + 0x51, + 0xc1, + 0xed, + 0xa9, + 0xfd, + 0xb7, + 0x76, + 0x93, + 0x41, + 0xd8, + 0xc8, + 0x22, + 0x94, + 0x1a, + 0x77, + 0xf6, + 0x9c, + 0xc3, + 0xc3, + 0x89, + 0x02, + 0x41, + 0x00, + 0x8e, + 0xf9, + 0xa7, + 0x08, + 0xad, + 0xb5, + 0x2a, + 0x04, + 0xdb, + 0x8d, + 0x04, + 0xa1, + 0xb5, + 0x06, + 0x20, + 0x34, + 0xd2, + 0xcf, + 0xc0, + 0x89, + 0xb1, + 0x72, + 0x31, + 0xb8, + 0x39, + 0x8b, + 0xcf, + 0xe2, + 0x8e, + 0xa5, + 0xda, + 0x4f, + 0x45, + 0x1e, + 0x53, + 0x42, + 0x66, + 0xc4, + 0x30, + 0x4b, + 0x29, + 0x8e, + 0xc1, + 0x69, + 0x17, + 0x29, + 0x8c, + 0x8a, + 0xe6, + 0x0f, + 0x82, + 0x68, + 0xa1, + 0x41, + 0xb3, + 0xb6, + 0x70, + 0x99, + 0x75, + 0xa9, + 0x27, + 0x18, + 0xe4, + 0xe9, + 0x02, + 0x41, + 0x00, + 0x89, + 0xea, + 0x6e, + 0x6d, + 0x70, + 0xdf, + 0x25, + 0x5f, + 0x18, + 0x3f, + 0x48, + 0xda, + 0x63, + 0x10, + 0x8b, + 0xfe, + 0xa8, + 0x0c, + 0x94, + 0x0f, + 0xde, + 0x97, + 0x56, + 0x53, + 0x89, + 0x94, + 0xe2, + 0x1e, + 0x2c, + 0x74, + 0x3c, + 0x91, + 0x81, + 0x34, + 0x0b, + 0xa6, + 0x40, + 0xf8, + 0xcb, + 0x2a, + 0x60, + 0x8c, + 0xe0, + 0x02, + 0xb7, + 0x89, + 0x93, + 0xcf, + 0x18, + 0x9f, + 0x49, + 0x54, + 0xfd, + 0x7d, + 0x3f, + 0x9a, + 0xef, + 0xd4, + 0xa4, + 0x4f, + 0xc1, + 0x45, + 0x99, + 0x91, }; p = rsa_key; diff --git a/test/pkcs7_test.c b/test/pkcs7_test.c index 8514101121..adf069695e 100644 --- a/test/pkcs7_test.c +++ b/test/pkcs7_test.c @@ -15,30 +15,6 @@ #include "internal/nelem.h" #include "testutil.h" -static int pkcs7_issuer_and_serial_negative_idx_test(void) -{ - PKCS7 *p7 = NULL; - PKCS7_RECIP_INFO *ri = NULL; - int ret = 0; - - if (!TEST_ptr(p7 = PKCS7_new()) - || !TEST_true(PKCS7_set_type(p7, NID_pkcs7_signedAndEnveloped)) - || !TEST_ptr(ri = PKCS7_RECIP_INFO_new()) - || !TEST_true(PKCS7_add_recipient_info(p7, ri))) - goto end; - ri = NULL; - - if (!TEST_ptr(PKCS7_get_issuer_and_serial(p7, 0)) - || !TEST_ptr_null(PKCS7_get_issuer_and_serial(p7, -1))) - goto end; - - ret = 1; -end: - PKCS7_RECIP_INFO_free(ri); - PKCS7_free(p7); - return ret; -} - #ifndef OPENSSL_NO_EC static const unsigned char cert_der[] = { 0x30, 0x82, 0x01, 0x51, 0x30, 0x81, 0xf7, 0xa0, 0x03, 0x02, 0x01, 0x02, @@ -385,10 +361,10 @@ static int pkcs7_inner_content_verify_test(void) 0x2D, 0x6F, 0x81 }; - if (!TEST_ptr(bio = BIO_new_mem_buf(sig_der, sizeof(sig_der)))) + if (!TEST_ptr(bio = BIO_new_mem_buf(sig_der, sizeof sig_der))) goto end; - ret = TEST_ptr(x509_bio = BIO_new_mem_buf(smroot_der, sizeof(smroot_der))) + ret = TEST_ptr(x509_bio = BIO_new_mem_buf(smroot_der, sizeof smroot_der)) && TEST_ptr(cert = d2i_X509_bio(x509_bio, NULL)) && TEST_int_eq(ERR_peek_error(), 0) && TEST_ptr(store = X509_STORE_new()) @@ -413,7 +389,6 @@ end: int setup_tests(void) { - ADD_TEST(pkcs7_issuer_and_serial_negative_idx_test); #ifndef OPENSSL_NO_EC ADD_TEST(pkcs7_verify_test); ADD_TEST(pkcs7_inner_content_verify_test); diff --git a/test/pkey_meth_test.c b/test/pkey_meth_test.c new file mode 100644 index 0000000000..46b39efc3b --- /dev/null +++ b/test/pkey_meth_test.c @@ -0,0 +1,94 @@ +/* + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/* Internal tests for EVP_PKEY method ordering */ + +/* + * Because of *asn1_* + */ +#define OPENSSL_SUPPRESS_DEPRECATED + +#include +#include + +#include +#include "testutil.h" + +#ifndef OPENSSL_NO_DEPRECATED_3_6 +/* Test of EVP_PKEY_ASN1_METHOD ordering */ +static int test_asn1_meths(void) +{ + int i; + int prev = -1; + int good = 1; + int pkey_id; + const EVP_PKEY_ASN1_METHOD *ameth; + + for (i = 0; i < EVP_PKEY_asn1_get_count(); i++) { + ameth = EVP_PKEY_asn1_get0(i); + EVP_PKEY_asn1_get0_info(&pkey_id, NULL, NULL, NULL, NULL, ameth); + if (pkey_id < prev) + good = 0; + prev = pkey_id; + } + if (!good) { + TEST_error("EVP_PKEY_ASN1_METHOD table out of order"); + for (i = 0; i < EVP_PKEY_asn1_get_count(); i++) { + const char *info; + + ameth = EVP_PKEY_asn1_get0(i); + EVP_PKEY_asn1_get0_info(&pkey_id, NULL, NULL, &info, NULL, ameth); + if (info == NULL) + info = ""; + TEST_note("%d : %s : %s", pkey_id, OBJ_nid2ln(pkey_id), info); + } + } + return good; +} +#endif + +#ifndef OPENSSL_NO_DEPRECATED_3_0 +/* Test of EVP_PKEY_METHOD ordering */ +static int test_pkey_meths(void) +{ + size_t i; + int prev = -1; + int good = 1; + int pkey_id; + const EVP_PKEY_METHOD *pmeth; + + for (i = 0; i < EVP_PKEY_meth_get_count(); i++) { + pmeth = EVP_PKEY_meth_get0(i); + EVP_PKEY_meth_get0_info(&pkey_id, NULL, pmeth); + if (pkey_id < prev) + good = 0; + prev = pkey_id; + } + if (!good) { + TEST_error("EVP_PKEY_METHOD table out of order"); + for (i = 0; i < EVP_PKEY_meth_get_count(); i++) { + pmeth = EVP_PKEY_meth_get0(i); + EVP_PKEY_meth_get0_info(&pkey_id, NULL, pmeth); + TEST_note("%d : %s", pkey_id, OBJ_nid2ln(pkey_id)); + } + } + return good; +} +#endif + +int setup_tests(void) +{ +#ifndef OPENSSL_NO_DEPRECATED_3_6 + ADD_TEST(test_asn1_meths); +#endif +#ifndef OPENSSL_NO_DEPRECATED_3_0 + ADD_TEST(test_pkey_meths); +#endif + return 1; +} diff --git a/test/priority_queue_test.c b/test/priority_queue_test.c index 9cf8557594..e90d5b330a 100644 --- a/test/priority_queue_test.c +++ b/test/priority_queue_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -24,11 +24,8 @@ DEFINE_PRIORITY_QUEUE_OF(size_t); static size_t num_rec_freed; -static int size_t_compare(const void *av, const void *bv) +static int size_t_compare(const size_t *a, const size_t *b) { - const size_t *a = av; - const size_t *b = bv; - if (*a < *b) return -1; if (*a > *b) @@ -36,12 +33,17 @@ static int size_t_compare(const void *av, const void *bv) return 0; } -static int qsort_size_t_compare_rev(const void *a, const void *b) +static int qsort_size_t_compare(const void *a, const void *b) { - return size_t_compare(b, a); + return size_t_compare((size_t *)a, (size_t *)b); } -static void free_checker(ossl_unused void *p) +static int qsort_size_t_compare_rev(const void *a, const void *b) +{ + return size_t_compare((size_t *)b, (size_t *)a); +} + +static void free_checker(ossl_unused size_t *p) { num_rec_freed++; } @@ -70,7 +72,7 @@ static int test_size_t_priority_queue_int(int reserve, int order, int count, for (i = 0; i < count; i++) values[i] = random ? test_random() : (size_t)(count - i); memcpy(sorted, values, sizeof(*sorted) * count); - qsort(sorted, count, sizeof(*sorted), &size_t_compare); + qsort(sorted, count, sizeof(*sorted), &qsort_size_t_compare); if (order == 1) memcpy(values, sorted, sizeof(*values) * count); @@ -103,7 +105,7 @@ static int test_size_t_priority_queue_int(int reserve, int order, int count, } } memcpy(sorted, values, sizeof(*sorted) * count); - qsort(sorted, count, sizeof(*sorted), &size_t_compare); + qsort(sorted, count, sizeof(*sorted), &qsort_size_t_compare); } for (i = 0; ossl_pqueue_size_t_peek(pq) != NULL; i++) if (!TEST_size_t_eq(*ossl_pqueue_size_t_peek(pq), sorted[i]) @@ -162,11 +164,8 @@ typedef struct info_st { DEFINE_PRIORITY_QUEUE_OF(INFO); -static int cmp(const void *av, const void *bv) +static int cmp(const INFO *a, const INFO *b) { - const INFO *a = av; - const INFO *b = bv; - if (a->seq_num < b->seq_num) return -1; if (a->seq_num > b->seq_num) diff --git a/test/property_test.c b/test/property_test.c index ed868dbe8c..a5ae9e9d21 100644 --- a/test/property_test.c +++ b/test/property_test.c @@ -13,7 +13,6 @@ #include "testutil.h" #include "internal/nelem.h" #include "internal/property.h" -#include "internal/refcount.h" #include "../crypto/property/property_local.h" /* @@ -23,18 +22,7 @@ * passed around, and used as a tag of sorts. */ struct ossl_provider_st { - /* Flag bits */ - unsigned int flag_initialized : 1; - unsigned int flag_activated : 1; - - /* Getting and setting the flags require synchronization */ - CRYPTO_RWLOCK *flag_lock; - - /* OpenSSL library side data */ - CRYPTO_REF_COUNT refcnt; - CRYPTO_RWLOCK *activatecnt_lock; /* For the activatecnt counter */ - int activatecnt; - char *name; + int x; }; static int add_property_names(const char *n, ...) @@ -60,21 +48,6 @@ static void down_ref(void *p) { } -static int counted_up_ref(void *p) -{ - int *refs = p; - - (*refs)++; - return 1; -} - -static void counted_down_ref(void *p) -{ - int *refs = p; - - (*refs)--; -} - static int test_property_string(void) { OSSL_LIB_CTX *ctx; @@ -419,7 +392,7 @@ static int test_register_deregister(void) for (i = 0; i < OSSL_NELEM(impls); i++) if (!TEST_true(ossl_method_store_add(store, &prov, impls[i].nid, impls[i].prop, impls[i].impl, - &up_ref, &down_ref))) { + &up_ref, &down_ref, NULL, NULL))) { TEST_note("iteration %zd", i + 1); goto err; } @@ -444,18 +417,45 @@ err: return ret; } +static int test_freeze_flag(void) +{ + int ret = 0, nid = 6; + const char *prop = "position=1", *prop2 = "position=2"; + char *impl = "a", *impl2 = "b"; + OSSL_METHOD_STORE *store; + OSSL_PROVIDER prov = { 1 }; + const OSSL_PROVIDER *fetched_prov = NULL; + void *fetched_meth = NULL; + + if (!TEST_ptr(store = ossl_method_store_new(NULL)) + || !TEST_true(add_property_names("position", NULL)) + || !TEST_true(ossl_method_store_add(store, &prov, nid, prop, impl, &up_ref, &down_ref, NULL, NULL)) + || !TEST_true(ossl_method_store_fetch(store, nid, prop, &fetched_prov, &fetched_meth)) + || !TEST_ptr_eq(&prov, fetched_prov) + || !TEST_str_eq((char *)fetched_meth, impl) + || !TEST_true(ossl_method_store_freeze_cache(store, NULL)) + || !TEST_false(ossl_method_store_remove(store, nid, impl)) + || !TEST_true(ossl_method_store_fetch(store, nid, prop, &fetched_prov, &fetched_meth)) + || !TEST_ptr_eq(&prov, fetched_prov) + || !TEST_str_eq((char *)fetched_meth, impl) + || !TEST_false(ossl_method_store_remove_all_provided(store, fetched_prov)) + || !TEST_true(ossl_method_store_fetch(store, nid, prop, &fetched_prov, &fetched_meth)) + || !TEST_ptr_eq(&prov, fetched_prov) + || !TEST_str_eq((char *)fetched_meth, impl) + || !TEST_false(ossl_method_store_add(store, &prov, nid, prop2, impl2, &up_ref, &down_ref, NULL, NULL)) + || !TEST_false(ossl_method_store_freeze_cache(store, NULL))) + goto err; + + ret = 1; +err: + ossl_method_store_free(store); + return ret; +} + static int test_property(void) { - static OSSL_PROVIDER fake_provider1 = { - .flag_initialized = 1, - .flag_activated = 1, - .name = "fake-provider1" - }; - static OSSL_PROVIDER fake_provider2 = { - .flag_initialized = 1, - .flag_activated = 1, - .name = "fake-provider2" - }; + static OSSL_PROVIDER fake_provider1 = { 1 }; + static OSSL_PROVIDER fake_provider2 = { 2 }; static const OSSL_PROVIDER *fake_prov1 = &fake_provider1; static const OSSL_PROVIDER *fake_prov2 = &fake_provider2; static const struct { @@ -502,7 +502,7 @@ static int test_property(void) if (!TEST_true(ossl_method_store_add(store, *impls[i].prov, impls[i].nid, impls[i].prop, impls[i].impl, - &up_ref, &down_ref))) { + &up_ref, &down_ref, NULL, NULL))) { TEST_note("iteration %zd", i + 1); goto err; } @@ -596,18 +596,14 @@ err: static int test_query_cache_stochastic(void) { - const int max = 10000; + const int max = 10000, tail = 10; OSSL_METHOD_STORE *store; int i, res = 0; char buf[50]; void *result; int errors = 0; int v[10001]; - OSSL_PROVIDER prov = { - .flag_initialized = 1, - .flag_activated = 1, - .name = "dummy-test-provider" - }; + OSSL_PROVIDER prov = { 1 }; if (!TEST_ptr(store = ossl_method_store_new(NULL)) || !add_property_names("n", NULL)) @@ -617,13 +613,13 @@ static int test_query_cache_stochastic(void) v[i] = 2 * i; BIO_snprintf(buf, sizeof(buf), "n=%d\n", i); if (!TEST_true(ossl_method_store_add(store, &prov, i, buf, "abc", - &up_ref, &down_ref)) + &up_ref, &down_ref, NULL, NULL)) || !TEST_true(ossl_method_store_cache_set(store, &prov, i, buf, v + i, - &up_ref, &down_ref)) + &up_ref, &down_ref, NULL, NULL)) || !TEST_true(ossl_method_store_cache_set(store, &prov, i, "n=1234", "miss", - &up_ref, &down_ref))) { + &up_ref, &down_ref, NULL, NULL))) { TEST_note("iteration %d", i); goto err; } @@ -634,236 +630,14 @@ static int test_query_cache_stochastic(void) || result != v + i) errors++; } - - res = TEST_int_eq(errors, 0); + /* There is a tiny probability that this will fail when it shouldn't */ + res = TEST_int_gt(errors, tail) && TEST_int_lt(errors, max - tail); err: ossl_method_store_free(store); return res; } -static int test_query_cache_set_duplicate(void) -{ - OSSL_METHOD_STORE *store = NULL; - int res = 0; - int refs = 0; - void *result = NULL; - OSSL_PROVIDER prov = { - .flag_initialized = 1, - .flag_activated = 1, - .name = "dummy-test-provider" - }; - - if (!TEST_ptr(store = ossl_method_store_new(NULL)) - || !TEST_true(ossl_method_store_add(store, &prov, 1, "", &refs, - counted_up_ref, counted_down_ref)) - || !TEST_true(ossl_method_store_cache_set(store, &prov, 1, "", &refs, - counted_up_ref, - counted_down_ref)) - || !TEST_int_eq(refs, 3)) - goto err; - - /* - * Re-adding the same cache key exercises cleanup for a temporary generic - * QUERY that cannot be inserted because a providerless entry already - * exists. Note: Under the lockless store, the cleanup is an archival operation - * That keeps the old entry around until the libctx is freed, as so the refcount - * is monotonically incremented here - */ - ossl_method_store_cache_set(store, &prov, 1, "", &refs, counted_up_ref, - counted_down_ref); - if (!TEST_int_eq(refs, 4) - || !TEST_true(ossl_method_store_cache_get(store, &prov, 1, "", - &result)) - || !TEST_ptr_eq(result, &refs)) - goto err; - -#ifdef OPENSSL_NO_CACHED_FETCH - counted_down_ref(result); -#endif - result = NULL; - res = 1; - -err: - ossl_method_store_free(store); - if (!TEST_int_eq(refs, 0)) - res = 0; - return res; -} - -/* - * When two providers cache the same nid and property query, the first one to - * do so must own the providerless ("any provider will do") cache entry, so - * that a NULL-provider lookup keeps resolving to that provider regardless of - * how many other providers subsequently cache the same nid. This matches the - * provider ossl_method_store_fetch would pick by implementation order. - */ -static int test_query_cache_provider_order(void) -{ - OSSL_METHOD_STORE *store = NULL; - int res = 0; - int method1 = 0, method2 = 0; - void *result = NULL; - OSSL_PROVIDER prov1 = { - .flag_initialized = 1, - .flag_activated = 1, - .name = "first-provider" - }; - OSSL_PROVIDER prov2 = { - .flag_initialized = 1, - .flag_activated = 1, - .name = "second-provider" - }; - - if (!TEST_ptr(store = ossl_method_store_new(NULL))) - goto err; - - /* prov1 caches the nid first, so it owns the providerless entry. */ - if (!TEST_true(ossl_method_store_cache_set(store, &prov1, 1, "", &method1, - up_ref, down_ref)) - || !TEST_true(ossl_method_store_cache_set(store, &prov2, 1, "", - &method2, up_ref, down_ref))) - goto err; - - /* A NULL-provider ("any provider") lookup must resolve to prov1. */ - if (!TEST_true(ossl_method_store_cache_get(store, NULL, 1, "", &result)) - || !TEST_ptr_eq(result, &method1)) - goto err; - - /* Provider-specific lookups must still return each provider's method. */ - result = NULL; - if (!TEST_true(ossl_method_store_cache_get(store, &prov1, 1, "", &result)) - || !TEST_ptr_eq(result, &method1)) - goto err; - result = NULL; - if (!TEST_true(ossl_method_store_cache_get(store, &prov2, 1, "", &result)) - || !TEST_ptr_eq(result, &method2)) - goto err; - - res = 1; - -err: - ossl_method_store_free(store); - return res; -} - -/* Memory-failure coverage for store creation. */ -static int test_query_store_new_mfail(void) -{ - OSSL_METHOD_STORE *store; - int rc; - - MFAIL_start(); - store = ossl_method_store_new(NULL); - MFAIL_end(); - - rc = store != NULL ? 1 : 0; - ossl_method_store_free(store); - return rc; -} - -/* Memory-failure coverage for method registration. */ -static int test_query_store_add_mfail(void) -{ - static OSSL_PROVIDER prov = { - .flag_initialized = 1, - .flag_activated = 1, - .name = "add-mfail-provider" - }; - OSSL_METHOD_STORE *store = NULL; - int refs = 0; - int rc = -1; - - if (!TEST_ptr(store = ossl_method_store_new(NULL))) - goto end; - - MFAIL_start(); - rc = ossl_method_store_add(store, &prov, 1, "", &refs, - counted_up_ref, counted_down_ref) - ? 1 - : 0; - MFAIL_end(); - -end: - ossl_method_store_free(store); - if (rc >= 0 && !TEST_int_eq(refs, 0)) - rc = -1; - return rc; -} - -/* A NULL method archives the matching entry instead of caching a new one. */ -static int test_query_cache_set_null(void) -{ - static OSSL_PROVIDER prov = { - .flag_initialized = 1, - .flag_activated = 1, - .name = "null-set-provider" - }; - OSSL_METHOD_STORE *store = NULL; - int refs = 0; - void *result = NULL; - int res = 0; - - if (!TEST_ptr(store = ossl_method_store_new(NULL)) - || !TEST_true(ossl_method_store_add(store, &prov, 1, "", &refs, - counted_up_ref, counted_down_ref)) - || !TEST_true(ossl_method_store_cache_set(store, &prov, 1, "", &refs, - counted_up_ref, counted_down_ref)) - || !TEST_true(ossl_method_store_cache_set(store, &prov, 1, "", NULL, - counted_up_ref, counted_down_ref)) - || !TEST_false(ossl_method_store_cache_get(store, &prov, 1, "", - &result))) - goto err; - - res = 1; - -err: - ossl_method_store_free(store); - if (!TEST_int_eq(refs, 0)) - res = 0; - return res; -} - -/* Memory-failure coverage for the cache set and providerless lookup. */ -static int test_query_cache_set_mfail(void) -{ - static OSSL_PROVIDER prov = { - .flag_initialized = 1, - .flag_activated = 1, - .name = "mfail-provider" - }; - OSSL_METHOD_STORE *store = NULL; - int refs = 0; - void *result = NULL; - int rc = -1; - - if (!TEST_ptr(store = ossl_method_store_new(NULL)) - || !TEST_true(ossl_method_store_add(store, &prov, 1, "", &refs, - counted_up_ref, counted_down_ref))) - goto end; - - /* Cache the method, then resolve it via the "any provider" (NULL) lookup. */ - MFAIL_start(); - rc = ossl_method_store_cache_set(store, &prov, 1, "", &refs, - counted_up_ref, counted_down_ref) - && ossl_method_store_cache_get(store, NULL, 1, "", &result) - && result == &refs - ? 1 - : 0; - MFAIL_end(); - -#ifdef OPENSSL_NO_CACHED_FETCH - if (result != NULL) - counted_down_ref(result); -#endif - -end: - ossl_method_store_free(store); - if (rc >= 0 && !TEST_int_eq(refs, 0)) - rc = -1; - return rc; -} - static int test_fips_mode(void) { int ret = 0; @@ -974,14 +748,9 @@ int setup_tests(void) ADD_TEST(test_property_defn_cache); ADD_ALL_TESTS(test_definition_compares, OSSL_NELEM(definition_tests)); ADD_TEST(test_register_deregister); + ADD_TEST(test_freeze_flag); ADD_TEST(test_property); ADD_TEST(test_query_cache_stochastic); - ADD_TEST(test_query_cache_set_duplicate); - ADD_TEST(test_query_cache_provider_order); - ADD_TEST(test_query_cache_set_null); - ADD_MFAIL_TEST(test_query_store_new_mfail); - ADD_MFAIL_TEST(test_query_store_add_mfail); - ADD_MFAIL_TEST(test_query_cache_set_mfail); ADD_TEST(test_fips_mode); ADD_ALL_TESTS(test_property_list_to_string, OSSL_NELEM(to_string_tests)); ADD_TEST(test_property_list_to_string_bounds); diff --git a/test/punycode_test.c b/test/punycode_test.c index 3591f0dc19..37f6056903 100644 --- a/test/punycode_test.c +++ b/test/punycode_test.c @@ -188,7 +188,7 @@ static int test_puny_overrun(void) unsigned int bsize = OSSL_NELEM(buf) - 1; if (!TEST_false(ossl_punycode_decode(in, strlen(in), buf, &bsize))) { - if (!TEST_mem_ne(buf, bsize * sizeof(*buf), out, sizeof(out))) + if (TEST_mem_eq(buf, bsize * sizeof(*buf), out, sizeof(out))) TEST_error("CRITICAL: buffer overrun detected!"); return 0; } diff --git a/test/quic-openssl-docker/Dockerfile b/test/quic-openssl-docker/Dockerfile index 292e8181cd..348f43673d 100644 --- a/test/quic-openssl-docker/Dockerfile +++ b/test/quic-openssl-docker/Dockerfile @@ -11,8 +11,7 @@ ARG OPENSSL_BRANCH=master # Install needed tools RUN apt-get update && apt-get install -y \ git make gcc perl cmake build-essential \ - autoconf libtool pkg-config libpsl-dev && \ - apt-get clean + autoconf libtool pkg-config libpsl-dev WORKDIR / @@ -33,11 +32,19 @@ RUN git clone --depth 1 -b $OPENSSL_BRANCH $OPENSSL_URL && \ make -j 4 && make install && cp test/quic-openssl-docker/hq-interop/quic-hq-interop /usr/local/bin && \ cp test/quic-openssl-docker/hq-interop/quic-hq-interop-server /usr/local/bin && \ cp demos/http3/ossl-nghttp3-demo-server /usr/local/bin && \ - cp demos/http3/ossl-nghttp3-demo /usr/local/bin && \ rm -rf /openssl +# Build curl +RUN git clone --depth 1 https://github.com/curl/curl.git && \ + cd curl && \ + autoreconf -fi && ./configure --with-openssl-quic --with-openssl --with-nghttp3 --prefix=/usr && \ + make -j 4 && \ + make install && \ + rm -rf /curl + # copy run script and run it COPY run_endpoint.sh . RUN chmod +x run_endpoint.sh +RUN apt-get clean ENTRYPOINT [ "./run_endpoint.sh" ] diff --git a/test/quic-openssl-docker/hq-interop/quic-hq-interop-server.c b/test/quic-openssl-docker/hq-interop/quic-hq-interop-server.c index 7c8b18ff0c..b0b62fb206 100644 --- a/test/quic-openssl-docker/hq-interop/quic-hq-interop-server.c +++ b/test/quic-openssl-docker/hq-interop/quic-hq-interop-server.c @@ -31,7 +31,7 @@ * Environment variables: * - FILEPREFIX: Specifies the directory containing files to serve. * Defaults to "./downloads" if not set. - * - SSLKEYLOGFILE: specifies that keylogging should be performed on the server + * - SSLKEYLOGFILE: specifies that keylogging should be preformed on the server * should be set to a file name to record keylog data to * - NO_ADDR_VALIDATE: Disables server address validation of clients * @@ -654,18 +654,18 @@ static int run_quic_server(SSL_CTX *ctx, BIO *sock) if (!SSL_set_incoming_stream_policy(conn, SSL_INCOMING_STREAM_POLICY_ACCEPT, 0)) { - fprintf(stderr, "Failed to set incoming stream policy\n"); + fprintf(stderr, "Failed to set incomming stream policy\n"); goto close_conn; } /* - * Until the connection is closed, accept incoming stream + * Until the connection is closed, accept incomming stream * requests and serve them */ for (;;) { /* * Note that SSL_accept_stream is blocking here, as the - * conn SSL object inherited the default blocking property + * conn SSL object inherited the deafult blocking property * from its parent, the listener SSL object. As such there * is no need to handle retry failures here. */ @@ -676,7 +676,7 @@ static int run_quic_server(SSL_CTX *ctx, BIO *sock) * Hit a legitimate error, and should bail out * or * The Client closed the connection, and there are no - * more incoming streams expected + * more incomming streams expected * * Filter on the shutdown error, and only print an error * message if the cause is not SHUTDOWN diff --git a/test/quic-openssl-docker/hq-interop/quic-hq-interop.c b/test/quic-openssl-docker/hq-interop/quic-hq-interop.c index 7f7347a0df..2ebb768fe0 100644 --- a/test/quic-openssl-docker/hq-interop/quic-hq-interop.c +++ b/test/quic-openssl-docker/hq-interop/quic-hq-interop.c @@ -1,5 +1,5 @@ /* - * Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -403,7 +403,7 @@ static int setup_session_cache(SSL *ssl, SSL_CTX *ctx, const char *filename) /* * Because we cache sessions to a file in this client, we don't - * actually need to internally store sessions, because we restore them + * actualy need to internally store sessions, because we restore them * from the file with SSL_set_session below, but we want to ensure * that caching is enabled so that the session cache callbacks get called * properly. The documentation is a bit unclear under what conditions @@ -467,7 +467,7 @@ static BIO **outbiolist = NULL; * This static variable holds the reference to a dynamically allocated array * of strings, representing output names. It is initialized to NULL and * populated as required during operation. This array holds the names of the - * output files from http GET requests. Indices are correlated with the + * output files from http GET requests. Indicies are correlated with the * corresponding outbiolist and poll_list arrays */ static char **outnames = NULL; @@ -606,7 +606,7 @@ static size_t build_request_set(SSL *ssl) new_stream = NULL; /* - * NOTE: We are doing groups of 25 because that's 1/4 of the initial max + * NOTE: We are doing groups of 25 because thats 1/4 of the initial max * stream count that most servers advertise. This gives the server an * opportunity to send us updated MAX_STREAM frames to extend our stream * allotment before we run out, which many servers defer doing. @@ -783,7 +783,7 @@ static int setup_connection(char *hostname, char *port, * Virtually all clients should do this unless you really know what you * are doing. */ - if (!SSL_set1_dnsname(*ssl, hostname)) { + if (!SSL_set1_host(*ssl, hostname)) { fprintf(stderr, "Failed to set the certificate verification hostname"); goto end; } diff --git a/test/quic-openssl-docker/run_endpoint.sh b/test/quic-openssl-docker/run_endpoint.sh index b1ba034692..89c7681482 100644 --- a/test/quic-openssl-docker/run_endpoint.sh +++ b/test/quic-openssl-docker/run_endpoint.sh @@ -10,6 +10,23 @@ CURLRC=~/testcase_curlrc # - SERVER_PARAMS contains user-supplied command line parameters # - CLIENT_PARAMS contains user-supplied command line parameters +generate_outputs_http3() { + for i in $REQUESTS + do + OUTFILE=$(basename $i) + echo -e "--http3-only\n-o /downloads/$OUTFILE\n--url $i" >> $CURLRC + echo "--next" >> $CURLRC + done + # Remove the last --next + head -n -1 $CURLRC > $CURLRC.tmp + mv $CURLRC.tmp $CURLRC +} + +dump_curlrc() { + echo "Using curlrc:" + cat $CURLRC +} + if [ "$ROLE" == "client" ]; then # Wait for the simulator to start up. echo "Waiting for simulator" @@ -19,19 +36,10 @@ if [ "$ROLE" == "client" ]; then case "$TESTCASE" in "http3") - HOSTNAME=none - for req in $REQUESTS - do - OUTFILE=$(basename $req) - if [ "$HOSTNAME" == "none" ] - then - HOSTNAME=$(printf "%s\n" "$req" | sed -ne 's,^https://\([^/:]*\).*,\1,p') - HOSTPORT=$(printf "%s\n" "$req" | sed -ne 's,^https://[^:/]*:\([^/]*\).*,\1,p') - fi - echo "/$OUTFILE" >> ./reqfile.txt - done - cat ./reqfile.txt - SSL_CERT_FILE=/certs/ca.pem ossl-nghttp3-demo $HOSTNAME:$HOSTPORT ./reqfile.txt /downloads || exit 1 + echo -e "--verbose\n--parallel" >> $CURLRC + generate_outputs_http3 + dump_curlrc + SSL_CERT_FILE=/certs/ca.pem curl --config $CURLRC || exit 1 exit 0 ;; "handshake"|"transfer"|"retry"|"ipv6") diff --git a/test/quic_ackm_test.c b/test/quic_ackm_test.c index 8598bf8398..eb523d6a06 100644 --- a/test/quic_ackm_test.c +++ b/test/quic_ackm_test.c @@ -11,7 +11,6 @@ #include #include "internal/quic_ackm.h" #include "internal/quic_cc.h" -#include "internal/quic_vlint.h" static OSSL_TIME fake_time = { 0 }; @@ -148,26 +147,13 @@ struct tx_ack_test_case { const OSSL_QUIC_ACK_RANGE *ack_ranges; size_t num_ack_ranges; const char *expect_ack; /* 1=ack, 2=lost, 4=discarded */ - int expect_reject; /* if nonzero the ACK must be rejected (returns 0) */ }; #define DEFINE_TX_ACK_CASE(n, pntable) \ static const struct tx_ack_test_case tx_ack_case_##n = { \ (pntable), OSSL_NELEM(pntable), \ tx_ack_range_##n, OSSL_NELEM(tx_ack_range_##n), \ - tx_ack_expect_##n, 0 \ - } - -/* - * As DEFINE_TX_ACK_CASE, but the ACK acknowledges a packet number that was - * never sent and so must be rejected by ossl_ackm_on_rx_ack_frame() - * (RFC 9000 s. 13.1). - */ -#define DEFINE_TX_ACK_CASE_REJECT(n, pntable) \ - static const struct tx_ack_test_case tx_ack_case_##n = { \ - (pntable), OSSL_NELEM(pntable), \ - tx_ack_range_##n, OSSL_NELEM(tx_ack_range_##n), \ - tx_ack_expect_##n, 1 \ + tx_ack_expect_##n \ } /* One range, partial coverage of space */ @@ -221,32 +207,32 @@ static const char tx_ack_expect_5[] = { }; DEFINE_TX_ACK_CASE(5, linear_20); -/* One range covering the whole space (0..19, highest sent PN is 19): all acked */ +/* One range, covering entire space */ static const OSSL_QUIC_ACK_RANGE tx_ack_range_6[] = { - { 0, 19 }, + { 0, 20 }, }; static const char tx_ack_expect_6[] = { 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1 }; DEFINE_TX_ACK_CASE(6, linear_20); -/* One range above the highest sent PN (30 > 19): ACK rejected */ +/* One range, covering more space than exists */ static const OSSL_QUIC_ACK_RANGE tx_ack_range_7[] = { { 0, 30 }, }; static const char tx_ack_expect_7[] = { - 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 + 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1, 1 }; -DEFINE_TX_ACK_CASE_REJECT(7, linear_20); +DEFINE_TX_ACK_CASE(7, linear_20); -/* One range entirely above the sent PNs (21..30): ACK rejected */ +/* One range, covering nothing (too high) */ static const OSSL_QUIC_ACK_RANGE tx_ack_range_8[] = { { 21, 30 }, }; static const char tx_ack_expect_8[] = { 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 }; -DEFINE_TX_ACK_CASE_REJECT(8, linear_20); +DEFINE_TX_ACK_CASE(8, linear_20); /* One range, covering nothing (too low) */ static const OSSL_QUIC_ACK_RANGE tx_ack_range_9[] = { @@ -303,20 +289,6 @@ static const char tx_ack_expect_13[] = { }; DEFINE_TX_ACK_CASE(13, high_linear_20); -/* - * Largest range claims the maximum PN (2**62 - 1, never sent) plus a second - * range over real packets so loss detection would otherwise run. ACK rejected; - * otherwise largest_acked_pkt pins at the maximum and every in-flight packet is - * declared lost. - */ -static const OSSL_QUIC_ACK_RANGE tx_ack_range_14[] = { - { OSSL_QUIC_VLINT_MAX, OSSL_QUIC_VLINT_MAX }, { 15, 19 } -}; -static const char tx_ack_expect_14[] = { - 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0, 0 -}; -DEFINE_TX_ACK_CASE_REJECT(14, linear_20); - static const struct tx_ack_test_case *const tx_ack_cases[] = { &tx_ack_case_1, &tx_ack_case_2, @@ -331,7 +303,6 @@ static const struct tx_ack_test_case *const tx_ack_cases[] = { &tx_ack_case_11, &tx_ack_case_12, &tx_ack_case_13, - &tx_ack_case_14, }; enum { @@ -431,25 +402,6 @@ static int test_tx_ack_case_actual(int tidx, int space, int mode) /* Try acknowledging. */ ack.ack_ranges = (OSSL_QUIC_ACK_RANGE *)c->ack_ranges; ack.num_ack_ranges = c->num_ack_ranges; - - if (c->expect_reject) { - /* ACK of an unsent PN: rejected without touching loss detection. */ - if (!TEST_int_eq(ossl_ackm_on_rx_ack_frame(h.ackm, &ack, space, - fake_time), - 0)) - goto err; - - for (i = 0; i < c->pn_table_len; ++i) { - if (!TEST_int_eq(h.pkts[i].acked, 0) - || !TEST_int_eq(h.pkts[i].lost, 0) - || !TEST_int_eq(h.pkts[i].discarded, 0)) - goto err; - } - - testresult = 1; - goto err; - } - if (!TEST_int_eq(ossl_ackm_on_rx_ack_frame(h.ackm, &ack, space, fake_time), 1)) goto err; @@ -543,11 +495,11 @@ struct tx_ack_time_op { }; #define TX_OP_PKT(advance, pn, num_pn) \ - { TX_ACK_TIME_OP_PKT, (advance) * OSSL_TIME_MS, (pn), (num_pn), NULL } + { TX_ACK_TIME_OP_PKT, (advance) * OSSL_TIME_MS, (pn), (num_pn), NULL }, #define TX_OP_ACK(advance, pn, num_pn) \ - { TX_ACK_TIME_OP_ACK, (advance) * OSSL_TIME_MS, (pn), (num_pn), NULL } + { TX_ACK_TIME_OP_ACK, (advance) * OSSL_TIME_MS, (pn), (num_pn), NULL }, #define TX_OP_EXPECT(expect) \ - { TX_ACK_TIME_OP_EXPECT, 0, 0, 0, (expect) } + { TX_ACK_TIME_OP_EXPECT, 0, 0, 0, (expect) }, #define TX_OP_END { TX_ACK_TIME_OP_END } static const char tx_ack_time_script_1_expect[] = { @@ -555,11 +507,11 @@ static const char tx_ack_time_script_1_expect[] = { }; static const struct tx_ack_time_op tx_ack_time_script_1[] = { - TX_OP_PKT(0, 0, 1), - TX_OP_PKT(3600000, 1, 1), - TX_OP_ACK(1000, 1, 1), - TX_OP_EXPECT(tx_ack_time_script_1_expect), - TX_OP_END + TX_OP_PKT(0, 0, 1) + TX_OP_PKT(3600000, 1, 1) + TX_OP_ACK(1000, 1, 1) + TX_OP_EXPECT(tx_ack_time_script_1_expect) + TX_OP_END }; static const struct tx_ack_time_op *const tx_ack_time_scripts[] = { @@ -625,7 +577,7 @@ static int test_tx_ack_time_script(int tidx) ack.num_ack_ranges = 1; ack_range.start = s->pn; - ack_range.end = s->pn + s->num_pn - 1; + ack_range.end = s->pn + s->num_pn; fake_time = ossl_time_add(fake_time, ossl_ticks2time(s->time_advance)); @@ -696,55 +648,55 @@ struct rx_test_op { { \ RX_OPK_PKT, (advance) * OSSL_TIME_MS, (pn), (num_pn), \ 0, 0, NULL, 0, 0 \ - } + }, #define RX_OP_CHECK_UNPROC(advance, pn, num_pn) \ { \ RX_OPK_CHECK_UNPROC, (advance) * OSSL_TIME_MS, (pn), (num_pn), \ 0, 0, NULL, 0, 0 \ - } + }, #define RX_OP_CHECK_PROC(advance, pn, num_pn) \ { \ RX_OPK_CHECK_PROC, (advance) * OSSL_TIME_MS, (pn), (num_pn), \ 0, 0, NULL, 0, 0 \ - } + }, #define RX_OP_CHECK_STATE(advance, expect_desired, expect_deadline) \ { \ RX_OPK_CHECK_STATE, (advance) * OSSL_TIME_MS, 0, 0, \ (expect_desired), (expect_deadline), NULL, 0, 0 \ - } + }, #define RX_OP_CHECK_ACKS(advance, ack_ranges) \ { \ RX_OPK_CHECK_ACKS, (advance) * OSSL_TIME_MS, 0, 0, \ 0, 0, (ack_ranges), OSSL_NELEM(ack_ranges), 0 \ - } + }, #define RX_OP_CHECK_NO_ACKS(advance) \ { \ RX_OPK_CHECK_ACKS, (advance) * OSSL_TIME_MS, 0, 0, \ 0, 0, NULL, 0, 0 \ - } + }, #define RX_OP_TX(advance, pn, largest_acked) \ { \ RX_OPK_TX, (advance) * OSSL_TIME_MS, (pn), 1, \ 0, 0, NULL, 0, (largest_acked) \ - } + }, #define RX_OP_RX_ACK(advance, pn, num_pn) \ { \ RX_OPK_RX_ACK, (advance) * OSSL_TIME_MS, (pn), (num_pn), \ 0, 0, NULL, 0, 0 \ - } + }, #define RX_OP_SKIP_IF_PN_SPACE(pn_space) \ { \ RX_OPK_SKIP_IF_PN_SPACE, 0, (pn_space), 0, \ 0, 0, NULL, 0, 0 \ - } + }, #define RX_OP_END \ { RX_OPK_END } @@ -755,23 +707,23 @@ static const OSSL_QUIC_ACK_RANGE rx_ack_ranges_1a[] = { }; static const struct rx_test_op rx_script_1[] = { - RX_OP_CHECK_STATE(0, 0, 0), /* no threshold yet */ - RX_OP_CHECK_PROC(0, 0, 3), + RX_OP_CHECK_STATE(0, 0, 0) /* no threshold yet */ + RX_OP_CHECK_PROC(0, 0, 3) - RX_OP_PKT(0, 0, 2), /* two packets, threshold */ - RX_OP_CHECK_UNPROC(0, 0, 2), - RX_OP_CHECK_PROC(0, 2, 1), - RX_OP_CHECK_STATE(0, 1, 0), /* threshold met, immediate */ - RX_OP_CHECK_ACKS(0, rx_ack_ranges_1a), + RX_OP_PKT(0, 0, 2) /* two packets, threshold */ + RX_OP_CHECK_UNPROC(0, 0, 2) + RX_OP_CHECK_PROC(0, 2, 1) + RX_OP_CHECK_STATE(0, 1, 0) /* threshold met, immediate */ + RX_OP_CHECK_ACKS(0, rx_ack_ranges_1a) /* At this point we would generate e.g. a packet with an ACK. */ - RX_OP_TX(0, 0, 1), /* ACKs both */ - RX_OP_CHECK_ACKS(0, rx_ack_ranges_1a), /* not provably ACKed yet */ - RX_OP_RX_ACK(0, 0, 1), /* TX'd packet is ACK'd */ + RX_OP_TX(0, 0, 1) /* ACKs both */ + RX_OP_CHECK_ACKS(0, rx_ack_ranges_1a) /* not provably ACKed yet */ + RX_OP_RX_ACK(0, 0, 1) /* TX'd packet is ACK'd */ - RX_OP_CHECK_NO_ACKS(0), /* nothing more to ACK */ - RX_OP_CHECK_UNPROC(0, 0, 2), /* still unprocessable */ - RX_OP_CHECK_PROC(0, 2, 1), /* still processable */ + RX_OP_CHECK_NO_ACKS(0) /* nothing more to ACK */ + RX_OP_CHECK_UNPROC(0, 0, 2) /* still unprocessable */ + RX_OP_CHECK_PROC(0, 2, 1) /* still processable */ RX_OP_END }; @@ -791,42 +743,42 @@ static const struct rx_test_op rx_script_2[] = { * (rx_script_4) for those spaces as those spaces should not delay ACK * generation, so a different RX_OP_CHECK_STATE test is needed. */ - RX_OP_SKIP_IF_PN_SPACE(QUIC_PN_SPACE_INITIAL), - RX_OP_SKIP_IF_PN_SPACE(QUIC_PN_SPACE_HANDSHAKE), + RX_OP_SKIP_IF_PN_SPACE(QUIC_PN_SPACE_INITIAL) + RX_OP_SKIP_IF_PN_SPACE(QUIC_PN_SPACE_HANDSHAKE) - RX_OP_CHECK_STATE(0, 0, 0), /* no threshold yet */ - RX_OP_CHECK_PROC(0, 0, 3), + RX_OP_CHECK_STATE(0, 0, 0) /* no threshold yet */ + RX_OP_CHECK_PROC(0, 0, 3) /* First packet always generates an ACK so get it out of the way. */ - RX_OP_PKT(0, 0, 1), - RX_OP_CHECK_UNPROC(0, 0, 1), - RX_OP_CHECK_PROC(0, 1, 1), - RX_OP_CHECK_STATE(0, 1, 0), /* first packet always causes ACK */ - RX_OP_CHECK_ACKS(0, rx_ack_ranges_2a), /* clears packet counter */ - RX_OP_CHECK_STATE(0, 0, 0), /* desired state should have been cleared */ + RX_OP_PKT(0, 0, 1) + RX_OP_CHECK_UNPROC(0, 0, 1) + RX_OP_CHECK_PROC(0, 1, 1) + RX_OP_CHECK_STATE(0, 1, 0) /* first packet always causes ACK */ + RX_OP_CHECK_ACKS(0, rx_ack_ranges_2a) /* clears packet counter */ + RX_OP_CHECK_STATE(0, 0, 0) /* desired state should have been cleared */ /* Second packet should not cause ACK-desired state */ - RX_OP_PKT(0, 1, 1), /* just one packet, threshold is 2 */ - RX_OP_CHECK_UNPROC(0, 0, 2), - RX_OP_CHECK_PROC(0, 2, 1), - RX_OP_CHECK_STATE(0, 0, 1), /* threshold not yet met, so deadline */ + RX_OP_PKT(0, 1, 1) /* just one packet, threshold is 2 */ + RX_OP_CHECK_UNPROC(0, 0, 2) + RX_OP_CHECK_PROC(0, 2, 1) + RX_OP_CHECK_STATE(0, 0, 1) /* threshold not yet met, so deadline */ /* Don't check ACKs here, as it would reset our threshold counter. */ /* Now receive a second packet, triggering the threshold */ - RX_OP_PKT(0, 2, 1), /* second packet meets threshold */ - RX_OP_CHECK_UNPROC(0, 0, 3), - RX_OP_CHECK_PROC(0, 3, 1), - RX_OP_CHECK_STATE(0, 1, 0), /* desired immediately */ - RX_OP_CHECK_ACKS(0, rx_ack_ranges_2b), + RX_OP_PKT(0, 2, 1) /* second packet meets threshold */ + RX_OP_CHECK_UNPROC(0, 0, 3) + RX_OP_CHECK_PROC(0, 3, 1) + RX_OP_CHECK_STATE(0, 1, 0) /* desired immediately */ + RX_OP_CHECK_ACKS(0, rx_ack_ranges_2b) /* At this point we would generate e.g. a packet with an ACK. */ - RX_OP_TX(0, 0, 2), /* ACKs all */ - RX_OP_CHECK_ACKS(0, rx_ack_ranges_2b), /* not provably ACKed yet */ - RX_OP_RX_ACK(0, 0, 1), /* TX'd packet is ACK'd */ + RX_OP_TX(0, 0, 2) /* ACKs all */ + RX_OP_CHECK_ACKS(0, rx_ack_ranges_2b) /* not provably ACKed yet */ + RX_OP_RX_ACK(0, 0, 1) /* TX'd packet is ACK'd */ - RX_OP_CHECK_NO_ACKS(0), /* nothing more to ACK */ - RX_OP_CHECK_UNPROC(0, 0, 3), /* still unprocessable */ - RX_OP_CHECK_PROC(0, 3, 1), /* still processable */ + RX_OP_CHECK_NO_ACKS(0) /* nothing more to ACK */ + RX_OP_CHECK_UNPROC(0, 0, 3) /* still unprocessable */ + RX_OP_CHECK_PROC(0, 3, 1) /* still processable */ RX_OP_END }; @@ -845,52 +797,52 @@ static const OSSL_QUIC_ACK_RANGE rx_ack_ranges_3c[] = { }; static const struct rx_test_op rx_script_3[] = { - RX_OP_CHECK_STATE(0, 0, 0), /* no threshold yet */ - RX_OP_CHECK_PROC(0, 0, 11), + RX_OP_CHECK_STATE(0, 0, 0) /* no threshold yet */ + RX_OP_CHECK_PROC(0, 0, 11) /* First packet always generates an ACK so get it out of the way. */ - RX_OP_PKT(0, 0, 1), - RX_OP_CHECK_UNPROC(0, 0, 1), - RX_OP_CHECK_PROC(0, 1, 1), - RX_OP_CHECK_STATE(0, 1, 0), /* first packet always causes ACK */ - RX_OP_CHECK_ACKS(0, rx_ack_ranges_3a), /* clears packet counter */ - RX_OP_CHECK_STATE(0, 0, 0), /* desired state should have been cleared */ + RX_OP_PKT(0, 0, 1) + RX_OP_CHECK_UNPROC(0, 0, 1) + RX_OP_CHECK_PROC(0, 1, 1) + RX_OP_CHECK_STATE(0, 1, 0) /* first packet always causes ACK */ + RX_OP_CHECK_ACKS(0, rx_ack_ranges_3a) /* clears packet counter */ + RX_OP_CHECK_STATE(0, 0, 0) /* desired state should have been cleared */ /* Generate ten packets, exceeding the threshold. */ - RX_OP_PKT(0, 1, 10), /* ten packets, threshold is 2 */ - RX_OP_CHECK_UNPROC(0, 0, 11), - RX_OP_CHECK_PROC(0, 11, 1), - RX_OP_CHECK_STATE(0, 1, 0), /* threshold met, immediate */ - RX_OP_CHECK_ACKS(0, rx_ack_ranges_3b), + RX_OP_PKT(0, 1, 10) /* ten packets, threshold is 2 */ + RX_OP_CHECK_UNPROC(0, 0, 11) + RX_OP_CHECK_PROC(0, 11, 1) + RX_OP_CHECK_STATE(0, 1, 0) /* threshold met, immediate */ + RX_OP_CHECK_ACKS(0, rx_ack_ranges_3b) /* * Test TX'ing a packet which doesn't ACK anything. */ - RX_OP_TX(0, 0, QUIC_PN_INVALID), - RX_OP_RX_ACK(0, 0, 1), + RX_OP_TX(0, 0, QUIC_PN_INVALID) + RX_OP_RX_ACK(0, 0, 1) /* * At this point we would generate a packet with an ACK immediately. * TX a packet which when ACKed makes [0,5] provably ACKed. */ - RX_OP_TX(0, 1, 5), - RX_OP_CHECK_ACKS(0, rx_ack_ranges_3b), /* not provably ACKed yet */ - RX_OP_RX_ACK(0, 1, 1), + RX_OP_TX(0, 1, 5) + RX_OP_CHECK_ACKS(0, rx_ack_ranges_3b) /* not provably ACKed yet */ + RX_OP_RX_ACK(0, 1, 1) - RX_OP_CHECK_ACKS(0, rx_ack_ranges_3c), /* provably ACKed now gone */ - RX_OP_CHECK_UNPROC(0, 0, 11), /* still unprocessable */ - RX_OP_CHECK_PROC(0, 11, 1), /* still processable */ + RX_OP_CHECK_ACKS(0, rx_ack_ranges_3c) /* provably ACKed now gone */ + RX_OP_CHECK_UNPROC(0, 0, 11) /* still unprocessable */ + RX_OP_CHECK_PROC(0, 11, 1) /* still processable */ /* * Now TX another packet which provably ACKs the rest when ACKed. */ - RX_OP_TX(0, 2, 10), - RX_OP_CHECK_ACKS(0, rx_ack_ranges_3c), /* not provably ACKed yet */ - RX_OP_RX_ACK(0, 2, 1), + RX_OP_TX(0, 2, 10) + RX_OP_CHECK_ACKS(0, rx_ack_ranges_3c) /* not provably ACKed yet */ + RX_OP_RX_ACK(0, 2, 1) - RX_OP_CHECK_NO_ACKS(0), /* provably ACKed now gone */ - RX_OP_CHECK_UNPROC(0, 0, 11), /* still unprocessable */ - RX_OP_CHECK_PROC(0, 11, 1), /* still processable */ + RX_OP_CHECK_NO_ACKS(0) /* provably ACKed now gone */ + RX_OP_CHECK_UNPROC(0, 0, 11) /* still unprocessable */ + RX_OP_CHECK_PROC(0, 11, 1) /* still processable */ RX_OP_END }; @@ -905,38 +857,38 @@ static const OSSL_QUIC_ACK_RANGE rx_ack_ranges_4a[] = { static const struct rx_test_op rx_script_4[] = { /* The application PN space is tested in rx_script_2. */ - RX_OP_SKIP_IF_PN_SPACE(QUIC_PN_SPACE_APP), + RX_OP_SKIP_IF_PN_SPACE(QUIC_PN_SPACE_APP) - RX_OP_CHECK_STATE(0, 0, 0), /* no threshold yet */ - RX_OP_CHECK_PROC(0, 0, 3), + RX_OP_CHECK_STATE(0, 0, 0) /* no threshold yet */ + RX_OP_CHECK_PROC(0, 0, 3) /* First packet always generates an ACK so get it out of the way. */ - RX_OP_PKT(0, 0, 1), - RX_OP_CHECK_UNPROC(0, 0, 1), - RX_OP_CHECK_PROC(0, 1, 1), - RX_OP_CHECK_STATE(0, 1, 0), /* first packet always causes ACK */ - RX_OP_CHECK_ACKS(0, rx_ack_ranges_2a), /* clears packet counter */ - RX_OP_CHECK_STATE(0, 0, 0), /* desired state should have been cleared */ + RX_OP_PKT(0, 0, 1) + RX_OP_CHECK_UNPROC(0, 0, 1) + RX_OP_CHECK_PROC(0, 1, 1) + RX_OP_CHECK_STATE(0, 1, 0) /* first packet always causes ACK */ + RX_OP_CHECK_ACKS(0, rx_ack_ranges_2a) /* clears packet counter */ + RX_OP_CHECK_STATE(0, 0, 0) /* desired state should have been cleared */ /* * Second packet should cause ACK-desired state because we are * INITIAL/HANDSHAKE (RFC 9000 s. 13.2.1) */ - RX_OP_PKT(0, 1, 1), /* just one packet, threshold is 2 */ - RX_OP_CHECK_UNPROC(0, 0, 2), - RX_OP_CHECK_PROC(0, 2, 1), - RX_OP_CHECK_STATE(0, 1, 1), - RX_OP_CHECK_ACKS(0, rx_ack_ranges_4a), - RX_OP_CHECK_STATE(0, 0, 0), /* desired state should have been cleared */ + RX_OP_PKT(0, 1, 1) /* just one packet, threshold is 2 */ + RX_OP_CHECK_UNPROC(0, 0, 2) + RX_OP_CHECK_PROC(0, 2, 1) + RX_OP_CHECK_STATE(0, 1, 1) + RX_OP_CHECK_ACKS(0, rx_ack_ranges_4a) + RX_OP_CHECK_STATE(0, 0, 0) /* desired state should have been cleared */ /* At this point we would generate e.g. a packet with an ACK. */ - RX_OP_TX(0, 0, 1), /* ACKs all */ - RX_OP_CHECK_ACKS(0, rx_ack_ranges_4a), /* not provably ACKed yet */ - RX_OP_RX_ACK(0, 0, 1), /* TX'd packet is ACK'd */ + RX_OP_TX(0, 0, 1) /* ACKs all */ + RX_OP_CHECK_ACKS(0, rx_ack_ranges_4a) /* not provably ACKed yet */ + RX_OP_RX_ACK(0, 0, 1) /* TX'd packet is ACK'd */ - RX_OP_CHECK_NO_ACKS(0), /* nothing more to ACK */ - RX_OP_CHECK_UNPROC(0, 0, 2), /* still unprocessable */ - RX_OP_CHECK_PROC(0, 2, 1), /* still processable */ + RX_OP_CHECK_NO_ACKS(0) /* nothing more to ACK */ + RX_OP_CHECK_UNPROC(0, 0, 2) /* still unprocessable */ + RX_OP_CHECK_PROC(0, 2, 1) /* still processable */ RX_OP_END }; diff --git a/test/quic_cc_test.c b/test/quic_cc_test.c index b4ce5caa1b..abe10780fc 100644 --- a/test/quic_cc_test.c +++ b/test/quic_cc_test.c @@ -86,11 +86,8 @@ typedef struct net_pkt_st { DEFINE_PRIORITY_QUEUE_OF(NET_PKT); -static int net_pkt_cmp(const void *av, const void *bv) +static int net_pkt_cmp(const NET_PKT *a, const NET_PKT *b) { - const NET_PKT *a = av; - const NET_PKT *b = bv; - return ossl_time_compare(a->next_time, b->next_time); } @@ -128,7 +125,7 @@ static int net_sim_init(struct net_sim *s, return 1; } -static void do_free(void *pkt) +static void do_free(NET_PKT *pkt) { OPENSSL_free(pkt); } diff --git a/test/quic_client_test.c b/test/quic_client_test.c index 90e8498148..9edf3c18d8 100644 --- a/test/quic_client_test.c +++ b/test/quic_client_test.c @@ -172,7 +172,7 @@ err: static int test_quic_client(void) { - return test_quic_client_ex(INVALID_SOCKET); + return (test_quic_client_ex(INVALID_SOCKET)); } static int test_quic_client_connect_first(void) @@ -202,12 +202,12 @@ static int test_quic_client_connect_first(void) close(c_fd); - return rv; + return (rv); err: if (c_fd != INVALID_SOCKET) close(c_fd); - return 0; + return (0); } OPT_TEST_DECLARE_USAGE("certfile privkeyfile\n") diff --git a/test/quic_fc_test.c b/test/quic_fc_test.c index 1a36e1421e..52351e5ffe 100644 --- a/test/quic_fc_test.c +++ b/test/quic_fc_test.c @@ -229,242 +229,242 @@ struct rx_test_op { #define RX_OP_END \ { RX_OPC_END } #define RX_OP_INIT_CONN(init_window_size, max_window_size) \ - { RX_OPC_INIT_CONN, 0, (init_window_size), (max_window_size) } + { RX_OPC_INIT_CONN, 0, (init_window_size), (max_window_size) }, #define RX_OP_INIT_STREAM(stream_idx, init_window_size, max_window_size) \ - { RX_OPC_INIT_STREAM, (stream_idx), (init_window_size), (max_window_size) } + { RX_OPC_INIT_STREAM, (stream_idx), (init_window_size), (max_window_size) }, #define RX_OP_RX(stream_idx, end, is_fin) \ - { RX_OPC_RX, (stream_idx), (end), (is_fin) } + { RX_OPC_RX, (stream_idx), (end), (is_fin) }, #define RX_OP_RETIRE(stream_idx, num_bytes, rtt, expect_fail) \ - { RX_OPC_RETIRE, (stream_idx), (num_bytes), (rtt), (expect_fail) } + { RX_OPC_RETIRE, (stream_idx), (num_bytes), (rtt), (expect_fail) }, #define RX_OP_CHECK_CWM_CONN(expected) \ - { RX_OPC_CHECK_CWM_CONN, 0, (expected) } + { RX_OPC_CHECK_CWM_CONN, 0, (expected) }, #define RX_OP_CHECK_CWM_STREAM(stream_id, expected) \ - { RX_OPC_CHECK_CWM_STREAM, (stream_id), (expected) } + { RX_OPC_CHECK_CWM_STREAM, (stream_id), (expected) }, #define RX_OP_CHECK_SWM_CONN(expected) \ - { RX_OPC_CHECK_SWM_CONN, 0, (expected) } + { RX_OPC_CHECK_SWM_CONN, 0, (expected) }, #define RX_OP_CHECK_SWM_STREAM(stream_id, expected) \ - { RX_OPC_CHECK_SWM_STREAM, (stream_id), (expected) } + { RX_OPC_CHECK_SWM_STREAM, (stream_id), (expected) }, #define RX_OP_CHECK_RWM_CONN(expected) \ - { RX_OPC_CHECK_RWM_CONN, 0, (expected) } + { RX_OPC_CHECK_RWM_CONN, 0, (expected) }, #define RX_OP_CHECK_RWM_STREAM(stream_id, expected) \ - { RX_OPC_CHECK_RWM_STREAM, (stream_id), (expected) } + { RX_OPC_CHECK_RWM_STREAM, (stream_id), (expected) }, #define RX_OP_CHECK_CHANGED_CONN(expected, clear) \ - { RX_OPC_CHECK_CHANGED_CONN, 0, (expected), (clear) } + { RX_OPC_CHECK_CHANGED_CONN, 0, (expected), (clear) }, #define RX_OP_CHECK_CHANGED_STREAM(stream_id, expected, clear) \ - { RX_OPC_CHECK_CHANGED_STREAM, (stream_id), (expected), (clear) } + { RX_OPC_CHECK_CHANGED_STREAM, (stream_id), (expected), (clear) }, #define RX_OP_CHECK_ERROR_CONN(expected, clear) \ - { RX_OPC_CHECK_ERROR_CONN, 0, (expected), (clear) } + { RX_OPC_CHECK_ERROR_CONN, 0, (expected), (clear) }, #define RX_OP_CHECK_ERROR_STREAM(stream_id, expected, clear) \ - { RX_OPC_CHECK_ERROR_STREAM, (stream_id), (expected), (clear) } + { RX_OPC_CHECK_ERROR_STREAM, (stream_id), (expected), (clear) }, #define RX_OP_STEP_TIME(t) \ - { RX_OPC_STEP_TIME, 0, (t) } + { RX_OPC_STEP_TIME, 0, (t) }, #define RX_OP_MSG(msg) \ - { RX_OPC_MSG, 0, 0, 0, 0, (msg) } + { RX_OPC_MSG, 0, 0, 0, 0, (msg) }, -#define RX_OP_INIT(init_window_size, max_window_size) \ - RX_OP_INIT_CONN(init_window_size, max_window_size), \ - RX_OP_INIT_STREAM(0, init_window_size, max_window_size) -#define RX_OP_CHECK_CWM(expected) \ - RX_OP_CHECK_CWM_CONN(expected), \ - RX_OP_CHECK_CWM_STREAM(0, expected) -#define RX_OP_CHECK_SWM(expected) \ - RX_OP_CHECK_SWM_CONN(expected), \ - RX_OP_CHECK_SWM_STREAM(0, expected) -#define RX_OP_CHECK_RWM(expected) \ - RX_OP_CHECK_RWM_CONN(expected), \ - RX_OP_CHECK_RWM_STREAM(0, expected) -#define RX_OP_CHECK_CHANGED(expected, clear) \ - RX_OP_CHECK_CHANGED_CONN(expected, clear), \ - RX_OP_CHECK_CHANGED_STREAM(0, expected, clear) -#define RX_OP_CHECK_ERROR(expected, clear) \ - RX_OP_CHECK_ERROR_CONN(expected, clear), \ - RX_OP_CHECK_ERROR_STREAM(0, expected, clear) +#define RX_OP_INIT(init_window_size, max_window_size) \ + RX_OP_INIT_CONN(init_window_size, max_window_size) \ + RX_OP_INIT_STREAM(0, init_window_size, max_window_size) +#define RX_OP_CHECK_CWM(expected) \ + RX_OP_CHECK_CWM_CONN(expected) \ + RX_OP_CHECK_CWM_STREAM(0, expected) +#define RX_OP_CHECK_SWM(expected) \ + RX_OP_CHECK_SWM_CONN(expected) \ + RX_OP_CHECK_SWM_STREAM(0, expected) +#define RX_OP_CHECK_RWM(expected) \ + RX_OP_CHECK_RWM_CONN(expected) \ + RX_OP_CHECK_RWM_STREAM(0, expected) +#define RX_OP_CHECK_CHANGED(expected, clear) \ + RX_OP_CHECK_CHANGED_CONN(expected, clear) \ + RX_OP_CHECK_CHANGED_STREAM(0, expected, clear) +#define RX_OP_CHECK_ERROR(expected, clear) \ + RX_OP_CHECK_ERROR_CONN(expected, clear) \ + RX_OP_CHECK_ERROR_STREAM(0, expected, clear) #define INIT_WINDOW_SIZE (1 * 1024 * 1024) #define INIT_S_WINDOW_SIZE (384 * 1024) /* 1. Basic RXFC Tests (stream window == connection window) */ static const struct rx_test_op rx_script_1[] = { - RX_OP_STEP_TIME(1000 * OSSL_TIME_MS), - RX_OP_INIT(INIT_WINDOW_SIZE, 10 * INIT_WINDOW_SIZE), + RX_OP_STEP_TIME(1000 * OSSL_TIME_MS) + RX_OP_INIT(INIT_WINDOW_SIZE, 10 * INIT_WINDOW_SIZE) /* Check initial state. */ - RX_OP_CHECK_CWM(INIT_WINDOW_SIZE), - RX_OP_CHECK_ERROR(0, 0), - RX_OP_CHECK_CHANGED(0, 0), + RX_OP_CHECK_CWM(INIT_WINDOW_SIZE) + RX_OP_CHECK_ERROR(0, 0) + RX_OP_CHECK_CHANGED(0, 0) /* We cannot retire what we have not received. */ - RX_OP_RETIRE(0, 1, 0, 1), + RX_OP_RETIRE(0, 1, 0, 1) /* Zero bytes is a no-op and always valid. */ - RX_OP_RETIRE(0, 0, 0, 0), + RX_OP_RETIRE(0, 0, 0, 0) /* Consume some window. */ - RX_OP_RX(0, 50, 0), + RX_OP_RX(0, 50, 0) /* CWM has not changed. */ - RX_OP_CHECK_CWM(INIT_WINDOW_SIZE), - RX_OP_CHECK_SWM(50), + RX_OP_CHECK_CWM(INIT_WINDOW_SIZE) + RX_OP_CHECK_SWM(50) /* RX, Partial retire */ - RX_OP_RX(0, 60, 0), - RX_OP_CHECK_SWM(60), - RX_OP_RETIRE(0, 20, 50 * OSSL_TIME_MS, 0), - RX_OP_CHECK_RWM(20), - RX_OP_CHECK_SWM(60), - RX_OP_CHECK_CWM(INIT_WINDOW_SIZE), - RX_OP_CHECK_CHANGED(0, 0), - RX_OP_CHECK_ERROR(0, 0), + RX_OP_RX(0, 60, 0) + RX_OP_CHECK_SWM(60) + RX_OP_RETIRE(0, 20, 50 * OSSL_TIME_MS, 0) + RX_OP_CHECK_RWM(20) + RX_OP_CHECK_SWM(60) + RX_OP_CHECK_CWM(INIT_WINDOW_SIZE) + RX_OP_CHECK_CHANGED(0, 0) + RX_OP_CHECK_ERROR(0, 0) /* Fully retired */ - RX_OP_RETIRE(0, 41, 0, 1), - RX_OP_RETIRE(0, 40, 0, 0), - RX_OP_CHECK_SWM(60), - RX_OP_CHECK_RWM(60), - RX_OP_CHECK_CWM(INIT_WINDOW_SIZE), - RX_OP_CHECK_CHANGED(0, 0), - RX_OP_CHECK_ERROR(0, 0), + RX_OP_RETIRE(0, 41, 0, 1) + RX_OP_RETIRE(0, 40, 0, 0) + RX_OP_CHECK_SWM(60) + RX_OP_CHECK_RWM(60) + RX_OP_CHECK_CWM(INIT_WINDOW_SIZE) + RX_OP_CHECK_CHANGED(0, 0) + RX_OP_CHECK_ERROR(0, 0) /* Exhaustion of window - we do not enlarge the window this epoch */ - RX_OP_STEP_TIME(201 * OSSL_TIME_MS), - RX_OP_RX(0, INIT_WINDOW_SIZE, 0), - RX_OP_RETIRE(0, INIT_WINDOW_SIZE - 60, 50 * OSSL_TIME_MS, 0), - RX_OP_CHECK_SWM(INIT_WINDOW_SIZE), - RX_OP_CHECK_CHANGED(1, 0), - RX_OP_CHECK_CHANGED(1, 1), - RX_OP_CHECK_CHANGED(0, 0), - RX_OP_CHECK_ERROR(0, 0), - RX_OP_CHECK_CWM(INIT_WINDOW_SIZE * 2), + RX_OP_STEP_TIME(201 * OSSL_TIME_MS) + RX_OP_RX(0, INIT_WINDOW_SIZE, 0) + RX_OP_RETIRE(0, INIT_WINDOW_SIZE - 60, 50 * OSSL_TIME_MS, 0) + RX_OP_CHECK_SWM(INIT_WINDOW_SIZE) + RX_OP_CHECK_CHANGED(1, 0) + RX_OP_CHECK_CHANGED(1, 1) + RX_OP_CHECK_CHANGED(0, 0) + RX_OP_CHECK_ERROR(0, 0) + RX_OP_CHECK_CWM(INIT_WINDOW_SIZE * 2) /* Second epoch - we still do not enlarge the window this epoch */ - RX_OP_RX(0, INIT_WINDOW_SIZE + 1, 0), - RX_OP_STEP_TIME(201 * OSSL_TIME_MS), - RX_OP_RX(0, INIT_WINDOW_SIZE * 2, 0), - RX_OP_RETIRE(0, INIT_WINDOW_SIZE, 50 * OSSL_TIME_MS, 0), - RX_OP_CHECK_SWM(INIT_WINDOW_SIZE * 2), - RX_OP_CHECK_CHANGED(1, 0), - RX_OP_CHECK_CHANGED(1, 1), - RX_OP_CHECK_CHANGED(0, 0), - RX_OP_CHECK_ERROR(0, 0), - RX_OP_CHECK_CWM(INIT_WINDOW_SIZE * 3), + RX_OP_RX(0, INIT_WINDOW_SIZE + 1, 0) + RX_OP_STEP_TIME(201 * OSSL_TIME_MS) + RX_OP_RX(0, INIT_WINDOW_SIZE * 2, 0) + RX_OP_RETIRE(0, INIT_WINDOW_SIZE, 50 * OSSL_TIME_MS, 0) + RX_OP_CHECK_SWM(INIT_WINDOW_SIZE * 2) + RX_OP_CHECK_CHANGED(1, 0) + RX_OP_CHECK_CHANGED(1, 1) + RX_OP_CHECK_CHANGED(0, 0) + RX_OP_CHECK_ERROR(0, 0) + RX_OP_CHECK_CWM(INIT_WINDOW_SIZE * 3) /* Third epoch - we enlarge the window */ - RX_OP_RX(0, INIT_WINDOW_SIZE * 2 + 1, 0), - RX_OP_STEP_TIME(199 * OSSL_TIME_MS), - RX_OP_RX(0, INIT_WINDOW_SIZE * 3, 0), - RX_OP_RETIRE(0, INIT_WINDOW_SIZE, 50 * OSSL_TIME_MS, 0), - RX_OP_CHECK_SWM(INIT_WINDOW_SIZE * 3), - RX_OP_CHECK_CHANGED(1, 0), - RX_OP_CHECK_CHANGED(1, 1), - RX_OP_CHECK_CHANGED(0, 0), - RX_OP_CHECK_ERROR(0, 0), - RX_OP_CHECK_CWM(INIT_WINDOW_SIZE * 5), + RX_OP_RX(0, INIT_WINDOW_SIZE * 2 + 1, 0) + RX_OP_STEP_TIME(199 * OSSL_TIME_MS) + RX_OP_RX(0, INIT_WINDOW_SIZE * 3, 0) + RX_OP_RETIRE(0, INIT_WINDOW_SIZE, 50 * OSSL_TIME_MS, 0) + RX_OP_CHECK_SWM(INIT_WINDOW_SIZE * 3) + RX_OP_CHECK_CHANGED(1, 0) + RX_OP_CHECK_CHANGED(1, 1) + RX_OP_CHECK_CHANGED(0, 0) + RX_OP_CHECK_ERROR(0, 0) + RX_OP_CHECK_CWM(INIT_WINDOW_SIZE * 5) /* Fourth epoch - peer violates flow control */ - RX_OP_RX(0, INIT_WINDOW_SIZE * 5 - 5, 0), - RX_OP_STEP_TIME(250 * OSSL_TIME_MS), - RX_OP_RX(0, INIT_WINDOW_SIZE * 5 + 1, 0), - RX_OP_CHECK_SWM(INIT_WINDOW_SIZE * 5), - RX_OP_CHECK_ERROR(OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, 0), - RX_OP_CHECK_ERROR(OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, 1), - RX_OP_CHECK_ERROR(0, 0), - RX_OP_CHECK_CWM(INIT_WINDOW_SIZE * 5), + RX_OP_RX(0, INIT_WINDOW_SIZE * 5 - 5, 0) + RX_OP_STEP_TIME(250 * OSSL_TIME_MS) + RX_OP_RX(0, INIT_WINDOW_SIZE * 5 + 1, 0) + RX_OP_CHECK_SWM(INIT_WINDOW_SIZE * 5) + RX_OP_CHECK_ERROR(OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, 0) + RX_OP_CHECK_ERROR(OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, 1) + RX_OP_CHECK_ERROR(0, 0) + RX_OP_CHECK_CWM(INIT_WINDOW_SIZE * 5) /* * No window expansion due to flow control violation; window expansion is * triggered by retirement only. */ - RX_OP_CHECK_CHANGED(0, 0), + RX_OP_CHECK_CHANGED(0, 0) - RX_OP_END, + RX_OP_END }; /* 2. Interaction between connection and stream-level flow control */ static const struct rx_test_op rx_script_2[] = { - RX_OP_STEP_TIME(1000 * OSSL_TIME_MS), - RX_OP_INIT_CONN(INIT_WINDOW_SIZE, 10 * INIT_WINDOW_SIZE), - RX_OP_INIT_STREAM(0, INIT_S_WINDOW_SIZE, 30 * INIT_S_WINDOW_SIZE), - RX_OP_INIT_STREAM(1, INIT_S_WINDOW_SIZE, 30 * INIT_S_WINDOW_SIZE), + RX_OP_STEP_TIME(1000 * OSSL_TIME_MS) + RX_OP_INIT_CONN(INIT_WINDOW_SIZE, 10 * INIT_WINDOW_SIZE) + RX_OP_INIT_STREAM(0, INIT_S_WINDOW_SIZE, 30 * INIT_S_WINDOW_SIZE) + RX_OP_INIT_STREAM(1, INIT_S_WINDOW_SIZE, 30 * INIT_S_WINDOW_SIZE) - RX_OP_RX(0, 10, 0), - RX_OP_CHECK_CWM_CONN(INIT_WINDOW_SIZE), - RX_OP_CHECK_CWM_STREAM(0, INIT_S_WINDOW_SIZE), - RX_OP_CHECK_CWM_STREAM(1, INIT_S_WINDOW_SIZE), - RX_OP_CHECK_SWM_CONN(10), - RX_OP_CHECK_SWM_STREAM(0, 10), - RX_OP_CHECK_SWM_STREAM(1, 0), - RX_OP_CHECK_RWM_CONN(0), - RX_OP_CHECK_RWM_STREAM(0, 0), - RX_OP_CHECK_RWM_STREAM(1, 0), + RX_OP_RX(0, 10, 0) + RX_OP_CHECK_CWM_CONN(INIT_WINDOW_SIZE) + RX_OP_CHECK_CWM_STREAM(0, INIT_S_WINDOW_SIZE) + RX_OP_CHECK_CWM_STREAM(1, INIT_S_WINDOW_SIZE) + RX_OP_CHECK_SWM_CONN(10) + RX_OP_CHECK_SWM_STREAM(0, 10) + RX_OP_CHECK_SWM_STREAM(1, 0) + RX_OP_CHECK_RWM_CONN(0) + RX_OP_CHECK_RWM_STREAM(0, 0) + RX_OP_CHECK_RWM_STREAM(1, 0) - RX_OP_RX(1, 42, 0), - RX_OP_RX(1, 42, 0), /* monotonic; equal or lower values ignored */ - RX_OP_RX(1, 35, 0), - RX_OP_CHECK_CWM_CONN(INIT_WINDOW_SIZE), - RX_OP_CHECK_CWM_STREAM(0, INIT_S_WINDOW_SIZE), - RX_OP_CHECK_CWM_STREAM(1, INIT_S_WINDOW_SIZE), - RX_OP_CHECK_SWM_CONN(52), - RX_OP_CHECK_SWM_STREAM(0, 10), - RX_OP_CHECK_SWM_STREAM(1, 42), - RX_OP_CHECK_RWM_CONN(0), - RX_OP_CHECK_RWM_STREAM(0, 0), - RX_OP_CHECK_RWM_STREAM(1, 0), + RX_OP_RX(1, 42, 0) + RX_OP_RX(1, 42, 0) /* monotonic; equal or lower values ignored */ + RX_OP_RX(1, 35, 0) + RX_OP_CHECK_CWM_CONN(INIT_WINDOW_SIZE) + RX_OP_CHECK_CWM_STREAM(0, INIT_S_WINDOW_SIZE) + RX_OP_CHECK_CWM_STREAM(1, INIT_S_WINDOW_SIZE) + RX_OP_CHECK_SWM_CONN(52) + RX_OP_CHECK_SWM_STREAM(0, 10) + RX_OP_CHECK_SWM_STREAM(1, 42) + RX_OP_CHECK_RWM_CONN(0) + RX_OP_CHECK_RWM_STREAM(0, 0) + RX_OP_CHECK_RWM_STREAM(1, 0) - RX_OP_RETIRE(0, 10, 50 * OSSL_TIME_MS, 0), - RX_OP_CHECK_RWM_CONN(10), - RX_OP_CHECK_RWM_STREAM(0, 10), - RX_OP_CHECK_CWM_CONN(INIT_WINDOW_SIZE), - RX_OP_CHECK_CWM_STREAM(0, INIT_S_WINDOW_SIZE), - RX_OP_CHECK_CWM_STREAM(1, INIT_S_WINDOW_SIZE), + RX_OP_RETIRE(0, 10, 50 * OSSL_TIME_MS, 0) + RX_OP_CHECK_RWM_CONN(10) + RX_OP_CHECK_RWM_STREAM(0, 10) + RX_OP_CHECK_CWM_CONN(INIT_WINDOW_SIZE) + RX_OP_CHECK_CWM_STREAM(0, INIT_S_WINDOW_SIZE) + RX_OP_CHECK_CWM_STREAM(1, INIT_S_WINDOW_SIZE) - RX_OP_RETIRE(1, 42, 50 * OSSL_TIME_MS, 0), - RX_OP_CHECK_RWM_CONN(52), - RX_OP_CHECK_RWM_STREAM(1, 42), - RX_OP_CHECK_CWM_CONN(INIT_WINDOW_SIZE), - RX_OP_CHECK_CWM_STREAM(0, INIT_S_WINDOW_SIZE), - RX_OP_CHECK_CWM_STREAM(1, INIT_S_WINDOW_SIZE), + RX_OP_RETIRE(1, 42, 50 * OSSL_TIME_MS, 0) + RX_OP_CHECK_RWM_CONN(52) + RX_OP_CHECK_RWM_STREAM(1, 42) + RX_OP_CHECK_CWM_CONN(INIT_WINDOW_SIZE) + RX_OP_CHECK_CWM_STREAM(0, INIT_S_WINDOW_SIZE) + RX_OP_CHECK_CWM_STREAM(1, INIT_S_WINDOW_SIZE) - RX_OP_CHECK_CHANGED_CONN(0, 0), + RX_OP_CHECK_CHANGED_CONN(0, 0) /* FC limited by stream but not connection */ - RX_OP_STEP_TIME(1000 * OSSL_TIME_MS), - RX_OP_RX(0, INIT_S_WINDOW_SIZE, 0), - RX_OP_CHECK_SWM_CONN(INIT_S_WINDOW_SIZE + 42), - RX_OP_CHECK_SWM_STREAM(0, INIT_S_WINDOW_SIZE), - RX_OP_CHECK_SWM_STREAM(1, 42), - RX_OP_CHECK_CWM_CONN(INIT_WINDOW_SIZE), - RX_OP_CHECK_CWM_STREAM(0, INIT_S_WINDOW_SIZE), + RX_OP_STEP_TIME(1000 * OSSL_TIME_MS) + RX_OP_RX(0, INIT_S_WINDOW_SIZE, 0) + RX_OP_CHECK_SWM_CONN(INIT_S_WINDOW_SIZE + 42) + RX_OP_CHECK_SWM_STREAM(0, INIT_S_WINDOW_SIZE) + RX_OP_CHECK_SWM_STREAM(1, 42) + RX_OP_CHECK_CWM_CONN(INIT_WINDOW_SIZE) + RX_OP_CHECK_CWM_STREAM(0, INIT_S_WINDOW_SIZE) /* We bump CWM when more than 1/4 of the window has been retired */ - RX_OP_RETIRE(0, INIT_S_WINDOW_SIZE - 10, 50 * OSSL_TIME_MS, 0), - RX_OP_CHECK_CWM_STREAM(0, INIT_S_WINDOW_SIZE * 2), - RX_OP_CHECK_CHANGED_STREAM(0, 1, 0), - RX_OP_CHECK_CHANGED_STREAM(0, 1, 1), - RX_OP_CHECK_CHANGED_STREAM(0, 0, 0), + RX_OP_RETIRE(0, INIT_S_WINDOW_SIZE - 10, 50 * OSSL_TIME_MS, 0) + RX_OP_CHECK_CWM_STREAM(0, INIT_S_WINDOW_SIZE * 2) + RX_OP_CHECK_CHANGED_STREAM(0, 1, 0) + RX_OP_CHECK_CHANGED_STREAM(0, 1, 1) + RX_OP_CHECK_CHANGED_STREAM(0, 0, 0) /* * This is more than 1/4 of the connection window, so CWM will * be bumped here too. */ - RX_OP_CHECK_CWM_CONN(INIT_S_WINDOW_SIZE + INIT_WINDOW_SIZE + 42), - RX_OP_CHECK_RWM_CONN(INIT_S_WINDOW_SIZE + 42), - RX_OP_CHECK_RWM_STREAM(0, INIT_S_WINDOW_SIZE), - RX_OP_CHECK_RWM_STREAM(1, 42), - RX_OP_CHECK_CHANGED_CONN(1, 0), - RX_OP_CHECK_CHANGED_CONN(1, 1), - RX_OP_CHECK_CHANGED_CONN(0, 0), - RX_OP_CHECK_ERROR_CONN(0, 0), - RX_OP_CHECK_ERROR_STREAM(0, 0, 0), - RX_OP_CHECK_ERROR_STREAM(1, 0, 0), + RX_OP_CHECK_CWM_CONN(INIT_S_WINDOW_SIZE + INIT_WINDOW_SIZE + 42) + RX_OP_CHECK_RWM_CONN(INIT_S_WINDOW_SIZE + 42) + RX_OP_CHECK_RWM_STREAM(0, INIT_S_WINDOW_SIZE) + RX_OP_CHECK_RWM_STREAM(1, 42) + RX_OP_CHECK_CHANGED_CONN(1, 0) + RX_OP_CHECK_CHANGED_CONN(1, 1) + RX_OP_CHECK_CHANGED_CONN(0, 0) + RX_OP_CHECK_ERROR_CONN(0, 0) + RX_OP_CHECK_ERROR_STREAM(0, 0, 0) + RX_OP_CHECK_ERROR_STREAM(1, 0, 0) /* Test exceeding limit at stream level. */ - RX_OP_RX(0, INIT_S_WINDOW_SIZE * 2 + 1, 0), - RX_OP_CHECK_ERROR_STREAM(0, OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, 0), - RX_OP_CHECK_ERROR_STREAM(0, OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, 1), - RX_OP_CHECK_ERROR_STREAM(0, 0, 0), - RX_OP_CHECK_ERROR_CONN(0, 0), /* doesn't affect conn */ + RX_OP_RX(0, INIT_S_WINDOW_SIZE * 2 + 1, 0) + RX_OP_CHECK_ERROR_STREAM(0, OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, 0) + RX_OP_CHECK_ERROR_STREAM(0, OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, 1) + RX_OP_CHECK_ERROR_STREAM(0, 0, 0) + RX_OP_CHECK_ERROR_CONN(0, 0) /* doesn't affect conn */ /* Test exceeding limit at connection level. */ - RX_OP_RX(0, INIT_WINDOW_SIZE * 2, 0), - RX_OP_CHECK_ERROR_CONN(OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, 0), - RX_OP_CHECK_ERROR_CONN(OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, 1), - RX_OP_CHECK_ERROR_CONN(0, 0), + RX_OP_RX(0, INIT_WINDOW_SIZE * 2, 0) + RX_OP_CHECK_ERROR_CONN(OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, 0) + RX_OP_CHECK_ERROR_CONN(OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, 1) + RX_OP_CHECK_ERROR_CONN(0, 0) - RX_OP_END, + RX_OP_END }; static const struct rx_test_op *rx_scripts[] = { diff --git a/test/quic_memfail_test.c b/test/quic_memfail_test.c deleted file mode 100644 index 6d791be57a..0000000000 --- a/test/quic_memfail_test.c +++ /dev/null @@ -1,239 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include -#include - -#include -#include -#include - -#include "internal/quic_channel.h" -#include "internal/quic_port.h" -#include "internal/quic_ssl.h" -#include "internal/quic_stream_map.h" -#include "internal/ssl_unwrap.h" -#include "../ssl/quic/quic_local.h" -#include "../ssl/quic/quic_channel_local.h" -#include "../ssl/quic/quic_port_local.h" -#include "testutil.h" - -static int test_ossl_quic_port_create_incoming(void) -{ - SSL_CTX *ctx = NULL; - SSL *listener = NULL; - QUIC_LISTENER *ql; - QUIC_CHANNEL *ch = NULL; - int ret = 0; - OSSL_LIB_CTX *lctx; - - if (!TEST_ptr(lctx = OSSL_LIB_CTX_new())) - goto err; - ctx = SSL_CTX_new_ex(lctx, NULL, OSSL_QUIC_server_method()); - if (!TEST_ptr(ctx)) - goto err; - - if (!TEST_true(ossl_quic_set_diag_title(ctx, "QUIC port qlog leak test"))) - goto err; - - listener = SSL_new_listener(ctx, SSL_LISTENER_FLAG_NO_VALIDATE); - if (!TEST_ptr(listener)) - goto err; - - ql = QUIC_LISTENER_FROM_SSL(listener); - if (!TEST_true(ossl_quic_port_test_and_set_peeloff(ql->port, PEELOFF_ACCEPT))) - goto err; - - MFAIL_start(); - ch = ossl_quic_port_create_incoming(ql->port, NULL); - MFAIL_end(); - - if (ch == NULL) - goto err; - - ret = 1; - -err: - /* - * On success, the channel and the inner TLS are owned by the user_ssl - * created inside port_new_handshake_layer (we passed tls=NULL). Freeing - * user_ssl cascades through qc_cleanup() to free both the inner TLS and - * the channel. ossl_quic_channel_free() alone would leak both. - * - * On failure (ch == NULL), port_make_channel already cleaned everything up. - */ - if (ch != NULL) { - SSL *inner_tls = ossl_quic_channel_get0_tls(ch); - SSL_CONNECTION *sc = SSL_CONNECTION_FROM_SSL(inner_tls); - SSL *user_ssl = SSL_CONNECTION_GET_USER_SSL(sc); - SSL_free(user_ssl); - } - - SSL_free(listener); - SSL_CTX_free(ctx); - OSSL_LIB_CTX_free(lctx); - return ret; -} - -static int test_ch_cleanup_idempotent(void) -{ - SSL_CTX *ctx = NULL; - SSL *listener = NULL; - QUIC_LISTENER *ql; - QUIC_CHANNEL_ARGS args = { 0 }; - QUIC_CHANNEL *ch = NULL; - int alloc_failed = 0; - int ret = 0; - OSSL_LIB_CTX *lctx = NULL; - - if (!TEST_ptr(lctx = OSSL_LIB_CTX_new())) - goto err; - ctx = SSL_CTX_new_ex(lctx, NULL, OSSL_QUIC_server_method()); - if (!TEST_ptr(ctx)) - goto err; - - listener = SSL_new_listener(ctx, SSL_LISTENER_FLAG_NO_VALIDATE); - if (!TEST_ptr(listener)) - goto err; - ql = QUIC_LISTENER_FROM_SSL(listener); - - args.port = ql->port; - args.lcidm = ql->port->lcidm; - args.srtm = ql->port->srtm; - args.is_server = 1; - args.is_tserver_ch = 1; - args.use_qlog = 1; - args.qlog_title = "qlog"; - - MFAIL_start(); - ch = ossl_quic_channel_alloc(&args); - if (ch == NULL) { - alloc_failed = 1; - } else { - if (!ossl_quic_channel_init(ch)) - alloc_failed = 1; - - /* - * Whether init succeeded or failed, ossl_quic_channel_free() runs - * ch_cleanup(). On the failure path that's the second ch_cleanup() - * for this channel and must not crash or double-free. - */ - ossl_quic_channel_free(ch); - ch = NULL; - } - MFAIL_end(); - - ret = alloc_failed ? 0 : 1; - -err: - SSL_free(listener); - SSL_CTX_free(ctx); - OSSL_LIB_CTX_free(lctx); - return ret; -} - -static int test_ossl_quic_stream_map_alloc_fail(void) -{ - SSL_CTX *ctx = NULL; - SSL *listener = NULL; - QUIC_LISTENER *ql; - QUIC_CHANNEL_ARGS args = { 0 }; - QUIC_CHANNEL *ch = NULL; - QUIC_STREAM *qs = NULL; - int alloc_failed = 0; - int ret = 0; - OSSL_LIB_CTX *lctx = NULL; - - if (!TEST_ptr(lctx = OSSL_LIB_CTX_new())) - goto err; - ctx = SSL_CTX_new_ex(lctx, NULL, OSSL_QUIC_server_method()); - if (!TEST_ptr(ctx)) - goto err; - - listener = SSL_new_listener(ctx, SSL_LISTENER_FLAG_NO_VALIDATE); - if (!TEST_ptr(listener)) - goto err; - ql = QUIC_LISTENER_FROM_SSL(listener); - - args.port = ql->port; - args.lcidm = ql->port->lcidm; - args.srtm = ql->port->srtm; - args.is_server = 1; - args.is_tserver_ch = 1; - - ch = ossl_quic_channel_alloc(&args); - if (ch == NULL) - goto err; - - if (!ossl_quic_channel_init(ch)) - goto err; - - MFAIL_start(); - qs = ossl_quic_stream_map_alloc(&ch->qsm, 4, QUIC_STREAM_DIR_BIDI); - if (qs == NULL) - alloc_failed = 1; - MFAIL_end(); - - ret = alloc_failed ? 0 : 1; - -err: - if (ch != NULL) - ossl_quic_channel_free(ch); - SSL_free(listener); - SSL_CTX_free(ctx); - OSSL_LIB_CTX_free(lctx); - return ret; -} - -static int test_ossl_quic_peer_token_fail(void) -{ - SSL_CTX *ctx = NULL; - int alloc_failed = 0; - int ret = 0; - OSSL_LIB_CTX *lctx = NULL; - BIO_ADDR *peer = NULL; - const uint8_t token[] = "dummytokentest"; - - if (!TEST_ptr(lctx = OSSL_LIB_CTX_new())) - goto err; - ctx = SSL_CTX_new_ex(lctx, NULL, OSSL_QUIC_client_method()); - if (!TEST_ptr(ctx)) - goto err; - - peer = BIO_ADDR_new(); - if (!TEST_ptr(peer)) - goto err; - - if (!TEST_true(BIO_ADDR_rawmake(peer, AF_INET, "\x7f\x00\x00\x01", 4, 443))) - goto err; - - MFAIL_start(); - if (!ossl_quic_set_peer_token(ctx, peer, token, sizeof(token))) - alloc_failed = 1; - MFAIL_end(); - - ret = alloc_failed ? 0 : 1; - -err: - BIO_ADDR_free(peer); - SSL_CTX_free(ctx); - OSSL_LIB_CTX_free(lctx); - return ret; -} - -int setup_tests(void) -{ - ADD_MFAIL_TEST(test_ossl_quic_port_create_incoming); - ADD_MFAIL_TEST(test_ch_cleanup_idempotent); - ADD_MFAIL_TEST(test_ossl_quic_stream_map_alloc_fail); - ADD_MFAIL_TEST(test_ossl_quic_peer_token_fail); - - return 1; -} diff --git a/test/quic_multistream_test.c b/test/quic_multistream_test.c index a921f13610..e0de3f7850 100644 --- a/test/quic_multistream_test.c +++ b/test/quic_multistream_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -155,6 +155,8 @@ struct script_op { #define OPK_S_EXPECT_FIN 9 #define OPK_C_CONCLUDE 10 #define OPK_S_CONCLUDE 11 +#define OPK_C_DETACH 12 +#define OPK_C_ATTACH 13 #define OPK_C_NEW_STREAM 14 #define OPK_S_NEW_STREAM 15 #define OPK_C_ACCEPT_STREAM_WAIT 16 @@ -218,129 +220,133 @@ struct script_op { #define OP_END \ { OPK_END } #define OP_CHECK(func, arg2) \ - { OPK_CHECK, NULL, 0, (func), NULL, (arg2) } + { OPK_CHECK, NULL, 0, (func), NULL, (arg2) }, #define OP_C_SET_ALPN(alpn) \ - { OPK_C_SET_ALPN, (alpn), 0, NULL, NULL } + { OPK_C_SET_ALPN, (alpn), 0, NULL, NULL }, #define OP_C_CONNECT_WAIT() \ - { OPK_C_CONNECT_WAIT, NULL, 0, NULL, NULL } + { OPK_C_CONNECT_WAIT, NULL, 0, NULL, NULL }, #define OP_C_CONNECT_WAIT_OR_FAIL() \ - { OPK_C_CONNECT_WAIT, NULL, 1, NULL, NULL } + { OPK_C_CONNECT_WAIT, NULL, 1, NULL, NULL }, #define OP_C_WRITE(stream_name, buf, buf_len) \ - { OPK_C_WRITE, (buf), (buf_len), NULL, #stream_name } + { OPK_C_WRITE, (buf), (buf_len), NULL, #stream_name }, #define OP_S_WRITE(stream_name, buf, buf_len) \ - { OPK_S_WRITE, (buf), (buf_len), NULL, #stream_name } + { OPK_S_WRITE, (buf), (buf_len), NULL, #stream_name }, #define OP_C_READ_EXPECT(stream_name, buf, buf_len) \ - { OPK_C_READ_EXPECT, (buf), (buf_len), NULL, #stream_name } + { OPK_C_READ_EXPECT, (buf), (buf_len), NULL, #stream_name }, #define OP_S_READ_EXPECT(stream_name, buf, buf_len) \ - { OPK_S_READ_EXPECT, (buf), (buf_len), NULL, #stream_name } + { OPK_S_READ_EXPECT, (buf), (buf_len), NULL, #stream_name }, #define OP_C_EXPECT_FIN(stream_name) \ - { OPK_C_EXPECT_FIN, NULL, 0, NULL, #stream_name } + { OPK_C_EXPECT_FIN, NULL, 0, NULL, #stream_name }, #define OP_S_EXPECT_FIN(stream_name) \ - { OPK_S_EXPECT_FIN, NULL, 0, NULL, #stream_name } + { OPK_S_EXPECT_FIN, NULL, 0, NULL, #stream_name }, #define OP_C_CONCLUDE(stream_name) \ - { OPK_C_CONCLUDE, NULL, 0, NULL, #stream_name } + { OPK_C_CONCLUDE, NULL, 0, NULL, #stream_name }, #define OP_S_CONCLUDE(stream_name) \ - { OPK_S_CONCLUDE, NULL, 0, NULL, #stream_name } + { OPK_S_CONCLUDE, NULL, 0, NULL, #stream_name }, +#define OP_C_DETACH(stream_name) \ + { OPK_C_DETACH, NULL, 0, NULL, #stream_name }, +#define OP_C_ATTACH(stream_name) \ + { OPK_C_ATTACH, NULL, 0, NULL, #stream_name }, #define OP_C_NEW_STREAM_BIDI(stream_name, expect_id) \ - { OPK_C_NEW_STREAM, NULL, 0, NULL, #stream_name, (expect_id) } + { OPK_C_NEW_STREAM, NULL, 0, NULL, #stream_name, (expect_id) }, #define OP_C_NEW_STREAM_BIDI_EX(stream_name, expect_id, flags) \ - { OPK_C_NEW_STREAM, NULL, (flags), NULL, #stream_name, (expect_id) } + { OPK_C_NEW_STREAM, NULL, (flags), NULL, #stream_name, (expect_id) }, #define OP_C_NEW_STREAM_UNI(stream_name, expect_id) \ { OPK_C_NEW_STREAM, NULL, SSL_STREAM_FLAG_UNI, \ - NULL, #stream_name, (expect_id) } + NULL, #stream_name, (expect_id) }, #define OP_C_NEW_STREAM_UNI_EX(stream_name, expect_id, flags) \ { OPK_C_NEW_STREAM, NULL, (flags) | SSL_STREAM_FLAG_UNI, \ - NULL, #stream_name, (expect_id) } + NULL, #stream_name, (expect_id) }, #define OP_S_NEW_STREAM_BIDI(stream_name, expect_id) \ - { OPK_S_NEW_STREAM, NULL, 0, NULL, #stream_name, (expect_id) } + { OPK_S_NEW_STREAM, NULL, 0, NULL, #stream_name, (expect_id) }, #define OP_S_NEW_STREAM_UNI(stream_name, expect_id) \ - { OPK_S_NEW_STREAM, NULL, 1, NULL, #stream_name, (expect_id) } + { OPK_S_NEW_STREAM, NULL, 1, NULL, #stream_name, (expect_id) }, #define OP_C_ACCEPT_STREAM_WAIT(stream_name) \ - { OPK_C_ACCEPT_STREAM_WAIT, NULL, 0, NULL, #stream_name } + { OPK_C_ACCEPT_STREAM_WAIT, NULL, 0, NULL, #stream_name }, #define OP_C_ACCEPT_STREAM_NONE() \ - { OPK_C_ACCEPT_STREAM_NONE, NULL, 0, NULL, NULL } + { OPK_C_ACCEPT_STREAM_NONE, NULL, 0, NULL, NULL }, #define OP_C_FREE_STREAM(stream_name) \ - { OPK_C_FREE_STREAM, NULL, 0, NULL, #stream_name } + { OPK_C_FREE_STREAM, NULL, 0, NULL, #stream_name }, #define OP_C_SET_DEFAULT_STREAM_MODE(mode) \ - { OPK_C_SET_DEFAULT_STREAM_MODE, NULL, (mode), NULL, NULL } + { OPK_C_SET_DEFAULT_STREAM_MODE, NULL, (mode), NULL, NULL }, #define OP_C_SET_INCOMING_STREAM_POLICY(policy) \ - { OPK_C_SET_INCOMING_STREAM_POLICY, NULL, (policy), NULL, NULL } + { OPK_C_SET_INCOMING_STREAM_POLICY, NULL, (policy), NULL, NULL }, #define OP_C_SHUTDOWN(reason, flags) \ - { OPK_C_SHUTDOWN, (reason), (flags), NULL, NULL } + { OPK_C_SHUTDOWN, (reason), (flags), NULL, NULL }, #define OP_C_SHUTDOWN_WAIT(reason, flags) \ - { OPK_C_SHUTDOWN_WAIT, (reason), (flags), NULL, NULL } + { OPK_C_SHUTDOWN_WAIT, (reason), (flags), NULL, NULL }, #define OP_C_EXPECT_CONN_CLOSE_INFO(ec, app, remote) \ { OPK_C_EXPECT_CONN_CLOSE_INFO, NULL, \ ((app) ? EXPECT_CONN_CLOSE_APP : 0) | ((remote) ? EXPECT_CONN_CLOSE_REMOTE : 0), \ - NULL, NULL, (ec) } + NULL, NULL, (ec) }, #define OP_S_EXPECT_CONN_CLOSE_INFO(ec, app, remote) \ { OPK_S_EXPECT_CONN_CLOSE_INFO, NULL, \ ((app) ? EXPECT_CONN_CLOSE_APP : 0) | ((remote) ? EXPECT_CONN_CLOSE_REMOTE : 0), \ - NULL, NULL, (ec) } + NULL, NULL, (ec) }, #define OP_S_BIND_STREAM_ID(stream_name, stream_id) \ - { OPK_S_BIND_STREAM_ID, NULL, 0, NULL, #stream_name, (stream_id) } + { OPK_S_BIND_STREAM_ID, NULL, 0, NULL, #stream_name, (stream_id) }, #define OP_C_WAIT_FOR_DATA(stream_name) \ - { OPK_C_WAIT_FOR_DATA, NULL, 0, NULL, #stream_name } + { OPK_C_WAIT_FOR_DATA, NULL, 0, NULL, #stream_name }, #define OP_C_WRITE_FAIL(stream_name) \ - { OPK_C_WRITE_FAIL, NULL, 0, NULL, #stream_name } + { OPK_C_WRITE_FAIL, NULL, 0, NULL, #stream_name }, #define OP_S_WRITE_FAIL(stream_name) \ - { OPK_S_WRITE_FAIL, NULL, 0, NULL, #stream_name } + { OPK_S_WRITE_FAIL, NULL, 0, NULL, #stream_name }, #define OP_C_READ_FAIL(stream_name) \ - { OPK_C_READ_FAIL, NULL, 0, NULL, #stream_name } + { OPK_C_READ_FAIL, NULL, 0, NULL, #stream_name }, #define OP_S_READ_FAIL(stream_name, allow_zero_len) \ - { OPK_S_READ_FAIL, NULL, (allow_zero_len), NULL, #stream_name } + { OPK_S_READ_FAIL, NULL, (allow_zero_len), NULL, #stream_name }, #define OP_C_STREAM_RESET(stream_name, aec) \ - { OPK_C_STREAM_RESET, NULL, 0, NULL, #stream_name, (aec) } + { OPK_C_STREAM_RESET, NULL, 0, NULL, #stream_name, (aec) }, #define OP_C_STREAM_RESET_FAIL(stream_name, aec) \ - { OPK_C_STREAM_RESET_FAIL, NULL, 0, NULL, #stream_name, (aec) } + { OPK_C_STREAM_RESET_FAIL, NULL, 0, NULL, #stream_name, (aec) }, #define OP_S_ACCEPT_STREAM_WAIT(stream_name) \ - { OPK_S_ACCEPT_STREAM_WAIT, NULL, 0, NULL, #stream_name } + { OPK_S_ACCEPT_STREAM_WAIT, NULL, 0, NULL, #stream_name }, #define OP_NEW_THREAD(num_threads, script) \ - { OPK_NEW_THREAD, (script), (num_threads), NULL, NULL, 0 } + { OPK_NEW_THREAD, (script), (num_threads), NULL, NULL, 0 }, #define OP_BEGIN_REPEAT(n) \ - { OPK_BEGIN_REPEAT, NULL, (n) } + { OPK_BEGIN_REPEAT, NULL, (n) }, #define OP_END_REPEAT() \ - { OPK_END_REPEAT } + { OPK_END_REPEAT }, #define OP_S_UNBIND_STREAM_ID(stream_name) \ - { OPK_S_UNBIND_STREAM_ID, NULL, 0, NULL, #stream_name } + { OPK_S_UNBIND_STREAM_ID, NULL, 0, NULL, #stream_name }, #define OP_C_READ_FAIL_WAIT(stream_name) \ - { OPK_C_READ_FAIL_WAIT, NULL, 0, NULL, #stream_name } + { OPK_C_READ_FAIL_WAIT, NULL, 0, NULL, #stream_name }, #define OP_C_CLOSE_SOCKET() \ - { OPK_C_CLOSE_SOCKET } + { OPK_C_CLOSE_SOCKET }, #define OP_C_EXPECT_SSL_ERR(stream_name, err) \ - { OPK_C_EXPECT_SSL_ERR, NULL, (err), NULL, #stream_name } + { OPK_C_EXPECT_SSL_ERR, NULL, (err), NULL, #stream_name }, #define OP_EXPECT_ERR_REASON(err) \ - { OPK_EXPECT_ERR_REASON, NULL, (err) } + { OPK_EXPECT_ERR_REASON, NULL, (err) }, #define OP_EXPECT_ERR_LIB(lib) \ - { OPK_EXPECT_ERR_LIB, NULL, (lib) } + { OPK_EXPECT_ERR_LIB, NULL, (lib) }, #define OP_SLEEP(ms) \ - { OPK_SLEEP, NULL, 0, NULL, NULL, (ms) } + { OPK_SLEEP, NULL, 0, NULL, NULL, (ms) }, #define OP_S_SET_INJECT_PLAIN(f) \ - { OPK_S_SET_INJECT_PLAIN, NULL, 0, NULL, NULL, 0, (f) } + { OPK_S_SET_INJECT_PLAIN, NULL, 0, NULL, NULL, 0, (f) }, #define OP_SET_INJECT_WORD(w0, w1) \ - { OPK_SET_INJECT_WORD, NULL, (w0), NULL, NULL, (w1), NULL } + { OPK_SET_INJECT_WORD, NULL, (w0), NULL, NULL, (w1), NULL }, #define OP_C_INHIBIT_TICK(inhibit) \ - { OPK_C_INHIBIT_TICK, NULL, (inhibit), NULL, NULL, 0, NULL } + { OPK_C_INHIBIT_TICK, NULL, (inhibit), NULL, NULL, 0, NULL }, #define OP_C_SET_WRITE_BUF_SIZE(stream_name, size) \ - { OPK_C_SET_WRITE_BUF_SIZE, NULL, (size), NULL, #stream_name } + { OPK_C_SET_WRITE_BUF_SIZE, NULL, (size), NULL, #stream_name }, #define OP_S_SET_INJECT_HANDSHAKE(f) \ - { OPK_S_SET_INJECT_HANDSHAKE, NULL, 0, NULL, NULL, 0, NULL, (f) } + { OPK_S_SET_INJECT_HANDSHAKE, NULL, 0, NULL, NULL, 0, NULL, (f) }, #define OP_S_NEW_TICKET() \ - { OPK_S_NEW_TICKET } + { OPK_S_NEW_TICKET }, #define OP_C_SKIP_IF_UNBOUND(stream_name, n) \ - { OPK_C_SKIP_IF_UNBOUND, NULL, (n), NULL, #stream_name } + { OPK_C_SKIP_IF_UNBOUND, NULL, (n), NULL, #stream_name }, #define OP_S_SET_INJECT_DATAGRAM(f) \ - { OPK_S_SET_INJECT_DATAGRAM, NULL, 0, NULL, NULL, 0, NULL, NULL, (f) } + { OPK_S_SET_INJECT_DATAGRAM, NULL, 0, NULL, NULL, 0, NULL, NULL, (f) }, #define OP_S_SHUTDOWN(error_code) \ - { OPK_S_SHUTDOWN, NULL, (error_code) } + { OPK_S_SHUTDOWN, NULL, (error_code) }, #define OP_POP_ERR() \ - { OPK_POP_ERR } + { OPK_POP_ERR }, #define OP_C_WRITE_EX2(stream_name, buf, buf_len, flags) \ - { OPK_C_WRITE_EX2, (buf), (buf_len), NULL, #stream_name, (flags) } + { OPK_C_WRITE_EX2, (buf), (buf_len), NULL, #stream_name, (flags) }, #define OP_CHECK2(func, arg1, arg2) \ - { OPK_CHECK, NULL, (arg1), (func), NULL, (arg2) } + { OPK_CHECK, NULL, (arg1), (func), NULL, (arg2) }, #define OP_SKIP_IF_BLOCKING(n) \ - { OPK_SKIP_IF_BLOCKING, NULL, (n), NULL, 0 } + { OPK_SKIP_IF_BLOCKING, NULL, (n), NULL, 0 }, static OSSL_TIME get_time(void *arg) { @@ -356,12 +362,109 @@ static OSSL_TIME get_time(void *arg) return t; } +static int skip_time_ms(struct helper *h, struct helper_local *hl) +{ + if (!TEST_true(CRYPTO_THREAD_write_lock(h->time_lock))) + return 0; + + h->time_slip = ossl_time_add(h->time_slip, ossl_ms2time(hl->check_op->arg2)); + + CRYPTO_THREAD_unlock(h->time_lock); + return 1; +} + static QUIC_TSERVER *s_lock(struct helper *h, struct helper_local *hl); static void s_unlock(struct helper *h, struct helper_local *hl); #define ACQUIRE_S() s_lock(h, hl) #define ACQUIRE_S_NOHL() s_lock(h, NULL) +static int check_rejected(struct helper *h, struct helper_local *hl) +{ + uint64_t stream_id = hl->check_op->arg2; + + if (!ossl_quic_tserver_stream_has_peer_stop_sending(ACQUIRE_S(), stream_id, NULL) + || !ossl_quic_tserver_stream_has_peer_reset_stream(ACQUIRE_S(), stream_id, NULL)) { + h->check_spin_again = 1; + return 0; + } + + return 1; +} + +static int check_stream_reset(struct helper *h, struct helper_local *hl) +{ + uint64_t stream_id = hl->check_op->arg2, aec = 0; + + if (!ossl_quic_tserver_stream_has_peer_reset_stream(ACQUIRE_S(), stream_id, &aec)) { + h->check_spin_again = 1; + return 0; + } + + return TEST_uint64_t_eq(aec, 42); +} + +static int check_stream_stopped(struct helper *h, struct helper_local *hl) +{ + uint64_t stream_id = hl->check_op->arg2; + + if (!ossl_quic_tserver_stream_has_peer_stop_sending(ACQUIRE_S(), stream_id, NULL)) { + h->check_spin_again = 1; + return 0; + } + + return 1; +} + +static int override_key_update(struct helper *h, struct helper_local *hl) +{ + QUIC_CHANNEL *ch = ossl_quic_conn_get_channel(h->c_conn); + + ossl_quic_channel_set_txku_threshold_override(ch, hl->check_op->arg2); + return 1; +} + +static int trigger_key_update(struct helper *h, struct helper_local *hl) +{ + if (!TEST_true(SSL_key_update(h->c_conn, SSL_KEY_UPDATE_REQUESTED))) + return 0; + + return 1; +} + +static int check_key_update_ge(struct helper *h, struct helper_local *hl) +{ + QUIC_CHANNEL *ch = ossl_quic_conn_get_channel(h->c_conn); + int64_t txke = (int64_t)ossl_quic_channel_get_tx_key_epoch(ch); + int64_t rxke = (int64_t)ossl_quic_channel_get_rx_key_epoch(ch); + int64_t diff = txke - rxke; + + /* + * TXKE must always be equal to or ahead of RXKE. + * It can be ahead of RXKE by at most 1. + */ + if (!TEST_int64_t_ge(diff, 0) || !TEST_int64_t_le(diff, 1)) + return 0; + + /* Caller specifies a minimum number of RXKEs which must have happened. */ + if (!TEST_uint64_t_ge((uint64_t)rxke, hl->check_op->arg2)) + return 0; + + return 1; +} + +static int check_key_update_lt(struct helper *h, struct helper_local *hl) +{ + QUIC_CHANNEL *ch = ossl_quic_conn_get_channel(h->c_conn); + uint64_t txke = ossl_quic_channel_get_tx_key_epoch(ch); + + /* Caller specifies a maximum number of TXKEs which must have happened. */ + if (!TEST_uint64_t_lt(txke, hl->check_op->arg2)) + return 0; + + return 1; +} + static unsigned long stream_info_hash(const STREAM_INFO *info) { return OPENSSL_LH_strhash(info->name); @@ -995,7 +1098,7 @@ static int run_script_worker(struct helper *h, const struct script_op *script, first = 0; offset = 0; op_start_time = ossl_time_now(); - op_deadline = ossl_time_add(op_start_time, ossl_ms2time(180000)); + op_deadline = ossl_time_add(op_start_time, ossl_ms2time(60000)); } if (!TEST_int_le(ossl_time_compare(ossl_time_now(), op_deadline), 0)) { @@ -1346,6 +1449,36 @@ static int run_script_worker(struct helper *h, const struct script_op *script, S_SPIN_AGAIN(); } break; + case OPK_C_DETACH: { + SSL *c_stream; + + if (!TEST_ptr_null(c_tgt)) + goto out; /* don't overwrite existing stream with same name */ + + if (!TEST_ptr(op->stream_name)) + goto out; + + if (!TEST_ptr(c_stream = ossl_quic_detach_stream(h->c_conn))) + goto out; + + if (!TEST_true(helper_local_set_c_stream(hl, op->stream_name, c_stream))) + goto out; + } break; + + case OPK_C_ATTACH: { + if (!TEST_ptr(c_tgt)) + goto out; + + if (!TEST_ptr(op->stream_name)) + goto out; + + if (!TEST_true(ossl_quic_attach_stream(h->c_conn, c_tgt))) + goto out; + + if (!TEST_true(helper_local_set_c_stream(hl, op->stream_name, NULL))) + goto out; + } break; + case OPK_C_NEW_STREAM: { SSL *c_stream; uint64_t flags = op->arg1; @@ -1945,126 +2078,599 @@ static CRYPTO_THREAD_RETVAL run_script_child_thread(void *arg) /* 1. Simple single-stream test */ static const struct script_op script_1[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_WRITE(DEFAULT, "apple", 5) + OP_C_CONCLUDE(DEFAULT) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) + OP_S_EXPECT_FIN(a) + OP_S_WRITE(a, "orange", 6) + OP_S_CONCLUDE(a) + OP_C_READ_EXPECT(DEFAULT, "orange", 6) + OP_C_EXPECT_FIN(DEFAULT) + OP_END }; /* 2. Multi-stream test */ static const struct script_op script_2[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_INCOMING_STREAM_POLICY(SSL_INCOMING_STREAM_POLICY_ACCEPT) + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(DEFAULT, "orange", 6) + + OP_C_NEW_STREAM_BIDI(b, C_BIDI_ID(1)) + OP_C_WRITE(b, "flamingo", 8) + OP_C_CONCLUDE(b) + OP_S_BIND_STREAM_ID(b, C_BIDI_ID(1)) + OP_S_READ_EXPECT(b, "flamingo", 8) + OP_S_EXPECT_FIN(b) + OP_S_WRITE(b, "gargoyle", 8) + OP_S_CONCLUDE(b) + OP_C_READ_EXPECT(b, "gargoyle", 8) + OP_C_EXPECT_FIN(b) + + OP_C_NEW_STREAM_UNI(c, C_UNI_ID(0)) + OP_C_WRITE(c, "elephant", 8) + OP_C_CONCLUDE(c) + OP_S_BIND_STREAM_ID(c, C_UNI_ID(0)) + OP_S_READ_EXPECT(c, "elephant", 8) + OP_S_EXPECT_FIN(c) + OP_S_WRITE_FAIL(c) + + OP_C_ACCEPT_STREAM_NONE() + + OP_S_NEW_STREAM_BIDI(d, S_BIDI_ID(0)) + OP_S_WRITE(d, "frog", 4) + OP_S_CONCLUDE(d) + + OP_C_ACCEPT_STREAM_WAIT(d) + OP_C_ACCEPT_STREAM_NONE() + OP_C_READ_EXPECT(d, "frog", 4) + OP_C_EXPECT_FIN(d) + + OP_S_NEW_STREAM_BIDI(e, S_BIDI_ID(1)) + OP_S_WRITE(e, "mixture", 7) + OP_S_CONCLUDE(e) + + OP_C_ACCEPT_STREAM_WAIT(e) + OP_C_READ_EXPECT(e, "mixture", 7) + OP_C_EXPECT_FIN(e) + OP_C_WRITE(e, "ramble", 6) + OP_S_READ_EXPECT(e, "ramble", 6) + OP_C_CONCLUDE(e) + OP_S_EXPECT_FIN(e) + + OP_S_NEW_STREAM_UNI(f, S_UNI_ID(0)) + OP_S_WRITE(f, "yonder", 6) + OP_S_CONCLUDE(f) + + OP_C_ACCEPT_STREAM_WAIT(f) + OP_C_ACCEPT_STREAM_NONE() + OP_C_READ_EXPECT(f, "yonder", 6) + OP_C_EXPECT_FIN(f) + OP_C_WRITE_FAIL(f) + + OP_C_SET_INCOMING_STREAM_POLICY(SSL_INCOMING_STREAM_POLICY_REJECT) + OP_S_NEW_STREAM_BIDI(g, S_BIDI_ID(2)) + OP_S_WRITE(g, "unseen", 6) + OP_S_CONCLUDE(g) + + OP_C_ACCEPT_STREAM_NONE() + + OP_C_SET_INCOMING_STREAM_POLICY(SSL_INCOMING_STREAM_POLICY_AUTO) + OP_S_NEW_STREAM_BIDI(h, S_BIDI_ID(3)) + OP_S_WRITE(h, "UNSEEN", 6) + OP_S_CONCLUDE(h) + + OP_C_ACCEPT_STREAM_NONE() + + /* + * Streams g, h should have been rejected, so server should have got + * STOP_SENDING/RESET_STREAM. + */ + OP_CHECK(check_rejected, S_BIDI_ID(2)) + OP_CHECK(check_rejected, S_BIDI_ID(3)) + + OP_END }; /* 3. Default stream detach/reattach test */ static const struct script_op script_3[] = { - /* - * SSL_attach_stream()/SSL_detach_stream() no longer exists, - * there is no reason to keep their private implementation - * with test - */ + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_END + OP_C_WRITE(DEFAULT, "apple", 5) + OP_C_DETACH(a) /* DEFAULT becomes stream 'a' */ + OP_C_WRITE_FAIL(DEFAULT) + + OP_C_WRITE(a, "by", 2) + + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "appleby", 7) + + OP_S_WRITE(a, "hello", 5) + OP_C_READ_EXPECT(a, "hello", 5) + + OP_C_WRITE_FAIL(DEFAULT) + OP_C_ATTACH(a) + OP_C_WRITE(DEFAULT, "is here", 7) + OP_S_READ_EXPECT(a, "is here", 7) + + OP_C_DETACH(a) + OP_C_CONCLUDE(a) + OP_S_EXPECT_FIN(a) + + OP_END }; /* 4. Default stream mode test */ static const struct script_op script_4[] = { - /* - * SSL_attach_stream()/SSL_detach_stream() no longer exists, - * there is no reason to keep their private implementation - * with test - */ + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_END + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) + OP_C_WRITE_FAIL(DEFAULT) + + OP_S_NEW_STREAM_BIDI(a, S_BIDI_ID(0)) + OP_S_WRITE(a, "apple", 5) + + OP_C_READ_FAIL(DEFAULT) + + OP_C_ACCEPT_STREAM_WAIT(a) + OP_C_READ_EXPECT(a, "apple", 5) + + OP_C_ATTACH(a) + OP_C_WRITE(DEFAULT, "orange", 6) + OP_S_READ_EXPECT(a, "orange", 6) + + OP_END }; /* 5. Test stream reset functionality */ static const struct script_op script_5[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_NEW_STREAM_BIDI(b, C_BIDI_ID(1)) + + OP_C_WRITE(a, "apple", 5) + OP_C_STREAM_RESET(a, 42) + + OP_C_WRITE(b, "strawberry", 10) + + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_BIND_STREAM_ID(b, C_BIDI_ID(1)) + OP_S_READ_EXPECT(b, "strawberry", 10) + /* Reset disrupts read of already sent data */ + OP_S_READ_FAIL(a, 0) + OP_CHECK(check_stream_reset, C_BIDI_ID(0)) + + OP_END }; /* 6. Test STOP_SENDING functionality */ static const struct script_op script_6[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) + OP_S_NEW_STREAM_BIDI(a, S_BIDI_ID(0)) + OP_S_WRITE(a, "apple", 5) + + OP_C_ACCEPT_STREAM_WAIT(a) + OP_C_FREE_STREAM(a) + OP_C_ACCEPT_STREAM_NONE() + + OP_CHECK(check_stream_stopped, S_BIDI_ID(0)) + + OP_END }; /* 7. Unidirectional default stream mode test (client sends first) */ static const struct script_op script_7[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_AUTO_UNI) + OP_C_WRITE(DEFAULT, "apple", 5) + + OP_S_BIND_STREAM_ID(a, C_UNI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) + OP_S_WRITE_FAIL(a) + + OP_END }; /* 8. Unidirectional default stream mode test (server sends first) */ static const struct script_op script_8[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_AUTO_UNI) + OP_S_NEW_STREAM_UNI(a, S_UNI_ID(0)) + OP_S_WRITE(a, "apple", 5) + OP_C_READ_EXPECT(DEFAULT, "apple", 5) + OP_C_WRITE_FAIL(DEFAULT) + + OP_END }; /* 9. Unidirectional default stream mode test (server sends first on bidi) */ static const struct script_op script_9[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_AUTO_UNI) + OP_S_NEW_STREAM_BIDI(a, S_BIDI_ID(0)) + OP_S_WRITE(a, "apple", 5) + OP_C_READ_EXPECT(DEFAULT, "apple", 5) + OP_C_WRITE(DEFAULT, "orange", 6) + OP_S_READ_EXPECT(a, "orange", 6) + + OP_END }; /* 10. Shutdown */ static const struct script_op script_10[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) + + OP_C_SHUTDOWN_WAIT(NULL, 0) + OP_C_EXPECT_CONN_CLOSE_INFO(0, 1, 0) + OP_S_EXPECT_CONN_CLOSE_INFO(0, 1, 1) + + OP_END }; /* 11. Many threads accepted on the same client connection */ +static const struct script_op script_11_child[] = { + OP_C_ACCEPT_STREAM_WAIT(a) + OP_C_READ_EXPECT(a, "foo", 3) + OP_SLEEP(10) + OP_C_EXPECT_FIN(a) + + OP_END +}; + static const struct script_op script_11[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) + + OP_NEW_THREAD(5, script_11_child) + + OP_S_NEW_STREAM_BIDI(a, ANY_ID) + OP_S_WRITE(a, "foo", 3) + OP_S_CONCLUDE(a) + + OP_S_NEW_STREAM_BIDI(b, ANY_ID) + OP_S_WRITE(b, "foo", 3) + OP_S_CONCLUDE(b) + + OP_S_NEW_STREAM_BIDI(c, ANY_ID) + OP_S_WRITE(c, "foo", 3) + OP_S_CONCLUDE(c) + + OP_S_NEW_STREAM_BIDI(d, ANY_ID) + OP_S_WRITE(d, "foo", 3) + OP_S_CONCLUDE(d) + + OP_S_NEW_STREAM_BIDI(e, ANY_ID) + OP_S_WRITE(e, "foo", 3) + OP_S_CONCLUDE(e) + + OP_END }; /* 12. Many threads initiated on the same client connection */ +static const struct script_op script_12_child[] = { + OP_C_NEW_STREAM_BIDI(a, ANY_ID) + OP_C_WRITE(a, "foo", 3) + OP_C_CONCLUDE(a) + OP_C_FREE_STREAM(a) + + OP_END +}; + static const struct script_op script_12[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) + + OP_NEW_THREAD(5, script_12_child) + + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "foo", 3) + OP_S_EXPECT_FIN(a) + OP_S_BIND_STREAM_ID(b, C_BIDI_ID(1)) + OP_S_READ_EXPECT(b, "foo", 3) + OP_S_EXPECT_FIN(b) + OP_S_BIND_STREAM_ID(c, C_BIDI_ID(2)) + OP_S_READ_EXPECT(c, "foo", 3) + OP_S_EXPECT_FIN(c) + OP_S_BIND_STREAM_ID(d, C_BIDI_ID(3)) + OP_S_READ_EXPECT(d, "foo", 3) + OP_S_EXPECT_FIN(d) + OP_S_BIND_STREAM_ID(e, C_BIDI_ID(4)) + OP_S_READ_EXPECT(e, "foo", 3) + OP_S_EXPECT_FIN(e) + + OP_END }; /* 13. Many threads accepted on the same client connection (stress test) */ +static const struct script_op script_13_child[] = { + OP_BEGIN_REPEAT(10) + + OP_C_ACCEPT_STREAM_WAIT(a) + OP_C_READ_EXPECT(a, "foo", 3) + OP_C_EXPECT_FIN(a) + OP_C_FREE_STREAM(a) + + OP_END_REPEAT() + + OP_END +}; + static const struct script_op script_13[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) + + OP_NEW_THREAD(5, script_13_child) + + OP_BEGIN_REPEAT(50) + + OP_S_NEW_STREAM_BIDI(a, ANY_ID) + OP_S_WRITE(a, "foo", 3) + OP_S_CONCLUDE(a) + OP_S_UNBIND_STREAM_ID(a) + + OP_END_REPEAT() + + OP_END }; /* 14. Many threads initiating on the same client connection (stress test) */ +static const struct script_op script_14_child[] = { + OP_BEGIN_REPEAT(10) + + OP_C_NEW_STREAM_BIDI(a, ANY_ID) + OP_C_WRITE(a, "foo", 3) + OP_C_CONCLUDE(a) + OP_C_FREE_STREAM(a) + + OP_END_REPEAT() + + OP_END +}; + static const struct script_op script_14[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) + + OP_NEW_THREAD(5, script_14_child) + + OP_BEGIN_REPEAT(50) + + OP_S_ACCEPT_STREAM_WAIT(a) + OP_S_READ_EXPECT(a, "foo", 3) + OP_S_EXPECT_FIN(a) + OP_S_UNBIND_STREAM_ID(a) + + OP_END_REPEAT() + + OP_END }; /* 15. Client sending large number of streams, MAX_STREAMS test */ static const struct script_op script_15[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) + + /* + * This will cause a protocol violation to be raised by the server if we are + * not handling the stream limit correctly on the TX side. + */ + OP_BEGIN_REPEAT(200) + + OP_C_NEW_STREAM_BIDI_EX(a, ANY_ID, SSL_STREAM_FLAG_ADVANCE) + OP_C_WRITE(a, "foo", 3) + OP_C_CONCLUDE(a) + OP_C_FREE_STREAM(a) + + OP_END_REPEAT() + + /* Prove the connection is still good. */ + OP_S_NEW_STREAM_BIDI(a, S_BIDI_ID(0)) + OP_S_WRITE(a, "bar", 3) + OP_S_CONCLUDE(a) + + OP_C_ACCEPT_STREAM_WAIT(a) + OP_C_READ_EXPECT(a, "bar", 3) + OP_C_EXPECT_FIN(a) + + /* + * Drain the queue of incoming streams. We should be able to get all 200 + * even though only 100 can be initiated at a time. + */ + OP_BEGIN_REPEAT(200) + + OP_S_ACCEPT_STREAM_WAIT(b) + OP_S_READ_EXPECT(b, "foo", 3) + OP_S_EXPECT_FIN(b) + OP_S_UNBIND_STREAM_ID(b) + + OP_END_REPEAT() + + OP_END }; /* 16. Server sending large number of streams, MAX_STREAMS test */ static const struct script_op script_16[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) + + /* + * This will cause a protocol violation to be raised by the client if we are + * not handling the stream limit correctly on the TX side. + */ + OP_BEGIN_REPEAT(200) + + OP_S_NEW_STREAM_BIDI(a, ANY_ID) + OP_S_WRITE(a, "foo", 3) + OP_S_CONCLUDE(a) + OP_S_UNBIND_STREAM_ID(a) + + OP_END_REPEAT() + + /* Prove that the connection is still good. */ + OP_C_NEW_STREAM_BIDI(a, ANY_ID) + OP_C_WRITE(a, "bar", 3) + OP_C_CONCLUDE(a) + + OP_S_ACCEPT_STREAM_WAIT(b) + OP_S_READ_EXPECT(b, "bar", 3) + OP_S_EXPECT_FIN(b) + + /* Drain the queue of incoming streams. */ + OP_BEGIN_REPEAT(200) + + OP_C_ACCEPT_STREAM_WAIT(b) + OP_C_READ_EXPECT(b, "foo", 3) + OP_C_EXPECT_FIN(b) + OP_C_FREE_STREAM(b) + + OP_END_REPEAT() + + OP_END }; /* 17. Key update test - unlimited */ static const struct script_op script_17[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + + OP_C_WRITE(DEFAULT, "apple", 5) + + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) + + OP_CHECK(override_key_update, 1) + + OP_BEGIN_REPEAT(200) + + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_READ_EXPECT(a, "apple", 5) + + /* + * TXKU frequency is bounded by RTT because a previous TXKU needs to be + * acknowledged by the peer first before another one can be begin. By + * waiting this long, we eliminate any such concern and ensure as many key + * updates as possible can occur for the purposes of this test. + */ + OP_CHECK(skip_time_ms, 100) + + OP_END_REPEAT() + + /* At least 5 RXKUs detected */ + OP_CHECK(check_key_update_ge, 5) + + /* + * Prove the connection is still healthy by sending something in both + * directions. + */ + OP_C_WRITE(DEFAULT, "xyzzy", 5) + OP_S_READ_EXPECT(a, "xyzzy", 5) + + OP_S_WRITE(a, "plugh", 5) + OP_C_READ_EXPECT(DEFAULT, "plugh", 5) + + OP_END }; /* 18. Key update test - RTT-bounded */ static const struct script_op script_18[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + + OP_C_WRITE(DEFAULT, "apple", 5) + + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) + + OP_CHECK(override_key_update, 1) + + OP_BEGIN_REPEAT(200) + + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_READ_EXPECT(a, "apple", 5) + OP_CHECK(skip_time_ms, 8) + + OP_END_REPEAT() + + /* + * This time we simulate far less time passing between writes, so there are + * fewer opportunities to initiate TXKUs. Note that we ask for a TXKU every + * 1 packet above, which is absurd; thus this ensures we only actually + * generate TXKUs when we are allowed to. + */ + OP_CHECK(check_key_update_lt, 240) + + /* + * Prove the connection is still healthy by sending something in both + * directions. + */ + OP_C_WRITE(DEFAULT, "xyzzy", 5) + OP_S_READ_EXPECT(a, "xyzzy", 5) + + OP_S_WRITE(a, "plugh", 5) + OP_C_READ_EXPECT(DEFAULT, "plugh", 5) + + OP_END }; /* 19. Key update test - artificially triggered */ static const struct script_op script_19[] = { - /* test moved to test/radix/quic_tests.c */ - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + + OP_C_WRITE(DEFAULT, "apple", 5) + + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) + + OP_C_WRITE(DEFAULT, "orange", 6) + OP_S_READ_EXPECT(a, "orange", 6) + + OP_S_WRITE(a, "strawberry", 10) + OP_C_READ_EXPECT(DEFAULT, "strawberry", 10) + + OP_CHECK(check_key_update_lt, 1) + OP_CHECK(trigger_key_update, 0) + + OP_C_WRITE(DEFAULT, "orange", 6) + OP_S_READ_EXPECT(a, "orange", 6) + OP_S_WRITE(a, "ok", 2) + + OP_C_READ_EXPECT(DEFAULT, "ok", 2) + OP_CHECK(check_key_update_ge, 1) + + OP_END }; /* 20. Multiple threads accept stream with socket forcibly closed (error test) */ @@ -2119,48 +2725,48 @@ static int script_20_wait2(struct helper *h, struct helper_local *hl) } static const struct script_op script_20_child[] = { - OP_C_ACCEPT_STREAM_WAIT(a), - OP_C_READ_EXPECT(a, "foo", 3), + OP_C_ACCEPT_STREAM_WAIT(a) + OP_C_READ_EXPECT(a, "foo", 3) - OP_CHECK(script_20_trigger1, 0), - OP_CHECK(script_20_wait2, 1), + OP_CHECK(script_20_trigger1, 0) + OP_CHECK(script_20_wait2, 1) - OP_C_READ_FAIL_WAIT(a), - OP_C_EXPECT_SSL_ERR(a, SSL_ERROR_SYSCALL), + OP_C_READ_FAIL_WAIT(a) + OP_C_EXPECT_SSL_ERR(a, SSL_ERROR_SYSCALL) - OP_EXPECT_ERR_LIB(ERR_LIB_SSL), - OP_EXPECT_ERR_REASON(SSL_R_PROTOCOL_IS_SHUTDOWN), + OP_EXPECT_ERR_LIB(ERR_LIB_SSL) + OP_EXPECT_ERR_REASON(SSL_R_PROTOCOL_IS_SHUTDOWN) - OP_POP_ERR(), - OP_EXPECT_ERR_LIB(ERR_LIB_SSL), - OP_EXPECT_ERR_REASON(SSL_R_QUIC_NETWORK_ERROR), + OP_POP_ERR() + OP_EXPECT_ERR_LIB(ERR_LIB_SSL) + OP_EXPECT_ERR_REASON(SSL_R_QUIC_NETWORK_ERROR) - OP_C_FREE_STREAM(a), + OP_C_FREE_STREAM(a) - OP_END + OP_END }; static const struct script_op script_20[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_NEW_THREAD(5, script_20_child), + OP_NEW_THREAD(5, script_20_child) - OP_BEGIN_REPEAT(5), + OP_BEGIN_REPEAT(5) - OP_S_NEW_STREAM_BIDI(a, ANY_ID), - OP_S_WRITE(a, "foo", 3), - OP_S_UNBIND_STREAM_ID(a), + OP_S_NEW_STREAM_BIDI(a, ANY_ID) + OP_S_WRITE(a, "foo", 3) + OP_S_UNBIND_STREAM_ID(a) - OP_END_REPEAT(), + OP_END_REPEAT() - OP_CHECK(script_20_wait1, 5), + OP_CHECK(script_20_wait1, 5) - OP_C_CLOSE_SOCKET(), - OP_CHECK(script_20_trigger2, 0), + OP_C_CLOSE_SOCKET() + OP_CHECK(script_20_trigger2, 0) - OP_END + OP_END }; /* 21. Fault injection - unknown frame in 1-RTT packet */ @@ -2286,21 +2892,21 @@ err: } static const struct script_op script_21[] = { - OP_S_SET_INJECT_PLAIN(script_21_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_21_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(QUIC_PKT_TYPE_1RTT, OSSL_QUIC_VLINT_MAX), + OP_SET_INJECT_WORD(QUIC_PKT_TYPE_1RTT, OSSL_QUIC_VLINT_MAX) - OP_S_WRITE(a, "orange", 6), + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0) - OP_END + OP_END }; /* 22. Fault injection - non-zero packet header reserved bits */ @@ -2315,21 +2921,21 @@ static int script_22_inject_plain(struct helper *h, QUIC_PKT_HDR *hdr, } static const struct script_op script_22[] = { - OP_S_SET_INJECT_PLAIN(script_22_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_22_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, 0), + OP_SET_INJECT_WORD(1, 0) - OP_S_WRITE(a, "orange", 6), + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_PROTOCOL_VIOLATION, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_PROTOCOL_VIOLATION, 0, 0) - OP_END + OP_END }; /* 23. Fault injection - empty NEW_TOKEN */ @@ -2368,21 +2974,21 @@ err: } static const struct script_op script_23[] = { - OP_S_SET_INJECT_PLAIN(script_23_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_23_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, 0), + OP_SET_INJECT_WORD(1, 0) - OP_S_WRITE(a, "orange", 6), + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0) - OP_END + OP_END }; /* 24. Fault injection - excess value of MAX_STREAMS_BIDI */ @@ -2421,78 +3027,78 @@ err: } static const struct script_op script_24[] = { - OP_S_SET_INJECT_PLAIN(script_24_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_24_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_MAX_STREAMS_BIDI), + OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_MAX_STREAMS_BIDI) - OP_S_WRITE(a, "orange", 6), + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0) - OP_END + OP_END }; /* 25. Fault injection - excess value of MAX_STREAMS_UNI */ static const struct script_op script_25[] = { - OP_S_SET_INJECT_PLAIN(script_24_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_24_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_MAX_STREAMS_UNI), + OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_MAX_STREAMS_UNI) - OP_S_WRITE(a, "orange", 6), + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0) - OP_END + OP_END }; /* 26. Fault injection - excess value of STREAMS_BLOCKED_BIDI */ static const struct script_op script_26[] = { - OP_S_SET_INJECT_PLAIN(script_24_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_24_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_STREAMS_BLOCKED_BIDI), + OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_STREAMS_BLOCKED_BIDI) - OP_S_WRITE(a, "orange", 6), + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_LIMIT_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_LIMIT_ERROR, 0, 0) - OP_END + OP_END }; /* 27. Fault injection - excess value of STREAMS_BLOCKED_UNI */ static const struct script_op script_27[] = { - OP_S_SET_INJECT_PLAIN(script_24_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_24_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_STREAMS_BLOCKED_UNI), + OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_STREAMS_BLOCKED_UNI) - OP_S_WRITE(a, "orange", 6), + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_LIMIT_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_LIMIT_ERROR, 0, 0) - OP_END + OP_END }; /* 28. Fault injection - received RESET_STREAM for send-only stream */ @@ -2535,98 +3141,98 @@ err: } static const struct script_op script_28[] = { - OP_S_SET_INJECT_PLAIN(script_28_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_28_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "orange", 6), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "orange", 6) - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "orange", 6), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "orange", 6) - OP_C_NEW_STREAM_UNI(b, C_UNI_ID(0)), - OP_C_WRITE(b, "apple", 5), + OP_C_NEW_STREAM_UNI(b, C_UNI_ID(0)) + OP_C_WRITE(b, "apple", 5) - OP_S_BIND_STREAM_ID(b, C_UNI_ID(0)), - OP_S_READ_EXPECT(b, "apple", 5), + OP_S_BIND_STREAM_ID(b, C_UNI_ID(0)) + OP_S_READ_EXPECT(b, "apple", 5) - OP_SET_INJECT_WORD(C_UNI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_RESET_STREAM), - OP_S_WRITE(a, "fruit", 5), + OP_SET_INJECT_WORD(C_UNI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_RESET_STREAM) + OP_S_WRITE(a, "fruit", 5) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0) - OP_END + OP_END }; /* 29. Fault injection - received RESET_STREAM for nonexistent send-only stream */ static const struct script_op script_29[] = { - OP_S_SET_INJECT_PLAIN(script_28_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_28_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "orange", 6), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "orange", 6) - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "orange", 6), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "orange", 6) - OP_C_NEW_STREAM_UNI(b, C_UNI_ID(0)), - OP_C_WRITE(b, "apple", 5), + OP_C_NEW_STREAM_UNI(b, C_UNI_ID(0)) + OP_C_WRITE(b, "apple", 5) - OP_S_BIND_STREAM_ID(b, C_UNI_ID(0)), - OP_S_READ_EXPECT(b, "apple", 5), + OP_S_BIND_STREAM_ID(b, C_UNI_ID(0)) + OP_S_READ_EXPECT(b, "apple", 5) - OP_SET_INJECT_WORD(C_UNI_ID(1) + 1, OSSL_QUIC_FRAME_TYPE_RESET_STREAM), - OP_S_WRITE(a, "fruit", 5), + OP_SET_INJECT_WORD(C_UNI_ID(1) + 1, OSSL_QUIC_FRAME_TYPE_RESET_STREAM) + OP_S_WRITE(a, "fruit", 5) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0) - OP_END + OP_END }; /* 30. Fault injection - received STOP_SENDING for receive-only stream */ static const struct script_op script_30[] = { - OP_S_SET_INJECT_PLAIN(script_28_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_28_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_S_NEW_STREAM_UNI(a, S_UNI_ID(0)), - OP_S_WRITE(a, "apple", 5), + OP_S_NEW_STREAM_UNI(a, S_UNI_ID(0)) + OP_S_WRITE(a, "apple", 5) - OP_C_ACCEPT_STREAM_WAIT(a), - OP_C_READ_EXPECT(a, "apple", 5), + OP_C_ACCEPT_STREAM_WAIT(a) + OP_C_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(S_UNI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_STOP_SENDING), - OP_S_WRITE(a, "orange", 6), + OP_SET_INJECT_WORD(S_UNI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_STOP_SENDING) + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0) - OP_END + OP_END }; /* 31. Fault injection - received STOP_SENDING for nonexistent receive-only stream */ static const struct script_op script_31[] = { - OP_S_SET_INJECT_PLAIN(script_28_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_28_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_S_NEW_STREAM_UNI(a, S_UNI_ID(0)), - OP_S_WRITE(a, "apple", 5), + OP_S_NEW_STREAM_UNI(a, S_UNI_ID(0)) + OP_S_WRITE(a, "apple", 5) - OP_C_ACCEPT_STREAM_WAIT(a), - OP_C_READ_EXPECT(a, "apple", 5), + OP_C_ACCEPT_STREAM_WAIT(a) + OP_C_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(C_UNI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_STOP_SENDING), - OP_S_WRITE(a, "orange", 6), + OP_SET_INJECT_WORD(C_UNI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_STOP_SENDING) + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0) - OP_END + OP_END }; /* 32. Fault injection - STREAM frame for nonexistent stream */ @@ -2696,152 +3302,152 @@ err: } static const struct script_op script_32[] = { - OP_S_SET_INJECT_PLAIN(script_32_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_32_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_S_NEW_STREAM_UNI(a, S_UNI_ID(0)), - OP_S_WRITE(a, "apple", 5), + OP_S_NEW_STREAM_UNI(a, S_UNI_ID(0)) + OP_S_WRITE(a, "apple", 5) - OP_C_ACCEPT_STREAM_WAIT(a), - OP_C_READ_EXPECT(a, "apple", 5), + OP_C_ACCEPT_STREAM_WAIT(a) + OP_C_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(C_UNI_ID(0) + 1, 1), - OP_S_WRITE(a, "orange", 6), + OP_SET_INJECT_WORD(C_UNI_ID(0) + 1, 1) + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0) - OP_END + OP_END }; /* 33. Fault injection - STREAM frame with illegal offset */ static const struct script_op script_33[] = { - OP_S_SET_INJECT_PLAIN(script_32_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_32_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(C_BIDI_ID(0) + 1, 2), - OP_S_WRITE(a, "orange", 6), + OP_SET_INJECT_WORD(C_BIDI_ID(0) + 1, 2) + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0) - OP_END + OP_END }; /* 34. Fault injection - STREAM frame which exceeds FC */ static const struct script_op script_34[] = { - OP_S_SET_INJECT_PLAIN(script_32_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_32_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(C_BIDI_ID(0) + 1, 3), - OP_S_WRITE(a, "orange", 6), + OP_SET_INJECT_WORD(C_BIDI_ID(0) + 1, 3) + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FLOW_CONTROL_ERROR, 0, 0) - OP_END + OP_END }; /* 35. Fault injection - MAX_STREAM_DATA for receive-only stream */ static const struct script_op script_35[] = { - OP_S_SET_INJECT_PLAIN(script_28_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_28_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_S_NEW_STREAM_UNI(a, S_UNI_ID(0)), - OP_S_WRITE(a, "apple", 5), + OP_S_NEW_STREAM_UNI(a, S_UNI_ID(0)) + OP_S_WRITE(a, "apple", 5) - OP_C_ACCEPT_STREAM_WAIT(a), - OP_C_READ_EXPECT(a, "apple", 5), + OP_C_ACCEPT_STREAM_WAIT(a) + OP_C_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(S_UNI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_MAX_STREAM_DATA), - OP_S_WRITE(a, "orange", 6), + OP_SET_INJECT_WORD(S_UNI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_MAX_STREAM_DATA) + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0) - OP_END + OP_END }; /* 36. Fault injection - MAX_STREAM_DATA for nonexistent stream */ static const struct script_op script_36[] = { - OP_S_SET_INJECT_PLAIN(script_28_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_28_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_S_NEW_STREAM_UNI(a, S_UNI_ID(0)), - OP_S_WRITE(a, "apple", 5), + OP_S_NEW_STREAM_UNI(a, S_UNI_ID(0)) + OP_S_WRITE(a, "apple", 5) - OP_C_ACCEPT_STREAM_WAIT(a), - OP_C_READ_EXPECT(a, "apple", 5), + OP_C_ACCEPT_STREAM_WAIT(a) + OP_C_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(C_BIDI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_MAX_STREAM_DATA), - OP_S_WRITE(a, "orange", 6), + OP_SET_INJECT_WORD(C_BIDI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_MAX_STREAM_DATA) + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0) - OP_END + OP_END }; /* 37. Fault injection - STREAM_DATA_BLOCKED for send-only stream */ static const struct script_op script_37[] = { - OP_S_SET_INJECT_PLAIN(script_28_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_28_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_UNI(a, C_UNI_ID(0)), - OP_C_WRITE(a, "apple", 5), + OP_C_NEW_STREAM_UNI(a, C_UNI_ID(0)) + OP_C_WRITE(a, "apple", 5) - OP_S_BIND_STREAM_ID(a, C_UNI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_S_BIND_STREAM_ID(a, C_UNI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_S_NEW_STREAM_UNI(b, S_UNI_ID(0)), - OP_SET_INJECT_WORD(C_UNI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_STREAM_DATA_BLOCKED), - OP_S_WRITE(b, "orange", 5), + OP_S_NEW_STREAM_UNI(b, S_UNI_ID(0)) + OP_SET_INJECT_WORD(C_UNI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_STREAM_DATA_BLOCKED) + OP_S_WRITE(b, "orange", 5) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0) - OP_END + OP_END }; /* 38. Fault injection - STREAM_DATA_BLOCKED for non-existent stream */ static const struct script_op script_38[] = { - OP_S_SET_INJECT_PLAIN(script_28_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_28_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_UNI(a, C_UNI_ID(0)), - OP_C_WRITE(a, "apple", 5), + OP_C_NEW_STREAM_UNI(a, C_UNI_ID(0)) + OP_C_WRITE(a, "apple", 5) - OP_S_BIND_STREAM_ID(a, C_UNI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_S_BIND_STREAM_ID(a, C_UNI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(C_BIDI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_STREAM_DATA_BLOCKED), + OP_SET_INJECT_WORD(C_BIDI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_STREAM_DATA_BLOCKED) - OP_S_NEW_STREAM_UNI(b, S_UNI_ID(0)), - OP_S_WRITE(b, "orange", 5), + OP_S_NEW_STREAM_UNI(b, S_UNI_ID(0)) + OP_S_WRITE(b, "orange", 5) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0) - OP_END + OP_END }; /* 39. Fault injection - NEW_CONN_ID with zero-len CID */ @@ -2933,62 +3539,62 @@ err: } static const struct script_op script_39[] = { - OP_S_SET_INJECT_PLAIN(script_39_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_39_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(0, 1), - OP_S_WRITE(a, "orange", 5), + OP_SET_INJECT_WORD(0, 1) + OP_S_WRITE(a, "orange", 5) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0) - OP_END + OP_END }; /* 40. Shutdown flush test */ static const unsigned char script_40_data[1024] = "strawberry"; static const struct script_op script_40[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) - OP_C_INHIBIT_TICK(1), - OP_C_SET_WRITE_BUF_SIZE(a, 1024 * 100 * 3), + OP_C_INHIBIT_TICK(1) + OP_C_SET_WRITE_BUF_SIZE(a, 1024 * 100 * 3) - OP_BEGIN_REPEAT(100), + OP_BEGIN_REPEAT(100) - OP_C_WRITE(a, script_40_data, sizeof(script_40_data)), + OP_C_WRITE(a, script_40_data, sizeof(script_40_data)) - OP_END_REPEAT(), + OP_END_REPEAT() - OP_C_CONCLUDE(a), - OP_C_SHUTDOWN_WAIT(NULL, 0), /* disengages tick inhibition */ + OP_C_CONCLUDE(a) + OP_C_SHUTDOWN_WAIT(NULL, 0) /* disengages tick inhibition */ - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_BEGIN_REPEAT(100), + OP_BEGIN_REPEAT(100) - OP_S_READ_EXPECT(a, script_40_data, sizeof(script_40_data)), + OP_S_READ_EXPECT(a, script_40_data, sizeof(script_40_data)) - OP_END_REPEAT(), + OP_END_REPEAT() - OP_S_EXPECT_FIN(a), + OP_S_EXPECT_FIN(a) - OP_C_EXPECT_CONN_CLOSE_INFO(0, 1, 0), - OP_S_EXPECT_CONN_CLOSE_INFO(0, 1, 1), + OP_C_EXPECT_CONN_CLOSE_INFO(0, 1, 0) + OP_S_EXPECT_CONN_CLOSE_INFO(0, 1, 1) - OP_END + OP_END }; /* 41. Fault injection - PATH_CHALLENGE yields PATH_RESPONSE */ @@ -3086,25 +3692,25 @@ static int script_41_check(struct helper *h, struct helper_local *hl) } static const struct script_op script_41[] = { - OP_S_SET_INJECT_PLAIN(script_41_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_CHECK(script_41_setup, 0), + OP_S_SET_INJECT_PLAIN(script_41_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_CHECK(script_41_setup, 0) - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_PATH_CHALLENGE), + OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_PATH_CHALLENGE) - OP_S_WRITE(a, "orange", 6), - OP_C_READ_EXPECT(DEFAULT, "orange", 6), + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(DEFAULT, "orange", 6) - OP_C_WRITE(DEFAULT, "strawberry", 10), - OP_S_READ_EXPECT(a, "strawberry", 10), + OP_C_WRITE(DEFAULT, "strawberry", 10) + OP_S_READ_EXPECT(a, "strawberry", 10) - OP_CHECK(script_41_check, 0), - OP_END + OP_CHECK(script_41_check, 0) + OP_END }; /* 42. Fault injection - CRYPTO frame with illegal offset */ @@ -3147,44 +3753,44 @@ err: } static const struct script_op script_42[] = { - OP_S_SET_INJECT_PLAIN(script_42_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_42_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, (((uint64_t)1) << 62) - 1), - OP_S_WRITE(a, "orange", 6), + OP_SET_INJECT_WORD(1, (((uint64_t)1) << 62) - 1) + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0) - OP_END + OP_END }; /* 43. Fault injection - CRYPTO frame exceeding FC */ static const struct script_op script_43[] = { - OP_S_SET_INJECT_PLAIN(script_42_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_42_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, 0x100000 /* 1 MiB */), - OP_S_WRITE(a, "orange", 6), + OP_SET_INJECT_WORD(1, 0x100000 /* 1 MiB */) + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_CRYPTO_BUFFER_EXCEEDED, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_CRYPTO_BUFFER_EXCEEDED, 0, 0) - OP_END + OP_END }; /* 44. Fault injection - PADDING */ @@ -3222,20 +3828,20 @@ err: } static const struct script_op script_44[] = { - OP_S_SET_INJECT_PLAIN(script_44_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_44_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, 0), + OP_SET_INJECT_WORD(1, 0) - OP_S_WRITE(a, "Strawberry", 10), - OP_C_READ_EXPECT(DEFAULT, "Strawberry", 10), + OP_S_WRITE(a, "Strawberry", 10) + OP_C_READ_EXPECT(DEFAULT, "Strawberry", 10) - OP_END + OP_END }; /* 45. PING must generate ACK */ @@ -3267,24 +3873,24 @@ static int wait_incoming_acks_increased(struct helper *h, struct helper_local *h } static const struct script_op script_45[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_BEGIN_REPEAT(2), + OP_BEGIN_REPEAT(2) - OP_CHECK(force_ping, 0), - OP_CHECK(wait_incoming_acks_increased, 0), + OP_CHECK(force_ping, 0) + OP_CHECK(wait_incoming_acks_increased, 0) - OP_END_REPEAT(), + OP_END_REPEAT() - OP_S_WRITE(a, "Strawberry", 10), - OP_C_READ_EXPECT(DEFAULT, "Strawberry", 10), + OP_S_WRITE(a, "Strawberry", 10) + OP_C_READ_EXPECT(DEFAULT, "Strawberry", 10) - OP_END + OP_END }; /* 46. Fault injection - ACK - malformed initial range */ @@ -3382,125 +3988,120 @@ err: } static const struct script_op script_46[] = { - OP_S_SET_INJECT_PLAIN(script_46_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_46_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, 0), + OP_SET_INJECT_WORD(1, 0) - OP_S_WRITE(a, "Strawberry", 10), + OP_S_WRITE(a, "Strawberry", 10) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0) - OP_END + OP_END }; /* 47. Fault injection - ACK - malformed subsequent range */ static const struct script_op script_47[] = { - OP_S_SET_INJECT_PLAIN(script_46_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_46_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(2, 0), + OP_SET_INJECT_WORD(2, 0) - OP_S_WRITE(a, "Strawberry", 10), + OP_S_WRITE(a, "Strawberry", 10) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0) - OP_END + OP_END }; /* 48. Fault injection - ACK - malformed subsequent range */ static const struct script_op script_48[] = { - OP_S_SET_INJECT_PLAIN(script_46_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_46_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(3, 0), + OP_SET_INJECT_WORD(3, 0) - OP_S_WRITE(a, "Strawberry", 10), + OP_S_WRITE(a, "Strawberry", 10) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0) - OP_END + OP_END }; /* 49. Fault injection - ACK - fictional PN */ static const struct script_op script_49[] = { - OP_S_SET_INJECT_PLAIN(script_46_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_46_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(4, 0), + OP_SET_INJECT_WORD(4, 0) - OP_S_WRITE(a, "Strawberry", 10), - /* - * The injected ACK acknowledges a packet number we have not sent, which the - * peer is expected to treat as a PROTOCOL_VIOLATION, so the connection is - * closed rather than the stream data being delivered. - */ - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_PROTOCOL_VIOLATION, 0, 0), + OP_S_WRITE(a, "Strawberry", 10) + OP_C_READ_EXPECT(DEFAULT, "Strawberry", 10) - OP_END + OP_END }; /* 50. Fault injection - ACK - duplicate PN */ static const struct script_op script_50[] = { - OP_S_SET_INJECT_PLAIN(script_46_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_46_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_BEGIN_REPEAT(2), + OP_BEGIN_REPEAT(2) - OP_SET_INJECT_WORD(5, 0), + OP_SET_INJECT_WORD(5, 0) - OP_S_WRITE(a, "Strawberry", 10), - OP_C_READ_EXPECT(DEFAULT, "Strawberry", 10), + OP_S_WRITE(a, "Strawberry", 10) + OP_C_READ_EXPECT(DEFAULT, "Strawberry", 10) - OP_END_REPEAT(), + OP_END_REPEAT() - OP_END + OP_END }; /* 51. Fault injection - PATH_RESPONSE is ignored */ static const struct script_op script_51[] = { - OP_S_SET_INJECT_PLAIN(script_41_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_41_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_PATH_RESPONSE), + OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_PATH_RESPONSE) - OP_S_WRITE(a, "orange", 6), - OP_C_READ_EXPECT(DEFAULT, "orange", 6), + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(DEFAULT, "orange", 6) - OP_C_WRITE(DEFAULT, "Strawberry", 10), - OP_S_READ_EXPECT(a, "Strawberry", 10), + OP_C_WRITE(DEFAULT, "Strawberry", 10) + OP_S_READ_EXPECT(a, "Strawberry", 10) - OP_END + OP_END }; /* 52. Fault injection - ignore BLOCKED frames with bogus values */ @@ -3548,47 +4149,47 @@ err: } static const struct script_op script_52[] = { - OP_S_SET_INJECT_PLAIN(script_52_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_52_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_DATA_BLOCKED), + OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_DATA_BLOCKED) - OP_S_WRITE(a, "orange", 6), - OP_C_READ_EXPECT(DEFAULT, "orange", 6), + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(DEFAULT, "orange", 6) - OP_C_WRITE(DEFAULT, "Strawberry", 10), - OP_S_READ_EXPECT(a, "Strawberry", 10), + OP_C_WRITE(DEFAULT, "Strawberry", 10) + OP_S_READ_EXPECT(a, "Strawberry", 10) - OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_STREAM_DATA_BLOCKED), + OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_STREAM_DATA_BLOCKED) - OP_S_WRITE(a, "orange", 6), - OP_C_READ_EXPECT(DEFAULT, "orange", 6), + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(DEFAULT, "orange", 6) - OP_C_WRITE(DEFAULT, "Strawberry", 10), - OP_S_READ_EXPECT(a, "Strawberry", 10), + OP_C_WRITE(DEFAULT, "Strawberry", 10) + OP_S_READ_EXPECT(a, "Strawberry", 10) - OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_STREAMS_BLOCKED_UNI), + OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_STREAMS_BLOCKED_UNI) - OP_S_WRITE(a, "orange", 6), - OP_C_READ_EXPECT(DEFAULT, "orange", 6), + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(DEFAULT, "orange", 6) - OP_C_WRITE(DEFAULT, "Strawberry", 10), - OP_S_READ_EXPECT(a, "Strawberry", 10), + OP_C_WRITE(DEFAULT, "Strawberry", 10) + OP_S_READ_EXPECT(a, "Strawberry", 10) - OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_STREAMS_BLOCKED_BIDI), + OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_STREAMS_BLOCKED_BIDI) - OP_S_WRITE(a, "orange", 6), - OP_C_READ_EXPECT(DEFAULT, "orange", 6), + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(DEFAULT, "orange", 6) - OP_C_WRITE(DEFAULT, "Strawberry", 10), - OP_S_READ_EXPECT(a, "Strawberry", 10), + OP_C_WRITE(DEFAULT, "Strawberry", 10) + OP_S_READ_EXPECT(a, "Strawberry", 10) - OP_END + OP_END }; /* 53. Fault injection - excess CRYPTO buffer size */ @@ -3653,20 +4254,20 @@ err: } static const struct script_op script_53[] = { - OP_S_SET_INJECT_PLAIN(script_53_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_53_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, 0), - OP_S_WRITE(a, "Strawberry", 10), + OP_SET_INJECT_WORD(1, 0) + OP_S_WRITE(a, "Strawberry", 10) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_CRYPTO_BUFFER_EXCEEDED, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_CRYPTO_BUFFER_EXCEEDED, 0, 0) - OP_END + OP_END }; /* 54. Fault injection - corrupted crypto stream data */ @@ -3682,87 +4283,87 @@ static int script_54_inject_handshake(struct helper *h, } static const struct script_op script_54[] = { - OP_S_SET_INJECT_HANDSHAKE(script_54_inject_handshake), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT_OR_FAIL(), + OP_S_SET_INJECT_HANDSHAKE(script_54_inject_handshake) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT_OR_FAIL() - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_CRYPTO_UNEXPECTED_MESSAGE, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_CRYPTO_UNEXPECTED_MESSAGE, 0, 0) - OP_END + OP_END }; /* 55. Fault injection - NEW_CONN_ID with >20 byte CID */ static const struct script_op script_55[] = { - OP_S_SET_INJECT_PLAIN(script_39_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_39_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(0, 2), - OP_S_WRITE(a, "orange", 5), + OP_SET_INJECT_WORD(0, 2) + OP_S_WRITE(a, "orange", 5) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0) - OP_END + OP_END }; /* 56. Fault injection - NEW_CONN_ID with seq no < retire prior to */ static const struct script_op script_56[] = { - OP_S_SET_INJECT_PLAIN(script_39_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_39_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(0, 3), - OP_S_WRITE(a, "orange", 5), + OP_SET_INJECT_WORD(0, 3) + OP_S_WRITE(a, "orange", 5) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0) - OP_END + OP_END }; /* 57. Fault injection - NEW_CONN_ID with lower seq so ignored */ static const struct script_op script_57[] = { - OP_S_SET_INJECT_PLAIN(script_39_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_39_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(0, 4), - OP_S_WRITE(a, "orange", 5), - OP_C_READ_EXPECT(a, "orange", 5), + OP_SET_INJECT_WORD(0, 4) + OP_S_WRITE(a, "orange", 5) + OP_C_READ_EXPECT(a, "orange", 5) - OP_C_WRITE(a, "Strawberry", 10), - OP_S_READ_EXPECT(a, "Strawberry", 10), + OP_C_WRITE(a, "Strawberry", 10) + OP_S_READ_EXPECT(a, "Strawberry", 10) /* * Now we send a NEW_CONN_ID with a bogus CID. However the sequence number * is old so it should be ignored and we should still be able to * communicate. */ - OP_SET_INJECT_WORD(0, 5), - OP_S_WRITE(a, "raspberry", 9), - OP_C_READ_EXPECT(a, "raspberry", 9), + OP_SET_INJECT_WORD(0, 5) + OP_S_WRITE(a, "raspberry", 9) + OP_C_READ_EXPECT(a, "raspberry", 9) - OP_C_WRITE(a, "peach", 5), - OP_S_READ_EXPECT(a, "peach", 5), + OP_C_WRITE(a, "peach", 5) + OP_S_READ_EXPECT(a, "peach", 5) - OP_END + OP_END }; /* 58. Fault injection - repeated HANDSHAKE_DONE */ @@ -3807,42 +4408,42 @@ err: } static const struct script_op script_58[] = { - OP_S_SET_INJECT_PLAIN(script_58_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_58_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, 0), + OP_SET_INJECT_WORD(1, 0) - OP_S_WRITE(a, "orange", 6), - OP_C_READ_EXPECT(DEFAULT, "orange", 6), + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(DEFAULT, "orange", 6) - OP_C_WRITE(DEFAULT, "Strawberry", 10), - OP_S_READ_EXPECT(a, "Strawberry", 10), + OP_C_WRITE(DEFAULT, "Strawberry", 10) + OP_S_READ_EXPECT(a, "Strawberry", 10) - OP_END + OP_END }; /* 59. Fault injection - multi-byte frame encoding */ static const struct script_op script_59[] = { - OP_S_SET_INJECT_PLAIN(script_58_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_S_SET_INJECT_PLAIN(script_58_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(2, 0), + OP_SET_INJECT_WORD(2, 0) - OP_S_WRITE(a, "orange", 6), + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_PROTOCOL_VIOLATION, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_PROTOCOL_VIOLATION, 0, 0) - OP_END + OP_END }; /* 60. Connection close reason truncation */ @@ -3874,18 +4475,18 @@ static int check_shutdown_reason(struct helper *h, struct helper_local *hl) } static const struct script_op script_60[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_WRITE(DEFAULT, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_WRITE(DEFAULT, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_CHECK(init_reason, 0), - OP_C_SHUTDOWN_WAIT(long_reason, 0), - OP_CHECK(check_shutdown_reason, 0), + OP_CHECK(init_reason, 0) + OP_C_SHUTDOWN_WAIT(long_reason, 0) + OP_CHECK(check_shutdown_reason, 0) - OP_END + OP_END }; /* 61. Fault injection - RESET_STREAM exceeding stream count FC */ @@ -3928,85 +4529,87 @@ err: } static const struct script_op script_61[] = { - OP_S_SET_INJECT_PLAIN(script_61_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_61_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "orange", 6), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "orange", 6) - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "orange", 6), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "orange", 6) - OP_SET_INJECT_WORD(OSSL_QUIC_FRAME_TYPE_RESET_STREAM, S_BIDI_ID(OSSL_QUIC_VLINT_MAX / 4)), - OP_S_WRITE(a, "fruit", 5), + OP_SET_INJECT_WORD(OSSL_QUIC_FRAME_TYPE_RESET_STREAM, + S_BIDI_ID(OSSL_QUIC_VLINT_MAX / 4)) + OP_S_WRITE(a, "fruit", 5) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_LIMIT_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_LIMIT_ERROR, 0, 0) - OP_END + OP_END }; /* 62. Fault injection - STOP_SENDING with high ID */ static const struct script_op script_62[] = { - OP_S_SET_INJECT_PLAIN(script_61_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_61_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "orange", 6), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "orange", 6) - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "orange", 6), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "orange", 6) - OP_SET_INJECT_WORD(OSSL_QUIC_FRAME_TYPE_STOP_SENDING, C_BIDI_ID(OSSL_QUIC_VLINT_MAX / 4)), - OP_S_WRITE(a, "fruit", 5), + OP_SET_INJECT_WORD(OSSL_QUIC_FRAME_TYPE_STOP_SENDING, + C_BIDI_ID(OSSL_QUIC_VLINT_MAX / 4)) + OP_S_WRITE(a, "fruit", 5) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_STATE_ERROR, 0, 0) - OP_END + OP_END }; /* 63. Fault injection - STREAM frame exceeding stream limit */ static const struct script_op script_63[] = { - OP_S_SET_INJECT_PLAIN(script_32_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_32_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(S_BIDI_ID(5000) + 1, 4), - OP_S_WRITE(a, "orange", 6), + OP_SET_INJECT_WORD(S_BIDI_ID(5000) + 1, 4) + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_LIMIT_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_STREAM_LIMIT_ERROR, 0, 0) - OP_END + OP_END }; /* 64. Fault injection - STREAM - zero-length no-FIN is accepted */ static const struct script_op script_64[] = { - OP_S_SET_INJECT_PLAIN(script_32_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_32_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_S_NEW_STREAM_UNI(a, S_UNI_ID(0)), - OP_S_WRITE(a, "apple", 5), + OP_S_NEW_STREAM_UNI(a, S_UNI_ID(0)) + OP_S_WRITE(a, "apple", 5) - OP_C_ACCEPT_STREAM_WAIT(a), - OP_C_READ_EXPECT(a, "apple", 5), + OP_C_ACCEPT_STREAM_WAIT(a) + OP_C_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(S_BIDI_ID(20) + 1, 1), - OP_S_WRITE(a, "orange", 6), - OP_C_READ_EXPECT(a, "orange", 6), + OP_SET_INJECT_WORD(S_BIDI_ID(20) + 1, 1) + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(a, "orange", 6) - OP_END + OP_END }; /* 65. Fault injection - CRYPTO - zero-length is accepted */ @@ -4048,22 +4651,22 @@ err: } static const struct script_op script_65[] = { - OP_S_SET_INJECT_PLAIN(script_65_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_65_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, 0), - OP_S_WRITE(a, "orange", 6), - OP_C_READ_EXPECT(a, "orange", 6), + OP_SET_INJECT_WORD(1, 0) + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(a, "orange", 6) - OP_END + OP_END }; /* 66. Fault injection - large MAX_STREAM_DATA */ @@ -4109,46 +4712,46 @@ err: } static const struct script_op script_66[] = { - OP_S_SET_INJECT_PLAIN(script_66_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_66_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_S_NEW_STREAM_BIDI(a, S_BIDI_ID(0)), - OP_S_WRITE(a, "apple", 5), + OP_S_NEW_STREAM_BIDI(a, S_BIDI_ID(0)) + OP_S_WRITE(a, "apple", 5) - OP_C_ACCEPT_STREAM_WAIT(a), - OP_C_READ_EXPECT(a, "apple", 5), + OP_C_ACCEPT_STREAM_WAIT(a) + OP_C_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(S_BIDI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_MAX_STREAM_DATA), - OP_S_WRITE(a, "orange", 6), - OP_C_READ_EXPECT(a, "orange", 6), - OP_C_WRITE(a, "Strawberry", 10), - OP_S_READ_EXPECT(a, "Strawberry", 10), + OP_SET_INJECT_WORD(S_BIDI_ID(0) + 1, OSSL_QUIC_FRAME_TYPE_MAX_STREAM_DATA) + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(a, "orange", 6) + OP_C_WRITE(a, "Strawberry", 10) + OP_S_READ_EXPECT(a, "Strawberry", 10) - OP_END + OP_END }; /* 67. Fault injection - large MAX_DATA */ static const struct script_op script_67[] = { - OP_S_SET_INJECT_PLAIN(script_66_inject_plain), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_PLAIN(script_66_inject_plain) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_S_NEW_STREAM_BIDI(a, S_BIDI_ID(0)), - OP_S_WRITE(a, "apple", 5), + OP_S_NEW_STREAM_BIDI(a, S_BIDI_ID(0)) + OP_S_WRITE(a, "apple", 5) - OP_C_ACCEPT_STREAM_WAIT(a), - OP_C_READ_EXPECT(a, "apple", 5), + OP_C_ACCEPT_STREAM_WAIT(a) + OP_C_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_MAX_DATA), - OP_S_WRITE(a, "orange", 6), - OP_C_READ_EXPECT(a, "orange", 6), - OP_C_WRITE(a, "Strawberry", 10), - OP_S_READ_EXPECT(a, "Strawberry", 10), + OP_SET_INJECT_WORD(1, OSSL_QUIC_FRAME_TYPE_MAX_DATA) + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(a, "orange", 6) + OP_C_WRITE(a, "Strawberry", 10) + OP_S_READ_EXPECT(a, "Strawberry", 10) - OP_END + OP_END }; /* 68. Fault injection - Unexpected TLS messages */ @@ -4203,46 +4806,48 @@ static int script_68_inject_handshake(struct helper *h, unsigned char *msg, return 1; } -/* Send a CertificateRequest message post-handshake */ +/* Send a CerticateRequest message post-handshake */ static const struct script_op script_68[] = { - OP_S_SET_INJECT_HANDSHAKE(script_68_inject_handshake), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_HANDSHAKE(script_68_inject_handshake) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(1, 0), - OP_S_NEW_TICKET(), - OP_S_WRITE(a, "orange", 6), + OP_SET_INJECT_WORD(1, 0) + OP_S_NEW_TICKET() + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_PROTOCOL_VIOLATION, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_PROTOCOL_VIOLATION, 0, 0) - OP_END + OP_END }; /* 69. Send a TLS KeyUpdate message post-handshake */ static const struct script_op script_69[] = { - OP_S_SET_INJECT_HANDSHAKE(script_68_inject_handshake), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_S_SET_INJECT_HANDSHAKE(script_68_inject_handshake) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_SET_INJECT_WORD(2, 0), - OP_S_NEW_TICKET(), - OP_S_WRITE(a, "orange", 6), + OP_SET_INJECT_WORD(2, 0) + OP_S_NEW_TICKET() + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_CRYPTO_ERR_BEGIN + SSL_AD_UNEXPECTED_MESSAGE, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_CRYPTO_ERR_BEGIN + + SSL_AD_UNEXPECTED_MESSAGE, + 0, 0) - OP_END + OP_END }; static int set_max_early_data(struct helper *h, struct helper_local *hl) @@ -4257,41 +4862,41 @@ static int set_max_early_data(struct helper *h, struct helper_local *hl) /* 70. Send a TLS NewSessionTicket message with invalid max_early_data */ static const struct script_op script_70[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_CHECK(set_max_early_data, 0xfffffffe), - OP_S_NEW_TICKET(), - OP_S_WRITE(a, "orange", 6), + OP_CHECK(set_max_early_data, 0xfffffffe) + OP_S_NEW_TICKET() + OP_S_WRITE(a, "orange", 6) - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_PROTOCOL_VIOLATION, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_PROTOCOL_VIOLATION, 0, 0) - OP_END + OP_END }; /* 71. Send a TLS NewSessionTicket message with valid max_early_data */ static const struct script_op script_71[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_CHECK(set_max_early_data, 0xffffffff), - OP_S_NEW_TICKET(), - OP_S_WRITE(a, "orange", 6), - OP_C_READ_EXPECT(a, "orange", 6), + OP_CHECK(set_max_early_data, 0xffffffff) + OP_S_NEW_TICKET() + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(a, "orange", 6) - OP_END + OP_END }; /* 72. Test that APL stops handing out streams after limit reached (bidi) */ @@ -4304,50 +4909,50 @@ static int script_72_check(struct helper *h, struct helper_local *hl) } static const struct script_op script_72[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) /* * Request more streams than a server will initially hand out and test that * they fail properly. */ - OP_BEGIN_REPEAT(200), + OP_BEGIN_REPEAT(200) - OP_C_NEW_STREAM_BIDI_EX(a, ANY_ID, ALLOW_FAIL | SSL_STREAM_FLAG_NO_BLOCK), - OP_C_SKIP_IF_UNBOUND(a, 2), - OP_C_WRITE(a, "apple", 5), - OP_C_FREE_STREAM(a), + OP_C_NEW_STREAM_BIDI_EX(a, ANY_ID, ALLOW_FAIL | SSL_STREAM_FLAG_NO_BLOCK) + OP_C_SKIP_IF_UNBOUND(a, 2) + OP_C_WRITE(a, "apple", 5) + OP_C_FREE_STREAM(a) - OP_END_REPEAT(), + OP_END_REPEAT() - OP_CHECK(script_72_check, 0), + OP_CHECK(script_72_check, 0) - OP_END + OP_END }; /* 73. Test that APL stops handing out streams after limit reached (uni) */ static const struct script_op script_73[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) /* * Request more streams than a server will initially hand out and test that * they fail properly. */ - OP_BEGIN_REPEAT(200), + OP_BEGIN_REPEAT(200) - OP_C_NEW_STREAM_UNI_EX(a, ANY_ID, ALLOW_FAIL | SSL_STREAM_FLAG_NO_BLOCK), - OP_C_SKIP_IF_UNBOUND(a, 2), - OP_C_WRITE(a, "apple", 5), - OP_C_FREE_STREAM(a), + OP_C_NEW_STREAM_UNI_EX(a, ANY_ID, ALLOW_FAIL | SSL_STREAM_FLAG_NO_BLOCK) + OP_C_SKIP_IF_UNBOUND(a, 2) + OP_C_WRITE(a, "apple", 5) + OP_C_FREE_STREAM(a) - OP_END_REPEAT(), + OP_END_REPEAT() - OP_CHECK(script_72_check, 0), + OP_CHECK(script_72_check, 0) - OP_END + OP_END }; /* 74. Version negotiation: QUIC_VERSION_1 ignored */ @@ -4475,31 +5080,31 @@ static int script_74_arm_packet_mutator(struct helper *h, } static const struct script_op script_74[] = { - OP_CHECK(script_74_arm_packet_mutator, 0), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_CHECK(script_74_arm_packet_mutator, 0) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_END + OP_END }; /* 75. Version negotiation: Unknown version causes connection abort */ static const struct script_op script_75[] = { - OP_S_SET_INJECT_DATAGRAM(server_gen_version_neg), - OP_SET_INJECT_WORD(2, 0), + OP_S_SET_INJECT_DATAGRAM(server_gen_version_neg) + OP_SET_INJECT_WORD(2, 0) - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT_OR_FAIL(), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT_OR_FAIL() - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_CONNECTION_REFUSED, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_CONNECTION_REFUSED, 0, 0) - OP_END + OP_END }; /* 76. Test peer-initiated shutdown wait */ @@ -4515,45 +5120,45 @@ static int script_76_check(struct helper *h, struct helper_local *hl) } static const struct script_op script_76[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) /* Check a WAIT_PEER call doesn't succeed yet. */ - OP_CHECK(script_76_check, 0), - OP_S_SHUTDOWN(42), + OP_CHECK(script_76_check, 0) + OP_S_SHUTDOWN(42) - OP_C_SHUTDOWN_WAIT(NULL, SSL_SHUTDOWN_FLAG_WAIT_PEER), - OP_C_EXPECT_CONN_CLOSE_INFO(42, 1, 1), + OP_C_SHUTDOWN_WAIT(NULL, SSL_SHUTDOWN_FLAG_WAIT_PEER) + OP_C_EXPECT_CONN_CLOSE_INFO(42, 1, 1) - OP_END + OP_END }; /* 77. Ensure default stream popping operates correctly */ static const struct script_op script_77[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_SET_INCOMING_STREAM_POLICY(SSL_INCOMING_STREAM_POLICY_ACCEPT), + OP_C_SET_INCOMING_STREAM_POLICY(SSL_INCOMING_STREAM_POLICY_ACCEPT) - OP_S_NEW_STREAM_BIDI(a, S_BIDI_ID(0)), - OP_S_WRITE(a, "Strawberry", 10), + OP_S_NEW_STREAM_BIDI(a, S_BIDI_ID(0)) + OP_S_WRITE(a, "Strawberry", 10) - OP_C_READ_EXPECT(DEFAULT, "Strawberry", 10), + OP_C_READ_EXPECT(DEFAULT, "Strawberry", 10) - OP_S_NEW_STREAM_BIDI(b, S_BIDI_ID(1)), - OP_S_WRITE(b, "xyz", 3), + OP_S_NEW_STREAM_BIDI(b, S_BIDI_ID(1)) + OP_S_WRITE(b, "xyz", 3) - OP_C_ACCEPT_STREAM_WAIT(b), - OP_C_READ_EXPECT(b, "xyz", 3), + OP_C_ACCEPT_STREAM_WAIT(b) + OP_C_READ_EXPECT(b, "xyz", 3) - OP_END + OP_END }; /* 78. Post-connection session ticket handling */ @@ -4593,44 +5198,46 @@ static int check_got_session_ticket(struct helper *h, struct helper_local *hl) static int check_idle_timeout(struct helper *h, struct helper_local *hl); static const struct script_op script_78[] = { - OP_C_SET_ALPN("ossltest"), - OP_CHECK(setup_session, 0), - OP_C_CONNECT_WAIT(), + OP_C_SET_ALPN("ossltest") + OP_CHECK(setup_session, 0) + OP_C_CONNECT_WAIT() - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) - OP_S_WRITE(a, "orange", 6), - OP_C_READ_EXPECT(a, "orange", 6), + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(a, "orange", 6) - OP_CHECK(trigger_late_session_ticket, 0), + OP_CHECK(trigger_late_session_ticket, 0) - OP_S_WRITE(a, "Strawberry", 10), - OP_C_READ_EXPECT(a, "Strawberry", 10), + OP_S_WRITE(a, "Strawberry", 10) + OP_C_READ_EXPECT(a, "Strawberry", 10) - OP_CHECK(check_got_session_ticket, 0), OP_CHECK2(check_idle_timeout, SSL_VALUE_CLASS_FEATURE_NEGOTIATED, 30000), + OP_CHECK(check_got_session_ticket, 0) + OP_CHECK2(check_idle_timeout, + SSL_VALUE_CLASS_FEATURE_NEGOTIATED, 30000) - OP_END + OP_END }; /* 79. Optimised FIN test */ static const struct script_op script_79[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_WRITE_EX2(DEFAULT, "apple", 5, SSL_WRITE_FLAG_CONCLUDE), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), - OP_S_EXPECT_FIN(a), - OP_S_WRITE(a, "orange", 6), - OP_S_CONCLUDE(a), - OP_C_READ_EXPECT(DEFAULT, "orange", 6), - OP_C_EXPECT_FIN(DEFAULT), - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_WRITE_EX2(DEFAULT, "apple", 5, SSL_WRITE_FLAG_CONCLUDE) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) + OP_S_EXPECT_FIN(a) + OP_S_WRITE(a, "orange", 6) + OP_S_CONCLUDE(a) + OP_C_READ_EXPECT(DEFAULT, "orange", 6) + OP_C_EXPECT_FIN(DEFAULT) + OP_END }; /* 80. Stateless reset detection test */ @@ -4733,40 +5340,41 @@ static int script_80_inject_pkt(struct helper *h, QUIC_PKT_HDR *hdr, } static const struct script_op script_80[] = { - OP_S_SET_INJECT_PLAIN(script_80_inject_pkt), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_WRITE(DEFAULT, "apple", 5), - OP_C_CONCLUDE(DEFAULT), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), - OP_SET_INJECT_WORD(1, 0), - OP_S_WRITE(a, "apple", 5), - OP_C_READ_EXPECT(DEFAULT, "apple", 5), - OP_SET_INJECT_WORD(0, 1), - OP_S_WRITE(a, "apple", 5), - OP_C_EXPECT_CONN_CLOSE_INFO(0, 0, 1), - OP_END + OP_S_SET_INJECT_PLAIN(script_80_inject_pkt) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_WRITE(DEFAULT, "apple", 5) + OP_C_CONCLUDE(DEFAULT) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) + OP_SET_INJECT_WORD(1, 0) + OP_S_WRITE(a, "apple", 5) + OP_C_READ_EXPECT(DEFAULT, "apple", 5) + OP_SET_INJECT_WORD(0, 1) + OP_S_WRITE(a, "apple", 5) + OP_C_EXPECT_CONN_CLOSE_INFO(0, 0, 1) + OP_END }; -static int modify_static_tp(struct helper *h, struct helper_local *hl, int ssl_value) +/* 81. Idle timeout configuration */ +static int modify_idle_timeout(struct helper *h, struct helper_local *hl) { uint64_t v = 0; /* Test bad value is rejected. */ if (!TEST_false(SSL_set_feature_request_uint(h->c_conn, - ssl_value, - OSSL_QUIC_VLINT_MAX + 1))) + SSL_VALUE_QUIC_IDLE_TIMEOUT, + (1ULL << 62)))) return 0; /* Set value. */ if (!TEST_true(SSL_set_feature_request_uint(h->c_conn, - ssl_value, + SSL_VALUE_QUIC_IDLE_TIMEOUT, hl->check_op->arg2))) return 0; if (!TEST_true(SSL_get_feature_request_uint(h->c_conn, - ssl_value, + SSL_VALUE_QUIC_IDLE_TIMEOUT, &v))) return 0; @@ -4776,95 +5384,85 @@ static int modify_static_tp(struct helper *h, struct helper_local *hl, int ssl_v return 1; } -static int check_static_tp(struct helper *h, struct helper_local *hl, int ssl_value) -{ - uint64_t v = 0; - - if (!TEST_true(SSL_get_value_uint(h->c_conn, (uint32_t)hl->check_op->arg1, - ssl_value, - &v))) - return 0; - - if (!TEST_uint64_t_eq(v, hl->check_op->arg2)) - return 0; - - return 1; -} - -static int cannot_change_static_tp(struct helper *h, struct helper_local *hl, int ssl_value) -{ - uint64_t v = 0; - - if (!TEST_true(SSL_get_feature_request_uint(h->c_conn, - ssl_value, - &v))) - return 0; - - if (!TEST_uint64_t_eq(v, hl->check_op->arg1)) - return 0; - - if (!TEST_false(SSL_set_feature_request_uint(h->c_conn, - ssl_value, - hl->check_op->arg2))) - return 0; - - return 1; -} - -static int modify_idle_timeout(struct helper *h, struct helper_local *hl) -{ - return modify_static_tp(h, hl, SSL_VALUE_QUIC_IDLE_TIMEOUT); -} - static int check_idle_timeout(struct helper *h, struct helper_local *hl) { - return check_static_tp(h, hl, SSL_VALUE_QUIC_IDLE_TIMEOUT); + uint64_t v = 0; + + if (!TEST_true(SSL_get_value_uint(h->c_conn, (uint32_t)hl->check_op->arg1, + SSL_VALUE_QUIC_IDLE_TIMEOUT, + &v))) + return 0; + + if (!TEST_uint64_t_eq(v, hl->check_op->arg2)) + return 0; + + return 1; } -static int cannot_change_idle_timeout(struct helper *h, struct helper_local *hl) -{ - return cannot_change_static_tp(h, hl, SSL_VALUE_QUIC_IDLE_TIMEOUT); -} - -/* 81. Idle timeout configuration */ static const struct script_op script_81[] = { - OP_C_SET_ALPN("ossltest"), - OP_CHECK(modify_idle_timeout, 25000), - OP_C_CONNECT_WAIT(), + OP_C_SET_ALPN("ossltest") + OP_CHECK(modify_idle_timeout, 25000) + OP_C_CONNECT_WAIT() - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_CHECK2(check_idle_timeout, SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, 30000), - OP_CHECK2(check_idle_timeout, SSL_VALUE_CLASS_FEATURE_NEGOTIATED, 25000), + OP_CHECK2(check_idle_timeout, + SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, 30000) + OP_CHECK2(check_idle_timeout, + SSL_VALUE_CLASS_FEATURE_NEGOTIATED, 25000) - OP_END + OP_END }; /* 82. Negotiated default idle timeout if not configured */ static const struct script_op script_82[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_CHECK2(check_idle_timeout, SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, 30000), - OP_CHECK2(check_idle_timeout, SSL_VALUE_CLASS_FEATURE_NEGOTIATED, 30000), + OP_CHECK2(check_idle_timeout, + SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, 30000) + OP_CHECK2(check_idle_timeout, + SSL_VALUE_CLASS_FEATURE_NEGOTIATED, 30000) - OP_END + OP_END }; /* 83. No late changes to idle timeout */ +static int cannot_change_idle_timeout(struct helper *h, struct helper_local *hl) +{ + uint64_t v = 0; + + if (!TEST_true(SSL_get_feature_request_uint(h->c_conn, + SSL_VALUE_QUIC_IDLE_TIMEOUT, + &v))) + return 0; + + if (!TEST_uint64_t_eq(v, 30000)) + return 0; + + if (!TEST_false(SSL_set_feature_request_uint(h->c_conn, + SSL_VALUE_QUIC_IDLE_TIMEOUT, + 5000))) + return 0; + + return 1; +} + static const struct script_op script_83[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_CHECK2(cannot_change_idle_timeout, 30000, 5000), - OP_CHECK2(check_idle_timeout, SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, 30000), - OP_CHECK2(check_idle_timeout, SSL_VALUE_CLASS_FEATURE_NEGOTIATED, 30000), + OP_CHECK(cannot_change_idle_timeout, 0) + OP_CHECK2(check_idle_timeout, + SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, 30000) + OP_CHECK2(check_idle_timeout, + SSL_VALUE_CLASS_FEATURE_NEGOTIATED, 30000) - OP_END + OP_END }; /* 84. Test query of available streams */ @@ -4925,65 +5523,66 @@ static int check_write_buf_stat(struct helper *h, struct helper_local *hl) } static const struct script_op script_84[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_CHECK2(check_avail_streams, 0, 100), - OP_CHECK2(check_avail_streams, 1, 100), - OP_CHECK2(check_avail_streams, 2, 100), - OP_CHECK2(check_avail_streams, 3, 100), + OP_CHECK2(check_avail_streams, 0, 100) + OP_CHECK2(check_avail_streams, 1, 100) + OP_CHECK2(check_avail_streams, 2, 100) + OP_CHECK2(check_avail_streams, 3, 100) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) - OP_CHECK2(check_avail_streams, 0, 99), - OP_CHECK2(check_avail_streams, 1, 100), - OP_CHECK2(check_avail_streams, 2, 100), - OP_CHECK2(check_avail_streams, 3, 100), + OP_CHECK2(check_avail_streams, 0, 99) + OP_CHECK2(check_avail_streams, 1, 100) + OP_CHECK2(check_avail_streams, 2, 100) + OP_CHECK2(check_avail_streams, 3, 100) - OP_C_NEW_STREAM_UNI(b, C_UNI_ID(0)), + OP_C_NEW_STREAM_UNI(b, C_UNI_ID(0)) - OP_CHECK2(check_avail_streams, 0, 99), - OP_CHECK2(check_avail_streams, 1, 100), - OP_CHECK2(check_avail_streams, 2, 99), - OP_CHECK2(check_avail_streams, 3, 100), + OP_CHECK2(check_avail_streams, 0, 99) + OP_CHECK2(check_avail_streams, 1, 100) + OP_CHECK2(check_avail_streams, 2, 99) + OP_CHECK2(check_avail_streams, 3, 100) - OP_S_NEW_STREAM_BIDI(c, S_BIDI_ID(0)), - OP_S_WRITE(c, "x", 1), + OP_S_NEW_STREAM_BIDI(c, S_BIDI_ID(0)) + OP_S_WRITE(c, "x", 1) - OP_C_ACCEPT_STREAM_WAIT(c), - OP_C_READ_EXPECT(c, "x", 1), + OP_C_ACCEPT_STREAM_WAIT(c) + OP_C_READ_EXPECT(c, "x", 1) - OP_CHECK2(check_avail_streams, 0, 99), - OP_CHECK2(check_avail_streams, 1, 99), - OP_CHECK2(check_avail_streams, 2, 99), - OP_CHECK2(check_avail_streams, 3, 100), + OP_CHECK2(check_avail_streams, 0, 99) + OP_CHECK2(check_avail_streams, 1, 99) + OP_CHECK2(check_avail_streams, 2, 99) + OP_CHECK2(check_avail_streams, 3, 100) - OP_S_NEW_STREAM_UNI(d, S_UNI_ID(0)), - OP_S_WRITE(d, "x", 1), + OP_S_NEW_STREAM_UNI(d, S_UNI_ID(0)) + OP_S_WRITE(d, "x", 1) - OP_C_ACCEPT_STREAM_WAIT(d), - OP_C_READ_EXPECT(d, "x", 1), + OP_C_ACCEPT_STREAM_WAIT(d) + OP_C_READ_EXPECT(d, "x", 1) - OP_CHECK2(check_avail_streams, 0, 99), - OP_CHECK2(check_avail_streams, 1, 99), - OP_CHECK2(check_avail_streams, 2, 99), - OP_CHECK2(check_avail_streams, 3, 99), + OP_CHECK2(check_avail_streams, 0, 99) + OP_CHECK2(check_avail_streams, 1, 99) + OP_CHECK2(check_avail_streams, 2, 99) + OP_CHECK2(check_avail_streams, 3, 99) - OP_CHECK2(check_write_buf_stat, 0, 0), - OP_CHECK(set_event_handling_mode_conn, SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT), - OP_C_WRITE(a, "apple", 5), - OP_CHECK2(check_write_buf_stat, 5, 0), + OP_CHECK2(check_write_buf_stat, 0, 0) + OP_CHECK(set_event_handling_mode_conn, + SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT) + OP_C_WRITE(a, "apple", 5) + OP_CHECK2(check_write_buf_stat, 5, 0) - OP_CHECK(reenable_test_event_handling, 0), + OP_CHECK(reenable_test_event_handling, 0) - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), - OP_S_WRITE(a, "orange", 6), - OP_C_READ_EXPECT(a, "orange", 6), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(a, "orange", 6) - OP_END + OP_END }; /* 85. Test SSL_poll (lite, non-blocking) */ @@ -5072,59 +5671,59 @@ ossl_unused static int script_85_poll(struct helper *h, struct helper_local *hl) } static const struct script_op script_85[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "flamingo", 8), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "flamingo", 8) - OP_C_NEW_STREAM_BIDI(b, C_BIDI_ID(1)), - OP_C_WRITE(b, "orange", 6), + OP_C_NEW_STREAM_BIDI(b, C_BIDI_ID(1)) + OP_C_WRITE(b, "orange", 6) - OP_C_NEW_STREAM_BIDI(c, C_BIDI_ID(2)), - OP_C_WRITE(c, "Strawberry", 10), + OP_C_NEW_STREAM_BIDI(c, C_BIDI_ID(2)) + OP_C_WRITE(c, "Strawberry", 10) - OP_C_NEW_STREAM_BIDI(d, C_BIDI_ID(3)), - OP_C_WRITE(d, "sync", 4), + OP_C_NEW_STREAM_BIDI(d, C_BIDI_ID(3)) + OP_C_WRITE(d, "sync", 4) - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_BIND_STREAM_ID(b, C_BIDI_ID(1)), - OP_S_BIND_STREAM_ID(c, C_BIDI_ID(2)), - OP_S_BIND_STREAM_ID(d, C_BIDI_ID(3)), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_BIND_STREAM_ID(b, C_BIDI_ID(1)) + OP_S_BIND_STREAM_ID(c, C_BIDI_ID(2)) + OP_S_BIND_STREAM_ID(d, C_BIDI_ID(3)) /* Check nothing readable yet. */ - OP_CHECK(script_85_poll, 0), + OP_CHECK(script_85_poll, 0) /* Send something that will make client sockets readable. */ - OP_S_READ_EXPECT(a, "flamingo", 8), - OP_S_WRITE(a, "herringbone", 11), + OP_S_READ_EXPECT(a, "flamingo", 8) + OP_S_WRITE(a, "herringbone", 11) /* Send something that will make 'b' reset. */ - OP_S_SET_INJECT_PLAIN(script_28_inject_plain), - OP_SET_INJECT_WORD(C_BIDI_ID(1) + 1, OSSL_QUIC_FRAME_TYPE_RESET_STREAM), + OP_S_SET_INJECT_PLAIN(script_28_inject_plain) + OP_SET_INJECT_WORD(C_BIDI_ID(1) + 1, OSSL_QUIC_FRAME_TYPE_RESET_STREAM) /* Ensure sync. */ - OP_S_READ_EXPECT(d, "sync", 4), - OP_S_WRITE(d, "x", 1), - OP_C_READ_EXPECT(d, "x", 1), + OP_S_READ_EXPECT(d, "sync", 4) + OP_S_WRITE(d, "x", 1) + OP_C_READ_EXPECT(d, "x", 1) /* Send something that will make 'c' reset. */ - OP_S_SET_INJECT_PLAIN(script_28_inject_plain), - OP_SET_INJECT_WORD(C_BIDI_ID(2) + 1, OSSL_QUIC_FRAME_TYPE_STOP_SENDING), + OP_S_SET_INJECT_PLAIN(script_28_inject_plain) + OP_SET_INJECT_WORD(C_BIDI_ID(2) + 1, OSSL_QUIC_FRAME_TYPE_STOP_SENDING) - OP_S_NEW_STREAM_BIDI(z, S_BIDI_ID(0)), - OP_S_WRITE(z, "z", 1), + OP_S_NEW_STREAM_BIDI(z, S_BIDI_ID(0)) + OP_S_WRITE(z, "z", 1) /* Ensure sync. */ - OP_S_WRITE(d, "x", 1), - OP_C_READ_EXPECT(d, "x", 1), + OP_S_WRITE(d, "x", 1) + OP_C_READ_EXPECT(d, "x", 1) /* Check a is now readable. */ - OP_CHECK(script_85_poll, 1), + OP_CHECK(script_85_poll, 1) - OP_END + OP_END }; #define POLL_FMT "%s%s%s%s%s%s%s%s%s%s%s%s%s" @@ -5266,36 +5865,36 @@ ossl_unused static int script_88_poll_conly(struct helper *h, struct helper_loca * to notify client it's time to call SSL_shutdown(). */ static const struct script_op script_88[] = { - OP_SKIP_IF_BLOCKING(16), - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_SKIP_IF_BLOCKING(16) + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) /* Check nothing readable yet. */ - OP_CHECK(script_88_poll, 0 /* ->arg2 */), + OP_CHECK(script_88_poll, 0 /* ->arg2 */) - OP_C_WRITE(a, "flamingo", 8), - OP_C_CONCLUDE(a), + OP_C_WRITE(a, "flamingo", 8) + OP_C_CONCLUDE(a) /* Send something that will make client sockets readable. */ - OP_S_READ_EXPECT(a, "flamingo", 8), - OP_S_WRITE(a, "flamingo", 8), - OP_S_CONCLUDE(a), + OP_S_READ_EXPECT(a, "flamingo", 8) + OP_S_WRITE(a, "flamingo", 8) + OP_S_CONCLUDE(a) - OP_CHECK(script_88_poll, 1 /* ->arg2 */), + OP_CHECK(script_88_poll, 1 /* ->arg2 */) - OP_C_READ_EXPECT(a, "flamingo", 8), + OP_C_READ_EXPECT(a, "flamingo", 8) /* * client calls non-blocking SSL_shutdown() and gives * server chance to run by calling sleep. */ - OP_C_SHUTDOWN(NULL, 0), - OP_SLEEP(100), + OP_C_SHUTDOWN(NULL, 0) + OP_SLEEP(100) /* * Here we call SSL_poll() and handle SSL_POLL_EVENT_EC @@ -5305,9 +5904,9 @@ static const struct script_op script_88[] = { * SSL_poll() signals SSL_POLL_EVENT_ECD to let us know connection * has dried out and con be closed. */ - OP_CHECK(script_88_poll_conly, 0), + OP_CHECK(script_88_poll_conly, 0) - OP_END + OP_END }; /* 86. Event Handling Mode Configuration */ static int set_event_handling_mode_conn(struct helper *h, struct helper_local *hl) @@ -5333,31 +5932,34 @@ static ossl_unused int set_event_handling_mode_stream(struct helper *h, struct h } static const struct script_op script_86[] = { - OP_SKIP_IF_BLOCKING(23), + OP_SKIP_IF_BLOCKING(23) - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), + OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE) /* Turn on explicit handling mode. */ - OP_CHECK(set_event_handling_mode_conn, SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT), + OP_CHECK(set_event_handling_mode_conn, + SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT) /* * Create a new stream and write data. This won't get sent * to the network net because we are in explicit mode * and we haven't called SSL_handle_events(). */ - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) /* Put connection back into implicit handling mode. */ - OP_CHECK(set_event_handling_mode_conn, SSL_VALUE_EVENT_HANDLING_MODE_IMPLICIT), + OP_CHECK(set_event_handling_mode_conn, + SSL_VALUE_EVENT_HANDLING_MODE_IMPLICIT) /* Override at stream level. */ - OP_CHECK(set_event_handling_mode_stream, SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT), - OP_C_WRITE(a, "orange", 6), - OP_C_CONCLUDE(a), + OP_CHECK(set_event_handling_mode_stream, + SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT) + OP_C_WRITE(a, "orange", 6) + OP_C_CONCLUDE(a) /* * Confirm the data isn't going to arrive. OP_SLEEP is always undesirable @@ -5366,417 +5968,48 @@ static const struct script_op script_86[] = { * signals arriving from the peer which could be used for synchronisation. * Slow OSes will pass this anyway (fail-open). */ - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) - OP_BEGIN_REPEAT(20), - OP_S_READ_FAIL(a, 1), - OP_SLEEP(10), - OP_END_REPEAT(), + OP_BEGIN_REPEAT(20) + OP_S_READ_FAIL(a, 1) + OP_SLEEP(10) + OP_END_REPEAT() /* Now let the data arrive and confirm it arrives. */ - OP_CHECK(reenable_test_event_handling, 0), - OP_S_READ_EXPECT(a, "appleorange", 11), - OP_S_EXPECT_FIN(a), + OP_CHECK(reenable_test_event_handling, 0) + OP_S_READ_EXPECT(a, "appleorange", 11) + OP_S_EXPECT_FIN(a) /* Back into explicit mode. */ OP_CHECK(set_event_handling_mode_conn, - SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT), - OP_S_WRITE(a, "ok", 2), - OP_C_READ_FAIL(a), + SSL_VALUE_EVENT_HANDLING_MODE_EXPLICIT) + OP_S_WRITE(a, "ok", 2) + OP_C_READ_FAIL(a) /* Works once event handling is done. */ - OP_CHECK(reenable_test_event_handling, 0), - OP_C_READ_EXPECT(a, "ok", 2), + OP_CHECK(reenable_test_event_handling, 0) + OP_C_READ_EXPECT(a, "ok", 2) - OP_END + OP_END }; /* 87. Test stream reset functionality */ static const struct script_op script_87[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)), - OP_C_WRITE(a, "apple", 5), - OP_C_CONCLUDE(a), - OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)), - OP_S_READ_EXPECT(a, "apple", 5), - OP_S_EXPECT_FIN(a), - OP_S_WRITE(a, "orange", 6), - OP_C_READ_EXPECT(a, "orange", 6), - OP_S_CONCLUDE(a), - OP_C_EXPECT_FIN(a), - OP_SLEEP(1000), - OP_C_STREAM_RESET_FAIL(a, 42), - OP_END -}; - -static int modify_udp_payload_size_max(struct helper *h, struct helper_local *hl) -{ - if (!TEST_false(SSL_set_feature_request_uint(h->c_conn, - SSL_VALUE_QUIC_UDP_PAYLOAD_SIZE_MAX, - QUIC_MIN_INITIAL_DGRAM_LEN - 1))) - return 0; - - if (!TEST_false(SSL_set_feature_request_uint(h->c_conn, - SSL_VALUE_QUIC_UDP_PAYLOAD_SIZE_MAX, - QUIC_DEFAULT_MAX_UDP_PAYLOAD_SIZE + 1))) - return 0; - - return modify_static_tp(h, hl, SSL_VALUE_QUIC_UDP_PAYLOAD_SIZE_MAX); -} - -static int check_udp_payload_size_max(struct helper *h, struct helper_local *hl) -{ - return check_static_tp(h, hl, SSL_VALUE_QUIC_UDP_PAYLOAD_SIZE_MAX); -} - -static int cannot_change_udp_payload_size_max(struct helper *h, struct helper_local *hl) -{ - return cannot_change_static_tp(h, hl, SSL_VALUE_QUIC_UDP_PAYLOAD_SIZE_MAX); -} - -/* 89. Max udp payload size configuration */ -static const struct script_op script_89[] = { - OP_C_SET_ALPN("ossltest"), - OP_CHECK(modify_udp_payload_size_max, QUIC_DEFAULT_MAX_UDP_PAYLOAD_SIZE), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(check_udp_payload_size_max, - SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, QUIC_MIN_INITIAL_DGRAM_LEN), - OP_CHECK2(check_udp_payload_size_max, - SSL_VALUE_CLASS_FEATURE_REQUEST, QUIC_DEFAULT_MAX_UDP_PAYLOAD_SIZE), - - OP_END -}; - -/* 90. Negotiated default max udp payload size if not configured */ -static const struct script_op script_90[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(check_udp_payload_size_max, - SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, QUIC_MIN_INITIAL_DGRAM_LEN), - OP_CHECK2(check_udp_payload_size_max, - SSL_VALUE_CLASS_FEATURE_REQUEST, QUIC_MIN_INITIAL_DGRAM_LEN), - - OP_END -}; - -/* 91. No late changes to max udp payload size */ -static const struct script_op script_91[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(cannot_change_udp_payload_size_max, QUIC_MIN_INITIAL_DGRAM_LEN, - QUIC_DEFAULT_MAX_UDP_PAYLOAD_SIZE), - OP_CHECK2(check_udp_payload_size_max, - SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, QUIC_MIN_INITIAL_DGRAM_LEN), - - OP_END -}; - -static int modify_window_con(struct helper *h, struct helper_local *hl) -{ - return modify_static_tp(h, hl, SSL_VALUE_QUIC_WINDOWCON); -} - -static int check_window_con(struct helper *h, struct helper_local *hl) -{ - return check_static_tp(h, hl, SSL_VALUE_QUIC_WINDOWCON); -} - -static int cannot_change_window_con(struct helper *h, struct helper_local *hl) -{ - return cannot_change_static_tp(h, hl, SSL_VALUE_QUIC_WINDOWCON); -} - -/* 92. Connection window configuration */ -static const struct script_op script_92[] = { - OP_C_SET_ALPN("ossltest"), - OP_CHECK(modify_window_con, 800000), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(check_window_con, SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, 768 * 1024), - OP_CHECK2(check_window_con, SSL_VALUE_CLASS_FEATURE_REQUEST, 800000), - - OP_END -}; - -/* 93. Negotiated default connection window if not configured */ -static const struct script_op script_93[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(check_window_con, SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, 768 * 1024), - OP_CHECK2(check_window_con, SSL_VALUE_CLASS_FEATURE_REQUEST, 768 * 1024), - - OP_END -}; - -/* 94. No late changes to connection window */ -static const struct script_op script_94[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(cannot_change_window_con, 768 * 1024, 800000), - OP_CHECK2(check_window_con, SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, 768 * 1024), - - OP_END -}; - -static int modify_window_bidi_stream(struct helper *h, struct helper_local *hl) -{ - return modify_static_tp(h, hl, SSL_VALUE_QUIC_WINDOWBSTR); -} - -static int check_window_bidi_stream(struct helper *h, struct helper_local *hl) -{ - return check_static_tp(h, hl, SSL_VALUE_QUIC_WINDOWBSTR); -} - -static int cannot_change_window_bidi_stream(struct helper *h, struct helper_local *hl) -{ - return cannot_change_static_tp(h, hl, SSL_VALUE_QUIC_WINDOWBSTR); -} - -/* 95. Bidi stream window configuration */ -static const struct script_op script_95[] = { - OP_C_SET_ALPN("ossltest"), - OP_CHECK(modify_window_bidi_stream, 600000), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(check_window_bidi_stream, SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, 512 * 1024), - OP_CHECK2(check_window_bidi_stream, SSL_VALUE_CLASS_FEATURE_REQUEST, 600000), - - OP_END -}; - -/* 96. Negotiated default bidi stream window if not configured */ -static const struct script_op script_96[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(check_window_bidi_stream, SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, 512 * 1024), - OP_CHECK2(check_window_bidi_stream, SSL_VALUE_CLASS_FEATURE_REQUEST, 512 * 1024), - - OP_END -}; - -/* 97. No late changes to bidi stream window */ -static const struct script_op script_97[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(cannot_change_window_bidi_stream, 512 * 1024, 600000), - OP_CHECK2(check_window_bidi_stream, SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, 512 * 1024), - - OP_END -}; - -static int modify_window_uni_stream(struct helper *h, struct helper_local *hl) -{ - return modify_static_tp(h, hl, SSL_VALUE_QUIC_WINDOWUSTR); -} - -static int check_window_uni_stream(struct helper *h, struct helper_local *hl) -{ - return check_static_tp(h, hl, SSL_VALUE_QUIC_WINDOWUSTR); -} - -static int cannot_change_window_uni_stream(struct helper *h, struct helper_local *hl) -{ - return cannot_change_static_tp(h, hl, SSL_VALUE_QUIC_WINDOWUSTR); -} - -/* 98. Uni stream window configuration */ -static const struct script_op script_98[] = { - OP_C_SET_ALPN("ossltest"), - OP_CHECK(modify_window_uni_stream, 600000), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(check_window_uni_stream, SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, 512 * 1024), - OP_CHECK2(check_window_uni_stream, SSL_VALUE_CLASS_FEATURE_REQUEST, 600000), - - OP_END -}; - -/* 99. Negotiated default uni stream window if not configured */ -static const struct script_op script_99[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(check_window_uni_stream, SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, 512 * 1024), - OP_CHECK2(check_window_uni_stream, SSL_VALUE_CLASS_FEATURE_REQUEST, 512 * 1024), - - OP_END -}; - -/* 100. No late changes to uni stream window */ -static const struct script_op script_100[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(cannot_change_window_uni_stream, 512 * 1024, 600000), - OP_CHECK2(check_window_uni_stream, SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, 512 * 1024), - - OP_END -}; - -static int -modify_ack_delay_exponent(struct helper *h, struct helper_local *hl) -{ - if (!TEST_false(SSL_set_feature_request_uint(h->c_conn, - SSL_VALUE_QUIC_ACK_DELAY_EXPONENT, - QUIC_MAX_ACK_DELAY_EXP + 1))) - return 0; - - return modify_static_tp(h, hl, SSL_VALUE_QUIC_ACK_DELAY_EXPONENT); -} - -static int check_ack_delay_exponent(struct helper *h, struct helper_local *hl) -{ - return check_static_tp(h, hl, SSL_VALUE_QUIC_ACK_DELAY_EXPONENT); -} - -static int cannot_change_ack_delay_exponent(struct helper *h, struct helper_local *hl) -{ - return cannot_change_static_tp(h, hl, SSL_VALUE_QUIC_ACK_DELAY_EXPONENT); -} - -/* 101. Ack delay exponent configuration */ -static const struct script_op script_101[] = { - OP_C_SET_ALPN("ossltest"), - OP_CHECK(modify_ack_delay_exponent, QUIC_DEFAULT_ACK_DELAY_EXP + 1), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(check_ack_delay_exponent, - SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, QUIC_DEFAULT_ACK_DELAY_EXP), - OP_CHECK2(check_ack_delay_exponent, - SSL_VALUE_CLASS_FEATURE_REQUEST, QUIC_DEFAULT_ACK_DELAY_EXP + 1), - - OP_END -}; - -/* 102. Negotiated default ack delay exponent if not configured */ -static const struct script_op script_102[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(check_ack_delay_exponent, - SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, QUIC_DEFAULT_ACK_DELAY_EXP), - OP_CHECK2(check_ack_delay_exponent, - SSL_VALUE_CLASS_FEATURE_REQUEST, QUIC_DEFAULT_ACK_DELAY_EXP), - - OP_END -}; - -/* 103. No late changes to ack delay exponent */ -static const struct script_op script_103[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(cannot_change_ack_delay_exponent, QUIC_DEFAULT_ACK_DELAY_EXP, - QUIC_DEFAULT_ACK_DELAY_EXP + 1), - OP_CHECK2(check_ack_delay_exponent, - SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, QUIC_DEFAULT_ACK_DELAY_EXP), - - OP_END -}; - -static int modify_ack_delay_max(struct helper *h, struct helper_local *hl) -{ - if (!TEST_false(SSL_set_feature_request_uint(h->c_conn, - SSL_VALUE_QUIC_ACK_DELAY_MAX, - QUIC_MAX_MAX_ACK_DELAY + 1))) - return 0; - - return modify_static_tp(h, hl, SSL_VALUE_QUIC_ACK_DELAY_MAX); -} - -static int check_ack_delay_max(struct helper *h, struct helper_local *hl) -{ - return check_static_tp(h, hl, SSL_VALUE_QUIC_ACK_DELAY_MAX); -} - -static int cannot_change_ack_delay_max(struct helper *h, struct helper_local *hl) -{ - return cannot_change_static_tp(h, hl, SSL_VALUE_QUIC_ACK_DELAY_MAX); -} - -/* 104. Max ack delay configuration */ -static const struct script_op script_104[] = { - OP_C_SET_ALPN("ossltest"), - OP_CHECK(modify_ack_delay_max, QUIC_DEFAULT_MAX_ACK_DELAY / 2), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(check_ack_delay_max, - SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, QUIC_DEFAULT_MAX_ACK_DELAY), - OP_CHECK2(check_ack_delay_max, - SSL_VALUE_CLASS_FEATURE_REQUEST, QUIC_DEFAULT_MAX_ACK_DELAY / 2), - - OP_END -}; - -/* 105. Negotiated default max ack delay if not configured */ -static const struct script_op script_105[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(check_ack_delay_max, - SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, QUIC_DEFAULT_MAX_ACK_DELAY), - OP_CHECK2(check_ack_delay_max, - SSL_VALUE_CLASS_FEATURE_REQUEST, QUIC_DEFAULT_MAX_ACK_DELAY), - - OP_END -}; - -/* 106. No late changes to max ack delay */ -static const struct script_op script_106[] = { - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT(), - - OP_C_SET_DEFAULT_STREAM_MODE(SSL_DEFAULT_STREAM_MODE_NONE), - - OP_CHECK2(cannot_change_ack_delay_max, QUIC_DEFAULT_MAX_ACK_DELAY, - QUIC_DEFAULT_MAX_ACK_DELAY / 2), - OP_CHECK2(check_ack_delay_max, - SSL_VALUE_CLASS_FEATURE_PEER_REQUEST, QUIC_DEFAULT_MAX_ACK_DELAY), - - OP_END + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT() + OP_C_NEW_STREAM_BIDI(a, C_BIDI_ID(0)) + OP_C_WRITE(a, "apple", 5) + OP_C_CONCLUDE(a) + OP_S_BIND_STREAM_ID(a, C_BIDI_ID(0)) + OP_S_READ_EXPECT(a, "apple", 5) + OP_S_EXPECT_FIN(a) + OP_S_WRITE(a, "orange", 6) + OP_C_READ_EXPECT(a, "orange", 6) + OP_S_CONCLUDE(a) + OP_C_EXPECT_FIN(a) + OP_SLEEP(1000) + OP_C_STREAM_RESET_FAIL(a, 42) + OP_END }; static const struct script_op *const scripts[] = { @@ -5868,24 +6101,6 @@ static const struct script_op *const scripts[] = { script_86, script_87, script_88, - script_89, - script_90, - script_91, - script_92, - script_93, - script_94, - script_95, - script_96, - script_97, - script_98, - script_99, - script_100, - script_101, - script_102, - script_103, - script_104, - script_105, - script_106, }; static int test_script(int idx) @@ -5921,15 +6136,15 @@ static int test_script(int idx) /* Dynamically generated tests. */ static struct script_op dyn_frame_types_script[] = { - OP_S_SET_INJECT_PLAIN(script_21_inject_plain), - OP_SET_INJECT_WORD(0, 0), /* dynamic */ + OP_S_SET_INJECT_PLAIN(script_21_inject_plain) + OP_SET_INJECT_WORD(0, 0) /* dynamic */ - OP_C_SET_ALPN("ossltest"), - OP_C_CONNECT_WAIT_OR_FAIL(), + OP_C_SET_ALPN("ossltest") + OP_C_CONNECT_WAIT_OR_FAIL() - OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0), + OP_C_EXPECT_CONN_CLOSE_INFO(OSSL_QUIC_ERR_FRAME_ENCODING_ERROR, 0, 0) - OP_END + OP_END }; struct forbidden_frame_type { diff --git a/test/quic_rcidm_test.c b/test/quic_rcidm_test.c index 1b966c93d3..619c4c3efe 100644 --- a/test/quic_rcidm_test.c +++ b/test/quic_rcidm_test.c @@ -125,41 +125,8 @@ err: return testresult; } -static int test_rcidm_mfail(void) -{ - int testresult = 0; - QUIC_RCIDM *rcidm = NULL; - OSSL_QUIC_FRAME_NEW_CONN_ID ncid = { 0 }; - uint64_t i; - - MFAIL_start(); - - rcidm = ossl_quic_rcidm_new(&cid8_1); - if (rcidm == NULL) - goto err; - - if (!ossl_quic_rcidm_add_from_initial(rcidm, &cid8_2)) - goto err; - - /* Push enough NCIDs to force at least one priority-queue grow/realloc. */ - ncid.conn_id.id_len = 8; - for (i = 2; i < 20; ++i) { - ncid.seq_num = i; - ncid.conn_id.id[0] = (unsigned char)i; - if (!ossl_quic_rcidm_add_from_ncid(rcidm, &ncid)) - goto err; - } - - testresult = 1; -err: - MFAIL_end(); - ossl_quic_rcidm_free(rcidm); - return testresult; -} - int setup_tests(void) { ADD_ALL_TESTS(test_rcidm, 3); - ADD_MFAIL_TEST(test_rcidm_mfail); return 1; } diff --git a/test/quic_record_test.c b/test/quic_record_test.c index 0c9fa3a098..4966a2f7b5 100644 --- a/test/quic_record_test.c +++ b/test/quic_record_test.c @@ -51,39 +51,39 @@ struct rx_test_op { #define RX_OP_END \ { RX_TEST_OP_END } #define RX_OP_SET_SCID_LEN(scid_len) \ - { RX_TEST_OP_SET_SCID_LEN, 0, NULL, 0, NULL, (scid_len), 0, 0, NULL, NULL } + { RX_TEST_OP_SET_SCID_LEN, 0, NULL, 0, NULL, (scid_len), 0, 0, NULL, NULL }, #define RX_OP_SET_INIT_LARGEST_PN(largest_pn) \ - { RX_TEST_OP_SET_INIT_LARGEST_PN, 0, NULL, 0, NULL, 0, 0, (largest_pn), NULL, NULL } + { RX_TEST_OP_SET_INIT_LARGEST_PN, 0, NULL, 0, NULL, 0, 0, (largest_pn), NULL, NULL }, #define RX_OP_SET_RX_DCID(dcid) \ - { RX_TEST_OP_SET_RX_DCID, 0, NULL, 0, NULL, 0, 0, 0, &(dcid), NULL } + { RX_TEST_OP_SET_RX_DCID, 0, NULL, 0, NULL, 0, 0, 0, &(dcid), NULL }, #define RX_OP_INJECT(dgram) \ - { RX_TEST_OP_INJECT, 0, (dgram), sizeof(dgram), NULL, 0, 0, 0, NULL } + { RX_TEST_OP_INJECT, 0, (dgram), sizeof(dgram), NULL, 0, 0, 0, NULL }, #define RX_OP_PROVIDE_SECRET(el, suite, key) \ { \ RX_TEST_OP_PROVIDE_SECRET, 0, (key), sizeof(key), \ NULL, (el), (suite), 0, NULL, NULL \ - } + }, #define RX_OP_PROVIDE_SECRET_INITIAL(dcid) \ - { RX_TEST_OP_PROVIDE_SECRET_INITIAL, 0, NULL, 0, NULL, 0, 0, 0, &(dcid), NULL } + { RX_TEST_OP_PROVIDE_SECRET_INITIAL, 0, NULL, 0, NULL, 0, 0, 0, &(dcid), NULL }, #define RX_OP_DISCARD_EL(el) \ - { RX_TEST_OP_DISCARD_EL, 0, NULL, 0, NULL, (el), 0, 0, NULL, NULL } + { RX_TEST_OP_DISCARD_EL, 0, NULL, 0, NULL, (el), 0, 0, NULL, NULL }, #define RX_OP_CHECK_PKT(expect_hdr, expect_body) \ { \ RX_TEST_OP_CHECK_PKT, 0, (expect_body), sizeof(expect_body), \ &(expect_hdr), 0, 0, 0, NULL, NULL \ - } + }, #define RX_OP_CHECK_NO_PKT() \ - { RX_TEST_OP_CHECK_NO_PKT, 0, NULL, 0, NULL, 0, 0, 0, NULL, NULL } + { RX_TEST_OP_CHECK_NO_PKT, 0, NULL, 0, NULL, 0, 0, 0, NULL, NULL }, #define RX_OP_CHECK_KEY_EPOCH(expected) \ - { RX_TEST_OP_CHECK_KEY_EPOCH, 0, NULL, 0, NULL, 0, 0, (expected), NULL } + { RX_TEST_OP_CHECK_KEY_EPOCH, 0, NULL, 0, NULL, 0, 0, (expected), NULL }, #define RX_OP_KEY_UPDATE_TIMEOUT(normal) \ - { RX_TEST_OP_KEY_UPDATE_TIMEOUT, 0, NULL, 0, NULL, (normal), 0, 0, NULL } + { RX_TEST_OP_KEY_UPDATE_TIMEOUT, 0, NULL, 0, NULL, (normal), 0, 0, NULL }, #define RX_OP_SET_INIT_KEY_PHASE(kp_bit) \ - { RX_TEST_OP_SET_INIT_KEY_PHASE, 0, NULL, 0, NULL, (kp_bit), 0, 0, NULL } + { RX_TEST_OP_SET_INIT_KEY_PHASE, 0, NULL, 0, NULL, (kp_bit), 0, 0, NULL }, #define RX_OP_CHECK_PKT_EPOCH(expected) \ - { RX_TEST_OP_CHECK_PKT_EPOCH, 0, NULL, 0, NULL, 0, 0, (expected), NULL } + { RX_TEST_OP_CHECK_PKT_EPOCH, 0, NULL, 0, NULL, 0, 0, (expected), NULL }, #define RX_OP_ALLOW_1RTT() \ - { RX_TEST_OP_ALLOW_1RTT, 0, NULL, 0, NULL, 0, 0, 0, NULL } + { RX_TEST_OP_ALLOW_1RTT, 0, NULL, 0, NULL, 0, 0, 0, NULL }, #define RX_OP_INJECT_N(n) \ RX_OP_INJECT(rx_script_##n##_in) @@ -91,7 +91,8 @@ struct rx_test_op { RX_OP_CHECK_PKT(rx_script_##n##_expect_hdr, rx_script_##n##_body) #define RX_OP_INJECT_CHECK(n) \ - RX_OP_INJECT_N(n), RX_OP_CHECK_PKT_N(n) + RX_OP_INJECT_N(n) \ + RX_OP_CHECK_PKT_N(n) /* 1. RFC 9001 - A.3 Server Initial */ static const unsigned char rx_script_1_in[] = { @@ -135,13 +136,13 @@ static const QUIC_PKT_HDR rx_script_1_expect_hdr = { }; static const struct rx_test_op rx_script_1[] = { - RX_OP_SET_SCID_LEN(2), - RX_OP_SET_INIT_LARGEST_PN(0), - RX_OP_SET_RX_DCID(empty_conn_id), - RX_OP_PROVIDE_SECRET_INITIAL(rx_script_1_dcid), - RX_OP_INJECT_CHECK(1), - RX_OP_CHECK_NO_PKT(), - RX_OP_END + RX_OP_SET_SCID_LEN(2) + RX_OP_SET_INIT_LARGEST_PN(0) + RX_OP_SET_RX_DCID(empty_conn_id) + RX_OP_PROVIDE_SECRET_INITIAL(rx_script_1_dcid) + RX_OP_INJECT_CHECK(1) + RX_OP_CHECK_NO_PKT() + RX_OP_END }; /* 2. RFC 9001 - A.5 ChaCha20-Poly1305 Short Header Packet */ @@ -170,13 +171,14 @@ static const QUIC_PKT_HDR rx_script_2_expect_hdr = { }; static const struct rx_test_op rx_script_2[] = { - RX_OP_ALLOW_1RTT(), - RX_OP_SET_INIT_LARGEST_PN(654360560), - RX_OP_SET_RX_DCID(empty_conn_id), - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_CHACHA20POLY1305, rx_script_2_secret), - RX_OP_INJECT_CHECK(2), - RX_OP_CHECK_NO_PKT(), - RX_OP_END + RX_OP_ALLOW_1RTT() + RX_OP_SET_INIT_LARGEST_PN(654360560) + RX_OP_SET_RX_DCID(empty_conn_id) + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_CHACHA20POLY1305, + rx_script_2_secret) + RX_OP_INJECT_CHECK(2) + RX_OP_CHECK_NO_PKT() + RX_OP_END }; #endif /* !defined(OPENSSL_NO_CHACHA) && !defined(OPENSSL_NO_POLY1305) */ @@ -216,36 +218,145 @@ static const unsigned char rx_script_3_body[] = { }; static const struct rx_test_op rx_script_3[] = { - RX_OP_SET_RX_DCID(empty_conn_id), + RX_OP_SET_RX_DCID(empty_conn_id) /* * This is a version negotiation packet, so doesn't have any frames. * However, the depacketizer still handles this sort of packet, so * we still pass the packet to it, to exercise what it does. */ - RX_OP_INJECT_CHECK(3), - RX_OP_CHECK_NO_PKT(), - RX_OP_END + RX_OP_INJECT_CHECK(3) + RX_OP_CHECK_NO_PKT() + RX_OP_END }; /* 4. Real World - Retry (S2C) */ static const unsigned char rx_script_4_in[] = { 0xf0, /* Long; Retry */ - 0x00, 0x00, 0x00, 0x01, /* Version 1 */ + 0x00, + 0x00, + 0x00, + 0x01, /* Version 1 */ 0x00, /* DCID */ - 0x04, 0xad, 0x15, 0x3f, 0xae, /* SCID */ + 0x04, + 0xad, + 0x15, + 0x3f, + 0xae, /* SCID */ /* Retry Token, including 16-byte Retry Integrity Tag */ - 0xf6, 0x8b, 0x6e, 0xa3, 0xdc, 0x40, 0x38, 0xc6, 0xa5, 0x99, - 0x1c, 0xa9, 0x77, 0xe6, 0x1d, 0x4f, 0x09, 0x36, 0x12, 0x26, - 0x00, 0x56, 0x0b, 0x29, 0x7d, 0x5e, 0xda, 0x39, 0xc6, 0x61, - 0x57, 0x69, 0x15, 0xff, 0x93, 0x39, 0x95, 0xf0, 0x57, 0xf1, - 0xe5, 0x36, 0x08, 0xad, 0xd2, 0x75, 0xa9, 0x68, 0x29, 0xed, - 0xaa, 0x03, 0x0e, 0x5f, 0xac, 0xbd, 0x26, 0x07, 0x95, 0x4e, - 0x48, 0x61, 0x26, 0xc5, 0xe2, 0x6c, 0x60, 0xbf, 0xa8, 0x6f, - 0x51, 0xbb, 0x1d, 0xf7, 0x98, 0x95, 0x3b, 0x2c, 0x50, 0x79, - 0xcc, 0xde, 0x27, 0x84, 0x44, 0x9b, 0xb2, 0x4a, 0x94, 0x4d, - 0x4d, 0x3d, 0xbc, 0x00, 0x9d, 0x69, 0xad, 0x45, 0x89, 0x04, - 0x48, 0xca, 0x04, 0xf6, 0x3a, 0x62, 0xc1, 0x38, 0x9d, 0x82, - 0xb3, 0x45, 0x62, 0x4c + 0xf6, + 0x8b, + 0x6e, + 0xa3, + 0xdc, + 0x40, + 0x38, + 0xc6, + 0xa5, + 0x99, + 0x1c, + 0xa9, + 0x77, + 0xe6, + 0x1d, + 0x4f, + 0x09, + 0x36, + 0x12, + 0x26, + 0x00, + 0x56, + 0x0b, + 0x29, + 0x7d, + 0x5e, + 0xda, + 0x39, + 0xc6, + 0x61, + 0x57, + 0x69, + 0x15, + 0xff, + 0x93, + 0x39, + 0x95, + 0xf0, + 0x57, + 0xf1, + 0xe5, + 0x36, + 0x08, + 0xad, + 0xd2, + 0x75, + 0xa9, + 0x68, + 0x29, + 0xed, + 0xaa, + 0x03, + 0x0e, + 0x5f, + 0xac, + 0xbd, + 0x26, + 0x07, + 0x95, + 0x4e, + 0x48, + 0x61, + 0x26, + 0xc5, + 0xe2, + 0x6c, + 0x60, + 0xbf, + 0xa8, + 0x6f, + 0x51, + 0xbb, + 0x1d, + 0xf7, + 0x98, + 0x95, + 0x3b, + 0x2c, + 0x50, + 0x79, + 0xcc, + 0xde, + 0x27, + 0x84, + 0x44, + 0x9b, + 0xb2, + 0x4a, + 0x94, + 0x4d, + 0x4d, + 0x3d, + 0xbc, + 0x00, + 0x9d, + 0x69, + 0xad, + 0x45, + 0x89, + 0x04, + 0x48, + 0xca, + 0x04, + 0xf6, + 0x3a, + 0x62, + 0xc1, + 0x38, + 0x9d, + 0x82, + 0xb3, + 0x45, + 0x62, + 0x4c, }; static const QUIC_PKT_HDR rx_script_4_expect_hdr = { @@ -279,10 +390,10 @@ static const unsigned char rx_script_4_body[] = { }; static const struct rx_test_op rx_script_4[] = { - RX_OP_SET_RX_DCID(empty_conn_id), - RX_OP_INJECT_CHECK(4), - RX_OP_CHECK_NO_PKT(), - RX_OP_END + RX_OP_SET_RX_DCID(empty_conn_id) + RX_OP_INJECT_CHECK(4) + RX_OP_CHECK_NO_PKT() + RX_OP_END }; /* @@ -300,10 +411,38 @@ static const unsigned char rx_script_5_handshake_secret[32] = { }; static const unsigned char rx_script_5_1rtt_secret[32] = { - 0x53, 0xf2, 0x1b, 0x94, 0xa7, 0x65, 0xf7, 0x76, 0xfb, 0x06, - 0x27, 0xaa, 0xd2, 0x3f, 0xe0, 0x9a, 0xbb, 0xcf, 0x99, 0x6f, - 0x13, 0x2c, 0x6a, 0x37, 0x95, 0xf3, 0xda, 0x21, 0xcb, 0xcb, - 0xa5, 0x26 + 0x53, + 0xf2, + 0x1b, + 0x94, + 0xa7, + 0x65, + 0xf7, + 0x76, + 0xfb, + 0x06, + 0x27, + 0xaa, + 0xd2, + 0x3f, + 0xe0, + 0x9a, + 0xbb, + 0xcf, + 0x99, + 0x6f, + 0x13, + 0x2c, + 0x6a, + 0x37, + 0x95, + 0xf3, + 0xda, + 0x21, + 0xcb, + 0xcb, + 0xa5, + 0x26, }; static const unsigned char rx_script_5_in[] = { @@ -324,53 +463,470 @@ static const unsigned char rx_script_5_in[] = { 0xd2, /* Length (466) */ 0xe3, 0xab, /* PN (0) */ - 0x22, 0x35, 0x34, 0x12, 0xcf, 0x20, 0x2b, 0x16, 0xaf, 0x08, - 0xd4, 0xe0, 0x94, 0x8b, 0x1e, 0x62, 0xdf, 0x31, 0x61, 0xcc, - 0xf9, 0xfa, 0x66, 0x4f, 0x18, 0x61, 0x07, 0xcb, 0x13, 0xd3, - 0xf9, 0xbf, 0xe2, 0x8e, 0x25, 0x8d, 0xd1, 0xdf, 0x58, 0x9c, - 0x05, 0x20, 0xf9, 0xf2, 0x01, 0x20, 0xe9, 0x39, 0xc3, 0x80, - 0x77, 0xec, 0xa4, 0x57, 0xcf, 0x57, 0x8c, 0xdd, 0x68, 0x82, - 0x91, 0xfe, 0x71, 0xa0, 0xfa, 0x56, 0x4c, 0xf2, 0xe7, 0x2b, - 0xd0, 0xc0, 0xda, 0x81, 0xe2, 0x39, 0xb5, 0xf0, 0x0f, 0xd9, - 0x07, 0xd5, 0x67, 0x09, 0x02, 0xf0, 0xff, 0x74, 0xb0, 0xa0, - 0xd9, 0x3a, 0x7e, 0xb6, 0x57, 0x82, 0x47, 0x18, 0x66, 0xed, - 0xe2, 0x18, 0x4d, 0xc2, 0x5c, 0x9f, 0x05, 0x09, 0x18, 0x24, - 0x0e, 0x3f, 0x3d, 0xf9, 0x15, 0x8b, 0x08, 0xfd, 0x25, 0xe9, - 0xc9, 0xb7, 0x8c, 0x18, 0x7b, 0xf3, 0x37, 0x58, 0xf0, 0xf0, - 0xac, 0x33, 0x55, 0x3f, 0x39, 0xbc, 0x62, 0x03, 0x8a, 0xc0, - 0xd6, 0xcc, 0x49, 0x47, 0xeb, 0x85, 0xb6, 0x72, 0xd7, 0xf8, - 0xdc, 0x01, 0x32, 0xec, 0x1b, 0x4e, 0x38, 0x6e, 0x2c, 0xc5, - 0x80, 0xf2, 0x43, 0x4a, 0xf5, 0xe5, 0xa2, 0xf8, 0x76, 0xa7, - 0xa8, 0x57, 0x32, 0x67, 0x72, 0xeb, 0x82, 0xac, 0x3e, 0xc0, - 0x15, 0x67, 0xac, 0x32, 0x19, 0x18, 0x0a, 0xef, 0x20, 0xa1, - 0xe8, 0xaf, 0xac, 0x33, 0x87, 0x4c, 0x55, 0x05, 0x9b, 0x78, - 0xf0, 0x3a, 0xce, 0x02, 0x28, 0x06, 0x84, 0x61, 0x97, 0xac, - 0x87, 0x8f, 0x25, 0xe7, 0x1b, 0xa3, 0x02, 0x08, 0x4c, 0x2e, - 0xef, 0xbd, 0x4f, 0x82, 0xe7, 0x37, 0x6c, 0x27, 0x6f, 0x85, - 0xb4, 0xbc, 0x79, 0x38, 0x45, 0x80, 0x8a, 0xda, 0x2f, 0x11, - 0x11, 0xac, 0x9c, 0xf3, 0x93, 0xc1, 0x49, 0x1b, 0x94, 0x12, - 0x77, 0x07, 0xdc, 0xbf, 0xc2, 0xfd, 0x8b, 0xf6, 0xf1, 0x66, - 0x1c, 0x7f, 0x07, 0xbf, 0x1f, 0xae, 0x27, 0x6c, 0x66, 0xe9, - 0xa3, 0x64, 0x7a, 0x96, 0x78, 0x45, 0xfe, 0x4b, 0x8c, 0x6f, - 0x7f, 0x03, 0x47, 0x3c, 0xd7, 0xf7, 0x63, 0x92, 0x58, 0x5b, - 0x63, 0x83, 0x03, 0x05, 0xc3, 0x5d, 0x36, 0x62, 0x63, 0x5e, - 0xcf, 0xfe, 0x0a, 0x29, 0xfa, 0xeb, 0xc8, 0xaf, 0xce, 0x31, - 0x07, 0x6a, 0x09, 0x41, 0xc0, 0x2d, 0x98, 0x70, 0x05, 0x3b, - 0x41, 0xfc, 0x7d, 0x61, 0xe0, 0x41, 0x7d, 0x13, 0x41, 0x51, - 0x52, 0xb4, 0x78, 0xd5, 0x46, 0x51, 0x3b, 0xf1, 0xcd, 0xcc, - 0x2e, 0x49, 0x30, 0x8b, 0x2a, 0xd2, 0xe6, 0x69, 0xb5, 0x6b, - 0x7a, 0xf4, 0xbb, 0xd1, 0xf8, 0x4a, 0xe8, 0x53, 0x10, 0x46, - 0x85, 0x8d, 0x66, 0x8e, 0x2b, 0xe8, 0x5d, 0xab, 0x7e, 0xfe, - 0x5a, 0x79, 0xcf, 0xc5, 0x0c, 0x30, 0x9e, 0x98, 0x02, 0xb3, - 0xa6, 0xd5, 0xfa, 0x25, 0xa8, 0xc8, 0xc1, 0xd9, 0x51, 0x60, - 0x57, 0x5d, 0xfe, 0x75, 0x97, 0x05, 0xda, 0xbb, 0xc6, 0x6a, - 0xbe, 0x5c, 0xa5, 0x65, 0x0a, 0x12, 0x33, 0x1c, 0xdf, 0xee, - 0x08, 0xa9, 0x13, 0x13, 0x28, 0xce, 0x61, 0x59, 0xd1, 0x4e, - 0xc7, 0x74, 0xfd, 0x64, 0xde, 0x08, 0xce, 0xda, 0x3f, 0xec, - 0xad, 0xc9, 0xe1, 0xf9, 0x1f, 0x74, 0xf6, 0x86, 0x37, 0x6a, - 0xa0, 0xc8, 0x0b, 0x1b, 0x94, 0x98, 0x86, 0x81, 0x3b, 0xfc, - 0x47, 0x6c, 0xc9, 0x3e, 0x3c, 0x30, 0xc5, 0x9e, 0xb2, 0x32, - 0x47, 0xf5, 0x0c, 0x6f, + 0x22, + 0x35, + 0x34, + 0x12, + 0xcf, + 0x20, + 0x2b, + 0x16, + 0xaf, + 0x08, + 0xd4, + 0xe0, + 0x94, + 0x8b, + 0x1e, + 0x62, + 0xdf, + 0x31, + 0x61, + 0xcc, + 0xf9, + 0xfa, + 0x66, + 0x4f, + 0x18, + 0x61, + 0x07, + 0xcb, + 0x13, + 0xd3, + 0xf9, + 0xbf, + 0xe2, + 0x8e, + 0x25, + 0x8d, + 0xd1, + 0xdf, + 0x58, + 0x9c, + 0x05, + 0x20, + 0xf9, + 0xf2, + 0x01, + 0x20, + 0xe9, + 0x39, + 0xc3, + 0x80, + 0x77, + 0xec, + 0xa4, + 0x57, + 0xcf, + 0x57, + 0x8c, + 0xdd, + 0x68, + 0x82, + 0x91, + 0xfe, + 0x71, + 0xa0, + 0xfa, + 0x56, + 0x4c, + 0xf2, + 0xe7, + 0x2b, + 0xd0, + 0xc0, + 0xda, + 0x81, + 0xe2, + 0x39, + 0xb5, + 0xf0, + 0x0f, + 0xd9, + 0x07, + 0xd5, + 0x67, + 0x09, + 0x02, + 0xf0, + 0xff, + 0x74, + 0xb0, + 0xa0, + 0xd9, + 0x3a, + 0x7e, + 0xb6, + 0x57, + 0x82, + 0x47, + 0x18, + 0x66, + 0xed, + 0xe2, + 0x18, + 0x4d, + 0xc2, + 0x5c, + 0x9f, + 0x05, + 0x09, + 0x18, + 0x24, + 0x0e, + 0x3f, + 0x3d, + 0xf9, + 0x15, + 0x8b, + 0x08, + 0xfd, + 0x25, + 0xe9, + 0xc9, + 0xb7, + 0x8c, + 0x18, + 0x7b, + 0xf3, + 0x37, + 0x58, + 0xf0, + 0xf0, + 0xac, + 0x33, + 0x55, + 0x3f, + 0x39, + 0xbc, + 0x62, + 0x03, + 0x8a, + 0xc0, + 0xd6, + 0xcc, + 0x49, + 0x47, + 0xeb, + 0x85, + 0xb6, + 0x72, + 0xd7, + 0xf8, + 0xdc, + 0x01, + 0x32, + 0xec, + 0x1b, + 0x4e, + 0x38, + 0x6e, + 0x2c, + 0xc5, + 0x80, + 0xf2, + 0x43, + 0x4a, + 0xf5, + 0xe5, + 0xa2, + 0xf8, + 0x76, + 0xa7, + 0xa8, + 0x57, + 0x32, + 0x67, + 0x72, + 0xeb, + 0x82, + 0xac, + 0x3e, + 0xc0, + 0x15, + 0x67, + 0xac, + 0x32, + 0x19, + 0x18, + 0x0a, + 0xef, + 0x20, + 0xa1, + 0xe8, + 0xaf, + 0xac, + 0x33, + 0x87, + 0x4c, + 0x55, + 0x05, + 0x9b, + 0x78, + 0xf0, + 0x3a, + 0xce, + 0x02, + 0x28, + 0x06, + 0x84, + 0x61, + 0x97, + 0xac, + 0x87, + 0x8f, + 0x25, + 0xe7, + 0x1b, + 0xa3, + 0x02, + 0x08, + 0x4c, + 0x2e, + 0xef, + 0xbd, + 0x4f, + 0x82, + 0xe7, + 0x37, + 0x6c, + 0x27, + 0x6f, + 0x85, + 0xb4, + 0xbc, + 0x79, + 0x38, + 0x45, + 0x80, + 0x8a, + 0xda, + 0x2f, + 0x11, + 0x11, + 0xac, + 0x9c, + 0xf3, + 0x93, + 0xc1, + 0x49, + 0x1b, + 0x94, + 0x12, + 0x77, + 0x07, + 0xdc, + 0xbf, + 0xc2, + 0xfd, + 0x8b, + 0xf6, + 0xf1, + 0x66, + 0x1c, + 0x7f, + 0x07, + 0xbf, + 0x1f, + 0xae, + 0x27, + 0x6c, + 0x66, + 0xe9, + 0xa3, + 0x64, + 0x7a, + 0x96, + 0x78, + 0x45, + 0xfe, + 0x4b, + 0x8c, + 0x6f, + 0x7f, + 0x03, + 0x47, + 0x3c, + 0xd7, + 0xf7, + 0x63, + 0x92, + 0x58, + 0x5b, + 0x63, + 0x83, + 0x03, + 0x05, + 0xc3, + 0x5d, + 0x36, + 0x62, + 0x63, + 0x5e, + 0xcf, + 0xfe, + 0x0a, + 0x29, + 0xfa, + 0xeb, + 0xc8, + 0xaf, + 0xce, + 0x31, + 0x07, + 0x6a, + 0x09, + 0x41, + 0xc0, + 0x2d, + 0x98, + 0x70, + 0x05, + 0x3b, + 0x41, + 0xfc, + 0x7d, + 0x61, + 0xe0, + 0x41, + 0x7d, + 0x13, + 0x41, + 0x51, + 0x52, + 0xb4, + 0x78, + 0xd5, + 0x46, + 0x51, + 0x3b, + 0xf1, + 0xcd, + 0xcc, + 0x2e, + 0x49, + 0x30, + 0x8b, + 0x2a, + 0xd2, + 0xe6, + 0x69, + 0xb5, + 0x6b, + 0x7a, + 0xf4, + 0xbb, + 0xd1, + 0xf8, + 0x4a, + 0xe8, + 0x53, + 0x10, + 0x46, + 0x85, + 0x8d, + 0x66, + 0x8e, + 0x2b, + 0xe8, + 0x5d, + 0xab, + 0x7e, + 0xfe, + 0x5a, + 0x79, + 0xcf, + 0xc5, + 0x0c, + 0x30, + 0x9e, + 0x98, + 0x02, + 0xb3, + 0xa6, + 0xd5, + 0xfa, + 0x25, + 0xa8, + 0xc8, + 0xc1, + 0xd9, + 0x51, + 0x60, + 0x57, + 0x5d, + 0xfe, + 0x75, + 0x97, + 0x05, + 0xda, + 0xbb, + 0xc6, + 0x6a, + 0xbe, + 0x5c, + 0xa5, + 0x65, + 0x0a, + 0x12, + 0x33, + 0x1c, + 0xdf, + 0xee, + 0x08, + 0xa9, + 0x13, + 0x13, + 0x28, + 0xce, + 0x61, + 0x59, + 0xd1, + 0x4e, + 0xc7, + 0x74, + 0xfd, + 0x64, + 0xde, + 0x08, + 0xce, + 0xda, + 0x3f, + 0xec, + 0xad, + 0xc9, + 0xe1, + 0xf9, + 0x1f, + 0x74, + 0xf6, + 0x86, + 0x37, + 0x6a, + 0xa0, + 0xc8, + 0x0b, + 0x1b, + 0x94, + 0x98, + 0x86, + 0x81, + 0x3b, + 0xfc, + 0x47, + 0x6c, + 0xc9, + 0x3e, + 0x3c, + 0x30, + 0xc5, + 0x9e, + 0xb2, + 0x32, + 0x47, + 0xf5, + 0x0c, + 0x6f, /* Second Packet: Handshake */ 0xe6, /* Long, Handshake, PN Length=2 bytes */ @@ -388,87 +944,765 @@ static const unsigned char rx_script_5_in[] = { 0x9c, /* Length (668) */ 0x9c, 0x55, /* PN (0) */ - 0x55, 0xd4, 0x50, 0x02, 0x1a, 0x57, 0x84, 0x22, 0xcd, 0x01, - 0xe5, 0x42, 0x1b, 0x1e, 0x06, 0xf1, 0x86, 0xe2, 0x90, 0xf8, - 0x9c, 0x3d, 0xa2, 0x7c, 0xde, 0x2b, 0xc9, 0x2e, 0xcd, 0xa8, - 0x4f, 0x5a, 0x20, 0xca, 0x96, 0xb6, 0x11, 0x4b, 0xc8, 0x71, - 0x32, 0xb5, 0xc7, 0x1a, 0x69, 0x7f, 0x1e, 0x37, 0x49, 0xfb, - 0x08, 0xce, 0x83, 0x5f, 0x02, 0x6d, 0x8a, 0x8f, 0xe7, 0x5d, - 0xe1, 0x34, 0x31, 0x22, 0x53, 0x53, 0x32, 0xcb, 0x04, 0x21, - 0xce, 0xbc, 0xa5, 0x1b, 0xdd, 0x4d, 0xd5, 0x1c, 0xd6, 0x5d, - 0x88, 0x29, 0x5a, 0x19, 0x71, 0x6a, 0xc2, 0xfa, 0xb7, 0xb4, - 0x7d, 0xd1, 0x72, 0x93, 0x8f, 0x7c, 0xb5, 0x36, 0x1b, 0xea, - 0xf3, 0xf1, 0xd7, 0x6e, 0xd3, 0x91, 0x96, 0x62, 0x4d, 0xc6, - 0xec, 0xb7, 0xb0, 0xb7, 0x9b, 0x95, 0x8b, 0x14, 0x8d, 0x1a, - 0x0d, 0xb6, 0x3e, 0xec, 0xfe, 0x3b, 0x51, 0xea, 0x1a, 0x05, - 0x14, 0x12, 0x93, 0x0e, 0x7e, 0xe6, 0xa2, 0xc5, 0x22, 0x87, - 0x65, 0xf8, 0x5d, 0x3c, 0x55, 0x18, 0xcb, 0xe9, 0xef, 0x23, - 0x43, 0xfe, 0xe8, 0x0d, 0xb2, 0x0f, 0xc5, 0xf4, 0xb3, 0xde, - 0x0c, 0xea, 0xa4, 0x48, 0x8e, 0xbf, 0x1f, 0xc7, 0x99, 0x53, - 0x8c, 0xc1, 0x3d, 0xba, 0xf4, 0x8e, 0x8e, 0x02, 0x52, 0xf6, - 0x1f, 0xcf, 0x1d, 0xaa, 0xb3, 0xcb, 0x08, 0xc2, 0xe1, 0x70, - 0x68, 0x74, 0x78, 0xa9, 0x30, 0x67, 0xba, 0x2b, 0xea, 0x35, - 0x63, 0x47, 0xff, 0x29, 0x73, 0x29, 0xc6, 0xe8, 0x08, 0xa9, - 0x1e, 0x8f, 0x28, 0x41, 0xa4, 0x24, 0x54, 0x26, 0x5f, 0x42, - 0x77, 0xb1, 0x2b, 0x3d, 0x65, 0x67, 0x60, 0xa7, 0x23, 0x0d, - 0xa7, 0xf4, 0xd6, 0xe9, 0x4e, 0x58, 0x43, 0x9f, 0x3c, 0x9e, - 0x77, 0x61, 0xe5, 0x04, 0x4f, 0x73, 0xc9, 0x10, 0x79, 0xd0, - 0xda, 0x3b, 0xc6, 0x19, 0x93, 0x9f, 0x48, 0x3b, 0x76, 0x38, - 0xa1, 0x72, 0x49, 0x7d, 0x86, 0x7f, 0xe8, 0x1b, 0xa9, 0x5b, - 0xc0, 0x47, 0xa0, 0x9c, 0x3f, 0x65, 0x60, 0x76, 0x59, 0xaf, - 0x20, 0x2d, 0x40, 0xa6, 0x80, 0x49, 0x5a, 0x8f, 0x09, 0xf8, - 0xf6, 0x97, 0xc1, 0xbd, 0xe1, 0x9f, 0x9b, 0xa2, 0x4c, 0x7b, - 0x88, 0xac, 0xbe, 0x4b, 0x11, 0x28, 0xd7, 0x67, 0xe6, 0xad, - 0xaf, 0xd0, 0xad, 0x01, 0x29, 0xa4, 0x4a, 0xc4, 0xb8, 0x2e, - 0x42, 0x79, 0x24, 0x9e, 0xd5, 0x34, 0xae, 0x45, 0xf1, 0x0b, - 0x38, 0x4a, 0x76, 0xfb, 0x50, 0xa2, 0x99, 0xc9, 0x5b, 0x6d, - 0xc0, 0xb7, 0x55, 0xd8, 0x8d, 0x49, 0xdd, 0x1b, 0xb8, 0xec, - 0x10, 0x57, 0x9e, 0x33, 0xb4, 0x10, 0x16, 0x19, 0xac, 0x69, - 0xa2, 0x19, 0x1b, 0xd0, 0x77, 0x45, 0xeb, 0x49, 0x5c, 0xc5, - 0x7c, 0xbe, 0x4b, 0x4a, 0x22, 0x5c, 0x3d, 0x0e, 0x6e, 0xe5, - 0x4b, 0x36, 0x06, 0x63, 0x03, 0x97, 0xab, 0xed, 0xdc, 0xea, - 0x64, 0xc2, 0x70, 0xb6, 0x7e, 0x35, 0xfb, 0x13, 0x66, 0x37, - 0xa3, 0x3f, 0x28, 0x16, 0x6c, 0xe7, 0xd4, 0xe6, 0xca, 0x26, - 0x0f, 0x19, 0xdd, 0x02, 0xae, 0xc1, 0xcf, 0x18, 0x7d, 0x56, - 0xe6, 0x52, 0xf3, 0x37, 0xb5, 0x86, 0x9d, 0x1d, 0x55, 0xb3, - 0x95, 0x19, 0x19, 0xa5, 0x44, 0x95, 0x81, 0xed, 0x02, 0x18, - 0xf1, 0x85, 0x57, 0x78, 0x28, 0xc4, 0x9a, 0xba, 0xe8, 0x5e, - 0x22, 0x8d, 0xc1, 0x7b, 0x2a, 0x8a, 0xc8, 0xb9, 0xdd, 0x82, - 0xb2, 0x7b, 0x9f, 0x3d, 0xf5, 0x27, 0x2a, 0x48, 0x53, 0xc7, - 0xa0, 0x70, 0x0e, 0x9d, 0x61, 0xaa, 0xe2, 0xad, 0x28, 0xf2, - 0xb4, 0xfc, 0x56, 0x6b, 0x89, 0xe7, 0xf9, 0x51, 0xc9, 0xe9, - 0xd3, 0x8a, 0x8c, 0x7e, 0x86, 0xdd, 0xba, 0x2f, 0x39, 0xbf, - 0x26, 0x62, 0x23, 0xd6, 0x98, 0x6d, 0x3e, 0x72, 0xd7, 0x1b, - 0xe1, 0x62, 0x94, 0x35, 0xe2, 0x18, 0x19, 0x46, 0xb8, 0x2c, - 0xb5, 0x8f, 0x8f, 0xb0, 0x5b, 0x76, 0x7b, 0x7e, 0xb8, 0xc6, - 0xb7, 0xe9, 0x4e, 0x9d, 0x30, 0x68, 0x03, 0x1e, 0x19, 0x73, - 0xc5, 0x3e, 0x24, 0xe2, 0x95, 0x60, 0x1b, 0x27, 0x93, 0x7c, - 0x17, 0xc2, 0xc6, 0xa3, 0xbd, 0xbd, 0x70, 0xc6, 0x60, 0x59, - 0xc8, 0x5c, 0xd7, 0x9a, 0xc4, 0x29, 0xac, 0x0f, 0xaa, 0x0d, - 0xa9, 0x92, 0xa3, 0x95, 0xd7, 0x0f, 0x6f, 0x74, 0x99, 0x9b, - 0xc1, 0xd3, 0x68, 0x6d, 0xac, 0x82, 0x2d, 0x32, 0x41, 0x9e, - 0x0c, 0xf7, 0x31, 0x59, 0x4c, 0x93, 0x1c, 0x3b, 0x71, 0x69, - 0xcf, 0xc5, 0xca, 0x2b, 0xdf, 0xe7, 0xaa, 0xfd, 0x1d, 0x71, - 0x01, 0x7e, 0x1c, 0x70, 0x62, 0x20, 0x61, 0xf8, 0x35, 0xc1, - 0x71, 0xe7, 0x02, 0x0d, 0x88, 0x44, 0xd9, 0x00, 0xc5, 0xcc, - 0x63, 0xe4, 0xf0, 0x86, 0xa7, 0xd0, 0xfe, 0xcc, 0xb7, 0x1d, - 0xfc, 0x21, 0x61, 0x54, 0x15, 0xea, 0x81, 0x5e, 0xc0, 0x31, - 0xfa, 0xbf, 0x7d, 0xb9, 0x3b, 0xa2, 0x1e, 0x42, 0x73, 0x05, - 0x3c, 0xdb, 0x21, 0x59, 0x4f, 0x63, + 0x55, + 0xd4, + 0x50, + 0x02, + 0x1a, + 0x57, + 0x84, + 0x22, + 0xcd, + 0x01, + 0xe5, + 0x42, + 0x1b, + 0x1e, + 0x06, + 0xf1, + 0x86, + 0xe2, + 0x90, + 0xf8, + 0x9c, + 0x3d, + 0xa2, + 0x7c, + 0xde, + 0x2b, + 0xc9, + 0x2e, + 0xcd, + 0xa8, + 0x4f, + 0x5a, + 0x20, + 0xca, + 0x96, + 0xb6, + 0x11, + 0x4b, + 0xc8, + 0x71, + 0x32, + 0xb5, + 0xc7, + 0x1a, + 0x69, + 0x7f, + 0x1e, + 0x37, + 0x49, + 0xfb, + 0x08, + 0xce, + 0x83, + 0x5f, + 0x02, + 0x6d, + 0x8a, + 0x8f, + 0xe7, + 0x5d, + 0xe1, + 0x34, + 0x31, + 0x22, + 0x53, + 0x53, + 0x32, + 0xcb, + 0x04, + 0x21, + 0xce, + 0xbc, + 0xa5, + 0x1b, + 0xdd, + 0x4d, + 0xd5, + 0x1c, + 0xd6, + 0x5d, + 0x88, + 0x29, + 0x5a, + 0x19, + 0x71, + 0x6a, + 0xc2, + 0xfa, + 0xb7, + 0xb4, + 0x7d, + 0xd1, + 0x72, + 0x93, + 0x8f, + 0x7c, + 0xb5, + 0x36, + 0x1b, + 0xea, + 0xf3, + 0xf1, + 0xd7, + 0x6e, + 0xd3, + 0x91, + 0x96, + 0x62, + 0x4d, + 0xc6, + 0xec, + 0xb7, + 0xb0, + 0xb7, + 0x9b, + 0x95, + 0x8b, + 0x14, + 0x8d, + 0x1a, + 0x0d, + 0xb6, + 0x3e, + 0xec, + 0xfe, + 0x3b, + 0x51, + 0xea, + 0x1a, + 0x05, + 0x14, + 0x12, + 0x93, + 0x0e, + 0x7e, + 0xe6, + 0xa2, + 0xc5, + 0x22, + 0x87, + 0x65, + 0xf8, + 0x5d, + 0x3c, + 0x55, + 0x18, + 0xcb, + 0xe9, + 0xef, + 0x23, + 0x43, + 0xfe, + 0xe8, + 0x0d, + 0xb2, + 0x0f, + 0xc5, + 0xf4, + 0xb3, + 0xde, + 0x0c, + 0xea, + 0xa4, + 0x48, + 0x8e, + 0xbf, + 0x1f, + 0xc7, + 0x99, + 0x53, + 0x8c, + 0xc1, + 0x3d, + 0xba, + 0xf4, + 0x8e, + 0x8e, + 0x02, + 0x52, + 0xf6, + 0x1f, + 0xcf, + 0x1d, + 0xaa, + 0xb3, + 0xcb, + 0x08, + 0xc2, + 0xe1, + 0x70, + 0x68, + 0x74, + 0x78, + 0xa9, + 0x30, + 0x67, + 0xba, + 0x2b, + 0xea, + 0x35, + 0x63, + 0x47, + 0xff, + 0x29, + 0x73, + 0x29, + 0xc6, + 0xe8, + 0x08, + 0xa9, + 0x1e, + 0x8f, + 0x28, + 0x41, + 0xa4, + 0x24, + 0x54, + 0x26, + 0x5f, + 0x42, + 0x77, + 0xb1, + 0x2b, + 0x3d, + 0x65, + 0x67, + 0x60, + 0xa7, + 0x23, + 0x0d, + 0xa7, + 0xf4, + 0xd6, + 0xe9, + 0x4e, + 0x58, + 0x43, + 0x9f, + 0x3c, + 0x9e, + 0x77, + 0x61, + 0xe5, + 0x04, + 0x4f, + 0x73, + 0xc9, + 0x10, + 0x79, + 0xd0, + 0xda, + 0x3b, + 0xc6, + 0x19, + 0x93, + 0x9f, + 0x48, + 0x3b, + 0x76, + 0x38, + 0xa1, + 0x72, + 0x49, + 0x7d, + 0x86, + 0x7f, + 0xe8, + 0x1b, + 0xa9, + 0x5b, + 0xc0, + 0x47, + 0xa0, + 0x9c, + 0x3f, + 0x65, + 0x60, + 0x76, + 0x59, + 0xaf, + 0x20, + 0x2d, + 0x40, + 0xa6, + 0x80, + 0x49, + 0x5a, + 0x8f, + 0x09, + 0xf8, + 0xf6, + 0x97, + 0xc1, + 0xbd, + 0xe1, + 0x9f, + 0x9b, + 0xa2, + 0x4c, + 0x7b, + 0x88, + 0xac, + 0xbe, + 0x4b, + 0x11, + 0x28, + 0xd7, + 0x67, + 0xe6, + 0xad, + 0xaf, + 0xd0, + 0xad, + 0x01, + 0x29, + 0xa4, + 0x4a, + 0xc4, + 0xb8, + 0x2e, + 0x42, + 0x79, + 0x24, + 0x9e, + 0xd5, + 0x34, + 0xae, + 0x45, + 0xf1, + 0x0b, + 0x38, + 0x4a, + 0x76, + 0xfb, + 0x50, + 0xa2, + 0x99, + 0xc9, + 0x5b, + 0x6d, + 0xc0, + 0xb7, + 0x55, + 0xd8, + 0x8d, + 0x49, + 0xdd, + 0x1b, + 0xb8, + 0xec, + 0x10, + 0x57, + 0x9e, + 0x33, + 0xb4, + 0x10, + 0x16, + 0x19, + 0xac, + 0x69, + 0xa2, + 0x19, + 0x1b, + 0xd0, + 0x77, + 0x45, + 0xeb, + 0x49, + 0x5c, + 0xc5, + 0x7c, + 0xbe, + 0x4b, + 0x4a, + 0x22, + 0x5c, + 0x3d, + 0x0e, + 0x6e, + 0xe5, + 0x4b, + 0x36, + 0x06, + 0x63, + 0x03, + 0x97, + 0xab, + 0xed, + 0xdc, + 0xea, + 0x64, + 0xc2, + 0x70, + 0xb6, + 0x7e, + 0x35, + 0xfb, + 0x13, + 0x66, + 0x37, + 0xa3, + 0x3f, + 0x28, + 0x16, + 0x6c, + 0xe7, + 0xd4, + 0xe6, + 0xca, + 0x26, + 0x0f, + 0x19, + 0xdd, + 0x02, + 0xae, + 0xc1, + 0xcf, + 0x18, + 0x7d, + 0x56, + 0xe6, + 0x52, + 0xf3, + 0x37, + 0xb5, + 0x86, + 0x9d, + 0x1d, + 0x55, + 0xb3, + 0x95, + 0x19, + 0x19, + 0xa5, + 0x44, + 0x95, + 0x81, + 0xed, + 0x02, + 0x18, + 0xf1, + 0x85, + 0x57, + 0x78, + 0x28, + 0xc4, + 0x9a, + 0xba, + 0xe8, + 0x5e, + 0x22, + 0x8d, + 0xc1, + 0x7b, + 0x2a, + 0x8a, + 0xc8, + 0xb9, + 0xdd, + 0x82, + 0xb2, + 0x7b, + 0x9f, + 0x3d, + 0xf5, + 0x27, + 0x2a, + 0x48, + 0x53, + 0xc7, + 0xa0, + 0x70, + 0x0e, + 0x9d, + 0x61, + 0xaa, + 0xe2, + 0xad, + 0x28, + 0xf2, + 0xb4, + 0xfc, + 0x56, + 0x6b, + 0x89, + 0xe7, + 0xf9, + 0x51, + 0xc9, + 0xe9, + 0xd3, + 0x8a, + 0x8c, + 0x7e, + 0x86, + 0xdd, + 0xba, + 0x2f, + 0x39, + 0xbf, + 0x26, + 0x62, + 0x23, + 0xd6, + 0x98, + 0x6d, + 0x3e, + 0x72, + 0xd7, + 0x1b, + 0xe1, + 0x62, + 0x94, + 0x35, + 0xe2, + 0x18, + 0x19, + 0x46, + 0xb8, + 0x2c, + 0xb5, + 0x8f, + 0x8f, + 0xb0, + 0x5b, + 0x76, + 0x7b, + 0x7e, + 0xb8, + 0xc6, + 0xb7, + 0xe9, + 0x4e, + 0x9d, + 0x30, + 0x68, + 0x03, + 0x1e, + 0x19, + 0x73, + 0xc5, + 0x3e, + 0x24, + 0xe2, + 0x95, + 0x60, + 0x1b, + 0x27, + 0x93, + 0x7c, + 0x17, + 0xc2, + 0xc6, + 0xa3, + 0xbd, + 0xbd, + 0x70, + 0xc6, + 0x60, + 0x59, + 0xc8, + 0x5c, + 0xd7, + 0x9a, + 0xc4, + 0x29, + 0xac, + 0x0f, + 0xaa, + 0x0d, + 0xa9, + 0x92, + 0xa3, + 0x95, + 0xd7, + 0x0f, + 0x6f, + 0x74, + 0x99, + 0x9b, + 0xc1, + 0xd3, + 0x68, + 0x6d, + 0xac, + 0x82, + 0x2d, + 0x32, + 0x41, + 0x9e, + 0x0c, + 0xf7, + 0x31, + 0x59, + 0x4c, + 0x93, + 0x1c, + 0x3b, + 0x71, + 0x69, + 0xcf, + 0xc5, + 0xca, + 0x2b, + 0xdf, + 0xe7, + 0xaa, + 0xfd, + 0x1d, + 0x71, + 0x01, + 0x7e, + 0x1c, + 0x70, + 0x62, + 0x20, + 0x61, + 0xf8, + 0x35, + 0xc1, + 0x71, + 0xe7, + 0x02, + 0x0d, + 0x88, + 0x44, + 0xd9, + 0x00, + 0xc5, + 0xcc, + 0x63, + 0xe4, + 0xf0, + 0x86, + 0xa7, + 0xd0, + 0xfe, + 0xcc, + 0xb7, + 0x1d, + 0xfc, + 0x21, + 0x61, + 0x54, + 0x15, + 0xea, + 0x81, + 0x5e, + 0xc0, + 0x31, + 0xfa, + 0xbf, + 0x7d, + 0xb9, + 0x3b, + 0xa2, + 0x1e, + 0x42, + 0x73, + 0x05, + 0x3c, + 0xdb, + 0x21, + 0x59, + 0x4f, + 0x63, /* Third Packet: 1-RTT */ 0x5f, /* Short, 1-RTT, Spin=0, KP=0, PN Length=2 bytes */ 0x68, 0x47, /* PN (0) */ - 0xa3, 0x3c, 0xa5, 0x27, 0x5e, 0xf9, 0x8d, 0xec, 0xea, 0x6c, - 0x09, 0x18, 0x40, 0x80, 0xee, 0x9f, 0x6f, 0x73, 0x5c, 0x49, - 0xe3, 0xec, 0xb7, 0x58, 0x05, 0x66, 0x8f, 0xa3, 0x52, 0x37, - 0xa1, 0x22, 0x1f, 0xc6, 0x92, 0xd6, 0x59, 0x04, 0x99, 0xcb, - 0x44, 0xef, 0x66, 0x05, 0x2d, 0xd0, 0x85, 0x24, 0xbb, 0xe3, - 0xa1, 0xd1, 0xbe, 0xf7, 0x54, 0xad, 0x65, 0xf4, 0xd4, 0x59, - 0x54, 0x87, 0x4e, 0x22, 0x4f, 0x06, 0x07, 0xa7, 0x8a, 0x14, - 0x89, 0xd1, 0x3f, 0xd3, 0xe4, 0x6f, 0x71, 0x8f, 0x9a, 0xd2, - 0x3b, 0x61, 0x0a, 0xba, 0x9a, 0x31, 0x56, 0xc7 + 0xa3, + 0x3c, + 0xa5, + 0x27, + 0x5e, + 0xf9, + 0x8d, + 0xec, + 0xea, + 0x6c, + 0x09, + 0x18, + 0x40, + 0x80, + 0xee, + 0x9f, + 0x6f, + 0x73, + 0x5c, + 0x49, + 0xe3, + 0xec, + 0xb7, + 0x58, + 0x05, + 0x66, + 0x8f, + 0xa3, + 0x52, + 0x37, + 0xa1, + 0x22, + 0x1f, + 0xc6, + 0x92, + 0xd6, + 0x59, + 0x04, + 0x99, + 0xcb, + 0x44, + 0xef, + 0x66, + 0x05, + 0x2d, + 0xd0, + 0x85, + 0x24, + 0xbb, + 0xe3, + 0xa1, + 0xd1, + 0xbe, + 0xf7, + 0x54, + 0xad, + 0x65, + 0xf4, + 0xd4, + 0x59, + 0x54, + 0x87, + 0x4e, + 0x22, + 0x4f, + 0x06, + 0x07, + 0xa7, + 0x8a, + 0x14, + 0x89, + 0xd1, + 0x3f, + 0xd3, + 0xe4, + 0x6f, + 0x71, + 0x8f, + 0x9a, + 0xd2, + 0x3b, + 0x61, + 0x0a, + 0xba, + 0x9a, + 0x31, + 0x56, + 0xc7, }; static const QUIC_PKT_HDR rx_script_5a_expect_hdr = { @@ -489,51 +1723,454 @@ static const QUIC_PKT_HDR rx_script_5a_expect_hdr = { }; static const unsigned char rx_script_5a_body[] = { - 0x02, 0x03, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x06, 0x00, 0x40, 0x5a, 0x02, 0x00, - 0x00, 0x56, 0x03, 0x03, 0xe2, 0xd2, 0x0a, 0x3b, 0xa2, 0xc4, - 0xd2, 0x29, 0xc8, 0xe8, 0xba, 0x23, 0x31, 0x88, 0x2c, 0x71, - 0xeb, 0xba, 0x42, 0x5f, 0x94, 0xe9, 0x0a, 0x90, 0x35, 0x31, - 0x1e, 0xca, 0xed, 0xf8, 0x8a, 0x8d, 0x00, 0x13, 0x01, 0x00, - 0x00, 0x2e, 0x00, 0x2b, 0x00, 0x02, 0x03, 0x04, 0x00, 0x33, - 0x00, 0x24, 0x00, 0x1d, 0x00, 0x20, 0x96, 0x0b, 0x4b, 0x30, - 0x66, 0x3a, 0x75, 0x01, 0x4a, 0xdc, 0x2a, 0x75, 0x1f, 0xce, - 0x7a, 0x30, 0x9d, 0x00, 0xca, 0x20, 0xb4, 0xe0, 0x6b, 0x81, - 0x23, 0x18, 0x0b, 0x20, 0x1f, 0x54, 0x86, 0x1d + 0x02, + 0x03, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x06, + 0x00, + 0x40, + 0x5a, + 0x02, + 0x00, + 0x00, + 0x56, + 0x03, + 0x03, + 0xe2, + 0xd2, + 0x0a, + 0x3b, + 0xa2, + 0xc4, + 0xd2, + 0x29, + 0xc8, + 0xe8, + 0xba, + 0x23, + 0x31, + 0x88, + 0x2c, + 0x71, + 0xeb, + 0xba, + 0x42, + 0x5f, + 0x94, + 0xe9, + 0x0a, + 0x90, + 0x35, + 0x31, + 0x1e, + 0xca, + 0xed, + 0xf8, + 0x8a, + 0x8d, + 0x00, + 0x13, + 0x01, + 0x00, + 0x00, + 0x2e, + 0x00, + 0x2b, + 0x00, + 0x02, + 0x03, + 0x04, + 0x00, + 0x33, + 0x00, + 0x24, + 0x00, + 0x1d, + 0x00, + 0x20, + 0x96, + 0x0b, + 0x4b, + 0x30, + 0x66, + 0x3a, + 0x75, + 0x01, + 0x4a, + 0xdc, + 0x2a, + 0x75, + 0x1f, + 0xce, + 0x7a, + 0x30, + 0x9d, + 0x00, + 0xca, + 0x20, + 0xb4, + 0xe0, + 0x6b, + 0x81, + 0x23, + 0x18, + 0x0b, + 0x20, + 0x1f, + 0x54, + 0x86, + 0x1d, }; static const QUIC_PKT_HDR rx_script_5b_expect_hdr = { @@ -554,71 +2191,656 @@ static const QUIC_PKT_HDR rx_script_5b_expect_hdr = { }; static const unsigned char rx_script_5b_body[] = { - 0x06, 0x00, 0x42, 0x86, 0x08, 0x00, 0x00, 0x7d, 0x00, 0x7b, - 0x00, 0x10, 0x00, 0x08, 0x00, 0x06, 0x05, 0x64, 0x75, 0x6d, - 0x6d, 0x79, 0x00, 0x39, 0x00, 0x6b, 0x4b, 0x20, 0x0b, 0x1b, - 0xe1, 0x1f, 0xd0, 0x78, 0xc0, 0x69, 0x72, 0x9c, 0xe2, 0xf7, - 0x05, 0x04, 0x80, 0x08, 0x00, 0x00, 0x06, 0x04, 0x80, 0x08, - 0x00, 0x00, 0x07, 0x04, 0x80, 0x08, 0x00, 0x00, 0x04, 0x04, - 0x80, 0x0c, 0x00, 0x00, 0x08, 0x02, 0x40, 0x64, 0x09, 0x02, - 0x40, 0x64, 0x01, 0x04, 0x80, 0x00, 0x75, 0x30, 0x03, 0x02, - 0x45, 0xac, 0x0b, 0x01, 0x1a, 0x0c, 0x00, 0x02, 0x10, 0x41, - 0x94, 0x41, 0x8d, 0x0d, 0xfb, 0x60, 0x7b, 0xdc, 0xcc, 0xa2, - 0x9c, 0x3e, 0xa5, 0xdf, 0x8d, 0x00, 0x08, 0x2d, 0x71, 0x8a, - 0x38, 0xdf, 0xdd, 0xe0, 0x03, 0x0e, 0x01, 0x04, 0x0f, 0x04, - 0x83, 0xd0, 0x0a, 0x27, 0x10, 0x04, 0xad, 0x15, 0x3f, 0xae, - 0x20, 0x01, 0x00, 0x0b, 0x00, 0x01, 0x8f, 0x00, 0x00, 0x01, - 0x8b, 0x00, 0x01, 0x86, 0x30, 0x82, 0x01, 0x82, 0x30, 0x82, - 0x01, 0x29, 0xa0, 0x03, 0x02, 0x01, 0x02, 0x02, 0x14, 0x0a, - 0x73, 0x0f, 0x86, 0x18, 0xf2, 0xc3, 0x30, 0x01, 0xd2, 0xc0, - 0xc1, 0x62, 0x52, 0x13, 0xf1, 0x9c, 0x13, 0x39, 0xb5, 0x30, - 0x0a, 0x06, 0x08, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x03, - 0x02, 0x30, 0x17, 0x31, 0x15, 0x30, 0x13, 0x06, 0x03, 0x55, - 0x04, 0x03, 0x0c, 0x0c, 0x6d, 0x61, 0x70, 0x61, 0x6b, 0x74, - 0x2e, 0x6c, 0x6f, 0x63, 0x61, 0x6c, 0x30, 0x1e, 0x17, 0x0d, - 0x32, 0x32, 0x30, 0x38, 0x30, 0x32, 0x31, 0x32, 0x30, 0x30, - 0x31, 0x38, 0x5a, 0x17, 0x0d, 0x32, 0x32, 0x30, 0x39, 0x30, - 0x31, 0x31, 0x32, 0x30, 0x30, 0x31, 0x38, 0x5a, 0x30, 0x17, - 0x31, 0x15, 0x30, 0x13, 0x06, 0x03, 0x55, 0x04, 0x03, 0x0c, - 0x0c, 0x6d, 0x61, 0x70, 0x61, 0x6b, 0x74, 0x2e, 0x6c, 0x6f, - 0x63, 0x61, 0x6c, 0x30, 0x59, 0x30, 0x13, 0x06, 0x07, 0x2a, - 0x86, 0x48, 0xce, 0x3d, 0x02, 0x01, 0x06, 0x08, 0x2a, 0x86, - 0x48, 0xce, 0x3d, 0x03, 0x01, 0x07, 0x03, 0x42, 0x00, 0x04, - 0x67, 0xf4, 0xd3, 0x8f, 0x15, 0x6d, 0xee, 0x85, 0xcc, 0x2a, - 0x77, 0xfc, 0x0b, 0x8f, 0x9f, 0xcf, 0xa9, 0x95, 0x5d, 0x5b, - 0xcd, 0xb7, 0x8b, 0xba, 0x31, 0x0a, 0x73, 0x62, 0xc5, 0xd0, - 0x0e, 0x07, 0x90, 0xae, 0x38, 0x43, 0x79, 0xce, 0x5e, 0x33, - 0xad, 0x31, 0xbf, 0x9f, 0x2a, 0x56, 0x83, 0xa5, 0x24, 0x16, - 0xab, 0x0c, 0xf1, 0x64, 0xbe, 0xe4, 0x93, 0xb5, 0x89, 0xd6, - 0x05, 0xe4, 0xf7, 0x7b, 0xa3, 0x53, 0x30, 0x51, 0x30, 0x1d, - 0x06, 0x03, 0x55, 0x1d, 0x0e, 0x04, 0x16, 0x04, 0x14, 0x02, - 0x64, 0x0f, 0x55, 0x69, 0x14, 0x91, 0x19, 0xed, 0xf9, 0x1a, - 0xe9, 0x1d, 0xa5, 0x5a, 0xd0, 0x48, 0x96, 0x9f, 0x60, 0x30, - 0x1f, 0x06, 0x03, 0x55, 0x1d, 0x23, 0x04, 0x18, 0x30, 0x16, - 0x80, 0x14, 0x02, 0x64, 0x0f, 0x55, 0x69, 0x14, 0x91, 0x19, - 0xed, 0xf9, 0x1a, 0xe9, 0x1d, 0xa5, 0x5a, 0xd0, 0x48, 0x96, - 0x9f, 0x60, 0x30, 0x0f, 0x06, 0x03, 0x55, 0x1d, 0x13, 0x01, - 0x01, 0xff, 0x04, 0x05, 0x30, 0x03, 0x01, 0x01, 0xff, 0x30, - 0x0a, 0x06, 0x08, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x04, 0x03, - 0x02, 0x03, 0x47, 0x00, 0x30, 0x44, 0x02, 0x20, 0x0a, 0x82, - 0x92, 0x6e, 0xd3, 0xc6, 0x66, 0xd9, 0xd3, 0x75, 0xff, 0x71, - 0x3b, 0x61, 0x46, 0x21, 0x00, 0xe6, 0x21, 0x5d, 0x9c, 0x86, - 0xe9, 0x65, 0x40, 0x4f, 0xeb, 0x70, 0x4f, 0x2c, 0xad, 0x00, - 0x02, 0x20, 0x08, 0xc2, 0x07, 0x5d, 0x16, 0xfc, 0x54, 0x34, - 0x2b, 0xb4, 0x18, 0x67, 0x44, 0x81, 0xc9, 0xa9, 0x67, 0x2e, - 0xce, 0xa1, 0x02, 0x9f, 0x3b, 0xe5, 0x61, 0x16, 0x0b, 0x50, - 0xf6, 0xa1, 0x50, 0x94, 0x00, 0x00, 0x0f, 0x00, 0x00, 0x4a, - 0x04, 0x03, 0x00, 0x46, 0x30, 0x44, 0x02, 0x20, 0x7d, 0x57, - 0x17, 0x14, 0x46, 0x09, 0x95, 0x70, 0x09, 0x45, 0xe8, 0x9e, - 0x5c, 0x87, 0x55, 0xd9, 0x08, 0xc6, 0x5e, 0x47, 0x73, 0x5e, - 0xb1, 0xc9, 0xef, 0xcb, 0xe5, 0x7f, 0xcc, 0xb0, 0x28, 0xbc, - 0x02, 0x20, 0x5d, 0xe4, 0x2b, 0x83, 0xd9, 0x78, 0x75, 0x45, - 0xf3, 0x22, 0x2b, 0x38, 0xeb, 0x68, 0xe5, 0x71, 0x5d, 0xcb, - 0xc3, 0x68, 0xb3, 0x0e, 0x7d, 0x5e, 0x1d, 0xc2, 0x1b, 0x8a, - 0x62, 0x80, 0x48, 0x3e, 0x14, 0x00, 0x00, 0x20, 0x37, 0xcd, - 0x55, 0xca, 0x3f, 0x4b, 0xf0, 0x95, 0xf8, 0xe4, 0xfe, 0x59, - 0xab, 0xbc, 0xc1, 0x8f, 0x0c, 0x3f, 0x41, 0x59, 0xf6, 0x96, - 0xdb, 0x75, 0xae, 0xe7, 0x86, 0x1a, 0x92, 0xa7, 0x53, 0x0a + 0x06, + 0x00, + 0x42, + 0x86, + 0x08, + 0x00, + 0x00, + 0x7d, + 0x00, + 0x7b, + 0x00, + 0x10, + 0x00, + 0x08, + 0x00, + 0x06, + 0x05, + 0x64, + 0x75, + 0x6d, + 0x6d, + 0x79, + 0x00, + 0x39, + 0x00, + 0x6b, + 0x4b, + 0x20, + 0x0b, + 0x1b, + 0xe1, + 0x1f, + 0xd0, + 0x78, + 0xc0, + 0x69, + 0x72, + 0x9c, + 0xe2, + 0xf7, + 0x05, + 0x04, + 0x80, + 0x08, + 0x00, + 0x00, + 0x06, + 0x04, + 0x80, + 0x08, + 0x00, + 0x00, + 0x07, + 0x04, + 0x80, + 0x08, + 0x00, + 0x00, + 0x04, + 0x04, + 0x80, + 0x0c, + 0x00, + 0x00, + 0x08, + 0x02, + 0x40, + 0x64, + 0x09, + 0x02, + 0x40, + 0x64, + 0x01, + 0x04, + 0x80, + 0x00, + 0x75, + 0x30, + 0x03, + 0x02, + 0x45, + 0xac, + 0x0b, + 0x01, + 0x1a, + 0x0c, + 0x00, + 0x02, + 0x10, + 0x41, + 0x94, + 0x41, + 0x8d, + 0x0d, + 0xfb, + 0x60, + 0x7b, + 0xdc, + 0xcc, + 0xa2, + 0x9c, + 0x3e, + 0xa5, + 0xdf, + 0x8d, + 0x00, + 0x08, + 0x2d, + 0x71, + 0x8a, + 0x38, + 0xdf, + 0xdd, + 0xe0, + 0x03, + 0x0e, + 0x01, + 0x04, + 0x0f, + 0x04, + 0x83, + 0xd0, + 0x0a, + 0x27, + 0x10, + 0x04, + 0xad, + 0x15, + 0x3f, + 0xae, + 0x20, + 0x01, + 0x00, + 0x0b, + 0x00, + 0x01, + 0x8f, + 0x00, + 0x00, + 0x01, + 0x8b, + 0x00, + 0x01, + 0x86, + 0x30, + 0x82, + 0x01, + 0x82, + 0x30, + 0x82, + 0x01, + 0x29, + 0xa0, + 0x03, + 0x02, + 0x01, + 0x02, + 0x02, + 0x14, + 0x0a, + 0x73, + 0x0f, + 0x86, + 0x18, + 0xf2, + 0xc3, + 0x30, + 0x01, + 0xd2, + 0xc0, + 0xc1, + 0x62, + 0x52, + 0x13, + 0xf1, + 0x9c, + 0x13, + 0x39, + 0xb5, + 0x30, + 0x0a, + 0x06, + 0x08, + 0x2a, + 0x86, + 0x48, + 0xce, + 0x3d, + 0x04, + 0x03, + 0x02, + 0x30, + 0x17, + 0x31, + 0x15, + 0x30, + 0x13, + 0x06, + 0x03, + 0x55, + 0x04, + 0x03, + 0x0c, + 0x0c, + 0x6d, + 0x61, + 0x70, + 0x61, + 0x6b, + 0x74, + 0x2e, + 0x6c, + 0x6f, + 0x63, + 0x61, + 0x6c, + 0x30, + 0x1e, + 0x17, + 0x0d, + 0x32, + 0x32, + 0x30, + 0x38, + 0x30, + 0x32, + 0x31, + 0x32, + 0x30, + 0x30, + 0x31, + 0x38, + 0x5a, + 0x17, + 0x0d, + 0x32, + 0x32, + 0x30, + 0x39, + 0x30, + 0x31, + 0x31, + 0x32, + 0x30, + 0x30, + 0x31, + 0x38, + 0x5a, + 0x30, + 0x17, + 0x31, + 0x15, + 0x30, + 0x13, + 0x06, + 0x03, + 0x55, + 0x04, + 0x03, + 0x0c, + 0x0c, + 0x6d, + 0x61, + 0x70, + 0x61, + 0x6b, + 0x74, + 0x2e, + 0x6c, + 0x6f, + 0x63, + 0x61, + 0x6c, + 0x30, + 0x59, + 0x30, + 0x13, + 0x06, + 0x07, + 0x2a, + 0x86, + 0x48, + 0xce, + 0x3d, + 0x02, + 0x01, + 0x06, + 0x08, + 0x2a, + 0x86, + 0x48, + 0xce, + 0x3d, + 0x03, + 0x01, + 0x07, + 0x03, + 0x42, + 0x00, + 0x04, + 0x67, + 0xf4, + 0xd3, + 0x8f, + 0x15, + 0x6d, + 0xee, + 0x85, + 0xcc, + 0x2a, + 0x77, + 0xfc, + 0x0b, + 0x8f, + 0x9f, + 0xcf, + 0xa9, + 0x95, + 0x5d, + 0x5b, + 0xcd, + 0xb7, + 0x8b, + 0xba, + 0x31, + 0x0a, + 0x73, + 0x62, + 0xc5, + 0xd0, + 0x0e, + 0x07, + 0x90, + 0xae, + 0x38, + 0x43, + 0x79, + 0xce, + 0x5e, + 0x33, + 0xad, + 0x31, + 0xbf, + 0x9f, + 0x2a, + 0x56, + 0x83, + 0xa5, + 0x24, + 0x16, + 0xab, + 0x0c, + 0xf1, + 0x64, + 0xbe, + 0xe4, + 0x93, + 0xb5, + 0x89, + 0xd6, + 0x05, + 0xe4, + 0xf7, + 0x7b, + 0xa3, + 0x53, + 0x30, + 0x51, + 0x30, + 0x1d, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x0e, + 0x04, + 0x16, + 0x04, + 0x14, + 0x02, + 0x64, + 0x0f, + 0x55, + 0x69, + 0x14, + 0x91, + 0x19, + 0xed, + 0xf9, + 0x1a, + 0xe9, + 0x1d, + 0xa5, + 0x5a, + 0xd0, + 0x48, + 0x96, + 0x9f, + 0x60, + 0x30, + 0x1f, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x23, + 0x04, + 0x18, + 0x30, + 0x16, + 0x80, + 0x14, + 0x02, + 0x64, + 0x0f, + 0x55, + 0x69, + 0x14, + 0x91, + 0x19, + 0xed, + 0xf9, + 0x1a, + 0xe9, + 0x1d, + 0xa5, + 0x5a, + 0xd0, + 0x48, + 0x96, + 0x9f, + 0x60, + 0x30, + 0x0f, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x13, + 0x01, + 0x01, + 0xff, + 0x04, + 0x05, + 0x30, + 0x03, + 0x01, + 0x01, + 0xff, + 0x30, + 0x0a, + 0x06, + 0x08, + 0x2a, + 0x86, + 0x48, + 0xce, + 0x3d, + 0x04, + 0x03, + 0x02, + 0x03, + 0x47, + 0x00, + 0x30, + 0x44, + 0x02, + 0x20, + 0x0a, + 0x82, + 0x92, + 0x6e, + 0xd3, + 0xc6, + 0x66, + 0xd9, + 0xd3, + 0x75, + 0xff, + 0x71, + 0x3b, + 0x61, + 0x46, + 0x21, + 0x00, + 0xe6, + 0x21, + 0x5d, + 0x9c, + 0x86, + 0xe9, + 0x65, + 0x40, + 0x4f, + 0xeb, + 0x70, + 0x4f, + 0x2c, + 0xad, + 0x00, + 0x02, + 0x20, + 0x08, + 0xc2, + 0x07, + 0x5d, + 0x16, + 0xfc, + 0x54, + 0x34, + 0x2b, + 0xb4, + 0x18, + 0x67, + 0x44, + 0x81, + 0xc9, + 0xa9, + 0x67, + 0x2e, + 0xce, + 0xa1, + 0x02, + 0x9f, + 0x3b, + 0xe5, + 0x61, + 0x16, + 0x0b, + 0x50, + 0xf6, + 0xa1, + 0x50, + 0x94, + 0x00, + 0x00, + 0x0f, + 0x00, + 0x00, + 0x4a, + 0x04, + 0x03, + 0x00, + 0x46, + 0x30, + 0x44, + 0x02, + 0x20, + 0x7d, + 0x57, + 0x17, + 0x14, + 0x46, + 0x09, + 0x95, + 0x70, + 0x09, + 0x45, + 0xe8, + 0x9e, + 0x5c, + 0x87, + 0x55, + 0xd9, + 0x08, + 0xc6, + 0x5e, + 0x47, + 0x73, + 0x5e, + 0xb1, + 0xc9, + 0xef, + 0xcb, + 0xe5, + 0x7f, + 0xcc, + 0xb0, + 0x28, + 0xbc, + 0x02, + 0x20, + 0x5d, + 0xe4, + 0x2b, + 0x83, + 0xd9, + 0x78, + 0x75, + 0x45, + 0xf3, + 0x22, + 0x2b, + 0x38, + 0xeb, + 0x68, + 0xe5, + 0x71, + 0x5d, + 0xcb, + 0xc3, + 0x68, + 0xb3, + 0x0e, + 0x7d, + 0x5e, + 0x1d, + 0xc2, + 0x1b, + 0x8a, + 0x62, + 0x80, + 0x48, + 0x3e, + 0x14, + 0x00, + 0x00, + 0x20, + 0x37, + 0xcd, + 0x55, + 0xca, + 0x3f, + 0x4b, + 0xf0, + 0x95, + 0xf8, + 0xe4, + 0xfe, + 0x59, + 0xab, + 0xbc, + 0xc1, + 0x8f, + 0x0c, + 0x3f, + 0x41, + 0x59, + 0xf6, + 0x96, + 0xdb, + 0x75, + 0xae, + 0xe7, + 0x86, + 0x1a, + 0x92, + 0xa7, + 0x53, + 0x0a, }; static const QUIC_PKT_HDR rx_script_5c_expect_hdr = { @@ -639,73 +2861,141 @@ static const QUIC_PKT_HDR rx_script_5c_expect_hdr = { }; static const unsigned char rx_script_5c_body[] = { - 0x18, 0x03, 0x00, 0x04, 0x92, 0xec, 0xaa, 0xd6, 0x47, 0xd8, - 0x8b, 0x56, 0x3b, 0x5f, 0x67, 0xe6, 0xb9, 0xb9, 0xca, 0x72, - 0xca, 0xf2, 0x49, 0x7d, 0x18, 0x02, 0x00, 0x04, 0xa9, 0x6e, - 0x9b, 0x84, 0x26, 0x43, 0x00, 0xc7, 0x55, 0x71, 0x67, 0x2e, - 0x52, 0xdd, 0x47, 0xfd, 0x06, 0x51, 0x33, 0x08, 0x18, 0x01, - 0x00, 0x04, 0x36, 0xd5, 0x1f, 0x06, 0x4e, 0xbf, 0xb4, 0xc9, - 0xef, 0x97, 0x1e, 0x9a, 0x3c, 0xab, 0x1e, 0xfc, 0xb7, 0x90, - 0xc3, 0x1a + 0x18, + 0x03, + 0x00, + 0x04, + 0x92, + 0xec, + 0xaa, + 0xd6, + 0x47, + 0xd8, + 0x8b, + 0x56, + 0x3b, + 0x5f, + 0x67, + 0xe6, + 0xb9, + 0xb9, + 0xca, + 0x72, + 0xca, + 0xf2, + 0x49, + 0x7d, + 0x18, + 0x02, + 0x00, + 0x04, + 0xa9, + 0x6e, + 0x9b, + 0x84, + 0x26, + 0x43, + 0x00, + 0xc7, + 0x55, + 0x71, + 0x67, + 0x2e, + 0x52, + 0xdd, + 0x47, + 0xfd, + 0x06, + 0x51, + 0x33, + 0x08, + 0x18, + 0x01, + 0x00, + 0x04, + 0x36, + 0xd5, + 0x1f, + 0x06, + 0x4e, + 0xbf, + 0xb4, + 0xc9, + 0xef, + 0x97, + 0x1e, + 0x9a, + 0x3c, + 0xab, + 0x1e, + 0xfc, + 0xb7, + 0x90, + 0xc3, + 0x1a, }; static const struct rx_test_op rx_script_5[] = { - RX_OP_ALLOW_1RTT(), - RX_OP_SET_RX_DCID(empty_conn_id), - RX_OP_PROVIDE_SECRET_INITIAL(rx_script_5_c2s_init_dcid), - RX_OP_INJECT_N(5), - RX_OP_CHECK_PKT_N(5a), - RX_OP_CHECK_NO_PKT(), /* not got secret for next packet yet */ - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, QRL_SUITE_AES128GCM, rx_script_5_handshake_secret), - RX_OP_CHECK_PKT_N(5b), - RX_OP_CHECK_NO_PKT(), /* not got secret for next packet yet */ - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, rx_script_5_1rtt_secret), - RX_OP_CHECK_PKT_N(5c), - RX_OP_CHECK_NO_PKT(), + RX_OP_ALLOW_1RTT() + RX_OP_SET_RX_DCID(empty_conn_id) + RX_OP_PROVIDE_SECRET_INITIAL(rx_script_5_c2s_init_dcid) + RX_OP_INJECT_N(5) + RX_OP_CHECK_PKT_N(5a) + RX_OP_CHECK_NO_PKT() /* not got secret for next packet yet */ + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, + QRL_SUITE_AES128GCM, rx_script_5_handshake_secret) + RX_OP_CHECK_PKT_N(5b) + RX_OP_CHECK_NO_PKT() /* not got secret for next packet yet */ + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, + QRL_SUITE_AES128GCM, rx_script_5_1rtt_secret) + RX_OP_CHECK_PKT_N(5c) + RX_OP_CHECK_NO_PKT() /* Discard Initial EL and try injecting the packet again */ - RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_INITIAL), - RX_OP_INJECT_N(5), + RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_INITIAL) + RX_OP_INJECT_N(5) /* Initial packet is not output because we have discarded Initial keys */ - RX_OP_CHECK_PKT_N(5b), - RX_OP_CHECK_PKT_N(5c), - RX_OP_CHECK_NO_PKT(), + RX_OP_CHECK_PKT_N(5b) + RX_OP_CHECK_PKT_N(5c) + RX_OP_CHECK_NO_PKT() /* Try again with discarded keys */ - RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_HANDSHAKE), - RX_OP_INJECT_N(5), - RX_OP_CHECK_PKT_N(5c), - RX_OP_CHECK_NO_PKT(), + RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_HANDSHAKE) + RX_OP_INJECT_N(5) + RX_OP_CHECK_PKT_N(5c) + RX_OP_CHECK_NO_PKT() /* Try again */ - RX_OP_INJECT_N(5), - RX_OP_CHECK_PKT_N(5c), - RX_OP_CHECK_NO_PKT(), + RX_OP_INJECT_N(5) + RX_OP_CHECK_PKT_N(5c) + RX_OP_CHECK_NO_PKT() /* Try again with discarded 1-RTT keys */ - RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_1RTT), - RX_OP_INJECT_N(5), - RX_OP_CHECK_NO_PKT(), + RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_1RTT) + RX_OP_INJECT_N(5) + RX_OP_CHECK_NO_PKT() /* Recreate QRL, test reading packets received before key */ - RX_OP_SET_SCID_LEN(0), - RX_OP_SET_RX_DCID(empty_conn_id), - RX_OP_INJECT_N(5), - RX_OP_CHECK_NO_PKT(), - RX_OP_PROVIDE_SECRET_INITIAL(rx_script_5_c2s_init_dcid), - RX_OP_CHECK_PKT_N(5a), - RX_OP_CHECK_NO_PKT(), - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, QRL_SUITE_AES128GCM, rx_script_5_handshake_secret), - RX_OP_CHECK_PKT_N(5b), - RX_OP_CHECK_NO_PKT(), - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, rx_script_5_1rtt_secret), - RX_OP_CHECK_PKT_N(5c), - RX_OP_CHECK_NO_PKT(), + RX_OP_SET_SCID_LEN(0) + RX_OP_SET_RX_DCID(empty_conn_id) + RX_OP_INJECT_N(5) + RX_OP_CHECK_NO_PKT() + RX_OP_PROVIDE_SECRET_INITIAL(rx_script_5_c2s_init_dcid) + RX_OP_CHECK_PKT_N(5a) + RX_OP_CHECK_NO_PKT() + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, + QRL_SUITE_AES128GCM, rx_script_5_handshake_secret) + RX_OP_CHECK_PKT_N(5b) + RX_OP_CHECK_NO_PKT() + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, + QRL_SUITE_AES128GCM, rx_script_5_1rtt_secret) + RX_OP_CHECK_PKT_N(5c) + RX_OP_CHECK_NO_PKT() - RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_INITIAL), - RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_HANDSHAKE), - RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_1RTT), - RX_OP_INJECT_N(5), - RX_OP_CHECK_NO_PKT(), + RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_INITIAL) + RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_HANDSHAKE) + RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_1RTT) + RX_OP_INJECT_N(5) + RX_OP_CHECK_NO_PKT() - RX_OP_END + RX_OP_END }; /* @@ -717,19 +3007,105 @@ static const QUIC_CONN_ID rx_script_6_c2s_init_dcid = { }; static const unsigned char rx_script_6_handshake_secret[48] = { - 0xd1, 0x41, 0xb0, 0xf6, 0x0d, 0x8b, 0xbd, 0xe8, 0x5b, 0xa8, - 0xff, 0xd7, 0x18, 0x9a, 0x23, 0x7b, 0x13, 0x5c, 0x1e, 0x90, - 0x1d, 0x08, 0x95, 0xcc, 0xc5, 0x8e, 0x73, 0x4e, 0x02, 0x6f, - 0x3c, 0xb6, 0x26, 0x77, 0x8d, 0x53, 0xc5, 0x62, 0x9f, 0xb5, - 0xf0, 0x88, 0xfb, 0xe5, 0x14, 0x71, 0xab, 0xe6 + 0xd1, + 0x41, + 0xb0, + 0xf6, + 0x0d, + 0x8b, + 0xbd, + 0xe8, + 0x5b, + 0xa8, + 0xff, + 0xd7, + 0x18, + 0x9a, + 0x23, + 0x7b, + 0x13, + 0x5c, + 0x1e, + 0x90, + 0x1d, + 0x08, + 0x95, + 0xcc, + 0xc5, + 0x8e, + 0x73, + 0x4e, + 0x02, + 0x6f, + 0x3c, + 0xb6, + 0x26, + 0x77, + 0x8d, + 0x53, + 0xc5, + 0x62, + 0x9f, + 0xb5, + 0xf0, + 0x88, + 0xfb, + 0xe5, + 0x14, + 0x71, + 0xab, + 0xe6, }; static const unsigned char rx_script_6_1rtt_secret[48] = { - 0x2d, 0x6b, 0x9d, 0xd4, 0x39, 0xa0, 0xe7, 0xff, 0x17, 0xe2, - 0xcb, 0x5c, 0x0d, 0x4a, 0xf6, 0x3f, 0xf4, 0xfe, 0xfc, 0xe5, - 0x22, 0xfa, 0xf5, 0x5b, 0xc0, 0xb2, 0x18, 0xbb, 0x92, 0x4d, - 0x35, 0xea, 0x67, 0xa6, 0xe7, 0xc1, 0x90, 0x10, 0xc9, 0x14, - 0x46, 0xf5, 0x95, 0x57, 0x8b, 0x90, 0x88, 0x5d + 0x2d, + 0x6b, + 0x9d, + 0xd4, + 0x39, + 0xa0, + 0xe7, + 0xff, + 0x17, + 0xe2, + 0xcb, + 0x5c, + 0x0d, + 0x4a, + 0xf6, + 0x3f, + 0xf4, + 0xfe, + 0xfc, + 0xe5, + 0x22, + 0xfa, + 0xf5, + 0x5b, + 0xc0, + 0xb2, + 0x18, + 0xbb, + 0x92, + 0x4d, + 0x35, + 0xea, + 0x67, + 0xa6, + 0xe7, + 0xc1, + 0x90, + 0x10, + 0xc9, + 0x14, + 0x46, + 0xf5, + 0x95, + 0x57, + 0x8b, + 0x90, + 0x88, + 0x5d, }; static const unsigned char rx_script_6_in[] = { @@ -750,51 +3126,450 @@ static const unsigned char rx_script_6_in[] = { 0xbe, /* Length (446) */ 0xa9, 0xe2, /* PN (0) */ - 0x83, 0x39, 0x95, 0x8f, 0x8f, 0x8c, 0xa9, 0xaf, 0x10, 0x29, - 0x3d, 0xfc, 0x56, 0x4a, 0x1c, 0x4b, 0xc9, 0x48, 0xb1, 0xaf, - 0x36, 0xd5, 0xac, 0x95, 0xbf, 0xfd, 0x2c, 0x4d, 0x70, 0x2e, - 0x5b, 0x7c, 0x22, 0x5f, 0x5f, 0xee, 0x10, 0x8f, 0xfb, 0x0b, - 0x5f, 0x9d, 0x7e, 0x68, 0x2f, 0x94, 0x0b, 0xdb, 0xed, 0xef, - 0xfa, 0x4e, 0xc6, 0xd5, 0xe7, 0xef, 0xe0, 0x78, 0x3c, 0xdc, - 0xe9, 0xd8, 0xe8, 0x56, 0x71, 0xd7, 0xe7, 0x6c, 0x7f, 0x5d, - 0xaa, 0x7a, 0x52, 0x1d, 0x95, 0x7a, 0x80, 0x70, 0x38, 0xc0, - 0x8b, 0xa1, 0x2f, 0x09, 0x16, 0xd2, 0xec, 0xa3, 0x23, 0x72, - 0x45, 0x3c, 0xbd, 0x8c, 0xda, 0xbb, 0x37, 0x5a, 0x8d, 0xb2, - 0x00, 0x7e, 0x67, 0x0c, 0xa0, 0x32, 0xdd, 0x80, 0x07, 0x71, - 0xb0, 0x95, 0x21, 0xbc, 0x1e, 0xbd, 0x63, 0x0a, 0x10, 0xe7, - 0x4b, 0x6e, 0x2e, 0x85, 0x3a, 0x65, 0xf7, 0x06, 0x6e, 0x7e, - 0x8f, 0x65, 0x8c, 0xb1, 0x93, 0xe9, 0x0d, 0xe8, 0x46, 0xe7, - 0xcf, 0xa7, 0xd2, 0x8b, 0x15, 0x23, 0xec, 0xc3, 0xec, 0x44, - 0xda, 0x62, 0x15, 0x35, 0x34, 0x2f, 0x62, 0x77, 0xc8, 0x1f, - 0x83, 0x22, 0x00, 0xe5, 0xc0, 0x89, 0xb8, 0x97, 0xd2, 0x37, - 0x02, 0xea, 0xa2, 0x35, 0xbf, 0x19, 0xf0, 0xba, 0x1d, 0xb7, - 0xaa, 0x36, 0xbb, 0x11, 0x60, 0xc3, 0x45, 0x1f, 0xe5, 0x18, - 0xde, 0x4c, 0x01, 0x23, 0x2d, 0x17, 0x78, 0xdd, 0x4c, 0x8a, - 0x1e, 0x1b, 0xd4, 0xda, 0x56, 0x43, 0x13, 0xa4, 0x4f, 0xfd, - 0xd5, 0x92, 0x6a, 0x05, 0x5f, 0x14, 0x63, 0x85, 0x7d, 0xf1, - 0x31, 0xb8, 0x27, 0x0b, 0xa6, 0xb5, 0x50, 0xca, 0x8b, 0x0e, - 0xa1, 0x0d, 0xf9, 0xc4, 0xea, 0x6a, 0x6e, 0x4b, 0x6d, 0xdf, - 0x49, 0xe8, 0x32, 0xf6, 0x85, 0xc4, 0x29, 0x26, 0x32, 0xfb, - 0x5e, 0xa8, 0x55, 0x6b, 0x67, 0xe9, 0xaa, 0x35, 0x33, 0x90, - 0xd8, 0x2a, 0x71, 0x0b, 0x6a, 0x48, 0xc4, 0xa3, 0x8b, 0xe0, - 0xe7, 0x00, 0x3d, 0xee, 0x30, 0x70, 0x84, 0xbd, 0xa3, 0x3c, - 0x9e, 0xa3, 0x5c, 0x69, 0xab, 0x55, 0x7b, 0xe2, 0xe5, 0x86, - 0x13, 0xcb, 0x93, 0x3f, 0xcb, 0x3e, 0x6d, 0xc9, 0xc2, 0x10, - 0x2b, 0x00, 0x9b, 0x3f, 0x14, 0x4e, 0x04, 0x27, 0xc0, 0xae, - 0x1d, 0x48, 0x89, 0x3a, 0xf4, 0xac, 0xe0, 0x05, 0x07, 0xc9, - 0x74, 0x6e, 0x21, 0x01, 0xe9, 0x26, 0xfd, 0xb4, 0xb2, 0x2a, - 0xda, 0x72, 0xda, 0xbf, 0x63, 0x9d, 0x37, 0xaf, 0x90, 0x05, - 0xd6, 0x89, 0xc7, 0xa6, 0x81, 0x4e, 0x2a, 0x30, 0xe3, 0x05, - 0x88, 0x9f, 0xd0, 0xba, 0x8d, 0xc4, 0x21, 0x52, 0x5a, 0x7a, - 0xe1, 0xad, 0xd3, 0x88, 0xc2, 0x18, 0xad, 0x4c, 0xb1, 0x66, - 0x73, 0x1b, 0xf2, 0xd1, 0xb9, 0x43, 0xaa, 0xc4, 0x66, 0xcd, - 0x42, 0xfa, 0x80, 0xec, 0xa1, 0x7c, 0x45, 0x02, 0x53, 0x45, - 0xd5, 0x07, 0xd4, 0x70, 0x12, 0x1b, 0x08, 0x05, 0x6e, 0x99, - 0x0a, 0xd3, 0x5b, 0x99, 0x6b, 0x65, 0xc4, 0xc0, 0x04, 0x1b, - 0x75, 0xf2, 0x86, 0x99, 0x09, 0x4a, 0x50, 0x70, 0x00, 0x7a, - 0x93, 0xaa, 0xe6, 0xf4, 0x03, 0x29, 0x06, 0xa4, 0x30, 0x6d, - 0x52, 0xbd, 0x60, 0xd1, 0x7e, 0xd6, 0x07, 0xc0, 0x41, 0x01, - 0x12, 0x3e, 0x16, 0x94, + 0x83, + 0x39, + 0x95, + 0x8f, + 0x8f, + 0x8c, + 0xa9, + 0xaf, + 0x10, + 0x29, + 0x3d, + 0xfc, + 0x56, + 0x4a, + 0x1c, + 0x4b, + 0xc9, + 0x48, + 0xb1, + 0xaf, + 0x36, + 0xd5, + 0xac, + 0x95, + 0xbf, + 0xfd, + 0x2c, + 0x4d, + 0x70, + 0x2e, + 0x5b, + 0x7c, + 0x22, + 0x5f, + 0x5f, + 0xee, + 0x10, + 0x8f, + 0xfb, + 0x0b, + 0x5f, + 0x9d, + 0x7e, + 0x68, + 0x2f, + 0x94, + 0x0b, + 0xdb, + 0xed, + 0xef, + 0xfa, + 0x4e, + 0xc6, + 0xd5, + 0xe7, + 0xef, + 0xe0, + 0x78, + 0x3c, + 0xdc, + 0xe9, + 0xd8, + 0xe8, + 0x56, + 0x71, + 0xd7, + 0xe7, + 0x6c, + 0x7f, + 0x5d, + 0xaa, + 0x7a, + 0x52, + 0x1d, + 0x95, + 0x7a, + 0x80, + 0x70, + 0x38, + 0xc0, + 0x8b, + 0xa1, + 0x2f, + 0x09, + 0x16, + 0xd2, + 0xec, + 0xa3, + 0x23, + 0x72, + 0x45, + 0x3c, + 0xbd, + 0x8c, + 0xda, + 0xbb, + 0x37, + 0x5a, + 0x8d, + 0xb2, + 0x00, + 0x7e, + 0x67, + 0x0c, + 0xa0, + 0x32, + 0xdd, + 0x80, + 0x07, + 0x71, + 0xb0, + 0x95, + 0x21, + 0xbc, + 0x1e, + 0xbd, + 0x63, + 0x0a, + 0x10, + 0xe7, + 0x4b, + 0x6e, + 0x2e, + 0x85, + 0x3a, + 0x65, + 0xf7, + 0x06, + 0x6e, + 0x7e, + 0x8f, + 0x65, + 0x8c, + 0xb1, + 0x93, + 0xe9, + 0x0d, + 0xe8, + 0x46, + 0xe7, + 0xcf, + 0xa7, + 0xd2, + 0x8b, + 0x15, + 0x23, + 0xec, + 0xc3, + 0xec, + 0x44, + 0xda, + 0x62, + 0x15, + 0x35, + 0x34, + 0x2f, + 0x62, + 0x77, + 0xc8, + 0x1f, + 0x83, + 0x22, + 0x00, + 0xe5, + 0xc0, + 0x89, + 0xb8, + 0x97, + 0xd2, + 0x37, + 0x02, + 0xea, + 0xa2, + 0x35, + 0xbf, + 0x19, + 0xf0, + 0xba, + 0x1d, + 0xb7, + 0xaa, + 0x36, + 0xbb, + 0x11, + 0x60, + 0xc3, + 0x45, + 0x1f, + 0xe5, + 0x18, + 0xde, + 0x4c, + 0x01, + 0x23, + 0x2d, + 0x17, + 0x78, + 0xdd, + 0x4c, + 0x8a, + 0x1e, + 0x1b, + 0xd4, + 0xda, + 0x56, + 0x43, + 0x13, + 0xa4, + 0x4f, + 0xfd, + 0xd5, + 0x92, + 0x6a, + 0x05, + 0x5f, + 0x14, + 0x63, + 0x85, + 0x7d, + 0xf1, + 0x31, + 0xb8, + 0x27, + 0x0b, + 0xa6, + 0xb5, + 0x50, + 0xca, + 0x8b, + 0x0e, + 0xa1, + 0x0d, + 0xf9, + 0xc4, + 0xea, + 0x6a, + 0x6e, + 0x4b, + 0x6d, + 0xdf, + 0x49, + 0xe8, + 0x32, + 0xf6, + 0x85, + 0xc4, + 0x29, + 0x26, + 0x32, + 0xfb, + 0x5e, + 0xa8, + 0x55, + 0x6b, + 0x67, + 0xe9, + 0xaa, + 0x35, + 0x33, + 0x90, + 0xd8, + 0x2a, + 0x71, + 0x0b, + 0x6a, + 0x48, + 0xc4, + 0xa3, + 0x8b, + 0xe0, + 0xe7, + 0x00, + 0x3d, + 0xee, + 0x30, + 0x70, + 0x84, + 0xbd, + 0xa3, + 0x3c, + 0x9e, + 0xa3, + 0x5c, + 0x69, + 0xab, + 0x55, + 0x7b, + 0xe2, + 0xe5, + 0x86, + 0x13, + 0xcb, + 0x93, + 0x3f, + 0xcb, + 0x3e, + 0x6d, + 0xc9, + 0xc2, + 0x10, + 0x2b, + 0x00, + 0x9b, + 0x3f, + 0x14, + 0x4e, + 0x04, + 0x27, + 0xc0, + 0xae, + 0x1d, + 0x48, + 0x89, + 0x3a, + 0xf4, + 0xac, + 0xe0, + 0x05, + 0x07, + 0xc9, + 0x74, + 0x6e, + 0x21, + 0x01, + 0xe9, + 0x26, + 0xfd, + 0xb4, + 0xb2, + 0x2a, + 0xda, + 0x72, + 0xda, + 0xbf, + 0x63, + 0x9d, + 0x37, + 0xaf, + 0x90, + 0x05, + 0xd6, + 0x89, + 0xc7, + 0xa6, + 0x81, + 0x4e, + 0x2a, + 0x30, + 0xe3, + 0x05, + 0x88, + 0x9f, + 0xd0, + 0xba, + 0x8d, + 0xc4, + 0x21, + 0x52, + 0x5a, + 0x7a, + 0xe1, + 0xad, + 0xd3, + 0x88, + 0xc2, + 0x18, + 0xad, + 0x4c, + 0xb1, + 0x66, + 0x73, + 0x1b, + 0xf2, + 0xd1, + 0xb9, + 0x43, + 0xaa, + 0xc4, + 0x66, + 0xcd, + 0x42, + 0xfa, + 0x80, + 0xec, + 0xa1, + 0x7c, + 0x45, + 0x02, + 0x53, + 0x45, + 0xd5, + 0x07, + 0xd4, + 0x70, + 0x12, + 0x1b, + 0x08, + 0x05, + 0x6e, + 0x99, + 0x0a, + 0xd3, + 0x5b, + 0x99, + 0x6b, + 0x65, + 0xc4, + 0xc0, + 0x04, + 0x1b, + 0x75, + 0xf2, + 0x86, + 0x99, + 0x09, + 0x4a, + 0x50, + 0x70, + 0x00, + 0x7a, + 0x93, + 0xaa, + 0xe6, + 0xf4, + 0x03, + 0x29, + 0x06, + 0xa4, + 0x30, + 0x6d, + 0x52, + 0xbd, + 0x60, + 0xd1, + 0x7e, + 0xd6, + 0x07, + 0xc0, + 0x41, + 0x01, + 0x12, + 0x3e, + 0x16, + 0x94, /* Second Packet: Handshake */ 0xea, /* Long, Handshake, PN Length=2 bytes */ @@ -812,89 +3587,785 @@ static const unsigned char rx_script_6_in[] = { 0xb0, /* Length (688) */ 0x3a, 0xc5, /* PN (0) */ - 0x3b, 0x8e, 0x4c, 0x01, 0x72, 0x6b, 0xfa, 0xbb, 0xad, 0xf9, - 0x9e, 0x21, 0xb1, 0xd0, 0x01, 0xf1, 0xd4, 0x67, 0x8d, 0x2c, - 0xee, 0x04, 0x60, 0x4a, 0xe2, 0xe4, 0xc6, 0x89, 0x01, 0xae, - 0x3c, 0x1f, 0xf7, 0xe6, 0xf7, 0xac, 0x26, 0xcf, 0x3c, 0x6d, - 0x1d, 0xfd, 0x11, 0x02, 0x51, 0x73, 0xb5, 0xe1, 0xb2, 0x44, - 0x42, 0x32, 0x0f, 0xf5, 0x3d, 0x55, 0x2d, 0x1f, 0x02, 0x29, - 0x51, 0x35, 0xdb, 0xc7, 0x7a, 0x34, 0x4b, 0xec, 0x60, 0x49, - 0xa2, 0x90, 0x11, 0xef, 0x5a, 0xa9, 0x1c, 0xf7, 0xd9, 0x21, - 0x68, 0x1c, 0x2b, 0xc6, 0x57, 0xde, 0xb1, 0x0b, 0x31, 0xed, - 0xef, 0x16, 0xba, 0x08, 0xb9, 0xe2, 0xd9, 0xd0, 0xd8, 0x1f, - 0xc4, 0x32, 0xe8, 0x45, 0x2a, 0x86, 0xe4, 0xd3, 0xaf, 0x72, - 0x4f, 0x30, 0x01, 0x71, 0x15, 0x9b, 0xa9, 0x55, 0x35, 0xf7, - 0x39, 0x7e, 0x6a, 0x59, 0x18, 0x4f, 0xe6, 0xdf, 0xb5, 0x0d, - 0xc2, 0xe7, 0xb2, 0xa1, 0xa6, 0xa3, 0x9c, 0xf0, 0x0d, 0x59, - 0x05, 0x49, 0x95, 0xfa, 0xcc, 0x72, 0xd7, 0xc0, 0x84, 0x2e, - 0xc4, 0x1c, 0xd4, 0xa0, 0xe3, 0x6c, 0x5a, 0x8c, 0x94, 0x4d, - 0x37, 0x1a, 0x1c, 0x68, 0x93, 0x5f, 0xe5, 0x99, 0x27, 0xc6, - 0x06, 0xaa, 0x1f, 0x29, 0x17, 0xc5, 0x8c, 0x3d, 0x53, 0xa7, - 0x05, 0x3a, 0x44, 0x53, 0x86, 0xed, 0x56, 0x99, 0x4c, 0xe2, - 0x7b, 0x3a, 0x1e, 0x5d, 0x6d, 0xac, 0x78, 0x1e, 0xfa, 0x55, - 0x58, 0x6e, 0x72, 0xee, 0xf9, 0x33, 0x64, 0x7f, 0x93, 0x3c, - 0xfe, 0x18, 0x97, 0x6b, 0x02, 0x74, 0x90, 0x0d, 0xba, 0x89, - 0xc0, 0x22, 0x0a, 0x0a, 0x37, 0x4c, 0x28, 0x74, 0xa7, 0x3a, - 0x44, 0x74, 0x42, 0xff, 0xf1, 0xd2, 0x8d, 0x0c, 0xc1, 0xed, - 0x98, 0x98, 0x8e, 0xa8, 0x6b, 0x95, 0x6a, 0x86, 0x0b, 0xb4, - 0x95, 0x58, 0x34, 0x12, 0xb0, 0xc0, 0xf8, 0x2d, 0x5b, 0x40, - 0x51, 0x80, 0x07, 0x91, 0x31, 0x77, 0xd3, 0x06, 0xa5, 0xe5, - 0x1f, 0xe2, 0xf8, 0x92, 0xe4, 0x23, 0x2b, 0xf0, 0x4c, 0xa9, - 0xa5, 0x6c, 0x6f, 0xaf, 0xaf, 0xbf, 0x97, 0xcf, 0x46, 0xf2, - 0x8d, 0x61, 0x0e, 0x73, 0xcd, 0xc5, 0xde, 0xda, 0x50, 0x82, - 0x61, 0x6d, 0xb1, 0xa2, 0xbe, 0x6b, 0x99, 0xcd, 0x5b, 0x99, - 0x8f, 0x66, 0xab, 0x11, 0x78, 0xcc, 0xdb, 0x66, 0x98, 0xca, - 0x19, 0x92, 0xf4, 0x05, 0xae, 0xe6, 0xf3, 0xe7, 0xf0, 0x30, - 0x28, 0x31, 0x74, 0xff, 0xe2, 0xb3, 0x3a, 0x4f, 0x79, 0xe7, - 0x2a, 0x9f, 0xe3, 0x41, 0xb2, 0x88, 0xc8, 0x8f, 0x77, 0x57, - 0x42, 0x65, 0xdb, 0x07, 0xf6, 0x5f, 0xb8, 0x34, 0x17, 0xe3, - 0x8d, 0x22, 0x5b, 0x88, 0x94, 0x60, 0x97, 0x32, 0x3d, 0x8a, - 0x51, 0x9d, 0xb5, 0xac, 0xd7, 0x99, 0x96, 0x23, 0x6d, 0xc9, - 0xab, 0x61, 0x41, 0x8f, 0x72, 0x1b, 0xf8, 0x84, 0xd9, 0x57, - 0x88, 0x68, 0x3d, 0x73, 0x5f, 0xb1, 0x18, 0x5c, 0x3a, 0x35, - 0xd2, 0xc5, 0xb7, 0x29, 0xc7, 0x95, 0xdd, 0x21, 0xc0, 0x78, - 0x49, 0xf3, 0x24, 0xe0, 0x4c, 0x5c, 0x32, 0x08, 0xb7, 0x00, - 0x43, 0x70, 0x5a, 0x95, 0x23, 0x91, 0xf5, 0xb7, 0x61, 0x85, - 0x6f, 0xb3, 0xa4, 0x6b, 0x05, 0x9d, 0x39, 0xa3, 0xb1, 0x1c, - 0x61, 0xc5, 0xa5, 0xe7, 0x9a, 0xe9, 0x5d, 0xaa, 0xca, 0x11, - 0xd8, 0x4b, 0xa4, 0x9c, 0x18, 0x4e, 0x2b, 0x2d, 0x75, 0xc1, - 0x12, 0x20, 0xe4, 0x66, 0xa5, 0x59, 0x67, 0x4b, 0xcc, 0x52, - 0x2d, 0xfa, 0xaa, 0xa4, 0xe9, 0xfc, 0x79, 0xd7, 0xff, 0x03, - 0x3e, 0xec, 0xba, 0x97, 0x37, 0x52, 0xc1, 0x57, 0x31, 0x8e, - 0x57, 0x0c, 0x54, 0x92, 0x9c, 0x25, 0x5c, 0xfa, 0x9f, 0xa5, - 0x36, 0x18, 0xd0, 0xaa, 0xf3, 0x3b, 0x5b, 0x59, 0xbd, 0x33, - 0x5e, 0x7d, 0x74, 0x7c, 0xaf, 0xe9, 0x54, 0x80, 0xc4, 0xb4, - 0xa1, 0x24, 0x9e, 0x23, 0x0d, 0xbf, 0x4e, 0x0f, 0xaf, 0xa5, - 0x16, 0xcb, 0x3b, 0xfa, 0x33, 0xa5, 0x68, 0xa6, 0x64, 0x48, - 0x2f, 0x5e, 0xfa, 0x64, 0x4e, 0xe3, 0x27, 0x4f, 0x13, 0xe6, - 0x37, 0xf6, 0xb9, 0x63, 0x4b, 0xdc, 0x49, 0x3c, 0x5e, 0x9e, - 0x06, 0xea, 0xac, 0xa3, 0xdf, 0x6c, 0x49, 0xfb, 0xa1, 0x01, - 0x4f, 0x6f, 0x74, 0x1f, 0xd3, 0x26, 0xa1, 0x92, 0x3e, 0xe0, - 0x73, 0xd6, 0x3b, 0x67, 0x13, 0x53, 0x2e, 0xcb, 0xbc, 0x83, - 0xd0, 0x6e, 0x28, 0xb1, 0xcb, 0xd9, 0x66, 0xe0, 0x33, 0x59, - 0x45, 0xd3, 0x13, 0xc2, 0x48, 0xd5, 0x9e, 0x88, 0xba, 0x75, - 0x7b, 0xb1, 0xfe, 0x6f, 0xec, 0xde, 0xff, 0x14, 0x59, 0x75, - 0xbf, 0x1a, 0x74, 0x47, 0xc5, 0xd8, 0xe8, 0x1b, 0x3c, 0x86, - 0xd7, 0x1f, 0x99, 0x11, 0xd3, 0x29, 0xfd, 0x5d, 0x22, 0x7e, - 0x03, 0x78, 0xed, 0x62, 0x0e, 0xbe, 0x6d, 0x75, 0xf4, 0xa8, - 0x6e, 0xc7, 0x21, 0x76, 0xc5, 0xa0, 0x0c, 0xaa, 0x58, 0x78, - 0x7e, 0x6e, 0xfc, 0x1e, 0x2a, 0x1c, 0xdd, 0xe5, 0x78, 0x08, - 0xbd, 0xdb, 0xea, 0x8f, 0x8a, 0xa5, 0xbf, 0x93, 0xfe, 0x0f, - 0x03, 0xa1, 0xc8, 0x64, 0x9f, 0x4a, + 0x3b, + 0x8e, + 0x4c, + 0x01, + 0x72, + 0x6b, + 0xfa, + 0xbb, + 0xad, + 0xf9, + 0x9e, + 0x21, + 0xb1, + 0xd0, + 0x01, + 0xf1, + 0xd4, + 0x67, + 0x8d, + 0x2c, + 0xee, + 0x04, + 0x60, + 0x4a, + 0xe2, + 0xe4, + 0xc6, + 0x89, + 0x01, + 0xae, + 0x3c, + 0x1f, + 0xf7, + 0xe6, + 0xf7, + 0xac, + 0x26, + 0xcf, + 0x3c, + 0x6d, + 0x1d, + 0xfd, + 0x11, + 0x02, + 0x51, + 0x73, + 0xb5, + 0xe1, + 0xb2, + 0x44, + 0x42, + 0x32, + 0x0f, + 0xf5, + 0x3d, + 0x55, + 0x2d, + 0x1f, + 0x02, + 0x29, + 0x51, + 0x35, + 0xdb, + 0xc7, + 0x7a, + 0x34, + 0x4b, + 0xec, + 0x60, + 0x49, + 0xa2, + 0x90, + 0x11, + 0xef, + 0x5a, + 0xa9, + 0x1c, + 0xf7, + 0xd9, + 0x21, + 0x68, + 0x1c, + 0x2b, + 0xc6, + 0x57, + 0xde, + 0xb1, + 0x0b, + 0x31, + 0xed, + 0xef, + 0x16, + 0xba, + 0x08, + 0xb9, + 0xe2, + 0xd9, + 0xd0, + 0xd8, + 0x1f, + 0xc4, + 0x32, + 0xe8, + 0x45, + 0x2a, + 0x86, + 0xe4, + 0xd3, + 0xaf, + 0x72, + 0x4f, + 0x30, + 0x01, + 0x71, + 0x15, + 0x9b, + 0xa9, + 0x55, + 0x35, + 0xf7, + 0x39, + 0x7e, + 0x6a, + 0x59, + 0x18, + 0x4f, + 0xe6, + 0xdf, + 0xb5, + 0x0d, + 0xc2, + 0xe7, + 0xb2, + 0xa1, + 0xa6, + 0xa3, + 0x9c, + 0xf0, + 0x0d, + 0x59, + 0x05, + 0x49, + 0x95, + 0xfa, + 0xcc, + 0x72, + 0xd7, + 0xc0, + 0x84, + 0x2e, + 0xc4, + 0x1c, + 0xd4, + 0xa0, + 0xe3, + 0x6c, + 0x5a, + 0x8c, + 0x94, + 0x4d, + 0x37, + 0x1a, + 0x1c, + 0x68, + 0x93, + 0x5f, + 0xe5, + 0x99, + 0x27, + 0xc6, + 0x06, + 0xaa, + 0x1f, + 0x29, + 0x17, + 0xc5, + 0x8c, + 0x3d, + 0x53, + 0xa7, + 0x05, + 0x3a, + 0x44, + 0x53, + 0x86, + 0xed, + 0x56, + 0x99, + 0x4c, + 0xe2, + 0x7b, + 0x3a, + 0x1e, + 0x5d, + 0x6d, + 0xac, + 0x78, + 0x1e, + 0xfa, + 0x55, + 0x58, + 0x6e, + 0x72, + 0xee, + 0xf9, + 0x33, + 0x64, + 0x7f, + 0x93, + 0x3c, + 0xfe, + 0x18, + 0x97, + 0x6b, + 0x02, + 0x74, + 0x90, + 0x0d, + 0xba, + 0x89, + 0xc0, + 0x22, + 0x0a, + 0x0a, + 0x37, + 0x4c, + 0x28, + 0x74, + 0xa7, + 0x3a, + 0x44, + 0x74, + 0x42, + 0xff, + 0xf1, + 0xd2, + 0x8d, + 0x0c, + 0xc1, + 0xed, + 0x98, + 0x98, + 0x8e, + 0xa8, + 0x6b, + 0x95, + 0x6a, + 0x86, + 0x0b, + 0xb4, + 0x95, + 0x58, + 0x34, + 0x12, + 0xb0, + 0xc0, + 0xf8, + 0x2d, + 0x5b, + 0x40, + 0x51, + 0x80, + 0x07, + 0x91, + 0x31, + 0x77, + 0xd3, + 0x06, + 0xa5, + 0xe5, + 0x1f, + 0xe2, + 0xf8, + 0x92, + 0xe4, + 0x23, + 0x2b, + 0xf0, + 0x4c, + 0xa9, + 0xa5, + 0x6c, + 0x6f, + 0xaf, + 0xaf, + 0xbf, + 0x97, + 0xcf, + 0x46, + 0xf2, + 0x8d, + 0x61, + 0x0e, + 0x73, + 0xcd, + 0xc5, + 0xde, + 0xda, + 0x50, + 0x82, + 0x61, + 0x6d, + 0xb1, + 0xa2, + 0xbe, + 0x6b, + 0x99, + 0xcd, + 0x5b, + 0x99, + 0x8f, + 0x66, + 0xab, + 0x11, + 0x78, + 0xcc, + 0xdb, + 0x66, + 0x98, + 0xca, + 0x19, + 0x92, + 0xf4, + 0x05, + 0xae, + 0xe6, + 0xf3, + 0xe7, + 0xf0, + 0x30, + 0x28, + 0x31, + 0x74, + 0xff, + 0xe2, + 0xb3, + 0x3a, + 0x4f, + 0x79, + 0xe7, + 0x2a, + 0x9f, + 0xe3, + 0x41, + 0xb2, + 0x88, + 0xc8, + 0x8f, + 0x77, + 0x57, + 0x42, + 0x65, + 0xdb, + 0x07, + 0xf6, + 0x5f, + 0xb8, + 0x34, + 0x17, + 0xe3, + 0x8d, + 0x22, + 0x5b, + 0x88, + 0x94, + 0x60, + 0x97, + 0x32, + 0x3d, + 0x8a, + 0x51, + 0x9d, + 0xb5, + 0xac, + 0xd7, + 0x99, + 0x96, + 0x23, + 0x6d, + 0xc9, + 0xab, + 0x61, + 0x41, + 0x8f, + 0x72, + 0x1b, + 0xf8, + 0x84, + 0xd9, + 0x57, + 0x88, + 0x68, + 0x3d, + 0x73, + 0x5f, + 0xb1, + 0x18, + 0x5c, + 0x3a, + 0x35, + 0xd2, + 0xc5, + 0xb7, + 0x29, + 0xc7, + 0x95, + 0xdd, + 0x21, + 0xc0, + 0x78, + 0x49, + 0xf3, + 0x24, + 0xe0, + 0x4c, + 0x5c, + 0x32, + 0x08, + 0xb7, + 0x00, + 0x43, + 0x70, + 0x5a, + 0x95, + 0x23, + 0x91, + 0xf5, + 0xb7, + 0x61, + 0x85, + 0x6f, + 0xb3, + 0xa4, + 0x6b, + 0x05, + 0x9d, + 0x39, + 0xa3, + 0xb1, + 0x1c, + 0x61, + 0xc5, + 0xa5, + 0xe7, + 0x9a, + 0xe9, + 0x5d, + 0xaa, + 0xca, + 0x11, + 0xd8, + 0x4b, + 0xa4, + 0x9c, + 0x18, + 0x4e, + 0x2b, + 0x2d, + 0x75, + 0xc1, + 0x12, + 0x20, + 0xe4, + 0x66, + 0xa5, + 0x59, + 0x67, + 0x4b, + 0xcc, + 0x52, + 0x2d, + 0xfa, + 0xaa, + 0xa4, + 0xe9, + 0xfc, + 0x79, + 0xd7, + 0xff, + 0x03, + 0x3e, + 0xec, + 0xba, + 0x97, + 0x37, + 0x52, + 0xc1, + 0x57, + 0x31, + 0x8e, + 0x57, + 0x0c, + 0x54, + 0x92, + 0x9c, + 0x25, + 0x5c, + 0xfa, + 0x9f, + 0xa5, + 0x36, + 0x18, + 0xd0, + 0xaa, + 0xf3, + 0x3b, + 0x5b, + 0x59, + 0xbd, + 0x33, + 0x5e, + 0x7d, + 0x74, + 0x7c, + 0xaf, + 0xe9, + 0x54, + 0x80, + 0xc4, + 0xb4, + 0xa1, + 0x24, + 0x9e, + 0x23, + 0x0d, + 0xbf, + 0x4e, + 0x0f, + 0xaf, + 0xa5, + 0x16, + 0xcb, + 0x3b, + 0xfa, + 0x33, + 0xa5, + 0x68, + 0xa6, + 0x64, + 0x48, + 0x2f, + 0x5e, + 0xfa, + 0x64, + 0x4e, + 0xe3, + 0x27, + 0x4f, + 0x13, + 0xe6, + 0x37, + 0xf6, + 0xb9, + 0x63, + 0x4b, + 0xdc, + 0x49, + 0x3c, + 0x5e, + 0x9e, + 0x06, + 0xea, + 0xac, + 0xa3, + 0xdf, + 0x6c, + 0x49, + 0xfb, + 0xa1, + 0x01, + 0x4f, + 0x6f, + 0x74, + 0x1f, + 0xd3, + 0x26, + 0xa1, + 0x92, + 0x3e, + 0xe0, + 0x73, + 0xd6, + 0x3b, + 0x67, + 0x13, + 0x53, + 0x2e, + 0xcb, + 0xbc, + 0x83, + 0xd0, + 0x6e, + 0x28, + 0xb1, + 0xcb, + 0xd9, + 0x66, + 0xe0, + 0x33, + 0x59, + 0x45, + 0xd3, + 0x13, + 0xc2, + 0x48, + 0xd5, + 0x9e, + 0x88, + 0xba, + 0x75, + 0x7b, + 0xb1, + 0xfe, + 0x6f, + 0xec, + 0xde, + 0xff, + 0x14, + 0x59, + 0x75, + 0xbf, + 0x1a, + 0x74, + 0x47, + 0xc5, + 0xd8, + 0xe8, + 0x1b, + 0x3c, + 0x86, + 0xd7, + 0x1f, + 0x99, + 0x11, + 0xd3, + 0x29, + 0xfd, + 0x5d, + 0x22, + 0x7e, + 0x03, + 0x78, + 0xed, + 0x62, + 0x0e, + 0xbe, + 0x6d, + 0x75, + 0xf4, + 0xa8, + 0x6e, + 0xc7, + 0x21, + 0x76, + 0xc5, + 0xa0, + 0x0c, + 0xaa, + 0x58, + 0x78, + 0x7e, + 0x6e, + 0xfc, + 0x1e, + 0x2a, + 0x1c, + 0xdd, + 0xe5, + 0x78, + 0x08, + 0xbd, + 0xdb, + 0xea, + 0x8f, + 0x8a, + 0xa5, + 0xbf, + 0x93, + 0xfe, + 0x0f, + 0x03, + 0xa1, + 0xc8, + 0x64, + 0x9f, + 0x4a, /* Third Packet: 1-RTT */ 0x48, /* Short, 1-RTT, Spin=0, KP=0, PN Length=2 bytes */ 0x3e, 0x28, /* PN (0) */ - 0xb9, 0xdb, 0x61, 0xf8, 0x8b, 0x3a, 0xef, 0x26, 0x69, 0xf2, - 0x57, 0xc6, 0x84, 0x25, 0x6b, 0x77, 0xbe, 0x8c, 0x43, 0x32, - 0xf3, 0x9a, 0xd1, 0x85, 0x14, 0xbc, 0x89, 0x3b, 0x9c, 0xf3, - 0xfc, 0x00, 0xa1, 0x3a, 0xc3, 0xc4, 0x1e, 0xdf, 0xd0, 0x11, - 0x70, 0xd9, 0x02, 0x7a, 0xd4, 0xef, 0x86, 0x67, 0xb1, 0x1e, - 0x5d, 0xe3, 0x7f, 0x82, 0x14, 0x52, 0xa5, 0x8a, 0x89, 0xa7, - 0x98, 0x75, 0x2f, 0x8a, 0x00, 0xf3, 0xbd, 0x49, 0x26, 0x4d, - 0x0c, 0xc7, 0x38, 0xe7, 0x91, 0x85, 0xc9, 0x21, 0x6a, 0x1c, - 0xc4, 0xa3, 0x0e, 0xd8, 0xfe, 0xb1, 0x25, 0x1a + 0xb9, + 0xdb, + 0x61, + 0xf8, + 0x8b, + 0x3a, + 0xef, + 0x26, + 0x69, + 0xf2, + 0x57, + 0xc6, + 0x84, + 0x25, + 0x6b, + 0x77, + 0xbe, + 0x8c, + 0x43, + 0x32, + 0xf3, + 0x9a, + 0xd1, + 0x85, + 0x14, + 0xbc, + 0x89, + 0x3b, + 0x9c, + 0xf3, + 0xfc, + 0x00, + 0xa1, + 0x3a, + 0xc3, + 0xc4, + 0x1e, + 0xdf, + 0xd0, + 0x11, + 0x70, + 0xd9, + 0x02, + 0x7a, + 0xd4, + 0xef, + 0x86, + 0x67, + 0xb1, + 0x1e, + 0x5d, + 0xe3, + 0x7f, + 0x82, + 0x14, + 0x52, + 0xa5, + 0x8a, + 0x89, + 0xa7, + 0x98, + 0x75, + 0x2f, + 0x8a, + 0x00, + 0xf3, + 0xbd, + 0x49, + 0x26, + 0x4d, + 0x0c, + 0xc7, + 0x38, + 0xe7, + 0x91, + 0x85, + 0xc9, + 0x21, + 0x6a, + 0x1c, + 0xc4, + 0xa3, + 0x0e, + 0xd8, + 0xfe, + 0xb1, + 0x25, + 0x1a, }; static const QUIC_PKT_HDR rx_script_6a_expect_hdr = { @@ -915,49 +4386,434 @@ static const QUIC_PKT_HDR rx_script_6a_expect_hdr = { }; static const unsigned char rx_script_6a_body[] = { - 0x02, 0x03, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x06, 0x00, 0x40, 0x5a, 0x02, 0x00, - 0x00, 0x56, 0x03, 0x03, 0xc3, 0x45, 0xe8, 0xb8, 0xf9, 0x7c, - 0x9f, 0x5d, 0xcf, 0x66, 0x25, 0xe4, 0x91, 0x0e, 0xb0, 0x5a, - 0x14, 0xce, 0xaf, 0xea, 0x83, 0x12, 0xde, 0x68, 0xd9, 0x31, - 0xf2, 0x23, 0x11, 0x3a, 0x15, 0xcb, 0x00, 0x13, 0x02, 0x00, - 0x00, 0x2e, 0x00, 0x2b, 0x00, 0x02, 0x03, 0x04, 0x00, 0x33, - 0x00, 0x24, 0x00, 0x1d, 0x00, 0x20, 0xab, 0xd3, 0xc6, 0x9f, - 0x36, 0xd3, 0x52, 0x93, 0x87, 0xee, 0x92, 0x01, 0xa2, 0xd6, - 0x9a, 0x5e, 0x61, 0x43, 0xcc, 0x4a, 0xcc, 0x7a, 0xcd, 0x83, - 0xb2, 0xd9, 0xad, 0xd1, 0x14, 0xdc, 0x84, 0x61 + 0x02, + 0x03, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x06, + 0x00, + 0x40, + 0x5a, + 0x02, + 0x00, + 0x00, + 0x56, + 0x03, + 0x03, + 0xc3, + 0x45, + 0xe8, + 0xb8, + 0xf9, + 0x7c, + 0x9f, + 0x5d, + 0xcf, + 0x66, + 0x25, + 0xe4, + 0x91, + 0x0e, + 0xb0, + 0x5a, + 0x14, + 0xce, + 0xaf, + 0xea, + 0x83, + 0x12, + 0xde, + 0x68, + 0xd9, + 0x31, + 0xf2, + 0x23, + 0x11, + 0x3a, + 0x15, + 0xcb, + 0x00, + 0x13, + 0x02, + 0x00, + 0x00, + 0x2e, + 0x00, + 0x2b, + 0x00, + 0x02, + 0x03, + 0x04, + 0x00, + 0x33, + 0x00, + 0x24, + 0x00, + 0x1d, + 0x00, + 0x20, + 0xab, + 0xd3, + 0xc6, + 0x9f, + 0x36, + 0xd3, + 0x52, + 0x93, + 0x87, + 0xee, + 0x92, + 0x01, + 0xa2, + 0xd6, + 0x9a, + 0x5e, + 0x61, + 0x43, + 0xcc, + 0x4a, + 0xcc, + 0x7a, + 0xcd, + 0x83, + 0xb2, + 0xd9, + 0xad, + 0xd1, + 0x14, + 0xdc, + 0x84, + 0x61, }; static const QUIC_PKT_HDR rx_script_6b_expect_hdr = { @@ -978,73 +4834,676 @@ static const QUIC_PKT_HDR rx_script_6b_expect_hdr = { }; static const unsigned char rx_script_6b_body[] = { - 0x06, 0x00, 0x42, 0x9a, 0x08, 0x00, 0x00, 0x80, 0x00, 0x7e, - 0x00, 0x10, 0x00, 0x08, 0x00, 0x06, 0x05, 0x64, 0x75, 0x6d, - 0x6d, 0x79, 0x00, 0x39, 0x00, 0x6e, 0x47, 0xfa, 0x05, 0x5a, - 0xe0, 0xec, 0x4a, 0xf3, 0x05, 0x04, 0x80, 0x08, 0x00, 0x00, - 0x06, 0x04, 0x80, 0x08, 0x00, 0x00, 0x07, 0x04, 0x80, 0x08, - 0x00, 0x00, 0x04, 0x04, 0x80, 0x0c, 0x00, 0x00, 0x08, 0x02, - 0x40, 0x64, 0x09, 0x02, 0x40, 0x64, 0x01, 0x04, 0x80, 0x00, - 0x75, 0x30, 0x03, 0x02, 0x45, 0xac, 0x0b, 0x01, 0x1a, 0x0c, - 0x00, 0x02, 0x10, 0x35, 0xd7, 0x7d, 0x8b, 0xc5, 0xb1, 0x89, - 0xb1, 0x5c, 0x23, 0x74, 0x50, 0xfd, 0x47, 0xfe, 0xd2, 0x00, - 0x11, 0x96, 0x38, 0x27, 0xde, 0x7d, 0xfb, 0x2b, 0x38, 0x56, - 0xe5, 0x2a, 0xb8, 0x6b, 0xfa, 0xaa, 0xde, 0x81, 0x0e, 0x01, - 0x04, 0x0f, 0x04, 0x36, 0xf4, 0x75, 0x2d, 0x10, 0x04, 0xac, - 0x88, 0x95, 0xbd, 0x20, 0x01, 0x00, 0x0b, 0x00, 0x01, 0x8f, - 0x00, 0x00, 0x01, 0x8b, 0x00, 0x01, 0x86, 0x30, 0x82, 0x01, - 0x82, 0x30, 0x82, 0x01, 0x29, 0xa0, 0x03, 0x02, 0x01, 0x02, - 0x02, 0x14, 0x0a, 0x73, 0x0f, 0x86, 0x18, 0xf2, 0xc3, 0x30, - 0x01, 0xd2, 0xc0, 0xc1, 0x62, 0x52, 0x13, 0xf1, 0x9c, 0x13, - 0x39, 0xb5, 0x30, 0x0a, 0x06, 0x08, 0x2a, 0x86, 0x48, 0xce, - 0x3d, 0x04, 0x03, 0x02, 0x30, 0x17, 0x31, 0x15, 0x30, 0x13, - 0x06, 0x03, 0x55, 0x04, 0x03, 0x0c, 0x0c, 0x6d, 0x61, 0x70, - 0x61, 0x6b, 0x74, 0x2e, 0x6c, 0x6f, 0x63, 0x61, 0x6c, 0x30, - 0x1e, 0x17, 0x0d, 0x32, 0x32, 0x30, 0x38, 0x30, 0x32, 0x31, - 0x32, 0x30, 0x30, 0x31, 0x38, 0x5a, 0x17, 0x0d, 0x32, 0x32, - 0x30, 0x39, 0x30, 0x31, 0x31, 0x32, 0x30, 0x30, 0x31, 0x38, - 0x5a, 0x30, 0x17, 0x31, 0x15, 0x30, 0x13, 0x06, 0x03, 0x55, - 0x04, 0x03, 0x0c, 0x0c, 0x6d, 0x61, 0x70, 0x61, 0x6b, 0x74, - 0x2e, 0x6c, 0x6f, 0x63, 0x61, 0x6c, 0x30, 0x59, 0x30, 0x13, - 0x06, 0x07, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x02, 0x01, 0x06, - 0x08, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x03, 0x01, 0x07, 0x03, - 0x42, 0x00, 0x04, 0x67, 0xf4, 0xd3, 0x8f, 0x15, 0x6d, 0xee, - 0x85, 0xcc, 0x2a, 0x77, 0xfc, 0x0b, 0x8f, 0x9f, 0xcf, 0xa9, - 0x95, 0x5d, 0x5b, 0xcd, 0xb7, 0x8b, 0xba, 0x31, 0x0a, 0x73, - 0x62, 0xc5, 0xd0, 0x0e, 0x07, 0x90, 0xae, 0x38, 0x43, 0x79, - 0xce, 0x5e, 0x33, 0xad, 0x31, 0xbf, 0x9f, 0x2a, 0x56, 0x83, - 0xa5, 0x24, 0x16, 0xab, 0x0c, 0xf1, 0x64, 0xbe, 0xe4, 0x93, - 0xb5, 0x89, 0xd6, 0x05, 0xe4, 0xf7, 0x7b, 0xa3, 0x53, 0x30, - 0x51, 0x30, 0x1d, 0x06, 0x03, 0x55, 0x1d, 0x0e, 0x04, 0x16, - 0x04, 0x14, 0x02, 0x64, 0x0f, 0x55, 0x69, 0x14, 0x91, 0x19, - 0xed, 0xf9, 0x1a, 0xe9, 0x1d, 0xa5, 0x5a, 0xd0, 0x48, 0x96, - 0x9f, 0x60, 0x30, 0x1f, 0x06, 0x03, 0x55, 0x1d, 0x23, 0x04, - 0x18, 0x30, 0x16, 0x80, 0x14, 0x02, 0x64, 0x0f, 0x55, 0x69, - 0x14, 0x91, 0x19, 0xed, 0xf9, 0x1a, 0xe9, 0x1d, 0xa5, 0x5a, - 0xd0, 0x48, 0x96, 0x9f, 0x60, 0x30, 0x0f, 0x06, 0x03, 0x55, - 0x1d, 0x13, 0x01, 0x01, 0xff, 0x04, 0x05, 0x30, 0x03, 0x01, - 0x01, 0xff, 0x30, 0x0a, 0x06, 0x08, 0x2a, 0x86, 0x48, 0xce, - 0x3d, 0x04, 0x03, 0x02, 0x03, 0x47, 0x00, 0x30, 0x44, 0x02, - 0x20, 0x0a, 0x82, 0x92, 0x6e, 0xd3, 0xc6, 0x66, 0xd9, 0xd3, - 0x75, 0xff, 0x71, 0x3b, 0x61, 0x46, 0x21, 0x00, 0xe6, 0x21, - 0x5d, 0x9c, 0x86, 0xe9, 0x65, 0x40, 0x4f, 0xeb, 0x70, 0x4f, - 0x2c, 0xad, 0x00, 0x02, 0x20, 0x08, 0xc2, 0x07, 0x5d, 0x16, - 0xfc, 0x54, 0x34, 0x2b, 0xb4, 0x18, 0x67, 0x44, 0x81, 0xc9, - 0xa9, 0x67, 0x2e, 0xce, 0xa1, 0x02, 0x9f, 0x3b, 0xe5, 0x61, - 0x16, 0x0b, 0x50, 0xf6, 0xa1, 0x50, 0x94, 0x00, 0x00, 0x0f, - 0x00, 0x00, 0x4b, 0x04, 0x03, 0x00, 0x47, 0x30, 0x45, 0x02, - 0x20, 0x78, 0x9e, 0xe0, 0x6a, 0x7a, 0xbd, 0xc3, 0x84, 0x3d, - 0x25, 0x6a, 0x59, 0x23, 0x97, 0x52, 0x64, 0x4e, 0xb6, 0x9f, - 0xcc, 0xd3, 0xd7, 0xa9, 0x29, 0x44, 0x75, 0x6d, 0x50, 0xfc, - 0x22, 0xde, 0xd3, 0x02, 0x21, 0x00, 0xe5, 0x28, 0xd6, 0x5a, - 0xd1, 0xec, 0x4a, 0xcc, 0x20, 0xb4, 0xea, 0x15, 0xfb, 0x8e, - 0x73, 0xa8, 0x6b, 0xbb, 0x42, 0x70, 0x90, 0x08, 0x6e, 0x74, - 0x6f, 0x5a, 0x05, 0xb5, 0x39, 0xee, 0x01, 0x04, 0x14, 0x00, - 0x00, 0x30, 0xff, 0x9f, 0xb2, 0x1d, 0xcb, 0x4f, 0xfc, 0x7a, - 0xac, 0xf4, 0x75, 0x24, 0x83, 0x5f, 0x8d, 0xa3, 0x3e, 0x9d, - 0xef, 0x43, 0x67, 0x89, 0x5d, 0x55, 0xc7, 0xce, 0x80, 0xab, - 0xc3, 0xc7, 0x74, 0xc7, 0xb2, 0x91, 0x27, 0xce, 0xd8, 0x5e, - 0xc4, 0x4e, 0x96, 0x19, 0x68, 0x2d, 0xbe, 0x6f, 0x49, 0xfa + 0x06, + 0x00, + 0x42, + 0x9a, + 0x08, + 0x00, + 0x00, + 0x80, + 0x00, + 0x7e, + 0x00, + 0x10, + 0x00, + 0x08, + 0x00, + 0x06, + 0x05, + 0x64, + 0x75, + 0x6d, + 0x6d, + 0x79, + 0x00, + 0x39, + 0x00, + 0x6e, + 0x47, + 0xfa, + 0x05, + 0x5a, + 0xe0, + 0xec, + 0x4a, + 0xf3, + 0x05, + 0x04, + 0x80, + 0x08, + 0x00, + 0x00, + 0x06, + 0x04, + 0x80, + 0x08, + 0x00, + 0x00, + 0x07, + 0x04, + 0x80, + 0x08, + 0x00, + 0x00, + 0x04, + 0x04, + 0x80, + 0x0c, + 0x00, + 0x00, + 0x08, + 0x02, + 0x40, + 0x64, + 0x09, + 0x02, + 0x40, + 0x64, + 0x01, + 0x04, + 0x80, + 0x00, + 0x75, + 0x30, + 0x03, + 0x02, + 0x45, + 0xac, + 0x0b, + 0x01, + 0x1a, + 0x0c, + 0x00, + 0x02, + 0x10, + 0x35, + 0xd7, + 0x7d, + 0x8b, + 0xc5, + 0xb1, + 0x89, + 0xb1, + 0x5c, + 0x23, + 0x74, + 0x50, + 0xfd, + 0x47, + 0xfe, + 0xd2, + 0x00, + 0x11, + 0x96, + 0x38, + 0x27, + 0xde, + 0x7d, + 0xfb, + 0x2b, + 0x38, + 0x56, + 0xe5, + 0x2a, + 0xb8, + 0x6b, + 0xfa, + 0xaa, + 0xde, + 0x81, + 0x0e, + 0x01, + 0x04, + 0x0f, + 0x04, + 0x36, + 0xf4, + 0x75, + 0x2d, + 0x10, + 0x04, + 0xac, + 0x88, + 0x95, + 0xbd, + 0x20, + 0x01, + 0x00, + 0x0b, + 0x00, + 0x01, + 0x8f, + 0x00, + 0x00, + 0x01, + 0x8b, + 0x00, + 0x01, + 0x86, + 0x30, + 0x82, + 0x01, + 0x82, + 0x30, + 0x82, + 0x01, + 0x29, + 0xa0, + 0x03, + 0x02, + 0x01, + 0x02, + 0x02, + 0x14, + 0x0a, + 0x73, + 0x0f, + 0x86, + 0x18, + 0xf2, + 0xc3, + 0x30, + 0x01, + 0xd2, + 0xc0, + 0xc1, + 0x62, + 0x52, + 0x13, + 0xf1, + 0x9c, + 0x13, + 0x39, + 0xb5, + 0x30, + 0x0a, + 0x06, + 0x08, + 0x2a, + 0x86, + 0x48, + 0xce, + 0x3d, + 0x04, + 0x03, + 0x02, + 0x30, + 0x17, + 0x31, + 0x15, + 0x30, + 0x13, + 0x06, + 0x03, + 0x55, + 0x04, + 0x03, + 0x0c, + 0x0c, + 0x6d, + 0x61, + 0x70, + 0x61, + 0x6b, + 0x74, + 0x2e, + 0x6c, + 0x6f, + 0x63, + 0x61, + 0x6c, + 0x30, + 0x1e, + 0x17, + 0x0d, + 0x32, + 0x32, + 0x30, + 0x38, + 0x30, + 0x32, + 0x31, + 0x32, + 0x30, + 0x30, + 0x31, + 0x38, + 0x5a, + 0x17, + 0x0d, + 0x32, + 0x32, + 0x30, + 0x39, + 0x30, + 0x31, + 0x31, + 0x32, + 0x30, + 0x30, + 0x31, + 0x38, + 0x5a, + 0x30, + 0x17, + 0x31, + 0x15, + 0x30, + 0x13, + 0x06, + 0x03, + 0x55, + 0x04, + 0x03, + 0x0c, + 0x0c, + 0x6d, + 0x61, + 0x70, + 0x61, + 0x6b, + 0x74, + 0x2e, + 0x6c, + 0x6f, + 0x63, + 0x61, + 0x6c, + 0x30, + 0x59, + 0x30, + 0x13, + 0x06, + 0x07, + 0x2a, + 0x86, + 0x48, + 0xce, + 0x3d, + 0x02, + 0x01, + 0x06, + 0x08, + 0x2a, + 0x86, + 0x48, + 0xce, + 0x3d, + 0x03, + 0x01, + 0x07, + 0x03, + 0x42, + 0x00, + 0x04, + 0x67, + 0xf4, + 0xd3, + 0x8f, + 0x15, + 0x6d, + 0xee, + 0x85, + 0xcc, + 0x2a, + 0x77, + 0xfc, + 0x0b, + 0x8f, + 0x9f, + 0xcf, + 0xa9, + 0x95, + 0x5d, + 0x5b, + 0xcd, + 0xb7, + 0x8b, + 0xba, + 0x31, + 0x0a, + 0x73, + 0x62, + 0xc5, + 0xd0, + 0x0e, + 0x07, + 0x90, + 0xae, + 0x38, + 0x43, + 0x79, + 0xce, + 0x5e, + 0x33, + 0xad, + 0x31, + 0xbf, + 0x9f, + 0x2a, + 0x56, + 0x83, + 0xa5, + 0x24, + 0x16, + 0xab, + 0x0c, + 0xf1, + 0x64, + 0xbe, + 0xe4, + 0x93, + 0xb5, + 0x89, + 0xd6, + 0x05, + 0xe4, + 0xf7, + 0x7b, + 0xa3, + 0x53, + 0x30, + 0x51, + 0x30, + 0x1d, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x0e, + 0x04, + 0x16, + 0x04, + 0x14, + 0x02, + 0x64, + 0x0f, + 0x55, + 0x69, + 0x14, + 0x91, + 0x19, + 0xed, + 0xf9, + 0x1a, + 0xe9, + 0x1d, + 0xa5, + 0x5a, + 0xd0, + 0x48, + 0x96, + 0x9f, + 0x60, + 0x30, + 0x1f, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x23, + 0x04, + 0x18, + 0x30, + 0x16, + 0x80, + 0x14, + 0x02, + 0x64, + 0x0f, + 0x55, + 0x69, + 0x14, + 0x91, + 0x19, + 0xed, + 0xf9, + 0x1a, + 0xe9, + 0x1d, + 0xa5, + 0x5a, + 0xd0, + 0x48, + 0x96, + 0x9f, + 0x60, + 0x30, + 0x0f, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x13, + 0x01, + 0x01, + 0xff, + 0x04, + 0x05, + 0x30, + 0x03, + 0x01, + 0x01, + 0xff, + 0x30, + 0x0a, + 0x06, + 0x08, + 0x2a, + 0x86, + 0x48, + 0xce, + 0x3d, + 0x04, + 0x03, + 0x02, + 0x03, + 0x47, + 0x00, + 0x30, + 0x44, + 0x02, + 0x20, + 0x0a, + 0x82, + 0x92, + 0x6e, + 0xd3, + 0xc6, + 0x66, + 0xd9, + 0xd3, + 0x75, + 0xff, + 0x71, + 0x3b, + 0x61, + 0x46, + 0x21, + 0x00, + 0xe6, + 0x21, + 0x5d, + 0x9c, + 0x86, + 0xe9, + 0x65, + 0x40, + 0x4f, + 0xeb, + 0x70, + 0x4f, + 0x2c, + 0xad, + 0x00, + 0x02, + 0x20, + 0x08, + 0xc2, + 0x07, + 0x5d, + 0x16, + 0xfc, + 0x54, + 0x34, + 0x2b, + 0xb4, + 0x18, + 0x67, + 0x44, + 0x81, + 0xc9, + 0xa9, + 0x67, + 0x2e, + 0xce, + 0xa1, + 0x02, + 0x9f, + 0x3b, + 0xe5, + 0x61, + 0x16, + 0x0b, + 0x50, + 0xf6, + 0xa1, + 0x50, + 0x94, + 0x00, + 0x00, + 0x0f, + 0x00, + 0x00, + 0x4b, + 0x04, + 0x03, + 0x00, + 0x47, + 0x30, + 0x45, + 0x02, + 0x20, + 0x78, + 0x9e, + 0xe0, + 0x6a, + 0x7a, + 0xbd, + 0xc3, + 0x84, + 0x3d, + 0x25, + 0x6a, + 0x59, + 0x23, + 0x97, + 0x52, + 0x64, + 0x4e, + 0xb6, + 0x9f, + 0xcc, + 0xd3, + 0xd7, + 0xa9, + 0x29, + 0x44, + 0x75, + 0x6d, + 0x50, + 0xfc, + 0x22, + 0xde, + 0xd3, + 0x02, + 0x21, + 0x00, + 0xe5, + 0x28, + 0xd6, + 0x5a, + 0xd1, + 0xec, + 0x4a, + 0xcc, + 0x20, + 0xb4, + 0xea, + 0x15, + 0xfb, + 0x8e, + 0x73, + 0xa8, + 0x6b, + 0xbb, + 0x42, + 0x70, + 0x90, + 0x08, + 0x6e, + 0x74, + 0x6f, + 0x5a, + 0x05, + 0xb5, + 0x39, + 0xee, + 0x01, + 0x04, + 0x14, + 0x00, + 0x00, + 0x30, + 0xff, + 0x9f, + 0xb2, + 0x1d, + 0xcb, + 0x4f, + 0xfc, + 0x7a, + 0xac, + 0xf4, + 0x75, + 0x24, + 0x83, + 0x5f, + 0x8d, + 0xa3, + 0x3e, + 0x9d, + 0xef, + 0x43, + 0x67, + 0x89, + 0x5d, + 0x55, + 0xc7, + 0xce, + 0x80, + 0xab, + 0xc3, + 0xc7, + 0x74, + 0xc7, + 0xb2, + 0x91, + 0x27, + 0xce, + 0xd8, + 0x5e, + 0xc4, + 0x4e, + 0x96, + 0x19, + 0x68, + 0x2d, + 0xbe, + 0x6f, + 0x49, + 0xfa, }; static const QUIC_PKT_HDR rx_script_6c_expect_hdr = { @@ -1065,67 +5524,135 @@ static const QUIC_PKT_HDR rx_script_6c_expect_hdr = { }; static const unsigned char rx_script_6c_body[] = { - 0x18, 0x03, 0x00, 0x04, 0xf2, 0x94, 0x49, 0xc3, 0x34, 0xa1, - 0xf4, 0x0f, 0xcb, 0xb8, 0x03, 0x04, 0x1f, 0xc8, 0x69, 0xb9, - 0x3b, 0xd5, 0xc6, 0x93, 0x18, 0x02, 0x00, 0x04, 0x9a, 0x4f, - 0xec, 0x52, 0xde, 0xd2, 0xc8, 0xb7, 0x1c, 0x0c, 0xf3, 0x4e, - 0x46, 0xf0, 0x6c, 0x54, 0x34, 0x1b, 0x0d, 0x98, 0x18, 0x01, - 0x00, 0x04, 0xe3, 0x33, 0x9e, 0x59, 0x00, 0x69, 0xc3, 0xac, - 0xfc, 0x58, 0x0e, 0xa4, 0xf4, 0xf3, 0x23, 0x1b, 0xd6, 0x8e, - 0x5b, 0x08 + 0x18, + 0x03, + 0x00, + 0x04, + 0xf2, + 0x94, + 0x49, + 0xc3, + 0x34, + 0xa1, + 0xf4, + 0x0f, + 0xcb, + 0xb8, + 0x03, + 0x04, + 0x1f, + 0xc8, + 0x69, + 0xb9, + 0x3b, + 0xd5, + 0xc6, + 0x93, + 0x18, + 0x02, + 0x00, + 0x04, + 0x9a, + 0x4f, + 0xec, + 0x52, + 0xde, + 0xd2, + 0xc8, + 0xb7, + 0x1c, + 0x0c, + 0xf3, + 0x4e, + 0x46, + 0xf0, + 0x6c, + 0x54, + 0x34, + 0x1b, + 0x0d, + 0x98, + 0x18, + 0x01, + 0x00, + 0x04, + 0xe3, + 0x33, + 0x9e, + 0x59, + 0x00, + 0x69, + 0xc3, + 0xac, + 0xfc, + 0x58, + 0x0e, + 0xa4, + 0xf4, + 0xf3, + 0x23, + 0x1b, + 0xd6, + 0x8e, + 0x5b, + 0x08, }; static const struct rx_test_op rx_script_6[] = { - RX_OP_ALLOW_1RTT(), - RX_OP_SET_RX_DCID(empty_conn_id), - RX_OP_PROVIDE_SECRET_INITIAL(rx_script_6_c2s_init_dcid), - RX_OP_INJECT_N(6), - RX_OP_CHECK_PKT_N(6a), - RX_OP_CHECK_NO_PKT(), /* not got secret for next packet yet */ - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, QRL_SUITE_AES256GCM, rx_script_6_handshake_secret), - RX_OP_CHECK_PKT_N(6b), - RX_OP_CHECK_NO_PKT(), /* not got secret for next packet yet */ - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES256GCM, rx_script_6_1rtt_secret), - RX_OP_CHECK_PKT_N(6c), - RX_OP_CHECK_NO_PKT(), + RX_OP_ALLOW_1RTT() + RX_OP_SET_RX_DCID(empty_conn_id) + RX_OP_PROVIDE_SECRET_INITIAL(rx_script_6_c2s_init_dcid) + RX_OP_INJECT_N(6) + RX_OP_CHECK_PKT_N(6a) + RX_OP_CHECK_NO_PKT() /* not got secret for next packet yet */ + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, + QRL_SUITE_AES256GCM, rx_script_6_handshake_secret) + RX_OP_CHECK_PKT_N(6b) + RX_OP_CHECK_NO_PKT() /* not got secret for next packet yet */ + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, + QRL_SUITE_AES256GCM, rx_script_6_1rtt_secret) + RX_OP_CHECK_PKT_N(6c) + RX_OP_CHECK_NO_PKT() /* Discard Initial EL and try injecting the packet again */ - RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_INITIAL), - RX_OP_INJECT_N(6), + RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_INITIAL) + RX_OP_INJECT_N(6) /* Initial packet is not output because we have discarded Initial keys */ - RX_OP_CHECK_PKT_N(6b), - RX_OP_CHECK_PKT_N(6c), - RX_OP_CHECK_NO_PKT(), + RX_OP_CHECK_PKT_N(6b) + RX_OP_CHECK_PKT_N(6c) + RX_OP_CHECK_NO_PKT() /* Try again with discarded keys */ - RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_HANDSHAKE), - RX_OP_INJECT_N(6), - RX_OP_CHECK_PKT_N(6c), - RX_OP_CHECK_NO_PKT(), + RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_HANDSHAKE) + RX_OP_INJECT_N(6) + RX_OP_CHECK_PKT_N(6c) + RX_OP_CHECK_NO_PKT() /* Try again */ - RX_OP_INJECT_N(6), - RX_OP_CHECK_PKT_N(6c), - RX_OP_CHECK_NO_PKT(), + RX_OP_INJECT_N(6) + RX_OP_CHECK_PKT_N(6c) + RX_OP_CHECK_NO_PKT() /* Try again with discarded 1-RTT keys */ - RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_1RTT), - RX_OP_INJECT_N(6), - RX_OP_CHECK_NO_PKT(), + RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_1RTT) + RX_OP_INJECT_N(6) + RX_OP_CHECK_NO_PKT() /* Recreate QRL, test reading packets received before key */ - RX_OP_SET_SCID_LEN(0), - RX_OP_SET_RX_DCID(empty_conn_id), - RX_OP_INJECT_N(6), - RX_OP_CHECK_NO_PKT(), - RX_OP_PROVIDE_SECRET_INITIAL(rx_script_6_c2s_init_dcid), - RX_OP_CHECK_PKT_N(6a), - RX_OP_CHECK_NO_PKT(), - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, QRL_SUITE_AES256GCM, rx_script_6_handshake_secret), - RX_OP_CHECK_PKT_N(6b), - RX_OP_CHECK_NO_PKT(), - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES256GCM, rx_script_6_1rtt_secret), - RX_OP_CHECK_PKT_N(6c), - RX_OP_CHECK_NO_PKT(), + RX_OP_SET_SCID_LEN(0) + RX_OP_SET_RX_DCID(empty_conn_id) + RX_OP_INJECT_N(6) + RX_OP_CHECK_NO_PKT() + RX_OP_PROVIDE_SECRET_INITIAL(rx_script_6_c2s_init_dcid) + RX_OP_CHECK_PKT_N(6a) + RX_OP_CHECK_NO_PKT() + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, + QRL_SUITE_AES256GCM, rx_script_6_handshake_secret) + RX_OP_CHECK_PKT_N(6b) + RX_OP_CHECK_NO_PKT() + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, + QRL_SUITE_AES256GCM, rx_script_6_1rtt_secret) + RX_OP_CHECK_PKT_N(6c) + RX_OP_CHECK_NO_PKT() - RX_OP_END + RX_OP_END }; /* @@ -1138,17 +5665,73 @@ static const QUIC_CONN_ID rx_script_7_c2s_init_dcid = { }; static const unsigned char rx_script_7_handshake_secret[32] = { - 0x85, 0x44, 0xa4, 0x02, 0x46, 0x5b, 0x2a, 0x92, 0x80, 0x71, - 0xfd, 0x11, 0x89, 0x73, 0x84, 0xeb, 0x3e, 0x0d, 0x89, 0x4f, - 0x71, 0xdc, 0x9c, 0xdd, 0x55, 0x77, 0x9e, 0x79, 0x7b, 0xeb, - 0xfa, 0x86 + 0x85, + 0x44, + 0xa4, + 0x02, + 0x46, + 0x5b, + 0x2a, + 0x92, + 0x80, + 0x71, + 0xfd, + 0x11, + 0x89, + 0x73, + 0x84, + 0xeb, + 0x3e, + 0x0d, + 0x89, + 0x4f, + 0x71, + 0xdc, + 0x9c, + 0xdd, + 0x55, + 0x77, + 0x9e, + 0x79, + 0x7b, + 0xeb, + 0xfa, + 0x86, }; static const unsigned char rx_script_7_1rtt_secret[32] = { - 0x4a, 0x77, 0xb6, 0x0e, 0xfd, 0x90, 0xca, 0xbf, 0xc0, 0x1a, - 0x64, 0x9f, 0xc0, 0x03, 0xd3, 0x8d, 0xc5, 0x41, 0x04, 0x50, - 0xb1, 0x5b, 0x74, 0xe7, 0xe3, 0x99, 0x0c, 0xdf, 0x74, 0x61, - 0x35, 0xe6 + 0x4a, + 0x77, + 0xb6, + 0x0e, + 0xfd, + 0x90, + 0xca, + 0xbf, + 0xc0, + 0x1a, + 0x64, + 0x9f, + 0xc0, + 0x03, + 0xd3, + 0x8d, + 0xc5, + 0x41, + 0x04, + 0x50, + 0xb1, + 0x5b, + 0x74, + 0xe7, + 0xe3, + 0x99, + 0x0c, + 0xdf, + 0x74, + 0x61, + 0x35, + 0xe6, }; static const unsigned char rx_script_7_in[] = { @@ -1169,52 +5752,463 @@ static const unsigned char rx_script_7_in[] = { 0xcb, /* Length (459) */ 0x3c, 0xe0, /* PN (0) */ - 0x85, 0x05, 0xc2, 0x4d, 0x0f, 0xf3, 0x62, 0x51, 0x04, 0x33, - 0xfa, 0xb5, 0xa3, 0x02, 0xbd, 0x5c, 0x22, 0x0c, 0x1d, 0xda, - 0x06, 0xf1, 0xd7, 0xe0, 0xc8, 0x56, 0xb0, 0x3d, 0xc1, 0x49, - 0x8c, 0xc2, 0x88, 0x5a, 0x0e, 0xd5, 0x67, 0x72, 0xec, 0xcc, - 0x7a, 0x2b, 0x46, 0x17, 0x49, 0x4b, 0x28, 0x6a, 0x89, 0x71, - 0xfd, 0x31, 0x9a, 0xa1, 0x97, 0x64, 0xe2, 0xbf, 0xa0, 0x6d, - 0xf6, 0x76, 0x83, 0x28, 0xc4, 0xd5, 0x39, 0x87, 0x22, 0x7c, - 0x11, 0x9a, 0x53, 0x66, 0xb4, 0x27, 0xf1, 0xab, 0x6f, 0x49, - 0x43, 0x3f, 0x9a, 0x23, 0xd3, 0x53, 0x06, 0xe8, 0x14, 0xfd, - 0xc0, 0x67, 0x1f, 0x88, 0x2a, 0xa8, 0xae, 0x5f, 0x05, 0x0a, - 0xeb, 0x66, 0x72, 0x8c, 0x46, 0xcc, 0x54, 0x21, 0x5e, 0x14, - 0xfe, 0x68, 0xc7, 0xf7, 0x60, 0x67, 0xb5, 0xa7, 0x0d, 0xf4, - 0xe1, 0xff, 0x60, 0xe3, 0x11, 0x38, 0x92, 0x90, 0xc2, 0x48, - 0x28, 0xbf, 0xf3, 0x85, 0x27, 0xfe, 0xbf, 0x42, 0x26, 0x1a, - 0x4e, 0x78, 0xf1, 0xf0, 0x88, 0x16, 0x1b, 0x64, 0x5f, 0x66, - 0x02, 0x0b, 0x45, 0x3d, 0x38, 0xd9, 0x09, 0xd5, 0xff, 0xc2, - 0x68, 0x02, 0x2c, 0xc4, 0x3f, 0x60, 0x6e, 0x2f, 0x7f, 0x43, - 0xf7, 0x1a, 0x37, 0xcc, 0xe0, 0xe0, 0x4b, 0x96, 0xc1, 0xb1, - 0x8b, 0x1c, 0x7c, 0x6e, 0x80, 0xe3, 0x92, 0x9b, 0x86, 0x87, - 0x1f, 0x9a, 0x6a, 0x62, 0x18, 0xf4, 0x86, 0xc2, 0x3e, 0x33, - 0xa3, 0xbf, 0x43, 0x96, 0x6e, 0xff, 0x94, 0xaf, 0x6d, 0x23, - 0x5c, 0x42, 0xed, 0xe7, 0xb9, 0x2c, 0x33, 0xb0, 0xc6, 0x3d, - 0x44, 0x00, 0x0b, 0xa3, 0x39, 0xa8, 0xeb, 0x8c, 0x81, 0x1a, - 0x99, 0x20, 0xbd, 0xfa, 0xf3, 0xf4, 0xf0, 0x11, 0xd8, 0x41, - 0x31, 0x8d, 0xdc, 0x0d, 0x00, 0xa6, 0x31, 0x40, 0xc6, 0xc6, - 0xad, 0x74, 0x93, 0x62, 0x1c, 0x55, 0xce, 0x5f, 0x8c, 0x5b, - 0x3c, 0xcb, 0x25, 0x5e, 0xbf, 0xed, 0xbb, 0x3c, 0x97, 0x4b, - 0x62, 0xe0, 0xba, 0xf1, 0xb0, 0x30, 0xbf, 0x35, 0x89, 0x7e, - 0x25, 0x61, 0x54, 0x86, 0x52, 0x11, 0x86, 0x90, 0xc3, 0xf5, - 0xad, 0xa0, 0x96, 0x30, 0xb2, 0xf0, 0xa6, 0x79, 0x39, 0x1c, - 0x51, 0x42, 0xa1, 0x00, 0x6f, 0x55, 0x7d, 0xdc, 0xd0, 0x7c, - 0xcf, 0x01, 0x88, 0x03, 0xd7, 0x2d, 0x65, 0x2b, 0x40, 0xee, - 0xba, 0x10, 0xd8, 0x0c, 0x85, 0x14, 0xb7, 0x4d, 0x9e, 0x7d, - 0x7c, 0xde, 0x7f, 0x0d, 0x0e, 0x3b, 0x3d, 0xe3, 0xd3, 0x63, - 0xc2, 0xed, 0xc7, 0x41, 0xaf, 0x05, 0x85, 0x87, 0x46, 0x55, - 0x7e, 0xbe, 0x14, 0x5b, 0x98, 0xae, 0x6e, 0x67, 0x1a, 0x65, - 0xc6, 0xcf, 0xe1, 0x28, 0x50, 0x6b, 0xb4, 0xf6, 0xba, 0x63, - 0xbc, 0xf1, 0xd7, 0xa4, 0x97, 0x2d, 0x4d, 0x04, 0x26, 0x96, - 0xec, 0x0c, 0xd4, 0xae, 0x6a, 0xca, 0x7e, 0x65, 0xc5, 0x43, - 0x7e, 0xf8, 0x77, 0x61, 0xd0, 0x2c, 0xe5, 0x37, 0x0a, 0xb3, - 0x7a, 0x8c, 0x2a, 0xa1, 0xdc, 0x29, 0xdb, 0xec, 0xca, 0xdc, - 0xfe, 0xdd, 0x38, 0xd2, 0x13, 0x9f, 0x94, 0x6d, 0x5b, 0x87, - 0xf3, 0x15, 0xa8, 0xe5, 0xe9, 0x65, 0x1d, 0x4f, 0x92, 0x1b, - 0xf4, 0xa6, 0xa4, 0xd6, 0x22, 0xfc, 0x26, 0x1b, 0x35, 0xa4, - 0x1c, 0x88, 0x9f, 0x7d, 0xe0, 0x9a, 0x89, 0x0f, 0x6c, 0xc1, - 0xda, 0x6e, 0x45, 0xce, 0x74, 0xb1, 0xff, + 0x85, + 0x05, + 0xc2, + 0x4d, + 0x0f, + 0xf3, + 0x62, + 0x51, + 0x04, + 0x33, + 0xfa, + 0xb5, + 0xa3, + 0x02, + 0xbd, + 0x5c, + 0x22, + 0x0c, + 0x1d, + 0xda, + 0x06, + 0xf1, + 0xd7, + 0xe0, + 0xc8, + 0x56, + 0xb0, + 0x3d, + 0xc1, + 0x49, + 0x8c, + 0xc2, + 0x88, + 0x5a, + 0x0e, + 0xd5, + 0x67, + 0x72, + 0xec, + 0xcc, + 0x7a, + 0x2b, + 0x46, + 0x17, + 0x49, + 0x4b, + 0x28, + 0x6a, + 0x89, + 0x71, + 0xfd, + 0x31, + 0x9a, + 0xa1, + 0x97, + 0x64, + 0xe2, + 0xbf, + 0xa0, + 0x6d, + 0xf6, + 0x76, + 0x83, + 0x28, + 0xc4, + 0xd5, + 0x39, + 0x87, + 0x22, + 0x7c, + 0x11, + 0x9a, + 0x53, + 0x66, + 0xb4, + 0x27, + 0xf1, + 0xab, + 0x6f, + 0x49, + 0x43, + 0x3f, + 0x9a, + 0x23, + 0xd3, + 0x53, + 0x06, + 0xe8, + 0x14, + 0xfd, + 0xc0, + 0x67, + 0x1f, + 0x88, + 0x2a, + 0xa8, + 0xae, + 0x5f, + 0x05, + 0x0a, + 0xeb, + 0x66, + 0x72, + 0x8c, + 0x46, + 0xcc, + 0x54, + 0x21, + 0x5e, + 0x14, + 0xfe, + 0x68, + 0xc7, + 0xf7, + 0x60, + 0x67, + 0xb5, + 0xa7, + 0x0d, + 0xf4, + 0xe1, + 0xff, + 0x60, + 0xe3, + 0x11, + 0x38, + 0x92, + 0x90, + 0xc2, + 0x48, + 0x28, + 0xbf, + 0xf3, + 0x85, + 0x27, + 0xfe, + 0xbf, + 0x42, + 0x26, + 0x1a, + 0x4e, + 0x78, + 0xf1, + 0xf0, + 0x88, + 0x16, + 0x1b, + 0x64, + 0x5f, + 0x66, + 0x02, + 0x0b, + 0x45, + 0x3d, + 0x38, + 0xd9, + 0x09, + 0xd5, + 0xff, + 0xc2, + 0x68, + 0x02, + 0x2c, + 0xc4, + 0x3f, + 0x60, + 0x6e, + 0x2f, + 0x7f, + 0x43, + 0xf7, + 0x1a, + 0x37, + 0xcc, + 0xe0, + 0xe0, + 0x4b, + 0x96, + 0xc1, + 0xb1, + 0x8b, + 0x1c, + 0x7c, + 0x6e, + 0x80, + 0xe3, + 0x92, + 0x9b, + 0x86, + 0x87, + 0x1f, + 0x9a, + 0x6a, + 0x62, + 0x18, + 0xf4, + 0x86, + 0xc2, + 0x3e, + 0x33, + 0xa3, + 0xbf, + 0x43, + 0x96, + 0x6e, + 0xff, + 0x94, + 0xaf, + 0x6d, + 0x23, + 0x5c, + 0x42, + 0xed, + 0xe7, + 0xb9, + 0x2c, + 0x33, + 0xb0, + 0xc6, + 0x3d, + 0x44, + 0x00, + 0x0b, + 0xa3, + 0x39, + 0xa8, + 0xeb, + 0x8c, + 0x81, + 0x1a, + 0x99, + 0x20, + 0xbd, + 0xfa, + 0xf3, + 0xf4, + 0xf0, + 0x11, + 0xd8, + 0x41, + 0x31, + 0x8d, + 0xdc, + 0x0d, + 0x00, + 0xa6, + 0x31, + 0x40, + 0xc6, + 0xc6, + 0xad, + 0x74, + 0x93, + 0x62, + 0x1c, + 0x55, + 0xce, + 0x5f, + 0x8c, + 0x5b, + 0x3c, + 0xcb, + 0x25, + 0x5e, + 0xbf, + 0xed, + 0xbb, + 0x3c, + 0x97, + 0x4b, + 0x62, + 0xe0, + 0xba, + 0xf1, + 0xb0, + 0x30, + 0xbf, + 0x35, + 0x89, + 0x7e, + 0x25, + 0x61, + 0x54, + 0x86, + 0x52, + 0x11, + 0x86, + 0x90, + 0xc3, + 0xf5, + 0xad, + 0xa0, + 0x96, + 0x30, + 0xb2, + 0xf0, + 0xa6, + 0x79, + 0x39, + 0x1c, + 0x51, + 0x42, + 0xa1, + 0x00, + 0x6f, + 0x55, + 0x7d, + 0xdc, + 0xd0, + 0x7c, + 0xcf, + 0x01, + 0x88, + 0x03, + 0xd7, + 0x2d, + 0x65, + 0x2b, + 0x40, + 0xee, + 0xba, + 0x10, + 0xd8, + 0x0c, + 0x85, + 0x14, + 0xb7, + 0x4d, + 0x9e, + 0x7d, + 0x7c, + 0xde, + 0x7f, + 0x0d, + 0x0e, + 0x3b, + 0x3d, + 0xe3, + 0xd3, + 0x63, + 0xc2, + 0xed, + 0xc7, + 0x41, + 0xaf, + 0x05, + 0x85, + 0x87, + 0x46, + 0x55, + 0x7e, + 0xbe, + 0x14, + 0x5b, + 0x98, + 0xae, + 0x6e, + 0x67, + 0x1a, + 0x65, + 0xc6, + 0xcf, + 0xe1, + 0x28, + 0x50, + 0x6b, + 0xb4, + 0xf6, + 0xba, + 0x63, + 0xbc, + 0xf1, + 0xd7, + 0xa4, + 0x97, + 0x2d, + 0x4d, + 0x04, + 0x26, + 0x96, + 0xec, + 0x0c, + 0xd4, + 0xae, + 0x6a, + 0xca, + 0x7e, + 0x65, + 0xc5, + 0x43, + 0x7e, + 0xf8, + 0x77, + 0x61, + 0xd0, + 0x2c, + 0xe5, + 0x37, + 0x0a, + 0xb3, + 0x7a, + 0x8c, + 0x2a, + 0xa1, + 0xdc, + 0x29, + 0xdb, + 0xec, + 0xca, + 0xdc, + 0xfe, + 0xdd, + 0x38, + 0xd2, + 0x13, + 0x9f, + 0x94, + 0x6d, + 0x5b, + 0x87, + 0xf3, + 0x15, + 0xa8, + 0xe5, + 0xe9, + 0x65, + 0x1d, + 0x4f, + 0x92, + 0x1b, + 0xf4, + 0xa6, + 0xa4, + 0xd6, + 0x22, + 0xfc, + 0x26, + 0x1b, + 0x35, + 0xa4, + 0x1c, + 0x88, + 0x9f, + 0x7d, + 0xe0, + 0x9a, + 0x89, + 0x0f, + 0x6c, + 0xc1, + 0xda, + 0x6e, + 0x45, + 0xce, + 0x74, + 0xb1, + 0xff, /* Second Packet: Handshake */ 0xeb, /* Long, Handshake, PN Length=2 bytes */ @@ -1232,88 +6226,772 @@ static const unsigned char rx_script_7_in[] = { 0xa3, /* Length (675) */ 0x43, 0x29, /* PN (0) */ - 0xff, 0xdb, 0xcf, 0x3c, 0x17, 0xcf, 0xdc, 0x42, 0x3a, 0x59, - 0x88, 0xdb, 0x13, 0xef, 0x09, 0x3d, 0xf2, 0x24, 0xf3, 0xeb, - 0xca, 0xb0, 0xe1, 0xa4, 0x67, 0x64, 0x65, 0x80, 0x5f, 0x73, - 0x29, 0x69, 0x29, 0xba, 0x03, 0x77, 0x22, 0xc8, 0xa8, 0xd5, - 0x21, 0xf2, 0xa2, 0x30, 0x7f, 0x86, 0x3a, 0x8a, 0xdd, 0x92, - 0x33, 0xa6, 0x57, 0x21, 0x39, 0xdd, 0x34, 0xb4, 0x39, 0xa7, - 0x6f, 0x0a, 0x14, 0xba, 0x9e, 0x3b, 0x3a, 0x6a, 0x4b, 0xc5, - 0xda, 0x44, 0x82, 0xca, 0x52, 0x86, 0x68, 0x8a, 0x0c, 0x5e, - 0xeb, 0x1e, 0x81, 0x43, 0x3a, 0x59, 0x2c, 0x26, 0x63, 0xa3, - 0x89, 0x92, 0x80, 0xe9, 0x75, 0xc2, 0xdb, 0xb9, 0x58, 0x6d, - 0xab, 0xfd, 0x21, 0xe0, 0x35, 0x79, 0x2e, 0x56, 0x7b, 0xfb, - 0xb3, 0x7a, 0x05, 0x33, 0x0f, 0x13, 0xe5, 0xef, 0x04, 0x41, - 0x69, 0x85, 0x91, 0x24, 0xce, 0xb5, 0x21, 0x8d, 0x0a, 0x13, - 0xda, 0xae, 0x86, 0x2f, 0x25, 0x1f, 0x9c, 0x70, 0x8a, 0xaa, - 0x05, 0xeb, 0x30, 0x93, 0x50, 0xc1, 0x39, 0xab, 0x99, 0x8a, - 0x31, 0xc1, 0xc1, 0x5e, 0x39, 0xcf, 0x64, 0x3f, 0x9f, 0x5c, - 0xa5, 0xa1, 0x88, 0xb2, 0x5f, 0x23, 0xcb, 0x76, 0xe5, 0xf3, - 0x2d, 0xa0, 0xed, 0xad, 0xcf, 0x30, 0x05, 0x44, 0xdc, 0xa5, - 0x81, 0xb1, 0x7f, 0x78, 0x0d, 0x4d, 0x96, 0xa3, 0xcb, 0xcb, - 0x45, 0xcf, 0x5f, 0x22, 0xb8, 0x93, 0x2b, 0x16, 0xe0, 0x1c, - 0x53, 0x34, 0x76, 0x3b, 0x7b, 0x78, 0xa1, 0x46, 0x40, 0x43, - 0x4b, 0x0e, 0x1c, 0xfd, 0xcf, 0x01, 0xf1, 0x2c, 0xee, 0xd0, - 0xbd, 0x9f, 0x44, 0xd2, 0xd7, 0x13, 0xf9, 0x65, 0x82, 0xf5, - 0x42, 0xec, 0x9f, 0x5d, 0x51, 0x5a, 0x7b, 0xf2, 0x39, 0xbb, - 0xa6, 0x19, 0x5c, 0x73, 0x95, 0x65, 0x5b, 0x64, 0x2f, 0xda, - 0x50, 0xd0, 0x02, 0x34, 0x3f, 0x35, 0xc1, 0xd6, 0x31, 0x3b, - 0xcf, 0x3f, 0x81, 0x8d, 0xe0, 0x40, 0xfd, 0x6d, 0x32, 0x68, - 0xa4, 0xf2, 0x4e, 0x3a, 0x4a, 0x42, 0x2c, 0x07, 0x2d, 0x27, - 0xa3, 0x34, 0xe7, 0x27, 0x87, 0x80, 0x76, 0xc0, 0xa0, 0x72, - 0x05, 0xf2, 0x88, 0x81, 0xe3, 0x32, 0x00, 0x76, 0x8d, 0x24, - 0x5c, 0x97, 0x2d, 0xd6, 0xb8, 0x34, 0xf8, 0x1c, 0x1a, 0x6d, - 0xc7, 0x3f, 0xcf, 0x56, 0xae, 0xec, 0x26, 0x74, 0x53, 0x69, - 0xcd, 0x7a, 0x97, 0x29, 0xab, 0x12, 0x7d, 0x75, 0xf8, 0x8d, - 0x5b, 0xc0, 0x77, 0x20, 0xb6, 0x6a, 0x0b, 0xce, 0x98, 0x50, - 0xca, 0x47, 0x42, 0x1e, 0x5d, 0xc3, 0x24, 0x5a, 0x47, 0x48, - 0x3b, 0xa0, 0x9e, 0x43, 0xe9, 0x8d, 0x18, 0x23, 0xda, 0x6f, - 0x8c, 0xda, 0xd0, 0x3e, 0xdb, 0x37, 0xff, 0xfc, 0x7e, 0x17, - 0xbe, 0x42, 0xfd, 0xdb, 0x51, 0xb1, 0xa4, 0xfd, 0x9a, 0x20, - 0x27, 0x24, 0x17, 0x04, 0x70, 0xb6, 0x21, 0x87, 0x88, 0xe9, - 0xda, 0x63, 0xcb, 0xcb, 0x1d, 0xaf, 0x4a, 0x46, 0x76, 0x88, - 0xa1, 0xf8, 0x48, 0x6c, 0x06, 0xb4, 0x62, 0x1a, 0x67, 0x18, - 0xb0, 0x1d, 0x58, 0x6a, 0xfe, 0x1f, 0xf1, 0x48, 0xff, 0xcb, - 0xa4, 0xd1, 0xa8, 0x12, 0x1f, 0x45, 0x94, 0x2f, 0x55, 0x80, - 0x6a, 0x06, 0xcc, 0x7b, 0xb0, 0xcc, 0xb8, 0x06, 0x52, 0x16, - 0xe3, 0x6e, 0x7e, 0xb0, 0x42, 0xfd, 0x3b, 0x7e, 0x0a, 0x42, - 0x7b, 0x73, 0xaf, 0x2c, 0xf3, 0xbd, 0xe5, 0x72, 0x8c, 0x16, - 0xb2, 0xd7, 0x7a, 0x11, 0xb6, 0x9f, 0xd1, 0x69, 0xc1, 0x1a, - 0xe0, 0x26, 0x26, 0x13, 0xe2, 0x75, 0xf5, 0x74, 0xae, 0x3f, - 0xee, 0x1e, 0x09, 0x63, 0x5a, 0x30, 0x19, 0xa5, 0x59, 0x48, - 0x90, 0x9b, 0x46, 0x56, 0xd8, 0x6f, 0x6b, 0x76, 0x82, 0x32, - 0xc7, 0x29, 0x76, 0x2e, 0x32, 0xb6, 0x23, 0x99, 0xeb, 0x92, - 0x5d, 0xc4, 0x4c, 0xa1, 0xe9, 0x26, 0x37, 0x9a, 0x7d, 0x4c, - 0x16, 0x9c, 0x18, 0xe9, 0xc0, 0xff, 0x48, 0x79, 0xb1, 0x7b, - 0x0b, 0x1e, 0x6f, 0xb1, 0x77, 0xa5, 0xd2, 0xc6, 0x9a, 0xa9, - 0xfc, 0xd1, 0x0f, 0x69, 0xf3, 0xe0, 0x49, 0x70, 0x57, 0x80, - 0x86, 0xa7, 0x3f, 0x54, 0xa8, 0x60, 0xfb, 0xe4, 0x06, 0xa3, - 0x13, 0xb9, 0x2f, 0xa7, 0x37, 0x80, 0x0c, 0x43, 0xac, 0x2f, - 0xae, 0x6e, 0x62, 0x2b, 0x53, 0xe4, 0xfe, 0x58, 0xd7, 0x8b, - 0x96, 0xdc, 0xe6, 0xd3, 0x86, 0xb8, 0xd6, 0x42, 0x5b, 0x68, - 0x03, 0x48, 0x3f, 0xcd, 0xee, 0x39, 0x8b, 0xc4, 0x53, 0x30, - 0x87, 0x48, 0x2a, 0x01, 0x9d, 0x6f, 0x8e, 0x36, 0x75, 0x73, - 0xef, 0x77, 0x3a, 0x82, 0xd8, 0x4c, 0x0e, 0x7f, 0xb3, 0x8f, - 0x16, 0xd1, 0x10, 0xcf, 0x2f, 0xa3, 0xdf, 0x65, 0xba, 0x91, - 0x79, 0xf6, 0x93, 0x60, 0x08, 0xe5, 0xdb, 0x73, 0x02, 0x7a, - 0x0b, 0x0e, 0xcc, 0x3b, 0x1f, 0x08, 0x2d, 0x51, 0x3e, 0x87, - 0x48, 0xd3, 0xd3, 0x75, 0xc2, 0x28, 0xa3, 0xf3, 0x02, 0xde, - 0x8f, 0xa6, 0xbd, 0xb3, 0x19, 0xa0, 0xdb, 0x48, 0x51, 0x03, - 0x5f, 0x98, 0xbe, + 0xff, + 0xdb, + 0xcf, + 0x3c, + 0x17, + 0xcf, + 0xdc, + 0x42, + 0x3a, + 0x59, + 0x88, + 0xdb, + 0x13, + 0xef, + 0x09, + 0x3d, + 0xf2, + 0x24, + 0xf3, + 0xeb, + 0xca, + 0xb0, + 0xe1, + 0xa4, + 0x67, + 0x64, + 0x65, + 0x80, + 0x5f, + 0x73, + 0x29, + 0x69, + 0x29, + 0xba, + 0x03, + 0x77, + 0x22, + 0xc8, + 0xa8, + 0xd5, + 0x21, + 0xf2, + 0xa2, + 0x30, + 0x7f, + 0x86, + 0x3a, + 0x8a, + 0xdd, + 0x92, + 0x33, + 0xa6, + 0x57, + 0x21, + 0x39, + 0xdd, + 0x34, + 0xb4, + 0x39, + 0xa7, + 0x6f, + 0x0a, + 0x14, + 0xba, + 0x9e, + 0x3b, + 0x3a, + 0x6a, + 0x4b, + 0xc5, + 0xda, + 0x44, + 0x82, + 0xca, + 0x52, + 0x86, + 0x68, + 0x8a, + 0x0c, + 0x5e, + 0xeb, + 0x1e, + 0x81, + 0x43, + 0x3a, + 0x59, + 0x2c, + 0x26, + 0x63, + 0xa3, + 0x89, + 0x92, + 0x80, + 0xe9, + 0x75, + 0xc2, + 0xdb, + 0xb9, + 0x58, + 0x6d, + 0xab, + 0xfd, + 0x21, + 0xe0, + 0x35, + 0x79, + 0x2e, + 0x56, + 0x7b, + 0xfb, + 0xb3, + 0x7a, + 0x05, + 0x33, + 0x0f, + 0x13, + 0xe5, + 0xef, + 0x04, + 0x41, + 0x69, + 0x85, + 0x91, + 0x24, + 0xce, + 0xb5, + 0x21, + 0x8d, + 0x0a, + 0x13, + 0xda, + 0xae, + 0x86, + 0x2f, + 0x25, + 0x1f, + 0x9c, + 0x70, + 0x8a, + 0xaa, + 0x05, + 0xeb, + 0x30, + 0x93, + 0x50, + 0xc1, + 0x39, + 0xab, + 0x99, + 0x8a, + 0x31, + 0xc1, + 0xc1, + 0x5e, + 0x39, + 0xcf, + 0x64, + 0x3f, + 0x9f, + 0x5c, + 0xa5, + 0xa1, + 0x88, + 0xb2, + 0x5f, + 0x23, + 0xcb, + 0x76, + 0xe5, + 0xf3, + 0x2d, + 0xa0, + 0xed, + 0xad, + 0xcf, + 0x30, + 0x05, + 0x44, + 0xdc, + 0xa5, + 0x81, + 0xb1, + 0x7f, + 0x78, + 0x0d, + 0x4d, + 0x96, + 0xa3, + 0xcb, + 0xcb, + 0x45, + 0xcf, + 0x5f, + 0x22, + 0xb8, + 0x93, + 0x2b, + 0x16, + 0xe0, + 0x1c, + 0x53, + 0x34, + 0x76, + 0x3b, + 0x7b, + 0x78, + 0xa1, + 0x46, + 0x40, + 0x43, + 0x4b, + 0x0e, + 0x1c, + 0xfd, + 0xcf, + 0x01, + 0xf1, + 0x2c, + 0xee, + 0xd0, + 0xbd, + 0x9f, + 0x44, + 0xd2, + 0xd7, + 0x13, + 0xf9, + 0x65, + 0x82, + 0xf5, + 0x42, + 0xec, + 0x9f, + 0x5d, + 0x51, + 0x5a, + 0x7b, + 0xf2, + 0x39, + 0xbb, + 0xa6, + 0x19, + 0x5c, + 0x73, + 0x95, + 0x65, + 0x5b, + 0x64, + 0x2f, + 0xda, + 0x50, + 0xd0, + 0x02, + 0x34, + 0x3f, + 0x35, + 0xc1, + 0xd6, + 0x31, + 0x3b, + 0xcf, + 0x3f, + 0x81, + 0x8d, + 0xe0, + 0x40, + 0xfd, + 0x6d, + 0x32, + 0x68, + 0xa4, + 0xf2, + 0x4e, + 0x3a, + 0x4a, + 0x42, + 0x2c, + 0x07, + 0x2d, + 0x27, + 0xa3, + 0x34, + 0xe7, + 0x27, + 0x87, + 0x80, + 0x76, + 0xc0, + 0xa0, + 0x72, + 0x05, + 0xf2, + 0x88, + 0x81, + 0xe3, + 0x32, + 0x00, + 0x76, + 0x8d, + 0x24, + 0x5c, + 0x97, + 0x2d, + 0xd6, + 0xb8, + 0x34, + 0xf8, + 0x1c, + 0x1a, + 0x6d, + 0xc7, + 0x3f, + 0xcf, + 0x56, + 0xae, + 0xec, + 0x26, + 0x74, + 0x53, + 0x69, + 0xcd, + 0x7a, + 0x97, + 0x29, + 0xab, + 0x12, + 0x7d, + 0x75, + 0xf8, + 0x8d, + 0x5b, + 0xc0, + 0x77, + 0x20, + 0xb6, + 0x6a, + 0x0b, + 0xce, + 0x98, + 0x50, + 0xca, + 0x47, + 0x42, + 0x1e, + 0x5d, + 0xc3, + 0x24, + 0x5a, + 0x47, + 0x48, + 0x3b, + 0xa0, + 0x9e, + 0x43, + 0xe9, + 0x8d, + 0x18, + 0x23, + 0xda, + 0x6f, + 0x8c, + 0xda, + 0xd0, + 0x3e, + 0xdb, + 0x37, + 0xff, + 0xfc, + 0x7e, + 0x17, + 0xbe, + 0x42, + 0xfd, + 0xdb, + 0x51, + 0xb1, + 0xa4, + 0xfd, + 0x9a, + 0x20, + 0x27, + 0x24, + 0x17, + 0x04, + 0x70, + 0xb6, + 0x21, + 0x87, + 0x88, + 0xe9, + 0xda, + 0x63, + 0xcb, + 0xcb, + 0x1d, + 0xaf, + 0x4a, + 0x46, + 0x76, + 0x88, + 0xa1, + 0xf8, + 0x48, + 0x6c, + 0x06, + 0xb4, + 0x62, + 0x1a, + 0x67, + 0x18, + 0xb0, + 0x1d, + 0x58, + 0x6a, + 0xfe, + 0x1f, + 0xf1, + 0x48, + 0xff, + 0xcb, + 0xa4, + 0xd1, + 0xa8, + 0x12, + 0x1f, + 0x45, + 0x94, + 0x2f, + 0x55, + 0x80, + 0x6a, + 0x06, + 0xcc, + 0x7b, + 0xb0, + 0xcc, + 0xb8, + 0x06, + 0x52, + 0x16, + 0xe3, + 0x6e, + 0x7e, + 0xb0, + 0x42, + 0xfd, + 0x3b, + 0x7e, + 0x0a, + 0x42, + 0x7b, + 0x73, + 0xaf, + 0x2c, + 0xf3, + 0xbd, + 0xe5, + 0x72, + 0x8c, + 0x16, + 0xb2, + 0xd7, + 0x7a, + 0x11, + 0xb6, + 0x9f, + 0xd1, + 0x69, + 0xc1, + 0x1a, + 0xe0, + 0x26, + 0x26, + 0x13, + 0xe2, + 0x75, + 0xf5, + 0x74, + 0xae, + 0x3f, + 0xee, + 0x1e, + 0x09, + 0x63, + 0x5a, + 0x30, + 0x19, + 0xa5, + 0x59, + 0x48, + 0x90, + 0x9b, + 0x46, + 0x56, + 0xd8, + 0x6f, + 0x6b, + 0x76, + 0x82, + 0x32, + 0xc7, + 0x29, + 0x76, + 0x2e, + 0x32, + 0xb6, + 0x23, + 0x99, + 0xeb, + 0x92, + 0x5d, + 0xc4, + 0x4c, + 0xa1, + 0xe9, + 0x26, + 0x37, + 0x9a, + 0x7d, + 0x4c, + 0x16, + 0x9c, + 0x18, + 0xe9, + 0xc0, + 0xff, + 0x48, + 0x79, + 0xb1, + 0x7b, + 0x0b, + 0x1e, + 0x6f, + 0xb1, + 0x77, + 0xa5, + 0xd2, + 0xc6, + 0x9a, + 0xa9, + 0xfc, + 0xd1, + 0x0f, + 0x69, + 0xf3, + 0xe0, + 0x49, + 0x70, + 0x57, + 0x80, + 0x86, + 0xa7, + 0x3f, + 0x54, + 0xa8, + 0x60, + 0xfb, + 0xe4, + 0x06, + 0xa3, + 0x13, + 0xb9, + 0x2f, + 0xa7, + 0x37, + 0x80, + 0x0c, + 0x43, + 0xac, + 0x2f, + 0xae, + 0x6e, + 0x62, + 0x2b, + 0x53, + 0xe4, + 0xfe, + 0x58, + 0xd7, + 0x8b, + 0x96, + 0xdc, + 0xe6, + 0xd3, + 0x86, + 0xb8, + 0xd6, + 0x42, + 0x5b, + 0x68, + 0x03, + 0x48, + 0x3f, + 0xcd, + 0xee, + 0x39, + 0x8b, + 0xc4, + 0x53, + 0x30, + 0x87, + 0x48, + 0x2a, + 0x01, + 0x9d, + 0x6f, + 0x8e, + 0x36, + 0x75, + 0x73, + 0xef, + 0x77, + 0x3a, + 0x82, + 0xd8, + 0x4c, + 0x0e, + 0x7f, + 0xb3, + 0x8f, + 0x16, + 0xd1, + 0x10, + 0xcf, + 0x2f, + 0xa3, + 0xdf, + 0x65, + 0xba, + 0x91, + 0x79, + 0xf6, + 0x93, + 0x60, + 0x08, + 0xe5, + 0xdb, + 0x73, + 0x02, + 0x7a, + 0x0b, + 0x0e, + 0xcc, + 0x3b, + 0x1f, + 0x08, + 0x2d, + 0x51, + 0x3e, + 0x87, + 0x48, + 0xd3, + 0xd3, + 0x75, + 0xc2, + 0x28, + 0xa3, + 0xf3, + 0x02, + 0xde, + 0x8f, + 0xa6, + 0xbd, + 0xb3, + 0x19, + 0xa0, + 0xdb, + 0x48, + 0x51, + 0x03, + 0x5f, + 0x98, + 0xbe, /* Third Packet: 1-RTT */ 0x5c, /* Short, 1-RTT, Spin=0, KP=0, PN Length=2 bytes */ 0x4f, 0x33, /* PN (0) */ - 0x16, 0x75, 0x98, 0x67, 0x04, 0x16, 0x61, 0xe3, 0x00, 0xb7, - 0x9d, 0x5c, 0x53, 0x4c, 0x26, 0x90, 0x92, 0x8e, 0x0e, 0xc0, - 0x9c, 0x6d, 0x8b, 0xac, 0x15, 0x6d, 0x89, 0x74, 0x2f, 0xe7, - 0x84, 0xe3, 0x46, 0x46, 0x8c, 0xc1, 0x21, 0x7c, 0x44, 0xa5, - 0x00, 0x29, 0xca, 0xf2, 0x11, 0x18, 0xe0, 0x04, 0x40, 0x55, - 0xd2, 0xa7, 0xe5, 0x9d, 0x22, 0xa2, 0x2a, 0x6c, 0x03, 0x87, - 0xa3, 0xa3, 0xfa, 0xf5, 0x6c, 0xd7, 0x7d, 0xae, 0x3f, 0x28, - 0x01, 0xae, 0x06, 0x11, 0x69, 0x67, 0x90, 0x57, 0x5a, 0xd0, - 0xeb, 0xdd, 0xac, 0xbd, 0x7f, 0x33, 0x86, 0xbb + 0x16, + 0x75, + 0x98, + 0x67, + 0x04, + 0x16, + 0x61, + 0xe3, + 0x00, + 0xb7, + 0x9d, + 0x5c, + 0x53, + 0x4c, + 0x26, + 0x90, + 0x92, + 0x8e, + 0x0e, + 0xc0, + 0x9c, + 0x6d, + 0x8b, + 0xac, + 0x15, + 0x6d, + 0x89, + 0x74, + 0x2f, + 0xe7, + 0x84, + 0xe3, + 0x46, + 0x46, + 0x8c, + 0xc1, + 0x21, + 0x7c, + 0x44, + 0xa5, + 0x00, + 0x29, + 0xca, + 0xf2, + 0x11, + 0x18, + 0xe0, + 0x04, + 0x40, + 0x55, + 0xd2, + 0xa7, + 0xe5, + 0x9d, + 0x22, + 0xa2, + 0x2a, + 0x6c, + 0x03, + 0x87, + 0xa3, + 0xa3, + 0xfa, + 0xf5, + 0x6c, + 0xd7, + 0x7d, + 0xae, + 0x3f, + 0x28, + 0x01, + 0xae, + 0x06, + 0x11, + 0x69, + 0x67, + 0x90, + 0x57, + 0x5a, + 0xd0, + 0xeb, + 0xdd, + 0xac, + 0xbd, + 0x7f, + 0x33, + 0x86, + 0xbb, }; static const QUIC_PKT_HDR rx_script_7a_expect_hdr = { @@ -1334,51 +7012,447 @@ static const QUIC_PKT_HDR rx_script_7a_expect_hdr = { }; static const unsigned char rx_script_7a_body[] = { - 0x02, 0x03, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x06, 0x00, 0x40, - 0x5a, 0x02, 0x00, 0x00, 0x56, 0x03, 0x03, 0xd5, 0xfb, 0x6a, - 0x81, 0x1c, 0xdb, 0xa2, 0x5c, 0x11, 0x31, 0xda, 0x15, 0x28, - 0x97, 0x94, 0x83, 0xfd, 0x9d, 0x91, 0x0e, 0x87, 0x71, 0x46, - 0x64, 0xb4, 0xd9, 0x9e, 0xbd, 0xa8, 0x48, 0x32, 0xbf, 0x00, - 0x13, 0x03, 0x00, 0x00, 0x2e, 0x00, 0x2b, 0x00, 0x02, 0x03, - 0x04, 0x00, 0x33, 0x00, 0x24, 0x00, 0x1d, 0x00, 0x20, 0xef, - 0xbb, 0x46, 0xe9, 0xb4, 0xf6, 0x54, 0xc4, 0x07, 0x71, 0xdc, - 0x50, 0xd5, 0x69, 0x40, 0xbc, 0x85, 0x7f, 0xf9, 0x48, 0x14, - 0xe3, 0xd6, 0x08, 0xa9, 0x0b, 0xfd, 0xbe, 0xf1, 0x57, 0x21, - 0x34 + 0x02, + 0x03, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x06, + 0x00, + 0x40, + 0x5a, + 0x02, + 0x00, + 0x00, + 0x56, + 0x03, + 0x03, + 0xd5, + 0xfb, + 0x6a, + 0x81, + 0x1c, + 0xdb, + 0xa2, + 0x5c, + 0x11, + 0x31, + 0xda, + 0x15, + 0x28, + 0x97, + 0x94, + 0x83, + 0xfd, + 0x9d, + 0x91, + 0x0e, + 0x87, + 0x71, + 0x46, + 0x64, + 0xb4, + 0xd9, + 0x9e, + 0xbd, + 0xa8, + 0x48, + 0x32, + 0xbf, + 0x00, + 0x13, + 0x03, + 0x00, + 0x00, + 0x2e, + 0x00, + 0x2b, + 0x00, + 0x02, + 0x03, + 0x04, + 0x00, + 0x33, + 0x00, + 0x24, + 0x00, + 0x1d, + 0x00, + 0x20, + 0xef, + 0xbb, + 0x46, + 0xe9, + 0xb4, + 0xf6, + 0x54, + 0xc4, + 0x07, + 0x71, + 0xdc, + 0x50, + 0xd5, + 0x69, + 0x40, + 0xbc, + 0x85, + 0x7f, + 0xf9, + 0x48, + 0x14, + 0xe3, + 0xd6, + 0x08, + 0xa9, + 0x0b, + 0xfd, + 0xbe, + 0xf1, + 0x57, + 0x21, + 0x34, }; static const QUIC_PKT_HDR rx_script_7b_expect_hdr = { @@ -1399,72 +7473,663 @@ static const QUIC_PKT_HDR rx_script_7b_expect_hdr = { }; static const unsigned char rx_script_7b_body[] = { - 0x06, 0x00, 0x42, 0x8d, 0x08, 0x00, 0x00, 0x82, 0x00, 0x80, - 0x00, 0x10, 0x00, 0x08, 0x00, 0x06, 0x05, 0x64, 0x75, 0x6d, - 0x6d, 0x79, 0x00, 0x39, 0x00, 0x70, 0x46, 0x0a, 0x0d, 0xdc, - 0x59, 0xf0, 0x4e, 0xb2, 0x2c, 0xac, 0x69, 0x6a, 0xc9, 0x77, - 0xa9, 0x99, 0x05, 0x04, 0x80, 0x08, 0x00, 0x00, 0x06, 0x04, - 0x80, 0x08, 0x00, 0x00, 0x07, 0x04, 0x80, 0x08, 0x00, 0x00, - 0x04, 0x04, 0x80, 0x0c, 0x00, 0x00, 0x08, 0x02, 0x40, 0x64, - 0x09, 0x02, 0x40, 0x64, 0x01, 0x04, 0x80, 0x00, 0x75, 0x30, - 0x03, 0x02, 0x45, 0xac, 0x0b, 0x01, 0x1a, 0x0c, 0x00, 0x02, - 0x10, 0x42, 0xf0, 0xed, 0x09, 0x07, 0x5b, 0xd9, 0x5a, 0xb2, - 0x39, 0x5d, 0x73, 0x2c, 0x57, 0x1f, 0x50, 0x00, 0x0b, 0xe0, - 0x3e, 0xf3, 0xd6, 0x91, 0x6f, 0x9c, 0xcc, 0x31, 0xf7, 0xa5, - 0x0e, 0x01, 0x04, 0x0f, 0x04, 0x03, 0x45, 0x0c, 0x7a, 0x10, - 0x04, 0xfa, 0x5d, 0xd6, 0x80, 0x20, 0x01, 0x00, 0x0b, 0x00, - 0x01, 0x8f, 0x00, 0x00, 0x01, 0x8b, 0x00, 0x01, 0x86, 0x30, - 0x82, 0x01, 0x82, 0x30, 0x82, 0x01, 0x29, 0xa0, 0x03, 0x02, - 0x01, 0x02, 0x02, 0x14, 0x0a, 0x73, 0x0f, 0x86, 0x18, 0xf2, - 0xc3, 0x30, 0x01, 0xd2, 0xc0, 0xc1, 0x62, 0x52, 0x13, 0xf1, - 0x9c, 0x13, 0x39, 0xb5, 0x30, 0x0a, 0x06, 0x08, 0x2a, 0x86, - 0x48, 0xce, 0x3d, 0x04, 0x03, 0x02, 0x30, 0x17, 0x31, 0x15, - 0x30, 0x13, 0x06, 0x03, 0x55, 0x04, 0x03, 0x0c, 0x0c, 0x6d, - 0x61, 0x70, 0x61, 0x6b, 0x74, 0x2e, 0x6c, 0x6f, 0x63, 0x61, - 0x6c, 0x30, 0x1e, 0x17, 0x0d, 0x32, 0x32, 0x30, 0x38, 0x30, - 0x32, 0x31, 0x32, 0x30, 0x30, 0x31, 0x38, 0x5a, 0x17, 0x0d, - 0x32, 0x32, 0x30, 0x39, 0x30, 0x31, 0x31, 0x32, 0x30, 0x30, - 0x31, 0x38, 0x5a, 0x30, 0x17, 0x31, 0x15, 0x30, 0x13, 0x06, - 0x03, 0x55, 0x04, 0x03, 0x0c, 0x0c, 0x6d, 0x61, 0x70, 0x61, - 0x6b, 0x74, 0x2e, 0x6c, 0x6f, 0x63, 0x61, 0x6c, 0x30, 0x59, - 0x30, 0x13, 0x06, 0x07, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x02, - 0x01, 0x06, 0x08, 0x2a, 0x86, 0x48, 0xce, 0x3d, 0x03, 0x01, - 0x07, 0x03, 0x42, 0x00, 0x04, 0x67, 0xf4, 0xd3, 0x8f, 0x15, - 0x6d, 0xee, 0x85, 0xcc, 0x2a, 0x77, 0xfc, 0x0b, 0x8f, 0x9f, - 0xcf, 0xa9, 0x95, 0x5d, 0x5b, 0xcd, 0xb7, 0x8b, 0xba, 0x31, - 0x0a, 0x73, 0x62, 0xc5, 0xd0, 0x0e, 0x07, 0x90, 0xae, 0x38, - 0x43, 0x79, 0xce, 0x5e, 0x33, 0xad, 0x31, 0xbf, 0x9f, 0x2a, - 0x56, 0x83, 0xa5, 0x24, 0x16, 0xab, 0x0c, 0xf1, 0x64, 0xbe, - 0xe4, 0x93, 0xb5, 0x89, 0xd6, 0x05, 0xe4, 0xf7, 0x7b, 0xa3, - 0x53, 0x30, 0x51, 0x30, 0x1d, 0x06, 0x03, 0x55, 0x1d, 0x0e, - 0x04, 0x16, 0x04, 0x14, 0x02, 0x64, 0x0f, 0x55, 0x69, 0x14, - 0x91, 0x19, 0xed, 0xf9, 0x1a, 0xe9, 0x1d, 0xa5, 0x5a, 0xd0, - 0x48, 0x96, 0x9f, 0x60, 0x30, 0x1f, 0x06, 0x03, 0x55, 0x1d, - 0x23, 0x04, 0x18, 0x30, 0x16, 0x80, 0x14, 0x02, 0x64, 0x0f, - 0x55, 0x69, 0x14, 0x91, 0x19, 0xed, 0xf9, 0x1a, 0xe9, 0x1d, - 0xa5, 0x5a, 0xd0, 0x48, 0x96, 0x9f, 0x60, 0x30, 0x0f, 0x06, - 0x03, 0x55, 0x1d, 0x13, 0x01, 0x01, 0xff, 0x04, 0x05, 0x30, - 0x03, 0x01, 0x01, 0xff, 0x30, 0x0a, 0x06, 0x08, 0x2a, 0x86, - 0x48, 0xce, 0x3d, 0x04, 0x03, 0x02, 0x03, 0x47, 0x00, 0x30, - 0x44, 0x02, 0x20, 0x0a, 0x82, 0x92, 0x6e, 0xd3, 0xc6, 0x66, - 0xd9, 0xd3, 0x75, 0xff, 0x71, 0x3b, 0x61, 0x46, 0x21, 0x00, - 0xe6, 0x21, 0x5d, 0x9c, 0x86, 0xe9, 0x65, 0x40, 0x4f, 0xeb, - 0x70, 0x4f, 0x2c, 0xad, 0x00, 0x02, 0x20, 0x08, 0xc2, 0x07, - 0x5d, 0x16, 0xfc, 0x54, 0x34, 0x2b, 0xb4, 0x18, 0x67, 0x44, - 0x81, 0xc9, 0xa9, 0x67, 0x2e, 0xce, 0xa1, 0x02, 0x9f, 0x3b, - 0xe5, 0x61, 0x16, 0x0b, 0x50, 0xf6, 0xa1, 0x50, 0x94, 0x00, - 0x00, 0x0f, 0x00, 0x00, 0x4c, 0x04, 0x03, 0x00, 0x48, 0x30, - 0x46, 0x02, 0x21, 0x00, 0xaa, 0x18, 0x61, 0x93, 0xdf, 0xbb, - 0x79, 0xe7, 0x34, 0x7e, 0x2e, 0x61, 0x13, 0x8c, 0xa0, 0x33, - 0xfb, 0x33, 0xca, 0xfc, 0xd2, 0x45, 0xb0, 0xc7, 0x89, 0x3d, - 0xf1, 0xd6, 0x54, 0x94, 0x05, 0xb6, 0x02, 0x21, 0x00, 0xef, - 0x6c, 0xb6, 0xf2, 0x00, 0xb2, 0x32, 0xb1, 0xf3, 0x3f, 0x59, - 0xf5, 0xc8, 0x18, 0xbe, 0x39, 0xbb, 0x27, 0xf8, 0x67, 0xac, - 0xcb, 0x63, 0xa4, 0x29, 0xfb, 0x8e, 0x88, 0x0f, 0xe5, 0xe9, - 0x7e, 0x14, 0x00, 0x00, 0x20, 0xfc, 0x2c, 0x4c, 0xa7, 0x77, - 0x24, 0x79, 0x29, 0xa8, 0x82, 0x1a, 0x4d, 0x58, 0x9d, 0x82, - 0xe2, 0x09, 0x36, 0x63, 0x0e, 0x0b, 0x55, 0x51, 0x80, 0x93, - 0x40, 0xda, 0x41, 0x33, 0x08, 0x10, 0x2c + 0x06, + 0x00, + 0x42, + 0x8d, + 0x08, + 0x00, + 0x00, + 0x82, + 0x00, + 0x80, + 0x00, + 0x10, + 0x00, + 0x08, + 0x00, + 0x06, + 0x05, + 0x64, + 0x75, + 0x6d, + 0x6d, + 0x79, + 0x00, + 0x39, + 0x00, + 0x70, + 0x46, + 0x0a, + 0x0d, + 0xdc, + 0x59, + 0xf0, + 0x4e, + 0xb2, + 0x2c, + 0xac, + 0x69, + 0x6a, + 0xc9, + 0x77, + 0xa9, + 0x99, + 0x05, + 0x04, + 0x80, + 0x08, + 0x00, + 0x00, + 0x06, + 0x04, + 0x80, + 0x08, + 0x00, + 0x00, + 0x07, + 0x04, + 0x80, + 0x08, + 0x00, + 0x00, + 0x04, + 0x04, + 0x80, + 0x0c, + 0x00, + 0x00, + 0x08, + 0x02, + 0x40, + 0x64, + 0x09, + 0x02, + 0x40, + 0x64, + 0x01, + 0x04, + 0x80, + 0x00, + 0x75, + 0x30, + 0x03, + 0x02, + 0x45, + 0xac, + 0x0b, + 0x01, + 0x1a, + 0x0c, + 0x00, + 0x02, + 0x10, + 0x42, + 0xf0, + 0xed, + 0x09, + 0x07, + 0x5b, + 0xd9, + 0x5a, + 0xb2, + 0x39, + 0x5d, + 0x73, + 0x2c, + 0x57, + 0x1f, + 0x50, + 0x00, + 0x0b, + 0xe0, + 0x3e, + 0xf3, + 0xd6, + 0x91, + 0x6f, + 0x9c, + 0xcc, + 0x31, + 0xf7, + 0xa5, + 0x0e, + 0x01, + 0x04, + 0x0f, + 0x04, + 0x03, + 0x45, + 0x0c, + 0x7a, + 0x10, + 0x04, + 0xfa, + 0x5d, + 0xd6, + 0x80, + 0x20, + 0x01, + 0x00, + 0x0b, + 0x00, + 0x01, + 0x8f, + 0x00, + 0x00, + 0x01, + 0x8b, + 0x00, + 0x01, + 0x86, + 0x30, + 0x82, + 0x01, + 0x82, + 0x30, + 0x82, + 0x01, + 0x29, + 0xa0, + 0x03, + 0x02, + 0x01, + 0x02, + 0x02, + 0x14, + 0x0a, + 0x73, + 0x0f, + 0x86, + 0x18, + 0xf2, + 0xc3, + 0x30, + 0x01, + 0xd2, + 0xc0, + 0xc1, + 0x62, + 0x52, + 0x13, + 0xf1, + 0x9c, + 0x13, + 0x39, + 0xb5, + 0x30, + 0x0a, + 0x06, + 0x08, + 0x2a, + 0x86, + 0x48, + 0xce, + 0x3d, + 0x04, + 0x03, + 0x02, + 0x30, + 0x17, + 0x31, + 0x15, + 0x30, + 0x13, + 0x06, + 0x03, + 0x55, + 0x04, + 0x03, + 0x0c, + 0x0c, + 0x6d, + 0x61, + 0x70, + 0x61, + 0x6b, + 0x74, + 0x2e, + 0x6c, + 0x6f, + 0x63, + 0x61, + 0x6c, + 0x30, + 0x1e, + 0x17, + 0x0d, + 0x32, + 0x32, + 0x30, + 0x38, + 0x30, + 0x32, + 0x31, + 0x32, + 0x30, + 0x30, + 0x31, + 0x38, + 0x5a, + 0x17, + 0x0d, + 0x32, + 0x32, + 0x30, + 0x39, + 0x30, + 0x31, + 0x31, + 0x32, + 0x30, + 0x30, + 0x31, + 0x38, + 0x5a, + 0x30, + 0x17, + 0x31, + 0x15, + 0x30, + 0x13, + 0x06, + 0x03, + 0x55, + 0x04, + 0x03, + 0x0c, + 0x0c, + 0x6d, + 0x61, + 0x70, + 0x61, + 0x6b, + 0x74, + 0x2e, + 0x6c, + 0x6f, + 0x63, + 0x61, + 0x6c, + 0x30, + 0x59, + 0x30, + 0x13, + 0x06, + 0x07, + 0x2a, + 0x86, + 0x48, + 0xce, + 0x3d, + 0x02, + 0x01, + 0x06, + 0x08, + 0x2a, + 0x86, + 0x48, + 0xce, + 0x3d, + 0x03, + 0x01, + 0x07, + 0x03, + 0x42, + 0x00, + 0x04, + 0x67, + 0xf4, + 0xd3, + 0x8f, + 0x15, + 0x6d, + 0xee, + 0x85, + 0xcc, + 0x2a, + 0x77, + 0xfc, + 0x0b, + 0x8f, + 0x9f, + 0xcf, + 0xa9, + 0x95, + 0x5d, + 0x5b, + 0xcd, + 0xb7, + 0x8b, + 0xba, + 0x31, + 0x0a, + 0x73, + 0x62, + 0xc5, + 0xd0, + 0x0e, + 0x07, + 0x90, + 0xae, + 0x38, + 0x43, + 0x79, + 0xce, + 0x5e, + 0x33, + 0xad, + 0x31, + 0xbf, + 0x9f, + 0x2a, + 0x56, + 0x83, + 0xa5, + 0x24, + 0x16, + 0xab, + 0x0c, + 0xf1, + 0x64, + 0xbe, + 0xe4, + 0x93, + 0xb5, + 0x89, + 0xd6, + 0x05, + 0xe4, + 0xf7, + 0x7b, + 0xa3, + 0x53, + 0x30, + 0x51, + 0x30, + 0x1d, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x0e, + 0x04, + 0x16, + 0x04, + 0x14, + 0x02, + 0x64, + 0x0f, + 0x55, + 0x69, + 0x14, + 0x91, + 0x19, + 0xed, + 0xf9, + 0x1a, + 0xe9, + 0x1d, + 0xa5, + 0x5a, + 0xd0, + 0x48, + 0x96, + 0x9f, + 0x60, + 0x30, + 0x1f, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x23, + 0x04, + 0x18, + 0x30, + 0x16, + 0x80, + 0x14, + 0x02, + 0x64, + 0x0f, + 0x55, + 0x69, + 0x14, + 0x91, + 0x19, + 0xed, + 0xf9, + 0x1a, + 0xe9, + 0x1d, + 0xa5, + 0x5a, + 0xd0, + 0x48, + 0x96, + 0x9f, + 0x60, + 0x30, + 0x0f, + 0x06, + 0x03, + 0x55, + 0x1d, + 0x13, + 0x01, + 0x01, + 0xff, + 0x04, + 0x05, + 0x30, + 0x03, + 0x01, + 0x01, + 0xff, + 0x30, + 0x0a, + 0x06, + 0x08, + 0x2a, + 0x86, + 0x48, + 0xce, + 0x3d, + 0x04, + 0x03, + 0x02, + 0x03, + 0x47, + 0x00, + 0x30, + 0x44, + 0x02, + 0x20, + 0x0a, + 0x82, + 0x92, + 0x6e, + 0xd3, + 0xc6, + 0x66, + 0xd9, + 0xd3, + 0x75, + 0xff, + 0x71, + 0x3b, + 0x61, + 0x46, + 0x21, + 0x00, + 0xe6, + 0x21, + 0x5d, + 0x9c, + 0x86, + 0xe9, + 0x65, + 0x40, + 0x4f, + 0xeb, + 0x70, + 0x4f, + 0x2c, + 0xad, + 0x00, + 0x02, + 0x20, + 0x08, + 0xc2, + 0x07, + 0x5d, + 0x16, + 0xfc, + 0x54, + 0x34, + 0x2b, + 0xb4, + 0x18, + 0x67, + 0x44, + 0x81, + 0xc9, + 0xa9, + 0x67, + 0x2e, + 0xce, + 0xa1, + 0x02, + 0x9f, + 0x3b, + 0xe5, + 0x61, + 0x16, + 0x0b, + 0x50, + 0xf6, + 0xa1, + 0x50, + 0x94, + 0x00, + 0x00, + 0x0f, + 0x00, + 0x00, + 0x4c, + 0x04, + 0x03, + 0x00, + 0x48, + 0x30, + 0x46, + 0x02, + 0x21, + 0x00, + 0xaa, + 0x18, + 0x61, + 0x93, + 0xdf, + 0xbb, + 0x79, + 0xe7, + 0x34, + 0x7e, + 0x2e, + 0x61, + 0x13, + 0x8c, + 0xa0, + 0x33, + 0xfb, + 0x33, + 0xca, + 0xfc, + 0xd2, + 0x45, + 0xb0, + 0xc7, + 0x89, + 0x3d, + 0xf1, + 0xd6, + 0x54, + 0x94, + 0x05, + 0xb6, + 0x02, + 0x21, + 0x00, + 0xef, + 0x6c, + 0xb6, + 0xf2, + 0x00, + 0xb2, + 0x32, + 0xb1, + 0xf3, + 0x3f, + 0x59, + 0xf5, + 0xc8, + 0x18, + 0xbe, + 0x39, + 0xbb, + 0x27, + 0xf8, + 0x67, + 0xac, + 0xcb, + 0x63, + 0xa4, + 0x29, + 0xfb, + 0x8e, + 0x88, + 0x0f, + 0xe5, + 0xe9, + 0x7e, + 0x14, + 0x00, + 0x00, + 0x20, + 0xfc, + 0x2c, + 0x4c, + 0xa7, + 0x77, + 0x24, + 0x79, + 0x29, + 0xa8, + 0x82, + 0x1a, + 0x4d, + 0x58, + 0x9d, + 0x82, + 0xe2, + 0x09, + 0x36, + 0x63, + 0x0e, + 0x0b, + 0x55, + 0x51, + 0x80, + 0x93, + 0x40, + 0xda, + 0x41, + 0x33, + 0x08, + 0x10, + 0x2c, }; static const QUIC_PKT_HDR rx_script_7c_expect_hdr = { @@ -1485,67 +8150,135 @@ static const QUIC_PKT_HDR rx_script_7c_expect_hdr = { }; static const unsigned char rx_script_7c_body[] = { - 0x18, 0x03, 0x00, 0x04, 0xf7, 0x75, 0x72, 0xa2, 0xfd, 0x17, - 0xd4, 0x82, 0x8e, 0xe9, 0x5b, 0xce, 0xed, 0xec, 0x88, 0xb9, - 0x73, 0xbf, 0x36, 0x9f, 0x18, 0x02, 0x00, 0x04, 0x5f, 0x43, - 0x96, 0xe4, 0x15, 0xdc, 0x56, 0x6b, 0x67, 0x4c, 0x36, 0xb2, - 0xe2, 0x77, 0xdc, 0x6e, 0xb9, 0x2c, 0x0d, 0x79, 0x18, 0x01, - 0x00, 0x04, 0xcb, 0x83, 0x4a, 0xf4, 0x8d, 0x7b, 0x69, 0x90, - 0xaf, 0x0d, 0xd2, 0x38, 0xa4, 0xf1, 0x94, 0xff, 0x63, 0x24, - 0xd3, 0x7a + 0x18, + 0x03, + 0x00, + 0x04, + 0xf7, + 0x75, + 0x72, + 0xa2, + 0xfd, + 0x17, + 0xd4, + 0x82, + 0x8e, + 0xe9, + 0x5b, + 0xce, + 0xed, + 0xec, + 0x88, + 0xb9, + 0x73, + 0xbf, + 0x36, + 0x9f, + 0x18, + 0x02, + 0x00, + 0x04, + 0x5f, + 0x43, + 0x96, + 0xe4, + 0x15, + 0xdc, + 0x56, + 0x6b, + 0x67, + 0x4c, + 0x36, + 0xb2, + 0xe2, + 0x77, + 0xdc, + 0x6e, + 0xb9, + 0x2c, + 0x0d, + 0x79, + 0x18, + 0x01, + 0x00, + 0x04, + 0xcb, + 0x83, + 0x4a, + 0xf4, + 0x8d, + 0x7b, + 0x69, + 0x90, + 0xaf, + 0x0d, + 0xd2, + 0x38, + 0xa4, + 0xf1, + 0x94, + 0xff, + 0x63, + 0x24, + 0xd3, + 0x7a, }; static const struct rx_test_op rx_script_7[] = { - RX_OP_ALLOW_1RTT(), - RX_OP_SET_RX_DCID(empty_conn_id), - RX_OP_PROVIDE_SECRET_INITIAL(rx_script_7_c2s_init_dcid), - RX_OP_INJECT_N(7), - RX_OP_CHECK_PKT_N(7a), - RX_OP_CHECK_NO_PKT(), /* not got secret for next packet yet */ - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, QRL_SUITE_CHACHA20POLY1305, rx_script_7_handshake_secret), - RX_OP_CHECK_PKT_N(7b), - RX_OP_CHECK_NO_PKT(), /* not got secret for next packet yet */ - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_CHACHA20POLY1305, rx_script_7_1rtt_secret), - RX_OP_CHECK_PKT_N(7c), - RX_OP_CHECK_NO_PKT(), + RX_OP_ALLOW_1RTT() + RX_OP_SET_RX_DCID(empty_conn_id) + RX_OP_PROVIDE_SECRET_INITIAL(rx_script_7_c2s_init_dcid) + RX_OP_INJECT_N(7) + RX_OP_CHECK_PKT_N(7a) + RX_OP_CHECK_NO_PKT() /* not got secret for next packet yet */ + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, + QRL_SUITE_CHACHA20POLY1305, rx_script_7_handshake_secret) + RX_OP_CHECK_PKT_N(7b) + RX_OP_CHECK_NO_PKT() /* not got secret for next packet yet */ + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, + QRL_SUITE_CHACHA20POLY1305, rx_script_7_1rtt_secret) + RX_OP_CHECK_PKT_N(7c) + RX_OP_CHECK_NO_PKT() /* Discard Initial EL and try injecting the packet again */ - RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_INITIAL), - RX_OP_INJECT_N(7), + RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_INITIAL) + RX_OP_INJECT_N(7) /* Initial packet is not output because we have discarded Initial keys */ - RX_OP_CHECK_PKT_N(7b), - RX_OP_CHECK_PKT_N(7c), - RX_OP_CHECK_NO_PKT(), + RX_OP_CHECK_PKT_N(7b) + RX_OP_CHECK_PKT_N(7c) + RX_OP_CHECK_NO_PKT() /* Try again with discarded keys */ - RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_HANDSHAKE), - RX_OP_INJECT_N(7), - RX_OP_CHECK_PKT_N(7c), - RX_OP_CHECK_NO_PKT(), + RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_HANDSHAKE) + RX_OP_INJECT_N(7) + RX_OP_CHECK_PKT_N(7c) + RX_OP_CHECK_NO_PKT() /* Try again */ - RX_OP_INJECT_N(7), - RX_OP_CHECK_PKT_N(7c), - RX_OP_CHECK_NO_PKT(), + RX_OP_INJECT_N(7) + RX_OP_CHECK_PKT_N(7c) + RX_OP_CHECK_NO_PKT() /* Try again with discarded 1-RTT keys */ - RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_1RTT), - RX_OP_INJECT_N(7), - RX_OP_CHECK_NO_PKT(), + RX_OP_DISCARD_EL(QUIC_ENC_LEVEL_1RTT) + RX_OP_INJECT_N(7) + RX_OP_CHECK_NO_PKT() /* Recreate QRL, test reading packets received before key */ - RX_OP_SET_SCID_LEN(0), - RX_OP_SET_RX_DCID(empty_conn_id), - RX_OP_INJECT_N(7), - RX_OP_CHECK_NO_PKT(), - RX_OP_PROVIDE_SECRET_INITIAL(rx_script_7_c2s_init_dcid), - RX_OP_CHECK_PKT_N(7a), - RX_OP_CHECK_NO_PKT(), - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, QRL_SUITE_CHACHA20POLY1305, rx_script_7_handshake_secret), - RX_OP_CHECK_PKT_N(7b), - RX_OP_CHECK_NO_PKT(), - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_CHACHA20POLY1305, rx_script_7_1rtt_secret), - RX_OP_CHECK_PKT_N(7c), - RX_OP_CHECK_NO_PKT(), + RX_OP_SET_SCID_LEN(0) + RX_OP_SET_RX_DCID(empty_conn_id) + RX_OP_INJECT_N(7) + RX_OP_CHECK_NO_PKT() + RX_OP_PROVIDE_SECRET_INITIAL(rx_script_7_c2s_init_dcid) + RX_OP_CHECK_PKT_N(7a) + RX_OP_CHECK_NO_PKT() + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, + QRL_SUITE_CHACHA20POLY1305, rx_script_7_handshake_secret) + RX_OP_CHECK_PKT_N(7b) + RX_OP_CHECK_NO_PKT() + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, + QRL_SUITE_CHACHA20POLY1305, rx_script_7_1rtt_secret) + RX_OP_CHECK_PKT_N(7c) + RX_OP_CHECK_NO_PKT() - RX_OP_END + RX_OP_END }; #endif /* !defined(OPENSSL_NO_CHACHA) && !defined(OPENSSL_NO_POLY1305) */ @@ -1562,12 +8295,57 @@ static const unsigned char rx_script_8a_in[] = { 0x51, /* Short, 1-RTT, PN Length=2 bytes, KP=0 */ 0xcb, 0xf4, /* PN (4) */ - 0x3f, 0x68, 0x7b, 0xa8, 0x2b, 0xb9, 0xfa, 0x7d, 0xe4, 0x6b, - 0x20, 0x48, 0xd1, 0x3c, 0xcb, 0x4b, 0xef, 0xb1, 0xfd, 0x5e, - 0x1b, 0x19, 0x83, 0xa9, 0x47, 0x62, 0xc1, 0x6e, 0xef, 0x27, - 0xc3, 0x9b, 0x8f, 0x3f, 0xce, 0x11, 0x68, 0xf5, 0x73, 0x0d, - 0xf2, 0xdc, 0xe0, 0x28, 0x28, 0x79, 0xa6, 0x39, 0xc3, 0xb9, - 0xd3 + 0x3f, + 0x68, + 0x7b, + 0xa8, + 0x2b, + 0xb9, + 0xfa, + 0x7d, + 0xe4, + 0x6b, + 0x20, + 0x48, + 0xd1, + 0x3c, + 0xcb, + 0x4b, + 0xef, + 0xb1, + 0xfd, + 0x5e, + 0x1b, + 0x19, + 0x83, + 0xa9, + 0x47, + 0x62, + 0xc1, + 0x6e, + 0xef, + 0x27, + 0xc3, + 0x9b, + 0x8f, + 0x3f, + 0xce, + 0x11, + 0x68, + 0xf5, + 0x73, + 0x0d, + 0xf2, + 0xdc, + 0xe0, + 0x28, + 0x28, + 0x79, + 0xa6, + 0x39, + 0xc3, + 0xb9, + 0xd3, }; static const QUIC_PKT_HDR rx_script_8a_expect_hdr = { @@ -1597,12 +8375,57 @@ static const unsigned char rx_script_8b_in[] = { 0x52, /* Short, 1-RTT, PN Length=2 bytes, KP=1 */ 0x21, 0x8e, /* PN (5) */ - 0xa2, 0x6a, 0x9c, 0x83, 0x24, 0x48, 0xae, 0x60, 0x1e, 0xc2, - 0xa5, 0x91, 0xfa, 0xe5, 0xf2, 0x05, 0x14, 0x37, 0x04, 0x6a, - 0xa8, 0xae, 0x06, 0x58, 0xd7, 0x85, 0x48, 0xd7, 0x3b, 0x85, - 0x9e, 0x5a, 0xb3, 0x46, 0x89, 0x1b, 0x4b, 0x6e, 0x1d, 0xd1, - 0xfc, 0xb7, 0x47, 0xda, 0x6a, 0x64, 0x4b, 0x8e, 0xf2, 0x69, - 0x16 + 0xa2, + 0x6a, + 0x9c, + 0x83, + 0x24, + 0x48, + 0xae, + 0x60, + 0x1e, + 0xc2, + 0xa5, + 0x91, + 0xfa, + 0xe5, + 0xf2, + 0x05, + 0x14, + 0x37, + 0x04, + 0x6a, + 0xa8, + 0xae, + 0x06, + 0x58, + 0xd7, + 0x85, + 0x48, + 0xd7, + 0x3b, + 0x85, + 0x9e, + 0x5a, + 0xb3, + 0x46, + 0x89, + 0x1b, + 0x4b, + 0x6e, + 0x1d, + 0xd1, + 0xfc, + 0xb7, + 0x47, + 0xda, + 0x6a, + 0x64, + 0x4b, + 0x8e, + 0xf2, + 0x69, + 0x16, }; static const QUIC_PKT_HDR rx_script_8b_expect_hdr = { @@ -1623,21 +8446,92 @@ static const QUIC_PKT_HDR rx_script_8b_expect_hdr = { }; static const unsigned char rx_script_8b_body[] = { - 0x02, 0x04, 0x03, 0x00, 0x00, 0x0c, 0x00, 0x36, 0x49, 0x27, - 0x6d, 0x20, 0x68, 0x61, 0x76, 0x69, 0x6e, 0x67, 0x20, 0x61, - 0x20, 0x77, 0x6f, 0x6e, 0x64, 0x65, 0x72, 0x66, 0x75, 0x6c, - 0x20, 0x74, 0x69, 0x6d, 0x65 + 0x02, + 0x04, + 0x03, + 0x00, + 0x00, + 0x0c, + 0x00, + 0x36, + 0x49, + 0x27, + 0x6d, + 0x20, + 0x68, + 0x61, + 0x76, + 0x69, + 0x6e, + 0x67, + 0x20, + 0x61, + 0x20, + 0x77, + 0x6f, + 0x6e, + 0x64, + 0x65, + 0x72, + 0x66, + 0x75, + 0x6c, + 0x20, + 0x74, + 0x69, + 0x6d, + 0x65, }; static const unsigned char rx_script_8c_in[] = { 0x5b, /* Short, 1-RTT, PN Length=2 bytes, KP=0 */ 0x98, 0xd6, /* PN (3) */ - 0x3c, 0x6f, 0x94, 0x20, 0x5e, 0xfc, 0x5b, 0x3a, 0x4a, 0x65, - 0x1a, 0x9a, 0x6c, 0x00, 0x52, 0xb6, 0x0c, 0x9b, 0x07, 0xf9, - 0x6f, 0xbc, 0x3d, 0xb4, 0x57, 0xe0, 0x15, 0x74, 0xfe, 0x76, - 0xea, 0x1f, 0x23, 0xae, 0x22, 0x62, 0xb7, 0x90, 0x94, 0x89, - 0x38, 0x9b, 0x5b, 0x47, 0xed + 0x3c, + 0x6f, + 0x94, + 0x20, + 0x5e, + 0xfc, + 0x5b, + 0x3a, + 0x4a, + 0x65, + 0x1a, + 0x9a, + 0x6c, + 0x00, + 0x52, + 0xb6, + 0x0c, + 0x9b, + 0x07, + 0xf9, + 0x6f, + 0xbc, + 0x3d, + 0xb4, + 0x57, + 0xe0, + 0x15, + 0x74, + 0xfe, + 0x76, + 0xea, + 0x1f, + 0x23, + 0xae, + 0x22, + 0x62, + 0xb7, + 0x90, + 0x94, + 0x89, + 0x38, + 0x9b, + 0x5b, + 0x47, + 0xed, }; static const QUIC_PKT_HDR rx_script_8c_expect_hdr = { @@ -1658,21 +8552,93 @@ static const QUIC_PKT_HDR rx_script_8c_expect_hdr = { }; static const unsigned char rx_script_8c_body[] = { - 0x08, 0x00, 0x49, 0x27, 0x6d, 0x20, 0x68, 0x61, 0x76, 0x69, - 0x6e, 0x67, 0x20, 0x61, 0x20, 0x77, 0x6f, 0x6e, 0x64, 0x65, - 0x72, 0x66, 0x75, 0x6c, 0x20, 0x74, 0x69, 0x6d, 0x65 + 0x08, + 0x00, + 0x49, + 0x27, + 0x6d, + 0x20, + 0x68, + 0x61, + 0x76, + 0x69, + 0x6e, + 0x67, + 0x20, + 0x61, + 0x20, + 0x77, + 0x6f, + 0x6e, + 0x64, + 0x65, + 0x72, + 0x66, + 0x75, + 0x6c, + 0x20, + 0x74, + 0x69, + 0x6d, + 0x65, }; static const unsigned char rx_script_8d_in[] = { 0x55, /* Short, 1-RTT, PN Length=2 bytes, KP=1 */ 0x98, 0x20, /* PN (6) */ - 0x45, 0x53, 0x05, 0x29, 0x30, 0x42, 0x29, 0x02, 0xf2, 0xa7, - 0x27, 0xd6, 0xb0, 0xb7, 0x30, 0xad, 0x45, 0xd8, 0x73, 0xd7, - 0xe3, 0x65, 0xee, 0xd9, 0x35, 0x33, 0x03, 0x3a, 0x35, 0x0b, - 0x59, 0xa7, 0xbc, 0x23, 0x37, 0xc2, 0x5e, 0x13, 0x88, 0x18, - 0x79, 0x94, 0x6c, 0x15, 0xe3, 0x1f, 0x0d, 0xd1, 0xc3, 0xfa, - 0x40, 0xff + 0x45, + 0x53, + 0x05, + 0x29, + 0x30, + 0x42, + 0x29, + 0x02, + 0xf2, + 0xa7, + 0x27, + 0xd6, + 0xb0, + 0xb7, + 0x30, + 0xad, + 0x45, + 0xd8, + 0x73, + 0xd7, + 0xe3, + 0x65, + 0xee, + 0xd9, + 0x35, + 0x33, + 0x03, + 0x3a, + 0x35, + 0x0b, + 0x59, + 0xa7, + 0xbc, + 0x23, + 0x37, + 0xc2, + 0x5e, + 0x13, + 0x88, + 0x18, + 0x79, + 0x94, + 0x6c, + 0x15, + 0xe3, + 0x1f, + 0x0d, + 0xd1, + 0xc3, + 0xfa, + 0x40, + 0xff, }; static const QUIC_PKT_HDR rx_script_8d_expect_hdr = { @@ -1693,22 +8659,100 @@ static const QUIC_PKT_HDR rx_script_8d_expect_hdr = { }; static const unsigned char rx_script_8d_body[] = { - 0x02, 0x05, 0x03, 0x00, 0x00, 0x0c, 0x00, 0x40, 0x51, 0x49, - 0x27, 0x6d, 0x20, 0x68, 0x61, 0x76, 0x69, 0x6e, 0x67, 0x20, - 0x61, 0x20, 0x77, 0x6f, 0x6e, 0x64, 0x65, 0x72, 0x66, 0x75, - 0x6c, 0x20, 0x74, 0x69, 0x6d, 0x65 + 0x02, + 0x05, + 0x03, + 0x00, + 0x00, + 0x0c, + 0x00, + 0x40, + 0x51, + 0x49, + 0x27, + 0x6d, + 0x20, + 0x68, + 0x61, + 0x76, + 0x69, + 0x6e, + 0x67, + 0x20, + 0x61, + 0x20, + 0x77, + 0x6f, + 0x6e, + 0x64, + 0x65, + 0x72, + 0x66, + 0x75, + 0x6c, + 0x20, + 0x74, + 0x69, + 0x6d, + 0x65, }; static const unsigned char rx_script_8e_in[] = { 0x55, /* Short, 1-RTTT, PN Length=2 bytes, KP=0 */ 0x76, 0x25, /* PN (10) */ - 0x1c, 0x0d, 0x70, 0x4c, 0x2b, 0xc5, 0x7d, 0x7b, 0x77, 0x64, - 0x03, 0x27, 0xb3, 0x5d, 0x83, 0x9e, 0x35, 0x05, 0x10, 0xd2, - 0xa4, 0x5c, 0x83, 0xd6, 0x94, 0x12, 0x18, 0xc5, 0xb3, 0x0f, - 0x0a, 0xb1, 0x8a, 0x82, 0x9f, 0xd6, 0xa9, 0xab, 0x40, 0xc1, - 0x05, 0xe8, 0x1b, 0x74, 0xaa, 0x8e, 0xd6, 0x8b, 0xa5, 0xa3, - 0x77, 0x79 + 0x1c, + 0x0d, + 0x70, + 0x4c, + 0x2b, + 0xc5, + 0x7d, + 0x7b, + 0x77, + 0x64, + 0x03, + 0x27, + 0xb3, + 0x5d, + 0x83, + 0x9e, + 0x35, + 0x05, + 0x10, + 0xd2, + 0xa4, + 0x5c, + 0x83, + 0xd6, + 0x94, + 0x12, + 0x18, + 0xc5, + 0xb3, + 0x0f, + 0x0a, + 0xb1, + 0x8a, + 0x82, + 0x9f, + 0xd6, + 0xa9, + 0xab, + 0x40, + 0xc1, + 0x05, + 0xe8, + 0x1b, + 0x74, + 0xaa, + 0x8e, + 0xd6, + 0x8b, + 0xa5, + 0xa3, + 0x77, + 0x79, }; static const QUIC_PKT_HDR rx_script_8e_expect_hdr = { @@ -1729,10 +8773,42 @@ static const QUIC_PKT_HDR rx_script_8e_expect_hdr = { }; static const unsigned char rx_script_8e_body[] = { - 0x02, 0x09, 0x04, 0x00, 0x00, 0x0c, 0x00, 0x40, 0xbd, 0x49, - 0x27, 0x6d, 0x20, 0x68, 0x61, 0x76, 0x69, 0x6e, 0x67, 0x20, - 0x61, 0x20, 0x77, 0x6f, 0x6e, 0x64, 0x65, 0x72, 0x66, 0x75, - 0x6c, 0x20, 0x74, 0x69, 0x6d, 0x65 + 0x02, + 0x09, + 0x04, + 0x00, + 0x00, + 0x0c, + 0x00, + 0x40, + 0xbd, + 0x49, + 0x27, + 0x6d, + 0x20, + 0x68, + 0x61, + 0x76, + 0x69, + 0x6e, + 0x67, + 0x20, + 0x61, + 0x20, + 0x77, + 0x6f, + 0x6e, + 0x64, + 0x65, + 0x72, + 0x66, + 0x75, + 0x6c, + 0x20, + 0x74, + 0x69, + 0x6d, + 0x65, }; static const unsigned char rx_script_8f_in[] = { @@ -1764,115 +8840,118 @@ static const unsigned char rx_script_8f_body[] = { }; static const struct rx_test_op rx_script_8[] = { - RX_OP_ALLOW_1RTT(), - RX_OP_SET_RX_DCID(empty_conn_id), + RX_OP_ALLOW_1RTT() + RX_OP_SET_RX_DCID(empty_conn_id) /* Inject before we get the keys */ - RX_OP_INJECT_N(8a), + RX_OP_INJECT_N(8a) /* Nothing yet */ - RX_OP_CHECK_NO_PKT(), + RX_OP_CHECK_NO_PKT() /* Provide keys */ - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, rx_script_8_1rtt_secret), + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, + QRL_SUITE_AES128GCM, rx_script_8_1rtt_secret) /* Now the injected packet is successfully returned */ - RX_OP_CHECK_PKT_N(8a), - RX_OP_CHECK_NO_PKT(), - RX_OP_CHECK_KEY_EPOCH(0), - RX_OP_CHECK_PKT_EPOCH(0), + RX_OP_CHECK_PKT_N(8a) + RX_OP_CHECK_NO_PKT() + RX_OP_CHECK_KEY_EPOCH(0) + RX_OP_CHECK_PKT_EPOCH(0) /* Packet with new key phase */ - RX_OP_INJECT_N(8b), + RX_OP_INJECT_N(8b) /* Packet is successfully decrypted and returned */ - RX_OP_CHECK_PKT_N(8b), - RX_OP_CHECK_NO_PKT(), + RX_OP_CHECK_PKT_N(8b) + RX_OP_CHECK_NO_PKT() /* Key epoch has increased */ - RX_OP_CHECK_KEY_EPOCH(1), - RX_OP_CHECK_PKT_EPOCH(1), + RX_OP_CHECK_KEY_EPOCH(1) + RX_OP_CHECK_PKT_EPOCH(1) /* * Now inject an old packet with the old keys (perhaps reordered in * network). */ - RX_OP_INJECT_N(8c), + RX_OP_INJECT_N(8c) /* Should still be decrypted OK */ - RX_OP_CHECK_PKT_N(8c), - RX_OP_CHECK_NO_PKT(), + RX_OP_CHECK_PKT_N(8c) + RX_OP_CHECK_NO_PKT() /* Epoch has not changed */ - RX_OP_CHECK_KEY_EPOCH(1), - RX_OP_CHECK_PKT_EPOCH(0), + RX_OP_CHECK_KEY_EPOCH(1) + RX_OP_CHECK_PKT_EPOCH(0) /* Another packet with the new keys. */ - RX_OP_INJECT_N(8d), - RX_OP_CHECK_PKT_N(8d), - RX_OP_CHECK_NO_PKT(), - RX_OP_CHECK_KEY_EPOCH(1), - RX_OP_CHECK_PKT_EPOCH(1), + RX_OP_INJECT_N(8d) + RX_OP_CHECK_PKT_N(8d) + RX_OP_CHECK_NO_PKT() + RX_OP_CHECK_KEY_EPOCH(1) + RX_OP_CHECK_PKT_EPOCH(1) /* We can inject the old packet multiple times and it still works */ - RX_OP_INJECT_N(8c), - RX_OP_CHECK_PKT_N(8c), - RX_OP_CHECK_NO_PKT(), - RX_OP_CHECK_KEY_EPOCH(1), - RX_OP_CHECK_PKT_EPOCH(0), + RX_OP_INJECT_N(8c) + RX_OP_CHECK_PKT_N(8c) + RX_OP_CHECK_NO_PKT() + RX_OP_CHECK_KEY_EPOCH(1) + RX_OP_CHECK_PKT_EPOCH(0) /* Until we move from UPDATING to COOLDOWN */ - RX_OP_KEY_UPDATE_TIMEOUT(0), - RX_OP_INJECT_N(8c), - RX_OP_CHECK_NO_PKT(), - RX_OP_CHECK_KEY_EPOCH(1), + RX_OP_KEY_UPDATE_TIMEOUT(0) + RX_OP_INJECT_N(8c) + RX_OP_CHECK_NO_PKT() + RX_OP_CHECK_KEY_EPOCH(1) /* * Injecting a packet from the next epoch (epoch 2) while in COOLDOWN * doesn't work */ - RX_OP_INJECT_N(8e), - RX_OP_CHECK_NO_PKT(), - RX_OP_CHECK_KEY_EPOCH(1), + RX_OP_INJECT_N(8e) + RX_OP_CHECK_NO_PKT() + RX_OP_CHECK_KEY_EPOCH(1) /* Move from COOLDOWN to NORMAL and try again */ - RX_OP_KEY_UPDATE_TIMEOUT(1), - RX_OP_INJECT_N(8e), - RX_OP_CHECK_PKT_N(8e), - RX_OP_CHECK_NO_PKT(), - RX_OP_CHECK_KEY_EPOCH(2), - RX_OP_CHECK_PKT_EPOCH(2), + RX_OP_KEY_UPDATE_TIMEOUT(1) + RX_OP_INJECT_N(8e) + RX_OP_CHECK_PKT_N(8e) + RX_OP_CHECK_NO_PKT() + RX_OP_CHECK_KEY_EPOCH(2) + RX_OP_CHECK_PKT_EPOCH(2) /* Can still receive old packet */ - RX_OP_INJECT_N(8d), - RX_OP_CHECK_PKT_N(8d), - RX_OP_CHECK_NO_PKT(), - RX_OP_CHECK_KEY_EPOCH(2), - RX_OP_CHECK_PKT_EPOCH(1), + RX_OP_INJECT_N(8d) + RX_OP_CHECK_PKT_N(8d) + RX_OP_CHECK_NO_PKT() + RX_OP_CHECK_KEY_EPOCH(2) + RX_OP_CHECK_PKT_EPOCH(1) /* Move straight from UPDATING to NORMAL */ - RX_OP_KEY_UPDATE_TIMEOUT(1), + RX_OP_KEY_UPDATE_TIMEOUT(1) /* Try a packet from epoch 3 */ - RX_OP_INJECT_N(8f), - RX_OP_CHECK_PKT_N(8f), - RX_OP_CHECK_NO_PKT(), - RX_OP_CHECK_KEY_EPOCH(3), - RX_OP_CHECK_PKT_EPOCH(3), + RX_OP_INJECT_N(8f) + RX_OP_CHECK_PKT_N(8f) + RX_OP_CHECK_NO_PKT() + RX_OP_CHECK_KEY_EPOCH(3) + RX_OP_CHECK_PKT_EPOCH(3) - RX_OP_END + RX_OP_END }; /* 9. 1-RTT Deferral Test */ static const struct rx_test_op rx_script_9[] = { - RX_OP_SET_RX_DCID(empty_conn_id), - RX_OP_PROVIDE_SECRET_INITIAL(rx_script_5_c2s_init_dcid), - RX_OP_INJECT_N(5), + RX_OP_SET_RX_DCID(empty_conn_id) + RX_OP_PROVIDE_SECRET_INITIAL(rx_script_5_c2s_init_dcid) + RX_OP_INJECT_N(5) - RX_OP_CHECK_PKT_N(5a), - RX_OP_CHECK_NO_PKT(), /* not got secret for next packet yet */ - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, QRL_SUITE_AES128GCM, rx_script_5_handshake_secret), - RX_OP_CHECK_PKT_N(5b), - RX_OP_CHECK_NO_PKT(), /* not got secret for next packet yet */ - RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, rx_script_5_1rtt_secret), - RX_OP_CHECK_NO_PKT(), /* still nothing - 1-RTT not enabled */ - RX_OP_ALLOW_1RTT(), - RX_OP_CHECK_PKT_N(5c), /* now we get the 1-RTT packet */ - RX_OP_CHECK_NO_PKT(), + RX_OP_CHECK_PKT_N(5a) + RX_OP_CHECK_NO_PKT() /* not got secret for next packet yet */ + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, + QRL_SUITE_AES128GCM, rx_script_5_handshake_secret) + RX_OP_CHECK_PKT_N(5b) + RX_OP_CHECK_NO_PKT() /* not got secret for next packet yet */ + RX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, + QRL_SUITE_AES128GCM, rx_script_5_1rtt_secret) + RX_OP_CHECK_NO_PKT() /* still nothing - 1-RTT not enabled */ + RX_OP_ALLOW_1RTT() + RX_OP_CHECK_PKT_N(5c) /* now we get the 1-RTT packet */ + RX_OP_CHECK_NO_PKT() - RX_OP_END + RX_OP_END }; static const struct rx_test_op *rx_scripts[] = { @@ -3194,24 +10273,24 @@ struct tx_test_op { #define TX_OP_END \ { TX_TEST_OP_END } #define TX_OP_WRITE(pkt) \ - { TX_TEST_OP_WRITE, NULL, 0, &(pkt), 0, 0, NULL } + { TX_TEST_OP_WRITE, NULL, 0, &(pkt), 0, 0, NULL }, #define TX_OP_PROVIDE_SECRET(el, suite, key) \ { \ TX_TEST_OP_PROVIDE_SECRET, (key), sizeof(key), \ NULL, (el), (suite), NULL \ - } + }, #define TX_OP_PROVIDE_SECRET_INITIAL(dcid, is_server) \ { TX_TEST_OP_PROVIDE_SECRET_INITIAL, \ - NULL, 0, NULL, 0, (is_server), &(dcid) } + NULL, 0, NULL, 0, (is_server), &(dcid) }, #define TX_OP_DISCARD_EL(el) \ - { TX_TEST_OP_DISCARD_EL, NULL, 0, NULL, (el), 0, NULL } + { TX_TEST_OP_DISCARD_EL, NULL, 0, NULL, (el), 0, NULL }, #define TX_OP_CHECK_DGRAM(expect_dgram) \ { \ TX_TEST_OP_CHECK_DGRAM, (expect_dgram), sizeof(expect_dgram), \ NULL, 0, 0, NULL \ - } + }, #define TX_OP_CHECK_NO_DGRAM() \ - { TX_TEST_OP_CHECK_NO_PKT, NULL, 0, NULL, 0, 0, NULL } + { TX_TEST_OP_CHECK_NO_PKT, NULL, 0, NULL, 0, 0, NULL }, #define TX_OP_WRITE_N(n) \ TX_OP_WRITE(tx_script_##n##_pkt) @@ -3219,10 +10298,11 @@ struct tx_test_op { TX_OP_CHECK_DGRAM(tx_script_##n##_dgram) #define TX_OP_WRITE_CHECK(n) \ - TX_OP_WRITE_N(n), TX_OP_CHECK_DGRAM_N(n) + TX_OP_WRITE_N(n) \ + TX_OP_CHECK_DGRAM_N(n) #define TX_OP_KEY_UPDATE() \ - { TX_TEST_OP_KEY_UPDATE, NULL, 0, NULL, 0, 0, NULL } + { TX_TEST_OP_KEY_UPDATE, NULL, 0, NULL, 0, 0, NULL }, /* 1. RFC 9001 - A.2 Client Initial */ static const unsigned char tx_script_1_body[1162] = { @@ -3383,9 +10463,9 @@ static const OSSL_QTX_PKT tx_script_1_pkt = { }; static const struct tx_test_op tx_script_1[] = { - TX_OP_PROVIDE_SECRET_INITIAL(tx_script_1_hdr.dst_conn_id, 0), - TX_OP_WRITE_CHECK(1), - TX_OP_END + TX_OP_PROVIDE_SECRET_INITIAL(tx_script_1_hdr.dst_conn_id, 0) + TX_OP_WRITE_CHECK(1) + TX_OP_END }; /* 2. RFC 9001 - A.3 Server Initial */ @@ -3448,9 +10528,9 @@ static const OSSL_QTX_PKT tx_script_2_pkt = { }; static const struct tx_test_op tx_script_2[] = { - TX_OP_PROVIDE_SECRET_INITIAL(tx_script_1_hdr.dst_conn_id, 1), - TX_OP_WRITE_CHECK(2), - TX_OP_END + TX_OP_PROVIDE_SECRET_INITIAL(tx_script_1_hdr.dst_conn_id, 1) + TX_OP_WRITE_CHECK(2) + TX_OP_END }; #if !defined(OPENSSL_NO_CHACHA) && !defined(OPENSSL_NO_POLY1305) @@ -3500,9 +10580,9 @@ static const OSSL_QTX_PKT tx_script_3_pkt = { }; static const struct tx_test_op tx_script_3[] = { - TX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_CHACHA20POLY1305, tx_script_3_secret), - TX_OP_WRITE_CHECK(3), - TX_OP_END + TX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_CHACHA20POLY1305, tx_script_3_secret) + TX_OP_WRITE_CHECK(3) + TX_OP_END }; #endif /* !defined(OPENSSL_NO_CHACHA) && !defined(OPENSSL_NO_POLY1305) */ @@ -3514,10 +10594,41 @@ static const unsigned char tx_script_4_secret[] = { }; static const unsigned char tx_script_4a_body[] = { - 0x02, 0x03, 0x09, 0x00, 0x03, 0x0c, 0x00, 0x36, 0x49, 0x27, - 0x6d, 0x20, 0x68, 0x61, 0x76, 0x69, 0x6e, 0x67, 0x20, 0x61, - 0x20, 0x77, 0x6f, 0x6e, 0x64, 0x65, 0x72, 0x66, 0x75, 0x6c, - 0x20, 0x74, 0x69, 0x6d, 0x65 + 0x02, + 0x03, + 0x09, + 0x00, + 0x03, + 0x0c, + 0x00, + 0x36, + 0x49, + 0x27, + 0x6d, + 0x20, + 0x68, + 0x61, + 0x76, + 0x69, + 0x6e, + 0x67, + 0x20, + 0x61, + 0x20, + 0x77, + 0x6f, + 0x6e, + 0x64, + 0x65, + 0x72, + 0x66, + 0x75, + 0x6c, + 0x20, + 0x74, + 0x69, + 0x6d, + 0x65, }; static const unsigned char tx_script_4a_dgram[] = { @@ -3559,19 +10670,104 @@ static const OSSL_QTX_PKT tx_script_4a_pkt = { }; static const unsigned char tx_script_4b_body[] = { - 0x02, 0x04, 0x07, 0x00, 0x00, 0x0c, 0x00, 0x40, 0x51, 0x49, - 0x27, 0x6d, 0x20, 0x68, 0x61, 0x76, 0x69, 0x6e, 0x67, 0x20, - 0x61, 0x20, 0x77, 0x6f, 0x6e, 0x64, 0x65, 0x72, 0x66, 0x75, - 0x6c, 0x20, 0x74, 0x69, 0x6d, 0x65 + 0x02, + 0x04, + 0x07, + 0x00, + 0x00, + 0x0c, + 0x00, + 0x40, + 0x51, + 0x49, + 0x27, + 0x6d, + 0x20, + 0x68, + 0x61, + 0x76, + 0x69, + 0x6e, + 0x67, + 0x20, + 0x61, + 0x20, + 0x77, + 0x6f, + 0x6e, + 0x64, + 0x65, + 0x72, + 0x66, + 0x75, + 0x6c, + 0x20, + 0x74, + 0x69, + 0x6d, + 0x65, }; static const unsigned char tx_script_4b_dgram[] = { - 0x58, 0x6e, 0x4e, 0xbd, 0x49, 0xa4, 0x43, 0x33, 0xea, 0x11, - 0x3a, 0x6c, 0xf5, 0x20, 0xef, 0x55, 0x8d, 0x25, 0xe2, 0x3b, - 0x0e, 0x8c, 0xea, 0x17, 0xfc, 0x2b, 0x7a, 0xab, 0xfa, 0x3d, - 0x07, 0xda, 0xa7, 0x7c, 0xc7, 0x47, 0x82, 0x02, 0x46, 0x40, - 0x4f, 0x01, 0xad, 0xb2, 0x9d, 0x97, 0xdb, 0xfc, 0x9c, 0x4b, - 0x46, 0xb1, 0x5a, 0x7f, 0x0b, 0x12, 0xaf, 0x49, 0xdf + 0x58, + 0x6e, + 0x4e, + 0xbd, + 0x49, + 0xa4, + 0x43, + 0x33, + 0xea, + 0x11, + 0x3a, + 0x6c, + 0xf5, + 0x20, + 0xef, + 0x55, + 0x8d, + 0x25, + 0xe2, + 0x3b, + 0x0e, + 0x8c, + 0xea, + 0x17, + 0xfc, + 0x2b, + 0x7a, + 0xab, + 0xfa, + 0x3d, + 0x07, + 0xda, + 0xa7, + 0x7c, + 0xc7, + 0x47, + 0x82, + 0x02, + 0x46, + 0x40, + 0x4f, + 0x01, + 0xad, + 0xb2, + 0x9d, + 0x97, + 0xdb, + 0xfc, + 0x9c, + 0x4b, + 0x46, + 0xb1, + 0x5a, + 0x7f, + 0x0b, + 0x12, + 0xaf, + 0x49, + 0xdf, }; static QUIC_PKT_HDR tx_script_4b_hdr = { @@ -3605,19 +10801,104 @@ static const OSSL_QTX_PKT tx_script_4b_pkt = { }; static const unsigned char tx_script_4c_body[] = { - 0x02, 0x09, 0x0e, 0x00, 0x00, 0x0c, 0x00, 0x40, 0xd8, 0x49, - 0x27, 0x6d, 0x20, 0x68, 0x61, 0x76, 0x69, 0x6e, 0x67, 0x20, - 0x61, 0x20, 0x77, 0x6f, 0x6e, 0x64, 0x65, 0x72, 0x66, 0x75, - 0x6c, 0x20, 0x74, 0x69, 0x6d, 0x65 + 0x02, + 0x09, + 0x0e, + 0x00, + 0x00, + 0x0c, + 0x00, + 0x40, + 0xd8, + 0x49, + 0x27, + 0x6d, + 0x20, + 0x68, + 0x61, + 0x76, + 0x69, + 0x6e, + 0x67, + 0x20, + 0x61, + 0x20, + 0x77, + 0x6f, + 0x6e, + 0x64, + 0x65, + 0x72, + 0x66, + 0x75, + 0x6c, + 0x20, + 0x74, + 0x69, + 0x6d, + 0x65, }; static const unsigned char tx_script_4c_dgram[] = { - 0x49, 0x6e, 0x4e, 0xbd, 0x49, 0x4d, 0xd9, 0x85, 0xba, 0x26, - 0xfb, 0x68, 0x83, 0x9b, 0x94, 0x34, 0x7d, 0xc1, 0x7a, 0x05, - 0xb7, 0x38, 0x43, 0x21, 0xe2, 0xec, 0x2b, 0xc1, 0x81, 0x74, - 0x2d, 0xda, 0x24, 0xba, 0xbd, 0x99, 0x69, 0xd2, 0x56, 0xfa, - 0xae, 0x29, 0x24, 0xb2, 0xaa, 0xda, 0xbd, 0x82, 0x80, 0xf1, - 0xbb, 0x6a, 0xfd, 0xae, 0xda, 0x0e, 0x09, 0xcf, 0x09 + 0x49, + 0x6e, + 0x4e, + 0xbd, + 0x49, + 0x4d, + 0xd9, + 0x85, + 0xba, + 0x26, + 0xfb, + 0x68, + 0x83, + 0x9b, + 0x94, + 0x34, + 0x7d, + 0xc1, + 0x7a, + 0x05, + 0xb7, + 0x38, + 0x43, + 0x21, + 0xe2, + 0xec, + 0x2b, + 0xc1, + 0x81, + 0x74, + 0x2d, + 0xda, + 0x24, + 0xba, + 0xbd, + 0x99, + 0x69, + 0xd2, + 0x56, + 0xfa, + 0xae, + 0x29, + 0x24, + 0xb2, + 0xaa, + 0xda, + 0xbd, + 0x82, + 0x80, + 0xf1, + 0xbb, + 0x6a, + 0xfd, + 0xae, + 0xda, + 0x0e, + 0x09, + 0xcf, + 0x09, }; static QUIC_PKT_HDR tx_script_4c_hdr = { @@ -3651,47 +10932,265 @@ static const OSSL_QTX_PKT tx_script_4c_pkt = { }; static const struct tx_test_op tx_script_4[] = { - TX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, tx_script_4_secret), - TX_OP_WRITE_CHECK(4a), - TX_OP_KEY_UPDATE(), - TX_OP_WRITE_CHECK(4b), - TX_OP_KEY_UPDATE(), - TX_OP_WRITE_CHECK(4c), - TX_OP_END + TX_OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, tx_script_4_secret) + TX_OP_WRITE_CHECK(4a) + TX_OP_KEY_UPDATE() + TX_OP_WRITE_CHECK(4b) + TX_OP_KEY_UPDATE() + TX_OP_WRITE_CHECK(4c) + TX_OP_END }; /* 5. Real World - Retry Packet */ static const unsigned char tx_script_5_body[] = { /* Retry Token */ - 0x92, 0xe7, 0xc6, 0xd8, 0x09, 0x65, 0x72, 0x55, 0xe5, 0xe2, - 0x73, 0x04, 0xf3, 0x07, 0x5b, 0x21, 0x9f, 0x50, 0xcb, 0xbc, - 0x79, 0xc5, 0x77, 0x5a, 0x29, 0x43, 0x65, 0x49, 0xf0, 0x6e, - 0xc1, 0xc0, 0x3a, 0xe8, 0xca, 0xd2, 0x44, 0x69, 0xdd, 0x23, - 0x31, 0x93, 0x52, 0x02, 0xf7, 0x42, 0x07, 0x78, 0xa1, 0x81, - 0x61, 0x9c, 0x39, 0x07, 0x18, 0x69, 0x6e, 0x4f, 0xdc, 0xa0, - 0xbe, 0x4b, 0xe5, 0xf2, 0xe9, 0xd2, 0xa4, 0xa7, 0x34, 0x55, - 0x5e, 0xf3, 0xf8, 0x9c, 0x49, 0x8f, 0x0c, 0xc8, 0xb2, 0x75, - 0x4b, 0x4d, 0x2f, 0xfe, 0x05, 0x5a, 0xdd, 0x4b, 0xe6, 0x14, - 0xb4, 0xd2, 0xc0, 0x93, 0x6e, 0x0e, 0x84, 0x41, 0x4d, 0x31, + 0x92, + 0xe7, + 0xc6, + 0xd8, + 0x09, + 0x65, + 0x72, + 0x55, + 0xe5, + 0xe2, + 0x73, + 0x04, + 0xf3, + 0x07, + 0x5b, + 0x21, + 0x9f, + 0x50, + 0xcb, + 0xbc, + 0x79, + 0xc5, + 0x77, + 0x5a, + 0x29, + 0x43, + 0x65, + 0x49, + 0xf0, + 0x6e, + 0xc1, + 0xc0, + 0x3a, + 0xe8, + 0xca, + 0xd2, + 0x44, + 0x69, + 0xdd, + 0x23, + 0x31, + 0x93, + 0x52, + 0x02, + 0xf7, + 0x42, + 0x07, + 0x78, + 0xa1, + 0x81, + 0x61, + 0x9c, + 0x39, + 0x07, + 0x18, + 0x69, + 0x6e, + 0x4f, + 0xdc, + 0xa0, + 0xbe, + 0x4b, + 0xe5, + 0xf2, + 0xe9, + 0xd2, + 0xa4, + 0xa7, + 0x34, + 0x55, + 0x5e, + 0xf3, + 0xf8, + 0x9c, + 0x49, + 0x8f, + 0x0c, + 0xc8, + 0xb2, + 0x75, + 0x4b, + 0x4d, + 0x2f, + 0xfe, + 0x05, + 0x5a, + 0xdd, + 0x4b, + 0xe6, + 0x14, + 0xb4, + 0xd2, + 0xc0, + 0x93, + 0x6e, + 0x0e, + 0x84, + 0x41, + 0x4d, + 0x31, /* Retry Integrity Tag */ - 0x43, 0x8e, 0xab, 0xcd, 0xce, 0x24, 0x44, 0xc2, 0x20, 0xe1, - 0xe2, 0xc8, 0xae, 0xa3, 0x8d, 0x4e + 0x43, + 0x8e, + 0xab, + 0xcd, + 0xce, + 0x24, + 0x44, + 0xc2, + 0x20, + 0xe1, + 0xe2, + 0xc8, + 0xae, + 0xa3, + 0x8d, + 0x4e, }; static const unsigned char tx_script_5_dgram[] = { - 0xf0, 0x00, 0x00, 0x00, 0x01, 0x00, 0x04, 0xa9, 0x20, 0xcc, - 0xc2, 0x92, 0xe7, 0xc6, 0xd8, 0x09, 0x65, 0x72, 0x55, 0xe5, - 0xe2, 0x73, 0x04, 0xf3, 0x07, 0x5b, 0x21, 0x9f, 0x50, 0xcb, - 0xbc, 0x79, 0xc5, 0x77, 0x5a, 0x29, 0x43, 0x65, 0x49, 0xf0, - 0x6e, 0xc1, 0xc0, 0x3a, 0xe8, 0xca, 0xd2, 0x44, 0x69, 0xdd, - 0x23, 0x31, 0x93, 0x52, 0x02, 0xf7, 0x42, 0x07, 0x78, 0xa1, - 0x81, 0x61, 0x9c, 0x39, 0x07, 0x18, 0x69, 0x6e, 0x4f, 0xdc, - 0xa0, 0xbe, 0x4b, 0xe5, 0xf2, 0xe9, 0xd2, 0xa4, 0xa7, 0x34, - 0x55, 0x5e, 0xf3, 0xf8, 0x9c, 0x49, 0x8f, 0x0c, 0xc8, 0xb2, - 0x75, 0x4b, 0x4d, 0x2f, 0xfe, 0x05, 0x5a, 0xdd, 0x4b, 0xe6, - 0x14, 0xb4, 0xd2, 0xc0, 0x93, 0x6e, 0x0e, 0x84, 0x41, 0x4d, - 0x31, 0x43, 0x8e, 0xab, 0xcd, 0xce, 0x24, 0x44, 0xc2, 0x20, - 0xe1, 0xe2, 0xc8, 0xae, 0xa3, 0x8d, 0x4e + 0xf0, + 0x00, + 0x00, + 0x00, + 0x01, + 0x00, + 0x04, + 0xa9, + 0x20, + 0xcc, + 0xc2, + 0x92, + 0xe7, + 0xc6, + 0xd8, + 0x09, + 0x65, + 0x72, + 0x55, + 0xe5, + 0xe2, + 0x73, + 0x04, + 0xf3, + 0x07, + 0x5b, + 0x21, + 0x9f, + 0x50, + 0xcb, + 0xbc, + 0x79, + 0xc5, + 0x77, + 0x5a, + 0x29, + 0x43, + 0x65, + 0x49, + 0xf0, + 0x6e, + 0xc1, + 0xc0, + 0x3a, + 0xe8, + 0xca, + 0xd2, + 0x44, + 0x69, + 0xdd, + 0x23, + 0x31, + 0x93, + 0x52, + 0x02, + 0xf7, + 0x42, + 0x07, + 0x78, + 0xa1, + 0x81, + 0x61, + 0x9c, + 0x39, + 0x07, + 0x18, + 0x69, + 0x6e, + 0x4f, + 0xdc, + 0xa0, + 0xbe, + 0x4b, + 0xe5, + 0xf2, + 0xe9, + 0xd2, + 0xa4, + 0xa7, + 0x34, + 0x55, + 0x5e, + 0xf3, + 0xf8, + 0x9c, + 0x49, + 0x8f, + 0x0c, + 0xc8, + 0xb2, + 0x75, + 0x4b, + 0x4d, + 0x2f, + 0xfe, + 0x05, + 0x5a, + 0xdd, + 0x4b, + 0xe6, + 0x14, + 0xb4, + 0xd2, + 0xc0, + 0x93, + 0x6e, + 0x0e, + 0x84, + 0x41, + 0x4d, + 0x31, + 0x43, + 0x8e, + 0xab, + 0xcd, + 0xce, + 0x24, + 0x44, + 0xc2, + 0x20, + 0xe1, + 0xe2, + 0xc8, + 0xae, + 0xa3, + 0x8d, + 0x4e, }; static QUIC_PKT_HDR tx_script_5_hdr = { @@ -3725,8 +11224,8 @@ static const OSSL_QTX_PKT tx_script_5_pkt = { }; static const struct tx_test_op tx_script_5[] = { - TX_OP_WRITE_CHECK(5), - TX_OP_END + TX_OP_WRITE_CHECK(5) + TX_OP_END }; /* 6. Real World - Version Negotiation Packet */ @@ -3777,8 +11276,8 @@ static const OSSL_QTX_PKT tx_script_6_pkt = { }; static const struct tx_test_op tx_script_6[] = { - TX_OP_WRITE_CHECK(6), - TX_OP_END + TX_OP_WRITE_CHECK(6) + TX_OP_END }; static const struct tx_test_op *const tx_scripts[] = { @@ -3883,37 +11382,6 @@ static int test_tx_script(int idx) return tx_run_script(tx_scripts[idx]); } -static int test_qrx_multipkt_alloc_failure(void) -{ - int testresult = 0; - struct rx_state s = { 0 }; - OSSL_QRX_PKT *pkt = NULL; - - s.args.short_conn_id_len = 0; - - if (!TEST_true(rx_state_ensure(&s))) - goto err; - - s.rx_dcid = empty_conn_id; - - if (!TEST_true(ossl_quic_provide_initial_secret(NULL, NULL, - &rx_script_5_c2s_init_dcid, 0, s.qrx, NULL))) - goto err; - - if (!TEST_true(ossl_quic_demux_inject(s.demux, rx_script_5_in, - sizeof(rx_script_5_in), NULL, NULL))) - goto err; - - MFAIL_start(); - testresult = ossl_qrx_read_pkt(s.qrx, &pkt); - MFAIL_end(); - -err: - ossl_qrx_pkt_release(pkt); - rx_state_teardown(&s); - return testresult; -} - int setup_tests(void) { ADD_ALL_TESTS(test_rx_script, OSSL_NELEM(rx_scripts)); @@ -3928,6 +11396,5 @@ int setup_tests(void) */ ADD_ALL_TESTS(test_wire_pkt_hdr, NUM_WIRE_PKT_HDR_TESTS + 1); ADD_ALL_TESTS(test_tx_script, OSSL_NELEM(tx_scripts)); - ADD_MFAIL_NO_CHECK_TEST(test_qrx_multipkt_alloc_failure); return 1; } diff --git a/test/quic_srt_gen_test.c b/test/quic_srt_gen_test.c index cfcee4a953..fcbf4aea22 100644 --- a/test/quic_srt_gen_test.c +++ b/test/quic_srt_gen_test.c @@ -70,26 +70,8 @@ err: return testresult; } -static int test_srt_gen_new_mfail(int idx) -{ - const struct test_case *t = &tests[idx]; - QUIC_SRT_GEN *srt_gen = NULL; - - MFAIL_start(); - srt_gen = ossl_quic_srt_gen_new(NULL, NULL, t->key, t->key_len); - MFAIL_end(); - - if (srt_gen == NULL) { - return 0; - } - - ossl_quic_srt_gen_free(srt_gen); - return 1; -} - int setup_tests(void) { ADD_ALL_TESTS(test_srt_gen, OSSL_NELEM(tests)); - ADD_MFAIL_ALL_TESTS(test_srt_gen_new_mfail, OSSL_NELEM(tests)); return 1; } diff --git a/test/quic_srtm_test.c b/test/quic_srtm_test.c index 7838d46a77..cbdf847632 100644 --- a/test/quic_srtm_test.c +++ b/test/quic_srtm_test.c @@ -22,17 +22,14 @@ static int test_srtm(void) QUIC_SRTM *srtm; void *opaque = NULL; uint64_t seq_num = 0; - uint8_t match; if (!TEST_ptr(srtm = ossl_quic_srtm_new(NULL, NULL))) goto err; if (!TEST_true(ossl_quic_srtm_add(srtm, ptrs + 0, 0, &token_1)) || !TEST_false(ossl_quic_srtm_add(srtm, ptrs + 0, 0, &token_1)) - || !TEST_true(ossl_quic_srtm_remove(srtm, ptrs + 0, 1, &match)) - || !TEST_uint_eq(match, 0) - || !TEST_true(ossl_quic_srtm_remove(srtm, ptrs + 3, 0, &match)) - || !TEST_uint_eq(match, 0) + || !TEST_false(ossl_quic_srtm_remove(srtm, ptrs + 0, 1)) + || !TEST_false(ossl_quic_srtm_remove(srtm, ptrs + 3, 0)) || !TEST_true(ossl_quic_srtm_cull(srtm, ptrs + 3)) || !TEST_true(ossl_quic_srtm_cull(srtm, ptrs + 3)) || !TEST_true(ossl_quic_srtm_add(srtm, ptrs + 0, 1, &token_1)) @@ -41,8 +38,7 @@ static int test_srtm(void) || !TEST_true(ossl_quic_srtm_add(srtm, ptrs + 1, 0, &token_1)) || !TEST_true(ossl_quic_srtm_add(srtm, ptrs + 2, 0, &token_2)) || !TEST_true(ossl_quic_srtm_add(srtm, ptrs + 3, 3, &token_2)) - || !TEST_true(ossl_quic_srtm_remove(srtm, ptrs + 3, 3, &match)) - || !TEST_uint_eq(match, 1) + || !TEST_true(ossl_quic_srtm_remove(srtm, ptrs + 3, 3)) || !TEST_true(ossl_quic_srtm_lookup(srtm, &token_1, 0, &opaque, &seq_num)) || !TEST_ptr_eq(opaque, ptrs + 1) || !TEST_uint64_t_eq(seq_num, 0) @@ -66,8 +62,7 @@ static int test_srtm(void) || !TEST_true(ossl_quic_srtm_lookup(srtm, &token_2, 0, &opaque, &seq_num)) || !TEST_ptr_eq(opaque, ptrs + 2) || !TEST_uint64_t_eq(seq_num, 0) - || !TEST_true(ossl_quic_srtm_remove(srtm, ptrs + 2, 0, &match)) - || !TEST_uint_eq(match, 1) + || !TEST_true(ossl_quic_srtm_remove(srtm, ptrs + 2, 0)) || !TEST_false(ossl_quic_srtm_lookup(srtm, &token_2, 0, &opaque, &seq_num))) goto err; @@ -77,54 +72,8 @@ err: return testresult; } -static int test_srtm_new_mfail(void) -{ - QUIC_SRTM *srtm; - - MFAIL_start(); - srtm = ossl_quic_srtm_new(NULL, NULL); - MFAIL_end(); - - ossl_quic_srtm_free(srtm); - return srtm != NULL; -} - -static int test_srtm_ops_mfail(void) -{ - int testresult = 0; - QUIC_SRTM *srtm; - void *opaque = NULL; - uint64_t seq_num = 0; - - if (!TEST_ptr(srtm = ossl_quic_srtm_new(NULL, NULL))) - goto err; - - MFAIL_start(); - - if (!ossl_quic_srtm_add(srtm, ptrs + 0, 0, &token_1) - || !ossl_quic_srtm_add(srtm, ptrs + 0, 1, &token_1) - || !ossl_quic_srtm_add(srtm, ptrs + 0, 2, &token_1) - || !ossl_quic_srtm_add(srtm, ptrs + 1, 0, &token_1) - || !ossl_quic_srtm_add(srtm, ptrs + 2, 0, &token_2) - || !ossl_quic_srtm_add(srtm, ptrs + 3, 3, &token_2) - || !ossl_quic_srtm_remove(srtm, ptrs + 3, 3, NULL) - || !ossl_quic_srtm_lookup(srtm, &token_1, 0, &opaque, &seq_num) - || !ossl_quic_srtm_cull(srtm, ptrs + 0) - || !ossl_quic_srtm_lookup(srtm, &token_2, 0, &opaque, &seq_num) - || !ossl_quic_srtm_remove(srtm, ptrs + 2, 0, NULL)) - goto err; - - testresult = 1; -err: - MFAIL_end(); - ossl_quic_srtm_free(srtm); - return testresult; -} - int setup_tests(void) { ADD_TEST(test_srtm); - ADD_MFAIL_TEST(test_srtm_new_mfail); - ADD_MFAIL_TEST(test_srtm_ops_mfail); return 1; } diff --git a/test/quic_tserver_test.c b/test/quic_tserver_test.c index b4e81f427f..0ef79035d2 100644 --- a/test/quic_tserver_test.c +++ b/test/quic_tserver_test.c @@ -331,38 +331,16 @@ static int do_test(int use_thread_assist, int use_fake_time, int use_inject) CRYPTO_THREAD_unlock(fake_time_lock); ++idle_units_done; + ossl_quic_conn_force_assist_thread_wake(c_ssl); /* - * The assist thread alone keeps the idle connection alive. It - * waits on real time internally, so advancing fake time can - * outrun it. Rather than race it, wait until it has caught up: - * the event timeout is computed against fake time, so once the - * next deadline is back in the future all events due up to now - * - including any keepalive - have been serviced. + * If the event timeout has expired then give the assistance + * thread a chance to catch up */ - for (;;) { - ossl_quic_conn_force_assist_thread_wake(c_ssl); - - if (!TEST_true(SSL_get_event_timeout(c_ssl, &tv, &isinf))) - goto err; - - if (isinf - || ossl_time_compare(ossl_time_from_timeval(tv), - ossl_time_zero()) - > 0) - break; - - if (ossl_time_compare(ossl_time_subtract(real_now(NULL), - start_time), - ossl_ms2time(limit_ms)) - >= 0) { - TEST_error("timeout waiting for assist thread to send " - "keepalive during idle test"); - goto err; - } - - OSSL_sleep(1); /* Yield so the assist thread can run. */ - } + if (!TEST_true(SSL_get_event_timeout(c_ssl, &tv, &isinf))) + goto err; + if (!isinf && ossl_time_compare(ossl_time_zero(), ossl_time_from_timeval(tv)) >= 0) + OSSL_sleep(10); /* Ensure CPU scheduling for test purposes */ } else { c_done_idle_test = 1; } diff --git a/test/quic_txp_test.c b/test/quic_txp_test.c index b2a2d79e5e..5ce7ab5b34 100644 --- a/test/quic_txp_test.c +++ b/test/quic_txp_test.c @@ -28,8 +28,22 @@ static const QUIC_CONN_ID cid_1 = { }; static const unsigned char reset_token_1[16] = { - 0x99, 0x88, 0x77, 0x66, 0x55, 0x44, 0x33, 0x22, 0x11, 0xaa, - 0xbb, 0xcc, 0xdd, 0xee, 0xff, 0x12 + 0x99, + 0x88, + 0x77, + 0x66, + 0x55, + 0x44, + 0x33, + 0x22, + 0x11, + 0xaa, + 0xbb, + 0xcc, + 0xdd, + 0xee, + 0xff, + 0x12, }; static const unsigned char secret_1[32] = { @@ -286,51 +300,51 @@ struct script_op { #define OP_END \ { OPK_END } #define OP_TXP_GENERATE() \ - { OPK_TXP_GENERATE } + { OPK_TXP_GENERATE }, #define OP_TXP_GENERATE_NONE() \ - { OPK_TXP_GENERATE_NONE } + { OPK_TXP_GENERATE_NONE }, #define OP_RX_PKT() \ - { OPK_RX_PKT } + { OPK_RX_PKT }, #define OP_RX_PKT_NONE() \ - { OPK_RX_PKT_NONE } + { OPK_RX_PKT_NONE }, #define OP_EXPECT_DGRAM_LEN(lo, hi) \ - { OPK_EXPECT_DGRAM_LEN, (lo), (hi) } + { OPK_EXPECT_DGRAM_LEN, (lo), (hi) }, #define OP_EXPECT_FRAME(frame_type) \ - { OPK_EXPECT_FRAME, (frame_type) } + { OPK_EXPECT_FRAME, (frame_type) }, #define OP_EXPECT_INITIAL_TOKEN(buf) \ - { OPK_EXPECT_INITIAL_TOKEN, sizeof(buf), 0, buf } + { OPK_EXPECT_INITIAL_TOKEN, sizeof(buf), 0, buf }, #define OP_EXPECT_HDR(hdr) \ - { OPK_EXPECT_HDR, 0, 0, &(hdr) } + { OPK_EXPECT_HDR, 0, 0, &(hdr) }, #define OP_CHECK(func) \ - { OPK_CHECK, 0, 0, NULL, 0, (func) } + { OPK_CHECK, 0, 0, NULL, 0, (func) }, #define OP_NEXT_FRAME() \ - { OPK_NEXT_FRAME } + { OPK_NEXT_FRAME }, #define OP_EXPECT_NO_FRAME() \ - { OPK_EXPECT_NO_FRAME } + { OPK_EXPECT_NO_FRAME }, #define OP_PROVIDE_SECRET(el, suite, secret) \ - { OPK_PROVIDE_SECRET, (el), (suite), (secret), sizeof(secret) } + { OPK_PROVIDE_SECRET, (el), (suite), (secret), sizeof(secret) }, #define OP_DISCARD_EL(el) \ - { OPK_DISCARD_EL, (el) } + { OPK_DISCARD_EL, (el) }, #define OP_CRYPTO_SEND(pn_space, buf) \ - { OPK_CRYPTO_SEND, (pn_space), 0, (buf), sizeof(buf) } + { OPK_CRYPTO_SEND, (pn_space), 0, (buf), sizeof(buf) }, #define OP_STREAM_NEW(id) \ - { OPK_STREAM_NEW, (id) } + { OPK_STREAM_NEW, (id) }, #define OP_STREAM_SEND(id, buf) \ - { OPK_STREAM_SEND, (id), 0, (buf), sizeof(buf) } + { OPK_STREAM_SEND, (id), 0, (buf), sizeof(buf) }, #define OP_STREAM_FIN(id) \ - { OPK_STREAM_FIN, (id) } + { OPK_STREAM_FIN, (id) }, #define OP_STOP_SENDING(id, aec) \ - { OPK_STOP_SENDING, (id), (aec) } + { OPK_STOP_SENDING, (id), (aec) }, #define OP_RESET_STREAM(id, aec) \ - { OPK_RESET_STREAM, (id), (aec) } + { OPK_RESET_STREAM, (id), (aec) }, #define OP_CONN_TXFC_BUMP(cwm) \ - { OPK_CONN_TXFC_BUMP, (cwm) } + { OPK_CONN_TXFC_BUMP, (cwm) }, #define OP_STREAM_TXFC_BUMP(id, cwm) \ - { OPK_STREAM_TXFC_BUMP, (cwm), (id) } + { OPK_STREAM_TXFC_BUMP, (cwm), (id) }, #define OP_HANDSHAKE_COMPLETE() \ - { OPK_HANDSHAKE_COMPLETE } + { OPK_HANDSHAKE_COMPLETE }, #define OP_NOP() \ - { OPK_NOP } + { OPK_NOP }, static int schedule_handshake_done(struct helper *h) { @@ -346,37 +360,37 @@ static int schedule_ack_eliciting_app(struct helper *h) /* 1. 1-RTT, Single Handshake Done Frame */ static const struct script_op script_1[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1), - OP_TXP_GENERATE_NONE(), - OP_CHECK(schedule_handshake_done), - OP_TXP_GENERATE(), - OP_RX_PKT(), + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1) + OP_TXP_GENERATE_NONE() + OP_CHECK(schedule_handshake_done) + OP_TXP_GENERATE() + OP_RX_PKT() /* Should not be long */ - OP_EXPECT_DGRAM_LEN(21, 32), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_HANDSHAKE_DONE), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_EXPECT_DGRAM_LEN(21, 32) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_HANDSHAKE_DONE) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; /* 2. 1-RTT, Forced ACK-Eliciting Frame */ static const struct script_op script_2[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1), - OP_TXP_GENERATE_NONE(), - OP_CHECK(schedule_ack_eliciting_app), - OP_TXP_GENERATE(), - OP_RX_PKT(), + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1) + OP_TXP_GENERATE_NONE() + OP_CHECK(schedule_ack_eliciting_app) + OP_TXP_GENERATE() + OP_RX_PKT() /* Should not be long */ - OP_EXPECT_DGRAM_LEN(21, 32), + OP_EXPECT_DGRAM_LEN(21, 32) /* A PING frame should have been added */ - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_PING), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_PING) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; /* 3. 1-RTT, MAX_DATA */ @@ -395,20 +409,20 @@ static int schedule_max_data(struct helper *h) } static const struct script_op script_3[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1), - OP_TXP_GENERATE_NONE(), - OP_CHECK(schedule_max_data), - OP_TXP_GENERATE(), - OP_RX_PKT(), + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1) + OP_TXP_GENERATE_NONE() + OP_CHECK(schedule_max_data) + OP_TXP_GENERATE() + OP_RX_PKT() /* Should not be long */ - OP_EXPECT_DGRAM_LEN(21, 40), + OP_EXPECT_DGRAM_LEN(21, 40) /* A PING frame should have been added */ - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_MAX_DATA), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_MAX_DATA) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; /* 4. 1-RTT, CFQ (NEW_CONN_ID) */ @@ -478,19 +492,19 @@ static int check_cfq_new_conn_id(struct helper *h) } static const struct script_op script_4[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1), - OP_TXP_GENERATE_NONE(), - OP_CHECK(schedule_cfq_new_conn_id), - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(21, 128), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_NEW_CONN_ID), - OP_CHECK(check_cfq_new_conn_id), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1) + OP_TXP_GENERATE_NONE() + OP_CHECK(schedule_cfq_new_conn_id) + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(21, 128) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_NEW_CONN_ID) + OP_CHECK(check_cfq_new_conn_id) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; /* 5. 1-RTT, CFQ (NEW_TOKEN) */ @@ -550,19 +564,19 @@ static int check_cfq_new_token(struct helper *h) } static const struct script_op script_5[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1), - OP_TXP_GENERATE_NONE(), - OP_CHECK(schedule_cfq_new_token), - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(21, 512), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_NEW_TOKEN), - OP_CHECK(check_cfq_new_token), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1) + OP_TXP_GENERATE_NONE() + OP_CHECK(schedule_cfq_new_token) + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(21, 512) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_NEW_TOKEN) + OP_CHECK(check_cfq_new_token) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; /* 6. 1-RTT, ACK */ @@ -586,38 +600,38 @@ static int schedule_ack(struct helper *h) } static const struct script_op script_6[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1), - OP_TXP_GENERATE_NONE(), - OP_CHECK(schedule_ack), - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(21, 512), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_ACK_WITHOUT_ECN), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1) + OP_TXP_GENERATE_NONE() + OP_CHECK(schedule_ack) + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(21, 512) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_ACK_WITHOUT_ECN) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; /* 7. 1-RTT, ACK, NEW_TOKEN */ static const struct script_op script_7[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1), - OP_TXP_GENERATE_NONE(), - OP_CHECK(schedule_cfq_new_token), - OP_CHECK(schedule_ack), - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(21, 512), + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1) + OP_TXP_GENERATE_NONE() + OP_CHECK(schedule_cfq_new_token) + OP_CHECK(schedule_ack) + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(21, 512) /* ACK must come before NEW_TOKEN */ - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_ACK_WITHOUT_ECN), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_NEW_TOKEN), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_ACK_WITHOUT_ECN) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_NEW_TOKEN) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; /* 8. 1-RTT, CRYPTO */ @@ -626,18 +640,18 @@ static const unsigned char crypto_1[] = { }; static const struct script_op script_8[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1), - OP_TXP_GENERATE_NONE(), - OP_CRYPTO_SEND(QUIC_PN_SPACE_APP, crypto_1), - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(21, 512), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_CRYPTO), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1) + OP_TXP_GENERATE_NONE() + OP_CRYPTO_SEND(QUIC_PN_SPACE_APP, crypto_1) + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(21, 512) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_CRYPTO) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; /* 9. 1-RTT, STREAM */ @@ -655,26 +669,26 @@ static int check_stream_9(struct helper *h) } static const struct script_op script_9[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1), - OP_HANDSHAKE_COMPLETE(), - OP_TXP_GENERATE_NONE(), - OP_STREAM_NEW(42), - OP_STREAM_SEND(42, stream_9), + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1) + OP_HANDSHAKE_COMPLETE() + OP_TXP_GENERATE_NONE() + OP_STREAM_NEW(42) + OP_STREAM_SEND(42, stream_9) /* Still no output because of TXFC */ - OP_TXP_GENERATE_NONE(), + OP_TXP_GENERATE_NONE() /* Now grant a TXFC budget */ - OP_CONN_TXFC_BUMP(1000), - OP_STREAM_TXFC_BUMP(42, 1000), - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(21, 512), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_STREAM), - OP_CHECK(check_stream_9), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_CONN_TXFC_BUMP(1000) + OP_STREAM_TXFC_BUMP(42, 1000) + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(21, 512) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_STREAM) + OP_CHECK(check_stream_9) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; /* 10. 1-RTT, STREAM, round robin */ @@ -964,67 +978,67 @@ static int check_stream_10d(struct helper *h) } static const struct script_op script_10[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1), - OP_HANDSHAKE_COMPLETE(), - OP_TXP_GENERATE_NONE(), - OP_STREAM_NEW(42), - OP_STREAM_NEW(43), - OP_CONN_TXFC_BUMP(10000), - OP_STREAM_TXFC_BUMP(42, 5000), - OP_STREAM_TXFC_BUMP(43, 5000), - OP_STREAM_SEND(42, stream_10a), - OP_STREAM_SEND(43, stream_10b), + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1) + OP_HANDSHAKE_COMPLETE() + OP_TXP_GENERATE_NONE() + OP_STREAM_NEW(42) + OP_STREAM_NEW(43) + OP_CONN_TXFC_BUMP(10000) + OP_STREAM_TXFC_BUMP(42, 5000) + OP_STREAM_TXFC_BUMP(43, 5000) + OP_STREAM_SEND(42, stream_10a) + OP_STREAM_SEND(43, stream_10b) /* First packet containing data from stream 42 */ - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(1100, 1200), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_STREAM), - OP_CHECK(check_stream_10a), - OP_EXPECT_NO_FRAME(), + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(1100, 1200) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_STREAM) + OP_CHECK(check_stream_10a) + OP_EXPECT_NO_FRAME() /* Second packet containing data from stream 43 */ - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(1100, 1200), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_STREAM), - OP_CHECK(check_stream_10b), - OP_EXPECT_NO_FRAME(), + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(1100, 1200) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_STREAM) + OP_CHECK(check_stream_10b) + OP_EXPECT_NO_FRAME() /* Third packet containing data from stream 42 */ - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(200, 500), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_STREAM_OFF_LEN), - OP_CHECK(check_stream_10c), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_STREAM_OFF), - OP_CHECK(check_stream_10d), - OP_EXPECT_NO_FRAME(), + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(200, 500) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_STREAM_OFF_LEN) + OP_CHECK(check_stream_10c) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_STREAM_OFF) + OP_CHECK(check_stream_10d) + OP_EXPECT_NO_FRAME() - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() - OP_END + OP_END }; /* 11. Initial, CRYPTO */ static const struct script_op script_11[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_INITIAL, QRL_SUITE_AES128GCM, secret_1), - OP_TXP_GENERATE_NONE(), - OP_CRYPTO_SEND(QUIC_PN_SPACE_INITIAL, crypto_1), - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(1200, 1200), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_CRYPTO), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_INITIAL, QRL_SUITE_AES128GCM, secret_1) + OP_TXP_GENERATE_NONE() + OP_CRYPTO_SEND(QUIC_PN_SPACE_INITIAL, crypto_1) + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(1200, 1200) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_CRYPTO) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; /* 12. 1-RTT, STOP_SENDING */ @@ -1038,21 +1052,21 @@ static int check_stream_12(struct helper *h) } static const struct script_op script_12[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1), - OP_HANDSHAKE_COMPLETE(), - OP_TXP_GENERATE_NONE(), - OP_STREAM_NEW(42), - OP_STOP_SENDING(42, 4568), - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(21, 128), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_STOP_SENDING), - OP_CHECK(check_stream_12), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1) + OP_HANDSHAKE_COMPLETE() + OP_TXP_GENERATE_NONE() + OP_STREAM_NEW(42) + OP_STOP_SENDING(42, 4568) + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(21, 128) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_STOP_SENDING) + OP_CHECK(check_stream_12) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; /* 13. 1-RTT, RESET_STREAM */ @@ -1071,25 +1085,25 @@ static ossl_unused int check_stream_13(struct helper *h) } static const struct script_op script_13[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1), - OP_HANDSHAKE_COMPLETE(), - OP_TXP_GENERATE_NONE(), - OP_STREAM_NEW(42), - OP_CONN_TXFC_BUMP(8), - OP_STREAM_TXFC_BUMP(42, 8), - OP_STREAM_SEND(42, stream_13), - OP_RESET_STREAM(42, 4568), - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(21, 128), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_RESET_STREAM), - OP_CHECK(check_stream_13), - OP_NEXT_FRAME(), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1) + OP_HANDSHAKE_COMPLETE() + OP_TXP_GENERATE_NONE() + OP_STREAM_NEW(42) + OP_CONN_TXFC_BUMP(8) + OP_STREAM_TXFC_BUMP(42, 8) + OP_STREAM_SEND(42, stream_13) + OP_RESET_STREAM(42, 4568) + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(21, 128) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_RESET_STREAM) + OP_CHECK(check_stream_13) + OP_NEXT_FRAME() + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; /* 14. 1-RTT, CONNECTION_CLOSE */ @@ -1122,19 +1136,19 @@ static int check_14(struct helper *h) } static const struct script_op script_14[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1), - OP_HANDSHAKE_COMPLETE(), - OP_TXP_GENERATE_NONE(), - OP_CHECK(gen_conn_close), - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(21, 512), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_CONN_CLOSE_TRANSPORT), - OP_CHECK(check_14), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_END + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1) + OP_HANDSHAKE_COMPLETE() + OP_TXP_GENERATE_NONE() + OP_CHECK(gen_conn_close) + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(21, 512) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_CONN_CLOSE_TRANSPORT) + OP_CHECK(check_14) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_END }; /* 15. INITIAL, Anti-Deadlock Probe Simulation */ @@ -1151,18 +1165,18 @@ static int gen_probe_initial(struct helper *h) } static const struct script_op script_15[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_INITIAL, QRL_SUITE_AES128GCM, secret_1), - OP_TXP_GENERATE_NONE(), - OP_CHECK(gen_probe_initial), - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(1200, 1200), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_PING), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_INITIAL, QRL_SUITE_AES128GCM, secret_1) + OP_TXP_GENERATE_NONE() + OP_CHECK(gen_probe_initial) + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(1200, 1200) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_PING) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; /* 16. HANDSHAKE, Anti-Deadlock Probe Simulation */ @@ -1179,19 +1193,19 @@ static int gen_probe_handshake(struct helper *h) } static const struct script_op script_16[] = { - OP_DISCARD_EL(QUIC_ENC_LEVEL_INITIAL), - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, QRL_SUITE_AES128GCM, secret_1), - OP_TXP_GENERATE_NONE(), - OP_CHECK(gen_probe_handshake), - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(21, 512), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_PING), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_DISCARD_EL(QUIC_ENC_LEVEL_INITIAL) + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, QRL_SUITE_AES128GCM, secret_1) + OP_TXP_GENERATE_NONE() + OP_CHECK(gen_probe_handshake) + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(21, 512) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_PING) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; /* 17. 1-RTT, Probe Simulation */ @@ -1208,20 +1222,20 @@ static int gen_probe_1rtt(struct helper *h) } static const struct script_op script_17[] = { - OP_DISCARD_EL(QUIC_ENC_LEVEL_INITIAL), - OP_DISCARD_EL(QUIC_ENC_LEVEL_HANDSHAKE), - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1), - OP_TXP_GENERATE_NONE(), - OP_CHECK(gen_probe_1rtt), - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(21, 512), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_PING), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_DISCARD_EL(QUIC_ENC_LEVEL_INITIAL) + OP_DISCARD_EL(QUIC_ENC_LEVEL_HANDSHAKE) + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_1RTT, QRL_SUITE_AES128GCM, secret_1) + OP_TXP_GENERATE_NONE() + OP_CHECK(gen_probe_1rtt) + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(21, 512) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_PING) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; /* 18. Big Token Rejection */ @@ -1256,20 +1270,20 @@ static int try_big_token(struct helper *h) } static const struct script_op script_18[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_INITIAL, QRL_SUITE_AES128GCM, secret_1), - OP_TXP_GENERATE_NONE(), - OP_CHECK(try_big_token), - OP_TXP_GENERATE_NONE(), - OP_CRYPTO_SEND(QUIC_PN_SPACE_INITIAL, crypto_1), - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(1200, 1200), - OP_NEXT_FRAME(), - OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_CRYPTO), - OP_EXPECT_NO_FRAME(), - OP_RX_PKT_NONE(), - OP_TXP_GENERATE_NONE(), - OP_END + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_INITIAL, QRL_SUITE_AES128GCM, secret_1) + OP_TXP_GENERATE_NONE() + OP_CHECK(try_big_token) + OP_TXP_GENERATE_NONE() + OP_CRYPTO_SEND(QUIC_PN_SPACE_INITIAL, crypto_1) + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(1200, 1200) + OP_NEXT_FRAME() + OP_EXPECT_FRAME(OSSL_QUIC_FRAME_TYPE_CRYPTO) + OP_EXPECT_NO_FRAME() + OP_RX_PKT_NONE() + OP_TXP_GENERATE_NONE() + OP_END }; static const struct script_op *const scripts[] = { @@ -1652,17 +1666,17 @@ static int check_is_handshake(struct helper *h) } static struct script_op dyn_script_1[] = { - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_INITIAL, QRL_SUITE_AES128GCM, secret_1), - OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, QRL_SUITE_AES128GCM, secret_1), - OP_TXP_GENERATE_NONE(), - OP_CRYPTO_SEND(QUIC_PN_SPACE_INITIAL, dyn_script_1_crypto_1a), /* [crypto_idx] */ - OP_CRYPTO_SEND(QUIC_PN_SPACE_HANDSHAKE, dyn_script_1_crypto_1b), - OP_TXP_GENERATE(), - OP_RX_PKT(), - OP_EXPECT_DGRAM_LEN(1200, 1200), - OP_CHECK(check_is_initial), - OP_NOP(), /* [pkt_idx] */ - OP_NOP(), /* [check_idx] */ + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_INITIAL, QRL_SUITE_AES128GCM, secret_1) + OP_PROVIDE_SECRET(QUIC_ENC_LEVEL_HANDSHAKE, QRL_SUITE_AES128GCM, secret_1) + OP_TXP_GENERATE_NONE() + OP_CRYPTO_SEND(QUIC_PN_SPACE_INITIAL, dyn_script_1_crypto_1a) /* [crypto_idx] */ + OP_CRYPTO_SEND(QUIC_PN_SPACE_HANDSHAKE, dyn_script_1_crypto_1b) + OP_TXP_GENERATE() + OP_RX_PKT() + OP_EXPECT_DGRAM_LEN(1200, 1200) + OP_CHECK(check_is_initial) + OP_NOP() /* [pkt_idx] */ + OP_NOP() /* [check_idx] */ OP_END }; diff --git a/test/quic_wire_test.c b/test/quic_wire_test.c index 3e31fdb312..d46628d27f 100644 --- a/test/quic_wire_test.c +++ b/test/quic_wire_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -1246,33 +1246,33 @@ static const unsigned char encode_case_23_expect[] = { encode_case_##n##_expect, \ OSSL_NELEM(encode_case_##n##_expect), \ encode_case_##n##_dec \ - } + }, static const struct encode_test_case encode_cases[] = { - ENCODE_CASE(1), - ENCODE_CASE(2), - ENCODE_CASE(3), - ENCODE_CASE(4), - ENCODE_CASE(5), - ENCODE_CASE(6), - ENCODE_CASE(7), - ENCODE_CASE(8), - ENCODE_CASE(9), - ENCODE_CASE(10), - ENCODE_CASE(11), - ENCODE_CASE(12), - ENCODE_CASE(13), - ENCODE_CASE(14), - ENCODE_CASE(15), - ENCODE_CASE(16), - ENCODE_CASE(16b), - ENCODE_CASE(17), - ENCODE_CASE(18), - ENCODE_CASE(19), - ENCODE_CASE(20), - ENCODE_CASE(21), - ENCODE_CASE(22), - ENCODE_CASE(23), + ENCODE_CASE(1) + ENCODE_CASE(2) + ENCODE_CASE(3) + ENCODE_CASE(4) + ENCODE_CASE(5) + ENCODE_CASE(6) + ENCODE_CASE(7) + ENCODE_CASE(8) + ENCODE_CASE(9) + ENCODE_CASE(10) + ENCODE_CASE(11) + ENCODE_CASE(12) + ENCODE_CASE(13) + ENCODE_CASE(14) + ENCODE_CASE(15) + ENCODE_CASE(16) + ENCODE_CASE(16b) + ENCODE_CASE(17) + ENCODE_CASE(18) + ENCODE_CASE(19) + ENCODE_CASE(20) + ENCODE_CASE(21) + ENCODE_CASE(22) + ENCODE_CASE(23) }; static int test_wire_encode(int idx) @@ -1321,7 +1321,7 @@ static int test_wire_encode(int idx) * truncated encoding is passed as an argument to the deserializer to * help it determine whether decoding should fail or not. */ - if (!TEST_int_eq(PACKET_buf_init(&pkt2, c->expect_buf, i), 1)) + if (!TEST_int_eq(PACKET_buf_init(&pkt2, (unsigned char *)c->expect_buf, i), 1)) goto err; if (!TEST_int_eq(c->deserializer(&pkt2, i), 1)) @@ -1466,16 +1466,16 @@ static int ack_generic_decode(PACKET *pkt) sizeof(ack_case_##n##_input), \ (dec), \ (expect_fail) \ - } + }, static const struct ack_test_case ack_cases[] = { - ACK_CASE(1, 1, ack_generic_decode), - ACK_CASE(2, 0, ack_generic_decode), - ACK_CASE(3, 1, ack_generic_decode), - ACK_CASE(4, 0, ack_generic_decode), - ACK_CASE(5, 1, ack_generic_decode), - ACK_CASE(6, 1, ack_generic_decode), - ACK_CASE(7, 0, ack_generic_decode), + ACK_CASE(1, 1, ack_generic_decode) + ACK_CASE(2, 0, ack_generic_decode) + ACK_CASE(3, 1, ack_generic_decode) + ACK_CASE(4, 0, ack_generic_decode) + ACK_CASE(5, 1, ack_generic_decode) + ACK_CASE(6, 1, ack_generic_decode) + ACK_CASE(7, 0, ack_generic_decode) }; static int test_wire_ack(int idx) @@ -1485,7 +1485,7 @@ static int test_wire_ack(int idx) const struct ack_test_case *c = &ack_cases[idx]; if (!TEST_int_eq(PACKET_buf_init(&pkt, - c->input_buf, + (unsigned char *)c->input_buf, c->input_buf_len), 1)) goto err; @@ -1625,19 +1625,27 @@ err: /* is_minimal=0 test */ static const unsigned char non_minimal_1[] = { - 0x40, 0x00 + 0x40, + 0x00, }; static const unsigned char non_minimal_2[] = { - 0x40, 0x3F + 0x40, + 0x3F, }; static const unsigned char non_minimal_3[] = { - 0x80, 0x00, 0x00, 0x00 + 0x80, + 0x00, + 0x00, + 0x00, }; static const unsigned char non_minimal_4[] = { - 0x80, 0x00, 0x3F, 0xFF + 0x80, + 0x00, + 0x3F, + 0xFF, }; static const unsigned char non_minimal_5[] = { diff --git a/test/quicapitest.c b/test/quicapitest.c index a8de8f9670..26d80d1a4b 100644 --- a/test/quicapitest.c +++ b/test/quicapitest.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -19,12 +19,9 @@ #include "testutil.h" #include "testutil/output.h" #include "../ssl/ssl_local.h" -#include "../ssl/quic/quic_channel_local.h" #include "internal/quic_error.h" -#include "internal/quic_ssl.h" static OSSL_LIB_CTX *libctx = NULL; -static char *propq = NULL; static OSSL_PROVIDER *defctxnull = NULL; static char *certsdir = NULL; static char *cert = NULL; @@ -40,17 +37,13 @@ static BIO_ADDR *create_addr(struct in_addr *ina, short int port); static int bio_addr_bind(BIO *bio, BIO_ADDR *addr); static SSL *ql_create(SSL_CTX *ssl_ctx, BIO *bio); static SSL_CTX *create_server_ctx(void); -static SSL_CTX *create_client_ctx(void); -static int create_quic_ssl_objects(SSL_CTX *sctx, SSL_CTX *cctx, - SSL **lssl, SSL **cssl); static int qc_init(SSL *qconn, BIO_ADDR *dst_addr); /* The ssltrace test assumes some options are switched on/off */ -#if !defined(OPENSSL_NO_SSL_TRACE) \ - && defined(OPENSSL_NO_BROTLI) && defined(OPENSSL_NO_ZSTD) \ - && !defined(OPENSSL_NO_ECX) && !defined(OPENSSL_NO_DH) \ - && !defined(OPENSSL_NO_ML_DSA) && !defined(OPENSSL_NO_ML_KEM) \ - && !defined(OPENSSL_NO_SLH_DSA) && !defined(OPENSSL_NO_SM2) +#if !defined(OPENSSL_NO_SSL_TRACE) \ + && defined(OPENSSL_NO_BROTLI) && defined(OPENSSL_NO_ZSTD) \ + && !defined(OPENSSL_NO_ECX) && !defined(OPENSSL_NO_DH) \ + && !defined(OPENSSL_NO_ML_DSA) && !defined(OPENSSL_NO_ML_KEM) #define DO_SSL_TRACE_TEST #endif @@ -218,90 +211,6 @@ end: return ret; } -static int test_ssl_read_key_update_mfail(void) -{ - SSL_CTX *cctx = NULL, *sctx = NULL; - SSL *clientssl = NULL, *serverssl = NULL, *qlistener = NULL; - QUIC_CHANNEL *sch = NULL; - int ret = 0, i; - const char *msg = "ping"; - size_t msglen = strlen(msg); - size_t numbytes = 0; - unsigned char buf[64]; - - if (!TEST_ptr(sctx = create_server_ctx()) - || !TEST_ptr(cctx = create_client_ctx())) - goto err; - - if (!create_quic_ssl_objects(sctx, cctx, &qlistener, &clientssl)) - goto err; - - if (!TEST_true(SSL_set_tlsext_host_name(clientssl, "localhost"))) - goto err; - - /* Send ClientHello and server retry. */ - for (i = 0; i < 2; i++) { - ret = SSL_connect(clientssl); - if (!TEST_int_le(ret, 0) - || !TEST_int_eq(SSL_get_error(clientssl, ret), SSL_ERROR_WANT_READ)) - goto err; - SSL_handle_events(qlistener); - } - - serverssl = SSL_accept_connection(qlistener, 0); - if (!TEST_ptr(serverssl) - || !TEST_true(create_bare_ssl_connection(serverssl, clientssl, - SSL_ERROR_NONE, 0, 0))) - goto err; - - if (!TEST_ptr(sch = ossl_quic_conn_get_channel(serverssl))) - goto err; - - /* Open the default stream so the server has something to write back on. */ - if (!TEST_true(SSL_write_ex(clientssl, msg, msglen, &numbytes)) - || !TEST_size_t_eq(numbytes, msglen)) - goto err; - - /* Route the datagram to the server connection and let it consume it. */ - SSL_handle_events(qlistener); - SSL_handle_events(serverssl); - if (!TEST_true(SSL_read_ex(serverssl, buf, sizeof(buf), &numbytes))) - goto err; - - /* - * Force the server's TX side to rotate keys. Its next outgoing packet - * will carry the flipped Key Phase bit. When the client decrypts that - * packet, qrx_key_update_initiated -> rxku_detected -> ch_trigger_txku - * fires on the client. - */ - if (!TEST_true(ossl_qtx_trigger_key_update(sch->qtx))) - goto err; - - if (!TEST_true(SSL_write_ex(serverssl, msg, msglen, &numbytes)) - || !TEST_size_t_eq(numbytes, msglen)) - goto err; - - /* - * Process the inbound packet (carrying the new Key Phase) under mfail. - * SSL_read_ex ticks the client, reads the datagram off its BIO and - * decrypts it, which is where the key update handling runs. - */ - MFAIL_start(); - ret = SSL_read_ex(clientssl, buf, sizeof(buf), &numbytes); - MFAIL_end(); - - ret = (ret > 0); - -err: - SSL_free(serverssl); - SSL_free(clientssl); - SSL_free(qlistener); - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - - return ret; -} - /* * Test that sending FIN with no data to a client blocking in SSL_read_ex() will * wake up the client. @@ -1793,12 +1702,12 @@ static int test_bw_limit(void) sendlen > TEST_SINGLE_WRITE_SIZE ? TEST_SINGLE_WRITE_SIZE : sendlen, &written)) { - TEST_info("Retrying to send: %zu", sendlen); + TEST_info("Retrying to send: %llu", (unsigned long long)sendlen); if (!TEST_int_eq(SSL_get_error(clientquic, 0), SSL_ERROR_WANT_WRITE)) goto err; } else { sendlen -= written; - TEST_info("Remaining to send: %zu", sendlen); + TEST_info("Remaining to send: %llu", (unsigned long long)sendlen); } } else { SSL_handle_events(clientquic); @@ -1810,9 +1719,9 @@ static int test_bw_limit(void) &readbytes) && readbytes > 1) { recvlen -= readbytes; - TEST_info("Remaining to recv: %zu", recvlen); + TEST_info("Remaining to recv: %llu", (unsigned long long)recvlen); } else { - TEST_info("No progress on recv: %zu", recvlen); + TEST_info("No progress on recv: %llu", (unsigned long long)recvlen); } ossl_quic_tserver_tick(qtserv); } @@ -1846,38 +1755,36 @@ enum { TPARAM_OP_MUTATE }; -/* clang-format off */ #define TPARAM_CHECK_DUP(name, reason) \ - { QUIC_TPARAM_##name, TPARAM_OP_DUP, (reason) } + { QUIC_TPARAM_##name, TPARAM_OP_DUP, (reason) }, #define TPARAM_CHECK_DROP(name, reason) \ - { QUIC_TPARAM_##name, TPARAM_OP_DROP, (reason) } + { QUIC_TPARAM_##name, TPARAM_OP_DROP, (reason) }, #define TPARAM_CHECK_INJECT(name, buf, buf_len, reason) \ { QUIC_TPARAM_##name, TPARAM_OP_INJECT, (reason), \ - (buf), (buf_len) } + (buf), (buf_len) }, #define TPARAM_CHECK_INJECT_A(name, buf, reason) \ TPARAM_CHECK_INJECT(name, buf, sizeof(buf), reason) #define TPARAM_CHECK_DROP_INJECT(name, buf, buf_len, reason) \ { QUIC_TPARAM_##name, TPARAM_OP_DROP_INJECT, (reason), \ - (buf), (buf_len) } + (buf), (buf_len) }, #define TPARAM_CHECK_DROP_INJECT_A(name, buf, reason) \ TPARAM_CHECK_DROP_INJECT(name, buf, sizeof(buf), reason) #define TPARAM_CHECK_INJECT_TWICE(name, buf, buf_len, reason) \ { QUIC_TPARAM_##name, TPARAM_OP_INJECT_TWICE, (reason), \ - (buf), (buf_len) } + (buf), (buf_len) }, #define TPARAM_CHECK_INJECT_TWICE_A(name, buf, reason) \ TPARAM_CHECK_INJECT_TWICE(name, buf, sizeof(buf), reason) #define TPARAM_CHECK_INJECT_RAW(buf, buf_len, reason) \ { 0, TPARAM_OP_INJECT_RAW, (reason), \ - (buf), (buf_len) } + (buf), (buf_len) }, #define TPARAM_CHECK_INJECT_RAW_A(buf, reason) \ TPARAM_CHECK_INJECT_RAW(buf, sizeof(buf), reason) #define TPARAM_CHECK_MUTATE(name, reason) \ - { QUIC_TPARAM_##name, TPARAM_OP_MUTATE, (reason) } -#define TPARAM_CHECK_INT(name, reason) \ - TPARAM_CHECK_DROP_INJECT(name, NULL, 0, reason), \ - TPARAM_CHECK_DROP_INJECT_A(name, bogus_int, reason), \ + { QUIC_TPARAM_##name, TPARAM_OP_MUTATE, (reason) }, +#define TPARAM_CHECK_INT(name, reason) \ + TPARAM_CHECK_DROP_INJECT(name, NULL, 0, reason) \ + TPARAM_CHECK_DROP_INJECT_A(name, bogus_int, reason) \ TPARAM_CHECK_DROP_INJECT_A(name, int_with_trailer, reason) -/* clang-format on */ struct tparam_test { uint64_t id; @@ -1908,21 +1815,61 @@ static const unsigned char malformed_preferred_addr_1[] = { }; static const unsigned char malformed_preferred_addr_2[42] = { - 0x0d, 0x28 /* too short */ + 0x0d, + 0x28, /* too short */ }; static const unsigned char malformed_preferred_addr_3[64] = { - 0x0d, 0x3e /* too long */ + 0x0d, + 0x3e, /* too long */ }; static const unsigned char malformed_preferred_addr_4[] = { /* TPARAM too short for CID length indicated */ - 0x0d, 0x29, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x01, 0x55, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, - 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00 + 0x0d, + 0x29, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x01, + 0x55, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, }; static const unsigned char malformed_unknown_1[] = { @@ -1930,11 +1877,14 @@ static const unsigned char malformed_unknown_1[] = { }; static const unsigned char malformed_unknown_2[] = { - 0x55, 0x55 + 0x55, + 0x55, }; static const unsigned char malformed_unknown_3[] = { - 0x55, 0x55, 0x01 + 0x55, + 0x55, + 0x01, }; static const unsigned char ack_delay_exp[] = { @@ -1944,36 +1894,99 @@ static const unsigned char ack_delay_exp[] = { static const unsigned char stateless_reset_token[16] = { 0x42 }; static const unsigned char preferred_addr[] = { - 0x44, 0x44, 0x44, 0x44, - 0x55, 0x55, - 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, - 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, 0x66, - 0x77, 0x77, - 0x02, 0xAA, 0xBB, - 0x99, 0x99, 0x99, 0x99, 0x99, 0x99, 0x99, 0x99, - 0x99, 0x99, 0x99, 0x99, 0x99, 0x99, 0x99, 0x99 + 0x44, + 0x44, + 0x44, + 0x44, + 0x55, + 0x55, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x66, + 0x77, + 0x77, + 0x02, + 0xAA, + 0xBB, + 0x99, + 0x99, + 0x99, + 0x99, + 0x99, + 0x99, + 0x99, + 0x99, + 0x99, + 0x99, + 0x99, + 0x99, + 0x99, + 0x99, + 0x99, + 0x99, }; static const unsigned char long_cid[21] = { 0x42 }; static const unsigned char excess_ack_delay_exp[] = { - 0x15 + 0x15, }; static const unsigned char excess_max_ack_delay[] = { - 0xC0, 0x00, 0x00, 0x00, 0x00, 0x00, 0x40, 0x00 + 0xC0, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x40, + 0x00, }; static const unsigned char excess_initial_max_streams[] = { - 0xD0, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01 + 0xD0, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x01, }; static const unsigned char undersize_udp_payload_size[] = { - 0xC0, 0x00, 0x00, 0x00, 0x00, 0x00, 0x04, 0xaf + 0xC0, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x04, + 0xaf, }; static const unsigned char undersize_active_conn_id_limit[] = { - 0xC0, 0x00, 0x00, 0x00, 0x00, 0x00, 0x00, 0x01 + 0xC0, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x00, + 0x01, }; static const unsigned char bogus_int[9] = { 0 }; @@ -1982,128 +1995,126 @@ static const unsigned char int_with_trailer[2] = { 0x01 }; #define QUIC_TPARAM_UNKNOWN_1 0xf1f1 -/* clang-format off */ static const struct tparam_test tparam_tests[] = { TPARAM_CHECK_DUP(ORIG_DCID, - "ORIG_DCID appears multiple times"), - TPARAM_CHECK_DUP(INITIAL_SCID, - "INITIAL_SCID appears multiple times"), - TPARAM_CHECK_DUP(INITIAL_MAX_DATA, - "INITIAL_MAX_DATA appears multiple times"), - TPARAM_CHECK_DUP(INITIAL_MAX_STREAM_DATA_BIDI_LOCAL, - "INITIAL_MAX_STREAM_DATA_BIDI_LOCAL appears multiple times"), - TPARAM_CHECK_DUP(INITIAL_MAX_STREAM_DATA_BIDI_REMOTE, - "INITIAL_MAX_STREAM_DATA_BIDI_REMOTE appears multiple times"), - TPARAM_CHECK_DUP(INITIAL_MAX_STREAM_DATA_UNI, - "INITIAL_MAX_STREAM_DATA_UNI appears multiple times"), - TPARAM_CHECK_DUP(INITIAL_MAX_STREAMS_BIDI, - "INITIAL_MAX_STREAMS_BIDI appears multiple times"), - TPARAM_CHECK_DUP(INITIAL_MAX_STREAMS_UNI, - "INITIAL_MAX_STREAMS_UNI appears multiple times"), - TPARAM_CHECK_DUP(MAX_IDLE_TIMEOUT, - "MAX_IDLE_TIMEOUT appears multiple times"), - TPARAM_CHECK_DUP(MAX_UDP_PAYLOAD_SIZE, - "MAX_UDP_PAYLOAD_SIZE appears multiple times"), - TPARAM_CHECK_DUP(ACTIVE_CONN_ID_LIMIT, - "ACTIVE_CONN_ID_LIMIT appears multiple times"), - TPARAM_CHECK_DUP(DISABLE_ACTIVE_MIGRATION, - "DISABLE_ACTIVE_MIGRATION appears multiple times"), + "ORIG_DCID appears multiple times") + TPARAM_CHECK_DUP(INITIAL_SCID, + "INITIAL_SCID appears multiple times") + TPARAM_CHECK_DUP(INITIAL_MAX_DATA, + "INITIAL_MAX_DATA appears multiple times") + TPARAM_CHECK_DUP(INITIAL_MAX_STREAM_DATA_BIDI_LOCAL, + "INITIAL_MAX_STREAM_DATA_BIDI_LOCAL appears multiple times") + TPARAM_CHECK_DUP(INITIAL_MAX_STREAM_DATA_BIDI_REMOTE, + "INITIAL_MAX_STREAM_DATA_BIDI_REMOTE appears multiple times") + TPARAM_CHECK_DUP(INITIAL_MAX_STREAM_DATA_UNI, + "INITIAL_MAX_STREAM_DATA_UNI appears multiple times") + TPARAM_CHECK_DUP(INITIAL_MAX_STREAMS_BIDI, + "INITIAL_MAX_STREAMS_BIDI appears multiple times") + TPARAM_CHECK_DUP(INITIAL_MAX_STREAMS_UNI, + "INITIAL_MAX_STREAMS_UNI appears multiple times") + TPARAM_CHECK_DUP(MAX_IDLE_TIMEOUT, + "MAX_IDLE_TIMEOUT appears multiple times") + TPARAM_CHECK_DUP(MAX_UDP_PAYLOAD_SIZE, + "MAX_UDP_PAYLOAD_SIZE appears multiple times") + TPARAM_CHECK_DUP(ACTIVE_CONN_ID_LIMIT, + "ACTIVE_CONN_ID_LIMIT appears multiple times") + TPARAM_CHECK_DUP(DISABLE_ACTIVE_MIGRATION, + "DISABLE_ACTIVE_MIGRATION appears multiple times") - TPARAM_CHECK_DROP(INITIAL_SCID, - "INITIAL_SCID was not sent but is required"), - TPARAM_CHECK_DROP(ORIG_DCID, - "ORIG_DCID was not sent but is required"), + TPARAM_CHECK_DROP(INITIAL_SCID, + "INITIAL_SCID was not sent but is required") + TPARAM_CHECK_DROP(ORIG_DCID, + "ORIG_DCID was not sent but is required") - TPARAM_CHECK_DROP_INJECT_A(DISABLE_ACTIVE_MIGRATION, disable_active_migration_1, - "DISABLE_ACTIVE_MIGRATION is malformed"), - TPARAM_CHECK_INJECT(UNKNOWN_1, NULL, 0, - NULL), - TPARAM_CHECK_INJECT_RAW_A(malformed_stateless_reset_token_1, - "STATELESS_RESET_TOKEN is malformed"), - TPARAM_CHECK_INJECT_A(STATELESS_RESET_TOKEN, - malformed_stateless_reset_token_2, - "STATELESS_RESET_TOKEN is malformed"), - TPARAM_CHECK_INJECT_A(STATELESS_RESET_TOKEN, - malformed_stateless_reset_token_3, - "STATELESS_RESET_TOKEN is malformed"), - TPARAM_CHECK_INJECT_A(STATELESS_RESET_TOKEN, - malformed_stateless_reset_token_4, - "STATELESS_RESET_TOKEN is malformed"), - TPARAM_CHECK_INJECT(STATELESS_RESET_TOKEN, - NULL, 0, - "STATELESS_RESET_TOKEN is malformed"), - TPARAM_CHECK_INJECT_RAW_A(malformed_preferred_addr_1, - "PREFERRED_ADDR is malformed"), - TPARAM_CHECK_INJECT_RAW_A(malformed_preferred_addr_2, - "PREFERRED_ADDR is malformed"), - TPARAM_CHECK_INJECT_RAW_A(malformed_preferred_addr_3, - "PREFERRED_ADDR is malformed"), - TPARAM_CHECK_INJECT_RAW_A(malformed_preferred_addr_4, - "PREFERRED_ADDR is malformed"), - TPARAM_CHECK_INJECT_RAW_A(malformed_unknown_1, - "bad transport parameter"), - TPARAM_CHECK_INJECT_RAW_A(malformed_unknown_2, - "bad transport parameter"), - TPARAM_CHECK_INJECT_RAW_A(malformed_unknown_3, - "bad transport parameter"), + TPARAM_CHECK_DROP_INJECT_A(DISABLE_ACTIVE_MIGRATION, disable_active_migration_1, + "DISABLE_ACTIVE_MIGRATION is malformed") + TPARAM_CHECK_INJECT(UNKNOWN_1, NULL, 0, + NULL) + TPARAM_CHECK_INJECT_RAW_A(malformed_stateless_reset_token_1, + "STATELESS_RESET_TOKEN is malformed") + TPARAM_CHECK_INJECT_A(STATELESS_RESET_TOKEN, + malformed_stateless_reset_token_2, + "STATELESS_RESET_TOKEN is malformed") + TPARAM_CHECK_INJECT_A(STATELESS_RESET_TOKEN, + malformed_stateless_reset_token_3, + "STATELESS_RESET_TOKEN is malformed") + TPARAM_CHECK_INJECT_A(STATELESS_RESET_TOKEN, + malformed_stateless_reset_token_4, + "STATELESS_RESET_TOKEN is malformed") + TPARAM_CHECK_INJECT(STATELESS_RESET_TOKEN, + NULL, 0, + "STATELESS_RESET_TOKEN is malformed") + TPARAM_CHECK_INJECT_RAW_A(malformed_preferred_addr_1, + "PREFERRED_ADDR is malformed") + TPARAM_CHECK_INJECT_RAW_A(malformed_preferred_addr_2, + "PREFERRED_ADDR is malformed") + TPARAM_CHECK_INJECT_RAW_A(malformed_preferred_addr_3, + "PREFERRED_ADDR is malformed") + TPARAM_CHECK_INJECT_RAW_A(malformed_preferred_addr_4, + "PREFERRED_ADDR is malformed") + TPARAM_CHECK_INJECT_RAW_A(malformed_unknown_1, + "bad transport parameter") + TPARAM_CHECK_INJECT_RAW_A(malformed_unknown_2, + "bad transport parameter") + TPARAM_CHECK_INJECT_RAW_A(malformed_unknown_3, + "bad transport parameter") - TPARAM_CHECK_INJECT_A(ACK_DELAY_EXP, excess_ack_delay_exp, - "ACK_DELAY_EXP is malformed"), - TPARAM_CHECK_INJECT_A(MAX_ACK_DELAY, excess_max_ack_delay, - "MAX_ACK_DELAY is malformed"), - TPARAM_CHECK_DROP_INJECT_A(INITIAL_MAX_STREAMS_BIDI, excess_initial_max_streams, - "INITIAL_MAX_STREAMS_BIDI is malformed"), - TPARAM_CHECK_DROP_INJECT_A(INITIAL_MAX_STREAMS_UNI, excess_initial_max_streams, - "INITIAL_MAX_STREAMS_UNI is malformed"), + TPARAM_CHECK_INJECT_A(ACK_DELAY_EXP, excess_ack_delay_exp, + "ACK_DELAY_EXP is malformed") + TPARAM_CHECK_INJECT_A(MAX_ACK_DELAY, excess_max_ack_delay, + "MAX_ACK_DELAY is malformed") + TPARAM_CHECK_DROP_INJECT_A(INITIAL_MAX_STREAMS_BIDI, excess_initial_max_streams, + "INITIAL_MAX_STREAMS_BIDI is malformed") + TPARAM_CHECK_DROP_INJECT_A(INITIAL_MAX_STREAMS_UNI, excess_initial_max_streams, + "INITIAL_MAX_STREAMS_UNI is malformed") - TPARAM_CHECK_DROP_INJECT_A(MAX_UDP_PAYLOAD_SIZE, undersize_udp_payload_size, - "MAX_UDP_PAYLOAD_SIZE is malformed"), - TPARAM_CHECK_DROP_INJECT_A(ACTIVE_CONN_ID_LIMIT, undersize_active_conn_id_limit, - "ACTIVE_CONN_ID_LIMIT is malformed"), + TPARAM_CHECK_DROP_INJECT_A(MAX_UDP_PAYLOAD_SIZE, undersize_udp_payload_size, + "MAX_UDP_PAYLOAD_SIZE is malformed") + TPARAM_CHECK_DROP_INJECT_A(ACTIVE_CONN_ID_LIMIT, undersize_active_conn_id_limit, + "ACTIVE_CONN_ID_LIMIT is malformed") - TPARAM_CHECK_INJECT_TWICE_A(ACK_DELAY_EXP, ack_delay_exp, - "ACK_DELAY_EXP appears multiple times"), - TPARAM_CHECK_INJECT_TWICE_A(MAX_ACK_DELAY, ack_delay_exp, - "MAX_ACK_DELAY appears multiple times"), - TPARAM_CHECK_INJECT_TWICE_A(STATELESS_RESET_TOKEN, stateless_reset_token, - "STATELESS_RESET_TOKEN appears multiple times"), - TPARAM_CHECK_INJECT_TWICE_A(PREFERRED_ADDR, preferred_addr, - "PREFERRED_ADDR appears multiple times"), + TPARAM_CHECK_INJECT_TWICE_A(ACK_DELAY_EXP, ack_delay_exp, + "ACK_DELAY_EXP appears multiple times") + TPARAM_CHECK_INJECT_TWICE_A(MAX_ACK_DELAY, ack_delay_exp, + "MAX_ACK_DELAY appears multiple times") + TPARAM_CHECK_INJECT_TWICE_A(STATELESS_RESET_TOKEN, stateless_reset_token, + "STATELESS_RESET_TOKEN appears multiple times") + TPARAM_CHECK_INJECT_TWICE_A(PREFERRED_ADDR, preferred_addr, + "PREFERRED_ADDR appears multiple times") - TPARAM_CHECK_MUTATE(ORIG_DCID, - "ORIG_DCID does not match expected value"), - TPARAM_CHECK_MUTATE(INITIAL_SCID, - "INITIAL_SCID does not match expected value"), + TPARAM_CHECK_MUTATE(ORIG_DCID, + "ORIG_DCID does not match expected value") + TPARAM_CHECK_MUTATE(INITIAL_SCID, + "INITIAL_SCID does not match expected value") - TPARAM_CHECK_DROP_INJECT_A(ORIG_DCID, long_cid, - "ORIG_DCID is malformed"), - TPARAM_CHECK_DROP_INJECT_A(INITIAL_SCID, long_cid, - "INITIAL_SCID is malformed"), + TPARAM_CHECK_DROP_INJECT_A(ORIG_DCID, long_cid, + "ORIG_DCID is malformed") + TPARAM_CHECK_DROP_INJECT_A(INITIAL_SCID, long_cid, + "INITIAL_SCID is malformed") - TPARAM_CHECK_INT(INITIAL_MAX_DATA, - "INITIAL_MAX_DATA is malformed"), - TPARAM_CHECK_INT(INITIAL_MAX_STREAM_DATA_BIDI_LOCAL, - "INITIAL_MAX_STREAM_DATA_BIDI_LOCAL is malformed"), - TPARAM_CHECK_INT(INITIAL_MAX_STREAM_DATA_BIDI_REMOTE, - "INITIAL_MAX_STREAM_DATA_BIDI_REMOTE is malformed"), - TPARAM_CHECK_INT(INITIAL_MAX_STREAM_DATA_UNI, - "INITIAL_MAX_STREAM_DATA_UNI is malformed"), - TPARAM_CHECK_INT(ACK_DELAY_EXP, - "ACK_DELAY_EXP is malformed"), - TPARAM_CHECK_INT(MAX_ACK_DELAY, - "MAX_ACK_DELAY is malformed"), - TPARAM_CHECK_INT(INITIAL_MAX_STREAMS_BIDI, - "INITIAL_MAX_STREAMS_BIDI is malformed"), - TPARAM_CHECK_INT(INITIAL_MAX_STREAMS_UNI, - "INITIAL_MAX_STREAMS_UNI is malformed"), - TPARAM_CHECK_INT(MAX_IDLE_TIMEOUT, - "MAX_IDLE_TIMEOUT is malformed"), - TPARAM_CHECK_INT(MAX_UDP_PAYLOAD_SIZE, - "MAX_UDP_PAYLOAD_SIZE is malformed"), - TPARAM_CHECK_INT(ACTIVE_CONN_ID_LIMIT, - "ACTIVE_CONN_ID_LIMIT is malformed"), + TPARAM_CHECK_INT(INITIAL_MAX_DATA, + "INITIAL_MAX_DATA is malformed") + TPARAM_CHECK_INT(INITIAL_MAX_STREAM_DATA_BIDI_LOCAL, + "INITIAL_MAX_STREAM_DATA_BIDI_LOCAL is malformed") + TPARAM_CHECK_INT(INITIAL_MAX_STREAM_DATA_BIDI_REMOTE, + "INITIAL_MAX_STREAM_DATA_BIDI_REMOTE is malformed") + TPARAM_CHECK_INT(INITIAL_MAX_STREAM_DATA_UNI, + "INITIAL_MAX_STREAM_DATA_UNI is malformed") + TPARAM_CHECK_INT(ACK_DELAY_EXP, + "ACK_DELAY_EXP is malformed") + TPARAM_CHECK_INT(MAX_ACK_DELAY, + "MAX_ACK_DELAY is malformed") + TPARAM_CHECK_INT(INITIAL_MAX_STREAMS_BIDI, + "INITIAL_MAX_STREAMS_BIDI is malformed") + TPARAM_CHECK_INT(INITIAL_MAX_STREAMS_UNI, + "INITIAL_MAX_STREAMS_UNI is malformed") + TPARAM_CHECK_INT(MAX_IDLE_TIMEOUT, + "MAX_IDLE_TIMEOUT is malformed") + TPARAM_CHECK_INT(MAX_UDP_PAYLOAD_SIZE, + "MAX_UDP_PAYLOAD_SIZE is malformed") + TPARAM_CHECK_INT(ACTIVE_CONN_ID_LIMIT, + "ACTIVE_CONN_ID_LIMIT is malformed") }; -/* clang-format on */ struct tparam_ctx { const struct tparam_test *t; @@ -2686,84 +2697,6 @@ err: return testresult; } -/* - * Verify that the SSL* received in the info callback after SSL_new_from_listener - * is the outer QUIC connection object, not the inner TLS SSL. - */ -static SSL *new_from_listener_info_cb_ssl = NULL; - -static void new_from_listener_info_cb(const SSL *ssl, int type, int val) -{ - if (type == SSL_CB_HANDSHAKE_DONE) - new_from_listener_info_cb_ssl = (SSL *)ssl; -} - -static int test_ssl_new_from_listener_user_ssl(void) -{ - SSL_CTX *lctx = NULL, *sctx = NULL; - SSL *qlistener = NULL, *qserver = NULL, *qconn = NULL; - BIO *lbio = NULL, *sbio = NULL; - BIO_ADDR *addr = NULL; - struct in_addr ina; - int ret = 0, chk; - - ina.s_addr = htonl(0x1f000001); - new_from_listener_info_cb_ssl = NULL; - - if (!TEST_ptr(lctx = create_server_ctx()) - || !TEST_ptr(sctx = create_server_ctx()) - || !TEST_true(BIO_new_bio_dgram_pair(&lbio, 0, &sbio, 0))) - goto err; - - /* - * Register an info callback on the listener CTX. The inner TLS connection - * created by ossl_quic_new_from_listener inherits this CTX, so when the TLS - * handshake completes it invokes the callback with user_ssl. That must be - * qconn (the outer QUIC object), not the inner TLS SSL object. - */ - SSL_CTX_set_info_callback(lctx, new_from_listener_info_cb); - - if (!TEST_ptr(addr = create_addr(&ina, 8041)) - || !TEST_true(bio_addr_bind(lbio, addr))) - goto err; - addr = NULL; - - if (!TEST_ptr(addr = create_addr(&ina, 4081)) - || !TEST_true(bio_addr_bind(sbio, addr))) - goto err; - addr = NULL; - - qlistener = ql_create(lctx, lbio); - lbio = NULL; - qserver = ql_create(sctx, sbio); - sbio = NULL; - if (!TEST_ptr(qlistener) || !TEST_ptr(qserver) - || !TEST_ptr(qconn = SSL_new_from_listener(qlistener, 0)) - || !TEST_ptr(addr = create_addr(&ina, 4081)) - || !TEST_true(qc_init(qconn, addr))) - goto err; - - while ((chk = SSL_do_handshake(qconn)) == -1) { - SSL_handle_events(qserver); - SSL_handle_events(qlistener); - } - - ret = TEST_int_gt(chk, 0) - && TEST_ptr(new_from_listener_info_cb_ssl) - && TEST_ptr_eq(new_from_listener_info_cb_ssl, qconn); - -err: - SSL_free(qconn); - SSL_free(qlistener); - SSL_free(qserver); - BIO_free(lbio); - BIO_free(sbio); - SSL_CTX_free(sctx); - SSL_CTX_free(lctx); - BIO_ADDR_free(addr); - return ret; -} - static int test_server_method_with_ssl_new(void) { SSL_CTX *ctx = NULL; @@ -2796,16 +2729,8 @@ end: return ret; } -/* Fake clock for tests that advance QUIC time without consuming real time. */ -static OSSL_TIME fake_now; - -static OSSL_TIME fake_now_cb(void *arg) -{ - return fake_now; -} - -static int create_quic_ssl_objects_ex(SSL_CTX *sctx, SSL_CTX *cctx, - SSL **lssl, SSL **cssl, int use_fake_time) +static int create_quic_ssl_objects(SSL_CTX *sctx, SSL_CTX *cctx, + SSL **lssl, SSL **cssl) { BIO_ADDR *addr = NULL; struct in_addr ina; @@ -2846,18 +2771,6 @@ static int create_quic_ssl_objects_ex(SSL_CTX *sctx, SSL_CTX *cctx, SSL_set_bio(*cssl, cbio, cbio); cbio = NULL; - if (use_fake_time) { - /* - * The base value does not matter but must be nonzero, as the ACK - * manager reads a zero packet timestamp as unset. Use real time to - * match the clock the engines were created with. - */ - fake_now = ossl_time_now(); - if (!TEST_true(ossl_quic_set_override_now_cb(*lssl, fake_now_cb, NULL)) - || !TEST_true(ossl_quic_set_override_now_cb(*cssl, fake_now_cb, NULL))) - goto err; - } - ret = 1; err: @@ -2873,12 +2786,6 @@ err: return ret; } -static int create_quic_ssl_objects(SSL_CTX *sctx, SSL_CTX *cctx, - SSL **lssl, SSL **cssl) -{ - return create_quic_ssl_objects_ex(sctx, cctx, lssl, cssl, 0); -} - static int test_ssl_client_as_ossl_quic_method(void) { SSL_CTX *cctx = NULL, *sctx = NULL; @@ -2986,7 +2893,8 @@ static int test_ssl_listen_ex(void) goto err; /* Call SSL_accept() and SSL_connect() until we are connected */ - if (!TEST_true(create_bare_ssl_connection(serverssl, clientssl, SSL_ERROR_NONE, 0, 0))) + if (!TEST_true(create_bare_ssl_connection(serverssl, clientssl, + SSL_ERROR_NONE, 0, 0))) /* * Ensure that, now that we have used SSL_listen_ex, SSL_accept_connection @@ -3002,9 +2910,9 @@ static int test_ssl_listen_ex(void) testresult = 1; err: - SSL_free(qlistener); SSL_free(serverssl); SSL_free(clientssl); + SSL_free(qlistener); SSL_CTX_free(sctx); SSL_CTX_free(cctx); SSL_CTX_free(qmctx); @@ -3103,8 +3011,8 @@ static int test_ssl_set_verify(void) serverssl = SSL_accept_connection(qlistener, 0); /* Call SSL_accept() and SSL_connect() until we are connected */ - if (!TEST_ptr(serverssl) - || !TEST_true(create_bare_ssl_connection(serverssl, clientssl, SSL_ERROR_NONE, 0, 0))) + if (!TEST_true(create_bare_ssl_connection(serverssl, clientssl, + SSL_ERROR_NONE, 0, 0))) goto err; testresult = 1; @@ -3316,8 +3224,8 @@ static int test_client_hello_retry(void) serverssl = SSL_accept_connection(qlistener, 0); /* Call SSL_accept() and SSL_connect() until we are connected */ - if (!TEST_ptr(serverssl) - || !TEST_true(create_bare_ssl_connection(serverssl, clientssl, SSL_ERROR_NONE, 0, 0))) + if (!TEST_true(create_bare_ssl_connection(serverssl, clientssl, + SSL_ERROR_NONE, 0, 0))) goto err; testresult = 1; @@ -3509,336 +3417,12 @@ static int test_quic_peer_addr_v4(void) "127.0.0.2", 4434); } -#if OPENSSL_USE_IPV6 static int test_quic_peer_addr_v6(void) { return test_quic_peer_addr_common(AF_INET6, "::1", 4433, "::2", 4434); } -#endif - -/* - * Advance the fake clock to the next QUIC timer event when both endpoints are - * idle, consuming no real time. - */ -static void quic_advance_time(SSL *clientssl, SSL *serverssl) -{ - struct timeval tv; - int inf = 0; - OSSL_TIME delay = ossl_time_infinite(), t; - - /* If there is data waiting to be processed, do not wait - tick instead. */ - if (BIO_pending(SSL_get_rbio(clientssl)) > 0) - return; - - if (SSL_get_event_timeout(clientssl, &tv, &inf) && !inf) { - t = ossl_time_from_timeval(tv); - if (ossl_time_compare(t, delay) < 0) - delay = t; - } - if (SSL_get_event_timeout(serverssl, &tv, &inf) && !inf) { - t = ossl_time_from_timeval(tv); - if (ossl_time_compare(t, delay) < 0) - delay = t; - } - - if (!ossl_time_is_infinite(delay)) - fake_now = ossl_time_add(fake_now, delay); -} - -static int test_quic_handshake_multipkt_mfail(void) -{ - SSL_CTX *cctx = NULL, *sctx = NULL; - SSL *clientssl = NULL, *serverssl = NULL, *qlistener = NULL; - QUIC_CHANNEL *sch = NULL, *cch = NULL; - int ret = 0, rc = 0, err, i; - - if (!TEST_ptr(sctx = create_server_ctx()) - || !TEST_ptr(cctx = create_client_ctx())) - goto err; - - if (!create_quic_ssl_objects_ex(sctx, cctx, &qlistener, &clientssl, 1)) - goto err; - - if (!TEST_true(SSL_set_tlsext_host_name(clientssl, "localhost"))) - goto err; - - /* Get the listener to bind a channel we can accept. */ - for (i = 0; i < 10; i++) { - rc = SSL_connect(clientssl); - if (rc <= 0) { - err = SSL_get_error(clientssl, rc); - if (!TEST_true(err == SSL_ERROR_WANT_READ - || err == SSL_ERROR_WANT_WRITE)) - goto err; - } - SSL_handle_events(qlistener); - - serverssl = SSL_accept_connection(qlistener, 0); - if (serverssl != NULL) - break; - } - if (!TEST_ptr(serverssl) - || !TEST_false(SSL_is_init_finished(serverssl))) - goto err; - - if (!TEST_ptr(sch = ossl_quic_conn_get_channel(serverssl))) - goto err; - - /* Do handshake until the server reaches the first flight. */ - for (i = 0; i < 10; i++) { - rc = SSL_do_handshake(clientssl); - if (rc <= 0) { - err = SSL_get_error(clientssl, rc); - if (!TEST_true(err == SSL_ERROR_WANT_READ - || err == SSL_ERROR_WANT_WRITE)) - goto err; - } - if (ossl_quic_channel_is_term_any(sch)) - goto err; - SSL_handle_events(serverssl); - if (sch->tx_enc_level >= QUIC_ENC_LEVEL_HANDSHAKE) - break; - quic_advance_time(clientssl, serverssl); - } - if (!TEST_int_lt(i, 10)) - goto err; - - /* Process the multi-packet datagram under mfail. */ - MFAIL_start(); - rc = SSL_do_handshake(clientssl); - MFAIL_end(); - - /* A fatal injected failure may terminate the connection - bail if so. */ - if (rc <= 0) { - err = SSL_get_error(clientssl, rc); - if (err != SSL_ERROR_WANT_READ && err != SSL_ERROR_WANT_WRITE) - goto err; - } - - if (!TEST_ptr(cch = ossl_quic_conn_get_channel(clientssl))) - goto err; - - /* Connection still live so get the handshake to converge. */ - for (i = 0; i < 10; i++) { - rc = SSL_do_handshake(clientssl); - if (rc == 1) - break; - - err = SSL_get_error(clientssl, rc); - if (err != SSL_ERROR_WANT_READ && err != SSL_ERROR_WANT_WRITE) { - ret = -1; - goto err; - } - - if (ossl_quic_channel_is_term_any(cch) - || ossl_quic_channel_is_term_any(sch)) - goto err; - - SSL_handle_events(serverssl); - quic_advance_time(clientssl, serverssl); - } - if (!TEST_int_lt(i, 10)) { - ret = is_fips && fips_provider_version_match(libctx, ">=3.5.0 <4.1.0") - ? 0 - : -1; - goto err; - } - - ret = 1; - -err: - SSL_free(serverssl); - SSL_free(clientssl); - SSL_free(qlistener); - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - - return ret; -} - -/* Test ECH with quic */ -static int test_ech(void) -{ - /* - * Don't try this test if various ECC things are set of unavailable - * or we're in a no-ech build - */ -#if defined(OPENSSL_NO_EC) || defined(OPENSSL_NO_ECX) || defined(OPENSSL_NO_ECH) - propq = NULL; /* avoid unused var warning */ - return 1; -#else - SSL_CTX *cctx = NULL, *sctx = NULL; - SSL *clientquic = NULL; - char *rinner = NULL, *router = NULL; - const char *inner = "inner.example.com"; - QUIC_TSERVER *qtserv = NULL; - int testresult = 0; - /* p256 ech key pair with public name server.example */ - const char echpem[] = "-----BEGIN PRIVATE KEY-----\n" - "MIGHAgEAMBMGByqGSM49AgEGCCqGSM49AwEHBG0wawIBAQQg+Ygt9nhASeoYbzo2\n" - "Nz/jGFAdeTo25SVYWQvnf86qzbahRANCAARS9QqkjJU311J7kS8LsyISJ8xYFbJ5\n" - "5BX/pu4QiFXJ3dEGrjYh4PDH/ehFfaqZgtRRg2r/AP+vwkLiP2mqCfdv\n" - "-----END PRIVATE KEY-----\n" - "-----BEGIN ECHCONFIG-----\n" - "AGL+DQBezwAQAEEEUvUKpIyVN9dSe5EvC7MiEifMWBWyeeQV/6buEIhVyd3RBq42\n" - "IeDwx/3oRX2qmYLUUYNq/wD/r8JC4j9pqgn3bwAEAAEAAQAOc2VydmVyLmV4YW1w\n" - "bGUAAA==\n" - "-----END ECHCONFIG-----\n"; - const char ec_pub[] = "AGL+DQBezwAQAEEEUvUKpIyVN9dSe5EvC7MiEifMWBWyeeQV/6buEIhVyd3RBq42" - "IeDwx/3oRX2qmYLUUYNq/wD/r8JC4j9pqgn3bwAEAAEAAQAOc2VydmVyLmV4YW1w" - "bGUAAA=="; - size_t ec_publen = sizeof(ec_pub) - 1; - BIO *in = NULL; - OSSL_ECHSTORE *es = NULL; - - /* HPKE and FIPS are not friends, so don't test in that case */ - if (is_fips) { - TEST_info("No real ECH test as is_fips is set\n"); - return 1; - } else { - TEST_info("Doing real ECH test as is_fips is not set\n"); - } - - /* make an OSSL_ECHSTORE for echpem */ - if ((in = BIO_new(BIO_s_mem())) == NULL - || BIO_write(in, echpem, (int)strlen(echpem)) <= 0 - || !TEST_ptr(es = OSSL_ECHSTORE_new(libctx, propq)) - || !TEST_true(OSSL_ECHSTORE_read_pem(es, in, OSSL_ECH_FOR_RETRY))) - goto err; - - cctx = SSL_CTX_new_ex(libctx, NULL, OSSL_QUIC_client_method()); - sctx = SSL_CTX_new_ex(libctx, NULL, TLS_method()); - /* set OSSL_ECHSTORE for server */ - if (!TEST_ptr(sctx) || !TEST_true(SSL_CTX_set1_echstore(sctx, es))) - goto err; - - if (!TEST_ptr(cctx) - || !TEST_true(qtest_create_quic_objects(libctx, cctx, sctx, cert, - privkey, - QTEST_FLAG_FAKE_TIME, - &qtserv, - &clientquic, NULL, NULL))) - goto err; - - /* set echconfig for client */ - if (!TEST_true(SSL_set1_ech_config_list(clientquic, - (unsigned char *)ec_pub, ec_publen)) - || !TEST_true(SSL_set_tlsext_host_name(clientquic, inner))) - goto err; - /* we expect the connection to succeed */ - if (!TEST_true(qtest_create_quic_connection(qtserv, clientquic))) - goto err; - SSL_set_verify_result(clientquic, X509_V_OK); - if (!TEST_int_eq(SSL_ech_get1_status(clientquic, &rinner, &router), - SSL_ECH_STATUS_SUCCESS)) - goto err; - - testresult = 1; -err: - ossl_quic_tserver_free(qtserv); - SSL_free(clientquic); - OPENSSL_free(router); - OPENSSL_free(rinner); - SSL_CTX_free(cctx); - SSL_CTX_free(sctx); - OSSL_ECHSTORE_free(es); - BIO_free_all(in); - - return testresult; -#endif -} - -static int test_quic_resize_txe(void) -{ - SSL_CTX *cctx = NULL; - SSL *clientquic = NULL; - QUIC_TSERVER *qtserv = NULL; - QUIC_CHANNEL *ch = NULL; - unsigned char msg[] = "resize test"; - unsigned char buf[sizeof(msg)]; - size_t numbytes = 0; - int ret = 0; - - if (!TEST_ptr(cctx = SSL_CTX_new_ex(libctx, NULL, OSSL_QUIC_client_method()))) - goto end; - - if (!TEST_true(qtest_create_quic_objects(libctx, cctx, NULL, - cert, privkey, 0, - &qtserv, &clientquic, - NULL, NULL))) - goto end; - - if (!TEST_true(qtest_create_quic_connection(qtserv, clientquic))) - goto end; - - /* - * Client writes first to open stream 0 (client-initiated bidirectional). - * The server must see the stream before it can write back on it. - */ - if (!TEST_true(SSL_write_ex(clientquic, msg, sizeof(msg), &numbytes)) - || !TEST_size_t_eq(numbytes, sizeof(msg))) - goto end; - - ossl_quic_tserver_tick(qtserv); - if (!TEST_true(ossl_quic_tserver_read(qtserv, 0, buf, sizeof(buf), - &numbytes))) - goto end; - - /* - * Increase the server's QTX MDPL above the initial allocation size - * (QUIC_MIN_INITIAL_DGRAM_LEN = 1200). All TXEs in the free list have - * alloc_len = 1200, so the next write will trigger qtx_resize_txe. - */ - ch = ossl_quic_tserver_get_channel(qtserv); - if (!TEST_true(ossl_qtx_set_mdpl(ch->qtx, - QUIC_MIN_INITIAL_DGRAM_LEN + 250))) - goto end; - - /* Trigger a server write: exercises qtx_resize_txe via qtx_reserve_txe */ - if (!TEST_true(ossl_quic_tserver_write(qtserv, 0, - msg, sizeof(msg), &numbytes)) - || !TEST_size_t_eq(numbytes, sizeof(msg))) - goto end; - - ossl_quic_tserver_tick(qtserv); - SSL_handle_events(clientquic); - - if (!TEST_true(SSL_read_ex(clientquic, buf, sizeof(buf), &numbytes)) - || !TEST_mem_eq(buf, numbytes, msg, sizeof(msg))) - goto end; - - ret = 1; -end: - ossl_quic_tserver_free(qtserv); - SSL_free(clientquic); - SSL_CTX_free(cctx); - return ret; -} - -static int test_ssl_new_mfail(void) -{ - int ret = 0; - SSL_CTX *cctx = NULL; - SSL *clientquic = NULL; - - if (!TEST_ptr(cctx = SSL_CTX_new_ex(libctx, NULL, OSSL_QUIC_client_method()))) - goto err; - - MFAIL_start(); - clientquic = SSL_new(cctx); - MFAIL_end(); - - if (clientquic != NULL) - ret = 1; - -err: - SSL_free(clientquic); - SSL_CTX_free(cctx); - - return ret; -} /***********************************************************************************/ OPT_TEST_DECLARE_USAGE("provider config certsdir datadir\n") @@ -3905,11 +3489,10 @@ int setup_tests(void) goto err; cprivkey = test_mk_file_path(certsdir, "ee-key.pem"); - if (cprivkey == NULL) + if (privkey == NULL) goto err; ADD_ALL_TESTS(test_quic_write_read, 3); - ADD_MFAIL_NO_CHECK_TEST(test_ssl_read_key_update_mfail); ADD_TEST(test_fin_only_blocking); ADD_TEST(test_ciphersuites); ADD_TEST(test_cipher_find); @@ -3938,7 +3521,6 @@ int setup_tests(void) ADD_TEST(test_domain_flags); ADD_TEST(test_early_ticks); ADD_TEST(test_ssl_new_from_listener); - ADD_TEST(test_ssl_new_from_listener_user_ssl); #ifndef OPENSSL_NO_SSL_TRACE ADD_TEST(test_new_token); #endif @@ -3947,14 +3529,8 @@ int setup_tests(void) ADD_TEST(test_ssl_set_verify); ADD_TEST(test_accept_stream); ADD_TEST(test_client_hello_retry); -#if OPENSSL_USE_IPV6 ADD_TEST(test_quic_peer_addr_v6); -#endif ADD_TEST(test_quic_peer_addr_v4); - ADD_MFAIL_NO_CHECK_TEST(test_quic_handshake_multipkt_mfail); - ADD_TEST(test_ech); - ADD_TEST(test_quic_resize_txe); - ADD_MFAIL_TEST(test_ssl_new_mfail); return 1; err: diff --git a/test/radix/quic_bindings.c b/test/radix/quic_bindings.c index 63bcecad99..9f887d55c6 100644 --- a/test/radix/quic_bindings.c +++ b/test/radix/quic_bindings.c @@ -52,7 +52,6 @@ typedef struct radix_obj_st { SSL *ssl; /* owns one reference */ unsigned int registered : 1; /* in LHASH? */ unsigned int active : 1; /* tick? */ - CRYPTO_MUTEX *mx; } RADIX_OBJ; DEFINE_LHASH_OF_EX(RADIX_OBJ); @@ -67,12 +66,9 @@ typedef struct radix_process_st { /* Process-global state. */ CRYPTO_MUTEX *gm; /* global mutex */ LHASH_OF(RADIX_OBJ) *objs; /* protected by gm */ + OSSL_TIME time_slip; /* protected by gm */ BIO *keylog_out; /* protected by gm */ - CRYPTO_MUTEX *time_m; - OSSL_TIME base_time; /* set once at init, constant thereafter */ - OSSL_TIME time_slip; /* protected by time_m */ - int done_join_all_threads; /* @@ -108,11 +104,11 @@ typedef struct radix_thread_st { DEFINE_STACK_OF(RADIX_THREAD) /* ssl reference is transferred. name is copied and is required. */ -static RADIX_OBJ *RADIX_OBJ_new_empty(const char *name) +static RADIX_OBJ *RADIX_OBJ_new(const char *name, SSL *ssl) { RADIX_OBJ *obj; - if (!TEST_ptr(name)) + if (!TEST_ptr(name) || !TEST_ptr(ssl)) return NULL; if (!TEST_ptr(obj = OPENSSL_zalloc(sizeof(*obj)))) @@ -123,31 +119,7 @@ static RADIX_OBJ *RADIX_OBJ_new_empty(const char *name) return NULL; } - obj->mx = ossl_crypto_mutex_new(); -#if !defined(OPENSSL_THREADS_NONE) - if (obj->mx == NULL) { - OPENSSL_free(obj->name); - OPENSSL_free(obj); - return NULL; - } -#endif - - return obj; -} - -static RADIX_OBJ *RADIX_OBJ_new(const char *name, SSL *ssl) -{ - RADIX_OBJ *obj; - - if (!TEST_ptr(ssl)) - return NULL; - - obj = RADIX_OBJ_new_empty(name); - if (!TEST_ptr(obj)) - return NULL; - obj->ssl = ssl; - return obj; } @@ -160,7 +132,6 @@ static void RADIX_OBJ_free(RADIX_OBJ *obj) SSL_free(obj->ssl); OPENSSL_free(obj->name); - ossl_crypto_mutex_free(&obj->mx); OPENSSL_free(obj); } @@ -181,8 +152,6 @@ static int RADIX_PROCESS_init(RADIX_PROCESS *rp, size_t node_idx, size_t process #if defined(OPENSSL_THREADS) if (!TEST_ptr(rp->gm = ossl_crypto_mutex_new())) goto err; - if (!TEST_ptr(rp->time_m = ossl_crypto_mutex_new())) - goto err; #endif if (!TEST_ptr(rp->objs = lh_RADIX_OBJ_new(RADIX_OBJ_hash, RADIX_OBJ_cmp))) @@ -201,15 +170,12 @@ static int RADIX_PROCESS_init(RADIX_PROCESS *rp, size_t node_idx, size_t process rp->process_idx = process_idx; rp->done_join_all_threads = 0; rp->next_thread_idx = 0; - rp->base_time = ossl_time_now(); - rp->time_slip = ossl_time_zero(); return 1; err: lh_RADIX_OBJ_free(rp->objs); rp->objs = NULL; ossl_crypto_mutex_free(&rp->gm); - ossl_crypto_mutex_free(&rp->time_m); return 0; } @@ -464,7 +430,6 @@ static void RADIX_PROCESS_cleanup(RADIX_PROCESS *rp) BIO_free_all(rp->keylog_out); rp->keylog_out = NULL; ossl_crypto_mutex_free(&rp->gm); - ossl_crypto_mutex_free(&rp->time_m); } static RADIX_OBJ *RADIX_PROCESS_get_obj(RADIX_PROCESS *rp, const char *name) @@ -479,9 +444,6 @@ static int RADIX_PROCESS_set_obj(RADIX_PROCESS *rp, const char *name, RADIX_OBJ *obj) { RADIX_OBJ *existing; - SSL *existing_ssl = NULL; - RADIX_THREAD *rt; - int i, j; if (obj != NULL && !TEST_false(obj->registered)) return 0; @@ -493,10 +455,7 @@ static int RADIX_PROCESS_set_obj(RADIX_PROCESS *rp, lh_RADIX_OBJ_delete(rp->objs, existing); existing->registered = 0; - existing_ssl = existing->ssl; RADIX_OBJ_free(existing); - } else { - existing = NULL; } if (obj != NULL) { @@ -504,18 +463,6 @@ static int RADIX_PROCESS_set_obj(RADIX_PROCESS *rp, obj->registered = 1; } - if (existing != NULL) { - for (i = 0; i < sk_RADIX_THREAD_num(rp->threads); i++) { - rt = (RADIX_THREAD *)sk_RADIX_THREAD_value(rp->threads, i); - for (j = 0; j < NUM_SLOTS; j++) { - if (rt->slot[j] == existing) - rt->slot[j] = obj; - if (rt->ssl[j] == existing_ssl) - rt->ssl[j] = (obj == NULL) ? NULL : obj->ssl; - } - } - } - return 1; } @@ -671,9 +618,6 @@ static int bindings_process_finish(int testresult_main) radix_thread_cleanup(); /* cleanup main thread */ RADIX_PROCESS_cleanup(&radix_process); - if (!TEST_true(CRYPTO_THREAD_cleanup_local(&radix_thread))) - testresult = 0; - if (testresult) BIO_printf(bio_err, "==> OK\n\n"); else @@ -690,46 +634,36 @@ static OSSL_TIME get_time(void *arg) { OSSL_TIME time_slip; - ossl_crypto_mutex_lock(RP()->time_m); + ossl_crypto_mutex_lock(RP()->gm); time_slip = RP()->time_slip; - ossl_crypto_mutex_unlock(RP()->time_m); + ossl_crypto_mutex_unlock(RP()->gm); - return ossl_time_add(RP()->base_time, time_slip); + return ossl_time_add(ossl_time_now(), time_slip); } -static OSSL_TIME terp_now(void *arg) +ossl_unused static void radix_skip_time(OSSL_TIME t) { - return ossl_time_now(); -} - -static void radix_skip_time(OSSL_TIME t) -{ - ossl_crypto_mutex_lock(RP()->time_m); + ossl_crypto_mutex_lock(RP()->gm); RP()->time_slip = ossl_time_add(RP()->time_slip, t); - ossl_crypto_mutex_unlock(RP()->time_m); + ossl_crypto_mutex_unlock(RP()->gm); } static void per_op_tick_obj(RADIX_OBJ *obj) { - ossl_crypto_mutex_lock(obj->mx); - if (obj->active && obj->ssl) + if (obj->active) SSL_handle_events(obj->ssl); - ossl_crypto_mutex_unlock(obj->mx); } static int do_per_op(TERP *terp, void *arg) { - radix_skip_time(ossl_ms2time(1)); lh_RADIX_OBJ_doall(RP()->objs, per_op_tick_obj); return 1; } static int bindings_adjust_terp_config(TERP_CONFIG *cfg) { - cfg->now_cb = terp_now; + cfg->now_cb = get_time; cfg->per_op_cb = do_per_op; - - cfg->max_execution_time = ossl_ms2time(60000); return 1; } diff --git a/test/radix/quic_ops.c b/test/radix/quic_ops.c index ed129d0ff7..c64f37ddda 100644 --- a/test/radix/quic_ops.c +++ b/test/radix/quic_ops.c @@ -27,24 +27,6 @@ err: return ok; } -DEF_FUNC(hf_bind) -{ - const char *name; - RADIX_OBJ *empty_obj; - - F_POP(name); - - empty_obj = RADIX_OBJ_new_empty(name); - if (empty_obj == NULL) - return 0; - - RADIX_PROCESS_set_obj(RP(), name, empty_obj); - - return 1; -err: - return 0; -} - static int ssl_ctx_select_alpn(SSL *ssl, const unsigned char **out, unsigned char *out_len, const unsigned char *in, unsigned int in_len, @@ -160,6 +142,45 @@ static int ssl_attach_bio_dgram(SSL *ssl, return 1; } +/* + * Test to make sure that SSL_accept_connection returns the same ssl object + * that is used in the various TLS callbacks + * + * Unlike TCP, QUIC processes new connections independently from their + * acceptance, and so we need to pre-allocate tls objects to return during + * connection acceptance via the user_ssl. This is just a quic test to validate + * that: + * 1) The new callback to inform the user of a new pending ssl acceptance works + * properly + * 2) That the object returned from SSL_accept_connection matches the one passed + * to various callbacks + * + * It would be better as its own test, but currently the tserver used in the + * other quic_tests doesn't actually accept connections (it pre-creates them + * and fixes them up in place), so testing there is not feasible at the moment + * + * For details on this issue see: + * https://github.com/openssl/project/issues/918 + */ +static SSL *pending_ssl_obj = NULL; +static SSL *client_hello_ssl_obj = NULL; +static int check_pending_match = 0; +static int pending_cb_called = 0; +static int hello_cb_called = 0; +static int new_pending_cb(SSL_CTX *ctx, SSL *new_ssl, void *arg) +{ + pending_ssl_obj = new_ssl; + pending_cb_called = 1; + return 1; +} + +static int client_hello_cb(SSL *s, int *al, void *arg) +{ + client_hello_ssl_obj = s; + hello_cb_called = 1; + return 1; +} + DEF_FUNC(hf_new_ssl) { int ok = 0; @@ -194,6 +215,9 @@ DEF_FUNC(hf_new_ssl) goto err; } else if (is_server) { + SSL_CTX_set_new_pending_conn_cb(ctx, new_pending_cb, NULL); + SSL_CTX_set_client_hello_cb(ctx, client_hello_cb, NULL); + check_pending_match = 1; if (!TEST_ptr(ssl = SSL_new_listener(ctx, 0))) goto err; } else { @@ -204,11 +228,6 @@ DEF_FUNC(hf_new_ssl) if (!is_domain && !TEST_true(ssl_attach_bio_dgram(ssl, 0, NULL))) goto err; - if (!TEST_true(ossl_quic_set_override_now_cb(ssl, get_time, NULL))) { - SSL_free(ssl); - goto err; - } - if (!TEST_true(RADIX_PROCESS_set_ssl(RP(), name, ssl))) { SSL_free(ssl); goto err; @@ -271,37 +290,27 @@ err: return ok; } -#define OP_F_REPLACE_STREAM 0x8000000000000000 -#define OP_F_MASK 0x7fffffffffffffff - DEF_FUNC(hf_new_stream) { int ok = 0; - int replace; - RADIX_OBJ *stream_obj; const char *stream_name; - SSL *conn, *stream, *old; + SSL *conn, *stream; uint64_t flags, do_accept; F_POP2(flags, do_accept); F_POP(stream_name); REQUIRE_SSL(conn); - replace = ((OP_F_REPLACE_STREAM & flags) != 0); - stream_obj = RADIX_PROCESS_get_obj(RP(), stream_name); - if (replace == 0) { - if (!TEST_ptr_null(stream_obj)) - goto err; - } else if (TEST_ptr_null(stream_obj)) + if (!TEST_ptr_null(RADIX_PROCESS_get_obj(RP(), stream_name))) goto err; if (do_accept) { - stream = SSL_accept_stream(conn, flags & OP_F_MASK); + stream = SSL_accept_stream(conn, flags); if (stream == NULL) F_SPIN_AGAIN(); } else { - stream = SSL_new_stream(conn, flags & OP_F_MASK); + stream = SSL_new_stream(conn, flags); } if (!TEST_ptr(stream)) @@ -309,14 +318,8 @@ DEF_FUNC(hf_new_stream) /* TODO(QUIC RADIX): Implement wait behaviour */ - if (stream_obj != NULL) { - ossl_crypto_mutex_lock(stream_obj->mx); - old = stream_obj->ssl; - stream_obj->ssl = stream; - stream = NULL; - ossl_crypto_mutex_unlock(stream_obj->mx); - SSL_free(old); - } else if (!TEST_true(RADIX_PROCESS_set_ssl(RP(), stream_name, stream))) { + if (stream != NULL + && !TEST_true(RADIX_PROCESS_set_ssl(RP(), stream_name, stream))) { SSL_free(stream); goto err; } @@ -347,8 +350,24 @@ DEF_FUNC(hf_accept_conn) SSL_free(conn); goto err; } - radix_activate_obj(RADIX_PROCESS_get_obj(RP(), conn_name)); + if (check_pending_match) { + if (!pending_cb_called || !hello_cb_called) { + TEST_info("Callbacks not called, skipping user_ssl check\n"); + } else { + if (!TEST_ptr_eq(pending_ssl_obj, client_hello_ssl_obj)) { + SSL_free(conn); + goto err; + } + if (!TEST_ptr_eq(pending_ssl_obj, conn)) { + SSL_free(conn); + goto err; + } + } + pending_ssl_obj = client_hello_ssl_obj = NULL; + check_pending_match = 0; + pending_cb_called = hello_cb_called = 0; + } ok = 1; err: return ok; @@ -728,6 +747,54 @@ err: return ok; } +DEF_FUNC(hf_detach) +{ + int ok = 0; + const char *conn_name, *stream_name; + SSL *conn, *stream; + + F_POP2(conn_name, stream_name); + if (!TEST_ptr(conn = RADIX_PROCESS_get_ssl(RP(), conn_name))) + goto err; + + if (!TEST_ptr(stream = ossl_quic_detach_stream(conn))) + goto err; + + if (!TEST_true(RADIX_PROCESS_set_ssl(RP(), stream_name, stream))) { + SSL_free(stream); + goto err; + } + + ok = 1; +err: + return ok; +} + +DEF_FUNC(hf_attach) +{ + int ok = 0; + const char *conn_name, *stream_name; + SSL *conn, *stream; + + F_POP2(conn_name, stream_name); + + if (!TEST_ptr(conn = RADIX_PROCESS_get_ssl(RP(), conn_name))) + goto err; + + if (!TEST_ptr(stream = RADIX_PROCESS_get_ssl(RP(), stream_name))) + goto err; + + if (!TEST_true(ossl_quic_attach_stream(conn, stream))) + goto err; + + if (!TEST_true(RADIX_PROCESS_set_ssl(RP(), stream_name, NULL))) + goto err; + + ok = 1; +err: + return ok; +} + DEF_FUNC(hf_expect_fin) { int ok = 0, ret; @@ -964,99 +1031,10 @@ err: return ok; } -DEF_FUNC(hf_override_key_update) -{ - int ok = 0; - SSL *ssl; - uint64_t threshold; - QUIC_CHANNEL *ch; - - F_POP(threshold); - REQUIRE_SSL(ssl); - ch = ossl_quic_conn_get_channel(ssl); - ossl_quic_channel_set_txku_threshold_override(ch, threshold); - ok = 1; -err: - return ok; -} - -DEF_FUNC(hf_check_key_update_ge) -{ - int ok = 0; - SSL *ssl; - uint64_t min_rxke, txke, rxke; - int64_t diff; - QUIC_CHANNEL *ch; - - F_POP(min_rxke); - REQUIRE_SSL(ssl); - ch = ossl_quic_conn_get_channel(ssl); - txke = ossl_quic_channel_get_tx_key_epoch(ch); - rxke = ossl_quic_channel_get_rx_key_epoch(ch); - diff = (int64_t)txke - (int64_t)rxke; - - /* - * TXKE must always be equal to or ahead of RXKE. - * It can be ahead of RXKE by at most 1. - */ - if (!TEST_int64_t_ge(diff, 0) || !TEST_int64_t_le(diff, 1)) - goto err; - - /* Caller specifies a minimum number of RXKEs which must have happened. */ - if (!TEST_uint64_t_ge(rxke, min_rxke)) - goto err; - - ok = 1; -err: - return ok; -} - -DEF_FUNC(hf_check_key_update_lt) -{ - int ok = 0; - SSL *ssl; - uint64_t max_txke, txke; - QUIC_CHANNEL *ch; - - F_POP(max_txke); - REQUIRE_SSL(ssl); - ch = ossl_quic_conn_get_channel(ssl); - txke = ossl_quic_channel_get_tx_key_epoch(ch); - - /* Caller specifies a maximum number of TXKEs which must not be exceeded. */ - if (!TEST_uint64_t_lt(txke, max_txke)) - goto err; - - ok = 1; -err: - return ok; -} - -DEF_FUNC(hf_trigger_key_update) -{ - int ok = 0; - SSL *ssl; - uint64_t update_type; - - F_POP(update_type); - REQUIRE_SSL(ssl); - - if (!TEST_true(SSL_key_update(ssl, (int)update_type))) - goto err; - - ok = 1; -err: - return ok; -} - #define OP_UNBIND(name) \ (OP_PUSH_PZ(#name), \ OP_FUNC(hf_unbind)) -#define OP_BIND(name) \ - (OP_PUSH_PZ(#name), \ - OP_FUNC(hf_bind)) - #define OP_SELECT_SSL(slot, name) \ (OP_PUSH_U64(slot), \ OP_PUSH_PZ(#name), \ @@ -1139,10 +1117,8 @@ err: OP_PUSH_U64(1), \ OP_FUNC(hf_new_stream)) -#define OP_ACCEPT_STREAM_NONE(conn_name, flags) \ - (OP_SELECT_SSL(0, conn_name), \ - OP_PUSH_PZ(#conn_name), \ - OP_PUSH_U64(flags), \ +#define OP_ACCEPT_STREAM_NONE(conn_name) \ + (OP_SELECT_SSL(0, conn_name), \ OP_FUNC(hf_accept_stream_none)) #define OP_ACCEPT_CONN_WAIT(listener_name, conn_name, flags) \ @@ -1202,15 +1178,15 @@ err: #define OP_READ_EXPECT_B(name, buf) \ OP_READ_EXPECT(name, (buf), sizeof(buf)) -#define OP_READ_FAIL(name) \ +#define OP_READ_FAIL() \ (OP_SELECT_SSL(0, name), \ OP_PUSH_U64(0), \ OP_FUNC(hf_read_fail)) #define OP_READ_FAIL_WAIT(name) \ - (OP_SELECT_SSL(0, name), \ - OP_PUSH_U64(1), \ - OP_FUNC(hf_read_fail)) + (OP_SELECT_SSL(0, name), \ + OP_PUSH_U64(1), \ + OP_FUNC(hf_read_fail) #define OP_POP_ERR() \ OP_FUNC(hf_pop_err) @@ -1228,7 +1204,7 @@ err: #define OP_STREAM_RESET(name, error_code) \ (OP_SELECT_SSL(0, name), \ - OP_PUSH_PZ(#name), \ + OP_PUSH_U64(flags), \ OP_PUSH_U64(error_code), \ OP_FUNC(hf_stream_reset)) @@ -1239,6 +1215,16 @@ err: OP_PUSH_PZ(reason), \ OP_FUNC(hf_shutdown_wait)) +#define OP_DETACH(conn_name, stream_name) \ + (OP_SELECT_SSL(0, conn_name), \ + OP_PUSH_PZ(#stream_name), \ + OP_FUNC(hf_detach)) + +#define OP_ATTACH(conn_name, stream_name) \ + (OP_SELECT_SSL(0, conn_name), \ + OP_PUSH_PZ(stream_name), \ + OP_FUNC(hf_attach)) + #define OP_EXPECT_FIN(name) \ (OP_SELECT_SSL(0, name), \ OP_FUNC(hf_expect_fin)) @@ -1275,23 +1261,3 @@ err: #define OP_SLEEP(ms) \ (OP_PUSH_U64(ms), \ OP_FUNC(hf_sleep)) - -#define OP_OVERRIDE_KEY_UPDATE(name, threshold) \ - (OP_SELECT_SSL(0, name), \ - OP_PUSH_U64(threshold), \ - OP_FUNC(hf_override_key_update)) - -#define OP_CHECK_KEY_UPDATE_GE(name, min_rxke) \ - (OP_SELECT_SSL(0, name), \ - OP_PUSH_U64(min_rxke), \ - OP_FUNC(hf_check_key_update_ge)) - -#define OP_CHECK_KEY_UPDATE_LT(name, max_txke) \ - (OP_SELECT_SSL(0, name), \ - OP_PUSH_U64(max_txke), \ - OP_FUNC(hf_check_key_update_lt)) - -#define OP_TRIGGER_KEY_UPDATE(name, update_type) \ - (OP_SELECT_SSL(0, name), \ - OP_PUSH_U64(update_type), \ - OP_FUNC(hf_trigger_key_update)) diff --git a/test/radix/quic_tests.c b/test/radix/quic_tests.c index 154926a16f..c0e54825ca 100644 --- a/test/radix/quic_tests.c +++ b/test/radix/quic_tests.c @@ -7,8 +7,6 @@ * https://www.openssl.org/source/license.html */ -#include "internal/quic_stream_map.h" - #if defined(_AIX) /* * Some versions of AIX define macros for events and revents for use when @@ -24,145 +22,6 @@ * ============================================================================ */ -DEF_FUNC(check_rejected) -{ - QUIC_CHANNEL *ch; - SSL *ssl, *stream; - QUIC_STREAM *qs; - uint64_t stream_id; - int ok = 0; - - REQUIRE_SSL_2(ssl, stream); - ch = ossl_quic_conn_get_channel(ssl); - if (!TEST_ptr(ch)) - goto err; - - stream_id = SSL_get_stream_id(stream); - qs = ossl_quic_stream_map_get_by_id(ossl_quic_channel_get_qsm(ch), stream_id); - if (!TEST_ptr(qs)) - goto err; - - if (qs->peer_stop_sending) - ok = 1; - else - F_SPIN_AGAIN(); - -err: - - return ok; -} - -/* - * Multi-stream test - */ -DEF_SCRIPT(multi_stream, "multi stream test") -{ - OP_SIMPLE_PAIR_CONN(); - OP_WRITE_B(C, "apple"); - OP_ACCEPT_CONN_WAIT(L, S, 0); - OP_SET_INCOMING_STREAM_POLICY(C, SSL_INCOMING_STREAM_POLICY_ACCEPT, 42 /* error code */); - OP_SET_INCOMING_STREAM_POLICY(S, SSL_INCOMING_STREAM_POLICY_ACCEPT, 42 /* error code */); - OP_READ_EXPECT_B(S, "apple"); - OP_WRITE_B(S, "orange"); - OP_READ_EXPECT_B(C, "orange"); - - OP_NEW_STREAM(C, C0, 0 /* bidirectional stream */); - OP_WRITE_B(C0, "flamingo"); - OP_ACCEPT_STREAM_WAIT(S, S0, 0 /* bidirectional stream */); - OP_READ_EXPECT_B(S0, "flamingo"); - OP_CONCLUDE(C0); - OP_EXPECT_FIN(S0); - OP_WRITE_B(S0, "gargoyle"); - OP_READ_EXPECT_B(C0, "gargoyle"); - OP_CONCLUDE(S0); - OP_EXPECT_FIN(C0); - - OP_NEW_STREAM(C, C1, SSL_STREAM_FLAG_UNI); - OP_WRITE_B(C1, "elephant"); - OP_ACCEPT_STREAM_WAIT(S, S1, SSL_STREAM_FLAG_UNI); - OP_READ_EXPECT_B(S1, "elephant"); - OP_CONCLUDE(C1); - OP_EXPECT_FIN(S1); - OP_READ_FAIL(S1); - OP_WRITE_FAIL(S1); - - OP_ACCEPT_STREAM_NONE(C, SSL_STREAM_FLAG_UNI); - - OP_NEW_STREAM(S, S2, 0 /* bidirectional stream */); - OP_WRITE_B(S2, "frog"); - OP_ACCEPT_STREAM_WAIT(C, C2, 0 /* bidirectional stream */); - OP_READ_EXPECT_B(C2, "frog"); - OP_CONCLUDE(S2); - OP_EXPECT_FIN(C2); - - OP_ACCEPT_STREAM_NONE(C, 0); - - OP_NEW_STREAM(S, S3, 0 /* bidirectional stream */); - OP_WRITE_B(S3, "mixture"); - OP_CONCLUDE(S3); - - OP_ACCEPT_STREAM_WAIT(C, C3, 0 /* bidirectional stream */); - OP_READ_EXPECT_B(C3, "mixture"); - OP_EXPECT_FIN(C3); - OP_WRITE_B(C3, "ramble"); - OP_READ_EXPECT_B(S3, "ramble"); - OP_CONCLUDE(C3); - OP_EXPECT_FIN(S3); - - OP_NEW_STREAM(S, S4, SSL_STREAM_FLAG_UNI); - OP_WRITE_B(S4, "yonder"); - OP_CONCLUDE(S4); - OP_ACCEPT_STREAM_WAIT(C, C4, SSL_STREAM_FLAG_UNI); - OP_ACCEPT_STREAM_NONE(C, SSL_STREAM_FLAG_UNI); - OP_READ_EXPECT_B(C4, "yonder"); - OP_EXPECT_FIN(C4); - OP_WRITE_FAIL(C4); - - OP_SET_INCOMING_STREAM_POLICY(C, SSL_INCOMING_STREAM_POLICY_REJECT, 42 /* application error code */); - OP_NEW_STREAM(S, S5, 0 /* bidirectional stream */); - OP_WRITE_B(S5, "unseen"); - OP_ACCEPT_STREAM_NONE(C, 0); - OP_SELECT_SSL(0, S); - OP_SELECT_SSL(1, S5); - /* - * Stream S5 is rejected because of reject policy on client side. - */ - OP_FUNC(check_rejected); - - OP_SET_INCOMING_STREAM_POLICY(C, SSL_INCOMING_STREAM_POLICY_AUTO, 0 /* app. error code */); - OP_NEW_STREAM(S, S6, 0 /* bidirectional stream */); - OP_WRITE_B(S6, "UNSEEN"); - OP_ACCEPT_STREAM_NONE(C, 0); - OP_SELECT_SSL(0, S); - OP_SELECT_SSL(1, S6); - /* - * Remember the client `C` and server `S` got created by - * OP_SIMPLE_PAIR_CON() which creates QUIC connection objects switched to - * default (implicit) stream mode (see SSL_set_default_stream_mode(3ossl)). - * The stream policy on client `C` is AUTO now which in combination with - * default stream mode makes `C` to reject incoming stream `S6` - * (see SSL_set_incoming_stream_policy(3ossl) for details). - */ - OP_FUNC(check_rejected); -} - -/* - * Simple single-stream test - */ -DEF_SCRIPT(simple_stream, "single stream test") -{ - OP_SIMPLE_PAIR_CONN(); - OP_WRITE_B(C, "apple"); - OP_ACCEPT_CONN_WAIT(L, S, 0); - OP_CONCLUDE(C); - OP_READ_EXPECT_B(S, "apple"); - OP_EXPECT_FIN(S); - OP_WRITE_B(S, "orange"); - OP_READ_EXPECT_B(C, "orange"); - OP_CONCLUDE(S); - OP_EXPECT_FIN(C); -} - /* * Test: simple_conn * ----------------- @@ -435,1481 +294,13 @@ DEF_SCRIPT(check_cwm, "check stream obeys cwm") OP_WRITE_FAIL(C); } -struct mutcbk_ctx { - QUIC_PKT_HDR mutctx_qhdrin; - OSSL_QTX_IOVEC mutctx_iov; - const unsigned char *mutctx_inject; - size_t mutctx_inject_sz; - int mutctx_done; -}; - -static int mutcbk_inject_frames(const QUIC_PKT_HDR *hdrin, - const OSSL_QTX_IOVEC *iovecin, size_t numin, QUIC_PKT_HDR **hdrout, - const OSSL_QTX_IOVEC **iovecout, size_t *numout, void *arg) -{ - struct mutcbk_ctx *mutctx = (struct mutcbk_ctx *)arg; - size_t i; - size_t grow_allowance = 1200; /* QUIC_MIN_INITIAL_DGRAM_LEN */ - size_t bufsz = 0; - char *buf; - - /* - * make injection callback a one shot event, - * callback is invoked for every packet we - * want to modify only one packet here. - */ - if (mutctx->mutctx_done) - return 0; - - mutctx->mutctx_done = 1; - - for (i = 0; i < numin; i++) - bufsz += iovecin[i].buf_len; - - mutctx->mutctx_iov.buf_len = bufsz; /* keeps old size */ - grow_allowance -= (bufsz < grow_allowance) ? bufsz : grow_allowance; - /* AEAD tag (16 bytes) + long header (14 bytes) */ - grow_allowance -= (30 < grow_allowance) ? 30 : grow_allowance; - - grow_allowance -= (hdrin->dst_conn_id.id_len < grow_allowance) ? hdrin->dst_conn_id.id_len : grow_allowance; - grow_allowance -= (hdrin->src_conn_id.id_len < grow_allowance) ? hdrin->src_conn_id.id_len : grow_allowance; - - if (grow_allowance == 0) { - TEST_info("%s not enough space to inject", __func__); - return 0; - } - bufsz += grow_allowance; - - /* discard const */ - OPENSSL_free((char *)mutctx->mutctx_iov.buf); - mutctx->mutctx_iov.buf = OPENSSL_malloc(bufsz); - /* discard const */ - buf = (char *)mutctx->mutctx_iov.buf; - if (buf == NULL) { - TEST_info("%s OPENSSL_malloc() failed", __func__); - return 0; - } - - for (i = 0; i < numin; i++) { - memcpy(buf, iovecin[i].buf, iovecin[i].buf_len); - buf += iovecin[i].buf_len; - } - - /* discard const */ - buf = (char *)mutctx->mutctx_iov.buf; - if (mutctx->mutctx_inject != NULL) { - memmove(buf + mutctx->mutctx_inject_sz, buf, - mutctx->mutctx_iov.buf_len); - memcpy(buf, mutctx->mutctx_inject, mutctx->mutctx_inject_sz); - } - /* - * perhaps needed to have not looked at yet - */ - mutctx->mutctx_qhdrin = *hdrin; - *hdrout = &mutctx->mutctx_qhdrin; - mutctx->mutctx_iov.buf_len += mutctx->mutctx_inject_sz; - *iovecout = &mutctx->mutctx_iov; - *numout = 1; - - return 1; -} - -static void mutcbk_finish_injecct_frames(void *arg) -{ - struct mutcbk_ctx *mutctx = (struct mutcbk_ctx *)arg; - - OPENSSL_free((char *)mutctx->mutctx_iov.buf); - mutctx->mutctx_iov.buf = NULL; -} - -/* 16 path challenge frames */ -#define PATH_CHALLENGE_FRAMES \ - "\x1a" \ - "ABCDEFGH" \ - "\x1a" \ - "ABCDEFGH" \ - "\x1a" \ - "ABCDEFGH" \ - "\x1a" \ - "ABCDEFGH" \ - "\x1a" \ - "ABCDEFGH" \ - "\x1a" \ - "ABCDEFGH" \ - "\x1a" \ - "ABCDEFGH" \ - "\x1a" \ - "ABCDEFGH" \ - "\x1a" \ - "ABCDEFGH" \ - "\x1a" \ - "ABCDEFGH" \ - "\x1a" \ - "ABCDEFGH" \ - "\x1a" \ - "ABCDEFGH" \ - "\x1a" \ - "ABCDEFGH" \ - "\x1a" \ - "ABCDEFGH" \ - "\x1a" \ - "ABCDEFGH" \ - "\x1a" \ - "ABCDEFGH" - -DEF_FUNC(mount_flood) -{ - int ok = 0; - SSL *ssl; - QUIC_CHANNEL *ch; - static struct mutcbk_ctx mutctx = { 0 }; - static const unsigned char *inject_frames = (const unsigned char *)PATH_CHALLENGE_FRAMES; - - mutctx.mutctx_inject = inject_frames; - mutctx.mutctx_inject_sz = sizeof(PATH_CHALLENGE_FRAMES) - 1; - REQUIRE_SSL(ssl); - ch = ossl_quic_conn_get_channel(ssl); - if (!TEST_ptr(ch)) - goto err; - - if (!TEST_true(ossl_quic_channel_set_mutator(ch, mutcbk_inject_frames, - mutcbk_finish_injecct_frames, &mutctx))) - goto err; - ok = 1; -err: - return ok; -} - -DEF_FUNC(check_flood_stats) -{ - int ok = 0; - SSL *ssl; - QUIC_CHANNEL *ch; - uint64_t path_response_count; - uint64_t path_challenge_count; - - REQUIRE_SSL(ssl); - ch = ossl_quic_conn_get_channel(ssl); - if (!TEST_ptr(ch)) - goto err; - - path_challenge_count = ossl_quic_channel_get_path_challenge_count(ch); - path_response_count = ossl_quic_channel_get_path_response_count(ch); - - /* - * The flood is delivered over a real socket and processed by the - * connection's assist thread asynchronously, so give it a chance to - * catch up rather than failing on the first observation. - */ - if (path_challenge_count < 16 || path_response_count < 1) - F_SPIN_AGAIN(); - - if (!TEST_uint64_t_eq(path_challenge_count, 16)) - goto err; - if (!TEST_uint64_t_eq(path_response_count, 1)) - goto err; - - ok = 1; -err: - return ok; -} - -DEF_SCRIPT(check_pc_flood, "check path challenge flood") -{ - OP_SIMPLE_PAIR_CONN(); - OP_SELECT_SSL(0, C); - OP_FUNC(mount_flood); - OP_ACCEPT_CONN_WAIT(L, S, 0); - OP_WRITE_B(C, "attack"); - OP_SELECT_SSL(0, S); - OP_FUNC(check_flood_stats); -} - -/* - * Test to make sure that SSL_accept_connection returns the same ssl object - * that is used in the various TLS callbacks - * - * Unlike TCP, QUIC processes new connections independently from their - * acceptance, and so we need to pre-allocate tls objects to return during - * connection acceptance via the user_ssl. This is just a quic test to validate - * that: - * 1) The new callback to inform the user of a new pending ssl acceptance works - * properly - * 2) That the object returned from SSL_accept_connection matches the one passed - * to various callbacks - * - * It would be better as its own test, but currently the tserver used in the - * other quic_tests doesn't actually accept connections (it pre-creates them - * and fixes them up in place), so testing there is not feasible at the moment - * - * For details on this issue see: - * https://github.com/openssl/project/issues/918 - */ -static SSL *pending_ssl_obj = NULL; -static SSL *client_hello_ssl_obj = NULL; -static int check_pending_match = 0; -static int pending_cb_called = 0; -static int hello_cb_called = 0; - -static int new_pending_cb(SSL_CTX *ctx, SSL *new_ssl, void *arg) -{ - pending_ssl_obj = new_ssl; - pending_cb_called = 1; - return 1; -} - -static int client_hello_cb(SSL *s, int *al, void *arg) -{ - client_hello_ssl_obj = s; - hello_cb_called = 1; - return 1; -} - -DEF_FUNC(init_pending_test) -{ - pending_ssl_obj = NULL; - client_hello_ssl_obj = NULL; - check_pending_match = 0; - pending_cb_called = 0; - hello_cb_called = 0; - - return 1; -} - -DEF_FUNC(check_pending) -{ - int ok = 0; - SSL *conn; - - REQUIRE_SSL(conn); - - if (check_pending_match) { - if (!TEST_true(pending_cb_called)) - goto err; - - if (!TEST_true(hello_cb_called)) - goto err; - - if (!TEST_ptr_eq(pending_ssl_obj, client_hello_ssl_obj)) - goto err; - - if (!TEST_ptr_eq(pending_ssl_obj, conn)) - goto err; - - pending_ssl_obj = client_hello_ssl_obj = NULL; - check_pending_match = 0; - pending_cb_called = hello_cb_called = 0; - } - - ok = 1; -err: - return ok; -} - -DEF_FUNC(new_listener) -{ - int ok = 0; - SSL_CTX *ctx = NULL; - SSL *listener; - const char *name; - - F_POP(name); - - if (!TEST_ptr(ctx = SSL_CTX_new(OSSL_QUIC_server_method()))) - goto err; - -#if defined(OPENSSL_THREADS) - if (!TEST_true(SSL_CTX_set_domain_flags(ctx, - SSL_DOMAIN_FLAG_MULTI_THREAD - | SSL_DOMAIN_FLAG_BLOCKING))) - goto err; -#endif - - if (!TEST_true(ssl_ctx_configure(ctx, 1))) - goto err; - - SSL_CTX_set_new_pending_conn_cb(ctx, new_pending_cb, NULL); - SSL_CTX_set_client_hello_cb(ctx, client_hello_cb, NULL); - check_pending_match = 1; - if (!TEST_ptr(listener = SSL_new_listener(ctx, 0))) - goto err; - - if (!TEST_true(ssl_attach_bio_dgram(listener, 0, NULL))) { - SSL_free(listener); - goto err; - } - - if (!TEST_true(RADIX_PROCESS_set_ssl(RP(), name, listener))) { - SSL_free(listener); - goto err; - } - - ok = 1; -err: - /* SSL object will hold ref, we don't need it */ - SSL_CTX_free(ctx); - return ok; -} - -DEF_SCRIPT(check_ctx_cbks, "Check new_pending and client_hello callbacks") -{ - OP_FUNC(init_pending_test); - OP_PUSH_PZ("L"); - OP_FUNC(new_listener); - OP_LISTEN(L); - OP_NEW_SSL_C(C); - OP_SET_PEER_ADDR_FROM(C, L); - OP_CONNECT_WAIT(C); - OP_ACCEPT_CONN_WAIT(L, S, 0); - OP_SELECT_SSL(0, S); - OP_FUNC(check_pending); -} - -DEF_FUNC(check_stream_reset_5) -{ - int ok = 0; - SSL *ssl; - uint64_t aec = 0; - int state; - - REQUIRE_SSL(ssl); - - state = SSL_get_stream_read_state(ssl); - if (state != SSL_STREAM_STATE_RESET_REMOTE) - F_SPIN_AGAIN(); - - if (!TEST_true(SSL_get_stream_read_error_code(ssl, &aec))) - goto err; - - if (!TEST_uint64_t_eq(aec, 42)) - goto err; - - ok = 1; -err: - return ok; -} - -/* - * script_5 - script_106 are place holders for tests we - * currently keep in test/quic_multistream_test.c. - * We need to move those here so we can get rid off - * QUIC T-server mock-up. - * - * there should be one PR for each script being moved here, - * to make reviewer's life easier. Once all scripts will be - * moved we can find better names for script_5, ..., script_106. - * - * The scaffolding here hopes to avoid conflicts in 'scripts' - * array below when more PRs will be in flight. - */ - -/* 5. Test stream reset functionality */ -DEF_SCRIPT(script_5, "Test stream reset functionality") -{ - OP_SIMPLE_PAIR_CONN_ND(); - - OP_NEW_STREAM(C, Ca, 0 /* bidirectional */); - OP_NEW_STREAM(C, Cb, 0 /* bidirectional */); - - OP_WRITE(Ca, "apple", 5); - OP_STREAM_RESET(Ca, 42); - - OP_WRITE(Cb, "strawberry", 10); - - OP_ACCEPT_CONN_WAIT_ND(L, S, 0); - OP_ACCEPT_STREAM_WAIT(S, Sa, 0); /* first stream = Ca */ - OP_ACCEPT_STREAM_WAIT(S, Sb, 0); /* second stream = Cb */ - - /* Reset disrupts read of already-sent data */ - OP_SELECT_SSL(0, Sa); - OP_FUNC(check_stream_reset_5); - - OP_READ_EXPECT(Sb, "strawberry", 10); -} - -DEF_FUNC(check_stream_stopped_6) -{ - int ok = 0; - SSL *ssl; - - REQUIRE_SSL(ssl); - - if (SSL_get_stream_write_state(ssl) != SSL_STREAM_STATE_RESET_LOCAL) - F_SPIN_AGAIN(); - - ok = 1; -err: - return ok; -} - -/* 6. Test STOP_SENDING functionality */ -DEF_SCRIPT(script_6, "Test STOP_SENDING functionality") -{ - OP_SIMPLE_PAIR_CONN_ND(); - OP_ACCEPT_CONN_WAIT_ND(L, S, 0); - - OP_NEW_STREAM(S, Sa, 0 /* bidirectional */); - OP_WRITE(Sa, "apple", 5); - - OP_ACCEPT_STREAM_WAIT(C, Ca, 0); - OP_UNBIND(Ca); - OP_ACCEPT_STREAM_NONE(C, 0); - - OP_SELECT_SSL(0, Sa); - OP_FUNC(check_stream_stopped_6); -} - -/* 7. Unidirectional default stream mode test (client sends first) */ -DEF_SCRIPT(script_7, "Unidirectional default stream mode (client sends first)") -{ - OP_SIMPLE_PAIR_CONN(); - OP_SET_DEFAULT_STREAM_MODE(C, SSL_DEFAULT_STREAM_MODE_AUTO_UNI); - OP_WRITE(C, "apple", 5); - - OP_ACCEPT_CONN_WAIT(L, S, 0); - OP_READ_EXPECT(S, "apple", 5); - OP_WRITE_FAIL(S); -} - -/* 8. Unidirectional default stream mode test (server sends first) */ -DEF_SCRIPT(script_8, "Unidirectional default stream mode (server sends first)") -{ - OP_SIMPLE_PAIR_CONN(); - OP_SET_DEFAULT_STREAM_MODE(C, SSL_DEFAULT_STREAM_MODE_AUTO_UNI); - - OP_ACCEPT_CONN_WAIT(L, S, 0); - OP_NEW_STREAM(S, Sa, SSL_STREAM_FLAG_UNI); - OP_WRITE(Sa, "apple", 5); - - OP_READ_EXPECT(C, "apple", 5); - OP_WRITE_FAIL(C); -} - -/* 9. Unidirectional default stream mode test (server sends first on bidi) */ -DEF_SCRIPT(script_9, "Unidirectional default stream mode (server sends bidi first)") -{ - OP_SIMPLE_PAIR_CONN(); - OP_SET_DEFAULT_STREAM_MODE(C, SSL_DEFAULT_STREAM_MODE_AUTO_UNI); - - OP_ACCEPT_CONN_WAIT(L, S, 0); - OP_NEW_STREAM(S, Sa, 0 /* bidirectional */); - OP_WRITE(Sa, "apple", 5); - - OP_READ_EXPECT(C, "apple", 5); - OP_WRITE(C, "orange", 6); - OP_READ_EXPECT(Sa, "orange", 6); -} - -/* 10. Shutdown */ -DEF_SCRIPT(script_10, "Shutdown test") -{ - OP_SIMPLE_PAIR_CONN(); - - OP_WRITE(C, "apple", 5); - OP_ACCEPT_CONN_WAIT(L, S, 0); - OP_READ_EXPECT(S, "apple", 5); - - OP_SHUTDOWN_WAIT(C, 0, 0, NULL); - OP_EXPECT_CONN_CLOSE_INFO(C, 0, 1, 0); - OP_EXPECT_CONN_CLOSE_INFO(S, 0, 1, 1); -} - -/* 11. Many threads accepted on the same client connection */ -DEF_SCRIPT(script_11_child_0, - "child: accept stream from C, read, sleep, expect FIN") -{ - OP_ACCEPT_STREAM_WAIT(C, C0, OP_F_REPLACE_STREAM /* bidirectional */); - OP_READ_EXPECT_B(C0, "foo"); - OP_SLEEP(10); - OP_EXPECT_FIN(C0); -} - -DEF_SCRIPT(script_11_child_1, - "child: accept stream from C, read, sleep, expect FIN") -{ - OP_ACCEPT_STREAM_WAIT(C, C1, OP_F_REPLACE_STREAM /* bidirectional */); - OP_READ_EXPECT_B(C1, "foo"); - OP_SLEEP(10); - OP_EXPECT_FIN(C1); -} - -DEF_SCRIPT(script_11_child_2, - "child: accept stream from C, read, sleep, expect FIN") -{ - OP_ACCEPT_STREAM_WAIT(C, C2, OP_F_REPLACE_STREAM /* bidirectional */); - OP_READ_EXPECT_B(C2, "foo"); - OP_SLEEP(10); - OP_EXPECT_FIN(C2); -} - -DEF_SCRIPT(script_11_child_3, - "child: accept stream from C, read, sleep, expect FIN") -{ - OP_ACCEPT_STREAM_WAIT(C, C3, OP_F_REPLACE_STREAM /* bidirectional */); - OP_READ_EXPECT_B(C3, "foo"); - OP_SLEEP(10); - OP_EXPECT_FIN(C3); -} - -DEF_SCRIPT(script_11_child_4, - "child: accept stream from C, read, sleep, expect FIN") -{ - OP_ACCEPT_STREAM_WAIT(C, C4, OP_F_REPLACE_STREAM /* bidirectional */); - OP_READ_EXPECT_B(C4, "foo"); - OP_SLEEP(10); - OP_EXPECT_FIN(C4); -} - -DEF_SCRIPT(script_11, "Many threads accepted on the same client connection") -{ - OP_SIMPLE_PAIR_CONN_ND(); - OP_ACCEPT_CONN_WAIT(L, S, 0); - - OP_BIND(C0); - OP_BIND(C1); - OP_BIND(C2); - OP_BIND(C3); - OP_BIND(C4); - OP_BIND(Sa); - OP_BIND(Sb); - OP_BIND(Sc); - OP_BIND(Sd); - OP_BIND(Se); - - OP_SPAWN_THREAD(script_11_child_0); - OP_SPAWN_THREAD(script_11_child_1); - OP_SPAWN_THREAD(script_11_child_2); - OP_SPAWN_THREAD(script_11_child_3); - OP_SPAWN_THREAD(script_11_child_4); - - OP_NEW_STREAM(S, Sa, OP_F_REPLACE_STREAM /* bidirectional */); - OP_WRITE_B(Sa, "foo"); - OP_CONCLUDE(Sa); - - OP_NEW_STREAM(S, Sb, OP_F_REPLACE_STREAM /* bidirectional */); - OP_WRITE_B(Sb, "foo"); - OP_CONCLUDE(Sb); - - OP_NEW_STREAM(S, Sc, OP_F_REPLACE_STREAM /* bidirectional */); - OP_WRITE_B(Sc, "foo"); - OP_CONCLUDE(Sc); - - OP_NEW_STREAM(S, Sd, OP_F_REPLACE_STREAM /* bidirectional */); - OP_WRITE_B(Sd, "foo"); - OP_CONCLUDE(Sd); - - OP_NEW_STREAM(S, Se, OP_F_REPLACE_STREAM /* bidirectional */); - OP_WRITE_B(Se, "foo"); - OP_CONCLUDE(Se); - OP_SLEEP(10); -} - -/* 12. Many threads initiated on the same client connection */ -DEF_SCRIPT(script_12_child_0, - "child: create stream on C, write, conclude") -{ - OP_NEW_STREAM(C, C0, OP_F_REPLACE_STREAM /* bidirectional */); - OP_WRITE_B(C0, "foo"); - OP_CONCLUDE(C0); -} - -DEF_SCRIPT(script_12_child_1, - "child: create stream on C, write, conclude") -{ - OP_NEW_STREAM(C, C1, OP_F_REPLACE_STREAM /* bidirectional */); - OP_WRITE_B(C1, "foo"); - OP_CONCLUDE(C1); -} - -DEF_SCRIPT(script_12_child_2, - "child: create stream on C, write, conclude") -{ - OP_NEW_STREAM(C, C2, OP_F_REPLACE_STREAM /* bidirectional */); - OP_WRITE_B(C2, "foo"); - OP_CONCLUDE(C2); -} - -DEF_SCRIPT(script_12_child_3, - "child: create stream on C, write, conclude") -{ - OP_NEW_STREAM(C, C3, OP_F_REPLACE_STREAM /* bidirectional */); - OP_WRITE_B(C3, "foo"); - OP_CONCLUDE(C3); -} - -DEF_SCRIPT(script_12_child_4, - "child: create stream on C, write, conclude") -{ - OP_NEW_STREAM(C, C4, OP_F_REPLACE_STREAM /* bidirectional */); - OP_WRITE_B(C4, "foo"); - OP_CONCLUDE(C4); -} - -DEF_SCRIPT(script_12, "Many threads initiated on the same client connection") -{ - OP_SIMPLE_PAIR_CONN_ND(); - OP_ACCEPT_CONN_WAIT_ND(L, S, 0); - - OP_BIND(C0); - OP_BIND(C1); - OP_BIND(C2); - OP_BIND(C3); - OP_BIND(C4); - OP_BIND(Sa); - OP_BIND(Sb); - OP_BIND(Sc); - OP_BIND(Sd); - OP_BIND(Se); - - OP_SPAWN_THREAD(script_12_child_0); - OP_SPAWN_THREAD(script_12_child_1); - OP_SPAWN_THREAD(script_12_child_2); - OP_SPAWN_THREAD(script_12_child_3); - OP_SPAWN_THREAD(script_12_child_4); - - OP_ACCEPT_STREAM_WAIT(S, Sa, OP_F_REPLACE_STREAM); - OP_READ_EXPECT_B(Sa, "foo"); - OP_EXPECT_FIN(Sa); - OP_ACCEPT_STREAM_WAIT(S, Sb, OP_F_REPLACE_STREAM); - OP_READ_EXPECT_B(Sb, "foo"); - OP_EXPECT_FIN(Sb); - OP_ACCEPT_STREAM_WAIT(S, Sc, OP_F_REPLACE_STREAM); - OP_READ_EXPECT_B(Sc, "foo"); - OP_EXPECT_FIN(Sc); - OP_ACCEPT_STREAM_WAIT(S, Sd, OP_F_REPLACE_STREAM); - OP_READ_EXPECT_B(Sd, "foo"); - OP_EXPECT_FIN(Sd); - OP_ACCEPT_STREAM_WAIT(S, Se, OP_F_REPLACE_STREAM); - OP_READ_EXPECT_B(Se, "foo"); - OP_EXPECT_FIN(Se); - OP_SLEEP(10); -} - -/* 13. Many threads accepted on the same client connection (stress test) */ -DEF_SCRIPT(script_13_child_1, - "child: 10x accept stream from C, read, expect FIN, free") -{ - size_t i; - - for (i = 0; i < 10; i++) { - OP_ACCEPT_STREAM_WAIT(C, C1, OP_F_REPLACE_STREAM); - OP_READ_EXPECT_B(C1, "foo"); - OP_EXPECT_FIN(C1); - } -} - -DEF_SCRIPT(script_13_child_2, - "child: 10x accept stream from C, read, expect FIN, free") -{ - size_t i; - - for (i = 0; i < 10; i++) { - OP_ACCEPT_STREAM_WAIT(C, C2, OP_F_REPLACE_STREAM); - OP_READ_EXPECT_B(C2, "foo"); - OP_EXPECT_FIN(C2); - } -} - -DEF_SCRIPT(script_13_child_3, - "child: 10x accept stream from C, read, expect FIN, free") -{ - size_t i; - - for (i = 0; i < 10; i++) { - OP_ACCEPT_STREAM_WAIT(C, C3, OP_F_REPLACE_STREAM); - OP_READ_EXPECT_B(C3, "foo"); - OP_EXPECT_FIN(C3); - } -} - -DEF_SCRIPT(script_13_child_4, - "child: 10x accept stream from C, read, expect FIN, free") -{ - size_t i; - - for (i = 0; i < 10; i++) { - OP_ACCEPT_STREAM_WAIT(C, C4, OP_F_REPLACE_STREAM); - OP_READ_EXPECT_B(C4, "foo"); - OP_EXPECT_FIN(C4); - } -} - -DEF_SCRIPT(script_13_child_5, - "child: 10x accept stream from C, read, expect FIN, free") -{ - size_t i; - - for (i = 0; i < 10; i++) { - OP_ACCEPT_STREAM_WAIT(C, C5, OP_F_REPLACE_STREAM); - OP_READ_EXPECT_B(C5, "foo"); - OP_EXPECT_FIN(C5); - } -} - -DEF_SCRIPT(script_13, - "Many threads accepted on same client connection (stress test)") -{ - size_t i; - - OP_SIMPLE_PAIR_CONN_ND(); - OP_ACCEPT_CONN_WAIT_ND(L, S, 0); - - /* - * put empty objects to radix process cache. - * objects C1 - C5 are going to be used for - * SSL streams in _child_1 - _child_5 threads. - */ - OP_BIND(C1); - OP_BIND(C2); - OP_BIND(C3); - OP_BIND(C4); - OP_BIND(C5); - OP_BIND(Sa); - - OP_SPAWN_THREAD(script_13_child_1); - OP_SPAWN_THREAD(script_13_child_2); - OP_SPAWN_THREAD(script_13_child_3); - OP_SPAWN_THREAD(script_13_child_4); - OP_SPAWN_THREAD(script_13_child_5); - - for (i = 0; i < 50; ++i) { - OP_NEW_STREAM(S, Sa, OP_F_REPLACE_STREAM); - OP_WRITE_B(Sa, "foo"); - OP_CONCLUDE(Sa); - } -} - -/* 14. Many threads initiating on the same client connection (stress test) */ -DEF_SCRIPT(script_14_child_1, - "child: 10x create stream on C, write, conclude, free") -{ - size_t i; - - for (i = 0; i < 10; i++) { - OP_NEW_STREAM(C, C1, OP_F_REPLACE_STREAM); - OP_WRITE_B(C1, "foo"); - OP_CONCLUDE(C1); - } -} - -DEF_SCRIPT(script_14_child_2, - "child: 10x create stream on C, write, conclude, free") -{ - size_t i; - - for (i = 0; i < 10; i++) { - OP_NEW_STREAM(C, C2, OP_F_REPLACE_STREAM); - OP_WRITE_B(C2, "foo"); - OP_CONCLUDE(C2); - } -} - -DEF_SCRIPT(script_14_child_3, - "child: 10x create stream on C, write, conclude, free") -{ - size_t i; - - for (i = 0; i < 10; i++) { - OP_NEW_STREAM(C, C3, OP_F_REPLACE_STREAM); - OP_WRITE_B(C3, "foo"); - OP_CONCLUDE(C3); - } -} - -DEF_SCRIPT(script_14_child_4, - "child: 10x create stream on C, write, conclude, free") -{ - size_t i; - - for (i = 0; i < 10; i++) { - OP_NEW_STREAM(C, C4, OP_F_REPLACE_STREAM); - OP_WRITE_B(C4, "foo"); - OP_CONCLUDE(C4); - } -} - -DEF_SCRIPT(script_14_child_5, - "child: 10x create stream on C, write, conclude, free") -{ - size_t i; - - for (i = 0; i < 10; i++) { - OP_NEW_STREAM(C, C5, OP_F_REPLACE_STREAM); - OP_WRITE_B(C5, "foo"); - OP_CONCLUDE(C5); - } -} - -DEF_SCRIPT(script_14, - "Many threads initiating on same client connection (stress test)") -{ - size_t i; - - OP_SIMPLE_PAIR_CONN_ND(); - OP_ACCEPT_CONN_WAIT_ND(L, S, 0); - - OP_BIND(C1); - OP_BIND(C2); - OP_BIND(C3); - OP_BIND(C4); - OP_BIND(C5); - OP_BIND(Sa); - - OP_SPAWN_THREAD(script_14_child_1); - OP_SPAWN_THREAD(script_14_child_2); - OP_SPAWN_THREAD(script_14_child_3); - OP_SPAWN_THREAD(script_14_child_4); - OP_SPAWN_THREAD(script_14_child_5); - - for (i = 0; i < 50; ++i) { - OP_ACCEPT_STREAM_WAIT(S, Sa, OP_F_REPLACE_STREAM); - OP_READ_EXPECT_B(Sa, "foo"); - OP_EXPECT_FIN(Sa); - } -} - -/* 15. Client sending large number of streams, MAX_STREAMS test */ -DEF_SCRIPT(script_15, "Client sending large number of streams, MAX_STREAMS test") -{ - size_t i; - - OP_SIMPLE_PAIR_CONN_ND(); - OP_ACCEPT_CONN_WAIT_ND(L, S, 0); - - /* - * This will cause a protocol violation to be raised by the server if we are - * not handling the stream limit correctly on the TX side. - */ - for (i = 0; i < 200; ++i) { - OP_NEW_STREAM(C, Ca, SSL_STREAM_FLAG_ADVANCE); - OP_WRITE(Ca, "foo", 3); - OP_CONCLUDE(Ca); - OP_UNBIND(Ca); - } - - /* Prove the connection is still good. */ - OP_NEW_STREAM(S, Sa, 0); - OP_WRITE(Sa, "bar", 3); - OP_CONCLUDE(Sa); - - OP_ACCEPT_STREAM_WAIT(C, Ca, 0); - OP_READ_EXPECT(Ca, "bar", 3); - OP_EXPECT_FIN(Ca); - - /* - * Drain the queue of incoming streams. We should be able to get all 200 - * even though only 100 can be initiated at a time. - */ - for (i = 0; i < 200; ++i) { - OP_ACCEPT_STREAM_WAIT(S, Sb, 0); - OP_READ_EXPECT(Sb, "foo", 3); - OP_EXPECT_FIN(Sb); - OP_UNBIND(Sb); - } -} - -/* 16. Server sending large number of streams, MAX_STREAMS test */ -DEF_SCRIPT(script_16, "Server sending large number of streams, MAX_STREAMS test") -{ - size_t i; - - OP_SIMPLE_PAIR_CONN_ND(); - OP_ACCEPT_CONN_WAIT_ND(L, S, 0); - - /* - * This will cause a protocol violation to be raised by the client if we are - * not handling the stream limit correctly on the TX side. - */ - for (i = 0; i < 200; ++i) { - OP_NEW_STREAM(S, Sa, SSL_STREAM_FLAG_ADVANCE); - OP_WRITE(Sa, "foo", 3); - OP_CONCLUDE(Sa); - OP_UNBIND(Sa); - } - - /* Prove that the connection is still good. */ - OP_NEW_STREAM(C, Ca, 0); - OP_WRITE(Ca, "bar", 3); - OP_CONCLUDE(Ca); - - OP_ACCEPT_STREAM_WAIT(S, Sb, 0); - OP_READ_EXPECT(Sb, "bar", 3); - OP_EXPECT_FIN(Sb); - - /* Drain the queue of incoming streams. */ - for (i = 0; i < 200; ++i) { - OP_ACCEPT_STREAM_WAIT(C, Cb, 0); - OP_READ_EXPECT(Cb, "foo", 3); - OP_EXPECT_FIN(Cb); - OP_UNBIND(Cb); - } -} - -/* 17. Key update test - unlimited */ -DEF_SCRIPT(script_17, "Key update test - unlimited") -{ - size_t i; - - OP_SIMPLE_PAIR_CONN(); - OP_ACCEPT_CONN_WAIT(L, S, 0); - - OP_WRITE(C, "apple", 5); - OP_READ_EXPECT(S, "apple", 5); - - OP_OVERRIDE_KEY_UPDATE(C, 1); - - for (i = 0; i < 200; ++i) { - OP_WRITE(C, "apple", 5); - OP_READ_EXPECT(S, "apple", 5); - /* - * TXKU frequency is bounded by RTT because a previous TXKU needs to be - * acknowledged by the peer first before another one can begin. By - * waiting this long, we eliminate any such concern and ensure as many key - * updates as possible can occur for the purposes of this test. - */ - OP_SKIP_TIME(100); - } - - /* At least 5 RXKUs detected */ - OP_CHECK_KEY_UPDATE_GE(C, 5); - - /* - * Prove the connection is still healthy by sending something in both - * directions. - */ - OP_WRITE(C, "xyzzy", 5); - OP_READ_EXPECT(S, "xyzzy", 5); - - OP_WRITE(S, "plugh", 5); - OP_READ_EXPECT(C, "plugh", 5); -} - -/* 18. Key update test - RTT-bounded */ -DEF_SCRIPT(script_18, "Key update test - RTT-bounded") -{ - size_t i; - - OP_SIMPLE_PAIR_CONN(); - OP_ACCEPT_CONN_WAIT(L, S, 0); - - OP_WRITE(C, "apple", 5); - OP_READ_EXPECT(S, "apple", 5); - - OP_OVERRIDE_KEY_UPDATE(C, 1); - - for (i = 0; i < 200; ++i) { - OP_WRITE(C, "apple", 5); - OP_READ_EXPECT(S, "apple", 5); - OP_SKIP_TIME(8); - } - - /* - * This time we simulate far less time passing between writes, so there are - * fewer opportunities to initiate TXKUs. Note that we ask for a TXKU every - * 1 packet above, which is absurd; thus this ensures we only actually - * generate TXKUs when we are allowed to. - */ - OP_CHECK_KEY_UPDATE_LT(C, 240); - - /* - * Prove the connection is still healthy by sending something in both - * directions. - */ - OP_WRITE(C, "xyzzy", 5); - OP_READ_EXPECT(S, "xyzzy", 5); - - OP_WRITE(S, "plugh", 5); - OP_READ_EXPECT(C, "plugh", 5); -} - -/* 19. Key update test - artificially triggered */ -DEF_SCRIPT(script_19, "Key update test - artificially triggered") -{ - OP_SIMPLE_PAIR_CONN(); - OP_ACCEPT_CONN_WAIT(L, S, 0); - - OP_WRITE(C, "apple", 5); - OP_READ_EXPECT(S, "apple", 5); - - OP_WRITE(C, "orange", 6); - OP_READ_EXPECT(S, "orange", 6); - - OP_WRITE(S, "strawberry", 10); - OP_READ_EXPECT(C, "strawberry", 10); - - OP_CHECK_KEY_UPDATE_LT(C, 1); - - OP_TRIGGER_KEY_UPDATE(C, SSL_KEY_UPDATE_REQUESTED); - - OP_WRITE(C, "orange", 6); - OP_READ_EXPECT(S, "orange", 6); - OP_WRITE(S, "ok", 2); - - OP_READ_EXPECT(C, "ok", 2); - OP_CHECK_KEY_UPDATE_GE(C, 1); -} - -DEF_SCRIPT(script_20, "place holder for multistrem script_20") -{ -} - -DEF_SCRIPT(script_21, "place holder for multistrem script_21") -{ -} - -DEF_SCRIPT(script_22, "place holder for multistrem script_22") -{ -} - -DEF_SCRIPT(script_23, "place holder for multistrem script_23") -{ -} - -DEF_SCRIPT(script_24, "place holder for multistrem script_24") -{ -} - -DEF_SCRIPT(script_25, "place holder for multistrem script_25") -{ -} - -DEF_SCRIPT(script_26, "place holder for multistrem script_26") -{ -} - -DEF_SCRIPT(script_27, "place holder for multistrem script_27") -{ -} - -DEF_SCRIPT(script_28, "place holder for multistrem script_28") -{ -} - -DEF_SCRIPT(script_29, "place holder for multistrem script_29") -{ -} - -DEF_SCRIPT(script_30, "place holder for multistrem script_30") -{ -} - -DEF_SCRIPT(script_31, "place holder for multistrem script_31") -{ -} - -DEF_SCRIPT(script_32, "place holder for multistrem script_32") -{ -} - -DEF_SCRIPT(script_33, "place holder for multistrem script_33") -{ -} - -DEF_SCRIPT(script_34, "place holder for multistrem script_34") -{ -} - -DEF_SCRIPT(script_35, "place holder for multistrem script_35") -{ -} - -DEF_SCRIPT(script_36, "place holder for multistrem script_36") -{ -} - -DEF_SCRIPT(script_37, "place holder for multistrem script_37") -{ -} - -DEF_SCRIPT(script_38, "place holder for multistrem script_38") -{ -} - -DEF_SCRIPT(script_39, "place holder for multistrem script_39") -{ -} - -DEF_SCRIPT(script_40, "place holder for multistrem script_40") -{ -} - -DEF_SCRIPT(script_41, "place holder for multistrem script_41") -{ -} - -DEF_SCRIPT(script_42, "place holder for multistrem script_42") -{ -} - -DEF_SCRIPT(script_43, "place holder for multistrem script_43") -{ -} - -DEF_SCRIPT(script_44, "place holder for multistrem script_44") -{ -} - -DEF_SCRIPT(script_45, "place holder for multistrem script_45") -{ -} - -DEF_SCRIPT(script_46, "place holder for multistrem script_46") -{ -} - -DEF_SCRIPT(script_47, "place holder for multistrem script_47") -{ -} - -DEF_SCRIPT(script_48, "place holder for multistrem script_48") -{ -} - -DEF_SCRIPT(script_49, "place holder for multistrem script_49") -{ -} - -DEF_SCRIPT(script_50, "place holder for multistrem script_50") -{ -} - -DEF_SCRIPT(script_51, "place holder for multistrem script_51") -{ -} - -DEF_SCRIPT(script_52, "place holder for multistrem script_52") -{ -} - -DEF_SCRIPT(script_53, "place holder for multistrem script_53") -{ -} - -DEF_SCRIPT(script_54, "place holder for multistrem script_54") -{ -} - -DEF_SCRIPT(script_55, "place holder for multistrem script_55") -{ -} - -DEF_SCRIPT(script_56, "place holder for multistrem script_56") -{ -} - -DEF_SCRIPT(script_57, "place holder for multistrem script_57") -{ -} - -DEF_SCRIPT(script_58, "place holder for multistrem script_58") -{ -} - -DEF_SCRIPT(script_59, "place holder for multistrem script_59") -{ -} - -DEF_SCRIPT(script_60, "place holder for multistrem script_60") -{ -} - -DEF_SCRIPT(script_61, "place holder for multistrem script_61") -{ -} - -DEF_SCRIPT(script_62, "place holder for multistrem script_62") -{ -} - -DEF_SCRIPT(script_63, "place holder for multistrem script_63") -{ -} - -DEF_SCRIPT(script_64, "place holder for multistrem script_64") -{ -} - -DEF_SCRIPT(script_65, "place holder for multistrem script_65") -{ -} - -DEF_SCRIPT(script_66, "place holder for multistrem script_66") -{ -} - -DEF_SCRIPT(script_67, "place holder for multistrem script_67") -{ -} - -DEF_SCRIPT(script_68, "place holder for multistrem script_68") -{ -} - -DEF_SCRIPT(script_69, "place holder for multistrem script_69") -{ -} - -DEF_SCRIPT(script_70, "place holder for multistrem script_70") -{ -} - -DEF_SCRIPT(script_71, "place holder for multistrem script_71") -{ -} - -DEF_SCRIPT(script_72, "place holder for multistrem script_72") -{ -} - -DEF_SCRIPT(script_73, "place holder for multistrem script_73") -{ -} - -DEF_SCRIPT(script_74, "place holder for multistrem script_74") -{ -} - -DEF_SCRIPT(script_75, "place holder for multistrem script_75") -{ -} - -DEF_SCRIPT(script_76, "place holder for multistrem script_76") -{ -} - -DEF_SCRIPT(script_77, "place holder for multistrem script_77") -{ -} - -DEF_SCRIPT(script_78, "place holder for multistrem script_78") -{ -} - -DEF_SCRIPT(script_79, "place holder for multistrem script_79") -{ -} - -DEF_SCRIPT(script_80, "place holder for multistrem script_80") -{ -} - -DEF_SCRIPT(script_81, "place holder for multistrem script_81") -{ -} - -DEF_SCRIPT(script_82, "place holder for multistrem script_82") -{ -} - -DEF_SCRIPT(script_83, "place holder for multistrem script_83") -{ -} - -DEF_SCRIPT(script_84, "place holder for multistrem script_84") -{ -} - -DEF_SCRIPT(script_85, "place holder for multistrem script_85") -{ -} - -DEF_SCRIPT(script_86, "place holder for multistrem script_86") -{ -} - -DEF_SCRIPT(script_87, "place holder for multistrem script_87") -{ -} - -DEF_SCRIPT(script_88, "place holder for multistrem script_88") -{ -} - -DEF_SCRIPT(script_89, "place holder for multistrem script_89") -{ -} - -DEF_SCRIPT(script_90, "place holder for multistrem script_90") -{ -} - -DEF_SCRIPT(script_91, "place holder for multistrem script_91") -{ -} - -DEF_SCRIPT(script_92, "place holder for multistrem script_92") -{ -} - -DEF_SCRIPT(script_93, "place holder for multistrem script_93") -{ -} - -DEF_SCRIPT(script_94, "place holder for multistrem script_94") -{ -} - -DEF_SCRIPT(script_95, "place holder for multistrem script_95") -{ -} - -DEF_SCRIPT(script_96, "place holder for multistrem script_96") -{ -} - -DEF_SCRIPT(script_97, "place holder for multistrem script_97") -{ -} - -DEF_SCRIPT(script_98, "place holder for multistrem script_98") -{ -} - -DEF_SCRIPT(script_99, "place holder for multistrem script_99") -{ -} - -DEF_SCRIPT(script_100, "place holder for multistrem script_100") -{ -} - -DEF_SCRIPT(script_101, "place holder for multistrem script_101") -{ -} - -DEF_SCRIPT(script_102, "place holder for multistrem script_102") -{ -} - -DEF_SCRIPT(script_103, "place holder for multistrem script_103") -{ -} - -DEF_SCRIPT(script_104, "place holder for multistrem script_104") -{ -} - -DEF_SCRIPT(script_105, "place holder for multistrem script_105") -{ -} - -DEF_SCRIPT(script_106, "place holder for multistrem script_106") -{ -} - /* * List of Test Scripts * ============================================================================ */ static SCRIPT_INFO *const scripts[] = { - USE(simple_stream), - USE(multi_stream), - USE(simple_conn), - USE(simple_thread), - USE(ssl_poll), - USE(check_cwm), - USE(check_pc_flood), - USE(check_ctx_cbks), - USE(script_5), - USE(script_6), - USE(script_7), - USE(script_8), - USE(script_9), - USE(script_10), - USE(script_11), - USE(script_12), - USE(script_13), - USE(script_14), - USE(script_15), - USE(script_16), - USE(script_17), - USE(script_18), - USE(script_19), - USE(script_20), - USE(script_21), - USE(script_22), - USE(script_23), - USE(script_24), - USE(script_25), - USE(script_26), - USE(script_27), - USE(script_28), - USE(script_29), - USE(script_30), - USE(script_31), - USE(script_32), - USE(script_33), - USE(script_34), - USE(script_35), - USE(script_36), - USE(script_37), - USE(script_38), - USE(script_39), - USE(script_40), - USE(script_41), - USE(script_42), - USE(script_43), - USE(script_44), - USE(script_45), - USE(script_46), - USE(script_47), - USE(script_48), - USE(script_49), - USE(script_50), - USE(script_51), - USE(script_52), - USE(script_53), - USE(script_54), - USE(script_55), - USE(script_56), - USE(script_57), - USE(script_58), - USE(script_59), - USE(script_60), - USE(script_61), - USE(script_62), - USE(script_63), - USE(script_64), - USE(script_65), - USE(script_66), - USE(script_67), - USE(script_68), - USE(script_69), - USE(script_70), - USE(script_71), - USE(script_72), - USE(script_73), - USE(script_74), - USE(script_75), - USE(script_76), - USE(script_77), - USE(script_78), - USE(script_79), - USE(script_80), - USE(script_81), - USE(script_82), - USE(script_83), - USE(script_84), - USE(script_85), - USE(script_86), - USE(script_87), - USE(script_88), - USE(script_89), - USE(script_90), - USE(script_91), - USE(script_92), - USE(script_93), - USE(script_94), - USE(script_95), - USE(script_96), - USE(script_97), - USE(script_98), - USE(script_99), - USE(script_100), - USE(script_101), - USE(script_102), - USE(script_103), - USE(script_104), - USE(script_105), - USE(script_106), + USE(simple_conn) + USE(simple_thread) + USE(ssl_poll) + USE(check_cwm) }; diff --git a/test/radix/terp.c b/test/radix/terp.c index a89367ce1f..9e64702908 100644 --- a/test/radix/terp.c +++ b/test/radix/terp.c @@ -858,4 +858,4 @@ err: } #define SCRIPT(name) (&script_info_##name) -#define USE(name) SCRIPT(name) +#define USE(name) SCRIPT(name), diff --git a/test/rand_test.c b/test/rand_test.c index 5b2270cb4e..0fbd89542f 100644 --- a/test/rand_test.c +++ b/test/rand_test.c @@ -275,142 +275,6 @@ err: return res; } -/* Warm up the DRBG cipher fetch caches outside the mfail injection window */ -static int rand_drbg_fetch_warmup(EVP_RAND *drbg_alg) -{ - EVP_RAND_CTX *warm; - OSSL_PARAM params[3]; - int ret; - - params[0] = OSSL_PARAM_construct_utf8_string(OSSL_DRBG_PARAM_CIPHER, - (char *)"AES-256-CTR", 0); - params[1] = OSSL_PARAM_construct_utf8_string(OSSL_PROV_PARAM_CORE_PROV_NAME, - (char *)"default", 0); - params[2] = OSSL_PARAM_construct_end(); - - if (!TEST_ptr(warm = EVP_RAND_CTX_new(drbg_alg, NULL))) - return 0; - ret = TEST_true(EVP_RAND_CTX_set_params(warm, params)); - EVP_RAND_CTX_free(warm); - return ret; -} - -/* - * Memory-failure coverage for the whole random generation stack on a fresh - * library context: the seed source and DRBG chain creation and seeding. - */ -static int test_rand_bytes_mfail(int idx) -{ - OSSL_LIB_CTX *ctx = NULL; - EVP_RAND *drbg = NULL, *seed = NULL; - unsigned char buf[16]; - int rc = -1; - - if (!TEST_ptr(ctx = OSSL_LIB_CTX_new()) - || !TEST_ptr(drbg = EVP_RAND_fetch(ctx, "CTR-DRBG", NULL)) - || !rand_drbg_fetch_warmup(drbg)) - goto end; - /* The default seed source may be unavailable in some configurations */ - ERR_set_mark(); - seed = EVP_RAND_fetch(ctx, OPENSSL_SEED_SRC_NAME, NULL); - ERR_pop_to_mark(); - - MFAIL_start(); - rc = (idx == 0 ? RAND_bytes_ex(ctx, buf, sizeof(buf), 0) - : RAND_priv_bytes_ex(ctx, buf, sizeof(buf), 0)) - > 0; - MFAIL_end(); - -end: - EVP_RAND_free(seed); - EVP_RAND_free(drbg); - OSSL_LIB_CTX_free(ctx); - return rc; -} - -/* Memory-failure coverage for the seed source entropy acquisition. */ -static int test_rand_seed_src_mfail(void) -{ - OSSL_LIB_CTX *ctx = NULL; - EVP_RAND *rand = NULL; - EVP_RAND_CTX *seed = NULL; - unsigned char buf[64]; - int rc = -1; - - if (!TEST_ptr(ctx = OSSL_LIB_CTX_new()) - || !TEST_ptr(rand = EVP_RAND_fetch(ctx, OPENSSL_SEED_SRC_NAME, NULL))) - goto end; - - MFAIL_start(); - rc = (seed = EVP_RAND_CTX_new(rand, NULL)) != NULL - && EVP_RAND_instantiate(seed, 0, 0, NULL, 0, NULL) - && EVP_RAND_generate(seed, buf, sizeof(buf), 0, 0, NULL, 0); - MFAIL_end(); - -end: - EVP_RAND_CTX_free(seed); - EVP_RAND_free(rand); - OSSL_LIB_CTX_free(ctx); - return rc; -} - -/* Memory-failure coverage for the DRBG operations with a TEST-RAND parent */ -static int test_rand_drbg_mfail(void) -{ - OSSL_LIB_CTX *ctx = NULL; - EVP_RAND *parent_alg = NULL, *drbg_alg = NULL; - EVP_RAND_CTX *parent = NULL, *drbg = NULL; - unsigned int strength = 256, generate = 1; - unsigned char entropy[128]; - unsigned char buf[32]; - OSSL_PARAM parent_params[4], drbg_params[3]; - size_t i; - int rc = -1; - - for (i = 0; i < sizeof(entropy); i++) - entropy[i] = 0xff & i; - parent_params[0] = OSSL_PARAM_construct_uint(OSSL_RAND_PARAM_STRENGTH, - &strength); - parent_params[1] = OSSL_PARAM_construct_uint(OSSL_RAND_PARAM_GENERATE, - &generate); - parent_params[2] = OSSL_PARAM_construct_octet_string( - OSSL_RAND_PARAM_TEST_ENTROPY, entropy, sizeof(entropy)); - parent_params[3] = OSSL_PARAM_construct_end(); - - drbg_params[0] = OSSL_PARAM_construct_utf8_string(OSSL_DRBG_PARAM_CIPHER, - (char *)"AES-256-CTR", 0); - drbg_params[1] = OSSL_PARAM_construct_utf8_string( - OSSL_PROV_PARAM_CORE_PROV_NAME, (char *)"default", 0); - drbg_params[2] = OSSL_PARAM_construct_end(); - - if (!TEST_ptr(ctx = OSSL_LIB_CTX_new()) - || !TEST_ptr(parent_alg = EVP_RAND_fetch(ctx, "TEST-RAND", NULL)) - || !TEST_ptr(drbg_alg = EVP_RAND_fetch(ctx, "CTR-DRBG", NULL)) - || !rand_drbg_fetch_warmup(drbg_alg) - || !TEST_ptr(parent = EVP_RAND_CTX_new(parent_alg, NULL)) - || !TEST_true(EVP_RAND_instantiate(parent, 0, 0, NULL, 0, - parent_params))) - goto end; - - MFAIL_start(); - rc = (drbg = EVP_RAND_CTX_new(drbg_alg, parent)) != NULL - && EVP_RAND_instantiate(drbg, 0, 0, (unsigned char *)"abc", 3, - drbg_params) - && EVP_RAND_generate(drbg, buf, sizeof(buf), 0, 0, NULL, 0) - && EVP_RAND_reseed(drbg, 0, NULL, 0, (unsigned char *)"xyz", 3) - && EVP_RAND_generate(drbg, buf, sizeof(buf), 0, 0, - (unsigned char *)"adin", 4); - MFAIL_end(); - -end: - EVP_RAND_CTX_free(drbg); - EVP_RAND_CTX_free(parent); - EVP_RAND_free(parent_alg); - EVP_RAND_free(drbg_alg); - OSSL_LIB_CTX_free(ctx); - return rc; -} - int setup_tests(void) { if (!test_skip_common_options()) { @@ -437,9 +301,5 @@ int setup_tests(void) if (!OSSL_PROVIDER_available(NULL, "fips") || fips_provider_version_ge(NULL, 3, 5, 1)) ADD_TEST(test_rand_get0_primary); - - ADD_MFAIL_ALL_TESTS(test_rand_bytes_mfail, 2); - ADD_MFAIL_TEST(test_rand_seed_src_mfail); - ADD_MFAIL_TEST(test_rand_drbg_mfail); return 1; } diff --git a/test/rdcpu_sanitytest.c b/test/rdcpu_sanitytest.c index 47c2ea71ca..e76b94b34c 100644 --- a/test/rdcpu_sanitytest.c +++ b/test/rdcpu_sanitytest.c @@ -23,7 +23,7 @@ size_t OPENSSL_ia32_rdseed_bytes(unsigned char *buf, size_t len); #if defined(__aarch64__) && defined(OPENSSL_CPUID_OBJ) #define IS_AARCH_64 1 -#include "arch/arm_arch.h" +#include "arm_arch.h" size_t OPENSSL_rndr_bytes(unsigned char *buf, size_t len); size_t OPENSSL_rndrrs_bytes(unsigned char *buf, size_t len); diff --git a/test/recipes/00-prep_fipsmodule_cnf.t b/test/recipes/00-prep_fipsmodule_cnf.t old mode 100755 new mode 100644 index 46a19a9d2d..4e3a6d85e8 --- a/test/recipes/00-prep_fipsmodule_cnf.t +++ b/test/recipes/00-prep_fipsmodule_cnf.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2023 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -30,7 +30,7 @@ my $fipsmoduleconf = bldtop_file('test', 'fipsmodule.cnf'); plan tests => 1; # Create the $fipsmoduleconf file -ok(run(app(['openssl', 'fipsinstall', '-pedantic', '-defer_tests', +ok(run(app(['openssl', 'fipsinstall', '-pedantic', '-module', $fipsmodule, '-provider_name', 'fips', '-section_name', 'fips_sect', '-out', $fipsmoduleconf])), "fips install"); diff --git a/test/recipes/01-test_abort.t b/test/recipes/01-test_abort.t index f0d1c4d1d5..f7e066bd47 100644 --- a/test/recipes/01-test_abort.t +++ b/test/recipes/01-test_abort.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2016 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -8,14 +8,9 @@ use OpenSSL::Test; -use OpenSSL::Test::Utils; -use OpenSSL::Test::Simple; setup("test_abort"); -plan skip_all => "This test should not be run under valgrind" - if ( defined $ENV{OSSL_USE_VALGRIND} ); - plan tests => 1; is(run(test(["aborttest"])), 0, "Testing that abort is caught correctly"); diff --git a/test/recipes/02-test_mem_alloc.t b/test/recipes/02-test_mem_alloc.t index d75a2c1112..89a3eceeb7 100644 --- a/test/recipes/02-test_mem_alloc.t +++ b/test/recipes/02-test_mem_alloc.t @@ -1,20 +1,14 @@ #! /usr/bin/env perl -# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy # in the file LICENSE in the source distribution or at # https://www.openssl.org/source/license.html -use OpenSSL::Test; -use OpenSSL::Test::Utils; use OpenSSL::Test::Simple; -plan skip_all => "This test should not be run under valgrind" - if ( defined $ENV{OSSL_USE_VALGRIND} ); - { - local $ENV{"OPENSSL_TEST_MFAIL_DISABLE"} = 1; local $ENV{"ASAN_OPTIONS"} = "allocator_may_return_null=true"; local $ENV{"MSAN_OPTIONS"} = "allocator_may_return_null=true"; diff --git a/test/recipes/02-test_mem_alloc_custom_fns.t b/test/recipes/02-test_mem_alloc_custom_fns.t index b402634ab3..06667f0d64 100644 --- a/test/recipes/02-test_mem_alloc_custom_fns.t +++ b/test/recipes/02-test_mem_alloc_custom_fns.t @@ -1,20 +1,14 @@ #! /usr/bin/env perl -# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy # in the file LICENSE in the source distribution or at # https://www.openssl.org/source/license.html -use OpenSSL::Test; -use OpenSSL::Test::Utils; use OpenSSL::Test::Simple; -plan skip_all => "This test should not be run under valgrind" - if ( defined $ENV{OSSL_USE_VALGRIND} ); - { - local $ENV{"OPENSSL_TEST_MFAIL_DISABLE"} = 1; local $ENV{"ASAN_OPTIONS"} = "allocator_may_return_null=true"; local $ENV{"MSAN_OPTIONS"} = "allocator_may_return_null=true"; diff --git a/test/recipes/02-test_unit.t b/test/recipes/02-test_unit.t deleted file mode 100644 index d88c3dcf31..0000000000 --- a/test/recipes/02-test_unit.t +++ /dev/null @@ -1,63 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use warnings; - -use File::Find; -use File::Spec::Functions qw(abs2rel); - -use OpenSSL::Test qw(:DEFAULT bldtop_dir); -use OpenSSL::Test::Utils; - -setup("test_unit"); - -my $unit_dir = bldtop_dir('test', 'unit'); -my $exeext = ''; - -if ($^O eq 'MSWin32') { - $exeext = '.exe'; - # The shared libraries (libcrypto/libssl DLLs) are only placed at the - # build top and copied into apps/, test/ and fuzz/. The unit test - # executables live in nested directories under test/unit/, so add the - # build top to PATH to let the loader find the DLLs. - $ENV{PATH} = bldtop_dir() . ';' . ($ENV{PATH} // ''); -} - -my @tests = (); -if (-d $unit_dir) { - find({ - wanted => sub { - return unless -f $_; - my $base = $_; - if ($exeext ne '') { - # require + strip .exe - return unless $base =~ s/\Q$exeext\E$//; - } else { - return unless -x $_; - } - return unless $base =~ m|/test_[^/]*$|; - # reject .pdb/.obj/etc - return if $base =~ m|\.\w+$|; - push @tests, $_; - }, - no_chdir => 1, - }, $unit_dir); -} - -@tests = sort @tests; - -plan skip_all => "No unit tests built (enable-unit-tests not set?)" - unless @tests; - -plan tests => scalar @tests; - -foreach my $test_bin (@tests) { - my $name = abs2rel($test_bin, $unit_dir); - ok(run(cmd([$test_bin])), "unit: $name"); -} diff --git a/test/recipes/03-test_internal_ml_dsa.t b/test/recipes/03-test_internal_ml_dsa.t deleted file mode 100644 index 8cdf917ed9..0000000000 --- a/test/recipes/03-test_internal_ml_dsa.t +++ /dev/null @@ -1,18 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use OpenSSL::Test; -use OpenSSL::Test::Utils; -use OpenSSL::Test qw/:DEFAULT srctop_file/; - -setup("ml_dsa_internal_test"); -plan skip_all => 'ML-DSA is not supported in this build' - if disabled('ml-dsa'); -plan tests => 1; - -ok(run(test(["ml_dsa_internal_test"]))); diff --git a/test/recipes/03-test_sha3_x4_internal.t b/test/recipes/03-test_sha3_x4_internal.t deleted file mode 100644 index 9e5793aaf3..0000000000 --- a/test/recipes/03-test_sha3_x4_internal.t +++ /dev/null @@ -1,16 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# Copyright (c) 2026 Intel Corporation. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use OpenSSL::Test; -use OpenSSL::Test::Simple; - -setup("test_sha3_x4_internal"); - -simple_test("test_sha3_x4_internal", "sha3_x4_internal_test"); diff --git a/test/recipes/04-test_asn1_parse.t b/test/recipes/04-test_asn1_parse.t index 192c3320ae..f3af436592 100644 --- a/test/recipes/04-test_asn1_parse.t +++ b/test/recipes/04-test_asn1_parse.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2023 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -12,7 +12,7 @@ use OpenSSL::Test::Utils; setup("test_asn1_parse"); -plan tests => 4; +plan tests => 3; $ENV{OPENSSL_CONF} = srctop_file("test", "test_asn1_parse.cnf"); @@ -24,6 +24,3 @@ ok(run(app(([ 'openssl', 'asn1parse', ok(run(app(([ 'openssl', 'asn1parse', '-genstr', 'OID:1.2.3.4.3'])))); - -ok(run(app(([ 'openssl', 'asn1parse', - '-genconf', srctop_file("test", "test_asn1_genconf.cnf")])))); diff --git a/test/recipes/90-test_asn1_string.t b/test/recipes/04-test_bioprint.t similarity index 72% rename from test/recipes/90-test_asn1_string.t rename to test/recipes/04-test_bioprint.t index ce0db28a18..4d5efc690d 100644 --- a/test/recipes/90-test_asn1_string.t +++ b/test/recipes/04-test_bioprint.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -9,4 +9,4 @@ use OpenSSL::Test::Simple; -simple_test("test_asn1_string", "asn1_string_test"); +simple_test("test_bioprint", "bioprinttest"); diff --git a/test/recipes/05-test_aes_wrap.t b/test/recipes/05-test_aes_wrap.t deleted file mode 100644 index 474e8fdace..0000000000 --- a/test/recipes/05-test_aes_wrap.t +++ /dev/null @@ -1,18 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use warnings; - -use OpenSSL::Test::Simple; -use OpenSSL::Test; -use OpenSSL::Test::Utils; - -setup("test_aeswrap"); - -simple_test("test_aeswrap", "aeswrap_test", "aeswrap"); diff --git a/test/recipes/05-test_rand.t b/test/recipes/05-test_rand.t index d70b65c649..73a163d4d1 100644 --- a/test/recipes/05-test_rand.t +++ b/test/recipes/05-test_rand.t @@ -13,7 +13,7 @@ use OpenSSL::Test::Utils; use OpenSSL::Test qw/:DEFAULT srctop_file bldtop_dir/; use Cwd qw(abs_path); -plan tests => 6; +plan tests => 5; setup("test_rand"); ok(run(test(["rand_test", srctop_file("test", "default.cnf")]))); @@ -41,15 +41,8 @@ SKIP: { chomp(@randdata); ok($success && $randdata[0] eq $expected, "rand with ossltest provider: Check rand output is as expected"); -} - -{ - my $success; - my @randdata; @randdata = run(app(['openssl', 'rand', '-hex', '2K' ]), capture => 1, statusvar => \$success); chomp(@randdata); - ok($success && length($randdata[0]) == 4096, - "rand: Check rand output is of expected length"); } diff --git a/test/recipes/10-test_bn_data/bnmod.txt b/test/recipes/10-test_bn_data/bnmod.txt index a0a30df45e..85a17e0a05 100644 --- a/test/recipes/10-test_bn_data/bnmod.txt +++ b/test/recipes/10-test_bn_data/bnmod.txt @@ -1,4 +1,4 @@ -# Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016-2022 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -2010,14 +2010,6 @@ A = ca6c51ba2f410d09bf71d60fe B = 8bdfa8fe5ef3b2ad02bc63c4d M = 84daecf412b8c50ad6dfdb546c3eb783dcc6f32003eda914bb -# These test vectors satisfy A ^ 2 = ModSqr (mod M) and 0 <= ModSqr < M. - -Title = ModSqr tests - -# Regression test for https://github.com/openssl/openssl/issues/15587 -ModSqr = 166794ed50cb31b6e6a319f7474416c266d5c3f3115ea2a7ed9638367d1f955f66a7179ee3ce5ee5e04e63c46781f1192beac3abb26ff238f5ed2f5505ae06003ff -A = 1407833bd4c893195cc32f56a507f15140be687a1994febe0bdbe793125f010a3c1c814737b10ab690498b7990ce4e625ad2f32cbf42626cb9649da38a5c9c76a99 -M = 1ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff # These test vectors satisfy A ^ E = ModExp (mod M) and 0 <= ModExp < M. diff --git a/test/recipes/15-test_dsa.t b/test/recipes/15-test_dsa.t index c30cbfbbe3..b2747e3d46 100644 --- a/test/recipes/15-test_dsa.t +++ b/test/recipes/15-test_dsa.t @@ -17,7 +17,7 @@ use OpenSSL::Test::Utils; setup("test_dsa"); plan skip_all => 'DSA is not supported in this build' if disabled('dsa'); -plan tests => 11; +plan tests => 7; require_ok(srctop_file('test','recipes','tconversion.pl')); @@ -45,99 +45,3 @@ subtest "dsa conversions using 'openssl pkey' -- public key" => sub { -in => srctop_file("test","testdsapub.pem"), -args => ["pkey", "-pubin", "-pubout"] ); }; - -SKIP: { - skip "Skipping PVK conversion test", 1 - if disabled("rc4") || disabled("legacy") || disabled("pvkkdf"); - - subtest "dsa conversions using 'openssl dsa' -- PVK" => sub { - tconversion( -type => 'pvk', -prefix => 'dsa-pvk', - -in => srctop_file("test", "testdsa.pem"), - -args => ["dsa", "-passin", "pass:testpass", - "-passout", "pass:testpass", - "-provider", "default", - "-provider", "legacy"] ); - }; -} - -subtest "dsa -modulus prints the DSA public value" => sub { - plan tests => 2; - - # The public value (y) of the committed testdsa.pem / testdsapub.pem - # keypair, i.e. the "pub:" field of 'openssl pkey -text'. - my $expected = "Public Key=CC99A07D9817BFF03BB09B183E9B19EB77ABECF192" - . "C3A9FBA833DBE69EDB719A8E9777BB82736CEC6A8E4E2FAD0693ACC3D1456" - . "5D62710B95B02CC6A5CF091EEF9C22F20193EBE114C45A0B5E54A645037E8" - . "787FE01B3871508A25BDBF7C6B81428F89858F133FDB858C390C2EF7BCF7E" - . "41D7C66578F792A2488C787EF7C7D41"; - - my @priv = run(app(['openssl', 'dsa', '-modulus', '-noout', - '-in', srctop_file("test", "testdsa.pem")], - stderr => undef), - capture => 1); - chomp @priv; - ok(grep(/^\Q$expected\E$/, @priv), - "-modulus prints the expected public value for a private key"); - - my @pub = run(app(['openssl', 'dsa', '-pubin', '-modulus', '-noout', - '-in', srctop_file("test", "testdsapub.pem")], - stderr => undef), - capture => 1); - chomp @pub; - ok(grep(/^\Q$expected\E$/, @pub), - "-modulus prints the expected public value for a public key"); -}; - -subtest "dsa -text prints the key in text form" => sub { - plan tests => 6; - - # The private (x) and public (y) values of the committed testdsa.pem / - # testdsapub.pem keypair. -text prints them as colon-separated hex; we - # strip the formatting and compare against the known values so the actual - # key material, not just the labels, is verified. - my $priv_hex = "BF71D497B89755D0C5E41285D81F9577CC3DF8C2"; - my $pub_hex = "CC99A07D9817BFF03BB09B183E9B19EB77ABECF192C3A9FBA833DBE" - . "69EDB719A8E9777BB82736CEC6A8E4E2FAD0693ACC3D14565D62710B95B02CC" - . "6A5CF091EEF9C22F20193EBE114C45A0B5E54A645037E8787FE01B3871508A2" - . "5BDBF7C6B81428F89858F133FDB858C390C2EF7BCF7E41D7C66578F792A2488" - . "C787EF7C7D41"; - - my @priv = run(app(['openssl', 'dsa', '-text', '-noout', - '-in', srctop_file("test", "testdsa.pem")], - stderr => undef), - capture => 1); - chomp @priv; - my $priv_blob = uc join('', @priv); - $priv_blob =~ s/[^0-9A-F]//g; - ok(grep(/^Private-Key: \(1024 bit\)$/, @priv), - "-text prints the private key header"); - ok(index($priv_blob, $priv_hex) >= 0, - "-text prints the expected private value"); - ok(index($priv_blob, $pub_hex) >= 0, - "-text prints the expected public value for a private key"); - - my @pub = run(app(['openssl', 'dsa', '-pubin', '-text', '-noout', - '-in', srctop_file("test", "testdsapub.pem")], - stderr => undef), - capture => 1); - chomp @pub; - my $pub_blob = uc join('', @pub); - $pub_blob =~ s/[^0-9A-F]//g; - ok(grep(/^Public-Key: \(1024 bit\)$/, @pub), - "-text prints the public key header"); - ok(index($pub_blob, $pub_hex) >= 0, - "-text prints the expected public value for a public key"); - ok(!grep(/^priv:/, @pub), - "-text does not print a private component for a public key"); -}; - -subtest "dsa PVK output is rejected for public key input" => sub { - plan tests => 1; - - # Note: -noout would short-circuit before the format check, so request - # an actual encoding to reach the PVK-with-public-key rejection. - ok(!run(app(['openssl', 'dsa', '-pubin', '-outform', 'PVK', - '-in', srctop_file("test", "testdsapub.pem"), - '-out', 'dsa-pubin.pvk'])), - "-outform PVK with -pubin is rejected"); -}; diff --git a/test/recipes/15-test_dsaparam.t b/test/recipes/15-test_dsaparam.t index fe7a52d836..8f7d2af175 100644 --- a/test/recipes/15-test_dsaparam.t +++ b/test/recipes/15-test_dsaparam.t @@ -68,7 +68,7 @@ plan skip_all => "DSA isn't supported in this build" my @valid = glob(data_file("valid", "*.pem")); my @invalid = glob(data_file("invalid", "*.pem")); -my $num_tests = scalar @valid + scalar @invalid + 4; +my $num_tests = scalar @valid + scalar @invalid + 2; plan tests => $num_tests; foreach (@valid) { @@ -85,32 +85,3 @@ copy($input, $inout); ok(run(app(['openssl', 'dsaparam', '-in', $inout, '-out', $inout])), "identical infile and outfile"); ok(!compare_text($input, $inout), "converted file $inout did not change"); - -# Cover the DER (ASN.1) output paths of the dsaparam app. -my $srcparams = data_file("valid", "p1024_q160_t1862.pem"); -my $params_der = "dsaparam.der"; -my $key_der = "dsakey.der"; - -subtest "dsaparam DER parameter output" => sub { - plan tests => 2; - - # Exercises i2d_KeyParams_bio(). - ok(run(app(['openssl', 'dsaparam', '-in', $srcparams, - '-outform', 'DER', '-out', $params_der])), - "write DSA parameters in DER form"); - ok(run(app(['openssl', 'dsaparam', '-inform', 'DER', '-in', $params_der, - '-noout'])), - "read the DER DSA parameters back"); -}; - -subtest "dsaparam DER private key output with -genkey" => sub { - plan tests => 2; - - # Exercises i2d_PrivateKey_bio(). - ok(run(app(['openssl', 'dsaparam', '-in', $srcparams, '-genkey', - '-outform', 'DER', '-out', $key_der])), - "generate a DSA key and write it in DER form"); - ok(run(app(['openssl', 'pkey', '-inform', 'DER', '-in', $key_der, - '-noout', '-check'])), - "read the DER DSA private key back"); -}; diff --git a/test/recipes/15-test_ec.t b/test/recipes/15-test_ec.t index e3d18a8849..9bf946e81b 100644 --- a/test/recipes/15-test_ec.t +++ b/test/recipes/15-test_ec.t @@ -11,15 +11,14 @@ use strict; use warnings; use File::Spec; -use File::Compare qw(compare); -use OpenSSL::Test qw/:DEFAULT srctop_file data_file/; +use OpenSSL::Test qw/:DEFAULT srctop_file/; use OpenSSL::Test::Utils; setup("test_ec"); plan skip_all => 'EC is not supported in this build' if disabled('ec'); -plan tests => 19; +plan tests => 16; my $no_fips = disabled('fips') || ($ENV{NO_FIPS} // 0); @@ -103,104 +102,6 @@ SKIP: { }; } -subtest 'EC point conversion form (-conv_form)' => sub { - plan tests => 6; - - my $key = srctop_file("test", "testec-p256.pem"); - - ok(run(app(['openssl', 'ec', '-in', $key, '-pubout', - '-outform', 'DER', '-out', 'ec-conv-unc.der'])), - "writing public key with default (uncompressed) conversion form"); - ok(run(app(['openssl', 'ec', '-in', $key, '-pubout', - '-conv_form', 'compressed', - '-outform', 'DER', '-out', 'ec-conv-comp.der'])), - "writing public key with compressed conversion form"); - ok((-s 'ec-conv-comp.der') < (-s 'ec-conv-unc.der'), - "compressed point encoding is smaller than uncompressed"); - # The encodings are deterministic for a fixed key, so compare them - # against the checked-in reference files. - is(compare('ec-conv-unc.der', data_file('ec-conv-unc.der')), 0, - "uncompressed encoding matches the reference file"); - is(compare('ec-conv-comp.der', data_file('ec-conv-comp.der')), 0, - "compressed encoding matches the reference file"); - ok(!run(app(['openssl', 'ec', '-in', $key, '-noout', - '-conv_form', 'bogus'])), - "an invalid conversion form is rejected"); -}; - -subtest 'EC parameter encoding (-param_enc)' => sub { - plan tests => 6; - - my $key = srctop_file("test", "testec-p256.pem"); - - ok(run(app(['openssl', 'ec', '-in', $key, '-pubout', '-param_enc', - 'named_curve', '-outform', 'DER', '-out', 'ec-param-named.der'])), - "writing public key with named_curve parameter encoding"); - ok(run(app(['openssl', 'ec', '-in', $key, '-pubout', '-param_enc', - 'explicit', '-outform', 'DER', '-out', 'ec-param-explicit.der'])), - "writing public key with explicit parameter encoding"); - ok((-s 'ec-param-named.der') < (-s 'ec-param-explicit.der'), - "named_curve encoding is smaller than explicit"); - # The encodings are deterministic for a fixed key, so compare them - # against the checked-in reference files. - is(compare('ec-param-named.der', data_file('ec-param-named.der')), 0, - "named_curve encoding matches the reference file"); - is(compare('ec-param-explicit.der', data_file('ec-param-explicit.der')), 0, - "explicit encoding matches the reference file"); - ok(!run(app(['openssl', 'ec', '-in', $key, '-noout', - '-param_enc', 'bogus'])), - "an invalid parameter encoding is rejected"); -}; - -subtest 'ec -text prints the key in text form' => sub { - plan tests => 7; - - my $priv_key = srctop_file("test", "testec-p256.pem"); - my $pub_key = srctop_file("test", "testecpub-p256.pem"); - - # The private (priv) and public (pub) values of the committed - # testec-p256.pem / testecpub-p256.pem keypair. -text prints them as - # colon-separated hex; we strip the formatting and compare against the - # known values so the actual key material, not just the labels, is checked. - my $priv_hex = "36045F6C909612570C8C0113071FC809F6788084289C6AB003C60A" - . "17B2D5ADAD"; - my $pub_hex = "04257C007484E23C571252C6912369E5CD33519FEFAAE85DFC5EB1FC" - . "9BCB1FDBC0D0FB63A86F9494CEF823552D1EEF4A48A87E9B4970E03DCF262AD" - . "4ACF598B6E9"; - - # ec -text on the private key. - my @priv = run(app(['openssl', 'ec', '-text', '-noout', '-in', $priv_key], - stderr => undef), - capture => 1); - chomp @priv; - my $priv_blob = uc join('', @priv); - $priv_blob =~ s/[^0-9A-F]//g; - ok(grep(/^Private-Key: \(256 bit field, 128 bit security level\)$/, @priv), - "ec -text prints the private key header"); - ok(index($priv_blob, $priv_hex) >= 0, - "ec -text prints the expected private value"); - ok(index($priv_blob, $pub_hex) >= 0, - "ec -text prints the expected public value"); - ok(grep(/^ASN1 OID: prime256v1$/, @priv) - && grep(/^NIST CURVE: P-256$/, @priv), - "ec -text prints the curve identification"); - - # ec -text on the public key. - my @pub = run(app(['openssl', 'ec', '-pubin', '-text', '-noout', - '-in', $pub_key], - stderr => undef), - capture => 1); - chomp @pub; - my $pub_blob = uc join('', @pub); - $pub_blob =~ s/[^0-9A-F]//g; - ok(grep(/^Public-Key: \(256 bit field, 128 bit security level\)$/, @pub), - "ec -text prints the public key header"); - ok(index($pub_blob, $pub_hex) >= 0, - "ec -text prints the expected public value for a public key"); - ok(!grep(/^priv:/, @pub), - "ec -text does not print a private component for a public key"); -}; - subtest 'Check loading of fips and non-fips keys' => sub { plan skip_all => "FIPS is disabled" if $no_fips; diff --git a/test/recipes/15-test_ec_data/ec-conv-comp.der b/test/recipes/15-test_ec_data/ec-conv-comp.der deleted file mode 100644 index cdae088783..0000000000 Binary files a/test/recipes/15-test_ec_data/ec-conv-comp.der and /dev/null differ diff --git a/test/recipes/15-test_ec_data/ec-conv-unc.der b/test/recipes/15-test_ec_data/ec-conv-unc.der deleted file mode 100644 index 7a75bb5cf8..0000000000 Binary files a/test/recipes/15-test_ec_data/ec-conv-unc.der and /dev/null differ diff --git a/test/recipes/15-test_ec_data/ec-param-explicit.der b/test/recipes/15-test_ec_data/ec-param-explicit.der deleted file mode 100644 index e29a3a7208..0000000000 Binary files a/test/recipes/15-test_ec_data/ec-param-explicit.der and /dev/null differ diff --git a/test/recipes/15-test_ec_data/ec-param-named.der b/test/recipes/15-test_ec_data/ec-param-named.der deleted file mode 100644 index 7a75bb5cf8..0000000000 Binary files a/test/recipes/15-test_ec_data/ec-param-named.der and /dev/null differ diff --git a/test/recipes/15-test_ecparam.t b/test/recipes/15-test_ecparam.t index 169814b4e5..0d72154745 100644 --- a/test/recipes/15-test_ecparam.t +++ b/test/recipes/15-test_ecparam.t @@ -30,7 +30,7 @@ if (disabled("sm2")) { @valid = grep { !/sm2-.*\.pem/} @valid; } -plan tests => 16; +plan tests => 14; sub checkload { my $files = shift; # List of files @@ -199,62 +199,4 @@ subtest "Check loading of fips and non-fips params" => sub { $ENV{OPENSSL_CONF} = $defaultconf; }; -subtest "Check ecparam -param_enc converts between named and explicit" => sub { - plan tests => 3; - - my $named = data_file('valid', 'secp384r1-named.pem'); - my $explicit = data_file('valid', 'secp384r1-explicit.pem'); - - # The encodings are canonical, so re-encoding a named curve as explicit - # (and vice versa) must reproduce the matching reference file byte for byte. - my $to_explicit = 'param-explicit.tst'; - ok(run(app(['openssl', 'ecparam', '-in', $named, '-param_enc', 'explicit', - '-out', $to_explicit])) - && !compare($to_explicit, $explicit), - "named_curve params re-encoded as explicit match the reference file"); - - my $to_named = 'param-named.tst'; - ok(run(app(['openssl', 'ecparam', '-in', $explicit, '-param_enc', - 'named_curve', '-out', $to_named])) - && !compare($to_named, $named), - "explicit params re-encoded as named_curve match the reference file"); - - ok(!run(app(['openssl', 'ecparam', '-in', $named, '-noout', - '-param_enc', 'bogus'])), - "an invalid parameter encoding is rejected"); -}; - -subtest "Check ecparam -text prints the parameters in text form" => sub { - plan tests => 6; - - my $named = data_file('valid', 'secp384r1-named.pem'); - my $explicit = data_file('valid', 'secp384r1-explicit.pem'); - - # Named parameters print the curve identification. - my @named = run(app(['openssl', 'ecparam', '-text', '-noout', '-in', $named], - stderr => undef), - capture => 1); - chomp @named; - ok(grep(/^EC-Parameters: \(384 bit field, 192 bit security level\)$/, @named), - "named parameters print the EC-Parameters header"); - ok(grep(/^ASN1 OID: secp384r1$/, @named), - "named parameters print the expected curve OID"); - ok(grep(/^NIST CURVE: P-384$/, @named), - "named parameters print the expected NIST curve name"); - - # Explicit parameters print the field parameters instead of the curve name. - my @explicit = run(app(['openssl', 'ecparam', '-text', '-noout', - '-in', $explicit], - stderr => undef), - capture => 1); - chomp @explicit; - ok(grep(/^EC-Parameters: \(384 bit field, 192 bit security level\)$/, @explicit), - "explicit parameters print the EC-Parameters header"); - ok(grep(/^Field Type: prime-field$/, @explicit) - && grep(/^Cofactor:/, @explicit), - "explicit parameters print the field parameters"); - ok(!grep(/^ASN1 OID:/, @explicit), - "explicit parameters do not print a curve OID"); -}; - ok(run(app(['openssl', 'ecparam', '-list_curves'])), "Test -list_curves"); diff --git a/test/recipes/15-test_genpkey.t b/test/recipes/15-test_genpkey.t index ddef803ff1..b918f73f9f 100644 --- a/test/recipes/15-test_genpkey.t +++ b/test/recipes/15-test_genpkey.t @@ -9,7 +9,7 @@ use strict; use warnings; -use OpenSSL::Test qw/:DEFAULT with/; +use OpenSSL::Test qw/:DEFAULT/; use OpenSSL::Test::Utils; setup("test_genpkey"); @@ -22,7 +22,7 @@ push @algs, qw(EC) unless disabled("ec"); push @algs, qw(X25519 X448) unless disabled("ecx"); push @algs, qw(SM2) unless disabled("sm2"); -plan tests => scalar(@algs) + 2; +plan tests => scalar(@algs); foreach (@algs) { my $alg = $_; @@ -30,40 +30,3 @@ foreach (@algs) { ok(run(app([ 'openssl', 'genpkey', '-algorithm', $alg, '-help'])), "show genpkey pkeyopt values for $alg"); } - -SKIP: { - skip "RSA is not supported by this OpenSSL build", 1 if disabled("rsa"); - - subtest "genpkey with a cipher encrypts the private key" => sub { - plan tests => 3; - - my $key = "genpkey_enc.pem"; - - ok(run(app(['openssl', 'genpkey', '-algorithm', 'RSA', - '-pkeyopt', 'rsa_keygen_bits:512', - '-aes256', '-pass', 'pass:secret', '-out', $key])), - "Generate an AES-256 encrypted RSA key"); - ok(run(app(['openssl', 'pkey', '-in', $key, - '-passin', 'pass:secret', '-noout'])), - "Read the encrypted key back with the correct passphrase"); - # A wrong passphrase must not decrypt the key. - with({ exit_checker => sub { return shift == 1; } }, - sub { - ok(run(app(['openssl', 'pkey', '-in', $key, - '-passin', 'pass:wrong', '-noout'])), - "Reading with a wrong passphrase fails"); - }); - }; -} - -SKIP: { - skip "DSA is not supported by this OpenSSL build", 1 if disabled("dsa"); - - # A cipher only encrypts a private key, so it is rejected with -genparam. - with({ exit_checker => sub { return shift == 1; } }, - sub { - ok(run(app(['openssl', 'genpkey', '-genparam', '-algorithm', 'DSA', - '-pkeyopt', 'dsa_paramgen_bits:512', '-aes256'])), - "Cannot use a cipher with -genparam"); - }); -} diff --git a/test/recipes/15-test_lms_codecs.t b/test/recipes/15-test_lms_codecs.t deleted file mode 100644 index 2dfb7d0bb4..0000000000 --- a/test/recipes/15-test_lms_codecs.t +++ /dev/null @@ -1,62 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use warnings; - -use File::Spec; -use File::Copy; -use File::Compare qw/compare_text compare/; -use IO::File; -use OpenSSL::Glob; -use OpenSSL::Test qw/:DEFAULT data_file srctop_file bldtop_dir/; -use OpenSSL::Test::Utils; - -setup("test_lms_codecs"); - -# The test vectors were generated using modified Bouncy Castle tests -# from core/src/test/java/org/bouncycastle/pqc/crypto/test/LMSTest.java -my @algs = qw(sha256_n24_w1 shake_n24_w1 shake_n24_w2 shake_n24_w4 shake_n24_w8 shake_n32_w1 shake_n32_w8); - -plan skip_all => "LMS isn't supported in this build" - if disabled("lms"); - -plan tests => @algs * 7; - -foreach my $alg (@algs) { - my $pubpem =data_file(sprintf("%s_pub.pem", $alg)); - my $pubder = data_file(sprintf("%s_pub.der", $alg)); - my $pubtxt = data_file(sprintf("%s_pub.txt", $alg)); - my $msg = data_file(sprintf("%s_msg.bin", $alg)); - my $sig = data_file(sprintf("%s_sig.bin", $alg)); - my $outpubder = sprintf("%s_pubout.der", $alg); - my $outpubpem = sprintf("%s_pubout.pem", $alg); - my $outpubtxt = sprintf("%s_pubout.txt", $alg); - - # Load Public PEM and generate Public DER - ok(run(app([qw(openssl pkey -pubin -outform DER -in), - $pubpem, '-out', $outpubder]))); - ok(!compare($pubder, $outpubder), - sprintf("pubkey DER match: %s", $alg)); - - # Load Public DER and generate Public PEM - ok(run(app([qw(openssl pkey -pubin -inform DER -outform PEM -in), - $pubder, '-out', $outpubpem]))); - ok(!compare($pubpem, $outpubpem), - sprintf("pubkey PEM match: %s", $alg)); - - # Check text encoding - ok(run(app([qw(openssl pkey -pubin -noout -text -in), - $pubpem, '-out', $outpubtxt]))); - ok(!compare_text($pubtxt, $outpubtxt), - sprintf("pubkey TEXT match: %s", $alg)); - - # Perform verify - ok(run(app([qw(openssl pkeyutl -verify -rawin -pubin -inkey), - $pubpem, '-in', $msg, '-sigfile', $sig]))); -} diff --git a/test/recipes/15-test_lms_codecs_data/sha256_n24_w1_msg.bin b/test/recipes/15-test_lms_codecs_data/sha256_n24_w1_msg.bin deleted file mode 100644 index aa52d7284f..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/sha256_n24_w1_msg.bin and /dev/null differ diff --git a/test/recipes/15-test_lms_codecs_data/sha256_n24_w1_pub.der b/test/recipes/15-test_lms_codecs_data/sha256_n24_w1_pub.der deleted file mode 100644 index aa33e95560..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/sha256_n24_w1_pub.der and /dev/null differ diff --git a/test/recipes/15-test_lms_codecs_data/sha256_n24_w1_pub.pem b/test/recipes/15-test_lms_codecs_data/sha256_n24_w1_pub.pem deleted file mode 100644 index 9525959d86..0000000000 --- a/test/recipes/15-test_lms_codecs_data/sha256_n24_w1_pub.pem +++ /dev/null @@ -1,4 +0,0 @@ ------BEGIN PUBLIC KEY----- -MEYwDQYLKoZIhvcNAQkQAxEDNQAAAAABAAAACgAAAAW7nBtfzxKGxB99zen7U6U5 -x+Pl7vX6uHi9NsBOq1Te98wljDKoQsT9 ------END PUBLIC KEY----- diff --git a/test/recipes/15-test_lms_codecs_data/sha256_n24_w1_pub.txt b/test/recipes/15-test_lms_codecs_data/sha256_n24_w1_pub.txt deleted file mode 100644 index 57dc596690..0000000000 --- a/test/recipes/15-test_lms_codecs_data/sha256_n24_w1_pub.txt +++ /dev/null @@ -1,12 +0,0 @@ -lms-type: SHA256-N24-H5 (0xa) -lm-ots-type: SHA256-N24-W1 (0x5) -Id: - bb:9c:1b:5f:cf:12:86:c4:1f:7d:cd:e9:fb:53:a5:39 -LMS Public-Key: -pub: - 00:00:00:0a:00:00:00:05:bb:9c:1b:5f:cf:12:86:c4: - 1f:7d:cd:e9:fb:53:a5:39:c7:e3:e5:ee:f5:fa:b8:78: - bd:36:c0:4e:ab:54:de:f7:cc:25:8c:32:a8:42:c4:fd -K: - c7:e3:e5:ee:f5:fa:b8:78:bd:36:c0:4e:ab:54:de:f7: - cc:25:8c:32:a8:42:c4:fd diff --git a/test/recipes/15-test_lms_codecs_data/sha256_n24_w1_sig.bin b/test/recipes/15-test_lms_codecs_data/sha256_n24_w1_sig.bin deleted file mode 100644 index 573353d7f5..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/sha256_n24_w1_sig.bin and /dev/null differ diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w1_msg.bin b/test/recipes/15-test_lms_codecs_data/shake_n24_w1_msg.bin deleted file mode 100644 index 289557b085..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n24_w1_msg.bin +++ /dev/null @@ -1,2 +0,0 @@ -7–\æ7Ь_ô -þM¢0Gùx@&?¼Tˆòv "G('ûEÖhƒp»ò_¡©Ô5ãÖ7^‘¢½ ~hQSº´ÓN=±1ŒŸ·âzô—qß_u·ûv9÷놵ýÕ‘ƒ$Ș¦íCK9ÌÿÕË™©&Ã|>ãj=Ø›çäŸWi \ No newline at end of file diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w1_pub.der b/test/recipes/15-test_lms_codecs_data/shake_n24_w1_pub.der deleted file mode 100644 index db738593cc..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/shake_n24_w1_pub.der and /dev/null differ diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w1_pub.pem b/test/recipes/15-test_lms_codecs_data/shake_n24_w1_pub.pem deleted file mode 100644 index 61a6b6c7a0..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n24_w1_pub.pem +++ /dev/null @@ -1,4 +0,0 @@ ------BEGIN PUBLIC KEY----- -MEYwDQYLKoZIhvcNAQkQAxEDNQAAAAABAAAAGAAAAA3hiMFvJkCjYSJ8Y1MrEAPo -BgOLGt8IGv2dTCxXArrkJ9yn/UDYE1gw ------END PUBLIC KEY----- diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w1_pub.txt b/test/recipes/15-test_lms_codecs_data/shake_n24_w1_pub.txt deleted file mode 100644 index 74d176b71d..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n24_w1_pub.txt +++ /dev/null @@ -1,12 +0,0 @@ -lms-type: SHAKE-N24-H25 (0x18) -lm-ots-type: SHAKE-N24-W1 (0xd) -Id: - e1:88:c1:6f:26:40:a3:61:22:7c:63:53:2b:10:03:e8 -LMS Public-Key: -pub: - 00:00:00:18:00:00:00:0d:e1:88:c1:6f:26:40:a3:61: - 22:7c:63:53:2b:10:03:e8:06:03:8b:1a:df:08:1a:fd: - 9d:4c:2c:57:02:ba:e4:27:dc:a7:fd:40:d8:13:58:30 -K: - 06:03:8b:1a:df:08:1a:fd:9d:4c:2c:57:02:ba:e4:27: - dc:a7:fd:40:d8:13:58:30 diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w1_sig.bin b/test/recipes/15-test_lms_codecs_data/shake_n24_w1_sig.bin deleted file mode 100644 index 9b8a45e6db..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/shake_n24_w1_sig.bin and /dev/null differ diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w2_msg.bin b/test/recipes/15-test_lms_codecs_data/shake_n24_w2_msg.bin deleted file mode 100644 index 5028abb9de..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n24_w2_msg.bin +++ /dev/null @@ -1,2 +0,0 @@ -é^/ BšÁ¢(ßáôÑuV*áª"®Ççiø`ž$g;É8 û­:ÿR±¹}ì1¶ Ÿo?Z… -v+º|™Sáÿ_àÌö™Ü<0(¸>$uú²xI›ª;í—ñG;‚Ùr^§°¼¹Gõ/A÷ “Õ•-S]ïð«};R$ \ No newline at end of file diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w2_pub.der b/test/recipes/15-test_lms_codecs_data/shake_n24_w2_pub.der deleted file mode 100644 index 041cc4518c..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/shake_n24_w2_pub.der and /dev/null differ diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w2_pub.pem b/test/recipes/15-test_lms_codecs_data/shake_n24_w2_pub.pem deleted file mode 100644 index bd75db43ba..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n24_w2_pub.pem +++ /dev/null @@ -1,4 +0,0 @@ ------BEGIN PUBLIC KEY----- -MEYwDQYLKoZIhvcNAQkQAxEDNQAAAAABAAAAFwAAAA5asYCHy4y+LHiEhTrF+45u -WeqnTn3NQY/AtFRb8S/IlLFjxDjHuZPS ------END PUBLIC KEY----- diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w2_pub.txt b/test/recipes/15-test_lms_codecs_data/shake_n24_w2_pub.txt deleted file mode 100644 index 59572f28b0..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n24_w2_pub.txt +++ /dev/null @@ -1,12 +0,0 @@ -lms-type: SHAKE-N24-H20 (0x17) -lm-ots-type: SHAKE-N24-W2 (0xe) -Id: - 5a:b1:80:87:cb:8c:be:2c:78:84:85:3a:c5:fb:8e:6e -LMS Public-Key: -pub: - 00:00:00:17:00:00:00:0e:5a:b1:80:87:cb:8c:be:2c: - 78:84:85:3a:c5:fb:8e:6e:59:ea:a7:4e:7d:cd:41:8f: - c0:b4:54:5b:f1:2f:c8:94:b1:63:c4:38:c7:b9:93:d2 -K: - 59:ea:a7:4e:7d:cd:41:8f:c0:b4:54:5b:f1:2f:c8:94: - b1:63:c4:38:c7:b9:93:d2 diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w2_sig.bin b/test/recipes/15-test_lms_codecs_data/shake_n24_w2_sig.bin deleted file mode 100644 index a6c8730b73..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/shake_n24_w2_sig.bin and /dev/null differ diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w4_msg.bin b/test/recipes/15-test_lms_codecs_data/shake_n24_w4_msg.bin deleted file mode 100644 index 76372b99fb..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/shake_n24_w4_msg.bin and /dev/null differ diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w4_pub.der b/test/recipes/15-test_lms_codecs_data/shake_n24_w4_pub.der deleted file mode 100644 index 5a00b90eaa..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/shake_n24_w4_pub.der and /dev/null differ diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w4_pub.pem b/test/recipes/15-test_lms_codecs_data/shake_n24_w4_pub.pem deleted file mode 100644 index 2b1aca7f66..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n24_w4_pub.pem +++ /dev/null @@ -1,4 +0,0 @@ ------BEGIN PUBLIC KEY----- -MEYwDQYLKoZIhvcNAQkQAxEDNQAAAAABAAAAFQAAAA8FRHkVfAnrfjSnkWv0wDTi -TwIBexRlvoUYM8uY201/i9qtrkT/IHG7 ------END PUBLIC KEY----- diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w4_pub.txt b/test/recipes/15-test_lms_codecs_data/shake_n24_w4_pub.txt deleted file mode 100644 index d95cd00a15..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n24_w4_pub.txt +++ /dev/null @@ -1,12 +0,0 @@ -lms-type: SHAKE-N24-H10 (0x15) -lm-ots-type: SHAKE-N24-W4 (0xf) -Id: - 05:44:79:15:7c:09:eb:7e:34:a7:91:6b:f4:c0:34:e2 -LMS Public-Key: -pub: - 00:00:00:15:00:00:00:0f:05:44:79:15:7c:09:eb:7e: - 34:a7:91:6b:f4:c0:34:e2:4f:02:01:7b:14:65:be:85: - 18:33:cb:98:db:4d:7f:8b:da:ad:ae:44:ff:20:71:bb -K: - 4f:02:01:7b:14:65:be:85:18:33:cb:98:db:4d:7f:8b: - da:ad:ae:44:ff:20:71:bb diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w4_sig.bin b/test/recipes/15-test_lms_codecs_data/shake_n24_w4_sig.bin deleted file mode 100644 index f2b7cce9af..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/shake_n24_w4_sig.bin and /dev/null differ diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w8_msg.bin b/test/recipes/15-test_lms_codecs_data/shake_n24_w8_msg.bin deleted file mode 100644 index 4116f7fe2a..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n24_w8_msg.bin +++ /dev/null @@ -1,2 +0,0 @@ - *6YŸ&uä˜ßNð¥p'Øl51ã?lzó‚‹âÁÐô†W$NÊ -°,ó,Χ½ìVÉߪ°)¨i0&Ä®õ­³]}-¢LßP“Ì•"]³6œæ†~êÁ9´¢|lV}†ùdÊÁ#òO^”àêBË$Ö‡¶ŽŠ½ÀÉt€p2 \ No newline at end of file diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w8_pub.der b/test/recipes/15-test_lms_codecs_data/shake_n24_w8_pub.der deleted file mode 100644 index 55d9a499ca..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/shake_n24_w8_pub.der and /dev/null differ diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w8_pub.pem b/test/recipes/15-test_lms_codecs_data/shake_n24_w8_pub.pem deleted file mode 100644 index b9d91ba840..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n24_w8_pub.pem +++ /dev/null @@ -1,4 +0,0 @@ ------BEGIN PUBLIC KEY----- -MEYwDQYLKoZIhvcNAQkQAxEDNQAAAAABAAAAFgAAABBKkKgaFDJ5ZZeXtXKGbK0k -Wz5VJo3faGque7ml53MEoMgiDstCvQCI ------END PUBLIC KEY----- diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w8_pub.txt b/test/recipes/15-test_lms_codecs_data/shake_n24_w8_pub.txt deleted file mode 100644 index e1d1669135..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n24_w8_pub.txt +++ /dev/null @@ -1,12 +0,0 @@ -lms-type: SHAKE-N24-H15 (0x16) -lm-ots-type: SHAKE-N24-W8 (0x10) -Id: - 4a:90:a8:1a:14:32:79:65:97:97:b5:72:86:6c:ad:24 -LMS Public-Key: -pub: - 00:00:00:16:00:00:00:10:4a:90:a8:1a:14:32:79:65: - 97:97:b5:72:86:6c:ad:24:5b:3e:55:26:8d:df:68:6a: - ae:7b:b9:a5:e7:73:04:a0:c8:22:0e:cb:42:bd:00:88 -K: - 5b:3e:55:26:8d:df:68:6a:ae:7b:b9:a5:e7:73:04:a0: - c8:22:0e:cb:42:bd:00:88 diff --git a/test/recipes/15-test_lms_codecs_data/shake_n24_w8_sig.bin b/test/recipes/15-test_lms_codecs_data/shake_n24_w8_sig.bin deleted file mode 100644 index 2705ff88c1..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/shake_n24_w8_sig.bin and /dev/null differ diff --git a/test/recipes/15-test_lms_codecs_data/shake_n32_w1_msg.bin b/test/recipes/15-test_lms_codecs_data/shake_n32_w1_msg.bin deleted file mode 100644 index c7066c1358..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n32_w1_msg.bin +++ /dev/null @@ -1 +0,0 @@ -Ý«å¸ÁHiä¹Ï«èy˜Ö&´~`bP”lÖÕ]µóÄ×÷{ÿlÐ,†Ìš›o3ê÷n_º<Õ'ä%Ó–j†¬jdD(É7wy’ªîÇ; øÞô\ D•%ßGOÝØ5>ÿ‰˜012)ºùøÝºŠ¿€ú<žzg \ No newline at end of file diff --git a/test/recipes/15-test_lms_codecs_data/shake_n32_w1_pub.der b/test/recipes/15-test_lms_codecs_data/shake_n32_w1_pub.der deleted file mode 100644 index 0474e535d4..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/shake_n32_w1_pub.der and /dev/null differ diff --git a/test/recipes/15-test_lms_codecs_data/shake_n32_w1_pub.pem b/test/recipes/15-test_lms_codecs_data/shake_n32_w1_pub.pem deleted file mode 100644 index 745d68e8f1..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n32_w1_pub.pem +++ /dev/null @@ -1,4 +0,0 @@ ------BEGIN PUBLIC KEY----- -ME4wDQYLKoZIhvcNAQkQAxEDPQAAAAABAAAAEQAAAAl0e74SphV4ef9P0i/rzbVX -ZhA1zoQ7v9BdHYPpf5Y1di1uJ0J48CEp4+bi4BKFnx4= ------END PUBLIC KEY----- diff --git a/test/recipes/15-test_lms_codecs_data/shake_n32_w1_pub.txt b/test/recipes/15-test_lms_codecs_data/shake_n32_w1_pub.txt deleted file mode 100644 index 685066ea94..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n32_w1_pub.txt +++ /dev/null @@ -1,13 +0,0 @@ -lms-type: SHAKE-N32-H15 (0x11) -lm-ots-type: SHAKE-N32-W1 (0x9) -Id: - 74:7b:be:12:a6:15:78:79:ff:4f:d2:2f:eb:cd:b5:57 -LMS Public-Key: -pub: - 00:00:00:11:00:00:00:09:74:7b:be:12:a6:15:78:79: - ff:4f:d2:2f:eb:cd:b5:57:66:10:35:ce:84:3b:bf:d0: - 5d:1d:83:e9:7f:96:35:76:2d:6e:27:42:78:f0:21:29: - e3:e6:e2:e0:12:85:9f:1e -K: - 66:10:35:ce:84:3b:bf:d0:5d:1d:83:e9:7f:96:35:76: - 2d:6e:27:42:78:f0:21:29:e3:e6:e2:e0:12:85:9f:1e diff --git a/test/recipes/15-test_lms_codecs_data/shake_n32_w1_sig.bin b/test/recipes/15-test_lms_codecs_data/shake_n32_w1_sig.bin deleted file mode 100644 index 80da90a09d..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/shake_n32_w1_sig.bin and /dev/null differ diff --git a/test/recipes/15-test_lms_codecs_data/shake_n32_w8_msg.bin b/test/recipes/15-test_lms_codecs_data/shake_n32_w8_msg.bin deleted file mode 100644 index 637df1950f..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n32_w8_msg.bin +++ /dev/null @@ -1 +0,0 @@ -K*ÙÇDã…½“ÀWŠÉªoâ³¼?ã^¥i„|ç—Ò@ØF¿­×*xOFó“±ÁQp® ¥ie é†çùÕ`°'r‚Y&¥ñH,PŸŠ½÷‚gJ_OÛÈ=Yƒžô7;¿aj-¥" ´Å\ÅO%u’—É—ìçsz†H \ No newline at end of file diff --git a/test/recipes/15-test_lms_codecs_data/shake_n32_w8_pub.der b/test/recipes/15-test_lms_codecs_data/shake_n32_w8_pub.der deleted file mode 100644 index 95bd5af430..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/shake_n32_w8_pub.der and /dev/null differ diff --git a/test/recipes/15-test_lms_codecs_data/shake_n32_w8_pub.pem b/test/recipes/15-test_lms_codecs_data/shake_n32_w8_pub.pem deleted file mode 100644 index 4ffcce60c6..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n32_w8_pub.pem +++ /dev/null @@ -1,4 +0,0 @@ ------BEGIN PUBLIC KEY----- -ME4wDQYLKoZIhvcNAQkQAxEDPQAAAAABAAAAEwAAAAyXL+d31A/h79l2A6YnM80c -0tbxPFSghfIwF7vUaWXAhTq8Nj+rztkRmiYzejBqe4g= ------END PUBLIC KEY----- diff --git a/test/recipes/15-test_lms_codecs_data/shake_n32_w8_pub.txt b/test/recipes/15-test_lms_codecs_data/shake_n32_w8_pub.txt deleted file mode 100644 index bd82d8cf90..0000000000 --- a/test/recipes/15-test_lms_codecs_data/shake_n32_w8_pub.txt +++ /dev/null @@ -1,13 +0,0 @@ -lms-type: SHAKE-N32-H25 (0x13) -lm-ots-type: SHAKE-N32-W8 (0xc) -Id: - 97:2f:e7:77:d4:0f:e1:ef:d9:76:03:a6:27:33:cd:1c -LMS Public-Key: -pub: - 00:00:00:13:00:00:00:0c:97:2f:e7:77:d4:0f:e1:ef: - d9:76:03:a6:27:33:cd:1c:d2:d6:f1:3c:54:a0:85:f2: - 30:17:bb:d4:69:65:c0:85:3a:bc:36:3f:ab:ce:d9:11: - 9a:26:33:7a:30:6a:7b:88 -K: - d2:d6:f1:3c:54:a0:85:f2:30:17:bb:d4:69:65:c0:85: - 3a:bc:36:3f:ab:ce:d9:11:9a:26:33:7a:30:6a:7b:88 diff --git a/test/recipes/15-test_lms_codecs_data/shake_n32_w8_sig.bin b/test/recipes/15-test_lms_codecs_data/shake_n32_w8_sig.bin deleted file mode 100644 index 39a2faf9d1..0000000000 Binary files a/test/recipes/15-test_lms_codecs_data/shake_n32_w8_sig.bin and /dev/null differ diff --git a/test/recipes/15-test_ml_dsa_codecs.t b/test/recipes/15-test_ml_dsa_codecs.t index 16fc5c3021..3c1e9e1bbc 100644 --- a/test/recipes/15-test_ml_dsa_codecs.t +++ b/test/recipes/15-test_ml_dsa_codecs.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -26,7 +26,7 @@ my @formats = qw(seed-priv priv-only seed-only oqskeypair bare-seed bare-priv); plan skip_all => "ML-DSA isn't supported in this build" if disabled("ml-dsa"); -plan tests => @algs * (27 + 13 * @formats); +plan tests => @algs * (23 + 10 * @formats); my $seed = join ("", map {sprintf "%02x", $_} (0..31)); my $weed = join ("", map {sprintf "%02x", $_} (1..32)); my $ikme = join ("", map {sprintf "%02x", $_} (0..31)); @@ -45,12 +45,6 @@ foreach my $alg (@algs) { my $der0 = sprintf("pub-%s.%d.der", $alg, $i++); ok(run(app(['openssl', 'pkey', '-pubin', '-in', $in0, '-outform', 'DER', '-out', $der0]))); - - # Default encoding (no -encopt) is seed-priv; used as a control below. - my $plain = sprintf("prv-%s.plain.pem", $alg); - ok(run(app(['openssl', 'pkey', '-in', data_file($formats{'seed-priv'}), - '-out', $plain])), - sprintf("pkey default re-encode: %s", $alg)); foreach my $f (keys %formats) { my $kf = $formats{$f}; my %pruned = %formats; @@ -69,7 +63,7 @@ foreach my $alg (@algs) { my $pem = sprintf("prv-%s-%s.%d.pem", $alg, $f, $i++); ok(run(app(['openssl', 'genpkey', '-out', $pem, '-pkeyopt', "hexseed:$seed", '-algorithm', "ml-dsa-$alg", - '-encopt', "output_formats:$f"]))); + '-provparam', "ml-dsa.output_formats=$f"]))); ok(!compare_text($in, $pem), sprintf("prvkey PEM match: %s, %s", $alg, $f)); @@ -77,20 +71,6 @@ foreach my $alg (@algs) { '-provparam', "ml-dsa.input_formats=$f"]))); ok(!run(app(['openssl', 'pkey', '-in', $in, '-noout', '-provparam', "ml-dsa.input_formats=$rest"]))); - - # Re-encode the seed-priv key into format $f via 'pkey -encopt' and - # check it matches the reference; the control asserts the match is due - # to -encopt, i.e. it differs from the default for every non-seed-priv - # format (and equals it for seed-priv). - my $enc = sprintf("prv-%s-%s.enc.pem", $alg, $f); - ok(run(app(['openssl', 'pkey', '-in', data_file($formats{'seed-priv'}), - '-encopt', "output_formats:$f", '-out', $enc])), - sprintf("pkey -encopt re-encode: %s, %s", $alg, $f)); - ok(!compare_text($in, $enc), - sprintf("pkey -encopt output_formats match: %s, %s", $alg, $f)); - ok($f eq 'seed-priv' ? compare_text($plain, $enc) == 0 - : compare_text($plain, $enc) != 0, - sprintf("pkey -encopt changed the encoding: %s, %s", $alg, $f)); } # (1 + 2 * @formats) tests @@ -232,17 +212,4 @@ foreach my $alg (@algs) { ok(!run(app([qw(openssl pkey -provparam ml-dsa.prefer_seed=no), qw(-inform DER -noout -in), $mash])), sprintf("reject real private and mutated public: %s", $alg)); - - # 3 wrapping tests - my $wrapped = sprintf('wrapped-%s.bin', $alg); - my $unwrapped = sprintf('unwrapped-%s.bin', $alg); - my $aes_key = '0102030405060708091011121314151617181920212223242526272829303132'; - ok(run(app([qw(openssl enc -pbkdf2 -id-aes256-wrap-pad -k), $aes_key, - '-in', $real, '-out', $wrapped])), - sprintf("AES Wrap private: %s", $alg)); - ok(run(app([qw(openssl enc -d -pbkdf2 -id-aes256-wrap-pad -k), $aes_key, - '-in', $wrapped, '-out', $unwrapped])), - sprintf("AES Unwrap private: %s", $alg)); - ok(!compare($unwrapped, $real), - sprintf("Unwrapped DER match: %s, %s", $alg, $real)); } diff --git a/test/recipes/15-test_ml_kem_codecs.t b/test/recipes/15-test_ml_kem_codecs.t index 25d92571c5..bebb8b8e85 100644 --- a/test/recipes/15-test_ml_kem_codecs.t +++ b/test/recipes/15-test_ml_kem_codecs.t @@ -59,7 +59,7 @@ foreach my $alg (@algs) { my $pem = sprintf("prv-%s-%s.%d.pem", $alg, $f, $i++); ok(run(app(['openssl', 'genpkey', '-out', $pem, '-pkeyopt', "hexseed:$seed", '-algorithm', "ml-kem-$alg", - '-encopt', "output_formats:$f"]))); + '-provparam', "ml-kem.output_formats=$f"]))); ok(!compare_text($in, $pem), sprintf("prvkey PEM match: %s, %s", $alg, $f)); diff --git a/test/recipes/15-test_pkey.t b/test/recipes/15-test_pkey.t index fa4363f057..3d6023e435 100644 --- a/test/recipes/15-test_pkey.t +++ b/test/recipes/15-test_pkey.t @@ -16,7 +16,7 @@ use OpenSSL::Test qw/:DEFAULT srctop_file/; setup("test_pkey"); -plan tests => 7; +plan tests => 5; my @app = ('openssl', 'pkey'); @@ -88,7 +88,7 @@ subtest "=== pkey handling of public keys (Ed25519) ===" => sub { ok(run(app([@app, '-in', $in_ed_key, '-pubin', '-pubout', '-out', $pub_out3])), "extract public key from pkey file with -pubin"); is(compare_text($in_pubkey, $pub_out3), 0, - "public key extracted from pkey file with -pubin is same as original"); + "public key extraced from pkey file with -pubin is same as original"); }; @@ -112,108 +112,18 @@ subtest "=== pkey handling of DER encoding ===" => sub { "Same file contents after converting to DER and back"); }; -subtest "=== pkey text and text_pub output ===" => sub { - plan tests => 6; +subtest "=== pkey text output ===" => sub { + plan tests => 3; ok((grep /BEGIN PRIVATE KEY/, run(app([@app, '-in', $in_key, '-text']), capture => 1)), "pkey text output contains PEM header"); ok(!(grep /BEGIN PRIVATE KEY/, - run(app([@app, '-in', $in_key, '-text', '-noout']), capture => 1)), - "pkey text output with -noout does not contain PEM header"); + run(app([@app, '-in', $in_key, '-text', '-noout']), capture => 1)), + "pkey text output with -noout does not contain PEM header"); ok((grep /Private-Key:/, run(app([@app, '-in', $in_key, '-text', '-noout']), capture => 1)), "pkey text output (even with -noout) contains \"Private-Key:\""); - - ok(!(grep /Private-Key:/, - run(app([@app, '-in', $in_key, '-text_pub', '-noout']), capture => 1)), - "-text_pub does not print private key components"); - - ok((grep /Public-Key:/, - run(app([@app, '-in', $in_key, '-text_pub', '-noout']), capture => 1)), - "-text_pub prints public key components"); - - ok(!run(app([@app, '-in', $in_key, '-text', '-outform', 'DER', - '-out', 'text_der.tmp'])), - "-text combined with DER output is rejected"); -}; - -subtest "=== pkey EC point conversion form ===" => sub { - plan skip_all => "EC not supported in this build" if disabled("ec"); - plan tests => 8; - - my $ec_key = 'ec_p256.pem'; - ok(run(app(['openssl', 'genpkey', '-algorithm', 'EC', - '-pkeyopt', 'ec_paramgen_curve:P-256', '-out', $ec_key])), - "generate P-256 EC key"); - - # In a named-curve P-256 SubjectPublicKeyInfo the EC point starts at a - # fixed 26-byte offset, so its first octet identifies the conversion form: - # 0x04 uncompressed, 0x02/0x03 compressed, 0x06/0x07 hybrid. - sub point_lead { - open IN, '<', $_[0] or return -1; - binmode IN; - read IN, my $buf, 27; - close IN; - return ord substr($buf, 26, 1); - } - - my $unc = 'pub_unc.der'; - ok(run(app([@app, '-in', $ec_key, '-pubout', '-ec_conv_form', 'uncompressed', - '-outform', 'DER', '-out', $unc])), - "write uncompressed public key"); - is(point_lead($unc), 0x04, "uncompressed point has 0x04 prefix"); - - my $comp = 'pub_comp.der'; - ok(run(app([@app, '-in', $ec_key, '-pubout', '-ec_conv_form', 'compressed', - '-outform', 'DER', '-out', $comp])), - "write compressed public key"); - my $clead = point_lead($comp); - ok($clead == 0x02 || $clead == 0x03, "compressed point has 0x02/0x03 prefix"); - - my $hyb = 'pub_hyb.der'; - ok(run(app([@app, '-in', $ec_key, '-pubout', '-ec_conv_form', 'hybrid', - '-outform', 'DER', '-out', $hyb])), - "write hybrid public key"); - my $hlead = point_lead($hyb); - ok($hlead == 0x06 || $hlead == 0x07, "hybrid point has 0x06/0x07 prefix"); - - ok(!run(app([@app, '-in', $in_key, '-ec_conv_form', 'compressed', '-noout'])), - "-ec_conv_form on a non-EC key fails"); -}; - -subtest "=== pkey EC parameter encoding ===" => sub { - plan skip_all => "EC not supported in this build" if disabled("ec"); - plan tests => 6; - - my $ec_key = 'ec_p256_enc.pem'; - ok(run(app(['openssl', 'genpkey', '-algorithm', 'EC', - '-pkeyopt', 'ec_paramgen_curve:P-256', '-out', $ec_key])), - "generate P-256 EC key"); - - # A named_curve encoding identifies the group by its OID (prime256v1), - # whereas an explicit encoding inlines the full curve parameters, which - # asn1parse shows via the field-type OID (prime-field). - my $named = 'pub_named.der'; - ok(run(app([@app, '-in', $ec_key, '-pubout', '-ec_param_enc', 'named_curve', - '-outform', 'DER', '-out', $named])), - "write public key with named_curve parameters"); - ok((grep /prime256v1/, - run(app(['openssl', 'asn1parse', '-in', $named, '-inform', 'DER']), - capture => 1)), - "named_curve encoding references the curve by OID"); - - my $explicit = 'pub_explicit.der'; - ok(run(app([@app, '-in', $ec_key, '-pubout', '-ec_param_enc', 'explicit', - '-outform', 'DER', '-out', $explicit])), - "write public key with explicit parameters"); - ok((grep /prime-field/, - run(app(['openssl', 'asn1parse', '-in', $explicit, '-inform', 'DER']), - capture => 1)), - "explicit encoding inlines the curve parameters"); - - ok(!run(app([@app, '-in', $in_key, '-ec_param_enc', 'explicit', '-noout'])), - "-ec_param_enc on a non-EC key fails"); }; diff --git a/test/recipes/15-test_rsa.t b/test/recipes/15-test_rsa.t index c7eafbfb1c..e0ac15772a 100644 --- a/test/recipes/15-test_rsa.t +++ b/test/recipes/15-test_rsa.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2023 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -11,13 +11,12 @@ use strict; use warnings; use File::Spec; -use File::Compare qw/compare/; use OpenSSL::Test qw/:DEFAULT srctop_file/; use OpenSSL::Test::Utils; setup("test_rsa"); -plan tests => 17; +plan tests => 14; require_ok(srctop_file('test', 'recipes', 'tconversion.pl')); @@ -27,53 +26,6 @@ run_rsa_tests("pkey"); run_rsa_tests("rsa"); -SKIP: { - skip "RSA is not supported in this build", 1 if disabled("rsa"); - - subtest "rsa -text prints the key in text form" => sub { - plan tests => 6; - - # The modulus (n) and private exponent (d) of the committed - # testrsa.pem keypair. -text prints them as colon-separated hex; we - # strip the formatting and compare against the known values so the - # actual key material, not just the labels, is verified. - my $modulus = "AADB7AA92E464F15711996166B4FF8BBE2301DFEE9D8B3596DC3" - . "C1A7DFCE7C87180170509FC84EFD17B5BB02CA5DD0A3228686B380CB746F" - . "3CAE4CDFC8AE5D3D"; - my $priv_exp = "677727CDA1D733F6F119A479091D51AC3D6A1410157E840588E1" - . "FDB8F26031AA00BA84048AC3C755C64329C3AFE30120EBF4C89C02170671" - . "2282DAAF473BB2A1"; - - my @priv = run(app(['openssl', 'rsa', '-text', '-noout', - '-in', srctop_file("test", "testrsa.pem")], - stderr => undef), - capture => 1); - chomp @priv; - my $priv_blob = uc join('', @priv); - $priv_blob =~ s/[^0-9A-F]//g; - ok(grep(/^Private-Key: \(512 bit, 2 primes\)$/, @priv), - "-text prints the private key header"); - ok(index($priv_blob, $modulus) >= 0, - "-text prints the expected modulus for a private key"); - ok(index($priv_blob, $priv_exp) >= 0, - "-text prints the expected private exponent"); - - my @pub = run(app(['openssl', 'rsa', '-pubin', '-text', '-noout', - '-in', srctop_file("test", "testrsapub.pem")], - stderr => undef), - capture => 1); - chomp @pub; - my $pub_blob = uc join('', @pub); - $pub_blob =~ s/[^0-9A-F]//g; - ok(grep(/^Public-Key: \(512 bit\)$/, @pub), - "-text prints the public key header"); - ok(index($pub_blob, $modulus) >= 0, - "-text prints the expected modulus for a public key"); - ok(!grep(/privateExponent/, @pub), - "-text does not print a private exponent for a public key"); - }; -} - sub run_rsa_tests { my $cmd = shift; @@ -102,7 +54,7 @@ sub run_rsa_tests { SKIP: { skip "Skipping msblob conversion test", 1 - if disabled("rsa") || $cmd eq 'pkey'; + if disabled($cmd) || $cmd eq 'pkey'; subtest "$cmd conversions -- public key" => sub { tconversion( -type => 'msb', -prefix => "$cmd-msb-pub", @@ -112,8 +64,8 @@ sub run_rsa_tests { } SKIP: { skip "Skipping PVK conversion test", 1 - if disabled("rsa") || $cmd eq 'pkey' || disabled("rc4") - || disabled ("legacy") || disabled("pvkkdf"); + if disabled($cmd) || $cmd eq 'pkey' || disabled("rc4") + || disabled ("legacy"); subtest "$cmd conversions -- private key" => sub { tconversion( -type => 'pvk', -prefix => "$cmd-pvk", @@ -124,59 +76,4 @@ sub run_rsa_tests { "-provider", "legacy"] ); }; } - - SKIP: { - # -RSAPublicKey_in/-RSAPublicKey_out are specific to the rsa app and - # select the PKCS#1 RSAPublicKey structure instead of the - # SubjectPublicKeyInfo used by -pubin/-pubout. - skip "Skipping RSAPublicKey conversion test", 1 - if disabled("rsa") || $cmd eq 'pkey'; - - subtest "$cmd conversions -- RSAPublicKey (PKCS#1) public key" => sub { - plan tests => 9; - - my $priv = srctop_file("test", "testrsa.pem"); - my $pub = srctop_file("test", "testrsapub.pem"); - - my $rsapub = "$cmd-rsapub.pem"; - ok(run(app(['openssl', 'rsa', '-in', $priv, '-RSAPublicKey_out', - '-out', $rsapub])), - "RSAPublicKey_out writes a public key"); - open(my $fh, '<', $rsapub); - my @rsapub_pem = <$fh>; - close($fh); - ok(grep(/BEGIN RSA PUBLIC KEY/, @rsapub_pem), - "RSAPublicKey_out uses the PKCS#1 RSA PUBLIC KEY header"); - - # Re-encoding an RSAPublicKey input as RSAPublicKey is stable. - my $rsapub2 = "$cmd-rsapub2.pem"; - ok(run(app(['openssl', 'rsa', '-in', $rsapub, '-RSAPublicKey_in', - '-RSAPublicKey_out', '-out', $rsapub2])), - "RSAPublicKey_in reads an RSAPublicKey"); - is(compare($rsapub, $rsapub2), 0, - "RSAPublicKey_in round-trips to an identical RSAPublicKey"); - - # RSAPublicKey input re-encoded as SubjectPublicKeyInfo matches the - # canonical SubjectPublicKeyInfo public key. - my $spki1 = "$cmd-spki1.pem"; - my $spki2 = "$cmd-spki2.pem"; - ok(run(app(['openssl', 'rsa', '-in', $rsapub, '-RSAPublicKey_in', - '-pubout', '-out', $spki1])), - "RSAPublicKey_in can be written as SubjectPublicKeyInfo"); - ok(run(app(['openssl', 'rsa', '-in', $pub, '-pubin', '-pubout', - '-out', $spki2])), - "canonical SubjectPublicKeyInfo public key written"); - is(compare($spki1, $spki2), 0, - "RSAPublicKey_in -pubout matches the SubjectPublicKeyInfo key"); - - # Conversely, a SubjectPublicKeyInfo input written as RSAPublicKey - # matches the RSAPublicKey extracted from the private key. - my $rsapub3 = "$cmd-rsapub3.pem"; - ok(run(app(['openssl', 'rsa', '-in', $pub, '-pubin', - '-RSAPublicKey_out', '-out', $rsapub3])), - "SubjectPublicKeyInfo input can be written as RSAPublicKey"); - is(compare($rsapub, $rsapub3), 0, - "pubin -RSAPublicKey_out matches the extracted RSAPublicKey"); - }; - } } diff --git a/test/recipes/20-test_app_ech.t b/test/recipes/20-test_app_ech.t deleted file mode 100644 index f242c44773..0000000000 --- a/test/recipes/20-test_app_ech.t +++ /dev/null @@ -1,106 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html -# - -use strict; -use warnings; - -use OpenSSL::Test::Utils; -use OpenSSL::Test qw/:DEFAULT srctop_file srctop_dir bldtop_dir bldtop_file with/; - -setup("test_app_ech"); - -plan skip_all => "ECH tests not supported in this build" - if disabled("ech") || disabled("tls1_3") - || disabled("ec") || disabled("ecx"); - -plan tests => 16; - -ok(run(app(["openssl", "ech", "-help"])), - "Run openssl ech with help"); -ok(run(app(["openssl", "ech", - "-ech_version", "13", - "-public_name", "example.com", - "-out", "eg1.pem", - "-verbose", - "-text"])), - "Generate an ECH key pair for example.com"); -ok(run(app(["openssl", "ech", - "-suite", "0x10,2,2", - "-public_name", "example.com", - "-out", "eg2.pem", - "-text"])), - "Generate an ECDSA ECH key pair for example.com"); -ok(run(app(["openssl", "ech", - "-max_name_len", "13", - "-public_name", "example.com", - "-out", "eg2.pem", - "-text"])), - "Generate an ECH key pair for example.com with max name len 13"); -ok(run(app(["openssl", "ech", - "-in", "eg1.pem", - "-in", "eg2.pem", - "-out", "eg3.pem", - "-verbose"])), - "Catenate the ECH for example.com twice"); -ok(run(app(["openssl", "ech", - "-in", "eg3.pem", - "-select", "1", - "-verbose", - "-out", "eg4.pem"])), - "Select one ECH Config"); - -with({ exit_checker => sub { return shift == 1; } }, - sub { - ok(run(app(["openssl", "ech" ])), - "Run openssl ech with no arg"); - ok(run(app(["openssl", "ech", "-nohelpatall"])), - "Run openssl ech with unknown arg"); - ok(run(app(["openssl", "ech", "nohelpatall"])), - "Run openssl ech with unknown non arg"); - ok(run(app(["openssl", "ech", - "-ech_version", "0xfe09", - "-public_name", "example.com", - "-out", "eg1.pem", - "-text"])), - "Fail to generate an ECH key pair for old draft version"); - ok(run(app(["openssl", "ech", - "-suite", "not,a,good,one", - "-public_name", "example.com", - "-out", "eg2.pem", - "-text"])), - "Fail to generate an ECH key pair with bad suite"); - ok(run(app(["openssl", "ech", - "-max_name_len", "1300", - "-public_name", "example.com", - "-text"])), - "(Fail to) Generate an ECH key pair for example.com with max name len 1300"); - ok(run(app(["openssl", "ech", - "-in", "eg1.pem", - "-in", "eg2.pem", - "-in", "eg3.pem", - "-in", "eg4.pem", - "-in", "eg1.pem", - "-in", "eg2.pem", - "-in", "eg3.pem", - "-in", "eg4.pem"])), - "Too many input files"); - ok(run(app(["openssl", "ech" ])), - "No input files"); - ok(run(app(["openssl", "ech", - "-public_name", "example.com", - "-out", "" - ])), - "(Fail to) Generate an ECH key pair to empty output file name"); - ok(run(app(["openssl", "ech", - "-in", "eg1.pem", - "-in", "eg2.pem", - "-out", "", - "-verbose"])), - "Fail to catenate due to empty output file name"); -}); diff --git a/test/recipes/20-test_app_s_client.t b/test/recipes/20-test_app_s_client.t deleted file mode 100644 index 162fb710da..0000000000 --- a/test/recipes/20-test_app_s_client.t +++ /dev/null @@ -1,110 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use warnings; - -use IO::Socket::INET; -use OpenSSL::Test qw/:DEFAULT result_file with/; -use OpenSSL::Test::Utils; - -setup("test_app_s_client"); - -plan skip_all => "test_app_s_client needs sock enabled" - if disabled("sock"); -plan skip_all => "test_app_s_client needs IPv4" - unless have_IPv4(); -plan skip_all => "test_app_s_client needs fork" - if $^O =~ /^(VMS|MSWin32|msys)$/; - -plan tests => 5; - -my $timeout = 30; -local $SIG{ALRM} = sub { BAIL_OUT("s_client Sieve STARTTLS test timed out") }; -alarm($timeout); - -my $listener = IO::Socket::INET->new( - LocalAddr => "127.0.0.1", - LocalPort => 0, - Listen => 1, - Proto => "tcp", - ReuseAddr => 1, -) or BAIL_OUT("failed to create local Sieve listener: $!"); - -my $port = $listener->sockport(); -my $command_file = result_file("sieve-starttls-command.txt"); -my $stdout_file = result_file("s_client-stdout.txt"); -my $stderr_file = result_file("s_client-stderr.txt"); -my $server_pid = fork(); - -BAIL_OUT("failed to fork Sieve listener: $!") unless defined $server_pid; - -if ($server_pid == 0) { - eval { - local $SIG{ALRM} = sub { die "Sieve listener timed out\n" }; - alarm($timeout); - - my $server = $listener->accept() - or die "failed to accept s_client connection: $!"; - - $server->autoflush(1); - print $server "\"STARTTLS\"\r\nOK\r\n"; - - my $command = <$server>; - open my $fh, ">", $command_file - or die "failed to open command capture file: $!"; - print $fh $command if defined $command; - close $fh; - - # This stub only needs to drive s_client through the plaintext - # Sieve STARTTLS response parser. After sending an exact two-byte - # lowercase OK response, it closes instead of performing TLS. The - # resulting handshake failure is expected, but sanitizer failures - # before that are not. - print $server "ok"; - close $server; - alarm(0); - }; - warn $@ if $@; - exit($@ ? 1 : 0); -} - -close $listener; - -with({ exit_checker => sub { return shift() < 128; } }, - sub { - ok(run(app(["openssl", "s_client", "-brief", "-starttls", "sieve", - "-connect", "127.0.0.1:$port"], - stdin => undef, stdout => $stdout_file, - stderr => $stderr_file)), - "s_client exits without signal"); - }); - -waitpid($server_pid, 0); -is($?, 0, "Sieve listener completed"); - -my $command = ""; -if (open my $fh, "<", $command_file) { - local $/; - $command = <$fh>; - close $fh; -} -is($command, "STARTTLS\r\n", "s_client sends Sieve STARTTLS command"); - -my $stderr = ""; -if (open my $fh, "<", $stderr_file) { - local $/; - $stderr = <$fh>; - close $fh; -} -unlike($stderr, qr/STARTTLS not supported/, - "s_client accepts case-insensitive two-byte OK response"); -unlike($stderr, qr/AddressSanitizer/, - "s_client does not trigger AddressSanitizer"); - -alarm(0); diff --git a/test/recipes/20-test_app_s_client_msg.t b/test/recipes/20-test_app_s_client_msg.t deleted file mode 100644 index 75d388efe8..0000000000 --- a/test/recipes/20-test_app_s_client_msg.t +++ /dev/null @@ -1,110 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use warnings; - -use IPC::Open3; -use OpenSSL::Test qw/:DEFAULT result_dir srctop_file bldtop_file/; -use OpenSSL::Test::Utils; - -my $test_name = "test_app_s_client_msg"; -setup($test_name); - -plan skip_all => "$test_name needs sock enabled" - if disabled("sock"); -plan skip_all => "$test_name is not available on Windows or VMS" - if $^O =~ /^(VMS|MSWin32|msys)$/; - -my $shlib_wrap = bldtop_file("util", "wrap.pl"); -my $apps_openssl = bldtop_file("apps", "openssl"); -my $server_pem = srctop_file("test", "certs", "servercert.pem"); -my $server_key = srctop_file("test", "certs", "serverkey.pem"); -my $resultdir = result_dir(); - -# Each case exercises the s_client message callback (-msg) over a different -# protocol version. Every record must be decoded; before the DTLSv1.2 fix such -# records were logged as "Not TLS data or unknown version". -my @cases = ( - { name => "TLSv1.2", flag => "-tls1_2", disabled => "tls1_2" }, - { name => "TLSv1.3", flag => "-tls1_3", disabled => "tls1_3" }, - { name => "DTLSv1.2", flag => "-dtls1_2", disabled => "dtls1_2" }, -); -@cases = grep { !disabled($_->{disabled}) } @cases; - -plan tests => scalar @cases; - -# Run one s_server/s_client handshake logging protocol messages via -msgfile. -# Returns the number of decoded and undecoded records seen in the log. -sub run_case -{ - my $case = shift; - my $msgfile = "$resultdir/s_client-msg-$case->{disabled}.txt"; - my ($records, $unknown) = (0, 0); - - eval { - local $SIG{ALRM} = sub { die "timeout\n" }; - alarm 60; - - # Start a server speaking just this protocol version - my @s_server_cmd = ("s_server", $case->{flag}, "-accept", "0", - "-naccept", "1", "-cert", $server_pem, - "-key", $server_key); - my $s_server_pid = open3(my $s_server_i, my $s_server_o, my $s_server_e, - $shlib_wrap, $apps_openssl, @s_server_cmd); - - # Figure out what port it is listening on - my $server_port = "0"; - while (<$s_server_o>) { - print($_); - chomp; - if (/^ACCEPT \S+?:(\d+)/) { - $server_port = $1; - last; - } elsif (/^Using default/) { - ; - } else { - last; - } - } - - # Connect a client that logs the protocol messages to a file. -msgfile - # sets the log destination but selects SSL_trace; the trailing -msg - # switches the callback back to msg_cb (the code under test) while - # keeping the file destination. - my @s_client_cmd = ("s_client", $case->{flag}, "-msgfile", $msgfile, - "-msg", "-connect", "localhost:$server_port"); - my $s_client_pid = open3(my $s_client_i, my $s_client_o, my $s_client_e, - $shlib_wrap, $apps_openssl, @s_client_cmd); - - # Quit the client once connected, then reap both processes - print $s_client_i "Q\n"; - waitpid($s_client_pid, 0); - kill 'HUP', $s_server_pid if kill 0, $s_server_pid; - waitpid($s_server_pid, 0); - - alarm 0; - }; - die $@ if $@ && $@ ne "timeout\n"; - print("TIMEOUT: $case->{name} timed out\n") if $@; - - if (open(my $fh, '<', $msgfile)) { - while (<$fh>) { - $records++ if /^(?:>>>|<<<)/; - $unknown++ if /Not TLS data or unknown version/; - } - close($fh); - } - return ($records, $unknown); -} - -foreach my $case (@cases) { - my ($records, $unknown) = run_case($case); - ok($records > 0 && $unknown == 0, - "s_client -msg decodes all $case->{name} records"); -} diff --git a/test/recipes/20-test_dgst.t b/test/recipes/20-test_dgst.t index 00af8cfff2..250821c9a7 100644 --- a/test/recipes/20-test_dgst.t +++ b/test/recipes/20-test_dgst.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -12,13 +12,13 @@ use warnings; use File::Spec; use File::Basename; -use OpenSSL::Test qw/:DEFAULT with srctop_file srctop_dir data_file bldtop_dir/; +use OpenSSL::Test qw/:DEFAULT with srctop_file data_file bldtop_dir/; use OpenSSL::Test::Utils; use Cwd qw(abs_path); setup("test_dgst"); -plan tests => 27; +plan tests => 24; sub tsignverify { my $testtext = shift; @@ -89,143 +89,91 @@ sub tsignverify_sha512 { $testtext.": Expect failure verifying mismatching data"); } -subtest "RSA signature generation and verification with `dgst` CLI" => sub { - if (disabled("rsa")) { - plan tests => 1; - ok(1, "Skipped (RSA not supported)"); - return; - } - tsignverify("RSA", - srctop_file("test","testrsa.pem"), - srctop_file("test","testrsapub.pem")); -}; +SKIP: { + skip "RSA is not supported by this OpenSSL build", 1 + if disabled("rsa"); -subtest "RSA signature generation and verification with `sha512` CLI" => sub { - if (disabled("rsa")) { - plan tests => 1; - ok(1, "Skipped (RSA not supported)"); - return; - } - tsignverify_sha512("RSA", - srctop_file("test","testrsa2048.pem"), - srctop_file("test","testrsa2048pub.pem")); -}; + subtest "RSA signature generation and verification with `dgst` CLI" => sub { + tsignverify("RSA", + srctop_file("test","testrsa.pem"), + srctop_file("test","testrsapub.pem")); + }; -subtest "DSA signature generation and verification with `dgst` CLI" => sub { - if (disabled("dsa")) { - plan tests => 1; - ok(1, "Skipped (DSA not supported)"); - return; - } - tsignverify("DSA", - srctop_file("test","testdsa.pem"), - srctop_file("test","testdsapub.pem")); -}; + subtest "RSA signature generation and verification with `sha512` CLI" => sub { + tsignverify_sha512("RSA", + srctop_file("test","testrsa2048.pem"), + srctop_file("test","testrsa2048pub.pem")); + }; +} -subtest "ECDSA signature generation and verification with `dgst` CLI" => sub { - if (disabled("ec")) { - plan tests => 1; - ok(1, "Skipped (ECDSA not supported)"); - return; - } - tsignverify("ECDSA", - srctop_file("test","testec-p256.pem"), - srctop_file("test","testecpub-p256.pem")); -}; +SKIP: { + skip "DSA is not supported by this OpenSSL build", 1 + if disabled("dsa"); -subtest "Ed25519 signature generation and verification with `dgst` CLI" => sub { - if (disabled("ecx")) { - plan tests => 1; - ok(1, "Skipped (EdDSA not supported)"); - return; - } - tsignverify("Ed25519", - srctop_file("test","tested25519.pem"), - srctop_file("test","tested25519pub.pem")); -}; + subtest "DSA signature generation and verification with `dgst` CLI" => sub { + tsignverify("DSA", + srctop_file("test","testdsa.pem"), + srctop_file("test","testdsapub.pem")); + }; +} -subtest "Ed448 signature generation and verification with `dgst` CLI" => sub { - if (disabled("ecx")) { - plan tests => 1; - ok(1, "Skipped (EdDSA not supported)"); - return; - } - tsignverify("Ed448", - srctop_file("test","tested448.pem"), - srctop_file("test","tested448pub.pem")); -}; +SKIP: { + skip "ECDSA is not supported by this OpenSSL build", 1 + if disabled("ec"); -subtest "dgst one-shot: no buffer fallback when mmap path fails (Unix)" => sub { - if ($^O eq 'MSWin32' || disabled("ecx")) { - plan tests => 1; - ok(1, "Skipped (Unix/mmap or EdDSA not available)"); - return; - } - plan tests => 2; + subtest "ECDSA signature generation and verification with `dgst` CLI" => sub { + tsignverify("ECDSA", + srctop_file("test","testec-p256.pem"), + srctop_file("test","testecpub-p256.pem")); + }; +} - # Use a directory with non-zero st_size so app_mmap_file() attempts open+mmap - # (curdir "." often has st_size 0 on some FS, which skips mmap and breaks this test). - # mmap() on a directory must fail; we must not fall back to bio_to_mem. - my $key = srctop_file("test", "tested25519.pem"); - my $dir = srctop_dir("test"); - my $stderr_file = "dgst_nofallback_err.txt"; +SKIP: { + skip "EdDSA is not supported by this OpenSSL build", 2 + if disabled("ecx"); - with({ exit_checker => sub { return shift != 0; } }, - sub { - ok(run(app(['openssl', 'dgst', '-sign', $key, $dir], - stderr => $stderr_file)), - "dgst one-shot with un-mmapable file fails (no fallback)"); - }); - if (open(my $fh, '<', $stderr_file)) { - my $err = do { local $/; <$fh> }; - close($fh); - ok($err =~ /Error: failed to use memory-mapped file/, "stderr mentions mmap failure"); - } else { - ok(0, "could not read stderr file"); - } - unlink($stderr_file) if -f $stderr_file; -}; + subtest "Ed25519 signature generation and verification with `dgst` CLI" => sub { + tsignverify("Ed25519", + srctop_file("test","tested25519.pem"), + srctop_file("test","tested25519pub.pem")); + }; -subtest "ML-DSA-44 signature generation and verification with `dgst` CLI" => sub { - if (disabled("ml-dsa")) { - plan tests => 1; - ok(1, "Skipped (ML-DSA not supported)"); - return; - } - tsignverify("Ml-DSA-44", - srctop_file("test","testmldsa44.pem"), - srctop_file("test","testmldsa44pub.pem")); -}; -subtest "ML-DSA-65 signature generation and verification with `dgst` CLI" => sub { - if (disabled("ml-dsa")) { - plan tests => 1; - ok(1, "Skipped (ML-DSA not supported)"); - return; - } - tsignverify("Ml-DSA-65", - srctop_file("test","testmldsa65.pem"), - srctop_file("test","testmldsa65pub.pem")); -}; -subtest "ML-DSA-87 signature generation and verification with `dgst` CLI" => sub { - if (disabled("ml-dsa")) { - plan tests => 1; - ok(1, "Skipped (ML-DSA not supported)"); - return; - } - tsignverify("Ml-DSA-87", - srctop_file("test","testmldsa87.pem"), - srctop_file("test","testmldsa87pub.pem")); -}; + subtest "Ed448 signature generation and verification with `dgst` CLI" => sub { + tsignverify("Ed448", + srctop_file("test","tested448.pem"), + srctop_file("test","tested448pub.pem")); + }; +} -subtest "SHA1 generation by provider with `dgst` CLI" => sub { - if (disabled("module")) { - plan tests => 1; - ok(1, "Skipped (dgst with provider not supported)"); - return; - } - plan tests => 1; +SKIP: { + skip "ML-DSA is not supported by this OpenSSL build", 3 + if disabled("ml-dsa"); - $ENV{OPENSSL_MODULES} = abs_path(bldtop_dir("test")); + subtest "ML-DSA-44 signature generation and verification with `dgst` CLI" => sub { + tsignverify("Ml-DSA-44", + srctop_file("test","testmldsa44.pem"), + srctop_file("test","testmldsa44pub.pem")); + }; + subtest "ML-DSA-65 signature generation and verification with `dgst` CLI" => sub { + tsignverify("Ml-DSA-65", + srctop_file("test","testmldsa65.pem"), + srctop_file("test","testmldsa65pub.pem")); + }; + subtest "ML-DSA-87 signature generation and verification with `dgst` CLI" => sub { + tsignverify("Ml-DSA-87", + srctop_file("test","testmldsa87.pem"), + srctop_file("test","testmldsa87pub.pem")); + }; +} + +SKIP: { + skip "dgst with provider is not supported by this OpenSSL build", 1 + if disabled("module"); + + subtest "SHA1 generation by provider with `dgst` CLI" => sub { + plan tests => 1; + + $ENV{OPENSSL_MODULES} = abs_path(bldtop_dir("test")); my $testdata = srctop_file('test', 'data.bin'); my @macdata = run(app(['openssl', 'dgst', '-sha1', '-provider', "p_ossltest", @@ -235,7 +183,8 @@ subtest "SHA1 generation by provider with `dgst` CLI" => sub { chomp(@macdata); my $expected = qr/SHA1\(\Q$testdata\E\)= 000102030405060708090a0b0c0d0e0f10111213/; ok($macdata[0] =~ $expected, "SHA1: Check HASH value is as expected ($macdata[0]) vs ($expected)"); -}; + } +} subtest "HMAC generation with `dgst` CLI" => sub { plan tests => 2; @@ -408,87 +357,30 @@ subtest "SHAKE digest generation with no xoflen set `dgst` CLI" => sub { ok(!run(app(['openssl', 'dgst', '-shake256', $testdata])), "SHAKE256 must fail without xoflen"); }; -subtest "signing with xoflen is not supported `dgst` CLI" => sub { - if (disabled("ec")) { +SKIP: { + skip "ECDSA is not supported by this OpenSSL build", 2 + if disabled("ec"); + + subtest "signing with xoflen is not supported `dgst` CLI" => sub { plan tests => 1; - ok(1, "Skipped (ECDSA not supported)"); - return; - } - plan tests => 1; - my $data_to_sign = srctop_file('test', 'data.bin'); + my $data_to_sign = srctop_file('test', 'data.bin'); - ok(!run(app(['openssl', 'dgst', '-shake256', '-xoflen', '64', - '-sign', srctop_file("test","testec-p256.pem"), - '-out', 'test.sig', - srctop_file('test', 'data.bin')])), - "Generating signature with xoflen should fail"); -}; + ok(!run(app(['openssl', 'dgst', '-shake256', '-xoflen', '64', + '-sign', srctop_file("test","testec-p256.pem"), + '-out', 'test.sig', + srctop_file('test', 'data.bin')])), + "Generating signature with xoflen should fail"); + }; -subtest "Listing supported digests with `dgst` CLI" => sub { - plan tests => 3; - - my @listdata = run(app(['openssl', 'dgst', '-list']), capture => 1); - chomp(@listdata); - my $listing = join("\n", @listdata); - - ok($listing =~ /Supported digests:/, "LIST: Check header is printed"); - # Only check digests that are always present, each printed as "-" - ok($listing =~ /-sha256\b/, "LIST: Check sha256 is listed"); - ok($listing =~ /-sha512\b/, "LIST: Check sha512 is listed"); -}; - -subtest "signing and verifying with DER `-keyform` `dgst` CLI" => sub { - if (disabled("rsa")) { + subtest "signing using the nonce-type sigopt" => sub { plan tests => 1; - ok(1, "Skipped (RSA not supported)"); - return; + my $data_to_sign = srctop_file('test', 'data.bin'); + + ok(run(app(['openssl', 'dgst', '-sha256', + '-sign', srctop_file("test","testec-p256.pem"), + '-out', 'test.sig', + '-sigopt', 'nonce-type:1', + srctop_file('test', 'data.bin')])), + "Sign using the nonce-type sigopt"); } - plan tests => 4; - - my $data_to_sign = srctop_file('test', 'data.bin'); - my $privkey_pem = srctop_file("test", "testrsa.pem"); - my $pubkey_pem = srctop_file("test", "testrsapub.pem"); - my $privkey_der = "testrsa-keyform.der"; - my $pubkey_der = "testrsapub-keyform.der"; - my $sigfile = "testrsa-keyform.sig"; - - # Convert the keys to DER so the `-keyform DER` code path can be exercised. - ok(run(app(['openssl', 'pkey', '-in', $privkey_pem, - '-outform', 'DER', '-out', $privkey_der])), - "Convert private key to DER"); - ok(run(app(['openssl', 'pkey', '-in', $pubkey_pem, '-pubin', - '-outform', 'DER', '-pubout', '-out', $pubkey_der])), - "Convert public key to DER"); - - ok(run(app(['openssl', 'dgst', '-sign', $privkey_der, '-keyform', 'DER', - '-out', $sigfile, - $data_to_sign])), - "Generating signature with DER private key via -keyform"); - - ok(run(app(['openssl', 'dgst', '-verify', $pubkey_der, '-keyform', 'DER', - '-signature', $sigfile, - $data_to_sign])), - "Verify signature with DER public key via -keyform"); -}; - -subtest "signing using the nonce-type sigopt" => sub { - if (disabled("ec")) { - plan tests => 1; - ok(1, "Skipped (ECDSA not supported)"); - return; - } - if (disabled("hmac-drbg-kdf")) { - plan tests => 1; - ok(1, "Skipped (HMAC-DRBG-KDF not supported)"); - return; - } - plan tests => 1; - my $data_to_sign = srctop_file('test', 'data.bin'); - - ok(run(app(['openssl', 'dgst', '-sha256', - '-sign', srctop_file("test","testec-p256.pem"), - '-out', 'test.sig', - '-sigopt', 'nonce-type:1', - srctop_file('test', 'data.bin')])), - "Sign using the nonce-type sigopt"); -}; +} diff --git a/test/recipes/20-test_kdf.t b/test/recipes/20-test_kdf.t index 8d926d68b3..00f9eeac95 100755 --- a/test/recipes/20-test_kdf.t +++ b/test/recipes/20-test_kdf.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -31,6 +31,18 @@ my @kdf_tests = ( { cmd => [qw{openssl kdf -keylen 25 -digest SHA256 -kdfopt pass:passwordPASSWORDpassword -kdfopt salt:saltSALTsaltSALTsaltSALTsaltSALTsalt -kdfopt iter:4096 PBKDF2}], expected => '34:8C:89:DB:CB:D3:2B:2F:32:D8:14:B8:11:6E:84:CF:2B:17:34:7E:BC:18:00:18:1C', desc => 'PBKDF2 SHA256'}, + { cmd => [qw{openssl kdf -keylen 64 -mac KMAC128 -kdfopt maclen:20 -kdfopt hexkey:b74a149a161546f8c20b06ac4ed4 -kdfopt hexinfo:348a37a27ef1282f5f020dcc -kdfopt hexsalt:3638271ccd68a25dc24ecddd39ef3f89 SSKDF}], + expected => 'e9:c1:84:53:a0:62:b5:3b:db:fc:bb:5a:34:bd:b8:e5:e7:07:ee:bb:5d:d1:34:42:43:d8:cf:c2:c2:e6:33:2f:91:bd:a5:86:f3:7d:e4:8a:65:d4:c5:14:fd:ef:aa:1e:67:54:f3:73:d2:38:e1:95:ae:15:7e:1d:e8:14:98:03', + desc => 'SSKDF KMAC128'}, + { cmd => [qw{openssl kdf -keylen 16 -mac HMAC -digest SHA256 -kdfopt hexkey:b74a149a161546f8c20b06ac4ed4 -kdfopt hexinfo:348a37a27ef1282f5f020dcc -kdfopt hexsalt:3638271ccd68a25dc24ecddd39ef3f89 SSKDF}], + expected => '44:f6:76:e8:5c:1b:1a:8b:bc:3d:31:92:18:63:1c:a3', + desc => 'SSKDF HMAC SHA256'}, + { cmd => [qw{openssl kdf -keylen 14 -digest SHA224 -kdfopt hexkey:6dbdc23f045488e4062757b06b9ebae183fc5a5946d80db93fec6f62ec07e3727f0126aed12ce4b262f47d48d54287f81d474c7c3b1850e9 -kdfopt hexinfo:a1b2c3d4e54341565369643c832e9849dcdba71e9a3139e606e095de3c264a66e98a165854cd07989b1ee0ec3f8dbe SSKDF}], + expected => 'a4:62:de:16:a8:9d:e8:46:6e:f5:46:0b:47:b8', + desc => 'SSKDF HASH SHA224'}, + { cmd => [qw{openssl kdf -keylen 16 -digest SHA256 -kdfopt hexkey:0102030405 -kdfopt hexxcghash:06090A -kdfopt hexsession_id:01020304 -kdfopt type:A SSHKDF}], + expected => '5C:49:94:47:3B:B1:53:3A:58:EB:19:42:04:D3:78:16', + desc => 'SSHKDF SHA256'}, # Using the -kdfopt digest: option instead of -digest { cmd => [qw{openssl kdf -keylen 16 -kdfopt digest:SHA256 -kdfopt secret:secret -kdfopt seed:seed TLS1-PRF}], @@ -45,19 +57,7 @@ my @kdf_tests = ( { cmd => [qw{openssl kdf -keylen 25 -kdfopt digest:SHA256 -kdfopt pass:passwordPASSWORDpassword -kdfopt salt:saltSALTsaltSALTsaltSALTsaltSALTsalt -kdfopt iter:4096 PBKDF2}], expected => '34:8C:89:DB:CB:D3:2B:2F:32:D8:14:B8:11:6E:84:CF:2B:17:34:7E:BC:18:00:18:1C', desc => 'PBKDF2 SHA256'}, -); - -my @sshkdf_tests = ( - { cmd => [qw{openssl kdf -keylen 16 -digest SHA256 -kdfopt hexkey:0102030405 -kdfopt hexxcghash:06090A -kdfopt hexsession_id:01020304 -kdfopt type:A SSHKDF}], - expected => '5C:49:94:47:3B:B1:53:3A:58:EB:19:42:04:D3:78:16', - desc => 'SSHKDF SHA256'}, - { cmd => [qw{openssl kdf -keylen 16 -kdfopt digest:SHA256 -kdfopt hexkey:0102030405 -kdfopt hexxcghash:06090A -kdfopt hexsession_id:01020304 -kdfopt type:A SSHKDF}], - expected => '5C:49:94:47:3B:B1:53:3A:58:EB:19:42:04:D3:78:16', - desc => 'SSHKDF SHA256'}, -); - -my @sskdf_tests = ( - { cmd => [qw{openssl kdf -keylen 64 -mac KMAC128 -kdfopt maclen:20 -kdfopt hexkey:b74a149a161546f8c20b06ac4ed4 -kdfopt hexinfo:348a37a27ef1282f5f020dcc -kdfopt hexsalt:3638271ccd68a25dc24ecddd39ef3f89 SSKDF}], + { cmd => [qw{openssl kdf -keylen 64 -mac KMAC128 -kdfopt maclen:20 -kdfopt hexkey:b74a149a161546f8c20b06ac4ed4 -kdfopt hexinfo:348a37a27ef1282f5f020dcc -kdfopt hexsalt:3638271ccd68a25dc24ecddd39ef3f89 SSKDF}], expected => 'e9:c1:84:53:a0:62:b5:3b:db:fc:bb:5a:34:bd:b8:e5:e7:07:ee:bb:5d:d1:34:42:43:d8:cf:c2:c2:e6:33:2f:91:bd:a5:86:f3:7d:e4:8a:65:d4:c5:14:fd:ef:aa:1e:67:54:f3:73:d2:38:e1:95:ae:15:7e:1d:e8:14:98:03', desc => 'SSKDF KMAC128'}, { cmd => [qw{openssl kdf -keylen 16 -mac HMAC -kdfopt digest:SHA256 -kdfopt hexkey:b74a149a161546f8c20b06ac4ed4 -kdfopt hexinfo:348a37a27ef1282f5f020dcc -kdfopt hexsalt:3638271ccd68a25dc24ecddd39ef3f89 SSKDF}], @@ -66,6 +66,10 @@ my @sskdf_tests = ( { cmd => [qw{openssl kdf -keylen 14 -kdfopt digest:SHA224 -kdfopt hexkey:6dbdc23f045488e4062757b06b9ebae183fc5a5946d80db93fec6f62ec07e3727f0126aed12ce4b262f47d48d54287f81d474c7c3b1850e9 -kdfopt hexinfo:a1b2c3d4e54341565369643c832e9849dcdba71e9a3139e606e095de3c264a66e98a165854cd07989b1ee0ec3f8dbe SSKDF}], expected => 'a4:62:de:16:a8:9d:e8:46:6e:f5:46:0b:47:b8', desc => 'SSKDF HASH SHA224'}, + { cmd => [qw{openssl kdf -keylen 16 -kdfopt digest:SHA256 -kdfopt hexkey:0102030405 -kdfopt hexxcghash:06090A -kdfopt hexsession_id:01020304 -kdfopt type:A SSHKDF}], + expected => '5C:49:94:47:3B:B1:53:3A:58:EB:19:42:04:D3:78:16', + desc => 'SSHKDF SHA256'}, + # Additionally using -kdfopt mac: instead of -mac { cmd => [qw{openssl kdf -keylen 64 -kdfopt mac:KMAC128 -kdfopt maclen:20 -kdfopt hexkey:b74a149a161546f8c20b06ac4ed4 -kdfopt hexinfo:348a37a27ef1282f5f020dcc -kdfopt hexsalt:3638271ccd68a25dc24ecddd39ef3f89 SSKDF}], expected => 'e9:c1:84:53:a0:62:b5:3b:db:fc:bb:5a:34:bd:b8:e5:e7:07:ee:bb:5d:d1:34:42:43:d8:cf:c2:c2:e6:33:2f:91:bd:a5:86:f3:7d:e4:8a:65:d4:c5:14:fd:ef:aa:1e:67:54:f3:73:d2:38:e1:95:ae:15:7e:1d:e8:14:98:03', @@ -75,29 +79,13 @@ my @sskdf_tests = ( desc => 'SSKDF HMAC SHA256'}, ); -my @krb5kdf_tests = ( - { cmd => [qw{openssl kdf -keylen 16 -cipher AES-128-CBC -kdfopt hexkey:42263C6E89F4FC28B8DF68EE09799F15 -kdfopt hexconstant:0000000299 KRB5KDF}], - expected => '34:28:0A:38:2B:C9:27:69:B2:DA:2F:9E:F0:66:85:4B', - desc => 'KRB5KDF AES-128-CBC'}, - { cmd => [qw{openssl kdf -keylen 32 -cipher AES-256-CBC -kdfopt hexkey:FE697B52BC0D3CE14432BA036A92E65BBB52280990A2FA27883998D72AF30161 -kdfopt hexconstant:0000000299 KRB5KDF}], - expected => 'BF:AB:38:8B:DC:B2:38:E9:F9:C9:8D:6A:87:83:04:F0:4D:30:C8:25:56:37:5A:C5:07:A7:A8:52:79:0F:46:74', - desc => 'KRB5KDF AES-256-CBC'}, - # Using the -kdfopt cipher: option instead of -cipher - { cmd => [qw{openssl kdf -keylen 16 -kdfopt cipher:AES-128-CBC -kdfopt hexkey:42263C6E89F4FC28B8DF68EE09799F15 -kdfopt hexconstant:0000000299 KRB5KDF}], - expected => '34:28:0A:38:2B:C9:27:69:B2:DA:2F:9E:F0:66:85:4B', - desc => 'KRB5KDF AES-128-CBC'}, -); - my @scrypt_tests = ( { cmd => [qw{openssl kdf -keylen 64 -kdfopt pass:password -kdfopt salt:NaCl -kdfopt n:1024 -kdfopt r:8 -kdfopt p:16 -kdfopt maxmem_bytes:10485760 id-scrypt}], expected => 'fd:ba:be:1c:9d:34:72:00:78:56:e7:19:0d:01:e9:fe:7c:6a:d7:cb:c8:23:78:30:e7:73:76:63:4b:37:31:62:2e:af:30:d9:2e:22:a3:88:6f:f1:09:27:9d:98:30:da:c7:27:af:b9:4a:83:ee:6d:83:60:cb:df:a2:cc:06:40', desc => 'SCRYPT' }, ); -push @kdf_tests, @krb5kdf_tests unless disabled("krb5kdf"); push @kdf_tests, @scrypt_tests unless disabled("scrypt"); -push @kdf_tests, @sshkdf_tests unless disabled("sshkdf"); -push @kdf_tests, @sskdf_tests unless disabled("sskdf"); plan tests => scalar @kdf_tests; diff --git a/test/recipes/20-test_mac.t b/test/recipes/20-test_mac.t index 84a8899049..35a4904188 100644 --- a/test/recipes/20-test_mac.t +++ b/test/recipes/20-test_mac.t @@ -10,7 +10,7 @@ use strict; use warnings; -use OpenSSL::Test qw(:DEFAULT data_file srctop_file); +use OpenSSL::Test qw(:DEFAULT data_file); use OpenSSL::Test::Utils; use Storable qw(dclone); @@ -138,9 +138,8 @@ my @siphash_fail_tests = ( push @mac_fail_tests, @siphash_fail_tests unless disabled("siphash"); -plan tests => (scalar @mac_tests * 2) + (scalar @mac_fail_tests) + 2; +plan tests => (scalar @mac_tests * 2) + scalar @mac_fail_tests; -my $no_fips = disabled('fips') || ($ENV{NO_FIPS} // 0); my $test_count = 0; foreach (@mac_tests) { @@ -175,28 +174,6 @@ foreach (@mac_fail_tests) { ok(compareline($_->{cmd}, $_->{type}, $_->{input}, $_->{expected}, $_->{err}), $_->{desc}); } -SKIP: { - skip "Skipping FIPS tests", 2 - if $no_fips; - - my $fipsconf = srctop_file("test", "fips-and-base.cnf"); - - # This is only valid after OpenSSL 4.1 - run(test(["fips_version_test", "-config", $fipsconf, ">=4.1.0"]), - capture => 1, statusvar => \my $exit); - skip "FIPS provider version is too old for this test", 2 - if !$exit; - - $ENV{OPENSSL_CONF} = $fipsconf; - ok(!run(app(['openssl', 'dgst', '-provider', 'fips', '-sha256', '-hmac', - '1234', srctop_file("test", "testec-p112r1.pem")])), - "Checking bad key size fails in FIPS provider"); - ok(run(app(['openssl', 'dgst', '-provider', 'fips', '-sha256', '-hmac', - '123456789ABCDE', srctop_file("test", "testec-p112r1.pem")])), - "Checking good key size passes in FIPS provider"); - delete $ENV{OPENSSL_CONF}; -} - # Create a temp input file and save the input data into it, and # then compare the stdout output matches the expected value. sub compareline { diff --git a/test/recipes/20-test_pkeyutl.t b/test/recipes/20-test_pkeyutl.t index dec9b4b183..31e46c6d99 100644 --- a/test/recipes/20-test_pkeyutl.t +++ b/test/recipes/20-test_pkeyutl.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2018-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -11,19 +11,19 @@ use warnings; use File::Spec; use File::Basename; -use OpenSSL::Test qw/:DEFAULT srctop_file srctop_dir ok_nofips with/; +use OpenSSL::Test qw/:DEFAULT srctop_file ok_nofips with/; use OpenSSL::Test::Utils; use File::Compare qw/compare_text compare/; setup("test_pkeyutl"); -plan tests => 33; +plan tests => 27; # For the tests below we use the cert itself as the TBS file SKIP: { skip "Skipping tests that require EC, SM2 or SM3", 4 - if disabled("ec") || disabled("sm2") || disabled("sm3") || disabled("x963kdf"); + if disabled("ec") || disabled("sm2") || disabled("sm3"); # SM2 ok_nofips(run(app(([ 'openssl', 'pkeyutl', '-sign', @@ -187,42 +187,6 @@ SKIP: { "-pkeyopt", "rsa_padding_mode:pss"); }; - subtest "pkeyutl -rev reverses the input buffer" => sub { - plan tests => 4; - - my $key = srctop_file("test", "testrsa.pem"); - my $in = "rev_in.bin"; - my $in_rev = "rev_in_reversed.bin"; - - # A non-palindromic input, short enough to be signed as a raw digest. - my $data = "0123456789abcdefghijklmnopqrstuv"; - open(my $fh, '>:raw', $in) or die "cannot create $in: $!"; - print $fh $data; - close($fh); - open($fh, '>:raw', $in_rev) or die "cannot create $in_rev: $!"; - print $fh scalar reverse $data; - close($fh); - - # RSA signing is deterministic, so signing with -rev must match signing - # the manually reversed input. - ok(run(app(['openssl', 'pkeyutl', '-sign', '-inkey', $key, - '-rev', '-in', $in, '-out', 'rev.sig'])), - "Sign with -rev"); - ok(run(app(['openssl', 'pkeyutl', '-sign', '-inkey', $key, - '-in', $in_rev, '-out', 'rev_manual.sig'])), - "Sign the manually reversed input"); - is(compare('rev.sig', 'rev_manual.sig'), 0, - "-rev signature matches signing the reversed input"); - - # -rev is rejected together with raw input. - with({ exit_checker => sub { return shift == 1; } }, - sub { - ok(run(app(['openssl', 'pkeyutl', '-sign', '-inkey', $key, - '-rawin', '-digest', 'sha256', '-rev', '-in', $in])), - "-rev cannot be used with -rawin"); - }); - }; - } SKIP: { @@ -250,101 +214,10 @@ SKIP: { } SKIP: { - skip "EdDSA is not supported by this OpenSSL build", 7 + skip "EdDSA is not supported by this OpenSSL build", 4 if disabled("ecx"); - subtest "pkeyutl -rawin oneshot with file input (mmap or buffer path)" => sub { - my $data = srctop_file("test", "data.bin"); - my $ed25519_key = srctop_file("test", "tested25519.pem"); - my $ed25519_pub = srctop_file("test", "tested25519pub.pem"); - my $ed448_key = srctop_file("test", "tested448.pem"); - my $ed448_pub = srctop_file("test", "tested448pub.pem"); - - plan tests => 4; - - # -in for oneshot: uses mmap on Unix when supported, else buffer+BIO_read - ok(run(app(['openssl', 'pkeyutl', '-sign', '-rawin', '-inkey', $ed25519_key, - '-in', $data, '-out', 'rawin_file_ed25519.sig'])), - "Ed25519 -rawin sign from file"); - ok(run(app(['openssl', 'pkeyutl', '-verify', '-rawin', '-pubin', '-inkey', $ed25519_pub, - '-sigfile', 'rawin_file_ed25519.sig', '-in', $data])), - "Ed25519 -rawin verify from file"); - ok(run(app(['openssl', 'pkeyutl', '-sign', '-rawin', '-inkey', $ed448_key, - '-in', $data, '-out', 'rawin_file_ed448.sig'])), - "Ed448 -rawin sign from file"); - ok(run(app(['openssl', 'pkeyutl', '-verify', '-rawin', '-pubin', '-inkey', $ed448_pub, - '-sigfile', 'rawin_file_ed448.sig', '-in', $data])), - "Ed448 -rawin verify from file"); - }; - - subtest "pkeyutl -rawin oneshot: no buffer fallback when mmap path fails (Unix)" => sub { - if ($^O eq 'MSWin32') { - plan tests => 1; - ok(1, "Skipped (Unix/mmap only)"); - return; - } - plan tests => 2; - - # Use a directory with non-zero st_size so the mmap path is attempted - # (curdir "." often has st_size 0 on some FS and skips mmap). - my $ed25519_key = srctop_file("test", "tested25519.pem"); - my $dir = srctop_dir("test"); - my $stderr_file = "pkeyutl_nofallback_err.txt"; - - with({ exit_checker => sub { return shift != 0; } }, - sub { - ok(run(app(['openssl', 'pkeyutl', '-sign', '-rawin', '-inkey', $ed25519_key, - '-in', $dir, '-out', 'nofallback.sig'], - stderr => $stderr_file)), - "pkeyutl -rawin with un-mmapable input fails (no fallback)"); - }); - if (open(my $fh, '<', $stderr_file)) { - my $err = do { local $/; <$fh> }; - close($fh); - ok($err =~ /Error(?: opening file for memory mapping|: failed to use memory-mapped file)/, - "stderr mentions mmap failure"); - } else { - ok(0, "could not read stderr file"); - } - unlink($stderr_file) if -f $stderr_file; - }; - - subtest "pkeyutl -rawin oneshot with empty file (buffer path, filesize 0)" => sub { - my $ed25519_key = srctop_file("test", "tested25519.pem"); - my $ed25519_pub = srctop_file("test", "tested25519pub.pem"); - my $empty = "pkeyutl_empty.bin"; - my $sigfile = "rawin_empty_ed25519.sig"; - # Ed25519 is deterministic, so signing the empty message with - # tested25519.pem always yields this exact signature. - my $expected_sig = - "42a443bd375c962f571dbf7402654219655b30c395dee06e" . - "d2a4a41342686da620889e374807266a3aab535345985c96" . - "cbb7475c8b0df47968d29fbf3d352e0c"; - - plan tests => 3; - - # create a zero-length input file - open(my $fh, '>', $empty) or die "cannot create $empty: $!"; - close($fh); - - ok(run(app(['openssl', 'pkeyutl', '-sign', '-rawin', '-inkey', $ed25519_key, - '-in', $empty, '-out', $sigfile])), - "Ed25519 -rawin sign from empty file (filesize 0 buffer path)"); - ok(run(app(['openssl', 'pkeyutl', '-verify', '-rawin', '-pubin', '-inkey', $ed25519_pub, - '-sigfile', $sigfile, '-in', $empty])), - "Ed25519 -rawin verify from empty file"); - - # check the produced signature matches the known reference value - open(my $sfh, '<:raw', $sigfile) or die "cannot open $sigfile: $!"; - read($sfh, my $sig, -s $sigfile); - close($sfh); - is(unpack("H*", $sig), $expected_sig, - "Ed25519 -rawin empty file signature matches the reference value"); - - unlink($empty); - }; - - subtest "Ed25519 CLI signature generation and verification" => sub { + subtest "Ed2559 CLI signature generation and verification" => sub { tsignverify("Ed25519", srctop_file("test","tested25519.pem"), srctop_file("test","tested25519pub.pem"), @@ -358,7 +231,7 @@ SKIP: { "-rawin"); }; - subtest "Ed25519 CLI signature generation and verification, no -rawin" => sub { + subtest "Ed2559 CLI signature generation and verification, no -rawin" => sub { tsignverify("Ed25519", srctop_file("test","tested25519.pem"), srctop_file("test","tested25519pub.pem")); @@ -407,86 +280,3 @@ SKIP: { is(compare(srctop_file('test', 'encap_secret.bin'), "decap_out_etl.bin"), 0, "Secret is correctly decapsulated - pregenerated"); } - -subtest "pkeyutl -pkeyopt_passin" => sub { - plan tests => 5; - - my @common = ('openssl', 'pkeyutl', '-kdf', 'TLS1-PRF', '-kdflen', '16', - '-pkeyopt', 'md:SHA256', - '-pkeyopt', 'seed:someseed'); - - ok(run(app([@common, '-pkeyopt', 'secret:somesecret', - '-out', 'tls1prf_plain.bin'])), - "Derive with -pkeyopt secret"); - - ok(run(app([@common, '-pkeyopt_passin', 'secret:pass:somesecret', - '-out', 'tls1prf_passin.bin'])), - "Derive with -pkeyopt_passin secret"); - - is(compare('tls1prf_plain.bin', 'tls1prf_passin.bin'), 0, - "pkeyopt_passin secret matches plain pkeyopt secret"); - - # app_passwd failure: passphrase source cannot be read - with({ exit_checker => sub { return shift == 1; } }, - sub { - ok(run(app([@common, '-pkeyopt_passin', - 'secret:file:no_such_passfile'])), - "Fail when the passphrase source cannot be read"); - }); - - # EVP_PKEY_CTX_ctrl_str failure: unknown control name - with({ exit_checker => sub { return shift == 1; } }, - sub { - ok(run(app([@common, '-pkeyopt_passin', 'bogus:pass:whatever'])), - "Fail on unknown pkey option via passin"); - }); -}; - -SKIP: { - skip "EC is not supported by this OpenSSL build", 1 - if disabled("ec"); - - subtest "pkeyutl -derive peer key setup" => sub { - my $eckey = srctop_file("test", "testec-p256.pem"); - my $ecpub = srctop_file("test", "testecpub-p256.pem"); - my $rsapub = srctop_file("test", "testrsapub.pem"); - - plan tests => 5; - - # ECDH derive against a matching peer public key - ok(run(app(['openssl', 'pkeyutl', '-derive', - '-inkey', $eckey, '-peerkey', $ecpub, - '-out', 'derive_secret.bin'])), - "Derive shared secret with matching peer key"); - - # setup_peer: peer key file cannot be loaded - with({ exit_checker => sub { return shift == 1; } }, - sub { - ok(run(app(['openssl', 'pkeyutl', '-derive', - '-inkey', $eckey, '-peerkey', 'no_such_peer.pem'])), - "Fail when the peer key cannot be read"); - }); - - # setup_peer: peer key type does not match the private key type - with({ exit_checker => sub { return shift == 1; } }, - sub { - ok(run(app(['openssl', 'pkeyutl', '-derive', - '-inkey', $eckey, '-peerkey', $rsapub])), - "Fail when peer key type does not match private key"); - }); - - # main: -derive requires -peerkey - with({ exit_checker => sub { return shift == 1; } }, - sub { - ok(run(app(['openssl', 'pkeyutl', '-derive', '-inkey', $eckey])), - "Fail when -derive is given without -peerkey"); - }); - - # main: -peerkey is only valid with -derive - with({ exit_checker => sub { return shift == 1; } }, - sub { - ok(run(app(['openssl', 'pkeyutl', '-inkey', $eckey, '-peerkey', $ecpub])), - "Fail when -peerkey is given without -derive"); - }); - }; -} diff --git a/test/recipes/20-test_rand_config.t b/test/recipes/20-test_rand_config.t index 1db541ffe0..5919eef56d 100644 --- a/test/recipes/20-test_rand_config.t +++ b/test/recipes/20-test_rand_config.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2019-2020 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -10,7 +10,7 @@ use strict; use warnings; -use OpenSSL::Test qw/:DEFAULT result_dir/; +use OpenSSL::Test; use OpenSSL::Test::Utils; setup("test_rand_config"); @@ -57,7 +57,7 @@ my @aria_tests = ( push @rand_tests, @aria_tests unless disabled("aria"); -plan tests => scalar @rand_tests * 2; +plan tests => scalar @rand_tests; my $contents =<<'CONFIGEND'; openssl_conf = openssl_init @@ -86,9 +86,6 @@ foreach (@rand_tests) { $ENV{OPENSSL_CONF} = $tmpfile; ok(comparelines($_->{expected}), $_->{desc}); - # Also check that instantiating the drbg works - my $result_dir = result_dir(); - ok(run(app(["openssl", "rand", "-writerand", "$result_dir/$tmpfile.bin"]))); } # Check that the stdout output contains the expected values. diff --git a/test/recipes/20-test_skeyutl.t b/test/recipes/20-test_skeyutl.t deleted file mode 100644 index 1c69935cac..0000000000 --- a/test/recipes/20-test_skeyutl.t +++ /dev/null @@ -1,99 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use warnings; - -use OpenSSL::Test qw/:DEFAULT bldtop_dir with/; -use OpenSSL::Test::Utils; - -setup("test_skeyutl"); - -# The success path needs the loadable fake-cipher provider, which is only built -# when module support is enabled. -my $fake_cipher = !disabled('module'); - -plan tests => 14 + ($fake_cipher ? 2 : 0); - -# Helper: run skeyutl expecting a non-zero (failure) exit code, and optionally -# check that stderr matches a regular expression. -sub skeyutl_fails { - my ($testtext, $re, @args) = @_; - - my $stderr_file = "skeyutl_err.txt"; - my $err = ''; - - with({ exit_checker => sub { return shift != 0; } }, - sub { - ok(run(app(['openssl', 'skeyutl', @args], stderr => $stderr_file)), - $testtext); - }); - - if (defined $re) { - if (open(my $fh, '<', $stderr_file)) { - $err = do { local $/; <$fh> }; - close($fh); - } - ok($err =~ $re, "$testtext: stderr matches"); - } - unlink($stderr_file) if -f $stderr_file; -} - -# -help exits successfully -ok(run(app(['openssl', 'skeyutl', '-help'])), - "skeyutl -help succeeds"); - -# Neither -cipher nor -skeymgmt is given -skeyutl_fails("skeyutl without -cipher or -skeymgmt fails", - qr/Either -skeymgmt -or -cipher option should be specified/); - -# -genkey but neither -cipher nor -skeymgmt is given: same early check -skeyutl_fails("skeyutl -genkey without -cipher or -skeymgmt fails", - qr/Either -skeymgmt -or -cipher option should be specified/, - '-genkey'); - -# A cipher is given but -genkey is not: generation is the only operation -skeyutl_fails("skeyutl without -genkey reports unsupported operation", - qr/Key generation is the only supported operation/, - '-cipher', 'AES-128-CBC'); - -# -genkey with a valid skey management name: reaches the generation path -# (no built-in provider supports opaque key generation yet) -skeyutl_fails("skeyutl -genkey with valid -skeymgmt reaches generation", - qr/Error creating opaque key for skeymgmt AES/, - '-genkey', '-skeymgmt', 'AES'); - -# -genkey with an unknown skey management name: fetch fails -skeyutl_fails("skeyutl -genkey with unknown -skeymgmt fails", - undef, - '-genkey', '-skeymgmt', 'NoSuchSkeyMgmt'); - -# An unknown cipher name is rejected by option parsing -skeyutl_fails("skeyutl with an unknown cipher fails", - qr/Unknown option or cipher/, - '-genkey', '-cipher', 'NoSuchCipher'); - -# An unknown option is rejected -skeyutl_fails("skeyutl with an unknown option fails", - qr/Unknown option/, - '-not-an-option'); - -# Success path: load the fake-cipher provider, which implements opaque key -# generation, and generate a key with it. -if ($fake_cipher) { - $ENV{OPENSSL_MODULES} = bldtop_dir("test"); - my @prov = ('-provider-path', bldtop_dir("test"), '-provider', 'fake-cipher'); - - my $status; - my @out = run(app(['openssl', 'skeyutl', @prov, - '-genkey', '-skeymgmt', 'fake_cipher']), - capture => 1, statusvar => \$status); - ok($status, "skeyutl -genkey with fake-cipher provider succeeds"); - ok(grep(/opaque key/, @out), - "skeyutl -genkey reports the generated opaque key"); -} diff --git a/test/recipes/20-test_speed.t b/test/recipes/20-test_speed.t index c6a982460f..3c3c5fab5f 100644 --- a/test/recipes/20-test_speed.t +++ b/test/recipes/20-test_speed.t @@ -118,7 +118,7 @@ ok(run(app(['openssl', 'speed', '-help'])), #Now test some invalid options. The speed app should fail ok(!run(app(['openssl', 'speed', 'blah'])), - "Test an unknown algorithm"); + "Test an unknwon algorithm"); ok(!run(app(['openssl', 'speed', '-evp', 'blah'])), "Test a unknown evp algorithm"); diff --git a/test/recipes/25-test_configutl.t b/test/recipes/25-test_configutl.t index 880758b35a..a97a78eecd 100644 --- a/test/recipes/25-test_configutl.t +++ b/test/recipes/25-test_configutl.t @@ -35,13 +35,13 @@ foreach my $file (@tests) { "-noheader", "-out", "$file.got"]))); if ($file eq "includes.cnf") { - my $cmp1 = cmp_text("$file.got", srctop_file("test", "recipes", "25-test_configutl_data", "$file-exp1.out")); - my $cmp2 = cmp_text("$file.got", srctop_file("test", "recipes", "25-test_configutl_data", "$file-exp2.out")); + my $cmp1 = cmp_text("$file.got", srctop_file("test", "recipes", "25-test_configutl_data", "$file.expected1")); + my $cmp2 = cmp_text("$file.got", srctop_file("test", "recipes", "25-test_configutl_data", "$file.expected2")); - is((($cmp1 == 0) || ($cmp2 == 0)), 1, "$file got/expected 1/2"); + is((($cmp1 == 0) || ($cmp2 == 0)), 1, "$file got/expected 1/2"); } else { is(cmp_text("$file.got", - srctop_file("test", "recipes", "25-test_configutl_data", "$file-exp.out")), + srctop_file("test", "recipes", "25-test_configutl_data", "$file.expected")), 0, "$file got/expected"); } diff --git a/test/recipes/25-test_configutl_data/escapes.cnf-exp.out b/test/recipes/25-test_configutl_data/escapes.cnf.expected similarity index 100% rename from test/recipes/25-test_configutl_data/escapes.cnf-exp.out rename to test/recipes/25-test_configutl_data/escapes.cnf.expected diff --git a/test/recipes/25-test_configutl_data/includes.cnf b/test/recipes/25-test_configutl_data/includes.cnf index 6c87aead5b..4e08e80cf0 100644 --- a/test/recipes/25-test_configutl_data/includes.cnf +++ b/test/recipes/25-test_configutl_data/includes.cnf @@ -2,5 +2,5 @@ openssl_conf = openssl_init .include = ./includes.1.d .include ./includes.2.d -.include ./nonexistent.d +.include ./nonexistant.d .include ./included-file.noncnf diff --git a/test/recipes/25-test_configutl_data/includes.cnf-exp1.out b/test/recipes/25-test_configutl_data/includes.cnf.expected1 similarity index 100% rename from test/recipes/25-test_configutl_data/includes.cnf-exp1.out rename to test/recipes/25-test_configutl_data/includes.cnf.expected1 diff --git a/test/recipes/25-test_configutl_data/includes.cnf-exp2.out b/test/recipes/25-test_configutl_data/includes.cnf.expected2 similarity index 100% rename from test/recipes/25-test_configutl_data/includes.cnf-exp2.out rename to test/recipes/25-test_configutl_data/includes.cnf.expected2 diff --git a/test/recipes/25-test_configutl_data/leading-and-trailing-whitespace.cnf-exp.out b/test/recipes/25-test_configutl_data/leading-and-trailing-whitespace.cnf.expected similarity index 100% rename from test/recipes/25-test_configutl_data/leading-and-trailing-whitespace.cnf-exp.out rename to test/recipes/25-test_configutl_data/leading-and-trailing-whitespace.cnf.expected diff --git a/test/recipes/25-test_configutl_data/order.cnf-exp.out b/test/recipes/25-test_configutl_data/order.cnf.expected similarity index 100% rename from test/recipes/25-test_configutl_data/order.cnf-exp.out rename to test/recipes/25-test_configutl_data/order.cnf.expected diff --git a/test/recipes/25-test_configutl_data/variables.cnf-exp.out b/test/recipes/25-test_configutl_data/variables.cnf.expected similarity index 100% rename from test/recipes/25-test_configutl_data/variables.cnf-exp.out rename to test/recipes/25-test_configutl_data/variables.cnf.expected diff --git a/test/recipes/25-test_crl.t b/test/recipes/25-test_crl.t index a65b2c6ce8..92101e8d94 100644 --- a/test/recipes/25-test_crl.t +++ b/test/recipes/25-test_crl.t @@ -11,12 +11,11 @@ use strict; use warnings; use File::Spec; -use File::Copy; use OpenSSL::Test qw/:DEFAULT srctop_file/; setup("test_crl"); -plan tests => 12; +plan tests => 10; require_ok(srctop_file('test','recipes','tconversion.pl')); @@ -52,106 +51,6 @@ ok(run(app(["openssl", "crl", "-text", "-in", $pem, "-inform", "PEM", is(cmp_text($out, srctop_file("test/certs", "cyrillic_crl.utf8")), 0, 'Comparing utf8 output'); -# Verify a CRL's signature against its issuer certificate, supplied via -# -CAfile, -CAstore and -CApath. -subtest 'crl signature verification' => sub { - plan tests => 4; - - my $crl = srctop_file("test/certs", "delta-crl-as-complete-delta.pem"); - my $cacert = srctop_file("test/certs", "delta-crl-as-complete-ca.pem"); - - ok(run(app(["openssl", "crl", "-noout", "-in", $crl, - "-CAfile", $cacert])), - "verify CRL signature with -CAfile"); - - ok(run(app(["openssl", "crl", "-noout", "-in", $crl, - "-CAstore", $cacert])), - "verify CRL signature with -CAstore"); - - # -CApath needs a rehashed directory, which relies on the rehash command - # (not available on platforms without symlink support, e.g. Windows). - SKIP: { - skip "rehash is not available on this platform", 2 - unless run(app(["openssl", "rehash", "-help"])); - - my $capath = "crl_capath"; - mkdir $capath; - copy($cacert, File::Spec->catfile($capath, "ca.pem")); - ok(run(app(["openssl", "rehash", $capath])), - "rehash the -CApath directory"); - ok(run(app(["openssl", "crl", "-noout", "-in", $crl, - "-CApath", $capath])), - "verify CRL signature with -CApath"); - } -}; - -# Cover -gendelta (delta CRL generation), which is the only code path in the -# crl app using the -key and -keyform options. -subtest 'crl delta generation with -gendelta, -key and -keyform' => sub { - plan tests => 5; - - # copy the CA cert and key in locally so the config uses plain paths - my $cacert = "gendelta-ca-cert.pem"; - my $cakey = "gendelta-ca-key.pem"; - copy(srctop_file("test", "certs", "ca-cert.pem"), $cacert); - copy(srctop_file("test", "certs", "ca-key.pem"), $cakey); - - open my $cfg, '>', "gencrl.cnf" or die "Could not create gencrl.cnf: $!"; - print $cfg <<"EOF"; -[ca] -default_ca = CA_default -[CA_default] -database = index.txt -certificate = $cacert -private_key = $cakey -crlnumber = crlnumber -default_md = sha256 -default_crl_days = 30 -EOF - close $cfg; - open my $db, '>', "index.txt" or die "Could not create index.txt: $!"; - close $db; # empty CA database - open my $num, '>', "crlnumber" or die "Could not create crlnumber: $!"; - print $num "1000\n"; - close $num; - - run(app(["openssl", "ca", "-gencrl", "-config", "gencrl.cnf", - "-out", "delta-base.crl"])); - run(app(["openssl", "ca", "-gencrl", "-config", "gencrl.cnf", - "-out", "delta-newer.crl"])); - - # -gendelta with a PEM signing key (the default -keyform) - ok(run(app(["openssl", "crl", "-in", "delta-base.crl", - "-gendelta", "delta-newer.crl", - "-key", $cakey, "-out", "delta.crl"])), - "generate delta CRL with -gendelta and a PEM -key"); - - run(app(["openssl", "crl", "-in", "delta.crl", "-noout", "-text", - "-out", "delta.txt"])); - test_file_contains("delta CRL", "delta.txt", "Delta CRL Indicator", 1); - - # The same, loading the signing key from DER via -keyform DER - run(app(["openssl", "pkey", "-in", $cakey, "-outform", "DER", - "-out", "ca-key.der"])); - ok(run(app(["openssl", "crl", "-in", "delta-base.crl", - "-gendelta", "delta-newer.crl", - "-key", "ca-key.der", "-keyform", "DER", - "-out", "delta-der.crl"])), - "generate delta CRL with a DER -key and -keyform DER"); - - # -keyform must match the key encoding: a DER key read as PEM fails. - ok(!run(app(["openssl", "crl", "-in", "delta-base.crl", - "-gendelta", "delta-newer.crl", - "-key", "ca-key.der", "-keyform", "PEM", - "-out", "delta-bad.crl"])), - "wrong -keyform for the signing key makes -gendelta fail"); - - # -gendelta requires a signing key. - ok(!run(app(["openssl", "crl", "-in", "delta-base.crl", - "-gendelta", "delta-newer.crl", "-out", "delta-nokey.crl"])), - "-gendelta without -key fails"); -}; - sub compare1stline { my ($cmdarray, $str) = @_; my @lines = run(app($cmdarray), capture => 1); diff --git a/test/recipes/25-test_pkcs7.t b/test/recipes/25-test_pkcs7.t index 3801c4b106..23f1c8a764 100644 --- a/test/recipes/25-test_pkcs7.t +++ b/test/recipes/25-test_pkcs7.t @@ -15,7 +15,7 @@ use OpenSSL::Test qw/:DEFAULT srctop_file data_file/; setup("test_pkcs7"); -plan tests => 10; +plan tests => 7; require_ok(srctop_file('test','recipes','tconversion.pl')); @@ -43,16 +43,3 @@ is(cmp_text($out, data_file('grfc.out')), my $malformed = data_file('malformed.pkcs7'); ok(run(app(["openssl", "pkcs7", "-in", $malformed]))); - -# Test that -print_certs prints CRLs contained in a PKCS#7 structure -my $crlp7 = "testcrl.p7"; -ok(run(app(["openssl", "crl2pkcs7", - "-in", srctop_file("test", "testcrl.pem"), - "-out", $crlp7])), - "create a PKCS#7 structure containing a CRL"); -my @crlout = run(app(["openssl", "pkcs7", "-print_certs", "-in", $crlp7]), - capture => 1); -ok(grep(/Certificate Revocation List \(CRL\):/, @crlout) == 1, - "print_certs shows the CRL contents"); -ok(grep(/-----BEGIN X509 CRL-----/, @crlout) == 1, - "print_certs outputs the CRL in PEM form"); diff --git a/test/recipes/25-test_pkcs8.t b/test/recipes/25-test_pkcs8.t index bd7224459b..50cb01a407 100644 --- a/test/recipes/25-test_pkcs8.t +++ b/test/recipes/25-test_pkcs8.t @@ -16,7 +16,7 @@ use OpenSSL::Test qw/:DEFAULT srctop_file ok_nofips is_nofips/; setup("test_pkcs8"); -plan tests => 19; +plan tests => 18; my $pc5_key = srctop_file('test', 'certs', 'pc5-key.pem'); @@ -128,38 +128,6 @@ ok(run(app(([ 'openssl', 'asn1parse', "Check the size of the PBKDF2 PARAM 'salt length' is 8"); -subtest 'PKCS#8 DER inform/outform round trip' => sub { - plan tests => 6; - - # PEM -> DER, unencrypted PKCS#8 (exercises -outform DER) - ok(run(app(['openssl', 'pkcs8', '-topk8', '-nocrypt', - '-in', $pc5_key, '-outform', 'DER', - '-out', 'p8-nocrypt.der'])), - "write unencrypted PKCS#8 in DER form"); - # DER -> PEM (exercises -inform DER) - ok(run(app(['openssl', 'pkcs8', '-nocrypt', - '-inform', 'DER', '-in', 'p8-nocrypt.der', - '-out', 'p8-roundtrip.pem'])), - "read unencrypted PKCS#8 from DER form"); - # PEM -> DER again, the result must match the original DER output - ok(run(app(['openssl', 'pkcs8', '-topk8', '-nocrypt', - '-in', 'p8-roundtrip.pem', '-outform', 'DER', - '-out', 'p8-roundtrip.der'])), - "re-encode the round-tripped key to DER"); - is(compare('p8-nocrypt.der', 'p8-roundtrip.der'), 0, - "DER output is identical after a PEM/DER round trip"); - - # The same for an encrypted PKCS#8 structure - ok(run(app(['openssl', 'pkcs8', '-topk8', - '-in', $pc5_key, '-outform', 'DER', - '-out', 'p8-enc.der', '-passout', 'pass:password'])), - "write encrypted PKCS#8 in DER form"); - ok(run(app(['openssl', 'pkcs8', - '-inform', 'DER', '-in', 'p8-enc.der', - '-out', 'p8-dec.pem', '-passin', 'pass:password'])), - "read encrypted PKCS#8 from DER form"); -}; - SKIP: { skip "SM2, SM3 or SM4 is not supported by this OpenSSL build", 3 if disabled("sm2") || disabled("sm3") || disabled("sm4"); diff --git a/test/recipes/25-test_req.t b/test/recipes/25-test_req.t index a37686736f..7dfbe02778 100644 --- a/test/recipes/25-test_req.t +++ b/test/recipes/25-test_req.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -15,7 +15,7 @@ use OpenSSL::Test qw/:DEFAULT srctop_file/; setup("test_req"); -plan tests => 131; +plan tests => 116; require_ok(srctop_file('test', 'recipes', 'tconversion.pl')); @@ -330,25 +330,27 @@ subtest "generating SM2 certificate requests" => sub { ok(run(app(["openssl", "req", "-config", srctop_file("test", "test.cnf"), "-new", "-key", srctop_file(@certs, "sm2.key"), - "-out", "testreq-sm2.pem"])), + "-sigopt", "distid:1234567812345678", + "-out", "testreq-sm2.pem", "-sm3"])), "Generating SM2 certificate request"); ok(run(app(["openssl", "req", "-config", srctop_file("test", "test.cnf"), - "-verify", "-in", "testreq-sm2.pem", "-noout"])), + "-verify", "-in", "testreq-sm2.pem", "-noout", + "-vfyopt", "distid:1234567812345678", "-sm3"])), "Verifying signature on SM2 certificate request"); ok(run(app(["openssl", "req", "-config", srctop_file("test", "test.cnf"), "-new", "-key", srctop_file(@certs, "sm2.key"), "-sigopt", "hexdistid:DEADBEEF", - "-out", "testreq-sm2.pem"])), + "-out", "testreq-sm2.pem", "-sm3"])), "Generating SM2 certificate request with hex id"); ok(run(app(["openssl", "req", "-config", srctop_file("test", "test.cnf"), "-verify", "-in", "testreq-sm2.pem", "-noout", - "-vfyopt", "hexdistid:DEADBEEF"])), + "-vfyopt", "hexdistid:DEADBEEF", "-sm3"])), "Verifying signature on SM2 certificate request"); } }; @@ -501,55 +503,6 @@ subtest "generating certificate requests with SLH-DSA" => sub { } }; -subtest "generating certificate with -set_serial" => sub { - plan tests => 3; - - my $cert = "self-signed_set_serial.pem"; - ok(run(app(["openssl", "req", "-x509", "-new", "-days", "365", - "-config", srctop_file("test", "test.cnf"), - "-key", srctop_file("test", "testrsa.pem"), - "-set_serial", "12345", - "-out", $cert])), - "Generating self-signed cert with -set_serial"); - - cert_contains($cert, "Serial Number: 12345", 1); - - ok(!run(app(["openssl", "req", "-x509", "-new", "-days", "365", - "-config", srctop_file("test", "test.cnf"), - "-key", srctop_file("test", "testrsa.pem"), - "-set_serial", "12345", "-set_serial", "67890", - "-out", $cert])), - "Supplying -set_serial twice fails"); -}; - -subtest "generating certificate requests with -pkeyopt" => sub { - plan tests => 3; - - SKIP: { - skip "EC is not supported by this OpenSSL build", 3 if disabled("ec"); - - my $key = "testreq-pkeyopt-key.pem"; - my $req = "testreq-pkeyopt.pem"; - my $text = "testreq-pkeyopt.txt"; - - ok(run(app(["openssl", "req", "-new", - "-config", srctop_file("test", "test.cnf"), - "-newkey", "ec", "-pkeyopt", "ec_paramgen_curve:P-384", - "-nodes", "-keyout", $key, "-out", $req])), - "Generating request with -pkeyopt ec_paramgen_curve:P-384"); - - run(app(["openssl", "req", "-in", $req, "-noout", "-text", - "-out", $text])); - test_file_contains("request", $text, "ASN1 OID: secp384r1", 1); - - ok(!run(app(["openssl", "req", "-new", - "-config", srctop_file("test", "test.cnf"), - "-newkey", "ec", "-pkeyopt", "bogus_opt:1", - "-nodes", "-keyout", $key, "-out", $req])), - "Supplying an unknown -pkeyopt fails"); - } -}; - my @openssl_args = ("req", "-config", srctop_file("apps", "openssl.cnf")); run_conversion('req conversions', @@ -591,8 +544,8 @@ sub generate_cert { my $cn = $is_ca ? "CA" : "EE"; my $ca_key = srctop_file(@certs, "ca-key.pem"); my $key = $is_ca ? $ca_key : srctop_file(@certs, "ee-key.pem"); - my @cmd = ("openssl", "req", "-config", srctop_file("test", "ca-and-certs.cnf"), - "-x509", "-subj", "/CN=$cn", @_, "-out", $cert); + my @cmd = ("openssl", "req", "-config", "", "-x509", + "-subj", "/CN=$cn", @_, "-out", $cert); push(@cmd, ("-key", $key)) if $ss; push(@cmd, ("-CA", $ca_cert, "-CAkey", $ca_key)) unless $ss; ok(run(app([@cmd])), "generate $cert"); @@ -603,23 +556,14 @@ sub has_keyUsage { my $expect = shift @_; cert_contains($cert, "Key Usage", $expect); } -sub verify { - my $strict = shift @_; +sub strict_verify { my $cert = shift @_; my $expect = shift @_; my $trusted = shift @_; $trusted = $cert unless $trusted; - my @cmd = ("openssl", "verify"); - push(@cmd, "-x509_strict") if $strict; - ok(run(app([@cmd, "-trusted", $trusted, + ok(run(app(["openssl", "verify", "-x509_strict", "-trusted", $trusted, "-partial_chain", $cert])) == $expect, - ($strict ? "strict " : "")." verify ". - ($expect ? "accept" : "reject")." $cert"); -} - -sub strict_verify { - unshift @_, 1; - return verify(@_); + "strict verify allow $cert"); } my @v3_ca = ("-addext", "basicConstraints = critical,CA:true", @@ -628,23 +572,18 @@ my $SKID_AKID = "subjectKeyIdentifier,authorityKeyIdentifier"; # # SKID -my $cert = "self-signed_default_SKID_minimal_exts.pem"; +my $cert = "self-signed_default_SKID_no_explicit_exts.pem"; generate_cert($cert); has_version($cert, 3); -has_SKID($cert, 1); +has_SKID($cert, 1); # SKID added, though no explicit extensions given has_AKID($cert, 0); -$cert = "self-signed_v3_CA_hash_SKID.pem"; +my $cert = "self-signed_v3_CA_hash_SKID.pem"; generate_cert($cert, @v3_ca, "-addext", "subjectKeyIdentifier = hash"); -has_version($cert, 3); has_SKID($cert, 1); # explicit hash SKID $cert = "self-signed_v3_CA_no_SKID.pem"; -generate_cert($cert, @v3_ca, - # Add SKID - "-extensions", "v3_skid", - # And explicitly drop it - "-addext", "subjectKeyIdentifier = none"); +generate_cert($cert, @v3_ca, "-addext", "subjectKeyIdentifier = none"); cert_ext_has_n_different_lines($cert, 0, $SKID_AKID); # no SKID and no AKID #TODO strict_verify($cert, 0); @@ -663,22 +602,17 @@ cert_ext_has_n_different_lines($cert, 0, $SKID_AKID); # no SKID and no AKID $ca_cert = "self-signed_v3_CA_default_SKID.pem"; # will also be used below generate_cert($ca_cert, @v3_ca); -has_version($ca_cert, 3); has_SKID($ca_cert, 1); # default SKID has_AKID($ca_cert, 0); # no default AKID strict_verify($ca_cert, 1); $cert = "self-signed_v3_CA_no_AKID.pem"; -generate_cert($cert, @v3_ca, - # Add AKID - "-extensions", "v3_akid", - # Explicitly drop it - "-addext", "authorityKeyIdentifier = none"); +generate_cert($cert, @v3_ca, "-addext", "authorityKeyIdentifier = none"); has_AKID($cert, 0); # forced no AKID $cert = "self-signed_v3_CA_explicit_AKID.pem"; -generate_cert($cert, @v3_ca, "-addext", "authorityKeyIdentifier = keyid:nonss"); -has_AKID($cert, 0); # for self-signed cert, AKID suppressed since self-signed +generate_cert($cert, @v3_ca, "-addext", "authorityKeyIdentifier = keyid"); +has_AKID($cert, 0); # for self-signed cert, AKID suppressed and not forced $cert = "self-signed_v3_CA_forced_AKID.pem"; generate_cert($cert, @v3_ca, "-addext", "authorityKeyIdentifier = keyid:always"); @@ -686,23 +620,23 @@ cert_ext_has_n_different_lines($cert, 3, $SKID_AKID); # forced AKID, AKID == SKI strict_verify($cert, 1); $cert = "self-signed_v3_CA_issuer_AKID.pem"; -generate_cert($cert, @v3_ca, "-addext", "authorityKeyIdentifier = issuer:nonss"); -has_AKID($cert, 0); # suppressed AKID since self-signed +generate_cert($cert, @v3_ca, "-addext", "authorityKeyIdentifier = issuer"); +has_AKID($cert, 0); # suppressed AKID since not forced $cert = "self-signed_v3_CA_forced_issuer_AKID.pem"; generate_cert($cert, @v3_ca, "-addext", "authorityKeyIdentifier = issuer:always"); cert_contains($cert, "Authority Key Identifier: DirName:/CN=CA serial:", 1); # forced issuer AKID $cert = "self-signed_v3_CA_nonforced_keyid_issuer_AKID.pem"; -generate_cert($cert, @v3_ca, "-addext", "authorityKeyIdentifier = keyid:nonss, issuer:nonss"); +generate_cert($cert, @v3_ca, "-addext", "authorityKeyIdentifier = keyid, issuer"); has_AKID($cert, 0); # AKID not present because not forced and cert self-signed $cert = "self-signed_v3_CA_keyid_forced_issuer_AKID.pem"; -generate_cert($cert, @v3_ca, "-addext", "authorityKeyIdentifier = keyid:nonss, issuer:always"); +generate_cert($cert, @v3_ca, "-addext", "authorityKeyIdentifier = keyid, issuer:always"); cert_contains($cert, "Authority Key Identifier: DirName:/CN=CA serial:", 1); # issuer AKID forced, with keyid not forced $cert = "self-signed_v3_CA_forced_keyid_issuer_AKID.pem"; -generate_cert($cert, @v3_ca, "-addext", "authorityKeyIdentifier = keyid:always, issuer:nonss"); +generate_cert($cert, @v3_ca, "-addext", "authorityKeyIdentifier = keyid:always, issuer"); has_AKID($cert, 1); # AKID with keyid forced cert_contains($cert, "Authority Key Identifier: DirName:/CN=CA serial:", 0); # no issuer AKID @@ -734,23 +668,10 @@ cert_ext_has_n_different_lines($cert, 4, $SKID_AKID); # SKID != AKID strict_verify($cert, 1); $cert = "self-issued_v3_CA_no_AKID.pem"; -generate_cert($cert, - # Add SKID and AKID - "-extensions", "v3_askid", - # Explicitly drop the AKID - "-addext", "authorityKeyIdentifier = none", - "-in", srctop_file(@certs, "x509-check.csr")); +generate_cert($cert, "-addext", "authorityKeyIdentifier = none", + "-in", srctop_file(@certs, "x509-check.csr")); has_version($cert, 3); -has_SKID($cert, 1); -has_AKID($cert, 0); -strict_verify($cert, 1); - -$cert = "self-issued_v3_CA_no_KIDs.pem"; -generate_cert($cert, "-addext", "subjectKeyIdentifier = none", - "-addext", "authorityKeyIdentifier = none", - "-in", srctop_file(@certs, "x509-check.csr")); -has_version($cert, 3); -has_SKID($cert, 0); +has_SKID($cert, 1); # SKID added, though no explicit extensions given has_AKID($cert, 0); strict_verify($cert, 1); @@ -790,7 +711,7 @@ generate_cert($cert, "-addext", "authorityKeyIdentifier = keyid:always, issuer:a "-in", srctop_file(@certs, "x509-check.csr")); cert_ext_has_n_different_lines($cert, 6, $SKID_AKID); # SKID != AKID, both forced -# AKID of not self-issued end-entity certs +# AKID of not self-issued certs $cert = "regular_v3_EE_default_KIDs_no_other_exts.pem"; generate_cert($cert, "-key", srctop_file(@certs, "ee-key.pem")); @@ -816,21 +737,6 @@ has_SKID($cert, 1); has_AKID($cert, 0); strict_verify($cert, 0, $ca_cert); -# weird self-issued end-entity cert without SKID/AKID signed by CA, as in #19095 -$cert = "self-issued_v3_EE_no_KIDs_signed_by_CA.pem"; -generate_cert($cert, "-addext", "subjectKeyIdentifier = none", - "-addext", "authorityKeyIdentifier = none", - "-key", srctop_file(@certs, "ee-key.pem")); -has_version($cert, 3); -cert_ext_has_n_different_lines($cert, 0, $SKID_AKID); # no SKID and no AKID -verify(0, $cert, 0, $ca_cert); # expecting failure because we won't fix #19095 - -# variant self-issued end-entity cert with only AKID signed by CA, which conforms to RFC 5280 -$cert = "self-issued_v3_EE_only_AKID_signed_by_CA.pem"; -generate_cert($cert, "-addext", "subjectKeyIdentifier = none", - "-key", srctop_file(@certs, "ee-key.pem")); -verify(0, $cert, 0, $ca_cert); # expecting failure because we won't fix #19095 - # Key Usage @@ -862,7 +768,7 @@ ok(run(app(["openssl", "x509", "-in", "testreq-cert.pem", # Generate cert with explicit start and end dates my %today = (strftime("%Y-%m-%d", gmtime) => 1); -$cert = "self-signed_explicit_date.pem"; +my $cert = "self-signed_explicit_date.pem"; ok(run(app(["openssl", "req", "-x509", "-new", "-text", "-config", srctop_file('test', 'test.cnf'), "-key", srctop_file("test", "testrsa.pem"), diff --git a/test/recipes/25-test_statem_clnt.t b/test/recipes/25-test_statem_clnt.t deleted file mode 100644 index 4352029eed..0000000000 --- a/test/recipes/25-test_statem_clnt.t +++ /dev/null @@ -1,19 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use OpenSSL::Test; -use OpenSSL::Test::Utils; - -setup("test_statem_clnt"); - -plan skip_all => "No TLS protocol enabled in this build" - if disabled("tls1_2") && disabled("tls1_3"); - -plan tests => 1; - -ok(run(test(["statem_clnt_construct_test"])), "statem_clnt construct functions"); diff --git a/test/recipes/25-test_verify.t b/test/recipes/25-test_verify.t index 6efe24087a..a95e47f552 100644 --- a/test/recipes/25-test_verify.t +++ b/test/recipes/25-test_verify.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -30,7 +30,7 @@ sub verify { run(app([@args])); } -plan tests => 221; +plan tests => 212; # Canonical success ok(verify("ee-cert", "sslserver", ["root-cert"], ["ca-cert"]), @@ -362,17 +362,6 @@ SKIP: { ok(verify("ee-cert-ec-sha3-512", "", ["root-cert"], ["ca-cert-ec-named"], ), "accept cert generated with EC and SHA3-512"); } - -# DSA chains using id-dsa-with-sha384 / id-dsa-with-sha512 (GitHub issue #30432) -SKIP: { - skip "DSA is not supported by this OpenSSL build", 2 - if disabled("dsa"); - - ok(verify("ee-cert-dsa-sha384", "", ["root-cert-dsa-sha384"], [], ), - "accept DSA cert chain with SHA-384 signatures"); - ok(verify("ee-cert-dsa-sha512", "", ["root-cert-dsa-sha512"], [], ), - "accept DSA cert chain with SHA-512 signatures"); -} # Same as above but with base provider used for decoding SKIP: { my $no_fips = disabled('fips') || ($ENV{NO_FIPS} // 0); @@ -484,10 +473,6 @@ ok(!verify("bad-othername-cert", "", ["root-cert"], ["nccaothername-cert"], ), ok(verify("nc-uri-cert", "", ["root-cert"], ["ncca4-cert"], ), "Name constraints URI with userinfo"); -ok(!verify("bad-cert-smtputf8-name-constraints", "root-cert", ["bad-cert-smtputf8-name-constraints"], [], - "-partial_chain", "-attime", "1623060000"), - "Name constraints bad othername name constraint"); - #Check that we get the expected failure return code with({ exit_checker => sub { return shift == 2; } }, sub { @@ -627,49 +612,6 @@ ok(verify("ee-expired2", "", ["root-cert"], ["ca-cert"], "-attime", ok(!verify("ee-expired2", "", ["root-cert"], ["ca-cert"], "-attime", "2073566278"), "Certificate invalid at time 2073566278"); -# CVE-2026-28388 -my $cve_28388_stderr = "cve-2026-28388.err"; -run(app(["openssl", "verify", - "-attime", "1739527200", - "-CAfile", srctop_file(@certspath, "cve-2026-28388-ca.pem"), - "-crl_check", "-use_deltas", - "-CRLfile", srctop_file(@certspath, "cve-2026-28388-crls.pem"), - srctop_file(@certspath, "cve-2026-28388-leaf.pem")], - stderr => $cve_28388_stderr)); -ok(grep(/CRL is not yet valid/, do { open my $fh, '<', $cve_28388_stderr; <$fh> }), - "CVE-2026-28388"); - -# Delta CRLs must not be accepted as complete CRLs -my $delta_crl_as_complete_stderr = "delta-crl-as-complete.err"; -ok(!run(app(["openssl", "verify", "-auth_level", "1", - "-CAfile", - srctop_file(@certspath, "delta-crl-as-complete-ca.pem"), - "-no_check_time", "-crl_check", - "-CRLfile", - srctop_file(@certspath, "delta-crl-as-complete-delta.pem"), - srctop_file(@certspath, "delta-crl-as-complete-leaf.pem")], - stderr => $delta_crl_as_complete_stderr)) - && grep(/unable to get certificate CRL/, - do { open my $fh, '<', $delta_crl_as_complete_stderr; <$fh> }), - "Delta CRL is not accepted as complete CRL"); - -my $delta_crl_as_complete_reasons_stderr = - "delta-crl-as-complete-reasons.err"; -ok(!run(app(["openssl", "verify", "-auth_level", "1", - "-CAfile", - srctop_file(@certspath, "delta-crl-as-complete-ca.pem"), - "-no_check_time", "-crl_check", "-extended_crl", - "-CRLfile", - srctop_file(@certspath, - "delta-crl-as-complete-delta-reasons.pem"), - srctop_file(@certspath, "delta-crl-as-complete-leaf.pem")], - stderr => $delta_crl_as_complete_reasons_stderr)) - && grep(/unable to get certificate CRL/, - do { - open my $fh, '<', $delta_crl_as_complete_reasons_stderr; - <$fh> - }), - "Delta CRL with onlySomeReasons is not accepted as complete CRL"); # CAstore option my $rootcertname = "root-cert"; @@ -689,26 +631,17 @@ SKIP: { ok(vfy_root("-CAstore", "file:".$foo_file), "CAstore file:foo:cert.pem"); } -my $rel_cert = "cert.pem"; -copy($rootcert, $rel_cert); -ok(vfy_root("-CAstore", $rel_cert), "CAstore cert"); -ok(vfy_root("-CAstore", "file:".$rel_cert), "CAstore file:cert"); -my $abs_cert = abs_path($rootcert); -SKIP: { - skip "drive letter with relative filename on Windows only", 2 - unless $^O =~ /^MsWin32$/; - my $drive_rel_cert = substr($abs_cert, 0, 2).$rel_cert; - ok(vfy_root("-CAstore", $drive_rel_cert), "CAstore D:cert"); - ok(vfy_root("-CAstore", "file:".$drive_rel_cert), "CAstore file:D:cert"); -} +my $file = "cert.pem"; +copy($rootcert, $file); +ok(vfy_root("-CAstore", $file), "CAstore cert.pem"); +ok(vfy_root("-CAstore", "file:".$file), "CAstore file:cert.pem"); +my $abs_cert = abs_path($rootcert); # Windows file: URIs should have a path part starting with a slash, i.e. -# file://authority/C:/what/ever/foo.pem and file:///C:/what/ever/foo.pem. -# So file://C:/what/ever/foo.pem is non-standard and may not be accepted. +# file://authority/C:/what/ever/foo.pem and file:///C:/what/ever/foo.pem +# file://C:/what/ever/foo.pem is non-standard and may not be accepted. # See RFC 8089 for details. $abs_cert = "/" . $abs_cert if ($^O eq "MSWin32"); - ok(vfy_root("-CAstore", "file://".$abs_cert), "CAstore file:///path"); -ok(vfy_root("-CAstore", "file:".$abs_cert), "CAstore file:/path"); # we allow dropping the "//" before an empty authority part ok(vfy_root("-CAstore", "file://localhost".$abs_cert), "CAstore file://localhost/path"); ok(!vfy_root("-CAstore", "file://otherhost".$abs_cert), "CAstore file://otherhost/path"); diff --git a/test/recipes/25-test_verify_store.t b/test/recipes/25-test_verify_store.t index bfac17c7f4..6338b862b5 100644 --- a/test/recipes/25-test_verify_store.t +++ b/test/recipes/25-test_verify_store.t @@ -72,11 +72,9 @@ SKIP: { -CAstore => $CAcert, $CAcert ); - # Put a pubkey and DH params to the store to test - # that other things in the store are just ignored open(my $out, '>', $CAobjects) or die $!; - my @pubkey = run(app([qw(openssl x509 -pubkey -noout -in), $CAcert]), capture => 1); - print $out @pubkey; + my $pubkey = qx(openssl x509 -pubkey -noout -in $CAcert); + print $out $pubkey; my @files; push @files, srctop_file("test", "certs", "dhp2048.pem") unless disabled("dh"); diff --git a/test/recipes/25-test_x509.t b/test/recipes/25-test_x509.t index 736d185de4..665ea164c6 100644 --- a/test/recipes/25-test_x509.t +++ b/test/recipes/25-test_x509.t @@ -17,7 +17,7 @@ use File::Compare qw/compare_text/; setup("test_x509"); -plan tests => 153; +plan tests => 150; # Prevent MSys2 filename munging for arguments that look like file paths but # aren't @@ -414,12 +414,6 @@ cert_contains($time_spec_per_cert, "Years: 2023, 2024", 1, 'X.509 Time Specification (Periodic)'); -my $time_spec_per_no_second_cert = - srctop_file(@certs, "ext-timeSpecification-periodic-no-second.pem"); -cert_contains($time_spec_per_no_second_cert, - "05:43:00 - 12:34:56", - 1, 'X.509 Time Specification (Periodic, no second)'); - my $attr_map_cert = srctop_file(@certs, "ext-attributeMappings.pem"); cert_contains($attr_map_cert, "commonName == localityName", @@ -569,61 +563,6 @@ has_version($b_cert, 3); has_SKID($b_cert, 1); has_AKID($b_cert, 1); -subtest "signing with -sigopt and verifying a CSR with -vfyopt" => sub { - plan tests => 6; - - # -sigopt is passed to the signature algorithm; force RSA-PSS padding - # and check it ends up in the issued certificate. - my $pss_cert = "sigopt-pss.pem"; - ok(run(app(["openssl", "x509", "-req", "-CAcreateserial", - "-CA", $ca_cert, "-CAkey", $ca_key, - "-sigopt", "rsa_padding_mode:pss", - "-in", $b_csr, "-out", $pss_cert])), - "sign cert from CSR with -sigopt rsa_padding_mode:pss"); - cert_contains($pss_cert, "Signature Algorithm: rsassaPss", 1, - "issued cert is signed with PSS as selected via -sigopt"); - - # An unknown -sigopt must abort signing. - ok(!run(app(["openssl", "x509", "-req", "-CAcreateserial", - "-CA", $ca_cert, "-CAkey", $ca_key, - "-sigopt", "bogus:1", - "-in", $b_csr, "-out", "sigopt-bogus.pem"])), - "an unknown -sigopt makes signing fail"); - - # An unknown -vfyopt must abort CSR verification. - ok(!run(app(["openssl", "x509", "-req", "-CAcreateserial", - "-CA", $ca_cert, "-CAkey", $ca_key, - "-vfyopt", "bogus:1", - "-in", $b_csr, "-out", "vfyopt-bogus.pem"])), - "an unknown -vfyopt makes CSR verification fail"); - - SKIP: { - skip "SM2 is not supported by this OpenSSL build", 2 if disabled("sm2"); - - # -vfyopt is used to verify the CSR self-signature. Sign an SM2 CSR - # with a non-default distinguishing id so that the id must be supplied - # via -vfyopt for verification to succeed. - my $sm2_key = "sm2-vfyopt-key.pem"; - my $sm2_csr = "sm2-vfyopt.csr"; - my $distid = "0102030405060708"; - run(app(["openssl", "req", "-new", "-newkey", "sm2", - "-keyout", $sm2_key, "-out", $sm2_csr, "-nodes", - "-config", $cnf, "-subj", "/CN=SM2", - "-sigopt", "distid:$distid"])); - - ok(run(app(["openssl", "x509", "-req", "-CAcreateserial", - "-CA", $ca_cert, "-CAkey", $ca_key, - "-vfyopt", "distid:$distid", - "-in", $sm2_csr, "-out", "sm2-vfyopt.pem"])), - "SM2 CSR verifies when its distid is given via -vfyopt"); - - ok(!run(app(["openssl", "x509", "-req", "-CAcreateserial", - "-CA", $ca_cert, "-CAkey", $ca_key, - "-in", $sm2_csr, "-out", "sm2-novfyopt.pem"])), - "SM2 CSR fails to verify without the matching -vfyopt distid"); - } -}; - # Tests for https://github.com/openssl/openssl/issues/10442 (fixed in 1.1.1a) # (incorrect default `-CAcreateserial` if `-CA` path has a dot in it) my $folder_with_dot = "test_x509.folder"; @@ -731,9 +670,8 @@ ok(!run(app(["openssl", "x509", "-checkend", $delta_early + 3600, # Single + expiring at boundary # Test may fail erroneously due to sequential now() calls # See https://github.com/openssl/openssl/pull/29155 -# Certificate should be valid at exact NotAfter time. my $delta_exact = Time::Piece->strptime( get_field($c_early, "Not After "), - "%b %d %T %Y %Z")->epoch - Time::Piece->gmtime->epoch + 1; + "%b %d %T %Y %Z")->epoch - Time::Piece->gmtime->epoch; ok(!run(app(["openssl", "x509", "-checkend", $delta_exact, "-in", $c_early])), "Single cert + expiring at -checkend boundary"); # Multi + none expiring @@ -764,42 +702,3 @@ ok(!run(app(["openssl", "x509", "-multi", "-checkend", # Bad parse still returns non-zero ok(!run(app(["openssl", "x509", "-checkend", "60", "-in", $c_key])), "Bad parse with -checkend returns non-zero"); - -# Signing using DER-encoded key and CA cert/key inputs, -# exercising -keyform, -CAform and -CAkeyform -subtest 'x509 signing with DER -keyform, -CAform and -CAkeyform' => sub { - plan tests => 6; - - my $csr = srctop_file(@certs, "x509-check.csr"); - my $signkey_der = "x509-check-key.der"; - my $cacert_der = "ca-cert.der"; - my $cakey_der = "ca-key.der"; - - # self-sign the CSR with a DER-encoded signing key - ok(run(app(["openssl", "pkey", - "-in", srctop_file(@certs, "x509-check-key.pem"), - "-outform", "DER", "-out", $signkey_der])), - "convert signing key to DER"); - ok(run(app(["openssl", "x509", "-req", "-in", $csr, - "-signkey", $signkey_der, "-keyform", "DER", - "-out", "x509-self-der.pem"])), - "self-sign CSR with -keyform DER"); - - # sign the CSR with a DER-encoded CA cert and CA key - ok(run(app(["openssl", "x509", - "-in", srctop_file(@certs, "ca-cert.pem"), - "-outform", "DER", "-out", $cacert_der])), - "convert CA cert to DER"); - ok(run(app(["openssl", "pkey", - "-in", srctop_file(@certs, "ca-key.pem"), - "-outform", "DER", "-out", $cakey_der])), - "convert CA key to DER"); - my $caout = "ca-issued-der.pem"; - ok(run(app(["openssl", "x509", "-req", "-in", $csr, - "-CA", $cacert_der, "-CAform", "DER", - "-CAkey", $cakey_der, "-CAkeyform", "DER", - "-CAcreateserial", "-text", "-out", $caout])), - "sign CSR with -CAform DER and -CAkeyform DER"); - ok(get_issuer($caout) =~ /CN=CA/, - "issuer of CA-signed cert matches DER CA cert"); -}; diff --git a/test/recipes/30-test_ech.t b/test/recipes/30-test_ech.t deleted file mode 100644 index 9c0114a790..0000000000 --- a/test/recipes/30-test_ech.t +++ /dev/null @@ -1,21 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. -# Copyright (c) 2022, Oracle and/or its affiliates. All rights reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use OpenSSL::Test::Utils; -use OpenSSL::Test qw/:DEFAULT srctop_file srctop_dir bldtop_dir bldtop_file/; - -setup("test_ech"); - -plan skip_all => "ECH tests not supported in this build" - if disabled("ech") || disabled("tls1_3") || disabled("ec") || disabled("ecx"); - -plan tests => 1; - -ok(run(test(["ech_test", srctop_dir("test", "certs")]))) diff --git a/test/recipes/30-test_ech_corrupt.t b/test/recipes/30-test_ech_corrupt.t deleted file mode 100644 index aed5fbab6e..0000000000 --- a/test/recipes/30-test_ech_corrupt.t +++ /dev/null @@ -1,25 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. -# Copyright (c) 2022, Oracle and/or its affiliates. All rights reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use OpenSSL::Test::Utils; -use OpenSSL::Test qw/:DEFAULT srctop_file srctop_dir bldtop_dir bldtop_file/; - -setup("test_ech_corrupt"); - -# Seeing tls1_2 below may be unexpected but we include a test case -# where the inner CH is TLSv1.2 and the outer is TLSv1.3, but we -# don't get the expected error in builds where TLSv1.2 is not supported -# so we'll skip those -plan skip_all => "ECH tests not supported in this build" - if disabled("ech") || disabled("tls1_2") || disabled("tls1_3") || disabled("ec") || disabled("ecx"); - -plan tests => 1; - -ok(run(test(["ech_corrupt_test", srctop_dir("test", "certs")]))) diff --git a/test/recipes/30-test_evp.t b/test/recipes/30-test_evp.t index d94c76fe79..98af32086d 100644 --- a/test/recipes/30-test_evp.t +++ b/test/recipes/30-test_evp.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -29,22 +29,12 @@ my $no_dsa = disabled("dsa"); my $no_ec = disabled("ec"); my $no_ecx = disabled("ecx"); my $no_ec2m = disabled("ec2m"); -my $no_sm2 = disabled("sm2") || disabled("x963kdf"); +my $no_sm2 = disabled("sm2"); my $no_siv = disabled("siv"); my $no_argon2 = disabled("argon2"); my $no_ml_dsa = disabled("ml-dsa"); my $no_ml_kem = disabled("ml-kem"); my $no_lms = disabled("lms"); -my $no_sskdf = disabled("sskdf"); -my $no_x942kdf = disabled("x942kdf"); -my $no_x963kdf = disabled("x963kdf"); -my $no_determinstic_nonce = disabled("hmac-drbg-kdf"); -my $no_ikev2kdf = disabled("ikev2kdf"); -my $no_kbkdf = disabled("kbkdf"); -my $no_krb5kdf = disabled("krb5kdf"); -my $no_snmpkdf = disabled("snmpkdf"); -my $no_srtpkdf = disabled("srtpkdf"); -my $no_sshkdf = disabled("sshkdf"); # Default config depends on if the legacy module is built or not my $defaultcnf = $no_legacy ? 'default.cnf' : 'default-and-legacy.cnf'; @@ -62,10 +52,17 @@ my @files = qw( evpciph_aes_stitched.txt evpciph_des3_common.txt evpkdf_hkdf.txt + evpkdf_kbkdf_counter.txt + evpkdf_kbkdf_kmac.txt evpkdf_pbkdf1.txt evpkdf_pbkdf2.txt + evpkdf_snmp.txt + evpkdf_ss.txt + evpkdf_ssh.txt evpkdf_tls12_prf.txt evpkdf_tls13_kdf.txt + evpkdf_x942.txt + evpkdf_x963.txt evpmac_common.txt evpmd_sha.txt evppbe_pbkdf2.txt @@ -76,24 +73,14 @@ my @files = qw( evppkey_rsa_sigalg.txt evprand.txt ); -push @files, qw(evpkdf_ikev2.txt) unless $no_ikev2kdf; -push @files, qw(evpkdf_ssh.txt) unless $no_sshkdf; -push @files, qw(evpkdf_snmp.txt) unless $no_snmpkdf; -push @files, qw(evpkdf_srtp.txt) unless $no_srtpkdf; -push @files, qw( - evpkdf_kbkdf_counter.txt - evpkdf_kbkdf_kmac.txt - ) unless $no_kbkdf; -push @files, qw(evpkdf_ss.txt) unless $no_sskdf; -push @files, qw(evpkdf_x942.txt) unless $no_x942kdf; -push @files, qw(evpkdf_x963.txt) unless $no_x963kdf; push @files, qw( evppkey_ffdhe.txt evppkey_dh.txt ) unless $no_dh; -push @files, qw(evppkey_ffdhe_x942kdf.txt) unless ($no_x942kdf || $no_dh); -push @files, qw(evpmac_cmac_des.txt) unless $no_des; -push @files, qw(evpkdf_x942_des.txt) unless ($no_des || $no_x942kdf); +push @files, qw( + evpkdf_x942_des.txt + evpmac_cmac_des.txt + ) unless $no_des; push @files, qw( evppkey_slh_dsa_siggen.txt evppkey_slh_dsa_sigver.txt @@ -144,7 +131,7 @@ push @files, qw( ) unless $no_lms; push @files, qw( evppkey_ecdsa_rfc6979.txt - ) unless ($no_ec || $no_determinstic_nonce); + ) unless $no_ec; # A list of tests that only run with the default provider # (i.e. The algorithms are not present in the fips provider) @@ -165,8 +152,10 @@ my @defltfiles = qw( evpciph_seed.txt evpciph_sm4.txt evpencod.txt + evpkdf_krb5.txt evpkdf_scrypt.txt evpkdf_tls11_prf.txt + evpkdf_hmac_drbg.txt evpmac_blake.txt evpmac_poly1305.txt evpmac_siphash.txt @@ -182,15 +171,13 @@ my @defltfiles = qw( evppkey_kdf_scrypt.txt evppkey_kdf_tls1_prf.txt ); -push @defltfiles, qw(evpkdf_krb5.txt) unless $no_krb5kdf; push @defltfiles, qw(evppkey_brainpool.txt) unless $no_ec; push @defltfiles, qw(evppkey_ecx_kem.txt) unless $no_ecx; -push @defltfiles, qw(evppkey_dsa_rfc6979.txt) unless ($no_dsa || $no_determinstic_nonce); +push @defltfiles, qw(evppkey_dsa_rfc6979.txt) unless $no_dsa; push @defltfiles, qw(evppkey_sm2.txt) unless $no_sm2; push @defltfiles, qw(evpciph_aes_gcm_siv.txt) unless $no_siv; push @defltfiles, qw(evpciph_aes_siv.txt) unless $no_siv; push @defltfiles, qw(evpkdf_argon2.txt) unless $no_argon2; -push @defltfiles, qw(evpkdf_hmac_drbg.txt) unless $no_determinstic_nonce; plan tests => + (scalar(@configs) * scalar(@files)) diff --git a/test/recipes/30-test_evp_data/evpkdf_ikev2.txt b/test/recipes/30-test_evp_data/evpkdf_ikev2.txt deleted file mode 100644 index 6d0333ad87..0000000000 --- a/test/recipes/30-test_evp_data/evpkdf_ikev2.txt +++ /dev/null @@ -1,340 +0,0 @@ -# -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -# Tests start with one of these keywords -# digest, ni, nr, secret, new secret, spi_init, spi_resp, mode -# and continue until a blank line. Lines starting with a pound sign are ignored. -# https://github.com/usnistgov/ACVP-Server/tree/master/gen-val/json-files/kdf-components-ikev2-1.0 - -Title = IKEV2KDF tests - -# self_test_data.c - GEN -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -Ctrl.hexsecret = hexsecret:D084A30166A50FB7325C3960874A839449EF9741C2F4F947D0201DD8C1269273D79509F37E3CA3EB4FA2FE2A28254E289CD3F34DAD4EB4DF1A07685A4B8A94FA61E2491F7598B3CE65547FF133B3F63D1AC4175EAA695033F3CEDB026A6873A36455172A8540B8A5D23A0143BED0390EE49B168269D75FFFEE9FB62BE965993C -Ctrl.mode = mode:0 -Output = EFAA7AB0EAA85A3D0BE2100CD4B6FE00FF5025A9EAFDDB3EF518E9F0D3FE60E6 - -# test case, GEN missing mode, mode is default as 0 -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -Ctrl.hexsecret = hexsecret:D084A30166A50FB7325C3960874A839449EF9741C2F4F947D0201DD8C1269273D79509F37E3CA3EB4FA2FE2A28254E289CD3F34DAD4EB4DF1A07685A4B8A94FA61E2491F7598B3CE65547FF133B3F63D1AC4175EAA695033F3CEDB026A6873A36455172A8540B8A5D23A0143BED0390EE49B168269D75FFFEE9FB62BE965993C -#Ctrl.mode = mode:0 -Output = EFAA7AB0EAA85A3D0BE2100CD4B6FE00FF5025A9EAFDDB3EF518E9F0D3FE60E6 - -# self_test_data.c - DKM -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -Ctrl.hexspii = hexspii:8E5C3AE507221684 -Ctrl.hexspir = hexspir:B1F201BB155C3ACD -Ctrl.hexseed = hexseed:EFAA7AB0EAA85A3D0BE2100CD4B6FE00FF5025A9EAFDDB3EF518E9F0D3FE60E6 -Ctrl.mode = mode:1 -Output = 462B9DD525D4FD71169174272779E704BAF62C6231779AE9EFE8C58B21916B42010164AF2111EBD762F6916CA9A6F0EE05C8B320E4EE27705521DE2589ADEA1878F1A551738AF7C88DC4F0BB0C096A3F7D1F1A670FC79F49F678D60D665BB3710C8657F03BA9F62B9A818D7A228968C506E237AE9502AA6DB395C61EA6A3E79504F86B7368BFB5423DF79E48809BBCCD49FD826D024F63D7C2A5566400A12E736AA034510428F5EA008FE2FC16886FA388274EA6C2B4FCFC6141BF04F8207EF8AFC224EA1059CB220DC0B23AC0E4CCDA495A4E131B1D56E223ABA5A48E8ED1F5 - -# self_test_data.c - DKM(Child_SA) -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -Ctrl.hexkey = hexkey:462B9DD525D4FD71169174272779E704BAF62C6231779AE9EFE8C58B21916B42 -Ctrl.mode = mode:1 -Output = 23647677E7D403FA1E3006F19840AEE18AD9FECC4215814C4131BDEBA98433D8B0E31BFBBDDF822ABCCE5E06486AA388022B75E27E1E68AA5983028B65282C730C5D49EF7606770376CFDEC41F7CC435D816029989BC353D3B67B9FD1168DDCB8978850DA9B752AEE6A30D0086D2C4D74EC0E03648A0DAD334FAF5FE88084E67B0F3E8FEE8B5E1BD3850DB540F1FB8CFFE23C9E92CDA209373F354880C246C753E2A0ECA9CB73B9910A8531C4010E6768FA29F909E60AF777FED6E739C3CFDA03467E915D6F03FCE9C41F5F9D578F8912D66A75457E79EE1D5BCC2BE5C2F9BAE - -# self_test_data.c - DKM(Child_DH) -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -Ctrl.hexkey = hexkey:462B9DD525D4FD71169174272779E704BAF62C6231779AE9EFE8C58B21916B42 -Ctrl.hexsecret = hexsecret:52F00AB174C25D5B7139AE5FF4E8E9EDDEE5992D2E36ADF8A559FFD90DAB1442E4FBE429D320C0F33552A17D1557FA41EA70E8FB916C4FA27ED52B5F8EBD8461AFA78F1159159A64055AC5F6319E29C28EAE58CBC6847770F32C3FED1D04750484F854790F95E9EC01BC5BC461F24966462E359511329305038E94DEB6DD42C2 -Ctrl.mode = mode:1 -Output = 6A919387A5FA2835FE8A8237E4A14845BD2B9930DB87EFF7ADF268F62186004902DBA9AA942D0259A0EDC4120B932A503865B57BA8FB88117EF5DF7B26799CD8BA37AA5438108CB1A4FE117907C9D0597B708C3F11151FEFD624D2317202B7C81430600E6FCBB6E1A8DF2B4861EF2363D53DE1BE69057B0CF6634A7E7BFA97B3C2810623E2BD6757738777177036E9C3A39794456954BD41FC444A12507AB9CAC69A0540D13C29DB8510F566A691691BAA2D9569DACC990D56A454BB444BCBBE8751B0550A5278812FC5AB4F28990DD6D608538D7DDDE24DC81BDAACA7751FDE - -# self_test_data.c - rekey -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -Ctrl.hexkey = hexkey:462B9DD525D4FD71169174272779E704BAF62C6231779AE9EFE8C58B21916B42 -Ctrl.hexsecret = hexsecret:52F00AB174C25D5B7139AE5FF4E8E9EDDEE5992D2E36ADF8A559FFD90DAB1442E4FBE429D320C0F33552A17D1557FA41EA70E8FB916C4FA27ED52B5F8EBD8461AFA78F1159159A64055AC5F6319E29C28EAE58CBC6847770F32C3FED1D04750484F854790F95E9EC01BC5BC461F24966462E359511329305038E94DEB6DD42C2 -Ctrl.mode = mode:2 -Output = 90722C42BD849E9B72D240FC254174270FA8295DE6F0338DAFC303A9EC104F12 - -# negative test case, GEN missing digest -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -#Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -Ctrl.hexsecret = hexsecret:D084A30166A50FB7325C3960874A839449EF9741C2F4F947D0201DD8C1269273D79509F37E3CA3EB4FA2FE2A28254E289CD3F34DAD4EB4DF1A07685A4B8A94FA61E2491F7598B3CE65547FF133B3F63D1AC4175EAA695033F3CEDB026A6873A36455172A8540B8A5D23A0143BED0390EE49B168269D75FFFEE9FB62BE965993C -Ctrl.mode = mode:0 -Result = KDF_DERIVE_ERROR -Reason = missing message digest - -# negative test case, GEN invalid digest -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA3-256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -Ctrl.hexsecret = hexsecret:D084A30166A50FB7325C3960874A839449EF9741C2F4F947D0201DD8C1269273D79509F37E3CA3EB4FA2FE2A28254E289CD3F34DAD4EB4DF1A07685A4B8A94FA61E2491F7598B3CE65547FF133B3F63D1AC4175EAA695033F3CEDB026A6873A36455172A8540B8A5D23A0143BED0390EE49B168269D75FFFEE9FB62BE965993C -Ctrl.mode = mode:0 -Result = KDF_CTRL_ERROR - -# negative test case, GEN missing ni -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -#Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -Ctrl.hexsecret = hexsecret:D084A30166A50FB7325C3960874A839449EF9741C2F4F947D0201DD8C1269273D79509F37E3CA3EB4FA2FE2A28254E289CD3F34DAD4EB4DF1A07685A4B8A94FA61E2491F7598B3CE65547FF133B3F63D1AC4175EAA695033F3CEDB026A6873A36455172A8540B8A5D23A0143BED0390EE49B168269D75FFFEE9FB62BE965993C -Ctrl.mode = mode:0 -Result = KDF_DERIVE_ERROR -Reason = missing nonce - -# negative test case, GEN ni < 8 bytes -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -Ctrl.hexsecret = hexsecret:D084A30166A50FB7325C3960874A839449EF9741C2F4F947D0201DD8C1269273D79509F37E3CA3EB4FA2FE2A28254E289CD3F34DAD4EB4DF1A07685A4B8A94FA61E2491F7598B3CE65547FF133B3F63D1AC4175EAA695033F3CEDB026A6873A36455172A8540B8A5D23A0143BED0390EE49B168269D75FFFEE9FB62BE965993C -Ctrl.mode = mode:0 -Result = KDF_CTRL_ERROR -Reason = invalid nonce length - -# negative test case, GEN missing nr -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -#Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -Ctrl.hexsecret = hexsecret:D084A30166A50FB7325C3960874A839449EF9741C2F4F947D0201DD8C1269273D79509F37E3CA3EB4FA2FE2A28254E289CD3F34DAD4EB4DF1A07685A4B8A94FA61E2491F7598B3CE65547FF133B3F63D1AC4175EAA695033F3CEDB026A6873A36455172A8540B8A5D23A0143BED0390EE49B168269D75FFFEE9FB62BE965993C -Ctrl.mode = mode:0 -Result = KDF_DERIVE_ERROR -Reason = missing nonce - -# negative test case, GEN nr < 8 bytes -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D -Ctrl.hexsecret = hexsecret:D084A30166A50FB7325C3960874A839449EF9741C2F4F947D0201DD8C1269273D79509F37E3CA3EB4FA2FE2A28254E289CD3F34DAD4EB4DF1A07685A4B8A94FA61E2491F7598B3CE65547FF133B3F63D1AC4175EAA695033F3CEDB026A6873A36455172A8540B8A5D23A0143BED0390EE49B168269D75FFFEE9FB62BE965993C -Ctrl.mode = mode:0 -Result = KDF_CTRL_ERROR -Reason = invalid nonce length - -# negative test case, GEN missing secret g^ir -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -#Ctrl.hexsecret = hexsecret:D084A30166A50FB7325C3960874A839449EF9741C2F4F947D0201DD8C1269273D79509F37E3CA3EB4FA2FE2A28254E289CD3F34DAD4EB4DF1A07685A4B8A94FA61E2491F7598B3CE65547FF133B3F63D1AC4175EAA695033F3CEDB026A6873A36455172A8540B8A5D23A0143BED0390EE49B168269D75FFFEE9FB62BE965993C -Ctrl.mode = mode:0 -Result = KDF_DERIVE_ERROR -Reason = missing secret - -# negative test case, DKM missing SPIi -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -#Ctrl.hexspii = hexspii:8E5C3AE507221684 -Ctrl.hexspir = hexspir:B1F201BB155C3ACD -Ctrl.hexseed = hexseed:EFAA7AB0EAA85A3D0BE2100CD4B6FE00FF5025A9EAFDDB3EF518E9F0D3FE60E6 -Ctrl.mode = mode:1 -Result = KDF_DERIVE_ERROR -Reason = invalid parameters for dkm - -# negative test case, DKM missing SPIr -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -Ctrl.hexspii = hexspii:8E5C3AE507221684 -#Ctrl.hexspir = hexspir:B1F201BB155C3ACD -Ctrl.hexseed = hexseed:CD2E8050137832245F1DBACC6E4F0A92F94D45D6 -Ctrl.mode = mode:1 -Result = KDF_DERIVE_ERROR -Reason = invalid parameters for dkm - -# negative test case, DKM has spii, spir and secret -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -Ctrl.hexspii = hexspii:8E5C3AE507221684 -#Ctrl.hexspir = hexspir:B1F201BB155C3ACD -Ctrl.hexseed = hexseed:CD2E8050137832245F1DBACC6E4F0A92F94D45D6 -Ctrl.hexsecret = hexsecret:D084A30166A50FB7325C3960874A839449EF9741C2F4F947D0201DD8C1269273D79509F37E3CA3EB4FA2FE2A28254E289CD3F34DAD4EB4DF1A07685A4B8A94FA61E2491F7598B3CE65547FF133B3F63D1AC4175EAA695033F3CEDB026A6873A36455172A8540B8A5D23A0143BED0390EE49B168269D75FFFEE9FB62BE965993C -Ctrl.mode = mode:1 -Result = KDF_DERIVE_ERROR -Reason = invalid parameters for dkm - -# negative test case, rekey missing key -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -#Ctrl.hexkey = hexkey:6F1B12CAD3CBE097B35430356D869D54CDDB0198 -Ctrl.hexsecret = hexsecret:52F00AB174C25D5B7139AE5FF4E8E9EDDEE5992D2E36ADF8A559FFD90DAB1442E4FBE429D320C0F33552A17D1557FA41EA70E8FB916C4FA27ED52B5F8EBD8461AFA78F1159159A64055AC5F6319E29C28EAE58CBC6847770F32C3FED1D04750484F854790F95E9EC01BC5BC461F24966462E359511329305038E94DEB6DD42C2 -Ctrl.mode = mode:2 -Result = KDF_DERIVE_ERROR -Reason = missing dkm - -# negative test case, rekey missing secret -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -Ctrl.hexkey = hexkey:462B9DD525D4FD71169174272779E704BAF62C6231779AE9EFE8C58B21916B42 -#Ctrl.hexsecret = hexsecret:52F00AB174C25D5B7139AE5FF4E8E9EDDEE5992D2E36ADF8A559FFD90DAB1442E4FBE429D320C0F33552A17D1557FA41EA70E8FB916C4FA27ED52B5F8EBD8461AFA78F1159159A64055AC5F6319E29C28EAE58CBC6847770F32C3FED1D04750484F854790F95E9EC01BC5BC461F24966462E359511329305038E94DEB6DD42C2 -Ctrl.mode = mode:2 -Result = KDF_DERIVE_ERROR -Reason = missing secret - -# test case, invalid mode -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.hexni = hexni:3651FEF5C9C35E93 -Ctrl.hexnr = hexnr:C09A8B90A3F04D59 -Ctrl.hexsecret = hexsecret:D084A30166A50FB7325C3960874A839449EF9741C2F4F947D0201DD8C1269273D79509F37E3CA3EB4FA2FE2A28254E289CD3F34DAD4EB4DF1A07685A4B8A94FA61E2491F7598B3CE65547FF133B3F63D1AC4175EAA695033F3CEDB026A6873A36455172A8540B8A5D23A0143BED0390EE49B168269D75FFFEE9FB62BE965993C -Ctrl.mode = mode:3 -Result = KDF_CTRL_ERROR -Reason = invalid mode - -# https://raw.githubusercontent.com/usnistgov/ACVP-Server/refs/heads/master/gen-val/json-files/kdf-components-ikev2-1.0/prompt.json - -# From libacvp testing sample testcases -# tgId = 7, tcId = 121, GEN -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.ni = hexni:F096BC348F4C0BE7A0932E065F72DA82F9E312379CBEC86574837E535DEDD0F81E86FE52F9D89336B17BF5DC030E766E71D25B60D724AAEFE8B60C2383BD6395703214D6E04C545443E95B47ADB11C80A60110C083402B335CDF9E4E2CD6200DC3A28D1F8E1D6F8293DEA1025707CE870439F9A3CB2638FE52A3F350CEE833E4EBB34F7C3920B9A0A4DCE7BC3E7DD6502F6D365FBB0BC0131FC74048BD145E7B9BE07F2E58FDF53A98B5AF8C3958C592ECB1642D63CEC46BE1A77A2E5B525554682114040FC201949B992E8076A2BA99F59C9B1368C69CB0E48FF0599290D4C635262EF4F1BB2E87C4CDF4FF7EA9FAD2010CBF30198B7A961606BF3E49C5618F -Ctrl.nr = hexnr:AA241EAD5C65408AE109D09993DBA807FF23E00883A466F2F408BCED7A8BB37729ABB124DE79A7652CDD450911B4FF1A252D11B8D6EF065B48FD2703CB6D682712E24E92F6CE3511DBB6F78AFFAFEF1B0B875AE2B3C559783EA7F2138B831C236845B800D00AA28010C47D2F6744033A10B286E791D16DCBE31E9C994E45D659E65ECF03EAFFCD916FEBB320913C97DB41415961DC02823849A2009D9C126CC4E50F6CFE1F447C691463EA1309B66DE3BC39ABBB0ABC69525DEF486669E1F45AFFBDD6FE1F5314EDFC631E4655DF289108697F906C6C82BC0D8C52343278CD32A93FF33247764D3CCA18278C7876DEB0247ADE36149D99F3EF1E746D90DE0524 -Ctrl.secret = hexsecret:9E3D6F5B906FAC77CC7C877948F19113FF2AAC2B51DDA3D03803808E09B840E1E73DC8489C31659BDD78218B367DA86DC0EA41408ACADC67860C8DF60A8AF0EE07BEF7F05E51FD416B37F62D4429DCC5FA8A19FAA648A0DF2D279A9A72D0D2D4A666B51342A2F7D9E4E7882AA90A8F20A7FFC6DD5E9755BDD23A92562BE228F462A037D34A84C4C1677791FB067219C07EC57C9BC43474DE3A009707635F5175E38F9DC3CA0DE6249A8B12D37590BE6942F6B67C580C83FF6402E130A85F4C794A078CC4DC5BB73542D5A74734D8E11C313F67B0D99C7D6F53791F824228F942D346AC56ACEFA9A9A79018D57CD67983842459A1A21FC0F65E38B386045EC55B -Ctrl.mode = mode:0 -Output = CB5B5E3729A6E797A257EE0124A6EA6143E753B7545C1266413119F5C108FE2E - -# tgId = 7, tcId = 121, DKM -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.ni = hexni:F096BC348F4C0BE7A0932E065F72DA82F9E312379CBEC86574837E535DEDD0F81E86FE52F9D89336B17BF5DC030E766E71D25B60D724AAEFE8B60C2383BD6395703214D6E04C545443E95B47ADB11C80A60110C083402B335CDF9E4E2CD6200DC3A28D1F8E1D6F8293DEA1025707CE870439F9A3CB2638FE52A3F350CEE833E4EBB34F7C3920B9A0A4DCE7BC3E7DD6502F6D365FBB0BC0131FC74048BD145E7B9BE07F2E58FDF53A98B5AF8C3958C592ECB1642D63CEC46BE1A77A2E5B525554682114040FC201949B992E8076A2BA99F59C9B1368C69CB0E48FF0599290D4C635262EF4F1BB2E87C4CDF4FF7EA9FAD2010CBF30198B7A961606BF3E49C5618F -Ctrl.nr = hexnr:AA241EAD5C65408AE109D09993DBA807FF23E00883A466F2F408BCED7A8BB37729ABB124DE79A7652CDD450911B4FF1A252D11B8D6EF065B48FD2703CB6D682712E24E92F6CE3511DBB6F78AFFAFEF1B0B875AE2B3C559783EA7F2138B831C236845B800D00AA28010C47D2F6744033A10B286E791D16DCBE31E9C994E45D659E65ECF03EAFFCD916FEBB320913C97DB41415961DC02823849A2009D9C126CC4E50F6CFE1F447C691463EA1309B66DE3BC39ABBB0ABC69525DEF486669E1F45AFFBDD6FE1F5314EDFC631E4655DF289108697F906C6C82BC0D8C52343278CD32A93FF33247764D3CCA18278C7876DEB0247ADE36149D99F3EF1E746D90DE0524 -Ctrl.spii = hexspii:DC90D7D683D1C342 -Ctrl.spir = hexspir:4BADDAC5301B550B -Ctrl.seed = hexseed:CB5B5E3729A6E797A257EE0124A6EA6143E753B7545C1266413119F5C108FE2E -Ctrl.mode = mode:1 -Output = CDDD59534E22D7306C94D07D5C14FAD33E58838E02C7A8FA9C421F66FB72E51B553BC4798039DC7DD51967D2DF6759C4196849E790D3874066C14443938FF6B04305B4A6E1297FC561554AF242F404342721A1A92F0AA5FD66EA1835DEC564042326B81DDDE622818BFA1B413BD02817F3AADD4DC43DFD64AC1EC3F072088E972D871E1100A0C23EC40484A45685889973984A17E8E081D0E80C91267D152E6B258C18525124FD2667249E1C645D98F6586E791222C5D4B94AE15F59D147F12821AED76B0F43BF3CB36410E58611C3CE61F08AB39A12639395FC4725AC23C9AD8635B508BCCACC79AB81AD68D531D439E4379A916EA19B63BB021576DDC7E4C14F471E368A6AE46852129931952DBEBC16AC8869C0462EDD98F80445495301F1BD6E1AB76312434C212DE18AA260DBD1EBDB13A3AD91ADA28D4CD533545EB93C0F2766E9034344855304DAD700A1CAC269DD9C36CCF08F01389D627B46D81F9CB43502FEE7584F74441C96EAC7F7D0EEBEB6B13BCD3041A94B3D5B08E3699B97 - -# tgId = 7, tcId = 121, DKM(Child_SA) -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.ni = hexni:F096BC348F4C0BE7A0932E065F72DA82F9E312379CBEC86574837E535DEDD0F81E86FE52F9D89336B17BF5DC030E766E71D25B60D724AAEFE8B60C2383BD6395703214D6E04C545443E95B47ADB11C80A60110C083402B335CDF9E4E2CD6200DC3A28D1F8E1D6F8293DEA1025707CE870439F9A3CB2638FE52A3F350CEE833E4EBB34F7C3920B9A0A4DCE7BC3E7DD6502F6D365FBB0BC0131FC74048BD145E7B9BE07F2E58FDF53A98B5AF8C3958C592ECB1642D63CEC46BE1A77A2E5B525554682114040FC201949B992E8076A2BA99F59C9B1368C69CB0E48FF0599290D4C635262EF4F1BB2E87C4CDF4FF7EA9FAD2010CBF30198B7A961606BF3E49C5618F -Ctrl.nr = hexnr:AA241EAD5C65408AE109D09993DBA807FF23E00883A466F2F408BCED7A8BB37729ABB124DE79A7652CDD450911B4FF1A252D11B8D6EF065B48FD2703CB6D682712E24E92F6CE3511DBB6F78AFFAFEF1B0B875AE2B3C559783EA7F2138B831C236845B800D00AA28010C47D2F6744033A10B286E791D16DCBE31E9C994E45D659E65ECF03EAFFCD916FEBB320913C97DB41415961DC02823849A2009D9C126CC4E50F6CFE1F447C691463EA1309B66DE3BC39ABBB0ABC69525DEF486669E1F45AFFBDD6FE1F5314EDFC631E4655DF289108697F906C6C82BC0D8C52343278CD32A93FF33247764D3CCA18278C7876DEB0247ADE36149D99F3EF1E746D90DE0524 -Ctrl.key = hexkey:CDDD59534E22D7306C94D07D5C14FAD33E58838E02C7A8FA9C421F66FB72E51B -Ctrl.mode = mode:1 -Output = 6E7CC5B65BB20CBDB06825802B98B62357D824F72D7756F9C97FD132788216F6594726217705098DA118A2023849DFF1A502E4BA5D8DFE9FFECEFDEE2BF79A3713C8E7A5C63A1429539AAB4C7C372C5A561BDCC82CCFAEAAFFF9ABDEBB2EA3B901EEC8252811CFA2422AAF2BA24CF1F9DD9AFB54C0F65A11BE7566AE0E6B5170BC205AC9A703E35D7D60D5ECF70A9B9EF4D72D37AB88AF021D38808341FC6EA522E6741550942799C4974333FEB6F9A3E7254EB476DA31DCF717DA189F8B7A075EB1BB06B5DC14714FFAAE1FD15F142CF9E6993E0A5A282124B46AEAAA5FC773EA3BDD3CC43E64ADC689BE3EAA9F977D950425203739C15794D2F3D48086CCF6404F799FB59BDB1F4D9596255CF2EDBD96C787B66CF47EFD7947469363D41750163B2D79D43A829C0D3695234094D3DCF56317948A92338BD22E3D3C27B976373B4FB513B38B696B340A747860DAD4DBDE0FD7D15D53F0A49DEF2A404FC152043FE94B868989F43CD4E90E3A90F95B6246072A55FD70A987A25BBFD93A37C8F7 - -# tgId = 7, tcId = 121, DKM(Child_DH) -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.ni = hexni:F096BC348F4C0BE7A0932E065F72DA82F9E312379CBEC86574837E535DEDD0F81E86FE52F9D89336B17BF5DC030E766E71D25B60D724AAEFE8B60C2383BD6395703214D6E04C545443E95B47ADB11C80A60110C083402B335CDF9E4E2CD6200DC3A28D1F8E1D6F8293DEA1025707CE870439F9A3CB2638FE52A3F350CEE833E4EBB34F7C3920B9A0A4DCE7BC3E7DD6502F6D365FBB0BC0131FC74048BD145E7B9BE07F2E58FDF53A98B5AF8C3958C592ECB1642D63CEC46BE1A77A2E5B525554682114040FC201949B992E8076A2BA99F59C9B1368C69CB0E48FF0599290D4C635262EF4F1BB2E87C4CDF4FF7EA9FAD2010CBF30198B7A961606BF3E49C5618F -Ctrl.nr = hexnr:AA241EAD5C65408AE109D09993DBA807FF23E00883A466F2F408BCED7A8BB37729ABB124DE79A7652CDD450911B4FF1A252D11B8D6EF065B48FD2703CB6D682712E24E92F6CE3511DBB6F78AFFAFEF1B0B875AE2B3C559783EA7F2138B831C236845B800D00AA28010C47D2F6744033A10B286E791D16DCBE31E9C994E45D659E65ECF03EAFFCD916FEBB320913C97DB41415961DC02823849A2009D9C126CC4E50F6CFE1F447C691463EA1309B66DE3BC39ABBB0ABC69525DEF486669E1F45AFFBDD6FE1F5314EDFC631E4655DF289108697F906C6C82BC0D8C52343278CD32A93FF33247764D3CCA18278C7876DEB0247ADE36149D99F3EF1E746D90DE0524 -Ctrl.key = hexkey:CDDD59534E22D7306C94D07D5C14FAD33E58838E02C7A8FA9C421F66FB72E51B -Ctrl.secret = hexsecret:5540B8884168C2D05B43FC37A9BC613D0F66FF3EEF3783D126DCC18EB6BBAE71376572F77F43874BECC9FCB3EC7BE89D1F8D923143FBA7C83838CBC8B3AF9A58F7E9B2915A81CBA198423A96FFBB09F2A4753E5014A65BEAF7CD784BE5208E2660FC6EF66D8C135EDEA6D89EE59E96B083B1E842D6FA5466DF1F1E6EDFA94870E11F35966C8DA38DB7144A680C3A0A163C57F42E916F469692DB83101ACA72290FE4D9EFB4D20877DF79B11C90E6416330393951D25855BA0FEA68750582066931DB4F4E9D3B4F75A9C786E62A5680FB5088932034A3045F33762B0348B23F6560DC7311E291EBC4596DF5D7B789313AEEB12744E86645A4EC31E089FFA8E39E -Ctrl.mode = mode:1 -Output = 81C3D430D4C808318288287AE8BEF264942D5DEB2DC42B8BE559315640E50ED9BFECA0F62B108FFB4E485BEB859B1704266D5B4450D7DAB7A65697F4CE95310A75E66EA170791911DB8D934D8DA9DBF47976666F61183AD2D98CD6BFC7442763BED87583C106BA42729FD7E2806E766E4A82B746AAF46126AFCC6FD932E5680C1000167E26C5777CAEC49BFF1B40566E017045200A9CFCDD1A5E87ADCC0E2E84CDFCB21C286028971AEE733D897ACF16A95C7D9016339983C3089E24CA41E178D120485657839F53B0220BD477BBB9D90DFDB8E647E3E8C59A74465697AC6D57D6BC67FBAEAB737D6DD7CCC912C37BFE4F11B4854CBEC8F15E6320E89D68133D5B0BC5ADF60DD7B83631B317717574956043CBAD4F1BF1769B3E5F2843D86876CF82E9AE7FBDCCB7E7C68D22F4954A03880AA8C26E0E48A02A3FDC14EF3C7FB91C3B5F745EB8B1C654168FD6D71EC3360A904E2F52DA7B25D02C0E3B31179C3724271F63DA41E5BE3992EF71AC864A6A352EFD05A88A2773AFD48A47DAACAEEE - -# tgId = 7, tcId = 121, ReKey -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA256 -Ctrl.ni = hexni:F096BC348F4C0BE7A0932E065F72DA82F9E312379CBEC86574837E535DEDD0F81E86FE52F9D89336B17BF5DC030E766E71D25B60D724AAEFE8B60C2383BD6395703214D6E04C545443E95B47ADB11C80A60110C083402B335CDF9E4E2CD6200DC3A28D1F8E1D6F8293DEA1025707CE870439F9A3CB2638FE52A3F350CEE833E4EBB34F7C3920B9A0A4DCE7BC3E7DD6502F6D365FBB0BC0131FC74048BD145E7B9BE07F2E58FDF53A98B5AF8C3958C592ECB1642D63CEC46BE1A77A2E5B525554682114040FC201949B992E8076A2BA99F59C9B1368C69CB0E48FF0599290D4C635262EF4F1BB2E87C4CDF4FF7EA9FAD2010CBF30198B7A961606BF3E49C5618F -Ctrl.nr = hexnr:AA241EAD5C65408AE109D09993DBA807FF23E00883A466F2F408BCED7A8BB37729ABB124DE79A7652CDD450911B4FF1A252D11B8D6EF065B48FD2703CB6D682712E24E92F6CE3511DBB6F78AFFAFEF1B0B875AE2B3C559783EA7F2138B831C236845B800D00AA28010C47D2F6744033A10B286E791D16DCBE31E9C994E45D659E65ECF03EAFFCD916FEBB320913C97DB41415961DC02823849A2009D9C126CC4E50F6CFE1F447C691463EA1309B66DE3BC39ABBB0ABC69525DEF486669E1F45AFFBDD6FE1F5314EDFC631E4655DF289108697F906C6C82BC0D8C52343278CD32A93FF33247764D3CCA18278C7876DEB0247ADE36149D99F3EF1E746D90DE0524 -Ctrl.key = hexkey:CDDD59534E22D7306C94D07D5C14FAD33E58838E02C7A8FA9C421F66FB72E51B -Ctrl.secret = hexsecret:5540B8884168C2D05B43FC37A9BC613D0F66FF3EEF3783D126DCC18EB6BBAE71376572F77F43874BECC9FCB3EC7BE89D1F8D923143FBA7C83838CBC8B3AF9A58F7E9B2915A81CBA198423A96FFBB09F2A4753E5014A65BEAF7CD784BE5208E2660FC6EF66D8C135EDEA6D89EE59E96B083B1E842D6FA5466DF1F1E6EDFA94870E11F35966C8DA38DB7144A680C3A0A163C57F42E916F469692DB83101ACA72290FE4D9EFB4D20877DF79B11C90E6416330393951D25855BA0FEA68750582066931DB4F4E9D3B4F75A9C786E62A5680FB5088932034A3045F33762B0348B23F6560DC7311E291EBC4596DF5D7B789313AEEB12744E86645A4EC31E089FFA8E39E -Ctrl.mode = mode:2 -Output = AAEBE45EE40BC364248FEBD74A9869B56E5DF1EA23D3619D23D0AFC1681E3F72 - -# tgId = 13, tcId = 241, GEN -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA512 -Ctrl.ni = hexni:834EA4753E9A06832072FA15E89E799035A1285CE241CAF3B5C724ECE8ECD0D2D1AC46FAB3D9D86BF2EBF4CC8F93E06C5342415E14DFCBC949574E1606F96F143E8AA8C80BCCD376FF3D3BAE0B134A04DD2AE557010E5D7A7552C6864FD8A82D99FFDFDA97BE97389A426D7259411B10DD9EEFAE2709141E654087A2056EB86DAF95EF262328A2CDD90C61152DC2BBFCF4CCF4084557C3892603023A8B7045FC589A35143E10DCD1A73406EA923B21687A12134B6A1007E4AA2E37FFFA4901DFF6F3514E2B350F08175E194D3C6DB75E03FD838D503CEFA9E9604A4E18F330C08142574A992465FEA063875ABAF144F47C50F32A0A83224E3EEA739033AF6B9F -Ctrl.nr = hexnr:F833709DE457FB58ABE1D26E8DECC8FE889D503954C4812AC0F41271394AF7C148B15A241C2D6D6502C3C57DAE854A97BFB3CCDCEC650153578CCB51BDFE1C715E81F3D78488B1547A3C9E5617D9B78B46D06F56BB56423C88DEACCD82E7A2A11ADD56651091682F0987332EA28A32045A4D39609F364EB5E70468ECB7BBDCAD6B41E04ADD11D97F300E8D0A0C2941F1CB64885F940EE2FA273477E910983E96913F58E37BFD68E3ADCD6E813176E95FEE7985F5526EEDC3245C4746F5864D9E90BF80F6882F6A505ADACD81D106576F7A6C705E37CE551235E012E64EC3BE7B4F3F8889E664CC5ED7BCC4A88022A437439609B3019CDE1948665A548E420D1E -Ctrl.secret = hexsecret:9566A04BF95F433C6497B3AE8CB0F600043F8438EB2B9E97E912AF1C5ACE9A73A8884BF1FF80A895EB97A6F5494B6CEA5B1C3123C3A9CBE057A0CBA2F52FD40A8DFDF9F99B521D356347E2B70CF637B5B4A44C2ED92770A281E6431CB50BDDCE4FB2EC8100218FA84B0A4A344C4DC79BBC81ADD2FD23BC797EFA1B2AFA6840AD7B2E04D391F33662774A5296A0EF9C9C113E84F5B958FD54857E75378406F29DA1EB23E9E9D9D94177672BFA7742F7F4319F31ED06E1999E17EEAC6B35ADC9A245CAD998E3CE3C422B8AD752F7144332E9AAE44EA837677A8406B7261C04CB4EB9230FBA75E09E16EEDA246D5B1DA5CF14C96F00FC83C555854E7982E52A1D4F -Ctrl.mode = mode:0 -Output = 3DAA296C25DD8CBDE8E9F5FE85498CB06339FC7AAA93F60987831A0FA79829E244AFE92BD66590D8C7F1BC281BADC619ED2C9762FDB913B052842E50E3989863 - -# tgId = 13, tcId = 241, DKM -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA512 -Ctrl.ni = hexni:834EA4753E9A06832072FA15E89E799035A1285CE241CAF3B5C724ECE8ECD0D2D1AC46FAB3D9D86BF2EBF4CC8F93E06C5342415E14DFCBC949574E1606F96F143E8AA8C80BCCD376FF3D3BAE0B134A04DD2AE557010E5D7A7552C6864FD8A82D99FFDFDA97BE97389A426D7259411B10DD9EEFAE2709141E654087A2056EB86DAF95EF262328A2CDD90C61152DC2BBFCF4CCF4084557C3892603023A8B7045FC589A35143E10DCD1A73406EA923B21687A12134B6A1007E4AA2E37FFFA4901DFF6F3514E2B350F08175E194D3C6DB75E03FD838D503CEFA9E9604A4E18F330C08142574A992465FEA063875ABAF144F47C50F32A0A83224E3EEA739033AF6B9F -Ctrl.nr = hexnr:F833709DE457FB58ABE1D26E8DECC8FE889D503954C4812AC0F41271394AF7C148B15A241C2D6D6502C3C57DAE854A97BFB3CCDCEC650153578CCB51BDFE1C715E81F3D78488B1547A3C9E5617D9B78B46D06F56BB56423C88DEACCD82E7A2A11ADD56651091682F0987332EA28A32045A4D39609F364EB5E70468ECB7BBDCAD6B41E04ADD11D97F300E8D0A0C2941F1CB64885F940EE2FA273477E910983E96913F58E37BFD68E3ADCD6E813176E95FEE7985F5526EEDC3245C4746F5864D9E90BF80F6882F6A505ADACD81D106576F7A6C705E37CE551235E012E64EC3BE7B4F3F8889E664CC5ED7BCC4A88022A437439609B3019CDE1948665A548E420D1E -Ctrl.spii = hexspii:6E5F49D279F4FBBB -Ctrl.spir = hexspir:FF7AE472AA4DD7AF -Ctrl.seed = hexseed:3DAA296C25DD8CBDE8E9F5FE85498CB06339FC7AAA93F60987831A0FA79829E244AFE92BD66590D8C7F1BC281BADC619ED2C9762FDB913B052842E50E3989863 -Ctrl.mode = mode:1 -Output = 2BD66826C397A19618E3133ACE96F6168A04EF9AFA53F2F07CECDA9E0F6139C37CC6512551F523006B74D501C5DD1AE502689ECE8A43CE7B3D866C7372176B1D5BC4A0B863F642351FD4822C79F0A8D97B03B09FA1393679149432798BEA545F70C663675E751A68AEEB7B238CA790229C7775E6A074BECDFAAD324AC546EEB5D0A9480B1AA06B6F225CBFAC7447DE3D8D292B0BEB7D9A5B709C02946A10F8799DD4E4B18C6D10CEDA39A82B9DAE01EFEBE6C31735590EF7D44E1C8DBBAD98DAFE620843065E5141D7C57770234128599E3223139656DBB3D0C494FABA482AE9740FAA3D3957EFD9D90FD24144BC9B317C7955722426A6719D0095D068FD0B63469140D1EF9DDEFC43B2BCFFF971A08A7E67E75B8F0DED8C4737175ABF04C32B906FE7D53E8C3B11B3829DB0082B73F44C042C285F079A3BD6C33F91559F31043E23BB0A79B83C93AAF1CFEAF6C5996E717869C2D7F6528C8ACAE6656A8430164886385441484107261DE0D9A9B6B39A24812CCFA24C1F964AEAC69CE6D00541 - -# tgId = 13, tcId = 241, DKM(Child_SA) -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA512 -Ctrl.ni = hexni:834EA4753E9A06832072FA15E89E799035A1285CE241CAF3B5C724ECE8ECD0D2D1AC46FAB3D9D86BF2EBF4CC8F93E06C5342415E14DFCBC949574E1606F96F143E8AA8C80BCCD376FF3D3BAE0B134A04DD2AE557010E5D7A7552C6864FD8A82D99FFDFDA97BE97389A426D7259411B10DD9EEFAE2709141E654087A2056EB86DAF95EF262328A2CDD90C61152DC2BBFCF4CCF4084557C3892603023A8B7045FC589A35143E10DCD1A73406EA923B21687A12134B6A1007E4AA2E37FFFA4901DFF6F3514E2B350F08175E194D3C6DB75E03FD838D503CEFA9E9604A4E18F330C08142574A992465FEA063875ABAF144F47C50F32A0A83224E3EEA739033AF6B9F -Ctrl.nr = hexnr:F833709DE457FB58ABE1D26E8DECC8FE889D503954C4812AC0F41271394AF7C148B15A241C2D6D6502C3C57DAE854A97BFB3CCDCEC650153578CCB51BDFE1C715E81F3D78488B1547A3C9E5617D9B78B46D06F56BB56423C88DEACCD82E7A2A11ADD56651091682F0987332EA28A32045A4D39609F364EB5E70468ECB7BBDCAD6B41E04ADD11D97F300E8D0A0C2941F1CB64885F940EE2FA273477E910983E96913F58E37BFD68E3ADCD6E813176E95FEE7985F5526EEDC3245C4746F5864D9E90BF80F6882F6A505ADACD81D106576F7A6C705E37CE551235E012E64EC3BE7B4F3F8889E664CC5ED7BCC4A88022A437439609B3019CDE1948665A548E420D1E -Ctrl.key = hexkey:2BD66826C397A19618E3133ACE96F6168A04EF9AFA53F2F07CECDA9E0F6139C37CC6512551F523006B74D501C5DD1AE502689ECE8A43CE7B3D866C7372176B1D -Ctrl.mode = mode:1 -Output = 0B0D01A13515AC0727F7D90456D3D2FD9C1172096CDED4A20BDA43FC796184BAEB3A7F34FFC09C584DD9BEEBC7629A36A5D143DFB1C2931F369E6702769B6A01AA20B7B955C30481D7894DF2AEBAB0DD669C3E1E168BE5F122F8A9D8A589F3C6C48EFC031129481E2DEA1F6FC10E07F3E39A1FCC3D660E289778458E752802501DBDE1EB0EDE3D2227DE7FAE3F265D66986B1AE4CF407EDC3A5168A6179ED8CA2006ACC2D9104749C3E2231482374E5F0CE3DA3C8B8520D37F37092669FBB78EAA4CC818BE8CA31935529E085BCE3830040F679883E3375C274CEF5BF5F36F34D8705B9EC48B4DC2FE9E3A269B41BED2D659767726DC775404610ED1B285067D900D20A38D02192475D2934AE8E4C47B4CF5729A42FEC7AF15C01AEB019069F2C87F2E6429D6CB2755384980DFAB9173C70AEDB30611A05FCD03078F2CAA8CB323452D6E899197992CF3B93343EEBAA1251E1D8F0B3664D0D0310217889510885D319C2BD8CD3A8FD49848D8331F8C248E6C3C7B6E3D4E376F7BC71FF10D66D1 - -# tgId = 13, tcId = 241, DKM(Child_DH) -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA512 -Ctrl.ni = hexni:834EA4753E9A06832072FA15E89E799035A1285CE241CAF3B5C724ECE8ECD0D2D1AC46FAB3D9D86BF2EBF4CC8F93E06C5342415E14DFCBC949574E1606F96F143E8AA8C80BCCD376FF3D3BAE0B134A04DD2AE557010E5D7A7552C6864FD8A82D99FFDFDA97BE97389A426D7259411B10DD9EEFAE2709141E654087A2056EB86DAF95EF262328A2CDD90C61152DC2BBFCF4CCF4084557C3892603023A8B7045FC589A35143E10DCD1A73406EA923B21687A12134B6A1007E4AA2E37FFFA4901DFF6F3514E2B350F08175E194D3C6DB75E03FD838D503CEFA9E9604A4E18F330C08142574A992465FEA063875ABAF144F47C50F32A0A83224E3EEA739033AF6B9F -Ctrl.nr = hexnr:F833709DE457FB58ABE1D26E8DECC8FE889D503954C4812AC0F41271394AF7C148B15A241C2D6D6502C3C57DAE854A97BFB3CCDCEC650153578CCB51BDFE1C715E81F3D78488B1547A3C9E5617D9B78B46D06F56BB56423C88DEACCD82E7A2A11ADD56651091682F0987332EA28A32045A4D39609F364EB5E70468ECB7BBDCAD6B41E04ADD11D97F300E8D0A0C2941F1CB64885F940EE2FA273477E910983E96913F58E37BFD68E3ADCD6E813176E95FEE7985F5526EEDC3245C4746F5864D9E90BF80F6882F6A505ADACD81D106576F7A6C705E37CE551235E012E64EC3BE7B4F3F8889E664CC5ED7BCC4A88022A437439609B3019CDE1948665A548E420D1E -Ctrl.key = hexkey:2BD66826C397A19618E3133ACE96F6168A04EF9AFA53F2F07CECDA9E0F6139C37CC6512551F523006B74D501C5DD1AE502689ECE8A43CE7B3D866C7372176B1D -Ctrl.secret = hexsecret:F34450EC9F4B07881FF17DB4AE1681B26F2FC8CBECDB7EF0463B09C4FE79F8414FBEA9FD3E7C18C845D04E283E1EEB7824484C72354A7A9C418E69B8134D596E1ABCD2998EA5FABCA1FD156678BF7FB0F31C1158E812FD215837A23938BAC55B37C6E8BECEDF9435A03484326CD2D4E3C7A273D8A99135027AA17823DA9BF0263082394CA3475266F5BAE91D1577C3D15A7DD429E1F5DE70138B05214589EF8A519AA930A42F609CCC54CE8701488E80C2BEACCA2542C0D9B2DD7C04E41EBBC341EB65A3F786900747FA6CA2CF914E908FEA40014D3175B73DA1B63437A89638F69E184FD91E6A02C0F9FC9AFAFE7B6811B3AC7A57B2615A3B3FC26289500143 -Ctrl.mode = mode:1 -Output = 48E185DC18E52193E01ECA3C0D739C3070A73B89A4D0FAC7B40E4D51250EEAE7232C2031DAA700E3A2D570BA67ECA56F1DBE5DE5B96CD718FAF2FCC7EBCA08D1FEFA2DB5B024CC9A03F50EF310D43A3E66D53912AF846CFF6BB039CBFF37BDD1C2D329993A98D3FAF9026A32EBF6747E347115AA3C604D187A25204407DB7E3FD4E1D28300E898028542C4B8D3C4EB26BD0ADF87439CCB7C0230351D38C92772CA234B887CA8F7667B4FBB9619151D75FECB2C30F570BC0EEDD5C6D89F39DE1A547AC99CFB7CF608AD4C56C83077E97CE850BE40344177CBEF2F22E37353E6A164A2683DE957A48754E8E74331A07503069E8ED44C68F27C0A414D582AA2DD7A66098E3C4D0BE5F0CC5FE9EBC042C3E794E53639A452F0449685DC3FC34C0EAE58AF6C7E862FAF0FC2E2C8F57C889E1DC19E8DAE2E92F828A3F01A1D3DBDCF3C7A0F61828E0E5C26E559E8D1320110D8477FF8A28D90BC9693BB99E10B7A3EA62E3559D7CC2E54279012D2C3CC7FBA3349E098D6756BCC7EE62507B350DBF3A3 - -# tgId = 13, tcId = 241, Rekey -FIPSversion = >=4.1.0 -KDF = IKEV2KDF -Ctrl.digest = digest:SHA512 -Ctrl.ni = hexni:834EA4753E9A06832072FA15E89E799035A1285CE241CAF3B5C724ECE8ECD0D2D1AC46FAB3D9D86BF2EBF4CC8F93E06C5342415E14DFCBC949574E1606F96F143E8AA8C80BCCD376FF3D3BAE0B134A04DD2AE557010E5D7A7552C6864FD8A82D99FFDFDA97BE97389A426D7259411B10DD9EEFAE2709141E654087A2056EB86DAF95EF262328A2CDD90C61152DC2BBFCF4CCF4084557C3892603023A8B7045FC589A35143E10DCD1A73406EA923B21687A12134B6A1007E4AA2E37FFFA4901DFF6F3514E2B350F08175E194D3C6DB75E03FD838D503CEFA9E9604A4E18F330C08142574A992465FEA063875ABAF144F47C50F32A0A83224E3EEA739033AF6B9F -Ctrl.nr = hexnr:F833709DE457FB58ABE1D26E8DECC8FE889D503954C4812AC0F41271394AF7C148B15A241C2D6D6502C3C57DAE854A97BFB3CCDCEC650153578CCB51BDFE1C715E81F3D78488B1547A3C9E5617D9B78B46D06F56BB56423C88DEACCD82E7A2A11ADD56651091682F0987332EA28A32045A4D39609F364EB5E70468ECB7BBDCAD6B41E04ADD11D97F300E8D0A0C2941F1CB64885F940EE2FA273477E910983E96913F58E37BFD68E3ADCD6E813176E95FEE7985F5526EEDC3245C4746F5864D9E90BF80F6882F6A505ADACD81D106576F7A6C705E37CE551235E012E64EC3BE7B4F3F8889E664CC5ED7BCC4A88022A437439609B3019CDE1948665A548E420D1E -Ctrl.key = hexkey:2BD66826C397A19618E3133ACE96F6168A04EF9AFA53F2F07CECDA9E0F6139C37CC6512551F523006B74D501C5DD1AE502689ECE8A43CE7B3D866C7372176B1D -Ctrl.secret = hexsecret:F34450EC9F4B07881FF17DB4AE1681B26F2FC8CBECDB7EF0463B09C4FE79F8414FBEA9FD3E7C18C845D04E283E1EEB7824484C72354A7A9C418E69B8134D596E1ABCD2998EA5FABCA1FD156678BF7FB0F31C1158E812FD215837A23938BAC55B37C6E8BECEDF9435A03484326CD2D4E3C7A273D8A99135027AA17823DA9BF0263082394CA3475266F5BAE91D1577C3D15A7DD429E1F5DE70138B05214589EF8A519AA930A42F609CCC54CE8701488E80C2BEACCA2542C0D9B2DD7C04E41EBBC341EB65A3F786900747FA6CA2CF914E908FEA40014D3175B73DA1B63437A89638F69E184FD91E6A02C0F9FC9AFAFE7B6811B3AC7A57B2615A3B3FC26289500143 -Ctrl.mode = mode:2 -Output = 1CC9237EBB1704D703952B6EDBE275CA51AC17E2E224F13E38F4C49F5FA9AF00F8ECB96FA0ECD6FF282C08A29D3E313AB4A4EE1022580118B8DEFF0CD8432A00 diff --git a/test/recipes/30-test_evp_data/evpkdf_srtp.txt b/test/recipes/30-test_evp_data/evpkdf_srtp.txt deleted file mode 100644 index 3eb53d63c1..0000000000 --- a/test/recipes/30-test_evp_data/evpkdf_srtp.txt +++ /dev/null @@ -1,469 +0,0 @@ -# -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -# Tests start with one of these keywords -# Cipher Decrypt Derive Digest Encoding KDF MAC PBE -# PrivPubKeyPair Sign Verify VerifyRecover -# and continue until a blank line. Lines starting with a pound sign are ignored. - -Title = SRTPKDF tests (from RFC 3711 test vectors and additional cases) - -# Test Case 1: RFC 3711 test vectors B.3, encryption key -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:E1F97A0D3E018BE0D64FA32C06DE4139 -Ctrl.hexsalt = hexsalt:0EC675AD498AFEEBB6960B3AABE6 -Ctrl.kdr = kdr:0 -Ctrl.index = hexindex:000000000000 -Ctrl.label = label:0 -Output = C61E7A93744F39EE10734AFE3FF7A087 - -# Test Case 1.1, variation, missing kdr (default as zero) -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:E1F97A0D3E018BE0D64FA32C06DE4139 -Ctrl.hexsalt = hexsalt:0EC675AD498AFEEBB6960B3AABE6 -Ctrl.index = hexindex:000000000000 -Ctrl.label = label:0 -Output = C61E7A93744F39EE10734AFE3FF7A087 - -# Test Case 1.2, variation, missing index (default as zero) -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:E1F97A0D3E018BE0D64FA32C06DE4139 -Ctrl.hexsalt = hexsalt:0EC675AD498AFEEBB6960B3AABE6 -Ctrl.kdr = kdr:0 -Ctrl.label = label:0 -Output = C61E7A93744F39EE10734AFE3FF7A087 - -# Test Case 1.3, variation, default kdr and index -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:E1F97A0D3E018BE0D64FA32C06DE4139 -Ctrl.hexsalt = hexsalt:0EC675AD498AFEEBB6960B3AABE6 -Ctrl.label = label:0 -Output = C61E7A93744F39EE10734AFE3FF7A087 - -# Test Case 1.4, variation, missing label (default as zero) -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:E1F97A0D3E018BE0D64FA32C06DE4139 -Ctrl.hexsalt = hexsalt:0EC675AD498AFEEBB6960B3AABE6 -Ctrl.kdr = kdr:0 -Ctrl.index = hexindex:000000000000 -Output = C61E7A93744F39EE10734AFE3FF7A087 - -# Test Case 2: RFC 3711 test vectors B.3, salt key -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:E1F97A0D3E018BE0D64FA32C06DE4139 -Ctrl.hexsalt = hexsalt:0EC675AD498AFEEBB6960B3AABE6 -Ctrl.kdr = kdr:0 -Ctrl.index = hexindex:000000000000 -Ctrl.label = label:2 -Output = 30CBBC08863D8C85D49DB34A9AE1 - -# Test Case 3: RFC 3711 test vectors B.3, authentication key -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:E1F97A0D3E018BE0D64FA32C06DE4139 -Ctrl.hexsalt = hexsalt:0EC675AD498AFEEBB6960B3AABE6 -Ctrl.kdr = kdr:0 -Ctrl.index = hexindex:000000000000 -Ctrl.label = label:1 -Output = CEBE321F6FF7716B6FD4AB49AF256A156D38BAA4 - -# Negative Test case 1, missing cipher -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.hexkey = hexkey:E1F97A0D3E018BE0D64FA32C06DE4139 -Ctrl.hexsalt = hexsalt:0EC675AD498AFEEBB6960B3AABE6 -Ctrl.kdr = kdr:0 -Ctrl.index = hexindex:000000000000 -Ctrl.label = label:0 -Output = C61E7A93744F39EE10734AFE3FF7A087 -Result = KDF_DERIVE_ERROR -Reason = missing cipher - -# Negative Test case 2, invalid cipher -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CBC -Ctrl.hexkey = hexkey:E1F97A0D3E018BE0D64FA32C06DE4139 -Ctrl.hexsalt = hexsalt:0EC675AD498AFEEBB6960B3AABE6 -Ctrl.kdr = kdr:0 -Ctrl.index = hexindex:000000000000 -Ctrl.label = label:0 -Output = C61E7A93744F39EE10734AFE3FF7A087 -Result = KDF_CTRL_ERROR -Reason = invalid cipher - -# Negative Test case 3, missing key -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexsalt = hexsalt:0EC675AD498AFEEBB6960B3AABE6 -Ctrl.kdr = kdr:0 -Ctrl.index = hexindex:000000000000 -Ctrl.label = label:0 -Output = C61E7A93744F39EE10734AFE3FF7A087 -Result = KDF_DERIVE_ERROR -Reason = missing key - -# Negative Test case 4, missing salt -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:E1F97A0D3E018BE0D64FA32C06DE4139 -Ctrl.kdr = kdr:0 -Ctrl.index = hexindex:000000000000 -Ctrl.label = label:0 -Output = C61E7A93744F39EE10734AFE3FF7A087 -Result = KDF_DERIVE_ERROR -Reason = missing salt - -# Negative Test case 5, invalid label -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:E1F97A0D3E018BE0D64FA32C06DE4139 -Ctrl.hexsalt = hexsalt:0EC675AD498AFEEBB6960B3AABE6 -Ctrl.kdr = kdr:0 -Ctrl.index = hexindex:000000000000 -Ctrl.label = label:8 -Output = C61E7A93744F39EE10734AFE3FF7A087 -Result = KDF_CTRL_ERROR -Reason = invalid label - -# Negative Test case 6, invalid kdr (not power of 2) -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:E1F97A0D3E018BE0D64FA32C06DE4139 -Ctrl.hexsalt = hexsalt:0EC675AD498AFEEBB6960B3AABE6 -Ctrl.kdr = kdr:5 -Ctrl.index = hexindex:000000000000 -Ctrl.label = label:0 -Output = C61E7A93744F39EE10734AFE3FF7A087 -Result = KDF_CTRL_ERROR -Reason = invalid kdr - -# Negative Test case 7, invalid kdr (kdr out of range) -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:E1F97A0D3E018BE0D64FA32C06DE4139 -Ctrl.hexsalt = hexsalt:0EC675AD498AFEEBB6960B3AABE6 -Ctrl.kdr = kdr:0x10000000 -Ctrl.index = hexindex:000000000000 -Ctrl.label = label:0 -Output = C61E7A93744F39EE10734AFE3FF7A087 -Result = KDF_CTRL_ERROR -Reason = invalid kdr - -# Additional tests from -# https://github.com/usnistgov/ACVP-Server/tree/master/gen-val/json-files/kdf-components-srtp-1.0 - -# prompt.json tgId:3, tcid:21, expectedResults.json tcId:21 srtpKe -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:8C307F105F79D5D2C26B1A933AE22CD5 -Ctrl.hexsalt = hexsalt:563B4C15458D977B68080242CEE1 -Ctrl.kdr = kdr:1 -Ctrl.index = hexindex:08284B49F520 -Ctrl.label = label:0 -Output = A920DF50EAA111D03FBE9B203121C07D - -# prompt.json tgId:3, tcid:21, expectedResults.json tcId:21 srtpKa -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:8C307F105F79D5D2C26B1A933AE22CD5 -Ctrl.hexsalt = hexsalt:563B4C15458D977B68080242CEE1 -Ctrl.kdr = kdr:1 -Ctrl.index = hexindex:08284B49F520 -Ctrl.label = label:1 -Output = A337DC070C0DAFA942F1E3A27ACD3C9917CE4B4D - -# prompt.json tgId:3, tcid:21, expectedResults.json tcId:21 srtpKs -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:8C307F105F79D5D2C26B1A933AE22CD5 -Ctrl.hexsalt = hexsalt:563B4C15458D977B68080242CEE1 -Ctrl.kdr = kdr:1 -Ctrl.index = hexindex:08284B49F520 -Ctrl.label = label:2 -Output = 9E2BC99C86037F2AD98D72927428 - -# prompt.json tgId:3, tcid:21, expectedResults.json tcId:21 srtcpKe -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:8C307F105F79D5D2C26B1A933AE22CD5 -Ctrl.hexsalt = hexsalt:563B4C15458D977B68080242CEE1 -Ctrl.kdr = kdr:1 -Ctrl.index = hexindex:69B62109 -Ctrl.label = label:3 -Output = 94D76CA7ADB05b8631CF62538D97BE74 - -# prompt.json tgId:3, tcid:21, expectedResults.json tcId:21 srtcpKa -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:8C307F105F79D5D2C26B1A933AE22CD5 -Ctrl.hexsalt = hexsalt:563B4C15458D977B68080242CEE1 -Ctrl.kdr = kdr:1 -Ctrl.index = hexindex:69B62109 -Ctrl.label = label:4 -Output = FA02251D693645BC1001f83C5A13CB3E3D77F7EA - -# prompt.json tgId:3, tcid:21, expectedResults.json tcId:21 srtcpKs -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:8C307F105F79D5D2C26B1A933AE22CD5 -Ctrl.hexsalt = hexsalt:563B4C15458D977B68080242CEE1 -Ctrl.kdr = kdr:1 -Ctrl.index = hexindex:69B62109 -Ctrl.label = label:5 -Output = 70C0481A04E3610EC8AF8623FA9B - -# prompt.json tgId:4, tcid:31, expectedResults.json tcId:31 srtpKe -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:127A535F66D5D43135E5DB87F04AF2DB -Ctrl.hexsalt = hexsalt:82D0D04DC693E29E0FE7FECBF041 -Ctrl.kdr = kdr:2 -Ctrl.index = hexindex:3D6FECDCE1BE -Ctrl.label = label:0 -Output = A2F4D858CCDF585D9C5CA787C5A3031F - -# prompt.json tgId:4, tcid:31, expectedResults.json tcId:31 srtpKa -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:127A535F66D5D43135E5DB87F04AF2DB -Ctrl.hexsalt = hexsalt:82D0D04DC693E29E0FE7FECBF041 -Ctrl.kdr = kdr:2 -Ctrl.index = hexindex:3D6FECDCE1BE -Ctrl.label = label:1 -Output = C140C97CAC05B2ED338AD353014A90012F37B45C - -# prompt.json tgId:4, tcid:31, expectedResults.json tcId:31 srtpKs -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:127A535F66D5D43135E5DB87F04AF2DB -Ctrl.hexsalt = hexsalt:82D0D04DC693E29E0FE7FECBF041 -Ctrl.kdr = kdr:2 -Ctrl.index = hexindex:3D6FECDCE1BE -Ctrl.label = label:2 -Output = AA6DE94B3BCB5108EFD350AD6936 - -# prompt.json tgId:4, tcid:31, expectedResults.json tcId:31 srtcpKe -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:127A535F66D5D43135E5DB87F04AF2DB -Ctrl.hexsalt = hexsalt:82D0D04DC693E29E0FE7FECBF041 -Ctrl.kdr = kdr:2 -Ctrl.index = hexindex:1C7B571C -Ctrl.label = label:3 -Output = 2844C8F56E2AF865E4EBBD0D083A4FAE - -# prompt.json tgId:4, tcid:31, expectedResults.json tcId:31 srtcpKa -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:127A535F66D5D43135E5DB87F04AF2DB -Ctrl.hexsalt = hexsalt:82D0D04DC693E29E0FE7FECBF041 -Ctrl.kdr = kdr:2 -Ctrl.index = hexindex:1C7B571C -Ctrl.label = label:4 -Output = 50135309CF64D5162723749CCF085708F8E81636 - -# prompt.json tgId:4, tcid:31, expectedResults.json tcId:31 srtcpKs -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:127A535F66D5D43135E5DB87F04AF2DB -Ctrl.hexsalt = hexsalt:82D0D04DC693E29E0FE7FECBF041 -Ctrl.kdr = kdr:2 -Ctrl.index = hexindex:1C7B571C -Ctrl.label = label:5 -Output = 47CB081EC69F7E74FEB3FCD1BD20 - -# prompt.json tgId:6, tcid:51, expectedResults.json tcId:51 srtpKe -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:CF08F8159FCF18DA8108A3FE3B707C2B -Ctrl.hexsalt = hexsalt:4AF8352708E0A164C6645A63E5BB -Ctrl.kdr = kdr:8 -Ctrl.index = hexindex:F4EE616415B9 -Ctrl.label = label:0 -Output = B46322B06F6E4B189F27744EAD8C5173 - -# prompt.json tgId:6, tcid:51, expectedResults.json tcId:51 srtpKa -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:CF08F8159FCF18DA8108A3FE3B707C2B -Ctrl.hexsalt = hexsalt:4AF8352708E0A164C6645A63E5BB -Ctrl.kdr = kdr:8 -Ctrl.index = hexindex:F4EE616415B9 -Ctrl.label = label:1 -Output = F9F246054B3D4AA2520CE2612192749AA6970BB0 - -# prompt.json tgId:6, tcid:51, expectedResults.json tcId:51 srtpKs -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:CF08F8159FCF18DA8108A3FE3B707C2B -Ctrl.hexsalt = hexsalt:4AF8352708E0A164C6645A63E5BB -Ctrl.kdr = kdr:8 -Ctrl.index = hexindex:F4EE616415B9 -Ctrl.label = label:2 -Output = 18EA8EA36A90617224FBFBCB849A - -# prompt.json tgId:6, tcid:51, expectedResults.json tcId:51 srtcpKe -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:CF08F8159FCF18DA8108A3FE3B707C2B -Ctrl.hexsalt = hexsalt:4AF8352708E0A164C6645A63E5BB -Ctrl.kdr = kdr:8 -Ctrl.index = hexindex:13DE080C -Ctrl.label = label:3 -Output = F4140d2419f7A75CEE91FC942CD94514 - -# prompt.json tgId:6, tcid:51, expectedResults.json tcId:51 srtcpKa -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:CF08F8159FCF18DA8108A3FE3B707C2B -Ctrl.hexsalt = hexsalt:4AF8352708E0A164C6645A63E5BB -Ctrl.kdr = kdr:8 -Ctrl.index = hexindex:13DE080C -Ctrl.label = label:4 -Output = 6E65548ABFE131FF91E7AE75409F96AD9D9FE345 - -# prompt.json tgId:6, tcid:51, expectedResults.json tcId:51 srtcpKs -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:CF08F8159FCF18DA8108A3FE3B707C2B -Ctrl.hexsalt = hexsalt:4AF8352708E0A164C6645A63E5BB -Ctrl.kdr = kdr:8 -Ctrl.index = hexindex:13DE080C -Ctrl.label = label:5 -Output = 2C195A5AA9F539BD7CC7D6E23483 - -# internalProjection.json, tgId: 1 -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:A48A570A43E12372BF58495FDFD88D78 -Ctrl.hexsalt = hexsalt:E1D109B42D6C16A8830F9E7DDF4B -Ctrl.index = hexindex:8E5BDF08FA78 -Ctrl.label = label:0 -Output = 30371635BF658204857EC5BFE13AFFE3 - -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:A48A570A43E12372BF58495FDFD88D78 -Ctrl.hexsalt = hexsalt:E1D109B42D6C16A8830F9E7DDF4B -Ctrl.index = hexindex:8E5BDF08FA78 -Ctrl.label = label:1 -Output = 83E0821E1DDBD044C2DD3A980BB445875F97B4D5 - -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:A48A570A43E12372BF58495FDFD88D78 -Ctrl.hexsalt = hexsalt:E1D109B42D6C16A8830F9E7DDF4B -Ctrl.index = hexindex:8E5BDF08FA78 -Ctrl.label = label:2 -Output = B27816A7A139D73E71A55FCD7006 - -# The following tests are copies of one of the above tests with -# invalid sizes for different inputs. - -# Test index size too small for label 0 (SRTP) -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:8C307F105F79D5D2C26B1A933AE22CD5 -Ctrl.hexsalt = hexsalt:563B4C15458D977B68080242CEE1 -Ctrl.kdr = kdr:1 -Ctrl.index = hexindex:08284B49F5 -Ctrl.label = label:0 -Output = A920DF50EAA111D03FBE9B203121C07D -Result = KDF_DERIVE_ERROR -Reason = invalid index length - -# Test index size too small for label 4 (SRTCP) -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:8C307F105F79D5D2C26B1A933AE22CD5 -Ctrl.hexsalt = hexsalt:563B4C15458D977B68080242CEE1 -Ctrl.kdr = kdr:1 -Ctrl.index = hexindex:69B621 -Ctrl.label = label:4 -Output = FA02251D693645BC1001f83C5A13CB3E3D77F7EA -Result = KDF_DERIVE_ERROR -Reason = invalid index length - -# Test salt size is too small -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:8C307F105F79D5D2C26B1A933AE22CD5 -Ctrl.hexsalt = hexsalt:563B -Ctrl.kdr = kdr:1 -Ctrl.index = hexindex:69B62109 -Ctrl.label = label:4 -Output = FA02251D693645BC1001f83C5A13CB3E3D77F7EA -Result = KDF_CTRL_ERROR -Reason = invalid salt length - -# Test invalid key size fails -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:8C307F -Ctrl.hexsalt = hexsalt:563B4C15458D977B68080242CEE1 -Ctrl.kdr = kdr:1 -Ctrl.index = hexindex:69B62109 -Ctrl.label = label:4 -Output = FA02251D693645BC1001f83C5A13CB3E3D77F7EA -Result = KDF_CTRL_ERROR -Reason = invalid key length - -# Test Case 1.3, variation, zero length index -FIPSversion = >=4.0.0 -KDF = SRTPKDF -Ctrl.cipher = cipher:AES-128-CTR -Ctrl.hexkey = hexkey:E1F97A0D3E018BE0D64FA32C06DE4139 -Ctrl.hexsalt = hexsalt:0EC675AD498AFEEBB6960B3AABE6 -Ctrl.index = hexindex: -Ctrl.kdr = kdr:1 -Ctrl.label = label:0 -Output = C61E7A93744F39EE10734AFE3FF7A087 diff --git a/test/recipes/30-test_evp_data/evpmd_sha.txt b/test/recipes/30-test_evp_data/evpmd_sha.txt index f91ddb71bf..b3b95ed76b 100644 --- a/test/recipes/30-test_evp_data/evpmd_sha.txt +++ b/test/recipes/30-test_evp_data/evpmd_sha.txt @@ -1,5 +1,5 @@ # -# Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2001-2023 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -384,94 +384,7 @@ Digest = KECCAK-512 Input = 4FBDC596508D24A2A0010E140980B809FB9C6D55EC75125891DD985D37665BD80F9BEB6A50207588ABF3CEEE8C77CD8A5AD48A9E0AA074ED388738362496D2FB2C87543BB3349EA64997CE3E7B424EA92D122F57DBB0855A803058437FE08AFB0C8B5E7179B9044BBF4D81A7163B3139E30888B536B0F957EFF99A7162F4CA5AA756A4A982DFADBF31EF255083C4B5C6C1B99A107D7D3AFFFDB89147C2CC4C9A2643F478E5E2D393AEA37B4C7CB4B5E97DADCF16B6B50AAE0F3B549ECE47746DB6CE6F67DD4406CD4E75595D5103D13F9DFA79372924D328F8DD1FCBEB5A8E2E8BF4C76DE08E3FC46AA021F989C49329C7ACAC5A688556D7BCBCB2A5D4BE69D3284E9C40EC4838EE8592120CE20A0B635ECADAA84FD5690509F54F77E35A417C584648BC9839B974E07BFAB0038E90295D0B13902530A830D1C2BDD53F1F9C9FAED43CA4EED0A8DD761BC7EDBDDA28A287C60CD42AF5F9C758E5C7250231C09A582563689AFC65E2B79A7A2B68200667752E9101746F03184E2399E4ED8835CB8E9AE90E296AF220AE234259FE0BD0BCC60F7A4A5FF3F70C5ED4DE9C8C519A10E962F673C82C5E9351786A8A3BFD570031857BD4C87F4FCA31ED4D50E14F2107DA02CB5058700B74EA241A8B41D78461658F1B2B90BFD84A4C2C9D6543861AB3C56451757DCFB9BA60333488DBDD02D601B41AAE317CA7474EB6E6DD Output = DEA56BDABBC6D24183CF7BDE1E1F78631B2B0230C76FF2F43075F2FDE77CF052769276CAD98DA62394EC62D77730F5761489585E093EA7315F3592717C485C84 -# Test vectors from https://csrc.nist.gov/CSRC/media/Projects/Cryptographic-Standards-and-Guidelines/documents/examples/cSHAKE_samples.pdf -FIPSversion = >=4.0.0 -Digest = CSHAKE-128 -Input = 00010203 -Output = C1C36925B6409A04F1B504FCBCA9D82B4017277CB5ED2B2065FC1D3814D5AAF5 -Ctrl = function-name: -Ctrl = customization:Email Signature -FIPSversion = >=4.0.0 -Digest = CSHAKE-128 -Input = 000102030405060708090A0B0C0D0E0F101112131415161718191A1B1C1D1E1F202122232425262728292A2B2C2D2E2F303132333435363738393A3B3C3D3E3F404142434445464748494A4B4C4D4E4F505152535455565758595A5B5C5D5E5F606162636465666768696A6B6C6D6E6F707172737475767778797A7B7C7D7E7F808182838485868788898A8B8C8D8E8F909192939495969798999A9B9C9D9E9FA0A1A2A3A4A5A6A7A8A9AAABACADAEAFB0B1B2B3B4B5B6B7B8B9BABBBCBDBEBFC0C1C2C3C4C5C6C7 -Output = C5221D50E4F822D96A2E8881A961420F294B7B24FE3D2094BAED2C6524CC166B -Ctrl = customization:Email Signature - -FIPSversion = >=4.0.0 -Digest = CSHAKE-256 -Input = 00010203 -Output = D008828E2B80AC9D2218FFEE1D070C48B8E4C87BFF32C9699D5B6896EEE0EDD164020E2BE0560858D9C00C037E34A96937C561A74C412BB4C746469527281C8C -Ctrl = customization:Email Signature - -FIPSversion = >=4.0.0 -Digest = CSHAKE-256 -Input = 000102030405060708090A0B0C0D0E0F101112131415161718191A1B1C1D1E1F202122232425262728292A2B2C2D2E2F303132333435363738393A3B3C3D3E3F404142434445464748494A4B4C4D4E4F505152535455565758595A5B5C5D5E5F606162636465666768696A6B6C6D6E6F707172737475767778797A7B7C7D7E7F808182838485868788898A8B8C8D8E8F909192939495969798999A9B9C9D9E9FA0A1A2A3A4A5A6A7A8A9AAABACADAEAFB0B1B2B3B4B5B6B7B8B9BABBBCBDBEBFC0C1C2C3C4C5C6C7 -Output = 07DC27B11E51FBAC75BC7B3C1D983E8B4B85FB1DEFAF218912AC86430273091727F42B17ED1DF63E8EC118F04B23633C1DFB1574C8FB55CB45DA8E25AFB092BB -Ctrl = function-name: -Ctrl = customization:Email Signature - -# These are SHAKE test vectors from (i.e where n = s = empty string) -FIPSversion = >=4.0.0 -Digest = CSHAKE128 -Input = 49d81708d86cd59dea0ac2c1017a9712d6dffb754dde0b57a9023a39fc5f5b6be276fc176f59f6826610428fac3a0e85fcf71011db061b8fcf2bf085ccd45670effb6dc46f4e3f2ed08e981c5935187fc95b86cf46da675096b1cf9591a67842d6301116be93d8288e4d6b70f1b1db8aa5d203b774a21825665b8170351ee86801da91154570eaf80a1564945af7822df8232fd04ea65593a7f2ab1e9e84cf6ad6c494c9ec2d9d27aaad2b8f7e4f33f12a17b422bc2d4724c13ff8a8b62054d1bfb5c33b9c11183cd8df67694300165ca37637b5a781155f1c070d156339a0242374c6723b6584bffb71c02b935455f8cb086392f5e8e8cc2015956d8f19daeb6aca4476b27108387a2ce0dc5591154d0b94ddc090abe8f4363036b821062baffb7fe550ea7dcd30bfd86c84710081e1c9e450475e123c5ec41f98ff0149bbf6405b5207cad1fb2f313d0f2bcee9be3f6ebe623049640d9234ab644a172ab14ba02633a339b5b9bb38226fda5694f7ec63ebbb8238eb8219ec9c429f4bf0353383a72f2d21702f5e3c513499f04852710f33044512edc47a56bad90885e5713851a7efac694b869fa590076e844ff757d95de581c1b3fa3dd8ccd28cad4f8ae173ee1b28f98ee606dca89063fbef0f262b33053f2c854debdc9cd433ab77abb64f445aa9b981761c4761767f3b71c2646c7b0d873baae50bc9f0 -Output = c609be05458f7ab33e7b6b54bc6e8999 - -FIPSversion = >=4.0.0 -Digest = CSHAKE256 -Input = dc5a100fa16df1583c79722a0d72833d3bf22c109b8889dbd35213c6bfce205813edae3242695cfd9f59b9a1c203c1b72ef1a5423147cb990b5316a85266675894e2644c3f9578cebe451a09e58c53788fe77a9e850943f8a275f830354b0593a762bac55e984db3e0661eca3cb83f67a6fb348e6177f7dee2df40c4322602f094953905681be3954fe44c4c902c8f6bba565a788b38f13411ba76ce0f9f6756a2a2687424c5435a51e62df7a8934b6e141f74c6ccf539e3782d22b5955d3baf1ab2cf7b5c3f74ec2f9447344e937957fd7f0bdfec56d5d25f61cde18c0986e244ecf780d6307e313117256948d4230ebb9ea62bb302cfe80d7dfebabc4a51d7687967ed5b416a139e974c005fff507a96 -Output = 2bac5716803a9cda8f9e84365ab0a681327b5ba34fdedfb1c12e6e807f45284b - -FIPSversion = >=4.0.0 -Digest = CSHAKE256 -Input = dc5a100fa16df1583c79722a0d72833d3bf22c109b8889dbd35213c6bfce205813edae3242695cfd9f59b9a1c203c1b72ef1a5423147cb990b5316a85266675894e2644c3f9578cebe451a09e58c53788fe77a9e850943f8a275f830354b0593a762bac55e984db3e0661eca3cb83f67a6fb348e6177f7dee2df40c4322602f094953905681be3954fe44c4c902c8f6bba565a788b38f13411ba76ce0f9f6756a2a2687424c5435a51e62df7a8934b6e141f74c6ccf539e3782d22b5955d3baf1ab2cf7b5c3f74ec2f9447344e937957fd7f0bdfec56d5d25f61cde18c0986e244ecf780d6307e313117256948d4230ebb9ea62bb302cfe80d7dfebabc4a51d7687967ed5b416a139e974c005fff507a96 -Output = 2bac5716803a9cda8f9e84365ab0a681327b5ba34fdedfb1c12e6e807f45284b -Ctrl = function-name: -Ctrl = customization: - -# A test from https://github.com/usnistgov/ACVP-Server/blob/master/gen-val/json-files/cSHAKE-128-1.0/internalProjection.json -# where the encoding of the strings is exactly a multiple of the block size w. i.e. no zero padding is added. -# The output length was modified to be on a byte boundary. -FIPSversion = >=4.0.0 -Digest = CSHAKE-128 -Input = EA18 -Ctrl = customization:fmkctMwhBB[=4.0.0 -Digest = CSHAKE-128 -Input = CA88F708FA -Ctrl = function-name:KMAC -Ctrl = customization:`kiEF`&I))7]yq0?*sKa q)[jP`4R=)lV_9tyvT$kAbH$)1}p].bbeomb. -Output = BEBB534CCFCCD300F731D2911FB4351D5FCC95AC2509E9ABAE8F9DC51106E28D7F25AE11738334 - -FIPSversion = >=4.0.0 -Digest = CSHAKE-256 -Input = 13D101DA -Ctrl = function-name:TupleHash -Ctrl = customization:q8gN}O&V*VDU4Y.^5J13tG2,1^Lw~C2rw $AB3.SX)=@z -Ctrl = properties:?fips=true -Output = 43163A57FC1EE8F1C501A2ADD927698CA5A4B52C0D3EF3FD6D91D8D2386765E0AE - -FIPSversion = >=4.0.0 -Digest = CSHAKE-256 -Input = D5D7E7517F -Ctrl = function-name:ParallelHash -Ctrl = customization:vD-1>T,f.R*V%ZA[ OyJ -Output = 442BE69B2AFD7C8282839920A8446AAF16A5049D3D018EAC87E04CF9225870EFCA6F88DB415829 - -# Test that uses an unknown function name -FIPSversion = >=4.0.0 -Digest = CSHAKE-128 -Input = CA88F708FA -Ctrl = function-name:BadName -Result = DIGESTINIT_ERROR -Reason = invalid function name Title = Case insensitive digest tests @@ -482,3 +395,4 @@ Output = A7FFC6F8BF1ED76651C14756A061D662F580FF4DE43B49FA82D80A4B80F8434A Digest = shA512 Input = "abc" Output = ddaf35a193617abacc417349ae20413112e6fa4e89a97ea20a9eeee64b55d39a2192992a274fc1a836ba3c23a3feebbd454d4423643ce80e2a9ac94fa54ca49f + diff --git a/test/recipes/30-test_evp_data/evppbe_pbkdf2.txt b/test/recipes/30-test_evp_data/evppbe_pbkdf2.txt index d179fc659d..ecf1d25ae5 100644 --- a/test/recipes/30-test_evp_data/evppbe_pbkdf2.txt +++ b/test/recipes/30-test_evp_data/evppbe_pbkdf2.txt @@ -1,5 +1,5 @@ # -# Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2001-2020 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -13,7 +13,6 @@ Title = PBKDF2 tests (using PBE) -Availablein = default PBE = pbkdf2 Password = "password" Salt = "salt" @@ -21,7 +20,6 @@ iter = 1 MD = sha1 Key = 0c60c80f961f0e71f3a9b524af6012062fe037a6 -Availablein = default PBE = pbkdf2 Password = "password" Salt = "salt" @@ -29,17 +27,6 @@ iter = 1 MD = sha256 Key = 120fb6cffcf8b32c43e7225256c4f837a86548c92ccc35480805987cb70be17b -Availablein = fips -PBE = pbkdf2 -Password = "password" -Salt = "salt" -iter = 1 -MD = sha256 -Key = 120fb6cffcf8b32c43e7225256c4f837a86548c92ccc35480805987cb70be17b -Result = PBKDF2_ERROR -Reason = invalid salt length - -Availablein = default PBE = pbkdf2 Password = "password" Salt = "salt" @@ -47,7 +34,6 @@ iter = 1 MD = sha512 Key = 867f70cf1ade02cff3752599a3a53dc4af34c7a669815ae5d513554e1c8cf252c02d470a285a0501bad999bfe943c08f050235d7d68b1da55e63f73b60a57fce -Availablein = default PBE = pbkdf2 Password = "password" Salt = "salt" @@ -55,7 +41,6 @@ iter = 2 MD = sha1 Key = ea6c014dc72d6f8ccd1ed92ace1d41f0d8de8957 -Availablein = default PBE = pbkdf2 Password = "password" Salt = "salt" @@ -63,7 +48,6 @@ iter = 2 MD = sha256 Key = ae4d0c95af6b46d32d0adff928f06dd02a303f8ef3c251dfd6e2d85a95474c43 -Availablein = default PBE = pbkdf2 Password = "password" Salt = "salt" @@ -71,7 +55,6 @@ iter = 2 MD = sha512 Key = e1d9c16aa681708a45f5c7c4e215ceb66e011a2e9f0040713f18aefdb866d53cf76cab2868a39b9f7840edce4fef5a82be67335c77a6068e04112754f27ccf4e -Availablein = default PBE = pbkdf2 Password = "password" Salt = "salt" @@ -79,7 +62,6 @@ iter = 4096 MD = sha1 Key = 4b007901b765489abead49d926f721d065a429c1 -Availablein = default PBE = pbkdf2 Password = "password" Salt = "salt" @@ -87,7 +69,6 @@ iter = 4096 MD = sha256 Key = c5e478d59288c841aa530db6845c4c8d962893a001ce4e11a4963873aa98134a -Availablein = default PBE = pbkdf2 Password = "password" Salt = "salt" @@ -116,7 +97,6 @@ iter = 4096 MD = sha512 Key = 8c0511f4c6e597c6ac6315d8f0362e225f3c501495ba23b868c005174dc4ee71115b59f9e60cd9532fa33e0f75aefe30225c583a186cd82bd4daea9724a3d3b8 -Availablein = default PBE = pbkdf2 Password = 7061737300776f7264 Salt = 7361006c74 @@ -124,7 +104,6 @@ iter = 4096 MD = sha1 Key = 56fa6aa75548099dcc37d7f03425e0c3 -Availablein = default PBE = pbkdf2 Password = 7061737300776f7264 Salt = 7361006c74 @@ -132,7 +111,6 @@ iter = 4096 MD = sha256 Key = 89b69d0516f829893c696226650a8687 -Availablein = default PBE = pbkdf2 Password = 7061737300776f7264 Salt = 7361006c74 @@ -140,7 +118,6 @@ iter = 4096 MD = sha512 Key = 9d9e9c4cd21fe4be24d5b8244c759665 -Availablein = default PBE = pbkdf2 Password = "password" Salt = "salt" @@ -148,7 +125,6 @@ iter = 4096 MD = sha3-224 Key = 691292bc3683d7d41ea2910f5b3eed23 -Availablein = default PBE = pbkdf2 Password = "password" Salt = "salt" @@ -156,7 +132,6 @@ iter = 4096 MD = sha3-256 Key = 778b6e237a0f49621549ff70d218d208 -Availablein = default PBE = pbkdf2 Password = "password" Salt = "salt" @@ -164,7 +139,6 @@ iter = 4096 MD = sha3-384 Key = 9a5f1e45e8b83f1b259ba72d11c59087 -Availablein = default PBE = pbkdf2 Password = "password" Salt = "salt" @@ -174,7 +148,6 @@ Key = 2bfaf2d5ceb6d10f5e262cd902488cfd Title = PBKDF2 tests for empty and NULL inputs -Availablein = default PBE = pbkdf2 Password = "" Salt = "salt" @@ -182,7 +155,6 @@ iter = 1 MD = sha1 Key = a33dddc30478185515311f8752895d36ea4363a2 -Availablein = default PBE = pbkdf2 Password = "" Salt = "salt" @@ -190,7 +162,6 @@ iter = 1 MD = sha256 Key = f135c27993baf98773c5cdb40a5706ce6a345cde -Availablein = default PBE = pbkdf2 Password = "" Salt = "salt" @@ -198,7 +169,6 @@ iter = 1 MD = sha512 Key = 00ef42cdbfc98d29db20976608e455567fdddf14 -Availablein = default PBE = pbkdf2 Password = NULL Salt = "salt" @@ -206,7 +176,6 @@ iter = 1 MD = sha1 Key = a33dddc30478185515311f8752895d36ea4363a2 -Availablein = default PBE = pbkdf2 Password = NULL Salt = "salt" @@ -214,7 +183,6 @@ iter = 1 MD = sha256 Key = f135c27993baf98773c5cdb40a5706ce6a345cde -Availablein = default PBE = pbkdf2 Password = NULL Salt = "salt" diff --git a/test/recipes/30-test_evp_data/evppkey_ecdsa_sigalg.txt b/test/recipes/30-test_evp_data/evppkey_ecdsa_sigalg.txt index 5faaca452f..7c339c272b 100644 --- a/test/recipes/30-test_evp_data/evppkey_ecdsa_sigalg.txt +++ b/test/recipes/30-test_evp_data/evppkey_ecdsa_sigalg.txt @@ -92,7 +92,7 @@ Output = 3045022100b1d1cb1a577035bccdd5a86c6148c2cc7c633cd42b7234139b593076d041e Title = Sign-Message and Verify-Message FIPSversion = >=3.4.0 -Verify-Message-Public = ECDSA-SHA256:P-256-PUBLIC +Verify-Message = ECDSA-SHA256:P-256-PUBLIC Input = "Hello World" Output = 3046022100e7515177ec3817b77a4a94066ab3070817b7aa9d44a8a09f040da250116e8972022100ba59b0f631258e59a9026be5d84f60685f4cf22b9165a0c2736d5c21c8ec1862 @@ -104,13 +104,13 @@ twD8guGxyFRaoMDTtW47/nifwYqRaIfC -----END PUBLIC KEY----- FIPSversion = >=3.4.0 -Verify-Message-Public = ECDSA-SHA384:P-384-PUBLIC +Verify-Message = ECDSA-SHA384:P-384-PUBLIC Input = "123400" Output = 304d0218389cb27e0bc8d21fa7e5f24cb74f58851313e696333ad68b023100ffffffffffffffffffffffffffffffffffffffffffffffffc7634d81f4372ddf581a0db248b0a77aecec196accc52970 # Oneshot tests FIPSversion = >=3.4.0 -Verify-Message-Public = ECDSA-SHA256:P-256-PUBLIC +Verify-Message = ECDSA-SHA256:P-256-PUBLIC Input = "Hello World" Output = 3046022100e7515177ec3817b77a4a94066ab3070817b7aa9d44a8a09f040da250116e8972022100ba59b0f631258e59a9026be5d84f60685f4cf22b9165a0c2736d5c21c8ec1862 @@ -220,6 +220,13 @@ Securitycheck = 1 Input = "0123456789ABCDEF1234" Result = KEYOP_INIT_ERROR +# Invalid non-approved digest +Availablein = fips +FIPSversion = >=3.4.0 +Verify-Message = ECDSA-MD5:P-256-PUBLIC +Securitycheck = 1 +Result = KEYOP_INIT_ERROR + Title = FIPS Indicator tests # Check that the indicator callback is triggered # We check for signature mismatch since the signature is unique diff --git a/test/recipes/30-test_evp_data/evppkey_ecx_sigalg.txt b/test/recipes/30-test_evp_data/evppkey_ecx_sigalg.txt index ca959d01c6..88a839948c 100644 --- a/test/recipes/30-test_evp_data/evppkey_ecx_sigalg.txt +++ b/test/recipes/30-test_evp_data/evppkey_ecx_sigalg.txt @@ -115,20 +115,20 @@ Output = dc2a4459e7369633a52b1bf277839a00201009a3efbf3ecb69bea2186c26b58909351fc # Verify test FIPSversion = >=3.4.0 -Verify-Message-Public = ED25519:ED25519-1-PUBLIC +Verify-Message = ED25519:ED25519-1-PUBLIC Input = "" Output = e5564300c360ac729086e2cc806e828a84877f1eb8e5d974d873e065224901555fb8821590a33bacc61e39701cf9b46bd25bf5f0595bbe24655141438e7a100b # Corrupted input FIPSversion = >=3.4.0 -Verify-Message-Public = ED25519:ED25519-1-PUBLIC +Verify-Message = ED25519:ED25519-1-PUBLIC Input = "bad" Output = e5564300c360ac729086e2cc806e828a84877f1eb8e5d974d873e065224901555fb8821590a33bacc61e39701cf9b46bd25bf5f0595bbe24655141438e7a100b Result = VERIFY_ERROR # Corrupted signature FIPSversion = >=3.4.0 -Verify-Message-Public = ED25519:ED25519-1-PUBLIC +Verify-Message = ED25519:ED25519-1-PUBLIC Input = "" Output = e5564300c360ac729086e2cc806e828a84877f1eb8e5d974d873e065224901555fb8821590a33bacc61e39701cf9b46bd25bf5f0595bbe24655141438e7a100c Result = VERIFY_ERROR @@ -144,14 +144,14 @@ Input = "" Output = e5564300c360ac729086e2cc806e828a84877f1eb8e5d974d873e065224901555fb8821590a33bacc61e39701cf9b46bd25bf5f0595bbe24655141438e7a100b FIPSversion = >=3.4.0 -Verify-Message-Public = ED25519:ED25519-1-PUBLIC-Raw +Verify-Message = ED25519:ED25519-1-PUBLIC-Raw Input = "" Output = e5564300c360ac729086e2cc806e828a84877f1eb8e5d974d873e065224901555fb8821590a33bacc61e39701cf9b46bd25bf5f0595bbe24655141438e7a100b #Signature maleability test. #Same as the verify operation above but with the order added to s FIPSversion = >=3.4.0 -Verify-Message-Public = ED25519:ED25519-1-PUBLIC-Raw +Verify-Message = ED25519:ED25519-1-PUBLIC-Raw Input = "" Output = e5564300c360ac729086e2cc806e828a84877f1eb8e5d974d873e065224901554c8c7872aa064e049dbb3013fbf29380d25bf5f0595bbe24655141438e7a101b Result = VERIFY_ERROR @@ -325,20 +325,20 @@ Output = e301345a41a39a4d72fff8df69c98075a0cc082b802fc9b2b6bc503f926b65bddf7f4c8 # Verify test FIPSversion = >=3.4.0 -Verify-Message-Public = ED448:ED448-1-PUBLIC +Verify-Message = ED448:ED448-1-PUBLIC Input = "" Output = 533a37f6bbe457251f023c0d88f976ae2dfb504a843e34d2074fd823d41a591f2b233f034f628281f2fd7a22ddd47d7828c59bd0a21bfd3980ff0d2028d4b18a9df63e006c5d1c2d345b925d8dc00b4104852db99ac5c7cdda8530a113a0f4dbb61149f05a7363268c71d95808ff2e652600 # Corrupted input FIPSversion = >=3.4.0 -Verify-Message-Public = ED448:ED448-1-PUBLIC +Verify-Message = ED448:ED448-1-PUBLIC Input = "bad" Output = 533a37f6bbe457251f023c0d88f976ae2dfb504a843e34d2074fd823d41a591f2b233f034f628281f2fd7a22ddd47d7828c59bd0a21bfd3980ff0d2028d4b18a9df63e006c5d1c2d345b925d8dc00b4104852db99ac5c7cdda8530a113a0f4dbb61149f05a7363268c71d95808ff2e652600 Result = VERIFY_ERROR # Corrupted signature FIPSversion = >=3.4.0 -Verify-Message-Public = ED448:ED448-1-PUBLIC +Verify-Message = ED448:ED448-1-PUBLIC Input = "" Output = 533a37f6bbe457251f023c0d88f976ae2dfb504a843e34d2074fd823d41a591f2b233f034f628281f2fd7a22ddd47d7828c59bd0a21bfd3980ff0d2028d4b18a9df63e006c5d1c2d345b925d8dc00b4104852db99ac5c7cdda8530a113a0f4dbb61149f05a7363268c71d95808ff2e652601 Result = VERIFY_ERROR @@ -350,14 +350,14 @@ Input = "" Output = 533a37f6bbe457251f023c0d88f976ae2dfb504a843e34d2074fd823d41a591f2b233f034f628281f2fd7a22ddd47d7828c59bd0a21bfd3980ff0d2028d4b18a9df63e006c5d1c2d345b925d8dc00b4104852db99ac5c7cdda8530a113a0f4dbb61149f05a7363268c71d95808ff2e652600 FIPSversion = >=3.4.0 -Verify-Message-Public = ED448:ED448-1-PUBLIC-Raw +Verify-Message = ED448:ED448-1-PUBLIC-Raw Input = "" Output = 533a37f6bbe457251f023c0d88f976ae2dfb504a843e34d2074fd823d41a591f2b233f034f628281f2fd7a22ddd47d7828c59bd0a21bfd3980ff0d2028d4b18a9df63e006c5d1c2d345b925d8dc00b4104852db99ac5c7cdda8530a113a0f4dbb61149f05a7363268c71d95808ff2e652600 #Signature malelability test. #Same as the verify operation above but with the order added to s FIPSversion = >=3.4.0 -Verify-Message-Public = ED448:ED448-1-PUBLIC-Raw +Verify-Message = ED448:ED448-1-PUBLIC-Raw Input = "" Output = 533a37f6bbe457251f023c0d88f976ae2dfb504a843e34d2074fd823d41a591f2b233f034f628281f2fd7a22ddd47d7828c59bd0a21bfd3980f25278d3667403c14bcec5f9cfde9955ebc8333c0ae78fc86e518317c5c7cdda8530a113a0f4dbb61149f05a7363268c71d95808ff2e656600 Result = VERIFY_ERROR diff --git a/test/recipes/30-test_evp_data/evppkey_ffdhe.txt b/test/recipes/30-test_evp_data/evppkey_ffdhe.txt index f15c23e5de..dd4dac63b6 100644 --- a/test/recipes/30-test_evp_data/evppkey_ffdhe.txt +++ b/test/recipes/30-test_evp_data/evppkey_ffdhe.txt @@ -1,5 +1,5 @@ # -# Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2001-2024 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -93,6 +93,29 @@ PeerKey=ffdhe2048-2-pub Ctrl = dh_pad:1 SharedSecret=00006620DD85B56EE8540C8040CAC46B7385344A164E4DBDF521F7D99F88FA68EDD295A45E36E0BBD5FF5DE84598824E2CA52ED82ACA918CAECC6B22846D0FC6F0203E8B6963964D11E9E704F83AF1D60E9B1931139E9E9967C4665A831A75D99359A8BA80DD5921E74379AF4CA8DB453EDBC5E669AB17A5254CA6C96794CD5196BE90AF37742C8F6812515FFCC45B08F4158EFF9559F1AEF3665B3D91519DCBC6DF22CD6DA521B86613558602E73D2CA4666972F7D2CB6B46299B1DF2DA29A2A2D99D105E10CB553D6738A9B1DB2A0314C3CF30642D5C44695623D8B95C4426BEA830FB51816B4F086945E9B12A445F42DD68610E3F378A6E69A383D13D85BF +# The following two testcases check that the padding is implicitly enabled +# with X942KDF-ASN1 KDF. +# The plain shared secret for these keys needs padding as seen above. +Derive=ffdhe2048-1 +PeerKey=ffdhe2048-2-pub +Ctrl = kdf-type:X942KDF-ASN1 +Ctrl = kdf-outlen:32 +Ctrl = kdf-digest:SHA-256 +Ctrl = cekalg:AES-128-WRAP +Ctrl = dh_pad:1 +SharedSecret=89A249DF4EE9033B89C2B4E52072A736D94F51143A1ED5C8F1E91FCBEBE09654 + +# FIPS(3.0.0): allows the padding to be set, later versions do not #17859 +FIPSversion = >3.0.0 +Derive=ffdhe2048-2 +PeerKey=ffdhe2048-1-pub +Ctrl = kdf-type:X942KDF-ASN1 +Ctrl = kdf-outlen:32 +Ctrl = kdf-digest:SHA-256 +Ctrl = cekalg:AES-128-WRAP +Ctrl = dh_pad:0 +SharedSecret=89A249DF4EE9033B89C2B4E52072A736D94F51143A1ED5C8F1E91FCBEBE09654 + PrivateKey=ffdhe3072-1 -----BEGIN PRIVATE KEY----- MIIByQIBADCCAZsGCSqGSIb3DQEDATCCAYwCggGBAP//////////rfhUWKK7Spqv diff --git a/test/recipes/30-test_evp_data/evppkey_ffdhe_x942kdf.txt b/test/recipes/30-test_evp_data/evppkey_ffdhe_x942kdf.txt deleted file mode 100644 index 8da2aa530d..0000000000 --- a/test/recipes/30-test_evp_data/evppkey_ffdhe_x942kdf.txt +++ /dev/null @@ -1,97 +0,0 @@ -# -# Copyright 2001-2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -# Tests start with one of these keywords -# Cipher Decrypt Derive Digest Encoding KDF MAC PBE -# PrivPubKeyPair Sign Verify VerifyRecover -# and continue until a blank line. Lines starting with a pound sign are ignored. - - -# ffdhe2048-1 and ffdhe2048-2 were randomly generated and have a shared secret -# less than 256 bytes in length (to test padding) other keys have no special -# properties -PrivateKey=ffdhe2048-1 ------BEGIN PRIVATE KEY----- -MIIBQwIBADCCARsGCSqGSIb3DQEDATCCAQwCggEBAP//////////rfhUWKK7Spqv -3FYgJz088di5xYPOLTaVqeE2QRRkM/vMk53OJJs++X0v42NjDHXY9oGyAq7EYXrT -3x7V1f1lYSQz9R9fBm7QhWNlVT3tGvO1VxNef1fJNZhPDHDg5ot34qaJ2vPv6HId -8VihNq3nNTCsyk9IOnl6vAqxgrMk+2HRCKlLssjj+7lq2rdg1/RoHU9Co945TfSu -Vu3nY3K7GQsHp8juCm1wngL84c334uzANATNKDQvYZFy/pzphYP/jk8SMu7ygYPD -/jsbTG+tczu1/LwuwiAFxY7xg30Wg7LG80omwbLv+ohrQjhhKFyX//////////8C -AQICAgDhBB8CHQGUa5iGUF9rGvDjv9PDFGIvtS9OIqbbi8rqm4b6 ------END PRIVATE KEY----- - -PrivateKey=ffdhe2048-2 ------BEGIN PRIVATE KEY----- -MIIBQwIBADCCARsGCSqGSIb3DQEDATCCAQwCggEBAP//////////rfhUWKK7Spqv -3FYgJz088di5xYPOLTaVqeE2QRRkM/vMk53OJJs++X0v42NjDHXY9oGyAq7EYXrT -3x7V1f1lYSQz9R9fBm7QhWNlVT3tGvO1VxNef1fJNZhPDHDg5ot34qaJ2vPv6HId -8VihNq3nNTCsyk9IOnl6vAqxgrMk+2HRCKlLssjj+7lq2rdg1/RoHU9Co945TfSu -Vu3nY3K7GQsHp8juCm1wngL84c334uzANATNKDQvYZFy/pzphYP/jk8SMu7ygYPD -/jsbTG+tczu1/LwuwiAFxY7xg30Wg7LG80omwbLv+ohrQjhhKFyX//////////8C -AQICAgDhBB8CHQEYNZIth+/EaIgKK2gcxFutVjUTWYCaReyTKMvP ------END PRIVATE KEY----- - -PublicKey=ffdhe2048-1-pub ------BEGIN PUBLIC KEY----- -MIICKTCCARsGCSqGSIb3DQEDATCCAQwCggEBAP//////////rfhUWKK7Spqv3FYg -Jz088di5xYPOLTaVqeE2QRRkM/vMk53OJJs++X0v42NjDHXY9oGyAq7EYXrT3x7V -1f1lYSQz9R9fBm7QhWNlVT3tGvO1VxNef1fJNZhPDHDg5ot34qaJ2vPv6HId8Vih -Nq3nNTCsyk9IOnl6vAqxgrMk+2HRCKlLssjj+7lq2rdg1/RoHU9Co945TfSuVu3n -Y3K7GQsHp8juCm1wngL84c334uzANATNKDQvYZFy/pzphYP/jk8SMu7ygYPD/jsb -TG+tczu1/LwuwiAFxY7xg30Wg7LG80omwbLv+ohrQjhhKFyX//////////8CAQIC -AgDhA4IBBgACggEBAOYRygvHGUKaIXLfUatc2YkYcm9Ew65H0hwpiDXG6XHAYAjJ -bjKNJxdFRjjeCwtJEAGlyUtjSHrka6dHDfzkQfDK6u13Z+3Xmh+nCMZwPOHDNR3I -Ep5vy3quU7suD3ADDrjwX3sVfsXensgh+JpexbrR+leHATf8aX1g8jQofFdi1Wn7 -CbE6VciU4b32L8HPwO1ePpJGib70Em45VurmUfCwNXgEUnu1N6LYRAjH9vnjB529 -C3BSp58rJnA2aslacC0CFY6YVCQfLTdN7y+F5QlGrdGd6wQmf3FXPLf9iYSiuLrm -jW/WDFmPnwAn5A7TEgiNeNu8pwsSKPgZqdW+lyw= ------END PUBLIC KEY----- - -PublicKey=ffdhe2048-2-pub ------BEGIN PUBLIC KEY----- -MIICKTCCARsGCSqGSIb3DQEDATCCAQwCggEBAP//////////rfhUWKK7Spqv3FYg -Jz088di5xYPOLTaVqeE2QRRkM/vMk53OJJs++X0v42NjDHXY9oGyAq7EYXrT3x7V -1f1lYSQz9R9fBm7QhWNlVT3tGvO1VxNef1fJNZhPDHDg5ot34qaJ2vPv6HId8Vih -Nq3nNTCsyk9IOnl6vAqxgrMk+2HRCKlLssjj+7lq2rdg1/RoHU9Co945TfSuVu3n -Y3K7GQsHp8juCm1wngL84c334uzANATNKDQvYZFy/pzphYP/jk8SMu7ygYPD/jsb -TG+tczu1/LwuwiAFxY7xg30Wg7LG80omwbLv+ohrQjhhKFyX//////////8CAQIC -AgDhA4IBBgACggEBAN5LAdrzTwa7nT7855NJQLNum5Yr1O8XZupjvwtVIrJgORvh -L8VMKJoerEwOZ38snTsh9tuKnAWrmdIyFhnOjaHm40GlvInQGff5Lwb1itf7ib3U -ELPOO29PajwY1RocWKX7Wfdj8n6Kd9gHhdoO5v8MyZMCkUU6Rz6y1VzaVwykdsqA -kbMdZfK8Dkpd5PBZ8SJpJF02IEzvh5OYfjcbMN2K0lDO5ZvoMYQku7yXr6PfJebC -CpoVOaoqH19n3g8Xni8IFi7znI83UqxKuYhyYCuMwtE+HS+9WkmkQ1coo512Gw2f -TcY3pf9gGZ41xLFxCOdrUbR3QlieI+zl+TttLzM= ------END PUBLIC KEY----- - -PrivPubKeyPair=ffdhe2048-1:ffdhe2048-1-pub - -PrivPubKeyPair=ffdhe2048-2:ffdhe2048-2-pub - -# The following two testcases check that the padding is implicitly enabled -# with X942KDF-ASN1 KDF. -# The plain shared secret for these keys needs padding as seen above. -Derive=ffdhe2048-1 -PeerKey=ffdhe2048-2-pub -Ctrl = kdf-type:X942KDF-ASN1 -Ctrl = kdf-outlen:32 -Ctrl = kdf-digest:SHA-256 -Ctrl = cekalg:AES-128-WRAP -Ctrl = dh_pad:1 -SharedSecret=89A249DF4EE9033B89C2B4E52072A736D94F51143A1ED5C8F1E91FCBEBE09654 - -# FIPS(3.0.0): allows the padding to be set, later versions do not #17859 -FIPSversion = >3.0.0 -Derive=ffdhe2048-2 -PeerKey=ffdhe2048-1-pub -Ctrl = kdf-type:X942KDF-ASN1 -Ctrl = kdf-outlen:32 -Ctrl = kdf-digest:SHA-256 -Ctrl = cekalg:AES-128-WRAP -Ctrl = dh_pad:0 -SharedSecret=89A249DF4EE9033B89C2B4E52072A736D94F51143A1ED5C8F1E91FCBEBE09654 diff --git a/test/recipes/30-test_evp_data/evppkey_ml_dsa_siggen.txt b/test/recipes/30-test_evp_data/evppkey_ml_dsa_siggen.txt index 7dd64ace2e..b05a764a16 100644 --- a/test/recipes/30-test_evp_data/evppkey_ml_dsa_siggen.txt +++ b/test/recipes/30-test_evp_data/evppkey_ml_dsa_siggen.txt @@ -1,4 +1,4 @@ -# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -1967,34 +1967,3 @@ Ctrl = message-encoding:1 Ctrl = mu:1 Ctrl = deterministic:0 Ctrl = hextest-entropy:3FD850EC10DC8555D77B36ED6FB9BC599D1FB4044B214FB4171570865A0A0E07 - -# ML-DSA test using external mu with no context (Using data from ML_DSA_87_345) -FIPSversion = >=4.0.0 -FIPSversion = >=3.5.0 -Sign-Message = ML-DSA-44:ML_DSA_44_8 -Input = F0A4A18CCF982E891F3E917327901F738390E17AB95FF1FB7C76835038889F73AF0D244976DB622194FADA41149E534ACD96B92338529814EE186832B9C383F980A5117BDBED093DB31ACD5273DF13E5A83D14BB821F18C188FF368019163C614C4D202783FC88E2523C425114211425988148F525D047A0CD957763CF5B79F66BE1738704AC66F133398BC9C0E557006306DB920CA843C0D524D4EAEDBC1BDE0503376B22772B7414559D68901CC5A1806520EB397FFAA24D96FF2F207B47D1A21CE68687D76583F21511074B9056D454F565358DBEFAEC8ABE4388FB1D8A255DE8F9E7F11A96E69AADA9346C8461901EFA4DAAA1A4BA9B04D8A11EBD00319B4A7D8BAC2174CFA2A006D94859FEC52BDC01882CB9D4A3E8951A5CC1BD36EC74F6033331B03E92A727077F448D4FB5609A5E55AA75289F7DAF3BEAB31CF7AA1F4B66980F5F5F8A31ACFE55585252247FCD78B9675638DB8E1292913A6F3EA57C60D197B1CF83D853C6ABE350B7B11040765AF1C1740AF1E318689237B350DD8F4F0C0A63939ADABF392D71471BF3F7A5CA448A4DCDF4896A342B4BA942128137F3FF44AE57DB8500A7BFB6FD74250E6312D54A3588D08E93BA623E189B817EEF2BE66D2A57097B147A131D5C8843CC7343E62BC002AD1E60299BB7D2F0FF14C51B3E414198524A3D964CE2A631B72F71342E17AF47992E6C27067CA14711615CB94F14B7B501A15B967259301A4566A63DFEE3515CCD142FF5F6423AADE0B0EF7CFCEB975E6C70187F737D5BC8236369402A82F701DD59A5E67223261921CF13CE22547DAFA7D0BFF6E52FB572FBA1191C5C5B7DF47E12D0799A3F2E2B67FDAE29F056693D7FC59CA8767613AED34026A04F8D17D0F803248C91FC744378356DF8DD88B2214269AA732B76F7A39E62760F82A761D4F68CB2A378ABA62A39C81E6E1AB211494FA848B1620D5DABA69D383826AE0B97A487ABEFD202CA8A1B0C8188219E40D69A9DBE8E3E065BA17B84A54236C137BB51400C5A89ABE70E3787B7BEAFD9304CDF6EFA5D695CD7B0E2349AB9110111D3CB306151EA204594FB28EB15B63ED5163EB744479402ECB291F77BCE40E236229C6EFC84EF6E0323B68F60560F68A75D03DA9C4724AE41C7B551C0EE44FB235B7EFA7E5D9BD8F1DBFE68F6D6CAA10452E5BFCA633DB41D1BCC975DE04A028BAC652AF714BA8C1CCD3EDAFC41C90D5F13320AF0CFA88885760E39EAB8A62FB5FBA9BFE329B5365CD68F72ECC32B2C55B650040FFFFE346C4954AD4A1762AB402A9E286D1EC4AF18410AEF0414D2DA2359514D64E65A532316DEA8D9CD7866C59386BE9E4F85A604B4EB6953214B4BF12E7BC37E283FC7E93C77F3C5C86303AB5D10505FC3089F1CCF75A3AE43909B09A3703DD124C4D6E4E681A6EEA2757A5799ADE4BC55EE616B4CE743FE24AD6BE365953B42BB9D5942CDA54E2574EC041373C85BAE74009FDEB3F96E7D07A48934A61BDAA788ED20F55B58BDF4CD1564BB644AA2AEE211FE403CC330DB92B49A8B9A1C3AD9A7695D16763EC07241DCA2E4D50132A12F2450E1F48110E60496331CCBFFD070F93ABC97ECD2D233F3F2C24DAA3571C6D1658B6B8C341363004AE84871B36503294D1947C70307BB8FDD1507E51130ECDEA5CF3002FABE1281839AF48D611108FAA75EDB21506CA0968D654B4694E69B3E75AA83BB5FAB88283B9733A49D48F5295C9BCCAC6E6288288B90AD82E74E18B73F91D6573A6496730B4A84D9952C263BE83294AC9EDBCF4C01BD1FF51E9373BF70C8D0C384DD5BF0486A883EAF8AE6AB85CC165A0E887F10555A359655DFDD938933637BD7AC08FE8CA2351DEB25A6365375D4FC27FCF3D344A76F8CDCE8937E88736455C13A205AC83D56015CC4B7C5E7117EE85D6607ED8924B6F706D13BE3A492E2A3EB8E48D25E32622EE97DF8FA9F765D18CB38116A164FE3090C7E8D2B6B407F54BE573C442A49216FD01D3C6D2EC37594FCA72423E7A0FA27D2721C7FA1334C26EA26BD150A5AC0EF5CF80B1176B67C28FD2F5FB8676A7B7C6C479FEA397D68DC2FB324ABEC73C35C5F8B8E631D676E725D55FD0A0F7BDA0FD1A989CEB71F7BEA5C2978E528DA7EFB396F3342794D26F5155609B568C405A7994C856A6EFCCC93CE07B0445D84C8670B65CE1523745B5714F7CA83B249F20C6DD56AF1418A60078456B6D5A43BEDE0D9BCFF5AD0727D043DC6F4CF0351E985DC557F4B64A1240AC09F88A078991E09C7CED49CCECE62ED21CF92659421A60DF72F6EC245B5AFAD59CD2933609ED3D02B89F1AA5EE1B44B18C500144F7DD8E9D2E83F4C6A4A93B879327E83197AB221E3E2E26C0A78F5377BD90CD86E28E0D75142AD12C0B7B30EF6FB2354182F24259D6F3C3055292C80FB00031E5889B49C8697B33DA050911F13389636F9F1377EF7656122C4676F04804E6251D6C7478C311C4550AE1B8BFF920198C42DACCE5E52D9E5A015E6B9CCE761592B4F2321ABFDC4E3C74F8958DC0677097E335665DA79B274F873445015E494DA06F791769B7FCC1B93864810C6D258E566FB9D60C26851BDC6BEA0781858690F60502A35EBDE041B9419CE2B37783398EB5DA87FF4F52B312D7D549F9B603562B17F89FA6A44420F7A9155EE9A7E3A1B5D3BD94EBA1B8EE94A95792EED7FADEA0768A9719391D4C4AB639B82DE76C6A6AC421E484B3CCA5BF11D8B3F08EE72151434646124E65D7C84248A85778007D5D4821D6094C11F6BC9CE58F10D58E936E81203E54C9B28C9A3B30A6BA894294A0F9897F2255B27171AB0FC4DB001308E8F3319A0CA166E6C7442BBBCD93A1CC61B09F23EE6796A02B3CDFCBB089C0B5F70E3A5C55B445302D77E6B8F5DDBE4176B04E9BB60A17135F975E51D1846EBDFD21998BE5188CB04C552E058AE637798EA1401F37CDD7808A1F64D26491854B7D719F2D573CF2C6DF86599D9AA132B479B2E356DFEC2F9C5EF0C8D7DF5C36A5E2B8A6BD9AA13C7208200B675A268142E7343EAB377804243F39DE83BEFAE6DAEDA3C41BF429F8A85E2ACEE4106EC62D7477C2B6372459B6D49AE793598AACD7041BC6105405CAB9FA75CF812EE8CF16CD281E6BC1FAE6A3C41811BED3E32E2DBBFDCCDF75934592D394A12DD81DDEE659BB7677B868C4D0FB3BB3A998AE4EAB93A7AF0DDF28C2439FC6C496CBE1EF87C1BA6D228EC1C56B0B9BF847E6E569A82B7D0FB79590A0B6DE05398DC3D06CE3839A8F02466A18A35F44AE7FEFA058D954886738D5631250BCB39CA76524AFBA1BE7F83FCEBE3092A5D52AB7E16D7A6ABCAEA2638A78DB7BCA5DB0770CBE8889FC9FDD5A1B0577F6FBF1A1A0EEECAE7D2A9965EDBEAC49E932034536B52C84577619949FDAA504128C510FC4620D7F0F8465A39105FE93812FB7FF1F2804580BC613AE6DFC32E2DE2A7BEC522D69A121226D3B0D385A6B247780C2CD732E8E78B33D3E033E917CCF72DBEB71230B11E275723DA67D0B490416ED0F690255BA05ED0F6D4F5C16A35003A818715E820176F9C5132D246B78108C9A19D1F170779B5D39F324820BB7989F6211E52BC59E30BEF0E979F1073FE033EF5B13AF32C2259D3446FCB2C077D34F1434644BBBFFD7ADC914C3A614CF9426B5F4F9EEF6ACD3D66DA11BAD4C09D3C48F9EB0AB669628D93A1A4C16A8833E5FF448CC943C52DDC4DFDAE1E4D911C8152B6C29532F886F72993631D471A3A14F85F4BF041EFF30A8E1E023D618C21F7BEECDBA59D2C454A34CDB937D0BCFB503A0FAA6F88DA6D2E5B5FC17743BBC5E2CA34D9426A7524A2CED4CBAE1E4F6A509646F8266EEC2C982E461AC1CE141F007CD7863A0C91963336185BB4729C757621908C62BB41B9516FE6D401A85ABB2A893D4B93C58BE022A9B467283D9B7E0348C31C8A3EA83DC76A4CC6EDB43FE79D419950F19FBD393D1ACA0AF909249E36D4884190F8FCC3D92EEB50FFC9FBEDB4AE704DDBD1528C8A53158601816CB3BB4C8FE9A1F3960E8E7422432C478C52A1CC8C66BCE0EAC6BD2A3526078A38FB7217988C1B9DB940142D2DC69710B6BF7A1C11397DDFCA54D8AB865B34AB3CBB3BBA53E307066FB30609458734C27144856AD1434673B5C6FA9F938B50C04A5AB4628809543C294B6058AD32A5C5F46B37D71B7E05F11EC3C3A81F3052CF0BB33CEB4C282EA81BA1E9D7346437796E1AD0E65B5B738646018BB6B26FDE122395BDE4AC14DFC45192338F054CF2A97A7617FD437665C897E9FF2CED7F3B4E30EE24270EB1F08617135CC0240B70462E7836EDBE0E0147BDCB969C9AF7D8AD52579B75922121B164D60C44BD22932D859A24C52D8DA6CB64B6493063545C24581AE2B839F5E0533E647B64DA66FE06FBF9F1F61C30C83510D46B73746015DF3AE7ABBC298F27779141F6F5C2B6A0D029BD907834970B03D60B48606D7194345A3E1A7B3727C48C71268E28349E405835D8E409946F1D5562E2E3ED1C999D1F692B94030ED5A90EC725E852EC6EE6BAF964F90A91FD60EE412950E0368BB15A787B961B583ABC2EE37507F45E5F7EB3C31A79CDF3169A0046ED3ECB048D84CE1A47B26B21A9D47231ED212BFEA6DC7FF4546DBA59CBA12BE6B8C42DADEE1B04A1059B3ADF730830D4D399954181B80A1AEBB91F9226D3B58291DF29DAA845CB8262ADB6B1F76AAE7400E02D8024BCC6E29ED6F2B99E674FBC4C3149217D31B4001AB9FE479BA9F1DD73BEFA758F01B4DB00A70B5D46E53C60F5525AE8482133FA55BC82D897C689AA34389EDAC8440EA6199243B02B0ABD9C91950E245325161299C3B99EA8CE6D435736680381CEF60376AD0D5F34CCBD0F5A2AA6050AE1E09C3C20A9BF48855427F1777DE81A18C6389B180534C2523242820123FCF55FBAD51F831B4806911C7CE2CFB1660F3F117E279B64C5B6001F5768AF51640136F6A3DE8C282B96EED3FFDEBB34E2AA9BF1D3662533EC02986148AEB236D991FA3817B15C02011377A35A87675E1749CE0A9F89E25F3A4DA800E08E3CA339495B673CD37DB0B53B7AB6C65F81940379EF8452EC7F35F8370C9562113D7CC93E02DB1C6AD707CD21F61FBEDB9747E20B121E0A05E13C2478D114DB4BD2AB5A39915DA663A01597FA8A3428A4ADCA4BE8E034BD98B55B9BA93FBD7F6F0157551EC36BA6E32FC340CFB6BF607DE664355184DDA227CA1EA53740D627E0E44EBAEAB10E09E21CD0C6835C87B65B92DC7F669D64BEBB42072DCC4EC2B3F5469C566D1AF35965CBD2B64299E52FF8EAF4FAF3CB6D7D3BBBD5DE0B74D4B5D2125F688B7FA14F8CCF4BD41A9F7A912012A2A10495C555AF28D60E6A8029B19FED55BC2A05419A8CF88FB9211CA611CA3F5E342573A228CE8A6ECD192D471C896CF0C1B044D07E47C815A7BE94E01DF6EF3CB19CB21D90AE0600FA848962A19F4D4D01399D0006F0FBE64304512ECF85F2567CCEE66AD76D2A5EB14AC07A2E0B19F8EC6465104D6C0B9707898BBA0DB74BBAFEB76DBA973AB26649EA6C11870270CEBF5FE61B40F10DEA897EA489D474491E5C477C9ED9D857D380A5015B569415AC135F2F56D5A8027B554793EF0D320C4B46C3A69CAE832DEEB5BCC3436C63311C6DB2BCE0BF8FE102E42A2207C60D8F43E86EBF88B1835ECF3FEEE5B7AAE7A5784F59FD9C76F5B9054B57200C526DDC9A736E2A12DB81766B4F32D579942C5A04377575A3A802B212819B0927EEAE0115687AE305EBDDEDC5FDA59F28073AA0547F0EBB54824515577415F0C9467310EF5BDDB43581DA13F2C9F8E8BD5A26287164509BFF9D5CF21CAF65DFFED0B6BDE563F94F30AB05A41A0D58B17561C4BC5314C080045874E9AA0D603A26F5214B7A6D4A82167A3C31E454F4738607007CEA8BD41F1B312B30E510C96DDDE9F90E81DFB975DEAE472833DBB12F8959F9747A3D241F04A22A34E329315EA2700D96847DCD7F7C7BBA0EABD8C246660E59166E6CDDEA807D8C4E5F35F099BDF200F522173DE26F68E05828A49D90F18969D4C2EE51A3662FAEC2603CE75CD4E2B24868B3D0CFE21C04BF0F44192E3FEC8B4792C47C6F3B69A9F2E720FF7427F09C41D2DD7C7CD1FB983E5D8C0D0F2295E25FB10F4C70248426E52FA1CB7B5B614C1D533CC4224B3C57DE35A0F4614FD894B29B5AD6740DF07D96FFC8B928DACEDF51EE5DE8B6487EBA87845A61A21B25AEE9C9A54A3BB33B7A3BF20CA006C4DB3997431087FDC15D58E5958AB0872C70A3A0CE7E0313662261765BA913A164501134E18D12BFC67C67CDB9B05E15B1D5E506AE0456D6101A2555CF4D7A292A1295F49F615C127651A42455132E8B7831C4D5D33EB3F944B1963DA088116AA1BCE1E73BD64675AAB84461FE9A88A658C5DEE0B81CE60CF9D1CBE6D707CBBBB3A3BFDDBA865057117CF2B94BADCB0F976D456B43C40E619A9B6E8C2E58F29D72900EC9A920149D3022A5C77D80A8685DF93ECAA43D4BC26D68FDCF24817AB7447039F3152908D638EAA88F867BC9976B920DA90F360DAC8324F2B2F64C88D8B12B42471813FB6BA24E01B2E9CEE6601BF41BAC5A2CE286B752061094AB25399C915D6DDBE58C863F67D5F2BDC5FE8A35875E1B86256A0F991D2DA49A3AD27841BE77E7581CE77910A1D2C43B7CA4E4F6A04B672466F71479B689C25F9C28112C116E61A9F42A81EE82827D39E3C622E08C41C24CFF89AF1F21DC839DD5FC921F0BA8019E847137639866AD161735553A26985C2E481DD5130DE51B2C8E19553098956F39004979E86F0B6AD49CBD053C0912B62B2C2BB47AE202E8FD5AA76E023B4AD41C725E4CDDC38859FC98B715F6E375D4FD1C907A6CB1E1984D273C71C908038BB2B4E8B1DD10D3BBA797665C7A4F0F3ACB717706C6FC8805243C5DB07F30F163F53164061D404574225777F4B705D4AAD8BCA1BB6BF8BD16BA06F22285F5131E8C1D624FF9E7F76C2CE2FE8413420C165EE2A6924E7E8157805DED15AD715720DB8A37C31C338C7E4FF039EC4F3E74A81BA094DC16EEA9C4E17E828566475D65CF4DC287EA27B6F3BEBD81F84262D503E2545C0AD7266E9D1221EBD2264A3CD1E87B4F254157FC77AA6B02858CBBE6CD51A9D0A21845E11E7203DEE79F615EC1420DB3282F26ACB3F67450B944E1A0F0098B34850C7EDE9BA47E4BED0AF3ECFB2447662DACEF58852EDC21F7E1869CBEF0E9DA8C5C8309A93A5F1787ACDA8F176C323FE1A091D9E3179109152719FBBC06F8C8990B582D642907BE85D36F1637F14811DC42A3B7B882E6E48AE732B0F9E5EAF7C21281607D0E8185574A5CCAFC1BF047D812E0A7FEBADA1A6CD53CE5AE5E08E29D6B3228392123BDE9A171939D52BAC7CDE00F02C78863F53ABA82A0CB6B26C9DDFA1CB6E3BE28E715A72F61AF15D5EE760851D428E6DCB92215E661083865190321A8734130CF1FB537E8A441850A211C8BD9308529EB866D5DE6B3DDDD1EFD4C71E6BA37F2795039D6FE136D4A1709C8C43F2736B18AE9DCDF65BB8009F6B44A55EE598ED3E65BB210E20F13C766D31867BCD49269533BCA758E1D4E2C601BE612DAD31E30708598D1908AEC555F6BFDB4E7E125DCC725290D8AFF597E2D439BCE64733263880049E2B1598E7D485474E79C7B6FFCEA4B850D37A631BA67492A1F0735A9D353993057DD10284D3360B3BBBAC1C85762A2040E4686FDB85727F2D9A6C1DEFC102EA964D3D29FEF59CC93345E89E25A22D0E0E531BA02FCFD032A7CFF811AC69512449C1CEB28428835C84982FBBC82A4F25BC088730E54CBC54FFC1528242216162F1A0B874C7D916859400FCDC14D003FA523A430DDC42D4F236869BAABE275D7164448BCC14916FFF065383BA4EE2EB8B6C10A99FA2D5A78D7CCD0637D81CE917CB3BCF006B700AFBD9E5D383D041CF4CBE63C7A74F18BD3344F73C2F9D49E4E9E7540C1E3FA9FF23B7E8B85008FC74A8FCA371BD06C07BC749FEAA5A93C2E49245EC7044EACBE03020CE67CAD00731FF41DFF271DC2AC657A8F6DA2FDA1FE22FA398573AEBC678EF154DE7CD2814BE241E747 -Output = A029AA0426F7A310A65CF259255F8958BB60DDF85D6F5CD6F40A5E0B2BC3E397BA91289D2729179956931EE52F32067C52134D288FCBFAD05CD3BFE1271C9DA66C309B7C54E5E9B11D68ECECC1CFB3A12E20C2FC8CEBADE805637FD50A5D7B83599C5B8EDF4129774733B62FC2FEE413348CEF3236E5DD14DE0E5E3099D46EEBAFDC0058B39EE718A3345435C2FFA2152F76F254B37E0578F758682A5DAC9E4FC5CCBF470DD9CF089F0BC4B491BC15EA627A87220F9DAB5E4B7690D1AAB724A20BB05768BFA500E766C4BF57DA2E61850791D0A0D150CA129ED9EB20F68F92750175A0C3D8934C17EABD24C65231F0B1CE66592502A47AEB076D19C94BD3D6B67B404D6BFD95B9065034752FF17357D6399BBEBCF868273DA2AEA74E9451E97C80F14F48B7D6D5E3BD96DF1476625A39C1F9055CDF990B7D0B04B85F6FF640659EC8F476D95FC1EF7028312E5F9AD0E0AB06C0615517F5F43F699B7FD34564CB0FC224BB8474D74ECEB7B6D47A8625356CF5DFC9BC84CFC62003CC9148CA479FA350BF60356C5E4A27434277505EF1C15C060DD1D34F2085FB342BB96821974761E8DCCE54F40F0451E3854561C45D7A2503C416BEFAA7F81C2DE25BC6968FE5B07B9204DD1B3AF89E98737125A4161CD2890E1ADB0E03C53AE2F077BA5515AE4BE0EC1E290A28D08F8596E7ED7414935CDC7EA0F6CACDBDC30C6D5797022AF0260C648B52AFC661D1EFFDEF33FE861C8972A835F85EE5CCD2EBB7AD53E908A860874876C8843E87140F77E058754D5664FA9D7DFE5E7802218A038A9DC1575ED6ACD5256A82F31F177DDB513A916AE9A55B304B151D553AB4DE7053FD642B32AF1A90D40BE2132FBCD8E6817C4C7CDF0D9D566549B49E8D3134D3F15C756AE08F1595DD282B42E0F280126B6EF3FBBF306A8544991AC2501ED1488378B4935F540FDBA2F7E5989B1E91968CCBFE9846A88BB77C8693732416C08C6BB58C57AA1ED2F0DD788CA1E6E2CD9144C7229ACA28942C54A43CFCAB47B05B456E6CC32852202D0A0D6FFA650C199B6D5E17350A90F74827BDBE0C0F7A9115DE3BE566C8C4F584780B96DDAB763C5BF7300A0A377C69B0AB418AAF245654E8B4CD36668B03DC50A59F344F80C95958E5B4571F500827FC18D594D688013D4627013BF37A6D2D5BC043187011C058806F5112766CBE2A5A89E235A73B6C99B4FA91B41CA048C930198751247FFCDCDA9507D3EB5BFE2A6F70AB77D028C72CA697C5F66537448C294E2A0EBAFC9172E134478D5D542CE38AD66691130EB25BF889BA7F702BC329C26D2AA177BA828D0E3753713C1F1DB1A9051D339C7BF5D927906AF9242C2166B7001B4828590ABC4814C11018187419F2DC56A2A35BC56C1A1DD96E4372A4FC8A9B727992C46C285BC9C594157CFC7EDA0B171BFA2E1EC7359C68E9FBF9E4F16503F2276B5F6978F760DC72811EF628085723A14AD4085F38CF28D952179EEAEF02ACDE2F51F522C0E53080B144E295B425413E435998BAD98060649DBC0A520BF94B95ADD98D544D7A94D6447C13CAEE32B1AA7EA8094A8BFD983BA9A26D86BBE46068B20727405717D19605E7421B674B0CD0E953F93906CF022ECE9EDE561EA583C5F4E577BB4682E2268C8664767A59CE81D5FC64AA9C89A592D3FE9562CE680C14F5097C480AE76B0342357882DCF85A0B86EAD8234BA5F1A17944A0D3AFCDE6924F7905E6612D5DF60C90E560FE4ECE200A1BD77362397164B4076A9FBAF3EABF5459127B46FB2FD2D2D4526C639178899A596ACBE132B49C0C210592D9CF957732B1A31F9D5B90F17FC76C2AD03A8E2AF0BEB340594B14FFFB9EAF1991CDF8FD5DE162296160286A0EC81D47185556E4C9B1AA39F80C83399BA0F65011AA11708FB7A02B2B4A8DBE4ACEE3D14A978C097219125141DCB0B00F50F02967B3274698DCB0D1F0CF255024F1AC8F010950A113EB2622A7828402E391A753B5B61F6B494B2011563D508E3C6F79C8CB425605E1BB25A8DD19DDAE6CDB45C108AFB89CFF206C82879866D9E8FAC5388716172E43F26A8B8FF3FB216EEA37DC0E1088315357127F2D108C1CBE4F8D5322B425F3F97A7BE86977C370C859FFC5A8F574C2EDD37B32279C62CB21EEA21D2EDE1FDB498DC0C6C8E9EAC852F1ED49B8BBA9B7D5BA404B1091FA497C0589C54A5327E39078B996B3E092367DB99777DFC7D1E997CF67D71CB3079527945B9A636A27B6BC2C3FA7112B1AF4633DDD50FEF8FB2E44B75E50E2828205D8F7AAFF4ECC5AA361B484F1E51E8B50BB9504322AC2C94F440AB7A845F801AB00BCBB047F2F0E2A15F7E3CF2C7C2C62F99C68A0C377F3D52346017CBAD4BD42F83E624CB60B09BDE4D6418EDCF9201341C60F5ED70DC8FE1EE919B247EE6F4A4BDFCEA9CDC019C64CB067A69EE74DAA184CC30113C532DD88B8D1DA6DB02047B1417AB5135A97F420448C3D898B25A59631DA6B20A30C05358D7B61285A6D6459FD25BED5B9E9C9058CFBBE6876E40ED91A41BD6D70FFC89C8322C885020EE45F7F15C6D959927CB41A86114CB9813B4345DDD4C818E04C73018FC745915B257DF7D4A08EF9E7452124F587E2BE9FA5B60431F604D3DABED49F934E251772C16BFEB4DD50A7BB4DEBC15BDC07C9B64F0FA2E134CEFA5581D07C32256F4D2B5350CBF1FC5BA06311033879B98DDD39A3A64B383245703EDE83C6B763EC9574ECBCF1C0AEEE559A652BCE34F8EE052F6F3D5C9A183B30FFBEA840BCE225CBF7406433DB56F64208713A562531C52F328D030B7EC4BF053B169BF3A5C1CB2D1A2312FD5C7C36850D1613CD93FF74D54718646CF24A792485D3D88DA1632863D56E88EB06212ED46B075A64F9AA3D95099DC2D8FFA27936398EC5656BFD7A09F80DD5D23D3A59A3B76995711CBCBBAEBC9C3093041317776555726BA333B564B43AF5290DE27187484DDF8C1001D474C47D48DEDCDC01B820FD25E306C021D194B415266767184F69210BA95059286F411C61312B514626D749B2738D2878593910D6063E5481A416BE314C82024B54BBB8C4444A2CA8EF5B3B9BF8FBB082CDA6DB3AD99E4225A2CA1F4B30465B66B8919D0613149DE3277E8966E56445D96D29A51DBC9A803040C703EEE75C9C6025A27B09BB373F3F616B440693A14B8DDD1D7F8560A75E4AABD534D30CB50944703298DE19E9C0F160A7E5AC59DAB4DEBFAAB50C8BAD8E50E1945318F5A9C6BB6FCECC4A47CDAB226167A91E7030522FAA266CAFC58F8D7E08A52C2E5D7E9A84E78575B3E512143B838A8BA8B4D4E8ECEE0C1E32384C4E6B819AB2CEF2162C3C3F40425C63728E9B9DBCC0CED2F0010C365C63697B8292ACADC3D1D9000000000000000000000000000000000000000000000000000C182937 -CtrlMu = hexcontext-string: -Ctrl = mu:1 -Ctrl = deterministic:1 - -# ML-DSA test using external mu with context -FIPSversion = >=4.0.0 -Sign-Message = ML-DSA-44:ML_DSA_44_1 -Input = 1E5A78AD64DF229AA22FD794EC0E82D0F69953118C09D134DFA20F1CC64A3671DDA292BFD9AC708D156639FFD63844C793D849C7743B4FB1195259D46D3801DB2EADCD31D515A93F60C84CDCBAEB8739777C54C826651FAAD368D582EBD0556242F4EA5D71BB44E8A06F2C94E52319EED545A4C29A44D0190A3FED19FD49AE8C5C32FFD4DA5C7E1C3FEE0CF67E2AE9C082D2CC9A5DB29441C9C4B9F0D883D6AC65AABECFE49CC1A1DF01752F8699DDC42FC59DD4F614371B02E3709BFE5D1EB41D92905CEE18861FA7C3AE94CD97253A60B84EF638F43FF507ADE86ABB69658D9643C6ABD33E7C7DBBD5C9350A3EC8EA4E2C0463EBB4F8E43D639B6B9642F571F9B8D295817367651B39AA30D97D59A2187EACB1DA5E4669D9471E3BA498B76606A2B363E0E068FADDDFC1311DD12C5C9E3F044DA9FB13AC1CB376EA6E4444DD6BC80205D9F8E11DCB56ACED0A621C50328D7FE975222F08A78D5CC2FE34508ACCCB9439225EE91E29796FD804BB397875741EBFCF11A8FF022463C3170A963B2EB1A943DB91C5514C4FFB1E22312D0B5073CD94707F3B760F6FCBE7AF366E2498920A32C68AEC42098F3E0B87B86FCE0B12F9852F2ECE38E36FCDC7D4CEE08B5A83D791FF391E4AF9FCC33EB81FE5DD36A0B58FC1C8A76F240A6BE4D4E53FCDCDF62A6D96A56EC1A2BA4ED69EF2424E54A2AC139CAE8184F06D376EFAC00547D26131FA6D3A80E3B4513E434D98DC5C7866A5DA2C112FFFF197A816892213E0FE9B6E7A4FBBB4F97CD925CBAD731C9883C0910EA103E341DC80B52234FCBCD91DEBB66A315F1D097447DD10520B7FA7BADC1245FC30CCB4059FD96CC529415AE978D62C1BD77596068E3E6EB8E9E0B5EC7B4C7557A651F317D241A6F52398B3B596F933C06B22065169EB4E23E4874646CF905DDCF7F0E3AB96983EDDC7FFF2DC62523F2F27847CD8286C4789FD8AB0101E6DF516741608D5295A45E8FB2FBEB1754CAE949765B3C4A6D1F3FFC60C06DC81390D86B1672810E6D695DA4923AA1C6C0D95046631492CF3A67D9D26EEACBF358F0CA54B2BBF0A5014C6E092A76B246F1AED72CB3C6C8DDE58B170727925ACB72782B54819365A806040D3BF2885A517F0164C9B63E6B84454BE81853F6B90E88508174C8314856689D6B2F4B0E29DDA36B0DD090D32BF3ECF385C9E9CE356133484A2C55FDCC8CD205ACE2325877DB15D1E69967EC56C28CD76284BE2A5C157F9D87C2E94FBF8A0465CCE795A8DB5F8833F445E3B4FEBB0B236C0587C0E2AEED428B1DB8001F1A27CA4E56A761E5E8ECEA5590D949580AAB3FC2F859D75442CC64498B91C849DDD4CD9F3BBFA9EADE1BC5DCDC03AF1336CE2CD5F1DDE3D7B7060E00823001AEC9C6594FEC802627712190EC318E6A40CCF6898D4082103714AA1F61D72B0C6EF7F76B36546C09C05B6D5802050881C667D52B9EAEF9A6250CBDBBE6407184D923A5E4B354C225E8852886E6A71CE4C0905FE36BF43014ECAAB0087A548EE8D2440F2EE9C912264B412FCEB3D650D5152800752953D8D8428FBDD57B1D671853DC6D378C321CD105893734DC82A49A803B25E17CD2B53F8B8B50F6AA27BF82860C515870D1104B197D57EE835463A38657FD3AAFFD14A524DE089C8D265E5D77BA9930362AE28D65C5DE8187EA0D9417EE2CF885273D1F3C8773635E7610F80EDFC890E88B81B3508251DD0C512CA83167129E2E5D3D304B71CBB7EE330FC7A2EAD2A4824EFB3A7C5B45B2678891084F61A66E4DB3E2D1744ADFE3B60E0E9644C9559D596C09D7C55052012EB18B1B6571C5ECD9548108882C008C16C09ADE6C7473E2A3F67A054E7FB2DECC6B0D84D6F6A440EC6B1AB8AC0993D3615857883F1E7C3C46621209C2A257F40D3D021BFF71E47E58C9FCD8B0BA54B6003CB79673C00BCE770D06CB74FD0AD943CB7300BF940018EECB583AECF3494D2D8706CD8B9BBF803DB1A00F9AC349A0F4D9CBFA07723D070A332223404980271CA18EBEAE0FB30FB57A72FC9B1A4C10FE98846D1A55FEBC35A4DD3EAB750AB0BE4B19E6E438398946E64FF63E72BBD761DD984AFA3E62369872F6D788F9F60570B17F46E1BDEE96E38EAB8C8C873F3C8C5628917A7B622D920B94D2DF2D07E272CC8D6DBF383D9A7F12C66C6BF4322D55C60480EC78C20E1F2E8F1F485DA9B9EB0780BEB4850290E7150A4C79714C112AED3088D6E2F9F38B31E2B1C924AF895F4FEDB8155D1A964EEB73D66C5D3001D05833E7D70909C8BF961BCF1B517C6AEB76A9B9832C795EC51781E0BBB999A6F10E03458F8AFFF90960D49EBBEFADD0CC2F8FF604310FD3ADC372D70203299424C7AEC922488A7B7CADFA92F0171247FE83E3D54DCE6EAFC7258E1A066C96F3F3D4A5CE279C54B004DDC462D0D7092BDD794398F72D78DA95C66586F89F593110DB79F942FFC1322CEB02B69904762CBC86A95FADA7CF6DDDE8CDE8DE819B17945D775703B5B276D8E140C69B46C353AF340893A6FD9E88227DBEF5769A237DA19E0D6C582560B51A504D3C3FE1EB8CEE3482F1FF4CB5A1C9CF7C647ACCD7262D80A876D3A188223607D05C9F58579EE229C24DC040FE5A14D10DE04796CCFAACEC948770CDA6A0724342FDA6CA72D7BFB40B37B77402B20829448A520A7578F5872702200752ED6179B1D302F683695B6FFACD0FC271C3EEB48EC3BB182A341655E42A33CE37AA811B0A3947F17696FD0F927C3E8BDEE9A15AD057B1D3F86BB2F9D4898D7078EDDC2958EEBC132ECF1C40A7B373DD3DEAEF719AACBC03D3D9F9B65C66C092D794B316596C76BE6B3C079C6B85BDE2220F60952C65053BF42585CF9D175F265B87C655A5A5EC9E800BE69FD8B03969A986DDAB8D2C1AADEA68BC360AF6CA41DBD04CA4EF5778FFBAFDB14712EF94B06B90C657693AF6A82CB5AD1EA5A79C3152F98F6D70A4FA7FEE46E683D44763877761DD97381D3B5B4DBD49D9C767469181859E76771C1249280E74A4964465769F7475EC491DC6E16FF67982EE127E62EB7CD839BDF30BFD4E26A50EFEAB51C74037FC45CA221E59CF4C697309506FCD0D734FE80BA5AE8BCA300E5767863DC97982E35DEF7BD63B54D3EF6C7EC63D5C7E1C953C74DB5A2385DBC1905D632DAEB8E84946BCEDE992AFC4B355D934578BD06BCA9534E6B1C2D9903BC91E85F01829C890D6521DB838B1CA23269E23C3C194D0164D7B577759BE9B5465169B6CC2EB4179ACF5FC6BF6B935FCAC40605E3E0552647B58DB59A36596C2BE04617EAE766396FC51C913F95B7F28D50AECF0815968D68539E326823DDB7619F5B765D21AF79930F1B796DBD79E5E8F5D978EEBB0C8756A4389960F9488A3F8A4FB97B9FE866C89C8A149CED32A0ECFE2CB0AE1C42B059D715468777151D24B766A05E66E414A68794306C655E6CEBC01076176C41A52BAE2060B38FEE5DCDF77AFB591D61FD75431DF0C26D5E7937C9D576D4E2149EB2C0BDBF645A57C477579ECBDE9636C036E5592C0BF465E86D84BA0B5365B46BC2599190DE97E3CE6F29E42756CCFDF1D429DB894ED7F844509B574828C6ED5C7EF498DC880AE9126FA7030339B584C5CCE3D240C233605A36199AC8AA5375722C1DDDDB92CAD5A6699EBCAE322E5DEB63019B9E391A7A5CCF2AA75DB153B02C55353196A1E8C768820B5A3C8F3085DD774C1B5A7FCBA85EB47EC3593357B2C4DA4CDEB70BD5377F5C1A6AE1782FDB9384DAB563178A7834ED3D6CD8682383ECEDD36B6AC309B72CAF33E5F700959B20572C7CB6449F9745B7A2C1C301E7B341126A77144F32BF0190F903AFD02FD6AE006DBF1B65955764E7BB9D830A4826B3E2B627D7439C8E1647E14B9C037F015426CB0B279A96F73942BAB0DE4907E3DC96062ED184FD7A0C955AB15CCF991E9899E68BED24BCB91187ABD4BDA92371F93E1B3622179A3AB1B930E454A77FE516775A01BA0021F7CC29456CBEAE333C79AE59DCB5B096F29BA08C0F1B89E357F46A83F1E69C1F521AD0E6B90A35DB3DC94B6D37FE73509968409EDA533CC7B3E24FA29AECFC88E6E6574F054AFF32397ADF4CE33CC6A796056FED6E8205AA6AD530B83C6F561C152EA9FEA50A550856AE20DFFDA79DE49B8C11F00911B790E4FD5A5A5256E15A5ADDF380216234A8F578FF2613EAA8C430830E1EC9B0FA08AECB60DAB24B8155D533CAA66CCD68AAABDBA1031A665B44D80CA6D4ABB78E2483604D890CDF83977B198D6E2E80D1D658BAD557D57E68FC546CB936E3FD6F62A2F9263DA4C065813377818363B0B1914289D11B19301DAA9DF24A7261B70FFD9CF01EE012146029D5EF88F32906EE9FDF1AEDF2FA0C53C0D9395205E93B71BB6BAB89524F90AC2F7BCB276DF1F7E4F0F734ADD2737AA826426D70BE43DCF5FD5D7AEA0DF6E5D38CED606CA333952E4AF896E1DF38CE3656B88037221D9A90E86F5A022041DC86D813E6A0A9D061A77A908E58D4C46457609A2CE97CBEE6738E093D04DA10BFD8516AA643902ED082A1FDF60890289925743513DF192DF07E5676CF795202A570991E816DEAD88C737945166D3D3DE95D828F07808158F6D2D7911C1DA14AC7B86A33457A861CB57BB5943710FFC70F739470C31ABB10A4DE9807899F544107B05616344DB07DCE46AAC29025378FD96130705FA8FA1ECE9F81F5F854625F3E45B96EA0D92840E3F319BE3889B025D4915CECFF9287C01FF6EF5D8E9371E805E24C404B0B20364D3002E6691A14BDFD0F89693D67418A86047AC10F7671E6D983D84C47AD355EFA9954411C0DC599B7FED4FF794A6CDD2F93EE80691BCFA1711FF32FB3CBBCD10E03B3A945711E7485E4DCDF17E206CCB38C18037F4361AE4399B23B814A7D94DDECE17F171F6948976EC4CBC9133B235B757A30609ABDF082CAC9AFB9B5E249AFA6F2530661422EBD789D3D34E4790C486BF164932C3ACF3FE7E0594D26C035ABF8AF421F848F4CD90E5D9A69FDD8632417D67AEB8D415EE912D795AD1B3C1A13073A0C489D241FE6DCF2D58B23E1167D8E748A41D43DE505F7E044A37528CBE4E8BE4B1356F298A1174E28734756C9567A0BD5E72002D1534E633A36C5373404661CE1ED379189635BAA44A6903468311609DAAA2C3100C9AB83A5DF55F44C5CF4B9A8AF87DF5F55B6021821CC7DD7F3428F2A129329BD0ECC69CC97E63F6574CC10236828AAC1401C6DD4EA3FCC32781B8C1EBB68186C1821D05A49207CC28AEC58EEFEF5F380604B932B0042DFDE26B2EC14A9CA51CDBA0F195BA80B0CD4476D16C91EF3E5652F35E90D36D37C317C786656F4C330A1B577E1E45A22B54A58C9FE7C735B568D09E0D8DA6B07449BF4737E5D55659D46EA89257480EE46071055147A6E70A5FAD6BCBB910A1B2BDAEB62D2A02AC69F6D446DED18562C49C572E2F597E230FDC714A824F4D2E1B3D8A27BA1C9B4B8E905ECF7AA6C37B9A3FAB18E73BDF3CD568D2C875914CC8B64EED925D1F926FA53E69FE96538BD294E6EBDF08036D08CFD7475C8C4079F89EF522F6896852760EA31C5444AF142CB55F08FF89DBBDD94576FABF95A112C192AE9DAA704131ADD665AAB5ECB27FCA96DCFD9F021C972C9F9337CB0638EBB958F906B469AB09B2FE1B0C21084D7C8D3200E8715A7BCA9963075589F43FB8D286A303593FB1DB8F5E580ACCA5FA23F51D3BFACF0B725C5C523676452A580B08E7B22B2C4299B93CCFF3E3B6C81CDFD94C8FD1FF489084B1DF45E2E8EEAB73420ED2E975D37074FF3B435F90243BA2452F54E0ADAA09EBC127FEACB798E4702F9417E26A51FF3E3D2D8C092461BCA08C0D7BDD6EDB0759E14D3B7501BDA28B4467C14CC4B7AFC0FCB3BBB503FB390C9CF06A5A1428E7E0E0DCAA1A12EBF1F8D280045D6E59A0E667900646BBE8368B575E50F3B6750B48C52FA665AE0750F2FA779D3A86806AFDF410DF1F71AD108742481173DEEC707FBA8AEDC94794F736AF77E3DC6F78C378C23FE026F4B5D3A2F8FDFAA54E007AEE540CA35A093D3DD437D3D5555019754CED5F7459DAC47C5DE4E6F675693F0A84CD33E5E4B5B0D84689BAFB7113B899FF7363D45885381249F1590AD173B79F2344F91DEA18E8B0B1A7F991ED1E7DB6EFC87A3D08625F8DDB2DFECD667280301BA809EEDAA86269A07C36A803133048CECF7D51A3D3372D23D3B65C72992CF8500CA52D573C866D2A2E103F9F7351917A7166836AD04CC0C5511B51159C87B0ABC61B54B4AABA2542E831F0940C8E3F24DBE90A49C8CE6B6169D81151C9555C1EA43C1DB2767D537BA05C394BAE3AAD626D2A6AF8A664E7E3CDDB320E35D59F117DAEDEA9F0AC5F46D1A0BEB0A2394C9BD657276876D9BD82E60E5ED5B4252C6F0CEB74FAC673B98482D1C263E7CDE21CA0E6336234AC0CF299952DBA20E2189404A67E9455FD8219B96C0473DC571803B88FB7DCC921057B7FDAE8489D72E097459EBB0FC1AA9C68B2FC934A178CCD81EDBB2D11796E32CFA6403EF25635064CA62BF0A9D8F5BEE591214B0BF0BBCBBECD3E8DA3CF96B34638940580803D9A0E0883F5D34B9AC06B5EFCB83CB47B53ABD0BF3FE0331ED09C0F3C3499611DD2596DFF8754679C7DFD2EC0B2A032C2727D3D76AE5286F7FD8FD85D7FB997EF3C019CEAFF36F891227F11B6E830AEB8F97EF5CC88AD2F6F346D267FE58A0B8FB406F151593C417849B613CDB1CB5523FFBDE78B494BE63D62E61740AF3247363CC3723D549E76E10A3F187EDA82455BADD5A22CB04853364455FFC01D4BB76224EE40071702F9A1EA97C3AC823A8352A6248C56946C147CDA99404E305188CDEB9AA95DD4FB703A2C3698D4C52DCF84A42021961992FCCE4C2502973D25E8837C8 -Output = A4E46D38AB1867BCDB21153C516FCBAA68875303ED438451E1F04597CE6E6B363B0CF32EB6EDFB3031E2611DF8B6549C04350795C0562F5ABA84B3081102F769D9AC2C01CF594AE408B5165197FC44AF951C0F82D5652E3A020D7CFDB970F4ACA2236FFF136CCE66401F063ADBDDD84839B56BC82FBF5CAFECA8FB055DDCC597F7E0E444AB3EDF5688827AA5E109386EDFBB4479803A30D2523F0BBDE033134B77127BC5427310018B59E0F93812BF0EEF4EC37A77F73D0AD3E4CDC4550215320C2C562E9DDFDFA3181029BFA46FD112AB4D1FA4CD0B9699B88F1BFBA2B00F0D330C6067B248028051EE7631609FCB2BC71573086F5DB99673C4318ADF8757941B0E7117C4BC2D047D5174E3A0E1E5CEC4EC2E29B9F617A2E75A91041543399477A07F24ADBA9F786E8040A30BFFBA0103C9331D790B1629886E94D535D3DFF043A89D5D9A5A6867920C31A94BBA0C3BCC473112087D31A54534CC772EC29106FAE39608F333238E74E18791227A475B7238B2F310AE5F1E196A3B14261C97F95355541AC56CE398F38535965C09708EEB7FCD23FE79B3E76FE4DE388B83AD13064F9AD4469AD85655AD3790B958F7B5D82269EBD2E06C343F7207F96CD16B7200150BBD327DD9B3405D58DD063193BA5B1648C8B4997BDD65271E782D2868109AFB01D30A4BA8720DA3E447B426B33C1CD94BDE859D18613D234C74A4790E23A174BC8CAEE8EADB19A9DAC27D340E62D8C2B3DF5D0D2147C4EA61078C9E4A2B3B1F9D0EEE979154E798547CDE291DB46D257228BE695D99C7F27356EF0C909573E989F555214C32C82C0251497B92935121CF1D921B0251025C56C7B1224AB18D19C6233D5B232D13763794B74F43801BF4BB85380E804AE931AD473B3D51DA4AF202C46EEA5E21259F31B732BAADC74C5E90F388DC121247EB447AC71504F483A7FBDEB5C3B6DDC6FEA607F3EB771026DDFB1756B1FB5F3DDF8AC834FD948C67F533244E8E6C9F574803E4029155B321ED4B54E1BFED00BD91FF596261F876756FBBC16EA125BE4D18ADF7B30D9DAD1A050D1B6804E6E5C88CCCAC2B3221BA2C0422B5575829A16A68D4192BE785C5AE609BF3AB68133A499BB0C3A112F391F47F3BA6828A37E6A5F776C5D45901660AE80FA23DA12C70E3BA88846864856F7C9E1EE0CBA22C1E48ACDAC8CC1E17CFE1EF2F50A7211F18E19866E6735BD17AF6696548C67CDAEC55A09951AB89426B54A2C4A9A60839D3C1B4B9FE26D9F53F4DDC832E1399BC04E4F8A1C0AC4083A0281514693F32266632010F74C4B302500E6B8C5F2F99664D1E4D1408ED726A88E301EB9D3B5E0493D9B6FC1884BC753B5D84B96B0E5F23E786DCA71D4EEA5A35F1748B4BAC9A43CE47A6FE073CEB1A57A5BF8D24009D11019F5EB04D3C79DD948D55F7F16886679F6CA592566EA18C51646F298722414C49164E27E85F94B1D4350799B6421BC179D7AC095652DBF6C75DBE4D2F4F831671E339941D1D21FE16BDA064C62859F5662139DF9C2F0B8A6F2562D1C7F9A509845722E916FE4D67F7CAB6E1459356499AE7FF61C9729409D4E1FD0731D69C2EEE5B7A4C5D85D2DA84984AFD6083C4794A837D0E1FD3283AEE7AB12558B186015C108F364A7EF09DD207818000267C0C975664F990CB51D48221AAEE94F5252FAD9E01652025F1678BE6044FAEBBA8E94DC43AF8902A5058CE29D6E17325B1F13A0FB3EEFE46067EEE5BF8E462CB9B6B466B14C541BD211E6260A31041C748EFDF1B35E75B0133E99283206344598ACEE2AD92519A90E99FD96DFEECB58BB40B2ADCA1B462E910D394181F9DF9B1D92686BA21E243DB7D8FE2A0713D6CCCBC0328F3F9DBCB3037DCF9E811F8C25B0AB9E73D4BCF1335187A86EE8911BB494B8F1B0228803EA37C8EFD3D947A08226F4A262984C20A9E58558E6AE03FA694622A634594DB35CC41974DF43C12D042DD752EAE99F31D34BB52AED1DA0069568E1C7A1EE725A7AED750DE79D94D7AB75499019D6C2DDA120A1C6F813AC008B16CAED0015AE609818FE7D8AD1EDD247DA3153EE3D9C8836C77EEC84B885F3856DFC304B57C67D930BCD6C77A29271F9035EA6212A9DCF5526DAF19C47533BF80BB6D15ECB582A78A67BA92F5B413E17AE69C2EFF3BC2EBF5256E92832130D3EC7F7AD76CC8C5DD59FC2EE9E0A7873806C152791741E6C6533F6368506FC4A655A92CF77FC44BD4CE3A4480D588DCAB0C8B398AE8CA6A7DA65792C3946102C45DF4C72EC9FAFF22430F131EDE726DC2987B4DABB72AFE5376A9798CFF3E8758B3F7BB56692BCC4822CA337395B6C2540FE966A70AC469FF6DDF0909AB83434C34A854381F5BADF46E4DB78A317E0BCA59A3A8C5972F8D059D7B3A51470D560D3B47EBC7FA13A253662305B78F7A146FE86B4381B4EE360ADB027C9646BBCEDEB03C959E4F3111B2F8434949CBF04CD487BBD100708F47C12715E4BC9E9D87DA5717246E6F3E4354636CE312560673F4037E4651A2098553C64C11BCFC9B881C7858583066D80353ABA92869BB20B75106C233619B95D7EC58630CC2D4158650582C345D3C3110361DDE04B69F38175D136F1E28020D36D2D90F2853748A232BAEEDEC38A739781BFB7F52154BA20DF52BEBA4CD65ABC7DC57EC484565186DAA795B42C8988293B2D4EF0524CBDE85143ADA3D1B28374D2B1A335C6A914705CBC2E2DBA7D363ED78590369FF256B3BE230412E821407865A07D1DA117BAE75B0226D173C14B15B3E85AE50A569ABD465D4E4500FDF535BBC2C1C5AE9C1CA73753CF488A9A4BB406549BD3BE25AFC62F7B70DFC2E940B8C37CF33D2F80AB3D1070B03617043BABF7D687CB04B33AAEE8005F58D06C4464440875A79AF4F5079FFA1CCA1B109419223FF9E56674D834FBFDE69F406873C3E54218EFD8F70D3DB7084AE9734E31906AD94491CE12B828CC785080DCC911ACF80C522817CCAEF838BC50ECBB499F12ABF32647C425C7A432C0321F13EF4E18B628DC68D7BD5D049592A73A96C2CC8F2D4924A1D14ABB2B15DB7BD5BD4A46B09FAFB0F80578C2B8D0F4767EE26AB05D22A3BF2F02FCDA404646495F27B2A4E6BFD33E732013DE703CAE16B45F9BC39BA8FA2EE8FF427DA4FAC6C822B905465014647873E1EE8832A87870107B9856E950EEDC6FB097F5383DDF6E4AE01C98D5AC6054AB35655318517E669E379140246AE63D52066037FF37B6814A911A15C0982140DC132143F8707C04C6F81742872FA83E6CFA8112C644BC1A86162527F924D9DF22341232E3540484956677D99D6DFFB055A7A7F8C9EAFB9BBC4C8D2D7DADEDFFA1B2B476578798091B8B9E2F0F1FBFE090B2E47818CAECED6E0E9FC00000000000000000000000000000000000000000000000D1E2D39 -CtrlMu = hexcontext-string:FDE19259E56C2602F3CB0DA509B912F88262A1701D4E02B513F45C97EBB100A17B208205098D6BED2638BEBDCDC52C4C5114E8CC8FD9A180E79CE750594C3BB188DB6A3605630C6A2F3049BECEE951FB45B5E426 -Ctrl = mu:1 -Ctrl = deterministic:1 - -PrivateKeyRaw = ML_DSA_44_16:ML-DSA-44:7CC4159615967F7E957D79F40856B4A3D33677AFC73474C8C57769A07C73DB888352E734EC7E57489E19838B8EE3FDFA8C65F9668D774E78248A498D66D9AE97098F76F4B0BB0FC63148C768C777083AC6D7BCD1FC402DA530C10B73E0845F29210C714E0A1012FDCAC40FB85F183A0EFB436C8D3D587F6CDA5A703C5931B7328812610B3640D92066883671D1108D084760DAB6611A1385A2C00DD3407014402D62300800468561240E482884A340900CA62400461250088D1C836C01382A4240210BB324083532C9968CD2426219181208300D091181D212284B806D0849811C819194262912030DC2360252148ED212081BB43122270DC3C280023429A2326C129881C98661C84281031101918029A1380E1219521826615B2245122110180120C034321B448C61440201314EA4C0715BC04823169121A8295980085A1645D1348964084953A00402C62C1BB20418112E13C75093B40C4A42488C104514312210A308C8022093180C80248D18296E11C508018050D02846104572620286CCB20DC8188C64A8444B1231A1869119A00904190A58344D1145660188211A221153284E941050DAC88592A8311C015022094C21324949A63103918C50144108C0608C002E132642119041A34828CCB885141370A48205833009132625A4388418A06424C661D826025B280420B24D11B630E2C20C8122821B1784102502D19025A4342804824DA4265163048D12C0011B939140C04012246E50362150307080A85151046460206260469144084A9BA28149C220248131D2C68908C57120832C93186059820149C66014C82442142614A64C9C362654C2000A04481B3590C1360503066120096C81B4898B4412E3324C0810284C0030D4342584A084E4466823030822156001832091C20DD8266AC9144413B40193B061802410889611A2346EA2428021040D42C20012C70542066D8AA42D921840C90871DB168A10142DC8240284164E82442E0B954D0C202CCA484CA40885E2B63064029282C4310BB7292231484B3052A0306EA0148A1C0966C414260306100B2769D2448DDA20044C489202306CD8868918B56109951104B290E23411249860A4A689A1306EE1203162920D13354E89246623474880200524351142B22C1BC69013A0690A31228C36885CC6016414520C1832122288891204C1202CC3982D14B46410334522B36000B34991244C831804C43624DC020A54C0651B304199B23080064982B66C880610C8448CABAA867E47F51A02B425E91D0E36DEFB54FEDD2D93CAAF5B841866D3995649125D1D05D486DA16B301128572FCDFC0CD434AC188A2688E0E919FFC40DCE0BB771CEAB6DD18608BA18381CFE0410065BCADF12284DAA43776FBF3C20CED2EB71A927CCB86B092C28C269B1B7310BD406066B15F2E9741DCDCCF203C36DF55DE54C3ED39C998BA7ED4D265356F50B213747FF9ED2FB1646E71A1B136E8313F1388FA9262B27F4F569F0FB286B4EA4BABBE627498D7AFD5963CB4BA3AB0F294CB650BB5363A0B9F8F43E04042976AC208DD600E5F81F51AC6BC1AACA7384D5F1C50F83DF296D506D06817A306AE3BA17B3C0695C961BECA64B0554FEC4194999633C24D5342B861C58357A4DC9C1F0AF260086DAD968FF228CB8F0E93E2027FDF4C308D62559994F7033167A5FA71F1AB6D0EE72EBF9DC200AB3A53E94C6EE5A8D7AF8FA68E41F671F10BB4EC96BF6CA13D77D254DE3962D526793DBA996D63170DAD941D3D3733CF91064576F6705EF7936489A7FB06A226BD5A86123BAF93DB5DEEAD00F5FC77809FA5745C3F2C5277E8F9A15B866CDD9AF4B3DB32A867CD6DCD1E18B4EE2650E608B77C4685E236BCB168B2BCF56EC5A37BBE96201C83736E98CC40BD27F9CA8E66BF8E38BAD6832D019BD3E462DCDF55EE443AD4F1A375D034C6B9A3847A178274A738BB8DAD71AC99D4648AF7C24040B4801DE30B43161AC1991F1754745397552814FDA797AA85CD065BBB8F0202FE729F0087414E16407D9DF1F50AFD4E9631017FD825D7F5261429C7504F46E9F9018AC347C86ADC980BDD43AEF8AFDF05B7E2901F8BA773810DF3603C17B6C7920676658F11709982B17CF287E1DF15F2731D3CB619D00D6B26F256BF69A833ABCE080B4CB89F9F809E91B60C11F2F8AF0E6B553CE92972B81D87C75547A23CCBC21F80E523523B77EE86EF6D7676C169C6867FC042E26F091BCB3AE70E5CBC520ABB9112BCBAB80AF4BAF73909E20B49A9518CDA21655F1BCEFEC0B5D8FE06F470CFF9171F84351272CAC944B0164CC0687361B87BAAA61AA64B850B6D3C27FC5A703A111DC5776567DBEA138203DAABD4E0226216F0DBD575779991F2F9404D6FD3BFD19EEBA0CFDAED98A8393AEC6E0D1BF216DF5E1B447B2A68B3B4763048D0F7BAB7162340E25615C6B74BA320080F62D957C1185C744FB940EEF9A0A70A69A1BE206AB753A5F3F0379CA0E54E231E1B95840C692A0754EC7456050EF6D3A6D763908F0191280DEDC5742E7519BC6922123F78E398EBE4BD8A3FE14805910D89ED8458489C79A8AC99DEC8B05B8B0CCE81634790B793CAFFAC74FE8655824E92D5AAF0F4746B3077B6C0AC5A7FB49BBA294A2AC48BCDACF28A18EF1DD53D62A82DB788FCCB8C2AA045DE4EB1375E9026C3FDD1238BBCB8C553C8816176629073C10C9B9E330F8B767057B765891521B5D24933CC6FC3DA89AF19A6E33BA9D3665C36EE5B0BB4982A13467A5F37125D5E9EF987A8DBAA332EC9337920F72F1E633AF03494B059726FF585D81E6F268E8A4990646493A660FDD7D7B1834E4FC9FBAF745920192065389EB95F21E6FB887E78E37D4145A0DC7C10C11B5655FDD1FA52D0FA29340FE806E86D295B251C7D88560098FF6370AB72A2A68C5A0849D9A7A278069531EFD58A4E73B79E1F28B6FD88333F10D92C2D537628CC599CA2A58936FA7398026BD059E4B7F92396E3A964AE7547983E9ABBE0D3A518EA11BE7ACEEE87757A9CFBE315FF93C45B49FED0CD723FBA2F1AC638A42EE2873F4E9D7F68945513A126861F1F551E93A3ED9EC402063EB9464A4ED1776FF44C122295C3B310670190144B9A49DF42B2D21E237EB814F705681F0DF39BF4723CCE228BD07141C324339CFED901715D67DAA6253C87E78BC681E7D3D95A993493B4EC267D978915F1003FFF7A697D550042ED9661F270C5458B86D930D0912FC95FAA6B85C7D8DEC1A1FE0B60FA3CAC1331F2F1E17AA02FF8D807415BD7E2F6DA1FD71EBEAAD8F574722040E8F11C86D586DA70DDF630833D06F8C0B84B789967A971C1595AF7C8CE78598AEECDF981352C17957EE13683BD75FCCC3A1F823C89473D8478E62EBF780D2B7B8775951762184BC4119E2A35E7BFC6A372B1B152893689D56B576DF8FBABA7E47A756D154F4A7F31A18BD9001F66E49BBEF13B137D5BF2C612677CD8762808338106F085325040F45ED07C2153EAB1E7CA955A9D1076A1DD5F7C248386933E53375EDEC86B1240E0BED8C8C19D13CE2EAE382D235438D294944F81088A6CB9A8D3D4D84776B59ADC42DE04114B8A2BEE2D8D0F9EB49790C938B0A4D8930213FA80 - -# HASH-ML-DSA test using external mu -FIPSversion = >=4.0.0 -Sign-Message = ML-DSA-44:ML_DSA_44_16 -Input = 2752D00550D79203509F2371E98FE111BFEC81B2E48534F7F73F0725371B94ACD190421BEB5B083C4D6F819AE834C25BD11BF9B00641596A6DBC605913E073D23A0BA6ACEBB32DB99D88F43EEFA1B457981A05AAEDCEB8773C2DCE1914A6C441AD703C9D8C5A76D7C5E77EBFB896983BD575FFD721204276A83206618AF3A01C47ADD487DD89CC97F227CB304561A9438F580CB5C20BEE81F8192659F269FE9118C32062D92794E12AC1E310A23B90CF8BF9CB8984B9DF670FADAF726BF759D6386D6BD530353C5AE2906FA273FE2FA78C92504B3F37FE84995198168277729963570FD2E21C61DC450AC0833D79B9A7C432E9DE91BC2D47404EF192118265A214AC1B2CA6F3DA7570E2086D7E3FD28AE4A998E81A87467E84B5C6BC92D2BE4D773FC210049D515C1A0365D73BB1FD060B8465CFCFDDE2D6BD1FCAF850F479D5B9431F7C45DD0F497968C5FC5D039E4EAE16B10CA7779196BB08EE13E7CBC5E000C3DBD900AB1DBC900D4760739DDFAB32B1C316D57998941C1F27629A9F56C1C9399A3DAED000712D8685400CAEB6E36A88B23E8C8E199A0089AA011D4A43164D540E2A804A34E5EF50A4EF13981EC72144ADDEB5A415D8631B87E2B6F0C2D27599D92B75D727186768E2A2677DB5876C60F1DF1CB9B0277F8402A8629B4ED2F30C6CC9208B281324C99765CC955C65C3E97E05C3B5DEE263F9B69DEA4BE1FECEAE38C3E37970EB66B595FA9C13213621ECF4439A1D812BD0504290768EC8B9C43479EDCB7E52B82C182244E1AE33A58A2C2BB305A533489C034236319D0388F976A8D0B9AB624DA0F9E9CD651D2F1287742E7A17C22F6C0432992ECBF3B215E6886210C0BB1AB8A642753412377A35320E29E4B3EA115C86698BD3640990152EFB05E0536120B158E164281EB6D68F05FE385B08E111EB68B572E16C739A0B6B94EBE9C780336B6A32C5C4D67911F94BF746FE15FBA91AE4CC6086CD8AE31EA63AA230AF21864CFC4D57B2FBF6B8C83C3F6C4F9140450DC49B0B4DCC30B8C1E4C0BB8E424D38B746D83E5A096EB5EF1A2DB6864BC7DE61C9E57EE8D9CD253BA86020B0E6D2F6F2C5B81770A10EF34283E41BF26B61210570A1613940FE6F5D48E069FCB038D4351F22E76DCD4F022A1EBFE7482B6E1C125DD1E9BA081515AD25E4BFA33911016A2D466088747ED65A5B6A4E56AB95420884A30EB2A3017C7FAA5BECA3A95D956D1593DE6D76A0B56B838DBB8595C00912876901CE7E17FE0BB4D6282AE959E716EFE417B5A7C97285728CCAA20D3056D385D6FD917484512D488637E82527F74D2FC8B5EC938FE984FA7553D0454691EBBF4D52E1A716DFA4D0AB44914E6CFBC55D0FE89E1B1620D7B8A4A8542922D88C17865520ED555D1767D102B466A129A2C97CF21DD2A971156E3F37042E4776D35FAB32770FC5414F2CBB488D2B8F17EFA9D69B9FF538374AFD65E62EA489D3B05E2E447D91D279651CE7550AF36F7A546EDB8E02F7D401A329C44A892A5D3782C53CFCA6E485CB37D89274F7DC600E48EF108CDC0C99EC5BD428035C0A52F790DF326A02B76A65FAB79A9BE330D6CC2C2054DC22EE16B4303EB4104A7F83D27475A5CDA88C2F9CCB327BF2C1C92A10E57282DFDCC66D36ADDBF73154359876AA5C650E41BC3FAF0031A38F24C38F28700846E2F62E2ED983E68AE83B2FCE6EC2A0B651F29A192C55790D0B9FF11C37C3336122A45A1761AD57A85AE994280E3D428041FB535BD12BEB3C0D8FDC302C40737C643E0BB142E1B2A44D6C441891869DE8D01D5DAB3F97A02D569DF81451A5149E0126AFAC25139E9EA692F3715841DA06A32ED541DF75A213EA30C5E180593740DE9D596C8D4116A65F3C20E2AA8A5D1B7E796D89E5F33C5B923CED3BB9FDDBC7759EFCB65D587F11B7BB341BD0354FD86B7EDE5B20ACDEDA53B7C40C52CD619358F117FA62C99A5DD58E35C4CD8F1257493F091B9133B88D985F7FF7B5549FEC8002ABE38C9917749A6F8FD9397739D2AE7A61F1BAE29503D4A4947A3E34CD64676F3C0762C1D1AB31C3FD27378D312DD9BD2C82B8075BBD090DA45D4449389896C6666BA41390DAFC1AF9169F9F117802D8C476CC632ACEDAE11AF29BCEC52BD99DC6480633059E33F8E6E3D6369E2300402C0A7512355D0E6D9FAAB2C4D3E3FDCF4C3EC212B92EE2398801C1383C798BCCB76FB1C3FA26DB895ABF62E7D8BCFAA71B12AF2AF0B7AFDDCD6F3810E6692C01928A80CD8B19E1FC68B3CA680CB0A9C112A7A2687A1E57373D3CDDDC22433C24276E98827D0C4EBE7A2A4848EFEC1AAA4C5A53228E546F2A0CFEDAD9D75C26B1FCB954265AF51B66CA30BDEA4864351716B43849F438DE7C94F278997218EE371591AC2504305F84A4485B6CD1041D84974DF2C5943C42A8DE5857BA7AC0AF259C8EEF65E8CD65087ACC8537E1BCD5ECADF259213E8AC604F794F26939DA5129803D29A6F0CA77F06F31505A40393DD1C19195CCE92F63C535E03060BED439CB27C6711E8E977D43BE4351A14FFBE427F5B03D73A579F0F25BB73E6D0D3634C0D2A05625613281FF043B45D921BE7C744E3E96F2950C6B7EECD3500F96817E041C7360CC7032668BA3D28011F7DCC5ACC6D5EF8C3A5034326CC658C8BE25D1854C3CB5E66B43493DCAD143C93FD745449B0F346807CA41D25ACB0FB970315DE69BC0E93C2060BBFB3EF7577C238EFE7C80C9F91B0B6D453579D647273F8735224D66573E53C50D942B40D64C00BAA9A1F24F41A553AB4DF3FE3C012EF5E73C14435736CC30F0CBC16F4DC7586043727B053D0E7B9B787A8433872E1F867DE2F29837907336AEDE00CADD1ECD30807B2C5C88ABD7DAD54BD3CB6C7A0FF1959E8D1BF7D9DC70CE03B014E850E74C45F1AE9620B5240AFDEA71130042395FF3E91BC46B13212E114D11ADB6D4C4475ED40DA6DA02DAB162F92E1907EEBDDFB167E9AC97462152988899FA6687042B037901BE22EAC6DC95B30B8C65BAB7AB487735BA00C7C060922F91A1DF70646D8594D3BF990557E622E97458A6B3812929786BCBF58ABFD6389AC379D0E8C6090CB240E7E4E024B3422A44C09EF9FB56A86289A67A7120C67CB79FBDB99A1166AA1252A2092A8CB31FE53C15503B8ED8587C13E24F711C5E544A12709443987F4094FC2CD253D3BC44D91796D074108E283400511951FBA63F25F6DCE7D08D367B0C8A60CAB60D59CE2D334B175B834A27FA41217A148CCBF5C6E3DFADA1EA78252FF154BF378869557B66A61DF16C2304A37ED249B2666D604998532063D435D3513D847E88EEA6CC8AD4E082ED158E19044281D7BEC962B370DCADDD55F42A5BE893327F86274725559012151ADD3DF776A8148D301E6783BD0BA6CF13FB5D9DE9FA5F2A0C04C219CFB1F5254D1FBF16ACC0D9B291135648BD3E84494116D64BB66034D9F4E9B74F5BA6A0866624C14154E7E6E94713FD1ED35314C3541DC070385C4A0E6014FE93AA21C68F312A9CD202D86701870EA8016E95EDF27C62712136D2B003F7C319BCE96DF8EF146CB4C1469125C53FF642E85F41D27AD0E700A310DAFCE6EBE263289EA6F8CAF707424110BDD97D0582FC32B89BE65BEBB862E137F0F757AEC47F1F0F2B473B29FB83469CBE3233C838930832AAAA6A027353E5E222C57B4EDF0043F1A2B6998A2EDD6306E8CE3F9D4403FD6B4537AF0770C1C6C4D26A065E8A2E6BFED078CC36FF4D6959B2DAC33918B84C2823057C4BFF13696EED98D8983715E1AB085855912C2170C182AE1BDA30B35DAA023D736BDA73562609F957700FEC07CDB5F4EC76624F66977056BE553A73684408E8853EE396A0F4CEB8E093B9E1184103554D98F76692887C57017A6824DEEA8C1051282E0B23028CE4DCF5D7E3EF71D0277A195DF5555A10B34A07982DD9AAADB877A852E9687E6FAB8D4DC0A33BC75E99A741CF8CA204B9A411978A92AD1A329C9813AB4D0B78694AA500F90EFE224AD49946470B4645CB22F55E61D2C815AB875CBEC5869CF8E0EF4D16D26D26AE02736952A759A18E5A5D994745EB67B660786E20BD0095B427419FE999A1A365693B49C988288D19A719BF5A3BC33A7FD8E7B775D390E94C3CF27B357249A71AB8D50B7F6B409E18ED41B1A74DD2A6A277123341BB5B3A74BAB50927407B5A59C00C2CE266B1920C2873D10D05A4014619BCB0CDA26827E5B77130FD4CC78BBF4EB74B4F18C05F27DFD6A9E240F1E6EBB356EECC3AA9100C5C45A2C5D872E2D25612FEEC8FB59D0788EA76B374832B593709702E99E2D14DA3DA04B5C8E81256891D666C4B1EF4238587AE0CF6B4E660FB6BAEEAC86BF0BC7E4A0B83D9228F37F76D675BE327C5E5F4399A899E5097AE5EDDD8581F09C3F17949931004E85D1F114D5C8E63453ED4C3CEF48C5C6906115B0F6B3641A18554FBCBA021FB88B3E8C5F7F3A561F2BECA131AF9A55DBFBC196B8E98B8D0231605F3BE81210F52EEBC73524B1983719FF3C73C5958A678127CECB073E944273B1110771701E685076D72A01D703BA8CADF77DDDF0C34277C0AC067A716BF605C91C387C14D5117D1A7498D7F2382D3E494C7334AA1B8FE99D2C46819B82C50FBF2C3A044203D9112C17F980BCDF94173D920D467BA53203207A7FFDF64D9513F545B7964F6AD04682EED9DC2EB0640D1A4CDF2096CA4566B2797F125A5C0FF5F4183110ECAE640CC2A400C10BF48C9F9CDA4A0643893C2666A434A36792FA93BFD5C0AB4FF0E7645312B9C2F0AC1AF72CD6B544FFBFDBC4B37111C402B71F7C67017D16EBA966421F49C61F4DFFA77878476A871F61952CFCBC44B642F6AE293207B2A824834E875DD4A694DCD871083754CAA0D0418429A9919A2A30C416C5DEA2F7CEF7EEDD32F84AC8938B4EBE96E6757A69CC7CCC29D6BA86F1B636D2266831D39B7F678DB1BE872DAC6B5AE42093506102FA8EF7B24E672675909BCA15E733EE7F6F51F7478874E8B42F0A80FD30179D804CB96A56A142ED66AF0626A74B5CB6FC58144820D0ADCC54E5A8F52BCDD58BB73305629E203683A772D7F544C9CE5D24365ED2CBDEC085BF579A9D34FA603E945AE075A870ED4B2AD016F1666D13EF72DDEF9C0C79E6A7A8ADD38B7B6163CE643E5268A9413B13C25B4CA276793392E3060EA8B8C47CF6B389C6E384BF9667728D6AAA0006E57176A86079609A317F81684B01D8E64BDEE8526F8EC2B1BC22C4AD3CA7E8C4FB2E17D78F04A355592318899540E26B14BF25537EFB24FD5905BD03CEB9BD4A0926A92D7CEDA57122575D948C1BC769369366F9F1E1FBA45B84B53485C5ACB6B7A4A56CAA18FE8BB927356AAF80820E3A32D97B7074FEAE8353467B695E9867B20D150E2A019C001EE77EE0908EF791F02E831E3D6EB3DCB2DF6E46291D632807D5F99712723CCD5106EA2441A18DF1996F88DC86A04DBB94378056CEFD16F90BC0921E7090F178FB19CE7B1A580433363D3330067EF899F47A2813FB37E71F81F47C55D4B42EDC9F8F4B7F4A3225CC5B7B8EA60CA8FD881666D2AF6D9108469918BD30145FAEB4E34FD8F4071F00C71995B4F37E70383F3490B57379122C7883429E5AF94F52006F0D2634D83218CBEA4BC18A198B992763B67F66601DC20984B1361FDAFB02EB2FCE8F17979BE5B3F715813B2BA129B96269460C2A71DEFE24CDD0CDE61FE17B76ED3B43450B90A9B2A9D83F0BE6D7558F1C3FCC6689C85B11C4233835A85DDF549D11F306B8D5A235AC85F2DCE0B247F6167643EF360898E041FC1AADC656489CA52FCE2EDD7BF5601EF26F12B8AD0DEEC0FE8BE0FA84745B40C082AE45B1281B98AB79EEA118F4A2573E63BA53E9B0C49A606EFE61E1382F1E6F47C21E5CAE82BCC2FC6971984F3FECFDC222A392BA9892910AF433E4DE9504EB86F048E1902961174D1E7243559554A2D340763D0AA56F90A3AE761F9A09D17EBCC73DA3D2C03E486FBE382A29463F7103DDEEB013B1B2C4942BA1CE61C0C58538AB9995165870B1F099FECD6A03BC557CE7D05F8F1A1A466C53FC53723ED25E7B922DE5ABAC68D42D6DDA2E082F18907F23FD442F3127668135418F3CAE1FDAB7F6EC82943B896A2C0F90A6809B8BBDD328F192099A555824C211251694D3BE046AC983DCFBC970C606DE84994C38925A6814105C2435818AC97E6DAC4F710A8429E2B93DD615F7495DC64F1BE021A32FBD6497AF67E7F713F769F2E302CE8C45FA64BAEF584FCEFFB378441B5988E4BC61606ACBB704E8E4D2118D9515BAB191E19894C4DE049028204EA440CCD935750F08ADC4506DDE9F3998F3F877EF4E67C900F48EFDE3C50F34CB299594127DD609F58454128AA2D61792B8A313C4E359E438633AAF4F6A936CB04F0333F621E23C17CD5B4922903C4B93CE687721CF73CE6D9BC604A9FDC750DD76A2B6EE69E60B3FC4D338B1B77FFE77E49D16BB60E362F5F1ADEC2D2200FAF61D00928EB43030D523E8052269B00B77E336BAE8CD6DDE19316B2EAACB2F17DA05A271C2E7E1BE9F85D4293EFCA4611048A75C49EAF0A88EC38A7062DFB6B94D1701C6DAD0541F3F8095E975EC9193B1DDFE51746C3EDBDC8D422707213F256F5A15D080563F0EAA2BB888C6DD25C0EA8191A1F5161352E7822D09DEFE3AF8095CB6ABBD8C15437FF37787BF266DF98711254219388215F5C35CA599AEF211B377AF24C6BCE20FC3AADA773C19264427B6B8D11FEE7FA8717D58AF9BE8FE5A7AB390E56A95A03FF2353088E0F3935E72F88E87F96CC5545D19CA76FCE444F433CB7ADF67993CB64EB24DE542CCB23BF45583D0ED2215E583087EA74BFEF2302A7355933F87A406C96BBA1F52485CDBB10665EF146F77895EBA571B900611F8C1903D9FA873425A34984054BB64AFDA241EBD6DE7B3D058130E1681E1E89F09B06584022280FA7E745DA2E4B78A97653C49043F1FD25E45926020A2E1B6A7D78CF7DF42D9EC13385DCD40460972B833A0F83899C02C019FB86DEE45B9483BB493AC577FCE386D74D2C45B217206A380B5E9EB2D6B4B73D477AD8B4760F5FCB8FEB25CACF36E2D9C25A3D54400893D33A55F4BB6013A66F0595AEDEBD48328B8086BAABF4A58DFF1AFFC57D24BDD3F55895FCA89AE0514996196F5D36FDD887D8621113FDEC6837FE8E9CB15D3D8975F2E4DB95D00AED9299B7975CDC8B8DB7B022BAAD32C5DA342BCDB38772EA012E764CE9C3B489AA921043D9D7219304B1160F9C5E6C00C1DCA8901E7B9DFDD5728FB9F0E13DA3C64C8127ADF3A282C549485085485D91E8672D26677AD52CB9BE367B5AE6DD4D029B57F9F05467EE03100BF4A757BC0CEDE9A0CE2E3F3F1E46717B15E1A592D03EEFA841544B7B88355B66A7991C9D35D31820ECB71C3CAADDAC446BDD9C4A69B7A410448D8F240ED657EA6AEA1DCA8ADD58B12B0F49744F3435D1795951E01FC651C464A67A8E854430362C6B71DFAF259EBDBDBC10BA7B08B7BF1B15693E0D8355DCCACCF0299A156D3CC9C57D07F450E6E2985E6375A21B9054D014A4F381FAFBA97265309607371B2031B3D60B5C87D4BF08EA39082DC841FA62F760B6369FF0A0D0DA8EC810EFCCD267903DE416F34B30CBDA92719ACC84012E4085D40983B16F97ECFEA8B89F9A9A5BD3D5B1CA6F3BE7CC6A39E70E878CCF834768AA8A28A53C41085351DA189A04C2A1F8269C074896EB0FFDAEC0F277EB3ED9C153A45C3C54F971B8120627F7C918FADA8672CAA9449A0D07C67C9FAEFA1B5A79D2E1B3FE9C276BF1464BE3A3F2D57A4E6FEC9245B7ABA207A3F963C0EBB704F6AA19CC436769C618B88255E7A1B000293D8A66FE1104939E251A68634024739B328454F3FFB7D8D5EAA34A4A4AC7210B5CA3E45E53367AFE0DCBFA3F3EB1BC02CCA0AFC3BC5CCC21E9BA348B03A06A1F5AA714FC27403CE147104FCCD8C2901F2F4DEAB5E77CB270A00B9E8F18C20F5C97D302CFD0EC50B755963F6ECD6D2D884A4D4E13FD02F35C76E5E877F79178877F1D39064ADA6C7E60E7B7DBD8285588839521904A8E79D0DA4CA93D6AB19E0D72189723F5B11E6BDE98A176D3CDA91F225329959EEA9F16402EB768464A17025E8AA9824878DBAC2BC07BEAA5BAFF91B5EF8781B4FD971B9ADF9BD15D492B59834731D25F5E0FAAD4DD9236063AF6DB0015B272A49A498F5D08E05822B08ABEF682249C9500A768622C1BFE8CF5237B37BD82E80822DCA7E3C6D306C772D6F0DB1F2B2AB52E9983FDBB9480422D56310EA7CAF8A166DE22ACDACA2E83A423F7AD5E2BE226322302B6234EE6448882ADF556ABEA69834E0602525CD9304FA64CA2D909C4DA4B87BA92337CF06CE07409B3FB7D2AF1C6D0B622062DAEECB6353214BBC7B99235A872819CB13A39710C3000498F6681BA086A939BF983BE0856436DB561791175534261FFE5F93064521C89EBB743FAA3E87535D82EE5780A726696E19E8C8D961CB78D89096A303D42C181728D306FED250C42EE102D2CE0CC6A6915367326D38E171C26311FAF2A6345065BC64474DC7BCD54C45F1BAE38DEBEA8B9949382491D47B6020CEABA79D0A10ABE660A9F7423FEA9B9BC431B451A2911EB9980CC6D036C6665B998DA248611077B61C862EFAA4139610186B683AD6F9BE70F418BD81D6B86C8FA49B65D5FAA3F72C6C9B5B511212C2458E9D98A3560AF6FF63ACFC684CD44167E7310D765924BDA11EBE35DDF9122DF070FA66181043C0B201CEFAA85515EA926944733003433FE4B5A8F716BD08BE6E55517E3776AABC5A7110B99919635A05D4E2D6B7707341EF21DCC2DCAE31C2CB58141BAF1BCF85300BF3A3553251B1888595588FC41672610099F6FBEAB84E1475EBFADAFBDFAB3D62AADDE2D4428918C8BD84EC5648B742EF078EC6FCE7DAD9E687A7BB7A8A460A81AEC87B6951788F60F3D3C59224AC2DA7655531EA3CDC2B1637445CD1EA1CAC832710F2665EB834496903C912F1012AE479A58726C931A2912EDA1185C1F864CCF6C6A35F80974CFC7BFB1BEF7D59E058DA1ECA4ED99349CA70730D9BA4B04484E3367CE159F4F333E450BA02FC13142C65C646067D480363A7FD4483DB315D360E07F28186561F10253796DCF6E1C7C506D8DCF1E6529CE5C7F3477915287B8B3DB0F4B3D81B0542B83C590A2DCB56EF7669AC46BC8AE702CBDAAC8BA8D74C7E41C4A85DD13E2EA32F998CDD5558B0748EE04051A6BD4FD60ED5E1F6CE34DC4519BE62EE3FD5CFB6BB43040C60F5D8BDD17AC0751C563CA4A2D833A0E4D9F63395EDD32E1681EF4F555CB7D361F2BE3276D6D0B4687222ECEC79601F2525137316660F1F385F94A22F28E73F43192E12F758C6085D1CA9A4FD0B8DAB340E784C9C0AEC8015A59B3CDF3DD102171FF86A24A42D9D61AF7E02F614B4C38C73DFF03B0E5F3B7342B724F627A7DB1F9FC9B1DF1A1F140EB35AFB365FD2DCCA81648708E0A1D0D1C77433B83C40BC9AB452D8E18F54F0FAE8E0DCEF3102E7867F5146E4429F6268AB31240B19FCFF903A2C4937694C2BD858D998431A8C12FB7F5DB52BE0F6C70D9A323DAB2D59D48123F77B43FE66E4248D27DB199CFCAAD8EC5154FE8E1387B56037AE4D60A8F033E3354FB564FF4CD44C334F68AC2735388F9E542D8DC7B673ACE0333B3B2067DC808730C2352A77408EE2B644972495A372D97DC87580BB23F774DFEC4FCBB70277D69D31CAA811FD66D9BE38EBBDF88CCC8306F232EFA31DB90B7A4717EE2A3D1BA1F28FB1522679DBA0B828AE742F71C -Output = 29B7DD5690B6791F21B42116670630DF0861DB7793B2D0EDF877B4870A2B19746FEEE2D761840E32E48E898FA15E1AF1AD6198248DE5428F7AE1711695DD9C094C17CB0C5D7F2DAEAF898A69593BADAD5979CFC8CA48A2D6E9244FF549DE089CBCCD8639C5E436643E316DD9DEFB9963407CF2E8D219055C78699987E5676DE4CF784668AC966AD00C953E83F570C5A84090A1BCAEFC38FA322FD968E41BE59629F34A14010D808C3060FA35B745049A60D675D180D50E95AE96BD82695A25167297A1D114F48BF10BF5A636D392F82E8AB3F630DEB722BD8090C31B8CD92015F10781900B83115EB03F64254093D10BD12EB4C6F5A679B08321C9BD666D171634B49BB511EBEE2AFBFBC4EC53C995F263CCFF0740944D692C6DF67542A2E95CCF865E33EFC697C0DD2B82F3C37C449EB63F6769D7C5A7AA7EC7F072C5620A4E5064F4B34ACC1F0219C325388800482F406BC628B049374D21F35706FA9568A50B6DDBC0212916F10DFF2ABF5B2C0D7ACA5ECFE7706FC0E11B482EEF750B857C0F602DDF21C5642CCAF4D0E780958D0885C1936DA7FB744A8F948C8AA3FB2E851F323B9AA0BA6CCDAC9F00E2B9A1360D0D0187CCDB21C11727A35ECC98E76446BBCAAFA0667217891352FB20AE87059F7838D667290291A5B713ADA1092FE6B54705E4D389777247F58AF2D448D0AE5A26A05AF7DA763B14270024BB547183607C0A1C76C058AB3808EC562FFF40BC3EC79824FF7A0B0D8F816B24ED40CB30675726C5837EE9159465BF92D0D01A28E675EB336B8AA653CB1B525145530FEDD6BD4155023DBD998155ABF9D49043582C90605BB0DF943A4B266C161EB5A0C6A45353D89EF80F5F74B7D0706E9F7D409E8163E44268F2A232E615F39D21D991BAC91C4B9513A8AE0A07D89F9DF4015019384DBE2B58BD32BB56C4752319BAA6A182C941E29EB61A2C2A43BACFEF81B30AD6C4E64DBD63FA849E9D13032B16899D263B695807E04874018DB280C4938EF3655FE4D0C73374CB7122F35A4499EA0C41492E87C5120FBC0F352C22D505FFA94BCFC9665D1A25AC9E28FEFA2CB1CB2580F4C7781FB150648CF7EDF96626A9AD32DAAF869DF0038C8F8BF89342327E472D1341BB92A2F60DA99A761C5C582EC041AAB0C30D5BD4BDF826C0F53D68C799A0F68D319459E9FAA2ECB825E424B62B2D6EAD49897F63E2B0B58AD8603797458E0A867AE5590C79729FFFD86C1062BEC01BF74897B7615BF95352ACE11CA91D79C9BE7E5E10C05A1F66CB5FDBFBB492C25A6B313821F8EB2E5483612EAE93BE3CAEEF340A5E715E8C85691E7E65F7BE30FB47967406121346A864E94878826ABD06C1B38D8FDA75706233B286590D8678C23AB85C4B4C0B07949E2FD93F6B93C12C3F172E25DD178DB06BBE470D166AB8D4AF266C604122BDA72767D9CA3AB944A89580AE6A25C4F8AC2FE67B6613F5E03C1B92DAEA2A84A0DBC76B90045F3E89E600B006EC607EB6002216DF22045107661E48F5FBAE18A6DDE4D9B36706057E6152DC28E5F2BEE17812057F0C6157A3C8420EAFA5BE83816E5E836E25059AAF7E8DFBF9551A5F5E5A3371E31856EEBEC0A6886A87D710942228FE53DCFCF4D2F075FF17B913872C36DEA0FCBB0CF08664D2E1B464C3BAC040E6D6A47F69BC494C4942ECAF9553D150F202A57548195364A229792C0D8136A676345FCB340B065A51EC358237053565C1E7BC2013C01094D480D9F6B5D80BA08B32FA9BE2CAFF496E48545E9062DD68C2DDD3AB4278C31167CB12B22AA5B7FCE5C5B0601390E9B3ED81B67F20ED529EADA36A25D65FFDC126CE58EBA566F27AF2DF84485D0AA047C89E40B93218D9DC8938B38BB9F94A67C174F22A99AF815E288927BDCACBCECADC65E660D6C5EE5C92C93C84D8CF95EC8FCD41C96FDA9A60718222D29650DDA785966439CB5E8FD4AD009F97BA4E70B881DF726319A0F0ED34A0E75BEA26831E659F53B685F475C3BB88BF171A92740F9D137A64E04F413F1565778915A0887CED9257D3901C09B9FBA90F42977486ECD9887638503BAFB959420B36370E286189F448214F9A7452990117A4E40A8250872022E72B5C126F453EAD0DC3270518F548E2D3B82090EE4FECA91D7CBF01E4B420E41AFC99BBD6FCC866B1860E3B258AE697CCD6FC1BDBB4C18814E58A1C6A98D0AEEE197933E65324F181CBF87ED0F0D87405F7FB865B170ADA773C84AF81C274A42290D5D95D51EF9BD791B05D016002306CE8522B125E50D50A11BF57C768A1E1F64389F701C085D7B0D39BCC004CB0AAEFC287579C87CEC2EB94CA5647C711156E536538440F33A85EB1F22DF6DC899E5B3DF6C92D39CE9CAEC14F4A2827378D964B8711F230C1E9D6C87791DA1F65AAEC4D81ED7488DE43FA86F18BED47C3E74387084ED031D49D94BDA1EB1317B62400F4C3BA147A6AD29D25B7F6E59B98BB7B6299569E582300A1A868489EB3BCEE8EFD7C193EAB1DA0D54AA53517DE0FE7095F5A0677092B20C0C99942F0E3AAC2741E926A0B84D1031D0C999DC1E9B8DDE18521A1D65D2F3C0053CD278784098FD240F70F16FB8B6F7A212843D19DE388D15B80305FFB906504CFCC8B0C8F05FE19EB8974A99C97DAA2D616C454BE333E803B39E080AA7FA8652050944760DA8C1F974FF9001854C0DCA1AC2E4DF7BA442DD60C02B0EF9F79FD4B6C199662577680F022DFA68B2A0B9491F4A9E44EBF7EE56CDD29D8191A2CA22E4089CF3F3953ED7B913BA1C1493A4F15B10CDAA0AEC992971D1423AD1C6957E63A3D46DBAF90F254347B1F4DCD947FBF01D6ECE01AAA2DCF5BD14D0F2B9EA3A352201DA66346D5EDB03D842543E8C4CD330AE2F2CF43CB0F043364CAC020669863442D9DD4DA1B6D3171A766F835A8C4A0CA891C6137AC45AC2F45BACC02E800EE6A0A8A17C1A326752195537F5A9E94D7D363CBEC46D5ABEDF2AF8198F92111124B1FA34EBDF2DB629DA0D81FCEDF6DB16B47867B061BB0472B89BDB8B9CD581D472C27611D604C2801CBA0CD22516499AC370A58ECFA7740CF4382FACB41CF6EF8283E6E910F2700F37AECFEE92EA043E8526E774DB7151C63624967C83BB852FA5E3D997CAC7D34A3CE87DFDAE7A51B053E96771D92CDC330122F8276900498445C3DCD106879F04DFEBBA5608739D84E5CBFC602B3E2B1775D38A2BBCE8C457E13A85497F59526C0FB3892C0A0CE06DCBCB716BB39903EEA1A4EEF760E82A25F5ABFC488EE40700E191BFFC58116959557481CC1ADEDE94EF0582588E435F701151F2125364D6A6D78A4B1B5D8E6F6262735384A517074A6D1EDFF2D303C515A96A2B2B4B9BBBCBEF3FE06070D0E1F4344526A7B8F97A5A6BBBFC7DEE0E4E600000000000000000000000000000000101C2B40 -CtrlMu = hexcontext-string:9C974FE4D8AA2E867B189FE65F594C745380CFA2CF710D96185924162100276EE186CDDBEF303B914863AB836CB8FFAD56E0816DBA72356A733F14143B77EA269B0C9F5F06A354D5ED8A1505DB80D62D6E608E0B26C37A81E6D47F4305291B5E69870343E66D0DE5EBA83035F41B3EF2831A3D57D553AD9E4F85CC1488407D1DC009201A725948ABB7635FD462CA06B3E807848347DB6789A1769C2E19C5484B7C9200FBCE27FA079E84323DDD4F15EBB3E6D9D18BFAB0C004EF426C60E630EAA03D2377B5BA99C2D80F7EF79C6C79E4E3FD154AAFE988A009B6B568E9D2171C7CCFA95633F8E8C93088BA149AB976BA572B3F7703ACB94A93576F9E83C94A -CtrlMu = digest:SHA3-512 -Ctrl = mu:1 -Ctrl = deterministic:1 diff --git a/test/recipes/30-test_evp_data/evppkey_ml_kem_1024_decap.txt b/test/recipes/30-test_evp_data/evppkey_ml_kem_1024_decap.txt index 8af06ec95f..423c4c4012 100644 --- a/test/recipes/30-test_evp_data/evppkey_ml_kem_1024_decap.txt +++ b/test/recipes/30-test_evp_data/evppkey_ml_kem_1024_decap.txt @@ -2215,70 +2215,70 @@ EncodedPrivateKey = 16997ff80976d1506b23c012e387ac6ca0a792f7481ac3c9775317ee3ca5 Input = 6e78c7085b62594c22b881c61e63674892e8b15be6b3137030cf91834ac0126295c6893f0c386b7670821cbbcafac5d4211cfad5c1f75deb8e7df047b950fa504c189fcef6806e16c7a447187a7877ff91d5aa1f89d9f4c2f8c726dd7cbc688e247c929117e01c8cf93e62440ac3f9affd27ecfd76d525dde13ec8b3a6686e25cea8e46fdb3a264b4e1692bcb1cbfbf6e750a1faf99d8864c1a9beabe0d436b7ec5566c92be999b165ff4f30d6ba43347c326edf4a41ecf2d35cb825bafe62184cfc28b30419f509b631f9affdca2b3b78771fdfb006f5b6cca6d0f5522308543b4a1fc65463d8b0ef14fb3fdc160178692d598e59d71110447fec3d02a58556bd1d17d212bd09d4dcda359fc4ee60dd2f0c73db72ee684a28b550f6b17e7dc8e2bd1867076222033023851676c0a55956e14f2c67874217e5349918243011ace52437a127c1a743a52c7c6fd8a0a007d5d020ec1bfb9f98b0ae36561eadbb5e23b7202d909c7d5fad270542c2e57dd0a54fe7179050b7ca81d72fc8c4f07f45fb2ac905e209a3ced970bcf5334daf441a0ea8f250d41be94cc33d96a42a067654f43047cc500214d0a54920f61728b6e95a014926f03faa1b27f6f5cb4397347dd0744c09ad92608ed7cbc0bae29092d6846fbe0fa14a38529e00c165a7ba098c16e532d43a8e4bff1490c45e0a33bc02738b4a1958cebeb39fd30ed7026b3a015863c2e4a2ca00635475678132e7fc114fc8e891711241942b787384ee22352b2811cfe1a22fb7e8f2e173df93e59cfc98a677a136ec29bbd47bc66070a7a8fa3a709aed2123ce55bf27ff2d23eb87b9762659d16ced5e24b7e825e0b4c2e8a6b6cd1596e4fafc06c9e90a8f0137ad182662f54288da8b590d42c6fbf9bb14cc8f23fff1abcc5885ecccb580d93846b2ebec01bd528547765fa2c231dc1b5ec3b3263617d136a102f6e02458444b158162b80e9acd39ce90db232582ecfd679029c6ed4d5a17f28b4ef2a120455b5933b51d3751728ad07e9d1ae3dc52d690d5838cbfc8c8d5bd7284dca1b753be3cc485aff60a120eff28891e902af0ec3358785a0ac87f99f18f268d73c05ba725de2cbc82d2918f1694c3f6c813d02f341c9f40a7c75bcc5984d5ecc1cc308eb16a9c1971d4f8e6a8d5ba59e855656543c0c7e5b7e49a360bc31c9411da0642bb815703bb64fb550f19fbb0bb993453ab8f15ca9ebddae7ef5acf2910f130f95fe1e4ca602f7e09d605a4dddacdd3cf5c2830a7bd1fafa1d63f7cf4ad511303ce42fb6348397df469a813c822527b933747f8f419177caad0787b63570cdb807a35a190a46f2150fd19c18db91c9435908d79449b23430c1d26a7354b6b9d1d21f31d160e767681580c770bb264dcc24567e88a8bc6512831fba35cf6aa4fcac1040b200df1c60b88a3d7e1550f0a27e8232dd88a9c751624198f811ddbf1c2a833c58b91bab501e7cfccb5374c21482808be44877ed51389234f3bda65c44ab5781da9ee3269a0cd4a3f13f50ec1445c859fc164774cac725a3b561bd63a97170823fdc07bd6ecb46bcfcd76384e7baa0ec3c1f4c89215e26b580962502a4c06aa26068c041ff1354ee9ec07da71b163901784ef525c65bd00c403a9445ade4b0bddfc30e04d278b4873dbd1f18f4587cedf870d958b16be02ecdf3a5cc435b49e0e56775521579530013aea6a081aed4a5774bf72918526eb290a5bc1ef3f0ed9440863c1133a70b1481d46b6f0adb352b3cd4e50bba138570b8e5617e3a10b6382970ace312b95d87f5e8a6baea10d2ea19546acb5fcbac0d20e964b7c0bd0d1825d3955971bd657c316710066d81ccc421c786f7d21df4e748b47111732f1851dc992322d5b50cfcb66321b46588b39184c503666435d620eb03a3535b9611e7aac801e9cf90ecf7671f70eeec6103d6e00a2ca5a6a8424e645d4fa89b058b5f77441437e40bba596d705ba522fae5fb1240d9f9e25c9bcae741b514b9ff33d0132db5f06a73964f05dce8b41a568413bd7f4fc78a4c7dbd2f5815f3dff8f25b2e82a508f5f2fb02087bd23927707bc729574777e01ed0c93557867956d8493c1cd9dc86ef3c1e48986be905101578c8e7a11ea96709929e5dbb1560bd4d9f9acb7957355e09fad7c97712e890234b335fd950e25cf59a4ccc6cd461e6ffbbc43026faa7dcc6df33a8bc5f1dae7e5 Output = 8918cd0c3eabdb8267e24b79272ab6b67c9ea6418cab15e2e3070f6c747b4dc4 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 EncodedPrivateKey = 00208080e8b3938b09aab715a0b7a09314c3d2aa03e900528a209c655886bf0180a0775a1ee133e543c17d7c24407131f0b813a9287c5c9939d43ba2c1f064015c1babc910d1024bfb46a3fbb1ae13dc5d8bb4576787a592495786a53d4c172cbd3b2cac6a2f5ab68fcfeb2a67a997d809800615c043e4bcc0985de9d671e6e0c8b071a20264c457c13b1f4734f234142e86c23170821d068210b29358694d8ff27e89c59264a315b6591d97d90ede633b68fbc36ca96b823a4bc66144b541cc118b0d60a66c89124d9080ae30f44b9f4793cfac65ab8b8cd65ac81cd95de566ca2c19906a955a04047052a699e8a132e2e48aab916278c49ccd1ca0076b5254784a23f7a8c164229bdb9b46e1c7bd4c74639053cad5226c598918687fbc50323f086238366c4ad9172346626b54ce142053de67ce8867cf599587d0a47aff0a7fc113140c18c40bb31e2340822cac294aeb3a02652b424ac9f1008a592ccf70170246e689edeab03dc0249ba59fcc6477fb668038443bf9a743255310df11b4c90a97bd212a74d5142bc6461a135ce7376995372a1bf919e3db20f22c683f488395a95e31ab13aa707c59f22e85d892830bb550395633f6c87df28401865106b5cffb75729391767522ac236072250c6f4dda196a90bbdfa183113c5fe2e31ba1187b4f682399f3c6c0288977904ab445c0c1b9caca030aa639b35029657c1608e3a654cbc39f8f096414d278059a6f56c8c838b1879b00ceff668190213eb15184a57706bd8c9111667f52a656d161bcb5e7cb8ef5beb6756371ba4297397eb6d0c850aac1e01025001b71a874a25e3ac16450228dc33691b3112de319f69ac29f2a1cdf02a0cd77319931003910331a6268f42669f4a90e79bb820e5c98aa252dcbd056318a050ab71f5d60028fc41594688cea4a95b32529c39c582ae828016644faf4b7b1fa6fd9c305807c43dbba54d44273669bcf956c197ea3462a30be3aabb1a6654dc4a72bbae53982ebb986e249d9438d66b65fa15b723267ce1fc1200bc26656d7c4e1839e02927a96304460a34a9c0a22ccf15c7390afed4a612ef236f9d00c22d04cc1dc362c08afd0a16536985f69f6a15d6585c410ac7a39599c683b9e67a33ee299a5000c7e4acde611bd6c817b1aeb1373835a245b916620be6ce8093f88635cfb619a963c99785cc5c354e5d025f954071e380876408fc5ac7fbbeb4c532b1f1be67ebfacac4cf907be9485c6da8da380809ee102af0c98beebb088c13d29830e7fca4dab8c1e8cc87a3b4198c50686c82626c41414d50878f403c10ac905f39a901405b93366a575338ed7d66c0a27c9dbc4af2d217688dc3909db8878000af307a989234174363f3cc35c25a42d7361ccadeca25a484a01967be2a65bf4998d57943759528d54e498ab18514a5665b87c98339c3fc01baaa2953abc1aba78778b26d54bdb2ab69dd705d6953dea404adf8c82d29b932e144f48a2661dc2129e6a2a1bc5242552374a504e0d135e6cfc9fb91a492e443c608c6e5342361aa8205ac744ecf974b667a6528938b6085492298e97ea827d5a4274ca359a1811c71a574dc986f4262b2e29256c4b52c9a22c3f168988ccca62e0b7d8cc8d1d861dd052bd9bb622cd8b769551c2307c82aedc92accc3d2c67c3ecf8341290af6c93a295fc027895809a081aaaf3cd0131174c8605c7fc29ece47036866f7fc326f7c947f70852356410e22700b5480897f288dba24c494685ecfbb624bc189dca10d9307595969145b21ef4ca1c435b3d39555434e133f8ec8c00dc49f02788041a6deae40ad5c9a3198804fde6230dc25b7f86a86bc00b43da73b5b40e3943096fa4540a019817881b4421961e293250056300e273f3d87153765ec237a79a16ba89a960fe42aa887c65fae65719766c44b2b8a0e54e97aab5febb1c194939e11928258cbcad6281cd37ad6033b1c9982df721200e36cb70326403422519f3afc3451af15969c2b26957c452fb136db18357516617892214c758cd9b556a827434c9510a5f6094bd32c8633966eb113f9e4902b6306c87732b96542979159ab49a170fe71a23093c1aca70202287d8288fc2f56072ec7aefa293015b6a58a2899ed79d4a09701ba42d26c599d8a2164204563fb90ff7372e9d76798256925e67ccd5ccac6d69a85343825b6a20793095e1a29d1b526e183611bad90cf6440bd3e79f847c6b912aa1919a9e7d9357b414cfccb206180067469b294b2c4233960a40e17800ab0ce483c40b653392488df837689fd72da0daae74575da747527b2a116984b2adccba04000ab72402f09c749341be42c79a5c8198488124fe750f66b82cf272826747c68a946d2629a48ce0a777b4a9673ba9c3a2a402305506f4b65b65b327e62de16c696bca3d0b8ca44013cc88d9444a83549af17a3f8270565359b168ca721027479a6e60a28f11b33d88da4faa084b576ba5bea09c2fa8a68c0aa8a309c96119aa52443bae570abbd942d193cc8ccab6e5643d0e362049f1ad00f98d173849afb1248ee2a67873950ec849e9b7042b94222b60bd50720b94d7317053cc86758cfc0bae9c9856c0c4411e74730fb65d8b7b838426123bf68b9804473469c6d8717dff450fcfa208b8f53e2cd8987919a5defbcda5a422ed82b495c67b46264106a613ec138097f05a2f2c5efc2076b9e2475ee162a5e7242cea1598088f8146bc8ea65909723fb7a60b1db157a4f43158457d2d157a1f980925a396401450b670728b2c7ca3aba3e7d4b4fd34b24caa87d45846bc2104e95a1d9a5676b734736fb00f7b3241160c2299b50e5517bd4faa859b79c8590c4322115a7c724f0767c056620bd006c01b5b87d80091bc483e5d341d14149095045d0648acabb46053e78c84045a9606bf82f6124fa9a8a9104ebaa734e3720eb6921553e353e66152f2e96adf34534a06aeeb677fc4f901bea148d28411f1f856b4d2cd261526e3a8139788796690413a50251dc1763703a42ee708f932cdeb9b7ecfb2c7d99002bb93cc248a133b9a4c8e910a045669ef5bc75113ce12f7963d665d6662246d383767f74317dbaaa3d0b855bb0274815442f0b66821cda6aab15672192d20c6aa8537432699ca8a22392a855323ad70f75979b56b392c29caf9c072885710c33967120aeef0bcfca1293df8181ce50dae21577701b1fa216dadf19fee4c35e0d435ffc83de3f92c2b276461b66398c75c98d92628b32a2ac3b571853c4a142bd5e81a8770c9d9359c91ac41aa2b4b063a9bcaf4592cb6626c213bc89c6eee3b75c59a21d6d748825b336f4052c6bb79f4ea13f51b672d1abb32887f1977505a75c13f0b66db14b56956050550ab0d85a814640dd3a36a825682c9cc6d6f13cf132780f5fcce87355007f9021ab5a5a3a69369c7876a5158654bc9f9400a1de60e71e34a370372f24cbc84166ee68b6433b6911a76bd78fa249e850bab6aa96ad820e0dcb438fbcfd9ea81f5f3c0d5d53653ba288815029202807aebb27402660e4b3cdb609bb7145dbc055fa146466b121e673359a8465073d99b63e799cafca95733938dfc2ad7d6007a36a8da027ad396618f1647b1287094737fe518b779f238b1ec0c9351b3c408b8f66b27f5262693826b24842a9153a9d205a7593665fc172c7c835354daaf90574686a8ca7fe5824ab94f29d6a5ac87cc40b999e5e7ade2744e1fe7048e38c804472579d93309986c28962b06e80d0952ab10d1cf1d945b99432ef5074dea9c6f4ed97959fc904e23a3834cc30de35f5350656d027a1e6620925a6840a337d14a82dd524c2077302fd6b72e97a959001d3d81768ccb7937f4aa07f00eef0aaeca877999e5598d30a81e920e2e8489970a31fdeb7d921474500835a01530e0177a44852cba38c3b0c297a0c5bc73db986d24cb0b323402d5355b543468f948976284dbcaa1c87c8b27cc62ce2b8306da3a5e08b0991403e7b0381adb0c897c7a994997a69ac1f5092f8edc480e77a82ae9bdedc724883b5eb3da56648979fd2337fb42aed861859aa6165a800d4c9b964e70195927359378073a84b80219613873a164324a04144c4a5b551937c23ac75e3a664a773966b512a01f3a7a60ec1ee06a068933a8ab0844511488f058b2c5bbc1c8dc07e32b267aeac8285543300bc66f8514ed6aac59cbb9be835b3ec68987a5cff5791643c60841da8c172c1ffc07110c77a43ab34621c474a60a385d153d79831922638740657030481146ca6843f6043cec1de4b0b307c52b288b98905b918bf3af0e698b4ea261db5895f7d02ea0fc59156090609764d09b4a7ed5000000000000000000000000000000000000000000000000000000ab115291ae8961b14e3b7681e82897a566fae64d7340c19370d028ed1b71881f11536217ef54eccc82ada15ed86ba2003e177f270bb5aeee52f9436e31a379d2 Input = 02c49972f757b82c1f5e7ff048b375cf05adac485075ca5a1eeadb615de1306d6712f0cfc452db395c57039fec57708d0a35b7bb238d1e4fd58301473cc4737d72ceab2b097d513ccd17a7f54d1fd145bc28aeaefd2157f2a8dbea391cffecfc2e1fb86c909b45e97a39b30ff59f176b2359a92cab56cf8d04ca42a08c70051c8d9405fa9aa2aaf5724d8b2a00528b7818671af4129c527bffa74702f02172bf51cb8e5b7c07438c785329807bd022fcb5aad5286642b1fbaf976af9816d3f0a3fdb79c2787f6abc1dd20fbb2995bc2a4b2408f5900c68a60f38f78037c3ddee01a3861433a7d9eeb5e7a41a56d2b2a11615d8ef8751d19cf7bc5e5e46b0944dfa61cee6dc16c490f5c7b62ebb6bd9bdca7dee23c3bf1529a4bf40977b307e945efb6451d4ae1c1aa507e30f653ef476c64610edb39201492434dcf36053f668b43746cda8fefd4316425c92f97e1900c62a91004405349c69497438aeecb876ab534220a4563138ceeb3d4edb0d70330ad031aa82dd62e19d17f62bf83dc3d4e2c3850d47efd50edbab06c9661d1ef274e856d8ae58564909625de2acf771334ffc3a3d7a0b1a382e8a17c1a1dc0f29401d9a3dd198a4ad70a740700301da40b468fc4232ae841489a1169170d5131d9b0a036149eedc23f2abba55883ffbfe4788c887e3248bc1de1b3677f286f1269d110d574d01199524d93263517afb76759bcc2728ac595b004508946618b55b0ca734431e85496f07e153f9707d876b6342cc99be864d9d603c645bb9731890d497d85d955e2d80e2e660c93968873eeca1a51157ceca558c0544040db61fb4ac4e20effdccdf950feb214971dde984cff17a75973b8d3a8cd27c92a8686fb93564def326e3cb617411892469be218d663a009c37e2d573b59beb4c5f62206f3a0df818608583e73d12366fcb1d685650d72ca4f533b928c0b4772ae645f0b0ad71bb8313a601723b8f90ffcc53dfcda9d092f8931ef168ca2f53d4600677833b9443fdc05db07f80c03bcf6e364fd4d85c89fab6a08cc9399b10afcb908cc4b6b6a3f6a4725bcf8de94e6515345e333a8324765ca69ddf9c61539d36c67e91ced0396ab2adc022ae9fa8e41d5a00168cd8c9ad0291f653af63e67b90ff2d448fdbb058702c551d323f5916ed90f6b87e354944e167887c5ea4b37703c8b0a94edf20d188ea989999deafe0a6de995434275b18d17a33b100032f2796749a385d972542dbc9989311068e84f3629bbb797f7c6f1057d99185009b5ac0d43d7b944b2e5f528cdb26ca14d995671e72eb725bf2de60289da1f06d78b137a79ebfb75425446c20b4310700053cf3ad58ce01cfb4d97325a27e5b5eda3cfe1009cdd186313ec3d16f005be47c8f38051cf2108b85ec43aa0d527b8d3bdae4e0a7a711c6fa69998bc26a9a8d2f7433f24f79c0dfc74a56083b42de7860b22c45f0c6e31422080c7a21c8d672fba60ce7652a90a3134f54594eb0fafe5a953e4f179ab06ea6b9795bc31a4f6a7f18bd5f1800a5263c48da4ad48ceca613fadea7741dff9d90f6400aa31519bef0b01e3312a5042ac35362df5e61c8e04eb52bf5bce0505ea7233b516321a08185fbdb9ff8434b4c6a88f880f594d100f46924a26f468c754d6af07f4868cbd7aff2caa53e5146df4afde9f7753484fa8be36baf89ebd4741b7260ff1ea398d59e503f5fd6c5c543ae1d318dc1894a48025c76e872fdc3026bf33a91b4618d1618554393eef6f7816b7de65c4bfbb55353cef9a53ad35340049ec65ad5af27db6fa597eae6499a3e5a192ed731915f6ffac811e35555ba5ffcb6628f812bf71a268620c161fe2a571921f5bceb4d0cdca776c7e52f68140845f455d247cad416c4de040bc37f5421e2b8bd6a049db84f0b3c807c3bb9d47cc7ac3ae9599ce82cebce8243306c0f3de6af1526475387c76751b7412a227571450599120570cf3cda19264136e0a93b4d25a160dee03d3d812dbf172618f58d09645becacb5c287b3b01ce4d1121272747648c50112c44728f66d86bd421390f2b36ed7e18b09a985a306ec52f240c0bc0957335483439f146b6c340f7e062a6059b1d47750c11cda575f8a2aea78ee09af0e06dbc2b2ac2b2bbef17fa108681dc90a7b970306522e521aa987e3ab6dfe2e1b3c6d9fa68897efc9e998afe55620cdbe9ddbbac8a0e22395d5628a Output = 6e63c5ca8af98628c02c8f1d520615a1a2c4824d5d155a6e51d181e8eb44c7fa -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 EncodedPrivateKey = c5f6c739c640b093956cfb9d54272b3c704d3b364ff1c68510b875c8c29f30051b5f60b53f6341082252746b8d4eb52b3f77c818d42ac776ad393072d458a28b186da2b61cf64bc6d8b424afb49a3b2528d4863c876aac69b7c7fa95314dd36ab5f021ba8c575ca458c469409b71b31f3a8e371937405067951c084b6a832ab321642c82f33395b0701e5a677c3c783a47d7a6e474af454c1b31b174ce5285e90608e1932493e44bf48b921d6a58b1b86ec2a38b8ba2a1fe884c0fd608af3986270391d1a42843637d75194722d31bc81b2b507ccc0fdb309e59549a874d09239bec5a41c4e9bb48d6968152ac9d431cc3b290371296b8056ed56898b272b948e556926478291cb0eb1bac50b6718e98b74a1777e685b7b6d7cd6b22bb5846c69149b4e7b292a4153763b768cd5a67b65c3d059464ccc123ac086f9f41c3395a56ff3152fe149d76ac2fee2079653326bdd82dd6f66b6687a7fbe00d9832b09135756c5819b1f66dc44c7b32c2496f63cf077ab51b8626d0918030134b8384c565f0715167b21fab697e84c6838a71176748f12334078c27dda3133bd44abd69bf631badb5f2664f2857c033102ce8284e4b2beb9095cbb40587bbbf457054f4d11bf938af207c1cdc5217b0e9797bf9ac88f3943873c8b66883d2ba5ec7e6696d50a69ba55457853bc526819f1a6fe09973fbd19832312b554653b8441e5eb01884e94a355732e3da645eb849f520bb2bb4327d560612852152f8cba2f77db8d21922da08e60bb9e3b39b9b85bbeb9b1715982d292b8f1017cd3e60447278cc0257898575a0eab1408122bb3fba17b62a31902a567a0821d42086aa6417c259a1dbc93b25003fcdec9f6a5507b4b732a43c444c5825a05119cd089fb2e569f70b4d5e6919faf15d6eea641f5a2875763f42b3991f7c89fe473cc057c148ac58b6c88dce537da8632c10ac851f8916fb7b6ce89ba5053b8d95d29ea5d36c91981042c4aa1330aa098a6ab256ade08592a05c95021606adea0ab637824214009c2b915be450a1f7434ea2c7f562a4fe21139c2652ca8785af3208f4927abae698dd435e90e7474556af9b907f6d73c4ee64897dc74c6a876eba1b598e784b8094232dc62bf1119ef764bd1a3bb2d4fc7de069273a223abe5269a1403873087906db164b58435ef41d7d78b36087062419123c8b1d54da918f34920d3302ddaa300797b32c1c81b82798e421ab2589964334714a75cc84548031d5810fd87890a1932c98bad37c860bb15663cc0e91880af1947b8a26be9183b648b714f763b81652786682c210301852776aa673a1fde470afb56eb0b0114895638c609d8d55585d68c165f7aad64c1406a165788c3364667f0a3c65aa300fc4585e959abbc5e1b316aa108a1cbf703965a74475147a2d323b7295d185571000e43b9120b76fb0105ee7a385965026e8f8309d4badef88b433a59090f88bc4eb4ee2f6c1f0d880057b477e628bc35b023a4c9ab682822556afeb32b6c9088e35c107e2a43506c43a986a0420f5164167519c4029b47bc81e93c1ec149e6083b13589bd2a9c64fc6247ec323b8cb73cb9f9ccfb8bcf25617a87a3c2d8b5158ac8661dfc789e92cc8cb39ba3237b6f13c80ef947630578d2d213f1914f94c61429bcaea77c646f1b99d35ac8009907ccf604c1211ddaeccc2f1001b49776df94560e5ac35e0a7ee3f39377e252d83558d6e57651b0b3c0365e6a133dbe3002270a0bfdc524e5d298b42c1408e17d155c82d69c256f78a69937843491153ec2117ac40370934d28783a69d0a02526afaa8600d289c27e9481cb737cdc4b9ddf53caf313b3c4b862b08045dc38428b126622d77ff3864fa93919427b049786042d234429e9858ce7b1d57a2fe92979851b9d4ca23fa7a80aa4738c9b777020b857b8fa2e442522423608d51b78c574569b9746e441bed403ac21391fe327818dc81355bcb2f5758320965e10946cda9a7c1d329f7c1720857c8751e57b87186e8dc21199e3b7ffc1c4c5607cc3c258a30163131c5db5d96e2e8c2f209419d5a03dfc618a53b1799cf102348b89ba289fab2b206f61688fd974023619fa5187b8cb28be778b666294bf029d7fa9abe3ea739f131930a13629bb6fa7221a788591f595911d3c8a6625a0452bab83196c047889f7eb13897b3d73db6ecf5c9687c3a97d5b3fca3071a29cb82902c7a4e673f56842129c4e27254d50c2a9741abedcd925a62796d9a98733262e45366a5d7b81cf7c9b3c42a6b2f70626d0adde9311239061dd893669404058da8d209ba6a6825e796c84e765b348414447246f57acad8c933dcaf752ef268bd6246f6b57377cf82607a522dd7028b572319263c9a9805aa6501ca4ec2a182a25cb751ad6f0a0a23955986155e0a1b0957bb9afb35320da2b20e29210b2605122791db13adb91a0fed0b36bca7d6f03b0ca6c8597b56a189c10ee887b4429b0cda99d83728aa6f57a03d182685b2266ac1f70645b123c0ddf352520332fb5ea06e716b010f82c62858c0408446afb0ffe23ae9241be953b3d05a9087f8738143c3c66b5b3c61ba1240b99c2f50b620038d775706aa58cb0f7094d52c755b992e008c2419b3b4bd85a41f65bf633136867caf5872d551340f377c06546495b8882e4e14df8a958a501161c547146fa2132160fce98c830a5b42784cfec7410bfe87f185657a29508bf339c7871ab9de91423d23e90ca2bdddbacf7f4af0f616e9626a3ed4a87b9b900b2412b0b5328104479d33046f54a06cd88a3d0c9780af5807e3517e0c72d45b17106a136e68a49521364e8661636f250fb679d3fb649a0491d349a6bcb49a4e06552ec60b33f947e37fa11b6742ca9119f0c6953f8175deac4576292165f42110c99467b008f53e25308e560fc845df84b28eff321687c45d6d09d96533f1d0078af998a9db59cc51b1ed4ec6c13695fd33a768af521bc9c39bbf6c27c6266ba271e5d8cb89982077f553b1dfb5341b5caccb856a7608cfee57ad3dcbd782ababf70c4f825cbe1279b304c2cf134beb0268655951cd76079b06410737cc10550c16cb9848612b6b7652d4ca9bb5be64f08236b69a097cbd10014e561469b7a68723160d91632d67f4908622876a29c59682579b34a298cd01597887c1b4d100ea724ba3fc8960356b499825c5223585024a478d34561a98d0c23930473ad6da637666b454c7882f0a98254f41caee03e03067b3a001f303c651489c1d00a825537c2412826a73959f085c5d6a836836582d938b9d999b591019219c906f6712fdb52b13bb8708d0c570a00bc40f1168b80b9c11a4e72430943c2544e2bb910ca5c4f0b245f4bccf0f0c3a284757bc6c535c6a205b34cddc15abcd92dcee9717b413568b461e2b9035756a312414e2644422112b49a3a23eed98e07884c80a6291df38d5bb039df15b7d89b5021d691f1a165eab9242b34146f6b223195bff19c6c6197a5e424c59572502f69c7a8b633534786e4d8c1e280680361b8ab5657b74336d72571bcd12af7089d4a23c09a167d0a3bcc540b8be036b24664bdb3a13b62c11eee93c4ff5bc0bcd92f186741eaf56a5f6111f161b9158bae9691b8c99cbae21c9534da07d11930b96751e3c29a804195a18781e016b6af45bd23e8297759a1d1487c6212add88675cc3b92de46c09b4315c9a0cf6a5a20e7fa9ed5d594aa95cfa3681e42a3543429b9ec551e1e74ba46b79234b8c69c0b5f9553aa12455edd971ac29199c04a40d702128cb77f63d50f11184d2d0b66befa6adf7c2bed427c82a632a81497c3831e38256784802fb7195e40b571c26a925de84f6366b3d9aa2ecbe57ac61283f5ea3648b652f0c742b9d7c2a8c00ab5b611fd36458ec71f1c49579f96c1a774a3b4179ea63b4fd1e3b172b39eed1bbbf0d27aabd1befa0232440b336b53230bd60b88da4c116ac47b971de59a214a0752e75888172386ab2ba525ea50492a59467a57713985475108501cce687bca50b6c8840b03bf2a5072e8585f33625a9a8c17160fd7d630ba54c2dce9bc0ab2cae4965ddb9110ad612c65c8203e7b462ff86ba28abedb808f70818f022413ed5a9a3b0ba6aa24685fa91d5938a69693862e31aef5054af2f9849d3b1d22e121fec251c8f358a0d320efb9299df6194cf6cc5cf0c11363114abb8069e57634ba173ae199b080c1d935558c16696c97a5f316a4b8565c20b266802c60d4272e49c2a5ff794bbc914240f81317558a8cc862d9783630d90d99f6a68738219c44b9ad5c07b7242e85d71f2a958398e25047f494e7f6acfe339f98cc2d65c114a537b1259e000000000000000000000000000000000000000000000000000000db721a7dfb02556d4951dc5f3410ec6a5b8b78df5ec7b511533cae60713fb9dc2e8541047591efe1847559704339d0ddba611d0ff8017cdc84e61184715c93e2 Input = 841dcaa46434e75228b0bc10733771ae67fdcbef99433463b2aaf2da88a98e1bbc748e1d14239a3a91bd2b6752b83302265c58d36f176b15988a3cdcc0f65cd72eb5486913269eb31b42bd0ccec456b72ff18f3801a1ad44c3ae6eebfaca59f2ee8308bd6c4c05a7262a01f168662dd42153bcf885ca7e84adfbaf6429bfacfde0ba36426b17dec09cee0591eca54dce505b6f23d2b674fba0a9dffdf7e77ee007e7570b31c71723047c3e8a271d6876261fc1766e1e468bbaec2a42960c2f0a3ebb7dc5d5d6d75a24245a375d160bfafb01cfa2c08831b1ccc67bf9d05df3a14d8f4b170e145311a793a92b1d59602e45328e58c5842dfa6d7021e1c65a900e0b04a79b17edec62c5d1c2bb8679174b45da0cfa336f7a0973923b8812d7b2015e73c42e1219900cfc3cdc93824b55724acaff2158d38732c429883b4d461b74a858cd167ba9e47f8157834f2e758cfc1c8f0fc5e762d56ead723cac0759cfe5233473b9706be8d909c1bfb2cdecbe7eb15b74b181e8fb949aba6b82e2c7c1d40bfc43cdc758051d1ad428a43bc7708ea9b46ea3f202974abf44644c7614769c9fb39de6ba9fb3009cff125fae0ebf0ecf5c9dea4ef2b9a8f26fc5d27d875e068ce3d319f816000f1dd560d03cccf97c5485ce65a77a326ed0fb2ece5cd5a55661c7b41f4b08486770cdc510f03b2b85c73b95d0d77b0aa75f677682d0a383a6e69ece0d5bd62568f2f50dd64ce3cd9e51556043323729b165e4c6726dc77c78025faef0653e54c6474834b9e2b51c66bfc8fe90e6e48fa217add307120ee0c00e8ac8988e5765e66dd0dfd92c80a3b19eaefb46585f0078f5f2de0b9c83ee10996b27b7c64d0f7b4d3be78ae18030bcd792e83bbf99529d1e7917bc053846268ded779a622e83f5d2fcfb0c15bdb1a2621188037acb8999ccae846ab2664792b043903c3e6b59c2645ca44e2b19cb21122035f7f3b222bf382800df1d1d8926eada144f880ecc739bb5644986f0a3c1b7cabcf3c9cbc7938802274ba459c1b870ddc516b5ea871fa6bd87b8cc5e47541f1dab3b9fd63865bb514b85155c41780b6ae24a02a06804a319d3f8d81383e7c8167853f3e24b35e220c105dfe14c33441f928c6dcf63a606500539b602f3b3f547a49545fa43f3fa6bbbd6049d9769ae5ac0964d00d68409abac87369f9608f2d244935aefce11e009fdc9a94c4a803eff45f989affe68c4dabbb291de0e7251a82bd5e5d19bc165fafa25465066e23dd905dd456e0d02ec3cf229c330d404b5f214a37363bd997979fd171584a296cab6e37928940f6bde0d1ed593903d86524449ad42248572680f1b573ede4ae27237e56755485657a5f542577700680308cea4a0d249e48138743017078e668e9ee556c7ef5a83cca9f96ca22beb7e30e2df1a793c6e2f402f109770ce7763eeb057f65bc0fec1fde8ccbeef1441dc98d059d1589564debb2a993ce21031c67d4d8c61ec53160be67aee11ff4b901bfd7c91f6e1faf7aa525aa8d15c3212ebdf0e3a5adc57690d446fcc9435caa5b1ed174b96d4da42851545ce1764bcae48c5fa580802eec2d1b83e4307c1da0dbb2a0fa414d2db8d6335f898fec5e391d0d7c2098e35dcd68afa8adc29d5eee9a9cc6a517ed310897e69eb23ce83e5ef0535c0f64d4f8d62a962e8af80f47a7f76cf735ae4ab09db0b806a9c4b2fa9ee493d69e73af045e6a1eb07b5bbd3241ccce8b5196080c2953cbc50a2052126ad754dc971050150d7ad4b319fd85cec8c4be05b55ddcd5ec7e804083278495b1601792464202969dbe01488f876d1655e0a3f4879ba41712c9136ba0f99d4bbf3145f34bd6f4edad036e6db0ba2532e35c6c097820d1fb069f9d69c259fb17b94970f2cc8284e5fd80f4e6070b4389bcb49ca99f207d002e44f6f0c9046fd89c0ddb1d86b01007c02920acafdf28e49d3c209e3bca054b67398b6c6c2561004c129947d87d33390d28489855074a6777dbf72816f0e1bf9488009bb0a247784c8a9b8f13a163d86a614edda8d205058071c12845b21e82ead309ede45872c379417c536ba446272ffb63d924d0055a92c320739d364e3eafcea6d10ee09a58a70c6c9a88550327070d6de72034b8140976856895147e2a1ab4ad062c7d299228a50b605872e3d20daea3e918f2dda9f8182aed61c93b4a47c5796478e182ba54c87fe Output = d0ffac51bd8b7e6192ac5954b26a5c64f4d0ea746b08d9f73602062aa8aaf7cd -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 EncodedPrivateKey = ea53a046a53b7e3298d588b38c403e67b5620c5c73a438ab7357660362ab3822b5e774a9dae973c83a96db79b550dc176f9b0182d37f12118bc96a4982249a352219a110704e4a0ddbe545e4f55cfc2c50d54cac33ecb6fcbb3ac2a7bd4e41282476797a3c24f4ac4f60c33da281cb1313035c9c804d755267894d867469dbfac7be52a34f55c0dc642354e52967b043a0e0167c806581b51519e04af675147578c79f492da3ac0748352c6e5c7ff462008cb42e9817155444b214c3b93ff3ae7d44b5c2b659627a833cc18ccfab4fe6d6513dfa67cec499cd7a0d052a5f9ba378bff75033e69ad053c04b74c8cd756c7cc0bd494129e069cfb4358324066415bc2a4d1cb8401867c9954aa8a33f929ca279696cd515bff0abcb6c8692aa9cc076861e2bf27ec360983f775e9f166964d0c43c380366f19d3f868a7e038752d30e389c0c057b6d93a9ae64746d5b3a146d31269b94c7a753412be68d09d820be6890e5db1ec3eab1acb14cee8a317ee7ba0eb6027f13a540b07c12cb1164bc7d295c16eef4c8d9773bd2d32ead764f58fa48abc2a5491bbe00e07965017ebf40c973343704112bc90849d219c70b028ff3769e720c4599098d172674358bcaa8947ba6b874e3d94e623122ffb3984a0b571632be1c540cc5da45ed1c57da1054abbc4456678249a2589544c3dfdb6330ab35416ca49c8046c9446150660b45e05b720722bf390e307445dd8a3e23253cbf633c8ccb098976a68e481ee86b86a32865d9caaf385842cdd071b0974e807710e2b44c598a4a36bb2af048b0fd30bb6c64a539513ed2a5a9c6cb16129cb88d6bc62389b4846a2a0afc532eeb0f055aa85ce7b43f8099cbf194e664c59e683e535ca809d40f72d4a3d5e287b5ca3880d4af1f1523b60c8f811a17b2881602ec0393d54988d63a1620a48ab25a5336b25ca25d5b21425ee54673062020f065693665c68399691748ed8c2b6ea47b89391e7dbcbb3e4bb8bc0972916aa0ee5b90292b23618c5e9a68bff8476fec1c7e382b1cddd45069263a507c44b97663a9c8b4bc690c89d25893c4caca0caa7633bc66f449bc06603fb747843b0a8ce11d46ca100b3243a8617904a2ae48db08ba24bacd5b946cc96b834491a246850c44a0f049bb3e099b3353b28c3889bd4520ce75749b745e65e6442d970e917362cafcc9cd1a6194d9ba41f29feab98320e10234c1b0fa367f7c3a420052a9ace9a0787bbc420832db814e8f86804fb74090146f899a624ee9739ed55c40b3716724b8a8164b8b976130d89e15dc24e2078f24a953b2781b7d36a12334356a6998870a0128ab5152a89ddc84aca3475f8cf849bd762ea7b23bd2d743a9d3a9a2c2ae4723b5c1a3b5349a2d4bd2907d89ab8fe80624838130697bb1d45f873a3416164f862630e96075fbc5192be26755eaa1f33026a1f201a05b6b57ccc83fe9c191b13016a921532c4558b44ff0a26c864c3102ca921c299b38199f7162938387c3598362e5f616756bb5aad68c68e0a34ce96684597712341f391ca6696538582ab0dbd532c7757b5b24b0413145395123f0c4668cd538782b0f65ecc30b687efa78183de47f53b73831210c513c54febca584a4780ea352e9dc85393457e71ca62e85abb2322aa45c4fb3d29b15d55a027b8a74186000b9a05550b2a343a3ac21b0f7a2b2aaf736a1ca49df5b61fa749266b0696ad7b6c48b0dc82803b10a4b64d6caebb33a13c60effd699ad44c1985c9e3f8ab21a0cbd728ab52e07c4bc5ab3f6c698ea307f435bb7b5545c44758fee3b9077b5a318c2b584012cc9b57560236be789bc4b026d1f26a857365b2d1a6e809a9f71e140ec56c4db3829b74539a90345841483daf6840141100c66cbe057261fc346ab8c36b03cc2b2ac838835cd373836bca05d9f57ce2231980ea1bd9908111e79b602572ab37495e9f6025269713f4318dc472d06b473268bcc7c5cb956b5a1ebf419aa18b9d6f184849240470607fdf6325ed561c270b095079734fb61e04c531be893c2621c5ba48bc897868126b995e75777c8ceb100c67556484b71404be802ded5299cc41a83b0c7a99c8d36d55f7fdb4697c446904c2420d667f5e58e0837778ea960bb6605890b8437f24f7d35acbccc41acfcbf2e35270ab36804db6353d04f4a88b97b6aa5a6a42a101a535da323cae6c7dd757de67c24fc0c1dd894ba24c26c873172bf2c1ce63c56cb98189d60587cd76c2ff70cbea93a0d0767ff347a071333986226a8812677e2b5e18a15fc5b2d23bc03786b2faf8a9d2705bcb6276d2c140509f67a123a34a98bc879386b5a596b4fe77f0caa5145d766e05834658961a4aa3d5a90bf9da5a53ddac964e62216d0a6e39934f00c6ab988cfe6334a69480bfecbc7b100b621d471ab51725008a21f404142e489cc30cb1aec8dbf99038c8989ae8c477c198cefba1f3420951b660026c820fb406d19fb0878677cbb852bf5978d99d33f6fd7c3aad87585e68e5dd5a444a8369749ac03902b91000c0d986b26029005ac6daab8b0888a75b75bb667469525a70278945e2847cfcf242b420a10af98cdcab58417400b9d58b68f3670aec0ade93996a8e16d63337444d0b7de449f3ee63b30aabc9ac2b77d5bb13d672ce9db86770b9c21e11ca3f42c2117654c657da94c451c319e1139088d008179707eccd6a47d68677c692c9bc7790a6311dfc244d1c67eeb3420109404a86ba668e24c09b6308f3b09e546cb20db4117c74b4124946735ae70ec8147bb2e24784c3b4a24eec5ba8de3269054399a623f0050b5d0c10b5f5139b0786353504216850c85677bb596b2ac6a5fd4c224bf61ced0fb031411a887066d7a5455afeb8309058485386a023b6c58b5b967557a5b291698d488a131826b958df717caf472118d96a3b6882c1e95240909886895a0f5946aad1c690b7a904121688f5685ae775738307786c5a6915baee72b3d71103a96860afd696bc70b880c019e6dc77c38e33817db195ffc2f7cc37b4a6450a2e787d2e65c55748be376af57251974ccbd8b398858971eb5ac62f7156e9f2b43d6c54a51c40c55156971804e21869933771b3ef64d16e48ec5195018425d32b56dcce1844f33600bf366b9237f6ba451fef0816d17a00542433dd7312c474f2c1abe2e3a1a12b303f9d42891b12954473f6eb41ce2014bc083732e7a4a7808831ae478bf2865934437d4874b6e5132ee99c727798aac4b99c7494fb555a594d21bc99a014001b7d06612c2b3a8c7170e99e037a2d50f33e61156c519a1a15dc78a60afd1c2c159375ed570878c319db912c1745b90321ddaa48bfb80411197b2fa146315bcaeb292714ab7576d946b3927a280319395dcc4a0c431692c7848d10a36dbaf5d78af33f62c25e5c4fb009be83a5b93e054e587393c48ac1c65a524a0cb4e6637fdd90e43346fc9a45a720898d05b4d3743a0e2e40f4cc77237e8913ac0557db49eadd7cf00c3695379b06602c332f57da6409b3b888e7c06898fc4412444c677482003c73fdf07ba45ec968591c3445b14053a8077e664b9964956fba6faa50d680352a4c8378d208940722bda766910403970e3b50d863d28400512d7adfb372052f1cfd3b24ff4e46695533449dc232a14604a08b00da1ad81e31232412e72d180826b968513a2dcc724085a3ff0d5c3a7361f861a3e02b0308b897ed9d35b14a4159cf646336ab8c0e273a6915a14297abd937afeaa3f62005a001417d91699e4166740764cee25b91fc2c44753a3bcc2a8144174cea18546fc513028018aca8cff714d6eea7515db543a192d8695b1923642228394dfb428cf167201bcbd1e217ed1e2391c616db739b09c9a0996c5bab53bb5e1bb3aa547937dfc49223897034bcfedd55599e15641bbcd1b0072e11ca24ce7a828776fd0c94bce2738eaf13075aa7340d51b30fa0caf857f1c5b7808048917e7490ab0739147b7cf229953a633f080ac80c495f5b03355bcca47a94b60e95d72a29147f2b677c6a106f905f5349933b0b7600358fb009bace2c229246aaa51a95842cee212c11a205711125c4ea14d68a833c2892e8bd265bfab3e7b16cc2d34adeac46aa6e92598d45d972577fd76a9a7b954ad1bba6ed63132a375aa29b9eaa42366e2aa8da0374a19b16389a1b36c025168584a91a4328071de904ff9162a06a8bb9b9030f4571b1166133bd11f9fb9a2214c3f838a0a6106359e778fa7f504c6e719ed9c2ac66479eb1b662c8571d7e398f80941bf2ca0b8791bfb51693fa95894f25f2ba53882e450eaeb0b3ca706a936bf22f6056588144c1c3219f0eab96c000000000000000000000000000000000000000000000000000000209ba491e8a9350c68a6cb643fe16e7cea65ea4cd099b14c90e7a0f627f502f45ea63afb095b03165e6f3b9488778fdd771036713df7b893ab8777554eb05f64 Input = 8106cd6746bff4925c2620882d571c50b36b066a5ea43fa6528351d97dda7dff1d9e9ee6ddc640ddb88851844c388727c918152c41c814be39f274183e116432a61f9a7c1885f07bf118e4ba631598fa9b1e01e72a68ec43dba62235587c9b9dd1c8e806174ad612a2ffd477e8d0edc2ebaf4036393283b55144b9c83cbb31d1674565abf29a56980dc4a3803a389a20dbf78c78a907a5d651649c27c9771ef436c189d1922564397f5b5594d7efa951ba7d05962df80c49c1f73029c3d7899852d8a1fe03d1245a228028cf713f4403abc64a9093d782cd1a6dfe12a79098e07f40904ad146dbbdfa919058149b051bea097a60aa0373cf9c0803e8da99c03a6b83813f99adea8c87e6da09013947cbbbde8edc3b7ca29f3180882cb11bec706f4048a20c5938560ea83380be5cd75f48d77bf3360fc131509317dd72b9340bab91fc6bf7ce099bfa58d6c5a413fd2801a15ce7ac6f6f2c0447cba39987a37695468cd0fdc982631d9b0354205194323e74d41c54e0a026c4e67467b5595aae7c8346d1bc5538ad0acdd56fcda32f95dd7830b65b2d98c05355a3ad9c84cb43c23ef9845250888ecb6f992da17f769a13bb7bfd621571f98b42a9aaf19d0626d7d59355d9730371b29a3868b97afd7013142866e0b2f1c54841de47c47775940c58475c96a4881bc69c6de346e05f55cab15d497392fbefd2309a834c733eb3ec8df4ae65ccaf690af492e39d0b5c91d09b39966b31b47ddf6751b481966f19758dbbc373debf284640015cb197e53120e0a36ab02203e0992f35b4c8347021f8c4663c996597a466b416cf271e04a20045639635b904b63250817c29451dd2ada5f3011500f705c2f0982d236ee1cd02944e35cfc6704f0e8fa30d8d2d595340b4245d3f3d5246d368062b53f06ad365dbf12c0fe7f492690fbf3389d234e76a618e63f785af41b2f4af70be0bf0a917df6a5f34683d931604c6df9288cb9e38b8d8396ab2e21a1c9a54f4dca2a4985c3c4aaf20af5e6fdd126860df422a894dff4a857f2a8aa54c4bebb70d44a4ad15d47497be7e0b7487003ecd6f92cec84bf4c459eb5f480dc20bb6db735cfaade1ce33782aaffa6a39e4f2ce9e7df44347b91d75bbe71b824d6302608dedab325d00163cb9e0a274ce49717bd6ddf4b9c02fb6986a8f765ed565f48c10dc90f39b93aba1a69a832e41f2b0dc2113fee500c99471ab67e3ab5a1cccc0f92273739eae4747de461ca3ce6161b558577b56af9e695a978970473dc671efcddda2bbd8d15fa6eb8ec0ec9f479bd9b8d3dd4865460846733856fd57664760bbd5ed354696ce6c8b44c6ebbcb07920cb6c3cf769c005503add472c7374b8875d714d25c74e2d4390ea455e00208763f56e475b630a30875bafc70f87f541bfd0a28839d441ce567db3be7a20e2773f08ae73f9686b95623fcfa7b1b3052d64448756f9a7481b1d9c6022898e79afd4c2290a9ed2e0658c6178826ce94e0ab460798a88cc54558c51239bbcc5347d59ac87fb6580f84aae6492e1ca700093438889fd50eb7028153e8b4675fd272667fa022b17029808b88df427ac048d8b410f60a56ac39220f8b509ca93c34c7dd62934f62a7e29aa3b0918299fd5c56b3c3158775a3b3d5c78aaf2f656257fdaaaa5b7daf83294b5fc48d08922ea6f5487d647c30b1c11a30d2b1690958fd90107a0d6cc689441a36d04039bea83c447e79b04bdbcbab04427949855aa1a32790075438ca6ae6f7897581b4489ea1dbc4c025fa1ebe698959a8145e8f11aa1cb6f742d1be789cba73fdea457eb0abf1e814c931922f451a7d59514c3e2526b1378be1ba8ce317ec3fe2e3d983edb346874f5251d197ea02c7b16fef2b7ba8cd3b0179b1f935d4aa4d463bda2d5dadd6ba96c0ad630f1eff86e34dee3f2eafb9cc5f5ed13dac2149a583e2af8db3a789c39f751e645acb58743646c6f65bb12564b8f26697e80b8d9636b0833d71433a0465dd501eb313158275608390568c7130ae5f998d3819ad7f3855d26ddc9f4ec07a36d191450dd6502a28665eaf8235a3f10b90aba654c70974038cdc9b3335d9b865da8a07be70d53f6a5edc7c4a5f4b5220c8e7fc01f5740360db072a4f8d7e80246dced5c75ad642ef1b41841f43e6e422f4f9131c1b3f505197f18571b057ed1cf2dab2f37dcb88082f8d8291d13eb7abdbb14 Output = ab923efab9857dba5a68f9198c4318f54a42aec38d194133eb7f5dc172478e79 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 EncodedPrivateKey = a7d40e120206cecb9458a1464b96c447db086780708c7435e40bafe1ab8cf26caced91b888711b8b95414e080c2be24d7a622c2e0410fb9c795a25a50554abe8b9049f9890e29531cca88e4284a5bcec559f939061b003510c8a23991cf474ba6676b0599c86dcc0976f3b61cb624954d3914bf28e109193ef1b9efdacace8574dceda34905485e1a79d51c8ba06722150d8a243d69f671c18b1c2a77c990699b72ef5b1c4aaa121a8e5a6cc971178127024166f2593893bf3b9e0db273040b0821051cab28af5196b8937538a680b39251b08051502c2a3d5504f78b767dce91e2116280c3532e9426b93d8cae3e9abc5aa4832c6bfb02a71559bb689f82c22835fb314a5e6d44bc4085eb39ab41555103033a0f4b6aabfc5246c93c07840254989301f88776c06c9f808369e18445058b4d940783d57b7d7901b0d63a6e6512b31a63ce0704028d936462c18eb4bb78accc3dc56884d9837d8632a258c4e998cc536248aacc62f7b9b65191a28a27a1cf44a0d512875ad5112e034c0adbcc67edb84eb000bf3621e7c1c5cad1cbd06f848c5d8c3601b07463b5c0e33cd260a2ec99a972c47cda74229f6292221391f37d20903aa76eb6966195acac6373a41db78b8f7515a473ba04397c2e94a26a6acd8f2cccdc572d4b60e56880fd0295152e18bc79699feb1a0b6f6c7ee19545f4124eeda5755a85d79fc2dddd2848216576e9ab4d07b7ecf77a74937cc1605602c62003dd5abaf601b55ab0cdb37bb3110290f829a742c5607ab24a50000f3191f435427b5345ef884b91811bc44fc4c6de32bdb0a73edf80c8783a5a6b6a2d06657b16104cd62ad847206ec1b87729260e91b2afde6b0f13a87025c10bafa88e1fb1a66b98a5308a2c4f10874324179a2729df786627271ac5a945072beadf878035169c543c0b07acc49241b7feb406f524b71c787ed757a3d48c233bb75d97c42e03b9973cc680169520e400b00879cf2bc9119325586719f22e1b2de163184b2c43735b2c1a8654c92138b90c458421f681136e0d6c417b20a5f8c126d3672a4073942855b127a87ce96c7e34861923b3ea9bc9f0aa277746927f0777814862b0845c3bdc12309241f387cc6f4ba4a9688b947ec8b5603ce88ccac5c35756d0031ab4a5e32f6ca97184df2acb38f724fee64a6a688c69f6b913576af98ea2487db097d7c81dbc2a29a381b2345495160c348e8207e313929dc08412304f6a01c90f6889e23b7974bbd6f081f52dba8baa716b53769e6f71b962156cd44a3f50563efb3b65741aa26e42a3720ce737c7a7ad5c875663bfe36bde03b106647ba1ef098569bc10a0940cd300d58571dd354ca5ef714733bafa4308b3c4b7528862664a8656d16c9c3837355e39072db20af20025306390ef32931e793e33333cfd893c6227215027ab7ba9cc0212ebc749abbc62be483b3e2406a5ca10d7fc534166646473c27979053928aa5445c4c1c26cde40777aca39f5a64161c322135fa176d44b694341a0d3a05de662ef0e1aced53c4ea2762c1333da3f987fac65ea63a17b55c3f681c568d648966eccd095928f2e32af2fcb0674ba3a50350e282c99af149ab1b3f52d3b9f838b1aa8cc5dc9ba816e19d8a177de33a855960b7c464cfd51a7279a48c80091ec357b9fd118e12f00736036fa8268079754a4d565773f2a5d5c913109a4606a276d07372eb96474c7722d85a17a50a956b3ca8132415b2c404a0288aadb44fbb00217c0005ee36137768c3d4169d300ab2876c1b2a92c0cf119fef5018bf7acfd2031929b9671898c64388898fb74a483a100ce2ae67275e53b00d94c2888f831a286631450308aea2580fc5cdbae53b7108a9d3cba88a437a5c0917dfa3bd7fb2266f2b2f57f52724b67e58cc2781a95191f60a34d74199102b5fe941874a4433034ae6c9aff9e2bf16f01781d72424508835e3a587903eefeb0b0d218e11183cc7293c81c09cb5fc4eaba4cdf22284206b23b87566da704665527c6c587aa3070b01e79094747a87ebb2b9e5296a2405528c224ef45ee6fcaf0c537fa2e2479d579d71a3400793188d895323f274077416f94c4e68811ad9c73598d7ccd53bcd18f8b1cca8bb5591298132258f4210d36722217c2fc5925330d03d1c037cc7d520f52b7761e61727c66c5cdab43ea53041e25b36b56a323a12f70c99eea25fb4d387c1aa2d871244021a45ab27a0709583e0c8652db31167da21ca46b84002ab009a8659656876a037e844b6c027545cc66d783713a79b1bb5021e7a2c5deaa900e595503cb1bfc394cf65707c78a97ee522be49c2c08de89336b4b50270ce189bc81fb6a464a853262791c748714aea70e79a6967e62566492157b4bff737804b014c69f41eedeb07e47cac957b4ca937cf4c907189606a9187c700a7b6756c5694b285ea6171625038f1c729a7897e5cf853aae66104fa1e6c66b86b643b1e37838f85bea35132a4176afefb2e6254433af76d5eb455b11a0624fcb63f7310b0c9b171d62134fcc361c2a58b12b2c53530fb658b83107e76006e43ca74d9093fe0ec4127f5866c306b791b5d033cc834652e6ba485efc76b5289304b3c774e88ce0173012e0203eda7a71eea170517114ef93f739501c6f9c9a4d56b77494f82c06753a996f33721a56a003167bc773c44d685a2aa45b61744058a1a097a14299d7a5257e27f8efa796776249878854f458d7e4b70db914e888567e5aa9cf238ac4187bd783570daa77c3a9854c11c80bee12374267da446cb1a3b5177c112a3945a92596093f77c3ea9bc2f95452b89879bb6c0028b653cb6c804d2680da39cb99233067c7b9124a27c4c6558a641718588709ac86d5c57ac7a1f1aac68c9c027cd2c0433a139f17b2972a5a81fc8763ad92391e818a8b77c43fa7e71930ab5934d58301c723825f9079ee9ebcc8096a1c4eaabfb5b73f070b43c3112af289c09d908fb8a2ab48786db29c2dfa82a16c6c8a8b34f83583a6fe3a630b639631742adc422a71798974727e2a80b139872df5420c60954a453633bb99dd40098be6952930cb35cda52a33c4728eb31fc7048ee5176ce947b194885395163af5aa5f2f53fe8c9246bf6143d199d2a797dd62b0fe67042fd455acebaaab2bb61ff778ffdac5edaf8778879c5517911a468a583286bb4d11a7f852ce921cec823647226c96110063d02a2708364e585c5ddb3914a27123a8c6ac89c6f98260009f172f644b10a27201a73812de28eb9f04cd0e4a19080001d082189b7b85c788e02324b2f4b07dcd4aa298b44b0f49efca0b9c0811b57729ec7ab7f0a6a7bd14c220394a2609832a26b3b8c29139af994a5c96bdcf13d8fe21c225b5e5f5aa2e0c7a21ec3a8017c885ab5a694aaad999c6ed14b77dba90fc666c0ef88336d79b3093719df8179e25bb59301a67548cf74122954e34fc5e94fc70b931a3669314605d609cf06f25f74f76fddc056cfa4654094b724636f49fbc3964a5ccd79580cc8a15eb07eb4061d528a32de192413d388b051660d43507c49720ec67ae41461b5ac87cbf91dcf42af4d38680f450acb9c6cec903807153b71613f02900117ccaa11e2cbd2885187a49089b63c3f1106fd5a3070a38b25c9757bb9b40c80c6fc4611334c4463e1aca784af6bc38584a72ca4db482361314fa1b18da660f440ab6c9167a4c18afe6395cbdc5320fca49aea990e12ad6863a0725863dc1009de81abf3d56ed4c70258096f6647cd3c5b1033512a742984af1a08617aa63e1b754ec93e77eb1f379532cebb7d4421a58bd133b9ec264ffb252bb8b546961e2f602aa45c5c20756f51c0ac29983ed95036758b05f6d90aaadc464e914004ea81eb74162d8a1e4bf986120c1e9d13cebc774677577f86c10addfba2b9486f9123458fb20e73c32c8a36a60f457074ba640309a7c9b744413a5622f43ef3785da0b77739e00f1268b50e04056b0c2071f8ab5451cc0d2861310806a4f180867310b03c0fd0d9781b3315c0da53d30b5a84f27962326084b4cf8e88a2087b420a9299c34a517c088e12ab2f54f35bc4542b85d455f6e9307c949cfd617dee8153a46c99fdaa1c00795296e9816e557369e34bb25b1555199dbe0a089cf83cfe019e5d013c6507294ce27e51ca5e805b894c13655ae6a0f9da6051706d46dacc69ec3898fc58ddd5c75e82345fd8137cb606a7707b4d3bb801f77b615527705399c8448f95d3c292662957e48bae0004acb52e55385f0cac2a9c76c471e2654968113c98be84c89e0a49040ef23751521558e677e32089a6969beb0897f74a52aefa2a087c454ef26efd08a555d6000000000000000000000000000000000000000000000000000000d2c662773707380b77713c51b59f8f1c67e6541a410027312c5dea82f0ba5c1f8bac5e523fc2f73973b46b1727891a6077329e10e94acd027c9dfa38ef4e21e4 Input = c60d4aa71649960bedcfd1ba225807739b82f912425f50d32153167826926e51f8ed961b5439fcc7a3804d55ff46d5b873e13a0c8ee7606fbb21c5e121fb8e60377ec46ead034bea9c44a685e7a588875e5bc2dff98e5529cff460ef5fd1ede8d4cf2b02e9a537887028150d0d79ee6a0ef2f0d5507c42ad1d788a75899d0b7243f7179af88cd6b7fa41849f1f49f782eb0bb727a9b0fd51ebe3f05ae80fe7259aac42c8b0a70b7b74da297c03dc1f06c44edf72773958e5a0d38aa91c35e71b27155e875f3378ad6a2d064d6d7cd56689b1a42dc4a26ce2cfc8012e147940980403bb6bc164f3a0f9055867efd0bdd3ff4c36ad8165aaba00c8365d217d4bf208312f3ce9fbd7bde30d6e4d3f1a98b0a20f947d03b45f3a25ad481fd1dc271a0cafdcc04f02d314ce3da2e1aeb00c7d3a88ea3ea2783b75e16768f0aa122db015492b0ac9bab3d3f85fe6d8e32cfd66fab8e3138402f690bfd3a5fcf09ca27cfaffca96181b8a906a67d93303069ff91c2e3e6cb26c5608bb04e05ddeab18ad3ff916bded7e9e27c99492b7525f95e02833ae827c48b1f4ef06b77633a66ef85520768b64641c5b1b3bf319c390006a026b3a77331c530aa5a86d0e329d4c7bd729992e3c574876ad9a29d79b09018e850e2e63d51f75861af33e6acbdabb722d41312294a9b302aba8e3f04ab1f04688e373f86e3753d84070bda2feabf6b94617cccae0fd427f90f43d3b686fd772292fe1c93f355fffd2683eb8dbdf171b69bb6a5c929b7109744f542a21539e04151ac7e46f5d4b8b151981d4860a366d3500c3422a2bb5c24fced0221e1b84b9e5b587e9bcb87220dd92c127be67a396ac18cfd3470e715ebd320fa07097122f696ff81923e4c2d3c0310bb8b70690dabee4e17efe6d871b32eeaeebb448f7d65fd60e7a3f32cd07e61948be330179dfdab4d748d01694d64edabfa95647a21ceafd5261cca24a0548a135ca1f7c262952bee7a291857062d3546dea97cd745050121c82a73ec9c0095847e0563229ec36046ee1564ef3747b49812eb2bd015025f077b56d63500bfe523689a6be7b886fd8aebbff18cfb6e4ca18c2d0dcbdcff8fb7a9e852f81ffb39245abc6ebb9f58a28beb15942cfd5f797dc867f7a855a3e6ecbdd9a8123ecdc30c7240d44dffcbdca05bb17d524a791ea32d60c65dcb6ae3ae3b724ae7da36b88d3563a63f4c059fc83c97ad79602cd7701749f92c02bd65f505f407b64ab3f8417d3de5631804eeae565af62d7fbf95bfe25126aa2494368bab7afabc23825d6cb03151222bec05b09a3fabd5937b7a0ff17246564e163d049e0724456576f250045d13d99aa07a5f298cd76ac73f69c3547ec9a344998dea3448a96480ece462922f76f1fab68d030796bcf570298013001414ee238a8ac4d7047514ebd5c3e55e051846403acbd3d7a581c1d53084eef20edce56c2f50443440ad0fc77a955c1e5c4d610cb45f43435b1a66bcec638ce88126ad88bd1b0d10cc5aa23789d5c8f4d9c63cf796e1ee6f7fb309855f332a648c731775edbcb4968592f1f633a3fc74bc5fbfe9c0e74d8379fc56f869e63d8db3b9ffa92e9b470e668e10acc1c7606839f2ec0abd02629007e3b1300e558e5afd136f949eb1e6ae56b5a8c21d15ec4b62b22af89618501c1af9992a3f002242288fe01140e2476ff900afe32685afac7baee893bcfaa54c1bcae65b2c9db04b1e17dec3821145daa041150f3282a500ca46c535ee47ec02b1a1639713354bc4ff7217ec169a63bbf26a26b2c712b02c76b56a8ed0535e3ee1c3f118f2a68f9c699ed8702f3eb30328118922b15b8399a3fca410dae21e7d762e6e45c8de7ff023a75211e42d1acf1d8f506223cb281fb9615b2de1848ad674236e768a0f315041daab6f491195453081535f9235f6d215e5750226ae7eef4df26469cea1d0541e7932ad917fb360f4a9d5601126b1c76bdd1696e6d59749635b844c9d416a12d0eff4c4a9e7f40860b047ffad7bce7439ef0fef50cccbdcc848b02f66bf67f2d3cd795242896c5f2cff82864b1d1f00974c9142d0b0ef2a8d00289238e822d352a924c689ab15e6e5b201ee7ebca1253b9964a04efb4d7af21c6ecdc03365b4275d72502523d562209a316a88163ca33ea279702309f8c2373514d459a5298ce6999571072852d996fa8421fa594069645f034d3 Output = a6ac9ae3077504c8a7b1e5558a0fb1e7d60cd2bc3e59d615e68d5165e4903d07 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 EncodedPrivateKey = 610c36a286cca4815c657bc2f28b854aa8602890bd6ec2700d64b495b50d049c5963b8294752942d11c1d0182ba6704e54c003b828bc58b6ca3ee0823607c3c00bd0471b4df571c51db3003e4cbe6166c0caeb747f79573f5b8b80d12ca78bc1d3e01a318bac91fc863198afb70cb9256a330faa06639caa7ffcc1248b367bb6b0bd905ab0098b79b85ac5dc083ed43ed8b248dbb72e5ad962b3201c92b132b2961d9867b48208896c11afdd929be2792839674b18e4c1e99a7df714ab7ecb58570281ca80a92f148bc492797564682b560f1bfa42b2f7734047cfd6375d3dc05846da1d3511cb3c8221d38226f29ca52b07471a41764f86ac3418a96aab70fc8454d6823f8b7c6211d216d08c67eec474a3cbad8f3587e22670ae5a9938651f3b48011341b6140ba393621accdc3f606b080579197c48967f1c8d11026d8f90b0697869ea49cb9db086ef687227b2549ac689b564326a2280d8384698185afb25941ba0365b0c1939148ed6e1bf0ef5c764832178d47a01c3573aa268e168b740194a9b36ac2580a7bbe1625900befef3adc6fcb356100ddeac4393d388fe647c3d623d1e6a56a96073bec59f5fa39581245e31aa33cfb865bbc28e9f2498bad34a5bc65c517bb8cae19b6d1864fd7a0c48aabc78d0373a84c168f33ff13a9586aa349a185e3528003e804c8cacbccf0073da46567f7c3ee6a55eba856851234b4f3725e1bb3609e50cd4c9c96ff947c4b048dd7c64b3498d23c234e9bc45230b8b0c797946d0980dfc7bbc5773620b8330262ab6247fca5684c9fb8c2e692c3f654099a7a93d0aae62d24eb594544a81431f295bbca7b15dab7bcf728e3dc61f6354a459a120c371030f3b622569a78762b1cb08248a455e0f0847e1531d194acb0507bb53e9c0e13c8b2f45ab06362be3d9bb58ab6d90825a15211f81f4987000cf74355a28ba08443b3fd9d26b70039955773f9f840207f696d0e7a4989c4b38cb23df626e53b7ccf7c1bd96bc3f68c20ba180a482799d2cf975e0a39d5fe863df954665509b3eb63c257b8c9e39050bc4a739468e716cc289a79053453a28906d003535536439d418736a95763ae222c8870b66f1b5a9978c29d238658a3e773063dab55125e851983706c3ec68d7fb1d595b55292885f758a8df752fd3d97a8dfc33a228c896a44bc039ce1a2069810b1304d44522b1a5e43756cb843b5ef515d89c310f442f585259e5d460dcd578cc51ab49e63a7cdc2566d77e6959a7d24150cf0b413d335efa65385ae13b482b9b4db4ad2518b71704098d7481d2233e2ab201dcb4a1b3604149710de3cb247f29ce8ccb2ec062b014708f397482dae5936bec37663c849c9baa9d3cc88146b88cf970e574694af03fb78205e205435221b32e5513989047e62775f1ba5aa89a10c9d35cb566328eaa5748e9c5057446f96cc691d80208940cfea984df8817d4507aff0a0a96b8c6729329775c8d75935d7624cc0a06ab7a950f2b73ce4d90239706403c0651dda56544ea59bb06a99f00bd698a8c3f127fb4a3759317a05ac244a07342f9a47257e5649dec2c7050188ea669a97c137f707f4e5b4c57945f82c1b0b2040476d73acb54724cba00dfa8bb9d8c58e33260020a33fc04021baba0f6375ddee4a6023846a2dc73eb69758edc915ab2446b1c59fed89bbb86a9be2242c117cb719274873c8b0a2857e4076b3a792965011675c23deb8bc0cf7b2e3ee38493461f8a2068bcd899f1822dfbe8444a612f9fbacbf87a0d45f98a541c5141b230be12763a3563f5d47e369b65c10254e5f63934a05c8ab3409d7b4207dc423d537abd4404a9ec6afb1cbb529619bee740a4c71efc952b3b871043c24c0c919f74f508bc23a9c1ea8b76ac449e28379af42bb6140d376c9a4ec76b34042c7d711efb559c8c87170662788b4cc907e4882d4332d90c43175cc56eb943d589a30a5ac1ae312aeb8432a1d7b2f7448fe0f48ad069989e908d28616530246f8e817aecf6ae638acd7030a596d5be06964eeada35f6175bc0d20c26636943f1609eba3b8852531f083a576231c9b222a9f96ab1fb79aa0149155881fae91adf26c4f1e463f6f603511311351c6c1d1832f482306d66a4a2e585b7e223bd539fc45c5b29558e3110cc268356edf4bd6328240b1a7286c71c5cc17284fb5058410381c74456c1ae3ad93735b6c7d0e13621c924a67a44937039df4b4da608ab49978109f077c961c2e6d02cb0f429fb04bf7b32afd9e0748a50162bf49ab17602717b25800ca3c762145636adeeec6543c43dd20a2a194211030971f16139ab86a22fe07664b425e47240ee1101cd171bd681a681804d38bc4cd562b7675a1a4fb113ab476fb7e67009c8ad5edcb053e77e99d10a348851f266919d29204f5bbe27e8672ed92e7777aae4141a8e81a39cd83a30005127289092929a41b42db3ea2c3b9b4e14a02a45906e871b5ed4c5067180aa97a6967642a5ea52639f27665a78aa24511ec6bb8ec7c3ca2fd34fafd5b5397c75c8144894b56d61e57ef77725ed8909afc703c6cb858fa1c600556babf3cf4fbc089595606f450753c727b42c7e8a8c470ae99e40e518d73684f2810e1ccb187441873fe14cce8628efb360083029fad17c1a9809daa08df859a0626365e0f1ba97ab9bb0d09e3b2632812152ec6361cdc65307f916b1782eee7873c2313089f3bd0c5ba938b80f1b43c7fc6c3f801444a34ab9c167629076442b1cb34c9b02941368c6377098a7618ae352d7cb1ed9419d56158f9222c644f58c3efa5209317a165434b86350c1a94d21fbb065854534120e665bb73266b6a392a60fda82b096701cb100aff65b44a40a4d8c83f8c63621f44a6de22f9b4817a2772085a95597c309b6423b9710cf72720598064717b52a336a0d3d9b6092e9a445a3c507e37ea9ca126b1b8f4f702d55959faa7b80322045508b2025ba64575049738699e2e1a42630c80615724dca7e98acb40f6415f6907e3649962c451f31164e88601cc2c37a65c636b6c146cdc24e5ce6976bc3457277a588118712cbabd8dc273fd0c8c3835fdeb500fe035116f6beaf437354c39e9152c3c9999f5f98281096a0f1cbafbef24e87bbce8f88377a0a3541eb128e31a0d77c247dd32180b97bf6f8bb2f611e7a7927f7ca25706cbc7b52598b4865ed8b520aa53e6199a96a0bc79a09002e07bcdf78473b273028b34e7a7c9f71ac38bd6327ea4c9acba59a07b59433908a3b8a4cc5a01d704773621b4c750389e8557498747ebb3b8b41b99105756205b2b578f668de8c293ef989a934cd1c80b18d700f7666986fc445854c9a6bbb8c9ae050c6316bafda5e98aba4ca0b92e3c3a43c504e214193b43c9c9ccacdf4ba85a57c6da6d1a8b310c4f0b7390c7001e8004beb92bf55cc8eaf37ae07738a090018e843288a965d4e8bbbf9a18730106c52758367361f558272f3887762ea91c35a23a708394b8a3b505098f7ab8ba505bbd1763a0339084f3ccdb2e68ce8b032bc217d51110c6cca10f277142a844ce5e7c8800b5bc857613deb0e5e59b4acc72f0fa1bdb0f016ace9b02a43a49e83c207e8ab82e98fa1144a47809a5dbc5be622b1bb364e8000cfa2c203f247706b3b3dc520bb308a62bd893c3bd890102bcdfa1b6ea91cb5f86758d5339396184b2ad4b36d6c875675261658615e55c85839cb10ac8c789959cc675a976c4b88146179d38820344f319b1621248577294d4550a33e723d65f11f3f654f11f206a7b4c4b909a4b1490f41d68752aa4af2723ba9c092d371c0e2459c9361230cea1772ac0990b6626a9914b20769c51b2df3996639fab765164a7b61280049ba14d55a98537e85ca0d8259b14ea4151c787d49c9b2d291c9e2b005c13a3d93a88840f9a19d30c346b14b413c150818850bb8585ef0263b515a74e79032b3c561ea543d652076a38fb4f769318378510a8e277334c148bbf38868d74ab56adb16f75a6c4ecbca6e1ba200874567fa5d1bb42527f123faa69bf2c45e4e79022799a717c21260e3585d6a86b7582a1f166dee7015abe11b42a961d60750e2e40ffc82588448b515bb4afe246c875297ef87740a775fcbe0bd902c67b9830c6d318523e422b0060bcc5a5a5f7b267f5b53e111c7121b86a6025a0fc2716fc11025c857ae1926fa7066ab527045d8244c75bf13a1a3c6688811d35ad23c1435b4cd536c6f14f78bb5d34b4bb34548a375b93234c63645d7ab59580567f9517604837fa6f98b2b4911d9946a54d0ad2cf0747b4081b904a2d6f953c70065b0c4b698e556daa27cee3b40070326f43c3d93a7cfc649000000000000000000000000000000000000000000000000000000bbd7982687ffd48dc0a8badfdd4788bce9b1b4242f5ae1d14b1ba97c0642a6b4e42ed33e0da5856106580e02aacd0aa1546d3df0571d17452d22f186d011981a Input = b0ea35919c0560ba7caf9fb6352b36bba962cd45d3d2b7f6bd97ebb2a3ba6df22e018390330f75cb4eaef8c9ee9bde4a1f25110dadf363df31f3f8702a3c14d5d2da303bbaf0fb199384a2702f7089fcc63acfb29d5e53571102566866898055258241e5ec4f1a325175cf3a64a84ec50b4e8e511ec24dfdaf0ca79911b1d84b5a0872fb1618edf364ea06d7287c6ac39e842c56d6630ef38f4c812a8d1fcad73f2d4ecf8f7033c1f5ab982c5b6b8c5545237c4a3ba8d5ece30dc93d1d4f4e89d3bba0b8149ee5c2df793c8779d45de92630b292714582387e60769209ea7d00e2f1173f8817567f52fe53d908d11e8e77375e7d2f73f44a01ee3c87c8f4163c579c40ce70dbc006ad2426667650c35d80ced3df0f3f626fb52f57d874625d414aeaa658a220a4ee6350900dd7b1b9e165661b41cd0c96c3b665d789a297f6b7b4f261e6dda3f6b027ed8a308f1168627f71656bb0ad456ed2b197c672d88ea6bd61fde6dc3df7e4d8b505afcaa35fc1d9b5df57b69679811ab5b738d62a5800555fe282dd4d06d5ab25a3847b4f22725a2360d8b47c69458b55f485a1ee75918cefbac2b4945c20a7356d1b7c69f1c047ba355496e21eaa2123b5b545e86c23d4cf27011e68611290161366d6c12b340292113d3973efb312b1474807f8cf735b76bb3a722aeaca7b865530fba177f9016d1ad1a7bd86da6f657c32d6662e57cc691f5acad0faf4f21027fd761ae23456b599333c9af918166927c6253dabe508c7d931d50cc824c589881b39087e02b52276b9d4252c08199dd4943d72b4fc14e603c9e901d0038da715973b0d168b13edc26b20e2649f37d27c9cacc7a8508ab340a1c3ed8d26099171bfaebd39b0b9fedb3c195a381b55c13365139063e5525400127cc963d9659c964ef3415b31c3a2a923ed3b96ffd327d6eb4929ce1d0d26232b46da119e5e38e71a2dc97bb953567bb5dde9c2d19bbd208c85b135bdc885121b5f7195904d2a9141bf5222e98f95ead571db8fe2df9a93501b8fb9a06a3ce0338a37920fc4268e26e71f94cc218d6fad6c2cfdbf0a5855b186ccdf10f66f01f884f22503c530b3c5ecd96d9b55651b1eeb3af62cb7a4cf4cd185d98afd1b942e8f7eff849ce843e113e82c3a875fb996161e0d0185aa99e21e7c99c9636cedf0dc9aeb55a37eb1f744841f5d8fb3eeb5eef76039a40a5c643957cc81dba3fe556234acc512efa07f3a140ef28a93ed9cdd2088456e3bfad0e8377e69fbb3dc67f3864ab36f8f8422837e067c20787b80d77a30995e5d78f84804cd7c897d0ffa5fe1e7b92f17575d94512b6a4b5888a3cfa6e03be3a50b8797f43a87477982fb241f24af59f13acf60ecc4c11e558b1a4feb81f69acd5a67f56bd698888c9f00430dd8f8309629f7c29e96d2951fcd8b521265c368e13e22fefa30bdecd51407387c77259e64a62e5d705d3d46be5b6f710ad86e844e509a3c5c1dce0efe4b1427bcbe56758432301a14d8b882a70cb5c587e1636ecf96c61998bec7a9b6b98eab92be2e30b30174c87bb8bd66d13282dc4d1b67757435807a90a0b268a9f760054c219bef6c8811476a56a14994c760e21a1b786efda3fcda5acd859967b9874eb049a9690b0acd97c907c1ec6b1bc9790b1fa6c8f15518b9c18b3f0cf672d26496be193602d909efc2562bf72e83a3d8244eea1942c6b6708f006963ed1005615abfdb57cff11b985134ef3ca90116a7ae35299d1627fc05cd40cb32a83c9f9e19570ab0b4e079ae34402641e47e1f0bb20b63e551dc7c090421bb1916e970b33a6cee4be985f28ea66cbcbaa21279b45a4d3927eff26dd1d171f18ba8c5e78644d6027e7ace96ab62bc862d8cd69bdc9c07a4d8d66ce2a08601783e6d40665fdc637aa813a447361ccd9d843bfa05f5e88f1f74a4d6fd1bdeddb1c50523d731cf6cb4686018e8518525a83c2aab2fc5ff97ea1562c7cc7347482c96675b0b249f99428d68f180d6590c67025e41c80468a3edcf147368f3612456e9d73bc4d6e0a70364036f75cb6657ea99c8fa365c165d7fc912bc583f0f4e57ba0f531544282e21dc42e00f00fc59273d272a711748bf62760377e5c30c1776542936a10fdfa8acca0b4b5e5c9cabf461ed5caa9124c59a4e867859401c158080970ada9cf76ab49e250411a61ec5e83c781c269b75ed1c193bf8134d7b0dea Output = be6aaee5bf0744e7ca1ca0e545171f3075aba9b4d10a71ae00848c8398e3c52c -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 EncodedPrivateKey = cc389888219463a7a5f6c2ca3014accb3bc26f2318f593876de6a49822b6c1e694b7e5aa9140a0765b6334ec762c8bb018d28a99004081256159c836f4f800d0c9aa4a7136fcd89ba7cc1d6a32b23ed181b3fc118ecc60096a4ce8261ea2c0a6ca49baa28b75d1b40215367e6a33a1c177937bf43a70c3889f6aa239e20e499bc7a836694a0bc2912cc7cf211ba20c12d5ec312da2815ef20c8565712b22a927451271040cf4daa44d79705b97993584424e7b3224a5583e5b8eaf640e85015676517113f53a415220fde3638b9c0a38115e668545305ab298b9923bc16de5b9137b30a39a2c8b5fb75e4d1168593a8eb0e067bb9343f1a030e5228bf0b3a49169393cd14f73c2b8221b1267627d80b97d30544b02a4c7bf06099194b2d646596aa439d82a214e6cb9c5ea1ded727c8143755cf881415b6357661a90d5ae759475baa6076eb478a5826f86f9868afc47ac3a02a0e84579a25466a63d933b071213c886790c320416d9422d280745758779635ba6f848440b2489144866e8e018200cb8305b3060926d7e7213089a06d044176b053f3bfbcecac7840dd7844ec29eb17bb2caf321a5b17848c16a678552727a3d70c34f024164b3c4856b0a4ecbc78d345187c6e09f055273bb775078b43ecc534a40e66592b607b56b5f9304aeb048375ac71c30464e979a656f1728a7b700e3b33e5026bf40198b94455d2be37cd65867522b20bddb5ecb7a010191254b8a403f37c4577a613ea30678daab55508b16d6020f074504f928dddac1e8367faf6199715048c96a8fd6bb225715accdcb012cc856a76057b6b72b09a4aeff5b8ba278c54a750596e82bda45be19014e8ff52df181435ed9ac8c402147b539ffd984c291535b7bc8b26c5036352520730195fbaf40033fac450843e808b9ccbf03b40a9ed657f6ac4af8b65b4e389280633d79799e0226b28b356fc2e39f10a80452dc934caac7c3c521f0c5544e7821a403688f08378c3086d3ab8f7e4036ad516778da606204aed3ca1ae8c42e11038a64ec78a5fc5dcd0475429124b5d665e4acbeccca3a296a8e878b917b886ec7f029491c661bba684ac4229cd71373c829055b602db0518a481230345a34a709010a03e4b197273510a0a24465288c327c10c75434d9473208a7964db7792ea81c5fe0c4bd967c3f0c98765ba7d3faa4e6097f09e9bf10638fb900a764e4a0bdba2f19165bd69832681310a7a2585bf06322a3238dd26a4807af44faad999397d4aa14e76c2cad5326ce573d7ca04c03db769dd01a65583ecbbb991e7a31b59238f8741845f1adb5992607184dfa19a9e8840ed9e1622ab93031e2b448860d411a3d239277052cc8ea71046a0b1ada191a020c322d776c6655ae71964d86314a86a47b6a367b8ac5a4aec75677226de0c1864492c88fb70a53187cb76835d5477346646a9da97301156a3ffcc231f9a0da760dac142674e5cea882364dd74fab66901dbb7eaf037008c52073054cc2f94ec845444054058402515bd206d496bfa02c442c746ff3e662b899c34c40900902c4f8ca146458522c6a7af772b2df483f9d840fe07464b0c66fe1036c070c6f70278e9506342663b07529247b1697c6b844a5959672b08796868e7107108ca4c30a58be4ff7b37b0402697aca2dc4839dc51a8811c34c8183442711a8d055b640cd73d2caff9357bdd9ad36835ae9d55d1a291e040652d020a905027a616b3b5c63c0be2c1068e9cb0a9b4abbf346590237f96422308ba86b055872e156470b53e35b2a604bcbd2b97849446684149a86d9980c5182f1a020c32b14de18c03cd0633e303bf9f8a24ff0c95d5a65c031c18550b7d7d5b8ec672c3953bb3be0c3f13925200394aabb26090a3b9a12bde30418b997abf310c1724a88b9782418d09552a63e2855b7af2196d422761f5c8a877426976c90552bc203f5657f5370258b936c3706f074c11b3b2586391f4c4bcdd959615a819aacfb48d2c799a9abb182c7a9fda6a80ee50c4a827c9f50835b1859033629a9601b5b8b357913b6de142a501974a0c191a071a95cb8c45fa857736a93400141cc325d1b4518d3ea58a94c14f9b261759281b00213f91652b1e52bbc0c488bc0990a136e8e3b5e20f41d9f218646d43745245ca4c2777099032b1a5060745e8525bc617900d53b414dc995772543cc58a6bb7c4868f8999509428a3244db4081ac6b3f3c685865814c318032a678ce19866754c0774b31cc47a6a8e3cc90d6a15e54c7370c0360c38409b126c06d4b06b7d652318cc810c774f0e66e7e547305d03109030fded56940d472ee123438551d6885922ee91889f97ae31954703952f4a3951e8003ca2836fce071e382373c36a27b947ec8766bcafb1a3105aa2b082802b9bca0e4c50b80cf9a4033b44ba4b8a2cd6d480a315b08e7774d68f8ca8778894bebc2ab431d63c931e61c5366699b65ea448c127b82ea493034616fc1b6be01243bc84dc92bcb50aa4c7a417f1b5268e93b35ced9cd6263227c849dc8b107b10120f9f690706cb0ddec8fe2b20a26da422604c9135c58f0b06aa5180ccb55adcce07e51f885998398c4f16162c33b89bb37a09b84dd0a9d0e8c90a71c2851e33b3e9cc5531a76f81992344161a837608872355d57111df72412e58c5ff85b97ab2016b41487f56a9fbb48d2e498c2e12d3972c677caae5e439c598b67520a7ff6ac9c2424482988153b145d6b40973a1582b90a5bb76716c9878dee223046f746f08323ac3a5390a6148d767c3054524b7247c26c9339c0642632710b8a4fe0502dcbc32c35ec2e1e22510ea4abc7c74980ab25f9fa58caf4a70eec2d22c1957f162f5f1c5e5ad0a0fda4c342885081d3070d773cc972928eaab2ed604503257bfe448ef2a9c9c933055e633a339792d24a44769b95123c1f9588c8759a469c049a75bcad2e6087559c8afa5b6415a8825567aa44f63ce5b49ba4fabaea311918b804c7fa2d1742945f39bc9e8256b537128a9735a0939a1150c10418551723154cf4c027a5355e1751a9866bf558672fc68324438f12d83551ea49b358cf873772ae7853b53c9627ec75479c746a116c5e66b20ce0478c490946a0af4a3a3138534c2c94a44bca955e84513f548840b929f4b4ae51d53d52225a21b320d0d8b075358b019720c325814303170b627fd6856a149214eb192659d21001d5ba6953288e5a62d141ad5ff31c413418f332947f1441b8663f95b1a8ea35576e725a83177126719889651e8f20a8fc2392cdf55976651f1c177c5d8bb035993b0f2ca020a8b22b27080c4161cb86abda574deb0c858d14ab4261b1b8718ac12c56db9071a5acb00c4b1fcc9b9880917f53cc12bdfc77103a45ce8a2f4875c7e3711b659b967c5c26497c6e2903198f36b01c56ac5d054672d6914498643ae6b5bdc2447300737883306e4250ec445b543bb06b6113db5369da2b02dde3a11b2c080732979676040ddb2941956068557e65e0c4ae9c2834671f9ff65c246b31dbfb82720c8f014aa35d343b8eb762219b0eb802637574724595ac1c92b85e9a416089a2366ac9002d01af606ee9b21868e72ba96c6d5adb51f97c778cb8653e30a253b333ae5bb600a2b064cc387b38bbc0379c77dc45f7fc45fd060c60bcac60bbc794d18a5a8ab680a0ae202c97c3f153d07058017bc0b74458959c2a358b6c3733c60374a2ad540c75785ec95cb0bc125df1e8359af2bff55026d18348d0eca6672a87671925a8568060c09913993fc6f89e2523023544938a573ad208761e3ba85354cec6d999ee1c5f909bb973e0780c84101cd3cb42319b0d5614b9d103be8477ee9713cf943e038a04259c0958376c1013445731b0a5224402845499f30449f0800de86b614718bbe333b4b8245fc1a8e0c43eadd61f11f532ddb7551686cb8b054b2e90a19c889ccf68394cd501fb92a7211b9b599b2a2b637dd4246a7b8a5f713acfdeba03fb513f998177dd8cb216aa12c27ac3a5b84491738e5a745cbe7a3b5006bae6a08b0cd79a2b27af3da8ab021893e7727192e28787a052df8b434abb0f3a5866368991aba8ae3c891a0870327c3967eac16e8bd725bde990ef882bd6e5663d50b7adf75048d3202b39b44606ba1ac33fbb7a866a59a8c70988705974ec413abf660d5e98b6d9c60454a8825874953d778ac527578769aede871242b04561ea2d6e5c8aa04ba44228125bdb4beb90ca152705716cadd283ca2fd83ed9087ac5b2c7cba9334fe936c69586e3399fa46a174170aa8db62bd7095736012b49111e73bbcbbc89391bf70af7bc3581777c54d74ac2fd37b45300000000000000000000000000000000000000000000000000000057407f828b076da9179f40805f8392d4baaea0bac363dfbac88cfda8ce1ed279c975767ff083234b2979bb109a24a27bca17d170abd8d9e6ad3c3ba19e306bce Input = 1feb4f1d63f08052045012a21c33c2951b16c4b5ec02c00093d54ded6f94309e44d558787273bf593ac4bd77a56fe4dc30a54eb68a2f473c31c239ba18c9ca489cd50611fcd3be42f6f5069facdbcb7166a64ba7c06ba953142e5914ce20ec69038895c9860e69ce6cc3dac6c1b28d30fe83487d40591995f091d4ea116ad2675e32bb83325b7f379449dcded935027120d01ee43b2208deba910ca7ee635c5b928e5f6167307c813c8e7034096878a2915ed2d20898d8412ae61a72378a4eaee2f227ad5467d04ab884340cbfde2400cbdbca7e07a2f14016fa9e403a2b0ed27ad1dbb3cc492f584a6b5a7525baa628303039f69cf1c1e4db920ef7882de21eda5d2bad76231c88a061fbb2829fe93149c69204e2e783009beb4188fb876a6f869eb11b1c32c2ef15f9aef62f699f9692a502a4d87e5a497097ca73f8fddacbc03dd40a53abf267f749f9ac0f7b4ce9417a0f5eafa91fef75441ff7c887dc2eab2336fd257d4cda373121af864d4707fd20965e063fae456f0bef8f587bb385f8e5c96592c9b7d6c284197ca1706e1961dadf16a2264f74be425ce117a95dc9466474c856adb20931cc920177dc3f8c93d2bb3ad5f7c5517f0b7d141b87a8c287207e64158934766c8845ff0a480da124716b11d0e257206f68f2d4334e8e260895ab83e218e032a35f8d792be7b413b2679f8044e1c0ff67c474ef4c9b7e0dfd3d9bc4252fa81922cb146417dcadae7d7a7ee96e13bd480c96a4314f31fea83eef588bbf1435528c51eaf05cee2f193c3fc234d695ba32546ec77a16b1ea8047498125f2bf78dc9510812be57fe0ec77bfb3e28f42a4d15c2a2f0b54aae023ada92395cf384a1524a24e36ee2e69128fd2ab78b5af77d28c2e9ccd6c706315d46887db0c0c4f28666da7437489e3b245a19fcee97f187327a5806d35889e63940b19249d627165727f66f50aee62dd9496d6493c1f01ed0091e985048c2aa85a3b25a4f90f6e9f9cf67d6961ca246d763d3437ad64e7bc5c58b10117a66c40be088c58a27be4bc1360d114e61d002e271c4806b872f5ef7127217d5af6092e4aedf8b5c40198f266f9e10c560d4873668d58c912ec7ec18d27249f5be604a82d50421d436a3230780419bdefd10f049f404184b3530361c5c0644c3205c32fd451f6c6919487aefb12a75c821cfddeaa14c2abe20db3ac57ae0ee8ac4567db2d1e2d0920fa036351e8bcadbc14ab73d0868df6ab06e675ee193722f93f64a5344bd70593c23647152a81acb4d1a08b62b5f0b2669210d5d7845248d95fe9ccd796d73e34af955d1c94edcd2bba91be211cacb0884a90eab8a0125130ae65318f5419810f4df129c8504def662df4879e2a8df02d881e9990148065942c0d52865425f3239c4a4af51eeb85e1baeaf647e794b9fc04ea16eb328b8b1d0550e5dad8bf6248782b530735f8f5da40cf21241a2d62951cc9e894a339491f64b78d436c635eccb855d3a1f7d64f63f23023620408df6b3d190e7965d219a0cabc0933f7d50d9854e4d4aa7a5cf67b37e0475241a5af8e5000d117ebcea40b526c5a669dea1760d7fc30519148649fb00ca434f2cd84862a2755a99531854cdc847b7d5af3ede653ad6959f49c921d4a8675f7f3f51416c39e026488c297d844a8429caab43671093cc3ebf8730a18bae06f10ff8047cafb8d80edd7630c95d008cefca78f2b08ccb330d36eb33b18cf47bfbbcd0e2f81daa87160f421603d10409b8eab53f1561623f5167dafccda4f9a4e6504a0b5e67ab5dcfae98672f4cf62e4f152d09f2c64dd81e3476839aef8538a86f3b616ce55adf1dfe9451ca48acbe210c32ea1cc574730b37d4747b580c66820caf475858b4b6ad0eb7c06ed56b8f16f83595ee3466bdb8aaba3bbf35a177fd6645610b9dc238571e81b27b94757c9004a4c512cbad25730bc6f85255ffdcd052447766219e667095d4058e5f0045e16c0fcae1aed8dcb7c25fbcaf29a71a8abf72c398a61b1a57bec4b11a8c746bcce3ef0f82b9b2bd702d92a7fabc1efe0065e662270e1ab664cb1197f00983f1d265ff738f63b93d5d95aa4ddef2ea3f473440ce7ca1558b28fd68ee09c7b97e9d4c2052fb1dd657ecf09a2f664de0902f23bacab5d64bd449a0ddab34d4c0695c67ff5f6e11044a0db15d2d19a9ce2aeb818f0ecaf8c1522276521b0193f76e2 Output = ff81d45deb69b6890f147710945d1b750cf17e876cd4e694158efcaf4fa2cb15 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 EncodedPrivateKey = 078bc69561af0cc77acc291fcb063e1d7c82bdd7cc31d5b44d1aa746e261f2a592d4aa9165c2c3755aa457b886cdd55840767f4fa0b19e45410872cb1db3b8b5829c4ce9b2a8969330cb5bba2397119310fa072b7053b35fb135d04977b9ab4766c4c1ecd9695957473f10c679d71d2f6b57db2ab0726022bfeb10b61807d35447a141255bf5b3d0e3bbf5cc3ae74932d87268e172978d78b99daabcb16b44bd578f6dac130c2528fbc89ffa94b48e6785293023e2605a8533a5ac17c15f34b1e30501729a78d3b8ac6e4a329e1006e0c0735c737283856d7cc7663cdaa1610b1045b7423ca8ccb59ca6b1c482dc02ba117c17588809ef8506f09a7162720142e397c6ac0f8fdb02e4c1c557050af941ae8165ae01d9228f767ef1ac3d72f27cf9a2282a6c379a669d01cc0a6c560b21169557b88771008dad62641f435e0780234e86c1ead05f14c0ad68b6b1041492a166bc4a278b0d352129556d55f37ef8969b596c5e41f8597878c8c6c83de675019c022314215eac667a7b559146478a4a5634ff193f6b83673072643efa59c27650fec168ff17109577083bfa8493f38301528f27681405693345e523ea4398055606d4ccad9df967fe59428ca7502f046506756a6b9a78182383db4baf05014fbb20afaf148456126fa393abfc480edc92465d93aaa158c2a8493882b24c564b607cccb2c8f6cbb43abd722c74c2c63230946acc091c48b865cdb33edb712c670648b07c06691687685218ba48648fa3054ae7a6a663aca6aa4e66506516100c8f2caf9c0645f2554c10c480e798b9c96756e42cc8a7f626c2759d21555342548e0490420df3a8124b0566b1804933b68225359cf66caa599c55573b70d488d16185496216cc09090de382d570795efa569aa5bfa8f4a60665cd30d63bb36cc5ac050310ba9bbe4b3af2f9400296bd344cb72bb623c757366ef1369c968578eba52a092dfef34aadf552a63b1495a5b78168cf6e58b218a3ae64310d16734d5e72b2036bcc001ca07533085548809bf114a092225aec9cce6950a953773ee37ad3467bd5ea0b4cc4c6b0695a774781ce17004cd48e36116776db19565367c92a94488ccbf4ca3c3960524d1b13d6f77399ac625de5a2d09954cf867011f79bb4c3682cd40f133a9d67778a24d7cf1a5b71b7b81dfe335d0fc392a8b12b234950ab79cac94776ad1b713e99b0f394aedce739a15334f19042f4861e739c839ce07da145808260b159625b5a742258779440953c743c591659b9d982aa7da028c7eac4390b47b243ba23e8ae4fd9c98042a0c2d25a6688c9ec774cd7e95899fb7f081035b0c4217c2903688ca7e4466e66ac4e3ca938fd58b4d6bb732a36aa8e097fd75976d1200d61a5c988c12702698b1cfcbd93157d3d1c6e76d316b00b4e462588bbf3c480d8374df3cf66a16f9dd2ab721954e02a9f8eea4380c381da230f10c2c7dec02b057177e157cbd5304ab1d8160a323fd5892fe1649c2e270dbd3777035912dc0802f4d18a56356b52946f30c516838028f7f39cc22466ed277a5adb6864972e1063b1af0709dfd60136b16a3d6c863a68895677c488eb1d879a69a5341a695212066ab848609cbe331704aa56092a4204a2293e77935390cb1d2b2924e0bb27d4aa471474fed2b6982b71a1c14b2cd3ae12b12d5d12919235caeb8aa3827c844bda40f5f57e5f59c75c86b645224b3a861eb9d9773b01cbba45122bfb1e4a60ada0fc10f133c546563661064adbf4a89117657366789cfc282f9bbdd0547029c92aced02963f8cf462326db19bdc980149ee0823ecb1d9e22a5effc6cb588b17da70789d813b749be180457e82a5c958b069551748e12bae79cbc0dfb5ecccc85f565c22eea1836b52435b023959b4f4fc12956a09f38d58836891c4c2b0b4502b012b868fb9bc0455c12e83c182f1637c05469708279b1f4af2c275e174ca5ed0a12b39849f49535b8ca73089acd5067b6b57297327c4cdddc7d5c752a5d2cb04c659d04f803c72507f5832e7bd528e903863b932d80c51e8b2833684a084c7100728ca33a4304c85b8cf7b61412e76373566c34a75ca88004cab21a3274bca1ebcbf34222e351a3df4b557f09904173065b460d54210511f4515180b3bc0a87f9125a0a91252c1146101738f8f11e10897f9b1b16cc7c57ddfb3e4f6b01ad6239982baa07c56c05827e838c1b4bc99f9cc40608e74ed2d123757aca9d8030a0857ee2676db47bbcb1e10badb32508b87aac4c066fc747ad09a52177b378fc1446ea5aefcc30b0d744d2240e5e94c6f12254945223aa93abd8e71fe926a4fafa2a49273d618a0a5921cbde9c6f9648c6c12bad96d080e39ba128464d8f496b7cb020ebb03fbb2850a7118a7edb1bdc438565ca33850c1b1bfa6be29b88bcbcbb3e6675924550a7427035f60000841603c2b4c9f22040f9205c9386cd1b457046b4fb1521e4fcc47c1a0e7fe072bda26946762167d8bddba8c6d04470a2705fc05a6b00c4cc54409499a4859c4148b2a7596c8c7b2e597f0912742794495491117fec96486035f270363fb88511f756238ac9faf98251ecc06e1495337529b209031c0008e4250f550c3d476352ab82c8ef41c4b8203caab3b81335613016cb71b6a1f2c9b71158526cda75d9057c7597099789782b05164d338593b0a9b5ec85e0e6263c6a54d5a06ab4caa6c8db5b40e099f0ec7c00628373c3189e6c129b76827d160783f183ee14151b3b92e72bc4c65a06296a88b9f75948a18d50f53381f59360a19daba36939c3af104362d725c62f51b72ba1c8526c0be6a36930e19de18c2b1e470136cb7f92d246dc45992879b3762c92da6b97c10a552ff7a8b56788985814d2f9c5cd316dde3b2c7329b42f7492917c9174552219719575196844144a04a0b6718158cefc7833a421016b5193a5b965eb7b689698d14a41c03a408f8713aa46a077eac06a6106796c64b67117acd1bc0220125f4408222159503864eaa8824626c5651959d0f4c250c0002ec513c0817a47927ed99467c1eb6091f91773495d70084a7c344f41e0967925734ad846d360bc2a73c96f754b065112f1f472fcfb331eb8a286bc69cc1486d58b2d4932086f40c90ec601035c3016985962da0ca3571f5f36791a466861527a1ea52dc5a6254303971ce841d165985e2c02ec5b6a92278106117fcb377ad2c6c48bb24899a519626c74da9a3b026623417156aeebadabd418a0a8bc0bec5b43316ba7d7c4145016ca515ae19932a50819ce609b9ee9997c29a9af03a05ae9aaa89aa03b4ac5ca887b7b05a14d283a42da27ed7187369b0108165ef403550c99cad5c3cf7e28bef8a83ac8867341b331c9c02176520e0555af9b8047b3753e1928c849a13900545ba7a5c16bb9b6c689102aeb73eac0c5aa093a1f92810472c29642cd2a549a32bb9029961f6c4a20876ba8f4ab5212539f543c9d247355a300467b5a0a9d130613549d17a185fd045495f06820684c86aaa18a89317ea34eb0923d5600146497729fca9a66e9a544a55c1aa6841c556cdfe7ac0959635281c54e044c025c5b466442f15655474928c617a646c7178bf5b679062ceada6c6d702c22d339e0d3a9563a252e36287fc7975725bbc1a68122f4579a34c9c84318b13a76254c6be35a1ac3b26a8c2b373c6378cc20a7de414924a38ae7e8423fa1a66367a14b198f9980aeef068f346b208aecb13d827b3b5ac088878548171451109ce1535eb0a18ed1c1c677f9ca7f60501e1986ac19764849633c408d476540d6290738633a2e711eddc883ecb5111ce01bdbaa3df0f381facb31389249e261786f79aab0a80992b9a74002c9a7432fe88243f4276599389ce8119b846a75dcaa8eb300a7cfe266bbcb3742bc1e4dca77b986be341a03a75644dda25805bc50818a05a8495fb351c0709a5c37a07759dc0c3a253a3c56740aa8095d402bc65554880c2919dc6375451be6186d18da30c2f35ee4f1abfdbc594ea6ac5799c1d9912fb173044ad995d675751294489be7674d84181f4aaeacd9951dd0be79b919e585560d0b090b750f2f667e2ea21e283577e3aa4f6b11ad2560212f8309fad233ef87c6fa37480217a7b3933147daa29d2642cd582a3ac96ce5026135d5376a586f4604a8d511bcf5d09dd3e895fc3cb7d90a2535a1c31da1b1df5562e1b2a86a116212ab10a6328d2b80921c3c04ca9a4a9424bcc3a75e649ab34481561eb0a0920b71c245c1789770df5a7fc9136d4b573b227614dee4b23276af4b6c3537bcca67b59afa0119e668c910060e04e7c94a1a7fe0e191fe22cc727d12dc6d0000000000000000000000000000000000000000000000000000002d1ca62c220d1a0581d585ab445c7e001ad9056b3d6a44c8f563f136088de171d48790195fff2c19f221b7cd8637576cec18c29a4a51cd07c82eed4974c36e8c Input = d4952da07911c8ceb643e6b3254f7fcc22242a88df735c9aa9a91fc692f32544b7f30fefed3311dc8a927930c50b17577573f858b778294929b123b180498c22c1ddc92a11cda9c0da3cf300664feda28bff6f1873a682451d24e2c2a5991fa8aa29718a43c2b379ebc7387fad5dc9e3681d233641d1b805b167ae52631b3b6ebb0aaaa6507d4a87a808a1c3b62c97da49c02dfa2c729693de194a1bb1643fff14e0fd8d3749ad33936e8b4f8f6f3106c08a8098c6b903d1cb70c2636571253564fb7dbe54b96b1f999749d0c81c698934756b455bc6ec918ec267b5e54a0a812c62de971d8ccd93e4c1d6752afe3d5308c5257abed2b1c01d0489bc1d5fb5b2f4b199cfec784b2bf92dc85904cf78a9a6c0fc3a9c5c1640f905fb8fee2e08b3c0d5fa029062a5d41c82c512ab0645e7a1d728e7fdbcd95ec59d121fe876b1e6d624dba73cf68f35b23bfff7a435a5afc81947587b60d588c54ba0c999242830e568c3269bc96e001a99edb6ccef086abec634d0febbbaf72d872eae8c5606e86d9bbe279395c5370647f245351ae41358cc26f5447c37f959396dbb03e484c80dfcfdf93701e849e081232e85eb15e034b5421dc63c62190ea54a83ae06c89f395f7cef8eaa41517345a3a0aae4705529d3c2c13f71418817287c860f062c6d0c5ee918c50e613164dfd241533dd08928fc695f3b3c45cd75c740f76f6a896cceaafc9afd64deb69db89cdbd589fd6987b1f5da8b5b9115d675d3ab6cabcd0f793f00418c97b673fa31b851c1209140f76492359f3580c0e4de09d2a3efb2b3dd4afd4abde0e97180b7b24a45063f07f82771991fd2da92e12de7a868e6e84dca6a318dd8ef3a1ae6420d63051306d0582b058b7a96f25766aa0d863059483e9c7a17748a268e896f0d02173606e4381b639b480fbf0b3541a7c1790e66810e064cdc9d4e176cadf3d64ac27648467cd0b8643ad1255347cb6b086788f6c4dcfb3363cfef54c3ba5c13562ce884b53b09e6f149a60e1fbb35b65261406ec04f4146b2de7c61c2fdcf0f714981308774af933b710d1d4f315feefa97a581a98dd083a4d31749e5d0af2ccc2109cb739f8bfe85e4e7844dc3907959ff3c04ab9edebf3317f354c5e0aabe4de2e0711ee771b8dd70a3008eb9936f8b6924ec0dc9897a801e00f6738ec7f31cef0db9608d2c3d3683e97befb02f0ecff93068a46e57c97201608756dc45ca8bad93e0f562f5d74790c87d4ffaa67613b89c22339115d7499a2fd038bc4533e46bfb5eef28b06b8fe9a3182c6a8b18286edd1b57adeb55bacebf7c842d527ff5024c0ffabbf78eeb956a5127555894ca8459d99df31fc0fd1e1c5f7050d2cfb427dbb2f67530e049e23f8310b88c39d25dacbd6c7dccb9e382b0b471980d54974adcdb082825a9d6325cbaf90030a58193d5ef0a4e1e8fc885f04329253408b4de1d25acd097ff10e0afb4ff344063edde277e49b18996cfa57a7617b395a54731052a95a3cced450d38a31f19811ba278c60097aa1e3c91e87c57486b23ccb07d687c48fbaef4e814f9500b1e6f679a749614c86197239936be1f7ad2290b9a421c4f2fdbd4178a75cbb9cb1f7eddaad9d369f79c0e383fc9ccbbfd5e4cb93b211c477cac2786395e92385a4c0815d0ff6849e961395eba07c86e698d5f62466492efdbc326ff7c955840ed2877919d1cf95cdf5f557ad069363caa905c97471c85c5d0e65cea1ca90df82a0f8ef5660f68191c1aa19a180d18ef4a7b0dde8250ff3ff0a97dd4d65c3faf1e3a426f6c4b64f1f2d65ce9c5e5921ac20197a00f2331e810acf4f6b71878f1b785a28970d844ab4b6d1a604824db09f15e96bb711389114a4680b1c8b19be73aa5b039116c7a7cb7d2c2b026f5847afd6d2ac804f4ca24554f5ab27db900a159579efd23d78cf5542a038744cd6bdd64a3b59d233b878b383bc0ef38a0a2a8ab60869b64634df1cfdf3b53a367d3bfbbfb741badc819cb01823a8e8e16f6b4a35c380f99cd45af0edabf9de4fe2e5b0e6c34f7dce2c8d9a4be2b2b8951c27080aa965ae3afc422ddbefe0da8f766c8c63823050d1ba055e42352d305385ab932f99c0309dfa8d6362ec1c07e33909ac63200787f5963653db6ba2994cf308c9763a153b6ba824fb8ee94bd6a38f2a12047f7e0b01d090aaa41b4acce8396c18aece73cce364a7e6d9d Output = bd452a700448a4542a31dcddcd0bf285610aca6570d8bc85e20e163a13db5663 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 EncodedPrivateKey = cc4a14e75a6b1bf87f11a240424645dee23657db9819ac274780c2d7d8ac64f2cb82530b40a078791a2ae70aba868253bdc3045b6254c4e29024894cd13723edc7461a37403609b48f79b8e8b1018981bca9f68031dcaf87528a6b065d8cb83c142ba20d68a728a3866ca88e6836cab209ab49bb234312916e432fa51152c763a62cc53da61480691b07a073be74aa6c2b88468bca8302a23d1d6405ddf4aec2f88ab055b18e2b1873862af6539ca83b1c270b6a563cbc7a220cdc8106e6e5595d63a26c0cb86ff11b48066721634b43b361b57a5b4ddb2967d232d34cb750026b362cbd20188260c6a856e9493ae09c462bc4c8663c7903112488b06b2a996dc6668e382e9cdc93e52a1a368b07d8388c9531afff0cc4c07ab423bac717dcc888e213e3a75d69a633f49745bab10f62592f59d53ef19b6a62f0b24216aaed9c91203b7ee65b9d097cc1e2676deeeb576ceb4fa4a867ab7310076a912a41292c658e8f75a98603612558352a5b7beb404fd2bb6de18c7ac838464b6399182536509624e1e25a7821b71edc57c35541cd115ec52c13a739c3de231ada741274272383cc78bc9869d37282f5980209543c92b76ddf99c3d45cb7409b5e44599b75412d8bd122460905c250a94dd4052c0b0a91c9a906aa3652180fba9212046b4f7ad14f7c304780d553f19487b8b7413de732ba1296b41a2d94983d4be93e540a4a4137a030629e97fa640c21ba5b7b5537a03a2a958ec3a888590a5c14a904dd74c83631264644cc6689a245f833530124f7d10e2596a8be227f270941faa75300bd731c145f781cce52247418595ef67c94a170676cda269e51c7ddbc63b6765b010aa061cc576696c84345c35c491d3e4626efc8b73dfcb481c11bbf8c79c6a3aa4e54c43a44141f5c35932486320567ce37adaf5241bfd8c44ec140d30823b58223b02742f3e2bf5864756d528ea36348c1c2293d8ca050b6307d71a20a036e0060697b58a0ada53eee5a6990a9cfe283436cd36a02dcb1a2b7200a267c3f133ea6423bc001baeca953515214e2766f066cae531212dd3551e22bbb1c705f21753ab60a70f364bf1949901d9a0415a36567614c1aba2dacf2c5435b4ee66193c5e461596719790aa792d5a09ac474343509ee36ca048751bd4b0c644b2b039b1320b2294df814b419c3ac55541be5cf4b93593aa4c099142de9e13699a40709d70070aba9227b6c14f216d434c9bc16112b8b4237f838340a5c317a618a91170709bae6a7c13cf96851f72a8761736c452df27758afa4b02fd55b3493b1bbf96dfc45ac743718978b7de8a017eca45dea633dbc417f856781c856c87516429127c6a3d335f162ace0982235ac79ba0ba68edbc1eafb9ed7a3597ca7a612a9bf3ef2b0d1d7c238e98714a434b8b08b35e3885e007501f9bc06e841921521d47999db3ac3937468a54b95b57a2bbe34aeb48ba57f0744021bc684456a8ed413b9192057eb77a5502dbc89c5964c0383b4c9034396da209279199ab5830abe9386b2e811c222a6ccb0cb23732a95676fd5c0376505943ef8bd67a95defe0af7cac395a743bdc3119b1a74771343bad21c53ec80cafd7548ae310293027d62960116a338d74bbaeac359ab3728e268abf75a8d30b118141bbc56670dc0c5b2d05c9c2f03952338170754e20287c99177c66b810f009002c244f213891c5b980aaa23d15f413d4a80160d24e692c450b68c8c43ac60256ad748ab6aa85aeac5c623d199928f88b04ac7bad2c1249c18fe1b867a02a353a112ef71368eee3210f7082f8b216c975070e9a1a27dc265698bfe4849611716d0fa1b1f9047e8b0905d184b1fdd863377353fae732a5d0388c3c6606a773360734c9ba915d49aa7d358263d7abce563afaf382976b2ca2e1328d4aacdfd78851eb143a1b81c21713442421bb1abf77ba25d4355dd10602ce06754dd9a77aca0e25b1260e994d0fe1b83088a5d385251ad5c6a54c45d93a7d1b25cfddc1612b8b30e753814b505524a5b0b26747645c9b636543ac7a871b6a7cd3865f1d8636cb5210ae9157b567b2ebd17fe3f59b73379d086348c9806848ac3ccc1547e8964f6a1c4b532787dc8620050b7e628274683b79e133969ae154da157bbbab159941484cda4108c84aeef56af6036a8efa3d74327dac2417e6fb05e2f1c178023b70214296c3ce65151248533f43a4b50826b181bcb51fbc54279397a6e50113635faca0cf7439be90867a4c548a9af0704da13d12c7549ebcbe5b279afc266fd83b9c4222b717b86fd4724cd0a35238abc2c3390695ab975bd38e0681b67bf86f36cc91af700277998ad3d700e6419105dbc952144561137711a0acaad546e76c66ab5722bae1cc110abdff7044b662beb6acac276317a7799f7ec6bc1282c87cb284006b3e74c361e5c6c8b899ad122880a1219102404fad458170f8aa3576750a9682c830c7c8796daef63042f3607c5c059ff98b7a093ebda2947b861f497202510a6a2cdbad3d7ba3b8da61f02671be3410549aaa9c3140635334f6b4385cf4105ce791db08b73f3ccebac9ad93f1c7abf6289721568d601c2cf5ae2e4690ae0c77b66134f3e1c33bf82771491da4d228ebbb7077312babb47e1262009457a3caf60f0e47145e29a3ec3b37a67b9b418625142937278c50344c05a0a606fe43c229749415064556a55dac28321be77a256637fe2b8dedbcbb02a29ae505c641b004f970b051e028d047cd152477db673875148b71434a80221166698c3cc589374634c06110320b0f249a3ec4856ffeb478979533be7a333eb144550939b00164b6b1b545905612dc24775ac2e4bbb531c6763f934121a8a8d804951b05c8f9c9237046245b422272288e333970f7469a78d543132055c8781ee308382398a7bff70f62b7357bb8093624a3ebe3169e957f3a33019fb0296ea1cebbb484e87b04eec76a3e29cb38b451816a8feba195dfe79e820591d7e73c50139e2beb847ef43e42ecad64b533ee3857dcb35413066c7eb19e8c1bcc42c9959c13ccc4bab6ac81b44346261ebc74af482e34f855e08916e0c1bf33861fb6d706c3a5c03bc62c6d97cba4174b2441a32ce47db7b8703452bc4693be69a4c539c6a6b744211598cb644209e84a711a05b9116574c7a222bf459305f10a68d4c48eb72ea16526ff7619e8391032685e244693ec24b30a257511e00ada5a69b6cb75c2983d53157fbd708fa1e54057757bfe6067d242cee6492a51098913a6b2bf888ccb280dd3cc48c6a95ceaa5a844338cf4985978929e9ed153819b97dbb944e18c0d7530a09cd420aa7ac5f5910325d02368c602d531289db188d30c6fba407f32c41e80133cea869b52e8091f701c3d7a7d4b317e9b0291f05a652165695130c6cb783b18ab1ffeba0f72d2c21cd9844f8ac2826267081a4315927d9ab6123fdb0193f723a3cc3738794f735b1a145b83189b71c597bd8248ba511b9463b9262c80790a09167720473fb77b1da2af8632ad793c10d1916868b99d2d23a06875769d7151c9a524aad51eb4f20bc58b4c572cab2642769fe444362533a04c7350b3c5eb418785e13e05b5459ca2c856b1b4e1b266e9677a27d29f6dca61a2776c92dc9290c04d77d7bc7cfaa8a31a581a623cd1c046a488080ffa8c13f66f4d262aba53cfcad64313c5c2fd838f88e903fd3c7da0942fbb3c84f4581457252e8248a75e185d4b5b64e0634b2ec5c5a088a6251c9c8c76837c95c066a565f9fcaf0cc76a79e1a20fb05a5bc1bcdef32deae76105c581319bad317b7991d062ba1761cf1accc2b969ece35274d7b6a3c8c79142c43b14772ad96fe2f296eca5c9aa4b68cf14c584792b1e4ba1132aab4de7788dd642e307a6b2476caaca69a1f7a3946404a440764e4446c20c216da5965c88bb9e09c165b93845c68a5674105884c46c601d35737649815de052cabbb31b39f95531286e08e64772213280ba64b6467d03ec43c5911854498656a831a366cbc256813d451153a3610e6979671ba7bb7ba41dc832a81885589974f8ebc2e57a1709eab2ae9931a09bc97d486839d6a16b29b7de642aaf1861c31b6ebe82891896b4e75b2360a776678aab892b81c5e2175eb588885b980ca02e9ae7bde1dc6346a13a5964c4391b4a3cc776d9311f0a9706c2c04584d05b58624906417eabc95738407ba197b2a14c6e4655396575b585f7c2a8b262cfc7c7d6f3a1fcbbb4356195b502ca7b278133614379176f3f4aaa49a040c7672cfada79ed5a2400dab4d050560d8a30c3e57ec6411988e941622c64b934833f9225daf42885a5b1f7909d65b5000000000000000000000000000000000000000000000000000000ab6452d0cdf5872a6a7d3c97f59f7d2be589eb4ccf832936a00151b5443fc707a9e4a0d3487b6714e18bcc9d1daeb3127164328a19d5cf60822f3fd37a24bbed Input = 021a27d9ee3c76b205152ced9c68003eedb09245954d50316a14a3e1d877bd9d6480d479265cf7a693e77b8761f11a09c1c30d2fa5f50497ae6a4d2afa3e61b0b7fb4b3504024763ac6c10fc2e6bc77dda7fd837ce115b84b1d0c749e8e4a961d3e7de1bf6b36741be282f9df710b46410df07191c3207dd9e74e8c4d43e3c75607966a1894e86caa95cba51a9c3289b00ad0fe59c034099b822654caec138a1b06635d1de59fd469ca3e928deb7873cc3dc2fe03aa4b5729f91b940f01ce83ae5aedac13d0a961cd9420584346346955780974ef21ccbe3208cb019f050fac0b80076b48ac6c0f3c2aa2dc3a13b914ce5343c7a140186728bb335a47515d361466c2d78f3fc6250f13a4d4fe6c8a587512700fd5272c9de73eb698045708e18b86d6b6692e3afa1b73e5ed55614dce4b8e71ba9dab03a246b1469c617f5bbf3e502632b060c7c17145ba7df290ec310661480de58a56cdab7a2e5a8e298746eb1b7b8703c5c650456c567056451e209148059a59af315540e448c0c6a7f48df9e22f373aca8be4df3bc9bda80e94a92634a612afdbfced39194e124c07748328698cc21f39de459b4cb08c6c73e80fcb6d0d86adbea470a207b0575f180ddc0d658d7ae66b2166cdecdee265a02e56bc4880797f0fe09c081788f5bb507db2406f37a2743a3c22ee0caa51ab62ceccaeaa9e189ae412f8dece857b0faaf61f81f2bd968d0f6c9048fca287f74d954e48ecf05806a695d06bfc66ed8b5297899dd4b3942424cec559c33ef0da1ca083e7eea98585f89003ae0ba98fb3f51becb80094ba0091f97b3a32c635a12308851e070f4a94502be51fc6f4e11bb7803cfbee43135c82bdd3bc82d58383636eee387d2c13c1866982d7c4f15f0be3bf5f87c8fa5d43daba703c73135ff3aafe4cec43abf9c1bcd16e56d6df85fc38dca4d09245677ed75b585722a9b20fd5ffe9d0436b3fb592ca6982ec2b96a8af589296b0b0ffcae14ec9027d4815bb9b933470a357d0afe5aba5010eb0d93a0fab2c28f84d7091e607505ecada258a551238a2ff68621bdf5ee1246c27d6e8673f1b785f7abc9b88310e3c1ca5e266f2c974d1c88a31e27a102330f924fb3713adccfd09c4415c1773c8da37e4e18ef274b00d462970873b54ad108f588c8bee6a7b4cce157109aa04ba0daefc9b5119b3ff9f70d4728574cb9f57573f41760248a8a8cdbbf7492083cfbf585c844f03ee2e08da4a08d04717b6244b63bbf80d0f4f0477f94de7ae6b2883388ba05b27ffe8a497541f012f16bd9ec50f64cd0d14e1a6c2be8c77ffd39d1d19ef402b46c0c41718ac406acb1b71fc044b1f93a4fe98fa8a0bbf09caf9dcfcbd8e8ecba42e4bbac9bb5de40f089b86ef71003b92a3fe385bfe603b098185d05f43819f8686b4f4e14a75463f2026baa66789edc52610ca8d3d5b11f10672c70c80effd7ba0352b2079de6910221ed21c487a7367cff076e84e1cd3ec625065d7a9b8ce4eed9d91c8a72b16a4a50d96b8a00921695a00167b53471e79aa445c656fc0d41da64d836ac21a34be767c514d1571e500fcea435d1a1d59a6d07140ee4d1a4014cfa8a6f0be9c334ebdea053c842a06124dfd165232c1a2ce63babadd8a56fd78ffbed64b63bac3b49e5af81c746253bcfdfd045deec785e0e272ef8c7151bcefdad6fa2bea962d621abd97f9b5cbf1eab792139d16b51e1f732326a5e02926817ed0bc4c6c4680e42e7d5847d6e0195c402e59290ce8a8f040a70980eac1a0bcd3867ddc0f2de9b204514011491c8dd63a371d331b2edb870e76e7ec5b27146a0097b969a6b157d00f66ce53b71598b71869063b9a29b23f3623837385571962ac29ac868301e2ec0643bf639b074c8a28f0a66acbd0ad77e5c86d01cabd8fddd77a4fce6185768566a6d98e679986aaf9978c49189a2ef1a218977f4d2c34c5027188d816cc918061ad13421be77fb910ee5aef5e159fb74169d7763b446e523470409c4fc4e76aa6d98f120013d4af284bb0a8e9eecff71b8544f9d3815062173ad6d4e9c4727cd6395bd3da54237501c73390cc5c48683d780efec478d2a15a40a5ffa3455f52c092993859fc8ff9c1ebb308ed03b5b88f6de341c3be3ddc96f695d68c1562b85806e162f1b07c5f10a1213f8d85f6b7d92e06d664cda2ddba47b93e2922d30c3bb110405fc7dd9213812 Output = 8d99392e447dbb7f7eefd329325bd71d1d984cfb01fd609c3283a84fdd0f0138 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 EncodedPrivateKey = cca22002e0b84e0c0fa98c902c2a30f0d9303a411db91a26576834d4f1645c181bba750c42ab6bcf401739f83fe2a4a3aa1a3f5917418003aed863875fc044dbc99c70b27758389fdd3cce51d5a13b21afe1219f0bab5dc3b15952591e6f80068b30870ed644de082476e7b32d3a531ff8631914c7a5c106a5acbf8672ab4a304afb71b1672cb281438f0fdb1db0f52948e8b0a1422ba10ac5e0a480e87bb844072e7a134dcce36f27274775fc6a8bc611b2a33cf85a4820e18b47b24188030fcaaba998d84a68424c07f4503abb553ec33b4be2af3557aae2797649da014dd0264d00ce74431e46f8969276b24b359c6750c5bc15a6318c2d06898ec5f473380a68302a91eb562fe4f10596012e5efa83f4c55a19912978a6583e4a884e36af1b9367e69ab0566c3cd8c34eaea615f49c094bcbc63d52a21d74c02462cb0bb7c77cbaa03df988b60cba880771a7c179315a9f6ebc6e9b8c90bbf17f737508b1691ef1952363e9499b5007a9c84838c2a149478e4be76c0368a8220b9a3ac68ef6560dba6b3f68257b6719551d83c38f73654fb392af0c1c2517851fc160c343cf826aca2c5614726c774c758e1abaa9ac04ae0742799060970909cbc2f78ca739c71bf6528f0695ea6175a4ac13555c3bcb9920bca3a37d363ba622666e54a4e779cad5059612792d610257a689975fd664dc5081d5ac4586c60e99b9a2a17ac612e5a794ca4dc097a71f72bce02b4907d69d801a22fd7b88f9e4ab284076037a0f6ac803bd7b243b835e51873919d3b77de041bbdb9c2917338f0c42a54ba6f5539d60e827387a9e7c156155d693b85701b53278139b29858785cb59788ed981d77556d27390285bc3f9408cbdc717895815d31641d0c31f2d911515f36743c40f4f3517432c620892149b518fecc80cd2d14c99730e0c940dec155930dcb5ef861b7c80b55c2223f7066b625c9fe5f0cb04f0bcb880119de142ce511affc01d483ac8db8b73e504b242315533d9c02cb64d15445fe32bb0c8e19383f82854981a9ea465b05c77cfd66d97a2b262bb37398cb4654a0fc8146c00b7608f061a216b9becec17f686b93d88309a7ac04c2447030b41ebc6a95fc52466d36dfd461bb046172f3b83fd10bf79c281202a60aed8467748a986100b97742c8d70c8de523c1d700489c391096c1b92654064cb7e35d7b25f29818ff39fa523c88bd69b8cf41689a414288c492f2a83f7b34a4d95770e6144b7731057c73a077a471e7b378fa48464c426ce5a6566e7c862131ebd5a1b3df013641a878fd702d167ae3f369361666514d98f325679c22aaddb56406e148e744960ee1395866acbe095542a6836571959a80238d037260fa053a52cbbc2cbc035e78fa9c306ebcb61ce33422584009271835ac3845524794f18bd7e1b4c034832fe68ba24a162815404f65c0af0944c9789b1d92767268c801a0444fff50399b3a192131e965523bbc2c75c286c96450c3f0733458bad7831205b1b4841a617626b4bee232cd1f220edf53b59bc213a055d956591fc3518a1974582f79a66dc8892ba71ccf7a5fae1c01841428525c32dd2b433445118559cb5447e3c851a0cb498cf99c2d359999fa3969fec41d1311ed2545f5281a09df223bc4918e55551ec060dbfeb41c777c79acb7375215002d9afa37b5a126625f7445c3fb51233650037e070648c924586bf7013c203e907332901ff722c35c1991acb2da41cacad4b709ee242a9e71eeb0ca1d05595fcea8d175553ce689ba595b8f98707a68a4d20f8a1fca8c34c3482e88c8b043a9d42e4a9e55a6cdd867e106b271031355bdc71c85c80713c0ef7c3ba3bbb9ad4e32615a2b104e52dc5e7481e258351385f9c8932a074529e327e6c0949756b57ef47094e184517819d459bbe35ac6154a70d004490b03803e58c9bbcdcbcd8451c2b0373656373be77a59beb2d47410d8a8631745653a02956dd0a0fe99ca87d78c273230667f25bddf3a65a216921a12844b8c98c197026e14638a97fa5144b44189621f00c75857fca20342a09ac44a4aa6c336d9ae58a15972f22555139e2b3e00ac0bf67b15d64ca8ae77a79b44e5b47a72ea06930aa9695b96987aa0dfbe63d83a352c9370247f6b21f225e096480b17333009bb78582464130612970cafb137f0e7c060db72de03a46d8a860b0cb2a45b462e5530eb566bcddda2315a633ae5054957cb74df537c30777a547b0c6e486787c74c3d242ee34158b212f4fe4107885b2d3da2224803e73bb282cdc8ca0365eb70751c3263531b31dae5a29561316003b2d781790cdc2ca09b65ed19995765263f06c8a1f3378d46c19b1b46a43932952a37e4c828e99f95404075b013b7471070422fc65f9c9965a1c0cd0141472fc7004f6319b548c19929f792ca0d588208ba4628cf2bbf7377ddac05a058308b7fb92cf55584a381204523a460310bba06a88d4b69cf62fe2a71097461a8c3b5eb212337887a34fcb278c59931f28a0000227d9cb9b1b3753dafa63e893c9783764bd01b7f668b83cea1e7fd94913a405babb301ffb6b57b2845cb7cd929c0acc7540e1bcb196679380822c7bb67f732a3c9ca778b60451fb03755ba151e6b0bacd1129df5174ebca123805beb8e91b840b70643713272ccbcc2b80008a46b3a818ccfa6ece2c3364f373fc8c10ef4b4c95955052f99202362bc3020cc2528486784784095fbe10b4a44732a2c6c0b2b50d199a93c544a00980baa2f5cbcc6a3456eab71c2798d04c9a85827b8b654c962b7e4125cfc0f82a59632462d656b9b96188cc89373a6165c287bc890d5ed9500ed08ec1f2822d718bb94525ce81cb48b4999e288b5c90bb7e3647ab26a7f5479199f9198fc950948605b9aa0c8d0b133851abe4d77aed7455b70410b54a00bdaa166f0b4712e3916a70846840c8f3f9c80c8a95c912bfef188782974eb372795d96cccfb6c9209cc2cbec64bcd064e238608ea46f841ac02d6aba8ba9bb251a381777b50570a5c79257a964190e56aba3b27c708803a2e6909a6920f546c509a7524d138a9c2c839f34a6a814b10ba4642b7214e447844d553532804154b36f688715b203cd576274445c98abc60192f603d970c988b42d6cc250b4349f2d91b50c123875c608c932a7f85bae2cd54b6de80be13914f2606cdd9b03ed83219ae5623748972a657e0ccc41579b745b3abf6b04b50b945f2f2963504bae804a261254ceedb767e252c64908abeb94669a94cf511b992c475d99939095ab9b19f74f75d30efd58beec598352108e1ca648b5f31bc7071c86aa97c5fcb60bba8884a3c72414916bf68a277a82b78857de531611ab7c7a111a632a64704458dac97dee2442b4b05a378baa74f34154bc8c191591eb2196a4d3174c3848b5f02f2351211f605b2608c9fd8a101b658599b87c65a3c2c7a266c02b3b8beab84feb0071c25a50b23ec8acb1daa290cca2ad6fbc8280c5cadac42993c083a25338150231cd134548661d645c678bcbc0e7815da41a14e8eb123c482e2831a1ab0399ce02cfa1a39a41c714bd8c9206d6c8c922043a235cae2bb6dd1ac430e22947444ded7447e00a51c13308365aaaf4da9dec03495c73295aa9259d4529eafb67dce58b374066796983f06c91d034226aa75afed116c886927e135564e4000cd86016346b56d9864c7abc6211a72cdbcd32fa869cab01f1da8f6bcb84cf1441781c6baa263ea684cf96a1277e2459ea07c6071b06093985b047b791ab6e6593be230099308a79376bbbcd71492a4a4de83a4d70c290aa05b74a8c80fdfb9293317d10e07615acc85d762ae35b187c55060c912d9a2a09e995afeadb874a5526cef75fa4701e9e0a5c082b92ed3b8887f0bcca362b492369881373ab878d00054027c4cef0c07cae57b30fc51e744653316591b5845c0a47492378764769cf3846b263ca6e086835cf0197b5025b2a960097e57597327f28d4b2fbc6bb241863a2c96d3242a031171042fb40afe8a75cc2976903a603b96019f4c7420b77625470b62287e03239e5008c1297888f5322937457b9467e52937996157e50764537ca495ac75fbff53dc1e8cb77002aa7988604b0829976c8e49649f7446495a7548227ce61d963da3bbd2705a8dfc73f091c20e72b77f6640a14aaa30134a1b3fa7083a50cbc720bc9a802a4208568e2a2ab065db245628ef2a138ca1d71fb3f66d6a8aee513f1c80b64a0bf38f01f4979a975054dfca823c4165aeb1876a7a81fd6920974b516d6b3a1aa71776a264a32447240855b84ba0fa1d35f07a8c11361040da933c4c44e88417b585c1a1605c68ce4000000000000000000000000000000000000000000000000000000c07898c8f447decd9bbfef0871a28f3bcaa4eb22ae145d00ea63a463ed3333c253f53a49ff45b0ae588d417a63a599670cd391c5e9885c972593d09350bd7523 Input = 6899d650581d8ddd73d6e7095d24e2962ac573877204768c66a78047649ffd373d4e0cac20e0b98675e6f50962871c33957b5a7ba2af2ab800ad728c2d0e70877cc3f459ba53d432d45f4c9ff4c951c35f14185e01a1fbd735fc3ed84063b579e69c230f41af67c9cd7481fea81ed64bf248c63f56f81115ad8255a172fc99d87d8fdd6db00ee407618c7877a2486b6fac3b8eb7bea62c24bb5c5655e47388f2108ac36d5e55c5511d72bbba65706ffdf297cd0788b4c34ead564e86e78c605359b6b344380a4ec73a4f64b7866a2eaf36a494c76adba39158a3d1d3b41973cad055780ce211982fee596ba61e5e5f7e44cdd8b1d6f866c708d20403760b9fd4abf31a0573afa130aab5bf7493b2365ef5437b7824366fb3ec967016e2da547eb61276be7c5509c2bd5e16d8812c034f6b4c5a7f5f489137385ad5697c4312042303a5d7f62e398bf5fcc758ec1475e7ba671c656911bcc32ddedfdb07252ecd0eeea696046e3fc9e564b2ffca11562191c4a1e4b31d9494961fb66ad44f24c4b0d8d7422df106663600ba380baf53007b6146c923412228936d7324a87050e62b185bf3700959e262fc64bc4f2b55402d57c63539c57272240f4725ea23d389b17d6af64e864ce3429c9c0514c9b384d79b830a9c6fe12f8781755d53b8af9bf81e4784d9780ba6ba0ae36f89a99289307481bb3955075057648129349f1e0ce4e750be53372f82c92230127280f0f393150c89715a43eaac8abf538a031155661b489b066e915505d59ba40cc0b5a4b8de7e731533fd06dda44e65f22b7931c4b8e34a72331d32798aee1c16d81e06eeef892e7858ed2e9c27d21a3030567e40a369e21c925a26712e1ad6344474bf8e9539027040eb4b0cf65b627623ddf81253c6cf002f837673d2389cd296f9abfcd38a36c6976b03432c9100c7ce9bc862d2c98a6dc2f931f62e471369bbfab644f8ae37deb65784e6f5414bf88cba9e6836d3fa3c0ab7ceddd81d31e94c612224270fe79048688b6d8d46acc7d656a647888a469fdfb6ef8c8daf78a2270c5058e9b87d2fc0e4f8a098c1cebf96e06ff1edb382e545387b2314b2f7d4a669dff20122a0165c285258a39e2a1d27c5eac3d79ce0cdc64dff98a8633882db588a34b93a1403f6a739bd056cd2d6531af36a2701acf47617024cd1cd4b9b60a02cdfcc6f34e4693eba3bfb32780c573b4482a5f6bf109c7ee51792252dc119a5e41a4ea8f25557b64e500a83a6d8a839c456775a9ccb906a733391605bc487bbd6ea7272325df31cce2093649fa8a379f4977801240ea2be8b1e6a5ac95ba613bb2798bfd1cedfc34c39e1c43cc094f8bff34607f8419bc3ef2fc0c37075dc49280656304d2f642c5ffe86d5cdea4fe96cc8b4451954e5d898f6cdf7e7ec5af447dbda66a254b964df9e8dd565d46cdf04dd2d19ea1c7400925be2105e45343baa9855c5236dd70e042d0153c904d30fe45d087b0f0863ec603ad74baf1836b18c91d98455f3e6477936dba7379a6072744be6d4c64bca89ac3334ba727e0763f0ea52faff3daa52de9fad1f27e566e7a6e85914a02bdec5f7a8509f80a616f6ed66848d4ce8920757fb7611ee7c70366ce847fcb62a94452dd2523daa21c759f36cd31337afe1a5c8e8ce8799c6f03873f58bac3649e0d0fe6adea0199ef6eed64dd1e2fe0bc606b97ec8ed1e0b567baec2816273b7280ac91b05fb25e7467e934bf79025f5b4060a813c221291cb307f7783d5877987124ecab1d9d8c8e36c10608871a92e8878220f593cbd4ba61c35d2805500cdc0b145cd6ad2cd614481edbc913733e3a5104b0006dd26e871df58f32047701b2420d93bdc2d0a2474f7d9927e7f196993d9792e30cdff67ae89bc6a27236a6f0ce0439d4b04788765943c2be5c9fbc0f139135ded84ce79d876eeb37f30371194c8eba42659c185a10c8941f9fe9fcc722183ba7e22a7885a66d8cd10f214f4534171e0836d86368cd04d87737923da8801166afb398bb345b5bee89eb512cbae07f192aa50a932a5d92e909e65443f4004fca49de5eb19abedbf57d066d134e096e7c63defe4430f8e1886bdd3cfb8077f7196584398589ced5670c7be91d715a20f51603db8ef35724805eb1c270cf16b282ce7c79111e4577a0a1a27a435c070d6b3e89dce1bdb53826fe9a05d86e586ecd950d27247ceec6d Output = 71e358b21b3b98d915b70e9b877e94159aabe9df32737c71c50c2f99d7a074e3 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 EncodedPrivateKey = 16997ff80976d1506b23c012e387ac6ca0a792f7481ac3c9775317ee3ca5267bc7180ca884d28bad6b5a05b045f33a9b975c6c98908d670550b874ca70a77424e48bf097256434b9d9b96c8b8149f02ba5bde9b813eb2b60f20da4440b4cfb05716bbfd86255a1e82941d2816caa7253e7368a4bbf4bf546f40b1bafc65bb994c34f7337e82818021797a431cfc664699bc22b92561fe3d1cd6306b89a36380920abbb466477549d1bf14364221c10f51fc3f7240de4c99b3bb3eeb9ac1fe12bb7c97888e8386da4a341a0be8f78a7b7c49f2184376c3c3784289a6bd9b6a03a110c228f72939b86c7a87dab3e093c0ade693a0e5331c48b761b070476f55cc45ba1dda14dfde01a011776143a4d29d48b47b0c6cd2111bf18360a7438f384a28d772177f648773b961a86637c946d7981a6b9f571a4c29aad07220fe081f1f18700f3c99ef28e76819f8d7c4c43d754cea21180c43357f3430bcbce1fe8952c691cfe9a7483026386a479eee4025a838df5c563b9f5a1882a2d7209a68d231ee82260a7eb4fc157936deab52618cba32772fa1440fb675220f4610d749a5b3b142f31b404d94d2bd816cc4773ec83aa1445a37b361e52b10960827e94171dce3c12cec80a1ec65aa6f117fe937673a78cd7767dadd3cebe0217f13c903ca25d6a681116b206acb46949b18f671a63fd2581a6c0978738460cc51df3711dc1215dcf75525d30559ab6bc52e16fa513753454888189348f045aee8a32e98cb2dfd708e7d42818115e5c61711a0c43e85a13657aadc24b5b30a04a43cb97bafa433204c18536337758c0db6154d4fac670fa3af148b52f24aa731c31f98464ca9bc975e97fd665710ee2c56b024fb8d7c7f4a20cc9d510f8eac38f96129c97b17c890417a21465d05abca02754ac3614e964f1a24393d05ccf5cb9500852cc9231656ca899f3538df30984475209f84ae8b99983e844b06ba4cd8a9640a513cee439ae13ad57d3846aea4fa165b68c6c03c05c835bcc5a63d45cc5568aef94ae7798bf29aa7f38e275c902236e63872a274e4776cf1928c492036166d04eed9ca64aa16ebb4b11fc3ba802c6b249e4b53f90112b587d36c6bfb0733a2ee3003419026a10a4c54c2be294b2031a48fe895c2c9920b3772f127338a865a82c3262dabac113c235d433b90d401f5557bb1bc68359020f75742c2008c2bc8862416910f53772a55376ef05a5eca853eb1ba5ef841f243b8d98b11e94483ad7e72fd7360a3641159e481ca50971a6e8aee73a0d4f24b25430ccc0997c631308fe2aaefcf79af5d2045932043d95933919b21ef87865b8550742a513d67af756c5958465f582983a777e9032ac43164e552358861a0ebc458e55865fc3545fd01b0e7565877ed3229f8267369c319abbb017a87ca662c635519ff418682af39ba387aa38ec37396b4d6ab505219314f4448d0f572f4330cf33fa1369872649c922bcd228c294b3213a216e59752072b8e026700ea63061855be3d6037c0cabe0c21f5be948ee4b18dd935ad358a5885a0331db2e496995bd47c3ff2b679e0abafc02804b6117271a2b00e33bc06250fb30ae2036716d30a50aa07e45f244e1f0100d74933a0cba383545cf629d357aa8927a7bd4f6575059485fd455be7198fc01a509920f6c0b8c5a565b4b86c084a60bd9b9b6037727df67b83ae06c5e47aba5d263ce83808f40a378aa43b4ec5458b33a0eac8c816abf5bf76a1220a99205258cc4a9236b4dc252cbbe8884e8ebc1fe921ed408582182b273a199d121153ec38b7f183174754f66332ca98b87a31672720815ff7bcd0cdac810db905ea76e6496742d26b2989b201fbc2936f5a6cd60c35e757f8c33b75277560ab948bab2962df9c38c91b44f08090e5585d852c4b729c52de88fd8c54722162f2d7696946c7b710079500136a28b9abf9a5c0294a5b265865cb04f9796b648f85858f8982f15c2bf31626b236b2c3a6493910be2cc8610829d96693cce3686b8a63b91439118fa661729462ce58e5e28b764aa39911569d1ca5c1b33885400a16f169858930c7f135ab6a95d08ccc70d057f9e73a4c8ca2da7185df37c8a6f727893bb6db74329cccc4692589128867cbaf28694fa747e86cf98619e99b221db88a81afa73b3485846e77cf311b99822a8fde459d7d01210db0ce68054199939e8156f8f7c33adf5bd5f2c54c6bc70054a5b8e305d526c1322e49f57c47264091e39eb0c72a596ad5575434c4de07c0bbac32f7ed30a0930221bba0aa75140b0c97a6e1775e1211740c23390f0094d144632169e4a0c2534479b85546a7fa65694610b2fc19488a5833aa7bd0ecbc6dee36997a900fad18b1c13b7cd381b1ca598038c2a4e40ac374615ffab46b3cc992df777eb0781aec573783b75cb426283ea01bdcbbdf8f8b30ce92f46cc7d4ce407bacbab2bfa27fd7792f43ac0ba74b58b332bb915be649a573eb22c12b6037b4a8cc109cb4495a337e42ac82c48dac2099684bd01700b7da007dd8039bd6b09900776cc783ca114358ada02cf5443c9bc6c181a6c86daa79371bf6e6c5cb68b7255d592796bb7b38c5f8c655b2e480cec127a2dd4aae4b23c44d4367de78e74797b64b0ce07a36e73613ddee8a61c5c32f865119f1a60b44ab5a28374af3324e68604bfb33962fc1f06d661119c0a081c45dea91190c4cad6b6253ce560d4e7855a64c58bc950bac88ce61b76691a93be4b81c202768c984ba2d9122cab4880942c40d87022b91c5ad817dcb5037b835dffd916a2b35c09f782ecb72cf63239b6c33bd73c0efd115357b283bd6512c1eb3ede4730284328a86021fa805ddc55c96c1caa3832857cacbeb5353453638ee70669c4dcb6a10c723b18c71dfc44fb5600c0f8cbb35c6d0b075335f6bec7ba1306766591575b5d2b4eba76a84e326b1475b5ece6c3ccea5e555616d38c03fe630c3ce56d3ad73858539d1718b915fa703996ce39745831b3c93e4829cc5677e5a79d3b1794f81816dcc2c5babc859b0966c76c23a4e66f1031634c93b8a51550d7850d5407b4e2d00ddfb5862c1c570b778042986f66ec940c5039dddba773c9a6a3c10e370714d0a4a43300a7b06b01aea6b6a4b5c17e7482d59bb9e1fb16897cc0340c5b65b9239d973c06d41f6e7b9f351a22b8eba6ac1148d91bb4f8959395e6a6ab996fc79bc8f0f7309be14fdb65bfb0287771908244033a3975ce2ec096abb9c15fb40d33a074fa2c84bdf7b1ee94746c42044be55484a179ec5c7edfecce56f9845f29c7c535282759c2d0a2546a13bf56dccc6d4463376a46ed05ba7f54577f26c78e2aaefb0928c36820db23a999e4b399b9b4fc864444d665e58ab24577533aca26acc5c512970c3a84bdd6fa7c7fca6c60eb73a1ab79db779c208c61a2f5311a694dcb7ba37ef7c7db92587d4a77fe3665036531d12c1adcd29cd2ab733e1b2d3ca56a2c7c9f7e3b96d6355b73c4bc4061ce276308b449cc0660b0f9c30fa4a62005f836e182a77e0b74d2b86e3bb6a63fb58d362b9496025bc5485a086808d3779ee28038d1939c5e39b645db160059a04e1b8e0e532686f29d34467fedb02236f3bb0b699c68726961f49824d277c8495c9d804a61f5320e61bc57a85bef199700d18a69e25331c41646abc434e6033d4abb30f114c35377365c51f5173769c315edf076e58710449763af61cc316b5a3e75346bba705db322cc683d5258a249a22524db0e88059a423c9b55d173eca88ed47cc4711a2ae295b846fb113834ab688bc2a42435258b9b1be648c5889230dc153273903e06aa2590ba5d77a63a16853d304933157288e03af785bbce36067c296a18cca79a18aefa33855683becd7b19b3890de40a24d6d389460a4a66378da2b82980e61ff0b144bfd64d0ce294e9816b9105c20c2076ddaa1026c68e50982cf79ba879f630d4eb8df663390307902207950b8b9db571c306a033272ac8976133a641c585d43e730a4969d752072bc6f180180e0ca0fd9c27d7845be15cbdbdd44c7c525fd70b5479c18a24800833c9338a5635034704db0443307c616209ab2172a0bc42c239d87ced11779625315ec168c3716ae62a209ed7096ecb83d7939593e519fff06e99a6a09122c5bf20c5bdc09af2402a3a605318d68c2b31a284b33b1719a4b6c7a5fbe4500ce23f7d858456f47d135a8256c9b40f52c37d07c728da600f127738c027d131b19b0070cbf9322d1865fa515471d461d17c424626b305d68e34838d5d7a35fb91816b65a1f9403771fc3a8f22403ca8616f89995b52425d618a63a789a0dcbb9ac196bd6612fb69000000000000000000000000000000000000000000000000000000e07f23404b053d03c5dcbfc340f9406bd010d254685ac2e204a32e68c7ac5afee366c059f5f26e6dfba8db203c5b27beca8fedd3de2664f6bd5c3e2ac9fb3891 diff --git a/test/recipes/30-test_evp_data/evppkey_ml_kem_1024_encap.txt b/test/recipes/30-test_evp_data/evppkey_ml_kem_1024_encap.txt index 5db6f99e97..f1a05c6780 100644 --- a/test/recipes/30-test_evp_data/evppkey_ml_kem_1024_encap.txt +++ b/test/recipes/30-test_evp_data/evppkey_ml_kem_1024_encap.txt @@ -2154,7 +2154,7 @@ EncodedPublicKey = 1cfa5addb505d4b3155f44c292f958f02c32de979b3b042f85ac3354fa319 Ciphertext = 6e78c7085b62594c22b881c61e63674892e8b15be6b3137030cf91834ac0126295c6893f0c386b7670821cbbcafac5d4211cfad5c1f75deb8e7df047b950fa504c189fcef6806e16c7a447187a7877ff91d5aa1f89d9f4c2f8c726dd7cbc688e247c929117e01c8cf93e62440ac3f9affd27ecfd76d525dde13ec8b3a6686e25cea8e46fdb3a264b4e1692bcb1cbfbf6e750a1faf99d8864c1a9beabe0d436b7ec5566c92be999b165ff4f30d6ba43347c326edf4a41ecf2d35cb825bafe62184cfc28b30419f509b631f9affdca2b3b78771fdfb006f5b6cca6d0f5522308543b4a1fc65463d8b0ef14fb3fdc160178692d598e59d71110447fec3d02a58556bd1d17d212bd09d4dcda359fc4ee60dd2f0c73db72ee684a28b550f6b17e7dc8e2bd1867076222033023851676c0a55956e14f2c67874217e5349918243011ace52437a127c1a743a52c7c6fd8a0a007d5d020ec1bfb9f98b0ae36561eadbb5e23b7202d909c7d5fad270542c2e57dd0a54fe7179050b7ca81d72fc8c4f07f45fb2ac905e209a3ced970bcf5334daf441a0ea8f250d41be94cc33d96a42a067654f43047cc500214d0a54920f61728b6e95a014926f03faa1b27f6f5cb4397347dd0744c09ad92608ed7cbc0bae29092d6846fbe0fa14a38529e00c165a7ba098c16e532d43a8e4bff1490c45e0a33bc02738b4a1958cebeb39fd30ed7026b3a015863c2e4a2ca00635475678132e7fc114fc8e891711241942b787384ee22352b2811cfe1a22fb7e8f2e173df93e59cfc98a677a136ec29bbd47bc66070a7a8fa3a709aed2123ce55bf27ff2d23eb87b9762659d16ced5e24b7e825e0b4c2e8a6b6cd1596e4fafc06c9e90a8f0137ad182662f54288da8b590d42c6fbf9bb14cc8f23fff1abcc5885ecccb580d93846b2ebec01bd528547765fa2c231dc1b5ec3b3263617d136a102f6e02458444b158162b80e9acd39ce90db232582ecfd679029c6ed4d5a17f28b4ef2a120455b5933b51d3751728ad07e9d1ae3dc52d690d5838cbfc8c8d5bd7284dca1b753be3cc485aff60a120eff28891e902af0ec3358785a0ac87f99f18f268d73c05ba725de2cbc82d2918f1694c3f6c813d02f341c9f40a7c75bcc5984d5ecc1cc308eb16a9c1971d4f8e6a8d5ba59e855656543c0c7e5b7e49a360bc31c9411da0642bb815703bb64fb550f19fbb0bb993453ab8f15ca9ebddae7ef5acf2910f130f95fe1e4ca602f7e09d605a4dddacdd3cf5c2830a7bd1fafa1d63f7cf4ad511303ce42fb6348397df469a813c822527b933747f8f419177caad0787b63570cdb807a35a190a46f2150fd19c18db91c9435908d79449b23430c1d26a7354b6b9d1d21f31d160e767681580c770bb264dcc24567e88a8bc6512831fba35cf6aa4fcac1040b200df1c60b88a3d7e1550f0a27e8232dd88a9c751624198f811ddbf1c2a833c58b91bab501e7cfccb5374c21482808be44877ed51389234f3bda65c44ab5781da9ee3269a0cd4a3f13f50ec1445c859fc164774cac725a3b561bd63a97170823fdc07bd6ecb46bcfcd76384e7baa0ec3c1f4c89215e26b580962502a4c06aa26068c041ff1354ee9ec07da71b163901784ef525c65bd00c403a9445ade4b0bddfc30e04d278b4873dbd1f18f4587cedf870d958b16be02ecdf3a5cc435b49e0e56775521579530013aea6a081aed4a5774bf72918526eb290a5bc1ef3f0ed9440863c1133a70b1481d46b6f0adb352b3cd4e50bba138570b8e5617e3a10b6382970ace312b95d87f5e8a6baea10d2ea19546acb5fcbac0d20e964b7c0bd0d1825d3955971bd657c316710066d81ccc421c786f7d21df4e748b47111732f1851dc992322d5b50cfcb66321b46588b39184c503666435d620eb03a3535b9611e7aac801e9cf90ecf7671f70eeec6103d6e00a2ca5a6a8424e645d4fa89b058b5f77441437e40bba596d705ba522fae5fb1240d9f9e25c9bcae741b514b9ff33d0132db5f06a73964f05dce8b41a568413bd7f4fc78a4c7dbd2f5815f3dff8f25b2e82a508f5f2fb02087bd23927707bc729574777e01ed0c93557867956d8493c1cd9dc86ef3c1e48986be905101578c8e7a11ea96709929e5dbb1560bd4d9f9acb7957355e09fad7c97712e890234b335fd950e25cf59a4ccc6cd461e6ffbbc43026faa7dcc6df33a8bc5f1dae7e5 Output = 8918cd0c3eabdb8267e24b79272ab6b67c9ea6418cab15e2e3070f6c747b4dc4 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 Entropy = adf510dc0e997af14f96e4863f316475be59850bc861ca0d1b057d6b94c3b5d6 @@ -2162,7 +2162,7 @@ EncodedPublicKey = 9d76798256925e67ccd5ccac6d69a85343825b6a20793095e1a29d1b526e1 Ciphertext = 02c49972f757b82c1f5e7ff048b375cf05adac485075ca5a1eeadb615de1306d6712f0cfc452db395c57039fec57708d0a35b7bb238d1e4fd58301473cc4737d72ceab2b097d513ccd17a7f54d1fd145bc28aeaefd2157f2a8dbea391cffecfc2e1fb86c909b45e97a39b30ff59f176b2359a92cab56cf8d04ca42a08c70051c8d9405fa9aa2aaf5724d8b2a00528b7818671af4129c527bffa74702f02172bf51cb8e5b7c07438c785329807bd022fcb5aad5286642b1fbaf976af9816d3f0a3fdb79c2787f6abc1dd20fbb2995bc2a4b2408f5900c68a60f38f78037c3ddee01a3861433a7d9eeb5e7a41a56d2b2a11615d8ef8751d19cf7bc5e5e46b0944dfa61cee6dc16c490f5c7b62ebb6bd9bdca7dee23c3bf1529a4bf40977b307e945efb6451d4ae1c1aa507e30f653ef476c64610edb39201492434dcf36053f668b43746cda8fefd4316425c92f97e1900c62a91004405349c69497438aeecb876ab534220a4563138ceeb3d4edb0d70330ad031aa82dd62e19d17f62bf83dc3d4e2c3850d47efd50edbab06c9661d1ef274e856d8ae58564909625de2acf771334ffc3a3d7a0b1a382e8a17c1a1dc0f29401d9a3dd198a4ad70a740700301da40b468fc4232ae841489a1169170d5131d9b0a036149eedc23f2abba55883ffbfe4788c887e3248bc1de1b3677f286f1269d110d574d01199524d93263517afb76759bcc2728ac595b004508946618b55b0ca734431e85496f07e153f9707d876b6342cc99be864d9d603c645bb9731890d497d85d955e2d80e2e660c93968873eeca1a51157ceca558c0544040db61fb4ac4e20effdccdf950feb214971dde984cff17a75973b8d3a8cd27c92a8686fb93564def326e3cb617411892469be218d663a009c37e2d573b59beb4c5f62206f3a0df818608583e73d12366fcb1d685650d72ca4f533b928c0b4772ae645f0b0ad71bb8313a601723b8f90ffcc53dfcda9d092f8931ef168ca2f53d4600677833b9443fdc05db07f80c03bcf6e364fd4d85c89fab6a08cc9399b10afcb908cc4b6b6a3f6a4725bcf8de94e6515345e333a8324765ca69ddf9c61539d36c67e91ced0396ab2adc022ae9fa8e41d5a00168cd8c9ad0291f653af63e67b90ff2d448fdbb058702c551d323f5916ed90f6b87e354944e167887c5ea4b37703c8b0a94edf20d188ea989999deafe0a6de995434275b18d17a33b100032f2796749a385d972542dbc9989311068e84f3629bbb797f7c6f1057d99185009b5ac0d43d7b944b2e5f528cdb26ca14d995671e72eb725bf2de60289da1f06d78b137a79ebfb75425446c20b4310700053cf3ad58ce01cfb4d97325a27e5b5eda3cfe1009cdd186313ec3d16f005be47c8f38051cf2108b85ec43aa0d527b8d3bdae4e0a7a711c6fa69998bc26a9a8d2f7433f24f79c0dfc74a56083b42de7860b22c45f0c6e31422080c7a21c8d672fba60ce7652a90a3134f54594eb0fafe5a953e4f179ab06ea6b9795bc31a4f6a7f18bd5f1800a5263c48da4ad48ceca613fadea7741dff9d90f6400aa31519bef0b01e3312a5042ac35362df5e61c8e04eb52bf5bce0505ea7233b516321a08185fbdb9ff8434b4c6a88f880f594d100f46924a26f468c754d6af07f4868cbd7aff2caa53e5146df4afde9f7753484fa8be36baf89ebd4741b7260ff1ea398d59e503f5fd6c5c543ae1d318dc1894a48025c76e872fdc3026bf33a91b4618d1618554393eef6f7816b7de65c4bfbb55353cef9a53ad35340049ec65ad5af27db6fa597eae6499a3e5a192ed731915f6ffac811e35555ba5ffcb6628f812bf71a268620c161fe2a571921f5bceb4d0cdca776c7e52f68140845f455d247cad416c4de040bc37f5421e2b8bd6a049db84f0b3c807c3bb9d47cc7ac3ae9599ce82cebce8243306c0f3de6af1526475387c76751b7412a227571450599120570cf3cda19264136e0a93b4d25a160dee03d3d812dbf172618f58d09645becacb5c287b3b01ce4d1121272747648c50112c44728f66d86bd421390f2b36ed7e18b09a985a306ec52f240c0bc0957335483439f146b6c340f7e062a6059b1d47750c11cda575f8a2aea78ee09af0e06dbc2b2ac2b2bbef17fa108681dc90a7b970306522e521aa987e3ab6dfe2e1b3c6d9fa68897efc9e998afe55620cdbe9ddbbac8a0e22395d5628a Output = 6e63c5ca8af98628c02c8f1d520615a1a2c4824d5d155a6e51d181e8eb44c7fa -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 Entropy = 3983da6a4615805f6d55c14ba582d59a40e646c7ae77f4835a51afc6c37f11f3 @@ -2170,7 +2170,7 @@ EncodedPublicKey = 452bab83196c047889f7eb13897b3d73db6ecf5c9687c3a97d5b3fca3071a Ciphertext = 841dcaa46434e75228b0bc10733771ae67fdcbef99433463b2aaf2da88a98e1bbc748e1d14239a3a91bd2b6752b83302265c58d36f176b15988a3cdcc0f65cd72eb5486913269eb31b42bd0ccec456b72ff18f3801a1ad44c3ae6eebfaca59f2ee8308bd6c4c05a7262a01f168662dd42153bcf885ca7e84adfbaf6429bfacfde0ba36426b17dec09cee0591eca54dce505b6f23d2b674fba0a9dffdf7e77ee007e7570b31c71723047c3e8a271d6876261fc1766e1e468bbaec2a42960c2f0a3ebb7dc5d5d6d75a24245a375d160bfafb01cfa2c08831b1ccc67bf9d05df3a14d8f4b170e145311a793a92b1d59602e45328e58c5842dfa6d7021e1c65a900e0b04a79b17edec62c5d1c2bb8679174b45da0cfa336f7a0973923b8812d7b2015e73c42e1219900cfc3cdc93824b55724acaff2158d38732c429883b4d461b74a858cd167ba9e47f8157834f2e758cfc1c8f0fc5e762d56ead723cac0759cfe5233473b9706be8d909c1bfb2cdecbe7eb15b74b181e8fb949aba6b82e2c7c1d40bfc43cdc758051d1ad428a43bc7708ea9b46ea3f202974abf44644c7614769c9fb39de6ba9fb3009cff125fae0ebf0ecf5c9dea4ef2b9a8f26fc5d27d875e068ce3d319f816000f1dd560d03cccf97c5485ce65a77a326ed0fb2ece5cd5a55661c7b41f4b08486770cdc510f03b2b85c73b95d0d77b0aa75f677682d0a383a6e69ece0d5bd62568f2f50dd64ce3cd9e51556043323729b165e4c6726dc77c78025faef0653e54c6474834b9e2b51c66bfc8fe90e6e48fa217add307120ee0c00e8ac8988e5765e66dd0dfd92c80a3b19eaefb46585f0078f5f2de0b9c83ee10996b27b7c64d0f7b4d3be78ae18030bcd792e83bbf99529d1e7917bc053846268ded779a622e83f5d2fcfb0c15bdb1a2621188037acb8999ccae846ab2664792b043903c3e6b59c2645ca44e2b19cb21122035f7f3b222bf382800df1d1d8926eada144f880ecc739bb5644986f0a3c1b7cabcf3c9cbc7938802274ba459c1b870ddc516b5ea871fa6bd87b8cc5e47541f1dab3b9fd63865bb514b85155c41780b6ae24a02a06804a319d3f8d81383e7c8167853f3e24b35e220c105dfe14c33441f928c6dcf63a606500539b602f3b3f547a49545fa43f3fa6bbbd6049d9769ae5ac0964d00d68409abac87369f9608f2d244935aefce11e009fdc9a94c4a803eff45f989affe68c4dabbb291de0e7251a82bd5e5d19bc165fafa25465066e23dd905dd456e0d02ec3cf229c330d404b5f214a37363bd997979fd171584a296cab6e37928940f6bde0d1ed593903d86524449ad42248572680f1b573ede4ae27237e56755485657a5f542577700680308cea4a0d249e48138743017078e668e9ee556c7ef5a83cca9f96ca22beb7e30e2df1a793c6e2f402f109770ce7763eeb057f65bc0fec1fde8ccbeef1441dc98d059d1589564debb2a993ce21031c67d4d8c61ec53160be67aee11ff4b901bfd7c91f6e1faf7aa525aa8d15c3212ebdf0e3a5adc57690d446fcc9435caa5b1ed174b96d4da42851545ce1764bcae48c5fa580802eec2d1b83e4307c1da0dbb2a0fa414d2db8d6335f898fec5e391d0d7c2098e35dcd68afa8adc29d5eee9a9cc6a517ed310897e69eb23ce83e5ef0535c0f64d4f8d62a962e8af80f47a7f76cf735ae4ab09db0b806a9c4b2fa9ee493d69e73af045e6a1eb07b5bbd3241ccce8b5196080c2953cbc50a2052126ad754dc971050150d7ad4b319fd85cec8c4be05b55ddcd5ec7e804083278495b1601792464202969dbe01488f876d1655e0a3f4879ba41712c9136ba0f99d4bbf3145f34bd6f4edad036e6db0ba2532e35c6c097820d1fb069f9d69c259fb17b94970f2cc8284e5fd80f4e6070b4389bcb49ca99f207d002e44f6f0c9046fd89c0ddb1d86b01007c02920acafdf28e49d3c209e3bca054b67398b6c6c2561004c129947d87d33390d28489855074a6777dbf72816f0e1bf9488009bb0a247784c8a9b8f13a163d86a614edda8d205058071c12845b21e82ead309ede45872c379417c536ba446272ffb63d924d0055a92c320739d364e3eafcea6d10ee09a58a70c6c9a88550327070d6de72034b8140976856895147e2a1ab4ad062c7d299228a50b605872e3d20daea3e918f2dda9f8182aed61c93b4a47c5796478e182ba54c87fe Output = d0ffac51bd8b7e6192ac5954b26a5c64f4d0ea746b08d9f73602062aa8aaf7cd -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 Entropy = 2676b8426b9d6a30af007094bb76d65d388c2b3da938215dd6f6987206400e13 @@ -2178,7 +2178,7 @@ EncodedPublicKey = 04db6353d04f4a88b97b6aa5a6a42a101a535da323cae6c7dd757de67c24f Ciphertext = 8106cd6746bff4925c2620882d571c50b36b066a5ea43fa6528351d97dda7dff1d9e9ee6ddc640ddb88851844c388727c918152c41c814be39f274183e116432a61f9a7c1885f07bf118e4ba631598fa9b1e01e72a68ec43dba62235587c9b9dd1c8e806174ad612a2ffd477e8d0edc2ebaf4036393283b55144b9c83cbb31d1674565abf29a56980dc4a3803a389a20dbf78c78a907a5d651649c27c9771ef436c189d1922564397f5b5594d7efa951ba7d05962df80c49c1f73029c3d7899852d8a1fe03d1245a228028cf713f4403abc64a9093d782cd1a6dfe12a79098e07f40904ad146dbbdfa919058149b051bea097a60aa0373cf9c0803e8da99c03a6b83813f99adea8c87e6da09013947cbbbde8edc3b7ca29f3180882cb11bec706f4048a20c5938560ea83380be5cd75f48d77bf3360fc131509317dd72b9340bab91fc6bf7ce099bfa58d6c5a413fd2801a15ce7ac6f6f2c0447cba39987a37695468cd0fdc982631d9b0354205194323e74d41c54e0a026c4e67467b5595aae7c8346d1bc5538ad0acdd56fcda32f95dd7830b65b2d98c05355a3ad9c84cb43c23ef9845250888ecb6f992da17f769a13bb7bfd621571f98b42a9aaf19d0626d7d59355d9730371b29a3868b97afd7013142866e0b2f1c54841de47c47775940c58475c96a4881bc69c6de346e05f55cab15d497392fbefd2309a834c733eb3ec8df4ae65ccaf690af492e39d0b5c91d09b39966b31b47ddf6751b481966f19758dbbc373debf284640015cb197e53120e0a36ab02203e0992f35b4c8347021f8c4663c996597a466b416cf271e04a20045639635b904b63250817c29451dd2ada5f3011500f705c2f0982d236ee1cd02944e35cfc6704f0e8fa30d8d2d595340b4245d3f3d5246d368062b53f06ad365dbf12c0fe7f492690fbf3389d234e76a618e63f785af41b2f4af70be0bf0a917df6a5f34683d931604c6df9288cb9e38b8d8396ab2e21a1c9a54f4dca2a4985c3c4aaf20af5e6fdd126860df422a894dff4a857f2a8aa54c4bebb70d44a4ad15d47497be7e0b7487003ecd6f92cec84bf4c459eb5f480dc20bb6db735cfaade1ce33782aaffa6a39e4f2ce9e7df44347b91d75bbe71b824d6302608dedab325d00163cb9e0a274ce49717bd6ddf4b9c02fb6986a8f765ed565f48c10dc90f39b93aba1a69a832e41f2b0dc2113fee500c99471ab67e3ab5a1cccc0f92273739eae4747de461ca3ce6161b558577b56af9e695a978970473dc671efcddda2bbd8d15fa6eb8ec0ec9f479bd9b8d3dd4865460846733856fd57664760bbd5ed354696ce6c8b44c6ebbcb07920cb6c3cf769c005503add472c7374b8875d714d25c74e2d4390ea455e00208763f56e475b630a30875bafc70f87f541bfd0a28839d441ce567db3be7a20e2773f08ae73f9686b95623fcfa7b1b3052d64448756f9a7481b1d9c6022898e79afd4c2290a9ed2e0658c6178826ce94e0ab460798a88cc54558c51239bbcc5347d59ac87fb6580f84aae6492e1ca700093438889fd50eb7028153e8b4675fd272667fa022b17029808b88df427ac048d8b410f60a56ac39220f8b509ca93c34c7dd62934f62a7e29aa3b0918299fd5c56b3c3158775a3b3d5c78aaf2f656257fdaaaa5b7daf83294b5fc48d08922ea6f5487d647c30b1c11a30d2b1690958fd90107a0d6cc689441a36d04039bea83c447e79b04bdbcbab04427949855aa1a32790075438ca6ae6f7897581b4489ea1dbc4c025fa1ebe698959a8145e8f11aa1cb6f742d1be789cba73fdea457eb0abf1e814c931922f451a7d59514c3e2526b1378be1ba8ce317ec3fe2e3d983edb346874f5251d197ea02c7b16fef2b7ba8cd3b0179b1f935d4aa4d463bda2d5dadd6ba96c0ad630f1eff86e34dee3f2eafb9cc5f5ed13dac2149a583e2af8db3a789c39f751e645acb58743646c6f65bb12564b8f26697e80b8d9636b0833d71433a0465dd501eb313158275608390568c7130ae5f998d3819ad7f3855d26ddc9f4ec07a36d191450dd6502a28665eaf8235a3f10b90aba654c70974038cdc9b3335d9b865da8a07be70d53f6a5edc7c4a5f4b5220c8e7fc01f5740360db072a4f8d7e80246dced5c75ad642ef1b41841f43e6e422f4f9131c1b3f505197f18571b057ed1cf2dab2f37dcb88082f8d8291d13eb7abdbb14 Output = ab923efab9857dba5a68f9198c4318f54a42aec38d194133eb7f5dc172478e79 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 Entropy = 319c51bcb76124b92f39820a5653c0ecfba79ec91d632b0488f4020e5df4e37a @@ -2186,7 +2186,7 @@ EncodedPublicKey = 61e61727c66c5cdab43ea53041e25b36b56a323a12f70c99eea25fb4d387c Ciphertext = c60d4aa71649960bedcfd1ba225807739b82f912425f50d32153167826926e51f8ed961b5439fcc7a3804d55ff46d5b873e13a0c8ee7606fbb21c5e121fb8e60377ec46ead034bea9c44a685e7a588875e5bc2dff98e5529cff460ef5fd1ede8d4cf2b02e9a537887028150d0d79ee6a0ef2f0d5507c42ad1d788a75899d0b7243f7179af88cd6b7fa41849f1f49f782eb0bb727a9b0fd51ebe3f05ae80fe7259aac42c8b0a70b7b74da297c03dc1f06c44edf72773958e5a0d38aa91c35e71b27155e875f3378ad6a2d064d6d7cd56689b1a42dc4a26ce2cfc8012e147940980403bb6bc164f3a0f9055867efd0bdd3ff4c36ad8165aaba00c8365d217d4bf208312f3ce9fbd7bde30d6e4d3f1a98b0a20f947d03b45f3a25ad481fd1dc271a0cafdcc04f02d314ce3da2e1aeb00c7d3a88ea3ea2783b75e16768f0aa122db015492b0ac9bab3d3f85fe6d8e32cfd66fab8e3138402f690bfd3a5fcf09ca27cfaffca96181b8a906a67d93303069ff91c2e3e6cb26c5608bb04e05ddeab18ad3ff916bded7e9e27c99492b7525f95e02833ae827c48b1f4ef06b77633a66ef85520768b64641c5b1b3bf319c390006a026b3a77331c530aa5a86d0e329d4c7bd729992e3c574876ad9a29d79b09018e850e2e63d51f75861af33e6acbdabb722d41312294a9b302aba8e3f04ab1f04688e373f86e3753d84070bda2feabf6b94617cccae0fd427f90f43d3b686fd772292fe1c93f355fffd2683eb8dbdf171b69bb6a5c929b7109744f542a21539e04151ac7e46f5d4b8b151981d4860a366d3500c3422a2bb5c24fced0221e1b84b9e5b587e9bcb87220dd92c127be67a396ac18cfd3470e715ebd320fa07097122f696ff81923e4c2d3c0310bb8b70690dabee4e17efe6d871b32eeaeebb448f7d65fd60e7a3f32cd07e61948be330179dfdab4d748d01694d64edabfa95647a21ceafd5261cca24a0548a135ca1f7c262952bee7a291857062d3546dea97cd745050121c82a73ec9c0095847e0563229ec36046ee1564ef3747b49812eb2bd015025f077b56d63500bfe523689a6be7b886fd8aebbff18cfb6e4ca18c2d0dcbdcff8fb7a9e852f81ffb39245abc6ebb9f58a28beb15942cfd5f797dc867f7a855a3e6ecbdd9a8123ecdc30c7240d44dffcbdca05bb17d524a791ea32d60c65dcb6ae3ae3b724ae7da36b88d3563a63f4c059fc83c97ad79602cd7701749f92c02bd65f505f407b64ab3f8417d3de5631804eeae565af62d7fbf95bfe25126aa2494368bab7afabc23825d6cb03151222bec05b09a3fabd5937b7a0ff17246564e163d049e0724456576f250045d13d99aa07a5f298cd76ac73f69c3547ec9a344998dea3448a96480ece462922f76f1fab68d030796bcf570298013001414ee238a8ac4d7047514ebd5c3e55e051846403acbd3d7a581c1d53084eef20edce56c2f50443440ad0fc77a955c1e5c4d610cb45f43435b1a66bcec638ce88126ad88bd1b0d10cc5aa23789d5c8f4d9c63cf796e1ee6f7fb309855f332a648c731775edbcb4968592f1f633a3fc74bc5fbfe9c0e74d8379fc56f869e63d8db3b9ffa92e9b470e668e10acc1c7606839f2ec0abd02629007e3b1300e558e5afd136f949eb1e6ae56b5a8c21d15ec4b62b22af89618501c1af9992a3f002242288fe01140e2476ff900afe32685afac7baee893bcfaa54c1bcae65b2c9db04b1e17dec3821145daa041150f3282a500ca46c535ee47ec02b1a1639713354bc4ff7217ec169a63bbf26a26b2c712b02c76b56a8ed0535e3ee1c3f118f2a68f9c699ed8702f3eb30328118922b15b8399a3fca410dae21e7d762e6e45c8de7ff023a75211e42d1acf1d8f506223cb281fb9615b2de1848ad674236e768a0f315041daab6f491195453081535f9235f6d215e5750226ae7eef4df26469cea1d0541e7932ad917fb360f4a9d5601126b1c76bdd1696e6d59749635b844c9d416a12d0eff4c4a9e7f40860b047ffad7bce7439ef0fef50cccbdcc848b02f66bf67f2d3cd795242896c5f2cff82864b1d1f00974c9142d0b0ef2a8d00289238e822d352a924c689ab15e6e5b201ee7ebca1253b9964a04efb4d7af21c6ecdc03365b4275d72502523d562209a316a88163ca33ea279702309f8c2373514d459a5298ce6999571072852d996fa8421fa594069645f034d3 Output = a6ac9ae3077504c8a7b1e5558a0fb1e7d60cd2bc3e59d615e68d5165e4903d07 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 Entropy = 00ff48b3769ffaf4e91c1c9110eb8ce9e2cb99f060b486b37035407d2f4ca517 @@ -2194,7 +2194,7 @@ EncodedPublicKey = 6328240b1a7286c71c5cc17284fb5058410381c74456c1ae3ad93735b6c7d Ciphertext = b0ea35919c0560ba7caf9fb6352b36bba962cd45d3d2b7f6bd97ebb2a3ba6df22e018390330f75cb4eaef8c9ee9bde4a1f25110dadf363df31f3f8702a3c14d5d2da303bbaf0fb199384a2702f7089fcc63acfb29d5e53571102566866898055258241e5ec4f1a325175cf3a64a84ec50b4e8e511ec24dfdaf0ca79911b1d84b5a0872fb1618edf364ea06d7287c6ac39e842c56d6630ef38f4c812a8d1fcad73f2d4ecf8f7033c1f5ab982c5b6b8c5545237c4a3ba8d5ece30dc93d1d4f4e89d3bba0b8149ee5c2df793c8779d45de92630b292714582387e60769209ea7d00e2f1173f8817567f52fe53d908d11e8e77375e7d2f73f44a01ee3c87c8f4163c579c40ce70dbc006ad2426667650c35d80ced3df0f3f626fb52f57d874625d414aeaa658a220a4ee6350900dd7b1b9e165661b41cd0c96c3b665d789a297f6b7b4f261e6dda3f6b027ed8a308f1168627f71656bb0ad456ed2b197c672d88ea6bd61fde6dc3df7e4d8b505afcaa35fc1d9b5df57b69679811ab5b738d62a5800555fe282dd4d06d5ab25a3847b4f22725a2360d8b47c69458b55f485a1ee75918cefbac2b4945c20a7356d1b7c69f1c047ba355496e21eaa2123b5b545e86c23d4cf27011e68611290161366d6c12b340292113d3973efb312b1474807f8cf735b76bb3a722aeaca7b865530fba177f9016d1ad1a7bd86da6f657c32d6662e57cc691f5acad0faf4f21027fd761ae23456b599333c9af918166927c6253dabe508c7d931d50cc824c589881b39087e02b52276b9d4252c08199dd4943d72b4fc14e603c9e901d0038da715973b0d168b13edc26b20e2649f37d27c9cacc7a8508ab340a1c3ed8d26099171bfaebd39b0b9fedb3c195a381b55c13365139063e5525400127cc963d9659c964ef3415b31c3a2a923ed3b96ffd327d6eb4929ce1d0d26232b46da119e5e38e71a2dc97bb953567bb5dde9c2d19bbd208c85b135bdc885121b5f7195904d2a9141bf5222e98f95ead571db8fe2df9a93501b8fb9a06a3ce0338a37920fc4268e26e71f94cc218d6fad6c2cfdbf0a5855b186ccdf10f66f01f884f22503c530b3c5ecd96d9b55651b1eeb3af62cb7a4cf4cd185d98afd1b942e8f7eff849ce843e113e82c3a875fb996161e0d0185aa99e21e7c99c9636cedf0dc9aeb55a37eb1f744841f5d8fb3eeb5eef76039a40a5c643957cc81dba3fe556234acc512efa07f3a140ef28a93ed9cdd2088456e3bfad0e8377e69fbb3dc67f3864ab36f8f8422837e067c20787b80d77a30995e5d78f84804cd7c897d0ffa5fe1e7b92f17575d94512b6a4b5888a3cfa6e03be3a50b8797f43a87477982fb241f24af59f13acf60ecc4c11e558b1a4feb81f69acd5a67f56bd698888c9f00430dd8f8309629f7c29e96d2951fcd8b521265c368e13e22fefa30bdecd51407387c77259e64a62e5d705d3d46be5b6f710ad86e844e509a3c5c1dce0efe4b1427bcbe56758432301a14d8b882a70cb5c587e1636ecf96c61998bec7a9b6b98eab92be2e30b30174c87bb8bd66d13282dc4d1b67757435807a90a0b268a9f760054c219bef6c8811476a56a14994c760e21a1b786efda3fcda5acd859967b9874eb049a9690b0acd97c907c1ec6b1bc9790b1fa6c8f15518b9c18b3f0cf672d26496be193602d909efc2562bf72e83a3d8244eea1942c6b6708f006963ed1005615abfdb57cff11b985134ef3ca90116a7ae35299d1627fc05cd40cb32a83c9f9e19570ab0b4e079ae34402641e47e1f0bb20b63e551dc7c090421bb1916e970b33a6cee4be985f28ea66cbcbaa21279b45a4d3927eff26dd1d171f18ba8c5e78644d6027e7ace96ab62bc862d8cd69bdc9c07a4d8d66ce2a08601783e6d40665fdc637aa813a447361ccd9d843bfa05f5e88f1f74a4d6fd1bdeddb1c50523d731cf6cb4686018e8518525a83c2aab2fc5ff97ea1562c7cc7347482c96675b0b249f99428d68f180d6590c67025e41c80468a3edcf147368f3612456e9d73bc4d6e0a70364036f75cb6657ea99c8fa365c165d7fc912bc583f0f4e57ba0f531544282e21dc42e00f00fc59273d272a711748bf62760377e5c30c1776542936a10fdfa8acca0b4b5e5c9cabf461ed5caa9124c59a4e867859401c158080970ada9cf76ab49e250411a61ec5e83c781c269b75ed1c193bf8134d7b0dea Output = be6aaee5bf0744e7ca1ca0e545171f3075aba9b4d10a71ae00848c8398e3c52c -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 Entropy = 4960ccb1276f96d7aa55885b6ae6f90343d42e1391e8241b5952931a979837e1 @@ -2202,7 +2202,7 @@ EncodedPublicKey = 2b1a5060745e8525bc617900d53b414dc995772543cc58a6bb7c4868f8999 Ciphertext = 1feb4f1d63f08052045012a21c33c2951b16c4b5ec02c00093d54ded6f94309e44d558787273bf593ac4bd77a56fe4dc30a54eb68a2f473c31c239ba18c9ca489cd50611fcd3be42f6f5069facdbcb7166a64ba7c06ba953142e5914ce20ec69038895c9860e69ce6cc3dac6c1b28d30fe83487d40591995f091d4ea116ad2675e32bb83325b7f379449dcded935027120d01ee43b2208deba910ca7ee635c5b928e5f6167307c813c8e7034096878a2915ed2d20898d8412ae61a72378a4eaee2f227ad5467d04ab884340cbfde2400cbdbca7e07a2f14016fa9e403a2b0ed27ad1dbb3cc492f584a6b5a7525baa628303039f69cf1c1e4db920ef7882de21eda5d2bad76231c88a061fbb2829fe93149c69204e2e783009beb4188fb876a6f869eb11b1c32c2ef15f9aef62f699f9692a502a4d87e5a497097ca73f8fddacbc03dd40a53abf267f749f9ac0f7b4ce9417a0f5eafa91fef75441ff7c887dc2eab2336fd257d4cda373121af864d4707fd20965e063fae456f0bef8f587bb385f8e5c96592c9b7d6c284197ca1706e1961dadf16a2264f74be425ce117a95dc9466474c856adb20931cc920177dc3f8c93d2bb3ad5f7c5517f0b7d141b87a8c287207e64158934766c8845ff0a480da124716b11d0e257206f68f2d4334e8e260895ab83e218e032a35f8d792be7b413b2679f8044e1c0ff67c474ef4c9b7e0dfd3d9bc4252fa81922cb146417dcadae7d7a7ee96e13bd480c96a4314f31fea83eef588bbf1435528c51eaf05cee2f193c3fc234d695ba32546ec77a16b1ea8047498125f2bf78dc9510812be57fe0ec77bfb3e28f42a4d15c2a2f0b54aae023ada92395cf384a1524a24e36ee2e69128fd2ab78b5af77d28c2e9ccd6c706315d46887db0c0c4f28666da7437489e3b245a19fcee97f187327a5806d35889e63940b19249d627165727f66f50aee62dd9496d6493c1f01ed0091e985048c2aa85a3b25a4f90f6e9f9cf67d6961ca246d763d3437ad64e7bc5c58b10117a66c40be088c58a27be4bc1360d114e61d002e271c4806b872f5ef7127217d5af6092e4aedf8b5c40198f266f9e10c560d4873668d58c912ec7ec18d27249f5be604a82d50421d436a3230780419bdefd10f049f404184b3530361c5c0644c3205c32fd451f6c6919487aefb12a75c821cfddeaa14c2abe20db3ac57ae0ee8ac4567db2d1e2d0920fa036351e8bcadbc14ab73d0868df6ab06e675ee193722f93f64a5344bd70593c23647152a81acb4d1a08b62b5f0b2669210d5d7845248d95fe9ccd796d73e34af955d1c94edcd2bba91be211cacb0884a90eab8a0125130ae65318f5419810f4df129c8504def662df4879e2a8df02d881e9990148065942c0d52865425f3239c4a4af51eeb85e1baeaf647e794b9fc04ea16eb328b8b1d0550e5dad8bf6248782b530735f8f5da40cf21241a2d62951cc9e894a339491f64b78d436c635eccb855d3a1f7d64f63f23023620408df6b3d190e7965d219a0cabc0933f7d50d9854e4d4aa7a5cf67b37e0475241a5af8e5000d117ebcea40b526c5a669dea1760d7fc30519148649fb00ca434f2cd84862a2755a99531854cdc847b7d5af3ede653ad6959f49c921d4a8675f7f3f51416c39e026488c297d844a8429caab43671093cc3ebf8730a18bae06f10ff8047cafb8d80edd7630c95d008cefca78f2b08ccb330d36eb33b18cf47bfbbcd0e2f81daa87160f421603d10409b8eab53f1561623f5167dafccda4f9a4e6504a0b5e67ab5dcfae98672f4cf62e4f152d09f2c64dd81e3476839aef8538a86f3b616ce55adf1dfe9451ca48acbe210c32ea1cc574730b37d4747b580c66820caf475858b4b6ad0eb7c06ed56b8f16f83595ee3466bdb8aaba3bbf35a177fd6645610b9dc238571e81b27b94757c9004a4c512cbad25730bc6f85255ffdcd052447766219e667095d4058e5f0045e16c0fcae1aed8dcb7c25fbcaf29a71a8abf72c398a61b1a57bec4b11a8c746bcce3ef0f82b9b2bd702d92a7fabc1efe0065e662270e1ab664cb1197f00983f1d265ff738f63b93d5d95aa4ddef2ea3f473440ce7ca1558b28fd68ee09c7b97e9d4c2052fb1dd657ecf09a2f664de0902f23bacab5d64bd449a0ddab34d4c0695c67ff5f6e11044a0db15d2d19a9ce2aeb818f0ecaf8c1522276521b0193f76e2 Output = ff81d45deb69b6890f147710945d1b750cf17e876cd4e694158efcaf4fa2cb15 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 Entropy = 456be124e7f43803de5f734ea016455d68164a7f054c003f4ef49e46f42dd8d0 @@ -2210,7 +2210,7 @@ EncodedPublicKey = 101738f8f11e10897f9b1b16cc7c57ddfb3e4f6b01ad6239982baa07c56c0 Ciphertext = d4952da07911c8ceb643e6b3254f7fcc22242a88df735c9aa9a91fc692f32544b7f30fefed3311dc8a927930c50b17577573f858b778294929b123b180498c22c1ddc92a11cda9c0da3cf300664feda28bff6f1873a682451d24e2c2a5991fa8aa29718a43c2b379ebc7387fad5dc9e3681d233641d1b805b167ae52631b3b6ebb0aaaa6507d4a87a808a1c3b62c97da49c02dfa2c729693de194a1bb1643fff14e0fd8d3749ad33936e8b4f8f6f3106c08a8098c6b903d1cb70c2636571253564fb7dbe54b96b1f999749d0c81c698934756b455bc6ec918ec267b5e54a0a812c62de971d8ccd93e4c1d6752afe3d5308c5257abed2b1c01d0489bc1d5fb5b2f4b199cfec784b2bf92dc85904cf78a9a6c0fc3a9c5c1640f905fb8fee2e08b3c0d5fa029062a5d41c82c512ab0645e7a1d728e7fdbcd95ec59d121fe876b1e6d624dba73cf68f35b23bfff7a435a5afc81947587b60d588c54ba0c999242830e568c3269bc96e001a99edb6ccef086abec634d0febbbaf72d872eae8c5606e86d9bbe279395c5370647f245351ae41358cc26f5447c37f959396dbb03e484c80dfcfdf93701e849e081232e85eb15e034b5421dc63c62190ea54a83ae06c89f395f7cef8eaa41517345a3a0aae4705529d3c2c13f71418817287c860f062c6d0c5ee918c50e613164dfd241533dd08928fc695f3b3c45cd75c740f76f6a896cceaafc9afd64deb69db89cdbd589fd6987b1f5da8b5b9115d675d3ab6cabcd0f793f00418c97b673fa31b851c1209140f76492359f3580c0e4de09d2a3efb2b3dd4afd4abde0e97180b7b24a45063f07f82771991fd2da92e12de7a868e6e84dca6a318dd8ef3a1ae6420d63051306d0582b058b7a96f25766aa0d863059483e9c7a17748a268e896f0d02173606e4381b639b480fbf0b3541a7c1790e66810e064cdc9d4e176cadf3d64ac27648467cd0b8643ad1255347cb6b086788f6c4dcfb3363cfef54c3ba5c13562ce884b53b09e6f149a60e1fbb35b65261406ec04f4146b2de7c61c2fdcf0f714981308774af933b710d1d4f315feefa97a581a98dd083a4d31749e5d0af2ccc2109cb739f8bfe85e4e7844dc3907959ff3c04ab9edebf3317f354c5e0aabe4de2e0711ee771b8dd70a3008eb9936f8b6924ec0dc9897a801e00f6738ec7f31cef0db9608d2c3d3683e97befb02f0ecff93068a46e57c97201608756dc45ca8bad93e0f562f5d74790c87d4ffaa67613b89c22339115d7499a2fd038bc4533e46bfb5eef28b06b8fe9a3182c6a8b18286edd1b57adeb55bacebf7c842d527ff5024c0ffabbf78eeb956a5127555894ca8459d99df31fc0fd1e1c5f7050d2cfb427dbb2f67530e049e23f8310b88c39d25dacbd6c7dccb9e382b0b471980d54974adcdb082825a9d6325cbaf90030a58193d5ef0a4e1e8fc885f04329253408b4de1d25acd097ff10e0afb4ff344063edde277e49b18996cfa57a7617b395a54731052a95a3cced450d38a31f19811ba278c60097aa1e3c91e87c57486b23ccb07d687c48fbaef4e814f9500b1e6f679a749614c86197239936be1f7ad2290b9a421c4f2fdbd4178a75cbb9cb1f7eddaad9d369f79c0e383fc9ccbbfd5e4cb93b211c477cac2786395e92385a4c0815d0ff6849e961395eba07c86e698d5f62466492efdbc326ff7c955840ed2877919d1cf95cdf5f557ad069363caa905c97471c85c5d0e65cea1ca90df82a0f8ef5660f68191c1aa19a180d18ef4a7b0dde8250ff3ff0a97dd4d65c3faf1e3a426f6c4b64f1f2d65ce9c5e5921ac20197a00f2331e810acf4f6b71878f1b785a28970d844ab4b6d1a604824db09f15e96bb711389114a4680b1c8b19be73aa5b039116c7a7cb7d2c2b026f5847afd6d2ac804f4ca24554f5ab27db900a159579efd23d78cf5542a038744cd6bdd64a3b59d233b878b383bc0ef38a0a2a8ab60869b64634df1cfdf3b53a367d3bfbbfb741badc819cb01823a8e8e16f6b4a35c380f99cd45af0edabf9de4fe2e5b0e6c34f7dce2c8d9a4be2b2b8951c27080aa965ae3afc422ddbefe0da8f766c8c63823050d1ba055e42352d305385ab932f99c0309dfa8d6362ec1c07e33909ac63200787f5963653db6ba2994cf308c9763a153b6ba824fb8ee94bd6a38f2a12047f7e0b01d090aaa41b4acce8396c18aece73cce364a7e6d9d Output = bd452a700448a4542a31dcddcd0bf285610aca6570d8bc85e20e163a13db5663 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 Entropy = e8ac9e76377d67d84f85a142383e777157805be0d0f679ba89cefdfa61583780 @@ -2218,7 +2218,7 @@ EncodedPublicKey = f6036a8efa3d74327dac2417e6fb05e2f1c178023b70214296c3ce6515124 Ciphertext = 021a27d9ee3c76b205152ced9c68003eedb09245954d50316a14a3e1d877bd9d6480d479265cf7a693e77b8761f11a09c1c30d2fa5f50497ae6a4d2afa3e61b0b7fb4b3504024763ac6c10fc2e6bc77dda7fd837ce115b84b1d0c749e8e4a961d3e7de1bf6b36741be282f9df710b46410df07191c3207dd9e74e8c4d43e3c75607966a1894e86caa95cba51a9c3289b00ad0fe59c034099b822654caec138a1b06635d1de59fd469ca3e928deb7873cc3dc2fe03aa4b5729f91b940f01ce83ae5aedac13d0a961cd9420584346346955780974ef21ccbe3208cb019f050fac0b80076b48ac6c0f3c2aa2dc3a13b914ce5343c7a140186728bb335a47515d361466c2d78f3fc6250f13a4d4fe6c8a587512700fd5272c9de73eb698045708e18b86d6b6692e3afa1b73e5ed55614dce4b8e71ba9dab03a246b1469c617f5bbf3e502632b060c7c17145ba7df290ec310661480de58a56cdab7a2e5a8e298746eb1b7b8703c5c650456c567056451e209148059a59af315540e448c0c6a7f48df9e22f373aca8be4df3bc9bda80e94a92634a612afdbfced39194e124c07748328698cc21f39de459b4cb08c6c73e80fcb6d0d86adbea470a207b0575f180ddc0d658d7ae66b2166cdecdee265a02e56bc4880797f0fe09c081788f5bb507db2406f37a2743a3c22ee0caa51ab62ceccaeaa9e189ae412f8dece857b0faaf61f81f2bd968d0f6c9048fca287f74d954e48ecf05806a695d06bfc66ed8b5297899dd4b3942424cec559c33ef0da1ca083e7eea98585f89003ae0ba98fb3f51becb80094ba0091f97b3a32c635a12308851e070f4a94502be51fc6f4e11bb7803cfbee43135c82bdd3bc82d58383636eee387d2c13c1866982d7c4f15f0be3bf5f87c8fa5d43daba703c73135ff3aafe4cec43abf9c1bcd16e56d6df85fc38dca4d09245677ed75b585722a9b20fd5ffe9d0436b3fb592ca6982ec2b96a8af589296b0b0ffcae14ec9027d4815bb9b933470a357d0afe5aba5010eb0d93a0fab2c28f84d7091e607505ecada258a551238a2ff68621bdf5ee1246c27d6e8673f1b785f7abc9b88310e3c1ca5e266f2c974d1c88a31e27a102330f924fb3713adccfd09c4415c1773c8da37e4e18ef274b00d462970873b54ad108f588c8bee6a7b4cce157109aa04ba0daefc9b5119b3ff9f70d4728574cb9f57573f41760248a8a8cdbbf7492083cfbf585c844f03ee2e08da4a08d04717b6244b63bbf80d0f4f0477f94de7ae6b2883388ba05b27ffe8a497541f012f16bd9ec50f64cd0d14e1a6c2be8c77ffd39d1d19ef402b46c0c41718ac406acb1b71fc044b1f93a4fe98fa8a0bbf09caf9dcfcbd8e8ecba42e4bbac9bb5de40f089b86ef71003b92a3fe385bfe603b098185d05f43819f8686b4f4e14a75463f2026baa66789edc52610ca8d3d5b11f10672c70c80effd7ba0352b2079de6910221ed21c487a7367cff076e84e1cd3ec625065d7a9b8ce4eed9d91c8a72b16a4a50d96b8a00921695a00167b53471e79aa445c656fc0d41da64d836ac21a34be767c514d1571e500fcea435d1a1d59a6d07140ee4d1a4014cfa8a6f0be9c334ebdea053c842a06124dfd165232c1a2ce63babadd8a56fd78ffbed64b63bac3b49e5af81c746253bcfdfd045deec785e0e272ef8c7151bcefdad6fa2bea962d621abd97f9b5cbf1eab792139d16b51e1f732326a5e02926817ed0bc4c6c4680e42e7d5847d6e0195c402e59290ce8a8f040a70980eac1a0bcd3867ddc0f2de9b204514011491c8dd63a371d331b2edb870e76e7ec5b27146a0097b969a6b157d00f66ce53b71598b71869063b9a29b23f3623837385571962ac29ac868301e2ec0643bf639b074c8a28f0a66acbd0ad77e5c86d01cabd8fddd77a4fce6185768566a6d98e679986aaf9978c49189a2ef1a218977f4d2c34c5027188d816cc918061ad13421be77fb910ee5aef5e159fb74169d7763b446e523470409c4fc4e76aa6d98f120013d4af284bb0a8e9eecff71b8544f9d3815062173ad6d4e9c4727cd6395bd3da54237501c73390cc5c48683d780efec478d2a15a40a5ffa3455f52c092993859fc8ff9c1ebb308ed03b5b88f6de341c3be3ddc96f695d68c1562b85806e162f1b07c5f10a1213f8d85f6b7d92e06d664cda2ddba47b93e2922d30c3bb110405fc7dd9213812 Output = 8d99392e447dbb7f7eefd329325bd71d1d984cfb01fd609c3283a84fdd0f0138 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 Entropy = 2fe6b9cf4510f212839e348d671b3345da68a477f57513ce363414e87299a717 @@ -2226,7 +2226,7 @@ EncodedPublicKey = 2970cafb137f0e7c060db72de03a46d8a860b0cb2a45b462e5530eb566bcd Ciphertext = 6899d650581d8ddd73d6e7095d24e2962ac573877204768c66a78047649ffd373d4e0cac20e0b98675e6f50962871c33957b5a7ba2af2ab800ad728c2d0e70877cc3f459ba53d432d45f4c9ff4c951c35f14185e01a1fbd735fc3ed84063b579e69c230f41af67c9cd7481fea81ed64bf248c63f56f81115ad8255a172fc99d87d8fdd6db00ee407618c7877a2486b6fac3b8eb7bea62c24bb5c5655e47388f2108ac36d5e55c5511d72bbba65706ffdf297cd0788b4c34ead564e86e78c605359b6b344380a4ec73a4f64b7866a2eaf36a494c76adba39158a3d1d3b41973cad055780ce211982fee596ba61e5e5f7e44cdd8b1d6f866c708d20403760b9fd4abf31a0573afa130aab5bf7493b2365ef5437b7824366fb3ec967016e2da547eb61276be7c5509c2bd5e16d8812c034f6b4c5a7f5f489137385ad5697c4312042303a5d7f62e398bf5fcc758ec1475e7ba671c656911bcc32ddedfdb07252ecd0eeea696046e3fc9e564b2ffca11562191c4a1e4b31d9494961fb66ad44f24c4b0d8d7422df106663600ba380baf53007b6146c923412228936d7324a87050e62b185bf3700959e262fc64bc4f2b55402d57c63539c57272240f4725ea23d389b17d6af64e864ce3429c9c0514c9b384d79b830a9c6fe12f8781755d53b8af9bf81e4784d9780ba6ba0ae36f89a99289307481bb3955075057648129349f1e0ce4e750be53372f82c92230127280f0f393150c89715a43eaac8abf538a031155661b489b066e915505d59ba40cc0b5a4b8de7e731533fd06dda44e65f22b7931c4b8e34a72331d32798aee1c16d81e06eeef892e7858ed2e9c27d21a3030567e40a369e21c925a26712e1ad6344474bf8e9539027040eb4b0cf65b627623ddf81253c6cf002f837673d2389cd296f9abfcd38a36c6976b03432c9100c7ce9bc862d2c98a6dc2f931f62e471369bbfab644f8ae37deb65784e6f5414bf88cba9e6836d3fa3c0ab7ceddd81d31e94c612224270fe79048688b6d8d46acc7d656a647888a469fdfb6ef8c8daf78a2270c5058e9b87d2fc0e4f8a098c1cebf96e06ff1edb382e545387b2314b2f7d4a669dff20122a0165c285258a39e2a1d27c5eac3d79ce0cdc64dff98a8633882db588a34b93a1403f6a739bd056cd2d6531af36a2701acf47617024cd1cd4b9b60a02cdfcc6f34e4693eba3bfb32780c573b4482a5f6bf109c7ee51792252dc119a5e41a4ea8f25557b64e500a83a6d8a839c456775a9ccb906a733391605bc487bbd6ea7272325df31cce2093649fa8a379f4977801240ea2be8b1e6a5ac95ba613bb2798bfd1cedfc34c39e1c43cc094f8bff34607f8419bc3ef2fc0c37075dc49280656304d2f642c5ffe86d5cdea4fe96cc8b4451954e5d898f6cdf7e7ec5af447dbda66a254b964df9e8dd565d46cdf04dd2d19ea1c7400925be2105e45343baa9855c5236dd70e042d0153c904d30fe45d087b0f0863ec603ad74baf1836b18c91d98455f3e6477936dba7379a6072744be6d4c64bca89ac3334ba727e0763f0ea52faff3daa52de9fad1f27e566e7a6e85914a02bdec5f7a8509f80a616f6ed66848d4ce8920757fb7611ee7c70366ce847fcb62a94452dd2523daa21c759f36cd31337afe1a5c8e8ce8799c6f03873f58bac3649e0d0fe6adea0199ef6eed64dd1e2fe0bc606b97ec8ed1e0b567baec2816273b7280ac91b05fb25e7467e934bf79025f5b4060a813c221291cb307f7783d5877987124ecab1d9d8c8e36c10608871a92e8878220f593cbd4ba61c35d2805500cdc0b145cd6ad2cd614481edbc913733e3a5104b0006dd26e871df58f32047701b2420d93bdc2d0a2474f7d9927e7f196993d9792e30cdff67ae89bc6a27236a6f0ce0439d4b04788765943c2be5c9fbc0f139135ded84ce79d876eeb37f30371194c8eba42659c185a10c8941f9fe9fcc722183ba7e22a7885a66d8cd10f214f4534171e0836d86368cd04d87737923da8801166afb398bb345b5bee89eb512cbae07f192aa50a932a5d92e909e65443f4004fca49de5eb19abedbf57d066d134e096e7c63defe4430f8e1886bdd3cfb8077f7196584398589ced5670c7be91d715a20f51603db8ef35724805eb1c270cf16b282ce7c79111e4577a0a1a27a435c070d6b3e89dce1bdb53826fe9a05d86e586ecd950d27247ceec6d Output = 71e358b21b3b98d915b70e9b877e94159aabe9df32737c71c50c2f99d7a074e3 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-1024 Entropy = 86630b4f72820d19e9941784183b3a0d770609becd6fe0dc463cb6edac432d59 diff --git a/test/recipes/30-test_evp_data/evppkey_ml_kem_768_decap.txt b/test/recipes/30-test_evp_data/evppkey_ml_kem_768_decap.txt index ad1c8d5b96..518e578887 100644 --- a/test/recipes/30-test_evp_data/evppkey_ml_kem_768_decap.txt +++ b/test/recipes/30-test_evp_data/evppkey_ml_kem_768_decap.txt @@ -2215,70 +2215,70 @@ EncodedPrivateKey = 16997ff80976d1506b23c012e387ac6ca0a792f7481ac3c9775317ee3ca5 Input = bb7e0dca6eca3ef57e945d921c2f80875556f7786d6bcca1312f86b3bea6d0f0a73f7d6036a7c38c62d4e356961ec6a28d8026a2d915d9721ef815147fc09ca65a3394aa5dc14c08d41cbe932337b9a531ddf68df20b6aea297194ac398f15919830e3ee6c20145c0aae7a2cd276ccad7b5c414212f0c0ae7106333868938a6a00da19377d996c7796d400606007dff30fe554a5fef86944d43ba047a00da5c2c2a1aad053aeafcc75a1e826a417b4c320e60a68e63dd7b54827f5b8b0063a00043f29ce8975d95bd418eb2ed29db0d9263c67fdcc153ba9b5a33279becb7ab193c2f257bd660fd7012712be3fdc2e52490ade145e8e030ba1ee5368791e6f3efe00deb34cb454cbf7fdae3a507261d9fce66ab58998ca19380187e3455d425977a8396cee3442935e24347aed45fba9b323a289f1b98691e35017ecfd7a423cd8d0149432a2063e0786c2f912e1134ebed188511c905a1a9890cd55d496e8441ccf637b4d660d93c7a46c3e17219167c3b4740878ae35766470b5eff3c6b1fc8c30e5c9645a94ebd48d2d40fbd4baf9d822deb26c089da84043340a564e6c311bca18c7a2c868831fbb866d89652556b53297b9c0040e98a692fa536af4c9a7aa09321ca27068ca66c665b1121ee4529cb3e6d899964de759ab915b0d2c571c5aa76cd64df4a4e55d9de59eca7b4379b30f8559db41e804a18b8771f594b9bee3de9ae98a003430aac58c141e6f0b7b1e5e08e27d1127b682882be055ba31e280dbace7878ae60426626ea4c5bc034a9206e27f578edd17fa6c33180b649bc7bd437b2c86ef4e0f4583071f99090b95db1e415d21ddd88a910b1fd10e3a04e391d947558a6619683ae070be04cab88300614839503f088e2f04cc4a7d091af9833a4f957cfdc574b1c994673ea14dce6ad89adebf5130d266c1440b3f544eea380ba245e21651f1f2aeb2b3d578000a87683dec69ccac18b0702d3d030077981076766e7e5f3ae1174eaf21bf03662c6bda5fd209da19ff6792c0bbc5d210851061dcdd2e4794d2c3c0c531e92a2c4a23556878d3e890b65289a6a02530bbd40ed66db3bb220aeb71fcc3c0b5d5b3afc71377746b22ce636dba028bc052c219783d468fac1d4eed555c1b4676705c8d27aa8a09c6fd8640a6f7b6790ff173ac39b5f3c709281df4274cccdc1e3b690ac0a77f7ece34cdf3216d2b6058baf5f649ff5036360dff99334ff06a366785c0404c584f623801190082fe5cdf88f9cf41032681e8fd6b84d127add01d4b2286af648b83fe69aa8d109c9320bd40621cf75adff8603e3da00be36f03ed7925f19b2e913d756e952a9402cd4fbffc0428cd7eebdd7fc7d3b4cde181b16b26811cd53d9f5d85d37c1670b957d4b3d04fd06567ac68d3f9dbdd45d182619180cf9292e86f42bcc213e94900e0c759e051bc0e30ffbdb91a2493913dc8b81ba4c3e8ba0e7277dc38dc91eb2b27823dac71b6f1c47e2a04136e2c0474fe070e2e4bf8e6fc98e73143ead3c5f778ce8a4efde4 Output = 5b357f714a293b6724c0dc2e2c5509676782a9dddb050d88e6efa0a6d09d20b7 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 EncodedPrivateKey = 00208080e8b3938b09aab715a0b7a09314c3d2aa03e900528a209c655886bf0180a0775a1ee133e543c17d7c24407131f0b813a9287c5c9939d43ba2c1f064015c1babc910d1024bfb46a3fbb1ae13dc5d8bb4576787a592495786a53d4c172cbd3b2cac6a2f5ab68fcfeb2a67a997d809800615c043e4bcc0985de9d671e6e0c8b071a20264c457c13b1f4734f234142e86c23170821d068210b29358694d8ff27e89c59264a315b6591d97d90ede633b68fbc36ca96b823a4bc66144b541cc118b0d60a66c89124d9080ae30f44b9f4793cfac65ab8b8cd65ac81cd95de566ca2c19906a955a04047052a699e8a132e2e48aab916278c49ccd1ca0076b5254784a23f7a8c164229bdb9b46e1c7bd4c74639053cad5226c598918687fbc50323f086238366c4ad9172346626b54ce142053de67ce8867cf599587d0a47aff0a7fc113140c18c40bb31e2340822cac294aeb3a02652b424ac9f1008a592ccf70170246e689edeab03dc0249ba59fcc6477fb668038443bf9a743255310df11b4c90a97bd212a74d5142bc6461a135ce7376995372a1bf919e3db20f22c683f488395a95e31ab13aa707c59f22e85d892830bb550395633f6c87df28401865106b5cffb75729391767522ac236072250c6f4dda196a90bbdfa183113c5fe2e31ba1187b4f682399f3c6c0288977904ab445c0c1b9caca030aa639b35029657c1608e3a654cbc39f8f096414d278059a6f56c8c838b1879b00ceff668190213eb15184a57706bd8c9111667f52a656d161bcb5e7cb8ef5beb6756371ba4297397eb6d0c850aac1e01025001b71a874a25e3ac16450228dc33691b3112de319f69ac29f2a1cdf02a0cd77319931003910331a6268f42669f4a90e79bb820e5c98aa252dcbd056318a050ab71f5d60028fc41594688cea4a95b32529c39c582ae828016644faf4b7b1fa6fd9c305807c43dbba54d44273669bcf956c197ea3462a30be3aabb1a6654dc4a72bbae53982ebb986e249d9438d66b65fa15b723267ce1fc1200bc26656d7c4e1839e02927a96304460a34a9c0a22ccf15c7390afed4a612ef236f9d00c22d04cc1dc362c08afd0a16536985f69f6a15d6585c410ac7a39599c683b9e67a33ee299a5000c7e4acde611bd6c817b1aeb1373835a245b916620be6ce8093f88635cfb619a963c99785cc5c354e5d025f954071e380876408fc5ac7fbbeb4c532b1f1be67ebfacac4cf907be9485c6da8da380809ee102af0c98beebb088c13d29830e7fca4dab8c1e8cc87a3b4198c50686c82626c41414d50878f403c10ac905f39a901405b93366a575338ed7d66c0a27c9dbc4af2d217688dc3909db8878000af307a989234174363f3cc35c25a42d7361ccadeca25a484a01967be2a65bf4998d57943759528d54e498ab18514a5665b87c98339c3fc01baaa2953abc1aba78778b26d54bdb2ab69dd705d6953dea404adf8c82d29b932e144f48a2661dc2129e6a2a1bc5242552374a504e0d135e6cfc9fb91a492e443c608c6e5342361aa8205ac744ecf974b667a6528938b6085492298e97ea827d5a4274ca359a1811c71a574dc986f4262b2e29256c4b52c9a22c3f168988cccad7dab73b47cd1ca43c7e036d41c94f8f31a0de404fa38a1da0992933d752acc0407234883488a581e340bf5a8dd7112099259ebfdb0cb094c8d592485f25729e1844870a3d57d63fe9c1295fc2c4a374508f359a7e9b062348c6c807322f1a2dc887a20ff1b8e951b103698492504dd86babc01339f5b0c9bdb01b65514c8df3a61abb7941da84b8005648fa0e5b094e54e56a56e8c840371349820dc3f48ef0fa488f180f57b5c0ad663512467836d6765f6517ebd0172d886430357baec25c709b3abb9c01dda27e2ac7c17cac7511726a39050fe92399e14780e3288ae775612b2c4baaa032af561d0356c43175c6263c5d9cbc62f57194c9f76fb5293e86d9a95a641325013dee98067d513525eb5d2f7cb5783915d0917faee635bcdab95a61592fdb1de202c439dba37a235e3888134249044519732701111385b9c91c2fc96b039d6483c6d1bba2223cb0f612c3f7c6dc62bf64a04b349a0fab73290acbb15ce1cfaa15c68d896493e67dd9a518782b35fe141a4d70bf33e97a616c51193b711b04a40c9634bb62726f748572155667146d311016880c670067c653e9a8dc0bc32865adbf41ba99f19b2dd9ac7998bfc8679c689a05a5038042885742a68ef84c429984588995a6cee077c3a099caa7a5d3761cb4411d1dab8fe7258c75903ef515b6b0629ff659436ff687e6625d2080671e0cbe0cb624bf8b367e780452ea3713804e083aa6e0c7adc15618cf223b3587a364320d56c58be8f037f89cae0be209ded78cbae29ed73767ede6793f0051cd5692f63661a257ccd9d859a92ac08784070bfa7ede4577e7ab1ff6c7b159089b8dbcc5ba56357b2659a7a04c8748a86991b2b775c2015a4c12341ebb419e1244396c233c161495366104b8e29979e571c9614fe10c868db56cd934c5b2d04986a70be8dc25d61cb6f0054d5e4000ef72557b712658d962b1e673a07222d59bcbc4e8339bb5b37cc1c2bbd38780f8233843ad420782b4951c3321888fc3b488897c8bab046f79cc456bba9f666ba261284a1285bf1a9a9d274d9b87788c225c0ffa20388183f35817e5825d450a1eee881f94a5a129e688ce6664021356580190a3ec5ed220b8a5878068ec5cd485816f8c1ee05c3c23ec0d0aab7f73aac249142d8992678b38410d41be710a285d3b593a8245e514a870c3c348fa45f99aacc464b399ecc0cb3c306c273e5f4c671b806864120a88c07caa53a550d52c5641203a7927b40631e21344a9337da2d128dbbb5f97b68b8e57cfbb1a67ca7741c60c2533e49ece409b0492a2e81523e6b6ad655a6dd1870b5de3690de3369c898b557886c4877ad1d67a1583bc70502b32a44afb9b60f88838eae005e2703ca26355ddc479bdf1a93756af16b7789a3221fed9a4e468b710035060752e884c56034b768d0a7106a4bebde7622bb46b6649195301192c498bb555c653c42f6d84883be82e8fa56ea303caac534014b6bbf38a9f73283e5a40b36e36c9d8b1a9856aa7d9913b22c40cb103b74853c53c3ab4ce895388aca8584449fae927b16534f48b3aaf350030a8460c8572bcc527f1f62bf1c5a9bb8ccf3ee66f66dc19286782911a6765c72db77ac0e976a2bc114a1b110000000000000000000000000000000000000000000000000000006bb77bbab15f219641914e23e02624045beeb4d7f4608d5e52063d1ecdd8ac5f11536217ef54eccc82ada15ed86ba2003e177f270bb5aeee52f9436e31a379d2 Input = 1a2dd390e05984bfc0f55ef96da5050fd9bb03891d4d2ddea46c463aab28fdfaf63d4b2e0c9af992e4f1421efc26ae86c2b296f6851bbe2e898b8bdf4057e875d4a98469b7d2646edb86a5eb5259341e0d14986a8ccf93563bc6ac067f8ff6997c2e7bbd897f02e844f180769fec5af9d6fa017022cb0af622b6e4f7a69d73ab01d3d09067b118d51805e1b6413b7a9e0ef292a6fca18a8828912a2db675f0244cd63d9340aa3ca00dc5d70c915b0061664b1e1d64d3d4dced3ef739302f1063442569efed0dfbe8c019c27823a3aabd865a47600ff9e24f748302bfca1bb60faf4105889a548be9ecaf266d8f02d3aa4997202477a70ee71b6e79dd1609acb4dabab72a38448758d8debf55369c5d3e0870ca193018e0ae6d0ffa33b93e962598b43e89d5978a9d55a608b98ceae5e897363f8a9e253acf8af560c57e07c4c4bde807620b6deb76d581bf92b7f514509446f5c4e4d09430b1855e62854988302c931b9e624644a636ab8acaec56d7673b26852c692e8325fa1b6215f24ebfb388ad1022fedc0bef272c87e10dca97df1e63f1a0e9582daae0f49e30c6acd119f7c4eef59d47443f491df846431cfbd23900341086a304589f52de1d862c26af32095e922b92650c68facfc13892430d428f626fba00cf9501e1e4646e55f5304c806b5acafe100084d7635702139725561522632e7e3871effe883298a7264a411484cdef78f9e721c0e5f3937f2fb7d40bb91620e473f9b97adddea69b3ac682e8aea2513b985fbae268176c1bff90e401a31e729fe8b76d13b5c8c85ed833d9b076b5e11acecbf0e96edcf8ff562255124edbeb5b9117cf486f30d7883aa353b9e433a77ac6912cc8e5093c12385ad926be1d0893afc7e64fb9ec55d3285e01a3ca63f3c07b95399bb4411c3f820f53d8350d1979ee9cc6bbf2d7c92d0cb2fd0a1de910d92589cf1aac29992489bc179676c31ae768869398fda50ff14860a1b4dd3bb2e4ba8b2c87aef7ee00d375956a62dc1e5d548a59f209448e62c4b1221631d4776dd5192154d637217d31feea1c4cb3ef1903b8987f4c184cf3d6b5355ad53c7bd3e0ae5373d9971115698214a93e12b98489cdd75028cf22c1da41096daca95854b35d8bbf7d0d4ca2727aa511eeb6cec5352ed487bd3b00b261cbabcfa9f082ba7300610c6f92725d532a86e00b2ed1929a8be7a342c079835a2285569dca92a808049f170fba39d990884ef39ca511aaf9a713b8d78973b4f4a2fde7ca8b6adbdc5a70241fe3ea7d005b33e48cc9fe6ce5bc2bae0746827e548332adf83f8aa707e703fd688c494136d8dfa50961a9e5b69b542ed6ae0e70ae159df95dd9d4789e284a675fe048585214047f7f6819f7f011141d265de9fd4c04f4ed5dead63fa4c8938b2f42108d263d5394d164b3254294402cbeb48663cf1ab2c296d6ada107e8aa5b505da49af96e1cebc6b302faa148216d38b9e8130cc654974ce299172cb875742e62c32c063ffe7535db2726f65fc8f600d4dbb1a20f Output = 54c35602dafe572b99aedb7069a59c4f7818c860b27a947347657ac1954d6454 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 EncodedPrivateKey = c5f6c739c640b093956cfb9d54272b3c704d3b364ff1c68510b875c8c29f30051b5f60b53f6341082252746b8d4eb52b3f77c818d42ac776ad393072d458a28b186da2b61cf64bc6d8b424afb49a3b2528d4863c876aac69b7c7fa95314dd36ab5f021ba8c575ca458c469409b71b31f3a8e371937405067951c084b6a832ab321642c82f33395b0701e5a677c3c783a47d7a6e474af454c1b31b174ce5285e90608e1932493e44bf48b921d6a58b1b86ec2a38b8ba2a1fe884c0fd608af3986270391d1a42843637d75194722d31bc81b2b507ccc0fdb309e59549a874d09239bec5a41c4e9bb48d6968152ac9d431cc3b290371296b8056ed56898b272b948e556926478291cb0eb1bac50b6718e98b74a1777e685b7b6d7cd6b22bb5846c69149b4e7b292a4153763b768cd5a67b65c3d059464ccc123ac086f9f41c3395a56ff3152fe149d76ac2fee2079653326bdd82dd6f66b6687a7fbe00d9832b09135756c5819b1f66dc44c7b32c2496f63cf077ab51b8626d0918030134b8384c565f0715167b21fab697e84c6838a71176748f12334078c27dda3133bd44abd69bf631badb5f2664f2857c033102ce8284e4b2beb9095cbb40587bbbf457054f4d11bf938af207c1cdc5217b0e9797bf9ac88f3943873c8b66883d2ba5ec7e6696d50a69ba55457853bc526819f1a6fe09973fbd19832312b554653b8441e5eb01884e94a355732e3da645eb849f520bb2bb4327d560612852152f8cba2f77db8d21922da08e60bb9e3b39b9b85bbeb9b1715982d292b8f1017cd3e60447278cc0257898575a0eab1408122bb3fba17b62a31902a567a0821d42086aa6417c259a1dbc93b25003fcdec9f6a5507b4b732a43c444c5825a05119cd089fb2e569f70b4d5e6919faf15d6eea641f5a2875763f42b3991f7c89fe473cc057c148ac58b6c88dce537da8632c10ac851f8916fb7b6ce89ba5053b8d95d29ea5d36c91981042c4aa1330aa098a6ab256ade08592a05c95021606adea0ab637824214009c2b915be450a1f7434ea2c7f562a4fe21139c2652ca8785af3208f4927abae698dd435e90e7474556af9b907f6d73c4ee64897dc74c6a876eba1b598e784b8094232dc62bf1119ef764bd1a3bb2d4fc7de069273a223abe5269a1403873087906db164b58435ef41d7d78b36087062419123c8b1d54da918f34920d3302ddaa300797b32c1c81b82798e421ab2589964334714a75cc84548031d5810fd87890a1932c98bad37c860bb15663cc0e91880af1947b8a26be9183b648b714f763b81652786682c210301852776aa673a1fde470afb56eb0b0114895638c609d8d55585d68c165f7aad64c1406a165788c3364667f0a3c65aa300fc4585e959abbc5e1b316aa108a1cbf703965a74475147a2d323b7295d185571000e43b9120b76fb0105ee7a385965026e8f8309d4badef88b433a59090f88bc4eb4ee2f6c1f0d880057b477e628bc35b023a4c9ab682822556afeb32b6c9088e35c107e2a43506c43a986a0420f5164167519c4029b47bc81e93c1ec149e6083b13589bd2a9c64fc6247ec323b8cb73cb9f9ccfb8bcf25617a87a3c2d8b5158ac8661dfc789e92cc47340db6d04313d3a689b357566b9743cace5d5b906a39249f1c2bcdf335f37aac2565932631ac318bbb7ca75db36ac198ac6b15a02173049721d10f7521a52f358f35f3719269a695a4b0fa03b32d8a209aa12a5d786d8dea4ba05498ba222eadd647dd5a397e655ed309883d76326231a6764a7ba4226567022d70fa20cc53a045cc5a1fc54abe0189a4a2b6bf8a969d61706944bc59c6add2992b6e562e9732973d32b97956203dbc523803ca0a462ae118633483cab85c645ee3ad51682c0596378dea5e93bc7ab652648cf1954745172a75c2bf6a3177a7841b089b6ee911149871a9d987c6d499b6e0c4d15c9b74685401b680d3e112d6d70bdad6a3f9954b0057335ca36823328ac4e124d55b9932d548f58b85a32844e9f0260d8a4339285ab46152bbc05a967c5f16072f16178687b0bc06b621f5a4a14ef86b9cf1bade0185c5c52b3f2c407479467e5516ab9a1128260317605d4db250e8f4b59bf28a6ac2606d280af28664b75092fdea1fe9374976722dff579728e121fc1944891c586625a880a7bd154aace3e919b841b1f5f8c0fb841d1eac1fb18002ece216d42cb401dc1681836c1198653456c9392944054200a3b95b986a396d443a306b66018b525fbbb042e662ec108f6b872749d3287440c12bd07d1061a524a01ad7342d74f8a4b76222c5a439eef4235d51c9494602f6624dee256ea7fc09ceba9877f9332bf195c43502ee43c75e78720c306c2fa47f4ef6b7d69038dbcb8272b334c98cb665b306c04252fad3559eda4b96c14bf50b78d4a9a37081a2d61cad33b3b9418bba25409fbf4a5bb3c775a43b39520b37b5b82191b4983398858bbb0c6c8031b9736a5f76cab0e647443cb6d983a5e0a6c27756cbf471baa17870015566db8c8a51aba969e976a1c6cb2be166f20680893950ddf09cf8e3827a2a884a7a65d61c7c70a522d17ac0939625fe63958741255b012712e76fa8da809a8cb447d730d4097bd3e86471019dc8897bfc82c3804a76a38919f7cb50ce79bc13ec4bdda215bda9789503aa822c71ad8107a35818a7cb055b303338e465933565b94950c11836e8e33ae8093b0aa0c5d5d555cbec5eb4190eecaa1525014e8a341e9400180937afeb126c278a5bc4713fe9c417c50c1e47c8756fbb6a6b265bdffb4c1456c5b7d7a895b6932dd9a55623341354549283ccfb36abb3068b2db7348bdb1172318357bac12422ab93a32b453bcc0faa4e8e595b05a145e614aded6bb77278bd78907b828b18a22aabea48bdd69cab061522a618cf39406f6c78cb983354384415d8b857cb451e01b24f489a3133070d775307fb61a0f6d56d1255c4d4e18c62e57d8422080cebc919b81e67c4304cdb560ab16d929413af650a53f870e8017e90096452ca3ea648ca644010d34bb79c5898b775b197189a55840f43371dd9cccb7b4a28a66309a515658f06acdddc47042acee250a37632b42af51adf1c0666902fe0acbfc8f59127753a40161de4ca07a5c8bec0d8ad3141487da4a842147b9de945e4962699033375548d680b88ae8354d6114efe284517778eb9b7957eecaf5b4165424a5f82f100d02b7d39968b98f69c2cea1a0b39394f49265b492ea8f4000000000000000000000000000000000000000000000000000000050f496e61849154f498d752102402b70d58f7e61615f724973e5ffa9065b18a2e8541047591efe1847559704339d0ddba611d0ff8017cdc84e61184715c93e2 Input = bc07d2caff561b4645e3878d1de0730a88c05f46348526829a396f05a0a00603f0e2fc79e13beaacbe903827c20d9d687f3fb4eb2a8e9335459fb21380b8bf3734518778d8cfae9524ead1427c6a2dc379ddd2e985e2977bb63e932ed59c83a8b9a593e2adba0cc5f106620fc8c6c4cba5106bfdb4105def0c1d7b6800327cacb964e1d4ebbddfaa15b279115a1d05754c0c8a715fc2fe5aa09af7b96d5a93e758458aa5af8cba03b942f4d3c0fbbc2a45d3f7af5818d67219a72f4f538883ee2d3e507e2dbf4f7748446443bb71bfbb4eff0f57d8154d29f5cb26cfb52c51b676e9b1ac08786d5f475cbbfb49697a748b7902a83da49d285a48c7e9cae74b66a30b02a353a287b40a66a0663e7a71adab7d03272f2ec32d47097d4c303396db3e7b7a947f467a70646777cda227d72310806107b5dc16cfb36918e88784524e3a46c30242a40811593aa8f72c742f885a9623534753b2bac5e29110a1a854646abe1c0337251e85987aa612f3a095409a5a632af14acd19491577223c278b18a9c3ffa7f72ae49b89df6dc45ebb2803ece96cfa94ef9ef5b24fbe686ff90d130d3ae953a4f9ee6581a346b0612f84cb6ccad4fe94a53602817d67c61a9604d288319f5933f4a97dcc6ffc36cf14db593fe27f873be712186a6695d949d4552dab37e36e2e0ced229ea9dccd6d3bae22f9fb888ef400b594ec08a15972e8d2478e50f11947b52bf384c731b0e50dcd4ba116abab8af3b880c54badb11d83b4266d3e5fc25c2c8dbbba12fee2fa5c2017987f31277a67ac702b8dbe110894a8c81011c7c662ce9ab96a2e25cf5056a3e202dbf6bd5bef2347537f7811637e932d13ce02283d48d032c284b6cfb84fd813b6c3421017a7527eafcd3fbc5d4324b5351b30abcf1b366f424a8a0b5edf6bc1f3e8702b03eff875687c6caebd7bc15f1118696cc63859e3aab75aa9acc58484da7f2bc9a120844e4830429c0eee2b2324890bde302bc93f661edd9c04e1183528482f9950654e8c267234245aa9482d94e90e00e929b65431f986e7bb34524cc41f4b4443646713c7abe6c4131a2d67f3bf42f0a7f2eddf82b5c08a94d99a0a7d14c1b0b375fc158b7d4276eab22efb438f0d0a9b30e9dc127026181e42643af8da0b24bd10a532069392724948ad722b25477b481006fc1fd030aa62b217e6695dd4c7ad34dbfb75aff1df5774b061a4ea8526e9bcdf9679405c0d2e40dca00c9e80840e832fd663596dc55f602d094253893405a02d4414f119d23c4544cf832888db5ae8494dd2e8ee357753515d929b8a37b5b45446ffac20fb204b5c937f6344c453ffa449fe839b4afe1da61301057338fe29df93aa962a7374a2ec181ffff9252c8af5c3f75ebee02fba58a76066df4c6acfd5d1c18390652eb2f469d35dd708e63a498c08c5241b2717333904ba0e6e0845dca8c9608f28bd1046805cf7b220498145b23cb18184a259458dd2fbaeb1c383005a0d289562b0a9daf7d1e320aa302fd3d9a02c65fa901d46d4 Output = 7e1b4195e9cb70e6884d3d00f0b3f0a66b4d8c00ce112e1e79a1dd236ab62b26 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 EncodedPrivateKey = ea53a046a53b7e3298d588b38c403e67b5620c5c73a438ab7357660362ab3822b5e774a9dae973c83a96db79b550dc176f9b0182d37f12118bc96a4982249a352219a110704e4a0ddbe545e4f55cfc2c50d54cac33ecb6fcbb3ac2a7bd4e41282476797a3c24f4ac4f60c33da281cb1313035c9c804d755267894d867469dbfac7be52a34f55c0dc642354e52967b043a0e0167c806581b51519e04af675147578c79f492da3ac0748352c6e5c7ff462008cb42e9817155444b214c3b93ff3ae7d44b5c2b659627a833cc18ccfab4fe6d6513dfa67cec499cd7a0d052a5f9ba378bff75033e69ad053c04b74c8cd756c7cc0bd494129e069cfb4358324066415bc2a4d1cb8401867c9954aa8a33f929ca279696cd515bff0abcb6c8692aa9cc076861e2bf27ec360983f775e9f166964d0c43c380366f19d3f868a7e038752d30e389c0c057b6d93a9ae64746d5b3a146d31269b94c7a753412be68d09d820be6890e5db1ec3eab1acb14cee8a317ee7ba0eb6027f13a540b07c12cb1164bc7d295c16eef4c8d9773bd2d32ead764f58fa48abc2a5491bbe00e07965017ebf40c973343704112bc90849d219c70b028ff3769e720c4599098d172674358bcaa8947ba6b874e3d94e623122ffb3984a0b571632be1c540cc5da45ed1c57da1054abbc4456678249a2589544c3dfdb6330ab35416ca49c8046c9446150660b45e05b720722bf390e307445dd8a3e23253cbf633c8ccb098976a68e481ee86b86a32865d9caaf385842cdd071b0974e807710e2b44c598a4a36bb2af048b0fd30bb6c64a539513ed2a5a9c6cb16129cb88d6bc62389b4846a2a0afc532eeb0f055aa85ce7b43f8099cbf194e664c59e683e535ca809d40f72d4a3d5e287b5ca3880d4af1f1523b60c8f811a17b2881602ec0393d54988d63a1620a48ab25a5336b25ca25d5b21425ee54673062020f065693665c68399691748ed8c2b6ea47b89391e7dbcbb3e4bb8bc0972916aa0ee5b90292b23618c5e9a68bff8476fec1c7e382b1cddd45069263a507c44b97663a9c8b4bc690c89d25893c4caca0caa7633bc66f449bc06603fb747843b0a8ce11d46ca100b3243a8617904a2ae48db08ba24bacd5b946cc96b834491a246850c44a0f049bb3e099b3353b28c3889bd4520ce75749b745e65e6442d970e917362cafcc9cd1a6194d9ba41f29feab98320e10234c1b0fa367f7c3a420052a9ace9a0787bbc420832db814e8f86804fb74090146f899a624ee9739ed55c40b3716724b8a8164b8b976130d89e15dc24e2078f24a953b2781b7d36a12334356a6998870a0128ab5152a89ddc84aca3475f8cf849bd762ea7b23bd2d743a9d3a9a2c2ae4723b5c1a3b5349a2d4bd2907d89ab8fe80624838130697bb1d45f873a3416164f862630e96075fbc5192be26755eaa1f33026a1f201a05b6b57ccc83fe9c191b13016a921532c4558b44ff0a26c864c3102ca921c299b38199f7162938387c3598362e5f616756bb5aad68c68e0a34ce96684597712341f391ca6696538582ab0dbd532c7757b5b24b0413145395123f0c4668cd538782b0f65ecc30b687efa78183de47f53b73831210c513c54febca5ddabceea01649d9c6588d68c05e93cb6959fbe348468cb6e7f482d2b0507a097625325a7ff5740086bc203410414845a177c578698b313842dd2737d79806fdc8aa4ad8b91b514b6aab60885a49be68ba60d05891dd1cb47c1850b0105ec15a95c93136f22a170e346d2256a0cea672941335423cde35492967759b4317981c34fb0d759a2b08aeb411c362b2630c4b8ef342cf844206d7a5a3934bdfda95ba9fac912fb1844a0bb62041868ba0e3660a5551951b39880eac2959b5028eaa765492416ecf7a05102450eb20eb2a28be460972066b41ac87abcc28b38a7c92d91779e0c7cc8b42f107b48269521edf0c558a1b767536d295c3a7e60b9de6a8f299563be7c4d33d33940234af8c7764b181fb7b5af1dc88e4e830725533656520af7344e4ab40f6df34a90a898c672b854021d0631c1b1e9999d8176b22a5ce829a240642e19472e635a83c5086f87872f72a62e5fa038481a6861141227666f9203675db45a444c6310518d86a9221c9b6bedd753bb7914f7995e39031963ea056536a96c9b14598c95652091dba9210168467d7388b73770aa905052645eaa877c6f8a45acbb775d080521479314e214a5217835667dc2cc67dac17b0103b1049a03585b30631c6dac53b6d4056e5877786b295fe94c8804b57a027609bee938a8812666d12345e04c92469463443fad1c2188c951cfc6a06c3b8c3ad8856ef26a67b7841428a1f5b69a3fb82cad843a55645b78219d6de824701b0b1f192d4f816f45032b1cd5b465d33b3a9cb2fb04cb271a3cc74a8bf7ab6ac7a00e8ce6a0486c660680219c6ace0917b31595584f4756c9c5273ee36c37d25d5da146e57613edd34795b9cf61bbb7ebc441d575631215a87c4070159136348854c297cf3ca44fb2814448e30eb2c555aa2393bee966ceec0221a278f048aaa6d09b1d801aa0fb369ae4480f051329390af222712c61a59f98a31a03ba90c1a6c34c1c98c0be7bf59fd717ad9894786acb1cd081405c66a2e79a1fd77cad853761461c99218aca3cf4920703654fb9529c106f41a78b259294709bbc91679d0442bb383c28d64683ebdc7b94f4592c8ba2c1126c9dba9377040d3a124176fa33a3905cbb96764bc89a69480b74e38f558b422ef22e390bbc76e048c01129c97c26125bb2f86c4bcd274816265d8c41167223b0a22406d2a193ad3b1083b0cb75f9542e55b9aac02845f59618b5aa580b5b2bb44c192a906ce61b8c368278618d8ca8409fc02bb9b097acb208e3c2a9b651a316b70cafe6b9bdb32ad794b4f018b66ce55639e5558f5a3990475794bcaa06f17093d490fa583e6fd9596b40958359a30f813b940b1e1e4223d3857cfea691eeca944de845c2fb502e35a5f1a3750454593fe1c41662a3b3da407aa269c43167acc98f5f3c662d6177d3594d0cb800087c6a525c586d86c12e941b046625d90c8ec6dc8a5c546abb19a0b585aef39379db926691124265103bbb49cfc4e9100c803b4ef68a904273a6c899e48609bca003bcea9cf82203d52b5f9b65c409ba9503b3b16c7077465aae45d2cd4ada79ca43a9e99a124b7c9fa24a323f6c6bc18b81d9a6161191561f3776740b539479582a46bd913ad73e0900000000000000000000000000000000000000000000000000000009ff3bbc6c725ac014b798e2d5146532f55ca1f580b27b436aafd30679eb4bf35ea63afb095b03165e6f3b9488778fdd771036713df7b893ab8777554eb05f64 Input = 79efa2d537baa2b87a787317162d3dbcb40cb3c25f540ddb91aea6cea9870bbc5a5f86f8900b913fd4154bcfc7c8a463b9b66118c502ddad539186fcb079664f44a5363cc8d80d6a4c09f28cf8952157526cfef7bad2fc2cb69ff03ac39e37d47faab64cf54f63919303badeaab9e59df7040511ae335c5230e46e00a666b994d647d11cb032e7ee235b5e18b1894621ae93ee129823334580381b857cf0360196cb75180410f9fe7558d0e189502a5dbac5b4f0597cb3d1d201f89de26f7b4ec0d200a418a26cfb82cd4496c3ee22f6eb60f3ad2e1af981c238da13063d1746d65f77ce0ef30894468b687b31443c7acacfc3b3878fc9ec56878e7bd1a9f72ecb1706a4e5face0a83282cbc2bd15c89afbe3c97dfaf395a96ffbe1a3f75af03311afc69dbc01b11ffed2aeb8906505e910105806febc6e1298fbb5c0bf501232b888b7e8b285953d250b866a20cfdc7833a732966b3a03485ae2852d0a3fbeec6dfd0ec8015db5de69e55f091e956ab4392834c5128417105541b1145b27175fe35efbf3102277b35e42bd83aac25e25da6c55c28a03b9e2a8135871b4cc49fbfd5598c9eaa2482f249c0b6332a6999306be55921a3016499bc63a072a6e9eac894a3ec209177d07208d0d271c47f8065d0facd2e975011944f7884088768fdc053cf86f31f6d348222c06467fcf8ce0d404a2558e8cc422521a4e249549037d3e8a29e03a9a9bb511d9ffef4c5185a380d874732c9e862a6e8fa3fb72b213dab2ad0d91b047440b1d334660067566e6d2e14765d8fd0a45b9b8e8566419a6d7138e5a106c31b1278d50027d152bc8658d7045cb2297bb8382585b38be2d5fafaa7e8c867c74be013793874f181a9798193dee26fd5812eb469d1b842a969cda65d3440c67b00e6d1c3ae8630165499c1b4cf3153fb5731916ab779a2562ec62637d747d61342d832aed330e5cd794de900fa507d4b5fbdbc5f3ec1aa69d0319b3644d46d9502d435c1b5a329c0d3524611a145e3024595e91c2afd577a422d59d4d54a430f439534003be467b6f018736c4bebceaf7c83c799c2b7745ce7498dc84b9e455b96410dba1a0a5720fe703b7c0d859a42445eee7ca3353f294438a7d463fc3e98f4403f93b5fc4add88cc22db7bba150a2988639ba96cba8e2a0c980c9bf8cebdb5beb262d79e86cceb774750cd9a192ae93d85e60722ec6590beb7df8e4d036837c97dc05c7964dab00034683a576da5b51aa8a0622edc27975978c7daf1b942285572b09c170dd332a99bbf703d84becc6a96373fd1c0b355f063e4c2c6e59f5437802676000a819b9b99418df893b98a8e6ca22d95da2c151fb24a3a0e5944ac4ca6376e6c281b275589a3907c0473282967a121f1792d09a15e9d71e71e73f9f627ef0dd478061cf053af434b0663624c3bbafe0f37d7a32504e9c686f41bf48e287aaa8fadb73fece907f26a9576611ab2176a58e5c1f3e98ec0248a15774434c2a81c7a8f57f9950b83c0d3770d17c4e57582387d6f19bd Output = 2522e72d308dc9d7d701e0b024af9e15627572f13573b27c406fa750df9636fd -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 EncodedPrivateKey = a7d40e120206cecb9458a1464b96c447db086780708c7435e40bafe1ab8cf26caced91b888711b8b95414e080c2be24d7a622c2e0410fb9c795a25a50554abe8b9049f9890e29531cca88e4284a5bcec559f939061b003510c8a23991cf474ba6676b0599c86dcc0976f3b61cb624954d3914bf28e109193ef1b9efdacace8574dceda34905485e1a79d51c8ba06722150d8a243d69f671c18b1c2a77c990699b72ef5b1c4aaa121a8e5a6cc971178127024166f2593893bf3b9e0db273040b0821051cab28af5196b8937538a680b39251b08051502c2a3d5504f78b767dce91e2116280c3532e9426b93d8cae3e9abc5aa4832c6bfb02a71559bb689f82c22835fb314a5e6d44bc4085eb39ab41555103033a0f4b6aabfc5246c93c07840254989301f88776c06c9f808369e18445058b4d940783d57b7d7901b0d63a6e6512b31a63ce0704028d936462c18eb4bb78accc3dc56884d9837d8632a258c4e998cc536248aacc62f7b9b65191a28a27a1cf44a0d512875ad5112e034c0adbcc67edb84eb000bf3621e7c1c5cad1cbd06f848c5d8c3601b07463b5c0e33cd260a2ec99a972c47cda74229f6292221391f37d20903aa76eb6966195acac6373a41db78b8f7515a473ba04397c2e94a26a6acd8f2cccdc572d4b60e56880fd0295152e18bc79699feb1a0b6f6c7ee19545f4124eeda5755a85d79fc2dddd2848216576e9ab4d07b7ecf77a74937cc1605602c62003dd5abaf601b55ab0cdb37bb3110290f829a742c5607ab24a50000f3191f435427b5345ef884b91811bc44fc4c6de32bdb0a73edf80c8783a5a6b6a2d06657b16104cd62ad847206ec1b87729260e91b2afde6b0f13a87025c10bafa88e1fb1a66b98a5308a2c4f10874324179a2729df786627271ac5a945072beadf878035169c543c0b07acc49241b7feb406f524b71c787ed757a3d48c233bb75d97c42e03b9973cc680169520e400b00879cf2bc9119325586719f22e1b2de163184b2c43735b2c1a8654c92138b90c458421f681136e0d6c417b20a5f8c126d3672a4073942855b127a87ce96c7e34861923b3ea9bc9f0aa277746927f0777814862b0845c3bdc12309241f387cc6f4ba4a9688b947ec8b5603ce88ccac5c35756d0031ab4a5e32f6ca97184df2acb38f724fee64a6a688c69f6b913576af98ea2487db097d7c81dbc2a29a381b2345495160c348e8207e313929dc08412304f6a01c90f6889e23b7974bbd6f081f52dba8baa716b53769e6f71b962156cd44a3f50563efb3b65741aa26e42a3720ce737c7a7ad5c875663bfe36bde03b106647ba1ef098569bc10a0940cd300d58571dd354ca5ef714733bafa4308b3c4b7528862664a8656d16c9c3837355e39072db20af20025306390ef32931e793e33333cfd893c6227215027ab7ba9cc0212ebc749abbc62be483b3e2406a5ca10d7fc534166646473c27979053928aa5445c4c1c26cde40777aca39f5a64161c322135fa176d44b694341a0d3a05de662ef0e1aced53c4ea2762c1333da3f987fac65ea63a17b55c3f681c568d648966eccd095928f2e32af2fcb0674ba3a50350e282c99af149ab1b3f52d3b9f838b1aa8cc5e2c1184862562b91806efa62f1b72a8ec43e70663de1f66a59687ae0cc1d9de1ce69244fccb0841b4b1de2e964e29408094a1ac0a9b4daa836e94454ebb942c6e9ac66f39abae73f61a99834292ada3c824bb53c8e67912a07377da92e63087f8d947f59d94a842b7aa8832b2c3c1aa957577f55027e76c106f86946f036804671b0e0416cf62e70eb8194d88030e2b38585181c4ab1fd8165a821bd68dc8fb3b403016ba5fd129bb9d23182029c4a292433087632816c009a237a608e65cbae17d688a326bd6c1ab4634576fdab2322b983f29c3e63b31303cc386bc90641c84965572c49a91f4e8258764834f38ca7f869cddbb10674d4296e5205ad805ac48462d3b31a9e6067fc0a27470aa593b896c3c319357b9bdf0632bf0786fadb0ac242609462a06f82460ea75762a678fcb07c350649d13c24c9e33200c9ca0e9bb87dd2c8578c7c4e27b1b75681a0b6aec6a55e767c4e14820f2ea609a16b862d5695556b0937f53e0ae370086c8f771295b1a09f0003a07bf512c4272f7241752a6603f8f51ea9a088e5263a59eb0b13b87a1d2929c2c29557681f180261f46c294de4aeaf380ca5f79efa2c64ed3131272ba489494ddbea14c69c46fd6346a7ec9f72d89559435e139a67bc3240bca29b3774127dd85d53c20bef719724612c462bc598c54738c87a00a9cb8c4b44e4e7ad4573afd9324fcab820cbf2091fd83fea52adc1b82b3f6c86369aa358498197631a20d40c790c2ddc66b0871c1ef882305bd978055bb934467d3ffc0359c2b31748cb19f615a63262fdf695f555be1ac432126b08e4a97acc18b8606ab6adc5cbe4589389e1121d737ba2b3a84d02bfbaa669f3a06b1be13fafd42a1773c830749cad35456e956c0ee64a5fcc46f1763c3b0c0d3de5c296a28f61194ae72979add8c7ce710d4ee846af81cba3e18d5e459addea9fb565b010e9ceed5798155227dcab155984635d7539d68c9f0d30537ce8b573b6bef1170540d0c10528737d6a5b219b2d96e5709a721b40536ee3c416fcec0bdba013b0fc0e786c9765d312692a80a5c9a3d65a6662788d194722d63b4bdcaa700e4c3daeb911e4d45674c3720be35269a21c0717a4c3aa2f3e1ab4f20a885cac44228138ebb70bb4548dedf8678d2163c339c1a9c719c2f1a51748571358c1451b0ced7b90109c98591126fbe57e1c913b5a935eff14450a22c4a108108b99b6efcc9bfd8438b5024677144885f1886ba068a6191ae17b9ffac1087bc94badf510095baa7167a7fe245a89a2a627d2631706a15d5aa081d037a4101b217c1c45fa0d83dc790447121cd9a533592cf8ac424de8770b45307f0aab484467c4acaa82a5669f7621e8ca42ec0b9222766b52775173b288ff5b01d70a60a853aa44917b8cd09a4b666138e91a3206c97877c96d690957b58553018f55f168c1c51bd9a48ae762a65dc73f366c79e77c42e793750924bcc1472cd5e552e20868a42047593842619c2e0fd40a3c7bba9557bb5c71185430a0158b9b95d04fefa266005141ffb4ba5160a5eee1499c09b11c549bc88cc501dc94a0a5828ee8a776a2a4aba3bafd410cc8354216cc3a93a457e9847af39b898b04b60a0c661a72a2df2b000000000000000000000000000000000000000000000000000000da8d41b69d2601355a1e57206c862dee967af0224b3c5ccbbbb89be1bf12fc688bac5e523fc2f73973b46b1727891a6077329e10e94acd027c9dfa38ef4e21e4 Input = b0e578cabf9deab616e52934955f42eec74bde5ea98acb022c427e08232142dd08f9120eefe5f455c8f120e672cb68f3a146c3aa457b637d0901fe2b4cd45e8b208e06823b8aae09778cd00fff5bed5232d219a2c33645f2dc30593e591f697118a8472eadbce05c9fbbc5d4b717b880065173cc0854182555376dbbe39194e4204067358808c890e5fe96028921fca344e3500b615f2201a1c4e4d13dcc889cc9b1ac72429074c21a52f4c78ea2c467d65cd2c9ed682f21f31b27af4eb5cad33dd633185bf32e726fe6e57b03168803f693bd85f5a9f2c3ec6944e9ded2b8f3270a89139ce50ba6ded6bc6b0be8893f44aa5856acda60dc1c4c0834d45574ecb6183d6e59a183c0125ff45c718be2cf85b5ce6daae6e37336ea63856561f1bd4404df725d5ed9263038d1c623b2e1aeb35924b79de474407168834891af783fe5d83a631eb14d7cfa949d698ffa45e7d8c46ed4abf75cc666b78526c9b95ebb2920c77c56227eae6c893b57f9f463ff2ebc9acddb2f7ad543c5b2259047a4cc87ad05c08bbf02e8bb267bc490c4b67106fb598d42135c927fef3397f4c3f6838776787f23a9759dd3214075e79eb3929932becde84e82c257e4638a19e1e3312cfe09d4ac681d653d749c8fa6efa6dac35ad59399f1e233540fa354681ca55db90007039b7e504e2e4082aa3e4d672019741aa02a281454d4e1c73a1c7d0b5449c2e143ceaa3b18cb9a74a89f1ba74963dc5dd4155a356211277af3a267947700a2cfd84a605ab02d37bd6faa8a26b50f7b3d9bdc79913272c31dcc0f0183d05933a9f233504ddee2dd851529667ec5174a3d23bfca197538ebacda36bc29ca675384c0b3f45e4f67fb66d8dd4aa57b7da50ead391e6b663af173e7f4d46139f5d0f4cea84dd32e4e718967c6b93617271224f2fb3a1ca5febff5f26c4edc60e9acdd9e464ebb4571dced645814e1038a50515a7e06501adb2de19fec4119dec7548c41097964c3151226153ccac24abd1415579ba1c37c805a5827332d97ba90713829fb30b7b09b275d75bc10d4a26b33980a0ccd4b00844d9f379551bd0170ee895286526ea9625a72b6cb8decd9cf18e57262f8102a025025e8168465a65a7c7e4d5fc8742781acdc16171085d51dd5ec9f4f71f58cfaf4557a55d07e7c164ccf7eb427145c7f9a800e9bd9192ec0f74d19fc17d3881b1d55e8600aa55abf78fd1e226d9dd6e8da2bea15712f5f43325d4b9c083d6e37d35c043f2bc8c796ade072555263331bee7fffa54e2099135ea363575847abb770322376cbfd3f1b7980a1857c55fc82aa80bdcd701c7b7d66221f08492efb5438a04d041b485bcb61f6fd306e96cfe758d99ca1cee70b200eedee86145fe37ab7aafcfbb2df694361fe9923e754187c3277cc895c4a53732ee118c7b6156b55b30847a6e828b7069a5d4be623abff66ba87bff49294dd9b1f698ba445d610973d052a80691c9968e3179aa3eea5b0bccb3cf674c5cfe7d2c14d7b6daa7a4813abcd56ef930099 Output = 1cffb3d6d9dd9cf90d79fb2c5c974818c5bd6f32ea4d44c302337c4cbea44334 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 EncodedPrivateKey = 610c36a286cca4815c657bc2f28b854aa8602890bd6ec2700d64b495b50d049c5963b8294752942d11c1d0182ba6704e54c003b828bc58b6ca3ee0823607c3c00bd0471b4df571c51db3003e4cbe6166c0caeb747f79573f5b8b80d12ca78bc1d3e01a318bac91fc863198afb70cb9256a330faa06639caa7ffcc1248b367bb6b0bd905ab0098b79b85ac5dc083ed43ed8b248dbb72e5ad962b3201c92b132b2961d9867b48208896c11afdd929be2792839674b18e4c1e99a7df714ab7ecb58570281ca80a92f148bc492797564682b560f1bfa42b2f7734047cfd6375d3dc05846da1d3511cb3c8221d38226f29ca52b07471a41764f86ac3418a96aab70fc8454d6823f8b7c6211d216d08c67eec474a3cbad8f3587e22670ae5a9938651f3b48011341b6140ba393621accdc3f606b080579197c48967f1c8d11026d8f90b0697869ea49cb9db086ef687227b2549ac689b564326a2280d8384698185afb25941ba0365b0c1939148ed6e1bf0ef5c764832178d47a01c3573aa268e168b740194a9b36ac2580a7bbe1625900befef3adc6fcb356100ddeac4393d388fe647c3d623d1e6a56a96073bec59f5fa39581245e31aa33cfb865bbc28e9f2498bad34a5bc65c517bb8cae19b6d1864fd7a0c48aabc78d0373a84c168f33ff13a9586aa349a185e3528003e804c8cacbccf0073da46567f7c3ee6a55eba856851234b4f3725e1bb3609e50cd4c9c96ff947c4b048dd7c64b3498d23c234e9bc45230b8b0c797946d0980dfc7bbc5773620b8330262ab6247fca5684c9fb8c2e692c3f654099a7a93d0aae62d24eb594544a81431f295bbca7b15dab7bcf728e3dc61f6354a459a120c371030f3b622569a78762b1cb08248a455e0f0847e1531d194acb0507bb53e9c0e13c8b2f45ab06362be3d9bb58ab6d90825a15211f81f4987000cf74355a28ba08443b3fd9d26b70039955773f9f840207f696d0e7a4989c4b38cb23df626e53b7ccf7c1bd96bc3f68c20ba180a482799d2cf975e0a39d5fe863df954665509b3eb63c257b8c9e39050bc4a739468e716cc289a79053453a28906d003535536439d418736a95763ae222c8870b66f1b5a9978c29d238658a3e773063dab55125e851983706c3ec68d7fb1d595b55292885f758a8df752fd3d97a8dfc33a228c896a44bc039ce1a2069810b1304d44522b1a5e43756cb843b5ef515d89c310f442f585259e5d460dcd578cc51ab49e63a7cdc2566d77e6959a7d24150cf0b413d335efa65385ae13b482b9b4db4ad2518b71704098d7481d2233e2ab201dcb4a1b3604149710de3cb247f29ce8ccb2ec062b014708f397482dae5936bec37663c849c9baa9d3cc88146b88cf970e574694af03fb78205e205435221b32e5513989047e62775f1ba5aa89a10c9d35cb566328eaa5748e9c5057446f96cc691d80208940cfea984df8817d4507aff0a0a96b8c6729329775c8d75935d7624cc0a06ab7a950f2b73ce4d90239706403c0651dda56544ea59bb06a99f00bd698a8c3f127fb4a3759317a05ac244a07342f9a47257e5649dec2c7050188ea669a97c137f707f4e5b4c57945f82c1b0b2040476d73acb54724cba00e8014b4f4687bb6670b1c2a29ba577100943d5b926cb396423663f710328a8b536403530eee05006e7a7cd679ea44c29146494f1775cddd3b43ce6a903283f7890979ee98842d5a76f93777297abffccc0b8faace8f362c081aa435c32a5c31773bc046e61921f1a5707579fe36067588a0f32e2cbf91aa3ca6b38a0e12ffdf8685874869028775fcb7d7fd7a1e37c611316515638a510a13e950960e6f39395e436821165e734837ed575ad510d4fba6c3ad67e039b71a9b6c2a7ac240ccb3742d65b4b1c50a6a1a496995da77921ce33624fc48135e88c59caa47b299605ac1c79009dabb2062e375547ec907590b9bec52c86a6b9e394ba5f02401e4545c462c5f320939075b516c4a5dd0aa5d879456449a115125369584a609a83df8685ed2ab45f038559dc6b0ea170b09680e7e747cc7246b6c182d9199941847d9c1168a84400da2a98215a9e96f6bc869035a8822b27d459cb52147d966e0c354b70ecbe46daa9034074019acdac30055d8a1a02741ed8e602e2cb3185ea44c9e61fab637188554c8b12cc5abb9073b35108f59f6832112ff23b00acb0936594c00c0534a8c4c11cae4787092bf497b60b4a44116156e8368c0c950f3677f6424690803ee92373ed5c13d84c355bf041edcc872965816d6723b344244d0a54f8ecb0f1703ac251293503baac445996a1c9bd6ab851eb52f042692a2b10e4b9b44dc9625973af03fba67a3a93ff849dbea64739f643bfb803ea8653c2b9ab9639614000994bf48a8024c4e61c8a07a5c79b19540084bc7664ad44122e46ca1fbd517c8e68aeb3d835e53846848742a9fc2a4058047969bc11a773e623462c7bac66a34c62db861ef64dedf23c0b7441f6b75b4e60b86fe309b1b7746d558987f6a92cb8513792360ef76cb6548f0813ae8dbac418c25a1d95b06c530d79c6751e7569a2027f8a5354de3a70752764fabc632f3a1bf2473e8aa2a5cf815b3856a89afc122d98ba3f74185a3b2c09049601e23ee226329f024ac2692adccb2018b22a592a450b4a5819b2a498738d29f7145e534e527c859f05ad96cb963314c58a5a6b050ac6ead9adc4782859e3383170cabe4871cfc17a30ea4ac55cb998e77e1a26662a255f99f4ac7b98723341b2c7134adcdcab12a473bfe001127bcb01f84df31384af06171776263085bed1aa3374da7136648608b569a88663d2122e84b4b946b35c1f24a836e924202b7c7828c15507b17f906bc0e4b28c230134d90655696edde11a32c7a70303aaae3363e2a6947b4bccefe9ce62953f92521029959096a8910e71c51b69a0615ac790341c0ac3a574a79d34c11b4a974ffd7cccb05995d4089f8186b545b80a166982cb53123ef644e82897c77889ef91bd8c5a4ed1a4a414389d77307d53487940fa32782061e8458e0c601c884321d121b48ec04bca78c60d39b0c4bc9291945ae18224ec73ab7a451b9cb511bae34a20e326a497cb6ce46b5848c289da630f497ea3975eda79489f18a405e91bde288379f291f538c1a1426cf1634bc033098bbc9958f7af6e408354314e7221c37c1610bf904cf9e7807ad327f0f316761939674867ec7223f06a245711b0d47832b1a699badc8e1217798c0d0000000000000000000000000000000000000000000000000000007420233153145d018d37197db4a72facb39b5779cfde51a1ffe665b09f338119e42ed33e0da5856106580e02aacd0aa1546d3df0571d17452d22f186d011981a Input = 3159aa52482f4262cee553f9eb6d853d091a507831f5ed1af37b9c55f217eb1e87e8b0dfb653932c27e9e9f2c4d45cf89e9cfe9ba0d5175be56b7fe3751a4255649cfabdf0cbd5a8704d58511acf6e0580eed572561fab262b24d39c3a430a4e54fca969394037df12fd8cd71b7b6ec3d8f7345b05d4c16c5871b686690cee9804012a3379bbcf720f405c3c83f59aa391cefd8b00a73b41147d42c8b7820b0e779c44e032209067349fa4cd35e83850ae37ee73f96fc6bc5b71ff9b0462604b4e07be60cc76903175b045b908c9b8e7e94c6bc7c48ffd49698873913f9132025e51614317d27a874e319d802923804d1ce1626420d5794bbbe5e077cbd7fa3d958fb2d9608a3d41f605908d21fc7f942e3152337115a28b661f76405620b056692bfcc066f370449628f8e31b7453e5b7b10702f7c195dfb779fb3253f86acbaf4444ba9ce01c9b043133a233030247f8fc44d5b8c9b024ee83c186a62ba9fa5a3e45389217884a478f238d6a9b8eaf3d87b7b4b4375d4d5226dfb80255faab42380365b5511567978be9726d21178eced7294463a348b1e976d800b1114fb8230115b28e51f628a31aa8cf2e3253a7dccaa37f975fa2b8d32a6b6147033cfcbde33ab8857e3a6af95e4cd0db62fc020f55c2d6c9204a05835e2cf878c66502f572016d95b30c45c2ef6048471ad0cb7fe14250dddcb4014c392c22fb1dce1adc8e02f416d3e9b417f41c1b4065b975de472d0e9fd5b3a012ee9bf6311345b4968f6f18262bfc2a38d56d911f9efb981813f77a8a8d6af0618e015b8b005e7ea957f89f140192c7442a645ea7012b5ea2ba9f8cd2fea2ad3e41c6a57582237d53444fceaa933d61eac36d03a2865bfb7f12fd8cf451edb5050a35a75c95dd328296dc32daf61622ce0cc457c5968414b634b3e12a0ce45bbd733e3982c087a037d89cc86d546007bd92eef33949d19dbd4daa18e59c7ea3572bf3155a9a46af527347f4f4dcc2be3cc285d65f2f86c681a137850431ce8d2f76e295e74bd0b3c88f1b68885522dadb99fe1c8e40d938c9610e466770d62c34e9393241907d9cd7bfa470cb8fc149306d9450a7a1887d03cddad3fcdeda1ea54d3f126bb29a1ac3d7c5a60ead90d74ccbf1a75b4289a74a49e0a7c4006ab76a83915ebd4a95a471525444dd2c3e748b1bd347774e2cf01f90f05a1672c58f4f563e4da083e95e0fadd4ba57acebcb45611a3923da1d0d73f5c9a55489fb0097e123694e413460252892a0c6317dcb56efa834f7a51db4a413976afcb30ab4dafbe737f43da11c1b08a2472cdff3995dd7d23382b866873624fedee76823d37ec230dee2107258993d5b802fadeb89c9469a33c66c91567ea92581e0c2c1eaa2e2a4696b024c7c6009687d07769438a8b2ba75a7bfb32841dab8acfb8cbd4d1e26c5eb68bc49bb394b178e6f89dde843f4e2c5353b04390c245a0bddd1aeaefb87528b719fe42b35ad2a89ef34826d9e23f95b1bd3c3b24f785985e10dcaf0eb33f5f71f5cbe55 Output = fd9e333ac811ae8be12c052c65131e3a7a32ce82e39055012ea564e10acaa85e -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 EncodedPrivateKey = cc389888219463a7a5f6c2ca3014accb3bc26f2318f593876de6a49822b6c1e694b7e5aa9140a0765b6334ec762c8bb018d28a99004081256159c836f4f800d0c9aa4a7136fcd89ba7cc1d6a32b23ed181b3fc118ecc60096a4ce8261ea2c0a6ca49baa28b75d1b40215367e6a33a1c177937bf43a70c3889f6aa239e20e499bc7a836694a0bc2912cc7cf211ba20c12d5ec312da2815ef20c8565712b22a927451271040cf4daa44d79705b97993584424e7b3224a5583e5b8eaf640e85015676517113f53a415220fde3638b9c0a38115e668545305ab298b9923bc16de5b9137b30a39a2c8b5fb75e4d1168593a8eb0e067bb9343f1a030e5228bf0b3a49169393cd14f73c2b8221b1267627d80b97d30544b02a4c7bf06099194b2d646596aa439d82a214e6cb9c5ea1ded727c8143755cf881415b6357661a90d5ae759475baa6076eb478a5826f86f9868afc47ac3a02a0e84579a25466a63d933b071213c886790c320416d9422d280745758779635ba6f848440b2489144866e8e018200cb8305b3060926d7e7213089a06d044176b053f3bfbcecac7840dd7844ec29eb17bb2caf321a5b17848c16a678552727a3d70c34f024164b3c4856b0a4ecbc78d345187c6e09f055273bb775078b43ecc534a40e66592b607b56b5f9304aeb048375ac71c30464e979a656f1728a7b700e3b33e5026bf40198b94455d2be37cd65867522b20bddb5ecb7a010191254b8a403f37c4577a613ea30678daab55508b16d6020f074504f928dddac1e8367faf6199715048c96a8fd6bb225715accdcb012cc856a76057b6b72b09a4aeff5b8ba278c54a750596e82bda45be19014e8ff52df181435ed9ac8c402147b539ffd984c291535b7bc8b26c5036352520730195fbaf40033fac450843e808b9ccbf03b40a9ed657f6ac4af8b65b4e389280633d79799e0226b28b356fc2e39f10a80452dc934caac7c3c521f0c5544e7821a403688f08378c3086d3ab8f7e4036ad516778da606204aed3ca1ae8c42e11038a64ec78a5fc5dcd0475429124b5d665e4acbeccca3a296a8e878b917b886ec7f029491c661bba684ac4229cd71373c829055b602db0518a481230345a34a709010a03e4b197273510a0a24465288c327c10c75434d9473208a7964db7792ea81c5fe0c4bd967c3f0c98765ba7d3faa4e6097f09e9bf10638fb900a764e4a0bdba2f19165bd69832681310a7a2585bf06322a3238dd26a4807af44faad999397d4aa14e76c2cad5326ce573d7ca04c03db769dd01a65583ecbbb991e7a31b59238f8741845f1adb5992607184dfa19a9e8840ed9e1622ab93031e2b448860d411a3d239277052cc8ea71046a0b1ada191a020c322d776c6655ae71964d86314a86a47b6a367b8ac5a4aec75677226de0c1864492c88fb70a53187cb76835d5477346646a9da97301156a3ffcc231f9a0da760dac142674e5cea882364dd74fab66901dbb7eaf037008c52073054cc2f94ec845444054058402515bd206d496bfa02c442c746ff3e662b899c34c40900902c4f8ca146458522c6a7af772b2df483f9d840fe07464b0c66fe1036c070c6f70278e9506342663b07529247b1697f6513e1ec8234bc145eba3446eec18b3826b2ae709792648e071a7c4627e4ac7716db5b1d6040ba7b8ac39b347ef721a99c879453846e1aa591b8495e19003df973580d4192cabb72ae2b1f498bae9b3cfffc8bbce09122cd1910a406574106810dc556894777f35316c992f3b902186dba411ca3462b927688c81f7269b7c2770de5aaf90c81f752a3ec77942729a68fcb38a62946c601c945249bf0e280b66764ba71a44134ba84df1400bebccc61456fdf3bf50aa85e8e60f491ac1c1317d831ba5db6601133883fda81115c67fe4691d9df01fd3732b336bbc3899cf067b9e3905294902ca5686480cc94eb4e98260408b4dd060cf4b5344380c89d564b31158ce098ce1e06b91446c4189c6a4d89aa7e81befa900b250a7060406e25725e09399963c5e3e04219d390e6c28983e335646485023312c4d5bcad9aa7ee683b935d71af1908703fa2c9d66c8b6c55049b3319d39c047b5824d04975a9034e8ca1a9e1a5b0bcb222c5b5c848818d14503c31270d4f8446d013d4ecbc250b72dc25934726b426afc85631ca1065ca6e957ba00f1176a6a45b68a5e93274423e642451129ce83b7de439963c0c4e5d8b25f3b74fc053151610b4263725fe51423e886bed19c534165b4cc90fbd67256839b9371290af9853c948251c768e157041ac91fe6649bd1b1855dc417624b8ca0d798b1947c720b3414db56f01500fba30207322ede05612bb6505818a9a68538c9eb98f2b0a83dd38b765891f0d01f1db768d2355fc6b7a47414527c92ba104637072a72a6c0ce74772664e68660c9c0c28347315b17273a6846a79904a04b90a60c5b15973630209d9460365529bb72524404b3d9cacc013b0a7355a7eb2172d317cd356a07e5a341bab7c33db5a48fca4b1600443df6bf441983cc05125f6aa94f114a8c3ccea3f9c498c1126c072f27e97555456114f6bb3244c4698c3f6091864274a16bd82aaf0711eb8c4fd86a11b35b3b8b0528cefc253d7906b6b05382e37428253ebda5b48b6a068354381b24348dec73c279010bd32e41431d139a021a398f0e5c7fc1a98863f069b9d42a96b029455670caa89e0b867781f73fb7549392124485cb032a008d63812f832cab899a8d5d24b403e76d17d6ccb56c729e15abb2e04e32928c9b8971be6a4c70b15bee620eef375489347df7c622d9a803a86c2a9ec5a7a0554ff763912bcb7f57eb8b8633cf6ef39556162eadf8c285b61a53f4837c8c9ef48c3a58b3b6c31b8227c98df0b9057d452df2c258da8a1de1b99449c0054c48a0bc61a2336323367077cee252d366661904b12ea6215b3ba55aab06f60a517704a4046312731325df563cbed805e2c7b2a5848fa1cb97e17a2f926664c2947a2fdb56ed1b3c5e084a680073669b2b9e888ee010410acba461910795958e7c0c98294865cc700315e86a5c54912dc2affc2469244912d8180eab244332a00b7536c4cab62345872dc31ca3c0d2078d07beda4431f278aeaf2482cde53afc56352a894dfe3948fc14956917a4dc836f54369eacd4af052b4aa6b60af5e86bc868be275abd1118a83e5acfdcd4c92a3c2e2b13cce7101a9d303339f0b2dd4a282499579b803ede0b26c75eb8af340000000000000000000000000000000000000000000000000000005781f74024912ac52aead1be2a87e042830737220659467bd06128a096343d5fc975767ff083234b2979bb109a24a27bca17d170abd8d9e6ad3c3ba19e306bce Input = 5ab063c95a541d1be3fa0744e0db7e0ece17b6b47cca0fa41d08e7969fe87de63f319f80b9a31ff01e203de6e518e62e6133edd108e5a3e08d3f8ae0556cfd36b399dc1ebf3b229bc5013d06d7550512280bad2b27657d3ca0679d9fc62f0bf875dd0b326008a89b4f29e97211ee7ec75108a9e4a320a34daed15fd7ad394a1747e4e35bbe4f1118703c330aea81bef3e3883fd41c3efc3423ab46b553c7587894ad64db57bb0fe4d289d54c8ba78d40683bdf6330ccecbacd3f7f41541f1f2b1a7626d3969df6586b4214c02f921451f6adc04f5e8de1e3beda82e4aebc5e06abb33f4cd8a3b3b5741617b6a385739133cf5b77dd5607a5c8721d5b51c6c0b6df551a5b440082093f49f31910a04e4226b9ae6f41383672e0694bc4075207034e39c40668aa3174cfc8a75fb1a474485e9aff01f3572a5c7e4914e7519344c8ce7b81377d8c2af66bebc558359601b21beb984c1f00564d46585b4bf02c958c6b348642be25119b12f34a6e5755588f649837ba53c0efaa4c6c95d109a4ce1f761c1dcecb84cce8376cb1c4e34ff932408ccd2d06f20c5397f6277bf9c3234b20cedd45afecb7e87793d85af15909546c6ee41987f36d85865c8c1e281e13d9575abb9a9f215c08d89420535f73643dc584707deb7d5275252e862393fb6493f9e126c651b7981f26af8daf978153fa4476d615183bf147629fe36de7cceaa670dab930ba8a684b0bee24b55961ea556123b34e29491704d2122e46bed0f6fd50601e13a5d46c907b915f3b8e695e0bbf474aab6e082d156e79e59572731b48338892f2268dcbb8fc21cfd537979278ceb210fe3efd052365fa249c97e8e596ae6225839e5b8b296770f3b42240b8727a0a730534d0f42f8c6ef148fc04e4285e1aecf060c3666fc17a1ff794f584b26b0b1c41f0fcca249935cd411a151932b09402016a99832850b3f56c4846145738f709f5e11e28a90d9137e4e43f03dd1ddb6565c67c2a138aca59e8aebcfa61984bc7ac13a60ddd2c1f0fa84fcf9264ad5049c888b9f555e024f0fa685474e083025da168e3b9c4ad91f074e7e711f84bb808604114e09d1ceb83b697cc0f045b5089b0bf7381ff2efc08e7316ddb7eb7be47a1d82cf533ea898e668f0da124d2e87fef2b558f877b50b13a08641c74e2726b19fa7c0f33ab213f403c328ea60d08c07155ca0c19bb75f7f6716de89e34c20f9d15ba8aebcb98e9b6461477f56f9c65ea7e8744a4d7306e216f806ea8f9f1dc45781c1adba44319031fb9e81c6d33bb317d959bc53a677270f13d96da19833965aea9a18172f6f975bc4d03036b1239e7c315ecacec35cc0f788be1220c0497844fe7c989fff5ef7fcdf89c261a0fed3915cbfae94b1fba22827daaaaa0f968f1ac71e9772aed587d607d5d3f57c1500b6e08760e0b971c1999d01553bf87f55fbad96ce61d0750d75180623543f40e5b0cee74bb429edbed1b4c2a3e1aab86c8dc7381afb0b9e7d4151a3f76b7dec4199b97304d7b3845788e19126e Output = b4b4634ad37852e19175ccfb5eca50093291da8f76b86be7511379188bc20d92 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 EncodedPrivateKey = 078bc69561af0cc77acc291fcb063e1d7c82bdd7cc31d5b44d1aa746e261f2a592d4aa9165c2c3755aa457b886cdd55840767f4fa0b19e45410872cb1db3b8b5829c4ce9b2a8969330cb5bba2397119310fa072b7053b35fb135d04977b9ab4766c4c1ecd9695957473f10c679d71d2f6b57db2ab0726022bfeb10b61807d35447a141255bf5b3d0e3bbf5cc3ae74932d87268e172978d78b99daabcb16b44bd578f6dac130c2528fbc89ffa94b48e6785293023e2605a8533a5ac17c15f34b1e30501729a78d3b8ac6e4a329e1006e0c0735c737283856d7cc7663cdaa1610b1045b7423ca8ccb59ca6b1c482dc02ba117c17588809ef8506f09a7162720142e397c6ac0f8fdb02e4c1c557050af941ae8165ae01d9228f767ef1ac3d72f27cf9a2282a6c379a669d01cc0a6c560b21169557b88771008dad62641f435e0780234e86c1ead05f14c0ad68b6b1041492a166bc4a278b0d352129556d55f37ef8969b596c5e41f8597878c8c6c83de675019c022314215eac667a7b559146478a4a5634ff193f6b83673072643efa59c27650fec168ff17109577083bfa8493f38301528f27681405693345e523ea4398055606d4ccad9df967fe59428ca7502f046506756a6b9a78182383db4baf05014fbb20afaf148456126fa393abfc480edc92465d93aaa158c2a8493882b24c564b607cccb2c8f6cbb43abd722c74c2c63230946acc091c48b865cdb33edb712c670648b07c06691687685218ba48648fa3054ae7a6a663aca6aa4e66506516100c8f2caf9c0645f2554c10c480e798b9c96756e42cc8a7f626c2759d21555342548e0490420df3a8124b0566b1804933b68225359cf66caa599c55573b70d488d16185496216cc09090de382d570795efa569aa5bfa8f4a60665cd30d63bb36cc5ac050310ba9bbe4b3af2f9400296bd344cb72bb623c757366ef1369c968578eba52a092dfef34aadf552a63b1495a5b78168cf6e58b218a3ae64310d16734d5e72b2036bcc001ca07533085548809bf114a092225aec9cce6950a953773ee37ad3467bd5ea0b4cc4c6b0695a774781ce17004cd48e36116776db19565367c92a94488ccbf4ca3c3960524d1b13d6f77399ac625de5a2d09954cf867011f79bb4c3682cd40f133a9d67778a24d7cf1a5b71b7b81dfe335d0fc392a8b12b234950ab79cac94776ad1b713e99b0f394aedce739a15334f19042f4861e739c839ce07da145808260b159625b5a742258779440953c743c591659b9d982aa7da028c7eac4390b47b243ba23e8ae4fd9c98042a0c2d25a6688c9ec774cd7e95899fb7f081035b0c4217c2903688ca7e4466e66ac4e3ca938fd58b4d6bb732a36aa8e097fd75976d1200d61a5c988c12702698b1cfcbd93157d3d1c6e76d316b00b4e462588bbf3c480d8374df3cf66a16f9dd2ab721954e02a9f8eea4380c381da230f10c2c7dec02b057177e157cbd5304ab1d8160a323fd5892fe1649c2e270dbd3777035912dc0802f4d18a56356b52946f30c516838028f7f39cc22466ed277a5adb6864972e1063b1af0709dfd60136b16a3d6c863a68895677c488eb1d879a69a5341a695212066ab848609cbe3317b0abba905c1559715f25f720b7b745a52332355154e60577e598c754b6346b335b0195ac305268bae78bb4617807ca4666738ca81515bb041d43a4188003c52ac4ae4b3808d8c755d3e99d00537249d39d4cc02ed9f98ed4106895666c47538f79e30f5104adab1540a1fc58d1a857a1a4611257be37e0327491aa4b543aa6322ef7816a5c9a55eb3bc8604b15540b62c3405b861a84218211c20bc3d35a8a506b0153306fa98b9488a7841d85197c170f84c380098077e42cafdf1913df369f37f3291ec47289710c57f152b74572c23324f83618fd281f5e41976e77097a570a991b3bc623ad6331a1bb34673b1c328319758ed731ca2981b50a5a2cf8c66d31b10e88c95ffc27c3b6aabe8b207e6cb4373464b1b83f4a5a9806449bf7fb622360bf9f098b56729c5738191d57492b377ca8f989a87922a7368d724b07b7e36133620fa0735d60f5be8b51c19ed1655de5108681cb27273d511c643b7867516c2982a74f62e4cb759bb1f5f0808cc90e1baab60365722293bb07841803076504d00e6fbaae853749fc322e3458810ea41d832b35bf05a10e62a4ff8317b506b9af7216c445663c9061cc62914b0b72b5989d7d9c2b761c2fc5a28b5839bee5596c0de25c10a15776447e17770edb666249a2310962152059c5ed5738741a29e899072427891fb53606ab8b5dd06c005d239adb7bc368b10b74508c45c4aca726fe59c7729cc1ad617236e1b75c760e47815df33297c084429ca371c16c5761c9a23ebbcc2cb43ae9734ba9495d5a86a89e75aef50b9e73470d8d9974cf27a961c0cb2c180ff36140818b005f05afaabc86d8b8bf5c2a62f0632ebeca0c9c567514c9311ba6216fb13f1603c77656cced520d977ac75031044c8790d1b4c97dd38b2aa43dd8808a79e406f8e01503db8f7b51cc1e4265ee830461f41cec398251ea60d2c573ec59b4d28b09dc9446bb972f6d134e2e192e987153b39538e1f631bd81b2e65c2c5c68a96d1b78360889efa4c692b7cc374160e8dc485f47a676d77706e047d3e717386bb49cd942e4c05374b3a1cca148535a3ff1085102f4a7077b5f9c7b1a9ed651edb32691037f9388b672a662bc247beed215d51b414d3530c6b0631999663fd7c0e5da7e411c32c506476fd08a09d499ba3c27bbf6a804cc7e8be5c1f3f97d7aac085dbb3bd1076a69db89bc990efe59b00ca943ef8560642176e926af342b48e8002f6d1aa99b58cd013b03e0d285455786b54a4be3c581419730081361c04697b1b2c07df068621213c8ca6554b5982d5a1aaa113ed9343a56101aec68b838a37ef2c8a15d0504c672b278556b40c766c2066ac995caa32676da182545773881545cd58b71d3d7a02a209bc7407f420a830513b9d9d6c93c56571e42c8bf154afa060667a46d13cc542429c9d1a35be012cd3c9abc2bb7484fc89a4a83a20f7c2bb088793dab732ff370cbab614aa851fb77ce176b8f806c4f2e6068235b93d08c39e96badb37a457e8a790b2b8ef00b0b9e941592373fd2caa3ec3477c6c440d0daa755ac0ad2285754ac64b0852086112b0c9794f1657916fc173209a40425afc9b19946c529ca95154f24ca3cda5f9547c429836c377123c6ec0000000000000000000000000000000000000000000000000000006f8e54b993cf2cd10ba4e61693d9aad8943af37178908ab532712df5dec4b908d48790195fff2c19f221b7cd8637576cec18c29a4a51cd07c82eed4974c36e8c Input = 925fde875ae198cfea88c4eeb3a0091897e25a793672df1de3f24ab4fd3edb2cad0b07e698f35dc97bfd1d551fcace3282c8c3d8131857d96ee9986da7b79a02ddc6cfc9fb7f2b809a8e5511b1c1256dbab33e7606d8a5fc048b36f6ee53c7f556efadf94494595a549ca260ac9c45bf9962bf406610ca58dc286a9eeccc447a767b6db3ab009f5848558acea4503de747d72d43218babd6f68c091b4581f4e41f2e850047f5f543a02407e7331202b0eac7bed180061bb53f4dd3504ccbd3f298d96b43bbaf8f0c2545be54c59830e1f343ca88bb9c6812c66bfbb59a6d68298985767a73d34fa69b52cea98d95d8305f97c4d4fd643b56c60fe31e3c2ee7e938ac2e4a5da2297e670931c1dea5fcbe9cf118c62a76a461495f10f640fb416ff7bc2478c0e8a1356bb840345f3d43476bc4cd990eb7f7cde7ccb96452d055397ee402be2ce395a29a4f4061ec3d85b99f086341441022435b636028a1a04c5d787abe1c24a5a55653b7063b1cacdaee40ae0de77b4034b9ac0e860a90c8834b352c71e353c02b1f46b135fa68fa7a5c1c719896987d79f3174b8d0b0c28ed64cf9f2907924497e35bf519d519a9199a4dd68025992c6f466604bb2ec3d7b13eba76e4803fb73bb125b83413998ae86691a0b35c0054e1418898f435ab26cc12a12fd4dcfa9e80887af7ebb6c856a7fc010cfcaef9e1c5a4dc24a91a622fb7307521faff0b8e8e966b7b6ae849ccc75d31c8d700a3b6a9c3f646b2a88d1e9391c2ddc6c9ff15db961874c87dd94bf0165cfc8f719806539a8beb8e28350610461b1252872f0f3ac273b3366abd78d9fe8868dca1a5eecb683ab8b50ced8cf4a5ed3b721e0fe6b205fb191985ca745ff5dae0010493f8296b6586e1c96f7f23fcb4ac4dda15eab811107c977aa0a16439b06986a9027640cf7a01051934dfc758215d22c6f06866d5b871dfdb6ed240a73dfde43f7f89c0ce6909b54b0a633a25f7253c10906166f81ae91a1419028d6182c1f277dc7872b824c7a5a22bc7afc02afeaa9ba4c271ee68882397e6cec34a955cfc672f4e6f5ed870a35ebce97f34542cf0a162938c91922230ee3fe9ed9a166a790ccf450b80cb5f483c3c6ae5b2e52e907824b45e69e5ab38226cbd6519de995e1a62a910fd45ed189540e0b4058ff01edbc6ba4eebd58d55c0e33702de299eb53d6518254b8471f282779533eaaef90602e52373be8b519c56a2f6fac0953c0f84135715c5674e45d15804fb94d9e0525ab493aa625fbf73ebdf74f0a1246e1eb0e4e2e261b24ab81d8da6e1770634c747542450cf0a2af23507f8b6766a16dbb2e67b2c94859228b91eec6c59f5a271902b340320412ae947398ad102073f8b9b8c021f81f786622c3483e61f812aa76232e6f9453eae044c5e918e6e4e0e18a78efaf6cb36f7b75929d0036c44edf928d6efe1ddc87b96288c7c624655d302b98865978ed7bc779c800e6113a0484dd225aef29796c8ba300b3f48dd566fd877dfeb5d25f96da5d07e643c5d Output = d4b9a0f77a52d4f8b9c95951257348d1931725c27eede694ecc09204a931daf7 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 EncodedPrivateKey = cc4a14e75a6b1bf87f11a240424645dee23657db9819ac274780c2d7d8ac64f2cb82530b40a078791a2ae70aba868253bdc3045b6254c4e29024894cd13723edc7461a37403609b48f79b8e8b1018981bca9f68031dcaf87528a6b065d8cb83c142ba20d68a728a3866ca88e6836cab209ab49bb234312916e432fa51152c763a62cc53da61480691b07a073be74aa6c2b88468bca8302a23d1d6405ddf4aec2f88ab055b18e2b1873862af6539ca83b1c270b6a563cbc7a220cdc8106e6e5595d63a26c0cb86ff11b48066721634b43b361b57a5b4ddb2967d232d34cb750026b362cbd20188260c6a856e9493ae09c462bc4c8663c7903112488b06b2a996dc6668e382e9cdc93e52a1a368b07d8388c9531afff0cc4c07ab423bac717dcc888e213e3a75d69a633f49745bab10f62592f59d53ef19b6a62f0b24216aaed9c91203b7ee65b9d097cc1e2676deeeb576ceb4fa4a867ab7310076a912a41292c658e8f75a98603612558352a5b7beb404fd2bb6de18c7ac838464b6399182536509624e1e25a7821b71edc57c35541cd115ec52c13a739c3de231ada741274272383cc78bc9869d37282f5980209543c92b76ddf99c3d45cb7409b5e44599b75412d8bd122460905c250a94dd4052c0b0a91c9a906aa3652180fba9212046b4f7ad14f7c304780d553f19487b8b7413de732ba1296b41a2d94983d4be93e540a4a4137a030629e97fa640c21ba5b7b5537a03a2a958ec3a888590a5c14a904dd74c83631264644cc6689a245f833530124f7d10e2596a8be227f270941faa75300bd731c145f781cce52247418595ef67c94a170676cda269e51c7ddbc63b6765b010aa061cc576696c84345c35c491d3e4626efc8b73dfcb481c11bbf8c79c6a3aa4e54c43a44141f5c35932486320567ce37adaf5241bfd8c44ec140d30823b58223b02742f3e2bf5864756d528ea36348c1c2293d8ca050b6307d71a20a036e0060697b58a0ada53eee5a6990a9cfe283436cd36a02dcb1a2b7200a267c3f133ea6423bc001baeca953515214e2766f066cae531212dd3551e22bbb1c705f21753ab60a70f364bf1949901d9a0415a36567614c1aba2dacf2c5435b4ee66193c5e461596719790aa792d5a09ac474343509ee36ca048751bd4b0c644b2b039b1320b2294df814b419c3ac55541be5cf4b93593aa4c099142de9e13699a40709d70070aba9227b6c14f216d434c9bc16112b8b4237f838340a5c317a618a91170709bae6a7c13cf96851f72a8761736c452df27758afa4b02fd55b3493b1bbf96dfc45ac743718978b7de8a017eca45dea633dbc417f856781c856c87516429127c6a3d335f162ace0982235ac79ba0ba68edbc1eafb9ed7a3597ca7a612a9bf3ef2b0d1d7c238e98714a434b8b08b35e3885e007501f9bc06e841921521d47999db3ac3937468a54b95b57a2bbe34aeb48ba57f0744021bc684456a8ed413b9192057eb77a5502dbc89c5964c0383b4c9034396da209279199ab5830abe9386b2e811c222a6ccb0cb23732a95676fd5c0376505943ef8bd67a95defe0af7cac395a743bdc3119b1a74771343bad21c53ec80cafd7548ae310293027d62960038c5d80656805b427d0b9167abb3697444af88a0f3eb48bf658be44f36b01233902291860215084ec7bb3e170e517c65c623ecf4a488f69923f9045ea18334d5c8ee847381b5a8903a6233796b1def36e46d343cd3547f4a757d82c262278432bd555fb5430e7f936affb453ac1a031c70cb1b3a8f3762dbe226461501d13d10052fb621be30b8ce63ce93591979863816397f0d198a6c534b55213d778ae7bb1a20ef1809ec37b08382c43e82b4a758458d7758d23a350538b3e524d27c9074d1cc4e3e1a17a6b06fd71178c5b18803b1c439b9e903a0d63018d2f765fa7426a0684793ea789c30435657b9aed58886cb8788e14426ea0295da18293024eb1a39eb99a20619a3e2db48a93eb90dbf42b84fbcec1f0b9571946b6f150ef5a672686a30e52be2d536bf3664550f60c99a89b81f3c911784d8a371ebea0b97ff50e2af68f822a72e9a76cf473bcc1cb81fe2a03051771b1c91f1e1a444ab6119c0a83b25a434fd598bc767315881aef9cb4d4c51ceadbb3b1a1142e0b87d5826b161233ce253d2adc9a00bd00e3cc21fff09abd919b54e09ba6b505601a358e50593dfa117eb2b8d7458745a25e7c7321cda0c432aa5bb41aab60eb3dc7e03ce4017b245809a534c3dfa49e97f4474689901e814a97fc0892ca04d0c00e3dfc836b36bbf74256e77525a031160fb3bf8ac31502c049d0a264140104c7488e36a46d23a76f4535b5902677cb98a5abec57b9357b0cb3b36b68349b273a2f8396e6c8594b4a32f0aa8a622378b3ca0426f44443942c02162907b2651ac2168fd1279b040192716bb584211df4ba36cb363b8c3adc39b410977ae3cac26c21470426837a43b821f65d8ee1950c87b4765a034aba1a35579f4148b8c2f39949812cf9d850d5e25be7713ce62ba31366737c03ad45f23e9b226d1835c5ab01c081063dc193630d72821cfa2a56d16108c40ffc483177d075b6a7a1bbf5cac7da0834d755acd10b9b9850a7c97d90a1061ce94efa4b0c0707339dbc7f160a45eeec022815a4494334254c08ade388c07c34e3a07e51ea60fdeb9b20b4b9afdc6c3c2b63e872aac9b2a90b798bc2dc8d585c69c1b33c1d51372c583e835b9ed561c218a2968c044051f8a969a7b2db6a7031d20cc9e024bbaab4385a3ae13ca264c25f6c5b4170b5c0da13044664a10f335ae9045bd6319abe139bb2b8b635bb06e2f48427e256a16a0f71f119230a9acfb19f0fe07c71828063f42a844a5c703aab9a844f689944ead511d8c97127d99429fc87ede190e0fa002261494076b7a10496dbe12919f585685733ae780eab3ac168287aae3842cfb637a94483f68170f6a3092d51b82ef10496a6374572a527aa7a7d1a99315953f625842ec0bc8851180b98cbe411453027c9b8a4a07fc3bbe32b897fc09e5e65a0457556a8b28e5b7c8b28db24e5431893953c912c195ca52db5d125c3f595f2ea75a63b6c83c8cbca257824ac60ce16bb5be02b30488974a22a66d37b19531e3cf17b59bb43d738cea25326dbd6355243ceff3caae98446927351ff623260472f8c7a715016ca5480af5cecc001c6b65f41221b16bfa61863e225709775b5e6393e4b71920c0c539c6bc5ec5c609466000000000000000000000000000000000000000000000000000000313af29c47d66acaecdafe1b91b95ddce43b0cd52be1d1a84428587728f01522a9e4a0d3487b6714e18bcc9d1daeb3127164328a19d5cf60822f3fd37a24bbed Input = 7c06bbeca8b58423e2ad420ec36064ed42c881e3655668f8865a2d643ecd1a4eecf915b6c64b37c98947f06c3ccc8e00bbd16017c246db88cc83f12c887aaad7db61b4d567c285841689169c3f928f1d178a0ddae50d8c46cfd95258667d6239c300595738defd2e806637ca46baa4c6c7b97f1a9b47d53cba9ffe074f88d104c4971d250d085b1800fcbd91584d8cc48e145fc81438290d74765e7ee8c1605e8048b37b9d22b050791fe008b9b84b7f23b0f49955e32c0eef78d7a3a0b2effe8b37d124e19d4cb6f6914204598a525239d9baa116e1c9c39c47f9f37f965941b2aef8519782c65f3ad3a6509d1e31e7efb67db21911e4edeb1f7e9c37b3f852c81d63a95e4775e3f2a8ff315a214680adf44d290e42ebab8ca95bf471140b9d7e03f5e9f97864289a0ae8c9a105e00409f714e413b69be366303b4a138ed51264ab0e5cca5f6dc9387c6608109e8859893efa3bc7384e9f418468b1078807dadb768e254094039d1b807d67353c8e0b5a03d28b8e41ffa0eb3ce0837a132144597908f7a059a097b79a1bac323757324e907b445d064e25c378d2069e7c5d671036871e4fe36705747635e40c6e835319e3ff81714cacc44515d671b703c5581dc76afca0b881f37c1ffc93f2e4afab1e8ac776ca883f3adf7f9ab99396f7e19541c26342a7d5618958523b81871326c357ad84ccc6d3574d97cbd875524e7b08a102263d80f318a48e510c22126568f76936c904c231700ad042d73137eec741c827a082de4a45d296745c55b8367719dd08b8295e38d8d3894b9f8e2f9b483b266e1fc71d6374353ca7d9ed1c6b73ab5a42f6abff7b2ba8fd484d1ae6928b5ea92ea3577be01dc1e88abcd0886eb771dca4d36e91c45bca4807c89736b7d6a927cf64b22c5f323077f5488f6044976f310b4b99f7d486335dcca60571157ac0e480a4dba79a826b4bac3dcb7327a33b16381eb41e1d39915e91a58750ceb71098ec7f1a2d7e44d4bab75bb7482eec277df206502c497eaa345109a145a4da6bed1900b680ad12fb028d33563bfb204ecf66e6ead587c5fe27f8a2eb0e27471925ea0f35eb9d5e53ef801eba3acaaa7790b105eb6128ace992668181c1d7cf203afdccdfefbac67dbd97cad05d499239df84e4cf7372117932c973957e5c70a8520f822be430758990296877df62069d818768513d14df0568be8e63e123bdde35036dcc69a98197f52dfbaae5e5e0cee4a48c67fdda605dad8a27651625c2b35e81dfcacd2a41a6d17f6d7067a67faf2479b3868673b248270f4a2d8ee26de9c787ce966ecf186c1401ad9d3bbf2c43b1d5de32bdd77f5433f4325427254a13985d733ab0863e62a4f3d484ab3f5d3b88f23049079143b058babffc8367cebdd9d2468d7af782979a3ef12841370da6ef2db03679e6bca0db72166c361adfbfc02234119abaf98d4fea8ddc6e8490c2fb5a1be4806a61bc7b36884cf4631cfd53138a23fdda11e597aed323748314282672473a1819ef2b9488f6744544ad Output = c9d0cf3edb1172344364afec3615ba98477ce9316f92ca46ca5f42b73553a9f5 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 EncodedPrivateKey = cca22002e0b84e0c0fa98c902c2a30f0d9303a411db91a26576834d4f1645c181bba750c42ab6bcf401739f83fe2a4a3aa1a3f5917418003aed863875fc044dbc99c70b27758389fdd3cce51d5a13b21afe1219f0bab5dc3b15952591e6f80068b30870ed644de082476e7b32d3a531ff8631914c7a5c106a5acbf8672ab4a304afb71b1672cb281438f0fdb1db0f52948e8b0a1422ba10ac5e0a480e87bb844072e7a134dcce36f27274775fc6a8bc611b2a33cf85a4820e18b47b24188030fcaaba998d84a68424c07f4503abb553ec33b4be2af3557aae2797649da014dd0264d00ce74431e46f8969276b24b359c6750c5bc15a6318c2d06898ec5f473380a68302a91eb562fe4f10596012e5efa83f4c55a19912978a6583e4a884e36af1b9367e69ab0566c3cd8c34eaea615f49c094bcbc63d52a21d74c02462cb0bb7c77cbaa03df988b60cba880771a7c179315a9f6ebc6e9b8c90bbf17f737508b1691ef1952363e9499b5007a9c84838c2a149478e4be76c0368a8220b9a3ac68ef6560dba6b3f68257b6719551d83c38f73654fb392af0c1c2517851fc160c343cf826aca2c5614726c774c758e1abaa9ac04ae0742799060970909cbc2f78ca739c71bf6528f0695ea6175a4ac13555c3bcb9920bca3a37d363ba622666e54a4e779cad5059612792d610257a689975fd664dc5081d5ac4586c60e99b9a2a17ac612e5a794ca4dc097a71f72bce02b4907d69d801a22fd7b88f9e4ab284076037a0f6ac803bd7b243b835e51873919d3b77de041bbdb9c2917338f0c42a54ba6f5539d60e827387a9e7c156155d693b85701b53278139b29858785cb59788ed981d77556d27390285bc3f9408cbdc717895815d31641d0c31f2d911515f36743c40f4f3517432c620892149b518fecc80cd2d14c99730e0c940dec155930dcb5ef861b7c80b55c2223f7066b625c9fe5f0cb04f0bcb880119de142ce511affc01d483ac8db8b73e504b242315533d9c02cb64d15445fe32bb0c8e19383f82854981a9ea465b05c77cfd66d97a2b262bb37398cb4654a0fc8146c00b7608f061a216b9becec17f686b93d88309a7ac04c2447030b41ebc6a95fc52466d36dfd461bb046172f3b83fd10bf79c281202a60aed8467748a986100b97742c8d70c8de523c1d700489c391096c1b92654064cb7e35d7b25f29818ff39fa523c88bd69b8cf41689a414288c492f2a83f7b34a4d95770e6144b7731057c73a077a471e7b378fa48464c426ce5a6566e7c862131ebd5a1b3df013641a878fd702d167ae3f369361666514d98f325679c22aaddb56406e148e744960ee1395866acbe095542a6836571959a80238d037260fa053a52cbbc2cbc035e78fa9c306ebcb61ce33422584009271835ac3845524794f18bd7e1b4c034832fe68ba24a162815404f65c0af0944c9789b1d92767268c801a0444fff50399b3a192131e965523bbc2c75c286c96450c3f0733458bad7831205b1b4841a617626b4bee232cd1f220edf53b59bc213a055d956591fc3518a1974582f79a66dc8892ba71ccf7a5fae1c01841428525c32dd2b433445118559cb5447e3c851a0cb498cf99c2d359999fa3967dd722a23522b0d8cb522a67d63a75af305c05f3659bc496f1c47e410582a0e58bbba80751bb2f5ab71414051627f46a78f9708e3139f8950b999378df4709a08b9b511982ab1b2cc4d51d177578ef263c8e12752f914733023d9e8068d4fc1aac34106fa72197f6b4e4bb26ab29ab64d7c848f98ef5557ec2b35edea70b67c084193921d8cb52e132a24372be7046aa2af66696007e2e0830df1c7b4396bcc8f27aca46932c463b49db0ed88882f3a45901a4b96ee3b74e78afb8dbae7bc653be895179f208c27c6ecd60c26e54152aecbc13bb5ece39840574c56fb39fd2385c76d62c59a41b3311702d5a99e366467b6c4f6c252a95db32e5096e61d1ba872924d358b346dc099a485c3df72a94e437a82a6cd778888995c473c203e091309ba42511950c19db3acbc5987259bea952b5a549839f197d7bf64ca0772cc1dc89572a0e04690fe651a79ffb3dc07388c30c06711c6b25572bbc83ba868a379d54c6439754bcd67c9b0364ab3790967a062948084ab33a80ac5971fa99830aa7d1e9263e7087af67ab6a83ab34f405dbd72b3fe46e9f2114e26cc6643b6d3adb9de63090394213e72b64ecbb2242266139579ea9cab2e51868ef82ababaac38e7ca0b9554d665365dd8b0b58f3020cc9218b866955f54d9f7b9af9634ab995a0b5e234fcc78cd1594e1cb8a845ca0cdbc82e3fbb35414c53423b76875ab267a702d51710149061e7655a0168695053aa61b990fa9439883640e7600345033ca90678925b1d632962deaa0ef5642b870610be3387eda90cf608254dc2b000c06632331680e12e9b277597d07633a31f6445318ac7b9cc1b087cb58bddd30a07ea6e1b1429950b7e7efb1a6b88b037c92cf987c904268ce39cba4bd3c163f5a8bdb9698488152a18b02bc98a83fb6c28a55a018b48979660ad5b42281b8745a4bdcb02cabd16735ab1523916adcb031e34ccbf4c50bf61bb7d562804d4104d3f6ac183f447e6608acb0bc40a34ada4897e9a91c542571877931864b612cec01c88010cbe039d42540835422f5900c944c7025ba3365543536d093a68c27abe1175bc227faa590f8fb8ca9ab1a87366574422379fd8659fe5bb5ec76e179666adebcedc7b54f1aa9388b2907a4ba5c48441ad90499c64a57768631d4a961d88976c816adb897da7715a100c75099cc122f3b1df183385673a3bbc98cbb0ccb0b090b3517993815e3f6b26b984bdda32c11947b2fa5411004c2c41f2a646036b86bba618e72be7f97ec6369af5ca2ab2dc9493d9078a0c8598841385205177c80a3be42a31d1166b02cd1dd2871148033c794242962e8645ae2e4867a3e5c74f71a1d978379ad45f7fa5c70066cbfc4cbfbe05cf23612b2dea551cc52dd90a8468ec771ff071371544e96400e288a82e9c9eefe807d6f4903ac567741abeaec9707533b38dd8c4366bb33cf86f77272478e43a2d8061293332c8d805a4516238d5ad1934a9683655674aa6b6d91610d4c82e966d74c41dfe7ac18e993c22d59b2d286a0b5272cd44988510b9b342405757a25731729e934c58c601f5c311a244a24dbcc772088a20dac4c8410167304fda18445f6c6126b9645d4042d6033419d246968848e1f5000000000000000000000000000000000000000000000000000000ed43f6cfc5464d2f56a817a3dc74b5ab404164947d8c0792f6bc9bc00bb4d20253f53a49ff45b0ae588d417a63a599670cd391c5e9885c972593d09350bd7523 Input = 83ea5ed982570cd981b7430de924469d4e2faba68e03261a74f5114ab8c448376cfcd1b9cb3e72bb031bf0fefe772bc40888abc6acffc1d335d46d267acde2cb89cf1b3c67a139796d6a5763805d5edcebb81070b44ffe021b6c2b3c6c3d5dfb6d9e546930223ab0139990c6c5d6257520fe394a3aa30c6a71d47f415ac86b68eb8c83b131a3c5cbf051971fef5ef3bda355d3868e71ed8a0e2c6de8a759bc0c9e760277cc2c04c783d29d1ad3d3385accb85cc88c39bc8348f84dd8c714c5feda50b0770414a333136d6678be6ccbc5df488bafdcade883fbb310c99cc648493aed72680fe1e43c0cf523d3dd06417d29dd97c98ce53089505d36a476c0ae6d89b165c3ff6b2c62ba954fb81ac5782ae648a6802bc057c64fabd3726559ba79de9c144aaa525f6a840ed55abf21b37231c6c4cbb0110fdbcd0004f6f4974ec644c33a8aea34ef4a0a146f7502650c3def5a313d2f309cb428880502d3bdf39196a99bee296f9231d87972efd1159d3cf59bea05f0d0373a0e218ee5e0528e1ac7132440980d1153b9423bb2e099d05fbc8241ec1f316bf0add575a69982f546e99c64457c12ac83951ad46a5f024f6a61c91b7d3853ba1fa41d5a95f6ca811610ba3f32addf011ea4091ef217cdd126ec5e45cc40ec6f1292602b16c02718419646370e5b2c7c55c1128fc5d6c767cc75248b79e2379d40f91a8617e8a3db43c42cabb5cd39a7a7969147f30344c4b03de7034b12d8a1c3639697c97c4483e4191ca0fa81d8659f40e31b899b4ef4610644b1314ab2ef14b8dd8dc0082826fe65dc17211572cb14fa376f1b1784a00033c8dcddc44d6a1128a200eea668b6516ba42585cbb2e2be2a42148120013d0a9378ed7c185071fa8fdc09102164c63a665fd09c08d34104c9abb64e394b2e2a00dd834f7c7f5de16f6c02906ae37acc923dd76e530c78f2143396bfc371d14e6c48bec072b6b4e18eeae967456beb3f897a06eae17de174cf09be1435e691350632c0b1eac69dd66549c1d980fb147fa295ca6f21b5dc398e63a7c4263c75b55c85b4f38fbd7cc0fad84aba90dda1f2c9ca88d88905602096162486dba1ed0a8caa6b897c99e25934152a35fd0d476de09fb211abf36565af3744f3fb737247f5d8f172fbf438ed04422a6b3e17bdfe2cb0f09a1d57f1f1a113a768697f23d61ab288f15abc760feb0f5c5d4d5c0b1c891d3dad6089a3b7e54516b8f9755d38430312cf17b21efeeecbfd2719b62480225b9b3ee8940b1f1784ed5630d152635a1233acdd16e5489a9a15eafa7bec99aff25b18d9cac1e726c9e424773a7083f213cea53dcd310b0037aecbde1d584657f32cf548a6872c6f5a1a3a70d4db29ee3773291c94b00b5a596e1691f7752e246ca0960561cd233ec7d5f54496d34ba65b359a856315f02d16c990cdf3db2051b17bf283fed1b808ac79a9ce8250c806896bf75f2cfe76465c09360aba4c9688acea341fe755363abe41c0cba3ebad00c6c7bcc3f7ce091f87079f60094b92 Output = 4bb6a6b27596869efae3d411c69c593afff99b1a703ee1f4ff3e0e7e9756e75b -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 EncodedPrivateKey = 16997ff80976d1506b23c012e387ac6ca0a792f7481ac3c9775317ee3ca5267bc7180ca884d28bad6b5a05b045f33a9b975c6c98908d670550b874ca70a77424e48bf097256434b9d9b96c8b8149f02ba5bde9b813eb2b60f20da4440b4cfb05716bbfd86255a1e82941d2816caa7253e7368a4bbf4bf546f40b1bafc65bb994c34f7337e82818021797a431cfc664699bc22b92561fe3d1cd6306b89a36380920abbb466477549d1bf14364221c10f51fc3f7240de4c99b3bb3eeb9ac1fe12bb7c97888e8386da4a341a0be8f78a7b7c49f2184376c3c3784289a6bd9b6a03a110c228f72939b86c7a87dab3e093c0ade693a0e5331c48b761b070476f55cc45ba1dda14dfde01a011776143a4d29d48b47b0c6cd2111bf18360a7438f384a28d772177f648773b961a86637c946d7981a6b9f571a4c29aad07220fe081f1f18700f3c99ef28e76819f8d7c4c43d754cea21180c43357f3430bcbce1fe8952c691cfe9a7483026386a479eee4025a838df5c563b9f5a1882a2d7209a68d231ee82260a7eb4fc157936deab52618cba32772fa1440fb675220f4610d749a5b3b142f31b404d94d2bd816cc4773ec83aa1445a37b361e52b10960827e94171dce3c12cec80a1ec65aa6f117fe937673a78cd7767dadd3cebe0217f13c903ca25d6a681116b206acb46949b18f671a63fd2581a6c0978738460cc51df3711dc1215dcf75525d30559ab6bc52e16fa513753454888189348f045aee8a32e98cb2dfd708e7d42818115e5c61711a0c43e85a13657aadc24b5b30a04a43cb97bafa433204c18536337758c0db6154d4fac670fa3af148b52f24aa731c31f98464ca9bc975e97fd665710ee2c56b024fb8d7c7f4a20cc9d510f8eac38f96129c97b17c890417a21465d05abca02754ac3614e964f1a24393d05ccf5cb9500852cc9231656ca899f3538df30984475209f84ae8b99983e844b06ba4cd8a9640a513cee439ae13ad57d3846aea4fa165b68c6c03c05c835bcc5a63d45cc5568aef94ae7798bf29aa7f38e275c902236e63872a274e4776cf1928c492036166d04eed9ca64aa16ebb4b11fc3ba802c6b249e4b53f90112b587d36c6bfb0733a2ee3003419026a10a4c54c2be294b2031a48fe895c2c9920b3772f127338a865a82c3262dabac113c235d433b90d401f5557bb1bc68359020f75742c2008c2bc8862416910f53772a55376ef05a5eca853eb1ba5ef841f243b8d98b11e94483ad7e72fd7360a3641159e481ca50971a6e8aee73a0d4f24b25430ccc0997c631308fe2aaefcf79af5d2045932043d95933919b21ef87865b8550742a513d67af756c5958465f582983a777e9032ac43164e552358861a0ebc458e55865fc3545fd01b0e7565877ed3229f8267369c319abbb017a87ca662c635519ff418682af39ba387aa38ec37396b4d6ab505219314f4448d0f572f4330cf33fa1369872649c922bcd228c294b3213a216e59752072b8e026700ea63061855be3d6037c0cabe0c21f5be948ee4b18dd935ad358a5885a0331db2e496995bd47c3ff2b679e0abafc02804b6117271a2b00e33bc06250fb30ae2036716d30a50aa07e45f244e1f0100d749359b479b444b510d9b6d89b7001b237f4a34c57509f69208c7e6b956144bedc8b2d19b12c1baa725dd106f5418ed943370050808ed2636fa634add059541a7a8c7976b0990e59c20c00343d1c37bc3ab587e312991bb88a74227651b340346c58bbb174ac18c204f37445681bc5905354d834f86016d0921219fb467d829daf24901815666d664b8c4aae307485cb95885b7cb9125a14d4d988d3a42c0816ba7ef14de9b622e08871988b8c02d857626b65065551d5bcc81112384f979cd8d2b9ecb55c6afaa700e92e3ecbb285c01112a19cbdb90b8af135b235914c901e2314902a43c939d065481128f83ac801dc2fa69c912f2b69189736d72414df12646680c9c858a9afaa28b994531960b0f2b82fc6b9c6f10706930786ab5c6b0da61ae813cdb7387c27324499b111c6ca5767056070e608cf421af52cb45a842da82560dd86acf45a7e70245e0b535f7559a9fceb9369c44032c09302438cb4670925c7a831d52f083a7919e575be844d9e6a009957c15e6c5f84f050cc4801561876f9f483ded505b3c77a4a97788358801f012b59d716fed55975f8abd3464420d849d89c16dd2a95c372cf631a93a8897ddda2a038070adc2a97b5538778c0215cea399deb8279b2ade6c5ab84bbc8c6e181c091b7002a4d5f395bb60c817e03966b63ba76e88fb05b79d126ab0975c995b5bb2ae6550af78d80b96af40c9514f945d72b0c9602412242c81b60b2df97999fbbaec0404056195879535041231803aa7cf064b5fdfc8b86344d65eb30e52cc0d5b86947b8051ea93008d789914493b58abbd5395b657560f5823c387574db554118d06b26ba14b9660b4b390f8b828ba8a852870cba24a114a68094cf0168b721af8f0998e599b5db2135a3e9360b5754dd49155eea830f0035c2c116dbc9039cf69034c505ed998f8460a170eb5f09786d902664c8135ad77101d0b802248b6f3165a847b5c989131d7ee3135cbcb48b3cabfd100074c00f2e7bc85d4c84bec8980a6920e6f318a4bc805900b548fc7d98316c1b3c3b49f6c5d90595ff7a7b56465385620544aa3f39114e53581e851849726023d953b5df56b87be98854b253a39297f060449fc1c02725c3442a4ed8624f7f6abf3854cf04166b24c3b5a38358bae933ee4777df09720415314b152efc0b175b664c0c0a3521cac1817314d1e69fe03b351fe211c4c44639622a73a4547ef52d46b033aa52a79182baf49a8808fb259c048a04cc03f8a1038e9112eb30965c797f90c277b3549df4f757526351bd1a100767b4bcfa7489c17cb181b707986b9af85e766aa1f99b08aa2a7bc8a385d294277cb00d705b4ce2583e61c16be2b18445d051d7f0cee51703db3162bdd328cf0b0b24a424bd830c6574091088ab746a291c737e8cd595d1b51f9646c7813a8991f89c168489d1a3b61a82466d98ac9de55b4d5aa020243e638328fedbc93d341e1fdc7eb861bba3783a57c86a7184aaa7d5051b7018f3f18b40b69fd7780ae9609194db70123801729c561e973dff3a7ea5ba9045b24e5fe5bc63ea858c687184a8276612c80ab600cc37699583b9ffa8c5a1b7934f3c12873522dd1c4f976b73121bb79766803d247de1dff18807000000000000000000000000000000000000000000000000000000c69860913068eb936405db039e82a2f7fec48a8ea570bd538dc9741a6aaadb02e366c059f5f26e6dfba8db203c5b27beca8fedd3de2664f6bd5c3e2ac9fb3891 diff --git a/test/recipes/30-test_evp_data/evppkey_ml_kem_768_encap.txt b/test/recipes/30-test_evp_data/evppkey_ml_kem_768_encap.txt index 6901150bed..35fc017a35 100644 --- a/test/recipes/30-test_evp_data/evppkey_ml_kem_768_encap.txt +++ b/test/recipes/30-test_evp_data/evppkey_ml_kem_768_encap.txt @@ -2154,7 +2154,7 @@ EncodedPublicKey = c30b1c077bcd1dd852cdb9736289bb441013f7132a86664c31990bf601cff Ciphertext = bb7e0dca6eca3ef57e945d921c2f80875556f7786d6bcca1312f86b3bea6d0f0a73f7d6036a7c38c62d4e356961ec6a28d8026a2d915d9721ef815147fc09ca65a3394aa5dc14c08d41cbe932337b9a531ddf68df20b6aea297194ac398f15919830e3ee6c20145c0aae7a2cd276ccad7b5c414212f0c0ae7106333868938a6a00da19377d996c7796d400606007dff30fe554a5fef86944d43ba047a00da5c2c2a1aad053aeafcc75a1e826a417b4c320e60a68e63dd7b54827f5b8b0063a00043f29ce8975d95bd418eb2ed29db0d9263c67fdcc153ba9b5a33279becb7ab193c2f257bd660fd7012712be3fdc2e52490ade145e8e030ba1ee5368791e6f3efe00deb34cb454cbf7fdae3a507261d9fce66ab58998ca19380187e3455d425977a8396cee3442935e24347aed45fba9b323a289f1b98691e35017ecfd7a423cd8d0149432a2063e0786c2f912e1134ebed188511c905a1a9890cd55d496e8441ccf637b4d660d93c7a46c3e17219167c3b4740878ae35766470b5eff3c6b1fc8c30e5c9645a94ebd48d2d40fbd4baf9d822deb26c089da84043340a564e6c311bca18c7a2c868831fbb866d89652556b53297b9c0040e98a692fa536af4c9a7aa09321ca27068ca66c665b1121ee4529cb3e6d899964de759ab915b0d2c571c5aa76cd64df4a4e55d9de59eca7b4379b30f8559db41e804a18b8771f594b9bee3de9ae98a003430aac58c141e6f0b7b1e5e08e27d1127b682882be055ba31e280dbace7878ae60426626ea4c5bc034a9206e27f578edd17fa6c33180b649bc7bd437b2c86ef4e0f4583071f99090b95db1e415d21ddd88a910b1fd10e3a04e391d947558a6619683ae070be04cab88300614839503f088e2f04cc4a7d091af9833a4f957cfdc574b1c994673ea14dce6ad89adebf5130d266c1440b3f544eea380ba245e21651f1f2aeb2b3d578000a87683dec69ccac18b0702d3d030077981076766e7e5f3ae1174eaf21bf03662c6bda5fd209da19ff6792c0bbc5d210851061dcdd2e4794d2c3c0c531e92a2c4a23556878d3e890b65289a6a02530bbd40ed66db3bb220aeb71fcc3c0b5d5b3afc71377746b22ce636dba028bc052c219783d468fac1d4eed555c1b4676705c8d27aa8a09c6fd8640a6f7b6790ff173ac39b5f3c709281df4274cccdc1e3b690ac0a77f7ece34cdf3216d2b6058baf5f649ff5036360dff99334ff06a366785c0404c584f623801190082fe5cdf88f9cf41032681e8fd6b84d127add01d4b2286af648b83fe69aa8d109c9320bd40621cf75adff8603e3da00be36f03ed7925f19b2e913d756e952a9402cd4fbffc0428cd7eebdd7fc7d3b4cde181b16b26811cd53d9f5d85d37c1670b957d4b3d04fd06567ac68d3f9dbdd45d182619180cf9292e86f42bcc213e94900e0c759e051bc0e30ffbdb91a2493913dc8b81ba4c3e8ba0e7277dc38dc91eb2b27823dac71b6f1c47e2a04136e2c0474fe070e2e4bf8e6fc98e73143ead3c5f778ce8a4efde4 Output = 5b357f714a293b6724c0dc2e2c5509676782a9dddb050d88e6efa0a6d09d20b7 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 Entropy = adf510dc0e997af14f96e4863f316475be59850bc861ca0d1b057d6b94c3b5d6 @@ -2162,7 +2162,7 @@ EncodedPublicKey = d7dab73b47cd1ca43c7e036d41c94f8f31a0de404fa38a1da0992933d752a Ciphertext = 1a2dd390e05984bfc0f55ef96da5050fd9bb03891d4d2ddea46c463aab28fdfaf63d4b2e0c9af992e4f1421efc26ae86c2b296f6851bbe2e898b8bdf4057e875d4a98469b7d2646edb86a5eb5259341e0d14986a8ccf93563bc6ac067f8ff6997c2e7bbd897f02e844f180769fec5af9d6fa017022cb0af622b6e4f7a69d73ab01d3d09067b118d51805e1b6413b7a9e0ef292a6fca18a8828912a2db675f0244cd63d9340aa3ca00dc5d70c915b0061664b1e1d64d3d4dced3ef739302f1063442569efed0dfbe8c019c27823a3aabd865a47600ff9e24f748302bfca1bb60faf4105889a548be9ecaf266d8f02d3aa4997202477a70ee71b6e79dd1609acb4dabab72a38448758d8debf55369c5d3e0870ca193018e0ae6d0ffa33b93e962598b43e89d5978a9d55a608b98ceae5e897363f8a9e253acf8af560c57e07c4c4bde807620b6deb76d581bf92b7f514509446f5c4e4d09430b1855e62854988302c931b9e624644a636ab8acaec56d7673b26852c692e8325fa1b6215f24ebfb388ad1022fedc0bef272c87e10dca97df1e63f1a0e9582daae0f49e30c6acd119f7c4eef59d47443f491df846431cfbd23900341086a304589f52de1d862c26af32095e922b92650c68facfc13892430d428f626fba00cf9501e1e4646e55f5304c806b5acafe100084d7635702139725561522632e7e3871effe883298a7264a411484cdef78f9e721c0e5f3937f2fb7d40bb91620e473f9b97adddea69b3ac682e8aea2513b985fbae268176c1bff90e401a31e729fe8b76d13b5c8c85ed833d9b076b5e11acecbf0e96edcf8ff562255124edbeb5b9117cf486f30d7883aa353b9e433a77ac6912cc8e5093c12385ad926be1d0893afc7e64fb9ec55d3285e01a3ca63f3c07b95399bb4411c3f820f53d8350d1979ee9cc6bbf2d7c92d0cb2fd0a1de910d92589cf1aac29992489bc179676c31ae768869398fda50ff14860a1b4dd3bb2e4ba8b2c87aef7ee00d375956a62dc1e5d548a59f209448e62c4b1221631d4776dd5192154d637217d31feea1c4cb3ef1903b8987f4c184cf3d6b5355ad53c7bd3e0ae5373d9971115698214a93e12b98489cdd75028cf22c1da41096daca95854b35d8bbf7d0d4ca2727aa511eeb6cec5352ed487bd3b00b261cbabcfa9f082ba7300610c6f92725d532a86e00b2ed1929a8be7a342c079835a2285569dca92a808049f170fba39d990884ef39ca511aaf9a713b8d78973b4f4a2fde7ca8b6adbdc5a70241fe3ea7d005b33e48cc9fe6ce5bc2bae0746827e548332adf83f8aa707e703fd688c494136d8dfa50961a9e5b69b542ed6ae0e70ae159df95dd9d4789e284a675fe048585214047f7f6819f7f011141d265de9fd4c04f4ed5dead63fa4c8938b2f42108d263d5394d164b3254294402cbeb48663cf1ab2c296d6ada107e8aa5b505da49af96e1cebc6b302faa148216d38b9e8130cc654974ce299172cb875742e62c32c063ffe7535db2726f65fc8f600d4dbb1a20f Output = 54c35602dafe572b99aedb7069a59c4f7818c860b27a947347657ac1954d6454 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 Entropy = 3983da6a4615805f6d55c14ba582d59a40e646c7ae77f4835a51afc6c37f11f3 @@ -2170,7 +2170,7 @@ EncodedPublicKey = 47340db6d04313d3a689b357566b9743cace5d5b906a39249f1c2bcdf335f Ciphertext = bc07d2caff561b4645e3878d1de0730a88c05f46348526829a396f05a0a00603f0e2fc79e13beaacbe903827c20d9d687f3fb4eb2a8e9335459fb21380b8bf3734518778d8cfae9524ead1427c6a2dc379ddd2e985e2977bb63e932ed59c83a8b9a593e2adba0cc5f106620fc8c6c4cba5106bfdb4105def0c1d7b6800327cacb964e1d4ebbddfaa15b279115a1d05754c0c8a715fc2fe5aa09af7b96d5a93e758458aa5af8cba03b942f4d3c0fbbc2a45d3f7af5818d67219a72f4f538883ee2d3e507e2dbf4f7748446443bb71bfbb4eff0f57d8154d29f5cb26cfb52c51b676e9b1ac08786d5f475cbbfb49697a748b7902a83da49d285a48c7e9cae74b66a30b02a353a287b40a66a0663e7a71adab7d03272f2ec32d47097d4c303396db3e7b7a947f467a70646777cda227d72310806107b5dc16cfb36918e88784524e3a46c30242a40811593aa8f72c742f885a9623534753b2bac5e29110a1a854646abe1c0337251e85987aa612f3a095409a5a632af14acd19491577223c278b18a9c3ffa7f72ae49b89df6dc45ebb2803ece96cfa94ef9ef5b24fbe686ff90d130d3ae953a4f9ee6581a346b0612f84cb6ccad4fe94a53602817d67c61a9604d288319f5933f4a97dcc6ffc36cf14db593fe27f873be712186a6695d949d4552dab37e36e2e0ced229ea9dccd6d3bae22f9fb888ef400b594ec08a15972e8d2478e50f11947b52bf384c731b0e50dcd4ba116abab8af3b880c54badb11d83b4266d3e5fc25c2c8dbbba12fee2fa5c2017987f31277a67ac702b8dbe110894a8c81011c7c662ce9ab96a2e25cf5056a3e202dbf6bd5bef2347537f7811637e932d13ce02283d48d032c284b6cfb84fd813b6c3421017a7527eafcd3fbc5d4324b5351b30abcf1b366f424a8a0b5edf6bc1f3e8702b03eff875687c6caebd7bc15f1118696cc63859e3aab75aa9acc58484da7f2bc9a120844e4830429c0eee2b2324890bde302bc93f661edd9c04e1183528482f9950654e8c267234245aa9482d94e90e00e929b65431f986e7bb34524cc41f4b4443646713c7abe6c4131a2d67f3bf42f0a7f2eddf82b5c08a94d99a0a7d14c1b0b375fc158b7d4276eab22efb438f0d0a9b30e9dc127026181e42643af8da0b24bd10a532069392724948ad722b25477b481006fc1fd030aa62b217e6695dd4c7ad34dbfb75aff1df5774b061a4ea8526e9bcdf9679405c0d2e40dca00c9e80840e832fd663596dc55f602d094253893405a02d4414f119d23c4544cf832888db5ae8494dd2e8ee357753515d929b8a37b5b45446ffac20fb204b5c937f6344c453ffa449fe839b4afe1da61301057338fe29df93aa962a7374a2ec181ffff9252c8af5c3f75ebee02fba58a76066df4c6acfd5d1c18390652eb2f469d35dd708e63a498c08c5241b2717333904ba0e6e0845dca8c9608f28bd1046805cf7b220498145b23cb18184a259458dd2fbaeb1c383005a0d289562b0a9daf7d1e320aa302fd3d9a02c65fa901d46d4 Output = 7e1b4195e9cb70e6884d3d00f0b3f0a66b4d8c00ce112e1e79a1dd236ab62b26 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 Entropy = 2676b8426b9d6a30af007094bb76d65d388c2b3da938215dd6f6987206400e13 @@ -2178,7 +2178,7 @@ EncodedPublicKey = ddabceea01649d9c6588d68c05e93cb6959fbe348468cb6e7f482d2b0507a Ciphertext = 79efa2d537baa2b87a787317162d3dbcb40cb3c25f540ddb91aea6cea9870bbc5a5f86f8900b913fd4154bcfc7c8a463b9b66118c502ddad539186fcb079664f44a5363cc8d80d6a4c09f28cf8952157526cfef7bad2fc2cb69ff03ac39e37d47faab64cf54f63919303badeaab9e59df7040511ae335c5230e46e00a666b994d647d11cb032e7ee235b5e18b1894621ae93ee129823334580381b857cf0360196cb75180410f9fe7558d0e189502a5dbac5b4f0597cb3d1d201f89de26f7b4ec0d200a418a26cfb82cd4496c3ee22f6eb60f3ad2e1af981c238da13063d1746d65f77ce0ef30894468b687b31443c7acacfc3b3878fc9ec56878e7bd1a9f72ecb1706a4e5face0a83282cbc2bd15c89afbe3c97dfaf395a96ffbe1a3f75af03311afc69dbc01b11ffed2aeb8906505e910105806febc6e1298fbb5c0bf501232b888b7e8b285953d250b866a20cfdc7833a732966b3a03485ae2852d0a3fbeec6dfd0ec8015db5de69e55f091e956ab4392834c5128417105541b1145b27175fe35efbf3102277b35e42bd83aac25e25da6c55c28a03b9e2a8135871b4cc49fbfd5598c9eaa2482f249c0b6332a6999306be55921a3016499bc63a072a6e9eac894a3ec209177d07208d0d271c47f8065d0facd2e975011944f7884088768fdc053cf86f31f6d348222c06467fcf8ce0d404a2558e8cc422521a4e249549037d3e8a29e03a9a9bb511d9ffef4c5185a380d874732c9e862a6e8fa3fb72b213dab2ad0d91b047440b1d334660067566e6d2e14765d8fd0a45b9b8e8566419a6d7138e5a106c31b1278d50027d152bc8658d7045cb2297bb8382585b38be2d5fafaa7e8c867c74be013793874f181a9798193dee26fd5812eb469d1b842a969cda65d3440c67b00e6d1c3ae8630165499c1b4cf3153fb5731916ab779a2562ec62637d747d61342d832aed330e5cd794de900fa507d4b5fbdbc5f3ec1aa69d0319b3644d46d9502d435c1b5a329c0d3524611a145e3024595e91c2afd577a422d59d4d54a430f439534003be467b6f018736c4bebceaf7c83c799c2b7745ce7498dc84b9e455b96410dba1a0a5720fe703b7c0d859a42445eee7ca3353f294438a7d463fc3e98f4403f93b5fc4add88cc22db7bba150a2988639ba96cba8e2a0c980c9bf8cebdb5beb262d79e86cceb774750cd9a192ae93d85e60722ec6590beb7df8e4d036837c97dc05c7964dab00034683a576da5b51aa8a0622edc27975978c7daf1b942285572b09c170dd332a99bbf703d84becc6a96373fd1c0b355f063e4c2c6e59f5437802676000a819b9b99418df893b98a8e6ca22d95da2c151fb24a3a0e5944ac4ca6376e6c281b275589a3907c0473282967a121f1792d09a15e9d71e71e73f9f627ef0dd478061cf053af434b0663624c3bbafe0f37d7a32504e9c686f41bf48e287aaa8fadb73fece907f26a9576611ab2176a58e5c1f3e98ec0248a15774434c2a81c7a8f57f9950b83c0d3770d17c4e57582387d6f19bd Output = 2522e72d308dc9d7d701e0b024af9e15627572f13573b27c406fa750df9636fd -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 Entropy = 319c51bcb76124b92f39820a5653c0ecfba79ec91d632b0488f4020e5df4e37a @@ -2186,7 +2186,7 @@ EncodedPublicKey = e2c1184862562b91806efa62f1b72a8ec43e70663de1f66a59687ae0cc1d9 Ciphertext = b0e578cabf9deab616e52934955f42eec74bde5ea98acb022c427e08232142dd08f9120eefe5f455c8f120e672cb68f3a146c3aa457b637d0901fe2b4cd45e8b208e06823b8aae09778cd00fff5bed5232d219a2c33645f2dc30593e591f697118a8472eadbce05c9fbbc5d4b717b880065173cc0854182555376dbbe39194e4204067358808c890e5fe96028921fca344e3500b615f2201a1c4e4d13dcc889cc9b1ac72429074c21a52f4c78ea2c467d65cd2c9ed682f21f31b27af4eb5cad33dd633185bf32e726fe6e57b03168803f693bd85f5a9f2c3ec6944e9ded2b8f3270a89139ce50ba6ded6bc6b0be8893f44aa5856acda60dc1c4c0834d45574ecb6183d6e59a183c0125ff45c718be2cf85b5ce6daae6e37336ea63856561f1bd4404df725d5ed9263038d1c623b2e1aeb35924b79de474407168834891af783fe5d83a631eb14d7cfa949d698ffa45e7d8c46ed4abf75cc666b78526c9b95ebb2920c77c56227eae6c893b57f9f463ff2ebc9acddb2f7ad543c5b2259047a4cc87ad05c08bbf02e8bb267bc490c4b67106fb598d42135c927fef3397f4c3f6838776787f23a9759dd3214075e79eb3929932becde84e82c257e4638a19e1e3312cfe09d4ac681d653d749c8fa6efa6dac35ad59399f1e233540fa354681ca55db90007039b7e504e2e4082aa3e4d672019741aa02a281454d4e1c73a1c7d0b5449c2e143ceaa3b18cb9a74a89f1ba74963dc5dd4155a356211277af3a267947700a2cfd84a605ab02d37bd6faa8a26b50f7b3d9bdc79913272c31dcc0f0183d05933a9f233504ddee2dd851529667ec5174a3d23bfca197538ebacda36bc29ca675384c0b3f45e4f67fb66d8dd4aa57b7da50ead391e6b663af173e7f4d46139f5d0f4cea84dd32e4e718967c6b93617271224f2fb3a1ca5febff5f26c4edc60e9acdd9e464ebb4571dced645814e1038a50515a7e06501adb2de19fec4119dec7548c41097964c3151226153ccac24abd1415579ba1c37c805a5827332d97ba90713829fb30b7b09b275d75bc10d4a26b33980a0ccd4b00844d9f379551bd0170ee895286526ea9625a72b6cb8decd9cf18e57262f8102a025025e8168465a65a7c7e4d5fc8742781acdc16171085d51dd5ec9f4f71f58cfaf4557a55d07e7c164ccf7eb427145c7f9a800e9bd9192ec0f74d19fc17d3881b1d55e8600aa55abf78fd1e226d9dd6e8da2bea15712f5f43325d4b9c083d6e37d35c043f2bc8c796ade072555263331bee7fffa54e2099135ea363575847abb770322376cbfd3f1b7980a1857c55fc82aa80bdcd701c7b7d66221f08492efb5438a04d041b485bcb61f6fd306e96cfe758d99ca1cee70b200eedee86145fe37ab7aafcfbb2df694361fe9923e754187c3277cc895c4a53732ee118c7b6156b55b30847a6e828b7069a5d4be623abff66ba87bff49294dd9b1f698ba445d610973d052a80691c9968e3179aa3eea5b0bccb3cf674c5cfe7d2c14d7b6daa7a4813abcd56ef930099 Output = 1cffb3d6d9dd9cf90d79fb2c5c974818c5bd6f32ea4d44c302337c4cbea44334 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 Entropy = 00ff48b3769ffaf4e91c1c9110eb8ce9e2cb99f060b486b37035407d2f4ca517 @@ -2194,7 +2194,7 @@ EncodedPublicKey = e8014b4f4687bb6670b1c2a29ba577100943d5b926cb396423663f710328a Ciphertext = 3159aa52482f4262cee553f9eb6d853d091a507831f5ed1af37b9c55f217eb1e87e8b0dfb653932c27e9e9f2c4d45cf89e9cfe9ba0d5175be56b7fe3751a4255649cfabdf0cbd5a8704d58511acf6e0580eed572561fab262b24d39c3a430a4e54fca969394037df12fd8cd71b7b6ec3d8f7345b05d4c16c5871b686690cee9804012a3379bbcf720f405c3c83f59aa391cefd8b00a73b41147d42c8b7820b0e779c44e032209067349fa4cd35e83850ae37ee73f96fc6bc5b71ff9b0462604b4e07be60cc76903175b045b908c9b8e7e94c6bc7c48ffd49698873913f9132025e51614317d27a874e319d802923804d1ce1626420d5794bbbe5e077cbd7fa3d958fb2d9608a3d41f605908d21fc7f942e3152337115a28b661f76405620b056692bfcc066f370449628f8e31b7453e5b7b10702f7c195dfb779fb3253f86acbaf4444ba9ce01c9b043133a233030247f8fc44d5b8c9b024ee83c186a62ba9fa5a3e45389217884a478f238d6a9b8eaf3d87b7b4b4375d4d5226dfb80255faab42380365b5511567978be9726d21178eced7294463a348b1e976d800b1114fb8230115b28e51f628a31aa8cf2e3253a7dccaa37f975fa2b8d32a6b6147033cfcbde33ab8857e3a6af95e4cd0db62fc020f55c2d6c9204a05835e2cf878c66502f572016d95b30c45c2ef6048471ad0cb7fe14250dddcb4014c392c22fb1dce1adc8e02f416d3e9b417f41c1b4065b975de472d0e9fd5b3a012ee9bf6311345b4968f6f18262bfc2a38d56d911f9efb981813f77a8a8d6af0618e015b8b005e7ea957f89f140192c7442a645ea7012b5ea2ba9f8cd2fea2ad3e41c6a57582237d53444fceaa933d61eac36d03a2865bfb7f12fd8cf451edb5050a35a75c95dd328296dc32daf61622ce0cc457c5968414b634b3e12a0ce45bbd733e3982c087a037d89cc86d546007bd92eef33949d19dbd4daa18e59c7ea3572bf3155a9a46af527347f4f4dcc2be3cc285d65f2f86c681a137850431ce8d2f76e295e74bd0b3c88f1b68885522dadb99fe1c8e40d938c9610e466770d62c34e9393241907d9cd7bfa470cb8fc149306d9450a7a1887d03cddad3fcdeda1ea54d3f126bb29a1ac3d7c5a60ead90d74ccbf1a75b4289a74a49e0a7c4006ab76a83915ebd4a95a471525444dd2c3e748b1bd347774e2cf01f90f05a1672c58f4f563e4da083e95e0fadd4ba57acebcb45611a3923da1d0d73f5c9a55489fb0097e123694e413460252892a0c6317dcb56efa834f7a51db4a413976afcb30ab4dafbe737f43da11c1b08a2472cdff3995dd7d23382b866873624fedee76823d37ec230dee2107258993d5b802fadeb89c9469a33c66c91567ea92581e0c2c1eaa2e2a4696b024c7c6009687d07769438a8b2ba75a7bfb32841dab8acfb8cbd4d1e26c5eb68bc49bb394b178e6f89dde843f4e2c5353b04390c245a0bddd1aeaefb87528b719fe42b35ad2a89ef34826d9e23f95b1bd3c3b24f785985e10dcaf0eb33f5f71f5cbe55 Output = fd9e333ac811ae8be12c052c65131e3a7a32ce82e39055012ea564e10acaa85e -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 Entropy = 4960ccb1276f96d7aa55885b6ae6f90343d42e1391e8241b5952931a979837e1 @@ -2202,7 +2202,7 @@ EncodedPublicKey = f6513e1ec8234bc145eba3446eec18b3826b2ae709792648e071a7c4627e4 Ciphertext = 5ab063c95a541d1be3fa0744e0db7e0ece17b6b47cca0fa41d08e7969fe87de63f319f80b9a31ff01e203de6e518e62e6133edd108e5a3e08d3f8ae0556cfd36b399dc1ebf3b229bc5013d06d7550512280bad2b27657d3ca0679d9fc62f0bf875dd0b326008a89b4f29e97211ee7ec75108a9e4a320a34daed15fd7ad394a1747e4e35bbe4f1118703c330aea81bef3e3883fd41c3efc3423ab46b553c7587894ad64db57bb0fe4d289d54c8ba78d40683bdf6330ccecbacd3f7f41541f1f2b1a7626d3969df6586b4214c02f921451f6adc04f5e8de1e3beda82e4aebc5e06abb33f4cd8a3b3b5741617b6a385739133cf5b77dd5607a5c8721d5b51c6c0b6df551a5b440082093f49f31910a04e4226b9ae6f41383672e0694bc4075207034e39c40668aa3174cfc8a75fb1a474485e9aff01f3572a5c7e4914e7519344c8ce7b81377d8c2af66bebc558359601b21beb984c1f00564d46585b4bf02c958c6b348642be25119b12f34a6e5755588f649837ba53c0efaa4c6c95d109a4ce1f761c1dcecb84cce8376cb1c4e34ff932408ccd2d06f20c5397f6277bf9c3234b20cedd45afecb7e87793d85af15909546c6ee41987f36d85865c8c1e281e13d9575abb9a9f215c08d89420535f73643dc584707deb7d5275252e862393fb6493f9e126c651b7981f26af8daf978153fa4476d615183bf147629fe36de7cceaa670dab930ba8a684b0bee24b55961ea556123b34e29491704d2122e46bed0f6fd50601e13a5d46c907b915f3b8e695e0bbf474aab6e082d156e79e59572731b48338892f2268dcbb8fc21cfd537979278ceb210fe3efd052365fa249c97e8e596ae6225839e5b8b296770f3b42240b8727a0a730534d0f42f8c6ef148fc04e4285e1aecf060c3666fc17a1ff794f584b26b0b1c41f0fcca249935cd411a151932b09402016a99832850b3f56c4846145738f709f5e11e28a90d9137e4e43f03dd1ddb6565c67c2a138aca59e8aebcfa61984bc7ac13a60ddd2c1f0fa84fcf9264ad5049c888b9f555e024f0fa685474e083025da168e3b9c4ad91f074e7e711f84bb808604114e09d1ceb83b697cc0f045b5089b0bf7381ff2efc08e7316ddb7eb7be47a1d82cf533ea898e668f0da124d2e87fef2b558f877b50b13a08641c74e2726b19fa7c0f33ab213f403c328ea60d08c07155ca0c19bb75f7f6716de89e34c20f9d15ba8aebcb98e9b6461477f56f9c65ea7e8744a4d7306e216f806ea8f9f1dc45781c1adba44319031fb9e81c6d33bb317d959bc53a677270f13d96da19833965aea9a18172f6f975bc4d03036b1239e7c315ecacec35cc0f788be1220c0497844fe7c989fff5ef7fcdf89c261a0fed3915cbfae94b1fba22827daaaaa0f968f1ac71e9772aed587d607d5d3f57c1500b6e08760e0b971c1999d01553bf87f55fbad96ce61d0750d75180623543f40e5b0cee74bb429edbed1b4c2a3e1aab86c8dc7381afb0b9e7d4151a3f76b7dec4199b97304d7b3845788e19126e Output = b4b4634ad37852e19175ccfb5eca50093291da8f76b86be7511379188bc20d92 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 Entropy = 456be124e7f43803de5f734ea016455d68164a7f054c003f4ef49e46f42dd8d0 @@ -2210,7 +2210,7 @@ EncodedPublicKey = b0abba905c1559715f25f720b7b745a52332355154e60577e598c754b6346 Ciphertext = 925fde875ae198cfea88c4eeb3a0091897e25a793672df1de3f24ab4fd3edb2cad0b07e698f35dc97bfd1d551fcace3282c8c3d8131857d96ee9986da7b79a02ddc6cfc9fb7f2b809a8e5511b1c1256dbab33e7606d8a5fc048b36f6ee53c7f556efadf94494595a549ca260ac9c45bf9962bf406610ca58dc286a9eeccc447a767b6db3ab009f5848558acea4503de747d72d43218babd6f68c091b4581f4e41f2e850047f5f543a02407e7331202b0eac7bed180061bb53f4dd3504ccbd3f298d96b43bbaf8f0c2545be54c59830e1f343ca88bb9c6812c66bfbb59a6d68298985767a73d34fa69b52cea98d95d8305f97c4d4fd643b56c60fe31e3c2ee7e938ac2e4a5da2297e670931c1dea5fcbe9cf118c62a76a461495f10f640fb416ff7bc2478c0e8a1356bb840345f3d43476bc4cd990eb7f7cde7ccb96452d055397ee402be2ce395a29a4f4061ec3d85b99f086341441022435b636028a1a04c5d787abe1c24a5a55653b7063b1cacdaee40ae0de77b4034b9ac0e860a90c8834b352c71e353c02b1f46b135fa68fa7a5c1c719896987d79f3174b8d0b0c28ed64cf9f2907924497e35bf519d519a9199a4dd68025992c6f466604bb2ec3d7b13eba76e4803fb73bb125b83413998ae86691a0b35c0054e1418898f435ab26cc12a12fd4dcfa9e80887af7ebb6c856a7fc010cfcaef9e1c5a4dc24a91a622fb7307521faff0b8e8e966b7b6ae849ccc75d31c8d700a3b6a9c3f646b2a88d1e9391c2ddc6c9ff15db961874c87dd94bf0165cfc8f719806539a8beb8e28350610461b1252872f0f3ac273b3366abd78d9fe8868dca1a5eecb683ab8b50ced8cf4a5ed3b721e0fe6b205fb191985ca745ff5dae0010493f8296b6586e1c96f7f23fcb4ac4dda15eab811107c977aa0a16439b06986a9027640cf7a01051934dfc758215d22c6f06866d5b871dfdb6ed240a73dfde43f7f89c0ce6909b54b0a633a25f7253c10906166f81ae91a1419028d6182c1f277dc7872b824c7a5a22bc7afc02afeaa9ba4c271ee68882397e6cec34a955cfc672f4e6f5ed870a35ebce97f34542cf0a162938c91922230ee3fe9ed9a166a790ccf450b80cb5f483c3c6ae5b2e52e907824b45e69e5ab38226cbd6519de995e1a62a910fd45ed189540e0b4058ff01edbc6ba4eebd58d55c0e33702de299eb53d6518254b8471f282779533eaaef90602e52373be8b519c56a2f6fac0953c0f84135715c5674e45d15804fb94d9e0525ab493aa625fbf73ebdf74f0a1246e1eb0e4e2e261b24ab81d8da6e1770634c747542450cf0a2af23507f8b6766a16dbb2e67b2c94859228b91eec6c59f5a271902b340320412ae947398ad102073f8b9b8c021f81f786622c3483e61f812aa76232e6f9453eae044c5e918e6e4e0e18a78efaf6cb36f7b75929d0036c44edf928d6efe1ddc87b96288c7c624655d302b98865978ed7bc779c800e6113a0484dd225aef29796c8ba300b3f48dd566fd877dfeb5d25f96da5d07e643c5d Output = d4b9a0f77a52d4f8b9c95951257348d1931725c27eede694ecc09204a931daf7 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 Entropy = e8ac9e76377d67d84f85a142383e777157805be0d0f679ba89cefdfa61583780 @@ -2218,7 +2218,7 @@ EncodedPublicKey = 038c5d80656805b427d0b9167abb3697444af88a0f3eb48bf658be44f36b0 Ciphertext = 7c06bbeca8b58423e2ad420ec36064ed42c881e3655668f8865a2d643ecd1a4eecf915b6c64b37c98947f06c3ccc8e00bbd16017c246db88cc83f12c887aaad7db61b4d567c285841689169c3f928f1d178a0ddae50d8c46cfd95258667d6239c300595738defd2e806637ca46baa4c6c7b97f1a9b47d53cba9ffe074f88d104c4971d250d085b1800fcbd91584d8cc48e145fc81438290d74765e7ee8c1605e8048b37b9d22b050791fe008b9b84b7f23b0f49955e32c0eef78d7a3a0b2effe8b37d124e19d4cb6f6914204598a525239d9baa116e1c9c39c47f9f37f965941b2aef8519782c65f3ad3a6509d1e31e7efb67db21911e4edeb1f7e9c37b3f852c81d63a95e4775e3f2a8ff315a214680adf44d290e42ebab8ca95bf471140b9d7e03f5e9f97864289a0ae8c9a105e00409f714e413b69be366303b4a138ed51264ab0e5cca5f6dc9387c6608109e8859893efa3bc7384e9f418468b1078807dadb768e254094039d1b807d67353c8e0b5a03d28b8e41ffa0eb3ce0837a132144597908f7a059a097b79a1bac323757324e907b445d064e25c378d2069e7c5d671036871e4fe36705747635e40c6e835319e3ff81714cacc44515d671b703c5581dc76afca0b881f37c1ffc93f2e4afab1e8ac776ca883f3adf7f9ab99396f7e19541c26342a7d5618958523b81871326c357ad84ccc6d3574d97cbd875524e7b08a102263d80f318a48e510c22126568f76936c904c231700ad042d73137eec741c827a082de4a45d296745c55b8367719dd08b8295e38d8d3894b9f8e2f9b483b266e1fc71d6374353ca7d9ed1c6b73ab5a42f6abff7b2ba8fd484d1ae6928b5ea92ea3577be01dc1e88abcd0886eb771dca4d36e91c45bca4807c89736b7d6a927cf64b22c5f323077f5488f6044976f310b4b99f7d486335dcca60571157ac0e480a4dba79a826b4bac3dcb7327a33b16381eb41e1d39915e91a58750ceb71098ec7f1a2d7e44d4bab75bb7482eec277df206502c497eaa345109a145a4da6bed1900b680ad12fb028d33563bfb204ecf66e6ead587c5fe27f8a2eb0e27471925ea0f35eb9d5e53ef801eba3acaaa7790b105eb6128ace992668181c1d7cf203afdccdfefbac67dbd97cad05d499239df84e4cf7372117932c973957e5c70a8520f822be430758990296877df62069d818768513d14df0568be8e63e123bdde35036dcc69a98197f52dfbaae5e5e0cee4a48c67fdda605dad8a27651625c2b35e81dfcacd2a41a6d17f6d7067a67faf2479b3868673b248270f4a2d8ee26de9c787ce966ecf186c1401ad9d3bbf2c43b1d5de32bdd77f5433f4325427254a13985d733ab0863e62a4f3d484ab3f5d3b88f23049079143b058babffc8367cebdd9d2468d7af782979a3ef12841370da6ef2db03679e6bca0db72166c361adfbfc02234119abaf98d4fea8ddc6e8490c2fb5a1be4806a61bc7b36884cf4631cfd53138a23fdda11e597aed323748314282672473a1819ef2b9488f6744544ad Output = c9d0cf3edb1172344364afec3615ba98477ce9316f92ca46ca5f42b73553a9f5 -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 Entropy = 2fe6b9cf4510f212839e348d671b3345da68a477f57513ce363414e87299a717 @@ -2226,7 +2226,7 @@ EncodedPublicKey = 7dd722a23522b0d8cb522a67d63a75af305c05f3659bc496f1c47e410582a Ciphertext = 83ea5ed982570cd981b7430de924469d4e2faba68e03261a74f5114ab8c448376cfcd1b9cb3e72bb031bf0fefe772bc40888abc6acffc1d335d46d267acde2cb89cf1b3c67a139796d6a5763805d5edcebb81070b44ffe021b6c2b3c6c3d5dfb6d9e546930223ab0139990c6c5d6257520fe394a3aa30c6a71d47f415ac86b68eb8c83b131a3c5cbf051971fef5ef3bda355d3868e71ed8a0e2c6de8a759bc0c9e760277cc2c04c783d29d1ad3d3385accb85cc88c39bc8348f84dd8c714c5feda50b0770414a333136d6678be6ccbc5df488bafdcade883fbb310c99cc648493aed72680fe1e43c0cf523d3dd06417d29dd97c98ce53089505d36a476c0ae6d89b165c3ff6b2c62ba954fb81ac5782ae648a6802bc057c64fabd3726559ba79de9c144aaa525f6a840ed55abf21b37231c6c4cbb0110fdbcd0004f6f4974ec644c33a8aea34ef4a0a146f7502650c3def5a313d2f309cb428880502d3bdf39196a99bee296f9231d87972efd1159d3cf59bea05f0d0373a0e218ee5e0528e1ac7132440980d1153b9423bb2e099d05fbc8241ec1f316bf0add575a69982f546e99c64457c12ac83951ad46a5f024f6a61c91b7d3853ba1fa41d5a95f6ca811610ba3f32addf011ea4091ef217cdd126ec5e45cc40ec6f1292602b16c02718419646370e5b2c7c55c1128fc5d6c767cc75248b79e2379d40f91a8617e8a3db43c42cabb5cd39a7a7969147f30344c4b03de7034b12d8a1c3639697c97c4483e4191ca0fa81d8659f40e31b899b4ef4610644b1314ab2ef14b8dd8dc0082826fe65dc17211572cb14fa376f1b1784a00033c8dcddc44d6a1128a200eea668b6516ba42585cbb2e2be2a42148120013d0a9378ed7c185071fa8fdc09102164c63a665fd09c08d34104c9abb64e394b2e2a00dd834f7c7f5de16f6c02906ae37acc923dd76e530c78f2143396bfc371d14e6c48bec072b6b4e18eeae967456beb3f897a06eae17de174cf09be1435e691350632c0b1eac69dd66549c1d980fb147fa295ca6f21b5dc398e63a7c4263c75b55c85b4f38fbd7cc0fad84aba90dda1f2c9ca88d88905602096162486dba1ed0a8caa6b897c99e25934152a35fd0d476de09fb211abf36565af3744f3fb737247f5d8f172fbf438ed04422a6b3e17bdfe2cb0f09a1d57f1f1a113a768697f23d61ab288f15abc760feb0f5c5d4d5c0b1c891d3dad6089a3b7e54516b8f9755d38430312cf17b21efeeecbfd2719b62480225b9b3ee8940b1f1784ed5630d152635a1233acdd16e5489a9a15eafa7bec99aff25b18d9cac1e726c9e424773a7083f213cea53dcd310b0037aecbde1d584657f32cf548a6872c6f5a1a3a70d4db29ee3773291c94b00b5a596e1691f7752e246ca0960561cd233ec7d5f54496d34ba65b359a856315f02d16c990cdf3db2051b17bf283fed1b808ac79a9ce8250c806896bf75f2cfe76465c09360aba4c9688acea341fe755363abe41c0cba3ebad00c6c7bcc3f7ce091f87079f60094b92 Output = 4bb6a6b27596869efae3d411c69c593afff99b1a703ee1f4ff3e0e7e9756e75b -# Rho leads to a matrix with unusually large entries +# Rho leads to a matrix with unusally large entries FIPSversion = >=3.5.0 Kem = ML-KEM-768 Entropy = 86630b4f72820d19e9941784183b3a0d770609becd6fe0dc463cb6edac432d59 diff --git a/test/recipes/30-test_evp_fetch_prov.t b/test/recipes/30-test_evp_fetch_prov.t index 63082dd311..85c7b794a7 100644 --- a/test/recipes/30-test_evp_fetch_prov.t +++ b/test/recipes/30-test_evp_fetch_prov.t @@ -21,7 +21,7 @@ use lib bldtop_dir('.'); my $no_fips = disabled('fips') || ($ENV{NO_FIPS} // 0); -my @types = ( "digest", "cipher" ); +my @types = ( "digest", "cipher", "rand", "mac", "kmgmt", "kem", "kdf", "asymcipher", "evp_keyexch", "skeymgmt" ); my @testdata = ( { config => srctop_file("test", "default.cnf"), diff --git a/test/recipes/30-test_evp_list_noncache.t b/test/recipes/30-test_evp_list_noncache.t deleted file mode 100644 index 511bcec628..0000000000 --- a/test/recipes/30-test_evp_list_noncache.t +++ /dev/null @@ -1,34 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use warnings; - - -use OpenSSL::Test qw/:DEFAULT srctop_file srctop_dir bldtop_dir/; -use OpenSSL::Test::Utils; - -setup("test_noncaching_evp_fetch"); - -plan skip_all => "This test requires provider module support" - if disabled("module"); - -plan tests => 1; - -# This tells the p_ossltest provider to request no caching of algs -$ENV{OSSL_TEST_PROVIDER_NO_CACHE} = "yes"; - -my $provdir = bldtop_dir("test"); - -# list all algorithms in p_ossltest, this exercises the EVP_*do_all_provided paths when algorithms -# are not being cached -# -ok(run(app(["openssl", "list", "-provider-path", $provdir, "-provider", "p_ossltest", "-all-algorithms"])), - "list provided algs when provider requests no caching"); - - diff --git a/test/recipes/30-test_evp_pkey_provided/EC.priv.txt b/test/recipes/30-test_evp_pkey_provided/EC.priv.txt index 84ca806062..9df6455401 100644 --- a/test/recipes/30-test_evp_pkey_provided/EC.priv.txt +++ b/test/recipes/30-test_evp_pkey_provided/EC.priv.txt @@ -1,4 +1,4 @@ -Private-Key: (256 bit field, 128 bit security level) +Private-Key: (256 bit) priv: 33:d0:43:83:a9:89:56:03:d2:d7:fe:6b:01:6f:e4:59: cc:0d:9a:24:6c:86:1b:2e:dc:4b:4d:35:43:e1:1b:ad diff --git a/test/recipes/30-test_evp_pkey_provided/EC.pub.txt b/test/recipes/30-test_evp_pkey_provided/EC.pub.txt index d8dec75adc..c72473f72b 100644 --- a/test/recipes/30-test_evp_pkey_provided/EC.pub.txt +++ b/test/recipes/30-test_evp_pkey_provided/EC.pub.txt @@ -1,4 +1,4 @@ -Public-Key: (256 bit field, 128 bit security level) +Public-Key: (256 bit) pub: 04:1b:93:67:55:1c:55:9f:63:d1:22:a4:d8:d1:0a:60: 6d:02:a5:77:57:c8:a3:47:73:3a:6a:08:28:39:bd:c9: diff --git a/test/recipes/30-test_pairwise_fail.t b/test/recipes/30-test_pairwise_fail.t index ca2d1f96e4..eaf0dbbb42 100644 --- a/test/recipes/30-test_pairwise_fail.t +++ b/test/recipes/30-test_pairwise_fail.t @@ -22,7 +22,7 @@ use lib bldtop_dir('.'); plan skip_all => "These tests are unsupported in a non fips build" if disabled("fips"); -plan tests => 8; +plan tests => 9; my $provconf = srctop_file("test", "fips-and-base.cnf"); run(test(["fips_version_test", "-config", $provconf, ">=3.1.0"]), @@ -37,11 +37,17 @@ SKIP: { } SKIP: { - skip "Skip EC test because of no ec in this build", 1 + skip "Skip EC test because of no ec in this build", 2 if disabled("ec"); ok(run(test(["pairwise_fail_test", "-config", $provconf, "-pairwise", "ec"])), "fips provider ec keygen pairwise failure test"); + + skip "FIPS provider version is too old", 1 + if !$fips_exit; + ok(run(test(["pairwise_fail_test", "-config", $provconf, + "-pairwise", "eckat"])), + "fips provider ec keygen kat failure test"); } SKIP: { diff --git a/test/recipes/61-test_bio_eof.t b/test/recipes/30-test_pkey_meth.t similarity index 73% rename from test/recipes/61-test_bio_eof.t rename to test/recipes/30-test_pkey_meth.t index 7b53e49e8a..b34dcc77c9 100644 --- a/test/recipes/61-test_bio_eof.t +++ b/test/recipes/30-test_pkey_meth.t @@ -1,12 +1,12 @@ #! /usr/bin/env perl -# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2016 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy # in the file LICENSE in the source distribution or at # https://www.openssl.org/source/license.html + use OpenSSL::Test::Simple; -simple_test("test_bio_eof", "bio_eof_test"); - +simple_test("test_pkey_meth", "pkey_meth_test"); diff --git a/test/recipes/60-test_x509_load_cert_file.t b/test/recipes/60-test_x509_load_cert_file.t index 15e9908ce1..e329d7675c 100644 --- a/test/recipes/60-test_x509_load_cert_file.t +++ b/test/recipes/60-test_x509_load_cert_file.t @@ -8,8 +8,6 @@ use OpenSSL::Test qw/:DEFAULT srctop_file/; -$ENV{ASAN_OPTIONS} = "detect_leaks=1"; - setup("test_load_cert_file"); plan tests => 1; diff --git a/test/recipes/61-test_bio_readbuffer.t b/test/recipes/61-test_bio_readbuffer.t index 72027f722f..e10ab746ae 100644 --- a/test/recipes/61-test_bio_readbuffer.t +++ b/test/recipes/61-test_bio_readbuffer.t @@ -16,7 +16,7 @@ setup('test_bio_readbuffer'); my $pemfile = srctop_file("test", "certs", "leaf.pem"); my $derfile = 'readbuffer_leaf.der'; -plan tests => 4; +plan tests => 3; ok(run(app([ 'openssl', 'x509', '-inform', 'PEM', '-in', $pemfile, '-outform', 'DER', '-out', $derfile])), @@ -27,7 +27,3 @@ ok(run(test(["bio_readbuffer_test", $derfile])), ok(run(test(["bio_readbuffer_test", $pemfile])), "Running bio_readbuffer_test $pemfile"); - -ok(run(app([ 'openssl', 'x509', '-inform', 'DER', '-outform', 'PEM', - '-noout' ], stdin => $derfile)), - "Test stdin read buffer in openssl app"); diff --git a/test/recipes/61-test_bio_socketsigpipe.t b/test/recipes/61-test_bio_socketsigpipe.t deleted file mode 100644 index 8e0c56dc45..0000000000 --- a/test/recipes/61-test_bio_socketsigpipe.t +++ /dev/null @@ -1,26 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use OpenSSL::Test qw/:DEFAULT srctop_file/; -use OpenSSL::Test::Utils; - -setup("test_bio_socketsigpipe"); - -plan skip_all => "SIGPIPE is not supported on Windows" - if $^O eq 'MSWin32'; - -plan skip_all => "DJGPP target does not support this test" - if config('target') =~ /djgpp/i; - -plan skip_all => "sockets are disabled (no-sock)" - if disabled("sock"); - -plan tests => 1; - -ok(run(test(["bio_socket_sigpipe_test"])), "bio_socket_sigpipe_test"); - diff --git a/test/recipes/65-test_cmp_vfy.t b/test/recipes/65-test_cmp_vfy.t index 7cfeb4cc05..f722800e27 100644 --- a/test/recipes/65-test_cmp_vfy.t +++ b/test/recipes/65-test_cmp_vfy.t @@ -37,7 +37,6 @@ my @basic_cmd = ("cmp_vfy_test", data_file("IR_unprotected.der"), data_file("IP_waitingStatus_PBM.der"), data_file("IR_rmprotection.der"), - data_file("error_protected.der"), data_file("insta.cert.pem"), data_file("insta_ca.cert.pem"), data_file("IR_protected_0_extraCerts.der"), diff --git a/test/recipes/65-test_cmp_vfy_data/error_protected.der b/test/recipes/65-test_cmp_vfy_data/error_protected.der deleted file mode 100644 index 26af9f03ff..0000000000 Binary files a/test/recipes/65-test_cmp_vfy_data/error_protected.der and /dev/null differ diff --git a/test/recipes/70-test_asyncio.t b/test/recipes/70-test_asyncio.t index 9364acf2dd..c5b39128eb 100644 --- a/test/recipes/70-test_asyncio.t +++ b/test/recipes/70-test_asyncio.t @@ -13,7 +13,7 @@ use OpenSSL::Test qw/:DEFAULT srctop_file/; setup("test_asyncio"); plan skip_all => "No TLS/SSL protocols are supported by this OpenSSL build" - if alldisabled(available_protocols("tls")); + if alldisabled(grep { $_ ne "ssl3" } available_protocols("tls")); plan tests => 1; diff --git a/test/recipes/70-test_certtypeext.t b/test/recipes/70-test_certtypeext.t index a310524ee8..cdfc5ae7cc 100644 --- a/test/recipes/70-test_certtypeext.t +++ b/test/recipes/70-test_certtypeext.t @@ -33,8 +33,7 @@ my $proxy = TLSProxy::Proxy->new( \&certtype_filter, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); use constant { diff --git a/test/recipes/70-test_clienthello.t b/test/recipes/70-test_clienthello.t index 662b31dc4a..61130bd9b4 100644 --- a/test/recipes/70-test_clienthello.t +++ b/test/recipes/70-test_clienthello.t @@ -13,7 +13,7 @@ use OpenSSL::Test::Utils; setup("test_clienthello"); plan skip_all => "No TLS/SSL protocols are supported by this OpenSSL build" - if alldisabled(available_protocols("tls")); + if alldisabled(grep { $_ ne "ssl3" } available_protocols("tls")); #No EC with TLSv1.3 confuses the padding calculations in this test plan skip_all => "No EC with TLSv1.3 is not supported by this test" diff --git a/test/recipes/70-test_comp.t b/test/recipes/70-test_comp.t index c8e37f4cc3..2e4b288e51 100644 --- a/test/recipes/70-test_comp.t +++ b/test/recipes/70-test_comp.t @@ -85,8 +85,7 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); $proxy->start() or plan skip_all => "Unable to start up Proxy for tests"; diff --git a/test/recipes/70-test_ec_point_formats.t b/test/recipes/70-test_ec_point_formats.t deleted file mode 100644 index 4c86b66c9a..0000000000 --- a/test/recipes/70-test_ec_point_formats.t +++ /dev/null @@ -1,183 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; - -use OpenSSL::Test qw/:DEFAULT cmdstr srctop_file bldtop_dir/; -use OpenSSL::Test::Utils; -use TLSProxy::Proxy; -use Cwd qw(abs_path); - -my $test_name = "test_ec_point_formats"; -setup($test_name); - -$ENV{OPENSSL_MODULES} = abs_path(bldtop_dir("test")); - -plan skip_all => "TLSProxy isn't usable on $^O" - if $^O =~ /^(VMS)$/; - -plan skip_all => "$test_name needs the module feature enabled" - if disabled("module"); - -plan skip_all => "$test_name needs the sock feature enabled" - if disabled("sock"); - -plan skip_all => "$test_name needs TLS 1.2 enabled" - if disabled("tls1_2"); - -plan skip_all => "$test_name needs EC enabled" - if disabled("ec"); - -# RFC 4492 section 5.1.2 requires the peer's ec_point_formats list to -# contain "uncompressed", but only when an EC cipher suite is actually -# negotiated at TLS 1.2 or below. The peer's list is irrelevant at TLS -# 1.3 (the extension itself is) and at TLS 1.2 with a non-ECC cipher -# suite. We mangle the list to contain only "compressed" (0x01) and -# verify the four corner cases: both sides reject in an ECC TLS 1.2 -# handshake; both sides tolerate the missing "uncompressed" when TLS 1.3 -# or a non-ECC cipher suite is in play. - -# Wire format for ec_point_formats: 1-byte length prefix, then the -# ECPointFormat bytes. "\x01\x01" advertises a list of one format, -# the value 1 = ansiX962_compressed_prime; 0 (uncompressed) is absent. -my $only_compressed = "\x01\x01"; - -my $fatal_alert = 0; - -my $proxy = TLSProxy::Proxy->new( - \&mangle_ec_point_formats_clienthello, - cmdstr(app(["openssl"]), display => 1), - srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), -); - -# Test 1: a non-conforming list in the ClientHello -- the server -# must abort with illegal_parameter. ECDHE-RSA suffices to -# trigger the check (client supports at least one ECDHE group and -# cipher, so sends the extension), no EC cert required from either -# side. -$proxy->clientflags("-tls1_2"); -$proxy->serverflags("-tls1_2"); -$proxy->cipherc("ECDHE-RSA-AES128-SHA256"); -$proxy->ciphers("ECDHE-RSA-AES128-SHA256"); -$proxy->start() or plan skip_all => "Unable to start up proxy for tests"; -plan tests => 4; -ok($fatal_alert, - "Server rejects ClientHello whose ec_point_formats omits uncompressed"); - -# Test 2: a non-conforming list in the ServerHello -- the client must -# abort with the same error. -$fatal_alert = 0; -$proxy->clear(); -$proxy->filter(\&mangle_ec_point_formats_serverhello); -$proxy->clientflags("-tls1_2"); -$proxy->serverflags("-tls1_2"); -$proxy->cipherc("ECDHE-RSA-AES128-SHA256"); -$proxy->ciphers("ECDHE-RSA-AES128-SHA256"); -$proxy->start(); -ok($fatal_alert, - "Client rejects ServerHello whose ec_point_formats omits uncompressed"); - -# Mutating a ClientHello on the wire breaks the handshake transcript -# (the client and server compute different transcript hashes), so a -# tolerance test can't wait for the handshake to complete -- the -# Finished MAC will fail later regardless of whether the construct -# hook rejected. Instead, the proxy is allowed to run to whatever -# end it finds and we look at $proxy->message_list afterwards: if the -# server sent a ServerHello in response to the mangled ClientHello, -# it accepted the extension; if it rejected, the only server-side -# message in the list will be the fatal alert. -sub server_sent_hello { - my $proxy = shift; - foreach my $msg (@{$proxy->message_list}) { - return 1 if $msg->mt == TLSProxy::Message::MT_SERVER_HELLO; - } - return 0; -} - -# Test 3: TLS 1.3 ignores the ec_point_formats extension entirely. The -# server doesn't emit one in its TLS 1.3 ServerHello, and the -# construct-hook 5.1.2 check requires an ECC TLS <= 1.2 ciphersuite -# to fire. A mangled ClientHello list must therefore leave the server -# willing to send its ServerHello. -SKIP: { - skip "TLS 1.3 disabled", 1 if disabled("tls1_3"); - - $fatal_alert = 0; - $proxy->clear(); - $proxy->filter(\&mangle_ec_point_formats_clienthello); - $proxy->clientflags("-tls1_3"); - $proxy->serverflags("-tls1_3"); - $proxy->start(); - ok(server_sent_hello($proxy), - "TLS 1.3 server tolerates ec_point_formats missing uncompressed"); -} - -# Test 4: At TLS 1.2 with a non-ECC cipher suite, the construct hook -# returns NOT_SENT without inspecting the peer's list. Offer ECDHE-RSA -# alongside DHE-RSA on the client -- the ECDHE entry is enough for the -# client to advertise ec_point_formats -- pin the server to DHE-RSA, -# and confirm a mangled list is tolerated. -SKIP: { - skip "DH disabled", 1 if disabled("dh"); - - $fatal_alert = 0; - $proxy->clear(); - $proxy->filter(\&mangle_ec_point_formats_clienthello); - $proxy->clientflags("-tls1_2"); - $proxy->serverflags("-tls1_2"); - $proxy->cipherc("ECDHE-RSA-AES128-SHA256:DHE-RSA-AES128-GCM-SHA256"); - $proxy->ciphers("DHE-RSA-AES128-GCM-SHA256"); - $proxy->start(); - ok(server_sent_hello($proxy), - "TLS 1.2 non-ECC server tolerates ec_point_formats missing uncompressed"); -} - -sub mangle_ec_point_formats_clienthello -{ - my $proxy = shift; - - if ($proxy->flight == 0) { - foreach my $message (@{$proxy->message_list}) { - if ($message->mt == TLSProxy::Message::MT_CLIENT_HELLO) { - $message->set_extension( - TLSProxy::Message::EXT_EC_POINT_FORMATS, - $only_compressed); - $message->repack(); - } - } - return; - } - - my $last_record = @{$proxy->{record_list}}[-1]; - $fatal_alert = 1 - if defined $last_record && $last_record->is_fatal_alert(1); -} - -sub mangle_ec_point_formats_serverhello -{ - my $proxy = shift; - - if ($proxy->flight == 0) { - return; - } elsif ($proxy->flight == 1) { - foreach my $message (@{$proxy->message_list}) { - if ($message->mt == TLSProxy::Message::MT_SERVER_HELLO) { - $message->set_extension( - TLSProxy::Message::EXT_EC_POINT_FORMATS, - $only_compressed); - $message->repack(); - } - } - return; - } - - my $last_record = @{$proxy->{record_list}}[-1]; - $fatal_alert = 1 - if defined $last_record && $last_record->is_fatal_alert(0); -} diff --git a/test/recipes/70-test_expected_rpk.t b/test/recipes/70-test_expected_rpk.t deleted file mode 100644 index 5165ed9263..0000000000 --- a/test/recipes/70-test_expected_rpk.t +++ /dev/null @@ -1,62 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use OpenSSL::Test qw/:DEFAULT cmdstr srctop_file bldtop_dir/; -use OpenSSL::Test::Utils; -use TLSProxy::Proxy; -use Cwd qw(abs_path); - -my $test_name = "test_expected_rpk"; -setup($test_name); - -$ENV{OPENSSL_MODULES} = abs_path(bldtop_dir("test")); - -plan skip_all => "TLSProxy isn't usable on $^O" - if $^O =~ /^(VMS)$/; - -plan skip_all => "$test_name needs the module feature enabled" - if disabled("module"); - -plan skip_all => "$test_name needs the sock feature enabled" - if disabled("sock"); - -plan tests => 2; - -my $proxy = TLSProxy::Proxy->new( - sub { return; }, - cmdstr(app(["openssl"]), display => 1), - srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() -); - -SKIP: { - skip "No TLS 1.2 support in this OpenSSL build", 1 if disabled("tls1_2"); - $proxy->clear(); - $proxy->clientflags("-tls1_2 -verify 1 -verify_return_error -enable_client_rpk". - " -cert ". srctop_file("apps", "server.pem"). - " -expected-rpks ". srctop_file("apps", "server.pem")); - $proxy->serverflags("-tls1_2 -Verify 1 -verify_return_error -enable_server_rpk". - " -expected-rpks ". srctop_file("apps", "server.pem")); - - $proxy->start() or plan skip_all => "Unable to start up Proxy for tests"; - ok(TLSProxy::Message->success, "Verified TLS 1.2 mutual RPK"); -} - -SKIP: { - skip "No TLS 1.3 support in this OpenSSL build", 1 if disabled("tls1_3"); - $proxy->clear(); - $proxy->clientflags("-tls1_3 -verify 1 -verify_return_error -enable_client_rpk". - " -cert ". srctop_file("apps", "server.pem"). - " -expected-rpks ". srctop_file("apps", "server.pem")); - $proxy->serverflags("-tls1_3 -Verify 1 -verify_return_error -enable_server_rpk". - " -expected-rpks ". srctop_file("apps", "server.pem")); - $proxy->start(); - ok(TLSProxy::Message->success, "Verified TLS 1.3 mutual RPK"); -} diff --git a/test/recipes/70-test_key_share.t b/test/recipes/70-test_key_share.t index afd769c9b0..5964d778ff 100644 --- a/test/recipes/70-test_key_share.t +++ b/test/recipes/70-test_key_share.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -27,9 +27,7 @@ use constant { TRAILING_DATA => 10, SELECT_X25519 => 11, NO_KEY_SHARES_IN_HRR => 12, - NON_TLS1_3_KEY_SHARE => 13, - LARGE_NUM_KEY_SHARES => 14, - LARGE_NUM_SUPP_GROUPS => 15 + NON_TLS1_3_KEY_SHARE => 13 }; use constant { @@ -73,8 +71,7 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); #We assume that test_ssl_new and friends will test the happy path for this, @@ -90,7 +87,7 @@ if (disabled("ec")) { $proxy->serverflags("-groups P-384"); } $proxy->start() or plan skip_all => "Unable to start up Proxy for tests"; -plan tests => 25; +plan tests => 23; ok(TLSProxy::Message->success(), "Success after HRR"); #Test 2: The server sending an HRR requesting a group the client already sent @@ -151,15 +148,6 @@ SKIP: { #Test 7: An acceptable key_share after a list of non-acceptable ones should #succeed $proxy->clear(); - # The test assumes that one of the client initial keyshares includes - # either X25519 if ECX is enabled or P-256 otherwise. While the default - # groups have been adjusted to make it true for now, the test was brittle, - # best to set the client groups explicitly. - if (disabled("ecx")) { - $proxy->clientflags("-groups P-256"); - } else { - $proxy->clientflags("-groups X25519:P-256"); - } $testtype = ACCEPTABLE_AT_END; $proxy->start(); ok(TLSProxy::Message->success(), "Acceptable key_share at end of list"); @@ -305,7 +293,7 @@ $proxy->start(); ok(TLSProxy::Message->fail(), "Server sends HRR with no key_shares"); SKIP: { - skip "No EC support in this OpenSSL build", 3 if disabled("ec"); + skip "No EC support in this OpenSSL build", 1 if disabled("ec"); #Test 23: Trailing data on key_share in ServerHello should fail $proxy->clear(); $direction = CLIENT_TO_SERVER; @@ -322,27 +310,6 @@ SKIP: { && (${$proxy->message_list}[2]->mt == TLSProxy::Message::MT_CLIENT_HELLO); ok(TLSProxy::Message->success() && $ishrr, "Client sends a key_share for a Non TLSv1.3 group"); - - #Test 24: Client sends a large number of key shares. We should ignore them. - $proxy->clear(); - $direction = CLIENT_TO_SERVER; - $testtype = LARGE_NUM_KEY_SHARES; - $proxy->clientflags("-groups P-256"); - $proxy->start(); - ok(TLSProxy::Message->success(), "Large number of key shares"); - - #Test 25: Client sends a large number of supported groups. We should ignore - # them. - $proxy->clear(); - $direction = CLIENT_TO_SERVER; - $testtype = LARGE_NUM_SUPP_GROUPS; - if (disabled("ecx")) { - $proxy->clientflags("-groups P-384"); - } else { - $proxy->clientflags("-groups X25519"); - } - $proxy->start(); - ok(TLSProxy::Message->success(), "Large number of supported groups"); } sub modify_key_shares_filter @@ -362,42 +329,33 @@ sub modify_key_shares_filter my $ext; my $suppgroups; - if ($testtype == NON_TLS1_3_KEY_SHARE) { - if (disabled("ecx")) { - $suppgroups = pack "C6", - 0x00, 0x04, #List Length - 0x00, 0x13, - 0x00, 0x18; #P-384 - } else { - $suppgroups = pack "C6", - 0x00, 0x04, #List Length - 0x00, 0x13, - 0x00, 0x1d; #X25519 - } - } elsif ($testtype == NOT_IN_SUPPORTED_GROUPS) { - $suppgroups = pack "C4", - 0x00, 0x02, #List Length - 0x00, 0xfe; #Non existing group 1 - } elsif ($testtype == LARGE_NUM_SUPP_GROUPS) { - if (disabled("ecx")) { - $suppgroups = pack "C4", - 0x01, 0x02, #List Length - 0x00, 0x18; #P-384 - } else { - $suppgroups = pack "C4", - 0x01, 0x02, #List Length - 0x00, 0x1d; #X25519 - } - $suppgroups .= pack "C256", - (0xff, 0xff)x128; - } else { + if ($testtype != NON_TLS1_3_KEY_SHARE) { #Setup supported groups to include some unrecognised groups - $suppgroups = pack "C10", - 0x00, 0x08, #List Length - 0xff, 0xfe, #Non existing group 1 - 0xff, 0xff, #Non existing group 2 - 0x00, 0x1d, #X25519 - 0x00, 0x17; #P-256 + if (disabled("ecx")) { + $suppgroups = pack "C8", + 0x00, 0x06, #List Length + 0xff, 0xfe, #Non existing group 1 + 0xff, 0xff, #Non existing group 2 + 0x00, 0x17; #P-256 + } else { + $suppgroups = pack "C8", + 0x00, 0x06, #List Length + 0xff, 0xfe, #Non existing group 1 + 0xff, 0xff, #Non existing group 2 + 0x00, 0x1d; #X25519 + } + } else { + if (disabled("ecx")) { + $suppgroups = pack "C6", + 0x00, 0x04, #List Length + 0x00, 0x13, + 0x00, 0x18; #P-384 + } else { + $suppgroups = pack "C6", + 0x00, 0x04, #List Length + 0x00, 0x13, + 0x00, 0x1d; #X25519 + } } if ($testtype == EMPTY_EXTENSION) { @@ -430,6 +388,10 @@ sub modify_key_shares_filter "155155B95269ED5C87EAA99C2EF5A593". "EDF83495E80380089F831B94D14B1421"; #key_exchange data } + } elsif ($testtype == NOT_IN_SUPPORTED_GROUPS) { + $suppgroups = pack "C4", + 0x00, 0x02, #List Length + 0x00, 0xfe; #Non existing group 1 } elsif ($testtype == GROUP_ID_TOO_SHORT) { $ext = pack "C6H64C1", 0x00, 0x25, #List Length @@ -476,15 +438,6 @@ sub modify_key_shares_filter 0x00, 0x31, #key_exchange data length "04EE3B38D1CB800A1A2B702FC8423599F2AC7161E175C865F8". "3DAF78BCBAE561464E8144359BE70CB7989D28A2F43F8F2C"; #key_exchange data - } elsif ($testtype == LARGE_NUM_KEY_SHARES) { - #We include 17 key shares (we only accept the first 16). We - #should just ignore them and still succeed - $ext = pack "C6H130C80", 0x00, 0x95, #List Length (149 bytes) - 0x00, 0x17, #P-256 - 0x00, 0x41, #key_exchange data length - "04A798ACF80B2991A0A53D084F4F649A46BE49D061EB5B8CFF9C8EC6AE792507B6". - "F77FE6E446AF3645FD86BB7CFFD2644E45CC00183343C5CEAD67BB017B082007", #key_exchange data - (0xff, 0xff, 0x00, 0x01, 0xff)x16; #16 dummy key shares } if ($testtype != EMPTY_EXTENSION @@ -495,7 +448,7 @@ sub modify_key_shares_filter if ($testtype == MISSING_EXTENSION) { $message->delete_extension( TLSProxy::Message::EXT_KEY_SHARE); - } elsif ($testtype != NOT_IN_SUPPORTED_GROUPS && $testtype != LARGE_NUM_SUPP_GROUPS) { + } elsif ($testtype != NOT_IN_SUPPORTED_GROUPS) { $message->set_extension( TLSProxy::Message::EXT_KEY_SHARE, $ext); } diff --git a/test/recipes/70-test_npn.t b/test/recipes/70-test_npn.t index 13ac6fc48d..e1d058dbb6 100644 --- a/test/recipes/70-test_npn.t +++ b/test/recipes/70-test_npn.t @@ -36,8 +36,7 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); $proxy->start() or plan skip_all => "Unable to start up Proxy for tests"; diff --git a/test/recipes/70-test_recordlen.t b/test/recipes/70-test_recordlen.t index 4901633ce5..9adc71cb8f 100644 --- a/test/recipes/70-test_recordlen.t +++ b/test/recipes/70-test_recordlen.t @@ -13,7 +13,7 @@ use OpenSSL::Test qw/:DEFAULT srctop_file/; setup("test_recordlen"); plan skip_all => "No TLS/SSL protocols are supported by this OpenSSL build" - if alldisabled(available_protocols("tls")); + if alldisabled(grep { $_ ne "ssl3" } available_protocols("tls")); plan tests => 1; diff --git a/test/recipes/70-test_renegotiation.t b/test/recipes/70-test_renegotiation.t index d0ab0fcbe1..54d2cf922e 100644 --- a/test/recipes/70-test_renegotiation.t +++ b/test/recipes/70-test_renegotiation.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -28,7 +28,7 @@ plan skip_all => "$test_name needs the sock feature enabled" if disabled("sock"); plan skip_all => "$test_name needs TLS <= 1.2 enabled" - if alldisabled(("tls1", "tls1_1", "tls1_2")); + if alldisabled(("ssl3", "tls1", "tls1_1", "tls1_2")); plan tests => 9; @@ -36,27 +36,15 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); -sub success_or_closenotify -{ - return 1 if TLSProxy::Message->success(); - - my $alert = TLSProxy::Message->alert(); - return 0 unless defined $alert; - - return ($alert->level() == TLSProxy::Message::AL_LEVEL_WARN() - && $alert->description() == TLSProxy::Message::AL_DESC_CLOSE_NOTIFY()); -} - #Test 1: A basic renegotiation test $proxy->clientflags("-no_tls1_3"); $proxy->serverflags("-client_renegotiation"); $proxy->reneg(1); $proxy->start() or plan skip_all => "Unable to start up Proxy for tests"; -ok(success_or_closenotify(), "Basic renegotiation"); +ok(TLSProxy::Message->success(), "Basic renegotiation"); #Test 2: Seclevel 0 client does not send the Reneg SCSV. Reneg should fail $proxy->clear(); @@ -109,7 +97,7 @@ SKIP: { } } } - ok(success_or_closenotify() && $chmatch, + ok(TLSProxy::Message->success() && $chmatch, "Check ClientHello version is the same"); } diff --git a/test/recipes/70-test_rio_notifier.t b/test/recipes/70-test_rio_notifier.t deleted file mode 100644 index 016cc01216..0000000000 --- a/test/recipes/70-test_rio_notifier.t +++ /dev/null @@ -1,19 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use OpenSSL::Test; -use OpenSSL::Test::Utils; - -setup("test_rio_notifier"); - -plan skip_all => "RIO notifier tests require QUIC" - if disabled("quic"); - -plan tests => 1; - -ok(run(test(["rio_notifier_test"]))); diff --git a/test/recipes/70-test_servername.t b/test/recipes/70-test_servername.t index 47b5e9dbec..f5ea9473c2 100644 --- a/test/recipes/70-test_servername.t +++ b/test/recipes/70-test_servername.t @@ -17,7 +17,7 @@ use OpenSSL::Test::Utils qw(alldisabled available_protocols); setup("test_servername"); plan skip_all => "No TLS/SSL protocols are supported by this OpenSSL build" - if alldisabled(available_protocols("tls")); + if alldisabled(grep { $_ ne "ssl3" } available_protocols("tls")); plan tests => 1; diff --git a/test/recipes/70-test_sslcbcpadding.t b/test/recipes/70-test_sslcbcpadding.t index 7c614fe6a0..83fc8ab91c 100644 --- a/test/recipes/70-test_sslcbcpadding.t +++ b/test/recipes/70-test_sslcbcpadding.t @@ -35,8 +35,7 @@ my $proxy = TLSProxy::Proxy->new( \&add_maximal_padding_filter, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); # TODO: We could test all 256 values, but then the log file gets too large for @@ -119,6 +118,7 @@ sub add_maximal_padding_filter TLSProxy::Record::RT_APPLICATION_DATA, TLSProxy::Record::VERS_TLS_1_2, length($data), + 0, length($data), $plaintext_len, $data, diff --git a/test/recipes/70-test_sslcertstatus.t b/test/recipes/70-test_sslcertstatus.t index 4c384ff49e..c6aca567f7 100644 --- a/test/recipes/70-test_sslcertstatus.t +++ b/test/recipes/70-test_sslcertstatus.t @@ -37,8 +37,7 @@ my $proxy = TLSProxy::Proxy->new( \&certstatus_filter, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); #Test 1: Sending a status_request extension in both ClientHello and diff --git a/test/recipes/70-test_sslextension.t b/test/recipes/70-test_sslextension.t index 89b241efee..31e494134a 100644 --- a/test/recipes/70-test_sslextension.t +++ b/test/recipes/70-test_sslextension.t @@ -38,8 +38,7 @@ use constant { UNSOLICITED_SERVER_NAME => 0, UNSOLICITED_SERVER_NAME_TLS13 => 1, UNSOLICITED_SCT => 2, - NONCOMPLIANT_SUPPORTED_GROUPS => 3, - UNKNOWN_SERVER_HELLO_TLS13 => 4 + NONCOMPLIANT_SUPPORTED_GROUPS => 3 }; my $testtype; @@ -49,8 +48,7 @@ my $proxy = TLSProxy::Proxy->new( \&inject_duplicate_extension_clienthello, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); @@ -147,8 +145,7 @@ sub inject_unsolicited_extension if ($proxy->flight != 1) { if ($sent_unsolisited_extension) { my $last_record = @{$proxy->record_list}[-1]; - my $alert = $last_record->is_fatal_alert(0); - $fatal_alert = $alert if $alert; + $fatal_alert = 1 if $last_record->is_fatal_alert(0); } return; } @@ -174,8 +171,6 @@ sub inject_unsolicited_extension $type = TLSProxy::Message::EXT_SCT; } elsif ($testtype == NONCOMPLIANT_SUPPORTED_GROUPS) { $type = TLSProxy::Message::EXT_SUPPORTED_GROUPS; - } elsif ($testtype == UNKNOWN_SERVER_HELLO_TLS13) { - $type = TLSProxy::Message::EXT_UNKNOWN; } $message->set_extension($type, $ext); $message->repack(); @@ -198,7 +193,7 @@ sub inject_cryptopro_extension # Test 1-2: Sending a duplicate extension should fail. $proxy->start() or plan skip_all => "Unable to start up Proxy for tests"; -plan tests => 9; +plan tests => 8; ok($fatal_alert, "Duplicate ClientHello extension"); SKIP: { @@ -265,7 +260,7 @@ SKIP: { } SKIP: { - skip "TLS 1.3 disabled", 2 + skip "TLS 1.3 disabled", 1 if disabled("tls1_3") || (disabled("ec") && disabled("dh")); #Test 8: Inject an unsolicited extension (TLSv1.3) $fatal_alert = 0; @@ -275,14 +270,4 @@ SKIP: { $proxy->clientflags("-noservername"); $proxy->start(); ok($fatal_alert, "Unsolicited server name extension (TLSv1.3)"); - - #Test 9: Inject an unknown extension in ServerHello (TLSv1.3) - $fatal_alert = 0; - $proxy->clear(); - $proxy->filter(\&inject_unsolicited_extension); - $testtype = UNKNOWN_SERVER_HELLO_TLS13; - $proxy->clientflags(""); - $proxy->start(); - ok($fatal_alert == TLSProxy::Message::AL_DESC_UNSUPPORTED_EXTENSION, - "Unknown ServerHello extension (TLSv1.3)"); } diff --git a/test/recipes/70-test_sslmessages.t b/test/recipes/70-test_sslmessages.t index 3b2756de8b..bb1789710c 100644 --- a/test/recipes/70-test_sslmessages.t +++ b/test/recipes/70-test_sslmessages.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -36,8 +36,7 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); @handmessages = ( @@ -101,7 +100,7 @@ my $proxy = TLSProxy::Proxy->new( [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_STATUS_REQUEST, TLSProxy::Message::CLIENT, checkhandshake::STATUS_REQUEST_CLI_EXTENSION], - ((disabled("ec") && disabled("dh")) ? () : + (disabled("ec") ? () : [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_SUPPORTED_GROUPS, TLSProxy::Message::CLIENT, diff --git a/test/recipes/70-test_sslrecords.t b/test/recipes/70-test_sslrecords.t index a49e3a256c..fe26564d50 100644 --- a/test/recipes/70-test_sslrecords.t +++ b/test/recipes/70-test_sslrecords.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -33,19 +33,20 @@ my $inject_recs_num = undef; my $content_type = undef; my $boundary_test_type = undef; my $fatal_alert = undef; # set by filters at expected fatal alerts +my $sslv2testtype = undef; my $proxy_start_success = 0; -plan tests => 34; +plan tests => 44; SKIP: { - skip "TLS 1.2 is disabled", 17 if disabled("tls1_2"); + skip "TLS 1.2 is disabled", 22 if disabled("tls1_2"); # Run tests with TLS run_tests(0); } SKIP: { - skip "DTLS 1.2 is disabled", 17 if disabled("dtls1_2"); - skip "DTLSProxy does not work on Windows", 17 if $^O =~ /^(MSWin32)$/; + skip "DTLS 1.2 is disabled", 22 if disabled("dtls1_2"); + skip "DTLSProxy does not work on Windows", 22 if $^O =~ /^(MSWin32)$/; run_tests(1); } @@ -59,16 +60,14 @@ sub run_tests \&add_empty_recs_filter, cmdstr(app([ "openssl" ]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); } else { $proxy = TLSProxy::Proxy->new( \&add_empty_recs_filter, cmdstr(app([ "openssl" ]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); } @@ -108,7 +107,7 @@ sub run_tests "In context empty records test".($run_test_as_dtls == 1) ? " for DTLS" : " for TLS"); SKIP: { - skip "Record tests not intended for dtls", 2 if $run_test_as_dtls == 1; + skip "Record tests not intended for dtls", 7 if $run_test_as_dtls == 1; #Test 3: Injecting too many in context empty records should fail $fatal_alert = 0; $proxy->clear(); @@ -129,10 +128,76 @@ sub run_tests $proxy->clientflags("-no_tls1_3"); $proxy->start(); ok($fatal_alert, "Fragmented alert records test"); + + #Run some SSLv2 ClientHello tests + + use constant { + TLSV1_2_IN_SSLV2 => 0, + SSLV2_IN_SSLV2 => 1, + FRAGMENTED_IN_TLSV1_2 => 2, + FRAGMENTED_IN_SSLV2 => 3, + ALERT_BEFORE_SSLV2 => 4 + }; + + # The TLSv1.2 in SSLv2 ClientHello need to run at security level 0 + # because in a SSLv2 ClientHello we can't send extensions to indicate + # which signature algorithm we want to use, and the default is SHA1. + + #Test 5: Inject an SSLv2 style record format for a TLSv1.2 ClientHello + $sslv2testtype = TLSV1_2_IN_SSLV2; + $proxy->clear(); + $proxy->filter(\&add_sslv2_filter); + $proxy->serverflags("-tls1_2"); + $proxy->clientflags("-no_tls1_3 -legacy_renegotiation"); + $proxy->ciphers("AES128-SHA:\@SECLEVEL=0"); + $proxy->start(); + ok(TLSProxy::Message->success(), "TLSv1.2 in SSLv2 ClientHello test"); + + #Test 6: Inject an SSLv2 style record format for an SSLv2 ClientHello. We don't + # support this so it should fail. We actually treat it as an unknown + # protocol so we don't even send an alert in this case. + $sslv2testtype = SSLV2_IN_SSLV2; + $proxy->clear(); + $proxy->serverflags("-tls1_2"); + $proxy->clientflags("-no_tls1_3"); + $proxy->ciphers("AES128-SHA:\@SECLEVEL=0"); + $proxy->start(); + ok(TLSProxy::Message->fail(), "SSLv2 in SSLv2 ClientHello test"); + + #Test 7: Sanity check ClientHello fragmentation. This isn't really an SSLv2 test + # at all, but it gives us confidence that Test 8 fails for the right + # reasons + $sslv2testtype = FRAGMENTED_IN_TLSV1_2; + $proxy->clear(); + $proxy->serverflags("-tls1_2"); + $proxy->clientflags("-no_tls1_3"); + $proxy->ciphers("AES128-SHA:\@SECLEVEL=0"); + $proxy->start(); + ok(TLSProxy::Message->success(), "Fragmented ClientHello in TLSv1.2 test"); + + #Test 8: Fragment a TLSv1.2 ClientHello across a TLS1.2 record; an SSLv2 + # record; and another TLS1.2 record. This isn't allowed so should fail + $sslv2testtype = FRAGMENTED_IN_SSLV2; + $proxy->clear(); + $proxy->serverflags("-tls1_2"); + $proxy->clientflags("-no_tls1_3"); + $proxy->ciphers("AES128-SHA:\@SECLEVEL=0"); + $proxy->start(); + ok(TLSProxy::Message->fail(), "Fragmented ClientHello in TLSv1.2/SSLv2 test"); + + #Test 9: Send a TLS warning alert before an SSLv2 ClientHello. This should + # fail because an SSLv2 ClientHello must be the first record. + $sslv2testtype = ALERT_BEFORE_SSLV2; + $proxy->clear(); + $proxy->serverflags("-tls1_2"); + $proxy->clientflags("-no_tls1_3"); + $proxy->ciphers("AES128-SHA:\@SECLEVEL=0"); + $proxy->start(); + ok(TLSProxy::Message->fail(), "Alert before SSLv2 ClientHello test"); } #Unrecognised record type tests - #Test 5: Sending an unrecognised record type in TLS1.2 should fail + #Test 10: Sending an unrecognised record type in TLS1.2 should fail $fatal_alert = 0; $proxy->clear(); if ($run_test_as_dtls == 1) { @@ -146,12 +211,7 @@ sub run_tests $proxy_start_success = $proxy->start(); if ($run_test_as_dtls == 1) { - # DTLS alerts are best-effort (RFC 6347 section 4.2.7): the client's - # fatal alert may be lost, so we cannot rely on observing it. What we - # verify is that the client rejected the connection, i.e. exited with a - # failure. Whether we happened to see the alert is only diagnostic. - ok($proxy->clientexit != 0, "Unrecognised record type in DTLS1.2"); - note("client fatal alert observed") if $fatal_alert; + ok($proxy_start_success == 0, "Unrecognised record type in DTLS1.2"); } else { ok($fatal_alert, "Unrecognised record type in TLS1.2"); } @@ -160,7 +220,7 @@ sub run_tests skip "TLSv1.1 or DTLSv1 disabled", 1 if ($run_test_as_dtls == 0 && disabled("tls1_1")) || ($run_test_as_dtls == 1 && disabled("dtls1")); - #Test 6: Sending an unrecognised record type in TLS1.1 should fail + #Test 11: Sending an unrecognised record type in TLS1.1 should fail $fatal_alert = 0; $proxy->clear(); if ($run_test_as_dtls == 1) { @@ -171,8 +231,7 @@ sub run_tests $proxy->ciphers("AES128-SHA:\@SECLEVEL=0"); $proxy_start_success = $proxy->start(); if ($run_test_as_dtls == 1) { - ok($proxy->clientexit != 0, "Unrecognised record type in DTLSv1"); - note("client fatal alert observed") if $fatal_alert; + ok($proxy_start_success == 0, "Unrecognised record type in DTLSv1"); } else { ok($fatal_alert, "Unrecognised record type in TLSv1.1"); } @@ -180,7 +239,7 @@ sub run_tests SKIP: { skip "Record tests not intended for dtls", 10 if $run_test_as_dtls == 1; - #Test 7: Sending a different record version in TLS1.2 should fail + #Test 12: Sending a different record version in TLS1.2 should fail $fatal_alert = 0; $proxy->clear(); $proxy->clientflags("-tls1_2"); @@ -193,20 +252,20 @@ sub run_tests skip "TLSv1.3 disabled", 9 if disabled("tls1_3") || (disabled("ec") && disabled("dh")); - #Test 8: Sending a different record version in TLS1.3 should fail + #Test 13: Sending a different record version in TLS1.3 should fail $proxy->clear(); $proxy->filter(\&change_version); $proxy->start(); ok(TLSProxy::Message->fail(), "Changed record version in TLS1.3"); - #Test 9: Sending an unrecognised record type in TLS1.3 should fail + #Test 14: Sending an unrecognised record type in TLS1.3 should fail $fatal_alert = 0; $proxy->clear(); $proxy->filter(\&add_unknown_record_type); $proxy->start(); ok($fatal_alert, "Unrecognised record type in TLS1.3"); - #Test 10: Sending an outer record type other than app data once encrypted + #Test 15: Sending an outer record type other than app data once encrypted #should fail $fatal_alert = 0; $proxy->clear(); @@ -222,7 +281,7 @@ sub run_tests NO_DATA_BETWEEN_KEY_UPDATE => 4, }; - #Test 11: Sending a ServerHello which doesn't end on a record boundary + #Test 16: Sending a ServerHello which doesn't end on a record boundary # should fail $fatal_alert = 0; $proxy->clear(); @@ -231,7 +290,7 @@ sub run_tests $proxy->start(); ok($fatal_alert, "Record not on boundary in TLS1.3 (ServerHello)"); - #Test 12: Sending a Finished which doesn't end on a record boundary + #Test 17: Sending a Finished which doesn't end on a record boundary # should fail $fatal_alert = 0; $proxy->clear(); @@ -239,7 +298,7 @@ sub run_tests $proxy->start(); ok($fatal_alert, "Record not on boundary in TLS1.3 (Finished)"); - #Test 13: Sending a KeyUpdate which doesn't end on a record boundary + #Test 18: Sending a KeyUpdate which doesn't end on a record boundary # should fail $fatal_alert = 0; $proxy->clear(); @@ -247,7 +306,7 @@ sub run_tests $proxy->start(); ok($fatal_alert, "Record not on boundary in TLS1.3 (KeyUpdate)"); - #Test 14: Sending application data in the middle of a fragmented KeyUpdate + #Test 19: Sending application data in the middle of a fragmented KeyUpdate # should fail. Strictly speaking this is not a record boundary test # but we use the same filter. $fatal_alert = 0; @@ -256,7 +315,7 @@ sub run_tests $proxy->start(); ok($fatal_alert, "Data between KeyUpdate"); - #Test 15: Fragmented KeyUpdate. This should succeed. Strictly speaking this + #Test 20: Fragmented KeyUpdate. This should succeed. Strictly speaking this # is not a record boundary test but we use the same filter. $proxy->clear(); $boundary_test_type = NO_DATA_BETWEEN_KEY_UPDATE; @@ -266,7 +325,7 @@ sub run_tests SKIP: { skip "EC disabled", 1 if disabled("ec"); - #Test 16: Force an HRR and change the "real" ServerHello to have a protocol + #Test 21: Force an HRR and change the "real" ServerHello to have a protocol # record version of 0x0301 (TLSv1.0). At this point we have already # decided that we are doing TLSv1.3 but are still using plaintext # records. The server should be sending a record version of 0x303 @@ -283,7 +342,7 @@ sub run_tests SKIP: { skip "DTLS only record tests", 1 if $run_test_as_dtls != 1; - #Test 17: We should ignore empty app data records + #Test 22: We should ignore empty app data records $proxy->clear(); $proxy->filter(\&empty_app_data); $proxy->start(); @@ -316,6 +375,7 @@ sub add_empty_recs_filter 0, 0, 0, + 0, "", "" ); @@ -327,6 +387,7 @@ sub add_empty_recs_filter 0, 0, 0, + 0, "", "" ); @@ -347,6 +408,19 @@ sub add_frag_alert_filter return; } + # Add a zero length fragment first + #my $record = TLSProxy::Record->new( + # 0, + # TLSProxy::Record::RT_ALERT, + # TLSProxy::Record::VERS_TLS_1_2, + # 0, + # 0, + # 0, + # "", + # "" + #); + #push @{$proxy->record_list}, $record; + # Now add the alert level (Fatal) as a separate record $byte = pack('C', TLSProxy::Message::AL_LEVEL_FATAL); my $record = TLSProxy::Record->new( @@ -354,6 +428,7 @@ sub add_frag_alert_filter TLSProxy::Record::RT_ALERT, TLSProxy::Record::VERS_TLS_1_2, 1, + 0, 1, 1, $byte, @@ -368,6 +443,7 @@ sub add_frag_alert_filter TLSProxy::Record::RT_ALERT, TLSProxy::Record::VERS_TLS_1_2, 1, + 0, 1, 1, $byte, @@ -376,6 +452,153 @@ sub add_frag_alert_filter push @{$records}, $record; } +sub add_sslv2_filter +{ + my $proxy = shift; + my $clienthello; + my $record; + + # We're only interested in the initial ClientHello + if ($proxy->flight != 0) { + return; + } + + # Ditch the real ClientHello - we're going to replace it with our own + shift @{$proxy->record_list}; + + if ($sslv2testtype == ALERT_BEFORE_SSLV2) { + my $alert = pack('CC', TLSProxy::Message::AL_LEVEL_FATAL, + TLSProxy::Message::AL_DESC_NO_RENEGOTIATION); + my $alertlen = length $alert; + $record = TLSProxy::Record->new( + 0, + TLSProxy::Record::RT_ALERT, + TLSProxy::Record::VERS_TLS_1_2, + $alertlen, + 0, + $alertlen, + $alertlen, + $alert, + $alert + ); + + push @{$proxy->record_list}, $record; + } + + if ($sslv2testtype == ALERT_BEFORE_SSLV2 + || $sslv2testtype == TLSV1_2_IN_SSLV2 + || $sslv2testtype == SSLV2_IN_SSLV2) { + # This is an SSLv2 format ClientHello + $clienthello = + pack "C44", + 0x01, # ClientHello + 0x03, 0x03, #TLSv1.2 + 0x00, 0x03, # Ciphersuites len + 0x00, 0x00, # Session id len + 0x00, 0x20, # Challenge len + 0x00, 0x00, 0x2f, #AES128-SHA + 0x01, 0x18, 0x9F, 0x76, 0xEC, 0x57, 0xCE, 0xE5, 0xB3, 0xAB, 0x79, 0x90, + 0xAD, 0xAC, 0x6E, 0xD1, 0x58, 0x35, 0x03, 0x97, 0x16, 0x10, 0x82, 0x56, + 0xD8, 0x55, 0xFF, 0xE1, 0x8A, 0xA3, 0x2E, 0xF6; # Challenge + + if ($sslv2testtype == SSLV2_IN_SSLV2) { + # Set the version to "real" SSLv2 + vec($clienthello, 1, 8) = 0x00; + vec($clienthello, 2, 8) = 0x02; + } + + my $chlen = length $clienthello; + + $record = TLSProxy::Record->new( + 0, + TLSProxy::Record::RT_HANDSHAKE, + TLSProxy::Record::VERS_TLS_1_2, + $chlen, + 1, #SSLv2 + $chlen, + $chlen, + $clienthello, + $clienthello + ); + + push @{$proxy->record_list}, $record; + } else { + # For this test we're using a real TLS ClientHello + $clienthello = + pack "C49", + 0x01, # ClientHello + 0x00, 0x00, 0x2D, # Message length + 0x03, 0x03, # TLSv1.2 + 0x01, 0x18, 0x9F, 0x76, 0xEC, 0x57, 0xCE, 0xE5, 0xB3, 0xAB, 0x79, 0x90, + 0xAD, 0xAC, 0x6E, 0xD1, 0x58, 0x35, 0x03, 0x97, 0x16, 0x10, 0x82, 0x56, + 0xD8, 0x55, 0xFF, 0xE1, 0x8A, 0xA3, 0x2E, 0xF6, # Random + 0x00, # Session id len + 0x00, 0x04, # Ciphersuites len + 0x00, 0x2f, # AES128-SHA + 0x00, 0xff, # Empty reneg info SCSV + 0x01, # Compression methods len + 0x00, # Null compression + 0x00, 0x00; # Extensions len + + # Split this into 3: A TLS record; a SSLv2 record and a TLS record. + # We deliberately split the second record prior to the Challenge/Random + # and set the first byte of the random to 1. This makes the second SSLv2 + # record look like an SSLv2 ClientHello + my $frag1 = substr $clienthello, 0, 6; + my $frag2 = substr $clienthello, 6, 32; + my $frag3 = substr $clienthello, 38; + + my $fraglen = length $frag1; + $record = TLSProxy::Record->new( + 0, + TLSProxy::Record::RT_HANDSHAKE, + TLSProxy::Record::VERS_TLS_1_2, + $fraglen, + 0, + $fraglen, + $fraglen, + $frag1, + $frag1 + ); + push @{$proxy->record_list}, $record; + + $fraglen = length $frag2; + my $recvers; + if ($sslv2testtype == FRAGMENTED_IN_SSLV2) { + $recvers = 1; + } else { + $recvers = 0; + } + $record = TLSProxy::Record->new( + 0, + TLSProxy::Record::RT_HANDSHAKE, + TLSProxy::Record::VERS_TLS_1_2, + $fraglen, + $recvers, + $fraglen, + $fraglen, + $frag2, + $frag2 + ); + push @{$proxy->record_list}, $record; + + $fraglen = length $frag3; + $record = TLSProxy::Record->new( + 0, + TLSProxy::Record::RT_HANDSHAKE, + TLSProxy::Record::VERS_TLS_1_2, + $fraglen, + 0, + $fraglen, + $fraglen, + $frag3, + $frag3 + ); + push @{$proxy->record_list}, $record; + } + +} + sub add_unknown_record_type { my $proxy = shift; @@ -402,6 +625,7 @@ sub add_unknown_record_type @{$records}[-1]->epoch(), @{$records}[-1]->seq() +1, 1, + 0, 1, 1, "X", @@ -413,6 +637,7 @@ sub add_unknown_record_type TLSProxy::Record::RT_UNKNOWN, @{$records}[-1]->version(), 1, + 0, 1, 1, "X", @@ -556,6 +781,7 @@ sub not_on_record_boundary 0, 0, 0, + 0, "", "" ); @@ -585,6 +811,7 @@ sub not_on_record_boundary 0, 0, 0, + 0, "", "" ); @@ -609,6 +836,7 @@ sub not_on_record_boundary 0, 0, 0, + 0, "", "" ); @@ -629,6 +857,7 @@ sub not_on_record_boundary 0, 0, 0, + 0, "", "" ); @@ -677,6 +906,7 @@ sub empty_app_data 1, 1, length($data), + 0, length($data), 0, $data, diff --git a/test/recipes/70-test_sslsessiontick.t b/test/recipes/70-test_sslsessiontick.t index 8ebbbf2cb9..5dcdea8bc2 100644 --- a/test/recipes/70-test_sslsessiontick.t +++ b/test/recipes/70-test_sslsessiontick.t @@ -27,8 +27,8 @@ plan skip_all => "$test_name needs the module feature enabled" plan skip_all => "$test_name needs the sock feature enabled" if disabled("sock"); -plan skip_all => "$test_name needs TLSv1, TLSv1.1 or TLSv1.2 enabled" - if alldisabled(("tls1", "tls1_1", "tls1_2")); +plan skip_all => "$test_name needs SSLv3, TLSv1, TLSv1.1 or TLSv1.2 enabled" + if alldisabled(("ssl3", "tls1", "tls1_1", "tls1_2")); sub checkmessages($$$$$$); sub clearclient(); @@ -43,8 +43,7 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); #Test 1: By default with no existing session we should get a session ticket diff --git a/test/recipes/70-test_sslsigalgs.t b/test/recipes/70-test_sslsigalgs.t index c4c22df06e..904f7e6e61 100644 --- a/test/recipes/70-test_sslsigalgs.t +++ b/test/recipes/70-test_sslsigalgs.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -33,8 +33,7 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); use constant { @@ -51,8 +50,7 @@ use constant { UNRECOGNIZED_SIGALGS_CERT => 10, UNRECOGNIZED_SIGALG => 11, RSAPSSPSS_SIG_ALG => 12, - MLDSA65_SIG_ALG => 13, - LARGE_NUM_SIG_ALGS => 14 + MLDSA65_SIG_ALG => 13 }; srand(70); @@ -74,7 +72,7 @@ sub randcase { #Test 1: Default sig algs should succeed $proxy->clientflags("-no_tls1_3") if disabled("ec") && disabled("dh"); $proxy->start() or plan skip_all => "Unable to start up Proxy for tests"; -plan tests => 28; +plan tests => 27; ok(TLSProxy::Message->success, "Default sigalgs"); my $testtype; @@ -82,7 +80,7 @@ SKIP: { skip "TLSv1.3 disabled", 7 if disabled("tls1_3") || (disabled("ec") && disabled("dh")); - $proxy->filter(\&modify_sigalgs_filter); + $proxy->filter(\&sigalgs_filter); #Test 2: Sending no sig algs extension in TLSv1.3 should fail $proxy->clear(); @@ -176,7 +174,7 @@ SKIP: { SKIP: { skip "EC or TLSv1.2 disabled", 10 if disabled("tls1_2") || disabled("ec"); - $proxy->filter(\&modify_sigalgs_filter); + $proxy->filter(\&sigalgs_filter); #Test 11: Sending no sig algs extension in TLSv1.2 will make it use # SHA1, which is only supported at security level 0. @@ -259,7 +257,7 @@ SKIP: { $proxy->filter(undef); $proxy->start(); ok(TLSProxy::Message->fail, "No matching TLSv1.2 sigalgs"); - $proxy->filter(\&modify_sigalgs_filter); + $proxy->filter(\&sigalgs_filter); #Test 20: No sig algs extension, ECDSA cert, will use SHA1, # TLSv1.2 should succeed at security level 0 @@ -286,7 +284,7 @@ SKIP: { $dsa_status = $sha1_status = $sha224_status = 0; $proxy->clear(); $proxy->clientflags("-tls1_3"); - $proxy->filter(\&examine_sigalgs_filter); + $proxy->filter(\&modify_sigalgs_filter); $proxy->start(); ok($dsa_status && $sha1_status && $sha224_status, "DSA and SHA1 sigalgs not sent for 1.3-only ClientHello"); @@ -298,7 +296,7 @@ SKIP: { $dsa_status = $sha1_status = $sha224_status = 0; $proxy->clear(); $proxy->clientflags("-cipher AES128-SHA\@SECLEVEL=0"); - $proxy->filter(\&examine_sigalgs_filter); + $proxy->filter(\&modify_sigalgs_filter); $proxy->start(); ok($dsa_status && $sha1_status && $sha224_status, "backwards compatible sigalg sent for compat ClientHello"); @@ -306,7 +304,7 @@ SKIP: { } SKIP: { - skip "TLSv1.3 disabled", 6 + skip "TLSv1.3 disabled", 5 if disabled("tls1_3") || (disabled("ec") && disabled("dh")); #Test 23: Insert signature_algorithms_cert that match normal sigalgs $testtype = SIGALGS_CERT_ALL; @@ -358,17 +356,9 @@ SKIP: { $testtype = UNRECOGNIZED_SIGALG; $proxy->start(); ok(TLSProxy::Message->success(), "Unrecognized sigalg in ClientHello"); - - #Test 28: Insert large number of sig algs. We should ignore any beyond our - # limit but the handshake should still complete successfully. - $testtype = LARGE_NUM_SIG_ALGS; - $proxy->clear(); - $proxy->filter(\&modify_sigalgs_filter); - $proxy->start(); - ok(TLSProxy::Message->success(), "Large number of sigalgs"); } -sub modify_sigalgs_filter +sub sigalgs_filter { my $proxy = shift; @@ -390,12 +380,6 @@ sub modify_sigalgs_filter } elsif ($testtype == NO_PSS_SIG_ALGS) { #No PSS sig algs - just send rsa_pkcs1_sha256 $sigalg = pack "C4", 0x00, 0x02, 0x04, 0x01; - } elsif ($testtype == LARGE_NUM_SIG_ALGS) { - #Send 129 sig algs to test that we correctly ignore those - #beyond our limit of 128 - $sigalg = pack "C260", 0x01, 0x02, - 0x08, 0x04, # rsa_pss_rsae_sha256 - (0xfe, 0x00) x 128; # invalid/reserved sigalg codepoint } else { #PSS sig algs only - just send rsa_pss_rsae_sha256 $sigalg = pack "C4", 0x00, 0x02, 0x08, 0x04; @@ -408,7 +392,7 @@ sub modify_sigalgs_filter } } -sub examine_sigalgs_filter +sub modify_sigalgs_filter { my $proxy = shift; diff --git a/test/recipes/70-test_sslsignature.t b/test/recipes/70-test_sslsignature.t index 27a1ad5f7f..fdfa7f320c 100644 --- a/test/recipes/70-test_sslsignature.t +++ b/test/recipes/70-test_sslsignature.t @@ -33,8 +33,7 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); use constant { @@ -88,7 +87,7 @@ SKIP: { SKIP: { skip "TLS <= 1.2 disabled", 2 - if alldisabled(("tls1", "tls1_1", "tls1_2")); + if alldisabled(("ssl3", "tls1", "tls1_1", "tls1_2")); #Test 3: Corrupting a CertVerify signature in <=TLSv1.2 should fail $proxy->clear(); diff --git a/test/recipes/70-test_sslskewith0p.t b/test/recipes/70-test_sslskewith0p.t index 8b6569a5f4..49f26c1cab 100644 --- a/test/recipes/70-test_sslskewith0p.t +++ b/test/recipes/70-test_sslskewith0p.t @@ -36,8 +36,7 @@ my $proxy = TLSProxy::Proxy->new( \&ske_0_p_filter, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); #We must use an anon DHE cipher for this test diff --git a/test/recipes/70-test_sslversions.t b/test/recipes/70-test_sslversions.t index 6ec62ab4af..e9c2d4ff2c 100644 --- a/test/recipes/70-test_sslversions.t +++ b/test/recipes/70-test_sslversions.t @@ -49,8 +49,7 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); #We're just testing various negative and unusual scenarios here. ssltest with diff --git a/test/recipes/70-test_sslvertol.t b/test/recipes/70-test_sslvertol.t index 8462818ac2..8a675bf7a7 100644 --- a/test/recipes/70-test_sslvertol.t +++ b/test/recipes/70-test_sslvertol.t @@ -33,8 +33,7 @@ my $proxy = TLSProxy::Proxy->new( \&vers_tolerance_filter, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); my @available_tls_versions = (); @@ -94,10 +93,10 @@ SKIP: { "Version tolerance test, max version but not TLS 1.3"); } -#Test 3: Testing something below TLS1.0 should fail. We must disable TLS 1.3 +#Test 3: Testing something below SSLv3 should fail. We must disable TLS 1.3 #to avoid having the 'supported_versions' extension kick in and override our #desires. -$client_version = TLSProxy::Record::VERS_TLS_1_0 - 1; +$client_version = TLSProxy::Record::VERS_SSL_3_0 - 1; $proxy->clear(); $proxy->clientflags("-no_tls1_3"); $proxy->start(); @@ -105,7 +104,7 @@ my $record = pop @{$proxy->record_list}; ok((note("Record version received: ". (defined $record ? $record->version() : "none")), TLSProxy::Message->fail()), - "Version tolerance test, TLS < 1.0"); + "Version tolerance test, SSL < 3.0"); sub vers_tolerance_filter { @@ -120,7 +119,7 @@ sub vers_tolerance_filter if ($message->mt == TLSProxy::Message::MT_CLIENT_HELLO) { #Set the client version #Anything above the max supported version should succeed - #Anything below TLS1.0 should fail + #Anything below SSLv3 should fail $message->client_version($client_version); $message->repack(); } diff --git a/test/recipes/70-test_stime.t b/test/recipes/70-test_stime.t deleted file mode 100644 index 0717224266..0000000000 --- a/test/recipes/70-test_stime.t +++ /dev/null @@ -1,78 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use warnings; - -use IPC::Open3; -use OpenSSL::Test qw/:DEFAULT srctop_file bldtop_file/; -use OpenSSL::Test::Utils; - -my $test_name = "test_stime"; -setup($test_name); - -plan skip_all => "$test_name is not available on $^O" - if $^O =~ /^(VMS|MSWin32|msys)$/; -plan skip_all => "$test_name needs the sock feature enabled" - if disabled("sock"); -plan skip_all => "$test_name needs some TLS protocols to be enabled" - if alldisabled(available_protocols("tls")); -plan skip_all => "$test_name needs ec, ecx or dh for TLS key exchange" - if disabled("ec") && disabled("ecx") && disabled("dh"); - -my $shlib_wrap = bldtop_file("util", "wrap.pl"); -my $apps_openssl = bldtop_file("apps", "openssl"); -my $server_pem = srctop_file("apps", "server.pem"); - -plan tests => 4; - -my @srv_cmd = ("s_server", "-accept", "0", "-cert", $server_pem); -my $srv_pid = open3(my $srv_in, my $srv_out, undef, - $shlib_wrap, $apps_openssl, @srv_cmd); - -my $port = "0"; -while (<$srv_out>) { - chomp; - if (/^ACCEPT 0\.0\.0\.0:(\d+)/) { $port = $1; last; } - elsif (/^ACCEPT \[.*\]:(\d+)/) { $port = $1; last; } - elsif (/^Using default/) { ; } - else { last; } -} - -close $srv_out; - -SKIP: { - skip "Could not start s_server", 4 if $port eq "0"; - - my $connect = "localhost:$port"; - - ok(run(app(["openssl", "s_time", - "-connect", $connect, "-new", "-testmode"])), - "s_time new connections"); - ok(run(app(["openssl", "s_time", - "-connect", $connect, "-reuse", "-testmode"])), - "s_time session reuse"); - - SKIP: { - skip "TLS 1.2 disabled", 1 if disabled("tls1_2"); - ok(run(app(["openssl", "s_time", - "-connect", $connect, "-new", "-tls1_2", "-testmode"])), - "s_time TLSv1.2 new connections"); - } - - SKIP: { - skip "TLS 1.3 disabled", 1 if disabled("tls1_3"); - ok(run(app(["openssl", "s_time", - "-connect", $connect, "-new", "-tls1_3", "-testmode"])), - "s_time TLSv1.3 new connections"); - } -} - -close $srv_in; -kill 'HUP', $srv_pid; -waitpid($srv_pid, 0); diff --git a/test/recipes/70-test_tls13alerts.t b/test/recipes/70-test_tls13alerts.t index a3849ccc36..1858a8d4f2 100644 --- a/test/recipes/70-test_tls13alerts.t +++ b/test/recipes/70-test_tls13alerts.t @@ -33,8 +33,7 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); #Test 1: We test that a server can handle an unencrypted alert when normally the diff --git a/test/recipes/70-test_tls13certcomp.t b/test/recipes/70-test_tls13certcomp.t index f58c285281..57712de7c7 100644 --- a/test/recipes/70-test_tls13certcomp.t +++ b/test/recipes/70-test_tls13certcomp.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -11,7 +11,6 @@ use OpenSSL::Test qw/:DEFAULT cmdstr srctop_file srctop_dir bldtop_dir/; use OpenSSL::Test::Utils; use File::Temp qw(tempfile); use TLSProxy::Proxy; -use TLSProxy::Message; use checkhandshake qw(checkhandshake @handmessages @extensions); use Cwd qw(abs_path); @@ -214,8 +213,7 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); @@ -225,7 +223,7 @@ $proxy->clear(); $proxy->serverflags("-no_tx_cert_comp -no_rx_cert_comp"); # One final skip check $proxy->start() or plan skip_all => "Unable to start up Proxy for tests"; -plan tests => 9; +plan tests => 8; checkhandshake($proxy, checkhandshake::DEFAULT_HANDSHAKE, checkhandshake::DEFAULT_EXTENSIONS | checkhandshake::CERT_COMP_CLI_EXTENSION, @@ -301,42 +299,3 @@ $proxy->start(); checkhandshake($proxy, checkhandshake::DEFAULT_HANDSHAKE, checkhandshake::DEFAULT_EXTENSIONS, "Send but not accept compressed certificates"); - -#Test 9: Excessive uncompressed certificate length in CompressedCertificate -$proxy->clear(); -$proxy->filter(\&excessive_uncompressed_len_filter); -$proxy->serverflags("-cert_comp"); -$proxy->start(); -ok(is_alert_message(TLSProxy::Message::AL_DESC_BAD_CERTIFICATE), - "Excessive uncompressed certificate length rejected"); - -my $done = 0; - -sub excessive_uncompressed_len_filter -{ - my $proxy = shift; - - return if $done; - - foreach my $m (@{$proxy->message_list}) { - next unless $m->mt == TLSProxy::Message::MT_COMPRESSED_CERTIFICATE; - - my $data = $m->data; - # RFC8879 CompressedCertificate: - # uint16 algorithm; uint24 uncompressed_length; ... - substr($data, 2, 3) = "\xFF\xFF\xFF"; # uncompressed_length - $m->data($data); - $m->repack(); - $done = 1; - last; - } -} - -# Test if the last message was a failure and matches the expected type. -sub is_alert_message -{ - my $alert_type = shift; - return 0 unless TLSProxy::Message->fail(); - return 1 if TLSProxy::Message->alert->description() == $alert_type; - return 0; -} diff --git a/test/recipes/70-test_tls13cookie.t b/test/recipes/70-test_tls13cookie.t index 994f2945db..e1c65f2fa4 100644 --- a/test/recipes/70-test_tls13cookie.t +++ b/test/recipes/70-test_tls13cookie.t @@ -31,20 +31,17 @@ plan skip_all => "$test_name needs TLS1.3 enabled" use constant { COOKIE_ONLY => 0, - COOKIE_AND_KEY_SHARE => 1, - EMPTY_COOKIE => 2 + COOKIE_AND_KEY_SHARE => 1 }; my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); my $cookieseen = 0; -my $fatal_alert = 0; my $testtype; #Test 1: Inserting a cookie into an HRR should see it echoed in the ClientHello @@ -59,7 +56,7 @@ if (disabled("ecx")) { $proxy->serverflags("-curves X25519"); } $proxy->start() or plan skip_all => "Unable to start up Proxy for tests"; -plan tests => 3; +plan tests => 2; ok(TLSProxy::Message->success() && $cookieseen == 1, "Cookie seen"); #Test 2: Inserting a cookie into an HRR should see it echoed in the ClientHello @@ -74,41 +71,18 @@ SKIP: { ok(TLSProxy::Message->success() && $cookieseen == 1, "Cookie seen"); } -#Test 3: A client should reject an empty cookie in an HRR -$testtype = EMPTY_COOKIE; -$fatal_alert = 0; -$proxy->clear(); -if (disabled("ecx")) { - $proxy->clientflags("-curves ffdhe3072:ffdhe2048"); - $proxy->serverflags("-curves ffdhe2048"); -} else { - $proxy->clientflags("-curves P-256:X25519"); - $proxy->serverflags("-curves X25519"); -} -$proxy->start(); -ok($fatal_alert, "Empty cookie rejected"); - sub cookie_filter { my $proxy = shift; - if ($testtype == EMPTY_COOKIE && $proxy->flight == 2) { - $fatal_alert = 1 - if @{$proxy->record_list}[-1]->is_fatal_alert(0) - == TLSProxy::Message::AL_DESC_DECODE_ERROR; - return; - } - # We're only interested in the HRR and both ClientHellos return if ($proxy->flight > 2); - my $ext = $testtype == EMPTY_COOKIE - ? pack("n", 0) - : pack("C8", - 0x00, 0x06, #Cookie Length - 0x00, 0x01, #Dummy cookie data (6 bytes) - 0x02, 0x03, - 0x04, 0x05); + my $ext = pack "C8", + 0x00, 0x06, #Cookie Length + 0x00, 0x01, #Dummy cookie data (6 bytes) + 0x02, 0x03, + 0x04, 0x05; foreach my $message (@{$proxy->message_list}) { if ($message->mt == TLSProxy::Message::MT_SERVER_HELLO diff --git a/test/recipes/70-test_tls13downgrade.t b/test/recipes/70-test_tls13downgrade.t index 7d750a292b..6802fbc8ec 100644 --- a/test/recipes/70-test_tls13downgrade.t +++ b/test/recipes/70-test_tls13downgrade.t @@ -34,8 +34,7 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); use constant { diff --git a/test/recipes/70-test_tls13hrr.t b/test/recipes/70-test_tls13hrr.t index c6138b6d29..0ed006a167 100644 --- a/test/recipes/70-test_tls13hrr.t +++ b/test/recipes/70-test_tls13hrr.t @@ -34,8 +34,7 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); use constant { @@ -177,6 +176,7 @@ sub hrr_filter $hrr_record->content_type(), $hrr_record->version(), $hrr_record->len(), + $hrr_record->sslv2(), $hrr_record->len_real(), $hrr_record->decrypt_len(), $hrr_record->data(), diff --git a/test/recipes/70-test_tls13kexmodes.t b/test/recipes/70-test_tls13kexmodes.t index 685adcd5a9..cd71a313b8 100644 --- a/test/recipes/70-test_tls13kexmodes.t +++ b/test/recipes/70-test_tls13kexmodes.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2017-2024 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -70,10 +70,9 @@ plan skip_all => "$test_name needs EC enabled" [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_SUPPORTED_GROUPS, TLSProxy::Message::CLIENT, checkhandshake::DEFAULT_EXTENSIONS], - (disabled("tls1_2") ? () : - [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_EC_POINT_FORMATS, - TLSProxy::Message::CLIENT, - checkhandshake::DEFAULT_EXTENSIONS]), + [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_EC_POINT_FORMATS, + TLSProxy::Message::CLIENT, + checkhandshake::DEFAULT_EXTENSIONS], [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_SIG_ALGS, TLSProxy::Message::CLIENT, checkhandshake::DEFAULT_EXTENSIONS], @@ -124,10 +123,9 @@ plan skip_all => "$test_name needs EC enabled" [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_SUPPORTED_GROUPS, TLSProxy::Message::CLIENT, checkhandshake::DEFAULT_EXTENSIONS], - (disabled("tls1_2") ? () : - [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_EC_POINT_FORMATS, - TLSProxy::Message::CLIENT, - checkhandshake::DEFAULT_EXTENSIONS]), + [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_EC_POINT_FORMATS, + TLSProxy::Message::CLIENT, + checkhandshake::DEFAULT_EXTENSIONS], [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_SIG_ALGS, TLSProxy::Message::CLIENT, checkhandshake::DEFAULT_EXTENSIONS], @@ -193,8 +191,7 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); #Test 1: First get a session diff --git a/test/recipes/70-test_tls13messages.t b/test/recipes/70-test_tls13messages.t index b2e356763c..3a04cca334 100644 --- a/test/recipes/70-test_tls13messages.t +++ b/test/recipes/70-test_tls13messages.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -70,10 +70,9 @@ plan skip_all => "$test_name needs EC enabled" [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_SUPPORTED_GROUPS, TLSProxy::Message::CLIENT, checkhandshake::DEFAULT_EXTENSIONS], - (disabled("tls1_2") ? () : - [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_EC_POINT_FORMATS, - TLSProxy::Message::CLIENT, - checkhandshake::DEFAULT_EXTENSIONS]), + [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_EC_POINT_FORMATS, + TLSProxy::Message::CLIENT, + checkhandshake::DEFAULT_EXTENSIONS], [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_SIG_ALGS, TLSProxy::Message::CLIENT, checkhandshake::DEFAULT_EXTENSIONS], @@ -127,10 +126,9 @@ plan skip_all => "$test_name needs EC enabled" [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_SUPPORTED_GROUPS, TLSProxy::Message::CLIENT, checkhandshake::DEFAULT_EXTENSIONS], - (disabled("tls1_2") ? () : - [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_EC_POINT_FORMATS, - TLSProxy::Message::CLIENT, - checkhandshake::DEFAULT_EXTENSIONS]), + [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_EC_POINT_FORMATS, + TLSProxy::Message::CLIENT, + checkhandshake::DEFAULT_EXTENSIONS], [TLSProxy::Message::MT_CLIENT_HELLO, TLSProxy::Message::EXT_SIG_ALGS, TLSProxy::Message::CLIENT, checkhandshake::DEFAULT_EXTENSIONS], @@ -208,12 +206,8 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); -my $fatal_alert = 0; -my $hello_request_added = 0; -my $hello_request_after_server_hello = 0; #Test 1: Check we get all the right messages for a default handshake (undef, my $session) = tempfile(); @@ -222,7 +216,7 @@ $proxy->cipherc("DEFAULT:\@SECLEVEL=2"); $proxy->clientflags("-no_rx_cert_comp -sess_out ".$session); $proxy->sessionfile($session); $proxy->start() or plan skip_all => "Unable to start up Proxy for tests"; -plan tests => 19; +plan tests => 17; checkhandshake($proxy, checkhandshake::DEFAULT_HANDSHAKE, checkhandshake::DEFAULT_EXTENSIONS, "Default handshake test"); @@ -422,90 +416,4 @@ checkhandshake($proxy, checkhandshake::DEFAULT_HANDSHAKE, | checkhandshake::SUPPORTED_GROUPS_SRV_EXTENSION, "Acceptable but non preferred key_share"); -#Test 18: HelloRequest is reserved in TLSv1.3 -$proxy->clear(); -$fatal_alert = 0; -$hello_request_added = 0; -$hello_request_after_server_hello = 0; -$proxy->filter(\&inject_hello_request); -$proxy->cipherc("DEFAULT:\@SECLEVEL=2"); -$proxy->clientflags("-no_rx_cert_comp"); -$proxy->start(); -ok($fatal_alert, "HelloRequest rejected in TLSv1.3"); - -#Test 19: A HelloRequest received after selecting TLSv1.2 in the initial -# handshake is still ignored, confirming the legacy skip path is -# preserved even when TLSv1.3 was initially enabled. -SKIP: { - skip "TLSv1.2 disabled", 1 if disabled("tls1_2"); - - $proxy->clear(); - $fatal_alert = 0; - $hello_request_added = 0; - $hello_request_after_server_hello = 1; - $proxy->filter(\&inject_hello_request); - $proxy->cipherc("DEFAULT:\@SECLEVEL=2"); - $proxy->clientflags("-no_rx_cert_comp"); - $proxy->serverflags("-no_tls1_3"); - $proxy->start(); - ok(TLSProxy::Message->success() && !$fatal_alert, - "HelloRequest ignored in TLSv1.2"); -} - unlink $session; - -sub inject_hello_request -{ - my $proxy = shift; - my $records = $proxy->record_list; - my $hello_request; - my $record; - my $server_hello_record; - my $i; - - if ($hello_request_added) { - $fatal_alert = 1 - if @{$records}[-1]->is_fatal_alert(0) - == TLSProxy::Message::AL_DESC_UNEXPECTED_MESSAGE; - return; - } - - return if $proxy->flight != 1; - - $hello_request = pack("C4", TLSProxy::Message::MT_HELLO_REQUEST, - 0, 0, 0); - $record = TLSProxy::Record->new( - 1, - TLSProxy::Record::RT_HANDSHAKE, - TLSProxy::Record::VERS_TLS_1_2, - length($hello_request), - length($hello_request), - length($hello_request), - $hello_request, - $hello_request - ); - - if ($hello_request_after_server_hello) { - foreach my $message (@{$proxy->message_list}) { - next if $message->mt != TLSProxy::Message::MT_SERVER_HELLO - || ${$message->records}[0]->flight != 1; - - $server_hello_record = @{$message->records}[-1]; - last; - } - - return if !defined $server_hello_record; - - for ($i = 0; $i < @{$records}; $i++) { - last if ${$records}[$i] == $server_hello_record; - } - $i++; - } else { - for ($i = 0; ${$records}[$i]->flight() < 1; $i++) { - next; - } - } - - splice @{$records}, $i, 0, $record; - $hello_request_added = 1; -} diff --git a/test/recipes/70-test_tls13psk.t b/test/recipes/70-test_tls13psk.t index d15f838e9d..3de688ec74 100644 --- a/test/recipes/70-test_tls13psk.t +++ b/test/recipes/70-test_tls13psk.t @@ -34,14 +34,12 @@ my $proxy = TLSProxy::Proxy->new( undef, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); use constant { PSK_LAST_FIRST_CH => 0, - ILLEGAL_EXT_SECOND_CH => 1, - TOO_MANY_PSKS => 2 + ILLEGAL_EXT_SECOND_CH => 1 }; #Most PSK tests are done in test_ssl_new. This tests various failure scenarios @@ -53,7 +51,7 @@ $proxy->clientflags("-sess_out ".$session); $proxy->serverflags("-servername localhost"); $proxy->sessionfile($session); $proxy->start() or plan skip_all => "Unable to start up Proxy for tests"; -plan tests => 7; +plan tests => 5; ok(TLSProxy::Message->success(), "Initial connection"); #Test 2: Attempt a resume with PSK not in last place. Should fail @@ -113,64 +111,27 @@ $proxy->filter(\&remove_sig_algs_filter); $proxy->start(); ok(TLSProxy::Message->success(), "Remove sig algs"); -#Test 6: Attempt a resume with too many PSKs. Handshake should still succeed. -# It will just ignore the PSKs. -$proxy->clear(); -$proxy->clientflags("-sess_in ".$session); -$proxy->filter(\&modify_psk_filter); -$testtype = TOO_MANY_PSKS; -$proxy->start(); -ok(TLSProxy::Message->success(), "Too many PSKs"); - -my $proxy2 = TLSProxy::Proxy->new( - undef, - cmdstr(app(["openssl"]), display => 1), - undef, # Deliberately set to no_cert to force a PSK-only server - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() -); - -#Test 7: Attempt an invalid resume, with a server that can only do PSK. -# Should be treated the same as an invalid binder (decrypt_error) -# as per RFC8446 Appendix E.6 -$proxy2->clear(); -$proxy2->clientflags("-sess_in ".$session); -$proxy2->serverflags("-psk ffeeddccbbaa99887766554433221100 -no_ticket"); -$proxy2->start() or die "Failed to start proxy2"; -ok(is_decode_error_server_alert(), "Bad PSK with no handshake fallback"); - unlink $session; -sub is_decode_error_server_alert -{ - return 0 unless TLSProxy::Message->fail(); - - my $alert = TLSProxy::Message->alert(); - return 1 if $alert->server() - && $alert->description() - == TLSProxy::Message::AL_DESC_DECRYPT_ERROR; - return 0; -} - sub modify_psk_filter { my $proxy = shift; my $flight; my $message; - if ($testtype == ILLEGAL_EXT_SECOND_CH) { - $flight = 2; - } else { + if ($testtype == PSK_LAST_FIRST_CH) { $flight = 0; + } else { + $flight = 2; } # Only look at the first or second ClientHello return if $proxy->flight != $flight; - if ($testtype == ILLEGAL_EXT_SECOND_CH) { - $message = ${$proxy->message_list}[2]; - } else { + if ($testtype == PSK_LAST_FIRST_CH) { $message = ${$proxy->message_list}[0]; + } else { + $message = ${$proxy->message_list}[2]; } return if (!defined $message @@ -178,20 +139,9 @@ sub modify_psk_filter if ($testtype == PSK_LAST_FIRST_CH) { $message->set_extension(TLSProxy::Message::EXT_FORCE_LAST, ""); - } elsif ($testtype == ILLEGAL_EXT_SECOND_CH) { + } else { #Deliberately break the connection $message->set_extension(TLSProxy::Message::EXT_SUPPORTED_GROUPS, ""); - } else { - my $psklist = pack "C*", - 0x00, 0x77, #Identities length - (( - 0x00, 0x01, #Identity length - 0x01, #Identity data - 0x00, 0x00, 0x00, 0x00 #Obfuscated ticket age - ) x 17), #17 identities - 0x00, 0x22, #Binder length - (0x01) x 34; #17 fake binders, each with 1 length byte, and 1 payload byte - $message->set_extension(TLSProxy::Message::EXT_PSK, $psklist); } $message->repack(); } diff --git a/test/recipes/70-test_tls13ticket.t b/test/recipes/70-test_tls13ticket.t deleted file mode 100644 index 5bd745d6dd..0000000000 --- a/test/recipes/70-test_tls13ticket.t +++ /dev/null @@ -1,28 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use OpenSSL::Test::Simple; -use OpenSSL::Test qw/:DEFAULT srctop_file/; -use OpenSSL::Test::Utils qw(disabled); - -setup("test_tls13ticket"); - -plan skip_all => "needs TLSv1.3 enabled" - if disabled("tls1_3"); - -plan skip_all => "needs TLSv1.2 enabled" - if disabled("tls1_2"); - -plan skip_all => "needs ECX enabled" - if disabled("ecx"); - -plan tests => 1; - -ok(run(test(["tls13ticket_test", srctop_file("apps", "server.pem"), - srctop_file("apps", "server.pem")])), - "running tls13ticket_test"); diff --git a/test/recipes/70-test_tls_groups_list.t b/test/recipes/70-test_tls_groups_list.t deleted file mode 100644 index e200a63d0c..0000000000 --- a/test/recipes/70-test_tls_groups_list.t +++ /dev/null @@ -1,17 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use OpenSSL::Test::Simple; -use OpenSSL::Test qw/:DEFAULT/; -use OpenSSL::Test::Utils qw(disabled); - -setup("test_tls_groups_list"); - -plan skip_all => "needs EC and ECX enabled" if disabled("ecx"); - -simple_test("test_tls_groups_list", "tls_groups_list_test"); diff --git a/test/recipes/70-test_tlsextms.t b/test/recipes/70-test_tlsextms.t index 0e5f5d44b8..feccd5a888 100644 --- a/test/recipes/70-test_tlsextms.t +++ b/test/recipes/70-test_tlsextms.t @@ -44,8 +44,7 @@ my $proxy = TLSProxy::Proxy->new( \&extms_filter, cmdstr(app(["openssl"]), display => 1), srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() + (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}) ); #Note that EXTMS is only relevant for "TLSProxy isn't usable on $^O" - if $^O =~ /^(VMS)$/; -plan skip_all => "$test_name needs the sock feature enabled" - if disabled("sock"); -plan skip_all => "No TLS protocols are supported by this OpenSSL build" - if alldisabled(available_protocols("tls")); -plan skip_all => "$test_name needs the module feature enabled" - if disabled("module"); -plan skip_all => "$test_name needs the psk feature enabled" - if disabled("psk"); - -$ENV{OPENSSL_MODULES} = abs_path(bldtop_dir("test")); - -my $psk = "0102030405060708090a0b0c0d0e0f10"; - -my $proxy = TLSProxy::Proxy->new( - undef, - cmdstr(app(["openssl"]), display => 1), - srctop_file("apps", "server.pem"), - (!$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}), - have_IPv6() -); - -$proxy->start() or plan skip_all => "Unable to start up Proxy for tests"; - -my $tls13_disabled = disabled("tls1_3") || (disabled("ec") && disabled("dh")); -my $tls12_disabled = disabled("tls1_2"); -plan skip_all => "$test_name needs TLSv1.2 or TLSv1.3 enabled" - if $tls13_disabled && $tls12_disabled; -plan tests => 6; - -my $psk_ext_in_ch = 0; -my $psk_ext_in_sh = 0; - -SKIP: { - skip "TLS 1.3 disabled", 4 - if disabled("tls1_3") || (disabled("ec") && disabled("dh")); - - my $flags = "-tls1_3 -no_rx_cert_comp"; - - # psk_use_session_cb (client) / psk_find_session_cb (server). - $proxy->clear(); - $proxy->clientflags("-psk $psk $flags"); - $proxy->serverflags("-psk $psk $flags"); - $proxy->filter(undef); - $proxy->start(); - ok(TLSProxy::Message->success(), "TLS 1.3 PSK connection"); - - $proxy->clear(); - $proxy->clientflags("-psk $psk $flags"); - $proxy->serverflags("-psk $psk $flags"); - $psk_ext_in_ch = 0; - $proxy->filter(\&check_psk_in_ch); - $proxy->start(); - ok($psk_ext_in_ch, "PSK extension present in TLS 1.3 ClientHello"); - - # psk_find_session_cb returns *sess = NULL on mismatch; falls back to cert. - $proxy->clear(); - $proxy->clientflags("-psk $psk -psk_identity other_id $flags"); - $proxy->serverflags("-psk $psk $flags"); - $proxy->filter(undef); - $proxy->start(); - ok(TLSProxy::Message->success(), - "TLS 1.3 PSK identity mismatch falls back to certificate auth"); - - $proxy->clear(); - $proxy->clientflags("-psk $psk -psk_identity other_id $flags"); - $proxy->serverflags("-psk $psk $flags"); - $psk_ext_in_sh = 0; - $proxy->filter(\&check_psk_in_sh); - $proxy->start(); - ok(!$psk_ext_in_sh, - "No PSK in ServerHello when TLS 1.3 identity mismatches"); -} - -SKIP: { - skip "TLS 1.2 disabled", 2 if disabled("tls1_2"); - - # PSK-AES128-CBC-SHA is required here: TLSProxy's record layer only handles - # CBC correctly (it strips IV + padding + MAC as fixed offset bytes). - # GCM ciphers use a different wire layout and confuse the decryption stub, - # making close_notify detection fail even on a successful connection. - my $psk_cipher = "PSK-AES128-CBC-SHA:\@SECLEVEL=0"; - my $flags = "-tls1_2 -no_rx_cert_comp"; - - # psk_client_cb (client) / psk_server_cb (server). - $proxy->clear(); - $proxy->ciphers($psk_cipher); - $proxy->cipherc($psk_cipher); - $proxy->clientflags("-psk $psk $flags"); - $proxy->serverflags("-psk $psk $flags"); - $proxy->filter(undef); - $proxy->start(); - ok(TLSProxy::Message->success(), "TLS 1.2 PSK connection"); - - # psk_server_cb accepts regardless of identity and only logs a warning. - $proxy->clear(); - $proxy->ciphers($psk_cipher); - $proxy->cipherc($psk_cipher); - $proxy->clientflags("-psk $psk -psk_identity other_id $flags"); - $proxy->serverflags("-psk $psk $flags"); - $proxy->filter(undef); - $proxy->start(); - ok(TLSProxy::Message->success(), - "TLS 1.2 PSK identity mismatch succeeds with warning"); -} - -sub check_psk_in_ch -{ - my $proxy = shift; - - return if $proxy->flight != 0; - - foreach my $message (@{$proxy->message_list}) { - next unless $message->mt == TLSProxy::Message::MT_CLIENT_HELLO; - $psk_ext_in_ch = 1 - if defined ${$message->extension_data}{TLSProxy::Message::EXT_PSK}; - } -} - -sub check_psk_in_sh -{ - my $proxy = shift; - - return if $proxy->flight != 1; - - foreach my $message (@{$proxy->message_list}) { - next unless $message->mt == TLSProxy::Message::MT_SERVER_HELLO; - $psk_ext_in_sh = 1 - if defined ${$message->extension_data}{TLSProxy::Message::EXT_PSK}; - } -} diff --git a/test/recipes/75-test_quicapi.t b/test/recipes/75-test_quicapi.t index cb19cdb2e4..7056ad17b0 100644 --- a/test/recipes/75-test_quicapi.t +++ b/test/recipes/75-test_quicapi.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2022-2023 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -25,17 +25,6 @@ plan skip_all => "QUIC protocol is not supported by this OpenSSL build" plan skip_all => "These tests are not supported in a fuzz build" if config('options') =~ /-DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION|enable-fuzz-afl/; -# When we support ECH, the ECH compression scheme affects the ordering -# of extensions in the ClientHello as the set of compressed extensions -# need to be contiguous in the outer ClientHello. We would need different -# trace files to compare against for this test in ECH builds vs. 'no-ech' -# buiids, so we'll just skip this test in 'no-ech' builds.. -# Note that that ordering will be affected if the ECH compression -# choices are changed - see the comments in ssl/statem/extensions.c -# where those choices are embedded in the ext_defs table. -plan skip_all => "QUIC API trace tests aren't done in no-ech builds" - if disabled('ech'); - plan tests => ($no_fips ? 0 : 1) # quicapitest with fips + 1; # quicapitest with default provider diff --git a/test/recipes/75-test_quicapi_data/ssltraceref-zlib.txt b/test/recipes/75-test_quicapi_data/ssltraceref-zlib.txt index 1bce022109..535b37b2bd 100644 --- a/test/recipes/75-test_quicapi_data/ssltraceref-zlib.txt +++ b/test/recipes/75-test_quicapi_data/ssltraceref-zlib.txt @@ -19,19 +19,20 @@ Header: 000f - 01 02 04 04 80 0c 00 00-05 04 80 08 00 00 06 ............... 001e - 04 80 08 00 00 07 04 80-08 00 00 08 02 40 64 .............@d 002d - 09 02 40 64 ..@d - extension_type=supported_groups(10), length=24 + extension_type=ec_point_formats(11), length=2 + uncompressed (0) + extension_type=supported_groups(10), length=18 X25519MLKEM768 (4588) - SecP256r1MLKEM768 (4587) - curveSM2MLKEM768 (4590) ecdh_x25519 (29) secp256r1 (P-256) (23) ecdh_x448 (30) secp384r1 (P-384) (24) secp521r1 (P-521) (25) - curveSM2 (41) ffdhe2048 (256) ffdhe3072 (257) extension_type=session_ticket(35), length=0 + extension_type=application_layer_protocol_negotiation(16), length=11 + ossltest extension_type=encrypt_then_mac(22), length=0 extension_type=extended_master_secret(23), length=0 extension_type=signature_algorithms(13), length=? @@ -55,19 +56,6 @@ Header: rsa_pkcs1_sha256 (0x0401) rsa_pkcs1_sha384 (0x0501) rsa_pkcs1_sha512 (0x0601) - slhdsa_sha2_128s (0x0911) - slhdsa_sha2_128f (0x0912) - slhdsa_sha2_192s (0x0913) - slhdsa_sha2_192f (0x0914) - slhdsa_sha2_256s (0x0915) - slhdsa_sha2_256f (0x0916) - slhdsa_shake_128s (0x0917) - slhdsa_shake_128f (0x0918) - slhdsa_shake_192s (0x0919) - slhdsa_shake_192f (0x091a) - slhdsa_shake_256s (0x091b) - slhdsa_shake_256f (0x091c) - sm2sig_sm3 (0x0708) extension_type=supported_versions(43), length=3 TLS 1.3 (772) extension_type=psk_key_exchange_modes(45), length=2 @@ -79,8 +67,6 @@ Header: key_exchange: (len=32): ? extension_type=compress_certificate(27), length=3 zlib (1) - extension_type=application_layer_protocol_negotiation(16), length=11 - ossltest Sent Frame: Crypto Offset: 0 diff --git a/test/recipes/75-test_quicapi_data/ssltraceref.txt b/test/recipes/75-test_quicapi_data/ssltraceref.txt index 300b4ca456..c5502b68a7 100644 --- a/test/recipes/75-test_quicapi_data/ssltraceref.txt +++ b/test/recipes/75-test_quicapi_data/ssltraceref.txt @@ -19,19 +19,20 @@ Header: 000f - 01 02 04 04 80 0c 00 00-05 04 80 08 00 00 06 ............... 001e - 04 80 08 00 00 07 04 80-08 00 00 08 02 40 64 .............@d 002d - 09 02 40 64 ..@d - extension_type=supported_groups(10), length=24 + extension_type=ec_point_formats(11), length=2 + uncompressed (0) + extension_type=supported_groups(10), length=18 X25519MLKEM768 (4588) - SecP256r1MLKEM768 (4587) - curveSM2MLKEM768 (4590) ecdh_x25519 (29) secp256r1 (P-256) (23) ecdh_x448 (30) secp384r1 (P-384) (24) secp521r1 (P-521) (25) - curveSM2 (41) ffdhe2048 (256) ffdhe3072 (257) extension_type=session_ticket(35), length=0 + extension_type=application_layer_protocol_negotiation(16), length=11 + ossltest extension_type=encrypt_then_mac(22), length=0 extension_type=extended_master_secret(23), length=0 extension_type=signature_algorithms(13), length=? @@ -55,19 +56,6 @@ Header: rsa_pkcs1_sha256 (0x0401) rsa_pkcs1_sha384 (0x0501) rsa_pkcs1_sha512 (0x0601) - slhdsa_sha2_128s (0x0911) - slhdsa_sha2_128f (0x0912) - slhdsa_sha2_192s (0x0913) - slhdsa_sha2_192f (0x0914) - slhdsa_sha2_256s (0x0915) - slhdsa_sha2_256f (0x0916) - slhdsa_shake_128s (0x0917) - slhdsa_shake_128f (0x0918) - slhdsa_shake_192s (0x0919) - slhdsa_shake_192f (0x091a) - slhdsa_shake_256s (0x091b) - slhdsa_shake_256f (0x091c) - sm2sig_sm3 (0x0708) extension_type=supported_versions(43), length=3 TLS 1.3 (772) extension_type=psk_key_exchange_modes(45), length=2 @@ -77,8 +65,6 @@ Header: key_exchange: (len=1216): ? NamedGroup: ecdh_x25519 (29) key_exchange: (len=32): ? - extension_type=application_layer_protocol_negotiation(16), length=11 - ossltest Sent Frame: Crypto Offset: 0 diff --git a/test/recipes/80-test_ca.t b/test/recipes/80-test_ca.t index 95e21b92ab..5fc620a139 100644 --- a/test/recipes/80-test_ca.t +++ b/test/recipes/80-test_ca.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -72,7 +72,10 @@ SKIP: { is(yes(cmdstr(app(["openssl", "ca", "-config", $cnf, "-in", src_file("sm2-csr.pem"), - "-out", "sm2-test.crt", "-md", "sm3", + "-out", "sm2-test.crt", + "-sigopt", "distid:1234567812345678", + "-vfyopt", "distid:1234567812345678", + "-md", "sm3", "-cert", src_file("sm2-root.crt"), "-keyfile", src_file("sm2-root.key")]))), 0, @@ -80,9 +83,9 @@ SKIP: { } my $v3_cert = "v3-test.crt"; -ok(run(app(["openssl", "ca", "-batch", "-config", $cnf, "-extensions", "minimal", +ok(run(app(["openssl", "ca", "-batch", "-config", $cnf, "-extensions", "empty", "-in", src_file("x509-check.csr"), "-out", $v3_cert]))); -# The "minimal" extensions include SKID and AKID. +# although no explicit extensions given: has_version($v3_cert, 3); has_SKID($v3_cert, 1); has_AKID($v3_cert, 1); diff --git a/test/recipes/80-test_cmp_http.t b/test/recipes/80-test_cmp_http.t index 24ec6cd756..63b25259f5 100644 --- a/test/recipes/80-test_cmp_http.t +++ b/test/recipes/80-test_cmp_http.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2007-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved. # Copyright Nokia 2007-2019 # Copyright Siemens AG 2015-2019 # @@ -56,7 +56,7 @@ my @app = qw(openssl cmp); # the server-dependent client configuration consists of: my $ca_dn; # The CA's Distinguished Name my $server_dn; # The server's Distinguished Name -my $server_host;# The server's hostname or IP address, '*' means to be determined from server output +my $server_host;# The server's hostname or IP address my $server_port;# The server's port my $server_tls; # The server's TLS port, if any, or 0 my $server_path;# The server's CMP alias @@ -328,14 +328,12 @@ sub start_server { print "$server_name server PID=$pid\n"; if ($server_host eq '*' || $server_port == 0) { - my $server_output = ""; - # Determine the actual server host and port and possibly different PID from server output + # Find out the actual server host and port and possibly different PID my ($host, $port); my $pid0 = $pid; while (<$server_fh>) { - $server_output .= $_; print "$server_name server output: $_"; - next if m/[Uu]sing section/; + next if m/using section/; s/\R$//; # Better chomp ($host, $port, $pid) = ($1, $2, $3) if /^ACCEPT\s(.*?):(\d+) PID=(\d+)$/; @@ -351,11 +349,11 @@ sub start_server { kill('KILL', $pid0); waitpid($pid0, 0); } - if ($server_host eq '*' || $server_port == 0) { - stop_server($server_name, $pid) if $pid; - print "Cannot get server host and port from the $server_name server output: $server_output\n"; - return 0; - } + } + if ($server_host eq '*' || $server_port == 0) { + stop_server($server_name, $pid) if $pid; + print "Cannot get expected output from the $server_name server\n"; + return 0; } $kur_port = $server_port if $kur_port eq "\$server_port"; $pbm_port = $server_port if $pbm_port eq "\$server_port"; diff --git a/test/recipes/80-test_cmp_http_data/Mock/test.cnf b/test/recipes/80-test_cmp_http_data/Mock/test.cnf index 7450eb692a..3276001fec 100644 --- a/test/recipes/80-test_cmp_http_data/Mock/test.cnf +++ b/test/recipes/80-test_cmp_http_data/Mock/test.cnf @@ -18,7 +18,7 @@ policies = certificatePolicies [Mock] # the built-in OpenSSL CMP mock server # no_check_time = 1 server_host = * # to be determined by server: 127.0.0.1 or ::1 (localhost) -server_port = 0 # 0 means that the port is determined from server output +server_port = 0 # 0 means that the port is determined by the server server_tls = $server_port server_cert = server.crt # server = $server_host:$server_port diff --git a/test/recipes/80-test_cmp_http_data/test_commands.csv b/test/recipes/80-test_cmp_http_data/test_commands.csv index 9e77baa4b1..c6c54239b1 100644 --- a/test/recipes/80-test_cmp_http_data/test_commands.csv +++ b/test/recipes/80-test_cmp_http_data/test_commands.csv @@ -147,7 +147,6 @@ expected,description, -section,val, -cmd,val,val2, -cacertsout,val,val2, -infoty 0,using popo 1 with -centralkeygen, -section,, -cmd,cr,, -centralkeygen, -popo,1, -newkeyout,_RESULT_DIR/newkeyout.pem 1, using popo -1 redundantly with -centralkeygen, -section,, -cmd,cr,, -centralkeygen, -popo,-1, -newkeyout,_RESULT_DIR/newkeyout2.pem 1, using popo -1 alternatively to -centralkeygen, -section,, -cmd,cr,, -popo,-1, -newkeyout,_RESULT_DIR/newkeyout3.pem, -newkeypass,pass:12345, -certout,_RESULT_DIR/test.cert3.pem -1, using centrally generated key (and cert) with existing chain, -section,, -cmd,cr,,-cert,_RESULT_DIR/test.cert3.pem, -key,_RESULT_DIR/newkeyout3.pem, -keypass,pass:12345, -extracerts, issuing.crt -1, using centrally generated key (and cert) without giving chain (requires sender cert caching), -section,, -cmd,cr,,-cert,_RESULT_DIR/test.cert3.pem, -key,_RESULT_DIR/newkeyout3.pem, -keypass,pass:12345, -extracerts, "" +1, using centrally generated key (and cert) , -section,, -cmd,cr,,-cert,_RESULT_DIR/test.cert3.pem, -key,_RESULT_DIR/newkeyout3.pem, -keypass,pass:12345 0, using centrally generated key with wrong password, -section,, -cmd,cr,,-cert,_RESULT_DIR/test.cert3.pem, -key,_RESULT_DIR/newkeyout3.pem, -keypass,pass:wrong 0, using popo -1 (instead of -centralkeygen) without -newkeyout, -section,, -cmd,cr,, -popo,-1,,BLANK,,BLANK,,BLANK,,BLANK diff --git a/test/recipes/80-test_cmp_http_data/test_enrollment.csv b/test/recipes/80-test_cmp_http_data/test_enrollment.csv index ab348af3a0..a66afdc837 100644 --- a/test/recipes/80-test_cmp_http_data/test_enrollment.csv +++ b/test/recipes/80-test_cmp_http_data/test_enrollment.csv @@ -47,10 +47,6 @@ expected,description, -section,val, -cmd,val, -newkey,val,val, -newkeypass,val, 1,sans critical, -section,, -cmd,ir, -newkey,new.key,, -newkeypass,pass:,,,BLANK,,,,BLANK,, -sans,critical,BLANK,,BLANK,,BLANK,,BLANK,, -certout,_RESULT_DIR/test.certout_sans_critical.pem,, -out_trusted,root.crt,,BLANK,,BLANK,,, 1,sans 2 dns, -section,, -cmd,ir, -newkey,new.key,, -newkeypass,pass:,,,BLANK,,,,BLANK,, -sans,localhost test,BLANK,,BLANK,,BLANK,,BLANK,, -certout,_RESULT_DIR/test.certout_sans_two_dns.pem,, -out_trusted,root.crt,,BLANK,,BLANK,,, 1,sans 1 dns 1 ip, -section,, -cmd,ir, -newkey,new.key,, -newkeypass,pass:,,,BLANK,,,,BLANK,, -sans,localhost 127.0.0.1,BLANK,,BLANK,,BLANK,,BLANK,, -certout,_RESULT_DIR/test.certout_sans_dns_ip.pem,, -out_trusted,root.crt,,BLANK,,BLANK,,, -1,sans dns comma ip, -section,, -cmd,ir, -newkey,new.key,, -newkeypass,pass:,,,BLANK,,,,BLANK,, -sans,'DNS:localhost,IP:127.0.0.1' ,BLANK,,BLANK,,BLANK,,BLANK,, -certout,_RESULT_DIR/test.certout_sans_dns_ip1.pem -1,sans dns space comma ip, -section,, -cmd,ir, -newkey,new.key,, -newkeypass,pass:,,,BLANK,,,,BLANK,, -sans,'DNS:localhost ,IP:127.0.0.1' ,BLANK,,BLANK,,BLANK,,BLANK,, -certout,_RESULT_DIR/test.certout_sans_dns_ip2.pem -1,sans dns comma space ip, -section,, -cmd,ir, -newkey,new.key,, -newkeypass,pass:,,,BLANK,,,,BLANK,, -sans,'DNS:localhost, IP:127.0.0.1' ,BLANK,,BLANK,,BLANK,,BLANK,, -certout,_RESULT_DIR/test.certout_sans_dns_ip3.pem -1,sans dns space comma space ip, -section,, -cmd,ir, -newkey,new.key,, -newkeypass,pass:,,,BLANK,,,,BLANK,, -sans,'DNS:localhost , IP:127.0.0.1',BLANK,,BLANK,,BLANK,,BLANK,, -certout,_RESULT_DIR/test.certout_sans_dns_ip4.pem 1,sans 2 ip, -section,, -cmd,ir, -newkey,new.key,, -newkeypass,pass:,,,BLANK,,,,BLANK,, -sans,127.0.0.1 1.2.3.4,BLANK,,BLANK,,BLANK,,BLANK,, -certout,_RESULT_DIR/test.certout_sans_two_ip.pem,, -out_trusted,root.crt,,BLANK,,BLANK,,, 1,sans 1 uri, -section,, -cmd,ir, -newkey,new.key,, -newkeypass,pass:,,,BLANK,,,,BLANK,, -sans,https://www.sample.com,BLANK,,BLANK,,BLANK,,BLANK,, -certout,_RESULT_DIR/test.certout_sans_uri.pem,, -out_trusted,root.crt,,BLANK,,BLANK,,, 1,san_nodefault, -section,, -cmd,ir, -newkey,new.key,, -newkeypass,pass:,,,BLANK,,,,BLANK,, -sans,127.0.0.1 1.2.3.4, -san_nodefault,,BLANK,,BLANK,,BLANK,, -certout,_RESULT_DIR/test.certout_sans_nodefault.pem,, -out_trusted,root.crt,,BLANK,,BLANK,,, diff --git a/test/recipes/80-test_cms.t b/test/recipes/80-test_cms.t index 7516cf024e..8a5cfac69c 100644 --- a/test/recipes/80-test_cms.t +++ b/test/recipes/80-test_cms.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -44,8 +44,6 @@ my $provname = 'default'; my $dsaallow = '1'; my $no_pqc = 0; my $no_hkdf_fixed = 0; -my $no_x963kdf = disabled("x963kdf"); -my $no_x942kdf = disabled("x942kdf"); my $datadir = srctop_dir("test", "recipes", "80-test_cms_data"); my $smdir = srctop_dir("test", "smime-certs"); @@ -56,7 +54,7 @@ my ($no_des, $no_dh, $no_dsa, $no_ec, $no_ec2m, $no_rc2, $no_zlib) $no_rc2 = 1 if disabled("legacy"); -plan tests => 40; +plan tests => 34; ok(run(test(["pkcs7_test"])), "test pkcs7"); @@ -121,16 +119,6 @@ my @smime_pkcs7_tests = ( \&final_compare ], - [ "signed content DER format, two RSA signers with explicit -inkey", - [ "{cmd1}", @prov, "-sign", "-in", $smcont, "-outform", "DER", "-nodetach", - "-signer", catfile($smdir, "smrsa3-cert.pem"), - "-inkey", catfile($smdir, "smrsa3-key.pem"), - "-signer", $smrsa1, "-out", "{output}.cms" ], - [ "{cmd2}", @prov, "-verify", "-in", "{output}.cms", "-inform", "DER", - "-CAfile", $smroot, "-out", "{output}.txt" ], - \&final_compare - ], - [ "signed content DER format, DSA key", [ "{cmd1}", @prov, "-sign", "-in", $smcont, "-outform", "DER", "-nodetach", "-signer", catfile($smdir, "smdsa1.pem"), "-out", "{output}.cms" ], @@ -382,10 +370,10 @@ my @smime_cms_tests = ( [ "{cmd1}", @prov, "-encrypt", "-in", $smcont, "-outform", "PEM", "-aes-128-gcm", "-kekcipher", "aes-128-cbc", "-stream", "-out", "{output}.cms", - "-pwri_password", "testtest" ], + "-pwri_password", "test" ], [ "{cmd2}", "-decrypt", "-in", "{output}.cms", "-out", "{output}.txt", "-inform", "PEM", - "-pwri_password", "testtest" ], + "-pwri_password", "test" ], \&final_compare ], @@ -403,10 +391,10 @@ my @smime_cms_tests = ( [ "enveloped content test streaming PEM format, AES-128-CBC cipher, password", [ "{cmd1}", @prov, "-encrypt", "-in", $smcont, "-outform", "PEM", "-aes128", "-stream", "-out", "{output}.cms", - "-pwri_password", "testtest" ], + "-pwri_password", "test" ], [ "{cmd2}", @prov, "-decrypt", "-in", "{output}.cms", "-out", "{output}.txt", "-inform", "PEM", - "-pwri_password", "testtest" ], + "-pwri_password", "test" ], \&final_compare ], @@ -706,7 +694,7 @@ my @smime_cms_param_tests = ( ] ); -if (!$no_x942kdf && ($no_fips || $old_fips)) { +if ($no_fips || $old_fips) { # Only SHA1 supported in dh_cms_encrypt() push(@smime_cms_param_tests, @@ -822,18 +810,6 @@ sub zero_compare { return (-e "$opts{output}.txt" && -z "$opts{output}.txt"); } -sub read_file_text { - my ($file) = @_; - open(my $fh, "<", $file) or return undef; - binmode $fh; - local $/; - my $data = <$fh>; - close($fh); - # Normalise line endings as -out is written in text mode on Windows. - $data =~ s/\r\n/\n/g if defined $data; - return $data; -} - subtest "CMS => PKCS#7 compatibility tests\n" => sub { plan tests => scalar @smime_pkcs7_tests; @@ -1029,7 +1005,7 @@ subtest "CMS Decrypt message encrypted with OpenSSL 1.1.1\n" => sub { SKIP: { skip "EC or DES isn't supported in this build", 1 - if disabled("ec") || disabled("des") || disabled("x963kdf"); + if disabled("ec") || disabled("des"); my $out = "smtst.txt"; @@ -1042,33 +1018,6 @@ subtest "CMS Decrypt message encrypted with OpenSSL 1.1.1\n" => sub { } }; -subtest "CMS decrypt authEnvelopedData with authenticated attributes\n" => sub { - plan tests => 4; - - # BouncyCastle AES-128-GCM authEnvelopedData (KEK) carrying authAttrs; - # a clean decrypt confirms the authAttrs are verified as the AEAD AAD. - 1 while unlink "authattrs.txt"; - ok(run(app(["openssl", "cms", @defaultprov, "-decrypt", "-inform", "PEM", - "-secretkey", "000102030405060708090A0B0C0D0E0F", - "-secretkeyid", "C0FEE0", - "-in", catfile($datadir, "authenveloped_attrs.pem"), - "-out", "authattrs.txt" ])), - "decrypt authEnvelopedData with authAttrs"); - is(read_file_text("authattrs.txt"), "Hello AuthEnvelopedData world\n", - "decrypted authEnvelopedData plaintext matches expected"); - - # A flipped authAttrs byte must fail the tag check and leave -out empty. - 1 while unlink "bad_authattrs.txt"; - ok(!run(app(["openssl", "cms", @defaultprov, "-decrypt", "-inform", "PEM", - "-secretkey", "000102030405060708090A0B0C0D0E0F", - "-secretkeyid", "C0FEE0", - "-in", catfile($datadir, "bad_authenveloped_attrs.pem"), - "-out", "bad_authattrs.txt" ])), - "reject authEnvelopedData with tampered authAttrs"); - ok(!-s "bad_authattrs.txt", - "tampered authEnvelopedData leaks no plaintext to -out"); -}; - subtest "CAdES <=> CAdES consistency tests\n" => sub { plan tests => (scalar @smime_cms_cades_tests); @@ -1312,23 +1261,6 @@ subtest "CMS code signing test" => sub { "fail verify CMS signature with code signing certificate for purpose smime_sign"); }; -# Regression test for PKCS7_verify() ownership handling when -# digestAlgorithms is an empty SET. -# The malformed structure must fail cleanly without crashing or -# triggering use-after-free behaviour. -with({ exit_checker => sub { return shift == 4; } }, - sub { - ok(run(app([ - 'openssl', 'smime', - '-verify', - '-noverify', - '-in', - srctop_file('test', 'smime-eml', - 'pkcs7-empty-digest-set.eml'), - ])), - "Check empty digestAlgorithms SET is handled safely"); - }); - # Test case for missing MD algorithm (must not segfault) with({ exit_checker => sub { return shift == 4; } }, @@ -1351,8 +1283,8 @@ with({ exit_checker => sub { return shift == 4; } }, sub check_availability { my $tnam = shift; - return "$tnam: skipped, X963KDF disabled\n" - if ($no_x963kdf && $tnam =~ /ECDH/); + return "$tnam: skipped, EC disabled\n" + if ($no_ec && $tnam =~ /ECDH/); return "$tnam: skipped, ECDH disabled\n" if ($no_ec && $tnam =~ /ECDH/); return "$tnam: skipped, EC2M disabled\n" @@ -1442,49 +1374,6 @@ with({ exit_checker => sub { return shift == 3; } }, "Check for failure when cipher does not have an assigned OID (issue#22225)"); }); -# Test cases for CVE-2026-28389 -my $smcont_malformed = srctop_file("test", "recipes", "80-test_cms_data", "dh-malformed.der"); -my $smdhcert = srctop_file("test", "recipes", "80-test_cms_data", "dh-cert.pem"); -my $smdhkey = srctop_file("test", "recipes", "80-test_cms_data", "dh-key.pem"); - -with({ exit_checker => sub { return shift == 4; } }, - sub { - SKIP: { - skip "DH is not supported in this build", 1 if $no_dh; - - ok(run(app(["openssl", "cms", @prov, "-decrypt", "-in", $smcont_malformed, - "-inform", "DER", "-recip", $smdhcert, "-inkey", $smdhkey])), - "Must not crash on malformed cms inputs with dh key"); - } - }); - -$smcont_malformed = srctop_file("test", "recipes", "80-test_cms_data", "ecdh-malformed.der"); -my $smecdhcert = srctop_file("test", "recipes", "80-test_cms_data", "ecdh-cert.pem"); -my $smecdhkey = srctop_file("test", "recipes", "80-test_cms_data", "ecdh-key.pem"); - -with({ exit_checker => sub { return shift == 4; } }, - sub { - SKIP: { - skip "EC is not supported in this build", 1 if $no_ec; - - ok(run(app(["openssl", "cms", @prov, "-decrypt", "-in", $smcont_malformed, - "-inform", "DER", "-recip", $smecdhcert, "-inkey", $smecdhkey])), - "Must not crash on malformed cms inputs with ecdh key"); - } - }); - -$smcont_malformed = srctop_file("test", "recipes", "80-test_cms_data", "rsa-malformed.der"); -my $smrsacert = catfile($smdir, "smrsa3.pem"); -my $smrsakey = catfile($smdir, "smrsa3-key.pem"); - -# Test case for CVE-2026-28390 -with({ exit_checker => sub { my $ret = shift; return $ret == 4 || $ret == 0; } }, - sub { - ok(run(app(["openssl", "cms", @prov, "-decrypt", "-in", $smcont_malformed, "-inform", - "DER", "-recip", $smrsacert, "-inkey", $smrsakey, "-out", "{output}.cms"])), - "Must not crash on malformed cms inputs with RSA key"); - }); - # Test encrypt to three recipients, and decrypt using key-only; # i.e. do not follow the recommended practice of providing the # recipient cert in the decrypt op. @@ -1768,22 +1657,3 @@ subtest "ML-KEM KEMRecipientInfo tests for CMS" => sub { "CMS decrypt with ML-KEM-768 and using UKM"); } }; - -# Regression test for NULL dereference in PWRI decrypt path -# when optional keyDerivationAlgorithm is omitted. -subtest "PWRI missing keyDerivationAlgorithm regression" => sub { - plan tests => 1; - - with({ exit_checker => sub { return shift == 4; } }, sub { - ok(run(app([ - "openssl", "cms", @prov, - "-decrypt", - "-inform", "DER", - "-in", - srctop_file('test', 'cms-msg', 'missing-kdf.der'), - "-out", "pwri-out.txt", - "-pwri_password", "secret"])), - "missing keyDerivationAlgorithm is rejected"); - }); -}; - diff --git a/test/recipes/80-test_cms_data/authenveloped_attrs.pem b/test/recipes/80-test_cms_data/authenveloped_attrs.pem deleted file mode 100644 index 75c8eab00b..0000000000 --- a/test/recipes/80-test_cms_data/authenveloped_attrs.pem +++ /dev/null @@ -1,7 +0,0 @@ ------BEGIN CMS----- -MIAGCyqGSIb3DQEJEAEXoIAwgAIBADEzojECAQQwBQQDwP7gMAsGCWCGSAFlAwQB -BQQYknpV85muZoLZSPkwi5Ll1Z1HwzAeZThVMIAGCSqGSIb3DQEHATAeBglghkgB -ZQMEAQYwEQQMkCQb305essfGO2nqAgEQoIAEHvYjM7EK9qZAHgoohdcbSHXe0lGJ -/Hjk3nkK5VsHxgAAAAChFjAUBgkrBgEEAYaNHwExBwwFaGVsbG8EENeGq4IXAd1O -iv8hMl+lHZOiFjAUBgkrBgEEAYaNHwIxBwwFd29ybGQAAAAAAAA= ------END CMS----- diff --git a/test/recipes/80-test_cms_data/bad_authenveloped_attrs.pem b/test/recipes/80-test_cms_data/bad_authenveloped_attrs.pem deleted file mode 100644 index e14946c96d..0000000000 --- a/test/recipes/80-test_cms_data/bad_authenveloped_attrs.pem +++ /dev/null @@ -1,7 +0,0 @@ ------BEGIN CMS----- -MIAGCyqGSIb3DQEJEAEXoIAwgAIBADEzojECAQQwBQQDwP7gMAsGCWCGSAFlAwQB -BQQYknpV85muZoLZSPkwi5Ll1Z1HwzAeZThVMIAGCSqGSIb3DQEHATAeBglghkgB -ZQMEAQYwEQQMkCQb305essfGO2nqAgEQoIAEHvYjM7EK9qZAHgoohdcbSHXe0lGJ -/Hjk3nkK5VsHxgAAAAChFjAUBgkrBgEEAYaNHwExBwwFaWVsbG8EENeGq4IXAd1O -iv8hMl+lHZOiFjAUBgkrBgEEAYaNHwIxBwwFd29ybGQAAAAAAAA= ------END CMS----- diff --git a/test/recipes/80-test_cms_data/dh-cert.pem b/test/recipes/80-test_cms_data/dh-cert.pem deleted file mode 100644 index f5fb90b900..0000000000 --- a/test/recipes/80-test_cms_data/dh-cert.pem +++ /dev/null @@ -1,31 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIFSjCCBDKgAwIBAgIUAV5WB+HkJTxtCmGX88OYfIRfEu8wDQYJKoZIhvcNAQEL -BQAwVjELMAkGA1UEBhMCQVUxEzARBgNVBAgMClNvbWUtU3RhdGUxITAfBgNVBAoM -GEludGVybmV0IFdpZGdpdHMgUHR5IEx0ZDEPMA0GA1UEAwwGcm9vdENBMB4XDTI2 -MDMzMTA4NDUwOVoXDTI2MDQwMTA4NDUwOVowDjEMMAoGA1UEAwwDcG9jMIIDJzCC -AhkGByqGSM4+AgEwggIMAoIBAQD//////////634VFiiu0qar9xWICc9PPHYucWD -zi02lanhNkEUZDP7zJOdziSbPvl9L+NjYwx12PaBsgKuxGF6098e1dX9ZWEkM/Uf -XwZu0IVjZVU97RrztVcTXn9XyTWYTwxw4OaLd+Kmidrz7+hyHfFYoTat5zUwrMpP -SDp5erwKsYKzJPth0QipS7LI4/u5atq3YNf0aB1PQqPeOU30rlbt52NyuxkLB6fI -7gptcJ4C/OHN9+LswDQEzSg0L2GRcv6c6YWD/45PEjLu8oGDw/47G0xvrXM7tfy8 -LsIgBcWO8YN9FoOyxvNKJsGy7/qIa0I4YShcl///////////AgECAoIBAH////// -////1vwqLFFdpU1X7isQE56eeOxc4sHnFptK1PCbIIoyGf3mSc7nEk2ffL6X8bGx -hjrse0DZAVdiML1p749q6v6ysJIZ+o+vgzdoQrGyqp72jXnaq4mvP6vkmswnhjhw -c0W78VNE7Xn39DkO+KxQm1bzmphWZSekHTy9XgVYwVmSfbDohFSl2WRx/dy1bVuw -a/o0DqehUe8cpvpXK3bzsbldjIWD0+R3BTa4TwF+cOb78XZgGgJmlBoXsMi5f050 -wsH/xyeJGXd5QMHh/x2NpjfWuZ3a/l4XYRAC4sd4wb6LQdljeaUTYNl3/UQ1oRww -lC5L//////////8DggEGAAKCAQEA8IGxSTAsrdMqlK3rFejocWZ0fmXhLzlhnARX -l3RL+jHyiFoCyCPRLmGBMaL9HqfcVp7E98IvFBxEjtDVc2tcbUJrbv922QaNYqQl -IwuUhdBHDpg0aSbDTV0Vvbny0hDuD7T7VTUO5D7XJammA2hlbpcfO8xuWFmRjdBJ -ctA+MaUbWL21ZzsF8A5rz58mVRHchrAez5ksNb8xaLd0lZqtbiBDntA52XnSp1bO -M2CPlKcb4qMMxVop2DGakChcxu7BUzob22HpRQl+k5K4Tq+kkToHKMR6obpl9Leu -lzJdR8cH9WqF6TE2YFYkpvzE7V7/Rp4uC6UqOGr62oS4thwLtqNTMFEwHwYDVR0j -BBgwFoAUhVaJNeKfABrhhgMLS692Emszbf0wDwYDVR0TAQH/BAUwAwEB/zAdBgNV -HQ4EFgQUIpXhOwY+ufefb4dBhx3niO/ntO0wDQYJKoZIhvcNAQELBQADggEBABWo -cJfSVwpnYmDHi9U0r0yickvRyFLiOK1vruoKfbkxfYk9J9OwLr4n4S5P5bGXXOSW -AAVXnvYKs6Xn07sg+1X1Sti/1wd/OLOvjaz1ebRqP5MiZRbKIlRHkv2maJEmcdyp -JGR4gHGnu/0I5Zp4DOi+xv1R3vGIkkcl/WIncrJflMJcCRMM4YdMV838kFU2esGm -eB8pTv7acyYsGeSTIk+AYEtS84w3ZQ2sOuGAep0hp9saV/LKiRzNUG0yX2LWP8EO -VMqGSXJqg1TYgAa7lcidtXfQgm+xdTeZzJRbl8Ti3d5YbgXW2vt4vhwkXtPGy5Y3 -NGpnrpeWX4rk4kQmx/I= ------END CERTIFICATE----- diff --git a/test/recipes/80-test_cms_data/dh-key.pem b/test/recipes/80-test_cms_data/dh-key.pem deleted file mode 100644 index 1601078521..0000000000 --- a/test/recipes/80-test_cms_data/dh-key.pem +++ /dev/null @@ -1,15 +0,0 @@ ------BEGIN PRIVATE KEY----- -MIICQAIBADCCAhkGByqGSM4+AgEwggIMAoIBAQD//////////634VFiiu0qar9xW -ICc9PPHYucWDzi02lanhNkEUZDP7zJOdziSbPvl9L+NjYwx12PaBsgKuxGF6098e -1dX9ZWEkM/UfXwZu0IVjZVU97RrztVcTXn9XyTWYTwxw4OaLd+Kmidrz7+hyHfFY -oTat5zUwrMpPSDp5erwKsYKzJPth0QipS7LI4/u5atq3YNf0aB1PQqPeOU30rlbt -52NyuxkLB6fI7gptcJ4C/OHN9+LswDQEzSg0L2GRcv6c6YWD/45PEjLu8oGDw/47 -G0xvrXM7tfy8LsIgBcWO8YN9FoOyxvNKJsGy7/qIa0I4YShcl///////////AgEC -AoIBAH//////////1vwqLFFdpU1X7isQE56eeOxc4sHnFptK1PCbIIoyGf3mSc7n -Ek2ffL6X8bGxhjrse0DZAVdiML1p749q6v6ysJIZ+o+vgzdoQrGyqp72jXnaq4mv -P6vkmswnhjhwc0W78VNE7Xn39DkO+KxQm1bzmphWZSekHTy9XgVYwVmSfbDohFSl -2WRx/dy1bVuwa/o0DqehUe8cpvpXK3bzsbldjIWD0+R3BTa4TwF+cOb78XZgGgJm -lBoXsMi5f050wsH/xyeJGXd5QMHh/x2NpjfWuZ3a/l4XYRAC4sd4wb6LQdljeaUT -YNl3/UQ1oRwwlC5L//////////8EHgIcJmHQRSrQ2wQnNyMZhx9Xdkf8hro/xi1r -xDHoWg== ------END PRIVATE KEY----- diff --git a/test/recipes/80-test_cms_data/dh-malformed.der b/test/recipes/80-test_cms_data/dh-malformed.der deleted file mode 100644 index 20a5ed84bd..0000000000 Binary files a/test/recipes/80-test_cms_data/dh-malformed.der and /dev/null differ diff --git a/test/recipes/80-test_cms_data/ecdh-cert.pem b/test/recipes/80-test_cms_data/ecdh-cert.pem deleted file mode 100644 index 3a0ab6624c..0000000000 --- a/test/recipes/80-test_cms_data/ecdh-cert.pem +++ /dev/null @@ -1,10 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIBcTCCARegAwIBAgIUFyBfipahA11TzFxBhYY2WfTejGswCgYIKoZIzj0EAwIw -DjEMMAoGA1UEAwwDcG9jMB4XDTI2MDMzMTA3MzQyOVoXDTI2MDQwMTA3MzQyOVow -DjEMMAoGA1UEAwwDcG9jMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE6iA2FR7s -OgRtpf8cRXDSLSSB5nSzQt2/hzueZTiQXUT1Knto2U5zRqUoioZ/FKsazdhQVQQC -EN0/WYGND+XwmaNTMFEwHwYDVR0jBBgwFoAU+AH0MqgJJ4WYRK+BmEDebmjREYcw -DwYDVR0TAQH/BAUwAwEB/zAdBgNVHQ4EFgQU+AH0MqgJJ4WYRK+BmEDebmjREYcw -CgYIKoZIzj0EAwIDSAAwRQIhAPTS8MWoylN+jfLgRfr75WkJqNFlsrfxCDvMtWV+ -NT2yAiBaY72EVG36EP2gGFEhkBaXb0vLx0r7umDgejEwBWQ9mQ== ------END CERTIFICATE----- diff --git a/test/recipes/80-test_cms_data/ecdh-key.pem b/test/recipes/80-test_cms_data/ecdh-key.pem deleted file mode 100644 index ef9488b3c5..0000000000 --- a/test/recipes/80-test_cms_data/ecdh-key.pem +++ /dev/null @@ -1,5 +0,0 @@ ------BEGIN PRIVATE KEY----- -MIGHAgEAMBMGByqGSM49AgEGCCqGSM49AwEHBG0wawIBAQQgeDjy2W+FHVPt1Kg1 -unwzzD9yBC+NtbH/UaZ9PY4wZP6hRANCAATqIDYVHuw6BG2l/xxFcNItJIHmdLNC -3b+HO55lOJBdRPUqe2jZTnNGpSiKhn8UqxrN2FBVBAIQ3T9ZgY0P5fCZ ------END PRIVATE KEY----- diff --git a/test/recipes/80-test_cms_data/ecdh-malformed.der b/test/recipes/80-test_cms_data/ecdh-malformed.der deleted file mode 100644 index 14ddc1dea2..0000000000 Binary files a/test/recipes/80-test_cms_data/ecdh-malformed.der and /dev/null differ diff --git a/test/recipes/80-test_cms_data/rsa-malformed.der b/test/recipes/80-test_cms_data/rsa-malformed.der deleted file mode 100644 index 4182a465ce..0000000000 Binary files a/test/recipes/80-test_cms_data/rsa-malformed.der and /dev/null differ diff --git a/test/recipes/80-test_cmsapi.t b/test/recipes/80-test_cmsapi.t index 3d1dae8464..af00355a9d 100644 --- a/test/recipes/80-test_cmsapi.t +++ b/test/recipes/80-test_cmsapi.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2018-2022 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -18,7 +18,5 @@ plan tests => 1; ok(run(test(["cmsapitest", srctop_file("test", "certs", "servercert.pem"), srctop_file("test", "certs", "serverkey.pem"), - srctop_file("test", "recipes", "80-test_cmsapi_data", "encryptedData.der"), - srctop_file("test", "recipes", "80-test_cmsapi_data", "encDataWithTooLongIV.pem"), - srctop_file("test", "recipes", "80-test_cmsapi_data", "cms_pwri_kek_oob.der")])), + srctop_file("test", "recipes", "80-test_cmsapi_data", "encryptedData.der")])), "running cmsapitest"); diff --git a/test/recipes/80-test_cmsapi_data/cms_pwri_kek_oob.der b/test/recipes/80-test_cmsapi_data/cms_pwri_kek_oob.der deleted file mode 100644 index c3ef3abd10..0000000000 Binary files a/test/recipes/80-test_cmsapi_data/cms_pwri_kek_oob.der and /dev/null differ diff --git a/test/recipes/80-test_cmsapi_data/encDataWithTooLongIV.pem b/test/recipes/80-test_cmsapi_data/encDataWithTooLongIV.pem deleted file mode 100644 index 4323cd2fb0..0000000000 --- a/test/recipes/80-test_cmsapi_data/encDataWithTooLongIV.pem +++ /dev/null @@ -1,11 +0,0 @@ ------BEGIN CMS----- -MIIBmgYLKoZIhvcNAQkQARegggGJMIIBhQIBADGCATMwggEvAgEAMBcwEjEQMA4G -A1UEAwwHUm9vdCBDQQIBAjANBgkqhkiG9w0BAQEFAASCAQC8ZqP1OqbletcUre1V -b4XOobZzQr6wKMSsdjtGzVbZowUVv5DkOn9VOefrpg4HxMq/oi8IpzVYj8ZiKRMV -NTJ+/d8FwwBwUUNNP/IDnfEpX+rT1+pGS5zAa7NenLoZgGBNjPy5I2OHP23fPnEd -sm8YkFjzubkhAD1lod9pEOEqB3V2kTrTTiwzSNtMHggna1zPox6TkdZwFmMnp8d2 -CVa6lIPGx26gFwCuIDSaavmQ2URJ615L8gAvpYUlpsDqjFsabWsbaOFbMz3bIGJu -GkrX2ezX7CpuC1wjix26ojlTySJHv+L0IrpcaIzLlC5lB1rqtuija8dGm3rBNm/P -AAUNMDcGCSqGSIb3DQEHATAjBglghkgBZQMEAQYwFgQRzxwoRQzOHVooVn3CpaWl -paUCARCABUNdolo6BBA55E9hYaYO2S8C/ZnD8dRO ------END CMS----- diff --git a/test/recipes/80-test_dtls_ccs_reorder.t b/test/recipes/80-test_dtls_ccs_reorder.t deleted file mode 100755 index 3c703afc34..0000000000 --- a/test/recipes/80-test_dtls_ccs_reorder.t +++ /dev/null @@ -1,26 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use warnings; - -use OpenSSL::Test::Simple; -use OpenSSL::Test::Utils; -use OpenSSL::Test qw/:DEFAULT srctop_file/; - -setup("test_dtls_ccs_reorder"); - -plan skip_all => "No DTLS protocols are supported" - if alldisabled(available_protocols("dtls")); - -plan tests => 1; - -ok(run(test(["dtls_ccs_reorder_test", - srctop_file("test/certs/servercert.pem"), - srctop_file("test/certs/serverkey.pem")])), - "DTLS CCS reorder tolerance tests"); diff --git a/test/recipes/80-test_ocsp.t b/test/recipes/80-test_ocsp.t index 3f9255b530..0539c79d56 100644 --- a/test/recipes/80-test_ocsp.t +++ b/test/recipes/80-test_ocsp.t @@ -37,24 +37,22 @@ sub test_ocsp { } my $expected_exit = shift; my $nochecks = shift; - my $opt_untrusted = shift // "-verify_other"; my $outputfile = basename($inputfile, '.ors') . '.dat'; run(app(["openssl", "base64", "-d", "-in", catfile($ocspdir,$inputfile), "-out", $outputfile])); - my @certopt = ($opt_untrusted, catfile($ocspdir, $untrusted)); with({ exit_checker => sub { return shift == $expected_exit; } }, sub { ok(run(app(["openssl", "ocsp", "-respin", $outputfile, "-partial_chain", @check_time, "-CAfile", catfile($ocspdir, $CAfile), - @certopt, + "-verify_other", catfile($ocspdir, $untrusted), "-no-CApath", "-no-CAstore", $nochecks ? "-no_cert_checks" : ()])), $title); }); } -plan tests => 15; +plan tests => 12; subtest "=== VALID OCSP RESPONSES ===" => sub { plan tests => 7; @@ -232,20 +230,6 @@ subtest "=== OCSP API TESTS===" => sub { "running ocspapitest"); }; -subtest "=== OCSP VERIFICATION TESTS ===" => sub { - plan tests => 1; - - ok(run(test(["ocsptest"])), "running ocsptest"); -}; - -subtest "=== UNTRUSTED ISSUER HINTS ===" => sub { - plan tests => 1; - - test_ocsp("NON-DELEGATED; invalid issuer via -issuer", - "ND1.ors", "ND1_Cross_Root.pem", - "ISIC_ND1_Issuer_ICA.pem", 1, 0, "-issuer"); -}; - subtest "=== OCSP handling of identical input and output files ===" => sub { plan tests => 5; @@ -263,44 +247,3 @@ subtest "=== OCSP handling of identical input and output files ===" => sub { ok(run(app(['openssl', 'ocsp', '-respin', $inout2, '-respout', $inout2, '-noverify']))); ok(!compare($inout2, $backup2), "copied response $inout2 did not change"); }; - -subtest "=== OCSP offline request/responder/verify round-trip ===" => sub { - plan tests => 6; - - # Offline round-trip: build a request, answer it with the built-in - # responder using a static index, then verify the response. - my $issuer = catfile($ocspdir, "intermediate-cert.pem"); - my $ee = catfile($ocspdir, "server-cert.pem"); - my $index = catfile($ocspdir, "index.txt"); - my $rsigner = catfile($ocspdir, "ocsp.pem"); - my $root = catfile($ocspdir, "root-cert.pem"); - - # The serial of server-cert.pem is listed as valid in index.txt, so its - # status is "good"; a serial absent from the index yields "unknown". - my $roundtrip = sub { - my ($title, $reqargs, $status) = @_; - my $req = "rt-req.der"; - my $resp = "rt-resp.der"; - - ok(run(app(['openssl', 'ocsp', '-issuer', $issuer, @$reqargs, - '-reqout', $req])), - "$title: produce request"); - ok(run(app(['openssl', 'ocsp', '-index', $index, '-rsigner', $rsigner, - '-CA', $issuer, '-reqin', $req, '-respout', $resp])), - "$title: responder produces response"); - # Passing the request again lets print_ocsp_summary report the status. - ok(run(app(['openssl', 'ocsp', '-issuer', $issuer, @$reqargs, - '-no_nonce', '-respin', $resp, '-CAfile', $root, - '-verify_other', $rsigner, - '-no-CApath', '-no-CAstore'])), - "$title: verify self-generated response ($status)"); - }; - - SKIP: { - # The responder certificates use EC keys. - skip "EC is not supported by this OpenSSL build", 6 if disabled("ec"); - - $roundtrip->("GOOD (by cert)", ['-cert', $ee], "good"); - $roundtrip->("UNKNOWN (by serial)", ['-serial', '0x1234'], "unknown"); - } -}; diff --git a/test/recipes/80-test_pkcs12.t b/test/recipes/80-test_pkcs12.t index 5e9838d107..06fa85af0f 100644 --- a/test/recipes/80-test_pkcs12.t +++ b/test/recipes/80-test_pkcs12.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -56,7 +56,7 @@ $ENV{OPENSSL_WIN32_UTF8}=1; my $no_fips = disabled('fips') || ($ENV{NO_FIPS} // 0); -plan tests => 64 + ($no_fips ? 0 : 5); +plan tests => $no_fips ? 47 : 53; # Test different PKCS#12 formats ok(run(test(["pkcs12_format_test"])), "test pkcs12 formats"); @@ -107,7 +107,7 @@ SKIP: { } SKIP: { - skip "Skipping legacy PKCS#12 test because the required algorithms are disabled", 2 + skip "Skipping legacy PKCS#12 test because the required algorithms are disabled", 1 if disabled("des") || disabled("rc2") || disabled("legacy"); # Test reading legacy PKCS#12 file ok(run(app(["openssl", "pkcs12", "-export", @@ -115,12 +115,8 @@ SKIP: { "-passin", "pass:v3-certs", "-provider", "default", "-provider", "legacy", "-nokeys", "-passout", "pass:v3-certs", "-descert", - "-out", $outfile3], stderr => "outerr2.txt")), + "-out", $outfile3])), "test_pkcs12_passcerts_legacy"); - open DATA, "outerr2.txt"; - my @match = grep /:error:/, ; - close DATA; - ok(scalar @match > 0 ? 0 : 1, "test_pkcs12_passcerts_legacy_outerr2_empty"); } # Test export of PEM file with both cert and key @@ -176,29 +172,6 @@ ok(grep(/Trusted key usage (Oracle)/, @pkcs12info) == 0, ok(scalar @match > 0 ? 0 : 1, "test_export_pkcs12_outerr6_empty"); } -# Test dumping a PKCS#12 file whose private key is stored in an unencrypted -# keyBag (created with -keypbe NONE) rather than a shrouded keyBag. -{ - my $keybag = "keybag.p12"; - ok(run(app(["openssl", "pkcs12", "-export", "-keypbe", "NONE", - "-certpbe", "NONE", "-nomac", - "-inkey", srctop_file(@path, "cert-key-cert.pem"), - "-in", srctop_file(@path, "cert-key-cert.pem"), - "-passout", "pass:", "-out", $keybag])), - "export PKCS#12 with an unencrypted key bag"); - - # -nodes so the dumped key isn't re-encrypted (which would prompt). - my @info = run(app(["openssl", "pkcs12", "-in", $keybag, "-info", "-nodes", - "-passin", "pass:"], stderr => "keybag_info.txt"), - capture => 1); - open DATA, "keybag_info.txt"; - my @match = grep /Key bag/, ; - close DATA; - ok(scalar @match > 0 ? 1 : 0, "test unencrypted key bag is reported"); - ok(grep(/-----BEGIN PRIVATE KEY-----/, @info) == 1, - "test private key from key bag is output"); -} - my %pbmac1_tests = ( pbmac1_defaults => {args => [], lookup => "hmacWithSHA256"}, pbmac1_nondefaults => {args => ["-pbmac1_pbkdf2_md", "sha512", "-macalg", "sha384"], lookup => "hmacWithSHA512"}, @@ -226,29 +199,44 @@ for my $instance (sort keys %pbmac1_tests) { "-passin", "pass:1234"], stderr => "${pbmac1_id}_info.txt")), "test_export_pkcs12_${pbmac1_id}_info"); open DATA, "${pbmac1_id}_info.txt"; - @match = grep /$lookup/, ; + my @match = grep /$lookup/, ; close DATA; ok(scalar @match > 0 ? 1 : 0, "test_export_pkcs12_${pbmac1_id}_info"); } } -# Test pbmac1 pkcs12 good files, RFC 9579, and one extra with shorter key -# length -for my $file ("pbmac1_256_256.good.p12", "pbmac1_512_256.good.p12", - "pbmac1_512_512.good.p12", - "pbmac1_256_256.good-shorter-key-len.p12") +# Test pbmac1 pkcs12 good files, RFC 9579 +for my $file ("pbmac1_256_256.good.p12", "pbmac1_512_256.good.p12", "pbmac1_512_512.good.p12") { my $path = srctop_file("test", "recipes", "80-test_pkcs12_data", $file); ok(run(app(["openssl", "pkcs12", "-in", $path, "-password", "pass:1234", "-noenc"])), "test pbmac1 pkcs12 file $file"); } -# Test pbmac1 pkcs12 bad files, RFC 9579, CVE-2025-11187 and CVE-2026-34181 -for my $file ("pbmac1_256_256.bad-iter.p12", "pbmac1_256_256.bad-salt.p12", - "pbmac1_256_256.no-len.p12", "pbmac1_256_256.bad-len.p12", - "pbmac1_256_256.bad-salt-type.p12", "pbmac1_256_256.negative-len.p12", - "pbmac1_256_256.no-salt.p12", "pbmac1_256_256.very-big-len.p12", - "pbmac1_256_256.zero-len.p12", "pbmac1_256_256.bad-key-len.p12") + +unless ($no_fips) { + my $provpath = bldtop_dir("providers"); + my $provconf = srctop_file("test", "fips-and-base.cnf"); + my $provname = 'fips'; + my @prov = ("-provider-path", $provpath, + "-provider", $provname); + local $ENV{OPENSSL_CONF} = $provconf; + +# Test pbmac1 pkcs12 good files, RFC 9579 + for my $file ("pbmac1_256_256.good.p12", "pbmac1_512_256.good.p12", "pbmac1_512_512.good.p12") + { + my $path = srctop_file("test", "recipes", "80-test_pkcs12_data", $file); + ok(run(app(["openssl", "pkcs12", @prov, "-in", $path, "-password", "pass:1234", "-noenc"])), + "test pbmac1 pkcs12 file $file"); + + ok(run(app(["openssl", "pkcs12", @prov, "-in", $path, "-info", "-noout", + "-passin", "pass:1234"], stderr => "${file}_info.txt")), + "test_export_pkcs12_${file}_info"); + } +} + +# Test pbmac1 pkcs12 bad files, RFC 9579 +for my $file ("pbmac1_256_256.bad-iter.p12", "pbmac1_256_256.bad-salt.p12", "pbmac1_256_256.no-len.p12") { my $path = srctop_file("test", "recipes", "80-test_pkcs12_data", $file); with({ exit_checker => sub { return shift == 1; } }, @@ -369,118 +357,4 @@ ok(run(test(["pkcs12_api_test", "-has-cert", 1, ])), "Test pkcs12_parse()"); -# Test against CVE-2025-69421, octet parameter is expected, but -# NULL is being received and dereferenced - -unless ($no_fips) { - my $file = "sha256mac_cert.oct-is-null.p12"; - my $path = srctop_file("test", "recipes", "80-test_pkcs12_data", $file); - with({ exit_checker => sub { return shift == 1; } }, - sub { - my @output = run(app(["openssl", "storeutl", "-certs", "-text", - "-passin", "pass:RedHatEnterpriseLinux10.0", $path]), - capture => 1, stderr => "outerr.txt"); - open DATA, "outerr.txt"; - my @match = grep /PKCS12_item_decrypt_d2i_ex:passed a null parameter/, ; - close DATA; - ok(scalar @match > 0 ? 0 : 1, "Test against CVE-2025-69421 - null parameter, sha256mac"); - } - ); -} - -{ - my $file = "pbmac1_cert.oct-is-null.p12"; - my $path = srctop_file("test", "recipes", "80-test_pkcs12_data", $file); - with({ exit_checker => sub { return shift == 1; } }, - sub { - my @output = run(app(["openssl", "storeutl", "-certs", "-text", - "-passin", "pass:RedHatEnterpriseLinux10.0", $path]), - capture => 1, stderr => "outerr.txt"); - open DATA, "outerr.txt"; - my @match = grep /PKCS12_item_decrypt_d2i_ex:passed a null parameter/, ; - close DATA; - ok(scalar @match > 0 ? 0 : 1, "Test against CVE-2025-69421 - null parameter, pbmac1"); - } - ); -} - -# Test against CVE-2026-22795 , missing ASN1_TYPE validation in cert -unless ($no_fips) { - for my $file ("BOOLEAN-in-friendlyName-of-cert-pkcs12-sha256mac.p12", - "BOOLEAN-in-localKeyID-of-cert-pkcs12-sha256mac.p12" - ) - { - my $path = srctop_file("test", "recipes", "80-test_pkcs12_data", $file); - with({ exit_checker => sub { return shift == 1; } }, - sub { - my @output = run(app(["openssl", "storeutl", "-certs", "-text", - "-passin", "pass:RedHatEnterpriseLinux10.0", $path]), - capture => 1, stderr => "outerr.txt"); - open DATA, "outerr.txt"; - my @match = grep /:PKCS12_parse:parse error:/, ; - close DATA; - ok(scalar @match > 0 ? 0 : 1, "Test against CVE-2026-22795 , missing ASN1_TYPE validation in cert, sha256mac"); - } - ); - } -} - -for my $file ("BOOLEAN-in-friendlyName-of-cert-pbmac1.p12", - "BOOLEAN-in-localKeyID-of-cert-pbmac1.p12" - ) -{ - my $path = srctop_file("test", "recipes", "80-test_pkcs12_data", $file); - with({ exit_checker => sub { return shift == 1; } }, - sub { - my @output = run(app(["openssl", "storeutl", "-certs", "-text", - "-passin", "pass:RedHatEnterpriseLinux10.0", $path]), - capture => 1, stderr => "outerr.txt"); - open DATA, "outerr.txt"; - my @match = grep /:PKCS12_parse:parse error:/, ; - close DATA; - ok(scalar @match > 0 ? 0 : 1, "Test against CVE-2026-22795 , missing ASN1_TYPE validation in cert, pbmac1"); - } - ); -} - -# Test against CVE-2026-22795, missing ASN1_TYPE validation in keys -unless ($no_fips) { - for my $file ("BOOLEAN-in-friendlyName-of-key-pkcs12-sha256mac.p12", - "BOOLEAN-in-localKeyID-of-key-pkcs12-sha256mac.p12" - ) - { - my $path = srctop_file("test", "recipes", "80-test_pkcs12_data", $file); - with({ exit_checker => sub { return shift == 1; } }, - sub { - - my @output = run(app(["openssl", "storeutl", "-keys", "-text", - "-passin", "pass:RedHatEnterpriseLinux10.0", $path]), - capture => 1, stderr => "outerr.txt"); - open DATA, "outerr.txt"; - my @match = grep /:PKCS12_parse:parse error:/, ; - close DATA; - ok(scalar @match > 0 ? 0 : 1, "Test against CVE-2026-22795 , missing ASN1_TYPE validation in keys, sha256mac"); - } - ); - } -} - -for my $file ("BOOLEAN-in-friendlyName-of-key-pbmac1.p12", - "BOOLEAN-in-localKeyID-of-key-pbmac1.p12" - ) -{ - my $path = srctop_file("test", "recipes", "80-test_pkcs12_data", $file); - with({ exit_checker => sub { return shift == 1; } }, - sub { - my @output = run(app(["openssl", "storeutl", "-keys", "-text", - "-passin", "pass:RedHatEnterpriseLinux10.0", $path]), - capture => 1, stderr => "outerr.txt"); - open DATA, "outerr.txt"; - my @match = grep /:PKCS12_parse:parse error:/, ; - close DATA; - ok(scalar @match > 0 ? 0 : 1, "Test against CVE-2026-22795 , missing ASN1_TYPE validation in keys, pbmac1"); - } - ); -} - SetConsoleOutputCP($savedcp) if (defined($savedcp)); diff --git a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-friendlyName-of-cert-pbmac1.p12 b/test/recipes/80-test_pkcs12_data/BOOLEAN-in-friendlyName-of-cert-pbmac1.p12 deleted file mode 100644 index c2438e98f6..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-friendlyName-of-cert-pbmac1.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-friendlyName-of-cert-pkcs12-sha256mac.p12 b/test/recipes/80-test_pkcs12_data/BOOLEAN-in-friendlyName-of-cert-pkcs12-sha256mac.p12 deleted file mode 100644 index b531f66d7a..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-friendlyName-of-cert-pkcs12-sha256mac.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-friendlyName-of-key-pbmac1.p12 b/test/recipes/80-test_pkcs12_data/BOOLEAN-in-friendlyName-of-key-pbmac1.p12 deleted file mode 100644 index 02d2334c42..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-friendlyName-of-key-pbmac1.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-friendlyName-of-key-pkcs12-sha256mac.p12 b/test/recipes/80-test_pkcs12_data/BOOLEAN-in-friendlyName-of-key-pkcs12-sha256mac.p12 deleted file mode 100644 index 15edc18016..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-friendlyName-of-key-pkcs12-sha256mac.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-localKeyID-of-cert-pbmac1.p12 b/test/recipes/80-test_pkcs12_data/BOOLEAN-in-localKeyID-of-cert-pbmac1.p12 deleted file mode 100644 index dc82f4d4e0..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-localKeyID-of-cert-pbmac1.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-localKeyID-of-cert-pkcs12-sha256mac.p12 b/test/recipes/80-test_pkcs12_data/BOOLEAN-in-localKeyID-of-cert-pkcs12-sha256mac.p12 deleted file mode 100644 index 5754b52230..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-localKeyID-of-cert-pkcs12-sha256mac.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-localKeyID-of-key-pbmac1.p12 b/test/recipes/80-test_pkcs12_data/BOOLEAN-in-localKeyID-of-key-pbmac1.p12 deleted file mode 100644 index c71ed5b596..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-localKeyID-of-key-pbmac1.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-localKeyID-of-key-pkcs12-sha256mac.p12 b/test/recipes/80-test_pkcs12_data/BOOLEAN-in-localKeyID-of-key-pkcs12-sha256mac.p12 deleted file mode 100644 index 6bfabc1710..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/BOOLEAN-in-localKeyID-of-key-pkcs12-sha256mac.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.bad-key-len.p12 b/test/recipes/80-test_pkcs12_data/pbmac1_256_256.bad-key-len.p12 deleted file mode 100644 index 7162fd1871..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.bad-key-len.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.bad-len.p12 b/test/recipes/80-test_pkcs12_data/pbmac1_256_256.bad-len.p12 deleted file mode 100644 index a1acf2fc21..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.bad-len.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.bad-salt-type.p12 b/test/recipes/80-test_pkcs12_data/pbmac1_256_256.bad-salt-type.p12 deleted file mode 100644 index 7f4e1e89ca..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.bad-salt-type.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.good-shorter-key-len.p12 b/test/recipes/80-test_pkcs12_data/pbmac1_256_256.good-shorter-key-len.p12 deleted file mode 100644 index 3c202dd58d..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.good-shorter-key-len.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.negative-len.p12 b/test/recipes/80-test_pkcs12_data/pbmac1_256_256.negative-len.p12 deleted file mode 100644 index 9a4fd45922..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.negative-len.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.no-salt.p12 b/test/recipes/80-test_pkcs12_data/pbmac1_256_256.no-salt.p12 deleted file mode 100644 index c43b4be043..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.no-salt.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.very-big-len.p12 b/test/recipes/80-test_pkcs12_data/pbmac1_256_256.very-big-len.p12 deleted file mode 100644 index 6920b89a6c..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.very-big-len.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.zero-len.p12 b/test/recipes/80-test_pkcs12_data/pbmac1_256_256.zero-len.p12 deleted file mode 100644 index 0e63eb6077..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/pbmac1_256_256.zero-len.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/pbmac1_cert.oct-is-null.p12 b/test/recipes/80-test_pkcs12_data/pbmac1_cert.oct-is-null.p12 deleted file mode 100644 index 47e2e8619e..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/pbmac1_cert.oct-is-null.p12 and /dev/null differ diff --git a/test/recipes/80-test_pkcs12_data/sha256mac_cert.oct-is-null.p12 b/test/recipes/80-test_pkcs12_data/sha256mac_cert.oct-is-null.p12 deleted file mode 100644 index 099fb0088f..0000000000 Binary files a/test/recipes/80-test_pkcs12_data/sha256mac_cert.oct-is-null.p12 and /dev/null differ diff --git a/test/recipes/80-test_ssl_new.t b/test/recipes/80-test_ssl_new.t index 8516652f97..44c674e467 100644 --- a/test/recipes/80-test_ssl_new.t +++ b/test/recipes/80-test_ssl_new.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -42,7 +42,7 @@ if (defined $ENV{SSL_TESTS}) { @conf_srcs = glob(srctop_file("test", "ssl-tests", "*.cnf.in")); # We hard-code the number of tests to double-check that the globbing above # finds all files as expected. - plan tests => 32; + plan tests => 31; } map { s/;.*// } @conf_srcs if $^O eq "VMS"; my @conf_files = map { basename($_, ".in") } @conf_srcs; @@ -50,13 +50,13 @@ map { s/\^// } @conf_files if $^O eq "VMS"; # Some test results depend on the configuration of enabled protocols. We only # verify generated sources in the default configuration. -my $is_default_tls = (!disabled("tls1") && !disabled("tls1_1") && - !disabled("tls1_2") && !disabled("tls1_3") && - (!disabled("ec") || !disabled("dh"))); +my $is_default_tls = (disabled("ssl3") && !disabled("tls1") && + !disabled("tls1_1") && !disabled("tls1_2") && + !disabled("tls1_3") && (!disabled("ec") || !disabled("dh"))); my $is_default_dtls = (!disabled("dtls1") && !disabled("dtls1_2")); -my @all_pre_tls1_3 = ("tls1", "tls1_1", "tls1_2"); +my @all_pre_tls1_3 = ("ssl3", "tls1", "tls1_1", "tls1_2"); my $no_tls = alldisabled(available_protocols("tls")); my $no_tls_below1_3 = $no_tls || (disabled("tls1_2") && !disabled("tls1_3")); if (!$no_tls && $no_tls_below1_3 && disabled("ec") && disabled("dh")) { @@ -73,8 +73,6 @@ my $no_dsa = disabled("dsa"); my $no_ec2m = disabled("ec2m"); my $no_ocsp = disabled("ocsp"); my $no_ml_dsa = disabled("ml-dsa"); -my $no_sm2 = disabled("sm2"); -my $no_ml_kem = disabled("ml-kem"); # Add your test here if the test conf.in generates test cases and/or # expectations dynamically based on the OpenSSL compile-time config. @@ -86,21 +84,18 @@ my %conf_dependent_tests = ( "07-dtls-protocol-version.cnf" => !$is_default_dtls || !disabled("sctp"), "10-resumption.cnf" => !$is_default_tls || $no_ec, "11-dtls_resumption.cnf" => !$is_default_dtls || !disabled("sctp"), - "14-curves.cnf" => disabled("tls-deprecated-ec") || $no_ecx || $no_sm2 || $no_ml_kem, + "14-curves.cnf" => disabled("tls-deprecated-ec"), "16-dtls-certstatus.cnf" => !$is_default_dtls || !disabled("sctp"), "17-renegotiate.cnf" => disabled("tls1_2"), "18-dtls-renegotiate.cnf" => disabled("dtls1_2") || !disabled("sctp"), "19-mac-then-encrypt.cnf" => !$is_default_tls, - "20-cert-select.cnf" => !$is_default_tls || $no_dh || $no_dsa || $no_ml_dsa || $no_sm2, + "20-cert-select.cnf" => !$is_default_tls || $no_dh || $no_dsa || $no_ml_dsa, "22-compression.cnf" => !$is_default_tls, - "25-cipher.cnf" => disabled("poly1305") || disabled("chacha") - || disabled("sm3") || disabled("sm4") - || disabled("tls1_3"), + "25-cipher.cnf" => disabled("poly1305") || disabled("chacha"), "27-ticket-appdata.cnf" => !$is_default_tls, "28-seclevel.cnf" => disabled("tls1_2") || $no_ecx, "30-extended-master-secret.cnf" => disabled("tls1_2"), "32-compressed-certificate.cnf" => disabled("comp") || disabled("tls1_3"), - "33-compressed-spki.cnf" => disabled("tls1_2") || disabled("tls1_3") || $no_ec, ); # Add your test here if it should be skipped for some compile-time @@ -136,7 +131,6 @@ my %skip = ( "26-tls13_client_auth.cnf" => disabled("tls1_3") || ($no_ec && $no_dh), "29-dtls-sctp-label-bug.cnf" => disabled("sctp") || disabled("sock"), "32-compressed-certificate.cnf" => disabled("comp") || disabled("tls1_3"), - "33-compressed-spki.cnf" => disabled("tls1_2") || disabled("tls1_3") || $no_ec, ); foreach my $conf (@conf_files) { diff --git a/test/recipes/80-test_ssl_old.t b/test/recipes/80-test_ssl_old.t index 81ecda9b4d..f7be2e1872 100644 --- a/test/recipes/80-test_ssl_old.t +++ b/test/recipes/80-test_ssl_old.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2024 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -25,10 +25,10 @@ use lib bldtop_dir('.'); my $no_fips = disabled('fips') || ($ENV{NO_FIPS} // 0); my ($no_rsa, $no_dsa, $no_dh, $no_ec, $no_psk, - $no_tls1, $no_tls1_1, $no_tls1_2, $no_tls1_3, + $no_ssl3, $no_tls1, $no_tls1_1, $no_tls1_2, $no_tls1_3, $no_dtls, $no_dtls1, $no_dtls1_2, $no_ct) = anydisabled qw/rsa dsa dh ec psk - tls1 tls1_1 tls1_2 tls1_3 + ssl3 tls1 tls1_1 tls1_2 tls1_3 dtls dtls1 dtls1_2 ct/; #If ec and dh are disabled then don't use TLSv1.3 $no_tls1_3 = 1 if (!$no_tls1_3 && $no_ec && $no_dh); @@ -416,25 +416,42 @@ sub testssl { subtest 'standard SSL tests' => sub { ###################################################################### - plan tests => 15; + plan tests => 19; SKIP: { - skip "No TLS versions are supported by this OpenSSL build", 1 - if $no_anytls; + skip "SSLv3 is not supported by this OpenSSL build", 4 + if disabled("ssl3"); - ok(run(test([@ssltest, "-bio_pair"])), - 'test via BIO pair'); + skip "SSLv3 is not supported by the FIPS provider", 4 + if $provider eq "fips"; + + ok(run(test([@ssltest, "-bio_pair", "-ssl3"])), + 'test sslv3 via BIO pair'); + ok(run(test([@ssltest, "-bio_pair", "-ssl3", "-server_auth", @CA])), + 'test sslv3 with server authentication via BIO pair'); + ok(run(test([@ssltest, "-bio_pair", "-ssl3", "-client_auth", @CA])), + 'test sslv3 with client authentication via BIO pair'); + ok(run(test([@ssltest, "-bio_pair", "-ssl3", "-server_auth", "-client_auth", @CA])), + 'test sslv3 with both server and client authentication via BIO pair'); } SKIP: { - skip "No TLS versions are supported by this OpenSSL build", 14 + skip "Neither SSLv3 nor any TLS version are supported by this OpenSSL build", 1 + if $no_anytls; + + ok(run(test([@ssltest, "-bio_pair"])), + 'test sslv2/sslv3 via BIO pair'); + } + + SKIP: { + skip "Neither SSLv3 nor any TLS version are supported by this OpenSSL build", 14 if $no_anytls; SKIP: { - skip "skipping test w/o (EC)DHE test", 1 if $dsa_cert; + skip "skipping test of sslv2/sslv3 w/o (EC)DHE test", 1 if $dsa_cert; ok(run(test([@ssltest, "-bio_pair", "-no_dhe", "-no_ecdhe"])), - 'test w/o (EC)DHE via BIO pair'); + 'test sslv2/sslv3 w/o (EC)DHE via BIO pair'); } SKIP: { @@ -442,17 +459,17 @@ sub testssl { if ($no_dh); ok(run(test([@ssltest, "-bio_pair", "-dhe1024dsa", "-v"])), - 'test with 1024bit DHE via BIO pair'); + 'test sslv2/sslv3 with 1024bit DHE via BIO pair'); } ok(run(test([@ssltest, "-bio_pair", "-server_auth", @CA])), - 'test with server authentication'); + 'test sslv2/sslv3 with server authentication'); ok(run(test([@ssltest, "-bio_pair", "-client_auth", @CA])), - 'test with client authentication via BIO pair'); + 'test sslv2/sslv3 with client authentication via BIO pair'); ok(run(test([@ssltest, "-bio_pair", "-server_auth", "-client_auth", @CA])), - 'test with both client and server authentication via BIO pair'); + 'test sslv2/sslv3 with both client and server authentication via BIO pair'); ok(run(test([@ssltest, "-bio_pair", "-server_auth", "-client_auth", "-app_verify", @CA])), - 'test with both client and server authentication via BIO pair and app verify'); + 'test sslv2/sslv3 with both client and server authentication via BIO pair and app verify'); SKIP: { skip "No IPv4 available on this machine", 4 @@ -500,6 +517,7 @@ sub testssl { push @protocols, "-tls1_3" unless $no_tls1_3; push @protocols, "-tls1_2" unless $no_tls1_2; push @protocols, "-tls1" unless $no_tls1 || $provider eq "fips"; + push @protocols, "-ssl3" unless $no_ssl3 || $provider eq "fips"; my $protocolciphersuitecount = 0; my %ciphersuites = (); my %ciphersstatus = (); @@ -548,6 +566,9 @@ sub testssl { # DSA is not allowed in FIPS 140-3 note "*****SKIPPING $protocol $cipher"; ok(1); + } elsif ($protocol eq "-ssl3" && $cipher =~ /ECDH/ ) { + note "*****SKIPPING $protocol $cipher"; + ok(1); } else { if ($protocol eq "-tls1_3") { $ciphersuites = $cipher; @@ -566,16 +587,11 @@ sub testssl { SKIP: { skip "skipping dhe512 test", 1 - if ($no_dh || $no_ec); + if ($no_dh); - # Need some explicit EC groups to suppress default support of - # ffdhe2048 and ffdhe3072 in the client hello, which then - # overrides the server's DH temp parameters from "-dh512". - # is(run(test([@ssltest, "-s_cipher", "EDH", "-c_cipher", 'EDH:@SECLEVEL=1', - "-groups", "?P-256:?X25519:?MLKEM512", "-dhe512", $protocol])), 0, "testing connection with weak DH, expecting failure"); @@ -585,7 +601,18 @@ sub testssl { subtest 'SSL security level failure tests' => sub { ###################################################################### - plan tests => 2; + plan tests => 3; + + SKIP: { + skip "SSLv3 is not supported by this OpenSSL build", 1 + if disabled("ssl3"); + + skip "SSLv3 is not supported by the FIPS provider", 1 + if $provider eq "fips"; + + is(run(test([@ssltest, "-bio_pair", "-ssl3", "-cipher", '@SECLEVEL=1'])), + 0, "test sslv3 fails at security level 1, expecting failure"); + } SKIP: { skip "TLSv1.0 is not supported by this OpenSSL build", 1 diff --git a/test/recipes/82-test_ech_client_server.t b/test/recipes/82-test_ech_client_server.t deleted file mode 100644 index b988d8de71..0000000000 --- a/test/recipes/82-test_ech_client_server.t +++ /dev/null @@ -1,445 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use warnings; - -use IPC::Open3; -use OpenSSL::Test qw/:DEFAULT srctop_file srctop_dir bldtop_file/; -use OpenSSL::Test::Utils; - -# servers randomly pick a port, then set this for clients to use -# we also record the pid so we can kill it later if needed -my $s_server_port = 0; -my $s_server_pid = 0; -my $s_client_match = 0; - -my $test_name = "test_ech_client_server"; -setup($test_name); - -plan skip_all => "$test_name requires ECH" - if disabled("ech"); -plan skip_all => "$test_name requires EC cryptography" - if disabled("ec") || disabled("ecx"); -plan skip_all => "$test_name requires sock enabled" - if disabled("sock"); -plan skip_all => "$test_name requires TLSv1.3 enabled" - if disabled("tls1_3"); -plan skip_all => "$test_name is not available Windows or VMS" - if $^O =~ /^(VMS|MSWin32|msys)$/; - -plan tests => 26; - -my $shlib_wrap = bldtop_file("util", "shlib_wrap.sh"); -my $apps_openssl = bldtop_file("apps", "openssl"); - -my $echconfig_pem = srctop_file("test", "certs", "echdir", "ech-eg.pem"); -my $badconfig_pem = srctop_file("test", "certs", "echdir", "ech-mid.pem"); -my $server_pem = srctop_file("test", "certs", "echserver.pem"); -my $server_key = srctop_file("test", "certs", "echserver.key"); -my $root_pem = srctop_file("test", "certs", "rootcert.pem"); -my $ech_dir = srctop_dir("test", "certs", "echdir" ); - -sub extract_ecl() -{ - # extract b64 encoded ECHConfigList from pem file - my $lb64 = ""; - my $inwanted = 0; - open( my $fh, '<', $echconfig_pem ) or die "Can't open $echconfig_pem $!"; - while( my $line = <$fh>) { - chomp $line; - if ( $line =~ /^-----BEGIN ECHCONFIG/) { - $inwanted = 1; - } elsif ( $line =~ /^-----END ECHCONFIG/) { - $inwanted = 0; - } elsif ($inwanted == 1) { - $lb64 .= $line; - } - } - print("base64 ECHConfigList: $lb64\n"); - return($lb64); -} - -my $good_b64 = extract_ecl(); - -sub start_ech_client_server -{ - my ( $test_type, $winpattern ) = @_; - my $timeout = 60; - - eval { - local $SIG{ALRM} = sub { die "timeout\n" }; - alarm $timeout; - my @s_server_cmd; - if ($test_type eq "cid-free" ) { - # turn on trial-decrypt, so client can use random CID - @s_server_cmd = ("s_server", "-accept", "0", "-naccept", "1", - "-cert", $server_pem, "-key", $server_key, - "-cert2", $server_pem, "-key2", $server_key, - "-ech_key", $echconfig_pem, - "-servername", "example.com", - "-ech_trialdecrypt", - "-tls1_3"); - } elsif ($test_type eq "keydir" ) { - # load keys from key dir (some will fail) - @s_server_cmd = ("s_server", "-accept", "0", "-naccept", "1", - "-cert", $server_pem, "-key", $server_key, - "-cert2", $server_pem, "-key2", $server_key, - "-ech_dir", $ech_dir, - "-ech_noretry_dir", $ech_dir, - "-servername", "example.com", - "-tls1_3"); - } elsif ($test_type eq "servername_fatal" ) { - # load keys from key dir (some will fail) - @s_server_cmd = ("s_server", "-accept", "0", "-naccept", "1", - "-cert", $server_pem, "-key", $server_key, - "-cert2", $server_pem, "-key2", $server_key, - "-ech_dir", $ech_dir, - "-ech_noretry_dir", $ech_dir, - "-servername", "example.com", - "-servername_fatal", - "-tls1_3"); - } elsif ($test_type eq "servername_fatal2" ) { - # load keys from key dir (some will fail) - @s_server_cmd = ("s_server", "-accept", "0", "-naccept", "1", - "-cert", $server_pem, "-key", $server_key, - "-cert2", $server_pem, "-key2", $server_key, - "-ech_dir", $ech_dir, - "-ech_noretry_dir", $ech_dir, - "-servername", "example.com", - "-servername_fatal", - "-tls1_3"); - } else { - # default for all other tests (for now) - @s_server_cmd = ("s_server", "-accept", "0", "-naccept", "1", - "-cert", $server_pem, "-key", $server_key, - "-cert2", $server_pem, "-key2", $server_key, - "-ech_key", $echconfig_pem, - "-servername", "example.com", - "-ech_greaseretries", - "-tls1_3"); - } - print("@s_server_cmd\n"); - $s_server_pid = open3(my $s_server_i, my $s_server_o, - my $s_server_e, - $shlib_wrap, $apps_openssl, @s_server_cmd); - # we're looking for... - # ACCEPT 0.0.0.0:45921 - # ACCEPT [::]:45921 - $s_server_port = "0"; - while (<$s_server_o>) { - print($_); - chomp; - if (/^ACCEPT 0.0.0.0:(\d+)/) { - $s_server_port = $1; - last; - } elsif (/^ACCEPT \[::\]:(\d+)/) { - $s_server_port = $1; - last; - } elsif (/^Using default/) { - ; - } elsif (/^Added (\d+) ECH/) { - ; - } elsif (/^Added ECH key pair/) { - ; - } elsif (/^Loaded/) { - ; - } elsif (/^Setting secondary/) { - ; - } elsif (/^Failed reading from/) { - ; - } else { - last; - } - } - # openssl s_client -connect localhost:NNNNN - # -servername server.example - # -CAfile test/certs/rootcert.pem - # -ech_config_list "ADn+...AA=" - # -prexit - my @s_client_cmd; - if ($test_type eq "GREASE-suite" ) { - # GREASE with suite - @s_client_cmd = ("s_client", - "-connect", "localhost:$s_server_port", - "-servername", "server.example", - "-CAfile", $root_pem, - "-ech_grease_suite", "0x21,2,3", - "-prexit"); - } elsif ($test_type eq "bad-GREASE-suite" ) { - # bad GREASE suite - @s_client_cmd = ("s_client", - "-connect", "localhost:$s_server_port", - "-servername", "server.example", - "-CAfile", $root_pem, - "-ech_grease_suite", "thisisnotagoodone", - "-prexit"); - } elsif ($test_type eq "lots-of-options" ) { - # real ECH with lots of options - @s_client_cmd = ("s_client", - "-connect", "localhost:$s_server_port", - "-servername", "server.example", - "-CAfile", $root_pem, - "-ech_config_list", $good_b64, - "-ech_outer_sni", "foodle.doodle", - "-ech_select", "0", - "-alpn", "http/1.1", - "-ech_outer_alpn", "http451", - "-prexit"); - } elsif ($test_type eq "GREASE-type" ) { - # GREASE with type - @s_client_cmd = ("s_client", - "-connect", "localhost:$s_server_port", - "-servername", "server.example", - "-CAfile", $root_pem, - "-ech_grease_type", "12345", - "-prexit"); - } elsif ($test_type eq "GREASE" ) { - # GREASE with suite - @s_client_cmd = ("s_client", - "-connect", "localhost:$s_server_port", - "-servername", "server.example", - "-CAfile", $root_pem, - "-ech_grease", - "-prexit"); - } elsif ($test_type eq "no-outer" ) { - # Real ECH, no outer SNI - @s_client_cmd = ("s_client", - "-connect", "localhost:$s_server_port", - "-servername", "server.example", - "-CAfile", $root_pem, - "-ech_config_list", $good_b64, - "-ech_no_outer_sni", - "-prexit"); - } elsif ($test_type eq "bad-ech" ) { - # bad ECH - @s_client_cmd = ("s_client", - "-connect", "localhost:$s_server_port", - "-servername", "server.example", - "-CAfile", $root_pem, - "-ech_config_list", "AEH+DQA91wAgACCBdNrnZxqNrUXSyimqqnfmNG4lHtVsbmaaIeRoUoFWFQAEAAEAAQAOc2VydmVyLmV4YW1wbGUAAA==", - "-prexit"); - } elsif ($test_type eq "cid-free" ) { - # Real ECH, ignore CID - @s_client_cmd = ("s_client", - "-connect", "localhost:$s_server_port", - "-servername", "server.example", - "-CAfile", $root_pem, - "-ech_config_list", $good_b64, - "-ech_ignore_cid", - "-prexit"); - } elsif ($test_type eq "cid-wrong" ) { - # Real ECH, ignore CID, no trial decrypt - @s_client_cmd = ("s_client", - "-connect", "localhost:$s_server_port", - "-servername", "server.example", - "-CAfile", $root_pem, - "-ech_config_list", $good_b64, - "-ech_ignore_cid", - "-prexit"); - - } elsif ($test_type eq "servername_fatal2" ) { - # Real ECH, but mismatching servername - @s_client_cmd = ("s_client", - "-connect", "localhost:$s_server_port", - "-servername", "server.not-the-example", - "-CAfile", $root_pem, - "-ech_config_list", $good_b64, - "-prexit"); - } else { - # Real ECH, and default - @s_client_cmd = ("s_client", - "-connect", "localhost:$s_server_port", - "-servername", "server.example", - "-CAfile", $root_pem, - "-ech_config_list", $good_b64, - "-prexit"); - } - print("@s_client_cmd\n"); - local (*sc_input); - my $s_client_pid = open3(*sc_input, my $s_client_o, - my $s_client_e, - $shlib_wrap, $apps_openssl, @s_client_cmd); - print sc_input "Q\n"; - close(sc_input); - waitpid($s_client_pid, 0); - my $stillthere = kill 0, $s_server_pid; - if ($stillthere) { - print("s_server process ($s_server_pid) is not dead yet.\n"); - kill 'HUP', $s_server_pid; - } - # the output from s_client that we want to check is written to its - # stdout, e.g: "^ECH: success, yay!" - $s_client_match = 0; - while (<$s_client_o>) { - print($_); - chomp; - if (/$winpattern/) { - $s_client_match = 1; - last; - } - } - - alarm 0; - }; - if ($@) { - if ($@ eq "timeout\n") { - print("TIMEOUT: test timed out after ${timeout}s\n"); - kill 'KILL', $s_server_pid - if $s_server_pid && kill(0, $s_server_pid); - } else { - die $@; - } - } -} - -sub basic_test { - print("\n\nBasic test.\n"); - my $tt = "basic"; - my $win = "^ECH: success"; - start_ech_client_server($tt, $win); - ok($s_server_port ne "0", "s_server port check"); - print("s_server ready, on port $s_server_port pid: $s_server_pid\n"); - ok($s_client_match == 1, "s_client with ECH on command line"); -} - -sub wrong_test { - print("\n\nWrong ECHConfig test.\n"); - # hardcoded 'cause we want a fail - my $tt="bad-ech", - my $win="^ECH: failed.retry-configs: -105"; - start_ech_client_server($tt, $win); - ok($s_server_port ne "0", "s_server port check"); - print("s_server ready, on port $s_server_port pid: $s_server_pid\n"); - ok($s_client_match == 1, "s_client with bad ECH"); -} - -sub grease_test { - print("\n\nGREASE ECHConfig test.\n"); - my $tt="GREASE"; - my $win="^ECH: GREASE"; - start_ech_client_server($tt, $win); - ok($s_server_port ne "0", "s_server port check"); - print("s_server ready, on port $s_server_port pid: $s_server_pid\n"); - ok($s_client_match == 1, "s_client with GREASE ECH"); -} - -sub grease_suite_test { - print("\n\nGREASE suite ECHConfig test.\n"); - my $tt="GREASE-suite"; - my $win="^ECH: GREASE"; - start_ech_client_server($tt, $win); - ok($s_server_port ne "0", "s_server port check"); - print("s_server ready, on port $s_server_port pid: $s_server_pid\n"); - ok($s_client_match == 1, "s_client with GREASE-suite ECH"); -} - -sub bad_grease_suite_test { - print("\n\nGREASE suite ECHConfig test.\n"); - my $tt="bad-GREASE-suite"; - my $win="^ECH: NOT CONFIGURED"; - start_ech_client_server($tt, $win); - ok($s_server_port ne "0", "s_server port check"); - print("s_server ready, on port $s_server_port pid: $s_server_pid\n"); - ok($s_client_match == 1, "s_client with bad GREASE-suite ECH"); -} - -sub grease_type_test { - print("\n\nGREASE type ECH test.\n"); - my $tt="GREASE-type"; - my $win="^ECH: GREASE"; - start_ech_client_server($tt, $win); - ok($s_server_port ne "0", "s_server port check"); - print("s_server ready, on port $s_server_port pid: $s_server_pid\n"); - ok($s_client_match == 1, "s_client with GREASE-type ECH"); -} - -sub lots_of_options_test { - print("\n\nLots of options ECH test.\n"); - my $tt="lots-of-options"; - my $win="^ECH: success"; - start_ech_client_server($tt, $win); - ok($s_server_port ne "0", "s_server port check"); - print("s_server ready, on port $s_server_port pid: $s_server_pid\n"); - ok($s_client_match == 1, "s_client with lots of ECH options"); -} - -sub no_outer_test { - print("\n\nNo outer SNI test.\n"); - my $tt = "no-outer"; - my $win = "^ECH: success"; - start_ech_client_server($tt, $win); - ok($s_server_port ne "0", "s_server port check"); - print("s_server ready, on port $s_server_port pid: $s_server_pid\n"); - ok($s_client_match == 1, "s_client with no outer SNI ECH"); -} - -sub cid_free_test { - print("\n\nIgnore CIDs test.\n"); - my $tt = "cid-free"; - my $win = "^ECH: success"; - start_ech_client_server($tt, $win); - ok($s_server_port ne "0", "s_server port check"); - print("s_server ready, on port $s_server_port pid: $s_server_pid\n"); - ok($s_client_match == 1, "s_client/s_server with no CID/trial decrypt"); -} - -sub cid_wrong_test { - print("\n\nIgnore CIDs test.\n"); - my $tt = "cid-wrong"; - my $win = "^ECH: failed"; - start_ech_client_server($tt, $win); - ok($s_server_port ne "0", "s_server port check"); - print("s_server ready, on port $s_server_port pid: $s_server_pid\n"); - ok($s_client_match == 1, "s_client/s_server with no CID/no trial decrypt"); -} - -sub keydir_test { - print("\n\nServer using key dir test.\n"); - my $tt = "keydir"; - my $win = "^ECH: success"; - start_ech_client_server($tt, $win); - ok($s_server_port ne "0", "s_server port check"); - print("s_server ready, on port $s_server_port pid: $s_server_pid\n"); - ok($s_client_match == 1, "s_server using ech keydir on command line"); -} - -sub servernamefatal_test { - print("\n\nServer using servername_fatal test.\n"); - my $tt = "servername_fatal"; - my $win = "^ECH: success"; - start_ech_client_server($tt, $win); - ok($s_server_port ne "0", "s_server port check"); - print("s_server ready, on port $s_server_port pid: $s_server_pid\n"); - ok($s_client_match == 1, "s_server using ech servername_fatal on command line"); -} - -sub servernamefatal_test2 { - print("\n\nServer using servername_fatal test.\n"); - my $tt = "servername_fatal2"; - my $win = "^ECH: tried but failed"; - start_ech_client_server($tt, $win); - ok($s_server_port ne "0", "s_server port check"); - print("s_server ready, on port $s_server_port pid: $s_server_pid\n"); - ok($s_client_match == 1, "s_server using ech servername_fatal and bad name on command line"); -} - -basic_test(); -wrong_test(); -grease_test(); -grease_suite_test(); -bad_grease_suite_test(); -grease_type_test(); -lots_of_options_test(); -no_outer_test(); -cid_free_test(); -cid_wrong_test(); -keydir_test(); -servernamefatal_test(); -servernamefatal_test2(); - diff --git a/test/recipes/90-test_base64_simdutf.t b/test/recipes/90-test_base64_simdutf.t deleted file mode 100644 index be30583787..0000000000 --- a/test/recipes/90-test_base64_simdutf.t +++ /dev/null @@ -1,11 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use OpenSSL::Test::Simple; - -simple_test("test_base64_simdutf", "base64_simdutf_test", "base64_simdutf"); diff --git a/test/recipes/90-test_crypto_memcmp.t b/test/recipes/90-test_crypto_memcmp.t deleted file mode 100644 index 6ddd279458..0000000000 --- a/test/recipes/90-test_crypto_memcmp.t +++ /dev/null @@ -1,12 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - - -use OpenSSL::Test::Simple; - -simple_test("test_crypto_memcmp", "crypto_memcmp_test"); diff --git a/test/recipes/90-test_dtls12_psk.t b/test/recipes/90-test_dtls12_psk.t deleted file mode 100644 index c7ed9759fc..0000000000 --- a/test/recipes/90-test_dtls12_psk.t +++ /dev/null @@ -1,20 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use OpenSSL::Test; -use OpenSSL::Test::Utils; - -my $test_name = "test_dtls12psk"; -setup($test_name); - -plan skip_all => "$test_name is not supported in this build" - if disabled("dtls1_2") || disabled("psk"); - -plan tests => 1; - -ok(run(test(["dtls12psk_test"])), "running dtls12psk_test"); diff --git a/test/recipes/90-test_fatalerr.t b/test/recipes/90-test_fatalerr.t index 50b7a7543b..a52878373e 100644 --- a/test/recipes/90-test_fatalerr.t +++ b/test/recipes/90-test_fatalerr.t @@ -13,7 +13,7 @@ use OpenSSL::Test qw/:DEFAULT srctop_file/; setup("test_fatalerr"); plan skip_all => "No TLS/SSL protocols are supported by this OpenSSL build" - if alldisabled(available_protocols("tls")); + if alldisabled(grep { $_ ne "ssl3" } available_protocols("tls")); plan tests => 1; diff --git a/test/recipes/90-test_includes.t b/test/recipes/90-test_includes.t index 412bdf6115..5ff61910c5 100644 --- a/test/recipes/90-test_includes.t +++ b/test/recipes/90-test_includes.t @@ -35,9 +35,6 @@ ok(run(test(["conf_include_test", "-f", data_file("incdir.cnf")])), "test inclu SKIP: { skip "Skipping legacy test", 1 if disabled("legacy"); - # Ensure libcrypto can be resolved for the legacy provider on AIX. - local $ENV{LIBPATH} = abs_path(bldtop_dir(".")) - if config('target') =~ m|^aix|; ok(run(test(["conf_include_test", "-providers", data_file("includes-prov-dir.cnf")])), "test directory includes with provider configs"); } diff --git a/test/recipes/90-test_includes_data/conf-includes/includes1.cnf b/test/recipes/90-test_includes_data/conf-includes/includes1.cnf index 45b85c4c9a..5959b23e4b 100644 --- a/test/recipes/90-test_includes_data/conf-includes/includes1.cnf +++ b/test/recipes/90-test_includes_data/conf-includes/includes1.cnf @@ -13,6 +13,7 @@ default_ca = CA_default # The default ca section dir = ./demoCA # Where everything is kept certs = $dir/certs # Where the issued certs are kept +crl_dir = $dir/crl # Where the issued crl are kept database = $dir/index.txt # database index file. new_certs_dir = $dir/new_certs # default place for new certs. diff --git a/test/recipes/90-test_memfail.t b/test/recipes/90-test_memfail.t index fefc2771b6..070a270ec4 100644 --- a/test/recipes/90-test_memfail.t +++ b/test/recipes/90-test_memfail.t @@ -26,32 +26,32 @@ plan skip_all => "$test_name requires allocfail-tests to be enabled" # and parse that to figure out what our values are # my $resultdir = result_dir(); - -$ENV{OPENSSL_TEST_MFAIL_DISABLE} = "1"; - run(test(["handshake-memfail", "count", srctop_dir("test", "certs")], stderr => "$resultdir/hscountinfo.txt")); run(test(["x509-memfail", "count", srctop_file("test", "certs", "servercert.pem")], stderr => "$resultdir/x509countinfo.txt")); -run(test(["load_key_certs_crls_memfail", "count", srctop_file("test", "certs", "servercert.pem")], stderr => "$resultdir/load_key_certs_crls_countinfo.txt")); - sub get_count_info { my ($infile) = @_; - my ($skipcount, $malloccount) = (0, 0); + my @vals; - open my $handle, '<', "$infile" or return (0, 0); + # Read in our input file + open my $handle, '<', "$infile"; chomp(my @lines = <$handle>); close $handle; - # Match the test program output: "skip: count " - # Stderr may be captured with a "# " prefix per line (TAP-style). - foreach (@lines) { - if (/\bskip:\s*(\d+)\s+count\s+(\d+)/) { - $skipcount = $1; - $malloccount = $2; + # parse the input file + foreach(@lines) { + if ($_ =~/skip:/) { + @vals = split ' ', $_; last; } } + # + #The number of allocations we skip is in argument 2 + #The number of mallocs we shoudl test is in argument 4 + # + my $skipcount = $vals[2]; + my $malloccount = $vals[4]; return ($skipcount, $malloccount); } @@ -59,36 +59,28 @@ my ($hsskipcount, $hsmalloccount) = get_count_info("$resultdir/hscountinfo.txt") my ($x509skipcount, $x509malloccount) = get_count_info("$resultdir/x509countinfo.txt"); -my ($load_key_certs_crls_skipcount, $load_key_certs_crls_malloccount) = get_count_info("$resultdir/load_key_certs_crls_countinfo.txt"); - -my $total_malloccount = $hsmalloccount + $x509malloccount - + $load_key_certs_crls_malloccount; -plan skip_all => "could not get malloc counts (one or more count runs failed or output format changed)" - if $total_malloccount == 0; - # # Now we can plan our tests. We plan to run malloccount iterations of this # test # -plan tests => $total_malloccount; +plan tests => $hsmalloccount + $x509malloccount; sub run_memfail_test { my $skipcount = $_[0]; - my @mallocseq = (0..$_[1] - 1); + my @mallocseq = (1..$_[1]); my @cmd = $_[2]; for my $idx (@mallocseq) { # # We need to setup our openssl malloc failures env var to fail the target malloc # the format of this string is a series of A@B;C@D tuples where A,C are the number - # of mallocs to consider, and B,D are the likelihood that they should fail. + # of mallocs to consider, and B,D are the likelyhood that they should fail. # We always skip the first "skip" allocations, then iteratively guarantee that # next mallocs pass, followed by the next single malloc failing, with the remainder # passing # $ENV{OPENSSL_MALLOC_FAILURES} = "$skipcount\@0;$idx\@0;1\@100;0\@0"; - ok(run(test(@cmd))) || \ - print STDERR "# OPENSSL_MALLOC_FAILURES=$ENV{OPENSSL_MALLOC_FAILURES}\n"; + ok(run(test(@cmd))); } } @@ -96,4 +88,3 @@ run_memfail_test($hsskipcount, $hsmalloccount, ["handshake-memfail", "run", srct run_memfail_test($x509skipcount, $x509malloccount, ["x509-memfail", "run", srctop_file("test", "certs", "servercert.pem")]); -run_memfail_test($load_key_certs_crls_skipcount, $load_key_certs_crls_malloccount, ["load_key_certs_crls_memfail", "run", srctop_file("test", "certs", "servercert.pem")]); diff --git a/test/recipes/90-test_memleak.t b/test/recipes/90-test_memleak.t index 3a1306192e..76f1dcb06d 100644 --- a/test/recipes/90-test_memleak.t +++ b/test/recipes/90-test_memleak.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2016 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -8,13 +8,9 @@ use OpenSSL::Test; -use OpenSSL::Test::Utils; setup("test_memleak"); -plan skip_all => "This test should not be run under valgrind" - if (defined ($ENV{OSSL_USE_VALGRIND})); - plan skip_all => "MacOS currently doesn't support leak sanitizer" if $^O eq 'darwin'; diff --git a/test/recipes/90-test_quic_memfail.t b/test/recipes/90-test_quic_memfail.t deleted file mode 100644 index c90ac772c9..0000000000 --- a/test/recipes/90-test_quic_memfail.t +++ /dev/null @@ -1,22 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use OpenSSL::Test; -use OpenSSL::Test::Utils; - -setup("quic_memfail_test"); - -plan skip_all => "QUIC protocol is not supported by this OpenSSL build" - if disabled('quic'); - -plan skip_all => "qlog is not supported by this OpenSSL build" - if disabled('qlog'); - -plan tests => 1; - -ok(run(test(["quic_memfail_test"]))); diff --git a/test/recipes/90-test_shlibload.t b/test/recipes/90-test_shlibload.t index 6b0cda3872..67afff607e 100644 --- a/test/recipes/90-test_shlibload.t +++ b/test/recipes/90-test_shlibload.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016-2024 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -23,20 +23,53 @@ plan skip_all => "Test is disabled on AIX" if config('target') =~ m|^aix|; plan skip_all => "Test is disabled on NonStop" if config('target') =~ m|^nonstop|; plan skip_all => "Test only supported in a dso build" if disabled("dso"); plan skip_all => "Test is disabled in an address sanitizer build" unless disabled("asan"); +plan skip_all => "Test is disabled in no-atexit build" if disabled("atexit"); -plan tests => 4; +plan tests => 10; my $libcrypto = platform->sharedlib('libcrypto'); my $libssl = platform->sharedlib('libssl'); +my $atexit_outfile; -ok(run(test(["shlibloadtest", "-crypto_first", $libcrypto, $libssl])), - "running shlibloadtest -crypto_first"); +$atexit_outfile = 'atexit-cryptofirst.txt'; +1 while unlink $atexit_outfile; +ok(run(test(["shlibloadtest", "-crypto_first", $libcrypto, $libssl, $atexit_outfile])), + "running shlibloadtest -crypto_first $atexit_outfile"); +ok(check_atexit($atexit_outfile)); -ok(run(test(["shlibloadtest", "-ssl_first", $libcrypto, $libssl])), - "running shlibloadtest -ssl_first"); +$atexit_outfile = 'atexit-sslfirst.txt'; +1 while unlink $atexit_outfile; +ok(run(test(["shlibloadtest", "-ssl_first", $libcrypto, $libssl, $atexit_outfile])), + "running shlibloadtest -ssl_first $atexit_outfile"); +ok(check_atexit($atexit_outfile)); -ok(run(test(["shlibloadtest", "-just_crypto", $libcrypto, $libssl])), - "running shlibloadtest -just_crypto"); +$atexit_outfile = 'atexit-justcrypto.txt'; +1 while unlink $atexit_outfile; +ok(run(test(["shlibloadtest", "-just_crypto", $libcrypto, $libssl, $atexit_outfile])), + "running shlibloadtest -just_crypto $atexit_outfile"); +ok(check_atexit($atexit_outfile)); -ok(run(test(["shlibloadtest", "-dso_ref", $libcrypto, $libssl])), - "running shlibloadtest -dso_ref"); +$atexit_outfile = 'atexit-dsoref.txt'; +1 while unlink $atexit_outfile; +ok(run(test(["shlibloadtest", "-dso_ref", $libcrypto, $libssl, $atexit_outfile])), + "running shlibloadtest -dso_ref $atexit_outfile"); +ok(check_atexit($atexit_outfile)); + +$atexit_outfile = 'atexit-noatexit.txt'; +1 while unlink $atexit_outfile; +ok(run(test(["shlibloadtest", "-no_atexit", $libcrypto, $libssl, $atexit_outfile])), + "running shlibloadtest -no_atexit $atexit_outfile"); +ok(!check_atexit($atexit_outfile)); + +sub check_atexit { + my $filename = shift; + + open my $fh, '<', $filename; + return 0 unless defined $fh; + + my $data = <$fh>; + + return 1 if (defined $data && $data =~ m/atexit\(\) run/); + + return 0; +} diff --git a/test/recipes/90-test_sslapi.t b/test/recipes/90-test_sslapi.t index 25069f7985..9bb5c50c47 100644 --- a/test/recipes/90-test_sslapi.t +++ b/test/recipes/90-test_sslapi.t @@ -32,7 +32,7 @@ my $fipsmodcfgtmp = result_file($fipsmodcfgtmp_filename); my $provconfnew = result_file("fips-and-base-temp.cnf"); plan skip_all => "No TLS/SSL protocols are supported by this OpenSSL build" - if alldisabled(available_protocols("tls")); + if alldisabled(grep { $_ ne "ssl3" } available_protocols("tls")); plan tests => 4; diff --git a/test/recipes/90-test_sslapi_data/ssltraceref-zlib.txt b/test/recipes/90-test_sslapi_data/ssltraceref-zlib.txt index e6c193fa82..4c58d23db5 100644 --- a/test/recipes/90-test_sslapi_data/ssltraceref-zlib.txt +++ b/test/recipes/90-test_sslapi_data/ssltraceref-zlib.txt @@ -14,6 +14,10 @@ Header: compression_methods (len=1) No Compression (0x00) extensions, length = ? + extension_type=ec_point_formats(11), length=4 + uncompressed (0) + ansiX962_compressed_prime (1) + ansiX962_compressed_char2 (2) extension_type=supported_groups(10), length=20 MLKEM512 (512) MLKEM768 (513) @@ -48,19 +52,6 @@ Header: rsa_pkcs1_sha256 (0x0401) rsa_pkcs1_sha384 (0x0501) rsa_pkcs1_sha512 (0x0601) - slhdsa_sha2_128s (0x0911) - slhdsa_sha2_128f (0x0912) - slhdsa_sha2_192s (0x0913) - slhdsa_sha2_192f (0x0914) - slhdsa_sha2_256s (0x0915) - slhdsa_sha2_256f (0x0916) - slhdsa_shake_128s (0x0917) - slhdsa_shake_128f (0x0918) - slhdsa_shake_192s (0x0919) - slhdsa_shake_192f (0x091a) - slhdsa_shake_256s (0x091b) - slhdsa_shake_256f (0x091c) - sm2sig_sm3 (0x0708) extension_type=supported_versions(43), length=3 TLS 1.3 (772) extension_type=psk_key_exchange_modes(45), length=2 diff --git a/test/recipes/90-test_sslapi_data/ssltraceref.txt b/test/recipes/90-test_sslapi_data/ssltraceref.txt index b5d8931e3d..451c98284b 100644 --- a/test/recipes/90-test_sslapi_data/ssltraceref.txt +++ b/test/recipes/90-test_sslapi_data/ssltraceref.txt @@ -14,6 +14,10 @@ Header: compression_methods (len=1) No Compression (0x00) extensions, length = ? + extension_type=ec_point_formats(11), length=4 + uncompressed (0) + ansiX962_compressed_prime (1) + ansiX962_compressed_char2 (2) extension_type=supported_groups(10), length=20 MLKEM512 (512) MLKEM768 (513) @@ -48,19 +52,6 @@ Header: rsa_pkcs1_sha256 (0x0401) rsa_pkcs1_sha384 (0x0501) rsa_pkcs1_sha512 (0x0601) - slhdsa_sha2_128s (0x0911) - slhdsa_sha2_128f (0x0912) - slhdsa_sha2_192s (0x0913) - slhdsa_sha2_192f (0x0914) - slhdsa_sha2_256s (0x0915) - slhdsa_sha2_256f (0x0916) - slhdsa_shake_128s (0x0917) - slhdsa_shake_128f (0x0918) - slhdsa_shake_192s (0x0919) - slhdsa_shake_192f (0x091a) - slhdsa_shake_256s (0x091b) - slhdsa_shake_256f (0x091c) - sm2sig_sm3 (0x0708) extension_type=supported_versions(43), length=3 TLS 1.3 (772) extension_type=psk_key_exchange_modes(45), length=2 diff --git a/test/recipes/90-test_store.t b/test/recipes/90-test_store.t index cb3289d077..bc22fdaad7 100644 --- a/test/recipes/90-test_store.t +++ b/test/recipes/90-test_store.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -36,7 +36,7 @@ my @data_files = ( "testrsa.msb" ); push(@data_files, ( "testrsa.pvk" )) - unless disabled("legacy") || disabled("rc4") || disabled("pvkkdf"); + unless disabled("legacy") || disabled("rc4"); my @src_rsa_files = ( "test/testrsa.pem", "test/testrsapub.pem" ); diff --git a/test/recipes/90-test_sysdefault_data/sysdefault-ignore.cnf b/test/recipes/90-test_sysdefault_data/sysdefault-ignore.cnf index e2b845021a..2b04caf83f 100644 --- a/test/recipes/90-test_sysdefault_data/sysdefault-ignore.cnf +++ b/test/recipes/90-test_sysdefault_data/sysdefault-ignore.cnf @@ -19,6 +19,5 @@ system_default = ssl_default_sect [ssl_default_sect] SignatureAlgorithms = RSA+SHA256:nonex -Ciphersuites = INVALID_CIPHERSUITE MaxProtocol = TLSv1.2 MinProtocol = TLSv1.2 diff --git a/test/recipes/90-test_threads.t b/test/recipes/90-test_threads.t index 749a4f482a..8033ad10c6 100644 --- a/test/recipes/90-test_threads.t +++ b/test/recipes/90-test_threads.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2015-2022 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -23,9 +23,6 @@ my $no_fips = disabled('fips') || ($ENV{NO_FIPS} // 0); my $config_path = abs_path(srctop_file("test", $no_fips ? "default.cnf" : "default-and-fips.cnf")); -plan skip_all => "This test should not be run under valgrind" - if (defined $ENV{OSSL_USE_VALGRIND}); - plan tests => 3; if ($no_fips) { diff --git a/test/recipes/90-test_tls12_psk.t b/test/recipes/90-test_tls12_psk.t deleted file mode 100644 index e8d3aa7009..0000000000 --- a/test/recipes/90-test_tls12_psk.t +++ /dev/null @@ -1,20 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use OpenSSL::Test; -use OpenSSL::Test::Utils; - -my $test_name = "test_tls12psk"; -setup($test_name); - -plan skip_all => "$test_name is not supported in this build" - if disabled("tls1_2") || disabled("psk"); - -plan tests => 1; - -ok(run(test(["tls12psk_test"])), "running tls12psk_test"); diff --git a/test/recipes/92-test_engine_stubs.t b/test/recipes/92-test_engine_stubs.t deleted file mode 100644 index 4e750abfb8..0000000000 --- a/test/recipes/92-test_engine_stubs.t +++ /dev/null @@ -1,12 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - - -use OpenSSL::Test::Simple; - -simple_test("test_engine_stubs", "engine_stubs_test"); diff --git a/test/recipes/95-test_external_ech_bssl.t b/test/recipes/95-test_external_ech_bssl.t deleted file mode 100644 index f46d2f174d..0000000000 --- a/test/recipes/95-test_external_ech_bssl.t +++ /dev/null @@ -1,29 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - - -use OpenSSL::Test; -use OpenSSL::Test::Utils; -use OpenSSL::Test qw/:DEFAULT data_file bldtop_dir srctop_dir cmdstr/; - -setup("test_external_ech_bssl"); - -plan skip_all => "No external tests in this configuration" - if disabled("external-tests"); -plan skip_all => "External ECH tests not available on Windows or VMS" - if $^O =~ /^(VMS|MSWin32)$/; -plan skip_all => "External ECH tests not supported in out of tree builds" - if bldtop_dir() ne srctop_dir(); - -plan tests => 2; - -ok(run(cmd(["sh", data_file("ech_bssl_external.sh")])), - "running ECH client external boringssl tests"); - -ok(run(cmd(["sh", data_file("ech_bssl_server_external.sh")])), - "running ECH server external boringssl tests"); diff --git a/test/recipes/95-test_external_ech_bssl_data/ech_bssl_external.sh b/test/recipes/95-test_external_ech_bssl_data/ech_bssl_external.sh deleted file mode 100755 index 10970b2232..0000000000 --- a/test/recipes/95-test_external_ech_bssl_data/ech_bssl_external.sh +++ /dev/null @@ -1,101 +0,0 @@ -#!/bin/sh - -# -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -# OpenSSL ECH external testing using boringssl client - -PWD="$(pwd)" - -SRCTOP="$(cd $SRCTOP; pwd)" -BLDTOP="$(cd $BLDTOP; pwd)" - -if [ "$SRCTOP" != "$BLDTOP" ] ; then - echo "Out of tree builds not supported with ECH external test!" - exit 1 -fi - -O_EXE="$BLDTOP/apps" -O_BINC="$BLDTOP/include" -O_SINC="$SRCTOP/include" -O_LIB="$BLDTOP" - -unset OPENSSL_CONF - -export PATH="$O_EXE:$PATH" -export LD_LIBRARY_PATH="$O_LIB:$LD_LIBRARY_PATH" -export OPENSSL_ROOT_DIR="$O_LIB" - -# Check/Set openssl version -OPENSSL_VERSION=`openssl version | cut -f 2 -d ' '` -ECHCONFIGFILE=$SRCTOP/test/certs/echdir/ech-eg.pem -httphost=server.example -httpreq="GET /stats HTTP/1.1\\r\\nConnection: close\\r\\nHost: $httphost\\r\\n\\r\\n" -BTOOL=$SRCTOP/boringssl/.local/bin - -echo "------------------------------------------------------------------" -echo "Testing OpenSSL s_server using ECH-enabled boringssl client:" -echo " CWD: $PWD" -echo " SRCTOP: $SRCTOP" -echo " BLDTOP: $BLDTOP" -echo " OPENSSL_ROOT_DIR: $OPENSSL_ROOT_DIR" -echo " OpenSSL version: $OPENSSL_VERSION" -echo " PEM ECH Config file: $ECHCONFIGFILE" - -echo "------------------------------------------------------------------" - -if [ ! -f $BTOOL/bssl ]; then - echo "You need to have built boringssl before running this test." - echo "To do that, run the following commands:" - cat <$bechfile -echo "Running bssl s_client against localhost" -(echo -e $httpreq ; sleep 2) | \ - $BTOOL/bssl s_client -connect localhost:8443 \ - -ech-config-list $bechfile \ - -server-name $httphost \ - -root-certs $SRCTOP/test/certs/rootcert.pem > $resfile 2>&1 -rm -f $bechfile -cat $resfile -success=`grep -c "Encrypted ClientHello: yes" $resfile` -rm -f $resfile -# if success==1 we're good so exit with a zero for test success -exit $((success != 1)) diff --git a/test/recipes/95-test_external_ech_bssl_data/ech_bssl_server_external.sh b/test/recipes/95-test_external_ech_bssl_data/ech_bssl_server_external.sh deleted file mode 100755 index 863ad52973..0000000000 --- a/test/recipes/95-test_external_ech_bssl_data/ech_bssl_server_external.sh +++ /dev/null @@ -1,107 +0,0 @@ -#!/bin/sh - -# -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -# OpenSSL ECH external testing using boringssl server - -PWD="$(pwd)" - -SRCTOP="$(cd $SRCTOP; pwd)" -BLDTOP="$(cd $BLDTOP; pwd)" - -if [ "$SRCTOP" != "$BLDTOP" ] ; then - echo "Out of tree builds not supported with ECH external test!" - exit 1 -fi - -O_EXE="$BLDTOP/apps" -O_BINC="$BLDTOP/include" -O_SINC="$SRCTOP/include" -O_LIB="$BLDTOP" - -unset OPENSSL_CONF - -export PATH="$O_EXE:$PATH" -export LD_LIBRARY_PATH="$O_LIB:$LD_LIBRARY_PATH" -export OPENSSL_ROOT_DIR="$O_LIB" - -# Check/Set openssl version -OPENSSL_VERSION=`openssl version | cut -f 2 -d ' '` -ECHCONFIGFILE=$SRCTOP/test/certs/echdir/ech-eg.pem -httphost=server.example -httpreq="GET /stats HTTP/1.1\\r\\nConnection: close\\r\\nHost: $httphost\\r\\n\\r\\n" -BTOOL=$SRCTOP/boringssl/.local/bin - -echo "------------------------------------------------------------------" -echo "Testing ECH-enabled boringssl server using s_client:" -echo " CWD: $PWD" -echo " SRCTOP: $SRCTOP" -echo " BLDTOP: $BLDTOP" -echo " OPENSSL_ROOT_DIR: $OPENSSL_ROOT_DIR" -echo " OpenSSL version: $OPENSSL_VERSION" -echo " PEM ECH Config file: $ECHCONFIGFILE" - -echo "------------------------------------------------------------------" - -if [ ! -f $BTOOL/bssl ]; then - echo "You need to have built boringssl before running this test." - echo "To do that, run the following commands:" - cat <$bsslpem - -# Start a boringssl s_server -$BTOOL/bssl s_server \ - -accept 8443 \ - -key $SRCTOP/test/certs/echserver.key -cert $SRCTOP/test/certs/echserver.pem \ - -ech-config $bsslech -ech-key $bsslkey \ - -www -loop & -pids=`ps -ef | grep 'bssl s_server' | grep -v grep | awk '{print $2}'` -if [ -z "$pids" ] -then - echo "No sign of s_server - exiting (before client)" - rm -f $bssllist $bsslech $bsslkey $bsslpem - exit 88 -fi -echo "Running openssl s_client against localhost" -(echo -e $httpreq ; sleep 2) | \ - $SRCTOP/apps/openssl s_client -connect localhost:8443 \ - -CAfile $SRCTOP/test/certs/rootcert.pem \ - -ech_config_list `cat $bsslpem` \ - -servername $httphost \ - -tls1_3 -ignore_unexpected_eof -success=$? -# bssl server has to be killed -kill $pids -rm -f $bssllist $bsslech $bsslkey $bsslpem -# s_client returns 1 if ok, we want to exit with 0 for a PASS -exit $success diff --git a/test/recipes/95-test_external_ech_nss.t b/test/recipes/95-test_external_ech_nss.t deleted file mode 100644 index c6aefdbb45..0000000000 --- a/test/recipes/95-test_external_ech_nss.t +++ /dev/null @@ -1,48 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - - -use OpenSSL::Test; -use OpenSSL::Test::Utils; -use OpenSSL::Test qw/:DEFAULT data_file bldtop_dir srctop_dir cmdstr/; - -setup("test_external_ech_nss"); - -plan skip_all => "No external tests in this configuration" - if disabled("external-tests"); -plan skip_all => "External ECH tests not available on Windows or VMS" - if $^O =~ /^(VMS|MSWin32)$/; - #plan skip_all => "External ECH tests only available in a shared build" - #if disabled("shared"); -plan skip_all => "External ECH tests not supported in out of tree builds" - if bldtop_dir() ne srctop_dir(); - -# There is an issue with running the NSS server test in the CI setup. The -# NSS server test uses the NSS selfserv test server, which, when ECH is -# enabled generates an ephemeral ECHConfig and private key and prints the -# base64 encoded ECHConfigList to stdout, which we then collect and feed -# into s_client for the ECH test. When run locally this requires setting -# `stdbuf -o0` on the command line to avoid buffering, but that setting -# seems not to work in the CI environment. For now, we therefore omit the -# NSS server test when running in the CI environment, which is ok as we -# have another test checking ECH between s_client and the BoringSSL test -# server. As a result, we need to set `OSSL_RUN_CI_TESTS` in the CI -# environment to signal that the NSS server test is not to be run. -if (defined ($ENV{OSSL_RUN_CI_TESTS})) { - plan tests => 1; -} else { - plan tests => 2; -} - -ok(run(cmd(["sh", data_file("ech_nss_external.sh")])), - "running ECH client external NSS tests"); - -if (! defined ($ENV{OSSL_RUN_CI_TESTS})) { - ok(run(cmd(["sh", data_file("ech_nss_server_external.sh")])), - "running ECH server external NSS tests"); -} diff --git a/test/recipes/95-test_external_ech_nss_data/ech_nss_external.sh b/test/recipes/95-test_external_ech_nss_data/ech_nss_external.sh deleted file mode 100755 index f855b3125f..0000000000 --- a/test/recipes/95-test_external_ech_nss_data/ech_nss_external.sh +++ /dev/null @@ -1,118 +0,0 @@ -#!/usr/bin/env bash - -# -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -# OpenSSL ECH external testing using nss client - -PWD="$(pwd)" - -SRCTOP="$(cd $SRCTOP; pwd)" -BLDTOP="$(cd $BLDTOP; pwd)" - -if [ "$SRCTOP" != "$BLDTOP" ] ; then - echo "Out of tree builds not supported with ECH external test!" - exit 1 -fi - -O_EXE="$BLDTOP/apps" -O_BINC="$BLDTOP/include" -O_SINC="$SRCTOP/include" -O_LIB="$BLDTOP" - -unset OPENSSL_CONF - -export PATH="$O_EXE:$PATH" -export LD_LIBRARY_PATH="$O_LIB:$LD_LIBRARY_PATH" -export OPENSSL_ROOT_DIR="$O_LIB" - -# Check/Set openssl version -OPENSSL_VERSION=`openssl version | cut -f 2 -d ' '` -ECHCONFIGFILE=$SRCTOP/test/certs/echdir/ech-eg.pem -httphost=server.example -httpreq="GET /stats HTTP/1.1\\r\\nConnection: close\\r\\nHost: $httphost\\r\\n\\r\\n" - -echo "------------------------------------------------------------------" -echo "Testing OpenSSL s_server using ECH-enabled nss client:" -echo " CWD: $PWD" -echo " SRCTOP: $SRCTOP" -echo " BLDTOP: $BLDTOP" -echo " OPENSSL_ROOT_DIR: $OPENSSL_ROOT_DIR" -echo " OpenSSL version: $OPENSSL_VERSION" -echo " PEM ECH Config file: $ECHCONFIGFILE" - -echo "------------------------------------------------------------------" - -LATEST='non-existent-directory' -if [ -f $SRCTOP/nss/dist/latest ]; then - LATEST=`cat $SRCTOP/nss/dist/latest` -fi -LDIR=$SRCTOP/nss/dist/$LATEST/bin -NLIB=$SRCTOP/nss/dist/$LATEST/lib - -if [ ! -f $LDIR/tstclnt ]; then - # clone our NSS and NSPR - echo "You need to have built NSS before running this test." - echo "To do that, run the following commands:" - cat <sillypassfile - LD_LIBRARY_PATH=$NLIB $LDIR/pk12util \ - -i tmp.p12 -d $SRCTOP/nss/server -w sillypassfile - cat sillypassfile - # rm -f sillypassfile tmp.p12 -fi - -echo " CWD: $PWD" - -# Start an NSS server -# We'll let the server generate the ECH key pair for now (see -# below for why). - -# need to use ``stdbuf -o0`` so that we don't get buffering and -# can grab echconfig immediately... -LD_LIBRARY_PATH=$NLIB stdbuf -o0 $LDIR/selfserv -p 8443 -d $SRCTOP/nss/server \ - -n server.example -X "publicname:example.com" >ss-echfile & - -# For the future, we'd like a provide our private-key/ECHConfig to -# NSS - looks like there could be some work required to get that -# selfserve option working. -# https://bugzilla.mozilla.org/show_bug.cgi?id=1876732 - -pids=`ps -ef | grep selfserv | grep -v grep | awk '{print $2}'` -if [ -z "$pids" ] -then - echo "No sign of selfserv - exiting (before client)" - exit 88 -fi - -ECH=`cat ss-echfile` -echo "Running openssl s_client against localhost" -(echo -e $httpreq ; sleep 2) | \ - $SRCTOP/apps/openssl s_client -connect localhost:8443 \ - -CAfile $SRCTOP/test/certs/rootcert.pem \ - -ech_config_list $ECH \ - -servername $httphost \ - -no_ssl3 -no_tls1 -no_tls1_1 -no_tls1_2 -success=$? -# nss server needs killing -kill $pids -exit $success diff --git a/test/recipes/95-test_external_krb5_data/krb5.sh b/test/recipes/95-test_external_krb5_data/krb5.sh index 88a08e3127..eeaa59f961 100755 --- a/test/recipes/95-test_external_krb5_data/krb5.sh +++ b/test/recipes/95-test_external_krb5_data/krb5.sh @@ -1,6 +1,6 @@ #!/bin/sh -ex # -# Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2017-2021 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -11,26 +11,7 @@ LDFLAGS="-L`pwd`/$BLDTOP -Wl,-rpath,`pwd`/$BLDTOP" CFLAGS="-I`pwd`/$BLDTOP/include -I`pwd`/$SRCTOP/include" -unpatch() { - cd "$SRC_ABS_TOP/krb5" && git reset --hard "$GITLEVEL" -} - -trap unpatch EXIT - -cd $SRCTOP -SRC_ABS_TOP=$PWD; -DATA_ABS_TOP=$SRC_ABS_TOP/test/recipes/95-test_external_krb5_data - -cd $SRC_ABS_TOP/krb5 -GITLEVEL=$(git rev-parse HEAD) -# "git am" refuses to run without a user configured. -for FILE in "$DATA_ABS_TOP"/patches/*; do - if [ -f "$FILE" ]; then - git -c 'user.name=OpenSSL External Tests' -c 'user.email=nonsuch@openssl.org' am $FILE - fi -done -cd $SRC_ABS_TOP/krb5/src - +cd $SRCTOP/krb5/src autoreconf ./configure --with-ldap --with-prng-alg=os --enable-pkinit \ --with-crypto-impl=openssl --with-tls-impl=openssl \ diff --git a/test/recipes/95-test_external_krb5_data/patches/0001-Cons-return-value-from-X509_STORE_CTX_get_current_ce.patch b/test/recipes/95-test_external_krb5_data/patches/0001-Cons-return-value-from-X509_STORE_CTX_get_current_ce.patch deleted file mode 100644 index 8ea4257405..0000000000 --- a/test/recipes/95-test_external_krb5_data/patches/0001-Cons-return-value-from-X509_STORE_CTX_get_current_ce.patch +++ /dev/null @@ -1,57 +0,0 @@ -From db9d5b69c2987c4aaf0db612d76fb0931b990019 Mon Sep 17 00:00:00 2001 -From: Bob Beck -Date: Fri, 20 Feb 2026 17:38:19 -0700 -Subject: [PATCH] Cons return value from X509_STORE_CTX_get_current_cert - ---- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 4 ++-- - src/plugins/tls/k5tls/openssl.c | 4 ++-- - 2 files changed, 4 insertions(+), 4 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index d1fe18e5a..d5e3f0094 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -2156,7 +2156,7 @@ cms_signeddata_verify(krb5_context context, - i = X509_verify_cert(cert_ctx); - if (i <= 0) { - int j = X509_STORE_CTX_get_error(cert_ctx); -- X509 *cert; -+ const X509 *cert; - - cert = X509_STORE_CTX_get_current_cert(cert_ctx); - reqctx->received_cert = X509_dup(cert); -@@ -3355,7 +3355,7 @@ openssl_callback(int ok, X509_STORE_CTX * ctx) - { - #ifdef DEBUG - if (!ok) { -- X509 *cert = X509_STORE_CTX_get_current_cert(ctx); -+ const X509 *cert = X509_STORE_CTX_get_current_cert(ctx); - int err = X509_STORE_CTX_get_error(ctx); - const char *errmsg = X509_verify_cert_error_string(err); - char buf[DN_BUF_LEN]; -diff --git a/src/plugins/tls/k5tls/openssl.c b/src/plugins/tls/k5tls/openssl.c -index aab67c01c..2c7ce0317 100644 ---- a/src/plugins/tls/k5tls/openssl.c -+++ b/src/plugins/tls/k5tls/openssl.c -@@ -288,7 +288,7 @@ check_cert_name_or_ip(X509 *x, const char *expected_name) - static int - verify_callback(int preverify_ok, X509_STORE_CTX *store_ctx) - { -- X509 *x; -+ const X509 *x; - SSL *ssl; - BIO *bio; - krb5_context context; -@@ -330,7 +330,7 @@ verify_callback(int preverify_ok, X509_STORE_CTX *store_ctx) - return 1; - /* Check if the name we expect to find is in the certificate. */ - expected_name = handle->servername; -- if (check_cert_name_or_ip(x, expected_name)) { -+ if (check_cert_name_or_ip((X509 *)x, expected_name)) { - TRACE_TLS_SERVER_NAME_MATCH(context, expected_name); - return 1; - } else { --- -2.52.0 - diff --git a/test/recipes/95-test_external_krb5_data/patches/0001-Fix-X509_NAME-const-issues-in-krb.patch b/test/recipes/95-test_external_krb5_data/patches/0001-Fix-X509_NAME-const-issues-in-krb.patch deleted file mode 100644 index 91dd2016fe..0000000000 --- a/test/recipes/95-test_external_krb5_data/patches/0001-Fix-X509_NAME-const-issues-in-krb.patch +++ /dev/null @@ -1,146 +0,0 @@ -From 8ab536cf04d9a87a2e87b7bb775563ffb8cc14b2 Mon Sep 17 00:00:00 2001 -From: Bob Beck -Date: Fri, 20 Feb 2026 18:38:42 -0700 -Subject: [PATCH] Fix X509_NAME const issues in krb - ---- - .../preauth/pkinit/pkinit_crypto_openssl.c | 4 +-- - src/plugins/tls/k5tls/openssl.c | 27 +++++++++---------- - 2 files changed, 14 insertions(+), 17 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index 2f26197b1..0a4c510f4 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -4768,7 +4768,7 @@ out: - } - - static krb5_error_code --rfc2253_name(X509_NAME *name, char **str_out) -+rfc2253_name(const X509_NAME *name, char **str_out) - { - BIO *b = NULL; - char *str; -@@ -5237,7 +5237,7 @@ create_identifiers_from_stack(STACK_OF(X509) *sk, - int i = 0, sk_size = sk_X509_num(sk); - krb5_external_principal_identifier **krb5_cas = NULL; - X509 *x = NULL; -- X509_NAME *xn = NULL; -+ const X509_NAME *xn = NULL; - unsigned char *p = NULL; - int len = 0; - PKCS7_ISSUER_AND_SERIAL *is = NULL; -diff --git a/src/plugins/tls/k5tls/openssl.c b/src/plugins/tls/k5tls/openssl.c -index aab67c01c..f7db3a11b 100644 ---- a/src/plugins/tls/k5tls/openssl.c -+++ b/src/plugins/tls/k5tls/openssl.c -@@ -48,8 +48,7 @@ static int ex_handle_id = -1; - - MAKE_INIT_FUNCTION(init_openssl); - --int --init_openssl(void) -+int init_openssl(void) - { - SSL_library_init(); - SSL_load_error_strings(); -@@ -89,7 +88,7 @@ ascii_tolower(char p) - */ - static krb5_boolean - label_match(const char *presented, size_t plen, const char *expected, -- size_t elen, krb5_boolean allow_wildcard, krb5_boolean *wildcard) -+ size_t elen, krb5_boolean allow_wildcard, krb5_boolean *wildcard) - { - unsigned int i; - -@@ -158,7 +157,7 @@ get_cert_sans(X509 *x) - static int - get_cert_cn(X509 *x, char *buf, size_t bufsize) - { -- X509_NAME *name; -+ const X509_NAME *name; - - name = X509_get_subject_name(x); - if (name == NULL) -@@ -217,8 +216,7 @@ check_cert_address(X509 *x, const char *text) - name_length = get_cert_cn(x, buf, sizeof(buf)); - if (name_length >= 0) { - /* Do a string compare to check if it's an acceptable value. */ -- return strlen(text) == (size_t)name_length && -- strncmp(text, buf, name_length) == 0; -+ return strlen(text) == (size_t)name_length && strncmp(text, buf, name_length) == 0; - } - - /* We didn't find a match. */ -@@ -277,8 +275,7 @@ check_cert_name_or_ip(X509 *x, const char *expected_name) - struct in_addr in; - struct in6_addr in6; - -- if (inet_pton(AF_INET, expected_name, &in) != 0 || -- inet_pton(AF_INET6, expected_name, &in6) != 0) { -+ if (inet_pton(AF_INET, expected_name, &in) != 0 || inet_pton(AF_INET6, expected_name, &in6) != 0) { - return check_cert_address(x, expected_name); - } else { - return check_cert_servername(x, expected_name); -@@ -298,7 +295,7 @@ verify_callback(int preverify_ok, X509_STORE_CTX *store_ctx) - size_t count; - - ssl = X509_STORE_CTX_get_ex_data(store_ctx, -- SSL_get_ex_data_X509_STORE_CTX_idx()); -+ SSL_get_ex_data_X509_STORE_CTX_idx()); - context = SSL_get_ex_data(ssl, ex_context_id); - handle = SSL_get_ex_data(ssl, ex_handle_id); - assert(context != NULL && handle != NULL); -@@ -378,7 +375,7 @@ load_anchor_dir(X509_STORE *store, const char *path) - while ((dentry = readdir(d)) != NULL) { - if (dentry->d_name[0] != '.') { - snprintf(filename, sizeof(filename), "%s/%s", -- path, dentry->d_name); -+ path, dentry->d_name); - if (load_anchor_file(store, filename) == 0) - found_any = TRUE; - } -@@ -430,7 +427,7 @@ load_anchors(krb5_context context, char **anchors, SSL_CTX *sctx) - - static krb5_error_code - setup(krb5_context context, SOCKET fd, const char *servername, -- char **anchors, k5_tls_handle *handle_out) -+ char **anchors, k5_tls_handle *handle_out) - { - int e; - long options = SSL_OP_NO_SSLv2; -@@ -503,7 +500,7 @@ error: - - static k5_tls_status - write_tls(krb5_context context, k5_tls_handle handle, const void *data, -- size_t len) -+ size_t len) - { - int nwritten, e; - -@@ -526,7 +523,7 @@ write_tls(krb5_context context, k5_tls_handle handle, const void *data, - - static k5_tls_status - read_tls(krb5_context context, k5_tls_handle handle, void *data, -- size_t data_size, size_t *len_out) -+ size_t data_size, size_t *len_out) - { - ssize_t nread; - int e; -@@ -566,11 +563,11 @@ free_handle(krb5_context context, k5_tls_handle handle) - - krb5_error_code - tls_k5tls_initvt(krb5_context context, int maj_ver, int min_ver, -- krb5_plugin_vtable vtable); -+ krb5_plugin_vtable vtable); - - krb5_error_code - tls_k5tls_initvt(krb5_context context, int maj_ver, int min_ver, -- krb5_plugin_vtable vtable) -+ krb5_plugin_vtable vtable) - { - k5_tls_vtable vt; - --- -2.52.0 - diff --git a/test/recipes/95-test_external_krb5_data/patches/0001-Use-Accessors-for-ASN1_STRING-values-from-OpenSSL.patch b/test/recipes/95-test_external_krb5_data/patches/0001-Use-Accessors-for-ASN1_STRING-values-from-OpenSSL.patch deleted file mode 100644 index c571f0ea3a..0000000000 --- a/test/recipes/95-test_external_krb5_data/patches/0001-Use-Accessors-for-ASN1_STRING-values-from-OpenSSL.patch +++ /dev/null @@ -1,69 +0,0 @@ -From 77e11f75423e971e1af9e5f8cc971a606adcb01e Mon Sep 17 00:00:00 2001 -From: Bob Beck -Date: Mon, 2 Feb 2026 09:50:36 -0700 -Subject: [PATCH] Use Accessors for ASN1_STRING values from OpenSSL. - -OpenSSL is making ASN1_STRING opaque, These accessors -have been around for a very long time. and should be -used instead of directly manipulating the fields int the -structure. - -https://github.com/openssl/openssl/issues/29117 ---- - .../preauth/pkinit/pkinit_crypto_openssl.c | 16 +++++++++------- - 1 file changed, 9 insertions(+), 7 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index d1fe18e5a..14e060de8 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -2002,7 +2002,7 @@ cms_signeddata_verify(krb5_context context, - unsigned char *d; - *is_signed = 0; - octets = CMS_get0_content(cms); -- if (!octets || ((*octets)->type != V_ASN1_OCTET_STRING)) { -+ if (!octets || (ASN1_STRING_type(*octets) != V_ASN1_OCTET_STRING)) { - retval = KRB5KDC_ERR_PREAUTH_FAILED; - krb5_set_error_message(context, retval, - _("Invalid pkinit packet: octet string " -@@ -2058,7 +2058,8 @@ cms_signeddata_verify(krb5_context context, - /* We cannot use CMS_dataInit because there may be no digest */ - octets = CMS_get0_content(cms); - if (octets) -- out = BIO_new_mem_buf((*octets)->data, (*octets)->length); -+ out = BIO_new_mem_buf(ASN1_STRING_get0_data(*octets), -+ ASN1_STRING_length(*octets)); - if (out == NULL) - goto cleanup; - } else { -@@ -2379,8 +2380,8 @@ crypto_retrieve_X509_sans(krb5_context context, - gen = sk_GENERAL_NAME_value(ialt, i); - switch (gen->type) { - case GEN_OTHERNAME: -- name.length = gen->d.otherName->value->value.sequence->length; -- name.data = (char *)gen->d.otherName->value->value.sequence->data; -+ name.length = ASN1_STRING_length(gen->d.otherName->value->value.sequence); -+ name.data = (char *)ASN1_STRING_get0_data(gen->d.otherName->value->value.sequence); - if (princs != NULL && - OBJ_cmp(plgctx->id_pkinit_san, - gen->d.otherName->type_id) == 0) { -@@ -2414,12 +2415,13 @@ crypto_retrieve_X509_sans(krb5_context context, - case GEN_DNS: - if (dnss != NULL) { - /* Prevent abuse of embedded null characters. */ -- if (memchr(gen->d.dNSName->data, '\0', gen->d.dNSName->length)) -+ if (memchr(ASN1_STRING_get0_data(gen->d.dNSName), '\0', -+ ASN1_STRING_length(gen->d.dNSName))) - break; - pkiDebug("%s: found dns name = %s\n", __FUNCTION__, -- gen->d.dNSName->data); -+ ASN1_STRING_get0_data(gen->d.dNSName)); - dnss[d] = (unsigned char *) -- strdup((char *)gen->d.dNSName->data); -+ strdup((char *)ASN1_STRING_get0_data(gen->d.dNSName)); - if (dnss[d] == NULL) { - pkiDebug("%s: failed to duplicate dns name\n", - __FUNCTION__); --- -2.52.0 - diff --git a/test/recipes/95-test_external_krb5_data/patches/0001-constify-X509_EXTENSION-return-values.patch b/test/recipes/95-test_external_krb5_data/patches/0001-constify-X509_EXTENSION-return-values.patch deleted file mode 100644 index 46cc217191..0000000000 --- a/test/recipes/95-test_external_krb5_data/patches/0001-constify-X509_EXTENSION-return-values.patch +++ /dev/null @@ -1,39 +0,0 @@ -From d7699a98e33376bccf3221bfd46c9e3519e1fdd2 Mon Sep 17 00:00:00 2001 -From: Bob Beck -Date: Mon, 22 Dec 2025 15:34:19 -0700 -Subject: [PATCH] constify X509_EXTENSION return values - ---- - src/plugins/preauth/pkinit/pkinit_crypto_openssl.c | 2 +- - src/plugins/tls/k5tls/openssl.c | 2 +- - 2 files changed, 2 insertions(+), 2 deletions(-) - -diff --git a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -index d1fe18e5a..27dfca6e1 100644 ---- a/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -+++ b/src/plugins/preauth/pkinit/pkinit_crypto_openssl.c -@@ -2316,7 +2316,7 @@ crypto_retrieve_X509_sans(krb5_context context, - char **upns = NULL; - unsigned char **dnss = NULL; - unsigned int i, num_sans = 0; -- X509_EXTENSION *ext = NULL; -+ const X509_EXTENSION *ext = NULL; - GENERAL_NAMES *ialt = NULL; - GENERAL_NAME *gen = NULL; - -diff --git a/src/plugins/tls/k5tls/openssl.c b/src/plugins/tls/k5tls/openssl.c -index aab67c01c..c3a253009 100644 ---- a/src/plugins/tls/k5tls/openssl.c -+++ b/src/plugins/tls/k5tls/openssl.c -@@ -142,7 +142,7 @@ static GENERAL_NAMES * - get_cert_sans(X509 *x) - { - int ext; -- X509_EXTENSION *san_ext; -+ const X509_EXTENSION *san_ext; - - ext = X509_get_ext_by_NID(x, NID_subject_alt_name, -1); - if (ext < 0) --- -2.52.0 - diff --git a/test/recipes/95-test_external_oqsprovider.t b/test/recipes/95-test_external_oqsprovider.t index a5447e1820..139fc811be 100644 --- a/test/recipes/95-test_external_oqsprovider.t +++ b/test/recipes/95-test_external_oqsprovider.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2022 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -20,8 +20,6 @@ plan skip_all => "oqsprovider tests not available on Windows or VMS" plan skip_all => "oqsprovider tests only available in a shared build" if disabled("shared"); -plan skip_all => "oqsprovider HEAD is currently broken - skipping test"; - plan tests => 1; $ENV{SHLIB_VERSION_NUMBER} = config('shlib_version'); diff --git a/test/recipes/95-test_external_pkcs11_provider_data/patches/0002-Temporarily-disable-the-pem-encoder.patch b/test/recipes/95-test_external_pkcs11_provider_data/patches/0002-Temporarily-disable-the-pem-encoder.patch deleted file mode 100644 index 2498938a69..0000000000 --- a/test/recipes/95-test_external_pkcs11_provider_data/patches/0002-Temporarily-disable-the-pem-encoder.patch +++ /dev/null @@ -1,27 +0,0 @@ -From 891c0d9a615ce37506969875792afdb6defe9b79 Mon Sep 17 00:00:00 2001 -From: Bob Beck -Date: Wed, 10 Jun 2026 16:40:37 -0600 -Subject: [PATCH] Temporarily disable the pem encoder - -This appears to have some sort of internal error fetching ec keys -from the softhsm. (and appears to also be disabled for -similar reasons on some linux distros) ---- - tests/meson.build | 1 - - 1 file changed, 1 deletion(-) - -diff --git a/tests/meson.build b/tests/meson.build -index 6050fe5..24520d1 100644 ---- a/tests/meson.build -+++ b/tests/meson.build -@@ -155,7 +155,6 @@ tests = { - 'oaepsha2': {'suites': ['softokn', 'kryoptic', 'kryoptic.nss']}, - 'hkdf': {'suites': ['softokn', 'kryoptic', 'kryoptic.nss']}, - 'imported' : {'suites': ['softokn', 'kryoptic', 'kryoptic.nss']}, -- 'pem_encoder': {'suites': all_suites}, - 'rsa': {'suites': all_suites}, - 'rsapss': {'suites': all_suites}, - 'rsapssam': {'suites': ['softhsm', 'kryoptic']}, --- -2.53.0 - diff --git a/test/recipes/95-test_external_pkcs11_provider_data/pkcs11-provider.sh b/test/recipes/95-test_external_pkcs11_provider_data/pkcs11-provider.sh index f75f1260a0..a45984cee1 100755 --- a/test/recipes/95-test_external_pkcs11_provider_data/pkcs11-provider.sh +++ b/test/recipes/95-test_external_pkcs11_provider_data/pkcs11-provider.sh @@ -1,6 +1,6 @@ #!/bin/sh # -# Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2024-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -11,19 +11,9 @@ # OpenSSL external testing using the pkcs11-provider # -unpatch() { - cd "$SRC_ABS_TOP/pkcs11-provider" && git reset --hard "$GITLEVEL" -} - -trap unpatch EXIT - - PWD="$(pwd)" SRCTOP="$(cd $SRCTOP; pwd)" -SRC_ABS_TOP="$PWD/../.." -DATA_ABS_TOP="$SRC_ABS_TOP/test/recipes/95-test_external_pkcs11_provider_data" -echo "$DATA_ABS_TOP" BLDTOP="$(cd $BLDTOP; pwd)" if [ "$SRCTOP" != "$BLDTOP" ] ; then @@ -31,17 +21,6 @@ if [ "$SRCTOP" != "$BLDTOP" ] ; then exit 1 fi -GITLEVEL=$(git rev-parse HEAD) -cd "$SRC_ABS_TOP/pkcs11-provider" -# "git am" refuses to run without a user configured. -for FILE in "$DATA_ABS_TOP"/patches/*; do - if [ -f "$FILE" ]; then - git -c 'user.name=OpenSSL External Tests' -c 'user.email=nonsuch@openssl.org' am $FILE - fi -done - -cd $BLDTOP - O_EXE="$BLDTOP/apps" O_BINC="$BLDTOP/include" O_SINC="$SRCTOP/include" @@ -85,10 +64,13 @@ echo "Running tests" echo "------------------------------------------------------------------" # For maintenance reasons and simplicity we only run test with kryoptic token -meson test -C $PKCS11_PROVIDER_BUILDDIR --print-errorlogs --suite=kryoptic +SUPPORT_ML_DSA=0 meson test -C $PKCS11_PROVIDER_BUILDDIR --suite=kryoptic -RESULT=$? +if [ $? -ne 0 ]; then + cat $PKCS11_PROVIDER_BUILDDIR/meson-logs/testlog.txt + exit 1 +fi rm -rf $PKCS11_PROVIDER_BUILDDIR -exit $RESULT +exit 0 diff --git a/test/recipes/95-test_external_rpki-client-portable.t b/test/recipes/95-test_external_rpki-client-portable.t index ed72e0296b..dc49587940 100644 --- a/test/recipes/95-test_external_rpki-client-portable.t +++ b/test/recipes/95-test_external_rpki-client-portable.t @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -19,7 +19,7 @@ plan skip_all => "No external tests in this configuration" plan tests => 1; -$RPKI_VERSION = "9.7"; +$RPKI_VERSION = "9.6"; $RPKI_SRC = "rpki-client-".$RPKI_VERSION; $RPKI_SUFFIX = ".tar.gz"; $RPKI_TARBALL = $RPKI_SRC.$RPKI_SUFFIX; diff --git a/test/recipes/95-test_external_rpki-client-portable_data/rpki-client-portable.sh b/test/recipes/95-test_external_rpki-client-portable_data/rpki-client-portable.sh index ec2fa8e285..c483eb5feb 100755 --- a/test/recipes/95-test_external_rpki-client-portable_data/rpki-client-portable.sh +++ b/test/recipes/95-test_external_rpki-client-portable_data/rpki-client-portable.sh @@ -1,6 +1,6 @@ #!/bin/sh -ex # -# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -64,52 +64,10 @@ zyzSqbo//+SSFHZG EOF gpg --verify $RPKI_TARBALL.asc $RPKI_TARBALL || exit 1 -cd $RPKI_SRC/src +cd $RPKI_SRC -cat <flags & ASN1_STRING_FLAG_BITS_LEFT)) - unused = abs->flags & 0x07; -- -+#else -+ if (!ASN1_BIT_STRING_get_length(abs, &length, &unused)) -+ return 0; -+#endif - if (length == 0 && unused != 0) { - warnx("%s: RFC 3779 section 2.2.3.8: " - "unused bit count must be zero if length is zero", fn); ---- ccr.c.orig 2026-02-22 09:51:29.076899178 -0700 -+++ ccr.c 2026-02-22 09:55:27.678095938 -0700 -@@ -398,8 +398,10 @@ - if (!ASN1_BIT_STRING_set(ripa->address, vrp->addr.addr, num_bytes)) - errx(1, "ASN1_BIT_STRING_set"); - -+#if defined(ASN1_STRING_FLAGS_BITS_LEFT) - /* ip_addr_parse() handles unused bits, no need to clear them here. */ - ripa->address->flags |= ASN1_STRING_FLAG_BITS_LEFT | unused_bits; -+#endif - - /* XXX - assert that unused bits are zero */ - -EOF -cd .. ./configure --with-openssl-cflags="$CFLAGS" --with-openssl-ldflags="$LDFLAGS" \ - CFLAGS="$CFLAGS -w" LDFLAGS="$LDFLAGS" + CFLAGS="$CFLAGS" LDFLAGS="$LDFLAGS" # quiet make so that Travis doesn't overflow make diff --git a/test/recipes/95-test_external_tlsfuzzer_data/cert.json.in b/test/recipes/95-test_external_tlsfuzzer_data/cert.json.in index e22ffd2641..a14e10e8f2 100644 --- a/test/recipes/95-test_external_tlsfuzzer_data/cert.json.in +++ b/test/recipes/95-test_external_tlsfuzzer_data/cert.json.in @@ -12,12 +12,12 @@ {"name" : "test-tls13-certificate-verify.py", "arguments" : ["-k", "tests/clientX509Key.pem", "-c", "tests/clientX509Cert.pem", - "-s", "9+5 9+6 9+4 ecdsa_secp256r1_sha256 ecdsa_secp384r1_sha384 ecdsa_secp521r1_sha512 ed25519 ed448 8+26 8+27 8+28 rsa_pss_pss_sha256 rsa_pss_pss_sha384 rsa_pss_pss_sha512 rsa_pss_rsae_sha256 rsa_pss_rsae_sha384 rsa_pss_rsae_sha512 rsa_pkcs1_sha256 rsa_pkcs1_sha384 rsa_pkcs1_sha512 9+17 9+18 9+19 9+20 9+21 9+22 9+23 9+24 9+25 9+26 9+27 9+28 7+8", + "-s", "9+5 9+6 9+4 ecdsa_secp256r1_sha256 ecdsa_secp384r1_sha384 ecdsa_secp521r1_sha512 ed25519 ed448 8+26 8+27 8+28 rsa_pss_pss_sha256 rsa_pss_pss_sha384 rsa_pss_pss_sha512 rsa_pss_rsae_sha256 rsa_pss_rsae_sha384 rsa_pss_rsae_sha512 rsa_pkcs1_sha256 rsa_pkcs1_sha384 rsa_pkcs1_sha512", "-p", "@PORT@"]}, {"name" : "test-tls13-ecdsa-in-certificate-verify.py", "arguments" : ["-k", "tests/serverECKey.pem", "-c", "tests/serverECCert.pem", - "-s", "9+5 9+6 9+4 ecdsa_secp256r1_sha256 ecdsa_secp384r1_sha384 ecdsa_secp521r1_sha512 ed25519 ed448 8+26 8+27 8+28 rsa_pss_pss_sha256 rsa_pss_pss_sha384 rsa_pss_pss_sha512 rsa_pss_rsae_sha256 rsa_pss_rsae_sha384 rsa_pss_rsae_sha512 rsa_pkcs1_sha256 rsa_pkcs1_sha384 rsa_pkcs1_sha512 9+17 9+18 9+19 9+20 9+21 9+22 9+23 9+24 9+25 9+26 9+27 9+28 7+8", + "-s", "9+5 9+6 9+4 ecdsa_secp256r1_sha256 ecdsa_secp384r1_sha384 ecdsa_secp521r1_sha512 ed25519 ed448 8+26 8+27 8+28 rsa_pss_pss_sha256 rsa_pss_pss_sha384 rsa_pss_pss_sha512 rsa_pss_rsae_sha256 rsa_pss_rsae_sha384 rsa_pss_rsae_sha512 rsa_pkcs1_sha256 rsa_pkcs1_sha384 rsa_pkcs1_sha512", "-p", "@PORT@"]} ] }, diff --git a/test/recipes/99-test_fuzz_echconfiglist_parser.t b/test/recipes/99-test_fuzz_echconfiglist_parser.t deleted file mode 100644 index 09e115caa6..0000000000 --- a/test/recipes/99-test_fuzz_echconfiglist_parser.t +++ /dev/null @@ -1,25 +0,0 @@ -#!/usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use warnings; - -use OpenSSL::Test qw/:DEFAULT srctop_file/; -use OpenSSL::Test::Utils; - -my $fuzzer = "echconfiglist_parser"; -setup("test_fuzz_${fuzzer}"); - -plan skip_all => "This test requires ech support" - if disabled("ech"); - -plan tests => 2; # one more due to below require_ok(...) - -require_ok(srctop_file('test','recipes','fuzz.pl')); - -fuzz_ok($fuzzer); diff --git a/test/recipes/99-test_fuzz_pkcs12.t b/test/recipes/99-test_fuzz_pkcs12.t deleted file mode 100644 index c1c6bf2620..0000000000 --- a/test/recipes/99-test_fuzz_pkcs12.t +++ /dev/null @@ -1,22 +0,0 @@ -#!/usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use warnings; - -use OpenSSL::Test qw/:DEFAULT srctop_file/; -use OpenSSL::Test::Utils; - -my $fuzzer = "pkcs12"; -setup("test_fuzz_${fuzzer}"); - -plan tests => 2; # one more due to below require_ok (...) - -require_ok(srctop_file('test','recipes','fuzz.pl')); - -fuzz_ok($fuzzer); diff --git a/test/recipes/fuzz.pl b/test/recipes/fuzz.pl index e5182a362c..3f03eef4f7 100644 --- a/test/recipes/fuzz.pl +++ b/test/recipes/fuzz.pl @@ -1,4 +1,4 @@ -# Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016-2020 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -8,295 +8,18 @@ use strict; use warnings; -use Cwd qw/abs_path/; - use OpenSSL::Glob; -use OpenSSL::Test qw/:DEFAULT srctop_dir bldtop_file result_file/; - -# print logs -sub fuzz_dump_log { - my ($log) = @_; - return unless $ENV{HARNESS_VERBOSE} && open(my $fh, '<', $log); - print STDERR <$fh>; - close $fh; -} - -# execute test and print backtrace -sub fuzz_print_backtrace { - my ($f, $path, $point) = @_; - my $bt_log = result_file("$f-backtrace.stderr.log"); - local $ENV{OPENSSL_TEST_MFAIL_BACKTRACE} = 1; - local $ENV{OPENSSL_TEST_MFAIL_POINT} = $point if defined $point; - run(fuzz(["$f-test", $path], stderr => $bt_log)); - - diag("- backtrace at injection point:"); - if (open(my $fh, '<', $bt_log)) { - while (my $line = <$fh>) { - chomp $line; - diag(" $line"); - } - close $fh; - } -} - -# check fuzz test logs -sub fuzz_check_log { - my ($f, $log, $exit_ok, $silent_leak) = @_; - - my $has_leaks = 0; - my $corpus_time = 0; - my @tail; - my ($last_path, $last_point); - - # collect info from the executed fuzz log - if (open(my $fh, '<', $log)) { - while (my $line = <$fh>) { - chomp $line; - if ($line =~ /^#\s/) { - $corpus_time = $1 - if $line =~ /^#\s*corpus_time:\s*([\d.]+)/; - $last_path = $1 if $line =~ /\bpath=(.+?)\s*$/; - $last_point = $1 if $line =~ /\bpoint=(\d+)\//; - @tail = ($line); - } else { - push @tail, $line; - $has_leaks = 1 - if $line =~ /^(?:Direct|Indirect) leak of \d+ byte/; - } - } - close $fh; - } - - # return if the test passed and there is no leak - return (1, 0, $corpus_time) if $exit_ok && !$has_leaks; - # return if there is a leak but it's silent (should not be reported) - return (0, $has_leaks, $corpus_time) if $has_leaks && $silent_leak; - - # log leak info - my $why = !$exit_ok ? "non-zero exit" : "leaks (clean exit)"; - diag("fuzz $f failed: $why"); - diag("- full stderr: $log"); - if (defined $last_path) { - my $bin = abs_path(bldtop_file('fuzz', "$f-test")); - my $path = abs_path($last_path); - my $env = defined $last_point - ? "OPENSSL_TEST_MFAIL_POINT=$last_point " : ""; - diag("- reproduce: $env$bin $path"); - } - diag($_) for @tail; - fuzz_print_backtrace($f, $last_path, $last_point) - if defined $last_path && !$has_leaks; - return (0, $has_leaks, $corpus_time); -} - -# run fuzz test and dump logs -sub fuzz_run { - my ($f, $d, $log_name, $silent_leak) = @_; - my $log = result_file($log_name); - my $exit_ok = run(fuzz(["$f-test", $d], stderr => $log)); - fuzz_dump_log($log); - my ($passed, $leaks, $corpus_time) = fuzz_check_log($f, $log, $exit_ok, - $silent_leak); - return ($passed, $leaks, $corpus_time, $log); -} - -# run fuzz test in counting mode and no fail run -sub fuzz_run_count_only { - my ($f, $d) = @_; - my $log = result_file("$f-count.stderr.log"); - local $ENV{OPENSSL_TEST_MFAIL_COUNT_ONLY} = 1; - my $exit_ok = run(fuzz(["$f-test", $d], stderr => $log)); - fuzz_dump_log($log); - - my ($corpus_time, $cur, @allocs) = (0, undef); - if (open(my $fh, '<', $log)) { - while (my $line = <$fh>) { - $corpus_time = $1 if $line =~ /^#\s*corpus_time:\s*([\d.]+)/; - $cur = $1 if $line =~ /^#\s*CORPUS_FILE\s+file_idx=(\d+)/; - push @allocs, $1 + 0 if defined $cur - && $line =~ /:\s*(\d+)\s+allocations\s*$/; - } - close $fh; - } - return ($exit_ok, $corpus_time, \@allocs); -} - -# find path and point of the reported leak for easy recreation -sub fuzz_mfail_bisect { - my ($f, $log) = @_; - - # collect all paths and executed points from the output - my (%path, %points); - if (open(my $fh, '<', $log)) { - while (my $line = <$fh>) { - $path{$1} = $2 - if $line =~ - /CORPUS_FILE\s+file_idx=(\d+)\s+size=\d+\s+path=(\S+)/; - push @{$points{$1}}, $2 - if $line =~ /MFAIL_BEGIN\s+file_idx=(\d+)\s+point=(\d+)\/\d+/; - } - close $fh; - } - - # reset current envs so they don't get used in bisect run - delete local $ENV{OPENSSL_TEST_MFAIL_COUNT}; - delete local $ENV{OPENSSL_TEST_MFAIL_START}; - delete local $ENV{OPENSSL_TEST_MFAIL_POINT}; - - diag("bisecting mfail leak across isolated point reruns"); - - # go through all executed corpus files - for my $idx (sort { $a <=> $b } keys %path) { - # go trhout all executed points in path - for my $p (@{$points{$idx} || []}) { - local $ENV{OPENSSL_TEST_MFAIL_POINT} = $p; - my $plog = result_file("$f-bisect-$idx-$p.stderr.log"); - my $exit_ok = run(fuzz(["$f-test", $path{$idx}], stderr => $plog), - quiet => 1); - # silently skip runs without a leak - my (undef, $leaks) = fuzz_check_log($f, $plog, $exit_ok, 1); - next unless $leaks; - # report exact leak location - my $bin = abs_path(bldtop_file('fuzz', "$f-test")); - my $abs = abs_path($path{$idx}); - diag("isolated leak: file_idx=$idx point=$p path=$path{$idx}"); - diag("- log: $plog"); - diag("- reproduce: OPENSSL_TEST_MFAIL_POINT=$p $bin $abs"); - fuzz_print_backtrace($f, $path{$idx}, $p); - return; - } - } - diag("bisection did not reproduce the leak"); -} - -# get all test_fuzz tests calling this -sub fuzz_test_names { - my @names; - for my $p (glob(srctop_dir('test', 'recipes') . '/[0-9][0-9]-test_fuzz_*.t')) { - # push the actual name of the test used in TESTS filtering - push @names, $1 if $p =~ m{/\d+-(test_fuzz_\S+)\.t$}; - } - return @names; -} - -# match a test name against TESTS env filter (test/run_tests.pl semantics) -sub fuzz_match_tests_filter { - my ($name, $filter) = @_; - return 1 unless defined $filter && $filter ne ''; - - my @pats = grep { length } split /\s+/, $filter; - return 1 unless @pats; - - # a leading negative implies a starting "alltests" - my $included = $pats[0] =~ /^-/ ? 1 : 0; - - for my $pat (@pats) { - # alltests resets the set to all, ignoring everything before - if ($pat eq 'alltests') { - $included = 1; - next; - } - - my $neg = $pat =~ s/^-//; - - # glob -> regex - (my $re = quotemeta $pat) =~ s/\\\*/.*/g; - $re =~ s/\\\?/./g; - next unless $name =~ /\A$re\z/; - - $included = $neg ? 0 : 1; - } - - return $included; -} - -# get budget per test -sub fuzz_per_test_budget { - my $budget = $ENV{OSSL_FUZZ_TEST_BUDGET} or return 0; - my $jobs = $ENV{OSSL_FUZZ_TEST_JOBS} || 1; - my $filter = $ENV{TESTS}; - - my @active = grep { fuzz_match_tests_filter($_, $filter) } fuzz_test_names(); - my $count = scalar(@active) || 1; - - # we don't need all jobs if there are less tests - $jobs = $count if $jobs > $count; - - my $per_test = $budget * $jobs / $count; - diag(sprintf("budget=%ss jobs=%d active=%d -> per-test=%.3fs", - $budget, $jobs, $count, $per_test)); - return $per_test; -} +use OpenSSL::Test qw/:DEFAULT srctop_dir/; sub fuzz_ok { - my ($f, %opts) = @_; + die "Only one argument accepted" if scalar @_ != 1; + + my $f = $_[0]; my $d = srctop_dir('fuzz', 'corpora', $f); SKIP: { skip "No directory $d", 1 unless -d $d; - - my $per_test = fuzz_per_test_budget(); - my $safety = 0.8; - my $target = $per_test * $safety; - - # no budget configured, just run the corpus - unless ($per_test > 0) { - ok(run(fuzz(["$f-test", $d])), "Fuzzing $f"); - return; - } - - # baseline run to measure the corpus run time - my ($ok, $corpus_time, $allocs) = fuzz_run_count_only($f, $d); - unless ($ok) { - ok(0, "Fuzzing $f (count-only)"); - return; - } - - # get the maximum allocations in instance and count total - my $total_allocs = 0; - my $max_k = 0; - for (@$allocs) { - $total_allocs += $_; - $max_k = $_ if $_ > $max_k; - } - my $num_files = scalar @$allocs; - diag(sprintf("%s: count-only %.3fs, allocs=%d, files=%d, max=%d", - $f, $corpus_time, $total_allocs, $num_files, $max_k)); - - # baseline alone consumed the budget, nothing left for mfail - if ($corpus_time <= 0 || $corpus_time >= $target) { - ok(1, "Fuzzing $f (no mfail budget; " - . "corpus=${corpus_time}s, target=${target}s)"); - return; - } - - # no allocations counted, can't size the mfail run - if ($total_allocs <= 0 || $num_files <= 0) { - ok(1, "Fuzzing $f (no allocations counted)"); - return; - } - - # number of mfail iterations that fit alongside the baseline: - # ~corpus_time * (1 + count / 2) <= target - my $count = int(2 * ($target - $corpus_time) / $corpus_time); - # never exceed max(K_i); injections beyond that are wasted - $count = $max_k if $count > $max_k; - if ($count <= 0) { - ok(1, "Fuzzing $f (budget too small for mfail)"); - return; - } - diag("$f: running mfail with count=$count"); - - local $ENV{OPENSSL_TEST_MFAIL_COUNT} = $count; - my $main_log = "$f-mfail.stderr.log"; - my ($passed, $leaks, undef, $log) = fuzz_run($f, $d, $main_log, 1); - - unless ($passed) { - fuzz_mfail_bisect($f, $log) if $leaks; - ok(0, "Fuzzing $f (mfail count=$count, per-test=${per_test}s)"); - return; - } - ok(1, "Fuzzing $f (mfail count=$count, per-test=${per_test}s)"); + ok(run(fuzz(["$f-test", $d])), "Fuzzing $f"); } } diff --git a/test/rio_notifier_test.c b/test/rio_notifier_test.c deleted file mode 100644 index 984ee51b9b..0000000000 --- a/test/rio_notifier_test.c +++ /dev/null @@ -1,37 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include "internal/rio_notifier.h" -#include "testutil.h" - -static int test_rio_notifier_smoke(void) -{ - RIO_NOTIFIER nfy = { -1, -1 }; - int ret = 0; - - if (!TEST_true(ossl_rio_notifier_init(&nfy))) - goto err; - - if (!TEST_int_ne(ossl_rio_notifier_as_fd(&nfy), (int)INVALID_SOCKET) - || !TEST_true(ossl_rio_notifier_signal(&nfy)) - || !TEST_true(ossl_rio_notifier_unsignal(&nfy))) - goto err; - - ret = 1; - -err: - ossl_rio_notifier_cleanup(&nfy); - return ret; -} - -int setup_tests(void) -{ - ADD_TEST(test_rio_notifier_smoke); - return 1; -} diff --git a/test/rpktest.c b/test/rpktest.c index 98be18b3a6..338c33f80c 100644 --- a/test/rpktest.c +++ b/test/rpktest.c @@ -152,7 +152,7 @@ static int test_rpk(int idx) privkey_file = privkey; other_cert_file = cert2; break; -#ifndef OPENSSL_NO_EC +#ifndef OPENSSL_NO_ECDSA case 1: /* use ECDSA */ cert_file = cert2; @@ -188,7 +188,7 @@ static int test_rpk(int idx) if (!TEST_ptr(other_x509)) goto end; other_pkey = X509_get0_pubkey(other_x509); -#ifdef OPENSSL_NO_EC +#ifdef OPENSSL_NO_ECDSA /* Can't get other_key if it's ECDSA */ if (other_pkey == NULL && idx_cert == 0 && (idx == 4 || idx == 6 || idx == 7 || idx == 16)) { diff --git a/test/rsa_test.c b/test/rsa_test.c index de2966b2a2..190d49d69a 100644 --- a/test/rsa_test.c +++ b/test/rsa_test.c @@ -302,70 +302,6 @@ err: return ret; } -static int test_rsa_pkcs1_mfail(int idx) -{ - RSA *key = NULL; - unsigned char ctext[256]; - unsigned char ptext[256]; - static unsigned char ptext_ex[] = "\x54\x85\x9b\x34\x2c\x49\xea\x2a"; - int plen = sizeof(ptext_ex) - 1; - int clen, enclen, declen = 0; - int ret = 0; - - /* key construction is setup; only the round trip is under injection */ - clen = rsa_setkey(&key, NULL, idx); - if (!TEST_ptr(key)) - goto err; - - MFAIL_start(); - enclen = RSA_public_encrypt(plen, ptext_ex, ctext, key, RSA_PKCS1_PADDING); - if (enclen == clen) - declen = RSA_private_decrypt(enclen, ctext, ptext, key, - RSA_PKCS1_PADDING); - MFAIL_end(); - - if (enclen != clen || declen <= 0) - goto err; - - ret = TEST_mem_eq(ptext, declen, ptext_ex, plen); - -err: - RSA_free(key); - return ret; -} - -static int test_rsa_oaep_mfail(int idx) -{ - RSA *key = NULL; - unsigned char ctext[256]; - unsigned char ptext[256]; - static unsigned char ptext_ex[] = "\x54\x85\x9b\x34\x2c\x49\xea\x2a"; - int plen = sizeof(ptext_ex) - 1; - int clen, enclen, declen = 0; - int ret = 0; - - clen = rsa_setkey(&key, NULL, idx); - if (!TEST_ptr(key)) - goto err; - - MFAIL_start(); - enclen = RSA_public_encrypt(plen, ptext_ex, ctext, key, - RSA_PKCS1_OAEP_PADDING); - if (enclen == clen) - declen = RSA_private_decrypt(enclen, ctext, ptext, key, - RSA_PKCS1_OAEP_PADDING); - MFAIL_end(); - - if (enclen != clen || declen <= 0) - goto err; - - ret = TEST_mem_eq(ptext, declen, ptext_ex, plen); - -err: - RSA_free(key); - return ret; -} - static const struct { int bits; unsigned int r; @@ -757,8 +693,6 @@ int setup_tests(void) { ADD_ALL_TESTS(test_rsa_pkcs1, 3); ADD_ALL_TESTS(test_rsa_oaep, 3); - ADD_MFAIL_ALL_TESTS(test_rsa_pkcs1_mfail, 3); - ADD_MFAIL_ALL_TESTS(test_rsa_oaep_mfail, 3); ADD_ALL_TESTS(test_rsa_security_bit, OSSL_NELEM(rsa_security_bits_cases)); ADD_TEST(test_rsa_saos); ADD_TEST(test_EVP_rsa_legacy_key); diff --git a/test/run_tests.pl b/test/run_tests.pl index f31c181a3d..38d38bdb5c 100644 --- a/test/run_tests.pl +++ b/test/run_tests.pl @@ -26,7 +26,6 @@ use File::Basename; use FindBin; use lib "$FindBin::Bin/../util/perl"; use OpenSSL::Glob; -use Scalar::Util qw(looks_like_number); my $srctop = $ENV{SRCTOP} || $ENV{TOP}; my $bldtop = $ENV{BLDTOP} || $ENV{TOP}; @@ -47,7 +46,7 @@ if (!defined($jobs)) { } if (!defined($cpus) && -r "/proc/cpuinfo") { # Smells like Linux or something else attempting bug for bug - # compatibility with the /proc paradigm. + # compatibilty with the /proc paradigm. my $tmp = qx(grep -c ^processor /proc/cpuinfo 2>/dev/null); if ($? == 0 && $tmp > 0) { $cpus = $tmp; @@ -78,24 +77,12 @@ $ENV{CTLOG_FILE} = rel2abs(catfile($srctop, "test", "ct", "log_list.cnf")); # some situations. $ENV{'MALLOC_PERTURB_'} = '128' if !defined $ENV{'MALLOC_PERTURB_'}; -my $tap_verbosity = exists $ENV{'HARNESS_VERBOSE'} ? $ENV{'HARNESS_VERBOSE'} : 0; -# If $tap_verbosity looks like a number, keep its value. Otherwise, enforce a -# numeric value for its truthiness. -$tap_verbosity = - looks_like_number($tap_verbosity) - ? $tap_verbosity - : ($tap_verbosity ? 1 : 0); -# Show test times by default, unless we have lowered verbosity (HARNESS_VERBOSE value < 0). -my $tap_timer = ($tap_verbosity >= 0) ? 1 : 0; -# But also ensure HARNESS_TIMER is respected if it is set. -$tap_timer = exists $ENV{'HARNESS_TIMER'} ? $ENV{'HARNESS_TIMER'} : $tap_timer; - my %tapargs = - ( verbosity => $tap_verbosity, + ( verbosity => $ENV{HARNESS_VERBOSE} ? 1 : 0, lib => [ $libdir ], switches => '-w', merge => 1, - timer => $tap_timer, + timer => $ENV{HARNESS_TIMER} ? 1 : 0, ); if ($jobs > 1) { @@ -128,7 +115,6 @@ open $openssl_args{'tap_copy'}, ">$outfilename" my @alltests = find_matching_tests("*"); my %tests = (); -my $has_nonexistent_test = 0; sub reorder { my $key = pop; @@ -153,7 +139,6 @@ foreach my $arg (@ARGV ? @ARGV : ('alltests')) { warn "'alltests' encountered, ignoring everything before that...\n" unless $initial_arg; %tests = map { $_ => 1 } @alltests; - $has_nonexistent_test = 0; } elsif ($arg =~ m/^(-?)(.*)/) { my $sign = $1; my $test = $2; @@ -164,12 +149,10 @@ foreach my $arg (@ARGV ? @ARGV : ('alltests')) { %tests = map { $_ => 1 } @alltests; } - # Flag non-existent test so we can return an error if (scalar @matches == 0) { warn "Test $test found no match, skipping ", ($sign eq '-' ? "removal" : "addition"), "...\n"; - $has_nonexistent_test = 1 unless $sign eq '-'; } else { foreach $test (@matches) { if ($sign eq '-') { @@ -395,10 +378,9 @@ if (ref($ret) ne "TAP::Parser::Aggregator" || !$ret->has_errors) { # If this is a TAP::Parser::Aggregator, $ret->has_errors is the count of # tests that failed. We don't bother with that exact number, just exit -# with an appropriate exit code when it isn't zero. We also return an error -# if attempting to run a non-existent test. +# with an appropriate exit code when it isn't zero. if (ref($ret) eq "TAP::Parser::Aggregator") { - exit 0 unless $ret->has_errors || $has_nonexistent_test; + exit 0 unless $ret->has_errors; exit 1 unless $^O eq 'VMS'; # On VMS, perl converts an exit 1 to SS$_ABORT (%SYSTEM-F-ABORT), which # is a bit harsh. As per perl recommendations, we explicitly use the @@ -414,6 +396,4 @@ if (ref($ret) eq "TAP::Parser::Aggregator") { # If this isn't a TAP::Parser::Aggregator, it's the pre-TAP test harness, # which simply dies at the end if any test failed, so we don't need to bother -# with any exit code in that case. The only exception is if we have a -# non-existent test). -exit 1 if $has_nonexistent_test; +# with any exit code in that case. diff --git a/test/secmemtest.c b/test/secmemtest.c index b0ac91a38f..05b0bbc857 100644 --- a/test/secmemtest.c +++ b/test/secmemtest.c @@ -81,7 +81,7 @@ static int test_sec_mem(void) * If init fails, then initialized should be false, if not, this * could cause an infinite loop secure_malloc, but we don't test it */ - if (!TEST_true(CRYPTO_secure_malloc_init(16, 16)) && !TEST_false(CRYPTO_secure_malloc_initialized())) { + if (TEST_false(CRYPTO_secure_malloc_init(16, 16)) && !TEST_false(CRYPTO_secure_malloc_initialized())) { TEST_true(CRYPTO_secure_malloc_done()); goto end; } diff --git a/test/sha3_x4_internal_test.c b/test/sha3_x4_internal_test.c deleted file mode 100644 index aa6a452db6..0000000000 --- a/test/sha3_x4_internal_test.c +++ /dev/null @@ -1,430 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * Copyright (c) 2026 Intel Corporation. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* - * Internal cross-validation tests for the SHAKE x4 multi-buffer API. - * - * Each test computes SHAKE-128 or SHAKE-256 on four independent inputs - * using the x4 (AVX-512VL) path and compares every lane's output to the - * equivalent result produced by the scalar ossl_sha3_* API. - * - * Tests cover: - * - Single-call (ossl_sha3_shake{128,256}_x4_avx512vl) for many (inlen, outlen) pairs - * - Incremental init/absorb/squeeze for the same (inlen, outlen) pairs - * - Multi-absorb: input split at every possible block boundary - * - Multi-squeeze: output produced in two successive squeeze calls - */ - -#include -#include "testutil.h" - -/* - * KECCAK1600_ASM is only added to the library compilation flags by the build - * system, not to test binaries. Since the x4 declarations in internal/sha3.h - * are guarded by that macro, we define it here before the include so that the - * KECCAK1600_X4_AVX512VL_CTX type and function prototypes are visible. - * The symbols themselves live in libcrypto and are always present. - * We additionally gate all x4 code on x86_64 (GCC/Clang: __x86_64__, - * MSVC: _M_AMD64/_M_X64) and !OPENSSL_NO_ASM so that the test still - * compiles on other platforms or in no-asm builds. - */ -#if (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)) \ - && !defined(OPENSSL_NO_ASM) -#ifndef KECCAK1600_ASM -#define KECCAK1600_ASM -#endif -#endif -#include "internal/sha3.h" - -/* - * A single deterministic 1024-byte message. Each of the four lanes receives - * a different slice of this buffer, with lane base pointers spaced 64 bytes - * apart, so their inputs are distinct yet entirely self-contained. - */ -#define MSG_BUF_SIZE 1024 -#define LANE_STRIDE 64 /* byte offset between lane base pointers */ -#define NUM_LANES 4 - -static unsigned char msg[MSG_BUF_SIZE]; - -/* Maximum output length used in this file – must fit chunk1 + chunk2. */ -#define MAX_OUT 640 - -#if defined(KECCAK1600_ASM) \ - && (defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)) \ - && !defined(OPENSSL_NO_ASM) - -/* - * Input lengths exercising: empty, tiny, sub-block, block boundary ±1, - * multiple blocks and a longer message for SHAKE-128 (rate=168) and - * SHAKE-256 (rate=136). - */ -static const size_t input_sizes[] = { - 0, 1, 17, 100, 135, 136, 137, 168, 169, 200, 400 -}; -#define NUM_INPUT_SIZES (sizeof(input_sizes) / sizeof(input_sizes[0])) - -/* Output lengths chosen to straddle rate boundaries for both variants. */ -static const size_t output_sizes[] = { - 16, 32, 64, 136, 168, 256, 512 -}; -#define NUM_OUTPUT_SIZES (sizeof(output_sizes) / sizeof(output_sizes[0])) - -/* Helpers functions */ - -/* - * Compute a scalar SHAKE-128 or SHAKE-256 digest. - * bitlen: 128 or 256. Returns 1 on success, 0 on failure. - */ -static int scalar_shake(const unsigned int bitlen, - const unsigned char *in, const size_t inlen, - unsigned char *out, const size_t outlen) -{ - KECCAK1600_CTX ctx; - - if (!ossl_sha3_init(&ctx, 0x1f, bitlen)) - return 0; - /* ossl_sha3_init does not populate the method vtable; do it here. */ - ctx.meth.absorb = ossl_sha3_absorb_default; - ctx.meth.final = ossl_sha3_final_default; - ctx.meth.squeeze = ossl_shake_squeeze_default; - return ossl_sha3_absorb(&ctx, in, inlen) - && ossl_sha3_squeeze(&ctx, out, outlen); -} - -/* - * Encode (inlen_idx, outlen_idx) into a single test index and back. - * test index n = inlen_idx * NUM_OUTPUT_SIZES + outlen_idx - */ -static void decode_idx(const int n, size_t *inlen, size_t *outlen) -{ - *inlen = input_sizes[n / (int)NUM_OUTPUT_SIZES]; - *outlen = output_sizes[n % (int)NUM_OUTPUT_SIZES]; -} - -/* One-shot tests */ - -static int test_shake_x4_oneshot(const unsigned int bitlen, const int n) -{ - size_t inlen, outlen; - const unsigned char *in[NUM_LANES]; - unsigned char x4_out[NUM_LANES][MAX_OUT]; - unsigned char ref_out[NUM_LANES][MAX_OUT]; - int i; - - decode_idx(n, &inlen, &outlen); - - for (i = 0; i < NUM_LANES; i++) - in[i] = msg + i * LANE_STRIDE; - - /* Ensure the lane inputs fit within the message buffer. */ - if (!TEST_size_t_le(inlen + (NUM_LANES - 1) * LANE_STRIDE, MSG_BUF_SIZE)) - return 0; - if (!TEST_size_t_le(outlen, MAX_OUT)) - return 0; - - /* x4 single-call */ - if (bitlen == 128) - ossl_sha3_shake128_x4_avx512vl(x4_out[0], x4_out[1], x4_out[2], x4_out[3], - outlen, - in[0], in[1], in[2], in[3], inlen); - else - ossl_sha3_shake256_x4_avx512vl(x4_out[0], x4_out[1], x4_out[2], x4_out[3], - outlen, - in[0], in[1], in[2], in[3], inlen); - - /* scalar reference */ - for (i = 0; i < NUM_LANES; i++) - if (!TEST_true(scalar_shake(bitlen, in[i], inlen, ref_out[i], outlen))) - return 0; - - /* compare */ - for (i = 0; i < NUM_LANES; i++) { - if (!TEST_mem_eq(x4_out[i], outlen, ref_out[i], outlen)) { - TEST_info("SHAKE-%u x4 oneshot lane %d: inlen=%zu outlen=%zu", - bitlen, i, inlen, outlen); - return 0; - } - } - return 1; -} - -static int test_shake128_x4_oneshot(const int n) -{ - return test_shake_x4_oneshot(128, n); -} - -static int test_shake256_x4_oneshot(const int n) -{ - return test_shake_x4_oneshot(256, n); -} - -/* Incremental (init / absorb / finalize / squeeze) tests */ - -static int test_shake_x4_incremental(const unsigned int bitlen, const int n) -{ - size_t inlen, outlen; - const unsigned char *in[NUM_LANES]; - unsigned char x4_out[NUM_LANES][MAX_OUT]; - unsigned char ref_out[NUM_LANES][MAX_OUT]; - KECCAK1600_X4_AVX512VL_CTX ctx; - int i; - - decode_idx(n, &inlen, &outlen); - - for (i = 0; i < NUM_LANES; i++) - in[i] = msg + i * LANE_STRIDE; - - if (!TEST_size_t_le(inlen + (NUM_LANES - 1) * LANE_STRIDE, MSG_BUF_SIZE)) - return 0; - - /* x4 incremental */ - if (bitlen == 128) { - ossl_sha3_shake128_x4_inc_init_avx512vl(&ctx); - ossl_sha3_shake128_x4_inc_absorb_avx512vl(&ctx, in[0], in[1], in[2], in[3], - inlen); - ossl_sha3_shake128_x4_inc_squeeze_avx512vl(x4_out[0], x4_out[1], - x4_out[2], x4_out[3], outlen, &ctx); - } else { - ossl_sha3_shake256_x4_inc_init_avx512vl(&ctx); - ossl_sha3_shake256_x4_inc_absorb_avx512vl(&ctx, in[0], in[1], in[2], in[3], - inlen); - ossl_sha3_shake256_x4_inc_squeeze_avx512vl(x4_out[0], x4_out[1], - x4_out[2], x4_out[3], outlen, &ctx); - } - - /* scalar reference */ - for (i = 0; i < NUM_LANES; i++) - if (!TEST_true(scalar_shake(bitlen, in[i], inlen, ref_out[i], outlen))) - return 0; - - for (i = 0; i < NUM_LANES; i++) { - if (!TEST_mem_eq(x4_out[i], outlen, ref_out[i], outlen)) { - TEST_info("SHAKE-%u x4 incremental lane %d: inlen=%zu outlen=%zu", - bitlen, i, inlen, outlen); - return 0; - } - } - return 1; -} - -static int test_shake128_x4_incremental(const int n) -{ - return test_shake_x4_incremental(128, n); -} - -static int test_shake256_x4_incremental(const int n) -{ - return test_shake_x4_incremental(256, n); -} - -/* Multi-absorb tests */ - -/* - * Split the input at every tested input size, absorbing the two halves - * in separate calls. The split length is chosen as input_sizes[n] so that - * we exercise sub-block, at-block and multi-block split points. - * - * Full message length is fixed at the largest tested input size so that - * every split index is meaningful. - */ -static int test_shake_x4_multi_absorb(const unsigned int bitlen, const int n) -{ - const size_t total = input_sizes[NUM_INPUT_SIZES - 1]; - const size_t split = input_sizes[n]; - const size_t outlen = 64; /* fixed output length for this sub-test */ - const unsigned char *in[NUM_LANES]; - unsigned char x4_out[NUM_LANES][MAX_OUT]; - unsigned char ref_out[NUM_LANES][MAX_OUT]; - KECCAK1600_X4_AVX512VL_CTX ctx; - int i; - - if (split > total) - return 1; /* nothing to test */ - - for (i = 0; i < NUM_LANES; i++) - in[i] = msg + i * LANE_STRIDE; - - if (!TEST_size_t_le(total + (NUM_LANES - 1) * LANE_STRIDE, MSG_BUF_SIZE)) - return 0; - - /* x4 split absorb */ - if (bitlen == 128) { - ossl_sha3_shake128_x4_inc_init_avx512vl(&ctx); - ossl_sha3_shake128_x4_inc_absorb_avx512vl(&ctx, - in[0], in[1], in[2], in[3], split); - ossl_sha3_shake128_x4_inc_absorb_avx512vl(&ctx, - in[0] + split, in[1] + split, in[2] + split, in[3] + split, - total - split); - ossl_sha3_shake128_x4_inc_squeeze_avx512vl(x4_out[0], x4_out[1], - x4_out[2], x4_out[3], outlen, &ctx); - } else { - ossl_sha3_shake256_x4_inc_init_avx512vl(&ctx); - ossl_sha3_shake256_x4_inc_absorb_avx512vl(&ctx, - in[0], in[1], in[2], in[3], split); - ossl_sha3_shake256_x4_inc_absorb_avx512vl(&ctx, - in[0] + split, in[1] + split, in[2] + split, in[3] + split, - total - split); - ossl_sha3_shake256_x4_inc_squeeze_avx512vl(x4_out[0], x4_out[1], - x4_out[2], x4_out[3], outlen, &ctx); - } - - /* scalar reference (single absorb of full message) */ - for (i = 0; i < NUM_LANES; i++) - if (!TEST_true(scalar_shake(bitlen, in[i], total, ref_out[i], outlen))) - return 0; - - for (i = 0; i < NUM_LANES; i++) { - if (!TEST_mem_eq(x4_out[i], outlen, ref_out[i], outlen)) { - TEST_info("SHAKE-%u x4 multi-absorb lane %d: total=%zu split=%zu", - bitlen, i, total, split); - return 0; - } - } - return 1; -} - -static int test_shake128_x4_multi_absorb(const int n) -{ - return test_shake_x4_multi_absorb(128, n); -} - -static int test_shake256_x4_multi_absorb(const int n) -{ - return test_shake_x4_multi_absorb(256, n); -} - -/* Multi-squeeze tests */ - -/* - * Squeeze in two successive calls and verify that the concatenated output - * matches a single scalar squeeze of the same total length. - * Parameterized over output_sizes[] for the first chunk; the second chunk - * is always 64 bytes so the total length varies. - */ -static int test_shake_x4_multi_squeeze(const unsigned int bitlen, const int n) -{ - const size_t inlen = 200; /* fixed input length */ - const size_t chunk1 = output_sizes[n]; - const size_t chunk2 = 64; - const size_t total = chunk1 + chunk2; - const unsigned char *in[NUM_LANES]; - unsigned char x4_a[NUM_LANES][MAX_OUT]; /* first chunk */ - unsigned char x4_b[NUM_LANES][MAX_OUT]; /* second chunk */ - unsigned char ref_out[NUM_LANES][MAX_OUT]; - KECCAK1600_X4_AVX512VL_CTX ctx; - int i; - - if (!TEST_size_t_le(total, MAX_OUT)) - return 0; - if (!TEST_size_t_le(inlen + (NUM_LANES - 1) * LANE_STRIDE, MSG_BUF_SIZE)) - return 0; - - for (i = 0; i < NUM_LANES; i++) - in[i] = msg + i * LANE_STRIDE; - - /* x4 two-shot squeeze */ - if (bitlen == 128) { - ossl_sha3_shake128_x4_inc_init_avx512vl(&ctx); - ossl_sha3_shake128_x4_inc_absorb_avx512vl(&ctx, in[0], in[1], in[2], in[3], - inlen); - /* first squeeze */ - ossl_sha3_shake128_x4_inc_squeeze_avx512vl(x4_a[0], x4_a[1], x4_a[2], x4_a[3], - chunk1, &ctx); - /* second squeeze – context carries state from previous call */ - ossl_sha3_shake128_x4_inc_squeeze_avx512vl(x4_b[0], x4_b[1], x4_b[2], x4_b[3], - chunk2, &ctx); - } else { - ossl_sha3_shake256_x4_inc_init_avx512vl(&ctx); - ossl_sha3_shake256_x4_inc_absorb_avx512vl(&ctx, in[0], in[1], in[2], in[3], - inlen); - ossl_sha3_shake256_x4_inc_squeeze_avx512vl(x4_a[0], x4_a[1], x4_a[2], x4_a[3], - chunk1, &ctx); - ossl_sha3_shake256_x4_inc_squeeze_avx512vl(x4_b[0], x4_b[1], x4_b[2], x4_b[3], - chunk2, &ctx); - } - - /* scalar reference – squeeze the full total in one call */ - for (i = 0; i < NUM_LANES; i++) - if (!TEST_true(scalar_shake(bitlen, in[i], inlen, ref_out[i], total))) - return 0; - - /* check first chunk, then second chunk */ - for (i = 0; i < NUM_LANES; i++) { - if (!TEST_mem_eq(x4_a[i], chunk1, ref_out[i], chunk1)) { - TEST_info("SHAKE-%u x4 multi-squeeze lane %d chunk1: " - "inlen=%zu chunk1=%zu chunk2=%zu", - bitlen, i, inlen, chunk1, chunk2); - return 0; - } - if (!TEST_mem_eq(x4_b[i], chunk2, ref_out[i] + chunk1, chunk2)) { - TEST_info("SHAKE-%u x4 multi-squeeze lane %d chunk2: " - "inlen=%zu chunk1=%zu chunk2=%zu", - bitlen, i, inlen, chunk1, chunk2); - return 0; - } - } - return 1; -} - -static int test_shake128_x4_multi_squeeze(const int n) -{ - return test_shake_x4_multi_squeeze(128, n); -} - -static int test_shake256_x4_multi_squeeze(const int n) -{ - return test_shake_x4_multi_squeeze(256, n); -} - -#endif /* KECCAK1600_ASM && x86_64 && !OPENSSL_NO_ASM */ - -/* Test entry point */ - -int setup_tests(void) -{ - size_t i; - - /* Fill the message buffer with a deterministic non-zero pattern. */ - for (i = 0; i < MSG_BUF_SIZE; i++) - msg[i] = (unsigned char)(251 * i + 17); - -#ifdef OPENSSL_CPUID_OBJ - OPENSSL_cpuid_setup(); -#endif - -#if !defined(KECCAK1600_ASM) \ - || !(defined(__x86_64) || defined(__x86_64__) || defined(_M_AMD64) || defined(_M_X64)) \ - || defined(OPENSSL_NO_ASM) - return TEST_skip("SHAKE x4 API not available in this build"); -#else - if (!SHA3_avx512vl_capable()) { - return TEST_skip("AVX-512VL not available; skipping SHAKE x4 tests"); - } - - ADD_ALL_TESTS(test_shake128_x4_oneshot, - (int)(NUM_INPUT_SIZES * NUM_OUTPUT_SIZES)); - ADD_ALL_TESTS(test_shake256_x4_oneshot, - (int)(NUM_INPUT_SIZES * NUM_OUTPUT_SIZES)); - - ADD_ALL_TESTS(test_shake128_x4_incremental, - (int)(NUM_INPUT_SIZES * NUM_OUTPUT_SIZES)); - ADD_ALL_TESTS(test_shake256_x4_incremental, - (int)(NUM_INPUT_SIZES * NUM_OUTPUT_SIZES)); - - ADD_ALL_TESTS(test_shake128_x4_multi_absorb, (int)NUM_INPUT_SIZES); - ADD_ALL_TESTS(test_shake256_x4_multi_absorb, (int)NUM_INPUT_SIZES); - - ADD_ALL_TESTS(test_shake128_x4_multi_squeeze, (int)NUM_OUTPUT_SIZES); - ADD_ALL_TESTS(test_shake256_x4_multi_squeeze, (int)NUM_OUTPUT_SIZES); -#endif - - return 1; -} diff --git a/test/shlibloadtest.c b/test/shlibloadtest.c index de37b0bfe6..034780ea55 100644 --- a/test/shlibloadtest.c +++ b/test/shlibloadtest.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2021 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -21,6 +21,7 @@ typedef const SSL_METHOD *(*TLS_method_t)(void); typedef SSL_CTX *(*SSL_CTX_new_t)(const SSL_METHOD *meth); typedef void (*SSL_CTX_free_t)(SSL_CTX *); typedef int (*OPENSSL_init_crypto_t)(uint64_t, void *); +typedef int (*OPENSSL_atexit_t)(void (*handler)(void)); typedef unsigned long (*ERR_get_error_t)(void); typedef unsigned long (*OPENSSL_version_major_t)(void); typedef unsigned long (*OPENSSL_version_minor_t)(void); @@ -33,14 +34,30 @@ typedef enum test_types_en { SSL_FIRST, JUST_CRYPTO, DSO_REFTEST, + NO_ATEXIT } TEST_TYPE; static TEST_TYPE test_type; static const char *path_crypto; static const char *path_ssl; +static const char *path_atexit; #ifdef SD_INIT +static int atexit_handler_done = 0; + +static void atexit_handler(void) +{ + FILE *atexit_file = fopen(path_atexit, "w"); + + if (atexit_file == NULL) + return; + + fprintf(atexit_file, "atexit() run\n"); + fclose(atexit_file); + atexit_handler_done++; +} + static int test_lib(void) { SD ssllib = SD_INIT; @@ -57,11 +74,13 @@ static int test_lib(void) OPENSSL_version_major_t myOPENSSL_version_major; OPENSSL_version_minor_t myOPENSSL_version_minor; OPENSSL_version_patch_t myOPENSSL_version_patch; + OPENSSL_atexit_t myOPENSSL_atexit; int result = 0; switch (test_type) { case JUST_CRYPTO: case DSO_REFTEST: + case NO_ATEXIT: case CRYPTO_FIRST: if (!sd_load(path_crypto, &cryptolib, SD_SHLIB)) { fprintf(stderr, "Failed to load libcrypto\n"); @@ -85,8 +104,23 @@ static int test_lib(void) break; } + if (test_type == NO_ATEXIT) { + OPENSSL_init_crypto_t myOPENSSL_init_crypto; + + if (!sd_sym(cryptolib, "OPENSSL_init_crypto", &symbols[0].sym)) { + fprintf(stderr, "Failed to load OPENSSL_init_crypto symbol\n"); + goto end; + } + myOPENSSL_init_crypto = (OPENSSL_init_crypto_t)symbols[0].func; + if (!myOPENSSL_init_crypto(OPENSSL_INIT_NO_ATEXIT, NULL)) { + fprintf(stderr, "Failed to initialise libcrypto\n"); + goto end; + } + } + if (test_type != JUST_CRYPTO - && test_type != DSO_REFTEST) { + && test_type != DSO_REFTEST + && test_type != NO_ATEXIT) { if (!sd_sym(ssllib, "TLS_method", &symbols[0].sym) || !sd_sym(ssllib, "SSL_CTX_new", &symbols[1].sym) || !sd_sym(ssllib, "SSL_CTX_free", &symbols[2].sym)) { @@ -107,7 +141,8 @@ static int test_lib(void) if (!sd_sym(cryptolib, "ERR_get_error", &symbols[0].sym) || !sd_sym(cryptolib, "OPENSSL_version_major", &symbols[1].sym) || !sd_sym(cryptolib, "OPENSSL_version_minor", &symbols[2].sym) - || !sd_sym(cryptolib, "OPENSSL_version_patch", &symbols[3].sym)) { + || !sd_sym(cryptolib, "OPENSSL_version_patch", &symbols[3].sym) + || !sd_sym(cryptolib, "OPENSSL_atexit", &symbols[4].sym)) { fprintf(stderr, "Failed to load libcrypto symbols\n"); goto end; } @@ -128,17 +163,24 @@ static int test_lib(void) goto end; } + myOPENSSL_atexit = (OPENSSL_atexit_t)symbols[4].func; + if (!myOPENSSL_atexit(atexit_handler)) { + fprintf(stderr, "Failed to register atexit handler\n"); + goto end; + } + if (test_type == DSO_REFTEST) { #ifdef DSO_DLFCN DSO_dsobyaddr_t myDSO_dsobyaddr; DSO_free_t myDSO_free; /* - * This is resembling the code used in ossl_init_base() to block - * unloading the library after dlclose(). We are not testing this on - * Windows, because it is done there in a completely different way. - * Especially as a call to DSO_dsobyaddr() will always return an error, - * because DSO_pathbyaddr() is not implemented there. + * This is resembling the code used in ossl_init_base() and + * OPENSSL_atexit() to block unloading the library after dlclose(). + * We are not testing this on Windows, because it is done there in a + * completely different way. Especially as a call to DSO_dsobyaddr() + * will always return an error, because DSO_pathbyaddr() is not + * implemented there. */ if (!sd_sym(cryptolib, "DSO_dsobyaddr", &symbols[0].sym) || !sd_sym(cryptolib, "DSO_free", &symbols[1].sym)) { @@ -176,6 +218,23 @@ static int test_lib(void) ssllib = SD_INIT; } +#if defined(OPENSSL_NO_PINSHARED) \ + && defined(__GLIBC__) \ + && defined(__GLIBC_PREREQ) \ + && defined(OPENSSL_SYS_LINUX) +#if __GLIBC_PREREQ(2, 3) + /* + * If we didn't pin the so then we are hopefully on a platform that supports + * running atexit() on so unload. If not we might crash. We know this is + * true on linux since glibc 2.2.3 + */ + if (test_type != NO_ATEXIT && atexit_handler_done != 1) { + fprintf(stderr, "atexit() handler did not run\n"); + goto end; + } +#endif +#endif + result = 1; end: if (cryptolib != SD_INIT) @@ -195,7 +254,7 @@ int main(int argc, char *argv[]) { const char *p; - if (argc != 4) { + if (argc != 5) { fprintf(stderr, "Incorrect number of arguments\n"); return 1; } @@ -210,12 +269,15 @@ int main(int argc, char *argv[]) test_type = JUST_CRYPTO; } else if (strcmp(p, "-dso_ref") == 0) { test_type = DSO_REFTEST; + } else if (strcmp(p, "-no_atexit") == 0) { + test_type = NO_ATEXIT; } else { fprintf(stderr, "Unrecognised argument\n"); return 1; } path_crypto = argv[2]; path_ssl = argv[3]; + path_atexit = argv[4]; if (path_crypto == NULL || path_ssl == NULL) { fprintf(stderr, "Invalid libcrypto/libssl path\n"); return 1; diff --git a/test/simpledynamic.c b/test/simpledynamic.c index 5918797cd6..b3d3d2a59b 100644 --- a/test/simpledynamic.c +++ b/test/simpledynamic.c @@ -52,7 +52,7 @@ int sd_load(const char *filename, SD *lib, ossl_unused int type) int sd_sym(SD lib, const char *symname, SD_SYM *sym) { - *sym = (SD_SYM)(uintptr_t)GetProcAddress(lib, symname); + *sym = (SD_SYM)GetProcAddress(lib, symname); return *sym != NULL; } diff --git a/test/siphash_internal_test.c b/test/siphash_internal_test.c index 6ea87d9b9c..4ac82a15ea 100644 --- a/test/siphash_internal_test.c +++ b/test/siphash_internal_test.c @@ -36,134 +36,1798 @@ typedef struct { /* From C reference: https://131002.net/siphash/ */ static TESTDATA tests[] = { - { 0, { 8, { 0x31, 0x0e, 0x0e, 0xdd, 0x47, 0xdb, 0x6f, 0x72 } } }, - { 1, { 8, { 0xfd, 0x67, 0xdc, 0x93, 0xc5, 0x39, 0xf8, 0x74 } } }, - { 2, { 8, { 0x5a, 0x4f, 0xa9, 0xd9, 0x09, 0x80, 0x6c, 0x0d } } }, - { 3, { 8, { 0x2d, 0x7e, 0xfb, 0xd7, 0x96, 0x66, 0x67, 0x85 } } }, - { 4, { 8, { 0xb7, 0x87, 0x71, 0x27, 0xe0, 0x94, 0x27, 0xcf } } }, - { 5, { 8, { 0x8d, 0xa6, 0x99, 0xcd, 0x64, 0x55, 0x76, 0x18 } } }, - { 6, { 8, { 0xce, 0xe3, 0xfe, 0x58, 0x6e, 0x46, 0xc9, 0xcb } } }, - { 7, { 8, { 0x37, 0xd1, 0x01, 0x8b, 0xf5, 0x00, 0x02, 0xab } } }, - { 8, { 8, { 0x62, 0x24, 0x93, 0x9a, 0x79, 0xf5, 0xf5, 0x93 } } }, - { 9, { 8, { 0xb0, 0xe4, 0xa9, 0x0b, 0xdf, 0x82, 0x00, 0x9e } } }, - { 10, { 8, { 0xf3, 0xb9, 0xdd, 0x94, 0xc5, 0xbb, 0x5d, 0x7a } } }, - { 11, { 8, { 0xa7, 0xad, 0x6b, 0x22, 0x46, 0x2f, 0xb3, 0xf4 } } }, - { 12, { 8, { 0xfb, 0xe5, 0x0e, 0x86, 0xbc, 0x8f, 0x1e, 0x75 } } }, - { 13, { 8, { 0x90, 0x3d, 0x84, 0xc0, 0x27, 0x56, 0xea, 0x14 } } }, - { 14, { 8, { 0xee, 0xf2, 0x7a, 0x8e, 0x90, 0xca, 0x23, 0xf7 } } }, - { 15, { 8, { 0xe5, 0x45, 0xbe, 0x49, 0x61, 0xca, 0x29, 0xa1 } } }, - { 16, { 8, { 0xdb, 0x9b, 0xc2, 0x57, 0x7f, 0xcc, 0x2a, 0x3f } } }, - { 17, { 8, { 0x94, 0x47, 0xbe, 0x2c, 0xf5, 0xe9, 0x9a, 0x69 } } }, - { 18, { 8, { 0x9c, 0xd3, 0x8d, 0x96, 0xf0, 0xb3, 0xc1, 0x4b } } }, - { 19, { 8, { 0xbd, 0x61, 0x79, 0xa7, 0x1d, 0xc9, 0x6d, 0xbb } } }, - { 20, { 8, { 0x98, 0xee, 0xa2, 0x1a, 0xf2, 0x5c, 0xd6, 0xbe } } }, - { 21, { 8, { 0xc7, 0x67, 0x3b, 0x2e, 0xb0, 0xcb, 0xf2, 0xd0 } } }, - { 22, { 8, { 0x88, 0x3e, 0xa3, 0xe3, 0x95, 0x67, 0x53, 0x93 } } }, - { 23, { 8, { 0xc8, 0xce, 0x5c, 0xcd, 0x8c, 0x03, 0x0c, 0xa8 } } }, - { 24, { 8, { 0x94, 0xaf, 0x49, 0xf6, 0xc6, 0x50, 0xad, 0xb8 } } }, - { 25, { 8, { 0xea, 0xb8, 0x85, 0x8a, 0xde, 0x92, 0xe1, 0xbc } } }, - { 26, { 8, { 0xf3, 0x15, 0xbb, 0x5b, 0xb8, 0x35, 0xd8, 0x17 } } }, - { 27, { 8, { 0xad, 0xcf, 0x6b, 0x07, 0x63, 0x61, 0x2e, 0x2f } } }, - { 28, { 8, { 0xa5, 0xc9, 0x1d, 0xa7, 0xac, 0xaa, 0x4d, 0xde } } }, - { 29, { 8, { 0x71, 0x65, 0x95, 0x87, 0x66, 0x50, 0xa2, 0xa6 } } }, - { 30, { 8, { 0x28, 0xef, 0x49, 0x5c, 0x53, 0xa3, 0x87, 0xad } } }, - { 31, { 8, { 0x42, 0xc3, 0x41, 0xd8, 0xfa, 0x92, 0xd8, 0x32 } } }, - { 32, { 8, { 0xce, 0x7c, 0xf2, 0x72, 0x2f, 0x51, 0x27, 0x71 } } }, - { 33, { 8, { 0xe3, 0x78, 0x59, 0xf9, 0x46, 0x23, 0xf3, 0xa7 } } }, - { 34, { 8, { 0x38, 0x12, 0x05, 0xbb, 0x1a, 0xb0, 0xe0, 0x12 } } }, - { 35, { 8, { 0xae, 0x97, 0xa1, 0x0f, 0xd4, 0x34, 0xe0, 0x15 } } }, - { 36, { 8, { 0xb4, 0xa3, 0x15, 0x08, 0xbe, 0xff, 0x4d, 0x31 } } }, - { 37, { 8, { 0x81, 0x39, 0x62, 0x29, 0xf0, 0x90, 0x79, 0x02 } } }, - { 38, { 8, { 0x4d, 0x0c, 0xf4, 0x9e, 0xe5, 0xd4, 0xdc, 0xca } } }, - { 39, { 8, { 0x5c, 0x73, 0x33, 0x6a, 0x76, 0xd8, 0xbf, 0x9a } } }, - { 40, { 8, { 0xd0, 0xa7, 0x04, 0x53, 0x6b, 0xa9, 0x3e, 0x0e } } }, - { 41, { 8, { 0x92, 0x59, 0x58, 0xfc, 0xd6, 0x42, 0x0c, 0xad } } }, - { 42, { 8, { 0xa9, 0x15, 0xc2, 0x9b, 0xc8, 0x06, 0x73, 0x18 } } }, - { 43, { 8, { 0x95, 0x2b, 0x79, 0xf3, 0xbc, 0x0a, 0xa6, 0xd4 } } }, - { 44, { 8, { 0xf2, 0x1d, 0xf2, 0xe4, 0x1d, 0x45, 0x35, 0xf9 } } }, - { 45, { 8, { 0x87, 0x57, 0x75, 0x19, 0x04, 0x8f, 0x53, 0xa9 } } }, - { 46, { 8, { 0x10, 0xa5, 0x6c, 0xf5, 0xdf, 0xcd, 0x9a, 0xdb } } }, - { 47, { 8, { 0xeb, 0x75, 0x09, 0x5c, 0xcd, 0x98, 0x6c, 0xd0 } } }, - { 48, { 8, { 0x51, 0xa9, 0xcb, 0x9e, 0xcb, 0xa3, 0x12, 0xe6 } } }, - { 49, { 8, { 0x96, 0xaf, 0xad, 0xfc, 0x2c, 0xe6, 0x66, 0xc7 } } }, - { 50, { 8, { 0x72, 0xfe, 0x52, 0x97, 0x5a, 0x43, 0x64, 0xee } } }, - { 51, { 8, { 0x5a, 0x16, 0x45, 0xb2, 0x76, 0xd5, 0x92, 0xa1 } } }, - { 52, { 8, { 0xb2, 0x74, 0xcb, 0x8e, 0xbf, 0x87, 0x87, 0x0a } } }, - { 53, { 8, { 0x6f, 0x9b, 0xb4, 0x20, 0x3d, 0xe7, 0xb3, 0x81 } } }, - { 54, { 8, { 0xea, 0xec, 0xb2, 0xa3, 0x0b, 0x22, 0xa8, 0x7f } } }, - { 55, { 8, { 0x99, 0x24, 0xa4, 0x3c, 0xc1, 0x31, 0x57, 0x24 } } }, - { 56, { 8, { 0xbd, 0x83, 0x8d, 0x3a, 0xaf, 0xbf, 0x8d, 0xb7 } } }, - { 57, { 8, { 0x0b, 0x1a, 0x2a, 0x32, 0x65, 0xd5, 0x1a, 0xea } } }, - { 58, { 8, { 0x13, 0x50, 0x79, 0xa3, 0x23, 0x1c, 0xe6, 0x60 } } }, - { 59, { 8, { 0x93, 0x2b, 0x28, 0x46, 0xe4, 0xd7, 0x06, 0x66 } } }, - { 60, { 8, { 0xe1, 0x91, 0x5f, 0x5c, 0xb1, 0xec, 0xa4, 0x6c } } }, - { 61, { 8, { 0xf3, 0x25, 0x96, 0x5c, 0xa1, 0x6d, 0x62, 0x9f } } }, - { 62, { 8, { 0x57, 0x5f, 0xf2, 0x8e, 0x60, 0x38, 0x1b, 0xe5 } } }, - { 63, { 8, { 0x72, 0x45, 0x06, 0xeb, 0x4c, 0x32, 0x8a, 0x95 } } }, - { 0, { 16, { 0xa3, 0x81, 0x7f, 0x04, 0xba, 0x25, 0xa8, 0xe6, 0x6d, 0xf6, 0x72, 0x14, 0xc7, 0x55, 0x02, 0x93 } } }, - { 1, { 16, { 0xda, 0x87, 0xc1, 0xd8, 0x6b, 0x99, 0xaf, 0x44, 0x34, 0x76, 0x59, 0x11, 0x9b, 0x22, 0xfc, 0x45 } } }, - { 2, { 16, { 0x81, 0x77, 0x22, 0x8d, 0xa4, 0xa4, 0x5d, 0xc7, 0xfc, 0xa3, 0x8b, 0xde, 0xf6, 0x0a, 0xff, 0xe4 } } }, - { 3, { 16, { 0x9c, 0x70, 0xb6, 0x0c, 0x52, 0x67, 0xa9, 0x4e, 0x5f, 0x33, 0xb6, 0xb0, 0x29, 0x85, 0xed, 0x51 } } }, - { 4, { 16, { 0xf8, 0x81, 0x64, 0xc1, 0x2d, 0x9c, 0x8f, 0xaf, 0x7d, 0x0f, 0x6e, 0x7c, 0x7b, 0xcd, 0x55, 0x79 } } }, - { 5, { 16, { 0x13, 0x68, 0x87, 0x59, 0x80, 0x77, 0x6f, 0x88, 0x54, 0x52, 0x7a, 0x07, 0x69, 0x0e, 0x96, 0x27 } } }, - { 6, { 16, { 0x14, 0xee, 0xca, 0x33, 0x8b, 0x20, 0x86, 0x13, 0x48, 0x5e, 0xa0, 0x30, 0x8f, 0xd7, 0xa1, 0x5e } } }, - { 7, { 16, { 0xa1, 0xf1, 0xeb, 0xbe, 0xd8, 0xdb, 0xc1, 0x53, 0xc0, 0xb8, 0x4a, 0xa6, 0x1f, 0xf0, 0x82, 0x39 } } }, - { 8, { 16, { 0x3b, 0x62, 0xa9, 0xba, 0x62, 0x58, 0xf5, 0x61, 0x0f, 0x83, 0xe2, 0x64, 0xf3, 0x14, 0x97, 0xb4 } } }, - { 9, { 16, { 0x26, 0x44, 0x99, 0x06, 0x0a, 0xd9, 0xba, 0xab, 0xc4, 0x7f, 0x8b, 0x02, 0xbb, 0x6d, 0x71, 0xed } } }, - { 10, { 16, { 0x00, 0x11, 0x0d, 0xc3, 0x78, 0x14, 0x69, 0x56, 0xc9, 0x54, 0x47, 0xd3, 0xf3, 0xd0, 0xfb, 0xba } } }, - { 11, { 16, { 0x01, 0x51, 0xc5, 0x68, 0x38, 0x6b, 0x66, 0x77, 0xa2, 0xb4, 0xdc, 0x6f, 0x81, 0xe5, 0xdc, 0x18 } } }, - { 12, { 16, { 0xd6, 0x26, 0xb2, 0x66, 0x90, 0x5e, 0xf3, 0x58, 0x82, 0x63, 0x4d, 0xf6, 0x85, 0x32, 0xc1, 0x25 } } }, - { 13, { 16, { 0x98, 0x69, 0xe2, 0x47, 0xe9, 0xc0, 0x8b, 0x10, 0xd0, 0x29, 0x93, 0x4f, 0xc4, 0xb9, 0x52, 0xf7 } } }, - { 14, { 16, { 0x31, 0xfc, 0xef, 0xac, 0x66, 0xd7, 0xde, 0x9c, 0x7e, 0xc7, 0x48, 0x5f, 0xe4, 0x49, 0x49, 0x02 } } }, - { 15, { 16, { 0x54, 0x93, 0xe9, 0x99, 0x33, 0xb0, 0xa8, 0x11, 0x7e, 0x08, 0xec, 0x0f, 0x97, 0xcf, 0xc3, 0xd9 } } }, - { 16, { 16, { 0x6e, 0xe2, 0xa4, 0xca, 0x67, 0xb0, 0x54, 0xbb, 0xfd, 0x33, 0x15, 0xbf, 0x85, 0x23, 0x05, 0x77 } } }, - { 17, { 16, { 0x47, 0x3d, 0x06, 0xe8, 0x73, 0x8d, 0xb8, 0x98, 0x54, 0xc0, 0x66, 0xc4, 0x7a, 0xe4, 0x77, 0x40 } } }, - { 18, { 16, { 0xa4, 0x26, 0xe5, 0xe4, 0x23, 0xbf, 0x48, 0x85, 0x29, 0x4d, 0xa4, 0x81, 0xfe, 0xae, 0xf7, 0x23 } } }, - { 19, { 16, { 0x78, 0x01, 0x77, 0x31, 0xcf, 0x65, 0xfa, 0xb0, 0x74, 0xd5, 0x20, 0x89, 0x52, 0x51, 0x2e, 0xb1 } } }, - { 20, { 16, { 0x9e, 0x25, 0xfc, 0x83, 0x3f, 0x22, 0x90, 0x73, 0x3e, 0x93, 0x44, 0xa5, 0xe8, 0x38, 0x39, 0xeb } } }, - { 21, { 16, { 0x56, 0x8e, 0x49, 0x5a, 0xbe, 0x52, 0x5a, 0x21, 0x8a, 0x22, 0x14, 0xcd, 0x3e, 0x07, 0x1d, 0x12 } } }, - { 22, { 16, { 0x4a, 0x29, 0xb5, 0x45, 0x52, 0xd1, 0x6b, 0x9a, 0x46, 0x9c, 0x10, 0x52, 0x8e, 0xff, 0x0a, 0xae } } }, - { 23, { 16, { 0xc9, 0xd1, 0x84, 0xdd, 0xd5, 0xa9, 0xf5, 0xe0, 0xcf, 0x8c, 0xe2, 0x9a, 0x9a, 0xbf, 0x69, 0x1c } } }, - { 24, { 16, { 0x2d, 0xb4, 0x79, 0xae, 0x78, 0xbd, 0x50, 0xd8, 0x88, 0x2a, 0x8a, 0x17, 0x8a, 0x61, 0x32, 0xad } } }, - { 25, { 16, { 0x8e, 0xce, 0x5f, 0x04, 0x2d, 0x5e, 0x44, 0x7b, 0x50, 0x51, 0xb9, 0xea, 0xcb, 0x8d, 0x8f, 0x6f } } }, - { 26, { 16, { 0x9c, 0x0b, 0x53, 0xb4, 0xb3, 0xc3, 0x07, 0xe8, 0x7e, 0xae, 0xe0, 0x86, 0x78, 0x14, 0x1f, 0x66 } } }, - { 27, { 16, { 0xab, 0xf2, 0x48, 0xaf, 0x69, 0xa6, 0xea, 0xe4, 0xbf, 0xd3, 0xeb, 0x2f, 0x12, 0x9e, 0xeb, 0x94 } } }, - { 28, { 16, { 0x06, 0x64, 0xda, 0x16, 0x68, 0x57, 0x4b, 0x88, 0xb9, 0x35, 0xf3, 0x02, 0x73, 0x58, 0xae, 0xf4 } } }, - { 29, { 16, { 0xaa, 0x4b, 0x9d, 0xc4, 0xbf, 0x33, 0x7d, 0xe9, 0x0c, 0xd4, 0xfd, 0x3c, 0x46, 0x7c, 0x6a, 0xb7 } } }, - { 30, { 16, { 0xea, 0x5c, 0x7f, 0x47, 0x1f, 0xaf, 0x6b, 0xde, 0x2b, 0x1a, 0xd7, 0xd4, 0x68, 0x6d, 0x22, 0x87 } } }, - { 31, { 16, { 0x29, 0x39, 0xb0, 0x18, 0x32, 0x23, 0xfa, 0xfc, 0x17, 0x23, 0xde, 0x4f, 0x52, 0xc4, 0x3d, 0x35 } } }, - { 32, { 16, { 0x7c, 0x39, 0x56, 0xca, 0x5e, 0xea, 0xfc, 0x3e, 0x36, 0x3e, 0x9d, 0x55, 0x65, 0x46, 0xeb, 0x68 } } }, - { 33, { 16, { 0x77, 0xc6, 0x07, 0x71, 0x46, 0xf0, 0x1c, 0x32, 0xb6, 0xb6, 0x9d, 0x5f, 0x4e, 0xa9, 0xff, 0xcf } } }, - { 34, { 16, { 0x37, 0xa6, 0x98, 0x6c, 0xb8, 0x84, 0x7e, 0xdf, 0x09, 0x25, 0xf0, 0xf1, 0x30, 0x9b, 0x54, 0xde } } }, - { 35, { 16, { 0xa7, 0x05, 0xf0, 0xe6, 0x9d, 0xa9, 0xa8, 0xf9, 0x07, 0x24, 0x1a, 0x2e, 0x92, 0x3c, 0x8c, 0xc8 } } }, - { 36, { 16, { 0x3d, 0xc4, 0x7d, 0x1f, 0x29, 0xc4, 0x48, 0x46, 0x1e, 0x9e, 0x76, 0xed, 0x90, 0x4f, 0x67, 0x11 } } }, - { 37, { 16, { 0x0d, 0x62, 0xbf, 0x01, 0xe6, 0xfc, 0x0e, 0x1a, 0x0d, 0x3c, 0x47, 0x51, 0xc5, 0xd3, 0x69, 0x2b } } }, - { 38, { 16, { 0x8c, 0x03, 0x46, 0x8b, 0xca, 0x7c, 0x66, 0x9e, 0xe4, 0xfd, 0x5e, 0x08, 0x4b, 0xbe, 0xe7, 0xb5 } } }, - { 39, { 16, { 0x52, 0x8a, 0x5b, 0xb9, 0x3b, 0xaf, 0x2c, 0x9c, 0x44, 0x73, 0xcc, 0xe5, 0xd0, 0xd2, 0x2b, 0xd9 } } }, - { 40, { 16, { 0xdf, 0x6a, 0x30, 0x1e, 0x95, 0xc9, 0x5d, 0xad, 0x97, 0xae, 0x0c, 0xc8, 0xc6, 0x91, 0x3b, 0xd8 } } }, - { 41, { 16, { 0x80, 0x11, 0x89, 0x90, 0x2c, 0x85, 0x7f, 0x39, 0xe7, 0x35, 0x91, 0x28, 0x5e, 0x70, 0xb6, 0xdb } } }, - { 42, { 16, { 0xe6, 0x17, 0x34, 0x6a, 0xc9, 0xc2, 0x31, 0xbb, 0x36, 0x50, 0xae, 0x34, 0xcc, 0xca, 0x0c, 0x5b } } }, - { 43, { 16, { 0x27, 0xd9, 0x34, 0x37, 0xef, 0xb7, 0x21, 0xaa, 0x40, 0x18, 0x21, 0xdc, 0xec, 0x5a, 0xdf, 0x89 } } }, - { 44, { 16, { 0x89, 0x23, 0x7d, 0x9d, 0xed, 0x9c, 0x5e, 0x78, 0xd8, 0xb1, 0xc9, 0xb1, 0x66, 0xcc, 0x73, 0x42 } } }, - { 45, { 16, { 0x4a, 0x6d, 0x80, 0x91, 0xbf, 0x5e, 0x7d, 0x65, 0x11, 0x89, 0xfa, 0x94, 0xa2, 0x50, 0xb1, 0x4c } } }, - { 46, { 16, { 0x0e, 0x33, 0xf9, 0x60, 0x55, 0xe7, 0xae, 0x89, 0x3f, 0xfc, 0x0e, 0x3d, 0xcf, 0x49, 0x29, 0x02 } } }, - { 47, { 16, { 0xe6, 0x1c, 0x43, 0x2b, 0x72, 0x0b, 0x19, 0xd1, 0x8e, 0xc8, 0xd8, 0x4b, 0xdc, 0x63, 0x15, 0x1b } } }, - { 48, { 16, { 0xf7, 0xe5, 0xae, 0xf5, 0x49, 0xf7, 0x82, 0xcf, 0x37, 0x90, 0x55, 0xa6, 0x08, 0x26, 0x9b, 0x16 } } }, - { 49, { 16, { 0x43, 0x8d, 0x03, 0x0f, 0xd0, 0xb7, 0xa5, 0x4f, 0xa8, 0x37, 0xf2, 0xad, 0x20, 0x1a, 0x64, 0x03 } } }, - { 50, { 16, { 0xa5, 0x90, 0xd3, 0xee, 0x4f, 0xbf, 0x04, 0xe3, 0x24, 0x7e, 0x0d, 0x27, 0xf2, 0x86, 0x42, 0x3f } } }, - { 51, { 16, { 0x5f, 0xe2, 0xc1, 0xa1, 0x72, 0xfe, 0x93, 0xc4, 0xb1, 0x5c, 0xd3, 0x7c, 0xae, 0xf9, 0xf5, 0x38 } } }, - { 52, { 16, { 0x2c, 0x97, 0x32, 0x5c, 0xbd, 0x06, 0xb3, 0x6e, 0xb2, 0x13, 0x3d, 0xd0, 0x8b, 0x3a, 0x01, 0x7c } } }, - { 53, { 16, { 0x92, 0xc8, 0x14, 0x22, 0x7a, 0x6b, 0xca, 0x94, 0x9f, 0xf0, 0x65, 0x9f, 0x00, 0x2a, 0xd3, 0x9e } } }, - { 54, { 16, { 0xdc, 0xe8, 0x50, 0x11, 0x0b, 0xd8, 0x32, 0x8c, 0xfb, 0xd5, 0x08, 0x41, 0xd6, 0x91, 0x1d, 0x87 } } }, - { 55, { 16, { 0x67, 0xf1, 0x49, 0x84, 0xc7, 0xda, 0x79, 0x12, 0x48, 0xe3, 0x2b, 0xb5, 0x92, 0x25, 0x83, 0xda } } }, - { 56, { 16, { 0x19, 0x38, 0xf2, 0xcf, 0x72, 0xd5, 0x4e, 0xe9, 0x7e, 0x94, 0x16, 0x6f, 0xa9, 0x1d, 0x2a, 0x36 } } }, - { 57, { 16, { 0x74, 0x48, 0x1e, 0x96, 0x46, 0xed, 0x49, 0xfe, 0x0f, 0x62, 0x24, 0x30, 0x16, 0x04, 0x69, 0x8e } } }, - { 58, { 16, { 0x57, 0xfc, 0xa5, 0xde, 0x98, 0xa9, 0xd6, 0xd8, 0x00, 0x64, 0x38, 0xd0, 0x58, 0x3d, 0x8a, 0x1d } } }, - { 59, { 16, { 0x9f, 0xec, 0xde, 0x1c, 0xef, 0xdc, 0x1c, 0xbe, 0xd4, 0x76, 0x36, 0x74, 0xd9, 0x57, 0x53, 0x59 } } }, - { 60, { 16, { 0xe3, 0x04, 0x0c, 0x00, 0xeb, 0x28, 0xf1, 0x53, 0x66, 0xca, 0x73, 0xcb, 0xd8, 0x72, 0xe7, 0x40 } } }, - { 61, { 16, { 0x76, 0x97, 0x00, 0x9a, 0x6a, 0x83, 0x1d, 0xfe, 0xcc, 0xa9, 0x1c, 0x59, 0x93, 0x67, 0x0f, 0x7a } } }, - { 62, { 16, { 0x58, 0x53, 0x54, 0x23, 0x21, 0xf5, 0x67, 0xa0, 0x05, 0xd5, 0x47, 0xa4, 0xf0, 0x47, 0x59, 0xbd } } }, - { 63, { 16, { 0x51, 0x50, 0xd1, 0x77, 0x2f, 0x50, 0x83, 0x4a, 0x50, 0x3e, 0x06, 0x9a, 0x97, 0x3f, 0xbd, 0x7c } } } + { 0, { 8, { + 0x31, + 0x0e, + 0x0e, + 0xdd, + 0x47, + 0xdb, + 0x6f, + 0x72, + } } }, + { 1, { 8, { + 0xfd, + 0x67, + 0xdc, + 0x93, + 0xc5, + 0x39, + 0xf8, + 0x74, + } } }, + { 2, { 8, { + 0x5a, + 0x4f, + 0xa9, + 0xd9, + 0x09, + 0x80, + 0x6c, + 0x0d, + } } }, + { 3, { 8, { + 0x2d, + 0x7e, + 0xfb, + 0xd7, + 0x96, + 0x66, + 0x67, + 0x85, + } } }, + { 4, { 8, { + 0xb7, + 0x87, + 0x71, + 0x27, + 0xe0, + 0x94, + 0x27, + 0xcf, + } } }, + { 5, { 8, { + 0x8d, + 0xa6, + 0x99, + 0xcd, + 0x64, + 0x55, + 0x76, + 0x18, + } } }, + { 6, { 8, { + 0xce, + 0xe3, + 0xfe, + 0x58, + 0x6e, + 0x46, + 0xc9, + 0xcb, + } } }, + { 7, { 8, { + 0x37, + 0xd1, + 0x01, + 0x8b, + 0xf5, + 0x00, + 0x02, + 0xab, + } } }, + { 8, { 8, { + 0x62, + 0x24, + 0x93, + 0x9a, + 0x79, + 0xf5, + 0xf5, + 0x93, + } } }, + { 9, { 8, { + 0xb0, + 0xe4, + 0xa9, + 0x0b, + 0xdf, + 0x82, + 0x00, + 0x9e, + } } }, + { 10, { 8, { + 0xf3, + 0xb9, + 0xdd, + 0x94, + 0xc5, + 0xbb, + 0x5d, + 0x7a, + } } }, + { 11, { 8, { + 0xa7, + 0xad, + 0x6b, + 0x22, + 0x46, + 0x2f, + 0xb3, + 0xf4, + } } }, + { 12, { 8, { + 0xfb, + 0xe5, + 0x0e, + 0x86, + 0xbc, + 0x8f, + 0x1e, + 0x75, + } } }, + { 13, { 8, { + 0x90, + 0x3d, + 0x84, + 0xc0, + 0x27, + 0x56, + 0xea, + 0x14, + } } }, + { 14, { 8, { + 0xee, + 0xf2, + 0x7a, + 0x8e, + 0x90, + 0xca, + 0x23, + 0xf7, + } } }, + { 15, { 8, { + 0xe5, + 0x45, + 0xbe, + 0x49, + 0x61, + 0xca, + 0x29, + 0xa1, + } } }, + { 16, { 8, { + 0xdb, + 0x9b, + 0xc2, + 0x57, + 0x7f, + 0xcc, + 0x2a, + 0x3f, + } } }, + { 17, { 8, { + 0x94, + 0x47, + 0xbe, + 0x2c, + 0xf5, + 0xe9, + 0x9a, + 0x69, + } } }, + { 18, { 8, { + 0x9c, + 0xd3, + 0x8d, + 0x96, + 0xf0, + 0xb3, + 0xc1, + 0x4b, + } } }, + { 19, { 8, { + 0xbd, + 0x61, + 0x79, + 0xa7, + 0x1d, + 0xc9, + 0x6d, + 0xbb, + } } }, + { 20, { 8, { + 0x98, + 0xee, + 0xa2, + 0x1a, + 0xf2, + 0x5c, + 0xd6, + 0xbe, + } } }, + { 21, { 8, { + 0xc7, + 0x67, + 0x3b, + 0x2e, + 0xb0, + 0xcb, + 0xf2, + 0xd0, + } } }, + { 22, { 8, { + 0x88, + 0x3e, + 0xa3, + 0xe3, + 0x95, + 0x67, + 0x53, + 0x93, + } } }, + { 23, { 8, { + 0xc8, + 0xce, + 0x5c, + 0xcd, + 0x8c, + 0x03, + 0x0c, + 0xa8, + } } }, + { 24, { 8, { + 0x94, + 0xaf, + 0x49, + 0xf6, + 0xc6, + 0x50, + 0xad, + 0xb8, + } } }, + { 25, { 8, { + 0xea, + 0xb8, + 0x85, + 0x8a, + 0xde, + 0x92, + 0xe1, + 0xbc, + } } }, + { 26, { 8, { + 0xf3, + 0x15, + 0xbb, + 0x5b, + 0xb8, + 0x35, + 0xd8, + 0x17, + } } }, + { 27, { 8, { + 0xad, + 0xcf, + 0x6b, + 0x07, + 0x63, + 0x61, + 0x2e, + 0x2f, + } } }, + { 28, { 8, { + 0xa5, + 0xc9, + 0x1d, + 0xa7, + 0xac, + 0xaa, + 0x4d, + 0xde, + } } }, + { 29, { 8, { + 0x71, + 0x65, + 0x95, + 0x87, + 0x66, + 0x50, + 0xa2, + 0xa6, + } } }, + { 30, { 8, { + 0x28, + 0xef, + 0x49, + 0x5c, + 0x53, + 0xa3, + 0x87, + 0xad, + } } }, + { 31, { 8, { + 0x42, + 0xc3, + 0x41, + 0xd8, + 0xfa, + 0x92, + 0xd8, + 0x32, + } } }, + { 32, { 8, { + 0xce, + 0x7c, + 0xf2, + 0x72, + 0x2f, + 0x51, + 0x27, + 0x71, + } } }, + { 33, { 8, { + 0xe3, + 0x78, + 0x59, + 0xf9, + 0x46, + 0x23, + 0xf3, + 0xa7, + } } }, + { 34, { 8, { + 0x38, + 0x12, + 0x05, + 0xbb, + 0x1a, + 0xb0, + 0xe0, + 0x12, + } } }, + { 35, { 8, { + 0xae, + 0x97, + 0xa1, + 0x0f, + 0xd4, + 0x34, + 0xe0, + 0x15, + } } }, + { 36, { 8, { + 0xb4, + 0xa3, + 0x15, + 0x08, + 0xbe, + 0xff, + 0x4d, + 0x31, + } } }, + { 37, { 8, { + 0x81, + 0x39, + 0x62, + 0x29, + 0xf0, + 0x90, + 0x79, + 0x02, + } } }, + { 38, { 8, { + 0x4d, + 0x0c, + 0xf4, + 0x9e, + 0xe5, + 0xd4, + 0xdc, + 0xca, + } } }, + { 39, { 8, { + 0x5c, + 0x73, + 0x33, + 0x6a, + 0x76, + 0xd8, + 0xbf, + 0x9a, + } } }, + { 40, { 8, { + 0xd0, + 0xa7, + 0x04, + 0x53, + 0x6b, + 0xa9, + 0x3e, + 0x0e, + } } }, + { 41, { 8, { + 0x92, + 0x59, + 0x58, + 0xfc, + 0xd6, + 0x42, + 0x0c, + 0xad, + } } }, + { 42, { 8, { + 0xa9, + 0x15, + 0xc2, + 0x9b, + 0xc8, + 0x06, + 0x73, + 0x18, + } } }, + { 43, { 8, { + 0x95, + 0x2b, + 0x79, + 0xf3, + 0xbc, + 0x0a, + 0xa6, + 0xd4, + } } }, + { 44, { 8, { + 0xf2, + 0x1d, + 0xf2, + 0xe4, + 0x1d, + 0x45, + 0x35, + 0xf9, + } } }, + { 45, { 8, { + 0x87, + 0x57, + 0x75, + 0x19, + 0x04, + 0x8f, + 0x53, + 0xa9, + } } }, + { 46, { 8, { + 0x10, + 0xa5, + 0x6c, + 0xf5, + 0xdf, + 0xcd, + 0x9a, + 0xdb, + } } }, + { 47, { 8, { + 0xeb, + 0x75, + 0x09, + 0x5c, + 0xcd, + 0x98, + 0x6c, + 0xd0, + } } }, + { 48, { 8, { + 0x51, + 0xa9, + 0xcb, + 0x9e, + 0xcb, + 0xa3, + 0x12, + 0xe6, + } } }, + { 49, { 8, { + 0x96, + 0xaf, + 0xad, + 0xfc, + 0x2c, + 0xe6, + 0x66, + 0xc7, + } } }, + { 50, { 8, { + 0x72, + 0xfe, + 0x52, + 0x97, + 0x5a, + 0x43, + 0x64, + 0xee, + } } }, + { 51, { 8, { + 0x5a, + 0x16, + 0x45, + 0xb2, + 0x76, + 0xd5, + 0x92, + 0xa1, + } } }, + { 52, { 8, { + 0xb2, + 0x74, + 0xcb, + 0x8e, + 0xbf, + 0x87, + 0x87, + 0x0a, + } } }, + { 53, { 8, { + 0x6f, + 0x9b, + 0xb4, + 0x20, + 0x3d, + 0xe7, + 0xb3, + 0x81, + } } }, + { 54, { 8, { + 0xea, + 0xec, + 0xb2, + 0xa3, + 0x0b, + 0x22, + 0xa8, + 0x7f, + } } }, + { 55, { 8, { + 0x99, + 0x24, + 0xa4, + 0x3c, + 0xc1, + 0x31, + 0x57, + 0x24, + } } }, + { 56, { 8, { + 0xbd, + 0x83, + 0x8d, + 0x3a, + 0xaf, + 0xbf, + 0x8d, + 0xb7, + } } }, + { 57, { 8, { + 0x0b, + 0x1a, + 0x2a, + 0x32, + 0x65, + 0xd5, + 0x1a, + 0xea, + } } }, + { 58, { 8, { + 0x13, + 0x50, + 0x79, + 0xa3, + 0x23, + 0x1c, + 0xe6, + 0x60, + } } }, + { 59, { 8, { + 0x93, + 0x2b, + 0x28, + 0x46, + 0xe4, + 0xd7, + 0x06, + 0x66, + } } }, + { 60, { 8, { + 0xe1, + 0x91, + 0x5f, + 0x5c, + 0xb1, + 0xec, + 0xa4, + 0x6c, + } } }, + { 61, { 8, { + 0xf3, + 0x25, + 0x96, + 0x5c, + 0xa1, + 0x6d, + 0x62, + 0x9f, + } } }, + { 62, { 8, { + 0x57, + 0x5f, + 0xf2, + 0x8e, + 0x60, + 0x38, + 0x1b, + 0xe5, + } } }, + { 63, { 8, { + 0x72, + 0x45, + 0x06, + 0xeb, + 0x4c, + 0x32, + 0x8a, + 0x95, + } } }, + { 0, { 16, { + 0xa3, + 0x81, + 0x7f, + 0x04, + 0xba, + 0x25, + 0xa8, + 0xe6, + 0x6d, + 0xf6, + 0x72, + 0x14, + 0xc7, + 0x55, + 0x02, + 0x93, + } } }, + { 1, { 16, { + 0xda, + 0x87, + 0xc1, + 0xd8, + 0x6b, + 0x99, + 0xaf, + 0x44, + 0x34, + 0x76, + 0x59, + 0x11, + 0x9b, + 0x22, + 0xfc, + 0x45, + } } }, + { 2, { 16, { + 0x81, + 0x77, + 0x22, + 0x8d, + 0xa4, + 0xa4, + 0x5d, + 0xc7, + 0xfc, + 0xa3, + 0x8b, + 0xde, + 0xf6, + 0x0a, + 0xff, + 0xe4, + } } }, + { 3, { 16, { + 0x9c, + 0x70, + 0xb6, + 0x0c, + 0x52, + 0x67, + 0xa9, + 0x4e, + 0x5f, + 0x33, + 0xb6, + 0xb0, + 0x29, + 0x85, + 0xed, + 0x51, + } } }, + { 4, { 16, { + 0xf8, + 0x81, + 0x64, + 0xc1, + 0x2d, + 0x9c, + 0x8f, + 0xaf, + 0x7d, + 0x0f, + 0x6e, + 0x7c, + 0x7b, + 0xcd, + 0x55, + 0x79, + } } }, + { 5, { 16, { + 0x13, + 0x68, + 0x87, + 0x59, + 0x80, + 0x77, + 0x6f, + 0x88, + 0x54, + 0x52, + 0x7a, + 0x07, + 0x69, + 0x0e, + 0x96, + 0x27, + } } }, + { 6, { 16, { + 0x14, + 0xee, + 0xca, + 0x33, + 0x8b, + 0x20, + 0x86, + 0x13, + 0x48, + 0x5e, + 0xa0, + 0x30, + 0x8f, + 0xd7, + 0xa1, + 0x5e, + } } }, + { 7, { 16, { + 0xa1, + 0xf1, + 0xeb, + 0xbe, + 0xd8, + 0xdb, + 0xc1, + 0x53, + 0xc0, + 0xb8, + 0x4a, + 0xa6, + 0x1f, + 0xf0, + 0x82, + 0x39, + } } }, + { 8, { 16, { + 0x3b, + 0x62, + 0xa9, + 0xba, + 0x62, + 0x58, + 0xf5, + 0x61, + 0x0f, + 0x83, + 0xe2, + 0x64, + 0xf3, + 0x14, + 0x97, + 0xb4, + } } }, + { 9, { 16, { + 0x26, + 0x44, + 0x99, + 0x06, + 0x0a, + 0xd9, + 0xba, + 0xab, + 0xc4, + 0x7f, + 0x8b, + 0x02, + 0xbb, + 0x6d, + 0x71, + 0xed, + } } }, + { 10, { 16, { + 0x00, + 0x11, + 0x0d, + 0xc3, + 0x78, + 0x14, + 0x69, + 0x56, + 0xc9, + 0x54, + 0x47, + 0xd3, + 0xf3, + 0xd0, + 0xfb, + 0xba, + } } }, + { 11, { 16, { + 0x01, + 0x51, + 0xc5, + 0x68, + 0x38, + 0x6b, + 0x66, + 0x77, + 0xa2, + 0xb4, + 0xdc, + 0x6f, + 0x81, + 0xe5, + 0xdc, + 0x18, + } } }, + { 12, { 16, { + 0xd6, + 0x26, + 0xb2, + 0x66, + 0x90, + 0x5e, + 0xf3, + 0x58, + 0x82, + 0x63, + 0x4d, + 0xf6, + 0x85, + 0x32, + 0xc1, + 0x25, + } } }, + { 13, { 16, { + 0x98, + 0x69, + 0xe2, + 0x47, + 0xe9, + 0xc0, + 0x8b, + 0x10, + 0xd0, + 0x29, + 0x93, + 0x4f, + 0xc4, + 0xb9, + 0x52, + 0xf7, + } } }, + { 14, { 16, { + 0x31, + 0xfc, + 0xef, + 0xac, + 0x66, + 0xd7, + 0xde, + 0x9c, + 0x7e, + 0xc7, + 0x48, + 0x5f, + 0xe4, + 0x49, + 0x49, + 0x02, + } } }, + { 15, { 16, { + 0x54, + 0x93, + 0xe9, + 0x99, + 0x33, + 0xb0, + 0xa8, + 0x11, + 0x7e, + 0x08, + 0xec, + 0x0f, + 0x97, + 0xcf, + 0xc3, + 0xd9, + } } }, + { 16, { 16, { + 0x6e, + 0xe2, + 0xa4, + 0xca, + 0x67, + 0xb0, + 0x54, + 0xbb, + 0xfd, + 0x33, + 0x15, + 0xbf, + 0x85, + 0x23, + 0x05, + 0x77, + } } }, + { 17, { 16, { + 0x47, + 0x3d, + 0x06, + 0xe8, + 0x73, + 0x8d, + 0xb8, + 0x98, + 0x54, + 0xc0, + 0x66, + 0xc4, + 0x7a, + 0xe4, + 0x77, + 0x40, + } } }, + { 18, { 16, { + 0xa4, + 0x26, + 0xe5, + 0xe4, + 0x23, + 0xbf, + 0x48, + 0x85, + 0x29, + 0x4d, + 0xa4, + 0x81, + 0xfe, + 0xae, + 0xf7, + 0x23, + } } }, + { 19, { 16, { + 0x78, + 0x01, + 0x77, + 0x31, + 0xcf, + 0x65, + 0xfa, + 0xb0, + 0x74, + 0xd5, + 0x20, + 0x89, + 0x52, + 0x51, + 0x2e, + 0xb1, + } } }, + { 20, { 16, { + 0x9e, + 0x25, + 0xfc, + 0x83, + 0x3f, + 0x22, + 0x90, + 0x73, + 0x3e, + 0x93, + 0x44, + 0xa5, + 0xe8, + 0x38, + 0x39, + 0xeb, + } } }, + { 21, { 16, { + 0x56, + 0x8e, + 0x49, + 0x5a, + 0xbe, + 0x52, + 0x5a, + 0x21, + 0x8a, + 0x22, + 0x14, + 0xcd, + 0x3e, + 0x07, + 0x1d, + 0x12, + } } }, + { 22, { 16, { + 0x4a, + 0x29, + 0xb5, + 0x45, + 0x52, + 0xd1, + 0x6b, + 0x9a, + 0x46, + 0x9c, + 0x10, + 0x52, + 0x8e, + 0xff, + 0x0a, + 0xae, + } } }, + { 23, { 16, { + 0xc9, + 0xd1, + 0x84, + 0xdd, + 0xd5, + 0xa9, + 0xf5, + 0xe0, + 0xcf, + 0x8c, + 0xe2, + 0x9a, + 0x9a, + 0xbf, + 0x69, + 0x1c, + } } }, + { 24, { 16, { + 0x2d, + 0xb4, + 0x79, + 0xae, + 0x78, + 0xbd, + 0x50, + 0xd8, + 0x88, + 0x2a, + 0x8a, + 0x17, + 0x8a, + 0x61, + 0x32, + 0xad, + } } }, + { 25, { 16, { + 0x8e, + 0xce, + 0x5f, + 0x04, + 0x2d, + 0x5e, + 0x44, + 0x7b, + 0x50, + 0x51, + 0xb9, + 0xea, + 0xcb, + 0x8d, + 0x8f, + 0x6f, + } } }, + { 26, { 16, { + 0x9c, + 0x0b, + 0x53, + 0xb4, + 0xb3, + 0xc3, + 0x07, + 0xe8, + 0x7e, + 0xae, + 0xe0, + 0x86, + 0x78, + 0x14, + 0x1f, + 0x66, + } } }, + { 27, { 16, { + 0xab, + 0xf2, + 0x48, + 0xaf, + 0x69, + 0xa6, + 0xea, + 0xe4, + 0xbf, + 0xd3, + 0xeb, + 0x2f, + 0x12, + 0x9e, + 0xeb, + 0x94, + } } }, + { 28, { 16, { + 0x06, + 0x64, + 0xda, + 0x16, + 0x68, + 0x57, + 0x4b, + 0x88, + 0xb9, + 0x35, + 0xf3, + 0x02, + 0x73, + 0x58, + 0xae, + 0xf4, + } } }, + { 29, { 16, { + 0xaa, + 0x4b, + 0x9d, + 0xc4, + 0xbf, + 0x33, + 0x7d, + 0xe9, + 0x0c, + 0xd4, + 0xfd, + 0x3c, + 0x46, + 0x7c, + 0x6a, + 0xb7, + } } }, + { 30, { 16, { + 0xea, + 0x5c, + 0x7f, + 0x47, + 0x1f, + 0xaf, + 0x6b, + 0xde, + 0x2b, + 0x1a, + 0xd7, + 0xd4, + 0x68, + 0x6d, + 0x22, + 0x87, + } } }, + { 31, { 16, { + 0x29, + 0x39, + 0xb0, + 0x18, + 0x32, + 0x23, + 0xfa, + 0xfc, + 0x17, + 0x23, + 0xde, + 0x4f, + 0x52, + 0xc4, + 0x3d, + 0x35, + } } }, + { 32, { 16, { + 0x7c, + 0x39, + 0x56, + 0xca, + 0x5e, + 0xea, + 0xfc, + 0x3e, + 0x36, + 0x3e, + 0x9d, + 0x55, + 0x65, + 0x46, + 0xeb, + 0x68, + } } }, + { 33, { 16, { + 0x77, + 0xc6, + 0x07, + 0x71, + 0x46, + 0xf0, + 0x1c, + 0x32, + 0xb6, + 0xb6, + 0x9d, + 0x5f, + 0x4e, + 0xa9, + 0xff, + 0xcf, + } } }, + { 34, { 16, { + 0x37, + 0xa6, + 0x98, + 0x6c, + 0xb8, + 0x84, + 0x7e, + 0xdf, + 0x09, + 0x25, + 0xf0, + 0xf1, + 0x30, + 0x9b, + 0x54, + 0xde, + } } }, + { 35, { 16, { + 0xa7, + 0x05, + 0xf0, + 0xe6, + 0x9d, + 0xa9, + 0xa8, + 0xf9, + 0x07, + 0x24, + 0x1a, + 0x2e, + 0x92, + 0x3c, + 0x8c, + 0xc8, + } } }, + { 36, { 16, { + 0x3d, + 0xc4, + 0x7d, + 0x1f, + 0x29, + 0xc4, + 0x48, + 0x46, + 0x1e, + 0x9e, + 0x76, + 0xed, + 0x90, + 0x4f, + 0x67, + 0x11, + } } }, + { 37, { 16, { + 0x0d, + 0x62, + 0xbf, + 0x01, + 0xe6, + 0xfc, + 0x0e, + 0x1a, + 0x0d, + 0x3c, + 0x47, + 0x51, + 0xc5, + 0xd3, + 0x69, + 0x2b, + } } }, + { 38, { 16, { + 0x8c, + 0x03, + 0x46, + 0x8b, + 0xca, + 0x7c, + 0x66, + 0x9e, + 0xe4, + 0xfd, + 0x5e, + 0x08, + 0x4b, + 0xbe, + 0xe7, + 0xb5, + } } }, + { 39, { 16, { + 0x52, + 0x8a, + 0x5b, + 0xb9, + 0x3b, + 0xaf, + 0x2c, + 0x9c, + 0x44, + 0x73, + 0xcc, + 0xe5, + 0xd0, + 0xd2, + 0x2b, + 0xd9, + } } }, + { 40, { 16, { + 0xdf, + 0x6a, + 0x30, + 0x1e, + 0x95, + 0xc9, + 0x5d, + 0xad, + 0x97, + 0xae, + 0x0c, + 0xc8, + 0xc6, + 0x91, + 0x3b, + 0xd8, + } } }, + { 41, { 16, { + 0x80, + 0x11, + 0x89, + 0x90, + 0x2c, + 0x85, + 0x7f, + 0x39, + 0xe7, + 0x35, + 0x91, + 0x28, + 0x5e, + 0x70, + 0xb6, + 0xdb, + } } }, + { 42, { 16, { + 0xe6, + 0x17, + 0x34, + 0x6a, + 0xc9, + 0xc2, + 0x31, + 0xbb, + 0x36, + 0x50, + 0xae, + 0x34, + 0xcc, + 0xca, + 0x0c, + 0x5b, + } } }, + { 43, { 16, { + 0x27, + 0xd9, + 0x34, + 0x37, + 0xef, + 0xb7, + 0x21, + 0xaa, + 0x40, + 0x18, + 0x21, + 0xdc, + 0xec, + 0x5a, + 0xdf, + 0x89, + } } }, + { 44, { 16, { + 0x89, + 0x23, + 0x7d, + 0x9d, + 0xed, + 0x9c, + 0x5e, + 0x78, + 0xd8, + 0xb1, + 0xc9, + 0xb1, + 0x66, + 0xcc, + 0x73, + 0x42, + } } }, + { 45, { 16, { + 0x4a, + 0x6d, + 0x80, + 0x91, + 0xbf, + 0x5e, + 0x7d, + 0x65, + 0x11, + 0x89, + 0xfa, + 0x94, + 0xa2, + 0x50, + 0xb1, + 0x4c, + } } }, + { 46, { 16, { + 0x0e, + 0x33, + 0xf9, + 0x60, + 0x55, + 0xe7, + 0xae, + 0x89, + 0x3f, + 0xfc, + 0x0e, + 0x3d, + 0xcf, + 0x49, + 0x29, + 0x02, + } } }, + { 47, { 16, { + 0xe6, + 0x1c, + 0x43, + 0x2b, + 0x72, + 0x0b, + 0x19, + 0xd1, + 0x8e, + 0xc8, + 0xd8, + 0x4b, + 0xdc, + 0x63, + 0x15, + 0x1b, + } } }, + { 48, { 16, { + 0xf7, + 0xe5, + 0xae, + 0xf5, + 0x49, + 0xf7, + 0x82, + 0xcf, + 0x37, + 0x90, + 0x55, + 0xa6, + 0x08, + 0x26, + 0x9b, + 0x16, + } } }, + { 49, { 16, { + 0x43, + 0x8d, + 0x03, + 0x0f, + 0xd0, + 0xb7, + 0xa5, + 0x4f, + 0xa8, + 0x37, + 0xf2, + 0xad, + 0x20, + 0x1a, + 0x64, + 0x03, + } } }, + { 50, { 16, { + 0xa5, + 0x90, + 0xd3, + 0xee, + 0x4f, + 0xbf, + 0x04, + 0xe3, + 0x24, + 0x7e, + 0x0d, + 0x27, + 0xf2, + 0x86, + 0x42, + 0x3f, + } } }, + { 51, { 16, { + 0x5f, + 0xe2, + 0xc1, + 0xa1, + 0x72, + 0xfe, + 0x93, + 0xc4, + 0xb1, + 0x5c, + 0xd3, + 0x7c, + 0xae, + 0xf9, + 0xf5, + 0x38, + } } }, + { 52, { 16, { + 0x2c, + 0x97, + 0x32, + 0x5c, + 0xbd, + 0x06, + 0xb3, + 0x6e, + 0xb2, + 0x13, + 0x3d, + 0xd0, + 0x8b, + 0x3a, + 0x01, + 0x7c, + } } }, + { 53, { 16, { + 0x92, + 0xc8, + 0x14, + 0x22, + 0x7a, + 0x6b, + 0xca, + 0x94, + 0x9f, + 0xf0, + 0x65, + 0x9f, + 0x00, + 0x2a, + 0xd3, + 0x9e, + } } }, + { 54, { 16, { + 0xdc, + 0xe8, + 0x50, + 0x11, + 0x0b, + 0xd8, + 0x32, + 0x8c, + 0xfb, + 0xd5, + 0x08, + 0x41, + 0xd6, + 0x91, + 0x1d, + 0x87, + } } }, + { 55, { 16, { + 0x67, + 0xf1, + 0x49, + 0x84, + 0xc7, + 0xda, + 0x79, + 0x12, + 0x48, + 0xe3, + 0x2b, + 0xb5, + 0x92, + 0x25, + 0x83, + 0xda, + } } }, + { 56, { 16, { + 0x19, + 0x38, + 0xf2, + 0xcf, + 0x72, + 0xd5, + 0x4e, + 0xe9, + 0x7e, + 0x94, + 0x16, + 0x6f, + 0xa9, + 0x1d, + 0x2a, + 0x36, + } } }, + { 57, { 16, { + 0x74, + 0x48, + 0x1e, + 0x96, + 0x46, + 0xed, + 0x49, + 0xfe, + 0x0f, + 0x62, + 0x24, + 0x30, + 0x16, + 0x04, + 0x69, + 0x8e, + } } }, + { 58, { 16, { + 0x57, + 0xfc, + 0xa5, + 0xde, + 0x98, + 0xa9, + 0xd6, + 0xd8, + 0x00, + 0x64, + 0x38, + 0xd0, + 0x58, + 0x3d, + 0x8a, + 0x1d, + } } }, + { 59, { 16, { + 0x9f, + 0xec, + 0xde, + 0x1c, + 0xef, + 0xdc, + 0x1c, + 0xbe, + 0xd4, + 0x76, + 0x36, + 0x74, + 0xd9, + 0x57, + 0x53, + 0x59, + } } }, + { 60, { 16, { + 0xe3, + 0x04, + 0x0c, + 0x00, + 0xeb, + 0x28, + 0xf1, + 0x53, + 0x66, + 0xca, + 0x73, + 0xcb, + 0xd8, + 0x72, + 0xe7, + 0x40, + } } }, + { 61, { 16, { + 0x76, + 0x97, + 0x00, + 0x9a, + 0x6a, + 0x83, + 0x1d, + 0xfe, + 0xcc, + 0xa9, + 0x1c, + 0x59, + 0x93, + 0x67, + 0x0f, + 0x7a, + } } }, + { 62, { 16, { + 0x58, + 0x53, + 0x54, + 0x23, + 0x21, + 0xf5, + 0x67, + 0xa0, + 0x05, + 0xd5, + 0x47, + 0xa4, + 0xf0, + 0x47, + 0x59, + 0xbd, + } } }, + { 63, { 16, { + 0x51, + 0x50, + 0xd1, + 0x77, + 0x2f, + 0x50, + 0x83, + 0x4a, + 0x50, + 0x3e, + 0x06, + 0x9a, + 0x97, + 0x3f, + 0xbd, + 0x7c, + } } } }; static int test_siphash(int idx) diff --git a/test/sm2_internal_test.c b/test/sm2_internal_test.c index f9b1be0826..c0dbb66b71 100644 --- a/test/sm2_internal_test.c +++ b/test/sm2_internal_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -130,7 +130,6 @@ done: return group; } -#ifndef OPENSSL_NO_X963KDF static int test_sm2_crypt(const EC_GROUP *group, const EVP_MD *digest, const char *privkey_hex, @@ -295,11 +294,9 @@ done: return testresult; } -#endif /* OPENSSL_NO_X963KDF */ static int test_sm2_sign(const EC_GROUP *group, - const uint8_t *userid, - size_t userid_len, + const char *userid, const char *privkey_hex, const char *message, const char *k_hex, @@ -336,8 +333,8 @@ static int test_sm2_sign(const EC_GROUP *group, } start_fake_rand(k_hex); - sig = ossl_sm2_do_sign(key, EVP_sm3(), userid, - userid_len, (const uint8_t *)message, msg_len); + sig = ossl_sm2_do_sign(key, EVP_sm3(), (const uint8_t *)userid, + strlen(userid), (const uint8_t *)message, msg_len); if (!TEST_ptr(sig)) { restore_rand(); goto done; @@ -352,8 +349,8 @@ static int test_sm2_sign(const EC_GROUP *group, || !TEST_BN_eq(s, sig_s)) goto done; - ok = ossl_sm2_do_verify(key, EVP_sm3(), sig, userid, - userid_len, (const uint8_t *)message, msg_len); + ok = ossl_sm2_do_verify(key, EVP_sm3(), sig, (const uint8_t *)userid, + strlen(userid), (const uint8_t *)message, msg_len); /* We goto done whether this passes or fails */ TEST_true(ok); @@ -373,11 +370,6 @@ static int sm2_sig_test(void) { int testresult = 0; EC_GROUP *gm_group = NULL; - /* ALICE123@YAHOO.COM */ - static const uint8_t test_alice_id[] = { - 0x41, 0x4c, 0x49, 0x43, 0x45, 0x31, 0x32, 0x33, 0x40, - 0x59, 0x41, 0x48, 0x4f, 0x4f, 0x2e, 0x43, 0x4f, 0x4d - }; /* From draft-shen-sm2-ecdsa-02 */ EC_GROUP *test_group = create_EC_group("8542D69E4C044F18E8B92435BF6FF7DE457283915C45517D722EDB8B08F1DFC3", "787968B4FA32C3FD2417842E73BBFEFF2F3C848B6831D7E0EC65228B3937E498", @@ -392,7 +384,7 @@ static int sm2_sig_test(void) if (!TEST_true(test_sm2_sign( test_group, - test_alice_id, sizeof(test_alice_id), + "ALICE123@YAHOO.COM", "128B2FA8BD433C6C068C8D803DFF79792A519A55171B1B650C23661D15897263", "message digest", "006CB28D99385C175C94F94E934817663FC176D925DD72B727260DBAAE1FB2F96F" @@ -416,8 +408,8 @@ static int sm2_sig_test(void) if (!TEST_true(test_sm2_sign( gm_group, - /* Use the default ID. */ - NULL, 0, + /* the default ID specified in GM/T 0009-2012 (Sec. 10).*/ + SM2_DEFAULT_USERID, /* privkey */ "3945208F7B2144B13F36E38AC6D39F95889393692860B51A42FB81EF4DF7C5B8", /* plaintext message */ @@ -435,8 +427,8 @@ static int sm2_sig_test(void) /* Make sure we fail if we omit the public portion of the key */ if (!TEST_false(test_sm2_sign( gm_group, - /* Use the default ID. */ - NULL, 0, + /* the default ID specified in GM/T 0009-2012 (Sec. 10).*/ + SM2_DEFAULT_USERID, /* privkey */ "3945208F7B2144B13F36E38AC6D39F95889393692860B51A42FB81EF4DF7C5B8", /* plaintext message */ @@ -471,9 +463,7 @@ int setup_tests(void) if (fake_rand == NULL) return 0; -#ifndef OPENSSL_NO_X963KDF ADD_TEST(sm2_crypt_test); -#endif ADD_TEST(sm2_sig_test); #endif return 1; diff --git a/test/smime-eml/pkcs7-empty-digest-set.eml b/test/smime-eml/pkcs7-empty-digest-set.eml deleted file mode 100644 index a6db2c38ad..0000000000 --- a/test/smime-eml/pkcs7-empty-digest-set.eml +++ /dev/null @@ -1,45 +0,0 @@ -MIME-Version: 1.0 -Content-Type: multipart/signed; protocol="application/x-pkcs7-signature"; micalg="sha-256"; boundary="----E0314CC5D732C92AE2D7A3BACDCDCFCE" - -This is an S/MIME signed message - -------E0314CC5D732C92AE2D7A3BACDCDCFCE -This is the content to be signed. - -------E0314CC5D732C92AE2D7A3BACDCDCFCE -Content-Type: application/x-pkcs7-signature; name="smime.p7s" -Content-Transfer-Encoding: base64 -Content-Disposition: attachment; filename="smime.p7s" - -MIIFWgYJKoZIhvcNAQcCoIIFSzCCBUcCAQExADALBgkqhkiG9w0BBwGgggLuMIIC -6jCCAdKgAwIBAgIUL5E46FxyhsT7C3G1NS27OtR7XAowDQYJKoZIhvcNAQELBQAw -FTETMBEGA1UEAwwKUG9DIFNpZ25lcjAeFw0yNjA1MDgxMDIwNDhaFw0yNzA1MDgx -MDIwNDhaMBUxEzARBgNVBAMMClBvQyBTaWduZXIwggEiMA0GCSqGSIb3DQEBAQUA -A4IBDwAwggEKAoIBAQDSSu/gupmIlclvmTMHiqOrCqmB8NRTjAMoI//MPJrnFXYp -FjDPMk7Y/kCcHztudaIvADkowaFtOm4oMinQFhjwCNCo5K5WrrlAitnpcd5QH2nA -iVZXjjohQUJEd7n33AGqTwo5EGaCK+alAZL7tA7bdhNi/aZ33L3bUNYqoHbXiNsE -u1tj8frLfIjduOt0TMPSOrrFjjEsrL3T3tg+HmxpalDHz7E6o9zJu0wlk8bcR2Xk -mpX8RdYCu7K9m39N1F2WKa9WJh24NQLpWRfwD213jaIFK2EXy/XHePDUeiMYtVOV -oovCSmY7OqowupA7J+4dcsnRjFqgZECctHhAfk+PAgMBAAGjMjAwMB0GA1UdDgQW -BBRZlupXNYq4fny0SE76sr/CdQ2DUTAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3 -DQEBCwUAA4IBAQANOlttTWVz620JNTrPzhiR4x9+5UiF4GSqv8BRJQFj3Xh7fsUp -+3GDs9M27f4FVh3utJsjt7Sa9ZWLpBVdgjGBwGLAtPsoYMjhnUgZTUvwEk5+aXyv -zJxn4I7mMbDhlNCMHcVtGdtA+2UOEuvdGfuEilpzPsV8DzM1K3xU5bSWoo0BRFKK -srHkyEfxCFPAQOcX80ZbMO6zdcXeJjC6mQXGqy2aqeQob0vuSZJ7QHZBlRjY5YHR -wWlIqG8G3Eist16iTqdX2PQFZT1/QAEQ/LnXARTUUjUroccdci8YNASoeHDpcjRL -MBrN+QBNZVt5qLhDogwZb2ZwqKfZ8Aqg3oAkMYICPzCCAjsCAQEwLTAVMRMwEQYD -VQQDDApQb0MgU2lnbmVyAhQvkTjoXHKGxPsLcbU1Lbs61HtcCjANBglghkgBZQME -AgEFAKCB5DAYBgkqhkiG9w0BCQMxCwYJKoZIhvcNAQcBMBwGCSqGSIb3DQEJBTEP -Fw0yNjA1MDgxMDIwNDhaMC8GCSqGSIb3DQEJBDEiBCAvyoHfycLqb8UzVPizy1uA -o3h7tza3HebeiJaSnpIJHzB5BgkqhkiG9w0BCQ8xbDBqMAsGCWCGSAFlAwQBKjAL -BglghkgBZQMEARYwCwYJYIZIAWUDBAECMAoGCCqGSIb3DQMHMA4GCCqGSIb3DQMC -AgIAgDANBggqhkiG9w0DAgIBQDAHBgUrDgMCBzANBggqhkiG9w0DAgIBKDANBgkq -hkiG9w0BAQEFAASCAQBIpl7U2j4YiU1vdZHyx2dCK41ZahtTVOB4RVJcrmopgans -fICdkSTfb0dVqc13++bYn4i1b2R2os5YIkoGxdrM5aZB7KF9r1xwgrendTF4/BwP -gQq2khNtKebv9Yr0kOPynFIsgx5BHk99wrzfwidJUFuJJgQ9W0YOf7EGkbnZvPT+ -hV0aeLmJAb5jjWhbDciqUjR3O23JQhzVj4U3vo2TeN7VYmNJsX+fA4sZzIbYSei9 -ps7GZruiRcKgqgUj1l8HjIGMHqd9lccchk/BYyAGxAbgGisntvfJdPZO09wG8rHh -eS6FYkkXAKBO49WbhE9aVLJH0zgA6gTfyEvOOOS1 - -------E0314CC5D732C92AE2D7A3BACDCDCFCE-- - diff --git a/test/srptest.c b/test/srptest.c index d7620f95f9..0fceadd24b 100644 --- a/test/srptest.c +++ b/test/srptest.c @@ -149,10 +149,11 @@ static int run_srp_kat(void) /* use builtin 1024-bit params */ const SRP_gN *GN; - if (!TEST_ptr(GN = SRP_get_default_gN("1024")) - || !TEST_true(BN_hex2bn(&s, "BEB25379D1A8581EB5A727673A2441EE")) - /* Set up server's password entry */ - || !TEST_true(SRP_create_verifier_BN("alice", "password123", &s, &v, GN->N, + if (!TEST_ptr(GN = SRP_get_default_gN("1024"))) + goto err; + BN_hex2bn(&s, "BEB25379D1A8581EB5A727673A2441EE"); + /* Set up server's password entry */ + if (!TEST_true(SRP_create_verifier_BN("alice", "password123", &s, &v, GN->N, GN->g))) goto err; @@ -167,9 +168,8 @@ static int run_srp_kat(void) TEST_note(" okay"); /* Server random */ - if (!TEST_true(BN_hex2bn(&b, "E487CB59D31AC550471E81F00F6928E01DDA08E974A004F49E61F5D1" - "05284D20"))) - goto err; + BN_hex2bn(&b, "E487CB59D31AC550471E81F00F6928E01DDA08E974A004F49E61F5D1" + "05284D20"); /* Server's first message */ Bpub = SRP_Calc_B(b, GN->N, GN->g, v); @@ -187,9 +187,8 @@ static int run_srp_kat(void) TEST_note(" okay"); /* Client random */ - if (!TEST_true(BN_hex2bn(&a, "60975527035CF2AD1989806F0407210BC81EDC04E2762A56AFD529DD" - "DA2D4393"))) - goto err; + BN_hex2bn(&a, "60975527035CF2AD1989806F0407210BC81EDC04E2762A56AFD529DD" + "DA2D4393"); /* Client's response */ Apub = SRP_Calc_A(a, GN->N, GN->g); diff --git a/test/ssl-tests/02-protocol-version.cnf b/test/ssl-tests/02-protocol-version.cnf index 8fc30f9087..ef5e994277 100644 --- a/test/ssl-tests/02-protocol-version.cnf +++ b/test/ssl-tests/02-protocol-version.cnf @@ -1,6 +1,6 @@ # Generated with generate_ssl_tests.pl -num_tests = 363 +num_tests = 678 test-0 = 0-version-negotiation test-1 = 1-version-negotiation @@ -363,8 +363,323 @@ test-357 = 357-version-negotiation test-358 = 358-version-negotiation test-359 = 359-version-negotiation test-360 = 360-version-negotiation -test-361 = 361-ciphersuite-sanity-check-client -test-362 = 362-ciphersuite-sanity-check-server +test-361 = 361-version-negotiation +test-362 = 362-version-negotiation +test-363 = 363-version-negotiation +test-364 = 364-version-negotiation +test-365 = 365-version-negotiation +test-366 = 366-version-negotiation +test-367 = 367-version-negotiation +test-368 = 368-version-negotiation +test-369 = 369-version-negotiation +test-370 = 370-version-negotiation +test-371 = 371-version-negotiation +test-372 = 372-version-negotiation +test-373 = 373-version-negotiation +test-374 = 374-version-negotiation +test-375 = 375-version-negotiation +test-376 = 376-version-negotiation +test-377 = 377-version-negotiation +test-378 = 378-version-negotiation +test-379 = 379-version-negotiation +test-380 = 380-version-negotiation +test-381 = 381-version-negotiation +test-382 = 382-version-negotiation +test-383 = 383-version-negotiation +test-384 = 384-version-negotiation +test-385 = 385-version-negotiation +test-386 = 386-version-negotiation +test-387 = 387-version-negotiation +test-388 = 388-version-negotiation +test-389 = 389-version-negotiation +test-390 = 390-version-negotiation +test-391 = 391-version-negotiation +test-392 = 392-version-negotiation +test-393 = 393-version-negotiation +test-394 = 394-version-negotiation +test-395 = 395-version-negotiation +test-396 = 396-version-negotiation +test-397 = 397-version-negotiation +test-398 = 398-version-negotiation +test-399 = 399-version-negotiation +test-400 = 400-version-negotiation +test-401 = 401-version-negotiation +test-402 = 402-version-negotiation +test-403 = 403-version-negotiation +test-404 = 404-version-negotiation +test-405 = 405-version-negotiation +test-406 = 406-version-negotiation +test-407 = 407-version-negotiation +test-408 = 408-version-negotiation +test-409 = 409-version-negotiation +test-410 = 410-version-negotiation +test-411 = 411-version-negotiation +test-412 = 412-version-negotiation +test-413 = 413-version-negotiation +test-414 = 414-version-negotiation +test-415 = 415-version-negotiation +test-416 = 416-version-negotiation +test-417 = 417-version-negotiation +test-418 = 418-version-negotiation +test-419 = 419-version-negotiation +test-420 = 420-version-negotiation +test-421 = 421-version-negotiation +test-422 = 422-version-negotiation +test-423 = 423-version-negotiation +test-424 = 424-version-negotiation +test-425 = 425-version-negotiation +test-426 = 426-version-negotiation +test-427 = 427-version-negotiation +test-428 = 428-version-negotiation +test-429 = 429-version-negotiation +test-430 = 430-version-negotiation +test-431 = 431-version-negotiation +test-432 = 432-version-negotiation +test-433 = 433-version-negotiation +test-434 = 434-version-negotiation +test-435 = 435-version-negotiation +test-436 = 436-version-negotiation +test-437 = 437-version-negotiation +test-438 = 438-version-negotiation +test-439 = 439-version-negotiation +test-440 = 440-version-negotiation +test-441 = 441-version-negotiation +test-442 = 442-version-negotiation +test-443 = 443-version-negotiation +test-444 = 444-version-negotiation +test-445 = 445-version-negotiation +test-446 = 446-version-negotiation +test-447 = 447-version-negotiation +test-448 = 448-version-negotiation +test-449 = 449-version-negotiation +test-450 = 450-version-negotiation +test-451 = 451-version-negotiation +test-452 = 452-version-negotiation +test-453 = 453-version-negotiation +test-454 = 454-version-negotiation +test-455 = 455-version-negotiation +test-456 = 456-version-negotiation +test-457 = 457-version-negotiation +test-458 = 458-version-negotiation +test-459 = 459-version-negotiation +test-460 = 460-version-negotiation +test-461 = 461-version-negotiation +test-462 = 462-version-negotiation +test-463 = 463-version-negotiation +test-464 = 464-version-negotiation +test-465 = 465-version-negotiation +test-466 = 466-version-negotiation +test-467 = 467-version-negotiation +test-468 = 468-version-negotiation +test-469 = 469-version-negotiation +test-470 = 470-version-negotiation +test-471 = 471-version-negotiation +test-472 = 472-version-negotiation +test-473 = 473-version-negotiation +test-474 = 474-version-negotiation +test-475 = 475-version-negotiation +test-476 = 476-version-negotiation +test-477 = 477-version-negotiation +test-478 = 478-version-negotiation +test-479 = 479-version-negotiation +test-480 = 480-version-negotiation +test-481 = 481-version-negotiation +test-482 = 482-version-negotiation +test-483 = 483-version-negotiation +test-484 = 484-version-negotiation +test-485 = 485-version-negotiation +test-486 = 486-version-negotiation +test-487 = 487-version-negotiation +test-488 = 488-version-negotiation +test-489 = 489-version-negotiation +test-490 = 490-version-negotiation +test-491 = 491-version-negotiation +test-492 = 492-version-negotiation +test-493 = 493-version-negotiation +test-494 = 494-version-negotiation +test-495 = 495-version-negotiation +test-496 = 496-version-negotiation +test-497 = 497-version-negotiation +test-498 = 498-version-negotiation +test-499 = 499-version-negotiation +test-500 = 500-version-negotiation +test-501 = 501-version-negotiation +test-502 = 502-version-negotiation +test-503 = 503-version-negotiation +test-504 = 504-version-negotiation +test-505 = 505-version-negotiation +test-506 = 506-version-negotiation +test-507 = 507-version-negotiation +test-508 = 508-version-negotiation +test-509 = 509-version-negotiation +test-510 = 510-version-negotiation +test-511 = 511-version-negotiation +test-512 = 512-version-negotiation +test-513 = 513-version-negotiation +test-514 = 514-version-negotiation +test-515 = 515-version-negotiation +test-516 = 516-version-negotiation +test-517 = 517-version-negotiation +test-518 = 518-version-negotiation +test-519 = 519-version-negotiation +test-520 = 520-version-negotiation +test-521 = 521-version-negotiation +test-522 = 522-version-negotiation +test-523 = 523-version-negotiation +test-524 = 524-version-negotiation +test-525 = 525-version-negotiation +test-526 = 526-version-negotiation +test-527 = 527-version-negotiation +test-528 = 528-version-negotiation +test-529 = 529-version-negotiation +test-530 = 530-version-negotiation +test-531 = 531-version-negotiation +test-532 = 532-version-negotiation +test-533 = 533-version-negotiation +test-534 = 534-version-negotiation +test-535 = 535-version-negotiation +test-536 = 536-version-negotiation +test-537 = 537-version-negotiation +test-538 = 538-version-negotiation +test-539 = 539-version-negotiation +test-540 = 540-version-negotiation +test-541 = 541-version-negotiation +test-542 = 542-version-negotiation +test-543 = 543-version-negotiation +test-544 = 544-version-negotiation +test-545 = 545-version-negotiation +test-546 = 546-version-negotiation +test-547 = 547-version-negotiation +test-548 = 548-version-negotiation +test-549 = 549-version-negotiation +test-550 = 550-version-negotiation +test-551 = 551-version-negotiation +test-552 = 552-version-negotiation +test-553 = 553-version-negotiation +test-554 = 554-version-negotiation +test-555 = 555-version-negotiation +test-556 = 556-version-negotiation +test-557 = 557-version-negotiation +test-558 = 558-version-negotiation +test-559 = 559-version-negotiation +test-560 = 560-version-negotiation +test-561 = 561-version-negotiation +test-562 = 562-version-negotiation +test-563 = 563-version-negotiation +test-564 = 564-version-negotiation +test-565 = 565-version-negotiation +test-566 = 566-version-negotiation +test-567 = 567-version-negotiation +test-568 = 568-version-negotiation +test-569 = 569-version-negotiation +test-570 = 570-version-negotiation +test-571 = 571-version-negotiation +test-572 = 572-version-negotiation +test-573 = 573-version-negotiation +test-574 = 574-version-negotiation +test-575 = 575-version-negotiation +test-576 = 576-version-negotiation +test-577 = 577-version-negotiation +test-578 = 578-version-negotiation +test-579 = 579-version-negotiation +test-580 = 580-version-negotiation +test-581 = 581-version-negotiation +test-582 = 582-version-negotiation +test-583 = 583-version-negotiation +test-584 = 584-version-negotiation +test-585 = 585-version-negotiation +test-586 = 586-version-negotiation +test-587 = 587-version-negotiation +test-588 = 588-version-negotiation +test-589 = 589-version-negotiation +test-590 = 590-version-negotiation +test-591 = 591-version-negotiation +test-592 = 592-version-negotiation +test-593 = 593-version-negotiation +test-594 = 594-version-negotiation +test-595 = 595-version-negotiation +test-596 = 596-version-negotiation +test-597 = 597-version-negotiation +test-598 = 598-version-negotiation +test-599 = 599-version-negotiation +test-600 = 600-version-negotiation +test-601 = 601-version-negotiation +test-602 = 602-version-negotiation +test-603 = 603-version-negotiation +test-604 = 604-version-negotiation +test-605 = 605-version-negotiation +test-606 = 606-version-negotiation +test-607 = 607-version-negotiation +test-608 = 608-version-negotiation +test-609 = 609-version-negotiation +test-610 = 610-version-negotiation +test-611 = 611-version-negotiation +test-612 = 612-version-negotiation +test-613 = 613-version-negotiation +test-614 = 614-version-negotiation +test-615 = 615-version-negotiation +test-616 = 616-version-negotiation +test-617 = 617-version-negotiation +test-618 = 618-version-negotiation +test-619 = 619-version-negotiation +test-620 = 620-version-negotiation +test-621 = 621-version-negotiation +test-622 = 622-version-negotiation +test-623 = 623-version-negotiation +test-624 = 624-version-negotiation +test-625 = 625-version-negotiation +test-626 = 626-version-negotiation +test-627 = 627-version-negotiation +test-628 = 628-version-negotiation +test-629 = 629-version-negotiation +test-630 = 630-version-negotiation +test-631 = 631-version-negotiation +test-632 = 632-version-negotiation +test-633 = 633-version-negotiation +test-634 = 634-version-negotiation +test-635 = 635-version-negotiation +test-636 = 636-version-negotiation +test-637 = 637-version-negotiation +test-638 = 638-version-negotiation +test-639 = 639-version-negotiation +test-640 = 640-version-negotiation +test-641 = 641-version-negotiation +test-642 = 642-version-negotiation +test-643 = 643-version-negotiation +test-644 = 644-version-negotiation +test-645 = 645-version-negotiation +test-646 = 646-version-negotiation +test-647 = 647-version-negotiation +test-648 = 648-version-negotiation +test-649 = 649-version-negotiation +test-650 = 650-version-negotiation +test-651 = 651-version-negotiation +test-652 = 652-version-negotiation +test-653 = 653-version-negotiation +test-654 = 654-version-negotiation +test-655 = 655-version-negotiation +test-656 = 656-version-negotiation +test-657 = 657-version-negotiation +test-658 = 658-version-negotiation +test-659 = 659-version-negotiation +test-660 = 660-version-negotiation +test-661 = 661-version-negotiation +test-662 = 662-version-negotiation +test-663 = 663-version-negotiation +test-664 = 664-version-negotiation +test-665 = 665-version-negotiation +test-666 = 666-version-negotiation +test-667 = 667-version-negotiation +test-668 = 668-version-negotiation +test-669 = 669-version-negotiation +test-670 = 670-version-negotiation +test-671 = 671-version-negotiation +test-672 = 672-version-negotiation +test-673 = 673-version-negotiation +test-674 = 674-version-negotiation +test-675 = 675-version-negotiation +test-676 = 676-ciphersuite-sanity-check-client +test-677 = 677-ciphersuite-sanity-check-server # =========================================================== [0-version-negotiation] @@ -377,18 +692,17 @@ client = 0-version-negotiation-client [0-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [0-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-0] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -403,18 +717,17 @@ client = 1-version-negotiation-client [1-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [1-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-1] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -429,18 +742,17 @@ client = 2-version-negotiation-client [2-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [2-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-2] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -455,18 +767,17 @@ client = 3-version-negotiation-client [3-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [3-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-3] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -481,17 +792,17 @@ client = 4-version-negotiation-client [4-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [4-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-4] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -506,19 +817,16 @@ client = 5-version-negotiation-client [5-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [5-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-5] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -533,19 +841,18 @@ client = 6-version-negotiation-client [6-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [6-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-6] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -560,19 +867,18 @@ client = 7-version-negotiation-client [7-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [7-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-7] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -587,19 +893,18 @@ client = 8-version-negotiation-client [8-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [8-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-8] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -614,18 +919,18 @@ client = 9-version-negotiation-client [9-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [9-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-9] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -640,18 +945,18 @@ client = 10-version-negotiation-client [10-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [10-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-10] -ExpectedResult = ServerFail +ExpectedResult = ClientFail # =========================================================== @@ -666,18 +971,17 @@ client = 11-version-negotiation-client [11-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [11-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-11] -ExpectedResult = ServerFail +ExpectedResult = ClientFail # =========================================================== @@ -692,18 +996,18 @@ client = 12-version-negotiation-client [12-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [12-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-12] -ExpectedResult = ServerFail +ExpectedResult = ClientFail # =========================================================== @@ -718,17 +1022,18 @@ client = 13-version-negotiation-client [13-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [13-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-13] -ExpectedResult = ServerFail +ExpectedResult = ClientFail # =========================================================== @@ -744,17 +1049,17 @@ client = 14-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [14-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-14] -ExpectedResult = ServerFail +ExpectedResult = ClientFail # =========================================================== @@ -770,17 +1075,17 @@ client = 15-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [15-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-15] -ExpectedResult = ServerFail +ExpectedResult = ClientFail # =========================================================== @@ -795,17 +1100,17 @@ client = 16-version-negotiation-client [16-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [16-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-16] -ExpectedResult = ServerFail +ExpectedResult = ClientFail # =========================================================== @@ -820,18 +1125,18 @@ client = 17-version-negotiation-client [17-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [17-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-17] -ExpectedResult = ServerFail +ExpectedResult = ClientFail # =========================================================== @@ -846,17 +1151,18 @@ client = 18-version-negotiation-client [18-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [18-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-18] -ExpectedResult = ServerFail +ExpectedResult = ClientFail # =========================================================== @@ -871,18 +1177,18 @@ client = 19-version-negotiation-client [19-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [19-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-19] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -897,18 +1203,17 @@ client = 20-version-negotiation-client [20-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [20-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-20] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -924,17 +1229,17 @@ client = 21-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [21-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-21] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -950,17 +1255,17 @@ client = 22-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [22-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-22] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -975,17 +1280,17 @@ client = 23-version-negotiation-client [23-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [23-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-23] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -1000,19 +1305,18 @@ client = 24-version-negotiation-client [24-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [24-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-24] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -1027,19 +1331,17 @@ client = 25-version-negotiation-client [25-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [25-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-25] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -1054,19 +1356,17 @@ client = 26-version-negotiation-client [26-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [26-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-26] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -1081,18 +1381,17 @@ client = 27-version-negotiation-client [27-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [27-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-27] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -1108,17 +1407,17 @@ client = 28-version-negotiation-client [28-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [28-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-28] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -1134,18 +1433,17 @@ client = 29-version-negotiation-client [29-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [29-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-29] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -1161,18 +1459,17 @@ client = 30-version-negotiation-client [30-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [30-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-30] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -1188,18 +1485,16 @@ client = 31-version-negotiation-client [31-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [31-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-31] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -1215,18 +1510,18 @@ client = 32-version-negotiation-client [32-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [32-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-32] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -1241,18 +1536,19 @@ client = 33-version-negotiation-client [33-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [33-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-33] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -1267,18 +1563,19 @@ client = 34-version-negotiation-client [34-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [34-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-34] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -1293,17 +1590,19 @@ client = 35-version-negotiation-client [35-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [35-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-35] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -1319,17 +1618,18 @@ client = 36-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [36-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-36] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -1344,17 +1644,18 @@ client = 37-version-negotiation-client [37-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [37-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-37] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -1370,11 +1671,12 @@ client = 38-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [38-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -1396,16 +1698,17 @@ client = 39-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [39-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-39] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -1422,16 +1725,17 @@ client = 40-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [40-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-40] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -1448,16 +1752,17 @@ client = 41-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [41-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-41] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -1473,16 +1778,17 @@ client = 42-version-negotiation-client [42-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [42-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-42] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -1498,19 +1804,18 @@ client = 43-version-negotiation-client [43-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [43-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-43] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -1525,19 +1830,18 @@ client = 44-version-negotiation-client [44-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [44-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-44] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -1552,19 +1856,18 @@ client = 45-version-negotiation-client [45-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [45-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-45] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -1579,19 +1882,17 @@ client = 46-version-negotiation-client [46-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [46-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-46] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -1606,18 +1907,18 @@ client = 47-version-negotiation-client [47-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [47-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-47] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -1632,19 +1933,18 @@ client = 48-version-negotiation-client [48-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [48-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-48] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -1659,19 +1959,17 @@ client = 49-version-negotiation-client [49-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [49-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-49] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -1687,18 +1985,17 @@ client = 50-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [50-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-50] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -1713,18 +2010,17 @@ client = 51-version-negotiation-client [51-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [51-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-51] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -1739,19 +2035,17 @@ client = 52-version-negotiation-client [52-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [52-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-52] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -1766,18 +2060,17 @@ client = 53-version-negotiation-client [53-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [53-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-53] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -1793,17 +2086,17 @@ client = 54-version-negotiation-client [54-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [54-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-54] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -1819,18 +2112,18 @@ client = 55-version-negotiation-client [55-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [55-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-55] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -1845,17 +2138,18 @@ client = 56-version-negotiation-client [56-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [56-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-56] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -1870,17 +2164,16 @@ client = 57-version-negotiation-client [57-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [57-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-57] -ExpectedProtocol = TLSv1 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -1896,18 +2189,18 @@ client = 58-version-negotiation-client [58-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [58-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-58] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -1922,17 +2215,18 @@ client = 59-version-negotiation-client [59-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [59-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-59] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -1948,17 +2242,18 @@ client = 60-version-negotiation-client [60-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [60-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-60] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -1974,16 +2269,18 @@ client = 61-version-negotiation-client [61-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [61-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-61] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -1999,18 +2296,18 @@ client = 62-version-negotiation-client [62-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [62-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-62] -ExpectedProtocol = TLSv1 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -2026,13 +2323,12 @@ client = 63-version-negotiation-client [63-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [63-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2053,18 +2349,18 @@ client = 64-version-negotiation-client [64-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [64-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-64] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -2080,18 +2376,18 @@ client = 65-version-negotiation-client [65-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [65-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-65] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -2107,17 +2403,18 @@ client = 66-version-negotiation-client [66-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [66-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-66] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -2133,13 +2430,13 @@ client = 67-version-negotiation-client [67-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [67-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2160,18 +2457,17 @@ client = 68-version-negotiation-client [68-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [68-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-68] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -2187,18 +2483,18 @@ client = 69-version-negotiation-client [69-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [69-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-69] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -2214,17 +2510,18 @@ client = 70-version-negotiation-client [70-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [70-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-70] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -2240,18 +2537,18 @@ client = 71-version-negotiation-client [71-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [71-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-71] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -2267,18 +2564,17 @@ client = 72-version-negotiation-client [72-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [72-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-72] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -2294,18 +2590,18 @@ client = 73-version-negotiation-client [73-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [73-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-73] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -2321,18 +2617,17 @@ client = 74-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [74-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-74] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -2347,18 +2642,17 @@ client = 75-version-negotiation-client [75-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [75-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-75] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -2373,17 +2667,18 @@ client = 76-version-negotiation-client [76-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [76-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-76] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -2398,17 +2693,17 @@ client = 77-version-negotiation-client [77-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [77-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-77] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -2423,17 +2718,17 @@ client = 78-version-negotiation-client [78-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [78-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-78] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -2448,16 +2743,17 @@ client = 79-version-negotiation-client [79-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [79-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-79] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -2473,15 +2769,17 @@ client = 80-version-negotiation-client [80-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [80-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-80] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -2497,17 +2795,17 @@ client = 81-version-negotiation-client [81-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [81-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-81] -ExpectedProtocol = TLSv1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -2523,17 +2821,17 @@ client = 82-version-negotiation-client [82-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [82-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-82] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -2549,12 +2847,11 @@ client = 83-version-negotiation-client [83-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [83-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2575,18 +2872,18 @@ client = 84-version-negotiation-client [84-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [84-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-84] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -2601,16 +2898,18 @@ client = 85-version-negotiation-client [85-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [85-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-85] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -2627,11 +2926,12 @@ client = 86-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [86-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2653,11 +2953,12 @@ client = 87-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [87-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2679,16 +2980,17 @@ client = 88-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [88-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-88] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -2704,16 +3006,17 @@ client = 89-version-negotiation-client [89-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [89-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-89] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -2729,17 +3032,18 @@ client = 90-version-negotiation-client [90-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [90-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-90] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -2755,17 +3059,18 @@ client = 91-version-negotiation-client [91-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [91-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-91] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -2781,16 +3086,18 @@ client = 92-version-negotiation-client [92-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [92-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-92] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -2807,16 +3114,17 @@ client = 93-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [93-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-93] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -2832,16 +3140,17 @@ client = 94-version-negotiation-client [94-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [94-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-94] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -2857,18 +3166,18 @@ client = 95-version-negotiation-client [95-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [95-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-95] -ExpectedProtocol = TLSv1 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -2884,18 +3193,18 @@ client = 96-version-negotiation-client [96-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [96-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-96] -ExpectedProtocol = TLSv1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -2911,18 +3220,18 @@ client = 97-version-negotiation-client [97-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [97-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-97] -ExpectedProtocol = TLSv1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -2938,18 +3247,17 @@ client = 98-version-negotiation-client [98-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [98-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-98] -ExpectedProtocol = TLSv1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -2965,17 +3273,18 @@ client = 99-version-negotiation-client [99-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [99-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-99] -ExpectedProtocol = TLSv1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -2991,19 +3300,18 @@ client = 100-version-negotiation-client [100-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [100-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-100] -ExpectedProtocol = TLSv1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -3019,19 +3327,17 @@ client = 101-version-negotiation-client [101-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [101-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-101] -ExpectedProtocol = TLSv1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -3047,20 +3353,18 @@ client = 102-version-negotiation-client [102-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [102-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-102] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -3075,20 +3379,17 @@ client = 103-version-negotiation-client [103-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [103-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-103] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -3103,19 +3404,17 @@ client = 104-version-negotiation-client [104-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [104-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-104] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -3130,19 +3429,18 @@ client = 105-version-negotiation-client [105-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [105-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-105] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -3157,19 +3455,18 @@ client = 106-version-negotiation-client [106-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [106-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-106] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -3184,19 +3481,18 @@ client = 107-version-negotiation-client [107-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [107-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-107] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success # =========================================================== @@ -3211,18 +3507,18 @@ client = 108-version-negotiation-client [108-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [108-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-108] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success # =========================================================== @@ -3237,19 +3533,17 @@ client = 109-version-negotiation-client [109-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [109-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-109] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success # =========================================================== @@ -3264,14 +3558,13 @@ client = 110-version-negotiation-client [110-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [110-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -3291,18 +3584,19 @@ client = 111-version-negotiation-client [111-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [111-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-111] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -3317,19 +3611,19 @@ client = 112-version-negotiation-client [112-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [112-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-112] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -3344,18 +3638,19 @@ client = 113-version-negotiation-client [113-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [113-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-113] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success # =========================================================== @@ -3370,18 +3665,18 @@ client = 114-version-negotiation-client [114-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [114-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-114] -ExpectedProtocol = TLSv1 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -3397,18 +3692,17 @@ client = 115-version-negotiation-client [115-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [115-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-115] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -3424,18 +3718,18 @@ client = 116-version-negotiation-client [116-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [116-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-116] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -3451,13 +3745,13 @@ client = 117-version-negotiation-client [117-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [117-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -3478,17 +3772,18 @@ client = 118-version-negotiation-client [118-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [118-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-118] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -3504,19 +3799,18 @@ client = 119-version-negotiation-client [119-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = TLSv1.3 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [119-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-119] -ExpectedProtocol = TLSv1 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -3532,19 +3826,17 @@ client = 120-version-negotiation-client [120-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [120-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-120] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -3560,14 +3852,13 @@ client = 121-version-negotiation-client [121-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [121-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -3588,19 +3879,18 @@ client = 122-version-negotiation-client [122-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [122-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-122] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -3616,18 +3906,18 @@ client = 123-version-negotiation-client [123-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [123-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-123] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -3643,19 +3933,17 @@ client = 124-version-negotiation-client [124-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [124-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-124] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -3672,18 +3960,17 @@ client = 125-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [125-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-125] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -3700,18 +3987,17 @@ client = 126-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [126-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-126] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -3727,18 +4013,17 @@ client = 127-version-negotiation-client [127-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [127-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-127] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -3754,19 +4039,19 @@ client = 128-version-negotiation-client [128-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [128-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-128] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success # =========================================================== @@ -3781,19 +4066,18 @@ client = 129-version-negotiation-client [129-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [129-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-129] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success # =========================================================== @@ -3808,13 +4092,11 @@ client = 130-version-negotiation-client [130-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [130-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -3834,19 +4116,17 @@ client = 131-version-negotiation-client [131-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [131-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-131] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -3861,18 +4141,17 @@ client = 132-version-negotiation-client [132-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [132-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-132] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -3887,18 +4166,16 @@ client = 133-version-negotiation-client [133-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [133-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-133] -ExpectedProtocol = TLSv1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -3914,18 +4191,16 @@ client = 134-version-negotiation-client [134-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [134-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-134] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -3941,18 +4216,15 @@ client = 135-version-negotiation-client [135-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [135-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-135] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -3968,19 +4240,17 @@ client = 136-version-negotiation-client [136-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [136-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-136] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -3995,17 +4265,17 @@ client = 137-version-negotiation-client [137-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [137-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-137] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -4021,19 +4291,17 @@ client = 138-version-negotiation-client [138-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [138-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-138] -ExpectedProtocol = TLSv1 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -4049,19 +4317,17 @@ client = 139-version-negotiation-client [139-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [139-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-139] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -4077,19 +4343,17 @@ client = 140-version-negotiation-client [140-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [140-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-140] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -4105,19 +4369,16 @@ client = 141-version-negotiation-client [141-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [141-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-141] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -4133,18 +4394,17 @@ client = 142-version-negotiation-client [142-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [142-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-142] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -4161,13 +4421,11 @@ client = 143-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [143-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -4189,13 +4447,11 @@ client = 144-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [144-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -4217,18 +4473,16 @@ client = 145-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [145-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-145] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -4244,18 +4498,16 @@ client = 146-version-negotiation-client [146-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [146-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-146] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -4271,19 +4523,17 @@ client = 147-version-negotiation-client [147-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [147-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-147] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -4299,14 +4549,12 @@ client = 148-version-negotiation-client [148-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [148-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -4327,18 +4575,17 @@ client = 149-version-negotiation-client [149-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [149-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-149] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -4354,19 +4601,17 @@ client = 150-version-negotiation-client [150-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [150-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-150] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success # =========================================================== @@ -4381,18 +4626,18 @@ client = 151-version-negotiation-client [151-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [151-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-151] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success # =========================================================== @@ -4407,18 +4652,17 @@ client = 152-version-negotiation-client [152-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [152-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-152] -ExpectedProtocol = TLSv1 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -4434,18 +4678,16 @@ client = 153-version-negotiation-client [153-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [153-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-153] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -4461,18 +4703,17 @@ client = 154-version-negotiation-client [154-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [154-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-154] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -4488,13 +4729,11 @@ client = 155-version-negotiation-client [155-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [155-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -4515,18 +4754,18 @@ client = 156-version-negotiation-client [156-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [156-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-156] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4542,19 +4781,17 @@ client = 157-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1 -MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [157-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-157] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4570,19 +4807,17 @@ client = 158-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [158-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-158] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4598,19 +4833,17 @@ client = 159-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [159-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-159] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4626,19 +4859,17 @@ client = 160-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [160-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-160] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4653,19 +4884,17 @@ client = 161-version-negotiation-client [161-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [161-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-161] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4680,20 +4909,19 @@ client = 162-version-negotiation-client [162-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [162-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-162] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4708,20 +4936,19 @@ client = 163-version-negotiation-client [163-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [163-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-163] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4736,20 +4963,19 @@ client = 164-version-negotiation-client [164-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [164-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-164] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4764,19 +4990,19 @@ client = 165-version-negotiation-client [165-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [165-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-165] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4791,20 +5017,19 @@ client = 166-version-negotiation-client [166-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [166-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-166] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4819,20 +5044,18 @@ client = 167-version-negotiation-client [167-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [167-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-167] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4847,19 +5070,19 @@ client = 168-version-negotiation-client [168-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [168-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-168] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4874,20 +5097,19 @@ client = 169-version-negotiation-client [169-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [169-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-169] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4902,19 +5124,19 @@ client = 170-version-negotiation-client [170-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [170-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-170] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4929,18 +5151,19 @@ client = 171-version-negotiation-client [171-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [171-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-171] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4955,18 +5178,18 @@ client = 172-version-negotiation-client [172-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [172-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-172] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -4981,18 +5204,19 @@ client = 173-version-negotiation-client [173-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [173-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-173] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -5007,18 +5231,19 @@ client = 174-version-negotiation-client [174-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [174-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-174] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -5033,17 +5258,19 @@ client = 175-version-negotiation-client [175-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [175-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-175] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -5058,19 +5285,18 @@ client = 176-version-negotiation-client [176-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [176-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-176] -ExpectedProtocol = TLSv1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -5085,19 +5311,19 @@ client = 177-version-negotiation-client [177-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [177-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-177] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -5112,19 +5338,19 @@ client = 178-version-negotiation-client [178-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [178-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-178] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -5139,19 +5365,18 @@ client = 179-version-negotiation-client [179-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [179-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-179] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -5166,18 +5391,19 @@ client = 180-version-negotiation-client [180-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [180-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-180] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -5192,19 +5418,18 @@ client = 181-version-negotiation-client [181-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [181-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-181] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ClientFail # =========================================================== @@ -5219,19 +5444,18 @@ client = 182-version-negotiation-client [182-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [182-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-182] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -5246,18 +5470,18 @@ client = 183-version-negotiation-client [183-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [183-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-183] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -5273,17 +5497,18 @@ client = 184-version-negotiation-client [184-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [184-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-184] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -5300,17 +5525,17 @@ client = 185-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [185-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-185] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -5327,17 +5552,17 @@ client = 186-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [186-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-186] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -5353,17 +5578,17 @@ client = 187-version-negotiation-client [187-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [187-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-187] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -5379,19 +5604,19 @@ client = 188-version-negotiation-client [188-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [188-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-188] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -5406,17 +5631,19 @@ client = 189-version-negotiation-client [189-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [189-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-189] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -5432,18 +5659,20 @@ client = 190-version-negotiation-client [190-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [190-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-190] -ExpectedResult = ClientFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -5458,18 +5687,19 @@ client = 191-version-negotiation-client [191-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [191-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-191] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -5485,18 +5715,19 @@ client = 192-version-negotiation-client [192-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [192-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-192] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -5512,18 +5743,18 @@ client = 193-version-negotiation-client [193-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [193-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-193] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -5539,17 +5770,19 @@ client = 194-version-negotiation-client [194-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [194-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-194] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -5565,19 +5798,20 @@ client = 195-version-negotiation-client [195-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = TLSv1.1 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [195-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-195] -ExpectedResult = ClientFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -5592,19 +5826,19 @@ client = 196-version-negotiation-client [196-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [196-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-196] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -5620,19 +5854,19 @@ client = 197-version-negotiation-client [197-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [197-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-197] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -5648,19 +5882,18 @@ client = 198-version-negotiation-client [198-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [198-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-198] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -5676,19 +5909,19 @@ client = 199-version-negotiation-client [199-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [199-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-199] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -5703,20 +5936,19 @@ client = 200-version-negotiation-client [200-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [200-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-200] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -5731,20 +5963,19 @@ client = 201-version-negotiation-client [201-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [201-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-201] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -5759,20 +5990,18 @@ client = 202-version-negotiation-client [202-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [202-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-202] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -5787,19 +6016,19 @@ client = 203-version-negotiation-client [203-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [203-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-203] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -5814,14 +6043,14 @@ client = 204-version-negotiation-client [204-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [204-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -5841,14 +6070,13 @@ client = 205-version-negotiation-client [205-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [205-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -5868,13 +6096,14 @@ client = 206-version-negotiation-client [206-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [206-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -5894,14 +6123,13 @@ client = 207-version-negotiation-client [207-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [207-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -5921,13 +6149,13 @@ client = 208-version-negotiation-client [208-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [208-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -5952,13 +6180,14 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [209-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-209] -ExpectedResult = ClientFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -5978,8 +6207,8 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [210-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -6005,13 +6234,13 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [211-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-211] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -6032,13 +6261,13 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [212-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-212] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -6058,13 +6287,13 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [213-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-213] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -6080,19 +6309,19 @@ client = 214-version-negotiation-client [214-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [214-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-214] -ExpectedResult = ClientFail +ExpectedResult = ServerFail # =========================================================== @@ -6107,19 +6336,19 @@ client = 215-version-negotiation-client [215-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [215-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-215] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -6135,19 +6364,19 @@ client = 216-version-negotiation-client [216-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [216-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-216] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -6163,19 +6392,19 @@ client = 217-version-negotiation-client [217-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [217-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-217] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -6191,18 +6420,19 @@ client = 218-version-negotiation-client [218-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [218-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-218] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -6218,14 +6448,13 @@ client = 219-version-negotiation-client [219-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [219-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -6246,19 +6475,19 @@ client = 220-version-negotiation-client [220-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [220-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-220] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -6274,19 +6503,19 @@ client = 221-version-negotiation-client [221-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [221-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-221] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -6302,18 +6531,19 @@ client = 222-version-negotiation-client [222-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [222-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-222] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -6329,19 +6559,19 @@ client = 223-version-negotiation-client [223-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [223-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-223] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -6357,19 +6587,18 @@ client = 224-version-negotiation-client [224-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [224-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-224] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -6385,18 +6614,19 @@ client = 225-version-negotiation-client [225-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [225-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-225] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -6412,19 +6642,20 @@ client = 226-version-negotiation-client [226-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [226-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-226] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -6439,18 +6670,20 @@ client = 227-version-negotiation-client [227-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [227-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-227] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -6465,18 +6698,19 @@ client = 228-version-negotiation-client [228-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [228-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-228] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -6491,19 +6725,19 @@ client = 229-version-negotiation-client [229-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [229-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-229] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -6518,19 +6752,19 @@ client = 230-version-negotiation-client [230-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [230-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-230] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -6545,19 +6779,18 @@ client = 231-version-negotiation-client [231-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [231-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-231] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -6572,18 +6805,19 @@ client = 232-version-negotiation-client [232-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [232-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-232] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -6598,14 +6832,13 @@ client = 233-version-negotiation-client [233-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [233-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -6625,20 +6858,18 @@ client = 234-version-negotiation-client [234-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [234-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-234] -ExpectedProtocol = TLSv1.1 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -6653,19 +6884,18 @@ client = 235-version-negotiation-client [235-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 +MaxProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [235-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-235] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -6681,19 +6911,18 @@ client = 236-version-negotiation-client [236-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [236-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-236] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -6709,18 +6938,18 @@ client = 237-version-negotiation-client [237-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [237-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-237] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -6736,19 +6965,18 @@ client = 238-version-negotiation-client [238-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [238-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-238] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -6764,14 +6992,12 @@ client = 239-version-negotiation-client [239-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [239-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -6792,20 +7018,19 @@ client = 240-version-negotiation-client [240-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [240-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-240] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -6820,18 +7045,19 @@ client = 241-version-negotiation-client [241-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [241-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-241] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -6847,19 +7073,19 @@ client = 242-version-negotiation-client [242-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [242-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-242] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -6875,19 +7101,19 @@ client = 243-version-negotiation-client [243-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [243-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-243] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -6903,18 +7129,19 @@ client = 244-version-negotiation-client [244-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [244-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-244] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -6930,19 +7157,18 @@ client = 245-version-negotiation-client [245-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [245-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-245] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -6958,18 +7184,19 @@ client = 246-version-negotiation-client [246-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [246-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-246] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -6985,17 +7212,20 @@ client = 247-version-negotiation-client [247-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [247-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-247] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -7010,17 +7240,19 @@ client = 248-version-negotiation-client [248-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [248-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-248] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -7036,12 +7268,14 @@ client = 249-version-negotiation-client [249-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [249-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -7062,17 +7296,18 @@ client = 250-version-negotiation-client [250-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [250-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-250] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -7088,16 +7323,19 @@ client = 251-version-negotiation-client [251-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [251-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-251] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -7113,18 +7351,20 @@ client = 252-version-negotiation-client [252-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [252-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-252] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success # =========================================================== @@ -7139,18 +7379,19 @@ client = 253-version-negotiation-client [253-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [253-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-253] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -7166,13 +7407,13 @@ client = 254-version-negotiation-client [254-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [254-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -7193,18 +7434,19 @@ client = 255-version-negotiation-client [255-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [255-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-255] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -7220,17 +7462,19 @@ client = 256-version-negotiation-client [256-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [256-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-256] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -7246,18 +7490,18 @@ client = 257-version-negotiation-client [257-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [257-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-257] -ExpectedProtocol = TLSv1.1 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -7273,19 +7517,19 @@ client = 258-version-negotiation-client [258-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [258-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-258] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -7300,19 +7544,18 @@ client = 259-version-negotiation-client [259-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [259-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-259] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -7327,18 +7570,18 @@ client = 260-version-negotiation-client [260-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [260-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-260] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -7353,18 +7596,18 @@ client = 261-version-negotiation-client [261-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [261-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-261] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -7380,18 +7623,18 @@ client = 262-version-negotiation-client [262-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [262-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-262] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -7407,17 +7650,18 @@ client = 263-version-negotiation-client [263-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [263-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-263] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -7434,12 +7678,12 @@ client = 264-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [264-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -7460,12 +7704,12 @@ client = 265-version-negotiation-client [265-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [265-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -7486,18 +7730,19 @@ client = 266-version-negotiation-client [266-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [266-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-266] -ExpectedResult = ClientFail +ExpectedResult = ServerFail # =========================================================== @@ -7512,18 +7757,20 @@ client = 267-version-negotiation-client [267-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [267-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-267] -ExpectedResult = ClientFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -7538,18 +7785,19 @@ client = 268-version-negotiation-client [268-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [268-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-268] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -7565,13 +7813,14 @@ client = 269-version-negotiation-client [269-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [269-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -7592,17 +7841,19 @@ client = 270-version-negotiation-client [270-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [270-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-270] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -7618,19 +7869,19 @@ client = 271-version-negotiation-client [271-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [271-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-271] -ExpectedResult = ClientFail +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success # =========================================================== @@ -7645,19 +7896,20 @@ client = 272-version-negotiation-client [272-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [272-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-272] -ExpectedResult = ClientFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -7672,19 +7924,19 @@ client = 273-version-negotiation-client [273-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [273-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-273] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -7700,14 +7952,14 @@ client = 274-version-negotiation-client [274-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [274-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -7728,18 +7980,19 @@ client = 275-version-negotiation-client [275-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [275-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-275] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -7755,19 +8008,19 @@ client = 276-version-negotiation-client [276-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [276-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-276] -ExpectedResult = ClientFail +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success # =========================================================== @@ -7782,19 +8035,19 @@ client = 277-version-negotiation-client [277-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [277-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-277] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -7810,14 +8063,14 @@ client = 278-version-negotiation-client [278-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [278-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -7838,18 +8091,19 @@ client = 279-version-negotiation-client [279-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [279-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-279] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -7865,19 +8119,18 @@ client = 280-version-negotiation-client [280-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [280-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-280] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -7893,14 +8146,14 @@ client = 281-version-negotiation-client [281-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [281-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -7921,18 +8174,19 @@ client = 282-version-negotiation-client [282-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [282-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-282] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -7948,19 +8202,19 @@ client = 283-version-negotiation-client [283-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [283-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-283] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success # =========================================================== @@ -7975,18 +8229,20 @@ client = 284-version-negotiation-client [284-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [284-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-284] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success # =========================================================== @@ -8001,18 +8257,19 @@ client = 285-version-negotiation-client [285-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [285-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-285] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success # =========================================================== @@ -8027,13 +8284,12 @@ client = 286-version-negotiation-client [286-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [286-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -8053,18 +8309,17 @@ client = 287-version-negotiation-client [287-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [287-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-287] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -8080,18 +8335,17 @@ client = 288-version-negotiation-client [288-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [288-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-288] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -8107,17 +8361,17 @@ client = 289-version-negotiation-client [289-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [289-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-289] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -8133,19 +8387,18 @@ client = 290-version-negotiation-client [290-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [290-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-290] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success # =========================================================== @@ -8160,19 +8413,17 @@ client = 291-version-negotiation-client [291-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [291-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-291] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success # =========================================================== @@ -8187,20 +8438,18 @@ client = 292-version-negotiation-client [292-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [292-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-292] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -8215,19 +8464,18 @@ client = 293-version-negotiation-client [293-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [293-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-293] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -8243,18 +8491,18 @@ client = 294-version-negotiation-client [294-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [294-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-294] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -8270,19 +8518,19 @@ client = 295-version-negotiation-client [295-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [295-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-295] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success # =========================================================== @@ -8297,19 +8545,18 @@ client = 296-version-negotiation-client [296-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [296-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-296] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -8325,14 +8572,12 @@ client = 297-version-negotiation-client [297-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [297-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -8353,18 +8598,18 @@ client = 298-version-negotiation-client [298-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [298-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-298] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -8380,19 +8625,18 @@ client = 299-version-negotiation-client [299-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [299-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-299] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -8408,19 +8652,18 @@ client = 300-version-negotiation-client [300-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [300-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-300] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -8436,13 +8679,13 @@ client = 301-version-negotiation-client [301-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [301-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -8463,14 +8706,12 @@ client = 302-version-negotiation-client [302-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [302-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -8491,18 +8732,18 @@ client = 303-version-negotiation-client [303-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [303-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-303] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -8518,17 +8759,19 @@ client = 304-version-negotiation-client [304-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [304-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-304] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success # =========================================================== @@ -8543,17 +8786,19 @@ client = 305-version-negotiation-client [305-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [305-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-305] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success # =========================================================== @@ -8568,17 +8813,17 @@ client = 306-version-negotiation-client [306-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [306-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-306] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -8594,17 +8839,18 @@ client = 307-version-negotiation-client [307-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [307-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-307] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.2 ExpectedResult = Success @@ -8620,11 +8866,13 @@ client = 308-version-negotiation-client [308-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [308-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -8645,18 +8893,18 @@ client = 309-version-negotiation-client [309-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [309-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-309] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success # =========================================================== @@ -8671,18 +8919,19 @@ client = 310-version-negotiation-client [310-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [310-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-310] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success # =========================================================== @@ -8697,18 +8946,17 @@ client = 311-version-negotiation-client [311-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [311-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MinProtocol = SSLv3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-311] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -8724,19 +8972,18 @@ client = 312-version-negotiation-client [312-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MaxProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [312-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-312] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -8751,17 +8998,18 @@ client = 313-version-negotiation-client [313-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MaxProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [313-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-313] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -8778,17 +9026,18 @@ client = 314-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [314-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-314] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -8804,17 +9053,17 @@ client = 315-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [315-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-315] -ExpectedProtocol = TLSv1.2 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -8831,17 +9080,17 @@ client = 316-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [316-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-316] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -8857,17 +9106,17 @@ client = 317-version-negotiation-client [317-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [317-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-317] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -8883,19 +9132,19 @@ client = 318-version-negotiation-client [318-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [318-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-318] -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -8910,18 +9159,19 @@ client = 319-version-negotiation-client [319-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [319-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-319] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -8937,17 +9187,19 @@ client = 320-version-negotiation-client [320-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [320-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-320] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -8963,18 +9215,19 @@ client = 321-version-negotiation-client [321-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [321-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-321] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -8990,17 +9243,19 @@ client = 322-version-negotiation-client [322-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [322-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-322] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -9016,18 +9271,19 @@ client = 323-version-negotiation-client [323-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [323-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-323] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -9042,18 +9298,20 @@ client = 324-version-negotiation-client [324-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [324-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-324] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -9068,18 +9326,20 @@ client = 325-version-negotiation-client [325-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [325-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-325] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -9094,18 +9354,19 @@ client = 326-version-negotiation-client [326-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [326-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-326] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -9121,17 +9382,19 @@ client = 327-version-negotiation-client [327-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [327-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-327] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -9147,19 +9410,19 @@ client = 328-version-negotiation-client [328-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [328-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-328] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1 +ExpectedResult = Success # =========================================================== @@ -9175,13 +9438,13 @@ client = 329-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [329-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -9202,13 +9465,13 @@ client = 330-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [330-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -9229,19 +9492,18 @@ client = 331-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 -MinProtocol = TLSv1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [331-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-331] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -9256,19 +9518,18 @@ client = 332-version-negotiation-client [332-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [332-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-332] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -9283,14 +9544,14 @@ client = 333-version-negotiation-client [333-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [333-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -9310,14 +9571,14 @@ client = 334-version-negotiation-client [334-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [334-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -9337,20 +9598,18 @@ client = 335-version-negotiation-client [335-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [335-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-335] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -9365,19 +9624,19 @@ client = 336-version-negotiation-client [336-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [336-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-336] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -9392,14 +9651,13 @@ client = 337-version-negotiation-client [337-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [337-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -9419,20 +9677,18 @@ client = 338-version-negotiation-client [338-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MaxProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [338-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-338] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -9447,18 +9703,18 @@ client = 339-version-negotiation-client [339-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MaxProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [339-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-339] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -9474,19 +9730,18 @@ client = 340-version-negotiation-client [340-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [340-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-340] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -9502,18 +9757,18 @@ client = 341-version-negotiation-client [341-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [341-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-341] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -9529,17 +9784,19 @@ client = 342-version-negotiation-client [342-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 +MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [342-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-342] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -9554,17 +9811,18 @@ client = 343-version-negotiation-client [343-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [343-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-343] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -9579,12 +9837,14 @@ client = 344-version-negotiation-client [344-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [344-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -9604,17 +9864,19 @@ client = 345-version-negotiation-client [345-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [345-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-345] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -9630,16 +9892,19 @@ client = 346-version-negotiation-client [346-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [346-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-346] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -9655,18 +9920,20 @@ client = 347-version-negotiation-client [347-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [347-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-347] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -9681,18 +9948,20 @@ client = 348-version-negotiation-client [348-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [348-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-348] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -9707,18 +9976,19 @@ client = 349-version-negotiation-client [349-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1 +MinProtocol = SSLv3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [349-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-349] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -9733,18 +10003,19 @@ client = 350-version-negotiation-client [350-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 +MaxProtocol = TLSv1 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [350-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-350] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1 ExpectedResult = Success @@ -9760,17 +10031,19 @@ client = 351-version-negotiation-client [351-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [351-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-351] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -9786,18 +10059,20 @@ client = 352-version-negotiation-client [352-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [352-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-352] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -9812,18 +10087,20 @@ client = 353-version-negotiation-client [353-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.1 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [353-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-353] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -9838,18 +10115,18 @@ client = 354-version-negotiation-client [354-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.1 +MinProtocol = TLSv1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [354-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-354] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -9865,17 +10142,19 @@ client = 355-version-negotiation-client [355-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [355-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-355] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -9892,17 +10171,19 @@ client = 356-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [356-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-356] -ExpectedResult = ServerFail +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success # =========================================================== @@ -9918,17 +10199,18 @@ client = 357-version-negotiation-client Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.2 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [357-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-357] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -9944,17 +10226,18 @@ client = 358-version-negotiation-client [358-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.2 +MinProtocol = TLSv1.1 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [358-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-358] -ExpectedProtocol = TLSv1.3 +ExpectedProtocol = TLSv1.1 ExpectedResult = Success @@ -9970,19 +10253,19 @@ client = 359-version-negotiation-client [359-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [359-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-359] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== @@ -9997,63 +10280,67 @@ client = 360-version-negotiation-client [360-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem [360-version-negotiation-client] CipherString = DEFAULT:@SECLEVEL=0 -MinProtocol = TLSv1.3 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-360] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== -[361-ciphersuite-sanity-check-client] -ssl_conf = 361-ciphersuite-sanity-check-client-ssl +[361-version-negotiation] +ssl_conf = 361-version-negotiation-ssl -[361-ciphersuite-sanity-check-client-ssl] -server = 361-ciphersuite-sanity-check-client-server -client = 361-ciphersuite-sanity-check-client-client +[361-version-negotiation-ssl] +server = 361-version-negotiation-server +client = 361-version-negotiation-client -[361-ciphersuite-sanity-check-client-server] +[361-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT -MaxProtocol = TLSv1.2 +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[361-ciphersuite-sanity-check-client-client] -CipherString = AES128-SHA -Ciphersuites = +[361-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-361] -ExpectedResult = ClientFail +ExpectedResult = ServerFail # =========================================================== -[362-ciphersuite-sanity-check-server] -ssl_conf = 362-ciphersuite-sanity-check-server-ssl +[362-version-negotiation] +ssl_conf = 362-version-negotiation-ssl -[362-ciphersuite-sanity-check-server-ssl] -server = 362-ciphersuite-sanity-check-server-server -client = 362-ciphersuite-sanity-check-server-client +[362-version-negotiation-ssl] +server = 362-version-negotiation-server +client = 362-version-negotiation-client -[362-ciphersuite-sanity-check-server-server] +[362-version-negotiation-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = AES128-SHA -Ciphersuites = +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[362-ciphersuite-sanity-check-server-client] -CipherString = AES128-SHA -MaxProtocol = TLSv1.2 +[362-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -10061,3 +10348,8475 @@ VerifyMode = Peer ExpectedResult = ServerFail +# =========================================================== + +[363-version-negotiation] +ssl_conf = 363-version-negotiation-ssl + +[363-version-negotiation-ssl] +server = 363-version-negotiation-server +client = 363-version-negotiation-client + +[363-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[363-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-363] +ExpectedResult = ServerFail + + +# =========================================================== + +[364-version-negotiation] +ssl_conf = 364-version-negotiation-ssl + +[364-version-negotiation-ssl] +server = 364-version-negotiation-server +client = 364-version-negotiation-client + +[364-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[364-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-364] +ExpectedResult = ServerFail + + +# =========================================================== + +[365-version-negotiation] +ssl_conf = 365-version-negotiation-ssl + +[365-version-negotiation-ssl] +server = 365-version-negotiation-server +client = 365-version-negotiation-client + +[365-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[365-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-365] +ExpectedProtocol = TLSv1 +ExpectedResult = Success + + +# =========================================================== + +[366-version-negotiation] +ssl_conf = 366-version-negotiation-ssl + +[366-version-negotiation-ssl] +server = 366-version-negotiation-server +client = 366-version-negotiation-client + +[366-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[366-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-366] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[367-version-negotiation] +ssl_conf = 367-version-negotiation-ssl + +[367-version-negotiation-ssl] +server = 367-version-negotiation-server +client = 367-version-negotiation-client + +[367-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[367-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-367] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[368-version-negotiation] +ssl_conf = 368-version-negotiation-ssl + +[368-version-negotiation-ssl] +server = 368-version-negotiation-server +client = 368-version-negotiation-client + +[368-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[368-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-368] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[369-version-negotiation] +ssl_conf = 369-version-negotiation-ssl + +[369-version-negotiation-ssl] +server = 369-version-negotiation-server +client = 369-version-negotiation-client + +[369-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[369-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-369] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[370-version-negotiation] +ssl_conf = 370-version-negotiation-ssl + +[370-version-negotiation-ssl] +server = 370-version-negotiation-server +client = 370-version-negotiation-client + +[370-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[370-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-370] +ExpectedResult = ServerFail + + +# =========================================================== + +[371-version-negotiation] +ssl_conf = 371-version-negotiation-ssl + +[371-version-negotiation-ssl] +server = 371-version-negotiation-server +client = 371-version-negotiation-client + +[371-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[371-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-371] +ExpectedProtocol = TLSv1 +ExpectedResult = Success + + +# =========================================================== + +[372-version-negotiation] +ssl_conf = 372-version-negotiation-ssl + +[372-version-negotiation-ssl] +server = 372-version-negotiation-server +client = 372-version-negotiation-client + +[372-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[372-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-372] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[373-version-negotiation] +ssl_conf = 373-version-negotiation-ssl + +[373-version-negotiation-ssl] +server = 373-version-negotiation-server +client = 373-version-negotiation-client + +[373-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[373-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-373] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[374-version-negotiation] +ssl_conf = 374-version-negotiation-ssl + +[374-version-negotiation-ssl] +server = 374-version-negotiation-server +client = 374-version-negotiation-client + +[374-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[374-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-374] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[375-version-negotiation] +ssl_conf = 375-version-negotiation-ssl + +[375-version-negotiation-ssl] +server = 375-version-negotiation-server +client = 375-version-negotiation-client + +[375-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[375-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-375] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[376-version-negotiation] +ssl_conf = 376-version-negotiation-ssl + +[376-version-negotiation-ssl] +server = 376-version-negotiation-server +client = 376-version-negotiation-client + +[376-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[376-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-376] +ExpectedProtocol = TLSv1 +ExpectedResult = Success + + +# =========================================================== + +[377-version-negotiation] +ssl_conf = 377-version-negotiation-ssl + +[377-version-negotiation-ssl] +server = 377-version-negotiation-server +client = 377-version-negotiation-client + +[377-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[377-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-377] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[378-version-negotiation] +ssl_conf = 378-version-negotiation-ssl + +[378-version-negotiation-ssl] +server = 378-version-negotiation-server +client = 378-version-negotiation-client + +[378-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[378-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-378] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[379-version-negotiation] +ssl_conf = 379-version-negotiation-ssl + +[379-version-negotiation-ssl] +server = 379-version-negotiation-server +client = 379-version-negotiation-client + +[379-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[379-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-379] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[380-version-negotiation] +ssl_conf = 380-version-negotiation-ssl + +[380-version-negotiation-ssl] +server = 380-version-negotiation-server +client = 380-version-negotiation-client + +[380-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[380-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-380] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[381-version-negotiation] +ssl_conf = 381-version-negotiation-ssl + +[381-version-negotiation-ssl] +server = 381-version-negotiation-server +client = 381-version-negotiation-client + +[381-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[381-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-381] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[382-version-negotiation] +ssl_conf = 382-version-negotiation-ssl + +[382-version-negotiation-ssl] +server = 382-version-negotiation-server +client = 382-version-negotiation-client + +[382-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[382-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-382] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[383-version-negotiation] +ssl_conf = 383-version-negotiation-ssl + +[383-version-negotiation-ssl] +server = 383-version-negotiation-server +client = 383-version-negotiation-client + +[383-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[383-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-383] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[384-version-negotiation] +ssl_conf = 384-version-negotiation-ssl + +[384-version-negotiation-ssl] +server = 384-version-negotiation-server +client = 384-version-negotiation-client + +[384-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[384-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-384] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[385-version-negotiation] +ssl_conf = 385-version-negotiation-ssl + +[385-version-negotiation-ssl] +server = 385-version-negotiation-server +client = 385-version-negotiation-client + +[385-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[385-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-385] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[386-version-negotiation] +ssl_conf = 386-version-negotiation-ssl + +[386-version-negotiation-ssl] +server = 386-version-negotiation-server +client = 386-version-negotiation-client + +[386-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[386-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-386] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[387-version-negotiation] +ssl_conf = 387-version-negotiation-ssl + +[387-version-negotiation-ssl] +server = 387-version-negotiation-server +client = 387-version-negotiation-client + +[387-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[387-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-387] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[388-version-negotiation] +ssl_conf = 388-version-negotiation-ssl + +[388-version-negotiation-ssl] +server = 388-version-negotiation-server +client = 388-version-negotiation-client + +[388-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[388-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-388] +ExpectedResult = ServerFail + + +# =========================================================== + +[389-version-negotiation] +ssl_conf = 389-version-negotiation-ssl + +[389-version-negotiation-ssl] +server = 389-version-negotiation-server +client = 389-version-negotiation-client + +[389-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[389-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-389] +ExpectedResult = ServerFail + + +# =========================================================== + +[390-version-negotiation] +ssl_conf = 390-version-negotiation-ssl + +[390-version-negotiation-ssl] +server = 390-version-negotiation-server +client = 390-version-negotiation-client + +[390-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[390-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-390] +ExpectedResult = ServerFail + + +# =========================================================== + +[391-version-negotiation] +ssl_conf = 391-version-negotiation-ssl + +[391-version-negotiation-ssl] +server = 391-version-negotiation-server +client = 391-version-negotiation-client + +[391-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[391-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-391] +ExpectedProtocol = TLSv1 +ExpectedResult = Success + + +# =========================================================== + +[392-version-negotiation] +ssl_conf = 392-version-negotiation-ssl + +[392-version-negotiation-ssl] +server = 392-version-negotiation-server +client = 392-version-negotiation-client + +[392-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[392-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-392] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[393-version-negotiation] +ssl_conf = 393-version-negotiation-ssl + +[393-version-negotiation-ssl] +server = 393-version-negotiation-server +client = 393-version-negotiation-client + +[393-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[393-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-393] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[394-version-negotiation] +ssl_conf = 394-version-negotiation-ssl + +[394-version-negotiation-ssl] +server = 394-version-negotiation-server +client = 394-version-negotiation-client + +[394-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[394-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-394] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[395-version-negotiation] +ssl_conf = 395-version-negotiation-ssl + +[395-version-negotiation-ssl] +server = 395-version-negotiation-server +client = 395-version-negotiation-client + +[395-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[395-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-395] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[396-version-negotiation] +ssl_conf = 396-version-negotiation-ssl + +[396-version-negotiation-ssl] +server = 396-version-negotiation-server +client = 396-version-negotiation-client + +[396-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[396-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-396] +ExpectedResult = ServerFail + + +# =========================================================== + +[397-version-negotiation] +ssl_conf = 397-version-negotiation-ssl + +[397-version-negotiation-ssl] +server = 397-version-negotiation-server +client = 397-version-negotiation-client + +[397-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[397-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-397] +ExpectedProtocol = TLSv1 +ExpectedResult = Success + + +# =========================================================== + +[398-version-negotiation] +ssl_conf = 398-version-negotiation-ssl + +[398-version-negotiation-ssl] +server = 398-version-negotiation-server +client = 398-version-negotiation-client + +[398-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[398-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-398] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[399-version-negotiation] +ssl_conf = 399-version-negotiation-ssl + +[399-version-negotiation-ssl] +server = 399-version-negotiation-server +client = 399-version-negotiation-client + +[399-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[399-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-399] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[400-version-negotiation] +ssl_conf = 400-version-negotiation-ssl + +[400-version-negotiation-ssl] +server = 400-version-negotiation-server +client = 400-version-negotiation-client + +[400-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[400-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-400] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[401-version-negotiation] +ssl_conf = 401-version-negotiation-ssl + +[401-version-negotiation-ssl] +server = 401-version-negotiation-server +client = 401-version-negotiation-client + +[401-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[401-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-401] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[402-version-negotiation] +ssl_conf = 402-version-negotiation-ssl + +[402-version-negotiation-ssl] +server = 402-version-negotiation-server +client = 402-version-negotiation-client + +[402-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[402-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-402] +ExpectedProtocol = TLSv1 +ExpectedResult = Success + + +# =========================================================== + +[403-version-negotiation] +ssl_conf = 403-version-negotiation-ssl + +[403-version-negotiation-ssl] +server = 403-version-negotiation-server +client = 403-version-negotiation-client + +[403-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[403-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-403] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[404-version-negotiation] +ssl_conf = 404-version-negotiation-ssl + +[404-version-negotiation-ssl] +server = 404-version-negotiation-server +client = 404-version-negotiation-client + +[404-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[404-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-404] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[405-version-negotiation] +ssl_conf = 405-version-negotiation-ssl + +[405-version-negotiation-ssl] +server = 405-version-negotiation-server +client = 405-version-negotiation-client + +[405-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[405-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-405] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[406-version-negotiation] +ssl_conf = 406-version-negotiation-ssl + +[406-version-negotiation-ssl] +server = 406-version-negotiation-server +client = 406-version-negotiation-client + +[406-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[406-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-406] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[407-version-negotiation] +ssl_conf = 407-version-negotiation-ssl + +[407-version-negotiation-ssl] +server = 407-version-negotiation-server +client = 407-version-negotiation-client + +[407-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[407-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-407] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[408-version-negotiation] +ssl_conf = 408-version-negotiation-ssl + +[408-version-negotiation-ssl] +server = 408-version-negotiation-server +client = 408-version-negotiation-client + +[408-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[408-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-408] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[409-version-negotiation] +ssl_conf = 409-version-negotiation-ssl + +[409-version-negotiation-ssl] +server = 409-version-negotiation-server +client = 409-version-negotiation-client + +[409-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[409-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-409] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[410-version-negotiation] +ssl_conf = 410-version-negotiation-ssl + +[410-version-negotiation-ssl] +server = 410-version-negotiation-server +client = 410-version-negotiation-client + +[410-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[410-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-410] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[411-version-negotiation] +ssl_conf = 411-version-negotiation-ssl + +[411-version-negotiation-ssl] +server = 411-version-negotiation-server +client = 411-version-negotiation-client + +[411-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[411-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-411] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[412-version-negotiation] +ssl_conf = 412-version-negotiation-ssl + +[412-version-negotiation-ssl] +server = 412-version-negotiation-server +client = 412-version-negotiation-client + +[412-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[412-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-412] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[413-version-negotiation] +ssl_conf = 413-version-negotiation-ssl + +[413-version-negotiation-ssl] +server = 413-version-negotiation-server +client = 413-version-negotiation-client + +[413-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[413-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-413] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[414-version-negotiation] +ssl_conf = 414-version-negotiation-ssl + +[414-version-negotiation-ssl] +server = 414-version-negotiation-server +client = 414-version-negotiation-client + +[414-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[414-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-414] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[415-version-negotiation] +ssl_conf = 415-version-negotiation-ssl + +[415-version-negotiation-ssl] +server = 415-version-negotiation-server +client = 415-version-negotiation-client + +[415-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[415-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-415] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[416-version-negotiation] +ssl_conf = 416-version-negotiation-ssl + +[416-version-negotiation-ssl] +server = 416-version-negotiation-server +client = 416-version-negotiation-client + +[416-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[416-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-416] +ExpectedResult = ServerFail + + +# =========================================================== + +[417-version-negotiation] +ssl_conf = 417-version-negotiation-ssl + +[417-version-negotiation-ssl] +server = 417-version-negotiation-server +client = 417-version-negotiation-client + +[417-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[417-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-417] +ExpectedProtocol = TLSv1 +ExpectedResult = Success + + +# =========================================================== + +[418-version-negotiation] +ssl_conf = 418-version-negotiation-ssl + +[418-version-negotiation-ssl] +server = 418-version-negotiation-server +client = 418-version-negotiation-client + +[418-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[418-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-418] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[419-version-negotiation] +ssl_conf = 419-version-negotiation-ssl + +[419-version-negotiation-ssl] +server = 419-version-negotiation-server +client = 419-version-negotiation-client + +[419-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[419-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-419] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[420-version-negotiation] +ssl_conf = 420-version-negotiation-ssl + +[420-version-negotiation-ssl] +server = 420-version-negotiation-server +client = 420-version-negotiation-client + +[420-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[420-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-420] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[421-version-negotiation] +ssl_conf = 421-version-negotiation-ssl + +[421-version-negotiation-ssl] +server = 421-version-negotiation-server +client = 421-version-negotiation-client + +[421-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[421-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-421] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[422-version-negotiation] +ssl_conf = 422-version-negotiation-ssl + +[422-version-negotiation-ssl] +server = 422-version-negotiation-server +client = 422-version-negotiation-client + +[422-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[422-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-422] +ExpectedResult = ServerFail + + +# =========================================================== + +[423-version-negotiation] +ssl_conf = 423-version-negotiation-ssl + +[423-version-negotiation-ssl] +server = 423-version-negotiation-server +client = 423-version-negotiation-client + +[423-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[423-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-423] +ExpectedProtocol = TLSv1 +ExpectedResult = Success + + +# =========================================================== + +[424-version-negotiation] +ssl_conf = 424-version-negotiation-ssl + +[424-version-negotiation-ssl] +server = 424-version-negotiation-server +client = 424-version-negotiation-client + +[424-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[424-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-424] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[425-version-negotiation] +ssl_conf = 425-version-negotiation-ssl + +[425-version-negotiation-ssl] +server = 425-version-negotiation-server +client = 425-version-negotiation-client + +[425-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[425-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-425] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[426-version-negotiation] +ssl_conf = 426-version-negotiation-ssl + +[426-version-negotiation-ssl] +server = 426-version-negotiation-server +client = 426-version-negotiation-client + +[426-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[426-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-426] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[427-version-negotiation] +ssl_conf = 427-version-negotiation-ssl + +[427-version-negotiation-ssl] +server = 427-version-negotiation-server +client = 427-version-negotiation-client + +[427-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[427-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-427] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[428-version-negotiation] +ssl_conf = 428-version-negotiation-ssl + +[428-version-negotiation-ssl] +server = 428-version-negotiation-server +client = 428-version-negotiation-client + +[428-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[428-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-428] +ExpectedProtocol = TLSv1 +ExpectedResult = Success + + +# =========================================================== + +[429-version-negotiation] +ssl_conf = 429-version-negotiation-ssl + +[429-version-negotiation-ssl] +server = 429-version-negotiation-server +client = 429-version-negotiation-client + +[429-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[429-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-429] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[430-version-negotiation] +ssl_conf = 430-version-negotiation-ssl + +[430-version-negotiation-ssl] +server = 430-version-negotiation-server +client = 430-version-negotiation-client + +[430-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[430-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-430] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[431-version-negotiation] +ssl_conf = 431-version-negotiation-ssl + +[431-version-negotiation-ssl] +server = 431-version-negotiation-server +client = 431-version-negotiation-client + +[431-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[431-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-431] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[432-version-negotiation] +ssl_conf = 432-version-negotiation-ssl + +[432-version-negotiation-ssl] +server = 432-version-negotiation-server +client = 432-version-negotiation-client + +[432-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[432-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-432] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[433-version-negotiation] +ssl_conf = 433-version-negotiation-ssl + +[433-version-negotiation-ssl] +server = 433-version-negotiation-server +client = 433-version-negotiation-client + +[433-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[433-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-433] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[434-version-negotiation] +ssl_conf = 434-version-negotiation-ssl + +[434-version-negotiation-ssl] +server = 434-version-negotiation-server +client = 434-version-negotiation-client + +[434-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[434-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-434] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[435-version-negotiation] +ssl_conf = 435-version-negotiation-ssl + +[435-version-negotiation-ssl] +server = 435-version-negotiation-server +client = 435-version-negotiation-client + +[435-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[435-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-435] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[436-version-negotiation] +ssl_conf = 436-version-negotiation-ssl + +[436-version-negotiation-ssl] +server = 436-version-negotiation-server +client = 436-version-negotiation-client + +[436-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[436-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-436] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[437-version-negotiation] +ssl_conf = 437-version-negotiation-ssl + +[437-version-negotiation-ssl] +server = 437-version-negotiation-server +client = 437-version-negotiation-client + +[437-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[437-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-437] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[438-version-negotiation] +ssl_conf = 438-version-negotiation-ssl + +[438-version-negotiation-ssl] +server = 438-version-negotiation-server +client = 438-version-negotiation-client + +[438-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[438-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-438] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[439-version-negotiation] +ssl_conf = 439-version-negotiation-ssl + +[439-version-negotiation-ssl] +server = 439-version-negotiation-server +client = 439-version-negotiation-client + +[439-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[439-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-439] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[440-version-negotiation] +ssl_conf = 440-version-negotiation-ssl + +[440-version-negotiation-ssl] +server = 440-version-negotiation-server +client = 440-version-negotiation-client + +[440-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[440-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-440] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[441-version-negotiation] +ssl_conf = 441-version-negotiation-ssl + +[441-version-negotiation-ssl] +server = 441-version-negotiation-server +client = 441-version-negotiation-client + +[441-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[441-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-441] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[442-version-negotiation] +ssl_conf = 442-version-negotiation-ssl + +[442-version-negotiation-ssl] +server = 442-version-negotiation-server +client = 442-version-negotiation-client + +[442-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[442-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-442] +ExpectedResult = ServerFail + + +# =========================================================== + +[443-version-negotiation] +ssl_conf = 443-version-negotiation-ssl + +[443-version-negotiation-ssl] +server = 443-version-negotiation-server +client = 443-version-negotiation-client + +[443-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[443-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-443] +ExpectedResult = ClientFail + + +# =========================================================== + +[444-version-negotiation] +ssl_conf = 444-version-negotiation-ssl + +[444-version-negotiation-ssl] +server = 444-version-negotiation-server +client = 444-version-negotiation-client + +[444-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[444-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-444] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[445-version-negotiation] +ssl_conf = 445-version-negotiation-ssl + +[445-version-negotiation-ssl] +server = 445-version-negotiation-server +client = 445-version-negotiation-client + +[445-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[445-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-445] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[446-version-negotiation] +ssl_conf = 446-version-negotiation-ssl + +[446-version-negotiation-ssl] +server = 446-version-negotiation-server +client = 446-version-negotiation-client + +[446-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[446-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-446] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[447-version-negotiation] +ssl_conf = 447-version-negotiation-ssl + +[447-version-negotiation-ssl] +server = 447-version-negotiation-server +client = 447-version-negotiation-client + +[447-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[447-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-447] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[448-version-negotiation] +ssl_conf = 448-version-negotiation-ssl + +[448-version-negotiation-ssl] +server = 448-version-negotiation-server +client = 448-version-negotiation-client + +[448-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[448-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-448] +ExpectedResult = ServerFail + + +# =========================================================== + +[449-version-negotiation] +ssl_conf = 449-version-negotiation-ssl + +[449-version-negotiation-ssl] +server = 449-version-negotiation-server +client = 449-version-negotiation-client + +[449-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[449-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-449] +ExpectedResult = ClientFail + + +# =========================================================== + +[450-version-negotiation] +ssl_conf = 450-version-negotiation-ssl + +[450-version-negotiation-ssl] +server = 450-version-negotiation-server +client = 450-version-negotiation-client + +[450-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[450-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-450] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[451-version-negotiation] +ssl_conf = 451-version-negotiation-ssl + +[451-version-negotiation-ssl] +server = 451-version-negotiation-server +client = 451-version-negotiation-client + +[451-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[451-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-451] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[452-version-negotiation] +ssl_conf = 452-version-negotiation-ssl + +[452-version-negotiation-ssl] +server = 452-version-negotiation-server +client = 452-version-negotiation-client + +[452-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[452-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-452] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[453-version-negotiation] +ssl_conf = 453-version-negotiation-ssl + +[453-version-negotiation-ssl] +server = 453-version-negotiation-server +client = 453-version-negotiation-client + +[453-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[453-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-453] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[454-version-negotiation] +ssl_conf = 454-version-negotiation-ssl + +[454-version-negotiation-ssl] +server = 454-version-negotiation-server +client = 454-version-negotiation-client + +[454-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[454-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-454] +ExpectedResult = ClientFail + + +# =========================================================== + +[455-version-negotiation] +ssl_conf = 455-version-negotiation-ssl + +[455-version-negotiation-ssl] +server = 455-version-negotiation-server +client = 455-version-negotiation-client + +[455-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[455-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-455] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[456-version-negotiation] +ssl_conf = 456-version-negotiation-ssl + +[456-version-negotiation-ssl] +server = 456-version-negotiation-server +client = 456-version-negotiation-client + +[456-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[456-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-456] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[457-version-negotiation] +ssl_conf = 457-version-negotiation-ssl + +[457-version-negotiation-ssl] +server = 457-version-negotiation-server +client = 457-version-negotiation-client + +[457-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[457-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-457] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[458-version-negotiation] +ssl_conf = 458-version-negotiation-ssl + +[458-version-negotiation-ssl] +server = 458-version-negotiation-server +client = 458-version-negotiation-client + +[458-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[458-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-458] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[459-version-negotiation] +ssl_conf = 459-version-negotiation-ssl + +[459-version-negotiation-ssl] +server = 459-version-negotiation-server +client = 459-version-negotiation-client + +[459-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[459-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-459] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[460-version-negotiation] +ssl_conf = 460-version-negotiation-ssl + +[460-version-negotiation-ssl] +server = 460-version-negotiation-server +client = 460-version-negotiation-client + +[460-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[460-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-460] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[461-version-negotiation] +ssl_conf = 461-version-negotiation-ssl + +[461-version-negotiation-ssl] +server = 461-version-negotiation-server +client = 461-version-negotiation-client + +[461-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[461-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-461] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[462-version-negotiation] +ssl_conf = 462-version-negotiation-ssl + +[462-version-negotiation-ssl] +server = 462-version-negotiation-server +client = 462-version-negotiation-client + +[462-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[462-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-462] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[463-version-negotiation] +ssl_conf = 463-version-negotiation-ssl + +[463-version-negotiation-ssl] +server = 463-version-negotiation-server +client = 463-version-negotiation-client + +[463-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[463-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-463] +ExpectedResult = ServerFail + + +# =========================================================== + +[464-version-negotiation] +ssl_conf = 464-version-negotiation-ssl + +[464-version-negotiation-ssl] +server = 464-version-negotiation-server +client = 464-version-negotiation-client + +[464-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[464-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-464] +ExpectedResult = ServerFail + + +# =========================================================== + +[465-version-negotiation] +ssl_conf = 465-version-negotiation-ssl + +[465-version-negotiation-ssl] +server = 465-version-negotiation-server +client = 465-version-negotiation-client + +[465-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[465-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-465] +ExpectedResult = ServerFail + + +# =========================================================== + +[466-version-negotiation] +ssl_conf = 466-version-negotiation-ssl + +[466-version-negotiation-ssl] +server = 466-version-negotiation-server +client = 466-version-negotiation-client + +[466-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[466-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-466] +ExpectedResult = ServerFail + + +# =========================================================== + +[467-version-negotiation] +ssl_conf = 467-version-negotiation-ssl + +[467-version-negotiation-ssl] +server = 467-version-negotiation-server +client = 467-version-negotiation-client + +[467-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[467-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-467] +ExpectedResult = ServerFail + + +# =========================================================== + +[468-version-negotiation] +ssl_conf = 468-version-negotiation-ssl + +[468-version-negotiation-ssl] +server = 468-version-negotiation-server +client = 468-version-negotiation-client + +[468-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[468-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-468] +ExpectedResult = ServerFail + + +# =========================================================== + +[469-version-negotiation] +ssl_conf = 469-version-negotiation-ssl + +[469-version-negotiation-ssl] +server = 469-version-negotiation-server +client = 469-version-negotiation-client + +[469-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[469-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-469] +ExpectedResult = ClientFail + + +# =========================================================== + +[470-version-negotiation] +ssl_conf = 470-version-negotiation-ssl + +[470-version-negotiation-ssl] +server = 470-version-negotiation-server +client = 470-version-negotiation-client + +[470-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[470-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-470] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[471-version-negotiation] +ssl_conf = 471-version-negotiation-ssl + +[471-version-negotiation-ssl] +server = 471-version-negotiation-server +client = 471-version-negotiation-client + +[471-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[471-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-471] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[472-version-negotiation] +ssl_conf = 472-version-negotiation-ssl + +[472-version-negotiation-ssl] +server = 472-version-negotiation-server +client = 472-version-negotiation-client + +[472-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[472-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-472] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[473-version-negotiation] +ssl_conf = 473-version-negotiation-ssl + +[473-version-negotiation-ssl] +server = 473-version-negotiation-server +client = 473-version-negotiation-client + +[473-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[473-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-473] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[474-version-negotiation] +ssl_conf = 474-version-negotiation-ssl + +[474-version-negotiation-ssl] +server = 474-version-negotiation-server +client = 474-version-negotiation-client + +[474-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[474-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-474] +ExpectedResult = ServerFail + + +# =========================================================== + +[475-version-negotiation] +ssl_conf = 475-version-negotiation-ssl + +[475-version-negotiation-ssl] +server = 475-version-negotiation-server +client = 475-version-negotiation-client + +[475-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[475-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-475] +ExpectedResult = ClientFail + + +# =========================================================== + +[476-version-negotiation] +ssl_conf = 476-version-negotiation-ssl + +[476-version-negotiation-ssl] +server = 476-version-negotiation-server +client = 476-version-negotiation-client + +[476-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[476-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-476] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[477-version-negotiation] +ssl_conf = 477-version-negotiation-ssl + +[477-version-negotiation-ssl] +server = 477-version-negotiation-server +client = 477-version-negotiation-client + +[477-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[477-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-477] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[478-version-negotiation] +ssl_conf = 478-version-negotiation-ssl + +[478-version-negotiation-ssl] +server = 478-version-negotiation-server +client = 478-version-negotiation-client + +[478-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[478-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-478] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[479-version-negotiation] +ssl_conf = 479-version-negotiation-ssl + +[479-version-negotiation-ssl] +server = 479-version-negotiation-server +client = 479-version-negotiation-client + +[479-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[479-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-479] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[480-version-negotiation] +ssl_conf = 480-version-negotiation-ssl + +[480-version-negotiation-ssl] +server = 480-version-negotiation-server +client = 480-version-negotiation-client + +[480-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[480-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-480] +ExpectedResult = ClientFail + + +# =========================================================== + +[481-version-negotiation] +ssl_conf = 481-version-negotiation-ssl + +[481-version-negotiation-ssl] +server = 481-version-negotiation-server +client = 481-version-negotiation-client + +[481-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[481-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-481] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[482-version-negotiation] +ssl_conf = 482-version-negotiation-ssl + +[482-version-negotiation-ssl] +server = 482-version-negotiation-server +client = 482-version-negotiation-client + +[482-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[482-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-482] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[483-version-negotiation] +ssl_conf = 483-version-negotiation-ssl + +[483-version-negotiation-ssl] +server = 483-version-negotiation-server +client = 483-version-negotiation-client + +[483-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[483-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-483] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[484-version-negotiation] +ssl_conf = 484-version-negotiation-ssl + +[484-version-negotiation-ssl] +server = 484-version-negotiation-server +client = 484-version-negotiation-client + +[484-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[484-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-484] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[485-version-negotiation] +ssl_conf = 485-version-negotiation-ssl + +[485-version-negotiation-ssl] +server = 485-version-negotiation-server +client = 485-version-negotiation-client + +[485-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[485-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-485] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[486-version-negotiation] +ssl_conf = 486-version-negotiation-ssl + +[486-version-negotiation-ssl] +server = 486-version-negotiation-server +client = 486-version-negotiation-client + +[486-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[486-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-486] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[487-version-negotiation] +ssl_conf = 487-version-negotiation-ssl + +[487-version-negotiation-ssl] +server = 487-version-negotiation-server +client = 487-version-negotiation-client + +[487-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[487-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-487] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[488-version-negotiation] +ssl_conf = 488-version-negotiation-ssl + +[488-version-negotiation-ssl] +server = 488-version-negotiation-server +client = 488-version-negotiation-client + +[488-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[488-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-488] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[489-version-negotiation] +ssl_conf = 489-version-negotiation-ssl + +[489-version-negotiation-ssl] +server = 489-version-negotiation-server +client = 489-version-negotiation-client + +[489-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[489-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-489] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[490-version-negotiation] +ssl_conf = 490-version-negotiation-ssl + +[490-version-negotiation-ssl] +server = 490-version-negotiation-server +client = 490-version-negotiation-client + +[490-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[490-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-490] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[491-version-negotiation] +ssl_conf = 491-version-negotiation-ssl + +[491-version-negotiation-ssl] +server = 491-version-negotiation-server +client = 491-version-negotiation-client + +[491-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[491-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-491] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[492-version-negotiation] +ssl_conf = 492-version-negotiation-ssl + +[492-version-negotiation-ssl] +server = 492-version-negotiation-server +client = 492-version-negotiation-client + +[492-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[492-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-492] +ExpectedResult = ServerFail + + +# =========================================================== + +[493-version-negotiation] +ssl_conf = 493-version-negotiation-ssl + +[493-version-negotiation-ssl] +server = 493-version-negotiation-server +client = 493-version-negotiation-client + +[493-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[493-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-493] +ExpectedResult = ServerFail + + +# =========================================================== + +[494-version-negotiation] +ssl_conf = 494-version-negotiation-ssl + +[494-version-negotiation-ssl] +server = 494-version-negotiation-server +client = 494-version-negotiation-client + +[494-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[494-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-494] +ExpectedResult = ServerFail + + +# =========================================================== + +[495-version-negotiation] +ssl_conf = 495-version-negotiation-ssl + +[495-version-negotiation-ssl] +server = 495-version-negotiation-server +client = 495-version-negotiation-client + +[495-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[495-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-495] +ExpectedResult = ServerFail + + +# =========================================================== + +[496-version-negotiation] +ssl_conf = 496-version-negotiation-ssl + +[496-version-negotiation-ssl] +server = 496-version-negotiation-server +client = 496-version-negotiation-client + +[496-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[496-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-496] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[497-version-negotiation] +ssl_conf = 497-version-negotiation-ssl + +[497-version-negotiation-ssl] +server = 497-version-negotiation-server +client = 497-version-negotiation-client + +[497-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[497-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-497] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[498-version-negotiation] +ssl_conf = 498-version-negotiation-ssl + +[498-version-negotiation-ssl] +server = 498-version-negotiation-server +client = 498-version-negotiation-client + +[498-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[498-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-498] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[499-version-negotiation] +ssl_conf = 499-version-negotiation-ssl + +[499-version-negotiation-ssl] +server = 499-version-negotiation-server +client = 499-version-negotiation-client + +[499-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[499-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-499] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[500-version-negotiation] +ssl_conf = 500-version-negotiation-ssl + +[500-version-negotiation-ssl] +server = 500-version-negotiation-server +client = 500-version-negotiation-client + +[500-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[500-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-500] +ExpectedResult = ServerFail + + +# =========================================================== + +[501-version-negotiation] +ssl_conf = 501-version-negotiation-ssl + +[501-version-negotiation-ssl] +server = 501-version-negotiation-server +client = 501-version-negotiation-client + +[501-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[501-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-501] +ExpectedResult = ServerFail + + +# =========================================================== + +[502-version-negotiation] +ssl_conf = 502-version-negotiation-ssl + +[502-version-negotiation-ssl] +server = 502-version-negotiation-server +client = 502-version-negotiation-client + +[502-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[502-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-502] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[503-version-negotiation] +ssl_conf = 503-version-negotiation-ssl + +[503-version-negotiation-ssl] +server = 503-version-negotiation-server +client = 503-version-negotiation-client + +[503-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[503-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-503] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[504-version-negotiation] +ssl_conf = 504-version-negotiation-ssl + +[504-version-negotiation-ssl] +server = 504-version-negotiation-server +client = 504-version-negotiation-client + +[504-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[504-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-504] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[505-version-negotiation] +ssl_conf = 505-version-negotiation-ssl + +[505-version-negotiation-ssl] +server = 505-version-negotiation-server +client = 505-version-negotiation-client + +[505-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[505-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-505] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[506-version-negotiation] +ssl_conf = 506-version-negotiation-ssl + +[506-version-negotiation-ssl] +server = 506-version-negotiation-server +client = 506-version-negotiation-client + +[506-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[506-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-506] +ExpectedResult = ServerFail + + +# =========================================================== + +[507-version-negotiation] +ssl_conf = 507-version-negotiation-ssl + +[507-version-negotiation-ssl] +server = 507-version-negotiation-server +client = 507-version-negotiation-client + +[507-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[507-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-507] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[508-version-negotiation] +ssl_conf = 508-version-negotiation-ssl + +[508-version-negotiation-ssl] +server = 508-version-negotiation-server +client = 508-version-negotiation-client + +[508-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[508-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-508] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[509-version-negotiation] +ssl_conf = 509-version-negotiation-ssl + +[509-version-negotiation-ssl] +server = 509-version-negotiation-server +client = 509-version-negotiation-client + +[509-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[509-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-509] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[510-version-negotiation] +ssl_conf = 510-version-negotiation-ssl + +[510-version-negotiation-ssl] +server = 510-version-negotiation-server +client = 510-version-negotiation-client + +[510-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[510-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-510] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[511-version-negotiation] +ssl_conf = 511-version-negotiation-ssl + +[511-version-negotiation-ssl] +server = 511-version-negotiation-server +client = 511-version-negotiation-client + +[511-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[511-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-511] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[512-version-negotiation] +ssl_conf = 512-version-negotiation-ssl + +[512-version-negotiation-ssl] +server = 512-version-negotiation-server +client = 512-version-negotiation-client + +[512-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[512-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-512] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[513-version-negotiation] +ssl_conf = 513-version-negotiation-ssl + +[513-version-negotiation-ssl] +server = 513-version-negotiation-server +client = 513-version-negotiation-client + +[513-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[513-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-513] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[514-version-negotiation] +ssl_conf = 514-version-negotiation-ssl + +[514-version-negotiation-ssl] +server = 514-version-negotiation-server +client = 514-version-negotiation-client + +[514-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[514-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-514] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[515-version-negotiation] +ssl_conf = 515-version-negotiation-ssl + +[515-version-negotiation-ssl] +server = 515-version-negotiation-server +client = 515-version-negotiation-client + +[515-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[515-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-515] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[516-version-negotiation] +ssl_conf = 516-version-negotiation-ssl + +[516-version-negotiation-ssl] +server = 516-version-negotiation-server +client = 516-version-negotiation-client + +[516-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[516-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-516] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[517-version-negotiation] +ssl_conf = 517-version-negotiation-ssl + +[517-version-negotiation-ssl] +server = 517-version-negotiation-server +client = 517-version-negotiation-client + +[517-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[517-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-517] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[518-version-negotiation] +ssl_conf = 518-version-negotiation-ssl + +[518-version-negotiation-ssl] +server = 518-version-negotiation-server +client = 518-version-negotiation-client + +[518-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[518-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-518] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[519-version-negotiation] +ssl_conf = 519-version-negotiation-ssl + +[519-version-negotiation-ssl] +server = 519-version-negotiation-server +client = 519-version-negotiation-client + +[519-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[519-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-519] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[520-version-negotiation] +ssl_conf = 520-version-negotiation-ssl + +[520-version-negotiation-ssl] +server = 520-version-negotiation-server +client = 520-version-negotiation-client + +[520-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[520-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-520] +ExpectedResult = ServerFail + + +# =========================================================== + +[521-version-negotiation] +ssl_conf = 521-version-negotiation-ssl + +[521-version-negotiation-ssl] +server = 521-version-negotiation-server +client = 521-version-negotiation-client + +[521-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[521-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-521] +ExpectedResult = ServerFail + + +# =========================================================== + +[522-version-negotiation] +ssl_conf = 522-version-negotiation-ssl + +[522-version-negotiation-ssl] +server = 522-version-negotiation-server +client = 522-version-negotiation-client + +[522-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[522-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-522] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[523-version-negotiation] +ssl_conf = 523-version-negotiation-ssl + +[523-version-negotiation-ssl] +server = 523-version-negotiation-server +client = 523-version-negotiation-client + +[523-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[523-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-523] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[524-version-negotiation] +ssl_conf = 524-version-negotiation-ssl + +[524-version-negotiation-ssl] +server = 524-version-negotiation-server +client = 524-version-negotiation-client + +[524-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[524-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-524] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[525-version-negotiation] +ssl_conf = 525-version-negotiation-ssl + +[525-version-negotiation-ssl] +server = 525-version-negotiation-server +client = 525-version-negotiation-client + +[525-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[525-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-525] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[526-version-negotiation] +ssl_conf = 526-version-negotiation-ssl + +[526-version-negotiation-ssl] +server = 526-version-negotiation-server +client = 526-version-negotiation-client + +[526-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[526-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-526] +ExpectedResult = ServerFail + + +# =========================================================== + +[527-version-negotiation] +ssl_conf = 527-version-negotiation-ssl + +[527-version-negotiation-ssl] +server = 527-version-negotiation-server +client = 527-version-negotiation-client + +[527-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[527-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-527] +ExpectedResult = ServerFail + + +# =========================================================== + +[528-version-negotiation] +ssl_conf = 528-version-negotiation-ssl + +[528-version-negotiation-ssl] +server = 528-version-negotiation-server +client = 528-version-negotiation-client + +[528-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[528-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-528] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[529-version-negotiation] +ssl_conf = 529-version-negotiation-ssl + +[529-version-negotiation-ssl] +server = 529-version-negotiation-server +client = 529-version-negotiation-client + +[529-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[529-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-529] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[530-version-negotiation] +ssl_conf = 530-version-negotiation-ssl + +[530-version-negotiation-ssl] +server = 530-version-negotiation-server +client = 530-version-negotiation-client + +[530-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[530-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-530] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[531-version-negotiation] +ssl_conf = 531-version-negotiation-ssl + +[531-version-negotiation-ssl] +server = 531-version-negotiation-server +client = 531-version-negotiation-client + +[531-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[531-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-531] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[532-version-negotiation] +ssl_conf = 532-version-negotiation-ssl + +[532-version-negotiation-ssl] +server = 532-version-negotiation-server +client = 532-version-negotiation-client + +[532-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[532-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-532] +ExpectedResult = ServerFail + + +# =========================================================== + +[533-version-negotiation] +ssl_conf = 533-version-negotiation-ssl + +[533-version-negotiation-ssl] +server = 533-version-negotiation-server +client = 533-version-negotiation-client + +[533-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[533-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-533] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[534-version-negotiation] +ssl_conf = 534-version-negotiation-ssl + +[534-version-negotiation-ssl] +server = 534-version-negotiation-server +client = 534-version-negotiation-client + +[534-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[534-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-534] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[535-version-negotiation] +ssl_conf = 535-version-negotiation-ssl + +[535-version-negotiation-ssl] +server = 535-version-negotiation-server +client = 535-version-negotiation-client + +[535-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[535-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-535] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[536-version-negotiation] +ssl_conf = 536-version-negotiation-ssl + +[536-version-negotiation-ssl] +server = 536-version-negotiation-server +client = 536-version-negotiation-client + +[536-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[536-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-536] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[537-version-negotiation] +ssl_conf = 537-version-negotiation-ssl + +[537-version-negotiation-ssl] +server = 537-version-negotiation-server +client = 537-version-negotiation-client + +[537-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[537-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-537] +ExpectedProtocol = TLSv1.1 +ExpectedResult = Success + + +# =========================================================== + +[538-version-negotiation] +ssl_conf = 538-version-negotiation-ssl + +[538-version-negotiation-ssl] +server = 538-version-negotiation-server +client = 538-version-negotiation-client + +[538-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[538-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-538] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[539-version-negotiation] +ssl_conf = 539-version-negotiation-ssl + +[539-version-negotiation-ssl] +server = 539-version-negotiation-server +client = 539-version-negotiation-client + +[539-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[539-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-539] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[540-version-negotiation] +ssl_conf = 540-version-negotiation-ssl + +[540-version-negotiation-ssl] +server = 540-version-negotiation-server +client = 540-version-negotiation-client + +[540-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[540-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-540] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[541-version-negotiation] +ssl_conf = 541-version-negotiation-ssl + +[541-version-negotiation-ssl] +server = 541-version-negotiation-server +client = 541-version-negotiation-client + +[541-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[541-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-541] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[542-version-negotiation] +ssl_conf = 542-version-negotiation-ssl + +[542-version-negotiation-ssl] +server = 542-version-negotiation-server +client = 542-version-negotiation-client + +[542-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[542-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-542] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[543-version-negotiation] +ssl_conf = 543-version-negotiation-ssl + +[543-version-negotiation-ssl] +server = 543-version-negotiation-server +client = 543-version-negotiation-client + +[543-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[543-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-543] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[544-version-negotiation] +ssl_conf = 544-version-negotiation-ssl + +[544-version-negotiation-ssl] +server = 544-version-negotiation-server +client = 544-version-negotiation-client + +[544-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[544-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-544] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[545-version-negotiation] +ssl_conf = 545-version-negotiation-ssl + +[545-version-negotiation-ssl] +server = 545-version-negotiation-server +client = 545-version-negotiation-client + +[545-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[545-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-545] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[546-version-negotiation] +ssl_conf = 546-version-negotiation-ssl + +[546-version-negotiation-ssl] +server = 546-version-negotiation-server +client = 546-version-negotiation-client + +[546-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[546-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-546] +ExpectedResult = ServerFail + + +# =========================================================== + +[547-version-negotiation] +ssl_conf = 547-version-negotiation-ssl + +[547-version-negotiation-ssl] +server = 547-version-negotiation-server +client = 547-version-negotiation-client + +[547-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[547-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-547] +ExpectedResult = ClientFail + + +# =========================================================== + +[548-version-negotiation] +ssl_conf = 548-version-negotiation-ssl + +[548-version-negotiation-ssl] +server = 548-version-negotiation-server +client = 548-version-negotiation-client + +[548-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[548-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-548] +ExpectedResult = ClientFail + + +# =========================================================== + +[549-version-negotiation] +ssl_conf = 549-version-negotiation-ssl + +[549-version-negotiation-ssl] +server = 549-version-negotiation-server +client = 549-version-negotiation-client + +[549-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[549-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-549] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[550-version-negotiation] +ssl_conf = 550-version-negotiation-ssl + +[550-version-negotiation-ssl] +server = 550-version-negotiation-server +client = 550-version-negotiation-client + +[550-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[550-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-550] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[551-version-negotiation] +ssl_conf = 551-version-negotiation-ssl + +[551-version-negotiation-ssl] +server = 551-version-negotiation-server +client = 551-version-negotiation-client + +[551-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[551-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-551] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[552-version-negotiation] +ssl_conf = 552-version-negotiation-ssl + +[552-version-negotiation-ssl] +server = 552-version-negotiation-server +client = 552-version-negotiation-client + +[552-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[552-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-552] +ExpectedResult = ServerFail + + +# =========================================================== + +[553-version-negotiation] +ssl_conf = 553-version-negotiation-ssl + +[553-version-negotiation-ssl] +server = 553-version-negotiation-server +client = 553-version-negotiation-client + +[553-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[553-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-553] +ExpectedResult = ClientFail + + +# =========================================================== + +[554-version-negotiation] +ssl_conf = 554-version-negotiation-ssl + +[554-version-negotiation-ssl] +server = 554-version-negotiation-server +client = 554-version-negotiation-client + +[554-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[554-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-554] +ExpectedResult = ClientFail + + +# =========================================================== + +[555-version-negotiation] +ssl_conf = 555-version-negotiation-ssl + +[555-version-negotiation-ssl] +server = 555-version-negotiation-server +client = 555-version-negotiation-client + +[555-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[555-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-555] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[556-version-negotiation] +ssl_conf = 556-version-negotiation-ssl + +[556-version-negotiation-ssl] +server = 556-version-negotiation-server +client = 556-version-negotiation-client + +[556-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[556-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-556] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[557-version-negotiation] +ssl_conf = 557-version-negotiation-ssl + +[557-version-negotiation-ssl] +server = 557-version-negotiation-server +client = 557-version-negotiation-client + +[557-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[557-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-557] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[558-version-negotiation] +ssl_conf = 558-version-negotiation-ssl + +[558-version-negotiation-ssl] +server = 558-version-negotiation-server +client = 558-version-negotiation-client + +[558-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[558-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-558] +ExpectedResult = ClientFail + + +# =========================================================== + +[559-version-negotiation] +ssl_conf = 559-version-negotiation-ssl + +[559-version-negotiation-ssl] +server = 559-version-negotiation-server +client = 559-version-negotiation-client + +[559-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[559-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-559] +ExpectedResult = ClientFail + + +# =========================================================== + +[560-version-negotiation] +ssl_conf = 560-version-negotiation-ssl + +[560-version-negotiation-ssl] +server = 560-version-negotiation-server +client = 560-version-negotiation-client + +[560-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[560-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-560] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[561-version-negotiation] +ssl_conf = 561-version-negotiation-ssl + +[561-version-negotiation-ssl] +server = 561-version-negotiation-server +client = 561-version-negotiation-client + +[561-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[561-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-561] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[562-version-negotiation] +ssl_conf = 562-version-negotiation-ssl + +[562-version-negotiation-ssl] +server = 562-version-negotiation-server +client = 562-version-negotiation-client + +[562-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[562-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-562] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[563-version-negotiation] +ssl_conf = 563-version-negotiation-ssl + +[563-version-negotiation-ssl] +server = 563-version-negotiation-server +client = 563-version-negotiation-client + +[563-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[563-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-563] +ExpectedResult = ClientFail + + +# =========================================================== + +[564-version-negotiation] +ssl_conf = 564-version-negotiation-ssl + +[564-version-negotiation-ssl] +server = 564-version-negotiation-server +client = 564-version-negotiation-client + +[564-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[564-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-564] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[565-version-negotiation] +ssl_conf = 565-version-negotiation-ssl + +[565-version-negotiation-ssl] +server = 565-version-negotiation-server +client = 565-version-negotiation-client + +[565-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[565-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-565] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[566-version-negotiation] +ssl_conf = 566-version-negotiation-ssl + +[566-version-negotiation-ssl] +server = 566-version-negotiation-server +client = 566-version-negotiation-client + +[566-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[566-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-566] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[567-version-negotiation] +ssl_conf = 567-version-negotiation-ssl + +[567-version-negotiation-ssl] +server = 567-version-negotiation-server +client = 567-version-negotiation-client + +[567-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[567-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-567] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[568-version-negotiation] +ssl_conf = 568-version-negotiation-ssl + +[568-version-negotiation-ssl] +server = 568-version-negotiation-server +client = 568-version-negotiation-client + +[568-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[568-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-568] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[569-version-negotiation] +ssl_conf = 569-version-negotiation-ssl + +[569-version-negotiation-ssl] +server = 569-version-negotiation-server +client = 569-version-negotiation-client + +[569-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[569-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-569] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[570-version-negotiation] +ssl_conf = 570-version-negotiation-ssl + +[570-version-negotiation-ssl] +server = 570-version-negotiation-server +client = 570-version-negotiation-client + +[570-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[570-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-570] +ExpectedResult = ServerFail + + +# =========================================================== + +[571-version-negotiation] +ssl_conf = 571-version-negotiation-ssl + +[571-version-negotiation-ssl] +server = 571-version-negotiation-server +client = 571-version-negotiation-client + +[571-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[571-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-571] +ExpectedResult = ServerFail + + +# =========================================================== + +[572-version-negotiation] +ssl_conf = 572-version-negotiation-ssl + +[572-version-negotiation-ssl] +server = 572-version-negotiation-server +client = 572-version-negotiation-client + +[572-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[572-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-572] +ExpectedResult = ServerFail + + +# =========================================================== + +[573-version-negotiation] +ssl_conf = 573-version-negotiation-ssl + +[573-version-negotiation-ssl] +server = 573-version-negotiation-server +client = 573-version-negotiation-client + +[573-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[573-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-573] +ExpectedResult = ServerFail + + +# =========================================================== + +[574-version-negotiation] +ssl_conf = 574-version-negotiation-ssl + +[574-version-negotiation-ssl] +server = 574-version-negotiation-server +client = 574-version-negotiation-client + +[574-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[574-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-574] +ExpectedResult = ServerFail + + +# =========================================================== + +[575-version-negotiation] +ssl_conf = 575-version-negotiation-ssl + +[575-version-negotiation-ssl] +server = 575-version-negotiation-server +client = 575-version-negotiation-client + +[575-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[575-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-575] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[576-version-negotiation] +ssl_conf = 576-version-negotiation-ssl + +[576-version-negotiation-ssl] +server = 576-version-negotiation-server +client = 576-version-negotiation-client + +[576-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[576-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-576] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[577-version-negotiation] +ssl_conf = 577-version-negotiation-ssl + +[577-version-negotiation-ssl] +server = 577-version-negotiation-server +client = 577-version-negotiation-client + +[577-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[577-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-577] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[578-version-negotiation] +ssl_conf = 578-version-negotiation-ssl + +[578-version-negotiation-ssl] +server = 578-version-negotiation-server +client = 578-version-negotiation-client + +[578-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[578-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-578] +ExpectedResult = ServerFail + + +# =========================================================== + +[579-version-negotiation] +ssl_conf = 579-version-negotiation-ssl + +[579-version-negotiation-ssl] +server = 579-version-negotiation-server +client = 579-version-negotiation-client + +[579-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[579-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-579] +ExpectedResult = ServerFail + + +# =========================================================== + +[580-version-negotiation] +ssl_conf = 580-version-negotiation-ssl + +[580-version-negotiation-ssl] +server = 580-version-negotiation-server +client = 580-version-negotiation-client + +[580-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[580-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-580] +ExpectedResult = ServerFail + + +# =========================================================== + +[581-version-negotiation] +ssl_conf = 581-version-negotiation-ssl + +[581-version-negotiation-ssl] +server = 581-version-negotiation-server +client = 581-version-negotiation-client + +[581-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[581-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-581] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[582-version-negotiation] +ssl_conf = 582-version-negotiation-ssl + +[582-version-negotiation-ssl] +server = 582-version-negotiation-server +client = 582-version-negotiation-client + +[582-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[582-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-582] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[583-version-negotiation] +ssl_conf = 583-version-negotiation-ssl + +[583-version-negotiation-ssl] +server = 583-version-negotiation-server +client = 583-version-negotiation-client + +[583-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[583-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-583] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[584-version-negotiation] +ssl_conf = 584-version-negotiation-ssl + +[584-version-negotiation-ssl] +server = 584-version-negotiation-server +client = 584-version-negotiation-client + +[584-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[584-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-584] +ExpectedResult = ServerFail + + +# =========================================================== + +[585-version-negotiation] +ssl_conf = 585-version-negotiation-ssl + +[585-version-negotiation-ssl] +server = 585-version-negotiation-server +client = 585-version-negotiation-client + +[585-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[585-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-585] +ExpectedResult = ServerFail + + +# =========================================================== + +[586-version-negotiation] +ssl_conf = 586-version-negotiation-ssl + +[586-version-negotiation-ssl] +server = 586-version-negotiation-server +client = 586-version-negotiation-client + +[586-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[586-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-586] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[587-version-negotiation] +ssl_conf = 587-version-negotiation-ssl + +[587-version-negotiation-ssl] +server = 587-version-negotiation-server +client = 587-version-negotiation-client + +[587-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[587-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-587] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[588-version-negotiation] +ssl_conf = 588-version-negotiation-ssl + +[588-version-negotiation-ssl] +server = 588-version-negotiation-server +client = 588-version-negotiation-client + +[588-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[588-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-588] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[589-version-negotiation] +ssl_conf = 589-version-negotiation-ssl + +[589-version-negotiation-ssl] +server = 589-version-negotiation-server +client = 589-version-negotiation-client + +[589-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[589-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-589] +ExpectedResult = ServerFail + + +# =========================================================== + +[590-version-negotiation] +ssl_conf = 590-version-negotiation-ssl + +[590-version-negotiation-ssl] +server = 590-version-negotiation-server +client = 590-version-negotiation-client + +[590-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[590-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-590] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[591-version-negotiation] +ssl_conf = 591-version-negotiation-ssl + +[591-version-negotiation-ssl] +server = 591-version-negotiation-server +client = 591-version-negotiation-client + +[591-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[591-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-591] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[592-version-negotiation] +ssl_conf = 592-version-negotiation-ssl + +[592-version-negotiation-ssl] +server = 592-version-negotiation-server +client = 592-version-negotiation-client + +[592-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[592-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-592] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[593-version-negotiation] +ssl_conf = 593-version-negotiation-ssl + +[593-version-negotiation-ssl] +server = 593-version-negotiation-server +client = 593-version-negotiation-client + +[593-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[593-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-593] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[594-version-negotiation] +ssl_conf = 594-version-negotiation-ssl + +[594-version-negotiation-ssl] +server = 594-version-negotiation-server +client = 594-version-negotiation-client + +[594-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[594-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-594] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[595-version-negotiation] +ssl_conf = 595-version-negotiation-ssl + +[595-version-negotiation-ssl] +server = 595-version-negotiation-server +client = 595-version-negotiation-client + +[595-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[595-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-595] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[596-version-negotiation] +ssl_conf = 596-version-negotiation-ssl + +[596-version-negotiation-ssl] +server = 596-version-negotiation-server +client = 596-version-negotiation-client + +[596-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[596-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-596] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[597-version-negotiation] +ssl_conf = 597-version-negotiation-ssl + +[597-version-negotiation-ssl] +server = 597-version-negotiation-server +client = 597-version-negotiation-client + +[597-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[597-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-597] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[598-version-negotiation] +ssl_conf = 598-version-negotiation-ssl + +[598-version-negotiation-ssl] +server = 598-version-negotiation-server +client = 598-version-negotiation-client + +[598-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[598-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-598] +ExpectedResult = ServerFail + + +# =========================================================== + +[599-version-negotiation] +ssl_conf = 599-version-negotiation-ssl + +[599-version-negotiation-ssl] +server = 599-version-negotiation-server +client = 599-version-negotiation-client + +[599-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[599-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-599] +ExpectedResult = ServerFail + + +# =========================================================== + +[600-version-negotiation] +ssl_conf = 600-version-negotiation-ssl + +[600-version-negotiation-ssl] +server = 600-version-negotiation-server +client = 600-version-negotiation-client + +[600-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[600-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-600] +ExpectedResult = ServerFail + + +# =========================================================== + +[601-version-negotiation] +ssl_conf = 601-version-negotiation-ssl + +[601-version-negotiation-ssl] +server = 601-version-negotiation-server +client = 601-version-negotiation-client + +[601-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[601-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-601] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[602-version-negotiation] +ssl_conf = 602-version-negotiation-ssl + +[602-version-negotiation-ssl] +server = 602-version-negotiation-server +client = 602-version-negotiation-client + +[602-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[602-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-602] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[603-version-negotiation] +ssl_conf = 603-version-negotiation-ssl + +[603-version-negotiation-ssl] +server = 603-version-negotiation-server +client = 603-version-negotiation-client + +[603-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[603-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-603] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[604-version-negotiation] +ssl_conf = 604-version-negotiation-ssl + +[604-version-negotiation-ssl] +server = 604-version-negotiation-server +client = 604-version-negotiation-client + +[604-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[604-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-604] +ExpectedResult = ServerFail + + +# =========================================================== + +[605-version-negotiation] +ssl_conf = 605-version-negotiation-ssl + +[605-version-negotiation-ssl] +server = 605-version-negotiation-server +client = 605-version-negotiation-client + +[605-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[605-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-605] +ExpectedResult = ServerFail + + +# =========================================================== + +[606-version-negotiation] +ssl_conf = 606-version-negotiation-ssl + +[606-version-negotiation-ssl] +server = 606-version-negotiation-server +client = 606-version-negotiation-client + +[606-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[606-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-606] +ExpectedResult = ServerFail + + +# =========================================================== + +[607-version-negotiation] +ssl_conf = 607-version-negotiation-ssl + +[607-version-negotiation-ssl] +server = 607-version-negotiation-server +client = 607-version-negotiation-client + +[607-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[607-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-607] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[608-version-negotiation] +ssl_conf = 608-version-negotiation-ssl + +[608-version-negotiation-ssl] +server = 608-version-negotiation-server +client = 608-version-negotiation-client + +[608-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[608-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-608] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[609-version-negotiation] +ssl_conf = 609-version-negotiation-ssl + +[609-version-negotiation-ssl] +server = 609-version-negotiation-server +client = 609-version-negotiation-client + +[609-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[609-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-609] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[610-version-negotiation] +ssl_conf = 610-version-negotiation-ssl + +[610-version-negotiation-ssl] +server = 610-version-negotiation-server +client = 610-version-negotiation-client + +[610-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[610-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-610] +ExpectedResult = ServerFail + + +# =========================================================== + +[611-version-negotiation] +ssl_conf = 611-version-negotiation-ssl + +[611-version-negotiation-ssl] +server = 611-version-negotiation-server +client = 611-version-negotiation-client + +[611-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[611-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-611] +ExpectedResult = ServerFail + + +# =========================================================== + +[612-version-negotiation] +ssl_conf = 612-version-negotiation-ssl + +[612-version-negotiation-ssl] +server = 612-version-negotiation-server +client = 612-version-negotiation-client + +[612-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[612-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-612] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[613-version-negotiation] +ssl_conf = 613-version-negotiation-ssl + +[613-version-negotiation-ssl] +server = 613-version-negotiation-server +client = 613-version-negotiation-client + +[613-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[613-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-613] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[614-version-negotiation] +ssl_conf = 614-version-negotiation-ssl + +[614-version-negotiation-ssl] +server = 614-version-negotiation-server +client = 614-version-negotiation-client + +[614-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[614-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-614] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[615-version-negotiation] +ssl_conf = 615-version-negotiation-ssl + +[615-version-negotiation-ssl] +server = 615-version-negotiation-server +client = 615-version-negotiation-client + +[615-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[615-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-615] +ExpectedResult = ServerFail + + +# =========================================================== + +[616-version-negotiation] +ssl_conf = 616-version-negotiation-ssl + +[616-version-negotiation-ssl] +server = 616-version-negotiation-server +client = 616-version-negotiation-client + +[616-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[616-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-616] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[617-version-negotiation] +ssl_conf = 617-version-negotiation-ssl + +[617-version-negotiation-ssl] +server = 617-version-negotiation-server +client = 617-version-negotiation-client + +[617-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[617-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-617] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[618-version-negotiation] +ssl_conf = 618-version-negotiation-ssl + +[618-version-negotiation-ssl] +server = 618-version-negotiation-server +client = 618-version-negotiation-client + +[618-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[618-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-618] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[619-version-negotiation] +ssl_conf = 619-version-negotiation-ssl + +[619-version-negotiation-ssl] +server = 619-version-negotiation-server +client = 619-version-negotiation-client + +[619-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[619-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-619] +ExpectedProtocol = TLSv1.2 +ExpectedResult = Success + + +# =========================================================== + +[620-version-negotiation] +ssl_conf = 620-version-negotiation-ssl + +[620-version-negotiation-ssl] +server = 620-version-negotiation-server +client = 620-version-negotiation-client + +[620-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[620-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-620] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[621-version-negotiation] +ssl_conf = 621-version-negotiation-ssl + +[621-version-negotiation-ssl] +server = 621-version-negotiation-server +client = 621-version-negotiation-client + +[621-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[621-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-621] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[622-version-negotiation] +ssl_conf = 622-version-negotiation-ssl + +[622-version-negotiation-ssl] +server = 622-version-negotiation-server +client = 622-version-negotiation-client + +[622-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[622-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-622] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[623-version-negotiation] +ssl_conf = 623-version-negotiation-ssl + +[623-version-negotiation-ssl] +server = 623-version-negotiation-server +client = 623-version-negotiation-client + +[623-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[623-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-623] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[624-version-negotiation] +ssl_conf = 624-version-negotiation-ssl + +[624-version-negotiation-ssl] +server = 624-version-negotiation-server +client = 624-version-negotiation-client + +[624-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[624-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-624] +ExpectedResult = ServerFail + + +# =========================================================== + +[625-version-negotiation] +ssl_conf = 625-version-negotiation-ssl + +[625-version-negotiation-ssl] +server = 625-version-negotiation-server +client = 625-version-negotiation-client + +[625-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[625-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-625] +ExpectedResult = ServerFail + + +# =========================================================== + +[626-version-negotiation] +ssl_conf = 626-version-negotiation-ssl + +[626-version-negotiation-ssl] +server = 626-version-negotiation-server +client = 626-version-negotiation-client + +[626-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[626-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-626] +ExpectedResult = ServerFail + + +# =========================================================== + +[627-version-negotiation] +ssl_conf = 627-version-negotiation-ssl + +[627-version-negotiation-ssl] +server = 627-version-negotiation-server +client = 627-version-negotiation-client + +[627-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[627-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-627] +ExpectedResult = ServerFail + + +# =========================================================== + +[628-version-negotiation] +ssl_conf = 628-version-negotiation-ssl + +[628-version-negotiation-ssl] +server = 628-version-negotiation-server +client = 628-version-negotiation-client + +[628-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[628-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-628] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[629-version-negotiation] +ssl_conf = 629-version-negotiation-ssl + +[629-version-negotiation-ssl] +server = 629-version-negotiation-server +client = 629-version-negotiation-client + +[629-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[629-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-629] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[630-version-negotiation] +ssl_conf = 630-version-negotiation-ssl + +[630-version-negotiation-ssl] +server = 630-version-negotiation-server +client = 630-version-negotiation-client + +[630-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[630-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-630] +ExpectedResult = ServerFail + + +# =========================================================== + +[631-version-negotiation] +ssl_conf = 631-version-negotiation-ssl + +[631-version-negotiation-ssl] +server = 631-version-negotiation-server +client = 631-version-negotiation-client + +[631-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[631-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-631] +ExpectedResult = ServerFail + + +# =========================================================== + +[632-version-negotiation] +ssl_conf = 632-version-negotiation-ssl + +[632-version-negotiation-ssl] +server = 632-version-negotiation-server +client = 632-version-negotiation-client + +[632-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[632-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-632] +ExpectedResult = ServerFail + + +# =========================================================== + +[633-version-negotiation] +ssl_conf = 633-version-negotiation-ssl + +[633-version-negotiation-ssl] +server = 633-version-negotiation-server +client = 633-version-negotiation-client + +[633-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[633-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-633] +ExpectedResult = ServerFail + + +# =========================================================== + +[634-version-negotiation] +ssl_conf = 634-version-negotiation-ssl + +[634-version-negotiation-ssl] +server = 634-version-negotiation-server +client = 634-version-negotiation-client + +[634-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[634-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-634] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[635-version-negotiation] +ssl_conf = 635-version-negotiation-ssl + +[635-version-negotiation-ssl] +server = 635-version-negotiation-server +client = 635-version-negotiation-client + +[635-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[635-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-635] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[636-version-negotiation] +ssl_conf = 636-version-negotiation-ssl + +[636-version-negotiation-ssl] +server = 636-version-negotiation-server +client = 636-version-negotiation-client + +[636-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[636-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-636] +ExpectedResult = ServerFail + + +# =========================================================== + +[637-version-negotiation] +ssl_conf = 637-version-negotiation-ssl + +[637-version-negotiation-ssl] +server = 637-version-negotiation-server +client = 637-version-negotiation-client + +[637-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[637-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-637] +ExpectedResult = ServerFail + + +# =========================================================== + +[638-version-negotiation] +ssl_conf = 638-version-negotiation-ssl + +[638-version-negotiation-ssl] +server = 638-version-negotiation-server +client = 638-version-negotiation-client + +[638-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[638-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-638] +ExpectedResult = ServerFail + + +# =========================================================== + +[639-version-negotiation] +ssl_conf = 639-version-negotiation-ssl + +[639-version-negotiation-ssl] +server = 639-version-negotiation-server +client = 639-version-negotiation-client + +[639-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[639-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-639] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[640-version-negotiation] +ssl_conf = 640-version-negotiation-ssl + +[640-version-negotiation-ssl] +server = 640-version-negotiation-server +client = 640-version-negotiation-client + +[640-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[640-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-640] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[641-version-negotiation] +ssl_conf = 641-version-negotiation-ssl + +[641-version-negotiation-ssl] +server = 641-version-negotiation-server +client = 641-version-negotiation-client + +[641-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[641-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-641] +ExpectedResult = ServerFail + + +# =========================================================== + +[642-version-negotiation] +ssl_conf = 642-version-negotiation-ssl + +[642-version-negotiation-ssl] +server = 642-version-negotiation-server +client = 642-version-negotiation-client + +[642-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[642-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-642] +ExpectedResult = ServerFail + + +# =========================================================== + +[643-version-negotiation] +ssl_conf = 643-version-negotiation-ssl + +[643-version-negotiation-ssl] +server = 643-version-negotiation-server +client = 643-version-negotiation-client + +[643-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[643-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-643] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[644-version-negotiation] +ssl_conf = 644-version-negotiation-ssl + +[644-version-negotiation-ssl] +server = 644-version-negotiation-server +client = 644-version-negotiation-client + +[644-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[644-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-644] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[645-version-negotiation] +ssl_conf = 645-version-negotiation-ssl + +[645-version-negotiation-ssl] +server = 645-version-negotiation-server +client = 645-version-negotiation-client + +[645-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[645-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-645] +ExpectedResult = ServerFail + + +# =========================================================== + +[646-version-negotiation] +ssl_conf = 646-version-negotiation-ssl + +[646-version-negotiation-ssl] +server = 646-version-negotiation-server +client = 646-version-negotiation-client + +[646-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[646-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-646] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[647-version-negotiation] +ssl_conf = 647-version-negotiation-ssl + +[647-version-negotiation-ssl] +server = 647-version-negotiation-server +client = 647-version-negotiation-client + +[647-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[647-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-647] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[648-version-negotiation] +ssl_conf = 648-version-negotiation-ssl + +[648-version-negotiation-ssl] +server = 648-version-negotiation-server +client = 648-version-negotiation-client + +[648-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[648-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-648] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[649-version-negotiation] +ssl_conf = 649-version-negotiation-ssl + +[649-version-negotiation-ssl] +server = 649-version-negotiation-server +client = 649-version-negotiation-client + +[649-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[649-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-649] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[650-version-negotiation] +ssl_conf = 650-version-negotiation-ssl + +[650-version-negotiation-ssl] +server = 650-version-negotiation-server +client = 650-version-negotiation-client + +[650-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[650-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-650] +ExpectedResult = ServerFail + + +# =========================================================== + +[651-version-negotiation] +ssl_conf = 651-version-negotiation-ssl + +[651-version-negotiation-ssl] +server = 651-version-negotiation-server +client = 651-version-negotiation-client + +[651-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[651-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-651] +ExpectedResult = ServerFail + + +# =========================================================== + +[652-version-negotiation] +ssl_conf = 652-version-negotiation-ssl + +[652-version-negotiation-ssl] +server = 652-version-negotiation-server +client = 652-version-negotiation-client + +[652-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[652-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-652] +ExpectedResult = ServerFail + + +# =========================================================== + +[653-version-negotiation] +ssl_conf = 653-version-negotiation-ssl + +[653-version-negotiation-ssl] +server = 653-version-negotiation-server +client = 653-version-negotiation-client + +[653-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[653-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-653] +ExpectedResult = ServerFail + + +# =========================================================== + +[654-version-negotiation] +ssl_conf = 654-version-negotiation-ssl + +[654-version-negotiation-ssl] +server = 654-version-negotiation-server +client = 654-version-negotiation-client + +[654-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[654-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-654] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[655-version-negotiation] +ssl_conf = 655-version-negotiation-ssl + +[655-version-negotiation-ssl] +server = 655-version-negotiation-server +client = 655-version-negotiation-client + +[655-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[655-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-655] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[656-version-negotiation] +ssl_conf = 656-version-negotiation-ssl + +[656-version-negotiation-ssl] +server = 656-version-negotiation-server +client = 656-version-negotiation-client + +[656-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = SSLv3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[656-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-656] +ExpectedResult = ServerFail + + +# =========================================================== + +[657-version-negotiation] +ssl_conf = 657-version-negotiation-ssl + +[657-version-negotiation-ssl] +server = 657-version-negotiation-server +client = 657-version-negotiation-client + +[657-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[657-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-657] +ExpectedResult = ServerFail + + +# =========================================================== + +[658-version-negotiation] +ssl_conf = 658-version-negotiation-ssl + +[658-version-negotiation-ssl] +server = 658-version-negotiation-server +client = 658-version-negotiation-client + +[658-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[658-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-658] +ExpectedResult = ServerFail + + +# =========================================================== + +[659-version-negotiation] +ssl_conf = 659-version-negotiation-ssl + +[659-version-negotiation-ssl] +server = 659-version-negotiation-server +client = 659-version-negotiation-client + +[659-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[659-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-659] +ExpectedResult = ServerFail + + +# =========================================================== + +[660-version-negotiation] +ssl_conf = 660-version-negotiation-ssl + +[660-version-negotiation-ssl] +server = 660-version-negotiation-server +client = 660-version-negotiation-client + +[660-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[660-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-660] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[661-version-negotiation] +ssl_conf = 661-version-negotiation-ssl + +[661-version-negotiation-ssl] +server = 661-version-negotiation-server +client = 661-version-negotiation-client + +[661-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = SSLv3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[661-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-661] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[662-version-negotiation] +ssl_conf = 662-version-negotiation-ssl + +[662-version-negotiation-ssl] +server = 662-version-negotiation-server +client = 662-version-negotiation-client + +[662-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[662-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-662] +ExpectedResult = ServerFail + + +# =========================================================== + +[663-version-negotiation] +ssl_conf = 663-version-negotiation-ssl + +[663-version-negotiation-ssl] +server = 663-version-negotiation-server +client = 663-version-negotiation-client + +[663-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[663-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-663] +ExpectedResult = ServerFail + + +# =========================================================== + +[664-version-negotiation] +ssl_conf = 664-version-negotiation-ssl + +[664-version-negotiation-ssl] +server = 664-version-negotiation-server +client = 664-version-negotiation-client + +[664-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[664-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-664] +ExpectedResult = ServerFail + + +# =========================================================== + +[665-version-negotiation] +ssl_conf = 665-version-negotiation-ssl + +[665-version-negotiation-ssl] +server = 665-version-negotiation-server +client = 665-version-negotiation-client + +[665-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[665-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-665] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[666-version-negotiation] +ssl_conf = 666-version-negotiation-ssl + +[666-version-negotiation-ssl] +server = 666-version-negotiation-server +client = 666-version-negotiation-client + +[666-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[666-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-666] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[667-version-negotiation] +ssl_conf = 667-version-negotiation-ssl + +[667-version-negotiation-ssl] +server = 667-version-negotiation-server +client = 667-version-negotiation-client + +[667-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[667-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-667] +ExpectedResult = ServerFail + + +# =========================================================== + +[668-version-negotiation] +ssl_conf = 668-version-negotiation-ssl + +[668-version-negotiation-ssl] +server = 668-version-negotiation-server +client = 668-version-negotiation-client + +[668-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[668-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-668] +ExpectedResult = ServerFail + + +# =========================================================== + +[669-version-negotiation] +ssl_conf = 669-version-negotiation-ssl + +[669-version-negotiation-ssl] +server = 669-version-negotiation-server +client = 669-version-negotiation-client + +[669-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[669-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-669] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[670-version-negotiation] +ssl_conf = 670-version-negotiation-ssl + +[670-version-negotiation-ssl] +server = 670-version-negotiation-server +client = 670-version-negotiation-client + +[670-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.1 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[670-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-670] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[671-version-negotiation] +ssl_conf = 671-version-negotiation-ssl + +[671-version-negotiation-ssl] +server = 671-version-negotiation-server +client = 671-version-negotiation-client + +[671-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.2 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[671-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-671] +ExpectedResult = ServerFail + + +# =========================================================== + +[672-version-negotiation] +ssl_conf = 672-version-negotiation-ssl + +[672-version-negotiation-ssl] +server = 672-version-negotiation-server +client = 672-version-negotiation-client + +[672-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[672-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-672] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[673-version-negotiation] +ssl_conf = 673-version-negotiation-ssl + +[673-version-negotiation-ssl] +server = 673-version-negotiation-server +client = 673-version-negotiation-client + +[673-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[673-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-673] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[674-version-negotiation] +ssl_conf = 674-version-negotiation-ssl + +[674-version-negotiation-ssl] +server = 674-version-negotiation-server +client = 674-version-negotiation-client + +[674-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[674-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-674] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[675-version-negotiation] +ssl_conf = 675-version-negotiation-ssl + +[675-version-negotiation-ssl] +server = 675-version-negotiation-server +client = 675-version-negotiation-client + +[675-version-negotiation-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[675-version-negotiation-client] +CipherString = DEFAULT:@SECLEVEL=0 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-675] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success + + +# =========================================================== + +[676-ciphersuite-sanity-check-client] +ssl_conf = 676-ciphersuite-sanity-check-client-ssl + +[676-ciphersuite-sanity-check-client-ssl] +server = 676-ciphersuite-sanity-check-client-server +client = 676-ciphersuite-sanity-check-client-client + +[676-ciphersuite-sanity-check-client-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT +MaxProtocol = TLSv1.2 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[676-ciphersuite-sanity-check-client-client] +CipherString = AES128-SHA +Ciphersuites = +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-676] +ExpectedResult = ClientFail + + +# =========================================================== + +[677-ciphersuite-sanity-check-server] +ssl_conf = 677-ciphersuite-sanity-check-server-ssl + +[677-ciphersuite-sanity-check-server-ssl] +server = 677-ciphersuite-sanity-check-server-server +client = 677-ciphersuite-sanity-check-server-client + +[677-ciphersuite-sanity-check-server-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = AES128-SHA +Ciphersuites = +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[677-ciphersuite-sanity-check-server-client] +CipherString = AES128-SHA +MaxProtocol = TLSv1.2 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-677] +ExpectedResult = ServerFail + + diff --git a/test/ssl-tests/04-client_auth.cnf.in b/test/ssl-tests/04-client_auth.cnf.in index 9337b91b8a..ba170bbfb8 100644 --- a/test/ssl-tests/04-client_auth.cnf.in +++ b/test/ssl-tests/04-client_auth.cnf.in @@ -21,8 +21,8 @@ if ($fips_mode) { @protocols = (undef, "TLSv1.2", "DTLSv1.2"); push @is_disabled, anydisabled("tls1_2", "dtls1_2"); } else { - @protocols = (undef, "TLSv1", "TLSv1.1", "TLSv1.2", "DTLSv1", "DTLSv1.2"); - push @is_disabled, anydisabled("tls1", "tls1_1", "tls1_2", "dtls1", "dtls1_2"); + @protocols = (undef, "SSLv3", "TLSv1", "TLSv1.1", "TLSv1.2", "DTLSv1", "DTLSv1.2"); + push @is_disabled, anydisabled("ssl3", "tls1", "tls1_1", "tls1_2", "dtls1", "dtls1_2"); } our @tests = (); @@ -47,7 +47,11 @@ sub generate_tests() { my $method; my $sctpenabled = 0; if (!$is_disabled[$_]) { - $caalert = "UnknownCA"; + if ($protocol_name eq "SSLv3") { + $caalert = "BadCertificate"; + } else { + $caalert = "UnknownCA"; + } if ($protocol_name =~ m/^DTLS/) { $method = "DTLS"; $sctpenabled = 1 if !disabled("sctp"); diff --git a/test/ssl-tests/14-curves.cnf b/test/ssl-tests/14-curves.cnf index 5a215d5b4e..e075a37943 100644 --- a/test/ssl-tests/14-curves.cnf +++ b/test/ssl-tests/14-curves.cnf @@ -1,6 +1,6 @@ # Generated with generate_ssl_tests.pl -num_tests = 119 +num_tests = 104 test-0 = 0-curve-prime256v1 test-1 = 1-curve-secp384r1 @@ -15,112 +15,97 @@ test-9 = 9-curve-ffdhe8192 test-10 = 10-curve-brainpoolP256r1tls13 test-11 = 11-curve-brainpoolP384r1tls13 test-12 = 12-curve-brainpoolP512r1tls13 -test-13 = 13-curve-X25519MLKEM768 -test-14 = 14-curve-SecP256r1MLKEM768 -test-15 = 15-curve-SecP384r1MLKEM1024 -test-16 = 16-curve-curveSM2 -test-17 = 17-curve-curveSM2MLKEM768 -test-18 = 18-curve-sect233k1 -test-19 = 19-curve-sect233r1 -test-20 = 20-curve-sect283k1 -test-21 = 21-curve-sect283r1 -test-22 = 22-curve-sect409k1 -test-23 = 23-curve-sect409r1 -test-24 = 24-curve-sect571k1 -test-25 = 25-curve-sect571r1 -test-26 = 26-curve-secp224r1 -test-27 = 27-curve-sect163k1 -test-28 = 28-curve-sect163r2 -test-29 = 29-curve-prime192v1 -test-30 = 30-curve-sect163r1 -test-31 = 31-curve-sect193r1 -test-32 = 32-curve-sect193r2 -test-33 = 33-curve-sect239k1 -test-34 = 34-curve-secp160k1 -test-35 = 35-curve-secp160r1 -test-36 = 36-curve-secp160r2 -test-37 = 37-curve-secp192k1 -test-38 = 38-curve-secp224k1 -test-39 = 39-curve-secp256k1 -test-40 = 40-curve-brainpoolP256r1 -test-41 = 41-curve-brainpoolP384r1 -test-42 = 42-curve-brainpoolP512r1 -test-43 = 43-curve-sect233k1-tls12-in-tls13 -test-44 = 44-curve-sect233r1-tls12-in-tls13 -test-45 = 45-curve-sect283k1-tls12-in-tls13 -test-46 = 46-curve-sect283r1-tls12-in-tls13 -test-47 = 47-curve-sect409k1-tls12-in-tls13 -test-48 = 48-curve-sect409r1-tls12-in-tls13 -test-49 = 49-curve-sect571k1-tls12-in-tls13 -test-50 = 50-curve-sect571r1-tls12-in-tls13 -test-51 = 51-curve-secp224r1-tls12-in-tls13 -test-52 = 52-curve-sect163k1-tls12-in-tls13 -test-53 = 53-curve-sect163r2-tls12-in-tls13 -test-54 = 54-curve-prime192v1-tls12-in-tls13 -test-55 = 55-curve-sect163r1-tls12-in-tls13 -test-56 = 56-curve-sect193r1-tls12-in-tls13 -test-57 = 57-curve-sect193r2-tls12-in-tls13 -test-58 = 58-curve-sect239k1-tls12-in-tls13 -test-59 = 59-curve-secp160k1-tls12-in-tls13 -test-60 = 60-curve-secp160r1-tls12-in-tls13 -test-61 = 61-curve-secp160r2-tls12-in-tls13 -test-62 = 62-curve-secp192k1-tls12-in-tls13 -test-63 = 63-curve-secp224k1-tls12-in-tls13 -test-64 = 64-curve-secp256k1-tls12-in-tls13 -test-65 = 65-curve-brainpoolP256r1-tls12-in-tls13 -test-66 = 66-curve-brainpoolP384r1-tls12-in-tls13 -test-67 = 67-curve-brainpoolP512r1-tls12-in-tls13 -test-68 = 68-curve-sect233k1-tls13 -test-69 = 69-curve-sect233r1-tls13 -test-70 = 70-curve-sect283k1-tls13 -test-71 = 71-curve-sect283r1-tls13 -test-72 = 72-curve-sect409k1-tls13 -test-73 = 73-curve-sect409r1-tls13 -test-74 = 74-curve-sect571k1-tls13 -test-75 = 75-curve-sect571r1-tls13 -test-76 = 76-curve-secp224r1-tls13 -test-77 = 77-curve-sect163k1-tls13 -test-78 = 78-curve-sect163r2-tls13 -test-79 = 79-curve-prime192v1-tls13 -test-80 = 80-curve-sect163r1-tls13 -test-81 = 81-curve-sect193r1-tls13 -test-82 = 82-curve-sect193r2-tls13 -test-83 = 83-curve-sect239k1-tls13 -test-84 = 84-curve-secp160k1-tls13 -test-85 = 85-curve-secp160r1-tls13 -test-86 = 86-curve-secp160r2-tls13 -test-87 = 87-curve-secp192k1-tls13 -test-88 = 88-curve-secp224k1-tls13 -test-89 = 89-curve-secp256k1-tls13 -test-90 = 90-curve-brainpoolP256r1-tls13 -test-91 = 91-curve-brainpoolP384r1-tls13 -test-92 = 92-curve-brainpoolP512r1-tls13 -test-93 = 93-curve-ffdhe2048-tls13-in-tls12 -test-94 = 94-curve-ffdhe2048-tls13-in-tls12-2 -test-95 = 95-curve-ffdhe3072-tls13-in-tls12 -test-96 = 96-curve-ffdhe3072-tls13-in-tls12-2 -test-97 = 97-curve-ffdhe4096-tls13-in-tls12 -test-98 = 98-curve-ffdhe4096-tls13-in-tls12-2 -test-99 = 99-curve-ffdhe6144-tls13-in-tls12 -test-100 = 100-curve-ffdhe6144-tls13-in-tls12-2 -test-101 = 101-curve-ffdhe8192-tls13-in-tls12 -test-102 = 102-curve-ffdhe8192-tls13-in-tls12-2 -test-103 = 103-curve-brainpoolP256r1tls13-tls13-in-tls12 -test-104 = 104-curve-brainpoolP256r1tls13-tls13-in-tls12-2 -test-105 = 105-curve-brainpoolP384r1tls13-tls13-in-tls12 -test-106 = 106-curve-brainpoolP384r1tls13-tls13-in-tls12-2 -test-107 = 107-curve-brainpoolP512r1tls13-tls13-in-tls12 -test-108 = 108-curve-brainpoolP512r1tls13-tls13-in-tls12-2 -test-109 = 109-curve-X25519MLKEM768-tls13-in-tls12 -test-110 = 110-curve-X25519MLKEM768-tls13-in-tls12-2 -test-111 = 111-curve-SecP256r1MLKEM768-tls13-in-tls12 -test-112 = 112-curve-SecP256r1MLKEM768-tls13-in-tls12-2 -test-113 = 113-curve-SecP384r1MLKEM1024-tls13-in-tls12 -test-114 = 114-curve-SecP384r1MLKEM1024-tls13-in-tls12-2 -test-115 = 115-curve-curveSM2-tls13-in-tls12 -test-116 = 116-curve-curveSM2-tls13-in-tls12-2 -test-117 = 117-curve-curveSM2MLKEM768-tls13-in-tls12 -test-118 = 118-curve-curveSM2MLKEM768-tls13-in-tls12-2 +test-13 = 13-curve-sect233k1 +test-14 = 14-curve-sect233r1 +test-15 = 15-curve-sect283k1 +test-16 = 16-curve-sect283r1 +test-17 = 17-curve-sect409k1 +test-18 = 18-curve-sect409r1 +test-19 = 19-curve-sect571k1 +test-20 = 20-curve-sect571r1 +test-21 = 21-curve-secp224r1 +test-22 = 22-curve-sect163k1 +test-23 = 23-curve-sect163r2 +test-24 = 24-curve-prime192v1 +test-25 = 25-curve-sect163r1 +test-26 = 26-curve-sect193r1 +test-27 = 27-curve-sect193r2 +test-28 = 28-curve-sect239k1 +test-29 = 29-curve-secp160k1 +test-30 = 30-curve-secp160r1 +test-31 = 31-curve-secp160r2 +test-32 = 32-curve-secp192k1 +test-33 = 33-curve-secp224k1 +test-34 = 34-curve-secp256k1 +test-35 = 35-curve-brainpoolP256r1 +test-36 = 36-curve-brainpoolP384r1 +test-37 = 37-curve-brainpoolP512r1 +test-38 = 38-curve-sect233k1-tls12-in-tls13 +test-39 = 39-curve-sect233r1-tls12-in-tls13 +test-40 = 40-curve-sect283k1-tls12-in-tls13 +test-41 = 41-curve-sect283r1-tls12-in-tls13 +test-42 = 42-curve-sect409k1-tls12-in-tls13 +test-43 = 43-curve-sect409r1-tls12-in-tls13 +test-44 = 44-curve-sect571k1-tls12-in-tls13 +test-45 = 45-curve-sect571r1-tls12-in-tls13 +test-46 = 46-curve-secp224r1-tls12-in-tls13 +test-47 = 47-curve-sect163k1-tls12-in-tls13 +test-48 = 48-curve-sect163r2-tls12-in-tls13 +test-49 = 49-curve-prime192v1-tls12-in-tls13 +test-50 = 50-curve-sect163r1-tls12-in-tls13 +test-51 = 51-curve-sect193r1-tls12-in-tls13 +test-52 = 52-curve-sect193r2-tls12-in-tls13 +test-53 = 53-curve-sect239k1-tls12-in-tls13 +test-54 = 54-curve-secp160k1-tls12-in-tls13 +test-55 = 55-curve-secp160r1-tls12-in-tls13 +test-56 = 56-curve-secp160r2-tls12-in-tls13 +test-57 = 57-curve-secp192k1-tls12-in-tls13 +test-58 = 58-curve-secp224k1-tls12-in-tls13 +test-59 = 59-curve-secp256k1-tls12-in-tls13 +test-60 = 60-curve-brainpoolP256r1-tls12-in-tls13 +test-61 = 61-curve-brainpoolP384r1-tls12-in-tls13 +test-62 = 62-curve-brainpoolP512r1-tls12-in-tls13 +test-63 = 63-curve-sect233k1-tls13 +test-64 = 64-curve-sect233r1-tls13 +test-65 = 65-curve-sect283k1-tls13 +test-66 = 66-curve-sect283r1-tls13 +test-67 = 67-curve-sect409k1-tls13 +test-68 = 68-curve-sect409r1-tls13 +test-69 = 69-curve-sect571k1-tls13 +test-70 = 70-curve-sect571r1-tls13 +test-71 = 71-curve-secp224r1-tls13 +test-72 = 72-curve-sect163k1-tls13 +test-73 = 73-curve-sect163r2-tls13 +test-74 = 74-curve-prime192v1-tls13 +test-75 = 75-curve-sect163r1-tls13 +test-76 = 76-curve-sect193r1-tls13 +test-77 = 77-curve-sect193r2-tls13 +test-78 = 78-curve-sect239k1-tls13 +test-79 = 79-curve-secp160k1-tls13 +test-80 = 80-curve-secp160r1-tls13 +test-81 = 81-curve-secp160r2-tls13 +test-82 = 82-curve-secp192k1-tls13 +test-83 = 83-curve-secp224k1-tls13 +test-84 = 84-curve-secp256k1-tls13 +test-85 = 85-curve-brainpoolP256r1-tls13 +test-86 = 86-curve-brainpoolP384r1-tls13 +test-87 = 87-curve-brainpoolP512r1-tls13 +test-88 = 88-curve-ffdhe2048-tls13-in-tls12 +test-89 = 89-curve-ffdhe2048-tls13-in-tls12-2 +test-90 = 90-curve-ffdhe3072-tls13-in-tls12 +test-91 = 91-curve-ffdhe3072-tls13-in-tls12-2 +test-92 = 92-curve-ffdhe4096-tls13-in-tls12 +test-93 = 93-curve-ffdhe4096-tls13-in-tls12-2 +test-94 = 94-curve-ffdhe6144-tls13-in-tls12 +test-95 = 95-curve-ffdhe6144-tls13-in-tls12-2 +test-96 = 96-curve-ffdhe8192-tls13-in-tls12 +test-97 = 97-curve-ffdhe8192-tls13-in-tls12-2 +test-98 = 98-curve-brainpoolP256r1tls13-tls13-in-tls12 +test-99 = 99-curve-brainpoolP256r1tls13-tls13-in-tls12-2 +test-100 = 100-curve-brainpoolP384r1tls13-tls13-in-tls12 +test-101 = 101-curve-brainpoolP384r1tls13-tls13-in-tls12-2 +test-102 = 102-curve-brainpoolP512r1tls13-tls13-in-tls12 +test-103 = 103-curve-brainpoolP512r1tls13-tls13-in-tls12-2 # =========================================================== [0-curve-prime256v1] @@ -500,173 +485,28 @@ ExpectedTmpKeyType = brainpoolP512r1tls13 # =========================================================== -[13-curve-X25519MLKEM768] -ssl_conf = 13-curve-X25519MLKEM768-ssl +[13-curve-sect233k1] +ssl_conf = 13-curve-sect233k1-ssl -[13-curve-X25519MLKEM768-ssl] -server = 13-curve-X25519MLKEM768-server -client = 13-curve-X25519MLKEM768-client +[13-curve-sect233k1-ssl] +server = 13-curve-sect233k1-server +client = 13-curve-sect233k1-client -[13-curve-X25519MLKEM768-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = X25519MLKEM768 -MaxProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[13-curve-X25519MLKEM768-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = X25519MLKEM768 -MaxProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-13] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success -ExpectedTmpKeyType = X25519MLKEM768 - - -# =========================================================== - -[14-curve-SecP256r1MLKEM768] -ssl_conf = 14-curve-SecP256r1MLKEM768-ssl - -[14-curve-SecP256r1MLKEM768-ssl] -server = 14-curve-SecP256r1MLKEM768-server -client = 14-curve-SecP256r1MLKEM768-client - -[14-curve-SecP256r1MLKEM768-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = SecP256r1MLKEM768 -MaxProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[14-curve-SecP256r1MLKEM768-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = SecP256r1MLKEM768 -MaxProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-14] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success -ExpectedTmpKeyType = SecP256r1MLKEM768 - - -# =========================================================== - -[15-curve-SecP384r1MLKEM1024] -ssl_conf = 15-curve-SecP384r1MLKEM1024-ssl - -[15-curve-SecP384r1MLKEM1024-ssl] -server = 15-curve-SecP384r1MLKEM1024-server -client = 15-curve-SecP384r1MLKEM1024-client - -[15-curve-SecP384r1MLKEM1024-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = SecP384r1MLKEM1024 -MaxProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[15-curve-SecP384r1MLKEM1024-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = SecP384r1MLKEM1024 -MaxProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-15] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success -ExpectedTmpKeyType = SecP384r1MLKEM1024 - - -# =========================================================== - -[16-curve-curveSM2] -ssl_conf = 16-curve-curveSM2-ssl - -[16-curve-curveSM2-ssl] -server = 16-curve-curveSM2-server -client = 16-curve-curveSM2-client - -[16-curve-curveSM2-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = curveSM2 -MaxProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[16-curve-curveSM2-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = curveSM2 -MaxProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-16] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success -ExpectedTmpKeyType = curveSM2 - - -# =========================================================== - -[17-curve-curveSM2MLKEM768] -ssl_conf = 17-curve-curveSM2MLKEM768-ssl - -[17-curve-curveSM2MLKEM768-ssl] -server = 17-curve-curveSM2MLKEM768-server -client = 17-curve-curveSM2MLKEM768-client - -[17-curve-curveSM2MLKEM768-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = curveSM2MLKEM768 -MaxProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[17-curve-curveSM2MLKEM768-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = curveSM2MLKEM768 -MaxProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-17] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success -ExpectedTmpKeyType = curveSM2MLKEM768 - - -# =========================================================== - -[18-curve-sect233k1] -ssl_conf = 18-curve-sect233k1-ssl - -[18-curve-sect233k1-ssl] -server = 18-curve-sect233k1-server -client = 18-curve-sect233k1-client - -[18-curve-sect233k1-server] +[13-curve-sect233k1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = sect233k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[18-curve-sect233k1-client] +[13-curve-sect233k1-client] CipherString = ECDHE@SECLEVEL=1 Curves = sect233k1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-18] +[test-13] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = sect233k1 @@ -674,28 +514,28 @@ ExpectedTmpKeyType = sect233k1 # =========================================================== -[19-curve-sect233r1] -ssl_conf = 19-curve-sect233r1-ssl +[14-curve-sect233r1] +ssl_conf = 14-curve-sect233r1-ssl -[19-curve-sect233r1-ssl] -server = 19-curve-sect233r1-server -client = 19-curve-sect233r1-client +[14-curve-sect233r1-ssl] +server = 14-curve-sect233r1-server +client = 14-curve-sect233r1-client -[19-curve-sect233r1-server] +[14-curve-sect233r1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = sect233r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[19-curve-sect233r1-client] +[14-curve-sect233r1-client] CipherString = ECDHE@SECLEVEL=1 Curves = sect233r1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-19] +[test-14] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = sect233r1 @@ -703,28 +543,28 @@ ExpectedTmpKeyType = sect233r1 # =========================================================== -[20-curve-sect283k1] -ssl_conf = 20-curve-sect283k1-ssl +[15-curve-sect283k1] +ssl_conf = 15-curve-sect283k1-ssl -[20-curve-sect283k1-ssl] -server = 20-curve-sect283k1-server -client = 20-curve-sect283k1-client +[15-curve-sect283k1-ssl] +server = 15-curve-sect283k1-server +client = 15-curve-sect283k1-client -[20-curve-sect283k1-server] +[15-curve-sect283k1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = sect283k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[20-curve-sect283k1-client] +[15-curve-sect283k1-client] CipherString = ECDHE@SECLEVEL=1 Curves = sect283k1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-20] +[test-15] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = sect283k1 @@ -732,28 +572,28 @@ ExpectedTmpKeyType = sect283k1 # =========================================================== -[21-curve-sect283r1] -ssl_conf = 21-curve-sect283r1-ssl +[16-curve-sect283r1] +ssl_conf = 16-curve-sect283r1-ssl -[21-curve-sect283r1-ssl] -server = 21-curve-sect283r1-server -client = 21-curve-sect283r1-client +[16-curve-sect283r1-ssl] +server = 16-curve-sect283r1-server +client = 16-curve-sect283r1-client -[21-curve-sect283r1-server] +[16-curve-sect283r1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = sect283r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[21-curve-sect283r1-client] +[16-curve-sect283r1-client] CipherString = ECDHE@SECLEVEL=1 Curves = sect283r1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-21] +[test-16] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = sect283r1 @@ -761,28 +601,28 @@ ExpectedTmpKeyType = sect283r1 # =========================================================== -[22-curve-sect409k1] -ssl_conf = 22-curve-sect409k1-ssl +[17-curve-sect409k1] +ssl_conf = 17-curve-sect409k1-ssl -[22-curve-sect409k1-ssl] -server = 22-curve-sect409k1-server -client = 22-curve-sect409k1-client +[17-curve-sect409k1-ssl] +server = 17-curve-sect409k1-server +client = 17-curve-sect409k1-client -[22-curve-sect409k1-server] +[17-curve-sect409k1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = sect409k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[22-curve-sect409k1-client] +[17-curve-sect409k1-client] CipherString = ECDHE@SECLEVEL=1 Curves = sect409k1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-22] +[test-17] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = sect409k1 @@ -790,28 +630,28 @@ ExpectedTmpKeyType = sect409k1 # =========================================================== -[23-curve-sect409r1] -ssl_conf = 23-curve-sect409r1-ssl +[18-curve-sect409r1] +ssl_conf = 18-curve-sect409r1-ssl -[23-curve-sect409r1-ssl] -server = 23-curve-sect409r1-server -client = 23-curve-sect409r1-client +[18-curve-sect409r1-ssl] +server = 18-curve-sect409r1-server +client = 18-curve-sect409r1-client -[23-curve-sect409r1-server] +[18-curve-sect409r1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = sect409r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[23-curve-sect409r1-client] +[18-curve-sect409r1-client] CipherString = ECDHE@SECLEVEL=1 Curves = sect409r1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-23] +[test-18] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = sect409r1 @@ -819,28 +659,28 @@ ExpectedTmpKeyType = sect409r1 # =========================================================== -[24-curve-sect571k1] -ssl_conf = 24-curve-sect571k1-ssl +[19-curve-sect571k1] +ssl_conf = 19-curve-sect571k1-ssl -[24-curve-sect571k1-ssl] -server = 24-curve-sect571k1-server -client = 24-curve-sect571k1-client +[19-curve-sect571k1-ssl] +server = 19-curve-sect571k1-server +client = 19-curve-sect571k1-client -[24-curve-sect571k1-server] +[19-curve-sect571k1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = sect571k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[24-curve-sect571k1-client] +[19-curve-sect571k1-client] CipherString = ECDHE@SECLEVEL=1 Curves = sect571k1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-24] +[test-19] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = sect571k1 @@ -848,28 +688,28 @@ ExpectedTmpKeyType = sect571k1 # =========================================================== -[25-curve-sect571r1] -ssl_conf = 25-curve-sect571r1-ssl +[20-curve-sect571r1] +ssl_conf = 20-curve-sect571r1-ssl -[25-curve-sect571r1-ssl] -server = 25-curve-sect571r1-server -client = 25-curve-sect571r1-client +[20-curve-sect571r1-ssl] +server = 20-curve-sect571r1-server +client = 20-curve-sect571r1-client -[25-curve-sect571r1-server] +[20-curve-sect571r1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = sect571r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[25-curve-sect571r1-client] +[20-curve-sect571r1-client] CipherString = ECDHE@SECLEVEL=1 Curves = sect571r1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-25] +[test-20] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = sect571r1 @@ -877,28 +717,28 @@ ExpectedTmpKeyType = sect571r1 # =========================================================== -[26-curve-secp224r1] -ssl_conf = 26-curve-secp224r1-ssl +[21-curve-secp224r1] +ssl_conf = 21-curve-secp224r1-ssl -[26-curve-secp224r1-ssl] -server = 26-curve-secp224r1-server -client = 26-curve-secp224r1-client +[21-curve-secp224r1-ssl] +server = 21-curve-secp224r1-server +client = 21-curve-secp224r1-client -[26-curve-secp224r1-server] +[21-curve-secp224r1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = secp224r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[26-curve-secp224r1-client] +[21-curve-secp224r1-client] CipherString = ECDHE@SECLEVEL=1 Curves = secp224r1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-26] +[test-21] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = secp224r1 @@ -906,28 +746,28 @@ ExpectedTmpKeyType = secp224r1 # =========================================================== -[27-curve-sect163k1] -ssl_conf = 27-curve-sect163k1-ssl +[22-curve-sect163k1] +ssl_conf = 22-curve-sect163k1-ssl -[27-curve-sect163k1-ssl] -server = 27-curve-sect163k1-server -client = 27-curve-sect163k1-client +[22-curve-sect163k1-ssl] +server = 22-curve-sect163k1-server +client = 22-curve-sect163k1-client -[27-curve-sect163k1-server] +[22-curve-sect163k1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = sect163k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[27-curve-sect163k1-client] +[22-curve-sect163k1-client] CipherString = ECDHE@SECLEVEL=1 Curves = sect163k1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-27] +[test-22] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = sect163k1 @@ -935,28 +775,28 @@ ExpectedTmpKeyType = sect163k1 # =========================================================== -[28-curve-sect163r2] -ssl_conf = 28-curve-sect163r2-ssl +[23-curve-sect163r2] +ssl_conf = 23-curve-sect163r2-ssl -[28-curve-sect163r2-ssl] -server = 28-curve-sect163r2-server -client = 28-curve-sect163r2-client +[23-curve-sect163r2-ssl] +server = 23-curve-sect163r2-server +client = 23-curve-sect163r2-client -[28-curve-sect163r2-server] +[23-curve-sect163r2-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = sect163r2 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[28-curve-sect163r2-client] +[23-curve-sect163r2-client] CipherString = ECDHE@SECLEVEL=1 Curves = sect163r2 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-28] +[test-23] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = sect163r2 @@ -964,28 +804,28 @@ ExpectedTmpKeyType = sect163r2 # =========================================================== -[29-curve-prime192v1] -ssl_conf = 29-curve-prime192v1-ssl +[24-curve-prime192v1] +ssl_conf = 24-curve-prime192v1-ssl -[29-curve-prime192v1-ssl] -server = 29-curve-prime192v1-server -client = 29-curve-prime192v1-client +[24-curve-prime192v1-ssl] +server = 24-curve-prime192v1-server +client = 24-curve-prime192v1-client -[29-curve-prime192v1-server] +[24-curve-prime192v1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = prime192v1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[29-curve-prime192v1-client] +[24-curve-prime192v1-client] CipherString = ECDHE@SECLEVEL=1 Curves = prime192v1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-29] +[test-24] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = prime192v1 @@ -993,28 +833,28 @@ ExpectedTmpKeyType = prime192v1 # =========================================================== -[30-curve-sect163r1] -ssl_conf = 30-curve-sect163r1-ssl +[25-curve-sect163r1] +ssl_conf = 25-curve-sect163r1-ssl -[30-curve-sect163r1-ssl] -server = 30-curve-sect163r1-server -client = 30-curve-sect163r1-client +[25-curve-sect163r1-ssl] +server = 25-curve-sect163r1-server +client = 25-curve-sect163r1-client -[30-curve-sect163r1-server] +[25-curve-sect163r1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = sect163r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[30-curve-sect163r1-client] +[25-curve-sect163r1-client] CipherString = ECDHE@SECLEVEL=1 Curves = sect163r1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-30] +[test-25] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = sect163r1 @@ -1022,28 +862,28 @@ ExpectedTmpKeyType = sect163r1 # =========================================================== -[31-curve-sect193r1] -ssl_conf = 31-curve-sect193r1-ssl +[26-curve-sect193r1] +ssl_conf = 26-curve-sect193r1-ssl -[31-curve-sect193r1-ssl] -server = 31-curve-sect193r1-server -client = 31-curve-sect193r1-client +[26-curve-sect193r1-ssl] +server = 26-curve-sect193r1-server +client = 26-curve-sect193r1-client -[31-curve-sect193r1-server] +[26-curve-sect193r1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = sect193r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[31-curve-sect193r1-client] +[26-curve-sect193r1-client] CipherString = ECDHE@SECLEVEL=1 Curves = sect193r1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-31] +[test-26] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = sect193r1 @@ -1051,28 +891,28 @@ ExpectedTmpKeyType = sect193r1 # =========================================================== -[32-curve-sect193r2] -ssl_conf = 32-curve-sect193r2-ssl +[27-curve-sect193r2] +ssl_conf = 27-curve-sect193r2-ssl -[32-curve-sect193r2-ssl] -server = 32-curve-sect193r2-server -client = 32-curve-sect193r2-client +[27-curve-sect193r2-ssl] +server = 27-curve-sect193r2-server +client = 27-curve-sect193r2-client -[32-curve-sect193r2-server] +[27-curve-sect193r2-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = sect193r2 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[32-curve-sect193r2-client] +[27-curve-sect193r2-client] CipherString = ECDHE@SECLEVEL=1 Curves = sect193r2 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-32] +[test-27] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = sect193r2 @@ -1080,28 +920,28 @@ ExpectedTmpKeyType = sect193r2 # =========================================================== -[33-curve-sect239k1] -ssl_conf = 33-curve-sect239k1-ssl +[28-curve-sect239k1] +ssl_conf = 28-curve-sect239k1-ssl -[33-curve-sect239k1-ssl] -server = 33-curve-sect239k1-server -client = 33-curve-sect239k1-client +[28-curve-sect239k1-ssl] +server = 28-curve-sect239k1-server +client = 28-curve-sect239k1-client -[33-curve-sect239k1-server] +[28-curve-sect239k1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = sect239k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[33-curve-sect239k1-client] +[28-curve-sect239k1-client] CipherString = ECDHE@SECLEVEL=1 Curves = sect239k1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-33] +[test-28] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = sect239k1 @@ -1109,28 +949,28 @@ ExpectedTmpKeyType = sect239k1 # =========================================================== -[34-curve-secp160k1] -ssl_conf = 34-curve-secp160k1-ssl +[29-curve-secp160k1] +ssl_conf = 29-curve-secp160k1-ssl -[34-curve-secp160k1-ssl] -server = 34-curve-secp160k1-server -client = 34-curve-secp160k1-client +[29-curve-secp160k1-ssl] +server = 29-curve-secp160k1-server +client = 29-curve-secp160k1-client -[34-curve-secp160k1-server] +[29-curve-secp160k1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = secp160k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[34-curve-secp160k1-client] +[29-curve-secp160k1-client] CipherString = ECDHE@SECLEVEL=1 Curves = secp160k1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-34] +[test-29] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = secp160k1 @@ -1138,28 +978,28 @@ ExpectedTmpKeyType = secp160k1 # =========================================================== -[35-curve-secp160r1] -ssl_conf = 35-curve-secp160r1-ssl +[30-curve-secp160r1] +ssl_conf = 30-curve-secp160r1-ssl -[35-curve-secp160r1-ssl] -server = 35-curve-secp160r1-server -client = 35-curve-secp160r1-client +[30-curve-secp160r1-ssl] +server = 30-curve-secp160r1-server +client = 30-curve-secp160r1-client -[35-curve-secp160r1-server] +[30-curve-secp160r1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = secp160r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[35-curve-secp160r1-client] +[30-curve-secp160r1-client] CipherString = ECDHE@SECLEVEL=1 Curves = secp160r1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-35] +[test-30] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = secp160r1 @@ -1167,28 +1007,28 @@ ExpectedTmpKeyType = secp160r1 # =========================================================== -[36-curve-secp160r2] -ssl_conf = 36-curve-secp160r2-ssl +[31-curve-secp160r2] +ssl_conf = 31-curve-secp160r2-ssl -[36-curve-secp160r2-ssl] -server = 36-curve-secp160r2-server -client = 36-curve-secp160r2-client +[31-curve-secp160r2-ssl] +server = 31-curve-secp160r2-server +client = 31-curve-secp160r2-client -[36-curve-secp160r2-server] +[31-curve-secp160r2-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = secp160r2 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[36-curve-secp160r2-client] +[31-curve-secp160r2-client] CipherString = ECDHE@SECLEVEL=1 Curves = secp160r2 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-36] +[test-31] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = secp160r2 @@ -1196,28 +1036,28 @@ ExpectedTmpKeyType = secp160r2 # =========================================================== -[37-curve-secp192k1] -ssl_conf = 37-curve-secp192k1-ssl +[32-curve-secp192k1] +ssl_conf = 32-curve-secp192k1-ssl -[37-curve-secp192k1-ssl] -server = 37-curve-secp192k1-server -client = 37-curve-secp192k1-client +[32-curve-secp192k1-ssl] +server = 32-curve-secp192k1-server +client = 32-curve-secp192k1-client -[37-curve-secp192k1-server] +[32-curve-secp192k1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = secp192k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[37-curve-secp192k1-client] +[32-curve-secp192k1-client] CipherString = ECDHE@SECLEVEL=1 Curves = secp192k1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-37] +[test-32] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = secp192k1 @@ -1225,28 +1065,28 @@ ExpectedTmpKeyType = secp192k1 # =========================================================== -[38-curve-secp224k1] -ssl_conf = 38-curve-secp224k1-ssl +[33-curve-secp224k1] +ssl_conf = 33-curve-secp224k1-ssl -[38-curve-secp224k1-ssl] -server = 38-curve-secp224k1-server -client = 38-curve-secp224k1-client +[33-curve-secp224k1-ssl] +server = 33-curve-secp224k1-server +client = 33-curve-secp224k1-client -[38-curve-secp224k1-server] +[33-curve-secp224k1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = secp224k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[38-curve-secp224k1-client] +[33-curve-secp224k1-client] CipherString = ECDHE@SECLEVEL=1 Curves = secp224k1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-38] +[test-33] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = secp224k1 @@ -1254,28 +1094,28 @@ ExpectedTmpKeyType = secp224k1 # =========================================================== -[39-curve-secp256k1] -ssl_conf = 39-curve-secp256k1-ssl +[34-curve-secp256k1] +ssl_conf = 34-curve-secp256k1-ssl -[39-curve-secp256k1-ssl] -server = 39-curve-secp256k1-server -client = 39-curve-secp256k1-client +[34-curve-secp256k1-ssl] +server = 34-curve-secp256k1-server +client = 34-curve-secp256k1-client -[39-curve-secp256k1-server] +[34-curve-secp256k1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = secp256k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[39-curve-secp256k1-client] +[34-curve-secp256k1-client] CipherString = ECDHE@SECLEVEL=1 Curves = secp256k1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-39] +[test-34] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = secp256k1 @@ -1283,28 +1123,28 @@ ExpectedTmpKeyType = secp256k1 # =========================================================== -[40-curve-brainpoolP256r1] -ssl_conf = 40-curve-brainpoolP256r1-ssl +[35-curve-brainpoolP256r1] +ssl_conf = 35-curve-brainpoolP256r1-ssl -[40-curve-brainpoolP256r1-ssl] -server = 40-curve-brainpoolP256r1-server -client = 40-curve-brainpoolP256r1-client +[35-curve-brainpoolP256r1-ssl] +server = 35-curve-brainpoolP256r1-server +client = 35-curve-brainpoolP256r1-client -[40-curve-brainpoolP256r1-server] +[35-curve-brainpoolP256r1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = brainpoolP256r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[40-curve-brainpoolP256r1-client] +[35-curve-brainpoolP256r1-client] CipherString = ECDHE@SECLEVEL=1 Curves = brainpoolP256r1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-40] +[test-35] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = brainpoolP256r1 @@ -1312,28 +1152,28 @@ ExpectedTmpKeyType = brainpoolP256r1 # =========================================================== -[41-curve-brainpoolP384r1] -ssl_conf = 41-curve-brainpoolP384r1-ssl +[36-curve-brainpoolP384r1] +ssl_conf = 36-curve-brainpoolP384r1-ssl -[41-curve-brainpoolP384r1-ssl] -server = 41-curve-brainpoolP384r1-server -client = 41-curve-brainpoolP384r1-client +[36-curve-brainpoolP384r1-ssl] +server = 36-curve-brainpoolP384r1-server +client = 36-curve-brainpoolP384r1-client -[41-curve-brainpoolP384r1-server] +[36-curve-brainpoolP384r1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = brainpoolP384r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[41-curve-brainpoolP384r1-client] +[36-curve-brainpoolP384r1-client] CipherString = ECDHE@SECLEVEL=1 Curves = brainpoolP384r1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-41] +[test-36] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = brainpoolP384r1 @@ -1341,28 +1181,28 @@ ExpectedTmpKeyType = brainpoolP384r1 # =========================================================== -[42-curve-brainpoolP512r1] -ssl_conf = 42-curve-brainpoolP512r1-ssl +[37-curve-brainpoolP512r1] +ssl_conf = 37-curve-brainpoolP512r1-ssl -[42-curve-brainpoolP512r1-ssl] -server = 42-curve-brainpoolP512r1-server -client = 42-curve-brainpoolP512r1-client +[37-curve-brainpoolP512r1-ssl] +server = 37-curve-brainpoolP512r1-server +client = 37-curve-brainpoolP512r1-client -[42-curve-brainpoolP512r1-server] +[37-curve-brainpoolP512r1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = brainpoolP512r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[42-curve-brainpoolP512r1-client] +[37-curve-brainpoolP512r1-client] CipherString = ECDHE@SECLEVEL=1 Curves = brainpoolP512r1 MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-42] +[test-37] ExpectedProtocol = TLSv1.2 ExpectedResult = Success ExpectedTmpKeyType = brainpoolP512r1 @@ -1370,21 +1210,21 @@ ExpectedTmpKeyType = brainpoolP512r1 # =========================================================== -[43-curve-sect233k1-tls12-in-tls13] -ssl_conf = 43-curve-sect233k1-tls12-in-tls13-ssl +[38-curve-sect233k1-tls12-in-tls13] +ssl_conf = 38-curve-sect233k1-tls12-in-tls13-ssl -[43-curve-sect233k1-tls12-in-tls13-ssl] -server = 43-curve-sect233k1-tls12-in-tls13-server -client = 43-curve-sect233k1-tls12-in-tls13-client +[38-curve-sect233k1-tls12-in-tls13-ssl] +server = 38-curve-sect233k1-tls12-in-tls13-server +client = 38-curve-sect233k1-tls12-in-tls13-client -[43-curve-sect233k1-tls12-in-tls13-server] +[38-curve-sect233k1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 Curves = sect233k1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[43-curve-sect233k1-tls12-in-tls13-client] +[38-curve-sect233k1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 Curves = sect233k1:P-256 MaxProtocol = TLSv1.3 @@ -1392,6 +1232,156 @@ MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer +[test-38] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success +ExpectedTmpKeyType = P-256 + + +# =========================================================== + +[39-curve-sect233r1-tls12-in-tls13] +ssl_conf = 39-curve-sect233r1-tls12-in-tls13-ssl + +[39-curve-sect233r1-tls12-in-tls13-ssl] +server = 39-curve-sect233r1-tls12-in-tls13-server +client = 39-curve-sect233r1-tls12-in-tls13-client + +[39-curve-sect233r1-tls12-in-tls13-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT@SECLEVEL=1 +Curves = sect233r1:P-256 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[39-curve-sect233r1-tls12-in-tls13-client] +CipherString = ECDHE@SECLEVEL=1 +Curves = sect233r1:P-256 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-39] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success +ExpectedTmpKeyType = P-256 + + +# =========================================================== + +[40-curve-sect283k1-tls12-in-tls13] +ssl_conf = 40-curve-sect283k1-tls12-in-tls13-ssl + +[40-curve-sect283k1-tls12-in-tls13-ssl] +server = 40-curve-sect283k1-tls12-in-tls13-server +client = 40-curve-sect283k1-tls12-in-tls13-client + +[40-curve-sect283k1-tls12-in-tls13-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT@SECLEVEL=1 +Curves = sect283k1:P-256 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[40-curve-sect283k1-tls12-in-tls13-client] +CipherString = ECDHE@SECLEVEL=1 +Curves = sect283k1:P-256 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-40] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success +ExpectedTmpKeyType = P-256 + + +# =========================================================== + +[41-curve-sect283r1-tls12-in-tls13] +ssl_conf = 41-curve-sect283r1-tls12-in-tls13-ssl + +[41-curve-sect283r1-tls12-in-tls13-ssl] +server = 41-curve-sect283r1-tls12-in-tls13-server +client = 41-curve-sect283r1-tls12-in-tls13-client + +[41-curve-sect283r1-tls12-in-tls13-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT@SECLEVEL=1 +Curves = sect283r1:P-256 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[41-curve-sect283r1-tls12-in-tls13-client] +CipherString = ECDHE@SECLEVEL=1 +Curves = sect283r1:P-256 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-41] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success +ExpectedTmpKeyType = P-256 + + +# =========================================================== + +[42-curve-sect409k1-tls12-in-tls13] +ssl_conf = 42-curve-sect409k1-tls12-in-tls13-ssl + +[42-curve-sect409k1-tls12-in-tls13-ssl] +server = 42-curve-sect409k1-tls12-in-tls13-server +client = 42-curve-sect409k1-tls12-in-tls13-client + +[42-curve-sect409k1-tls12-in-tls13-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT@SECLEVEL=1 +Curves = sect409k1:P-256 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[42-curve-sect409k1-tls12-in-tls13-client] +CipherString = ECDHE@SECLEVEL=1 +Curves = sect409k1:P-256 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-42] +ExpectedProtocol = TLSv1.3 +ExpectedResult = Success +ExpectedTmpKeyType = P-256 + + +# =========================================================== + +[43-curve-sect409r1-tls12-in-tls13] +ssl_conf = 43-curve-sect409r1-tls12-in-tls13-ssl + +[43-curve-sect409r1-tls12-in-tls13-ssl] +server = 43-curve-sect409r1-tls12-in-tls13-server +client = 43-curve-sect409r1-tls12-in-tls13-client + +[43-curve-sect409r1-tls12-in-tls13-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT@SECLEVEL=1 +Curves = sect409r1:P-256 +MaxProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[43-curve-sect409r1-tls12-in-tls13-client] +CipherString = ECDHE@SECLEVEL=1 +Curves = sect409r1:P-256 +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + [test-43] ExpectedProtocol = TLSv1.3 ExpectedResult = Success @@ -1400,23 +1390,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[44-curve-sect233r1-tls12-in-tls13] -ssl_conf = 44-curve-sect233r1-tls12-in-tls13-ssl +[44-curve-sect571k1-tls12-in-tls13] +ssl_conf = 44-curve-sect571k1-tls12-in-tls13-ssl -[44-curve-sect233r1-tls12-in-tls13-ssl] -server = 44-curve-sect233r1-tls12-in-tls13-server -client = 44-curve-sect233r1-tls12-in-tls13-client +[44-curve-sect571k1-tls12-in-tls13-ssl] +server = 44-curve-sect571k1-tls12-in-tls13-server +client = 44-curve-sect571k1-tls12-in-tls13-client -[44-curve-sect233r1-tls12-in-tls13-server] +[44-curve-sect571k1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect233r1:P-256 +Curves = sect571k1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[44-curve-sect233r1-tls12-in-tls13-client] +[44-curve-sect571k1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect233r1:P-256 +Curves = sect571k1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1430,23 +1420,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[45-curve-sect283k1-tls12-in-tls13] -ssl_conf = 45-curve-sect283k1-tls12-in-tls13-ssl +[45-curve-sect571r1-tls12-in-tls13] +ssl_conf = 45-curve-sect571r1-tls12-in-tls13-ssl -[45-curve-sect283k1-tls12-in-tls13-ssl] -server = 45-curve-sect283k1-tls12-in-tls13-server -client = 45-curve-sect283k1-tls12-in-tls13-client +[45-curve-sect571r1-tls12-in-tls13-ssl] +server = 45-curve-sect571r1-tls12-in-tls13-server +client = 45-curve-sect571r1-tls12-in-tls13-client -[45-curve-sect283k1-tls12-in-tls13-server] +[45-curve-sect571r1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect283k1:P-256 +Curves = sect571r1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[45-curve-sect283k1-tls12-in-tls13-client] +[45-curve-sect571r1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect283k1:P-256 +Curves = sect571r1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1460,23 +1450,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[46-curve-sect283r1-tls12-in-tls13] -ssl_conf = 46-curve-sect283r1-tls12-in-tls13-ssl +[46-curve-secp224r1-tls12-in-tls13] +ssl_conf = 46-curve-secp224r1-tls12-in-tls13-ssl -[46-curve-sect283r1-tls12-in-tls13-ssl] -server = 46-curve-sect283r1-tls12-in-tls13-server -client = 46-curve-sect283r1-tls12-in-tls13-client +[46-curve-secp224r1-tls12-in-tls13-ssl] +server = 46-curve-secp224r1-tls12-in-tls13-server +client = 46-curve-secp224r1-tls12-in-tls13-client -[46-curve-sect283r1-tls12-in-tls13-server] +[46-curve-secp224r1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect283r1:P-256 +Curves = secp224r1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[46-curve-sect283r1-tls12-in-tls13-client] +[46-curve-secp224r1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect283r1:P-256 +Curves = secp224r1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1490,23 +1480,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[47-curve-sect409k1-tls12-in-tls13] -ssl_conf = 47-curve-sect409k1-tls12-in-tls13-ssl +[47-curve-sect163k1-tls12-in-tls13] +ssl_conf = 47-curve-sect163k1-tls12-in-tls13-ssl -[47-curve-sect409k1-tls12-in-tls13-ssl] -server = 47-curve-sect409k1-tls12-in-tls13-server -client = 47-curve-sect409k1-tls12-in-tls13-client +[47-curve-sect163k1-tls12-in-tls13-ssl] +server = 47-curve-sect163k1-tls12-in-tls13-server +client = 47-curve-sect163k1-tls12-in-tls13-client -[47-curve-sect409k1-tls12-in-tls13-server] +[47-curve-sect163k1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect409k1:P-256 +Curves = sect163k1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[47-curve-sect409k1-tls12-in-tls13-client] +[47-curve-sect163k1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect409k1:P-256 +Curves = sect163k1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1520,23 +1510,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[48-curve-sect409r1-tls12-in-tls13] -ssl_conf = 48-curve-sect409r1-tls12-in-tls13-ssl +[48-curve-sect163r2-tls12-in-tls13] +ssl_conf = 48-curve-sect163r2-tls12-in-tls13-ssl -[48-curve-sect409r1-tls12-in-tls13-ssl] -server = 48-curve-sect409r1-tls12-in-tls13-server -client = 48-curve-sect409r1-tls12-in-tls13-client +[48-curve-sect163r2-tls12-in-tls13-ssl] +server = 48-curve-sect163r2-tls12-in-tls13-server +client = 48-curve-sect163r2-tls12-in-tls13-client -[48-curve-sect409r1-tls12-in-tls13-server] +[48-curve-sect163r2-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect409r1:P-256 +Curves = sect163r2:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[48-curve-sect409r1-tls12-in-tls13-client] +[48-curve-sect163r2-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect409r1:P-256 +Curves = sect163r2:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1550,23 +1540,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[49-curve-sect571k1-tls12-in-tls13] -ssl_conf = 49-curve-sect571k1-tls12-in-tls13-ssl +[49-curve-prime192v1-tls12-in-tls13] +ssl_conf = 49-curve-prime192v1-tls12-in-tls13-ssl -[49-curve-sect571k1-tls12-in-tls13-ssl] -server = 49-curve-sect571k1-tls12-in-tls13-server -client = 49-curve-sect571k1-tls12-in-tls13-client +[49-curve-prime192v1-tls12-in-tls13-ssl] +server = 49-curve-prime192v1-tls12-in-tls13-server +client = 49-curve-prime192v1-tls12-in-tls13-client -[49-curve-sect571k1-tls12-in-tls13-server] +[49-curve-prime192v1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect571k1:P-256 +Curves = prime192v1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[49-curve-sect571k1-tls12-in-tls13-client] +[49-curve-prime192v1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect571k1:P-256 +Curves = prime192v1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1580,23 +1570,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[50-curve-sect571r1-tls12-in-tls13] -ssl_conf = 50-curve-sect571r1-tls12-in-tls13-ssl +[50-curve-sect163r1-tls12-in-tls13] +ssl_conf = 50-curve-sect163r1-tls12-in-tls13-ssl -[50-curve-sect571r1-tls12-in-tls13-ssl] -server = 50-curve-sect571r1-tls12-in-tls13-server -client = 50-curve-sect571r1-tls12-in-tls13-client +[50-curve-sect163r1-tls12-in-tls13-ssl] +server = 50-curve-sect163r1-tls12-in-tls13-server +client = 50-curve-sect163r1-tls12-in-tls13-client -[50-curve-sect571r1-tls12-in-tls13-server] +[50-curve-sect163r1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect571r1:P-256 +Curves = sect163r1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[50-curve-sect571r1-tls12-in-tls13-client] +[50-curve-sect163r1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect571r1:P-256 +Curves = sect163r1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1610,23 +1600,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[51-curve-secp224r1-tls12-in-tls13] -ssl_conf = 51-curve-secp224r1-tls12-in-tls13-ssl +[51-curve-sect193r1-tls12-in-tls13] +ssl_conf = 51-curve-sect193r1-tls12-in-tls13-ssl -[51-curve-secp224r1-tls12-in-tls13-ssl] -server = 51-curve-secp224r1-tls12-in-tls13-server -client = 51-curve-secp224r1-tls12-in-tls13-client +[51-curve-sect193r1-tls12-in-tls13-ssl] +server = 51-curve-sect193r1-tls12-in-tls13-server +client = 51-curve-sect193r1-tls12-in-tls13-client -[51-curve-secp224r1-tls12-in-tls13-server] +[51-curve-sect193r1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = secp224r1:P-256 +Curves = sect193r1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[51-curve-secp224r1-tls12-in-tls13-client] +[51-curve-sect193r1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = secp224r1:P-256 +Curves = sect193r1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1640,23 +1630,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[52-curve-sect163k1-tls12-in-tls13] -ssl_conf = 52-curve-sect163k1-tls12-in-tls13-ssl +[52-curve-sect193r2-tls12-in-tls13] +ssl_conf = 52-curve-sect193r2-tls12-in-tls13-ssl -[52-curve-sect163k1-tls12-in-tls13-ssl] -server = 52-curve-sect163k1-tls12-in-tls13-server -client = 52-curve-sect163k1-tls12-in-tls13-client +[52-curve-sect193r2-tls12-in-tls13-ssl] +server = 52-curve-sect193r2-tls12-in-tls13-server +client = 52-curve-sect193r2-tls12-in-tls13-client -[52-curve-sect163k1-tls12-in-tls13-server] +[52-curve-sect193r2-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect163k1:P-256 +Curves = sect193r2:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[52-curve-sect163k1-tls12-in-tls13-client] +[52-curve-sect193r2-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect163k1:P-256 +Curves = sect193r2:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1670,23 +1660,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[53-curve-sect163r2-tls12-in-tls13] -ssl_conf = 53-curve-sect163r2-tls12-in-tls13-ssl +[53-curve-sect239k1-tls12-in-tls13] +ssl_conf = 53-curve-sect239k1-tls12-in-tls13-ssl -[53-curve-sect163r2-tls12-in-tls13-ssl] -server = 53-curve-sect163r2-tls12-in-tls13-server -client = 53-curve-sect163r2-tls12-in-tls13-client +[53-curve-sect239k1-tls12-in-tls13-ssl] +server = 53-curve-sect239k1-tls12-in-tls13-server +client = 53-curve-sect239k1-tls12-in-tls13-client -[53-curve-sect163r2-tls12-in-tls13-server] +[53-curve-sect239k1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect163r2:P-256 +Curves = sect239k1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[53-curve-sect163r2-tls12-in-tls13-client] +[53-curve-sect239k1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect163r2:P-256 +Curves = sect239k1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1700,23 +1690,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[54-curve-prime192v1-tls12-in-tls13] -ssl_conf = 54-curve-prime192v1-tls12-in-tls13-ssl +[54-curve-secp160k1-tls12-in-tls13] +ssl_conf = 54-curve-secp160k1-tls12-in-tls13-ssl -[54-curve-prime192v1-tls12-in-tls13-ssl] -server = 54-curve-prime192v1-tls12-in-tls13-server -client = 54-curve-prime192v1-tls12-in-tls13-client +[54-curve-secp160k1-tls12-in-tls13-ssl] +server = 54-curve-secp160k1-tls12-in-tls13-server +client = 54-curve-secp160k1-tls12-in-tls13-client -[54-curve-prime192v1-tls12-in-tls13-server] +[54-curve-secp160k1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = prime192v1:P-256 +Curves = secp160k1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[54-curve-prime192v1-tls12-in-tls13-client] +[54-curve-secp160k1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = prime192v1:P-256 +Curves = secp160k1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1730,23 +1720,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[55-curve-sect163r1-tls12-in-tls13] -ssl_conf = 55-curve-sect163r1-tls12-in-tls13-ssl +[55-curve-secp160r1-tls12-in-tls13] +ssl_conf = 55-curve-secp160r1-tls12-in-tls13-ssl -[55-curve-sect163r1-tls12-in-tls13-ssl] -server = 55-curve-sect163r1-tls12-in-tls13-server -client = 55-curve-sect163r1-tls12-in-tls13-client +[55-curve-secp160r1-tls12-in-tls13-ssl] +server = 55-curve-secp160r1-tls12-in-tls13-server +client = 55-curve-secp160r1-tls12-in-tls13-client -[55-curve-sect163r1-tls12-in-tls13-server] +[55-curve-secp160r1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect163r1:P-256 +Curves = secp160r1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[55-curve-sect163r1-tls12-in-tls13-client] +[55-curve-secp160r1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect163r1:P-256 +Curves = secp160r1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1760,23 +1750,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[56-curve-sect193r1-tls12-in-tls13] -ssl_conf = 56-curve-sect193r1-tls12-in-tls13-ssl +[56-curve-secp160r2-tls12-in-tls13] +ssl_conf = 56-curve-secp160r2-tls12-in-tls13-ssl -[56-curve-sect193r1-tls12-in-tls13-ssl] -server = 56-curve-sect193r1-tls12-in-tls13-server -client = 56-curve-sect193r1-tls12-in-tls13-client +[56-curve-secp160r2-tls12-in-tls13-ssl] +server = 56-curve-secp160r2-tls12-in-tls13-server +client = 56-curve-secp160r2-tls12-in-tls13-client -[56-curve-sect193r1-tls12-in-tls13-server] +[56-curve-secp160r2-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect193r1:P-256 +Curves = secp160r2:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[56-curve-sect193r1-tls12-in-tls13-client] +[56-curve-secp160r2-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect193r1:P-256 +Curves = secp160r2:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1790,23 +1780,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[57-curve-sect193r2-tls12-in-tls13] -ssl_conf = 57-curve-sect193r2-tls12-in-tls13-ssl +[57-curve-secp192k1-tls12-in-tls13] +ssl_conf = 57-curve-secp192k1-tls12-in-tls13-ssl -[57-curve-sect193r2-tls12-in-tls13-ssl] -server = 57-curve-sect193r2-tls12-in-tls13-server -client = 57-curve-sect193r2-tls12-in-tls13-client +[57-curve-secp192k1-tls12-in-tls13-ssl] +server = 57-curve-secp192k1-tls12-in-tls13-server +client = 57-curve-secp192k1-tls12-in-tls13-client -[57-curve-sect193r2-tls12-in-tls13-server] +[57-curve-secp192k1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect193r2:P-256 +Curves = secp192k1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[57-curve-sect193r2-tls12-in-tls13-client] +[57-curve-secp192k1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect193r2:P-256 +Curves = secp192k1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1820,23 +1810,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[58-curve-sect239k1-tls12-in-tls13] -ssl_conf = 58-curve-sect239k1-tls12-in-tls13-ssl +[58-curve-secp224k1-tls12-in-tls13] +ssl_conf = 58-curve-secp224k1-tls12-in-tls13-ssl -[58-curve-sect239k1-tls12-in-tls13-ssl] -server = 58-curve-sect239k1-tls12-in-tls13-server -client = 58-curve-sect239k1-tls12-in-tls13-client +[58-curve-secp224k1-tls12-in-tls13-ssl] +server = 58-curve-secp224k1-tls12-in-tls13-server +client = 58-curve-secp224k1-tls12-in-tls13-client -[58-curve-sect239k1-tls12-in-tls13-server] +[58-curve-secp224k1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect239k1:P-256 +Curves = secp224k1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[58-curve-sect239k1-tls12-in-tls13-client] +[58-curve-secp224k1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect239k1:P-256 +Curves = secp224k1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1850,23 +1840,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[59-curve-secp160k1-tls12-in-tls13] -ssl_conf = 59-curve-secp160k1-tls12-in-tls13-ssl +[59-curve-secp256k1-tls12-in-tls13] +ssl_conf = 59-curve-secp256k1-tls12-in-tls13-ssl -[59-curve-secp160k1-tls12-in-tls13-ssl] -server = 59-curve-secp160k1-tls12-in-tls13-server -client = 59-curve-secp160k1-tls12-in-tls13-client +[59-curve-secp256k1-tls12-in-tls13-ssl] +server = 59-curve-secp256k1-tls12-in-tls13-server +client = 59-curve-secp256k1-tls12-in-tls13-client -[59-curve-secp160k1-tls12-in-tls13-server] +[59-curve-secp256k1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = secp160k1:P-256 +Curves = secp256k1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[59-curve-secp160k1-tls12-in-tls13-client] +[59-curve-secp256k1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = secp160k1:P-256 +Curves = secp256k1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1880,23 +1870,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[60-curve-secp160r1-tls12-in-tls13] -ssl_conf = 60-curve-secp160r1-tls12-in-tls13-ssl +[60-curve-brainpoolP256r1-tls12-in-tls13] +ssl_conf = 60-curve-brainpoolP256r1-tls12-in-tls13-ssl -[60-curve-secp160r1-tls12-in-tls13-ssl] -server = 60-curve-secp160r1-tls12-in-tls13-server -client = 60-curve-secp160r1-tls12-in-tls13-client +[60-curve-brainpoolP256r1-tls12-in-tls13-ssl] +server = 60-curve-brainpoolP256r1-tls12-in-tls13-server +client = 60-curve-brainpoolP256r1-tls12-in-tls13-client -[60-curve-secp160r1-tls12-in-tls13-server] +[60-curve-brainpoolP256r1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = secp160r1:P-256 +Curves = brainpoolP256r1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[60-curve-secp160r1-tls12-in-tls13-client] +[60-curve-brainpoolP256r1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = secp160r1:P-256 +Curves = brainpoolP256r1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1910,23 +1900,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[61-curve-secp160r2-tls12-in-tls13] -ssl_conf = 61-curve-secp160r2-tls12-in-tls13-ssl +[61-curve-brainpoolP384r1-tls12-in-tls13] +ssl_conf = 61-curve-brainpoolP384r1-tls12-in-tls13-ssl -[61-curve-secp160r2-tls12-in-tls13-ssl] -server = 61-curve-secp160r2-tls12-in-tls13-server -client = 61-curve-secp160r2-tls12-in-tls13-client +[61-curve-brainpoolP384r1-tls12-in-tls13-ssl] +server = 61-curve-brainpoolP384r1-tls12-in-tls13-server +client = 61-curve-brainpoolP384r1-tls12-in-tls13-client -[61-curve-secp160r2-tls12-in-tls13-server] +[61-curve-brainpoolP384r1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = secp160r2:P-256 +Curves = brainpoolP384r1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[61-curve-secp160r2-tls12-in-tls13-client] +[61-curve-brainpoolP384r1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = secp160r2:P-256 +Curves = brainpoolP384r1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1940,23 +1930,23 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[62-curve-secp192k1-tls12-in-tls13] -ssl_conf = 62-curve-secp192k1-tls12-in-tls13-ssl +[62-curve-brainpoolP512r1-tls12-in-tls13] +ssl_conf = 62-curve-brainpoolP512r1-tls12-in-tls13-ssl -[62-curve-secp192k1-tls12-in-tls13-ssl] -server = 62-curve-secp192k1-tls12-in-tls13-server -client = 62-curve-secp192k1-tls12-in-tls13-client +[62-curve-brainpoolP512r1-tls12-in-tls13-ssl] +server = 62-curve-brainpoolP512r1-tls12-in-tls13-server +client = 62-curve-brainpoolP512r1-tls12-in-tls13-client -[62-curve-secp192k1-tls12-in-tls13-server] +[62-curve-brainpoolP512r1-tls12-in-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = secp192k1:P-256 +Curves = brainpoolP512r1:P-256 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[62-curve-secp192k1-tls12-in-tls13-client] +[62-curve-brainpoolP512r1-tls12-in-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = secp192k1:P-256 +Curves = brainpoolP512r1:P-256 MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem @@ -1970,173 +1960,158 @@ ExpectedTmpKeyType = P-256 # =========================================================== -[63-curve-secp224k1-tls12-in-tls13] -ssl_conf = 63-curve-secp224k1-tls12-in-tls13-ssl +[63-curve-sect233k1-tls13] +ssl_conf = 63-curve-sect233k1-tls13-ssl -[63-curve-secp224k1-tls12-in-tls13-ssl] -server = 63-curve-secp224k1-tls12-in-tls13-server -client = 63-curve-secp224k1-tls12-in-tls13-client +[63-curve-sect233k1-tls13-ssl] +server = 63-curve-sect233k1-tls13-server +client = 63-curve-sect233k1-tls13-client -[63-curve-secp224k1-tls12-in-tls13-server] +[63-curve-sect233k1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = secp224k1:P-256 +Curves = sect233k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[63-curve-secp224k1-tls12-in-tls13-client] +[63-curve-sect233k1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = secp224k1:P-256 -MaxProtocol = TLSv1.3 +Curves = sect233k1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-63] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success -ExpectedTmpKeyType = P-256 +ExpectedResult = ClientFail # =========================================================== -[64-curve-secp256k1-tls12-in-tls13] -ssl_conf = 64-curve-secp256k1-tls12-in-tls13-ssl +[64-curve-sect233r1-tls13] +ssl_conf = 64-curve-sect233r1-tls13-ssl -[64-curve-secp256k1-tls12-in-tls13-ssl] -server = 64-curve-secp256k1-tls12-in-tls13-server -client = 64-curve-secp256k1-tls12-in-tls13-client +[64-curve-sect233r1-tls13-ssl] +server = 64-curve-sect233r1-tls13-server +client = 64-curve-sect233r1-tls13-client -[64-curve-secp256k1-tls12-in-tls13-server] +[64-curve-sect233r1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = secp256k1:P-256 +Curves = sect233r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[64-curve-secp256k1-tls12-in-tls13-client] +[64-curve-sect233r1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = secp256k1:P-256 -MaxProtocol = TLSv1.3 +Curves = sect233r1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-64] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success -ExpectedTmpKeyType = P-256 +ExpectedResult = ClientFail # =========================================================== -[65-curve-brainpoolP256r1-tls12-in-tls13] -ssl_conf = 65-curve-brainpoolP256r1-tls12-in-tls13-ssl +[65-curve-sect283k1-tls13] +ssl_conf = 65-curve-sect283k1-tls13-ssl -[65-curve-brainpoolP256r1-tls12-in-tls13-ssl] -server = 65-curve-brainpoolP256r1-tls12-in-tls13-server -client = 65-curve-brainpoolP256r1-tls12-in-tls13-client +[65-curve-sect283k1-tls13-ssl] +server = 65-curve-sect283k1-tls13-server +client = 65-curve-sect283k1-tls13-client -[65-curve-brainpoolP256r1-tls12-in-tls13-server] +[65-curve-sect283k1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = brainpoolP256r1:P-256 +Curves = sect283k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[65-curve-brainpoolP256r1-tls12-in-tls13-client] +[65-curve-sect283k1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = brainpoolP256r1:P-256 -MaxProtocol = TLSv1.3 +Curves = sect283k1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-65] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success -ExpectedTmpKeyType = P-256 +ExpectedResult = ClientFail # =========================================================== -[66-curve-brainpoolP384r1-tls12-in-tls13] -ssl_conf = 66-curve-brainpoolP384r1-tls12-in-tls13-ssl +[66-curve-sect283r1-tls13] +ssl_conf = 66-curve-sect283r1-tls13-ssl -[66-curve-brainpoolP384r1-tls12-in-tls13-ssl] -server = 66-curve-brainpoolP384r1-tls12-in-tls13-server -client = 66-curve-brainpoolP384r1-tls12-in-tls13-client +[66-curve-sect283r1-tls13-ssl] +server = 66-curve-sect283r1-tls13-server +client = 66-curve-sect283r1-tls13-client -[66-curve-brainpoolP384r1-tls12-in-tls13-server] +[66-curve-sect283r1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = brainpoolP384r1:P-256 +Curves = sect283r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[66-curve-brainpoolP384r1-tls12-in-tls13-client] +[66-curve-sect283r1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = brainpoolP384r1:P-256 -MaxProtocol = TLSv1.3 +Curves = sect283r1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-66] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success -ExpectedTmpKeyType = P-256 +ExpectedResult = ClientFail # =========================================================== -[67-curve-brainpoolP512r1-tls12-in-tls13] -ssl_conf = 67-curve-brainpoolP512r1-tls12-in-tls13-ssl +[67-curve-sect409k1-tls13] +ssl_conf = 67-curve-sect409k1-tls13-ssl -[67-curve-brainpoolP512r1-tls12-in-tls13-ssl] -server = 67-curve-brainpoolP512r1-tls12-in-tls13-server -client = 67-curve-brainpoolP512r1-tls12-in-tls13-client +[67-curve-sect409k1-tls13-ssl] +server = 67-curve-sect409k1-tls13-server +client = 67-curve-sect409k1-tls13-client -[67-curve-brainpoolP512r1-tls12-in-tls13-server] +[67-curve-sect409k1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = brainpoolP512r1:P-256 +Curves = sect409k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[67-curve-brainpoolP512r1-tls12-in-tls13-client] +[67-curve-sect409k1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = brainpoolP512r1:P-256 -MaxProtocol = TLSv1.3 +Curves = sect409k1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-67] -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success -ExpectedTmpKeyType = P-256 +ExpectedResult = ClientFail # =========================================================== -[68-curve-sect233k1-tls13] -ssl_conf = 68-curve-sect233k1-tls13-ssl +[68-curve-sect409r1-tls13] +ssl_conf = 68-curve-sect409r1-tls13-ssl -[68-curve-sect233k1-tls13-ssl] -server = 68-curve-sect233k1-tls13-server -client = 68-curve-sect233k1-tls13-client +[68-curve-sect409r1-tls13-ssl] +server = 68-curve-sect409r1-tls13-server +client = 68-curve-sect409r1-tls13-client -[68-curve-sect233k1-tls13-server] +[68-curve-sect409r1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect233k1 +Curves = sect409r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[68-curve-sect233k1-tls13-client] +[68-curve-sect409r1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect233k1 +Curves = sect409r1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2147,23 +2122,23 @@ ExpectedResult = ClientFail # =========================================================== -[69-curve-sect233r1-tls13] -ssl_conf = 69-curve-sect233r1-tls13-ssl +[69-curve-sect571k1-tls13] +ssl_conf = 69-curve-sect571k1-tls13-ssl -[69-curve-sect233r1-tls13-ssl] -server = 69-curve-sect233r1-tls13-server -client = 69-curve-sect233r1-tls13-client +[69-curve-sect571k1-tls13-ssl] +server = 69-curve-sect571k1-tls13-server +client = 69-curve-sect571k1-tls13-client -[69-curve-sect233r1-tls13-server] +[69-curve-sect571k1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect233r1 +Curves = sect571k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[69-curve-sect233r1-tls13-client] +[69-curve-sect571k1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect233r1 +Curves = sect571k1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2174,23 +2149,23 @@ ExpectedResult = ClientFail # =========================================================== -[70-curve-sect283k1-tls13] -ssl_conf = 70-curve-sect283k1-tls13-ssl +[70-curve-sect571r1-tls13] +ssl_conf = 70-curve-sect571r1-tls13-ssl -[70-curve-sect283k1-tls13-ssl] -server = 70-curve-sect283k1-tls13-server -client = 70-curve-sect283k1-tls13-client +[70-curve-sect571r1-tls13-ssl] +server = 70-curve-sect571r1-tls13-server +client = 70-curve-sect571r1-tls13-client -[70-curve-sect283k1-tls13-server] +[70-curve-sect571r1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect283k1 +Curves = sect571r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[70-curve-sect283k1-tls13-client] +[70-curve-sect571r1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect283k1 +Curves = sect571r1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2201,23 +2176,23 @@ ExpectedResult = ClientFail # =========================================================== -[71-curve-sect283r1-tls13] -ssl_conf = 71-curve-sect283r1-tls13-ssl +[71-curve-secp224r1-tls13] +ssl_conf = 71-curve-secp224r1-tls13-ssl -[71-curve-sect283r1-tls13-ssl] -server = 71-curve-sect283r1-tls13-server -client = 71-curve-sect283r1-tls13-client +[71-curve-secp224r1-tls13-ssl] +server = 71-curve-secp224r1-tls13-server +client = 71-curve-secp224r1-tls13-client -[71-curve-sect283r1-tls13-server] +[71-curve-secp224r1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect283r1 +Curves = secp224r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[71-curve-sect283r1-tls13-client] +[71-curve-secp224r1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect283r1 +Curves = secp224r1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2228,23 +2203,23 @@ ExpectedResult = ClientFail # =========================================================== -[72-curve-sect409k1-tls13] -ssl_conf = 72-curve-sect409k1-tls13-ssl +[72-curve-sect163k1-tls13] +ssl_conf = 72-curve-sect163k1-tls13-ssl -[72-curve-sect409k1-tls13-ssl] -server = 72-curve-sect409k1-tls13-server -client = 72-curve-sect409k1-tls13-client +[72-curve-sect163k1-tls13-ssl] +server = 72-curve-sect163k1-tls13-server +client = 72-curve-sect163k1-tls13-client -[72-curve-sect409k1-tls13-server] +[72-curve-sect163k1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect409k1 +Curves = sect163k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[72-curve-sect409k1-tls13-client] +[72-curve-sect163k1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect409k1 +Curves = sect163k1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2255,23 +2230,23 @@ ExpectedResult = ClientFail # =========================================================== -[73-curve-sect409r1-tls13] -ssl_conf = 73-curve-sect409r1-tls13-ssl +[73-curve-sect163r2-tls13] +ssl_conf = 73-curve-sect163r2-tls13-ssl -[73-curve-sect409r1-tls13-ssl] -server = 73-curve-sect409r1-tls13-server -client = 73-curve-sect409r1-tls13-client +[73-curve-sect163r2-tls13-ssl] +server = 73-curve-sect163r2-tls13-server +client = 73-curve-sect163r2-tls13-client -[73-curve-sect409r1-tls13-server] +[73-curve-sect163r2-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect409r1 +Curves = sect163r2 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[73-curve-sect409r1-tls13-client] +[73-curve-sect163r2-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect409r1 +Curves = sect163r2 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2282,23 +2257,23 @@ ExpectedResult = ClientFail # =========================================================== -[74-curve-sect571k1-tls13] -ssl_conf = 74-curve-sect571k1-tls13-ssl +[74-curve-prime192v1-tls13] +ssl_conf = 74-curve-prime192v1-tls13-ssl -[74-curve-sect571k1-tls13-ssl] -server = 74-curve-sect571k1-tls13-server -client = 74-curve-sect571k1-tls13-client +[74-curve-prime192v1-tls13-ssl] +server = 74-curve-prime192v1-tls13-server +client = 74-curve-prime192v1-tls13-client -[74-curve-sect571k1-tls13-server] +[74-curve-prime192v1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect571k1 +Curves = prime192v1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[74-curve-sect571k1-tls13-client] +[74-curve-prime192v1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect571k1 +Curves = prime192v1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2309,23 +2284,23 @@ ExpectedResult = ClientFail # =========================================================== -[75-curve-sect571r1-tls13] -ssl_conf = 75-curve-sect571r1-tls13-ssl +[75-curve-sect163r1-tls13] +ssl_conf = 75-curve-sect163r1-tls13-ssl -[75-curve-sect571r1-tls13-ssl] -server = 75-curve-sect571r1-tls13-server -client = 75-curve-sect571r1-tls13-client +[75-curve-sect163r1-tls13-ssl] +server = 75-curve-sect163r1-tls13-server +client = 75-curve-sect163r1-tls13-client -[75-curve-sect571r1-tls13-server] +[75-curve-sect163r1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect571r1 +Curves = sect163r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[75-curve-sect571r1-tls13-client] +[75-curve-sect163r1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect571r1 +Curves = sect163r1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2336,23 +2311,23 @@ ExpectedResult = ClientFail # =========================================================== -[76-curve-secp224r1-tls13] -ssl_conf = 76-curve-secp224r1-tls13-ssl +[76-curve-sect193r1-tls13] +ssl_conf = 76-curve-sect193r1-tls13-ssl -[76-curve-secp224r1-tls13-ssl] -server = 76-curve-secp224r1-tls13-server -client = 76-curve-secp224r1-tls13-client +[76-curve-sect193r1-tls13-ssl] +server = 76-curve-sect193r1-tls13-server +client = 76-curve-sect193r1-tls13-client -[76-curve-secp224r1-tls13-server] +[76-curve-sect193r1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = secp224r1 +Curves = sect193r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[76-curve-secp224r1-tls13-client] +[76-curve-sect193r1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = secp224r1 +Curves = sect193r1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2363,23 +2338,23 @@ ExpectedResult = ClientFail # =========================================================== -[77-curve-sect163k1-tls13] -ssl_conf = 77-curve-sect163k1-tls13-ssl +[77-curve-sect193r2-tls13] +ssl_conf = 77-curve-sect193r2-tls13-ssl -[77-curve-sect163k1-tls13-ssl] -server = 77-curve-sect163k1-tls13-server -client = 77-curve-sect163k1-tls13-client +[77-curve-sect193r2-tls13-ssl] +server = 77-curve-sect193r2-tls13-server +client = 77-curve-sect193r2-tls13-client -[77-curve-sect163k1-tls13-server] +[77-curve-sect193r2-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect163k1 +Curves = sect193r2 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[77-curve-sect163k1-tls13-client] +[77-curve-sect193r2-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect163k1 +Curves = sect193r2 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2390,23 +2365,23 @@ ExpectedResult = ClientFail # =========================================================== -[78-curve-sect163r2-tls13] -ssl_conf = 78-curve-sect163r2-tls13-ssl +[78-curve-sect239k1-tls13] +ssl_conf = 78-curve-sect239k1-tls13-ssl -[78-curve-sect163r2-tls13-ssl] -server = 78-curve-sect163r2-tls13-server -client = 78-curve-sect163r2-tls13-client +[78-curve-sect239k1-tls13-ssl] +server = 78-curve-sect239k1-tls13-server +client = 78-curve-sect239k1-tls13-client -[78-curve-sect163r2-tls13-server] +[78-curve-sect239k1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect163r2 +Curves = sect239k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[78-curve-sect163r2-tls13-client] +[78-curve-sect239k1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect163r2 +Curves = sect239k1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2417,23 +2392,23 @@ ExpectedResult = ClientFail # =========================================================== -[79-curve-prime192v1-tls13] -ssl_conf = 79-curve-prime192v1-tls13-ssl +[79-curve-secp160k1-tls13] +ssl_conf = 79-curve-secp160k1-tls13-ssl -[79-curve-prime192v1-tls13-ssl] -server = 79-curve-prime192v1-tls13-server -client = 79-curve-prime192v1-tls13-client +[79-curve-secp160k1-tls13-ssl] +server = 79-curve-secp160k1-tls13-server +client = 79-curve-secp160k1-tls13-client -[79-curve-prime192v1-tls13-server] +[79-curve-secp160k1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = prime192v1 +Curves = secp160k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[79-curve-prime192v1-tls13-client] +[79-curve-secp160k1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = prime192v1 +Curves = secp160k1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2444,23 +2419,23 @@ ExpectedResult = ClientFail # =========================================================== -[80-curve-sect163r1-tls13] -ssl_conf = 80-curve-sect163r1-tls13-ssl +[80-curve-secp160r1-tls13] +ssl_conf = 80-curve-secp160r1-tls13-ssl -[80-curve-sect163r1-tls13-ssl] -server = 80-curve-sect163r1-tls13-server -client = 80-curve-sect163r1-tls13-client +[80-curve-secp160r1-tls13-ssl] +server = 80-curve-secp160r1-tls13-server +client = 80-curve-secp160r1-tls13-client -[80-curve-sect163r1-tls13-server] +[80-curve-secp160r1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect163r1 +Curves = secp160r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[80-curve-sect163r1-tls13-client] +[80-curve-secp160r1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect163r1 +Curves = secp160r1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2471,23 +2446,23 @@ ExpectedResult = ClientFail # =========================================================== -[81-curve-sect193r1-tls13] -ssl_conf = 81-curve-sect193r1-tls13-ssl +[81-curve-secp160r2-tls13] +ssl_conf = 81-curve-secp160r2-tls13-ssl -[81-curve-sect193r1-tls13-ssl] -server = 81-curve-sect193r1-tls13-server -client = 81-curve-sect193r1-tls13-client +[81-curve-secp160r2-tls13-ssl] +server = 81-curve-secp160r2-tls13-server +client = 81-curve-secp160r2-tls13-client -[81-curve-sect193r1-tls13-server] +[81-curve-secp160r2-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect193r1 +Curves = secp160r2 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[81-curve-sect193r1-tls13-client] +[81-curve-secp160r2-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect193r1 +Curves = secp160r2 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2498,23 +2473,23 @@ ExpectedResult = ClientFail # =========================================================== -[82-curve-sect193r2-tls13] -ssl_conf = 82-curve-sect193r2-tls13-ssl +[82-curve-secp192k1-tls13] +ssl_conf = 82-curve-secp192k1-tls13-ssl -[82-curve-sect193r2-tls13-ssl] -server = 82-curve-sect193r2-tls13-server -client = 82-curve-sect193r2-tls13-client +[82-curve-secp192k1-tls13-ssl] +server = 82-curve-secp192k1-tls13-server +client = 82-curve-secp192k1-tls13-client -[82-curve-sect193r2-tls13-server] +[82-curve-secp192k1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect193r2 +Curves = secp192k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[82-curve-sect193r2-tls13-client] +[82-curve-secp192k1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect193r2 +Curves = secp192k1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2525,23 +2500,23 @@ ExpectedResult = ClientFail # =========================================================== -[83-curve-sect239k1-tls13] -ssl_conf = 83-curve-sect239k1-tls13-ssl +[83-curve-secp224k1-tls13] +ssl_conf = 83-curve-secp224k1-tls13-ssl -[83-curve-sect239k1-tls13-ssl] -server = 83-curve-sect239k1-tls13-server -client = 83-curve-sect239k1-tls13-client +[83-curve-secp224k1-tls13-ssl] +server = 83-curve-secp224k1-tls13-server +client = 83-curve-secp224k1-tls13-client -[83-curve-sect239k1-tls13-server] +[83-curve-secp224k1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = sect239k1 +Curves = secp224k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[83-curve-sect239k1-tls13-client] +[83-curve-secp224k1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = sect239k1 +Curves = secp224k1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2552,23 +2527,23 @@ ExpectedResult = ClientFail # =========================================================== -[84-curve-secp160k1-tls13] -ssl_conf = 84-curve-secp160k1-tls13-ssl +[84-curve-secp256k1-tls13] +ssl_conf = 84-curve-secp256k1-tls13-ssl -[84-curve-secp160k1-tls13-ssl] -server = 84-curve-secp160k1-tls13-server -client = 84-curve-secp160k1-tls13-client +[84-curve-secp256k1-tls13-ssl] +server = 84-curve-secp256k1-tls13-server +client = 84-curve-secp256k1-tls13-client -[84-curve-secp160k1-tls13-server] +[84-curve-secp256k1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = secp160k1 +Curves = secp256k1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[84-curve-secp160k1-tls13-client] +[84-curve-secp256k1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = secp160k1 +Curves = secp256k1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2579,23 +2554,23 @@ ExpectedResult = ClientFail # =========================================================== -[85-curve-secp160r1-tls13] -ssl_conf = 85-curve-secp160r1-tls13-ssl +[85-curve-brainpoolP256r1-tls13] +ssl_conf = 85-curve-brainpoolP256r1-tls13-ssl -[85-curve-secp160r1-tls13-ssl] -server = 85-curve-secp160r1-tls13-server -client = 85-curve-secp160r1-tls13-client +[85-curve-brainpoolP256r1-tls13-ssl] +server = 85-curve-brainpoolP256r1-tls13-server +client = 85-curve-brainpoolP256r1-tls13-client -[85-curve-secp160r1-tls13-server] +[85-curve-brainpoolP256r1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = secp160r1 +Curves = brainpoolP256r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[85-curve-secp160r1-tls13-client] +[85-curve-brainpoolP256r1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = secp160r1 +Curves = brainpoolP256r1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2606,23 +2581,23 @@ ExpectedResult = ClientFail # =========================================================== -[86-curve-secp160r2-tls13] -ssl_conf = 86-curve-secp160r2-tls13-ssl +[86-curve-brainpoolP384r1-tls13] +ssl_conf = 86-curve-brainpoolP384r1-tls13-ssl -[86-curve-secp160r2-tls13-ssl] -server = 86-curve-secp160r2-tls13-server -client = 86-curve-secp160r2-tls13-client +[86-curve-brainpoolP384r1-tls13-ssl] +server = 86-curve-brainpoolP384r1-tls13-server +client = 86-curve-brainpoolP384r1-tls13-client -[86-curve-secp160r2-tls13-server] +[86-curve-brainpoolP384r1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = secp160r2 +Curves = brainpoolP384r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[86-curve-secp160r2-tls13-client] +[86-curve-brainpoolP384r1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = secp160r2 +Curves = brainpoolP384r1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2633,23 +2608,23 @@ ExpectedResult = ClientFail # =========================================================== -[87-curve-secp192k1-tls13] -ssl_conf = 87-curve-secp192k1-tls13-ssl +[87-curve-brainpoolP512r1-tls13] +ssl_conf = 87-curve-brainpoolP512r1-tls13-ssl -[87-curve-secp192k1-tls13-ssl] -server = 87-curve-secp192k1-tls13-server -client = 87-curve-secp192k1-tls13-client +[87-curve-brainpoolP512r1-tls13-ssl] +server = 87-curve-brainpoolP512r1-tls13-server +client = 87-curve-brainpoolP512r1-tls13-client -[87-curve-secp192k1-tls13-server] +[87-curve-brainpoolP512r1-tls13-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = secp192k1 +Curves = brainpoolP512r1 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[87-curve-secp192k1-tls13-client] +[87-curve-brainpoolP512r1-tls13-client] CipherString = ECDHE@SECLEVEL=1 -Curves = secp192k1 +Curves = brainpoolP512r1 MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -2660,838 +2635,433 @@ ExpectedResult = ClientFail # =========================================================== -[88-curve-secp224k1-tls13] -ssl_conf = 88-curve-secp224k1-tls13-ssl +[88-curve-ffdhe2048-tls13-in-tls12] +ssl_conf = 88-curve-ffdhe2048-tls13-in-tls12-ssl -[88-curve-secp224k1-tls13-ssl] -server = 88-curve-secp224k1-tls13-server -client = 88-curve-secp224k1-tls13-client +[88-curve-ffdhe2048-tls13-in-tls12-ssl] +server = 88-curve-ffdhe2048-tls13-in-tls12-server +client = 88-curve-ffdhe2048-tls13-in-tls12-client -[88-curve-secp224k1-tls13-server] +[88-curve-ffdhe2048-tls13-in-tls12-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = secp224k1 +Curves = ffdhe2048 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[88-curve-secp224k1-tls13-client] +[88-curve-ffdhe2048-tls13-in-tls12-client] CipherString = ECDHE@SECLEVEL=1 -Curves = secp224k1 -MinProtocol = TLSv1.3 +Curves = ffdhe2048 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-88] -ExpectedResult = ClientFail +ExpectedResult = ServerFail # =========================================================== -[89-curve-secp256k1-tls13] -ssl_conf = 89-curve-secp256k1-tls13-ssl +[89-curve-ffdhe2048-tls13-in-tls12-2] +ssl_conf = 89-curve-ffdhe2048-tls13-in-tls12-2-ssl -[89-curve-secp256k1-tls13-ssl] -server = 89-curve-secp256k1-tls13-server -client = 89-curve-secp256k1-tls13-client +[89-curve-ffdhe2048-tls13-in-tls12-2-ssl] +server = 89-curve-ffdhe2048-tls13-in-tls12-2-server +client = 89-curve-ffdhe2048-tls13-in-tls12-2-client -[89-curve-secp256k1-tls13-server] +[89-curve-ffdhe2048-tls13-in-tls12-2-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = secp256k1 -MaxProtocol = TLSv1.3 +Curves = ffdhe2048 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[89-curve-secp256k1-tls13-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = secp256k1 -MinProtocol = TLSv1.3 +[89-curve-ffdhe2048-tls13-in-tls12-2-client] +CipherString = DEFAULT@SECLEVEL=1 +Curves = ffdhe2048 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-89] -ExpectedResult = ClientFail +ExpectedResult = Success # =========================================================== -[90-curve-brainpoolP256r1-tls13] -ssl_conf = 90-curve-brainpoolP256r1-tls13-ssl +[90-curve-ffdhe3072-tls13-in-tls12] +ssl_conf = 90-curve-ffdhe3072-tls13-in-tls12-ssl -[90-curve-brainpoolP256r1-tls13-ssl] -server = 90-curve-brainpoolP256r1-tls13-server -client = 90-curve-brainpoolP256r1-tls13-client +[90-curve-ffdhe3072-tls13-in-tls12-ssl] +server = 90-curve-ffdhe3072-tls13-in-tls12-server +client = 90-curve-ffdhe3072-tls13-in-tls12-client -[90-curve-brainpoolP256r1-tls13-server] +[90-curve-ffdhe3072-tls13-in-tls12-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = brainpoolP256r1 +Curves = ffdhe3072 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[90-curve-brainpoolP256r1-tls13-client] +[90-curve-ffdhe3072-tls13-in-tls12-client] CipherString = ECDHE@SECLEVEL=1 -Curves = brainpoolP256r1 -MinProtocol = TLSv1.3 +Curves = ffdhe3072 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-90] -ExpectedResult = ClientFail +ExpectedResult = ServerFail # =========================================================== -[91-curve-brainpoolP384r1-tls13] -ssl_conf = 91-curve-brainpoolP384r1-tls13-ssl +[91-curve-ffdhe3072-tls13-in-tls12-2] +ssl_conf = 91-curve-ffdhe3072-tls13-in-tls12-2-ssl -[91-curve-brainpoolP384r1-tls13-ssl] -server = 91-curve-brainpoolP384r1-tls13-server -client = 91-curve-brainpoolP384r1-tls13-client +[91-curve-ffdhe3072-tls13-in-tls12-2-ssl] +server = 91-curve-ffdhe3072-tls13-in-tls12-2-server +client = 91-curve-ffdhe3072-tls13-in-tls12-2-client -[91-curve-brainpoolP384r1-tls13-server] +[91-curve-ffdhe3072-tls13-in-tls12-2-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = brainpoolP384r1 -MaxProtocol = TLSv1.3 +Curves = ffdhe3072 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[91-curve-brainpoolP384r1-tls13-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = brainpoolP384r1 -MinProtocol = TLSv1.3 +[91-curve-ffdhe3072-tls13-in-tls12-2-client] +CipherString = DEFAULT@SECLEVEL=1 +Curves = ffdhe3072 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-91] -ExpectedResult = ClientFail +ExpectedResult = Success # =========================================================== -[92-curve-brainpoolP512r1-tls13] -ssl_conf = 92-curve-brainpoolP512r1-tls13-ssl +[92-curve-ffdhe4096-tls13-in-tls12] +ssl_conf = 92-curve-ffdhe4096-tls13-in-tls12-ssl -[92-curve-brainpoolP512r1-tls13-ssl] -server = 92-curve-brainpoolP512r1-tls13-server -client = 92-curve-brainpoolP512r1-tls13-client +[92-curve-ffdhe4096-tls13-in-tls12-ssl] +server = 92-curve-ffdhe4096-tls13-in-tls12-server +client = 92-curve-ffdhe4096-tls13-in-tls12-client -[92-curve-brainpoolP512r1-tls13-server] +[92-curve-ffdhe4096-tls13-in-tls12-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = brainpoolP512r1 +Curves = ffdhe4096 MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[92-curve-brainpoolP512r1-tls13-client] +[92-curve-ffdhe4096-tls13-in-tls12-client] CipherString = ECDHE@SECLEVEL=1 -Curves = brainpoolP512r1 -MinProtocol = TLSv1.3 +Curves = ffdhe4096 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-92] -ExpectedResult = ClientFail +ExpectedResult = ServerFail # =========================================================== -[93-curve-ffdhe2048-tls13-in-tls12] -ssl_conf = 93-curve-ffdhe2048-tls13-in-tls12-ssl +[93-curve-ffdhe4096-tls13-in-tls12-2] +ssl_conf = 93-curve-ffdhe4096-tls13-in-tls12-2-ssl -[93-curve-ffdhe2048-tls13-in-tls12-ssl] -server = 93-curve-ffdhe2048-tls13-in-tls12-server -client = 93-curve-ffdhe2048-tls13-in-tls12-client +[93-curve-ffdhe4096-tls13-in-tls12-2-ssl] +server = 93-curve-ffdhe4096-tls13-in-tls12-2-server +client = 93-curve-ffdhe4096-tls13-in-tls12-2-client -[93-curve-ffdhe2048-tls13-in-tls12-server] +[93-curve-ffdhe4096-tls13-in-tls12-2-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = ffdhe2048 -MaxProtocol = TLSv1.3 +Curves = ffdhe4096 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[93-curve-ffdhe2048-tls13-in-tls12-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = ffdhe2048 -MaxProtocol = TLSv1.2 +[93-curve-ffdhe4096-tls13-in-tls12-2-client] +CipherString = DEFAULT@SECLEVEL=1 +Curves = ffdhe4096 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-93] -ExpectedResult = ServerFail +ExpectedResult = Success # =========================================================== -[94-curve-ffdhe2048-tls13-in-tls12-2] -ssl_conf = 94-curve-ffdhe2048-tls13-in-tls12-2-ssl +[94-curve-ffdhe6144-tls13-in-tls12] +ssl_conf = 94-curve-ffdhe6144-tls13-in-tls12-ssl -[94-curve-ffdhe2048-tls13-in-tls12-2-ssl] -server = 94-curve-ffdhe2048-tls13-in-tls12-2-server -client = 94-curve-ffdhe2048-tls13-in-tls12-2-client +[94-curve-ffdhe6144-tls13-in-tls12-ssl] +server = 94-curve-ffdhe6144-tls13-in-tls12-server +client = 94-curve-ffdhe6144-tls13-in-tls12-client -[94-curve-ffdhe2048-tls13-in-tls12-2-server] +[94-curve-ffdhe6144-tls13-in-tls12-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = ffdhe2048 -MaxProtocol = TLSv1.2 +Curves = ffdhe6144 +MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[94-curve-ffdhe2048-tls13-in-tls12-2-client] -CipherString = DEFAULT@SECLEVEL=1 -Curves = ffdhe2048 -MaxProtocol = TLSv1.3 +[94-curve-ffdhe6144-tls13-in-tls12-client] +CipherString = ECDHE@SECLEVEL=1 +Curves = ffdhe6144 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-94] -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== -[95-curve-ffdhe3072-tls13-in-tls12] -ssl_conf = 95-curve-ffdhe3072-tls13-in-tls12-ssl +[95-curve-ffdhe6144-tls13-in-tls12-2] +ssl_conf = 95-curve-ffdhe6144-tls13-in-tls12-2-ssl -[95-curve-ffdhe3072-tls13-in-tls12-ssl] -server = 95-curve-ffdhe3072-tls13-in-tls12-server -client = 95-curve-ffdhe3072-tls13-in-tls12-client +[95-curve-ffdhe6144-tls13-in-tls12-2-ssl] +server = 95-curve-ffdhe6144-tls13-in-tls12-2-server +client = 95-curve-ffdhe6144-tls13-in-tls12-2-client -[95-curve-ffdhe3072-tls13-in-tls12-server] +[95-curve-ffdhe6144-tls13-in-tls12-2-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = ffdhe3072 -MaxProtocol = TLSv1.3 +Curves = ffdhe6144 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[95-curve-ffdhe3072-tls13-in-tls12-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = ffdhe3072 -MaxProtocol = TLSv1.2 +[95-curve-ffdhe6144-tls13-in-tls12-2-client] +CipherString = DEFAULT@SECLEVEL=1 +Curves = ffdhe6144 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-95] -ExpectedResult = ServerFail +ExpectedResult = Success # =========================================================== -[96-curve-ffdhe3072-tls13-in-tls12-2] -ssl_conf = 96-curve-ffdhe3072-tls13-in-tls12-2-ssl +[96-curve-ffdhe8192-tls13-in-tls12] +ssl_conf = 96-curve-ffdhe8192-tls13-in-tls12-ssl -[96-curve-ffdhe3072-tls13-in-tls12-2-ssl] -server = 96-curve-ffdhe3072-tls13-in-tls12-2-server -client = 96-curve-ffdhe3072-tls13-in-tls12-2-client +[96-curve-ffdhe8192-tls13-in-tls12-ssl] +server = 96-curve-ffdhe8192-tls13-in-tls12-server +client = 96-curve-ffdhe8192-tls13-in-tls12-client -[96-curve-ffdhe3072-tls13-in-tls12-2-server] +[96-curve-ffdhe8192-tls13-in-tls12-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = ffdhe3072 -MaxProtocol = TLSv1.2 +Curves = ffdhe8192 +MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[96-curve-ffdhe3072-tls13-in-tls12-2-client] -CipherString = DEFAULT@SECLEVEL=1 -Curves = ffdhe3072 -MaxProtocol = TLSv1.3 +[96-curve-ffdhe8192-tls13-in-tls12-client] +CipherString = ECDHE@SECLEVEL=1 +Curves = ffdhe8192 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-96] -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== -[97-curve-ffdhe4096-tls13-in-tls12] -ssl_conf = 97-curve-ffdhe4096-tls13-in-tls12-ssl +[97-curve-ffdhe8192-tls13-in-tls12-2] +ssl_conf = 97-curve-ffdhe8192-tls13-in-tls12-2-ssl -[97-curve-ffdhe4096-tls13-in-tls12-ssl] -server = 97-curve-ffdhe4096-tls13-in-tls12-server -client = 97-curve-ffdhe4096-tls13-in-tls12-client +[97-curve-ffdhe8192-tls13-in-tls12-2-ssl] +server = 97-curve-ffdhe8192-tls13-in-tls12-2-server +client = 97-curve-ffdhe8192-tls13-in-tls12-2-client -[97-curve-ffdhe4096-tls13-in-tls12-server] +[97-curve-ffdhe8192-tls13-in-tls12-2-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = ffdhe4096 -MaxProtocol = TLSv1.3 +Curves = ffdhe8192 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[97-curve-ffdhe4096-tls13-in-tls12-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = ffdhe4096 -MaxProtocol = TLSv1.2 +[97-curve-ffdhe8192-tls13-in-tls12-2-client] +CipherString = DEFAULT@SECLEVEL=1 +Curves = ffdhe8192 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-97] -ExpectedResult = ServerFail +ExpectedResult = Success # =========================================================== -[98-curve-ffdhe4096-tls13-in-tls12-2] -ssl_conf = 98-curve-ffdhe4096-tls13-in-tls12-2-ssl +[98-curve-brainpoolP256r1tls13-tls13-in-tls12] +ssl_conf = 98-curve-brainpoolP256r1tls13-tls13-in-tls12-ssl -[98-curve-ffdhe4096-tls13-in-tls12-2-ssl] -server = 98-curve-ffdhe4096-tls13-in-tls12-2-server -client = 98-curve-ffdhe4096-tls13-in-tls12-2-client +[98-curve-brainpoolP256r1tls13-tls13-in-tls12-ssl] +server = 98-curve-brainpoolP256r1tls13-tls13-in-tls12-server +client = 98-curve-brainpoolP256r1tls13-tls13-in-tls12-client -[98-curve-ffdhe4096-tls13-in-tls12-2-server] +[98-curve-brainpoolP256r1tls13-tls13-in-tls12-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = ffdhe4096 -MaxProtocol = TLSv1.2 +Curves = brainpoolP256r1tls13 +MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[98-curve-ffdhe4096-tls13-in-tls12-2-client] -CipherString = DEFAULT@SECLEVEL=1 -Curves = ffdhe4096 -MaxProtocol = TLSv1.3 +[98-curve-brainpoolP256r1tls13-tls13-in-tls12-client] +CipherString = ECDHE@SECLEVEL=1 +Curves = brainpoolP256r1tls13 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-98] -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== -[99-curve-ffdhe6144-tls13-in-tls12] -ssl_conf = 99-curve-ffdhe6144-tls13-in-tls12-ssl +[99-curve-brainpoolP256r1tls13-tls13-in-tls12-2] +ssl_conf = 99-curve-brainpoolP256r1tls13-tls13-in-tls12-2-ssl -[99-curve-ffdhe6144-tls13-in-tls12-ssl] -server = 99-curve-ffdhe6144-tls13-in-tls12-server -client = 99-curve-ffdhe6144-tls13-in-tls12-client +[99-curve-brainpoolP256r1tls13-tls13-in-tls12-2-ssl] +server = 99-curve-brainpoolP256r1tls13-tls13-in-tls12-2-server +client = 99-curve-brainpoolP256r1tls13-tls13-in-tls12-2-client -[99-curve-ffdhe6144-tls13-in-tls12-server] +[99-curve-brainpoolP256r1tls13-tls13-in-tls12-2-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = ffdhe6144 -MaxProtocol = TLSv1.3 +Curves = brainpoolP256r1tls13 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[99-curve-ffdhe6144-tls13-in-tls12-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = ffdhe6144 -MaxProtocol = TLSv1.2 +[99-curve-brainpoolP256r1tls13-tls13-in-tls12-2-client] +CipherString = DEFAULT@SECLEVEL=1 +Curves = brainpoolP256r1tls13 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-99] -ExpectedResult = ServerFail +ExpectedResult = Success # =========================================================== -[100-curve-ffdhe6144-tls13-in-tls12-2] -ssl_conf = 100-curve-ffdhe6144-tls13-in-tls12-2-ssl +[100-curve-brainpoolP384r1tls13-tls13-in-tls12] +ssl_conf = 100-curve-brainpoolP384r1tls13-tls13-in-tls12-ssl -[100-curve-ffdhe6144-tls13-in-tls12-2-ssl] -server = 100-curve-ffdhe6144-tls13-in-tls12-2-server -client = 100-curve-ffdhe6144-tls13-in-tls12-2-client +[100-curve-brainpoolP384r1tls13-tls13-in-tls12-ssl] +server = 100-curve-brainpoolP384r1tls13-tls13-in-tls12-server +client = 100-curve-brainpoolP384r1tls13-tls13-in-tls12-client -[100-curve-ffdhe6144-tls13-in-tls12-2-server] +[100-curve-brainpoolP384r1tls13-tls13-in-tls12-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = ffdhe6144 -MaxProtocol = TLSv1.2 +Curves = brainpoolP384r1tls13 +MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[100-curve-ffdhe6144-tls13-in-tls12-2-client] -CipherString = DEFAULT@SECLEVEL=1 -Curves = ffdhe6144 -MaxProtocol = TLSv1.3 +[100-curve-brainpoolP384r1tls13-tls13-in-tls12-client] +CipherString = ECDHE@SECLEVEL=1 +Curves = brainpoolP384r1tls13 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-100] -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== -[101-curve-ffdhe8192-tls13-in-tls12] -ssl_conf = 101-curve-ffdhe8192-tls13-in-tls12-ssl +[101-curve-brainpoolP384r1tls13-tls13-in-tls12-2] +ssl_conf = 101-curve-brainpoolP384r1tls13-tls13-in-tls12-2-ssl -[101-curve-ffdhe8192-tls13-in-tls12-ssl] -server = 101-curve-ffdhe8192-tls13-in-tls12-server -client = 101-curve-ffdhe8192-tls13-in-tls12-client +[101-curve-brainpoolP384r1tls13-tls13-in-tls12-2-ssl] +server = 101-curve-brainpoolP384r1tls13-tls13-in-tls12-2-server +client = 101-curve-brainpoolP384r1tls13-tls13-in-tls12-2-client -[101-curve-ffdhe8192-tls13-in-tls12-server] +[101-curve-brainpoolP384r1tls13-tls13-in-tls12-2-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = ffdhe8192 -MaxProtocol = TLSv1.3 +Curves = brainpoolP384r1tls13 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[101-curve-ffdhe8192-tls13-in-tls12-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = ffdhe8192 -MaxProtocol = TLSv1.2 +[101-curve-brainpoolP384r1tls13-tls13-in-tls12-2-client] +CipherString = DEFAULT@SECLEVEL=1 +Curves = brainpoolP384r1tls13 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-101] -ExpectedResult = ServerFail +ExpectedResult = Success # =========================================================== -[102-curve-ffdhe8192-tls13-in-tls12-2] -ssl_conf = 102-curve-ffdhe8192-tls13-in-tls12-2-ssl +[102-curve-brainpoolP512r1tls13-tls13-in-tls12] +ssl_conf = 102-curve-brainpoolP512r1tls13-tls13-in-tls12-ssl -[102-curve-ffdhe8192-tls13-in-tls12-2-ssl] -server = 102-curve-ffdhe8192-tls13-in-tls12-2-server -client = 102-curve-ffdhe8192-tls13-in-tls12-2-client +[102-curve-brainpoolP512r1tls13-tls13-in-tls12-ssl] +server = 102-curve-brainpoolP512r1tls13-tls13-in-tls12-server +client = 102-curve-brainpoolP512r1tls13-tls13-in-tls12-client -[102-curve-ffdhe8192-tls13-in-tls12-2-server] +[102-curve-brainpoolP512r1tls13-tls13-in-tls12-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = ffdhe8192 -MaxProtocol = TLSv1.2 +Curves = brainpoolP512r1tls13 +MaxProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[102-curve-ffdhe8192-tls13-in-tls12-2-client] -CipherString = DEFAULT@SECLEVEL=1 -Curves = ffdhe8192 -MaxProtocol = TLSv1.3 +[102-curve-brainpoolP512r1tls13-tls13-in-tls12-client] +CipherString = ECDHE@SECLEVEL=1 +Curves = brainpoolP512r1tls13 +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-102] -ExpectedResult = Success +ExpectedResult = ServerFail # =========================================================== -[103-curve-brainpoolP256r1tls13-tls13-in-tls12] -ssl_conf = 103-curve-brainpoolP256r1tls13-tls13-in-tls12-ssl +[103-curve-brainpoolP512r1tls13-tls13-in-tls12-2] +ssl_conf = 103-curve-brainpoolP512r1tls13-tls13-in-tls12-2-ssl -[103-curve-brainpoolP256r1tls13-tls13-in-tls12-ssl] -server = 103-curve-brainpoolP256r1tls13-tls13-in-tls12-server -client = 103-curve-brainpoolP256r1tls13-tls13-in-tls12-client +[103-curve-brainpoolP512r1tls13-tls13-in-tls12-2-ssl] +server = 103-curve-brainpoolP512r1tls13-tls13-in-tls12-2-server +client = 103-curve-brainpoolP512r1tls13-tls13-in-tls12-2-client -[103-curve-brainpoolP256r1tls13-tls13-in-tls12-server] +[103-curve-brainpoolP512r1tls13-tls13-in-tls12-2-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT@SECLEVEL=1 -Curves = brainpoolP256r1tls13 -MaxProtocol = TLSv1.3 +Curves = brainpoolP512r1tls13 +MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[103-curve-brainpoolP256r1tls13-tls13-in-tls12-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = brainpoolP256r1tls13 -MaxProtocol = TLSv1.2 +[103-curve-brainpoolP512r1tls13-tls13-in-tls12-2-client] +CipherString = DEFAULT@SECLEVEL=1 +Curves = brainpoolP512r1tls13 +MaxProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-103] -ExpectedResult = ServerFail - - -# =========================================================== - -[104-curve-brainpoolP256r1tls13-tls13-in-tls12-2] -ssl_conf = 104-curve-brainpoolP256r1tls13-tls13-in-tls12-2-ssl - -[104-curve-brainpoolP256r1tls13-tls13-in-tls12-2-ssl] -server = 104-curve-brainpoolP256r1tls13-tls13-in-tls12-2-server -client = 104-curve-brainpoolP256r1tls13-tls13-in-tls12-2-client - -[104-curve-brainpoolP256r1tls13-tls13-in-tls12-2-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = brainpoolP256r1tls13 -MaxProtocol = TLSv1.2 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[104-curve-brainpoolP256r1tls13-tls13-in-tls12-2-client] -CipherString = DEFAULT@SECLEVEL=1 -Curves = brainpoolP256r1tls13 -MaxProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-104] -ExpectedResult = Success - - -# =========================================================== - -[105-curve-brainpoolP384r1tls13-tls13-in-tls12] -ssl_conf = 105-curve-brainpoolP384r1tls13-tls13-in-tls12-ssl - -[105-curve-brainpoolP384r1tls13-tls13-in-tls12-ssl] -server = 105-curve-brainpoolP384r1tls13-tls13-in-tls12-server -client = 105-curve-brainpoolP384r1tls13-tls13-in-tls12-client - -[105-curve-brainpoolP384r1tls13-tls13-in-tls12-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = brainpoolP384r1tls13 -MaxProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[105-curve-brainpoolP384r1tls13-tls13-in-tls12-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = brainpoolP384r1tls13 -MaxProtocol = TLSv1.2 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-105] -ExpectedResult = ServerFail - - -# =========================================================== - -[106-curve-brainpoolP384r1tls13-tls13-in-tls12-2] -ssl_conf = 106-curve-brainpoolP384r1tls13-tls13-in-tls12-2-ssl - -[106-curve-brainpoolP384r1tls13-tls13-in-tls12-2-ssl] -server = 106-curve-brainpoolP384r1tls13-tls13-in-tls12-2-server -client = 106-curve-brainpoolP384r1tls13-tls13-in-tls12-2-client - -[106-curve-brainpoolP384r1tls13-tls13-in-tls12-2-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = brainpoolP384r1tls13 -MaxProtocol = TLSv1.2 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[106-curve-brainpoolP384r1tls13-tls13-in-tls12-2-client] -CipherString = DEFAULT@SECLEVEL=1 -Curves = brainpoolP384r1tls13 -MaxProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-106] -ExpectedResult = Success - - -# =========================================================== - -[107-curve-brainpoolP512r1tls13-tls13-in-tls12] -ssl_conf = 107-curve-brainpoolP512r1tls13-tls13-in-tls12-ssl - -[107-curve-brainpoolP512r1tls13-tls13-in-tls12-ssl] -server = 107-curve-brainpoolP512r1tls13-tls13-in-tls12-server -client = 107-curve-brainpoolP512r1tls13-tls13-in-tls12-client - -[107-curve-brainpoolP512r1tls13-tls13-in-tls12-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = brainpoolP512r1tls13 -MaxProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[107-curve-brainpoolP512r1tls13-tls13-in-tls12-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = brainpoolP512r1tls13 -MaxProtocol = TLSv1.2 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-107] -ExpectedResult = ServerFail - - -# =========================================================== - -[108-curve-brainpoolP512r1tls13-tls13-in-tls12-2] -ssl_conf = 108-curve-brainpoolP512r1tls13-tls13-in-tls12-2-ssl - -[108-curve-brainpoolP512r1tls13-tls13-in-tls12-2-ssl] -server = 108-curve-brainpoolP512r1tls13-tls13-in-tls12-2-server -client = 108-curve-brainpoolP512r1tls13-tls13-in-tls12-2-client - -[108-curve-brainpoolP512r1tls13-tls13-in-tls12-2-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = brainpoolP512r1tls13 -MaxProtocol = TLSv1.2 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[108-curve-brainpoolP512r1tls13-tls13-in-tls12-2-client] -CipherString = DEFAULT@SECLEVEL=1 -Curves = brainpoolP512r1tls13 -MaxProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-108] -ExpectedResult = Success - - -# =========================================================== - -[109-curve-X25519MLKEM768-tls13-in-tls12] -ssl_conf = 109-curve-X25519MLKEM768-tls13-in-tls12-ssl - -[109-curve-X25519MLKEM768-tls13-in-tls12-ssl] -server = 109-curve-X25519MLKEM768-tls13-in-tls12-server -client = 109-curve-X25519MLKEM768-tls13-in-tls12-client - -[109-curve-X25519MLKEM768-tls13-in-tls12-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = X25519MLKEM768 -MaxProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[109-curve-X25519MLKEM768-tls13-in-tls12-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = X25519MLKEM768 -MaxProtocol = TLSv1.2 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-109] -ExpectedResult = ServerFail - - -# =========================================================== - -[110-curve-X25519MLKEM768-tls13-in-tls12-2] -ssl_conf = 110-curve-X25519MLKEM768-tls13-in-tls12-2-ssl - -[110-curve-X25519MLKEM768-tls13-in-tls12-2-ssl] -server = 110-curve-X25519MLKEM768-tls13-in-tls12-2-server -client = 110-curve-X25519MLKEM768-tls13-in-tls12-2-client - -[110-curve-X25519MLKEM768-tls13-in-tls12-2-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = X25519MLKEM768 -MaxProtocol = TLSv1.2 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[110-curve-X25519MLKEM768-tls13-in-tls12-2-client] -CipherString = DEFAULT@SECLEVEL=1 -Curves = X25519MLKEM768 -MaxProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-110] -ExpectedResult = Success - - -# =========================================================== - -[111-curve-SecP256r1MLKEM768-tls13-in-tls12] -ssl_conf = 111-curve-SecP256r1MLKEM768-tls13-in-tls12-ssl - -[111-curve-SecP256r1MLKEM768-tls13-in-tls12-ssl] -server = 111-curve-SecP256r1MLKEM768-tls13-in-tls12-server -client = 111-curve-SecP256r1MLKEM768-tls13-in-tls12-client - -[111-curve-SecP256r1MLKEM768-tls13-in-tls12-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = SecP256r1MLKEM768 -MaxProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[111-curve-SecP256r1MLKEM768-tls13-in-tls12-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = SecP256r1MLKEM768 -MaxProtocol = TLSv1.2 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-111] -ExpectedResult = ServerFail - - -# =========================================================== - -[112-curve-SecP256r1MLKEM768-tls13-in-tls12-2] -ssl_conf = 112-curve-SecP256r1MLKEM768-tls13-in-tls12-2-ssl - -[112-curve-SecP256r1MLKEM768-tls13-in-tls12-2-ssl] -server = 112-curve-SecP256r1MLKEM768-tls13-in-tls12-2-server -client = 112-curve-SecP256r1MLKEM768-tls13-in-tls12-2-client - -[112-curve-SecP256r1MLKEM768-tls13-in-tls12-2-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = SecP256r1MLKEM768 -MaxProtocol = TLSv1.2 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[112-curve-SecP256r1MLKEM768-tls13-in-tls12-2-client] -CipherString = DEFAULT@SECLEVEL=1 -Curves = SecP256r1MLKEM768 -MaxProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-112] -ExpectedResult = Success - - -# =========================================================== - -[113-curve-SecP384r1MLKEM1024-tls13-in-tls12] -ssl_conf = 113-curve-SecP384r1MLKEM1024-tls13-in-tls12-ssl - -[113-curve-SecP384r1MLKEM1024-tls13-in-tls12-ssl] -server = 113-curve-SecP384r1MLKEM1024-tls13-in-tls12-server -client = 113-curve-SecP384r1MLKEM1024-tls13-in-tls12-client - -[113-curve-SecP384r1MLKEM1024-tls13-in-tls12-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = SecP384r1MLKEM1024 -MaxProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[113-curve-SecP384r1MLKEM1024-tls13-in-tls12-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = SecP384r1MLKEM1024 -MaxProtocol = TLSv1.2 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-113] -ExpectedResult = ServerFail - - -# =========================================================== - -[114-curve-SecP384r1MLKEM1024-tls13-in-tls12-2] -ssl_conf = 114-curve-SecP384r1MLKEM1024-tls13-in-tls12-2-ssl - -[114-curve-SecP384r1MLKEM1024-tls13-in-tls12-2-ssl] -server = 114-curve-SecP384r1MLKEM1024-tls13-in-tls12-2-server -client = 114-curve-SecP384r1MLKEM1024-tls13-in-tls12-2-client - -[114-curve-SecP384r1MLKEM1024-tls13-in-tls12-2-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = SecP384r1MLKEM1024 -MaxProtocol = TLSv1.2 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[114-curve-SecP384r1MLKEM1024-tls13-in-tls12-2-client] -CipherString = DEFAULT@SECLEVEL=1 -Curves = SecP384r1MLKEM1024 -MaxProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-114] -ExpectedResult = Success - - -# =========================================================== - -[115-curve-curveSM2-tls13-in-tls12] -ssl_conf = 115-curve-curveSM2-tls13-in-tls12-ssl - -[115-curve-curveSM2-tls13-in-tls12-ssl] -server = 115-curve-curveSM2-tls13-in-tls12-server -client = 115-curve-curveSM2-tls13-in-tls12-client - -[115-curve-curveSM2-tls13-in-tls12-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = curveSM2 -MaxProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[115-curve-curveSM2-tls13-in-tls12-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = curveSM2 -MaxProtocol = TLSv1.2 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-115] -ExpectedResult = ServerFail - - -# =========================================================== - -[116-curve-curveSM2-tls13-in-tls12-2] -ssl_conf = 116-curve-curveSM2-tls13-in-tls12-2-ssl - -[116-curve-curveSM2-tls13-in-tls12-2-ssl] -server = 116-curve-curveSM2-tls13-in-tls12-2-server -client = 116-curve-curveSM2-tls13-in-tls12-2-client - -[116-curve-curveSM2-tls13-in-tls12-2-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = curveSM2 -MaxProtocol = TLSv1.2 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[116-curve-curveSM2-tls13-in-tls12-2-client] -CipherString = DEFAULT@SECLEVEL=1 -Curves = curveSM2 -MaxProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-116] -ExpectedResult = Success - - -# =========================================================== - -[117-curve-curveSM2MLKEM768-tls13-in-tls12] -ssl_conf = 117-curve-curveSM2MLKEM768-tls13-in-tls12-ssl - -[117-curve-curveSM2MLKEM768-tls13-in-tls12-ssl] -server = 117-curve-curveSM2MLKEM768-tls13-in-tls12-server -client = 117-curve-curveSM2MLKEM768-tls13-in-tls12-client - -[117-curve-curveSM2MLKEM768-tls13-in-tls12-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = curveSM2MLKEM768 -MaxProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[117-curve-curveSM2MLKEM768-tls13-in-tls12-client] -CipherString = ECDHE@SECLEVEL=1 -Curves = curveSM2MLKEM768 -MaxProtocol = TLSv1.2 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-117] -ExpectedResult = ServerFail - - -# =========================================================== - -[118-curve-curveSM2MLKEM768-tls13-in-tls12-2] -ssl_conf = 118-curve-curveSM2MLKEM768-tls13-in-tls12-2-ssl - -[118-curve-curveSM2MLKEM768-tls13-in-tls12-2-ssl] -server = 118-curve-curveSM2MLKEM768-tls13-in-tls12-2-server -client = 118-curve-curveSM2MLKEM768-tls13-in-tls12-2-client - -[118-curve-curveSM2MLKEM768-tls13-in-tls12-2-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT@SECLEVEL=1 -Curves = curveSM2MLKEM768 -MaxProtocol = TLSv1.2 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[118-curve-curveSM2MLKEM768-tls13-in-tls12-2-client] -CipherString = DEFAULT@SECLEVEL=1 -Curves = curveSM2MLKEM768 -MaxProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-118] ExpectedResult = Success diff --git a/test/ssl-tests/14-curves.cnf.in b/test/ssl-tests/14-curves.cnf.in index abcdb5dc0f..e50421d501 100644 --- a/test/ssl-tests/14-curves.cnf.in +++ b/test/ssl-tests/14-curves.cnf.in @@ -12,7 +12,6 @@ use OpenSSL::Test::Utils; our $fips_mode; our $fips_3_4; -our $fips_3_5; my @curves = ("prime256v1", "secp384r1", "secp521r1"); @@ -46,19 +45,6 @@ push @curves_non_fips, push @curves_tls_1_2, @curves_non_fips if !$fips_mode; -my @curves_no_nid = (); -push @curves_no_nid, qw(X25519MLKEM768) - unless (disabled("ml-kem") || disabled("ecx") || ($fips_mode && !$fips_3_5)); -push @curves_no_nid, qw(SecP256r1MLKEM768 SecP384r1MLKEM1024) - unless (disabled("ml-kem") || ($fips_mode && !$fips_3_5)); -push @curves_no_nid, qw(curveSM2) - unless ($fips_mode || disabled("sm2")); -push @curves_no_nid, qw(curveSM2MLKEM768) - unless ($fips_mode || disabled("sm2") || disabled("ml-kem")); - -push @curves_tls_1_3, @curves_no_nid; -push @curves, @curves_no_nid; - our @tests = (); sub get_key_type { diff --git a/test/ssl-tests/20-cert-select.cnf b/test/ssl-tests/20-cert-select.cnf index 10b49efd4a..12c0de1e79 100644 --- a/test/ssl-tests/20-cert-select.cnf +++ b/test/ssl-tests/20-cert-select.cnf @@ -1,6 +1,6 @@ # Generated with generate_ssl_tests.pl -num_tests = 63 +num_tests = 58 test-0 = 0-ECDSA CipherString Selection test-1 = 1-ECDSA CipherString Selection @@ -21,50 +21,45 @@ test-15 = 15-Ed25519 CipherString and Signature Algorithm Selection test-16 = 16-Ed448 CipherString and Signature Algorithm Selection test-17 = 17-TLS 1.2 Ed25519 Client Auth test-18 = 18-TLS 1.2 Ed448 Client Auth -test-19 = 19-DTLS 1.2 Ed25519 CipherString and Signature Algorithm Selection -test-20 = 20-DTLS 1.2 Ed448 CipherString and Signature Algorithm Selection -test-21 = 21-DTLS 1.2 Ed25519 Client Auth -test-22 = 22-DTLS 1.2 Ed448 Client Auth -test-23 = 23-ECDSA Signature Algorithm Selection SHA1 -test-24 = 24-ECDSA with brainpool -test-25 = 25-Ed25519 CipherString and Curves Selection -test-26 = 26-Ed448 CipherString and Curves Selection -test-27 = 27-RSA-PSS Certificate CipherString Selection -test-28 = 28-RSA-PSS Certificate Legacy Signature Algorithm Selection -test-29 = 29-RSA-PSS Certificate Unified Signature Algorithm Selection -test-30 = 30-Only RSA-PSS Certificate -test-31 = 31-Only RSA-PSS Certificate Valid Signature Algorithms -test-32 = 32-RSA-PSS Certificate, no PSS signature algorithms -test-33 = 33-Only RSA-PSS Restricted Certificate -test-34 = 34-RSA-PSS Restricted Certificate Valid Signature Algorithms -test-35 = 35-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm -test-36 = 36-RSA-PSS Restricted Certificate Invalid Signature Algorithms -test-37 = 37-RSA key exchange with only RSA-PSS certificate -test-38 = 38-Only RSA-PSS Certificate, TLS v1.1 -test-39 = 39-TLS 1.3 ECDSA Signature Algorithm Selection -test-40 = 40-TLS 1.3 ECDSA Signature Algorithm Selection compressed point -test-41 = 41-TLS 1.3 ECDSA Signature Algorithm Selection SHA1 -test-42 = 42-TLS 1.3 ECDSA Signature Algorithm Selection with PSS -test-43 = 43-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS -test-44 = 44-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate -test-45 = 45-TLS 1.3 RSA Signature Algorithm Selection, no PSS -test-46 = 46-TLS 1.3 RSA-PSS Signature Algorithm Selection -test-47 = 47-TLS 1.3 RSA Client Auth Signature Algorithm Selection -test-48 = 48-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names -test-49 = 49-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection -test-50 = 50-TLS 1.3 Ed25519 Signature Algorithm Selection -test-51 = 51-TLS 1.3 Ed448 Signature Algorithm Selection -test-52 = 52-TLS 1.3 Ed25519 CipherString and Groups Selection -test-53 = 53-TLS 1.3 Ed448 CipherString and Groups Selection -test-54 = 54-TLS 1.3 Ed25519 Client Auth -test-55 = 55-TLS 1.3 Ed448 Client Auth -test-56 = 56-TLS 1.3 ECDSA with brainpool but no suitable groups -test-57 = 57-TLS 1.3 ECDSA with brainpool -test-58 = 58-TLS 1.3 SM2 -test-59 = 59-TLS 1.2 DSA Certificate Test -test-60 = 60-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms -test-61 = 61-TLS 1.3 DSA Certificate Test -test-62 = 62-TLS 1.3 ML-DSA Certificate Test +test-19 = 19-ECDSA Signature Algorithm Selection SHA1 +test-20 = 20-ECDSA with brainpool +test-21 = 21-Ed25519 CipherString and Curves Selection +test-22 = 22-Ed448 CipherString and Curves Selection +test-23 = 23-RSA-PSS Certificate CipherString Selection +test-24 = 24-RSA-PSS Certificate Legacy Signature Algorithm Selection +test-25 = 25-RSA-PSS Certificate Unified Signature Algorithm Selection +test-26 = 26-Only RSA-PSS Certificate +test-27 = 27-Only RSA-PSS Certificate Valid Signature Algorithms +test-28 = 28-RSA-PSS Certificate, no PSS signature algorithms +test-29 = 29-Only RSA-PSS Restricted Certificate +test-30 = 30-RSA-PSS Restricted Certificate Valid Signature Algorithms +test-31 = 31-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm +test-32 = 32-RSA-PSS Restricted Certificate Invalid Signature Algorithms +test-33 = 33-RSA key exchange with only RSA-PSS certificate +test-34 = 34-Only RSA-PSS Certificate, TLS v1.1 +test-35 = 35-TLS 1.3 ECDSA Signature Algorithm Selection +test-36 = 36-TLS 1.3 ECDSA Signature Algorithm Selection compressed point +test-37 = 37-TLS 1.3 ECDSA Signature Algorithm Selection SHA1 +test-38 = 38-TLS 1.3 ECDSA Signature Algorithm Selection with PSS +test-39 = 39-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS +test-40 = 40-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate +test-41 = 41-TLS 1.3 RSA Signature Algorithm Selection, no PSS +test-42 = 42-TLS 1.3 RSA-PSS Signature Algorithm Selection +test-43 = 43-TLS 1.3 RSA Client Auth Signature Algorithm Selection +test-44 = 44-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names +test-45 = 45-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection +test-46 = 46-TLS 1.3 Ed25519 Signature Algorithm Selection +test-47 = 47-TLS 1.3 Ed448 Signature Algorithm Selection +test-48 = 48-TLS 1.3 Ed25519 CipherString and Groups Selection +test-49 = 49-TLS 1.3 Ed448 CipherString and Groups Selection +test-50 = 50-TLS 1.3 Ed25519 Client Auth +test-51 = 51-TLS 1.3 Ed448 Client Auth +test-52 = 52-TLS 1.3 ECDSA with brainpool but no suitable groups +test-53 = 53-TLS 1.3 ECDSA with brainpool +test-54 = 54-TLS 1.2 DSA Certificate Test +test-55 = 55-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms +test-56 = 56-TLS 1.3 DSA Certificate Test +test-57 = 57-TLS 1.3 ML-DSA Certificate Test # =========================================================== [0-ECDSA CipherString Selection] @@ -672,16 +667,16 @@ ExpectedResult = Success # =========================================================== -[19-DTLS 1.2 Ed25519 CipherString and Signature Algorithm Selection] -ssl_conf = 19-DTLS 1.2 Ed25519 CipherString and Signature Algorithm Selection-ssl +[19-ECDSA Signature Algorithm Selection SHA1] +ssl_conf = 19-ECDSA Signature Algorithm Selection SHA1-ssl -[19-DTLS 1.2 Ed25519 CipherString and Signature Algorithm Selection-ssl] -server = 19-DTLS 1.2 Ed25519 CipherString and Signature Algorithm Selection-server -client = 19-DTLS 1.2 Ed25519 CipherString and Signature Algorithm Selection-client +[19-ECDSA Signature Algorithm Selection SHA1-ssl] +server = 19-ECDSA Signature Algorithm Selection SHA1-server +client = 19-ECDSA Signature Algorithm Selection SHA1-client -[19-DTLS 1.2 Ed25519 CipherString and Signature Algorithm Selection-server] +[19-ECDSA Signature Algorithm Selection SHA1-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT +CipherString = DEFAULT:@SECLEVEL=0 ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem ECDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ecdsa-key.pem Ed25519.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed25519-cert.pem @@ -691,150 +686,14 @@ Ed448.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed448-key.pem MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[19-DTLS 1.2 Ed25519 CipherString and Signature Algorithm Selection-client] -CipherString = aECDSA -MaxProtocol = DTLSv1.2 -MinProtocol = DTLSv1.2 -RequestCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem -SignatureAlgorithms = ed25519:eCdsa+SHA256 +[19-ECDSA Signature Algorithm Selection SHA1-client] +CipherString = DEFAULT:@SECLEVEL=0 +SignatureAlgorithms = ECdSa+SHA1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-19] ExpectedResult = Success -ExpectedServerCANames = empty -ExpectedServerCertType = Ed25519 -ExpectedServerSignType = Ed25519 - - -# =========================================================== - -[20-DTLS 1.2 Ed448 CipherString and Signature Algorithm Selection] -ssl_conf = 20-DTLS 1.2 Ed448 CipherString and Signature Algorithm Selection-ssl - -[20-DTLS 1.2 Ed448 CipherString and Signature Algorithm Selection-ssl] -server = 20-DTLS 1.2 Ed448 CipherString and Signature Algorithm Selection-server -client = 20-DTLS 1.2 Ed448 CipherString and Signature Algorithm Selection-client - -[20-DTLS 1.2 Ed448 CipherString and Signature Algorithm Selection-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT -ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem -ECDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ecdsa-key.pem -Ed25519.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed25519-cert.pem -Ed25519.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed25519-key.pem -Ed448.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed448-cert.pem -Ed448.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed448-key.pem -MaxProtocol = TLSv1.2 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[20-DTLS 1.2 Ed448 CipherString and Signature Algorithm Selection-client] -CipherString = aECDSA -MaxProtocol = DTLSv1.2 -MinProtocol = DTLSv1.2 -RequestCAFile = ${ENV::TEST_CERTS_DIR}/root-ed448-cert.pem -SignatureAlgorithms = ed448:EcDSA+SHA256 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-ed448-cert.pem -VerifyMode = Peer - -[test-20] -ExpectedResult = Success -ExpectedServerCANames = empty -ExpectedServerCertType = Ed448 -ExpectedServerSignType = Ed448 - - -# =========================================================== - -[21-DTLS 1.2 Ed25519 Client Auth] -ssl_conf = 21-DTLS 1.2 Ed25519 Client Auth-ssl - -[21-DTLS 1.2 Ed25519 Client Auth-ssl] -server = 21-DTLS 1.2 Ed25519 Client Auth-server -client = 21-DTLS 1.2 Ed25519 Client Auth-client - -[21-DTLS 1.2 Ed25519 Client Auth-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem -VerifyMode = Require - -[21-DTLS 1.2 Ed25519 Client Auth-client] -CipherString = DEFAULT -Ed25519.Certificate = ${ENV::TEST_CERTS_DIR}/client-ed25519-cert.pem -Ed25519.PrivateKey = ${ENV::TEST_CERTS_DIR}/client-ed25519-key.pem -MaxProtocol = DTLSv1.2 -MinProtocol = DTLSv1.2 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-21] -ExpectedClientCertType = Ed25519 -ExpectedClientSignType = Ed25519 -ExpectedResult = Success - - -# =========================================================== - -[22-DTLS 1.2 Ed448 Client Auth] -ssl_conf = 22-DTLS 1.2 Ed448 Client Auth-ssl - -[22-DTLS 1.2 Ed448 Client Auth-ssl] -server = 22-DTLS 1.2 Ed448 Client Auth-server -client = 22-DTLS 1.2 Ed448 Client Auth-client - -[22-DTLS 1.2 Ed448 Client Auth-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem -VerifyMode = Require - -[22-DTLS 1.2 Ed448 Client Auth-client] -CipherString = DEFAULT -Ed448.Certificate = ${ENV::TEST_CERTS_DIR}/client-ed448-cert.pem -Ed448.PrivateKey = ${ENV::TEST_CERTS_DIR}/client-ed448-key.pem -MaxProtocol = DTLSv1.2 -MinProtocol = DTLSv1.2 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-22] -ExpectedClientCertType = Ed448 -ExpectedClientSignType = Ed448 -ExpectedResult = Success - - -# =========================================================== - -[23-ECDSA Signature Algorithm Selection SHA1] -ssl_conf = 23-ECDSA Signature Algorithm Selection SHA1-ssl - -[23-ECDSA Signature Algorithm Selection SHA1-ssl] -server = 23-ECDSA Signature Algorithm Selection SHA1-server -client = 23-ECDSA Signature Algorithm Selection SHA1-client - -[23-ECDSA Signature Algorithm Selection SHA1-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT:@SECLEVEL=0 -ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem -ECDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ecdsa-key.pem -Ed25519.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed25519-cert.pem -Ed25519.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed25519-key.pem -Ed448.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed448-cert.pem -Ed448.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed448-key.pem -MaxProtocol = TLSv1.2 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[23-ECDSA Signature Algorithm Selection SHA1-client] -CipherString = DEFAULT:@SECLEVEL=0 -SignatureAlgorithms = ECdsa+SHA1 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-23] -ExpectedResult = Success ExpectedServerCertType = P-256 ExpectedServerSignHash = SHA1 ExpectedServerSignType = EC @@ -842,20 +701,20 @@ ExpectedServerSignType = EC # =========================================================== -[24-ECDSA with brainpool] -ssl_conf = 24-ECDSA with brainpool-ssl +[20-ECDSA with brainpool] +ssl_conf = 20-ECDSA with brainpool-ssl -[24-ECDSA with brainpool-ssl] -server = 24-ECDSA with brainpool-server -client = 24-ECDSA with brainpool-client +[20-ECDSA with brainpool-ssl] +server = 20-ECDSA with brainpool-server +client = 20-ECDSA with brainpool-client -[24-ECDSA with brainpool-server] +[20-ECDSA with brainpool-server] Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-brainpoolP256r1-cert.pem CipherString = DEFAULT Groups = brainpoolP256r1 PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ecdsa-brainpoolP256r1-key.pem -[24-ECDSA with brainpool-client] +[20-ECDSA with brainpool-client] CipherString = aECDSA Groups = brainpoolP256r1 MaxProtocol = TLSv1.2 @@ -863,7 +722,7 @@ RequestCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-24] +[test-20] ExpectedResult = Success ExpectedServerCANames = empty ExpectedServerCertType = brainpoolP256r1 @@ -872,14 +731,14 @@ ExpectedServerSignType = EC # =========================================================== -[25-Ed25519 CipherString and Curves Selection] -ssl_conf = 25-Ed25519 CipherString and Curves Selection-ssl +[21-Ed25519 CipherString and Curves Selection] +ssl_conf = 21-Ed25519 CipherString and Curves Selection-ssl -[25-Ed25519 CipherString and Curves Selection-ssl] -server = 25-Ed25519 CipherString and Curves Selection-server -client = 25-Ed25519 CipherString and Curves Selection-client +[21-Ed25519 CipherString and Curves Selection-ssl] +server = 21-Ed25519 CipherString and Curves Selection-server +client = 21-Ed25519 CipherString and Curves Selection-client -[25-Ed25519 CipherString and Curves Selection-server] +[21-Ed25519 CipherString and Curves Selection-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem @@ -891,15 +750,15 @@ Ed448.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed448-key.pem MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[25-Ed25519 CipherString and Curves Selection-client] +[21-Ed25519 CipherString and Curves Selection-client] CipherString = aECDSA Curves = X25519 MaxProtocol = TLSv1.2 -SignatureAlgorithms = eCDsA+SHA256:ed25519 +SignatureAlgorithms = ecDSA+SHA256:Ed25519 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-25] +[test-21] ExpectedResult = Success ExpectedServerCertType = Ed25519 ExpectedServerSignType = Ed25519 @@ -907,14 +766,14 @@ ExpectedServerSignType = Ed25519 # =========================================================== -[26-Ed448 CipherString and Curves Selection] -ssl_conf = 26-Ed448 CipherString and Curves Selection-ssl +[22-Ed448 CipherString and Curves Selection] +ssl_conf = 22-Ed448 CipherString and Curves Selection-ssl -[26-Ed448 CipherString and Curves Selection-ssl] -server = 26-Ed448 CipherString and Curves Selection-server -client = 26-Ed448 CipherString and Curves Selection-client +[22-Ed448 CipherString and Curves Selection-ssl] +server = 22-Ed448 CipherString and Curves Selection-server +client = 22-Ed448 CipherString and Curves Selection-client -[26-Ed448 CipherString and Curves Selection-server] +[22-Ed448 CipherString and Curves Selection-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem @@ -926,15 +785,15 @@ Ed448.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed448-key.pem MaxProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[26-Ed448 CipherString and Curves Selection-client] +[22-Ed448 CipherString and Curves Selection-client] CipherString = aECDSA Curves = X448 MaxProtocol = TLSv1.2 -SignatureAlgorithms = EcdSa+SHA256:Ed448 +SignatureAlgorithms = ECDSa+SHA256:ED448 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-ed448-cert.pem VerifyMode = Peer -[test-26] +[test-22] ExpectedResult = Success ExpectedServerCertType = Ed448 ExpectedServerSignType = Ed448 @@ -942,14 +801,14 @@ ExpectedServerSignType = Ed448 # =========================================================== -[27-RSA-PSS Certificate CipherString Selection] -ssl_conf = 27-RSA-PSS Certificate CipherString Selection-ssl +[23-RSA-PSS Certificate CipherString Selection] +ssl_conf = 23-RSA-PSS Certificate CipherString Selection-ssl -[27-RSA-PSS Certificate CipherString Selection-ssl] -server = 27-RSA-PSS Certificate CipherString Selection-server -client = 27-RSA-PSS Certificate CipherString Selection-client +[23-RSA-PSS Certificate CipherString Selection-ssl] +server = 23-RSA-PSS Certificate CipherString Selection-server +client = 23-RSA-PSS Certificate CipherString Selection-client -[27-RSA-PSS Certificate CipherString Selection-server] +[23-RSA-PSS Certificate CipherString Selection-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem @@ -963,13 +822,13 @@ PSS.Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-cert.pem PSS.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-key.pem PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[27-RSA-PSS Certificate CipherString Selection-client] +[23-RSA-PSS Certificate CipherString Selection-client] CipherString = aRSA MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-27] +[test-23] ExpectedResult = Success ExpectedServerCertType = RSA-PSS ExpectedServerSignType = RSA-PSS @@ -977,14 +836,14 @@ ExpectedServerSignType = RSA-PSS # =========================================================== -[28-RSA-PSS Certificate Legacy Signature Algorithm Selection] -ssl_conf = 28-RSA-PSS Certificate Legacy Signature Algorithm Selection-ssl +[24-RSA-PSS Certificate Legacy Signature Algorithm Selection] +ssl_conf = 24-RSA-PSS Certificate Legacy Signature Algorithm Selection-ssl -[28-RSA-PSS Certificate Legacy Signature Algorithm Selection-ssl] -server = 28-RSA-PSS Certificate Legacy Signature Algorithm Selection-server -client = 28-RSA-PSS Certificate Legacy Signature Algorithm Selection-client +[24-RSA-PSS Certificate Legacy Signature Algorithm Selection-ssl] +server = 24-RSA-PSS Certificate Legacy Signature Algorithm Selection-server +client = 24-RSA-PSS Certificate Legacy Signature Algorithm Selection-client -[28-RSA-PSS Certificate Legacy Signature Algorithm Selection-server] +[24-RSA-PSS Certificate Legacy Signature Algorithm Selection-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem @@ -998,13 +857,13 @@ PSS.Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-cert.pem PSS.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-key.pem PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[28-RSA-PSS Certificate Legacy Signature Algorithm Selection-client] +[24-RSA-PSS Certificate Legacy Signature Algorithm Selection-client] CipherString = DEFAULT -SignatureAlgorithms = rSa-PSS+SHA256 +SignatureAlgorithms = rSA-pSS+SHA256 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-28] +[test-24] ExpectedResult = Success ExpectedServerCertType = RSA ExpectedServerSignHash = SHA256 @@ -1013,14 +872,14 @@ ExpectedServerSignType = RSA-PSS # =========================================================== -[29-RSA-PSS Certificate Unified Signature Algorithm Selection] -ssl_conf = 29-RSA-PSS Certificate Unified Signature Algorithm Selection-ssl +[25-RSA-PSS Certificate Unified Signature Algorithm Selection] +ssl_conf = 25-RSA-PSS Certificate Unified Signature Algorithm Selection-ssl -[29-RSA-PSS Certificate Unified Signature Algorithm Selection-ssl] -server = 29-RSA-PSS Certificate Unified Signature Algorithm Selection-server -client = 29-RSA-PSS Certificate Unified Signature Algorithm Selection-client +[25-RSA-PSS Certificate Unified Signature Algorithm Selection-ssl] +server = 25-RSA-PSS Certificate Unified Signature Algorithm Selection-server +client = 25-RSA-PSS Certificate Unified Signature Algorithm Selection-client -[29-RSA-PSS Certificate Unified Signature Algorithm Selection-server] +[25-RSA-PSS Certificate Unified Signature Algorithm Selection-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem @@ -1034,9 +893,112 @@ PSS.Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-cert.pem PSS.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-key.pem PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[29-RSA-PSS Certificate Unified Signature Algorithm Selection-client] +[25-RSA-PSS Certificate Unified Signature Algorithm Selection-client] +CipherString = DEFAULT +SignatureAlgorithms = rsA_PsS_PsS_sHa256 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-25] +ExpectedResult = Success +ExpectedServerCertType = RSA-PSS +ExpectedServerSignHash = SHA256 +ExpectedServerSignType = RSA-PSS + + +# =========================================================== + +[26-Only RSA-PSS Certificate] +ssl_conf = 26-Only RSA-PSS Certificate-ssl + +[26-Only RSA-PSS Certificate-ssl] +server = 26-Only RSA-PSS Certificate-server +client = 26-Only RSA-PSS Certificate-client + +[26-Only RSA-PSS Certificate-server] +Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-cert.pem +CipherString = DEFAULT +PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-key.pem + +[26-Only RSA-PSS Certificate-client] +CipherString = DEFAULT +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-26] +ExpectedResult = Success +ExpectedServerCertType = RSA-PSS +ExpectedServerSignHash = SHA256 +ExpectedServerSignType = RSA-PSS + + +# =========================================================== + +[27-Only RSA-PSS Certificate Valid Signature Algorithms] +ssl_conf = 27-Only RSA-PSS Certificate Valid Signature Algorithms-ssl + +[27-Only RSA-PSS Certificate Valid Signature Algorithms-ssl] +server = 27-Only RSA-PSS Certificate Valid Signature Algorithms-server +client = 27-Only RSA-PSS Certificate Valid Signature Algorithms-client + +[27-Only RSA-PSS Certificate Valid Signature Algorithms-server] +Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-cert.pem +CipherString = DEFAULT +PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-key.pem + +[27-Only RSA-PSS Certificate Valid Signature Algorithms-client] +CipherString = DEFAULT +SignatureAlgorithms = rsa_psS_psS_sHa512 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-27] +ExpectedResult = Success +ExpectedServerCertType = RSA-PSS +ExpectedServerSignHash = SHA512 +ExpectedServerSignType = RSA-PSS + + +# =========================================================== + +[28-RSA-PSS Certificate, no PSS signature algorithms] +ssl_conf = 28-RSA-PSS Certificate, no PSS signature algorithms-ssl + +[28-RSA-PSS Certificate, no PSS signature algorithms-ssl] +server = 28-RSA-PSS Certificate, no PSS signature algorithms-server +client = 28-RSA-PSS Certificate, no PSS signature algorithms-client + +[28-RSA-PSS Certificate, no PSS signature algorithms-server] +Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-cert.pem +CipherString = DEFAULT +PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-key.pem + +[28-RSA-PSS Certificate, no PSS signature algorithms-client] +CipherString = DEFAULT +SignatureAlgorithms = rsa+SHA256 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-28] +ExpectedResult = ServerFail + + +# =========================================================== + +[29-Only RSA-PSS Restricted Certificate] +ssl_conf = 29-Only RSA-PSS Restricted Certificate-ssl + +[29-Only RSA-PSS Restricted Certificate-ssl] +server = 29-Only RSA-PSS Restricted Certificate-server +client = 29-Only RSA-PSS Restricted Certificate-client + +[29-Only RSA-PSS Restricted Certificate-server] +Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-cert.pem +CipherString = DEFAULT +PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-key.pem + +[29-Only RSA-PSS Restricted Certificate-client] CipherString = DEFAULT -SignatureAlgorithms = rsa_Pss_PsS_sHA256 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -1049,20 +1011,21 @@ ExpectedServerSignType = RSA-PSS # =========================================================== -[30-Only RSA-PSS Certificate] -ssl_conf = 30-Only RSA-PSS Certificate-ssl +[30-RSA-PSS Restricted Certificate Valid Signature Algorithms] +ssl_conf = 30-RSA-PSS Restricted Certificate Valid Signature Algorithms-ssl -[30-Only RSA-PSS Certificate-ssl] -server = 30-Only RSA-PSS Certificate-server -client = 30-Only RSA-PSS Certificate-client +[30-RSA-PSS Restricted Certificate Valid Signature Algorithms-ssl] +server = 30-RSA-PSS Restricted Certificate Valid Signature Algorithms-server +client = 30-RSA-PSS Restricted Certificate Valid Signature Algorithms-client -[30-Only RSA-PSS Certificate-server] -Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-cert.pem +[30-RSA-PSS Restricted Certificate Valid Signature Algorithms-server] +Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-cert.pem CipherString = DEFAULT -PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-key.pem +PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-key.pem -[30-Only RSA-PSS Certificate-client] +[30-RSA-PSS Restricted Certificate Valid Signature Algorithms-client] CipherString = DEFAULT +SignatureAlgorithms = RSa_pSS_pSs_sHA256:rsa_PsS_PSs_sHA512 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -1075,48 +1038,48 @@ ExpectedServerSignType = RSA-PSS # =========================================================== -[31-Only RSA-PSS Certificate Valid Signature Algorithms] -ssl_conf = 31-Only RSA-PSS Certificate Valid Signature Algorithms-ssl +[31-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm] +ssl_conf = 31-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm-ssl -[31-Only RSA-PSS Certificate Valid Signature Algorithms-ssl] -server = 31-Only RSA-PSS Certificate Valid Signature Algorithms-server -client = 31-Only RSA-PSS Certificate Valid Signature Algorithms-client +[31-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm-ssl] +server = 31-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm-server +client = 31-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm-client -[31-Only RSA-PSS Certificate Valid Signature Algorithms-server] -Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-cert.pem +[31-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm-server] +Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-cert.pem CipherString = DEFAULT -PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-key.pem +PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-key.pem -[31-Only RSA-PSS Certificate Valid Signature Algorithms-client] +[31-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm-client] CipherString = DEFAULT -SignatureAlgorithms = RSA_psS_PsS_shA512 +SignatureAlgorithms = rsA_pss_psS_sha512:rsA_pSS_PSs_ShA256 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-31] ExpectedResult = Success ExpectedServerCertType = RSA-PSS -ExpectedServerSignHash = SHA512 +ExpectedServerSignHash = SHA256 ExpectedServerSignType = RSA-PSS # =========================================================== -[32-RSA-PSS Certificate, no PSS signature algorithms] -ssl_conf = 32-RSA-PSS Certificate, no PSS signature algorithms-ssl +[32-RSA-PSS Restricted Certificate Invalid Signature Algorithms] +ssl_conf = 32-RSA-PSS Restricted Certificate Invalid Signature Algorithms-ssl -[32-RSA-PSS Certificate, no PSS signature algorithms-ssl] -server = 32-RSA-PSS Certificate, no PSS signature algorithms-server -client = 32-RSA-PSS Certificate, no PSS signature algorithms-client +[32-RSA-PSS Restricted Certificate Invalid Signature Algorithms-ssl] +server = 32-RSA-PSS Restricted Certificate Invalid Signature Algorithms-server +client = 32-RSA-PSS Restricted Certificate Invalid Signature Algorithms-client -[32-RSA-PSS Certificate, no PSS signature algorithms-server] -Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-cert.pem +[32-RSA-PSS Restricted Certificate Invalid Signature Algorithms-server] +Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-cert.pem CipherString = DEFAULT -PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-key.pem +PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-key.pem -[32-RSA-PSS Certificate, no PSS signature algorithms-client] +[32-RSA-PSS Restricted Certificate Invalid Signature Algorithms-client] CipherString = DEFAULT -SignatureAlgorithms = rSA+SHA256 +SignatureAlgorithms = rSa_PSS_pSS_sHa512 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -1126,125 +1089,145 @@ ExpectedResult = ServerFail # =========================================================== -[33-Only RSA-PSS Restricted Certificate] -ssl_conf = 33-Only RSA-PSS Restricted Certificate-ssl +[33-RSA key exchange with only RSA-PSS certificate] +ssl_conf = 33-RSA key exchange with only RSA-PSS certificate-ssl -[33-Only RSA-PSS Restricted Certificate-ssl] -server = 33-Only RSA-PSS Restricted Certificate-server -client = 33-Only RSA-PSS Restricted Certificate-client +[33-RSA key exchange with only RSA-PSS certificate-ssl] +server = 33-RSA key exchange with only RSA-PSS certificate-server +client = 33-RSA key exchange with only RSA-PSS certificate-client -[33-Only RSA-PSS Restricted Certificate-server] -Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-cert.pem +[33-RSA key exchange with only RSA-PSS certificate-server] +Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-cert.pem CipherString = DEFAULT -PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-key.pem +PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-key.pem -[33-Only RSA-PSS Restricted Certificate-client] -CipherString = DEFAULT +[33-RSA key exchange with only RSA-PSS certificate-client] +CipherString = kRSA +MaxProtocol = TLSv1.2 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-33] -ExpectedResult = Success -ExpectedServerCertType = RSA-PSS -ExpectedServerSignHash = SHA256 -ExpectedServerSignType = RSA-PSS - - -# =========================================================== - -[34-RSA-PSS Restricted Certificate Valid Signature Algorithms] -ssl_conf = 34-RSA-PSS Restricted Certificate Valid Signature Algorithms-ssl - -[34-RSA-PSS Restricted Certificate Valid Signature Algorithms-ssl] -server = 34-RSA-PSS Restricted Certificate Valid Signature Algorithms-server -client = 34-RSA-PSS Restricted Certificate Valid Signature Algorithms-client - -[34-RSA-PSS Restricted Certificate Valid Signature Algorithms-server] -Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-cert.pem -CipherString = DEFAULT -PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-key.pem - -[34-RSA-PSS Restricted Certificate Valid Signature Algorithms-client] -CipherString = DEFAULT -SignatureAlgorithms = rSa_PSS_psS_Sha256:Rsa_pss_Pss_sha512 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-34] -ExpectedResult = Success -ExpectedServerCertType = RSA-PSS -ExpectedServerSignHash = SHA256 -ExpectedServerSignType = RSA-PSS - - -# =========================================================== - -[35-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm] -ssl_conf = 35-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm-ssl - -[35-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm-ssl] -server = 35-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm-server -client = 35-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm-client - -[35-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm-server] -Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-cert.pem -CipherString = DEFAULT -PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-key.pem - -[35-RSA-PSS Restricted Cert client prefers invalid Signature Algorithm-client] -CipherString = DEFAULT -SignatureAlgorithms = RsA_PSS_pSs_ShA512:rSA_PsS_PsS_sha256 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-35] -ExpectedResult = Success -ExpectedServerCertType = RSA-PSS -ExpectedServerSignHash = SHA256 -ExpectedServerSignType = RSA-PSS - - -# =========================================================== - -[36-RSA-PSS Restricted Certificate Invalid Signature Algorithms] -ssl_conf = 36-RSA-PSS Restricted Certificate Invalid Signature Algorithms-ssl - -[36-RSA-PSS Restricted Certificate Invalid Signature Algorithms-ssl] -server = 36-RSA-PSS Restricted Certificate Invalid Signature Algorithms-server -client = 36-RSA-PSS Restricted Certificate Invalid Signature Algorithms-client - -[36-RSA-PSS Restricted Certificate Invalid Signature Algorithms-server] -Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-cert.pem -CipherString = DEFAULT -PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-restrict-key.pem - -[36-RSA-PSS Restricted Certificate Invalid Signature Algorithms-client] -CipherString = DEFAULT -SignatureAlgorithms = rSA_PSs_psS_sha512 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-36] ExpectedResult = ServerFail # =========================================================== -[37-RSA key exchange with only RSA-PSS certificate] -ssl_conf = 37-RSA key exchange with only RSA-PSS certificate-ssl +[34-Only RSA-PSS Certificate, TLS v1.1] +ssl_conf = 34-Only RSA-PSS Certificate, TLS v1.1-ssl -[37-RSA key exchange with only RSA-PSS certificate-ssl] -server = 37-RSA key exchange with only RSA-PSS certificate-server -client = 37-RSA key exchange with only RSA-PSS certificate-client +[34-Only RSA-PSS Certificate, TLS v1.1-ssl] +server = 34-Only RSA-PSS Certificate, TLS v1.1-server +client = 34-Only RSA-PSS Certificate, TLS v1.1-client -[37-RSA key exchange with only RSA-PSS certificate-server] +[34-Only RSA-PSS Certificate, TLS v1.1-server] Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-cert.pem -CipherString = DEFAULT +CipherString = DEFAULT:@SECLEVEL=0 PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-key.pem -[37-RSA key exchange with only RSA-PSS certificate-client] -CipherString = kRSA -MaxProtocol = TLSv1.2 +[34-Only RSA-PSS Certificate, TLS v1.1-client] +CipherString = DEFAULT:@SECLEVEL=0 +MaxProtocol = TLSv1.1 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-34] +ExpectedResult = ServerFail + + +# =========================================================== + +[35-TLS 1.3 ECDSA Signature Algorithm Selection] +ssl_conf = 35-TLS 1.3 ECDSA Signature Algorithm Selection-ssl + +[35-TLS 1.3 ECDSA Signature Algorithm Selection-ssl] +server = 35-TLS 1.3 ECDSA Signature Algorithm Selection-server +client = 35-TLS 1.3 ECDSA Signature Algorithm Selection-client + +[35-TLS 1.3 ECDSA Signature Algorithm Selection-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT +ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem +ECDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ecdsa-key.pem +Ed25519.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed25519-cert.pem +Ed25519.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed25519-key.pem +Ed448.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed448-cert.pem +Ed448.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed448-key.pem +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[35-TLS 1.3 ECDSA Signature Algorithm Selection-client] +CipherString = DEFAULT +SignatureAlgorithms = ECDsa+SHA256 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-35] +ExpectedResult = Success +ExpectedServerCANames = empty +ExpectedServerCertType = P-256 +ExpectedServerSignHash = SHA256 +ExpectedServerSignType = EC + + +# =========================================================== + +[36-TLS 1.3 ECDSA Signature Algorithm Selection compressed point] +ssl_conf = 36-TLS 1.3 ECDSA Signature Algorithm Selection compressed point-ssl + +[36-TLS 1.3 ECDSA Signature Algorithm Selection compressed point-ssl] +server = 36-TLS 1.3 ECDSA Signature Algorithm Selection compressed point-server +client = 36-TLS 1.3 ECDSA Signature Algorithm Selection compressed point-client + +[36-TLS 1.3 ECDSA Signature Algorithm Selection compressed point-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT +ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-cecdsa-cert.pem +ECDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-cecdsa-key.pem +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[36-TLS 1.3 ECDSA Signature Algorithm Selection compressed point-client] +CipherString = DEFAULT +SignatureAlgorithms = ecDSA+SHA256 +VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem +VerifyMode = Peer + +[test-36] +ExpectedResult = Success +ExpectedServerCANames = empty +ExpectedServerCertType = P-256 +ExpectedServerSignHash = SHA256 +ExpectedServerSignType = EC + + +# =========================================================== + +[37-TLS 1.3 ECDSA Signature Algorithm Selection SHA1] +ssl_conf = 37-TLS 1.3 ECDSA Signature Algorithm Selection SHA1-ssl + +[37-TLS 1.3 ECDSA Signature Algorithm Selection SHA1-ssl] +server = 37-TLS 1.3 ECDSA Signature Algorithm Selection SHA1-server +client = 37-TLS 1.3 ECDSA Signature Algorithm Selection SHA1-client + +[37-TLS 1.3 ECDSA Signature Algorithm Selection SHA1-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT:@SECLEVEL=0 +ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem +ECDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ecdsa-key.pem +Ed25519.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed25519-cert.pem +Ed25519.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed25519-key.pem +Ed448.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed448-cert.pem +Ed448.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed448-key.pem +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem + +[37-TLS 1.3 ECDSA Signature Algorithm Selection SHA1-client] +CipherString = DEFAULT:@SECLEVEL=0 +SignatureAlgorithms = eCDSa+SHA1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer @@ -1254,158 +1237,34 @@ ExpectedResult = ServerFail # =========================================================== -[38-Only RSA-PSS Certificate, TLS v1.1] -ssl_conf = 38-Only RSA-PSS Certificate, TLS v1.1-ssl +[38-TLS 1.3 ECDSA Signature Algorithm Selection with PSS] +ssl_conf = 38-TLS 1.3 ECDSA Signature Algorithm Selection with PSS-ssl -[38-Only RSA-PSS Certificate, TLS v1.1-ssl] -server = 38-Only RSA-PSS Certificate, TLS v1.1-server -client = 38-Only RSA-PSS Certificate, TLS v1.1-client +[38-TLS 1.3 ECDSA Signature Algorithm Selection with PSS-ssl] +server = 38-TLS 1.3 ECDSA Signature Algorithm Selection with PSS-server +client = 38-TLS 1.3 ECDSA Signature Algorithm Selection with PSS-client -[38-Only RSA-PSS Certificate, TLS v1.1-server] -Certificate = ${ENV::TEST_CERTS_DIR}/server-pss-cert.pem -CipherString = DEFAULT:@SECLEVEL=0 -PrivateKey = ${ENV::TEST_CERTS_DIR}/server-pss-key.pem +[38-TLS 1.3 ECDSA Signature Algorithm Selection with PSS-server] +Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem +CipherString = DEFAULT +ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem +ECDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ecdsa-key.pem +Ed25519.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed25519-cert.pem +Ed25519.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed25519-key.pem +Ed448.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed448-cert.pem +Ed448.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed448-key.pem +MaxProtocol = TLSv1.3 +MinProtocol = TLSv1.3 +PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[38-Only RSA-PSS Certificate, TLS v1.1-client] -CipherString = DEFAULT:@SECLEVEL=0 -MaxProtocol = TLSv1.1 +[38-TLS 1.3 ECDSA Signature Algorithm Selection with PSS-client] +CipherString = DEFAULT +RequestCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem +SignatureAlgorithms = eCdsA+SHA256:rsA-pSs+SHA256 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer [test-38] -ExpectedResult = ServerFail - - -# =========================================================== - -[39-TLS 1.3 ECDSA Signature Algorithm Selection] -ssl_conf = 39-TLS 1.3 ECDSA Signature Algorithm Selection-ssl - -[39-TLS 1.3 ECDSA Signature Algorithm Selection-ssl] -server = 39-TLS 1.3 ECDSA Signature Algorithm Selection-server -client = 39-TLS 1.3 ECDSA Signature Algorithm Selection-client - -[39-TLS 1.3 ECDSA Signature Algorithm Selection-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT -ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem -ECDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ecdsa-key.pem -Ed25519.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed25519-cert.pem -Ed25519.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed25519-key.pem -Ed448.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed448-cert.pem -Ed448.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed448-key.pem -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[39-TLS 1.3 ECDSA Signature Algorithm Selection-client] -CipherString = DEFAULT -SignatureAlgorithms = ecDsa+SHA256 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-39] -ExpectedResult = Success -ExpectedServerCANames = empty -ExpectedServerCertType = P-256 -ExpectedServerSignHash = SHA256 -ExpectedServerSignType = EC - - -# =========================================================== - -[40-TLS 1.3 ECDSA Signature Algorithm Selection compressed point] -ssl_conf = 40-TLS 1.3 ECDSA Signature Algorithm Selection compressed point-ssl - -[40-TLS 1.3 ECDSA Signature Algorithm Selection compressed point-ssl] -server = 40-TLS 1.3 ECDSA Signature Algorithm Selection compressed point-server -client = 40-TLS 1.3 ECDSA Signature Algorithm Selection compressed point-client - -[40-TLS 1.3 ECDSA Signature Algorithm Selection compressed point-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT -ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-cecdsa-cert.pem -ECDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-cecdsa-key.pem -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[40-TLS 1.3 ECDSA Signature Algorithm Selection compressed point-client] -CipherString = DEFAULT -SignatureAlgorithms = EcdSa+SHA256 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-40] -ExpectedResult = Success -ExpectedServerCANames = empty -ExpectedServerCertType = P-256 -ExpectedServerSignHash = SHA256 -ExpectedServerSignType = EC - - -# =========================================================== - -[41-TLS 1.3 ECDSA Signature Algorithm Selection SHA1] -ssl_conf = 41-TLS 1.3 ECDSA Signature Algorithm Selection SHA1-ssl - -[41-TLS 1.3 ECDSA Signature Algorithm Selection SHA1-ssl] -server = 41-TLS 1.3 ECDSA Signature Algorithm Selection SHA1-server -client = 41-TLS 1.3 ECDSA Signature Algorithm Selection SHA1-client - -[41-TLS 1.3 ECDSA Signature Algorithm Selection SHA1-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT:@SECLEVEL=0 -ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem -ECDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ecdsa-key.pem -Ed25519.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed25519-cert.pem -Ed25519.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed25519-key.pem -Ed448.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed448-cert.pem -Ed448.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed448-key.pem -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[41-TLS 1.3 ECDSA Signature Algorithm Selection SHA1-client] -CipherString = DEFAULT:@SECLEVEL=0 -SignatureAlgorithms = EcDSa+SHA1 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-41] -ExpectedResult = ServerFail - - -# =========================================================== - -[42-TLS 1.3 ECDSA Signature Algorithm Selection with PSS] -ssl_conf = 42-TLS 1.3 ECDSA Signature Algorithm Selection with PSS-ssl - -[42-TLS 1.3 ECDSA Signature Algorithm Selection with PSS-ssl] -server = 42-TLS 1.3 ECDSA Signature Algorithm Selection with PSS-server -client = 42-TLS 1.3 ECDSA Signature Algorithm Selection with PSS-client - -[42-TLS 1.3 ECDSA Signature Algorithm Selection with PSS-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT -ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem -ECDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ecdsa-key.pem -Ed25519.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed25519-cert.pem -Ed25519.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed25519-key.pem -Ed448.Certificate = ${ENV::TEST_CERTS_DIR}/server-ed448-cert.pem -Ed448.PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ed448-key.pem -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[42-TLS 1.3 ECDSA Signature Algorithm Selection with PSS-client] -CipherString = DEFAULT -RequestCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem -SignatureAlgorithms = eCDSa+SHA256:rsA-pSS+SHA256 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-42] ExpectedResult = Success ExpectedServerCANames = ${ENV::TEST_CERTS_DIR}/root-cert.pem ExpectedServerCertType = P-256 @@ -1415,14 +1274,14 @@ ExpectedServerSignType = EC # =========================================================== -[43-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS] -ssl_conf = 43-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS-ssl +[39-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS] +ssl_conf = 39-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS-ssl -[43-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS-ssl] -server = 43-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS-server -client = 43-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS-client +[39-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS-ssl] +server = 39-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS-server +client = 39-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS-client -[43-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS-server] +[39-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem @@ -1435,13 +1294,13 @@ MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[43-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS-client] +[39-TLS 1.3 RSA Signature Algorithm Selection SHA384 with PSS-client] CipherString = DEFAULT -SignatureAlgorithms = ECDSA+SHA384:Rsa-PSS+SHA384 +SignatureAlgorithms = ECdsA+SHA384:RSa-psS+SHA384 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-43] +[test-39] ExpectedResult = Success ExpectedServerCertType = RSA ExpectedServerSignHash = SHA384 @@ -1450,40 +1309,40 @@ ExpectedServerSignType = RSA-PSS # =========================================================== -[44-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate] -ssl_conf = 44-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate-ssl +[40-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate] +ssl_conf = 40-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate-ssl -[44-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate-ssl] -server = 44-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate-server -client = 44-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate-client +[40-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate-ssl] +server = 40-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate-server +client = 40-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate-client -[44-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate-server] +[40-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[44-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate-client] +[40-TLS 1.3 ECDSA Signature Algorithm Selection, no ECDSA certificate-client] CipherString = DEFAULT -SignatureAlgorithms = ECDSa+SHA256 +SignatureAlgorithms = eCDSA+SHA256 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-44] +[test-40] ExpectedResult = ServerFail # =========================================================== -[45-TLS 1.3 RSA Signature Algorithm Selection, no PSS] -ssl_conf = 45-TLS 1.3 RSA Signature Algorithm Selection, no PSS-ssl +[41-TLS 1.3 RSA Signature Algorithm Selection, no PSS] +ssl_conf = 41-TLS 1.3 RSA Signature Algorithm Selection, no PSS-ssl -[45-TLS 1.3 RSA Signature Algorithm Selection, no PSS-ssl] -server = 45-TLS 1.3 RSA Signature Algorithm Selection, no PSS-server -client = 45-TLS 1.3 RSA Signature Algorithm Selection, no PSS-client +[41-TLS 1.3 RSA Signature Algorithm Selection, no PSS-ssl] +server = 41-TLS 1.3 RSA Signature Algorithm Selection, no PSS-server +client = 41-TLS 1.3 RSA Signature Algorithm Selection, no PSS-client -[45-TLS 1.3 RSA Signature Algorithm Selection, no PSS-server] +[41-TLS 1.3 RSA Signature Algorithm Selection, no PSS-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem @@ -1496,26 +1355,26 @@ MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[45-TLS 1.3 RSA Signature Algorithm Selection, no PSS-client] +[41-TLS 1.3 RSA Signature Algorithm Selection, no PSS-client] CipherString = DEFAULT -SignatureAlgorithms = rSA+SHA256 +SignatureAlgorithms = RSA+SHA256 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-45] +[test-41] ExpectedResult = ServerFail # =========================================================== -[46-TLS 1.3 RSA-PSS Signature Algorithm Selection] -ssl_conf = 46-TLS 1.3 RSA-PSS Signature Algorithm Selection-ssl +[42-TLS 1.3 RSA-PSS Signature Algorithm Selection] +ssl_conf = 42-TLS 1.3 RSA-PSS Signature Algorithm Selection-ssl -[46-TLS 1.3 RSA-PSS Signature Algorithm Selection-ssl] -server = 46-TLS 1.3 RSA-PSS Signature Algorithm Selection-server -client = 46-TLS 1.3 RSA-PSS Signature Algorithm Selection-client +[42-TLS 1.3 RSA-PSS Signature Algorithm Selection-ssl] +server = 42-TLS 1.3 RSA-PSS Signature Algorithm Selection-server +client = 42-TLS 1.3 RSA-PSS Signature Algorithm Selection-client -[46-TLS 1.3 RSA-PSS Signature Algorithm Selection-server] +[42-TLS 1.3 RSA-PSS Signature Algorithm Selection-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem @@ -1528,13 +1387,13 @@ MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[46-TLS 1.3 RSA-PSS Signature Algorithm Selection-client] +[42-TLS 1.3 RSA-PSS Signature Algorithm Selection-client] CipherString = DEFAULT -SignatureAlgorithms = RsA-PsS+SHA256 +SignatureAlgorithms = Rsa-PSS+SHA256 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-46] +[test-42] ExpectedResult = Success ExpectedServerCertType = RSA ExpectedServerSignHash = SHA256 @@ -1543,22 +1402,22 @@ ExpectedServerSignType = RSA-PSS # =========================================================== -[47-TLS 1.3 RSA Client Auth Signature Algorithm Selection] -ssl_conf = 47-TLS 1.3 RSA Client Auth Signature Algorithm Selection-ssl +[43-TLS 1.3 RSA Client Auth Signature Algorithm Selection] +ssl_conf = 43-TLS 1.3 RSA Client Auth Signature Algorithm Selection-ssl -[47-TLS 1.3 RSA Client Auth Signature Algorithm Selection-ssl] -server = 47-TLS 1.3 RSA Client Auth Signature Algorithm Selection-server -client = 47-TLS 1.3 RSA Client Auth Signature Algorithm Selection-client +[43-TLS 1.3 RSA Client Auth Signature Algorithm Selection-ssl] +server = 43-TLS 1.3 RSA Client Auth Signature Algorithm Selection-server +client = 43-TLS 1.3 RSA Client Auth Signature Algorithm Selection-client -[47-TLS 1.3 RSA Client Auth Signature Algorithm Selection-server] +[43-TLS 1.3 RSA Client Auth Signature Algorithm Selection-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT -ClientSignatureAlgorithms = pSs+SHA256 +ClientSignatureAlgorithms = PSS+SHA256 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem VerifyMode = Require -[47-TLS 1.3 RSA Client Auth Signature Algorithm Selection-client] +[43-TLS 1.3 RSA Client Auth Signature Algorithm Selection-client] CipherString = DEFAULT ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/ee-ecdsa-client-chain.pem ECDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/ee-ecdsa-key.pem @@ -1569,7 +1428,7 @@ RSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/ee-key.pem VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-47] +[test-43] ExpectedClientCANames = empty ExpectedClientCertType = RSA ExpectedClientSignHash = SHA256 @@ -1579,23 +1438,23 @@ ExpectedResult = Success # =========================================================== -[48-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names] -ssl_conf = 48-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names-ssl +[44-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names] +ssl_conf = 44-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names-ssl -[48-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names-ssl] -server = 48-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names-server -client = 48-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names-client +[44-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names-ssl] +server = 44-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names-server +client = 44-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names-client -[48-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names-server] +[44-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT -ClientSignatureAlgorithms = pSS+SHA256 +ClientSignatureAlgorithms = Pss+SHA256 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem RequestCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem VerifyMode = Require -[48-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names-client] +[44-TLS 1.3 RSA Client Auth Signature Algorithm Selection non-empty CA Names-client] CipherString = DEFAULT ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/ee-ecdsa-client-chain.pem ECDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/ee-ecdsa-key.pem @@ -1606,7 +1465,7 @@ RSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/ee-key.pem VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-48] +[test-44] ExpectedClientCANames = ${ENV::TEST_CERTS_DIR}/root-cert.pem ExpectedClientCertType = RSA ExpectedClientSignHash = SHA256 @@ -1616,22 +1475,22 @@ ExpectedResult = Success # =========================================================== -[49-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection] -ssl_conf = 49-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection-ssl +[45-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection] +ssl_conf = 45-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection-ssl -[49-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection-ssl] -server = 49-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection-server -client = 49-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection-client +[45-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection-ssl] +server = 45-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection-server +client = 45-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection-client -[49-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection-server] +[45-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT -ClientSignatureAlgorithms = EcdSA+SHA256 +ClientSignatureAlgorithms = ECDsA+SHA256 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem VerifyMode = Require -[49-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection-client] +[45-TLS 1.3 ECDSA Client Auth Signature Algorithm Selection-client] CipherString = DEFAULT ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/ee-ecdsa-client-chain.pem ECDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/ee-ecdsa-key.pem @@ -1642,7 +1501,7 @@ RSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/ee-key.pem VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-49] +[test-45] ExpectedClientCertType = P-256 ExpectedClientSignHash = SHA256 ExpectedClientSignType = EC @@ -1651,14 +1510,14 @@ ExpectedResult = Success # =========================================================== -[50-TLS 1.3 Ed25519 Signature Algorithm Selection] -ssl_conf = 50-TLS 1.3 Ed25519 Signature Algorithm Selection-ssl +[46-TLS 1.3 Ed25519 Signature Algorithm Selection] +ssl_conf = 46-TLS 1.3 Ed25519 Signature Algorithm Selection-ssl -[50-TLS 1.3 Ed25519 Signature Algorithm Selection-ssl] -server = 50-TLS 1.3 Ed25519 Signature Algorithm Selection-server -client = 50-TLS 1.3 Ed25519 Signature Algorithm Selection-client +[46-TLS 1.3 Ed25519 Signature Algorithm Selection-ssl] +server = 46-TLS 1.3 Ed25519 Signature Algorithm Selection-server +client = 46-TLS 1.3 Ed25519 Signature Algorithm Selection-client -[50-TLS 1.3 Ed25519 Signature Algorithm Selection-server] +[46-TLS 1.3 Ed25519 Signature Algorithm Selection-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem @@ -1671,13 +1530,13 @@ MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[50-TLS 1.3 Ed25519 Signature Algorithm Selection-client] +[46-TLS 1.3 Ed25519 Signature Algorithm Selection-client] CipherString = DEFAULT SignatureAlgorithms = eD25519 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-50] +[test-46] ExpectedResult = Success ExpectedServerCertType = Ed25519 ExpectedServerSignType = Ed25519 @@ -1685,14 +1544,14 @@ ExpectedServerSignType = Ed25519 # =========================================================== -[51-TLS 1.3 Ed448 Signature Algorithm Selection] -ssl_conf = 51-TLS 1.3 Ed448 Signature Algorithm Selection-ssl +[47-TLS 1.3 Ed448 Signature Algorithm Selection] +ssl_conf = 47-TLS 1.3 Ed448 Signature Algorithm Selection-ssl -[51-TLS 1.3 Ed448 Signature Algorithm Selection-ssl] -server = 51-TLS 1.3 Ed448 Signature Algorithm Selection-server -client = 51-TLS 1.3 Ed448 Signature Algorithm Selection-client +[47-TLS 1.3 Ed448 Signature Algorithm Selection-ssl] +server = 47-TLS 1.3 Ed448 Signature Algorithm Selection-server +client = 47-TLS 1.3 Ed448 Signature Algorithm Selection-client -[51-TLS 1.3 Ed448 Signature Algorithm Selection-server] +[47-TLS 1.3 Ed448 Signature Algorithm Selection-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem @@ -1705,13 +1564,13 @@ MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[51-TLS 1.3 Ed448 Signature Algorithm Selection-client] +[47-TLS 1.3 Ed448 Signature Algorithm Selection-client] CipherString = DEFAULT -SignatureAlgorithms = ED448 +SignatureAlgorithms = eD448 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-ed448-cert.pem VerifyMode = Peer -[test-51] +[test-47] ExpectedResult = Success ExpectedServerCertType = Ed448 ExpectedServerSignType = Ed448 @@ -1719,14 +1578,14 @@ ExpectedServerSignType = Ed448 # =========================================================== -[52-TLS 1.3 Ed25519 CipherString and Groups Selection] -ssl_conf = 52-TLS 1.3 Ed25519 CipherString and Groups Selection-ssl +[48-TLS 1.3 Ed25519 CipherString and Groups Selection] +ssl_conf = 48-TLS 1.3 Ed25519 CipherString and Groups Selection-ssl -[52-TLS 1.3 Ed25519 CipherString and Groups Selection-ssl] -server = 52-TLS 1.3 Ed25519 CipherString and Groups Selection-server -client = 52-TLS 1.3 Ed25519 CipherString and Groups Selection-client +[48-TLS 1.3 Ed25519 CipherString and Groups Selection-ssl] +server = 48-TLS 1.3 Ed25519 CipherString and Groups Selection-server +client = 48-TLS 1.3 Ed25519 CipherString and Groups Selection-client -[52-TLS 1.3 Ed25519 CipherString and Groups Selection-server] +[48-TLS 1.3 Ed25519 CipherString and Groups Selection-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem @@ -1739,14 +1598,14 @@ MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[52-TLS 1.3 Ed25519 CipherString and Groups Selection-client] +[48-TLS 1.3 Ed25519 CipherString and Groups Selection-client] CipherString = DEFAULT Groups = X25519 -SignatureAlgorithms = ECDSA+SHA256:ED25519 +SignatureAlgorithms = EcdSA+SHA256:eD25519 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-52] +[test-48] ExpectedResult = Success ExpectedServerCertType = P-256 ExpectedServerSignType = EC @@ -1754,14 +1613,14 @@ ExpectedServerSignType = EC # =========================================================== -[53-TLS 1.3 Ed448 CipherString and Groups Selection] -ssl_conf = 53-TLS 1.3 Ed448 CipherString and Groups Selection-ssl +[49-TLS 1.3 Ed448 CipherString and Groups Selection] +ssl_conf = 49-TLS 1.3 Ed448 CipherString and Groups Selection-ssl -[53-TLS 1.3 Ed448 CipherString and Groups Selection-ssl] -server = 53-TLS 1.3 Ed448 CipherString and Groups Selection-server -client = 53-TLS 1.3 Ed448 CipherString and Groups Selection-client +[49-TLS 1.3 Ed448 CipherString and Groups Selection-ssl] +server = 49-TLS 1.3 Ed448 CipherString and Groups Selection-server +client = 49-TLS 1.3 Ed448 CipherString and Groups Selection-client -[53-TLS 1.3 Ed448 CipherString and Groups Selection-server] +[49-TLS 1.3 Ed448 CipherString and Groups Selection-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT ECDSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-cert.pem @@ -1774,14 +1633,14 @@ MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[53-TLS 1.3 Ed448 CipherString and Groups Selection-client] +[49-TLS 1.3 Ed448 CipherString and Groups Selection-client] CipherString = DEFAULT Groups = X448 -SignatureAlgorithms = eCDSA+SHA256:Ed448 +SignatureAlgorithms = eCDSa+SHA256:ED448 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-53] +[test-49] ExpectedResult = Success ExpectedServerCertType = P-256 ExpectedServerSignType = EC @@ -1789,21 +1648,21 @@ ExpectedServerSignType = EC # =========================================================== -[54-TLS 1.3 Ed25519 Client Auth] -ssl_conf = 54-TLS 1.3 Ed25519 Client Auth-ssl +[50-TLS 1.3 Ed25519 Client Auth] +ssl_conf = 50-TLS 1.3 Ed25519 Client Auth-ssl -[54-TLS 1.3 Ed25519 Client Auth-ssl] -server = 54-TLS 1.3 Ed25519 Client Auth-server -client = 54-TLS 1.3 Ed25519 Client Auth-client +[50-TLS 1.3 Ed25519 Client Auth-ssl] +server = 50-TLS 1.3 Ed25519 Client Auth-server +client = 50-TLS 1.3 Ed25519 Client Auth-client -[54-TLS 1.3 Ed25519 Client Auth-server] +[50-TLS 1.3 Ed25519 Client Auth-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem VerifyMode = Require -[54-TLS 1.3 Ed25519 Client Auth-client] +[50-TLS 1.3 Ed25519 Client Auth-client] CipherString = DEFAULT EdDSA.Certificate = ${ENV::TEST_CERTS_DIR}/client-ed25519-cert.pem EdDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/client-ed25519-key.pem @@ -1812,7 +1671,7 @@ MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-54] +[test-50] ExpectedClientCertType = Ed25519 ExpectedClientSignType = Ed25519 ExpectedResult = Success @@ -1820,21 +1679,21 @@ ExpectedResult = Success # =========================================================== -[55-TLS 1.3 Ed448 Client Auth] -ssl_conf = 55-TLS 1.3 Ed448 Client Auth-ssl +[51-TLS 1.3 Ed448 Client Auth] +ssl_conf = 51-TLS 1.3 Ed448 Client Auth-ssl -[55-TLS 1.3 Ed448 Client Auth-ssl] -server = 55-TLS 1.3 Ed448 Client Auth-server -client = 55-TLS 1.3 Ed448 Client Auth-client +[51-TLS 1.3 Ed448 Client Auth-ssl] +server = 51-TLS 1.3 Ed448 Client Auth-server +client = 51-TLS 1.3 Ed448 Client Auth-client -[55-TLS 1.3 Ed448 Client Auth-server] +[51-TLS 1.3 Ed448 Client Auth-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem VerifyMode = Require -[55-TLS 1.3 Ed448 Client Auth-client] +[51-TLS 1.3 Ed448 Client Auth-client] CipherString = DEFAULT EdDSA.Certificate = ${ENV::TEST_CERTS_DIR}/client-ed448-cert.pem EdDSA.PrivateKey = ${ENV::TEST_CERTS_DIR}/client-ed448-key.pem @@ -1843,7 +1702,7 @@ MinProtocol = TLSv1.3 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-55] +[test-51] ExpectedClientCertType = Ed448 ExpectedClientSignType = Ed448 ExpectedResult = Success @@ -1851,45 +1710,45 @@ ExpectedResult = Success # =========================================================== -[56-TLS 1.3 ECDSA with brainpool but no suitable groups] -ssl_conf = 56-TLS 1.3 ECDSA with brainpool but no suitable groups-ssl +[52-TLS 1.3 ECDSA with brainpool but no suitable groups] +ssl_conf = 52-TLS 1.3 ECDSA with brainpool but no suitable groups-ssl -[56-TLS 1.3 ECDSA with brainpool but no suitable groups-ssl] -server = 56-TLS 1.3 ECDSA with brainpool but no suitable groups-server -client = 56-TLS 1.3 ECDSA with brainpool but no suitable groups-client +[52-TLS 1.3 ECDSA with brainpool but no suitable groups-ssl] +server = 52-TLS 1.3 ECDSA with brainpool but no suitable groups-server +client = 52-TLS 1.3 ECDSA with brainpool but no suitable groups-client -[56-TLS 1.3 ECDSA with brainpool but no suitable groups-server] +[52-TLS 1.3 ECDSA with brainpool but no suitable groups-server] Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-brainpoolP256r1-cert.pem CipherString = DEFAULT Groups = brainpoolP256r1 PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ecdsa-brainpoolP256r1-key.pem -[56-TLS 1.3 ECDSA with brainpool but no suitable groups-client] +[52-TLS 1.3 ECDSA with brainpool but no suitable groups-client] CipherString = aECDSA Groups = brainpoolP256r1 RequestCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-56] +[test-52] ExpectedResult = ClientFail # =========================================================== -[57-TLS 1.3 ECDSA with brainpool] -ssl_conf = 57-TLS 1.3 ECDSA with brainpool-ssl +[53-TLS 1.3 ECDSA with brainpool] +ssl_conf = 53-TLS 1.3 ECDSA with brainpool-ssl -[57-TLS 1.3 ECDSA with brainpool-ssl] -server = 57-TLS 1.3 ECDSA with brainpool-server -client = 57-TLS 1.3 ECDSA with brainpool-client +[53-TLS 1.3 ECDSA with brainpool-ssl] +server = 53-TLS 1.3 ECDSA with brainpool-server +client = 53-TLS 1.3 ECDSA with brainpool-client -[57-TLS 1.3 ECDSA with brainpool-server] +[53-TLS 1.3 ECDSA with brainpool-server] Certificate = ${ENV::TEST_CERTS_DIR}/server-ecdsa-brainpoolP256r1-cert.pem CipherString = DEFAULT PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ecdsa-brainpoolP256r1-key.pem -[57-TLS 1.3 ECDSA with brainpool-client] +[53-TLS 1.3 ECDSA with brainpool-client] CipherString = DEFAULT MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 @@ -1897,45 +1756,20 @@ RequestCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-57] +[test-53] ExpectedResult = Success # =========================================================== -[58-TLS 1.3 SM2] -ssl_conf = 58-TLS 1.3 SM2-ssl +[54-TLS 1.2 DSA Certificate Test] +ssl_conf = 54-TLS 1.2 DSA Certificate Test-ssl -[58-TLS 1.3 SM2-ssl] -server = 58-TLS 1.3 SM2-server -client = 58-TLS 1.3 SM2-client +[54-TLS 1.2 DSA Certificate Test-ssl] +server = 54-TLS 1.2 DSA Certificate Test-server +client = 54-TLS 1.2 DSA Certificate Test-client -[58-TLS 1.3 SM2-server] -Certificate = ${ENV::TEST_CERTS_DIR}/sm2.pem -CipherString = DEFAULT -PrivateKey = ${ENV::TEST_CERTS_DIR}/sm2.key - -[58-TLS 1.3 SM2-client] -CipherString = DEFAULT -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/sm2-root.crt -VerifyMode = Peer - -[test-58] -ExpectedResult = Success - - -# =========================================================== - -[59-TLS 1.2 DSA Certificate Test] -ssl_conf = 59-TLS 1.2 DSA Certificate Test-ssl - -[59-TLS 1.2 DSA Certificate Test-ssl] -server = 59-TLS 1.2 DSA Certificate Test-server -client = 59-TLS 1.2 DSA Certificate Test-client - -[59-TLS 1.2 DSA Certificate Test-server] +[54-TLS 1.2 DSA Certificate Test-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = ALL DHParameters = ${ENV::TEST_CERTS_DIR}/dhp2048.pem @@ -1945,52 +1779,52 @@ MaxProtocol = TLSv1.2 MinProtocol = TLSv1.2 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[59-TLS 1.2 DSA Certificate Test-client] +[54-TLS 1.2 DSA Certificate Test-client] CipherString = ALL -SignatureAlgorithms = dsA+SHA256:dSA+SHA1 +SignatureAlgorithms = DSA+SHA256:DSa+SHA1 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-59] +[test-54] ExpectedResult = Success # =========================================================== -[60-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms] -ssl_conf = 60-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms-ssl +[55-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms] +ssl_conf = 55-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms-ssl -[60-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms-ssl] -server = 60-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms-server -client = 60-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms-client +[55-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms-ssl] +server = 55-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms-server +client = 55-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms-client -[60-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms-server] +[55-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = DEFAULT -ClientSignatureAlgorithms = ECDsa+SHA1:Dsa+SHA256:RSa+SHA256 +ClientSignatureAlgorithms = ecDSA+SHA1:DsA+SHA256:rsA+SHA256 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-cert.pem VerifyMode = Request -[60-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms-client] +[55-TLS 1.3 Client Auth No TLS 1.3 Signature Algorithms-client] CipherString = DEFAULT VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-60] +[test-55] ExpectedResult = ServerFail # =========================================================== -[61-TLS 1.3 DSA Certificate Test] -ssl_conf = 61-TLS 1.3 DSA Certificate Test-ssl +[56-TLS 1.3 DSA Certificate Test] +ssl_conf = 56-TLS 1.3 DSA Certificate Test-ssl -[61-TLS 1.3 DSA Certificate Test-ssl] -server = 61-TLS 1.3 DSA Certificate Test-server -client = 61-TLS 1.3 DSA Certificate Test-client +[56-TLS 1.3 DSA Certificate Test-ssl] +server = 56-TLS 1.3 DSA Certificate Test-server +client = 56-TLS 1.3 DSA Certificate Test-client -[61-TLS 1.3 DSA Certificate Test-server] +[56-TLS 1.3 DSA Certificate Test-server] Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem CipherString = ALL DSA.Certificate = ${ENV::TEST_CERTS_DIR}/server-dsa-cert.pem @@ -1999,42 +1833,42 @@ MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem -[61-TLS 1.3 DSA Certificate Test-client] +[56-TLS 1.3 DSA Certificate Test-client] CipherString = ALL -SignatureAlgorithms = DsA+SHA1:Dsa+SHA256:ECdsa+SHA256 +SignatureAlgorithms = dSA+SHA1:DSA+SHA256:ecDsa+SHA256 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem VerifyMode = Peer -[test-61] +[test-56] ExpectedResult = ServerFail # =========================================================== -[62-TLS 1.3 ML-DSA Certificate Test] -ssl_conf = 62-TLS 1.3 ML-DSA Certificate Test-ssl +[57-TLS 1.3 ML-DSA Certificate Test] +ssl_conf = 57-TLS 1.3 ML-DSA Certificate Test-ssl -[62-TLS 1.3 ML-DSA Certificate Test-ssl] -server = 62-TLS 1.3 ML-DSA Certificate Test-server -client = 62-TLS 1.3 ML-DSA Certificate Test-client +[57-TLS 1.3 ML-DSA Certificate Test-ssl] +server = 57-TLS 1.3 ML-DSA Certificate Test-server +client = 57-TLS 1.3 ML-DSA Certificate Test-client -[62-TLS 1.3 ML-DSA Certificate Test-server] +[57-TLS 1.3 ML-DSA Certificate Test-server] Certificate = ${ENV::TEST_CERTS_DIR}/server-ml-dsa-44-cert.pem CipherString = DEFAULT MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ml-dsa-44-key.pem -SignatureAlgorithms = MLdsA44 +SignatureAlgorithms = mlDsA44 -[62-TLS 1.3 ML-DSA Certificate Test-client] +[57-TLS 1.3 ML-DSA Certificate Test-client] CipherString = DEFAULT MaxProtocol = TLSv1.3 MinProtocol = TLSv1.3 -SignatureAlgorithms = MlDSa44 +SignatureAlgorithms = mlDSa44 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/root-ml-dsa-44-cert.pem VerifyMode = Peer -[test-62] +[test-57] ExpectedResult = Success diff --git a/test/ssl-tests/20-cert-select.cnf.in b/test/ssl-tests/20-cert-select.cnf.in index ff74339ced..c3d0062050 100644 --- a/test/ssl-tests/20-cert-select.cnf.in +++ b/test/ssl-tests/20-cert-select.cnf.in @@ -380,79 +380,6 @@ our @tests = ( "ExpectedResult" => "Success" }, }, - { - name => "DTLS 1.2 Ed25519 CipherString and Signature Algorithm Selection", - server => $server, - client => { - "CipherString" => "aECDSA", - "MinProtocol" => "DTLSv1.2", - "MaxProtocol" => "DTLSv1.2", - "SignatureAlgorithms" => randcase("ed25519:ECDSA+SHA256"), - "RequestCAFile" => test_pem("root-cert.pem"), - }, - test => { - "ExpectedServerCertType" =>, "Ed25519", - "ExpectedServerSignType" =>, "Ed25519", - # Note: certificate_authorities not sent for DTLS < 1.3 - "ExpectedServerCANames" =>, "empty", - "ExpectedResult" => "Success" - }, - }, - { - name => "DTLS 1.2 Ed448 CipherString and Signature Algorithm Selection", - server => $server, - client => { - "CipherString" => "aECDSA", - "MinProtocol" => "DTLSv1.2", - "MaxProtocol" => "DTLSv1.2", - "SignatureAlgorithms" => randcase("ed448:ECDSA+SHA256"), - "RequestCAFile" => test_pem("root-ed448-cert.pem"), - "VerifyCAFile" => test_pem("root-ed448-cert.pem"), - }, - test => { - "ExpectedServerCertType" =>, "Ed448", - "ExpectedServerSignType" =>, "Ed448", - # Note: certificate_authorities not sent for DTLS < 1.3 - "ExpectedServerCANames" =>, "empty", - "ExpectedResult" => "Success" - }, - }, - { - name => "DTLS 1.2 Ed25519 Client Auth", - server => { - "VerifyCAFile" => test_pem("root-cert.pem"), - "VerifyMode" => "Require" - }, - client => { - "Ed25519.Certificate" => test_pem("client-ed25519-cert.pem"), - "Ed25519.PrivateKey" => test_pem("client-ed25519-key.pem"), - "MinProtocol" => "DTLSv1.2", - "MaxProtocol" => "DTLSv1.2" - }, - test => { - "ExpectedClientCertType" => "Ed25519", - "ExpectedClientSignType" => "Ed25519", - "ExpectedResult" => "Success" - }, - }, - { - name => "DTLS 1.2 Ed448 Client Auth", - server => { - "VerifyCAFile" => test_pem("root-cert.pem"), - "VerifyMode" => "Require" - }, - client => { - "Ed448.Certificate" => test_pem("client-ed448-cert.pem"), - "Ed448.PrivateKey" => test_pem("client-ed448-key.pem"), - "MinProtocol" => "DTLSv1.2", - "MaxProtocol" => "DTLSv1.2" - }, - test => { - "ExpectedClientCertType" => "Ed448", - "ExpectedClientSignType" => "Ed448", - "ExpectedResult" => "Success" - }, - }, ); my @tests_non_fips = ( @@ -1022,25 +949,6 @@ my @tests_tls_1_3_non_fips = ( }, }, ); -my @tests_tls_1_3_sm2 = ( - { - name => "TLS 1.3 SM2", - server => { - "Certificate" => test_pem("sm2.pem"), - "PrivateKey" => test_pem("sm2.key"), - }, - client => { - "VerifyCAFile" => test_pem("sm2-root.crt"), - "MinProtocol" => "TLSv1.3", - "MaxProtocol" => "TLSv1.3" - }, - test => { - "ExpectedResult" => "Success" - }, - }, -); -push @tests_tls_1_3_non_fips, @tests_tls_1_3_sm2 - unless disabled("sm2"); push @tests, @tests_tls_1_3 unless disabled("tls1_3"); push @tests, @tests_tls_1_3_non_fips unless disabled("tls1_3") || $fips_mode; diff --git a/test/ssl-tests/25-cipher.cnf b/test/ssl-tests/25-cipher.cnf index 6e2ccef9f4..a28c1f7bed 100644 --- a/test/ssl-tests/25-cipher.cnf +++ b/test/ssl-tests/25-cipher.cnf @@ -1,6 +1,6 @@ # Generated with generate_ssl_tests.pl -num_tests = 11 +num_tests = 9 test-0 = 0-cipher-server-1 test-1 = 1-cipher-server-2 @@ -11,8 +11,6 @@ test-5 = 5-cipher-server-pref-client-list test-6 = 6-cipher-server-pref-not-mobile test-7 = 7-cipher-server-pref-mobile test-8 = 8-cipher-server-pref-mobile2 -test-9 = 9-cipher-server-sm-1 -test-10 = 10-cipher-server-sm-2 # =========================================================== [0-cipher-server-1] @@ -244,61 +242,3 @@ VerifyMode = Peer ExpectedCipher = ECDHE-RSA-CHACHA20-POLY1305 -# =========================================================== - -[9-cipher-server-sm-1] -ssl_conf = 9-cipher-server-sm-1-ssl - -[9-cipher-server-sm-1-ssl] -server = 9-cipher-server-sm-1-server -client = 9-cipher-server-sm-1-client - -[9-cipher-server-sm-1-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT -CipherSuites = TLS_SM4_GCM_SM3 -MinProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[9-cipher-server-sm-1-client] -CipherString = DEFAULT -CipherSuites = TLS_SM4_GCM_SM3 -MinProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-9] -ExpectedCipher = TLS_SM4_GCM_SM3 -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success - - -# =========================================================== - -[10-cipher-server-sm-2] -ssl_conf = 10-cipher-server-sm-2-ssl - -[10-cipher-server-sm-2-ssl] -server = 10-cipher-server-sm-2-server -client = 10-cipher-server-sm-2-client - -[10-cipher-server-sm-2-server] -Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem -CipherString = DEFAULT -CipherSuites = TLS_SM4_CCM_SM3 -MinProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem - -[10-cipher-server-sm-2-client] -CipherString = DEFAULT -CipherSuites = TLS_SM4_CCM_SM3 -MinProtocol = TLSv1.3 -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem -VerifyMode = Peer - -[test-10] -ExpectedCipher = TLS_SM4_CCM_SM3 -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success - - diff --git a/test/ssl-tests/25-cipher.cnf.in b/test/ssl-tests/25-cipher.cnf.in index 316d8b4d33..f1388e8fb4 100644 --- a/test/ssl-tests/25-cipher.cnf.in +++ b/test/ssl-tests/25-cipher.cnf.in @@ -1,5 +1,5 @@ # -*- mode: perl; -*- -# Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2017-2020 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -155,40 +155,5 @@ my @tests_poly1305 = ( }, ); -my @tests_sm4 = ( - { - name => "cipher-server-sm-1", - server => { - "MinProtocol" => "TLSv1.3", - "CipherSuites" => "TLS_SM4_GCM_SM3", - }, - client => { - "MinProtocol" => "TLSv1.3", - "CipherSuites" => "TLS_SM4_GCM_SM3", - }, - test => { - "ExpectedResult" => "Success", - "ExpectedProtocol" => "TLSv1.3", - "ExpectedCipher" => "TLS_SM4_GCM_SM3", - }, - }, - { - name => "cipher-server-sm-2", - server => { - "MinProtocol" => "TLSv1.3", - "CipherSuites" => "TLS_SM4_CCM_SM3", - }, - client => { - "MinProtocol" => "TLSv1.3", - "CipherSuites" => "TLS_SM4_CCM_SM3", - }, - test => { - "ExpectedResult" => "Success", - "ExpectedProtocol" => "TLSv1.3", - "ExpectedCipher" => "TLS_SM4_CCM_SM3", - }, - }, -); - -push @tests, @tests_poly1305 unless disabled("poly1305") || disabled("chacha") || $fips_mode; -push @tests, @tests_sm4 unless disabled("sm3") || disabled("sm4") || disabled("tls1_3") || $fips_mode; +push @tests, @tests_poly1305 + unless disabled("poly1305") || disabled("chacha") || $fips_mode; diff --git a/test/ssl-tests/33-compressed-spki.cnf b/test/ssl-tests/33-compressed-spki.cnf deleted file mode 100644 index fd9816a27e..0000000000 --- a/test/ssl-tests/33-compressed-spki.cnf +++ /dev/null @@ -1,76 +0,0 @@ -# Generated with generate_ssl_tests.pl - -num_tests = 2 - -test-0 = 0-tls12-compressed-spki -test-1 = 1-tls13-compressed-spki -# =========================================================== - -[0-tls12-compressed-spki] -ssl_conf = 0-tls12-compressed-spki-ssl - -[0-tls12-compressed-spki-ssl] -server = 0-tls12-compressed-spki-server -client = 0-tls12-compressed-spki-client - -[0-tls12-compressed-spki-server] -Certificate = ${ENV::TEST_CERTS_DIR}/server-ec-compressed-cert.pem -CipherString = DEFAULT -ClientCAFile = ${ENV::TEST_CERTS_DIR}/p384-root.pem -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 -PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ec-compressed-key.pem -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/p384-root.pem -VerifyMode = Require - -[0-tls12-compressed-spki-client] -Certificate = ${ENV::TEST_CERTS_DIR}/server-ec-compressed-cert.pem -CipherString = ECDHE-ECDSA-AES128-GCM-SHA256 -MaxProtocol = TLSv1.2 -MinProtocol = TLSv1.2 -PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ec-compressed-key.pem -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/p384-root.pem -VerifyMode = Peer - -[test-0] -ExpectedClientCertType = P-256 -ExpectedProtocol = TLSv1.2 -ExpectedResult = Success -ExpectedServerCertType = P-256 - - -# =========================================================== - -[1-tls13-compressed-spki] -ssl_conf = 1-tls13-compressed-spki-ssl - -[1-tls13-compressed-spki-ssl] -server = 1-tls13-compressed-spki-server -client = 1-tls13-compressed-spki-client - -[1-tls13-compressed-spki-server] -Certificate = ${ENV::TEST_CERTS_DIR}/server-ec-compressed-cert.pem -CipherString = DEFAULT -ClientCAFile = ${ENV::TEST_CERTS_DIR}/p384-root.pem -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ec-compressed-key.pem -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/p384-root.pem -VerifyMode = Require - -[1-tls13-compressed-spki-client] -Certificate = ${ENV::TEST_CERTS_DIR}/server-ec-compressed-cert.pem -CipherString = DEFAULT -MaxProtocol = TLSv1.3 -MinProtocol = TLSv1.3 -PrivateKey = ${ENV::TEST_CERTS_DIR}/server-ec-compressed-key.pem -VerifyCAFile = ${ENV::TEST_CERTS_DIR}/p384-root.pem -VerifyMode = Peer - -[test-1] -ExpectedClientCertType = P-256 -ExpectedProtocol = TLSv1.3 -ExpectedResult = Success -ExpectedServerCertType = P-256 - - diff --git a/test/ssl-tests/33-compressed-spki.cnf.in b/test/ssl-tests/33-compressed-spki.cnf.in deleted file mode 100644 index 06302a46a9..0000000000 --- a/test/ssl-tests/33-compressed-spki.cnf.in +++ /dev/null @@ -1,81 +0,0 @@ -# -*- mode: perl; -*- -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - - -## End-to-end check that compressed-form EC leaf certificates -## (server-ec-compressed-cert.pem, P-256 named curve, SPKI bit-string -## leading byte 0x02 or 0x03, anchored to the P-384 EC root) work at -## both TLS 1.2 and TLS 1.3 in both directions: the client presents -## the same compressed leaf to a server that requires client -## authentication, exercising X.509 acceptance of compressed point -## form on both sides simultaneously. The ec_point_formats extension -## no longer affects X.509 cert selection or acceptance, so neither -## peer opts into LegacyECPointFormats; the default ec_point_formats -## lists ('uncompressed' only) and the compressed leaves coexist. - -package ssltests; -use OpenSSL::Test::Utils; - -our @tests = (); - -unless (disabled("ec") || disabled("tls1_2") || disabled("tls1_3")) { -@tests = ( - { - name => "tls12-compressed-spki", - server => { - "Certificate" => test_pem("server-ec-compressed-cert.pem"), - "PrivateKey" => test_pem("server-ec-compressed-key.pem"), - "VerifyCAFile" => test_pem("p384-root.pem"), - "ClientCAFile" => test_pem("p384-root.pem"), - "VerifyMode" => "Require", - "MinProtocol" => "TLSv1.2", - "MaxProtocol" => "TLSv1.2", - }, - client => { - "Certificate" => test_pem("server-ec-compressed-cert.pem"), - "PrivateKey" => test_pem("server-ec-compressed-key.pem"), - "VerifyCAFile" => test_pem("p384-root.pem"), - "MinProtocol" => "TLSv1.2", - "MaxProtocol" => "TLSv1.2", - "CipherString" => "ECDHE-ECDSA-AES128-GCM-SHA256", - }, - test => { - "ExpectedResult" => "Success", - "ExpectedProtocol" => "TLSv1.2", - "ExpectedServerCertType" => "P-256", - "ExpectedClientCertType" => "P-256", - }, - }, - - { - name => "tls13-compressed-spki", - server => { - "Certificate" => test_pem("server-ec-compressed-cert.pem"), - "PrivateKey" => test_pem("server-ec-compressed-key.pem"), - "VerifyCAFile" => test_pem("p384-root.pem"), - "ClientCAFile" => test_pem("p384-root.pem"), - "VerifyMode" => "Require", - "MinProtocol" => "TLSv1.3", - "MaxProtocol" => "TLSv1.3", - }, - client => { - "Certificate" => test_pem("server-ec-compressed-cert.pem"), - "PrivateKey" => test_pem("server-ec-compressed-key.pem"), - "VerifyCAFile" => test_pem("p384-root.pem"), - "MinProtocol" => "TLSv1.3", - "MaxProtocol" => "TLSv1.3", - }, - test => { - "ExpectedResult" => "Success", - "ExpectedProtocol" => "TLSv1.3", - "ExpectedServerCertType" => "P-256", - "ExpectedClientCertType" => "P-256", - }, - }, -); -} diff --git a/test/ssl-tests/protocol_version.pm b/test/ssl-tests/protocol_version.pm index 4a5522fc4c..4e4ce365d6 100644 --- a/test/ssl-tests/protocol_version.pm +++ b/test/ssl-tests/protocol_version.pm @@ -20,15 +20,15 @@ use OpenSSL::Test; use OpenSSL::Test::Utils qw/anydisabled alldisabled disabled/; setup("no_test_here"); -my @tls_protocols = ("TLSv1", "TLSv1.1", "TLSv1.2", "TLSv1.3"); +my @tls_protocols = ("SSLv3", "TLSv1", "TLSv1.1", "TLSv1.2", "TLSv1.3"); my @tls_protocols_fips = ("TLSv1.2", "TLSv1.3"); # undef stands for "no limit". -my @min_tls_protocols = (undef, "TLSv1", "TLSv1.1", "TLSv1.2", "TLSv1.3"); +my @min_tls_protocols = (undef, "SSLv3", "TLSv1", "TLSv1.1", "TLSv1.2", "TLSv1.3"); my @min_tls_protocols_fips = (undef, "TLSv1.2", "TLSv1.3"); -my @max_tls_protocols = ("TLSv1", "TLSv1.1", "TLSv1.2", "TLSv1.3", undef); +my @max_tls_protocols = ("SSLv3", "TLSv1", "TLSv1.1", "TLSv1.2", "TLSv1.3", undef); my @max_tls_protocols_fips = ("TLSv1.2", "TLSv1.3", undef); -my @is_tls_disabled = anydisabled("tls1", "tls1_1", "tls1_2", "tls1_3"); +my @is_tls_disabled = anydisabled("ssl3", "tls1", "tls1_1", "tls1_2", "tls1_3"); my @is_tls_disabled_fips = anydisabled("tls1_2", "tls1_3"); my $min_tls_enabled; my $max_tls_enabled; @@ -107,7 +107,7 @@ sub no_tests { return disabled("dtls1_2"); } return $dtls ? alldisabled("dtls1", "dtls1_2") : - alldisabled("tls1", "tls1_1", "tls1_2", "tls1_3"); + alldisabled("ssl3", "tls1", "tls1_1", "tls1_2", "tls1_3"); } sub generate_version_tests { diff --git a/test/ssl_ctx_test.c b/test/ssl_ctx_test.c index 796472f0cb..dd075acd9b 100644 --- a/test/ssl_ctx_test.c +++ b/test/ssl_ctx_test.c @@ -33,12 +33,13 @@ typedef struct { static const version_test version_testdata[] = { /* proto min max ok expected min expected max */ { PROTO_TLS, 0, 0, 1, 1, 0, 0 }, + { PROTO_TLS, SSL3_VERSION, TLS1_3_VERSION, 1, 1, SSL3_VERSION, TLS1_3_VERSION }, { PROTO_TLS, TLS1_VERSION, TLS1_3_VERSION, 1, 1, TLS1_VERSION, TLS1_3_VERSION }, { PROTO_TLS, TLS1_VERSION, TLS1_2_VERSION, 1, 1, TLS1_VERSION, TLS1_2_VERSION }, { PROTO_TLS, TLS1_2_VERSION, TLS1_2_VERSION, 1, 1, TLS1_2_VERSION, TLS1_2_VERSION }, { PROTO_TLS, TLS1_2_VERSION, TLS1_1_VERSION, 1, 1, TLS1_2_VERSION, TLS1_1_VERSION }, - { PROTO_TLS, SSL3_VERSION, TLS1_3_VERSION, 0, 1, 0, TLS1_3_VERSION }, - { PROTO_TLS, TLS1_VERSION, TLS1_3_VERSION + 1, 1, 0, TLS1_VERSION, 0 }, + { PROTO_TLS, SSL3_VERSION - 1, TLS1_3_VERSION, 0, 1, 0, TLS1_3_VERSION }, + { PROTO_TLS, SSL3_VERSION, TLS1_3_VERSION + 1, 1, 0, SSL3_VERSION, 0 }, #ifndef OPENSSL_NO_DTLS { PROTO_TLS, DTLS1_VERSION, DTLS1_2_VERSION, 1, 1, 0, 0 }, #endif diff --git a/test/ssl_old_test.c b/test/ssl_old_test.c index 40df6536e3..909a33e6ed 100644 --- a/test/ssl_old_test.c +++ b/test/ssl_old_test.c @@ -1,5 +1,5 @@ /* - * Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved * Copyright 2005 Nokia. All rights reserved. * @@ -648,9 +648,6 @@ static void sv_usage(void) fprintf(stderr, " -dhe4096 - use 4096 bit key (safe prime) for DHE\n"); #endif - fprintf( - stderr, - " -groups - override the default client supported groups list\n"); fprintf(stderr, " -no_dhe - disable DHE\n"); #ifndef OPENSSL_NO_EC fprintf(stderr, " -no_ecdhe - disable ECDHE\n"); @@ -658,6 +655,9 @@ static void sv_usage(void) #ifndef OPENSSL_NO_PSK fprintf(stderr, " -psk arg - PSK in hex (without 0x)\n"); #endif +#ifndef OPENSSL_NO_SSL3 + fprintf(stderr, " -ssl3 - use SSLv3\n"); +#endif #ifndef OPENSSL_NO_TLS1 fprintf(stderr, " -tls1 - use TLSv1\n"); #endif @@ -814,6 +814,7 @@ static int protocol_from_string(const char *value) int version; }; static const struct protocol_versions versions[] = { + { "ssl3", SSL3_VERSION }, { "tls1", TLS1_VERSION }, { "tls1.1", TLS1_1_VERSION }, { "tls1.2", TLS1_2_VERSION }, @@ -897,7 +898,7 @@ int main(int argc, char *argv[]) BIO_IPV6 } bio_type = BIO_MEM; int force = 0; - int dtls1 = 0, dtls12 = 0, dtls = 0, tls1 = 0, tls1_1 = 0, tls1_2 = 0; + int dtls1 = 0, dtls12 = 0, dtls = 0, tls1 = 0, tls1_1 = 0, tls1_2 = 0, ssl3 = 0; int ret = EXIT_FAILURE; int client_auth = 0; int server_auth = 0, i; @@ -913,10 +914,9 @@ int main(int argc, char *argv[]) long bytes = 256L; #ifndef OPENSSL_NO_DH EVP_PKEY *dhpkey; - int dhe512 = 0, dhe1024dsa = 0, dhe2048 = 0, dhe4096 = 0; + int dhe512 = 0, dhe1024dsa = 0, dhe4096 = 0; int no_dhe = 0; #endif - const char *groups = NULL; int no_psk = 0; int print_time = 0; clock_t s_time = 0, c_time = 0; @@ -1005,8 +1005,6 @@ int main(int argc, char *argv[]) dhe512 = 1; else if (strcmp(*argv, "-dhe1024dsa") == 0) dhe1024dsa = 1; - else if (strcmp(*argv, "-dhe2048") == 0) - dhe2048 = 1; else if (strcmp(*argv, "-dhe4096") == 0) dhe4096 = 1; #endif @@ -1024,16 +1022,14 @@ int main(int argc, char *argv[]) #else no_psk = 1; #endif - } else if (strcmp(*argv, "-groups") == 0) { - if (--argc < 1) - goto bad; - groups = *(++argv); } else if (strcmp(*argv, "-tls1_2") == 0) { tls1_2 = 1; } else if (strcmp(*argv, "-tls1_1") == 0) { tls1_1 = 1; } else if (strcmp(*argv, "-tls1") == 0) { tls1 = 1; + } else if (strcmp(*argv, "-ssl3") == 0) { + ssl3 = 1; } else if (strcmp(*argv, "-dtls1") == 0) { dtls1 = 1; } else if (strcmp(*argv, "-dtls12") == 0) { @@ -1250,14 +1246,19 @@ int main(int argc, char *argv[]) goto end; } - if (tls1 + tls1_1 + tls1_2 + dtls + dtls1 + dtls12 > 1) { - fprintf(stderr, "At most one of -tls1, -tls1_1, -tls1_2, -dtls, -dtls1 or -dtls12 should " + if (ssl3 + tls1 + tls1_1 + tls1_2 + dtls + dtls1 + dtls12 > 1) { + fprintf(stderr, "At most one of -ssl3, -tls1, -tls1_1, -tls1_2, -dtls, -dtls1 or -dtls12 should " "be requested.\n"); goto end; } +#ifdef OPENSSL_NO_SSL3 + if (ssl3) + no_protocol = 1; + else +#endif #ifdef OPENSSL_NO_TLS1 - if (tls1) + if (tls1) no_protocol = 1; else #endif @@ -1284,7 +1285,7 @@ int main(int argc, char *argv[]) no_protocol = 0; /* - * Testing was requested for a compiled-out protocol (e.g. TLSv1, etc.). + * Testing was requested for a compiled-out protocol (e.g. SSLv3). * Ideally, we would error out, but the generic test wrapper can't know * when to expect failure. So we do nothing and return success. */ @@ -1295,11 +1296,11 @@ int main(int argc, char *argv[]) goto end; } - if (!tls1 && !tls1_1 && !tls1_2 && !dtls && !dtls1 && !dtls12 && number > 1 + if (!ssl3 && !tls1 && !tls1_1 && !tls1_2 && !dtls && !dtls1 && !dtls12 && number > 1 && !reuse && !force) { fprintf(stderr, "This case cannot work. Use -f to perform " "the test anyway (and\n-d to see what happens), " - "or add one of -tls1, -tls1_1, -tls1_2, -dtls, -dtls1, -dtls12, -reuse\n" + "or add one of -ssl3, -tls1, -tls1_1, -tls1_2, -dtls, -dtls1, -dtls12, -reuse\n" "to avoid protocol mismatch.\n"); goto end; } @@ -1343,7 +1344,10 @@ int main(int argc, char *argv[]) #ifndef OPENSSL_NO_TLS meth = TLS_method(); - if (tls1) { + if (ssl3) { + min_version = SSL3_VERSION; + max_version = SSL3_VERSION; + } else if (tls1) { min_version = TLS1_VERSION; max_version = TLS1_VERSION; } else if (tls1_1) { @@ -1512,8 +1516,6 @@ int main(int argc, char *argv[]) dhpkey = get_dh1024dsa(libctx); else if (dhe512) dhpkey = get_dh512(libctx); - else if (dhe2048) - dhpkey = get_dh2048(libctx); else if (dhe4096) dhpkey = get_dh4096(libctx); else @@ -1531,12 +1533,6 @@ int main(int argc, char *argv[]) EVP_PKEY_free(dhpkey); } #endif - if (groups != NULL && !SSL_CTX_set1_groups_list(c_ctx, groups)) { - BIO_printf(bio_err, "error setting client supported groups to: %s\n", - groups); - ERR_print_errors(bio_err); - goto end; - } if (!(SSL_CTX_load_verify_file(s_ctx, CAfile) || SSL_CTX_load_verify_dir(s_ctx, CApath)) @@ -2478,7 +2474,7 @@ int doit_biopair(SSL *s_ssl, SSL *c_ssl, long count, progress = 1; if (debug) - printf((io1 == client_io) ? "C->S relaying: %zu bytes\n" : "S->C relaying: %zu bytes\n", num); + printf((io1 == client_io) ? "C->S relaying: %d bytes\n" : "S->C relaying: %d bytes\n", (int)num); } } while (r1 && r2); @@ -2525,7 +2521,7 @@ int doit_biopair(SSL *s_ssl, SSL *c_ssl, long count, } if (debug) - printf((io2 == client_io) ? "C->S relaying: %zu bytes\n" : "S->C relaying: %zu bytes\n", num); + printf((io2 == client_io) ? "C->S relaying: %d bytes\n" : "S->C relaying: %d bytes\n", (int)num); } } /* no loop, BIO_ctrl_get_read_request now * returns 0 anyway */ @@ -2911,7 +2907,7 @@ static int app_verify_callback(X509_STORE_CTX *ctx, void *arg) if (cb_arg->app_verify) { char *s = NULL, buf[256]; - const X509 *c = X509_STORE_CTX_get0_cert(ctx); + X509 *c = X509_STORE_CTX_get0_cert(ctx); printf("In app_verify_callback, allowing cert. "); printf("Arg is: %s\n", cb_arg->string); diff --git a/test/sslapitest.c b/test/sslapitest.c index 6fc18a0dc0..56a70231f8 100644 --- a/test/sslapitest.c +++ b/test/sslapitest.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -119,14 +119,11 @@ static int error_writing_log = 0; #ifndef OPENSSL_NO_OCSP static int ocsp_server_called = 0; static int ocsp_client_called = 0; -static int ocsp_verify_error = X509_V_OK; #ifndef OSSL_NO_USABLE_TLS1_3 static int ocsp_verify_cb_called = 0; #endif static int cdummyarg = 1; static X509 *ocspcert = NULL; -static const char *ocsp_signer_key = "subinterCA.key"; -static const char *ocsp_signer_cert = "subinterCA.pem"; #endif #define CLIENT_VERSION_LEN 2 @@ -136,8 +133,7 @@ static const char *ocsp_signer_cert = "subinterCA.pem"; && defined(OPENSSL_NO_BROTLI) && defined(OPENSSL_NO_ZSTD) \ && !defined(OPENSSL_NO_ECX) && !defined(OPENSSL_NO_DH) \ && !defined(OPENSSL_NO_ML_DSA) && !defined(OPENSSL_NO_ML_KEM) \ - && !defined(OPENSSL_NO_SLH_DSA) \ - && !defined(OPENSSL_NO_TLS1_3) && !defined(OPENSSL_NO_SM2) + && !defined(OPENSSL_NO_TLS1_3) #define DO_SSL_TRACE_TEST #endif @@ -786,7 +782,7 @@ static int test_client_hello_cb(void) /* Avoid problems where the default seclevel has been changed */ SSL_CTX_set_security_level(cctx, 2); if (!TEST_true(SSL_CTX_set_cipher_list(cctx, - "aes256-gcm-sha384:ecdhe-ecdsa-aes256-gcm-sha384")) + "AES256-GCM-SHA384:ECDHE-ECDSA-AES256-GCM-SHA384")) || !TEST_true(create_ssl_objects(sctx, cctx, &serverssl, &clientssl, NULL, NULL)) || !TEST_false(create_ssl_connection(serverssl, clientssl, @@ -890,7 +886,7 @@ static int test_ccs_change_cipher(void) || !TEST_true(SSL_CTX_set_options(sctx, SSL_OP_NO_TICKET)) || !TEST_true(create_ssl_objects(sctx, cctx, &serverssl, &clientssl, NULL, NULL)) - || !TEST_true(SSL_set_cipher_list(clientssl, "aes128-gcm-sha256")) + || !TEST_true(SSL_set_cipher_list(clientssl, "AES128-GCM-SHA256")) || !TEST_true(create_ssl_connection(serverssl, clientssl, SSL_ERROR_NONE)) || !TEST_ptr(sesspre = SSL_get0_session(serverssl)) @@ -905,7 +901,7 @@ static int test_ccs_change_cipher(void) if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, &clientssl, NULL, NULL)) || !TEST_true(SSL_set_session(clientssl, sess)) - || !TEST_true(SSL_set_cipher_list(clientssl, "aes256-gcm-sha384:aes128-gcm-sha256")) + || !TEST_true(SSL_set_cipher_list(clientssl, "AES256-GCM-SHA384:AES128-GCM-SHA256")) || !TEST_true(create_ssl_connection(serverssl, clientssl, SSL_ERROR_NONE)) || !TEST_true(SSL_session_reused(clientssl)) @@ -924,11 +920,11 @@ static int test_ccs_change_cipher(void) */ if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, &clientssl, NULL, NULL)) - || !TEST_true(SSL_set_cipher_list(clientssl, "aes128-gcm-sha256")) + || !TEST_true(SSL_set_cipher_list(clientssl, "AES128-GCM-SHA256")) || !TEST_true(create_ssl_connection(serverssl, clientssl, SSL_ERROR_NONE)) || !TEST_ptr(sesspre = SSL_get0_session(serverssl)) - || !TEST_true(SSL_set_cipher_list(clientssl, "aes256-gcm-sha384")) + || !TEST_true(SSL_set_cipher_list(clientssl, "AES256-GCM-SHA384")) || !TEST_true(SSL_renegotiate(clientssl)) || !TEST_true(SSL_renegotiate_pending(clientssl))) goto end; @@ -1462,144 +1458,6 @@ end: return testresult; } -#ifndef OSSL_NO_USABLE_TLS1_3 -/* - * Test kTLS with SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER: retry SSL_write() after - * SSL_ERROR_WANT_WRITE using a different buffer pointer (same content) and - * verify that the data arrives intact. - */ -static int test_ktls_moving_write_buffer(void) -{ - SSL_CTX *cctx = NULL, *sctx = NULL; - SSL *clientssl = NULL, *serverssl = NULL; - BIO *bio_retry = NULL, *bio_orig = NULL; - int testresult = 0, cfd = -1, sfd = -1; - unsigned char *buf_orig = NULL, *buf_retry = NULL; - unsigned char outbuf[1024]; - const size_t bufsz = sizeof(outbuf); - size_t written, readbytes, totread = 0, i; - - /* kTLS requires real sockets */ - if (!TEST_true(create_test_sockets(&cfd, &sfd, SOCK_STREAM, NULL))) - goto end; - - /* Skip if the kernel does not support kTLS */ - if (!ktls_chk_platform(cfd)) { - testresult = TEST_skip("Kernel does not support KTLS"); - goto end; - } - - if (!TEST_true(create_ssl_ctx_pair(libctx, - TLS_server_method(), TLS_client_method(), - TLS1_3_VERSION, TLS1_3_VERSION, - &sctx, &cctx, cert, privkey))) - goto end; - - if (!TEST_true(SSL_CTX_set_ciphersuites(cctx, "TLS_AES_128_GCM_SHA256")) - || !TEST_true(SSL_CTX_set_ciphersuites(sctx, "TLS_AES_128_GCM_SHA256"))) - goto end; - - if (!TEST_true(create_ssl_objects2(sctx, cctx, &serverssl, - &clientssl, sfd, cfd))) - goto end; - - /* Enable kTLS on the writing side (client) */ - if (!TEST_true(SSL_set_options(clientssl, SSL_OP_ENABLE_KTLS))) - goto end; - - SSL_set_mode(clientssl, SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER); - SSL_set_mode(clientssl, SSL_MODE_ENABLE_PARTIAL_WRITE); - - if (!TEST_true(create_ssl_connection(serverssl, clientssl, SSL_ERROR_NONE))) - goto end; - - /* Get a reference to the original BIO to replace it later. */ - bio_orig = SSL_get_wbio(clientssl); - if (!TEST_ptr(bio_orig) || !TEST_true(BIO_up_ref(bio_orig))) { - bio_orig = NULL; - goto end; - } - - /* Skip if kTLS TX was not activated for this cipher */ - if (!BIO_get_ktls_send(bio_orig)) { - testresult = TEST_skip("kTLS send not supported"); - goto end; - } - - /* Swap write BIO to force WANT_WRITE */ - bio_retry = BIO_new(bio_s_always_retry()); - if (!TEST_ptr(bio_retry)) - goto end; - - SSL_set0_wbio(clientssl, bio_retry); - bio_retry = NULL; /* ownership transferred to clientssl */ - - /* Allocate two buffers with identical content but different addresses */ - buf_orig = OPENSSL_malloc(bufsz); - buf_retry = OPENSSL_malloc(bufsz); - if (!TEST_ptr(buf_orig) || !TEST_ptr(buf_retry)) - goto end; - - for (i = 0; i < bufsz; i++) - buf_orig[i] = buf_retry[i] = (unsigned char)(i & 0xff); - - /* First write attempt - will fail with WANT_WRITE */ - if (!TEST_false(SSL_write_ex(clientssl, buf_orig, bufsz, &written)) - || !TEST_int_eq(SSL_get_error(clientssl, 0), SSL_ERROR_WANT_WRITE)) - goto end; - - /* Restore the real socket BIO so the retry can actually send data */ - SSL_set0_wbio(clientssl, bio_orig); - bio_orig = NULL; - - /* Poison and free the original buffer */ - memset(buf_orig, 0xDE, bufsz); - OPENSSL_free(buf_orig); - buf_orig = NULL; - - /* Retry with a different buffer pointer */ - if (!TEST_true(SSL_write_ex(clientssl, buf_retry, bufsz, &written))) - goto end; - - /* Read the data on the server side */ - totread = 0; - while (totread < bufsz) { - if (!SSL_read_ex(serverssl, outbuf + totread, bufsz - totread, - &readbytes)) { - if (!TEST_int_eq(SSL_get_error(serverssl, 0), SSL_ERROR_WANT_READ)) - goto end; - } else { - totread += readbytes; - } - } - - /* Verify data integrity */ - if (!TEST_mem_eq(buf_retry, bufsz, outbuf, totread)) - goto end; - - testresult = 1; -end: - OPENSSL_free(buf_orig); - OPENSSL_free(buf_retry); - if (clientssl != NULL) { - SSL_shutdown(clientssl); - SSL_free(clientssl); - } - if (serverssl != NULL) { - SSL_shutdown(serverssl); - SSL_free(serverssl); - } - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - BIO_free_all(bio_orig); - if (cfd != -1) - close(cfd); - if (sfd != -1) - close(sfd); - return testresult; -} -#endif /* !defined(OSSL_NO_USABLE_TLS1_3) */ - static struct ktls_test_cipher { int tls_version; const char *cipher; @@ -1748,7 +1606,12 @@ static int test_large_app_data(int tst) #endif case 4: +#ifndef OPENSSL_NO_SSL3 + prot = SSL3_VERSION; + break; +#else return TEST_skip("SSL 3 not supported"); +#endif case 5: #ifndef OPENSSL_NO_DTLS1_2 @@ -1998,7 +1861,7 @@ static int test_cleanse_plaintext(void) #ifndef OPENSSL_NO_OCSP static OCSP_RESPONSE *create_ocsp_resp(X509 *ssl_cert, X509 *issuer, int status, - const char *signer_key_files, const char *signer_cert_files) + char *signer_key_files, char *signer_cert_files) { ASN1_TIME *thisupd = X509_gmtime_adj(NULL, 0); ASN1_TIME *nextupd = X509_time_adj_ex(NULL, 1, 0, NULL); @@ -2071,8 +1934,7 @@ static int ocsp_server_cb_single(SSL *s, void *arg) SSL_get0_chain_certs(s, &server_certs); issuer = sk_X509_value(server_certs, 0); - ocsp_resp = create_ocsp_resp(ssl_cert, issuer, V_OCSP_CERTSTATUS_GOOD, - ocsp_signer_key, ocsp_signer_cert); + ocsp_resp = create_ocsp_resp(ssl_cert, issuer, V_OCSP_CERTSTATUS_GOOD, "subinterCA.key", "subinterCA.pem"); if (!TEST_ptr(ocsp_resp)) return SSL_TLSEXT_ERR_ALERT_FATAL; @@ -2110,13 +1972,6 @@ static int ocsp_client_cb_single(SSL *s, void *arg) return 1; } -static int verify_cb_capture_error(int preverify_ok, X509_STORE_CTX *x509_ctx) -{ - if (!preverify_ok && ocsp_verify_error == X509_V_OK) - ocsp_verify_error = X509_STORE_CTX_get_error(x509_ctx); - return preverify_ok; -} - static int test_tlsext_status_type(void) { SSL_CTX *cctx = NULL, *sctx = NULL; @@ -2243,59 +2098,9 @@ static int test_tlsext_status_type(void) || !TEST_true(ocsp_server_called)) goto end; - /* - * Test that a stapled OCSP response signed by the leaf certificate - * (unauthorized signer) is rejected when X509_V_FLAG_OCSP_RESP_CHECK - * is enabled. Reuse the existing sctx/cctx, adding only the trust - * anchor, verify callback, and OCSP response check flag. - */ - SSL_free(serverssl); - SSL_free(clientssl); - serverssl = clientssl = NULL; - - ocsp_signer_key = "leaf.key"; - ocsp_signer_cert = "leaf.pem"; - ocsp_server_called = 0; - ocsp_verify_error = X509_V_OK; - cdummyarg = 1; - - { - char *root = test_mk_file_path(certsdir, "rootCA.pem"); - - if (!TEST_ptr(root) - || !TEST_true(SSL_CTX_load_verify_locations(cctx, root, NULL))) { - OPENSSL_free(root); - goto end; - } - OPENSSL_free(root); - } - SSL_CTX_set_verify(cctx, SSL_VERIFY_PEER, verify_cb_capture_error); - { - X509_VERIFY_PARAM *vpm = X509_VERIFY_PARAM_new(); - - if (!TEST_ptr(vpm)) - goto end; - X509_VERIFY_PARAM_set_flags(vpm, X509_V_FLAG_OCSP_RESP_CHECK); - if (!TEST_true(SSL_CTX_set1_param(cctx, vpm))) { - X509_VERIFY_PARAM_free(vpm); - goto end; - } - X509_VERIFY_PARAM_free(vpm); - } - - if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, &clientssl, - NULL, NULL)) - || !TEST_false(create_ssl_connection(serverssl, clientssl, - SSL_ERROR_SSL)) - || !TEST_int_eq(ocsp_server_called, 1) - || !TEST_int_eq(ocsp_verify_error, X509_V_ERR_OCSP_VERIFY_FAILED)) - goto end; - testresult = 1; end: - ocsp_signer_key = "subinterCA.key"; - ocsp_signer_cert = "subinterCA.pem"; SSL_free(serverssl); SSL_free(clientssl); SSL_CTX_free(sctx); @@ -2519,11 +2324,11 @@ static int test_tlsext_status_type_multi(void) if (!TEST_true(create_ssl_ctx_pair(libctx, TLS_server_method(), TLS_client_method(), TLS1_VERSION, 0, &sctx, &cctx, leaf, skey))) goto end; - if (!TEST_int_ge(SSL_CTX_use_certificate_chain_file(sctx, leaf_chain), 0)) + if (TEST_int_lt(SSL_CTX_use_certificate_chain_file(sctx, leaf_chain), 0)) goto end; if (!TEST_true(SSL_CTX_load_verify_locations(cctx, root, NULL))) goto end; - if (!TEST_int_eq(SSL_CTX_get_tlsext_status_type(cctx), -1)) + if (TEST_int_ne(SSL_CTX_get_tlsext_status_type(cctx), -1)) goto end; /* set verify callback function */ @@ -3030,58 +2835,6 @@ static int test_session_with_both_cache(void) #endif } -/* - * Test that remove_session_cb is not invoked while ctx->lock is held. - * The callback calls SSL_CTX_flush_sessions_ex(), which itself tries to - * acquire ctx->lock; if the lock is already held when the callback fires, - * the nested acquisition deadlocks immediately. t = 1 (Unix epoch + 1s) is - * used so that no current sessions are flushed and the callback is not - * re-entered. - */ -static void remove_session_lock_test_cb(SSL_CTX *ctx, SSL_SESSION *sess) -{ - SSL_CTX_flush_sessions_ex(ctx, 1); -} - -static int test_remove_session_cb_not_under_lock(void) -{ - SSL_CTX *ctx = NULL; - SSL_SESSION *sess1 = NULL, *sess2 = NULL; - static const unsigned char sid1[] = { 1 }; - static const unsigned char sid2[] = { 2 }; - int testresult = 0; - - if (!TEST_ptr(ctx = SSL_CTX_new_ex(libctx, NULL, TLS_server_method()))) - goto end; - - SSL_CTX_sess_set_cache_size(ctx, 1); - SSL_CTX_sess_set_remove_cb(ctx, remove_session_lock_test_cb); - - if (!TEST_ptr(sess1 = SSL_SESSION_new()) - || !TEST_true(SSL_SESSION_set1_id(sess1, sid1, sizeof(sid1))) - || !TEST_true(SSL_CTX_add_session(ctx, sess1))) - goto end; - - if (!TEST_ptr(sess2 = SSL_SESSION_new()) - || !TEST_true(SSL_SESSION_set1_id(sess2, sid2, sizeof(sid2)))) - goto end; - - /* - * Adding sess2 evicts sess1 (cache is full), firing remove_session_cb. - * If the callback is invoked while holding ctx->lock the flush call - * inside it will deadlock. - */ - if (!TEST_true(SSL_CTX_add_session(ctx, sess2))) - goto end; - - testresult = 1; -end: - SSL_SESSION_free(sess1); - SSL_SESSION_free(sess2); - SSL_CTX_free(ctx); - return testresult; -} - static int test_session_wo_ca_names(void) { #ifndef OSSL_NO_USABLE_TLS1_3 @@ -3795,52 +3548,6 @@ static int test_ssl_bio_change_wbio(void) return execute_test_ssl_bio(0, CHANGE_WBIO); } -/* - * Regression for GH #30458: tls_set1_bio() must BIO_free_all the old chain - * when the write BIO is replaced, not only the top BIO. - */ -static int test_ssl_set_wbio_chain_no_leak(void) -{ - SSL_CTX *ctx = NULL; - SSL *ssl = NULL; - BIO *bio = NULL, *filter = NULL, *chain1 = NULL; - int testresult = 0; - - if (!TEST_ptr(ctx = SSL_CTX_new_ex(libctx, NULL, TLS_method()))) - goto end; - if (!TEST_ptr(ssl = SSL_new(ctx))) - goto end; - - if (!TEST_ptr(filter = BIO_new(BIO_f_nbio_test()))) - goto end; - if (!TEST_ptr(bio = BIO_new(BIO_s_mem()))) { - BIO_free(filter); - filter = NULL; - goto end; - } - if (!TEST_ptr(chain1 = BIO_push(filter, bio))) { - BIO_free_all(filter); - filter = bio = NULL; - goto end; - } - filter = bio = NULL; - - SSL_set0_wbio(ssl, chain1); - chain1 = NULL; - SSL_set0_wbio(ssl, NULL); - - testresult = 1; - -end: - BIO_free(filter); - BIO_free(bio); - BIO_free(chain1); - SSL_free(ssl); - SSL_CTX_free(ctx); - - return testresult; -} - #if !defined(OPENSSL_NO_TLS1_2) || defined(OSSL_NO_USABLE_TLS1_3) typedef struct { /* The list of sig algs */ @@ -4635,18 +4342,18 @@ static int test_early_data_replay(int idx) } static const char *ciphersuites[] = { - "tls_aes_128_ccm_8_sha256", - "tls_aes_128_gcm_sha256", - "tls_aes_256_gcm_sha384", - "tls_aes_128_ccm_sha256", + "TLS_AES_128_CCM_8_SHA256", + "TLS_AES_128_GCM_SHA256", + "TLS_AES_256_GCM_SHA384", + "TLS_AES_128_CCM_SHA256", #if !defined(OPENSSL_NO_CHACHA) && !defined(OPENSSL_NO_POLY1305) - "tls_chacha20_poly1305_sha256", + "TLS_CHACHA20_POLY1305_SHA256", #else NULL, #endif #if !defined(OPENSSL_NO_INTEGRITY_ONLY_CIPHERS) - "tls_sha256_sha256", - "tls_sha384_sha384" + "TLS_SHA256_SHA256", + "TLS_SHA384_SHA384" #endif }; @@ -5448,12 +5155,12 @@ static int test_set_ciphersuite(int idx) TLS_client_method(), TLS1_VERSION, 0, &sctx, &cctx, cert, privkey)) || !TEST_true(SSL_CTX_set_ciphersuites(sctx, - "tls_aes_128_gcm_sha256:tls_aes_128_ccm_sha256"))) + "TLS_AES_128_GCM_SHA256:TLS_AES_128_CCM_SHA256"))) goto end; if (idx >= 4 && idx <= 7) { /* SSL_CTX explicit cipher list */ - if (!TEST_true(SSL_CTX_set_cipher_list(cctx, "aes256-gcm-sha384"))) + if (!TEST_true(SSL_CTX_set_cipher_list(cctx, "AES256-GCM-SHA384"))) goto end; } @@ -5487,7 +5194,7 @@ static int test_set_ciphersuite(int idx) } else if (idx == 3 || idx == 7 || idx == 9) { /* Non default ciphersuite */ if (!TEST_true(SSL_set_ciphersuites(clientssl, - "tls_aes_128_ccm_sha256"))) + "TLS_AES_128_CCM_SHA256"))) goto end; } @@ -5518,9 +5225,9 @@ static int test_ciphersuite_change(void) TLS_client_method(), TLS1_VERSION, 0, &sctx, &cctx, cert, privkey)) || !TEST_true(SSL_CTX_set_ciphersuites(sctx, - "tls_aes_128_gcm_sha256:" + "TLS_AES_128_GCM_SHA256:" "TLS_AES_256_GCM_SHA384:" - "tls_aes_128_ccm_sha256")) + "TLS_AES_128_CCM_SHA256")) || !TEST_true(SSL_CTX_set_ciphersuites(cctx, "TLS_AES_128_GCM_SHA256"))) goto end; @@ -5659,24 +5366,22 @@ end: * Test 16 = Test X25519MLKEM768 * Test 17 = Test SecP256r1MLKEM768 * Test 18 = Test SecP384r1MLKEM1024 - * Test 19 = Test curveSM2 with TLSv1.3 client and server - * Test 20 = Test curveSM2MLKEM768 with TLSv1.3 client and server - * Test 21 = Test all ML-KEM with TLSv1.2 client and server - * Test 22 = Test all FFDHE with TLSv1.2 client and server - * Test 23 = Test all ECDHE with TLSv1.2 client and server + * Test 19 = Test all ML-KEM with TLSv1.2 client and server + * Test 20 = Test all FFDHE with TLSv1.2 client and server + * Test 21 = Test all ECDHE with TLSv1.2 client and server */ #ifndef OPENSSL_NO_EC static int ecdhe_kexch_groups[] = { NID_X9_62_prime256v1, NID_secp384r1, NID_secp521r1, #ifndef OPENSSL_NO_ECX NID_X25519, NID_X448 -#endif /* OPENSSL_NO_ECX */ +#endif }; -#endif /* OPENSSL_NO_EC */ +#endif #ifndef OPENSSL_NO_DH static int ffdhe_kexch_groups[] = { NID_ffdhe2048, NID_ffdhe3072, NID_ffdhe4096, NID_ffdhe6144, NID_ffdhe8192 }; -#endif /* OPENSSL_NO_DH */ +#endif static int test_key_exchange(int idx) { SSL_CTX *sctx = NULL, *cctx = NULL; @@ -5689,14 +5394,13 @@ static int test_key_exchange(int idx) char *kexch_name0 = NULL; const char *kexch_names = NULL; int shared_group0; - const char *client_group_name = NULL; switch (idx) { #ifndef OPENSSL_NO_EC #ifndef OPENSSL_NO_TLS1_2 - case 23: + case 21: max_version = TLS1_2_VERSION; -#endif /* OPENSSL_NO_TLS1_2 */ +#endif /* Fall through */ case 0: kexch_groups = ecdhe_kexch_groups; @@ -5728,13 +5432,14 @@ static int test_key_exchange(int idx) kexch_alg = NID_X448; kexch_name0 = "x448"; break; -#endif /* OPENSSL_NO_ECX */ -#endif /* OPENSSL_NO_EC */ +#endif +#endif #ifndef OPENSSL_NO_DH #ifndef OPENSSL_NO_TLS1_2 - case 22: + case 20: max_version = TLS1_2_VERSION; -#endif /* OPENSSL_NO_TLS1_2 */ + kexch_name0 = "ffdhe2048"; +#endif /* Fall through */ case 6: kexch_groups = ffdhe_kexch_groups; @@ -5761,26 +5466,22 @@ static int test_key_exchange(int idx) kexch_alg = NID_ffdhe8192; kexch_name0 = "ffdhe8192"; break; -#endif /* OPENSSL_NO_DH */ +#endif #ifndef OPENSSL_NO_ML_KEM #if !defined(OPENSSL_NO_TLS1_2) - case 21: + case 19: max_version = TLS1_2_VERSION; - kexch_groups = NULL; #if !defined(OPENSSL_NO_EC) /* Set at least one EC group so the handshake completes */ kexch_names = "MLKEM512:MLKEM768:MLKEM1024:secp256r1"; - kexch_name0 = "secp256r1"; - break; #elif !defined(OPENSSL_NO_DH) - kexch_names = "MLKEM512:MLKEM768:MLKEM1024:ffdhe2048"; - kexch_name0 = "ffdhe2048"; - break; + kexch_names = "MLKEM512:MLKEM768:MLKEM1024"; #else /* With neither EC nor DH TLS 1.2 can't happen */ return 1; #endif -#endif /* OPENSSL_NO_TLS1_2 */ +#endif + /* Fall through */ case 12: kexch_groups = NULL; if (kexch_names == NULL) @@ -5809,7 +5510,7 @@ static int test_key_exchange(int idx) kexch_name0 = "X25519MLKEM768"; kexch_names = kexch_name0; break; -#endif /* OPENSSL_NO_ECX */ +#endif case 17: kexch_groups = NULL; kexch_name0 = "SecP256r1MLKEM768"; @@ -5820,37 +5521,15 @@ static int test_key_exchange(int idx) kexch_name0 = "SecP384r1MLKEM1024"; kexch_names = kexch_name0; break; -#endif /* OPENSSL_NO_EC */ -#endif /* OPENSSL_NO_ML_KEM */ - -#ifndef OPENSSL_NO_EC -#ifndef OPENSSL_NO_SM2 - case 19: - if (is_fips) - return TEST_skip("curveSM2 is not supported by the fips provider."); - kexch_groups = NULL; - kexch_name0 = "curveSM2"; - kexch_names = kexch_name0; - break; -#ifndef OPENSSL_NO_ML_KEM - case 20: - if (is_fips) - return TEST_skip("curveSM2MLKEM768 is not supported by the fips provider."); - kexch_groups = NULL; - kexch_name0 = "curveSM2MLKEM768"; - kexch_names = kexch_name0; - break; -#endif /* OPENSSL_NO_ML_KEM */ -#endif /* OPENSSL_NO_SM2 */ -#endif /* OPENSSL_NO_EC */ - +#endif +#endif default: /* We're skipping this test */ return 1; } if (is_fips && fips_provider_version_lt(libctx, 3, 5, 0) - && ((idx >= 12 && idx <= 18) || idx == 21)) + && idx >= 12 && idx <= 19) return TEST_skip("ML-KEM not supported in this version of fips provider"); if (!TEST_true(create_ssl_ctx_pair(libctx, TLS_server_method(), @@ -5899,28 +5578,42 @@ static int test_key_exchange(int idx) if (!TEST_true(create_ssl_connection(serverssl, clientssl, SSL_ERROR_NONE))) goto end; - shared_group0 = SSL_get_shared_group(serverssl, 0); - if (kexch_groups != NULL - && !TEST_int_eq(shared_group0, kexch_groups[0])) - goto end; - if (!TEST_str_eq(SSL_group_to_name(serverssl, shared_group0), - kexch_name0)) - goto end; /* - * With TLS <= 1.2, the client will not infer an FFDHE group name from - * the server's DH parameters, so we allow NULL client names in that - * case. + * If the handshake succeeds the negotiated kexch alg should be the first + * one in configured, except in the case of "all" FFDHE and "all" ML-KEM + * groups (idx == 19, 20), which are TLSv1.3 only so we expect no shared + * group to exist. */ - client_group_name = SSL_get0_group_name(clientssl); - if (!TEST_str_eq(SSL_get0_group_name(serverssl), kexch_name0) - || ((max_version >= TLS1_3_VERSION || client_group_name != NULL) - && !TEST_str_eq(client_group_name, kexch_name0))) - goto end; - if (!TEST_int_eq(SSL_get_negotiated_group(serverssl), shared_group0)) - goto end; - if (client_group_name != NULL - && !TEST_int_eq(SSL_get_negotiated_group(clientssl), shared_group0)) - goto end; + shared_group0 = SSL_get_shared_group(serverssl, 0); + switch (idx) { + case 19: +#if !defined(OPENSSL_NO_EC) + /* MLKEM + TLS 1.2 and no DH => "secp526r1" */ + if (!TEST_int_eq(shared_group0, NID_X9_62_prime256v1)) + goto end; + break; +#endif + /* Fall through */ + case 20: + if (!TEST_int_eq(shared_group0, 0)) + goto end; + break; + default: + if (kexch_groups != NULL + && !TEST_int_eq(shared_group0, kexch_groups[0])) + goto end; + if (!TEST_str_eq(SSL_group_to_name(serverssl, shared_group0), + kexch_name0)) + goto end; + if (!TEST_str_eq(SSL_get0_group_name(serverssl), kexch_name0) + || !TEST_str_eq(SSL_get0_group_name(clientssl), kexch_name0)) + goto end; + if (!TEST_int_eq(SSL_get_negotiated_group(serverssl), shared_group0)) + goto end; + if (!TEST_int_eq(SSL_get_negotiated_group(clientssl), shared_group0)) + goto end; + break; + } testresult = 1; end: @@ -6025,7 +5718,11 @@ static int test_negotiated_group(int idx) kexch_alg = ecdhe_kexch_groups[idx]; else kexch_alg = ffdhe_kexch_groups[idx]; - expectednid = kexch_alg; + /* We expect nothing for the unimplemented TLS 1.2 FFDHE named groups */ + if (!istls13 && !isecdhe) + expectednid = NID_undef; + else + expectednid = kexch_alg; if (is_fips && (kexch_alg == NID_X25519 || kexch_alg == NID_X448)) return TEST_skip("X25519 and X448 might not be available in fips provider."); @@ -6062,13 +5759,9 @@ static int test_negotiated_group(int idx) if (!TEST_true(create_ssl_connection(serverssl, clientssl, SSL_ERROR_NONE))) goto end; - /* - * Initial handshake; always the configured one. With TLS <= 1.2 and FFDHE - * the client does not infer a negotiated group id. - */ - if (!TEST_uint_eq(SSL_get_negotiated_group(serverssl), expectednid) - || ((istls13 || isecdhe) - && !TEST_uint_eq(SSL_get_negotiated_group(clientssl), expectednid))) + /* Initial handshake; always the configured one */ + if (!TEST_uint_eq(SSL_get_negotiated_group(clientssl), expectednid) + || !TEST_uint_eq(SSL_get_negotiated_group(serverssl), expectednid)) goto end; if (!TEST_ptr((origsess = SSL_get1_session(clientssl)))) @@ -6093,9 +5786,8 @@ static int test_negotiated_group(int idx) goto end; /* Still had better agree, since nothing changed... */ - if (!TEST_uint_eq(SSL_get_negotiated_group(serverssl), expectednid) - || ((istls13 || isecdhe) - && !TEST_uint_eq(SSL_get_negotiated_group(clientssl), expectednid))) + if (!TEST_uint_eq(SSL_get_negotiated_group(clientssl), expectednid) + || !TEST_uint_eq(SSL_get_negotiated_group(serverssl), expectednid)) goto end; SSL_shutdown(clientssl); @@ -6122,7 +5814,11 @@ static int test_negotiated_group(int idx) if (!TEST_int_ne(expectednid, kexch_alg)) goto end; } else { - expectednid = kexch_alg; + /* TLS 1.2 only supports named groups for ECDHE. */ + if (isecdhe) + expectednid = kexch_alg; + else + expectednid = 0; } if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, &clientssl, NULL, NULL)) @@ -6136,9 +5832,8 @@ static int test_negotiated_group(int idx) goto end; /* Check that we get what we expected */ - if (!TEST_uint_eq(SSL_get_negotiated_group(serverssl), expectednid) - || ((istls13 || isecdhe) - && !TEST_uint_eq(SSL_get_negotiated_group(clientssl), expectednid))) + if (!TEST_uint_eq(SSL_get_negotiated_group(clientssl), expectednid) + || !TEST_uint_eq(SSL_get_negotiated_group(serverssl), expectednid)) goto end; testresult = 1; @@ -6546,165 +6241,6 @@ end: return testresult; } -/* - * A server with SSL_VERIFY_PEER set but no session ID context configured - * must still accept a TLS 1.3 external PSK connection: the session was - * just resolved via the application's own callback for this identity, not - * read back out of a shared cache, so the sid_ctx check that guards - * against cross-context cache reuse does not apply to it. - */ -static int test_tls13_psk_verify_peer_no_sid_ctx(void) -{ - SSL_CTX *sctx = NULL, *cctx = NULL; - SSL *serverssl = NULL, *clientssl = NULL; - int testresult = 0; - - if (!TEST_true(create_ssl_ctx_pair(libctx, TLS_server_method(), - TLS_client_method(), TLS1_VERSION, 0, &sctx, &cctx, NULL, NULL)) - || !TEST_true(SSL_CTX_set_ciphersuites(cctx, "TLS_AES_128_GCM_SHA256"))) - goto end; - - SSL_CTX_set_verify(sctx, SSL_VERIFY_PEER, NULL); - - SSL_CTX_set_psk_use_session_callback(cctx, use_session_cb); - SSL_CTX_set_psk_find_session_callback(sctx, find_session_cb); - srvid = pskid; - use_session_cb_cnt = 0; - find_session_cb_cnt = 0; - - if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, &clientssl, - NULL, NULL))) - goto end; - - clientpsk = create_a_psk(clientssl, SHA256_DIGEST_LENGTH); - if (!TEST_ptr(clientpsk) || !TEST_true(SSL_SESSION_up_ref(clientpsk))) - goto end; - serverpsk = clientpsk; - - if (!TEST_true(create_ssl_connection(serverssl, clientssl, SSL_ERROR_NONE)) - || !TEST_true(SSL_session_reused(clientssl)) - || !TEST_true(SSL_session_reused(serverssl))) - goto end; - - testresult = 1; -end: - SSL_SESSION_free(clientpsk); - SSL_SESSION_free(serverpsk); - clientpsk = serverpsk = NULL; - SSL_free(serverssl); - SSL_free(clientssl); - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - return testresult; -} - -/* - * A server with SSL_VERIFY_PEER set but no session ID context configured - * must not issue a session ticket after a full (non-PSK) handshake: any - * such ticket would be a poison pill, since resuming it would hit exactly - * the sid_ctx check that a fresh external PSK is exempted from above. - */ -static int test_tls13_psk_verify_peer_no_ticket(void) -{ - SSL_CTX *sctx = NULL, *cctx = NULL; - SSL *serverssl = NULL, *clientssl = NULL; - SSL_SESSION *sess = NULL; - int testresult = 0; - - if (!TEST_true(create_ssl_ctx_pair(libctx, TLS_server_method(), - TLS_client_method(), TLS1_VERSION, 0, &sctx, &cctx, cert, privkey))) - goto end; - - SSL_CTX_set_verify(sctx, SSL_VERIFY_PEER, NULL); - - if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, &clientssl, - NULL, NULL)) - || !TEST_true(create_ssl_connection(serverssl, clientssl, - SSL_ERROR_NONE))) - goto end; - - sess = SSL_get1_session(clientssl); - if (!TEST_ptr(sess) || !TEST_false(SSL_SESSION_has_ticket(sess))) - goto end; - - testresult = 1; -end: - SSL_SESSION_free(sess); - SSL_free(serverssl); - SSL_free(clientssl); - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - return testresult; -} - -/* - * A client with its own session ID context configured must still be able - * to resume a TLS 1.3 external PSK obtained via the legacy - * psk_use_session_cb()/psk_client_callback() callbacks. s->psksession is - * never routed through ssl_get_new_session(), so, unlike an ordinary - * session, it was never stamped with the client's own sid_ctx; without - * that stamp tls_process_server_hello()'s own sid_ctx self-consistency - * check fatally rejects marking it reused. - * - * Test 0: new style callback (psk_use_session_cb()/psk_find_session_cb()). - * Test 1: old style callback (psk_client_callback()/psk_server_callback()). - */ -static int test_tls13_psk_client_sid_ctx(int idx) -{ - SSL_CTX *sctx = NULL, *cctx = NULL; - SSL *serverssl = NULL, *clientssl = NULL; - int sess_id_ctx = 1; - int testresult = 0; - - if (!TEST_true(create_ssl_ctx_pair(libctx, TLS_server_method(), - TLS_client_method(), TLS1_VERSION, 0, &sctx, &cctx, NULL, NULL)) - || !TEST_true(SSL_CTX_set_ciphersuites(cctx, "TLS_AES_128_GCM_SHA256")) - || !TEST_true(SSL_CTX_set_session_id_context(cctx, - (void *)&sess_id_ctx, sizeof(sess_id_ctx)))) - goto end; - - srvid = pskid; - if (idx == 0) { - SSL_CTX_set_psk_use_session_callback(cctx, use_session_cb); - SSL_CTX_set_psk_find_session_callback(sctx, find_session_cb); - use_session_cb_cnt = 0; - find_session_cb_cnt = 0; - } -#ifndef OPENSSL_NO_PSK - else { - SSL_CTX_set_psk_client_callback(cctx, psk_client_cb); - SSL_CTX_set_psk_server_callback(sctx, psk_server_cb); - psk_client_cb_cnt = 0; - psk_server_cb_cnt = 0; - } -#endif - - if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, &clientssl, - NULL, NULL))) - goto end; - - clientpsk = create_a_psk(clientssl, SHA256_DIGEST_LENGTH); - if (!TEST_ptr(clientpsk) || !TEST_true(SSL_SESSION_up_ref(clientpsk))) - goto end; - serverpsk = clientpsk; - - if (!TEST_true(create_ssl_connection(serverssl, clientssl, SSL_ERROR_NONE)) - || !TEST_true(SSL_session_reused(clientssl)) - || !TEST_true(SSL_session_reused(serverssl))) - goto end; - - testresult = 1; -end: - SSL_SESSION_free(clientpsk); - SSL_SESSION_free(serverpsk); - clientpsk = serverpsk = NULL; - SSL_free(serverssl); - SSL_free(clientssl); - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - return testresult; -} - #ifndef OSSL_NO_USABLE_TLS1_3 /* * Test TLS1.3 connection establishment succeeds with various configurations of @@ -7485,9 +7021,7 @@ static int test_export_key_mat(int tst) OPENSSL_assert(tst >= 0 && (size_t)tst < OSSL_NELEM(protocols)); SSL_CTX_set_max_proto_version(cctx, protocols[tst]); SSL_CTX_set_min_proto_version(cctx, protocols[tst]); - if ((protocols[tst] < TLS1_2_VERSION) - && (!SSL_CTX_set_cipher_list(cctx, "default:@seclevel=0") - || !SSL_CTX_set_cipher_list(sctx, "DEFAULT:@SECLEVEL=0"))) + if ((protocols[tst] < TLS1_2_VERSION) && (!SSL_CTX_set_cipher_list(cctx, "DEFAULT:@SECLEVEL=0") || !SSL_CTX_set_cipher_list(sctx, "DEFAULT:@SECLEVEL=0"))) goto end; if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, &clientssl, NULL, @@ -9134,9 +8668,9 @@ static int test_ssl_pending(int tst) * Default sigalgs are SHA1 based in = TLS1_3_VERSION - && fips_provider_version_ge(libctx, 3, 5, 0)) { - if (!TEST_ptr(chain) - || !TEST_true(load_chain("root-ml-dsa-44-cert.pem", NULL, NULL, chain)) - || !TEST_true(load_chain("server-ml-dsa-44-cert.pem", NULL, &x509, NULL)) - || !TEST_true(load_chain("server-ml-dsa-44-key.pem", &pkey, NULL, NULL))) - goto out; - goto check; - } -#endif if (!TEST_ptr(chain) || !TEST_true(load_chain("ca-cert.pem", NULL, NULL, chain)) || !TEST_true(load_chain("root-cert.pem", NULL, NULL, chain)) @@ -10214,10 +9543,6 @@ static int cert_cb(SSL *s, void *arg) || !TEST_true(load_chain("p256-ee-rsa-ca-key.pem", &pkey, NULL, NULL))) goto out; - -#ifndef OPENSSL_NO_ML_DSA - check: -#endif rv = SSL_check_chain(s, x509, pkey, chain); /* * If the cert doesn't show as valid here (e.g., because we don't @@ -10260,7 +9585,7 @@ static int test_cert_cb_int(int prot, int tst) int testresult = 0, ret; #ifdef OPENSSL_NO_EC - /* We use an EC cert in these tests with TLS 1.2 or absent ML-DSA */ + /* We use an EC cert in these tests, so we skip in a no-ec build */ if (tst >= 3) return 1; #endif @@ -10291,34 +9616,21 @@ static int test_cert_cb_int(int prot, int tst) NULL, NULL))) goto end; - if (tst == 3) { - if (!TEST_true(SSL_set1_sigalgs_list(clientssl, - "rsa_pss_rsae_sha256:rsa_pkcs1_sha256:" - "?ecdsa_secp256r1_sha256:?mldsa44")) - || !TEST_true(SSL_set1_sigalgs_list(serverssl, - "rsa_pss_rsae_sha256:rsa_pkcs1_sha256:" - "?ecdsa_secp256r1_sha256:?mldsa44"))) - goto end; - } else if (tst == 4) { + if (tst == 4) { /* * We cause SSL_check_chain() to fail by specifying sig_algs that - * the chain doesn't meet (root either RSA or ML-DSA). + * the chain doesn't meet (the root uses an RSA cert) */ if (!TEST_true(SSL_set1_sigalgs_list(clientssl, - "ecdsa_secp256r1_sha256")) - || !TEST_true(SSL_set1_sigalgs_list(serverssl, - "?ecdsa_secp256r1_sha256:?mldsa44"))) + "ecdsa_secp256r1_sha256"))) goto end; } else if (tst == 5) { /* * We cause SSL_check_chain() to fail by specifying sig_algs that - * the ee cert doesn't meet (the ee uses an ECDSA or ML-DSA cert) + * the ee cert doesn't meet (the ee uses an ECDSA cert) */ if (!TEST_true(SSL_set1_sigalgs_list(clientssl, - "rsa_pss_rsae_sha256:rsa_pkcs1_sha256")) - || !TEST_true(SSL_set1_sigalgs_list(serverssl, - "rsa_pss_rsae_sha256:rsa_pkcs1_sha256:" - "?ecdsa_secp256r1_sha256:?mldsa44"))) + "rsa_pss_rsae_sha256:rsa_pkcs1_sha256"))) goto end; } @@ -10612,8 +9924,8 @@ static int test_multiblock_write(int test_index) * i.e: write_len >= 4 * frag_size * 9 * is chosen so that multiple multiblocks are used + some leftover. */ - unsigned char msg[MULTIBLOCK_FRAGSIZE * 9] = { 0 }; - unsigned char buf[sizeof(msg)] = { 0 }, *p = buf; + unsigned char msg[MULTIBLOCK_FRAGSIZE * 9]; + unsigned char buf[sizeof(msg)], *p = buf; size_t readbytes, written, len; EVP_CIPHER *ciph = NULL; @@ -10813,8 +10125,6 @@ static int test_session_cache_overflow(int idx) int testresult = 0; SSL_SESSION *sess = NULL; - get_sess_val = NULL; - #ifdef OSSL_NO_USABLE_TLS1_3 /* If no TLSv1.3 available then do nothing in this case */ if (idx % 2 == 0) @@ -10884,7 +10194,7 @@ static int test_session_cache_overflow(int idx) * The session we just negotiated may have been already removed from the * internal cache - but we will return it anyway from our external cache. */ - get_sess_val = SSL_get1_session(serverssl); + get_sess_val = SSL_get_session(serverssl); if (!TEST_ptr(get_sess_val)) goto end; sess = SSL_get1_session(clientssl); @@ -10910,8 +10220,6 @@ static int test_session_cache_overflow(int idx) testresult = 1; end: - SSL_SESSION_free(get_sess_val); - get_sess_val = NULL; SSL_free(serverssl); SSL_free(clientssl); SSL_CTX_free(sctx); @@ -11195,9 +10503,7 @@ static int test_sigalgs_available(int idx) OSSL_LIB_CTX *clientctx = libctx, *serverctx = libctx; OSSL_PROVIDER *filterprov = NULL; int sig, hash, numshared, numshared_expected, hash_expected, sig_expected; - unsigned char rsig, rhash; - unsigned int sigalg, csigalg_expected; - const char *sigalg_name, *signame_expected, *csigname_expected; + const char *sigalg_name, *signame_expected; if (!TEST_ptr(tmpctx)) goto end; @@ -11317,30 +10623,20 @@ static int test_sigalgs_available(int idx) /* For tests 0 and 3 we expect 2 shared sigalgs, otherwise exactly 1 */ numshared = SSL_get_shared_sigalgs(serverssl, 0, &sig, &hash, - NULL, &rsig, &rhash); + NULL, NULL, NULL); numshared_expected = 1; hash_expected = NID_sha256; sig_expected = NID_rsassaPss; signame_expected = "rsa_pss_rsae_sha256"; - csigname_expected = "rsa_pss_rsae_sha256"; - csigalg_expected = 0x0804; switch (idx) { case 0: - signame_expected = "rsa_pss_rsae_sha384"; hash_expected = NID_sha384; - numshared_expected = 2; + signame_expected = "rsa_pss_rsae_sha384"; /* FALLTHROUGH */ - case 2: - csigname_expected = "rsa_pss_rsae_sha384"; - csigalg_expected = 0x0805; - break; case 3: numshared_expected = 2; break; case 4: - csigname_expected = "ecdsa_secp256r1_sha256"; - csigalg_expected = 0x0403; - /* FALLTHROUGH */ case 5: sig_expected = EVP_PKEY_EC; signame_expected = "ecdsa_secp256r1_sha256"; @@ -11351,13 +10647,7 @@ static int test_sigalgs_available(int idx) || !TEST_int_eq(sig, sig_expected) || !TEST_true(SSL_get0_peer_signature_name(clientssl, &sigalg_name)) || !TEST_ptr(sigalg_name) - || !TEST_str_eq(sigalg_name, signame_expected) - || !TEST_int_gt(SSL_get0_shared_sigalg(serverssl, 0, &sigalg, &sigalg_name), 0) - || !TEST_int_eq(sigalg, (((int)rhash) << 8) | rsig) - || !TEST_str_eq(sigalg_name, signame_expected) - || !TEST_int_gt(SSL_get0_sigalg(serverssl, 0, &sigalg, &sigalg_name), 0) - || !TEST_int_eq(sigalg, csigalg_expected) - || !TEST_str_eq(sigalg_name, csigname_expected)) + || !TEST_str_eq(sigalg_name, signame_expected)) goto end; testresult = filter_provider_check_clean_finish(); @@ -11455,14 +10745,13 @@ static int create_cert_key(int idx, char *certfilename, char *privkeyfilename) || !TEST_true(X509_gmtime_adj(X509_getm_notBefore(x509), 0)) || !TEST_true(X509_gmtime_adj(X509_getm_notAfter(x509), 31536000L)) || !TEST_true(X509_set_pubkey(x509, pkey)) - || !TEST_ptr(name = X509_NAME_new()) + || !TEST_ptr(name = X509_get_subject_name(x509)) || !TEST_true(X509_NAME_add_entry_by_txt(name, "C", MBSTRING_ASC, (unsigned char *)"CH", -1, -1, 0)) || !TEST_true(X509_NAME_add_entry_by_txt(name, "O", MBSTRING_ASC, (unsigned char *)"test.org", -1, -1, 0)) || !TEST_true(X509_NAME_add_entry_by_txt(name, "CN", MBSTRING_ASC, (unsigned char *)"localhost", -1, -1, 0)) - || !TEST_true(X509_set_subject_name(x509, name)) || !TEST_true(X509_set_issuer_name(x509, name)) || !TEST_true(X509_sign(x509, pkey, EVP_sha1())) || !TEST_ptr(keybio = BIO_new_file(privkeyfilename, "wb")) @@ -11473,7 +10762,6 @@ static int create_cert_key(int idx, char *certfilename, char *privkeyfilename) EVP_PKEY_free(pkey); X509_free(x509); - X509_NAME_free(name); EVP_PKEY_CTX_free(evpctx); BIO_free(keybio); BIO_free(certbio); @@ -11625,8 +10913,7 @@ static int test_ssl_dup(void) client2ssl = SSL_dup(clientssl); rbio = SSL_get_rbio(clientssl); if (!TEST_ptr(rbio) - || !TEST_true(BIO_up_ref(rbio)) - || !TEST_ptr(client2ssl)) + || !TEST_true(BIO_up_ref(rbio))) goto end; SSL_set0_rbio(client2ssl, rbio); rbio = NULL; @@ -11687,13 +10974,11 @@ static int secret_cb(SSL *s, void *secretin, int *secret_len, /* * Test the session_secret_cb which is designed for use with EAP-FAST */ -static int test_session_secret_cb(int idx) +static int test_session_secret_cb(void) { SSL_CTX *cctx = NULL, *sctx = NULL; SSL *clientssl = NULL, *serverssl = NULL; - SSL_SESSION *secret_sess = NULL, *server_sess = NULL; - unsigned int sess_len; - const unsigned char *sessid; + SSL_SESSION *secret_sess = NULL; int testresult = 0; if (!TEST_true(create_ssl_ctx_pair(libctx, TLS_server_method(), @@ -11727,20 +11012,12 @@ static int test_session_secret_cb(int idx) NULL, NULL))) goto end; - if (idx == 0) { - /* - * Normal case: no session id - */ - if (!TEST_true(SSL_SESSION_set1_id(secret_sess, NULL, 0))) - goto end; - } else { - /* - * Set an explicit session id. Normally we don't support this, but we - * can get away with it if we reset the session id later - */ - if (!TEST_true(SSL_SESSION_set1_id(secret_sess, (unsigned char *)"sessionid", 9))) - goto end; - } + /* + * No session ids for EAP-FAST - otherwise the state machine gets very + * confused. + */ + if (!TEST_true(SSL_SESSION_set1_id(secret_sess, NULL, 0))) + goto end; if (!TEST_true(SSL_set_min_proto_version(clientssl, TLS1_2_VERSION)) || !TEST_true(SSL_set_max_proto_version(serverssl, TLS1_2_VERSION)) @@ -11751,39 +11028,13 @@ static int test_session_secret_cb(int idx) || !TEST_true(SSL_set_session(clientssl, secret_sess))) goto end; - if (idx == 1) { - /* - * We just send the ClientHello here. We expect this to fail with - * SSL_ERROR_WANT_READ - */ - if (!TEST_int_le(SSL_connect(clientssl), 0)) - goto end; - /* Reset the session id to avoid confusing the state machine */ - if (!TEST_true(SSL_SESSION_set1_id(secret_sess, NULL, 0))) - goto end; - } if (!TEST_true(create_ssl_connection(serverssl, clientssl, SSL_ERROR_NONE))) goto end; - /* Check that session resumption was successful */ - if (!TEST_true(SSL_session_reused(clientssl)) - || !TEST_true(SSL_session_reused(serverssl))) - goto end; - - if (idx == 1) { - server_sess = SSL_get1_session(serverssl); - if (!TEST_ptr(server_sess)) - goto end; - sessid = SSL_SESSION_get_id(server_sess, &sess_len); - - if (!TEST_mem_eq(sessid, sess_len, "sessionid", 9)) - goto end; - } testresult = 1; end: SSL_SESSION_free(secret_sess); - SSL_SESSION_free(server_sess); SSL_free(serverssl); SSL_free(clientssl); SSL_CTX_free(sctx); @@ -11905,11 +11156,6 @@ static int test_set_tmp_dh(int idx) return 1; #endif - OSSL_PROVIDER *tlsprov = OSSL_PROVIDER_load(libctx, "tls-provider"); - - if (!TEST_ptr(tlsprov)) - goto end; - if (idx >= 5 && idx <= 8) { dhpkey = get_tmp_dh_params(); if (!TEST_ptr(dhpkey)) @@ -11973,9 +11219,7 @@ static int test_set_tmp_dh(int idx) if (!TEST_true(SSL_set_min_proto_version(serverssl, TLS1_2_VERSION)) || !TEST_true(SSL_set_max_proto_version(serverssl, TLS1_2_VERSION)) - || !TEST_true(SSL_set_cipher_list(serverssl, "DHE-RSA-AES128-SHA")) - /* This is required so the server does not use RFC7919 groups */ - || !TEST_true(SSL_set1_groups_list(clientssl, "xorgroup"))) + || !TEST_true(SSL_set_cipher_list(serverssl, "DHE-RSA-AES128-SHA"))) goto end; /* @@ -11998,7 +11242,6 @@ end: SSL_CTX_free(sctx); SSL_CTX_free(cctx); EVP_PKEY_free(dhpkey); - OSSL_PROVIDER_unload(tlsprov); return testresult; } @@ -12008,7 +11251,6 @@ end: */ static int test_dh_auto(int idx) { - OSSL_PROVIDER *tlsprov = OSSL_PROVIDER_load(libctx, "tls-provider"); SSL_CTX *cctx = SSL_CTX_new_ex(libctx, NULL, TLS_client_method()); SSL_CTX *sctx = SSL_CTX_new_ex(libctx, NULL, TLS_server_method()); SSL *clientssl = NULL, *serverssl = NULL; @@ -12016,10 +11258,7 @@ static int test_dh_auto(int idx) EVP_PKEY *tmpkey = NULL; char *thiscert = NULL, *thiskey = NULL; size_t expdhsize = 0; - const char *ciphersuite = "dhe-rsa-aes128-sha"; - - if (!TEST_ptr(tlsprov)) - goto end; + const char *ciphersuite = "DHE-RSA-AES128-SHA"; if (!TEST_ptr(sctx) || !TEST_ptr(cctx)) goto end; @@ -12065,11 +11304,11 @@ static int test_dh_auto(int idx) testresult = 1; goto end; } - ciphersuite = "adh-aes128-sha256:@seclevel=0"; + ciphersuite = "ADH-AES128-SHA256:@SECLEVEL=0"; expdhsize = 1024; break; case 6: - ciphersuite = "adh-aes256-sha256:@seclevel=0"; + ciphersuite = "ADH-AES256-SHA256:@SECLEVEL=0"; expdhsize = 3072; break; default: @@ -12092,9 +11331,7 @@ static int test_dh_auto(int idx) || !TEST_true(SSL_set_min_proto_version(serverssl, TLS1_2_VERSION)) || !TEST_true(SSL_set_max_proto_version(serverssl, TLS1_2_VERSION)) || !TEST_true(SSL_set_cipher_list(serverssl, ciphersuite)) - || !TEST_true(SSL_set_cipher_list(clientssl, ciphersuite)) - /* This is required so the server does not use RFC7919 groups */ - || !TEST_true(SSL_set1_groups_list(clientssl, "xorgroup"))) + || !TEST_true(SSL_set_cipher_list(clientssl, ciphersuite))) goto end; /* @@ -12122,231 +11359,9 @@ end: SSL_CTX_free(sctx); SSL_CTX_free(cctx); EVP_PKEY_free(tmpkey); - OSSL_PROVIDER_unload(tlsprov); return testresult; } - -/* - * Test the server will reject FFDHE ciphersuites if no supported FFDHE group is - * advertised by the client. - */ -static int test_no_shared_ffdhe_group(int idx) -{ - SSL_CTX *cctx = SSL_CTX_new_ex(libctx, NULL, TLS_client_method()); - SSL_CTX *sctx = SSL_CTX_new_ex(libctx, NULL, TLS_server_method()); - SSL *clientssl = NULL, *serverssl = NULL; - int testresult = 0, ret, expected = 1; - char *clientgroup = NULL, *servergroup = NULL, *ciphersuite = NULL; - int want_error = SSL_ERROR_NONE; - - if (!TEST_ptr(sctx) || !TEST_ptr(cctx)) - goto end; - - switch (idx) { - case 0: - clientgroup = "ffdhe2048"; - servergroup = "ffdhe3072"; - ciphersuite = "dhe-rsa-aes128-sha256:aes128-sha256"; - break; - case 1: - clientgroup = "ffdhe3072"; - servergroup = "ffdhe4096"; - ciphersuite = "dhe-rsa-aes128-sha256:aes128-sha256"; - break; - case 2: - clientgroup = "ffdhe4096"; - servergroup = "ffdhe6144"; - ciphersuite = "dhe-rsa-aes128-sha256:aes128-sha256"; - break; - case 3: - clientgroup = "ffdhe6144"; - servergroup = "ffdhe8192"; - ciphersuite = "dhe-rsa-aes128-sha256:aes128-sha256"; - break; - case 4: - clientgroup = "ffdhe8192"; - servergroup = "ffdhe2048"; - ciphersuite = "dhe-rsa-aes128-sha256:aes128-sha256"; - break; - case 5: - clientgroup = "ffdhe2048"; - servergroup = "ffdhe3072"; - ciphersuite = "dhe-rsa-aes128-sha256"; - expected = 0; - want_error = SSL_ERROR_SSL; - break; - case 6: - clientgroup = "ffdhe3072"; - servergroup = "ffdhe4096"; - ciphersuite = "dhe-rsa-aes128-sha256"; - expected = 0; - want_error = SSL_ERROR_SSL; - break; - case 7: - clientgroup = "ffdhe4096"; - servergroup = "ffdhe6144"; - ciphersuite = "dhe-rsa-aes128-sha256"; - expected = 0; - want_error = SSL_ERROR_SSL; - break; - case 8: - clientgroup = "ffdhe6144"; - servergroup = "ffdhe8192"; - ciphersuite = "dhe-rsa-aes128-sha256"; - expected = 0; - want_error = SSL_ERROR_SSL; - break; - case 9: - clientgroup = "ffdhe8192"; - servergroup = "ffdhe2048"; - ciphersuite = "dhe-rsa-aes128-sha256"; - expected = 0; - want_error = SSL_ERROR_SSL; - break; - default: - TEST_error("Invalid text index"); - goto end; - } - - if (!TEST_true(create_ssl_ctx_pair(libctx, NULL, - NULL, - 0, - 0, - &sctx, &cctx, cert, privkey))) - goto end; - - if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, &clientssl, - NULL, NULL))) - goto end; - - if (!TEST_true(SSL_set_dh_auto(serverssl, 1)) - || !TEST_true(SSL_set_min_proto_version(serverssl, TLS1_2_VERSION)) - || !TEST_true(SSL_set_max_proto_version(serverssl, TLS1_2_VERSION)) - || !TEST_true(SSL_set_cipher_list(serverssl, ciphersuite)) - || !TEST_true(SSL_set_cipher_list(clientssl, ciphersuite)) - || !TEST_true(SSL_set1_groups_list(serverssl, servergroup)) - || !TEST_true(SSL_set1_groups_list(clientssl, clientgroup))) - goto end; - - ret = create_ssl_connection(serverssl, clientssl, want_error); - if (!TEST_int_eq(expected, ret)) - goto end; - - if (expected <= 0) { - testresult = 1; - goto end; - } - - /* - * Note that the server should not select the DHE ciphersuite if there are - * no shared FFDHE groups, so if it was selected, that is an error. - */ - if (!TEST_int_ne(TLS1_CK_DHE_RSA_WITH_AES_128_SHA256, - SSL_CIPHER_get_id(SSL_get_current_cipher(clientssl)))) - goto end; - - testresult = 1; - -end: - SSL_free(serverssl); - SSL_free(clientssl); - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - - return testresult; -} - -/* - * Test the server will use the supported FFDHE group advertised by the client. - */ -static int test_shared_ffdhe_group(int idx) -{ - SSL_CTX *cctx = SSL_CTX_new_ex(libctx, NULL, TLS_client_method()); - SSL_CTX *sctx = SSL_CTX_new_ex(libctx, NULL, TLS_server_method()); - SSL *clientssl = NULL, *serverssl = NULL; - int testresult = 0; - EVP_PKEY *tmpkey = NULL; - char *servergroups = "ffdhe2048:ffdhe3072:ffdhe4096:ffdhe6144:ffdhe8192"; - char *clientgroup = NULL; - const char *ciphersuite = "DHE-RSA-AES128-SHA256"; - char gname[10]; - size_t gname_len; - - if (!TEST_ptr(sctx) || !TEST_ptr(cctx)) - goto end; - - switch (idx) { - case 0: - clientgroup = "ffdhe2048"; - break; - case 1: - clientgroup = "ffdhe3072"; - break; - case 2: - clientgroup = "ffdhe4096"; - break; - case 3: - clientgroup = "ffdhe6144"; - break; - case 4: - clientgroup = "ffdhe8192"; - break; - default: - TEST_error("Invalid text index"); - goto end; - } - - if (!TEST_true(create_ssl_ctx_pair(libctx, NULL, - NULL, - 0, - 0, - &sctx, &cctx, cert, privkey))) - goto end; - - if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, &clientssl, - NULL, NULL))) - goto end; - - if (!TEST_true(SSL_set_dh_auto(serverssl, 1)) - || !TEST_true(SSL_set_min_proto_version(serverssl, TLS1_2_VERSION)) - || !TEST_true(SSL_set_max_proto_version(serverssl, TLS1_2_VERSION)) - || !TEST_true(SSL_set_cipher_list(serverssl, ciphersuite)) - || !TEST_true(SSL_set_cipher_list(clientssl, ciphersuite)) - || !TEST_true(SSL_set1_groups_list(serverssl, servergroups)) - || !TEST_true(SSL_set1_groups_list(clientssl, clientgroup))) - goto end; - - /* - * Send the server's first flight. At this point the server has created the - * temporary DH key but hasn't finished using it yet. Once used it is - * removed, so we cannot test it. - */ - if (!TEST_int_le(SSL_connect(clientssl), 0) - || !TEST_int_le(SSL_accept(serverssl), 0)) - goto end; - - if (!TEST_int_gt(SSL_get_tmp_key(serverssl, &tmpkey), 0)) - goto end; - if (!TEST_true(EVP_PKEY_get_group_name(tmpkey, gname, sizeof(gname), &gname_len)) - || !TEST_str_eq(gname, clientgroup)) - goto end; - - if (!TEST_true(create_ssl_connection(serverssl, clientssl, SSL_ERROR_NONE))) - goto end; - - testresult = 1; - -end: - SSL_free(serverssl); - SSL_free(clientssl); - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - EVP_PKEY_free(tmpkey); - - return testresult; -} - #endif /* OPENSSL_NO_DH */ #endif /* OPENSSL_NO_TLS1_2 */ @@ -12539,57 +11554,6 @@ end: return testresult; } -static int test_get_alpn(void) -{ - SSL_CTX *ctx = NULL; - SSL *ssl = NULL; - int testresult = 0; - unsigned char good[] = { 0x04, 'g', 'o', 'o', 'd' }; - const unsigned char *expect; - unsigned int expect_len; - - /* Create an initial SSL_CTX with no certificate configured */ - ctx = SSL_CTX_new_ex(libctx, NULL, TLS_server_method()); - if (!TEST_ptr(ctx)) - goto end; - - SSL_CTX_get0_alpn_protos(NULL, &expect, &expect_len); - if (!TEST_ptr_null(expect)) - goto end; - if (!TEST_int_eq(expect_len, 0)) - goto end; - if (!TEST_false(SSL_CTX_set_alpn_protos(ctx, good, sizeof(good)))) - goto end; - - SSL_CTX_get0_alpn_protos(ctx, &expect, &expect_len); - if (!TEST_mem_eq(expect, expect_len, good, sizeof(good))) - goto end; - - ssl = SSL_new(ctx); - if (!TEST_ptr(ssl)) - goto end; - - SSL_get0_alpn_protos(NULL, &expect, &expect_len); - if (!TEST_ptr_null(expect)) - goto end; - if (!TEST_int_eq(expect_len, 0)) - goto end; - - if (!TEST_false(SSL_set_alpn_protos(ssl, good, sizeof(good)))) - goto end; - - SSL_get0_alpn_protos(ssl, &expect, &expect_len); - if (!TEST_mem_eq(expect, expect_len, good, sizeof(good))) - goto end; - - testresult = 1; - -end: - SSL_free(ssl); - SSL_CTX_free(ctx); - return testresult; -} - #if !defined(OPENSSL_NO_EC) && !defined(OPENSSL_NO_TLS1_2) /* * Complete a connection with legacy EC point format configuration @@ -12598,7 +11562,7 @@ static int test_legacy_ec_point_formats(void) { SSL_CTX *cctx = NULL, *sctx = NULL; SSL *clientssl = NULL, *serverssl = NULL; - const unsigned char *pformats = NULL; + const char *pformats = NULL; int nformats; int testresult = 0; @@ -13079,51 +12043,6 @@ end: SSL_CTX_free(cctx); return testresult; } - -static int un_ext_add_cb(SSL *s, unsigned int ext_type, - unsigned int context, const unsigned char **out, size_t *outlen, X509 *x, - size_t chainidx, int *al, void *add_arg) -{ - static const unsigned char data[] = { 0xaa }; - *out = data; - *outlen = sizeof(data); - return 1; -} - -static int un_ext_parse_cb(SSL *s, unsigned int ext_type, - unsigned int context, const unsigned char *in, size_t inlen, X509 *x, - size_t chainidx, int *al, void *parse_arg) -{ - return 1; -} - -/* - * Test that a handshake succeeds when the peer sends an extension type we do - * not recognise. The client registers a custom extension in its ClientHello - * that the server knows nothing about, so on the server tls_collect_extensions() - * takes the "unknown extension" branch. - */ -static int test_tls13_unknown_extension(void) -{ - SSL_CTX *s = NULL, *c = NULL; - SSL *s_ssl = NULL, *c_ssl = NULL; - int test; - - test = TEST_true(create_ssl_ctx_pair(libctx, TLS_server_method(), - TLS_client_method(), TLS1_3_VERSION, TLS1_3_VERSION, &s, &c, cert, privkey)) - && TEST_true(SSL_CTX_add_custom_ext(c, 0xfefe, SSL_EXT_CLIENT_HELLO, - un_ext_add_cb, NULL, NULL, un_ext_parse_cb, NULL)) - && TEST_true(create_ssl_objects(s, c, &s_ssl, &c_ssl, NULL, NULL)) - /* The server must tolerate the unknown extension and complete. */ - && TEST_true(create_ssl_connection(s_ssl, c_ssl, SSL_ERROR_NONE)); - - SSL_free(s_ssl); - SSL_free(c_ssl); - SSL_CTX_free(s); - SSL_CTX_free(c); - return test; -} - #endif /* OSSL_NO_USABLE_TLS1_3 */ static int check_version_string(SSL *s, int version) @@ -13131,6 +12050,9 @@ static int check_version_string(SSL *s, int version) const char *verstr = NULL; switch (version) { + case SSL3_VERSION: + verstr = "SSLv3"; + break; case TLS1_VERSION: verstr = "TLSv1"; break; @@ -13168,6 +12090,11 @@ static int test_version(int idx) const SSL_METHOD *clientmeth = TLS_client_method(); switch (idx) { +#if !defined(OPENSSL_NO_SSL3) + case 0: + version = SSL3_VERSION; + break; +#endif #if !defined(OPENSSL_NO_TLS1) case 1: version = TLS1_VERSION; @@ -13204,7 +12131,8 @@ static int test_version(int idx) } if (is_fips - && (version == TLS1_VERSION + && (version == SSL3_VERSION + || version == TLS1_VERSION || version == DTLS1_VERSION)) { TEST_skip("Protocol version not supported with FIPS"); return 1; @@ -13221,9 +12149,9 @@ static int test_version(int idx) version, &sctx, &cctx, cert, privkey))) goto end; - if (!TEST_true(SSL_CTX_set_cipher_list(sctx, "default:@SECLEVEL=0")) + if (!TEST_true(SSL_CTX_set_cipher_list(sctx, "DEFAULT:@SECLEVEL=0")) || !TEST_true(SSL_CTX_set_cipher_list(cctx, - "DEFAULT:@seclevel=0"))) + "DEFAULT:@SECLEVEL=0"))) goto end; if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, @@ -13266,34 +12194,6 @@ end: return testresult; } -/* - * Test that SSL_CTX_is_server returns the expected results. - */ -static int test_ssl_ctx_is_server(void) -{ - int testresult = 0; - SSL_CTX *cctx = NULL, *sctx = NULL, *gctx = NULL; - - cctx = SSL_CTX_new_ex(libctx, NULL, TLS_client_method()); - sctx = SSL_CTX_new_ex(libctx, NULL, TLS_server_method()); - gctx = SSL_CTX_new_ex(libctx, NULL, TLS_method()); - - if (!TEST_ptr(cctx) || !TEST_ptr(sctx) || !TEST_ptr(gctx)) - goto end; - - if (!TEST_false(SSL_CTX_is_server(cctx)) - || !TEST_true(SSL_CTX_is_server(sctx)) - || !TEST_true(SSL_CTX_is_server(gctx))) - goto end; - - testresult = 1; -end: - SSL_CTX_free(cctx); - SSL_CTX_free(sctx); - SSL_CTX_free(gctx); - return testresult; -} - /* * Test that the SSL_rstate_string*() APIs return sane results */ @@ -14189,9 +13089,9 @@ static int check_secret_history(SSL *s) * write case * NOTE: There is an odd corner case here. It may occur that * in a single iteration of the state machine, the read key is yielded - * prior to the write key for the same level. This is undesirable + * prior to the write key for the same level. This is undesireable * for quic, but it is ok, as the general implementation of every 3rd - * party quic stack while preferring write keys before read, allows + * party quic stack while prefering write keys before read, allows * for read before write if both keys are yielded in the same call * to SSL_do_handshake, as the tls adaptation code for that quic stack * can then cache keys until both are available, so we allow read before @@ -14324,42 +13224,6 @@ static int alert_cb(SSL *s, unsigned char alert_code, void *arg) return 1; } -/* Extension id reserved for private use by IANA */ -#define TEST_TLS_EXTENSION_ID 65282 - -static int add_ext_cb_called = 0; -static int parse_ext_cb_called = 0; - -static int add_old_ext(SSL *s, unsigned int ext_type, - const unsigned char **out, size_t *outlen, - int *al, void *add_arg) -{ - static const unsigned char data = 0xff; - - add_ext_cb_called++; - *out = &data; - *outlen = 1; - return 1; -} - -static void free_old_ext(SSL *s, unsigned int ext_type, - const unsigned char *out, void *add_arg) -{ - /* Do nothing */ -} - -static int parse_old_ext(SSL *s, unsigned int ext_type, - const unsigned char *in, size_t inlen, - int *al, void *parse_arg) -{ - parse_ext_cb_called++; - if (inlen != 1 || *in != 0xff) { - *al = SSL_AD_DECODE_ERROR; - return 0; - } - return 1; -} - /* * Test the QUIC TLS API * Test 0: Normal run @@ -14414,32 +13278,11 @@ static int test_quic_tls(int idx) goto end; if (idx == 5) { - static int dummy = 1; - if (!TEST_true(create_ssl_ctx_pair(libctx, TLS_server_method(), NULL, TLS1_3_VERSION, 0, &sctx2, NULL, cert, privkey))) goto end; - /* - * We add an old style custom extension to ensure that it gets correctly - * handled when we copy QUIC's connection specific custom extensions. - */ - add_ext_cb_called = 0; - parse_ext_cb_called = 0; - if (!TEST_true(SSL_CTX_add_client_custom_ext(cctx, - TEST_TLS_EXTENSION_ID, - add_old_ext, free_old_ext, &dummy, parse_old_ext, &dummy))) - goto end; - if (!TEST_true(SSL_CTX_add_server_custom_ext(sctx, - TEST_TLS_EXTENSION_ID, - add_old_ext, free_old_ext, &dummy, parse_old_ext, &dummy))) - goto end; - if (!TEST_true(SSL_CTX_add_server_custom_ext(sctx2, - TEST_TLS_EXTENSION_ID, - add_old_ext, free_old_ext, &dummy, parse_old_ext, &dummy))) - goto end; - /* Set up SNI */ if (!TEST_true(SSL_CTX_set_tlsext_servername_callback(sctx, sni_cb)) || !TEST_true(SSL_CTX_set_tlsext_servername_arg(sctx, sctx2))) @@ -14529,18 +13372,6 @@ static int test_quic_tls(int idx) || !TEST_true(cdata.wenc_level == OSSL_RECORD_PROTECTION_LEVEL_APPLICATION)) goto end; - /* - * We only expect the add cb to have actually been called because we are - * using the old style callbacks that only apply to TLSv1.2. Since we are - * using TLSv1.3 here, the add will be called for the ClientHello but - * nothing else. - */ - if (idx == 5) { - if (!TEST_int_eq(add_ext_cb_called, 1) - || !TEST_int_eq(parse_ext_cb_called, 0)) - goto end; - } - testresult = 1; end: SSL_free(serverssl); @@ -14873,287 +13704,6 @@ err: } #endif -#if !defined(OSSL_NO_USABLE_TLS1_3) -/* - * RFC 8701 GREASE test helpers. - * We capture the raw ClientHello via msg_callback and then parse it with - * PACKET functions to confirm that GREASE values (matching 0x?A?A) are - * present in the expected fields. - */ -static unsigned char *grease_ch_buf; -static size_t grease_ch_len; - -static int is_grease(unsigned int v) -{ - return (v & 0x0f0f) == 0x0a0a && (v >> 8) == (v & 0xff); -} - -static void grease_msg_cb(int write_p, int version, int content_type, - const void *buf, size_t len, SSL *ssl, void *arg) -{ - const unsigned char *p = buf; - - /* - * We want the outgoing (write_p == 1) handshake (content_type == 22) - * ClientHello (msg_type == 1). The buf starts at the handshake header: - * byte 0: msg_type, bytes 1-3: length - */ - if (write_p != 1 || content_type != SSL3_RT_HANDSHAKE - || len < SSL3_HM_HEADER_LENGTH - || p[0] != SSL3_MT_CLIENT_HELLO) - return; - - /* Only capture the first ClientHello (not HRR retry) */ - if (grease_ch_buf != NULL) - return; - - grease_ch_buf = OPENSSL_memdup(buf, len); - grease_ch_len = len; -} - -/* - * Parse a captured ClientHello (starting from handshake header) and check - * that it contains GREASE values in cipher suites, extensions, supported - * groups, key shares, and signature algorithms. - * Returns 1 on success, 0 on failure. - */ -static int check_grease_in_client_hello(void) -{ - PACKET pkt, ciphers, session, compression, exts, ext_data; - PACKET inner; - unsigned int ext_type = 0, val = 0; - int found_grease_cipher = 0; - int found_grease_ext = 0; - int found_grease_group = 0; - int found_grease_kshare = 0; - int found_grease_sigalg = 0; - int found_grease_version = 0; - - memset(&pkt, 0, sizeof(pkt)); - memset(&ciphers, 0, sizeof(ciphers)); - memset(&session, 0, sizeof(session)); - memset(&compression, 0, sizeof(compression)); - memset(&exts, 0, sizeof(exts)); - memset(&ext_data, 0, sizeof(ext_data)); - memset(&inner, 0, sizeof(inner)); - - if (!TEST_ptr(grease_ch_buf) - || !TEST_true(PACKET_buf_init(&pkt, grease_ch_buf, - grease_ch_len)) - /* Skip handshake message header */ - || !TEST_true(PACKET_forward(&pkt, SSL3_HM_HEADER_LENGTH)) - /* Skip client_version + random */ - || !TEST_true(PACKET_forward(&pkt, - CLIENT_VERSION_LEN + SSL3_RANDOM_SIZE)) - /* Skip session_id */ - || !TEST_true(PACKET_get_length_prefixed_1(&pkt, &session)) - /* Get cipher suites */ - || !TEST_true(PACKET_get_length_prefixed_2(&pkt, &ciphers)) - /* Skip compression */ - || !TEST_true(PACKET_get_length_prefixed_1(&pkt, &compression)) - /* Get extensions */ - || !TEST_true(PACKET_as_length_prefixed_2(&pkt, &exts))) - return 0; - - /* Scan cipher suites for GREASE */ - while (PACKET_remaining(&ciphers) > 0) { - if (!TEST_true(PACKET_get_net_2(&ciphers, &val))) - return 0; - if (is_grease(val)) - found_grease_cipher = 1; - } - - /* Scan extensions */ - while (PACKET_remaining(&exts) > 0) { - if (!TEST_true(PACKET_get_net_2(&exts, &ext_type)) - || !TEST_true(PACKET_get_length_prefixed_2(&exts, - &ext_data))) - return 0; - - if (is_grease(ext_type)) - found_grease_ext++; - - /* Check for GREASE inside supported_versions */ - if (ext_type == TLSEXT_TYPE_supported_versions) { - if (!TEST_true(PACKET_get_length_prefixed_1(&ext_data, - &inner))) - return 0; - while (PACKET_remaining(&inner) > 0) { - if (!TEST_true(PACKET_get_net_2(&inner, &val))) - return 0; - if (is_grease(val)) - found_grease_version = 1; - } - } - - /* Check for GREASE inside supported_groups */ - if (ext_type == TLSEXT_TYPE_supported_groups) { - if (!TEST_true(PACKET_get_length_prefixed_2(&ext_data, - &inner))) - return 0; - while (PACKET_remaining(&inner) > 0) { - if (!TEST_true(PACKET_get_net_2(&inner, &val))) - return 0; - if (is_grease(val)) - found_grease_group = 1; - } - } - - /* Check for GREASE inside key_share */ - if (ext_type == TLSEXT_TYPE_key_share) { - PACKET ks_entry; - - memset(&ks_entry, 0, sizeof(ks_entry)); - if (!TEST_true(PACKET_get_length_prefixed_2(&ext_data, - &inner))) - return 0; - while (PACKET_remaining(&inner) > 0) { - if (!TEST_true(PACKET_get_net_2(&inner, &val)) - || !TEST_true(PACKET_get_length_prefixed_2( - &inner, &ks_entry))) - return 0; - if (is_grease(val)) - found_grease_kshare = 1; - } - } - - /* Check for GREASE inside signature_algorithms */ - if (ext_type == TLSEXT_TYPE_signature_algorithms) { - if (!TEST_true(PACKET_get_length_prefixed_2(&ext_data, - &inner))) - return 0; - while (PACKET_remaining(&inner) > 0) { - if (!TEST_true(PACKET_get_net_2(&inner, &val))) - return 0; - if (is_grease(val)) - found_grease_sigalg = 1; - } - } - } - - if (!TEST_true(found_grease_cipher)) - return 0; - if (!TEST_int_eq(found_grease_ext, 2)) - return 0; - if (!TEST_true(found_grease_version)) - return 0; - if (!TEST_true(found_grease_group)) - return 0; - if (!TEST_true(found_grease_kshare)) - return 0; - if (!TEST_true(found_grease_sigalg)) - return 0; - - return 1; -} - -static int test_grease(void) -{ - SSL_CTX *sctx = NULL, *cctx = NULL; - SSL *serverssl = NULL, *clientssl = NULL; - int testresult = 0; - - grease_ch_buf = NULL; - grease_ch_len = 0; - - if (!TEST_true(create_ssl_ctx_pair(libctx, TLS_server_method(), - TLS_client_method(), - TLS1_3_VERSION, TLS1_3_VERSION, - &sctx, &cctx, cert, privkey))) - goto end; - - SSL_CTX_set_options(cctx, SSL_OP_GREASE); - - if (!TEST_true(create_ssl_objects(sctx, cctx, &serverssl, - &clientssl, NULL, NULL))) - goto end; - - SSL_set_msg_callback(clientssl, grease_msg_cb); - - /* A full handshake should succeed - server must tolerate GREASE */ - if (!TEST_true(create_ssl_connection(serverssl, clientssl, - SSL_ERROR_NONE))) - goto end; - - /* Now verify the captured ClientHello contains GREASE values */ - if (!TEST_true(check_grease_in_client_hello())) - goto end; - - testresult = 1; - -end: - OPENSSL_free(grease_ch_buf); - grease_ch_buf = NULL; - grease_ch_len = 0; - SSL_free(serverssl); - SSL_free(clientssl); - SSL_CTX_free(sctx); - SSL_CTX_free(cctx); - - return testresult; -} -#endif /* !defined(OSSL_NO_USABLE_TLS1_3) */ - -static int test_ssl_conf_flags(void) -{ - SSL_CONF_CTX *cctx = NULL; - int ret = 0; - - if (!TEST_ptr(cctx = SSL_CONF_CTX_new())) - goto err; - - /* Initial flags should be 0 */ - if (!TEST_uint_eq(SSL_CONF_CTX_set_flags(cctx, 0), 0)) - goto err; - - /* Setting CMDLINE should succeed */ - if (!TEST_uint_eq(SSL_CONF_CTX_set_flags(cctx, SSL_CONF_FLAG_CMDLINE), - SSL_CONF_FLAG_CMDLINE)) - goto err; - - /* - * Setting FILE when CMDLINE is set should fail to set the flag but return - * success (return the original flags value). - * If we also try to set a non-conflicting flag at the same time it should - * succeed. - */ - if (!TEST_uint_eq(SSL_CONF_CTX_set_flags(cctx, - SSL_CONF_FLAG_FILE - | SSL_CONF_FLAG_SHOW_ERRORS), - SSL_CONF_FLAG_CMDLINE | SSL_CONF_FLAG_SHOW_ERRORS)) - goto err; - - SSL_CONF_CTX_free(cctx); - cctx = NULL; - - /* Retry in reverse */ - if (!TEST_ptr(cctx = SSL_CONF_CTX_new())) - goto err; - - /* Setting FILE should succeed */ - if (!TEST_uint_eq(SSL_CONF_CTX_set_flags(cctx, SSL_CONF_FLAG_FILE), - SSL_CONF_FLAG_FILE)) - goto err; - - /* - * Setting CMDLINE when FILE is set should fail to set the flag but return - * success (return the original flags value) - * If we also try to set a non-conflicting flag at the same time it should - * succeed. - */ - if (!TEST_uint_eq(SSL_CONF_CTX_set_flags(cctx, - SSL_CONF_FLAG_CMDLINE - | SSL_CONF_FLAG_SHOW_ERRORS), - SSL_CONF_FLAG_FILE | SSL_CONF_FLAG_SHOW_ERRORS)) - goto err; - - ret = 1; - -err: - SSL_CONF_CTX_free(cctx); - return ret; -} - /* * Test that SSL_CTX_set1_groups() when called with a list where the first * entry is unsupported, will send a key_share that uses the next usable entry. @@ -15216,52 +13766,6 @@ end: #endif /* !defined(OPENSSL_NO_EC) || !defined(OPENSSL_NO_DH) */ } -/* - * Test that if we attempt to send HTTP to a TLS server that we get the expected - * failure reason code. - */ -static int test_http_verbs(int idx) -{ - SSL_CTX *sctx = NULL; - SSL *serverssl = NULL; - int testresult = 0; - const char *verbs[] = { "GET", "POST", "HEAD" }; - const char *http_trailer = " / HTTP/1.0\r\n\r\n"; - BIO *b = BIO_new(BIO_s_mem()); - - if (!TEST_true((unsigned int)idx < OSSL_NELEM(verbs))) - goto end; - - if (!TEST_true(create_ssl_ctx_pair(libctx, TLS_server_method(), - NULL, 0, 0, &sctx, NULL, cert, privkey))) - goto end; - - serverssl = SSL_new(sctx); - if (!TEST_ptr(serverssl)) - goto end; - - if (!TEST_int_gt(BIO_write(b, verbs[idx], (int)strlen(verbs[idx])), 0)) - goto end; - if (!TEST_int_gt(BIO_write(b, http_trailer, (int)strlen(http_trailer)), 0)) - goto end; - SSL_set_bio(serverssl, b, b); - b = NULL; - - ERR_clear_error(); - if (!TEST_int_le(SSL_accept(serverssl), 0)) - goto end; - if (!TEST_int_eq(ERR_GET_REASON(ERR_get_error()), SSL_R_HTTP_REQUEST)) - goto end; - - testresult = 1; -end: - SSL_free(serverssl); - SSL_CTX_free(sctx); - BIO_free(b); - - return testresult; -} - OPT_TEST_DECLARE_USAGE("certfile privkeyfile srpvfile tmpfile provider config dhfile\n") int setup_tests(void) @@ -15410,9 +13914,6 @@ int setup_tests(void) ADD_ALL_TESTS(test_ktls, NUM_KTLS_TEST_CIPHERS * 4); ADD_ALL_TESTS(test_ktls_sendfile, NUM_KTLS_TEST_CIPHERS * 2); #endif -#ifndef OSSL_NO_USABLE_TLS1_3 - ADD_TEST(test_ktls_moving_write_buffer); -#endif #endif ADD_TEST(test_large_message_tls); ADD_TEST(test_large_message_tls_read_ahead); @@ -15430,7 +13931,6 @@ int setup_tests(void) ADD_TEST(test_session_with_only_int_cache); ADD_TEST(test_session_with_only_ext_cache); ADD_TEST(test_session_with_both_cache); - ADD_TEST(test_remove_session_cb_not_under_lock); ADD_TEST(test_session_wo_ca_names); #ifndef OSSL_NO_USABLE_TLS1_3 ADD_ALL_TESTS(test_stateful_tickets, 3); @@ -15443,7 +13943,6 @@ int setup_tests(void) ADD_TEST(test_ssl_bio_pop_ssl_bio); ADD_TEST(test_ssl_bio_change_rbio); ADD_TEST(test_ssl_bio_change_wbio); - ADD_TEST(test_ssl_set_wbio_chain_no_leak); #if !defined(OPENSSL_NO_TLS1_2) || defined(OSSL_NO_USABLE_TLS1_3) ADD_ALL_TESTS(test_set_sigalgs, OSSL_NELEM(testsigalgs) * 2); ADD_TEST(test_keylog); @@ -15484,26 +13983,22 @@ int setup_tests(void) ADD_ALL_TESTS(test_tls13_ciphersuite, 4); #ifdef OPENSSL_NO_PSK ADD_ALL_TESTS(test_tls13_psk, 1); - ADD_ALL_TESTS(test_tls13_psk_client_sid_ctx, 1); #else ADD_ALL_TESTS(test_tls13_psk, 4); - ADD_ALL_TESTS(test_tls13_psk_client_sid_ctx, 2); #endif /* OPENSSL_NO_PSK */ - ADD_TEST(test_tls13_psk_verify_peer_no_sid_ctx); - ADD_TEST(test_tls13_psk_verify_peer_no_ticket); #ifndef OSSL_NO_USABLE_TLS1_3 ADD_ALL_TESTS(test_tls13_no_dhe_kex, 8); #endif /* OSSL_NO_USABLE_TLS1_3 */ #ifndef OPENSSL_NO_TLS1_2 /* Test with both TLSv1.3 and 1.2 versions */ - ADD_ALL_TESTS(test_key_exchange, 23); + ADD_ALL_TESTS(test_key_exchange, 21); #if !defined(OPENSSL_NO_EC) && !defined(OPENSSL_NO_DH) ADD_ALL_TESTS(test_negotiated_group, 4 * (OSSL_NELEM(ecdhe_kexch_groups) + OSSL_NELEM(ffdhe_kexch_groups))); #endif #else /* Test with only TLSv1.3 versions */ - ADD_ALL_TESTS(test_key_exchange, 20); + ADD_ALL_TESTS(test_key_exchange, 18); #endif ADD_ALL_TESTS(test_custom_exts, 6); ADD_TEST(test_stateless); @@ -15534,10 +14029,8 @@ int setup_tests(void) ADD_ALL_TESTS(test_ssl_pending, 2); ADD_ALL_TESTS(test_ssl_get_shared_ciphers, OSSL_NELEM(shared_ciphers_data)); ADD_ALL_TESTS(test_ticket_callbacks, 20); - ADD_TEST(test_ticket_abort_session_leak); ADD_ALL_TESTS(test_shutdown, 7); ADD_TEST(test_async_shutdown); - ADD_ALL_TESTS(test_ssl_bio_eof, 2); ADD_ALL_TESTS(test_incorrect_shutdown, 2); ADD_ALL_TESTS(test_cert_cb, 6); ADD_ALL_TESTS(test_client_cert_cb, 2); @@ -15560,12 +14053,10 @@ int setup_tests(void) #endif #ifndef OPENSSL_NO_TLS1_2 ADD_TEST(test_ssl_dup); - ADD_ALL_TESTS(test_session_secret_cb, 2); + ADD_TEST(test_session_secret_cb); #ifndef OPENSSL_NO_DH ADD_ALL_TESTS(test_set_tmp_dh, 11); ADD_ALL_TESTS(test_dh_auto, 7); - ADD_ALL_TESTS(test_no_shared_ffdhe_group, 10); - ADD_ALL_TESTS(test_shared_ffdhe_group, 5); #endif #endif #ifndef OSSL_NO_USABLE_TLS1_3 @@ -15574,7 +14065,6 @@ int setup_tests(void) #endif ADD_TEST(test_inherit_verify_param); ADD_TEST(test_set_alpn); - ADD_TEST(test_get_alpn); #if !defined(OPENSSL_NO_EC) && !defined(OPENSSL_NO_TLS1_2) ADD_TEST(test_legacy_ec_point_formats); #endif @@ -15588,13 +14078,11 @@ int setup_tests(void) #ifndef OSSL_NO_USABLE_TLS1_3 ADD_TEST(test_read_ahead_key_change); ADD_ALL_TESTS(test_tls13_record_padding, 6); - ADD_TEST(test_tls13_unknown_extension); #endif #if !defined(OPENSSL_NO_TLS1_2) && !defined(OSSL_NO_USABLE_TLS1_3) ADD_ALL_TESTS(test_serverinfo_custom, 4); #endif ADD_ALL_TESTS(test_version, 6); - ADD_TEST(test_ssl_ctx_is_server); ADD_TEST(test_rstate_string); ADD_ALL_TESTS(test_handshake_retry, 16); ADD_TEST(test_data_retry); @@ -15614,11 +14102,6 @@ int setup_tests(void) ADD_TEST(test_ssl_trace); #endif ADD_ALL_TESTS(test_ssl_set_groups_unsupported_keyshare, 2); - ADD_TEST(test_ssl_conf_flags); - ADD_ALL_TESTS(test_http_verbs, 3); -#if !defined(OSSL_NO_USABLE_TLS1_3) - ADD_TEST(test_grease); -#endif return 1; err: diff --git a/test/sslbuffertest.c b/test/sslbuffertest.c index 13b6f6b404..c7bcbe66e9 100644 --- a/test/sslbuffertest.c +++ b/test/sslbuffertest.c @@ -177,7 +177,7 @@ end: * Test 1: Attempt to free buffers after only a partial record header has been * received * Test 2: Attempt to free buffers after a full record header but no record body - * Test 3: Attempt to free buffers after a full record header and partial record + * Test 3: Attempt to free buffers after a full record hedaer and partial record * body */ static int test_free_buffers(int test) diff --git a/test/stack_test.c b/test/stack_test.c index c2ed731f44..aa29e6c822 100644 --- a/test/stack_test.c +++ b/test/stack_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved. * Copyright (c) 2017, Oracle and/or its affiliates. All rights reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use @@ -29,17 +29,17 @@ typedef struct { int n; char c; -} TST_SS; +} SS; typedef union { int n; char c; -} TST_SU; +} SU; DEFINE_SPECIAL_STACK_OF(sint, int) DEFINE_SPECIAL_STACK_OF_CONST(uchar, unsigned char) -DEFINE_STACK_OF(TST_SS) -DEFINE_STACK_OF_CONST(TST_SU) +DEFINE_STACK_OF(SS) +DEFINE_STACK_OF_CONST(SU) static int int_compare(const int *const *a, const int *const *b) { @@ -255,15 +255,6 @@ static int test_uchar_stack(int reserve) goto end; sk_uchar_sort(r); sk_uchar_sort(q); - for (i = 0; i < n; i++) { - int idx = sk_uchar_find(q, v + i); - - if (!TEST_int_ge(idx, 0) - || !TEST_uchar_eq(*sk_uchar_value(q, idx), v[i])) { - TEST_info("uchar sorted find %d", i); - goto end; - } - } /* pop */ for (i = 0; i < n; i++) { @@ -334,59 +325,25 @@ end: return testresult; } -static TST_SS *SS_copy(const TST_SS *p) +static SS *SS_copy(const SS *p) { - TST_SS *q = OPENSSL_malloc(sizeof(*q)); + SS *q = OPENSSL_malloc(sizeof(*q)); if (q != NULL) memcpy(q, p, sizeof(*q)); return q; } -static void SS_free(TST_SS *p) +static void SS_free(SS *p) { OPENSSL_free(p); } -static char *string_copy(const char *p) -{ - return OPENSSL_strdup(p); -} - -static int string_cmp(const char *const *a, const char *const *b) -{ - return strcmp(*a, *b); -} - -static void string_free(char *p) -{ - OPENSSL_free(p); -} - -static int push_string(STACK_OF(OPENSSL_STRING) *s, const char *str) -{ - char *p = OPENSSL_strdup(str); - int expected = sk_OPENSSL_STRING_num(s) + 1; - int pushed; - - if (!TEST_ptr(p)) - return 0; - - pushed = sk_OPENSSL_STRING_push(s, p); - if (!TEST_int_eq(pushed, expected)) { - if (pushed <= 0) - OPENSSL_free(p); - return 0; - } - - return 1; -} - static int test_SS_stack(void) { - STACK_OF(TST_SS) *s = sk_TST_SS_new_null(); - STACK_OF(TST_SS) *r = NULL; - TST_SS *v[10], *p; + STACK_OF(SS) *s = sk_SS_new_null(); + STACK_OF(SS) *r = NULL; + SS *v[10], *p; const int n = OSSL_NELEM(v); int i; int testresult = 0; @@ -399,25 +356,25 @@ static int test_SS_stack(void) goto end; v[i]->n = i; v[i]->c = 'A' + i; - if (!TEST_int_eq(sk_TST_SS_num(s), i)) { + if (!TEST_int_eq(sk_SS_num(s), i)) { TEST_info("SS stack size %d", i); goto end; } - sk_TST_SS_push(s, v[i]); + sk_SS_push(s, v[i]); } - if (!TEST_int_eq(sk_TST_SS_num(s), n)) + if (!TEST_int_eq(sk_SS_num(s), n)) goto end; /* deepcopy */ - r = sk_TST_SS_deep_copy(NULL, &SS_copy, &SS_free); - if (sk_TST_SS_num(r) != 0) + r = sk_SS_deep_copy(NULL, &SS_copy, &SS_free); + if (sk_SS_num(r) != 0) goto end; - sk_TST_SS_free(r); - r = sk_TST_SS_deep_copy(s, &SS_copy, &SS_free); + sk_SS_free(r); + r = sk_SS_deep_copy(s, &SS_copy, &SS_free); if (!TEST_ptr(r)) goto end; for (i = 0; i < n; i++) { - p = sk_TST_SS_value(r, i); + p = sk_SS_value(r, i); if (!TEST_ptr_ne(p, v[i])) { TEST_info("SS deepcopy non-copy %d", i); goto end; @@ -433,82 +390,33 @@ static int test_SS_stack(void) } /* pop_free - we rely on the malloc debug to catch the leak */ - sk_TST_SS_pop_free(r, &SS_free); + sk_SS_pop_free(r, &SS_free); r = NULL; /* delete_ptr */ - p = sk_TST_SS_delete_ptr(s, v[3]); + p = sk_SS_delete_ptr(s, v[3]); if (!TEST_ptr(p)) goto end; SS_free(p); - if (!TEST_int_eq(sk_TST_SS_num(s), n - 1)) + if (!TEST_int_eq(sk_SS_num(s), n - 1)) goto end; for (i = 0; i < n - 1; i++) - if (!TEST_ptr_eq(sk_TST_SS_value(s, i), v[i < 3 ? i : 1 + i])) { + if (!TEST_ptr_eq(sk_SS_value(s, i), v[i < 3 ? i : 1 + i])) { TEST_info("SS delete ptr item %d", i); goto end; } testresult = 1; end: - sk_TST_SS_pop_free(r, &SS_free); - sk_TST_SS_pop_free(s, &SS_free); - return testresult; -} - -static int test_OPENSSL_STRING_deep_copy_mfail(void) -{ - STACK_OF(OPENSSL_STRING) *s = sk_OPENSSL_STRING_new_null(); - STACK_OF(OPENSSL_STRING) *r = NULL; - static const char *strings[] = { - "alpha", "beta", "gamma" - }; - char *p; - int i; - int testresult = 0; - - if (!TEST_ptr(s)) - goto end; - - for (i = 0; i < (int)OSSL_NELEM(strings); i++) { - p = OPENSSL_strdup(strings[i]); - if (!TEST_ptr(p) - || !TEST_int_eq(sk_OPENSSL_STRING_push(s, p), i + 1)) { - OPENSSL_free(p); - goto end; - } - } - - MFAIL_start(); - r = sk_OPENSSL_STRING_deep_copy(s, string_copy, string_free); - MFAIL_end(); - - if (r == NULL) - goto end; - - if (!TEST_int_eq(sk_OPENSSL_STRING_num(r), sk_OPENSSL_STRING_num(s))) - goto end; - - for (i = 0; i < sk_OPENSSL_STRING_num(s); i++) { - char *src = sk_OPENSSL_STRING_value(s, i); - char *dst = sk_OPENSSL_STRING_value(r, i); - - if (!TEST_ptr_ne(dst, src) - || !TEST_str_eq(dst, src)) - goto end; - } - - testresult = 1; -end: - sk_OPENSSL_STRING_pop_free(r, string_free); - sk_OPENSSL_STRING_pop_free(s, string_free); + sk_SS_pop_free(r, &SS_free); + sk_SS_pop_free(s, &SS_free); return testresult; } static int test_SU_stack(void) { - STACK_OF(TST_SU) *s = sk_TST_SU_new_null(); - TST_SU v[10]; + STACK_OF(SU) *s = sk_SU_new_null(); + SU v[10]; const int n = OSSL_NELEM(v); int i; int testresult = 0; @@ -519,101 +427,25 @@ static int test_SU_stack(void) v[i].n = i; else v[i].c = 'A' + i; - if (!TEST_int_eq(sk_TST_SU_num(s), i)) { + if (!TEST_int_eq(sk_SU_num(s), i)) { TEST_info("SU stack size %d", i); goto end; } - sk_TST_SU_push(s, v + i); + sk_SU_push(s, v + i); } - if (!TEST_int_eq(sk_TST_SU_num(s), n)) + if (!TEST_int_eq(sk_SU_num(s), n)) goto end; /* check the pointers are correct */ for (i = 0; i < n; i++) - if (!TEST_ptr_eq(sk_TST_SU_value(s, i), v + i)) { + if (!TEST_ptr_eq(sk_SU_value(s, i), v + i)) { TEST_info("SU pointer check %d", i); goto end; } testresult = 1; end: - sk_TST_SU_free(s); - return testresult; -} - -static int test_STRING_STACK_stack_ubsan(int idx) -{ - STACK_OF(OPENSSL_STRING) *s = NULL; - STACK_OF(OPENSSL_STRING) *t = NULL; - STACK_OF(OPENSSL_STRING) *u = NULL; - int testresult = 0; - - switch (idx) { - case 0: - s = sk_OPENSSL_STRING_new_null(); - break; - case 1: - s = sk_OPENSSL_STRING_new(string_cmp); - break; - case 2: - s = sk_OPENSSL_STRING_new_reserve(string_cmp, 2); - break; - case 3: - s = sk_OPENSSL_STRING_deep_copy(NULL, string_copy, string_free); - break; - case 4: - t = sk_OPENSSL_STRING_new(string_cmp); - if (!TEST_ptr(t)) - goto end; - if (!push_string(t, "b") - || !push_string(t, "a")) - goto end; - s = sk_OPENSSL_STRING_dup(t); - if (s != NULL) { - sk_OPENSSL_STRING_free(t); - t = NULL; - } - break; - case 5: - t = sk_OPENSSL_STRING_deep_copy(NULL, string_copy, string_free); - if (!TEST_ptr(t)) - goto end; - if (!push_string(t, "b") - || !push_string(t, "a")) - goto end; - s = sk_OPENSSL_STRING_deep_copy(t, string_copy, string_free); - break; - default: - goto end; - } - if (!TEST_ptr(s)) - goto end; - - if (idx < 4) { - if (!push_string(s, "b") - || !push_string(s, "a")) - goto end; - } - - sk_OPENSSL_STRING_set_cmp_func(s, string_cmp); - sk_OPENSSL_STRING_sort(s); - if (!TEST_str_eq(sk_OPENSSL_STRING_value(s, 0), "a") - || !TEST_int_eq(sk_OPENSSL_STRING_find(s, "b"), 1)) - goto end; - - u = sk_OPENSSL_STRING_deep_copy(s, string_copy, string_free); - if (!TEST_ptr(u) - || !TEST_int_eq(sk_OPENSSL_STRING_num(u), 2) - || !TEST_ptr_ne(sk_OPENSSL_STRING_value(u, 0), - sk_OPENSSL_STRING_value(s, 0)) - || !TEST_str_eq(sk_OPENSSL_STRING_value(u, 0), "a")) - goto end; - - testresult = 1; -end: - sk_OPENSSL_STRING_pop_free(u, string_free); - sk_OPENSSL_STRING_pop_free(s, string_free); - sk_OPENSSL_STRING_pop_free(t, string_free); + sk_SU_free(s); return testresult; } @@ -622,8 +454,6 @@ int setup_tests(void) ADD_ALL_TESTS(test_int_stack, 4); ADD_ALL_TESTS(test_uchar_stack, 4); ADD_TEST(test_SS_stack); - ADD_ALL_TESTS(test_STRING_STACK_stack_ubsan, 6); ADD_TEST(test_SU_stack); - ADD_MFAIL_TEST(test_OPENSSL_STRING_deep_copy_mfail); return 1; } diff --git a/test/statem_clnt_construct_test.c b/test/statem_clnt_construct_test.c deleted file mode 100644 index 350e59ce2f..0000000000 --- a/test/statem_clnt_construct_test.c +++ /dev/null @@ -1,1102 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* - * Direct tests for the client state-machine construct functions in - * statem_clnt.c: prime a client SSL_CONNECTION enough to call a construct - * function without a full handshake, then check the result structurally and, - * where useful, by round-tripping it through the server parser. OOM branches - * are covered with mfail tests. - */ - -#include -#ifndef OPENSSL_NO_ECH -#include -#include -#endif - -#include "internal/ssl_unwrap.h" -#include "../ssl/ssl_local.h" -#include "../ssl/statem/statem_local.h" -#include "testutil.h" - -/* - * TLS 1.3 needs a key-share group, so it is unusable when both EC and DH are - * disabled even though the protocol itself is compiled in (e.g. no-bulk). - */ -#if defined(OPENSSL_NO_TLS1_3) \ - || (defined(OPENSSL_NO_EC) && defined(OPENSSL_NO_DH)) -#define OSSL_NO_USABLE_TLS1_3 -#endif - -/* ECH needs a curve (EC/ECX) for its default suite and usable TLS 1.3. */ -#if defined(OPENSSL_NO_ECH) || defined(OPENSSL_NO_EC) \ - || defined(OPENSSL_NO_ECX) || defined(OSSL_NO_USABLE_TLS1_3) -#define OSSL_NO_USABLE_ECH -#endif - -/* - * Helpers down to finish_msg() are generic and reusable by tests for any - * statem_clnt construct function; the per-message code follows. - */ - -/* Connection configuration shared by the construct tests. */ -typedef struct { - int is_dtls; - int min_ver; /* 0 for library default */ - int max_ver; /* 0 for library default */ - int clear_midbox; /* clear SSL_OP_ENABLE_MIDDLEBOX_COMPAT */ -} CH_CONFIG; - -static const SSL_METHOD *client_method(const CH_CONFIG *cfg) -{ - return cfg->is_dtls ? DTLS_client_method() : TLS_client_method(); -} - -/* Handshake message header length (msg precedes the ClientHello body). */ -static size_t hdr_len(const CH_CONFIG *cfg) -{ - return cfg->is_dtls ? DTLS1_HM_HEADER_LENGTH : SSL3_HM_HEADER_LENGTH; -} - -static const SSL_METHOD *server_method(const CH_CONFIG *cfg) -{ - return cfg->is_dtls ? DTLS_server_method() : TLS_server_method(); -} - -static SSL_CTX *new_ctx(const CH_CONFIG *cfg, const SSL_METHOD *meth) -{ - SSL_CTX *ctx = SSL_CTX_new(meth); - - if (ctx == NULL) - return NULL; - if ((cfg->min_ver != 0 - && !SSL_CTX_set_min_proto_version(ctx, cfg->min_ver)) - || (cfg->max_ver != 0 - && !SSL_CTX_set_max_proto_version(ctx, cfg->max_ver))) { - SSL_CTX_free(ctx); - return NULL; - } - return ctx; -} - -/* - * Set up the init_buf and handshake state the write state machine would have - * established before calling a construct function. For the client a WPACKET - * with the handshake header for message type mt is emitted into init_buf. - * initbuf_len of 0 means full size; a small value exercises WPACKET failures. - */ -static int prime_ssl(SSL *ssl, int is_client, size_t initbuf_len, WPACKET *pkt, - int mt) -{ - SSL_CONNECTION *s = SSL_CONNECTION_FROM_SSL(ssl); - - if (!TEST_ptr(s)) - return 0; - - if (is_client) - SSL_set_connect_state(ssl); - else - SSL_set_accept_state(ssl); - - if (initbuf_len == 0) - initbuf_len = SSL3_RT_MAX_PLAIN_LENGTH; - - if (!TEST_ptr(s->init_buf = BUF_MEM_new()) - || !TEST_true(BUF_MEM_grow(s->init_buf, initbuf_len))) - return 0; - - if (!TEST_true(tls_setup_handshake(s))) - return 0; - - if (pkt != NULL - && (!TEST_true(WPACKET_init(pkt, s->init_buf)) - || !TEST_true(ssl_set_handshake_header(s, pkt, mt)))) - return 0; - - return 1; -} - -/* Finalize a constructed message and return its bytes (header + body). */ -static int finish_msg(SSL *ssl, WPACKET *pkt, int mt, unsigned char **msg, - size_t *msglen) -{ - SSL_CONNECTION *s = SSL_CONNECTION_FROM_SSL(ssl); - - if (!TEST_ptr(s) - || !TEST_true(ssl_close_construct_packet(s, pkt, mt)) - || !TEST_true(WPACKET_get_total_written(pkt, msglen)) - || !TEST_true(WPACKET_finish(pkt))) - return 0; - - *msg = (unsigned char *)s->init_buf->data; - return 1; -} - -/* - * =========================================================================== - * tls_construct_client_hello - * =========================================================================== - */ - -/* Recover the session_id length, the main branching difference in construct. */ -static int get_ch_sessid_len(const CH_CONFIG *cfg, const unsigned char *msg, - size_t msglen, size_t *sidlen) -{ - PACKET pkt = { 0 }, sessid = { 0 }, cookie = { 0 }; - PACKET ciphers = { 0 }, comp = { 0 }; - unsigned int legacy_version; - size_t hl = hdr_len(cfg); - - if (!TEST_size_t_gt(msglen, hl) - || !TEST_true(PACKET_buf_init(&pkt, msg + hl, msglen - hl))) - return 0; - - if (!TEST_true(PACKET_get_net_2(&pkt, &legacy_version)) - || !TEST_true(PACKET_forward(&pkt, SSL3_RANDOM_SIZE)) - || !TEST_true(PACKET_get_length_prefixed_1(&pkt, &sessid))) - return 0; - - if (cfg->is_dtls - && !TEST_true(PACKET_get_length_prefixed_1(&pkt, &cookie))) - return 0; - - /* Sanity: cipher list non-empty, compression present and contains NULL. */ - if (!TEST_true(PACKET_get_length_prefixed_2(&pkt, &ciphers)) - || !TEST_size_t_gt(PACKET_remaining(&ciphers), 0) - || !TEST_true(PACKET_get_length_prefixed_1(&pkt, &comp)) - || !TEST_size_t_gt(PACKET_remaining(&comp), 0)) - return 0; - - *sidlen = PACKET_remaining(&sessid); - return 1; -} - -/* Run the produced ClientHello body through the server-side parser. */ -static int roundtrip_process_ch(const CH_CONFIG *cfg, const unsigned char *msg, - size_t msglen) -{ - SSL_CTX *sctx = NULL; - SSL *ssl = NULL; - SSL_CONNECTION *s; - PACKET pkt; - int ret = 0; - - if (!TEST_ptr(sctx = new_ctx(cfg, server_method(cfg))) - || !TEST_ptr(ssl = SSL_new(sctx))) - goto err; - - if (!prime_ssl(ssl, 0, 0, NULL, SSL3_MT_CLIENT_HELLO)) - goto err; - s = SSL_CONNECTION_FROM_SSL(ssl); - - if (!TEST_true(PACKET_buf_init(&pkt, msg + hdr_len(cfg), - msglen - hdr_len(cfg)))) - goto err; - - if (!TEST_int_eq(tls_process_client_hello(s, &pkt), - MSG_PROCESS_CONTINUE_PROCESSING)) - goto err; - - ret = 1; -err: - SSL_free(ssl); - SSL_CTX_free(sctx); - return ret; -} - -/* - * Construct a ClientHello, assert its session_id length and optionally - * round-trip it. prep injects extra state just before construct; - * expect_random asserts the produced client random (to check reuse). - * Both may be NULL. - */ -static int do_construct_ch(const CH_CONFIG *cfg, - int (*prep)(SSL_CONNECTION *s), size_t expect_sidlen, int roundtrip, - const unsigned char *expect_random) -{ - SSL_CTX *cctx = NULL; - SSL *ssl = NULL; - SSL_CONNECTION *s; - WPACKET pkt; - unsigned char *msg = NULL; - size_t msglen = 0, sidlen = 0; - int ret = 0; - - if (!TEST_ptr(cctx = new_ctx(cfg, client_method(cfg))) - || !TEST_ptr(ssl = SSL_new(cctx))) - goto err; - if (cfg->clear_midbox) - SSL_clear_options(ssl, SSL_OP_ENABLE_MIDDLEBOX_COMPAT); - - if (!prime_ssl(ssl, 1, 0, &pkt, SSL3_MT_CLIENT_HELLO)) - goto err; - s = SSL_CONNECTION_FROM_SSL(ssl); - - if (prep != NULL && !prep(s)) { - WPACKET_cleanup(&pkt); - goto err; - } - - if (!TEST_int_eq(tls_construct_client_hello(s, &pkt), CON_FUNC_SUCCESS)) { - WPACKET_cleanup(&pkt); - goto err; - } - if (!finish_msg(ssl, &pkt, SSL3_MT_CLIENT_HELLO, &msg, &msglen)) - goto err; - - if (!get_ch_sessid_len(cfg, msg, msglen, &sidlen) - || !TEST_size_t_eq(sidlen, expect_sidlen)) - goto err; - - /* The client random follows the 2-byte legacy_version in the body. */ - if (expect_random != NULL - && !TEST_mem_eq(msg + hdr_len(cfg) + 2, SSL3_RANDOM_SIZE, - expect_random, SSL3_RANDOM_SIZE)) - goto err; - - if (roundtrip && !roundtrip_process_ch(cfg, msg, msglen)) - goto err; - - ret = 1; -err: - SSL_free(ssl); - SSL_CTX_free(cctx); - return ret; -} - -/* Expect tls_construct_client_hello() to fail (CON_FUNC_ERROR). */ -static int do_construct_ch_expect_fail(const CH_CONFIG *cfg, - int (*prep)(SSL_CONNECTION *s), - size_t initbuf_len, int empty_ciphers) -{ - SSL_CTX *cctx = NULL; - SSL *ssl = NULL; - SSL_CONNECTION *s; - WPACKET pkt; - int have_pkt = 0; - int ret = 0; - - if (!TEST_ptr(cctx = new_ctx(cfg, client_method(cfg))) - || !TEST_ptr(ssl = SSL_new(cctx))) - goto err; - - if (empty_ciphers) { - /* Leave no usable cipher: aNULL is disabled at default sec level. */ - int r1 = SSL_set_ciphersuites(ssl, ""); - int r2 = SSL_set_cipher_list(ssl, "aNULL"); - - (void)r1; - (void)r2; - } - - if (!prime_ssl(ssl, 1, initbuf_len, &pkt, SSL3_MT_CLIENT_HELLO)) - goto err; - have_pkt = 1; - s = SSL_CONNECTION_FROM_SSL(ssl); - - if (prep != NULL && !prep(s)) - goto err; - - if (!TEST_int_eq(tls_construct_client_hello(s, &pkt), CON_FUNC_ERROR)) - goto err; - - ret = 1; -err: - if (have_pkt) - WPACKET_cleanup(&pkt); - SSL_free(ssl); - SSL_CTX_free(cctx); - return ret; -} - -/* TLS 1.2 happy-path / session tests */ - -#ifndef OPENSSL_NO_TLS1_2 -static int test_construct_ch_tls12(void) -{ - CH_CONFIG cfg = { 0, TLS1_2_VERSION, TLS1_2_VERSION, 0 }; - - /* Fresh (non-resumable) TLS 1.2 session: empty session id. */ - return do_construct_ch(&cfg, NULL, 0, 1, NULL); -} - -/* Resumable non-TLS1.3 session: construct reuses its session id. */ -static int prep_resume(SSL_CONNECTION *s) -{ - SSL *ssl = SSL_CONNECTION_GET_SSL(s); - SSL_SESSION *sess = SSL_SESSION_new(); - int ret = 0; - - if (!TEST_ptr(sess)) - goto err; - sess->ssl_version = TLS1_2_VERSION; - sess->session_id_length = sizeof(sess->session_id); - memset(sess->session_id, 0x5A, sess->session_id_length); - sess->cipher = sk_SSL_CIPHER_value(SSL_get_ciphers(ssl), 0); - if (!TEST_ptr(sess->cipher) || !TEST_true(SSL_set_session(ssl, sess))) - goto err; - ret = 1; -err: - SSL_SESSION_free(sess); - return ret; -} - -static int test_construct_ch_resume(void) -{ - CH_CONFIG cfg = { 0, TLS1_2_VERSION, TLS1_2_VERSION, 0 }; - - /* Resumed session: the pre-loaded 32-byte session id is sent. */ - return do_construct_ch(&cfg, prep_resume, SSL_MAX_SSL_SESSION_ID_LENGTH, 1, - NULL); -} -#endif /* OPENSSL_NO_TLS1_2 */ - -/* TLS 1.3 happy-path / HRR tests */ - -#ifndef OSSL_NO_USABLE_TLS1_3 -static int test_construct_ch_tls13(void) -{ - CH_CONFIG cfg = { 0, TLS1_3_VERSION, TLS1_3_VERSION, 0 }; - - /* Middlebox compat is on by default: a random 32-byte session id. */ - return do_construct_ch(&cfg, NULL, SSL_MAX_SSL_SESSION_ID_LENGTH, 1, NULL); -} - -static int test_construct_ch_tls13_no_middlebox(void) -{ - CH_CONFIG cfg = { 0, TLS1_3_VERSION, TLS1_3_VERSION, 1 }; - - /* No middlebox compat: empty session id. */ - return do_construct_ch(&cfg, NULL, 0, 1, NULL); -} - -static int prep_hrr(SSL_CONNECTION *s) -{ - SSL *ssl = SSL_CONNECTION_GET_SSL(s); - SSL_SESSION *sess = SSL_SESSION_new(); - int ret = 0; - - /* Under HRR construct skips ssl_get_new_session(), so a session must - * already exist (created for the first ClientHello). */ - if (!TEST_ptr(sess)) - goto err; - sess->ssl_version = TLS1_3_VERSION; - sess->cipher = sk_SSL_CIPHER_value(SSL_get_ciphers(ssl), 0); - if (!TEST_ptr(sess->cipher) || !TEST_true(SSL_set_session(ssl, sess))) - goto err; - s->hello_retry_request = SSL_HRR_COMPLETE; - ret = 1; -err: - SSL_SESSION_free(sess); - return ret; -} - -static int test_construct_ch_hrr(void) -{ - CH_CONFIG cfg = { 0, TLS1_3_VERSION, TLS1_3_VERSION, 0 }; - - /* TLS 1.3 + middlebox compat still emits a 32-byte session id under HRR. */ - return do_construct_ch(&cfg, prep_hrr, SSL_MAX_SSL_SESSION_ID_LENGTH, 1, - NULL); -} -#endif /* OSSL_NO_USABLE_TLS1_3 */ - -/* DTLS happy-path / cookie / random-reuse tests */ - -#if !defined(OPENSSL_NO_DTLS) && !defined(OPENSSL_NO_DTLS1_2) -static int test_construct_ch_dtls(void) -{ - CH_CONFIG cfg = { 1, 0, 0, 0 }; - - /* DTLS uses a different server parser path; skip the roundtrip. */ - return do_construct_ch(&cfg, NULL, 0, 0, NULL); -} - -static int prep_dtls_cookie(SSL_CONNECTION *s) -{ - /* A HelloVerifyRequest cookie is echoed in the ClientHello. */ - static const unsigned char cookie[16] = { - 0xc0, 0x01, 0xc0, 0x02, 0xc0, 0x03, 0xc0, 0x04, - 0xc0, 0x05, 0xc0, 0x06, 0xc0, 0x07, 0xc0, 0x08 - }; - - memcpy(s->d1->cookie, cookie, sizeof(cookie)); - s->d1->cookie_len = sizeof(cookie); - return 1; -} - -static int test_construct_ch_dtls_cookie(void) -{ - CH_CONFIG cfg = { 1, 0, 0, 0 }; - - return do_construct_ch(&cfg, prep_dtls_cookie, 0, 0, NULL); -} - -/* A recognizable, all-non-zero client random to detect reuse. */ -static const unsigned char reused_random[SSL3_RANDOM_SIZE] = { - 0xa0, 0xa1, 0xa2, 0xa3, 0xa4, 0xa5, 0xa6, 0xa7, - 0xa8, 0xa9, 0xaa, 0xab, 0xac, 0xad, 0xae, 0xaf, - 0xb0, 0xb1, 0xb2, 0xb3, 0xb4, 0xb5, 0xb6, 0xb7, - 0xb8, 0xb9, 0xba, 0xbb, 0xbc, 0xbd, 0xbe, 0xbf -}; - -static int prep_dtls_client_random(SSL_CONNECTION *s) -{ - /* DTLS reuses an already-set client random (HelloVerifyRequest reply). */ - memcpy(s->s3.client_random, reused_random, sizeof(reused_random)); - return 1; -} - -static int test_construct_ch_dtls_client_random(void) -{ - CH_CONFIG cfg = { 1, 0, 0, 0 }; - - return do_construct_ch(&cfg, prep_dtls_client_random, 0, 0, reused_random); -} -#endif /* OPENSSL_NO_DTLS */ - -/* Deterministic error-branch tests */ - -static int test_construct_ch_small_buf(void) -{ - /* Default version: the overflow is version-independent. */ - CH_CONFIG cfg = { 0, 0, 0, 0 }; - SSL_CTX *cctx = NULL; - SSL *ssl = NULL; - SSL_CONNECTION *s; - WPACKET pkt; - /* - * Fixed, non-growable buffer that overflows part-way through the body (a - * BUF_MEM-backed WPACKET would just grow), hitting a WPACKET write failure. - */ - unsigned char buf[40]; - int have_pkt = 0; - int ret = 0; - - if (!TEST_ptr(cctx = new_ctx(&cfg, client_method(&cfg))) - || !TEST_ptr(ssl = SSL_new(cctx))) - goto err; - SSL_set_connect_state(ssl); - s = SSL_CONNECTION_FROM_SSL(ssl); - if (!TEST_ptr(s) - || !TEST_ptr(s->init_buf = BUF_MEM_new()) - || !TEST_true(BUF_MEM_grow(s->init_buf, SSL3_RT_MAX_PLAIN_LENGTH)) - || !TEST_true(tls_setup_handshake(s))) - goto err; - - if (!TEST_true(WPACKET_init_static_len(&pkt, buf, sizeof(buf), 0))) - goto err; - have_pkt = 1; - if (!TEST_true(ssl_set_handshake_header(s, &pkt, SSL3_MT_CLIENT_HELLO))) - goto err; - - if (!TEST_int_eq(tls_construct_client_hello(s, &pkt), CON_FUNC_ERROR)) - goto err; - - ret = 1; -err: - if (have_pkt) - WPACKET_cleanup(&pkt); - SSL_free(ssl); - SSL_CTX_free(cctx); - return ret; -} - -static int test_construct_ch_no_ciphers(void) -{ - CH_CONFIG cfg = { 0, 0, 0, 0 }; - - return do_construct_ch_expect_fail(&cfg, NULL, 0, 1); -} - -/* Allocation-failure (mfail) tests */ - -/* Compiled when any mfail caller below (TLS 1.2, TLS 1.3 or ECH) is. */ -#if !defined(OSSL_NO_USABLE_TLS1_3) || !defined(OPENSSL_NO_TLS1_2) -static int mfail_construct_ch_common(const CH_CONFIG *cfg, - int (*prep)(SSL_CONNECTION *s)) -{ - SSL_CTX *cctx = NULL; - SSL *ssl = NULL; - SSL_CONNECTION *s; - WPACKET pkt; - int ok = 0; - int ret = 0; - - if (!TEST_ptr(cctx = new_ctx(cfg, client_method(cfg))) - || !TEST_ptr(ssl = SSL_new(cctx))) - goto err; - if (cfg->clear_midbox) - SSL_clear_options(ssl, SSL_OP_ENABLE_MIDDLEBOX_COMPAT); - - if (!prime_ssl(ssl, 1, 0, &pkt, SSL3_MT_CLIENT_HELLO)) - goto err; - s = SSL_CONNECTION_FROM_SSL(ssl); - - if (prep != NULL && !prep(s)) { - WPACKET_cleanup(&pkt); - goto err; - } - - MFAIL_start(); - ok = (tls_construct_client_hello(s, &pkt) == CON_FUNC_SUCCESS); - MFAIL_end(); - - WPACKET_cleanup(&pkt); - - /* 1 on clean success, 0 on an injected allocation failure. */ - ret = ok ? 1 : 0; -err: - SSL_free(ssl); - SSL_CTX_free(cctx); - return ret; -} -#endif - -#ifndef OSSL_NO_USABLE_TLS1_3 -static int mfail_construct_ch_tls13(void) -{ - CH_CONFIG cfg = { 0, TLS1_3_VERSION, TLS1_3_VERSION, 0 }; - - return mfail_construct_ch_common(&cfg, NULL); -} -#endif - -#ifndef OPENSSL_NO_TLS1_2 -static int mfail_construct_ch_tls12(void) -{ - CH_CONFIG cfg = { 0, TLS1_2_VERSION, TLS1_2_VERSION, 0 }; - - return mfail_construct_ch_common(&cfg, NULL); -} -#endif - -#ifndef OSSL_NO_USABLE_ECH -/* ECH path tests */ - -/* Attach an ECH config so construct takes the ECH wrapper path. */ -static int prep_ech(SSL_CONNECTION *s) -{ - SSL *ssl = SSL_CONNECTION_GET_SSL(s); - OSSL_ECHSTORE *es = NULL; - OSSL_HPKE_SUITE suite = OSSL_HPKE_SUITE_DEFAULT; - int ret = 0; - - if (!TEST_ptr(es = OSSL_ECHSTORE_new(NULL, NULL)) - || !TEST_true(OSSL_ECHSTORE_new_config(es, OSSL_ECH_CURRENT_VERSION, 0, - "example.com", suite)) - || !TEST_true(SSL_set1_echstore(ssl, es))) - goto err; - ret = 1; -err: - OSSL_ECHSTORE_free(es); - return ret; -} - -/* - * ECH happy path: the server reuses the client's store, which holds the private - * key needed to decrypt the inner ClientHello, so the round-trip can succeed. - */ -static int test_construct_ch_ech(void) -{ - CH_CONFIG cfg = { 0, TLS1_3_VERSION, TLS1_3_VERSION, 0 }; - SSL_CTX *cctx = NULL, *sctx = NULL; - SSL *cssl = NULL, *sssl = NULL; - SSL_CONNECTION *cs, *ss; - OSSL_ECHSTORE *es = NULL; - OSSL_HPKE_SUITE suite = OSSL_HPKE_SUITE_DEFAULT; - WPACKET pkt; - PACKET rpkt; - unsigned char *msg = NULL; - size_t msglen = 0, sidlen = 0; - int ret = 0; - - if (!TEST_ptr(es = OSSL_ECHSTORE_new(NULL, NULL)) - || !TEST_true(OSSL_ECHSTORE_new_config(es, OSSL_ECH_CURRENT_VERSION, 0, - "example.com", suite))) - goto err; - - /* Client: construct the outer ClientHello with ECH. */ - if (!TEST_ptr(cctx = new_ctx(&cfg, client_method(&cfg))) - || !TEST_ptr(cssl = SSL_new(cctx)) - || !TEST_true(SSL_set1_echstore(cssl, es)) - || !prime_ssl(cssl, 1, 0, &pkt, SSL3_MT_CLIENT_HELLO)) - goto err; - cs = SSL_CONNECTION_FROM_SSL(cssl); - if (!TEST_int_eq(tls_construct_client_hello(cs, &pkt), CON_FUNC_SUCCESS)) { - WPACKET_cleanup(&pkt); - goto err; - } - if (!finish_msg(cssl, &pkt, SSL3_MT_CLIENT_HELLO, &msg, &msglen) - || !get_ch_sessid_len(&cfg, msg, msglen, &sidlen) - || !TEST_size_t_eq(sidlen, SSL_MAX_SSL_SESSION_ID_LENGTH)) - goto err; - - /* Server: decrypt and process the outer using the same store. */ - if (!TEST_ptr(sctx = new_ctx(&cfg, server_method(&cfg))) - || !TEST_ptr(sssl = SSL_new(sctx)) - || !TEST_true(SSL_set1_echstore(sssl, es)) - || !prime_ssl(sssl, 0, 0, NULL, SSL3_MT_CLIENT_HELLO)) - goto err; - ss = SSL_CONNECTION_FROM_SSL(sssl); - if (!TEST_true(PACKET_buf_init(&rpkt, msg + hdr_len(&cfg), - msglen - hdr_len(&cfg))) - || !TEST_int_eq(tls_process_client_hello(ss, &rpkt), - MSG_PROCESS_CONTINUE_PROCESSING)) - goto err; - - ret = 1; -err: - OSSL_ECHSTORE_free(es); - SSL_free(cssl); - SSL_free(sssl); - SSL_CTX_free(cctx); - SSL_CTX_free(sctx); - return ret; -} - -#ifndef OPENSSL_NO_TLS1_2 -static int test_construct_ch_ech_tls12(void) -{ - CH_CONFIG cfg = { 0, TLS1_2_VERSION, TLS1_2_VERSION, 0 }; - - /* ECH requires TLS 1.3: the inner construct fails the version check. */ - return do_construct_ch_expect_fail(&cfg, prep_ech, 0, 0); -} -#endif /* OPENSSL_NO_TLS1_2 */ - -static int mfail_construct_ch_ech(void) -{ - CH_CONFIG cfg = { 0, TLS1_3_VERSION, TLS1_3_VERSION, 0 }; - - return mfail_construct_ch_common(&cfg, prep_ech); -} -#endif /* OSSL_NO_USABLE_ECH */ - -/* - * =========================================================================== - * tls_construct_end_of_early_data - * =========================================================================== - */ - -#ifndef OSSL_NO_USABLE_TLS1_3 -/* - * EndOfEarlyData carries no body and only advances early_data_state; it is - * valid only from the WRITE_RETRY/FINISHED_WRITING states. - */ -static int do_construct_eoed(int state, CON_FUNC_RETURN expect) -{ - CH_CONFIG cfg = { 0, TLS1_3_VERSION, TLS1_3_VERSION, 0 }; - SSL_CTX *cctx = NULL; - SSL *ssl = NULL; - SSL_CONNECTION *s; - WPACKET pkt; - unsigned char *msg = NULL; - size_t msglen = 0; - int have_pkt = 0; - int ret = 0; - - if (!TEST_ptr(cctx = new_ctx(&cfg, client_method(&cfg))) - || !TEST_ptr(ssl = SSL_new(cctx)) - || !prime_ssl(ssl, 1, 0, &pkt, SSL3_MT_END_OF_EARLY_DATA)) - goto err; - have_pkt = 1; - s = SSL_CONNECTION_FROM_SSL(ssl); - s->early_data_state = state; - - if (!TEST_int_eq(tls_construct_end_of_early_data(s, &pkt), expect)) - goto err; - - if (expect == CON_FUNC_SUCCESS) { - /* State advances and the body is empty (only the header is written). */ - if (!TEST_int_eq(s->early_data_state, SSL_EARLY_DATA_FINISHED_WRITING) - || !finish_msg(ssl, &pkt, SSL3_MT_END_OF_EARLY_DATA, &msg, &msglen)) - goto err; - have_pkt = 0; - if (!TEST_size_t_eq(msglen, hdr_len(&cfg))) - goto err; - } - - ret = 1; -err: - if (have_pkt) - WPACKET_cleanup(&pkt); - SSL_free(ssl); - SSL_CTX_free(cctx); - return ret; -} - -static int test_construct_eoed(void) -{ - return do_construct_eoed(SSL_EARLY_DATA_WRITE_RETRY, CON_FUNC_SUCCESS); -} - -static int test_construct_eoed_bad_state(void) -{ - /* Called from an unexpected state: CON_FUNC_ERROR, nothing written. */ - return do_construct_eoed(SSL_EARLY_DATA_NONE, CON_FUNC_ERROR); -} -#endif /* OSSL_NO_USABLE_TLS1_3 */ - -/* - * =========================================================================== - * tls_construct_client_certificate - * =========================================================================== - */ - -#if !defined(OSSL_NO_USABLE_TLS1_3) || !defined(OPENSSL_NO_TLS1_2) -/* Self-signed client cert + signing-capable key; regenerate with the - * statem_clnt_construct_test ossl-test-tools subcommand. */ -static const char *kClientCert[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIIDvzCCAqegAwIBAgICAQAwDQYJKoZIhvcNAQELBQAwgYExCzAJBgNVBAYTAlVT\n", - "MRAwDgYDVQQIDAdXeW9taW5nMREwDwYDVQQHDAhDaGV5ZW5uZTEVMBMGA1UECgwM\n", - "T3BlblNTTCBUZXN0MRQwEgYDVQQLDAtzdGF0ZW1fY2xudDEgMB4GA1UEAwwXc3Rh\n", - "dGVtX2NsbnQgdGVzdCBjbGllbnQwHhcNMjYwMTAxMDAwMDAwWhcNNDYwMTAxMDAw\n", - "MDAwWjCBgTELMAkGA1UEBhMCVVMxEDAOBgNVBAgMB1d5b21pbmcxETAPBgNVBAcM\n", - "CENoZXllbm5lMRUwEwYDVQQKDAxPcGVuU1NMIFRlc3QxFDASBgNVBAsMC3N0YXRl\n", - "bV9jbG50MSAwHgYDVQQDDBdzdGF0ZW1fY2xudCB0ZXN0IGNsaWVudDCCASIwDQYJ\n", - "KoZIhvcNAQEBBQADggEPADCCAQoCggEBAMnUvJvluB2ZUoQNQlW4wgv0qceITB5X\n", - "cHQe60H1CMTapaRi32dpwEzoEMnMjULcrZshcTAkdke6J1ubJ6qviGp7n1kVYH18\n", - "rGYYk6VT+GPb/SZnjMX3+e5WEpH+53UEGVvBPHl/med0AzklOOf/0hDlMFzMBejA\n", - "z+T++88QIT19BoIwfilcMDZxE0uXbq3QLpugADGd93zLSCwM1vxd9Vi0EwyMpy7Q\n", - "Ot9eIR/+ML0HESXZ1AvVcLjvuhqm+xkNiR9qil68zqgJk+dUpK5hCpLBi7cfBpk7\n", - "jLultF09up6G3Y5KiXd8wS9upwJZXA9+9OKHTf05w4xWAA/kpp9gt0MCAwEAAaM/\n", - "MD0wDAYDVR0TAQH/BAIwADAOBgNVHQ8BAf8EBAMCB4AwHQYDVR0OBBYEFM9Nespo\n", - "NSyfQO8jPjRl4JfH5kOsMA0GCSqGSIb3DQEBCwUAA4IBAQBtTgy5ePCHR+iu3Ign\n", - "wlJzL5+zkWOkQsbAzJsbWrvzqwx2shXr1adM7OJy7tCkmDgwHsXjTTO2qAZrlmYQ\n", - "ktGA/UAtttIqgiiYcyGdrZas2vXUWLUps5YzMm4YdY8YNTvqQl3LCziUhO5YREDP\n", - "teXy4FF6ijGUDe84CYsmKvtbIn34LtZ2Vo3gsiRHvdiaxHavH30UqED9k4NjKnFx\n", - "XM6eMw+bs0Yl1vi/Dz5tHPRaAnsGvnKcEveSAdAoSWmodw8n8W5t8ZvPoPCoKz88\n", - "DOGzUvLma/kVL+3HLiSn6XFiQ2NLfO9ceUgDsSzcRo76XZHJnfGsK6Iewgje3NrB\n", - "WnZs\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -static const char *kClientKey[] = { - "-----BEGIN RSA PRIVATE KEY-----\n", - "MIIEowIBAAKCAQEAydS8m+W4HZlShA1CVbjCC/Spx4hMHldwdB7rQfUIxNqlpGLf\n", - "Z2nATOgQycyNQtytmyFxMCR2R7onW5snqq+IanufWRVgfXysZhiTpVP4Y9v9JmeM\n", - "xff57lYSkf7ndQQZW8E8eX+Z53QDOSU45//SEOUwXMwF6MDP5P77zxAhPX0GgjB+\n", - "KVwwNnETS5durdAum6AAMZ33fMtILAzW/F31WLQTDIynLtA6314hH/4wvQcRJdnU\n", - "C9VwuO+6Gqb7GQ2JH2qKXrzOqAmT51SkrmEKksGLtx8GmTuMu6W0XT26nobdjkqJ\n", - "d3zBL26nAllcD3704odN/TnDjFYAD+Smn2C3QwIDAQABAoIBAGAjkzIJczG6MmmP\n", - "bU0q5FfQk7zlaii7yuetQK/a2fH3GpbauALpBz46/qA5bQJv3sw52lIt1B+nhw7m\n", - "MbdmxKrANy+2dI9hvzckttO2U2exxvyvr4kvbWB/pHnhu3vsV23y9m0DgJqVEuH6\n", - "Hoi4PWZp3aceUiRED+NLKERCMSs5lPSSWR7sUkzHku4x5fZXZppcQW4leo+Z/kNC\n", - "I36CGF4pI9FJXwcuRhbv3NsFMVl/Ng4hWgzgu7zwJEPw2OSKyhdwHV53qGQWyMnJ\n", - "7SawyQfyspKlMZnjWxplFZ5tgaV6O63zZZPEOC2mZNeiZKWC9Lut/wyriLs+W4w7\n", - "9BBX3q0CgYEA94sgemr3rGY2R+9kiPV/TC08IUflMJ7kt0epDDRnojWqobinJzQG\n", - "Nq25i5vZHbjn9g7l2hNmOcHVZZmCYZitmjwWr4ibthftU7+H6WkvcBvH6b6EmHQm\n", - "5IGtOxYPmtf2Ghnj1uQmsBe9vRYcqx7B8/anqRi3lQhebykkII0MLR8CgYEA0LnV\n", - "vXaFAwLOta4Kn43mXC6sVRRMt316d70zRpVRsSQ64TdhtwArmKq3RUmLH2r3ysRL\n", - "6+mxEGJriL7JERH3Jlm0YGsUUQvQWxCddccuTQRc16+UVt7+xzfhzJZNTD4+t0aA\n", - "jsVLpPQHzXI8Yqzh1p83oC4XV4hCYZNLlfleTV0CgYBWIG/yZ9k4gG+OY7pk9JWP\n", - "2YU8Rxl06zPEmQg2GN2d0HJHxklSGIW47ITMEDNgZf8+2zwZvfopSkmHCfwVHNv5\n", - "98Ik3LDgkD6gjtko2tIIfYH2z7SunmsRwhSVpD1VsKINvshI8iSLzBbV/SWIXDE7\n", - "Qqxe5xyom7rPjk7ljG2aHQKBgB36oxV8YWxmSdRUdBgopG6XEY+Cw+YS8rUiCqxX\n", - "pA0iXAafErzbHGfoFTyxbHcNwRtxiEoRHapxyGoypOR7xRjQB5VVq+xcGwgJYeRZ\n", - "wG+1cbRU9qRnkQaCIz9kUyPhSNbAHJTlB5Fgr4I1pzCxDhrqcW3jUNz0qDwlkNSw\n", - "pXfNAoGBAKlFbbPEzFonlkHVtdUuk6Chsi5k/ddrWsGxwUw5F5BSu0UaseolVls5\n", - "TyDVa8FEfDnUZRxl8HSfC/Qp/kAdveGKyhNaex22L5G8m20rXjsQBMFHMOy2Mho1\n", - "hgs0/emKuVyCs+wnYOqJlWZ8Vf/qGcUtDF3r4aEZ1JUDhUBAVEpo\n", - "-----END RSA PRIVATE KEY-----\n", - NULL -}; - -static int load_cert_and_key(SSL *ssl) -{ - X509 *cert = NULL; - EVP_PKEY *pkey = NULL; - int ret = 0; - - if (!TEST_ptr(cert = X509_from_strings(kClientCert)) - || !TEST_ptr(pkey = PKEY_from_strings(kClientKey)) - || !TEST_int_eq(SSL_use_certificate(ssl, cert), 1) - || !TEST_int_eq(SSL_use_PrivateKey(ssl, pkey), 1)) - goto err; - ret = 1; -err: - X509_free(cert); - EVP_PKEY_free(pkey); - return ret; -} - -/* - * Run tls_construct_client_certificate() under mfail; prep installs the cert - * material. For TLS 1.3 the method is swapped in (IS_TLS13 keys off it) and - * middlebox compat cleared to skip the write-key change. - */ -static int mfail_construct_cert(int is_tls13, int (*prep)(SSL_CONNECTION *s)) -{ - CH_CONFIG cfg = { 0, 0, 0, 0 }; - SSL_CTX *cctx = NULL; - SSL *ssl = NULL; - SSL_CONNECTION *s; - WPACKET pkt; - int ok = 0; - int ret = 0; - - if (!TEST_ptr(cctx = new_ctx(&cfg, client_method(&cfg))) - || !TEST_ptr(ssl = SSL_new(cctx))) - goto err; - if (is_tls13) - SSL_clear_options(ssl, SSL_OP_ENABLE_MIDDLEBOX_COMPAT); - if (!prime_ssl(ssl, 1, 0, &pkt, SSL3_MT_CERTIFICATE)) - goto err; - s = SSL_CONNECTION_FROM_SSL(ssl); -#ifndef OSSL_NO_USABLE_TLS1_3 - if (is_tls13) - ssl->method = tlsv1_3_client_method(); -#endif - - if (prep != NULL && !prep(s)) { - WPACKET_cleanup(&pkt); - goto err; - } - - MFAIL_start(); - ok = (tls_construct_client_certificate(s, &pkt) == CON_FUNC_SUCCESS); - MFAIL_end(); - - WPACKET_cleanup(&pkt); - - ret = ok ? 1 : 0; -err: - SSL_free(ssl); - SSL_CTX_free(cctx); - return ret; -} -#endif /* TLS 1.2 or usable TLS 1.3 */ - -#ifndef OSSL_NO_USABLE_TLS1_3 -/* x509 over TLS 1.3; NO_AUTO_CHAIN avoids best-effort verify swallowing OOM. */ -static int prep_cert_x509(SSL_CONNECTION *s) -{ - SSL *ssl = SSL_CONNECTION_GET_SSL(s); - - SSL_set_mode(ssl, SSL_MODE_NO_AUTO_CHAIN); - return load_cert_and_key(ssl); -} - -static int mfail_construct_cert_x509(void) -{ - return mfail_construct_cert(1, prep_cert_x509); -} -#endif /* OSSL_NO_USABLE_TLS1_3 */ - -#ifndef OPENSSL_NO_TLS1_2 -/* RPK derived from the certificate public key over TLS 1.2 (tls_output_rpk). */ -static int prep_cert_rpk(SSL_CONNECTION *s) -{ - if (!load_cert_and_key(SSL_CONNECTION_GET_SSL(s))) - return 0; - s->ext.client_cert_type = TLSEXT_cert_type_rpk; - return 1; -} - -static int mfail_construct_cert_rpk(void) -{ - return mfail_construct_cert(0, prep_cert_rpk); -} -#endif /* OPENSSL_NO_TLS1_2 */ - -/* Deterministic error branches that mfail (allocation-only) cannot reach. */ - -/* An unrecognized certificate type is rejected. */ -static int test_construct_cert_bad_type(void) -{ - CH_CONFIG cfg = { 0, 0, 0, 0 }; - SSL_CTX *cctx = NULL; - SSL *ssl = NULL; - SSL_CONNECTION *s; - WPACKET pkt; - int have_pkt = 0; - int ret = 0; - - if (!TEST_ptr(cctx = new_ctx(&cfg, client_method(&cfg))) - || !TEST_ptr(ssl = SSL_new(cctx)) - || !prime_ssl(ssl, 1, 0, &pkt, SSL3_MT_CERTIFICATE)) - goto err; - have_pkt = 1; - s = SSL_CONNECTION_FROM_SSL(ssl); - s->ext.client_cert_type = 0xff; - - if (!TEST_int_eq(tls_construct_client_certificate(s, &pkt), CON_FUNC_ERROR)) - goto err; - - ret = 1; -err: - if (have_pkt) - WPACKET_cleanup(&pkt); - SSL_free(ssl); - SSL_CTX_free(cctx); - return ret; -} - -#ifndef OSSL_NO_USABLE_TLS1_3 -/* - * With middlebox compat on, the TLS 1.3 path changes the write keys; without a - * negotiated cipher that fails rather than succeeding. - */ -static int test_construct_cert_change_cipher_fail(void) -{ - CH_CONFIG cfg = { 0, 0, 0, 0 }; - SSL_CTX *cctx = NULL; - SSL *ssl = NULL; - SSL_CONNECTION *s; - WPACKET pkt; - int have_pkt = 0; - int ret = 0; - - if (!TEST_ptr(cctx = new_ctx(&cfg, client_method(&cfg))) - || !TEST_ptr(ssl = SSL_new(cctx)) - || !prime_ssl(ssl, 1, 0, &pkt, SSL3_MT_CERTIFICATE)) - goto err; - have_pkt = 1; - s = SSL_CONNECTION_FROM_SSL(ssl); - ssl->method = tlsv1_3_client_method(); - - if (!TEST_int_eq(tls_construct_client_certificate(s, &pkt), CON_FUNC_ERROR)) - goto err; - - ret = 1; -err: - if (have_pkt) - WPACKET_cleanup(&pkt); - SSL_free(ssl); - SSL_CTX_free(cctx); - return ret; -} - -/* - * A WPACKET failure while writing the TLS 1.3 certificate_request_context - * yields CON_FUNC_ERROR. with_pha exercises the non-empty-context branch. - */ -static int do_construct_cert_ctx_small_buf(int with_pha) -{ - CH_CONFIG cfg = { 0, 0, 0, 0 }; - SSL_CTX *cctx = NULL; - SSL *ssl = NULL; - SSL_CONNECTION *s; - WPACKET pkt; - unsigned char buf[16]; - int have_pkt = 0; - int ret = 0; - - if (!TEST_ptr(cctx = new_ctx(&cfg, client_method(&cfg))) - || !TEST_ptr(ssl = SSL_new(cctx))) - goto err; - SSL_set_connect_state(ssl); - s = SSL_CONNECTION_FROM_SSL(ssl); - if (!TEST_ptr(s) - || !TEST_ptr(s->init_buf = BUF_MEM_new()) - || !TEST_true(BUF_MEM_grow(s->init_buf, SSL3_RT_MAX_PLAIN_LENGTH)) - || !TEST_true(tls_setup_handshake(s))) - goto err; - ssl->method = tlsv1_3_client_method(); - - if (with_pha) { - if (!TEST_ptr(s->pha_context = OPENSSL_malloc(4))) - goto err; - s->pha_context_len = 4; - } - - /* Only the handshake header fits, so the context write overflows. */ - if (!TEST_true(WPACKET_init_static_len(&pkt, buf, hdr_len(&cfg), 0))) - goto err; - have_pkt = 1; - if (!TEST_true(ssl_set_handshake_header(s, &pkt, SSL3_MT_CERTIFICATE))) - goto err; - - if (!TEST_int_eq(tls_construct_client_certificate(s, &pkt), CON_FUNC_ERROR)) - goto err; - - ret = 1; -err: - if (have_pkt) - WPACKET_cleanup(&pkt); - SSL_free(ssl); - SSL_CTX_free(cctx); - return ret; -} - -static int test_construct_cert_ctx_small_buf(void) -{ - return do_construct_cert_ctx_small_buf(0); -} - -static int test_construct_cert_pha_ctx_small_buf(void) -{ - return do_construct_cert_ctx_small_buf(1); -} -#endif /* OSSL_NO_USABLE_TLS1_3 */ - -int setup_tests(void) -{ - ADD_TEST(test_construct_ch_small_buf); - ADD_TEST(test_construct_ch_no_ciphers); - -#ifndef OPENSSL_NO_TLS1_2 - ADD_TEST(test_construct_ch_tls12); - ADD_TEST(test_construct_ch_resume); - ADD_MFAIL_TEST(mfail_construct_ch_tls12); -#endif - -#ifndef OSSL_NO_USABLE_TLS1_3 - ADD_TEST(test_construct_ch_tls13); - ADD_TEST(test_construct_ch_tls13_no_middlebox); - ADD_TEST(test_construct_ch_hrr); - ADD_TEST(test_construct_eoed); - ADD_TEST(test_construct_eoed_bad_state); -#if defined(OPENSSL_NO_ECX) - /* - * Without ECX the key_share falls back to EC keygen, which makes a - * best-effort param-cache allocation whose failure does not propagate; - * only crash/leak checking is meaningful then. - * - * No caching also needs no check. - */ - ADD_MFAIL_NO_CHECK_TEST(mfail_construct_ch_tls13); -#else - ADD_MFAIL_TEST(mfail_construct_ch_tls13); -#endif /* OPENSSL_NO_ECX */ -#endif /* OSSL_NO_USABLE_TLS1_3 */ - -#if !defined(OPENSSL_NO_DTLS) && !defined(OPENSSL_NO_DTLS1_2) - ADD_TEST(test_construct_ch_dtls); - ADD_TEST(test_construct_ch_dtls_cookie); - ADD_TEST(test_construct_ch_dtls_client_random); -#endif - -#ifndef OSSL_NO_USABLE_ECH - ADD_TEST(test_construct_ch_ech); -#ifndef OPENSSL_NO_TLS1_2 - ADD_TEST(test_construct_ch_ech_tls12); -#endif - ADD_MFAIL_TEST(mfail_construct_ch_ech); -#endif /* OSSL_NO_USABLE_ECH */ - - /* tls_construct_client_certificate: OOM coverage of the output functions. */ -#ifndef OSSL_NO_USABLE_TLS1_3 - ADD_MFAIL_TEST(mfail_construct_cert_x509); -#endif -#ifndef OPENSSL_NO_TLS1_2 - ADD_MFAIL_TEST(mfail_construct_cert_rpk); -#endif - ADD_TEST(test_construct_cert_bad_type); -#ifndef OSSL_NO_USABLE_TLS1_3 - ADD_TEST(test_construct_cert_change_cipher_fail); - ADD_TEST(test_construct_cert_ctx_small_buf); - ADD_TEST(test_construct_cert_pha_ctx_small_buf); -#endif - return 1; -} diff --git a/test/sysdefaulttest.c b/test/sysdefaulttest.c index 6e3b53e3b9..a2354c6331 100644 --- a/test/sysdefaulttest.c +++ b/test/sysdefaulttest.c @@ -11,7 +11,6 @@ #include #include -#include #include #include #include @@ -36,8 +35,6 @@ static int test_func(void) TEST_info("min/max version setting incorrect"); goto err; } - if (!TEST_long_eq(ERR_peek_error(), 0)) - goto err; } ret = 1; err: diff --git a/test/test.cnf b/test/test.cnf index a4d8355c5b..3d1a823a7a 100644 --- a/test/test.cnf +++ b/test/test.cnf @@ -8,6 +8,7 @@ default_ca = CA_default # The default ca section dir = ./demoCA # Where everything is kept certs = $dir/certs # Where the issued certs are kept +crl_dir = $dir/crl # Where the issued crl are kept database = $dir/index.txt # database index file. new_certs_dir = $dir/new_certs # default place for new certs. diff --git a/test/test_asn1_genconf.cnf b/test/test_asn1_genconf.cnf deleted file mode 100644 index 946bab7962..0000000000 --- a/test/test_asn1_genconf.cnf +++ /dev/null @@ -1,5 +0,0 @@ -asn1=SEQUENCE:seq - -[seq] -impl=IMPLICIT:1,BOOL:true -expl=EXPLICIT:2,BITWRAP,OCT:X diff --git a/test/testutil.h b/test/testutil.h index 7e23f53827..f0b6c6ad5e 100644 --- a/test/testutil.h +++ b/test/testutil.h @@ -1,5 +1,5 @@ /* - * Copyright 2014-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2014-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -12,7 +12,6 @@ #include #include "internal/common.h" /* for HAS_PREFIX */ -#include "internal/err.h" /* for ERR_NUM_ERRORS */ #include #include @@ -20,7 +19,6 @@ #include #include #include "opt.h" -#include "mfail/mfail.h" /*- * Simple unit tests should implement setup_tests(). @@ -58,48 +56,6 @@ */ #define ADD_ALL_TESTS(test_function, num) \ add_all_tests(#test_function, test_function, num, 1) - -/* - * Memory failure exhaustive test. Runs test_fn repeatedly, each time - * injecting an allocation failure one step later. When a failure is - * injected, asserts test_fn returns 0. When no failure is injected - * (all allocation points exhausted), asserts test_fn returns 1 and stops. - * - * The NO_CHECK variant disables the assertion that failed tests must - * result in function failure. - * - * test_fn has no parameters and returns 1 on success, 0 on failure. - */ - -/* Per-test flags for add_mfail_test() */ -#define MFAIL_TEST_NO_CHECK (1 << 0) -#define MFAIL_TEST_SAMPLED (1 << 1) - -#define ADD_MFAIL_TEST(test_fn) \ - add_mfail_test(#test_fn, test_fn, 0, 0) -#define ADD_MFAIL_NO_CHECK_TEST(test_fn) \ - add_mfail_test(#test_fn, test_fn, MFAIL_TEST_NO_CHECK, 0) - -/* Caps injection at |cnt| points (exhaustive when allocations <= cnt) */ -#define ADD_MFAIL_SAMPLED_TEST(test_fn, cnt) \ - add_mfail_test(#test_fn, test_fn, MFAIL_TEST_SAMPLED, cnt) -#define ADD_MFAIL_SAMPLED_NO_CHECK_TEST(test_fn, cnt) \ - add_mfail_test(#test_fn, test_fn, \ - MFAIL_TEST_NO_CHECK | MFAIL_TEST_SAMPLED, cnt) - -/* Runs the exhaustive mfail cycle for each 0 <= idx < num */ -#define ADD_MFAIL_ALL_TESTS(test_fn, num) \ - add_mfail_all_tests(#test_fn, test_fn, num, 0, 0) -#define ADD_MFAIL_ALL_NO_CHECK_TESTS(test_fn, num) \ - add_mfail_all_tests(#test_fn, test_fn, num, MFAIL_TEST_NO_CHECK, 0) - -/* Sampled variants of the above */ -#define ADD_MFAIL_SAMPLED_ALL_TESTS(test_fn, num, cnt) \ - add_mfail_all_tests(#test_fn, test_fn, num, MFAIL_TEST_SAMPLED, cnt) -#define ADD_MFAIL_SAMPLED_ALL_NO_CHECK_TESTS(test_fn, num, cnt) \ - add_mfail_all_tests(#test_fn, test_fn, num, \ - MFAIL_TEST_NO_CHECK | MFAIL_TEST_SAMPLED, cnt) - /* * A variant of the same without TAP output. */ @@ -270,13 +226,6 @@ int test_arg_libctx(OSSL_LIB_CTX **libctx, OSSL_PROVIDER **default_null_prov, void add_test(const char *test_case_name, int (*test_fn)(void)); void add_all_tests(const char *test_case_name, int (*test_fn)(int idx), int num, int subtest); -void add_mfail_test(const char *test_case_name, int (*test_fn)(void), - int flags, int sampled); -void add_mfail_all_tests(const char *test_case_name, int (*test_fn)(int idx), - int num, int flags, int sampled); - -#define MFAIL_start mfail_start -#define MFAIL_end mfail_end /* * Declarations for user defined functions. @@ -337,11 +286,18 @@ const OPTIONS *test_get_options(void); */ #define PRINTF_FORMAT(a, b) -#if defined(__GNUC__) && !defined(__MINGW32__) && !defined(__MINGW64__) \ +#if defined(__GNUC__) && defined(__STDC_VERSION__) \ + && !defined(__MINGW32__) && !defined(__MINGW64__) \ && !defined(__APPLE__) +/* + * Because we support the 'z' modifier, which made its appearance in C99, + * we can't use __attribute__ with pre C99 dialects. + */ +#if __STDC_VERSION__ >= 199901L #undef PRINTF_FORMAT #define PRINTF_FORMAT(a, b) __attribute__((format(printf, a, b))) #endif +#endif #define DECLARE_COMPARISON(type, name, opname) \ int test_##name##_##opname(const char *, int, \ @@ -399,9 +355,9 @@ DECLARE_COMPARISON(char *, str, ne) * Same as above, but for strncmp. */ int test_strn_eq(const char *file, int line, const char *, const char *, - const char *a, const char *b, size_t n); + const char *a, size_t an, const char *b, size_t bn); int test_strn_ne(const char *file, int line, const char *, const char *, - const char *a, const char *b, size_t n); + const char *a, size_t an, const char *b, size_t bn); /* * Equality test for memory blocks where NULL is a legitimate value. @@ -423,23 +379,6 @@ int test_mem_ne(const char *, int, const char *, const char *, int test_true(const char *file, int line, const char *s, int b); int test_false(const char *file, int line, const char *s, int b); -/* - * Checks whether a specific error reason is present in the error stack. - * This function iterates over the current thread's error queue extracting all - * pending errors. If any of them match the specified reason code (as returned - * by ERR_GET_REASON()), the function returns 1 to indicate that the - * corresponding error was found. - */ -int test_err_r(const char *file, int line, int lib, int reason); - -/* - * Checks whether a specific string is present in the error data stack. - * This function iterates over the current thread's error queue extracting all - * pending errors. If any of them match the specified string the function - * returns 1 to indicate that the corresponding error was found. - */ -int test_err_s(const char *file, int line, const char *data); - /* * Comparisons between BIGNUMs. * BIGNUMS can be compared against other BIGNUMs or zero. @@ -572,8 +511,10 @@ void test_perror(const char *s); #define TEST_str_eq(a, b) test_str_eq(__FILE__, __LINE__, #a, #b, a, b) #define TEST_str_ne(a, b) test_str_ne(__FILE__, __LINE__, #a, #b, a, b) -#define TEST_strn_eq(a, b, n) test_strn_eq(__FILE__, __LINE__, #a, #b, a, b, n) -#define TEST_strn_ne(a, b, n) test_strn_ne(__FILE__, __LINE__, #a, #b, a, b, n) +#define TEST_strn_eq(a, b, n) test_strn_eq(__FILE__, __LINE__, #a, #b, a, n, b, n) +#define TEST_strn_ne(a, b, n) test_strn_ne(__FILE__, __LINE__, #a, #b, a, n, b, n) +#define TEST_strn2_eq(a, m, b, n) test_strn_eq(__FILE__, __LINE__, #a, #b, a, m, b, n) +#define TEST_strn2_ne(a, m, b, n) test_strn_ne(__FILE__, __LINE__, #a, #b, a, m, b, n) #define TEST_mem_eq(a, m, b, n) test_mem_eq(__FILE__, __LINE__, #a, #b, a, m, b, n) #define TEST_mem_ne(a, m, b, n) test_mem_ne(__FILE__, __LINE__, #a, #b, a, m, b, n) @@ -581,9 +522,6 @@ void test_perror(const char *s); #define TEST_true(a) test_true(__FILE__, __LINE__, #a, (a) != 0) #define TEST_false(a) test_false(__FILE__, __LINE__, #a, (a) != 0) -#define TEST_err_r(a, b) test_err_r(__FILE__, __LINE__, a, b) -#define TEST_err_s(a) test_err_s(__FILE__, __LINE__, a) - #define TEST_BN_eq(a, b) test_BN_eq(__FILE__, __LINE__, #a, #b, a, b) #define TEST_BN_ne(a, b) test_BN_ne(__FILE__, __LINE__, #a, #b, a, b) #define TEST_BN_lt(a, b) test_BN_lt(__FILE__, __LINE__, #a, #b, a, b) @@ -720,10 +658,6 @@ X509 *X509_from_strings(const char **pem); * Create a CRL from an array of strings. */ X509_CRL *CRL_from_strings(const char **pem); -/* - * Create a PKEY from an array of strings. - */ -EVP_PKEY *PKEY_from_strings(const char **pem); /* * Glue an array of strings together. Return a BIO and put the string * into |*out| so we can free it. diff --git a/test/testutil/driver.c b/test/testutil/driver.c index bfcb65b7bc..1097c68fc3 100644 --- a/test/testutil/driver.c +++ b/test/testutil/driver.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2023 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -19,9 +19,6 @@ #include "platform.h" /* From libapps */ -#include "mfail.h" -#include - #if defined(_WIN32) && !defined(__BORLANDC__) #define strdup _strdup #endif @@ -36,10 +33,7 @@ typedef struct test_info { int num; /* flags */ - unsigned int subtest : 1; - unsigned int mfail : 1; - int mfail_flags; - int mfail_sampled; + int subtest : 1; } TEST_INFO; static TEST_INFO all_tests[1024]; @@ -85,35 +79,6 @@ void add_all_tests(const char *test_case_name, int (*test_fn)(int idx), num_test_cases += num; } -void add_mfail_test(const char *test_case_name, int (*test_fn)(void), int flags, - int sampled) -{ - assert(num_tests != OSSL_NELEM(all_tests)); - all_tests[num_tests].test_case_name = test_case_name; - all_tests[num_tests].test_fn = test_fn; - all_tests[num_tests].num = -1; - all_tests[num_tests].mfail = 1; - all_tests[num_tests].mfail_flags = flags; - all_tests[num_tests].mfail_sampled = sampled; - ++num_tests; - ++num_test_cases; -} - -void add_mfail_all_tests(const char *test_case_name, int (*test_fn)(int idx), - int num, int flags, int sampled) -{ - assert(num_tests != OSSL_NELEM(all_tests)); - all_tests[num_tests].test_case_name = test_case_name; - all_tests[num_tests].param_test_fn = test_fn; - all_tests[num_tests].num = num; - all_tests[num_tests].subtest = 1; - all_tests[num_tests].mfail = 1; - all_tests[num_tests].mfail_flags = flags; - all_tests[num_tests].mfail_sampled = sampled; - ++num_tests; - ++num_test_cases; -} - static int gcd(int a, int b) { while (b != 0) { @@ -313,112 +278,6 @@ static void test_verdict(int verdict, test_flush_tapout(); } -static double mfail_elapsed_secs(clock_t start) -{ - return (double)(clock() - start) / CLOCKS_PER_SEC; -} - -static int mfail_run_test(const TEST_INFO *t, int idx) -{ - int counting_ok = 1; - int injection_ok = 1; - int injections = 0; - int allocations = 0; - int no_check = (t->mfail_flags & MFAIL_TEST_NO_CHECK) != 0; - int sampled = (t->mfail_flags & MFAIL_TEST_SAMPLED) != 0; - int init_flags = no_check ? MFAIL_FLAG_NO_CHECK : 0; - clock_t start = clock(); - - if (sampled) - /* cap injection at mfail_sampled points (exhaustive below that) */ - init_flags |= MFAIL_FLAG_COUNT; -#ifdef OPENSSL_NO_CACHED_FETCH - else - /* - * The non-cached does too many allocations, which results in a - * significant slowdown of the tests. It does not provide much value, - * as it also requires NO_CHECK variant, so just run counting - * correctness check and skip the memory failure injection part. - */ - init_flags |= MFAIL_FLAG_COUNT_ONLY; -#endif - - level += 4; - test_adjust_streams_tap_level(level); - test_printf_stdout("Subtest: %s[%d]\n", t->test_case_name, idx); - test_printf_tapout("1..2\n"); - test_flush_stdout(); - test_flush_tapout(); - - mfail_init_ex(idx, init_flags, t->mfail_sampled); - - while (mfail_has_next()) { - int phase = mfail_get_phase(); - int rv; - - ERR_clear_error(); - rv = t->param_test_fn != NULL ? t->param_test_fn(idx) : t->test_fn(); - - if (phase == MFAIL_PHASE_COUNTING) { - allocations = mfail_get_count(); - if (!TEST_int_eq(rv, 1)) { - TEST_error("mfail test '%s': counting iteration failed", - t->test_case_name); - counting_ok = 0; - } - test_verdict(counting_ok, "1 - counting (%d allocations)", - allocations); - if (!counting_ok || !mfail_is_installed() || mfail_env_skip_all()) - break; - } else { - injections++; - if (rv == -1) { - TEST_error("mfail test '%s': unconditional failure at " - "point %d", - t->test_case_name, mfail_get_point()); - injection_ok = 0; - } else if (mfail_was_triggered()) { - if (!no_check && !TEST_int_eq(rv, 0)) { - TEST_error("mfail test '%s': allocation failure at " - "point %d not handled", - t->test_case_name, mfail_get_point()); - injection_ok = 0; - } - } else if (mfail_get_mode() == MFAIL_MODE_SINGLE) { - test_printf_tapout( - "# point %d is beyond the last allocation point\n", - mfail_get_point()); - test_flush_tapout(); - } else if (!TEST_int_eq(rv, 1)) { - TEST_error("mfail test '%s': no injection but test failed", - t->test_case_name); - injection_ok = 0; - } - } - } - - if (!counting_ok) - test_verdict(TEST_SKIP_CODE, "2 - injection (counting failed)"); - else if (!mfail_is_installed()) - test_verdict(TEST_SKIP_CODE, "2 - injection (mfail not installed)"); - else if (mfail_env_skip_all()) - test_verdict(TEST_SKIP_CODE, "2 - injection (mfail skip-all set)"); - else if (mfail_is_count_only()) - test_verdict(TEST_SKIP_CODE, "2 - injection (count only)"); - else if (mfail_was_slow_skipped()) - test_verdict(TEST_SKIP_CODE, - "2 - injection (%d allocations exceeds slow threshold %d)", - allocations, mfail_get_slow_threshold()); - else - test_verdict(injection_ok, "2 - injection (%d iterations, %.3fs)", - injections, mfail_elapsed_secs(start)); - - level -= 4; - test_adjust_streams_tap_level(level); - - return counting_ok && injection_ok; -} - int run_tests(const char *test_prog_name) { int num_failed = 0; @@ -474,10 +333,7 @@ int run_tests(const char *test_prog_name) } else if (all_tests[i].num == -1) { set_test_title(all_tests[i].test_case_name); ERR_clear_error(); - if (all_tests[i].mfail) - verdict = mfail_run_test(&all_tests[i], 0); - else - verdict = all_tests[i].test_fn(); + verdict = all_tests[i].test_fn(); finalize(verdict != 0); test_verdict(verdict, "%d - %s", test_case_count + 1, test_title); if (verdict == 0) @@ -512,10 +368,7 @@ int run_tests(const char *test_prog_name) if (single_iter != -1 && ((jj + 1) != single_iter)) continue; ERR_clear_error(); - if (all_tests[i].mfail) - v = mfail_run_test(&all_tests[i], j); - else - v = all_tests[i].param_test_fn(j); + v = all_tests[i].param_test_fn(j); if (v == 0) { verdict = 0; diff --git a/test/testutil/format_output.c b/test/testutil/format_output.c index 5bb5302989..842a4543bf 100644 --- a/test/testutil/format_output.c +++ b/test/testutil/format_output.c @@ -385,8 +385,7 @@ void test_fail_bignum_mono_message(const char *prefix, const char *file, void test_output_bignum(const char *name, const BIGNUM *bn) { if (bn == NULL || BN_is_zero(bn)) { - test_printf_stderr("bignum: '%s' = %s\n", - name == NULL ? "" : name, + test_printf_stderr("bignum: '%s' = %s\n", name, test_bignum_zero_null(bn)); } else if (BN_num_bytes(bn) <= BN_OUTPUT_SIZE) { unsigned char buf[BN_OUTPUT_SIZE]; @@ -397,8 +396,7 @@ void test_output_bignum(const char *name, const BIGNUM *bn) hex_convert_memory(buf, n, p, BN_OUTPUT_SIZE); while (*p == '0' && *++p != '\0') ; - test_printf_stderr("bignum: '%s' = %s0x%s\n", - name == NULL ? "" : name, + test_printf_stderr("bignum: '%s' = %s0x%s\n", name, BN_is_negative(bn) ? "-" : "", p); } else { test_fail_bignum_common("bignum", NULL, 0, NULL, NULL, NULL, name, diff --git a/test/testutil/load.c b/test/testutil/load.c index 1c6bc8fcd4..3af2ddd53d 100644 --- a/test/testutil/load.c +++ b/test/testutil/load.c @@ -1,5 +1,5 @@ /* - * Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2020-2021 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -130,7 +130,6 @@ X509_CRL *CRL_from_strings(const char **pem) return NULL; } - ERR_clear_error(); crl = PEM_read_bio_X509_CRL(b, NULL, NULL, NULL); OPENSSL_free(p); @@ -152,31 +151,9 @@ X509 *X509_from_strings(const char **pem) return NULL; } - ERR_clear_error(); x = PEM_read_bio_X509(b, NULL, NULL, NULL); OPENSSL_free(p); BIO_free(b); return x; } - -/* - * Create a PKEY from an array of strings. - */ -EVP_PKEY *PKEY_from_strings(const char **pem) -{ - EVP_PKEY *key; - char *p; - BIO *b = glue2bio(pem, &p); - - if (b == NULL) { - OPENSSL_free(p); - return NULL; - } - - ERR_clear_error(); - key = PEM_read_bio_PrivateKey_ex(b, NULL, NULL, NULL, NULL, NULL); - OPENSSL_free(p); - BIO_free(b); - return key; -} diff --git a/test/testutil/main.c b/test/testutil/main.c index 940d25f707..468d18a825 100644 --- a/test/testutil/main.c +++ b/test/testutil/main.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -7,35 +7,16 @@ * https://www.openssl.org/source/license.html */ -#include #include "../testutil.h" #include "output.h" #include "tu_local.h" -#if defined __has_include -/* Any compiler you're going to run valgrind on has this */ -#if __has_include() -#include -#define OPENSSL_VALGRIND_H_INCLUDED -#endif -#endif /* defined(__has_include) */ - -/* - * At some point we should consider looking at this function with a view to - * moving most/all of this into onfree handlers in OSSL_LIB_CTX. - */ - int main(int argc, char *argv[]) { int ret = EXIT_FAILURE; int setup_res; int gi_ret; - if (mfail_install(0) < 0) { - test_printf_stderr("MFAIL installation failed - aborting\n"); - return ret; - } - gi_ret = global_init(); test_open_streams(); @@ -58,20 +39,5 @@ int main(int argc, char *argv[]) end: ret = pulldown_test_framework(ret); test_close_streams(); -#if defined(OPENSSL_VALGRIND_H_INCLUDED) && defined(RUNNING_ON_VALGRIND) - /* - * Somewhat paradoxically, we do *NOT* want to clean up normally - * when running our tests using valgrind in order to test the - * suppression file which we will ship with the distribution. We - * set the OSSL_USE_VALGRIND environment variable for this - * purpose, but we only want to dodge cleanup when running under - * valgrind, *and* that environment variable is set. If you run - * this under valgrind without that environment variable set, it - * will still call OPENSSL_cleanup normally. - */ - if (RUNNING_ON_VALGRIND && getenv("OSSL_USE_VALGRIND") != NULL) - return ret; -#endif /* defined(OPENSSL_VALGRIND_H_INCLUDED) && defined(RUNNING_ON_VALGRIND) */ - OPENSSL_cleanup(); return ret; } diff --git a/test/testutil/output.h b/test/testutil/output.h index e4f6058ac7..cee3026b11 100644 --- a/test/testutil/output.h +++ b/test/testutil/output.h @@ -13,10 +13,22 @@ #include #define ossl_test__attr__(x) -#if defined(__GNUC__) && !defined(__MINGW32__) && !defined(__MINGW64__) \ +#if defined(__GNUC__) && defined(__STDC_VERSION__) \ + && !defined(__MINGW32__) && !defined(__MINGW64__) \ && !defined(__APPLE__) +/* + * Because we support the 'z' modifier, which made its appearance in C99, + * we can't use __attribute__ with pre C99 dialects. + */ +#if __STDC_VERSION__ >= 199901L #undef ossl_test__attr__ #define ossl_test__attr__ __attribute__ +#if __GNUC__ * 10 + __GNUC_MINOR__ >= 44 +#define ossl_test__printf__ __gnu_printf__ +#else +#define ossl_test__printf__ __printf__ +#endif +#endif #endif /* * The basic I/O functions used internally by the test framework. These @@ -27,13 +39,13 @@ void test_close_streams(void); void test_adjust_streams_tap_level(int level); /* The following ALL return the number of characters written */ int test_vprintf_stdout(const char *fmt, va_list ap) - ossl_test__attr__((__format__(__printf__, 1, 0))); + ossl_test__attr__((__format__(ossl_test__printf__, 1, 0))); int test_vprintf_tapout(const char *fmt, va_list ap) - ossl_test__attr__((__format__(__printf__, 1, 0))); + ossl_test__attr__((__format__(ossl_test__printf__, 1, 0))); int test_vprintf_stderr(const char *fmt, va_list ap) - ossl_test__attr__((__format__(__printf__, 1, 0))); + ossl_test__attr__((__format__(ossl_test__printf__, 1, 0))); int test_vprintf_taperr(const char *fmt, va_list ap) - ossl_test__attr__((__format__(__printf__, 1, 0))); + ossl_test__attr__((__format__(ossl_test__printf__, 1, 0))); /* These return failure or success */ int test_flush_stdout(void); int test_flush_tapout(void); @@ -42,14 +54,15 @@ int test_flush_taperr(void); /* Commodity functions. There's no need to override these */ int test_printf_stdout(const char *fmt, ...) - ossl_test__attr__((__format__(__printf__, 1, 2))); + ossl_test__attr__((__format__(ossl_test__printf__, 1, 2))); int test_printf_tapout(const char *fmt, ...) - ossl_test__attr__((__format__(__printf__, 1, 2))); + ossl_test__attr__((__format__(ossl_test__printf__, 1, 2))); int test_printf_stderr(const char *fmt, ...) - ossl_test__attr__((__format__(__printf__, 1, 2))); + ossl_test__attr__((__format__(ossl_test__printf__, 1, 2))); int test_printf_taperr(const char *fmt, ...) - ossl_test__attr__((__format__(__printf__, 1, 2))); + ossl_test__attr__((__format__(ossl_test__printf__, 1, 2))); +#undef ossl_test__printf__ #undef ossl_test__attr__ #endif /* OSSL_TESTUTIL_OUTPUT_H */ diff --git a/test/testutil/tests.c b/test/testutil/tests.c index ccc4727bac..f67b5ce4bf 100644 --- a/test/testutil/tests.c +++ b/test/testutil/tests.c @@ -1,5 +1,5 @@ /* - * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -238,8 +238,8 @@ DEFINE_COMPARISONS(uint64_t, uint64_t, "%llu", unsigned long long) DEFINE_COMPARISONS(size_t, size_t, "%zu", size_t) DEFINE_COMPARISONS(double, double, "%g", double) -DEFINE_COMPARISON(void *, ptr, eq, ==, "%p", const void *) -DEFINE_COMPARISON(void *, ptr, ne, !=, "%p", const void *) +DEFINE_COMPARISON(void *, ptr, eq, ==, "%p", void *) +DEFINE_COMPARISON(void *, ptr, ne, !=, "%p", void *) int test_ptr_null(const char *file, int line, const char *s, const void *p) { @@ -302,28 +302,28 @@ int test_str_ne(const char *file, int line, const char *st1, const char *st2, } int test_strn_eq(const char *file, int line, const char *st1, const char *st2, - const char *s1, const char *s2, size_t n) + const char *s1, size_t n1, const char *s2, size_t n2) { if (s1 == NULL && s2 == NULL) return 1; - if (s1 == NULL || s2 == NULL || strncmp(s1, s2, n) != 0) { + if (n1 != n2 || s1 == NULL || s2 == NULL || strncmp(s1, s2, n1) != 0) { test_fail_string_message(NULL, file, line, "string", st1, st2, "==", - s1, s1 == NULL ? 0 : OPENSSL_strnlen(s1, n), - s2, s2 == NULL ? 0 : OPENSSL_strnlen(s2, n)); + s1, s1 == NULL ? 0 : OPENSSL_strnlen(s1, n1), + s2, s2 == NULL ? 0 : OPENSSL_strnlen(s2, n2)); return 0; } return 1; } int test_strn_ne(const char *file, int line, const char *st1, const char *st2, - const char *s1, const char *s2, size_t n) + const char *s1, size_t n1, const char *s2, size_t n2) { if ((s1 == NULL) ^ (s2 == NULL)) return 1; - if (s1 == NULL || strncmp(s1, s2, n) == 0) { + if (n1 != n2 || s1 == NULL || strncmp(s1, s2, n1) == 0) { test_fail_string_message(NULL, file, line, "string", st1, st2, "!=", - s1, s1 == NULL ? 0 : OPENSSL_strnlen(s1, n), - s2, s2 == NULL ? 0 : OPENSSL_strnlen(s2, n)); + s1, s1 == NULL ? 0 : OPENSSL_strnlen(s1, n1), + s2, s2 == NULL ? 0 : OPENSSL_strnlen(s2, n2)); return 0; } return 1; @@ -357,97 +357,6 @@ int test_mem_ne(const char *file, int line, const char *st1, const char *st2, return 1; } -#if defined(OPENSSL_NO_ERR) || defined(OPENSSL_NO_DEPRECATED_3_0) || defined(OPENSSL_SMALL_FOOTPRINT) - -int test_err_r(const char *file, int line, int lib, int reason) -{ - return 1; -} - -int test_err_s(const char *file, int line, const char *data) -{ - return 1; -} - -#else - -struct test_err_expect_ctx { - struct test_err_expect { - char *file, *fn, *data; - unsigned long code; - int line; - } errs[ERR_NUM_ERRORS]; - int err_count; -}; - -static int err_r_cb(int lib, int reason, struct test_err_expect *e) -{ - if (ERR_GET_LIB(e->code) == lib && ERR_GET_REASON(e->code) == reason) - return 1; - return 0; -} - -static int err_s_cb(const char *data, struct test_err_expect *e) -{ - if (e->data != NULL && strcmp(e->data, data) == 0) - return 1; - return 0; -} - -static int test_err_helper(int lib, int reason, const char *str) -{ - struct test_err_expect_ctx ctx; - int result = 0; - - for (ctx.err_count = 0;; ctx.err_count++) { - struct test_err_expect *e = &ctx.errs[ctx.err_count]; - const char *file = NULL, *fn = NULL, *data = NULL; - - if ((e->code = ERR_get_error_all(&file, &e->line, &fn, &data, NULL)) == 0) - break; - - /* - * Usage after free won't actually happen in tests, but for greater - * robustness, paying for 3 allocations per record in the test is not a - * problem and we also gain robustness against future changes in the - * error stack. - */ - - e->file = file != NULL ? OPENSSL_strdup(file) : NULL; - e->fn = fn != NULL ? OPENSSL_strdup(fn) : NULL; - e->data = data != NULL ? OPENSSL_strdup(data) : NULL; - } - - for (int i = 0; i < ctx.err_count; i++) { - struct test_err_expect *e = &ctx.errs[i]; - - if ((str != NULL ? err_s_cb(str, e) : err_r_cb(lib, reason, e)) == 1) - result = 1; - - ERR_new(); - ERR_set_debug(e->file, e->line, e->fn); - ERR_set_error(ERR_GET_LIB(e->code), ERR_GET_REASON(e->code), e->data); - - OPENSSL_free(e->file); - OPENSSL_free(e->fn); - OPENSSL_free(e->data); - } - - return result; -} - -int test_err_r(const char *file, int line, int lib, int reason) -{ - return test_err_helper(lib, reason, NULL); -} - -int test_err_s(const char *file, int line, const char *data) -{ - return test_err_helper(0, 0, data); -} - -#endif - #define DEFINE_BN_COMPARISONS(opname, op, zero_cond) \ int test_BN_##opname(const char *file, int line, \ const char *s1, const char *s2, \ diff --git a/test/threadstest.c b/test/threadstest.c index 50a5d90340..7167bbc223 100644 --- a/test/threadstest.c +++ b/test/threadstest.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -125,8 +125,7 @@ static void rwwriter_fn(int id, int *iterations) t1 = ossl_time_now(); for (count = 0;; count++) { - new = OPENSSL_zalloc(sizeof(int)); - OPENSSL_assert(new != NULL); + new = CRYPTO_zalloc(sizeof(int), NULL, 0); if (contention == 0) OSSL_sleep(1000); if (!CRYPTO_THREAD_write_lock(rwtorturelock)) @@ -320,20 +319,12 @@ static void writer_fn(int id, int *iterations) int count; OSSL_TIME t1, t2; uint64_t *old, *new; - CRYPTO_RCU_CB_ITEM *cbi = NULL; t1 = ossl_time_now(); for (count = 0;; count++) { - new = OPENSSL_zalloc(sizeof(uint64_t)); - OPENSSL_assert(new != NULL); + new = CRYPTO_malloc(sizeof(uint64_t), NULL, 0); *new = (uint64_t)0xBAD; - - if (contention == 0) { - cbi = ossl_rcu_cb_item_new(); - OPENSSL_assert(cbi != NULL); - } - if (contention == 0) OSSL_sleep(1000); ossl_rcu_write_lock(rcu_lock); @@ -342,7 +333,7 @@ static void writer_fn(int id, int *iterations) *new = global_ctr++; ossl_rcu_assign_ptr(&writer_ptr, &new); if (contention == 0) - ossl_rcu_call(rcu_lock, cbi, free_old_rcu_data, old); + ossl_rcu_call(rcu_lock, free_old_rcu_data, old); ossl_rcu_write_unlock(rcu_lock); if (contention != 0) { ossl_synchronize_rcu(rcu_lock); @@ -760,7 +751,7 @@ static OSSL_PROVIDER *multi_provider[MAXIMUM_PROVIDERS + 1]; static size_t multi_num_threads; static thread_t multi_threads[MAXIMUM_THREADS]; -static void multi_initialise(void) +static void multi_intialise(void) { multi_success = 1; multi_libctx = NULL; @@ -789,7 +780,7 @@ static void thead_teardown_libctx(void) for (p = multi_provider; *p != NULL; p++) OSSL_PROVIDER_unload(*p); OSSL_LIB_CTX_free(multi_libctx); - multi_initialise(); + multi_intialise(); } static int thread_setup_libctx(int libctx, const char *providers[]) @@ -840,7 +831,7 @@ static int thread_run_test(void (*main_func)(void), { int testresult = 0; - multi_initialise(); + multi_intialise(); if (!thread_setup_libctx(libctx, providers) || !start_threads(num_threads, thread_func)) goto err; @@ -1019,7 +1010,7 @@ static int test_multi_shared_pkey_common(void (*worker)(void)) { int testresult = 0; - multi_initialise(); + multi_intialise(); if (!thread_setup_libctx(1, do_fips ? fips_and_default_providers : default_provider) || !TEST_ptr(shared_evp_pkey = load_pkey_pem(privkey, multi_libctx)) || !start_threads(1, &thread_shared_evp_pkey) @@ -1071,7 +1062,7 @@ static int test_multi_shared_pkey_release(void) int testresult = 0; size_t i = 1; - multi_initialise(); + multi_intialise(); shared_evp_pkey = NULL; if (!thread_setup_libctx(1, do_fips ? fips_and_default_providers : default_provider) || !TEST_ptr(shared_evp_pkey = load_pkey_pem(privkey, multi_libctx))) @@ -1104,7 +1095,7 @@ static int test_multi_load_unload_provider(void) OSSL_PROVIDER *prov = NULL; int testresult = 0; - multi_initialise(); + multi_intialise(); if (!thread_setup_libctx(1, NULL) || !TEST_ptr(prov = OSSL_PROVIDER_load(multi_libctx, "default")) || !TEST_ptr(sha256 = EVP_MD_fetch(multi_libctx, "SHA2-256", NULL)) @@ -1379,7 +1370,7 @@ static void test_obj_create_worker(void) for (i = 0; i < 4; i++) { now = time(NULL); - BIO_snprintf(name, sizeof(name), "Time in Seconds = %ld", (long)now); + snprintf(name, sizeof(name), "Time in Seconds = %ld", (long)now); while (now == time(NULL)) /* no-op */; nid = OBJ_create(NULL, NULL, name); diff --git a/test/time_offset_test.c b/test/time_offset_test.c index f49769a425..ebfbffff93 100644 --- a/test/time_offset_test.c +++ b/test/time_offset_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -18,8 +18,6 @@ #include "testutil.h" #include "internal/nelem.h" -#include - typedef struct { const char *data; int time_result; diff --git a/test/tls-provider.c b/test/tls-provider.c index 34ea1652a0..707c9ac2dd 100644 --- a/test/tls-provider.c +++ b/test/tls-provider.c @@ -1,5 +1,5 @@ /* - * Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2019-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -26,8 +26,6 @@ #include "internal/nelem.h" #include "internal/refcount.h" -#include - /* error codes */ /* xorprovider error codes */ @@ -216,7 +214,7 @@ struct tls_group_st { static struct tls_group_st xor_group = { 0, /* group_id, set by randomize_tls_alg_id() */ 128, /* secbits */ - TLS1_2_VERSION, /* mintls */ + TLS1_3_VERSION, /* mintls */ 0, /* maxtls */ -1, /* mindtls */ -1, /* maxdtls */ @@ -725,7 +723,7 @@ static int xor_key_up_ref(XORKEY *key) { int refcnt; - if (!CRYPTO_UP_REF(&key->references, &refcnt)) + if (CRYPTO_UP_REF(&key->references, &refcnt) <= 0) return 0; assert(refcnt > 1); @@ -1282,7 +1280,7 @@ static XORKEY *xor_key_from_pkcs8(const PKCS8_PRIV_KEY_INFO *p8inf, plen = 0; } else { p = ASN1_STRING_get0_data(oct); - plen = (int)ASN1_STRING_length_ex(oct); + plen = ASN1_STRING_length(oct); } xork = xor_key_op(palg, p, plen, KEY_OP_PRIVATE, @@ -2164,7 +2162,8 @@ ASN1_SEQUENCE(X509_PUBKEY_INTERNAL) = { ASN1_SIMPLE(X509_PUBKEY, public_key, ASN1_BIT_STRING) } static_ASN1_SEQUENCE_END_name(X509_PUBKEY, X509_PUBKEY_INTERNAL) -static X509_PUBKEY *xorx_d2i_X509_PUBKEY_INTERNAL(const unsigned char **pp, long len, OSSL_LIB_CTX *libctx) + static X509_PUBKEY + * xorx_d2i_X509_PUBKEY_INTERNAL(const unsigned char **pp, long len, OSSL_LIB_CTX *libctx) { X509_PUBKEY *xpub = OPENSSL_zalloc(sizeof(*xpub)); @@ -2598,7 +2597,7 @@ static int xor_get_aid(unsigned char **oidbuf, const char *tls_name) aidlen = i2d_X509_ALGOR(algor, oidbuf); X509_ALGOR_free(algor); - return aidlen; + return (aidlen); } /* @@ -3229,11 +3228,6 @@ int tls_provider_init(const OSSL_CORE_HANDLE *handle, } } - if (c_obj_create == NULL || c_obj_add_sigid == NULL) { - ERR_raise(ERR_LIB_USER, XORPROV_R_OBJ_CREATE_ERR); - goto err; - } - /* * Register algorithms manually as add_provider_sigalgs is * only called during session establishment -- too late for diff --git a/test/tls12psk.c b/test/tls12psk.c deleted file mode 100644 index 1a9b7a54f8..0000000000 --- a/test/tls12psk.c +++ /dev/null @@ -1,333 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include -#include -#include - -#include "helpers/ssltestlib.h" -#include "testutil.h" - -static const char psk_secret[] = "shared-secret"; -static const char psk_identity[] = "identity"; - -static const unsigned char sid_req[] = { - 0xde, 0xad, 0xbe, 0xef, 0x01, 0x02, 0x03, 0x04, - 0x05, 0x06, 0x07, 0x08, 0x09, 0x0a, 0x0b, 0x0c -}; - -static const struct ciphersuites { - char *name; -} css[] = { - { "PSK-AES128-CBC-SHA256" }, - { "PSK-AES256-CBC-SHA384" }, - { "PSK-AES128-GCM-SHA256" }, - { "PSK-AES256-GCM-SHA384" } -}; - -#define HELLO_RANDOM_OFF 6 -#define HELLO_RANDOM_LEN 32 -#define HELLO_SID_LEN_OFF (HELLO_RANDOM_OFF + HELLO_RANDOM_LEN) -#define HELLO_SID_OFF (HELLO_SID_LEN_OFF + 1) -#define HELLO_MIN_LEN (HELLO_SID_LEN_OFF + 1) - -static void hello_session_id(const unsigned char *p, size_t len) -{ - char *str; - size_t sid_len; - - if (len < HELLO_MIN_LEN) - return; - - sid_len = p[HELLO_SID_LEN_OFF]; - if (sid_len == 0 || len < HELLO_SID_OFF + sid_len) - return; - - str = OPENSSL_buf2hexstr(p + HELLO_SID_OFF, (long)sid_len); - TEST_info("session_id(%zu): <%s>", sid_len, str); - OPENSSL_free(str); -} - -static void msg_cb(int write_p, int version, int content_type, - const void *buf, size_t len, SSL *ssl, void *arg) -{ - const unsigned char *p = buf; - - if (content_type != SSL3_RT_HANDSHAKE || len < 1) - return; - - switch (p[0]) { - case SSL3_MT_CLIENT_HELLO: - TEST_info("%p client_hello", (void *)ssl); - hello_session_id(p, len); - break; - - case SSL3_MT_SERVER_HELLO: - TEST_info("%p server_hello", (void *)ssl); - hello_session_id(p, len); - break; - } -} - -static void handshake_finished(const SSL *ssl) -{ - const char *endpoint = SSL_is_server(ssl) ? "server" : "client"; - unsigned int has_ticket = SSL_SESSION_has_ticket(SSL_get_session(ssl)); - - if (SSL_session_reused(ssl)) - TEST_info("%s: Abbreviated handshake finished", endpoint); - else - TEST_info("%s: Full handshake finished", endpoint); - - TEST_info("%s: has_ticket: %u", endpoint, has_ticket); -} - -static void info_cb(const SSL *ssl, int type, int val) -{ - const char *endpoint = SSL_is_server(ssl) ? "server" : "client"; - - if (type & SSL_CB_ALERT) { - const char *dir = (type & SSL_CB_READ) ? "read" : "write"; - - TEST_info("%s: alert %s: %s : %s", endpoint, dir, - SSL_alert_type_string_long(val), - SSL_alert_desc_string_long(val)); - } - if (type & SSL_CB_HANDSHAKE_DONE) - handshake_finished(ssl); -} - -static unsigned int server_psk_cb(SSL *ssl, const char *identity, - unsigned char *psk, unsigned int max) -{ - if (max < (sizeof(psk_secret) - 1)) - return 0; - memcpy(psk, psk_secret, (sizeof(psk_secret) - 1)); - return (unsigned int)(sizeof(psk_secret) - 1); -} - -static unsigned int client_psk_cb(SSL *ssl, const char *hint, - char *identity, unsigned int max_id, - unsigned char *psk, unsigned int max) -{ - if (max < (sizeof(psk_secret) - 1) || max_id < sizeof(psk_identity)) - return 0; - strncpy(identity, psk_identity, max_id); - memcpy(psk, psk_secret, (sizeof(psk_secret) - 1)); - return (unsigned int)(sizeof(psk_secret) - 1); -} - -static SSL_SESSION *sess_cache; -static SSL_SESSION *get_sess_cb(SSL *ssl, const unsigned char *id, int len, int *copy) -{ - *copy = 1; - - if (sess_cache != NULL) { - char *str; - const unsigned char *sid; - unsigned int sid_len; - - sid = SSL_SESSION_get_id(sess_cache, &sid_len); - str = OPENSSL_buf2hexstr(sid, sid_len); - TEST_info("(cached) session_id: <%s>", str); - OPENSSL_free(str); - } - return sess_cache; -} - -static int ctx_set_cache(SSL_CTX *s_ctx, SSL_CTX *c_ctx) -{ - SSL_CTX_set_psk_server_callback(s_ctx, server_psk_cb); - SSL_CTX_set_psk_client_callback(c_ctx, client_psk_cb); - SSL_CTX_set_session_cache_mode(s_ctx, SSL_SESS_CACHE_SERVER); - SSL_CTX_set_session_cache_mode(c_ctx, SSL_SESS_CACHE_CLIENT); - SSL_CTX_set_options(s_ctx, SSL_OP_NO_TICKET); - SSL_CTX_set_verify(c_ctx, SSL_VERIFY_NONE, NULL); - return 1; -} - -static int ctx_set_ticket(SSL_CTX *s_ctx, SSL_CTX *c_ctx) -{ - SSL_CTX_set_psk_server_callback(s_ctx, server_psk_cb); - SSL_CTX_set_psk_client_callback(c_ctx, client_psk_cb); - SSL_CTX_set_session_cache_mode(s_ctx, SSL_SESS_CACHE_SERVER); - SSL_CTX_set_session_cache_mode(c_ctx, SSL_SESS_CACHE_CLIENT); - SSL_CTX_set_verify(c_ctx, SSL_VERIFY_NONE, NULL); - return 1; -} - -static int set_shutdown(SSL *c, SSL *s) -{ - SSL_set_shutdown(c, SSL_SENT_SHUTDOWN | SSL_RECEIVED_SHUTDOWN); - SSL_set_shutdown(s, SSL_SENT_SHUTDOWN | SSL_RECEIVED_SHUTDOWN); - return 1; -} - -static int set_server_cache(SSL_CTX *s_ctx) -{ - unsigned int v = SSL_SESS_CACHE_SERVER | SSL_SESS_CACHE_NO_INTERNAL_STORE; - SSL_CTX_sess_set_get_cb(s_ctx, get_sess_cb); - SSL_CTX_set_session_cache_mode(s_ctx, v); - return 1; -} - -static int set_callbacks(SSL *c, SSL *s) -{ - SSL_set_msg_callback(c, msg_cb); - SSL_set_info_callback(c, info_cb); - SSL_set_msg_callback(s, msg_cb); - SSL_set_info_callback(s, info_cb); - return 1; -} - -static int sessid_matches(SSL *c, SSL *s) -{ - const unsigned char *c_sid, *s_sid; - unsigned int c_len, s_len; - int test; - - test = TEST_ptr(c_sid = SSL_SESSION_get_id(SSL_get0_session(c), &c_len)) - && TEST_ptr(s_sid = SSL_SESSION_get_id(SSL_get0_session(s), &s_len)) - && TEST_uint_eq(c_len, s_len) && TEST_mem_eq(c_sid, c_len, s_sid, s_len); - - return test; -} - -/* - * The session ID stored in an SSL_SESSION is assigned by the server at the - * end of the original full handshake and never modified afterwards. The - * client-supplied session ID in ClientHello is copied verbatim from the - * session the client cached after that same handshake. If both sides behaved - * correctly, the two values are guaranteed to be identical. - * - * This Explicit comparison inside ssl_get_prev_session() between the session ID - * the client offered in ClientHello and the session ID embedded in the - * SSL_SESSION returned by the cache. If they do not match, the cached session - * is released and ssl_get_prev_session() returns a cache miss, forcing a full - * handshake. Catching the mismatch here ensures the server never sends a - * ServerHello that claims resumption of a session ID it cannot legitimately - * echo. - * - * A mismatch unambiguously indicates one of: - * - a corrupt cache entry - * - an cache implementation that returned the wrong session - * - an active tampering attempt - * - * In all three cases, refusing resumption and falling back to a full - * handshake is the correct response. - */ - -static int test_tls12_psk_resume_sessid_mismatch(int idx) -{ - const struct ciphersuites *cs = &css[idx]; - SSL_CTX *s_ctx = NULL, *c_ctx = NULL; - SSL *s_ssl = NULL, *c_ssl = NULL, *s = NULL, *c = NULL; - SSL_SESSION *sess = NULL, *r_sess = NULL; - const unsigned char *sid; - unsigned int sid_len; - int test; - - sess_cache = NULL; - - test = TEST_true(create_ssl_ctx_pair(NULL, TLS_server_method(), TLS_client_method(), - TLS1_2_VERSION, TLS1_2_VERSION, &s_ctx, &c_ctx, NULL, NULL)) - && TEST_true(SSL_CTX_set_cipher_list(s_ctx, cs->name)) - && TEST_true(SSL_CTX_set_cipher_list(c_ctx, cs->name)) - && TEST_true(ctx_set_cache(s_ctx, c_ctx)) - && TEST_true(create_ssl_objects(s_ctx, c_ctx, &s, &c, NULL, NULL)) - && TEST_true(set_callbacks(c, s)) - && TEST_true(create_ssl_connection(s, c, SSL_ERROR_NONE)) - && TEST_ptr(sess = SSL_get1_session(c)) - && TEST_true(set_shutdown(c, s)) - && TEST_ptr(sid = SSL_SESSION_get_id(sess, &sid_len)) - && TEST_uint_eq(sid_len, 32) - && TEST_ptr(r_sess = SSL_SESSION_dup(sess)) - && TEST_true(SSL_SESSION_set1_id(r_sess, sid_req, sizeof(sid_req))) - && TEST_ptr(sess_cache = sess) - && TEST_true(set_server_cache(s_ctx)) - && TEST_true(create_ssl_objects(s_ctx, c_ctx, &s_ssl, &c_ssl, NULL, NULL)) - && TEST_true(set_callbacks(c_ssl, s_ssl)) - && TEST_true(SSL_set_session(c_ssl, r_sess)) - && TEST_true(create_ssl_connection(s_ssl, c_ssl, SSL_ERROR_NONE)) - && TEST_false(SSL_session_reused(s_ssl)); - - sess_cache = NULL; - SSL_free(s_ssl); - SSL_free(c_ssl); - SSL_SESSION_free(r_sess); - SSL_SESSION_free(sess); - SSL_CTX_free(s_ctx); - SSL_CTX_free(c_ctx); - SSL_free(s); - SSL_free(c); - return test; -} - -/* - * RFC 5077 3.4 requires the server to echo the session ID from ClientHello - * in the ServerHello when accepting a session ticket. Some clients rely on - * this echo to confirm that resumption succeeded. The ticket decryption path - * in tls_decrypt_ticket() guarantees the restored SSL_SESSION carries the - * correct session ID, so tls_construct_server_hello() will echo it correctly. - * If the session ID is empty, its length is set to zero as required by the - * RFC. - */ -static int test_tls12_psk_resume_ticket_mismatch(int idx) -{ - const struct ciphersuites *cs = &css[idx]; - SSL_CTX *s_ctx = NULL, *c_ctx = NULL; - SSL *s_ssl = NULL, *c_ssl = NULL, *s = NULL, *c = NULL; - SSL_SESSION *c_sess = NULL, *r_sess = NULL; - int test; - - test = TEST_true(create_ssl_ctx_pair(NULL, TLS_server_method(), TLS_client_method(), - TLS1_2_VERSION, TLS1_2_VERSION, &s_ctx, &c_ctx, NULL, NULL)) - && TEST_true(SSL_CTX_set_cipher_list(s_ctx, cs->name)) - && TEST_true(SSL_CTX_set_cipher_list(c_ctx, cs->name)) - && TEST_true(ctx_set_ticket(s_ctx, c_ctx)) - && TEST_true(create_ssl_objects(s_ctx, c_ctx, &s, &c, NULL, NULL)) - && TEST_true(set_callbacks(c, s)) - && TEST_true(create_ssl_connection(s, c, SSL_ERROR_NONE)) - && TEST_ptr(c_sess = SSL_get1_session(c)) - && TEST_true(SSL_SESSION_has_ticket(c_sess)) - && TEST_int_eq(set_shutdown(c, s), 1) - && TEST_ptr(r_sess = SSL_SESSION_dup(c_sess)) - && TEST_true(SSL_SESSION_set1_id(r_sess, sid_req, sizeof(sid_req))) - && TEST_true(create_ssl_objects(s_ctx, c_ctx, &s_ssl, &c_ssl, NULL, NULL)) - && TEST_true(set_callbacks(c_ssl, s_ssl)) - && TEST_true(SSL_set_session(c_ssl, r_sess)) - && TEST_true(create_ssl_connection(s_ssl, c_ssl, SSL_ERROR_NONE)) - && TEST_true(SSL_session_reused(s_ssl)) - && TEST_true(sessid_matches(c_ssl, s_ssl)); - - SSL_free(s_ssl); - SSL_free(c_ssl); - SSL_SESSION_free(r_sess); - SSL_SESSION_free(c_sess); - SSL_CTX_free(s_ctx); - SSL_CTX_free(c_ctx); - SSL_free(s); - SSL_free(c); - return test; -} - -OPT_TEST_DECLARE_USAGE("\n") - -int setup_tests(void) -{ - if (!test_skip_common_options()) { - TEST_error("Error parsing test options\n"); - return 0; - } - - ADD_ALL_TESTS(test_tls12_psk_resume_sessid_mismatch, OSSL_NELEM(css)); - ADD_ALL_TESTS(test_tls12_psk_resume_ticket_mismatch, OSSL_NELEM(css)); - return 1; -} diff --git a/test/tls13encryptiontest.c b/test/tls13encryptiontest.c index 1bb940ae87..b9d3861946 100644 --- a/test/tls13encryptiontest.c +++ b/test/tls13encryptiontest.c @@ -312,7 +312,7 @@ static int test_tls13_encryption(void) OSSL_RECORD_PROTECTION_LEVEL_APPLICATION, 0, NULL, 0, key, 16, iv, ivlen, NULL, 0, EVP_aes_128_gcm(), EVP_GCM_TLS_TAG_LEN, 0, NULL, NULL, NULL, NULL, NULL, - NULL, NULL, NULL, NULL, NULL, NULL, + NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, &wrl))) goto err; memcpy(wrl->sequence, seqbuf, sizeof(seqbuf)); @@ -335,7 +335,7 @@ static int test_tls13_encryption(void) OSSL_RECORD_PROTECTION_LEVEL_APPLICATION, 0, NULL, 0, key, 16, iv, ivlen, NULL, 0, EVP_aes_128_gcm(), EVP_GCM_TLS_TAG_LEN, 0, NULL, NULL, NULL, NULL, NULL, - NULL, NULL, NULL, NULL, NULL, NULL, + NULL, NULL, NULL, NULL, NULL, NULL, NULL, NULL, &rrl))) goto err; memcpy(rrl->sequence, seqbuf, sizeof(seqbuf)); diff --git a/test/tls13groupselection_test.c b/test/tls13groupselection_test.c index 96aa5e7f46..54e094464f 100644 --- a/test/tls13groupselection_test.c +++ b/test/tls13groupselection_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -40,12 +40,6 @@ typedef enum SERVER_RESPONSE { SH = 2 } SERVER_RESPONSE; -static const char *response_desc[] = { - "HRR", - "INIT", - "SH", -}; - static char *cert = NULL; static char *privkey = NULL; @@ -57,17 +51,6 @@ struct tls13groupselection_test_st { const enum SERVER_RESPONSE expected_server_response; }; -/* - * Tests that probe robust handling of group removal depend on detailed - * knowledge of the default group list. A stable list is needed that does not - * depend on future changes in the actual built-in default. - */ -#define TEST_DEFLT \ - "?*X25519MLKEM768 / " \ - "?*X25519 : ?secp256r1 / " \ - "?X448 : ?secp384r1 : ?secp521r1 / " \ - "?ffdhe2048:?ffdhe3072" - static const struct tls13groupselection_test_st tls13groupselection_tests[] = { /* @@ -197,17 +180,11 @@ static const struct tls13groupselection_test_st tls13groupselection_tests[] = { * (I) Check handling of the "DEFAULT" 'pseudo group name' */ { "*X25519:DEFAULT:-prime256v1:-X448", /* test 18 */ - "DEFAULT:-X25519" - ":-?X25519MLKEM768" - ":-?SecP256r1MLKEM768" - ":-?curveSM2MLKEM768", + "DEFAULT:-X25519:-?X25519MLKEM768", CLIENT_PREFERENCE, "secp384r1", HRR }, { "*X25519:DEFAULT:-prime256v1:-X448", /* test 19 */ - "DEFAULT:-X25519" - ":-?X25519MLKEM768" - ":-?SecP256r1MLKEM768" - ":-?curveSM2MLKEM768", + "DEFAULT:-X25519:-?X25519MLKEM768", SERVER_PREFERENCE, "secp384r1", HRR }, /* @@ -330,74 +307,7 @@ static const struct tls13groupselection_test_st tls13groupselection_tests[] = { { "*brainpoolP256r1:X25519", /* test 43 */ "X25519", SERVER_PREFERENCE, - NEGOTIATION_FAILURE, INIT }, - - /* DEFAULT retains tuple structure */ - { "*X25519:secp256r1", - "secp256r1:DEFAULT", /* test 44 */ - SERVER_PREFERENCE, - "secp256r1", HRR }, -#ifndef OPENSSL_NO_DH - { "*ffdhe2048:secp256r1", - "DEFAULT:ffdhe4096", /* test 45 */ - CLIENT_PREFERENCE, - "secp256r1", HRR }, - { "x25519:ffdhe2048:*ffdhe4096", - "DEFAULT:ffdhe4096", /* test 46 */ - SERVER_PREFERENCE, - "x25519", HRR }, - /* - * The server's second tuple becomes empty after removal - * of "secp256r1", the subsequent removal of X448 is - * then from the third tuple. - */ - { "*ffdhe2048:secp384r1", /* test 47 */ - "*X25519:" TEST_DEFLT ":-secp256r1:-X448", - SERVER_PREFERENCE, - "secp384r1", HRR }, - /* - * The server's last tuple becomes empty after removals, - * and then continues to fill. - */ - { "*ffdhe2048:ffdhe4096", /* test 48 */ - "*X25519:" TEST_DEFLT ":-ffdhe2048:-ffdhe3072:ffdhe4096", - SERVER_PREFERENCE, - "ffdhe4096", HRR }, -#endif - - /* Sole unknown keyshare inherited by first remaining tuple group */ - { "?*BOGUS:X25519 / *secp256r1", /* test 49 */ - "X25519 / secp256r1", - SERVER_PREFERENCE, - "x25519", SH }, - { "X25519:?*BOGUS / *secp256r1", /* test 50 */ - "X25519 / secp256r1", - SERVER_PREFERENCE, - "x25519", SH }, - { "?*BOGUS:X25519:*X448 / *secp256r1", /* test 51 */ - "X25519:X448 / secp256r1", - SERVER_PREFERENCE, - "x448", SH }, - { "X25519:?*BOGUS:*X448 / *secp256r1", /* test 52 */ - "X25519:X448 / secp256r1", - SERVER_PREFERENCE, - "x448", SH }, - - /* Sole removed keyshares inherited by first remaining tuple group */ - { "X25519:*X448:secp384r1 / *secp256r1:-X448", /* test 53 */ - "secp384r1:X448:X25519 / secp256r1", - SERVER_PREFERENCE, - "x25519", SH }, - { "X25519:*X448:*secp384r1 / *secp256r1:-X448", /* test 54 */ - "X25519:secp384r1 / secp256r1", - SERVER_PREFERENCE, - "secp384r1", SH }, - - /* DEFAULT retains tuple structure and inheritance */ - { "secp256r1:DEFAULT:-?X25519MLKEM768", /* test 55 */ - "x25519:secp256r1", - CLIENT_PREFERENCE, - "secp256r1", SH }, + NEGOTIATION_FAILURE, INIT } }; static void server_response_check_cb(int write_p, int version, @@ -407,13 +317,11 @@ static void server_response_check_cb(int write_p, int version, /* Cast arg to SERVER_RESPONSE */ enum SERVER_RESPONSE *server_response = (enum SERVER_RESPONSE *)arg; /* Prepare check for HRR */ - const uint8_t *incoming_random = (const uint8_t *)buf + 6; - const uint8_t magic_HRR_random[32] = { - 0xCF, 0x21, 0xAD, 0x74, 0xE5, 0x9A, 0x61, 0x11, + const uint8_t *incoming_random = (uint8_t *)buf + 6; + const uint8_t magic_HRR_random[32] = { 0xCF, 0x21, 0xAD, 0x74, 0xE5, 0x9A, 0x61, 0x11, 0xBE, 0x1D, 0x8C, 0x02, 0x1E, 0x65, 0xB8, 0x91, 0xC2, 0xA2, 0x11, 0x16, 0x7A, 0xBB, 0x8C, 0x5E, - 0x07, 0x9E, 0x09, 0xE2, 0xC8, 0xA8, 0x33, 0x9C - }; + 0x07, 0x9E, 0x09, 0xE2, 0xC8, 0xA8, 0x33, 0x9C }; /* Did a server hello arrive? */ if (write_p == 0 && /* Incoming data... */ @@ -421,7 +329,7 @@ static void server_response_check_cb(int write_p, int version, version == TLS1_3_VERSION && /* for TLSv1.3 ... */ ((uint8_t *)buf)[0] == SSL3_MT_SERVER_HELLO) { /* with message type "ServerHello" */ /* Check what it is: SH or HRR (compare the 'random' data field with HRR magic number) */ - if (memcmp(incoming_random, magic_HRR_random, 32) == 0) + if (memcmp((void *)incoming_random, (void *)magic_HRR_random, 32) == 0) *server_response *= HRR; else *server_response *= SH; @@ -542,16 +450,13 @@ static int test_groupnegotiation(const struct tls13groupselection_test_st *curre group_name_client = SSL_group_to_name(clientssl, negotiated_group_client); if (!TEST_int_eq(negotiated_group_client, negotiated_group_server)) goto end; - if (!TEST_str_eq(response_desc[current_test_vector->expected_server_response], - response_desc[server_response])) + if (!TEST_int_eq((int)current_test_vector->expected_server_response, (int)server_response)) goto end; if (TEST_str_eq(group_name_client, current_test_vector->expected_group)) ok = 1; } else { TEST_false_or_end(create_ssl_connection(serverssl, clientssl, SSL_ERROR_NONE)); - if (test_type == TEST_NEGOTIATION_FAILURE - && !TEST_str_eq(response_desc[current_test_vector->expected_server_response], - response_desc[server_response])) + if (test_type == TEST_NEGOTIATION_FAILURE && !TEST_int_eq((int)current_test_vector->expected_server_response, (int)server_response)) goto end; ok = 1; } diff --git a/test/tls13tickettest.c b/test/tls13tickettest.c deleted file mode 100644 index f761419a56..0000000000 --- a/test/tls13tickettest.c +++ /dev/null @@ -1,679 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include -#include -#include -#include "ssl/ssl_local.h" -#include "internal/packet.h" -#include "helpers/ssltestlib.h" -#include "testutil.h" - -/* - * Do not issue TLS 1.3 session tickets if the server has explicitly disabled - * them via SSL_OP_NO_TICKET and also disabled the session cache with - * SSL_SESS_CACHE_OFF. Together, these settings clearly indicate an intent to - * suppress session resumption; sending NewSessionTicket messages in this case - * would be wasteful and misleading. - * - * From the server’s perspective, a client that does not advertise - * psk_key_exchange_modes in TLS 1.3, or that sends it with RFC 9149 parameters - * such as new_session_count = 0 or resumption_count = 0, is effectively - * signaling no interest in session tickets or resumption. - * - * RFC 8446 section 4.2.9: Servers MUST NOT select a key exchange mode that is - * not listed by the client. This extension also restricts the modes for use - * with PSK resumption. Servers SHOULD NOT send NewSessionTicket with tickets - * that are not compatible with the advertised modes; however, if a server does - * so, the impact will just be that the client's attempts at resumption fail. - * - * In other words, if psk_key_exchange_modes is missing or the server doesn't - * recognize any of the client's advertised modes, this effectively disables - * both resumption and ticket issuance, since the server has no valid mode the - * client understands. In TLS 1.3 terms, omitting this extension is essentially - * a signal that the client has no interest in tickets and resumption. - */ - -#ifndef CLIENT_VERSION_LEN -/* - * This is the legacy version length, i.e. len(0x0303). The same - * label is used in e.g. test/sslapitest.c and elsewhere but not - * defined in a header file I could find. - */ -#define CLIENT_VERSION_LEN 2 -#endif - -#define TICKET_KEYS_LENGTH (TLSEXT_KEYNAME_LENGTH + (2 * TLSEXT_TICK_KEY_LENGTH)) - -struct stats { - unsigned int tickets; - unsigned int nst_msgs; - unsigned int ch_has_psk; - unsigned int ch_has_psk_kex_modes; - unsigned int ch_has_session_ticket; - unsigned int sh_has_psk; - unsigned int sh_has_supported_versions; -}; - -struct tls13_endpoint { - SSL *ssl; - struct stats stats; -}; - -struct tls13_channel { - struct tls13_endpoint c, s; -}; - -static char *cert = NULL; -static char *pkey = NULL; -static int stats_idx = -1; - -static int sess_new_cb(SSL *ssl, SSL_SESSION *session) -{ - struct stats *stats = SSL_get_ex_data(ssl, stats_idx); - if (stats == NULL) - return 0; - if (SSL_is_init_finished(ssl) == 0) - stats->tickets++; - return 0; -} - -static void handshake_finished(const SSL *ssl) -{ - const char *endpoint = SSL_is_server(ssl) ? "server" : "client"; - if (SSL_session_reused(ssl)) - TEST_info("%s: Abbreviated handshake finished", endpoint); - else - TEST_info("%s: Full handshake finished", endpoint); -} - -static void info_cb(const SSL *ssl, int type, int val) -{ - const char *endpoint = SSL_is_server(ssl) ? "server" : "client"; - - if (type & SSL_CB_ALERT) { - const char *dir = (type & SSL_CB_READ) ? "read" : "write"; - - TEST_info("%s: alert %s: %s : %s", endpoint, dir, - SSL_alert_type_string_long(val), - SSL_alert_desc_string_long(val)); - } - if (type & SSL_CB_HANDSHAKE_DONE) - handshake_finished(ssl); -} - -static void parse_ch_exts(const unsigned char *buf, size_t len, struct stats *x) -{ - PACKET pkt, e, ex; - unsigned int v; - - if (!PACKET_buf_init(&pkt, buf, len) - || !PACKET_forward(&pkt, 4 + 2 + 32) - || !PACKET_get_1(&pkt, &v) - || !PACKET_forward(&pkt, v) - || !PACKET_get_net_2(&pkt, &v) - || !PACKET_forward(&pkt, v) - || !PACKET_get_1(&pkt, &v) - || !PACKET_forward(&pkt, v) - || !PACKET_as_length_prefixed_2(&pkt, &e)) - return; - - while (PACKET_remaining(&e) > 0) { - if (!PACKET_get_net_2(&e, &v) || !PACKET_get_length_prefixed_2(&e, &ex)) - return; - switch (v) { - case TLSEXT_TYPE_psk: - x->ch_has_psk = 1; - break; - case TLSEXT_TYPE_psk_kex_modes: - x->ch_has_psk_kex_modes = 1; - break; - case TLSEXT_TYPE_session_ticket: - x->ch_has_session_ticket = 1; - break; - } - } - TEST_info("ch extensions: psk=%d psk_kex_modes=%d session_ticket=%d", - x->ch_has_psk, x->ch_has_psk_kex_modes, x->ch_has_session_ticket); -} - -static void parse_sh_exts(const unsigned char *buf, size_t len, struct stats *x) -{ - PACKET pkt, e, ex; - unsigned int v; - - if (!PACKET_buf_init(&pkt, buf, len) - || !PACKET_forward(&pkt, 4 + 2 + 32) - || !PACKET_get_1(&pkt, &v) - || !PACKET_forward(&pkt, v + 2 + 1) - || !PACKET_as_length_prefixed_2(&pkt, &e)) - return; - - while (PACKET_remaining(&e) > 0) { - if (!PACKET_get_net_2(&e, &v) || !PACKET_get_length_prefixed_2(&e, &ex)) - return; - switch (v) { - case TLSEXT_TYPE_psk: - x->sh_has_psk = 1; - break; - case TLSEXT_TYPE_supported_versions: - x->sh_has_supported_versions = 1; - break; - } - } - TEST_info("sh extensions: psk=%d supported_versions=%d", - x->sh_has_psk, x->sh_has_supported_versions); -} - -static void msg_cb(int write_p, int version, int content_type, - const void *buf, size_t len, SSL *ssl, void *arg) -{ - struct stats *stats = SSL_get_ex_data(ssl, stats_idx); - - if (content_type == SSL3_RT_HANDSHAKE && len > 0) { - unsigned char mt = ((const unsigned char *)buf)[0]; - - if (mt == SSL3_MT_NEWSESSION_TICKET && stats != NULL) - stats->nst_msgs++; - if (mt == SSL3_MT_CLIENT_HELLO && stats != NULL) - parse_ch_exts(buf, len, stats); - if (mt == SSL3_MT_SERVER_HELLO && stats != NULL) - parse_sh_exts(buf, len, stats); - } -} - -static int set_ctx_callbacks(SSL_CTX *c, SSL_CTX *s) -{ - SSL_CTX_sess_set_new_cb(s, sess_new_cb); - SSL_CTX_sess_set_new_cb(c, sess_new_cb); - SSL_CTX_set_verify(c, SSL_VERIFY_NONE, NULL); - return 1; -} - -static int tls_channel_init(SSL_CTX *c_ctx, SSL_CTX *s_ctx, struct tls13_channel *ch) -{ - SSL *c = NULL, *s = NULL; - int test; - - memset(ch, 0, sizeof(*ch)); - - test = TEST_true(create_ssl_objects(s_ctx, c_ctx, &s, &c, NULL, NULL)) - && TEST_true(SSL_set_ex_data(c, stats_idx, &ch->c.stats)) - && TEST_true(SSL_set_ex_data(s, stats_idx, &ch->s.stats)); - - if (test != 0) { - SSL_set_info_callback(c, info_cb); - SSL_set_msg_callback(c, msg_cb); - SSL_set_info_callback(s, info_cb); - SSL_set_msg_callback(s, msg_cb); - ch->c.ssl = c; - ch->s.ssl = s; - } - return test; -} - -static void tls_channel_fini(struct tls13_channel *ch) -{ - SSL_free(ch->c.ssl); - SSL_free(ch->s.ssl); -} - -static int tls_shutdown(struct tls13_channel *ch) -{ - SSL_set_shutdown(ch->c.ssl, SSL_SENT_SHUTDOWN | SSL_RECEIVED_SHUTDOWN); - SSL_set_shutdown(ch->s.ssl, SSL_SENT_SHUTDOWN | SSL_RECEIVED_SHUTDOWN); - return 1; -} - -static int ticket_enable(SSL_CTX *ctx) -{ - unsigned flags = SSL_SESS_CACHE_NO_INTERNAL_STORE; - if (SSL_CTX_is_server(ctx)) - flags |= SSL_SESS_CACHE_SERVER; - else - flags |= SSL_SESS_CACHE_CLIENT; - - SSL_CTX_set_session_cache_mode(ctx, flags); - return 1; -} - -static int ticket_disable(SSL_CTX *ctx) -{ - SSL_CTX_set_options(ctx, SSL_OP_NO_TICKET); - SSL_CTX_set_session_cache_mode(ctx, SSL_SESS_CACHE_OFF); - return 1; -} - -/* - * RFC 5077 3.1: The server sends an empty SessionTicket extension to indicate - * that it will send a new session ticket using the NewSessionTicket handshake - * message. - */ - -static int test_tls12_ticket_enable(void) -{ - SSL_CTX *c = NULL, *s = NULL; - struct tls13_channel initial = { .c.ssl = NULL, .s.ssl = NULL }; - struct tls13_channel resumed = { .c.ssl = NULL, .s.ssl = NULL }; - SSL_SESSION *sess = NULL; - int test; - - test = TEST_true(create_ssl_ctx_pair(NULL, TLS_server_method(), TLS_client_method(), - TLS1_2_VERSION, TLS1_2_VERSION, &s, &c, cert, pkey)) - && TEST_true(set_ctx_callbacks(c, s)) - && TEST_true(ticket_enable(s)) - && TEST_true(ticket_enable(c)) - && TEST_true(tls_channel_init(c, s, &initial)) - && TEST_true(create_ssl_connection(initial.s.ssl, initial.c.ssl, SSL_ERROR_NONE)) - && TEST_true(tls_shutdown(&initial)) - && TEST_uint_eq(initial.s.stats.nst_msgs, 1) - && TEST_uint_eq(initial.c.stats.nst_msgs, 1) - && TEST_uint_eq(initial.c.stats.tickets, 1) - && TEST_uint_eq(initial.s.stats.tickets, 0) - && TEST_uint_eq(initial.s.stats.ch_has_psk_kex_modes, 0) - && TEST_uint_eq(initial.c.stats.ch_has_psk_kex_modes, 0) - && TEST_uint_eq(initial.s.stats.ch_has_session_ticket, 1) - && TEST_uint_eq(initial.c.stats.ch_has_session_ticket, 1) - && TEST_uint_eq(initial.c.stats.sh_has_supported_versions, 0) - && TEST_uint_eq(initial.s.stats.sh_has_supported_versions, 0) - && TEST_ptr(sess = SSL_get1_session(initial.c.ssl)) - && TEST_true(tls_channel_init(c, s, &resumed)) - && TEST_true(SSL_set_session(resumed.c.ssl, sess)) - && TEST_true(create_ssl_connection(resumed.s.ssl, resumed.c.ssl, SSL_ERROR_NONE)) - && TEST_true(SSL_session_reused(resumed.c.ssl)) - && TEST_uint_eq(resumed.s.stats.nst_msgs, 0) - && TEST_uint_eq(resumed.c.stats.nst_msgs, 0) - && TEST_uint_eq(resumed.c.stats.tickets, 0) - && TEST_uint_eq(resumed.s.stats.tickets, 0) - && TEST_uint_eq(resumed.s.stats.ch_has_psk_kex_modes, 0) - && TEST_uint_eq(resumed.c.stats.ch_has_psk_kex_modes, 0) - && TEST_uint_eq(resumed.s.stats.ch_has_session_ticket, 1) - && TEST_uint_eq(resumed.c.stats.ch_has_session_ticket, 1) - && TEST_uint_eq(resumed.c.stats.sh_has_supported_versions, 0) - && TEST_uint_eq(resumed.s.stats.sh_has_supported_versions, 0); - - SSL_SESSION_free(sess); - tls_channel_fini(&initial); - tls_channel_fini(&resumed); - SSL_CTX_free(c); - SSL_CTX_free(s); - return test; -} - -static int test_tls12_ticket_disable_server(void) -{ - SSL_CTX *c = NULL, *s = NULL; - struct tls13_channel initial = { .c.ssl = NULL, .s.ssl = NULL }; - int test; - - test = TEST_true(create_ssl_ctx_pair(NULL, TLS_server_method(), TLS_client_method(), - TLS1_2_VERSION, TLS1_2_VERSION, &s, &c, cert, pkey)) - && TEST_true(set_ctx_callbacks(c, s)) - && TEST_true(ticket_disable(s)) - && TEST_true(ticket_enable(c)) - && TEST_true(tls_channel_init(c, s, &initial)) - && TEST_true(create_ssl_connection(initial.s.ssl, initial.c.ssl, SSL_ERROR_NONE)) - && TEST_true(tls_shutdown(&initial)) - && TEST_uint_eq(initial.s.stats.nst_msgs, 0) - && TEST_uint_eq(initial.c.stats.nst_msgs, 0) - && TEST_uint_eq(initial.c.stats.tickets, 0) - && TEST_uint_eq(initial.s.stats.tickets, 0) - && TEST_uint_eq(initial.s.stats.ch_has_session_ticket, 1) - && TEST_uint_eq(initial.c.stats.ch_has_session_ticket, 1) - && TEST_uint_eq(initial.s.stats.ch_has_psk_kex_modes, 0) - && TEST_uint_eq(initial.c.stats.ch_has_psk_kex_modes, 0) - && TEST_uint_eq(initial.c.stats.sh_has_supported_versions, 0) - && TEST_uint_eq(initial.s.stats.sh_has_supported_versions, 0); - - tls_channel_fini(&initial); - SSL_CTX_free(c); - SSL_CTX_free(s); - return test; -} - -/* - * Verify ticket regeneration after fallback to a full handshake. If session - * resumption fails due to a ciphersuite mismatch, it falls back to a full - * handshake. In that case, ensure a new session ticket is issued reflecting the - * negotiated ciphersuite. - */ -static int test_tls13_ticket_ciphersuite_mismatch(void) -{ - SSL_CTX *c = NULL, *s = NULL; - struct tls13_channel initial = { .c.ssl = NULL, .s.ssl = NULL }; - struct tls13_channel resumed = { .c.ssl = NULL, .s.ssl = NULL }; - SSL_SESSION *sess = NULL; - int test; - - test = TEST_true(create_ssl_ctx_pair(NULL, TLS_server_method(), TLS_client_method(), - TLS1_3_VERSION, TLS1_3_VERSION, &s, &c, cert, pkey)) - && TEST_true(set_ctx_callbacks(c, s)) - && TEST_true(ticket_enable(s)) - && TEST_true(ticket_enable(c)) - && TEST_true(SSL_CTX_set_ciphersuites(s, "TLS_AES_128_GCM_SHA256")) - && TEST_true(SSL_CTX_set_ciphersuites(c, "TLS_AES_128_GCM_SHA256")) - && TEST_true(tls_channel_init(c, s, &initial)) - && TEST_true(create_ssl_connection(initial.s.ssl, initial.c.ssl, SSL_ERROR_NONE)) - && TEST_uint_ge(initial.c.stats.tickets, 1) - && TEST_true(tls_shutdown(&initial)) - && TEST_ptr(sess = SSL_get1_session(initial.c.ssl)) - && TEST_true(SSL_CTX_set_ciphersuites(s, "TLS_AES_256_GCM_SHA384")) - && TEST_true(SSL_CTX_set_ciphersuites(c, "TLS_AES_256_GCM_SHA384")) - && TEST_true(tls_channel_init(c, s, &resumed)) - && TEST_true(SSL_set_session(resumed.c.ssl, sess)) - && TEST_true(create_ssl_connection(resumed.s.ssl, resumed.c.ssl, SSL_ERROR_NONE)) - && TEST_false(SSL_session_reused(resumed.c.ssl)) - && TEST_uint_eq(resumed.s.stats.tickets, 2) - && TEST_uint_eq(resumed.s.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(resumed.c.stats.ch_has_psk_kex_modes, 1); - - SSL_SESSION_free(sess); - tls_channel_fini(&initial); - tls_channel_fini(&resumed); - SSL_CTX_free(c); - SSL_CTX_free(s); - return test; -} - -/* - * The session_ticket extension (#35) is still present in the ClientHello for - * channels where both min and max protocol version are TLS 1.3. This is - * unexpected given that session_ticket (#35) is defined as - * TLS1_2_AND_BELOW_ONLY in OpenSSL, and therefore should not appear in a - * strictly TLS 1.3 handshake. - */ - -static int test_tls13_ticket_enable(void) -{ - SSL_CTX *c = NULL, *s = NULL; - struct tls13_channel initial = { .c.ssl = NULL, .s.ssl = NULL }; - struct tls13_channel resumed = { .c.ssl = NULL, .s.ssl = NULL }; - SSL_SESSION *sess = NULL; - int test; - - test = TEST_true(create_ssl_ctx_pair(NULL, TLS_server_method(), TLS_client_method(), - TLS1_3_VERSION, TLS1_3_VERSION, &s, &c, cert, pkey)) - && TEST_true(set_ctx_callbacks(c, s)) - && TEST_true(ticket_enable(s)) - && TEST_true(ticket_enable(c)) - && TEST_true(tls_channel_init(c, s, &initial)) - && TEST_true(create_ssl_connection(initial.s.ssl, initial.c.ssl, SSL_ERROR_NONE)) - && TEST_true(tls_shutdown(&initial)) - && TEST_uint_eq(initial.s.stats.nst_msgs, 2) - && TEST_uint_eq(initial.c.stats.nst_msgs, 2) - && TEST_uint_eq(initial.c.stats.tickets, 2) - && TEST_uint_eq(initial.s.stats.tickets, 2) - && TEST_uint_eq(initial.s.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(initial.c.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(initial.s.stats.ch_has_session_ticket, 1) - && TEST_uint_eq(initial.c.stats.ch_has_session_ticket, 1) - && TEST_ptr(sess = SSL_get1_session(initial.c.ssl)) - && TEST_true(tls_channel_init(c, s, &resumed)) - && TEST_true(SSL_set_session(resumed.c.ssl, sess)) - && TEST_true(create_ssl_connection(resumed.s.ssl, resumed.c.ssl, SSL_ERROR_NONE)) - && TEST_true(SSL_session_reused(resumed.c.ssl)) - && TEST_uint_eq(resumed.s.stats.nst_msgs, 1) - && TEST_uint_eq(resumed.c.stats.nst_msgs, 1) - && TEST_uint_eq(resumed.c.stats.tickets, 1) - && TEST_uint_eq(resumed.s.stats.tickets, 1) - && TEST_uint_eq(resumed.s.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(resumed.c.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(resumed.c.stats.sh_has_supported_versions, 1) - && TEST_uint_eq(resumed.s.stats.sh_has_supported_versions, 1); - - SSL_SESSION_free(sess); - tls_channel_fini(&initial); - tls_channel_fini(&resumed); - SSL_CTX_free(c); - SSL_CTX_free(s); - return test; -} - -/* - * If num_tickets is set to 0, then no tickets will be issued for either - * a full (initial) connection or a resumed session. - */ -static int test_tls13_ticket_initial_set_num_tickets_zero(void) -{ - SSL_CTX *c = NULL, *s = NULL; - struct tls13_channel initial = { .c.ssl = NULL, .s.ssl = NULL }; - struct tls13_channel resumed = { .c.ssl = NULL, .s.ssl = NULL }; - SSL_SESSION *sess = NULL; - int test; - - test = TEST_true(create_ssl_ctx_pair(NULL, TLS_server_method(), TLS_client_method(), - TLS1_3_VERSION, TLS1_3_VERSION, &s, &c, cert, pkey)) - && TEST_true(set_ctx_callbacks(c, s)) - && TEST_true(SSL_CTX_set_num_tickets(s, 0)) - && TEST_true(ticket_enable(s)) - && TEST_true(ticket_enable(c)) - && TEST_true(tls_channel_init(c, s, &initial)) - && TEST_true(create_ssl_connection(initial.s.ssl, initial.c.ssl, SSL_ERROR_NONE)) - && TEST_true(tls_shutdown(&initial)) - && TEST_uint_eq(initial.s.stats.nst_msgs, 0) - && TEST_uint_eq(initial.c.stats.nst_msgs, 0) - && TEST_uint_eq(initial.c.stats.tickets, 0) - && TEST_uint_eq(initial.s.stats.tickets, 0) - && TEST_uint_eq(initial.s.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(initial.c.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(initial.s.stats.ch_has_session_ticket, 1) - && TEST_uint_eq(initial.c.stats.ch_has_session_ticket, 1) - && TEST_ptr(sess = SSL_get1_session(initial.c.ssl)) - && TEST_true(tls_channel_init(c, s, &resumed)) - && TEST_true(SSL_set_session(resumed.c.ssl, sess)) - && TEST_true(create_ssl_connection(resumed.s.ssl, resumed.c.ssl, SSL_ERROR_NONE)) - && TEST_false(SSL_session_reused(resumed.c.ssl)) - && TEST_uint_eq(resumed.s.stats.nst_msgs, 0) - && TEST_uint_eq(resumed.c.stats.nst_msgs, 0) - && TEST_uint_eq(resumed.c.stats.tickets, 0) - && TEST_uint_eq(resumed.s.stats.tickets, 0) - && TEST_uint_eq(resumed.s.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(resumed.c.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(resumed.c.stats.sh_has_supported_versions, 1) - && TEST_uint_eq(resumed.s.stats.sh_has_supported_versions, 1); - - SSL_SESSION_free(sess); - tls_channel_fini(&initial); - tls_channel_fini(&resumed); - SSL_CTX_free(c); - SSL_CTX_free(s); - return test; -} - -static int test_tls13_ticket_resumed_set_num_tickets_zero(void) -{ - SSL_CTX *c = NULL, *s = NULL; - struct tls13_channel initial = { .c.ssl = NULL, .s.ssl = NULL }; - struct tls13_channel resumed = { .c.ssl = NULL, .s.ssl = NULL }; - SSL_SESSION *sess = NULL; - int test; - - test = TEST_true(create_ssl_ctx_pair(NULL, TLS_server_method(), TLS_client_method(), - TLS1_3_VERSION, TLS1_3_VERSION, &s, &c, cert, pkey)) - && TEST_true(set_ctx_callbacks(c, s)) - && TEST_true(ticket_enable(s)) - && TEST_true(ticket_enable(c)) - && TEST_true(tls_channel_init(c, s, &initial)) - && TEST_true(create_ssl_connection(initial.s.ssl, initial.c.ssl, SSL_ERROR_NONE)) - && TEST_true(tls_shutdown(&initial)) - && TEST_uint_eq(initial.s.stats.nst_msgs, 2) - && TEST_uint_eq(initial.c.stats.nst_msgs, 2) - && TEST_uint_eq(initial.c.stats.tickets, 2) - && TEST_uint_eq(initial.s.stats.tickets, 2) - && TEST_uint_eq(initial.s.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(initial.c.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(initial.s.stats.ch_has_session_ticket, 1) - && TEST_uint_eq(initial.c.stats.ch_has_session_ticket, 1) - && TEST_ptr(sess = SSL_get1_session(initial.c.ssl)) - && TEST_true(SSL_CTX_set_num_tickets(s, 0)) - && TEST_true(tls_channel_init(c, s, &resumed)) - && TEST_true(SSL_set_session(resumed.c.ssl, sess)) - && TEST_true(create_ssl_connection(resumed.s.ssl, resumed.c.ssl, SSL_ERROR_NONE)) - && TEST_true(SSL_session_reused(resumed.c.ssl)) - && TEST_uint_eq(resumed.s.stats.nst_msgs, 0) - && TEST_uint_eq(resumed.c.stats.nst_msgs, 0) - && TEST_uint_eq(resumed.c.stats.tickets, 0) - && TEST_uint_eq(resumed.s.stats.tickets, 0) - && TEST_uint_eq(resumed.s.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(resumed.c.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(resumed.c.stats.sh_has_supported_versions, 1) - && TEST_uint_eq(resumed.s.stats.sh_has_supported_versions, 1); - - SSL_SESSION_free(sess); - tls_channel_fini(&initial); - tls_channel_fini(&resumed); - SSL_CTX_free(c); - SSL_CTX_free(s); - return test; -} - -/* - * Do not issue TLSv1.3 session tickets if the server has explicitly disabled - * them via SSL_OP_NO_TICKET and also turned off the session cache with - * SSL_SESS_CACHE_OFF. Both conditions together indicate a clear intent to - * suppress resumption, so sending NewSessionTicket messages would be - * wasteful and misleading. - */ -static int test_tls13_ticket_disable_server(void) -{ - SSL_CTX *c = NULL, *s = NULL; - struct tls13_channel initial = { .c.ssl = NULL, .s.ssl = NULL }; - struct tls13_channel resumed = { .c.ssl = NULL, .s.ssl = NULL }; - SSL_SESSION *sess = NULL; - int test; - - test = TEST_true(create_ssl_ctx_pair(NULL, TLS_server_method(), TLS_client_method(), - TLS1_3_VERSION, TLS1_3_VERSION, &s, &c, cert, pkey)) - && TEST_true(set_ctx_callbacks(c, s)) - && TEST_true(ticket_disable(s)) - && TEST_true(ticket_enable(c)) - && TEST_true(tls_channel_init(c, s, &initial)) - && TEST_true(create_ssl_connection(initial.s.ssl, initial.c.ssl, SSL_ERROR_NONE)) - && TEST_true(tls_shutdown(&initial)) - && TEST_uint_eq(initial.s.stats.nst_msgs, 0) - && TEST_uint_eq(initial.c.stats.nst_msgs, 0) - && TEST_uint_eq(initial.c.stats.tickets, 0) - && TEST_uint_eq(initial.s.stats.tickets, 0) - && TEST_uint_eq(initial.s.stats.ch_has_session_ticket, 1) - && TEST_uint_eq(initial.c.stats.ch_has_session_ticket, 1) - && TEST_uint_eq(initial.s.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(initial.c.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(initial.c.stats.sh_has_supported_versions, 1) - && TEST_uint_eq(initial.s.stats.sh_has_supported_versions, 1) - && TEST_ptr(sess = SSL_get1_session(initial.c.ssl)) - && TEST_true(tls_channel_init(c, s, &resumed)) - && TEST_true(SSL_set_session(resumed.c.ssl, sess)) - && TEST_true(create_ssl_connection(resumed.s.ssl, resumed.c.ssl, SSL_ERROR_NONE)) - && TEST_false(SSL_session_reused(resumed.c.ssl)) - && TEST_uint_eq(resumed.s.stats.nst_msgs, 0) - && TEST_uint_eq(resumed.c.stats.nst_msgs, 0) - && TEST_uint_eq(resumed.c.stats.tickets, 0) - && TEST_uint_eq(resumed.s.stats.tickets, 0) - && TEST_uint_eq(resumed.s.stats.ch_has_session_ticket, 1) - && TEST_uint_eq(resumed.c.stats.ch_has_session_ticket, 1) - && TEST_uint_eq(resumed.s.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(resumed.c.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(resumed.c.stats.sh_has_supported_versions, 1) - && TEST_uint_eq(resumed.s.stats.sh_has_supported_versions, 1); - - SSL_SESSION_free(sess); - tls_channel_fini(&initial); - tls_channel_fini(&resumed); - SSL_CTX_free(c); - SSL_CTX_free(s); - return test; -} - -/* - * Exercise the SSL_TICKET_NO_DECRYPT path in tls_parse_ctos_psk(). - * - * Rotate ticket keys so that the previously issued ticket can no longer be - * decrypted. If session resumption fails due to a NO_DECRYPT, it falls back to - * a full handshake. In that case, ensure a new session ticket is issued. - */ -static int test_tls13_ticket_no_decrypt(void) -{ - SSL_CTX *c = NULL, *s = NULL; - struct tls13_channel initial = { .c.ssl = NULL, .s.ssl = NULL }; - struct tls13_channel resumed = { .c.ssl = NULL, .s.ssl = NULL }; - SSL_SESSION *sess = NULL; - unsigned char k1[TICKET_KEYS_LENGTH]; - unsigned char k2[TICKET_KEYS_LENGTH]; - int test; - - memset(k1, 0xaa, sizeof(k1)); - memset(k2, 0xbb, sizeof(k2)); - - test = TEST_true(create_ssl_ctx_pair(NULL, TLS_server_method(), TLS_client_method(), - TLS1_3_VERSION, TLS1_3_VERSION, &s, &c, cert, pkey)) - && TEST_true(set_ctx_callbacks(c, s)) - && TEST_true(ticket_enable(s)) - && TEST_true(ticket_enable(c)) - && TEST_int_eq(SSL_CTX_set_tlsext_ticket_keys(s, k1, sizeof(k1)), 1) - && TEST_true(tls_channel_init(c, s, &initial)) - && TEST_true(create_ssl_connection(initial.s.ssl, initial.c.ssl, SSL_ERROR_NONE)) - && TEST_true(tls_shutdown(&initial)) - && TEST_uint_eq(initial.s.stats.nst_msgs, 2) - && TEST_uint_eq(initial.c.stats.nst_msgs, 2) - && TEST_uint_eq(initial.c.stats.tickets, 2) - && TEST_uint_eq(initial.s.stats.tickets, 2) - && TEST_uint_eq(initial.s.stats.ch_has_session_ticket, 1) - && TEST_uint_eq(initial.c.stats.ch_has_session_ticket, 1) - && TEST_uint_eq(initial.s.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(initial.c.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(initial.c.stats.sh_has_supported_versions, 1) - && TEST_uint_eq(initial.s.stats.sh_has_supported_versions, 1) - && TEST_ptr(sess = SSL_get1_session(initial.c.ssl)) - && TEST_int_eq(SSL_CTX_set_tlsext_ticket_keys(s, k2, sizeof(k2)), 1) - && TEST_true(tls_channel_init(c, s, &resumed)) - && TEST_true(SSL_set_session(resumed.c.ssl, sess)) - && TEST_true(create_ssl_connection(resumed.s.ssl, resumed.c.ssl, SSL_ERROR_NONE)) - && TEST_false(SSL_session_reused(resumed.c.ssl)) - && TEST_uint_eq(resumed.s.stats.nst_msgs, 2) - && TEST_uint_eq(resumed.c.stats.nst_msgs, 2) - && TEST_uint_eq(resumed.c.stats.tickets, 2) - && TEST_uint_eq(resumed.s.stats.tickets, 2) - && TEST_uint_eq(resumed.s.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(resumed.c.stats.ch_has_psk_kex_modes, 1) - && TEST_uint_eq(resumed.c.stats.sh_has_supported_versions, 1) - && TEST_uint_eq(resumed.s.stats.sh_has_supported_versions, 1); - - SSL_SESSION_free(sess); - tls_channel_fini(&initial); - tls_channel_fini(&resumed); - SSL_CTX_free(c); - SSL_CTX_free(s); - return test; -} - -OPT_TEST_DECLARE_USAGE("\n") - -int setup_tests(void) -{ - if (!test_skip_common_options()) { - TEST_error("Error parsing test options\n"); - return 0; - } - - if (!TEST_ptr(cert = test_get_argument(0)) - || !TEST_ptr(pkey = test_get_argument(1))) - return 0; - - stats_idx = SSL_get_ex_new_index(0, NULL, NULL, NULL, NULL); - ADD_TEST(test_tls12_ticket_enable); - ADD_TEST(test_tls12_ticket_disable_server); - ADD_TEST(test_tls13_ticket_ciphersuite_mismatch); - ADD_TEST(test_tls13_ticket_enable); - ADD_TEST(test_tls13_ticket_initial_set_num_tickets_zero); - ADD_TEST(test_tls13_ticket_resumed_set_num_tickets_zero); - ADD_TEST(test_tls13_ticket_disable_server); - ADD_TEST(test_tls13_ticket_no_decrypt); - - return 1; -} diff --git a/test/tls_groups_list_test.c b/test/tls_groups_list_test.c deleted file mode 100644 index 9770393634..0000000000 --- a/test/tls_groups_list_test.c +++ /dev/null @@ -1,411 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -/* - * Tests for the TLS supported-groups list parser (tls1_set_groups_list()), - * driven through the public SSL_CTX_set1_groups_list() entry point. - * - * The parser maintains three flat arrays and their bookkeeping in SSL_CTX: - * ctx->ext.supportedgroups[0..supportedgroups_len) - groups, in order - * ctx->ext.tuples[0..tuples_len) - group count per tuple - * ctx->ext.keyshares[0..keyshares_len) - keyshare group IDs - * with the governing invariant that the per-tuple counts sum to the group - * count: sum(tuples) == supportedgroups_len. Those fields are not visible - * through the public API, so we include ssl_local.h and check them directly. - * - * Several of the cases below are regressions for GitHub #31315, where the - * remove-group path could leave tuples/keyshares out of step with the group - * array (manifesting as an out-of-bounds read under a sanitizer). - */ - -#include -#include "internal/nelem.h" -#include "internal/tlsgroups.h" -#include "../ssl/ssl_local.h" -#include "testutil.h" - -#define MAX_GROUPS 8 -#define MAX_TUPLES 8 -#define MAX_KS 8 - -/* - * Sentinel used in ctx->ext.keyshares to mean "a single keyshare from the - * first supported group" (set when no '*' prefix appears anywhere). - */ -#define KS_FIRST 0 - -typedef struct { - const char *desc; - const char *list; /* input passed to set1_groups_list */ - uint16_t groups[MAX_GROUPS]; /* expected groups, in order */ - size_t ngroups; - size_t tuples[MAX_TUPLES]; /* expected per-tuple group counts */ - size_t ntuples; - uint16_t keyshares[MAX_KS]; /* expected keyshares (KS_FIRST == 0) */ - size_t nkeyshares; -} TESTCASE; - -static const TESTCASE cases[] = { - /* --- Well-formed baselines --------------------------------------- */ - { - "single tuple, two groups, implicit keyshare", - "X25519:prime256v1", - { OSSL_TLS_GROUP_ID_x25519, OSSL_TLS_GROUP_ID_secp256r1 }, - 2, - { 2 }, - 1, - { KS_FIRST }, - 1, - }, - { - "two tuples, implicit keyshare", - "X25519/prime256v1", - { OSSL_TLS_GROUP_ID_x25519, OSSL_TLS_GROUP_ID_secp256r1 }, - 2, - { 1, 1 }, - 2, - { KS_FIRST }, - 1, - }, - { - "explicit keyshare prefix", - "*X25519:prime256v1", - { OSSL_TLS_GROUP_ID_x25519, OSSL_TLS_GROUP_ID_secp256r1 }, - 2, - { 2 }, - 1, - { OSSL_TLS_GROUP_ID_x25519 }, - 1, - }, - - /* --- #31315: removal that empties a *closed* tuple --------------- */ - { - /* - * -X25519 empties closed tuple 0; it must be excised and the - * active-tuple counter shifted down (was: "1 group, 0 tuples"). - */ - "remove empties closed tuple (excision)", - "X25519/prime256v1:-X25519", - { OSSL_TLS_GROUP_ID_secp256r1 }, - 1, - { 1 }, - 1, - { KS_FIRST }, - 1, - }, - { - /* - * Removed group carried the keyshare and its tuple empties: the - * keyshare must be dropped, not floated onto another tuple's group - * (was: "1 group, tuples {1,1}", keyshare pointing at prime256v1). - */ - "remove keyshared group empties tuple (drop, not float)", - "*X25519/prime256v1/-X25519", - { OSSL_TLS_GROUP_ID_secp256r1 }, - 1, - { 1 }, - 1, - { KS_FIRST }, - 1, - }, - { - /* - * Two removals, each emptying a distinct closed tuple (was: - * "3 groups but tuple counts summing to 5"). - */ - "two removals empty two closed tuples", - "X25519/secp256r1:secp384r1:secp521r1/*X448:-X25519/-X448", - { OSSL_TLS_GROUP_ID_secp256r1, OSSL_TLS_GROUP_ID_secp384r1, - OSSL_TLS_GROUP_ID_secp521r1 }, - 3, - { 3 }, - 1, - { KS_FIRST }, - 1, - }, - - /* --- Removal from the *active* tuple (no excision) --------------- */ - { - "remove empties the active tuple only", - "X25519:-X25519", - { 0 }, - 0, - { 0 }, - 0, - { 0 }, - 0, - }, - { - "closed tuple intact, active tuple emptied and discarded", - "X25519/prime256v1:-prime256v1", - { OSSL_TLS_GROUP_ID_x25519 }, - 1, - { 1 }, - 1, - { KS_FIRST }, - 1, - }, - { - "keyshared group removed from active tuple", - "X25519/secp384r1/*X448:-X448", - { OSSL_TLS_GROUP_ID_x25519, OSSL_TLS_GROUP_ID_secp384r1 }, - 2, - { 1, 1 }, - 2, - { KS_FIRST }, - 1, - }, - - /* --- Legitimate keyshare retention (tuple not emptied) ----------- */ - { - /* - * Removing the keyshared X25519 from a tuple that still has - * prime256v1: prime256v1's own keyshare is retained. - */ - "remove one of two keyshares, tuple survives", - "*X25519:*prime256v1:-X25519", - { OSSL_TLS_GROUP_ID_secp256r1 }, - 1, - { 1 }, - 1, - { OSSL_TLS_GROUP_ID_secp256r1 }, - 1, - }, - - /* --- Keyshare floats *within* its own (surviving, closed) tuple --- */ - { - /* - * X25519 carried the keyshare in closed tuple 0 {X25519,secp384r1}; - * removing it must float the keyshare to secp384r1 (the remaining - * group of tuple 0), NOT to secp256r1 which is in tuple 1. - */ - "keyshare floats to remaining group of same tuple", - "*X25519:secp384r1/secp256r1:-X25519", - { OSSL_TLS_GROUP_ID_secp384r1, OSSL_TLS_GROUP_ID_secp256r1 }, - 2, - { 1, 1 }, - 2, - { OSSL_TLS_GROUP_ID_secp384r1 }, - 1, - }, - { - /* - * Removed keyshared group is in the middle of tuple 0; its keyshare - * floats to the tuple's first group (X25519), and tuple 1's own - * keyshare (secp256r1) is untouched. A float that escaped tuple 0 - * would corrupt this to a different keyshare set. - */ - "mid-tuple keyshare floats to tuple head, not across tuples", - "X25519:*X448:secp384r1 / *secp256r1:-X448", - { OSSL_TLS_GROUP_ID_x25519, OSSL_TLS_GROUP_ID_secp384r1, - OSSL_TLS_GROUP_ID_secp256r1 }, - 3, - { 2, 1 }, - 2, - { OSSL_TLS_GROUP_ID_x25519, OSSL_TLS_GROUP_ID_secp256r1 }, - 2, - }, -}; - -/* - * Assert every structural invariant the parser must maintain, from the parsed - * state alone (independent of the specific input): - * - * 1. Partition: sum(tuples[0..tuples_len)) == supportedgroups_len. - * 2. No empty tuples survive the final compaction (every count > 0). - * 3. Groups are distinct. - * 4. Keyshares are either the lone "first group" sentinel {0}, or a set of - * distinct non-zero group IDs that appear as an ordered subsequence of - * the supported groups (never the sentinel mixed with real IDs). - * - * These are exactly the properties that were violated by GitHub #31315 (a - * broken partition led to an out-of-bounds read in the remove path). - */ -static int check_invariants(SSL_CTX *ctx) -{ - size_t i, j, sum; - int ok = 1; - - /* 1 + 2: partition, with no zero-count tuple left behind. */ - for (i = 0, sum = 0; i < ctx->ext.tuples_len; i++) { - if (!TEST_size_t_gt(ctx->ext.tuples[i], 0)) { - TEST_error("zero-count tuple at index %zu survived", i); - ok = 0; - } - sum += ctx->ext.tuples[i]; - } - if (!TEST_size_t_eq(sum, ctx->ext.supportedgroups_len)) - ok = 0; - - /* 3: groups distinct. */ - for (i = 0; i < ctx->ext.supportedgroups_len; i++) - for (j = 0; j < i; j++) - if (!TEST_uint_ne(ctx->ext.supportedgroups[i], - ctx->ext.supportedgroups[j])) - ok = 0; - - /* 4: keyshare shape. */ - if (ctx->ext.keyshares_len == 1 && ctx->ext.keyshares[0] == KS_FIRST) { - /* Sentinel form: a single implicit keyshare from the first group. */ - } else { - size_t g = 0; - - for (i = 0; i < ctx->ext.keyshares_len; i++) { - uint16_t ks = ctx->ext.keyshares[i]; - - if (!TEST_uint_ne(ks, KS_FIRST)) { /* sentinel must be alone */ - ok = 0; - continue; - } - for (j = 0; j < i; j++) /* distinct */ - if (!TEST_uint_ne(ks, ctx->ext.keyshares[j])) - ok = 0; - while (g < ctx->ext.supportedgroups_len - && ctx->ext.supportedgroups[g] != ks) - g++; /* ordered subsequence */ - if (!TEST_size_t_lt(g, ctx->ext.supportedgroups_len)) { - TEST_error("keyshare 0x%04X not an in-order group", ks); - ok = 0; - break; - } - g++; - } - } - - return ok; -} - -static int run_case(int idx) -{ - const TESTCASE *tc = &cases[idx]; - SSL_CTX *ctx = NULL; - int ret = 0; - size_t i; - - TEST_info("case %d: %s [\"%s\"]", idx, tc->desc, tc->list); - - if (!TEST_ptr(ctx = SSL_CTX_new(TLS_method()))) - goto end; - - if (!TEST_int_eq(SSL_CTX_set1_groups_list(ctx, tc->list), 1)) - goto end; - - /* Groups: exact contents and order. */ - if (!TEST_size_t_eq(ctx->ext.supportedgroups_len, tc->ngroups)) - goto end; - for (i = 0; i < tc->ngroups; i++) - if (!TEST_uint_eq(ctx->ext.supportedgroups[i], tc->groups[i])) - goto end; - - /* Tuples: exact per-tuple counts. */ - if (!TEST_size_t_eq(ctx->ext.tuples_len, tc->ntuples)) - goto end; - for (i = 0; i < tc->ntuples; i++) - if (!TEST_size_t_eq(ctx->ext.tuples[i], tc->tuples[i])) - goto end; - - /* Keyshares: exact contents (KS_FIRST == 0 sentinel). */ - if (!TEST_size_t_eq(ctx->ext.keyshares_len, tc->nkeyshares)) - goto end; - for (i = 0; i < tc->nkeyshares; i++) - if (!TEST_uint_eq(ctx->ext.keyshares[i], tc->keyshares[i])) - goto end; - - if (!check_invariants(ctx)) - goto end; - - ret = 1; -end: - SSL_CTX_free(ctx); - return ret; -} - -/* - * Synthetic edge-case forms. We do not spell out the exact parsed result for - * these (that would just re-derive the parser); instead we assert the parse - * succeeds or fails as expected and, on success, that all invariants hold. - * These deliberately stress the corners of the remove/dedup/keyshare paths. - */ -typedef struct { - const char *list; - int expect_ok; /* 1: parse succeeds; 0: syntax/parse error */ -} EDGECASE; - -static const EDGECASE edgecases[] = { - /* --- valid, invariant-preserving corner cases --- */ - { "X25519", 1 }, - { "X25519:secp256r1:secp384r1:secp521r1:X448", 1 }, /* one full tuple */ - { "X25519/secp256r1/secp384r1/secp521r1/X448", 1 }, /* many tuples */ - { "*X25519:secp256r1", 1 }, - { "X25519:X25519", 1 }, /* dup within tuple */ - { "X25519/X25519", 1 }, /* dup across tuples */ - { "X25519:-secp384r1", 1 }, /* remove absent: no-op */ - { "X25519:-X25519", 1 }, /* empty the active tuple */ - { "X25519/secp256r1:-X25519", 1 }, /* excise closed tuple */ - { "X25519/secp256r1/secp384r1:-secp256r1", 1 }, /* excise middle tuple */ - { "X25519:secp256r1/secp384r1:-secp384r1", 1 }, /* empty active, discard */ - { "*X25519/prime256v1/-X25519", 1 }, /* #31315: drop, not float */ - { "X25519/secp256r1:secp384r1:secp521r1/*X448:-X25519/-X448", 1 }, /* #31315 */ - { "*X25519:*secp256r1:-X25519", 1 }, /* keyshare survives sibling */ - { "X25519/secp256r1:-X25519:secp384r1", 1 }, /* excise then refill */ - { "X25519:secp256r1:X448:-X25519:-X448", 1 }, /* multiple removals */ - { "?*BOGUS:X25519 / *secp256r1", 1 }, /* stacked prefix, unknown */ - { "X25519:?BOGUS:secp256r1", 1 }, /* ignore unknown mid-tuple */ - { "*X25519:DEFAULT:-secp256r1:-X448", 1 }, /* DEFAULT + removals */ - { "DEFAULT:-X25519:-?curveSM2:-?ffdhe2048:-?ffdhe3072", 1 }, - { "secp256r1:DEFAULT", 1 }, /* prepend then DEFAULT */ - - /* --- expected syntax / parse errors --- */ - { "X25519//secp256r1", 0 }, /* empty tuple */ - { "X25519::secp256r1", 0 }, /* empty group */ - { ":X25519", 0 }, - { "X25519:", 0 }, - { "/X25519", 0 }, - { "X25519/", 0 }, - { "**X25519", 0 }, /* double keyshare prefix */ - { "??X25519", 0 }, - { "--X25519", 0 }, - { "X25519:NOTAREALGROUP", 0 }, /* unknown w/o '?' */ - { "-DEFAULT", 0 }, /* prefix on pseudo-group */ - { "?DEFAULT", 0 }, -}; - -static int run_edge(int idx) -{ - const EDGECASE *tc = &edgecases[idx]; - SSL_CTX *ctx = NULL; - int ret = 0, r; - - TEST_info("edge %d: [\"%s\"] expect %s", idx, tc->list, - tc->expect_ok ? "ok" : "error"); - - if (!TEST_ptr(ctx = SSL_CTX_new(TLS_method()))) - goto end; - - r = SSL_CTX_set1_groups_list(ctx, tc->list); - if (tc->expect_ok) { - if (!TEST_int_eq(r, 1) || !check_invariants(ctx)) - goto end; - } else { - if (!TEST_int_eq(r, 0)) - goto end; - } - - ret = 1; -end: - SSL_CTX_free(ctx); - return ret; -} - -int setup_tests(void) -{ - ADD_ALL_TESTS(run_case, (int)OSSL_NELEM(cases)); - ADD_ALL_TESTS(run_edge, (int)OSSL_NELEM(edgecases)); - return 1; -} diff --git a/test/trace_api_test.c b/test/trace_api_test.c index a648019b86..532c31be2b 100644 --- a/test/trace_api_test.c +++ b/test/trace_api_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -147,7 +147,7 @@ static int test_trace_channel(void) ret = put_trace_output(); len = BIO_get_mem_data(bio, &p_buf); - if (!TEST_size_t_eq(len, expected_len) || !TEST_strn_eq(p_buf, expected, len)) + if (!TEST_strn2_eq(p_buf, len, expected, expected_len)) ret = 0; ret = TEST_int_eq(OSSL_trace_set_channel(OSSL_TRACE_CATEGORY_HTTP, NULL), 1) && ret; diff --git a/test/unit/.gitignore b/test/unit/.gitignore deleted file mode 100644 index 2576bf0319..0000000000 --- a/test/unit/.gitignore +++ /dev/null @@ -1,13 +0,0 @@ -* -!*/ -!*.c -!*.h -!*.inc -!*.pl -!*.t -!*.txt -!*.cnf -!*.pem -!build.info -!.gitignore -!README* diff --git a/test/unit/README.md b/test/unit/README.md deleted file mode 100644 index b945b438ab..0000000000 --- a/test/unit/README.md +++ /dev/null @@ -1,564 +0,0 @@ -OpenSSL Unit Tests -================== - -This directory holds the OpenSSL *unit* tests. Their purpose is to test a -single function, or a small group of related functions, in isolation by -replacing the other functions it calls with mocks. This makes it possible to -test logic that is otherwise hard to reach: error and failure paths of -dependencies, branches that depend on the exact arguments passed to a -collaborator, or code whose real dependencies would require network access, -specific hardware, or elaborate setup. Each test can then drive the function -under test through a precise, fully controlled sequence of calls and return -values, and assert on exactly how it interacts with its surroundings. - -Unit tests are not meant to replace the broader, integration-style testing that -makes up most of `test/`, and they are not the right tool for everything. They -are used for selected, self-contained pieces of the library where the mocking -boundary is clean and the payoff is high, the BIO layer being the main example. -Most code continues to be tested through the ordinary recipes (typically built -on `testutil`, and generally without mocking). - -Requirements ------------- - -The tests are built on [cmocka], a lightweight C unit-testing framework, and -rely on the GNU/BSD linker's `--wrap` option to intercept calls into the -function under test's dependencies. Because `--wrap` is required, unit tests -are only built on platforms that support it (Linux and BSD only at present), -and only when the build is configured with `enable-unit-tests`. - -[cmocka]: https://cmocka.org/ - -Tests must build and run against cmocka 1.1.5, as that is still the version -shipped by some currently supported enterprise and LTS distributions. Do not -rely on APIs introduced in cmocka 2.x, since a test that needs them cannot be -built on those systems; when in doubt, check against the 1.1.5 headers rather -than the latest online documentation. - -Building and Running --------------------- - -Unit tests are disabled by default. To build them, configure with -`enable-unit-tests` and make sure the cmocka development files are installed -on the system: - -```console -$ sudo apt-get install libcmocka-dev # Debian/Ubuntu -$ ./config enable-unit-tests -$ make -``` - -If cmocka is installed in a non-standard location, point the build at it with: - -```console -$ ./config enable-unit-tests \ - --with-cmocka-include=/path/to/include \ - --with-cmocka-lib=/path/to/lib -``` - -On a platform without `--wrap` support, `enable-unit-tests` is silently turned -off during configuration; the rest of the build proceeds normally. - -The whole unit-test suite runs as part of the normal test target: - -```console -$ make test -``` - -It is gathered under a single recipe, so it can also be run on its own: - -```console -$ make test TESTS=test_unit -``` - -The recipe discovers every executable named `test_*` under the build's -`test/unit` tree and runs each one, so a newly added test binary is picked up -automatically once it builds. Each binary reports its results in TAP, which the -harness consumes directly. - -Because each test is an ordinary standalone executable, it can also be run -directly, which is convenient when debugging a single failure under a debugger: - -```console -$ gdb test/unit/crypto/foo/test_bar -``` - -Running the binary on its own prints its TAP output to the terminal and makes -it straightforward to set breakpoints in a specific test, mock, or in the -function under test. - -For debugging it is worth configuring the build with `--debug` as well, e.g. -`./config enable-unit-tests --debug`. A normal build is optimized, which makes -stepping through code and inspecting variables awkward; `--debug` lowers the -optimization level and adds debug information, giving a much more predictable -experience under gdb. - -Anatomy of a Unit Test ----------------------- - -A unit test is a single C source file laid out under `test/unit/` in a path -that mirrors the location of the code it exercises. For example, code that -lives in `crypto/foo/bar.c` is tested by `test/unit/crypto/foo/test_bar.c`. The -file is self-contained: it provides its own `main()`, registers a list of test -cases, and runs them as a cmocka group. - -The body of a test file is organised into a few clearly separated sections, -conventionally introduced by short comments, in this order: - - * the `__wrap_*` mock implementations (`/* wraps */`), - * thin `expect_*` helpers that program each mock (`/* expectations */`), - * any shared helpers (fake methods, accessors, reset routines), - * the `setup`/`teardown` fixtures, - * the test functions themselves, and - * `main()`, which builds the `CMUnitTest` array and runs it. - -Keeping these sections in this order and clearly labelled makes a test file -predictable to read and easy to extend. - -### main() and the test list - -`main()` declares a `struct CMUnitTest` array, selects TAP output, and runs the -group: - -```c -int main(void) -{ - const struct CMUnitTest tests[] = { - cmocka_unit_test(test_something_simple), - cmocka_unit_test_setup_teardown(test_with_fixture, setup, teardown), - }; - - cmocka_set_message_output(CM_OUTPUT_TAP); - - return cmocka_run_group_tests(tests, NULL, NULL); -} -``` - -Always select `CM_OUTPUT_TAP` so the harness can parse the results. Use -`cmocka_unit_test()` for tests that need no per-test fixture, and -`cmocka_unit_test_setup_teardown()` when a test needs a fresh object built -before it and cleaned up after. The last two arguments to -`cmocka_run_group_tests()` are an optional group-level setup and teardown, run -once before and after the whole group; pass `NULL` when they are not needed. - -It is common to wrap the registration macros in a short local macro when most -tests share the same fixture, e.g. - -```c -#define MY_TEST(name) \ - cmocka_unit_test_setup_teardown(name, setup, teardown) -``` - -### A test function - -Each test is a function with the signature `void (void **state)`. The `state` -argument carries whatever a `setup` fixture stored there; tests that do not use -it should cast it to `void` to silence warnings: - -```c -static void test_addr_family(void **state) -{ - BIO_ADDR ap; - - (void)state; - memset(&ap, 0, sizeof(ap)); - ap.sa.sa_family = AF_INET; - assert_int_equal(BIO_ADDR_family(&ap), AF_INET); -} -``` - -Assertions come from cmocka: `assert_int_equal`, `assert_ptr_equal`, -`assert_true`, `assert_false`, `assert_null`, `assert_non_null`, -`assert_string_equal`, `assert_memory_equal`, and friends. A failing assertion -aborts the current test and marks it failed without disturbing the others. - -How the Expectation Mechanism Works ------------------------------------ - -Before writing mocks it helps to understand what cmocka is actually doing, -because the model is simple once stated plainly and it makes the rest of the -API obvious. - -For each `(function, parameter)` pair cmocka keeps an internal queue. The -`expect_*()` macros, called from the test, push values onto these queues. The -`check_expected()` macro, called from inside the mock, pops the next value and -compares it against the argument the mock actually received; a mismatch fails -the test. Return values work the same way: `will_return()` pushes a value from -the test, and `mock_type()`/`mock_ptr_type()` pops it inside the mock to use as -the return value. Call accounting is analogous: `expect_function_call()` pushes -an expected call and `function_called()` consumes one. - -So a test programs, in order, the calls it expects the function under test to -make, and the mocks consume those programmed entries as the calls actually -happen. Entries are consumed in the order they were queued, which is why the -`expect_*`/`will_return` calls in a test must be written in the same order the -function under test will call its dependencies. At the end of the test cmocka -fails if any queued entry was never consumed, or if a mock is called with -nothing queued for it. This is what turns the expected interaction sequence -into a checked specification rather than a loose suggestion. - -Because each entry covers a single call, a function that is expected to be -called more than once is programmed by pushing the entries that many times, in -the order the calls will occur: - -```c -/* the SUT is expected to call BIO_socket twice */ -expect_BIO_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, INVALID_SOCKET); -expect_BIO_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, FAKE_SOCKET); -``` - -cmocka also offers `_count` variants (such as `will_return_count()`, -`expect_value_count()` and `expect_function_calls()`) that program one entry -for a given number of calls in a single statement. These are not just a -shorthand for repeating the macro: they carry a different ordering semantics. -Repeating `expect_function_call()` pins each call's position in the overall -sequence, so any other expected call programmed between two of them must -actually occur between them. `expect_function_calls(f, 2)`, by contrast, only -requires that `f` is called twice somewhere; other calls may fall before, -after, or in between without failing the test. Prefer repeating the plain -macros when the interleaving matters (which is the common case), and reach for -the count variants only when a function is genuinely called many times and its -position relative to the others is not what the test is checking. - -Two consequences are worth keeping in mind: - - * **cmocka has nothing to do with `--wrap`.** The expectation machinery is - just these queues plus the `check_expected`/`mock`/`function_called` - macros. It works in any function whose body calls them. `--wrap` is merely - the linker trick OpenSSL uses to *substitute* a dependency with a mock; the - two are independent. The same `expect_*` style is used below for purpose- - built fake objects that are never wrapped at all (see Fixtures). - - * Because matching is per parameter and in order, a mock must call - `check_expected()` for exactly the parameters the test programs with - `expect_*()`, and the `will_return`/`mock_type` counts must balance. - -Mocking Dependencies with --wrap --------------------------------- - -The core technique is link-time function interception. When a binary is linked -with `-Wl,--wrap=foo`, every call to `foo` is redirected to a function named -`__wrap_foo`, and the original is still reachable as `__real_foo`. This lets a -test replace the function under test's dependencies with mocks that record how -they were called and return whatever the test dictates. - -### Declaring the wraps - -The set of wrapped symbols for a test binary is declared in the `build.info` -file (see below). For each wrapped symbol the test file provides a -`__wrap_` function with exactly the same signature as the real one. A -prototype is also needed to satisfy `-Wmissing-prototypes`: - -```c -int __wrap_BIO_socket(int domain, int socktype, int protocol, int options); - -int __wrap_BIO_socket(int domain, int socktype, int protocol, int options) -{ - function_called(); - check_expected(domain); - check_expected(socktype); - check_expected(protocol); - check_expected(options); - return mock_type(int); -} -``` - -A typical mock does three things: - - * `function_called()` records that the function was invoked, balanced against - the test's `expect_function_call()`. - * `check_expected(param)` (or `check_expected_ptr(param)` for pointers) - verifies the argument against the value the test queued. Use the `_ptr` - variant for pointer parameters. - * `mock_type(T)` (or `mock_ptr_type(T)` for pointers) returns the value the - test queued for this call. A `void` mock omits this. - -Mocks may also have deliberate side effects when the real function would -produce one that the code under test depends on. For example, a function that -fills a caller-supplied buffer should have its mock write into that buffer, and -a fatal-error reporter that the code expects to flip a state flag should do so: - -```c -int __wrap_ssl_fill_hello_random(SSL_CONNECTION *s, int server, - unsigned char *field, size_t len, DOWNGRADE dgrd) -{ - function_called(); - check_expected_ptr(s); - check_expected(server); - check_expected_ptr(field); - check_expected(len); - check_expected(dgrd); - - if (field != NULL) - memset(field, 0xAB, len); - - return mock_type(int); -} -``` - -Keep these side effects minimal and confined to what the function under test -genuinely observes; the goal is to reproduce the contract of the real function, -not to re-implement it. - -### Programming the mocks: expectations - -Rather than scatter `expect_function_call`/`expect_value`/`will_return` calls -through every test, wrap each mock in a small `expect_` helper that takes -the expected arguments and the return value. This keeps the tests readable and, -crucially, gives a single place to update when a function's signature or call -contract changes: - -```c -static void expect_BIO_socket(int domain, int socktype, int protocol, - int options, int rc) -{ - expect_function_call(__wrap_BIO_socket); - expect_value(__wrap_BIO_socket, domain, domain); - expect_value(__wrap_BIO_socket, socktype, socktype); - expect_value(__wrap_BIO_socket, protocol, protocol); - expect_value(__wrap_BIO_socket, options, options); - will_return(__wrap_BIO_socket, rc); -} -``` - -The most useful cmocka primitives here are: - - * `expect_function_call(f)`: expect one call to `f`. Pair every - `function_called()` in a mock with one of these. - * `expect_value(f, param, value)`: the argument must equal `value`. This is - consumed by `check_expected(param)`. - * `expect_any(f, param)`: the argument may be anything; still consumed by - `check_expected(param)`, so it must be present whenever the mock checks - that parameter. - * `will_return(f, value)`: queue a return value for the next call, - retrieved by `mock_type`/`mock_ptr_type`. Queue several in order if the - mock pulls more than one value (e.g. a return code followed by an - out-parameter payload). - -When a mock conditionally retrieves a second value, the matching expectation -must queue it under the same condition, so the queues stay aligned: - -```c -static void expect_BIO_lookup(BIO_ADDRINFO *res, int rc) -{ - expect_function_call(__wrap_BIO_lookup); - expect_any(__wrap_BIO_lookup, host); - expect_any(__wrap_BIO_lookup, service); - expect_value(__wrap_BIO_lookup, lookup_type, BIO_LOOKUP_SERVER); - expect_any(__wrap_BIO_lookup, family); - expect_any(__wrap_BIO_lookup, socktype); - will_return(__wrap_BIO_lookup, rc); - if (rc == 1) - will_return(__wrap_BIO_lookup, res); -} -``` - -### Writing a test against the mocks - -With the helpers in place, a test reads as: arrange the object, declare the -expected sequence of calls, invoke the function under test, and assert on the -result and any observable state. - -```c -static void test_socket_then_listen_fails(void **state) -{ - BIO *bio = *state; - - expect_BIO_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, FAKE_SOCKET); - expect_BIO_listen(FAKE_SOCKET, &expected_addr, 0, 0); - expect_BIO_closesocket(FAKE_SOCKET, 0); - - assert_true(BIO_do_accept(bio) <= 0); -} -``` - -If the function under test makes a call that was not programmed, or fails to -make one that was, or passes an argument that does not match, cmocka fails the -test and reports the mismatch. - -Fixtures and Real Fake Objects ------------------------------- - -A `setup` function allocates or initialises whatever object the test needs and -stores it through `*state`; the matching `teardown` releases it. Returning -non-zero from either aborts the test as an error. - -```c -static int setup(void **state) -{ - BIO *bio = BIO_new(BIO_s_accept()); - - assert_non_null(bio); - *state = bio; - return 0; -} - -static int teardown(void **state) -{ - if (*state != NULL) - BIO_free(*state); - return 0; -} -``` - -A group-level setup/teardown (the last two arguments to -`cmocka_run_group_tests`) is the place for one-time work shared by every test, -such as initialising static fixtures used across the file. - -Two practical cautions apply when fixtures interact with wrapped functions: - - * Teardown can itself trigger wrapped calls. If freeing the object under test - would invoke a wrapped function (for instance, closing a socket), reset the - relevant fields to safe sentinels before the free so no *unexpected* mock - call is made, or program the expectation for it. A common pattern is a - small `reset_for_teardown()` helper called at the end of any test that left - such state behind. - - * It is often cleaner to drive an object through its public interface with a - *real* minimal fake than to mock everything. For example, building a small - fake `BIO_METHOD` whose read/write callbacks are themselves cmocka mocks - (using the same `function_called`/`check_expected`/`mock_type` machinery, - even though nothing is wrapped) lets a test exercise the forwarding logic - of the object under test without wrapping low-level syscalls. Choose - whichever boundary keeps the test focused on the function actually under - examination. - -Conditional Compilation ------------------------- - -Mirror the `#ifdef`/`#ifndef` guards of the code under test. If a function only -exists under a build option, guard both the test function and its registration -in `main()` with the same condition, so the suite still builds in every -configuration: - -```c -#ifndef OPENSSL_NO_UNIX_SOCK -static void test_addr_make_unix(void **state) -{ - ... -} -#endif - -int main(void) -{ - const struct CMUnitTest tests[] = { -#ifndef OPENSSL_NO_UNIX_SOCK - cmocka_unit_test(test_addr_make_unix), -#endif - ... - }; - ... -} -``` - -When an entire test file only makes sense under some option, guard the whole -body and provide a trivial `main()` for the disabled case so the binary still -links and the recipe still finds something to run: - -```c -#ifndef OPENSSL_NO_SOCK - -/* ... the tests ... */ - -#else - -int main(void) -{ - return 0; -} - -#endif -``` - -Wiring a New Test into the Build --------------------------------- - -Test binaries are declared in `test/unit/build.info`. A unit test that wraps no -symbols would not be linked against cmocka, so **every** unit test must declare -at least one `WRAP[]` entry: this is what causes both the `--wrap` link flags -and `-lcmocka` to be added for that binary. The directives needed per test are -`PROGRAMS`, `SOURCE`, `INCLUDE`, `DEPEND`, and `WRAP`: - -```text -PROGRAMS{noinst}=crypto/foo/test_bar -SOURCE[crypto/foo/test_bar]=crypto/foo/test_bar.c -INCLUDE[crypto/foo/test_bar]=../../include ../../include/internal \ - ../../crypto/foo -DEPEND[crypto/foo/test_bar]=../../libcrypto.a -WRAP[crypto/foo/test_bar]=BIO_socket BIO_listen BIO_closesocket -``` - -Notes: - - * `PROGRAMS{noinst}` marks the binary as not installed. - * `INCLUDE[]` lists the directories needed to reach the headers the test - uses, including any internal directory that declares the types or the - function under test. The cmocka include path is added automatically to - every target that has a `WRAP[]` entry, so it need not be listed. - * `DEPEND[]` links the appropriate static libraries: `../../libcrypto.a`, - and `../../libssl.a` as well for libssl code. - * `WRAP[]` is the whitespace-separated list of symbols to intercept; it may - be split over several lines with trailing backslashes. List exactly the - dependencies the test mocks. - -Because the recipe discovers binaries by name, no change to the Perl recipe is -needed; building the new `test_*` binary is enough for it to run under -`test_unit`. - -Generating Mock Stubs with mkwraps.pl -------------------------------------- - -Writing the `__wrap_*` and `expect_*` boilerplate by hand for a long `WRAP[]` -list is tedious and error-prone, so the helper script `util/mkwraps.pl` -generates a first draft from the `build.info` declaration. It reads the -`WRAP[]` list, searches the headers under the target's `INCLUDE[]` -directories for each function's prototype, and emits matching wrap functions -and expectation helpers. Functions not found there (typically libc/POSIX -functions such as `read` or `socket`) are looked up under the compiler's -default system include paths, and emitted with angle-bracket includes. - -```console -$ ./util/mkwraps.pl --build-info test/unit/build.info \ - --target crypto/foo/test_bar -``` - -Useful options: - - * `--mode wraps|expects|both`: emit only the `__wrap_*` functions, only the - `expect_*` helpers, or both (the default). - * `--include DIR`: add an extra header search directory beyond those in - `INCLUDE[]`. Cumulative. - * `--cc NAME`: C compiler queried for the system include paths (default - `$CC` or `cc`). - * `--no-system`: do not fall back to the compiler's system include - directories for functions missing from the project headers. - * `--output FILE`: write to a file instead of standard output. - * `--verbose`: report progress and where each prototype was found. - -The output is a *starting point*, not a finished test. The generated mocks call -`function_called()`, check every parameter, and return a `mock_type` value, but -any real behaviour still has to be added by hand: side effects on -out-parameters, variadic forwarding, conditional `will_return` payloads, and -the use of internal headers for opaque types. Generated `#include` lines and -parameter checks frequently need adjusting. Treat the script as a way to skip -the mechanical typing, then review and edit every generated function. - -Conventions ------------ - -Unit tests follow the usual OpenSSL C coding style (enforced via -clang-format), so it is not repeated here. A few conventions specific to unit -tests keep them consistent and maintainable: - - * Order the file as wraps, expectations, helpers, fixtures, tests, then - `main()`, with the short section-header comments shown above. - * Name test functions `test__` so the suite reads as a list - of behaviours, and add a brief comment on any test whose setup or expected - sequence is not obvious from the name. - * Give every mock a matching `expect_` helper and route all programming - of that mock through it rather than inlining `expect_value`/`will_return` - in the tests, so a change to a function's contract is fixed in one place. - * Keep each test focused on one behaviour, and prefer several small tests - over one test with many branches. - * Always emit TAP output, and always reset fixture state that would otherwise - cause an unexpected wrapped call during teardown. diff --git a/test/unit/build.info b/test/unit/build.info deleted file mode 100644 index ac04787457..0000000000 --- a/test/unit/build.info +++ /dev/null @@ -1,67 +0,0 @@ -IF[{- $config{target} =~ /^(?:linux|BSD)/ -}] - PROGRAMS{noinst}=crypto/bio/test_bio_addr - SOURCE[crypto/bio/test_bio_addr]=crypto/bio/test_bio_addr.c - INCLUDE[crypto/bio/test_bio_addr]=../../include ../../crypto/bio - DEPEND[crypto/bio/test_bio_addr]=../../libcrypto.a - WRAP[crypto/bio/test_bio_addr]=BIO_sock_init getnameinfo freeaddrinfo - - PROGRAMS{noinst}=crypto/bio/test_bio_sock - SOURCE[crypto/bio/test_bio_sock]=crypto/bio/test_bio_sock.c - INCLUDE[crypto/bio/test_bio_sock]=../../include ../../crypto/bio - DEPEND[crypto/bio/test_bio_sock]=../../libcrypto.a - WRAP[crypto/bio/test_bio_sock]=getsockopt setsockopt getsockname ioctl poll \ - gethostbyname BIO_lookup BIO_socket BIO_listen BIO_closesocket \ - BIO_ADDRINFO_free BIO_accept_ex BIO_sock_should_retry \ - BIO_ADDR_hostname_string BIO_ADDR_service_string - - PROGRAMS{noinst}=crypto/bio/test_bio_sock2 - SOURCE[crypto/bio/test_bio_sock2]=crypto/bio/test_bio_sock2.c - INCLUDE[crypto/bio/test_bio_sock2]=../../include ../../crypto/bio - DEPEND[crypto/bio/test_bio_sock2]=../../libcrypto.a - WRAP[crypto/bio/test_bio_sock2]=socket connect bind listen accept close \ - getsockopt setsockopt BIO_socket_nbio BIO_sock_should_retry - - PROGRAMS{noinst}=crypto/bio/test_bss_acpt - SOURCE[crypto/bio/test_bss_acpt]=crypto/bio/test_bss_acpt.c - WRAP[crypto/bio/test_bss_acpt]=BIO_lookup BIO_socket BIO_listen \ - BIO_accept_ex BIO_sock_info BIO_sock_should_retry BIO_closesocket \ - BIO_ADDR_hostname_string BIO_ADDR_service_string - INCLUDE[crypto/bio/test_bss_acpt]=../../include ../../crypto/bio - DEPEND[crypto/bio/test_bss_acpt]=../../libcrypto.a - - PROGRAMS{noinst}=crypto/bio/test_bss_conn - SOURCE[crypto/bio/test_bss_conn]=crypto/bio/test_bss_conn.c - WRAP[crypto/bio/test_bss_conn]=BIO_lookup BIO_socket BIO_connect \ - BIO_sock_should_retry BIO_closesocket BIO_socket_wait BIO_sock_error \ - read write - INCLUDE[crypto/bio/test_bss_conn]=../../include ../../crypto/bio - DEPEND[crypto/bio/test_bss_conn]=../../libcrypto.a - - PROGRAMS{noinst}=crypto/bio/test_bss_dgram - SOURCE[crypto/bio/test_bss_dgram]=crypto/bio/test_bss_dgram.c - WRAP[crypto/bio/test_bss_dgram]=recvfrom sendto write getsockname \ - getpeername BIO_closesocket BIO_socket_nbio - INCLUDE[crypto/bio/test_bss_dgram]=../../include ../../crypto/bio - DEPEND[crypto/bio/test_bss_dgram]=../../libcrypto.a - - PROGRAMS{noinst}=crypto/bio/test_bss_fd - SOURCE[crypto/bio/test_bss_fd]=crypto/bio/test_bss_fd.c - INCLUDE[crypto/bio/test_bss_fd]=../../include ../../crypto/bio - DEPEND[crypto/bio/test_bss_fd]=../../libcrypto.a - WRAP[crypto/bio/test_bss_fd]=read write lseek close - - PROGRAMS{noinst}=crypto/bio/test_bss_sock - SOURCE[crypto/bio/test_bss_sock]=crypto/bio/test_bss_sock.c - WRAP[crypto/bio/test_bss_sock]=read write BIO_closesocket - INCLUDE[crypto/bio/test_bss_sock]=../../include ../../crypto/bio - DEPEND[crypto/bio/test_bss_sock]=../../libcrypto.a -ENDIF - -IF[{- $config{target} =~ /^VC-/ -}] - PROGRAMS{noinst}=crypto/bio/test_bss_dgram_win - SOURCE[crypto/bio/test_bss_dgram_win]=crypto/bio/test_bss_dgram_win.c - UNIT_TEST[crypto/bio/test_bss_dgram_win]=cmocka detours - INCLUDE[crypto/bio/test_bss_dgram_win]=../../include ../../include/internal \ - ../../crypto/bio - DEPEND[crypto/bio/test_bss_dgram_win]=../../libcrypto -ENDIF diff --git a/test/unit/crypto/bio/test_bio_addr.c b/test/unit/crypto/bio/test_bio_addr.c deleted file mode 100644 index de92d8a0f6..0000000000 --- a/test/unit/crypto/bio/test_bio_addr.c +++ /dev/null @@ -1,1155 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include "internal/sockets.h" - -#ifdef OPENSSL_NO_SOCK - -int main(void) -{ - return 0; -} - -#else - -#include -#include -#include -#include -#include - -#include "bio_local.h" - -#include - -/* wraps */ - -int __wrap_BIO_sock_init(void); -#ifdef AI_PASSIVE -int __wrap_getnameinfo(const struct sockaddr *sa, socklen_t salen, - char *host, socklen_t hostlen, - char *serv, socklen_t servlen, int flags); -void __wrap_freeaddrinfo(struct addrinfo *res); -#endif - -int __wrap_BIO_sock_init(void) -{ - function_called(); - return mock_type(int); -} - -#ifdef AI_PASSIVE -int __wrap_getnameinfo(const struct sockaddr *sa, socklen_t salen, - char *host, socklen_t hostlen, - char *serv, socklen_t servlen, int flags) -{ - int rc; - - function_called(); - check_expected_ptr(sa); - check_expected(salen); - check_expected(flags); - rc = mock_type(int); - if (rc == 0) { - if (host != NULL) - strncpy(host, mock_ptr_type(const char *), hostlen - 1); - if (serv != NULL) - strncpy(serv, mock_ptr_type(const char *), servlen - 1); - } - return rc; -} - -void __wrap_freeaddrinfo(struct addrinfo *res) -{ - function_called(); - check_expected_ptr(res); -} -#endif /* AI_PASSIVE */ - -/* expectations */ - -static void expect_sock_init(int rc) -{ - expect_function_call(__wrap_BIO_sock_init); - will_return(__wrap_BIO_sock_init, rc); -} - -#ifdef AI_PASSIVE -static void expect_getnameinfo(const struct sockaddr *sa, socklen_t salen, - int flags, int rc, - const char *host_out, const char *serv_out) -{ - expect_function_call(__wrap_getnameinfo); - expect_value(__wrap_getnameinfo, sa, sa); - expect_value(__wrap_getnameinfo, salen, salen); - expect_value(__wrap_getnameinfo, flags, flags); - will_return(__wrap_getnameinfo, rc); - if (rc == 0) { - will_return(__wrap_getnameinfo, host_out); - will_return(__wrap_getnameinfo, serv_out); - } -} - -static void expect_freeaddrinfo(const struct addrinfo *res) -{ - expect_function_call(__wrap_freeaddrinfo); - expect_value(__wrap_freeaddrinfo, res, res); -} -#endif /* AI_PASSIVE */ - -/* BIO_ADDR_clear */ - -static void test_addr_clear(void **state) -{ - BIO_ADDR ap; - - (void)state; - memset(&ap, 0xFF, sizeof(ap)); - BIO_ADDR_clear(&ap); - assert_int_equal(ap.sa.sa_family, AF_UNSPEC); - assert_int_equal(ap.s_in.sin_port, 0); - assert_int_equal(ap.s_in.sin_addr.s_addr, 0); -} - -/* BIO_ADDR_make */ - -static void test_addr_make_ipv4(void **state) -{ - struct sockaddr_in sa4; - BIO_ADDR ap; - - (void)state; - memset(&sa4, 0, sizeof(sa4)); - sa4.sin_family = AF_INET; - sa4.sin_port = htons(443); - sa4.sin_addr.s_addr = htonl(INADDR_LOOPBACK); - - assert_int_equal(BIO_ADDR_make(&ap, (const struct sockaddr *)&sa4), 1); - assert_int_equal(ap.s_in.sin_family, AF_INET); - assert_int_equal(ap.s_in.sin_port, htons(443)); - assert_int_equal(ap.s_in.sin_addr.s_addr, htonl(INADDR_LOOPBACK)); -} - -#if OPENSSL_USE_IPV6 -static void test_addr_make_ipv6(void **state) -{ - struct sockaddr_in6 sa6; - BIO_ADDR ap; - struct in6_addr loopback = IN6ADDR_LOOPBACK_INIT; - - (void)state; - memset(&sa6, 0, sizeof(sa6)); - sa6.sin6_family = AF_INET6; - sa6.sin6_port = htons(443); - sa6.sin6_addr = loopback; - - assert_int_equal(BIO_ADDR_make(&ap, (const struct sockaddr *)&sa6), 1); - assert_int_equal(ap.s_in6.sin6_family, AF_INET6); - assert_int_equal(ap.s_in6.sin6_port, htons(443)); - assert_memory_equal(&ap.s_in6.sin6_addr, &loopback, sizeof(loopback)); -} -#endif - -#ifndef OPENSSL_NO_UNIX_SOCK -static void test_addr_make_unix(void **state) -{ - struct sockaddr_un sau; - BIO_ADDR ap; - - (void)state; - memset(&sau, 0, sizeof(sau)); - sau.sun_family = AF_UNIX; - strncpy(sau.sun_path, "/tmp/test.sock", sizeof(sau.sun_path) - 1); - - assert_int_equal(BIO_ADDR_make(&ap, (const struct sockaddr *)&sau), 1); - assert_int_equal(ap.s_un.sun_family, AF_UNIX); - assert_string_equal(ap.s_un.sun_path, "/tmp/test.sock"); -} -#endif - -static void test_addr_make_unknown_family(void **state) -{ - struct sockaddr sa; - BIO_ADDR ap; - - (void)state; - memset(&sa, 0, sizeof(sa)); - sa.sa_family = AF_UNSPEC; - assert_int_equal(BIO_ADDR_make(&ap, &sa), 0); -} - -/* BIO_ADDR_rawmake */ - -static void test_rawmake_ipv4(void **state) -{ - struct in_addr addr4; - BIO_ADDR ap; - - (void)state; - addr4.s_addr = htonl(INADDR_LOOPBACK); - assert_int_equal( - BIO_ADDR_rawmake(&ap, AF_INET, &addr4, sizeof(addr4), htons(80)), 1); - assert_int_equal(ap.s_in.sin_family, AF_INET); - assert_int_equal(ap.s_in.sin_port, htons(80)); - assert_int_equal(ap.s_in.sin_addr.s_addr, htonl(INADDR_LOOPBACK)); -} - -static void test_rawmake_ipv4_wrong_len(void **state) -{ - struct in_addr addr4; - BIO_ADDR ap; - - (void)state; - addr4.s_addr = htonl(INADDR_LOOPBACK); - assert_int_equal( - BIO_ADDR_rawmake(&ap, AF_INET, &addr4, sizeof(addr4) - 1, 0), 0); -} - -#if OPENSSL_USE_IPV6 -static void test_rawmake_ipv6(void **state) -{ - struct in6_addr addr6 = IN6ADDR_LOOPBACK_INIT; - BIO_ADDR ap; - - (void)state; - assert_int_equal( - BIO_ADDR_rawmake(&ap, AF_INET6, &addr6, sizeof(addr6), htons(443)), 1); - assert_int_equal(ap.s_in6.sin6_family, AF_INET6); - assert_int_equal(ap.s_in6.sin6_port, htons(443)); - assert_memory_equal(&ap.s_in6.sin6_addr, &addr6, sizeof(addr6)); -} -#endif - -#ifndef OPENSSL_NO_UNIX_SOCK -static void test_rawmake_unix(void **state) -{ - const char *path = "/tmp/test.sock"; - BIO_ADDR ap; - - (void)state; - assert_int_equal( - BIO_ADDR_rawmake(&ap, AF_UNIX, path, strlen(path), 0), 1); - assert_int_equal(ap.s_un.sun_family, AF_UNIX); - assert_string_equal(ap.s_un.sun_path, path); -} - -static void test_rawmake_unix_too_long(void **state) -{ - /* path longer than sun_path must be rejected */ - char path[sizeof(((struct sockaddr_un *)0)->sun_path) + 2]; - BIO_ADDR ap; - - (void)state; - memset(path, 'x', sizeof(path) - 1); - path[sizeof(path) - 1] = '\0'; - assert_int_equal( - BIO_ADDR_rawmake(&ap, AF_UNIX, path, strlen(path), 0), 0); -} -#endif - -static void test_rawmake_unknown_family(void **state) -{ - char data[4] = { 0 }; - BIO_ADDR ap; - - (void)state; - assert_int_equal(BIO_ADDR_rawmake(&ap, AF_UNSPEC, data, 0, 0), 0); -} - -/* BIO_ADDR_family */ - -static void test_addr_family(void **state) -{ - BIO_ADDR ap; - - (void)state; - memset(&ap, 0, sizeof(ap)); - ap.sa.sa_family = AF_UNSPEC; - assert_int_equal(BIO_ADDR_family(&ap), AF_UNSPEC); - ap.sa.sa_family = AF_INET; - assert_int_equal(BIO_ADDR_family(&ap), AF_INET); -} - -/* BIO_ADDR_rawport */ - -static void test_rawport_ipv4(void **state) -{ - BIO_ADDR ap; - struct in_addr addr4; - - (void)state; - addr4.s_addr = htonl(INADDR_LOOPBACK); - BIO_ADDR_rawmake(&ap, AF_INET, &addr4, sizeof(addr4), htons(443)); - assert_int_equal(BIO_ADDR_rawport(&ap), htons(443)); -} - -#if OPENSSL_USE_IPV6 -static void test_rawport_ipv6(void **state) -{ - BIO_ADDR ap; - struct in6_addr addr6 = IN6ADDR_LOOPBACK_INIT; - - (void)state; - BIO_ADDR_rawmake(&ap, AF_INET6, &addr6, sizeof(addr6), htons(8080)); - assert_int_equal(BIO_ADDR_rawport(&ap), htons(8080)); -} -#endif - -static void test_rawport_no_port(void **state) -{ - BIO_ADDR ap; - - (void)state; - memset(&ap, 0, sizeof(ap)); - ap.sa.sa_family = AF_UNSPEC; - assert_int_equal(BIO_ADDR_rawport(&ap), 0); -} - -/* BIO_ADDR_sockaddr and BIO_ADDR_sockaddr_noconst */ - -static void test_sockaddr_pointers(void **state) -{ - BIO_ADDR ap = { 0 }; - - (void)state; - memset(&ap, 0, sizeof(ap)); - assert_ptr_equal(BIO_ADDR_sockaddr(&ap), &ap.sa); - assert_ptr_equal(BIO_ADDR_sockaddr_noconst(&ap), &ap.sa); -} - -/* BIO_ADDR_sockaddr_size */ - -static void test_sockaddr_size_ipv4(void **state) -{ - BIO_ADDR ap; - - (void)state; - memset(&ap, 0, sizeof(ap)); - ap.sa.sa_family = AF_INET; - assert_int_equal(BIO_ADDR_sockaddr_size(&ap), sizeof(struct sockaddr_in)); -} - -#if OPENSSL_USE_IPV6 -static void test_sockaddr_size_ipv6(void **state) -{ - BIO_ADDR ap; - - (void)state; - memset(&ap, 0, sizeof(ap)); - ap.sa.sa_family = AF_INET6; - assert_int_equal(BIO_ADDR_sockaddr_size(&ap), sizeof(struct sockaddr_in6)); -} -#endif - -#ifndef OPENSSL_NO_UNIX_SOCK -static void test_sockaddr_size_unix(void **state) -{ - BIO_ADDR ap; - - (void)state; - memset(&ap, 0, sizeof(ap)); - ap.sa.sa_family = AF_UNIX; - assert_int_equal(BIO_ADDR_sockaddr_size(&ap), sizeof(struct sockaddr_un)); -} -#endif - -static void test_sockaddr_size_default(void **state) -{ - BIO_ADDR ap; - - (void)state; - memset(&ap, 0, sizeof(ap)); - ap.sa.sa_family = AF_UNSPEC; - assert_int_equal(BIO_ADDR_sockaddr_size(&ap), sizeof(BIO_ADDR)); -} - -/* BIO_ADDR_rawaddress */ - -static void test_rawaddress_unset(void **state) -{ - BIO_ADDR ap; - struct in_addr out; - size_t len; - - (void)state; - memset(&ap, 0, sizeof(ap)); - ap.sa.sa_family = AF_UNSPEC; - assert_int_equal(BIO_ADDR_rawaddress(&ap, &out, &len), 0); -} - -static void test_rawaddress_ipv4(void **state) -{ - BIO_ADDR ap; - struct in_addr expected, out; - size_t len = 0; - - (void)state; - expected.s_addr = htonl(INADDR_LOOPBACK); - BIO_ADDR_rawmake(&ap, AF_INET, &expected, sizeof(expected), htons(80)); - - assert_int_equal(BIO_ADDR_rawaddress(&ap, &out, &len), 1); - assert_int_equal(len, sizeof(struct in_addr)); - assert_memory_equal(&out, &expected, sizeof(expected)); -} - -static void test_rawaddress_ipv4_len_only(void **state) -{ - BIO_ADDR ap; - struct in_addr addr4; - size_t len = 0; - - (void)state; - addr4.s_addr = htonl(INADDR_LOOPBACK); - BIO_ADDR_rawmake(&ap, AF_INET, &addr4, sizeof(addr4), 0); - - assert_int_equal(BIO_ADDR_rawaddress(&ap, NULL, &len), 1); - assert_int_equal(len, sizeof(struct in_addr)); -} - -static void test_rawaddress_ipv4_ptr_only(void **state) -{ - BIO_ADDR ap; - struct in_addr expected, out; - - (void)state; - expected.s_addr = htonl(INADDR_LOOPBACK); - BIO_ADDR_rawmake(&ap, AF_INET, &expected, sizeof(expected), 0); - - assert_int_equal(BIO_ADDR_rawaddress(&ap, &out, NULL), 1); - assert_memory_equal(&out, &expected, sizeof(expected)); -} - -#ifndef OPENSSL_NO_UNIX_SOCK -static void test_rawaddress_unix(void **state) -{ - BIO_ADDR ap; - const char *path = "/tmp/unit.sock"; - char out[64]; - size_t len = 0; - - (void)state; - BIO_ADDR_rawmake(&ap, AF_UNIX, path, strlen(path), 0); - - assert_int_equal(BIO_ADDR_rawaddress(&ap, out, &len), 1); - assert_int_equal(len, strlen(path)); - assert_memory_equal(out, path, strlen(path)); -} -#endif - -/* BIO_ADDR_copy */ - -static void test_addr_copy_null(void **state) -{ - BIO_ADDR ap; - - (void)state; - memset(&ap, 0, sizeof(ap)); - assert_int_equal(BIO_ADDR_copy(NULL, NULL), 0); - assert_int_equal(BIO_ADDR_copy(NULL, &ap), 0); - assert_int_equal(BIO_ADDR_copy(&ap, NULL), 0); -} - -static void test_addr_copy_unspec(void **state) -{ - BIO_ADDR src, dst; - - (void)state; - memset(&src, 0, sizeof(src)); - src.sa.sa_family = AF_UNSPEC; - memset(&dst, 0xFF, sizeof(dst)); - - assert_int_equal(BIO_ADDR_copy(&dst, &src), 1); - assert_int_equal(dst.sa.sa_family, AF_UNSPEC); -} - -static void test_addr_copy_ipv4(void **state) -{ - BIO_ADDR src, dst; - struct in_addr addr4; - - (void)state; - addr4.s_addr = htonl(INADDR_LOOPBACK); - BIO_ADDR_rawmake(&src, AF_INET, &addr4, sizeof(addr4), htons(443)); - memset(&dst, 0, sizeof(dst)); - - assert_int_equal(BIO_ADDR_copy(&dst, &src), 1); - assert_int_equal(dst.s_in.sin_family, AF_INET); - assert_int_equal(dst.s_in.sin_port, htons(443)); - assert_int_equal(dst.s_in.sin_addr.s_addr, htonl(INADDR_LOOPBACK)); -} - -/* BIO_ADDR_new and BIO_ADDR_free */ - -static void test_addr_new_sets_unspec(void **state) -{ - BIO_ADDR *ap; - - (void)state; - ap = BIO_ADDR_new(); - assert_non_null(ap); - assert_int_equal(BIO_ADDR_family(ap), AF_UNSPEC); - BIO_ADDR_free(ap); -} - -/* BIO_ADDR_dup */ - -static void test_addr_dup_null(void **state) -{ - (void)state; - assert_null(BIO_ADDR_dup(NULL)); -} - -static void test_addr_dup_ipv4(void **state) -{ - BIO_ADDR src, *dup; - struct in_addr addr4; - - (void)state; - addr4.s_addr = htonl(INADDR_LOOPBACK); - BIO_ADDR_rawmake(&src, AF_INET, &addr4, sizeof(addr4), htons(8443)); - - dup = BIO_ADDR_dup(&src); - assert_non_null(dup); - assert_int_equal(dup->s_in.sin_family, AF_INET); - assert_int_equal(dup->s_in.sin_port, htons(8443)); - assert_int_equal(dup->s_in.sin_addr.s_addr, htonl(INADDR_LOOPBACK)); - BIO_ADDR_free(dup); -} - -/* BIO_ADDR_path_string */ - -#ifndef OPENSSL_NO_UNIX_SOCK -static void test_path_string_unix(void **state) -{ - BIO_ADDR ap; - char *path; - - (void)state; - BIO_ADDR_rawmake(&ap, AF_UNIX, "/run/unit.sock", 14, 0); - - path = BIO_ADDR_path_string(&ap); - assert_non_null(path); - assert_string_equal(path, "/run/unit.sock"); - OPENSSL_free(path); -} -#endif - -static void test_path_string_non_unix(void **state) -{ - BIO_ADDR ap; - struct in_addr addr4; - - (void)state; - addr4.s_addr = htonl(INADDR_LOOPBACK); - BIO_ADDR_rawmake(&ap, AF_INET, &addr4, sizeof(addr4), htons(80)); - assert_null(BIO_ADDR_path_string(&ap)); -} - -/* BIO_ADDRINFO accessors */ - -static void test_addrinfo_next_null(void **state) -{ - (void)state; - assert_null(BIO_ADDRINFO_next(NULL)); -} - -static void test_addrinfo_next(void **state) -{ - BIO_ADDRINFO a, b; - - (void)state; - memset(&a, 0, sizeof(a)); - memset(&b, 0, sizeof(b)); - a.bai_next = &b; - b.bai_next = NULL; - assert_ptr_equal(BIO_ADDRINFO_next(&a), &b); - assert_null(BIO_ADDRINFO_next(&b)); -} - -static void test_addrinfo_family(void **state) -{ - BIO_ADDRINFO bai; - - (void)state; - assert_int_equal(BIO_ADDRINFO_family(NULL), 0); - memset(&bai, 0, sizeof(bai)); - bai.bai_family = AF_INET; - assert_int_equal(BIO_ADDRINFO_family(&bai), AF_INET); -} - -static void test_addrinfo_socktype(void **state) -{ - BIO_ADDRINFO bai; - - (void)state; - assert_int_equal(BIO_ADDRINFO_socktype(NULL), 0); - memset(&bai, 0, sizeof(bai)); - bai.bai_socktype = SOCK_STREAM; - assert_int_equal(BIO_ADDRINFO_socktype(&bai), SOCK_STREAM); -} - -/* BIO_ADDRINFO_protocol */ - -static void test_addrinfo_protocol_null(void **state) -{ - (void)state; - assert_int_equal(BIO_ADDRINFO_protocol(NULL), 0); -} - -static void test_addrinfo_protocol_explicit(void **state) -{ - BIO_ADDRINFO bai; - - (void)state; - memset(&bai, 0, sizeof(bai)); - bai.bai_protocol = IPPROTO_SCTP; - assert_int_equal(BIO_ADDRINFO_protocol(&bai), IPPROTO_SCTP); -} - -static void test_addrinfo_protocol_stream(void **state) -{ - BIO_ADDRINFO bai; - - (void)state; - memset(&bai, 0, sizeof(bai)); - bai.bai_family = AF_INET; - bai.bai_socktype = SOCK_STREAM; - assert_int_equal(BIO_ADDRINFO_protocol(&bai), IPPROTO_TCP); -} - -static void test_addrinfo_protocol_dgram(void **state) -{ - BIO_ADDRINFO bai; - - (void)state; - memset(&bai, 0, sizeof(bai)); - bai.bai_family = AF_INET; - bai.bai_socktype = SOCK_DGRAM; - assert_int_equal(BIO_ADDRINFO_protocol(&bai), IPPROTO_UDP); -} - -#ifndef OPENSSL_NO_UNIX_SOCK -static void test_addrinfo_protocol_unix(void **state) -{ - BIO_ADDRINFO bai; - - (void)state; - memset(&bai, 0, sizeof(bai)); - bai.bai_family = AF_UNIX; - bai.bai_socktype = SOCK_STREAM; - /* AF_UNIX always returns 0, regardless of socktype */ - assert_int_equal(BIO_ADDRINFO_protocol(&bai), 0); -} -#endif - -static void test_addrinfo_sockaddr_size(void **state) -{ - BIO_ADDRINFO bai; - - (void)state; - assert_int_equal(BIO_ADDRINFO_sockaddr_size(NULL), 0); - memset(&bai, 0, sizeof(bai)); - bai.bai_addrlen = 28; - assert_int_equal(BIO_ADDRINFO_sockaddr_size(&bai), 28); -} - -static void test_addrinfo_sockaddr(void **state) -{ - BIO_ADDRINFO bai; - struct sockaddr sa; - - (void)state; - assert_null(BIO_ADDRINFO_sockaddr(NULL)); - memset(&bai, 0, sizeof(bai)); - bai.bai_addr = &sa; - assert_ptr_equal(BIO_ADDRINFO_sockaddr(&bai), &sa); -} - -static void test_addrinfo_address(void **state) -{ - BIO_ADDRINFO bai; - struct sockaddr sa; - - (void)state; - assert_null(BIO_ADDRINFO_address(NULL)); - memset(&bai, 0, sizeof(bai)); - bai.bai_addr = &sa; - assert_ptr_equal(BIO_ADDRINFO_address(&bai), (BIO_ADDR *)&sa); -} - -/* BIO_ADDRINFO_free */ - -static void test_addrinfo_free_null(void **state) -{ - (void)state; - BIO_ADDRINFO_free(NULL); /* must not crash */ -} - -#ifdef AI_PASSIVE -static void test_addrinfo_free_ip(void **state) -{ - /* AF_INET with AI_PASSIVE: freeaddrinfo is called, not manual free */ - struct addrinfo bai; - - (void)state; - memset(&bai, 0, sizeof(bai)); - bai.ai_family = AF_INET; - - expect_freeaddrinfo(&bai); - BIO_ADDRINFO_free(&bai); -} -#endif - -/* BIO_parse_hostserv */ - -static void test_parse_host_and_service(void **state) -{ - char *host = NULL, *service = NULL; - - (void)state; - assert_int_equal( - BIO_parse_hostserv("host.example:443", &host, &service, - BIO_PARSE_PRIO_HOST), - 1); - assert_string_equal(host, "host.example"); - assert_string_equal(service, "443"); - OPENSSL_free(host); - OPENSSL_free(service); -} - -static void test_parse_empty_host(void **state) -{ - char *host = NULL, *service = NULL; - - (void)state; - assert_int_equal( - BIO_parse_hostserv(":80", &host, &service, BIO_PARSE_PRIO_HOST), 1); - assert_null(host); - assert_string_equal(service, "80"); - OPENSSL_free(service); -} - -static void test_parse_star_host(void **state) -{ - char *host = NULL, *service = NULL; - - (void)state; - assert_int_equal( - BIO_parse_hostserv("*:80", &host, &service, BIO_PARSE_PRIO_HOST), 1); - assert_null(host); - assert_string_equal(service, "80"); - OPENSSL_free(service); -} - -static void test_parse_empty_service(void **state) -{ - char *host = NULL, *service = NULL; - - (void)state; - assert_int_equal( - BIO_parse_hostserv("host:", &host, &service, BIO_PARSE_PRIO_HOST), 1); - assert_string_equal(host, "host"); - assert_null(service); - OPENSSL_free(host); -} - -static void test_parse_star_service(void **state) -{ - char *host = NULL, *service = NULL; - - (void)state; - assert_int_equal( - BIO_parse_hostserv("host:*", &host, &service, BIO_PARSE_PRIO_HOST), 1); - assert_string_equal(host, "host"); - assert_null(service); - OPENSSL_free(host); -} - -static void test_parse_no_colon_host_prio(void **state) -{ - /* no colon + HOST prio: host set, service untouched */ - char *host = NULL, *service = NULL; - - (void)state; - assert_int_equal( - BIO_parse_hostserv("myhost", &host, &service, BIO_PARSE_PRIO_HOST), 1); - assert_string_equal(host, "myhost"); - assert_null(service); - OPENSSL_free(host); -} - -static void test_parse_no_colon_serv_prio(void **state) -{ - /* no colon + SERV prio: service set, host untouched */ - char *host = NULL, *service = NULL; - - (void)state; - assert_int_equal( - BIO_parse_hostserv("https", &host, &service, BIO_PARSE_PRIO_SERV), 1); - assert_null(host); - assert_string_equal(service, "https"); - OPENSSL_free(service); -} - -static void test_parse_bracket_host_and_service(void **state) -{ - char *host = NULL, *service = NULL; - - (void)state; - assert_int_equal( - BIO_parse_hostserv("[::1]:443", &host, &service, BIO_PARSE_PRIO_HOST), 1); - assert_string_equal(host, "::1"); - assert_string_equal(service, "443"); - OPENSSL_free(host); - OPENSSL_free(service); -} - -static void test_parse_bracket_no_service(void **state) -{ - /* "[host]" with no trailing colon: service left untouched */ - char *host = NULL, *service = NULL; - - (void)state; - assert_int_equal( - BIO_parse_hostserv("[::1]", &host, &service, BIO_PARSE_PRIO_HOST), 1); - assert_string_equal(host, "::1"); - assert_null(service); - OPENSSL_free(host); -} - -static void test_parse_bracket_unclosed(void **state) -{ - char *host = NULL, *service = NULL; - - (void)state; - assert_int_equal( - BIO_parse_hostserv("[::1", &host, &service, BIO_PARSE_PRIO_HOST), 0); -} - -static void test_parse_bracket_bad_suffix(void **state) -{ - /* ']' not followed by ':' or '\0' */ - char *host = NULL, *service = NULL; - - (void)state; - assert_int_equal( - BIO_parse_hostserv("[::1]X", &host, &service, BIO_PARSE_PRIO_HOST), 0); -} - -static void test_parse_bracket_service_with_colon(void **state) -{ - /* service part contains a colon */ - char *host = NULL, *service = NULL; - - (void)state; - assert_int_equal( - BIO_parse_hostserv("[host]:a:b", &host, &service, BIO_PARSE_PRIO_HOST), 0); -} - -static void test_parse_ambiguous(void **state) -{ - /* multiple colons without brackets */ - char *host = NULL, *service = NULL; - - (void)state; - assert_int_equal( - BIO_parse_hostserv("host:port:extra", &host, &service, - BIO_PARSE_PRIO_HOST), - 0); -} - -static void test_parse_null_host_param(void **state) -{ - /* host output param NULL */ - char *service = NULL; - - (void)state; - assert_int_equal( - BIO_parse_hostserv("host:443", NULL, &service, BIO_PARSE_PRIO_HOST), 1); - assert_string_equal(service, "443"); - OPENSSL_free(service); -} - -static void test_parse_null_service_param(void **state) -{ - /* service output param NULL */ - char *host = NULL; - - (void)state; - assert_int_equal( - BIO_parse_hostserv("host:443", &host, NULL, BIO_PARSE_PRIO_HOST), 1); - assert_string_equal(host, "host"); - OPENSSL_free(host); -} - -/* BIO_ADDR_hostname_string and BIO_ADDR_service_string (addr_strings) */ - -static void make_ipv4_addr(BIO_ADDR *ap, unsigned short port) -{ - struct in_addr addr4; - - addr4.s_addr = htonl(INADDR_LOOPBACK); - BIO_ADDR_rawmake(ap, AF_INET, &addr4, sizeof(addr4), htons(port)); -} - -static void test_hostname_string_sock_init_fail(void **state) -{ - BIO_ADDR ap; - - (void)state; - make_ipv4_addr(&ap, 80); - - expect_sock_init(0); - assert_null(BIO_ADDR_hostname_string(&ap, 1)); -} - -static void test_service_string_sock_init_fail(void **state) -{ - BIO_ADDR ap; - - (void)state; - make_ipv4_addr(&ap, 443); - - expect_sock_init(0); - assert_null(BIO_ADDR_service_string(&ap, 1)); -} - -#ifdef AI_PASSIVE -static void test_hostname_string_getnameinfo_fail(void **state) -{ - BIO_ADDR ap; - - (void)state; - make_ipv4_addr(&ap, 80); - - expect_sock_init(1); - expect_getnameinfo(BIO_ADDR_sockaddr(&ap), - BIO_ADDR_sockaddr_size(&ap), - NI_NUMERICHOST | NI_NUMERICSERV, - EAI_AGAIN, NULL, NULL); - assert_null(BIO_ADDR_hostname_string(&ap, 1)); -} - -static void test_hostname_string_numeric(void **state) -{ - BIO_ADDR ap; - char *result; - - (void)state; - make_ipv4_addr(&ap, 80); - - expect_sock_init(1); - expect_getnameinfo(BIO_ADDR_sockaddr(&ap), - BIO_ADDR_sockaddr_size(&ap), - NI_NUMERICHOST | NI_NUMERICSERV, - 0, "127.0.0.1", "80"); - result = BIO_ADDR_hostname_string(&ap, 1); - assert_non_null(result); - assert_string_equal(result, "127.0.0.1"); - OPENSSL_free(result); -} - -static void test_hostname_string_non_numeric(void **state) -{ - BIO_ADDR ap; - char *result; - - (void)state; - make_ipv4_addr(&ap, 80); - - expect_sock_init(1); - expect_getnameinfo(BIO_ADDR_sockaddr(&ap), - BIO_ADDR_sockaddr_size(&ap), - 0, /* flags = 0 for non-numeric lookup */ - 0, "localhost", "http"); - result = BIO_ADDR_hostname_string(&ap, 0); - assert_non_null(result); - assert_string_equal(result, "localhost"); - OPENSSL_free(result); -} - -static void test_service_string_numeric(void **state) -{ - BIO_ADDR ap; - char *result; - - (void)state; - make_ipv4_addr(&ap, 443); - - expect_sock_init(1); - expect_getnameinfo(BIO_ADDR_sockaddr(&ap), - BIO_ADDR_sockaddr_size(&ap), - NI_NUMERICHOST | NI_NUMERICSERV, - 0, "127.0.0.1", "443"); - result = BIO_ADDR_service_string(&ap, 1); - assert_non_null(result); - assert_string_equal(result, "443"); - OPENSSL_free(result); -} -#else - -/* inet_ntoa path: no getnameinfo, result is deterministic from the address */ -static void test_hostname_string_fallback(void **state) -{ - BIO_ADDR ap; - char *result; - - (void)state; - make_ipv4_addr(&ap, 80); - - expect_sock_init(1); - result = BIO_ADDR_hostname_string(&ap, 1); - assert_non_null(result); - assert_string_equal(result, "127.0.0.1"); - OPENSSL_free(result); -} - -static void test_service_string_fallback(void **state) -{ - BIO_ADDR ap; - char *result; - - (void)state; - make_ipv4_addr(&ap, 443); - - expect_sock_init(1); - result = BIO_ADDR_service_string(&ap, 1); - assert_non_null(result); - assert_string_equal(result, "443"); - OPENSSL_free(result); -} - -#endif /* AI_PASSIVE */ - -/* main */ - -#define ADDR_TEST(name) cmocka_unit_test(name) - -int main(void) -{ - const struct CMUnitTest tests[] = { - /* BIO_ADDR_clear */ - ADDR_TEST(test_addr_clear), - /* BIO_ADDR_make */ - ADDR_TEST(test_addr_make_ipv4), -#if OPENSSL_USE_IPV6 - ADDR_TEST(test_addr_make_ipv6), -#endif -#ifndef OPENSSL_NO_UNIX_SOCK - ADDR_TEST(test_addr_make_unix), -#endif - ADDR_TEST(test_addr_make_unknown_family), - /* BIO_ADDR_rawmake */ - ADDR_TEST(test_rawmake_ipv4), - ADDR_TEST(test_rawmake_ipv4_wrong_len), -#if OPENSSL_USE_IPV6 - ADDR_TEST(test_rawmake_ipv6), -#endif -#ifndef OPENSSL_NO_UNIX_SOCK - ADDR_TEST(test_rawmake_unix), - ADDR_TEST(test_rawmake_unix_too_long), -#endif - ADDR_TEST(test_rawmake_unknown_family), - /* BIO_ADDR_family */ - ADDR_TEST(test_addr_family), - /* BIO_ADDR_rawport */ - ADDR_TEST(test_rawport_ipv4), -#if OPENSSL_USE_IPV6 - ADDR_TEST(test_rawport_ipv6), -#endif - ADDR_TEST(test_rawport_no_port), - /* BIO_ADDR_sockaddr / BIO_ADDR_sockaddr_noconst */ - ADDR_TEST(test_sockaddr_pointers), - /* BIO_ADDR_sockaddr_size */ - ADDR_TEST(test_sockaddr_size_ipv4), -#if OPENSSL_USE_IPV6 - ADDR_TEST(test_sockaddr_size_ipv6), -#endif -#ifndef OPENSSL_NO_UNIX_SOCK - ADDR_TEST(test_sockaddr_size_unix), -#endif - ADDR_TEST(test_sockaddr_size_default), - /* BIO_ADDR_rawaddress */ - ADDR_TEST(test_rawaddress_unset), - ADDR_TEST(test_rawaddress_ipv4), - ADDR_TEST(test_rawaddress_ipv4_len_only), - ADDR_TEST(test_rawaddress_ipv4_ptr_only), -#ifndef OPENSSL_NO_UNIX_SOCK - ADDR_TEST(test_rawaddress_unix), -#endif - /* BIO_ADDR_copy */ - ADDR_TEST(test_addr_copy_null), - ADDR_TEST(test_addr_copy_unspec), - ADDR_TEST(test_addr_copy_ipv4), - /* BIO_ADDR_new and BIO_ADDR_free */ - ADDR_TEST(test_addr_new_sets_unspec), - /* BIO_ADDR_dup */ - ADDR_TEST(test_addr_dup_null), - ADDR_TEST(test_addr_dup_ipv4), - /* BIO_ADDR_path_string */ -#ifndef OPENSSL_NO_UNIX_SOCK - ADDR_TEST(test_path_string_unix), -#endif - ADDR_TEST(test_path_string_non_unix), - /* BIO_ADDRINFO accessors */ - ADDR_TEST(test_addrinfo_next_null), - ADDR_TEST(test_addrinfo_next), - ADDR_TEST(test_addrinfo_family), - ADDR_TEST(test_addrinfo_socktype), - ADDR_TEST(test_addrinfo_protocol_null), - ADDR_TEST(test_addrinfo_protocol_explicit), - ADDR_TEST(test_addrinfo_protocol_stream), - ADDR_TEST(test_addrinfo_protocol_dgram), -#ifndef OPENSSL_NO_UNIX_SOCK - ADDR_TEST(test_addrinfo_protocol_unix), -#endif - ADDR_TEST(test_addrinfo_sockaddr_size), - ADDR_TEST(test_addrinfo_sockaddr), - ADDR_TEST(test_addrinfo_address), - /* BIO_ADDRINFO_free */ - ADDR_TEST(test_addrinfo_free_null), -#ifdef AI_PASSIVE - ADDR_TEST(test_addrinfo_free_ip), -#endif - /* BIO_parse_hostserv */ - ADDR_TEST(test_parse_host_and_service), - ADDR_TEST(test_parse_empty_host), - ADDR_TEST(test_parse_star_host), - ADDR_TEST(test_parse_empty_service), - ADDR_TEST(test_parse_star_service), - ADDR_TEST(test_parse_no_colon_host_prio), - ADDR_TEST(test_parse_no_colon_serv_prio), - ADDR_TEST(test_parse_bracket_host_and_service), - ADDR_TEST(test_parse_bracket_no_service), - ADDR_TEST(test_parse_bracket_unclosed), - ADDR_TEST(test_parse_bracket_bad_suffix), - ADDR_TEST(test_parse_bracket_service_with_colon), - ADDR_TEST(test_parse_ambiguous), - ADDR_TEST(test_parse_null_host_param), - ADDR_TEST(test_parse_null_service_param), - /* BIO_ADDR_hostname_string / BIO_ADDR_service_string */ - ADDR_TEST(test_hostname_string_sock_init_fail), - ADDR_TEST(test_service_string_sock_init_fail), -#ifdef AI_PASSIVE - ADDR_TEST(test_hostname_string_getnameinfo_fail), - ADDR_TEST(test_hostname_string_numeric), - ADDR_TEST(test_hostname_string_non_numeric), - ADDR_TEST(test_service_string_numeric), -#else - ADDR_TEST(test_hostname_string_fallback), - ADDR_TEST(test_service_string_fallback), -#endif - }; - - cmocka_set_message_output(CM_OUTPUT_TAP); - - return cmocka_run_group_tests(tests, NULL, NULL); -} - -#endif /* OPENSSL_NO_SOCK */ diff --git a/test/unit/crypto/bio/test_bio_sock.c b/test/unit/crypto/bio/test_bio_sock.c deleted file mode 100644 index b41f9ed011..0000000000 --- a/test/unit/crypto/bio/test_bio_sock.c +++ /dev/null @@ -1,536 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include "internal/sockets.h" - -#ifndef OPENSSL_NO_SOCK - -#include -#include -#include -#include - -#include "bio_local.h" -#include - -#define FAKE_SOCKET 42 - -#if defined(TCP_NODELAY) && (defined(IPPROTO_TCP) || defined(SOL_TCP)) -#ifdef SOL_TCP -#define TEST_TCP_LEVEL SOL_TCP -#else -#define TEST_TCP_LEVEL IPPROTO_TCP -#endif -#endif - -/* prototypes for __wrap_* (required by -Wmissing-prototypes) */ -int __wrap_getsockopt(int fd, int level, int optname, void *optval, - socklen_t *optlen); -int __wrap_setsockopt(int fd, int level, int optname, const void *optval, - socklen_t optlen); -int __wrap_getsockname(int fd, struct sockaddr *addr, socklen_t *slen); -int __wrap_ioctl(int fd, unsigned long request, void *arg); -int __wrap_poll(struct pollfd *fds, nfds_t nfds, int timeout); -struct hostent *__wrap_gethostbyname(const char *name); -int __wrap_BIO_lookup(const char *host, const char *service, - enum BIO_lookup_type lookup_type, int family, int socktype, - BIO_ADDRINFO **res); -int __wrap_BIO_socket(int domain, int socktype, int protocol, int options); -int __wrap_BIO_listen(int sock, const BIO_ADDR *ba, int options); -int __wrap_BIO_closesocket(int sock); -void __wrap_BIO_ADDRINFO_free(BIO_ADDRINFO *bai); -int __wrap_BIO_accept_ex(int accept_sock, BIO_ADDR *addr, int options); -int __wrap_BIO_sock_should_retry(int i); -char *__wrap_BIO_ADDR_hostname_string(const BIO_ADDR *ap, int numeric); -char *__wrap_BIO_ADDR_service_string(const BIO_ADDR *ap, int numeric); - -/* wraps */ - -int __wrap_getsockopt(int fd, int level, int optname, void *optval, - socklen_t *optlen) -{ - int rc; - - function_called(); - check_expected(fd); - check_expected(level); - check_expected(optname); - (void)optlen; - rc = mock_type(int); - if (rc == 0) { - if (optval != NULL) - *(int *)optval = mock_type(int); - } else { - errno = mock_type(int); - } - return rc; -} - -int __wrap_setsockopt(int fd, int level, int optname, const void *optval, - socklen_t optlen) -{ - int on = (optval != NULL) ? *(const int *)optval : 0; - - function_called(); - check_expected(fd); - check_expected(level); - check_expected(optname); - check_expected(on); - (void)optlen; - return mock_type(int); -} - -int __wrap_getsockname(int fd, struct sockaddr *addr, socklen_t *slen) -{ - int rc; - - function_called(); - check_expected(fd); - (void)addr; - rc = mock_type(int); - if (rc == 0 && slen != NULL) - *slen = (socklen_t)mock_type(int); - return rc; -} - -int __wrap_ioctl(int fd, unsigned long request, void *arg) -{ - function_called(); - check_expected(fd); - check_expected(request); - (void)arg; - return mock_type(int); -} - -int __wrap_poll(struct pollfd *fds, nfds_t nfds, int timeout) -{ - int pfd = fds[0].fd; - int events = fds[0].events; - - function_called(); - check_expected(pfd); - check_expected(events); - (void)nfds; - (void)timeout; - return mock_type(int); -} - -struct hostent *__wrap_gethostbyname(const char *name) -{ - function_called(); - check_expected_ptr(name); - return mock_ptr_type(struct hostent *); -} - -int __wrap_BIO_lookup(const char *host, const char *service, - enum BIO_lookup_type lookup_type, int family, int socktype, - BIO_ADDRINFO **res) -{ - int rc; - - function_called(); - check_expected(family); - check_expected(socktype); - check_expected(lookup_type); - (void)host; - (void)service; - rc = mock_type(int); - if (rc == 1) { - BIO_ADDRINFO *r = mock_ptr_type(BIO_ADDRINFO *); - - if (res != NULL) - *res = r; - } - return rc; -} - -int __wrap_BIO_socket(int domain, int socktype, int protocol, int options) -{ - function_called(); - check_expected(domain); - check_expected(socktype); - check_expected(protocol); - (void)options; - return mock_type(int); -} - -int __wrap_BIO_listen(int sock, const BIO_ADDR *ba, int options) -{ - function_called(); - check_expected(sock); - check_expected(options); - (void)ba; - return mock_type(int); -} - -int __wrap_BIO_closesocket(int sock) -{ - function_called(); - check_expected(sock); - return mock_type(int); -} - -/* the fake addrinfo handed back by BIO_lookup is static; nothing to release */ -void __wrap_BIO_ADDRINFO_free(BIO_ADDRINFO *bai) -{ - (void)bai; -} - -int __wrap_BIO_accept_ex(int accept_sock, BIO_ADDR *addr, int options) -{ - function_called(); - check_expected(accept_sock); - check_expected(options); - (void)addr; - return mock_type(int); -} - -int __wrap_BIO_sock_should_retry(int i) -{ - function_called(); - check_expected(i); - return mock_type(int); -} - -char *__wrap_BIO_ADDR_hostname_string(const BIO_ADDR *ap, int numeric) -{ - function_called(); - check_expected(numeric); - (void)ap; - return mock_ptr_type(char *); -} - -char *__wrap_BIO_ADDR_service_string(const BIO_ADDR *ap, int numeric) -{ - function_called(); - check_expected(numeric); - (void)ap; - return mock_ptr_type(char *); -} - -/* expectations */ - -static void expect_getsockopt(int fd, int rc, int value) -{ - expect_function_call(__wrap_getsockopt); - expect_value(__wrap_getsockopt, fd, fd); - expect_value(__wrap_getsockopt, level, SOL_SOCKET); - expect_value(__wrap_getsockopt, optname, SO_ERROR); - will_return(__wrap_getsockopt, rc); - will_return(__wrap_getsockopt, value); -} - -#if defined(TCP_NODELAY) && (defined(IPPROTO_TCP) || defined(SOL_TCP)) -static void expect_setsockopt(int fd, int on, int rc) -{ - expect_function_call(__wrap_setsockopt); - expect_value(__wrap_setsockopt, fd, fd); - expect_value(__wrap_setsockopt, level, TEST_TCP_LEVEL); - expect_value(__wrap_setsockopt, optname, TCP_NODELAY); - expect_value(__wrap_setsockopt, on, on); - will_return(__wrap_setsockopt, rc); -} -#endif - -static void expect_getsockname(int fd, int rc, socklen_t outlen) -{ - expect_function_call(__wrap_getsockname); - expect_value(__wrap_getsockname, fd, fd); - will_return(__wrap_getsockname, rc); - if (rc == 0) - will_return(__wrap_getsockname, (int)outlen); -} - -#ifdef FIONBIO -static void expect_ioctl(int fd, unsigned long request, int rc) -{ - expect_function_call(__wrap_ioctl); - expect_value(__wrap_ioctl, fd, fd); - expect_value(__wrap_ioctl, request, request); - will_return(__wrap_ioctl, rc); -} -#endif - -static void expect_poll(int fd, int events, int rc) -{ - expect_function_call(__wrap_poll); - expect_value(__wrap_poll, pfd, fd); - expect_value(__wrap_poll, events, events); - will_return(__wrap_poll, rc); -} - -/* setup */ - -/* BIO_sock_init / bio_sock_cleanup_int */ - -static void test_sock_init(void **state) -{ - (void)state; - assert_int_equal(BIO_sock_init(), 1); -} - -static void test_sock_cleanup(void **state) -{ - (void)state; - /* no-op on non-Windows; exercised for coverage */ - bio_sock_cleanup_int(); -} - -/* BIO_sock_error */ - -static void test_sock_error_value(void **state) -{ - /* getsockopt succeeds: SO_ERROR value is returned verbatim */ - (void)state; - expect_getsockopt(FAKE_SOCKET, 0, ECONNREFUSED); - assert_int_equal(BIO_sock_error(FAKE_SOCKET), ECONNREFUSED); -} - -static void test_sock_error_getsockopt_fails(void **state) -{ - /* getsockopt fails: the last socket error (errno) is returned */ - (void)state; - expect_getsockopt(FAKE_SOCKET, -1, EBADF); - assert_int_equal(BIO_sock_error(FAKE_SOCKET), EBADF); -} - -/* BIO_socket_ioctl */ - -#ifdef FIONBIO -static void test_socket_ioctl_success(void **state) -{ - int arg = 1; - - (void)state; - expect_ioctl(FAKE_SOCKET, FIONBIO, 0); - assert_int_equal(BIO_socket_ioctl(FAKE_SOCKET, FIONBIO, &arg), 0); -} - -static void test_socket_ioctl_error(void **state) -{ - int arg = 1; - - (void)state; - expect_ioctl(FAKE_SOCKET, FIONBIO, -1); - assert_int_equal(BIO_socket_ioctl(FAKE_SOCKET, FIONBIO, &arg), -1); -} -#endif - -/* BIO_set_tcp_ndelay */ - -#if defined(TCP_NODELAY) && (defined(IPPROTO_TCP) || defined(SOL_TCP)) -static void test_set_tcp_ndelay_on(void **state) -{ - (void)state; - expect_setsockopt(FAKE_SOCKET, 1, 0); - assert_int_equal(BIO_set_tcp_ndelay(FAKE_SOCKET, 1), 1); -} - -static void test_set_tcp_ndelay_off(void **state) -{ - (void)state; - expect_setsockopt(FAKE_SOCKET, 0, 0); - assert_int_equal(BIO_set_tcp_ndelay(FAKE_SOCKET, 0), 1); -} - -static void test_set_tcp_ndelay_fails(void **state) -{ - (void)state; - expect_setsockopt(FAKE_SOCKET, 1, -1); - assert_int_equal(BIO_set_tcp_ndelay(FAKE_SOCKET, 1), 0); -} -#endif - -/* BIO_socket_nbio */ - -#ifdef FIONBIO -static void test_socket_nbio_enable(void **state) -{ - (void)state; - expect_ioctl(FAKE_SOCKET, FIONBIO, 0); - assert_int_equal(BIO_socket_nbio(FAKE_SOCKET, 1), 1); -} - -static void test_socket_nbio_disable(void **state) -{ - (void)state; - expect_ioctl(FAKE_SOCKET, FIONBIO, 0); - assert_int_equal(BIO_socket_nbio(FAKE_SOCKET, 0), 1); -} - -static void test_socket_nbio_fails(void **state) -{ - (void)state; - expect_ioctl(FAKE_SOCKET, FIONBIO, -1); - assert_int_equal(BIO_socket_nbio(FAKE_SOCKET, 1), 0); -} -#endif - -/* BIO_sock_info */ - -static void test_sock_info_success(void **state) -{ - union BIO_sock_info_u info; - BIO_ADDR addr; - - (void)state; - memset(&addr, 0, sizeof(addr)); - info.addr = &addr; - expect_getsockname(FAKE_SOCKET, 0, (socklen_t)sizeof(struct sockaddr_in)); - assert_int_equal( - BIO_sock_info(FAKE_SOCKET, BIO_SOCK_INFO_ADDRESS, &info), 1); -} - -static void test_sock_info_getsockname_fails(void **state) -{ - union BIO_sock_info_u info; - BIO_ADDR addr; - - (void)state; - memset(&addr, 0, sizeof(addr)); - info.addr = &addr; - expect_getsockname(FAKE_SOCKET, -1, 0); - assert_int_equal( - BIO_sock_info(FAKE_SOCKET, BIO_SOCK_INFO_ADDRESS, &info), 0); -} - -static void test_sock_info_truncated(void **state) -{ - /* getsockname reports an address larger than the BIO_ADDR storage */ - union BIO_sock_info_u info; - BIO_ADDR addr; - - (void)state; - memset(&addr, 0, sizeof(addr)); - info.addr = &addr; - expect_getsockname(FAKE_SOCKET, 0, (socklen_t)(sizeof(BIO_ADDR) + 1)); - assert_int_equal( - BIO_sock_info(FAKE_SOCKET, BIO_SOCK_INFO_ADDRESS, &info), 0); -} - -static void test_sock_info_unknown_type(void **state) -{ - union BIO_sock_info_u info; - BIO_ADDR addr; - - (void)state; - memset(&addr, 0, sizeof(addr)); - info.addr = &addr; - assert_int_equal( - BIO_sock_info(FAKE_SOCKET, (enum BIO_sock_info_type)999, &info), 0); -} - -/* BIO_socket_wait */ - -static void test_socket_wait_immediate(void **state) -{ - /* max_time == 0 returns immediately without polling */ - (void)state; - assert_int_equal(BIO_socket_wait(FAKE_SOCKET, 1, 0), 1); -} - -static void test_socket_wait_bad_fd(void **state) -{ - (void)state; - assert_int_equal(BIO_socket_wait(-1, 1, time(NULL) + 100), -1); -} - -static void test_socket_wait_past(void **state) -{ - /* deadline already elapsed: timeout without polling */ - (void)state; - assert_int_equal(BIO_socket_wait(FAKE_SOCKET, 1, (time_t)1), 0); -} - -static void test_socket_wait_read_ready(void **state) -{ - (void)state; - expect_poll(FAKE_SOCKET, POLLIN, 1); - assert_int_equal(BIO_socket_wait(FAKE_SOCKET, 1, time(NULL) + 100), 1); -} - -static void test_socket_wait_write_ready(void **state) -{ - (void)state; - expect_poll(FAKE_SOCKET, POLLOUT, 1); - assert_int_equal(BIO_socket_wait(FAKE_SOCKET, 0, time(NULL) + 100), 1); -} - -static void test_socket_wait_timeout(void **state) -{ - (void)state; - expect_poll(FAKE_SOCKET, POLLIN, 0); - assert_int_equal(BIO_socket_wait(FAKE_SOCKET, 1, time(NULL) + 100), 0); -} - -static void test_socket_wait_error(void **state) -{ - (void)state; - expect_poll(FAKE_SOCKET, POLLIN, -1); - assert_int_equal(BIO_socket_wait(FAKE_SOCKET, 1, time(NULL) + 100), -1); -} - -/* main */ - -#define SOCK_TEST(name) cmocka_unit_test(name) - -int main(void) -{ - const struct CMUnitTest tests[] = { - /* BIO_sock_init / cleanup */ - SOCK_TEST(test_sock_init), - SOCK_TEST(test_sock_cleanup), - /* BIO_sock_error */ - SOCK_TEST(test_sock_error_value), - SOCK_TEST(test_sock_error_getsockopt_fails), -#ifdef FIONBIO - /* BIO_socket_ioctl */ - SOCK_TEST(test_socket_ioctl_success), - SOCK_TEST(test_socket_ioctl_error), -#endif - /* BIO_set_tcp_ndelay */ -#if defined(TCP_NODELAY) && (defined(IPPROTO_TCP) || defined(SOL_TCP)) - SOCK_TEST(test_set_tcp_ndelay_on), - SOCK_TEST(test_set_tcp_ndelay_off), - SOCK_TEST(test_set_tcp_ndelay_fails), -#endif - /* BIO_socket_nbio */ -#ifdef FIONBIO - SOCK_TEST(test_socket_nbio_enable), - SOCK_TEST(test_socket_nbio_disable), - SOCK_TEST(test_socket_nbio_fails), -#endif - /* BIO_sock_info */ - SOCK_TEST(test_sock_info_success), - SOCK_TEST(test_sock_info_getsockname_fails), - SOCK_TEST(test_sock_info_truncated), - SOCK_TEST(test_sock_info_unknown_type), - /* BIO_socket_wait */ - SOCK_TEST(test_socket_wait_immediate), - SOCK_TEST(test_socket_wait_bad_fd), - SOCK_TEST(test_socket_wait_past), - SOCK_TEST(test_socket_wait_read_ready), - SOCK_TEST(test_socket_wait_write_ready), - SOCK_TEST(test_socket_wait_timeout), - SOCK_TEST(test_socket_wait_error), - }; - - cmocka_set_message_output(CM_OUTPUT_TAP); - - return cmocka_run_group_tests(tests, NULL, NULL); -} - -#else - -int main(void) -{ - return 0; -} - -#endif /* OPENSSL_NO_SOCK */ diff --git a/test/unit/crypto/bio/test_bio_sock2.c b/test/unit/crypto/bio/test_bio_sock2.c deleted file mode 100644 index 96f63e59cf..0000000000 --- a/test/unit/crypto/bio/test_bio_sock2.c +++ /dev/null @@ -1,786 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include "internal/sockets.h" - -#ifndef OPENSSL_NO_SOCK - -#include -#include -#include -#include - -#include "bio_local.h" -#include "internal/bio_tfo.h" -#include - -#define FAKE_SOCKET 42 -#define ACCEPTED_SOCKET 7 - -/* prototypes for __wrap_* (required by -Wmissing-prototypes) */ -int __wrap_socket(int domain, int type, int protocol); -int __wrap_connect(int fd, const struct sockaddr *addr, socklen_t addrlen); -int __wrap_bind(int fd, const struct sockaddr *addr, socklen_t addrlen); -int __wrap_listen(int fd, int backlog); -int __wrap_accept(int fd, struct sockaddr *addr, socklen_t *addrlen); -int __wrap_close(int fd); -int __wrap_getsockopt(int fd, int level, int optname, void *optval, - socklen_t *optlen); -int __wrap_setsockopt(int fd, int level, int optname, const void *optval, - socklen_t optlen); -int __wrap_BIO_socket_nbio(int fd, int mode); -int __wrap_BIO_sock_should_retry(int i); - -/* wraps */ - -int __wrap_socket(int domain, int type, int protocol) -{ - function_called(); - check_expected(domain); - check_expected(type); - check_expected(protocol); - return mock_type(int); -} - -int __wrap_connect(int fd, const struct sockaddr *addr, socklen_t addrlen) -{ - function_called(); - check_expected(fd); - (void)addr; - (void)addrlen; - return mock_type(int); -} - -int __wrap_bind(int fd, const struct sockaddr *addr, socklen_t addrlen) -{ - function_called(); - check_expected(fd); - (void)addr; - (void)addrlen; - return mock_type(int); -} - -int __wrap_listen(int fd, int backlog) -{ - function_called(); - check_expected(fd); - (void)backlog; - return mock_type(int); -} - -int __wrap_accept(int fd, struct sockaddr *addr, socklen_t *addrlen) -{ - function_called(); - check_expected(fd); - (void)addr; - (void)addrlen; - return mock_type(int); -} - -int __wrap_close(int fd) -{ - function_called(); - check_expected(fd); - return mock_type(int); -} - -int __wrap_getsockopt(int fd, int level, int optname, void *optval, - socklen_t *optlen) -{ - int rc; - - function_called(); - check_expected(fd); - check_expected(level); - check_expected(optname); - rc = mock_type(int); - if (rc == 0) { - if (optval != NULL) - *(int *)optval = mock_type(int); - if (optlen != NULL) - *optlen = (socklen_t)mock_type(int); - } - return rc; -} - -int __wrap_setsockopt(int fd, int level, int optname, const void *optval, - socklen_t optlen) -{ - int on = (optval != NULL) ? *(const int *)optval : 0; - - function_called(); - check_expected(fd); - check_expected(level); - check_expected(optname); - check_expected(on); - (void)optlen; - return mock_type(int); -} - -int __wrap_BIO_socket_nbio(int fd, int mode) -{ - function_called(); - check_expected(fd); - check_expected(mode); - return mock_type(int); -} - -int __wrap_BIO_sock_should_retry(int i) -{ - function_called(); - check_expected(i); - return mock_type(int); -} - -/* expectations */ - -static void expect_socket(int domain, int type, int protocol, int rc) -{ - expect_function_call(__wrap_socket); - expect_value(__wrap_socket, domain, domain); - expect_value(__wrap_socket, type, type); - expect_value(__wrap_socket, protocol, protocol); - will_return(__wrap_socket, rc); -} - -static void expect_connect(int fd, int rc) -{ - expect_function_call(__wrap_connect); - expect_value(__wrap_connect, fd, fd); - will_return(__wrap_connect, rc); -} - -static void expect_bind(int fd, int rc) -{ - expect_function_call(__wrap_bind); - expect_value(__wrap_bind, fd, fd); - will_return(__wrap_bind, rc); -} - -static void expect_listen(int fd, int rc) -{ - expect_function_call(__wrap_listen); - expect_value(__wrap_listen, fd, fd); - will_return(__wrap_listen, rc); -} - -static void expect_accept(int fd, int rc) -{ - expect_function_call(__wrap_accept); - expect_value(__wrap_accept, fd, fd); - will_return(__wrap_accept, rc); -} - -static void expect_close(int fd, int rc) -{ - expect_function_call(__wrap_close); - expect_value(__wrap_close, fd, fd); - will_return(__wrap_close, rc); -} - -static void expect_getsockopt(int fd, int level, int optname, int rc, - int value, socklen_t outlen) -{ - expect_function_call(__wrap_getsockopt); - expect_value(__wrap_getsockopt, fd, fd); - expect_value(__wrap_getsockopt, level, level); - expect_value(__wrap_getsockopt, optname, optname); - will_return(__wrap_getsockopt, rc); - if (rc == 0) { - will_return(__wrap_getsockopt, value); - will_return(__wrap_getsockopt, (int)outlen); - } -} - -static void expect_setsockopt(int fd, int level, int optname, int on, int rc) -{ - expect_function_call(__wrap_setsockopt); - expect_value(__wrap_setsockopt, fd, fd); - expect_value(__wrap_setsockopt, level, level); - expect_value(__wrap_setsockopt, optname, optname); - expect_value(__wrap_setsockopt, on, on); - will_return(__wrap_setsockopt, rc); -} - -static void expect_nbio(int fd, int mode, int rc) -{ - expect_function_call(__wrap_BIO_socket_nbio); - expect_value(__wrap_BIO_socket_nbio, fd, fd); - expect_value(__wrap_BIO_socket_nbio, mode, mode); - will_return(__wrap_BIO_socket_nbio, rc); -} - -static void expect_should_retry(int i, int rc) -{ - expect_function_call(__wrap_BIO_sock_should_retry); - expect_value(__wrap_BIO_sock_should_retry, i, i); - will_return(__wrap_BIO_sock_should_retry, rc); -} - -/* helpers */ - -static void make_addr(BIO_ADDR *a, int family) -{ - memset(a, 0, sizeof(*a)); - a->sa.sa_family = family; -} - -/* BIO_socket */ - -static void test_socket_success(void **state) -{ - (void)state; - expect_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, FAKE_SOCKET); - assert_int_equal( - BIO_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0), FAKE_SOCKET); -} - -static void test_socket_fails(void **state) -{ - (void)state; - expect_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, -1); - assert_int_equal( - BIO_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0), (int)INVALID_SOCKET); -} - -/* BIO_connect */ - -static void test_connect_invalid_sock(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - assert_int_equal(BIO_connect(-1, &a, 0), 0); -} - -static void test_connect_nbio_fails(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_nbio(FAKE_SOCKET, 0, 0); - assert_int_equal(BIO_connect(FAKE_SOCKET, &a, 0), 0); -} - -static void test_connect_success(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_connect(FAKE_SOCKET, 0); - assert_int_equal(BIO_connect(FAKE_SOCKET, &a, 0), 1); -} - -static void test_connect_nonblock(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_nbio(FAKE_SOCKET, 1, 1); - expect_connect(FAKE_SOCKET, 0); - assert_int_equal(BIO_connect(FAKE_SOCKET, &a, BIO_SOCK_NONBLOCK), 1); -} - -static void test_connect_keepalive(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_setsockopt(FAKE_SOCKET, SOL_SOCKET, SO_KEEPALIVE, 1, 0); - expect_connect(FAKE_SOCKET, 0); - assert_int_equal(BIO_connect(FAKE_SOCKET, &a, BIO_SOCK_KEEPALIVE), 1); -} - -static void test_connect_keepalive_fails(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_setsockopt(FAKE_SOCKET, SOL_SOCKET, SO_KEEPALIVE, 1, -1); - assert_int_equal(BIO_connect(FAKE_SOCKET, &a, BIO_SOCK_KEEPALIVE), 0); -} - -static void test_connect_nodelay(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_setsockopt(FAKE_SOCKET, IPPROTO_TCP, TCP_NODELAY, 1, 0); - expect_connect(FAKE_SOCKET, 0); - assert_int_equal(BIO_connect(FAKE_SOCKET, &a, BIO_SOCK_NODELAY), 1); -} - -static void test_connect_nodelay_fails(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_setsockopt(FAKE_SOCKET, IPPROTO_TCP, TCP_NODELAY, 1, -1); - assert_int_equal(BIO_connect(FAKE_SOCKET, &a, BIO_SOCK_NODELAY), 0); -} - -static void test_connect_fails_retry(void **state) -{ - /* connect() failing retryably returns 0 without raising a fatal error */ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_connect(FAKE_SOCKET, -1); - expect_should_retry(-1, 1); - assert_int_equal(BIO_connect(FAKE_SOCKET, &a, 0), 0); -} - -static void test_connect_fails_error(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_connect(FAKE_SOCKET, -1); - expect_should_retry(-1, 0); - assert_int_equal(BIO_connect(FAKE_SOCKET, &a, 0), 0); -} - -/* BIO_bind */ - -static void test_bind_invalid_sock(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - assert_int_equal(BIO_bind(-1, &a, 0), 0); -} - -static void test_bind_success(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_bind(FAKE_SOCKET, 0); - assert_int_equal(BIO_bind(FAKE_SOCKET, &a, 0), 1); -} - -static void test_bind_reuseaddr(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_setsockopt(FAKE_SOCKET, SOL_SOCKET, SO_REUSEADDR, 1, 0); - expect_bind(FAKE_SOCKET, 0); - assert_int_equal(BIO_bind(FAKE_SOCKET, &a, BIO_SOCK_REUSEADDR), 1); -} - -static void test_bind_reuseaddr_fails(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_setsockopt(FAKE_SOCKET, SOL_SOCKET, SO_REUSEADDR, 1, -1); - assert_int_equal(BIO_bind(FAKE_SOCKET, &a, BIO_SOCK_REUSEADDR), 0); -} - -static void test_bind_bind_fails(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_bind(FAKE_SOCKET, -1); - assert_int_equal(BIO_bind(FAKE_SOCKET, &a, 0), 0); -} - -/* BIO_listen */ - -static void test_listen_success(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_getsockopt(FAKE_SOCKET, SOL_SOCKET, SO_TYPE, 0, SOCK_STREAM, - sizeof(int)); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_bind(FAKE_SOCKET, 0); - expect_listen(FAKE_SOCKET, 0); - assert_int_equal(BIO_listen(FAKE_SOCKET, &a, 0), 1); -} - -static void test_listen_invalid_sock(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - assert_int_equal(BIO_listen(-1, &a, 0), 0); -} - -static void test_listen_getsockopt_fails(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_getsockopt(FAKE_SOCKET, SOL_SOCKET, SO_TYPE, -1, 0, 0); - assert_int_equal(BIO_listen(FAKE_SOCKET, &a, 0), 0); -} - -static void test_listen_socktype_len_mismatch(void **state) -{ - /* a short socktype_len is rejected even when getsockopt succeeds */ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_getsockopt(FAKE_SOCKET, SOL_SOCKET, SO_TYPE, 0, SOCK_STREAM, - (socklen_t)(sizeof(int) - 1)); - assert_int_equal(BIO_listen(FAKE_SOCKET, &a, 0), 0); -} - -static void test_listen_nbio_fails(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_getsockopt(FAKE_SOCKET, SOL_SOCKET, SO_TYPE, 0, SOCK_STREAM, - sizeof(int)); - expect_nbio(FAKE_SOCKET, 0, 0); - assert_int_equal(BIO_listen(FAKE_SOCKET, &a, 0), 0); -} - -static void test_listen_keepalive(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_getsockopt(FAKE_SOCKET, SOL_SOCKET, SO_TYPE, 0, SOCK_STREAM, - sizeof(int)); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_setsockopt(FAKE_SOCKET, SOL_SOCKET, SO_KEEPALIVE, 1, 0); - expect_bind(FAKE_SOCKET, 0); - expect_listen(FAKE_SOCKET, 0); - assert_int_equal(BIO_listen(FAKE_SOCKET, &a, BIO_SOCK_KEEPALIVE), 1); -} - -static void test_listen_keepalive_fails(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_getsockopt(FAKE_SOCKET, SOL_SOCKET, SO_TYPE, 0, SOCK_STREAM, - sizeof(int)); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_setsockopt(FAKE_SOCKET, SOL_SOCKET, SO_KEEPALIVE, 1, -1); - assert_int_equal(BIO_listen(FAKE_SOCKET, &a, BIO_SOCK_KEEPALIVE), 0); -} - -static void test_listen_nodelay(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_getsockopt(FAKE_SOCKET, SOL_SOCKET, SO_TYPE, 0, SOCK_STREAM, - sizeof(int)); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_setsockopt(FAKE_SOCKET, IPPROTO_TCP, TCP_NODELAY, 1, 0); - expect_bind(FAKE_SOCKET, 0); - expect_listen(FAKE_SOCKET, 0); - assert_int_equal(BIO_listen(FAKE_SOCKET, &a, BIO_SOCK_NODELAY), 1); -} - -static void test_listen_reuseaddr(void **state) -{ - /* REUSEADDR is honoured inside the real (unwrappable) BIO_bind */ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_getsockopt(FAKE_SOCKET, SOL_SOCKET, SO_TYPE, 0, SOCK_STREAM, - sizeof(int)); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_setsockopt(FAKE_SOCKET, SOL_SOCKET, SO_REUSEADDR, 1, 0); - expect_bind(FAKE_SOCKET, 0); - expect_listen(FAKE_SOCKET, 0); - assert_int_equal(BIO_listen(FAKE_SOCKET, &a, BIO_SOCK_REUSEADDR), 1); -} - -static void test_listen_bind_fails(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_getsockopt(FAKE_SOCKET, SOL_SOCKET, SO_TYPE, 0, SOCK_STREAM, - sizeof(int)); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_bind(FAKE_SOCKET, -1); - assert_int_equal(BIO_listen(FAKE_SOCKET, &a, 0), 0); -} - -static void test_listen_dgram(void **state) -{ - /* datagram sockets are bound but never put into listen() */ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_getsockopt(FAKE_SOCKET, SOL_SOCKET, SO_TYPE, 0, SOCK_DGRAM, - sizeof(int)); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_bind(FAKE_SOCKET, 0); - assert_int_equal(BIO_listen(FAKE_SOCKET, &a, 0), 1); -} - -static void test_listen_listen_fails(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET); - expect_getsockopt(FAKE_SOCKET, SOL_SOCKET, SO_TYPE, 0, SOCK_STREAM, - sizeof(int)); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_bind(FAKE_SOCKET, 0); - expect_listen(FAKE_SOCKET, -1); - assert_int_equal(BIO_listen(FAKE_SOCKET, &a, 0), 0); -} - -#if defined(IPV6_V6ONLY) && !defined(__OpenBSD__) -static void test_listen_v6only(void **state) -{ - /* an AF_INET6 socket always gets IPV6_V6ONLY set, here to 1 */ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET6); - expect_getsockopt(FAKE_SOCKET, SOL_SOCKET, SO_TYPE, 0, SOCK_STREAM, - sizeof(int)); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_setsockopt(FAKE_SOCKET, IPPROTO_IPV6, IPV6_V6ONLY, 1, 0); - expect_bind(FAKE_SOCKET, 0); - expect_listen(FAKE_SOCKET, 0); - assert_int_equal(BIO_listen(FAKE_SOCKET, &a, BIO_SOCK_V6_ONLY), 1); -} - -static void test_listen_v6only_off(void **state) -{ - /* without BIO_SOCK_V6_ONLY the option is still set, to 0 */ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET6); - expect_getsockopt(FAKE_SOCKET, SOL_SOCKET, SO_TYPE, 0, SOCK_STREAM, - sizeof(int)); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_setsockopt(FAKE_SOCKET, IPPROTO_IPV6, IPV6_V6ONLY, 0, 0); - expect_bind(FAKE_SOCKET, 0); - expect_listen(FAKE_SOCKET, 0); - assert_int_equal(BIO_listen(FAKE_SOCKET, &a, 0), 1); -} - -static void test_listen_v6only_fails(void **state) -{ - BIO_ADDR a; - - (void)state; - make_addr(&a, AF_INET6); - expect_getsockopt(FAKE_SOCKET, SOL_SOCKET, SO_TYPE, 0, SOCK_STREAM, - sizeof(int)); - expect_nbio(FAKE_SOCKET, 0, 1); - expect_setsockopt(FAKE_SOCKET, IPPROTO_IPV6, IPV6_V6ONLY, 1, -1); - assert_int_equal(BIO_listen(FAKE_SOCKET, &a, BIO_SOCK_V6_ONLY), 0); -} -#endif - -/* BIO_accept_ex */ - -static void test_accept_ex_success(void **state) -{ - BIO_ADDR a; - - (void)state; - memset(&a, 0, sizeof(a)); - expect_accept(FAKE_SOCKET, ACCEPTED_SOCKET); - expect_nbio(ACCEPTED_SOCKET, 0, 1); - assert_int_equal(BIO_accept_ex(FAKE_SOCKET, &a, 0), ACCEPTED_SOCKET); -} - -static void test_accept_ex_null_addr(void **state) -{ - /* a NULL addr is accepted into an internal local BIO_ADDR */ - (void)state; - expect_accept(FAKE_SOCKET, ACCEPTED_SOCKET); - expect_nbio(ACCEPTED_SOCKET, 0, 1); - assert_int_equal(BIO_accept_ex(FAKE_SOCKET, NULL, 0), ACCEPTED_SOCKET); -} - -static void test_accept_ex_nonblock(void **state) -{ - BIO_ADDR a; - - (void)state; - memset(&a, 0, sizeof(a)); - expect_accept(FAKE_SOCKET, ACCEPTED_SOCKET); - expect_nbio(ACCEPTED_SOCKET, 1, 1); - assert_int_equal( - BIO_accept_ex(FAKE_SOCKET, &a, BIO_SOCK_NONBLOCK), ACCEPTED_SOCKET); -} - -static void test_accept_ex_retry(void **state) -{ - BIO_ADDR a; - - (void)state; - memset(&a, 0, sizeof(a)); - expect_accept(FAKE_SOCKET, -1); - expect_should_retry(-1, 1); - assert_int_equal(BIO_accept_ex(FAKE_SOCKET, &a, 0), (int)INVALID_SOCKET); -} - -static void test_accept_ex_error(void **state) -{ - BIO_ADDR a; - - (void)state; - memset(&a, 0, sizeof(a)); - expect_accept(FAKE_SOCKET, -1); - expect_should_retry(-1, 0); - assert_int_equal(BIO_accept_ex(FAKE_SOCKET, &a, 0), (int)INVALID_SOCKET); -} - -static void test_accept_ex_nbio_fails(void **state) -{ - /* a non-blocking failure on the accepted socket closes it again */ - BIO_ADDR a; - - (void)state; - memset(&a, 0, sizeof(a)); - expect_accept(FAKE_SOCKET, ACCEPTED_SOCKET); - expect_nbio(ACCEPTED_SOCKET, 0, 0); - expect_close(ACCEPTED_SOCKET, 0); - assert_int_equal(BIO_accept_ex(FAKE_SOCKET, &a, 0), (int)INVALID_SOCKET); -} - -/* BIO_closesocket */ - -static void test_closesocket_success(void **state) -{ - (void)state; - expect_close(FAKE_SOCKET, 0); - assert_int_equal(BIO_closesocket(FAKE_SOCKET), 1); -} - -static void test_closesocket_negative(void **state) -{ - /* a negative fd short-circuits before any close() */ - (void)state; - assert_int_equal(BIO_closesocket(-1), 0); -} - -static void test_closesocket_fails(void **state) -{ - (void)state; - expect_close(FAKE_SOCKET, -1); - assert_int_equal(BIO_closesocket(FAKE_SOCKET), 0); -} - -/* main */ - -#define SOCK_TEST(name) cmocka_unit_test(name) - -int main(void) -{ - const struct CMUnitTest tests[] = { - /* BIO_socket */ - SOCK_TEST(test_socket_success), - SOCK_TEST(test_socket_fails), - /* BIO_connect */ - SOCK_TEST(test_connect_invalid_sock), - SOCK_TEST(test_connect_nbio_fails), - SOCK_TEST(test_connect_success), - SOCK_TEST(test_connect_nonblock), - SOCK_TEST(test_connect_keepalive), - SOCK_TEST(test_connect_keepalive_fails), - SOCK_TEST(test_connect_nodelay), - SOCK_TEST(test_connect_nodelay_fails), - SOCK_TEST(test_connect_fails_retry), - SOCK_TEST(test_connect_fails_error), - /* BIO_bind */ - SOCK_TEST(test_bind_invalid_sock), - SOCK_TEST(test_bind_success), - SOCK_TEST(test_bind_reuseaddr), - SOCK_TEST(test_bind_reuseaddr_fails), - SOCK_TEST(test_bind_bind_fails), - /* BIO_listen */ - SOCK_TEST(test_listen_success), - SOCK_TEST(test_listen_invalid_sock), - SOCK_TEST(test_listen_getsockopt_fails), - SOCK_TEST(test_listen_socktype_len_mismatch), - SOCK_TEST(test_listen_nbio_fails), - SOCK_TEST(test_listen_keepalive), - SOCK_TEST(test_listen_keepalive_fails), - SOCK_TEST(test_listen_nodelay), - SOCK_TEST(test_listen_reuseaddr), - SOCK_TEST(test_listen_bind_fails), - SOCK_TEST(test_listen_dgram), - SOCK_TEST(test_listen_listen_fails), -#if defined(IPV6_V6ONLY) && !defined(__OpenBSD__) - SOCK_TEST(test_listen_v6only), - SOCK_TEST(test_listen_v6only_off), - SOCK_TEST(test_listen_v6only_fails), -#endif - /* BIO_accept_ex */ - SOCK_TEST(test_accept_ex_success), - SOCK_TEST(test_accept_ex_null_addr), - SOCK_TEST(test_accept_ex_nonblock), - SOCK_TEST(test_accept_ex_retry), - SOCK_TEST(test_accept_ex_error), - SOCK_TEST(test_accept_ex_nbio_fails), - /* BIO_closesocket */ - SOCK_TEST(test_closesocket_success), - SOCK_TEST(test_closesocket_negative), - SOCK_TEST(test_closesocket_fails), - }; - - cmocka_set_message_output(CM_OUTPUT_TAP); - - return cmocka_run_group_tests(tests, NULL, NULL); -} - -#else - -int main(void) -{ - return 0; -} - -#endif /* OPENSSL_NO_SOCK */ diff --git a/test/unit/crypto/bio/test_bss_acpt.c b/test/unit/crypto/bio/test_bss_acpt.c deleted file mode 100644 index 4a51c27373..0000000000 --- a/test/unit/crypto/bio/test_bss_acpt.c +++ /dev/null @@ -1,1054 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include "internal/sockets.h" - -#ifndef OPENSSL_NO_SOCK - -#include -#include -#include -#include -#include -#include -#include -#include -#include "bio_local.h" - -#define FAKE_SOCKET 42 - -/* - * Fake addrinfo used across state machine tests. g_addrinfo1.bai_next is - * NULL by default. Tests needing a second address temporarily set it to - * &g_addrinfo2 and restore it afterwards. - */ -static struct sockaddr_in g_sin; -static BIO_ADDRINFO g_addrinfo1; -static BIO_ADDRINFO g_addrinfo2; - -/* prototypes for __wrap_* (required by -Wmissing-prototypes) */ -int __wrap_BIO_lookup(const char *host, const char *service, - enum BIO_lookup_type lookup_type, - int family, int socktype, BIO_ADDRINFO **res); -int __wrap_BIO_socket(int domain, int socktype, int protocol, int options); -int __wrap_BIO_listen(int sock, const BIO_ADDR *addr, int options); -int __wrap_BIO_accept_ex(int accept_sock, BIO_ADDR *addr, int options); -int __wrap_BIO_sock_info(int sock, enum BIO_sock_info_type type, - union BIO_sock_info_u *info); -int __wrap_BIO_sock_should_retry(int i); -int __wrap_BIO_closesocket(int sock); -char *__wrap_BIO_ADDR_hostname_string(const BIO_ADDR *ap, int numeric); -char *__wrap_BIO_ADDR_service_string(const BIO_ADDR *ap, int numeric); - -/* wraps */ - -int __wrap_BIO_lookup(const char *host, const char *service, - enum BIO_lookup_type lookup_type, - int family, int socktype, BIO_ADDRINFO **res) -{ - int rc; - - function_called(); - check_expected(host); - check_expected(service); - check_expected(lookup_type); - check_expected(family); - check_expected(socktype); - rc = mock_type(int); - if (rc == 1) - *res = mock_ptr_type(BIO_ADDRINFO *); - return rc; -} - -int __wrap_BIO_socket(int domain, int socktype, int protocol, int options) -{ - function_called(); - check_expected(domain); - check_expected(socktype); - check_expected(protocol); - check_expected(options); - return mock_type(int); -} - -int __wrap_BIO_listen(int sock, const BIO_ADDR *addr, int options) -{ - function_called(); - check_expected(sock); - check_expected_ptr(addr); - check_expected(options); - return mock_type(int); -} - -int __wrap_BIO_accept_ex(int accept_sock, BIO_ADDR *addr, int options) -{ - function_called(); - check_expected(accept_sock); - check_expected_ptr(addr); - check_expected(options); - return mock_type(int); -} - -int __wrap_BIO_sock_info(int sock, enum BIO_sock_info_type type, - union BIO_sock_info_u *info) -{ - function_called(); - check_expected(sock); - check_expected(type); - (void)info; /* addr field left untouched; cache addr is zeroed already */ - return mock_type(int); -} - -int __wrap_BIO_sock_should_retry(int i) -{ - function_called(); - check_expected(i); - return mock_type(int); -} - -int __wrap_BIO_closesocket(int sock) -{ - function_called(); - check_expected(sock); - return mock_type(int); -} - -/* - * The cache_*_name / cache_*_serv pointers get OPENSSL_free()d in - * BIO_ACCEPT_free and when a new bind starts, so these wraps must return - * heap pointers (or NULL). - */ -char *__wrap_BIO_ADDR_hostname_string(const BIO_ADDR *ap, int numeric) -{ - function_called(); - (void)ap; - (void)numeric; - return mock_ptr_type(char *); -} - -char *__wrap_BIO_ADDR_service_string(const BIO_ADDR *ap, int numeric) -{ - function_called(); - (void)ap; - (void)numeric; - return mock_ptr_type(char *); -} - -/* - * A minimal fake sink BIO. The accept BIO forwards reads/writes to its - * next_bio once a connection is established, so I/O tests push one of these - * instead of a real socket BIO. This keeps acpt_read/acpt_write under test - * in isolation: no dependency on sock_read/sock_write, on the libc read/write - * syscalls, or on BIO_sock_should_retry. - * - * The fake read/write return mock_type and, on a non-positive result, set - * their own retry flag when asked, so acpt_read/acpt_write's - * BIO_copy_next_retry has a real source-of-truth to propagate upward. - */ - -static int fake_sink_read(BIO *b, char *buf, size_t size, size_t *readbytes); -static int fake_sink_write(BIO *b, const char *buf, size_t size, - size_t *written); -static long fake_sink_ctrl(BIO *b, int cmd, long arg1, void *arg2); - -static int fake_sink_read(BIO *b, char *buf, size_t size, size_t *readbytes) -{ - int ret; - - function_called(); - check_expected_ptr(buf); - check_expected(size); - BIO_clear_retry_flags(b); - ret = mock_type(int); - if (ret > 0) { - *readbytes = (size_t)ret; - return 1; - } - if (mock_type(int)) - BIO_set_retry_read(b); - *readbytes = 0; - return ret; -} - -static int fake_sink_write(BIO *b, const char *buf, size_t size, - size_t *written) -{ - int ret; - - function_called(); - check_expected_ptr(buf); - check_expected(size); - BIO_clear_retry_flags(b); - ret = mock_type(int); - if (ret > 0) { - *written = (size_t)ret; - return 1; - } - if (mock_type(int)) - BIO_set_retry_write(b); - *written = 0; - return ret; -} - -static long fake_sink_ctrl(BIO *b, int cmd, long arg1, void *arg2) -{ - (void)b; - (void)arg1; - (void)arg2; - if (cmd == BIO_CTRL_FLUSH) - return 1; - return 0; -} - -static BIO_METHOD *fake_sink_method = NULL; - -static BIO_METHOD *make_fake_sink_method(void) -{ - BIO_METHOD *m = BIO_meth_new(BIO_TYPE_SOURCE_SINK | 0xff, "fake sink"); - - assert_non_null(m); - assert_true(BIO_meth_set_read_ex(m, fake_sink_read)); - assert_true(BIO_meth_set_write_ex(m, fake_sink_write)); - assert_true(BIO_meth_set_ctrl(m, fake_sink_ctrl)); - return m; -} - -static BIO *make_fake_sink(void) -{ - BIO *b = BIO_new(fake_sink_method); - - assert_non_null(b); - BIO_set_init(b, 1); - return b; -} - -/* expectations */ - -static void expect_BIO_lookup(BIO_ADDRINFO *res, int rc) -{ - expect_function_call(__wrap_BIO_lookup); - expect_any(__wrap_BIO_lookup, host); - expect_any(__wrap_BIO_lookup, service); - expect_value(__wrap_BIO_lookup, lookup_type, BIO_LOOKUP_SERVER); - expect_any(__wrap_BIO_lookup, family); - expect_any(__wrap_BIO_lookup, socktype); - will_return(__wrap_BIO_lookup, rc); - if (rc == 1) - will_return(__wrap_BIO_lookup, res); -} - -/* options is the literal the state machine passes (always 0 here) */ -static void expect_BIO_socket(int domain, int socktype, int protocol, - int options, int rc) -{ - expect_function_call(__wrap_BIO_socket); - expect_value(__wrap_BIO_socket, domain, domain); - expect_value(__wrap_BIO_socket, socktype, socktype); - expect_value(__wrap_BIO_socket, protocol, protocol); - expect_value(__wrap_BIO_socket, options, options); - will_return(__wrap_BIO_socket, rc); -} - -static void expect_BIO_listen(int sock, const BIO_ADDR *addr, int options, - int rc) -{ - expect_function_call(__wrap_BIO_listen); - expect_value(__wrap_BIO_listen, sock, sock); - expect_value(__wrap_BIO_listen, addr, addr); - expect_value(__wrap_BIO_listen, options, options); - will_return(__wrap_BIO_listen, rc); -} - -static void expect_BIO_accept_ex(int sock, int options, int rc) -{ - expect_function_call(__wrap_BIO_accept_ex); - expect_value(__wrap_BIO_accept_ex, accept_sock, sock); - expect_any(__wrap_BIO_accept_ex, addr); - expect_value(__wrap_BIO_accept_ex, options, options); - will_return(__wrap_BIO_accept_ex, rc); -} - -static void expect_BIO_sock_info(int sock, int rc) -{ - expect_function_call(__wrap_BIO_sock_info); - expect_value(__wrap_BIO_sock_info, sock, sock); - expect_value(__wrap_BIO_sock_info, type, BIO_SOCK_INFO_ADDRESS); - will_return(__wrap_BIO_sock_info, rc); -} - -static void expect_BIO_sock_should_retry(int i, int rc) -{ - expect_function_call(__wrap_BIO_sock_should_retry); - expect_value(__wrap_BIO_sock_should_retry, i, i); - will_return(__wrap_BIO_sock_should_retry, rc); -} - -static void expect_BIO_closesocket(int sock, int rc) -{ - expect_function_call(__wrap_BIO_closesocket); - expect_value(__wrap_BIO_closesocket, sock, sock); - will_return(__wrap_BIO_closesocket, rc); -} - -/* The returned pointer is heap allocated; ownership passes to the BIO. */ -static void expect_BIO_ADDR_hostname_string(const char *val) -{ - expect_function_call(__wrap_BIO_ADDR_hostname_string); - will_return(__wrap_BIO_ADDR_hostname_string, - val == NULL ? NULL : OPENSSL_strdup(val)); -} - -static void expect_BIO_ADDR_service_string(const char *val) -{ - expect_function_call(__wrap_BIO_ADDR_service_string); - will_return(__wrap_BIO_ADDR_service_string, - val == NULL ? NULL : OPENSSL_strdup(val)); -} - -/* - * rc is the byte count (>0) or the non-positive result; retry tells the sink - * whether to set its own retry flag when rc <= 0. - */ -static void expect_fake_sink_read(const void *buf, size_t size, int rc, - int retry) -{ - expect_function_call(fake_sink_read); - expect_value(fake_sink_read, buf, buf); - expect_value(fake_sink_read, size, size); - will_return(fake_sink_read, rc); - if (rc <= 0) - will_return(fake_sink_read, retry); -} - -static void expect_fake_sink_write(const void *buf, size_t size, int rc, - int retry) -{ - expect_function_call(fake_sink_write); - expect_value(fake_sink_write, buf, buf); - expect_value(fake_sink_write, size, size); - will_return(fake_sink_write, rc); - if (rc <= 0) - will_return(fake_sink_write, retry); -} - -/* - * The LISTEN state always emits, in order: BIO_listen, BIO_sock_info, then a - * hostname_string + service_string pair for the accepting address cache. - */ -static void expect_listen_sequence(int sock) -{ - expect_BIO_listen(sock, (const BIO_ADDR *)&g_sin, 0, 1); - expect_BIO_sock_info(sock, 1); - expect_BIO_ADDR_hostname_string("127.0.0.1"); - expect_BIO_ADDR_service_string("443"); -} - -/* helpers */ - -static BIO_ACCEPT *get_data(BIO *bio) -{ - return (BIO_ACCEPT *)bio->ptr; -} - -/* - * Reset socket bookkeeping so acpt_close_socket is a no-op during free, and - * clear the address iterators that point at static storage. - */ -static void reset_for_teardown(BIO *bio) -{ - BIO_ACCEPT *data = get_data(bio); - - bio->num = (int)INVALID_SOCKET; - data->accept_sock = (int)INVALID_SOCKET; - data->addr_first = NULL; - data->addr_iter = NULL; - data->state = BIO_ACPT_S_BEFORE; -} - -/* setup / teardown */ - -static int setup(void **state) -{ - BIO *bio = BIO_new(BIO_s_accept()); - - assert_non_null(bio); - *state = bio; - return 0; -} - -static int teardown(void **state) -{ - if (*state != NULL) - BIO_free(*state); - return 0; -} - -/* - * I/O tests pre-establish state=OK and push a fake sink BIO so the state - * machine exits immediately and reads/writes are forwarded to next_bio. - */ -static int setup_io(void **state) -{ - BIO *bio, *sink; - BIO_ACCEPT *data; - - if (setup(state) != 0) - return -1; - bio = *state; - data = get_data(bio); - data->state = BIO_ACPT_S_OK; - data->accept_sock = FAKE_SOCKET; - bio->num = FAKE_SOCKET; - bio->init = 1; - - sink = make_fake_sink(); - assert_non_null(BIO_push(bio, sink)); - return 0; -} - -static int teardown_io(void **state) -{ - if (*state != NULL) { - reset_for_teardown(*state); - /* BIO_free_all to also release the pushed fake sink BIO. */ - BIO_free_all(*state); - *state = NULL; - } - return 0; -} - -static int group_setup(void **state) -{ - (void)state; - - fake_sink_method = make_fake_sink_method(); - - memset(&g_sin, 0, sizeof(g_sin)); - g_sin.sin_family = AF_INET; - g_sin.sin_port = htons(443); - g_sin.sin_addr.s_addr = htonl(INADDR_LOOPBACK); - - memset(&g_addrinfo1, 0, sizeof(g_addrinfo1)); - g_addrinfo1.bai_family = AF_INET; - g_addrinfo1.bai_socktype = SOCK_STREAM; - g_addrinfo1.bai_protocol = IPPROTO_TCP; - g_addrinfo1.bai_addrlen = sizeof(g_sin); - g_addrinfo1.bai_addr = (struct sockaddr *)&g_sin; - g_addrinfo1.bai_next = NULL; - - memcpy(&g_addrinfo2, &g_addrinfo1, sizeof(g_addrinfo1)); - g_addrinfo2.bai_next = NULL; - - return 0; -} - -static int group_teardown(void **state) -{ - (void)state; - BIO_meth_free(fake_sink_method); - fake_sink_method = NULL; - return 0; -} - -/* acpt_new */ - -static void test_acpt_new(void **state) -{ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - assert_non_null(data); - assert_int_equal(data->state, BIO_ACPT_S_BEFORE); - assert_int_equal(data->accept_family, BIO_FAMILY_IPANY); - assert_int_equal(data->accept_sock, (int)INVALID_SOCKET); - assert_null(data->param_addr); - assert_null(data->param_serv); - assert_null(data->addr_first); - assert_null(data->bio_chain); - assert_int_equal(bio->num, (int)INVALID_SOCKET); - assert_int_equal(bio->init, 0); - assert_int_equal(bio->shutdown, 1); -} - -/* acpt_free */ - -static void test_acpt_free_no_shutdown(void **state) -{ - /* shutdown=0: acpt_close_socket and BIO_ACCEPT_free are both skipped */ - BIO *bio = BIO_new(BIO_s_accept()); - - assert_non_null(bio); - bio->shutdown = BIO_NOCLOSE; - BIO_free(bio); - *state = NULL; -} - -/* acpt_close_socket (via BIO_CTRL_RESET) */ - -static void test_close_socket_none(void **state) -{ - /* accept_sock == INVALID_SOCKET: no closesocket expected */ - assert_int_equal(BIO_ctrl(*state, BIO_CTRL_RESET, 0, NULL), 0); - assert_int_equal(get_data(*state)->state, BIO_ACPT_S_BEFORE); -} - -/* acpt_state via BIO_C_DO_STATE_MACHINE (BIO_do_accept) */ - -static void test_acpt_state_no_addr(void **state) -{ - /* BEFORE with no addr and no serv -> error */ - assert_true(BIO_do_accept(*state) <= 0); -} - -static void test_acpt_state_unsupported_family(void **state) -{ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - data->param_serv = OPENSSL_strdup("443"); - data->accept_family = 9999; - - assert_true(BIO_do_accept(bio) <= 0); -} - -static void test_acpt_state_lookup_fails(void **state) -{ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - data->param_serv = OPENSSL_strdup("443"); - - expect_BIO_lookup(NULL, 0); - assert_true(BIO_do_accept(bio) <= 0); -} - -static void test_acpt_state_lookup_empty(void **state) -{ - /* BIO_lookup succeeds but returns no addresses */ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - data->param_serv = OPENSSL_strdup("443"); - - expect_BIO_lookup(NULL, 1); /* rc==1 but res stays NULL */ - assert_true(BIO_do_accept(bio) <= 0); -} - -static void test_acpt_state_socket_fails(void **state) -{ - /* Pre-set CREATE_SOCKET, single address: BIO_socket fails -> error */ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - data->state = BIO_ACPT_S_CREATE_SOCKET; - data->addr_iter = &g_addrinfo1; /* bai_next == NULL */ - - expect_BIO_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, - (int)INVALID_SOCKET); - assert_true(BIO_do_accept(bio) <= 0); - - reset_for_teardown(bio); -} - -static void test_acpt_state_socket_next_addr(void **state) -{ - /* - * Two addresses: first BIO_socket fails, iterator advances, second - * BIO_socket also fails -> clean error exit. - */ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - g_addrinfo1.bai_next = &g_addrinfo2; - data->state = BIO_ACPT_S_CREATE_SOCKET; - data->addr_iter = &g_addrinfo1; - - expect_BIO_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, - (int)INVALID_SOCKET); - expect_BIO_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, - (int)INVALID_SOCKET); - assert_true(BIO_do_accept(bio) <= 0); - - g_addrinfo1.bai_next = NULL; - reset_for_teardown(bio); -} - -static void test_acpt_state_listen_fails(void **state) -{ - /* CREATE_SOCKET succeeds, BIO_listen fails -> closesocket, error */ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - data->state = BIO_ACPT_S_CREATE_SOCKET; - data->addr_iter = &g_addrinfo1; - - expect_BIO_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, FAKE_SOCKET); - expect_BIO_listen(FAKE_SOCKET, (const BIO_ADDR *)&g_sin, 0, 0); - expect_BIO_closesocket(FAKE_SOCKET, 0); - - assert_true(BIO_do_accept(bio) <= 0); - assert_int_equal(data->accept_sock, (int)INVALID_SOCKET); - - reset_for_teardown(bio); -} - -static void test_acpt_state_sock_info_fails(void **state) -{ - /* listen ok, BIO_sock_info fails -> closesocket, error */ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - data->state = BIO_ACPT_S_CREATE_SOCKET; - data->addr_iter = &g_addrinfo1; - - expect_BIO_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, FAKE_SOCKET); - expect_BIO_listen(FAKE_SOCKET, (const BIO_ADDR *)&g_sin, 0, 1); - expect_BIO_sock_info(FAKE_SOCKET, 0); - expect_BIO_closesocket(FAKE_SOCKET, 0); - - assert_true(BIO_do_accept(bio) <= 0); - assert_int_equal(data->accept_sock, (int)INVALID_SOCKET); - - reset_for_teardown(bio); -} - -static void test_acpt_state_bind_ok(void **state) -{ - /* - * Full bind path: BEFORE -> GET_ADDR -> CREATE_SOCKET -> LISTEN returns 1 - * and the machine stops at BIO_ACPT_S_ACCEPT (next_bio is NULL). - */ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - data->param_serv = OPENSSL_strdup("443"); - - expect_BIO_lookup(&g_addrinfo1, 1); - expect_BIO_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, FAKE_SOCKET); - expect_listen_sequence(FAKE_SOCKET); - - assert_int_equal(BIO_do_accept(bio), 1); - assert_int_equal(data->state, BIO_ACPT_S_ACCEPT); - assert_int_equal(data->accept_sock, FAKE_SOCKET); - assert_string_equal(data->cache_accepting_name, "127.0.0.1"); - assert_string_equal(data->cache_accepting_serv, "443"); - - reset_for_teardown(bio); -} - -static void test_acpt_state_accept_retry(void **state) -{ - /* Pre-set ACCEPT, no next_bio: BIO_accept_ex retryable -> special flag */ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - data->state = BIO_ACPT_S_ACCEPT; - data->accept_sock = FAKE_SOCKET; - bio->num = FAKE_SOCKET; - - expect_BIO_accept_ex(FAKE_SOCKET, 0, -1); - expect_BIO_sock_should_retry(-1, 1); - - assert_true(BIO_do_accept(bio) <= 0); - assert_true(BIO_should_io_special(bio)); - assert_int_equal(bio->retry_reason, BIO_RR_ACCEPT); - - reset_for_teardown(bio); -} - -static void test_acpt_state_accept_error(void **state) -{ - /* Pre-set ACCEPT: BIO_accept_ex fails, not retryable -> error */ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - data->state = BIO_ACPT_S_ACCEPT; - data->accept_sock = FAKE_SOCKET; - bio->num = FAKE_SOCKET; - - expect_BIO_accept_ex(FAKE_SOCKET, 0, -1); - expect_BIO_sock_should_retry(-1, 0); - - assert_true(BIO_do_accept(bio) <= 0); - - reset_for_teardown(bio); -} - -static void test_acpt_state_already_ok_no_next(void **state) -{ - /* - * State OK but next_bio NULL: machine drops back to ACCEPT and tries to - * accept. We make that accept fail non-retryably for a clean exit. - */ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - data->state = BIO_ACPT_S_OK; - data->accept_sock = FAKE_SOCKET; - bio->num = FAKE_SOCKET; - - expect_BIO_accept_ex(FAKE_SOCKET, 0, -1); - expect_BIO_sock_should_retry(-1, 0); - - assert_true(BIO_do_accept(bio) <= 0); - - reset_for_teardown(bio); -} - -/* acpt_read / acpt_write (state already OK with a pushed fake sink BIO) */ - -static void test_acpt_read_forwards(void **state) -{ - BIO *bio = *state; - char buf[8] = { 0 }; - - expect_fake_sink_read(buf, 8, 8, 0); - assert_int_equal(BIO_read(bio, buf, 8), 8); - assert_false(BIO_should_retry(bio)); -} - -static void test_acpt_read_forwards_retry(void **state) -{ - /* - * The fake sink returns a retryable read and sets its own retry-read - * flag; acpt_read must propagate it onto the accept BIO via - * BIO_copy_next_retry. - */ - BIO *bio = *state; - char buf[8] = { 0 }; - - expect_fake_sink_read(buf, 8, -1, 1); - assert_true(BIO_read(bio, buf, 8) <= 0); - assert_true(BIO_should_read(bio)); - assert_true(BIO_should_retry(bio)); -} - -static void test_acpt_write_forwards(void **state) -{ - BIO *bio = *state; - const char buf[] = "hello"; - - expect_fake_sink_write(buf, 5, 5, 0); - assert_int_equal(BIO_write(bio, buf, 5), 5); - assert_false(BIO_should_retry(bio)); -} - -static void test_acpt_write_forwards_retry(void **state) -{ - BIO *bio = *state; - const char buf[] = "hello"; - - expect_fake_sink_write(buf, 5, -1, 1); - assert_true(BIO_write(bio, buf, 5) <= 0); - assert_true(BIO_should_write(bio)); - assert_true(BIO_should_retry(bio)); -} - -static void test_acpt_puts_forwards(void **state) -{ - BIO *bio = *state; - const char *str = "hello"; - - expect_fake_sink_write(str, 5, 5, 0); - assert_int_equal(BIO_puts(bio, str), 5); -} - -/* acpt_ctrl */ - -static void test_acpt_ctrl_reset_clears_addrs(void **state) -{ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - data->addr_first = NULL; /* keep BIO_ADDRINFO_free a no-op */ - data->addr_iter = &g_addrinfo1; - bio->flags = BIO_FLAGS_SHOULD_RETRY; - - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_RESET, 0, NULL), 0); - assert_null(data->addr_first); - assert_null(data->addr_iter); - assert_int_equal(bio->flags, 0); - assert_int_equal(data->state, BIO_ACPT_S_BEFORE); -} - -static void test_acpt_ctrl_set_accept_name(void **state) -{ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - assert_true(BIO_set_accept_name(bio, "host.example:443") > 0); - assert_int_equal(bio->init, 1); - assert_string_equal(data->param_addr, "host.example"); - assert_string_equal(data->param_serv, "443"); -} - -static void test_acpt_ctrl_set_accept_port(void **state) -{ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - assert_true(BIO_set_accept_port(bio, "8443") > 0); - assert_int_equal(bio->init, 1); - assert_string_equal(data->param_serv, "8443"); -} - -static void test_acpt_ctrl_set_nbio_accept(void **state) -{ - /* toggles BIO_SOCK_NONBLOCK in bind_mode */ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - BIO_set_nbio_accept(bio, 1); - assert_true(data->bind_mode & BIO_SOCK_NONBLOCK); - - BIO_set_nbio_accept(bio, 0); - assert_false(data->bind_mode & BIO_SOCK_NONBLOCK); -} - -static void test_acpt_ctrl_set_accept_bios(void **state) -{ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - BIO *chain = BIO_new(BIO_s_mem()); - - assert_non_null(chain); - assert_true(BIO_set_accept_bios(bio, chain) > 0); - assert_ptr_equal(data->bio_chain, chain); - /* freed by BIO_ACCEPT_free in teardown */ -} - -static void test_acpt_ctrl_set_accept_ip_family(void **state) -{ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - assert_true(BIO_set_accept_ip_family(bio, BIO_FAMILY_IPV4) > 0); - assert_int_equal(data->accept_family, BIO_FAMILY_IPV4); -} - -static void test_acpt_ctrl_set_tfo_accept(void **state) -{ - /* toggles BIO_SOCK_TFO in bind_mode */ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - BIO_set_tfo_accept(bio, 1); - assert_true(data->bind_mode & BIO_SOCK_TFO); - - BIO_set_tfo_accept(bio, 0); - assert_false(data->bind_mode & BIO_SOCK_TFO); -} - -static void test_acpt_ctrl_set_nbio(void **state) -{ - /* BIO_C_SET_NBIO: toggles BIO_SOCK_NONBLOCK in accepted_mode */ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - BIO_set_nbio(bio, 1); - assert_true(data->accepted_mode & BIO_SOCK_NONBLOCK); - - BIO_set_nbio(bio, 0); - assert_false(data->accepted_mode & BIO_SOCK_NONBLOCK); -} - -static void test_acpt_ctrl_set_fd(void **state) -{ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - BIO_set_fd(bio, FAKE_SOCKET, BIO_NOCLOSE); - assert_int_equal(bio->num, FAKE_SOCKET); - assert_int_equal(data->accept_sock, FAKE_SOCKET); - assert_int_equal(data->state, BIO_ACPT_S_ACCEPT); - assert_int_equal(bio->init, 1); - assert_int_equal(bio->shutdown, BIO_NOCLOSE); - - reset_for_teardown(bio); -} - -static void test_acpt_ctrl_get_fd(void **state) -{ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - int fd = -1; - - /* init==0 -> -1 */ - assert_int_equal(BIO_get_fd(bio, &fd), -1); - - bio->init = 1; - data->accept_sock = FAKE_SOCKET; - assert_int_equal(BIO_get_fd(bio, &fd), FAKE_SOCKET); - assert_int_equal(fd, FAKE_SOCKET); - - bio->init = 0; - data->accept_sock = (int)INVALID_SOCKET; -} - -static void test_acpt_ctrl_get_accept_names(void **state) -{ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - const char *out; - - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_ACCEPT, 0, &out), -1); - - bio->init = 1; - data->cache_accepting_name = OPENSSL_strdup("accept.host"); - data->cache_accepting_serv = OPENSSL_strdup("443"); - data->cache_peer_name = OPENSSL_strdup("peer.host"); - data->cache_peer_serv = OPENSSL_strdup("55000"); - - assert_string_equal(BIO_get_accept_name(bio), "accept.host"); - assert_string_equal(BIO_get_accept_port(bio), "443"); - assert_string_equal(BIO_get_peer_name(bio), "peer.host"); - assert_string_equal(BIO_get_peer_port(bio), "55000"); - - bio->init = 0; -} - -static void test_acpt_ctrl_get_accept_family(void **state) -{ - /* AF_INET addr_iter maps to BIO_FAMILY_IPV4 */ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - bio->init = 1; - data->addr_iter = &g_addrinfo1; - assert_int_equal(BIO_get_accept_ip_family(bio), BIO_FAMILY_IPV4); - data->addr_iter = NULL; - bio->init = 0; -} - -static void test_acpt_ctrl_get_set_close(void **state) -{ - BIO *bio = *state; - - bio->shutdown = BIO_NOCLOSE; - assert_int_equal(BIO_get_close(bio), BIO_NOCLOSE); - - assert_int_equal(BIO_set_close(bio, BIO_CLOSE), 1); - assert_int_equal(bio->shutdown, BIO_CLOSE); -} - -static void test_acpt_ctrl_bind_mode(void **state) -{ - BIO *bio = *state; - BIO_ACCEPT *data = get_data(bio); - - BIO_set_bind_mode(bio, BIO_SOCK_REUSEADDR); - assert_int_equal(data->bind_mode, BIO_SOCK_REUSEADDR); - assert_int_equal(BIO_get_bind_mode(bio), BIO_SOCK_REUSEADDR); -} - -static void test_acpt_ctrl_pending_flush(void **state) -{ - BIO *bio = *state; - - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_PENDING, 0, NULL), 0); - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_WPENDING, 0, NULL), 0); - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_FLUSH, 0, NULL), 1); -} - -static void test_acpt_ctrl_eof_no_next(void **state) -{ - /* next_bio == NULL -> 0 */ - assert_int_equal(BIO_ctrl(*state, BIO_CTRL_EOF, 0, NULL), 0); -} - -static void test_acpt_ctrl_default(void **state) -{ - assert_int_equal(BIO_ctrl(*state, 9999, 0, NULL), 0); -} - -/* BIO_new_accept convenience constructor */ - -static void test_bio_new_accept(void **state) -{ - BIO *bio = BIO_new_accept("localhost:443"); - BIO_ACCEPT *data; - - assert_non_null(bio); - data = (BIO_ACCEPT *)bio->ptr; - assert_string_equal(data->param_addr, "localhost"); - assert_string_equal(data->param_serv, "443"); - BIO_free(bio); - (void)state; -} - -/* main */ - -#define ACPT_TEST(name) \ - cmocka_unit_test_setup_teardown(name, setup, teardown) - -#define ACPT_TEST_IO(name) \ - cmocka_unit_test_setup_teardown(name, setup_io, teardown_io) - -int main(void) -{ - const struct CMUnitTest tests[] = { - /* acpt_new */ - ACPT_TEST(test_acpt_new), - /* acpt_free */ - ACPT_TEST(test_acpt_free_no_shutdown), - /* acpt_close_socket */ - ACPT_TEST(test_close_socket_none), - /* acpt_state */ - ACPT_TEST(test_acpt_state_no_addr), - ACPT_TEST(test_acpt_state_unsupported_family), - ACPT_TEST(test_acpt_state_lookup_fails), - ACPT_TEST(test_acpt_state_lookup_empty), - ACPT_TEST(test_acpt_state_socket_fails), - ACPT_TEST(test_acpt_state_socket_next_addr), - ACPT_TEST(test_acpt_state_listen_fails), - ACPT_TEST(test_acpt_state_sock_info_fails), - ACPT_TEST(test_acpt_state_bind_ok), - ACPT_TEST(test_acpt_state_accept_retry), - ACPT_TEST(test_acpt_state_accept_error), - ACPT_TEST(test_acpt_state_already_ok_no_next), - /* acpt_read / acpt_write / acpt_puts */ - ACPT_TEST_IO(test_acpt_read_forwards), - ACPT_TEST_IO(test_acpt_read_forwards_retry), - ACPT_TEST_IO(test_acpt_write_forwards), - ACPT_TEST_IO(test_acpt_write_forwards_retry), - ACPT_TEST_IO(test_acpt_puts_forwards), - /* acpt_ctrl */ - ACPT_TEST(test_acpt_ctrl_reset_clears_addrs), - ACPT_TEST(test_acpt_ctrl_set_accept_name), - ACPT_TEST(test_acpt_ctrl_set_accept_port), - ACPT_TEST(test_acpt_ctrl_set_nbio_accept), - ACPT_TEST(test_acpt_ctrl_set_accept_bios), - ACPT_TEST(test_acpt_ctrl_set_accept_ip_family), - ACPT_TEST(test_acpt_ctrl_set_tfo_accept), - ACPT_TEST(test_acpt_ctrl_set_nbio), - ACPT_TEST(test_acpt_ctrl_set_fd), - ACPT_TEST(test_acpt_ctrl_get_fd), - ACPT_TEST(test_acpt_ctrl_get_accept_names), - ACPT_TEST(test_acpt_ctrl_get_accept_family), - ACPT_TEST(test_acpt_ctrl_get_set_close), - ACPT_TEST(test_acpt_ctrl_bind_mode), - ACPT_TEST(test_acpt_ctrl_pending_flush), - ACPT_TEST(test_acpt_ctrl_eof_no_next), - ACPT_TEST(test_acpt_ctrl_default), - /* BIO_new_accept */ - ACPT_TEST(test_bio_new_accept), - }; - - cmocka_set_message_output(CM_OUTPUT_TAP); - - return cmocka_run_group_tests(tests, group_setup, group_teardown); -} - -#else - -int main(void) -{ - return 0; -} - -#endif /* OPENSSL_NO_SOCK */ diff --git a/test/unit/crypto/bio/test_bss_conn.c b/test/unit/crypto/bio/test_bss_conn.c deleted file mode 100644 index 992a1b781a..0000000000 --- a/test/unit/crypto/bio/test_bss_conn.c +++ /dev/null @@ -1,1590 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include "internal/sockets.h" - -#ifndef OPENSSL_NO_SOCK - -#include -#include -#include -#include -#include -#include -#include -#include -#include "bio_local.h" - -#define FAKE_SOCKET 42 - -/* - * Fake addrinfo used across state machine tests. g_addrinfo1.bai_next is - * NULL by default. Tests needing a second address temporarily set it to - * &g_addrinfo2 and restore it afterwards. - */ -static struct sockaddr_in g_sin; -static BIO_ADDRINFO g_addrinfo1; -static BIO_ADDRINFO g_addrinfo2; - -/* prototypes for __wrap_* (required by -Wmissing-prototypes) */ -ssize_t __wrap_read(int fd, void *buf, size_t count); -ssize_t __wrap_write(int fd, const void *buf, size_t count); -int __wrap_BIO_lookup(const char *host, const char *service, - enum BIO_lookup_type lookup_type, - int family, int socktype, BIO_ADDRINFO **res); -int __wrap_BIO_socket(int domain, int socktype, int protocol, int options); -int __wrap_BIO_connect(int sock, const BIO_ADDR *addr, int options); -int __wrap_BIO_sock_should_retry(int i); -int __wrap_BIO_closesocket(int sock); -int __wrap_BIO_socket_wait(int fd, int for_write, time_t max_time); -int __wrap_BIO_sock_error(int sock); - -/* wraps */ - -ssize_t __wrap_read(int fd, void *buf, size_t count) -{ - function_called(); - check_expected(fd); - check_expected_ptr(buf); - check_expected(count); - return mock_type(ssize_t); -} - -ssize_t __wrap_write(int fd, const void *buf, size_t count) -{ - function_called(); - check_expected(fd); - check_expected_ptr(buf); - check_expected(count); - return mock_type(ssize_t); -} - -int __wrap_BIO_lookup(const char *host, const char *service, - enum BIO_lookup_type lookup_type, - int family, int socktype, BIO_ADDRINFO **res) -{ - int rc; - - function_called(); - check_expected(host); - check_expected(service); - check_expected(lookup_type); - check_expected(family); - check_expected(socktype); - rc = mock_type(int); - if (rc == 1) - *res = mock_ptr_type(BIO_ADDRINFO *); - return rc; -} - -int __wrap_BIO_socket(int domain, int socktype, int protocol, int options) -{ - function_called(); - check_expected(domain); - check_expected(socktype); - check_expected(protocol); - check_expected(options); - return mock_type(int); -} - -int __wrap_BIO_connect(int sock, const BIO_ADDR *addr, int options) -{ - function_called(); - check_expected(sock); - check_expected_ptr(addr); - check_expected(options); - return mock_type(int); -} - -int __wrap_BIO_sock_should_retry(int i) -{ - function_called(); - check_expected(i); - return mock_type(int); -} - -int __wrap_BIO_closesocket(int sock) -{ - function_called(); - check_expected(sock); - return mock_type(int); -} - -int __wrap_BIO_socket_wait(int fd, int for_write, time_t max_time) -{ - function_called(); - check_expected(fd); - check_expected(for_write); - (void)max_time; /* derived from time(NULL): not checked */ - return mock_type(int); -} - -int __wrap_BIO_sock_error(int sock) -{ - function_called(); - check_expected(sock); - return mock_type(int); -} - -/* - * A minimal fake dgram BIO. conn_read/conn_write/conn_sendmmsg/conn_recvmmsg - * delegate to the public BIO_* calls on data->dgram_bio, so the leaf needs - * read/write/sendmmsg/recvmmsg to dispatch. Everything the connect layer - * forwards (the buffer, message array, stride, count and flags) is verified. - */ - -static int fake_dgram_read(BIO *b, char *buf, size_t size, size_t *readbytes); -static int fake_dgram_write(BIO *b, const char *buf, size_t size, - size_t *written); -static long fake_dgram_ctrl(BIO *b, int cmd, long arg1, void *arg2); -static int fake_dgram_sendmmsg(BIO *b, BIO_MSG *m, size_t s, size_t n, - uint64_t f, size_t *mp); -static int fake_dgram_recvmmsg(BIO *b, BIO_MSG *m, size_t s, size_t n, - uint64_t f, size_t *mp); - -static int fake_dgram_read(BIO *b, char *buf, size_t size, size_t *readbytes) -{ - int ret; - - (void)b; - function_called(); - check_expected_ptr(buf); - check_expected(size); - ret = mock_type(int); - if (ret > 0) { - *readbytes = (size_t)ret; - return 1; - } - *readbytes = 0; - return ret; -} - -static int fake_dgram_write(BIO *b, const char *buf, size_t size, - size_t *written) -{ - int ret; - - (void)b; - function_called(); - check_expected_ptr(buf); - check_expected(size); - ret = mock_type(int); - if (ret > 0) { - *written = (size_t)ret; - return 1; - } - *written = 0; - return ret; -} - -static long fake_dgram_ctrl(BIO *b, int cmd, long arg1, void *arg2) -{ - (void)b; - (void)arg1; - (void)arg2; - if (cmd == BIO_CTRL_FLUSH) - return 1; - return 0; -} - -static int fake_dgram_sendmmsg(BIO *b, BIO_MSG *m, size_t s, size_t n, - uint64_t f, size_t *mp) -{ - (void)b; - function_called(); - check_expected_ptr(m); - check_expected(s); - check_expected(n); - check_expected(f); - *mp = mock_type(size_t); - return mock_type(int); -} - -static int fake_dgram_recvmmsg(BIO *b, BIO_MSG *m, size_t s, size_t n, - uint64_t f, size_t *mp) -{ - (void)b; - function_called(); - check_expected_ptr(m); - check_expected(s); - check_expected(n); - check_expected(f); - *mp = mock_type(size_t); - return mock_type(int); -} - -static BIO_METHOD *fake_dgram_method = NULL; - -static BIO_METHOD *make_fake_dgram_method(void) -{ - BIO_METHOD *m = BIO_meth_new(BIO_TYPE_DGRAM | 0xff, "fake dgram"); - - assert_non_null(m); - assert_true(BIO_meth_set_read_ex(m, fake_dgram_read)); - assert_true(BIO_meth_set_write_ex(m, fake_dgram_write)); - assert_true(BIO_meth_set_ctrl(m, fake_dgram_ctrl)); - assert_true(BIO_meth_set_sendmmsg(m, fake_dgram_sendmmsg)); - assert_true(BIO_meth_set_recvmmsg(m, fake_dgram_recvmmsg)); - return m; -} - -static BIO *make_fake_dgram(void) -{ - BIO *d = BIO_new(fake_dgram_method); - - assert_non_null(d); - BIO_set_init(d, 1); - return d; -} - -/* expectations */ - -static void expect_read(int fd, const void *buf, size_t count, ssize_t rc) -{ - expect_function_call(__wrap_read); - expect_value(__wrap_read, fd, fd); - expect_value(__wrap_read, buf, buf); - expect_value(__wrap_read, count, count); - will_return(__wrap_read, rc); -} - -static void expect_write(int fd, const void *buf, size_t count, ssize_t rc) -{ - expect_function_call(__wrap_write); - expect_value(__wrap_write, fd, fd); - expect_value(__wrap_write, buf, buf); - expect_value(__wrap_write, count, count); - will_return(__wrap_write, rc); -} - -static void expect_BIO_lookup(BIO_ADDRINFO *res, int rc) -{ - expect_function_call(__wrap_BIO_lookup); - expect_any(__wrap_BIO_lookup, host); - expect_any(__wrap_BIO_lookup, service); - expect_any(__wrap_BIO_lookup, lookup_type); - expect_any(__wrap_BIO_lookup, family); - expect_any(__wrap_BIO_lookup, socktype); - will_return(__wrap_BIO_lookup, rc); - if (rc == 1) - will_return(__wrap_BIO_lookup, res); -} - -/* options is the literal the state machine passes (always 0 here) */ -static void expect_BIO_socket(int domain, int socktype, int protocol, - int options, int rc) -{ - expect_function_call(__wrap_BIO_socket); - expect_value(__wrap_BIO_socket, domain, domain); - expect_value(__wrap_BIO_socket, socktype, socktype); - expect_value(__wrap_BIO_socket, protocol, protocol); - expect_value(__wrap_BIO_socket, options, options); - will_return(__wrap_BIO_socket, rc); -} - -static void expect_BIO_connect(int sock, const BIO_ADDR *addr, int options, - int rc) -{ - expect_function_call(__wrap_BIO_connect); - expect_value(__wrap_BIO_connect, sock, sock); - expect_value(__wrap_BIO_connect, addr, addr); - expect_value(__wrap_BIO_connect, options, options); - will_return(__wrap_BIO_connect, rc); -} - -static void expect_BIO_sock_should_retry(int i, int rc) -{ - expect_function_call(__wrap_BIO_sock_should_retry); - expect_value(__wrap_BIO_sock_should_retry, i, i); - will_return(__wrap_BIO_sock_should_retry, rc); -} - -static void expect_BIO_closesocket(int sock, int rc) -{ - expect_function_call(__wrap_BIO_closesocket); - expect_value(__wrap_BIO_closesocket, sock, sock); - will_return(__wrap_BIO_closesocket, rc); -} - -static void expect_BIO_socket_wait(int fd, int for_write, int rc) -{ - expect_function_call(__wrap_BIO_socket_wait); - expect_value(__wrap_BIO_socket_wait, fd, fd); - expect_value(__wrap_BIO_socket_wait, for_write, for_write); - will_return(__wrap_BIO_socket_wait, rc); -} - -static void expect_BIO_sock_error(int sock, int rc) -{ - expect_function_call(__wrap_BIO_sock_error); - expect_value(__wrap_BIO_sock_error, sock, sock); - will_return(__wrap_BIO_sock_error, rc); -} - -static void expect_fake_dgram_read(const void *buf, size_t size, int rc) -{ - expect_function_call(fake_dgram_read); - expect_value(fake_dgram_read, buf, buf); - expect_value(fake_dgram_read, size, size); - will_return(fake_dgram_read, rc); -} - -static void expect_fake_dgram_write(const void *buf, size_t size, int rc) -{ - expect_function_call(fake_dgram_write); - expect_value(fake_dgram_write, buf, buf); - expect_value(fake_dgram_write, size, size); - will_return(fake_dgram_write, rc); -} - -static void expect_fake_dgram_sendmmsg(const BIO_MSG *m, size_t s, size_t n, - uint64_t f, size_t processed, int rc) -{ - expect_function_call(fake_dgram_sendmmsg); - expect_value(fake_dgram_sendmmsg, m, m); - expect_value(fake_dgram_sendmmsg, s, s); - expect_value(fake_dgram_sendmmsg, n, n); - expect_value(fake_dgram_sendmmsg, f, f); - will_return(fake_dgram_sendmmsg, processed); - will_return(fake_dgram_sendmmsg, rc); -} - -static void expect_fake_dgram_recvmmsg(const BIO_MSG *m, size_t s, size_t n, - uint64_t f, size_t processed, int rc) -{ - expect_function_call(fake_dgram_recvmmsg); - expect_value(fake_dgram_recvmmsg, m, m); - expect_value(fake_dgram_recvmmsg, s, s); - expect_value(fake_dgram_recvmmsg, n, n); - expect_value(fake_dgram_recvmmsg, f, f); - will_return(fake_dgram_recvmmsg, processed); - will_return(fake_dgram_recvmmsg, rc); -} - -/* helpers */ - -static BIO_CONNECT *get_data(BIO *bio) -{ - return (BIO_CONNECT *)bio->ptr; -} - -/* - * Call at the end of any test that sets bio->num or addr_first to prevent - * unexpected BIO_closesocket or BIO_ADDRINFO_free invocations in teardown. - */ -static void reset_for_teardown(BIO *bio) -{ - BIO_CONNECT *data = get_data(bio); - - bio->num = (int)INVALID_SOCKET; - data->addr_first = NULL; - data->addr_iter = NULL; - data->state = BIO_CONN_S_BEFORE; -} - -/* setup / teardown */ - -static int setup(void **state) -{ - BIO *bio = BIO_new(BIO_s_connect()); - - assert_non_null(bio); - *state = bio; - return 0; -} - -static int teardown(void **state) -{ - if (*state != NULL) - BIO_free(*state); - return 0; -} - -/* I/O tests pre-establish state=OK so the state machine is not entered. */ -static int setup_io(void **state) -{ - BIO *bio; - BIO_CONNECT *data; - - if (setup(state) != 0) - return -1; - bio = *state; - data = get_data(bio); - data->state = BIO_CONN_S_OK; - bio->num = FAKE_SOCKET; - bio->init = 1; - return 0; -} - -static int teardown_io(void **state) -{ - if (*state != NULL) - reset_for_teardown(*state); - return teardown(state); -} - -static int group_setup(void **state) -{ - (void)state; - - fake_dgram_method = make_fake_dgram_method(); - - memset(&g_sin, 0, sizeof(g_sin)); - g_sin.sin_family = AF_INET; - g_sin.sin_port = htons(443); - g_sin.sin_addr.s_addr = htonl(INADDR_LOOPBACK); - - memset(&g_addrinfo1, 0, sizeof(g_addrinfo1)); - g_addrinfo1.bai_family = AF_INET; - g_addrinfo1.bai_socktype = SOCK_STREAM; - g_addrinfo1.bai_protocol = IPPROTO_TCP; - g_addrinfo1.bai_addrlen = sizeof(g_sin); - g_addrinfo1.bai_addr = (struct sockaddr *)&g_sin; - g_addrinfo1.bai_next = NULL; - - memcpy(&g_addrinfo2, &g_addrinfo1, sizeof(g_addrinfo1)); - g_addrinfo2.bai_next = NULL; - - return 0; -} - -static int group_teardown(void **state) -{ - (void)state; - BIO_meth_free(fake_dgram_method); - fake_dgram_method = NULL; - return 0; -} - -/* conn_new */ - -static void test_conn_new(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - assert_non_null(data); - assert_int_equal(data->state, BIO_CONN_S_BEFORE); - assert_int_equal(data->connect_family, BIO_FAMILY_IPANY); - assert_int_equal(data->connect_sock_type, SOCK_STREAM); - assert_null(data->param_hostname); - assert_null(data->param_service); - assert_null(data->addr_first); - assert_null(data->dgram_bio); - assert_int_equal(bio->num, (int)INVALID_SOCKET); - assert_int_equal(bio->init, 0); -} - -/* conn_free */ - -static void test_conn_free_no_shutdown(void **state) -{ - /* shutdown=0: conn_close_socket and BIO_CONNECT_free are both skipped */ - BIO *bio = BIO_new(BIO_s_connect()); - - assert_non_null(bio); - bio->shutdown = BIO_NOCLOSE; - BIO_free(bio); - *state = NULL; -} - -/* conn_close_socket (via BIO_CTRL_RESET) */ - -static void test_close_socket_none(void **state) -{ - /* bio->num == INVALID_SOCKET: no calls expected */ - assert_int_equal(BIO_ctrl(*state, BIO_CTRL_RESET, 0, NULL), 0); -} - -static void test_close_socket_non_ok_state(void **state) -{ - /* Socket open but state != OK: BIO_closesocket called, no shutdown */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - bio->num = FAKE_SOCKET; - data->state = BIO_CONN_S_BLOCKED_CONNECT; - - expect_BIO_closesocket(FAKE_SOCKET, 0); - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_RESET, 0, NULL), 0); - assert_int_equal(bio->num, (int)INVALID_SOCKET); - assert_int_equal(data->state, BIO_CONN_S_BEFORE); -} - -static void test_close_socket_ok_state(void **state) -{ - /* Socket open and state=OK: shutdown first, then BIO_closesocket */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - bio->num = FAKE_SOCKET; - data->state = BIO_CONN_S_OK; - - expect_BIO_closesocket(FAKE_SOCKET, 0); - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_RESET, 0, NULL), 0); - assert_int_equal(bio->num, (int)INVALID_SOCKET); - assert_int_equal(data->state, BIO_CONN_S_BEFORE); -} - -/* conn_state (via BIO_C_DO_STATE_MACHINE) */ - -static void test_conn_state_no_hostname(void **state) -{ - /* BEFORE with no hostname and no service */ - assert_true(BIO_ctrl(*state, BIO_C_DO_STATE_MACHINE, 0, NULL) <= 0); -} - -static void test_conn_state_unsupported_family(void **state) -{ - /* BEFORE -> GET_ADDR -> unrecognised connect_family -> error */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - data->param_hostname = OPENSSL_strdup("host"); - data->param_service = OPENSSL_strdup("443"); - data->connect_family = 9999; - - assert_true(BIO_ctrl(bio, BIO_C_DO_STATE_MACHINE, 0, NULL) <= 0); -} - -static void test_conn_state_lookup_fails(void **state) -{ - /* BEFORE -> GET_ADDR -> BIO_lookup returns 0 */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - data->param_hostname = OPENSSL_strdup("host"); - data->param_service = OPENSSL_strdup("443"); - - expect_BIO_lookup(NULL, 0); - assert_true(BIO_ctrl(bio, BIO_C_DO_STATE_MACHINE, 0, NULL) <= 0); -} - -static void test_conn_state_socket_fails(void **state) -{ - /* Pre-set CREATE_SOCKET: BIO_socket returns INVALID_SOCKET */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - data->state = BIO_CONN_S_CREATE_SOCKET; - data->addr_iter = &g_addrinfo1; - - expect_BIO_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, - (int)INVALID_SOCKET); - assert_true(BIO_ctrl(bio, BIO_C_DO_STATE_MACHINE, 0, NULL) <= 0); - - data->addr_iter = NULL; - data->state = BIO_CONN_S_BEFORE; -} - -static void test_conn_state_connect_succeeds(void **state) -{ - /* Full happy path: BEFORE -> GET_ADDR -> CREATE_SOCKET -> CONNECT -> OK */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - data->param_hostname = OPENSSL_strdup("host"); - data->param_service = OPENSSL_strdup("443"); - - expect_BIO_lookup(&g_addrinfo1, 1); - expect_BIO_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, FAKE_SOCKET); - /* STREAM addrinfo adds KEEPALIVE to the default (zero) connect_mode */ - expect_BIO_connect(FAKE_SOCKET, (BIO_ADDR *)&g_sin, BIO_SOCK_KEEPALIVE, 1); - - assert_int_equal(BIO_ctrl(bio, BIO_C_DO_STATE_MACHINE, 0, NULL), 1); - assert_int_equal(data->state, BIO_CONN_S_OK); - - reset_for_teardown(bio); -} - -static void test_conn_state_already_ok(void **state) -{ - /* State already OK: returns 1 with no external calls */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - data->state = BIO_CONN_S_OK; - assert_int_equal(BIO_ctrl(bio, BIO_C_DO_STATE_MACHINE, 0, NULL), 1); - data->state = BIO_CONN_S_BEFORE; -} - -static void test_conn_state_connect_retry(void **state) -{ - /* Pre-set CONNECT: BIO_connect fails with retry -> BLOCKED_CONNECT */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - data->state = BIO_CONN_S_CONNECT; - data->addr_iter = &g_addrinfo1; - bio->num = FAKE_SOCKET; - - expect_BIO_connect(FAKE_SOCKET, (BIO_ADDR *)&g_sin, BIO_SOCK_KEEPALIVE, 0); - expect_BIO_sock_should_retry(0, 1); - - assert_int_equal(BIO_ctrl(bio, BIO_C_DO_STATE_MACHINE, 0, NULL), 0); - assert_int_equal(data->state, BIO_CONN_S_BLOCKED_CONNECT); - assert_int_equal(bio->retry_reason, BIO_RR_CONNECT); - - reset_for_teardown(bio); -} - -static void test_conn_state_connect_error(void **state) -{ - /* Pre-set CONNECT: fails, no retry, no more addresses -> CONNECT_ERROR */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - data->state = BIO_CONN_S_CONNECT; - data->addr_iter = &g_addrinfo1; /* bai_next == NULL */ - bio->num = FAKE_SOCKET; - - expect_BIO_connect(FAKE_SOCKET, (BIO_ADDR *)&g_sin, BIO_SOCK_KEEPALIVE, 0); - expect_BIO_sock_should_retry(0, 0); - /* loop continues to CONNECT_ERROR which exits immediately */ - - assert_int_equal(BIO_ctrl(bio, BIO_C_DO_STATE_MACHINE, 0, NULL), 0); - - reset_for_teardown(bio); -} - -static void test_conn_state_connect_next_addr(void **state) -{ - /* - * Pre-set CONNECT with two addresses: first connect fails, iterator - * advances, second CREATE_SOCKET fails so we get a clean exit. - */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - g_addrinfo1.bai_next = &g_addrinfo2; - data->state = BIO_CONN_S_CONNECT; - data->addr_iter = &g_addrinfo1; - bio->num = FAKE_SOCKET; - - expect_BIO_connect(FAKE_SOCKET, (BIO_ADDR *)&g_sin, BIO_SOCK_KEEPALIVE, 0); - expect_BIO_sock_should_retry(0, 0); - expect_BIO_closesocket(FAKE_SOCKET, 0); - /* CREATE_SOCKET for g_addrinfo2 */ - expect_BIO_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, - (int)INVALID_SOCKET); - - assert_true(BIO_ctrl(bio, BIO_C_DO_STATE_MACHINE, 0, NULL) <= 0); - - g_addrinfo1.bai_next = NULL; - reset_for_teardown(bio); -} - -static void test_conn_state_blocked_ok(void **state) -{ - /* Pre-set BLOCKED_CONNECT: socket becomes writable, no error -> OK */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - data->state = BIO_CONN_S_BLOCKED_CONNECT; - data->addr_iter = &g_addrinfo1; - bio->num = FAKE_SOCKET; - - expect_BIO_socket_wait(FAKE_SOCKET, 0, 1); - expect_BIO_sock_error(FAKE_SOCKET, 0); - - assert_int_equal(BIO_ctrl(bio, BIO_C_DO_STATE_MACHINE, 0, NULL), 1); - assert_int_equal(data->state, BIO_CONN_S_OK); - - reset_for_teardown(bio); -} - -static void test_conn_state_blocked_error(void **state) -{ - /* Pre-set BLOCKED_CONNECT: socket error, no more addresses -> error */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - data->state = BIO_CONN_S_BLOCKED_CONNECT; - data->addr_iter = &g_addrinfo1; /* bai_next == NULL */ - bio->num = FAKE_SOCKET; - - expect_BIO_socket_wait(FAKE_SOCKET, 0, 1); - expect_BIO_sock_error(FAKE_SOCKET, ECONNREFUSED); - - assert_int_equal(BIO_ctrl(bio, BIO_C_DO_STATE_MACHINE, 0, NULL), 0); - - reset_for_teardown(bio); -} - -#ifndef OPENSSL_NO_DGRAM -static void test_conn_state_connect_dgram_ok(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - data->connect_sock_type = SOCK_DGRAM; - data->state = BIO_CONN_S_CONNECT; - data->addr_iter = &g_addrinfo1; - bio->num = FAKE_SOCKET; - - /* DGRAM addrinfo means opts stays at the default connect_mode (0) */ - g_addrinfo1.bai_socktype = SOCK_DGRAM; - - expect_BIO_connect(FAKE_SOCKET, (BIO_ADDR *)&g_sin, 0, 1); - - assert_int_equal(BIO_ctrl(bio, BIO_C_DO_STATE_MACHINE, 0, NULL), 1); - assert_int_equal(data->state, BIO_CONN_S_OK); - assert_non_null(data->dgram_bio); - - g_addrinfo1.bai_socktype = SOCK_STREAM; - - assert_int_equal(BIO_set_close(data->dgram_bio, BIO_NOCLOSE), 1); - BIO_free(data->dgram_bio); - data->dgram_bio = NULL; - reset_for_teardown(bio); -} -#endif - -/* conn_read */ - -static void test_conn_read_success(void **state) -{ - BIO *bio = *state; - char buf[8] = { 0 }; - - expect_read(FAKE_SOCKET, buf, 8, 8); - assert_int_equal(BIO_read(bio, buf, 8), 8); - assert_false(BIO_should_retry(bio)); - assert_false(BIO_eof(bio)); -} - -static void test_conn_read_eof(void **state) -{ - BIO *bio = *state; - char buf[8] = { 0 }; - - expect_read(FAKE_SOCKET, buf, 8, 0); - expect_BIO_sock_should_retry(0, 0); - assert_true(BIO_read(bio, buf, 8) <= 0); - assert_true(BIO_eof(bio)); -} - -static void test_conn_read_retry(void **state) -{ - BIO *bio = *state; - char buf[8] = { 0 }; - - expect_read(FAKE_SOCKET, buf, 8, -1); - expect_BIO_sock_should_retry(-1, 1); - assert_true(BIO_read(bio, buf, 8) <= 0); - assert_true(BIO_should_read(bio)); -} - -static void test_conn_read_error(void **state) -{ - BIO *bio = *state; - char buf[8] = { 0 }; - - expect_read(FAKE_SOCKET, buf, 8, -1); - expect_BIO_sock_should_retry(-1, 0); - assert_true(BIO_read(bio, buf, 8) <= 0); - assert_false(BIO_should_retry(bio)); - assert_false(BIO_eof(bio)); -} - -static void test_conn_read_enters_state_machine(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - char buf[8] = { 0 }; - - data->param_hostname = OPENSSL_strdup("host"); - data->param_service = OPENSSL_strdup("443"); - bio->init = 1; - - expect_BIO_lookup(&g_addrinfo1, 1); - expect_BIO_socket(AF_INET, SOCK_STREAM, IPPROTO_TCP, 0, FAKE_SOCKET); - expect_BIO_connect(FAKE_SOCKET, (BIO_ADDR *)&g_sin, BIO_SOCK_KEEPALIVE, 1); - expect_read(FAKE_SOCKET, buf, 8, 8); - - assert_int_equal(BIO_read(bio, buf, 8), 8); - assert_int_equal(data->state, BIO_CONN_S_OK); - - reset_for_teardown(bio); -} - -static void test_conn_read_state_machine_fails(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - char buf[8] = { 0 }; - - data->param_hostname = OPENSSL_strdup("host"); - data->param_service = OPENSSL_strdup("443"); - bio->init = 1; - - expect_BIO_lookup(NULL, 0); /* conn_state <= 0, no socket touched */ - - assert_true(BIO_read(bio, buf, 8) <= 0); - - reset_for_teardown(bio); -} - -static void test_conn_read_dgram_delegates(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - BIO *dg = make_fake_dgram(); - char buf[8] = { 0 }; - - data->dgram_bio = dg; - - expect_fake_dgram_read(buf, 8, 4); - assert_int_equal(BIO_read(bio, buf, 8), 4); - - data->dgram_bio = NULL; - BIO_free(dg); -} - -/* conn_write */ - -static void test_conn_write_success(void **state) -{ - BIO *bio = *state; - const char buf[] = "hello"; - - expect_write(FAKE_SOCKET, buf, 5, 5); - assert_int_equal(BIO_write(bio, buf, 5), 5); - assert_false(BIO_should_retry(bio)); -} - -static void test_conn_write_retry(void **state) -{ - BIO *bio = *state; - const char buf[] = "hello"; - - expect_write(FAKE_SOCKET, buf, 5, -1); - expect_BIO_sock_should_retry(-1, 1); - assert_true(BIO_write(bio, buf, 5) <= 0); - assert_true(BIO_should_write(bio)); -} - -static void test_conn_write_error(void **state) -{ - BIO *bio = *state; - const char buf[] = "hello"; - - expect_write(FAKE_SOCKET, buf, 5, -1); - expect_BIO_sock_should_retry(-1, 0); - assert_true(BIO_write(bio, buf, 5) <= 0); - assert_false(BIO_should_retry(bio)); -} - -static void test_conn_write_dgram_delegates(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - BIO *dg = make_fake_dgram(); - const char buf[] = "hello"; - - data->dgram_bio = dg; - - expect_fake_dgram_write(buf, 5, 5); - assert_int_equal(BIO_write(bio, buf, 5), 5); - - data->dgram_bio = NULL; - BIO_free(dg); -} - -/* conn_gets - * - * conn_gets is non-static (unlike the other method functions) so it is a - * public symbol, but we exercise it via BIO_gets to stay in-interface. - */ - -static void test_conn_gets_null_buf(void **state) -{ - assert_true(BIO_gets(*state, NULL, 8) <= 0); -} - -static void test_conn_gets_zero_size(void **state) -{ - char buf[8] = { 0 }; - - assert_true(BIO_gets(*state, buf, 0) <= 0); -} - -static void test_conn_gets_null_ptr(void **state) -{ - /* bio->ptr == NULL is caught before any field access */ - BIO *bio = *state; - char buf[8] = { 0 }; - void *saved = bio->ptr; - - bio->ptr = NULL; - assert_true(BIO_gets(bio, buf, sizeof(buf)) <= 0); - bio->ptr = saved; -} - -static void test_conn_gets_dgram_bio_set(void **state) -{ - /* dgram_bio present is an error for gets */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - char buf[8] = { 0 }; - BIO fake_dgram; - - data->dgram_bio = &fake_dgram; - assert_int_equal(BIO_gets(bio, buf, sizeof(buf)), -1); - data->dgram_bio = NULL; -} - -static void test_conn_gets_newline(void **state) -{ - BIO *bio = *state; - char buf[8] = { 'h', 'i', '\n' }; - - expect_read(FAKE_SOCKET, buf, 1, 1); - expect_read(FAKE_SOCKET, buf + 1, 1, 1); - expect_read(FAKE_SOCKET, buf + 2, 1, 1); - - assert_int_equal(BIO_gets(bio, buf, sizeof(buf)), 3); -} - -static void test_conn_gets_fills_buffer(void **state) -{ - /* size=4 allows at most 3 chars before the terminating NUL */ - BIO *bio = *state; - char buf[4] = { 'a', 'b', 'c' }; - - expect_read(FAKE_SOCKET, buf, 1, 1); - expect_read(FAKE_SOCKET, buf + 1, 1, 1); - expect_read(FAKE_SOCKET, buf + 2, 1, 1); - - assert_int_equal(BIO_gets(bio, buf, 4), 3); -} - -static void test_conn_gets_eof_mid(void **state) -{ - /* One char read, then EOF: returns the char count */ - BIO *bio = *state; - char buf[8] = { 'z' }; - - expect_read(FAKE_SOCKET, buf, 1, 1); - expect_read(FAKE_SOCKET, buf + 1, 1, 0); - expect_BIO_sock_should_retry(0, 0); - - assert_int_equal(BIO_gets(bio, buf, sizeof(buf)), 1); -} - -static void test_conn_gets_immediate_eof(void **state) -{ - /* First read returns 0: EOF flag set, returns 0 */ - BIO *bio = *state; - char buf[8] = { 0 }; - - expect_read(FAKE_SOCKET, buf, 1, 0); - expect_BIO_sock_should_retry(0, 0); - - assert_int_equal(BIO_gets(bio, buf, sizeof(buf)), 0); - assert_int_equal(buf[0], '\0'); -} - -static void test_conn_gets_retry(void **state) -{ - BIO *bio = *state; - char buf[8] = { 0 }; - - expect_read(FAKE_SOCKET, buf, 1, -1); - expect_BIO_sock_should_retry(-1, 1); - - assert_int_equal(BIO_gets(bio, buf, sizeof(buf)), -1); - assert_true(BIO_should_retry(bio)); -} - -/* conn_puts */ - -static void test_conn_puts_success(void **state) -{ - BIO *bio = *state; - const char *str = "hello"; - - expect_write(FAKE_SOCKET, str, 5, 5); - assert_int_equal(BIO_puts(bio, str), 5); -} - -static void test_conn_puts_write_fails(void **state) -{ - BIO *bio = *state; - const char *str = "hello"; - - expect_write(FAKE_SOCKET, str, 5, -1); - expect_BIO_sock_should_retry(-1, 0); - assert_true(BIO_puts(bio, str) <= 0); -} - -/* conn_ctrl */ - -static void test_conn_ctrl_reset_no_socket(void **state) -{ - /* INVALID_SOCKET -> conn_close_socket is a no-op */ - assert_int_equal(BIO_ctrl(*state, BIO_CTRL_RESET, 0, NULL), 0); - assert_int_equal(get_data(*state)->state, BIO_CONN_S_BEFORE); -} - -static void test_conn_ctrl_reset_clears_addrs(void **state) -{ - /* RESET also nulls the iterators and clears flags */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - data->addr_first = NULL; /* keep BIO_ADDRINFO_free a no-op */ - data->addr_iter = &g_addrinfo1; - bio->flags = BIO_FLAGS_IN_EOF; - bio->num = (int)INVALID_SOCKET; - - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_RESET, 0, NULL), 0); - assert_null(data->addr_first); - assert_null(data->addr_iter); - assert_int_equal(bio->flags, 0); - assert_int_equal(data->state, BIO_CONN_S_BEFORE); -} - -static void test_conn_ctrl_get_connect(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - const char *out = NULL; - - /* NULL ptr always returns 0 regardless of num */ - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_CONNECT, 0, NULL), 0); - - data->param_hostname = OPENSSL_strdup("host.example"); - data->param_service = OPENSSL_strdup("443"); - data->connect_mode = BIO_SOCK_KEEPALIVE; - - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_CONNECT, 0, &out), 1); - assert_string_equal(out, "host.example"); - - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_CONNECT, 1, &out), 1); - assert_string_equal(out, "443"); - - /* num==4: connect_mode; ptr just needs to be non-NULL */ - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_CONNECT, 4, &out), - BIO_SOCK_KEEPALIVE); - - /* unknown num with non-NULL ptr -> 0 */ - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_CONNECT, 99, &out), 0); -} - -static void test_conn_ctrl_get_connect_address(void **state) -{ - /* num==2: address pointer from addr_iter */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - const char *out = NULL; - - data->addr_iter = &g_addrinfo1; - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_CONNECT, 2, &out), 1); - assert_non_null(out); - data->addr_iter = NULL; -} - -static void test_conn_ctrl_get_connect_family(void **state) -{ - /* num==3: AF_INET addr_iter maps to BIO_FAMILY_IPV4 */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - const char *out = NULL; - - data->addr_iter = &g_addrinfo1; - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_CONNECT, 3, &out), - BIO_FAMILY_IPV4); - data->addr_iter = NULL; -} - -static void test_conn_ctrl_set_connect_null_ptr(void **state) -{ - /* ptr == NULL: no-op, init left untouched */ - BIO *bio = *state; - - assert_int_equal(bio->init, 0); - assert_int_equal(BIO_ctrl(bio, BIO_C_SET_CONNECT, 0, NULL), 1); - assert_int_equal(bio->init, 0); -} - -static void test_conn_ctrl_set_connect_hostname(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - assert_int_equal(BIO_ctrl(bio, BIO_C_SET_CONNECT, 0, "host.example:443"), - 1); - assert_int_equal(bio->init, 1); - assert_string_equal(data->param_hostname, "host.example"); - assert_string_equal(data->param_service, "443"); -} - -static void test_conn_ctrl_set_connect_port(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - assert_int_equal(BIO_ctrl(bio, BIO_C_SET_CONNECT, 1, "8443"), 1); - assert_string_equal(data->param_service, "8443"); -} - -static void test_conn_ctrl_set_connect_address(void **state) -{ - /* num==2: derive host/service from a BIO_ADDR */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - BIO_ADDR *addr = BIO_ADDR_new(); - - assert_non_null(addr); - assert_true(BIO_ADDR_rawmake(addr, AF_INET, &g_sin.sin_addr, - sizeof(g_sin.sin_addr), g_sin.sin_port)); - - assert_int_equal(BIO_ctrl(bio, BIO_C_SET_CONNECT, 2, addr), 1); - assert_non_null(data->param_hostname); - assert_non_null(data->param_service); - assert_null(data->addr_first); - - BIO_ADDR_free(addr); -} - -static void test_conn_ctrl_set_connect_family(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - int family = BIO_FAMILY_IPV4; - - assert_int_equal(BIO_ctrl(bio, BIO_C_SET_CONNECT, 3, &family), 1); - assert_int_equal(data->connect_family, BIO_FAMILY_IPV4); -} - -static void test_conn_ctrl_set_sock_type(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - assert_int_equal(BIO_ctrl(bio, BIO_C_SET_SOCK_TYPE, SOCK_DGRAM, NULL), 1); - assert_int_equal(data->connect_sock_type, SOCK_DGRAM); - - assert_int_equal(BIO_ctrl(bio, BIO_C_SET_SOCK_TYPE, SOCK_STREAM, NULL), 1); - assert_int_equal(data->connect_sock_type, SOCK_STREAM); - - /* Invalid socktype */ - assert_int_equal(BIO_ctrl(bio, BIO_C_SET_SOCK_TYPE, 9999, NULL), 0); - - /* Too late once past BEFORE */ - data->state = BIO_CONN_S_GET_ADDR; - assert_int_equal(BIO_ctrl(bio, BIO_C_SET_SOCK_TYPE, SOCK_DGRAM, NULL), 0); - data->state = BIO_CONN_S_BEFORE; -} - -static void test_conn_ctrl_get_sock_type(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - data->connect_sock_type = SOCK_DGRAM; - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_SOCK_TYPE, 0, NULL), SOCK_DGRAM); - data->connect_sock_type = SOCK_STREAM; -} - -static void test_conn_ctrl_get_dgram_bio(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - BIO *out = NULL; - BIO fake_dgram; - - /* dgram_bio NULL -> 0 */ - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_DGRAM_BIO, 0, &out), 0); - - data->dgram_bio = &fake_dgram; - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_DGRAM_BIO, 0, &out), 1); - assert_ptr_equal(out, &fake_dgram); - data->dgram_bio = NULL; -} - -static void test_conn_ctrl_nbio(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - BIO_ctrl(bio, BIO_C_SET_NBIO, 1, NULL); - assert_true(data->connect_mode & BIO_SOCK_NONBLOCK); - - BIO_ctrl(bio, BIO_C_SET_NBIO, 0, NULL); - assert_false(data->connect_mode & BIO_SOCK_NONBLOCK); -} - -static void test_conn_ctrl_nbio_dgram(void **state) -{ - /* with a dgram_bio attached the mode flips and the call delegates */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - BIO *dg = make_fake_dgram(); - - data->dgram_bio = dg; - BIO_ctrl(bio, BIO_C_SET_NBIO, 1, NULL); - assert_true(data->connect_mode & BIO_SOCK_NONBLOCK); - - data->dgram_bio = NULL; - BIO_free(dg); -} - -static void test_conn_ctrl_connect_mode(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - - BIO_ctrl(bio, BIO_C_SET_CONNECT_MODE, BIO_SOCK_KEEPALIVE, NULL); - assert_int_equal(data->connect_mode, BIO_SOCK_KEEPALIVE); - assert_int_equal(data->tfo_first, 0); -} - -static void test_conn_ctrl_get_fd(void **state) -{ - BIO *bio = *state; - int fd = -1; - - /* init==0 -> -1 */ - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_FD, 0, &fd), -1); - - bio->init = 1; - bio->num = FAKE_SOCKET; - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_FD, 0, &fd), FAKE_SOCKET); - assert_int_equal(fd, FAKE_SOCKET); - - bio->init = 0; - bio->num = (int)INVALID_SOCKET; -} - -static void test_conn_ctrl_get_set_close(void **state) -{ - BIO *bio = *state; - - bio->shutdown = BIO_NOCLOSE; - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_GET_CLOSE, 0, NULL), BIO_NOCLOSE); - - BIO_ctrl(bio, BIO_CTRL_SET_CLOSE, BIO_CLOSE, NULL); - assert_int_equal(bio->shutdown, BIO_CLOSE); -} - -static void test_conn_ctrl_pending_flush(void **state) -{ - BIO *bio = *state; - - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_PENDING, 0, NULL), 0); - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_WPENDING, 0, NULL), 0); - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_FLUSH, 0, NULL), 1); -} - -static void test_conn_ctrl_eof(void **state) -{ - BIO *bio = *state; - - bio->flags &= ~BIO_FLAGS_IN_EOF; - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_EOF, 0, NULL), 0); - - bio->flags |= BIO_FLAGS_IN_EOF; - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_EOF, 0, NULL), 1); - bio->flags &= ~BIO_FLAGS_IN_EOF; -} - -static void test_conn_ctrl_set_callback_defers(void **state) -{ - /* BIO_CTRL_SET_CALLBACK via conn_ctrl returns 0 (use callback ctrl) */ - BIO *bio = *state; - - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_SET_CALLBACK, 0, NULL), 0); -} - -static void test_conn_ctrl_default(void **state) -{ - assert_int_equal(BIO_ctrl(*state, 9999, 0, NULL), 0); -} - -/* conn_callback_ctrl */ - -static int dummy_cb(BIO *b, int s, int res) -{ - (void)b; - (void)s; - return res; -} - -static void test_conn_ctrl_get_callback(void **state) -{ - /* BIO_CTRL_GET_CALLBACK returns the stored info_callback */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - BIO_info_cb *fp = NULL; - - data->info_callback = dummy_cb; - BIO_ctrl(bio, BIO_CTRL_GET_CALLBACK, 0, &fp); - assert_ptr_equal(fp, dummy_cb); - data->info_callback = NULL; -} - -static void test_conn_callback_ctrl_set(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - BIO_info_cb *retrieved; - - assert_int_equal(BIO_set_info_callback(bio, dummy_cb), 1); - assert_ptr_equal(data->info_callback, dummy_cb); - - assert_int_equal(BIO_get_info_callback(bio, &retrieved), 1); - assert_ptr_equal(retrieved, dummy_cb); - - assert_int_equal(BIO_set_info_callback(bio, NULL), 1); -} - -static void test_conn_callback_ctrl_default(void **state) -{ - assert_int_equal(BIO_callback_ctrl(*state, BIO_CTRL_SET_CALLBACK, dummy_cb), 1); -} - -static void test_conn_callback_ctrl_invalid(void **state) -{ - /* If cmd different than BIO_CTRL_SET_CALLBACK, return -2. */ - assert_int_equal(BIO_callback_ctrl(*state, 9999, dummy_cb), -2); -} - -/* conn_sendmmsg / conn_recvmmsg */ - -static void test_conn_sendmmsg_no_dgram(void **state) -{ - /* State OK, dgram_bio NULL -> error */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - BIO_MSG msg = { 0 }; - size_t processed = 1; - - data->state = BIO_CONN_S_OK; - bio->num = FAKE_SOCKET; - - assert_int_equal( - BIO_sendmmsg(bio, &msg, sizeof(msg), 1, 0, &processed), 0); - assert_int_equal(processed, 0); - - reset_for_teardown(bio); -} - -static void test_conn_sendmmsg_state_fails(void **state) -{ - /* state != OK and conn_state fails -> 0, processed zeroed */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - BIO_MSG msg = { 0 }; - size_t processed = 5; - - data->param_hostname = OPENSSL_strdup("host"); - data->param_service = OPENSSL_strdup("443"); - bio->init = 1; /* BIO_sendmmsg rejects !init before dispatch */ - - expect_BIO_lookup(NULL, 0); - - assert_int_equal( - BIO_sendmmsg(bio, &msg, sizeof(msg), 1, 0, &processed), 0); - assert_int_equal(processed, 0); - - reset_for_teardown(bio); -} - -static void test_conn_sendmmsg_dgram_delegates(void **state) -{ - /* state OK with dgram_bio -> delegates to BIO_sendmmsg on it */ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - BIO *dg = make_fake_dgram(); - BIO_MSG msg = { 0 }; - size_t processed = 0; - - data->dgram_bio = dg; - - expect_fake_dgram_sendmmsg(&msg, sizeof(msg), 1, 0, 1, 1); - - assert_int_equal( - BIO_sendmmsg(bio, &msg, sizeof(msg), 1, 0, &processed), 1); - assert_int_equal(processed, 1); - - data->dgram_bio = NULL; - BIO_free(dg); - reset_for_teardown(bio); -} - -static void test_conn_recvmmsg_no_dgram(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - BIO_MSG msg = { 0 }; - size_t processed = 1; - - data->state = BIO_CONN_S_OK; - bio->num = FAKE_SOCKET; - - assert_int_equal( - BIO_recvmmsg(bio, &msg, sizeof(msg), 1, 0, &processed), 0); - assert_int_equal(processed, 0); - - reset_for_teardown(bio); -} - -static void test_conn_recvmmsg_state_fails(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - BIO_MSG msg = { 0 }; - size_t processed = 5; - - data->param_hostname = OPENSSL_strdup("host"); - data->param_service = OPENSSL_strdup("443"); - bio->init = 1; - - expect_BIO_lookup(NULL, 0); - - assert_int_equal( - BIO_recvmmsg(bio, &msg, sizeof(msg), 1, 0, &processed), 0); - assert_int_equal(processed, 0); - - reset_for_teardown(bio); -} - -static void test_conn_recvmmsg_dgram_delegates(void **state) -{ - BIO *bio = *state; - BIO_CONNECT *data = get_data(bio); - BIO *dg = make_fake_dgram(); - BIO_MSG msg = { 0 }; - size_t processed = 0; - - data->dgram_bio = dg; - - expect_fake_dgram_recvmmsg(&msg, sizeof(msg), 1, 0, 1, 1); - - assert_int_equal( - BIO_recvmmsg(bio, &msg, sizeof(msg), 1, 0, &processed), 1); - assert_int_equal(processed, 1); - - data->dgram_bio = NULL; - BIO_free(dg); - reset_for_teardown(bio); -} - -/* main */ - -#define CONN_TEST(name) \ - cmocka_unit_test_setup_teardown(name, setup, teardown) - -#define CONN_TEST_IO(name) \ - cmocka_unit_test_setup_teardown(name, setup_io, teardown_io) - -int main(void) -{ - const struct CMUnitTest tests[] = { - /* conn_new */ - CONN_TEST(test_conn_new), - /* conn_free */ - CONN_TEST(test_conn_free_no_shutdown), - /* conn_close_socket */ - CONN_TEST(test_close_socket_none), - CONN_TEST(test_close_socket_non_ok_state), - CONN_TEST(test_close_socket_ok_state), - /* conn_state */ - CONN_TEST(test_conn_state_no_hostname), - CONN_TEST(test_conn_state_unsupported_family), - CONN_TEST(test_conn_state_lookup_fails), - CONN_TEST(test_conn_state_socket_fails), - CONN_TEST(test_conn_state_connect_succeeds), - CONN_TEST(test_conn_state_already_ok), - CONN_TEST(test_conn_state_connect_retry), - CONN_TEST(test_conn_state_connect_error), - CONN_TEST(test_conn_state_connect_next_addr), - CONN_TEST(test_conn_state_blocked_ok), - CONN_TEST(test_conn_state_blocked_error), -#ifndef OPENSSL_NO_DGRAM - CONN_TEST(test_conn_state_connect_dgram_ok), -#endif - /* conn_read */ - CONN_TEST_IO(test_conn_read_success), - CONN_TEST_IO(test_conn_read_eof), - CONN_TEST_IO(test_conn_read_retry), - CONN_TEST_IO(test_conn_read_error), - CONN_TEST(test_conn_read_enters_state_machine), - CONN_TEST(test_conn_read_state_machine_fails), - CONN_TEST_IO(test_conn_read_dgram_delegates), - /* conn_write */ - CONN_TEST_IO(test_conn_write_success), - CONN_TEST_IO(test_conn_write_retry), - CONN_TEST_IO(test_conn_write_error), - CONN_TEST_IO(test_conn_write_dgram_delegates), - /* conn_gets */ - CONN_TEST(test_conn_gets_null_buf), - CONN_TEST(test_conn_gets_zero_size), - CONN_TEST(test_conn_gets_null_ptr), - CONN_TEST_IO(test_conn_gets_dgram_bio_set), - CONN_TEST_IO(test_conn_gets_newline), - CONN_TEST_IO(test_conn_gets_fills_buffer), - CONN_TEST_IO(test_conn_gets_eof_mid), - CONN_TEST_IO(test_conn_gets_immediate_eof), - CONN_TEST_IO(test_conn_gets_retry), - /* conn_puts */ - CONN_TEST_IO(test_conn_puts_success), - CONN_TEST_IO(test_conn_puts_write_fails), - /* conn_ctrl */ - CONN_TEST(test_conn_ctrl_reset_no_socket), - CONN_TEST(test_conn_ctrl_reset_clears_addrs), - CONN_TEST(test_conn_ctrl_get_connect), - CONN_TEST(test_conn_ctrl_get_connect_address), - CONN_TEST(test_conn_ctrl_get_connect_family), - CONN_TEST(test_conn_ctrl_set_connect_null_ptr), - CONN_TEST(test_conn_ctrl_set_connect_hostname), - CONN_TEST(test_conn_ctrl_set_connect_port), - CONN_TEST(test_conn_ctrl_set_connect_address), - CONN_TEST(test_conn_ctrl_set_connect_family), - CONN_TEST(test_conn_ctrl_set_sock_type), - CONN_TEST(test_conn_ctrl_get_sock_type), - CONN_TEST(test_conn_ctrl_get_dgram_bio), - CONN_TEST(test_conn_ctrl_nbio), - CONN_TEST_IO(test_conn_ctrl_nbio_dgram), - CONN_TEST(test_conn_ctrl_connect_mode), - CONN_TEST(test_conn_ctrl_get_fd), - CONN_TEST(test_conn_ctrl_get_set_close), - CONN_TEST(test_conn_ctrl_pending_flush), - CONN_TEST(test_conn_ctrl_eof), - CONN_TEST(test_conn_ctrl_set_callback_defers), - CONN_TEST(test_conn_ctrl_default), - /* conn_callback_ctrl */ - CONN_TEST(test_conn_ctrl_get_callback), - CONN_TEST(test_conn_callback_ctrl_set), - CONN_TEST(test_conn_callback_ctrl_default), - CONN_TEST(test_conn_callback_ctrl_invalid), - /* conn_sendmmsg / conn_recvmmsg */ - CONN_TEST(test_conn_sendmmsg_no_dgram), - CONN_TEST(test_conn_sendmmsg_state_fails), - CONN_TEST_IO(test_conn_sendmmsg_dgram_delegates), - CONN_TEST(test_conn_recvmmsg_no_dgram), - CONN_TEST(test_conn_recvmmsg_state_fails), - CONN_TEST_IO(test_conn_recvmmsg_dgram_delegates), - }; - - cmocka_set_message_output(CM_OUTPUT_TAP); - - return cmocka_run_group_tests(tests, group_setup, group_teardown); -} - -#else - -int main(void) -{ - return 0; -} - -#endif /* OPENSSL_NO_SOCK */ diff --git a/test/unit/crypto/bio/test_bss_dgram.c b/test/unit/crypto/bio/test_bss_dgram.c deleted file mode 100644 index 4a39ebba5d..0000000000 --- a/test/unit/crypto/bio/test_bss_dgram.c +++ /dev/null @@ -1,772 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#if defined(OPENSSL_NO_SOCK) || defined(OPENSSL_NO_DGRAM) - -int main(void) -{ - return 0; -} - -#else - -#include -#include -#include -#include -#include -#include -#include -#include "bio_local.h" -#include - -#define FAKE_SOCKET 42 - -/* prototypes for __wrap_* (required by -Wmissing-prototypes) */ -ssize_t __wrap_recvfrom(int fd, void *buf, size_t len, int flags, - struct sockaddr *src, socklen_t *slen); -ssize_t __wrap_sendto(int fd, const void *buf, size_t len, int flags, - const struct sockaddr *dst, socklen_t slen); -ssize_t __wrap_write(int fd, const void *buf, size_t count); -int __wrap_getsockname(int fd, struct sockaddr *addr, socklen_t *slen); -int __wrap_getpeername(int fd, struct sockaddr *addr, socklen_t *slen); -int __wrap_BIO_closesocket(int fd); -int __wrap_BIO_socket_nbio(int fd, int mode); - -/* - * Shared sockaddrs handed back by the address-returning mocks. group_setup - * fills g_sin (AF_INET loopback); g_sin6 is an AF_INET6 loopback and - * g_sin6_v4m an IPv4-mapped IPv6 address (::ffff:127.0.0.1). - */ -static struct sockaddr_in g_sin; -static struct sockaddr_in6 g_sin6; -static struct sockaddr_in6 g_sin6_v4m; - -/* wraps */ - -ssize_t __wrap_recvfrom(int fd, void *buf, size_t len, int flags, - struct sockaddr *src, socklen_t *slen) -{ - ssize_t rc; - - function_called(); - check_expected(fd); - check_expected_ptr(buf); - check_expected(len); - check_expected(flags); - rc = mock_type(ssize_t); - if (rc >= 0 && src != NULL && slen != NULL) { - const struct sockaddr *sa = mock_ptr_type(const struct sockaddr *); - - if (sa != NULL && *slen >= sizeof(g_sin)) { - memcpy(src, sa, sizeof(g_sin)); - *slen = sizeof(g_sin); - } - } - if (rc < 0) - errno = mock_type(int); - return rc; -} - -ssize_t __wrap_sendto(int fd, const void *buf, size_t len, int flags, - const struct sockaddr *dst, socklen_t slen) -{ - ssize_t rc; - - function_called(); - check_expected(fd); - check_expected_ptr(buf); - check_expected(len); - check_expected(flags); - check_expected(slen); - (void)dst; - rc = mock_type(ssize_t); - if (rc < 0) - errno = mock_type(int); - return rc; -} - -ssize_t __wrap_write(int fd, const void *buf, size_t count) -{ - function_called(); - check_expected(fd); - check_expected_ptr(buf); - check_expected(count); - return mock_type(ssize_t); -} - -int __wrap_getsockname(int fd, struct sockaddr *addr, socklen_t *slen) -{ - int rc; - - function_called(); - check_expected(fd); - rc = mock_type(int); - if (rc == 0 && addr != NULL && slen != NULL) { - const struct sockaddr *sa = mock_ptr_type(const struct sockaddr *); - socklen_t sl = (socklen_t)mock_type(int); - - if (sa != NULL && *slen >= sl) { - memcpy(addr, sa, sl); - *slen = sl; - } - } - return rc; -} - -int __wrap_getpeername(int fd, struct sockaddr *addr, socklen_t *slen) -{ - int rc; - - function_called(); - check_expected(fd); - rc = mock_type(int); - if (rc == 0 && addr != NULL && slen != NULL && *slen >= sizeof(g_sin)) { - memcpy(addr, &g_sin, sizeof(g_sin)); - *slen = sizeof(g_sin); - } - return rc; -} - -int __wrap_BIO_closesocket(int fd) -{ - function_called(); - check_expected(fd); - return mock_type(int); -} - -int __wrap_BIO_socket_nbio(int fd, int mode) -{ - function_called(); - check_expected(fd); - check_expected(mode); - return mock_type(int); -} - -/* expectations */ - -static void expect_recvfrom(int fd, const void *buf, size_t len, int flags, - ssize_t rc, const struct sockaddr *src, int errnoval) -{ - expect_function_call(__wrap_recvfrom); - expect_value(__wrap_recvfrom, fd, fd); - expect_value(__wrap_recvfrom, buf, buf); - expect_value(__wrap_recvfrom, len, len); - expect_value(__wrap_recvfrom, flags, flags); - will_return(__wrap_recvfrom, rc); - if (rc >= 0) - will_return(__wrap_recvfrom, src); - else - will_return(__wrap_recvfrom, errnoval); -} - -static void expect_sendto(int fd, const void *buf, size_t len, int flags, - socklen_t slen, ssize_t rc, int errnoval) -{ - expect_function_call(__wrap_sendto); - expect_value(__wrap_sendto, fd, fd); - expect_value(__wrap_sendto, buf, buf); - expect_value(__wrap_sendto, len, len); - expect_value(__wrap_sendto, flags, flags); - expect_value(__wrap_sendto, slen, slen); - will_return(__wrap_sendto, rc); - if (rc < 0) - will_return(__wrap_sendto, errnoval); -} - -static void expect_write(int fd, const void *buf, size_t count, ssize_t rc) -{ - expect_function_call(__wrap_write); - expect_value(__wrap_write, fd, fd); - expect_value(__wrap_write, buf, buf); - expect_value(__wrap_write, count, count); - will_return(__wrap_write, rc); -} - -static void expect_getsockname(int fd, int rc) -{ - expect_function_call(__wrap_getsockname); - expect_value(__wrap_getsockname, fd, fd); - will_return(__wrap_getsockname, rc); - if (rc == 0) { - will_return(__wrap_getsockname, (const struct sockaddr *)&g_sin); - will_return(__wrap_getsockname, (int)sizeof(g_sin)); - } -} - -static void expect_getpeername(int fd, int rc) -{ - expect_function_call(__wrap_getpeername); - expect_value(__wrap_getpeername, fd, fd); - will_return(__wrap_getpeername, rc); -} - -static void expect_BIO_closesocket(int fd, int rc) -{ - expect_function_call(__wrap_BIO_closesocket); - expect_value(__wrap_BIO_closesocket, fd, fd); - will_return(__wrap_BIO_closesocket, rc); -} - -static void expect_BIO_socket_nbio(int fd, int mode, int rc) -{ - expect_function_call(__wrap_BIO_socket_nbio); - expect_value(__wrap_BIO_socket_nbio, fd, fd); - expect_value(__wrap_BIO_socket_nbio, mode, mode); - will_return(__wrap_BIO_socket_nbio, rc); -} - -/* helpers */ - -static bio_dgram_data *get_data(BIO *bio) -{ - return (bio_dgram_data *)bio->ptr; -} - -static void make_peer(BIO *bio, unsigned short port) -{ - struct sockaddr_in sa; - - memset(&sa, 0, sizeof(sa)); - sa.sin_family = AF_INET; - sa.sin_port = htons(port); - sa.sin_addr.s_addr = htonl(INADDR_LOOPBACK); - BIO_ctrl(bio, BIO_CTRL_DGRAM_SET_PEER, 0, &sa); -} - -/* - * Detach the fake socket before teardown so BIO_free does not call a real - * close: BIO_NOCLOSE already guards it, but resetting num keeps any stray - * dgram_clear path inert. - */ -static void reset_for_teardown(BIO *bio) -{ - bio->num = (int)INVALID_SOCKET; - bio->shutdown = BIO_NOCLOSE; -} - -/* setup / teardown */ - -static int setup(void **state) -{ - BIO *bio = BIO_new(BIO_s_datagram()); - - assert_non_null(bio); - *state = bio; - return 0; -} - -static int teardown(void **state) -{ - if (*state != NULL) - BIO_free(*state); - return 0; -} - -/* I/O tests attach the fake socket up front so the BIO is init'ed. */ -static int setup_io(void **state) -{ - BIO *bio; - - if (setup(state) != 0) - return -1; - bio = *state; - expect_getsockname(FAKE_SOCKET, 0); - expect_getpeername(FAKE_SOCKET, -1); - BIO_set_fd(bio, FAKE_SOCKET, BIO_NOCLOSE); - return 0; -} - -static int teardown_io(void **state) -{ - if (*state != NULL) - reset_for_teardown(*state); - return teardown(state); -} - -static int group_setup(void **state) -{ - struct in6_addr loop6 = IN6ADDR_LOOPBACK_INIT; - - (void)state; - memset(&g_sin, 0, sizeof(g_sin)); - g_sin.sin_family = AF_INET; - g_sin.sin_port = htons(443); - g_sin.sin_addr.s_addr = htonl(INADDR_LOOPBACK); - - memset(&g_sin6, 0, sizeof(g_sin6)); - g_sin6.sin6_family = AF_INET6; - g_sin6.sin6_port = htons(443); - g_sin6.sin6_addr = loop6; - - /* ::ffff:127.0.0.1 -> IPv4-mapped, exercises the v4mapped MTU branch */ - memset(&g_sin6_v4m, 0, sizeof(g_sin6_v4m)); - g_sin6_v4m.sin6_family = AF_INET6; - g_sin6_v4m.sin6_port = htons(443); - g_sin6_v4m.sin6_addr.s6_addr[10] = 0xff; - g_sin6_v4m.sin6_addr.s6_addr[11] = 0xff; - g_sin6_v4m.sin6_addr.s6_addr[12] = 127; - g_sin6_v4m.sin6_addr.s6_addr[15] = 1; - return 0; -} - -/* BIO_new_dgram */ -static void test_new_dgram(void **state) -{ - int out = -1; - BIO *bio; - - (void)state; - expect_getsockname(FAKE_SOCKET, 0); - expect_getpeername(FAKE_SOCKET, -1); - bio = BIO_new_dgram(FAKE_SOCKET, BIO_NOCLOSE); - assert_non_null(bio); - assert_int_equal(BIO_get_fd(bio, &out), FAKE_SOCKET); - assert_int_equal(out, FAKE_SOCKET); - reset_for_teardown(bio); - BIO_free(bio); -} - -static void test_dgram_new_defaults(void **state) -{ - BIO *bio = *state; - - assert_non_null(get_data(bio)); - assert_int_equal(bio->num, 0); - assert_int_equal(bio->init, 0); -} - -/* BIO_C_SET_FD / BIO_C_GET_FD */ - -static void test_set_fd_unconnected(void **state) -{ - BIO *bio = *state; - bio_dgram_data *data; - int out = -1; - - expect_getsockname(FAKE_SOCKET, 0); - expect_getpeername(FAKE_SOCKET, -1); - BIO_set_fd(bio, FAKE_SOCKET, BIO_NOCLOSE); - - data = get_data(bio); - assert_int_equal(data->connected, 0); - assert_int_equal(bio->init, 1); - assert_int_equal(BIO_get_fd(bio, &out), FAKE_SOCKET); - assert_int_equal(out, FAKE_SOCKET); - reset_for_teardown(bio); -} - -static void test_set_fd_connected(void **state) -{ - /* getpeername succeeds: peer is recorded and connected is set */ - BIO *bio = *state; - bio_dgram_data *data; - - expect_getsockname(FAKE_SOCKET, 0); - expect_getpeername(FAKE_SOCKET, 0); - BIO_set_fd(bio, FAKE_SOCKET, BIO_NOCLOSE); - - data = get_data(bio); - assert_int_equal(data->connected, 1); - assert_int_equal(BIO_ADDR_family(&data->peer), AF_INET); - reset_for_teardown(bio); -} - -static void test_get_fd_uninit(void **state) -{ - assert_int_equal(BIO_ctrl(*state, BIO_C_GET_FD, 0, NULL), -1); -} - -/* dgram_read */ - -static void test_dgram_read_noop(void **state) -{ - /* outl == 0: recvfrom is never reached */ - BIO *bio = *state; - char buf[1]; - - assert_int_equal(BIO_read(bio, buf, 0), 0); -} - -static void test_dgram_read_success(void **state) -{ - BIO *bio = *state; - char buf[16] = { 0 }; - - expect_recvfrom(FAKE_SOCKET, buf, sizeof(buf), 0, 4, NULL, 0); - assert_int_equal(BIO_read(bio, buf, sizeof(buf)), 4); - assert_false(BIO_should_retry(bio)); -} - -static void test_dgram_read_sets_peer(void **state) -{ - /* unconnected receive records the source address as the peer */ - BIO *bio = *state; - bio_dgram_data *data = get_data(bio); - char buf[16] = { 0 }; - - expect_recvfrom(FAKE_SOCKET, buf, sizeof(buf), 0, 4, - (const struct sockaddr *)&g_sin, 0); - assert_int_equal(BIO_read(bio, buf, sizeof(buf)), 4); - assert_int_equal(BIO_ADDR_family(&data->peer), AF_INET); -} - -static void test_dgram_read_peek(void **state) -{ - /* peekmode passes MSG_PEEK to recvfrom */ - BIO *bio = *state; - char buf[16] = { 0 }; - - get_data(bio)->peekmode = 1; - expect_recvfrom(FAKE_SOCKET, buf, sizeof(buf), MSG_PEEK, 4, NULL, 0); - assert_int_equal(BIO_read(bio, buf, sizeof(buf)), 4); -} - -static void test_dgram_read_retry(void **state) -{ - BIO *bio = *state; - char buf[16] = { 0 }; - - expect_recvfrom(FAKE_SOCKET, buf, sizeof(buf), 0, -1, NULL, EAGAIN); - assert_true(BIO_read(bio, buf, sizeof(buf)) <= 0); - assert_true(BIO_should_read(bio)); -} - -static void test_dgram_read_error(void **state) -{ - BIO *bio = *state; - char buf[16] = { 0 }; - - expect_recvfrom(FAKE_SOCKET, buf, sizeof(buf), 0, -1, NULL, ECONNREFUSED); - assert_true(BIO_read(bio, buf, sizeof(buf)) <= 0); - assert_false(BIO_should_retry(bio)); -} - -/* dgram_write */ - -static void test_dgram_write_unconnected(void **state) -{ - BIO *bio = *state; - const char buf[] = "hello"; - - make_peer(bio, 4433); - expect_sendto(FAKE_SOCKET, buf, 5, 0, - (socklen_t)sizeof(struct sockaddr_in), 5, 0); - assert_int_equal(BIO_write(bio, buf, 5), 5); - assert_false(BIO_should_retry(bio)); -} - -static void test_dgram_write_connected(void **state) -{ - BIO *bio = *state; - bio_dgram_data *data = get_data(bio); - const char buf[] = "hello"; - - data->connected = 1; - expect_write(FAKE_SOCKET, buf, 5, 5); - assert_int_equal(BIO_write(bio, buf, 5), 5); - data->connected = 0; -} - -static void test_dgram_write_retry(void **state) -{ - BIO *bio = *state; - const char buf[] = "hello"; - - make_peer(bio, 4433); - expect_sendto(FAKE_SOCKET, buf, 5, 0, - (socklen_t)sizeof(struct sockaddr_in), -1, EAGAIN); - assert_true(BIO_write(bio, buf, 5) <= 0); - assert_true(BIO_should_write(bio)); -} - -static void test_dgram_write_error(void **state) -{ - BIO *bio = *state; - const char buf[] = "hello"; - - make_peer(bio, 4433); - expect_sendto(FAKE_SOCKET, buf, 5, 0, - (socklen_t)sizeof(struct sockaddr_in), -1, ECONNREFUSED); - assert_true(BIO_write(bio, buf, 5) <= 0); - assert_false(BIO_should_retry(bio)); -} - -/* dgram_ctrl */ - -static void test_ctrl_reset(void **state) -{ - assert_int_equal(BIO_ctrl(*state, BIO_CTRL_RESET, 0, NULL), 0); -} - -static void test_ctrl_info(void **state) -{ - assert_int_equal(BIO_ctrl(*state, BIO_CTRL_INFO, 0, NULL), 0); -} - -static void test_ctrl_pending_wpending(void **state) -{ - assert_int_equal(BIO_ctrl(*state, BIO_CTRL_PENDING, 0, NULL), 0); - assert_int_equal(BIO_ctrl(*state, BIO_CTRL_WPENDING, 0, NULL), 0); -} - -static void test_ctrl_dup_flush(void **state) -{ - assert_int_equal(BIO_ctrl(*state, BIO_CTRL_DUP, 0, NULL), 1); - assert_int_equal(BIO_ctrl(*state, BIO_CTRL_FLUSH, 0, NULL), 1); -} - -static void test_ctrl_get_set_close(void **state) -{ - BIO *bio = *state; - - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_GET_CLOSE, 0, NULL), BIO_NOCLOSE); - BIO_ctrl(bio, BIO_CTRL_SET_CLOSE, BIO_CLOSE, NULL); - assert_int_equal(bio->shutdown, BIO_CLOSE); - bio->shutdown = BIO_NOCLOSE; -} - -static void test_ctrl_connect(void **state) -{ - BIO *bio = *state; - bio_dgram_data *data = get_data(bio); - struct sockaddr_in sa; - - memset(&sa, 0, sizeof(sa)); - sa.sin_family = AF_INET; - sa.sin_port = htons(4433); - sa.sin_addr.s_addr = htonl(INADDR_LOOPBACK); - - BIO_ctrl(bio, BIO_CTRL_DGRAM_CONNECT, 0, &sa); - assert_int_equal(BIO_ADDR_family(&data->peer), AF_INET); - assert_int_equal(data->peer.s_in.sin_port, htons(4433)); -} - -static void test_ctrl_set_get_peer(void **state) -{ - BIO *bio = *state; - BIO_ADDR got; - - make_peer(bio, 4433); - memset(&got, 0, sizeof(got)); - BIO_ctrl(bio, BIO_CTRL_DGRAM_GET_PEER, sizeof(got), &got); - assert_int_equal(got.s_in.sin_family, AF_INET); - assert_int_equal(got.s_in.sin_port, htons(4433)); -} - -static void test_ctrl_set_connected(void **state) -{ - BIO *bio = *state; - bio_dgram_data *data = get_data(bio); - struct sockaddr_in sa; - - memset(&sa, 0, sizeof(sa)); - sa.sin_family = AF_INET; - sa.sin_port = htons(4433); - sa.sin_addr.s_addr = htonl(INADDR_LOOPBACK); - - BIO_ctrl(bio, BIO_CTRL_DGRAM_SET_CONNECTED, 0, &sa); - assert_int_equal(data->connected, 1); - assert_int_equal(BIO_ADDR_family(&data->peer), AF_INET); - - BIO_ctrl(bio, BIO_CTRL_DGRAM_SET_CONNECTED, 0, NULL); - assert_int_equal(data->connected, 0); - assert_int_equal(BIO_ADDR_family(&data->peer), AF_UNSPEC); -} - -static void test_ctrl_detect_peer_addr_from_data(void **state) -{ - /* peer already known: returned without touching getpeername */ - BIO *bio = *state; - BIO_ADDR got; - - make_peer(bio, 4433); - memset(&got, 0, sizeof(got)); - assert_true( - BIO_ctrl(bio, BIO_CTRL_DGRAM_DETECT_PEER_ADDR, sizeof(got), &got) > 0); - assert_int_equal(got.s_in.sin_family, AF_INET); -} - -static void test_ctrl_detect_peer_addr_via_getpeername(void **state) -{ - /* peer unset: dgram_ctrl falls back to getpeername */ - BIO *bio = *state; - BIO_ADDR got; - - memset(&got, 0, sizeof(got)); - expect_getpeername(FAKE_SOCKET, 0); - assert_true( - BIO_ctrl(bio, BIO_CTRL_DGRAM_DETECT_PEER_ADDR, sizeof(got), &got) > 0); - assert_int_equal(got.s_in.sin_family, AF_INET); -} - -static void test_ctrl_set_get_mtu(void **state) -{ - BIO *bio = *state; - - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_DGRAM_SET_MTU, 1400, NULL), 1400); - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_DGRAM_GET_MTU, 0, NULL), 1400); -} - -static void test_ctrl_fallback_mtu_ipv4(void **state) -{ - /* AF_INET peer: 576 payload minus 28 bytes IP+UDP overhead */ - BIO *bio = *state; - - make_peer(bio, 4433); - assert_int_equal( - BIO_ctrl(bio, BIO_CTRL_DGRAM_GET_FALLBACK_MTU, 0, NULL), 576 - 28); -} - -#if OPENSSL_USE_IPV6 -static void test_ctrl_fallback_mtu_ipv6(void **state) -{ - /* AF_INET6 non-mapped peer: 1280 minus 48 bytes overhead */ - BIO *bio = *state; - - BIO_ctrl(bio, BIO_CTRL_DGRAM_SET_PEER, 0, &g_sin6); - assert_int_equal( - BIO_ctrl(bio, BIO_CTRL_DGRAM_GET_FALLBACK_MTU, 0, NULL), 1280 - 48); -} - -#ifdef IN6_IS_ADDR_V4MAPPED -static void test_ctrl_fallback_mtu_ipv6_v4mapped(void **state) -{ - /* v4-mapped AF_INET6 peer: treated as IPv4, 576 minus 28 overhead */ - BIO *bio = *state; - - BIO_ctrl(bio, BIO_CTRL_DGRAM_SET_PEER, 0, &g_sin6_v4m); - assert_int_equal( - BIO_ctrl(bio, BIO_CTRL_DGRAM_GET_FALLBACK_MTU, 0, NULL), 576 - 28); -} -#endif -#endif - -#if defined(OPENSSL_SYS_LINUX) && defined(IP_MTU_DISCOVER) && defined(IP_PMTUDISC_DO) -static void test_ctrl_mtu_discover_getsockname_fails(void **state) -{ - /* getsockname fails before any setsockopt: ret 0 */ - BIO *bio = *state; - - expect_getsockname(FAKE_SOCKET, -1); - assert_int_equal( - BIO_ctrl(bio, BIO_CTRL_DGRAM_MTU_DISCOVER, 0, NULL), 0); -} -#endif - -static void test_ctrl_nbio(void **state) -{ - BIO *bio = *state; - - expect_BIO_socket_nbio(FAKE_SOCKET, 1, 1); - assert_int_equal(BIO_ctrl(bio, BIO_C_SET_NBIO, 1, NULL), 1); -} - -static void test_ctrl_set_next_timeout(void **state) -{ - BIO *bio = *state; - struct timeval tv = { 1, 0 }; - - assert_int_equal( - BIO_ctrl(bio, BIO_CTRL_DGRAM_SET_NEXT_TIMEOUT, 0, &tv), 1); -} - -/* dgram_clear / dgram_free */ - -static void test_free_closes_when_shutdown(void **state) -{ - BIO *bio = BIO_new(BIO_s_datagram()); - - (void)state; - assert_non_null(bio); - expect_getsockname(FAKE_SOCKET, 0); - expect_getpeername(FAKE_SOCKET, -1); - BIO_set_fd(bio, FAKE_SOCKET, BIO_CLOSE); - - expect_BIO_closesocket(FAKE_SOCKET, 0); - BIO_free(bio); -} - -static void test_free_no_close_when_noclose(void **state) -{ - BIO *bio = BIO_new(BIO_s_datagram()); - - (void)state; - assert_non_null(bio); - expect_getsockname(FAKE_SOCKET, 0); - expect_getpeername(FAKE_SOCKET, -1); - BIO_set_fd(bio, FAKE_SOCKET, BIO_NOCLOSE); - BIO_free(bio); -} - -/* main */ - -#define DG_TEST(name) \ - cmocka_unit_test_setup_teardown(name, setup, teardown) - -#define DG_TEST_IO(name) \ - cmocka_unit_test_setup_teardown(name, setup_io, teardown_io) - -int main(void) -{ - const struct CMUnitTest tests[] = { - /* BIO_new_dgram */ - DG_TEST(test_new_dgram), - DG_TEST(test_dgram_new_defaults), - /* SET_FD / GET_FD */ - DG_TEST(test_set_fd_unconnected), - DG_TEST(test_set_fd_connected), - DG_TEST(test_get_fd_uninit), - /* dgram_read */ - DG_TEST_IO(test_dgram_read_noop), - DG_TEST_IO(test_dgram_read_success), - DG_TEST_IO(test_dgram_read_sets_peer), - DG_TEST_IO(test_dgram_read_peek), - DG_TEST_IO(test_dgram_read_retry), - DG_TEST_IO(test_dgram_read_error), - /* dgram_write */ - DG_TEST_IO(test_dgram_write_unconnected), - DG_TEST_IO(test_dgram_write_connected), - DG_TEST_IO(test_dgram_write_retry), - DG_TEST_IO(test_dgram_write_error), - /* dgram_ctrl */ - DG_TEST_IO(test_ctrl_reset), - DG_TEST_IO(test_ctrl_info), - DG_TEST_IO(test_ctrl_pending_wpending), - DG_TEST_IO(test_ctrl_dup_flush), - DG_TEST_IO(test_ctrl_get_set_close), - DG_TEST_IO(test_ctrl_connect), - DG_TEST_IO(test_ctrl_set_get_peer), - DG_TEST_IO(test_ctrl_set_connected), - DG_TEST_IO(test_ctrl_detect_peer_addr_from_data), - DG_TEST_IO(test_ctrl_detect_peer_addr_via_getpeername), - DG_TEST_IO(test_ctrl_set_get_mtu), - DG_TEST_IO(test_ctrl_fallback_mtu_ipv4), -#if OPENSSL_USE_IPV6 - DG_TEST_IO(test_ctrl_fallback_mtu_ipv6), -#ifdef IN6_IS_ADDR_V4MAPPED - DG_TEST_IO(test_ctrl_fallback_mtu_ipv6_v4mapped), -#endif -#endif -#if defined(OPENSSL_SYS_LINUX) && defined(IP_MTU_DISCOVER) && defined(IP_PMTUDISC_DO) - DG_TEST_IO(test_ctrl_mtu_discover_getsockname_fails), -#endif - DG_TEST_IO(test_ctrl_nbio), - DG_TEST_IO(test_ctrl_set_next_timeout), - /* dgram_clear / dgram_free */ - DG_TEST(test_free_closes_when_shutdown), - DG_TEST(test_free_no_close_when_noclose), - }; - - cmocka_set_message_output(CM_OUTPUT_TAP); - - return cmocka_run_group_tests(tests, group_setup, NULL); -} - -#endif /* OPENSSL_NO_SOCK || OPENSSL_NO_DGRAM */ diff --git a/test/unit/crypto/bio/test_bss_dgram_win.c b/test/unit/crypto/bio/test_bss_dgram_win.c deleted file mode 100644 index 080d91c4e2..0000000000 --- a/test/unit/crypto/bio/test_bss_dgram_win.c +++ /dev/null @@ -1,478 +0,0 @@ -/* - * test/bss_dgram_win_test.c - * - * Windows-only side test for bss_dgram.c Windows-specific paths. - * Uses Microsoft Detours to intercept Winsock calls at runtime. - * Does NOT replace the normal --wrap-based bss_dgram test; it only - * covers branches that differ under OPENSSL_SYS_WINDOWS. - * - * NOTE: not compiled/verified by the author's toolchain. The first - * test (detour_probe) is a hard gate: if Detours does not intercept - * cross-module Winsock calls, every other result is meaningless. - */ - -#include "openssl/e_os2.h" - -#if defined(OPENSSL_NO_SOCK) || defined(OPENSSL_NO_DGRAM) \ - || !defined(OPENSSL_SYS_WINDOWS) -int main(void) { return 0; } -#else - -#include -#include -#include - -#include -#include -#include -#include -#include -#include - -#include "internal/sockets.h" -#include "bio_local.h" -#include - -#define FAKE_SOCKET ((SOCKET)42) - -/* - * Real function pointers. After DetourAttach commits, Detours rewrites - * these to trampolines pointing at the original code. - */ -static int(WSAAPI *real_getsockname)(SOCKET, struct sockaddr *, int *) - = getsockname; -static int(WSAAPI *real_getpeername)(SOCKET, struct sockaddr *, int *) - = getpeername; -static int(WSAAPI *real_setsockopt)(SOCKET, int, int, const char *, int) - = setsockopt; -static int(WSAAPI *real_getsockopt)(SOCKET, int, int, char *, int *) - = getsockopt; -static int(WSAAPI *real_recvfrom)(SOCKET, char *, int, int, - struct sockaddr *, int *) - = recvfrom; - -static struct sockaddr_in g_sin; - -/* - * detour_probe uses this to confirm the mock actually fired. It is the - * only place a mock is allowed to run outside a cmocka expectation, so - * the mocks below special-case it. - */ -static int g_probe_active; -static int g_probe_getsockopt_hits; - -/* mocks */ - -static int WSAAPI mock_getsockname(SOCKET s, struct sockaddr *name, - int *namelen) -{ - int rc; - - function_called(); - check_expected_uint(s); - - rc = mock_type(int); - if (rc == 0) { - const struct sockaddr *sa = mock_ptr_type(const struct sockaddr *); - int sl = mock_type(int); - - assert_non_null(name); - assert_non_null(namelen); - assert_true(*namelen >= sl); - memcpy(name, sa, (size_t)sl); - *namelen = sl; - } else { - WSASetLastError(mock_type(int)); - } - return rc; -} - -static int WSAAPI mock_getpeername(SOCKET s, struct sockaddr *name, - int *namelen) -{ - int rc; - - function_called(); - check_expected_uint(s); - - rc = mock_type(int); - if (rc == 0) { - assert_non_null(name); - assert_non_null(namelen); - assert_true(*namelen >= (int)sizeof(g_sin)); - memcpy(name, &g_sin, sizeof(g_sin)); - *namelen = (int)sizeof(g_sin); - } else { - WSASetLastError(mock_type(int)); - } - return rc; -} - -static int WSAAPI mock_setsockopt(SOCKET s, int level, int optname, - const char *optval, int optlen) -{ - int expected_int; - int rc; - - function_called(); - check_expected_uint(s); - check_expected_int(level); - check_expected_int(optname); - check_expected_int(optlen); - - /* Every Windows path routed here passes a single int. */ - assert_int_equal(optlen, (int)sizeof(int)); - expected_int = mock_type(int); - assert_int_equal(*(const int *)optval, expected_int); - - rc = mock_type(int); - if (rc == SOCKET_ERROR) - WSASetLastError(mock_type(int)); - return rc; -} - -static int WSAAPI mock_getsockopt(SOCKET s, int level, int optname, - char *optval, int *optlen) -{ - int out_value; - int rc; - - /* Probe path: no expectations queued, just record and answer. */ - if (g_probe_active) { - g_probe_getsockopt_hits++; - if (optval != NULL && optlen != NULL && *optlen >= (int)sizeof(int)) { - *(int *)optval = 0; - *optlen = (int)sizeof(int); - } - return 0; - } - - function_called(); - check_expected_uint(s); - check_expected_int(level); - check_expected_int(optname); - - assert_non_null(optval); - assert_non_null(optlen); - assert_int_equal(*optlen, (int)sizeof(int)); - - out_value = mock_type(int); - rc = mock_type(int); - if (rc == 0) { - *(int *)optval = out_value; - *optlen = (int)sizeof(int); - } else { - WSASetLastError(mock_type(int)); - } - return rc; -} - -static int WSAAPI mock_recvfrom(SOCKET s, char *buf, int len, int flags, - struct sockaddr *from, int *fromlen) -{ - int rc; - - (void)from; - (void)fromlen; - - function_called(); - check_expected_uint(s); - check_expected_ptr(buf); - check_expected_int(len); - check_expected_int(flags); - - rc = mock_type(int); - if (rc == SOCKET_ERROR) - WSASetLastError(mock_type(int)); - return rc; -} - -/* expectations */ - -static void expect_getsockname_ok(void) -{ - expect_function_call(mock_getsockname); - expect_uint_value(mock_getsockname, s, FAKE_SOCKET); - will_return_int(mock_getsockname, 0); - will_return_ptr(mock_getsockname, (const struct sockaddr *)&g_sin); - will_return_int(mock_getsockname, (int)sizeof(g_sin)); -} - -static void expect_getpeername_fail(void) -{ - expect_function_call(mock_getpeername); - expect_uint_value(mock_getpeername, s, FAKE_SOCKET); - will_return_int(mock_getpeername, SOCKET_ERROR); - will_return_int(mock_getpeername, WSAENOTCONN); -} - -static void expect_setsockopt_int(int level, int optname, int value, int rc) -{ - expect_function_call(mock_setsockopt); - expect_uint_value(mock_setsockopt, s, FAKE_SOCKET); - expect_int_value(mock_setsockopt, level, level); - expect_int_value(mock_setsockopt, optname, optname); - expect_int_value(mock_setsockopt, optlen, (int)sizeof(int)); - will_return_int(mock_setsockopt, value); - will_return_int(mock_setsockopt, rc); - if (rc == SOCKET_ERROR) - will_return(mock_setsockopt, WSAEINVAL); -} - -static void expect_getsockopt_int(int level, int optname, int value, int rc) -{ - expect_function_call(mock_getsockopt); - expect_uint_value(mock_getsockopt, s, FAKE_SOCKET); - expect_int_value(mock_getsockopt, level, level); - expect_int_value(mock_getsockopt, optname, optname); - will_return_int(mock_getsockopt, value); - will_return_int(mock_getsockopt, rc); - if (rc == SOCKET_ERROR) - will_return_int(mock_getsockopt, WSAEINVAL); -} - -static void expect_recvfrom_error(char *buf, int len, int flags, int wsaerr) -{ - expect_function_call(mock_recvfrom); - expect_uint_value(mock_recvfrom, s, FAKE_SOCKET); - expect_value(mock_recvfrom, buf, buf); - expect_int_value(mock_recvfrom, len, len); - expect_int_value(mock_recvfrom, flags, flags); - will_return_int(mock_recvfrom, SOCKET_ERROR); - will_return_int(mock_recvfrom, wsaerr); -} - -/* detours */ - -static int attach_detours(void) -{ - if (DetourTransactionBegin() != NO_ERROR) - return 0; - if (DetourUpdateThread(GetCurrentThread()) != NO_ERROR) - return 0; - if (DetourAttach((PVOID *)&real_getsockname, mock_getsockname) != NO_ERROR) - return 0; - if (DetourAttach((PVOID *)&real_getpeername, mock_getpeername) != NO_ERROR) - return 0; - if (DetourAttach((PVOID *)&real_setsockopt, mock_setsockopt) != NO_ERROR) - return 0; - if (DetourAttach((PVOID *)&real_getsockopt, mock_getsockopt) != NO_ERROR) - return 0; - if (DetourAttach((PVOID *)&real_recvfrom, mock_recvfrom) != NO_ERROR) - return 0; - return DetourTransactionCommit() == NO_ERROR; -} - -static int detach_detours(void) -{ - if (DetourTransactionBegin() != NO_ERROR) - return 0; - if (DetourUpdateThread(GetCurrentThread()) != NO_ERROR) - return 0; - DetourDetach((PVOID *)&real_getsockname, mock_getsockname); - DetourDetach((PVOID *)&real_getpeername, mock_getpeername); - DetourDetach((PVOID *)&real_setsockopt, mock_setsockopt); - DetourDetach((PVOID *)&real_getsockopt, mock_getsockopt); - DetourDetach((PVOID *)&real_recvfrom, mock_recvfrom); - return DetourTransactionCommit() == NO_ERROR; -} - -/* setup / teardown */ - -static int setup_io(void **state) -{ - BIO *bio = BIO_new(BIO_s_datagram()); - - assert_non_null(bio); - expect_getsockname_ok(); - expect_getpeername_fail(); - BIO_set_fd(bio, (int)FAKE_SOCKET, BIO_NOCLOSE); - *state = bio; - return 0; -} - -static int teardown_io(void **state) -{ - if (*state != NULL) { - BIO *bio = *state; - - bio->num = (int)INVALID_SOCKET; - bio->shutdown = BIO_NOCLOSE; - BIO_free(bio); - } - return 0; -} - -static int group_setup(void **state) -{ - WSADATA wsa; - - (void)state; - memset(&g_sin, 0, sizeof(g_sin)); - g_sin.sin_family = AF_INET; - g_sin.sin_port = htons(443); - g_sin.sin_addr.s_addr = htonl(INADDR_LOOPBACK); - - assert_int_equal(WSAStartup(MAKEWORD(2, 2), &wsa), 0); - assert_true(attach_detours()); - return 0; -} - -static int group_teardown(void **state) -{ - (void)state; - assert_true(detach_detours()); - WSACleanup(); - return 0; -} - -/* - * GATE: prove Detours intercepts a Winsock call made through the same - * import machinery the production library uses. If this fails, fix the - * linkage (e.g. DetourFindFunction on ws2_32.dll) before trusting any - * other test below. - */ -static void detour_probe(void **state) -{ - int val = -1; - int len = (int)sizeof(val); - int rc; - - (void)state; - g_probe_getsockopt_hits = 0; - g_probe_active = 1; - rc = getsockopt(FAKE_SOCKET, SOL_SOCKET, SO_TYPE, (char *)&val, &len); - g_probe_active = 0; - - assert_int_equal(rc, 0); - assert_int_equal(g_probe_getsockopt_hits, 1); -} - -/* SO_RCVTIMEO / SO_SNDTIMEO use int milliseconds on Windows. */ - -static void test_win_set_recv_timeout_uses_milliseconds(void **state) -{ - BIO *bio = *state; - struct timeval tv = { 1, 500000 }; - - expect_setsockopt_int(SOL_SOCKET, SO_RCVTIMEO, 1500, 0); - assert_int_equal( - BIO_ctrl(bio, BIO_CTRL_DGRAM_SET_RECV_TIMEOUT, 0, &tv), 0); -} - -static void test_win_get_recv_timeout_converts_milliseconds(void **state) -{ - BIO *bio = *state; - struct timeval tv; - - memset(&tv, 0, sizeof(tv)); - expect_getsockopt_int(SOL_SOCKET, SO_RCVTIMEO, 2500, 0); - assert_int_equal( - BIO_ctrl(bio, BIO_CTRL_DGRAM_GET_RECV_TIMEOUT, 0, &tv), - (int)sizeof(tv)); - assert_int_equal(tv.tv_sec, 2); - assert_int_equal(tv.tv_usec, 500000); -} - -static void test_win_set_send_timeout_uses_milliseconds(void **state) -{ - BIO *bio = *state; - struct timeval tv = { 3, 250000 }; - - expect_setsockopt_int(SOL_SOCKET, SO_SNDTIMEO, 3250, 0); - assert_int_equal( - BIO_ctrl(bio, BIO_CTRL_DGRAM_SET_SEND_TIMEOUT, 0, &tv), 0); -} - -static void test_win_get_send_timeout_converts_milliseconds(void **state) -{ - BIO *bio = *state; - struct timeval tv; - - memset(&tv, 0, sizeof(tv)); - expect_getsockopt_int(SOL_SOCKET, SO_SNDTIMEO, 4250, 0); - assert_int_equal( - BIO_ctrl(bio, BIO_CTRL_DGRAM_GET_SEND_TIMEOUT, 0, &tv), - (int)sizeof(tv)); - assert_int_equal(tv.tv_sec, 4); - assert_int_equal(tv.tv_usec, 250000); -} - -/* - * GET_RECV_TIMER_EXP checks data->_errno == WSAETIMEDOUT on Windows - * (EAGAIN elsewhere), then consumes/clears it. WSAETIMEDOUT is treated - * as fatal by BIO_dgram_non_fatal_error, so we set _errno directly - * rather than driving it through a recvfrom retry that never sets it. - */ -static void test_win_recv_timer_exp_consumes_errno(void **state) -{ - BIO *bio = *state; - bio_dgram_data *data = (bio_dgram_data *)bio->ptr; - - data->_errno = WSAETIMEDOUT; - assert_int_equal( - BIO_ctrl(bio, BIO_CTRL_DGRAM_GET_RECV_TIMER_EXP, 0, NULL), 1); - /* second read reports 0: the ctrl cleared _errno */ - assert_int_equal( - BIO_ctrl(bio, BIO_CTRL_DGRAM_GET_RECV_TIMER_EXP, 0, NULL), 0); -} - -/* - * A fatal recvfrom error (WSAECONNRESET) must NOT set a retry flag. - * This exercises the real Windows recvfrom signature through Detours. - */ -static void test_win_recvfrom_fatal_no_retry(void **state) -{ - BIO *bio = *state; - char buf[16]; - - memset(buf, 0, sizeof(buf)); - expect_recvfrom_error(buf, (int)sizeof(buf), 0, WSAECONNRESET); - assert_true(BIO_read(bio, buf, (int)sizeof(buf)) <= 0); - assert_false(BIO_should_retry(bio)); -} - -#if defined(IP_DONTFRAGMENT) -/* - * IPv4 don't-fragment falls to IP_DONTFRAGMENT on Windows. This branch - * is reached only when IP_DONTFRAG is NOT defined (it is the #elif). - */ -static void test_win_set_dont_frag_ipv4(void **state) -{ - BIO *bio = *state; - struct sockaddr_in peer; - - memset(&peer, 0, sizeof(peer)); - peer.sin_family = AF_INET; - peer.sin_port = htons(4433); - peer.sin_addr.s_addr = htonl(INADDR_LOOPBACK); - BIO_ctrl(bio, BIO_CTRL_DGRAM_SET_PEER, 0, &peer); - - expect_setsockopt_int(IPPROTO_IP, IP_DONTFRAGMENT, 1, 0); - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_DGRAM_SET_DONT_FRAG, 1, NULL), 0); -} -#endif - -#define DG_WIN(name) \ - cmocka_unit_test_setup_teardown(name, setup_io, teardown_io) - -int main(void) -{ - const struct CMUnitTest tests[] = { - DG_WIN(detour_probe), - DG_WIN(test_win_set_recv_timeout_uses_milliseconds), - DG_WIN(test_win_get_recv_timeout_converts_milliseconds), - DG_WIN(test_win_set_send_timeout_uses_milliseconds), - DG_WIN(test_win_get_send_timeout_converts_milliseconds), - DG_WIN(test_win_recv_timer_exp_consumes_errno), - DG_WIN(test_win_recvfrom_fatal_no_retry), -#if defined(IP_DONTFRAGMENT) - DG_WIN(test_win_set_dont_frag_ipv4), -#endif - }; - - cmocka_set_message_output(CM_OUTPUT_TAP); - return cmocka_run_group_tests(tests, group_setup, group_teardown); -} - -#endif diff --git a/test/unit/crypto/bio/test_bss_fd.c b/test/unit/crypto/bio/test_bss_fd.c deleted file mode 100644 index 3bb6b7d714..0000000000 --- a/test/unit/crypto/bio/test_bss_fd.c +++ /dev/null @@ -1,644 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#ifdef OPENSSL_NO_POSIX_IO - -int main(void) -{ - return 0; -} - -#else - -#include -#include -#include -#include -#include - -#include "bio_local.h" - -#include - -#define FAKE_FD 42 - -/* wraps */ - -ssize_t __wrap_read(int fd, void *buf, size_t count); -ssize_t __wrap_write(int fd, const void *buf, size_t count); -off_t __wrap_lseek(int fd, off_t offset, int whence); -int __wrap_close(int fd); - -ssize_t __wrap_read(int fd, void *buf, size_t count) -{ - ssize_t rc; - - function_called(); - check_expected(fd); - check_expected_ptr(buf); - check_expected(count); - rc = mock_type(ssize_t); - if (rc <= 0) - errno = mock_type(int); - return rc; -} - -ssize_t __wrap_write(int fd, const void *buf, size_t count) -{ - ssize_t rc; - - function_called(); - check_expected(fd); - check_expected_ptr(buf); - check_expected(count); - rc = mock_type(ssize_t); - if (rc <= 0) - errno = mock_type(int); - return rc; -} - -off_t __wrap_lseek(int fd, off_t offset, int whence) -{ - function_called(); - check_expected(fd); - check_expected(offset); - check_expected(whence); - - return mock_type(off_t); -} - -int __wrap_close(int fd) -{ - function_called(); - check_expected(fd); - - return mock_type(int); -} - -/* expectations */ - -/* - * errnoval is consumed by __wrap_read only when rc <= 0; pass 0 for success - * calls where the value is irrelevant. - */ -static void expect_read(int fd, const void *buf, size_t count, ssize_t rc, - int errnoval) -{ - expect_function_call(__wrap_read); - expect_value(__wrap_read, fd, fd); - expect_value(__wrap_read, buf, buf); - expect_value(__wrap_read, count, count); - will_return(__wrap_read, rc); - if (rc <= 0) - will_return(__wrap_read, errnoval); -} - -static void expect_write(int fd, const void *buf, size_t count, ssize_t rc, - int errnoval) -{ - expect_function_call(__wrap_write); - expect_value(__wrap_write, fd, fd); - expect_value(__wrap_write, buf, buf); - expect_value(__wrap_write, count, count); - will_return(__wrap_write, rc); - if (rc <= 0) - will_return(__wrap_write, errnoval); -} - -static void expect_lseek(int fd, off_t offset, int whence, off_t rc) -{ - expect_function_call(__wrap_lseek); - expect_value(__wrap_lseek, fd, fd); - expect_value(__wrap_lseek, offset, offset); - expect_value(__wrap_lseek, whence, whence); - will_return(__wrap_lseek, rc); -} - -static void expect_close(int fd, int rc) -{ - expect_function_call(__wrap_close); - expect_value(__wrap_close, fd, fd); - will_return(__wrap_close, rc); -} - -/* setup / teardown */ - -static int setup(void **state) -{ - BIO *bio = BIO_new(BIO_s_fd()); - - assert_non_null(bio); - BIO_set_fd(bio, FAKE_FD, BIO_NOCLOSE); - *state = bio; - return 0; -} - -static int teardown(void **state) -{ - if (*state != NULL) - BIO_free(*state); - return 0; -} - -/* BIO_fd_non_fatal_error */ - -static void test_non_fatal_error_retryable(void **state) -{ - static const int errs[] = { -#ifdef EAGAIN - EAGAIN, -#endif -#ifdef EINTR - EINTR, -#endif -#if defined(EWOULDBLOCK) && (!defined(EAGAIN) || EWOULDBLOCK != EAGAIN) - EWOULDBLOCK, -#endif -#ifdef EINPROGRESS - EINPROGRESS, -#endif -#ifdef EALREADY - EALREADY, -#endif -#ifdef ENOTCONN - ENOTCONN, -#endif -#ifdef EPROTO - EPROTO, -#endif - }; - size_t i; - - (void)state; - for (i = 0; i < sizeof(errs) / sizeof(errs[0]); i++) - assert_int_equal(BIO_fd_non_fatal_error(errs[i]), 1); -} - -static void test_non_fatal_error_fatal(void **state) -{ - (void)state; - assert_int_equal(BIO_fd_non_fatal_error(ENOENT), 0); - assert_int_equal(BIO_fd_non_fatal_error(EBADF), 0); - assert_int_equal(BIO_fd_non_fatal_error(0), 0); -} - -/* BIO_fd_should_retry */ - -static void test_should_retry_positive_i(void **state) -{ - /* i > 0: always returns 0 regardless of errno */ - (void)state; - errno = EAGAIN; - assert_int_equal(BIO_fd_should_retry(1), 0); - assert_int_equal(BIO_fd_should_retry(100), 0); -} - -static void test_should_retry_fatal_errno(void **state) -{ - (void)state; - errno = ENOENT; - assert_int_equal(BIO_fd_should_retry(-1), 0); - errno = ENOENT; - assert_int_equal(BIO_fd_should_retry(0), 0); -} - -static void test_should_retry_non_fatal_errno(void **state) -{ - (void)state; - errno = EAGAIN; - assert_int_equal(BIO_fd_should_retry(-1), 1); - errno = EINTR; - assert_int_equal(BIO_fd_should_retry(0), 1); -} - -/* fd_read (via BIO_read) */ - -static void test_fd_read_success(void **state) -{ - BIO *bio = *state; - char buf[8] = { 0 }; - - expect_read(FAKE_FD, buf, 8, 8, 0); - assert_int_equal(BIO_read(bio, buf, 8), 8); - assert_false(BIO_should_retry(bio)); - assert_false(BIO_eof(bio)); -} - -static void test_fd_read_eof(void **state) -{ - BIO *bio = *state; - char buf[8] = { 0 }; - - expect_read(FAKE_FD, buf, 8, 0, 0); - assert_true(BIO_read(bio, buf, 8) <= 0); - assert_true(BIO_eof(bio)); - assert_false(BIO_should_retry(bio)); -} - -static void test_fd_read_retry(void **state) -{ - BIO *bio = *state; - char buf[8] = { 0 }; - - expect_read(FAKE_FD, buf, 8, -1, EAGAIN); - assert_true(BIO_read(bio, buf, 8) <= 0); - assert_true(BIO_should_retry(bio)); - assert_true(BIO_should_read(bio)); - assert_false(BIO_eof(bio)); -} - -static void test_fd_read_error(void **state) -{ - BIO *bio = *state; - char buf[8] = { 0 }; - - expect_read(FAKE_FD, buf, 8, -1, ENOENT); - assert_true(BIO_read(bio, buf, 8) <= 0); - assert_false(BIO_should_retry(bio)); - assert_false(BIO_eof(bio)); -} - -static void test_fd_read_clears_eof(void **state) -{ - /* BIO_FLAGS_IN_EOF is cleared at the start of each new read attempt. */ - BIO *bio = *state; - char buf[1] = { 0 }; - - expect_read(FAKE_FD, buf, 1, 0, 0); - BIO_read(bio, buf, 1); - assert_true(BIO_eof(bio)); - - expect_read(FAKE_FD, buf, 1, 1, 0); - assert_int_equal(BIO_read(bio, buf, 1), 1); - assert_false(BIO_eof(bio)); -} - -/* fd_write (via BIO_write) */ - -static void test_fd_write_success(void **state) -{ - BIO *bio = *state; - const char buf[] = "hello"; - - expect_write(FAKE_FD, buf, 5, 5, 0); - assert_int_equal(BIO_write(bio, buf, 5), 5); - assert_false(BIO_should_retry(bio)); -} - -static void test_fd_write_retry(void **state) -{ - BIO *bio = *state; - const char buf[] = "hello"; - - expect_write(FAKE_FD, buf, 5, -1, EAGAIN); - assert_true(BIO_write(bio, buf, 5) <= 0); - assert_true(BIO_should_retry(bio)); - assert_true(BIO_should_write(bio)); -} - -static void test_fd_write_error(void **state) -{ - BIO *bio = *state; - const char buf[] = "hello"; - - expect_write(FAKE_FD, buf, 5, -1, ENOSPC); - assert_true(BIO_write(bio, buf, 5) <= 0); - assert_false(BIO_should_retry(bio)); -} - -/* fd_ctrl (via BIO_ctrl) */ - -static void test_fd_ctrl_reset(void **state) -{ - BIO *bio = *state; - - /* RESET sets num=0 then falls through to FILE_SEEK: lseek(fd, 0, 0) */ - expect_lseek(FAKE_FD, 0, 0, 0); - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_RESET, 0, NULL), 0); -} - -static void test_fd_ctrl_seek(void **state) -{ - BIO *bio = *state; - - expect_lseek(FAKE_FD, 512, 0, 512); - assert_int_equal(BIO_ctrl(bio, BIO_C_FILE_SEEK, 512, NULL), 512); -} - -static void test_fd_ctrl_tell(void **state) -{ - BIO *bio = *state; - - expect_lseek(FAKE_FD, 0, 1, 256); - assert_int_equal(BIO_ctrl(bio, BIO_C_FILE_TELL, 0, NULL), 256); -} - -static void test_fd_ctrl_info(void **state) -{ - BIO *bio = *state; - - /* BIO_CTRL_INFO shares the lseek(fd, 0, 1) branch with FILE_TELL */ - expect_lseek(FAKE_FD, 0, 1, 128); - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_INFO, 0, NULL), 128); -} - -static void test_fd_ctrl_set_fd(void **state) -{ - BIO *bio = *state; - int newfd = 99; - - /* fd_free is called first; existing shutdown=BIO_NOCLOSE so no close */ - BIO_ctrl(bio, BIO_C_SET_FD, BIO_NOCLOSE, &newfd); - assert_int_equal(bio->num, 99); - assert_int_equal(bio->shutdown, BIO_NOCLOSE); - assert_int_equal(bio->init, 1); -} - -static void test_fd_ctrl_get_fd_init(void **state) -{ - BIO *bio = *state; - int out = -1; - - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_FD, 0, &out), FAKE_FD); - assert_int_equal(out, FAKE_FD); -} - -static void test_fd_ctrl_get_fd_uninit(void **state) -{ - BIO *bio = *state; - - /* teardown is safe: shutdown=BIO_NOCLOSE guards the close call */ - bio->init = 0; - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_FD, 0, NULL), -1); -} - -static void test_fd_ctrl_get_close(void **state) -{ - BIO *bio = *state; - - bio->shutdown = BIO_NOCLOSE; - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_GET_CLOSE, 0, NULL), BIO_NOCLOSE); - bio->shutdown = BIO_CLOSE; - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_GET_CLOSE, 0, NULL), BIO_CLOSE); - bio->shutdown = BIO_NOCLOSE; -} - -static void test_fd_ctrl_set_close(void **state) -{ - BIO *bio = *state; - - BIO_ctrl(bio, BIO_CTRL_SET_CLOSE, BIO_CLOSE, NULL); - assert_int_equal(bio->shutdown, BIO_CLOSE); - /* Restore before teardown to avoid an unexpected close call. */ - BIO_ctrl(bio, BIO_CTRL_SET_CLOSE, BIO_NOCLOSE, NULL); -} - -static void test_fd_ctrl_pending(void **state) -{ - assert_int_equal(BIO_ctrl(*state, BIO_CTRL_PENDING, 0, NULL), 0); -} - -static void test_fd_ctrl_wpending(void **state) -{ - assert_int_equal(BIO_ctrl(*state, BIO_CTRL_WPENDING, 0, NULL), 0); -} - -static void test_fd_ctrl_dup(void **state) -{ - assert_int_equal(BIO_ctrl(*state, BIO_CTRL_DUP, 0, NULL), 1); -} - -static void test_fd_ctrl_flush(void **state) -{ - assert_int_equal(BIO_ctrl(*state, BIO_CTRL_FLUSH, 0, NULL), 1); -} - -static void test_fd_ctrl_eof_clear(void **state) -{ - BIO *bio = *state; - - bio->flags &= ~BIO_FLAGS_IN_EOF; - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_EOF, 0, NULL), 0); -} - -static void test_fd_ctrl_eof_set(void **state) -{ - BIO *bio = *state; - - bio->flags |= BIO_FLAGS_IN_EOF; - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_EOF, 0, NULL), 1); - bio->flags &= ~BIO_FLAGS_IN_EOF; -} - -static void test_fd_ctrl_default(void **state) -{ - assert_int_equal(BIO_ctrl(*state, 9999, 0, NULL), 0); -} - -/* fd_free (via BIO_free) */ - -static void test_fd_free_shutdown_with_init(void **state) -{ - /* shutdown=1 and init=1: close must be called */ - BIO *bio = BIO_new(BIO_s_fd()); - - assert_non_null(bio); - bio->num = FAKE_FD; - bio->shutdown = BIO_CLOSE; - bio->init = 1; - - expect_close(FAKE_FD, 0); - BIO_free(bio); - *state = NULL; -} - -static void test_fd_free_shutdown_no_init(void **state) -{ - /* shutdown=1 but init=0: close must NOT be called */ - BIO *bio = BIO_new(BIO_s_fd()); - - assert_non_null(bio); - bio->num = FAKE_FD; - bio->shutdown = BIO_CLOSE; - bio->init = 0; - - BIO_free(bio); - *state = NULL; -} - -static void test_fd_free_no_shutdown(void **state) -{ - /* shutdown=0: close must NOT be called regardless of init */ - BIO *bio = BIO_new(BIO_s_fd()); - - assert_non_null(bio); - bio->num = FAKE_FD; - bio->shutdown = BIO_NOCLOSE; - bio->init = 1; - - BIO_free(bio); - *state = NULL; -} - -/* fd_puts (via BIO_puts) */ - -static void test_fd_puts_success(void **state) -{ - BIO *bio = *state; - const char *str = "hello"; - - expect_write(FAKE_FD, str, 5, 5, 0); - assert_int_equal(BIO_puts(bio, str), 5); -} - -static void test_fd_puts_write_fails(void **state) -{ - BIO *bio = *state; - const char *str = "hello"; - - expect_write(FAKE_FD, str, 5, -1, ENOSPC); - assert_true(BIO_puts(bio, str) <= 0); -} - -/* - * fd_gets (via BIO_gets) - * - * fd_gets calls fd_read one byte at a time, which in turn calls read. - * The buffer is pre-filled with the data that each mocked read delivers, - * since __wrap_read returns the count without writing into the buffer. - */ - -static void test_fd_gets_size_one(void **state) -{ - /* end == buf when size=1, so the loop body never executes */ - BIO *bio = *state; - char buf[4] = { 0 }; - - assert_int_equal(BIO_gets(bio, buf, 1), 0); - assert_int_equal(buf[0], '\0'); -} - -static void test_fd_gets_newline_terminates(void **state) -{ - BIO *bio = *state; - char buf[8] = { 'h', 'i', '\n' }; - - expect_read(FAKE_FD, buf, 1, 1, 0); - expect_read(FAKE_FD, buf + 1, 1, 1, 0); - expect_read(FAKE_FD, buf + 2, 1, 1, 0); - - assert_int_equal(BIO_gets(bio, buf, sizeof(buf)), 3); - assert_memory_equal(buf, "hi\n", 4); -} - -static void test_fd_gets_fills_to_limit(void **state) -{ - /* size=4: reads at most 3 chars (buf+3 is the null slot) */ - BIO *bio = *state; - char buf[4] = { 'a', 'b', 'c' }; - - expect_read(FAKE_FD, buf, 1, 1, 0); - expect_read(FAKE_FD, buf + 1, 1, 1, 0); - expect_read(FAKE_FD, buf + 2, 1, 1, 0); - - assert_int_equal(BIO_gets(bio, buf, 4), 3); - assert_memory_equal(buf, "abc", 4); -} - -static void test_fd_gets_eof_mid_line(void **state) -{ - /* read returns 0 after the first byte: return what was read */ - BIO *bio = *state; - char buf[8] = { 'z' }; - - expect_read(FAKE_FD, buf, 1, 1, 0); - expect_read(FAKE_FD, buf + 1, 1, 0, 0); - - assert_int_equal(BIO_gets(bio, buf, sizeof(buf)), 1); - assert_memory_equal(buf, "z", 2); -} - -static void test_fd_gets_immediate_eof(void **state) -{ - /* First read returns 0: returns 0 and buf[0] is '\0' */ - BIO *bio = *state; - char buf[8] = { 0 }; - - expect_read(FAKE_FD, buf, 1, 0, 0); - - assert_int_equal(BIO_gets(bio, buf, sizeof(buf)), 0); - assert_int_equal(buf[0], '\0'); -} - -/* main */ - -#define FD_TEST(name) \ - cmocka_unit_test_setup_teardown(name, setup, teardown) - -#define FD_TEST_PLAIN(name) \ - cmocka_unit_test(name) - -int main(void) -{ - const struct CMUnitTest tests[] = { - /* BIO_fd_non_fatal_error */ - FD_TEST_PLAIN(test_non_fatal_error_retryable), - FD_TEST_PLAIN(test_non_fatal_error_fatal), - /* BIO_fd_should_retry */ - FD_TEST_PLAIN(test_should_retry_positive_i), - FD_TEST_PLAIN(test_should_retry_fatal_errno), - FD_TEST_PLAIN(test_should_retry_non_fatal_errno), - /* fd_read */ - FD_TEST(test_fd_read_success), - FD_TEST(test_fd_read_eof), - FD_TEST(test_fd_read_retry), - FD_TEST(test_fd_read_error), - FD_TEST(test_fd_read_clears_eof), - /* fd_write */ - FD_TEST(test_fd_write_success), - FD_TEST(test_fd_write_retry), - FD_TEST(test_fd_write_error), - /* fd_ctrl */ - FD_TEST(test_fd_ctrl_reset), - FD_TEST(test_fd_ctrl_seek), - FD_TEST(test_fd_ctrl_tell), - FD_TEST(test_fd_ctrl_info), - FD_TEST(test_fd_ctrl_set_fd), - FD_TEST(test_fd_ctrl_get_fd_init), - FD_TEST(test_fd_ctrl_get_fd_uninit), - FD_TEST(test_fd_ctrl_get_close), - FD_TEST(test_fd_ctrl_set_close), - FD_TEST(test_fd_ctrl_pending), - FD_TEST(test_fd_ctrl_wpending), - FD_TEST(test_fd_ctrl_dup), - FD_TEST(test_fd_ctrl_flush), - FD_TEST(test_fd_ctrl_eof_clear), - FD_TEST(test_fd_ctrl_eof_set), - FD_TEST(test_fd_ctrl_default), - /* fd_free */ - FD_TEST(test_fd_free_shutdown_with_init), - FD_TEST(test_fd_free_shutdown_no_init), - FD_TEST(test_fd_free_no_shutdown), - /* fd_puts */ - FD_TEST(test_fd_puts_success), - FD_TEST(test_fd_puts_write_fails), - /* fd_gets */ - FD_TEST(test_fd_gets_size_one), - FD_TEST(test_fd_gets_newline_terminates), - FD_TEST(test_fd_gets_fills_to_limit), - FD_TEST(test_fd_gets_eof_mid_line), - FD_TEST(test_fd_gets_immediate_eof), - }; - - cmocka_set_message_output(CM_OUTPUT_TAP); - - return cmocka_run_group_tests(tests, NULL, NULL); -} - -#endif /* OPENSSL_NO_POSIX_IO */ diff --git a/test/unit/crypto/bio/test_bss_sock.c b/test/unit/crypto/bio/test_bss_sock.c deleted file mode 100644 index 8d5aa547f0..0000000000 --- a/test/unit/crypto/bio/test_bss_sock.c +++ /dev/null @@ -1,530 +0,0 @@ -/* - * Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -#include "internal/sockets.h" - -#ifndef OPENSSL_NO_SOCK - -#include -#include -#include -#include -#include -#include -#include -#include "bio_local.h" -#include "internal/bio_tfo.h" -#include - -#define FAKE_SOCKET 42 - -/* prototypes for __wrap_* (required by -Wmissing-prototypes) */ -ssize_t __wrap_read(int fd, void *buf, size_t count); -ssize_t __wrap_write(int fd, const void *buf, size_t count); -int __wrap_BIO_closesocket(int fd); - -/* wraps */ - -ssize_t __wrap_read(int fd, void *buf, size_t count) -{ - ssize_t rc; - - function_called(); - check_expected(fd); - check_expected_ptr(buf); - check_expected(count); - rc = mock_type(ssize_t); - if (rc < 0) - errno = mock_type(int); - return rc; -} - -ssize_t __wrap_write(int fd, const void *buf, size_t count) -{ - ssize_t rc; - - function_called(); - check_expected(fd); - check_expected_ptr(buf); - check_expected(count); - rc = mock_type(ssize_t); - if (rc < 0) - errno = mock_type(int); - return rc; -} - -int __wrap_BIO_closesocket(int fd) -{ - function_called(); - check_expected(fd); - return mock_type(int); -} - -/* expectations */ - -static void expect_read(int fd, const void *buf, size_t count, ssize_t rc, - int errnoval) -{ - expect_function_call(__wrap_read); - expect_value(__wrap_read, fd, fd); - expect_value(__wrap_read, buf, buf); - expect_value(__wrap_read, count, count); - will_return(__wrap_read, rc); - if (rc < 0) - will_return(__wrap_read, errnoval); -} - -static void expect_write(int fd, const void *buf, size_t count, ssize_t rc, - int errnoval) -{ - expect_function_call(__wrap_write); - expect_value(__wrap_write, fd, fd); - expect_value(__wrap_write, buf, buf); - expect_value(__wrap_write, count, count); - will_return(__wrap_write, rc); - if (rc < 0) - will_return(__wrap_write, errnoval); -} - -static void expect_BIO_closesocket(int fd, int rc) -{ - expect_function_call(__wrap_BIO_closesocket); - expect_value(__wrap_BIO_closesocket, fd, fd); - will_return(__wrap_BIO_closesocket, rc); -} - -/* setup / teardown */ - -static int setup(void **state) -{ - BIO *bio = BIO_new(BIO_s_socket()); - - assert_non_null(bio); - BIO_set_fd(bio, FAKE_SOCKET, BIO_NOCLOSE); - *state = bio; - return 0; -} - -static int teardown(void **state) -{ - if (*state != NULL) - BIO_free(*state); - return 0; -} - -/* sock_new defaults */ - -static void test_sock_new_defaults(void **state) -{ - /* fresh BIO before BIO_set_fd: init 0, num 0, ptr allocated */ - BIO *bio = BIO_new(BIO_s_socket()); - - (void)state; - assert_non_null(bio); - assert_int_equal(bio->init, 0); - assert_int_equal(bio->num, 0); - assert_non_null(bio->ptr); - BIO_free(bio); -} - -/* BIO_new_socket */ - -static void test_new_socket(void **state) -{ - int out = -1; - BIO *bio = BIO_new_socket(FAKE_SOCKET, BIO_NOCLOSE); - - (void)state; - assert_non_null(bio); - assert_int_equal(bio->init, 1); - assert_int_equal(BIO_get_fd(bio, &out), FAKE_SOCKET); - assert_int_equal(out, FAKE_SOCKET); - BIO_free(bio); -} - -/* sock_read */ - -static void test_sock_read_noop(void **state) -{ - /* outl == 0: readsocket is never reached */ - BIO *bio = *state; - char buf[1]; - - assert_int_equal(BIO_read(bio, buf, 0), 0); -} - -static void test_sock_read_success(void **state) -{ - BIO *bio = *state; - char buf[16] = { 0 }; - - expect_read(FAKE_SOCKET, buf, 16, 4, 0); - assert_int_equal(BIO_read(bio, buf, sizeof(buf)), 4); - assert_false(BIO_should_retry(bio)); - assert_false(BIO_eof(bio)); -} - -static void test_sock_read_eof(void **state) -{ - BIO *bio = *state; - char buf[16] = { 0 }; - - expect_read(FAKE_SOCKET, buf, 16, 0, 0); - assert_true(BIO_read(bio, buf, sizeof(buf)) <= 0); - assert_true(BIO_eof(bio)); - assert_false(BIO_should_retry(bio)); -} - -static void test_sock_read_retry(void **state) -{ - BIO *bio = *state; - char buf[16] = { 0 }; - - expect_read(FAKE_SOCKET, buf, 16, -1, EAGAIN); - assert_true(BIO_read(bio, buf, sizeof(buf)) <= 0); - assert_true(BIO_should_read(bio)); - assert_false(BIO_eof(bio)); -} - -static void test_sock_read_error(void **state) -{ - BIO *bio = *state; - char buf[16] = { 0 }; - - expect_read(FAKE_SOCKET, buf, 16, -1, ECONNREFUSED); - assert_true(BIO_read(bio, buf, sizeof(buf)) <= 0); - assert_false(BIO_should_retry(bio)); - assert_false(BIO_eof(bio)); -} - -static void test_sock_read_clears_eof(void **state) -{ - /* BIO_FLAGS_IN_EOF is cleared at the start of each new read attempt */ - BIO *bio = *state; - char buf[1] = { 0 }; - - expect_read(FAKE_SOCKET, buf, 1, 0, 0); - BIO_read(bio, buf, 1); - assert_true(BIO_eof(bio)); - - expect_read(FAKE_SOCKET, buf, 1, 1, 0); - assert_int_equal(BIO_read(bio, buf, 1), 1); - assert_false(BIO_eof(bio)); -} - -/* sock_write */ - -static void test_sock_write_success(void **state) -{ - BIO *bio = *state; - const char buf[] = "hello"; - - expect_write(FAKE_SOCKET, buf, 5, 5, 0); - assert_int_equal(BIO_write(bio, buf, 5), 5); - assert_false(BIO_should_retry(bio)); -} - -static void test_sock_write_retry(void **state) -{ - BIO *bio = *state; - const char buf[] = "hello"; - - expect_write(FAKE_SOCKET, buf, 5, -1, EAGAIN); - assert_true(BIO_write(bio, buf, 5) <= 0); - assert_true(BIO_should_write(bio)); -} - -static void test_sock_write_error(void **state) -{ - BIO *bio = *state; - const char buf[] = "hello"; - - expect_write(FAKE_SOCKET, buf, 5, -1, ECONNREFUSED); - assert_true(BIO_write(bio, buf, 5) <= 0); - assert_false(BIO_should_retry(bio)); -} - -/* sock_ctrl */ - -static void test_ctrl_get_fd(void **state) -{ - BIO *bio = *state; - int out = -1; - - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_FD, 0, &out), FAKE_SOCKET); - assert_int_equal(out, FAKE_SOCKET); -} - -static void test_ctrl_get_fd_uninit(void **state) -{ - BIO *bio = *state; - - bio->init = 0; - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_FD, 0, NULL), -1); - bio->init = 1; -} - -static void test_ctrl_set_fd(void **state) -{ - BIO *bio = *state; - int newfd = 99; - - /* existing shutdown=BIO_NOCLOSE so the old fd is not closed */ - BIO_ctrl(bio, BIO_C_SET_FD, BIO_NOCLOSE, &newfd); - assert_int_equal(bio->num, 99); - assert_int_equal(bio->shutdown, BIO_NOCLOSE); - assert_int_equal(bio->init, 1); -} - -static void test_ctrl_get_set_close(void **state) -{ - BIO *bio = *state; - - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_GET_CLOSE, 0, NULL), BIO_NOCLOSE); - BIO_ctrl(bio, BIO_CTRL_SET_CLOSE, BIO_CLOSE, NULL); - assert_int_equal(bio->shutdown, BIO_CLOSE); - bio->shutdown = BIO_NOCLOSE; -} - -static void test_ctrl_dup_flush(void **state) -{ - BIO *bio = *state; - - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_DUP, 0, NULL), 1); - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_FLUSH, 0, NULL), 1); -} - -static void test_ctrl_rpoll_descriptor(void **state) -{ - BIO *bio = *state; - BIO_POLL_DESCRIPTOR pd; - - memset(&pd, 0, sizeof(pd)); - assert_int_equal( - BIO_ctrl(bio, BIO_CTRL_GET_RPOLL_DESCRIPTOR, 0, &pd), 1); - assert_int_equal(pd.type, BIO_POLL_DESCRIPTOR_TYPE_SOCK_FD); - assert_int_equal(pd.value.fd, FAKE_SOCKET); -} - -static void test_ctrl_wpoll_descriptor(void **state) -{ - BIO *bio = *state; - BIO_POLL_DESCRIPTOR pd; - - memset(&pd, 0, sizeof(pd)); - assert_int_equal( - BIO_ctrl(bio, BIO_CTRL_GET_WPOLL_DESCRIPTOR, 0, &pd), 1); - assert_int_equal(pd.type, BIO_POLL_DESCRIPTOR_TYPE_SOCK_FD); - assert_int_equal(pd.value.fd, FAKE_SOCKET); -} - -static void test_ctrl_poll_descriptor_uninit(void **state) -{ - BIO *bio = *state; - BIO_POLL_DESCRIPTOR pd; - - memset(&pd, 0, sizeof(pd)); - bio->init = 0; - assert_int_equal( - BIO_ctrl(bio, BIO_CTRL_GET_RPOLL_DESCRIPTOR, 0, &pd), 0); - bio->init = 1; -} - -static void test_ctrl_eof_clear(void **state) -{ - BIO *bio = *state; - - bio->flags &= ~BIO_FLAGS_IN_EOF; - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_EOF, 0, NULL), 0); -} - -static void test_ctrl_eof_set(void **state) -{ - BIO *bio = *state; - - bio->flags |= BIO_FLAGS_IN_EOF; - assert_int_equal(BIO_ctrl(bio, BIO_CTRL_EOF, 0, NULL), 1); - bio->flags &= ~BIO_FLAGS_IN_EOF; -} - -static void test_ctrl_get_connect(void **state) -{ - /* num==2: returns a pointer to the stored tfo_peer */ - BIO *bio = *state; - const char *ptr = NULL; - - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_CONNECT, 2, &ptr), 1); - assert_non_null(ptr); -} - -static void test_ctrl_get_connect_bad_num(void **state) -{ - BIO *bio = *state; - const char *ptr = NULL; - - assert_int_equal(BIO_ctrl(bio, BIO_C_GET_CONNECT, 0, &ptr), 0); -} - -static void test_ctrl_set_connect(void **state) -{ - BIO *bio = *state; - struct sockaddr_in sa; - BIO_ADDR addr; - - memset(&sa, 0, sizeof(sa)); - sa.sin_family = AF_INET; - sa.sin_port = htons(4433); - sa.sin_addr.s_addr = htonl(INADDR_LOOPBACK); - assert_true(BIO_ADDR_make(&addr, (const struct sockaddr *)&sa)); - - assert_int_equal(BIO_ctrl(bio, BIO_C_SET_CONNECT, 2, &addr), 1); -} - -static void test_ctrl_set_connect_bad_num(void **state) -{ - BIO *bio = *state; - BIO_ADDR addr; - - memset(&addr, 0, sizeof(addr)); - assert_int_equal(BIO_ctrl(bio, BIO_C_SET_CONNECT, 0, &addr), 0); -} - -static void test_ctrl_set_send_flags(void **state) -{ - BIO *bio = *state; - - assert_int_equal(BIO_ctrl(bio, BIO_C_SET_SEND_FLAGS, 0, NULL), 1); -} - -static void test_ctrl_default(void **state) -{ - assert_int_equal(BIO_ctrl(*state, 9999, 0, NULL), 0); -} - -/* sock_puts */ - -static void test_sock_puts_success(void **state) -{ - BIO *bio = *state; - const char *str = "hello"; - - expect_write(FAKE_SOCKET, str, 5, 5, 0); - assert_int_equal(BIO_puts(bio, str), 5); -} - -static void test_sock_puts_write_fails(void **state) -{ - BIO *bio = *state; - const char *str = "hello"; - - expect_write(FAKE_SOCKET, str, 5, -1, ECONNREFUSED); - assert_true(BIO_puts(bio, str) <= 0); -} - -/* sock_free (via BIO_free) - mostly just coverage for ASAN */ - -static void test_free_closes_when_shutdown(void **state) -{ - BIO *bio = BIO_new(BIO_s_socket()); - - (void)state; - assert_non_null(bio); - BIO_set_fd(bio, FAKE_SOCKET, BIO_CLOSE); - - expect_BIO_closesocket(FAKE_SOCKET, 0); - BIO_free(bio); -} - -static void test_free_no_close_when_noclose(void **state) -{ - BIO *bio = BIO_new(BIO_s_socket()); - - (void)state; - assert_non_null(bio); - BIO_set_fd(bio, FAKE_SOCKET, BIO_NOCLOSE); - BIO_free(bio); -} - -static void test_free_no_close_when_uninit(void **state) -{ - /* shutdown set but init==0: closesocket must NOT be called */ - BIO *bio = BIO_new(BIO_s_socket()); - - (void)state; - assert_non_null(bio); - bio->num = FAKE_SOCKET; - bio->shutdown = BIO_CLOSE; - bio->init = 0; - BIO_free(bio); -} - -/* main */ - -#define SOCK_TEST(name) \ - cmocka_unit_test_setup_teardown(name, setup, teardown) - -#define SOCK_TEST_PLAIN(name) \ - cmocka_unit_test(name) - -int main(void) -{ - const struct CMUnitTest tests[] = { - /* sock_new / BIO_new_socket */ - SOCK_TEST_PLAIN(test_sock_new_defaults), - SOCK_TEST_PLAIN(test_new_socket), - /* sock_read */ - SOCK_TEST(test_sock_read_noop), - SOCK_TEST(test_sock_read_success), - SOCK_TEST(test_sock_read_eof), - SOCK_TEST(test_sock_read_retry), - SOCK_TEST(test_sock_read_error), - SOCK_TEST(test_sock_read_clears_eof), - /* sock_write */ - SOCK_TEST(test_sock_write_success), - SOCK_TEST(test_sock_write_retry), - SOCK_TEST(test_sock_write_error), - /* sock_ctrl */ - SOCK_TEST(test_ctrl_get_fd), - SOCK_TEST(test_ctrl_get_fd_uninit), - SOCK_TEST(test_ctrl_set_fd), - SOCK_TEST(test_ctrl_get_set_close), - SOCK_TEST(test_ctrl_dup_flush), - SOCK_TEST(test_ctrl_rpoll_descriptor), - SOCK_TEST(test_ctrl_wpoll_descriptor), - SOCK_TEST(test_ctrl_poll_descriptor_uninit), - SOCK_TEST(test_ctrl_eof_clear), - SOCK_TEST(test_ctrl_eof_set), - SOCK_TEST(test_ctrl_get_connect), - SOCK_TEST(test_ctrl_get_connect_bad_num), - SOCK_TEST(test_ctrl_set_connect), - SOCK_TEST(test_ctrl_set_connect_bad_num), - SOCK_TEST(test_ctrl_set_send_flags), - SOCK_TEST(test_ctrl_default), - /* sock_puts */ - SOCK_TEST(test_sock_puts_success), - SOCK_TEST(test_sock_puts_write_fails), - /* sock_free */ - SOCK_TEST(test_free_closes_when_shutdown), - SOCK_TEST(test_free_no_close_when_noclose), - SOCK_TEST(test_free_no_close_when_uninit), - }; - - cmocka_set_message_output(CM_OUTPUT_TAP); - - return cmocka_run_group_tests(tests, NULL, NULL); -} - -#else - -int main(void) -{ - return 0; -} - -#endif /* OPENSSL_NO_SOCK */ diff --git a/test/v3ext.c b/test/v3ext.c index e2b6441197..fc43cb533a 100644 --- a/test/v3ext.c +++ b/test/v3ext.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -17,8 +17,6 @@ #include "testutil.h" -#include - static const char *infile; static int test_pathlen(void) @@ -417,595 +415,6 @@ static int test_ext_syntax(void) return testresult; } -/* - * Number of entries the large-canonize regression tests construct. - * Chosen well above the legacy 4096 cap and large enough that the - * previous O(N^2) merge would be visibly slow under any sanitiser - * configuration, while still small enough to keep CI cost negligible - * with the linear merge. - */ -#define V3EXT_TEST_LARGE_N 8192 - -/* - * Build an ASIdentifiers extension containing V3EXT_TEST_LARGE_N - * adjacent single integers (1, 2, 3, ...), exercise canonize, and - * verify that the entire list collapses to one ASIdOrRange_range and - * that the post-canonize result reports canonical. Stresses the - * linear merge path that replaced the quadratic in-place delete. - */ -static int test_asid_large_canonize_merge(void) -{ - ASIdentifiers *asid = NULL; - ASN1_INTEGER *val = NULL; - int i; - int testresult = 0; - - if (!TEST_ptr(asid = ASIdentifiers_new())) - goto err; - - for (i = 0; i < V3EXT_TEST_LARGE_N; i++) { - if (!TEST_ptr(val = ASN1_INTEGER_new()) - || !TEST_true(ASN1_INTEGER_set_int64(val, (int64_t)(i + 1)))) - goto err; - if (!TEST_true(X509v3_asid_add_id_or_range(asid, V3_ASID_ASNUM, - val, NULL))) - goto err; - /* Ownership of val transferred on success. */ - val = NULL; - } - - if (!TEST_int_eq(sk_ASIdOrRange_num(asid->asnum->u.asIdsOrRanges), - V3EXT_TEST_LARGE_N)) - goto err; - - if (!TEST_true(X509v3_asid_canonize(asid))) - goto err; - - /* The whole list must collapse to a single merged range [1, N]. */ - if (!TEST_int_eq(sk_ASIdOrRange_num(asid->asnum->u.asIdsOrRanges), 1)) - goto err; - { - ASIdOrRange *aor = sk_ASIdOrRange_value(asid->asnum->u.asIdsOrRanges, - 0); - int64_t got_min = 0, got_max = 0; - - if (!TEST_ptr(aor) || !TEST_int_eq(aor->type, ASIdOrRange_range)) - goto err; - if (!TEST_true(ASN1_INTEGER_get_int64(&got_min, aor->u.range->min)) - || !TEST_int64_t_eq(got_min, 1) - || !TEST_true(ASN1_INTEGER_get_int64(&got_max, aor->u.range->max)) - || !TEST_int64_t_eq(got_max, (int64_t)V3EXT_TEST_LARGE_N)) - goto err; - } - - if (!TEST_int_eq(X509v3_asid_is_canonical(asid), 1)) - goto err; - - testresult = 1; -err: - ASN1_INTEGER_free(val); - ASIdentifiers_free(asid); - return testresult; -} - -/* - * Build an ASIdentifiers extension containing V3EXT_TEST_LARGE_N - * non-mergeable single integers (1, 3, 5, ...). After canonize the - * list must be unchanged in length, every entry must remain an id - * with its original value (none silently merged or transformed), and - * is_canonical must report canonical -- i.e. the large list is - * accepted on its merits with no arbitrary cap kicking in. - */ -static int test_asid_large_canonize_no_merge(void) -{ - ASIdentifiers *asid = NULL; - ASN1_INTEGER *val = NULL; - int i; - int testresult = 0; - - if (!TEST_ptr(asid = ASIdentifiers_new())) - goto err; - - for (i = 0; i < V3EXT_TEST_LARGE_N; i++) { - if (!TEST_ptr(val = ASN1_INTEGER_new()) - || !TEST_true(ASN1_INTEGER_set_int64(val, (int64_t)(2 * i + 1)))) - goto err; - if (!TEST_true(X509v3_asid_add_id_or_range(asid, V3_ASID_ASNUM, - val, NULL))) - goto err; - val = NULL; - } - - if (!TEST_true(X509v3_asid_canonize(asid))) - goto err; - - if (!TEST_int_eq(sk_ASIdOrRange_num(asid->asnum->u.asIdsOrRanges), - V3EXT_TEST_LARGE_N)) - goto err; - - /* - * Every entry must still be a single id with its original value; - * adjacent ids should NOT have been merged. - */ - for (i = 0; i < V3EXT_TEST_LARGE_N; i++) { - ASIdOrRange *aor = sk_ASIdOrRange_value(asid->asnum->u.asIdsOrRanges, - i); - int64_t got = 0; - - if (!TEST_ptr(aor) - || !TEST_int_eq(aor->type, ASIdOrRange_id) - || !TEST_true(ASN1_INTEGER_get_int64(&got, aor->u.id)) - || !TEST_int64_t_eq(got, (int64_t)(2 * i + 1))) - goto err; - } - - if (!TEST_int_eq(X509v3_asid_is_canonical(asid), 1)) - goto err; - - testresult = 1; -err: - ASN1_INTEGER_free(val); - ASIdentifiers_free(asid); - return testresult; -} - -/* - * Build an IPAddrBlocks with a single IPv4 family carrying - * V3EXT_TEST_LARGE_N adjacent /32 host prefixes starting at 1.0.0.1 - * (deliberately offset by one from the prefix-aligned 1.0.0.0 so the - * merged span [1.0.0.1, 1.0.32.0] cannot be expressed as a single - * prefix and stays an IPAddressOrRange_addressRange). After canonize - * the family must contain exactly one IPAddressOrRange of type - * addressRange covering the whole block, and is_canonical must - * accept it. Stresses the linear merge path in v3_addr.c. - */ -static int test_addr_large_canonize_merge(void) -{ - IPAddrBlocks *addr = NULL; - int i; - int testresult = 0; - - if (!TEST_ptr(addr = sk_IPAddressFamily_new_null())) - goto end; - - for (i = 0; i < V3EXT_TEST_LARGE_N; i++) { - unsigned char ip[4]; - unsigned int v = 0x01000001u + (unsigned int)i; /* 1.0.0.1 + i */ - - ip[0] = (unsigned char)((v >> 24) & 0xFF); - ip[1] = (unsigned char)((v >> 16) & 0xFF); - ip[2] = (unsigned char)((v >> 8) & 0xFF); - ip[3] = (unsigned char)(v & 0xFF); - if (!TEST_true(X509v3_addr_add_prefix(addr, IANA_AFI_IPV4, NULL, - ip, 32))) - goto end; - } - - if (!TEST_true(X509v3_addr_canonize(addr))) - goto end; - - if (!TEST_int_eq(sk_IPAddressFamily_num(addr), 1)) - goto end; - { - IPAddressFamily *f = sk_IPAddressFamily_value(addr, 0); - IPAddressOrRange *aor; - unsigned char got_min[4], got_max[4]; - unsigned int expected_max = 0x01000001u + V3EXT_TEST_LARGE_N - 1; - unsigned char want_min[4] = { 0x01, 0x00, 0x00, 0x01 }; - unsigned char want_max[4]; - - want_max[0] = (unsigned char)((expected_max >> 24) & 0xFF); - want_max[1] = (unsigned char)((expected_max >> 16) & 0xFF); - want_max[2] = (unsigned char)((expected_max >> 8) & 0xFF); - want_max[3] = (unsigned char)(expected_max & 0xFF); - - if (!TEST_ptr(f) - || !TEST_int_eq(f->ipAddressChoice->type, - IPAddressChoice_addressesOrRanges) - || !TEST_int_eq(sk_IPAddressOrRange_num( - f->ipAddressChoice->u.addressesOrRanges), - 1)) - goto end; - - aor = sk_IPAddressOrRange_value(f->ipAddressChoice->u.addressesOrRanges, - 0); - if (!TEST_ptr(aor) - || !TEST_int_eq(aor->type, IPAddressOrRange_addressRange)) - goto end; - if (!TEST_int_eq(X509v3_addr_get_range(aor, IANA_AFI_IPV4, - got_min, got_max, sizeof(got_min)), - 4) - || !TEST_mem_eq(got_min, 4, want_min, 4) - || !TEST_mem_eq(got_max, 4, want_max, 4)) - goto end; - } - - if (!TEST_int_eq(X509v3_addr_is_canonical(addr), 1)) - goto end; - - testresult = 1; -end: - sk_IPAddressFamily_pop_free(addr, IPAddressFamily_free); - return testresult; -} - -/* - * Interleaved merge / no-merge pattern, exercising the slide-forward - * arm of the linear-sweep compaction in ASIdentifierChoice_canonize. - * - * We build pairs of adjacent integers separated by gaps: (1, 2), (5, 6), - * (9, 10), ... Each pair merges to a single range, so the canonical - * output has exactly V3EXT_TEST_LARGE_N / 2 entries. Critically, after - * the second element of every pair merges into the first the merge - * loop's `write` index falls behind `read`; the *next* (non-mergeable) - * pair-start must then be slid forward into slot `write` and the source - * slot at `read` must be NULL'd. This is the path with no coverage in - * the all-merge or all-no-merge tests. - */ -static int test_asid_interleaved_canonize(void) -{ - ASIdentifiers *asid = NULL; - ASN1_INTEGER *val = NULL; - int i; - int expected = V3EXT_TEST_LARGE_N / 2; - int testresult = 0; - - if (!TEST_ptr(asid = ASIdentifiers_new())) - goto err; - - for (i = 0; i < V3EXT_TEST_LARGE_N; i++) { - /* Pair starts at 4*p, then 4*p+1; the next pair starts at 4*(p+1). */ - int pair = i / 2; - int within = i % 2; - int64_t v = 4 * (int64_t)pair + within + 1; - - if (!TEST_ptr(val = ASN1_INTEGER_new()) - || !TEST_true(ASN1_INTEGER_set_int64(val, v))) - goto err; - if (!TEST_true(X509v3_asid_add_id_or_range(asid, V3_ASID_ASNUM, - val, NULL))) - goto err; - val = NULL; - } - - if (!TEST_true(X509v3_asid_canonize(asid))) - goto err; - - if (!TEST_int_eq(sk_ASIdOrRange_num(asid->asnum->u.asIdsOrRanges), - expected)) - goto err; - - /* Every entry must now be a 2-wide range (the merge result of a pair). */ - for (i = 0; i < expected; i++) { - ASIdOrRange *aor = sk_ASIdOrRange_value(asid->asnum->u.asIdsOrRanges, i); - - if (!TEST_ptr(aor) || !TEST_int_eq(aor->type, ASIdOrRange_range)) - goto err; - } - - if (!TEST_int_eq(X509v3_asid_is_canonical(asid), 1)) - goto err; - - testresult = 1; -err: - ASN1_INTEGER_free(val); - ASIdentifiers_free(asid); - return testresult; -} - -/* - * IP-address counterpart to test_asid_interleaved_canonize: pairs of - * adjacent /32 prefixes separated by a gap of 2, so each pair merges - * but the next pair-start must be slid forward. - */ -static int test_addr_interleaved_canonize(void) -{ - IPAddrBlocks *addr = NULL; - int i; - int expected = V3EXT_TEST_LARGE_N / 2; - int testresult = 0; - - if (!TEST_ptr(addr = sk_IPAddressFamily_new_null())) - goto end; - - for (i = 0; i < V3EXT_TEST_LARGE_N; i++) { - unsigned char ip[4]; - unsigned int pair = (unsigned int)(i / 2); - unsigned int within = (unsigned int)(i % 2); - unsigned int v = 0x01000000u + 4u * pair + within; - - ip[0] = (unsigned char)((v >> 24) & 0xFF); - ip[1] = (unsigned char)((v >> 16) & 0xFF); - ip[2] = (unsigned char)((v >> 8) & 0xFF); - ip[3] = (unsigned char)(v & 0xFF); - if (!TEST_true(X509v3_addr_add_prefix(addr, IANA_AFI_IPV4, NULL, - ip, 32))) - goto end; - } - - if (!TEST_true(X509v3_addr_canonize(addr))) - goto end; - - if (!TEST_int_eq(sk_IPAddressFamily_num(addr), 1)) - goto end; - { - IPAddressFamily *f = sk_IPAddressFamily_value(addr, 0); - - if (!TEST_ptr(f) - || !TEST_int_eq(f->ipAddressChoice->type, - IPAddressChoice_addressesOrRanges) - || !TEST_int_eq(sk_IPAddressOrRange_num( - f->ipAddressChoice->u.addressesOrRanges), - expected)) - goto end; - } - - if (!TEST_int_eq(X509v3_addr_is_canonical(addr), 1)) - goto end; - - testresult = 1; -end: - sk_IPAddressFamily_pop_free(addr, IPAddressFamily_free); - return testresult; -} - -/* - * Trigger an overlap-detection error partway through the linear - * merge. The first V3EXT_TEST_LARGE_N / 2 entries are adjacent and - * mergeable; entry K is a duplicate of entry K-1 (overlap). The - * canonize call must return 0, and the caller's normal teardown of - * the choice must safely free the stack -- some slots hold merged - * results, some hold NULL (from earlier merges), and some hold - * originals that the loop never reached. ASan / UBSan-instrumented - * builds will catch any double-free or use-after-free in the - * teardown that the mixed-state-on-error invariant claims to avoid. - */ -static int test_asid_canonize_error_midsweep(void) -{ - ASIdentifiers *asid = NULL; - ASN1_INTEGER *val = NULL; - int i; - int n = V3EXT_TEST_LARGE_N; - int k = n / 2; - int testresult = 0; - - if (!TEST_ptr(asid = ASIdentifiers_new())) - goto err; - - for (i = 0; i < n; i++) { - /* - * Entries 1..k are 1,2,...,k (all adjacent). - * Entry k+1 duplicates entry k (overlap, triggers the error). - * Remaining entries are far away so they sort after the overlap. - */ - int64_t v; - - if (i < k) - v = (int64_t)i + 1; - else if (i == k) - v = (int64_t)k; /* duplicate, overlap */ - else - v = (int64_t)i + 1000000; /* far suffix, untouched */ - - if (!TEST_ptr(val = ASN1_INTEGER_new()) - || !TEST_true(ASN1_INTEGER_set_int64(val, v))) - goto err; - if (!TEST_true(X509v3_asid_add_id_or_range(asid, V3_ASID_ASNUM, - val, NULL))) - goto err; - val = NULL; - } - - /* canonize must reject overlap. */ - if (!TEST_int_eq(X509v3_asid_canonize(asid), 0)) - goto err; - - /* - * Successful return below relies on ASIdentifiers_free walking - * the partially-compacted stack without UAF or double-free. - * Under ASan / UBSan that walk is the actual test. - */ - testresult = 1; -err: - ASN1_INTEGER_free(val); - ASIdentifiers_free(asid); - return testresult; -} - -/* - * Trigger an overlap-detection error partway through the linear merge - * in IPAddressOrRanges_canonize. Construct a list whose first half is - * adjacent and mergeable, with a duplicate at position k that hits the - * overlap check after a series of merges has driven write < read. - * The canonize call must return 0, and the family's normal teardown - * (sk_IPAddressFamily_pop_free) must safely walk the partially - * compacted stack -- ASan / UBSan catches any double-free or UAF the - * mixed-state-on-error invariant would otherwise miss. Because the - * v3_addr.c canonize uses direct `return 0` rather than a `done:` - * cleanup label, the teardown invariant for this file is different - * from the asid path and warrants its own coverage. - */ -static int test_addr_canonize_error_midsweep(void) -{ - IPAddrBlocks *addr = NULL; - int i; - int n = V3EXT_TEST_LARGE_N; - int k = n / 2; - int testresult = 0; - - if (!TEST_ptr(addr = sk_IPAddressFamily_new_null())) - goto end; - - for (i = 0; i < n; i++) { - unsigned char ip[4]; - unsigned int v; - - if (i < k) - v = 0x01000000u + (unsigned int)i; /* adjacent /32 prefixes */ - else if (i == k) - v = 0x01000000u + (unsigned int)(k - 1); /* duplicate, overlap */ - else - v = 0x02000000u + (unsigned int)i; /* far suffix, untouched */ - - ip[0] = (unsigned char)((v >> 24) & 0xFF); - ip[1] = (unsigned char)((v >> 16) & 0xFF); - ip[2] = (unsigned char)((v >> 8) & 0xFF); - ip[3] = (unsigned char)(v & 0xFF); - if (!TEST_true(X509v3_addr_add_prefix(addr, IANA_AFI_IPV4, NULL, - ip, 32))) - goto end; - } - - /* canonize must reject overlap. */ - if (!TEST_int_eq(X509v3_addr_canonize(addr), 0)) - goto end; - - /* - * Successful return below relies on sk_IPAddressFamily_pop_free - * walking the partially-compacted aors stack without UAF or - * double-free. Under ASan / UBSan that walk is the actual test. - */ - testresult = 1; -end: - sk_IPAddressFamily_pop_free(addr, IPAddressFamily_free); - return testresult; -} - -/* - * Exercise the merge arm where `cur` is itself a range (rather than a - * single integer), hitting the `case ASIdOrRange_range` detach branch - * in ASIdentifierChoice_canonize. Build adjacent 2-wide ranges - * [1,2], [3,4], [5,6], ... which all fold into a single big range - * [1, 2 * V3EXT_TEST_LARGE_N]. - */ -static int test_asid_range_merge_canonize(void) -{ - ASIdentifiers *asid = NULL; - ASN1_INTEGER *minv = NULL, *maxv = NULL; - int i; - int testresult = 0; - - if (!TEST_ptr(asid = ASIdentifiers_new())) - goto err; - - for (i = 0; i < V3EXT_TEST_LARGE_N; i++) { - if (!TEST_ptr(minv = ASN1_INTEGER_new()) - || !TEST_true(ASN1_INTEGER_set_int64(minv, - (int64_t)(2 * i + 1))) - || !TEST_ptr(maxv = ASN1_INTEGER_new()) - || !TEST_true(ASN1_INTEGER_set_int64(maxv, - (int64_t)(2 * i + 2)))) - goto err; - if (!TEST_true(X509v3_asid_add_id_or_range(asid, V3_ASID_ASNUM, - minv, maxv))) - goto err; - minv = maxv = NULL; - } - - if (!TEST_true(X509v3_asid_canonize(asid))) - goto err; - - if (!TEST_int_eq(sk_ASIdOrRange_num(asid->asnum->u.asIdsOrRanges), 1)) - goto err; - { - ASIdOrRange *aor = sk_ASIdOrRange_value(asid->asnum->u.asIdsOrRanges, - 0); - int64_t got_min = 0, got_max = 0; - - if (!TEST_ptr(aor) || !TEST_int_eq(aor->type, ASIdOrRange_range)) - goto err; - /* - * The merged range must cover [1, 2 * V3EXT_TEST_LARGE_N]; - * incorrect max-propagation would still leave a single range - * but with a truncated upper bound. - */ - if (!TEST_true(ASN1_INTEGER_get_int64(&got_min, aor->u.range->min)) - || !TEST_int64_t_eq(got_min, 1) - || !TEST_true(ASN1_INTEGER_get_int64(&got_max, aor->u.range->max)) - || !TEST_int64_t_eq(got_max, (int64_t)(2 * V3EXT_TEST_LARGE_N))) - goto err; - } - - if (!TEST_int_eq(X509v3_asid_is_canonical(asid), 1)) - goto err; - - testresult = 1; -err: - ASN1_INTEGER_free(minv); - ASN1_INTEGER_free(maxv); - ASIdentifiers_free(asid); - return testresult; -} - -/* - * Trigger the inverted-range guard partway through the linear merge - * in ASIdentifierChoice_canonize. The first half of the list is - * well-formed adjacent integers; entry k is an explicitly inverted - * range (min = 1000, max = 100). X509v3_asid_add_id_or_range does - * not validate min <= max for ranges, so the bad entry is admitted - * into the list, and canonize must detect it on the sweep. The - * teardown under ASan / UBSan verifies that the early-exit path - * leaves the asIdsOrRanges stack in a freeable state. - * - * The addr-side counterpart of this branch (v3_addr.c:849) is not - * reachable through the public API: make_addressRange refuses to - * construct an inverted IPAddressOrRange in the first place. The - * guard remains as defence against a DER-decoded extension that - * carries inverted min/max bit strings; exercising it from C would - * require hand-building an IPAddressOrRange, which would bind the - * test to internal ASN.1 layout. - */ -static int test_asid_canonize_inverted_midsweep(void) -{ - ASIdentifiers *asid = NULL; - ASN1_INTEGER *val = NULL, *minv = NULL, *maxv = NULL; - int i; - int n = V3EXT_TEST_LARGE_N; - int k = n / 2; - int testresult = 0; - - if (!TEST_ptr(asid = ASIdentifiers_new())) - goto err; - - for (i = 0; i < n; i++) { - if (i == k) { - /* Inverted range: min=1000, max=100. */ - if (!TEST_ptr(minv = ASN1_INTEGER_new()) - || !TEST_true(ASN1_INTEGER_set_int64(minv, 1000)) - || !TEST_ptr(maxv = ASN1_INTEGER_new()) - || !TEST_true(ASN1_INTEGER_set_int64(maxv, 100))) - goto err; - if (!TEST_true(X509v3_asid_add_id_or_range(asid, V3_ASID_ASNUM, - minv, maxv))) - goto err; - minv = maxv = NULL; - } else { - int64_t v = (i < k) ? (int64_t)i + 1 - : (int64_t)i + 1000000; /* far suffix */ - - if (!TEST_ptr(val = ASN1_INTEGER_new()) - || !TEST_true(ASN1_INTEGER_set_int64(val, v))) - goto err; - if (!TEST_true(X509v3_asid_add_id_or_range(asid, V3_ASID_ASNUM, - val, NULL))) - goto err; - val = NULL; - } - } - - /* canonize must reject the inverted entry. */ - if (!TEST_int_eq(X509v3_asid_canonize(asid), 0)) - goto err; - - testresult = 1; -err: - ASN1_INTEGER_free(val); - ASN1_INTEGER_free(minv); - ASN1_INTEGER_free(maxv); - ASIdentifiers_free(asid); - return testresult; -} - static int test_addr_subset(void) { int i; @@ -1069,15 +478,6 @@ int setup_tests(void) ADD_TEST(test_ext_syntax); ADD_TEST(test_addr_fam_len); ADD_TEST(test_addr_subset); - ADD_TEST(test_asid_large_canonize_merge); - ADD_TEST(test_asid_large_canonize_no_merge); - ADD_TEST(test_addr_large_canonize_merge); - ADD_TEST(test_asid_interleaved_canonize); - ADD_TEST(test_addr_interleaved_canonize); - ADD_TEST(test_asid_canonize_error_midsweep); - ADD_TEST(test_addr_canonize_error_midsweep); - ADD_TEST(test_asid_range_merge_canonize); - ADD_TEST(test_asid_canonize_inverted_midsweep); #endif /* OPENSSL_NO_RFC3779 */ return 1; } diff --git a/test/v3nametest.c b/test/v3nametest.c index 757db8a18e..c73067d947 100644 --- a/test/v3nametest.c +++ b/test/v3nametest.c @@ -10,14 +10,11 @@ #include #include -#include #include #include #include "internal/nelem.h" #include "testutil.h" -#if !defined(OPENSSL_NO_DEPRECATED_4_1) -OSSL_BEGIN_ALLOW_DEPRECATED static const char *const names[] = { "a", "b", ".", "*", "@", ".a", "a.", ".b", "b.", ".*", "*.", "*@", "@*", "a@", "@a", "b@", "..", @@ -149,7 +146,7 @@ static int set_altname(X509 *crt, ...) ia5 = ASN1_IA5STRING_new(); if (ia5 == NULL) goto out; - if (!ASN1_STRING_set_string(ia5, name)) + if (!ASN1_STRING_set(ia5, name, -1)) goto out; switch (type) { case GEN_EMAIL: @@ -230,8 +227,6 @@ static int set_altname_email(X509 *crt, const char *name) { return set_altname(crt, GEN_EMAIL, name, 0); } -OSSL_END_ALLOW_DEPRECATED -#endif /* !defined(OPENSSL_NO_DEPRECATED_4_1) */ struct set_name_fn { int (*fn)(X509 *, const char *); @@ -240,8 +235,6 @@ struct set_name_fn { int email; }; -#if !defined(OPENSSL_NO_DEPRECATED_4_1) -OSSL_BEGIN_ALLOW_DEPRECATED static const struct set_name_fn name_fns[] = { { set_cn1, "set CN", 1, 0 }, { set_cn2, "set CN", 1, 0 }, @@ -365,8 +358,6 @@ static int call_run_cert(int i) } return failed == 0; } -OSSL_END_ALLOW_DEPRECATED -#endif /* !defined(OPENSSL_NO_DEPRECATED_4_1) */ static struct gennamedata { const unsigned char der[22]; @@ -666,9 +657,7 @@ end: int setup_tests(void) { -#if !defined(OPENSSL_NO_DEPRECATED_4_1) ADD_ALL_TESTS(call_run_cert, OSSL_NELEM(name_fns)); -#endif /* !defined(OPENSSL_NO_DEPRECATED_4_1) */ ADD_TEST(test_GENERAL_NAME_cmp); return 1; } diff --git a/test/verify_extra_test.c b/test/verify_extra_test.c index 37ac46356a..ad2649034f 100644 --- a/test/verify_extra_test.c +++ b/test/verify_extra_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2015-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2015-2022 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -108,8 +108,7 @@ static int test_distinguishing_id(void) { X509 *x = NULL; int ret = 0; - ASN1_OCTET_STRING *v = NULL; - const ASN1_OCTET_STRING *v2 = NULL; + ASN1_OCTET_STRING *v = NULL, *v2 = NULL; char *distid = "this is an ID"; x = load_cert_from_file(bad_f); @@ -202,482 +201,6 @@ static int test_self_signed(const char *filename, int use_trusted, int expected) return ret; } -static const char *multiname_cert[] = { - "-----BEGIN CERTIFICATE-----\n" - "MIIFnDCCBISgAwIBAgIUTgfdSQm2hjgUZoA8jeQX7sDPAoowDQYJKoZIhvcNAQEL\n" - "BQAwgYUxCzAJBgNVBAYTAkNBMRAwDgYDVQQIDAdBbGJlcnRhMREwDwYDVQQHDAhF\n" - "ZG1vbnRvbjERMA8GA1UECgwITXVwcGV0cnkxITAfBgNVBAsMGFN0YXRsZXIgYW5k\n" - "IFdhbGRvcmYgUiBVUzEbMBkGA1UEAwwSYmVha2VyLm11cHBldHJ5LmNhMB4XDTI2\n" - "MDExMjIwNTUwOVoXDTI3MDExMjIwNTUwOVowgYUxCzAJBgNVBAYTAkNBMRAwDgYD\n" - "VQQIDAdBbGJlcnRhMREwDwYDVQQHDAhFZG1vbnRvbjERMA8GA1UECgwITXVwcGV0\n" - "cnkxITAfBgNVBAsMGFN0YXRsZXIgYW5kIFdhbGRvcmYgUiBVUzEbMBkGA1UEAwwS\n" - "YmVha2VyLm11cHBldHJ5LmNhMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKC\n" - "AQEA+EsGQCX4YyZF3QbVcFUcWpYDp8MJHr5vF0cosvj9afGPhpLREWR7EmnNA8Gf\n" - "wb+ef/jNrDg8W81uDD3N29PvbM+hHAQPaHrRupQZ+W+uIVEAu/lpI359jIRS1Sey\n" - "IcU2vIgn3Tlnv4UX3o3QMyH8+RcCvSNrWu4+f9ipMAy/xq3PWBm+fHi/+bI03eDy\n" - "0xNm8kpXbhqZQiZ1tAhsTa3V2pIufqAnctDgl2GUHtfmKO095OHimjhQXHxO8Ctk\n" - "R+vFv0nleJoAAfkmaMdtdTd1O8m3AtQv6xQC4X5Tu/+FKKQOXjf/8OtqW2lrlxxR\n" - "pbFuy66I9HVyf+gGWEbZyqbCpwIDAQABo4ICADCCAfwwggG3BgNVHREEggGuMIIB\n" - "qoILbXVwcGV0cnkuY2GCD3d3dy5tdXBwZXRyeS5jYYITc3RhdGxlci5tdXBwZXRy\n" - "eS5jYYITd2FsZG9yZi5tdXBwZXRyeS5jYYETc3RhdGxlckBtdXBwdGVyeS5jYYET\n" - "d2FsZG9yZkBtdXBwdGVyeS5jYYcExikABIcQIAEFA7o+AAAAAAAAAAIAMIcEqveq\n" - "AocQKAEBuAAQAAAAAAAAAAAAC4cEwCEEDIcQIAEFAAACAAAAAAAAAAAADIcExwdb\n" - "DYcQIAEFAAAtAAAAAAAAAAAADYcEwMvmCocQIAEFAACoAAAAAAAAAAAADocEwAUF\n" - "8YcQIAEFAAAvAAAAAAAAAAAAD4cEwHAkBIcQIAEFAAASAAAAAAAAAAANDYcExmG+\n" - "NYcQIAEFAAABAAAAAAAAAAAAU4cEwCSUEYcQIAEH/gAAAAAAAAAAAAAAU4cEwDqA\n" - "HocQIAEFAwwnAAAAAAAAAAIAMIcEwQAOgYcQIAEH/QAAAAAAAAAAAAAAAYcExwdT\n" - "KocQIAEFAACfAAAAAAAAAAAAQocEygwbIYcQIAENwwAAAAAAAAAAAAAANTALBgNV\n" - "HQ8EBAMCBDAwEwYDVR0lBAwwCgYIKwYBBQUHAwEwHQYDVR0OBBYEFCutBN63ufhB\n" - "IY4dOuFcYfC3p+mMMA0GCSqGSIb3DQEBCwUAA4IBAQBBWfTvwxV1s3xaS5Ko6T7B\n" - "vS7TPih0MO8auv0mvZXG3jy/LfAfgu05PbGIf0dzFhBpoZD0VrrugmdemLkJd+u6\n" - "pbEttGFZtcGb//MtjUAYQnEq6fYgDeT0dGU0upwQPWGgh5LpFSab+71C6Ofc3YFM\n" - "WPH7UaRBUV2mqNtUokOce6kYtl97St7p6cGpQW9Q1uFQODvAm3ZPq/YNGnTJAOdb\n" - "9UX8Td1T5fH86H0hb6qB0AEhVdgjPUgs33zYNWRPg8fYleT6w1MpE2HaUqqhld3B\n" - "ZtVZ5IznkY+8qH0rua89m4TV3qzUqNVUL0uxkWnQI3W8g3Adin7QN3EA6ZYrTD3q\n" - "-----END CERTIFICATE-----\n", - NULL, -}; - -static const time_t multiname_valid_at = 1768253189; - -static const char *multiname_dnsnames[] = { - "muppetry.ca", - "www.muppetry.ca", - "statler.muppetry.ca", - "waldorf.muppetry.ca", - NULL, -}; - -static const char *multiname_emails[] = { - "statler@mupptery.ca", - "waldorf@mupptery.ca", - NULL, -}; - -static const char *multiname_ips[] = { - "198.41.0.4", - "2001:503:ba3e::2:30", - "170.247.170.2", - "2801:1b8:10::b", - "192.33.4.12", - "2001:500:2::c", - "199.7.91.13", - "2001:500:2d::d", - "192.203.230.10", - "2001:500:a8::e", - "192.5.5.241", - "2001:500:2f::f", - "192.112.36.4", - "2001:500:12::d0d", - "198.97.190.53", - "2001:500:1::53", - "192.36.148.17", - "2001:7fe::53", - "192.58.128.30", - "2001:503:c27::2:30", - "193.0.14.129", - "2001:7fd::1", - "199.7.83.42", - "2001:500:9f::42", - "202.12.27.33", - "2001:dc3::35", - NULL, -}; - -static int test_multiname_selfsigned(void) -{ - X509 *cert = NULL; - X509_STORE_CTX *ctx = NULL; - X509_STORE *store = NULL; - X509_VERIFY_PARAM *vpm = NULL; - int fails = 0; - int ret = 0; - - if (!TEST_ptr((cert = X509_from_strings(multiname_cert)))) - goto err; - - if (!TEST_true(X509_self_signed(cert, 1))) - goto err; - - if (!TEST_ptr(store = X509_STORE_new())) - goto err; - - if (!TEST_true(X509_STORE_add_cert(store, cert))) - goto err; - - if (!TEST_ptr((vpm = X509_STORE_get0_param(store)))) - goto err; - - if (!TEST_ptr(ctx = X509_STORE_CTX_new())) - goto err; - - X509_VERIFY_PARAM_set_time(vpm, multiname_valid_at); - - for (size_t i = 0; multiname_dnsnames[i] != NULL; i++) { - /* Try one not in the certificate */ - if (!TEST_true(X509_VERIFY_PARAM_set1_host(vpm, "bunsen.muppetry.ca", 0))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_false(X509_verify_cert(ctx))) { - TEST_info("Verify succeeded for non-present name bunsen.muppetry.ca\n"); - goto err; - } - X509_STORE_CTX_cleanup(ctx); - if (!TEST_true(X509_VERIFY_PARAM_set1_host(vpm, NULL, 0))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_true(X509_verify_cert(ctx))) - goto err; - X509_STORE_CTX_cleanup(ctx); - if (!TEST_true(X509_VERIFY_PARAM_set1_host(vpm, multiname_dnsnames[i], strlen(multiname_dnsnames[i])))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_true(X509_verify_cert(ctx))) { - TEST_info("Verify failed for initial name %s\n", multiname_dnsnames[i]); - fails++; - } - X509_STORE_CTX_cleanup(ctx); - for (size_t j = 0; multiname_dnsnames[j] != NULL; j++) { - if (j != i) { - if (!TEST_true(X509_VERIFY_PARAM_add1_host(vpm, multiname_dnsnames[j], 0))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_true(X509_verify_cert(ctx))) { - TEST_info("Verify failed with added name %s\n", multiname_dnsnames[j]); - fails++; - } - X509_STORE_CTX_cleanup(ctx); - } - } - /* Try the CN */ - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_true(X509_VERIFY_PARAM_set1_host(vpm, "beaker.muppetry.ca", 0))) - goto err; - if (!TEST_true(X509_verify_cert(ctx))) { - TEST_info("Verify failed for CN name beaker.muppetry.ca\n"); - fails++; - } - X509_STORE_CTX_cleanup(ctx); - if (!TEST_true(X509_VERIFY_PARAM_set1_host(vpm, NULL, 0))) - goto err; - /* Try the domain with . */ - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_true(X509_VERIFY_PARAM_set1_host(vpm, ".muppetry.ca", 0))) - goto err; - if (!TEST_true(X509_verify_cert(ctx))) { - TEST_info("Verify failed for domain name .muppetry.ca\n"); - fails++; - } - X509_STORE_CTX_cleanup(ctx); - if (!TEST_true(X509_VERIFY_PARAM_set1_host(vpm, NULL, 0))) - goto err; - } - - for (size_t i = 0; multiname_emails[i] != NULL; i++) { - /* Try one not in the certificate */ - if (!TEST_true(X509_VERIFY_PARAM_set1_email(vpm, "bunsen@muppetry.ca", 0))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_false(X509_verify_cert(ctx))) { - TEST_info("Verify succeeded for non-present name bunsen@muppetry.ca\n"); - goto err; - } - X509_STORE_CTX_cleanup(ctx); - if (!TEST_true(X509_VERIFY_PARAM_set1_email(vpm, NULL, 0))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_true(X509_verify_cert(ctx))) - goto err; - X509_STORE_CTX_cleanup(ctx); - if (!TEST_true(X509_VERIFY_PARAM_set1_email(vpm, multiname_emails[i], strlen(multiname_emails[i])))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_true(X509_verify_cert(ctx))) { - TEST_info("Verify failed for initial name %s\n", multiname_emails[i]); - fails++; - } - X509_STORE_CTX_cleanup(ctx); - for (size_t j = 0; multiname_emails[j] != NULL; j++) { - if (j != i) { - if (!TEST_true(X509_VERIFY_PARAM_add1_rfc822(vpm, multiname_emails[j], 0))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_true(X509_verify_cert(ctx))) { - TEST_info("Verify failed with added name %s\n", multiname_emails[j]); - fails++; - } - X509_STORE_CTX_cleanup(ctx); - } - } - X509_STORE_CTX_cleanup(ctx); - if (!TEST_true(X509_VERIFY_PARAM_set1_email(vpm, NULL, 0))) - goto err; - } - - for (size_t i = 0; multiname_ips[i] != NULL; i++) { - /* Try one not in the certificate */ - if (!TEST_true(X509_VERIFY_PARAM_set1_ip_asc(vpm, "8.8.8.8"))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_false(X509_verify_cert(ctx))) { - TEST_info("Verify succeeded for non-present name 8.8.8.8\n"); - goto err; - } - X509_STORE_CTX_cleanup(ctx); - if (!TEST_true(X509_VERIFY_PARAM_set1_ip_asc(vpm, NULL))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_true(X509_verify_cert(ctx))) - goto err; - X509_STORE_CTX_cleanup(ctx); - if (!TEST_true(X509_VERIFY_PARAM_set1_ip_asc(vpm, multiname_ips[i]))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_true(X509_verify_cert(ctx))) { - TEST_info("Verify failed for initial name %s\n", multiname_ips[i]); - fails++; - } - X509_STORE_CTX_cleanup(ctx); - for (size_t j = 0; multiname_ips[j] != NULL; j++) { - if (j != i) { - if (!TEST_true(X509_VERIFY_PARAM_add1_ip_asc(vpm, multiname_ips[j]))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_true(X509_verify_cert(ctx))) { - TEST_info("Verify failed with added name %s\n", multiname_ips[j]); - fails++; - } - X509_STORE_CTX_cleanup(ctx); - } - } - X509_STORE_CTX_cleanup(ctx); - if (!TEST_true(X509_VERIFY_PARAM_set1_ip_asc(vpm, NULL))) - goto err; - } - - /* - * Test that individual categories work together, and a non-match will still fail validation - */ - - /* A dnsname, email and ip that are all valid in the cert should succeed */ - if (!TEST_true(X509_VERIFY_PARAM_set1_host(vpm, "www.muppetry.ca", 0))) - goto err; - if (!TEST_true(X509_VERIFY_PARAM_set1_ip_asc(vpm, "2001:503:ba3e::2:30"))) - goto err; - if (!TEST_true(X509_VERIFY_PARAM_set1_email(vpm, "waldorf@mupptery.ca", 0))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_true(X509_verify_cert(ctx))) - fails++; - X509_STORE_CTX_cleanup(ctx); - - /* Setting an non-matching email should fail validation even with valid dnsname and ip */ - if (!TEST_true(X509_VERIFY_PARAM_set1_email(vpm, "bunsen@mupptery.ca", 0))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_false(X509_verify_cert(ctx))) - fails++; - X509_STORE_CTX_cleanup(ctx); - /* reset */ - if (!TEST_true(X509_VERIFY_PARAM_set1_email(vpm, "waldorf@mupptery.ca", 0))) - goto err; - - /* Setting an non-matching ip should fail validation even with valid dnsname and email */ - if (!TEST_true(X509_VERIFY_PARAM_set1_ip_asc(vpm, "199.185.178.80"))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_false(X509_verify_cert(ctx))) - fails++; - X509_STORE_CTX_cleanup(ctx); - /* reset */ - if (!TEST_true(X509_VERIFY_PARAM_set1_ip_asc(vpm, "2001:503:ba3e::2:30"))) - goto err; - - /* Setting an non-matching dnsname should fail validation even with valid ip and email */ - if (!TEST_true(X509_VERIFY_PARAM_set1_host(vpm, "www.libressl.org", 0))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_false(X509_verify_cert(ctx))) - fails++; - X509_STORE_CTX_cleanup(ctx); - /* reset */ - if (!TEST_true(X509_VERIFY_PARAM_set1_host(vpm, "www.muppetry.ca", 0))) - goto err; - - /* Adding non-matching values to each category with a match will still succeed */ - if (!TEST_true(X509_VERIFY_PARAM_add1_host(vpm, "www.libressl.org", 0))) - goto err; - if (!TEST_true(X509_VERIFY_PARAM_add1_ip_asc(vpm, "199.185.178.80"))) - goto err; - if (!TEST_true(X509_VERIFY_PARAM_add1_rfc822(vpm, "beck@openbsd.org", 0))) - goto err; - if (!TEST_true(X509_VERIFY_PARAM_add1_smtputf8(vpm, "学生@muppetry.ca", 0))) - goto err; - if (!TEST_true(X509_STORE_CTX_init(ctx, store, cert, NULL))) - goto err; - if (!TEST_true(X509_verify_cert(ctx))) - fails++; - X509_STORE_CTX_cleanup(ctx); - - ret = fails == 0; - -err: - X509_STORE_free(store); - X509_STORE_CTX_free(ctx); - X509_free(cert); - return ret; -} - -static int yolo_name_validation(const char *name, size_t len) -{ - return 1; -} - -static int yolo_ip_validation(const uint8_t *name, size_t len) -{ - return 1; -} - -static const char *valid_emails[] = { - "@bb", - "b@bb", - "b@b-b", - "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa@bb", - "b@aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa", - "b@aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa." - "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb." - "ccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc." - "ddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd", - NULL, -}; - -static const char *invalid_emails[] = { - "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa@bb", - "b@b", - "b@bb.", - "b@bb..bb", - "b@bb-.bb", - "b@-bb.bb", - "b@bb.-bb", - "@", - "@b", - "b@aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa", - "b@aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa." - "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb." - "ccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc." - "dddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddddd", - NULL, -}; - -static int test_vpm_input_validation(void) -{ - const char *utf8mail = "学生@muppetry.ca"; - const char *rfc822mail = "beaker@muppetry.ca"; - X509_VERIFY_PARAM *vpm = NULL; - int ret = 0; - - if (!TEST_ptr(vpm = X509_VERIFY_PARAM_new())) - goto err; - - if (!TEST_false(X509_VERIFY_PARAM_set1_rfc822(vpm, utf8mail, 0))) - goto err; - if (!TEST_false(X509_VERIFY_PARAM_set1_smtputf8(vpm, rfc822mail, 0))) - goto err; - if (!TEST_true(X509_VERIFY_PARAM_set1_rfc822(vpm, rfc822mail, 0))) - goto err; - if (!TEST_true(X509_VERIFY_PARAM_set1_smtputf8(vpm, utf8mail, 0))) - goto err; - if (!TEST_true(X509_VERIFY_PARAM_set1_email(vpm, rfc822mail, 0))) - goto err; - if (!TEST_true(X509_VERIFY_PARAM_set1_email(vpm, utf8mail, 0))) - goto err; - - for (size_t i = 0; multiname_dnsnames[i] != NULL; i++) { - if (!TEST_true(X509_VERIFY_PARAM_set1_host(vpm, multiname_dnsnames[i], 0))) - goto err; - if (!TEST_false(X509_VERIFY_PARAM_set1_email(vpm, multiname_dnsnames[i], 0))) - goto err; - } - for (size_t i = 0; multiname_emails[i] != NULL; i++) { - if (!TEST_true(X509_VERIFY_PARAM_set1_email(vpm, multiname_emails[i], 0))) - goto err; - if (!TEST_false(X509_VERIFY_PARAM_set1_host(vpm, multiname_emails[i], 0))) - goto err; - } - for (size_t i = 0; valid_emails[i] != NULL; i++) { - if (!TEST_true(X509_VERIFY_PARAM_set1_email(vpm, valid_emails[i], 0))) - goto err; - } - for (size_t i = 0; invalid_emails[i] != NULL; i++) { - if (!TEST_false(X509_VERIFY_PARAM_set1_email(vpm, invalid_emails[i], 0))) - goto err; - } - for (size_t i = 0; multiname_ips[i] != NULL; i++) { - size_t l = strlen(multiname_ips[i]); - if (!TEST_true(X509_VERIFY_PARAM_set1_ip_asc(vpm, multiname_ips[i]))) - goto err; - if (l == 4 || l == 16) { - if (!TEST_true(X509_VERIFY_PARAM_set1_ip(vpm, (const uint8_t *)multiname_ips[i], l))) - goto err; - } else { - if (!TEST_false(X509_VERIFY_PARAM_set1_ip(vpm, (const uint8_t *)multiname_ips[i], l))) - goto err; - } - } - - X509_VERIFY_PARAM_set1_host_input_validation(vpm, yolo_name_validation); - X509_VERIFY_PARAM_set1_rfc822_input_validation(vpm, yolo_name_validation); - X509_VERIFY_PARAM_set1_smtputf8_input_validation(vpm, yolo_name_validation); - X509_VERIFY_PARAM_set1_ip_input_validation(vpm, yolo_ip_validation); - for (size_t i = 0; multiname_dnsnames[i] != NULL; i++) { - /* should still work */ - if (!TEST_true(X509_VERIFY_PARAM_set1_host(vpm, multiname_dnsnames[i], 0))) - goto err; - /* should be accepted now */ - if (!TEST_true(X509_VERIFY_PARAM_set1_email(vpm, multiname_dnsnames[i], 0))) - goto err; - } - for (size_t i = 0; multiname_emails[i] != NULL; i++) { - /* should still work */ - if (!TEST_true(X509_VERIFY_PARAM_set1_email(vpm, multiname_emails[i], 0))) - goto err; - /* should be accepted now */ - if (!TEST_true(X509_VERIFY_PARAM_set1_host(vpm, multiname_emails[i], 0))) - goto err; - } - for (size_t i = 0; multiname_ips[i] != NULL; i++) { - if (!TEST_true(X509_VERIFY_PARAM_set1_ip_asc(vpm, multiname_ips[i]))) - goto err; - /* should be accepted now */ - if (!TEST_true(X509_VERIFY_PARAM_set1_ip(vpm, (const uint8_t *)multiname_ips[i], strlen(multiname_ips[i])))) - goto err; - } - - ret = 1; - -err: - X509_VERIFY_PARAM_free(vpm); - return ret; -} - static int test_self_signed_good(void) { return test_self_signed(root_f, 1, 1); @@ -798,8 +321,6 @@ int setup_tests(void) ADD_TEST(test_purpose_ssl_client); ADD_TEST(test_purpose_ssl_server); ADD_TEST(test_purpose_any); - ADD_TEST(test_multiname_selfsigned); - ADD_TEST(test_vpm_input_validation); return 1; err: cleanup_tests(); diff --git a/test/x509_internal_test.c b/test/x509_internal_test.c index 1176ef49ef..ec99024716 100644 --- a/test/x509_internal_test.c +++ b/test/x509_internal_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -152,7 +152,7 @@ static int test_a2i_ipaddress(int idx) { int good = 1; ASN1_OCTET_STRING *ip; - size_t len = a2i_ipaddress_tests[idx].length; + int len = a2i_ipaddress_tests[idx].length; ip = a2i_IPADDRESS(a2i_ipaddress_tests[idx].ipasc); if (len == 0) { @@ -162,7 +162,7 @@ static int test_a2i_ipaddress(int idx) } } else { if (!TEST_ptr(ip) - || !TEST_size_t_eq(ASN1_STRING_length_ex(ip), len) + || !TEST_int_eq(ASN1_STRING_length(ip), len) || !TEST_mem_eq(ASN1_STRING_get0_data(ip), len, a2i_ipaddress_tests[idx].data, len)) { good = 0; @@ -308,8 +308,8 @@ static int test_a_time(X509_STORE_CTX *ctx, X509 *x509, return 1; } error = 0; - if (X509_check_certificate_times(vpm, x509, &error) != expected_value) { - TEST_info("%s:%d - X509_check_certificate_times %s unexpectedly " + if (ossl_x509_check_certificate_times(vpm, x509, &error) != expected_value) { + TEST_info("%s:%d - ossl_X509_check_certificate_times %s unexpectedly " "when verifying notBefore %lld, notAfter %lld at time %lld\n", file, line, expected_value ? "failed" : "succeeded", @@ -495,462 +495,11 @@ static int tests_X509_check_time(void) return do_x509_time_tests(cert_test_data, sizeof(cert_test_data) / sizeof(CERT_TEST_DATA)); } -static const char *kRSAModulusNeg[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIIByjCCAXSgAwIBAgIQBjdsAKoAZIoRz7jUqlw19DANBgkqhkiG9w0BAQQFADAW\n", - "MRQwEgYDVQQDEwtSb290IEFnZW5jeTAeFw05NjA1MjgyMjAyNTlaFw0zOTEyMzEy\n", - "MzU5NTlaMBYxFDASBgNVBAMTC1Jvb3QgQWdlbmN5MFswDQYJKoZIhvcNAQEBBQAD\n", - "SgAwRwJAgVUiuYqkb+3W59lmD1W8183VvE5AAiGisfeHMIVe0vJEudybdbb7Rl9C\n", - "tp0jNgveVA/NvR+ZKhBYEctAy7WnQQIDAQABo4GeMIGbMFAGA1UEAwRJE0dGb3Ig\n", - "VGVzdGluZyBQdXJwb3NlcyBPbmx5IFNhbXBsZSBTb2Z0d2FyZSBQdWJsaXNoaW5n\n", - "IENyZWRlbnRpYWxzIEFnZW5jeTBHBgNVHQEEQDA+gBAS5AktBh0dTwCNYSHcFmRj\n", - "oRgwFjEUMBIGA1UEAxMLUm9vdCBBZ2VuY3mCEAY3bACqAGSKEc+41KpcNfQwDQYJ\n", - "KoZIhvcNAQEEBQADQQAtLj57iUKJP6ghF/rw9cOV22JpW8ncwbP68MRvb2Savecb\n", - "JWhyg2e9VrCNAb0q98xLvYeluocgTEIRQa0QFzuM\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -static int tests_X509_check_crypto(void) -{ - X509 *rsa_n_neg = NULL; - EVP_PKEY *pub = NULL; - int test; - - test = TEST_ptr((rsa_n_neg = X509_from_strings(kRSAModulusNeg))) - && TEST_ptr_null((pub = X509_get_pubkey(rsa_n_neg))) - && TEST_err_r(ERR_LIB_EVP, EVP_R_DECODE_ERROR); - - EVP_PKEY_free(pub); - X509_free(rsa_n_neg); - return test; -} - -/* https://github.com/openssl/openssl/issues/11722 */ -static const char *kDistributionPointWrongTag[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIIDiTCCAnGgAwIBAgIFAO3UVNIwDQYJKoZIhvcNAQELBQAwfTEWMBQGA1UEBhMN\n", - "VW5pdGVkTmF0aW9uczEQMA4GA1UECAwHTmV3WW9yazEQMA4GA1UEBwwHTmV3WW9y\n", - "azEcMBoGA1UECgwTU29mdHdhcmVFbmdpbmVlcmluZzEQMA4GA1UECwwHVGVzdGlu\n", - "ZzEPMA0GA1UEAwwGdW4ub3JnMCIYDzIwMTcwMTIzMDkzMDAwWhgPMjAxODEyMjMw\n", - "OTMwMDBaMGwxCzAJBgNVBAYTAlVOMRAwDgYDVQQIEwdOZXdZb3JrMRAwDgYDVQQH\n", - "EwdOZXdZb3JrMQ8wDQYDVQQKEwZzdWJPcmcxEzARBgNVBAsTCnN1Yk9yZ1VuaXQx\n", - "EzARBgNVBAMTCnN1Yi51bi5vcmcwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEK\n", - "AoIBAQDBpo9Viz3OQa6vmsyULUFLgznPkB3OX5Yf5XFBnZWoAu2d9qNypidARWUs\n", - "DomjtevXKrQApnmuWlxqLV5Q4JGbggeq6UsAwnoXCnH7zhQqInczr0U7rzlUYsZq\n", - "H+5haEfV9OewOIFHStAVXyTOqJuEfZOQKZbhhx7TDYg9IpoQisvKB4HbPfi6a6BV\n", - "YPAqNFlSfnYsF7sHNztTJXxyRY/KjrBeKVWs3n2+QQaydI+seiDD1GKBhApHrrWo\n", - "XtaP4VFbSyPszlRnW0ICAVrMItmt1rJBJlARVRq+gpU0gifmMheNBTWt8js6Ms/i\n", - "XeSzBkrQtFsnbVE75qeTrybOxqTXAgMBAAGjHTAbMBkGA1UdHwEB/wQPMA2BCwBS\n", - "ZWFzb24uLi4AMA0GCSqGSIb3DQEBCwUAA4IBAQCzwoxTrHgICZeYE7owZxV39BZh\n", - "MAHYYzS16/EXdXPZvZFQkL+wMBGkPC82s/3D/4kjHUwDxmmu2jBR8k+vEiV5VMnw\n", - "ZcoS22KFNVskk+CBfP0G5/d+ZfFMuW1tE3B1sO7RvYT1MtYt+DryRZ7vvLv7MlQb\n", - "sE+le0VjCfZHAZ+D3GqhYNNy+qhKYaHQDg/tfA/J28yyYm1EMzUd//Bao9BbnRxi\n", - "p4x2WfCFGB/ZP9BV0VA2KH3qF5M1RAETch/YbWqOIn+LxKomhvQSwQ4DEmRHRu69\n", - "loi+aH8qoQ4hb91EeaNb3OCV3azSH8I8RGGZDM2I2fZmgFwZ+5w7rgFjKe6b\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -static int tests_x509_check_dpn(void) -{ - X509 *cert = NULL; - STACK_OF(DIST_POINT) *crls = NULL; - int test, nid = NID_crl_distribution_points; - - test = TEST_ptr((cert = X509_from_strings(kDistributionPointWrongTag))) - && TEST_ptr_null((crls = X509_get_ext_d2i(cert, nid, NULL, NULL))) - && TEST_err_r(ERR_LIB_ASN1, ASN1_R_WRONG_TAG); - - sk_DIST_POINT_pop_free(crls, DIST_POINT_free); - X509_free(cert); - return test; -} - -/* https://github.com/openssl/openssl/issues/20027 */ -static const time_t mendel_verify_time = 1753284700; /* July 23th, 2025 */ - -static const char *kRootMendelsonAKIDKeyNULL[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIIE5zCCA8+gAwIBAgIJAMgskwXwf1MLMA0GCSqGSIb3DQEBBQUAMIIBADELMAkG\n", - "A1UEBhMCREUxEDAOBgNVBAgTB0dlcm1hbnkxDzANBgNVBAcTBkJlcmxpbjEiMCAG\n", - "A1UEChMZbWVuZGVsc29uLWUtY29tbWVyY2UgR21iSDFFMEMGA1UECxM8KGMpIDIw\n", - "MTYgbWVuZGVsc29uLWUtY29tbWVyY2UgR21iSCAtIGZvciBhdXRob3JpemVkIHVz\n", - "ZSBvbmx5MT4wPAYDVQQDEzVtZW5kZWxzb24gUHVibGljIFByaW1hcnkgQ2VydGlm\n", - "aWNhdGlvbiBBdXRob3JpdHkgLSBSNjEjMCEGCSqGSIb3DQEJARYUY2FAbWVuZGVs\n", - "c29uLWUtYy5jb20wHhcNMTYwNjI5MTEwNDMxWhcNMjYwNjI3MTEwNDMxWjCCAQAx\n", - "CzAJBgNVBAYTAkRFMRAwDgYDVQQIEwdHZXJtYW55MQ8wDQYDVQQHEwZCZXJsaW4x\n", - "IjAgBgNVBAoTGW1lbmRlbHNvbi1lLWNvbW1lcmNlIEdtYkgxRTBDBgNVBAsTPChj\n", - "KSAyMDE2IG1lbmRlbHNvbi1lLWNvbW1lcmNlIEdtYkggLSBmb3IgYXV0aG9yaXpl\n", - "ZCB1c2Ugb25seTE+MDwGA1UEAxM1bWVuZGVsc29uIFB1YmxpYyBQcmltYXJ5IENl\n", - "cnRpZmljYXRpb24gQXV0aG9yaXR5IC0gUjYxIzAhBgkqhkiG9w0BCQEWFGNhQG1l\n", - "bmRlbHNvbi1lLWMuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA\n", - "9wUk/mmMB1I3G3MdEyWdbhxM1hGNVOhEAvdyY+S2MxRP2W35kQ5HbztUofk/eACU\n", - "6tz5PuCp0zIVEW2GJdwkNn9B6OUjKZpOLErXBP6o+KRzqq0NtVLOo5Zy/zQ4NPsN\n", - "MNRwHdyoXVbBTZ1PSINb43mhlTTDO8B2oPArCaDFqMfdvvQRtKpD1RRM60Q+dDz8\n", - "PV5AbvUTwvfOmCXqEq2IcEzh3bLzAJCRvGOxM5YAkTlfA+M6OED8zDnsgRVuG6E9\n", - "Lqioh7zvUpmnA+ghKATtQ8Qwg5b+6TctJmxBbwVctZATuhiYXYSlhu2u06UyjPVj\n", - "bnP/kNfd8spvPgI9L3SH/QIDAQABo2AwXjAPBgNVHRMBAf8EBTADAQH/MA4GA1Ud\n", - "DwEB/wQEAwIBBjA7BgNVHR8ENDAyMDCgLqAshipodHRwOi8vY2EubWVuZGVsc29u\n", - "LWUtYy5jb20vbWVuZGVsc29uNi5jcmwwDQYJKoZIhvcNAQEFBQADggEBAN37IQQ5\n", - "rb6TxWczML/cg9cPDa16Jpj/t0yxg97oKRFsqBm0C+rySlWGFzsbj3YKUQVfabKT\n", - "DylOwjj2xIi6gsxWYcWz+kWzRDTs8IYLSLs8WQDtZIErI1eQTGfpfj/stH9fQ9D4\n", - "0+xDDqPH+6dH8JzQ/OTx0D4apRxcdAaDQUlTI/5U5nRuQqZlI0B9rUgQZN/whl6z\n", - "zaaCSj3gmP6AKqGznrvQGzu6W9zg9CezrxlZAeHsa0JDbZOqNvmNk3rsAA07H304\n", - "+UXXZovSGVK73OGw5s+KHTKe6+1/dOFkCJfFnX5pLMrihc5UqSig4JdKPoyvpgNJ\n", - "3mzVzjn/SyMJWo4=\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -static const char *kLeafMendelsonAKIDKeyNULL[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIIGBjCCBO6gAwIBAgIBKjANBgkqhkiG9w0BAQUFADCCAQAxCzAJBgNVBAYTAkRF\n", - "MRAwDgYDVQQIEwdHZXJtYW55MQ8wDQYDVQQHEwZCZXJsaW4xIjAgBgNVBAoTGW1l\n", - "bmRlbHNvbi1lLWNvbW1lcmNlIEdtYkgxRTBDBgNVBAsTPChjKSAyMDE2IG1lbmRl\n", - "bHNvbi1lLWNvbW1lcmNlIEdtYkggLSBmb3IgYXV0aG9yaXplZCB1c2Ugb25seTE+\n", - "MDwGA1UEAxM1bWVuZGVsc29uIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24g\n", - "QXV0aG9yaXR5IC0gUjYxIzAhBgkqhkiG9w0BCQEWFGNhQG1lbmRlbHNvbi1lLWMu\n", - "Y29tMCAXDTE2MDYyOTExMDUwOVoYDzIwMjYwMTAxMDEwMTAxWjCB2zELMAkGA1UE\n", - "BhMCREUxEDAOBgNVBAgTB0dlcm1hbnkxDzANBgNVBAcTBkJlcmxpbjEiMCAGA1UE\n", - "ChMZbWVuZGVsc29uLWUtY29tbWVyY2UgR21iSDFFMEMGA1UECxM8KGMpIDIwMTYg\n", - "bWVuZGVsc29uLWUtY29tbWVyY2UgR21iSCAtIGZvciBhdXRob3JpemVkIHVzZSBv\n", - "bmx5MT4wPAYDVQQDEzVtZW5kZWxzb24gUHVibGljIFByaW1hcnkgQ2VydGlmaWNh\n", - "dGlvbiBBdXRob3JpdHkgLSBJNjCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC\n", - "ggEBAN/6W8TW8YYHgKxHxXg6Cy1pZRhXHr6WBqaUwTglNBf788y3XJdaG/e1kwaw\n", - "MuYAdOYWt8sm2xYmpmJorcY7m4gTdcuMH8fCarDsRVdT2BMXxZ9JTIG4E9YflzOQ\n", - "MvOn+tZ6UyPkgbfX2zfKydSH5FJiY31QNbBb3MI1zAFUYC3mqmMEgrHwm5qTFrYb\n", - "p3v8ZBnBiWRR9H72IaV1ZjGP90Hyh6w/pQjo+TJnLIklLaTv6Cd70SWGhnhJwdPP\n", - "/9YvzfSXt9sW8wj6PkXT2cqW08o4hkmcc95MoIdsH6re+Gv0d3qt1a3yMnEdHHF8\n", - "g+t0P2VezEF+k0Mdib83HC8QAaMCAwEAAaOCAakwggGlMA8GA1UdEwEB/wQFMAMB\n", - "Af8wggEkBgNVHSMEggEbMIIBF6GCAQikggEEMIIBADELMAkGA1UEBhMCREUxEDAO\n", - "BgNVBAgTB0dlcm1hbnkxDzANBgNVBAcTBkJlcmxpbjEiMCAGA1UEChMZbWVuZGVs\n", - "c29uLWUtY29tbWVyY2UgR21iSDFFMEMGA1UECxM8KGMpIDIwMTYgbWVuZGVsc29u\n", - "LWUtY29tbWVyY2UgR21iSCAtIGZvciBhdXRob3JpemVkIHVzZSBvbmx5MT4wPAYD\n", - "VQQDEzVtZW5kZWxzb24gUHVibGljIFByaW1hcnkgQ2VydGlmaWNhdGlvbiBBdXRo\n", - "b3JpdHkgLSBSNjEjMCEGCSqGSIb3DQEJARYUY2FAbWVuZGVsc29uLWUtYy5jb22C\n", - "CQDILJMF8H9TCzAdBgNVHQ4EFgQUbPFwN+UTRvxdmehaSgrotrmrMv4wDgYDVR0P\n", - "AQH/BAQDAgGGMDsGA1UdHwQ0MDIwMKAuoCyGKmh0dHA6Ly9jYS5tZW5kZWxzb24t\n", - "ZS1jLmNvbS9tZW5kZWxzb242LmNybDANBgkqhkiG9w0BAQUFAAOCAQEAV66ufDx8\n", - "XusBk+G0z59P8+MYxdTJfnv6Q9ezZJ9zumVzp4CuuUp+8qtlC1+zN7HIgiR7C6eB\n", - "fvAopruYUTa8m+7ZMN/vBi7XkmAX7oUM4hZYd/2yoUjL/AXF1p4fgKcCJmgvlctC\n", - "tQrG+VdXOAmGGAhbfnOZPg+kRfO7MYKLn2BL266aPeEsBVg/xWw/NWOFYgCXeHb8\n", - "2huxL0Ir8yK2Qv3Nqlbt/6irYMAvElCuQCrp7wqX8tXvE7/HmT/JKHTzTW+APp0A\n", - "KHq3GiYk+/XgxHxfyVdo55iQOTqZSIigK8Yj2gFhocxCBifF6gbnbo6LTwH+I4Er\n", - "TAjrRai7UZlqjw==\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -static int tests_x509_check_akid(void) -{ - X509 *root = NULL, *leaf = NULL; - X509_STORE_CTX *ctx = NULL; - X509_STORE *store = NULL; - X509_VERIFY_PARAM *param = NULL; - STACK_OF(X509) *x509s = NULL; - int test; - - test = TEST_ptr(ctx = X509_STORE_CTX_new()) - && TEST_ptr(store = X509_STORE_new()) - && TEST_ptr(param = X509_VERIFY_PARAM_new()) - && TEST_ptr(x509s = sk_X509_new_null()) - && TEST_ptr((root = X509_from_strings(kRootMendelsonAKIDKeyNULL))) - && TEST_ptr((leaf = X509_from_strings(kLeafMendelsonAKIDKeyNULL))) - && TEST_true(X509_STORE_CTX_init(ctx, store, leaf, NULL)); - - if (test != 1) - goto err; - if (!TEST_true(sk_X509_push(x509s, root))) - goto err; - root = NULL; - - X509_STORE_CTX_set0_trusted_stack(ctx, x509s); - X509_VERIFY_PARAM_set_depth(param, 16); - X509_VERIFY_PARAM_set_time(param, mendel_verify_time); - X509_VERIFY_PARAM_set_flags(param, X509_V_FLAG_X509_STRICT); - X509_STORE_CTX_set0_param(ctx, param); - param = NULL; - ERR_clear_error(); - - test = TEST_int_eq(X509_verify_cert(ctx), 0) - && TEST_int_eq(X509_STORE_CTX_get_error(ctx), - X509_V_ERR_MISSING_SUBJECT_KEY_IDENTIFIER); - -err: - OSSL_STACK_OF_X509_free(x509s); - X509_VERIFY_PARAM_free(param); - X509_STORE_CTX_free(ctx); - X509_STORE_free(store); - X509_free(leaf); - X509_free(root); - - return test; -} - -/* https://github.com/openssl/openssl/issues/26325 */ -static const char *kRootExtensionDuplicity[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIIDhDCCAmygAwIBAgIDCxQYMA0GCSqGSIb3DQEBCwUAMHoxCzAJBgNVBAYTAlVO\n", - "MQ8wDQYDVQQIDAZNeSBTVDExFTATBgNVBAcMDE1ZIExvY2FsaXR5MTEUMBIGA1UE\n", - "CgwLTVkgQ29tcGFueTExETAPBgNVBAsMCE15IFVuaXQxMRowGAYDVQQDDBF3d3cu\n", - "bXljb21wYW55LmNvbTAeFw0xOTA2MTkwODU1NTlaFw0yOTA2MTkwODU1NTlaMHox\n", - "CzAJBgNVBAYTAlVOMQ8wDQYDVQQIDAZNeSBTVDExFTATBgNVBAcMDE1ZIExvY2Fs\n", - "aXR5MTEUMBIGA1UECgwLTXkgQ29tcGFueTExETAPBgNVBAsMCE15IFVuaXQxMRow\n", - "GAYDVQQDDBF3d3cubXljb21wYW55LmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEP\n", - "ADCCAQoCggEBALVNKQrEfNWp3s0FOW+9RAjXOMvhAprV/FsWo6M72Mq/EwaV4Ny+\n", - "Q2CZ2Bs09KmRw43RG4dHHkB5/ewE7HhohQcHVH+tcWrM0IdgQIzKva2vICFZkp6O\n", - "am71qSe8+qtLSkzlTYJv4oeTLmMA2SSwTTP74hB29MS6O8scaLcM+OqfaGzr6k/Z\n", - "GnMMjI/zf4rbrLGPJcGGZ4jIMkrYm1PnwAwg6ijXrU0kb8DBgVvpmrluYfQdBvy6\n", - "bSib3P9ckyCGqqszn50qQZqqa2n6Ol/CBwRsCuYuhazRsBcXiULQ1lv2JQG86ILb\n", - "h/SXXfB4A6p0ti3tmcTMIPN5AI3y/EvUUwkCAwEAAaMTMBEwDwYDVR0TAQH/BAUw\n", - "AwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAS6joG5vUo2kMLX0bcpjKzE3h40ZypVgJ\n", - "bSCLu/alVcIDzdLTK/SOp2NMvtGmn+BMRvfzW+Lk58sMZ2QC3x+RZKHV+pDsT+Lj\n", - "Zi1bhpvtzrN62PmYZXGTu0xPME3SlBLilUFIRgH5lrxzlBdRURMCbHJOblAfzVdw\n", - "EBCtDVdGcox/mzu1Jo/sJQb59a49ZQpvwp7m7kZE0q6dBgElYX4JaRYhbwsv/tP2\n", - "jEA+jQYNORgFvCOkITbaO4Avc7BXSCGkDHoH6GsANf0bdtaMQCbUMeaC2CYUzRoC\n", - "fTEJ9LvFu7syeEDpUbgPXgRqpUQLyxoVYxWjXZ3CG5jeRmJzAEAoyg==\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -static const char *kCertExtensionDuplicity[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIIENDCCAxygAwIBAgIVASygDp5oUEVMj9bx6z7bj3ce5ypQMA0GCSqGSIb3DQEB\n", - "CwUAMHoxCzAJBgNVBAYTAlVOMQ8wDQYDVQQIDAZNeSBTVDExFTATBgNVBAcMDE1Z\n", - "IExvY2FsaXR5MTEUMBIGA1UECgwLTXkgQ29tcGFueTExETAPBgNVBAsMCE15IFVu\n", - "aXQxMRowGAYDVQQDDBF3d3cubXljb21wYW55LmNvbTAiGA8yMDE5MDYxOTA4NTU1\n", - "OVoYDzIwMjkwNjE5MDg1NTU5WjB7MQswCQYDVQQGEwJVTjEPMA0GA1UECAwGTXkg\n", - "U1QxMRUwEwYDVQQHDAxNWSBMb2NhbGl0eTExFDASBgNVBAoMC015IENvbXBhbnkx\n", - "MREwDwYDVQQLDAhNeSBVbml0MTEbMBkGA1UEAwwSd3d3Lm15Y29tcGFueTEuY29t\n", - "MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtU0pCsR81anezQU5b71E\n", - "CNc4y+ECmtX8WxajozvYyr8TBpXg3L5DYJnYGzT0qZHDjdEbh0ceQHn97ATseGiF\n", - "BwdUf61xaszQh2BAjMq9ra8gIVmSno5qbvWpJ7z6q0tKTOVNgm/ih5MuYwDZJLBN\n", - "M/viEHb0xLo7yxxotwz46p9obOvqT9kacwyMj/N/itussY8lwYZniMgyStibU+fA\n", - "DCDqKNetTSRvwMGBW+mauW5h9B0G/LptKJvc/1yTIIaqqzOfnSpBmqprafo6X8IH\n", - "BGwK5i6FrNGwFxeJQtDWW/YlAbzogtuH9Jdd8HgDqnS2Le2ZxMwg83kAjfL8S9RT\n", - "CQIDAQABo4GrMIGoMFIGCCsGAQUFBwELBEYwRDBCBggrBgEFBQcwBYY2ZnRwOi8v\n", - "NjYuMjMzLjIuMjM1L2Z8M2YvTUI5JT94dV89WEdlYXxIMFgmcTRpRm1YIXs9dS89\n", - "MFIGCCsGAQUFBwELBEYwRDBCBggrBgEFBQcwBYY2ZnRwOi8vNjouMjMzLjIuMjM1\n", - "L2Z8M2YvTUI5JT94dV89WEdlYXxIMFgmcTRpRm1YIXs9dS89MA0GCSqGSIb3DQEB\n", - "CwUAA4IBAQCoLSlKFFlg2xSGf9PFrXayO9ODk4pUkzb/+u0fsf6Vekwo/0dFNxSM\n", - "1sPtfoyprGMd7DK8R0rELq7k4+TaypV1JFBj9G9///dCTdX8Fg1SMRamIY0cs8Cu\n", - "VJCPWpLD6RQzZm9WkUqcc1yhjW8eO7OABazKwFQBLRS97ocztbyNvPbsZ0xInSMV\n", - "7E3xOj4XeibJ2y+EHUbMRDPtwZuy+E1m/kYScLAqIweVaxrWQnCC1HcARxL6eHx9\n", - "8kzGS23XAT9jLvdxwNs23GXiAjzxifJmR7oujP+uALF+FfHdJb7vr6l8lVNzRnDH\n", - "utv/6BamvgrYfDmA6GO3UItEgYozDtaN\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -/* - * The following test checks for a duplicate extension with a known build-time - * NID, which is detected in constant time. - * */ -static int tests_x509_check_ext_duplicity(void) -{ - X509 *root = NULL, *leaf = NULL; - X509_STORE_CTX *ctx = NULL; - X509_STORE *store = NULL; - X509_VERIFY_PARAM *param = NULL; - STACK_OF(X509) *x509s = NULL; - const time_t verify_time = 1753284700; /* July 23th, 2025 */ - int test; - - test = TEST_ptr(ctx = X509_STORE_CTX_new()) - && TEST_ptr(store = X509_STORE_new()) - && TEST_ptr(param = X509_VERIFY_PARAM_new()) - && TEST_ptr(x509s = sk_X509_new_null()) - && TEST_ptr((root = X509_from_strings(kRootExtensionDuplicity))) - && TEST_ptr((leaf = X509_from_strings(kCertExtensionDuplicity))) - && TEST_true(X509_STORE_CTX_init(ctx, store, leaf, NULL)); - - if (test != 1) - goto err; - if (!TEST_true(sk_X509_push(x509s, root))) - goto err; - root = NULL; - - X509_STORE_CTX_set0_trusted_stack(ctx, x509s); - X509_VERIFY_PARAM_set_depth(param, 16); - X509_VERIFY_PARAM_set_time(param, verify_time); - X509_STORE_CTX_set0_param(ctx, param); - param = NULL; - ERR_clear_error(); - - test = TEST_int_eq(X509_verify_cert(ctx), 0) - && TEST_int_eq(X509_STORE_CTX_get_error(ctx), - X509_V_ERR_DUPLICATE_EXTENSION); - -err: - OSSL_STACK_OF_X509_free(x509s); - X509_VERIFY_PARAM_free(param); - X509_STORE_CTX_free(ctx); - X509_STORE_free(store); - X509_free(leaf); - X509_free(root); - - return test; -} - -/* - * This test checks for a duplicate extension with an undefined NID, where the - * duplicate is detected via OID. - */ -static int tests_x509_check_ext_duplicity_nid_undef(void) -{ - X509 *root = NULL, *leaf = NULL; - X509_STORE_CTX *ctx = NULL; - X509_STORE *store = NULL; - X509_VERIFY_PARAM *param = NULL; - STACK_OF(X509) *x509s = NULL; - ASN1_OBJECT *obj1 = NULL, *obj2 = NULL; - ASN1_OCTET_STRING *oct1 = NULL, *oct2 = NULL; - X509_EXTENSION *ext1 = NULL, *ext2 = NULL; - const unsigned char data[] = { 0x04, 0x03, 0x41, 0x42, 0x43 }; - const time_t verify_time = 1753284700; /* July 23th, 2025 */ - const char *unknown_oid = "1.2.3.4.5.6.7.8.9"; - int test; - - test = TEST_ptr(ctx = X509_STORE_CTX_new()) - && TEST_ptr(store = X509_STORE_new()) - && TEST_ptr(param = X509_VERIFY_PARAM_new()) - && TEST_ptr(x509s = sk_X509_new_null()) - && TEST_ptr((root = X509_from_strings(kRootMendelsonAKIDKeyNULL))) - && TEST_ptr((leaf = X509_from_strings(kLeafMendelsonAKIDKeyNULL))) - && TEST_true(X509_STORE_CTX_init(ctx, store, leaf, NULL)) - && TEST_ptr(obj1 = OBJ_txt2obj(unknown_oid, 1)) - && TEST_ptr(oct1 = ASN1_OCTET_STRING_new()) - && TEST_int_eq(ASN1_OCTET_STRING_set(oct1, data, sizeof(data)), 1) - && TEST_ptr(ext1 = X509_EXTENSION_create_by_OBJ(NULL, obj1, 0, oct1)) - && TEST_int_eq(X509_add_ext(leaf, ext1, -1), 1) - && TEST_ptr(obj2 = OBJ_txt2obj(unknown_oid, 1)) - && TEST_ptr(oct2 = ASN1_OCTET_STRING_new()) - && TEST_int_eq(ASN1_OCTET_STRING_set(oct2, data, sizeof(data)), 1) - && TEST_ptr(ext2 = X509_EXTENSION_create_by_OBJ(NULL, obj2, 0, oct2)) - && TEST_int_eq(X509_add_ext(leaf, ext2, -1), 1); - - if (test != 1) - goto err; - if (!TEST_true(sk_X509_push(x509s, root))) - goto err; - root = NULL; - - X509_STORE_CTX_set0_trusted_stack(ctx, x509s); - X509_VERIFY_PARAM_set_depth(param, 16); - X509_VERIFY_PARAM_set_time(param, verify_time); - X509_STORE_CTX_set0_param(ctx, param); - param = NULL; - ERR_clear_error(); - - test = TEST_int_eq(X509_verify_cert(ctx), 0) - && TEST_int_eq(X509_STORE_CTX_get_error(ctx), - X509_V_ERR_DUPLICATE_EXTENSION); - -err: - ASN1_OBJECT_free(obj1); - ASN1_OCTET_STRING_free(oct1); - X509_EXTENSION_free(ext1); - ASN1_OBJECT_free(obj2); - ASN1_OCTET_STRING_free(oct2); - X509_EXTENSION_free(ext2); - OSSL_STACK_OF_X509_free(x509s); - X509_VERIFY_PARAM_free(param); - X509_STORE_CTX_free(ctx); - X509_STORE_free(store); - X509_free(leaf); - X509_free(root); - - return test; -} - -/* - * This test checks for a duplicate extension with a dynamically registered NID, - * where the duplicate is detected via OID. - */ -static int tests_x509_check_ext_duplicity_nid_dynamic(void) -{ - X509 *root = NULL, *leaf = NULL; - X509_STORE_CTX *ctx = NULL; - X509_STORE *store = NULL; - X509_VERIFY_PARAM *param = NULL; - STACK_OF(X509) *x509s = NULL; - ASN1_OBJECT *obj1 = NULL, *obj2 = NULL; - ASN1_OCTET_STRING *oct1 = NULL, *oct2 = NULL; - X509_EXTENSION *ext1 = NULL, *ext2 = NULL; - const unsigned char data[] = { 0x04, 0x03, 0x41, 0x42, 0x43 }; - const time_t verify_time = 1753284700; /* July 23th, 2025 */ - const char *oid = "1.2.3.4.5.6.7.8.9"; - const char *sn = "testOID"; - const char *ln = "testOID Long Name"; - int nid; - int test; - - test = TEST_ptr(ctx = X509_STORE_CTX_new()) - && TEST_ptr(store = X509_STORE_new()) - && TEST_ptr(param = X509_VERIFY_PARAM_new()) - && TEST_ptr(x509s = sk_X509_new_null()) - && TEST_ptr((root = X509_from_strings(kRootMendelsonAKIDKeyNULL))) - && TEST_ptr((leaf = X509_from_strings(kLeafMendelsonAKIDKeyNULL))) - && TEST_true(X509_STORE_CTX_init(ctx, store, leaf, NULL)) - && TEST_true((nid = OBJ_create(oid, sn, ln)) != NID_undef) - && TEST_ptr(obj1 = OBJ_nid2obj(nid)) - && TEST_ptr(oct1 = ASN1_OCTET_STRING_new()) - && TEST_int_eq(ASN1_OCTET_STRING_set(oct1, data, sizeof(data)), 1) - && TEST_ptr(ext1 = X509_EXTENSION_create_by_OBJ(NULL, obj1, 0, oct1)) - && TEST_int_eq(X509_add_ext(leaf, ext1, -1), 1) - && TEST_ptr(obj2 = OBJ_nid2obj(nid)) - && TEST_ptr(oct2 = ASN1_OCTET_STRING_new()) - && TEST_int_eq(ASN1_OCTET_STRING_set(oct2, data, sizeof(data)), 1) - && TEST_ptr(ext2 = X509_EXTENSION_create_by_OBJ(NULL, obj2, 0, oct2)) - && TEST_int_eq(X509_add_ext(leaf, ext2, -1), 1); - - if (test != 1) - goto err; - if (!TEST_true(sk_X509_push(x509s, root))) - goto err; - root = NULL; - - X509_STORE_CTX_set0_trusted_stack(ctx, x509s); - X509_VERIFY_PARAM_set_depth(param, 16); - X509_VERIFY_PARAM_set_time(param, verify_time); - X509_STORE_CTX_set0_param(ctx, param); - param = NULL; - ERR_clear_error(); - - test = TEST_int_eq(X509_verify_cert(ctx), 0) - && TEST_int_eq(X509_STORE_CTX_get_error(ctx), - X509_V_ERR_DUPLICATE_EXTENSION); - -err: - ASN1_OBJECT_free(obj1); - ASN1_OCTET_STRING_free(oct1); - X509_EXTENSION_free(ext1); - ASN1_OBJECT_free(obj2); - ASN1_OCTET_STRING_free(oct2); - X509_EXTENSION_free(ext2); - OSSL_STACK_OF_X509_free(x509s); - X509_VERIFY_PARAM_free(param); - X509_STORE_CTX_free(ctx); - X509_STORE_free(store); - X509_free(leaf); - X509_free(root); - - return test; -} - int setup_tests(void) { ADD_TEST(test_standard_exts); ADD_ALL_TESTS(test_a2i_ipaddress, OSSL_NELEM(a2i_ipaddress_tests)); ADD_TEST(tests_X509_PURPOSE); ADD_TEST(tests_X509_check_time); - ADD_TEST(tests_X509_check_crypto); - ADD_TEST(tests_x509_check_dpn); - ADD_TEST(tests_x509_check_akid); - ADD_TEST(tests_x509_check_ext_duplicity); - ADD_TEST(tests_x509_check_ext_duplicity_nid_undef); - ADD_TEST(tests_x509_check_ext_duplicity_nid_dynamic); - return 1; } diff --git a/test/x509_load_cert_file_test.c b/test/x509_load_cert_file_test.c index f9656aaa31..721eff9cb5 100644 --- a/test/x509_load_cert_file_test.c +++ b/test/x509_load_cert_file_test.c @@ -172,64 +172,6 @@ err: return ret; } -/* - * Test to trigger memory failures in X509_STORE_add_cert. - */ -static int test_x509_store_add_mfail(void) -{ - X509 *cert = NULL; - X509_STORE *store = NULL; - int ret = 0; - - cert = X509_from_strings(cn_cert1); - if (!TEST_ptr(cert)) - goto err; - store = X509_STORE_new(); - if (!TEST_ptr(store)) - goto err; - - MFAIL_start(); - ret = X509_STORE_add_cert(store, cert); - MFAIL_end(); - -err: - X509_STORE_free(store); - X509_free(cert); - return ret; -} - -static int test_x509_get1_objects_mfail(void) -{ - X509 *cert1 = NULL, *cert2 = NULL; - X509_STORE *store = NULL; - STACK_OF(X509_OBJECT) *objs = NULL; - int ret = 0; - - if (!TEST_ptr(cert1 = X509_from_strings(cn_cert1)) - || !TEST_ptr(cert2 = X509_from_strings(cn_cert2))) - goto err; - - store = X509_STORE_new(); - if (!TEST_ptr(store)) - goto err; - if (!TEST_true(X509_STORE_add_cert(store, cert1)) - || !TEST_true(X509_STORE_add_cert(store, cert2))) - goto err; - - MFAIL_start(); - objs = X509_STORE_get1_objects(store); - MFAIL_end(); - - ret = (objs != NULL); - -err: - sk_X509_OBJECT_pop_free(objs, X509_OBJECT_free); - X509_STORE_free(store); - X509_free(cert1); - X509_free(cert2); - return ret; -} - OPT_TEST_DECLARE_USAGE("cert.pem [crl.pem]\n") int setup_tests(void) @@ -247,8 +189,6 @@ int setup_tests(void) ADD_TEST(test_load_cert_file); ADD_TEST(test_load_same_cn_certs); - ADD_MFAIL_TEST(test_x509_store_add_mfail); - ADD_MFAIL_TEST(test_x509_get1_objects_mfail); return 1; } diff --git a/test/x509_memfail.c b/test/x509_memfail.c index 41b2c098dc..5be192bd55 100644 --- a/test/x509_memfail.c +++ b/test/x509_memfail.c @@ -21,7 +21,7 @@ #include "testutil.h" static char *certfile = NULL; -static int mcount, rcount, fcount, scount, srcount; +static int mcount, rcount, fcount, scount; static int do_x509(int allow_failure) { @@ -91,16 +91,15 @@ static int test_report_alloc_counts(void) CRYPTO_get_alloc_counts(&mcount, &rcount, &fcount); /* * Report our memory allocations from the count run - * NOTE: We report a number of (re)allocations to skip here - * (the scount + srcount value). These are the allocations - * that took place while the test harness itself was getting - * setup (i.e. calling OPENSSL_init_crypto/etc). We can't fail + * NOTE: We report a number of allocations to skip here + * (the scount value). These are the allocations that took + * place while the test harness itself was getting setup + * (i.e. calling OPENSSL_init_crypto/etc). We can't fail * those allocations as they will cause the test to fail before * we have even run the workload. So report them so we can * allow them to function before we start doing any real testing */ - TEST_info("skip: %d count %d\n", - scount + srcount, mcount + rcount - scount - srcount); + TEST_info("skip: %d count %d\n", scount, mcount - scount); return 1; } @@ -116,7 +115,7 @@ int setup_tests(void) goto err; if (strcmp(opmode, "count") == 0) { - CRYPTO_get_alloc_counts(&scount, &srcount, &fcount); + CRYPTO_get_alloc_counts(&scount, &rcount, &fcount); ADD_TEST(test_record_alloc_counts); ADD_TEST(test_report_alloc_counts); } else { diff --git a/test/x509_test.c b/test/x509_test.c index a5beb7ca2f..00b7c2e55e 100644 --- a/test/x509_test.c +++ b/test/x509_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2022-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -10,7 +10,6 @@ #define OPENSSL_SUPPRESS_DEPRECATED /* EVP_PKEY_get1/set1_RSA */ #include -#include #include #include #include @@ -103,21 +102,6 @@ static int test_x509_tbs_cache(void) return ret; } -static int test_x509_verify_with_new(void) -{ - int ret; - EVP_PKEY *pkey = NULL; - X509 *x = NULL; - - ret = TEST_ptr(x = X509_new()) - && TEST_ptr(pkey = EVP_PKEY_new()) - && TEST_int_eq(X509_verify(x, pkey), -1) - && TEST_int_eq(X509_verify(x, pubkey), -1); - X509_free(x); - EVP_PKEY_free(pkey); - return ret; -} - /* * Test for Regression discussed in PR #19388 * In order for this simple test to fail, it requires the digest used for @@ -168,14 +152,14 @@ static int test_asn1_item_verify(void) X509_get0_signature(&sig, &alg, x509); if (!TEST_int_gt(ASN1_item_verify(ASN1_ITEM_rptr(X509_CINF), - alg, sig, + (X509_ALGOR *)alg, (ASN1_BIT_STRING *)sig, &x509->cert_info, pkey), 0)) goto err; ERR_set_mark(); if (!TEST_int_lt(ASN1_item_verify(ASN1_ITEM_rptr(X509_CINF), - alg, sig, + (X509_ALGOR *)alg, (ASN1_BIT_STRING *)sig, NULL, pkey), 0)) { ERR_clear_last_mark(); @@ -300,351 +284,6 @@ err: return ret; } -static int test_drop_empty_cert_keyids(void) -{ - static const unsigned char commonName[] = "test"; - BIO *bio = NULL; - CONF *conf = NULL; - X509 *x = NULL; - X509_NAME *subject = NULL; - X509_NAME_ENTRY *name_entry = NULL; - X509_EXTENSION *ext = NULL; - const STACK_OF(X509_EXTENSION) *exts; - X509V3_CTX ctx; - int ret = 0; - - if (!TEST_ptr(x = X509_new()) - || !TEST_int_eq(X509_set_version(x, X509_VERSION_3), 1) - || !TEST_int_eq(ASN1_INTEGER_set(X509_get_serialNumber(x), 1), 1) - || !TEST_ptr(subject = X509_NAME_new())) - goto err; - - name_entry = X509_NAME_ENTRY_create_by_NID(NULL, NID_commonName, - MBSTRING_ASC, commonName, -1); - if (!TEST_ptr(name_entry) - || !TEST_int_eq(X509_NAME_add_entry(subject, name_entry, -1, 0), 1) - || !TEST_int_eq(X509_set_subject_name(x, subject), 1) - || !TEST_int_eq(X509_set_issuer_name(x, subject), 1) - || !TEST_ptr(X509_gmtime_adj(X509_getm_notBefore(x), 0)) - || !TEST_ptr(X509_gmtime_adj(X509_getm_notAfter(x), 24 * 3600)) - || !TEST_int_eq(X509_set_pubkey(x, pubkey), 1)) - goto err; - - /* - * Check that X509_add_ext() does not create non-NULL empty stack when - * adding an ignored extension (from initial NULL state). - */ - X509V3_set_ctx(&ctx, x, x, NULL, NULL, X509V3_CTX_REPLACE); - if (!TEST_ptr(ext = X509V3_EXT_conf(NULL, &ctx, "subjectKeyIdentifier", "none")) - || !TEST_int_eq(X509_add_ext(x, ext, -1), 1) - || !TEST_ptr_null(X509_get0_extensions(x))) - goto err; - - /* Add non-empty SKID */ - if (!TEST_ptr(bio = BIO_new(BIO_s_mem())) - || !TEST_int_ge(BIO_printf(bio, "subjectKeyIdentifier = hash\n"), 0) - || !TEST_ptr(conf = NCONF_new(NULL)) - || !TEST_int_gt(NCONF_load_bio(conf, bio, NULL), 0)) - goto err; - (void)BIO_reset(bio); - - X509V3_set_nconf(&ctx, conf); - if (!TEST_true(X509V3_EXT_add_nconf(conf, &ctx, "default", x)) - || !TEST_ptr(exts = X509_get0_extensions(x)) - || !TEST_int_eq(sk_X509_EXTENSION_num(exts), 1)) - goto err; - - /* Request "empty" SKID in order to drop any previous value */ - NCONF_free(conf); - if (!TEST_ptr(conf = NCONF_new(NULL)) - || !TEST_int_ge(BIO_printf(bio, "subjectKeyIdentifier = none\n"), 0) - || !TEST_int_gt(NCONF_load_bio(conf, bio, NULL), 0)) - goto err; - - X509V3_set_nconf(&ctx, conf); - if (!TEST_true(X509V3_EXT_add_nconf(conf, &ctx, "default", x)) - || !TEST_int_gt(X509_sign(x, privkey, signmd), 0) - || !TEST_ptr_null(X509_get0_extensions(x))) - goto err; - - /* - * Now check that a non-empty extension is actually added via - * X509_add_ext(). - */ - X509_EXTENSION_free(ext); - if (!TEST_ptr(ext = X509V3_EXT_conf(NULL, &ctx, "subjectKeyIdentifier", "hash")) - || !TEST_int_eq(X509_add_ext(x, ext, -1), 1) - || !TEST_int_gt(X509_sign(x, privkey, signmd), 0) - || !TEST_ptr(exts = X509_get0_extensions(x)) - || !TEST_int_eq(sk_X509_EXTENSION_num(exts), 1)) - goto err; - - ret = 1; -err: - BIO_free(bio); - NCONF_free(conf); - X509_NAME_ENTRY_free(name_entry); - X509_NAME_free(subject); - X509_EXTENSION_free(ext); - X509_free(x); - return ret; -} - -static int test_drop_empty_csr_keyids(void) -{ - static const unsigned char commonName[] = "test"; - BIO *bio = NULL; - CONF *conf = NULL; - X509_REQ *x = NULL; - X509_NAME *subject = NULL; - X509_NAME_ENTRY *name_entry = NULL; - X509_EXTENSION *ext = NULL; - STACK_OF(X509_EXTENSION) *exts = NULL; - X509V3_CTX ctx; - int ret = 0; - - if (!TEST_ptr(x = X509_REQ_new()) - || !TEST_int_eq(X509_REQ_set_version(x, X509_REQ_VERSION_1), 1) - || !TEST_ptr(subject = X509_NAME_new())) - goto err; - - name_entry = X509_NAME_ENTRY_create_by_NID(NULL, NID_commonName, - MBSTRING_ASC, commonName, -1); - if (!TEST_ptr(name_entry) - || !TEST_int_eq(X509_NAME_add_entry(subject, name_entry, -1, 0), 1) - || !TEST_int_eq(X509_REQ_set_subject_name(x, subject), 1) - || !TEST_int_eq(X509_REQ_set_pubkey(x, pubkey), 1)) - goto err; - - /* Add non-empty SKID, CSRs have no issuer, so no AKID */ - if (!TEST_ptr(bio = BIO_new(BIO_s_mem())) - || !TEST_int_ge(BIO_printf(bio, "subjectKeyIdentifier = hash\n"), 0) - || !TEST_ptr(conf = NCONF_new(NULL)) - || !TEST_int_gt(NCONF_load_bio(conf, bio, NULL), 0)) - goto err; - (void)BIO_reset(bio); - - X509V3_set_ctx(&ctx, NULL, NULL, x, NULL, X509V3_CTX_REPLACE); - X509V3_set_nconf(&ctx, conf); - if (!TEST_true(X509V3_EXT_REQ_add_nconf(conf, &ctx, "default", x)) - || !TEST_int_eq(X509_REQ_get_attr_count(x), 1) - || !TEST_ptr(exts = X509_REQ_get_extensions(x)) - || !TEST_int_eq(sk_X509_EXTENSION_num(exts), 1)) - goto err; - sk_X509_EXTENSION_pop_free(exts, X509_EXTENSION_free); - exts = NULL; - - /* Request an "empty" SKID in order to drop the previous SKID */ - NCONF_free(conf); - if (!TEST_ptr(conf = NCONF_new(NULL)) - || !TEST_int_ge(BIO_printf(bio, "subjectKeyIdentifier = none\n"), 0) - || !TEST_int_gt(NCONF_load_bio(conf, bio, NULL), 0)) - goto err; - - X509V3_set_nconf(&ctx, conf); - if (!TEST_true(X509V3_EXT_REQ_add_nconf(conf, &ctx, "default", x)) - || !TEST_int_gt(X509_REQ_sign(x, privkey, signmd), 0) - || !TEST_int_eq(X509_REQ_get_attr_count(x), 0)) - goto err; - - ret = 1; - -err: - BIO_free(bio); - NCONF_free(conf); - X509_NAME_ENTRY_free(name_entry); - X509_NAME_free(subject); - X509_EXTENSION_free(ext); - sk_X509_EXTENSION_pop_free(exts, X509_EXTENSION_free); - X509_REQ_free(x); - return ret; -} - -/* - * TPM 1.2 Endorsement Key certificate with a NID_rsaesOaep - * SubjectPublicKeyInfo AlgorithmIdentifier (per TCG Credential - * Profiles V1.2 section 3.2.7). The AlgorithmIdentifier carries - * a TCG-specific pSourceAlgorithm ("TCPA") in its parameters, - * which we deliberately do not interpret. The key body itself - * is a standard RSAPublicKey. - */ -static const char *kRsaesOaepCert[] = { - "-----BEGIN CERTIFICATE-----\n", - "MIIDhDCCAmygAwIBAgIUBchBXcXPAWxNMJEsLXEXHv/eVZswDQYJKoZIhvcNAQEL\n", - "BQAwVTELMAkGA1UEBhMCQ0gxHjAcBgNVBAoTFVNUTWljcm9lbGVjdHJvbmljcyBO\n", - "VjEmMCQGA1UEAxMdU1RNIFRQTSBFSyBJbnRlcm1lZGlhdGUgQ0EgMDIwHhcNMjEw\n", - "OTA0MDAwMDAwWhcNMzEwOTA0MDAwMDAwWjAAMIIBNzAiBgkqhkiG9w0BAQcwFaIT\n", - "MBEGCSqGSIb3DQEBCQQEVENQQQOCAQ8AMIIBCgKCAQEAxpd3DnecpD87acEsYp4J\n", - "stM2q5Ss3CkjAP2Ei8yGjbO6DG/6WBIZjTdI5RfIcInoqN4QMso94vm8VqijdRI+\n", - "Zo5hLTCPLKXYwa6UG5yIPZ3ENQdhgZWeEPWe+pp9VUwz8wi78Ifk+CCV6Xp/5kQi\n", - "DCsR+RYbOVb9QgR6kjq+cx1z8YFp5u+k3Pl9tMq9xgIp5E6hT2MaS12KnoN8+hYI\n", - "mfCYVnpzBeQaHDp1KUoyDK6xGt86VxB0QyRbniHI38qgQL6qhO7z96aQ0pNGoQde\n", - "QUxFf/sETurQ5zSf+3btnS8afjxdVBKzj3isv5BaQrt0mdB7+3XWD+ASda33SY12\n", - "6wIDAQABo4GLMIGIMB8GA1UdIwQYMBaAFFcfgGtHzOeb+jWUfO2IuNEAWuCeMEIG\n", - "A1UdIAQ7MDkwNwYEVR0gADAvMC0GCCsGAQUFBwIBFiFodHRwOi8vd3d3LnN0LmNv\n", - "bS9UUE0vcmVwb3NpdG9yeS8wDAYDVR0TAQH/BAIwADATBgNVHSUBAf8ECTAHBgVn\n", - "gQUIATANBgkqhkiG9w0BAQsFAAOCAQEAMOhFPNcebyCRFOBztlWhmDb2DHTCD0nC\n", - "DVobH4WZJXGf4bkYNO3mOLyWtHEVzb36kiq7enh3f/eGhDPwKB8axlozpR5KAvER\n", - "szKNO8iLGOjuYzI2A4DazkttczFfzSB9QDgJrwTNEfIJtwRm2HQSiL0zzuEQOnaS\n", - "UWyt/iKn4/34BjEeaw4/Ld7+f06LXqSr18SUr0LTB2kk+Zzf0Och1C+G1CNLgJMM\n", - "MNQikAv0xdaOMX3HzA+phFlLbw/x8sboMlzmrbr92a/4Fp5WvmOSHH3ciwTtbAQn\n", - "A2TfExNOaKD2BG5FnB7c66puw2/yVxhveocQYgmT9XtMrNX00vEZJQ==\n", - "-----END CERTIFICATE-----\n", - NULL -}; - -/* - * Verify that a SubjectPublicKeyInfo with an id-RSAES-OAEP - * AlgorithmIdentifier decodes to an RSA EVP_PKEY via both the - * provider decoder path (exercised by X509_from_strings() + - * X509_get0_pubkey()) and the legacy type-specific path - * (exercised by d2i_RSA_PUBKEY() when available). - */ -static int test_rsaesoaep_spki(void) -{ - int ret = 0; - X509 *cert = NULL; - EVP_PKEY *pkey = NULL; -#ifndef OPENSSL_NO_DEPRECATED_3_0 - const X509_PUBKEY *xpk = NULL; - unsigned char *spki_der = NULL, *q; - const unsigned char *p; - int spki_len; - RSA *rsa = NULL; -#endif - - /* Provider / OSSL_DECODER path. */ - if (!TEST_ptr(cert = X509_from_strings(kRsaesOaepCert)) - || !TEST_ptr(pkey = X509_get0_pubkey(cert)) - || !TEST_int_eq(EVP_PKEY_get_base_id(pkey), EVP_PKEY_RSA) - || !TEST_int_ge(EVP_PKEY_get_bits(pkey), 2048)) - goto err; - -#ifndef OPENSSL_NO_DEPRECATED_3_0 - /* - * Legacy path: d2i_RSA_PUBKEY() routes through - * ossl_d2i_PUBKEY_legacy() which sets flag_force_legacy=1, - * so this exercises the NID_rsaesOaep -> NID_rsaEncryption - * remap in x509_pubkey_decode(). - */ - if (!TEST_ptr(xpk = X509_get_X509_PUBKEY(cert)) - || !TEST_int_gt((spki_len = i2d_X509_PUBKEY(xpk, NULL)), 0) - || !TEST_ptr(spki_der = OPENSSL_malloc(spki_len))) - goto err; - q = spki_der; - if (!TEST_int_eq(i2d_X509_PUBKEY(xpk, &q), spki_len)) - goto err; - p = spki_der; - if (!TEST_ptr(rsa = d2i_RSA_PUBKEY(NULL, &p, spki_len)) - || !TEST_int_ge(RSA_bits(rsa), 2048)) - goto err; -#endif - - ret = 1; -err: -#ifndef OPENSSL_NO_DEPRECATED_3_0 - RSA_free(rsa); - OPENSSL_free(spki_der); -#endif - X509_free(cert); - return ret; -} - -/* - * nameConstraints extnValue contents with one empty directoryName subtree. - * Empty X509_NAME has canon_enc == NULL / canon_enclen == 0. - * - * SEQUENCE { [0|1] { SEQUENCE { [4] { SEQUENCE {} } } } } - */ -static const unsigned char nc_excluded_empty_dirname[] = { - 0x30, 0x08, 0xa1, 0x06, 0x30, 0x04, 0xa4, 0x02, 0x30, 0x00 -}; -static const unsigned char nc_permitted_empty_dirname[] = { - 0x30, 0x08, 0xa0, 0x06, 0x30, 0x04, 0xa4, 0x02, 0x30, 0x00 -}; - -/* Decode a raw nameConstraints extnValue into a NAME_CONSTRAINTS object. */ -static NAME_CONSTRAINTS *nc_empty_dirname_from_der(const unsigned char *der, - unsigned int der_len) -{ - NAME_CONSTRAINTS *nc = NULL; - ASN1_OCTET_STRING *os = NULL; - X509_EXTENSION *ext = NULL; - - os = ASN1_OCTET_STRING_new(); - if (!TEST_ptr(os) - || !TEST_true(ASN1_OCTET_STRING_set(os, der, der_len))) - goto end; - ext = X509_EXTENSION_create_by_NID(NULL, NID_name_constraints, - 1 /* critical */, os); - if (!TEST_ptr(ext)) - goto end; - nc = X509V3_EXT_d2i(ext); - -end: - X509_EXTENSION_free(ext); - ASN1_OCTET_STRING_free(os); - return nc; -} - -/* Build a minimal certificate with a non-empty subject DN. */ -static X509 *nc_empty_dirname_subject(const char *cn) -{ - X509 *x = NULL; - X509_NAME *nm = NULL; - - if (!TEST_ptr(x = X509_new())) - goto err; - nm = X509_NAME_new(); - if (!TEST_ptr(nm) - || !TEST_true(X509_NAME_add_entry_by_txt(nm, "CN", MBSTRING_ASC, - (const unsigned char *)cn, -1, -1, 0)) - || !TEST_true(X509_set_subject_name(x, nm))) - goto err; - X509_NAME_free(nm); - return x; - -err: - X509_NAME_free(nm); - X509_free(x); - return NULL; -} - -/* Check an empty directoryName constraint against a non-empty subject DN. */ -static int nc_check_empty_dirname(const unsigned char *der, unsigned int der_len, - int expected) -{ - int ok = 0; - NAME_CONSTRAINTS *nc = NULL; - X509 *x = NULL; - - if (!TEST_ptr(nc = nc_empty_dirname_from_der(der, der_len)) - || !TEST_ptr(x = nc_empty_dirname_subject("leaf.example")) - || !TEST_int_eq(NAME_CONSTRAINTS_check(x, nc), expected)) - goto end; - - ok = 1; - -end: - X509_free(x); - NAME_CONSTRAINTS_free(nc); - return ok; -} - -/* Empty excluded directoryName matches the subject DN: excluded violation. */ -static int test_nc_empty_dirname_excluded(void) -{ - return nc_check_empty_dirname(nc_excluded_empty_dirname, - sizeof(nc_excluded_empty_dirname), X509_V_ERR_EXCLUDED_VIOLATION); -} - -/* Empty permitted directoryName matches the subject DN: permitted. */ -static int test_nc_empty_dirname_permitted(void) -{ - return nc_check_empty_dirname(nc_permitted_empty_dirname, - sizeof(nc_permitted_empty_dirname), X509_V_OK); -} - OPT_TEST_DECLARE_USAGE("\n") int setup_tests(void) @@ -682,12 +321,6 @@ int setup_tests(void) ADD_TEST(test_x509_delete_last_extension); ADD_TEST(test_x509_crl_delete_last_extension); ADD_TEST(test_x509_revoked_delete_last_extension); - ADD_TEST(test_drop_empty_cert_keyids); - ADD_TEST(test_drop_empty_csr_keyids); - ADD_TEST(test_rsaesoaep_spki); - ADD_TEST(test_x509_verify_with_new); - ADD_TEST(test_nc_empty_dirname_excluded); - ADD_TEST(test_nc_empty_dirname_permitted); return 1; } diff --git a/test/x509_time_test.c b/test/x509_time_test.c index 59dad294ef..b96a627bb5 100644 --- a/test/x509_time_test.c +++ b/test/x509_time_test.c @@ -1,5 +1,5 @@ /* - * Copyright 2017-2026 The OpenSSL Project Authors. All Rights Reserved. + * Copyright 2017-2025 The OpenSSL Project Authors. All Rights Reserved. * * Licensed under the Apache License 2.0 (the "License"). You may not use * this file except in compliance with the License. You can obtain a copy @@ -17,8 +17,6 @@ #include "testutil.h" #include "internal/nelem.h" -#include - typedef struct { const char *data; int type; @@ -216,7 +214,6 @@ static TESTDATA_FORMAT x509_format_tests[] = { }, }; -#if !defined(OPENSSL_NO_DEPRECATED_4_0) static TESTDATA x509_cmp_tests[] = { { "20170217180154Z", @@ -416,9 +413,7 @@ static int test_x509_cmp_time(int idx) t.length = (int)strlen(x509_cmp_tests[idx].data); t.flags = 0; - OSSL_BEGIN_ALLOW_DEPRECATED result = X509_cmp_time(&t, &x509_cmp_tests[idx].cmp_time); - OSSL_END_ALLOW_DEPRECATED if (!TEST_int_eq(result, x509_cmp_tests[idx].expected)) { TEST_info("test_x509_cmp_time(%d) failed: expected %d, got %d\n", idx, x509_cmp_tests[idx].expected, result); @@ -439,7 +434,6 @@ static int test_x509_cmp_time_current(void) asn1_now = ASN1_TIME_adj(NULL, now, 0, 0); /* X509_cmp_time is expected to return -1 for equal */ - OSSL_BEGIN_ALLOW_DEPRECATED cmp_result = X509_cmp_time(asn1_now, &now); if (!TEST_int_eq(cmp_result, -1)) failed = 1; @@ -451,7 +445,6 @@ static int test_x509_cmp_time_current(void) cmp_result = X509_cmp_time(asn1_after, &now); if (!TEST_int_eq(cmp_result, 1)) failed = 1; - OSSL_END_ALLOW_DEPRECATED ASN1_TIME_free(asn1_before); ASN1_TIME_free(asn1_after); @@ -469,7 +462,6 @@ static int test_X509_cmp_timeframe_vpm(const X509_VERIFY_PARAM *vpm, && (X509_VERIFY_PARAM_get_flags(vpm) & X509_V_FLAG_USE_CHECK_TIME) == 0 && (X509_VERIFY_PARAM_get_flags(vpm) & X509_V_FLAG_NO_CHECK_TIME) != 0; - OSSL_BEGIN_ALLOW_DEPRECATED return asn1_before != NULL && asn1_mid != NULL && asn1_after != NULL && TEST_int_eq(X509_cmp_timeframe(vpm, asn1_before, asn1_after), 0) && TEST_int_eq(X509_cmp_timeframe(vpm, asn1_before, NULL), 0) @@ -481,7 +473,6 @@ static int test_X509_cmp_timeframe_vpm(const X509_VERIFY_PARAM *vpm, always_0 ? 0 : 1) && TEST_int_eq(X509_cmp_timeframe(vpm, asn1_after, asn1_before), always_0 ? 0 : 1); - OSSL_END_ALLOW_DEPRECATED } static int test_X509_cmp_timeframe(void) @@ -513,7 +504,6 @@ finish: return res; } -#endif /* !defined(OPENSSL_NO_DEPRECATED_4_0) */ static int test_x509_time(int idx) { @@ -759,11 +749,9 @@ err: int setup_tests(void) { -#if !defined(OPENSSL_NO_DEPRECATED_4_0) ADD_TEST(test_x509_cmp_time_current); ADD_TEST(test_X509_cmp_timeframe); ADD_ALL_TESTS(test_x509_cmp_time, OSSL_NELEM(x509_cmp_tests)); -#endif /* !defined(OPENSSL_NO_DEPRECATED_4_0) */ ADD_ALL_TESTS(test_x509_time, OSSL_NELEM(x509_format_tests)); ADD_ALL_TESTS(test_days, OSSL_NELEM(day_of_week_tests)); ADD_ALL_TESTS(test_x509_time_print_rfc_822, OSSL_NELEM(x509_print_tests_rfc_822)); diff --git a/tools/build.info b/tools/build.info new file mode 100644 index 0000000000..059e582345 --- /dev/null +++ b/tools/build.info @@ -0,0 +1,7 @@ +{- our $c_rehash_name = + $config{target} =~ /^(VC|vms)-/ ? "c_rehash.pl" : "c_rehash"; + "" -} +IF[{- !$disabled{apps} -}] + SCRIPTS={- $c_rehash_name -} + SOURCE[{- $c_rehash_name -}]=c_rehash.in +ENDIF diff --git a/tools/c_rehash.in b/tools/c_rehash.in new file mode 100644 index 0000000000..bb68c44692 --- /dev/null +++ b/tools/c_rehash.in @@ -0,0 +1,252 @@ +#!{- $config{HASHBANGPERL} -} +{- use OpenSSL::Util; -} +# {- join("\n# ", @autowarntext) -} +# Copyright 1999-2025 The OpenSSL Project Authors. All Rights Reserved. +# +# Licensed under the Apache License 2.0 (the "License"). You may not use +# this file except in compliance with the License. You can obtain a copy +# in the file LICENSE in the source distribution or at +# https://www.openssl.org/source/license.html + +# Perl c_rehash script, scan all files in a directory +# and add symbolic links to their hash values. + +my $dir = {- quotify1($config{openssldir}) -}; +my $prefix = {- quotify1($config{prefix}) -}; + +my $errorcount = 0; +my $openssl = $ENV{OPENSSL} || "openssl"; +my $pwd; +my $x509hash = "-subject_hash"; +my $crlhash = "-hash"; +my $verbose = 0; +my $symlink_exists=eval {symlink("",""); 1}; +my $removelinks = 1; + +## Parse flags. +while ( $ARGV[0] =~ /^-/ ) { + my $flag = shift @ARGV; + last if ( $flag eq '--'); + if ( $flag eq '-old') { + $x509hash = "-subject_hash_old"; + $crlhash = "-hash_old"; + } elsif ( $flag eq '-h' || $flag eq '-help' ) { + help(); + } elsif ( $flag eq '-n' ) { + $removelinks = 0; + } elsif ( $flag eq '-v' ) { + $verbose++; + } + else { + print STDERR "Usage error; try -h.\n"; + exit 1; + } +} + +sub help { + print "Usage: c_rehash [-old] [-h] [-help] [-v] [dirs...]\n"; + print " -old use old-style digest\n"; + print " -h or -help print this help text\n"; + print " -v print files removed and linked\n"; + exit 0; +} + +eval "require Cwd"; +if (defined(&Cwd::getcwd)) { + $pwd=Cwd::getcwd(); +} else { + $pwd=`pwd`; + chomp($pwd); +} + +# DOS/Win32 or Unix delimiter? Prefix our installdir, then search. +my $path_delim = ($pwd =~ /^[a-z]\:/i) ? ';' : ':'; +$ENV{PATH} = "$prefix/bin" . ($ENV{PATH} ? $path_delim . $ENV{PATH} : ""); + +if (!(-f $openssl && -x $openssl)) { + my $found = 0; + foreach (split /$path_delim/, $ENV{PATH}) { + if (-f "$_/$openssl" && -x "$_/$openssl") { + $found = 1; + $openssl = "$_/$openssl"; + last; + } + } + if ($found == 0) { + print STDERR "c_rehash: rehashing skipped ('openssl' program not available)\n"; + exit 0; + } +} + +if (@ARGV) { + @dirlist = @ARGV; +} elsif ($ENV{SSL_CERT_DIR}) { + @dirlist = split /$path_delim/, $ENV{SSL_CERT_DIR}; +} else { + $dirlist[0] = "$dir/certs"; +} + +if (-d $dirlist[0]) { + chdir $dirlist[0]; + $openssl="$pwd/$openssl" if (!(-f $openssl && -x $openssl)); + chdir $pwd; +} + +foreach (@dirlist) { + if (-d $_ ) { + if ( -w $_) { + hash_dir($_); + } else { + print "Skipping $_, can't write\n"; + $errorcount++; + } + } +} +exit($errorcount); + +sub copy_file { + my ($src_fname, $dst_fname) = @_; + + if (open(my $in, "<", $src_fname)) { + if (open(my $out, ">", $dst_fname)) { + print $out $_ while (<$in>); + close $out; + } else { + warn "Cannot open $dst_fname for write, $!"; + } + close $in; + } else { + warn "Cannot open $src_fname for read, $!"; + } +} + +sub hash_dir { + my $dir = shift; + my %hashlist; + + print "Doing $dir\n"; + + if (!chdir $dir) { + print STDERR "WARNING: Cannot chdir to '$dir', $!\n"; + return; + } + + opendir(DIR, ".") || print STDERR "WARNING: Cannot opendir '.', $!\n"; + my @flist = sort readdir(DIR); + closedir DIR; + if ( $removelinks ) { + # Delete any existing symbolic links + foreach (grep {/^[\da-f]+\.r{0,1}\d+$/} @flist) { + if (-l $_) { + print "unlink $_\n" if $verbose; + unlink $_ || warn "Can't unlink $_, $!\n"; + } + } + } + FILE: foreach $fname (grep {/\.(pem|crt|cer|crl)$/} @flist) { + # Check to see if certificates and/or CRLs present. + my ($cert, $crl) = check_file($fname); + if (!$cert && !$crl) { + print STDERR "WARNING: $fname does not contain a certificate or CRL: skipping\n"; + next; + } + link_hash_cert($fname) if ($cert); + link_hash_crl($fname) if ($crl); + } + + chdir $pwd; +} + +sub check_file { + my ($is_cert, $is_crl) = (0,0); + my $fname = $_[0]; + + open(my $in, "<", $fname); + while(<$in>) { + if (/^-----BEGIN (.*)-----/) { + my $hdr = $1; + if ($hdr =~ /^(X509 |TRUSTED |)CERTIFICATE$/) { + $is_cert = 1; + last if ($is_crl); + } elsif ($hdr eq "X509 CRL") { + $is_crl = 1; + last if ($is_cert); + } + } + } + close $in; + return ($is_cert, $is_crl); +} + +sub compute_hash { + my $fh; + if ( $^O eq "VMS" ) { + # VMS uses the open through shell + # The file names are safe there and list form is unsupported + if (!open($fh, "-|", join(' ', @_))) { + print STDERR "Cannot compute hash on '$fname'\n"; + return; + } + } else { + if (!open($fh, "-|", @_)) { + print STDERR "Cannot compute hash on '$fname'\n"; + return; + } + binmode($fh, ":crlf"); + } + return (<$fh>, <$fh>); +} + +# Link a certificate to its subject name hash value, each hash is of +# the form . where n is an integer. If the hash value already exists +# then we need to up the value of n, unless its a duplicate in which +# case we skip the link. We check for duplicates by comparing the +# certificate fingerprints + +sub link_hash_cert { + link_hash($_[0], 'cert'); +} + +# Same as above except for a CRL. CRL links are of the form .r + +sub link_hash_crl { + link_hash($_[0], 'crl'); +} + +sub link_hash { + my ($fname, $type) = @_; + my $is_cert = $type eq 'cert'; + + my ($hash, $fprint) = compute_hash($openssl, + $is_cert ? "x509" : "crl", + $is_cert ? $x509hash : $crlhash, + "-fingerprint", "-noout", + "-in", $fname); + chomp $hash; + $hash =~ s/^.*=// if !$is_cert; + chomp $fprint; + return if !$hash; + $fprint =~ s/^.*=//; + $fprint =~ tr/://d; + my $suffix = 0; + # Search for an unused hash filename + my $crlmark = $is_cert ? "" : "r"; + while(exists $hashlist{"$hash.$crlmark$suffix"}) { + # Hash matches: if fingerprint matches its a duplicate cert + if ($hashlist{"$hash.$crlmark$suffix"} eq $fprint) { + my $what = $is_cert ? 'certificate' : 'CRL'; + print STDERR "WARNING: Skipping duplicate $what $fname\n"; + return; + } + $suffix++; + } + $hash .= ".$crlmark$suffix"; + if ($symlink_exists) { + print "link $fname -> $hash\n" if $verbose; + symlink $fname, $hash || warn "Can't symlink, $!"; + } else { + print "copy $fname -> $hash\n" if $verbose; + copy_file($fname, $hash); + } + $hashlist{$hash} = $fprint; +} diff --git a/util/acvp-test.py b/util/acvp-test.py deleted file mode 100755 index d1e56b4a7f..0000000000 --- a/util/acvp-test.py +++ /dev/null @@ -1,1301 +0,0 @@ -#!/usr/bin/env python3 -""" -acvp-test.py - -Tests an OpenSSL binary against the NIST ACVTS demo server for a chosen algorithm. - -Usage: - python acvp-test.py --openssl /path/to/openssl --cert my.cer --key my.key \ - --totp-seed totp.txt --algorithm ACVP-AES-CBC - python acvp-test.py --openssl /path/to/openssl --cert my.cer --key my.key \ - --totp-seed totp.txt --algorithm ACVP-AES-CBC --direction encrypt --key-len 256 - python acvp-test.py --openssl /path/to/openssl --cert my.cer --key my.key \ - --totp-seed totp.txt --algorithm SHA2-256 - python acvp-test.py --openssl /path/to/openssl --cert my.cer --key my.key \ - --totp-seed totp.txt --algorithm HMAC-SHA2-256 --save-vectors - -Algorithms supported: - Symmetric : ACVP-AES-CBC, ACVP-AES-ECB, ACVP-AES-CTR - Digest : SHA2-256, SHA2-384, SHA2-512, SHA3-256, SHA3-384, SHA3-512 - MAC : HMAC-SHA2-256, HMAC-SHA2-384, HMAC-SHA2-512 - PQC KEM : ML-KEM-keyGen - PQC Sig : ML-DSA-keyGen, ML-DSA-sigGen, ML-DSA-sigVer - SLH-DSA-keyGen, SLH-DSA-sigGen, SLH-DSA-sigVer - -Requirements: - pip install requests pyotp cryptography - -Credentials needed (pass via command-line arguments): - --openssl PATH - path to the OpenSSL binary to test - --cert FILE - TLS client certificate from NIST (.cer) - --key FILE - corresponding private key (.key) - --totp-seed FILE - file containing the Base64-encoded TOTP seed (one line) -""" - -import argparse -import base64 -import ctypes -import glob -import hashlib -import json -import os -import platform -import re -import subprocess -import sys -import time - -import pyotp -import requests -from cryptography.hazmat.primitives.ciphers import Cipher, algorithms, modes - -DEMO_URL = "https://demo.acvts.nist.gov/acvp/v1" -PROD_URL = "https://acvts.nist.gov/acvp/v1" -BASE_URL = DEMO_URL # overridden to PROD_URL when --production is set -CERT_FILE = None # set from --cert -KEY_FILE = None # set from --key -TOTP_SEED_FILE = None # set from --totp-seed -OPENSSL_BIN = None # set from --openssl - - -# --------------------------------------------------------------------------- -# ALGORITHM CAPABILITY BUILDERS -# Each returns the capability dict to include in the "algorithms" list during -# test session registration. Signature: (directions, key_lens) -> dict -# --------------------------------------------------------------------------- - -def build_aes_cbc_cap(directions, key_lens): - return { - "algorithm": "ACVP-AES-CBC", - "revision": "1.0", - "direction": directions or ["encrypt", "decrypt"], - "keyLen": key_lens or [128, 192, 256], - } - - -def build_aes_ecb_cap(directions, key_lens): - return { - "algorithm": "ACVP-AES-ECB", - "revision": "1.0", - "direction": directions or ["encrypt", "decrypt"], - "keyLen": key_lens or [128, 192, 256], - } - - -def build_sha256_cap(*_): - return { - "algorithm": "SHA2-256", - "revision": "1.0", - "messageLength": [{"min": 0, "max": 65536, "increment": 8}], - } - - -def build_sha384_cap(*_): - return { - "algorithm": "SHA2-384", - "revision": "1.0", - "messageLength": [{"min": 0, "max": 65536, "increment": 8}], - } - - -def build_sha512_cap(*_): - return { - "algorithm": "SHA2-512", - "revision": "1.0", - "messageLength": [{"min": 0, "max": 65536, "increment": 8}], - } - - -def build_aes_ctr_cap(directions, key_lens): - return { - "algorithm": "ACVP-AES-CTR", - "revision": "1.0", - "direction": directions or ["encrypt", "decrypt"], - "keyLen": key_lens or [128, 192, 256], - "payloadLen": [{"min": 8, "max": 128, "increment": 8}], - "incrementalCounter": True, - "overflowCounter": True, - "performCounterTests": False, - } - - -def build_hmac_sha256_cap(*_): - return { - "algorithm": "HMAC-SHA2-256", - "revision": "1.0", - "keyLen": [{"min": 8, "max": 524288, "increment": 8}], - "macLen": [{"min": 32, "max": 256, "increment": 8}], - } - - -def build_hmac_sha384_cap(*_): - return { - "algorithm": "HMAC-SHA2-384", - "revision": "1.0", - "keyLen": [{"min": 8, "max": 524288, "increment": 8}], - "macLen": [{"min": 32, "max": 384, "increment": 8}], - } - - -def build_hmac_sha512_cap(*_): - return { - "algorithm": "HMAC-SHA2-512", - "revision": "1.0", - "keyLen": [{"min": 8, "max": 524288, "increment": 8}], - "macLen": [{"min": 32, "max": 512, "increment": 8}], - } - - -def build_sha3_256_cap(*_): - return { - "algorithm": "SHA3-256", - "revision": "2.0", - "messageLength": [{"min": 0, "max": 65536, "increment": 8}], - } - - -def build_sha3_384_cap(*_): - return { - "algorithm": "SHA3-384", - "revision": "2.0", - "messageLength": [{"min": 0, "max": 65536, "increment": 8}], - } - - -def build_sha3_512_cap(*_): - return { - "algorithm": "SHA3-512", - "revision": "2.0", - "messageLength": [{"min": 0, "max": 65536, "increment": 8}], - } - - -# --------------------------------------------------------------------------- -# PQC CAPABILITY BUILDERS -# --------------------------------------------------------------------------- - -def build_ml_kem_keygen_cap(*_): - return { - "algorithm": "ML-KEM", - "mode": "keyGen", - "revision": "FIPS203", - "parameterSets": ["ML-KEM-512", "ML-KEM-768", "ML-KEM-1024"], - } - - -def build_ml_dsa_keygen_cap(*_): - return { - "algorithm": "ML-DSA", - "mode": "keyGen", - "revision": "FIPS204", - "parameterSets": ["ML-DSA-44", "ML-DSA-65", "ML-DSA-87"], - } - - -def build_ml_dsa_siggen_cap(*_): - ps = ["ML-DSA-44", "ML-DSA-65", "ML-DSA-87"] - mln = [{"min": 8, "max": 65536, "increment": 8}] - return { - "algorithm": "ML-DSA", - "mode": "sigGen", - "revision": "FIPS204", - "parameterSets": ps, - "messageLength": mln, - "deterministic": [True, False], - "signatureInterfaces": ["1"], - "capabilities": [{"parameterSets": ps, "messageLength": mln, "deterministic": [True, False]}], - } - - -def build_ml_dsa_sigver_cap(*_): - ps = ["ML-DSA-44", "ML-DSA-65", "ML-DSA-87"] - mln = [{"min": 8, "max": 65536, "increment": 8}] - return { - "algorithm": "ML-DSA", - "mode": "sigVer", - "revision": "FIPS204", - "parameterSets": ps, - "messageLength": mln, - "signatureInterfaces": ["1"], - "capabilities": [{"parameterSets": ps, "messageLength": mln}], - } - - -_SLH_DSA_PARAM_SETS = [ - "SLH-DSA-SHA2-128s", "SLH-DSA-SHA2-128f", - "SLH-DSA-SHA2-192s", "SLH-DSA-SHA2-192f", - "SLH-DSA-SHA2-256s", "SLH-DSA-SHA2-256f", - "SLH-DSA-SHAKE-128s", "SLH-DSA-SHAKE-128f", - "SLH-DSA-SHAKE-192s", "SLH-DSA-SHAKE-192f", - "SLH-DSA-SHAKE-256s", "SLH-DSA-SHAKE-256f", -] - - -def build_slh_dsa_keygen_cap(*_): - return { - "algorithm": "SLH-DSA", - "mode": "keyGen", - "revision": "FIPS205", - "parameterSets": _SLH_DSA_PARAM_SETS, - } - - -def build_slh_dsa_siggen_cap(*_): - mln = [{"min": 8, "max": 65536, "increment": 8}] - return { - "algorithm": "SLH-DSA", - "mode": "sigGen", - "revision": "FIPS205", - "parameterSets": _SLH_DSA_PARAM_SETS, - "messageLength": mln, - "deterministic": [True, False], - "signatureInterfaces": ["1"], - "capabilities": [{"parameterSets": _SLH_DSA_PARAM_SETS, "messageLength": mln, "deterministic": [True, False]}], - } - - -def build_slh_dsa_sigver_cap(*_): - mln = [{"min": 8, "max": 65536, "increment": 8}] - return { - "algorithm": "SLH-DSA", - "mode": "sigVer", - "revision": "FIPS205", - "parameterSets": _SLH_DSA_PARAM_SETS, - "messageLength": mln, - "signatureInterfaces": ["1"], - "capabilities": [{"parameterSets": _SLH_DSA_PARAM_SETS, "messageLength": mln}], - } - - -CAPABILITY_BUILDERS = { - "ACVP-AES-CBC": build_aes_cbc_cap, - "ACVP-AES-CTR": build_aes_ctr_cap, - "ACVP-AES-ECB": build_aes_ecb_cap, - "HMAC-SHA2-256": build_hmac_sha256_cap, - "HMAC-SHA2-384": build_hmac_sha384_cap, - "HMAC-SHA2-512": build_hmac_sha512_cap, - "SHA2-256": build_sha256_cap, - "SHA2-384": build_sha384_cap, - "SHA2-512": build_sha512_cap, - "SHA3-256": build_sha3_256_cap, - "SHA3-384": build_sha3_384_cap, - "SHA3-512": build_sha3_512_cap, - "ML-KEM-keyGen": build_ml_kem_keygen_cap, - "ML-DSA-keyGen": build_ml_dsa_keygen_cap, - "ML-DSA-sigGen": build_ml_dsa_siggen_cap, - "ML-DSA-sigVer": build_ml_dsa_sigver_cap, - "SLH-DSA-keyGen": build_slh_dsa_keygen_cap, - "SLH-DSA-sigGen": build_slh_dsa_siggen_cap, - "SLH-DSA-sigVer": build_slh_dsa_sigver_cap, -} - - -# --------------------------------------------------------------------------- -# OPENSSL HELPERS -# --------------------------------------------------------------------------- - -def run_openssl(args_list, stdin=None): - """Run openssl with the given argument list; return stdout bytes.""" - result = subprocess.run([OPENSSL_BIN] + args_list, input=stdin, capture_output=True) - if result.returncode != 0: - raise RuntimeError(result.stderr.decode().strip()) - return result.stdout - - -# --------------------------------------------------------------------------- -# PQC CTYPES HELPERS (EVP C API for deterministic keygen and sign/verify) -# --------------------------------------------------------------------------- - -_OSSL_LIB_PATH = None # set from --lib-path or auto-detected in main() - - -def _find_libcrypto(openssl_bin): - """Auto-detect libcrypto shared library for the given OpenSSL binary. - - Strategy (in order): - 1. Read the binary's dynamic link metadata to find the exact library it - was compiled against (otool -L on macOS; ldd on Linux). - 2. Glob for libcrypto in lib/ and lib64/ relative to the binary. - 3. Fall back to ctypes.util.find_library("crypto"). - """ - # 1. Inspect the binary's dynamic link metadata. - if platform.system() == "Darwin": - try: - out = subprocess.check_output( - ["otool", "-L", openssl_bin], stderr=subprocess.DEVNULL - ).decode() - for line in out.splitlines(): - m = re.match(r"\s+(/\S*libcrypto\S*\.dylib)", line) - if m: - return m.group(1) - except (subprocess.CalledProcessError, FileNotFoundError): - pass - else: - try: - out = subprocess.check_output( - ["ldd", openssl_bin], stderr=subprocess.DEVNULL - ).decode() - for line in out.splitlines(): - m = re.search(r"libcrypto\.so\S*\s+=>\s+(\S+)", line) - if m and m.group(1) != "not": - return m.group(1) - except (subprocess.CalledProcessError, FileNotFoundError): - pass - - # 2. Glob relative to the binary location. - bin_dir = os.path.dirname(os.path.realpath(openssl_bin)) - search_dirs = [ - os.path.realpath(os.path.join(bin_dir, "..", "lib")), - os.path.realpath(os.path.join(bin_dir, "..", "lib64")), - ] - patterns = (["libcrypto.*.dylib", "libcrypto.dylib"] if platform.system() == "Darwin" - else ["libcrypto.so.*", "libcrypto.so"]) - - for lib_dir in search_dirs: - for pattern in patterns: - matches = sorted(glob.glob(os.path.join(lib_dir, pattern))) - if matches: - return matches[-1] - - # 3. System-wide search. - from ctypes.util import find_library - found = find_library("crypto") - if found: - return found - - raise RuntimeError( - "Could not find libcrypto. Use --lib-path to specify the path explicitly." - ) - - -_EVP_PKEY_PUBLIC_KEY = 0x86 # OSSL_KEYMGMT_SELECT_PUBLIC_KEY | OSSL_KEYMGMT_SELECT_ALL_PARAMS -_EVP_PKEY_KEYPAIR = 0x87 # public + private - -_lib_crypto = None - - -def _lib(): - global _lib_crypto - if _lib_crypto is not None: - return _lib_crypto - - lib = ctypes.CDLL(os.path.realpath(_OSSL_LIB_PATH)) - - # OSSL_PARAM_BLD - lib.OSSL_PARAM_BLD_new.restype = ctypes.c_void_p - lib.OSSL_PARAM_BLD_new.argtypes = [] - lib.OSSL_PARAM_BLD_free.restype = None - lib.OSSL_PARAM_BLD_free.argtypes = [ctypes.c_void_p] - lib.OSSL_PARAM_BLD_to_param.restype = ctypes.c_void_p - lib.OSSL_PARAM_BLD_to_param.argtypes = [ctypes.c_void_p] - lib.OSSL_PARAM_BLD_push_octet_string.restype = ctypes.c_int - lib.OSSL_PARAM_BLD_push_octet_string.argtypes = [ - ctypes.c_void_p, ctypes.c_char_p, ctypes.c_void_p, ctypes.c_size_t, - ] - lib.OSSL_PARAM_free.restype = None - lib.OSSL_PARAM_free.argtypes = [ctypes.c_void_p] - - # EVP_PKEY_CTX - lib.EVP_PKEY_CTX_new_from_name.restype = ctypes.c_void_p - lib.EVP_PKEY_CTX_new_from_name.argtypes = [ctypes.c_void_p, ctypes.c_char_p, ctypes.c_char_p] - lib.EVP_PKEY_CTX_free.restype = None - lib.EVP_PKEY_CTX_free.argtypes = [ctypes.c_void_p] - lib.EVP_PKEY_CTX_set_params.restype = ctypes.c_int - lib.EVP_PKEY_CTX_set_params.argtypes = [ctypes.c_void_p, ctypes.c_void_p] - - # keygen - lib.EVP_PKEY_keygen_init.restype = ctypes.c_int - lib.EVP_PKEY_keygen_init.argtypes = [ctypes.c_void_p] - lib.EVP_PKEY_generate.restype = ctypes.c_int - lib.EVP_PKEY_generate.argtypes = [ctypes.c_void_p, ctypes.POINTER(ctypes.c_void_p)] - - # fromdata - lib.EVP_PKEY_fromdata_init.restype = ctypes.c_int - lib.EVP_PKEY_fromdata_init.argtypes = [ctypes.c_void_p] - lib.EVP_PKEY_fromdata.restype = ctypes.c_int - lib.EVP_PKEY_fromdata.argtypes = [ - ctypes.c_void_p, ctypes.POINTER(ctypes.c_void_p), ctypes.c_int, ctypes.c_void_p, - ] - - # raw key extraction - lib.EVP_PKEY_get_raw_public_key.restype = ctypes.c_int - lib.EVP_PKEY_get_raw_public_key.argtypes = [ - ctypes.c_void_p, ctypes.c_void_p, ctypes.POINTER(ctypes.c_size_t), - ] - lib.EVP_PKEY_get_raw_private_key.restype = ctypes.c_int - lib.EVP_PKEY_get_raw_private_key.argtypes = [ - ctypes.c_void_p, ctypes.c_void_p, ctypes.POINTER(ctypes.c_size_t), - ] - - # EVP_PKEY_free - lib.EVP_PKEY_free.restype = None - lib.EVP_PKEY_free.argtypes = [ctypes.c_void_p] - - # EVP_MD_CTX for sign/verify - lib.EVP_MD_CTX_new.restype = ctypes.c_void_p - lib.EVP_MD_CTX_new.argtypes = [] - lib.EVP_MD_CTX_free.restype = None - lib.EVP_MD_CTX_free.argtypes = [ctypes.c_void_p] - - lib.EVP_DigestSignInit_ex.restype = ctypes.c_int - lib.EVP_DigestSignInit_ex.argtypes = [ - ctypes.c_void_p, ctypes.POINTER(ctypes.c_void_p), - ctypes.c_char_p, ctypes.c_void_p, ctypes.c_char_p, - ctypes.c_void_p, ctypes.c_void_p, - ] - lib.EVP_DigestSign.restype = ctypes.c_int - lib.EVP_DigestSign.argtypes = [ - ctypes.c_void_p, ctypes.c_void_p, ctypes.POINTER(ctypes.c_size_t), - ctypes.c_void_p, ctypes.c_size_t, - ] - - lib.EVP_DigestVerifyInit_ex.restype = ctypes.c_int - lib.EVP_DigestVerifyInit_ex.argtypes = [ - ctypes.c_void_p, ctypes.POINTER(ctypes.c_void_p), - ctypes.c_char_p, ctypes.c_void_p, ctypes.c_char_p, - ctypes.c_void_p, ctypes.c_void_p, - ] - lib.EVP_DigestVerify.restype = ctypes.c_int - lib.EVP_DigestVerify.argtypes = [ - ctypes.c_void_p, ctypes.c_void_p, ctypes.c_size_t, - ctypes.c_void_p, ctypes.c_size_t, - ] - - _lib_crypto = lib - return lib - - -def _build_octet_params(key_name: bytes, data: bytes): - """Build a single-entry OSSL_PARAM array; caller must OSSL_PARAM_free. - - key_name MUST be a bytes literal from the caller (OSSL_PARAM_BLD_to_param - stores only a pointer to the key name, not a copy, so it must outlive params). - """ - lib = _lib() - bld = lib.OSSL_PARAM_BLD_new() - if not bld: - raise RuntimeError("OSSL_PARAM_BLD_new failed") - buf = (ctypes.c_ubyte * len(data))(*data) - ok = lib.OSSL_PARAM_BLD_push_octet_string(bld, key_name, buf, len(data)) - params = lib.OSSL_PARAM_BLD_to_param(bld) - lib.OSSL_PARAM_BLD_free(bld) - if not ok or not params: - raise RuntimeError(f"OSSL_PARAM_BLD_push_octet_string({key_name}) failed") - return params - - -def _pqc_keygen_from_seed(algo_name: str, seed: bytes): - """Generate a PQC key pair from a seed; returns (raw_pub_bytes, raw_priv_bytes).""" - lib = _lib() - params = _build_octet_params(b"seed", seed) - try: - ctx = lib.EVP_PKEY_CTX_new_from_name(None, algo_name.encode(), None) - if not ctx: - raise RuntimeError(f"EVP_PKEY_CTX_new_from_name({algo_name}) failed") - try: - if lib.EVP_PKEY_keygen_init(ctx) <= 0: - raise RuntimeError("EVP_PKEY_keygen_init failed") - if lib.EVP_PKEY_CTX_set_params(ctx, params) <= 0: - raise RuntimeError("EVP_PKEY_CTX_set_params(seed) failed") - pkey = ctypes.c_void_p(None) - if lib.EVP_PKEY_generate(ctx, ctypes.byref(pkey)) <= 0: - raise RuntimeError(f"EVP_PKEY_generate({algo_name}) failed") - finally: - lib.EVP_PKEY_CTX_free(ctx) - finally: - lib.OSSL_PARAM_free(params) - - try: - pub_len = ctypes.c_size_t(0) - lib.EVP_PKEY_get_raw_public_key(pkey, None, ctypes.byref(pub_len)) - pub_buf = (ctypes.c_ubyte * pub_len.value)() - if lib.EVP_PKEY_get_raw_public_key(pkey, pub_buf, ctypes.byref(pub_len)) <= 0: - raise RuntimeError("EVP_PKEY_get_raw_public_key failed") - - priv_len = ctypes.c_size_t(0) - lib.EVP_PKEY_get_raw_private_key(pkey, None, ctypes.byref(priv_len)) - priv_buf = (ctypes.c_ubyte * priv_len.value)() - if lib.EVP_PKEY_get_raw_private_key(pkey, priv_buf, ctypes.byref(priv_len)) <= 0: - raise RuntimeError("EVP_PKEY_get_raw_private_key failed") - - return bytes(pub_buf), bytes(priv_buf) - finally: - lib.EVP_PKEY_free(pkey) - - -def _pqc_load_pub(algo_name: str, pub_bytes: bytes): - """Load raw public key bytes into an EVP_PKEY (public key only); caller must free.""" - lib = _lib() - params = _build_octet_params(b"pub", pub_bytes) - try: - ctx = lib.EVP_PKEY_CTX_new_from_name(None, algo_name.encode(), None) - if not ctx: - raise RuntimeError(f"EVP_PKEY_CTX_new_from_name({algo_name}) failed") - try: - if lib.EVP_PKEY_fromdata_init(ctx) <= 0: - raise RuntimeError("EVP_PKEY_fromdata_init failed") - pkey = ctypes.c_void_p(None) - if lib.EVP_PKEY_fromdata(ctx, ctypes.byref(pkey), _EVP_PKEY_PUBLIC_KEY, params) <= 0: - raise RuntimeError(f"EVP_PKEY_fromdata(pub, {algo_name}) failed") - finally: - lib.EVP_PKEY_CTX_free(ctx) - finally: - lib.OSSL_PARAM_free(params) - return pkey - - -def _pqc_load_priv(algo_name: str, priv_bytes: bytes): - """Load raw private key bytes into an EVP_PKEY (keypair); caller must free.""" - lib = _lib() - params = _build_octet_params(b"priv", priv_bytes) - try: - ctx = lib.EVP_PKEY_CTX_new_from_name(None, algo_name.encode(), None) - if not ctx: - raise RuntimeError(f"EVP_PKEY_CTX_new_from_name({algo_name}) failed") - try: - if lib.EVP_PKEY_fromdata_init(ctx) <= 0: - raise RuntimeError("EVP_PKEY_fromdata_init failed") - pkey = ctypes.c_void_p(None) - if lib.EVP_PKEY_fromdata(ctx, ctypes.byref(pkey), _EVP_PKEY_KEYPAIR, params) <= 0: - raise RuntimeError(f"EVP_PKEY_fromdata(priv, {algo_name}) failed") - finally: - lib.EVP_PKEY_CTX_free(ctx) - finally: - lib.OSSL_PARAM_free(params) - return pkey - - -_MAX_SIG_BUF = 65536 # large enough for any PQC signature (SLH-DSA-SHA2-256f ≈ 49 856 B) - -# Direct OSSL_PARAM struct for setting sign params without PARAM_BLD (key name stays -# alive as a bytes literal in the calling frame — c_char_p stores only a pointer). -class _OSSL_PARAM(ctypes.Structure): - _fields_ = [ - ("key", ctypes.c_char_p), - ("data_type", ctypes.c_uint32), - ("data", ctypes.c_void_p), - ("data_size", ctypes.c_size_t), - ("return_size", ctypes.c_size_t), - ] - -_OSSL_PARAM_INTEGER = 1 -_OSSL_PARAM_OCTET_STRING = 5 -_OSSL_RETURN_SIZE_UNSET = ctypes.c_size_t(-1).value - - -def _pqc_sign(algo_name: str, priv_bytes: bytes, msg: bytes, - *, deterministic: bool = True, rnd: bytes = None) -> bytes: - """Sign msg with raw private key bytes; returns signature bytes. - - Always sets message-encoding=0 (RAW) for ACVP signatureInterface:internal. - deterministic=True → set "deterministic"=1 (rnd=0^n per FIPS 204/205). - deterministic=False → set "test-entropy"=rnd bytes provided by ACVP. - """ - lib = _lib() - pkey = _pqc_load_priv(algo_name, priv_bytes) - try: - mdctx = lib.EVP_MD_CTX_new() - if not mdctx: - raise RuntimeError("EVP_MD_CTX_new failed") - try: - pctx = ctypes.c_void_p(None) - if lib.EVP_DigestSignInit_ex( - mdctx, ctypes.byref(pctx), None, None, None, pkey, None) <= 0: - raise RuntimeError(f"EVP_DigestSignInit_ex({algo_name}) failed") - - enc_val = ctypes.c_int(0) # message-encoding = 0 (RAW) - if deterministic: - det_val = ctypes.c_int(1) - sp = (_OSSL_PARAM * 3)() - sp[0].key = b"message-encoding" - sp[0].data_type = _OSSL_PARAM_INTEGER - sp[0].data = ctypes.cast(ctypes.byref(enc_val), ctypes.c_void_p) - sp[0].data_size = ctypes.sizeof(enc_val) - sp[0].return_size = _OSSL_RETURN_SIZE_UNSET - sp[1].key = b"deterministic" - sp[1].data_type = _OSSL_PARAM_INTEGER - sp[1].data = ctypes.cast(ctypes.byref(det_val), ctypes.c_void_p) - sp[1].data_size = ctypes.sizeof(det_val) - sp[1].return_size = _OSSL_RETURN_SIZE_UNSET - sp[2].key = None - elif rnd is not None: - rnd_buf = (ctypes.c_ubyte * len(rnd))(*rnd) - sp = (_OSSL_PARAM * 3)() - sp[0].key = b"message-encoding" - sp[0].data_type = _OSSL_PARAM_INTEGER - sp[0].data = ctypes.cast(ctypes.byref(enc_val), ctypes.c_void_p) - sp[0].data_size = ctypes.sizeof(enc_val) - sp[0].return_size = _OSSL_RETURN_SIZE_UNSET - sp[1].key = b"test-entropy" - sp[1].data_type = _OSSL_PARAM_OCTET_STRING - sp[1].data = ctypes.cast(rnd_buf, ctypes.c_void_p) - sp[1].data_size = len(rnd) - sp[1].return_size = _OSSL_RETURN_SIZE_UNSET - sp[2].key = None - else: - sp = (_OSSL_PARAM * 2)() - sp[0].key = b"message-encoding" - sp[0].data_type = _OSSL_PARAM_INTEGER - sp[0].data = ctypes.cast(ctypes.byref(enc_val), ctypes.c_void_p) - sp[0].data_size = ctypes.sizeof(enc_val) - sp[0].return_size = _OSSL_RETURN_SIZE_UNSET - sp[1].key = None - - if lib.EVP_PKEY_CTX_set_params(pctx, sp) <= 0: - raise RuntimeError(f"EVP_PKEY_CTX_set_params({algo_name}) failed") - - sig_buf = (ctypes.c_ubyte * _MAX_SIG_BUF)() - sig_len = ctypes.c_size_t(_MAX_SIG_BUF) - msg_buf = (ctypes.c_ubyte * len(msg))(*msg) - if lib.EVP_DigestSign( - mdctx, sig_buf, ctypes.byref(sig_len), msg_buf, len(msg)) <= 0: - raise RuntimeError(f"EVP_DigestSign({algo_name}) failed") - return bytes(sig_buf[:sig_len.value]) - finally: - lib.EVP_MD_CTX_free(mdctx) - finally: - lib.EVP_PKEY_free(pkey) - - -def _pqc_verify(algo_name: str, pub_bytes: bytes, msg: bytes, sig: bytes) -> bool: - """Verify a PQC signature; returns True if valid.""" - lib = _lib() - pkey = _pqc_load_pub(algo_name, pub_bytes) - try: - mdctx = lib.EVP_MD_CTX_new() - if not mdctx: - raise RuntimeError("EVP_MD_CTX_new failed") - try: - pctx = ctypes.c_void_p(None) - if lib.EVP_DigestVerifyInit_ex( - mdctx, ctypes.byref(pctx), None, None, None, pkey, None) <= 0: - raise RuntimeError(f"EVP_DigestVerifyInit_ex({algo_name}) failed") - # message-encoding=0 (RAW) for ACVP signatureInterface:internal - enc_val = ctypes.c_int(0) - sp = (_OSSL_PARAM * 2)() - sp[0].key = b"message-encoding" - sp[0].data_type = _OSSL_PARAM_INTEGER - sp[0].data = ctypes.cast(ctypes.byref(enc_val), ctypes.c_void_p) - sp[0].data_size = ctypes.sizeof(enc_val) - sp[0].return_size = _OSSL_RETURN_SIZE_UNSET - sp[1].key = None - if lib.EVP_PKEY_CTX_set_params(pctx, sp) <= 0: - raise RuntimeError(f"EVP_PKEY_CTX_set_params({algo_name}) failed") - sig_buf = (ctypes.c_ubyte * len(sig))(*sig) - msg_buf = (ctypes.c_ubyte * len(msg))(*msg) - ret = lib.EVP_DigestVerify(mdctx, sig_buf, len(sig), msg_buf, len(msg)) - return ret == 1 - finally: - lib.EVP_MD_CTX_free(mdctx) - finally: - lib.EVP_PKEY_free(pkey) - - -def _aes_cipher_name(algorithm, key_len): - # "ACVP-AES-CBC" → "aes-256-cbc" - mode = algorithm.split("-")[-1].lower() - return f"aes-{key_len}-{mode}" - - -def _aes_ecb_block(key_bytes: bytes, block: bytes, decrypt: bool = False) -> bytes: - """Encrypt or decrypt one 16-byte block with AES-ECB via the cryptography library.""" - c = Cipher(algorithms.AES(key_bytes), modes.ECB()) - op = c.decryptor() if decrypt else c.encryptor() - return op.update(block) + op.finalize() - - -def _aes_ecb_mct(direction: str, key_hex: str, payload_hex: str) -> list[dict]: - """ - Run AES-ECB MCT (100 outer × 1000 inner iterations, no IV). - - Each inner step: output = AES_ECB_{Enc|Dec}(key, input); next_input = output. - Key derivation same as CBC: XOR with last n bytes of output[998] ‖ output[999]. - """ - key = bytes.fromhex(key_hex) - msg = bytes.fromhex(payload_hex) - n = len(key) - dec = (direction == "decrypt") - - results = [] - for _ in range(100): - round_key = key - round_msg = msg - - out_prev2 = out_prev = None - for _ in range(1000): - out = _aes_ecb_block(key, msg, decrypt=dec) - out_prev2, out_prev = out_prev, out - msg = out - - combined = out_prev2 + out_prev - key = bytes(a ^ b for a, b in zip(key, combined[-n:])) - msg = out_prev # output[999] seeds the next outer iteration - - if direction == "encrypt": - results.append({"key": round_key.hex().upper(), - "pt": round_msg.hex().upper(), - "ct": out_prev.hex().upper()}) - else: - results.append({"key": round_key.hex().upper(), - "ct": round_msg.hex().upper(), - "pt": out_prev.hex().upper()}) - - return results - - -def _aes_cbc_mct(direction: str, key_hex: str, iv_hex: str, payload_hex: str) -> list[dict]: - """ - Run the ACVP AES-CBC Monte Carlo Test (100 outer × 1000 inner iterations). - - Using the cryptography library for the inner loop avoids 100,000 subprocess - calls (~17 min) while still exercising the same mathematical operations that - the AFT tests already validated against the target binary. - - Key derivation per NIST SP 800-20 / ACVP spec: - 128-bit: newKey = key XOR CT[999] - 192-bit: newKey = key XOR CT[998][8:] ‖ CT[999] - 256-bit: newKey = key XOR CT[998] ‖ CT[999] - """ - key = bytes.fromhex(key_hex) - iv = bytes.fromhex(iv_hex) - pt = bytes.fromhex(payload_hex) - n = len(key) # 16, 24, or 32 bytes - - results = [] - for _ in range(100): - round_key = key - round_iv = iv - round_pt = pt - - ct_prev2 = ct_prev = None - for j in range(1000): - if direction == "encrypt": - ct = _aes_ecb_block(key, bytes(a ^ b for a, b in zip(pt, iv))) - pt, iv = (iv if j == 0 else ct_prev), ct - else: - # CBC decrypt: output = AES_ECB_Dec(key, CT_in) XOR IV - ct = bytes(a ^ b for a, b in zip(_aes_ecb_block(key, pt, decrypt=True), iv)) - iv, pt = pt, (iv if j == 0 else ct_prev) - ct_prev2, ct_prev = ct_prev, ct - - # ct_prev = output[999], ct_prev2 = output[998] - combined = ct_prev2 + ct_prev - key = bytes(a ^ b for a, b in zip(key, combined[-n:])) - iv = ct_prev # output[999] → next IV (same rule for both directions) - pt = ct_prev2 # output[998] → next msg (same rule for both directions) - - if direction == "encrypt": - results.append({"key": round_key.hex().upper(), - "iv": round_iv.hex().upper(), - "pt": round_pt.hex().upper(), - "ct": ct_prev.hex().upper()}) - else: - # round_pt holds the initial CT input for this outer iteration - results.append({"key": round_key.hex().upper(), - "iv": round_iv.hex().upper(), - "ct": round_pt.hex().upper(), - "pt": ct_prev.hex().upper()}) - - return results - - -def process_aes_symmetric(group, tc): - """Handler for ACVP-AES-CBC and ACVP-AES-ECB (AFT and MCT).""" - algorithm = group.get("algorithm", "ACVP-AES-CBC") - direction = group.get("direction", "encrypt") - test_type = group.get("testType", "AFT") - key = tc["key"] - key_len = group.get("keyLen", len(bytes.fromhex(key)) * 8) - cipher = _aes_cipher_name(algorithm, key_len) - iv = tc.get("iv", tc.get("IV", "")) - - if test_type == "MCT": - payload = tc.get("pt" if direction == "encrypt" else "ct", "") - if "ECB" in algorithm.upper(): - return {"tcId": tc["tcId"], "resultsArray": _aes_ecb_mct(direction, key, payload)} - return {"tcId": tc["tcId"], "resultsArray": _aes_cbc_mct(direction, key, iv, payload)} - - # AFT — call the target OpenSSL binary - base_args = ["enc", f"-{cipher}", "-nosalt", "-nopad", "-K", key] - if iv: - base_args += ["-iv", iv] - - if direction == "encrypt": - pt_bytes = bytes.fromhex(tc.get("pt", tc.get("plainText", ""))) - ct = run_openssl(base_args, stdin=pt_bytes).hex().upper() - return {"tcId": tc["tcId"], "ct": ct} - else: - ct_bytes = bytes.fromhex(tc.get("ct", tc.get("cipherText", ""))) - pt = run_openssl(base_args + ["-d"], stdin=ct_bytes).hex().upper() - return {"tcId": tc["tcId"], "pt": pt} - - -def process_aes_ctr(group, tc): - """Handler for ACVP-AES-CTR (AFT only — no MCT for CTR mode).""" - direction = group.get("direction", "encrypt") - key = tc["key"] - key_len = group.get("keyLen", len(bytes.fromhex(key)) * 8) - iv = tc.get("iv", tc.get("IV", "")) - payload = tc.get("pt" if direction == "encrypt" else "ct", "") - - result = run_openssl( - ["enc", f"-aes-{key_len}-ctr", "-nosalt", "-nopad", "-K", key, "-iv", iv], - stdin=bytes.fromhex(payload) if payload else b"", - ) - if direction == "encrypt": - return {"tcId": tc["tcId"], "ct": result.hex().upper()} - return {"tcId": tc["tcId"], "pt": result.hex().upper()} - - -def _sha2_mct(algorithm: str, seed_hex: str) -> list[dict]: - """SHA2 MCT: 3-value sliding window, 100 outer × 1000 inner iterations.""" - bits = algorithm.split("-")[-1] - h = getattr(hashlib, f"sha{bits}") - seed = bytes.fromhex(seed_hex) - results = [] - for _ in range(100): - md = [seed, seed, seed] - for _ in range(1000): - new_md = h(md[0] + md[1] + md[2]).digest() - md = [md[1], md[2], new_md] - seed = md[2] - results.append({"md": seed.hex().upper()}) - return results - - -def _sha3_mct(algorithm: str, seed_hex: str) -> list[dict]: - """SHA3 MCT: simple chain, 100 outer × 1000 inner iterations.""" - bits = algorithm.split("-")[-1] - h = getattr(hashlib, f"sha3_{bits}") - seed = bytes.fromhex(seed_hex) - results = [] - for _ in range(100): - for _ in range(1000): - seed = h(seed).digest() - results.append({"md": seed.hex().upper()}) - return results - - -def process_sha2(group, tc): - """Handler for SHA2-256/384/512. Only handles byte-aligned messages.""" - algorithm = group.get("algorithm", "SHA2-256") - test_type = group.get("testType", "AFT") - bits = algorithm.split("-")[-1] # "256", "384", "512" - - if test_type == "MCT": - seed_hex = tc.get("msg", "") - return {"tcId": tc["tcId"], "resultsArray": _sha2_mct(algorithm, seed_hex)} - - msg_hex = tc.get("msg", "") - msg_len = tc.get("len", len(msg_hex) * 4) # bit length - msg_bytes = bytes.fromhex(msg_hex)[:msg_len // 8] if msg_hex else b"" - md = run_openssl(["dgst", f"-sha{bits}", "-binary"], stdin=msg_bytes).hex().upper() - return {"tcId": tc["tcId"], "md": md} - - -def process_sha3(group, tc): - """Handler for SHA3-256/384/512. Only handles byte-aligned messages.""" - algorithm = group.get("algorithm", "SHA3-256") - test_type = group.get("testType", "AFT") - bits = algorithm.split("-")[-1] # "256", "384", "512" - - if test_type == "MCT": - seed_hex = tc.get("msg", "") - return {"tcId": tc["tcId"], "resultsArray": _sha3_mct(algorithm, seed_hex)} - - msg_hex = tc.get("msg", "") - msg_len = tc.get("len", len(msg_hex) * 4) - msg_bytes = bytes.fromhex(msg_hex)[:msg_len // 8] if msg_hex else b"" - md = run_openssl(["dgst", f"-sha3-{bits}", "-binary"], stdin=msg_bytes).hex().upper() - return {"tcId": tc["tcId"], "md": md} - - -def process_hmac_sha2(group, tc): - """Handler for HMAC-SHA2-256/384/512.""" - algorithm = group.get("algorithm", "HMAC-SHA2-256") - bits = algorithm.split("-")[-1] # "256", "384", "512" - key_hex = tc["key"] - msg_hex = tc.get("msg", "") - mac_len = group.get("macLen", int(bits)) // 8 # bits → bytes - - msg_bytes = bytes.fromhex(msg_hex) if msg_hex else b"" - full_mac = run_openssl( - ["dgst", f"-sha{bits}", "-mac", "HMAC", "-macopt", f"hexkey:{key_hex}", "-binary"], - stdin=msg_bytes, - ).hex().upper() - return {"tcId": tc["tcId"], "mac": full_mac[: mac_len * 2]} - - -# --------------------------------------------------------------------------- -# PQC ALGORITHM HANDLERS -# --------------------------------------------------------------------------- - -def process_ml_kem_keygen(group, tc): - param_set = group["parameterSet"] - seed = bytes.fromhex(tc["d"]) + bytes.fromhex(tc["z"]) - ek, dk = _pqc_keygen_from_seed(param_set, seed) - return {"tcId": tc["tcId"], "ek": ek.hex().upper(), "dk": dk.hex().upper()} - - -def process_ml_dsa_keygen(group, tc): - param_set = group["parameterSet"] - seed = bytes.fromhex(tc["seed"]) - pk, sk = _pqc_keygen_from_seed(param_set, seed) - return {"tcId": tc["tcId"], "pk": pk.hex().upper(), "sk": sk.hex().upper()} - - -def process_slh_dsa_keygen(group, tc): - param_set = group["parameterSet"] - seed = (bytes.fromhex(tc["skSeed"]) - + bytes.fromhex(tc["skPrf"]) - + bytes.fromhex(tc["pkSeed"])) - pk, sk = _pqc_keygen_from_seed(param_set, seed) - return {"tcId": tc["tcId"], "pk": pk.hex().upper(), "sk": sk.hex().upper()} - - -def process_ml_dsa_siggen(group, tc): - param_set = group["parameterSet"] - sk_hex = group.get("sk") or tc.get("sk", "") - msg = bytes.fromhex(tc.get("message", "")) - det = group.get("deterministic", True) - rnd = bytes.fromhex(tc["rnd"]) if not det and "rnd" in tc else None - sig = _pqc_sign(param_set, bytes.fromhex(sk_hex), msg, deterministic=det, rnd=rnd) - return {"tcId": tc["tcId"], "signature": sig.hex().upper()} - - -def process_ml_dsa_sigver(group, tc): - param_set = group["parameterSet"] - pk_hex = group.get("pk") or tc.get("pk", "") - msg = bytes.fromhex(tc.get("message", "")) - sig = bytes.fromhex(tc.get("signature", "")) - passed = _pqc_verify(param_set, bytes.fromhex(pk_hex), msg, sig) - return {"tcId": tc["tcId"], "testPassed": passed} - - -def process_slh_dsa_siggen(group, tc): - param_set = group["parameterSet"] - sk_hex = group.get("sk") or tc.get("sk", "") - msg = bytes.fromhex(tc.get("message", "")) - det = group.get("deterministic", True) - if not det: - rnd_hex = tc.get("rnd") or tc.get("additionalRandomness") or tc.get("optRand") - rnd = bytes.fromhex(rnd_hex) if rnd_hex else None - else: - rnd = None - sig = _pqc_sign(param_set, bytes.fromhex(sk_hex), msg, deterministic=det, rnd=rnd) - return {"tcId": tc["tcId"], "signature": sig.hex().upper()} - - -def process_slh_dsa_sigver(group, tc): - param_set = group["parameterSet"] - pk_hex = group.get("pk") or tc.get("pk", "") - msg = bytes.fromhex(tc.get("message", "")) - sig = bytes.fromhex(tc.get("signature", "")) - passed = _pqc_verify(param_set, bytes.fromhex(pk_hex), msg, sig) - return {"tcId": tc["tcId"], "testPassed": passed} - - -ALGORITHM_HANDLERS = { - "ACVP-AES-CBC": process_aes_symmetric, - "ACVP-AES-CTR": process_aes_ctr, - "ACVP-AES-ECB": process_aes_symmetric, - "HMAC-SHA2-256": process_hmac_sha2, - "HMAC-SHA2-384": process_hmac_sha2, - "HMAC-SHA2-512": process_hmac_sha2, - "SHA2-256": process_sha2, - "SHA2-384": process_sha2, - "SHA2-512": process_sha2, - "SHA3-256": process_sha3, - "SHA3-384": process_sha3, - "SHA3-512": process_sha3, - "ML-KEM-keyGen": process_ml_kem_keygen, - "ML-DSA-keyGen": process_ml_dsa_keygen, - "ML-DSA-sigGen": process_ml_dsa_siggen, - "ML-DSA-sigVer": process_ml_dsa_sigver, - "SLH-DSA-keyGen": process_slh_dsa_keygen, - "SLH-DSA-sigGen": process_slh_dsa_siggen, - "SLH-DSA-sigVer": process_slh_dsa_sigver, -} - - -# --------------------------------------------------------------------------- -# ACVTS REST API -# --------------------------------------------------------------------------- - -def load_totp_secret(): - with open(TOTP_SEED_FILE) as f: - b64 = f.read().strip() - return base64.b32encode(base64.b64decode(b64)).decode() - - -def get_totp(secret_b32): - return pyotp.TOTP(secret_b32, digits=8, digest=hashlib.sha256, interval=30).now() - - -def login(session, totp_secret_b32): - payload = [{"acvVersion": "1.0"}, {"password": get_totp(totp_secret_b32)}] - r = session.post(f"{BASE_URL}/login", json=payload) - r.raise_for_status() - info = r.json()[1] - token = info["accessToken"] - size_constraint = info.get("sizeConstraint", -1) - print(f"[+] Logged in sizeConstraint={size_constraint}") - return token, size_constraint - - -def register(session, token, algorithm_cap, is_sample=True): - """Create a test session; return (ts_id, [vs_id, ...], new_token).""" - headers = {"Authorization": f"Bearer {token}"} - payload = [ - {"acvVersion": "1.0"}, - { - "isSample": is_sample, - "algorithms": [algorithm_cap], # must be a list - }, - ] - r = session.post(f"{BASE_URL}/testSessions", json=payload, headers=headers) - r.raise_for_status() - info = r.json()[1] - - # Session id lives at the end of the "url" path - ts_url = info.get("url", "") - ts_id = ts_url.rstrip("/").split("/")[-1] if ts_url else str(info.get("id", "")) - - # Server returns either vectorSetUrls (list of URL strings) or - # vectorSets (list of {vsId, ...} objects) depending on server version. - vs_urls = info.get("vectorSetUrls", []) - if vs_urls: - vs_ids = [u.rstrip("/").split("/")[-1] for u in vs_urls] - else: - vs_ids = [str(vs["vsId"]) for vs in info.get("vectorSets", [])] - new_token = info.get("accessToken", token) - - print(f"[+] Session {ts_id} created vectorSets={vs_ids}") - return ts_id, vs_ids, new_token - - -def download_vector_set(session, token, ts_id, vs_id, max_retries=20): - headers = {"Authorization": f"Bearer {token}"} - url = f"{BASE_URL}/testSessions/{ts_id}/vectorSets/{vs_id}" - for _ in range(max_retries): - r = session.get(url, headers=headers) - r.raise_for_status() - body = r.json() - if isinstance(body, list) and "retry" in body[1]: - wait = int(body[1]["retry"]) - print(f" [~] VS {vs_id} not ready, waiting {wait}s...") - time.sleep(wait) - continue - print(f"[+] Downloaded VS {vs_id}") - return body - raise RuntimeError(f"VS {vs_id} never became ready after {max_retries} retries") - - -def process_vector_set(vs_data, algorithm): - vs_info = vs_data[1] - vs_id = vs_info["vsId"] - test_groups = vs_info.get("testGroups", []) - handler = ALGORITHM_HANDLERS[algorithm] - - result_groups = [] - for group in test_groups: - tg_id = group["tgId"] - group.setdefault("algorithm", algorithm) - result_tests = [] - for tc in group.get("tests", []): - try: - result_tests.append(handler(group, tc)) - except Exception as exc: - print(f" [!] tcId={tc['tcId']} error: {exc}", file=sys.stderr) - result_tests.append({"tcId": tc["tcId"]}) - result_groups.append({"tgId": tg_id, "tests": result_tests}) - - return [ - {"acvVersion": "1.0"}, - {"vsId": vs_id, "testGroups": result_groups}, - ] - - -def upload_results(session, token, ts_id, vs_id, results, size_constraint=-1): - headers = {"Authorization": f"Bearer {token}"} - url = f"{BASE_URL}/testSessions/{ts_id}/vectorSets/{vs_id}/results" - payload_str = json.dumps(results) - - if 0 < size_constraint < len(payload_str): - # Payload too large: request a dedicated large-submission URI first - r = session.post(f"{BASE_URL}/large", - json=[{"acvVersion": "1.0"}, {}], headers=headers) - r.raise_for_status() - large = r.json()[1] - large_headers = { - "Authorization": f"Bearer {large['accessToken']}", - "Content-Type": "application/json", - } - r = session.post(f"{BASE_URL}{large['url']}", data=payload_str, headers=large_headers) - else: - r = session.post(url, json=results, headers=headers) - - r.raise_for_status() - print(f"[+] Uploaded results for VS {vs_id}") - - -def poll_results(session, token, ts_id, vs_id, max_retries=30): - headers = {"Authorization": f"Bearer {token}"} - url = f"{BASE_URL}/testSessions/{ts_id}/vectorSets/{vs_id}/results" - for _ in range(max_retries): - r = session.get(url, headers=headers) - r.raise_for_status() - body = r.json() - info = body[1] if isinstance(body, list) and len(body) > 1 else body - if "retry" in info: - wait = int(info["retry"]) - print(f" [~] VS {vs_id} grading, waiting {wait}s...") - time.sleep(wait) - continue - # Grading is complete — server returns per-test results, no retry - print(f" [~] VS {vs_id} grading done") - return body - raise RuntimeError(f"VS {vs_id} did not finish within {max_retries} polls") - - -def certify_session(session, token, ts_id): - """PUT /testSessions/{id} to mark the session complete and trigger grading.""" - headers = {"Authorization": f"Bearer {token}"} - r = session.put(f"{BASE_URL}/testSessions/{ts_id}", - json=[{"acvVersion": "1.0"}, {}], headers=headers) - try: - r.raise_for_status() - except Exception: - print(f"[!] Certify returned {r.status_code}: {r.text[:200]}") - return {} - body = r.json() - info = body[1] if isinstance(body, list) and len(body) > 1 else body - print(f"[+] Session certified status={info.get('status')} passed={info.get('passed')}") - return info - - -# --------------------------------------------------------------------------- -# MAIN -# --------------------------------------------------------------------------- - -def main(): - algo_choices = sorted(CAPABILITY_BUILDERS) - parser = argparse.ArgumentParser( - description="Test an OpenSSL binary against the NIST ACVTS demo server.", - formatter_class=argparse.RawDescriptionHelpFormatter, - epilog=f"Supported algorithms: {', '.join(algo_choices)}", - ) - parser.add_argument( - "--openssl", required=True, metavar="PATH", - help="Path to the openssl binary to test", - ) - parser.add_argument( - "--cert", required=True, metavar="FILE", - help="TLS client certificate file (.cer) from NIST", - ) - parser.add_argument( - "--key", required=True, metavar="FILE", - help="Private key file (.key) for the client certificate", - ) - parser.add_argument( - "--totp-seed", required=True, metavar="FILE", - help="File containing the Base64-encoded TOTP seed (one line)", - ) - parser.add_argument( - "--lib-path", metavar="PATH", - help="Path to libcrypto shared library (auto-detected if omitted)", - ) - parser.add_argument( - "--algorithm", default="ACVP-AES-CBC", choices=algo_choices, metavar="ALGO", - help=f"Algorithm to test (default: ACVP-AES-CBC)", - ) - parser.add_argument( - "--direction", nargs="+", choices=["encrypt", "decrypt"], - help="Direction(s) for symmetric algorithms (default: both)", - ) - parser.add_argument( - "--key-len", nargs="+", type=int, metavar="BITS", - help="Key length(s) in bits for symmetric algorithms (default: all)", - ) - parser.add_argument( - "--production", action="store_true", - help="Run as a production validation (default: sample/demo mode)", - ) - parser.add_argument( - "--save-vectors", action="store_true", - help="Save downloaded vector sets to vectors_vsNNN.json", - ) - args = parser.parse_args() - - global BASE_URL, OPENSSL_BIN, CERT_FILE, KEY_FILE, TOTP_SEED_FILE, _OSSL_LIB_PATH - BASE_URL = PROD_URL if args.production else DEMO_URL - OPENSSL_BIN = args.openssl - CERT_FILE = args.cert - KEY_FILE = args.key - TOTP_SEED_FILE = args.totp_seed - _OSSL_LIB_PATH = args.lib_path if args.lib_path else _find_libcrypto(args.openssl) - - algorithm_cap = CAPABILITY_BUILDERS[args.algorithm](args.direction, args.key_len) - - print(f"[*] Algorithm : {args.algorithm}") - print(f"[*] Capability: {json.dumps(algorithm_cap)}") - print(f"[*] Binary : {OPENSSL_BIN}") - print(f"[*] Server : {BASE_URL}") - print(f"[*] Sample : {not args.production}") - - session = requests.Session() - session.cert = (CERT_FILE, KEY_FILE) - session.verify = True # verify NIST server cert via system CA - - totp_secret = load_totp_secret() - - token, size_constraint = login(session, totp_secret) - ts_id, vs_ids, token = register( - session, token, algorithm_cap, is_sample=not args.production - ) - - all_passed = True - for vs_id in vs_ids: - vs_data = download_vector_set(session, token, ts_id, vs_id) - - if args.save_vectors: - fname = f"vectors_vs{vs_id}.json" - with open(fname, "w") as f: - json.dump(vs_data, f, indent=2) - print(f"[+] Saved vectors → {fname}") - - print(f"[+] Running OpenSSL for VS {vs_id}...") - results = process_vector_set(vs_data, args.algorithm) - - with open(f"results_vs{vs_id}.json", "w") as f: - json.dump(results, f, indent=2) - - upload_results(session, token, ts_id, vs_id, results, size_constraint) - - final = poll_results(session, token, ts_id, vs_id) - info = final[1] if isinstance(final, list) and len(final) > 1 else final - # Server uses "disposition": "passed"/"failed"; per-test field is "result": "passed"/"failed" - disposition = info.get("disposition", "") - passed = disposition == "passed" - failed_tcs = sum( - 1 for tc in info.get("tests", []) - if tc.get("result", "passed") != "passed" - ) - label = "PASS" if passed else "FAIL" - print(f"[{label}] VS {vs_id} disposition={disposition} failed_tcs={failed_tcs}") - if not passed: - all_passed = False - - if not args.production: - print("[*] Sample session — skipping certify (not allowed for sample sessions)") - else: - certify_session(session, token, ts_id) - - print() - print("=" * 60) - print(f"{'ALL PASSED' if all_passed else 'ONE OR MORE FAILED'} — session {ts_id}") - sys.exit(0 if all_passed else 1) - - -if __name__ == "__main__": - main() diff --git a/util/check-format-test-negatives.c b/util/check-format-test-negatives.c new file mode 100644 index 0000000000..dd9a89848c --- /dev/null +++ b/util/check-format-test-negatives.c @@ -0,0 +1,911 @@ +/* + * Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved. + * Copyright Siemens AG 2015-2022 + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/* + * A collection of test cases where check-format.pl should not report issues. + * There are some known false positives, though, which are marked below using /*@ + */ + +#include /* should not report whitespace nits within <...> */ +#define F \ + void f() \ + { \ + int i; \ + int j; \ + \ + return; \ + } + +/* allow extra SPC in single-line comment */ +/* + * allow extra SPC in regular multi-line comment + */ +/*- + * allow extra SPC in format-tagged multi-line comment + */ +/** allow extra '*' in comment opening */ +/*! allow extra '!' in comment opening */ +/* + ** allow "**" as first non-space chars of a line within multi-line comment + */ + +int f(void) /* + * trailing multi-line comment + */ +{ + typedef int INT; + void v; + short b; + char c; + signed s; + unsigned u; + int i; + long l; + float f; + double d; + enum { } enu; + struct { + } stru; + union { + } un; + auto a; + extern e; + static int stat; + const int con; + volatile int vola; + register int reg; + OSSL_x y, *p = params; + int params[]; + OSSL_PARAM *(*params[])[MAX + 1]; + XY *(*fn)(int a, char b); + /* + * multi-line comment should not disturb detection of local decls + */ + BIO1 ***b; + /* intra-line comment should not disturb detection of local decls */ + unsigned k; + + /* intra-line comment should not disturb detection of end of local decls */ + + { + int x; /* just decls in block */ + } + if (p != (unsigned char *)&(ctx->tmp[0])) { + i -= (p - (unsigned char *)/* do not confuse with var decl */ + &(ctx->tmp[0])); + } + { + ctx->buf_off = 0; /* do not confuse with var decl */ + return 0; + } + { + ctx->buf_len = EVP_EncodeBlock((unsigned char *)ctx->buf, + (unsigned char *)ctx->tmp, /* no decl */ + ctx->tmp_len); + } + { + EVP_EncodeFinal(ctx->base64, + (unsigned char *)ctx->buf, &(ctx->len)); /* no decl */ + /* push out the bytes */ + goto again; + } + { + f(1, (unsigned long)2); /* no decl */ + x; + } + { + char *pass_str = get_passwd(opt_srv_secret, "x"); + + if (pass_str != NULL) { + cleanse(opt_srv_secret); + res = OSSL_CMP_CTX_set1_secretValue(ctx, (unsigned char *)pass_str, + strlen(pass_str)); + clear_free(pass_str); + } + } +} + +int g(void) +{ + if (ctx == NULL) { /* non-leading end-of-line comment */ + if (/* comment after '(' */ pem_name != NULL /* comment before ')' */) + /* entire-line comment indent usually like for the following line */ + return NULL; /* hanging indent also for this line after comment */ + /* leading comment has same indentation as normal code */ stmt; + /* entire-line comment may have same indent as normal code */ + } + for (i = 0; i < n; i++) + for (; i < n; i++) + for (i = 0;; i++) + for (i = 0;; i++) + for (i = 0; i < n;) + for (i = 0; i < n;) + ; + for (i = 0;;) + for (i = 0;;) + for (i = 0;;) + for (i = 0;;) + for (; i < n;) + for (; j < n;) + for (;; i++) + for (;; i++) + ; + for (;;) /* the only variant allowed in case of "empty" for (...) */ + ; + for (;;) + ; /* should not trigger: space before ';' */ +lab:; /* should not trigger: space before ';' */ + +#if X + if (1) /* bad style: just part of control structure depends on #if */ +#else + if (2) /*@ resulting false positive */ +#endif + c; /*@ resulting false positive */ + + if (1) + if (2) + c; + else + e; + else + f; + do + do + 2; + while (1); + while (2); + + if (pcrl != NULL) { + 1; + 2; + } else if (pcrls != NULL) { + 1; + } + + if (1) + f(a, b); + do + 1; + while (2); /*@ more than one stmt just to construct case */ + if (1) + f(a, b); + else + do + 1; + while (2); + if (1) + f(a, b); + else + do /*@ (non-brace) code before 'do' just to construct case */ + 1; + while (2); + f1234(a, + b); + do /*@ (non-brace) code before 'do' just to construct case */ + 1; + while (2); + if (1) + f(a, + b); + do /*@ (non-brace) code before 'do' just to construct case */ + 1; + while (2); + if (1) + f(a, b); + else + do + f(c, c); /*@ (non-brace) code after 'do' just to construct case */ + while (2); + + if (1) + f(a, b); + else + return; + if (1) + f(a, + b); + else /*@ (non-brace) code before 'else' just to construct case */ + do + 1; + while (2); + + if (1) { /*@ brace after 'if' not on same line just to construct case */ + c; + d; + } + /* this comment is correctly indented if it refers to the following line */ + d; + + if (1) { + 2; + } else /*@ no brace after 'else' just to construct case */ + 3; + do { + } while (x); + if (1) { + 2; + } else { + 3; + } + if (4) + 5; + else + 6; + + if (1) { + if (2) { + case MAC_TYPE_MAC: { + EVP_MAC_CTX *new_mac_ctx; + + if (ctx->pkey == NULL) + return 0; + } break; + case 1: { + ; + } + default: + /* This should be dead code */ + return 0; + } + } + if (expr_line1 + == expr_line2 + && expr_line3) { + c1; + } else { + c; + d; + } + if (expr_line1 + == expr_line2 + && expr_line3) + hanging_stmt; +} + +#define m1 \ + if (ctx == NULL) \ + return 0; \ + if (ossl_param_is_empty(params)) \ + return 1; + +#define m2 \ + do { /* should not be confused with function header followed by '{' */ \ + } while (0) + +/* should not trigger: constant on LHS of comparison or assignment operator */ +X509 *x509 = NULL; +int y = a + 1 < b; +int ret, was_NULL = *certs == NULL; + +/* should not trigger: missing space before ... */ +float z = 1e-6 * (-1) * b[+6] * 1e+1 * (a)->f * (long)+1 + - (tmstart.tv_sec + tmstart.tv_nsec * 1e-9); +struct st = { -1, 0 }; +int x = (y <<= 1) + (z <= 5.0); + +const OPTIONS passwd_options[] = { + { "aixmd5", OPT_AIXMD5, '-', "AIX MD5-based password algorithm" }, +#if !defined(OPENSSL_NO_DES) && !defined(OPENSSL_NO_DEPRECATED_3_0) + { "crypt", OPT_CRYPT, '-', "Standard Unix password algorithm (default)" }, +#endif + OPT_R_OPTIONS, + + { NULL } +}; + +typedef bool (*LOG_cb_t)(int lineno, severity level, const char *msg); +typedef *d(int) + x; +typedef(int) + x; +typedef(int) * () x; +typedef *int * + x; +typedef OSSL_CMP_MSG *(*cmp_srv_process_cb_t)(OSSL_CMP_SRV_CTX *ctx, OSSL_CMP_MSG *msg) + xx; + +#define IF(cond) if (cond) + +_Pragma("GCC diagnostic push") + _Pragma("GCC diagnostic pop") + +#define CB_ERR_IF(cond, ctx, cert, depth, err) \ + if ((cond) && ((depth) < 0 || verify_cb_cert(ctx, cert, depth, err) == 0)) \ + return err + static int verify_cb_crl(X509_STORE_CTX *ctx, int err) +{ + ctx->error = err; + return ctx->verify_cb(0, ctx); +} + +#ifdef CMP_FALLBACK_EST +#define CMP_FALLBACK_CERT_FILE "cert.pem" +#endif + +#define X509_OBJECT_get0_X509(obj) \ + ((obj) == NULL || (obj)->type != X509_LU_X509 ? NULL : (obj)->data.x509) +#define X509_STORE_CTX_set_current_cert(ctx, x) \ + { \ + (ctx)->current_cert = (x); \ + } +#define X509_STORE_set_ex_data(ctx, idx, data) \ + CRYPTO_set_ex_data(&(ctx)->ex_data, (idx), (data)) + +typedef int (*X509_STORE_CTX_check_revocation_fn)(X509_STORE_CTX *ctx); +#define X509_STORE_CTX_set_error_depth(ctx, depth) \ + { \ + (ctx)->error_depth = (depth); \ + } +#define EVP_PKEY_up_ref(x) ((x)->references++) +/* should not report missing blank line: */ +DECLARE_STACK_OF(OPENSSL_CSTRING) +bool UTIL_iterate_dir(int (*fn)(const char *file, void *arg), void *arg, + const char *path, bool recursive); +size_t UTIL_url_encode( + size_t *size_needed); +size_t UTIL_url_encode(const char *source, + char *destination, + size_t destination_len, + size_t *size_needed); +#error well. oops. + +int f() +{ + c; + if (1) + c; + c; + if (1) + if (2) { /*@ brace after 'if' not on same line just to construct case */ + c; + } + e; + const usign = { + 0xDF, + { dd }, + dd + }; + const unsign = { + 0xDF, { dd }, + dd + }; +} +const unsigned char trans_id[OSSL_CMP_TRANSACTIONID_LENGTH] = { + 0xDF, +}; +const unsigned char trans_id[OSSL_CMP_TRANSACTIONID_LENGTH] = { + 0xDF, +}; +typedef int + a; + +typedef struct +{ + int a; +} b; +typedef enum { + w = 0 +} e_type; +typedef struct { + enum { + w = 0 + } e_type; + enum { + w = 0 + } e_type; +} e; +struct s_type { + enum e_type { + w = 0 + }; +}; +struct s_type { + enum e_type { + w = 0 + }; + enum e2_type { + w = 0 + }; +}; + +#define X 1 + 1 +#define Y /* .. */ 2 + 2 +#define Z 3 + 3 * (*a++) + +static varref cmp_vars[] = { + /* comment. comment? comment! */ + { &opt_config }, + { &opt_section }, + + { &opt_server }, + { &opt_proxy }, + { &opt_path }, +}; + +#define SWITCH(x) \ + switch (x) { \ + case 0: \ + break; \ + default: \ + break; \ + } + +#define DEFINE_SET_GET_BASE_TEST(PREFIX, SETN, GETN, DUP, FIELD, TYPE, ERR, \ + DEFAULT, NEW, FREE) \ + static int execute_CTX_##SETN##_##GETN##_##FIELD( \ + TEST_FIXTURE *fixture) \ + { \ + CTX *ctx = fixture->ctx; \ + int (*set_fn)(CTX * ctx, TYPE) = (int (*)(CTX * ctx, TYPE)) PREFIX##_##SETN##_##FIELD; \ + /* comment */ \ + } + +union un var; /* struct/union/enum in variable type */ +struct provider_store_st *f() /* struct/union/enum in function return type */ +{ +} +static void f(struct pem_pass_data *data) /* struct/union/enum in arg list */ +{ +} + +static void *fun(void) +{ + if (pem_name != NULL) + /* comment */ + return NULL; + +label0: +label1: /* allow special indent 1 for label at outermost level in body */ + do { + label2: + size_t available_len, data_len; + const char *curr = txt, *next = txt; + char *tmp; + + { + label3: + } + } while (1); + + char *intraline_string_with_comment_delimiters_and_dbl_space = "1 /*1"; + char *multiline_string_with_comment_delimiters_and_dbl_space = "1 /*1\ +2222222\'22222222222222222\"222222222" + "33333 /*3333333333" + "44 /*44444444444\ +55555555555555\ +6666"; +} + +ASN1_CHOICE(OSSL_CRMF_POPO) = { + ASN1_IMP(OSSL_CRMF_POPO, value.raVerified, ASN1_NULL, 0), + ASN1_EXP(OSSL_CRMF_POPO, value.keyAgreement, OSSL_CRMF_POPOPRIVKEY, 3) +} ASN1_CHOICE_END(OSSL_CRMF_POPO) +IMPLEMENT_ASN1_FUNCTIONS(OSSL_CRMF_POPO) + +ASN1_ADB(OSSL_CRMF_ATTRIBUTETYPEANDVALUE) = { + ADB_ENTRY(NID_id_regCtrl_regToken, + ASN1_SIMPLE(OSSL_CRMF_ATTRIBUTETYPEANDVALUE, + value.regToken, ASN1_UTF8STRING)), +} ASN1_ADB_END(OSSL_CRMF_ATTRIBUTETYPEANDVALUE, 0, type, 0, &attributetypeandvalue_default_tt, NULL); + +ASN1_ITEM_TEMPLATE(OSSL_CRMF_MSGS) = ASN1_EX_TEMPLATE_TYPE(ASN1_TFLG_SEQUENCE_OF, 0, + OSSL_CRMF_MSGS, OSSL_CRMF_MSG) +ASN1_ITEM_TEMPLATE_END(OSSL_CRMF_MSGS) + +void f_looong_body_200() +{ /* function body length up to 200 lines accepted */ + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; +} + +void f_looong_body_201() +{ /* function body length > 200 lines, but LONG BODY marker present */ + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; +} diff --git a/util/check-format-test-positives.c b/util/check-format-test-positives.c new file mode 100644 index 0000000000..7a3afb7782 --- /dev/null +++ b/util/check-format-test-positives.c @@ -0,0 +1,367 @@ +/* + * Copyright 2007-2025 The OpenSSL Project Authors. All Rights Reserved. + * Copyright Siemens AG 2015-2022 + * + * Licensed under the Apache License 2.0 (the "License"). You may not use + * this file except in compliance with the License. You can obtain a copy + * in the file LICENSE in the source distribution or at + * https://www.openssl.org/source/license.html + */ + +/* + * This demonstrates/tests cases where check-format.pl should report issues. + * Some of the reports are due to sanity checks for proper nesting of comment + * delimiters and parenthesis-like symbols, e.g., on unexpected/unclosed braces. + */ + +/* + * The '@'s after leading '*' in comment lines are used for self-tests: + * they mark lines containing a single issue that should be reported. + * Normally it should be reported while handling the given line, + * but in case of delayed checks there is a following digit + * indicating the number of reports expected for this line. + */ + +/* this line is between 81 and 100 chars long, to be reported with -strict-len */ + +/* For each of the following set of lines the tool should complain once */ +/*@ tab character: */ +/*@ intra-line carriage return character: */ +/*@ non-printable ASCII character:  */ +/*@ non-ASCII character: ä */ +/*@ whitespace at EOL: */ +// /*@ end-of-line comment style not allowed (for C90 compatibility) */ +/*@0 intra-line comment indent off by 1, reported unless sloppy-cmt */ +/*X */ /*@2 missing spc or '*' after comment start reported unless sloppy-spc */ +/* X*/ /*@ missing space before comment end , reported unless sloppy-spc */ +/*@ comment starting delimiter: /* inside intra-line comment */ +/*@0 + *@ above multi-line comment start indent off by 1, reported unless sloppy-cmt; this comment line is too long + *@ multi-line comment indent further off by 1 relative to comment start + *@ multi-line comment ending with text on last line */ +/*@2 multi-line comment starting with text on first line + *@ comment starting delimiter: /* inside multi-line comment + *@ multi-line comment indent off by -1 + *X*@ no spc after leading '*' in multi-line comment, reported unless sloppy-spc + *@0 more than two spaces after . in comment, no more reported + *@0 more than two spaces after ? in comment, no more reported + *@0 more than two spaces after ! in comment, no more reported + */ +/*@ multi-line comment end indent off by -1 (relative to comment start) */ +*/ /*@ unexpected comment ending delimiter outside comment */ +/*- '-' for formatted comment not allowed in intra-line comment */ +/*@ comment line is toooooooooooo wide by 1 char, or by 21 chars in case strict-len option is used */ +#if ~0 /*@ '#if' with constant condition */ +#endif /*@ indent of preproc. directive off by 1 (must be 0) */ +#define X (1 + 1) /*@0 extra space in body, reported unless sloppy-spc */ +#define Y 1 /*@ extra space before body, reported unless sloppy-spc */ \ + #define Z /*@2 preprocessor directive within multi-line directive */ + typedef struct { /*@0 extra space in code, reported unless sloppy-spc */ + enum { /*@1 extra space in intra-line comment, no more reported */ + w = 0 /*@ hanging expr indent off by 1, or 3 for lines after '{' */ + && 1, /*@ hanging expr indent off by 3, or -1 for leading '&&' */ + x = 1, /*@ hanging expr indent off by -1 */ + y, + z /*@ no space after ',', reported unless sloppy-spc */ + } e_member; /*@ space before ';', reported unless sloppy-spc */ + int v[1; /*@ unclosed bracket in type declaration */ + union { /*@ statement/type declaration indent off by -1 */ + struct { + } s; /*@ no space before '{', reported unless sloppy-spc */ + }u_member; /*@ no space after '}', reported unless sloppy-spc */ +} s_type; /*@ statement/type declaration indent off by 4 */ +int *somefunc(); /*@ no space before '*' in type decl, r unless sloppy-spc */ +void main(int n) +{ /*@ opening brace at end of function definition header */ + for (;;) + ; /*@ space before ')', reported unless sloppy-spc */ + for (; x; y) + ; /*@2 space after '(' and before ';', unless sloppy-spc */ + for (;; n++) { /*@ missing space after ';', reported unless sloppy-spc */ + return; /*@0 (1-line) single statement in braces */ + } +} /*@2 code after '}' outside expr */ +} /*@ unexpected closing brace (too many '}') outside expr */ +) /*@ unexpected closing paren outside expr */ +#endif /*@ unexpected #endif */ +int f (int a, /*@ space after fn before '(', reported unless sloppy-spc */ + int b, /*@ hanging expr indent off by -1 */ + long I) /*@ single-letter name 'I' */ +{ + int x; /*@ code after '{' opening a block */ + int xx = 1) + /*@ unexpected closing parenthesis */ + 0L < /*@ constant on LHS of comparison operator */ + a] - /*@ unexpected closing bracket */ + 3: * /*@ unexpected ':' (without preceding '?') within expr */ + 4 +}; /*@ unexpected closing brace within expression */ + char y[] = { /*@0 unclosed brace within initializer/enum expression */ + 1* 1, /*@ no space etc. before '*', reported unless sloppy-spc */ + 2, /*@ hanging expr indent (for lines after '{') off by 1 */ + (xx /*@0 unclosed parenthesis in expression */ + ? y /*@0 unclosed '? (conditional expression) */ + [0; /*@4 unclosed bracket in expression */ + /*@ blank line within local decls */ + s_type s; /*@2 local variable declaration indent off by -1 */ + t_type t; /*@ local variable declaration indent again off by -1 */ + /* */ /*@0 missing blank line after local decls */ + somefunc(a, /*@2 statement indent off by -1 */ + "aligned" /*@ expr indent off by -2 accepted if sloppy-hang */ "right" + , b, /*@ expr indent off by -1 */ + b, /*@ expr indent as on line above, accepted if sloppy-hang */ + b, /*@ expr indent off -8 but @ extra indent accepted if sloppy-hang */ + "again aligned" /*@ expr indent off by -9 (left of stmt indent, */ "right", + abc == /*@ .. so reported also with sloppy-hang; this line is too long by 6 or 26 chars */ 456 +#define MAC(A) (A) /*@ nesting indent of preprocessor directive off by 1 */ + ? 1 /*@ hanging expr indent off by 1 */ + : 2); /*@ hanging expr indent off by 2, or 1 for leading ':' */ + if(a /*@ missing space after 'if', reported unless sloppy-spc */ + /*@0 intra-line comment indent off by -1 (not: by 3 due to '&&') */ + && ! 0 /*@2 space after '!', reported unless sloppy-spc */ + || b == /*@ hanging expr indent off by 2, or -2 for leading '||' */ + (x<<= 1) + /*@ missing space before '<<=' reported unless sloppy-spc */ + (xx+= 2) + /*@ missing space before '+=', reported unless sloppy-spc */ + (a^ 1) + /*@ missing space before '^', reported unless sloppy-spc */ + (y *=z) + /*@ missing space after '*=' reported unless sloppy-spc */ + a %2 / /*@ missing space after '%', reported unless sloppy-spc */ + 1 +/* */ /*@ no space before comment, reported unless sloppy-spc */ + /* */+ /*@ no space after comment, reported unless sloppy-spc */ + s. e_member) /*@ space after '.', reported unless sloppy-spc */ + xx = a + b /*@ extra single-statement indent off by 1 */ + + 0; /*@ two times extra single-statement indent off by 3 */ + if (a ++) /*@ space before postfix '++', reported unless sloppy-spc */ + { /*@ {' not on same line as preceding 'if' */ + c; /*@0 single stmt in braces, reported on 1-stmt */ + } else /*@ missing '{' on same line after '} else' */ + { /*@ statement indent off by 2 */ + d; /*@0 single stmt in braces, reported on 1-stmt */ + } /*@ statement indent off by 6 */ + if (1) f(a, /*@ (non-brace) code after end of 'if' condition */ + b); else /*@ (non-brace) code before 'else' */ + do f(c, c); /*@ (non-brace) code after 'do' */ + while ( 2); /*@ space after '(', reported unless sloppy-spc */ + b; c; /*@ more than one statement per line */ + outer: /*@ outer label special indent off by 1 */ + do{ /*@ missing space before '{', reported unless sloppy-spc */ +inner: /*@ inner label normal indent off by 1 */ + f(3, /*@ space after fn before '(', reported unless sloppy-spc */ + 4); /*@0 false negative: should report single stmt in braces */ + } /*@0 'while' not on same line as preceding '}' */ + while (a+ 0); /*@2 missing space before '+', reported unless sloppy-spc */ + switch (b ) { /*@ space before ')', reported unless sloppy-spc */ +case 1: /*@ 'case' special statement indent off by -1 */ +case (2): /*@ missing space after 'case', reported unless sloppy-spc */ +default:; /*@ code after 'default:' */ +} /*@ statement indent off by -4 */ + return( /*@ missing space after 'return', reported unless sloppy-spc */ + x); } /*@ code before block-level '}' */ +/* Here the tool should stop complaining apart from the below issues at EOF */ + +void f_looong_body() + { + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + ; + + ; /*@ 2 essentially blank lines before, if !sloppy-spc */ + } /*@ function body length > 200 lines */ +#if X /*@0 unclosed #if */ + struct t { /*@0 unclosed brace at decl/block level */ + enum { /*@0 unclosed brace at enum/expression level */ + v = (1 /*@0 unclosed parenthesis */ + etyp /*@0 blank line follows just before EOF, if !sloppy-spc: */ diff --git a/util/check-news-changes.sh b/util/check-news-changes.sh deleted file mode 100755 index fec2a318b8..0000000000 --- a/util/check-news-changes.sh +++ /dev/null @@ -1,81 +0,0 @@ -#!/bin/bash - -# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). -# You may not use this file except in compliance with the License. -# You can obtain a copy in the file LICENSE in the source distribution -# or at https://www.openssl.org/source/license.html - -# -# This script scans a commit range for common things in prs that we normally -# expect to come with a CHANGE.md or NEWS.md entry. Its meant to be run prior -# to the release process to aid in the capturing on PR's that got merged without -# a corresponding CHANGES/NEWS entry. Arguments are two tree references to scan between -# looking for PR's that (a) didn't add a NEWS/CHANGES entry and (b) have attributes that -# make them look like they might require one -# - -BASE_REF=$(git rev-parse $1) -HEAD_REF=$(git rev-parse $2) - -TEMPDIR=$(mktemp -d /tmp/CHECKCHANGES.XXXXXX) - -trap "rm -rf $TEMPDIR" EXIT - -check_for_news_changes_update() { - local COMMITS_FILE=$TEMPDIR/$1/commits - - for commit in $(cat $COMMITS_FILE); do - git show --pretty="format:" --name-only $commit | grep -q "NEWS\.md" - if [ $? -eq 0 ]; then - echo "FOUND" - return - fi - git show --pretty="format:" --name-only $commit | grep -q "CHANGES\.md" - if [ $? -eq 0 ]; then - echo "FOUND" - return - fi - done - echo "SCAN" -} - -scan_pr_for_news_changes_needs() { - local COMMITS_FILE=$TEMPDIR/$1/commits - local pr=$2 - - for commit in $(cat $COMMITS_FILE); do - # Check for the CVE keyword in the commit - git show --no-patch --pretty=format:"%B" $commit | grep -q "CVE-" - if [ $? -eq 0 ]; then - echo "$pr references a CVE in commit $commit, probably needs a CHANGES.md entry" - return - fi - - # Check for public api and config script modifications - git show --pretty="format:" --name-only $commit | grep -q "include/openssl" - if [ $? -eq 0 ]; then - echo "$pr modifies headers in include/openssl in commit $commit, probably needs a CHANGES.md entry" - return - fi - git show --pretty="format:" --name-only $commit | grep -q "Configure" - if [ $? -eq 0 ]; then - echo "$pr modifies ./Configure in commit $commit, probably needs a CHANGES.md entry" - return - fi - - done -} - -git log $BASE_REF..$HEAD_REF | grep "Merged from" | sort | uniq | awk '{print $3}' | sed -e"s/)//" > $TEMPDIR/prs - -for pr in $(cat $TEMPDIR/prs); do - PRNUM=$(basename $pr) - mkdir $TEMPDIR/$PRNUM - git log --reverse --format=%H --grep="$pr" $BASE_REF..$HEAD_REF > $TEMPDIR/$PRNUM/commits - FOUND=$(check_for_news_changes_update $PRNUM) - if [ "$FOUND" == "SCAN" ]; then - scan_pr_for_news_changes_needs $PRNUM $pr - fi -done diff --git a/util/checkplatformsyms.pl b/util/checkplatformsyms.pl index 991c74bac9..742dd8ea84 100755 --- a/util/checkplatformsyms.pl +++ b/util/checkplatformsyms.pl @@ -14,13 +14,6 @@ my $expectedsyms=$ARGV[0]; shift(@ARGV); -# Check that object files exist -foreach (@ARGV) { - unless (-f $_ && -r $_) { - die "Path is not a regular readable file: '$_'"; - } -} - my $objlist; my $objfilelist = join(" ", @ARGV); my $expsyms; @@ -43,13 +36,13 @@ if ($Config{osname} eq "MSWin32") { { chomp; my $dllfile = $_; - $dllfile =~ s/( +)(.*)(\.dll)(.*)/DLLFILE $2/; + $dllfile =~ s/( +)(.*)(\.dll)(.*)/DLLFILE \2/; if (index($dllfile, "DLLFILE") >= 0) { $currentdll = substr($dllfile, 8); $currentdll =~ s/^\s+|s+$//g; } # filter imports from our own library - if ("$currentdll" !~ /^libcrypto-[1-9][0-9]*(-x64)?$/) { + if ("$currentdll" ne "libcrypto-3-x64") { my $line = $_; $line =~ s/ [0-9a-fA-F]{1,2} /SYMBOL /; if (index($line, "SYMBOL") != -1) { @@ -58,28 +51,18 @@ if ($Config{osname} eq "MSWin32") { } } } - - close($OBJFH); - ($? >> 8 == 0) or die "Command '$cmd' has failed."; - - my $ok = 1; foreach (@symlist) { - chomp; if (index($exps, $_) < 0) { print "Symbol $_ not in the allowed platform symbols list\n"; - $ok = 0; + exit 1; } } - exit !$ok; + exit 0; } else { - $cmd = "objdump -t " . $objfilelist . " | awk " . - "'/\\\\*UND\\\\*/ {" . - "split(\$NF, sym_lib, \"@\");" . - "if (sym_lib[2] !~ \"OPENSSL_[1-9][0-9]*\\\\.[0-9]+\\\\.[0-9]+\$\")" . - "syms[sym_lib[1]] = 1;" . - "}" . - "END { for (s in syms) print s; };'"; + $cmd = "objdump -t " . $objfilelist . " | grep UND | grep -v \@OPENSSL"; + $cmd = $cmd . " | awk '{print \$NF}' |"; + $cmd = $cmd . " sed -e\"s/@.*\$//\" | sort | uniq"; open $expsyms, '<', $expectedsyms or die; { @@ -89,16 +72,13 @@ else { close($expsyms); open($OBJFH, "$cmd|") or die "Cannot open process: $!"; - my $ok = 1; while (<$OBJFH>) { - chomp; if (index($exps, $_) < 0) { print "Symbol $_ not in the allowed platform symbols list\n"; - $ok = 0; + exit 1; } } close($OBJFH); - - exit !(!($? >> 8) || !$ok); + exit 0; } diff --git a/util/find-doc-nits b/util/find-doc-nits index 2ec0939faa..fb3288c2d1 100755 --- a/util/find-doc-nits +++ b/util/find-doc-nits @@ -33,6 +33,7 @@ my $debug = 0; our($opt_d); our($opt_e); our($opt_s); +our($opt_o); our($opt_h); our($opt_l); our($opt_m); @@ -56,6 +57,7 @@ Find small errors (nits) in documentation. Options: -l Print bogus links -m Name(s) of manuals to focus on. Default: man1,man3,man5,man7 -n Print nits in POD pages + -o Causes -e/-v to count symbols added since 1.1.1 as new (implies -v) -i Checks for history entries available for symbols added since 4.0.0 as new -u Count undocumented functions -v Count new undocumented functions @@ -63,11 +65,11 @@ EOF exit; } -getopts('acdehlm:niuv'); +getopts('acdehlm:noiuv'); help() if $opt_h; $opt_u = 1 if $opt_d; -$opt_v = 1 if $opt_e; +$opt_v = 1 if $opt_o || $opt_e; die "Cannot use both -u and -v" if $opt_u && $opt_v; die "Cannot use both -d and -e" @@ -1472,7 +1474,11 @@ loadnum('util/libcrypto.num', 'crypto'); loadnum('util/libssl.num', 'ssl'); loadnum('util/other.syms', 'other'); loadnum('util/other-internal.syms'); -if ( !$opt_u ) { +if ( $opt_o ) { + loadmissing('util/missingmacro111.txt', 'crypto'); + loadmissing('util/missingcrypto111.txt', 'crypto'); + loadmissing('util/missingssl111.txt', 'ssl'); +} elsif ( !$opt_u ) { loadmissing('util/missingmacro.txt', 'crypto'); loadmissing('util/missingcrypto.txt', 'crypto'); loadmissing('util/missingssl.txt', 'ssl'); diff --git a/util/fix-includes.sed b/util/fix-includes.sed index 60b64ed69c..16c723bf73 100644 --- a/util/fix-includes.sed +++ b/util/fix-includes.sed @@ -1,5 +1,5 @@ s|internal/([a-z0-9_]+)_int\.h|crypto/\1.h|g ; -s@internal/(aria.h|asn1_dsa.h|async.h|bn_dh.h|bn_srp.h|chacha.h|(aes|des|cmll)_platform.h|ctype.h|__DECC_INCLUDE_EPILOGUE.H|__DECC_INCLUDE_PROLOGUE.H|dso_conf.h|dso_conf.h|lhash.h|objects.h|poly1305.h|sha.h|siphash.h|sm2err.h|sm2.h|sm4.h|sparse_array.h|store.h|foobar)@crypto/\1@g ; +s@internal/(aria.h|asn1_dsa.h|async.h|bn_dh.h|bn_srp.h|chacha.h|(aes|des|cmll)_platform.h|ctype.h|__DECC_INCLUDE_EPILOGUE.H|__DECC_INCLUDE_PROLOGUE.H|dso_conf.h|dso_conf.h|lhash.h|md32_common.h|objects.h|poly1305.h|sha.h|siphash.h|sm2err.h|sm2.h|sm4.h|sparse_array.h|store.h|foobar)@crypto/\1@g ; s/constant_time_locl/constant_time/g ; s/_lo?cl\.h/_local.h/g ; s/_int\.h/_local.h/g ; diff --git a/util/indent.pro b/util/indent.pro index 52f7a60e37..6fabf305da 100644 --- a/util/indent.pro +++ b/util/indent.pro @@ -619,5 +619,7 @@ -T ossl_uintmax_t -T ossl_uintmax_t -T CT_POLICY_EVAL_CTX +-T RAND_DRBG +-T RAND_DRBG_CTR -T RAND_POOL -T RAND_METHOD diff --git a/util/libcrypto.num b/util/libcrypto.num index c7b7777cc4..5eb70de5bb 100644 --- a/util/libcrypto.num +++ b/util/libcrypto.num @@ -1,5729 +1,5818 @@ -asn1_d2i_read_bio 1 4_0_0 EXIST::FUNCTION: -DSO_new 2 4_0_0 EXIST::FUNCTION: -DSO_free 3 4_0_0 EXIST::FUNCTION: -DSO_flags 4 4_0_0 EXIST::FUNCTION: -DSO_up_ref 5 4_0_0 EXIST::FUNCTION: -DSO_ctrl 6 4_0_0 EXIST::FUNCTION: -DSO_get_filename 7 4_0_0 EXIST::FUNCTION: -DSO_set_filename 8 4_0_0 EXIST::FUNCTION: -DSO_convert_filename 9 4_0_0 EXIST::FUNCTION: -DSO_merge 10 4_0_0 EXIST::FUNCTION: -DSO_load 11 4_0_0 EXIST::FUNCTION: -DSO_bind_func 12 4_0_0 EXIST::FUNCTION: -DSO_METHOD_openssl 13 4_0_0 EXIST::FUNCTION: -DSO_pathbyaddr 14 4_0_0 EXIST::FUNCTION: -DSO_dsobyaddr 15 4_0_0 EXIST::FUNCTION: -DSO_global_lookup 16 4_0_0 EXIST::FUNCTION: -err_free_strings_int 17 4_0_0 EXIST::FUNCTION: -OPENSSL_DIR_read 18 4_0_0 EXIST::FUNCTION: -OPENSSL_DIR_end 19 4_0_0 EXIST::FUNCTION: -conf_ssl_get 20 4_0_0 EXIST::FUNCTION: -conf_ssl_name_find 21 4_0_0 EXIST::FUNCTION: -conf_ssl_get_cmd 22 4_0_0 EXIST::FUNCTION: -AES_options 23 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -AES_set_encrypt_key 24 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -AES_set_decrypt_key 25 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -AES_encrypt 26 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -AES_decrypt 27 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -AES_ecb_encrypt 28 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -AES_cbc_encrypt 29 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -AES_cfb128_encrypt 30 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -AES_cfb1_encrypt 31 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -AES_cfb8_encrypt 32 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -AES_ofb128_encrypt 33 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -AES_ige_encrypt 34 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -AES_bi_ige_encrypt 35 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -AES_wrap_key 36 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -AES_unwrap_key 37 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ASYNC_init_thread 38 4_0_0 EXIST::FUNCTION: -ASYNC_cleanup_thread 39 4_0_0 EXIST::FUNCTION: -ASYNC_WAIT_CTX_new 40 4_0_0 EXIST::FUNCTION: -ASYNC_WAIT_CTX_free 41 4_0_0 EXIST::FUNCTION: -ASYNC_WAIT_CTX_set_wait_fd 42 4_0_0 EXIST::FUNCTION: -ASYNC_WAIT_CTX_get_fd 43 4_0_0 EXIST::FUNCTION: -ASYNC_WAIT_CTX_get_all_fds 44 4_0_0 EXIST::FUNCTION: -ASYNC_WAIT_CTX_get_callback 45 4_0_0 EXIST::FUNCTION: -ASYNC_WAIT_CTX_set_callback 46 4_0_0 EXIST::FUNCTION: -ASYNC_WAIT_CTX_set_status 47 4_0_0 EXIST::FUNCTION: -ASYNC_WAIT_CTX_get_status 48 4_0_0 EXIST::FUNCTION: -ASYNC_WAIT_CTX_get_changed_fds 49 4_0_0 EXIST::FUNCTION: -ASYNC_WAIT_CTX_clear_fd 50 4_0_0 EXIST::FUNCTION: -ASYNC_is_capable 51 4_0_0 EXIST::FUNCTION: -ASYNC_set_mem_functions 52 4_0_0 EXIST::FUNCTION: -ASYNC_get_mem_functions 53 4_0_0 EXIST::FUNCTION: -ASYNC_start_job 54 4_0_0 EXIST::FUNCTION: -ASYNC_pause_job 55 4_0_0 EXIST::FUNCTION: -ASYNC_get_current_job 56 4_0_0 EXIST::FUNCTION: -ASYNC_get_wait_ctx 57 4_0_0 EXIST::FUNCTION: -ASYNC_block_pause 58 4_0_0 EXIST::FUNCTION: -ASYNC_unblock_pause 59 4_0_0 EXIST::FUNCTION: -BF_set_key 60 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 -BF_encrypt 61 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 -BF_decrypt 62 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 -BF_ecb_encrypt 63 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 -BF_cbc_encrypt 64 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 -BF_cfb64_encrypt 65 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 -BF_ofb64_encrypt 66 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 -BF_options 67 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 -BN_set_flags 68 4_0_0 EXIST::FUNCTION: -BN_get_flags 69 4_0_0 EXIST::FUNCTION: -BN_with_flags 70 4_0_0 EXIST::FUNCTION: -BN_GENCB_call 71 4_0_0 EXIST::FUNCTION: -BN_GENCB_new 72 4_0_0 EXIST::FUNCTION: -BN_GENCB_free 73 4_0_0 EXIST::FUNCTION: -BN_GENCB_set_old 74 4_0_0 EXIST::FUNCTION: -BN_GENCB_set 75 4_0_0 EXIST::FUNCTION: -BN_GENCB_get_arg 76 4_0_0 EXIST::FUNCTION: -BN_abs_is_word 77 4_0_0 EXIST::FUNCTION: -BN_is_zero 78 4_0_0 EXIST::FUNCTION: -BN_is_one 79 4_0_0 EXIST::FUNCTION: -BN_is_word 80 4_0_0 EXIST::FUNCTION: -BN_is_odd 81 4_0_0 EXIST::FUNCTION: -BN_zero_ex 82 4_0_0 EXIST::FUNCTION: -BN_value_one 83 4_0_0 EXIST::FUNCTION: -BN_options 84 4_0_0 EXIST::FUNCTION: -BN_CTX_new_ex 85 4_0_0 EXIST::FUNCTION: -BN_CTX_new 86 4_0_0 EXIST::FUNCTION: -BN_CTX_secure_new_ex 87 4_0_0 EXIST::FUNCTION: -BN_CTX_secure_new 88 4_0_0 EXIST::FUNCTION: -BN_CTX_free 89 4_0_0 EXIST::FUNCTION: -BN_CTX_start 90 4_0_0 EXIST::FUNCTION: -BN_CTX_get 91 4_0_0 EXIST::FUNCTION: -BN_CTX_end 92 4_0_0 EXIST::FUNCTION: -BN_rand_ex 93 4_0_0 EXIST::FUNCTION: -BN_rand 94 4_0_0 EXIST::FUNCTION: -BN_priv_rand_ex 95 4_0_0 EXIST::FUNCTION: -BN_priv_rand 96 4_0_0 EXIST::FUNCTION: -BN_rand_range_ex 97 4_0_0 EXIST::FUNCTION: -BN_rand_range 98 4_0_0 EXIST::FUNCTION: -BN_priv_rand_range_ex 99 4_0_0 EXIST::FUNCTION: -BN_priv_rand_range 100 4_0_0 EXIST::FUNCTION: -BN_pseudo_rand 101 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -BN_pseudo_rand_range 102 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -BN_num_bits 103 4_0_0 EXIST::FUNCTION: -BN_num_bits_word 104 4_0_0 EXIST::FUNCTION: -BN_security_bits 105 4_0_0 EXIST::FUNCTION: -BN_new 106 4_0_0 EXIST::FUNCTION: -BN_secure_new 107 4_0_0 EXIST::FUNCTION: -BN_clear_free 108 4_0_0 EXIST::FUNCTION: -BN_copy 109 4_0_0 EXIST::FUNCTION: -BN_swap 110 4_0_0 EXIST::FUNCTION: -BN_bin2bn 111 4_0_0 EXIST::FUNCTION: -BN_signed_bin2bn 112 4_0_0 EXIST::FUNCTION: -BN_bn2bin 113 4_0_0 EXIST::FUNCTION: -BN_bn2binpad 114 4_0_0 EXIST::FUNCTION: -BN_signed_bn2bin 115 4_0_0 EXIST::FUNCTION: -BN_lebin2bn 116 4_0_0 EXIST::FUNCTION: -BN_signed_lebin2bn 117 4_0_0 EXIST::FUNCTION: -BN_bn2lebinpad 118 4_0_0 EXIST::FUNCTION: -BN_signed_bn2lebin 119 4_0_0 EXIST::FUNCTION: -BN_native2bn 120 4_0_0 EXIST::FUNCTION: -BN_signed_native2bn 121 4_0_0 EXIST::FUNCTION: -BN_bn2nativepad 122 4_0_0 EXIST::FUNCTION: -BN_signed_bn2native 123 4_0_0 EXIST::FUNCTION: -BN_mpi2bn 124 4_0_0 EXIST::FUNCTION: -BN_bn2mpi 125 4_0_0 EXIST::FUNCTION: -BN_sub 126 4_0_0 EXIST::FUNCTION: -BN_usub 127 4_0_0 EXIST::FUNCTION: -BN_uadd 128 4_0_0 EXIST::FUNCTION: -BN_add 129 4_0_0 EXIST::FUNCTION: -BN_mul 130 4_0_0 EXIST::FUNCTION: -BN_sqr 131 4_0_0 EXIST::FUNCTION: -BN_set_negative 132 4_0_0 EXIST::FUNCTION: -BN_is_negative 133 4_0_0 EXIST::FUNCTION: -BN_div 134 4_0_0 EXIST::FUNCTION: -BN_nnmod 135 4_0_0 EXIST::FUNCTION: -BN_mod_add 136 4_0_0 EXIST::FUNCTION: -BN_mod_add_quick 137 4_0_0 EXIST::FUNCTION: -BN_mod_sub 138 4_0_0 EXIST::FUNCTION: -BN_mod_sub_quick 139 4_0_0 EXIST::FUNCTION: -BN_mod_mul 140 4_0_0 EXIST::FUNCTION: -BN_mod_sqr 141 4_0_0 EXIST::FUNCTION: -BN_mod_lshift1 142 4_0_0 EXIST::FUNCTION: -BN_mod_lshift1_quick 143 4_0_0 EXIST::FUNCTION: -BN_mod_lshift 144 4_0_0 EXIST::FUNCTION: -BN_mod_lshift_quick 145 4_0_0 EXIST::FUNCTION: -BN_mod_word 146 4_0_0 EXIST::FUNCTION: -BN_div_word 147 4_0_0 EXIST::FUNCTION: -BN_mul_word 148 4_0_0 EXIST::FUNCTION: -BN_add_word 149 4_0_0 EXIST::FUNCTION: -BN_sub_word 150 4_0_0 EXIST::FUNCTION: -BN_set_word 151 4_0_0 EXIST::FUNCTION: -BN_get_word 152 4_0_0 EXIST::FUNCTION: -BN_cmp 153 4_0_0 EXIST::FUNCTION: -BN_free 154 4_0_0 EXIST::FUNCTION: -BN_is_bit_set 155 4_0_0 EXIST::FUNCTION: -BN_lshift 156 4_0_0 EXIST::FUNCTION: -BN_lshift1 157 4_0_0 EXIST::FUNCTION: -BN_exp 158 4_0_0 EXIST::FUNCTION: -BN_mod_exp 159 4_0_0 EXIST::FUNCTION: -BN_mod_exp_mont 160 4_0_0 EXIST::FUNCTION: -BN_mod_exp_mont_consttime 161 4_0_0 EXIST::FUNCTION: -BN_mod_exp_mont_word 162 4_0_0 EXIST::FUNCTION: -BN_mod_exp2_mont 163 4_0_0 EXIST::FUNCTION: -BN_mod_exp_simple 164 4_0_0 EXIST::FUNCTION: -BN_mod_exp_mont_consttime_x2 165 4_0_0 EXIST::FUNCTION: -BN_mask_bits 166 4_0_0 EXIST::FUNCTION: -BN_print_fp 167 4_0_0 EXIST::FUNCTION:STDIO -BN_print 168 4_0_0 EXIST::FUNCTION: -BN_reciprocal 169 4_0_0 EXIST::FUNCTION: -BN_rshift 170 4_0_0 EXIST::FUNCTION: -BN_rshift1 171 4_0_0 EXIST::FUNCTION: -BN_clear 172 4_0_0 EXIST::FUNCTION: -BN_dup 173 4_0_0 EXIST::FUNCTION: -BN_ucmp 174 4_0_0 EXIST::FUNCTION: -BN_set_bit 175 4_0_0 EXIST::FUNCTION: -BN_clear_bit 176 4_0_0 EXIST::FUNCTION: -BN_bn2hex 177 4_0_0 EXIST::FUNCTION: -BN_bn2dec 178 4_0_0 EXIST::FUNCTION: -BN_hex2bn 179 4_0_0 EXIST::FUNCTION: -BN_dec2bn 180 4_0_0 EXIST::FUNCTION: -BN_asc2bn 181 4_0_0 EXIST::FUNCTION: -BN_gcd 182 4_0_0 EXIST::FUNCTION: -BN_kronecker 183 4_0_0 EXIST::FUNCTION: -BN_are_coprime 184 4_0_0 EXIST::FUNCTION: -BN_mod_inverse 185 4_0_0 EXIST::FUNCTION: -BN_mod_sqrt 186 4_0_0 EXIST::FUNCTION: -BN_consttime_swap 187 4_0_0 EXIST::FUNCTION: -BN_generate_prime 188 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8 -BN_is_prime 189 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8 -BN_is_prime_fasttest 190 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8 -BN_is_prime_ex 191 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -BN_is_prime_fasttest_ex 192 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -BN_generate_prime_ex2 193 4_0_0 EXIST::FUNCTION: -BN_generate_prime_ex 194 4_0_0 EXIST::FUNCTION: -BN_check_prime 195 4_0_0 EXIST::FUNCTION: -BN_X931_generate_Xpq 196 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -BN_X931_derive_prime_ex 197 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -BN_X931_generate_prime_ex 198 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -BN_MONT_CTX_new 199 4_0_0 EXIST::FUNCTION: -BN_mod_mul_montgomery 200 4_0_0 EXIST::FUNCTION: -BN_to_montgomery 201 4_0_0 EXIST::FUNCTION: -BN_from_montgomery 202 4_0_0 EXIST::FUNCTION: -BN_MONT_CTX_free 203 4_0_0 EXIST::FUNCTION: -BN_MONT_CTX_set 204 4_0_0 EXIST::FUNCTION: -BN_MONT_CTX_copy 205 4_0_0 EXIST::FUNCTION: -BN_MONT_CTX_set_locked 206 4_0_0 EXIST::FUNCTION: -BN_BLINDING_new 207 4_0_0 EXIST::FUNCTION: -BN_BLINDING_free 208 4_0_0 EXIST::FUNCTION: -BN_BLINDING_update 209 4_0_0 EXIST::FUNCTION: -BN_BLINDING_convert 210 4_0_0 EXIST::FUNCTION: -BN_BLINDING_invert 211 4_0_0 EXIST::FUNCTION: -BN_BLINDING_convert_ex 212 4_0_0 EXIST::FUNCTION: -BN_BLINDING_invert_ex 213 4_0_0 EXIST::FUNCTION: -BN_BLINDING_is_current_thread 214 4_0_0 EXIST::FUNCTION: -BN_BLINDING_set_current_thread 215 4_0_0 EXIST::FUNCTION: -BN_BLINDING_lock 216 4_0_0 EXIST::FUNCTION: -BN_BLINDING_unlock 217 4_0_0 EXIST::FUNCTION: -BN_BLINDING_get_flags 218 4_0_0 EXIST::FUNCTION: -BN_BLINDING_set_flags 219 4_0_0 EXIST::FUNCTION: -BN_BLINDING_create_param 220 4_0_0 EXIST::FUNCTION: -BN_set_params 221 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8 -BN_get_params 222 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8 -BN_RECP_CTX_new 223 4_0_0 EXIST::FUNCTION: -BN_RECP_CTX_free 224 4_0_0 EXIST::FUNCTION: -BN_RECP_CTX_set 225 4_0_0 EXIST::FUNCTION: -BN_mod_mul_reciprocal 226 4_0_0 EXIST::FUNCTION: -BN_mod_exp_recp 227 4_0_0 EXIST::FUNCTION: -BN_div_recp 228 4_0_0 EXIST::FUNCTION: -BN_GF2m_add 229 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod 230 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod_mul 231 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod_sqr 232 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod_inv 233 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod_div 234 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod_exp 235 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod_sqrt 236 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod_solve_quad 237 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod_arr 238 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod_mul_arr 239 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod_sqr_arr 240 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod_inv_arr 241 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod_div_arr 242 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod_exp_arr 243 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod_sqrt_arr 244 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_mod_solve_quad_arr 245 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_poly2arr 246 4_0_0 EXIST::FUNCTION:EC2M -BN_GF2m_arr2poly 247 4_0_0 EXIST::FUNCTION:EC2M -BN_nist_mod_192 248 4_0_0 EXIST::FUNCTION: -BN_nist_mod_224 249 4_0_0 EXIST::FUNCTION: -BN_nist_mod_256 250 4_0_0 EXIST::FUNCTION: -BN_nist_mod_384 251 4_0_0 EXIST::FUNCTION: -BN_nist_mod_521 252 4_0_0 EXIST::FUNCTION: -BN_get0_nist_prime_192 253 4_0_0 EXIST::FUNCTION: -BN_get0_nist_prime_224 254 4_0_0 EXIST::FUNCTION: -BN_get0_nist_prime_256 255 4_0_0 EXIST::FUNCTION: -BN_get0_nist_prime_384 256 4_0_0 EXIST::FUNCTION: -BN_get0_nist_prime_521 257 4_0_0 EXIST::FUNCTION: -BN_nist_mod_func 258 4_0_0 EXIST::FUNCTION: -BN_generate_dsa_nonce 259 4_0_0 EXIST::FUNCTION: -BN_get_rfc2409_prime_768 260 4_0_0 EXIST::FUNCTION: -BN_get_rfc2409_prime_1024 261 4_0_0 EXIST::FUNCTION: -BN_get_rfc3526_prime_1536 262 4_0_0 EXIST::FUNCTION: -BN_get_rfc3526_prime_2048 263 4_0_0 EXIST::FUNCTION: -BN_get_rfc3526_prime_3072 264 4_0_0 EXIST::FUNCTION: -BN_get_rfc3526_prime_4096 265 4_0_0 EXIST::FUNCTION: -BN_get_rfc3526_prime_6144 266 4_0_0 EXIST::FUNCTION: -BN_get_rfc3526_prime_8192 267 4_0_0 EXIST::FUNCTION: -BN_bntest_rand 268 4_0_0 EXIST::FUNCTION: -BUF_MEM_new 269 4_0_0 EXIST::FUNCTION: -BUF_MEM_new_ex 270 4_0_0 EXIST::FUNCTION: -BUF_MEM_free 271 4_0_0 EXIST::FUNCTION: -BUF_MEM_grow 272 4_0_0 EXIST::FUNCTION: -BUF_MEM_grow_clean 273 4_0_0 EXIST::FUNCTION: -BUF_reverse 274 4_0_0 EXIST::FUNCTION: -Camellia_set_key 275 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 -Camellia_encrypt 276 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 -Camellia_decrypt 277 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 -Camellia_ecb_encrypt 278 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 -Camellia_cbc_encrypt 279 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 -Camellia_cfb128_encrypt 280 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 -Camellia_cfb1_encrypt 281 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 -Camellia_cfb8_encrypt 282 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 -Camellia_ofb128_encrypt 283 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 -Camellia_ctr128_encrypt 284 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 -CAST_set_key 285 4_0_0 EXIST::FUNCTION:CAST,DEPRECATEDIN_3_0 -CAST_ecb_encrypt 286 4_0_0 EXIST::FUNCTION:CAST,DEPRECATEDIN_3_0 -CAST_encrypt 287 4_0_0 EXIST::FUNCTION:CAST,DEPRECATEDIN_3_0 -CAST_decrypt 288 4_0_0 EXIST::FUNCTION:CAST,DEPRECATEDIN_3_0 -CAST_cbc_encrypt 289 4_0_0 EXIST::FUNCTION:CAST,DEPRECATEDIN_3_0 -CAST_cfb64_encrypt 290 4_0_0 EXIST::FUNCTION:CAST,DEPRECATEDIN_3_0 -CAST_ofb64_encrypt 291 4_0_0 EXIST::FUNCTION:CAST,DEPRECATEDIN_3_0 -CMAC_CTX_new 292 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 -CMAC_CTX_cleanup 293 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 -CMAC_CTX_free 294 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 -CMAC_CTX_get0_cipher_ctx 295 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 -CMAC_CTX_copy 296 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 -CMAC_Init 297 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 -CMAC_Update 298 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 -CMAC_Final 299 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 -CMAC_resume 300 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 -OSSL_CMP_log_open 301 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_log_close 302 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_print_to_bio 303 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_print_errors_cb 304 4_0_0 EXIST::FUNCTION:CMP -ERR_load_ASN1_strings 305 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_ASYNC_strings 306 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_BIO_strings 307 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_BN_strings 308 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_BUF_strings 309 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_CMS_strings 310 4_0_0 EXIST::FUNCTION:CMS,DEPRECATEDIN_3_0 -ERR_load_COMP_strings 311 4_0_0 EXIST::FUNCTION:COMP,DEPRECATEDIN_3_0 -ERR_load_CONF_strings 312 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_CRYPTO_strings 313 4_0_0 EXIST:!VMS:FUNCTION:DEPRECATEDIN_3_0 -ERR_load_CRYPTOlib_strings 313 4_0_0 EXIST:VMS:FUNCTION:DEPRECATEDIN_3_0 -ERR_load_CT_strings 314 4_0_0 EXIST::FUNCTION:CT,DEPRECATEDIN_3_0 -ERR_load_DH_strings 315 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -ERR_load_DSA_strings 316 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -ERR_load_EC_strings 317 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -ERR_load_ERR_strings 318 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_EVP_strings 319 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_KDF_strings 320 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_OBJ_strings 321 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_OCSP_strings 322 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,OCSP -ERR_load_PEM_strings 323 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_PKCS12_strings 324 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_PKCS7_strings 325 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_RAND_strings 326 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_RSA_strings 327 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_OSSL_STORE_strings 328 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_TS_strings 329 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,TS -ERR_load_UI_strings 330 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_X509_strings 331 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_load_X509V3_strings 332 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_DECODER_fetch 333 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_up_ref 334 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_free 335 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_get0_provider 336 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_get0_properties 337 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_get0_name 338 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_get0_description 339 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_is_a 340 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_do_all_provided 341 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_names_do_all 342 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_gettable_params 343 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_get_params 344 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_settable_ctx_params 345 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_new 346 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_set_params 347 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_free 348 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_set_passphrase 349 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_set_pem_password_cb 350 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_set_passphrase_cb 351 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_set_passphrase_ui 352 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_set_selection 353 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_set_input_type 354 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_set_input_structure 355 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_add_decoder 356 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_add_extra 357 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_get_num_decoders 358 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_INSTANCE_get_decoder 359 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_INSTANCE_get_decoder_ctx 360 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_INSTANCE_get_input_type 361 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_INSTANCE_get_input_structure 362 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_set_construct 363 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_set_construct_data 364 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_set_cleanup 365 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_get_construct 366 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_get_construct_data 367 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_get_cleanup 368 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_export 369 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_from_bio 370 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_from_fp 371 4_0_0 EXIST::FUNCTION:STDIO -OSSL_DECODER_from_data 372 4_0_0 EXIST::FUNCTION: -OSSL_DECODER_CTX_new_for_pkey 373 4_0_0 EXIST::FUNCTION: -DES_options 374 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_ecb3_encrypt 375 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_cbc_cksum 376 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_cbc_encrypt 377 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_ncbc_encrypt 378 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_xcbc_encrypt 379 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_cfb_encrypt 380 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_ecb_encrypt 381 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_encrypt1 382 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_encrypt2 383 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_encrypt3 384 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_decrypt3 385 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_ede3_cbc_encrypt 386 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_ede3_cfb64_encrypt 387 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_ede3_cfb_encrypt 388 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_ede3_ofb64_encrypt 389 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_fcrypt 390 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_crypt 391 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_ofb_encrypt 392 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_pcbc_encrypt 393 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_quad_cksum 394 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_random_key 395 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_set_odd_parity 396 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_check_key_parity 397 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_is_weak_key 398 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_set_key 399 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_key_sched 400 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_set_key_checked 401 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_set_key_unchecked 402 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_string_to_key 403 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_string_to_2keys 404 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_cfb64_encrypt 405 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -DES_ofb64_encrypt 406 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES -EVP_PKEY_CTX_set_dh_paramgen_type 407 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dh_paramgen_gindex 408 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dh_paramgen_seed 409 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dh_paramgen_prime_len 410 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dh_paramgen_subprime_len 411 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dh_paramgen_generator 412 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dh_nid 413 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dh_rfc5114 414 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dhx_rfc5114 415 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dh_pad 416 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dh_kdf_type 417 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_dh_kdf_type 418 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set0_dh_kdf_oid 419 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get0_dh_kdf_oid 420 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dh_kdf_md 421 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_dh_kdf_md 422 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dh_kdf_outlen 423 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_dh_kdf_outlen 424 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set0_dh_kdf_ukm 425 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get0_dh_kdf_ukm 426 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -DHparams_it 427 4_0_0 EXIST::FUNCTION:DH -DHparams_dup 428 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_OpenSSL 429 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_set_default_method 430 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_get_default_method 431 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_set_method 432 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_new_method 433 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_new 434 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_free 435 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_up_ref 436 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_bits 437 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_size 438 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_security_bits 439 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_set_ex_data 440 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_get_ex_data 441 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_generate_parameters_ex 442 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_check_params_ex 443 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_check_ex 444 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_check_pub_key_ex 445 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_check_params 446 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_check 447 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_check_pub_key 448 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_generate_key 449 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_compute_key 450 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_compute_key_padded 451 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -d2i_DHparams 452 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -i2d_DHparams 453 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -d2i_DHxparams 454 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -i2d_DHxparams 455 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DHparams_print_fp 456 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH,STDIO -DHparams_print 457 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_get_1024_160 458 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_get_2048_224 459 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_get_2048_256 460 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_new_by_nid 461 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_get_nid 462 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_KDF_X9_42 463 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_get0_pqg 464 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_set0_pqg 465 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_get0_key 466 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_set0_key 467 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_get0_p 468 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_get0_q 469 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_get0_g 470 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_get0_priv_key 471 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_get0_pub_key 472 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_clear_flags 473 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_test_flags 474 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_set_flags 475 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_get_length 476 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_set_length 477 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_new 478 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_free 479 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_dup 480 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_get0_name 481 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_set1_name 482 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_get_flags 483 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_set_flags 484 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_get0_app_data 485 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_set0_app_data 486 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_get_generate_key 487 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_set_generate_key 488 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_get_compute_key 489 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_set_compute_key 490 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_get_bn_mod_exp 491 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_set_bn_mod_exp 492 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_get_init 493 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_set_init 494 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_get_finish 495 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_set_finish 496 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_get_generate_params 497 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_meth_set_generate_params 498 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -DH_generate_parameters 499 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8,DH -EVP_PKEY_CTX_set_dsa_paramgen_bits 500 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dsa_paramgen_q_bits 501 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dsa_paramgen_md_props 502 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dsa_paramgen_gindex 503 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dsa_paramgen_type 504 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dsa_paramgen_seed 505 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_dsa_paramgen_md 506 4_0_0 EXIST::FUNCTION: -DSA_SIG_new 507 4_0_0 EXIST::FUNCTION:DSA -DSA_SIG_free 508 4_0_0 EXIST::FUNCTION:DSA -d2i_DSA_SIG 509 4_0_0 EXIST::FUNCTION:DSA -i2d_DSA_SIG 510 4_0_0 EXIST::FUNCTION:DSA -DSA_SIG_get0 511 4_0_0 EXIST::FUNCTION:DSA -DSA_SIG_set0 512 4_0_0 EXIST::FUNCTION:DSA -DSAparams_dup 513 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_do_sign 514 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_do_verify 515 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_OpenSSL 516 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_set_default_method 517 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_get_default_method 518 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_set_method 519 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_get_method 520 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_new 521 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_new_method 522 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_free 523 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_up_ref 524 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_size 525 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_bits 526 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_security_bits 527 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_sign_setup 528 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_sign 529 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_verify 530 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_set_ex_data 531 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_get_ex_data 532 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -d2i_DSAPublicKey 533 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -i2d_DSAPublicKey 534 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -d2i_DSAPrivateKey 535 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -i2d_DSAPrivateKey 536 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -d2i_DSAparams 537 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -i2d_DSAparams 538 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_generate_parameters 539 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8,DSA -DSA_generate_parameters_ex 540 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_generate_key 541 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSAparams_print 542 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_print 543 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSAparams_print_fp 544 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO -DSA_print_fp 545 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO -DSA_dup_DH 546 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH,DSA -DSA_get0_pqg 547 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_set0_pqg 548 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_get0_key 549 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_set0_key 550 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_get0_p 551 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_get0_q 552 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_get0_g 553 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_get0_pub_key 554 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_get0_priv_key 555 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_clear_flags 556 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_test_flags 557 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_set_flags 558 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_new 559 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_free 560 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_dup 561 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_get0_name 562 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_set1_name 563 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_get_flags 564 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_set_flags 565 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_get0_app_data 566 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_set0_app_data 567 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_get_sign 568 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_set_sign 569 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_get_sign_setup 570 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_set_sign_setup 571 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_get_verify 572 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_set_verify 573 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_get_mod_exp 574 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_set_mod_exp 575 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_get_bn_mod_exp 576 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_set_bn_mod_exp 577 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_get_init 578 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_set_init 579 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_get_finish 580 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_set_finish 581 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_get_paramgen 582 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_set_paramgen 583 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_get_keygen 584 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -DSA_meth_set_keygen 585 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -EVP_PKEY_CTX_set_ec_paramgen_curve_nid 586 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_ec_param_enc 587 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_ecdh_cofactor_mode 588 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_ecdh_cofactor_mode 589 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_ecdh_kdf_type 590 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_ecdh_kdf_type 591 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_ecdh_kdf_md 592 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_ecdh_kdf_md 593 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_ecdh_kdf_outlen 594 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_ecdh_kdf_outlen 595 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set0_ecdh_kdf_ukm 596 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get0_ecdh_kdf_ukm 597 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_EC_curve_nid2name 598 4_0_0 EXIST::FUNCTION: -EC_GFp_simple_method 599 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_GFp_mont_method 600 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_GFp_nist_method 601 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_GFp_nistp224_method 602 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC_NISTP_64_GCC_128 -EC_GFp_nistp256_method 603 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC_NISTP_64_GCC_128 -EC_GFp_nistp521_method 604 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC_NISTP_64_GCC_128 -EC_GF2m_simple_method 605 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC2M -EC_GROUP_new 606 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_GROUP_clear_free 607 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_GROUP_method_of 608 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_METHOD_get_field_type 609 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_GROUP_free 610 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_copy 611 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_dup 612 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_set_generator 613 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get0_generator 614 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get_mont_data 615 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get_order 616 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get0_order 617 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_order_bits 618 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_security_bits 619 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get_cofactor 620 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get0_cofactor 621 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_set_curve_name 622 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get_curve_name 623 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get0_field 624 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get_field_type 625 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_set_asn1_flag 626 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get_asn1_flag 627 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_set_point_conversion_form 628 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get_point_conversion_form 629 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get0_seed 630 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get_seed_len 631 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_set_seed 632 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_set_curve 633 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get_curve 634 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_set_curve_GFp 635 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_GROUP_get_curve_GFp 636 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_GROUP_set_curve_GF2m 637 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC2M -EC_GROUP_get_curve_GF2m 638 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC2M -EC_GROUP_get_degree 639 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_check 640 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_check_discriminant 641 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_cmp 642 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_new_curve_GFp 643 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_new_curve_GF2m 644 4_0_0 EXIST::FUNCTION:EC,EC2M -EC_GROUP_new_from_params 645 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_to_params 646 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_new_by_curve_name_ex 647 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_new_by_curve_name 648 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_new_from_ecparameters 649 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get_ecparameters 650 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_new_from_ecpkparameters 651 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get_ecpkparameters 652 4_0_0 EXIST::FUNCTION:EC -EC_get_builtin_curves 653 4_0_0 EXIST::FUNCTION:EC -EC_curve_nid2nist 654 4_0_0 EXIST::FUNCTION:EC -EC_curve_nist2nid 655 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_check_named_curve 656 4_0_0 EXIST::FUNCTION:EC -EC_POINT_new 657 4_0_0 EXIST::FUNCTION:EC -EC_POINT_free 658 4_0_0 EXIST::FUNCTION:EC -EC_POINT_clear_free 659 4_0_0 EXIST::FUNCTION:EC -EC_POINT_copy 660 4_0_0 EXIST::FUNCTION:EC -EC_POINT_dup 661 4_0_0 EXIST::FUNCTION:EC -EC_POINT_set_to_infinity 662 4_0_0 EXIST::FUNCTION:EC -EC_POINT_method_of 663 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_POINT_set_Jprojective_coordinates_GFp 664 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_POINT_get_Jprojective_coordinates_GFp 665 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_POINT_set_affine_coordinates 666 4_0_0 EXIST::FUNCTION:EC -EC_POINT_get_affine_coordinates 667 4_0_0 EXIST::FUNCTION:EC -EC_POINT_set_affine_coordinates_GFp 668 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_POINT_get_affine_coordinates_GFp 669 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_POINT_set_compressed_coordinates 670 4_0_0 EXIST::FUNCTION:EC -EC_POINT_set_compressed_coordinates_GFp 671 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_POINT_set_affine_coordinates_GF2m 672 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC2M -EC_POINT_get_affine_coordinates_GF2m 673 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC2M -EC_POINT_set_compressed_coordinates_GF2m 674 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC2M -EC_POINT_point2oct 675 4_0_0 EXIST::FUNCTION:EC -EC_POINT_oct2point 676 4_0_0 EXIST::FUNCTION:EC -EC_POINT_point2buf 677 4_0_0 EXIST::FUNCTION:EC -EC_POINT_point2bn 678 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_POINT_bn2point 679 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_POINT_point2hex 680 4_0_0 EXIST::FUNCTION:EC -EC_POINT_hex2point 681 4_0_0 EXIST::FUNCTION:EC -EC_POINT_add 682 4_0_0 EXIST::FUNCTION:EC -EC_POINT_dbl 683 4_0_0 EXIST::FUNCTION:EC -EC_POINT_invert 684 4_0_0 EXIST::FUNCTION:EC -EC_POINT_is_at_infinity 685 4_0_0 EXIST::FUNCTION:EC -EC_POINT_is_on_curve 686 4_0_0 EXIST::FUNCTION:EC -EC_POINT_cmp 687 4_0_0 EXIST::FUNCTION:EC -EC_POINT_make_affine 688 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_POINTs_make_affine 689 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_POINTs_mul 690 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_POINT_mul 691 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_precompute_mult 692 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_GROUP_have_precompute_mult 693 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -ECPKPARAMETERS_it 694 4_0_0 EXIST::FUNCTION:EC -ECPKPARAMETERS_free 695 4_0_0 EXIST::FUNCTION:EC -ECPKPARAMETERS_new 696 4_0_0 EXIST::FUNCTION:EC -ECPARAMETERS_it 697 4_0_0 EXIST::FUNCTION:EC -ECPARAMETERS_free 698 4_0_0 EXIST::FUNCTION:EC -ECPARAMETERS_new 699 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get_basis_type 700 4_0_0 EXIST::FUNCTION:EC -EC_GROUP_get_trinomial_basis 701 4_0_0 EXIST::FUNCTION:EC,EC2M -EC_GROUP_get_pentanomial_basis 702 4_0_0 EXIST::FUNCTION:EC,EC2M -d2i_ECPKParameters 703 4_0_0 EXIST::FUNCTION:EC -i2d_ECPKParameters 704 4_0_0 EXIST::FUNCTION:EC -ECPKParameters_print 705 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -ECPKParameters_print_fp 706 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO -EC_KEY_new_ex 707 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_new 708 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_get_flags 709 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_set_flags 710 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_clear_flags 711 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_decoded_from_explicit_params 712 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_new_by_curve_name_ex 713 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_new_by_curve_name 714 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_free 715 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_copy 716 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_dup 717 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_up_ref 718 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_get0_group 719 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_set_group 720 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_get0_private_key 721 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_set_private_key 722 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_get0_public_key 723 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_set_public_key 724 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_get_enc_flags 725 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_set_enc_flags 726 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_get_conv_form 727 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_set_conv_form 728 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_set_ex_data 729 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_get_ex_data 730 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_set_asn1_flag 731 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_precompute_mult 732 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_generate_key 733 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_check_key 734 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_can_sign 735 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_set_public_key_affine_coordinates 736 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_key2buf 737 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_oct2key 738 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_oct2priv 739 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_priv2oct 740 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_priv2buf 741 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -d2i_ECPrivateKey 742 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -i2d_ECPrivateKey 743 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -d2i_ECParameters 744 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -i2d_ECParameters 745 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -o2i_ECPublicKey 746 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -i2o_ECPublicKey 747 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -ECParameters_print 748 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_print 749 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -ECParameters_print_fp 750 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO -EC_KEY_print_fp 751 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO -EC_KEY_OpenSSL 752 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_get_default_method 753 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_set_default_method 754 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_get_method 755 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_set_method 756 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_new_method 757 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -ECDH_KDF_X9_62 758 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -ECDH_compute_key 759 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -ECDSA_SIG_new 760 4_0_0 EXIST::FUNCTION:EC -ECDSA_SIG_free 761 4_0_0 EXIST::FUNCTION:EC -d2i_ECDSA_SIG 762 4_0_0 EXIST::FUNCTION:EC -i2d_ECDSA_SIG 763 4_0_0 EXIST::FUNCTION:EC -ECDSA_SIG_get0 764 4_0_0 EXIST::FUNCTION:EC -ECDSA_SIG_get0_r 765 4_0_0 EXIST::FUNCTION:EC -ECDSA_SIG_get0_s 766 4_0_0 EXIST::FUNCTION:EC -ECDSA_SIG_set0 767 4_0_0 EXIST::FUNCTION:EC -ECDSA_do_sign 768 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -ECDSA_do_sign_ex 769 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -ECDSA_do_verify 770 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -ECDSA_sign_setup 771 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -ECDSA_sign 772 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -ECDSA_sign_ex 773 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -ECDSA_verify 774 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -ECDSA_size 775 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_METHOD_new 776 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_METHOD_free 777 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_METHOD_set_init 778 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_METHOD_set_keygen 779 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_METHOD_set_compute_key 780 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_METHOD_set_sign 781 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_METHOD_set_verify 782 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_METHOD_get_init 783 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_METHOD_get_keygen 784 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_METHOD_get_compute_key 785 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_METHOD_get_sign 786 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EC_KEY_METHOD_get_verify 787 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -OSSL_ENCODER_fetch 788 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_up_ref 789 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_free 790 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_get0_provider 791 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_get0_properties 792 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_get0_name 793 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_get0_description 794 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_is_a 795 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_do_all_provided 796 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_names_do_all 797 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_gettable_params 798 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_get_params 799 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_settable_ctx_params 800 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_new 801 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_set_params 802 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_free 803 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_set_passphrase 804 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_set_pem_password_cb 805 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_set_passphrase_cb 806 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_set_passphrase_ui 807 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_set_cipher 808 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_set_selection 809 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_set_output_type 810 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_set_output_structure 811 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_add_encoder 812 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_add_extra 813 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_get_num_encoders 814 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_INSTANCE_get_encoder 815 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_INSTANCE_get_encoder_ctx 816 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_INSTANCE_get_output_type 817 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_INSTANCE_get_output_structure 818 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_set_construct 819 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_set_construct_data 820 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_set_cleanup 821 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_to_bio 822 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_to_fp 823 4_0_0 EXIST::FUNCTION:STDIO -OSSL_ENCODER_to_data 824 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_new_for_pkey 825 4_0_0 EXIST::FUNCTION: -EVP_set_default_properties 826 4_0_0 EXIST::FUNCTION: -EVP_get1_default_properties 827 4_0_0 EXIST::FUNCTION: -EVP_default_properties_is_fips_enabled 828 4_0_0 EXIST::FUNCTION: -EVP_default_properties_enable_fips 829 4_0_0 EXIST::FUNCTION: -EVP_MD_get_type 830 4_0_0 EXIST::FUNCTION: -EVP_MD_get0_name 831 4_0_0 EXIST::FUNCTION: -EVP_MD_get0_description 832 4_0_0 EXIST::FUNCTION: -EVP_MD_is_a 833 4_0_0 EXIST::FUNCTION: -EVP_MD_names_do_all 834 4_0_0 EXIST::FUNCTION: -EVP_MD_get0_provider 835 4_0_0 EXIST::FUNCTION: -EVP_MD_get_pkey_type 836 4_0_0 EXIST::FUNCTION: -EVP_MD_get_size 837 4_0_0 EXIST::FUNCTION: -EVP_MD_get_block_size 838 4_0_0 EXIST::FUNCTION: -EVP_MD_get_flags 839 4_0_0 EXIST::FUNCTION: -EVP_MD_xof 840 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_get0_md 841 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_get1_md 842 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_md 843 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_MD_CTX_get_size_ex 844 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_get_pkey_ctx 845 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_set_pkey_ctx 846 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_get0_md_data 847 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_0 -EVP_CIPHER_get_nid 848 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_get0_name 849 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_get0_description 850 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_is_a 851 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_names_do_all 852 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_get0_provider 853 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_get_block_size 854 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_impl_ctx_size 855 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_CIPHER_get_key_length 856 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_get_iv_length 857 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_get_flags 858 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_get_mode 859 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_get_type 860 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_fetch 861 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_can_pipeline 862 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_up_ref 863 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_free 864 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_get0_cipher 865 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_get1_cipher 866 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_is_encrypting 867 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_get_nid 868 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_get_block_size 869 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_get_key_length 870 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_get_iv_length 871 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_get_tag_length 872 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_cipher 873 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_CIPHER_CTX_iv 874 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_CIPHER_CTX_original_iv 875 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_CIPHER_CTX_iv_noconst 876 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_CIPHER_CTX_get_updated_iv 877 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_get_original_iv 878 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_buf_noconst 879 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_CIPHER_CTX_get_num 880 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1 -EVP_CIPHER_CTX_set_num 881 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1 -EVP_CIPHER_CTX_dup 882 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_copy 883 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_get_app_data 884 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_set_app_data 885 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_get_cipher_data 886 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_set_cipher_data 887 4_0_0 EXIST::FUNCTION: -EVP_Cipher 888 4_0_0 EXIST::FUNCTION: -EVP_MD_get_params 889 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_set_params 890 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_get_params 891 4_0_0 EXIST::FUNCTION: -EVP_MD_gettable_params 892 4_0_0 EXIST::FUNCTION: -EVP_MD_settable_ctx_params 893 4_0_0 EXIST::FUNCTION: -EVP_MD_gettable_ctx_params 894 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_settable_params 895 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_gettable_params 896 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_ctrl 897 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_new 898 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_reset 899 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_free 900 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_dup 901 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_copy_ex 902 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_set_flags 903 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_clear_flags 904 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_test_flags 905 4_0_0 EXIST::FUNCTION: -EVP_DigestInit_ex2 906 4_0_0 EXIST::FUNCTION: -EVP_DigestInit_ex 907 4_0_0 EXIST::FUNCTION: -EVP_DigestUpdate 908 4_0_0 EXIST::FUNCTION: -EVP_DigestFinal_ex 909 4_0_0 EXIST::FUNCTION: -EVP_Digest 910 4_0_0 EXIST::FUNCTION: -EVP_Q_digest 911 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_copy 912 4_0_0 EXIST::FUNCTION: -EVP_DigestInit 913 4_0_0 EXIST::FUNCTION: -EVP_DigestFinal 914 4_0_0 EXIST::FUNCTION: -EVP_DigestFinalXOF 915 4_0_0 EXIST::FUNCTION: -EVP_DigestSqueeze 916 4_0_0 EXIST::FUNCTION: -EVP_MD_fetch 917 4_0_0 EXIST::FUNCTION: -EVP_MD_up_ref 918 4_0_0 EXIST::FUNCTION: -EVP_MD_free 919 4_0_0 EXIST::FUNCTION: -EVP_read_pw_string 920 4_0_0 EXIST::FUNCTION: -EVP_read_pw_string_min 921 4_0_0 EXIST::FUNCTION: -EVP_set_pw_prompt 922 4_0_0 EXIST::FUNCTION: -EVP_get_pw_prompt 923 4_0_0 EXIST::FUNCTION: -EVP_BytesToKey 924 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_set_flags 925 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_clear_flags 926 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_test_flags 927 4_0_0 EXIST::FUNCTION: -EVP_EncryptInit 928 4_0_0 EXIST::FUNCTION: -EVP_EncryptInit_ex 929 4_0_0 EXIST::FUNCTION: -EVP_EncryptInit_ex2 930 4_0_0 EXIST::FUNCTION: -EVP_EncryptUpdate 931 4_0_0 EXIST::FUNCTION: -EVP_EncryptFinal_ex 932 4_0_0 EXIST::FUNCTION: -EVP_EncryptFinal 933 4_0_0 EXIST::FUNCTION: -EVP_DecryptInit 934 4_0_0 EXIST::FUNCTION: -EVP_DecryptInit_ex 935 4_0_0 EXIST::FUNCTION: -EVP_DecryptInit_ex2 936 4_0_0 EXIST::FUNCTION: -EVP_DecryptUpdate 937 4_0_0 EXIST::FUNCTION: -EVP_DecryptFinal 938 4_0_0 EXIST::FUNCTION: -EVP_DecryptFinal_ex 939 4_0_0 EXIST::FUNCTION: -EVP_CipherInit 940 4_0_0 EXIST::FUNCTION: -EVP_CipherInit_ex 941 4_0_0 EXIST::FUNCTION: -EVP_CipherInit_SKEY 942 4_0_0 EXIST::FUNCTION: -EVP_CipherInit_ex2 943 4_0_0 EXIST::FUNCTION: -EVP_CipherUpdate 944 4_0_0 EXIST::FUNCTION: -EVP_CipherFinal 945 4_0_0 EXIST::FUNCTION: -EVP_CipherPipelineEncryptInit 946 4_0_0 EXIST::FUNCTION: -EVP_CipherPipelineDecryptInit 947 4_0_0 EXIST::FUNCTION: -EVP_CipherPipelineUpdate 948 4_0_0 EXIST::FUNCTION: -EVP_CipherPipelineFinal 949 4_0_0 EXIST::FUNCTION: -EVP_CipherFinal_ex 950 4_0_0 EXIST::FUNCTION: -EVP_SignFinal 951 4_0_0 EXIST::FUNCTION: -EVP_SignFinal_ex 952 4_0_0 EXIST::FUNCTION: -EVP_DigestSign 953 4_0_0 EXIST::FUNCTION: -EVP_VerifyFinal 954 4_0_0 EXIST::FUNCTION: -EVP_VerifyFinal_ex 955 4_0_0 EXIST::FUNCTION: -EVP_DigestVerify 956 4_0_0 EXIST::FUNCTION: -EVP_DigestSignInit_ex 957 4_0_0 EXIST::FUNCTION: -EVP_DigestSignInit 958 4_0_0 EXIST::FUNCTION: -EVP_DigestSignUpdate 959 4_0_0 EXIST::FUNCTION: -EVP_DigestSignFinal 960 4_0_0 EXIST::FUNCTION: -EVP_DigestVerifyInit_ex 961 4_0_0 EXIST::FUNCTION: -EVP_DigestVerifyInit 962 4_0_0 EXIST::FUNCTION: -EVP_DigestVerifyUpdate 963 4_0_0 EXIST::FUNCTION: -EVP_DigestVerifyFinal 964 4_0_0 EXIST::FUNCTION: -EVP_OpenInit 965 4_0_0 EXIST::FUNCTION: -EVP_OpenFinal 966 4_0_0 EXIST::FUNCTION: -EVP_SealInit 967 4_0_0 EXIST::FUNCTION: -EVP_SealFinal 968 4_0_0 EXIST::FUNCTION: -EVP_ENCODE_CTX_new 969 4_0_0 EXIST::FUNCTION: -EVP_ENCODE_CTX_free 970 4_0_0 EXIST::FUNCTION: -EVP_ENCODE_CTX_copy 971 4_0_0 EXIST::FUNCTION: -EVP_ENCODE_CTX_num 972 4_0_0 EXIST::FUNCTION: -EVP_EncodeInit 973 4_0_0 EXIST::FUNCTION: -EVP_EncodeUpdate 974 4_0_0 EXIST::FUNCTION: -EVP_EncodeFinal 975 4_0_0 EXIST::FUNCTION: -EVP_EncodeBlock 976 4_0_0 EXIST::FUNCTION: -EVP_DecodeInit 977 4_0_0 EXIST::FUNCTION: -EVP_DecodeUpdate 978 4_0_0 EXIST::FUNCTION: -EVP_DecodeFinal 979 4_0_0 EXIST::FUNCTION: -EVP_DecodeBlock 980 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_new 981 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_reset 982 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_free 983 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_set_key_length 984 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_set_padding 985 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_ctrl 986 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_rand_key 987 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_get_params 988 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_set_params 989 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_get_params 990 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_gettable_params 991 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_settable_ctx_params 992 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_gettable_ctx_params 993 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_settable_params 994 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_gettable_params 995 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_set_algor_params 996 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_get_algor_params 997 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_CTX_get_algor 998 4_0_0 EXIST::FUNCTION: -BIO_f_md 999 4_0_0 EXIST::FUNCTION: -BIO_f_base64 1000 4_0_0 EXIST::FUNCTION: -BIO_f_cipher 1001 4_0_0 EXIST::FUNCTION: -BIO_set_cipher 1002 4_0_0 EXIST::FUNCTION: -EVP_md_null 1003 4_0_0 EXIST::FUNCTION: -EVP_md2 1004 4_0_0 EXIST::FUNCTION:MD2 -EVP_md4 1005 4_0_0 EXIST::FUNCTION:MD4 -EVP_md5 1006 4_0_0 EXIST::FUNCTION:MD5 -EVP_md5_sha1 1007 4_0_0 EXIST::FUNCTION:MD5 -EVP_blake2b512 1008 4_0_0 EXIST::FUNCTION:BLAKE2 -EVP_blake2s256 1009 4_0_0 EXIST::FUNCTION:BLAKE2 -EVP_sha1 1010 4_0_0 EXIST::FUNCTION: -EVP_sha224 1011 4_0_0 EXIST::FUNCTION: -EVP_sha256 1012 4_0_0 EXIST::FUNCTION: -EVP_sha384 1013 4_0_0 EXIST::FUNCTION: -EVP_sha512 1014 4_0_0 EXIST::FUNCTION: -EVP_sha512_224 1015 4_0_0 EXIST::FUNCTION: -EVP_sha512_256 1016 4_0_0 EXIST::FUNCTION: -EVP_sha3_224 1017 4_0_0 EXIST::FUNCTION: -EVP_sha3_256 1018 4_0_0 EXIST::FUNCTION: -EVP_sha3_384 1019 4_0_0 EXIST::FUNCTION: -EVP_sha3_512 1020 4_0_0 EXIST::FUNCTION: -EVP_shake128 1021 4_0_0 EXIST::FUNCTION: -EVP_shake256 1022 4_0_0 EXIST::FUNCTION: -EVP_mdc2 1023 4_0_0 EXIST::FUNCTION:MDC2 -EVP_ripemd160 1024 4_0_0 EXIST::FUNCTION:RMD160 -EVP_whirlpool 1025 4_0_0 EXIST::FUNCTION:WHIRLPOOL -EVP_sm3 1026 4_0_0 EXIST::FUNCTION:SM3 -EVP_enc_null 1027 4_0_0 EXIST::FUNCTION: -EVP_des_ecb 1028 4_0_0 EXIST::FUNCTION:DES -EVP_des_ede 1029 4_0_0 EXIST::FUNCTION:DES -EVP_des_ede3 1030 4_0_0 EXIST::FUNCTION:DES -EVP_des_ede_ecb 1031 4_0_0 EXIST::FUNCTION:DES -EVP_des_ede3_ecb 1032 4_0_0 EXIST::FUNCTION:DES -EVP_des_cfb64 1033 4_0_0 EXIST::FUNCTION:DES -EVP_des_cfb1 1034 4_0_0 EXIST::FUNCTION:DES -EVP_des_cfb8 1035 4_0_0 EXIST::FUNCTION:DES -EVP_des_ede_cfb64 1036 4_0_0 EXIST::FUNCTION:DES -EVP_des_ede3_cfb64 1037 4_0_0 EXIST::FUNCTION:DES -EVP_des_ede3_cfb1 1038 4_0_0 EXIST::FUNCTION:DES -EVP_des_ede3_cfb8 1039 4_0_0 EXIST::FUNCTION:DES -EVP_des_ofb 1040 4_0_0 EXIST::FUNCTION:DES -EVP_des_ede_ofb 1041 4_0_0 EXIST::FUNCTION:DES -EVP_des_ede3_ofb 1042 4_0_0 EXIST::FUNCTION:DES -EVP_des_cbc 1043 4_0_0 EXIST::FUNCTION:DES -EVP_des_ede_cbc 1044 4_0_0 EXIST::FUNCTION:DES -EVP_des_ede3_cbc 1045 4_0_0 EXIST::FUNCTION:DES -EVP_desx_cbc 1046 4_0_0 EXIST::FUNCTION:DES -EVP_des_ede3_wrap 1047 4_0_0 EXIST::FUNCTION:DES -EVP_rc4 1048 4_0_0 EXIST::FUNCTION:RC4 -EVP_rc4_40 1049 4_0_0 EXIST::FUNCTION:RC4 -EVP_rc4_hmac_md5 1050 4_0_0 EXIST::FUNCTION:MD5,RC4 -EVP_idea_ecb 1051 4_0_0 EXIST::FUNCTION:IDEA -EVP_idea_cfb64 1052 4_0_0 EXIST::FUNCTION:IDEA -EVP_idea_ofb 1053 4_0_0 EXIST::FUNCTION:IDEA -EVP_idea_cbc 1054 4_0_0 EXIST::FUNCTION:IDEA -EVP_rc2_ecb 1055 4_0_0 EXIST::FUNCTION:RC2 -EVP_rc2_cbc 1056 4_0_0 EXIST::FUNCTION:RC2 -EVP_rc2_40_cbc 1057 4_0_0 EXIST::FUNCTION:RC2 -EVP_rc2_64_cbc 1058 4_0_0 EXIST::FUNCTION:RC2 -EVP_rc2_cfb64 1059 4_0_0 EXIST::FUNCTION:RC2 -EVP_rc2_ofb 1060 4_0_0 EXIST::FUNCTION:RC2 -EVP_bf_ecb 1061 4_0_0 EXIST::FUNCTION:BF -EVP_bf_cbc 1062 4_0_0 EXIST::FUNCTION:BF -EVP_bf_cfb64 1063 4_0_0 EXIST::FUNCTION:BF -EVP_bf_ofb 1064 4_0_0 EXIST::FUNCTION:BF -EVP_cast5_ecb 1065 4_0_0 EXIST::FUNCTION:CAST -EVP_cast5_cbc 1066 4_0_0 EXIST::FUNCTION:CAST -EVP_cast5_cfb64 1067 4_0_0 EXIST::FUNCTION:CAST -EVP_cast5_ofb 1068 4_0_0 EXIST::FUNCTION:CAST -EVP_rc5_32_12_16_cbc 1069 4_0_0 EXIST::FUNCTION:RC5 -EVP_rc5_32_12_16_ecb 1070 4_0_0 EXIST::FUNCTION:RC5 -EVP_rc5_32_12_16_cfb64 1071 4_0_0 EXIST::FUNCTION:RC5 -EVP_rc5_32_12_16_ofb 1072 4_0_0 EXIST::FUNCTION:RC5 -EVP_aes_128_ecb 1073 4_0_0 EXIST::FUNCTION: -EVP_aes_128_cbc 1074 4_0_0 EXIST::FUNCTION: -EVP_aes_128_cfb1 1075 4_0_0 EXIST::FUNCTION: -EVP_aes_128_cfb8 1076 4_0_0 EXIST::FUNCTION: -EVP_aes_128_cfb128 1077 4_0_0 EXIST::FUNCTION: -EVP_aes_128_ofb 1078 4_0_0 EXIST::FUNCTION: -EVP_aes_128_ctr 1079 4_0_0 EXIST::FUNCTION: -EVP_aes_128_ccm 1080 4_0_0 EXIST::FUNCTION: -EVP_aes_128_gcm 1081 4_0_0 EXIST::FUNCTION: -EVP_aes_128_xts 1082 4_0_0 EXIST::FUNCTION: -EVP_aes_128_wrap 1083 4_0_0 EXIST::FUNCTION: -EVP_aes_128_wrap_pad 1084 4_0_0 EXIST::FUNCTION: -EVP_aes_128_ocb 1085 4_0_0 EXIST::FUNCTION:OCB -EVP_aes_192_ecb 1086 4_0_0 EXIST::FUNCTION: -EVP_aes_192_cbc 1087 4_0_0 EXIST::FUNCTION: -EVP_aes_192_cfb1 1088 4_0_0 EXIST::FUNCTION: -EVP_aes_192_cfb8 1089 4_0_0 EXIST::FUNCTION: -EVP_aes_192_cfb128 1090 4_0_0 EXIST::FUNCTION: -EVP_aes_192_ofb 1091 4_0_0 EXIST::FUNCTION: -EVP_aes_192_ctr 1092 4_0_0 EXIST::FUNCTION: -EVP_aes_192_ccm 1093 4_0_0 EXIST::FUNCTION: -EVP_aes_192_gcm 1094 4_0_0 EXIST::FUNCTION: -EVP_aes_192_wrap 1095 4_0_0 EXIST::FUNCTION: -EVP_aes_192_wrap_pad 1096 4_0_0 EXIST::FUNCTION: -EVP_aes_192_ocb 1097 4_0_0 EXIST::FUNCTION:OCB -EVP_aes_256_ecb 1098 4_0_0 EXIST::FUNCTION: -EVP_aes_256_cbc 1099 4_0_0 EXIST::FUNCTION: -EVP_aes_256_cfb1 1100 4_0_0 EXIST::FUNCTION: -EVP_aes_256_cfb8 1101 4_0_0 EXIST::FUNCTION: -EVP_aes_256_cfb128 1102 4_0_0 EXIST::FUNCTION: -EVP_aes_256_ofb 1103 4_0_0 EXIST::FUNCTION: -EVP_aes_256_ctr 1104 4_0_0 EXIST::FUNCTION: -EVP_aes_256_ccm 1105 4_0_0 EXIST::FUNCTION: -EVP_aes_256_gcm 1106 4_0_0 EXIST::FUNCTION: -EVP_aes_256_xts 1107 4_0_0 EXIST::FUNCTION: -EVP_aes_256_wrap 1108 4_0_0 EXIST::FUNCTION: -EVP_aes_256_wrap_pad 1109 4_0_0 EXIST::FUNCTION: -EVP_aes_256_ocb 1110 4_0_0 EXIST::FUNCTION:OCB -EVP_aes_128_cbc_hmac_sha1 1111 4_0_0 EXIST::FUNCTION: -EVP_aes_256_cbc_hmac_sha1 1112 4_0_0 EXIST::FUNCTION: -EVP_aes_128_cbc_hmac_sha256 1113 4_0_0 EXIST::FUNCTION: -EVP_aes_256_cbc_hmac_sha256 1114 4_0_0 EXIST::FUNCTION: -EVP_aria_128_ecb 1115 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_128_cbc 1116 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_128_cfb1 1117 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_128_cfb8 1118 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_128_cfb128 1119 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_128_ctr 1120 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_128_ofb 1121 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_128_gcm 1122 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_128_ccm 1123 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_192_ecb 1124 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_192_cbc 1125 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_192_cfb1 1126 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_192_cfb8 1127 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_192_cfb128 1128 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_192_ctr 1129 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_192_ofb 1130 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_192_gcm 1131 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_192_ccm 1132 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_256_ecb 1133 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_256_cbc 1134 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_256_cfb1 1135 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_256_cfb8 1136 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_256_cfb128 1137 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_256_ctr 1138 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_256_ofb 1139 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_256_gcm 1140 4_0_0 EXIST::FUNCTION:ARIA -EVP_aria_256_ccm 1141 4_0_0 EXIST::FUNCTION:ARIA -EVP_camellia_128_ecb 1142 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_128_cbc 1143 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_128_cfb1 1144 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_128_cfb8 1145 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_128_cfb128 1146 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_128_ofb 1147 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_128_ctr 1148 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_192_ecb 1149 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_192_cbc 1150 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_192_cfb1 1151 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_192_cfb8 1152 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_192_cfb128 1153 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_192_ofb 1154 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_192_ctr 1155 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_256_ecb 1156 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_256_cbc 1157 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_256_cfb1 1158 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_256_cfb8 1159 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_256_cfb128 1160 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_256_ofb 1161 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_camellia_256_ctr 1162 4_0_0 EXIST::FUNCTION:CAMELLIA -EVP_chacha20 1163 4_0_0 EXIST::FUNCTION:CHACHA -EVP_chacha20_poly1305 1164 4_0_0 EXIST::FUNCTION:CHACHA,POLY1305 -EVP_seed_ecb 1165 4_0_0 EXIST::FUNCTION:SEED -EVP_seed_cbc 1166 4_0_0 EXIST::FUNCTION:SEED -EVP_seed_cfb128 1167 4_0_0 EXIST::FUNCTION:SEED -EVP_seed_ofb 1168 4_0_0 EXIST::FUNCTION:SEED -EVP_sm4_ecb 1169 4_0_0 EXIST::FUNCTION:SM4 -EVP_sm4_cbc 1170 4_0_0 EXIST::FUNCTION:SM4 -EVP_sm4_cfb128 1171 4_0_0 EXIST::FUNCTION:SM4 -EVP_sm4_ofb 1172 4_0_0 EXIST::FUNCTION:SM4 -EVP_sm4_ctr 1173 4_0_0 EXIST::FUNCTION:SM4 -EVP_add_cipher 1174 4_0_0 EXIST::FUNCTION: -EVP_add_digest 1175 4_0_0 EXIST::FUNCTION: -EVP_get_cipherbyname 1176 4_0_0 EXIST::FUNCTION: -EVP_get_digestbyname 1177 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_do_all 1178 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_do_all_sorted 1179 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_do_all_provided 1180 4_0_0 EXIST::FUNCTION: -EVP_MD_do_all 1181 4_0_0 EXIST::FUNCTION: -EVP_MD_do_all_sorted 1182 4_0_0 EXIST::FUNCTION: -EVP_MD_do_all_provided 1183 4_0_0 EXIST::FUNCTION: -EVP_MAC_fetch 1184 4_0_0 EXIST::FUNCTION: -EVP_MAC_up_ref 1185 4_0_0 EXIST::FUNCTION: -EVP_MAC_free 1186 4_0_0 EXIST::FUNCTION: -EVP_MAC_get0_name 1187 4_0_0 EXIST::FUNCTION: -EVP_MAC_get0_description 1188 4_0_0 EXIST::FUNCTION: -EVP_MAC_is_a 1189 4_0_0 EXIST::FUNCTION: -EVP_MAC_get0_provider 1190 4_0_0 EXIST::FUNCTION: -EVP_MAC_get_params 1191 4_0_0 EXIST::FUNCTION: -EVP_MAC_CTX_new 1192 4_0_0 EXIST::FUNCTION: -EVP_MAC_CTX_free 1193 4_0_0 EXIST::FUNCTION: -EVP_MAC_CTX_dup 1194 4_0_0 EXIST::FUNCTION: -EVP_MAC_CTX_get0_mac 1195 4_0_0 EXIST::FUNCTION: -EVP_MAC_CTX_get_params 1196 4_0_0 EXIST::FUNCTION: -EVP_MAC_CTX_set_params 1197 4_0_0 EXIST::FUNCTION: -EVP_MAC_CTX_get_mac_size 1198 4_0_0 EXIST::FUNCTION: -EVP_MAC_CTX_get_block_size 1199 4_0_0 EXIST::FUNCTION: -EVP_Q_mac 1200 4_0_0 EXIST::FUNCTION: -EVP_MAC_init 1201 4_0_0 EXIST::FUNCTION: -EVP_MAC_init_SKEY 1202 4_0_0 EXIST::FUNCTION: -EVP_MAC_update 1203 4_0_0 EXIST::FUNCTION: -EVP_MAC_final 1204 4_0_0 EXIST::FUNCTION: -EVP_MAC_finalXOF 1205 4_0_0 EXIST::FUNCTION: -EVP_MAC_gettable_params 1206 4_0_0 EXIST::FUNCTION: -EVP_MAC_gettable_ctx_params 1207 4_0_0 EXIST::FUNCTION: -EVP_MAC_settable_ctx_params 1208 4_0_0 EXIST::FUNCTION: -EVP_MAC_CTX_gettable_params 1209 4_0_0 EXIST::FUNCTION: -EVP_MAC_CTX_settable_params 1210 4_0_0 EXIST::FUNCTION: -EVP_MAC_do_all_provided 1211 4_0_0 EXIST::FUNCTION: -EVP_MAC_names_do_all 1212 4_0_0 EXIST::FUNCTION: -EVP_RAND_fetch 1213 4_0_0 EXIST::FUNCTION: -EVP_RAND_up_ref 1214 4_0_0 EXIST::FUNCTION: -EVP_RAND_free 1215 4_0_0 EXIST::FUNCTION: -EVP_RAND_get0_name 1216 4_0_0 EXIST::FUNCTION: -EVP_RAND_get0_description 1217 4_0_0 EXIST::FUNCTION: -EVP_RAND_is_a 1218 4_0_0 EXIST::FUNCTION: -EVP_RAND_get0_provider 1219 4_0_0 EXIST::FUNCTION: -EVP_RAND_get_params 1220 4_0_0 EXIST::FUNCTION: -EVP_RAND_CTX_new 1221 4_0_0 EXIST::FUNCTION: -EVP_RAND_CTX_up_ref 1222 4_0_0 EXIST::FUNCTION: -EVP_RAND_CTX_free 1223 4_0_0 EXIST::FUNCTION: -EVP_RAND_CTX_get0_rand 1224 4_0_0 EXIST::FUNCTION: -EVP_RAND_CTX_get_params 1225 4_0_0 EXIST::FUNCTION: -EVP_RAND_CTX_set_params 1226 4_0_0 EXIST::FUNCTION: -EVP_RAND_gettable_params 1227 4_0_0 EXIST::FUNCTION: -EVP_RAND_gettable_ctx_params 1228 4_0_0 EXIST::FUNCTION: -EVP_RAND_settable_ctx_params 1229 4_0_0 EXIST::FUNCTION: -EVP_RAND_CTX_gettable_params 1230 4_0_0 EXIST::FUNCTION: -EVP_RAND_CTX_settable_params 1231 4_0_0 EXIST::FUNCTION: -EVP_RAND_do_all_provided 1232 4_0_0 EXIST::FUNCTION: -EVP_RAND_names_do_all 1233 4_0_0 EXIST::FUNCTION: -EVP_RAND_instantiate 1234 4_0_0 EXIST::FUNCTION: -EVP_RAND_uninstantiate 1235 4_0_0 EXIST::FUNCTION: -EVP_RAND_generate 1236 4_0_0 EXIST::FUNCTION: -EVP_RAND_reseed 1237 4_0_0 EXIST::FUNCTION: -EVP_RAND_nonce 1238 4_0_0 EXIST::FUNCTION: -EVP_RAND_enable_locking 1239 4_0_0 EXIST::FUNCTION: -EVP_RAND_verify_zeroization 1240 4_0_0 EXIST::FUNCTION: -EVP_RAND_get_strength 1241 4_0_0 EXIST::FUNCTION: -EVP_RAND_get_state 1242 4_0_0 EXIST::FUNCTION: -EVP_PKEY_decrypt_old 1243 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_PKEY_encrypt_old 1244 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_PKEY_is_a 1245 4_0_0 EXIST::FUNCTION: -EVP_PKEY_type_names_do_all 1246 4_0_0 EXIST::FUNCTION: -EVP_PKEY_type 1247 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_id 1248 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_base_id 1249 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_bits 1250 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_security_bits 1251 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_security_category 1252 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_size 1253 4_0_0 EXIST::FUNCTION: -EVP_PKEY_can_sign 1254 4_0_0 EXIST::FUNCTION: -EVP_PKEY_set_type 1255 4_0_0 EXIST::FUNCTION: -EVP_PKEY_set_type_str 1256 4_0_0 EXIST::FUNCTION: -EVP_PKEY_set_type_by_keymgmt 1257 4_0_0 EXIST::FUNCTION: -EVP_PKEY_assign 1258 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_PKEY_get0 1259 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_PKEY_get0_hmac 1260 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_PKEY_get0_poly1305 1261 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,POLY1305 -EVP_PKEY_get0_siphash 1262 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SIPHASH -EVP_PKEY_set1_RSA 1263 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_PKEY_get0_RSA 1264 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_PKEY_get1_RSA 1265 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_PKEY_set1_DSA 1266 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -EVP_PKEY_get0_DSA 1267 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -EVP_PKEY_get1_DSA 1268 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -EVP_PKEY_set1_DH 1269 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -EVP_PKEY_get0_DH 1270 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -EVP_PKEY_get1_DH 1271 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -EVP_PKEY_set1_EC_KEY 1272 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EVP_PKEY_get0_EC_KEY 1273 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EVP_PKEY_get1_EC_KEY 1274 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -EVP_PKEY_new 1275 4_0_0 EXIST::FUNCTION: -EVP_PKEY_up_ref 1276 4_0_0 EXIST::FUNCTION: -EVP_PKEY_dup 1277 4_0_0 EXIST::FUNCTION: -EVP_PKEY_free 1278 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get0_description 1279 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get0_provider 1280 4_0_0 EXIST::FUNCTION: -d2i_PublicKey 1281 4_0_0 EXIST::FUNCTION: -i2d_PublicKey 1282 4_0_0 EXIST::FUNCTION: -d2i_PrivateKey_ex 1283 4_0_0 EXIST::FUNCTION: -d2i_PrivateKey 1284 4_0_0 EXIST::FUNCTION: -d2i_AutoPrivateKey_ex 1285 4_0_0 EXIST::FUNCTION: -d2i_AutoPrivateKey 1286 4_0_0 EXIST::FUNCTION: -i2d_PrivateKey 1287 4_0_0 EXIST::FUNCTION: -i2d_PKCS8PrivateKey 1288 4_0_0 EXIST::FUNCTION: -i2d_KeyParams 1289 4_0_0 EXIST::FUNCTION: -d2i_KeyParams 1290 4_0_0 EXIST::FUNCTION: -i2d_KeyParams_bio 1291 4_0_0 EXIST::FUNCTION: -d2i_KeyParams_bio 1292 4_0_0 EXIST::FUNCTION: -EVP_PKEY_copy_parameters 1293 4_0_0 EXIST::FUNCTION: -EVP_PKEY_missing_parameters 1294 4_0_0 EXIST::FUNCTION: -EVP_PKEY_save_parameters 1295 4_0_0 EXIST::FUNCTION: -EVP_PKEY_parameters_eq 1296 4_0_0 EXIST::FUNCTION: -EVP_PKEY_eq 1297 4_0_0 EXIST::FUNCTION: -EVP_PKEY_cmp_parameters 1298 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_PKEY_cmp 1299 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_PKEY_print_public 1300 4_0_0 EXIST::FUNCTION: -EVP_PKEY_print_private 1301 4_0_0 EXIST::FUNCTION: -EVP_PKEY_print_params 1302 4_0_0 EXIST::FUNCTION: -EVP_PKEY_print_public_fp 1303 4_0_0 EXIST::FUNCTION:STDIO -EVP_PKEY_print_private_fp 1304 4_0_0 EXIST::FUNCTION:STDIO -EVP_PKEY_print_params_fp 1305 4_0_0 EXIST::FUNCTION:STDIO -EVP_PKEY_get_default_digest_nid 1306 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_default_digest_name 1307 4_0_0 EXIST::FUNCTION: -EVP_PKEY_digestsign_supports_digest 1308 4_0_0 EXIST::FUNCTION: -EVP_PKEY_set1_encoded_public_key 1309 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get1_encoded_public_key 1310 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_param_to_asn1 1311 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_asn1_to_param 1312 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_set_asn1_iv 1313 4_0_0 EXIST::FUNCTION: -EVP_CIPHER_get_asn1_iv 1314 4_0_0 EXIST::FUNCTION: -PKCS5_PBE_keyivgen 1315 4_0_0 EXIST::FUNCTION: -PKCS5_PBE_keyivgen_ex 1316 4_0_0 EXIST::FUNCTION: -PKCS5_PBKDF2_HMAC_SHA1 1317 4_0_0 EXIST::FUNCTION: -PKCS5_PBKDF2_HMAC 1318 4_0_0 EXIST::FUNCTION: -PKCS5_v2_PBE_keyivgen 1319 4_0_0 EXIST::FUNCTION: -PKCS5_v2_PBE_keyivgen_ex 1320 4_0_0 EXIST::FUNCTION: -EVP_PBE_scrypt 1321 4_0_0 EXIST::FUNCTION:SCRYPT -EVP_PBE_scrypt_ex 1322 4_0_0 EXIST::FUNCTION:SCRYPT -PKCS5_v2_scrypt_keyivgen 1323 4_0_0 EXIST::FUNCTION:SCRYPT -PKCS5_v2_scrypt_keyivgen_ex 1324 4_0_0 EXIST::FUNCTION:SCRYPT -PKCS5_PBE_add 1325 4_0_0 EXIST::FUNCTION: -EVP_PBE_CipherInit 1326 4_0_0 EXIST::FUNCTION: -EVP_PBE_CipherInit_ex 1327 4_0_0 EXIST::FUNCTION: -EVP_PBE_alg_add_type 1328 4_0_0 EXIST::FUNCTION: -EVP_PBE_alg_add 1329 4_0_0 EXIST::FUNCTION: -EVP_PBE_find 1330 4_0_0 EXIST::FUNCTION: -EVP_PBE_find_ex 1331 4_0_0 EXIST::FUNCTION: -EVP_PBE_cleanup 1332 4_0_0 EXIST::FUNCTION: -EVP_PBE_get 1333 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_signature_md 1334 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_signature_md 1335 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set1_id 1336 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get1_id 1337 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get1_id_len 1338 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_kem_op 1339 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get0_type_name 1340 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_mac_key 1341 4_0_0 EXIST::FUNCTION: -EVP_KEYMGMT_fetch 1342 4_0_0 EXIST::FUNCTION: -EVP_KEYMGMT_up_ref 1343 4_0_0 EXIST::FUNCTION: -EVP_KEYMGMT_free 1344 4_0_0 EXIST::FUNCTION: -EVP_KEYMGMT_get0_provider 1345 4_0_0 EXIST::FUNCTION: -EVP_KEYMGMT_get0_name 1346 4_0_0 EXIST::FUNCTION: -EVP_KEYMGMT_get0_description 1347 4_0_0 EXIST::FUNCTION: -EVP_KEYMGMT_is_a 1348 4_0_0 EXIST::FUNCTION: -EVP_KEYMGMT_do_all_provided 1349 4_0_0 EXIST::FUNCTION: -EVP_KEYMGMT_names_do_all 1350 4_0_0 EXIST::FUNCTION: -EVP_KEYMGMT_gettable_params 1351 4_0_0 EXIST::FUNCTION: -EVP_KEYMGMT_settable_params 1352 4_0_0 EXIST::FUNCTION: -EVP_KEYMGMT_gen_settable_params 1353 4_0_0 EXIST::FUNCTION: -EVP_KEYMGMT_gen_gettable_params 1354 4_0_0 EXIST::FUNCTION: -EVP_SKEYMGMT_fetch 1355 4_0_0 EXIST::FUNCTION: -EVP_SKEYMGMT_up_ref 1356 4_0_0 EXIST::FUNCTION: -EVP_SKEYMGMT_free 1357 4_0_0 EXIST::FUNCTION: -EVP_SKEYMGMT_get0_provider 1358 4_0_0 EXIST::FUNCTION: -EVP_SKEYMGMT_get0_name 1359 4_0_0 EXIST::FUNCTION: -EVP_SKEYMGMT_get0_description 1360 4_0_0 EXIST::FUNCTION: -EVP_SKEYMGMT_is_a 1361 4_0_0 EXIST::FUNCTION: -EVP_SKEYMGMT_do_all_provided 1362 4_0_0 EXIST::FUNCTION: -EVP_SKEYMGMT_names_do_all 1363 4_0_0 EXIST::FUNCTION: -EVP_SKEYMGMT_get0_gen_settable_params 1364 4_0_0 EXIST::FUNCTION: -EVP_SKEYMGMT_get0_imp_settable_params 1365 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_new 1366 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_new_id 1367 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_new_from_name 1368 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_new_from_pkey 1369 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_dup 1370 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_free 1371 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_is_a 1372 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_params 1373 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_gettable_params 1374 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_params 1375 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_settable_params 1376 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_algor_params 1377 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_algor_params 1378 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_algor 1379 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_ctrl 1380 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_ctrl_str 1381 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_ctrl_uint64 1382 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_str2ctrl 1383 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_hex2ctrl 1384 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_md 1385 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_operation 1386 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set0_keygen_info 1387 4_0_0 EXIST::FUNCTION: -EVP_PKEY_new_mac_key 1388 4_0_0 EXIST::FUNCTION: -EVP_PKEY_new_raw_private_key_ex 1389 4_0_0 EXIST::FUNCTION: -EVP_PKEY_new_raw_private_key 1390 4_0_0 EXIST::FUNCTION: -EVP_PKEY_new_raw_public_key_ex 1391 4_0_0 EXIST::FUNCTION: -EVP_PKEY_new_raw_public_key 1392 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_raw_private_key 1393 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_raw_public_key 1394 4_0_0 EXIST::FUNCTION: -EVP_PKEY_new_CMAC_key 1395 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_PKEY_CTX_set_data 1396 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_data 1397 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get0_pkey 1398 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get0_peerkey 1399 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_app_data 1400 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_app_data 1401 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_signature 1402 4_0_0 EXIST::FUNCTION: -EVP_SIGNATURE_free 1403 4_0_0 EXIST::FUNCTION: -EVP_SIGNATURE_up_ref 1404 4_0_0 EXIST::FUNCTION: -EVP_SIGNATURE_get0_provider 1405 4_0_0 EXIST::FUNCTION: -EVP_SIGNATURE_fetch 1406 4_0_0 EXIST::FUNCTION: -EVP_SIGNATURE_is_a 1407 4_0_0 EXIST::FUNCTION: -EVP_SIGNATURE_get0_name 1408 4_0_0 EXIST::FUNCTION: -EVP_SIGNATURE_get0_description 1409 4_0_0 EXIST::FUNCTION: -EVP_SIGNATURE_do_all_provided 1410 4_0_0 EXIST::FUNCTION: -EVP_SIGNATURE_names_do_all 1411 4_0_0 EXIST::FUNCTION: -EVP_SIGNATURE_gettable_ctx_params 1412 4_0_0 EXIST::FUNCTION: -EVP_SIGNATURE_settable_ctx_params 1413 4_0_0 EXIST::FUNCTION: -EVP_ASYM_CIPHER_free 1414 4_0_0 EXIST::FUNCTION: -EVP_ASYM_CIPHER_up_ref 1415 4_0_0 EXIST::FUNCTION: -EVP_ASYM_CIPHER_get0_provider 1416 4_0_0 EXIST::FUNCTION: -EVP_ASYM_CIPHER_fetch 1417 4_0_0 EXIST::FUNCTION: -EVP_ASYM_CIPHER_is_a 1418 4_0_0 EXIST::FUNCTION: -EVP_ASYM_CIPHER_get0_name 1419 4_0_0 EXIST::FUNCTION: -EVP_ASYM_CIPHER_get0_description 1420 4_0_0 EXIST::FUNCTION: -EVP_ASYM_CIPHER_do_all_provided 1421 4_0_0 EXIST::FUNCTION: -EVP_ASYM_CIPHER_names_do_all 1422 4_0_0 EXIST::FUNCTION: -EVP_ASYM_CIPHER_gettable_ctx_params 1423 4_0_0 EXIST::FUNCTION: -EVP_ASYM_CIPHER_settable_ctx_params 1424 4_0_0 EXIST::FUNCTION: -EVP_KEM_free 1425 4_0_0 EXIST::FUNCTION: -EVP_KEM_up_ref 1426 4_0_0 EXIST::FUNCTION: -EVP_KEM_get0_provider 1427 4_0_0 EXIST::FUNCTION: -EVP_KEM_fetch 1428 4_0_0 EXIST::FUNCTION: -EVP_KEM_is_a 1429 4_0_0 EXIST::FUNCTION: -EVP_KEM_get0_name 1430 4_0_0 EXIST::FUNCTION: -EVP_KEM_get0_description 1431 4_0_0 EXIST::FUNCTION: -EVP_KEM_do_all_provided 1432 4_0_0 EXIST::FUNCTION: -EVP_KEM_names_do_all 1433 4_0_0 EXIST::FUNCTION: -EVP_KEM_gettable_ctx_params 1434 4_0_0 EXIST::FUNCTION: -EVP_KEM_settable_ctx_params 1435 4_0_0 EXIST::FUNCTION: -EVP_PKEY_sign_init 1436 4_0_0 EXIST::FUNCTION: -EVP_PKEY_sign_init_ex 1437 4_0_0 EXIST::FUNCTION: -EVP_PKEY_sign_init_ex2 1438 4_0_0 EXIST::FUNCTION: -EVP_PKEY_sign 1439 4_0_0 EXIST::FUNCTION: -EVP_PKEY_sign_message_init 1440 4_0_0 EXIST::FUNCTION: -EVP_PKEY_sign_message_update 1441 4_0_0 EXIST::FUNCTION: -EVP_PKEY_sign_message_final 1442 4_0_0 EXIST::FUNCTION: -EVP_PKEY_verify_init 1443 4_0_0 EXIST::FUNCTION: -EVP_PKEY_verify_init_ex 1444 4_0_0 EXIST::FUNCTION: -EVP_PKEY_verify_init_ex2 1445 4_0_0 EXIST::FUNCTION: -EVP_PKEY_verify 1446 4_0_0 EXIST::FUNCTION: -EVP_PKEY_verify_message_init 1447 4_0_0 EXIST::FUNCTION: -EVP_PKEY_verify_message_update 1448 4_0_0 EXIST::FUNCTION: -EVP_PKEY_verify_message_final 1449 4_0_0 EXIST::FUNCTION: -EVP_PKEY_verify_recover_init 1450 4_0_0 EXIST::FUNCTION: -EVP_PKEY_verify_recover_init_ex 1451 4_0_0 EXIST::FUNCTION: -EVP_PKEY_verify_recover_init_ex2 1452 4_0_0 EXIST::FUNCTION: -EVP_PKEY_verify_recover 1453 4_0_0 EXIST::FUNCTION: -EVP_PKEY_encrypt_init 1454 4_0_0 EXIST::FUNCTION: -EVP_PKEY_encrypt_init_ex 1455 4_0_0 EXIST::FUNCTION: -EVP_PKEY_encrypt 1456 4_0_0 EXIST::FUNCTION: -EVP_PKEY_decrypt_init 1457 4_0_0 EXIST::FUNCTION: -EVP_PKEY_decrypt_init_ex 1458 4_0_0 EXIST::FUNCTION: -EVP_PKEY_decrypt 1459 4_0_0 EXIST::FUNCTION: -EVP_PKEY_derive_init 1460 4_0_0 EXIST::FUNCTION: -EVP_PKEY_derive_init_ex 1461 4_0_0 EXIST::FUNCTION: -EVP_PKEY_derive_set_peer_ex 1462 4_0_0 EXIST::FUNCTION: -EVP_PKEY_derive_set_peer 1463 4_0_0 EXIST::FUNCTION: -EVP_PKEY_derive 1464 4_0_0 EXIST::FUNCTION: -EVP_PKEY_derive_SKEY 1465 4_0_0 EXIST::FUNCTION: -EVP_PKEY_encapsulate_init 1466 4_0_0 EXIST::FUNCTION: -EVP_PKEY_auth_encapsulate_init 1467 4_0_0 EXIST::FUNCTION: -EVP_PKEY_encapsulate 1468 4_0_0 EXIST::FUNCTION: -EVP_PKEY_decapsulate_init 1469 4_0_0 EXIST::FUNCTION: -EVP_PKEY_auth_decapsulate_init 1470 4_0_0 EXIST::FUNCTION: -EVP_PKEY_decapsulate 1471 4_0_0 EXIST::FUNCTION: -EVP_PKEY_fromdata_init 1472 4_0_0 EXIST::FUNCTION: -EVP_PKEY_fromdata 1473 4_0_0 EXIST::FUNCTION: -EVP_PKEY_fromdata_settable 1474 4_0_0 EXIST::FUNCTION: -EVP_PKEY_todata 1475 4_0_0 EXIST::FUNCTION: -EVP_PKEY_export 1476 4_0_0 EXIST::FUNCTION: -EVP_PKEY_gettable_params 1477 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_params 1478 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_int_param 1479 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_size_t_param 1480 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_bn_param 1481 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_utf8_string_param 1482 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_octet_string_param 1483 4_0_0 EXIST::FUNCTION: -EVP_PKEY_settable_params 1484 4_0_0 EXIST::FUNCTION: -EVP_PKEY_set_params 1485 4_0_0 EXIST::FUNCTION: -EVP_PKEY_set_int_param 1486 4_0_0 EXIST::FUNCTION: -EVP_PKEY_set_size_t_param 1487 4_0_0 EXIST::FUNCTION: -EVP_PKEY_set_bn_param 1488 4_0_0 EXIST::FUNCTION: -EVP_PKEY_set_utf8_string_param 1489 4_0_0 EXIST::FUNCTION: -EVP_PKEY_set_octet_string_param 1490 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_ec_point_conv_form 1491 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_field_type 1492 4_0_0 EXIST::FUNCTION: -EVP_PKEY_Q_keygen 1493 4_0_0 EXIST::FUNCTION: -EVP_PKEY_paramgen_init 1494 4_0_0 EXIST::FUNCTION: -EVP_PKEY_paramgen 1495 4_0_0 EXIST::FUNCTION: -EVP_PKEY_keygen_init 1496 4_0_0 EXIST::FUNCTION: -EVP_PKEY_keygen 1497 4_0_0 EXIST::FUNCTION: -EVP_PKEY_generate 1498 4_0_0 EXIST::FUNCTION: -EVP_PKEY_check 1499 4_0_0 EXIST::FUNCTION: -EVP_PKEY_public_check 1500 4_0_0 EXIST::FUNCTION: -EVP_PKEY_public_check_quick 1501 4_0_0 EXIST::FUNCTION: -EVP_PKEY_param_check 1502 4_0_0 EXIST::FUNCTION: -EVP_PKEY_param_check_quick 1503 4_0_0 EXIST::FUNCTION: -EVP_PKEY_private_check 1504 4_0_0 EXIST::FUNCTION: -EVP_PKEY_pairwise_check 1505 4_0_0 EXIST::FUNCTION: -EVP_PKEY_set_ex_data 1506 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_ex_data 1507 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_cb 1508 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_cb 1509 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_keygen_info 1510 4_0_0 EXIST::FUNCTION: -EVP_KEYEXCH_free 1511 4_0_0 EXIST::FUNCTION: -EVP_KEYEXCH_up_ref 1512 4_0_0 EXIST::FUNCTION: -EVP_KEYEXCH_fetch 1513 4_0_0 EXIST::FUNCTION: -EVP_KEYEXCH_get0_provider 1514 4_0_0 EXIST::FUNCTION: -EVP_KEYEXCH_is_a 1515 4_0_0 EXIST::FUNCTION: -EVP_KEYEXCH_get0_name 1516 4_0_0 EXIST::FUNCTION: -EVP_KEYEXCH_get0_description 1517 4_0_0 EXIST::FUNCTION: -EVP_KEYEXCH_do_all_provided 1518 4_0_0 EXIST::FUNCTION: -EVP_KEYEXCH_names_do_all 1519 4_0_0 EXIST::FUNCTION: -EVP_KEYEXCH_gettable_ctx_params 1520 4_0_0 EXIST::FUNCTION: -EVP_KEYEXCH_settable_ctx_params 1521 4_0_0 EXIST::FUNCTION: -EVP_add_alg_module 1522 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_group_name 1523 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_group_name 1524 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_group_name 1525 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get0_libctx 1526 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get0_propq 1527 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get0_provider 1528 4_0_0 EXIST::FUNCTION: -EVP_SKEY_is_a 1529 4_0_0 EXIST::FUNCTION: -EVP_SKEY_import 1530 4_0_0 EXIST::FUNCTION: -EVP_SKEY_generate 1531 4_0_0 EXIST::FUNCTION: -EVP_SKEY_import_raw_key 1532 4_0_0 EXIST::FUNCTION: -EVP_SKEY_import_SKEYMGMT 1533 4_0_0 EXIST::FUNCTION: -EVP_SKEY_get0_raw_key 1534 4_0_0 EXIST::FUNCTION: -EVP_SKEY_get0_key_id 1535 4_0_0 EXIST::FUNCTION: -EVP_SKEY_export 1536 4_0_0 EXIST::FUNCTION: -EVP_SKEY_up_ref 1537 4_0_0 EXIST::FUNCTION: -EVP_SKEY_free 1538 4_0_0 EXIST::FUNCTION: -EVP_SKEY_get0_skeymgmt_name 1539 4_0_0 EXIST::FUNCTION: -EVP_SKEY_get0_provider_name 1540 4_0_0 EXIST::FUNCTION: -EVP_SKEY_to_provider 1541 4_0_0 EXIST::FUNCTION: -HMAC_size 1542 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -HMAC_CTX_new 1543 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -HMAC_CTX_reset 1544 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -HMAC_CTX_free 1545 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -HMAC_Init 1546 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0 -HMAC_Init_ex 1547 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -HMAC_Update 1548 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -HMAC_Final 1549 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -HMAC_CTX_copy 1550 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -HMAC_CTX_set_flags 1551 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -HMAC_CTX_get_md 1552 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -HMAC 1553 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_CTX_new 1554 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_CTX_free 1555 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_encap 1556 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_seal 1557 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_keygen 1558 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_decap 1559 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_open 1560 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_export 1561 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_CTX_set1_authpriv 1562 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_CTX_set1_authpub 1563 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_CTX_set1_psk 1564 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_CTX_set1_ikme 1565 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_CTX_set_seq 1566 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_CTX_get_seq 1567 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_suite_check 1568 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_get_grease_value 1569 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_str2suite 1570 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_get_ciphertext_size 1571 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_get_public_encap_size 1572 4_0_0 EXIST::FUNCTION: -OSSL_HPKE_get_recommended_ikmelen 1573 4_0_0 EXIST::FUNCTION: -OSSL_parse_url 1574 4_0_0 EXIST::FUNCTION: -OSSL_HTTP_REQ_CTX_new 1575 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_REQ_CTX_free 1576 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_REQ_CTX_set_request_line 1577 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_REQ_CTX_add1_header 1578 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_REQ_CTX_set_expected 1579 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_REQ_CTX_set1_req 1580 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_REQ_CTX_nbio 1581 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_REQ_CTX_nbio_d2i 1582 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_REQ_CTX_exchange 1583 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_REQ_CTX_get0_mem_bio 1584 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_REQ_CTX_get_resp_len 1585 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_REQ_CTX_set_max_response_length 1586 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_REQ_CTX_set_max_response_hdr_lines 1587 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_is_alive 1588 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_open 1589 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_proxy_connect 1590 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_set1_request 1591 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_exchange 1592 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_get 1593 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_transfer 1594 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_close 1595 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_parse_url 1596 4_0_0 EXIST::FUNCTION:HTTP -OSSL_HTTP_adapt_proxy 1597 4_0_0 EXIST::FUNCTION:HTTP -IDEA_options 1598 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA -IDEA_ecb_encrypt 1599 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA -IDEA_set_encrypt_key 1600 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA -IDEA_set_decrypt_key 1601 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA -IDEA_cbc_encrypt 1602 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA -IDEA_cfb64_encrypt 1603 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA -IDEA_ofb64_encrypt 1604 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA -IDEA_encrypt 1605 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA -OSSL_INDICATOR_set_callback 1606 4_0_0 EXIST::FUNCTION: -OSSL_INDICATOR_get_callback 1607 4_0_0 EXIST::FUNCTION: -EVP_KDF_up_ref 1608 4_0_0 EXIST::FUNCTION: -EVP_KDF_free 1609 4_0_0 EXIST::FUNCTION: -EVP_KDF_fetch 1610 4_0_0 EXIST::FUNCTION: -EVP_KDF_CTX_new 1611 4_0_0 EXIST::FUNCTION: -EVP_KDF_CTX_free 1612 4_0_0 EXIST::FUNCTION: -EVP_KDF_CTX_dup 1613 4_0_0 EXIST::FUNCTION: -EVP_KDF_get0_description 1614 4_0_0 EXIST::FUNCTION: -EVP_KDF_is_a 1615 4_0_0 EXIST::FUNCTION: -EVP_KDF_get0_name 1616 4_0_0 EXIST::FUNCTION: -EVP_KDF_get0_provider 1617 4_0_0 EXIST::FUNCTION: -EVP_KDF_CTX_kdf 1618 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1 -EVP_KDF_CTX_reset 1619 4_0_0 EXIST::FUNCTION: -EVP_KDF_CTX_get_kdf_size 1620 4_0_0 EXIST::FUNCTION: -EVP_KDF_derive 1621 4_0_0 EXIST::FUNCTION: -EVP_KDF_CTX_set_SKEY 1622 4_0_0 EXIST::FUNCTION: -EVP_KDF_derive_SKEY 1623 4_0_0 EXIST::FUNCTION: -EVP_KDF_get_params 1624 4_0_0 EXIST::FUNCTION: -EVP_KDF_CTX_get_params 1625 4_0_0 EXIST::FUNCTION: -EVP_KDF_CTX_set_params 1626 4_0_0 EXIST::FUNCTION: -EVP_KDF_gettable_params 1627 4_0_0 EXIST::FUNCTION: -EVP_KDF_gettable_ctx_params 1628 4_0_0 EXIST::FUNCTION: -EVP_KDF_settable_ctx_params 1629 4_0_0 EXIST::FUNCTION: -EVP_KDF_CTX_gettable_params 1630 4_0_0 EXIST::FUNCTION: -EVP_KDF_CTX_settable_params 1631 4_0_0 EXIST::FUNCTION: -EVP_KDF_do_all_provided 1632 4_0_0 EXIST::FUNCTION: -EVP_KDF_names_do_all 1633 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_tls1_prf_md 1634 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set1_tls1_prf_secret 1635 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_add1_tls1_prf_seed 1636 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_hkdf_md 1637 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set1_hkdf_salt 1638 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set1_hkdf_key 1639 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_add1_hkdf_info 1640 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_hkdf_mode 1641 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set1_pbe_pass 1642 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set1_scrypt_salt 1643 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_scrypt_N 1644 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_scrypt_r 1645 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_scrypt_p 1646 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_scrypt_maxmem_bytes 1647 4_0_0 EXIST::FUNCTION: -MD2_options 1648 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD2 -MD2_Init 1649 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD2 -MD2_Update 1650 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD2 -MD2_Final 1651 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD2 -MD2 1652 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD2 -MD4_Init 1653 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD4 -MD4_Update 1654 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD4 -MD4_Final 1655 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD4 -MD4 1656 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD4 -MD4_Transform 1657 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD4 -MD5_Init 1658 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD5 -MD5_Update 1659 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD5 -MD5_Final 1660 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD5 -MD5 1661 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD5 -MD5_Transform 1662 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD5 -MDC2_Init 1663 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MDC2 -MDC2_Update 1664 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MDC2 -MDC2_Final 1665 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MDC2 -MDC2 1666 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MDC2 -CRYPTO_cbc128_encrypt 1667 4_0_0 EXIST::FUNCTION: -CRYPTO_cbc128_decrypt 1668 4_0_0 EXIST::FUNCTION: -CRYPTO_ctr128_encrypt 1669 4_0_0 EXIST::FUNCTION: -CRYPTO_ctr128_encrypt_ctr32 1670 4_0_0 EXIST::FUNCTION: -CRYPTO_ofb128_encrypt 1671 4_0_0 EXIST::FUNCTION: -CRYPTO_cfb128_encrypt 1672 4_0_0 EXIST::FUNCTION: -CRYPTO_cfb128_8_encrypt 1673 4_0_0 EXIST::FUNCTION: -CRYPTO_cfb128_1_encrypt 1674 4_0_0 EXIST::FUNCTION: -CRYPTO_cts128_encrypt_block 1675 4_0_0 EXIST::FUNCTION: -CRYPTO_cts128_encrypt 1676 4_0_0 EXIST::FUNCTION: -CRYPTO_cts128_decrypt_block 1677 4_0_0 EXIST::FUNCTION: -CRYPTO_cts128_decrypt 1678 4_0_0 EXIST::FUNCTION: -CRYPTO_nistcts128_encrypt_block 1679 4_0_0 EXIST::FUNCTION: -CRYPTO_nistcts128_encrypt 1680 4_0_0 EXIST::FUNCTION: -CRYPTO_nistcts128_decrypt_block 1681 4_0_0 EXIST::FUNCTION: -CRYPTO_nistcts128_decrypt 1682 4_0_0 EXIST::FUNCTION: -CRYPTO_gcm128_new 1683 4_0_0 EXIST::FUNCTION: -CRYPTO_gcm128_init 1684 4_0_0 EXIST::FUNCTION: -CRYPTO_gcm128_setiv 1685 4_0_0 EXIST::FUNCTION: -CRYPTO_gcm128_aad 1686 4_0_0 EXIST::FUNCTION: -CRYPTO_gcm128_encrypt 1687 4_0_0 EXIST::FUNCTION: -CRYPTO_gcm128_decrypt 1688 4_0_0 EXIST::FUNCTION: -CRYPTO_gcm128_encrypt_ctr32 1689 4_0_0 EXIST::FUNCTION: -CRYPTO_gcm128_decrypt_ctr32 1690 4_0_0 EXIST::FUNCTION: -CRYPTO_gcm128_finish 1691 4_0_0 EXIST::FUNCTION: -CRYPTO_gcm128_tag 1692 4_0_0 EXIST::FUNCTION: -CRYPTO_gcm128_release 1693 4_0_0 EXIST::FUNCTION: -CRYPTO_ccm128_init 1694 4_0_0 EXIST::FUNCTION: -CRYPTO_ccm128_setiv 1695 4_0_0 EXIST::FUNCTION: -CRYPTO_ccm128_aad 1696 4_0_0 EXIST::FUNCTION: -CRYPTO_ccm128_encrypt 1697 4_0_0 EXIST::FUNCTION: -CRYPTO_ccm128_decrypt 1698 4_0_0 EXIST::FUNCTION: -CRYPTO_ccm128_encrypt_ccm64 1699 4_0_0 EXIST::FUNCTION: -CRYPTO_ccm128_decrypt_ccm64 1700 4_0_0 EXIST::FUNCTION: -CRYPTO_ccm128_tag 1701 4_0_0 EXIST::FUNCTION: -CRYPTO_xts128_encrypt 1702 4_0_0 EXIST::FUNCTION: -CRYPTO_128_wrap 1703 4_0_0 EXIST::FUNCTION: -CRYPTO_128_unwrap 1704 4_0_0 EXIST::FUNCTION: -CRYPTO_128_wrap_pad 1705 4_0_0 EXIST::FUNCTION: -CRYPTO_128_unwrap_pad 1706 4_0_0 EXIST::FUNCTION: -CRYPTO_ocb128_new 1707 4_0_0 EXIST::FUNCTION:OCB -CRYPTO_ocb128_init 1708 4_0_0 EXIST::FUNCTION:OCB -CRYPTO_ocb128_copy_ctx 1709 4_0_0 EXIST::FUNCTION:OCB -CRYPTO_ocb128_setiv 1710 4_0_0 EXIST::FUNCTION:OCB -CRYPTO_ocb128_aad 1711 4_0_0 EXIST::FUNCTION:OCB -CRYPTO_ocb128_encrypt 1712 4_0_0 EXIST::FUNCTION:OCB -CRYPTO_ocb128_decrypt 1713 4_0_0 EXIST::FUNCTION:OCB -CRYPTO_ocb128_finish 1714 4_0_0 EXIST::FUNCTION:OCB -CRYPTO_ocb128_tag 1715 4_0_0 EXIST::FUNCTION:OCB -CRYPTO_ocb128_cleanup 1716 4_0_0 EXIST::FUNCTION:OCB -OBJ_NAME_init 1717 4_0_0 EXIST::FUNCTION: -OBJ_NAME_new_index 1718 4_0_0 EXIST::FUNCTION: -OBJ_NAME_get 1719 4_0_0 EXIST::FUNCTION: -OBJ_NAME_add 1720 4_0_0 EXIST::FUNCTION: -OBJ_NAME_remove 1721 4_0_0 EXIST::FUNCTION: -OBJ_NAME_cleanup 1722 4_0_0 EXIST::FUNCTION: -OBJ_NAME_do_all 1723 4_0_0 EXIST::FUNCTION: -OBJ_NAME_do_all_sorted 1724 4_0_0 EXIST::FUNCTION: -OBJ_dup 1725 4_0_0 EXIST::FUNCTION: -OBJ_nid2obj 1726 4_0_0 EXIST::FUNCTION: -OBJ_nid2ln 1727 4_0_0 EXIST::FUNCTION: -OBJ_nid2sn 1728 4_0_0 EXIST::FUNCTION: -OBJ_obj2nid 1729 4_0_0 EXIST::FUNCTION: -OBJ_txt2obj 1730 4_0_0 EXIST::FUNCTION: -OBJ_obj2txt 1731 4_0_0 EXIST::FUNCTION: -OBJ_txt2nid 1732 4_0_0 EXIST::FUNCTION: -OBJ_ln2nid 1733 4_0_0 EXIST::FUNCTION: -OBJ_sn2nid 1734 4_0_0 EXIST::FUNCTION: -OBJ_cmp 1735 4_0_0 EXIST::FUNCTION: -OBJ_bsearch_ 1736 4_0_0 EXIST::FUNCTION: -OBJ_bsearch_ex_ 1737 4_0_0 EXIST::FUNCTION: -OBJ_new_nid 1738 4_0_0 EXIST::FUNCTION: -OBJ_add_object 1739 4_0_0 EXIST::FUNCTION: -OBJ_create 1740 4_0_0 EXIST::FUNCTION: -OBJ_create_objects 1741 4_0_0 EXIST::FUNCTION: -OBJ_length 1742 4_0_0 EXIST::FUNCTION: -OBJ_get0_data 1743 4_0_0 EXIST::FUNCTION: -OBJ_find_sigid_algs 1744 4_0_0 EXIST::FUNCTION: -OBJ_find_sigid_by_algs 1745 4_0_0 EXIST::FUNCTION: -OBJ_add_sigid 1746 4_0_0 EXIST::FUNCTION: -OBJ_sigid_free 1747 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_new 1748 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_to_param 1749 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_free 1750 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_int 1751 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_uint 1752 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_long 1753 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_ulong 1754 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_int32 1755 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_uint32 1756 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_int64 1757 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_uint64 1758 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_size_t 1759 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_time_t 1760 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_double 1761 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_BN 1762 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_BN_pad 1763 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_utf8_string 1764 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_utf8_ptr 1765 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_octet_string 1766 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_BLD_push_octet_ptr 1767 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_locate 1768 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_locate_const 1769 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_int 1770 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_uint 1771 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_long 1772 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_ulong 1773 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_int32 1774 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_uint32 1775 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_int64 1776 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_uint64 1777 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_size_t 1778 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_time_t 1779 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_BN 1780 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_double 1781 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_utf8_string 1782 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_utf8_ptr 1783 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_octet_string 1784 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_octet_ptr 1785 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_construct_end 1786 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_allocate_from_text 1787 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_print_to_bio 1788 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_int 1789 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_uint 1790 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_long 1791 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_ulong 1792 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_int32 1793 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_uint32 1794 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_int64 1795 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_uint64 1796 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_size_t 1797 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_time_t 1798 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_int 1799 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_uint 1800 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_long 1801 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_ulong 1802 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_int32 1803 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_uint32 1804 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_int64 1805 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_uint64 1806 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_size_t 1807 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_time_t 1808 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_double 1809 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_double 1810 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_BN 1811 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_BN 1812 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_utf8_string 1813 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_utf8_string 1814 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_octet_string 1815 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_octet_string 1816 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_utf8_ptr 1817 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_utf8_ptr 1818 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_octet_ptr 1819 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_octet_ptr 1820 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_utf8_string_ptr 1821 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_get_octet_string_ptr 1822 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_modified 1823 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_all_unmodified 1824 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_dup 1825 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_merge 1826 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_free 1827 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_set_octet_string_or_ptr 1828 4_0_0 EXIST::FUNCTION: -PEM_get_EVP_CIPHER_INFO 1829 4_0_0 EXIST::FUNCTION: -PEM_do_header 1830 4_0_0 EXIST::FUNCTION: -PEM_read_bio 1831 4_0_0 EXIST::FUNCTION: -PEM_read_bio_ex 1832 4_0_0 EXIST::FUNCTION: -PEM_bytes_read_bio_secmem 1833 4_0_0 EXIST::FUNCTION: -PEM_write_bio 1834 4_0_0 EXIST::FUNCTION: -PEM_bytes_read_bio 1835 4_0_0 EXIST::FUNCTION: -PEM_ASN1_read_bio 1836 4_0_0 EXIST::FUNCTION: -PEM_ASN1_write_bio 1837 4_0_0 EXIST::FUNCTION: -PEM_ASN1_write_bio_ctx 1838 4_0_0 EXIST::FUNCTION: -PEM_X509_INFO_read_bio 1839 4_0_0 EXIST::FUNCTION: -PEM_X509_INFO_read_bio_ex 1840 4_0_0 EXIST::FUNCTION: -PEM_X509_INFO_write_bio 1841 4_0_0 EXIST::FUNCTION: -PEM_read 1842 4_0_0 EXIST::FUNCTION:STDIO -PEM_write 1843 4_0_0 EXIST::FUNCTION:STDIO -PEM_ASN1_read 1844 4_0_0 EXIST::FUNCTION:STDIO -PEM_ASN1_write 1845 4_0_0 EXIST::FUNCTION:STDIO -PEM_X509_INFO_read 1846 4_0_0 EXIST::FUNCTION:STDIO -PEM_X509_INFO_read_ex 1847 4_0_0 EXIST::FUNCTION:STDIO -PEM_SignInit 1848 4_0_0 EXIST::FUNCTION: -PEM_SignUpdate 1849 4_0_0 EXIST::FUNCTION: -PEM_SignFinal 1850 4_0_0 EXIST::FUNCTION: -PEM_def_callback 1851 4_0_0 EXIST::FUNCTION: -PEM_proc_type 1852 4_0_0 EXIST::FUNCTION: -PEM_dek_info 1853 4_0_0 EXIST::FUNCTION: -PEM_read_X509 1854 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_X509 1855 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_bio_X509 1856 4_0_0 EXIST::FUNCTION: -PEM_write_bio_X509 1857 4_0_0 EXIST::FUNCTION: -PEM_read_X509_AUX 1858 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_X509_AUX 1859 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_bio_X509_AUX 1860 4_0_0 EXIST::FUNCTION: -PEM_write_bio_X509_AUX 1861 4_0_0 EXIST::FUNCTION: -PEM_read_X509_REQ 1862 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_X509_REQ 1863 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_bio_X509_REQ 1864 4_0_0 EXIST::FUNCTION: -PEM_write_bio_X509_REQ 1865 4_0_0 EXIST::FUNCTION: -PEM_write_X509_REQ_NEW 1866 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_bio_X509_REQ_NEW 1867 4_0_0 EXIST::FUNCTION: -PEM_read_X509_CRL 1868 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_X509_CRL 1869 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_bio_X509_CRL 1870 4_0_0 EXIST::FUNCTION: -PEM_write_bio_X509_CRL 1871 4_0_0 EXIST::FUNCTION: -PEM_read_X509_PUBKEY 1872 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_X509_PUBKEY 1873 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_bio_X509_PUBKEY 1874 4_0_0 EXIST::FUNCTION: -PEM_write_bio_X509_PUBKEY 1875 4_0_0 EXIST::FUNCTION: -PEM_read_PKCS7 1876 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_PKCS7 1877 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_bio_PKCS7 1878 4_0_0 EXIST::FUNCTION: -PEM_write_bio_PKCS7 1879 4_0_0 EXIST::FUNCTION: -PEM_read_NETSCAPE_CERT_SEQUENCE 1880 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_NETSCAPE_CERT_SEQUENCE 1881 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_bio_NETSCAPE_CERT_SEQUENCE 1882 4_0_0 EXIST::FUNCTION: -PEM_write_bio_NETSCAPE_CERT_SEQUENCE 1883 4_0_0 EXIST::FUNCTION: -PEM_read_PKCS8 1884 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_PKCS8 1885 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_bio_PKCS8 1886 4_0_0 EXIST::FUNCTION: -PEM_write_bio_PKCS8 1887 4_0_0 EXIST::FUNCTION: -PEM_read_PKCS8_PRIV_KEY_INFO 1888 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_PKCS8_PRIV_KEY_INFO 1889 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_bio_PKCS8_PRIV_KEY_INFO 1890 4_0_0 EXIST::FUNCTION: -PEM_write_bio_PKCS8_PRIV_KEY_INFO 1891 4_0_0 EXIST::FUNCTION: -PEM_read_RSAPrivateKey 1892 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO -PEM_write_RSAPrivateKey 1893 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO -PEM_read_bio_RSAPrivateKey 1894 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -PEM_write_bio_RSAPrivateKey 1895 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -PEM_read_RSAPublicKey 1896 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO -PEM_write_RSAPublicKey 1897 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO -PEM_read_bio_RSAPublicKey 1898 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -PEM_write_bio_RSAPublicKey 1899 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -PEM_read_RSA_PUBKEY 1900 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO -PEM_write_RSA_PUBKEY 1901 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO -PEM_read_bio_RSA_PUBKEY 1902 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -PEM_write_bio_RSA_PUBKEY 1903 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -PEM_read_DSAPrivateKey 1904 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO -PEM_write_DSAPrivateKey 1905 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO -PEM_read_bio_DSAPrivateKey 1906 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -PEM_write_bio_DSAPrivateKey 1907 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -PEM_read_DSA_PUBKEY 1908 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO -PEM_write_DSA_PUBKEY 1909 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO -PEM_read_bio_DSA_PUBKEY 1910 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -PEM_write_bio_DSA_PUBKEY 1911 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -PEM_read_DSAparams 1912 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO -PEM_write_DSAparams 1913 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO -PEM_read_bio_DSAparams 1914 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -PEM_write_bio_DSAparams 1915 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -PEM_read_ECPKParameters 1916 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO -PEM_write_ECPKParameters 1917 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO -PEM_read_bio_ECPKParameters 1918 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -PEM_write_bio_ECPKParameters 1919 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -PEM_read_ECPrivateKey 1920 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO -PEM_write_ECPrivateKey 1921 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO -PEM_read_bio_ECPrivateKey 1922 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -PEM_write_bio_ECPrivateKey 1923 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -PEM_read_EC_PUBKEY 1924 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO -PEM_write_EC_PUBKEY 1925 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO -PEM_read_bio_EC_PUBKEY 1926 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -PEM_write_bio_EC_PUBKEY 1927 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -PEM_read_DHparams 1928 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH,STDIO -PEM_write_DHparams 1929 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH,STDIO -PEM_read_bio_DHparams 1930 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -PEM_write_bio_DHparams 1931 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -PEM_write_DHxparams 1932 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH,STDIO -PEM_write_bio_DHxparams 1933 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -PEM_read_PrivateKey 1934 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_PrivateKey 1935 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_PrivateKey_ex 1936 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_PrivateKey_ex 1937 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_bio_PrivateKey 1938 4_0_0 EXIST::FUNCTION: -PEM_write_bio_PrivateKey 1939 4_0_0 EXIST::FUNCTION: -PEM_read_bio_PrivateKey_ex 1940 4_0_0 EXIST::FUNCTION: -PEM_write_bio_PrivateKey_ex 1941 4_0_0 EXIST::FUNCTION: -PEM_read_PUBKEY 1942 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_PUBKEY 1943 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_PUBKEY_ex 1944 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_PUBKEY_ex 1945 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_bio_PUBKEY 1946 4_0_0 EXIST::FUNCTION: -PEM_write_bio_PUBKEY 1947 4_0_0 EXIST::FUNCTION: -PEM_read_bio_PUBKEY_ex 1948 4_0_0 EXIST::FUNCTION: -PEM_write_bio_PUBKEY_ex 1949 4_0_0 EXIST::FUNCTION: -PEM_write_bio_PrivateKey_traditional 1950 4_0_0 EXIST::FUNCTION: -PEM_write_bio_PKCS8PrivateKey_nid 1951 4_0_0 EXIST::FUNCTION: -PEM_write_bio_PKCS8PrivateKey 1952 4_0_0 EXIST::FUNCTION: -i2d_PKCS8PrivateKey_bio 1953 4_0_0 EXIST::FUNCTION: -i2d_PKCS8PrivateKey_nid_bio 1954 4_0_0 EXIST::FUNCTION: -d2i_PKCS8PrivateKey_bio 1955 4_0_0 EXIST::FUNCTION: -i2d_PKCS8PrivateKey_fp 1956 4_0_0 EXIST::FUNCTION:STDIO -i2d_PKCS8PrivateKey_nid_fp 1957 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_PKCS8PrivateKey_nid 1958 4_0_0 EXIST::FUNCTION:STDIO -d2i_PKCS8PrivateKey_fp 1959 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_PKCS8PrivateKey 1960 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_bio_Parameters_ex 1961 4_0_0 EXIST::FUNCTION: -PEM_read_bio_Parameters 1962 4_0_0 EXIST::FUNCTION: -PEM_write_bio_Parameters 1963 4_0_0 EXIST::FUNCTION: -b2i_PrivateKey 1964 4_0_0 EXIST::FUNCTION: -b2i_PublicKey 1965 4_0_0 EXIST::FUNCTION: -b2i_PrivateKey_bio 1966 4_0_0 EXIST::FUNCTION: -b2i_PublicKey_bio 1967 4_0_0 EXIST::FUNCTION: -i2b_PrivateKey_bio 1968 4_0_0 EXIST::FUNCTION: -i2b_PublicKey_bio 1969 4_0_0 EXIST::FUNCTION: -b2i_PVK_bio 1970 4_0_0 EXIST::FUNCTION: -b2i_PVK_bio_ex 1971 4_0_0 EXIST::FUNCTION: -i2b_PVK_bio 1972 4_0_0 EXIST::FUNCTION: -i2b_PVK_bio_ex 1973 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_set_default_search_path 1974 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_get0_default_search_path 1975 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_load 1976 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_load_ex 1977 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_try_load 1978 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_try_load_ex 1979 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_unload 1980 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_available 1981 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_do_all 1982 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_gettable_params 1983 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_get_params 1984 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_self_test 1985 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_get_capabilities 1986 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_add_conf_parameter 1987 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_get_conf_parameters 1988 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_conf_get_bool 1989 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_query_operation 1990 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_unquery_operation 1991 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_get0_provider_ctx 1992 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_get0_dispatch 1993 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_add_builtin 1994 4_0_0 EXIST::FUNCTION: -OSSL_PROVIDER_get0_name 1995 4_0_0 EXIST::FUNCTION: -RAND_set_rand_method 1996 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RAND_get_rand_method 1997 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RAND_OpenSSL 1998 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RAND_bytes 1999 4_0_0 EXIST::FUNCTION: -RAND_priv_bytes 2000 4_0_0 EXIST::FUNCTION: -RAND_priv_bytes_ex 2001 4_0_0 EXIST::FUNCTION: -RAND_bytes_ex 2002 4_0_0 EXIST::FUNCTION: -RAND_pseudo_bytes 2003 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0 -RAND_get0_primary 2004 4_0_0 EXIST::FUNCTION: -RAND_get0_public 2005 4_0_0 EXIST::FUNCTION: -RAND_get0_private 2006 4_0_0 EXIST::FUNCTION: -RAND_set0_public 2007 4_0_0 EXIST::FUNCTION: -RAND_set0_private 2008 4_0_0 EXIST::FUNCTION: -RAND_set_DRBG_type 2009 4_0_0 EXIST::FUNCTION: -RAND_set_seed_source_type 2010 4_0_0 EXIST::FUNCTION: -RAND_seed 2011 4_0_0 EXIST::FUNCTION: -RAND_keep_random_devices_open 2012 4_0_0 EXIST::FUNCTION: -RAND_add 2013 4_0_0 EXIST::FUNCTION: -RAND_load_file 2014 4_0_0 EXIST::FUNCTION: -RAND_write_file 2015 4_0_0 EXIST::FUNCTION: -RAND_file_name 2016 4_0_0 EXIST::FUNCTION: -RAND_status 2017 4_0_0 EXIST::FUNCTION: -RAND_query_egd_bytes 2018 4_0_0 EXIST::FUNCTION:EGD -RAND_egd 2019 4_0_0 EXIST::FUNCTION:EGD -RAND_egd_bytes 2020 4_0_0 EXIST::FUNCTION:EGD -RAND_poll 2021 4_0_0 EXIST::FUNCTION: -RAND_screen 2022 4_0_0 EXIST:_WIN32:FUNCTION:DEPRECATEDIN_1_1_0 -RAND_event 2023 4_0_0 EXIST:_WIN32:FUNCTION:DEPRECATEDIN_1_1_0 -RAND_set1_random_provider 2024 4_0_0 EXIST::FUNCTION: -RC2_set_key 2025 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC2 -RC2_ecb_encrypt 2026 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC2 -RC2_encrypt 2027 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC2 -RC2_decrypt 2028 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC2 -RC2_cbc_encrypt 2029 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC2 -RC2_cfb64_encrypt 2030 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC2 -RC2_ofb64_encrypt 2031 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC2 -RC4_options 2032 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC4 -RC4_set_key 2033 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC4 -RC4 2034 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC4 -RC5_32_set_key 2035 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC5 -RC5_32_ecb_encrypt 2036 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC5 -RC5_32_encrypt 2037 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC5 -RC5_32_decrypt 2038 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC5 -RC5_32_cbc_encrypt 2039 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC5 -RC5_32_cfb64_encrypt 2040 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC5 -RC5_32_ofb64_encrypt 2041 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC5 -RIPEMD160_Init 2042 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RMD160 -RIPEMD160_Update 2043 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RMD160 -RIPEMD160_Final 2044 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RMD160 -RIPEMD160 2045 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RMD160 -RIPEMD160_Transform 2046 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RMD160 -EVP_PKEY_CTX_set_rsa_padding 2047 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_rsa_padding 2048 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_rsa_pss_saltlen 2049 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_rsa_pss_saltlen 2050 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_rsa_keygen_bits 2051 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set1_rsa_keygen_pubexp 2052 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_rsa_keygen_primes 2053 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_rsa_pss_keygen_saltlen 2054 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_rsa_keygen_pubexp 2055 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -EVP_PKEY_CTX_set_rsa_mgf1_md 2056 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_rsa_mgf1_md_name 2057 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_rsa_mgf1_md 2058 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_rsa_mgf1_md_name 2059 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md 2060 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md_name 2061 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_rsa_pss_keygen_md 2062 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_rsa_pss_keygen_md_name 2063 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_rsa_oaep_md 2064 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set_rsa_oaep_md_name 2065 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_rsa_oaep_md 2066 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get_rsa_oaep_md_name 2067 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_set0_rsa_oaep_label 2068 4_0_0 EXIST::FUNCTION: -EVP_PKEY_CTX_get0_rsa_oaep_label 2069 4_0_0 EXIST::FUNCTION: -RSA_new 2070 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_new_method 2071 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_bits 2072 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_size 2073 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_security_bits 2074 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_set0_key 2075 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_set0_factors 2076 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_set0_crt_params 2077 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_set0_multi_prime_params 2078 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get0_key 2079 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get0_factors 2080 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get_multi_prime_extra_count 2081 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get0_multi_prime_factors 2082 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get0_crt_params 2083 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get0_multi_prime_crt_params 2084 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get0_n 2085 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get0_e 2086 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get0_d 2087 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get0_p 2088 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get0_q 2089 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get0_dmp1 2090 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get0_dmq1 2091 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get0_iqmp 2092 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get0_pss_params 2093 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_clear_flags 2094 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_test_flags 2095 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_set_flags 2096 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get_version 2097 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_generate_key 2098 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8 -RSA_generate_key_ex 2099 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_generate_multi_prime_key 2100 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_X931_derive_ex 2101 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_X931_generate_key_ex 2102 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_check_key 2103 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_check_key_ex 2104 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_public_encrypt 2105 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_private_encrypt 2106 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_public_decrypt 2107 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_private_decrypt 2108 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_free 2109 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_up_ref 2110 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_flags 2111 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_set_default_method 2112 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get_default_method 2113 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_null_method 2114 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get_method 2115 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_set_method 2116 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_PKCS1_OpenSSL 2117 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -d2i_RSAPublicKey 2118 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -i2d_RSAPublicKey 2119 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSAPublicKey_it 2120 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -d2i_RSAPrivateKey 2121 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -i2d_RSAPrivateKey 2122 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSAPrivateKey_it 2123 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_pkey_ctx_ctrl 2124 4_0_0 EXIST::FUNCTION: -d2i_RSA_PSS_PARAMS 2125 4_0_0 EXIST::FUNCTION: -i2d_RSA_PSS_PARAMS 2126 4_0_0 EXIST::FUNCTION: -RSA_PSS_PARAMS_free 2127 4_0_0 EXIST::FUNCTION: -RSA_PSS_PARAMS_new 2128 4_0_0 EXIST::FUNCTION: -RSA_PSS_PARAMS_it 2129 4_0_0 EXIST::FUNCTION: -RSA_PSS_PARAMS_dup 2130 4_0_0 EXIST::FUNCTION: -d2i_RSA_OAEP_PARAMS 2131 4_0_0 EXIST::FUNCTION: -i2d_RSA_OAEP_PARAMS 2132 4_0_0 EXIST::FUNCTION: -RSA_OAEP_PARAMS_free 2133 4_0_0 EXIST::FUNCTION: -RSA_OAEP_PARAMS_new 2134 4_0_0 EXIST::FUNCTION: -RSA_OAEP_PARAMS_it 2135 4_0_0 EXIST::FUNCTION: -RSA_print_fp 2136 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO -RSA_print 2137 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_sign 2138 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_verify 2139 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_sign_ASN1_OCTET_STRING 2140 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_verify_ASN1_OCTET_STRING 2141 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_blinding_on 2142 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_blinding_off 2143 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_setup_blinding 2144 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_padding_add_PKCS1_type_1 2145 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_padding_check_PKCS1_type_1 2146 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_padding_add_PKCS1_type_2 2147 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_padding_check_PKCS1_type_2 2148 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -PKCS1_MGF1 2149 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_padding_add_PKCS1_OAEP 2150 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_padding_check_PKCS1_OAEP 2151 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_padding_add_PKCS1_OAEP_mgf1 2152 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_padding_check_PKCS1_OAEP_mgf1 2153 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_padding_add_none 2154 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_padding_check_none 2155 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_padding_add_X931 2156 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_padding_check_X931 2157 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_X931_hash_id 2158 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_verify_PKCS1_PSS 2159 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_padding_add_PKCS1_PSS 2160 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_verify_PKCS1_PSS_mgf1 2161 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_padding_add_PKCS1_PSS_mgf1 2162 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_set_ex_data 2163 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_get_ex_data 2164 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSAPublicKey_dup 2165 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSAPrivateKey_dup 2166 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_new 2167 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_free 2168 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_dup 2169 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_get0_name 2170 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_set1_name 2171 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_get_flags 2172 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_set_flags 2173 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_get0_app_data 2174 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_set0_app_data 2175 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_get_pub_enc 2176 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_set_pub_enc 2177 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_get_pub_dec 2178 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_set_pub_dec 2179 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_get_priv_enc 2180 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_set_priv_enc 2181 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_get_priv_dec 2182 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_set_priv_dec 2183 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_get_mod_exp 2184 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_set_mod_exp 2185 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_get_bn_mod_exp 2186 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_set_bn_mod_exp 2187 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_get_init 2188 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_set_init 2189 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_get_finish 2190 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_set_finish 2191 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_get_sign 2192 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_set_sign 2193 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_get_verify 2194 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_set_verify 2195 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_get_keygen 2196 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_set_keygen 2197 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_get_multi_prime_keygen 2198 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -RSA_meth_set_multi_prime_keygen 2199 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SEED_set_key 2200 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SEED -SEED_encrypt 2201 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SEED -SEED_decrypt 2202 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SEED -SEED_ecb_encrypt 2203 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SEED -SEED_cbc_encrypt 2204 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SEED -SEED_cfb128_encrypt 2205 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SEED -SEED_ofb128_encrypt 2206 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SEED -OSSL_SELF_TEST_set_callback 2207 4_0_0 EXIST::FUNCTION: -OSSL_SELF_TEST_get_callback 2208 4_0_0 EXIST::FUNCTION: -OSSL_SELF_TEST_new 2209 4_0_0 EXIST::FUNCTION: -OSSL_SELF_TEST_free 2210 4_0_0 EXIST::FUNCTION: -OSSL_SELF_TEST_onbegin 2211 4_0_0 EXIST::FUNCTION: -OSSL_SELF_TEST_oncorrupt_byte 2212 4_0_0 EXIST::FUNCTION: -OSSL_SELF_TEST_onend 2213 4_0_0 EXIST::FUNCTION: -SHA1_Init 2214 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA1_Update 2215 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA1_Final 2216 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA1_Transform 2217 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA1 2218 4_0_0 EXIST::FUNCTION: -SHA224_Init 2219 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA224_Update 2220 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA224_Final 2221 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA256_Init 2222 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA256_Update 2223 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA256_Final 2224 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA256_Transform 2225 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA224 2226 4_0_0 EXIST::FUNCTION: -SHA256 2227 4_0_0 EXIST::FUNCTION: -SHA384_Init 2228 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA384_Update 2229 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA384_Final 2230 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA512_Init 2231 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA512_Update 2232 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA512_Final 2233 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA512_Transform 2234 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SHA384 2235 4_0_0 EXIST::FUNCTION: -SHA512 2236 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_num 2237 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_value 2238 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_set 2239 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_new 2240 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_new_null 2241 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_new_reserve 2242 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_set_thunks 2243 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_reserve 2244 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_free 2245 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_pop_free 2246 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_deep_copy 2247 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_insert 2248 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_delete 2249 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_delete_ptr 2250 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_find 2251 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_find_ex 2252 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_find_all 2253 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_push 2254 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_unshift 2255 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_shift 2256 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_pop 2257 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_zero 2258 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_set_cmp_func 2259 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_dup 2260 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_sort 2261 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_is_sorted 2262 4_0_0 EXIST::FUNCTION: -OSSL_STORE_open 2263 4_0_0 EXIST::FUNCTION: -OSSL_STORE_open_ex 2264 4_0_0 EXIST::FUNCTION: -OSSL_STORE_ctrl 2265 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_vctrl 2266 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_load 2267 4_0_0 EXIST::FUNCTION: -OSSL_STORE_delete 2268 4_0_0 EXIST::FUNCTION: -OSSL_STORE_eof 2269 4_0_0 EXIST::FUNCTION: -OSSL_STORE_error 2270 4_0_0 EXIST::FUNCTION: -OSSL_STORE_close 2271 4_0_0 EXIST::FUNCTION: -OSSL_STORE_attach 2272 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_new 2273 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_new_NAME 2274 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_set0_NAME_description 2275 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_new_PARAMS 2276 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_new_PUBKEY 2277 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_new_PKEY 2278 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_new_CERT 2279 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_new_CRL 2280 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get_type 2281 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get0_data 2282 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get0_NAME 2283 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get1_NAME 2284 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get0_NAME_description 2285 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get1_NAME_description 2286 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get0_PARAMS 2287 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get1_PARAMS 2288 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get0_PUBKEY 2289 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get1_PUBKEY 2290 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get0_PKEY 2291 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get1_PKEY 2292 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get0_CERT 2293 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get1_CERT 2294 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get0_CRL 2295 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get1_CRL 2296 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_type_string 2297 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_free 2298 4_0_0 EXIST::FUNCTION: -OSSL_STORE_supports_search 2299 4_0_0 EXIST::FUNCTION: -OSSL_STORE_SEARCH_by_name 2300 4_0_0 EXIST::FUNCTION: -OSSL_STORE_SEARCH_by_issuer_serial 2301 4_0_0 EXIST::FUNCTION: -OSSL_STORE_SEARCH_by_key_fingerprint 2302 4_0_0 EXIST::FUNCTION: -OSSL_STORE_SEARCH_by_alias 2303 4_0_0 EXIST::FUNCTION: -OSSL_STORE_SEARCH_free 2304 4_0_0 EXIST::FUNCTION: -OSSL_STORE_SEARCH_get_type 2305 4_0_0 EXIST::FUNCTION: -OSSL_STORE_SEARCH_get0_name 2306 4_0_0 EXIST::FUNCTION: -OSSL_STORE_SEARCH_get0_serial 2307 4_0_0 EXIST::FUNCTION: -OSSL_STORE_SEARCH_get0_bytes 2308 4_0_0 EXIST::FUNCTION: -OSSL_STORE_SEARCH_get0_string 2309 4_0_0 EXIST::FUNCTION: -OSSL_STORE_SEARCH_get0_digest 2310 4_0_0 EXIST::FUNCTION: -OSSL_STORE_expect 2311 4_0_0 EXIST::FUNCTION: -OSSL_STORE_find 2312 4_0_0 EXIST::FUNCTION: -OSSL_STORE_LOADER_fetch 2313 4_0_0 EXIST::FUNCTION: -OSSL_STORE_LOADER_up_ref 2314 4_0_0 EXIST::FUNCTION: -OSSL_STORE_LOADER_free 2315 4_0_0 EXIST::FUNCTION: -OSSL_STORE_LOADER_get0_provider 2316 4_0_0 EXIST::FUNCTION: -OSSL_STORE_LOADER_get0_properties 2317 4_0_0 EXIST::FUNCTION: -OSSL_STORE_LOADER_get0_description 2318 4_0_0 EXIST::FUNCTION: -OSSL_STORE_LOADER_is_a 2319 4_0_0 EXIST::FUNCTION: -OSSL_STORE_LOADER_do_all_provided 2320 4_0_0 EXIST::FUNCTION: -OSSL_STORE_LOADER_names_do_all 2321 4_0_0 EXIST::FUNCTION: -OSSL_STORE_LOADER_settable_ctx_params 2322 4_0_0 EXIST::FUNCTION: -OSSL_STORE_LOADER_new 2323 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_LOADER_set_open 2324 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_LOADER_set_open_ex 2325 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_LOADER_set_attach 2326 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_LOADER_set_ctrl 2327 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_LOADER_set_expect 2328 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_LOADER_set_find 2329 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_LOADER_set_load 2330 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_LOADER_set_eof 2331 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_LOADER_set_error 2332 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_LOADER_set_close 2333 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_LOADER_get0_scheme 2334 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_register_loader 2335 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_unregister_loader 2336 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_STORE_do_all_loaders 2337 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -OSSL_get_thread_support_flags 2338 4_0_0 EXIST::FUNCTION: -OSSL_set_max_threads 2339 4_0_0 EXIST::FUNCTION: -OSSL_get_max_threads 2340 4_0_0 EXIST::FUNCTION: -OSSL_trace_get_category_num 2341 4_0_0 EXIST::FUNCTION: -OSSL_trace_get_category_name 2342 4_0_0 EXIST::FUNCTION: -OSSL_trace_set_channel 2343 4_0_0 EXIST::FUNCTION: -OSSL_trace_set_prefix 2344 4_0_0 EXIST::FUNCTION: -OSSL_trace_set_suffix 2345 4_0_0 EXIST::FUNCTION: -OSSL_trace_set_callback 2346 4_0_0 EXIST::FUNCTION: -OSSL_trace_enabled 2347 4_0_0 EXIST::FUNCTION: -OSSL_trace_begin 2348 4_0_0 EXIST::FUNCTION: -OSSL_trace_end 2349 4_0_0 EXIST::FUNCTION: -OSSL_trace_string 2350 4_0_0 EXIST::FUNCTION: -TS_REQ_free 2351 4_0_0 EXIST::FUNCTION:TS -TS_REQ_new 2352 4_0_0 EXIST::FUNCTION:TS -d2i_TS_REQ 2353 4_0_0 EXIST::FUNCTION:TS -i2d_TS_REQ 2354 4_0_0 EXIST::FUNCTION:TS -TS_REQ_dup 2355 4_0_0 EXIST::FUNCTION:TS -d2i_TS_REQ_fp 2356 4_0_0 EXIST::FUNCTION:STDIO,TS -i2d_TS_REQ_fp 2357 4_0_0 EXIST::FUNCTION:STDIO,TS -d2i_TS_REQ_bio 2358 4_0_0 EXIST::FUNCTION:TS -i2d_TS_REQ_bio 2359 4_0_0 EXIST::FUNCTION:TS -TS_MSG_IMPRINT_free 2360 4_0_0 EXIST::FUNCTION:TS -TS_MSG_IMPRINT_new 2361 4_0_0 EXIST::FUNCTION:TS -d2i_TS_MSG_IMPRINT 2362 4_0_0 EXIST::FUNCTION:TS -i2d_TS_MSG_IMPRINT 2363 4_0_0 EXIST::FUNCTION:TS -TS_MSG_IMPRINT_dup 2364 4_0_0 EXIST::FUNCTION:TS -d2i_TS_MSG_IMPRINT_fp 2365 4_0_0 EXIST::FUNCTION:STDIO,TS -i2d_TS_MSG_IMPRINT_fp 2366 4_0_0 EXIST::FUNCTION:STDIO,TS -d2i_TS_MSG_IMPRINT_bio 2367 4_0_0 EXIST::FUNCTION:TS -i2d_TS_MSG_IMPRINT_bio 2368 4_0_0 EXIST::FUNCTION:TS -TS_RESP_free 2369 4_0_0 EXIST::FUNCTION:TS -TS_RESP_new 2370 4_0_0 EXIST::FUNCTION:TS -d2i_TS_RESP 2371 4_0_0 EXIST::FUNCTION:TS -i2d_TS_RESP 2372 4_0_0 EXIST::FUNCTION:TS -TS_RESP_dup 2373 4_0_0 EXIST::FUNCTION:TS -d2i_TS_RESP_fp 2374 4_0_0 EXIST::FUNCTION:STDIO,TS -i2d_TS_RESP_fp 2375 4_0_0 EXIST::FUNCTION:STDIO,TS -d2i_TS_RESP_bio 2376 4_0_0 EXIST::FUNCTION:TS -i2d_TS_RESP_bio 2377 4_0_0 EXIST::FUNCTION:TS -TS_STATUS_INFO_free 2378 4_0_0 EXIST::FUNCTION:TS -TS_STATUS_INFO_new 2379 4_0_0 EXIST::FUNCTION:TS -d2i_TS_STATUS_INFO 2380 4_0_0 EXIST::FUNCTION:TS -i2d_TS_STATUS_INFO 2381 4_0_0 EXIST::FUNCTION:TS -TS_STATUS_INFO_dup 2382 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_free 2383 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_new 2384 4_0_0 EXIST::FUNCTION:TS -d2i_TS_TST_INFO 2385 4_0_0 EXIST::FUNCTION:TS -i2d_TS_TST_INFO 2386 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_dup 2387 4_0_0 EXIST::FUNCTION:TS -PKCS7_to_TS_TST_INFO 2388 4_0_0 EXIST::FUNCTION:TS -d2i_TS_TST_INFO_fp 2389 4_0_0 EXIST::FUNCTION:STDIO,TS -i2d_TS_TST_INFO_fp 2390 4_0_0 EXIST::FUNCTION:STDIO,TS -d2i_TS_TST_INFO_bio 2391 4_0_0 EXIST::FUNCTION:TS -i2d_TS_TST_INFO_bio 2392 4_0_0 EXIST::FUNCTION:TS -TS_ACCURACY_free 2393 4_0_0 EXIST::FUNCTION:TS -TS_ACCURACY_new 2394 4_0_0 EXIST::FUNCTION:TS -d2i_TS_ACCURACY 2395 4_0_0 EXIST::FUNCTION:TS -i2d_TS_ACCURACY 2396 4_0_0 EXIST::FUNCTION:TS -TS_ACCURACY_dup 2397 4_0_0 EXIST::FUNCTION:TS -TS_REQ_set_version 2398 4_0_0 EXIST::FUNCTION:TS -TS_REQ_get_version 2399 4_0_0 EXIST::FUNCTION:TS -TS_STATUS_INFO_set_status 2400 4_0_0 EXIST::FUNCTION:TS -TS_STATUS_INFO_get0_status 2401 4_0_0 EXIST::FUNCTION:TS -TS_STATUS_INFO_get0_text 2402 4_0_0 EXIST::FUNCTION:TS -TS_STATUS_INFO_get0_failure_info 2403 4_0_0 EXIST::FUNCTION:TS -TS_REQ_set_msg_imprint 2404 4_0_0 EXIST::FUNCTION:TS -TS_REQ_get_msg_imprint 2405 4_0_0 EXIST::FUNCTION:TS -TS_MSG_IMPRINT_set_algo 2406 4_0_0 EXIST::FUNCTION:TS -TS_MSG_IMPRINT_get_algo 2407 4_0_0 EXIST::FUNCTION:TS -TS_MSG_IMPRINT_set_msg 2408 4_0_0 EXIST::FUNCTION:TS -TS_MSG_IMPRINT_get_msg 2409 4_0_0 EXIST::FUNCTION:TS -TS_REQ_set_policy_id 2410 4_0_0 EXIST::FUNCTION:TS -TS_REQ_get_policy_id 2411 4_0_0 EXIST::FUNCTION:TS -TS_REQ_set_nonce 2412 4_0_0 EXIST::FUNCTION:TS -TS_REQ_get_nonce 2413 4_0_0 EXIST::FUNCTION:TS -TS_REQ_set_cert_req 2414 4_0_0 EXIST::FUNCTION:TS -TS_REQ_get_cert_req 2415 4_0_0 EXIST::FUNCTION:TS -TS_REQ_get_exts 2416 4_0_0 EXIST::FUNCTION:TS -TS_REQ_ext_free 2417 4_0_0 EXIST::FUNCTION:TS -TS_REQ_get_ext_count 2418 4_0_0 EXIST::FUNCTION:TS -TS_REQ_get_ext_by_NID 2419 4_0_0 EXIST::FUNCTION:TS -TS_REQ_get_ext_by_OBJ 2420 4_0_0 EXIST::FUNCTION:TS -TS_REQ_get_ext_by_critical 2421 4_0_0 EXIST::FUNCTION:TS -TS_REQ_get_ext 2422 4_0_0 EXIST::FUNCTION:TS -TS_REQ_delete_ext 2423 4_0_0 EXIST::FUNCTION:TS -TS_REQ_add_ext 2424 4_0_0 EXIST::FUNCTION:TS -TS_REQ_get_ext_d2i 2425 4_0_0 EXIST::FUNCTION:TS -TS_REQ_print_bio 2426 4_0_0 EXIST::FUNCTION:TS -TS_RESP_set_status_info 2427 4_0_0 EXIST::FUNCTION:TS -TS_RESP_get_status_info 2428 4_0_0 EXIST::FUNCTION:TS -TS_RESP_set_tst_info 2429 4_0_0 EXIST::FUNCTION:TS -TS_RESP_get_token 2430 4_0_0 EXIST::FUNCTION:TS -TS_RESP_get_tst_info 2431 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_set_version 2432 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_version 2433 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_set_policy_id 2434 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_policy_id 2435 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_set_msg_imprint 2436 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_msg_imprint 2437 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_set_serial 2438 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_serial 2439 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_set_time 2440 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_time 2441 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_set_accuracy 2442 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_accuracy 2443 4_0_0 EXIST::FUNCTION:TS -TS_ACCURACY_set_seconds 2444 4_0_0 EXIST::FUNCTION:TS -TS_ACCURACY_get_seconds 2445 4_0_0 EXIST::FUNCTION:TS -TS_ACCURACY_set_millis 2446 4_0_0 EXIST::FUNCTION:TS -TS_ACCURACY_get_millis 2447 4_0_0 EXIST::FUNCTION:TS -TS_ACCURACY_set_micros 2448 4_0_0 EXIST::FUNCTION:TS -TS_ACCURACY_get_micros 2449 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_set_ordering 2450 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_ordering 2451 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_set_nonce 2452 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_nonce 2453 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_set_tsa 2454 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_tsa 2455 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_exts 2456 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_ext_free 2457 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_ext_count 2458 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_ext_by_NID 2459 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_ext_by_OBJ 2460 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_ext_by_critical 2461 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_ext 2462 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_delete_ext 2463 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_add_ext 2464 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_get_ext_d2i 2465 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_new 2466 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_new_ex 2467 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_free 2468 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_set_signer_cert 2469 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_set_signer_key 2470 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_set_signer_digest 2471 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_set_ess_cert_id_digest 2472 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_set_def_policy 2473 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_set_certs 2474 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_add_policy 2475 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_add_md 2476 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_set_accuracy 2477 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_set_clock_precision_digits 2478 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_add_flags 2479 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_set_serial_cb 2480 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_set_time_cb 2481 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_set_extension_cb 2482 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_set_status_info 2483 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_set_status_info_cond 2484 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_add_failure_info 2485 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_get_request 2486 4_0_0 EXIST::FUNCTION:TS -TS_RESP_CTX_get_tst_info 2487 4_0_0 EXIST::FUNCTION:TS -TS_RESP_create_response 2488 4_0_0 EXIST::FUNCTION:TS -TS_RESP_verify_signature 2489 4_0_0 EXIST::FUNCTION:TS -TS_RESP_verify_response 2490 4_0_0 EXIST::FUNCTION:TS -TS_RESP_verify_token 2491 4_0_0 EXIST::FUNCTION:TS -TS_VERIFY_CTX_new 2492 4_0_0 EXIST::FUNCTION:TS -TS_VERIFY_CTX_init 2493 4_0_0 EXIST::FUNCTION:TS -TS_VERIFY_CTX_free 2494 4_0_0 EXIST::FUNCTION:TS -TS_VERIFY_CTX_cleanup 2495 4_0_0 EXIST::FUNCTION:TS -TS_VERIFY_CTX_set_flags 2496 4_0_0 EXIST::FUNCTION:TS -TS_VERIFY_CTX_add_flags 2497 4_0_0 EXIST::FUNCTION:TS -TS_VERIFY_CTX_set_data 2498 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_4,TS -TS_VERIFY_CTX_set0_data 2499 4_0_0 EXIST::FUNCTION:TS -TS_VERIFY_CTX_set_imprint 2500 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_4,TS -TS_VERIFY_CTX_set0_imprint 2501 4_0_0 EXIST::FUNCTION:TS -TS_VERIFY_CTX_set_store 2502 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_4,TS -TS_VERIFY_CTX_set0_store 2503 4_0_0 EXIST::FUNCTION:TS -TS_VERIFY_CTX_set_certs 2504 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_4,TS -TS_VERIFY_CTX_set0_certs 2505 4_0_0 EXIST::FUNCTION:TS -TS_REQ_to_TS_VERIFY_CTX 2506 4_0_0 EXIST::FUNCTION:TS -TS_RESP_print_bio 2507 4_0_0 EXIST::FUNCTION:TS -TS_STATUS_INFO_print_bio 2508 4_0_0 EXIST::FUNCTION:TS -TS_TST_INFO_print_bio 2509 4_0_0 EXIST::FUNCTION:TS -TS_ASN1_INTEGER_print_bio 2510 4_0_0 EXIST::FUNCTION:TS -TS_OBJ_print_bio 2511 4_0_0 EXIST::FUNCTION:TS -TS_ext_print_bio 2512 4_0_0 EXIST::FUNCTION:TS -TS_X509_ALGOR_print_bio 2513 4_0_0 EXIST::FUNCTION:TS -TS_MSG_IMPRINT_print_bio 2514 4_0_0 EXIST::FUNCTION:TS -TS_CONF_load_cert 2515 4_0_0 EXIST::FUNCTION:TS -TS_CONF_load_certs 2516 4_0_0 EXIST::FUNCTION:TS -TS_CONF_load_key 2517 4_0_0 EXIST::FUNCTION:TS -TS_CONF_get_tsa_section 2518 4_0_0 EXIST::FUNCTION:TS -TS_CONF_set_serial 2519 4_0_0 EXIST::FUNCTION:TS -TS_CONF_set_signer_cert 2520 4_0_0 EXIST::FUNCTION:TS -TS_CONF_set_certs 2521 4_0_0 EXIST::FUNCTION:TS -TS_CONF_set_signer_key 2522 4_0_0 EXIST::FUNCTION:TS -TS_CONF_set_signer_digest 2523 4_0_0 EXIST::FUNCTION:TS -TS_CONF_set_def_policy 2524 4_0_0 EXIST::FUNCTION:TS -TS_CONF_set_policies 2525 4_0_0 EXIST::FUNCTION:TS -TS_CONF_set_digests 2526 4_0_0 EXIST::FUNCTION:TS -TS_CONF_set_accuracy 2527 4_0_0 EXIST::FUNCTION:TS -TS_CONF_set_clock_precision_digits 2528 4_0_0 EXIST::FUNCTION:TS -TS_CONF_set_ordering 2529 4_0_0 EXIST::FUNCTION:TS -TS_CONF_set_tsa_name 2530 4_0_0 EXIST::FUNCTION:TS -TS_CONF_set_ess_cert_id_chain 2531 4_0_0 EXIST::FUNCTION:TS -TS_CONF_set_ess_cert_id_digest 2532 4_0_0 EXIST::FUNCTION:TS -TXT_DB_read 2533 4_0_0 EXIST::FUNCTION: -TXT_DB_write 2534 4_0_0 EXIST::FUNCTION: -TXT_DB_create_index 2535 4_0_0 EXIST::FUNCTION: -TXT_DB_free 2536 4_0_0 EXIST::FUNCTION: -TXT_DB_get_by_index 2537 4_0_0 EXIST::FUNCTION: -TXT_DB_insert 2538 4_0_0 EXIST::FUNCTION: -WHIRLPOOL_Init 2539 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,WHIRLPOOL -WHIRLPOOL_Update 2540 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,WHIRLPOOL -WHIRLPOOL_BitUpdate 2541 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,WHIRLPOOL -WHIRLPOOL_Final 2542 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,WHIRLPOOL -WHIRLPOOL 2543 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,WHIRLPOOL -d2i_ASN1_SEQUENCE_ANY 2544 4_0_0 EXIST::FUNCTION: -i2d_ASN1_SEQUENCE_ANY 2545 4_0_0 EXIST::FUNCTION: -ASN1_SEQUENCE_ANY_it 2546 4_0_0 EXIST::FUNCTION: -d2i_ASN1_SET_ANY 2547 4_0_0 EXIST::FUNCTION: -i2d_ASN1_SET_ANY 2548 4_0_0 EXIST::FUNCTION: -ASN1_SET_ANY_it 2549 4_0_0 EXIST::FUNCTION: -ASN1_TYPE_free 2550 4_0_0 EXIST::FUNCTION: -ASN1_TYPE_new 2551 4_0_0 EXIST::FUNCTION: -d2i_ASN1_TYPE 2552 4_0_0 EXIST::FUNCTION: -i2d_ASN1_TYPE 2553 4_0_0 EXIST::FUNCTION: -ASN1_ANY_it 2554 4_0_0 EXIST::FUNCTION: -ASN1_TYPE_get 2555 4_0_0 EXIST::FUNCTION: -ASN1_TYPE_set 2556 4_0_0 EXIST::FUNCTION: -ASN1_TYPE_set1 2557 4_0_0 EXIST::FUNCTION: -ASN1_TYPE_cmp 2558 4_0_0 EXIST::FUNCTION: -ASN1_TYPE_pack_sequence 2559 4_0_0 EXIST::FUNCTION: -ASN1_TYPE_unpack_sequence 2560 4_0_0 EXIST::FUNCTION: -d2i_ASN1_OBJECT 2561 4_0_0 EXIST::FUNCTION: -i2d_ASN1_OBJECT 2562 4_0_0 EXIST::FUNCTION: -ASN1_OBJECT_free 2563 4_0_0 EXIST::FUNCTION: -ASN1_OBJECT_new 2564 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_0 -ASN1_OBJECT_it 2565 4_0_0 EXIST::FUNCTION: -ASN1_STRING_new 2566 4_0_0 EXIST::FUNCTION: -ASN1_STRING_free 2567 4_0_0 EXIST::FUNCTION: -ASN1_STRING_clear_free 2568 4_0_0 EXIST::FUNCTION: -ASN1_STRING_copy 2569 4_0_0 EXIST::FUNCTION: -ASN1_STRING_dup 2570 4_0_0 EXIST::FUNCTION: -ASN1_STRING_type_new 2571 4_0_0 EXIST::FUNCTION: -ASN1_STRING_cmp 2572 4_0_0 EXIST::FUNCTION: -ASN1_STRING_set 2573 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1 -ASN1_STRING_set0 2574 4_0_0 EXIST::FUNCTION: -ASN1_STRING_length 2575 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1 -ASN1_STRING_length_set 2576 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ASN1_STRING_type 2577 4_0_0 EXIST::FUNCTION: -ASN1_STRING_get0_data 2578 4_0_0 EXIST::FUNCTION: -d2i_ASN1_BIT_STRING 2579 4_0_0 EXIST::FUNCTION: -i2d_ASN1_BIT_STRING 2580 4_0_0 EXIST::FUNCTION: -ASN1_BIT_STRING_free 2581 4_0_0 EXIST::FUNCTION: -ASN1_BIT_STRING_new 2582 4_0_0 EXIST::FUNCTION: -ASN1_BIT_STRING_it 2583 4_0_0 EXIST::FUNCTION: -ASN1_BIT_STRING_set 2584 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1 -ASN1_BIT_STRING_set_bit 2585 4_0_0 EXIST::FUNCTION: -ASN1_BIT_STRING_get_bit 2586 4_0_0 EXIST::FUNCTION: -ASN1_BIT_STRING_check 2587 4_0_0 EXIST::FUNCTION: -ASN1_BIT_STRING_get_length 2588 4_0_0 EXIST::FUNCTION: -ASN1_BIT_STRING_name_print 2589 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1 -ASN1_BIT_STRING_num_asc 2590 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1 -ASN1_BIT_STRING_set_asc 2591 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1 -d2i_ASN1_INTEGER 2592 4_0_0 EXIST::FUNCTION: -i2d_ASN1_INTEGER 2593 4_0_0 EXIST::FUNCTION: -ASN1_INTEGER_free 2594 4_0_0 EXIST::FUNCTION: -ASN1_INTEGER_new 2595 4_0_0 EXIST::FUNCTION: -ASN1_INTEGER_it 2596 4_0_0 EXIST::FUNCTION: -d2i_ASN1_UINTEGER 2597 4_0_0 EXIST::FUNCTION: -ASN1_INTEGER_dup 2598 4_0_0 EXIST::FUNCTION: -ASN1_INTEGER_cmp 2599 4_0_0 EXIST::FUNCTION: -d2i_ASN1_ENUMERATED 2600 4_0_0 EXIST::FUNCTION: -i2d_ASN1_ENUMERATED 2601 4_0_0 EXIST::FUNCTION: -ASN1_ENUMERATED_free 2602 4_0_0 EXIST::FUNCTION: -ASN1_ENUMERATED_new 2603 4_0_0 EXIST::FUNCTION: -ASN1_ENUMERATED_it 2604 4_0_0 EXIST::FUNCTION: -ASN1_UTCTIME_check 2605 4_0_0 EXIST::FUNCTION: -ASN1_UTCTIME_set 2606 4_0_0 EXIST::FUNCTION: -ASN1_UTCTIME_adj 2607 4_0_0 EXIST::FUNCTION: -ASN1_UTCTIME_set_string 2608 4_0_0 EXIST::FUNCTION: -ASN1_UTCTIME_cmp_time_t 2609 4_0_0 EXIST::FUNCTION: -ASN1_GENERALIZEDTIME_check 2610 4_0_0 EXIST::FUNCTION: -ASN1_GENERALIZEDTIME_set 2611 4_0_0 EXIST::FUNCTION: -ASN1_GENERALIZEDTIME_adj 2612 4_0_0 EXIST::FUNCTION: -ASN1_GENERALIZEDTIME_set_string 2613 4_0_0 EXIST::FUNCTION: -ASN1_TIME_diff 2614 4_0_0 EXIST::FUNCTION: -d2i_ASN1_OCTET_STRING 2615 4_0_0 EXIST::FUNCTION: -i2d_ASN1_OCTET_STRING 2616 4_0_0 EXIST::FUNCTION: -ASN1_OCTET_STRING_free 2617 4_0_0 EXIST::FUNCTION: -ASN1_OCTET_STRING_new 2618 4_0_0 EXIST::FUNCTION: -ASN1_OCTET_STRING_it 2619 4_0_0 EXIST::FUNCTION: -ASN1_OCTET_STRING_dup 2620 4_0_0 EXIST::FUNCTION: -ASN1_OCTET_STRING_cmp 2621 4_0_0 EXIST::FUNCTION: -ASN1_OCTET_STRING_set 2622 4_0_0 EXIST::FUNCTION: -d2i_ASN1_VISIBLESTRING 2623 4_0_0 EXIST::FUNCTION: -i2d_ASN1_VISIBLESTRING 2624 4_0_0 EXIST::FUNCTION: -ASN1_VISIBLESTRING_free 2625 4_0_0 EXIST::FUNCTION: -ASN1_VISIBLESTRING_new 2626 4_0_0 EXIST::FUNCTION: -ASN1_VISIBLESTRING_it 2627 4_0_0 EXIST::FUNCTION: -d2i_ASN1_UNIVERSALSTRING 2628 4_0_0 EXIST::FUNCTION: -i2d_ASN1_UNIVERSALSTRING 2629 4_0_0 EXIST::FUNCTION: -ASN1_UNIVERSALSTRING_free 2630 4_0_0 EXIST::FUNCTION: -ASN1_UNIVERSALSTRING_new 2631 4_0_0 EXIST::FUNCTION: -ASN1_UNIVERSALSTRING_it 2632 4_0_0 EXIST::FUNCTION: -d2i_ASN1_UTF8STRING 2633 4_0_0 EXIST::FUNCTION: -i2d_ASN1_UTF8STRING 2634 4_0_0 EXIST::FUNCTION: -ASN1_UTF8STRING_free 2635 4_0_0 EXIST::FUNCTION: -ASN1_UTF8STRING_new 2636 4_0_0 EXIST::FUNCTION: -ASN1_UTF8STRING_it 2637 4_0_0 EXIST::FUNCTION: -d2i_ASN1_NULL 2638 4_0_0 EXIST::FUNCTION: -i2d_ASN1_NULL 2639 4_0_0 EXIST::FUNCTION: -ASN1_NULL_free 2640 4_0_0 EXIST::FUNCTION: -ASN1_NULL_new 2641 4_0_0 EXIST::FUNCTION: -ASN1_NULL_it 2642 4_0_0 EXIST::FUNCTION: -d2i_ASN1_BMPSTRING 2643 4_0_0 EXIST::FUNCTION: -i2d_ASN1_BMPSTRING 2644 4_0_0 EXIST::FUNCTION: -ASN1_BMPSTRING_free 2645 4_0_0 EXIST::FUNCTION: -ASN1_BMPSTRING_new 2646 4_0_0 EXIST::FUNCTION: -ASN1_BMPSTRING_it 2647 4_0_0 EXIST::FUNCTION: -UTF8_getc 2648 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1 -UTF8_putc 2649 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1 -d2i_ASN1_PRINTABLE 2650 4_0_0 EXIST::FUNCTION: -i2d_ASN1_PRINTABLE 2651 4_0_0 EXIST::FUNCTION: -ASN1_PRINTABLE_free 2652 4_0_0 EXIST::FUNCTION: -ASN1_PRINTABLE_new 2653 4_0_0 EXIST::FUNCTION: -ASN1_PRINTABLE_it 2654 4_0_0 EXIST::FUNCTION: -d2i_DIRECTORYSTRING 2655 4_0_0 EXIST::FUNCTION: -i2d_DIRECTORYSTRING 2656 4_0_0 EXIST::FUNCTION: -DIRECTORYSTRING_free 2657 4_0_0 EXIST::FUNCTION: -DIRECTORYSTRING_new 2658 4_0_0 EXIST::FUNCTION: -DIRECTORYSTRING_it 2659 4_0_0 EXIST::FUNCTION: -d2i_DISPLAYTEXT 2660 4_0_0 EXIST::FUNCTION: -i2d_DISPLAYTEXT 2661 4_0_0 EXIST::FUNCTION: -DISPLAYTEXT_free 2662 4_0_0 EXIST::FUNCTION: -DISPLAYTEXT_new 2663 4_0_0 EXIST::FUNCTION: -DISPLAYTEXT_it 2664 4_0_0 EXIST::FUNCTION: -d2i_ASN1_PRINTABLESTRING 2665 4_0_0 EXIST::FUNCTION: -i2d_ASN1_PRINTABLESTRING 2666 4_0_0 EXIST::FUNCTION: -ASN1_PRINTABLESTRING_free 2667 4_0_0 EXIST::FUNCTION: -ASN1_PRINTABLESTRING_new 2668 4_0_0 EXIST::FUNCTION: -ASN1_PRINTABLESTRING_it 2669 4_0_0 EXIST::FUNCTION: -d2i_ASN1_T61STRING 2670 4_0_0 EXIST::FUNCTION: -i2d_ASN1_T61STRING 2671 4_0_0 EXIST::FUNCTION: -ASN1_T61STRING_free 2672 4_0_0 EXIST::FUNCTION: -ASN1_T61STRING_new 2673 4_0_0 EXIST::FUNCTION: -ASN1_T61STRING_it 2674 4_0_0 EXIST::FUNCTION: -d2i_ASN1_IA5STRING 2675 4_0_0 EXIST::FUNCTION: -i2d_ASN1_IA5STRING 2676 4_0_0 EXIST::FUNCTION: -ASN1_IA5STRING_free 2677 4_0_0 EXIST::FUNCTION: -ASN1_IA5STRING_new 2678 4_0_0 EXIST::FUNCTION: -ASN1_IA5STRING_it 2679 4_0_0 EXIST::FUNCTION: -d2i_ASN1_GENERALSTRING 2680 4_0_0 EXIST::FUNCTION: -i2d_ASN1_GENERALSTRING 2681 4_0_0 EXIST::FUNCTION: -ASN1_GENERALSTRING_free 2682 4_0_0 EXIST::FUNCTION: -ASN1_GENERALSTRING_new 2683 4_0_0 EXIST::FUNCTION: -ASN1_GENERALSTRING_it 2684 4_0_0 EXIST::FUNCTION: -d2i_ASN1_UTCTIME 2685 4_0_0 EXIST::FUNCTION: -i2d_ASN1_UTCTIME 2686 4_0_0 EXIST::FUNCTION: -ASN1_UTCTIME_free 2687 4_0_0 EXIST::FUNCTION: -ASN1_UTCTIME_new 2688 4_0_0 EXIST::FUNCTION: -ASN1_UTCTIME_it 2689 4_0_0 EXIST::FUNCTION: -d2i_ASN1_GENERALIZEDTIME 2690 4_0_0 EXIST::FUNCTION: -i2d_ASN1_GENERALIZEDTIME 2691 4_0_0 EXIST::FUNCTION: -ASN1_GENERALIZEDTIME_free 2692 4_0_0 EXIST::FUNCTION: -ASN1_GENERALIZEDTIME_new 2693 4_0_0 EXIST::FUNCTION: -ASN1_GENERALIZEDTIME_it 2694 4_0_0 EXIST::FUNCTION: -d2i_ASN1_TIME 2695 4_0_0 EXIST::FUNCTION: -i2d_ASN1_TIME 2696 4_0_0 EXIST::FUNCTION: -ASN1_TIME_free 2697 4_0_0 EXIST::FUNCTION: -ASN1_TIME_new 2698 4_0_0 EXIST::FUNCTION: -ASN1_TIME_it 2699 4_0_0 EXIST::FUNCTION: -ASN1_TIME_dup 2700 4_0_0 EXIST::FUNCTION: -ASN1_UTCTIME_dup 2701 4_0_0 EXIST::FUNCTION: -ASN1_GENERALIZEDTIME_dup 2702 4_0_0 EXIST::FUNCTION: -ASN1_OCTET_STRING_NDEF_it 2703 4_0_0 EXIST::FUNCTION: -ASN1_TIME_set 2704 4_0_0 EXIST::FUNCTION: -ASN1_TIME_adj 2705 4_0_0 EXIST::FUNCTION: -ASN1_TIME_check 2706 4_0_0 EXIST::FUNCTION: -ASN1_TIME_to_generalizedtime 2707 4_0_0 EXIST::FUNCTION: -ASN1_TIME_set_string 2708 4_0_0 EXIST::FUNCTION: -ASN1_TIME_set_string_X509 2709 4_0_0 EXIST::FUNCTION: -ASN1_TIME_to_tm 2710 4_0_0 EXIST::FUNCTION: -ASN1_TIME_normalize 2711 4_0_0 EXIST::FUNCTION: -ASN1_TIME_cmp_time_t 2712 4_0_0 EXIST::FUNCTION: -ASN1_TIME_compare 2713 4_0_0 EXIST::FUNCTION: -i2a_ASN1_INTEGER 2714 4_0_0 EXIST::FUNCTION: -a2i_ASN1_INTEGER 2715 4_0_0 EXIST::FUNCTION: -i2a_ASN1_ENUMERATED 2716 4_0_0 EXIST::FUNCTION: -a2i_ASN1_ENUMERATED 2717 4_0_0 EXIST::FUNCTION: -i2a_ASN1_OBJECT 2718 4_0_0 EXIST::FUNCTION: -a2i_ASN1_STRING 2719 4_0_0 EXIST::FUNCTION: -i2a_ASN1_STRING 2720 4_0_0 EXIST::FUNCTION: -i2t_ASN1_OBJECT 2721 4_0_0 EXIST::FUNCTION: -a2d_ASN1_OBJECT 2722 4_0_0 EXIST::FUNCTION: -ASN1_OBJECT_create 2723 4_0_0 EXIST::FUNCTION: -ASN1_INTEGER_get_int64 2724 4_0_0 EXIST::FUNCTION: -ASN1_INTEGER_set_int64 2725 4_0_0 EXIST::FUNCTION: -ASN1_INTEGER_get_uint64 2726 4_0_0 EXIST::FUNCTION: -ASN1_INTEGER_set_uint64 2727 4_0_0 EXIST::FUNCTION: -ASN1_INTEGER_set 2728 4_0_0 EXIST::FUNCTION: -ASN1_INTEGER_get 2729 4_0_0 EXIST::FUNCTION: -BN_to_ASN1_INTEGER 2730 4_0_0 EXIST::FUNCTION: -ASN1_INTEGER_to_BN 2731 4_0_0 EXIST::FUNCTION: -ASN1_ENUMERATED_get_int64 2732 4_0_0 EXIST::FUNCTION: -ASN1_ENUMERATED_set_int64 2733 4_0_0 EXIST::FUNCTION: -ASN1_ENUMERATED_set 2734 4_0_0 EXIST::FUNCTION: -ASN1_ENUMERATED_get 2735 4_0_0 EXIST::FUNCTION: -BN_to_ASN1_ENUMERATED 2736 4_0_0 EXIST::FUNCTION: -ASN1_ENUMERATED_to_BN 2737 4_0_0 EXIST::FUNCTION: -ASN1_PRINTABLE_type 2738 4_0_0 EXIST::FUNCTION: -ASN1_tag2bit 2739 4_0_0 EXIST::FUNCTION: -ASN1_get_object 2740 4_0_0 EXIST::FUNCTION: -ASN1_check_infinite_end 2741 4_0_0 EXIST::FUNCTION: -ASN1_const_check_infinite_end 2742 4_0_0 EXIST::FUNCTION: -ASN1_put_object 2743 4_0_0 EXIST::FUNCTION: -ASN1_put_eoc 2744 4_0_0 EXIST::FUNCTION: -ASN1_object_size 2745 4_0_0 EXIST::FUNCTION: -ASN1_dup 2746 4_0_0 EXIST::FUNCTION: -ASN1_item_dup 2747 4_0_0 EXIST::FUNCTION: -ASN1_item_sign_ex 2748 4_0_0 EXIST::FUNCTION: -ASN1_item_verify_ex 2749 4_0_0 EXIST::FUNCTION: -ASN1_d2i_fp 2750 4_0_0 EXIST::FUNCTION:STDIO -ASN1_item_d2i_fp_ex 2751 4_0_0 EXIST::FUNCTION:STDIO -ASN1_item_d2i_fp 2752 4_0_0 EXIST::FUNCTION:STDIO -ASN1_i2d_fp 2753 4_0_0 EXIST::FUNCTION:STDIO -ASN1_item_i2d_fp 2754 4_0_0 EXIST::FUNCTION:STDIO -ASN1_STRING_print_ex_fp 2755 4_0_0 EXIST::FUNCTION:STDIO -ASN1_STRING_to_UTF8 2756 4_0_0 EXIST::FUNCTION: -ASN1_d2i_bio 2757 4_0_0 EXIST::FUNCTION: -ASN1_item_d2i_bio_ex 2758 4_0_0 EXIST::FUNCTION: -ASN1_item_d2i_bio 2759 4_0_0 EXIST::FUNCTION: -ASN1_i2d_bio 2760 4_0_0 EXIST::FUNCTION: -ASN1_item_i2d_bio 2761 4_0_0 EXIST::FUNCTION: -ASN1_item_i2d_mem_bio 2762 4_0_0 EXIST::FUNCTION: -ASN1_UTCTIME_print 2763 4_0_0 EXIST::FUNCTION: -ASN1_GENERALIZEDTIME_print 2764 4_0_0 EXIST::FUNCTION: -ASN1_TIME_print 2765 4_0_0 EXIST::FUNCTION: -ASN1_TIME_print_ex 2766 4_0_0 EXIST::FUNCTION: -ASN1_STRING_print 2767 4_0_0 EXIST::FUNCTION: -ASN1_STRING_print_ex 2768 4_0_0 EXIST::FUNCTION: -ASN1_buf_print 2769 4_0_0 EXIST::FUNCTION: -ASN1_bn_print 2770 4_0_0 EXIST::FUNCTION: -ASN1_parse 2771 4_0_0 EXIST::FUNCTION: -ASN1_parse_dump 2772 4_0_0 EXIST::FUNCTION: -ASN1_tag2str 2773 4_0_0 EXIST::FUNCTION: -ASN1_UNIVERSALSTRING_to_string 2774 4_0_0 EXIST::FUNCTION: -ASN1_TYPE_set_octetstring 2775 4_0_0 EXIST::FUNCTION: -ASN1_TYPE_get_octetstring 2776 4_0_0 EXIST::FUNCTION: -ASN1_TYPE_set_int_octetstring 2777 4_0_0 EXIST::FUNCTION: -ASN1_TYPE_get_int_octetstring 2778 4_0_0 EXIST::FUNCTION: -ASN1_item_unpack 2779 4_0_0 EXIST::FUNCTION: -ASN1_item_unpack_ex 2780 4_0_0 EXIST::FUNCTION: -ASN1_item_pack 2781 4_0_0 EXIST::FUNCTION: -ASN1_STRING_set_default_mask 2782 4_0_0 EXIST::FUNCTION: -ASN1_STRING_set_default_mask_asc 2783 4_0_0 EXIST::FUNCTION: -ASN1_STRING_get_default_mask 2784 4_0_0 EXIST::FUNCTION: -ASN1_mbstring_copy 2785 4_0_0 EXIST::FUNCTION: -ASN1_mbstring_ncopy 2786 4_0_0 EXIST::FUNCTION: -ASN1_STRING_set_by_NID 2787 4_0_0 EXIST::FUNCTION: -ASN1_STRING_TABLE_get 2788 4_0_0 EXIST::FUNCTION: -ASN1_STRING_TABLE_add 2789 4_0_0 EXIST::FUNCTION: -ASN1_STRING_TABLE_cleanup 2790 4_0_0 EXIST::FUNCTION: -ASN1_item_new 2791 4_0_0 EXIST::FUNCTION: -ASN1_item_new_ex 2792 4_0_0 EXIST::FUNCTION: -ASN1_item_free 2793 4_0_0 EXIST::FUNCTION: -ASN1_item_d2i_ex 2794 4_0_0 EXIST::FUNCTION: -ASN1_item_d2i 2795 4_0_0 EXIST::FUNCTION: -ASN1_item_i2d 2796 4_0_0 EXIST::FUNCTION: -ASN1_item_ndef_i2d 2797 4_0_0 EXIST::FUNCTION: -ASN1_add_oid_module 2798 4_0_0 EXIST::FUNCTION: -ASN1_add_stable_module 2799 4_0_0 EXIST::FUNCTION: -ASN1_generate_nconf 2800 4_0_0 EXIST::FUNCTION: -ASN1_generate_v3 2801 4_0_0 EXIST::FUNCTION: -ASN1_str2mask 2802 4_0_0 EXIST::FUNCTION: -ASN1_item_print 2803 4_0_0 EXIST::FUNCTION: -ASN1_PCTX_new 2804 4_0_0 EXIST::FUNCTION: -ASN1_PCTX_free 2805 4_0_0 EXIST::FUNCTION: -ASN1_PCTX_get_flags 2806 4_0_0 EXIST::FUNCTION: -ASN1_PCTX_set_flags 2807 4_0_0 EXIST::FUNCTION: -ASN1_PCTX_get_nm_flags 2808 4_0_0 EXIST::FUNCTION: -ASN1_PCTX_set_nm_flags 2809 4_0_0 EXIST::FUNCTION: -ASN1_PCTX_get_cert_flags 2810 4_0_0 EXIST::FUNCTION: -ASN1_PCTX_set_cert_flags 2811 4_0_0 EXIST::FUNCTION: -ASN1_PCTX_get_oid_flags 2812 4_0_0 EXIST::FUNCTION: -ASN1_PCTX_set_oid_flags 2813 4_0_0 EXIST::FUNCTION: -ASN1_PCTX_get_str_flags 2814 4_0_0 EXIST::FUNCTION: -ASN1_PCTX_set_str_flags 2815 4_0_0 EXIST::FUNCTION: -ASN1_SCTX_new 2816 4_0_0 EXIST::FUNCTION: -ASN1_SCTX_free 2817 4_0_0 EXIST::FUNCTION: -ASN1_SCTX_get_item 2818 4_0_0 EXIST::FUNCTION: -ASN1_SCTX_get_template 2819 4_0_0 EXIST::FUNCTION: -ASN1_SCTX_get_flags 2820 4_0_0 EXIST::FUNCTION: -ASN1_SCTX_set_app_data 2821 4_0_0 EXIST::FUNCTION: -ASN1_SCTX_get_app_data 2822 4_0_0 EXIST::FUNCTION: -BIO_f_asn1 2823 4_0_0 EXIST::FUNCTION: -BIO_new_NDEF 2824 4_0_0 EXIST::FUNCTION: -i2d_ASN1_bio_stream 2825 4_0_0 EXIST::FUNCTION: -PEM_write_bio_ASN1_stream 2826 4_0_0 EXIST::FUNCTION: -SMIME_write_ASN1 2827 4_0_0 EXIST::FUNCTION: -SMIME_write_ASN1_ex 2828 4_0_0 EXIST::FUNCTION: -SMIME_read_ASN1 2829 4_0_0 EXIST::FUNCTION: -SMIME_read_ASN1_ex 2830 4_0_0 EXIST::FUNCTION: -SMIME_crlf_copy 2831 4_0_0 EXIST::FUNCTION: -SMIME_text 2832 4_0_0 EXIST::FUNCTION: -ASN1_ITEM_lookup 2833 4_0_0 EXIST::FUNCTION: -ASN1_ITEM_get 2834 4_0_0 EXIST::FUNCTION: -ASN1_BOOLEAN_it 2835 4_0_0 EXIST::FUNCTION: -ASN1_TBOOLEAN_it 2836 4_0_0 EXIST::FUNCTION: -ASN1_FBOOLEAN_it 2837 4_0_0 EXIST::FUNCTION: -ASN1_SEQUENCE_it 2838 4_0_0 EXIST::FUNCTION: -CBIGNUM_it 2839 4_0_0 EXIST::FUNCTION: -BIGNUM_it 2840 4_0_0 EXIST::FUNCTION: -INT32_it 2841 4_0_0 EXIST::FUNCTION: -ZINT32_it 2842 4_0_0 EXIST::FUNCTION: -UINT32_it 2843 4_0_0 EXIST::FUNCTION: -ZUINT32_it 2844 4_0_0 EXIST::FUNCTION: -INT64_it 2845 4_0_0 EXIST::FUNCTION: -ZINT64_it 2846 4_0_0 EXIST::FUNCTION: -UINT64_it 2847 4_0_0 EXIST::FUNCTION: -ZUINT64_it 2848 4_0_0 EXIST::FUNCTION: -LONG_it 2849 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ZLONG_it 2850 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ASN1_item_ex_new 2851 4_0_0 EXIST::FUNCTION: -ASN1_item_ex_free 2852 4_0_0 EXIST::FUNCTION: -ASN1_item_ex_d2i 2853 4_0_0 EXIST::FUNCTION: -ASN1_item_ex_i2d 2854 4_0_0 EXIST::FUNCTION: -BIO_get_new_index 2855 4_0_0 EXIST::FUNCTION: -BIO_set_flags 2856 4_0_0 EXIST::FUNCTION: -BIO_test_flags 2857 4_0_0 EXIST::FUNCTION: -BIO_clear_flags 2858 4_0_0 EXIST::FUNCTION: -BIO_set_send_flags 2859 4_0_0 EXIST::FUNCTION: -BIO_get_callback 2860 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -BIO_set_callback 2861 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -BIO_debug_callback 2862 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -BIO_get_callback_ex 2863 4_0_0 EXIST::FUNCTION: -BIO_set_callback_ex 2864 4_0_0 EXIST::FUNCTION: -BIO_debug_callback_ex 2865 4_0_0 EXIST::FUNCTION: -BIO_get_callback_arg 2866 4_0_0 EXIST::FUNCTION: -BIO_set_callback_arg 2867 4_0_0 EXIST::FUNCTION: -BIO_method_name 2868 4_0_0 EXIST::FUNCTION: -BIO_method_type 2869 4_0_0 EXIST::FUNCTION: -BIO_ctrl_pending 2870 4_0_0 EXIST::FUNCTION: -BIO_ctrl_wpending 2871 4_0_0 EXIST::FUNCTION: -BIO_ctrl_get_write_guarantee 2872 4_0_0 EXIST::FUNCTION: -BIO_ctrl_get_read_request 2873 4_0_0 EXIST::FUNCTION: -BIO_ctrl_reset_read_request 2874 4_0_0 EXIST::FUNCTION: -BIO_set_ex_data 2875 4_0_0 EXIST::FUNCTION: -BIO_get_ex_data 2876 4_0_0 EXIST::FUNCTION: -BIO_number_read 2877 4_0_0 EXIST::FUNCTION: -BIO_number_written 2878 4_0_0 EXIST::FUNCTION: -BIO_asn1_set_prefix 2879 4_0_0 EXIST::FUNCTION: -BIO_asn1_get_prefix 2880 4_0_0 EXIST::FUNCTION: -BIO_asn1_set_suffix 2881 4_0_0 EXIST::FUNCTION: -BIO_asn1_get_suffix 2882 4_0_0 EXIST::FUNCTION: -BIO_s_file 2883 4_0_0 EXIST::FUNCTION: -BIO_new_file 2884 4_0_0 EXIST::FUNCTION: -BIO_new_from_core_bio 2885 4_0_0 EXIST::FUNCTION: -BIO_new_fp 2886 4_0_0 EXIST::FUNCTION:STDIO -BIO_new_ex 2887 4_0_0 EXIST::FUNCTION: -BIO_new 2888 4_0_0 EXIST::FUNCTION: -BIO_free 2889 4_0_0 EXIST::FUNCTION: -BIO_set_data 2890 4_0_0 EXIST::FUNCTION: -BIO_get_data 2891 4_0_0 EXIST::FUNCTION: -BIO_set_init 2892 4_0_0 EXIST::FUNCTION: -BIO_get_init 2893 4_0_0 EXIST::FUNCTION: -BIO_set_shutdown 2894 4_0_0 EXIST::FUNCTION: -BIO_get_shutdown 2895 4_0_0 EXIST::FUNCTION: -BIO_vfree 2896 4_0_0 EXIST::FUNCTION: -BIO_up_ref 2897 4_0_0 EXIST::FUNCTION: -BIO_read 2898 4_0_0 EXIST::FUNCTION: -BIO_read_ex 2899 4_0_0 EXIST::FUNCTION: -BIO_recvmmsg 2900 4_0_0 EXIST::FUNCTION: -BIO_gets 2901 4_0_0 EXIST::FUNCTION: -BIO_get_line 2902 4_0_0 EXIST::FUNCTION: -BIO_write 2903 4_0_0 EXIST::FUNCTION: -BIO_write_ex 2904 4_0_0 EXIST::FUNCTION: -BIO_sendmmsg 2905 4_0_0 EXIST::FUNCTION: -BIO_get_rpoll_descriptor 2906 4_0_0 EXIST::FUNCTION: -BIO_get_wpoll_descriptor 2907 4_0_0 EXIST::FUNCTION: -BIO_puts 2908 4_0_0 EXIST::FUNCTION: -BIO_indent 2909 4_0_0 EXIST::FUNCTION: -BIO_ctrl 2910 4_0_0 EXIST::FUNCTION: -BIO_eof 2911 4_0_0 EXIST::FUNCTION: -BIO_callback_ctrl 2912 4_0_0 EXIST::FUNCTION: -BIO_ptr_ctrl 2913 4_0_0 EXIST::FUNCTION: -BIO_int_ctrl 2914 4_0_0 EXIST::FUNCTION: -BIO_push 2915 4_0_0 EXIST::FUNCTION: -BIO_pop 2916 4_0_0 EXIST::FUNCTION: -BIO_free_all 2917 4_0_0 EXIST::FUNCTION: -BIO_find_type 2918 4_0_0 EXIST::FUNCTION: -BIO_next 2919 4_0_0 EXIST::FUNCTION: -BIO_set_next 2920 4_0_0 EXIST::FUNCTION: -BIO_get_retry_BIO 2921 4_0_0 EXIST::FUNCTION: -BIO_get_retry_reason 2922 4_0_0 EXIST::FUNCTION: -BIO_set_retry_reason 2923 4_0_0 EXIST::FUNCTION: -BIO_dup_chain 2924 4_0_0 EXIST::FUNCTION: -BIO_nread0 2925 4_0_0 EXIST::FUNCTION: -BIO_nread 2926 4_0_0 EXIST::FUNCTION: -BIO_nwrite0 2927 4_0_0 EXIST::FUNCTION: -BIO_nwrite 2928 4_0_0 EXIST::FUNCTION: -BIO_s_mem 2929 4_0_0 EXIST::FUNCTION: -BIO_s_dgram_mem 2930 4_0_0 EXIST::FUNCTION:DGRAM -BIO_s_secmem 2931 4_0_0 EXIST::FUNCTION: -BIO_new_mem_buf 2932 4_0_0 EXIST::FUNCTION: -BIO_s_socket 2933 4_0_0 EXIST::FUNCTION:SOCK -BIO_s_connect 2934 4_0_0 EXIST::FUNCTION:SOCK -BIO_s_accept 2935 4_0_0 EXIST::FUNCTION:SOCK -BIO_s_fd 2936 4_0_0 EXIST::FUNCTION: -BIO_s_log 2937 4_0_0 EXIST::FUNCTION: -BIO_s_bio 2938 4_0_0 EXIST::FUNCTION: -BIO_s_null 2939 4_0_0 EXIST::FUNCTION: -BIO_f_null 2940 4_0_0 EXIST::FUNCTION: -BIO_f_buffer 2941 4_0_0 EXIST::FUNCTION: -BIO_f_readbuffer 2942 4_0_0 EXIST::FUNCTION: -BIO_f_linebuffer 2943 4_0_0 EXIST::FUNCTION: -BIO_f_nbio_test 2944 4_0_0 EXIST::FUNCTION: -BIO_f_prefix 2945 4_0_0 EXIST::FUNCTION: -BIO_s_core 2946 4_0_0 EXIST::FUNCTION: -BIO_s_dgram_pair 2947 4_0_0 EXIST::FUNCTION:DGRAM -BIO_s_datagram 2948 4_0_0 EXIST::FUNCTION:DGRAM -BIO_dgram_non_fatal_error 2949 4_0_0 EXIST::FUNCTION:DGRAM -BIO_new_dgram 2950 4_0_0 EXIST::FUNCTION:DGRAM -BIO_s_datagram_sctp 2951 4_0_0 EXIST::FUNCTION:DGRAM,SCTP -BIO_new_dgram_sctp 2952 4_0_0 EXIST::FUNCTION:DGRAM,SCTP -BIO_dgram_is_sctp 2953 4_0_0 EXIST::FUNCTION:DGRAM,SCTP -BIO_dgram_sctp_notification_cb 2954 4_0_0 EXIST::FUNCTION:DGRAM,SCTP -BIO_dgram_sctp_wait_for_dry 2955 4_0_0 EXIST::FUNCTION:DGRAM,SCTP -BIO_dgram_sctp_msg_waiting 2956 4_0_0 EXIST::FUNCTION:DGRAM,SCTP -BIO_sock_should_retry 2957 4_0_0 EXIST::FUNCTION:SOCK -BIO_sock_non_fatal_error 2958 4_0_0 EXIST::FUNCTION:SOCK -BIO_err_is_non_fatal 2959 4_0_0 EXIST::FUNCTION:SOCK -BIO_socket_wait 2960 4_0_0 EXIST::FUNCTION:SOCK -BIO_wait 2961 4_0_0 EXIST::FUNCTION: -BIO_do_connect_retry 2962 4_0_0 EXIST::FUNCTION: -BIO_fd_should_retry 2963 4_0_0 EXIST::FUNCTION: -BIO_fd_non_fatal_error 2964 4_0_0 EXIST::FUNCTION: -BIO_dump_cb 2965 4_0_0 EXIST::FUNCTION: -BIO_dump_indent_cb 2966 4_0_0 EXIST::FUNCTION: -BIO_dump 2967 4_0_0 EXIST::FUNCTION: -BIO_dump_indent 2968 4_0_0 EXIST::FUNCTION: -BIO_dump_fp 2969 4_0_0 EXIST::FUNCTION:STDIO -BIO_dump_indent_fp 2970 4_0_0 EXIST::FUNCTION:STDIO -BIO_hex_string 2971 4_0_0 EXIST::FUNCTION: -BIO_ADDR_new 2972 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDR_copy 2973 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDR_dup 2974 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDR_rawmake 2975 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDR_free 2976 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDR_clear 2977 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDR_family 2978 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDR_rawaddress 2979 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDR_rawport 2980 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDR_hostname_string 2981 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDR_service_string 2982 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDR_path_string 2983 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDRINFO_next 2984 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDRINFO_family 2985 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDRINFO_socktype 2986 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDRINFO_protocol 2987 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDRINFO_address 2988 4_0_0 EXIST::FUNCTION:SOCK -BIO_ADDRINFO_free 2989 4_0_0 EXIST::FUNCTION:SOCK -BIO_parse_hostserv 2990 4_0_0 EXIST::FUNCTION:SOCK -BIO_lookup 2991 4_0_0 EXIST::FUNCTION:SOCK -BIO_lookup_ex 2992 4_0_0 EXIST::FUNCTION:SOCK -BIO_sock_error 2993 4_0_0 EXIST::FUNCTION:SOCK -BIO_socket_ioctl 2994 4_0_0 EXIST::FUNCTION:SOCK -BIO_socket_nbio 2995 4_0_0 EXIST::FUNCTION:SOCK -BIO_sock_init 2996 4_0_0 EXIST::FUNCTION:SOCK -BIO_set_tcp_ndelay 2997 4_0_0 EXIST::FUNCTION:SOCK -BIO_gethostbyname 2998 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,SOCK -BIO_get_port 2999 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,SOCK -BIO_get_host_ip 3000 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,SOCK -BIO_get_accept_socket 3001 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,SOCK -BIO_accept 3002 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,SOCK -BIO_sock_info 3003 4_0_0 EXIST::FUNCTION:SOCK -BIO_socket 3004 4_0_0 EXIST::FUNCTION:SOCK -BIO_connect 3005 4_0_0 EXIST::FUNCTION:SOCK -BIO_bind 3006 4_0_0 EXIST::FUNCTION:SOCK -BIO_listen 3007 4_0_0 EXIST::FUNCTION:SOCK -BIO_accept_ex 3008 4_0_0 EXIST::FUNCTION:SOCK -BIO_closesocket 3009 4_0_0 EXIST::FUNCTION:SOCK -BIO_new_socket 3010 4_0_0 EXIST::FUNCTION:SOCK -BIO_new_connect 3011 4_0_0 EXIST::FUNCTION:SOCK -BIO_new_accept 3012 4_0_0 EXIST::FUNCTION:SOCK -BIO_new_fd 3013 4_0_0 EXIST::FUNCTION: -BIO_new_bio_pair 3014 4_0_0 EXIST::FUNCTION: -BIO_new_bio_dgram_pair 3015 4_0_0 EXIST::FUNCTION:DGRAM -BIO_copy_next_retry 3016 4_0_0 EXIST::FUNCTION: -BIO_printf 3017 4_0_0 EXIST::FUNCTION: -BIO_vprintf 3018 4_0_0 EXIST::FUNCTION: -BIO_snprintf 3019 4_0_0 EXIST::FUNCTION: -BIO_vsnprintf 3020 4_0_0 EXIST::FUNCTION: -BIO_meth_new 3021 4_0_0 EXIST::FUNCTION: -BIO_meth_free 3022 4_0_0 EXIST::FUNCTION: -BIO_meth_set_write 3023 4_0_0 EXIST::FUNCTION: -BIO_meth_set_write_ex 3024 4_0_0 EXIST::FUNCTION: -BIO_meth_set_sendmmsg 3025 4_0_0 EXIST::FUNCTION: -BIO_meth_set_read 3026 4_0_0 EXIST::FUNCTION: -BIO_meth_set_read_ex 3027 4_0_0 EXIST::FUNCTION: -BIO_meth_set_recvmmsg 3028 4_0_0 EXIST::FUNCTION: -BIO_meth_set_puts 3029 4_0_0 EXIST::FUNCTION: -BIO_meth_set_gets 3030 4_0_0 EXIST::FUNCTION: -BIO_meth_set_ctrl 3031 4_0_0 EXIST::FUNCTION: -BIO_meth_set_create 3032 4_0_0 EXIST::FUNCTION: -BIO_meth_set_destroy 3033 4_0_0 EXIST::FUNCTION: -BIO_meth_set_callback_ctrl 3034 4_0_0 EXIST::FUNCTION: -BIO_meth_get_write 3035 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 -BIO_meth_get_write_ex 3036 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 -BIO_meth_get_sendmmsg 3037 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 -BIO_meth_get_read 3038 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 -BIO_meth_get_read_ex 3039 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 -BIO_meth_get_recvmmsg 3040 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 -BIO_meth_get_puts 3041 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 -BIO_meth_get_gets 3042 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 -BIO_meth_get_ctrl 3043 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 -BIO_meth_get_create 3044 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 -BIO_meth_get_destroy 3045 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 -BIO_meth_get_callback_ctrl 3046 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 -OSSL_CMP_PKISTATUS_it 3047 4_0_0 EXIST::FUNCTION:CMP -d2i_OSSL_CMP_PKIHEADER 3048 4_0_0 EXIST::FUNCTION:CMP -i2d_OSSL_CMP_PKIHEADER 3049 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_PKIHEADER_free 3050 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_PKIHEADER_new 3051 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_PKIHEADER_it 3052 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_MSG_dup 3053 4_0_0 EXIST::FUNCTION:CMP -d2i_OSSL_CMP_MSG 3054 4_0_0 EXIST::FUNCTION:CMP -i2d_OSSL_CMP_MSG 3055 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_MSG_it 3056 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_dup 3057 4_0_0 EXIST::FUNCTION:CMP -d2i_OSSL_CMP_ATAVS 3058 4_0_0 EXIST::FUNCTION:CMP -i2d_OSSL_CMP_ATAVS 3059 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ATAVS_free 3060 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ATAVS_new 3061 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ATAVS_it 3062 4_0_0 EXIST::FUNCTION:CMP -d2i_OSSL_CMP_PKISI 3063 4_0_0 EXIST::FUNCTION:CMP -i2d_OSSL_CMP_PKISI 3064 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_PKISI_free 3065 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_PKISI_new 3066 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_PKISI_it 3067 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_PKISI_dup 3068 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_create 3069 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_set0 3070 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_get0_type 3071 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_get0_value 3072 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_push0_stack_item 3073 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_free 3074 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_new0_certProfile 3075 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_get0_certProfile 3076 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_new_caCerts 3077 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_get0_caCerts 3078 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_new_rootCaCert 3079 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_get0_rootCaCert 3080 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_new_rootCaKeyUpdate 3081 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_get0_rootCaKeyUpdate 3082 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CRLSTATUS_create 3083 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CRLSTATUS_new1 3084 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CRLSTATUS_get0 3085 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CRLSTATUS_free 3086 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_new0_crlStatusList 3087 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_get0_crlStatusList 3088 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_new_crls 3089 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_get0_crls 3090 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_new0_certReqTemplate 3091 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ITAV_get1_certReqTemplate 3092 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ATAV_create 3093 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ATAV_set0 3094 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ATAV_get0_type 3095 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ATAV_get0_value 3096 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ATAV_new_algId 3097 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ATAV_get0_algId 3098 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ATAV_new_rsaKeyLen 3099 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ATAV_get_rsaKeyLen 3100 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_ATAV_push1 3101 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_MSG_free 3102 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_new 3103 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_free 3104 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_reinit 3105 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get0_libctx 3106 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get0_propq 3107 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set_option 3108 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get_option 3109 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set_log_cb 3110 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_print_errors 3111 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_serverPath 3112 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_server 3113 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set_serverPort 3114 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_proxy 3115 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_no_proxy 3116 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set_http_cb 3117 4_0_0 EXIST::FUNCTION:CMP,HTTP -OSSL_CMP_CTX_set_http_cb_arg 3118 4_0_0 EXIST::FUNCTION:CMP,HTTP -OSSL_CMP_CTX_get_http_cb_arg 3119 4_0_0 EXIST::FUNCTION:CMP,HTTP -OSSL_CMP_CTX_set_transfer_cb 3120 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set_transfer_cb_arg 3121 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get_transfer_cb_arg 3122 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_srvCert 3123 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_expected_sender 3124 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set0_trustedStore 3125 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get0_trustedStore 3126 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_untrusted 3127 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get0_untrusted 3128 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_cert 3129 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_build_cert_chain 3130 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_pkey 3131 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_referenceValue 3132 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_secretValue 3133 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_recipient 3134 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_push0_geninfo_ITAV 3135 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_reset_geninfo_ITAVs 3136 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get0_geninfo_ITAVs 3137 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_extraCertsOut 3138 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set0_newPkey 3139 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get0_newPkey 3140 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_issuer 3141 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_serialNumber 3142 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_subjectName 3143 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_push1_subjectAltName 3144 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set0_reqExtensions 3145 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_reqExtensions_have_SAN 3146 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_push0_policy 3147 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_oldCert 3148 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_p10CSR 3149 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_push0_genm_ITAV 3150 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_certConf_cb 3151 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set_certConf_cb 3152 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set_certConf_cb_arg 3153 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get_certConf_cb_arg 3154 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get_status 3155 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get0_statusString 3156 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get_failInfoCode 3157 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get0_validatedSrvCert 3158 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get0_newCert 3159 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get1_newChain 3160 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get1_caPubs 3161 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_get1_extraCertsIn 3162 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_transactionID 3163 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_set1_senderNonce 3164 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_snprint_PKIStatus 3165 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_snprint_PKIStatusInfo 3166 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_STATUSINFO_new 3167 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_HDR_get0_transactionID 3168 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_HDR_get0_recipNonce 3169 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_HDR_get0_geninfo_ITAVs 3170 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_MSG_get0_header 3171 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_MSG_get_bodytype 3172 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_MSG_get0_certreq_publickey 3173 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_MSG_update_transactionID 3174 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_MSG_update_recipNonce 3175 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_setup_CRM 3176 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_MSG_read 3177 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_MSG_write 3178 4_0_0 EXIST::FUNCTION:CMP -d2i_OSSL_CMP_MSG_bio 3179 4_0_0 EXIST::FUNCTION:CMP -i2d_OSSL_CMP_MSG_bio 3180 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_validate_msg 3181 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_validate_cert_path 3182 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_MSG_http_perform 3183 4_0_0 EXIST::FUNCTION:CMP,HTTP -OSSL_CMP_SRV_process_request 3184 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_CTX_server_perform 3185 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_SRV_CTX_new 3186 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_SRV_CTX_free 3187 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_SRV_CTX_init 3188 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_SRV_CTX_init_trans 3189 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_SRV_CTX_get0_cmp_ctx 3190 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_SRV_CTX_get0_custom_ctx 3191 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_SRV_CTX_set_send_unprotected_errors 3192 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_SRV_CTX_set_accept_unprotected 3193 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_SRV_CTX_set_accept_raverified 3194 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_SRV_CTX_set_grant_implicit_confirm 3195 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_exec_certreq 3196 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_try_certreq 3197 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_exec_RR_ses 3198 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_exec_GENM_ses 3199 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_get1_caCerts 3200 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_get1_rootCaKeyUpdate 3201 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_get1_crlUpdate 3202 4_0_0 EXIST::FUNCTION:CMP -OSSL_CMP_get1_certReqTemplate 3203 4_0_0 EXIST::FUNCTION:CMP -CMS_EnvelopedData_it 3204 4_0_0 EXIST::FUNCTION:CMS -CMS_SignedData_free 3205 4_0_0 EXIST::FUNCTION:CMS -CMS_SignedData_new 3206 4_0_0 EXIST::FUNCTION:CMS -d2i_CMS_ContentInfo 3207 4_0_0 EXIST::FUNCTION:CMS -i2d_CMS_ContentInfo 3208 4_0_0 EXIST::FUNCTION:CMS -CMS_ContentInfo_free 3209 4_0_0 EXIST::FUNCTION:CMS -CMS_ContentInfo_new 3210 4_0_0 EXIST::FUNCTION:CMS -CMS_ContentInfo_it 3211 4_0_0 EXIST::FUNCTION:CMS -d2i_CMS_ReceiptRequest 3212 4_0_0 EXIST::FUNCTION:CMS -i2d_CMS_ReceiptRequest 3213 4_0_0 EXIST::FUNCTION:CMS -CMS_ReceiptRequest_free 3214 4_0_0 EXIST::FUNCTION:CMS -CMS_ReceiptRequest_new 3215 4_0_0 EXIST::FUNCTION:CMS -CMS_ReceiptRequest_it 3216 4_0_0 EXIST::FUNCTION:CMS -CMS_ContentInfo_print_ctx 3217 4_0_0 EXIST::FUNCTION:CMS -CMS_EnvelopedData_dup 3218 4_0_0 EXIST::FUNCTION:CMS -CMS_ContentInfo_new_ex 3219 4_0_0 EXIST::FUNCTION:CMS -CMS_get0_type 3220 4_0_0 EXIST::FUNCTION:CMS -CMS_dataInit 3221 4_0_0 EXIST::FUNCTION:CMS -CMS_dataFinal 3222 4_0_0 EXIST::FUNCTION:CMS -CMS_get0_content 3223 4_0_0 EXIST::FUNCTION:CMS -CMS_is_detached 3224 4_0_0 EXIST::FUNCTION:CMS -CMS_set_detached 3225 4_0_0 EXIST::FUNCTION:CMS -PEM_read_CMS 3226 4_0_0 EXIST::FUNCTION:CMS,STDIO -PEM_write_CMS 3227 4_0_0 EXIST::FUNCTION:CMS,STDIO -PEM_read_bio_CMS 3228 4_0_0 EXIST::FUNCTION:CMS -PEM_write_bio_CMS 3229 4_0_0 EXIST::FUNCTION:CMS -CMS_stream 3230 4_0_0 EXIST::FUNCTION:CMS -d2i_CMS_bio 3231 4_0_0 EXIST::FUNCTION:CMS -i2d_CMS_bio 3232 4_0_0 EXIST::FUNCTION:CMS -BIO_new_CMS 3233 4_0_0 EXIST::FUNCTION:CMS -i2d_CMS_bio_stream 3234 4_0_0 EXIST::FUNCTION:CMS -PEM_write_bio_CMS_stream 3235 4_0_0 EXIST::FUNCTION:CMS -SMIME_read_CMS 3236 4_0_0 EXIST::FUNCTION:CMS -SMIME_read_CMS_ex 3237 4_0_0 EXIST::FUNCTION:CMS -SMIME_write_CMS 3238 4_0_0 EXIST::FUNCTION:CMS -CMS_final 3239 4_0_0 EXIST::FUNCTION:CMS -CMS_final_digest 3240 4_0_0 EXIST::FUNCTION:CMS -CMS_sign 3241 4_0_0 EXIST::FUNCTION:CMS -CMS_sign_ex 3242 4_0_0 EXIST::FUNCTION:CMS -CMS_sign_receipt 3243 4_0_0 EXIST::FUNCTION:CMS -CMS_data 3244 4_0_0 EXIST::FUNCTION:CMS -CMS_data_create 3245 4_0_0 EXIST::FUNCTION:CMS -CMS_data_create_ex 3246 4_0_0 EXIST::FUNCTION:CMS -CMS_digest_verify 3247 4_0_0 EXIST::FUNCTION:CMS -CMS_digest_create 3248 4_0_0 EXIST::FUNCTION:CMS -CMS_digest_create_ex 3249 4_0_0 EXIST::FUNCTION:CMS -CMS_EncryptedData_decrypt 3250 4_0_0 EXIST::FUNCTION:CMS -CMS_EncryptedData_encrypt 3251 4_0_0 EXIST::FUNCTION:CMS -CMS_EncryptedData_encrypt_ex 3252 4_0_0 EXIST::FUNCTION:CMS -CMS_EncryptedData_set1_key 3253 4_0_0 EXIST::FUNCTION:CMS -CMS_verify 3254 4_0_0 EXIST::FUNCTION:CMS -CMS_verify_receipt 3255 4_0_0 EXIST::FUNCTION:CMS -CMS_get0_signers 3256 4_0_0 EXIST::FUNCTION:CMS -CMS_encrypt 3257 4_0_0 EXIST::FUNCTION:CMS -CMS_encrypt_ex 3258 4_0_0 EXIST::FUNCTION:CMS -CMS_decrypt 3259 4_0_0 EXIST::FUNCTION:CMS -CMS_decrypt_set1_pkey 3260 4_0_0 EXIST::FUNCTION:CMS -CMS_decrypt_set1_pkey_and_peer 3261 4_0_0 EXIST::FUNCTION:CMS -CMS_decrypt_set1_key 3262 4_0_0 EXIST::FUNCTION:CMS -CMS_decrypt_set1_password 3263 4_0_0 EXIST::FUNCTION:CMS -CMS_get0_RecipientInfos 3264 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_type 3265 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_get0_pkey_ctx 3266 4_0_0 EXIST::FUNCTION:CMS -CMS_AuthEnvelopedData_create 3267 4_0_0 EXIST::FUNCTION:CMS -CMS_AuthEnvelopedData_create_ex 3268 4_0_0 EXIST::FUNCTION:CMS -CMS_EnvelopedData_create 3269 4_0_0 EXIST::FUNCTION:CMS -CMS_EnvelopedData_create_ex 3270 4_0_0 EXIST::FUNCTION:CMS -CMS_EnvelopedData_decrypt 3271 4_0_0 EXIST::FUNCTION:CMS -CMS_add1_recipient_cert 3272 4_0_0 EXIST::FUNCTION:CMS -CMS_add1_recipient 3273 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_set0_pkey 3274 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_ktri_cert_cmp 3275 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_ktri_get0_algs 3276 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_ktri_get0_signer_id 3277 4_0_0 EXIST::FUNCTION:CMS -CMS_add0_recipient_key 3278 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_kekri_get0_id 3279 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_set0_key 3280 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_kekri_id_cmp 3281 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_set0_password 3282 4_0_0 EXIST::FUNCTION:CMS -CMS_add0_recipient_password 3283 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_decrypt 3284 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_encrypt 3285 4_0_0 EXIST::FUNCTION:CMS -CMS_uncompress 3286 4_0_0 EXIST::FUNCTION:CMS -CMS_compress 3287 4_0_0 EXIST::FUNCTION:CMS -CMS_set1_eContentType 3288 4_0_0 EXIST::FUNCTION:CMS -CMS_get0_eContentType 3289 4_0_0 EXIST::FUNCTION:CMS -CMS_add0_CertificateChoices 3290 4_0_0 EXIST::FUNCTION:CMS -CMS_add0_cert 3291 4_0_0 EXIST::FUNCTION:CMS -CMS_add1_cert 3292 4_0_0 EXIST::FUNCTION:CMS -CMS_get1_certs 3293 4_0_0 EXIST::FUNCTION:CMS -CMS_add0_RevocationInfoChoice 3294 4_0_0 EXIST::FUNCTION:CMS -CMS_add0_crl 3295 4_0_0 EXIST::FUNCTION:CMS -CMS_add1_crl 3296 4_0_0 EXIST::FUNCTION:CMS -CMS_get1_crls 3297 4_0_0 EXIST::FUNCTION:CMS -CMS_SignedData_init 3298 4_0_0 EXIST::FUNCTION:CMS -CMS_add1_signer 3299 4_0_0 EXIST::FUNCTION:CMS -CMS_SignerInfo_get0_pkey_ctx 3300 4_0_0 EXIST::FUNCTION:CMS -CMS_SignerInfo_get0_md_ctx 3301 4_0_0 EXIST::FUNCTION:CMS -CMS_get0_SignerInfos 3302 4_0_0 EXIST::FUNCTION:CMS -CMS_SignerInfo_set1_signer_cert 3303 4_0_0 EXIST::FUNCTION:CMS -CMS_SignerInfo_get0_signer_id 3304 4_0_0 EXIST::FUNCTION:CMS -CMS_SignerInfo_cert_cmp 3305 4_0_0 EXIST::FUNCTION:CMS -CMS_set1_signers_certs 3306 4_0_0 EXIST::FUNCTION:CMS -CMS_SignerInfo_get0_algs 3307 4_0_0 EXIST::FUNCTION:CMS -CMS_SignerInfo_get0_signature 3308 4_0_0 EXIST::FUNCTION:CMS -CMS_SignerInfo_sign 3309 4_0_0 EXIST::FUNCTION:CMS -CMS_SignerInfo_verify 3310 4_0_0 EXIST::FUNCTION:CMS -CMS_SignerInfo_verify_content 3311 4_0_0 EXIST::FUNCTION:CMS -CMS_SignedData_verify 3312 4_0_0 EXIST::FUNCTION:CMS -CMS_add_smimecap 3313 4_0_0 EXIST::FUNCTION:CMS -CMS_add_simple_smimecap 3314 4_0_0 EXIST::FUNCTION:CMS -CMS_add_standard_smimecap 3315 4_0_0 EXIST::FUNCTION:CMS -CMS_signed_get_attr_count 3316 4_0_0 EXIST::FUNCTION:CMS -CMS_signed_get_attr_by_NID 3317 4_0_0 EXIST::FUNCTION:CMS -CMS_signed_get_attr_by_OBJ 3318 4_0_0 EXIST::FUNCTION:CMS -CMS_signed_get_attr 3319 4_0_0 EXIST::FUNCTION:CMS -CMS_signed_delete_attr 3320 4_0_0 EXIST::FUNCTION:CMS -CMS_signed_add1_attr 3321 4_0_0 EXIST::FUNCTION:CMS -CMS_signed_add1_attr_by_OBJ 3322 4_0_0 EXIST::FUNCTION:CMS -CMS_signed_add1_attr_by_NID 3323 4_0_0 EXIST::FUNCTION:CMS -CMS_signed_add1_attr_by_txt 3324 4_0_0 EXIST::FUNCTION:CMS -CMS_signed_get0_data_by_OBJ 3325 4_0_0 EXIST::FUNCTION:CMS -CMS_unsigned_get_attr_count 3326 4_0_0 EXIST::FUNCTION:CMS -CMS_unsigned_get_attr_by_NID 3327 4_0_0 EXIST::FUNCTION:CMS -CMS_unsigned_get_attr_by_OBJ 3328 4_0_0 EXIST::FUNCTION:CMS -CMS_unsigned_get_attr 3329 4_0_0 EXIST::FUNCTION:CMS -CMS_unsigned_delete_attr 3330 4_0_0 EXIST::FUNCTION:CMS -CMS_unsigned_add1_attr 3331 4_0_0 EXIST::FUNCTION:CMS -CMS_unsigned_add1_attr_by_OBJ 3332 4_0_0 EXIST::FUNCTION:CMS -CMS_unsigned_add1_attr_by_NID 3333 4_0_0 EXIST::FUNCTION:CMS -CMS_unsigned_add1_attr_by_txt 3334 4_0_0 EXIST::FUNCTION:CMS -CMS_unsigned_get0_data_by_OBJ 3335 4_0_0 EXIST::FUNCTION:CMS -CMS_get1_ReceiptRequest 3336 4_0_0 EXIST::FUNCTION:CMS -CMS_ReceiptRequest_create0 3337 4_0_0 EXIST::FUNCTION:CMS -CMS_ReceiptRequest_create0_ex 3338 4_0_0 EXIST::FUNCTION:CMS -CMS_add1_ReceiptRequest 3339 4_0_0 EXIST::FUNCTION:CMS -CMS_ReceiptRequest_get0_values 3340 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_kari_get0_alg 3341 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_kari_get0_reks 3342 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_kari_get0_orig_id 3343 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_kari_orig_id_cmp 3344 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientEncryptedKey_get0_id 3345 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientEncryptedKey_cert_cmp 3346 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_kari_set0_pkey 3347 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_kari_set0_pkey_and_peer 3348 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_kari_get0_ctx 3349 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_kari_decrypt 3350 4_0_0 EXIST::FUNCTION:CMS -CMS_SharedInfo_encode 3351 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_kemri_cert_cmp 3352 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_kemri_set0_pkey 3353 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_kemri_get0_ctx 3354 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_kemri_get0_kdf_alg 3355 4_0_0 EXIST::FUNCTION:CMS -CMS_RecipientInfo_kemri_set_ukm 3356 4_0_0 EXIST::FUNCTION:CMS -COMP_CTX_new 3357 4_0_0 EXIST::FUNCTION:COMP -COMP_CTX_get_method 3358 4_0_0 EXIST::FUNCTION:COMP -COMP_CTX_get_type 3359 4_0_0 EXIST::FUNCTION:COMP -COMP_get_type 3360 4_0_0 EXIST::FUNCTION:COMP -COMP_get_name 3361 4_0_0 EXIST::FUNCTION:COMP -COMP_CTX_free 3362 4_0_0 EXIST::FUNCTION:COMP -COMP_compress_block 3363 4_0_0 EXIST::FUNCTION:COMP -COMP_expand_block 3364 4_0_0 EXIST::FUNCTION:COMP -COMP_zlib 3365 4_0_0 EXIST::FUNCTION:COMP -COMP_zlib_oneshot 3366 4_0_0 EXIST::FUNCTION:COMP -COMP_brotli 3367 4_0_0 EXIST::FUNCTION:COMP -COMP_brotli_oneshot 3368 4_0_0 EXIST::FUNCTION:COMP -COMP_zstd 3369 4_0_0 EXIST::FUNCTION:COMP -COMP_zstd_oneshot 3370 4_0_0 EXIST::FUNCTION:COMP -BIO_f_zlib 3371 4_0_0 EXIST::FUNCTION:COMP -BIO_f_brotli 3372 4_0_0 EXIST::FUNCTION:COMP -BIO_f_zstd 3373 4_0_0 EXIST::FUNCTION:COMP -CONF_set_default_method 3374 4_0_0 EXIST::FUNCTION: -CONF_set_nconf 3375 4_0_0 EXIST::FUNCTION: -CONF_load 3376 4_0_0 EXIST::FUNCTION: -CONF_load_fp 3377 4_0_0 EXIST::FUNCTION:STDIO -CONF_load_bio 3378 4_0_0 EXIST::FUNCTION: -CONF_get_section 3379 4_0_0 EXIST::FUNCTION: -CONF_get_string 3380 4_0_0 EXIST::FUNCTION: -CONF_get_number 3381 4_0_0 EXIST::FUNCTION: -CONF_free 3382 4_0_0 EXIST::FUNCTION: -CONF_dump_fp 3383 4_0_0 EXIST::FUNCTION:STDIO -CONF_dump_bio 3384 4_0_0 EXIST::FUNCTION: -OPENSSL_config 3385 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0 -NCONF_new_ex 3386 4_0_0 EXIST::FUNCTION: -NCONF_get0_libctx 3387 4_0_0 EXIST::FUNCTION: -NCONF_new 3388 4_0_0 EXIST::FUNCTION: -NCONF_default 3389 4_0_0 EXIST::FUNCTION: -NCONF_WIN32 3390 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -NCONF_free 3391 4_0_0 EXIST::FUNCTION: -NCONF_free_data 3392 4_0_0 EXIST::FUNCTION: -NCONF_load 3393 4_0_0 EXIST::FUNCTION: -NCONF_load_fp 3394 4_0_0 EXIST::FUNCTION:STDIO -NCONF_load_bio 3395 4_0_0 EXIST::FUNCTION: -NCONF_get_section_names 3396 4_0_0 EXIST::FUNCTION: -NCONF_get_section 3397 4_0_0 EXIST::FUNCTION: -NCONF_get_string 3398 4_0_0 EXIST::FUNCTION: -NCONF_get_number_e 3399 4_0_0 EXIST::FUNCTION: -NCONF_dump_fp 3400 4_0_0 EXIST::FUNCTION:STDIO -NCONF_dump_bio 3401 4_0_0 EXIST::FUNCTION: -CONF_modules_load 3402 4_0_0 EXIST::FUNCTION: -CONF_modules_load_file_ex 3403 4_0_0 EXIST::FUNCTION: -CONF_modules_load_file 3404 4_0_0 EXIST::FUNCTION: -CONF_modules_unload 3405 4_0_0 EXIST::FUNCTION: -CONF_modules_finish 3406 4_0_0 EXIST::FUNCTION: -CONF_module_add 3407 4_0_0 EXIST::FUNCTION: -CONF_imodule_get_name 3408 4_0_0 EXIST::FUNCTION: -CONF_imodule_get_value 3409 4_0_0 EXIST::FUNCTION: -CONF_imodule_get_usr_data 3410 4_0_0 EXIST::FUNCTION: -CONF_imodule_set_usr_data 3411 4_0_0 EXIST::FUNCTION: -CONF_imodule_get_module 3412 4_0_0 EXIST::FUNCTION: -CONF_imodule_get_flags 3413 4_0_0 EXIST::FUNCTION: -CONF_imodule_set_flags 3414 4_0_0 EXIST::FUNCTION: -CONF_module_get_usr_data 3415 4_0_0 EXIST::FUNCTION: -CONF_module_set_usr_data 3416 4_0_0 EXIST::FUNCTION: -CONF_get1_default_config_file 3417 4_0_0 EXIST::FUNCTION: -CONF_parse_list 3418 4_0_0 EXIST::FUNCTION: -OPENSSL_load_builtin_modules 3419 4_0_0 EXIST::FUNCTION: -d2i_OSSL_CRMF_ENCRYPTEDVALUE 3420 4_0_0 EXIST::FUNCTION:CRMF -i2d_OSSL_CRMF_ENCRYPTEDVALUE 3421 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_ENCRYPTEDVALUE_free 3422 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_ENCRYPTEDVALUE_new 3423 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_ENCRYPTEDVALUE_it 3424 4_0_0 EXIST::FUNCTION:CRMF -d2i_OSSL_CRMF_ENCRYPTEDKEY 3425 4_0_0 EXIST::FUNCTION:CRMF -i2d_OSSL_CRMF_ENCRYPTEDKEY 3426 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_ENCRYPTEDKEY_free 3427 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_ENCRYPTEDKEY_new 3428 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_ENCRYPTEDKEY_it 3429 4_0_0 EXIST::FUNCTION:CRMF -d2i_OSSL_CRMF_MSG 3430 4_0_0 EXIST::FUNCTION:CRMF -i2d_OSSL_CRMF_MSG 3431 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_free 3432 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_new 3433 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_it 3434 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_dup 3435 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_ATTRIBUTETYPEANDVALUE_free 3436 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_ATTRIBUTETYPEANDVALUE_dup 3437 4_0_0 EXIST::FUNCTION:CRMF -d2i_OSSL_CRMF_PBMPARAMETER 3438 4_0_0 EXIST::FUNCTION:CRMF -i2d_OSSL_CRMF_PBMPARAMETER 3439 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_PBMPARAMETER_free 3440 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_PBMPARAMETER_new 3441 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_PBMPARAMETER_it 3442 4_0_0 EXIST::FUNCTION:CRMF -d2i_OSSL_CRMF_CERTID 3443 4_0_0 EXIST::FUNCTION:CRMF -i2d_OSSL_CRMF_CERTID 3444 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTID_free 3445 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTID_new 3446 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTID_it 3447 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTID_dup 3448 4_0_0 EXIST::FUNCTION:CRMF -d2i_OSSL_CRMF_PKIPUBLICATIONINFO 3449 4_0_0 EXIST::FUNCTION:CRMF -i2d_OSSL_CRMF_PKIPUBLICATIONINFO 3450 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_PKIPUBLICATIONINFO_free 3451 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_PKIPUBLICATIONINFO_new 3452 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_PKIPUBLICATIONINFO_it 3453 4_0_0 EXIST::FUNCTION:CRMF -d2i_OSSL_CRMF_SINGLEPUBINFO 3454 4_0_0 EXIST::FUNCTION:CRMF -i2d_OSSL_CRMF_SINGLEPUBINFO 3455 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_SINGLEPUBINFO_free 3456 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_SINGLEPUBINFO_new 3457 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_SINGLEPUBINFO_it 3458 4_0_0 EXIST::FUNCTION:CRMF -d2i_OSSL_CRMF_CERTTEMPLATE 3459 4_0_0 EXIST::FUNCTION:CRMF -i2d_OSSL_CRMF_CERTTEMPLATE 3460 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTTEMPLATE_free 3461 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTTEMPLATE_new 3462 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTTEMPLATE_it 3463 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTTEMPLATE_dup 3464 4_0_0 EXIST::FUNCTION:CRMF -d2i_OSSL_CRMF_MSGS 3465 4_0_0 EXIST::FUNCTION:CRMF -i2d_OSSL_CRMF_MSGS 3466 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSGS_free 3467 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSGS_new 3468 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSGS_it 3469 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_pbmp_new 3470 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_pbm_new 3471 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_set1_regCtrl_regToken 3472 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_get0_regCtrl_regToken 3473 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_set1_regCtrl_authenticator 3474 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_get0_regCtrl_authenticator 3475 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_PKIPublicationInfo_push0_SinglePubInfo 3476 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_set0_SinglePubInfo 3477 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_set_PKIPublicationInfo_action 3478 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_set1_regCtrl_pkiPublicationInfo 3479 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_get0_regCtrl_pkiPublicationInfo 3480 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_set1_regCtrl_protocolEncrKey 3481 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_get0_regCtrl_protocolEncrKey 3482 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_set1_regCtrl_oldCertID 3483 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_get0_regCtrl_oldCertID 3484 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTID_gen 3485 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_set1_regInfo_utf8Pairs 3486 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_get0_regInfo_utf8Pairs 3487 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_set1_regInfo_certReq 3488 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_get0_regInfo_certReq 3489 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_set0_validity 3490 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_set_certReqId 3491 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_get_certReqId 3492 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_set0_extensions 3493 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_push0_extension 3494 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_create_popo 3495 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSGS_verify_popo 3496 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_get0_tmpl 3497 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTTEMPLATE_get0_publicKey 3498 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTTEMPLATE_get0_subject 3499 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTTEMPLATE_get0_issuer 3500 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTTEMPLATE_get0_serialNumber 3501 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTTEMPLATE_get0_extensions 3502 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTID_get0_issuer 3503 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTID_get0_serialNumber 3504 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_CERTTEMPLATE_fill 3505 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert 3506 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_ENCRYPTEDKEY_get1_encCert 3507 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_ENCRYPTEDVALUE_decrypt 3508 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_ENCRYPTEDKEY_get1_pkey 3509 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_MSG_centralkeygen_requested 3510 4_0_0 EXIST::FUNCTION:CRMF -OSSL_CRMF_ENCRYPTEDKEY_init_envdata 3511 4_0_0 EXIST::FUNCTION:CMS,CRMF -CRYPTO_THREAD_lock_new 3512 4_0_0 EXIST::FUNCTION: -CRYPTO_THREAD_read_lock 3513 4_0_0 EXIST::FUNCTION: -CRYPTO_THREAD_write_lock 3514 4_0_0 EXIST::FUNCTION: -CRYPTO_THREAD_unlock 3515 4_0_0 EXIST::FUNCTION: -CRYPTO_THREAD_lock_free 3516 4_0_0 EXIST::FUNCTION: -CRYPTO_atomic_add 3517 4_0_0 EXIST::FUNCTION: -CRYPTO_atomic_add64 3518 4_0_0 EXIST::FUNCTION: -CRYPTO_atomic_and 3519 4_0_0 EXIST::FUNCTION: -CRYPTO_atomic_or 3520 4_0_0 EXIST::FUNCTION: -CRYPTO_atomic_load 3521 4_0_0 EXIST::FUNCTION: -CRYPTO_atomic_load_int 3522 4_0_0 EXIST::FUNCTION: -CRYPTO_atomic_store 3523 4_0_0 EXIST::FUNCTION: -CRYPTO_atomic_store_int 3524 4_0_0 EXIST::FUNCTION: -OPENSSL_strlcpy 3525 4_0_0 EXIST::FUNCTION: -OPENSSL_strlcat 3526 4_0_0 EXIST::FUNCTION: -OPENSSL_strnlen 3527 4_0_0 EXIST::FUNCTION: -OPENSSL_strtoul 3528 4_0_0 EXIST::FUNCTION: -OPENSSL_buf2hexstr_ex 3529 4_0_0 EXIST::FUNCTION: -OPENSSL_buf2hexstr 3530 4_0_0 EXIST::FUNCTION: -OPENSSL_hexstr2buf_ex 3531 4_0_0 EXIST::FUNCTION: -OPENSSL_hexstr2buf 3532 4_0_0 EXIST::FUNCTION: -OPENSSL_hexchar2int 3533 4_0_0 EXIST::FUNCTION: -OPENSSL_strcasecmp 3534 4_0_0 EXIST::FUNCTION: -OPENSSL_strncasecmp 3535 4_0_0 EXIST::FUNCTION: -OPENSSL_version_major 3536 4_0_0 EXIST::FUNCTION: -OPENSSL_version_minor 3537 4_0_0 EXIST::FUNCTION: -OPENSSL_version_patch 3538 4_0_0 EXIST::FUNCTION: -OPENSSL_version_pre_release 3539 4_0_0 EXIST::FUNCTION: -OPENSSL_version_build_metadata 3540 4_0_0 EXIST::FUNCTION: -OpenSSL_version_num 3541 4_0_0 EXIST::FUNCTION: -OpenSSL_version 3542 4_0_0 EXIST::FUNCTION: -OPENSSL_info 3543 4_0_0 EXIST::FUNCTION: -OPENSSL_issetugid 3544 4_0_0 EXIST::FUNCTION: -CRYPTO_get_ex_new_index 3545 4_0_0 EXIST::FUNCTION: -CRYPTO_free_ex_index 3546 4_0_0 EXIST::FUNCTION: -CRYPTO_new_ex_data 3547 4_0_0 EXIST::FUNCTION: -CRYPTO_dup_ex_data 3548 4_0_0 EXIST::FUNCTION: -CRYPTO_free_ex_data 3549 4_0_0 EXIST::FUNCTION: -CRYPTO_alloc_ex_data 3550 4_0_0 EXIST::FUNCTION: -CRYPTO_set_ex_data 3551 4_0_0 EXIST::FUNCTION: -CRYPTO_get_ex_data 3552 4_0_0 EXIST::FUNCTION: -CRYPTO_set_mem_functions 3553 4_0_0 EXIST::FUNCTION: -CRYPTO_get_mem_functions 3554 4_0_0 EXIST::FUNCTION: -CRYPTO_malloc 3555 4_0_0 EXIST::FUNCTION: -CRYPTO_zalloc 3556 4_0_0 EXIST::FUNCTION: -CRYPTO_malloc_array 3557 4_0_0 EXIST::FUNCTION: -CRYPTO_calloc 3558 4_0_0 EXIST::FUNCTION: -CRYPTO_aligned_alloc 3559 4_0_0 EXIST::FUNCTION: -CRYPTO_aligned_alloc_array 3560 4_0_0 EXIST::FUNCTION: -CRYPTO_memdup 3561 4_0_0 EXIST::FUNCTION: -CRYPTO_strdup 3562 4_0_0 EXIST::FUNCTION: -CRYPTO_strndup 3563 4_0_0 EXIST::FUNCTION: -CRYPTO_free 3564 4_0_0 EXIST::FUNCTION: -CRYPTO_clear_free 3565 4_0_0 EXIST::FUNCTION: -CRYPTO_realloc 3566 4_0_0 EXIST::FUNCTION: -CRYPTO_clear_realloc 3567 4_0_0 EXIST::FUNCTION: -CRYPTO_realloc_array 3568 4_0_0 EXIST::FUNCTION: -CRYPTO_clear_realloc_array 3569 4_0_0 EXIST::FUNCTION: -CRYPTO_secure_malloc_init 3570 4_0_0 EXIST::FUNCTION: -CRYPTO_secure_malloc_done 3571 4_0_0 EXIST::FUNCTION: -CRYPTO_secure_malloc 3572 4_0_0 EXIST::FUNCTION: -CRYPTO_secure_zalloc 3573 4_0_0 EXIST::FUNCTION: -CRYPTO_secure_malloc_array 3574 4_0_0 EXIST::FUNCTION: -CRYPTO_secure_calloc 3575 4_0_0 EXIST::FUNCTION: -CRYPTO_secure_free 3576 4_0_0 EXIST::FUNCTION: -CRYPTO_secure_clear_free 3577 4_0_0 EXIST::FUNCTION: -CRYPTO_secure_allocated 3578 4_0_0 EXIST::FUNCTION: -CRYPTO_secure_malloc_initialized 3579 4_0_0 EXIST::FUNCTION: -CRYPTO_secure_actual_size 3580 4_0_0 EXIST::FUNCTION: -CRYPTO_secure_used 3581 4_0_0 EXIST::FUNCTION: -OPENSSL_cleanse 3582 4_0_0 EXIST::FUNCTION: -CRYPTO_get_alloc_counts 3583 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG -CRYPTO_set_mem_debug 3584 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 -CRYPTO_mem_ctrl 3585 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 -CRYPTO_mem_debug_push 3586 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 -CRYPTO_mem_debug_pop 3587 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 -CRYPTO_mem_debug_malloc 3588 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 -CRYPTO_mem_debug_realloc 3589 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 -CRYPTO_mem_debug_free 3590 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 -CRYPTO_mem_leaks_cb 3591 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 -CRYPTO_mem_leaks_fp 3592 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0,STDIO -CRYPTO_mem_leaks 3593 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 -OPENSSL_die 3594 4_0_0 EXIST::FUNCTION: -OPENSSL_isservice 3595 4_0_0 EXIST::FUNCTION: -OPENSSL_init 3596 4_0_0 EXIST::FUNCTION: -OPENSSL_fork_prepare 3597 4_0_0 EXIST:UNIX:FUNCTION:DEPRECATEDIN_3_0 -OPENSSL_fork_parent 3598 4_0_0 EXIST:UNIX:FUNCTION:DEPRECATEDIN_3_0 -OPENSSL_fork_child 3599 4_0_0 EXIST:UNIX:FUNCTION:DEPRECATEDIN_3_0 -OPENSSL_gmtime 3600 4_0_0 EXIST::FUNCTION: -OPENSSL_gmtime_adj 3601 4_0_0 EXIST::FUNCTION: -OPENSSL_gmtime_diff 3602 4_0_0 EXIST::FUNCTION: -CRYPTO_memcmp 3603 4_0_0 EXIST::FUNCTION: -OPENSSL_cleanup 3604 4_0_0 EXIST::FUNCTION: -OPENSSL_init_crypto 3605 4_0_0 EXIST::FUNCTION: -OPENSSL_thread_stop 3606 4_0_0 EXIST::FUNCTION: -OPENSSL_thread_stop_ex 3607 4_0_0 EXIST::FUNCTION: -OPENSSL_INIT_new 3608 4_0_0 EXIST::FUNCTION: -OPENSSL_INIT_set_config_filename 3609 4_0_0 EXIST::FUNCTION:STDIO -OPENSSL_INIT_set_config_file_flags 3610 4_0_0 EXIST::FUNCTION:STDIO -OPENSSL_INIT_set_config_appname 3611 4_0_0 EXIST::FUNCTION:STDIO -OPENSSL_INIT_free 3612 4_0_0 EXIST::FUNCTION: -CRYPTO_THREAD_run_once 3613 4_0_0 EXIST::FUNCTION: -CRYPTO_THREAD_init_local 3614 4_0_0 EXIST::FUNCTION: -CRYPTO_THREAD_get_local 3615 4_0_0 EXIST::FUNCTION: -CRYPTO_THREAD_set_local 3616 4_0_0 EXIST::FUNCTION: -CRYPTO_THREAD_cleanup_local 3617 4_0_0 EXIST::FUNCTION: -CRYPTO_THREAD_get_current_id 3618 4_0_0 EXIST::FUNCTION: -CRYPTO_THREAD_compare_id 3619 4_0_0 EXIST::FUNCTION: -OSSL_LIB_CTX_new 3620 4_0_0 EXIST::FUNCTION: -OSSL_LIB_CTX_new_from_dispatch 3621 4_0_0 EXIST::FUNCTION: -OSSL_LIB_CTX_new_child 3622 4_0_0 EXIST::FUNCTION: -OSSL_LIB_CTX_load_config 3623 4_0_0 EXIST::FUNCTION: -OSSL_LIB_CTX_free 3624 4_0_0 EXIST::FUNCTION: -OSSL_LIB_CTX_get0_global_default 3625 4_0_0 EXIST::FUNCTION: -OSSL_LIB_CTX_set0_default 3626 4_0_0 EXIST::FUNCTION: -OSSL_LIB_CTX_get_conf_diagnostics 3627 4_0_0 EXIST::FUNCTION: -OSSL_LIB_CTX_set_conf_diagnostics 3628 4_0_0 EXIST::FUNCTION: -OSSL_sleep 3629 4_0_0 EXIST::FUNCTION: -OSSL_LIB_CTX_get_data 3630 4_0_0 EXIST::FUNCTION: -CT_POLICY_EVAL_CTX_new_ex 3631 4_0_0 EXIST::FUNCTION:CT -CT_POLICY_EVAL_CTX_new 3632 4_0_0 EXIST::FUNCTION:CT -CT_POLICY_EVAL_CTX_free 3633 4_0_0 EXIST::FUNCTION:CT -CT_POLICY_EVAL_CTX_get0_cert 3634 4_0_0 EXIST::FUNCTION:CT -CT_POLICY_EVAL_CTX_set1_cert 3635 4_0_0 EXIST::FUNCTION:CT -CT_POLICY_EVAL_CTX_get0_issuer 3636 4_0_0 EXIST::FUNCTION:CT -CT_POLICY_EVAL_CTX_set1_issuer 3637 4_0_0 EXIST::FUNCTION:CT -CT_POLICY_EVAL_CTX_get0_log_store 3638 4_0_0 EXIST::FUNCTION:CT -CT_POLICY_EVAL_CTX_set_shared_CTLOG_STORE 3639 4_0_0 EXIST::FUNCTION:CT -CT_POLICY_EVAL_CTX_get_time 3640 4_0_0 EXIST::FUNCTION:CT -CT_POLICY_EVAL_CTX_set_time 3641 4_0_0 EXIST::FUNCTION:CT -SCT_new 3642 4_0_0 EXIST::FUNCTION:CT -SCT_new_from_base64 3643 4_0_0 EXIST::FUNCTION:CT -SCT_free 3644 4_0_0 EXIST::FUNCTION:CT -SCT_LIST_free 3645 4_0_0 EXIST::FUNCTION:CT -SCT_get_version 3646 4_0_0 EXIST::FUNCTION:CT -SCT_set_version 3647 4_0_0 EXIST::FUNCTION:CT -SCT_get_log_entry_type 3648 4_0_0 EXIST::FUNCTION:CT -SCT_set_log_entry_type 3649 4_0_0 EXIST::FUNCTION:CT -SCT_get0_log_id 3650 4_0_0 EXIST::FUNCTION:CT -SCT_set0_log_id 3651 4_0_0 EXIST::FUNCTION:CT -SCT_set1_log_id 3652 4_0_0 EXIST::FUNCTION:CT -SCT_get_timestamp 3653 4_0_0 EXIST::FUNCTION:CT -SCT_set_timestamp 3654 4_0_0 EXIST::FUNCTION:CT -SCT_get_signature_nid 3655 4_0_0 EXIST::FUNCTION:CT -SCT_set_signature_nid 3656 4_0_0 EXIST::FUNCTION:CT -SCT_get0_extensions 3657 4_0_0 EXIST::FUNCTION:CT -SCT_set0_extensions 3658 4_0_0 EXIST::FUNCTION:CT -SCT_set1_extensions 3659 4_0_0 EXIST::FUNCTION:CT -SCT_get0_signature 3660 4_0_0 EXIST::FUNCTION:CT -SCT_set0_signature 3661 4_0_0 EXIST::FUNCTION:CT -SCT_set1_signature 3662 4_0_0 EXIST::FUNCTION:CT -SCT_get_source 3663 4_0_0 EXIST::FUNCTION:CT -SCT_set_source 3664 4_0_0 EXIST::FUNCTION:CT -SCT_validation_status_string 3665 4_0_0 EXIST::FUNCTION:CT -SCT_print 3666 4_0_0 EXIST::FUNCTION:CT -SCT_LIST_print 3667 4_0_0 EXIST::FUNCTION:CT -SCT_get_validation_status 3668 4_0_0 EXIST::FUNCTION:CT -SCT_validate 3669 4_0_0 EXIST::FUNCTION:CT -SCT_LIST_validate 3670 4_0_0 EXIST::FUNCTION:CT -i2o_SCT_LIST 3671 4_0_0 EXIST::FUNCTION:CT -o2i_SCT_LIST 3672 4_0_0 EXIST::FUNCTION:CT -i2d_SCT_LIST 3673 4_0_0 EXIST::FUNCTION:CT -d2i_SCT_LIST 3674 4_0_0 EXIST::FUNCTION:CT -i2o_SCT 3675 4_0_0 EXIST::FUNCTION:CT -o2i_SCT 3676 4_0_0 EXIST::FUNCTION:CT -CTLOG_new_ex 3677 4_0_0 EXIST::FUNCTION:CT -CTLOG_new 3678 4_0_0 EXIST::FUNCTION:CT -CTLOG_new_from_base64_ex 3679 4_0_0 EXIST::FUNCTION:CT -CTLOG_new_from_base64 3680 4_0_0 EXIST::FUNCTION:CT -CTLOG_free 3681 4_0_0 EXIST::FUNCTION:CT -CTLOG_get0_name 3682 4_0_0 EXIST::FUNCTION:CT -CTLOG_get0_log_id 3683 4_0_0 EXIST::FUNCTION:CT -CTLOG_get0_public_key 3684 4_0_0 EXIST::FUNCTION:CT -CTLOG_STORE_new_ex 3685 4_0_0 EXIST::FUNCTION:CT -CTLOG_STORE_new 3686 4_0_0 EXIST::FUNCTION:CT -CTLOG_STORE_free 3687 4_0_0 EXIST::FUNCTION:CT -CTLOG_STORE_get0_log_by_id 3688 4_0_0 EXIST::FUNCTION:CT -CTLOG_STORE_load_file 3689 4_0_0 EXIST::FUNCTION:CT -CTLOG_STORE_load_default_file 3690 4_0_0 EXIST::FUNCTION:CT -ERR_new 3691 4_0_0 EXIST::FUNCTION: -ERR_set_debug 3692 4_0_0 EXIST::FUNCTION: -ERR_set_error 3693 4_0_0 EXIST::FUNCTION: -ERR_vset_error 3694 4_0_0 EXIST::FUNCTION: -ERR_set_error_data 3695 4_0_0 EXIST::FUNCTION: -ERR_get_error 3696 4_0_0 EXIST::FUNCTION: -ERR_get_error_all 3697 4_0_0 EXIST::FUNCTION: -ERR_get_error_line 3698 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_get_error_line_data 3699 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_peek_error 3700 4_0_0 EXIST::FUNCTION: -ERR_peek_error_line 3701 4_0_0 EXIST::FUNCTION: -ERR_peek_error_func 3702 4_0_0 EXIST::FUNCTION: -ERR_peek_error_data 3703 4_0_0 EXIST::FUNCTION: -ERR_peek_error_all 3704 4_0_0 EXIST::FUNCTION: -ERR_peek_error_line_data 3705 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_peek_last_error 3706 4_0_0 EXIST::FUNCTION: -ERR_peek_last_error_line 3707 4_0_0 EXIST::FUNCTION: -ERR_peek_last_error_func 3708 4_0_0 EXIST::FUNCTION: -ERR_peek_last_error_data 3709 4_0_0 EXIST::FUNCTION: -ERR_peek_last_error_all 3710 4_0_0 EXIST::FUNCTION: -ERR_peek_last_error_line_data 3711 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_clear_error 3712 4_0_0 EXIST::FUNCTION: -ERR_error_string 3713 4_0_0 EXIST::FUNCTION: -ERR_error_string_n 3714 4_0_0 EXIST::FUNCTION: -ERR_lib_error_string 3715 4_0_0 EXIST::FUNCTION: -ERR_func_error_string 3716 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ERR_reason_error_string 3717 4_0_0 EXIST::FUNCTION: -ERR_print_errors_cb 3718 4_0_0 EXIST::FUNCTION: -ERR_print_errors_fp 3719 4_0_0 EXIST::FUNCTION:STDIO -ERR_print_errors 3720 4_0_0 EXIST::FUNCTION: -ERR_add_error_data 3721 4_0_0 EXIST::FUNCTION: -ERR_add_error_vdata 3722 4_0_0 EXIST::FUNCTION: -ERR_add_error_txt 3723 4_0_0 EXIST::FUNCTION: -ERR_add_error_mem_bio 3724 4_0_0 EXIST::FUNCTION: -ERR_load_strings 3725 4_0_0 EXIST::FUNCTION: -ERR_load_strings_const 3726 4_0_0 EXIST::FUNCTION: -ERR_unload_strings 3727 4_0_0 EXIST::FUNCTION: -ERR_get_next_error_library 3728 4_0_0 EXIST::FUNCTION: -ERR_set_mark 3729 4_0_0 EXIST::FUNCTION: -ERR_pop_to_mark 3730 4_0_0 EXIST::FUNCTION: -ERR_clear_last_mark 3731 4_0_0 EXIST::FUNCTION: -ERR_count_to_mark 3732 4_0_0 EXIST::FUNCTION: -ERR_pop 3733 4_0_0 EXIST::FUNCTION: -OSSL_ERR_STATE_new 3734 4_0_0 EXIST::FUNCTION: -OSSL_ERR_STATE_save 3735 4_0_0 EXIST::FUNCTION: -OSSL_ERR_STATE_save_to_mark 3736 4_0_0 EXIST::FUNCTION: -OSSL_ERR_STATE_restore 3737 4_0_0 EXIST::FUNCTION: -OSSL_ERR_STATE_free 3738 4_0_0 EXIST::FUNCTION: -ESS_ISSUER_SERIAL_free 3739 4_0_0 EXIST::FUNCTION: -ESS_ISSUER_SERIAL_new 3740 4_0_0 EXIST::FUNCTION: -d2i_ESS_ISSUER_SERIAL 3741 4_0_0 EXIST::FUNCTION: -i2d_ESS_ISSUER_SERIAL 3742 4_0_0 EXIST::FUNCTION: -ESS_ISSUER_SERIAL_dup 3743 4_0_0 EXIST::FUNCTION: -ESS_CERT_ID_free 3744 4_0_0 EXIST::FUNCTION: -ESS_CERT_ID_new 3745 4_0_0 EXIST::FUNCTION: -d2i_ESS_CERT_ID 3746 4_0_0 EXIST::FUNCTION: -i2d_ESS_CERT_ID 3747 4_0_0 EXIST::FUNCTION: -ESS_CERT_ID_dup 3748 4_0_0 EXIST::FUNCTION: -d2i_ESS_SIGNING_CERT 3749 4_0_0 EXIST::FUNCTION: -i2d_ESS_SIGNING_CERT 3750 4_0_0 EXIST::FUNCTION: -ESS_SIGNING_CERT_free 3751 4_0_0 EXIST::FUNCTION: -ESS_SIGNING_CERT_new 3752 4_0_0 EXIST::FUNCTION: -ESS_SIGNING_CERT_it 3753 4_0_0 EXIST::FUNCTION: -ESS_SIGNING_CERT_dup 3754 4_0_0 EXIST::FUNCTION: -ESS_CERT_ID_V2_free 3755 4_0_0 EXIST::FUNCTION: -ESS_CERT_ID_V2_new 3756 4_0_0 EXIST::FUNCTION: -d2i_ESS_CERT_ID_V2 3757 4_0_0 EXIST::FUNCTION: -i2d_ESS_CERT_ID_V2 3758 4_0_0 EXIST::FUNCTION: -ESS_CERT_ID_V2_dup 3759 4_0_0 EXIST::FUNCTION: -d2i_ESS_SIGNING_CERT_V2 3760 4_0_0 EXIST::FUNCTION: -i2d_ESS_SIGNING_CERT_V2 3761 4_0_0 EXIST::FUNCTION: -ESS_SIGNING_CERT_V2_free 3762 4_0_0 EXIST::FUNCTION: -ESS_SIGNING_CERT_V2_new 3763 4_0_0 EXIST::FUNCTION: -ESS_SIGNING_CERT_V2_it 3764 4_0_0 EXIST::FUNCTION: -ESS_SIGNING_CERT_V2_dup 3765 4_0_0 EXIST::FUNCTION: -OSSL_ESS_signing_cert_new_init 3766 4_0_0 EXIST::FUNCTION: -OSSL_ESS_signing_cert_v2_new_init 3767 4_0_0 EXIST::FUNCTION: -OSSL_ESS_check_signing_certs 3768 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_error 3769 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_new 3770 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_set_thunks 3771 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_free 3772 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_flush 3773 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_insert 3774 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_delete 3775 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_retrieve 3776 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_doall 3777 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_doall_arg 3778 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_doall_arg_thunk 3779 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_strhash 3780 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_num_items 3781 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_get_down_load 3782 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_set_down_load 3783 4_0_0 EXIST::FUNCTION: -OPENSSL_LH_stats 3784 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_1,STDIO -OPENSSL_LH_node_stats 3785 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_1,STDIO -OPENSSL_LH_node_usage_stats 3786 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_1,STDIO -OPENSSL_LH_stats_bio 3787 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_1 -OPENSSL_LH_node_stats_bio 3788 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_1 -OPENSSL_LH_node_usage_stats_bio 3789 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_1 -OCSP_CERTID_dup 3790 4_0_0 EXIST::FUNCTION:OCSP -OCSP_sendreq_new 3791 4_0_0 EXIST::FUNCTION:OCSP -OCSP_sendreq_bio 3792 4_0_0 EXIST::FUNCTION:OCSP -OCSP_cert_to_id 3793 4_0_0 EXIST::FUNCTION:OCSP -OCSP_cert_id_new 3794 4_0_0 EXIST::FUNCTION:OCSP -OCSP_request_add0_id 3795 4_0_0 EXIST::FUNCTION:OCSP -OCSP_request_add1_nonce 3796 4_0_0 EXIST::FUNCTION:OCSP -OCSP_basic_add1_nonce 3797 4_0_0 EXIST::FUNCTION:OCSP -OCSP_check_nonce 3798 4_0_0 EXIST::FUNCTION:OCSP -OCSP_copy_nonce 3799 4_0_0 EXIST::FUNCTION:OCSP -OCSP_request_set1_name 3800 4_0_0 EXIST::FUNCTION:OCSP -OCSP_request_add1_cert 3801 4_0_0 EXIST::FUNCTION:OCSP -OCSP_request_sign 3802 4_0_0 EXIST::FUNCTION:OCSP -OCSP_response_status 3803 4_0_0 EXIST::FUNCTION:OCSP -OCSP_response_get1_basic 3804 4_0_0 EXIST::FUNCTION:OCSP -OCSP_resp_get0_signature 3805 4_0_0 EXIST::FUNCTION:OCSP -OCSP_resp_get0_tbs_sigalg 3806 4_0_0 EXIST::FUNCTION:OCSP -OCSP_resp_get0_respdata 3807 4_0_0 EXIST::FUNCTION:OCSP -OCSP_resp_get0_signer 3808 4_0_0 EXIST::FUNCTION:OCSP -OCSP_resp_count 3809 4_0_0 EXIST::FUNCTION:OCSP -OCSP_resp_get0 3810 4_0_0 EXIST::FUNCTION:OCSP -OCSP_resp_get0_produced_at 3811 4_0_0 EXIST::FUNCTION:OCSP -OCSP_resp_get0_certs 3812 4_0_0 EXIST::FUNCTION:OCSP -OCSP_resp_get0_id 3813 4_0_0 EXIST::FUNCTION:OCSP -OCSP_resp_get1_id 3814 4_0_0 EXIST::FUNCTION:OCSP -OCSP_resp_find 3815 4_0_0 EXIST::FUNCTION:OCSP -OCSP_single_get0_status 3816 4_0_0 EXIST::FUNCTION:OCSP -OCSP_resp_find_status 3817 4_0_0 EXIST::FUNCTION:OCSP -OCSP_check_validity 3818 4_0_0 EXIST::FUNCTION:OCSP -OCSP_request_verify 3819 4_0_0 EXIST::FUNCTION:OCSP -OCSP_id_issuer_cmp 3820 4_0_0 EXIST::FUNCTION:OCSP -OCSP_id_cmp 3821 4_0_0 EXIST::FUNCTION:OCSP -OCSP_request_onereq_count 3822 4_0_0 EXIST::FUNCTION:OCSP -OCSP_request_onereq_get0 3823 4_0_0 EXIST::FUNCTION:OCSP -OCSP_onereq_get0_id 3824 4_0_0 EXIST::FUNCTION:OCSP -OCSP_id_get0_info 3825 4_0_0 EXIST::FUNCTION:OCSP -OCSP_request_is_signed 3826 4_0_0 EXIST::FUNCTION:OCSP -OCSP_response_create 3827 4_0_0 EXIST::FUNCTION:OCSP -OCSP_basic_add1_status 3828 4_0_0 EXIST::FUNCTION:OCSP -OCSP_basic_add1_cert 3829 4_0_0 EXIST::FUNCTION:OCSP -OCSP_basic_sign 3830 4_0_0 EXIST::FUNCTION:OCSP -OCSP_basic_sign_ctx 3831 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPID_set_by_name 3832 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPID_set_by_key_ex 3833 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPID_set_by_key 3834 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPID_match_ex 3835 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPID_match 3836 4_0_0 EXIST::FUNCTION:OCSP -OCSP_crlID_new 3837 4_0_0 EXIST:!VMS:FUNCTION:OCSP -OCSP_crlID2_new 3837 4_0_0 EXIST:VMS:FUNCTION:OCSP -OCSP_accept_responses_new 3838 4_0_0 EXIST::FUNCTION:OCSP -OCSP_archive_cutoff_new 3839 4_0_0 EXIST::FUNCTION:OCSP -OCSP_url_svcloc_new 3840 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQUEST_get_ext_count 3841 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQUEST_get_ext_by_NID 3842 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQUEST_get_ext_by_OBJ 3843 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQUEST_get_ext_by_critical 3844 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQUEST_get_ext 3845 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQUEST_delete_ext 3846 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQUEST_get1_ext_d2i 3847 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQUEST_add1_ext_i2d 3848 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQUEST_add_ext 3849 4_0_0 EXIST::FUNCTION:OCSP -OCSP_ONEREQ_get_ext_count 3850 4_0_0 EXIST::FUNCTION:OCSP -OCSP_ONEREQ_get_ext_by_NID 3851 4_0_0 EXIST::FUNCTION:OCSP -OCSP_ONEREQ_get_ext_by_OBJ 3852 4_0_0 EXIST::FUNCTION:OCSP -OCSP_ONEREQ_get_ext_by_critical 3853 4_0_0 EXIST::FUNCTION:OCSP -OCSP_ONEREQ_get_ext 3854 4_0_0 EXIST::FUNCTION:OCSP -OCSP_ONEREQ_delete_ext 3855 4_0_0 EXIST::FUNCTION:OCSP -OCSP_ONEREQ_get1_ext_d2i 3856 4_0_0 EXIST::FUNCTION:OCSP -OCSP_ONEREQ_add1_ext_i2d 3857 4_0_0 EXIST::FUNCTION:OCSP -OCSP_ONEREQ_add_ext 3858 4_0_0 EXIST::FUNCTION:OCSP -OCSP_BASICRESP_get_ext_count 3859 4_0_0 EXIST::FUNCTION:OCSP -OCSP_BASICRESP_get_ext_by_NID 3860 4_0_0 EXIST::FUNCTION:OCSP -OCSP_BASICRESP_get_ext_by_OBJ 3861 4_0_0 EXIST::FUNCTION:OCSP -OCSP_BASICRESP_get_ext_by_critical 3862 4_0_0 EXIST::FUNCTION:OCSP -OCSP_BASICRESP_get_ext 3863 4_0_0 EXIST::FUNCTION:OCSP -OCSP_BASICRESP_delete_ext 3864 4_0_0 EXIST::FUNCTION:OCSP -OCSP_BASICRESP_get1_ext_d2i 3865 4_0_0 EXIST::FUNCTION:OCSP -OCSP_BASICRESP_add1_ext_i2d 3866 4_0_0 EXIST::FUNCTION:OCSP -OCSP_BASICRESP_add_ext 3867 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SINGLERESP_get_ext_count 3868 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SINGLERESP_get_ext_by_NID 3869 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SINGLERESP_get_ext_by_OBJ 3870 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SINGLERESP_get_ext_by_critical 3871 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SINGLERESP_get_ext 3872 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SINGLERESP_delete_ext 3873 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SINGLERESP_get1_ext_d2i 3874 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SINGLERESP_add1_ext_i2d 3875 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SINGLERESP_add_ext 3876 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SINGLERESP_get0_id 3877 4_0_0 EXIST::FUNCTION:OCSP -d2i_OCSP_SINGLERESP 3878 4_0_0 EXIST::FUNCTION:OCSP -i2d_OCSP_SINGLERESP 3879 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SINGLERESP_free 3880 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SINGLERESP_new 3881 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SINGLERESP_it 3882 4_0_0 EXIST::FUNCTION:OCSP -d2i_OCSP_CERTSTATUS 3883 4_0_0 EXIST::FUNCTION:OCSP -i2d_OCSP_CERTSTATUS 3884 4_0_0 EXIST::FUNCTION:OCSP -OCSP_CERTSTATUS_free 3885 4_0_0 EXIST::FUNCTION:OCSP -OCSP_CERTSTATUS_new 3886 4_0_0 EXIST::FUNCTION:OCSP -OCSP_CERTSTATUS_it 3887 4_0_0 EXIST::FUNCTION:OCSP -d2i_OCSP_REVOKEDINFO 3888 4_0_0 EXIST::FUNCTION:OCSP -i2d_OCSP_REVOKEDINFO 3889 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REVOKEDINFO_free 3890 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REVOKEDINFO_new 3891 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REVOKEDINFO_it 3892 4_0_0 EXIST::FUNCTION:OCSP -d2i_OCSP_BASICRESP 3893 4_0_0 EXIST::FUNCTION:OCSP -i2d_OCSP_BASICRESP 3894 4_0_0 EXIST::FUNCTION:OCSP -OCSP_BASICRESP_free 3895 4_0_0 EXIST::FUNCTION:OCSP -OCSP_BASICRESP_new 3896 4_0_0 EXIST::FUNCTION:OCSP -OCSP_BASICRESP_it 3897 4_0_0 EXIST::FUNCTION:OCSP -d2i_OCSP_RESPDATA 3898 4_0_0 EXIST::FUNCTION:OCSP -i2d_OCSP_RESPDATA 3899 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPDATA_free 3900 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPDATA_new 3901 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPDATA_it 3902 4_0_0 EXIST::FUNCTION:OCSP -d2i_OCSP_RESPID 3903 4_0_0 EXIST::FUNCTION:OCSP -i2d_OCSP_RESPID 3904 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPID_free 3905 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPID_new 3906 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPID_it 3907 4_0_0 EXIST::FUNCTION:OCSP -d2i_OCSP_RESPONSE 3908 4_0_0 EXIST::FUNCTION:OCSP -i2d_OCSP_RESPONSE 3909 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPONSE_free 3910 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPONSE_new 3911 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPONSE_it 3912 4_0_0 EXIST::FUNCTION:OCSP -d2i_OCSP_RESPBYTES 3913 4_0_0 EXIST::FUNCTION:OCSP -i2d_OCSP_RESPBYTES 3914 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPBYTES_free 3915 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPBYTES_new 3916 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPBYTES_it 3917 4_0_0 EXIST::FUNCTION:OCSP -d2i_OCSP_ONEREQ 3918 4_0_0 EXIST::FUNCTION:OCSP -i2d_OCSP_ONEREQ 3919 4_0_0 EXIST::FUNCTION:OCSP -OCSP_ONEREQ_free 3920 4_0_0 EXIST::FUNCTION:OCSP -OCSP_ONEREQ_new 3921 4_0_0 EXIST::FUNCTION:OCSP -OCSP_ONEREQ_it 3922 4_0_0 EXIST::FUNCTION:OCSP -d2i_OCSP_CERTID 3923 4_0_0 EXIST::FUNCTION:OCSP -i2d_OCSP_CERTID 3924 4_0_0 EXIST::FUNCTION:OCSP -OCSP_CERTID_free 3925 4_0_0 EXIST::FUNCTION:OCSP -OCSP_CERTID_new 3926 4_0_0 EXIST::FUNCTION:OCSP -OCSP_CERTID_it 3927 4_0_0 EXIST::FUNCTION:OCSP -d2i_OCSP_REQUEST 3928 4_0_0 EXIST::FUNCTION:OCSP -i2d_OCSP_REQUEST 3929 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQUEST_free 3930 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQUEST_new 3931 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQUEST_it 3932 4_0_0 EXIST::FUNCTION:OCSP -d2i_OCSP_SIGNATURE 3933 4_0_0 EXIST::FUNCTION:OCSP -i2d_OCSP_SIGNATURE 3934 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SIGNATURE_free 3935 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SIGNATURE_new 3936 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SIGNATURE_it 3937 4_0_0 EXIST::FUNCTION:OCSP -d2i_OCSP_REQINFO 3938 4_0_0 EXIST::FUNCTION:OCSP -i2d_OCSP_REQINFO 3939 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQINFO_free 3940 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQINFO_new 3941 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQINFO_it 3942 4_0_0 EXIST::FUNCTION:OCSP -d2i_OCSP_CRLID 3943 4_0_0 EXIST::FUNCTION:OCSP -i2d_OCSP_CRLID 3944 4_0_0 EXIST::FUNCTION:OCSP -OCSP_CRLID_free 3945 4_0_0 EXIST::FUNCTION:OCSP -OCSP_CRLID_new 3946 4_0_0 EXIST::FUNCTION:OCSP -OCSP_CRLID_it 3947 4_0_0 EXIST::FUNCTION:OCSP -d2i_OCSP_SERVICELOC 3948 4_0_0 EXIST::FUNCTION:OCSP -i2d_OCSP_SERVICELOC 3949 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SERVICELOC_free 3950 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SERVICELOC_new 3951 4_0_0 EXIST::FUNCTION:OCSP -OCSP_SERVICELOC_it 3952 4_0_0 EXIST::FUNCTION:OCSP -OCSP_response_status_str 3953 4_0_0 EXIST::FUNCTION:OCSP -OCSP_cert_status_str 3954 4_0_0 EXIST::FUNCTION:OCSP -OCSP_crl_reason_str 3955 4_0_0 EXIST::FUNCTION:OCSP -OCSP_REQUEST_print 3956 4_0_0 EXIST::FUNCTION:OCSP -OCSP_RESPONSE_print 3957 4_0_0 EXIST::FUNCTION:OCSP -OCSP_basic_verify 3958 4_0_0 EXIST::FUNCTION:OCSP -PKCS12_get_attr 3959 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0 -PKCS8_get_attr 3960 4_0_0 EXIST::FUNCTION: -PKCS12_mac_present 3961 4_0_0 EXIST::FUNCTION: -PKCS12_get0_mac 3962 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_get0_attr 3963 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_get0_type 3964 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_get_nid 3965 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_get_bag_nid 3966 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_get0_bag_obj 3967 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_get0_bag_type 3968 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_get1_cert_ex 3969 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_get1_cert 3970 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_get1_crl_ex 3971 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_get1_crl 3972 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_get0_safes 3973 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_get0_p8inf 3974 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_get0_pkcs8 3975 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_create_cert 3976 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_create_crl 3977 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_create_secret 3978 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_create0_p8inf 3979 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_create0_pkcs8 3980 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_create_pkcs8_encrypt 3981 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_create_pkcs8_encrypt_ex 3982 4_0_0 EXIST::FUNCTION: -PKCS12_item_pack_safebag 3983 4_0_0 EXIST::FUNCTION: -PKCS8_decrypt 3984 4_0_0 EXIST::FUNCTION: -PKCS8_decrypt_ex 3985 4_0_0 EXIST::FUNCTION: -PKCS12_decrypt_skey 3986 4_0_0 EXIST::FUNCTION: -PKCS12_decrypt_skey_ex 3987 4_0_0 EXIST::FUNCTION: -PKCS8_encrypt 3988 4_0_0 EXIST::FUNCTION: -PKCS8_encrypt_ex 3989 4_0_0 EXIST::FUNCTION: -PKCS8_set0_pbe 3990 4_0_0 EXIST::FUNCTION: -PKCS8_set0_pbe_ex 3991 4_0_0 EXIST::FUNCTION: -PKCS12_pack_p7data 3992 4_0_0 EXIST::FUNCTION: -PKCS12_unpack_p7data 3993 4_0_0 EXIST::FUNCTION: -PKCS12_pack_p7encdata 3994 4_0_0 EXIST::FUNCTION: -PKCS12_pack_p7encdata_ex 3995 4_0_0 EXIST::FUNCTION: -PKCS12_unpack_p7encdata 3996 4_0_0 EXIST::FUNCTION: -PKCS12_pack_authsafes 3997 4_0_0 EXIST::FUNCTION: -PKCS12_unpack_authsafes 3998 4_0_0 EXIST::FUNCTION: -PKCS12_add_localkeyid 3999 4_0_0 EXIST::FUNCTION: -PKCS12_add_friendlyname_asc 4000 4_0_0 EXIST::FUNCTION: -PKCS12_add_friendlyname_utf8 4001 4_0_0 EXIST::FUNCTION: -PKCS12_add_CSPName_asc 4002 4_0_0 EXIST::FUNCTION: -PKCS12_add_friendlyname_uni 4003 4_0_0 EXIST::FUNCTION: -PKCS12_add1_attr_by_NID 4004 4_0_0 EXIST::FUNCTION: -PKCS12_add1_attr_by_txt 4005 4_0_0 EXIST::FUNCTION: -PKCS8_add_keyusage 4006 4_0_0 EXIST::FUNCTION: -PKCS12_get_attr_gen 4007 4_0_0 EXIST::FUNCTION: -PKCS12_get_friendlyname 4008 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_get0_attrs 4009 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_set0_attrs 4010 4_0_0 EXIST::FUNCTION: -PKCS12_pbe_crypt 4011 4_0_0 EXIST::FUNCTION: -PKCS12_pbe_crypt_ex 4012 4_0_0 EXIST::FUNCTION: -PKCS12_item_decrypt_d2i 4013 4_0_0 EXIST::FUNCTION: -PKCS12_item_decrypt_d2i_ex 4014 4_0_0 EXIST::FUNCTION: -PKCS12_item_i2d_encrypt 4015 4_0_0 EXIST::FUNCTION: -PKCS12_item_i2d_encrypt_ex 4016 4_0_0 EXIST::FUNCTION: -PKCS12_init 4017 4_0_0 EXIST::FUNCTION: -PKCS12_init_ex 4018 4_0_0 EXIST::FUNCTION: -PKCS12_key_gen_asc 4019 4_0_0 EXIST::FUNCTION: -PKCS12_key_gen_asc_ex 4020 4_0_0 EXIST::FUNCTION: -PKCS12_key_gen_uni 4021 4_0_0 EXIST::FUNCTION: -PKCS12_key_gen_uni_ex 4022 4_0_0 EXIST::FUNCTION: -PKCS12_key_gen_utf8 4023 4_0_0 EXIST::FUNCTION: -PKCS12_key_gen_utf8_ex 4024 4_0_0 EXIST::FUNCTION: -PKCS12_PBE_keyivgen 4025 4_0_0 EXIST::FUNCTION: -PKCS12_PBE_keyivgen_ex 4026 4_0_0 EXIST::FUNCTION: -PKCS12_gen_mac 4027 4_0_0 EXIST::FUNCTION: -PKCS12_verify_mac 4028 4_0_0 EXIST::FUNCTION: -PKCS12_set_mac 4029 4_0_0 EXIST::FUNCTION: -PKCS12_set_pbmac1_pbkdf2 4030 4_0_0 EXIST::FUNCTION: -PKCS12_setup_mac 4031 4_0_0 EXIST::FUNCTION: -OPENSSL_asc2uni 4032 4_0_0 EXIST::FUNCTION: -OPENSSL_uni2asc 4033 4_0_0 EXIST::FUNCTION: -OPENSSL_utf82uni 4034 4_0_0 EXIST::FUNCTION: -OPENSSL_uni2utf8 4035 4_0_0 EXIST::FUNCTION: -d2i_PKCS12 4036 4_0_0 EXIST::FUNCTION: -i2d_PKCS12 4037 4_0_0 EXIST::FUNCTION: -PKCS12_free 4038 4_0_0 EXIST::FUNCTION: -PKCS12_new 4039 4_0_0 EXIST::FUNCTION: -PKCS12_it 4040 4_0_0 EXIST::FUNCTION: -d2i_PKCS12_MAC_DATA 4041 4_0_0 EXIST::FUNCTION: -i2d_PKCS12_MAC_DATA 4042 4_0_0 EXIST::FUNCTION: -PKCS12_MAC_DATA_free 4043 4_0_0 EXIST::FUNCTION: -PKCS12_MAC_DATA_new 4044 4_0_0 EXIST::FUNCTION: -PKCS12_MAC_DATA_it 4045 4_0_0 EXIST::FUNCTION: -d2i_PKCS12_SAFEBAG 4046 4_0_0 EXIST::FUNCTION: -i2d_PKCS12_SAFEBAG 4047 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_free 4048 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_new 4049 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAG_it 4050 4_0_0 EXIST::FUNCTION: -d2i_PKCS12_BAGS 4051 4_0_0 EXIST::FUNCTION: -i2d_PKCS12_BAGS 4052 4_0_0 EXIST::FUNCTION: -PKCS12_BAGS_free 4053 4_0_0 EXIST::FUNCTION: -PKCS12_BAGS_new 4054 4_0_0 EXIST::FUNCTION: -PKCS12_BAGS_it 4055 4_0_0 EXIST::FUNCTION: -PKCS12_SAFEBAGS_it 4056 4_0_0 EXIST::FUNCTION: -PKCS12_AUTHSAFES_it 4057 4_0_0 EXIST::FUNCTION: -PKCS12_PBE_add 4058 4_0_0 EXIST::FUNCTION: -PKCS12_parse 4059 4_0_0 EXIST::FUNCTION: -PKCS12_create 4060 4_0_0 EXIST::FUNCTION: -PKCS12_create_ex 4061 4_0_0 EXIST::FUNCTION: -PKCS12_create_ex2 4062 4_0_0 EXIST::FUNCTION: -PKCS12_add_cert 4063 4_0_0 EXIST::FUNCTION: -PKCS12_add_key 4064 4_0_0 EXIST::FUNCTION: -PKCS12_add_key_ex 4065 4_0_0 EXIST::FUNCTION: -PKCS12_add_secret 4066 4_0_0 EXIST::FUNCTION: -PKCS12_add_safe 4067 4_0_0 EXIST::FUNCTION: -PKCS12_add_safe_ex 4068 4_0_0 EXIST::FUNCTION: -PKCS12_add_safes 4069 4_0_0 EXIST::FUNCTION: -PKCS12_add_safes_ex 4070 4_0_0 EXIST::FUNCTION: -i2d_PKCS12_bio 4071 4_0_0 EXIST::FUNCTION: -i2d_PKCS12_fp 4072 4_0_0 EXIST::FUNCTION:STDIO -d2i_PKCS12_bio 4073 4_0_0 EXIST::FUNCTION: -d2i_PKCS12_fp 4074 4_0_0 EXIST::FUNCTION:STDIO -PKCS12_newpass 4075 4_0_0 EXIST::FUNCTION: -d2i_PKCS7_ISSUER_AND_SERIAL 4076 4_0_0 EXIST::FUNCTION: -i2d_PKCS7_ISSUER_AND_SERIAL 4077 4_0_0 EXIST::FUNCTION: -PKCS7_ISSUER_AND_SERIAL_free 4078 4_0_0 EXIST::FUNCTION: -PKCS7_ISSUER_AND_SERIAL_new 4079 4_0_0 EXIST::FUNCTION: -PKCS7_ISSUER_AND_SERIAL_it 4080 4_0_0 EXIST::FUNCTION: -PKCS7_ISSUER_AND_SERIAL_digest 4081 4_0_0 EXIST::FUNCTION: -d2i_PKCS7_fp 4082 4_0_0 EXIST::FUNCTION:STDIO -i2d_PKCS7_fp 4083 4_0_0 EXIST::FUNCTION:STDIO -PKCS7_dup 4084 4_0_0 EXIST::FUNCTION: -d2i_PKCS7_bio 4085 4_0_0 EXIST::FUNCTION: -i2d_PKCS7_bio 4086 4_0_0 EXIST::FUNCTION: -i2d_PKCS7_bio_stream 4087 4_0_0 EXIST::FUNCTION: -PEM_write_bio_PKCS7_stream 4088 4_0_0 EXIST::FUNCTION: -d2i_PKCS7_SIGNER_INFO 4089 4_0_0 EXIST::FUNCTION: -i2d_PKCS7_SIGNER_INFO 4090 4_0_0 EXIST::FUNCTION: -PKCS7_SIGNER_INFO_free 4091 4_0_0 EXIST::FUNCTION: -PKCS7_SIGNER_INFO_new 4092 4_0_0 EXIST::FUNCTION: -PKCS7_SIGNER_INFO_it 4093 4_0_0 EXIST::FUNCTION: -d2i_PKCS7_RECIP_INFO 4094 4_0_0 EXIST::FUNCTION: -i2d_PKCS7_RECIP_INFO 4095 4_0_0 EXIST::FUNCTION: -PKCS7_RECIP_INFO_free 4096 4_0_0 EXIST::FUNCTION: -PKCS7_RECIP_INFO_new 4097 4_0_0 EXIST::FUNCTION: -PKCS7_RECIP_INFO_it 4098 4_0_0 EXIST::FUNCTION: -d2i_PKCS7_SIGNED 4099 4_0_0 EXIST::FUNCTION: -i2d_PKCS7_SIGNED 4100 4_0_0 EXIST::FUNCTION: -PKCS7_SIGNED_free 4101 4_0_0 EXIST::FUNCTION: -PKCS7_SIGNED_new 4102 4_0_0 EXIST::FUNCTION: -PKCS7_SIGNED_it 4103 4_0_0 EXIST::FUNCTION: -d2i_PKCS7_ENC_CONTENT 4104 4_0_0 EXIST::FUNCTION: -i2d_PKCS7_ENC_CONTENT 4105 4_0_0 EXIST::FUNCTION: -PKCS7_ENC_CONTENT_free 4106 4_0_0 EXIST::FUNCTION: -PKCS7_ENC_CONTENT_new 4107 4_0_0 EXIST::FUNCTION: -PKCS7_ENC_CONTENT_it 4108 4_0_0 EXIST::FUNCTION: -d2i_PKCS7_ENVELOPE 4109 4_0_0 EXIST::FUNCTION: -i2d_PKCS7_ENVELOPE 4110 4_0_0 EXIST::FUNCTION: -PKCS7_ENVELOPE_free 4111 4_0_0 EXIST::FUNCTION: -PKCS7_ENVELOPE_new 4112 4_0_0 EXIST::FUNCTION: -PKCS7_ENVELOPE_it 4113 4_0_0 EXIST::FUNCTION: -d2i_PKCS7_SIGN_ENVELOPE 4114 4_0_0 EXIST::FUNCTION: -i2d_PKCS7_SIGN_ENVELOPE 4115 4_0_0 EXIST::FUNCTION: -PKCS7_SIGN_ENVELOPE_free 4116 4_0_0 EXIST::FUNCTION: -PKCS7_SIGN_ENVELOPE_new 4117 4_0_0 EXIST::FUNCTION: -PKCS7_SIGN_ENVELOPE_it 4118 4_0_0 EXIST::FUNCTION: -d2i_PKCS7_DIGEST 4119 4_0_0 EXIST::FUNCTION: -i2d_PKCS7_DIGEST 4120 4_0_0 EXIST::FUNCTION: -PKCS7_DIGEST_free 4121 4_0_0 EXIST::FUNCTION: -PKCS7_DIGEST_new 4122 4_0_0 EXIST::FUNCTION: -PKCS7_DIGEST_it 4123 4_0_0 EXIST::FUNCTION: -d2i_PKCS7_ENCRYPT 4124 4_0_0 EXIST::FUNCTION: -i2d_PKCS7_ENCRYPT 4125 4_0_0 EXIST::FUNCTION: -PKCS7_ENCRYPT_free 4126 4_0_0 EXIST::FUNCTION: -PKCS7_ENCRYPT_new 4127 4_0_0 EXIST::FUNCTION: -PKCS7_ENCRYPT_it 4128 4_0_0 EXIST::FUNCTION: -d2i_PKCS7 4129 4_0_0 EXIST::FUNCTION: -i2d_PKCS7 4130 4_0_0 EXIST::FUNCTION: -PKCS7_free 4131 4_0_0 EXIST::FUNCTION: -PKCS7_new 4132 4_0_0 EXIST::FUNCTION: -PKCS7_it 4133 4_0_0 EXIST::FUNCTION: -PKCS7_new_ex 4134 4_0_0 EXIST::FUNCTION: -PKCS7_ATTR_SIGN_it 4135 4_0_0 EXIST::FUNCTION: -PKCS7_ATTR_VERIFY_it 4136 4_0_0 EXIST::FUNCTION: -i2d_PKCS7_NDEF 4137 4_0_0 EXIST::FUNCTION: -PKCS7_print_ctx 4138 4_0_0 EXIST::FUNCTION: -PKCS7_ctrl 4139 4_0_0 EXIST::FUNCTION: -PKCS7_type_is_other 4140 4_0_0 EXIST::FUNCTION: -PKCS7_set_type 4141 4_0_0 EXIST::FUNCTION: -PKCS7_set0_type_other 4142 4_0_0 EXIST::FUNCTION: -PKCS7_set_content 4143 4_0_0 EXIST::FUNCTION: -PKCS7_SIGNER_INFO_set 4144 4_0_0 EXIST::FUNCTION: -PKCS7_SIGNER_INFO_sign 4145 4_0_0 EXIST::FUNCTION: -PKCS7_add_signer 4146 4_0_0 EXIST::FUNCTION: -PKCS7_add_certificate 4147 4_0_0 EXIST::FUNCTION: -PKCS7_add_crl 4148 4_0_0 EXIST::FUNCTION: -PKCS7_content_new 4149 4_0_0 EXIST::FUNCTION: -PKCS7_dataVerify 4150 4_0_0 EXIST::FUNCTION: -PKCS7_signatureVerify 4151 4_0_0 EXIST::FUNCTION: -PKCS7_dataInit 4152 4_0_0 EXIST::FUNCTION: -PKCS7_dataFinal 4153 4_0_0 EXIST::FUNCTION: -PKCS7_dataDecode 4154 4_0_0 EXIST::FUNCTION: -PKCS7_add_signature 4155 4_0_0 EXIST::FUNCTION: -PKCS7_cert_from_signer_info 4156 4_0_0 EXIST::FUNCTION: -PKCS7_set_digest 4157 4_0_0 EXIST::FUNCTION: -PKCS7_get_signer_info 4158 4_0_0 EXIST::FUNCTION: -PKCS7_add_recipient 4159 4_0_0 EXIST::FUNCTION: -PKCS7_SIGNER_INFO_get0_algs 4160 4_0_0 EXIST::FUNCTION: -PKCS7_RECIP_INFO_get0_alg 4161 4_0_0 EXIST::FUNCTION: -PKCS7_add_recipient_info 4162 4_0_0 EXIST::FUNCTION: -PKCS7_RECIP_INFO_set 4163 4_0_0 EXIST::FUNCTION: -PKCS7_set_cipher 4164 4_0_0 EXIST::FUNCTION: -PKCS7_stream 4165 4_0_0 EXIST::FUNCTION: -PKCS7_get_issuer_and_serial 4166 4_0_0 EXIST::FUNCTION: -PKCS7_get_octet_string 4167 4_0_0 EXIST::FUNCTION: -PKCS7_digest_from_attributes 4168 4_0_0 EXIST::FUNCTION: -PKCS7_add_signed_attribute 4169 4_0_0 EXIST::FUNCTION: -PKCS7_add_attribute 4170 4_0_0 EXIST::FUNCTION: -PKCS7_get_attribute 4171 4_0_0 EXIST::FUNCTION: -PKCS7_get_signed_attribute 4172 4_0_0 EXIST::FUNCTION: -PKCS7_set_signed_attributes 4173 4_0_0 EXIST::FUNCTION: -PKCS7_set_attributes 4174 4_0_0 EXIST::FUNCTION: -PKCS7_sign 4175 4_0_0 EXIST::FUNCTION: -PKCS7_sign_ex 4176 4_0_0 EXIST::FUNCTION: -PKCS7_sign_add_signer 4177 4_0_0 EXIST::FUNCTION: -PKCS7_final 4178 4_0_0 EXIST::FUNCTION: -PKCS7_verify 4179 4_0_0 EXIST::FUNCTION: -PKCS7_get0_signers 4180 4_0_0 EXIST::FUNCTION: -PKCS7_encrypt 4181 4_0_0 EXIST::FUNCTION: -PKCS7_encrypt_ex 4182 4_0_0 EXIST::FUNCTION: -PKCS7_decrypt 4183 4_0_0 EXIST::FUNCTION: -PKCS7_add_attrib_smimecap 4184 4_0_0 EXIST::FUNCTION: -PKCS7_get_smimecap 4185 4_0_0 EXIST::FUNCTION: -PKCS7_simple_smimecap 4186 4_0_0 EXIST::FUNCTION: -PKCS7_add_attrib_content_type 4187 4_0_0 EXIST::FUNCTION: -PKCS7_add0_attrib_signing_time 4188 4_0_0 EXIST::FUNCTION: -PKCS7_add1_attrib_digest 4189 4_0_0 EXIST::FUNCTION: -SMIME_write_PKCS7 4190 4_0_0 EXIST::FUNCTION: -SMIME_read_PKCS7_ex 4191 4_0_0 EXIST::FUNCTION: -SMIME_read_PKCS7 4192 4_0_0 EXIST::FUNCTION: -BIO_new_PKCS7 4193 4_0_0 EXIST::FUNCTION: -SRP_user_pwd_new 4194 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_user_pwd_free 4195 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_user_pwd_set_gN 4196 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_user_pwd_set1_ids 4197 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_user_pwd_set0_sv 4198 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_VBASE_new 4199 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_VBASE_free 4200 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_VBASE_init 4201 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_VBASE_add0_user 4202 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_VBASE_get1_by_user 4203 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_create_verifier_ex 4204 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_create_verifier 4205 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_create_verifier_BN_ex 4206 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_create_verifier_BN 4207 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_check_known_gN_param 4208 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_get_default_gN 4209 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_Calc_server_key 4210 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_Calc_B_ex 4211 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_Calc_B 4212 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_Verify_A_mod_N 4213 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_Calc_u_ex 4214 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_Calc_u 4215 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_Calc_x_ex 4216 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_Calc_x 4217 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_Calc_A 4218 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_Calc_client_key_ex 4219 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_Calc_client_key 4220 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_Verify_B_mod_N 4221 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_VBASE_get_by_user 4222 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,SRP -UI_new 4223 4_0_0 EXIST::FUNCTION: -UI_new_method 4224 4_0_0 EXIST::FUNCTION: -UI_free 4225 4_0_0 EXIST::FUNCTION: -UI_add_input_string 4226 4_0_0 EXIST::FUNCTION: -UI_dup_input_string 4227 4_0_0 EXIST::FUNCTION: -UI_add_verify_string 4228 4_0_0 EXIST::FUNCTION: -UI_dup_verify_string 4229 4_0_0 EXIST::FUNCTION: -UI_add_input_boolean 4230 4_0_0 EXIST::FUNCTION: -UI_dup_input_boolean 4231 4_0_0 EXIST::FUNCTION: -UI_add_info_string 4232 4_0_0 EXIST::FUNCTION: -UI_dup_info_string 4233 4_0_0 EXIST::FUNCTION: -UI_add_error_string 4234 4_0_0 EXIST::FUNCTION: -UI_dup_error_string 4235 4_0_0 EXIST::FUNCTION: -UI_construct_prompt 4236 4_0_0 EXIST::FUNCTION: -UI_add_user_data 4237 4_0_0 EXIST::FUNCTION: -UI_dup_user_data 4238 4_0_0 EXIST::FUNCTION: -UI_get0_user_data 4239 4_0_0 EXIST::FUNCTION: -UI_get0_result 4240 4_0_0 EXIST::FUNCTION: -UI_get_result_length 4241 4_0_0 EXIST::FUNCTION: -UI_process 4242 4_0_0 EXIST::FUNCTION: -UI_ctrl 4243 4_0_0 EXIST::FUNCTION: -UI_set_ex_data 4244 4_0_0 EXIST::FUNCTION: -UI_get_ex_data 4245 4_0_0 EXIST::FUNCTION: -UI_set_default_method 4246 4_0_0 EXIST::FUNCTION: -UI_get_default_method 4247 4_0_0 EXIST::FUNCTION: -UI_get_method 4248 4_0_0 EXIST::FUNCTION: -UI_set_method 4249 4_0_0 EXIST::FUNCTION: -UI_OpenSSL 4250 4_0_0 EXIST::FUNCTION:UI_CONSOLE -UI_null 4251 4_0_0 EXIST::FUNCTION: -UI_create_method 4252 4_0_0 EXIST::FUNCTION: -UI_destroy_method 4253 4_0_0 EXIST::FUNCTION: -UI_method_set_opener 4254 4_0_0 EXIST::FUNCTION: -UI_method_set_writer 4255 4_0_0 EXIST::FUNCTION: -UI_method_set_flusher 4256 4_0_0 EXIST::FUNCTION: -UI_method_set_reader 4257 4_0_0 EXIST::FUNCTION: -UI_method_set_closer 4258 4_0_0 EXIST::FUNCTION: -UI_method_set_data_duplicator 4259 4_0_0 EXIST::FUNCTION: -UI_method_set_prompt_constructor 4260 4_0_0 EXIST::FUNCTION: -UI_method_set_ex_data 4261 4_0_0 EXIST::FUNCTION: -UI_method_get_opener 4262 4_0_0 EXIST::FUNCTION: -UI_method_get_writer 4263 4_0_0 EXIST::FUNCTION: -UI_method_get_flusher 4264 4_0_0 EXIST::FUNCTION: -UI_method_get_reader 4265 4_0_0 EXIST::FUNCTION: -UI_method_get_closer 4266 4_0_0 EXIST::FUNCTION: -UI_method_get_prompt_constructor 4267 4_0_0 EXIST::FUNCTION: -UI_method_get_data_duplicator 4268 4_0_0 EXIST::FUNCTION: -UI_method_get_data_destructor 4269 4_0_0 EXIST::FUNCTION: -UI_method_get_ex_data 4270 4_0_0 EXIST::FUNCTION: -UI_get_string_type 4271 4_0_0 EXIST::FUNCTION: -UI_get_input_flags 4272 4_0_0 EXIST::FUNCTION: -UI_get0_output_string 4273 4_0_0 EXIST::FUNCTION: -UI_get0_action_string 4274 4_0_0 EXIST::FUNCTION: -UI_get0_result_string 4275 4_0_0 EXIST::FUNCTION: -UI_get_result_string_length 4276 4_0_0 EXIST::FUNCTION: -UI_get0_test_string 4277 4_0_0 EXIST::FUNCTION: -UI_get_result_minsize 4278 4_0_0 EXIST::FUNCTION: -UI_get_result_maxsize 4279 4_0_0 EXIST::FUNCTION: -UI_set_result 4280 4_0_0 EXIST::FUNCTION: -UI_set_result_ex 4281 4_0_0 EXIST::FUNCTION: -UI_UTIL_read_pw_string 4282 4_0_0 EXIST::FUNCTION: -UI_UTIL_read_pw 4283 4_0_0 EXIST::FUNCTION: -UI_UTIL_wrap_read_pem_callback 4284 4_0_0 EXIST::FUNCTION: -X509_CRL_set_default_method 4285 4_0_0 EXIST::FUNCTION: -X509_CRL_METHOD_new 4286 4_0_0 EXIST::FUNCTION: -X509_CRL_METHOD_free 4287 4_0_0 EXIST::FUNCTION: -X509_CRL_set_meth_data 4288 4_0_0 EXIST::FUNCTION: -X509_CRL_get_meth_data 4289 4_0_0 EXIST::FUNCTION: -X509_verify_cert_error_string 4290 4_0_0 EXIST::FUNCTION: -X509_verify 4291 4_0_0 EXIST::FUNCTION: -X509_self_signed 4292 4_0_0 EXIST::FUNCTION: -X509_REQ_verify_ex 4293 4_0_0 EXIST::FUNCTION: -X509_REQ_verify 4294 4_0_0 EXIST::FUNCTION: -X509_CRL_verify 4295 4_0_0 EXIST::FUNCTION: -NETSCAPE_SPKI_verify 4296 4_0_0 EXIST::FUNCTION: -NETSCAPE_SPKI_b64_decode 4297 4_0_0 EXIST::FUNCTION: -NETSCAPE_SPKI_b64_encode 4298 4_0_0 EXIST::FUNCTION: -NETSCAPE_SPKI_get_pubkey 4299 4_0_0 EXIST::FUNCTION: -NETSCAPE_SPKI_set_pubkey 4300 4_0_0 EXIST::FUNCTION: -NETSCAPE_SPKI_print 4301 4_0_0 EXIST::FUNCTION: -X509_signature_dump 4302 4_0_0 EXIST::FUNCTION: -X509_signature_print 4303 4_0_0 EXIST::FUNCTION: -X509_sign 4304 4_0_0 EXIST::FUNCTION: -X509_sign_ctx 4305 4_0_0 EXIST::FUNCTION: -X509_REQ_sign 4306 4_0_0 EXIST::FUNCTION: -X509_REQ_sign_ctx 4307 4_0_0 EXIST::FUNCTION: -X509_CRL_sign 4308 4_0_0 EXIST::FUNCTION: -X509_CRL_sign_ctx 4309 4_0_0 EXIST::FUNCTION: -NETSCAPE_SPKI_sign 4310 4_0_0 EXIST::FUNCTION: -X509_pubkey_digest 4311 4_0_0 EXIST::FUNCTION: -X509_digest 4312 4_0_0 EXIST::FUNCTION: -X509_digest_sig 4313 4_0_0 EXIST::FUNCTION: -X509_CRL_digest 4314 4_0_0 EXIST::FUNCTION: -X509_REQ_digest 4315 4_0_0 EXIST::FUNCTION: -X509_NAME_digest 4316 4_0_0 EXIST::FUNCTION: -X509_load_http 4317 4_0_0 EXIST::FUNCTION: -X509_CRL_load_http 4318 4_0_0 EXIST::FUNCTION: -d2i_X509_fp 4319 4_0_0 EXIST::FUNCTION:STDIO -i2d_X509_fp 4320 4_0_0 EXIST::FUNCTION:STDIO -d2i_X509_CRL_fp 4321 4_0_0 EXIST::FUNCTION:STDIO -i2d_X509_CRL_fp 4322 4_0_0 EXIST::FUNCTION:STDIO -d2i_X509_REQ_fp 4323 4_0_0 EXIST::FUNCTION:STDIO -i2d_X509_REQ_fp 4324 4_0_0 EXIST::FUNCTION:STDIO -d2i_RSAPrivateKey_fp 4325 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO -i2d_RSAPrivateKey_fp 4326 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO -d2i_RSAPublicKey_fp 4327 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO -i2d_RSAPublicKey_fp 4328 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO -d2i_RSA_PUBKEY_fp 4329 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO -i2d_RSA_PUBKEY_fp 4330 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO -d2i_DSA_PUBKEY_fp 4331 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO -i2d_DSA_PUBKEY_fp 4332 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO -d2i_DSAPrivateKey_fp 4333 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO -i2d_DSAPrivateKey_fp 4334 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO -d2i_EC_PUBKEY_fp 4335 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO -i2d_EC_PUBKEY_fp 4336 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO -d2i_ECPrivateKey_fp 4337 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO -i2d_ECPrivateKey_fp 4338 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO -d2i_PKCS8_fp 4339 4_0_0 EXIST::FUNCTION:STDIO -i2d_PKCS8_fp 4340 4_0_0 EXIST::FUNCTION:STDIO -d2i_X509_PUBKEY_fp 4341 4_0_0 EXIST::FUNCTION:STDIO -i2d_X509_PUBKEY_fp 4342 4_0_0 EXIST::FUNCTION:STDIO -d2i_PKCS8_PRIV_KEY_INFO_fp 4343 4_0_0 EXIST::FUNCTION:STDIO -i2d_PKCS8_PRIV_KEY_INFO_fp 4344 4_0_0 EXIST::FUNCTION:STDIO -i2d_PKCS8PrivateKeyInfo_fp 4345 4_0_0 EXIST::FUNCTION:STDIO -i2d_PrivateKey_fp 4346 4_0_0 EXIST::FUNCTION:STDIO -d2i_PrivateKey_ex_fp 4347 4_0_0 EXIST::FUNCTION:STDIO -d2i_PrivateKey_fp 4348 4_0_0 EXIST::FUNCTION:STDIO -i2d_PUBKEY_fp 4349 4_0_0 EXIST::FUNCTION:STDIO -d2i_PUBKEY_ex_fp 4350 4_0_0 EXIST::FUNCTION:STDIO -d2i_PUBKEY_fp 4351 4_0_0 EXIST::FUNCTION:STDIO -d2i_X509_bio 4352 4_0_0 EXIST::FUNCTION: -i2d_X509_bio 4353 4_0_0 EXIST::FUNCTION: -d2i_X509_CRL_bio 4354 4_0_0 EXIST::FUNCTION: -i2d_X509_CRL_bio 4355 4_0_0 EXIST::FUNCTION: -d2i_X509_REQ_bio 4356 4_0_0 EXIST::FUNCTION: -i2d_X509_REQ_bio 4357 4_0_0 EXIST::FUNCTION: -d2i_RSAPrivateKey_bio 4358 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -i2d_RSAPrivateKey_bio 4359 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -d2i_RSAPublicKey_bio 4360 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -i2d_RSAPublicKey_bio 4361 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -d2i_RSA_PUBKEY_bio 4362 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -i2d_RSA_PUBKEY_bio 4363 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -d2i_DSA_PUBKEY_bio 4364 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -i2d_DSA_PUBKEY_bio 4365 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -d2i_DSAPrivateKey_bio 4366 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -i2d_DSAPrivateKey_bio 4367 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -d2i_EC_PUBKEY_bio 4368 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -i2d_EC_PUBKEY_bio 4369 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -d2i_ECPrivateKey_bio 4370 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -i2d_ECPrivateKey_bio 4371 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -d2i_PKCS8_bio 4372 4_0_0 EXIST::FUNCTION: -i2d_PKCS8_bio 4373 4_0_0 EXIST::FUNCTION: -d2i_X509_PUBKEY_bio 4374 4_0_0 EXIST::FUNCTION: -i2d_X509_PUBKEY_bio 4375 4_0_0 EXIST::FUNCTION: -d2i_PKCS8_PRIV_KEY_INFO_bio 4376 4_0_0 EXIST::FUNCTION: -i2d_PKCS8_PRIV_KEY_INFO_bio 4377 4_0_0 EXIST::FUNCTION: -i2d_PKCS8PrivateKeyInfo_bio 4378 4_0_0 EXIST::FUNCTION: -i2d_PrivateKey_bio 4379 4_0_0 EXIST::FUNCTION: -d2i_PrivateKey_ex_bio 4380 4_0_0 EXIST::FUNCTION: -d2i_PrivateKey_bio 4381 4_0_0 EXIST::FUNCTION: -i2d_PUBKEY_bio 4382 4_0_0 EXIST::FUNCTION: -d2i_PUBKEY_ex_bio 4383 4_0_0 EXIST::FUNCTION: -d2i_PUBKEY_bio 4384 4_0_0 EXIST::FUNCTION: -X509_dup 4385 4_0_0 EXIST::FUNCTION: -X509_ALGOR_dup 4386 4_0_0 EXIST::FUNCTION: -X509_ATTRIBUTE_dup 4387 4_0_0 EXIST::FUNCTION: -X509_CRL_dup 4388 4_0_0 EXIST::FUNCTION: -X509_EXTENSION_dup 4389 4_0_0 EXIST::FUNCTION: -X509_PUBKEY_dup 4390 4_0_0 EXIST::FUNCTION: -X509_REQ_dup 4391 4_0_0 EXIST::FUNCTION: -X509_REVOKED_dup 4392 4_0_0 EXIST::FUNCTION: -X509_ALGOR_set0 4393 4_0_0 EXIST::FUNCTION: -X509_ALGOR_get0 4394 4_0_0 EXIST::FUNCTION: -X509_ALGOR_set_md 4395 4_0_0 EXIST::FUNCTION: -X509_ALGOR_cmp 4396 4_0_0 EXIST::FUNCTION: -X509_ALGOR_copy 4397 4_0_0 EXIST::FUNCTION: -X509_NAME_dup 4398 4_0_0 EXIST::FUNCTION: -X509_NAME_ENTRY_dup 4399 4_0_0 EXIST::FUNCTION: -X509_cmp_time 4400 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_0 -X509_cmp_current_time 4401 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_0 -X509_cmp_timeframe 4402 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_0 -X509_check_certificate_times 4403 4_0_0 EXIST::FUNCTION: -X509_time_adj 4404 4_0_0 EXIST::FUNCTION: -X509_time_adj_ex 4405 4_0_0 EXIST::FUNCTION: -X509_gmtime_adj 4406 4_0_0 EXIST::FUNCTION: -X509_get_default_cert_area 4407 4_0_0 EXIST::FUNCTION: -X509_get_default_cert_dir 4408 4_0_0 EXIST::FUNCTION: -X509_get_default_cert_file 4409 4_0_0 EXIST::FUNCTION: -X509_get_default_cert_dir_env 4410 4_0_0 EXIST::FUNCTION: -X509_get_default_cert_file_env 4411 4_0_0 EXIST::FUNCTION: -X509_get_default_private_dir 4412 4_0_0 EXIST::FUNCTION: -X509_to_X509_REQ 4413 4_0_0 EXIST::FUNCTION: -X509_REQ_to_X509 4414 4_0_0 EXIST::FUNCTION: -d2i_X509_ALGOR 4415 4_0_0 EXIST::FUNCTION: -i2d_X509_ALGOR 4416 4_0_0 EXIST::FUNCTION: -X509_ALGOR_free 4417 4_0_0 EXIST::FUNCTION: -X509_ALGOR_new 4418 4_0_0 EXIST::FUNCTION: -X509_ALGOR_it 4419 4_0_0 EXIST::FUNCTION: -d2i_X509_ALGORS 4420 4_0_0 EXIST::FUNCTION: -i2d_X509_ALGORS 4421 4_0_0 EXIST::FUNCTION: -X509_ALGORS_it 4422 4_0_0 EXIST::FUNCTION: -d2i_X509_VAL 4423 4_0_0 EXIST::FUNCTION: -i2d_X509_VAL 4424 4_0_0 EXIST::FUNCTION: -X509_VAL_free 4425 4_0_0 EXIST::FUNCTION: -X509_VAL_new 4426 4_0_0 EXIST::FUNCTION: -X509_VAL_it 4427 4_0_0 EXIST::FUNCTION: -d2i_X509_PUBKEY 4428 4_0_0 EXIST::FUNCTION: -i2d_X509_PUBKEY 4429 4_0_0 EXIST::FUNCTION: -X509_PUBKEY_free 4430 4_0_0 EXIST::FUNCTION: -X509_PUBKEY_new 4431 4_0_0 EXIST::FUNCTION: -X509_PUBKEY_it 4432 4_0_0 EXIST::FUNCTION: -X509_PUBKEY_new_ex 4433 4_0_0 EXIST::FUNCTION: -X509_PUBKEY_set 4434 4_0_0 EXIST::FUNCTION: -X509_PUBKEY_get0 4435 4_0_0 EXIST::FUNCTION: -X509_PUBKEY_get 4436 4_0_0 EXIST::FUNCTION: -X509_get_pubkey_parameters 4437 4_0_0 EXIST::FUNCTION: -X509_get_pathlen 4438 4_0_0 EXIST::FUNCTION: -d2i_PUBKEY 4439 4_0_0 EXIST::FUNCTION: -i2d_PUBKEY 4440 4_0_0 EXIST::FUNCTION: -d2i_PUBKEY_ex 4441 4_0_0 EXIST::FUNCTION: -d2i_RSA_PUBKEY 4442 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -i2d_RSA_PUBKEY 4443 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -d2i_DSA_PUBKEY 4444 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -i2d_DSA_PUBKEY 4445 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA -d2i_EC_PUBKEY 4446 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -i2d_EC_PUBKEY 4447 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC -d2i_X509_SIG 4448 4_0_0 EXIST::FUNCTION: -i2d_X509_SIG 4449 4_0_0 EXIST::FUNCTION: -X509_SIG_free 4450 4_0_0 EXIST::FUNCTION: -X509_SIG_new 4451 4_0_0 EXIST::FUNCTION: -X509_SIG_it 4452 4_0_0 EXIST::FUNCTION: -X509_SIG_get0 4453 4_0_0 EXIST::FUNCTION: -X509_SIG_getm 4454 4_0_0 EXIST::FUNCTION: -d2i_X509_REQ_INFO 4455 4_0_0 EXIST::FUNCTION: -i2d_X509_REQ_INFO 4456 4_0_0 EXIST::FUNCTION: -X509_REQ_INFO_free 4457 4_0_0 EXIST::FUNCTION: -X509_REQ_INFO_new 4458 4_0_0 EXIST::FUNCTION: -X509_REQ_INFO_it 4459 4_0_0 EXIST::FUNCTION: -d2i_X509_REQ 4460 4_0_0 EXIST::FUNCTION: -i2d_X509_REQ 4461 4_0_0 EXIST::FUNCTION: -X509_REQ_free 4462 4_0_0 EXIST::FUNCTION: -X509_REQ_new 4463 4_0_0 EXIST::FUNCTION: -X509_REQ_it 4464 4_0_0 EXIST::FUNCTION: -X509_REQ_new_ex 4465 4_0_0 EXIST::FUNCTION: -d2i_X509_ATTRIBUTE 4466 4_0_0 EXIST::FUNCTION: -i2d_X509_ATTRIBUTE 4467 4_0_0 EXIST::FUNCTION: -X509_ATTRIBUTE_free 4468 4_0_0 EXIST::FUNCTION: -X509_ATTRIBUTE_new 4469 4_0_0 EXIST::FUNCTION: -X509_ATTRIBUTE_it 4470 4_0_0 EXIST::FUNCTION: -X509_ATTRIBUTE_create 4471 4_0_0 EXIST::FUNCTION: -d2i_X509_EXTENSION 4472 4_0_0 EXIST::FUNCTION: -i2d_X509_EXTENSION 4473 4_0_0 EXIST::FUNCTION: -X509_EXTENSION_free 4474 4_0_0 EXIST::FUNCTION: -X509_EXTENSION_new 4475 4_0_0 EXIST::FUNCTION: -X509_EXTENSION_it 4476 4_0_0 EXIST::FUNCTION: -d2i_X509_EXTENSIONS 4477 4_0_0 EXIST::FUNCTION: -i2d_X509_EXTENSIONS 4478 4_0_0 EXIST::FUNCTION: -X509_EXTENSIONS_it 4479 4_0_0 EXIST::FUNCTION: -d2i_X509_NAME_ENTRY 4480 4_0_0 EXIST::FUNCTION: -i2d_X509_NAME_ENTRY 4481 4_0_0 EXIST::FUNCTION: -X509_NAME_ENTRY_free 4482 4_0_0 EXIST::FUNCTION: -X509_NAME_ENTRY_new 4483 4_0_0 EXIST::FUNCTION: -X509_NAME_ENTRY_it 4484 4_0_0 EXIST::FUNCTION: -d2i_X509_NAME 4485 4_0_0 EXIST::FUNCTION: -i2d_X509_NAME 4486 4_0_0 EXIST::FUNCTION: -X509_NAME_free 4487 4_0_0 EXIST::FUNCTION: -X509_NAME_new 4488 4_0_0 EXIST::FUNCTION: -X509_NAME_it 4489 4_0_0 EXIST::FUNCTION: -X509_NAME_set 4490 4_0_0 EXIST::FUNCTION: -d2i_X509_CINF 4491 4_0_0 EXIST::FUNCTION: -i2d_X509_CINF 4492 4_0_0 EXIST::FUNCTION: -X509_CINF_free 4493 4_0_0 EXIST::FUNCTION: -X509_CINF_new 4494 4_0_0 EXIST::FUNCTION: -X509_CINF_it 4495 4_0_0 EXIST::FUNCTION: -d2i_X509 4496 4_0_0 EXIST::FUNCTION: -i2d_X509 4497 4_0_0 EXIST::FUNCTION: -X509_free 4498 4_0_0 EXIST::FUNCTION: -X509_new 4499 4_0_0 EXIST::FUNCTION: -X509_it 4500 4_0_0 EXIST::FUNCTION: -X509_new_ex 4501 4_0_0 EXIST::FUNCTION: -d2i_X509_CERT_AUX 4502 4_0_0 EXIST::FUNCTION: -i2d_X509_CERT_AUX 4503 4_0_0 EXIST::FUNCTION: -X509_CERT_AUX_free 4504 4_0_0 EXIST::FUNCTION: -X509_CERT_AUX_new 4505 4_0_0 EXIST::FUNCTION: -X509_CERT_AUX_it 4506 4_0_0 EXIST::FUNCTION: -X509_set_ex_data 4507 4_0_0 EXIST::FUNCTION: -X509_get_ex_data 4508 4_0_0 EXIST::FUNCTION: -d2i_X509_AUX 4509 4_0_0 EXIST::FUNCTION: -i2d_X509_AUX 4510 4_0_0 EXIST::FUNCTION: -i2d_re_X509_tbs 4511 4_0_0 EXIST::FUNCTION: -X509_SIG_INFO_get 4512 4_0_0 EXIST::FUNCTION: -X509_SIG_INFO_set 4513 4_0_0 EXIST::FUNCTION: -X509_get_signature_info 4514 4_0_0 EXIST::FUNCTION: -X509_get0_signature 4515 4_0_0 EXIST::FUNCTION: -X509_get_signature_nid 4516 4_0_0 EXIST::FUNCTION: -X509_set0_distinguishing_id 4517 4_0_0 EXIST::FUNCTION: -X509_get0_distinguishing_id 4518 4_0_0 EXIST::FUNCTION: -X509_REQ_set0_distinguishing_id 4519 4_0_0 EXIST::FUNCTION: -X509_REQ_get0_distinguishing_id 4520 4_0_0 EXIST::FUNCTION: -X509_alias_set1 4521 4_0_0 EXIST::FUNCTION: -X509_keyid_set1 4522 4_0_0 EXIST::FUNCTION: -X509_alias_get0 4523 4_0_0 EXIST::FUNCTION: -X509_keyid_get0 4524 4_0_0 EXIST::FUNCTION: -d2i_X509_REVOKED 4525 4_0_0 EXIST::FUNCTION: -i2d_X509_REVOKED 4526 4_0_0 EXIST::FUNCTION: -X509_REVOKED_free 4527 4_0_0 EXIST::FUNCTION: -X509_REVOKED_new 4528 4_0_0 EXIST::FUNCTION: -X509_REVOKED_it 4529 4_0_0 EXIST::FUNCTION: -d2i_X509_CRL_INFO 4530 4_0_0 EXIST::FUNCTION: -i2d_X509_CRL_INFO 4531 4_0_0 EXIST::FUNCTION: -X509_CRL_INFO_free 4532 4_0_0 EXIST::FUNCTION: -X509_CRL_INFO_new 4533 4_0_0 EXIST::FUNCTION: -X509_CRL_INFO_it 4534 4_0_0 EXIST::FUNCTION: -d2i_X509_CRL 4535 4_0_0 EXIST::FUNCTION: -i2d_X509_CRL 4536 4_0_0 EXIST::FUNCTION: -X509_CRL_free 4537 4_0_0 EXIST::FUNCTION: -X509_CRL_new 4538 4_0_0 EXIST::FUNCTION: -X509_CRL_it 4539 4_0_0 EXIST::FUNCTION: -X509_CRL_new_ex 4540 4_0_0 EXIST::FUNCTION: -X509_CRL_add0_revoked 4541 4_0_0 EXIST::FUNCTION: -X509_CRL_get0_by_serial 4542 4_0_0 EXIST::FUNCTION: -X509_CRL_get0_by_cert 4543 4_0_0 EXIST::FUNCTION: -X509_PKEY_new 4544 4_0_0 EXIST::FUNCTION: -X509_PKEY_free 4545 4_0_0 EXIST::FUNCTION: -d2i_NETSCAPE_SPKI 4546 4_0_0 EXIST::FUNCTION: -i2d_NETSCAPE_SPKI 4547 4_0_0 EXIST::FUNCTION: -NETSCAPE_SPKI_free 4548 4_0_0 EXIST::FUNCTION: -NETSCAPE_SPKI_new 4549 4_0_0 EXIST::FUNCTION: -NETSCAPE_SPKI_it 4550 4_0_0 EXIST::FUNCTION: -d2i_NETSCAPE_SPKAC 4551 4_0_0 EXIST::FUNCTION: -i2d_NETSCAPE_SPKAC 4552 4_0_0 EXIST::FUNCTION: -NETSCAPE_SPKAC_free 4553 4_0_0 EXIST::FUNCTION: -NETSCAPE_SPKAC_new 4554 4_0_0 EXIST::FUNCTION: -NETSCAPE_SPKAC_it 4555 4_0_0 EXIST::FUNCTION: -d2i_NETSCAPE_CERT_SEQUENCE 4556 4_0_0 EXIST::FUNCTION: -i2d_NETSCAPE_CERT_SEQUENCE 4557 4_0_0 EXIST::FUNCTION: -NETSCAPE_CERT_SEQUENCE_free 4558 4_0_0 EXIST::FUNCTION: -NETSCAPE_CERT_SEQUENCE_new 4559 4_0_0 EXIST::FUNCTION: -NETSCAPE_CERT_SEQUENCE_it 4560 4_0_0 EXIST::FUNCTION: -X509_INFO_new 4561 4_0_0 EXIST::FUNCTION: -X509_INFO_free 4562 4_0_0 EXIST::FUNCTION: -X509_NAME_oneline 4563 4_0_0 EXIST::FUNCTION: -ASN1_verify 4564 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ASN1_digest 4565 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ASN1_sign 4566 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -ASN1_item_digest 4567 4_0_0 EXIST::FUNCTION: -ASN1_item_verify 4568 4_0_0 EXIST::FUNCTION: -ASN1_item_verify_ctx 4569 4_0_0 EXIST::FUNCTION: -ASN1_item_sign 4570 4_0_0 EXIST::FUNCTION: -ASN1_item_sign_ctx 4571 4_0_0 EXIST::FUNCTION: -X509_get_version 4572 4_0_0 EXIST::FUNCTION: -X509_set_version 4573 4_0_0 EXIST::FUNCTION: -X509_set_serialNumber 4574 4_0_0 EXIST::FUNCTION: -X509_get_serialNumber 4575 4_0_0 EXIST::FUNCTION: -X509_get0_serialNumber 4576 4_0_0 EXIST::FUNCTION: -X509_set_issuer_name 4577 4_0_0 EXIST::FUNCTION: -X509_get_issuer_name 4578 4_0_0 EXIST::FUNCTION: -X509_set_subject_name 4579 4_0_0 EXIST::FUNCTION: -X509_get_subject_name 4580 4_0_0 EXIST::FUNCTION: -X509_get0_notBefore 4581 4_0_0 EXIST::FUNCTION: -X509_getm_notBefore 4582 4_0_0 EXIST::FUNCTION: -X509_set1_notBefore 4583 4_0_0 EXIST::FUNCTION: -X509_get0_notAfter 4584 4_0_0 EXIST::FUNCTION: -X509_getm_notAfter 4585 4_0_0 EXIST::FUNCTION: -X509_set1_notAfter 4586 4_0_0 EXIST::FUNCTION: -X509_up_ref 4587 4_0_0 EXIST::FUNCTION: -X509_get_signature_type 4588 4_0_0 EXIST::FUNCTION: -X509_set_pubkey 4589 4_0_0 EXIST::FUNCTION: -X509_get_pubkey 4590 4_0_0 EXIST::FUNCTION: -X509_get0_pubkey 4591 4_0_0 EXIST::FUNCTION: -X509_get_X509_PUBKEY 4592 4_0_0 EXIST::FUNCTION: -X509_get0_extensions 4593 4_0_0 EXIST::FUNCTION: -X509_get0_uids 4594 4_0_0 EXIST::FUNCTION: -X509_get0_tbs_sigalg 4595 4_0_0 EXIST::FUNCTION: -X509_get0_pubkey_bitstr 4596 4_0_0 EXIST::FUNCTION: -X509_REQ_get_version 4597 4_0_0 EXIST::FUNCTION: -X509_REQ_set_version 4598 4_0_0 EXIST::FUNCTION: -X509_REQ_get_subject_name 4599 4_0_0 EXIST::FUNCTION: -X509_REQ_set_subject_name 4600 4_0_0 EXIST::FUNCTION: -X509_REQ_get0_signature 4601 4_0_0 EXIST::FUNCTION: -X509_REQ_set0_signature 4602 4_0_0 EXIST::FUNCTION: -X509_REQ_set1_signature_algo 4603 4_0_0 EXIST::FUNCTION: -X509_REQ_get_signature_nid 4604 4_0_0 EXIST::FUNCTION: -i2d_re_X509_REQ_tbs 4605 4_0_0 EXIST::FUNCTION: -X509_REQ_set_pubkey 4606 4_0_0 EXIST::FUNCTION: -X509_REQ_get_pubkey 4607 4_0_0 EXIST::FUNCTION: -X509_REQ_get0_pubkey 4608 4_0_0 EXIST::FUNCTION: -X509_REQ_get_X509_PUBKEY 4609 4_0_0 EXIST::FUNCTION: -X509_REQ_extension_nid 4610 4_0_0 EXIST::FUNCTION: -X509_REQ_get_extension_nids 4611 4_0_0 EXIST::FUNCTION: -X509_REQ_set_extension_nids 4612 4_0_0 EXIST::FUNCTION: -X509_REQ_get_extensions 4613 4_0_0 EXIST::FUNCTION: -X509_REQ_add_extensions_nid 4614 4_0_0 EXIST::FUNCTION: -X509_REQ_add_extensions 4615 4_0_0 EXIST::FUNCTION: -X509_REQ_get_attr_count 4616 4_0_0 EXIST::FUNCTION: -X509_REQ_get_attr_by_NID 4617 4_0_0 EXIST::FUNCTION: -X509_REQ_get_attr_by_OBJ 4618 4_0_0 EXIST::FUNCTION: -X509_REQ_get_attr 4619 4_0_0 EXIST::FUNCTION: -X509_REQ_delete_attr 4620 4_0_0 EXIST::FUNCTION: -X509_REQ_add1_attr 4621 4_0_0 EXIST::FUNCTION: -X509_REQ_add1_attr_by_OBJ 4622 4_0_0 EXIST::FUNCTION: -X509_REQ_add1_attr_by_NID 4623 4_0_0 EXIST::FUNCTION: -X509_REQ_add1_attr_by_txt 4624 4_0_0 EXIST::FUNCTION: -X509_CRL_set_version 4625 4_0_0 EXIST::FUNCTION: -X509_CRL_set_issuer_name 4626 4_0_0 EXIST::FUNCTION: -X509_CRL_set1_lastUpdate 4627 4_0_0 EXIST::FUNCTION: -X509_CRL_set1_nextUpdate 4628 4_0_0 EXIST::FUNCTION: -X509_CRL_sort 4629 4_0_0 EXIST::FUNCTION: -X509_CRL_up_ref 4630 4_0_0 EXIST::FUNCTION: -X509_CRL_get_version 4631 4_0_0 EXIST::FUNCTION: -X509_CRL_get0_lastUpdate 4632 4_0_0 EXIST::FUNCTION: -X509_CRL_get0_nextUpdate 4633 4_0_0 EXIST::FUNCTION: -X509_CRL_get_lastUpdate 4634 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0 -X509_CRL_get_nextUpdate 4635 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0 -X509_CRL_get_issuer 4636 4_0_0 EXIST::FUNCTION: -X509_CRL_get0_extensions 4637 4_0_0 EXIST::FUNCTION: -X509_CRL_get_REVOKED 4638 4_0_0 EXIST::FUNCTION: -X509_CRL_get0_tbs_sigalg 4639 4_0_0 EXIST::FUNCTION: -X509_CRL_get0_signature 4640 4_0_0 EXIST::FUNCTION: -X509_CRL_get_signature_nid 4641 4_0_0 EXIST::FUNCTION: -i2d_re_X509_CRL_tbs 4642 4_0_0 EXIST::FUNCTION: -X509_REVOKED_get0_serialNumber 4643 4_0_0 EXIST::FUNCTION: -X509_REVOKED_set_serialNumber 4644 4_0_0 EXIST::FUNCTION: -X509_REVOKED_get0_revocationDate 4645 4_0_0 EXIST::FUNCTION: -X509_REVOKED_set_revocationDate 4646 4_0_0 EXIST::FUNCTION: -X509_REVOKED_get0_extensions 4647 4_0_0 EXIST::FUNCTION: -X509_CRL_diff 4648 4_0_0 EXIST::FUNCTION: -X509_REQ_check_private_key 4649 4_0_0 EXIST::FUNCTION: -X509_check_private_key 4650 4_0_0 EXIST::FUNCTION: -X509_chain_check_suiteb 4651 4_0_0 EXIST::FUNCTION: -X509_CRL_check_suiteb 4652 4_0_0 EXIST::FUNCTION: -OSSL_STACK_OF_X509_free 4653 4_0_0 EXIST::FUNCTION: -X509_chain_up_ref 4654 4_0_0 EXIST::FUNCTION: -X509_issuer_and_serial_cmp 4655 4_0_0 EXIST::FUNCTION: -X509_issuer_and_serial_hash 4656 4_0_0 EXIST::FUNCTION: -X509_issuer_name_cmp 4657 4_0_0 EXIST::FUNCTION: -X509_issuer_name_hash 4658 4_0_0 EXIST::FUNCTION: -X509_subject_name_cmp 4659 4_0_0 EXIST::FUNCTION: -X509_subject_name_hash 4660 4_0_0 EXIST::FUNCTION: -X509_issuer_name_hash_old 4661 4_0_0 EXIST::FUNCTION:MD5 -X509_subject_name_hash_old 4662 4_0_0 EXIST::FUNCTION:MD5 -X509_add_cert 4663 4_0_0 EXIST::FUNCTION: -X509_add_certs 4664 4_0_0 EXIST::FUNCTION: -X509_cmp 4665 4_0_0 EXIST::FUNCTION: -X509_NAME_cmp 4666 4_0_0 EXIST::FUNCTION: -X509_certificate_type 4667 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -X509_NAME_hash_ex 4668 4_0_0 EXIST::FUNCTION: -X509_NAME_hash_old 4669 4_0_0 EXIST::FUNCTION: -X509_CRL_cmp 4670 4_0_0 EXIST::FUNCTION: -X509_CRL_match 4671 4_0_0 EXIST::FUNCTION: -X509_aux_print 4672 4_0_0 EXIST::FUNCTION: -X509_print_ex_fp 4673 4_0_0 EXIST::FUNCTION:STDIO -X509_print_fp 4674 4_0_0 EXIST::FUNCTION:STDIO -X509_CRL_print_fp 4675 4_0_0 EXIST::FUNCTION:STDIO -X509_REQ_print_fp 4676 4_0_0 EXIST::FUNCTION:STDIO -X509_NAME_print_ex_fp 4677 4_0_0 EXIST::FUNCTION:STDIO -X509_NAME_print 4678 4_0_0 EXIST::FUNCTION: -X509_NAME_print_ex 4679 4_0_0 EXIST::FUNCTION: -X509_print_ex 4680 4_0_0 EXIST::FUNCTION: -X509_print 4681 4_0_0 EXIST::FUNCTION: -X509_ocspid_print 4682 4_0_0 EXIST::FUNCTION: -X509_CRL_print_ex 4683 4_0_0 EXIST::FUNCTION: -X509_CRL_print 4684 4_0_0 EXIST::FUNCTION: -X509_REQ_print_ex 4685 4_0_0 EXIST::FUNCTION: -X509_REQ_print 4686 4_0_0 EXIST::FUNCTION: -X509_NAME_entry_count 4687 4_0_0 EXIST::FUNCTION: -X509_NAME_get_text_by_NID 4688 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_0 -X509_NAME_get_text_by_OBJ 4689 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_0 -X509_NAME_get_index_by_NID 4690 4_0_0 EXIST::FUNCTION: -X509_NAME_get_index_by_OBJ 4691 4_0_0 EXIST::FUNCTION: -X509_NAME_get_entry 4692 4_0_0 EXIST::FUNCTION: -X509_NAME_delete_entry 4693 4_0_0 EXIST::FUNCTION: -X509_NAME_add_entry 4694 4_0_0 EXIST::FUNCTION: -X509_NAME_add_entry_by_OBJ 4695 4_0_0 EXIST::FUNCTION: -X509_NAME_add_entry_by_NID 4696 4_0_0 EXIST::FUNCTION: -X509_NAME_ENTRY_create_by_txt 4697 4_0_0 EXIST::FUNCTION: -X509_NAME_ENTRY_create_by_NID 4698 4_0_0 EXIST::FUNCTION: -X509_NAME_add_entry_by_txt 4699 4_0_0 EXIST::FUNCTION: -X509_NAME_ENTRY_create_by_OBJ 4700 4_0_0 EXIST::FUNCTION: -X509_NAME_ENTRY_set_object 4701 4_0_0 EXIST::FUNCTION: -X509_NAME_ENTRY_set_data 4702 4_0_0 EXIST::FUNCTION: -X509_NAME_ENTRY_get_object 4703 4_0_0 EXIST::FUNCTION: -X509_NAME_ENTRY_get_data 4704 4_0_0 EXIST::FUNCTION: -X509_NAME_ENTRY_set 4705 4_0_0 EXIST::FUNCTION: -X509_NAME_get0_der 4706 4_0_0 EXIST::FUNCTION: -X509v3_get_ext_count 4707 4_0_0 EXIST::FUNCTION: -X509v3_get_ext_by_NID 4708 4_0_0 EXIST::FUNCTION: -X509v3_get_ext_by_OBJ 4709 4_0_0 EXIST::FUNCTION: -X509v3_get_ext_by_critical 4710 4_0_0 EXIST::FUNCTION: -X509v3_get_ext 4711 4_0_0 EXIST::FUNCTION: -X509v3_delete_ext 4712 4_0_0 EXIST::FUNCTION: -X509v3_add_ext 4713 4_0_0 EXIST::FUNCTION: -X509v3_add_extensions 4714 4_0_0 EXIST::FUNCTION: -X509_get_ext_count 4715 4_0_0 EXIST::FUNCTION: -X509_get_ext_by_NID 4716 4_0_0 EXIST::FUNCTION: -X509_get_ext_by_OBJ 4717 4_0_0 EXIST::FUNCTION: -X509_get_ext_by_critical 4718 4_0_0 EXIST::FUNCTION: -X509_get_ext 4719 4_0_0 EXIST::FUNCTION: -X509_delete_ext 4720 4_0_0 EXIST::FUNCTION: -X509_add_ext 4721 4_0_0 EXIST::FUNCTION: -X509_get_ext_d2i 4722 4_0_0 EXIST::FUNCTION: -X509_add1_ext_i2d 4723 4_0_0 EXIST::FUNCTION: -X509_CRL_get_ext_count 4724 4_0_0 EXIST::FUNCTION: -X509_CRL_get_ext_by_NID 4725 4_0_0 EXIST::FUNCTION: -X509_CRL_get_ext_by_OBJ 4726 4_0_0 EXIST::FUNCTION: -X509_CRL_get_ext_by_critical 4727 4_0_0 EXIST::FUNCTION: -X509_CRL_get_ext 4728 4_0_0 EXIST::FUNCTION: -X509_CRL_delete_ext 4729 4_0_0 EXIST::FUNCTION: -X509_CRL_add_ext 4730 4_0_0 EXIST::FUNCTION: -X509_CRL_get_ext_d2i 4731 4_0_0 EXIST::FUNCTION: -X509_CRL_add1_ext_i2d 4732 4_0_0 EXIST::FUNCTION: -X509_REVOKED_get_ext_count 4733 4_0_0 EXIST::FUNCTION: -X509_REVOKED_get_ext_by_NID 4734 4_0_0 EXIST::FUNCTION: -X509_REVOKED_get_ext_by_OBJ 4735 4_0_0 EXIST::FUNCTION: -X509_REVOKED_get_ext_by_critical 4736 4_0_0 EXIST::FUNCTION: -X509_REVOKED_get_ext 4737 4_0_0 EXIST::FUNCTION: -X509_REVOKED_delete_ext 4738 4_0_0 EXIST::FUNCTION: -X509_REVOKED_add_ext 4739 4_0_0 EXIST::FUNCTION: -X509_REVOKED_get_ext_d2i 4740 4_0_0 EXIST::FUNCTION: -X509_REVOKED_add1_ext_i2d 4741 4_0_0 EXIST::FUNCTION: -X509_EXTENSION_create_by_NID 4742 4_0_0 EXIST::FUNCTION: -X509_EXTENSION_create_by_OBJ 4743 4_0_0 EXIST::FUNCTION: -X509_EXTENSION_set_object 4744 4_0_0 EXIST::FUNCTION: -X509_EXTENSION_set_critical 4745 4_0_0 EXIST::FUNCTION: -X509_EXTENSION_set_data 4746 4_0_0 EXIST::FUNCTION: -X509_EXTENSION_get_object 4747 4_0_0 EXIST::FUNCTION: -X509_EXTENSION_get_data 4748 4_0_0 EXIST::FUNCTION: -X509_EXTENSION_get_critical 4749 4_0_0 EXIST::FUNCTION: -X509at_get_attr_count 4750 4_0_0 EXIST::FUNCTION: -X509at_get_attr_by_NID 4751 4_0_0 EXIST::FUNCTION: -X509at_get_attr_by_OBJ 4752 4_0_0 EXIST::FUNCTION: -X509at_get_attr 4753 4_0_0 EXIST::FUNCTION: -X509at_delete_attr 4754 4_0_0 EXIST::FUNCTION: -X509at_add1_attr 4755 4_0_0 EXIST::FUNCTION: -X509at_add1_attr_by_OBJ 4756 4_0_0 EXIST::FUNCTION: -X509at_add1_attr_by_NID 4757 4_0_0 EXIST::FUNCTION: -X509at_add1_attr_by_txt 4758 4_0_0 EXIST::FUNCTION: -X509at_get0_data_by_OBJ 4759 4_0_0 EXIST::FUNCTION: -X509_ATTRIBUTE_create_by_NID 4760 4_0_0 EXIST::FUNCTION: -X509_ATTRIBUTE_create_by_OBJ 4761 4_0_0 EXIST::FUNCTION: -X509_ATTRIBUTE_create_by_txt 4762 4_0_0 EXIST::FUNCTION: -X509_ATTRIBUTE_set1_object 4763 4_0_0 EXIST::FUNCTION: -X509_ATTRIBUTE_set1_data 4764 4_0_0 EXIST::FUNCTION: -X509_ATTRIBUTE_get0_data 4765 4_0_0 EXIST::FUNCTION: -X509_ATTRIBUTE_count 4766 4_0_0 EXIST::FUNCTION: -X509_ATTRIBUTE_get0_object 4767 4_0_0 EXIST::FUNCTION: -X509_ATTRIBUTE_get0_type 4768 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_attr_count 4769 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_attr_by_NID 4770 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_attr_by_OBJ 4771 4_0_0 EXIST::FUNCTION: -EVP_PKEY_get_attr 4772 4_0_0 EXIST::FUNCTION: -EVP_PKEY_delete_attr 4773 4_0_0 EXIST::FUNCTION: -EVP_PKEY_add1_attr 4774 4_0_0 EXIST::FUNCTION: -EVP_PKEY_add1_attr_by_OBJ 4775 4_0_0 EXIST::FUNCTION: -EVP_PKEY_add1_attr_by_NID 4776 4_0_0 EXIST::FUNCTION: -EVP_PKEY_add1_attr_by_txt 4777 4_0_0 EXIST::FUNCTION: -X509_find_by_issuer_and_serial 4778 4_0_0 EXIST::FUNCTION: -X509_find_by_subject 4779 4_0_0 EXIST::FUNCTION: -d2i_PBEPARAM 4780 4_0_0 EXIST::FUNCTION: -i2d_PBEPARAM 4781 4_0_0 EXIST::FUNCTION: -PBEPARAM_free 4782 4_0_0 EXIST::FUNCTION: -PBEPARAM_new 4783 4_0_0 EXIST::FUNCTION: -PBEPARAM_it 4784 4_0_0 EXIST::FUNCTION: -d2i_PBE2PARAM 4785 4_0_0 EXIST::FUNCTION: -i2d_PBE2PARAM 4786 4_0_0 EXIST::FUNCTION: -PBE2PARAM_free 4787 4_0_0 EXIST::FUNCTION: -PBE2PARAM_new 4788 4_0_0 EXIST::FUNCTION: -PBE2PARAM_it 4789 4_0_0 EXIST::FUNCTION: -d2i_PBKDF2PARAM 4790 4_0_0 EXIST::FUNCTION: -i2d_PBKDF2PARAM 4791 4_0_0 EXIST::FUNCTION: -PBKDF2PARAM_free 4792 4_0_0 EXIST::FUNCTION: -PBKDF2PARAM_new 4793 4_0_0 EXIST::FUNCTION: -PBKDF2PARAM_it 4794 4_0_0 EXIST::FUNCTION: -d2i_PBMAC1PARAM 4795 4_0_0 EXIST::FUNCTION: -i2d_PBMAC1PARAM 4796 4_0_0 EXIST::FUNCTION: -PBMAC1PARAM_free 4797 4_0_0 EXIST::FUNCTION: -PBMAC1PARAM_new 4798 4_0_0 EXIST::FUNCTION: -PBMAC1PARAM_it 4799 4_0_0 EXIST::FUNCTION: -d2i_SCRYPT_PARAMS 4800 4_0_0 EXIST::FUNCTION:SCRYPT -i2d_SCRYPT_PARAMS 4801 4_0_0 EXIST::FUNCTION:SCRYPT -SCRYPT_PARAMS_free 4802 4_0_0 EXIST::FUNCTION:SCRYPT -SCRYPT_PARAMS_new 4803 4_0_0 EXIST::FUNCTION:SCRYPT -SCRYPT_PARAMS_it 4804 4_0_0 EXIST::FUNCTION:SCRYPT -PKCS5_pbe_set0_algor 4805 4_0_0 EXIST::FUNCTION: -PKCS5_pbe_set0_algor_ex 4806 4_0_0 EXIST::FUNCTION: -PKCS5_pbe_set 4807 4_0_0 EXIST::FUNCTION: -PKCS5_pbe_set_ex 4808 4_0_0 EXIST::FUNCTION: -PKCS5_pbe2_set 4809 4_0_0 EXIST::FUNCTION: -PKCS5_pbe2_set_iv 4810 4_0_0 EXIST::FUNCTION: -PKCS5_pbe2_set_iv_ex 4811 4_0_0 EXIST::FUNCTION: -PKCS5_pbe2_set_scrypt 4812 4_0_0 EXIST::FUNCTION:SCRYPT -PKCS5_pbkdf2_set 4813 4_0_0 EXIST::FUNCTION: -PKCS5_pbkdf2_set_ex 4814 4_0_0 EXIST::FUNCTION: -PBMAC1_get1_pbkdf2_param 4815 4_0_0 EXIST::FUNCTION: -d2i_PKCS8_PRIV_KEY_INFO 4816 4_0_0 EXIST::FUNCTION: -i2d_PKCS8_PRIV_KEY_INFO 4817 4_0_0 EXIST::FUNCTION: -PKCS8_PRIV_KEY_INFO_free 4818 4_0_0 EXIST::FUNCTION: -PKCS8_PRIV_KEY_INFO_new 4819 4_0_0 EXIST::FUNCTION: -PKCS8_PRIV_KEY_INFO_it 4820 4_0_0 EXIST::FUNCTION: -EVP_PKCS82PKEY 4821 4_0_0 EXIST::FUNCTION: -EVP_PKCS82PKEY_ex 4822 4_0_0 EXIST::FUNCTION: -EVP_PKEY2PKCS8 4823 4_0_0 EXIST::FUNCTION: -PKCS8_pkey_set0 4824 4_0_0 EXIST::FUNCTION: -PKCS8_pkey_get0 4825 4_0_0 EXIST::FUNCTION: -PKCS8_pkey_get0_attrs 4826 4_0_0 EXIST::FUNCTION: -PKCS8_pkey_add1_attr 4827 4_0_0 EXIST::FUNCTION: -PKCS8_pkey_add1_attr_by_NID 4828 4_0_0 EXIST::FUNCTION: -PKCS8_pkey_add1_attr_by_OBJ 4829 4_0_0 EXIST::FUNCTION: -X509_PUBKEY_set0_public_key 4830 4_0_0 EXIST::FUNCTION: -X509_PUBKEY_set0_param 4831 4_0_0 EXIST::FUNCTION: -X509_PUBKEY_get0_param 4832 4_0_0 EXIST::FUNCTION: -X509_PUBKEY_eq 4833 4_0_0 EXIST::FUNCTION: -d2i_X509_ACERT 4834 4_0_0 EXIST::FUNCTION: -i2d_X509_ACERT 4835 4_0_0 EXIST::FUNCTION: -X509_ACERT_free 4836 4_0_0 EXIST::FUNCTION: -X509_ACERT_new 4837 4_0_0 EXIST::FUNCTION: -X509_ACERT_it 4838 4_0_0 EXIST::FUNCTION: -X509_ACERT_dup 4839 4_0_0 EXIST::FUNCTION: -X509_ACERT_INFO_it 4840 4_0_0 EXIST::FUNCTION: -X509_ACERT_INFO_free 4841 4_0_0 EXIST::FUNCTION: -X509_ACERT_INFO_new 4842 4_0_0 EXIST::FUNCTION: -OSSL_OBJECT_DIGEST_INFO_free 4843 4_0_0 EXIST::FUNCTION: -OSSL_OBJECT_DIGEST_INFO_new 4844 4_0_0 EXIST::FUNCTION: -OSSL_ISSUER_SERIAL_free 4845 4_0_0 EXIST::FUNCTION: -OSSL_ISSUER_SERIAL_new 4846 4_0_0 EXIST::FUNCTION: -X509_ACERT_ISSUER_V2FORM_free 4847 4_0_0 EXIST::FUNCTION: -X509_ACERT_ISSUER_V2FORM_new 4848 4_0_0 EXIST::FUNCTION: -d2i_X509_ACERT_fp 4849 4_0_0 EXIST::FUNCTION:STDIO -i2d_X509_ACERT_fp 4850 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_X509_ACERT 4851 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_X509_ACERT 4852 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_bio_X509_ACERT 4853 4_0_0 EXIST::FUNCTION: -PEM_write_bio_X509_ACERT 4854 4_0_0 EXIST::FUNCTION: -d2i_X509_ACERT_bio 4855 4_0_0 EXIST::FUNCTION: -i2d_X509_ACERT_bio 4856 4_0_0 EXIST::FUNCTION: -X509_ACERT_sign 4857 4_0_0 EXIST::FUNCTION: -X509_ACERT_sign_ctx 4858 4_0_0 EXIST::FUNCTION: -X509_ACERT_verify 4859 4_0_0 EXIST::FUNCTION: -X509_ACERT_get0_holder_entityName 4860 4_0_0 EXIST::FUNCTION: -X509_ACERT_get0_holder_baseCertId 4861 4_0_0 EXIST::FUNCTION: -X509_ACERT_get0_holder_digest 4862 4_0_0 EXIST::FUNCTION: -X509_ACERT_get0_issuerName 4863 4_0_0 EXIST::FUNCTION: -X509_ACERT_get_version 4864 4_0_0 EXIST::FUNCTION: -X509_ACERT_get0_signature 4865 4_0_0 EXIST::FUNCTION: -X509_ACERT_get_signature_nid 4866 4_0_0 EXIST::FUNCTION: -X509_ACERT_get0_info_sigalg 4867 4_0_0 EXIST::FUNCTION: -X509_ACERT_get0_serialNumber 4868 4_0_0 EXIST::FUNCTION: -X509_ACERT_get0_notBefore 4869 4_0_0 EXIST::FUNCTION: -X509_ACERT_get0_notAfter 4870 4_0_0 EXIST::FUNCTION: -X509_ACERT_get0_issuerUID 4871 4_0_0 EXIST::FUNCTION: -X509_ACERT_print 4872 4_0_0 EXIST::FUNCTION: -X509_ACERT_print_ex 4873 4_0_0 EXIST::FUNCTION: -X509_ACERT_get_attr_count 4874 4_0_0 EXIST::FUNCTION: -X509_ACERT_get_attr_by_NID 4875 4_0_0 EXIST::FUNCTION: -X509_ACERT_get_attr_by_OBJ 4876 4_0_0 EXIST::FUNCTION: -X509_ACERT_get_attr 4877 4_0_0 EXIST::FUNCTION: -X509_ACERT_delete_attr 4878 4_0_0 EXIST::FUNCTION: -X509_ACERT_get_ext_d2i 4879 4_0_0 EXIST::FUNCTION: -X509_ACERT_add1_ext_i2d 4880 4_0_0 EXIST::FUNCTION: -X509_ACERT_get0_extensions 4881 4_0_0 EXIST::FUNCTION: -X509_ACERT_set_version 4882 4_0_0 EXIST::FUNCTION: -X509_ACERT_set0_holder_entityName 4883 4_0_0 EXIST::FUNCTION: -X509_ACERT_set0_holder_baseCertId 4884 4_0_0 EXIST::FUNCTION: -X509_ACERT_set0_holder_digest 4885 4_0_0 EXIST::FUNCTION: -X509_ACERT_add1_attr 4886 4_0_0 EXIST::FUNCTION: -X509_ACERT_add1_attr_by_OBJ 4887 4_0_0 EXIST::FUNCTION: -X509_ACERT_add1_attr_by_NID 4888 4_0_0 EXIST::FUNCTION: -X509_ACERT_add1_attr_by_txt 4889 4_0_0 EXIST::FUNCTION: -X509_ACERT_add_attr_nconf 4890 4_0_0 EXIST::FUNCTION: -X509_ACERT_set1_issuerName 4891 4_0_0 EXIST::FUNCTION: -X509_ACERT_set1_serialNumber 4892 4_0_0 EXIST::FUNCTION: -X509_ACERT_set1_notBefore 4893 4_0_0 EXIST::FUNCTION: -X509_ACERT_set1_notAfter 4894 4_0_0 EXIST::FUNCTION: -OSSL_OBJECT_DIGEST_INFO_get0_digest 4895 4_0_0 EXIST::FUNCTION: -OSSL_OBJECT_DIGEST_INFO_set1_digest 4896 4_0_0 EXIST::FUNCTION: -OSSL_ISSUER_SERIAL_get0_issuer 4897 4_0_0 EXIST::FUNCTION: -OSSL_ISSUER_SERIAL_get0_serial 4898 4_0_0 EXIST::FUNCTION: -OSSL_ISSUER_SERIAL_get0_issuerUID 4899 4_0_0 EXIST::FUNCTION: -OSSL_ISSUER_SERIAL_set1_issuer 4900 4_0_0 EXIST::FUNCTION: -OSSL_ISSUER_SERIAL_set1_serial 4901 4_0_0 EXIST::FUNCTION: -OSSL_ISSUER_SERIAL_set1_issuerUID 4902 4_0_0 EXIST::FUNCTION: -OSSL_IETF_ATTR_SYNTAX_VALUE_it 4903 4_0_0 EXIST::FUNCTION: -OSSL_IETF_ATTR_SYNTAX_VALUE_free 4904 4_0_0 EXIST::FUNCTION: -OSSL_IETF_ATTR_SYNTAX_VALUE_new 4905 4_0_0 EXIST::FUNCTION: -d2i_OSSL_IETF_ATTR_SYNTAX 4906 4_0_0 EXIST::FUNCTION: -i2d_OSSL_IETF_ATTR_SYNTAX 4907 4_0_0 EXIST::FUNCTION: -OSSL_IETF_ATTR_SYNTAX_free 4908 4_0_0 EXIST::FUNCTION: -OSSL_IETF_ATTR_SYNTAX_new 4909 4_0_0 EXIST::FUNCTION: -OSSL_IETF_ATTR_SYNTAX_it 4910 4_0_0 EXIST::FUNCTION: -OSSL_IETF_ATTR_SYNTAX_get0_policyAuthority 4911 4_0_0 EXIST::FUNCTION: -OSSL_IETF_ATTR_SYNTAX_set0_policyAuthority 4912 4_0_0 EXIST::FUNCTION: -OSSL_IETF_ATTR_SYNTAX_get_value_num 4913 4_0_0 EXIST::FUNCTION: -OSSL_IETF_ATTR_SYNTAX_get0_value 4914 4_0_0 EXIST::FUNCTION: -OSSL_IETF_ATTR_SYNTAX_add1_value 4915 4_0_0 EXIST::FUNCTION: -OSSL_IETF_ATTR_SYNTAX_print 4916 4_0_0 EXIST::FUNCTION: -d2i_OSSL_TARGET 4917 4_0_0 EXIST::FUNCTION: -i2d_OSSL_TARGET 4918 4_0_0 EXIST::FUNCTION: -OSSL_TARGET_free 4919 4_0_0 EXIST::FUNCTION: -OSSL_TARGET_new 4920 4_0_0 EXIST::FUNCTION: -OSSL_TARGET_it 4921 4_0_0 EXIST::FUNCTION: -d2i_OSSL_TARGETS 4922 4_0_0 EXIST::FUNCTION: -i2d_OSSL_TARGETS 4923 4_0_0 EXIST::FUNCTION: -OSSL_TARGETS_free 4924 4_0_0 EXIST::FUNCTION: -OSSL_TARGETS_new 4925 4_0_0 EXIST::FUNCTION: -OSSL_TARGETS_it 4926 4_0_0 EXIST::FUNCTION: -d2i_OSSL_TARGETING_INFORMATION 4927 4_0_0 EXIST::FUNCTION: -i2d_OSSL_TARGETING_INFORMATION 4928 4_0_0 EXIST::FUNCTION: -OSSL_TARGETING_INFORMATION_free 4929 4_0_0 EXIST::FUNCTION: -OSSL_TARGETING_INFORMATION_new 4930 4_0_0 EXIST::FUNCTION: -OSSL_TARGETING_INFORMATION_it 4931 4_0_0 EXIST::FUNCTION: -d2i_OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX 4932 4_0_0 EXIST::FUNCTION: -i2d_OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX 4933 4_0_0 EXIST::FUNCTION: -OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX_free 4934 4_0_0 EXIST::FUNCTION: -OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX_new 4935 4_0_0 EXIST::FUNCTION: -OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX_it 4936 4_0_0 EXIST::FUNCTION: -X509_TRUST_set 4937 4_0_0 EXIST::FUNCTION: -X509_TRUST_get_count 4938 4_0_0 EXIST::FUNCTION: -X509_TRUST_get0 4939 4_0_0 EXIST::FUNCTION: -X509_TRUST_get_by_id 4940 4_0_0 EXIST::FUNCTION: -X509_TRUST_add 4941 4_0_0 EXIST::FUNCTION: -X509_TRUST_cleanup 4942 4_0_0 EXIST::FUNCTION: -X509_TRUST_get_flags 4943 4_0_0 EXIST::FUNCTION: -X509_TRUST_get0_name 4944 4_0_0 EXIST::FUNCTION: -X509_TRUST_get_trust 4945 4_0_0 EXIST::FUNCTION: -X509_trusted 4946 4_0_0 EXIST::FUNCTION: -X509_add1_trust_object 4947 4_0_0 EXIST::FUNCTION: -X509_add1_reject_object 4948 4_0_0 EXIST::FUNCTION: -X509_trust_clear 4949 4_0_0 EXIST::FUNCTION: -X509_reject_clear 4950 4_0_0 EXIST::FUNCTION: -X509_get0_trust_objects 4951 4_0_0 EXIST::FUNCTION: -X509_get0_reject_objects 4952 4_0_0 EXIST::FUNCTION: -X509_TRUST_set_default 4953 4_0_0 EXIST::FUNCTION: -X509_check_trust 4954 4_0_0 EXIST::FUNCTION: -X509_verify_cert 4955 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_verify 4956 4_0_0 EXIST::FUNCTION: -X509_build_chain 4957 4_0_0 EXIST::FUNCTION: -X509_STORE_set_depth 4958 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_print_verify_cb 4959 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set_depth 4960 4_0_0 EXIST::FUNCTION: -X509_OBJECT_idx_by_subject 4961 4_0_0 EXIST::FUNCTION: -X509_OBJECT_retrieve_by_subject 4962 4_0_0 EXIST::FUNCTION: -X509_OBJECT_retrieve_match 4963 4_0_0 EXIST::FUNCTION: -X509_OBJECT_up_ref_count 4964 4_0_0 EXIST::FUNCTION: -X509_OBJECT_new 4965 4_0_0 EXIST::FUNCTION: -X509_OBJECT_free 4966 4_0_0 EXIST::FUNCTION: -X509_OBJECT_get_type 4967 4_0_0 EXIST::FUNCTION: -X509_OBJECT_get0_X509 4968 4_0_0 EXIST::FUNCTION: -X509_OBJECT_set1_X509 4969 4_0_0 EXIST::FUNCTION: -X509_OBJECT_get0_X509_CRL 4970 4_0_0 EXIST::FUNCTION: -X509_OBJECT_set1_X509_CRL 4971 4_0_0 EXIST::FUNCTION: -X509_STORE_new 4972 4_0_0 EXIST::FUNCTION: -X509_STORE_free 4973 4_0_0 EXIST::FUNCTION: -X509_STORE_lock 4974 4_0_0 EXIST::FUNCTION: -X509_STORE_unlock 4975 4_0_0 EXIST::FUNCTION: -X509_STORE_up_ref 4976 4_0_0 EXIST::FUNCTION: -X509_STORE_get0_objects 4977 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_0 -X509_STORE_get1_objects 4978 4_0_0 EXIST::FUNCTION: -X509_STORE_get1_all_certs 4979 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get1_certs 4980 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get1_crls 4981 4_0_0 EXIST::FUNCTION: -X509_STORE_set_flags 4982 4_0_0 EXIST::FUNCTION: -X509_STORE_set_purpose 4983 4_0_0 EXIST::FUNCTION: -X509_STORE_set_trust 4984 4_0_0 EXIST::FUNCTION: -X509_STORE_set1_param 4985 4_0_0 EXIST::FUNCTION: -X509_STORE_get0_param 4986 4_0_0 EXIST::FUNCTION: -X509_STORE_set_verify 4987 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set_verify 4988 4_0_0 EXIST::FUNCTION: -X509_STORE_get_verify 4989 4_0_0 EXIST::FUNCTION: -X509_STORE_set_verify_cb 4990 4_0_0 EXIST::FUNCTION: -X509_STORE_get_verify_cb 4991 4_0_0 EXIST::FUNCTION: -X509_STORE_set_get_issuer 4992 4_0_0 EXIST::FUNCTION: -X509_STORE_get_get_issuer 4993 4_0_0 EXIST::FUNCTION: -X509_STORE_set_check_issued 4994 4_0_0 EXIST::FUNCTION: -X509_STORE_get_check_issued 4995 4_0_0 EXIST::FUNCTION: -X509_STORE_set_check_revocation 4996 4_0_0 EXIST::FUNCTION: -X509_STORE_get_check_revocation 4997 4_0_0 EXIST::FUNCTION: -X509_STORE_set_get_crl 4998 4_0_0 EXIST::FUNCTION: -X509_STORE_get_get_crl 4999 4_0_0 EXIST::FUNCTION: -X509_STORE_set_check_crl 5000 4_0_0 EXIST::FUNCTION: -X509_STORE_get_check_crl 5001 4_0_0 EXIST::FUNCTION: -X509_STORE_set_cert_crl 5002 4_0_0 EXIST::FUNCTION: -X509_STORE_get_cert_crl 5003 4_0_0 EXIST::FUNCTION: -X509_STORE_set_check_policy 5004 4_0_0 EXIST::FUNCTION: -X509_STORE_get_check_policy 5005 4_0_0 EXIST::FUNCTION: -X509_STORE_set_lookup_certs 5006 4_0_0 EXIST::FUNCTION: -X509_STORE_get_lookup_certs 5007 4_0_0 EXIST::FUNCTION: -X509_STORE_set_lookup_crls 5008 4_0_0 EXIST::FUNCTION: -X509_STORE_get_lookup_crls 5009 4_0_0 EXIST::FUNCTION: -X509_STORE_set_cleanup 5010 4_0_0 EXIST::FUNCTION: -X509_STORE_get_cleanup 5011 4_0_0 EXIST::FUNCTION: -X509_STORE_set_ex_data 5012 4_0_0 EXIST::FUNCTION: -X509_STORE_get_ex_data 5013 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_new_ex 5014 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_new 5015 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get1_issuer 5016 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_free 5017 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_init 5018 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_init_rpk 5019 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set0_trusted_stack 5020 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_cleanup 5021 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get0_store 5022 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get0_cert 5023 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get0_rpk 5024 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get0_untrusted 5025 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set0_untrusted 5026 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set_verify_cb 5027 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_verify_cb 5028 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_verify 5029 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_get_issuer 5030 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_check_issued 5031 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_check_revocation 5032 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set_get_crl 5033 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_get_crl 5034 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_check_crl 5035 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_cert_crl 5036 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_check_policy 5037 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_lookup_certs 5038 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_lookup_crls 5039 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_cleanup 5040 4_0_0 EXIST::FUNCTION: -X509_STORE_add_lookup 5041 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_hash_dir 5042 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_file 5043 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_store 5044 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_new 5045 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_free 5046 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_set_new_item 5047 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_get_new_item 5048 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_set_free 5049 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_get_free 5050 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_set_init 5051 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_get_init 5052 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_set_shutdown 5053 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_get_shutdown 5054 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_set_ctrl 5055 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_get_ctrl 5056 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_set_get_by_subject 5057 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_get_get_by_subject 5058 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_set_get_by_issuer_serial 5059 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_get_get_by_issuer_serial 5060 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_set_get_by_fingerprint 5061 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_get_get_by_fingerprint 5062 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_set_get_by_alias 5063 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_meth_get_get_by_alias 5064 4_0_0 EXIST::FUNCTION: -X509_STORE_add_cert 5065 4_0_0 EXIST::FUNCTION: -X509_STORE_add_crl 5066 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_by_subject 5067 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_obj_by_subject 5068 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_ctrl 5069 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_ctrl_ex 5070 4_0_0 EXIST::FUNCTION: -X509_load_cert_file 5071 4_0_0 EXIST::FUNCTION: -X509_load_cert_file_ex 5072 4_0_0 EXIST::FUNCTION: -X509_load_crl_file 5073 4_0_0 EXIST::FUNCTION: -X509_load_cert_crl_file 5074 4_0_0 EXIST::FUNCTION: -X509_load_cert_crl_file_ex 5075 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_new 5076 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_free 5077 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_init 5078 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_by_subject 5079 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_by_subject_ex 5080 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_by_issuer_serial 5081 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_by_fingerprint 5082 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_by_alias 5083 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_set_method_data 5084 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_get_method_data 5085 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_get_store 5086 4_0_0 EXIST::FUNCTION: -X509_LOOKUP_shutdown 5087 4_0_0 EXIST::FUNCTION: -X509_STORE_load_file 5088 4_0_0 EXIST::FUNCTION: -X509_STORE_load_path 5089 4_0_0 EXIST::FUNCTION: -X509_STORE_load_store 5090 4_0_0 EXIST::FUNCTION: -X509_STORE_load_locations 5091 4_0_0 EXIST::FUNCTION: -X509_STORE_set_default_paths 5092 4_0_0 EXIST::FUNCTION: -X509_STORE_load_file_ex 5093 4_0_0 EXIST::FUNCTION: -X509_STORE_load_store_ex 5094 4_0_0 EXIST::FUNCTION: -X509_STORE_load_locations_ex 5095 4_0_0 EXIST::FUNCTION: -X509_STORE_set_default_paths_ex 5096 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set_ex_data 5097 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_ex_data 5098 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_error 5099 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set_error 5100 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_error_depth 5101 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set_error_depth 5102 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_current_cert 5103 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set_current_cert 5104 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get0_current_issuer 5105 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get0_current_crl 5106 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get0_parent_ctx 5107 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get0_chain 5108 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get1_chain 5109 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set_cert 5110 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set0_rpk 5111 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set0_verified_chain 5112 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set0_crls 5113 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set_ocsp_resp 5114 4_0_0 EXIST::FUNCTION:OCSP -X509_STORE_CTX_set_purpose 5115 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set_trust 5116 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_purpose_inherit 5117 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set_flags 5118 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set_time 5119 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set_current_reasons 5120 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get0_policy_tree 5121 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_explicit_policy 5122 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get_num_untrusted 5123 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_get0_param 5124 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set0_param 5125 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set_default 5126 4_0_0 EXIST::FUNCTION: -X509_STORE_CTX_set0_dane 5127 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_new 5128 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_free 5129 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_inherit 5130 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set1 5131 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set1_name 5132 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set_flags 5133 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_clear_flags 5134 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_get_flags 5135 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set_purpose 5136 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_get_purpose 5137 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set_trust 5138 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set_depth 5139 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set_auth_level 5140 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_get_time 5141 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set_time 5142 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_add0_policy 5143 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set1_policies 5144 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set_inh_flags 5145 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_get_inh_flags 5146 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_get0_host 5147 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set1_host 5148 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_add1_host 5149 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set1_host_input_validation 5150 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set_hostflags 5151 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_get_hostflags 5152 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_get0_peername 5153 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_move_peername 5154 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_get0_email 5155 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set1_email 5156 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set1_rfc822 5157 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_add1_rfc822 5158 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set1_rfc822_input_validation 5159 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set1_smtputf8 5160 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_add1_smtputf8 5161 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set1_smtputf8_input_validation 5162 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_get1_ip_asc 5163 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set1_ip 5164 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set1_ip_asc 5165 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_add1_ip 5166 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_add1_ip_asc 5167 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_set1_ip_input_validation 5168 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_get_depth 5169 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_get_auth_level 5170 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_get0_name 5171 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_add0_table 5172 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_get_count 5173 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_get0 5174 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_lookup 5175 4_0_0 EXIST::FUNCTION: -X509_VERIFY_PARAM_table_cleanup 5176 4_0_0 EXIST::FUNCTION: -X509_policy_check 5177 4_0_0 EXIST::FUNCTION: -X509_policy_tree_free 5178 4_0_0 EXIST::FUNCTION: -X509_policy_tree_level_count 5179 4_0_0 EXIST::FUNCTION: -X509_policy_tree_get0_level 5180 4_0_0 EXIST::FUNCTION: -X509_policy_tree_get0_policies 5181 4_0_0 EXIST::FUNCTION: -X509_policy_tree_get0_user_policies 5182 4_0_0 EXIST::FUNCTION: -X509_policy_level_node_count 5183 4_0_0 EXIST::FUNCTION: -X509_policy_level_get0_node 5184 4_0_0 EXIST::FUNCTION: -X509_policy_node_get0_policy 5185 4_0_0 EXIST::FUNCTION: -X509_policy_node_get0_qualifiers 5186 4_0_0 EXIST::FUNCTION: -X509_policy_node_get0_parent 5187 4_0_0 EXIST::FUNCTION: -GENERAL_NAME_set1_X509_NAME 5188 4_0_0 EXIST::FUNCTION: -DIST_POINT_NAME_dup 5189 4_0_0 EXIST::FUNCTION: -d2i_PROXY_POLICY 5190 4_0_0 EXIST::FUNCTION: -i2d_PROXY_POLICY 5191 4_0_0 EXIST::FUNCTION: -PROXY_POLICY_free 5192 4_0_0 EXIST::FUNCTION: -PROXY_POLICY_new 5193 4_0_0 EXIST::FUNCTION: -PROXY_POLICY_it 5194 4_0_0 EXIST::FUNCTION: -d2i_PROXY_CERT_INFO_EXTENSION 5195 4_0_0 EXIST::FUNCTION: -i2d_PROXY_CERT_INFO_EXTENSION 5196 4_0_0 EXIST::FUNCTION: -PROXY_CERT_INFO_EXTENSION_free 5197 4_0_0 EXIST::FUNCTION: -PROXY_CERT_INFO_EXTENSION_new 5198 4_0_0 EXIST::FUNCTION: -PROXY_CERT_INFO_EXTENSION_it 5199 4_0_0 EXIST::FUNCTION: -d2i_BASIC_CONSTRAINTS 5200 4_0_0 EXIST::FUNCTION: -i2d_BASIC_CONSTRAINTS 5201 4_0_0 EXIST::FUNCTION: -BASIC_CONSTRAINTS_free 5202 4_0_0 EXIST::FUNCTION: -BASIC_CONSTRAINTS_new 5203 4_0_0 EXIST::FUNCTION: -BASIC_CONSTRAINTS_it 5204 4_0_0 EXIST::FUNCTION: -d2i_OSSL_BASIC_ATTR_CONSTRAINTS 5205 4_0_0 EXIST::FUNCTION: -i2d_OSSL_BASIC_ATTR_CONSTRAINTS 5206 4_0_0 EXIST::FUNCTION: -OSSL_BASIC_ATTR_CONSTRAINTS_free 5207 4_0_0 EXIST::FUNCTION: -OSSL_BASIC_ATTR_CONSTRAINTS_new 5208 4_0_0 EXIST::FUNCTION: -OSSL_BASIC_ATTR_CONSTRAINTS_it 5209 4_0_0 EXIST::FUNCTION: -d2i_SXNET 5210 4_0_0 EXIST::FUNCTION: -i2d_SXNET 5211 4_0_0 EXIST::FUNCTION: -SXNET_free 5212 4_0_0 EXIST::FUNCTION: -SXNET_new 5213 4_0_0 EXIST::FUNCTION: -SXNET_it 5214 4_0_0 EXIST::FUNCTION: -d2i_SXNETID 5215 4_0_0 EXIST::FUNCTION: -i2d_SXNETID 5216 4_0_0 EXIST::FUNCTION: -SXNETID_free 5217 4_0_0 EXIST::FUNCTION: -SXNETID_new 5218 4_0_0 EXIST::FUNCTION: -SXNETID_it 5219 4_0_0 EXIST::FUNCTION: -d2i_ISSUER_SIGN_TOOL 5220 4_0_0 EXIST::FUNCTION: -i2d_ISSUER_SIGN_TOOL 5221 4_0_0 EXIST::FUNCTION: -ISSUER_SIGN_TOOL_free 5222 4_0_0 EXIST::FUNCTION: -ISSUER_SIGN_TOOL_new 5223 4_0_0 EXIST::FUNCTION: -ISSUER_SIGN_TOOL_it 5224 4_0_0 EXIST::FUNCTION: -SXNET_add_id_asc 5225 4_0_0 EXIST::FUNCTION: -SXNET_add_id_ulong 5226 4_0_0 EXIST::FUNCTION: -SXNET_add_id_INTEGER 5227 4_0_0 EXIST::FUNCTION: -SXNET_get_id_asc 5228 4_0_0 EXIST::FUNCTION: -SXNET_get_id_ulong 5229 4_0_0 EXIST::FUNCTION: -SXNET_get_id_INTEGER 5230 4_0_0 EXIST::FUNCTION: -d2i_AUTHORITY_KEYID 5231 4_0_0 EXIST::FUNCTION: -i2d_AUTHORITY_KEYID 5232 4_0_0 EXIST::FUNCTION: -AUTHORITY_KEYID_free 5233 4_0_0 EXIST::FUNCTION: -AUTHORITY_KEYID_new 5234 4_0_0 EXIST::FUNCTION: -AUTHORITY_KEYID_it 5235 4_0_0 EXIST::FUNCTION: -d2i_PKEY_USAGE_PERIOD 5236 4_0_0 EXIST::FUNCTION: -i2d_PKEY_USAGE_PERIOD 5237 4_0_0 EXIST::FUNCTION: -PKEY_USAGE_PERIOD_free 5238 4_0_0 EXIST::FUNCTION: -PKEY_USAGE_PERIOD_new 5239 4_0_0 EXIST::FUNCTION: -PKEY_USAGE_PERIOD_it 5240 4_0_0 EXIST::FUNCTION: -d2i_GENERAL_NAME 5241 4_0_0 EXIST::FUNCTION: -i2d_GENERAL_NAME 5242 4_0_0 EXIST::FUNCTION: -GENERAL_NAME_free 5243 4_0_0 EXIST::FUNCTION: -GENERAL_NAME_new 5244 4_0_0 EXIST::FUNCTION: -GENERAL_NAME_it 5245 4_0_0 EXIST::FUNCTION: -GENERAL_NAME_dup 5246 4_0_0 EXIST::FUNCTION: -GENERAL_NAME_cmp 5247 4_0_0 EXIST::FUNCTION: -v2i_ASN1_BIT_STRING 5248 4_0_0 EXIST::FUNCTION: -i2v_ASN1_BIT_STRING 5249 4_0_0 EXIST::FUNCTION: -i2s_ASN1_IA5STRING 5250 4_0_0 EXIST::FUNCTION: -s2i_ASN1_IA5STRING 5251 4_0_0 EXIST::FUNCTION: -i2s_ASN1_UTF8STRING 5252 4_0_0 EXIST::FUNCTION: -s2i_ASN1_UTF8STRING 5253 4_0_0 EXIST::FUNCTION: -i2v_GENERAL_NAME 5254 4_0_0 EXIST::FUNCTION: -GENERAL_NAME_print 5255 4_0_0 EXIST::FUNCTION: -d2i_GENERAL_NAMES 5256 4_0_0 EXIST::FUNCTION: -i2d_GENERAL_NAMES 5257 4_0_0 EXIST::FUNCTION: -GENERAL_NAMES_free 5258 4_0_0 EXIST::FUNCTION: -GENERAL_NAMES_new 5259 4_0_0 EXIST::FUNCTION: -GENERAL_NAMES_it 5260 4_0_0 EXIST::FUNCTION: -i2v_GENERAL_NAMES 5261 4_0_0 EXIST::FUNCTION: -v2i_GENERAL_NAMES 5262 4_0_0 EXIST::FUNCTION: -d2i_OTHERNAME 5263 4_0_0 EXIST::FUNCTION: -i2d_OTHERNAME 5264 4_0_0 EXIST::FUNCTION: -OTHERNAME_free 5265 4_0_0 EXIST::FUNCTION: -OTHERNAME_new 5266 4_0_0 EXIST::FUNCTION: -OTHERNAME_it 5267 4_0_0 EXIST::FUNCTION: -d2i_EDIPARTYNAME 5268 4_0_0 EXIST::FUNCTION: -i2d_EDIPARTYNAME 5269 4_0_0 EXIST::FUNCTION: -EDIPARTYNAME_free 5270 4_0_0 EXIST::FUNCTION: -EDIPARTYNAME_new 5271 4_0_0 EXIST::FUNCTION: -EDIPARTYNAME_it 5272 4_0_0 EXIST::FUNCTION: -OTHERNAME_cmp 5273 4_0_0 EXIST::FUNCTION: -GENERAL_NAME_set0_value 5274 4_0_0 EXIST::FUNCTION: -GENERAL_NAME_get0_value 5275 4_0_0 EXIST::FUNCTION: -GENERAL_NAME_set0_othername 5276 4_0_0 EXIST::FUNCTION: -GENERAL_NAME_get0_otherName 5277 4_0_0 EXIST::FUNCTION: -i2s_ASN1_OCTET_STRING 5278 4_0_0 EXIST::FUNCTION: -s2i_ASN1_OCTET_STRING 5279 4_0_0 EXIST::FUNCTION: -d2i_EXTENDED_KEY_USAGE 5280 4_0_0 EXIST::FUNCTION: -i2d_EXTENDED_KEY_USAGE 5281 4_0_0 EXIST::FUNCTION: -EXTENDED_KEY_USAGE_free 5282 4_0_0 EXIST::FUNCTION: -EXTENDED_KEY_USAGE_new 5283 4_0_0 EXIST::FUNCTION: -EXTENDED_KEY_USAGE_it 5284 4_0_0 EXIST::FUNCTION: -i2a_ACCESS_DESCRIPTION 5285 4_0_0 EXIST::FUNCTION: -TLS_FEATURE_free 5286 4_0_0 EXIST::FUNCTION: -TLS_FEATURE_new 5287 4_0_0 EXIST::FUNCTION: -d2i_CERTIFICATEPOLICIES 5288 4_0_0 EXIST::FUNCTION: -i2d_CERTIFICATEPOLICIES 5289 4_0_0 EXIST::FUNCTION: -CERTIFICATEPOLICIES_free 5290 4_0_0 EXIST::FUNCTION: -CERTIFICATEPOLICIES_new 5291 4_0_0 EXIST::FUNCTION: -CERTIFICATEPOLICIES_it 5292 4_0_0 EXIST::FUNCTION: -d2i_POLICYINFO 5293 4_0_0 EXIST::FUNCTION: -i2d_POLICYINFO 5294 4_0_0 EXIST::FUNCTION: -POLICYINFO_free 5295 4_0_0 EXIST::FUNCTION: -POLICYINFO_new 5296 4_0_0 EXIST::FUNCTION: -POLICYINFO_it 5297 4_0_0 EXIST::FUNCTION: -d2i_POLICYQUALINFO 5298 4_0_0 EXIST::FUNCTION: -i2d_POLICYQUALINFO 5299 4_0_0 EXIST::FUNCTION: -POLICYQUALINFO_free 5300 4_0_0 EXIST::FUNCTION: -POLICYQUALINFO_new 5301 4_0_0 EXIST::FUNCTION: -POLICYQUALINFO_it 5302 4_0_0 EXIST::FUNCTION: -d2i_USERNOTICE 5303 4_0_0 EXIST::FUNCTION: -i2d_USERNOTICE 5304 4_0_0 EXIST::FUNCTION: -USERNOTICE_free 5305 4_0_0 EXIST::FUNCTION: -USERNOTICE_new 5306 4_0_0 EXIST::FUNCTION: -USERNOTICE_it 5307 4_0_0 EXIST::FUNCTION: -d2i_NOTICEREF 5308 4_0_0 EXIST::FUNCTION: -i2d_NOTICEREF 5309 4_0_0 EXIST::FUNCTION: -NOTICEREF_free 5310 4_0_0 EXIST::FUNCTION: -NOTICEREF_new 5311 4_0_0 EXIST::FUNCTION: -NOTICEREF_it 5312 4_0_0 EXIST::FUNCTION: -d2i_CRL_DIST_POINTS 5313 4_0_0 EXIST::FUNCTION: -i2d_CRL_DIST_POINTS 5314 4_0_0 EXIST::FUNCTION: -CRL_DIST_POINTS_free 5315 4_0_0 EXIST::FUNCTION: -CRL_DIST_POINTS_new 5316 4_0_0 EXIST::FUNCTION: -CRL_DIST_POINTS_it 5317 4_0_0 EXIST::FUNCTION: -d2i_DIST_POINT 5318 4_0_0 EXIST::FUNCTION: -i2d_DIST_POINT 5319 4_0_0 EXIST::FUNCTION: -DIST_POINT_free 5320 4_0_0 EXIST::FUNCTION: -DIST_POINT_new 5321 4_0_0 EXIST::FUNCTION: -DIST_POINT_it 5322 4_0_0 EXIST::FUNCTION: -d2i_DIST_POINT_NAME 5323 4_0_0 EXIST::FUNCTION: -i2d_DIST_POINT_NAME 5324 4_0_0 EXIST::FUNCTION: -DIST_POINT_NAME_free 5325 4_0_0 EXIST::FUNCTION: -DIST_POINT_NAME_new 5326 4_0_0 EXIST::FUNCTION: -DIST_POINT_NAME_it 5327 4_0_0 EXIST::FUNCTION: -d2i_ISSUING_DIST_POINT 5328 4_0_0 EXIST::FUNCTION: -i2d_ISSUING_DIST_POINT 5329 4_0_0 EXIST::FUNCTION: -ISSUING_DIST_POINT_free 5330 4_0_0 EXIST::FUNCTION: -ISSUING_DIST_POINT_new 5331 4_0_0 EXIST::FUNCTION: -ISSUING_DIST_POINT_it 5332 4_0_0 EXIST::FUNCTION: -DIST_POINT_set_dpname 5333 4_0_0 EXIST::FUNCTION: -NAME_CONSTRAINTS_check 5334 4_0_0 EXIST::FUNCTION: -NAME_CONSTRAINTS_check_CN 5335 4_0_0 EXIST::FUNCTION: -d2i_ACCESS_DESCRIPTION 5336 4_0_0 EXIST::FUNCTION: -i2d_ACCESS_DESCRIPTION 5337 4_0_0 EXIST::FUNCTION: -ACCESS_DESCRIPTION_free 5338 4_0_0 EXIST::FUNCTION: -ACCESS_DESCRIPTION_new 5339 4_0_0 EXIST::FUNCTION: -ACCESS_DESCRIPTION_it 5340 4_0_0 EXIST::FUNCTION: -d2i_AUTHORITY_INFO_ACCESS 5341 4_0_0 EXIST::FUNCTION: -i2d_AUTHORITY_INFO_ACCESS 5342 4_0_0 EXIST::FUNCTION: -AUTHORITY_INFO_ACCESS_free 5343 4_0_0 EXIST::FUNCTION: -AUTHORITY_INFO_ACCESS_new 5344 4_0_0 EXIST::FUNCTION: -AUTHORITY_INFO_ACCESS_it 5345 4_0_0 EXIST::FUNCTION: -POLICY_MAPPING_it 5346 4_0_0 EXIST::FUNCTION: -POLICY_MAPPING_free 5347 4_0_0 EXIST::FUNCTION: -POLICY_MAPPING_new 5348 4_0_0 EXIST::FUNCTION: -POLICY_MAPPINGS_it 5349 4_0_0 EXIST::FUNCTION: -GENERAL_SUBTREE_it 5350 4_0_0 EXIST::FUNCTION: -GENERAL_SUBTREE_free 5351 4_0_0 EXIST::FUNCTION: -GENERAL_SUBTREE_new 5352 4_0_0 EXIST::FUNCTION: -NAME_CONSTRAINTS_it 5353 4_0_0 EXIST::FUNCTION: -NAME_CONSTRAINTS_free 5354 4_0_0 EXIST::FUNCTION: -NAME_CONSTRAINTS_new 5355 4_0_0 EXIST::FUNCTION: -POLICY_CONSTRAINTS_free 5356 4_0_0 EXIST::FUNCTION: -POLICY_CONSTRAINTS_new 5357 4_0_0 EXIST::FUNCTION: -POLICY_CONSTRAINTS_it 5358 4_0_0 EXIST::FUNCTION: -a2i_GENERAL_NAME 5359 4_0_0 EXIST::FUNCTION: -v2i_GENERAL_NAME 5360 4_0_0 EXIST::FUNCTION: -v2i_GENERAL_NAME_ex 5361 4_0_0 EXIST::FUNCTION: -X509V3_conf_free 5362 4_0_0 EXIST::FUNCTION: -X509V3_EXT_nconf_nid 5363 4_0_0 EXIST::FUNCTION: -X509V3_EXT_nconf 5364 4_0_0 EXIST::FUNCTION: -X509V3_EXT_add_nconf_sk 5365 4_0_0 EXIST::FUNCTION: -X509V3_EXT_add_nconf 5366 4_0_0 EXIST::FUNCTION: -X509V3_EXT_REQ_add_nconf 5367 4_0_0 EXIST::FUNCTION: -X509V3_EXT_CRL_add_nconf 5368 4_0_0 EXIST::FUNCTION: -X509V3_EXT_conf_nid 5369 4_0_0 EXIST::FUNCTION: -X509V3_EXT_conf 5370 4_0_0 EXIST::FUNCTION: -X509V3_EXT_add_conf 5371 4_0_0 EXIST::FUNCTION: -X509V3_EXT_REQ_add_conf 5372 4_0_0 EXIST::FUNCTION: -X509V3_EXT_CRL_add_conf 5373 4_0_0 EXIST::FUNCTION: -X509V3_add_value_bool_nf 5374 4_0_0 EXIST::FUNCTION: -X509V3_get_value_bool 5375 4_0_0 EXIST::FUNCTION: -X509V3_get_value_int 5376 4_0_0 EXIST::FUNCTION: -X509V3_set_nconf 5377 4_0_0 EXIST::FUNCTION: -X509V3_set_conf_lhash 5378 4_0_0 EXIST::FUNCTION: -X509V3_get_string 5379 4_0_0 EXIST::FUNCTION: -X509V3_get_section 5380 4_0_0 EXIST::FUNCTION: -X509V3_string_free 5381 4_0_0 EXIST::FUNCTION: -X509V3_section_free 5382 4_0_0 EXIST::FUNCTION: -X509V3_set_ctx 5383 4_0_0 EXIST::FUNCTION: -X509V3_set_issuer_pkey 5384 4_0_0 EXIST::FUNCTION: -X509V3_add_value 5385 4_0_0 EXIST::FUNCTION: -X509V3_add_value_uchar 5386 4_0_0 EXIST::FUNCTION: -X509V3_add_value_bool 5387 4_0_0 EXIST::FUNCTION: -X509V3_add_value_int 5388 4_0_0 EXIST::FUNCTION: -i2s_ASN1_INTEGER 5389 4_0_0 EXIST::FUNCTION: -s2i_ASN1_INTEGER 5390 4_0_0 EXIST::FUNCTION: -i2s_ASN1_ENUMERATED 5391 4_0_0 EXIST::FUNCTION: -i2s_ASN1_ENUMERATED_TABLE 5392 4_0_0 EXIST::FUNCTION: -X509V3_EXT_add 5393 4_0_0 EXIST::FUNCTION: -X509V3_EXT_add_list 5394 4_0_0 EXIST::FUNCTION: -X509V3_EXT_add_alias 5395 4_0_0 EXIST::FUNCTION: -X509V3_EXT_cleanup 5396 4_0_0 EXIST::FUNCTION: -X509V3_EXT_get 5397 4_0_0 EXIST::FUNCTION: -X509V3_EXT_get_nid 5398 4_0_0 EXIST::FUNCTION: -X509V3_add_standard_extensions 5399 4_0_0 EXIST::FUNCTION: -X509V3_parse_list 5400 4_0_0 EXIST::FUNCTION: -X509V3_EXT_d2i 5401 4_0_0 EXIST::FUNCTION: -X509V3_get_d2i 5402 4_0_0 EXIST::FUNCTION: -X509V3_EXT_i2d 5403 4_0_0 EXIST::FUNCTION: -X509V3_add1_i2d 5404 4_0_0 EXIST::FUNCTION: -X509V3_EXT_val_prn 5405 4_0_0 EXIST::FUNCTION: -X509V3_EXT_print 5406 4_0_0 EXIST::FUNCTION: -X509V3_EXT_print_fp 5407 4_0_0 EXIST::FUNCTION:STDIO -X509V3_extensions_print 5408 4_0_0 EXIST::FUNCTION: -X509_check_ca 5409 4_0_0 EXIST::FUNCTION: -X509_check_purpose 5410 4_0_0 EXIST::FUNCTION: -X509_supported_extension 5411 4_0_0 EXIST::FUNCTION: -X509_check_issued 5412 4_0_0 EXIST::FUNCTION: -X509_check_akid 5413 4_0_0 EXIST::FUNCTION: -X509_set_proxy_flag 5414 4_0_0 EXIST::FUNCTION: -X509_set_proxy_pathlen 5415 4_0_0 EXIST::FUNCTION: -X509_get_proxy_pathlen 5416 4_0_0 EXIST::FUNCTION: -X509_get_extension_flags 5417 4_0_0 EXIST::FUNCTION: -X509_get_key_usage 5418 4_0_0 EXIST::FUNCTION: -X509_get_extended_key_usage 5419 4_0_0 EXIST::FUNCTION: -X509_get0_subject_key_id 5420 4_0_0 EXIST::FUNCTION: -X509_get0_authority_key_id 5421 4_0_0 EXIST::FUNCTION: -X509_get0_authority_issuer 5422 4_0_0 EXIST::FUNCTION: -X509_get0_authority_serial 5423 4_0_0 EXIST::FUNCTION: -X509_PURPOSE_get_count 5424 4_0_0 EXIST::FUNCTION: -X509_PURPOSE_get_unused_id 5425 4_0_0 EXIST::FUNCTION: -X509_PURPOSE_get_by_sname 5426 4_0_0 EXIST::FUNCTION: -X509_PURPOSE_get_by_id 5427 4_0_0 EXIST::FUNCTION: -X509_PURPOSE_add 5428 4_0_0 EXIST::FUNCTION: -X509_PURPOSE_cleanup 5429 4_0_0 EXIST::FUNCTION: -X509_PURPOSE_get0 5430 4_0_0 EXIST::FUNCTION: -X509_PURPOSE_get_id 5431 4_0_0 EXIST::FUNCTION: -X509_PURPOSE_get0_name 5432 4_0_0 EXIST::FUNCTION: -X509_PURPOSE_get0_sname 5433 4_0_0 EXIST::FUNCTION: -X509_PURPOSE_get_trust 5434 4_0_0 EXIST::FUNCTION: -X509_PURPOSE_set 5435 4_0_0 EXIST::FUNCTION: -X509_get1_email 5436 4_0_0 EXIST::FUNCTION: -X509_REQ_get1_email 5437 4_0_0 EXIST::FUNCTION: -X509_email_free 5438 4_0_0 EXIST::FUNCTION: -X509_get1_ocsp 5439 4_0_0 EXIST::FUNCTION: -X509_check_host 5440 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1 -X509_check_email 5441 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1 -X509_check_ip 5442 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1 -X509_check_ip_asc 5443 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1 -a2i_IPADDRESS 5444 4_0_0 EXIST::FUNCTION: -a2i_IPADDRESS_NC 5445 4_0_0 EXIST::FUNCTION: -X509V3_NAME_from_section 5446 4_0_0 EXIST::FUNCTION: -X509_POLICY_NODE_print 5447 4_0_0 EXIST::FUNCTION: -d2i_ASRange 5448 4_0_0 EXIST::FUNCTION:RFC3779 -i2d_ASRange 5449 4_0_0 EXIST::FUNCTION:RFC3779 -ASRange_free 5450 4_0_0 EXIST::FUNCTION:RFC3779 -ASRange_new 5451 4_0_0 EXIST::FUNCTION:RFC3779 -ASRange_it 5452 4_0_0 EXIST::FUNCTION:RFC3779 -d2i_ASIdOrRange 5453 4_0_0 EXIST::FUNCTION:RFC3779 -i2d_ASIdOrRange 5454 4_0_0 EXIST::FUNCTION:RFC3779 -ASIdOrRange_free 5455 4_0_0 EXIST::FUNCTION:RFC3779 -ASIdOrRange_new 5456 4_0_0 EXIST::FUNCTION:RFC3779 -ASIdOrRange_it 5457 4_0_0 EXIST::FUNCTION:RFC3779 -d2i_ASIdentifierChoice 5458 4_0_0 EXIST::FUNCTION:RFC3779 -i2d_ASIdentifierChoice 5459 4_0_0 EXIST::FUNCTION:RFC3779 -ASIdentifierChoice_free 5460 4_0_0 EXIST::FUNCTION:RFC3779 -ASIdentifierChoice_new 5461 4_0_0 EXIST::FUNCTION:RFC3779 -ASIdentifierChoice_it 5462 4_0_0 EXIST::FUNCTION:RFC3779 -d2i_ASIdentifiers 5463 4_0_0 EXIST::FUNCTION:RFC3779 -i2d_ASIdentifiers 5464 4_0_0 EXIST::FUNCTION:RFC3779 -ASIdentifiers_free 5465 4_0_0 EXIST::FUNCTION:RFC3779 -ASIdentifiers_new 5466 4_0_0 EXIST::FUNCTION:RFC3779 -ASIdentifiers_it 5467 4_0_0 EXIST::FUNCTION:RFC3779 -d2i_IPAddressRange 5468 4_0_0 EXIST::FUNCTION:RFC3779 -i2d_IPAddressRange 5469 4_0_0 EXIST::FUNCTION:RFC3779 -IPAddressRange_free 5470 4_0_0 EXIST::FUNCTION:RFC3779 -IPAddressRange_new 5471 4_0_0 EXIST::FUNCTION:RFC3779 -IPAddressRange_it 5472 4_0_0 EXIST::FUNCTION:RFC3779 -d2i_IPAddressOrRange 5473 4_0_0 EXIST::FUNCTION:RFC3779 -i2d_IPAddressOrRange 5474 4_0_0 EXIST::FUNCTION:RFC3779 -IPAddressOrRange_free 5475 4_0_0 EXIST::FUNCTION:RFC3779 -IPAddressOrRange_new 5476 4_0_0 EXIST::FUNCTION:RFC3779 -IPAddressOrRange_it 5477 4_0_0 EXIST::FUNCTION:RFC3779 -d2i_IPAddressChoice 5478 4_0_0 EXIST::FUNCTION:RFC3779 -i2d_IPAddressChoice 5479 4_0_0 EXIST::FUNCTION:RFC3779 -IPAddressChoice_free 5480 4_0_0 EXIST::FUNCTION:RFC3779 -IPAddressChoice_new 5481 4_0_0 EXIST::FUNCTION:RFC3779 -IPAddressChoice_it 5482 4_0_0 EXIST::FUNCTION:RFC3779 -d2i_IPAddressFamily 5483 4_0_0 EXIST::FUNCTION:RFC3779 -i2d_IPAddressFamily 5484 4_0_0 EXIST::FUNCTION:RFC3779 -IPAddressFamily_free 5485 4_0_0 EXIST::FUNCTION:RFC3779 -IPAddressFamily_new 5486 4_0_0 EXIST::FUNCTION:RFC3779 -IPAddressFamily_it 5487 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_asid_add_inherit 5488 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_asid_add_id_or_range 5489 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_addr_add_inherit 5490 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_addr_add_prefix 5491 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_addr_add_range 5492 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_addr_get_afi 5493 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_addr_get_range 5494 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_asid_is_canonical 5495 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_addr_is_canonical 5496 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_asid_canonize 5497 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_addr_canonize 5498 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_asid_inherits 5499 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_addr_inherits 5500 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_asid_subset 5501 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_addr_subset 5502 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_asid_validate_path 5503 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_addr_validate_path 5504 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_asid_validate_resource_set 5505 4_0_0 EXIST::FUNCTION:RFC3779 -X509v3_addr_validate_resource_set 5506 4_0_0 EXIST::FUNCTION:RFC3779 -d2i_NAMING_AUTHORITY 5507 4_0_0 EXIST::FUNCTION: -i2d_NAMING_AUTHORITY 5508 4_0_0 EXIST::FUNCTION: -NAMING_AUTHORITY_free 5509 4_0_0 EXIST::FUNCTION: -NAMING_AUTHORITY_new 5510 4_0_0 EXIST::FUNCTION: -NAMING_AUTHORITY_it 5511 4_0_0 EXIST::FUNCTION: -d2i_PROFESSION_INFO 5512 4_0_0 EXIST::FUNCTION: -i2d_PROFESSION_INFO 5513 4_0_0 EXIST::FUNCTION: -PROFESSION_INFO_free 5514 4_0_0 EXIST::FUNCTION: -PROFESSION_INFO_new 5515 4_0_0 EXIST::FUNCTION: -PROFESSION_INFO_it 5516 4_0_0 EXIST::FUNCTION: -d2i_ADMISSIONS 5517 4_0_0 EXIST::FUNCTION: -i2d_ADMISSIONS 5518 4_0_0 EXIST::FUNCTION: -ADMISSIONS_free 5519 4_0_0 EXIST::FUNCTION: -ADMISSIONS_new 5520 4_0_0 EXIST::FUNCTION: -ADMISSIONS_it 5521 4_0_0 EXIST::FUNCTION: -d2i_ADMISSION_SYNTAX 5522 4_0_0 EXIST::FUNCTION: -i2d_ADMISSION_SYNTAX 5523 4_0_0 EXIST::FUNCTION: -ADMISSION_SYNTAX_free 5524 4_0_0 EXIST::FUNCTION: -ADMISSION_SYNTAX_new 5525 4_0_0 EXIST::FUNCTION: -ADMISSION_SYNTAX_it 5526 4_0_0 EXIST::FUNCTION: -NAMING_AUTHORITY_get0_authorityId 5527 4_0_0 EXIST::FUNCTION: -NAMING_AUTHORITY_get0_authorityURL 5528 4_0_0 EXIST::FUNCTION: -NAMING_AUTHORITY_get0_authorityText 5529 4_0_0 EXIST::FUNCTION: -NAMING_AUTHORITY_set0_authorityId 5530 4_0_0 EXIST::FUNCTION: -NAMING_AUTHORITY_set0_authorityURL 5531 4_0_0 EXIST::FUNCTION: -NAMING_AUTHORITY_set0_authorityText 5532 4_0_0 EXIST::FUNCTION: -ADMISSION_SYNTAX_get0_admissionAuthority 5533 4_0_0 EXIST::FUNCTION: -ADMISSION_SYNTAX_set0_admissionAuthority 5534 4_0_0 EXIST::FUNCTION: -ADMISSION_SYNTAX_get0_contentsOfAdmissions 5535 4_0_0 EXIST::FUNCTION: -ADMISSION_SYNTAX_set0_contentsOfAdmissions 5536 4_0_0 EXIST::FUNCTION: -ADMISSIONS_get0_admissionAuthority 5537 4_0_0 EXIST::FUNCTION: -ADMISSIONS_set0_admissionAuthority 5538 4_0_0 EXIST::FUNCTION: -ADMISSIONS_get0_namingAuthority 5539 4_0_0 EXIST::FUNCTION: -ADMISSIONS_set0_namingAuthority 5540 4_0_0 EXIST::FUNCTION: -ADMISSIONS_get0_professionInfos 5541 4_0_0 EXIST::FUNCTION: -ADMISSIONS_set0_professionInfos 5542 4_0_0 EXIST::FUNCTION: -PROFESSION_INFO_get0_addProfessionInfo 5543 4_0_0 EXIST::FUNCTION: -PROFESSION_INFO_set0_addProfessionInfo 5544 4_0_0 EXIST::FUNCTION: -PROFESSION_INFO_get0_namingAuthority 5545 4_0_0 EXIST::FUNCTION: -PROFESSION_INFO_set0_namingAuthority 5546 4_0_0 EXIST::FUNCTION: -PROFESSION_INFO_get0_professionItems 5547 4_0_0 EXIST::FUNCTION: -PROFESSION_INFO_set0_professionItems 5548 4_0_0 EXIST::FUNCTION: -PROFESSION_INFO_get0_professionOIDs 5549 4_0_0 EXIST::FUNCTION: -PROFESSION_INFO_set0_professionOIDs 5550 4_0_0 EXIST::FUNCTION: -PROFESSION_INFO_get0_registrationNumber 5551 4_0_0 EXIST::FUNCTION: -PROFESSION_INFO_set0_registrationNumber 5552 4_0_0 EXIST::FUNCTION: -OSSL_GENERAL_NAMES_print 5553 4_0_0 EXIST::FUNCTION: -d2i_OSSL_ATTRIBUTES_SYNTAX 5554 4_0_0 EXIST::FUNCTION: -i2d_OSSL_ATTRIBUTES_SYNTAX 5555 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTES_SYNTAX_free 5556 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTES_SYNTAX_new 5557 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTES_SYNTAX_it 5558 4_0_0 EXIST::FUNCTION: -d2i_OSSL_USER_NOTICE_SYNTAX 5559 4_0_0 EXIST::FUNCTION: -i2d_OSSL_USER_NOTICE_SYNTAX 5560 4_0_0 EXIST::FUNCTION: -OSSL_USER_NOTICE_SYNTAX_free 5561 4_0_0 EXIST::FUNCTION: -OSSL_USER_NOTICE_SYNTAX_new 5562 4_0_0 EXIST::FUNCTION: -OSSL_USER_NOTICE_SYNTAX_it 5563 4_0_0 EXIST::FUNCTION: -d2i_OSSL_ROLE_SPEC_CERT_ID 5564 4_0_0 EXIST::FUNCTION: -i2d_OSSL_ROLE_SPEC_CERT_ID 5565 4_0_0 EXIST::FUNCTION: -OSSL_ROLE_SPEC_CERT_ID_free 5566 4_0_0 EXIST::FUNCTION: -OSSL_ROLE_SPEC_CERT_ID_new 5567 4_0_0 EXIST::FUNCTION: -OSSL_ROLE_SPEC_CERT_ID_it 5568 4_0_0 EXIST::FUNCTION: -d2i_OSSL_ROLE_SPEC_CERT_ID_SYNTAX 5569 4_0_0 EXIST::FUNCTION: -i2d_OSSL_ROLE_SPEC_CERT_ID_SYNTAX 5570 4_0_0 EXIST::FUNCTION: -OSSL_ROLE_SPEC_CERT_ID_SYNTAX_free 5571 4_0_0 EXIST::FUNCTION: -OSSL_ROLE_SPEC_CERT_ID_SYNTAX_new 5572 4_0_0 EXIST::FUNCTION: -OSSL_ROLE_SPEC_CERT_ID_SYNTAX_it 5573 4_0_0 EXIST::FUNCTION: -d2i_OSSL_HASH 5574 4_0_0 EXIST::FUNCTION: -i2d_OSSL_HASH 5575 4_0_0 EXIST::FUNCTION: -OSSL_HASH_free 5576 4_0_0 EXIST::FUNCTION: -OSSL_HASH_new 5577 4_0_0 EXIST::FUNCTION: -OSSL_HASH_it 5578 4_0_0 EXIST::FUNCTION: -d2i_OSSL_INFO_SYNTAX 5579 4_0_0 EXIST::FUNCTION: -i2d_OSSL_INFO_SYNTAX 5580 4_0_0 EXIST::FUNCTION: -OSSL_INFO_SYNTAX_free 5581 4_0_0 EXIST::FUNCTION: -OSSL_INFO_SYNTAX_new 5582 4_0_0 EXIST::FUNCTION: -OSSL_INFO_SYNTAX_it 5583 4_0_0 EXIST::FUNCTION: -d2i_OSSL_INFO_SYNTAX_POINTER 5584 4_0_0 EXIST::FUNCTION: -i2d_OSSL_INFO_SYNTAX_POINTER 5585 4_0_0 EXIST::FUNCTION: -OSSL_INFO_SYNTAX_POINTER_free 5586 4_0_0 EXIST::FUNCTION: -OSSL_INFO_SYNTAX_POINTER_new 5587 4_0_0 EXIST::FUNCTION: -OSSL_INFO_SYNTAX_POINTER_it 5588 4_0_0 EXIST::FUNCTION: -d2i_OSSL_PRIVILEGE_POLICY_ID 5589 4_0_0 EXIST::FUNCTION: -i2d_OSSL_PRIVILEGE_POLICY_ID 5590 4_0_0 EXIST::FUNCTION: -OSSL_PRIVILEGE_POLICY_ID_free 5591 4_0_0 EXIST::FUNCTION: -OSSL_PRIVILEGE_POLICY_ID_new 5592 4_0_0 EXIST::FUNCTION: -OSSL_PRIVILEGE_POLICY_ID_it 5593 4_0_0 EXIST::FUNCTION: -d2i_OSSL_ATTRIBUTE_DESCRIPTOR 5594 4_0_0 EXIST::FUNCTION: -i2d_OSSL_ATTRIBUTE_DESCRIPTOR 5595 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTE_DESCRIPTOR_free 5596 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTE_DESCRIPTOR_new 5597 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTE_DESCRIPTOR_it 5598 4_0_0 EXIST::FUNCTION: -d2i_OSSL_DAY_TIME 5599 4_0_0 EXIST::FUNCTION: -i2d_OSSL_DAY_TIME 5600 4_0_0 EXIST::FUNCTION: -OSSL_DAY_TIME_free 5601 4_0_0 EXIST::FUNCTION: -OSSL_DAY_TIME_new 5602 4_0_0 EXIST::FUNCTION: -OSSL_DAY_TIME_it 5603 4_0_0 EXIST::FUNCTION: -d2i_OSSL_DAY_TIME_BAND 5604 4_0_0 EXIST::FUNCTION: -i2d_OSSL_DAY_TIME_BAND 5605 4_0_0 EXIST::FUNCTION: -OSSL_DAY_TIME_BAND_free 5606 4_0_0 EXIST::FUNCTION: -OSSL_DAY_TIME_BAND_new 5607 4_0_0 EXIST::FUNCTION: -OSSL_DAY_TIME_BAND_it 5608 4_0_0 EXIST::FUNCTION: -d2i_OSSL_TIME_SPEC_DAY 5609 4_0_0 EXIST::FUNCTION: -i2d_OSSL_TIME_SPEC_DAY 5610 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_DAY_free 5611 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_DAY_new 5612 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_DAY_it 5613 4_0_0 EXIST::FUNCTION: -d2i_OSSL_TIME_SPEC_WEEKS 5614 4_0_0 EXIST::FUNCTION: -i2d_OSSL_TIME_SPEC_WEEKS 5615 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_WEEKS_free 5616 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_WEEKS_new 5617 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_WEEKS_it 5618 4_0_0 EXIST::FUNCTION: -d2i_OSSL_TIME_SPEC_MONTH 5619 4_0_0 EXIST::FUNCTION: -i2d_OSSL_TIME_SPEC_MONTH 5620 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_MONTH_free 5621 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_MONTH_new 5622 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_MONTH_it 5623 4_0_0 EXIST::FUNCTION: -d2i_OSSL_NAMED_DAY 5624 4_0_0 EXIST::FUNCTION: -i2d_OSSL_NAMED_DAY 5625 4_0_0 EXIST::FUNCTION: -OSSL_NAMED_DAY_free 5626 4_0_0 EXIST::FUNCTION: -OSSL_NAMED_DAY_new 5627 4_0_0 EXIST::FUNCTION: -OSSL_NAMED_DAY_it 5628 4_0_0 EXIST::FUNCTION: -d2i_OSSL_TIME_SPEC_X_DAY_OF 5629 4_0_0 EXIST::FUNCTION: -i2d_OSSL_TIME_SPEC_X_DAY_OF 5630 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_X_DAY_OF_free 5631 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_X_DAY_OF_new 5632 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_X_DAY_OF_it 5633 4_0_0 EXIST::FUNCTION: -d2i_OSSL_TIME_SPEC_ABSOLUTE 5634 4_0_0 EXIST::FUNCTION: -i2d_OSSL_TIME_SPEC_ABSOLUTE 5635 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_ABSOLUTE_free 5636 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_ABSOLUTE_new 5637 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_ABSOLUTE_it 5638 4_0_0 EXIST::FUNCTION: -d2i_OSSL_TIME_SPEC_TIME 5639 4_0_0 EXIST::FUNCTION: -i2d_OSSL_TIME_SPEC_TIME 5640 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_TIME_free 5641 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_TIME_new 5642 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_TIME_it 5643 4_0_0 EXIST::FUNCTION: -d2i_OSSL_TIME_SPEC 5644 4_0_0 EXIST::FUNCTION: -i2d_OSSL_TIME_SPEC 5645 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_free 5646 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_new 5647 4_0_0 EXIST::FUNCTION: -OSSL_TIME_SPEC_it 5648 4_0_0 EXIST::FUNCTION: -d2i_OSSL_TIME_PERIOD 5649 4_0_0 EXIST::FUNCTION: -i2d_OSSL_TIME_PERIOD 5650 4_0_0 EXIST::FUNCTION: -OSSL_TIME_PERIOD_free 5651 4_0_0 EXIST::FUNCTION: -OSSL_TIME_PERIOD_new 5652 4_0_0 EXIST::FUNCTION: -OSSL_TIME_PERIOD_it 5653 4_0_0 EXIST::FUNCTION: -d2i_OSSL_ATAV 5654 4_0_0 EXIST::FUNCTION: -i2d_OSSL_ATAV 5655 4_0_0 EXIST::FUNCTION: -OSSL_ATAV_free 5656 4_0_0 EXIST::FUNCTION: -OSSL_ATAV_new 5657 4_0_0 EXIST::FUNCTION: -OSSL_ATAV_it 5658 4_0_0 EXIST::FUNCTION: -d2i_OSSL_ATTRIBUTE_TYPE_MAPPING 5659 4_0_0 EXIST::FUNCTION: -i2d_OSSL_ATTRIBUTE_TYPE_MAPPING 5660 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTE_TYPE_MAPPING_free 5661 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTE_TYPE_MAPPING_new 5662 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTE_TYPE_MAPPING_it 5663 4_0_0 EXIST::FUNCTION: -d2i_OSSL_ATTRIBUTE_VALUE_MAPPING 5664 4_0_0 EXIST::FUNCTION: -i2d_OSSL_ATTRIBUTE_VALUE_MAPPING 5665 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTE_VALUE_MAPPING_free 5666 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTE_VALUE_MAPPING_new 5667 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTE_VALUE_MAPPING_it 5668 4_0_0 EXIST::FUNCTION: -d2i_OSSL_ATTRIBUTE_MAPPING 5669 4_0_0 EXIST::FUNCTION: -i2d_OSSL_ATTRIBUTE_MAPPING 5670 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTE_MAPPING_free 5671 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTE_MAPPING_new 5672 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTE_MAPPING_it 5673 4_0_0 EXIST::FUNCTION: -d2i_OSSL_ATTRIBUTE_MAPPINGS 5674 4_0_0 EXIST::FUNCTION: -i2d_OSSL_ATTRIBUTE_MAPPINGS 5675 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTE_MAPPINGS_free 5676 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTE_MAPPINGS_new 5677 4_0_0 EXIST::FUNCTION: -OSSL_ATTRIBUTE_MAPPINGS_it 5678 4_0_0 EXIST::FUNCTION: -d2i_OSSL_ALLOWED_ATTRIBUTES_CHOICE 5679 4_0_0 EXIST::FUNCTION: -i2d_OSSL_ALLOWED_ATTRIBUTES_CHOICE 5680 4_0_0 EXIST::FUNCTION: -OSSL_ALLOWED_ATTRIBUTES_CHOICE_free 5681 4_0_0 EXIST::FUNCTION: -OSSL_ALLOWED_ATTRIBUTES_CHOICE_new 5682 4_0_0 EXIST::FUNCTION: -OSSL_ALLOWED_ATTRIBUTES_CHOICE_it 5683 4_0_0 EXIST::FUNCTION: -d2i_OSSL_ALLOWED_ATTRIBUTES_ITEM 5684 4_0_0 EXIST::FUNCTION: -i2d_OSSL_ALLOWED_ATTRIBUTES_ITEM 5685 4_0_0 EXIST::FUNCTION: -OSSL_ALLOWED_ATTRIBUTES_ITEM_free 5686 4_0_0 EXIST::FUNCTION: -OSSL_ALLOWED_ATTRIBUTES_ITEM_new 5687 4_0_0 EXIST::FUNCTION: -OSSL_ALLOWED_ATTRIBUTES_ITEM_it 5688 4_0_0 EXIST::FUNCTION: -d2i_OSSL_ALLOWED_ATTRIBUTES_SYNTAX 5689 4_0_0 EXIST::FUNCTION: -i2d_OSSL_ALLOWED_ATTRIBUTES_SYNTAX 5690 4_0_0 EXIST::FUNCTION: -OSSL_ALLOWED_ATTRIBUTES_SYNTAX_free 5691 4_0_0 EXIST::FUNCTION: -OSSL_ALLOWED_ATTRIBUTES_SYNTAX_new 5692 4_0_0 EXIST::FUNCTION: -OSSL_ALLOWED_ATTRIBUTES_SYNTAX_it 5693 4_0_0 EXIST::FUNCTION: -d2i_OSSL_AA_DIST_POINT 5694 4_0_0 EXIST::FUNCTION: -i2d_OSSL_AA_DIST_POINT 5695 4_0_0 EXIST::FUNCTION: -OSSL_AA_DIST_POINT_free 5696 4_0_0 EXIST::FUNCTION: -OSSL_AA_DIST_POINT_new 5697 4_0_0 EXIST::FUNCTION: -OSSL_AA_DIST_POINT_it 5698 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_new_SKEY 5699 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get0_SKEY 5700 4_0_0 EXIST::FUNCTION: -OSSL_STORE_INFO_get1_SKEY 5701 4_0_0 EXIST::FUNCTION: -OPENSSL_posix_to_tm 5702 4_0_0 EXIST::FUNCTION: -OPENSSL_tm_to_posix 5703 4_0_0 EXIST::FUNCTION: -OPENSSL_timegm 5704 4_0_0 EXIST::FUNCTION: -OSSL_PARAM_clear_free 5705 4_0_0 EXIST::FUNCTION: -CMS_dataFinal_ex 5706 4_0_0 EXIST::FUNCTION:CMS -CMS_SignerInfo_verify_ex 5707 4_0_0 EXIST::FUNCTION:CMS -EVP_SIGNATURE_has_message_update 5708 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_serialize 5709 4_0_0 EXIST::FUNCTION: -EVP_MD_CTX_deserialize 5710 4_0_0 EXIST::FUNCTION: -OSSL_ENCODER_CTX_ctrl_string 5711 4_0_0 EXIST::FUNCTION: -OPENSSL_sk_set_cmp_thunks 5712 4_0_0 EXIST::FUNCTION: -ASN1_BIT_STRING_set1 5713 4_0_0 EXIST::FUNCTION: -OSSL_ESS_check_signing_certs_ex 5714 4_0_0 EXIST::FUNCTION: -X509v3_delete_extension 5715 4_0_0 EXIST::FUNCTION: -CTLOG_STORE_add0_log ? 4_1_0 EXIST::FUNCTION:CT -CRYPTO_atomic_load_ptr ? 4_1_0 EXIST::FUNCTION: -CRYPTO_atomic_store_ptr ? 4_1_0 EXIST::FUNCTION: -CRYPTO_atomic_cmp_exch_ptr ? 4_1_0 EXIST::FUNCTION: -EVP_EC_affine2oct ? 4_1_0 EXIST::FUNCTION: -OPENSSL_sk_set_copy_thunks ? 4_1_0 EXIST::FUNCTION: -ASN1_STRING_new_not_owned ? 4_1_0 EXIST::FUNCTION: -EVP_KDF_CTX_get0_kdf ? 4_1_0 EXIST::FUNCTION: -EVP_KDF_CTX_get1_kdf ? 4_1_0 EXIST::FUNCTION: -ASN1_STRING_set_data ? 4_1_0 EXIST::FUNCTION: -ASN1_STRING_set_string ? 4_1_0 EXIST::FUNCTION: -ASN1_STRING_length_ex ? 4_1_0 EXIST::FUNCTION: +asn1_d2i_read_bio ? 4_0_0 EXIST::FUNCTION: +DSO_new ? 4_0_0 EXIST::FUNCTION: +DSO_free ? 4_0_0 EXIST::FUNCTION: +DSO_flags ? 4_0_0 EXIST::FUNCTION: +DSO_up_ref ? 4_0_0 EXIST::FUNCTION: +DSO_ctrl ? 4_0_0 EXIST::FUNCTION: +DSO_get_filename ? 4_0_0 EXIST::FUNCTION: +DSO_set_filename ? 4_0_0 EXIST::FUNCTION: +DSO_convert_filename ? 4_0_0 EXIST::FUNCTION: +DSO_merge ? 4_0_0 EXIST::FUNCTION: +DSO_load ? 4_0_0 EXIST::FUNCTION: +DSO_bind_func ? 4_0_0 EXIST::FUNCTION: +DSO_METHOD_openssl ? 4_0_0 EXIST::FUNCTION: +DSO_pathbyaddr ? 4_0_0 EXIST::FUNCTION: +DSO_dsobyaddr ? 4_0_0 EXIST::FUNCTION: +DSO_global_lookup ? 4_0_0 EXIST::FUNCTION: +err_free_strings_int ? 4_0_0 EXIST::FUNCTION: +OPENSSL_DIR_read ? 4_0_0 EXIST::FUNCTION: +OPENSSL_DIR_end ? 4_0_0 EXIST::FUNCTION: +conf_ssl_get ? 4_0_0 EXIST::FUNCTION: +conf_ssl_name_find ? 4_0_0 EXIST::FUNCTION: +conf_ssl_get_cmd ? 4_0_0 EXIST::FUNCTION: +AES_options ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +AES_set_encrypt_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +AES_set_decrypt_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +AES_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +AES_decrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +AES_ecb_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +AES_cbc_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +AES_cfb128_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +AES_cfb1_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +AES_cfb8_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +AES_ofb128_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +AES_ige_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +AES_bi_ige_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +AES_wrap_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +AES_unwrap_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ASYNC_init_thread ? 4_0_0 EXIST::FUNCTION: +ASYNC_cleanup_thread ? 4_0_0 EXIST::FUNCTION: +ASYNC_WAIT_CTX_new ? 4_0_0 EXIST::FUNCTION: +ASYNC_WAIT_CTX_free ? 4_0_0 EXIST::FUNCTION: +ASYNC_WAIT_CTX_set_wait_fd ? 4_0_0 EXIST::FUNCTION: +ASYNC_WAIT_CTX_get_fd ? 4_0_0 EXIST::FUNCTION: +ASYNC_WAIT_CTX_get_all_fds ? 4_0_0 EXIST::FUNCTION: +ASYNC_WAIT_CTX_get_callback ? 4_0_0 EXIST::FUNCTION: +ASYNC_WAIT_CTX_set_callback ? 4_0_0 EXIST::FUNCTION: +ASYNC_WAIT_CTX_set_status ? 4_0_0 EXIST::FUNCTION: +ASYNC_WAIT_CTX_get_status ? 4_0_0 EXIST::FUNCTION: +ASYNC_WAIT_CTX_get_changed_fds ? 4_0_0 EXIST::FUNCTION: +ASYNC_WAIT_CTX_clear_fd ? 4_0_0 EXIST::FUNCTION: +ASYNC_is_capable ? 4_0_0 EXIST::FUNCTION: +ASYNC_set_mem_functions ? 4_0_0 EXIST::FUNCTION: +ASYNC_get_mem_functions ? 4_0_0 EXIST::FUNCTION: +ASYNC_start_job ? 4_0_0 EXIST::FUNCTION: +ASYNC_pause_job ? 4_0_0 EXIST::FUNCTION: +ASYNC_get_current_job ? 4_0_0 EXIST::FUNCTION: +ASYNC_get_wait_ctx ? 4_0_0 EXIST::FUNCTION: +ASYNC_block_pause ? 4_0_0 EXIST::FUNCTION: +ASYNC_unblock_pause ? 4_0_0 EXIST::FUNCTION: +BF_set_key ? 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 +BF_encrypt ? 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 +BF_decrypt ? 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 +BF_ecb_encrypt ? 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 +BF_cbc_encrypt ? 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 +BF_cfb64_encrypt ? 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 +BF_ofb64_encrypt ? 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 +BF_options ? 4_0_0 EXIST::FUNCTION:BF,DEPRECATEDIN_3_0 +BN_set_flags ? 4_0_0 EXIST::FUNCTION: +BN_get_flags ? 4_0_0 EXIST::FUNCTION: +BN_with_flags ? 4_0_0 EXIST::FUNCTION: +BN_GENCB_call ? 4_0_0 EXIST::FUNCTION: +BN_GENCB_new ? 4_0_0 EXIST::FUNCTION: +BN_GENCB_free ? 4_0_0 EXIST::FUNCTION: +BN_GENCB_set_old ? 4_0_0 EXIST::FUNCTION: +BN_GENCB_set ? 4_0_0 EXIST::FUNCTION: +BN_GENCB_get_arg ? 4_0_0 EXIST::FUNCTION: +BN_abs_is_word ? 4_0_0 EXIST::FUNCTION: +BN_is_zero ? 4_0_0 EXIST::FUNCTION: +BN_is_one ? 4_0_0 EXIST::FUNCTION: +BN_is_word ? 4_0_0 EXIST::FUNCTION: +BN_is_odd ? 4_0_0 EXIST::FUNCTION: +BN_zero_ex ? 4_0_0 EXIST::FUNCTION: +BN_value_one ? 4_0_0 EXIST::FUNCTION: +BN_options ? 4_0_0 EXIST::FUNCTION: +BN_CTX_new_ex ? 4_0_0 EXIST::FUNCTION: +BN_CTX_new ? 4_0_0 EXIST::FUNCTION: +BN_CTX_secure_new_ex ? 4_0_0 EXIST::FUNCTION: +BN_CTX_secure_new ? 4_0_0 EXIST::FUNCTION: +BN_CTX_free ? 4_0_0 EXIST::FUNCTION: +BN_CTX_start ? 4_0_0 EXIST::FUNCTION: +BN_CTX_get ? 4_0_0 EXIST::FUNCTION: +BN_CTX_end ? 4_0_0 EXIST::FUNCTION: +BN_rand_ex ? 4_0_0 EXIST::FUNCTION: +BN_rand ? 4_0_0 EXIST::FUNCTION: +BN_priv_rand_ex ? 4_0_0 EXIST::FUNCTION: +BN_priv_rand ? 4_0_0 EXIST::FUNCTION: +BN_rand_range_ex ? 4_0_0 EXIST::FUNCTION: +BN_rand_range ? 4_0_0 EXIST::FUNCTION: +BN_priv_rand_range_ex ? 4_0_0 EXIST::FUNCTION: +BN_priv_rand_range ? 4_0_0 EXIST::FUNCTION: +BN_pseudo_rand ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +BN_pseudo_rand_range ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +BN_num_bits ? 4_0_0 EXIST::FUNCTION: +BN_num_bits_word ? 4_0_0 EXIST::FUNCTION: +BN_security_bits ? 4_0_0 EXIST::FUNCTION: +BN_new ? 4_0_0 EXIST::FUNCTION: +BN_secure_new ? 4_0_0 EXIST::FUNCTION: +BN_clear_free ? 4_0_0 EXIST::FUNCTION: +BN_copy ? 4_0_0 EXIST::FUNCTION: +BN_swap ? 4_0_0 EXIST::FUNCTION: +BN_bin2bn ? 4_0_0 EXIST::FUNCTION: +BN_signed_bin2bn ? 4_0_0 EXIST::FUNCTION: +BN_bn2bin ? 4_0_0 EXIST::FUNCTION: +BN_bn2binpad ? 4_0_0 EXIST::FUNCTION: +BN_signed_bn2bin ? 4_0_0 EXIST::FUNCTION: +BN_lebin2bn ? 4_0_0 EXIST::FUNCTION: +BN_signed_lebin2bn ? 4_0_0 EXIST::FUNCTION: +BN_bn2lebinpad ? 4_0_0 EXIST::FUNCTION: +BN_signed_bn2lebin ? 4_0_0 EXIST::FUNCTION: +BN_native2bn ? 4_0_0 EXIST::FUNCTION: +BN_signed_native2bn ? 4_0_0 EXIST::FUNCTION: +BN_bn2nativepad ? 4_0_0 EXIST::FUNCTION: +BN_signed_bn2native ? 4_0_0 EXIST::FUNCTION: +BN_mpi2bn ? 4_0_0 EXIST::FUNCTION: +BN_bn2mpi ? 4_0_0 EXIST::FUNCTION: +BN_sub ? 4_0_0 EXIST::FUNCTION: +BN_usub ? 4_0_0 EXIST::FUNCTION: +BN_uadd ? 4_0_0 EXIST::FUNCTION: +BN_add ? 4_0_0 EXIST::FUNCTION: +BN_mul ? 4_0_0 EXIST::FUNCTION: +BN_sqr ? 4_0_0 EXIST::FUNCTION: +BN_set_negative ? 4_0_0 EXIST::FUNCTION: +BN_is_negative ? 4_0_0 EXIST::FUNCTION: +BN_div ? 4_0_0 EXIST::FUNCTION: +BN_nnmod ? 4_0_0 EXIST::FUNCTION: +BN_mod_add ? 4_0_0 EXIST::FUNCTION: +BN_mod_add_quick ? 4_0_0 EXIST::FUNCTION: +BN_mod_sub ? 4_0_0 EXIST::FUNCTION: +BN_mod_sub_quick ? 4_0_0 EXIST::FUNCTION: +BN_mod_mul ? 4_0_0 EXIST::FUNCTION: +BN_mod_sqr ? 4_0_0 EXIST::FUNCTION: +BN_mod_lshift1 ? 4_0_0 EXIST::FUNCTION: +BN_mod_lshift1_quick ? 4_0_0 EXIST::FUNCTION: +BN_mod_lshift ? 4_0_0 EXIST::FUNCTION: +BN_mod_lshift_quick ? 4_0_0 EXIST::FUNCTION: +BN_mod_word ? 4_0_0 EXIST::FUNCTION: +BN_div_word ? 4_0_0 EXIST::FUNCTION: +BN_mul_word ? 4_0_0 EXIST::FUNCTION: +BN_add_word ? 4_0_0 EXIST::FUNCTION: +BN_sub_word ? 4_0_0 EXIST::FUNCTION: +BN_set_word ? 4_0_0 EXIST::FUNCTION: +BN_get_word ? 4_0_0 EXIST::FUNCTION: +BN_cmp ? 4_0_0 EXIST::FUNCTION: +BN_free ? 4_0_0 EXIST::FUNCTION: +BN_is_bit_set ? 4_0_0 EXIST::FUNCTION: +BN_lshift ? 4_0_0 EXIST::FUNCTION: +BN_lshift1 ? 4_0_0 EXIST::FUNCTION: +BN_exp ? 4_0_0 EXIST::FUNCTION: +BN_mod_exp ? 4_0_0 EXIST::FUNCTION: +BN_mod_exp_mont ? 4_0_0 EXIST::FUNCTION: +BN_mod_exp_mont_consttime ? 4_0_0 EXIST::FUNCTION: +BN_mod_exp_mont_word ? 4_0_0 EXIST::FUNCTION: +BN_mod_exp2_mont ? 4_0_0 EXIST::FUNCTION: +BN_mod_exp_simple ? 4_0_0 EXIST::FUNCTION: +BN_mod_exp_mont_consttime_x2 ? 4_0_0 EXIST::FUNCTION: +BN_mask_bits ? 4_0_0 EXIST::FUNCTION: +BN_print_fp ? 4_0_0 EXIST::FUNCTION:STDIO +BN_print ? 4_0_0 EXIST::FUNCTION: +BN_reciprocal ? 4_0_0 EXIST::FUNCTION: +BN_rshift ? 4_0_0 EXIST::FUNCTION: +BN_rshift1 ? 4_0_0 EXIST::FUNCTION: +BN_clear ? 4_0_0 EXIST::FUNCTION: +BN_dup ? 4_0_0 EXIST::FUNCTION: +BN_ucmp ? 4_0_0 EXIST::FUNCTION: +BN_set_bit ? 4_0_0 EXIST::FUNCTION: +BN_clear_bit ? 4_0_0 EXIST::FUNCTION: +BN_bn2hex ? 4_0_0 EXIST::FUNCTION: +BN_bn2dec ? 4_0_0 EXIST::FUNCTION: +BN_hex2bn ? 4_0_0 EXIST::FUNCTION: +BN_dec2bn ? 4_0_0 EXIST::FUNCTION: +BN_asc2bn ? 4_0_0 EXIST::FUNCTION: +BN_gcd ? 4_0_0 EXIST::FUNCTION: +BN_kronecker ? 4_0_0 EXIST::FUNCTION: +BN_are_coprime ? 4_0_0 EXIST::FUNCTION: +BN_mod_inverse ? 4_0_0 EXIST::FUNCTION: +BN_mod_sqrt ? 4_0_0 EXIST::FUNCTION: +BN_consttime_swap ? 4_0_0 EXIST::FUNCTION: +BN_generate_prime ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8 +BN_is_prime ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8 +BN_is_prime_fasttest ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8 +BN_is_prime_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +BN_is_prime_fasttest_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +BN_generate_prime_ex2 ? 4_0_0 EXIST::FUNCTION: +BN_generate_prime_ex ? 4_0_0 EXIST::FUNCTION: +BN_check_prime ? 4_0_0 EXIST::FUNCTION: +BN_X931_generate_Xpq ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +BN_X931_derive_prime_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +BN_X931_generate_prime_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +BN_MONT_CTX_new ? 4_0_0 EXIST::FUNCTION: +BN_mod_mul_montgomery ? 4_0_0 EXIST::FUNCTION: +BN_to_montgomery ? 4_0_0 EXIST::FUNCTION: +BN_from_montgomery ? 4_0_0 EXIST::FUNCTION: +BN_MONT_CTX_free ? 4_0_0 EXIST::FUNCTION: +BN_MONT_CTX_set ? 4_0_0 EXIST::FUNCTION: +BN_MONT_CTX_copy ? 4_0_0 EXIST::FUNCTION: +BN_MONT_CTX_set_locked ? 4_0_0 EXIST::FUNCTION: +BN_BLINDING_new ? 4_0_0 EXIST::FUNCTION: +BN_BLINDING_free ? 4_0_0 EXIST::FUNCTION: +BN_BLINDING_update ? 4_0_0 EXIST::FUNCTION: +BN_BLINDING_convert ? 4_0_0 EXIST::FUNCTION: +BN_BLINDING_invert ? 4_0_0 EXIST::FUNCTION: +BN_BLINDING_convert_ex ? 4_0_0 EXIST::FUNCTION: +BN_BLINDING_invert_ex ? 4_0_0 EXIST::FUNCTION: +BN_BLINDING_is_current_thread ? 4_0_0 EXIST::FUNCTION: +BN_BLINDING_set_current_thread ? 4_0_0 EXIST::FUNCTION: +BN_BLINDING_lock ? 4_0_0 EXIST::FUNCTION: +BN_BLINDING_unlock ? 4_0_0 EXIST::FUNCTION: +BN_BLINDING_get_flags ? 4_0_0 EXIST::FUNCTION: +BN_BLINDING_set_flags ? 4_0_0 EXIST::FUNCTION: +BN_BLINDING_create_param ? 4_0_0 EXIST::FUNCTION: +BN_set_params ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8 +BN_get_params ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8 +BN_RECP_CTX_new ? 4_0_0 EXIST::FUNCTION: +BN_RECP_CTX_free ? 4_0_0 EXIST::FUNCTION: +BN_RECP_CTX_set ? 4_0_0 EXIST::FUNCTION: +BN_mod_mul_reciprocal ? 4_0_0 EXIST::FUNCTION: +BN_mod_exp_recp ? 4_0_0 EXIST::FUNCTION: +BN_div_recp ? 4_0_0 EXIST::FUNCTION: +BN_GF2m_add ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod_mul ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod_sqr ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod_inv ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod_div ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod_exp ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod_sqrt ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod_solve_quad ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod_arr ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod_mul_arr ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod_sqr_arr ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod_inv_arr ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod_div_arr ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod_exp_arr ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod_sqrt_arr ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_mod_solve_quad_arr ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_poly2arr ? 4_0_0 EXIST::FUNCTION:EC2M +BN_GF2m_arr2poly ? 4_0_0 EXIST::FUNCTION:EC2M +BN_nist_mod_192 ? 4_0_0 EXIST::FUNCTION: +BN_nist_mod_224 ? 4_0_0 EXIST::FUNCTION: +BN_nist_mod_256 ? 4_0_0 EXIST::FUNCTION: +BN_nist_mod_384 ? 4_0_0 EXIST::FUNCTION: +BN_nist_mod_521 ? 4_0_0 EXIST::FUNCTION: +BN_get0_nist_prime_192 ? 4_0_0 EXIST::FUNCTION: +BN_get0_nist_prime_224 ? 4_0_0 EXIST::FUNCTION: +BN_get0_nist_prime_256 ? 4_0_0 EXIST::FUNCTION: +BN_get0_nist_prime_384 ? 4_0_0 EXIST::FUNCTION: +BN_get0_nist_prime_521 ? 4_0_0 EXIST::FUNCTION: +BN_nist_mod_func ? 4_0_0 EXIST::FUNCTION: +BN_generate_dsa_nonce ? 4_0_0 EXIST::FUNCTION: +BN_get_rfc2409_prime_768 ? 4_0_0 EXIST::FUNCTION: +BN_get_rfc2409_prime_1024 ? 4_0_0 EXIST::FUNCTION: +BN_get_rfc3526_prime_1536 ? 4_0_0 EXIST::FUNCTION: +BN_get_rfc3526_prime_2048 ? 4_0_0 EXIST::FUNCTION: +BN_get_rfc3526_prime_3072 ? 4_0_0 EXIST::FUNCTION: +BN_get_rfc3526_prime_4096 ? 4_0_0 EXIST::FUNCTION: +BN_get_rfc3526_prime_6144 ? 4_0_0 EXIST::FUNCTION: +BN_get_rfc3526_prime_8192 ? 4_0_0 EXIST::FUNCTION: +BN_bntest_rand ? 4_0_0 EXIST::FUNCTION: +BUF_MEM_new ? 4_0_0 EXIST::FUNCTION: +BUF_MEM_new_ex ? 4_0_0 EXIST::FUNCTION: +BUF_MEM_free ? 4_0_0 EXIST::FUNCTION: +BUF_MEM_grow ? 4_0_0 EXIST::FUNCTION: +BUF_MEM_grow_clean ? 4_0_0 EXIST::FUNCTION: +BUF_reverse ? 4_0_0 EXIST::FUNCTION: +Camellia_set_key ? 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 +Camellia_encrypt ? 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 +Camellia_decrypt ? 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 +Camellia_ecb_encrypt ? 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 +Camellia_cbc_encrypt ? 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 +Camellia_cfb128_encrypt ? 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 +Camellia_cfb1_encrypt ? 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 +Camellia_cfb8_encrypt ? 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 +Camellia_ofb128_encrypt ? 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 +Camellia_ctr128_encrypt ? 4_0_0 EXIST::FUNCTION:CAMELLIA,DEPRECATEDIN_3_0 +CAST_set_key ? 4_0_0 EXIST::FUNCTION:CAST,DEPRECATEDIN_3_0 +CAST_ecb_encrypt ? 4_0_0 EXIST::FUNCTION:CAST,DEPRECATEDIN_3_0 +CAST_encrypt ? 4_0_0 EXIST::FUNCTION:CAST,DEPRECATEDIN_3_0 +CAST_decrypt ? 4_0_0 EXIST::FUNCTION:CAST,DEPRECATEDIN_3_0 +CAST_cbc_encrypt ? 4_0_0 EXIST::FUNCTION:CAST,DEPRECATEDIN_3_0 +CAST_cfb64_encrypt ? 4_0_0 EXIST::FUNCTION:CAST,DEPRECATEDIN_3_0 +CAST_ofb64_encrypt ? 4_0_0 EXIST::FUNCTION:CAST,DEPRECATEDIN_3_0 +CMAC_CTX_new ? 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 +CMAC_CTX_cleanup ? 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 +CMAC_CTX_free ? 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 +CMAC_CTX_get0_cipher_ctx ? 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 +CMAC_CTX_copy ? 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 +CMAC_Init ? 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 +CMAC_Update ? 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 +CMAC_Final ? 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 +CMAC_resume ? 4_0_0 EXIST::FUNCTION:CMAC,DEPRECATEDIN_3_0 +OSSL_CMP_log_open ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_log_close ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_print_to_bio ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_print_errors_cb ? 4_0_0 EXIST::FUNCTION:CMP +ERR_load_ASN1_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_ASYNC_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_BIO_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_BN_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_BUF_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_CMS_strings ? 4_0_0 EXIST::FUNCTION:CMS,DEPRECATEDIN_3_0 +ERR_load_COMP_strings ? 4_0_0 EXIST::FUNCTION:COMP,DEPRECATEDIN_3_0 +ERR_load_CONF_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_CRYPTO_strings ? 4_0_0 EXIST:!VMS:FUNCTION:DEPRECATEDIN_3_0 +ERR_load_CRYPTOlib_strings ?+ 4_0_0 EXIST:VMS:FUNCTION:DEPRECATEDIN_3_0 +ERR_load_CT_strings ? 4_0_0 EXIST::FUNCTION:CT,DEPRECATEDIN_3_0 +ERR_load_DH_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +ERR_load_DSA_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +ERR_load_EC_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +ERR_load_ERR_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_EVP_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_KDF_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_OBJ_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_OCSP_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,OCSP +ERR_load_PEM_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_PKCS12_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_PKCS7_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_RAND_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_RSA_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_OSSL_STORE_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_TS_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,TS +ERR_load_UI_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_X509_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_load_X509V3_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_DECODER_fetch ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_up_ref ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_free ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_get0_provider ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_get0_properties ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_get0_name ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_get0_description ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_is_a ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_do_all_provided ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_names_do_all ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_gettable_params ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_get_params ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_settable_ctx_params ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_new ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_set_params ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_free ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_set_passphrase ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_set_pem_password_cb ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_set_passphrase_cb ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_set_passphrase_ui ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_set_selection ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_set_input_type ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_set_input_structure ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_add_decoder ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_add_extra ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_get_num_decoders ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_INSTANCE_get_decoder ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_INSTANCE_get_decoder_ctx ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_INSTANCE_get_input_type ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_INSTANCE_get_input_structure ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_set_construct ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_set_construct_data ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_set_cleanup ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_get_construct ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_get_construct_data ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_get_cleanup ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_export ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_from_bio ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_from_fp ? 4_0_0 EXIST::FUNCTION:STDIO +OSSL_DECODER_from_data ? 4_0_0 EXIST::FUNCTION: +OSSL_DECODER_CTX_new_for_pkey ? 4_0_0 EXIST::FUNCTION: +DES_options ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_ecb3_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_cbc_cksum ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_cbc_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_ncbc_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_xcbc_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_cfb_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_ecb_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_encrypt1 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_encrypt2 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_encrypt3 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_decrypt3 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_ede3_cbc_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_ede3_cfb64_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_ede3_cfb_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_ede3_ofb64_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_fcrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_crypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_ofb_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_pcbc_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_quad_cksum ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_random_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_set_odd_parity ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_check_key_parity ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_is_weak_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_set_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_key_sched ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_set_key_checked ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_set_key_unchecked ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_string_to_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_string_to_2keys ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_cfb64_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +DES_ofb64_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DES +EVP_PKEY_CTX_set_dh_paramgen_type ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dh_paramgen_gindex ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dh_paramgen_seed ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dh_paramgen_prime_len ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dh_paramgen_subprime_len ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dh_paramgen_generator ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dh_nid ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dh_rfc5114 ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dhx_rfc5114 ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dh_pad ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dh_kdf_type ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_dh_kdf_type ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set0_dh_kdf_oid ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get0_dh_kdf_oid ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dh_kdf_md ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_dh_kdf_md ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dh_kdf_outlen ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_dh_kdf_outlen ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set0_dh_kdf_ukm ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get0_dh_kdf_ukm ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +DHparams_it ? 4_0_0 EXIST::FUNCTION:DH +DHparams_dup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_OpenSSL ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_set_default_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_get_default_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_set_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_new_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_up_ref ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_bits ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_size ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_security_bits ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_set_ex_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_get_ex_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_generate_parameters_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_check_params_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_check_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_check_pub_key_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_check_params ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_check ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_check_pub_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_generate_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_compute_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_compute_key_padded ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +d2i_DHparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +i2d_DHparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +d2i_DHxparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +i2d_DHxparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DHparams_print_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH,STDIO +DHparams_print ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_get_1024_160 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_get_2048_224 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_get_2048_256 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_new_by_nid ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_get_nid ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_KDF_X9_42 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_get0_pqg ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_set0_pqg ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_get0_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_set0_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_get0_p ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_get0_q ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_get0_g ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_get0_priv_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_get0_pub_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_clear_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_test_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_set_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_get_length ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_set_length ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_dup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_get0_name ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_set1_name ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_get_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_set_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_get0_app_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_set0_app_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_get_generate_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_set_generate_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_get_compute_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_set_compute_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_get_bn_mod_exp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_set_bn_mod_exp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_get_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_set_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_get_finish ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_set_finish ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_get_generate_params ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_meth_set_generate_params ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +DH_generate_parameters ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8,DH +EVP_PKEY_CTX_set_dsa_paramgen_bits ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dsa_paramgen_q_bits ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dsa_paramgen_md_props ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dsa_paramgen_gindex ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dsa_paramgen_type ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dsa_paramgen_seed ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_dsa_paramgen_md ? 4_0_0 EXIST::FUNCTION: +DSA_SIG_new ? 4_0_0 EXIST::FUNCTION:DSA +DSA_SIG_free ? 4_0_0 EXIST::FUNCTION:DSA +d2i_DSA_SIG ? 4_0_0 EXIST::FUNCTION:DSA +i2d_DSA_SIG ? 4_0_0 EXIST::FUNCTION:DSA +DSA_SIG_get0 ? 4_0_0 EXIST::FUNCTION:DSA +DSA_SIG_set0 ? 4_0_0 EXIST::FUNCTION:DSA +DSAparams_dup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_do_sign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_do_verify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_OpenSSL ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_set_default_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_get_default_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_set_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_get_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_new_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_up_ref ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_size ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_bits ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_security_bits ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_sign_setup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_sign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_verify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_set_ex_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_get_ex_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +d2i_DSAPublicKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +i2d_DSAPublicKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +d2i_DSAPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +i2d_DSAPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +d2i_DSAparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +i2d_DSAparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_generate_parameters ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8,DSA +DSA_generate_parameters_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_generate_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSAparams_print ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_print ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSAparams_print_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO +DSA_print_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO +DSA_dup_DH ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH,DSA +DSA_get0_pqg ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_set0_pqg ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_get0_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_set0_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_get0_p ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_get0_q ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_get0_g ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_get0_pub_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_get0_priv_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_clear_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_test_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_set_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_dup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_get0_name ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_set1_name ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_get_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_set_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_get0_app_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_set0_app_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_get_sign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_set_sign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_get_sign_setup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_set_sign_setup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_get_verify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_set_verify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_get_mod_exp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_set_mod_exp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_get_bn_mod_exp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_set_bn_mod_exp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_get_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_set_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_get_finish ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_set_finish ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_get_paramgen ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_set_paramgen ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_get_keygen ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +DSA_meth_set_keygen ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +EVP_PKEY_CTX_set_ec_paramgen_curve_nid ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_ec_param_enc ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_ecdh_cofactor_mode ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_ecdh_cofactor_mode ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_ecdh_kdf_type ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_ecdh_kdf_type ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_ecdh_kdf_md ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_ecdh_kdf_md ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_ecdh_kdf_outlen ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_ecdh_kdf_outlen ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set0_ecdh_kdf_ukm ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get0_ecdh_kdf_ukm ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_EC_curve_nid2name ? 4_0_0 EXIST::FUNCTION: +EC_GFp_simple_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_GFp_mont_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_GFp_nist_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_GFp_nistp224_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC_NISTP_64_GCC_128 +EC_GFp_nistp256_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC_NISTP_64_GCC_128 +EC_GFp_nistp521_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC_NISTP_64_GCC_128 +EC_GF2m_simple_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC2M +EC_GROUP_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_GROUP_clear_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_GROUP_method_of ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_METHOD_get_field_type ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_GROUP_free ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_copy ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_dup ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_set_generator ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get0_generator ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get_mont_data ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get_order ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get0_order ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_order_bits ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get_cofactor ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get0_cofactor ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_set_curve_name ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get_curve_name ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get0_field ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get_field_type ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_set_asn1_flag ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get_asn1_flag ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_set_point_conversion_form ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get_point_conversion_form ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get0_seed ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get_seed_len ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_set_seed ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_set_curve ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get_curve ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_set_curve_GFp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_GROUP_get_curve_GFp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_GROUP_set_curve_GF2m ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC2M +EC_GROUP_get_curve_GF2m ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC2M +EC_GROUP_get_degree ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_check ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_check_discriminant ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_cmp ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_new_curve_GFp ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_new_curve_GF2m ? 4_0_0 EXIST::FUNCTION:EC,EC2M +EC_GROUP_new_from_params ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_to_params ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_new_by_curve_name_ex ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_new_by_curve_name ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_new_from_ecparameters ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get_ecparameters ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_new_from_ecpkparameters ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get_ecpkparameters ? 4_0_0 EXIST::FUNCTION:EC +EC_get_builtin_curves ? 4_0_0 EXIST::FUNCTION:EC +EC_curve_nid2nist ? 4_0_0 EXIST::FUNCTION:EC +EC_curve_nist2nid ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_check_named_curve ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_new ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_free ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_clear_free ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_copy ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_dup ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_set_to_infinity ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_method_of ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_POINT_set_Jprojective_coordinates_GFp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_POINT_get_Jprojective_coordinates_GFp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_POINT_set_affine_coordinates ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_get_affine_coordinates ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_set_affine_coordinates_GFp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_POINT_get_affine_coordinates_GFp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_POINT_set_compressed_coordinates ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_set_compressed_coordinates_GFp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_POINT_set_affine_coordinates_GF2m ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC2M +EC_POINT_get_affine_coordinates_GF2m ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC2M +EC_POINT_set_compressed_coordinates_GF2m ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,EC2M +EC_POINT_point2oct ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_oct2point ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_point2buf ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_point2bn ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_POINT_bn2point ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_POINT_point2hex ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_hex2point ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_add ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_dbl ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_invert ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_is_at_infinity ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_is_on_curve ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_cmp ? 4_0_0 EXIST::FUNCTION:EC +EC_POINT_make_affine ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_POINTs_make_affine ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_POINTs_mul ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_POINT_mul ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_precompute_mult ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_GROUP_have_precompute_mult ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +ECPKPARAMETERS_it ? 4_0_0 EXIST::FUNCTION:EC +ECPKPARAMETERS_free ? 4_0_0 EXIST::FUNCTION:EC +ECPKPARAMETERS_new ? 4_0_0 EXIST::FUNCTION:EC +ECPARAMETERS_it ? 4_0_0 EXIST::FUNCTION:EC +ECPARAMETERS_free ? 4_0_0 EXIST::FUNCTION:EC +ECPARAMETERS_new ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get_basis_type ? 4_0_0 EXIST::FUNCTION:EC +EC_GROUP_get_trinomial_basis ? 4_0_0 EXIST::FUNCTION:EC,EC2M +EC_GROUP_get_pentanomial_basis ? 4_0_0 EXIST::FUNCTION:EC,EC2M +d2i_ECPKParameters ? 4_0_0 EXIST::FUNCTION:EC +i2d_ECPKParameters ? 4_0_0 EXIST::FUNCTION:EC +ECPKParameters_print ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +ECPKParameters_print_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO +EC_KEY_new_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_get_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_set_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_clear_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_decoded_from_explicit_params ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_new_by_curve_name_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_new_by_curve_name ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_copy ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_dup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_up_ref ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_get0_group ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_set_group ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_get0_private_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_set_private_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_get0_public_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_set_public_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_get_enc_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_set_enc_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_get_conv_form ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_set_conv_form ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_set_ex_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_get_ex_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_set_asn1_flag ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_precompute_mult ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_generate_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_check_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_can_sign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_set_public_key_affine_coordinates ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_key2buf ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_oct2key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_oct2priv ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_priv2oct ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_priv2buf ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +d2i_ECPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +i2d_ECPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +d2i_ECParameters ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +i2d_ECParameters ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +o2i_ECPublicKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +i2o_ECPublicKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +ECParameters_print ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_print ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +ECParameters_print_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO +EC_KEY_print_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO +EC_KEY_OpenSSL ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_get_default_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_set_default_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_get_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_set_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_new_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +ECDH_KDF_X9_62 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +ECDH_compute_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +ECDSA_SIG_new ? 4_0_0 EXIST::FUNCTION:EC +ECDSA_SIG_free ? 4_0_0 EXIST::FUNCTION:EC +d2i_ECDSA_SIG ? 4_0_0 EXIST::FUNCTION:EC +i2d_ECDSA_SIG ? 4_0_0 EXIST::FUNCTION:EC +ECDSA_SIG_get0 ? 4_0_0 EXIST::FUNCTION:EC +ECDSA_SIG_get0_r ? 4_0_0 EXIST::FUNCTION:EC +ECDSA_SIG_get0_s ? 4_0_0 EXIST::FUNCTION:EC +ECDSA_SIG_set0 ? 4_0_0 EXIST::FUNCTION:EC +ECDSA_do_sign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +ECDSA_do_sign_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +ECDSA_do_verify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +ECDSA_sign_setup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +ECDSA_sign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +ECDSA_sign_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +ECDSA_verify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +ECDSA_size ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_METHOD_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_METHOD_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_METHOD_set_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_METHOD_set_keygen ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_METHOD_set_compute_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_METHOD_set_sign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_METHOD_set_verify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_METHOD_get_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_METHOD_get_keygen ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_METHOD_get_compute_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_METHOD_get_sign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EC_KEY_METHOD_get_verify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +OSSL_ENCODER_fetch ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_up_ref ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_free ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_get0_provider ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_get0_properties ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_get0_name ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_get0_description ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_is_a ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_do_all_provided ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_names_do_all ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_gettable_params ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_get_params ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_settable_ctx_params ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_new ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_set_params ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_free ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_set_passphrase ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_set_pem_password_cb ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_set_passphrase_cb ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_set_passphrase_ui ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_set_cipher ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_set_selection ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_set_output_type ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_set_output_structure ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_add_encoder ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_add_extra ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_get_num_encoders ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_INSTANCE_get_encoder ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_INSTANCE_get_encoder_ctx ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_INSTANCE_get_output_type ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_INSTANCE_get_output_structure ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_set_construct ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_set_construct_data ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_set_cleanup ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_to_bio ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_to_fp ? 4_0_0 EXIST::FUNCTION:STDIO +OSSL_ENCODER_to_data ? 4_0_0 EXIST::FUNCTION: +OSSL_ENCODER_CTX_new_for_pkey ? 4_0_0 EXIST::FUNCTION: +EVP_set_default_properties ? 4_0_0 EXIST::FUNCTION: +EVP_get1_default_properties ? 4_0_0 EXIST::FUNCTION: +EVP_default_properties_is_fips_enabled ? 4_0_0 EXIST::FUNCTION: +EVP_default_properties_enable_fips ? 4_0_0 EXIST::FUNCTION: +EVP_MD_meth_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_dup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_set_input_blocksize ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_set_result_size ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_set_app_datasize ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_set_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_set_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_set_update ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_set_final ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_set_copy ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_set_cleanup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_set_ctrl ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_get_input_blocksize ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_get_result_size ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_get_app_datasize ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_get_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_get_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_get_update ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_get_final ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_get_copy ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_get_cleanup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_meth_get_ctrl ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_dup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_set_iv_length ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_set_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_set_impl_ctx_size ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_set_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_set_do_cipher ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_set_cleanup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_set_set_asn1_params ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_set_get_asn1_params ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_set_ctrl ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_get_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_get_do_cipher ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_get_cleanup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_get_set_asn1_params ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_get_get_asn1_params ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_meth_get_ctrl ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_get_type ? 4_0_0 EXIST::FUNCTION: +EVP_MD_get0_name ? 4_0_0 EXIST::FUNCTION: +EVP_MD_get0_description ? 4_0_0 EXIST::FUNCTION: +EVP_MD_is_a ? 4_0_0 EXIST::FUNCTION: +EVP_MD_names_do_all ? 4_0_0 EXIST::FUNCTION: +EVP_MD_get0_provider ? 4_0_0 EXIST::FUNCTION: +EVP_MD_get_pkey_type ? 4_0_0 EXIST::FUNCTION: +EVP_MD_get_size ? 4_0_0 EXIST::FUNCTION: +EVP_MD_get_block_size ? 4_0_0 EXIST::FUNCTION: +EVP_MD_get_flags ? 4_0_0 EXIST::FUNCTION: +EVP_MD_xof ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_get0_md ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_get1_md ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_md ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_CTX_update_fn ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_CTX_set_update_fn ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_MD_CTX_get_size_ex ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_get_pkey_ctx ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_set_pkey_ctx ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_get0_md_data ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_get_nid ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_get0_name ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_get0_description ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_is_a ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_names_do_all ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_get0_provider ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_get_block_size ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_impl_ctx_size ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_get_key_length ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_get_iv_length ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_get_flags ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_get_mode ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_get_type ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_fetch ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_can_pipeline ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_up_ref ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_free ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_get0_cipher ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_get1_cipher ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_is_encrypting ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_get_nid ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_get_block_size ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_get_key_length ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_get_iv_length ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_get_tag_length ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_cipher ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_CTX_iv ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_CTX_original_iv ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_CTX_iv_noconst ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_CTX_get_updated_iv ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_get_original_iv ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_buf_noconst ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_CIPHER_CTX_get_num ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_set_num ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_dup ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_copy ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_get_app_data ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_set_app_data ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_get_cipher_data ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_set_cipher_data ? 4_0_0 EXIST::FUNCTION: +EVP_Cipher ? 4_0_0 EXIST::FUNCTION: +EVP_MD_get_params ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_set_params ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_get_params ? 4_0_0 EXIST::FUNCTION: +EVP_MD_gettable_params ? 4_0_0 EXIST::FUNCTION: +EVP_MD_settable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_MD_gettable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_settable_params ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_gettable_params ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_ctrl ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_new ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_reset ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_free ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_dup ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_copy_ex ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_set_flags ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_clear_flags ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_test_flags ? 4_0_0 EXIST::FUNCTION: +EVP_DigestInit_ex2 ? 4_0_0 EXIST::FUNCTION: +EVP_DigestInit_ex ? 4_0_0 EXIST::FUNCTION: +EVP_DigestUpdate ? 4_0_0 EXIST::FUNCTION: +EVP_DigestFinal_ex ? 4_0_0 EXIST::FUNCTION: +EVP_Digest ? 4_0_0 EXIST::FUNCTION: +EVP_Q_digest ? 4_0_0 EXIST::FUNCTION: +EVP_MD_CTX_copy ? 4_0_0 EXIST::FUNCTION: +EVP_DigestInit ? 4_0_0 EXIST::FUNCTION: +EVP_DigestFinal ? 4_0_0 EXIST::FUNCTION: +EVP_DigestFinalXOF ? 4_0_0 EXIST::FUNCTION: +EVP_DigestSqueeze ? 4_0_0 EXIST::FUNCTION: +EVP_MD_fetch ? 4_0_0 EXIST::FUNCTION: +EVP_MD_up_ref ? 4_0_0 EXIST::FUNCTION: +EVP_MD_free ? 4_0_0 EXIST::FUNCTION: +EVP_read_pw_string ? 4_0_0 EXIST::FUNCTION: +EVP_read_pw_string_min ? 4_0_0 EXIST::FUNCTION: +EVP_set_pw_prompt ? 4_0_0 EXIST::FUNCTION: +EVP_get_pw_prompt ? 4_0_0 EXIST::FUNCTION: +EVP_BytesToKey ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_set_flags ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_clear_flags ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_test_flags ? 4_0_0 EXIST::FUNCTION: +EVP_EncryptInit ? 4_0_0 EXIST::FUNCTION: +EVP_EncryptInit_ex ? 4_0_0 EXIST::FUNCTION: +EVP_EncryptInit_ex2 ? 4_0_0 EXIST::FUNCTION: +EVP_EncryptUpdate ? 4_0_0 EXIST::FUNCTION: +EVP_EncryptFinal_ex ? 4_0_0 EXIST::FUNCTION: +EVP_EncryptFinal ? 4_0_0 EXIST::FUNCTION: +EVP_DecryptInit ? 4_0_0 EXIST::FUNCTION: +EVP_DecryptInit_ex ? 4_0_0 EXIST::FUNCTION: +EVP_DecryptInit_ex2 ? 4_0_0 EXIST::FUNCTION: +EVP_DecryptUpdate ? 4_0_0 EXIST::FUNCTION: +EVP_DecryptFinal ? 4_0_0 EXIST::FUNCTION: +EVP_DecryptFinal_ex ? 4_0_0 EXIST::FUNCTION: +EVP_CipherInit ? 4_0_0 EXIST::FUNCTION: +EVP_CipherInit_ex ? 4_0_0 EXIST::FUNCTION: +EVP_CipherInit_SKEY ? 4_0_0 EXIST::FUNCTION: +EVP_CipherInit_ex2 ? 4_0_0 EXIST::FUNCTION: +EVP_CipherUpdate ? 4_0_0 EXIST::FUNCTION: +EVP_CipherFinal ? 4_0_0 EXIST::FUNCTION: +EVP_CipherPipelineEncryptInit ? 4_0_0 EXIST::FUNCTION: +EVP_CipherPipelineDecryptInit ? 4_0_0 EXIST::FUNCTION: +EVP_CipherPipelineUpdate ? 4_0_0 EXIST::FUNCTION: +EVP_CipherPipelineFinal ? 4_0_0 EXIST::FUNCTION: +EVP_CipherFinal_ex ? 4_0_0 EXIST::FUNCTION: +EVP_SignFinal ? 4_0_0 EXIST::FUNCTION: +EVP_SignFinal_ex ? 4_0_0 EXIST::FUNCTION: +EVP_DigestSign ? 4_0_0 EXIST::FUNCTION: +EVP_VerifyFinal ? 4_0_0 EXIST::FUNCTION: +EVP_VerifyFinal_ex ? 4_0_0 EXIST::FUNCTION: +EVP_DigestVerify ? 4_0_0 EXIST::FUNCTION: +EVP_DigestSignInit_ex ? 4_0_0 EXIST::FUNCTION: +EVP_DigestSignInit ? 4_0_0 EXIST::FUNCTION: +EVP_DigestSignUpdate ? 4_0_0 EXIST::FUNCTION: +EVP_DigestSignFinal ? 4_0_0 EXIST::FUNCTION: +EVP_DigestVerifyInit_ex ? 4_0_0 EXIST::FUNCTION: +EVP_DigestVerifyInit ? 4_0_0 EXIST::FUNCTION: +EVP_DigestVerifyUpdate ? 4_0_0 EXIST::FUNCTION: +EVP_DigestVerifyFinal ? 4_0_0 EXIST::FUNCTION: +EVP_OpenInit ? 4_0_0 EXIST::FUNCTION: +EVP_OpenFinal ? 4_0_0 EXIST::FUNCTION: +EVP_SealInit ? 4_0_0 EXIST::FUNCTION: +EVP_SealFinal ? 4_0_0 EXIST::FUNCTION: +EVP_ENCODE_CTX_new ? 4_0_0 EXIST::FUNCTION: +EVP_ENCODE_CTX_free ? 4_0_0 EXIST::FUNCTION: +EVP_ENCODE_CTX_copy ? 4_0_0 EXIST::FUNCTION: +EVP_ENCODE_CTX_num ? 4_0_0 EXIST::FUNCTION: +EVP_EncodeInit ? 4_0_0 EXIST::FUNCTION: +EVP_EncodeUpdate ? 4_0_0 EXIST::FUNCTION: +EVP_EncodeFinal ? 4_0_0 EXIST::FUNCTION: +EVP_EncodeBlock ? 4_0_0 EXIST::FUNCTION: +EVP_DecodeInit ? 4_0_0 EXIST::FUNCTION: +EVP_DecodeUpdate ? 4_0_0 EXIST::FUNCTION: +EVP_DecodeFinal ? 4_0_0 EXIST::FUNCTION: +EVP_DecodeBlock ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_new ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_reset ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_free ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_set_key_length ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_set_padding ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_ctrl ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_rand_key ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_get_params ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_set_params ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_get_params ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_gettable_params ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_settable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_gettable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_settable_params ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_gettable_params ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_set_algor_params ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_get_algor_params ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_CTX_get_algor ? 4_0_0 EXIST::FUNCTION: +BIO_f_md ? 4_0_0 EXIST::FUNCTION: +BIO_f_base64 ? 4_0_0 EXIST::FUNCTION: +BIO_f_cipher ? 4_0_0 EXIST::FUNCTION: +BIO_f_reliable ? 4_0_0 EXIST::FUNCTION: +BIO_set_cipher ? 4_0_0 EXIST::FUNCTION: +EVP_md_null ? 4_0_0 EXIST::FUNCTION: +EVP_md2 ? 4_0_0 EXIST::FUNCTION:MD2 +EVP_md4 ? 4_0_0 EXIST::FUNCTION:MD4 +EVP_md5 ? 4_0_0 EXIST::FUNCTION:MD5 +EVP_md5_sha1 ? 4_0_0 EXIST::FUNCTION:MD5 +EVP_blake2b512 ? 4_0_0 EXIST::FUNCTION:BLAKE2 +EVP_blake2s256 ? 4_0_0 EXIST::FUNCTION:BLAKE2 +EVP_sha1 ? 4_0_0 EXIST::FUNCTION: +EVP_sha224 ? 4_0_0 EXIST::FUNCTION: +EVP_sha256 ? 4_0_0 EXIST::FUNCTION: +EVP_sha384 ? 4_0_0 EXIST::FUNCTION: +EVP_sha512 ? 4_0_0 EXIST::FUNCTION: +EVP_sha512_224 ? 4_0_0 EXIST::FUNCTION: +EVP_sha512_256 ? 4_0_0 EXIST::FUNCTION: +EVP_sha3_224 ? 4_0_0 EXIST::FUNCTION: +EVP_sha3_256 ? 4_0_0 EXIST::FUNCTION: +EVP_sha3_384 ? 4_0_0 EXIST::FUNCTION: +EVP_sha3_512 ? 4_0_0 EXIST::FUNCTION: +EVP_shake128 ? 4_0_0 EXIST::FUNCTION: +EVP_shake256 ? 4_0_0 EXIST::FUNCTION: +EVP_mdc2 ? 4_0_0 EXIST::FUNCTION:MDC2 +EVP_ripemd160 ? 4_0_0 EXIST::FUNCTION:RMD160 +EVP_whirlpool ? 4_0_0 EXIST::FUNCTION:WHIRLPOOL +EVP_sm3 ? 4_0_0 EXIST::FUNCTION:SM3 +EVP_enc_null ? 4_0_0 EXIST::FUNCTION: +EVP_des_ecb ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_ede ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_ede3 ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_ede_ecb ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_ede3_ecb ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_cfb64 ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_cfb1 ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_cfb8 ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_ede_cfb64 ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_ede3_cfb64 ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_ede3_cfb1 ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_ede3_cfb8 ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_ofb ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_ede_ofb ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_ede3_ofb ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_cbc ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_ede_cbc ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_ede3_cbc ? 4_0_0 EXIST::FUNCTION:DES +EVP_desx_cbc ? 4_0_0 EXIST::FUNCTION:DES +EVP_des_ede3_wrap ? 4_0_0 EXIST::FUNCTION:DES +EVP_rc4 ? 4_0_0 EXIST::FUNCTION:RC4 +EVP_rc4_40 ? 4_0_0 EXIST::FUNCTION:RC4 +EVP_rc4_hmac_md5 ? 4_0_0 EXIST::FUNCTION:MD5,RC4 +EVP_idea_ecb ? 4_0_0 EXIST::FUNCTION:IDEA +EVP_idea_cfb64 ? 4_0_0 EXIST::FUNCTION:IDEA +EVP_idea_ofb ? 4_0_0 EXIST::FUNCTION:IDEA +EVP_idea_cbc ? 4_0_0 EXIST::FUNCTION:IDEA +EVP_rc2_ecb ? 4_0_0 EXIST::FUNCTION:RC2 +EVP_rc2_cbc ? 4_0_0 EXIST::FUNCTION:RC2 +EVP_rc2_40_cbc ? 4_0_0 EXIST::FUNCTION:RC2 +EVP_rc2_64_cbc ? 4_0_0 EXIST::FUNCTION:RC2 +EVP_rc2_cfb64 ? 4_0_0 EXIST::FUNCTION:RC2 +EVP_rc2_ofb ? 4_0_0 EXIST::FUNCTION:RC2 +EVP_bf_ecb ? 4_0_0 EXIST::FUNCTION:BF +EVP_bf_cbc ? 4_0_0 EXIST::FUNCTION:BF +EVP_bf_cfb64 ? 4_0_0 EXIST::FUNCTION:BF +EVP_bf_ofb ? 4_0_0 EXIST::FUNCTION:BF +EVP_cast5_ecb ? 4_0_0 EXIST::FUNCTION:CAST +EVP_cast5_cbc ? 4_0_0 EXIST::FUNCTION:CAST +EVP_cast5_cfb64 ? 4_0_0 EXIST::FUNCTION:CAST +EVP_cast5_ofb ? 4_0_0 EXIST::FUNCTION:CAST +EVP_rc5_32_12_16_cbc ? 4_0_0 EXIST::FUNCTION:RC5 +EVP_rc5_32_12_16_ecb ? 4_0_0 EXIST::FUNCTION:RC5 +EVP_rc5_32_12_16_cfb64 ? 4_0_0 EXIST::FUNCTION:RC5 +EVP_rc5_32_12_16_ofb ? 4_0_0 EXIST::FUNCTION:RC5 +EVP_aes_128_ecb ? 4_0_0 EXIST::FUNCTION: +EVP_aes_128_cbc ? 4_0_0 EXIST::FUNCTION: +EVP_aes_128_cfb1 ? 4_0_0 EXIST::FUNCTION: +EVP_aes_128_cfb8 ? 4_0_0 EXIST::FUNCTION: +EVP_aes_128_cfb128 ? 4_0_0 EXIST::FUNCTION: +EVP_aes_128_ofb ? 4_0_0 EXIST::FUNCTION: +EVP_aes_128_ctr ? 4_0_0 EXIST::FUNCTION: +EVP_aes_128_ccm ? 4_0_0 EXIST::FUNCTION: +EVP_aes_128_gcm ? 4_0_0 EXIST::FUNCTION: +EVP_aes_128_xts ? 4_0_0 EXIST::FUNCTION: +EVP_aes_128_wrap ? 4_0_0 EXIST::FUNCTION: +EVP_aes_128_wrap_pad ? 4_0_0 EXIST::FUNCTION: +EVP_aes_128_ocb ? 4_0_0 EXIST::FUNCTION:OCB +EVP_aes_192_ecb ? 4_0_0 EXIST::FUNCTION: +EVP_aes_192_cbc ? 4_0_0 EXIST::FUNCTION: +EVP_aes_192_cfb1 ? 4_0_0 EXIST::FUNCTION: +EVP_aes_192_cfb8 ? 4_0_0 EXIST::FUNCTION: +EVP_aes_192_cfb128 ? 4_0_0 EXIST::FUNCTION: +EVP_aes_192_ofb ? 4_0_0 EXIST::FUNCTION: +EVP_aes_192_ctr ? 4_0_0 EXIST::FUNCTION: +EVP_aes_192_ccm ? 4_0_0 EXIST::FUNCTION: +EVP_aes_192_gcm ? 4_0_0 EXIST::FUNCTION: +EVP_aes_192_wrap ? 4_0_0 EXIST::FUNCTION: +EVP_aes_192_wrap_pad ? 4_0_0 EXIST::FUNCTION: +EVP_aes_192_ocb ? 4_0_0 EXIST::FUNCTION:OCB +EVP_aes_256_ecb ? 4_0_0 EXIST::FUNCTION: +EVP_aes_256_cbc ? 4_0_0 EXIST::FUNCTION: +EVP_aes_256_cfb1 ? 4_0_0 EXIST::FUNCTION: +EVP_aes_256_cfb8 ? 4_0_0 EXIST::FUNCTION: +EVP_aes_256_cfb128 ? 4_0_0 EXIST::FUNCTION: +EVP_aes_256_ofb ? 4_0_0 EXIST::FUNCTION: +EVP_aes_256_ctr ? 4_0_0 EXIST::FUNCTION: +EVP_aes_256_ccm ? 4_0_0 EXIST::FUNCTION: +EVP_aes_256_gcm ? 4_0_0 EXIST::FUNCTION: +EVP_aes_256_xts ? 4_0_0 EXIST::FUNCTION: +EVP_aes_256_wrap ? 4_0_0 EXIST::FUNCTION: +EVP_aes_256_wrap_pad ? 4_0_0 EXIST::FUNCTION: +EVP_aes_256_ocb ? 4_0_0 EXIST::FUNCTION:OCB +EVP_aes_128_cbc_hmac_sha1 ? 4_0_0 EXIST::FUNCTION: +EVP_aes_256_cbc_hmac_sha1 ? 4_0_0 EXIST::FUNCTION: +EVP_aes_128_cbc_hmac_sha256 ? 4_0_0 EXIST::FUNCTION: +EVP_aes_256_cbc_hmac_sha256 ? 4_0_0 EXIST::FUNCTION: +EVP_aria_128_ecb ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_128_cbc ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_128_cfb1 ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_128_cfb8 ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_128_cfb128 ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_128_ctr ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_128_ofb ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_128_gcm ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_128_ccm ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_192_ecb ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_192_cbc ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_192_cfb1 ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_192_cfb8 ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_192_cfb128 ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_192_ctr ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_192_ofb ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_192_gcm ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_192_ccm ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_256_ecb ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_256_cbc ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_256_cfb1 ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_256_cfb8 ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_256_cfb128 ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_256_ctr ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_256_ofb ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_256_gcm ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_aria_256_ccm ? 4_0_0 EXIST::FUNCTION:ARIA +EVP_camellia_128_ecb ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_128_cbc ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_128_cfb1 ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_128_cfb8 ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_128_cfb128 ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_128_ofb ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_128_ctr ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_192_ecb ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_192_cbc ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_192_cfb1 ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_192_cfb8 ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_192_cfb128 ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_192_ofb ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_192_ctr ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_256_ecb ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_256_cbc ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_256_cfb1 ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_256_cfb8 ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_256_cfb128 ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_256_ofb ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_camellia_256_ctr ? 4_0_0 EXIST::FUNCTION:CAMELLIA +EVP_chacha20 ? 4_0_0 EXIST::FUNCTION:CHACHA +EVP_chacha20_poly1305 ? 4_0_0 EXIST::FUNCTION:CHACHA,POLY1305 +EVP_seed_ecb ? 4_0_0 EXIST::FUNCTION:SEED +EVP_seed_cbc ? 4_0_0 EXIST::FUNCTION:SEED +EVP_seed_cfb128 ? 4_0_0 EXIST::FUNCTION:SEED +EVP_seed_ofb ? 4_0_0 EXIST::FUNCTION:SEED +EVP_sm4_ecb ? 4_0_0 EXIST::FUNCTION:SM4 +EVP_sm4_cbc ? 4_0_0 EXIST::FUNCTION:SM4 +EVP_sm4_cfb128 ? 4_0_0 EXIST::FUNCTION:SM4 +EVP_sm4_ofb ? 4_0_0 EXIST::FUNCTION:SM4 +EVP_sm4_ctr ? 4_0_0 EXIST::FUNCTION:SM4 +EVP_add_cipher ? 4_0_0 EXIST::FUNCTION: +EVP_add_digest ? 4_0_0 EXIST::FUNCTION: +EVP_get_cipherbyname ? 4_0_0 EXIST::FUNCTION: +EVP_get_digestbyname ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_do_all ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_do_all_sorted ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_do_all_provided ? 4_0_0 EXIST::FUNCTION: +EVP_MD_do_all ? 4_0_0 EXIST::FUNCTION: +EVP_MD_do_all_sorted ? 4_0_0 EXIST::FUNCTION: +EVP_MD_do_all_provided ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_fetch ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_up_ref ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_free ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_get0_name ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_get0_description ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_is_a ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_get0_provider ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_get_params ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_CTX_new ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_CTX_free ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_CTX_dup ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_CTX_get0_mac ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_CTX_get_params ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_CTX_set_params ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_CTX_get_mac_size ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_CTX_get_block_size ? 4_0_0 EXIST::FUNCTION: +EVP_Q_mac ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_init ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_init_SKEY ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_update ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_final ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_finalXOF ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_gettable_params ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_gettable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_settable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_CTX_gettable_params ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_CTX_settable_params ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_do_all_provided ? 4_0_0 EXIST::FUNCTION: +EVP_MAC_names_do_all ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_fetch ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_up_ref ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_free ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_get0_name ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_get0_description ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_is_a ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_get0_provider ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_get_params ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_CTX_new ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_CTX_up_ref ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_CTX_free ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_CTX_get0_rand ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_CTX_get_params ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_CTX_set_params ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_gettable_params ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_gettable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_settable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_CTX_gettable_params ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_CTX_settable_params ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_do_all_provided ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_names_do_all ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_instantiate ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_uninstantiate ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_generate ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_reseed ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_nonce ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_enable_locking ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_verify_zeroization ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_get_strength ? 4_0_0 EXIST::FUNCTION: +EVP_RAND_get_state ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_decrypt_old ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_encrypt_old ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_is_a ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_type_names_do_all ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_type ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_id ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_base_id ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_bits ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_security_bits ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_security_category ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_size ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_can_sign ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_set_type ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_set_type_str ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_set_type_by_keymgmt ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_assign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_get0 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_get0_hmac ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_get0_poly1305 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,POLY1305 +EVP_PKEY_get0_siphash ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SIPHASH +EVP_PKEY_set1_RSA ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_get0_RSA ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_get1_RSA ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_set1_DSA ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +EVP_PKEY_get0_DSA ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +EVP_PKEY_get1_DSA ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +EVP_PKEY_set1_DH ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +EVP_PKEY_get0_DH ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +EVP_PKEY_get1_DH ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +EVP_PKEY_set1_EC_KEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EVP_PKEY_get0_EC_KEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EVP_PKEY_get1_EC_KEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +EVP_PKEY_new ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_up_ref ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_dup ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_free ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get0_description ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get0_provider ? 4_0_0 EXIST::FUNCTION: +d2i_PublicKey ? 4_0_0 EXIST::FUNCTION: +i2d_PublicKey ? 4_0_0 EXIST::FUNCTION: +d2i_PrivateKey_ex ? 4_0_0 EXIST::FUNCTION: +d2i_PrivateKey ? 4_0_0 EXIST::FUNCTION: +d2i_AutoPrivateKey_ex ? 4_0_0 EXIST::FUNCTION: +d2i_AutoPrivateKey ? 4_0_0 EXIST::FUNCTION: +i2d_PrivateKey ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS8PrivateKey ? 4_0_0 EXIST::FUNCTION: +i2d_KeyParams ? 4_0_0 EXIST::FUNCTION: +d2i_KeyParams ? 4_0_0 EXIST::FUNCTION: +i2d_KeyParams_bio ? 4_0_0 EXIST::FUNCTION: +d2i_KeyParams_bio ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_copy_parameters ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_missing_parameters ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_save_parameters ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_parameters_eq ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_eq ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_cmp_parameters ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_cmp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_print_public ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_print_private ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_print_params ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_print_public_fp ? 4_0_0 EXIST::FUNCTION:STDIO +EVP_PKEY_print_private_fp ? 4_0_0 EXIST::FUNCTION:STDIO +EVP_PKEY_print_params_fp ? 4_0_0 EXIST::FUNCTION:STDIO +EVP_PKEY_get_default_digest_nid ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_default_digest_name ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_digestsign_supports_digest ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_set1_encoded_public_key ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get1_encoded_public_key ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_param_to_asn1 ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_asn1_to_param ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_set_asn1_iv ? 4_0_0 EXIST::FUNCTION: +EVP_CIPHER_get_asn1_iv ? 4_0_0 EXIST::FUNCTION: +PKCS5_PBE_keyivgen ? 4_0_0 EXIST::FUNCTION: +PKCS5_PBE_keyivgen_ex ? 4_0_0 EXIST::FUNCTION: +PKCS5_PBKDF2_HMAC_SHA1 ? 4_0_0 EXIST::FUNCTION: +PKCS5_PBKDF2_HMAC ? 4_0_0 EXIST::FUNCTION: +PKCS5_v2_PBE_keyivgen ? 4_0_0 EXIST::FUNCTION: +PKCS5_v2_PBE_keyivgen_ex ? 4_0_0 EXIST::FUNCTION: +EVP_PBE_scrypt ? 4_0_0 EXIST::FUNCTION:SCRYPT +EVP_PBE_scrypt_ex ? 4_0_0 EXIST::FUNCTION:SCRYPT +PKCS5_v2_scrypt_keyivgen ? 4_0_0 EXIST::FUNCTION:SCRYPT +PKCS5_v2_scrypt_keyivgen_ex ? 4_0_0 EXIST::FUNCTION:SCRYPT +PKCS5_PBE_add ? 4_0_0 EXIST::FUNCTION: +EVP_PBE_CipherInit ? 4_0_0 EXIST::FUNCTION: +EVP_PBE_CipherInit_ex ? 4_0_0 EXIST::FUNCTION: +EVP_PBE_alg_add_type ? 4_0_0 EXIST::FUNCTION: +EVP_PBE_alg_add ? 4_0_0 EXIST::FUNCTION: +EVP_PBE_find ? 4_0_0 EXIST::FUNCTION: +EVP_PBE_find_ex ? 4_0_0 EXIST::FUNCTION: +EVP_PBE_cleanup ? 4_0_0 EXIST::FUNCTION: +EVP_PBE_get ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_asn1_get_count ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_get0 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_find ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_find_str ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_add0 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_add_alias ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_get0_info ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_get0_asn1 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_copy ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_set_public ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_set_private ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_set_param ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_set_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_set_ctrl ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_set_item ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_set_siginf ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_set_check ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_set_public_check ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_set_param_check ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_set_set_priv_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_set_set_pub_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_set_get_priv_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_set_get_pub_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_asn1_set_security_bits ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_6 +EVP_PKEY_CTX_get_signature_md ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_signature_md ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set1_id ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get1_id ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get1_id_len ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_kem_op ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get0_type_name ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_mac_key ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_meth_find ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get0_info ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_copy ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_add0 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_remove ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_count ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get0 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_KEYMGMT_fetch ? 4_0_0 EXIST::FUNCTION: +EVP_KEYMGMT_up_ref ? 4_0_0 EXIST::FUNCTION: +EVP_KEYMGMT_free ? 4_0_0 EXIST::FUNCTION: +EVP_KEYMGMT_get0_provider ? 4_0_0 EXIST::FUNCTION: +EVP_KEYMGMT_get0_name ? 4_0_0 EXIST::FUNCTION: +EVP_KEYMGMT_get0_description ? 4_0_0 EXIST::FUNCTION: +EVP_KEYMGMT_is_a ? 4_0_0 EXIST::FUNCTION: +EVP_KEYMGMT_do_all_provided ? 4_0_0 EXIST::FUNCTION: +EVP_KEYMGMT_names_do_all ? 4_0_0 EXIST::FUNCTION: +EVP_KEYMGMT_gettable_params ? 4_0_0 EXIST::FUNCTION: +EVP_KEYMGMT_settable_params ? 4_0_0 EXIST::FUNCTION: +EVP_KEYMGMT_gen_settable_params ? 4_0_0 EXIST::FUNCTION: +EVP_KEYMGMT_gen_gettable_params ? 4_0_0 EXIST::FUNCTION: +EVP_SKEYMGMT_fetch ? 4_0_0 EXIST::FUNCTION: +EVP_SKEYMGMT_up_ref ? 4_0_0 EXIST::FUNCTION: +EVP_SKEYMGMT_free ? 4_0_0 EXIST::FUNCTION: +EVP_SKEYMGMT_get0_provider ? 4_0_0 EXIST::FUNCTION: +EVP_SKEYMGMT_get0_name ? 4_0_0 EXIST::FUNCTION: +EVP_SKEYMGMT_get0_description ? 4_0_0 EXIST::FUNCTION: +EVP_SKEYMGMT_is_a ? 4_0_0 EXIST::FUNCTION: +EVP_SKEYMGMT_do_all_provided ? 4_0_0 EXIST::FUNCTION: +EVP_SKEYMGMT_names_do_all ? 4_0_0 EXIST::FUNCTION: +EVP_SKEYMGMT_get0_gen_settable_params ? 4_0_0 EXIST::FUNCTION: +EVP_SKEYMGMT_get0_imp_settable_params ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_new ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_new_id ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_new_from_name ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_new_from_pkey ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_dup ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_free ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_is_a ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_params ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_gettable_params ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_params ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_settable_params ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_algor_params ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_algor_params ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_algor ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_ctrl ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_ctrl_str ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_ctrl_uint64 ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_str2ctrl ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_hex2ctrl ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_md ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_operation ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set0_keygen_info ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_new_mac_key ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_new_raw_private_key_ex ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_new_raw_private_key ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_new_raw_public_key_ex ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_new_raw_public_key ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_raw_private_key ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_raw_public_key ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_new_CMAC_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_CTX_set_data ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_data ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get0_pkey ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get0_peerkey ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_app_data ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_app_data ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_signature ? 4_0_0 EXIST::FUNCTION: +EVP_SIGNATURE_free ? 4_0_0 EXIST::FUNCTION: +EVP_SIGNATURE_up_ref ? 4_0_0 EXIST::FUNCTION: +EVP_SIGNATURE_get0_provider ? 4_0_0 EXIST::FUNCTION: +EVP_SIGNATURE_fetch ? 4_0_0 EXIST::FUNCTION: +EVP_SIGNATURE_is_a ? 4_0_0 EXIST::FUNCTION: +EVP_SIGNATURE_get0_name ? 4_0_0 EXIST::FUNCTION: +EVP_SIGNATURE_get0_description ? 4_0_0 EXIST::FUNCTION: +EVP_SIGNATURE_do_all_provided ? 4_0_0 EXIST::FUNCTION: +EVP_SIGNATURE_names_do_all ? 4_0_0 EXIST::FUNCTION: +EVP_SIGNATURE_gettable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_SIGNATURE_settable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_ASYM_CIPHER_free ? 4_0_0 EXIST::FUNCTION: +EVP_ASYM_CIPHER_up_ref ? 4_0_0 EXIST::FUNCTION: +EVP_ASYM_CIPHER_get0_provider ? 4_0_0 EXIST::FUNCTION: +EVP_ASYM_CIPHER_fetch ? 4_0_0 EXIST::FUNCTION: +EVP_ASYM_CIPHER_is_a ? 4_0_0 EXIST::FUNCTION: +EVP_ASYM_CIPHER_get0_name ? 4_0_0 EXIST::FUNCTION: +EVP_ASYM_CIPHER_get0_description ? 4_0_0 EXIST::FUNCTION: +EVP_ASYM_CIPHER_do_all_provided ? 4_0_0 EXIST::FUNCTION: +EVP_ASYM_CIPHER_names_do_all ? 4_0_0 EXIST::FUNCTION: +EVP_ASYM_CIPHER_gettable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_ASYM_CIPHER_settable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_KEM_free ? 4_0_0 EXIST::FUNCTION: +EVP_KEM_up_ref ? 4_0_0 EXIST::FUNCTION: +EVP_KEM_get0_provider ? 4_0_0 EXIST::FUNCTION: +EVP_KEM_fetch ? 4_0_0 EXIST::FUNCTION: +EVP_KEM_is_a ? 4_0_0 EXIST::FUNCTION: +EVP_KEM_get0_name ? 4_0_0 EXIST::FUNCTION: +EVP_KEM_get0_description ? 4_0_0 EXIST::FUNCTION: +EVP_KEM_do_all_provided ? 4_0_0 EXIST::FUNCTION: +EVP_KEM_names_do_all ? 4_0_0 EXIST::FUNCTION: +EVP_KEM_gettable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_KEM_settable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_sign_init ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_sign_init_ex ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_sign_init_ex2 ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_sign ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_sign_message_init ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_sign_message_update ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_sign_message_final ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_verify_init ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_verify_init_ex ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_verify_init_ex2 ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_verify ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_verify_message_init ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_verify_message_update ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_verify_message_final ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_verify_recover_init ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_verify_recover_init_ex ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_verify_recover_init_ex2 ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_verify_recover ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_encrypt_init ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_encrypt_init_ex ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_encrypt ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_decrypt_init ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_decrypt_init_ex ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_decrypt ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_derive_init ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_derive_init_ex ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_derive_set_peer_ex ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_derive_set_peer ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_derive ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_derive_SKEY ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_encapsulate_init ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_auth_encapsulate_init ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_encapsulate ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_decapsulate_init ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_auth_decapsulate_init ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_decapsulate ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_fromdata_init ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_fromdata ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_fromdata_settable ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_todata ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_export ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_gettable_params ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_params ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_int_param ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_size_t_param ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_bn_param ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_utf8_string_param ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_octet_string_param ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_settable_params ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_set_params ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_set_int_param ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_set_size_t_param ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_set_bn_param ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_set_utf8_string_param ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_set_octet_string_param ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_ec_point_conv_form ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_field_type ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_Q_keygen ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_paramgen_init ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_paramgen ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_keygen_init ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_keygen ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_generate ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_check ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_public_check ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_public_check_quick ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_param_check ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_param_check_quick ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_private_check ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_pairwise_check ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_set_ex_data ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_ex_data ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_cb ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_cb ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_keygen_info ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_meth_set_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_copy ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_cleanup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_paramgen ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_keygen ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_sign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_verify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_verify_recover ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_signctx ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_verifyctx ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_decrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_derive ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_ctrl ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_digestsign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_digestverify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_check ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_public_check ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_param_check ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_set_digest_custom ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_copy ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_cleanup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_paramgen ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_keygen ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_sign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_verify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_verify_recover ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_signctx ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_verifyctx ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_decrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_derive ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_ctrl ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_digestsign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_digestverify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_check ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_public_check ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_param_check ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_meth_get_digest_custom ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_KEYEXCH_free ? 4_0_0 EXIST::FUNCTION: +EVP_KEYEXCH_up_ref ? 4_0_0 EXIST::FUNCTION: +EVP_KEYEXCH_fetch ? 4_0_0 EXIST::FUNCTION: +EVP_KEYEXCH_get0_provider ? 4_0_0 EXIST::FUNCTION: +EVP_KEYEXCH_is_a ? 4_0_0 EXIST::FUNCTION: +EVP_KEYEXCH_get0_name ? 4_0_0 EXIST::FUNCTION: +EVP_KEYEXCH_get0_description ? 4_0_0 EXIST::FUNCTION: +EVP_KEYEXCH_do_all_provided ? 4_0_0 EXIST::FUNCTION: +EVP_KEYEXCH_names_do_all ? 4_0_0 EXIST::FUNCTION: +EVP_KEYEXCH_gettable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_KEYEXCH_settable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_add_alg_module ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_group_name ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_group_name ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_group_name ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get0_libctx ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get0_propq ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get0_provider ? 4_0_0 EXIST::FUNCTION: +EVP_SKEY_is_a ? 4_0_0 EXIST::FUNCTION: +EVP_SKEY_import ? 4_0_0 EXIST::FUNCTION: +EVP_SKEY_generate ? 4_0_0 EXIST::FUNCTION: +EVP_SKEY_import_raw_key ? 4_0_0 EXIST::FUNCTION: +EVP_SKEY_import_SKEYMGMT ? 4_0_0 EXIST::FUNCTION: +EVP_SKEY_get0_raw_key ? 4_0_0 EXIST::FUNCTION: +EVP_SKEY_get0_key_id ? 4_0_0 EXIST::FUNCTION: +EVP_SKEY_export ? 4_0_0 EXIST::FUNCTION: +EVP_SKEY_up_ref ? 4_0_0 EXIST::FUNCTION: +EVP_SKEY_free ? 4_0_0 EXIST::FUNCTION: +EVP_SKEY_get0_skeymgmt_name ? 4_0_0 EXIST::FUNCTION: +EVP_SKEY_get0_provider_name ? 4_0_0 EXIST::FUNCTION: +EVP_SKEY_to_provider ? 4_0_0 EXIST::FUNCTION: +HMAC_size ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +HMAC_CTX_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +HMAC_CTX_reset ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +HMAC_CTX_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +HMAC_Init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0 +HMAC_Init_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +HMAC_Update ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +HMAC_Final ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +HMAC_CTX_copy ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +HMAC_CTX_set_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +HMAC_CTX_get_md ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +HMAC ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_CTX_new ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_CTX_free ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_encap ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_seal ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_keygen ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_decap ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_open ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_export ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_CTX_set1_authpriv ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_CTX_set1_authpub ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_CTX_set1_psk ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_CTX_set1_ikme ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_CTX_set_seq ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_CTX_get_seq ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_suite_check ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_get_grease_value ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_str2suite ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_get_ciphertext_size ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_get_public_encap_size ? 4_0_0 EXIST::FUNCTION: +OSSL_HPKE_get_recommended_ikmelen ? 4_0_0 EXIST::FUNCTION: +OSSL_parse_url ? 4_0_0 EXIST::FUNCTION: +OSSL_HTTP_REQ_CTX_new ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_REQ_CTX_free ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_REQ_CTX_set_request_line ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_REQ_CTX_add1_header ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_REQ_CTX_set_expected ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_REQ_CTX_set1_req ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_REQ_CTX_nbio ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_REQ_CTX_nbio_d2i ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_REQ_CTX_exchange ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_REQ_CTX_get0_mem_bio ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_REQ_CTX_get_resp_len ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_REQ_CTX_set_max_response_length ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_REQ_CTX_set_max_response_hdr_lines ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_is_alive ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_open ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_proxy_connect ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_set1_request ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_exchange ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_get ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_transfer ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_close ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_parse_url ? 4_0_0 EXIST::FUNCTION:HTTP +OSSL_HTTP_adapt_proxy ? 4_0_0 EXIST::FUNCTION:HTTP +IDEA_options ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA +IDEA_ecb_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA +IDEA_set_encrypt_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA +IDEA_set_decrypt_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA +IDEA_cbc_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA +IDEA_cfb64_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA +IDEA_ofb64_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA +IDEA_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,IDEA +OSSL_INDICATOR_set_callback ? 4_0_0 EXIST::FUNCTION: +OSSL_INDICATOR_get_callback ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_up_ref ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_free ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_fetch ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_CTX_new ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_CTX_free ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_CTX_dup ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_get0_description ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_is_a ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_get0_name ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_get0_provider ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_CTX_kdf ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_CTX_reset ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_CTX_get_kdf_size ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_derive ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_CTX_set_SKEY ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_derive_SKEY ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_get_params ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_CTX_get_params ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_CTX_set_params ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_gettable_params ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_gettable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_settable_ctx_params ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_CTX_gettable_params ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_CTX_settable_params ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_do_all_provided ? 4_0_0 EXIST::FUNCTION: +EVP_KDF_names_do_all ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_tls1_prf_md ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set1_tls1_prf_secret ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_add1_tls1_prf_seed ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_hkdf_md ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set1_hkdf_salt ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set1_hkdf_key ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_add1_hkdf_info ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_hkdf_mode ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set1_pbe_pass ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set1_scrypt_salt ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_scrypt_N ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_scrypt_r ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_scrypt_p ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_scrypt_maxmem_bytes ? 4_0_0 EXIST::FUNCTION: +MD2_options ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD2 +MD2_Init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD2 +MD2_Update ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD2 +MD2_Final ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD2 +MD2 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD2 +MD4_Init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD4 +MD4_Update ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD4 +MD4_Final ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD4 +MD4 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD4 +MD4_Transform ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD4 +MD5_Init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD5 +MD5_Update ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD5 +MD5_Final ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD5 +MD5 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD5 +MD5_Transform ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MD5 +MDC2_Init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MDC2 +MDC2_Update ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MDC2 +MDC2_Final ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MDC2 +MDC2 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,MDC2 +CRYPTO_cbc128_encrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_cbc128_decrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_ctr128_encrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_ctr128_encrypt_ctr32 ? 4_0_0 EXIST::FUNCTION: +CRYPTO_ofb128_encrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_cfb128_encrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_cfb128_8_encrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_cfb128_1_encrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_cts128_encrypt_block ? 4_0_0 EXIST::FUNCTION: +CRYPTO_cts128_encrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_cts128_decrypt_block ? 4_0_0 EXIST::FUNCTION: +CRYPTO_cts128_decrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_nistcts128_encrypt_block ? 4_0_0 EXIST::FUNCTION: +CRYPTO_nistcts128_encrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_nistcts128_decrypt_block ? 4_0_0 EXIST::FUNCTION: +CRYPTO_nistcts128_decrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_gcm128_new ? 4_0_0 EXIST::FUNCTION: +CRYPTO_gcm128_init ? 4_0_0 EXIST::FUNCTION: +CRYPTO_gcm128_setiv ? 4_0_0 EXIST::FUNCTION: +CRYPTO_gcm128_aad ? 4_0_0 EXIST::FUNCTION: +CRYPTO_gcm128_encrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_gcm128_decrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_gcm128_encrypt_ctr32 ? 4_0_0 EXIST::FUNCTION: +CRYPTO_gcm128_decrypt_ctr32 ? 4_0_0 EXIST::FUNCTION: +CRYPTO_gcm128_finish ? 4_0_0 EXIST::FUNCTION: +CRYPTO_gcm128_tag ? 4_0_0 EXIST::FUNCTION: +CRYPTO_gcm128_release ? 4_0_0 EXIST::FUNCTION: +CRYPTO_ccm128_init ? 4_0_0 EXIST::FUNCTION: +CRYPTO_ccm128_setiv ? 4_0_0 EXIST::FUNCTION: +CRYPTO_ccm128_aad ? 4_0_0 EXIST::FUNCTION: +CRYPTO_ccm128_encrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_ccm128_decrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_ccm128_encrypt_ccm64 ? 4_0_0 EXIST::FUNCTION: +CRYPTO_ccm128_decrypt_ccm64 ? 4_0_0 EXIST::FUNCTION: +CRYPTO_ccm128_tag ? 4_0_0 EXIST::FUNCTION: +CRYPTO_xts128_encrypt ? 4_0_0 EXIST::FUNCTION: +CRYPTO_128_wrap ? 4_0_0 EXIST::FUNCTION: +CRYPTO_128_unwrap ? 4_0_0 EXIST::FUNCTION: +CRYPTO_128_wrap_pad ? 4_0_0 EXIST::FUNCTION: +CRYPTO_128_unwrap_pad ? 4_0_0 EXIST::FUNCTION: +CRYPTO_ocb128_new ? 4_0_0 EXIST::FUNCTION:OCB +CRYPTO_ocb128_init ? 4_0_0 EXIST::FUNCTION:OCB +CRYPTO_ocb128_copy_ctx ? 4_0_0 EXIST::FUNCTION:OCB +CRYPTO_ocb128_setiv ? 4_0_0 EXIST::FUNCTION:OCB +CRYPTO_ocb128_aad ? 4_0_0 EXIST::FUNCTION:OCB +CRYPTO_ocb128_encrypt ? 4_0_0 EXIST::FUNCTION:OCB +CRYPTO_ocb128_decrypt ? 4_0_0 EXIST::FUNCTION:OCB +CRYPTO_ocb128_finish ? 4_0_0 EXIST::FUNCTION:OCB +CRYPTO_ocb128_tag ? 4_0_0 EXIST::FUNCTION:OCB +CRYPTO_ocb128_cleanup ? 4_0_0 EXIST::FUNCTION:OCB +OBJ_NAME_init ? 4_0_0 EXIST::FUNCTION: +OBJ_NAME_new_index ? 4_0_0 EXIST::FUNCTION: +OBJ_NAME_get ? 4_0_0 EXIST::FUNCTION: +OBJ_NAME_add ? 4_0_0 EXIST::FUNCTION: +OBJ_NAME_remove ? 4_0_0 EXIST::FUNCTION: +OBJ_NAME_cleanup ? 4_0_0 EXIST::FUNCTION: +OBJ_NAME_do_all ? 4_0_0 EXIST::FUNCTION: +OBJ_NAME_do_all_sorted ? 4_0_0 EXIST::FUNCTION: +OBJ_dup ? 4_0_0 EXIST::FUNCTION: +OBJ_nid2obj ? 4_0_0 EXIST::FUNCTION: +OBJ_nid2ln ? 4_0_0 EXIST::FUNCTION: +OBJ_nid2sn ? 4_0_0 EXIST::FUNCTION: +OBJ_obj2nid ? 4_0_0 EXIST::FUNCTION: +OBJ_txt2obj ? 4_0_0 EXIST::FUNCTION: +OBJ_obj2txt ? 4_0_0 EXIST::FUNCTION: +OBJ_txt2nid ? 4_0_0 EXIST::FUNCTION: +OBJ_ln2nid ? 4_0_0 EXIST::FUNCTION: +OBJ_sn2nid ? 4_0_0 EXIST::FUNCTION: +OBJ_cmp ? 4_0_0 EXIST::FUNCTION: +OBJ_bsearch_ ? 4_0_0 EXIST::FUNCTION: +OBJ_bsearch_ex_ ? 4_0_0 EXIST::FUNCTION: +OBJ_new_nid ? 4_0_0 EXIST::FUNCTION: +OBJ_add_object ? 4_0_0 EXIST::FUNCTION: +OBJ_create ? 4_0_0 EXIST::FUNCTION: +OBJ_create_objects ? 4_0_0 EXIST::FUNCTION: +OBJ_length ? 4_0_0 EXIST::FUNCTION: +OBJ_get0_data ? 4_0_0 EXIST::FUNCTION: +OBJ_find_sigid_algs ? 4_0_0 EXIST::FUNCTION: +OBJ_find_sigid_by_algs ? 4_0_0 EXIST::FUNCTION: +OBJ_add_sigid ? 4_0_0 EXIST::FUNCTION: +OBJ_sigid_free ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_new ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_to_param ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_free ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_int ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_uint ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_long ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_ulong ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_int32 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_uint32 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_int64 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_uint64 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_size_t ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_time_t ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_double ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_BN ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_BN_pad ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_utf8_string ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_utf8_ptr ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_octet_string ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_BLD_push_octet_ptr ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_locate ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_locate_const ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_int ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_uint ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_long ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_ulong ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_int32 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_uint32 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_int64 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_uint64 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_size_t ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_time_t ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_BN ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_double ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_utf8_string ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_utf8_ptr ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_octet_string ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_octet_ptr ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_construct_end ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_allocate_from_text ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_print_to_bio ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_int ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_uint ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_long ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_ulong ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_int32 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_uint32 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_int64 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_uint64 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_size_t ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_time_t ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_int ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_uint ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_long ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_ulong ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_int32 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_uint32 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_int64 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_uint64 ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_size_t ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_time_t ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_double ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_double ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_BN ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_BN ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_utf8_string ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_utf8_string ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_octet_string ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_octet_string ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_utf8_ptr ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_utf8_ptr ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_octet_ptr ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_octet_ptr ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_utf8_string_ptr ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_get_octet_string_ptr ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_modified ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_all_unmodified ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_dup ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_merge ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_free ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_set_octet_string_or_ptr ? 4_0_0 EXIST::FUNCTION: +PEM_get_EVP_CIPHER_INFO ? 4_0_0 EXIST::FUNCTION: +PEM_do_header ? 4_0_0 EXIST::FUNCTION: +PEM_read_bio ? 4_0_0 EXIST::FUNCTION: +PEM_read_bio_ex ? 4_0_0 EXIST::FUNCTION: +PEM_bytes_read_bio_secmem ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio ? 4_0_0 EXIST::FUNCTION: +PEM_bytes_read_bio ? 4_0_0 EXIST::FUNCTION: +PEM_ASN1_read_bio ? 4_0_0 EXIST::FUNCTION: +PEM_ASN1_write_bio ? 4_0_0 EXIST::FUNCTION: +PEM_ASN1_write_bio_ctx ? 4_0_0 EXIST::FUNCTION: +PEM_X509_INFO_read_bio ? 4_0_0 EXIST::FUNCTION: +PEM_X509_INFO_read_bio_ex ? 4_0_0 EXIST::FUNCTION: +PEM_X509_INFO_write_bio ? 4_0_0 EXIST::FUNCTION: +PEM_read ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_ASN1_read ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_ASN1_write ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_X509_INFO_read ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_X509_INFO_read_ex ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_SignInit ? 4_0_0 EXIST::FUNCTION: +PEM_SignUpdate ? 4_0_0 EXIST::FUNCTION: +PEM_SignFinal ? 4_0_0 EXIST::FUNCTION: +PEM_def_callback ? 4_0_0 EXIST::FUNCTION: +PEM_proc_type ? 4_0_0 EXIST::FUNCTION: +PEM_dek_info ? 4_0_0 EXIST::FUNCTION: +PEM_read_X509 ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_X509 ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_bio_X509 ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_X509 ? 4_0_0 EXIST::FUNCTION: +PEM_read_X509_AUX ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_X509_AUX ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_bio_X509_AUX ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_X509_AUX ? 4_0_0 EXIST::FUNCTION: +PEM_read_X509_REQ ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_X509_REQ ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_bio_X509_REQ ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_X509_REQ ? 4_0_0 EXIST::FUNCTION: +PEM_write_X509_REQ_NEW ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_bio_X509_REQ_NEW ? 4_0_0 EXIST::FUNCTION: +PEM_read_X509_CRL ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_X509_CRL ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_bio_X509_CRL ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_X509_CRL ? 4_0_0 EXIST::FUNCTION: +PEM_read_X509_PUBKEY ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_X509_PUBKEY ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_bio_X509_PUBKEY ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_X509_PUBKEY ? 4_0_0 EXIST::FUNCTION: +PEM_read_PKCS7 ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_PKCS7 ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_bio_PKCS7 ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_PKCS7 ? 4_0_0 EXIST::FUNCTION: +PEM_read_NETSCAPE_CERT_SEQUENCE ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_NETSCAPE_CERT_SEQUENCE ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_bio_NETSCAPE_CERT_SEQUENCE ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_NETSCAPE_CERT_SEQUENCE ? 4_0_0 EXIST::FUNCTION: +PEM_read_PKCS8 ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_PKCS8 ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_bio_PKCS8 ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_PKCS8 ? 4_0_0 EXIST::FUNCTION: +PEM_read_PKCS8_PRIV_KEY_INFO ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_PKCS8_PRIV_KEY_INFO ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_bio_PKCS8_PRIV_KEY_INFO ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_PKCS8_PRIV_KEY_INFO ? 4_0_0 EXIST::FUNCTION: +PEM_read_RSAPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO +PEM_write_RSAPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO +PEM_read_bio_RSAPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +PEM_write_bio_RSAPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +PEM_read_RSAPublicKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO +PEM_write_RSAPublicKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO +PEM_read_bio_RSAPublicKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +PEM_write_bio_RSAPublicKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +PEM_read_RSA_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO +PEM_write_RSA_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO +PEM_read_bio_RSA_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +PEM_write_bio_RSA_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +PEM_read_DSAPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO +PEM_write_DSAPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO +PEM_read_bio_DSAPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +PEM_write_bio_DSAPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +PEM_read_DSA_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO +PEM_write_DSA_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO +PEM_read_bio_DSA_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +PEM_write_bio_DSA_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +PEM_read_DSAparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO +PEM_write_DSAparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO +PEM_read_bio_DSAparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +PEM_write_bio_DSAparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +PEM_read_ECPKParameters ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO +PEM_write_ECPKParameters ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO +PEM_read_bio_ECPKParameters ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +PEM_write_bio_ECPKParameters ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +PEM_read_ECPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO +PEM_write_ECPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO +PEM_read_bio_ECPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +PEM_write_bio_ECPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +PEM_read_EC_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO +PEM_write_EC_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO +PEM_read_bio_EC_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +PEM_write_bio_EC_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +PEM_read_DHparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH,STDIO +PEM_write_DHparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH,STDIO +PEM_read_bio_DHparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +PEM_write_bio_DHparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +PEM_write_DHxparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH,STDIO +PEM_write_bio_DHxparams ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +PEM_read_PrivateKey ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_PrivateKey ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_PrivateKey_ex ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_PrivateKey_ex ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_bio_PrivateKey ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_PrivateKey ? 4_0_0 EXIST::FUNCTION: +PEM_read_bio_PrivateKey_ex ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_PrivateKey_ex ? 4_0_0 EXIST::FUNCTION: +PEM_read_PUBKEY ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_PUBKEY ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_PUBKEY_ex ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_PUBKEY_ex ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_bio_PUBKEY ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_PUBKEY ? 4_0_0 EXIST::FUNCTION: +PEM_read_bio_PUBKEY_ex ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_PUBKEY_ex ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_PrivateKey_traditional ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_PKCS8PrivateKey_nid ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_PKCS8PrivateKey ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS8PrivateKey_bio ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS8PrivateKey_nid_bio ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS8PrivateKey_bio ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS8PrivateKey_fp ? 4_0_0 EXIST::FUNCTION:STDIO +i2d_PKCS8PrivateKey_nid_fp ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_PKCS8PrivateKey_nid ? 4_0_0 EXIST::FUNCTION:STDIO +d2i_PKCS8PrivateKey_fp ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_PKCS8PrivateKey ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_bio_Parameters_ex ? 4_0_0 EXIST::FUNCTION: +PEM_read_bio_Parameters ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_Parameters ? 4_0_0 EXIST::FUNCTION: +b2i_PrivateKey ? 4_0_0 EXIST::FUNCTION: +b2i_PublicKey ? 4_0_0 EXIST::FUNCTION: +b2i_PrivateKey_bio ? 4_0_0 EXIST::FUNCTION: +b2i_PublicKey_bio ? 4_0_0 EXIST::FUNCTION: +i2b_PrivateKey_bio ? 4_0_0 EXIST::FUNCTION: +i2b_PublicKey_bio ? 4_0_0 EXIST::FUNCTION: +b2i_PVK_bio ? 4_0_0 EXIST::FUNCTION: +b2i_PVK_bio_ex ? 4_0_0 EXIST::FUNCTION: +i2b_PVK_bio ? 4_0_0 EXIST::FUNCTION: +i2b_PVK_bio_ex ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_set_default_search_path ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_get0_default_search_path ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_load ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_load_ex ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_try_load ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_try_load_ex ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_unload ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_available ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_do_all ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_gettable_params ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_get_params ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_self_test ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_get_capabilities ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_add_conf_parameter ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_get_conf_parameters ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_conf_get_bool ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_query_operation ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_unquery_operation ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_get0_provider_ctx ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_get0_dispatch ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_add_builtin ? 4_0_0 EXIST::FUNCTION: +OSSL_PROVIDER_get0_name ? 4_0_0 EXIST::FUNCTION: +RAND_set_rand_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RAND_get_rand_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RAND_OpenSSL ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RAND_bytes ? 4_0_0 EXIST::FUNCTION: +RAND_priv_bytes ? 4_0_0 EXIST::FUNCTION: +RAND_priv_bytes_ex ? 4_0_0 EXIST::FUNCTION: +RAND_bytes_ex ? 4_0_0 EXIST::FUNCTION: +RAND_pseudo_bytes ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0 +RAND_get0_primary ? 4_0_0 EXIST::FUNCTION: +RAND_get0_public ? 4_0_0 EXIST::FUNCTION: +RAND_get0_private ? 4_0_0 EXIST::FUNCTION: +RAND_set0_public ? 4_0_0 EXIST::FUNCTION: +RAND_set0_private ? 4_0_0 EXIST::FUNCTION: +RAND_set_DRBG_type ? 4_0_0 EXIST::FUNCTION: +RAND_set_seed_source_type ? 4_0_0 EXIST::FUNCTION: +RAND_seed ? 4_0_0 EXIST::FUNCTION: +RAND_keep_random_devices_open ? 4_0_0 EXIST::FUNCTION: +RAND_add ? 4_0_0 EXIST::FUNCTION: +RAND_load_file ? 4_0_0 EXIST::FUNCTION: +RAND_write_file ? 4_0_0 EXIST::FUNCTION: +RAND_file_name ? 4_0_0 EXIST::FUNCTION: +RAND_status ? 4_0_0 EXIST::FUNCTION: +RAND_query_egd_bytes ? 4_0_0 EXIST::FUNCTION:EGD +RAND_egd ? 4_0_0 EXIST::FUNCTION:EGD +RAND_egd_bytes ? 4_0_0 EXIST::FUNCTION:EGD +RAND_poll ? 4_0_0 EXIST::FUNCTION: +RAND_screen ? 4_0_0 EXIST:_WIN32:FUNCTION:DEPRECATEDIN_1_1_0 +RAND_event ? 4_0_0 EXIST:_WIN32:FUNCTION:DEPRECATEDIN_1_1_0 +RAND_set1_random_provider ? 4_0_0 EXIST::FUNCTION: +RC2_set_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC2 +RC2_ecb_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC2 +RC2_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC2 +RC2_decrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC2 +RC2_cbc_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC2 +RC2_cfb64_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC2 +RC2_ofb64_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC2 +RC4_options ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC4 +RC4_set_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC4 +RC4 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC4 +RC5_32_set_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC5 +RC5_32_ecb_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC5 +RC5_32_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC5 +RC5_32_decrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC5 +RC5_32_cbc_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC5 +RC5_32_cfb64_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC5 +RC5_32_ofb64_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RC5 +RIPEMD160_Init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RMD160 +RIPEMD160_Update ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RMD160 +RIPEMD160_Final ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RMD160 +RIPEMD160 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RMD160 +RIPEMD160_Transform ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,RMD160 +EVP_PKEY_CTX_set_rsa_padding ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_rsa_padding ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_rsa_pss_saltlen ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_rsa_pss_saltlen ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_rsa_keygen_bits ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set1_rsa_keygen_pubexp ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_rsa_keygen_primes ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_rsa_pss_keygen_saltlen ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_rsa_keygen_pubexp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +EVP_PKEY_CTX_set_rsa_mgf1_md ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_rsa_mgf1_md_name ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_rsa_mgf1_md ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_rsa_mgf1_md_name ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_rsa_pss_keygen_mgf1_md_name ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_rsa_pss_keygen_md ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_rsa_pss_keygen_md_name ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_rsa_oaep_md ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set_rsa_oaep_md_name ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_rsa_oaep_md ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get_rsa_oaep_md_name ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_set0_rsa_oaep_label ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_CTX_get0_rsa_oaep_label ? 4_0_0 EXIST::FUNCTION: +RSA_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_new_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_bits ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_size ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_security_bits ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_set0_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_set0_factors ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_set0_crt_params ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_set0_multi_prime_params ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get0_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get0_factors ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get_multi_prime_extra_count ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get0_multi_prime_factors ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get0_crt_params ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get0_multi_prime_crt_params ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get0_n ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get0_e ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get0_d ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get0_p ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get0_q ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get0_dmp1 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get0_dmq1 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get0_iqmp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get0_pss_params ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_clear_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_test_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_set_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get_version ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_generate_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_0_9_8 +RSA_generate_key_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_generate_multi_prime_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_X931_derive_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_X931_generate_key_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_check_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_check_key_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_public_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_private_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_public_decrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_private_decrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_up_ref ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_set_default_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get_default_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_null_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_set_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_PKCS1_OpenSSL ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +d2i_RSAPublicKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +i2d_RSAPublicKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSAPublicKey_it ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +d2i_RSAPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +i2d_RSAPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSAPrivateKey_it ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_pkey_ctx_ctrl ? 4_0_0 EXIST::FUNCTION: +d2i_RSA_PSS_PARAMS ? 4_0_0 EXIST::FUNCTION: +i2d_RSA_PSS_PARAMS ? 4_0_0 EXIST::FUNCTION: +RSA_PSS_PARAMS_free ? 4_0_0 EXIST::FUNCTION: +RSA_PSS_PARAMS_new ? 4_0_0 EXIST::FUNCTION: +RSA_PSS_PARAMS_it ? 4_0_0 EXIST::FUNCTION: +RSA_PSS_PARAMS_dup ? 4_0_0 EXIST::FUNCTION: +d2i_RSA_OAEP_PARAMS ? 4_0_0 EXIST::FUNCTION: +i2d_RSA_OAEP_PARAMS ? 4_0_0 EXIST::FUNCTION: +RSA_OAEP_PARAMS_free ? 4_0_0 EXIST::FUNCTION: +RSA_OAEP_PARAMS_new ? 4_0_0 EXIST::FUNCTION: +RSA_OAEP_PARAMS_it ? 4_0_0 EXIST::FUNCTION: +RSA_print_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO +RSA_print ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_sign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_verify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_sign_ASN1_OCTET_STRING ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_verify_ASN1_OCTET_STRING ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_blinding_on ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_blinding_off ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_setup_blinding ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_padding_add_PKCS1_type_1 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_padding_check_PKCS1_type_1 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_padding_add_PKCS1_type_2 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_padding_check_PKCS1_type_2 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +PKCS1_MGF1 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_padding_add_PKCS1_OAEP ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_padding_check_PKCS1_OAEP ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_padding_add_PKCS1_OAEP_mgf1 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_padding_check_PKCS1_OAEP_mgf1 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_padding_add_none ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_padding_check_none ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_padding_add_X931 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_padding_check_X931 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_X931_hash_id ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_verify_PKCS1_PSS ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_padding_add_PKCS1_PSS ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_verify_PKCS1_PSS_mgf1 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_padding_add_PKCS1_PSS_mgf1 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_set_ex_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_get_ex_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSAPublicKey_dup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSAPrivateKey_dup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_dup ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_get0_name ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_set1_name ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_get_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_set_flags ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_get0_app_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_set0_app_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_get_pub_enc ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_set_pub_enc ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_get_pub_dec ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_set_pub_dec ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_get_priv_enc ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_set_priv_enc ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_get_priv_dec ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_set_priv_dec ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_get_mod_exp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_set_mod_exp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_get_bn_mod_exp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_set_bn_mod_exp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_get_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_set_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_get_finish ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_set_finish ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_get_sign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_set_sign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_get_verify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_set_verify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_get_keygen ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_set_keygen ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_get_multi_prime_keygen ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +RSA_meth_set_multi_prime_keygen ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SEED_set_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SEED +SEED_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SEED +SEED_decrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SEED +SEED_ecb_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SEED +SEED_cbc_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SEED +SEED_cfb128_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SEED +SEED_ofb128_encrypt ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SEED +OSSL_SELF_TEST_set_callback ? 4_0_0 EXIST::FUNCTION: +OSSL_SELF_TEST_get_callback ? 4_0_0 EXIST::FUNCTION: +OSSL_SELF_TEST_new ? 4_0_0 EXIST::FUNCTION: +OSSL_SELF_TEST_free ? 4_0_0 EXIST::FUNCTION: +OSSL_SELF_TEST_onbegin ? 4_0_0 EXIST::FUNCTION: +OSSL_SELF_TEST_oncorrupt_byte ? 4_0_0 EXIST::FUNCTION: +OSSL_SELF_TEST_onend ? 4_0_0 EXIST::FUNCTION: +SHA1_Init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA1_Update ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA1_Final ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA1_Transform ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA1 ? 4_0_0 EXIST::FUNCTION: +SHA224_Init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA224_Update ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA224_Final ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA256_Init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA256_Update ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA256_Final ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA256_Transform ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA224 ? 4_0_0 EXIST::FUNCTION: +SHA256 ? 4_0_0 EXIST::FUNCTION: +SHA384_Init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA384_Update ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA384_Final ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA512_Init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA512_Update ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA512_Final ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA512_Transform ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SHA384 ? 4_0_0 EXIST::FUNCTION: +SHA512 ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_num ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_value ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_set ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_new ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_new_null ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_new_reserve ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_set_thunks ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_reserve ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_free ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_pop_free ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_deep_copy ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_insert ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_delete ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_delete_ptr ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_find ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_find_ex ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_find_all ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_push ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_unshift ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_shift ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_pop ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_zero ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_set_cmp_func ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_dup ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_sort ? 4_0_0 EXIST::FUNCTION: +OPENSSL_sk_is_sorted ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_open ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_open_ex ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_ctrl ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_vctrl ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_load ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_delete ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_eof ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_error ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_close ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_attach ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_new ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_new_NAME ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_set0_NAME_description ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_new_PARAMS ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_new_PUBKEY ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_new_PKEY ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_new_CERT ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_new_CRL ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get_type ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get0_data ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get0_NAME ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get1_NAME ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get0_NAME_description ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get1_NAME_description ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get0_PARAMS ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get1_PARAMS ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get0_PUBKEY ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get1_PUBKEY ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get0_PKEY ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get1_PKEY ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get0_CERT ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get1_CERT ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get0_CRL ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get1_CRL ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_type_string ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_free ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_supports_search ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_SEARCH_by_name ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_SEARCH_by_issuer_serial ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_SEARCH_by_key_fingerprint ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_SEARCH_by_alias ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_SEARCH_free ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_SEARCH_get_type ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_SEARCH_get0_name ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_SEARCH_get0_serial ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_SEARCH_get0_bytes ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_SEARCH_get0_string ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_SEARCH_get0_digest ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_expect ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_find ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_LOADER_fetch ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_LOADER_up_ref ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_LOADER_free ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_LOADER_get0_provider ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_LOADER_get0_properties ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_LOADER_get0_description ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_LOADER_is_a ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_LOADER_do_all_provided ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_LOADER_names_do_all ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_LOADER_settable_ctx_params ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_LOADER_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_LOADER_set_open ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_LOADER_set_open_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_LOADER_set_attach ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_LOADER_set_ctrl ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_LOADER_set_expect ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_LOADER_set_find ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_LOADER_set_load ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_LOADER_set_eof ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_LOADER_set_error ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_LOADER_set_close ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_LOADER_get0_scheme ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_register_loader ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_unregister_loader ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_STORE_do_all_loaders ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +OSSL_get_thread_support_flags ? 4_0_0 EXIST::FUNCTION: +OSSL_set_max_threads ? 4_0_0 EXIST::FUNCTION: +OSSL_get_max_threads ? 4_0_0 EXIST::FUNCTION: +OSSL_trace_get_category_num ? 4_0_0 EXIST::FUNCTION: +OSSL_trace_get_category_name ? 4_0_0 EXIST::FUNCTION: +OSSL_trace_set_channel ? 4_0_0 EXIST::FUNCTION: +OSSL_trace_set_prefix ? 4_0_0 EXIST::FUNCTION: +OSSL_trace_set_suffix ? 4_0_0 EXIST::FUNCTION: +OSSL_trace_set_callback ? 4_0_0 EXIST::FUNCTION: +OSSL_trace_enabled ? 4_0_0 EXIST::FUNCTION: +OSSL_trace_begin ? 4_0_0 EXIST::FUNCTION: +OSSL_trace_end ? 4_0_0 EXIST::FUNCTION: +OSSL_trace_string ? 4_0_0 EXIST::FUNCTION: +TS_REQ_free ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_new ? 4_0_0 EXIST::FUNCTION:TS +d2i_TS_REQ ? 4_0_0 EXIST::FUNCTION:TS +i2d_TS_REQ ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_dup ? 4_0_0 EXIST::FUNCTION:TS +d2i_TS_REQ_fp ? 4_0_0 EXIST::FUNCTION:STDIO,TS +i2d_TS_REQ_fp ? 4_0_0 EXIST::FUNCTION:STDIO,TS +d2i_TS_REQ_bio ? 4_0_0 EXIST::FUNCTION:TS +i2d_TS_REQ_bio ? 4_0_0 EXIST::FUNCTION:TS +TS_MSG_IMPRINT_free ? 4_0_0 EXIST::FUNCTION:TS +TS_MSG_IMPRINT_new ? 4_0_0 EXIST::FUNCTION:TS +d2i_TS_MSG_IMPRINT ? 4_0_0 EXIST::FUNCTION:TS +i2d_TS_MSG_IMPRINT ? 4_0_0 EXIST::FUNCTION:TS +TS_MSG_IMPRINT_dup ? 4_0_0 EXIST::FUNCTION:TS +d2i_TS_MSG_IMPRINT_fp ? 4_0_0 EXIST::FUNCTION:STDIO,TS +i2d_TS_MSG_IMPRINT_fp ? 4_0_0 EXIST::FUNCTION:STDIO,TS +d2i_TS_MSG_IMPRINT_bio ? 4_0_0 EXIST::FUNCTION:TS +i2d_TS_MSG_IMPRINT_bio ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_free ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_new ? 4_0_0 EXIST::FUNCTION:TS +d2i_TS_RESP ? 4_0_0 EXIST::FUNCTION:TS +i2d_TS_RESP ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_dup ? 4_0_0 EXIST::FUNCTION:TS +d2i_TS_RESP_fp ? 4_0_0 EXIST::FUNCTION:STDIO,TS +i2d_TS_RESP_fp ? 4_0_0 EXIST::FUNCTION:STDIO,TS +d2i_TS_RESP_bio ? 4_0_0 EXIST::FUNCTION:TS +i2d_TS_RESP_bio ? 4_0_0 EXIST::FUNCTION:TS +TS_STATUS_INFO_free ? 4_0_0 EXIST::FUNCTION:TS +TS_STATUS_INFO_new ? 4_0_0 EXIST::FUNCTION:TS +d2i_TS_STATUS_INFO ? 4_0_0 EXIST::FUNCTION:TS +i2d_TS_STATUS_INFO ? 4_0_0 EXIST::FUNCTION:TS +TS_STATUS_INFO_dup ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_free ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_new ? 4_0_0 EXIST::FUNCTION:TS +d2i_TS_TST_INFO ? 4_0_0 EXIST::FUNCTION:TS +i2d_TS_TST_INFO ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_dup ? 4_0_0 EXIST::FUNCTION:TS +PKCS7_to_TS_TST_INFO ? 4_0_0 EXIST::FUNCTION:TS +d2i_TS_TST_INFO_fp ? 4_0_0 EXIST::FUNCTION:STDIO,TS +i2d_TS_TST_INFO_fp ? 4_0_0 EXIST::FUNCTION:STDIO,TS +d2i_TS_TST_INFO_bio ? 4_0_0 EXIST::FUNCTION:TS +i2d_TS_TST_INFO_bio ? 4_0_0 EXIST::FUNCTION:TS +TS_ACCURACY_free ? 4_0_0 EXIST::FUNCTION:TS +TS_ACCURACY_new ? 4_0_0 EXIST::FUNCTION:TS +d2i_TS_ACCURACY ? 4_0_0 EXIST::FUNCTION:TS +i2d_TS_ACCURACY ? 4_0_0 EXIST::FUNCTION:TS +TS_ACCURACY_dup ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_set_version ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_get_version ? 4_0_0 EXIST::FUNCTION:TS +TS_STATUS_INFO_set_status ? 4_0_0 EXIST::FUNCTION:TS +TS_STATUS_INFO_get0_status ? 4_0_0 EXIST::FUNCTION:TS +TS_STATUS_INFO_get0_text ? 4_0_0 EXIST::FUNCTION:TS +TS_STATUS_INFO_get0_failure_info ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_set_msg_imprint ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_get_msg_imprint ? 4_0_0 EXIST::FUNCTION:TS +TS_MSG_IMPRINT_set_algo ? 4_0_0 EXIST::FUNCTION:TS +TS_MSG_IMPRINT_get_algo ? 4_0_0 EXIST::FUNCTION:TS +TS_MSG_IMPRINT_set_msg ? 4_0_0 EXIST::FUNCTION:TS +TS_MSG_IMPRINT_get_msg ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_set_policy_id ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_get_policy_id ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_set_nonce ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_get_nonce ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_set_cert_req ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_get_cert_req ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_get_exts ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_ext_free ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_get_ext_count ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_get_ext_by_NID ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_get_ext_by_OBJ ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_get_ext_by_critical ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_get_ext ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_delete_ext ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_add_ext ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_get_ext_d2i ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_print_bio ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_set_status_info ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_get_status_info ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_set_tst_info ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_get_token ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_get_tst_info ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_set_version ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_version ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_set_policy_id ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_policy_id ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_set_msg_imprint ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_msg_imprint ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_set_serial ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_serial ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_set_time ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_time ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_set_accuracy ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_accuracy ? 4_0_0 EXIST::FUNCTION:TS +TS_ACCURACY_set_seconds ? 4_0_0 EXIST::FUNCTION:TS +TS_ACCURACY_get_seconds ? 4_0_0 EXIST::FUNCTION:TS +TS_ACCURACY_set_millis ? 4_0_0 EXIST::FUNCTION:TS +TS_ACCURACY_get_millis ? 4_0_0 EXIST::FUNCTION:TS +TS_ACCURACY_set_micros ? 4_0_0 EXIST::FUNCTION:TS +TS_ACCURACY_get_micros ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_set_ordering ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_ordering ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_set_nonce ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_nonce ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_set_tsa ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_tsa ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_exts ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_ext_free ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_ext_count ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_ext_by_NID ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_ext_by_OBJ ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_ext_by_critical ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_ext ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_delete_ext ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_add_ext ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_get_ext_d2i ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_new ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_new_ex ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_free ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_set_signer_cert ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_set_signer_key ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_set_signer_digest ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_set_ess_cert_id_digest ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_set_def_policy ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_set_certs ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_add_policy ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_add_md ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_set_accuracy ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_set_clock_precision_digits ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_add_flags ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_set_serial_cb ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_set_time_cb ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_set_extension_cb ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_set_status_info ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_set_status_info_cond ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_add_failure_info ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_get_request ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_CTX_get_tst_info ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_create_response ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_verify_signature ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_verify_response ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_verify_token ? 4_0_0 EXIST::FUNCTION:TS +TS_VERIFY_CTX_new ? 4_0_0 EXIST::FUNCTION:TS +TS_VERIFY_CTX_init ? 4_0_0 EXIST::FUNCTION:TS +TS_VERIFY_CTX_free ? 4_0_0 EXIST::FUNCTION:TS +TS_VERIFY_CTX_cleanup ? 4_0_0 EXIST::FUNCTION:TS +TS_VERIFY_CTX_set_flags ? 4_0_0 EXIST::FUNCTION:TS +TS_VERIFY_CTX_add_flags ? 4_0_0 EXIST::FUNCTION:TS +TS_VERIFY_CTX_set_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_4,TS +TS_VERIFY_CTX_set0_data ? 4_0_0 EXIST::FUNCTION:TS +TS_VERIFY_CTX_set_imprint ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_4,TS +TS_VERIFY_CTX_set0_imprint ? 4_0_0 EXIST::FUNCTION:TS +TS_VERIFY_CTX_set_store ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_4,TS +TS_VERIFY_CTX_set0_store ? 4_0_0 EXIST::FUNCTION:TS +TS_VERIFY_CTX_set_certs ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_4,TS +TS_VERIFY_CTX_set0_certs ? 4_0_0 EXIST::FUNCTION:TS +TS_REQ_to_TS_VERIFY_CTX ? 4_0_0 EXIST::FUNCTION:TS +TS_RESP_print_bio ? 4_0_0 EXIST::FUNCTION:TS +TS_STATUS_INFO_print_bio ? 4_0_0 EXIST::FUNCTION:TS +TS_TST_INFO_print_bio ? 4_0_0 EXIST::FUNCTION:TS +TS_ASN1_INTEGER_print_bio ? 4_0_0 EXIST::FUNCTION:TS +TS_OBJ_print_bio ? 4_0_0 EXIST::FUNCTION:TS +TS_ext_print_bio ? 4_0_0 EXIST::FUNCTION:TS +TS_X509_ALGOR_print_bio ? 4_0_0 EXIST::FUNCTION:TS +TS_MSG_IMPRINT_print_bio ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_load_cert ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_load_certs ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_load_key ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_get_tsa_section ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_set_serial ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_set_signer_cert ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_set_certs ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_set_signer_key ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_set_signer_digest ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_set_def_policy ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_set_policies ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_set_digests ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_set_accuracy ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_set_clock_precision_digits ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_set_ordering ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_set_tsa_name ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_set_ess_cert_id_chain ? 4_0_0 EXIST::FUNCTION:TS +TS_CONF_set_ess_cert_id_digest ? 4_0_0 EXIST::FUNCTION:TS +TXT_DB_read ? 4_0_0 EXIST::FUNCTION: +TXT_DB_write ? 4_0_0 EXIST::FUNCTION: +TXT_DB_create_index ? 4_0_0 EXIST::FUNCTION: +TXT_DB_free ? 4_0_0 EXIST::FUNCTION: +TXT_DB_get_by_index ? 4_0_0 EXIST::FUNCTION: +TXT_DB_insert ? 4_0_0 EXIST::FUNCTION: +WHIRLPOOL_Init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,WHIRLPOOL +WHIRLPOOL_Update ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,WHIRLPOOL +WHIRLPOOL_BitUpdate ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,WHIRLPOOL +WHIRLPOOL_Final ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,WHIRLPOOL +WHIRLPOOL ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,WHIRLPOOL +d2i_ASN1_SEQUENCE_ANY ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_SEQUENCE_ANY ? 4_0_0 EXIST::FUNCTION: +ASN1_SEQUENCE_ANY_it ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_SET_ANY ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_SET_ANY ? 4_0_0 EXIST::FUNCTION: +ASN1_SET_ANY_it ? 4_0_0 EXIST::FUNCTION: +ASN1_TYPE_free ? 4_0_0 EXIST::FUNCTION: +ASN1_TYPE_new ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_TYPE ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_TYPE ? 4_0_0 EXIST::FUNCTION: +ASN1_ANY_it ? 4_0_0 EXIST::FUNCTION: +ASN1_TYPE_get ? 4_0_0 EXIST::FUNCTION: +ASN1_TYPE_set ? 4_0_0 EXIST::FUNCTION: +ASN1_TYPE_set1 ? 4_0_0 EXIST::FUNCTION: +ASN1_TYPE_cmp ? 4_0_0 EXIST::FUNCTION: +ASN1_TYPE_pack_sequence ? 4_0_0 EXIST::FUNCTION: +ASN1_TYPE_unpack_sequence ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_OBJECT ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_OBJECT ? 4_0_0 EXIST::FUNCTION: +ASN1_OBJECT_free ? 4_0_0 EXIST::FUNCTION: +ASN1_OBJECT_new ? 4_0_0 EXIST::FUNCTION: +ASN1_OBJECT_it ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_new ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_free ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_clear_free ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_copy ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_dup ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_type_new ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_cmp ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_set ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_set0 ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_length ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_length_set ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ASN1_STRING_type ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_get0_data ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_BIT_STRING ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_BIT_STRING ? 4_0_0 EXIST::FUNCTION: +ASN1_BIT_STRING_free ? 4_0_0 EXIST::FUNCTION: +ASN1_BIT_STRING_new ? 4_0_0 EXIST::FUNCTION: +ASN1_BIT_STRING_it ? 4_0_0 EXIST::FUNCTION: +ASN1_BIT_STRING_set ? 4_0_0 EXIST::FUNCTION: +ASN1_BIT_STRING_set_bit ? 4_0_0 EXIST::FUNCTION: +ASN1_BIT_STRING_get_bit ? 4_0_0 EXIST::FUNCTION: +ASN1_BIT_STRING_check ? 4_0_0 EXIST::FUNCTION: +ASN1_BIT_STRING_name_print ? 4_0_0 EXIST::FUNCTION: +ASN1_BIT_STRING_num_asc ? 4_0_0 EXIST::FUNCTION: +ASN1_BIT_STRING_set_asc ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_INTEGER ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_INTEGER ? 4_0_0 EXIST::FUNCTION: +ASN1_INTEGER_free ? 4_0_0 EXIST::FUNCTION: +ASN1_INTEGER_new ? 4_0_0 EXIST::FUNCTION: +ASN1_INTEGER_it ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_UINTEGER ? 4_0_0 EXIST::FUNCTION: +ASN1_INTEGER_dup ? 4_0_0 EXIST::FUNCTION: +ASN1_INTEGER_cmp ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_ENUMERATED ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_ENUMERATED ? 4_0_0 EXIST::FUNCTION: +ASN1_ENUMERATED_free ? 4_0_0 EXIST::FUNCTION: +ASN1_ENUMERATED_new ? 4_0_0 EXIST::FUNCTION: +ASN1_ENUMERATED_it ? 4_0_0 EXIST::FUNCTION: +ASN1_UTCTIME_check ? 4_0_0 EXIST::FUNCTION: +ASN1_UTCTIME_set ? 4_0_0 EXIST::FUNCTION: +ASN1_UTCTIME_adj ? 4_0_0 EXIST::FUNCTION: +ASN1_UTCTIME_set_string ? 4_0_0 EXIST::FUNCTION: +ASN1_UTCTIME_cmp_time_t ? 4_0_0 EXIST::FUNCTION: +ASN1_GENERALIZEDTIME_check ? 4_0_0 EXIST::FUNCTION: +ASN1_GENERALIZEDTIME_set ? 4_0_0 EXIST::FUNCTION: +ASN1_GENERALIZEDTIME_adj ? 4_0_0 EXIST::FUNCTION: +ASN1_GENERALIZEDTIME_set_string ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_diff ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_OCTET_STRING ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_OCTET_STRING ? 4_0_0 EXIST::FUNCTION: +ASN1_OCTET_STRING_free ? 4_0_0 EXIST::FUNCTION: +ASN1_OCTET_STRING_new ? 4_0_0 EXIST::FUNCTION: +ASN1_OCTET_STRING_it ? 4_0_0 EXIST::FUNCTION: +ASN1_OCTET_STRING_dup ? 4_0_0 EXIST::FUNCTION: +ASN1_OCTET_STRING_cmp ? 4_0_0 EXIST::FUNCTION: +ASN1_OCTET_STRING_set ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_VISIBLESTRING ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_VISIBLESTRING ? 4_0_0 EXIST::FUNCTION: +ASN1_VISIBLESTRING_free ? 4_0_0 EXIST::FUNCTION: +ASN1_VISIBLESTRING_new ? 4_0_0 EXIST::FUNCTION: +ASN1_VISIBLESTRING_it ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_UNIVERSALSTRING ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_UNIVERSALSTRING ? 4_0_0 EXIST::FUNCTION: +ASN1_UNIVERSALSTRING_free ? 4_0_0 EXIST::FUNCTION: +ASN1_UNIVERSALSTRING_new ? 4_0_0 EXIST::FUNCTION: +ASN1_UNIVERSALSTRING_it ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_UTF8STRING ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_UTF8STRING ? 4_0_0 EXIST::FUNCTION: +ASN1_UTF8STRING_free ? 4_0_0 EXIST::FUNCTION: +ASN1_UTF8STRING_new ? 4_0_0 EXIST::FUNCTION: +ASN1_UTF8STRING_it ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_NULL ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_NULL ? 4_0_0 EXIST::FUNCTION: +ASN1_NULL_free ? 4_0_0 EXIST::FUNCTION: +ASN1_NULL_new ? 4_0_0 EXIST::FUNCTION: +ASN1_NULL_it ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_BMPSTRING ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_BMPSTRING ? 4_0_0 EXIST::FUNCTION: +ASN1_BMPSTRING_free ? 4_0_0 EXIST::FUNCTION: +ASN1_BMPSTRING_new ? 4_0_0 EXIST::FUNCTION: +ASN1_BMPSTRING_it ? 4_0_0 EXIST::FUNCTION: +UTF8_getc ? 4_0_0 EXIST::FUNCTION: +UTF8_putc ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_PRINTABLE ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_PRINTABLE ? 4_0_0 EXIST::FUNCTION: +ASN1_PRINTABLE_free ? 4_0_0 EXIST::FUNCTION: +ASN1_PRINTABLE_new ? 4_0_0 EXIST::FUNCTION: +ASN1_PRINTABLE_it ? 4_0_0 EXIST::FUNCTION: +d2i_DIRECTORYSTRING ? 4_0_0 EXIST::FUNCTION: +i2d_DIRECTORYSTRING ? 4_0_0 EXIST::FUNCTION: +DIRECTORYSTRING_free ? 4_0_0 EXIST::FUNCTION: +DIRECTORYSTRING_new ? 4_0_0 EXIST::FUNCTION: +DIRECTORYSTRING_it ? 4_0_0 EXIST::FUNCTION: +d2i_DISPLAYTEXT ? 4_0_0 EXIST::FUNCTION: +i2d_DISPLAYTEXT ? 4_0_0 EXIST::FUNCTION: +DISPLAYTEXT_free ? 4_0_0 EXIST::FUNCTION: +DISPLAYTEXT_new ? 4_0_0 EXIST::FUNCTION: +DISPLAYTEXT_it ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_PRINTABLESTRING ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_PRINTABLESTRING ? 4_0_0 EXIST::FUNCTION: +ASN1_PRINTABLESTRING_free ? 4_0_0 EXIST::FUNCTION: +ASN1_PRINTABLESTRING_new ? 4_0_0 EXIST::FUNCTION: +ASN1_PRINTABLESTRING_it ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_T61STRING ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_T61STRING ? 4_0_0 EXIST::FUNCTION: +ASN1_T61STRING_free ? 4_0_0 EXIST::FUNCTION: +ASN1_T61STRING_new ? 4_0_0 EXIST::FUNCTION: +ASN1_T61STRING_it ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_IA5STRING ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_IA5STRING ? 4_0_0 EXIST::FUNCTION: +ASN1_IA5STRING_free ? 4_0_0 EXIST::FUNCTION: +ASN1_IA5STRING_new ? 4_0_0 EXIST::FUNCTION: +ASN1_IA5STRING_it ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_GENERALSTRING ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_GENERALSTRING ? 4_0_0 EXIST::FUNCTION: +ASN1_GENERALSTRING_free ? 4_0_0 EXIST::FUNCTION: +ASN1_GENERALSTRING_new ? 4_0_0 EXIST::FUNCTION: +ASN1_GENERALSTRING_it ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_UTCTIME ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_UTCTIME ? 4_0_0 EXIST::FUNCTION: +ASN1_UTCTIME_free ? 4_0_0 EXIST::FUNCTION: +ASN1_UTCTIME_new ? 4_0_0 EXIST::FUNCTION: +ASN1_UTCTIME_it ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_GENERALIZEDTIME ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_GENERALIZEDTIME ? 4_0_0 EXIST::FUNCTION: +ASN1_GENERALIZEDTIME_free ? 4_0_0 EXIST::FUNCTION: +ASN1_GENERALIZEDTIME_new ? 4_0_0 EXIST::FUNCTION: +ASN1_GENERALIZEDTIME_it ? 4_0_0 EXIST::FUNCTION: +d2i_ASN1_TIME ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_TIME ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_free ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_new ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_it ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_dup ? 4_0_0 EXIST::FUNCTION: +ASN1_UTCTIME_dup ? 4_0_0 EXIST::FUNCTION: +ASN1_GENERALIZEDTIME_dup ? 4_0_0 EXIST::FUNCTION: +ASN1_OCTET_STRING_NDEF_it ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_set ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_adj ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_check ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_to_generalizedtime ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_set_string ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_set_string_X509 ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_to_tm ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_normalize ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_cmp_time_t ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_compare ? 4_0_0 EXIST::FUNCTION: +i2a_ASN1_INTEGER ? 4_0_0 EXIST::FUNCTION: +a2i_ASN1_INTEGER ? 4_0_0 EXIST::FUNCTION: +i2a_ASN1_ENUMERATED ? 4_0_0 EXIST::FUNCTION: +a2i_ASN1_ENUMERATED ? 4_0_0 EXIST::FUNCTION: +i2a_ASN1_OBJECT ? 4_0_0 EXIST::FUNCTION: +a2i_ASN1_STRING ? 4_0_0 EXIST::FUNCTION: +i2a_ASN1_STRING ? 4_0_0 EXIST::FUNCTION: +i2t_ASN1_OBJECT ? 4_0_0 EXIST::FUNCTION: +a2d_ASN1_OBJECT ? 4_0_0 EXIST::FUNCTION: +ASN1_OBJECT_create ? 4_0_0 EXIST::FUNCTION: +ASN1_INTEGER_get_int64 ? 4_0_0 EXIST::FUNCTION: +ASN1_INTEGER_set_int64 ? 4_0_0 EXIST::FUNCTION: +ASN1_INTEGER_get_uint64 ? 4_0_0 EXIST::FUNCTION: +ASN1_INTEGER_set_uint64 ? 4_0_0 EXIST::FUNCTION: +ASN1_INTEGER_set ? 4_0_0 EXIST::FUNCTION: +ASN1_INTEGER_get ? 4_0_0 EXIST::FUNCTION: +BN_to_ASN1_INTEGER ? 4_0_0 EXIST::FUNCTION: +ASN1_INTEGER_to_BN ? 4_0_0 EXIST::FUNCTION: +ASN1_ENUMERATED_get_int64 ? 4_0_0 EXIST::FUNCTION: +ASN1_ENUMERATED_set_int64 ? 4_0_0 EXIST::FUNCTION: +ASN1_ENUMERATED_set ? 4_0_0 EXIST::FUNCTION: +ASN1_ENUMERATED_get ? 4_0_0 EXIST::FUNCTION: +BN_to_ASN1_ENUMERATED ? 4_0_0 EXIST::FUNCTION: +ASN1_ENUMERATED_to_BN ? 4_0_0 EXIST::FUNCTION: +ASN1_PRINTABLE_type ? 4_0_0 EXIST::FUNCTION: +ASN1_tag2bit ? 4_0_0 EXIST::FUNCTION: +ASN1_get_object ? 4_0_0 EXIST::FUNCTION: +ASN1_check_infinite_end ? 4_0_0 EXIST::FUNCTION: +ASN1_const_check_infinite_end ? 4_0_0 EXIST::FUNCTION: +ASN1_put_object ? 4_0_0 EXIST::FUNCTION: +ASN1_put_eoc ? 4_0_0 EXIST::FUNCTION: +ASN1_object_size ? 4_0_0 EXIST::FUNCTION: +ASN1_dup ? 4_0_0 EXIST::FUNCTION: +ASN1_item_dup ? 4_0_0 EXIST::FUNCTION: +ASN1_item_sign_ex ? 4_0_0 EXIST::FUNCTION: +ASN1_item_verify_ex ? 4_0_0 EXIST::FUNCTION: +ASN1_d2i_fp ? 4_0_0 EXIST::FUNCTION:STDIO +ASN1_item_d2i_fp_ex ? 4_0_0 EXIST::FUNCTION:STDIO +ASN1_item_d2i_fp ? 4_0_0 EXIST::FUNCTION:STDIO +ASN1_i2d_fp ? 4_0_0 EXIST::FUNCTION:STDIO +ASN1_item_i2d_fp ? 4_0_0 EXIST::FUNCTION:STDIO +ASN1_STRING_print_ex_fp ? 4_0_0 EXIST::FUNCTION:STDIO +ASN1_STRING_to_UTF8 ? 4_0_0 EXIST::FUNCTION: +ASN1_d2i_bio ? 4_0_0 EXIST::FUNCTION: +ASN1_item_d2i_bio_ex ? 4_0_0 EXIST::FUNCTION: +ASN1_item_d2i_bio ? 4_0_0 EXIST::FUNCTION: +ASN1_i2d_bio ? 4_0_0 EXIST::FUNCTION: +ASN1_item_i2d_bio ? 4_0_0 EXIST::FUNCTION: +ASN1_item_i2d_mem_bio ? 4_0_0 EXIST::FUNCTION: +ASN1_UTCTIME_print ? 4_0_0 EXIST::FUNCTION: +ASN1_GENERALIZEDTIME_print ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_print ? 4_0_0 EXIST::FUNCTION: +ASN1_TIME_print_ex ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_print ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_print_ex ? 4_0_0 EXIST::FUNCTION: +ASN1_buf_print ? 4_0_0 EXIST::FUNCTION: +ASN1_bn_print ? 4_0_0 EXIST::FUNCTION: +ASN1_parse ? 4_0_0 EXIST::FUNCTION: +ASN1_parse_dump ? 4_0_0 EXIST::FUNCTION: +ASN1_tag2str ? 4_0_0 EXIST::FUNCTION: +ASN1_UNIVERSALSTRING_to_string ? 4_0_0 EXIST::FUNCTION: +ASN1_TYPE_set_octetstring ? 4_0_0 EXIST::FUNCTION: +ASN1_TYPE_get_octetstring ? 4_0_0 EXIST::FUNCTION: +ASN1_TYPE_set_int_octetstring ? 4_0_0 EXIST::FUNCTION: +ASN1_TYPE_get_int_octetstring ? 4_0_0 EXIST::FUNCTION: +ASN1_item_unpack ? 4_0_0 EXIST::FUNCTION: +ASN1_item_unpack_ex ? 4_0_0 EXIST::FUNCTION: +ASN1_item_pack ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_set_default_mask ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_set_default_mask_asc ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_get_default_mask ? 4_0_0 EXIST::FUNCTION: +ASN1_mbstring_copy ? 4_0_0 EXIST::FUNCTION: +ASN1_mbstring_ncopy ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_set_by_NID ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_TABLE_get ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_TABLE_add ? 4_0_0 EXIST::FUNCTION: +ASN1_STRING_TABLE_cleanup ? 4_0_0 EXIST::FUNCTION: +ASN1_item_new ? 4_0_0 EXIST::FUNCTION: +ASN1_item_new_ex ? 4_0_0 EXIST::FUNCTION: +ASN1_item_free ? 4_0_0 EXIST::FUNCTION: +ASN1_item_d2i_ex ? 4_0_0 EXIST::FUNCTION: +ASN1_item_d2i ? 4_0_0 EXIST::FUNCTION: +ASN1_item_i2d ? 4_0_0 EXIST::FUNCTION: +ASN1_item_ndef_i2d ? 4_0_0 EXIST::FUNCTION: +ASN1_add_oid_module ? 4_0_0 EXIST::FUNCTION: +ASN1_add_stable_module ? 4_0_0 EXIST::FUNCTION: +ASN1_generate_nconf ? 4_0_0 EXIST::FUNCTION: +ASN1_generate_v3 ? 4_0_0 EXIST::FUNCTION: +ASN1_str2mask ? 4_0_0 EXIST::FUNCTION: +ASN1_item_print ? 4_0_0 EXIST::FUNCTION: +ASN1_PCTX_new ? 4_0_0 EXIST::FUNCTION: +ASN1_PCTX_free ? 4_0_0 EXIST::FUNCTION: +ASN1_PCTX_get_flags ? 4_0_0 EXIST::FUNCTION: +ASN1_PCTX_set_flags ? 4_0_0 EXIST::FUNCTION: +ASN1_PCTX_get_nm_flags ? 4_0_0 EXIST::FUNCTION: +ASN1_PCTX_set_nm_flags ? 4_0_0 EXIST::FUNCTION: +ASN1_PCTX_get_cert_flags ? 4_0_0 EXIST::FUNCTION: +ASN1_PCTX_set_cert_flags ? 4_0_0 EXIST::FUNCTION: +ASN1_PCTX_get_oid_flags ? 4_0_0 EXIST::FUNCTION: +ASN1_PCTX_set_oid_flags ? 4_0_0 EXIST::FUNCTION: +ASN1_PCTX_get_str_flags ? 4_0_0 EXIST::FUNCTION: +ASN1_PCTX_set_str_flags ? 4_0_0 EXIST::FUNCTION: +ASN1_SCTX_new ? 4_0_0 EXIST::FUNCTION: +ASN1_SCTX_free ? 4_0_0 EXIST::FUNCTION: +ASN1_SCTX_get_item ? 4_0_0 EXIST::FUNCTION: +ASN1_SCTX_get_template ? 4_0_0 EXIST::FUNCTION: +ASN1_SCTX_get_flags ? 4_0_0 EXIST::FUNCTION: +ASN1_SCTX_set_app_data ? 4_0_0 EXIST::FUNCTION: +ASN1_SCTX_get_app_data ? 4_0_0 EXIST::FUNCTION: +BIO_f_asn1 ? 4_0_0 EXIST::FUNCTION: +BIO_new_NDEF ? 4_0_0 EXIST::FUNCTION: +i2d_ASN1_bio_stream ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_ASN1_stream ? 4_0_0 EXIST::FUNCTION: +SMIME_write_ASN1 ? 4_0_0 EXIST::FUNCTION: +SMIME_write_ASN1_ex ? 4_0_0 EXIST::FUNCTION: +SMIME_read_ASN1 ? 4_0_0 EXIST::FUNCTION: +SMIME_read_ASN1_ex ? 4_0_0 EXIST::FUNCTION: +SMIME_crlf_copy ? 4_0_0 EXIST::FUNCTION: +SMIME_text ? 4_0_0 EXIST::FUNCTION: +ASN1_ITEM_lookup ? 4_0_0 EXIST::FUNCTION: +ASN1_ITEM_get ? 4_0_0 EXIST::FUNCTION: +ASN1_BOOLEAN_it ? 4_0_0 EXIST::FUNCTION: +ASN1_TBOOLEAN_it ? 4_0_0 EXIST::FUNCTION: +ASN1_FBOOLEAN_it ? 4_0_0 EXIST::FUNCTION: +ASN1_SEQUENCE_it ? 4_0_0 EXIST::FUNCTION: +CBIGNUM_it ? 4_0_0 EXIST::FUNCTION: +BIGNUM_it ? 4_0_0 EXIST::FUNCTION: +INT32_it ? 4_0_0 EXIST::FUNCTION: +ZINT32_it ? 4_0_0 EXIST::FUNCTION: +UINT32_it ? 4_0_0 EXIST::FUNCTION: +ZUINT32_it ? 4_0_0 EXIST::FUNCTION: +INT64_it ? 4_0_0 EXIST::FUNCTION: +ZINT64_it ? 4_0_0 EXIST::FUNCTION: +UINT64_it ? 4_0_0 EXIST::FUNCTION: +ZUINT64_it ? 4_0_0 EXIST::FUNCTION: +LONG_it ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ZLONG_it ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ASN1_item_ex_new ? 4_0_0 EXIST::FUNCTION: +ASN1_item_ex_free ? 4_0_0 EXIST::FUNCTION: +ASN1_item_ex_d2i ? 4_0_0 EXIST::FUNCTION: +ASN1_item_ex_i2d ? 4_0_0 EXIST::FUNCTION: +BIO_get_new_index ? 4_0_0 EXIST::FUNCTION: +BIO_set_flags ? 4_0_0 EXIST::FUNCTION: +BIO_test_flags ? 4_0_0 EXIST::FUNCTION: +BIO_clear_flags ? 4_0_0 EXIST::FUNCTION: +BIO_get_callback ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +BIO_set_callback ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +BIO_debug_callback ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +BIO_get_callback_ex ? 4_0_0 EXIST::FUNCTION: +BIO_set_callback_ex ? 4_0_0 EXIST::FUNCTION: +BIO_debug_callback_ex ? 4_0_0 EXIST::FUNCTION: +BIO_get_callback_arg ? 4_0_0 EXIST::FUNCTION: +BIO_set_callback_arg ? 4_0_0 EXIST::FUNCTION: +BIO_method_name ? 4_0_0 EXIST::FUNCTION: +BIO_method_type ? 4_0_0 EXIST::FUNCTION: +BIO_ctrl_pending ? 4_0_0 EXIST::FUNCTION: +BIO_ctrl_wpending ? 4_0_0 EXIST::FUNCTION: +BIO_ctrl_get_write_guarantee ? 4_0_0 EXIST::FUNCTION: +BIO_ctrl_get_read_request ? 4_0_0 EXIST::FUNCTION: +BIO_ctrl_reset_read_request ? 4_0_0 EXIST::FUNCTION: +BIO_set_ex_data ? 4_0_0 EXIST::FUNCTION: +BIO_get_ex_data ? 4_0_0 EXIST::FUNCTION: +BIO_number_read ? 4_0_0 EXIST::FUNCTION: +BIO_number_written ? 4_0_0 EXIST::FUNCTION: +BIO_asn1_set_prefix ? 4_0_0 EXIST::FUNCTION: +BIO_asn1_get_prefix ? 4_0_0 EXIST::FUNCTION: +BIO_asn1_set_suffix ? 4_0_0 EXIST::FUNCTION: +BIO_asn1_get_suffix ? 4_0_0 EXIST::FUNCTION: +BIO_s_file ? 4_0_0 EXIST::FUNCTION: +BIO_new_file ? 4_0_0 EXIST::FUNCTION: +BIO_new_from_core_bio ? 4_0_0 EXIST::FUNCTION: +BIO_new_fp ? 4_0_0 EXIST::FUNCTION:STDIO +BIO_new_ex ? 4_0_0 EXIST::FUNCTION: +BIO_new ? 4_0_0 EXIST::FUNCTION: +BIO_free ? 4_0_0 EXIST::FUNCTION: +BIO_set_data ? 4_0_0 EXIST::FUNCTION: +BIO_get_data ? 4_0_0 EXIST::FUNCTION: +BIO_set_init ? 4_0_0 EXIST::FUNCTION: +BIO_get_init ? 4_0_0 EXIST::FUNCTION: +BIO_set_shutdown ? 4_0_0 EXIST::FUNCTION: +BIO_get_shutdown ? 4_0_0 EXIST::FUNCTION: +BIO_vfree ? 4_0_0 EXIST::FUNCTION: +BIO_up_ref ? 4_0_0 EXIST::FUNCTION: +BIO_read ? 4_0_0 EXIST::FUNCTION: +BIO_read_ex ? 4_0_0 EXIST::FUNCTION: +BIO_recvmmsg ? 4_0_0 EXIST::FUNCTION: +BIO_gets ? 4_0_0 EXIST::FUNCTION: +BIO_get_line ? 4_0_0 EXIST::FUNCTION: +BIO_write ? 4_0_0 EXIST::FUNCTION: +BIO_write_ex ? 4_0_0 EXIST::FUNCTION: +BIO_sendmmsg ? 4_0_0 EXIST::FUNCTION: +BIO_get_rpoll_descriptor ? 4_0_0 EXIST::FUNCTION: +BIO_get_wpoll_descriptor ? 4_0_0 EXIST::FUNCTION: +BIO_puts ? 4_0_0 EXIST::FUNCTION: +BIO_indent ? 4_0_0 EXIST::FUNCTION: +BIO_ctrl ? 4_0_0 EXIST::FUNCTION: +BIO_callback_ctrl ? 4_0_0 EXIST::FUNCTION: +BIO_ptr_ctrl ? 4_0_0 EXIST::FUNCTION: +BIO_int_ctrl ? 4_0_0 EXIST::FUNCTION: +BIO_push ? 4_0_0 EXIST::FUNCTION: +BIO_pop ? 4_0_0 EXIST::FUNCTION: +BIO_free_all ? 4_0_0 EXIST::FUNCTION: +BIO_find_type ? 4_0_0 EXIST::FUNCTION: +BIO_next ? 4_0_0 EXIST::FUNCTION: +BIO_set_next ? 4_0_0 EXIST::FUNCTION: +BIO_get_retry_BIO ? 4_0_0 EXIST::FUNCTION: +BIO_get_retry_reason ? 4_0_0 EXIST::FUNCTION: +BIO_set_retry_reason ? 4_0_0 EXIST::FUNCTION: +BIO_dup_chain ? 4_0_0 EXIST::FUNCTION: +BIO_nread0 ? 4_0_0 EXIST::FUNCTION: +BIO_nread ? 4_0_0 EXIST::FUNCTION: +BIO_nwrite0 ? 4_0_0 EXIST::FUNCTION: +BIO_nwrite ? 4_0_0 EXIST::FUNCTION: +BIO_s_mem ? 4_0_0 EXIST::FUNCTION: +BIO_s_dgram_mem ? 4_0_0 EXIST::FUNCTION:DGRAM +BIO_s_secmem ? 4_0_0 EXIST::FUNCTION: +BIO_new_mem_buf ? 4_0_0 EXIST::FUNCTION: +BIO_s_socket ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_s_connect ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_s_accept ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_s_fd ? 4_0_0 EXIST::FUNCTION: +BIO_s_log ? 4_0_0 EXIST::FUNCTION: +BIO_s_bio ? 4_0_0 EXIST::FUNCTION: +BIO_s_null ? 4_0_0 EXIST::FUNCTION: +BIO_f_null ? 4_0_0 EXIST::FUNCTION: +BIO_f_buffer ? 4_0_0 EXIST::FUNCTION: +BIO_f_readbuffer ? 4_0_0 EXIST::FUNCTION: +BIO_f_linebuffer ? 4_0_0 EXIST::FUNCTION: +BIO_f_nbio_test ? 4_0_0 EXIST::FUNCTION: +BIO_f_prefix ? 4_0_0 EXIST::FUNCTION: +BIO_s_core ? 4_0_0 EXIST::FUNCTION: +BIO_s_dgram_pair ? 4_0_0 EXIST::FUNCTION:DGRAM +BIO_s_datagram ? 4_0_0 EXIST::FUNCTION:DGRAM +BIO_dgram_non_fatal_error ? 4_0_0 EXIST::FUNCTION:DGRAM +BIO_new_dgram ? 4_0_0 EXIST::FUNCTION:DGRAM +BIO_s_datagram_sctp ? 4_0_0 EXIST::FUNCTION:DGRAM,SCTP +BIO_new_dgram_sctp ? 4_0_0 EXIST::FUNCTION:DGRAM,SCTP +BIO_dgram_is_sctp ? 4_0_0 EXIST::FUNCTION:DGRAM,SCTP +BIO_dgram_sctp_notification_cb ? 4_0_0 EXIST::FUNCTION:DGRAM,SCTP +BIO_dgram_sctp_wait_for_dry ? 4_0_0 EXIST::FUNCTION:DGRAM,SCTP +BIO_dgram_sctp_msg_waiting ? 4_0_0 EXIST::FUNCTION:DGRAM,SCTP +BIO_sock_should_retry ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_sock_non_fatal_error ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_err_is_non_fatal ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_socket_wait ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_wait ? 4_0_0 EXIST::FUNCTION: +BIO_do_connect_retry ? 4_0_0 EXIST::FUNCTION: +BIO_fd_should_retry ? 4_0_0 EXIST::FUNCTION: +BIO_fd_non_fatal_error ? 4_0_0 EXIST::FUNCTION: +BIO_dump_cb ? 4_0_0 EXIST::FUNCTION: +BIO_dump_indent_cb ? 4_0_0 EXIST::FUNCTION: +BIO_dump ? 4_0_0 EXIST::FUNCTION: +BIO_dump_indent ? 4_0_0 EXIST::FUNCTION: +BIO_dump_fp ? 4_0_0 EXIST::FUNCTION:STDIO +BIO_dump_indent_fp ? 4_0_0 EXIST::FUNCTION:STDIO +BIO_hex_string ? 4_0_0 EXIST::FUNCTION: +BIO_ADDR_new ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDR_copy ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDR_dup ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDR_rawmake ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDR_free ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDR_clear ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDR_family ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDR_rawaddress ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDR_rawport ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDR_hostname_string ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDR_service_string ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDR_path_string ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDRINFO_next ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDRINFO_family ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDRINFO_socktype ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDRINFO_protocol ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDRINFO_address ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_ADDRINFO_free ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_parse_hostserv ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_lookup ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_lookup_ex ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_sock_error ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_socket_ioctl ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_socket_nbio ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_sock_init ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_set_tcp_ndelay ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_gethostbyname ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,SOCK +BIO_get_port ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,SOCK +BIO_get_host_ip ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,SOCK +BIO_get_accept_socket ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,SOCK +BIO_accept ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,SOCK +BIO_sock_info ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_socket ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_connect ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_bind ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_listen ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_accept_ex ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_closesocket ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_new_socket ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_new_connect ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_new_accept ? 4_0_0 EXIST::FUNCTION:SOCK +BIO_new_fd ? 4_0_0 EXIST::FUNCTION: +BIO_new_bio_pair ? 4_0_0 EXIST::FUNCTION: +BIO_new_bio_dgram_pair ? 4_0_0 EXIST::FUNCTION:DGRAM +BIO_copy_next_retry ? 4_0_0 EXIST::FUNCTION: +BIO_printf ? 4_0_0 EXIST::FUNCTION: +BIO_vprintf ? 4_0_0 EXIST::FUNCTION: +BIO_snprintf ? 4_0_0 EXIST::FUNCTION: +BIO_vsnprintf ? 4_0_0 EXIST::FUNCTION: +BIO_meth_new ? 4_0_0 EXIST::FUNCTION: +BIO_meth_free ? 4_0_0 EXIST::FUNCTION: +BIO_meth_set_write ? 4_0_0 EXIST::FUNCTION: +BIO_meth_set_write_ex ? 4_0_0 EXIST::FUNCTION: +BIO_meth_set_sendmmsg ? 4_0_0 EXIST::FUNCTION: +BIO_meth_set_read ? 4_0_0 EXIST::FUNCTION: +BIO_meth_set_read_ex ? 4_0_0 EXIST::FUNCTION: +BIO_meth_set_recvmmsg ? 4_0_0 EXIST::FUNCTION: +BIO_meth_set_puts ? 4_0_0 EXIST::FUNCTION: +BIO_meth_set_gets ? 4_0_0 EXIST::FUNCTION: +BIO_meth_set_ctrl ? 4_0_0 EXIST::FUNCTION: +BIO_meth_set_create ? 4_0_0 EXIST::FUNCTION: +BIO_meth_set_destroy ? 4_0_0 EXIST::FUNCTION: +BIO_meth_set_callback_ctrl ? 4_0_0 EXIST::FUNCTION: +BIO_meth_get_write ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 +BIO_meth_get_write_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 +BIO_meth_get_sendmmsg ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 +BIO_meth_get_read ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 +BIO_meth_get_read_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 +BIO_meth_get_recvmmsg ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 +BIO_meth_get_puts ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 +BIO_meth_get_gets ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 +BIO_meth_get_ctrl ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 +BIO_meth_get_create ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 +BIO_meth_get_destroy ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 +BIO_meth_get_callback_ctrl ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_5 +OSSL_CMP_PKISTATUS_it ? 4_0_0 EXIST::FUNCTION:CMP +d2i_OSSL_CMP_PKIHEADER ? 4_0_0 EXIST::FUNCTION:CMP +i2d_OSSL_CMP_PKIHEADER ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_PKIHEADER_free ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_PKIHEADER_new ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_PKIHEADER_it ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_MSG_dup ? 4_0_0 EXIST::FUNCTION:CMP +d2i_OSSL_CMP_MSG ? 4_0_0 EXIST::FUNCTION:CMP +i2d_OSSL_CMP_MSG ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_MSG_it ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_dup ? 4_0_0 EXIST::FUNCTION:CMP +d2i_OSSL_CMP_ATAVS ? 4_0_0 EXIST::FUNCTION:CMP +i2d_OSSL_CMP_ATAVS ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ATAVS_free ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ATAVS_new ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ATAVS_it ? 4_0_0 EXIST::FUNCTION:CMP +d2i_OSSL_CMP_PKISI ? 4_0_0 EXIST::FUNCTION:CMP +i2d_OSSL_CMP_PKISI ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_PKISI_free ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_PKISI_new ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_PKISI_it ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_PKISI_dup ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_create ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_set0 ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_get0_type ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_get0_value ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_push0_stack_item ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_free ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_new0_certProfile ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_get0_certProfile ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_new_caCerts ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_get0_caCerts ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_new_rootCaCert ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_get0_rootCaCert ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_new_rootCaKeyUpdate ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_get0_rootCaKeyUpdate ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CRLSTATUS_create ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CRLSTATUS_new1 ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CRLSTATUS_get0 ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CRLSTATUS_free ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_new0_crlStatusList ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_get0_crlStatusList ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_new_crls ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_get0_crls ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_new0_certReqTemplate ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ITAV_get1_certReqTemplate ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ATAV_create ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ATAV_set0 ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ATAV_get0_type ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ATAV_get0_value ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ATAV_new_algId ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ATAV_get0_algId ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ATAV_new_rsaKeyLen ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ATAV_get_rsaKeyLen ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_ATAV_push1 ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_MSG_free ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_new ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_free ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_reinit ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get0_libctx ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get0_propq ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set_option ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get_option ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set_log_cb ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_print_errors ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_serverPath ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_server ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set_serverPort ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_proxy ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_no_proxy ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set_http_cb ? 4_0_0 EXIST::FUNCTION:CMP,HTTP +OSSL_CMP_CTX_set_http_cb_arg ? 4_0_0 EXIST::FUNCTION:CMP,HTTP +OSSL_CMP_CTX_get_http_cb_arg ? 4_0_0 EXIST::FUNCTION:CMP,HTTP +OSSL_CMP_CTX_set_transfer_cb ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set_transfer_cb_arg ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get_transfer_cb_arg ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_srvCert ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_expected_sender ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set0_trustedStore ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get0_trustedStore ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_untrusted ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get0_untrusted ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_cert ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_build_cert_chain ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_pkey ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_referenceValue ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_secretValue ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_recipient ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_push0_geninfo_ITAV ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_reset_geninfo_ITAVs ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get0_geninfo_ITAVs ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_extraCertsOut ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set0_newPkey ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get0_newPkey ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_issuer ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_serialNumber ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_subjectName ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_push1_subjectAltName ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set0_reqExtensions ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_reqExtensions_have_SAN ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_push0_policy ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_oldCert ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_p10CSR ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_push0_genm_ITAV ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_certConf_cb ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set_certConf_cb ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set_certConf_cb_arg ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get_certConf_cb_arg ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get_status ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get0_statusString ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get_failInfoCode ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get0_validatedSrvCert ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get0_newCert ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get1_newChain ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get1_caPubs ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_get1_extraCertsIn ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_transactionID ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_set1_senderNonce ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_snprint_PKIStatus ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_snprint_PKIStatusInfo ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_STATUSINFO_new ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_HDR_get0_transactionID ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_HDR_get0_recipNonce ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_HDR_get0_geninfo_ITAVs ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_MSG_get0_header ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_MSG_get_bodytype ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_MSG_get0_certreq_publickey ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_MSG_update_transactionID ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_MSG_update_recipNonce ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_setup_CRM ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_MSG_read ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_MSG_write ? 4_0_0 EXIST::FUNCTION:CMP +d2i_OSSL_CMP_MSG_bio ? 4_0_0 EXIST::FUNCTION:CMP +i2d_OSSL_CMP_MSG_bio ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_validate_msg ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_validate_cert_path ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_MSG_http_perform ? 4_0_0 EXIST::FUNCTION:CMP,HTTP +OSSL_CMP_SRV_process_request ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_CTX_server_perform ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_SRV_CTX_new ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_SRV_CTX_free ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_SRV_CTX_init ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_SRV_CTX_init_trans ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_SRV_CTX_get0_cmp_ctx ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_SRV_CTX_get0_custom_ctx ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_SRV_CTX_set_send_unprotected_errors ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_SRV_CTX_set_accept_unprotected ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_SRV_CTX_set_accept_raverified ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_SRV_CTX_set_grant_implicit_confirm ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_exec_certreq ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_try_certreq ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_exec_RR_ses ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_exec_GENM_ses ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_get1_caCerts ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_get1_rootCaKeyUpdate ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_get1_crlUpdate ? 4_0_0 EXIST::FUNCTION:CMP +OSSL_CMP_get1_certReqTemplate ? 4_0_0 EXIST::FUNCTION:CMP +CMS_EnvelopedData_it ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SignedData_free ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SignedData_new ? 4_0_0 EXIST::FUNCTION:CMS +d2i_CMS_ContentInfo ? 4_0_0 EXIST::FUNCTION:CMS +i2d_CMS_ContentInfo ? 4_0_0 EXIST::FUNCTION:CMS +CMS_ContentInfo_free ? 4_0_0 EXIST::FUNCTION:CMS +CMS_ContentInfo_new ? 4_0_0 EXIST::FUNCTION:CMS +CMS_ContentInfo_it ? 4_0_0 EXIST::FUNCTION:CMS +d2i_CMS_ReceiptRequest ? 4_0_0 EXIST::FUNCTION:CMS +i2d_CMS_ReceiptRequest ? 4_0_0 EXIST::FUNCTION:CMS +CMS_ReceiptRequest_free ? 4_0_0 EXIST::FUNCTION:CMS +CMS_ReceiptRequest_new ? 4_0_0 EXIST::FUNCTION:CMS +CMS_ReceiptRequest_it ? 4_0_0 EXIST::FUNCTION:CMS +CMS_ContentInfo_print_ctx ? 4_0_0 EXIST::FUNCTION:CMS +CMS_EnvelopedData_dup ? 4_0_0 EXIST::FUNCTION:CMS +CMS_ContentInfo_new_ex ? 4_0_0 EXIST::FUNCTION:CMS +CMS_get0_type ? 4_0_0 EXIST::FUNCTION:CMS +CMS_dataInit ? 4_0_0 EXIST::FUNCTION:CMS +CMS_dataFinal ? 4_0_0 EXIST::FUNCTION:CMS +CMS_get0_content ? 4_0_0 EXIST::FUNCTION:CMS +CMS_is_detached ? 4_0_0 EXIST::FUNCTION:CMS +CMS_set_detached ? 4_0_0 EXIST::FUNCTION:CMS +PEM_read_CMS ? 4_0_0 EXIST::FUNCTION:CMS,STDIO +PEM_write_CMS ? 4_0_0 EXIST::FUNCTION:CMS,STDIO +PEM_read_bio_CMS ? 4_0_0 EXIST::FUNCTION:CMS +PEM_write_bio_CMS ? 4_0_0 EXIST::FUNCTION:CMS +CMS_stream ? 4_0_0 EXIST::FUNCTION:CMS +d2i_CMS_bio ? 4_0_0 EXIST::FUNCTION:CMS +i2d_CMS_bio ? 4_0_0 EXIST::FUNCTION:CMS +BIO_new_CMS ? 4_0_0 EXIST::FUNCTION:CMS +i2d_CMS_bio_stream ? 4_0_0 EXIST::FUNCTION:CMS +PEM_write_bio_CMS_stream ? 4_0_0 EXIST::FUNCTION:CMS +SMIME_read_CMS ? 4_0_0 EXIST::FUNCTION:CMS +SMIME_read_CMS_ex ? 4_0_0 EXIST::FUNCTION:CMS +SMIME_write_CMS ? 4_0_0 EXIST::FUNCTION:CMS +CMS_final ? 4_0_0 EXIST::FUNCTION:CMS +CMS_final_digest ? 4_0_0 EXIST::FUNCTION:CMS +CMS_sign ? 4_0_0 EXIST::FUNCTION:CMS +CMS_sign_ex ? 4_0_0 EXIST::FUNCTION:CMS +CMS_sign_receipt ? 4_0_0 EXIST::FUNCTION:CMS +CMS_data ? 4_0_0 EXIST::FUNCTION:CMS +CMS_data_create ? 4_0_0 EXIST::FUNCTION:CMS +CMS_data_create_ex ? 4_0_0 EXIST::FUNCTION:CMS +CMS_digest_verify ? 4_0_0 EXIST::FUNCTION:CMS +CMS_digest_create ? 4_0_0 EXIST::FUNCTION:CMS +CMS_digest_create_ex ? 4_0_0 EXIST::FUNCTION:CMS +CMS_EncryptedData_decrypt ? 4_0_0 EXIST::FUNCTION:CMS +CMS_EncryptedData_encrypt ? 4_0_0 EXIST::FUNCTION:CMS +CMS_EncryptedData_encrypt_ex ? 4_0_0 EXIST::FUNCTION:CMS +CMS_EncryptedData_set1_key ? 4_0_0 EXIST::FUNCTION:CMS +CMS_verify ? 4_0_0 EXIST::FUNCTION:CMS +CMS_verify_receipt ? 4_0_0 EXIST::FUNCTION:CMS +CMS_get0_signers ? 4_0_0 EXIST::FUNCTION:CMS +CMS_encrypt ? 4_0_0 EXIST::FUNCTION:CMS +CMS_encrypt_ex ? 4_0_0 EXIST::FUNCTION:CMS +CMS_decrypt ? 4_0_0 EXIST::FUNCTION:CMS +CMS_decrypt_set1_pkey ? 4_0_0 EXIST::FUNCTION:CMS +CMS_decrypt_set1_pkey_and_peer ? 4_0_0 EXIST::FUNCTION:CMS +CMS_decrypt_set1_key ? 4_0_0 EXIST::FUNCTION:CMS +CMS_decrypt_set1_password ? 4_0_0 EXIST::FUNCTION:CMS +CMS_get0_RecipientInfos ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_type ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_get0_pkey_ctx ? 4_0_0 EXIST::FUNCTION:CMS +CMS_AuthEnvelopedData_create ? 4_0_0 EXIST::FUNCTION:CMS +CMS_AuthEnvelopedData_create_ex ? 4_0_0 EXIST::FUNCTION:CMS +CMS_EnvelopedData_create ? 4_0_0 EXIST::FUNCTION:CMS +CMS_EnvelopedData_create_ex ? 4_0_0 EXIST::FUNCTION:CMS +CMS_EnvelopedData_decrypt ? 4_0_0 EXIST::FUNCTION:CMS +CMS_add1_recipient_cert ? 4_0_0 EXIST::FUNCTION:CMS +CMS_add1_recipient ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_set0_pkey ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_ktri_cert_cmp ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_ktri_get0_algs ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_ktri_get0_signer_id ? 4_0_0 EXIST::FUNCTION:CMS +CMS_add0_recipient_key ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_kekri_get0_id ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_set0_key ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_kekri_id_cmp ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_set0_password ? 4_0_0 EXIST::FUNCTION:CMS +CMS_add0_recipient_password ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_decrypt ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_encrypt ? 4_0_0 EXIST::FUNCTION:CMS +CMS_uncompress ? 4_0_0 EXIST::FUNCTION:CMS +CMS_compress ? 4_0_0 EXIST::FUNCTION:CMS +CMS_set1_eContentType ? 4_0_0 EXIST::FUNCTION:CMS +CMS_get0_eContentType ? 4_0_0 EXIST::FUNCTION:CMS +CMS_add0_CertificateChoices ? 4_0_0 EXIST::FUNCTION:CMS +CMS_add0_cert ? 4_0_0 EXIST::FUNCTION:CMS +CMS_add1_cert ? 4_0_0 EXIST::FUNCTION:CMS +CMS_get1_certs ? 4_0_0 EXIST::FUNCTION:CMS +CMS_add0_RevocationInfoChoice ? 4_0_0 EXIST::FUNCTION:CMS +CMS_add0_crl ? 4_0_0 EXIST::FUNCTION:CMS +CMS_add1_crl ? 4_0_0 EXIST::FUNCTION:CMS +CMS_get1_crls ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SignedData_init ? 4_0_0 EXIST::FUNCTION:CMS +CMS_add1_signer ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SignerInfo_get0_pkey_ctx ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SignerInfo_get0_md_ctx ? 4_0_0 EXIST::FUNCTION:CMS +CMS_get0_SignerInfos ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SignerInfo_set1_signer_cert ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SignerInfo_get0_signer_id ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SignerInfo_cert_cmp ? 4_0_0 EXIST::FUNCTION:CMS +CMS_set1_signers_certs ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SignerInfo_get0_algs ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SignerInfo_get0_signature ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SignerInfo_sign ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SignerInfo_verify ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SignerInfo_verify_content ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SignedData_verify ? 4_0_0 EXIST::FUNCTION:CMS +CMS_add_smimecap ? 4_0_0 EXIST::FUNCTION:CMS +CMS_add_simple_smimecap ? 4_0_0 EXIST::FUNCTION:CMS +CMS_add_standard_smimecap ? 4_0_0 EXIST::FUNCTION:CMS +CMS_signed_get_attr_count ? 4_0_0 EXIST::FUNCTION:CMS +CMS_signed_get_attr_by_NID ? 4_0_0 EXIST::FUNCTION:CMS +CMS_signed_get_attr_by_OBJ ? 4_0_0 EXIST::FUNCTION:CMS +CMS_signed_get_attr ? 4_0_0 EXIST::FUNCTION:CMS +CMS_signed_delete_attr ? 4_0_0 EXIST::FUNCTION:CMS +CMS_signed_add1_attr ? 4_0_0 EXIST::FUNCTION:CMS +CMS_signed_add1_attr_by_OBJ ? 4_0_0 EXIST::FUNCTION:CMS +CMS_signed_add1_attr_by_NID ? 4_0_0 EXIST::FUNCTION:CMS +CMS_signed_add1_attr_by_txt ? 4_0_0 EXIST::FUNCTION:CMS +CMS_signed_get0_data_by_OBJ ? 4_0_0 EXIST::FUNCTION:CMS +CMS_unsigned_get_attr_count ? 4_0_0 EXIST::FUNCTION:CMS +CMS_unsigned_get_attr_by_NID ? 4_0_0 EXIST::FUNCTION:CMS +CMS_unsigned_get_attr_by_OBJ ? 4_0_0 EXIST::FUNCTION:CMS +CMS_unsigned_get_attr ? 4_0_0 EXIST::FUNCTION:CMS +CMS_unsigned_delete_attr ? 4_0_0 EXIST::FUNCTION:CMS +CMS_unsigned_add1_attr ? 4_0_0 EXIST::FUNCTION:CMS +CMS_unsigned_add1_attr_by_OBJ ? 4_0_0 EXIST::FUNCTION:CMS +CMS_unsigned_add1_attr_by_NID ? 4_0_0 EXIST::FUNCTION:CMS +CMS_unsigned_add1_attr_by_txt ? 4_0_0 EXIST::FUNCTION:CMS +CMS_unsigned_get0_data_by_OBJ ? 4_0_0 EXIST::FUNCTION:CMS +CMS_get1_ReceiptRequest ? 4_0_0 EXIST::FUNCTION:CMS +CMS_ReceiptRequest_create0 ? 4_0_0 EXIST::FUNCTION:CMS +CMS_ReceiptRequest_create0_ex ? 4_0_0 EXIST::FUNCTION:CMS +CMS_add1_ReceiptRequest ? 4_0_0 EXIST::FUNCTION:CMS +CMS_ReceiptRequest_get0_values ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_kari_get0_alg ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_kari_get0_reks ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_kari_get0_orig_id ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_kari_orig_id_cmp ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientEncryptedKey_get0_id ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientEncryptedKey_cert_cmp ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_kari_set0_pkey ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_kari_set0_pkey_and_peer ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_kari_get0_ctx ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_kari_decrypt ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SharedInfo_encode ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_kemri_cert_cmp ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_kemri_set0_pkey ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_kemri_get0_ctx ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_kemri_get0_kdf_alg ? 4_0_0 EXIST::FUNCTION:CMS +CMS_RecipientInfo_kemri_set_ukm ? 4_0_0 EXIST::FUNCTION:CMS +COMP_CTX_new ? 4_0_0 EXIST::FUNCTION:COMP +COMP_CTX_get_method ? 4_0_0 EXIST::FUNCTION:COMP +COMP_CTX_get_type ? 4_0_0 EXIST::FUNCTION:COMP +COMP_get_type ? 4_0_0 EXIST::FUNCTION:COMP +COMP_get_name ? 4_0_0 EXIST::FUNCTION:COMP +COMP_CTX_free ? 4_0_0 EXIST::FUNCTION:COMP +COMP_compress_block ? 4_0_0 EXIST::FUNCTION:COMP +COMP_expand_block ? 4_0_0 EXIST::FUNCTION:COMP +COMP_zlib ? 4_0_0 EXIST::FUNCTION:COMP +COMP_zlib_oneshot ? 4_0_0 EXIST::FUNCTION:COMP +COMP_brotli ? 4_0_0 EXIST::FUNCTION:COMP +COMP_brotli_oneshot ? 4_0_0 EXIST::FUNCTION:COMP +COMP_zstd ? 4_0_0 EXIST::FUNCTION:COMP +COMP_zstd_oneshot ? 4_0_0 EXIST::FUNCTION:COMP +BIO_f_zlib ? 4_0_0 EXIST::FUNCTION:COMP +BIO_f_brotli ? 4_0_0 EXIST::FUNCTION:COMP +BIO_f_zstd ? 4_0_0 EXIST::FUNCTION:COMP +CONF_set_default_method ? 4_0_0 EXIST::FUNCTION: +CONF_set_nconf ? 4_0_0 EXIST::FUNCTION: +CONF_load ? 4_0_0 EXIST::FUNCTION: +CONF_load_fp ? 4_0_0 EXIST::FUNCTION:STDIO +CONF_load_bio ? 4_0_0 EXIST::FUNCTION: +CONF_get_section ? 4_0_0 EXIST::FUNCTION: +CONF_get_string ? 4_0_0 EXIST::FUNCTION: +CONF_get_number ? 4_0_0 EXIST::FUNCTION: +CONF_free ? 4_0_0 EXIST::FUNCTION: +CONF_dump_fp ? 4_0_0 EXIST::FUNCTION:STDIO +CONF_dump_bio ? 4_0_0 EXIST::FUNCTION: +OPENSSL_config ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0 +NCONF_new_ex ? 4_0_0 EXIST::FUNCTION: +NCONF_get0_libctx ? 4_0_0 EXIST::FUNCTION: +NCONF_new ? 4_0_0 EXIST::FUNCTION: +NCONF_default ? 4_0_0 EXIST::FUNCTION: +NCONF_WIN32 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +NCONF_free ? 4_0_0 EXIST::FUNCTION: +NCONF_free_data ? 4_0_0 EXIST::FUNCTION: +NCONF_load ? 4_0_0 EXIST::FUNCTION: +NCONF_load_fp ? 4_0_0 EXIST::FUNCTION:STDIO +NCONF_load_bio ? 4_0_0 EXIST::FUNCTION: +NCONF_get_section_names ? 4_0_0 EXIST::FUNCTION: +NCONF_get_section ? 4_0_0 EXIST::FUNCTION: +NCONF_get_string ? 4_0_0 EXIST::FUNCTION: +NCONF_get_number_e ? 4_0_0 EXIST::FUNCTION: +NCONF_dump_fp ? 4_0_0 EXIST::FUNCTION:STDIO +NCONF_dump_bio ? 4_0_0 EXIST::FUNCTION: +CONF_modules_load ? 4_0_0 EXIST::FUNCTION: +CONF_modules_load_file_ex ? 4_0_0 EXIST::FUNCTION: +CONF_modules_load_file ? 4_0_0 EXIST::FUNCTION: +CONF_modules_unload ? 4_0_0 EXIST::FUNCTION: +CONF_modules_finish ? 4_0_0 EXIST::FUNCTION: +CONF_module_add ? 4_0_0 EXIST::FUNCTION: +CONF_imodule_get_name ? 4_0_0 EXIST::FUNCTION: +CONF_imodule_get_value ? 4_0_0 EXIST::FUNCTION: +CONF_imodule_get_usr_data ? 4_0_0 EXIST::FUNCTION: +CONF_imodule_set_usr_data ? 4_0_0 EXIST::FUNCTION: +CONF_imodule_get_module ? 4_0_0 EXIST::FUNCTION: +CONF_imodule_get_flags ? 4_0_0 EXIST::FUNCTION: +CONF_imodule_set_flags ? 4_0_0 EXIST::FUNCTION: +CONF_module_get_usr_data ? 4_0_0 EXIST::FUNCTION: +CONF_module_set_usr_data ? 4_0_0 EXIST::FUNCTION: +CONF_get1_default_config_file ? 4_0_0 EXIST::FUNCTION: +CONF_parse_list ? 4_0_0 EXIST::FUNCTION: +OPENSSL_load_builtin_modules ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_CRMF_ENCRYPTEDVALUE ? 4_0_0 EXIST::FUNCTION:CRMF +i2d_OSSL_CRMF_ENCRYPTEDVALUE ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_ENCRYPTEDVALUE_free ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_ENCRYPTEDVALUE_new ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_ENCRYPTEDVALUE_it ? 4_0_0 EXIST::FUNCTION:CRMF +d2i_OSSL_CRMF_ENCRYPTEDKEY ? 4_0_0 EXIST::FUNCTION:CRMF +i2d_OSSL_CRMF_ENCRYPTEDKEY ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_ENCRYPTEDKEY_free ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_ENCRYPTEDKEY_new ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_ENCRYPTEDKEY_it ? 4_0_0 EXIST::FUNCTION:CRMF +d2i_OSSL_CRMF_MSG ? 4_0_0 EXIST::FUNCTION:CRMF +i2d_OSSL_CRMF_MSG ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_free ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_new ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_it ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_dup ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_ATTRIBUTETYPEANDVALUE_free ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_ATTRIBUTETYPEANDVALUE_dup ? 4_0_0 EXIST::FUNCTION:CRMF +d2i_OSSL_CRMF_PBMPARAMETER ? 4_0_0 EXIST::FUNCTION:CRMF +i2d_OSSL_CRMF_PBMPARAMETER ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_PBMPARAMETER_free ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_PBMPARAMETER_new ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_PBMPARAMETER_it ? 4_0_0 EXIST::FUNCTION:CRMF +d2i_OSSL_CRMF_CERTID ? 4_0_0 EXIST::FUNCTION:CRMF +i2d_OSSL_CRMF_CERTID ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTID_free ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTID_new ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTID_it ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTID_dup ? 4_0_0 EXIST::FUNCTION:CRMF +d2i_OSSL_CRMF_PKIPUBLICATIONINFO ? 4_0_0 EXIST::FUNCTION:CRMF +i2d_OSSL_CRMF_PKIPUBLICATIONINFO ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_PKIPUBLICATIONINFO_free ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_PKIPUBLICATIONINFO_new ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_PKIPUBLICATIONINFO_it ? 4_0_0 EXIST::FUNCTION:CRMF +d2i_OSSL_CRMF_SINGLEPUBINFO ? 4_0_0 EXIST::FUNCTION:CRMF +i2d_OSSL_CRMF_SINGLEPUBINFO ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_SINGLEPUBINFO_free ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_SINGLEPUBINFO_new ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_SINGLEPUBINFO_it ? 4_0_0 EXIST::FUNCTION:CRMF +d2i_OSSL_CRMF_CERTTEMPLATE ? 4_0_0 EXIST::FUNCTION:CRMF +i2d_OSSL_CRMF_CERTTEMPLATE ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTTEMPLATE_free ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTTEMPLATE_new ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTTEMPLATE_it ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTTEMPLATE_dup ? 4_0_0 EXIST::FUNCTION:CRMF +d2i_OSSL_CRMF_MSGS ? 4_0_0 EXIST::FUNCTION:CRMF +i2d_OSSL_CRMF_MSGS ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSGS_free ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSGS_new ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSGS_it ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_pbmp_new ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_pbm_new ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_set1_regCtrl_regToken ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_get0_regCtrl_regToken ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_set1_regCtrl_authenticator ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_get0_regCtrl_authenticator ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_PKIPublicationInfo_push0_SinglePubInfo ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_set0_SinglePubInfo ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_set_PKIPublicationInfo_action ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_set1_regCtrl_pkiPublicationInfo ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_get0_regCtrl_pkiPublicationInfo ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_set1_regCtrl_protocolEncrKey ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_get0_regCtrl_protocolEncrKey ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_set1_regCtrl_oldCertID ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_get0_regCtrl_oldCertID ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTID_gen ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_set1_regInfo_utf8Pairs ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_get0_regInfo_utf8Pairs ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_set1_regInfo_certReq ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_get0_regInfo_certReq ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_set0_validity ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_set_certReqId ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_get_certReqId ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_set0_extensions ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_push0_extension ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_create_popo ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSGS_verify_popo ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_get0_tmpl ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTTEMPLATE_get0_publicKey ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTTEMPLATE_get0_subject ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTTEMPLATE_get0_issuer ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTTEMPLATE_get0_serialNumber ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTTEMPLATE_get0_extensions ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTID_get0_issuer ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTID_get0_serialNumber ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_CERTTEMPLATE_fill ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_ENCRYPTEDVALUE_get1_encCert ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_ENCRYPTEDKEY_get1_encCert ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_ENCRYPTEDVALUE_decrypt ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_ENCRYPTEDKEY_get1_pkey ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_MSG_centralkeygen_requested ? 4_0_0 EXIST::FUNCTION:CRMF +OSSL_CRMF_ENCRYPTEDKEY_init_envdata ? 4_0_0 EXIST::FUNCTION:CMS,CRMF +CRYPTO_THREAD_lock_new ? 4_0_0 EXIST::FUNCTION: +CRYPTO_THREAD_read_lock ? 4_0_0 EXIST::FUNCTION: +CRYPTO_THREAD_write_lock ? 4_0_0 EXIST::FUNCTION: +CRYPTO_THREAD_unlock ? 4_0_0 EXIST::FUNCTION: +CRYPTO_THREAD_lock_free ? 4_0_0 EXIST::FUNCTION: +CRYPTO_atomic_add ? 4_0_0 EXIST::FUNCTION: +CRYPTO_atomic_add64 ? 4_0_0 EXIST::FUNCTION: +CRYPTO_atomic_and ? 4_0_0 EXIST::FUNCTION: +CRYPTO_atomic_or ? 4_0_0 EXIST::FUNCTION: +CRYPTO_atomic_load ? 4_0_0 EXIST::FUNCTION: +CRYPTO_atomic_load_int ? 4_0_0 EXIST::FUNCTION: +CRYPTO_atomic_store ? 4_0_0 EXIST::FUNCTION: +OPENSSL_strlcpy ? 4_0_0 EXIST::FUNCTION: +OPENSSL_strlcat ? 4_0_0 EXIST::FUNCTION: +OPENSSL_strnlen ? 4_0_0 EXIST::FUNCTION: +OPENSSL_strtoul ? 4_0_0 EXIST::FUNCTION: +OPENSSL_buf2hexstr_ex ? 4_0_0 EXIST::FUNCTION: +OPENSSL_buf2hexstr ? 4_0_0 EXIST::FUNCTION: +OPENSSL_hexstr2buf_ex ? 4_0_0 EXIST::FUNCTION: +OPENSSL_hexstr2buf ? 4_0_0 EXIST::FUNCTION: +OPENSSL_hexchar2int ? 4_0_0 EXIST::FUNCTION: +OPENSSL_strcasecmp ? 4_0_0 EXIST::FUNCTION: +OPENSSL_strncasecmp ? 4_0_0 EXIST::FUNCTION: +OPENSSL_version_major ? 4_0_0 EXIST::FUNCTION: +OPENSSL_version_minor ? 4_0_0 EXIST::FUNCTION: +OPENSSL_version_patch ? 4_0_0 EXIST::FUNCTION: +OPENSSL_version_pre_release ? 4_0_0 EXIST::FUNCTION: +OPENSSL_version_build_metadata ? 4_0_0 EXIST::FUNCTION: +OpenSSL_version_num ? 4_0_0 EXIST::FUNCTION: +OpenSSL_version ? 4_0_0 EXIST::FUNCTION: +OPENSSL_info ? 4_0_0 EXIST::FUNCTION: +OPENSSL_issetugid ? 4_0_0 EXIST::FUNCTION: +CRYPTO_get_ex_new_index ? 4_0_0 EXIST::FUNCTION: +CRYPTO_free_ex_index ? 4_0_0 EXIST::FUNCTION: +CRYPTO_new_ex_data ? 4_0_0 EXIST::FUNCTION: +CRYPTO_dup_ex_data ? 4_0_0 EXIST::FUNCTION: +CRYPTO_free_ex_data ? 4_0_0 EXIST::FUNCTION: +CRYPTO_alloc_ex_data ? 4_0_0 EXIST::FUNCTION: +CRYPTO_set_ex_data ? 4_0_0 EXIST::FUNCTION: +CRYPTO_get_ex_data ? 4_0_0 EXIST::FUNCTION: +CRYPTO_set_mem_functions ? 4_0_0 EXIST::FUNCTION: +CRYPTO_get_mem_functions ? 4_0_0 EXIST::FUNCTION: +CRYPTO_malloc ? 4_0_0 EXIST::FUNCTION: +CRYPTO_zalloc ? 4_0_0 EXIST::FUNCTION: +CRYPTO_malloc_array ? 4_0_0 EXIST::FUNCTION: +CRYPTO_calloc ? 4_0_0 EXIST::FUNCTION: +CRYPTO_aligned_alloc ? 4_0_0 EXIST::FUNCTION: +CRYPTO_aligned_alloc_array ? 4_0_0 EXIST::FUNCTION: +CRYPTO_memdup ? 4_0_0 EXIST::FUNCTION: +CRYPTO_strdup ? 4_0_0 EXIST::FUNCTION: +CRYPTO_strndup ? 4_0_0 EXIST::FUNCTION: +CRYPTO_free ? 4_0_0 EXIST::FUNCTION: +CRYPTO_clear_free ? 4_0_0 EXIST::FUNCTION: +CRYPTO_realloc ? 4_0_0 EXIST::FUNCTION: +CRYPTO_clear_realloc ? 4_0_0 EXIST::FUNCTION: +CRYPTO_realloc_array ? 4_0_0 EXIST::FUNCTION: +CRYPTO_clear_realloc_array ? 4_0_0 EXIST::FUNCTION: +CRYPTO_secure_malloc_init ? 4_0_0 EXIST::FUNCTION: +CRYPTO_secure_malloc_done ? 4_0_0 EXIST::FUNCTION: +CRYPTO_secure_malloc ? 4_0_0 EXIST::FUNCTION: +CRYPTO_secure_zalloc ? 4_0_0 EXIST::FUNCTION: +CRYPTO_secure_malloc_array ? 4_0_0 EXIST::FUNCTION: +CRYPTO_secure_calloc ? 4_0_0 EXIST::FUNCTION: +CRYPTO_secure_free ? 4_0_0 EXIST::FUNCTION: +CRYPTO_secure_clear_free ? 4_0_0 EXIST::FUNCTION: +CRYPTO_secure_allocated ? 4_0_0 EXIST::FUNCTION: +CRYPTO_secure_malloc_initialized ? 4_0_0 EXIST::FUNCTION: +CRYPTO_secure_actual_size ? 4_0_0 EXIST::FUNCTION: +CRYPTO_secure_used ? 4_0_0 EXIST::FUNCTION: +OPENSSL_cleanse ? 4_0_0 EXIST::FUNCTION: +CRYPTO_get_alloc_counts ? 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG +CRYPTO_set_mem_debug ? 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 +CRYPTO_mem_ctrl ? 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 +CRYPTO_mem_debug_push ? 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 +CRYPTO_mem_debug_pop ? 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 +CRYPTO_mem_debug_malloc ? 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 +CRYPTO_mem_debug_realloc ? 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 +CRYPTO_mem_debug_free ? 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 +CRYPTO_mem_leaks_cb ? 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 +CRYPTO_mem_leaks_fp ? 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0,STDIO +CRYPTO_mem_leaks ? 4_0_0 EXIST::FUNCTION:CRYPTO_MDEBUG,DEPRECATEDIN_3_0 +OPENSSL_die ? 4_0_0 EXIST::FUNCTION: +OPENSSL_isservice ? 4_0_0 EXIST::FUNCTION: +OPENSSL_init ? 4_0_0 EXIST::FUNCTION: +OPENSSL_fork_prepare ? 4_0_0 EXIST:UNIX:FUNCTION:DEPRECATEDIN_3_0 +OPENSSL_fork_parent ? 4_0_0 EXIST:UNIX:FUNCTION:DEPRECATEDIN_3_0 +OPENSSL_fork_child ? 4_0_0 EXIST:UNIX:FUNCTION:DEPRECATEDIN_3_0 +OPENSSL_gmtime ? 4_0_0 EXIST::FUNCTION: +OPENSSL_gmtime_adj ? 4_0_0 EXIST::FUNCTION: +OPENSSL_gmtime_diff ? 4_0_0 EXIST::FUNCTION: +CRYPTO_memcmp ? 4_0_0 EXIST::FUNCTION: +OPENSSL_cleanup ? 4_0_0 EXIST::FUNCTION: +OPENSSL_init_crypto ? 4_0_0 EXIST::FUNCTION: +OPENSSL_atexit ? 4_0_0 EXIST::FUNCTION: +OPENSSL_thread_stop ? 4_0_0 EXIST::FUNCTION: +OPENSSL_thread_stop_ex ? 4_0_0 EXIST::FUNCTION: +OPENSSL_INIT_new ? 4_0_0 EXIST::FUNCTION: +OPENSSL_INIT_set_config_filename ? 4_0_0 EXIST::FUNCTION:STDIO +OPENSSL_INIT_set_config_file_flags ? 4_0_0 EXIST::FUNCTION:STDIO +OPENSSL_INIT_set_config_appname ? 4_0_0 EXIST::FUNCTION:STDIO +OPENSSL_INIT_free ? 4_0_0 EXIST::FUNCTION: +CRYPTO_THREAD_run_once ? 4_0_0 EXIST::FUNCTION: +CRYPTO_THREAD_init_local ? 4_0_0 EXIST::FUNCTION: +CRYPTO_THREAD_get_local ? 4_0_0 EXIST::FUNCTION: +CRYPTO_THREAD_set_local ? 4_0_0 EXIST::FUNCTION: +CRYPTO_THREAD_cleanup_local ? 4_0_0 EXIST::FUNCTION: +CRYPTO_THREAD_get_current_id ? 4_0_0 EXIST::FUNCTION: +CRYPTO_THREAD_compare_id ? 4_0_0 EXIST::FUNCTION: +OSSL_LIB_CTX_new ? 4_0_0 EXIST::FUNCTION: +OSSL_LIB_CTX_new_from_dispatch ? 4_0_0 EXIST::FUNCTION: +OSSL_LIB_CTX_new_child ? 4_0_0 EXIST::FUNCTION: +OSSL_LIB_CTX_load_config ? 4_0_0 EXIST::FUNCTION: +OSSL_LIB_CTX_free ? 4_0_0 EXIST::FUNCTION: +OSSL_LIB_CTX_get0_global_default ? 4_0_0 EXIST::FUNCTION: +OSSL_LIB_CTX_set0_default ? 4_0_0 EXIST::FUNCTION: +OSSL_LIB_CTX_get_conf_diagnostics ? 4_0_0 EXIST::FUNCTION: +OSSL_LIB_CTX_set_conf_diagnostics ? 4_0_0 EXIST::FUNCTION: +OSSL_sleep ? 4_0_0 EXIST::FUNCTION: +OSSL_LIB_CTX_get_data ? 4_0_0 EXIST::FUNCTION: +CT_POLICY_EVAL_CTX_new_ex ? 4_0_0 EXIST::FUNCTION:CT +CT_POLICY_EVAL_CTX_new ? 4_0_0 EXIST::FUNCTION:CT +CT_POLICY_EVAL_CTX_free ? 4_0_0 EXIST::FUNCTION:CT +CT_POLICY_EVAL_CTX_get0_cert ? 4_0_0 EXIST::FUNCTION:CT +CT_POLICY_EVAL_CTX_set1_cert ? 4_0_0 EXIST::FUNCTION:CT +CT_POLICY_EVAL_CTX_get0_issuer ? 4_0_0 EXIST::FUNCTION:CT +CT_POLICY_EVAL_CTX_set1_issuer ? 4_0_0 EXIST::FUNCTION:CT +CT_POLICY_EVAL_CTX_get0_log_store ? 4_0_0 EXIST::FUNCTION:CT +CT_POLICY_EVAL_CTX_set_shared_CTLOG_STORE ? 4_0_0 EXIST::FUNCTION:CT +CT_POLICY_EVAL_CTX_get_time ? 4_0_0 EXIST::FUNCTION:CT +CT_POLICY_EVAL_CTX_set_time ? 4_0_0 EXIST::FUNCTION:CT +SCT_new ? 4_0_0 EXIST::FUNCTION:CT +SCT_new_from_base64 ? 4_0_0 EXIST::FUNCTION:CT +SCT_free ? 4_0_0 EXIST::FUNCTION:CT +SCT_LIST_free ? 4_0_0 EXIST::FUNCTION:CT +SCT_get_version ? 4_0_0 EXIST::FUNCTION:CT +SCT_set_version ? 4_0_0 EXIST::FUNCTION:CT +SCT_get_log_entry_type ? 4_0_0 EXIST::FUNCTION:CT +SCT_set_log_entry_type ? 4_0_0 EXIST::FUNCTION:CT +SCT_get0_log_id ? 4_0_0 EXIST::FUNCTION:CT +SCT_set0_log_id ? 4_0_0 EXIST::FUNCTION:CT +SCT_set1_log_id ? 4_0_0 EXIST::FUNCTION:CT +SCT_get_timestamp ? 4_0_0 EXIST::FUNCTION:CT +SCT_set_timestamp ? 4_0_0 EXIST::FUNCTION:CT +SCT_get_signature_nid ? 4_0_0 EXIST::FUNCTION:CT +SCT_set_signature_nid ? 4_0_0 EXIST::FUNCTION:CT +SCT_get0_extensions ? 4_0_0 EXIST::FUNCTION:CT +SCT_set0_extensions ? 4_0_0 EXIST::FUNCTION:CT +SCT_set1_extensions ? 4_0_0 EXIST::FUNCTION:CT +SCT_get0_signature ? 4_0_0 EXIST::FUNCTION:CT +SCT_set0_signature ? 4_0_0 EXIST::FUNCTION:CT +SCT_set1_signature ? 4_0_0 EXIST::FUNCTION:CT +SCT_get_source ? 4_0_0 EXIST::FUNCTION:CT +SCT_set_source ? 4_0_0 EXIST::FUNCTION:CT +SCT_validation_status_string ? 4_0_0 EXIST::FUNCTION:CT +SCT_print ? 4_0_0 EXIST::FUNCTION:CT +SCT_LIST_print ? 4_0_0 EXIST::FUNCTION:CT +SCT_get_validation_status ? 4_0_0 EXIST::FUNCTION:CT +SCT_validate ? 4_0_0 EXIST::FUNCTION:CT +SCT_LIST_validate ? 4_0_0 EXIST::FUNCTION:CT +i2o_SCT_LIST ? 4_0_0 EXIST::FUNCTION:CT +o2i_SCT_LIST ? 4_0_0 EXIST::FUNCTION:CT +i2d_SCT_LIST ? 4_0_0 EXIST::FUNCTION:CT +d2i_SCT_LIST ? 4_0_0 EXIST::FUNCTION:CT +i2o_SCT ? 4_0_0 EXIST::FUNCTION:CT +o2i_SCT ? 4_0_0 EXIST::FUNCTION:CT +CTLOG_new_ex ? 4_0_0 EXIST::FUNCTION:CT +CTLOG_new ? 4_0_0 EXIST::FUNCTION:CT +CTLOG_new_from_base64_ex ? 4_0_0 EXIST::FUNCTION:CT +CTLOG_new_from_base64 ? 4_0_0 EXIST::FUNCTION:CT +CTLOG_free ? 4_0_0 EXIST::FUNCTION:CT +CTLOG_get0_name ? 4_0_0 EXIST::FUNCTION:CT +CTLOG_get0_log_id ? 4_0_0 EXIST::FUNCTION:CT +CTLOG_get0_public_key ? 4_0_0 EXIST::FUNCTION:CT +CTLOG_STORE_new_ex ? 4_0_0 EXIST::FUNCTION:CT +CTLOG_STORE_new ? 4_0_0 EXIST::FUNCTION:CT +CTLOG_STORE_free ? 4_0_0 EXIST::FUNCTION:CT +CTLOG_STORE_get0_log_by_id ? 4_0_0 EXIST::FUNCTION:CT +CTLOG_STORE_load_file ? 4_0_0 EXIST::FUNCTION:CT +CTLOG_STORE_load_default_file ? 4_0_0 EXIST::FUNCTION:CT +ERR_new ? 4_0_0 EXIST::FUNCTION: +ERR_set_debug ? 4_0_0 EXIST::FUNCTION: +ERR_set_error ? 4_0_0 EXIST::FUNCTION: +ERR_vset_error ? 4_0_0 EXIST::FUNCTION: +ERR_set_error_data ? 4_0_0 EXIST::FUNCTION: +ERR_get_error ? 4_0_0 EXIST::FUNCTION: +ERR_get_error_all ? 4_0_0 EXIST::FUNCTION: +ERR_get_error_line ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_get_error_line_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_peek_error ? 4_0_0 EXIST::FUNCTION: +ERR_peek_error_line ? 4_0_0 EXIST::FUNCTION: +ERR_peek_error_func ? 4_0_0 EXIST::FUNCTION: +ERR_peek_error_data ? 4_0_0 EXIST::FUNCTION: +ERR_peek_error_all ? 4_0_0 EXIST::FUNCTION: +ERR_peek_error_line_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_peek_last_error ? 4_0_0 EXIST::FUNCTION: +ERR_peek_last_error_line ? 4_0_0 EXIST::FUNCTION: +ERR_peek_last_error_func ? 4_0_0 EXIST::FUNCTION: +ERR_peek_last_error_data ? 4_0_0 EXIST::FUNCTION: +ERR_peek_last_error_all ? 4_0_0 EXIST::FUNCTION: +ERR_peek_last_error_line_data ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_clear_error ? 4_0_0 EXIST::FUNCTION: +ERR_error_string ? 4_0_0 EXIST::FUNCTION: +ERR_error_string_n ? 4_0_0 EXIST::FUNCTION: +ERR_lib_error_string ? 4_0_0 EXIST::FUNCTION: +ERR_func_error_string ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_reason_error_string ? 4_0_0 EXIST::FUNCTION: +ERR_print_errors_cb ? 4_0_0 EXIST::FUNCTION: +ERR_print_errors_fp ? 4_0_0 EXIST::FUNCTION:STDIO +ERR_print_errors ? 4_0_0 EXIST::FUNCTION: +ERR_add_error_data ? 4_0_0 EXIST::FUNCTION: +ERR_add_error_vdata ? 4_0_0 EXIST::FUNCTION: +ERR_add_error_txt ? 4_0_0 EXIST::FUNCTION: +ERR_add_error_mem_bio ? 4_0_0 EXIST::FUNCTION: +ERR_load_strings ? 4_0_0 EXIST::FUNCTION: +ERR_load_strings_const ? 4_0_0 EXIST::FUNCTION: +ERR_unload_strings ? 4_0_0 EXIST::FUNCTION: +ERR_remove_thread_state ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0 +ERR_remove_state ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_0_0 +ERR_get_state ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ERR_get_next_error_library ? 4_0_0 EXIST::FUNCTION: +ERR_set_mark ? 4_0_0 EXIST::FUNCTION: +ERR_pop_to_mark ? 4_0_0 EXIST::FUNCTION: +ERR_clear_last_mark ? 4_0_0 EXIST::FUNCTION: +ERR_count_to_mark ? 4_0_0 EXIST::FUNCTION: +ERR_pop ? 4_0_0 EXIST::FUNCTION: +OSSL_ERR_STATE_new ? 4_0_0 EXIST::FUNCTION: +OSSL_ERR_STATE_save ? 4_0_0 EXIST::FUNCTION: +OSSL_ERR_STATE_save_to_mark ? 4_0_0 EXIST::FUNCTION: +OSSL_ERR_STATE_restore ? 4_0_0 EXIST::FUNCTION: +OSSL_ERR_STATE_free ? 4_0_0 EXIST::FUNCTION: +ESS_ISSUER_SERIAL_free ? 4_0_0 EXIST::FUNCTION: +ESS_ISSUER_SERIAL_new ? 4_0_0 EXIST::FUNCTION: +d2i_ESS_ISSUER_SERIAL ? 4_0_0 EXIST::FUNCTION: +i2d_ESS_ISSUER_SERIAL ? 4_0_0 EXIST::FUNCTION: +ESS_ISSUER_SERIAL_dup ? 4_0_0 EXIST::FUNCTION: +ESS_CERT_ID_free ? 4_0_0 EXIST::FUNCTION: +ESS_CERT_ID_new ? 4_0_0 EXIST::FUNCTION: +d2i_ESS_CERT_ID ? 4_0_0 EXIST::FUNCTION: +i2d_ESS_CERT_ID ? 4_0_0 EXIST::FUNCTION: +ESS_CERT_ID_dup ? 4_0_0 EXIST::FUNCTION: +d2i_ESS_SIGNING_CERT ? 4_0_0 EXIST::FUNCTION: +i2d_ESS_SIGNING_CERT ? 4_0_0 EXIST::FUNCTION: +ESS_SIGNING_CERT_free ? 4_0_0 EXIST::FUNCTION: +ESS_SIGNING_CERT_new ? 4_0_0 EXIST::FUNCTION: +ESS_SIGNING_CERT_it ? 4_0_0 EXIST::FUNCTION: +ESS_SIGNING_CERT_dup ? 4_0_0 EXIST::FUNCTION: +ESS_CERT_ID_V2_free ? 4_0_0 EXIST::FUNCTION: +ESS_CERT_ID_V2_new ? 4_0_0 EXIST::FUNCTION: +d2i_ESS_CERT_ID_V2 ? 4_0_0 EXIST::FUNCTION: +i2d_ESS_CERT_ID_V2 ? 4_0_0 EXIST::FUNCTION: +ESS_CERT_ID_V2_dup ? 4_0_0 EXIST::FUNCTION: +d2i_ESS_SIGNING_CERT_V2 ? 4_0_0 EXIST::FUNCTION: +i2d_ESS_SIGNING_CERT_V2 ? 4_0_0 EXIST::FUNCTION: +ESS_SIGNING_CERT_V2_free ? 4_0_0 EXIST::FUNCTION: +ESS_SIGNING_CERT_V2_new ? 4_0_0 EXIST::FUNCTION: +ESS_SIGNING_CERT_V2_it ? 4_0_0 EXIST::FUNCTION: +ESS_SIGNING_CERT_V2_dup ? 4_0_0 EXIST::FUNCTION: +OSSL_ESS_signing_cert_new_init ? 4_0_0 EXIST::FUNCTION: +OSSL_ESS_signing_cert_v2_new_init ? 4_0_0 EXIST::FUNCTION: +OSSL_ESS_check_signing_certs ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_error ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_new ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_set_thunks ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_free ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_flush ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_insert ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_delete ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_retrieve ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_doall ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_doall_arg ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_doall_arg_thunk ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_strhash ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_num_items ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_get_down_load ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_set_down_load ? 4_0_0 EXIST::FUNCTION: +OPENSSL_LH_stats ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_1,STDIO +OPENSSL_LH_node_stats ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_1,STDIO +OPENSSL_LH_node_usage_stats ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_1,STDIO +OPENSSL_LH_stats_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_1 +OPENSSL_LH_node_stats_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_1 +OPENSSL_LH_node_usage_stats_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_1 +OCSP_CERTID_dup ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_sendreq_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_sendreq_bio ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_cert_to_id ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_cert_id_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_request_add0_id ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_request_add1_nonce ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_basic_add1_nonce ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_check_nonce ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_copy_nonce ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_request_set1_name ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_request_add1_cert ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_request_sign ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_response_status ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_response_get1_basic ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_resp_get0_signature ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_resp_get0_tbs_sigalg ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_resp_get0_respdata ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_resp_get0_signer ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_resp_count ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_resp_get0 ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_resp_get0_produced_at ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_resp_get0_certs ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_resp_get0_id ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_resp_get1_id ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_resp_find ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_single_get0_status ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_resp_find_status ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_check_validity ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_request_verify ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_id_issuer_cmp ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_id_cmp ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_request_onereq_count ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_request_onereq_get0 ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_onereq_get0_id ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_id_get0_info ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_request_is_signed ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_response_create ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_basic_add1_status ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_basic_add1_cert ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_basic_sign ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_basic_sign_ctx ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPID_set_by_name ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPID_set_by_key_ex ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPID_set_by_key ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPID_match_ex ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPID_match ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_crlID_new ? 4_0_0 EXIST:!VMS:FUNCTION:OCSP +OCSP_crlID2_new ?+ 4_0_0 EXIST:VMS:FUNCTION:OCSP +OCSP_accept_responses_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_archive_cutoff_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_url_svcloc_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQUEST_get_ext_count ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQUEST_get_ext_by_NID ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQUEST_get_ext_by_OBJ ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQUEST_get_ext_by_critical ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQUEST_get_ext ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQUEST_delete_ext ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQUEST_get1_ext_d2i ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQUEST_add1_ext_i2d ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQUEST_add_ext ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_ONEREQ_get_ext_count ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_ONEREQ_get_ext_by_NID ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_ONEREQ_get_ext_by_OBJ ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_ONEREQ_get_ext_by_critical ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_ONEREQ_get_ext ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_ONEREQ_delete_ext ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_ONEREQ_get1_ext_d2i ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_ONEREQ_add1_ext_i2d ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_ONEREQ_add_ext ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_BASICRESP_get_ext_count ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_BASICRESP_get_ext_by_NID ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_BASICRESP_get_ext_by_OBJ ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_BASICRESP_get_ext_by_critical ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_BASICRESP_get_ext ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_BASICRESP_delete_ext ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_BASICRESP_get1_ext_d2i ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_BASICRESP_add1_ext_i2d ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_BASICRESP_add_ext ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SINGLERESP_get_ext_count ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SINGLERESP_get_ext_by_NID ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SINGLERESP_get_ext_by_OBJ ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SINGLERESP_get_ext_by_critical ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SINGLERESP_get_ext ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SINGLERESP_delete_ext ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SINGLERESP_get1_ext_d2i ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SINGLERESP_add1_ext_i2d ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SINGLERESP_add_ext ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SINGLERESP_get0_id ? 4_0_0 EXIST::FUNCTION:OCSP +d2i_OCSP_SINGLERESP ? 4_0_0 EXIST::FUNCTION:OCSP +i2d_OCSP_SINGLERESP ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SINGLERESP_free ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SINGLERESP_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SINGLERESP_it ? 4_0_0 EXIST::FUNCTION:OCSP +d2i_OCSP_CERTSTATUS ? 4_0_0 EXIST::FUNCTION:OCSP +i2d_OCSP_CERTSTATUS ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_CERTSTATUS_free ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_CERTSTATUS_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_CERTSTATUS_it ? 4_0_0 EXIST::FUNCTION:OCSP +d2i_OCSP_REVOKEDINFO ? 4_0_0 EXIST::FUNCTION:OCSP +i2d_OCSP_REVOKEDINFO ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REVOKEDINFO_free ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REVOKEDINFO_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REVOKEDINFO_it ? 4_0_0 EXIST::FUNCTION:OCSP +d2i_OCSP_BASICRESP ? 4_0_0 EXIST::FUNCTION:OCSP +i2d_OCSP_BASICRESP ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_BASICRESP_free ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_BASICRESP_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_BASICRESP_it ? 4_0_0 EXIST::FUNCTION:OCSP +d2i_OCSP_RESPDATA ? 4_0_0 EXIST::FUNCTION:OCSP +i2d_OCSP_RESPDATA ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPDATA_free ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPDATA_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPDATA_it ? 4_0_0 EXIST::FUNCTION:OCSP +d2i_OCSP_RESPID ? 4_0_0 EXIST::FUNCTION:OCSP +i2d_OCSP_RESPID ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPID_free ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPID_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPID_it ? 4_0_0 EXIST::FUNCTION:OCSP +d2i_OCSP_RESPONSE ? 4_0_0 EXIST::FUNCTION:OCSP +i2d_OCSP_RESPONSE ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPONSE_free ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPONSE_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPONSE_it ? 4_0_0 EXIST::FUNCTION:OCSP +d2i_OCSP_RESPBYTES ? 4_0_0 EXIST::FUNCTION:OCSP +i2d_OCSP_RESPBYTES ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPBYTES_free ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPBYTES_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPBYTES_it ? 4_0_0 EXIST::FUNCTION:OCSP +d2i_OCSP_ONEREQ ? 4_0_0 EXIST::FUNCTION:OCSP +i2d_OCSP_ONEREQ ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_ONEREQ_free ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_ONEREQ_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_ONEREQ_it ? 4_0_0 EXIST::FUNCTION:OCSP +d2i_OCSP_CERTID ? 4_0_0 EXIST::FUNCTION:OCSP +i2d_OCSP_CERTID ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_CERTID_free ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_CERTID_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_CERTID_it ? 4_0_0 EXIST::FUNCTION:OCSP +d2i_OCSP_REQUEST ? 4_0_0 EXIST::FUNCTION:OCSP +i2d_OCSP_REQUEST ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQUEST_free ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQUEST_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQUEST_it ? 4_0_0 EXIST::FUNCTION:OCSP +d2i_OCSP_SIGNATURE ? 4_0_0 EXIST::FUNCTION:OCSP +i2d_OCSP_SIGNATURE ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SIGNATURE_free ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SIGNATURE_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SIGNATURE_it ? 4_0_0 EXIST::FUNCTION:OCSP +d2i_OCSP_REQINFO ? 4_0_0 EXIST::FUNCTION:OCSP +i2d_OCSP_REQINFO ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQINFO_free ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQINFO_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQINFO_it ? 4_0_0 EXIST::FUNCTION:OCSP +d2i_OCSP_CRLID ? 4_0_0 EXIST::FUNCTION:OCSP +i2d_OCSP_CRLID ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_CRLID_free ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_CRLID_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_CRLID_it ? 4_0_0 EXIST::FUNCTION:OCSP +d2i_OCSP_SERVICELOC ? 4_0_0 EXIST::FUNCTION:OCSP +i2d_OCSP_SERVICELOC ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SERVICELOC_free ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SERVICELOC_new ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_SERVICELOC_it ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_response_status_str ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_cert_status_str ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_crl_reason_str ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_REQUEST_print ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_RESPONSE_print ? 4_0_0 EXIST::FUNCTION:OCSP +OCSP_basic_verify ? 4_0_0 EXIST::FUNCTION:OCSP +PKCS12_get_attr ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0 +PKCS8_get_attr ? 4_0_0 EXIST::FUNCTION: +PKCS12_mac_present ? 4_0_0 EXIST::FUNCTION: +PKCS12_get0_mac ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_get0_attr ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_get0_type ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_get_nid ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_get_bag_nid ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_get0_bag_obj ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_get0_bag_type ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_get1_cert_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_get1_cert ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_get1_crl_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_get1_crl ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_get0_safes ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_get0_p8inf ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_get0_pkcs8 ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_create_cert ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_create_crl ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_create_secret ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_create0_p8inf ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_create0_pkcs8 ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_create_pkcs8_encrypt ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_create_pkcs8_encrypt_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_item_pack_safebag ? 4_0_0 EXIST::FUNCTION: +PKCS8_decrypt ? 4_0_0 EXIST::FUNCTION: +PKCS8_decrypt_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_decrypt_skey ? 4_0_0 EXIST::FUNCTION: +PKCS12_decrypt_skey_ex ? 4_0_0 EXIST::FUNCTION: +PKCS8_encrypt ? 4_0_0 EXIST::FUNCTION: +PKCS8_encrypt_ex ? 4_0_0 EXIST::FUNCTION: +PKCS8_set0_pbe ? 4_0_0 EXIST::FUNCTION: +PKCS8_set0_pbe_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_pack_p7data ? 4_0_0 EXIST::FUNCTION: +PKCS12_unpack_p7data ? 4_0_0 EXIST::FUNCTION: +PKCS12_pack_p7encdata ? 4_0_0 EXIST::FUNCTION: +PKCS12_pack_p7encdata_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_unpack_p7encdata ? 4_0_0 EXIST::FUNCTION: +PKCS12_pack_authsafes ? 4_0_0 EXIST::FUNCTION: +PKCS12_unpack_authsafes ? 4_0_0 EXIST::FUNCTION: +PKCS12_add_localkeyid ? 4_0_0 EXIST::FUNCTION: +PKCS12_add_friendlyname_asc ? 4_0_0 EXIST::FUNCTION: +PKCS12_add_friendlyname_utf8 ? 4_0_0 EXIST::FUNCTION: +PKCS12_add_CSPName_asc ? 4_0_0 EXIST::FUNCTION: +PKCS12_add_friendlyname_uni ? 4_0_0 EXIST::FUNCTION: +PKCS12_add1_attr_by_NID ? 4_0_0 EXIST::FUNCTION: +PKCS12_add1_attr_by_txt ? 4_0_0 EXIST::FUNCTION: +PKCS8_add_keyusage ? 4_0_0 EXIST::FUNCTION: +PKCS12_get_attr_gen ? 4_0_0 EXIST::FUNCTION: +PKCS12_get_friendlyname ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_get0_attrs ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_set0_attrs ? 4_0_0 EXIST::FUNCTION: +PKCS12_pbe_crypt ? 4_0_0 EXIST::FUNCTION: +PKCS12_pbe_crypt_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_item_decrypt_d2i ? 4_0_0 EXIST::FUNCTION: +PKCS12_item_decrypt_d2i_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_item_i2d_encrypt ? 4_0_0 EXIST::FUNCTION: +PKCS12_item_i2d_encrypt_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_init ? 4_0_0 EXIST::FUNCTION: +PKCS12_init_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_key_gen_asc ? 4_0_0 EXIST::FUNCTION: +PKCS12_key_gen_asc_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_key_gen_uni ? 4_0_0 EXIST::FUNCTION: +PKCS12_key_gen_uni_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_key_gen_utf8 ? 4_0_0 EXIST::FUNCTION: +PKCS12_key_gen_utf8_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_PBE_keyivgen ? 4_0_0 EXIST::FUNCTION: +PKCS12_PBE_keyivgen_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_gen_mac ? 4_0_0 EXIST::FUNCTION: +PKCS12_verify_mac ? 4_0_0 EXIST::FUNCTION: +PKCS12_set_mac ? 4_0_0 EXIST::FUNCTION: +PKCS12_set_pbmac1_pbkdf2 ? 4_0_0 EXIST::FUNCTION: +PKCS12_setup_mac ? 4_0_0 EXIST::FUNCTION: +OPENSSL_asc2uni ? 4_0_0 EXIST::FUNCTION: +OPENSSL_uni2asc ? 4_0_0 EXIST::FUNCTION: +OPENSSL_utf82uni ? 4_0_0 EXIST::FUNCTION: +OPENSSL_uni2utf8 ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS12 ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS12 ? 4_0_0 EXIST::FUNCTION: +PKCS12_free ? 4_0_0 EXIST::FUNCTION: +PKCS12_new ? 4_0_0 EXIST::FUNCTION: +PKCS12_it ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS12_MAC_DATA ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS12_MAC_DATA ? 4_0_0 EXIST::FUNCTION: +PKCS12_MAC_DATA_free ? 4_0_0 EXIST::FUNCTION: +PKCS12_MAC_DATA_new ? 4_0_0 EXIST::FUNCTION: +PKCS12_MAC_DATA_it ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS12_SAFEBAG ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS12_SAFEBAG ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_free ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_new ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAG_it ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS12_BAGS ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS12_BAGS ? 4_0_0 EXIST::FUNCTION: +PKCS12_BAGS_free ? 4_0_0 EXIST::FUNCTION: +PKCS12_BAGS_new ? 4_0_0 EXIST::FUNCTION: +PKCS12_BAGS_it ? 4_0_0 EXIST::FUNCTION: +PKCS12_SAFEBAGS_it ? 4_0_0 EXIST::FUNCTION: +PKCS12_AUTHSAFES_it ? 4_0_0 EXIST::FUNCTION: +PKCS12_PBE_add ? 4_0_0 EXIST::FUNCTION: +PKCS12_parse ? 4_0_0 EXIST::FUNCTION: +PKCS12_create ? 4_0_0 EXIST::FUNCTION: +PKCS12_create_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_create_ex2 ? 4_0_0 EXIST::FUNCTION: +PKCS12_add_cert ? 4_0_0 EXIST::FUNCTION: +PKCS12_add_key ? 4_0_0 EXIST::FUNCTION: +PKCS12_add_key_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_add_secret ? 4_0_0 EXIST::FUNCTION: +PKCS12_add_safe ? 4_0_0 EXIST::FUNCTION: +PKCS12_add_safe_ex ? 4_0_0 EXIST::FUNCTION: +PKCS12_add_safes ? 4_0_0 EXIST::FUNCTION: +PKCS12_add_safes_ex ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS12_bio ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS12_fp ? 4_0_0 EXIST::FUNCTION:STDIO +d2i_PKCS12_bio ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS12_fp ? 4_0_0 EXIST::FUNCTION:STDIO +PKCS12_newpass ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS7_ISSUER_AND_SERIAL ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS7_ISSUER_AND_SERIAL ? 4_0_0 EXIST::FUNCTION: +PKCS7_ISSUER_AND_SERIAL_free ? 4_0_0 EXIST::FUNCTION: +PKCS7_ISSUER_AND_SERIAL_new ? 4_0_0 EXIST::FUNCTION: +PKCS7_ISSUER_AND_SERIAL_it ? 4_0_0 EXIST::FUNCTION: +PKCS7_ISSUER_AND_SERIAL_digest ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS7_fp ? 4_0_0 EXIST::FUNCTION:STDIO +i2d_PKCS7_fp ? 4_0_0 EXIST::FUNCTION:STDIO +PKCS7_dup ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS7_bio ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS7_bio ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS7_bio_stream ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_PKCS7_stream ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS7_SIGNER_INFO ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS7_SIGNER_INFO ? 4_0_0 EXIST::FUNCTION: +PKCS7_SIGNER_INFO_free ? 4_0_0 EXIST::FUNCTION: +PKCS7_SIGNER_INFO_new ? 4_0_0 EXIST::FUNCTION: +PKCS7_SIGNER_INFO_it ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS7_RECIP_INFO ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS7_RECIP_INFO ? 4_0_0 EXIST::FUNCTION: +PKCS7_RECIP_INFO_free ? 4_0_0 EXIST::FUNCTION: +PKCS7_RECIP_INFO_new ? 4_0_0 EXIST::FUNCTION: +PKCS7_RECIP_INFO_it ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS7_SIGNED ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS7_SIGNED ? 4_0_0 EXIST::FUNCTION: +PKCS7_SIGNED_free ? 4_0_0 EXIST::FUNCTION: +PKCS7_SIGNED_new ? 4_0_0 EXIST::FUNCTION: +PKCS7_SIGNED_it ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS7_ENC_CONTENT ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS7_ENC_CONTENT ? 4_0_0 EXIST::FUNCTION: +PKCS7_ENC_CONTENT_free ? 4_0_0 EXIST::FUNCTION: +PKCS7_ENC_CONTENT_new ? 4_0_0 EXIST::FUNCTION: +PKCS7_ENC_CONTENT_it ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS7_ENVELOPE ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS7_ENVELOPE ? 4_0_0 EXIST::FUNCTION: +PKCS7_ENVELOPE_free ? 4_0_0 EXIST::FUNCTION: +PKCS7_ENVELOPE_new ? 4_0_0 EXIST::FUNCTION: +PKCS7_ENVELOPE_it ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS7_SIGN_ENVELOPE ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS7_SIGN_ENVELOPE ? 4_0_0 EXIST::FUNCTION: +PKCS7_SIGN_ENVELOPE_free ? 4_0_0 EXIST::FUNCTION: +PKCS7_SIGN_ENVELOPE_new ? 4_0_0 EXIST::FUNCTION: +PKCS7_SIGN_ENVELOPE_it ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS7_DIGEST ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS7_DIGEST ? 4_0_0 EXIST::FUNCTION: +PKCS7_DIGEST_free ? 4_0_0 EXIST::FUNCTION: +PKCS7_DIGEST_new ? 4_0_0 EXIST::FUNCTION: +PKCS7_DIGEST_it ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS7_ENCRYPT ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS7_ENCRYPT ? 4_0_0 EXIST::FUNCTION: +PKCS7_ENCRYPT_free ? 4_0_0 EXIST::FUNCTION: +PKCS7_ENCRYPT_new ? 4_0_0 EXIST::FUNCTION: +PKCS7_ENCRYPT_it ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS7 ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS7 ? 4_0_0 EXIST::FUNCTION: +PKCS7_free ? 4_0_0 EXIST::FUNCTION: +PKCS7_new ? 4_0_0 EXIST::FUNCTION: +PKCS7_it ? 4_0_0 EXIST::FUNCTION: +PKCS7_new_ex ? 4_0_0 EXIST::FUNCTION: +PKCS7_ATTR_SIGN_it ? 4_0_0 EXIST::FUNCTION: +PKCS7_ATTR_VERIFY_it ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS7_NDEF ? 4_0_0 EXIST::FUNCTION: +PKCS7_print_ctx ? 4_0_0 EXIST::FUNCTION: +PKCS7_ctrl ? 4_0_0 EXIST::FUNCTION: +PKCS7_type_is_other ? 4_0_0 EXIST::FUNCTION: +PKCS7_set_type ? 4_0_0 EXIST::FUNCTION: +PKCS7_set0_type_other ? 4_0_0 EXIST::FUNCTION: +PKCS7_set_content ? 4_0_0 EXIST::FUNCTION: +PKCS7_SIGNER_INFO_set ? 4_0_0 EXIST::FUNCTION: +PKCS7_SIGNER_INFO_sign ? 4_0_0 EXIST::FUNCTION: +PKCS7_add_signer ? 4_0_0 EXIST::FUNCTION: +PKCS7_add_certificate ? 4_0_0 EXIST::FUNCTION: +PKCS7_add_crl ? 4_0_0 EXIST::FUNCTION: +PKCS7_content_new ? 4_0_0 EXIST::FUNCTION: +PKCS7_dataVerify ? 4_0_0 EXIST::FUNCTION: +PKCS7_signatureVerify ? 4_0_0 EXIST::FUNCTION: +PKCS7_dataInit ? 4_0_0 EXIST::FUNCTION: +PKCS7_dataFinal ? 4_0_0 EXIST::FUNCTION: +PKCS7_dataDecode ? 4_0_0 EXIST::FUNCTION: +PKCS7_add_signature ? 4_0_0 EXIST::FUNCTION: +PKCS7_cert_from_signer_info ? 4_0_0 EXIST::FUNCTION: +PKCS7_set_digest ? 4_0_0 EXIST::FUNCTION: +PKCS7_get_signer_info ? 4_0_0 EXIST::FUNCTION: +PKCS7_add_recipient ? 4_0_0 EXIST::FUNCTION: +PKCS7_SIGNER_INFO_get0_algs ? 4_0_0 EXIST::FUNCTION: +PKCS7_RECIP_INFO_get0_alg ? 4_0_0 EXIST::FUNCTION: +PKCS7_add_recipient_info ? 4_0_0 EXIST::FUNCTION: +PKCS7_RECIP_INFO_set ? 4_0_0 EXIST::FUNCTION: +PKCS7_set_cipher ? 4_0_0 EXIST::FUNCTION: +PKCS7_stream ? 4_0_0 EXIST::FUNCTION: +PKCS7_get_issuer_and_serial ? 4_0_0 EXIST::FUNCTION: +PKCS7_get_octet_string ? 4_0_0 EXIST::FUNCTION: +PKCS7_digest_from_attributes ? 4_0_0 EXIST::FUNCTION: +PKCS7_add_signed_attribute ? 4_0_0 EXIST::FUNCTION: +PKCS7_add_attribute ? 4_0_0 EXIST::FUNCTION: +PKCS7_get_attribute ? 4_0_0 EXIST::FUNCTION: +PKCS7_get_signed_attribute ? 4_0_0 EXIST::FUNCTION: +PKCS7_set_signed_attributes ? 4_0_0 EXIST::FUNCTION: +PKCS7_set_attributes ? 4_0_0 EXIST::FUNCTION: +PKCS7_sign ? 4_0_0 EXIST::FUNCTION: +PKCS7_sign_ex ? 4_0_0 EXIST::FUNCTION: +PKCS7_sign_add_signer ? 4_0_0 EXIST::FUNCTION: +PKCS7_final ? 4_0_0 EXIST::FUNCTION: +PKCS7_verify ? 4_0_0 EXIST::FUNCTION: +PKCS7_get0_signers ? 4_0_0 EXIST::FUNCTION: +PKCS7_encrypt ? 4_0_0 EXIST::FUNCTION: +PKCS7_encrypt_ex ? 4_0_0 EXIST::FUNCTION: +PKCS7_decrypt ? 4_0_0 EXIST::FUNCTION: +PKCS7_add_attrib_smimecap ? 4_0_0 EXIST::FUNCTION: +PKCS7_get_smimecap ? 4_0_0 EXIST::FUNCTION: +PKCS7_simple_smimecap ? 4_0_0 EXIST::FUNCTION: +PKCS7_add_attrib_content_type ? 4_0_0 EXIST::FUNCTION: +PKCS7_add0_attrib_signing_time ? 4_0_0 EXIST::FUNCTION: +PKCS7_add1_attrib_digest ? 4_0_0 EXIST::FUNCTION: +SMIME_write_PKCS7 ? 4_0_0 EXIST::FUNCTION: +SMIME_read_PKCS7_ex ? 4_0_0 EXIST::FUNCTION: +SMIME_read_PKCS7 ? 4_0_0 EXIST::FUNCTION: +BIO_new_PKCS7 ? 4_0_0 EXIST::FUNCTION: +SRP_user_pwd_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_user_pwd_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_user_pwd_set_gN ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_user_pwd_set1_ids ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_user_pwd_set0_sv ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_VBASE_new ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_VBASE_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_VBASE_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_VBASE_add0_user ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_VBASE_get1_by_user ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_create_verifier_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_create_verifier ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_create_verifier_BN_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_create_verifier_BN ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_check_known_gN_param ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_get_default_gN ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_Calc_server_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_Calc_B_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_Calc_B ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_Verify_A_mod_N ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_Calc_u_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_Calc_u ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_Calc_x_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_Calc_x ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_Calc_A ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_Calc_client_key_ex ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_Calc_client_key ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_Verify_B_mod_N ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_VBASE_get_by_user ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,SRP +UI_new ? 4_0_0 EXIST::FUNCTION: +UI_new_method ? 4_0_0 EXIST::FUNCTION: +UI_free ? 4_0_0 EXIST::FUNCTION: +UI_add_input_string ? 4_0_0 EXIST::FUNCTION: +UI_dup_input_string ? 4_0_0 EXIST::FUNCTION: +UI_add_verify_string ? 4_0_0 EXIST::FUNCTION: +UI_dup_verify_string ? 4_0_0 EXIST::FUNCTION: +UI_add_input_boolean ? 4_0_0 EXIST::FUNCTION: +UI_dup_input_boolean ? 4_0_0 EXIST::FUNCTION: +UI_add_info_string ? 4_0_0 EXIST::FUNCTION: +UI_dup_info_string ? 4_0_0 EXIST::FUNCTION: +UI_add_error_string ? 4_0_0 EXIST::FUNCTION: +UI_dup_error_string ? 4_0_0 EXIST::FUNCTION: +UI_construct_prompt ? 4_0_0 EXIST::FUNCTION: +UI_add_user_data ? 4_0_0 EXIST::FUNCTION: +UI_dup_user_data ? 4_0_0 EXIST::FUNCTION: +UI_get0_user_data ? 4_0_0 EXIST::FUNCTION: +UI_get0_result ? 4_0_0 EXIST::FUNCTION: +UI_get_result_length ? 4_0_0 EXIST::FUNCTION: +UI_process ? 4_0_0 EXIST::FUNCTION: +UI_ctrl ? 4_0_0 EXIST::FUNCTION: +UI_set_ex_data ? 4_0_0 EXIST::FUNCTION: +UI_get_ex_data ? 4_0_0 EXIST::FUNCTION: +UI_set_default_method ? 4_0_0 EXIST::FUNCTION: +UI_get_default_method ? 4_0_0 EXIST::FUNCTION: +UI_get_method ? 4_0_0 EXIST::FUNCTION: +UI_set_method ? 4_0_0 EXIST::FUNCTION: +UI_OpenSSL ? 4_0_0 EXIST::FUNCTION:UI_CONSOLE +UI_null ? 4_0_0 EXIST::FUNCTION: +UI_create_method ? 4_0_0 EXIST::FUNCTION: +UI_destroy_method ? 4_0_0 EXIST::FUNCTION: +UI_method_set_opener ? 4_0_0 EXIST::FUNCTION: +UI_method_set_writer ? 4_0_0 EXIST::FUNCTION: +UI_method_set_flusher ? 4_0_0 EXIST::FUNCTION: +UI_method_set_reader ? 4_0_0 EXIST::FUNCTION: +UI_method_set_closer ? 4_0_0 EXIST::FUNCTION: +UI_method_set_data_duplicator ? 4_0_0 EXIST::FUNCTION: +UI_method_set_prompt_constructor ? 4_0_0 EXIST::FUNCTION: +UI_method_set_ex_data ? 4_0_0 EXIST::FUNCTION: +UI_method_get_opener ? 4_0_0 EXIST::FUNCTION: +UI_method_get_writer ? 4_0_0 EXIST::FUNCTION: +UI_method_get_flusher ? 4_0_0 EXIST::FUNCTION: +UI_method_get_reader ? 4_0_0 EXIST::FUNCTION: +UI_method_get_closer ? 4_0_0 EXIST::FUNCTION: +UI_method_get_prompt_constructor ? 4_0_0 EXIST::FUNCTION: +UI_method_get_data_duplicator ? 4_0_0 EXIST::FUNCTION: +UI_method_get_data_destructor ? 4_0_0 EXIST::FUNCTION: +UI_method_get_ex_data ? 4_0_0 EXIST::FUNCTION: +UI_get_string_type ? 4_0_0 EXIST::FUNCTION: +UI_get_input_flags ? 4_0_0 EXIST::FUNCTION: +UI_get0_output_string ? 4_0_0 EXIST::FUNCTION: +UI_get0_action_string ? 4_0_0 EXIST::FUNCTION: +UI_get0_result_string ? 4_0_0 EXIST::FUNCTION: +UI_get_result_string_length ? 4_0_0 EXIST::FUNCTION: +UI_get0_test_string ? 4_0_0 EXIST::FUNCTION: +UI_get_result_minsize ? 4_0_0 EXIST::FUNCTION: +UI_get_result_maxsize ? 4_0_0 EXIST::FUNCTION: +UI_set_result ? 4_0_0 EXIST::FUNCTION: +UI_set_result_ex ? 4_0_0 EXIST::FUNCTION: +UI_UTIL_read_pw_string ? 4_0_0 EXIST::FUNCTION: +UI_UTIL_read_pw ? 4_0_0 EXIST::FUNCTION: +UI_UTIL_wrap_read_pem_callback ? 4_0_0 EXIST::FUNCTION: +X509_CRL_set_default_method ? 4_0_0 EXIST::FUNCTION: +X509_CRL_METHOD_new ? 4_0_0 EXIST::FUNCTION: +X509_CRL_METHOD_free ? 4_0_0 EXIST::FUNCTION: +X509_CRL_set_meth_data ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get_meth_data ? 4_0_0 EXIST::FUNCTION: +X509_verify_cert_error_string ? 4_0_0 EXIST::FUNCTION: +X509_verify ? 4_0_0 EXIST::FUNCTION: +X509_self_signed ? 4_0_0 EXIST::FUNCTION: +X509_REQ_verify_ex ? 4_0_0 EXIST::FUNCTION: +X509_REQ_verify ? 4_0_0 EXIST::FUNCTION: +X509_CRL_verify ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_SPKI_verify ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_SPKI_b64_decode ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_SPKI_b64_encode ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_SPKI_get_pubkey ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_SPKI_set_pubkey ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_SPKI_print ? 4_0_0 EXIST::FUNCTION: +X509_signature_dump ? 4_0_0 EXIST::FUNCTION: +X509_signature_print ? 4_0_0 EXIST::FUNCTION: +X509_sign ? 4_0_0 EXIST::FUNCTION: +X509_sign_ctx ? 4_0_0 EXIST::FUNCTION: +X509_REQ_sign ? 4_0_0 EXIST::FUNCTION: +X509_REQ_sign_ctx ? 4_0_0 EXIST::FUNCTION: +X509_CRL_sign ? 4_0_0 EXIST::FUNCTION: +X509_CRL_sign_ctx ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_SPKI_sign ? 4_0_0 EXIST::FUNCTION: +X509_pubkey_digest ? 4_0_0 EXIST::FUNCTION: +X509_digest ? 4_0_0 EXIST::FUNCTION: +X509_digest_sig ? 4_0_0 EXIST::FUNCTION: +X509_CRL_digest ? 4_0_0 EXIST::FUNCTION: +X509_REQ_digest ? 4_0_0 EXIST::FUNCTION: +X509_NAME_digest ? 4_0_0 EXIST::FUNCTION: +X509_load_http ? 4_0_0 EXIST::FUNCTION: +X509_CRL_load_http ? 4_0_0 EXIST::FUNCTION: +d2i_X509_fp ? 4_0_0 EXIST::FUNCTION:STDIO +i2d_X509_fp ? 4_0_0 EXIST::FUNCTION:STDIO +d2i_X509_CRL_fp ? 4_0_0 EXIST::FUNCTION:STDIO +i2d_X509_CRL_fp ? 4_0_0 EXIST::FUNCTION:STDIO +d2i_X509_REQ_fp ? 4_0_0 EXIST::FUNCTION:STDIO +i2d_X509_REQ_fp ? 4_0_0 EXIST::FUNCTION:STDIO +d2i_RSAPrivateKey_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO +i2d_RSAPrivateKey_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO +d2i_RSAPublicKey_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO +i2d_RSAPublicKey_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO +d2i_RSA_PUBKEY_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO +i2d_RSA_PUBKEY_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,STDIO +d2i_DSA_PUBKEY_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO +i2d_DSA_PUBKEY_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO +d2i_DSAPrivateKey_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO +i2d_DSAPrivateKey_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA,STDIO +d2i_EC_PUBKEY_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO +i2d_EC_PUBKEY_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO +d2i_ECPrivateKey_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO +i2d_ECPrivateKey_fp ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC,STDIO +d2i_PKCS8_fp ? 4_0_0 EXIST::FUNCTION:STDIO +i2d_PKCS8_fp ? 4_0_0 EXIST::FUNCTION:STDIO +d2i_X509_PUBKEY_fp ? 4_0_0 EXIST::FUNCTION:STDIO +i2d_X509_PUBKEY_fp ? 4_0_0 EXIST::FUNCTION:STDIO +d2i_PKCS8_PRIV_KEY_INFO_fp ? 4_0_0 EXIST::FUNCTION:STDIO +i2d_PKCS8_PRIV_KEY_INFO_fp ? 4_0_0 EXIST::FUNCTION:STDIO +i2d_PKCS8PrivateKeyInfo_fp ? 4_0_0 EXIST::FUNCTION:STDIO +i2d_PrivateKey_fp ? 4_0_0 EXIST::FUNCTION:STDIO +d2i_PrivateKey_ex_fp ? 4_0_0 EXIST::FUNCTION:STDIO +d2i_PrivateKey_fp ? 4_0_0 EXIST::FUNCTION:STDIO +i2d_PUBKEY_fp ? 4_0_0 EXIST::FUNCTION:STDIO +d2i_PUBKEY_ex_fp ? 4_0_0 EXIST::FUNCTION:STDIO +d2i_PUBKEY_fp ? 4_0_0 EXIST::FUNCTION:STDIO +d2i_X509_bio ? 4_0_0 EXIST::FUNCTION: +i2d_X509_bio ? 4_0_0 EXIST::FUNCTION: +d2i_X509_CRL_bio ? 4_0_0 EXIST::FUNCTION: +i2d_X509_CRL_bio ? 4_0_0 EXIST::FUNCTION: +d2i_X509_REQ_bio ? 4_0_0 EXIST::FUNCTION: +i2d_X509_REQ_bio ? 4_0_0 EXIST::FUNCTION: +d2i_RSAPrivateKey_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +i2d_RSAPrivateKey_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +d2i_RSAPublicKey_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +i2d_RSAPublicKey_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +d2i_RSA_PUBKEY_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +i2d_RSA_PUBKEY_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +d2i_DSA_PUBKEY_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +i2d_DSA_PUBKEY_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +d2i_DSAPrivateKey_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +i2d_DSAPrivateKey_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +d2i_EC_PUBKEY_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +i2d_EC_PUBKEY_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +d2i_ECPrivateKey_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +i2d_ECPrivateKey_bio ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +d2i_PKCS8_bio ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS8_bio ? 4_0_0 EXIST::FUNCTION: +d2i_X509_PUBKEY_bio ? 4_0_0 EXIST::FUNCTION: +i2d_X509_PUBKEY_bio ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS8_PRIV_KEY_INFO_bio ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS8_PRIV_KEY_INFO_bio ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS8PrivateKeyInfo_bio ? 4_0_0 EXIST::FUNCTION: +i2d_PrivateKey_bio ? 4_0_0 EXIST::FUNCTION: +d2i_PrivateKey_ex_bio ? 4_0_0 EXIST::FUNCTION: +d2i_PrivateKey_bio ? 4_0_0 EXIST::FUNCTION: +i2d_PUBKEY_bio ? 4_0_0 EXIST::FUNCTION: +d2i_PUBKEY_ex_bio ? 4_0_0 EXIST::FUNCTION: +d2i_PUBKEY_bio ? 4_0_0 EXIST::FUNCTION: +X509_dup ? 4_0_0 EXIST::FUNCTION: +X509_ALGOR_dup ? 4_0_0 EXIST::FUNCTION: +X509_ATTRIBUTE_dup ? 4_0_0 EXIST::FUNCTION: +X509_CRL_dup ? 4_0_0 EXIST::FUNCTION: +X509_EXTENSION_dup ? 4_0_0 EXIST::FUNCTION: +X509_PUBKEY_dup ? 4_0_0 EXIST::FUNCTION: +X509_REQ_dup ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_dup ? 4_0_0 EXIST::FUNCTION: +X509_ALGOR_set0 ? 4_0_0 EXIST::FUNCTION: +X509_ALGOR_get0 ? 4_0_0 EXIST::FUNCTION: +X509_ALGOR_set_md ? 4_0_0 EXIST::FUNCTION: +X509_ALGOR_cmp ? 4_0_0 EXIST::FUNCTION: +X509_ALGOR_copy ? 4_0_0 EXIST::FUNCTION: +X509_NAME_dup ? 4_0_0 EXIST::FUNCTION: +X509_NAME_ENTRY_dup ? 4_0_0 EXIST::FUNCTION: +X509_cmp_time ? 4_0_0 EXIST::FUNCTION: +X509_cmp_current_time ? 4_0_0 EXIST::FUNCTION: +X509_cmp_timeframe ? 4_0_0 EXIST::FUNCTION: +X509_time_adj ? 4_0_0 EXIST::FUNCTION: +X509_time_adj_ex ? 4_0_0 EXIST::FUNCTION: +X509_gmtime_adj ? 4_0_0 EXIST::FUNCTION: +X509_get_default_cert_area ? 4_0_0 EXIST::FUNCTION: +X509_get_default_cert_dir ? 4_0_0 EXIST::FUNCTION: +X509_get_default_cert_file ? 4_0_0 EXIST::FUNCTION: +X509_get_default_cert_dir_env ? 4_0_0 EXIST::FUNCTION: +X509_get_default_cert_file_env ? 4_0_0 EXIST::FUNCTION: +X509_get_default_private_dir ? 4_0_0 EXIST::FUNCTION: +X509_to_X509_REQ ? 4_0_0 EXIST::FUNCTION: +X509_REQ_to_X509 ? 4_0_0 EXIST::FUNCTION: +d2i_X509_ALGOR ? 4_0_0 EXIST::FUNCTION: +i2d_X509_ALGOR ? 4_0_0 EXIST::FUNCTION: +X509_ALGOR_free ? 4_0_0 EXIST::FUNCTION: +X509_ALGOR_new ? 4_0_0 EXIST::FUNCTION: +X509_ALGOR_it ? 4_0_0 EXIST::FUNCTION: +d2i_X509_ALGORS ? 4_0_0 EXIST::FUNCTION: +i2d_X509_ALGORS ? 4_0_0 EXIST::FUNCTION: +X509_ALGORS_it ? 4_0_0 EXIST::FUNCTION: +d2i_X509_VAL ? 4_0_0 EXIST::FUNCTION: +i2d_X509_VAL ? 4_0_0 EXIST::FUNCTION: +X509_VAL_free ? 4_0_0 EXIST::FUNCTION: +X509_VAL_new ? 4_0_0 EXIST::FUNCTION: +X509_VAL_it ? 4_0_0 EXIST::FUNCTION: +d2i_X509_PUBKEY ? 4_0_0 EXIST::FUNCTION: +i2d_X509_PUBKEY ? 4_0_0 EXIST::FUNCTION: +X509_PUBKEY_free ? 4_0_0 EXIST::FUNCTION: +X509_PUBKEY_new ? 4_0_0 EXIST::FUNCTION: +X509_PUBKEY_it ? 4_0_0 EXIST::FUNCTION: +X509_PUBKEY_new_ex ? 4_0_0 EXIST::FUNCTION: +X509_PUBKEY_set ? 4_0_0 EXIST::FUNCTION: +X509_PUBKEY_get0 ? 4_0_0 EXIST::FUNCTION: +X509_PUBKEY_get ? 4_0_0 EXIST::FUNCTION: +X509_get_pubkey_parameters ? 4_0_0 EXIST::FUNCTION: +X509_get_pathlen ? 4_0_0 EXIST::FUNCTION: +d2i_PUBKEY ? 4_0_0 EXIST::FUNCTION: +i2d_PUBKEY ? 4_0_0 EXIST::FUNCTION: +d2i_PUBKEY_ex ? 4_0_0 EXIST::FUNCTION: +d2i_RSA_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +i2d_RSA_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +d2i_DSA_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +i2d_DSA_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DSA +d2i_EC_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +i2d_EC_PUBKEY ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,EC +d2i_X509_SIG ? 4_0_0 EXIST::FUNCTION: +i2d_X509_SIG ? 4_0_0 EXIST::FUNCTION: +X509_SIG_free ? 4_0_0 EXIST::FUNCTION: +X509_SIG_new ? 4_0_0 EXIST::FUNCTION: +X509_SIG_it ? 4_0_0 EXIST::FUNCTION: +X509_SIG_get0 ? 4_0_0 EXIST::FUNCTION: +X509_SIG_getm ? 4_0_0 EXIST::FUNCTION: +d2i_X509_REQ_INFO ? 4_0_0 EXIST::FUNCTION: +i2d_X509_REQ_INFO ? 4_0_0 EXIST::FUNCTION: +X509_REQ_INFO_free ? 4_0_0 EXIST::FUNCTION: +X509_REQ_INFO_new ? 4_0_0 EXIST::FUNCTION: +X509_REQ_INFO_it ? 4_0_0 EXIST::FUNCTION: +d2i_X509_REQ ? 4_0_0 EXIST::FUNCTION: +i2d_X509_REQ ? 4_0_0 EXIST::FUNCTION: +X509_REQ_free ? 4_0_0 EXIST::FUNCTION: +X509_REQ_new ? 4_0_0 EXIST::FUNCTION: +X509_REQ_it ? 4_0_0 EXIST::FUNCTION: +X509_REQ_new_ex ? 4_0_0 EXIST::FUNCTION: +d2i_X509_ATTRIBUTE ? 4_0_0 EXIST::FUNCTION: +i2d_X509_ATTRIBUTE ? 4_0_0 EXIST::FUNCTION: +X509_ATTRIBUTE_free ? 4_0_0 EXIST::FUNCTION: +X509_ATTRIBUTE_new ? 4_0_0 EXIST::FUNCTION: +X509_ATTRIBUTE_it ? 4_0_0 EXIST::FUNCTION: +X509_ATTRIBUTE_create ? 4_0_0 EXIST::FUNCTION: +d2i_X509_EXTENSION ? 4_0_0 EXIST::FUNCTION: +i2d_X509_EXTENSION ? 4_0_0 EXIST::FUNCTION: +X509_EXTENSION_free ? 4_0_0 EXIST::FUNCTION: +X509_EXTENSION_new ? 4_0_0 EXIST::FUNCTION: +X509_EXTENSION_it ? 4_0_0 EXIST::FUNCTION: +d2i_X509_EXTENSIONS ? 4_0_0 EXIST::FUNCTION: +i2d_X509_EXTENSIONS ? 4_0_0 EXIST::FUNCTION: +X509_EXTENSIONS_it ? 4_0_0 EXIST::FUNCTION: +d2i_X509_NAME_ENTRY ? 4_0_0 EXIST::FUNCTION: +i2d_X509_NAME_ENTRY ? 4_0_0 EXIST::FUNCTION: +X509_NAME_ENTRY_free ? 4_0_0 EXIST::FUNCTION: +X509_NAME_ENTRY_new ? 4_0_0 EXIST::FUNCTION: +X509_NAME_ENTRY_it ? 4_0_0 EXIST::FUNCTION: +d2i_X509_NAME ? 4_0_0 EXIST::FUNCTION: +i2d_X509_NAME ? 4_0_0 EXIST::FUNCTION: +X509_NAME_free ? 4_0_0 EXIST::FUNCTION: +X509_NAME_new ? 4_0_0 EXIST::FUNCTION: +X509_NAME_it ? 4_0_0 EXIST::FUNCTION: +X509_NAME_set ? 4_0_0 EXIST::FUNCTION: +d2i_X509_CINF ? 4_0_0 EXIST::FUNCTION: +i2d_X509_CINF ? 4_0_0 EXIST::FUNCTION: +X509_CINF_free ? 4_0_0 EXIST::FUNCTION: +X509_CINF_new ? 4_0_0 EXIST::FUNCTION: +X509_CINF_it ? 4_0_0 EXIST::FUNCTION: +d2i_X509 ? 4_0_0 EXIST::FUNCTION: +i2d_X509 ? 4_0_0 EXIST::FUNCTION: +X509_free ? 4_0_0 EXIST::FUNCTION: +X509_new ? 4_0_0 EXIST::FUNCTION: +X509_it ? 4_0_0 EXIST::FUNCTION: +X509_new_ex ? 4_0_0 EXIST::FUNCTION: +d2i_X509_CERT_AUX ? 4_0_0 EXIST::FUNCTION: +i2d_X509_CERT_AUX ? 4_0_0 EXIST::FUNCTION: +X509_CERT_AUX_free ? 4_0_0 EXIST::FUNCTION: +X509_CERT_AUX_new ? 4_0_0 EXIST::FUNCTION: +X509_CERT_AUX_it ? 4_0_0 EXIST::FUNCTION: +X509_set_ex_data ? 4_0_0 EXIST::FUNCTION: +X509_get_ex_data ? 4_0_0 EXIST::FUNCTION: +d2i_X509_AUX ? 4_0_0 EXIST::FUNCTION: +i2d_X509_AUX ? 4_0_0 EXIST::FUNCTION: +i2d_re_X509_tbs ? 4_0_0 EXIST::FUNCTION: +X509_SIG_INFO_get ? 4_0_0 EXIST::FUNCTION: +X509_SIG_INFO_set ? 4_0_0 EXIST::FUNCTION: +X509_get_signature_info ? 4_0_0 EXIST::FUNCTION: +X509_get0_signature ? 4_0_0 EXIST::FUNCTION: +X509_get_signature_nid ? 4_0_0 EXIST::FUNCTION: +X509_set0_distinguishing_id ? 4_0_0 EXIST::FUNCTION: +X509_get0_distinguishing_id ? 4_0_0 EXIST::FUNCTION: +X509_REQ_set0_distinguishing_id ? 4_0_0 EXIST::FUNCTION: +X509_REQ_get0_distinguishing_id ? 4_0_0 EXIST::FUNCTION: +X509_alias_set1 ? 4_0_0 EXIST::FUNCTION: +X509_keyid_set1 ? 4_0_0 EXIST::FUNCTION: +X509_alias_get0 ? 4_0_0 EXIST::FUNCTION: +X509_keyid_get0 ? 4_0_0 EXIST::FUNCTION: +d2i_X509_REVOKED ? 4_0_0 EXIST::FUNCTION: +i2d_X509_REVOKED ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_free ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_new ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_it ? 4_0_0 EXIST::FUNCTION: +d2i_X509_CRL_INFO ? 4_0_0 EXIST::FUNCTION: +i2d_X509_CRL_INFO ? 4_0_0 EXIST::FUNCTION: +X509_CRL_INFO_free ? 4_0_0 EXIST::FUNCTION: +X509_CRL_INFO_new ? 4_0_0 EXIST::FUNCTION: +X509_CRL_INFO_it ? 4_0_0 EXIST::FUNCTION: +d2i_X509_CRL ? 4_0_0 EXIST::FUNCTION: +i2d_X509_CRL ? 4_0_0 EXIST::FUNCTION: +X509_CRL_free ? 4_0_0 EXIST::FUNCTION: +X509_CRL_new ? 4_0_0 EXIST::FUNCTION: +X509_CRL_it ? 4_0_0 EXIST::FUNCTION: +X509_CRL_new_ex ? 4_0_0 EXIST::FUNCTION: +X509_CRL_add0_revoked ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get0_by_serial ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get0_by_cert ? 4_0_0 EXIST::FUNCTION: +X509_PKEY_new ? 4_0_0 EXIST::FUNCTION: +X509_PKEY_free ? 4_0_0 EXIST::FUNCTION: +d2i_NETSCAPE_SPKI ? 4_0_0 EXIST::FUNCTION: +i2d_NETSCAPE_SPKI ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_SPKI_free ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_SPKI_new ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_SPKI_it ? 4_0_0 EXIST::FUNCTION: +d2i_NETSCAPE_SPKAC ? 4_0_0 EXIST::FUNCTION: +i2d_NETSCAPE_SPKAC ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_SPKAC_free ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_SPKAC_new ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_SPKAC_it ? 4_0_0 EXIST::FUNCTION: +d2i_NETSCAPE_CERT_SEQUENCE ? 4_0_0 EXIST::FUNCTION: +i2d_NETSCAPE_CERT_SEQUENCE ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_CERT_SEQUENCE_free ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_CERT_SEQUENCE_new ? 4_0_0 EXIST::FUNCTION: +NETSCAPE_CERT_SEQUENCE_it ? 4_0_0 EXIST::FUNCTION: +X509_INFO_new ? 4_0_0 EXIST::FUNCTION: +X509_INFO_free ? 4_0_0 EXIST::FUNCTION: +X509_NAME_oneline ? 4_0_0 EXIST::FUNCTION: +ASN1_verify ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ASN1_digest ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ASN1_sign ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +ASN1_item_digest ? 4_0_0 EXIST::FUNCTION: +ASN1_item_verify ? 4_0_0 EXIST::FUNCTION: +ASN1_item_verify_ctx ? 4_0_0 EXIST::FUNCTION: +ASN1_item_sign ? 4_0_0 EXIST::FUNCTION: +ASN1_item_sign_ctx ? 4_0_0 EXIST::FUNCTION: +X509_get_version ? 4_0_0 EXIST::FUNCTION: +X509_set_version ? 4_0_0 EXIST::FUNCTION: +X509_set_serialNumber ? 4_0_0 EXIST::FUNCTION: +X509_get_serialNumber ? 4_0_0 EXIST::FUNCTION: +X509_get0_serialNumber ? 4_0_0 EXIST::FUNCTION: +X509_set_issuer_name ? 4_0_0 EXIST::FUNCTION: +X509_get_issuer_name ? 4_0_0 EXIST::FUNCTION: +X509_set_subject_name ? 4_0_0 EXIST::FUNCTION: +X509_get_subject_name ? 4_0_0 EXIST::FUNCTION: +X509_get0_notBefore ? 4_0_0 EXIST::FUNCTION: +X509_getm_notBefore ? 4_0_0 EXIST::FUNCTION: +X509_set1_notBefore ? 4_0_0 EXIST::FUNCTION: +X509_get0_notAfter ? 4_0_0 EXIST::FUNCTION: +X509_getm_notAfter ? 4_0_0 EXIST::FUNCTION: +X509_set1_notAfter ? 4_0_0 EXIST::FUNCTION: +X509_up_ref ? 4_0_0 EXIST::FUNCTION: +X509_get_signature_type ? 4_0_0 EXIST::FUNCTION: +X509_set_pubkey ? 4_0_0 EXIST::FUNCTION: +X509_get_pubkey ? 4_0_0 EXIST::FUNCTION: +X509_get0_pubkey ? 4_0_0 EXIST::FUNCTION: +X509_get_X509_PUBKEY ? 4_0_0 EXIST::FUNCTION: +X509_get0_extensions ? 4_0_0 EXIST::FUNCTION: +X509_get0_uids ? 4_0_0 EXIST::FUNCTION: +X509_get0_tbs_sigalg ? 4_0_0 EXIST::FUNCTION: +X509_get0_pubkey_bitstr ? 4_0_0 EXIST::FUNCTION: +X509_REQ_get_version ? 4_0_0 EXIST::FUNCTION: +X509_REQ_set_version ? 4_0_0 EXIST::FUNCTION: +X509_REQ_get_subject_name ? 4_0_0 EXIST::FUNCTION: +X509_REQ_set_subject_name ? 4_0_0 EXIST::FUNCTION: +X509_REQ_get0_signature ? 4_0_0 EXIST::FUNCTION: +X509_REQ_set0_signature ? 4_0_0 EXIST::FUNCTION: +X509_REQ_set1_signature_algo ? 4_0_0 EXIST::FUNCTION: +X509_REQ_get_signature_nid ? 4_0_0 EXIST::FUNCTION: +i2d_re_X509_REQ_tbs ? 4_0_0 EXIST::FUNCTION: +X509_REQ_set_pubkey ? 4_0_0 EXIST::FUNCTION: +X509_REQ_get_pubkey ? 4_0_0 EXIST::FUNCTION: +X509_REQ_get0_pubkey ? 4_0_0 EXIST::FUNCTION: +X509_REQ_get_X509_PUBKEY ? 4_0_0 EXIST::FUNCTION: +X509_REQ_extension_nid ? 4_0_0 EXIST::FUNCTION: +X509_REQ_get_extension_nids ? 4_0_0 EXIST::FUNCTION: +X509_REQ_set_extension_nids ? 4_0_0 EXIST::FUNCTION: +X509_REQ_get_extensions ? 4_0_0 EXIST::FUNCTION: +X509_REQ_add_extensions_nid ? 4_0_0 EXIST::FUNCTION: +X509_REQ_add_extensions ? 4_0_0 EXIST::FUNCTION: +X509_REQ_get_attr_count ? 4_0_0 EXIST::FUNCTION: +X509_REQ_get_attr_by_NID ? 4_0_0 EXIST::FUNCTION: +X509_REQ_get_attr_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509_REQ_get_attr ? 4_0_0 EXIST::FUNCTION: +X509_REQ_delete_attr ? 4_0_0 EXIST::FUNCTION: +X509_REQ_add1_attr ? 4_0_0 EXIST::FUNCTION: +X509_REQ_add1_attr_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509_REQ_add1_attr_by_NID ? 4_0_0 EXIST::FUNCTION: +X509_REQ_add1_attr_by_txt ? 4_0_0 EXIST::FUNCTION: +X509_CRL_set_version ? 4_0_0 EXIST::FUNCTION: +X509_CRL_set_issuer_name ? 4_0_0 EXIST::FUNCTION: +X509_CRL_set1_lastUpdate ? 4_0_0 EXIST::FUNCTION: +X509_CRL_set1_nextUpdate ? 4_0_0 EXIST::FUNCTION: +X509_CRL_sort ? 4_0_0 EXIST::FUNCTION: +X509_CRL_up_ref ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get_version ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get0_lastUpdate ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get0_nextUpdate ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get_lastUpdate ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0 +X509_CRL_get_nextUpdate ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0 +X509_CRL_get_issuer ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get0_extensions ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get_REVOKED ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get0_tbs_sigalg ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get0_signature ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get_signature_nid ? 4_0_0 EXIST::FUNCTION: +i2d_re_X509_CRL_tbs ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_get0_serialNumber ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_set_serialNumber ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_get0_revocationDate ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_set_revocationDate ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_get0_extensions ? 4_0_0 EXIST::FUNCTION: +X509_CRL_diff ? 4_0_0 EXIST::FUNCTION: +X509_REQ_check_private_key ? 4_0_0 EXIST::FUNCTION: +X509_check_private_key ? 4_0_0 EXIST::FUNCTION: +X509_chain_check_suiteb ? 4_0_0 EXIST::FUNCTION: +X509_CRL_check_suiteb ? 4_0_0 EXIST::FUNCTION: +OSSL_STACK_OF_X509_free ? 4_0_0 EXIST::FUNCTION: +X509_chain_up_ref ? 4_0_0 EXIST::FUNCTION: +X509_issuer_and_serial_cmp ? 4_0_0 EXIST::FUNCTION: +X509_issuer_and_serial_hash ? 4_0_0 EXIST::FUNCTION: +X509_issuer_name_cmp ? 4_0_0 EXIST::FUNCTION: +X509_issuer_name_hash ? 4_0_0 EXIST::FUNCTION: +X509_subject_name_cmp ? 4_0_0 EXIST::FUNCTION: +X509_subject_name_hash ? 4_0_0 EXIST::FUNCTION: +X509_issuer_name_hash_old ? 4_0_0 EXIST::FUNCTION:MD5 +X509_subject_name_hash_old ? 4_0_0 EXIST::FUNCTION:MD5 +X509_add_cert ? 4_0_0 EXIST::FUNCTION: +X509_add_certs ? 4_0_0 EXIST::FUNCTION: +X509_cmp ? 4_0_0 EXIST::FUNCTION: +X509_NAME_cmp ? 4_0_0 EXIST::FUNCTION: +X509_certificate_type ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +X509_NAME_hash_ex ? 4_0_0 EXIST::FUNCTION: +X509_NAME_hash_old ? 4_0_0 EXIST::FUNCTION: +X509_CRL_cmp ? 4_0_0 EXIST::FUNCTION: +X509_CRL_match ? 4_0_0 EXIST::FUNCTION: +X509_aux_print ? 4_0_0 EXIST::FUNCTION: +X509_print_ex_fp ? 4_0_0 EXIST::FUNCTION:STDIO +X509_print_fp ? 4_0_0 EXIST::FUNCTION:STDIO +X509_CRL_print_fp ? 4_0_0 EXIST::FUNCTION:STDIO +X509_REQ_print_fp ? 4_0_0 EXIST::FUNCTION:STDIO +X509_NAME_print_ex_fp ? 4_0_0 EXIST::FUNCTION:STDIO +X509_NAME_print ? 4_0_0 EXIST::FUNCTION: +X509_NAME_print_ex ? 4_0_0 EXIST::FUNCTION: +X509_print_ex ? 4_0_0 EXIST::FUNCTION: +X509_print ? 4_0_0 EXIST::FUNCTION: +X509_ocspid_print ? 4_0_0 EXIST::FUNCTION: +X509_CRL_print_ex ? 4_0_0 EXIST::FUNCTION: +X509_CRL_print ? 4_0_0 EXIST::FUNCTION: +X509_REQ_print_ex ? 4_0_0 EXIST::FUNCTION: +X509_REQ_print ? 4_0_0 EXIST::FUNCTION: +X509_NAME_entry_count ? 4_0_0 EXIST::FUNCTION: +X509_NAME_get_text_by_NID ? 4_0_0 EXIST::FUNCTION: +X509_NAME_get_text_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509_NAME_get_index_by_NID ? 4_0_0 EXIST::FUNCTION: +X509_NAME_get_index_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509_NAME_get_entry ? 4_0_0 EXIST::FUNCTION: +X509_NAME_delete_entry ? 4_0_0 EXIST::FUNCTION: +X509_NAME_add_entry ? 4_0_0 EXIST::FUNCTION: +X509_NAME_add_entry_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509_NAME_add_entry_by_NID ? 4_0_0 EXIST::FUNCTION: +X509_NAME_ENTRY_create_by_txt ? 4_0_0 EXIST::FUNCTION: +X509_NAME_ENTRY_create_by_NID ? 4_0_0 EXIST::FUNCTION: +X509_NAME_add_entry_by_txt ? 4_0_0 EXIST::FUNCTION: +X509_NAME_ENTRY_create_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509_NAME_ENTRY_set_object ? 4_0_0 EXIST::FUNCTION: +X509_NAME_ENTRY_set_data ? 4_0_0 EXIST::FUNCTION: +X509_NAME_ENTRY_get_object ? 4_0_0 EXIST::FUNCTION: +X509_NAME_ENTRY_get_data ? 4_0_0 EXIST::FUNCTION: +X509_NAME_ENTRY_set ? 4_0_0 EXIST::FUNCTION: +X509_NAME_get0_der ? 4_0_0 EXIST::FUNCTION: +X509v3_get_ext_count ? 4_0_0 EXIST::FUNCTION: +X509v3_get_ext_by_NID ? 4_0_0 EXIST::FUNCTION: +X509v3_get_ext_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509v3_get_ext_by_critical ? 4_0_0 EXIST::FUNCTION: +X509v3_get_ext ? 4_0_0 EXIST::FUNCTION: +X509v3_delete_ext ? 4_0_0 EXIST::FUNCTION: +X509v3_add_ext ? 4_0_0 EXIST::FUNCTION: +X509v3_add_extensions ? 4_0_0 EXIST::FUNCTION: +X509_get_ext_count ? 4_0_0 EXIST::FUNCTION: +X509_get_ext_by_NID ? 4_0_0 EXIST::FUNCTION: +X509_get_ext_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509_get_ext_by_critical ? 4_0_0 EXIST::FUNCTION: +X509_get_ext ? 4_0_0 EXIST::FUNCTION: +X509_delete_ext ? 4_0_0 EXIST::FUNCTION: +X509_add_ext ? 4_0_0 EXIST::FUNCTION: +X509_get_ext_d2i ? 4_0_0 EXIST::FUNCTION: +X509_add1_ext_i2d ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get_ext_count ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get_ext_by_NID ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get_ext_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get_ext_by_critical ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get_ext ? 4_0_0 EXIST::FUNCTION: +X509_CRL_delete_ext ? 4_0_0 EXIST::FUNCTION: +X509_CRL_add_ext ? 4_0_0 EXIST::FUNCTION: +X509_CRL_get_ext_d2i ? 4_0_0 EXIST::FUNCTION: +X509_CRL_add1_ext_i2d ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_get_ext_count ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_get_ext_by_NID ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_get_ext_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_get_ext_by_critical ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_get_ext ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_delete_ext ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_add_ext ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_get_ext_d2i ? 4_0_0 EXIST::FUNCTION: +X509_REVOKED_add1_ext_i2d ? 4_0_0 EXIST::FUNCTION: +X509_EXTENSION_create_by_NID ? 4_0_0 EXIST::FUNCTION: +X509_EXTENSION_create_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509_EXTENSION_set_object ? 4_0_0 EXIST::FUNCTION: +X509_EXTENSION_set_critical ? 4_0_0 EXIST::FUNCTION: +X509_EXTENSION_set_data ? 4_0_0 EXIST::FUNCTION: +X509_EXTENSION_get_object ? 4_0_0 EXIST::FUNCTION: +X509_EXTENSION_get_data ? 4_0_0 EXIST::FUNCTION: +X509_EXTENSION_get_critical ? 4_0_0 EXIST::FUNCTION: +X509at_get_attr_count ? 4_0_0 EXIST::FUNCTION: +X509at_get_attr_by_NID ? 4_0_0 EXIST::FUNCTION: +X509at_get_attr_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509at_get_attr ? 4_0_0 EXIST::FUNCTION: +X509at_delete_attr ? 4_0_0 EXIST::FUNCTION: +X509at_add1_attr ? 4_0_0 EXIST::FUNCTION: +X509at_add1_attr_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509at_add1_attr_by_NID ? 4_0_0 EXIST::FUNCTION: +X509at_add1_attr_by_txt ? 4_0_0 EXIST::FUNCTION: +X509at_get0_data_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509_ATTRIBUTE_create_by_NID ? 4_0_0 EXIST::FUNCTION: +X509_ATTRIBUTE_create_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509_ATTRIBUTE_create_by_txt ? 4_0_0 EXIST::FUNCTION: +X509_ATTRIBUTE_set1_object ? 4_0_0 EXIST::FUNCTION: +X509_ATTRIBUTE_set1_data ? 4_0_0 EXIST::FUNCTION: +X509_ATTRIBUTE_get0_data ? 4_0_0 EXIST::FUNCTION: +X509_ATTRIBUTE_count ? 4_0_0 EXIST::FUNCTION: +X509_ATTRIBUTE_get0_object ? 4_0_0 EXIST::FUNCTION: +X509_ATTRIBUTE_get0_type ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_attr_count ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_attr_by_NID ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_attr_by_OBJ ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_get_attr ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_delete_attr ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_add1_attr ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_add1_attr_by_OBJ ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_add1_attr_by_NID ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY_add1_attr_by_txt ? 4_0_0 EXIST::FUNCTION: +X509_find_by_issuer_and_serial ? 4_0_0 EXIST::FUNCTION: +X509_find_by_subject ? 4_0_0 EXIST::FUNCTION: +d2i_PBEPARAM ? 4_0_0 EXIST::FUNCTION: +i2d_PBEPARAM ? 4_0_0 EXIST::FUNCTION: +PBEPARAM_free ? 4_0_0 EXIST::FUNCTION: +PBEPARAM_new ? 4_0_0 EXIST::FUNCTION: +PBEPARAM_it ? 4_0_0 EXIST::FUNCTION: +d2i_PBE2PARAM ? 4_0_0 EXIST::FUNCTION: +i2d_PBE2PARAM ? 4_0_0 EXIST::FUNCTION: +PBE2PARAM_free ? 4_0_0 EXIST::FUNCTION: +PBE2PARAM_new ? 4_0_0 EXIST::FUNCTION: +PBE2PARAM_it ? 4_0_0 EXIST::FUNCTION: +d2i_PBKDF2PARAM ? 4_0_0 EXIST::FUNCTION: +i2d_PBKDF2PARAM ? 4_0_0 EXIST::FUNCTION: +PBKDF2PARAM_free ? 4_0_0 EXIST::FUNCTION: +PBKDF2PARAM_new ? 4_0_0 EXIST::FUNCTION: +PBKDF2PARAM_it ? 4_0_0 EXIST::FUNCTION: +d2i_PBMAC1PARAM ? 4_0_0 EXIST::FUNCTION: +i2d_PBMAC1PARAM ? 4_0_0 EXIST::FUNCTION: +PBMAC1PARAM_free ? 4_0_0 EXIST::FUNCTION: +PBMAC1PARAM_new ? 4_0_0 EXIST::FUNCTION: +PBMAC1PARAM_it ? 4_0_0 EXIST::FUNCTION: +d2i_SCRYPT_PARAMS ? 4_0_0 EXIST::FUNCTION:SCRYPT +i2d_SCRYPT_PARAMS ? 4_0_0 EXIST::FUNCTION:SCRYPT +SCRYPT_PARAMS_free ? 4_0_0 EXIST::FUNCTION:SCRYPT +SCRYPT_PARAMS_new ? 4_0_0 EXIST::FUNCTION:SCRYPT +SCRYPT_PARAMS_it ? 4_0_0 EXIST::FUNCTION:SCRYPT +PKCS5_pbe_set0_algor ? 4_0_0 EXIST::FUNCTION: +PKCS5_pbe_set0_algor_ex ? 4_0_0 EXIST::FUNCTION: +PKCS5_pbe_set ? 4_0_0 EXIST::FUNCTION: +PKCS5_pbe_set_ex ? 4_0_0 EXIST::FUNCTION: +PKCS5_pbe2_set ? 4_0_0 EXIST::FUNCTION: +PKCS5_pbe2_set_iv ? 4_0_0 EXIST::FUNCTION: +PKCS5_pbe2_set_iv_ex ? 4_0_0 EXIST::FUNCTION: +PKCS5_pbe2_set_scrypt ? 4_0_0 EXIST::FUNCTION:SCRYPT +PKCS5_pbkdf2_set ? 4_0_0 EXIST::FUNCTION: +PKCS5_pbkdf2_set_ex ? 4_0_0 EXIST::FUNCTION: +PBMAC1_get1_pbkdf2_param ? 4_0_0 EXIST::FUNCTION: +d2i_PKCS8_PRIV_KEY_INFO ? 4_0_0 EXIST::FUNCTION: +i2d_PKCS8_PRIV_KEY_INFO ? 4_0_0 EXIST::FUNCTION: +PKCS8_PRIV_KEY_INFO_free ? 4_0_0 EXIST::FUNCTION: +PKCS8_PRIV_KEY_INFO_new ? 4_0_0 EXIST::FUNCTION: +PKCS8_PRIV_KEY_INFO_it ? 4_0_0 EXIST::FUNCTION: +EVP_PKCS82PKEY ? 4_0_0 EXIST::FUNCTION: +EVP_PKCS82PKEY_ex ? 4_0_0 EXIST::FUNCTION: +EVP_PKEY2PKCS8 ? 4_0_0 EXIST::FUNCTION: +PKCS8_pkey_set0 ? 4_0_0 EXIST::FUNCTION: +PKCS8_pkey_get0 ? 4_0_0 EXIST::FUNCTION: +PKCS8_pkey_get0_attrs ? 4_0_0 EXIST::FUNCTION: +PKCS8_pkey_add1_attr ? 4_0_0 EXIST::FUNCTION: +PKCS8_pkey_add1_attr_by_NID ? 4_0_0 EXIST::FUNCTION: +PKCS8_pkey_add1_attr_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509_PUBKEY_set0_public_key ? 4_0_0 EXIST::FUNCTION: +X509_PUBKEY_set0_param ? 4_0_0 EXIST::FUNCTION: +X509_PUBKEY_get0_param ? 4_0_0 EXIST::FUNCTION: +X509_PUBKEY_eq ? 4_0_0 EXIST::FUNCTION: +d2i_X509_ACERT ? 4_0_0 EXIST::FUNCTION: +i2d_X509_ACERT ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_free ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_new ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_it ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_dup ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_INFO_it ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_INFO_free ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_INFO_new ? 4_0_0 EXIST::FUNCTION: +OSSL_OBJECT_DIGEST_INFO_free ? 4_0_0 EXIST::FUNCTION: +OSSL_OBJECT_DIGEST_INFO_new ? 4_0_0 EXIST::FUNCTION: +OSSL_ISSUER_SERIAL_free ? 4_0_0 EXIST::FUNCTION: +OSSL_ISSUER_SERIAL_new ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_ISSUER_V2FORM_free ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_ISSUER_V2FORM_new ? 4_0_0 EXIST::FUNCTION: +d2i_X509_ACERT_fp ? 4_0_0 EXIST::FUNCTION:STDIO +i2d_X509_ACERT_fp ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_X509_ACERT ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_X509_ACERT ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_bio_X509_ACERT ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_X509_ACERT ? 4_0_0 EXIST::FUNCTION: +d2i_X509_ACERT_bio ? 4_0_0 EXIST::FUNCTION: +i2d_X509_ACERT_bio ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_sign ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_sign_ctx ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_verify ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get0_holder_entityName ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get0_holder_baseCertId ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get0_holder_digest ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get0_issuerName ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get_version ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get0_signature ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get_signature_nid ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get0_info_sigalg ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get0_serialNumber ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get0_notBefore ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get0_notAfter ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get0_issuerUID ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_print ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_print_ex ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get_attr_count ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get_attr_by_NID ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get_attr_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get_attr ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_delete_attr ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get_ext_d2i ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_add1_ext_i2d ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_get0_extensions ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_set_version ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_set0_holder_entityName ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_set0_holder_baseCertId ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_set0_holder_digest ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_add1_attr ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_add1_attr_by_OBJ ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_add1_attr_by_NID ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_add1_attr_by_txt ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_add_attr_nconf ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_set1_issuerName ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_set1_serialNumber ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_set1_notBefore ? 4_0_0 EXIST::FUNCTION: +X509_ACERT_set1_notAfter ? 4_0_0 EXIST::FUNCTION: +OSSL_OBJECT_DIGEST_INFO_get0_digest ? 4_0_0 EXIST::FUNCTION: +OSSL_OBJECT_DIGEST_INFO_set1_digest ? 4_0_0 EXIST::FUNCTION: +OSSL_ISSUER_SERIAL_get0_issuer ? 4_0_0 EXIST::FUNCTION: +OSSL_ISSUER_SERIAL_get0_serial ? 4_0_0 EXIST::FUNCTION: +OSSL_ISSUER_SERIAL_get0_issuerUID ? 4_0_0 EXIST::FUNCTION: +OSSL_ISSUER_SERIAL_set1_issuer ? 4_0_0 EXIST::FUNCTION: +OSSL_ISSUER_SERIAL_set1_serial ? 4_0_0 EXIST::FUNCTION: +OSSL_ISSUER_SERIAL_set1_issuerUID ? 4_0_0 EXIST::FUNCTION: +OSSL_IETF_ATTR_SYNTAX_VALUE_it ? 4_0_0 EXIST::FUNCTION: +OSSL_IETF_ATTR_SYNTAX_VALUE_free ? 4_0_0 EXIST::FUNCTION: +OSSL_IETF_ATTR_SYNTAX_VALUE_new ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_IETF_ATTR_SYNTAX ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_IETF_ATTR_SYNTAX ? 4_0_0 EXIST::FUNCTION: +OSSL_IETF_ATTR_SYNTAX_free ? 4_0_0 EXIST::FUNCTION: +OSSL_IETF_ATTR_SYNTAX_new ? 4_0_0 EXIST::FUNCTION: +OSSL_IETF_ATTR_SYNTAX_it ? 4_0_0 EXIST::FUNCTION: +OSSL_IETF_ATTR_SYNTAX_get0_policyAuthority ? 4_0_0 EXIST::FUNCTION: +OSSL_IETF_ATTR_SYNTAX_set0_policyAuthority ? 4_0_0 EXIST::FUNCTION: +OSSL_IETF_ATTR_SYNTAX_get_value_num ? 4_0_0 EXIST::FUNCTION: +OSSL_IETF_ATTR_SYNTAX_get0_value ? 4_0_0 EXIST::FUNCTION: +OSSL_IETF_ATTR_SYNTAX_add1_value ? 4_0_0 EXIST::FUNCTION: +OSSL_IETF_ATTR_SYNTAX_print ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_TARGET ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_TARGET ? 4_0_0 EXIST::FUNCTION: +OSSL_TARGET_free ? 4_0_0 EXIST::FUNCTION: +OSSL_TARGET_new ? 4_0_0 EXIST::FUNCTION: +OSSL_TARGET_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_TARGETS ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_TARGETS ? 4_0_0 EXIST::FUNCTION: +OSSL_TARGETS_free ? 4_0_0 EXIST::FUNCTION: +OSSL_TARGETS_new ? 4_0_0 EXIST::FUNCTION: +OSSL_TARGETS_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_TARGETING_INFORMATION ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_TARGETING_INFORMATION ? 4_0_0 EXIST::FUNCTION: +OSSL_TARGETING_INFORMATION_free ? 4_0_0 EXIST::FUNCTION: +OSSL_TARGETING_INFORMATION_new ? 4_0_0 EXIST::FUNCTION: +OSSL_TARGETING_INFORMATION_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX ? 4_0_0 EXIST::FUNCTION: +OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX_free ? 4_0_0 EXIST::FUNCTION: +OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX_new ? 4_0_0 EXIST::FUNCTION: +OSSL_AUTHORITY_ATTRIBUTE_ID_SYNTAX_it ? 4_0_0 EXIST::FUNCTION: +X509_TRUST_set ? 4_0_0 EXIST::FUNCTION: +X509_TRUST_get_count ? 4_0_0 EXIST::FUNCTION: +X509_TRUST_get0 ? 4_0_0 EXIST::FUNCTION: +X509_TRUST_get_by_id ? 4_0_0 EXIST::FUNCTION: +X509_TRUST_add ? 4_0_0 EXIST::FUNCTION: +X509_TRUST_cleanup ? 4_0_0 EXIST::FUNCTION: +X509_TRUST_get_flags ? 4_0_0 EXIST::FUNCTION: +X509_TRUST_get0_name ? 4_0_0 EXIST::FUNCTION: +X509_TRUST_get_trust ? 4_0_0 EXIST::FUNCTION: +X509_trusted ? 4_0_0 EXIST::FUNCTION: +X509_add1_trust_object ? 4_0_0 EXIST::FUNCTION: +X509_add1_reject_object ? 4_0_0 EXIST::FUNCTION: +X509_trust_clear ? 4_0_0 EXIST::FUNCTION: +X509_reject_clear ? 4_0_0 EXIST::FUNCTION: +X509_get0_trust_objects ? 4_0_0 EXIST::FUNCTION: +X509_get0_reject_objects ? 4_0_0 EXIST::FUNCTION: +X509_TRUST_set_default ? 4_0_0 EXIST::FUNCTION: +X509_check_trust ? 4_0_0 EXIST::FUNCTION: +X509_verify_cert ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_verify ? 4_0_0 EXIST::FUNCTION: +X509_build_chain ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_depth ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_print_verify_cb ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set_depth ? 4_0_0 EXIST::FUNCTION: +X509_OBJECT_idx_by_subject ? 4_0_0 EXIST::FUNCTION: +X509_OBJECT_retrieve_by_subject ? 4_0_0 EXIST::FUNCTION: +X509_OBJECT_retrieve_match ? 4_0_0 EXIST::FUNCTION: +X509_OBJECT_up_ref_count ? 4_0_0 EXIST::FUNCTION: +X509_OBJECT_new ? 4_0_0 EXIST::FUNCTION: +X509_OBJECT_free ? 4_0_0 EXIST::FUNCTION: +X509_OBJECT_get_type ? 4_0_0 EXIST::FUNCTION: +X509_OBJECT_get0_X509 ? 4_0_0 EXIST::FUNCTION: +X509_OBJECT_set1_X509 ? 4_0_0 EXIST::FUNCTION: +X509_OBJECT_get0_X509_CRL ? 4_0_0 EXIST::FUNCTION: +X509_OBJECT_set1_X509_CRL ? 4_0_0 EXIST::FUNCTION: +X509_STORE_new ? 4_0_0 EXIST::FUNCTION: +X509_STORE_free ? 4_0_0 EXIST::FUNCTION: +X509_STORE_lock ? 4_0_0 EXIST::FUNCTION: +X509_STORE_unlock ? 4_0_0 EXIST::FUNCTION: +X509_STORE_up_ref ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get0_objects ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_0 +X509_STORE_get1_objects ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get1_all_certs ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get1_certs ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get1_crls ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_flags ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_purpose ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_trust ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set1_param ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get0_param ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_verify ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set_verify ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get_verify ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_verify_cb ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get_verify_cb ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_get_issuer ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get_get_issuer ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_check_issued ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get_check_issued ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_check_revocation ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get_check_revocation ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_get_crl ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get_get_crl ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_check_crl ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get_check_crl ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_cert_crl ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get_cert_crl ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_check_policy ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get_check_policy ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_lookup_certs ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get_lookup_certs ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_lookup_crls ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get_lookup_crls ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_cleanup ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get_cleanup ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_ex_data ? 4_0_0 EXIST::FUNCTION: +X509_STORE_get_ex_data ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_new_ex ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_new ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get1_issuer ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_free ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_init ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_init_rpk ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set0_trusted_stack ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_cleanup ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get0_store ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get0_cert ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get0_rpk ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get0_untrusted ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set0_untrusted ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set_verify_cb ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_verify_cb ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_verify ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_get_issuer ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_check_issued ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_check_revocation ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set_get_crl ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_get_crl ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_check_crl ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_cert_crl ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_check_policy ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_lookup_certs ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_lookup_crls ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_cleanup ? 4_0_0 EXIST::FUNCTION: +X509_STORE_add_lookup ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_hash_dir ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_file ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_store ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_new ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_free ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_set_new_item ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_get_new_item ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_set_free ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_get_free ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_set_init ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_get_init ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_set_shutdown ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_get_shutdown ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_set_ctrl ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_get_ctrl ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_set_get_by_subject ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_get_get_by_subject ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_set_get_by_issuer_serial ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_get_get_by_issuer_serial ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_set_get_by_fingerprint ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_get_get_by_fingerprint ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_set_get_by_alias ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_meth_get_get_by_alias ? 4_0_0 EXIST::FUNCTION: +X509_STORE_add_cert ? 4_0_0 EXIST::FUNCTION: +X509_STORE_add_crl ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_by_subject ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_obj_by_subject ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_ctrl ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_ctrl_ex ? 4_0_0 EXIST::FUNCTION: +X509_load_cert_file ? 4_0_0 EXIST::FUNCTION: +X509_load_cert_file_ex ? 4_0_0 EXIST::FUNCTION: +X509_load_crl_file ? 4_0_0 EXIST::FUNCTION: +X509_load_cert_crl_file ? 4_0_0 EXIST::FUNCTION: +X509_load_cert_crl_file_ex ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_new ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_free ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_init ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_by_subject ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_by_subject_ex ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_by_issuer_serial ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_by_fingerprint ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_by_alias ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_set_method_data ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_get_method_data ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_get_store ? 4_0_0 EXIST::FUNCTION: +X509_LOOKUP_shutdown ? 4_0_0 EXIST::FUNCTION: +X509_STORE_load_file ? 4_0_0 EXIST::FUNCTION: +X509_STORE_load_path ? 4_0_0 EXIST::FUNCTION: +X509_STORE_load_store ? 4_0_0 EXIST::FUNCTION: +X509_STORE_load_locations ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_default_paths ? 4_0_0 EXIST::FUNCTION: +X509_STORE_load_file_ex ? 4_0_0 EXIST::FUNCTION: +X509_STORE_load_store_ex ? 4_0_0 EXIST::FUNCTION: +X509_STORE_load_locations_ex ? 4_0_0 EXIST::FUNCTION: +X509_STORE_set_default_paths_ex ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set_ex_data ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_ex_data ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_error ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set_error ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_error_depth ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set_error_depth ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_current_cert ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set_current_cert ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get0_current_issuer ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get0_current_crl ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get0_parent_ctx ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get0_chain ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get1_chain ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set_cert ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set0_rpk ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set0_verified_chain ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set0_crls ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set_ocsp_resp ? 4_0_0 EXIST::FUNCTION:OCSP +X509_STORE_CTX_set_purpose ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set_trust ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_purpose_inherit ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set_flags ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set_time ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set_current_reasons ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get0_policy_tree ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_explicit_policy ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get_num_untrusted ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_get0_param ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set0_param ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set_default ? 4_0_0 EXIST::FUNCTION: +X509_STORE_CTX_set0_dane ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_new ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_free ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_inherit ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_set1 ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_set1_name ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_set_flags ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_clear_flags ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_get_flags ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_set_purpose ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_get_purpose ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_set_trust ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_set_depth ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_set_auth_level ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_get_time ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_set_time ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_add0_policy ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_set1_policies ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_set_inh_flags ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_get_inh_flags ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_get0_host ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_set1_host ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_add1_host ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_set_hostflags ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_get_hostflags ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_get0_peername ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_move_peername ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_get0_email ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_set1_email ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_get1_ip_asc ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_set1_ip ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_set1_ip_asc ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_get_depth ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_get_auth_level ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_get0_name ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_add0_table ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_get_count ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_get0 ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_lookup ? 4_0_0 EXIST::FUNCTION: +X509_VERIFY_PARAM_table_cleanup ? 4_0_0 EXIST::FUNCTION: +X509_policy_check ? 4_0_0 EXIST::FUNCTION: +X509_policy_tree_free ? 4_0_0 EXIST::FUNCTION: +X509_policy_tree_level_count ? 4_0_0 EXIST::FUNCTION: +X509_policy_tree_get0_level ? 4_0_0 EXIST::FUNCTION: +X509_policy_tree_get0_policies ? 4_0_0 EXIST::FUNCTION: +X509_policy_tree_get0_user_policies ? 4_0_0 EXIST::FUNCTION: +X509_policy_level_node_count ? 4_0_0 EXIST::FUNCTION: +X509_policy_level_get0_node ? 4_0_0 EXIST::FUNCTION: +X509_policy_node_get0_policy ? 4_0_0 EXIST::FUNCTION: +X509_policy_node_get0_qualifiers ? 4_0_0 EXIST::FUNCTION: +X509_policy_node_get0_parent ? 4_0_0 EXIST::FUNCTION: +GENERAL_NAME_set1_X509_NAME ? 4_0_0 EXIST::FUNCTION: +DIST_POINT_NAME_dup ? 4_0_0 EXIST::FUNCTION: +d2i_PROXY_POLICY ? 4_0_0 EXIST::FUNCTION: +i2d_PROXY_POLICY ? 4_0_0 EXIST::FUNCTION: +PROXY_POLICY_free ? 4_0_0 EXIST::FUNCTION: +PROXY_POLICY_new ? 4_0_0 EXIST::FUNCTION: +PROXY_POLICY_it ? 4_0_0 EXIST::FUNCTION: +d2i_PROXY_CERT_INFO_EXTENSION ? 4_0_0 EXIST::FUNCTION: +i2d_PROXY_CERT_INFO_EXTENSION ? 4_0_0 EXIST::FUNCTION: +PROXY_CERT_INFO_EXTENSION_free ? 4_0_0 EXIST::FUNCTION: +PROXY_CERT_INFO_EXTENSION_new ? 4_0_0 EXIST::FUNCTION: +PROXY_CERT_INFO_EXTENSION_it ? 4_0_0 EXIST::FUNCTION: +d2i_BASIC_CONSTRAINTS ? 4_0_0 EXIST::FUNCTION: +i2d_BASIC_CONSTRAINTS ? 4_0_0 EXIST::FUNCTION: +BASIC_CONSTRAINTS_free ? 4_0_0 EXIST::FUNCTION: +BASIC_CONSTRAINTS_new ? 4_0_0 EXIST::FUNCTION: +BASIC_CONSTRAINTS_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_BASIC_ATTR_CONSTRAINTS ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_BASIC_ATTR_CONSTRAINTS ? 4_0_0 EXIST::FUNCTION: +OSSL_BASIC_ATTR_CONSTRAINTS_free ? 4_0_0 EXIST::FUNCTION: +OSSL_BASIC_ATTR_CONSTRAINTS_new ? 4_0_0 EXIST::FUNCTION: +OSSL_BASIC_ATTR_CONSTRAINTS_it ? 4_0_0 EXIST::FUNCTION: +d2i_SXNET ? 4_0_0 EXIST::FUNCTION: +i2d_SXNET ? 4_0_0 EXIST::FUNCTION: +SXNET_free ? 4_0_0 EXIST::FUNCTION: +SXNET_new ? 4_0_0 EXIST::FUNCTION: +SXNET_it ? 4_0_0 EXIST::FUNCTION: +d2i_SXNETID ? 4_0_0 EXIST::FUNCTION: +i2d_SXNETID ? 4_0_0 EXIST::FUNCTION: +SXNETID_free ? 4_0_0 EXIST::FUNCTION: +SXNETID_new ? 4_0_0 EXIST::FUNCTION: +SXNETID_it ? 4_0_0 EXIST::FUNCTION: +d2i_ISSUER_SIGN_TOOL ? 4_0_0 EXIST::FUNCTION: +i2d_ISSUER_SIGN_TOOL ? 4_0_0 EXIST::FUNCTION: +ISSUER_SIGN_TOOL_free ? 4_0_0 EXIST::FUNCTION: +ISSUER_SIGN_TOOL_new ? 4_0_0 EXIST::FUNCTION: +ISSUER_SIGN_TOOL_it ? 4_0_0 EXIST::FUNCTION: +SXNET_add_id_asc ? 4_0_0 EXIST::FUNCTION: +SXNET_add_id_ulong ? 4_0_0 EXIST::FUNCTION: +SXNET_add_id_INTEGER ? 4_0_0 EXIST::FUNCTION: +SXNET_get_id_asc ? 4_0_0 EXIST::FUNCTION: +SXNET_get_id_ulong ? 4_0_0 EXIST::FUNCTION: +SXNET_get_id_INTEGER ? 4_0_0 EXIST::FUNCTION: +d2i_AUTHORITY_KEYID ? 4_0_0 EXIST::FUNCTION: +i2d_AUTHORITY_KEYID ? 4_0_0 EXIST::FUNCTION: +AUTHORITY_KEYID_free ? 4_0_0 EXIST::FUNCTION: +AUTHORITY_KEYID_new ? 4_0_0 EXIST::FUNCTION: +AUTHORITY_KEYID_it ? 4_0_0 EXIST::FUNCTION: +d2i_PKEY_USAGE_PERIOD ? 4_0_0 EXIST::FUNCTION: +i2d_PKEY_USAGE_PERIOD ? 4_0_0 EXIST::FUNCTION: +PKEY_USAGE_PERIOD_free ? 4_0_0 EXIST::FUNCTION: +PKEY_USAGE_PERIOD_new ? 4_0_0 EXIST::FUNCTION: +PKEY_USAGE_PERIOD_it ? 4_0_0 EXIST::FUNCTION: +d2i_GENERAL_NAME ? 4_0_0 EXIST::FUNCTION: +i2d_GENERAL_NAME ? 4_0_0 EXIST::FUNCTION: +GENERAL_NAME_free ? 4_0_0 EXIST::FUNCTION: +GENERAL_NAME_new ? 4_0_0 EXIST::FUNCTION: +GENERAL_NAME_it ? 4_0_0 EXIST::FUNCTION: +GENERAL_NAME_dup ? 4_0_0 EXIST::FUNCTION: +GENERAL_NAME_cmp ? 4_0_0 EXIST::FUNCTION: +v2i_ASN1_BIT_STRING ? 4_0_0 EXIST::FUNCTION: +i2v_ASN1_BIT_STRING ? 4_0_0 EXIST::FUNCTION: +i2s_ASN1_IA5STRING ? 4_0_0 EXIST::FUNCTION: +s2i_ASN1_IA5STRING ? 4_0_0 EXIST::FUNCTION: +i2s_ASN1_UTF8STRING ? 4_0_0 EXIST::FUNCTION: +s2i_ASN1_UTF8STRING ? 4_0_0 EXIST::FUNCTION: +i2v_GENERAL_NAME ? 4_0_0 EXIST::FUNCTION: +GENERAL_NAME_print ? 4_0_0 EXIST::FUNCTION: +d2i_GENERAL_NAMES ? 4_0_0 EXIST::FUNCTION: +i2d_GENERAL_NAMES ? 4_0_0 EXIST::FUNCTION: +GENERAL_NAMES_free ? 4_0_0 EXIST::FUNCTION: +GENERAL_NAMES_new ? 4_0_0 EXIST::FUNCTION: +GENERAL_NAMES_it ? 4_0_0 EXIST::FUNCTION: +i2v_GENERAL_NAMES ? 4_0_0 EXIST::FUNCTION: +v2i_GENERAL_NAMES ? 4_0_0 EXIST::FUNCTION: +d2i_OTHERNAME ? 4_0_0 EXIST::FUNCTION: +i2d_OTHERNAME ? 4_0_0 EXIST::FUNCTION: +OTHERNAME_free ? 4_0_0 EXIST::FUNCTION: +OTHERNAME_new ? 4_0_0 EXIST::FUNCTION: +OTHERNAME_it ? 4_0_0 EXIST::FUNCTION: +d2i_EDIPARTYNAME ? 4_0_0 EXIST::FUNCTION: +i2d_EDIPARTYNAME ? 4_0_0 EXIST::FUNCTION: +EDIPARTYNAME_free ? 4_0_0 EXIST::FUNCTION: +EDIPARTYNAME_new ? 4_0_0 EXIST::FUNCTION: +EDIPARTYNAME_it ? 4_0_0 EXIST::FUNCTION: +OTHERNAME_cmp ? 4_0_0 EXIST::FUNCTION: +GENERAL_NAME_set0_value ? 4_0_0 EXIST::FUNCTION: +GENERAL_NAME_get0_value ? 4_0_0 EXIST::FUNCTION: +GENERAL_NAME_set0_othername ? 4_0_0 EXIST::FUNCTION: +GENERAL_NAME_get0_otherName ? 4_0_0 EXIST::FUNCTION: +i2s_ASN1_OCTET_STRING ? 4_0_0 EXIST::FUNCTION: +s2i_ASN1_OCTET_STRING ? 4_0_0 EXIST::FUNCTION: +d2i_EXTENDED_KEY_USAGE ? 4_0_0 EXIST::FUNCTION: +i2d_EXTENDED_KEY_USAGE ? 4_0_0 EXIST::FUNCTION: +EXTENDED_KEY_USAGE_free ? 4_0_0 EXIST::FUNCTION: +EXTENDED_KEY_USAGE_new ? 4_0_0 EXIST::FUNCTION: +EXTENDED_KEY_USAGE_it ? 4_0_0 EXIST::FUNCTION: +i2a_ACCESS_DESCRIPTION ? 4_0_0 EXIST::FUNCTION: +TLS_FEATURE_free ? 4_0_0 EXIST::FUNCTION: +TLS_FEATURE_new ? 4_0_0 EXIST::FUNCTION: +d2i_CERTIFICATEPOLICIES ? 4_0_0 EXIST::FUNCTION: +i2d_CERTIFICATEPOLICIES ? 4_0_0 EXIST::FUNCTION: +CERTIFICATEPOLICIES_free ? 4_0_0 EXIST::FUNCTION: +CERTIFICATEPOLICIES_new ? 4_0_0 EXIST::FUNCTION: +CERTIFICATEPOLICIES_it ? 4_0_0 EXIST::FUNCTION: +d2i_POLICYINFO ? 4_0_0 EXIST::FUNCTION: +i2d_POLICYINFO ? 4_0_0 EXIST::FUNCTION: +POLICYINFO_free ? 4_0_0 EXIST::FUNCTION: +POLICYINFO_new ? 4_0_0 EXIST::FUNCTION: +POLICYINFO_it ? 4_0_0 EXIST::FUNCTION: +d2i_POLICYQUALINFO ? 4_0_0 EXIST::FUNCTION: +i2d_POLICYQUALINFO ? 4_0_0 EXIST::FUNCTION: +POLICYQUALINFO_free ? 4_0_0 EXIST::FUNCTION: +POLICYQUALINFO_new ? 4_0_0 EXIST::FUNCTION: +POLICYQUALINFO_it ? 4_0_0 EXIST::FUNCTION: +d2i_USERNOTICE ? 4_0_0 EXIST::FUNCTION: +i2d_USERNOTICE ? 4_0_0 EXIST::FUNCTION: +USERNOTICE_free ? 4_0_0 EXIST::FUNCTION: +USERNOTICE_new ? 4_0_0 EXIST::FUNCTION: +USERNOTICE_it ? 4_0_0 EXIST::FUNCTION: +d2i_NOTICEREF ? 4_0_0 EXIST::FUNCTION: +i2d_NOTICEREF ? 4_0_0 EXIST::FUNCTION: +NOTICEREF_free ? 4_0_0 EXIST::FUNCTION: +NOTICEREF_new ? 4_0_0 EXIST::FUNCTION: +NOTICEREF_it ? 4_0_0 EXIST::FUNCTION: +d2i_CRL_DIST_POINTS ? 4_0_0 EXIST::FUNCTION: +i2d_CRL_DIST_POINTS ? 4_0_0 EXIST::FUNCTION: +CRL_DIST_POINTS_free ? 4_0_0 EXIST::FUNCTION: +CRL_DIST_POINTS_new ? 4_0_0 EXIST::FUNCTION: +CRL_DIST_POINTS_it ? 4_0_0 EXIST::FUNCTION: +d2i_DIST_POINT ? 4_0_0 EXIST::FUNCTION: +i2d_DIST_POINT ? 4_0_0 EXIST::FUNCTION: +DIST_POINT_free ? 4_0_0 EXIST::FUNCTION: +DIST_POINT_new ? 4_0_0 EXIST::FUNCTION: +DIST_POINT_it ? 4_0_0 EXIST::FUNCTION: +d2i_DIST_POINT_NAME ? 4_0_0 EXIST::FUNCTION: +i2d_DIST_POINT_NAME ? 4_0_0 EXIST::FUNCTION: +DIST_POINT_NAME_free ? 4_0_0 EXIST::FUNCTION: +DIST_POINT_NAME_new ? 4_0_0 EXIST::FUNCTION: +DIST_POINT_NAME_it ? 4_0_0 EXIST::FUNCTION: +d2i_ISSUING_DIST_POINT ? 4_0_0 EXIST::FUNCTION: +i2d_ISSUING_DIST_POINT ? 4_0_0 EXIST::FUNCTION: +ISSUING_DIST_POINT_free ? 4_0_0 EXIST::FUNCTION: +ISSUING_DIST_POINT_new ? 4_0_0 EXIST::FUNCTION: +ISSUING_DIST_POINT_it ? 4_0_0 EXIST::FUNCTION: +DIST_POINT_set_dpname ? 4_0_0 EXIST::FUNCTION: +NAME_CONSTRAINTS_check ? 4_0_0 EXIST::FUNCTION: +NAME_CONSTRAINTS_check_CN ? 4_0_0 EXIST::FUNCTION: +d2i_ACCESS_DESCRIPTION ? 4_0_0 EXIST::FUNCTION: +i2d_ACCESS_DESCRIPTION ? 4_0_0 EXIST::FUNCTION: +ACCESS_DESCRIPTION_free ? 4_0_0 EXIST::FUNCTION: +ACCESS_DESCRIPTION_new ? 4_0_0 EXIST::FUNCTION: +ACCESS_DESCRIPTION_it ? 4_0_0 EXIST::FUNCTION: +d2i_AUTHORITY_INFO_ACCESS ? 4_0_0 EXIST::FUNCTION: +i2d_AUTHORITY_INFO_ACCESS ? 4_0_0 EXIST::FUNCTION: +AUTHORITY_INFO_ACCESS_free ? 4_0_0 EXIST::FUNCTION: +AUTHORITY_INFO_ACCESS_new ? 4_0_0 EXIST::FUNCTION: +AUTHORITY_INFO_ACCESS_it ? 4_0_0 EXIST::FUNCTION: +POLICY_MAPPING_it ? 4_0_0 EXIST::FUNCTION: +POLICY_MAPPING_free ? 4_0_0 EXIST::FUNCTION: +POLICY_MAPPING_new ? 4_0_0 EXIST::FUNCTION: +POLICY_MAPPINGS_it ? 4_0_0 EXIST::FUNCTION: +GENERAL_SUBTREE_it ? 4_0_0 EXIST::FUNCTION: +GENERAL_SUBTREE_free ? 4_0_0 EXIST::FUNCTION: +GENERAL_SUBTREE_new ? 4_0_0 EXIST::FUNCTION: +NAME_CONSTRAINTS_it ? 4_0_0 EXIST::FUNCTION: +NAME_CONSTRAINTS_free ? 4_0_0 EXIST::FUNCTION: +NAME_CONSTRAINTS_new ? 4_0_0 EXIST::FUNCTION: +POLICY_CONSTRAINTS_free ? 4_0_0 EXIST::FUNCTION: +POLICY_CONSTRAINTS_new ? 4_0_0 EXIST::FUNCTION: +POLICY_CONSTRAINTS_it ? 4_0_0 EXIST::FUNCTION: +a2i_GENERAL_NAME ? 4_0_0 EXIST::FUNCTION: +v2i_GENERAL_NAME ? 4_0_0 EXIST::FUNCTION: +v2i_GENERAL_NAME_ex ? 4_0_0 EXIST::FUNCTION: +X509V3_conf_free ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_nconf_nid ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_nconf ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_add_nconf_sk ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_add_nconf ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_REQ_add_nconf ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_CRL_add_nconf ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_conf_nid ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_conf ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_add_conf ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_REQ_add_conf ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_CRL_add_conf ? 4_0_0 EXIST::FUNCTION: +X509V3_add_value_bool_nf ? 4_0_0 EXIST::FUNCTION: +X509V3_get_value_bool ? 4_0_0 EXIST::FUNCTION: +X509V3_get_value_int ? 4_0_0 EXIST::FUNCTION: +X509V3_set_nconf ? 4_0_0 EXIST::FUNCTION: +X509V3_set_conf_lhash ? 4_0_0 EXIST::FUNCTION: +X509V3_get_string ? 4_0_0 EXIST::FUNCTION: +X509V3_get_section ? 4_0_0 EXIST::FUNCTION: +X509V3_string_free ? 4_0_0 EXIST::FUNCTION: +X509V3_section_free ? 4_0_0 EXIST::FUNCTION: +X509V3_set_ctx ? 4_0_0 EXIST::FUNCTION: +X509V3_set_issuer_pkey ? 4_0_0 EXIST::FUNCTION: +X509V3_add_value ? 4_0_0 EXIST::FUNCTION: +X509V3_add_value_uchar ? 4_0_0 EXIST::FUNCTION: +X509V3_add_value_bool ? 4_0_0 EXIST::FUNCTION: +X509V3_add_value_int ? 4_0_0 EXIST::FUNCTION: +i2s_ASN1_INTEGER ? 4_0_0 EXIST::FUNCTION: +s2i_ASN1_INTEGER ? 4_0_0 EXIST::FUNCTION: +i2s_ASN1_ENUMERATED ? 4_0_0 EXIST::FUNCTION: +i2s_ASN1_ENUMERATED_TABLE ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_add ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_add_list ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_add_alias ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_cleanup ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_get ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_get_nid ? 4_0_0 EXIST::FUNCTION: +X509V3_add_standard_extensions ? 4_0_0 EXIST::FUNCTION: +X509V3_parse_list ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_d2i ? 4_0_0 EXIST::FUNCTION: +X509V3_get_d2i ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_i2d ? 4_0_0 EXIST::FUNCTION: +X509V3_add1_i2d ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_val_prn ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_print ? 4_0_0 EXIST::FUNCTION: +X509V3_EXT_print_fp ? 4_0_0 EXIST::FUNCTION:STDIO +X509V3_extensions_print ? 4_0_0 EXIST::FUNCTION: +X509_check_ca ? 4_0_0 EXIST::FUNCTION: +X509_check_purpose ? 4_0_0 EXIST::FUNCTION: +X509_supported_extension ? 4_0_0 EXIST::FUNCTION: +X509_check_issued ? 4_0_0 EXIST::FUNCTION: +X509_check_akid ? 4_0_0 EXIST::FUNCTION: +X509_set_proxy_flag ? 4_0_0 EXIST::FUNCTION: +X509_set_proxy_pathlen ? 4_0_0 EXIST::FUNCTION: +X509_get_proxy_pathlen ? 4_0_0 EXIST::FUNCTION: +X509_get_extension_flags ? 4_0_0 EXIST::FUNCTION: +X509_get_key_usage ? 4_0_0 EXIST::FUNCTION: +X509_get_extended_key_usage ? 4_0_0 EXIST::FUNCTION: +X509_get0_subject_key_id ? 4_0_0 EXIST::FUNCTION: +X509_get0_authority_key_id ? 4_0_0 EXIST::FUNCTION: +X509_get0_authority_issuer ? 4_0_0 EXIST::FUNCTION: +X509_get0_authority_serial ? 4_0_0 EXIST::FUNCTION: +X509_PURPOSE_get_count ? 4_0_0 EXIST::FUNCTION: +X509_PURPOSE_get_unused_id ? 4_0_0 EXIST::FUNCTION: +X509_PURPOSE_get_by_sname ? 4_0_0 EXIST::FUNCTION: +X509_PURPOSE_get_by_id ? 4_0_0 EXIST::FUNCTION: +X509_PURPOSE_add ? 4_0_0 EXIST::FUNCTION: +X509_PURPOSE_cleanup ? 4_0_0 EXIST::FUNCTION: +X509_PURPOSE_get0 ? 4_0_0 EXIST::FUNCTION: +X509_PURPOSE_get_id ? 4_0_0 EXIST::FUNCTION: +X509_PURPOSE_get0_name ? 4_0_0 EXIST::FUNCTION: +X509_PURPOSE_get0_sname ? 4_0_0 EXIST::FUNCTION: +X509_PURPOSE_get_trust ? 4_0_0 EXIST::FUNCTION: +X509_PURPOSE_set ? 4_0_0 EXIST::FUNCTION: +X509_get1_email ? 4_0_0 EXIST::FUNCTION: +X509_REQ_get1_email ? 4_0_0 EXIST::FUNCTION: +X509_email_free ? 4_0_0 EXIST::FUNCTION: +X509_get1_ocsp ? 4_0_0 EXIST::FUNCTION: +X509_check_host ? 4_0_0 EXIST::FUNCTION: +X509_check_email ? 4_0_0 EXIST::FUNCTION: +X509_check_ip ? 4_0_0 EXIST::FUNCTION: +X509_check_ip_asc ? 4_0_0 EXIST::FUNCTION: +a2i_IPADDRESS ? 4_0_0 EXIST::FUNCTION: +a2i_IPADDRESS_NC ? 4_0_0 EXIST::FUNCTION: +X509V3_NAME_from_section ? 4_0_0 EXIST::FUNCTION: +X509_POLICY_NODE_print ? 4_0_0 EXIST::FUNCTION: +d2i_ASRange ? 4_0_0 EXIST::FUNCTION:RFC3779 +i2d_ASRange ? 4_0_0 EXIST::FUNCTION:RFC3779 +ASRange_free ? 4_0_0 EXIST::FUNCTION:RFC3779 +ASRange_new ? 4_0_0 EXIST::FUNCTION:RFC3779 +ASRange_it ? 4_0_0 EXIST::FUNCTION:RFC3779 +d2i_ASIdOrRange ? 4_0_0 EXIST::FUNCTION:RFC3779 +i2d_ASIdOrRange ? 4_0_0 EXIST::FUNCTION:RFC3779 +ASIdOrRange_free ? 4_0_0 EXIST::FUNCTION:RFC3779 +ASIdOrRange_new ? 4_0_0 EXIST::FUNCTION:RFC3779 +ASIdOrRange_it ? 4_0_0 EXIST::FUNCTION:RFC3779 +d2i_ASIdentifierChoice ? 4_0_0 EXIST::FUNCTION:RFC3779 +i2d_ASIdentifierChoice ? 4_0_0 EXIST::FUNCTION:RFC3779 +ASIdentifierChoice_free ? 4_0_0 EXIST::FUNCTION:RFC3779 +ASIdentifierChoice_new ? 4_0_0 EXIST::FUNCTION:RFC3779 +ASIdentifierChoice_it ? 4_0_0 EXIST::FUNCTION:RFC3779 +d2i_ASIdentifiers ? 4_0_0 EXIST::FUNCTION:RFC3779 +i2d_ASIdentifiers ? 4_0_0 EXIST::FUNCTION:RFC3779 +ASIdentifiers_free ? 4_0_0 EXIST::FUNCTION:RFC3779 +ASIdentifiers_new ? 4_0_0 EXIST::FUNCTION:RFC3779 +ASIdentifiers_it ? 4_0_0 EXIST::FUNCTION:RFC3779 +d2i_IPAddressRange ? 4_0_0 EXIST::FUNCTION:RFC3779 +i2d_IPAddressRange ? 4_0_0 EXIST::FUNCTION:RFC3779 +IPAddressRange_free ? 4_0_0 EXIST::FUNCTION:RFC3779 +IPAddressRange_new ? 4_0_0 EXIST::FUNCTION:RFC3779 +IPAddressRange_it ? 4_0_0 EXIST::FUNCTION:RFC3779 +d2i_IPAddressOrRange ? 4_0_0 EXIST::FUNCTION:RFC3779 +i2d_IPAddressOrRange ? 4_0_0 EXIST::FUNCTION:RFC3779 +IPAddressOrRange_free ? 4_0_0 EXIST::FUNCTION:RFC3779 +IPAddressOrRange_new ? 4_0_0 EXIST::FUNCTION:RFC3779 +IPAddressOrRange_it ? 4_0_0 EXIST::FUNCTION:RFC3779 +d2i_IPAddressChoice ? 4_0_0 EXIST::FUNCTION:RFC3779 +i2d_IPAddressChoice ? 4_0_0 EXIST::FUNCTION:RFC3779 +IPAddressChoice_free ? 4_0_0 EXIST::FUNCTION:RFC3779 +IPAddressChoice_new ? 4_0_0 EXIST::FUNCTION:RFC3779 +IPAddressChoice_it ? 4_0_0 EXIST::FUNCTION:RFC3779 +d2i_IPAddressFamily ? 4_0_0 EXIST::FUNCTION:RFC3779 +i2d_IPAddressFamily ? 4_0_0 EXIST::FUNCTION:RFC3779 +IPAddressFamily_free ? 4_0_0 EXIST::FUNCTION:RFC3779 +IPAddressFamily_new ? 4_0_0 EXIST::FUNCTION:RFC3779 +IPAddressFamily_it ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_asid_add_inherit ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_asid_add_id_or_range ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_addr_add_inherit ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_addr_add_prefix ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_addr_add_range ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_addr_get_afi ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_addr_get_range ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_asid_is_canonical ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_addr_is_canonical ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_asid_canonize ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_addr_canonize ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_asid_inherits ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_addr_inherits ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_asid_subset ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_addr_subset ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_asid_validate_path ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_addr_validate_path ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_asid_validate_resource_set ? 4_0_0 EXIST::FUNCTION:RFC3779 +X509v3_addr_validate_resource_set ? 4_0_0 EXIST::FUNCTION:RFC3779 +d2i_NAMING_AUTHORITY ? 4_0_0 EXIST::FUNCTION: +i2d_NAMING_AUTHORITY ? 4_0_0 EXIST::FUNCTION: +NAMING_AUTHORITY_free ? 4_0_0 EXIST::FUNCTION: +NAMING_AUTHORITY_new ? 4_0_0 EXIST::FUNCTION: +NAMING_AUTHORITY_it ? 4_0_0 EXIST::FUNCTION: +d2i_PROFESSION_INFO ? 4_0_0 EXIST::FUNCTION: +i2d_PROFESSION_INFO ? 4_0_0 EXIST::FUNCTION: +PROFESSION_INFO_free ? 4_0_0 EXIST::FUNCTION: +PROFESSION_INFO_new ? 4_0_0 EXIST::FUNCTION: +PROFESSION_INFO_it ? 4_0_0 EXIST::FUNCTION: +d2i_ADMISSIONS ? 4_0_0 EXIST::FUNCTION: +i2d_ADMISSIONS ? 4_0_0 EXIST::FUNCTION: +ADMISSIONS_free ? 4_0_0 EXIST::FUNCTION: +ADMISSIONS_new ? 4_0_0 EXIST::FUNCTION: +ADMISSIONS_it ? 4_0_0 EXIST::FUNCTION: +d2i_ADMISSION_SYNTAX ? 4_0_0 EXIST::FUNCTION: +i2d_ADMISSION_SYNTAX ? 4_0_0 EXIST::FUNCTION: +ADMISSION_SYNTAX_free ? 4_0_0 EXIST::FUNCTION: +ADMISSION_SYNTAX_new ? 4_0_0 EXIST::FUNCTION: +ADMISSION_SYNTAX_it ? 4_0_0 EXIST::FUNCTION: +NAMING_AUTHORITY_get0_authorityId ? 4_0_0 EXIST::FUNCTION: +NAMING_AUTHORITY_get0_authorityURL ? 4_0_0 EXIST::FUNCTION: +NAMING_AUTHORITY_get0_authorityText ? 4_0_0 EXIST::FUNCTION: +NAMING_AUTHORITY_set0_authorityId ? 4_0_0 EXIST::FUNCTION: +NAMING_AUTHORITY_set0_authorityURL ? 4_0_0 EXIST::FUNCTION: +NAMING_AUTHORITY_set0_authorityText ? 4_0_0 EXIST::FUNCTION: +ADMISSION_SYNTAX_get0_admissionAuthority ? 4_0_0 EXIST::FUNCTION: +ADMISSION_SYNTAX_set0_admissionAuthority ? 4_0_0 EXIST::FUNCTION: +ADMISSION_SYNTAX_get0_contentsOfAdmissions ? 4_0_0 EXIST::FUNCTION: +ADMISSION_SYNTAX_set0_contentsOfAdmissions ? 4_0_0 EXIST::FUNCTION: +ADMISSIONS_get0_admissionAuthority ? 4_0_0 EXIST::FUNCTION: +ADMISSIONS_set0_admissionAuthority ? 4_0_0 EXIST::FUNCTION: +ADMISSIONS_get0_namingAuthority ? 4_0_0 EXIST::FUNCTION: +ADMISSIONS_set0_namingAuthority ? 4_0_0 EXIST::FUNCTION: +ADMISSIONS_get0_professionInfos ? 4_0_0 EXIST::FUNCTION: +ADMISSIONS_set0_professionInfos ? 4_0_0 EXIST::FUNCTION: +PROFESSION_INFO_get0_addProfessionInfo ? 4_0_0 EXIST::FUNCTION: +PROFESSION_INFO_set0_addProfessionInfo ? 4_0_0 EXIST::FUNCTION: +PROFESSION_INFO_get0_namingAuthority ? 4_0_0 EXIST::FUNCTION: +PROFESSION_INFO_set0_namingAuthority ? 4_0_0 EXIST::FUNCTION: +PROFESSION_INFO_get0_professionItems ? 4_0_0 EXIST::FUNCTION: +PROFESSION_INFO_set0_professionItems ? 4_0_0 EXIST::FUNCTION: +PROFESSION_INFO_get0_professionOIDs ? 4_0_0 EXIST::FUNCTION: +PROFESSION_INFO_set0_professionOIDs ? 4_0_0 EXIST::FUNCTION: +PROFESSION_INFO_get0_registrationNumber ? 4_0_0 EXIST::FUNCTION: +PROFESSION_INFO_set0_registrationNumber ? 4_0_0 EXIST::FUNCTION: +OSSL_GENERAL_NAMES_print ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_ATTRIBUTES_SYNTAX ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_ATTRIBUTES_SYNTAX ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTES_SYNTAX_free ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTES_SYNTAX_new ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTES_SYNTAX_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_USER_NOTICE_SYNTAX ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_USER_NOTICE_SYNTAX ? 4_0_0 EXIST::FUNCTION: +OSSL_USER_NOTICE_SYNTAX_free ? 4_0_0 EXIST::FUNCTION: +OSSL_USER_NOTICE_SYNTAX_new ? 4_0_0 EXIST::FUNCTION: +OSSL_USER_NOTICE_SYNTAX_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_ROLE_SPEC_CERT_ID ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_ROLE_SPEC_CERT_ID ? 4_0_0 EXIST::FUNCTION: +OSSL_ROLE_SPEC_CERT_ID_free ? 4_0_0 EXIST::FUNCTION: +OSSL_ROLE_SPEC_CERT_ID_new ? 4_0_0 EXIST::FUNCTION: +OSSL_ROLE_SPEC_CERT_ID_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_ROLE_SPEC_CERT_ID_SYNTAX ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_ROLE_SPEC_CERT_ID_SYNTAX ? 4_0_0 EXIST::FUNCTION: +OSSL_ROLE_SPEC_CERT_ID_SYNTAX_free ? 4_0_0 EXIST::FUNCTION: +OSSL_ROLE_SPEC_CERT_ID_SYNTAX_new ? 4_0_0 EXIST::FUNCTION: +OSSL_ROLE_SPEC_CERT_ID_SYNTAX_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_HASH ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_HASH ? 4_0_0 EXIST::FUNCTION: +OSSL_HASH_free ? 4_0_0 EXIST::FUNCTION: +OSSL_HASH_new ? 4_0_0 EXIST::FUNCTION: +OSSL_HASH_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_INFO_SYNTAX ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_INFO_SYNTAX ? 4_0_0 EXIST::FUNCTION: +OSSL_INFO_SYNTAX_free ? 4_0_0 EXIST::FUNCTION: +OSSL_INFO_SYNTAX_new ? 4_0_0 EXIST::FUNCTION: +OSSL_INFO_SYNTAX_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_INFO_SYNTAX_POINTER ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_INFO_SYNTAX_POINTER ? 4_0_0 EXIST::FUNCTION: +OSSL_INFO_SYNTAX_POINTER_free ? 4_0_0 EXIST::FUNCTION: +OSSL_INFO_SYNTAX_POINTER_new ? 4_0_0 EXIST::FUNCTION: +OSSL_INFO_SYNTAX_POINTER_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_PRIVILEGE_POLICY_ID ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_PRIVILEGE_POLICY_ID ? 4_0_0 EXIST::FUNCTION: +OSSL_PRIVILEGE_POLICY_ID_free ? 4_0_0 EXIST::FUNCTION: +OSSL_PRIVILEGE_POLICY_ID_new ? 4_0_0 EXIST::FUNCTION: +OSSL_PRIVILEGE_POLICY_ID_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_ATTRIBUTE_DESCRIPTOR ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_ATTRIBUTE_DESCRIPTOR ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTE_DESCRIPTOR_free ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTE_DESCRIPTOR_new ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTE_DESCRIPTOR_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_DAY_TIME ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_DAY_TIME ? 4_0_0 EXIST::FUNCTION: +OSSL_DAY_TIME_free ? 4_0_0 EXIST::FUNCTION: +OSSL_DAY_TIME_new ? 4_0_0 EXIST::FUNCTION: +OSSL_DAY_TIME_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_DAY_TIME_BAND ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_DAY_TIME_BAND ? 4_0_0 EXIST::FUNCTION: +OSSL_DAY_TIME_BAND_free ? 4_0_0 EXIST::FUNCTION: +OSSL_DAY_TIME_BAND_new ? 4_0_0 EXIST::FUNCTION: +OSSL_DAY_TIME_BAND_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_TIME_SPEC_DAY ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_TIME_SPEC_DAY ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_DAY_free ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_DAY_new ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_DAY_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_TIME_SPEC_WEEKS ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_TIME_SPEC_WEEKS ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_WEEKS_free ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_WEEKS_new ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_WEEKS_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_TIME_SPEC_MONTH ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_TIME_SPEC_MONTH ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_MONTH_free ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_MONTH_new ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_MONTH_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_NAMED_DAY ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_NAMED_DAY ? 4_0_0 EXIST::FUNCTION: +OSSL_NAMED_DAY_free ? 4_0_0 EXIST::FUNCTION: +OSSL_NAMED_DAY_new ? 4_0_0 EXIST::FUNCTION: +OSSL_NAMED_DAY_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_TIME_SPEC_X_DAY_OF ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_TIME_SPEC_X_DAY_OF ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_X_DAY_OF_free ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_X_DAY_OF_new ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_X_DAY_OF_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_TIME_SPEC_ABSOLUTE ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_TIME_SPEC_ABSOLUTE ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_ABSOLUTE_free ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_ABSOLUTE_new ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_ABSOLUTE_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_TIME_SPEC_TIME ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_TIME_SPEC_TIME ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_TIME_free ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_TIME_new ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_TIME_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_TIME_SPEC ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_TIME_SPEC ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_free ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_new ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_SPEC_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_TIME_PERIOD ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_TIME_PERIOD ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_PERIOD_free ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_PERIOD_new ? 4_0_0 EXIST::FUNCTION: +OSSL_TIME_PERIOD_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_ATAV ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_ATAV ? 4_0_0 EXIST::FUNCTION: +OSSL_ATAV_free ? 4_0_0 EXIST::FUNCTION: +OSSL_ATAV_new ? 4_0_0 EXIST::FUNCTION: +OSSL_ATAV_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_ATTRIBUTE_TYPE_MAPPING ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_ATTRIBUTE_TYPE_MAPPING ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTE_TYPE_MAPPING_free ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTE_TYPE_MAPPING_new ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTE_TYPE_MAPPING_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_ATTRIBUTE_VALUE_MAPPING ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_ATTRIBUTE_VALUE_MAPPING ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTE_VALUE_MAPPING_free ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTE_VALUE_MAPPING_new ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTE_VALUE_MAPPING_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_ATTRIBUTE_MAPPING ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_ATTRIBUTE_MAPPING ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTE_MAPPING_free ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTE_MAPPING_new ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTE_MAPPING_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_ATTRIBUTE_MAPPINGS ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_ATTRIBUTE_MAPPINGS ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTE_MAPPINGS_free ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTE_MAPPINGS_new ? 4_0_0 EXIST::FUNCTION: +OSSL_ATTRIBUTE_MAPPINGS_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_ALLOWED_ATTRIBUTES_CHOICE ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_ALLOWED_ATTRIBUTES_CHOICE ? 4_0_0 EXIST::FUNCTION: +OSSL_ALLOWED_ATTRIBUTES_CHOICE_free ? 4_0_0 EXIST::FUNCTION: +OSSL_ALLOWED_ATTRIBUTES_CHOICE_new ? 4_0_0 EXIST::FUNCTION: +OSSL_ALLOWED_ATTRIBUTES_CHOICE_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_ALLOWED_ATTRIBUTES_ITEM ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_ALLOWED_ATTRIBUTES_ITEM ? 4_0_0 EXIST::FUNCTION: +OSSL_ALLOWED_ATTRIBUTES_ITEM_free ? 4_0_0 EXIST::FUNCTION: +OSSL_ALLOWED_ATTRIBUTES_ITEM_new ? 4_0_0 EXIST::FUNCTION: +OSSL_ALLOWED_ATTRIBUTES_ITEM_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_ALLOWED_ATTRIBUTES_SYNTAX ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_ALLOWED_ATTRIBUTES_SYNTAX ? 4_0_0 EXIST::FUNCTION: +OSSL_ALLOWED_ATTRIBUTES_SYNTAX_free ? 4_0_0 EXIST::FUNCTION: +OSSL_ALLOWED_ATTRIBUTES_SYNTAX_new ? 4_0_0 EXIST::FUNCTION: +OSSL_ALLOWED_ATTRIBUTES_SYNTAX_it ? 4_0_0 EXIST::FUNCTION: +d2i_OSSL_AA_DIST_POINT ? 4_0_0 EXIST::FUNCTION: +i2d_OSSL_AA_DIST_POINT ? 4_0_0 EXIST::FUNCTION: +OSSL_AA_DIST_POINT_free ? 4_0_0 EXIST::FUNCTION: +OSSL_AA_DIST_POINT_new ? 4_0_0 EXIST::FUNCTION: +OSSL_AA_DIST_POINT_it ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_new_SKEY ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get0_SKEY ? 4_0_0 EXIST::FUNCTION: +OSSL_STORE_INFO_get1_SKEY ? 4_0_0 EXIST::FUNCTION: +OPENSSL_posix_to_tm ? 4_0_0 EXIST::FUNCTION: +OPENSSL_tm_to_posix ? 4_0_0 EXIST::FUNCTION: +OPENSSL_timegm ? 4_0_0 EXIST::FUNCTION: +OSSL_PARAM_clear_free ? 4_0_0 EXIST::FUNCTION: +CMS_dataFinal_ex ? 4_0_0 EXIST::FUNCTION:CMS +CMS_SignerInfo_verify_ex ? 4_0_0 EXIST::FUNCTION:CMS +EVP_SIGNATURE_has_message_update ? 4_0_0 EXIST::FUNCTION: +OSSL_LIB_CTX_freeze ? 4_0_0 EXIST::FUNCTION: diff --git a/util/libssl.num b/util/libssl.num index 9b24054a7c..c657d5ee61 100644 --- a/util/libssl.num +++ b/util/libssl.num @@ -1,628 +1,610 @@ -OSSL_QUIC_client_method 1 4_0_0 EXIST::FUNCTION:QUIC -OSSL_QUIC_client_thread_method 2 4_0_0 EXIST::FUNCTION:QUIC -OSSL_QUIC_server_method 3 4_0_0 EXIST::FUNCTION:QUIC -SSL_CTX_set_tlsext_use_srtp 4 4_0_0 EXIST::FUNCTION:SRTP -SSL_set_tlsext_use_srtp 5 4_0_0 EXIST::FUNCTION:SRTP -SSL_get_srtp_profiles 6 4_0_0 EXIST::FUNCTION:SRTP -SSL_get_selected_srtp_profile 7 4_0_0 EXIST::FUNCTION:SRTP -ERR_load_SSL_strings 8 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SSL_CTX_set_tlsext_max_fragment_length 9 4_0_0 EXIST::FUNCTION: -SSL_set_tlsext_max_fragment_length 10 4_0_0 EXIST::FUNCTION: -SSL_get_servername 11 4_0_0 EXIST::FUNCTION: -SSL_get_servername_type 12 4_0_0 EXIST::FUNCTION: -SSL_export_keying_material 13 4_0_0 EXIST::FUNCTION: -SSL_export_keying_material_early 14 4_0_0 EXIST::FUNCTION: -SSL_get_peer_signature_type_nid 15 4_0_0 EXIST::FUNCTION: -SSL_get_signature_type_nid 16 4_0_0 EXIST::FUNCTION: -SSL_get_sigalgs 17 4_0_0 EXIST::FUNCTION: -SSL_get1_builtin_sigalgs 18 4_0_0 EXIST::FUNCTION: -SSL_get_shared_sigalgs 19 4_0_0 EXIST::FUNCTION: -SSL_check_chain 20 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_tlsext_ticket_key_evp_cb 21 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_options 22 4_0_0 EXIST::FUNCTION: -SSL_get_options 23 4_0_0 EXIST::FUNCTION: -SSL_CTX_clear_options 24 4_0_0 EXIST::FUNCTION: -SSL_clear_options 25 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_options 26 4_0_0 EXIST::FUNCTION: -SSL_set_options 27 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_msg_callback 28 4_0_0 EXIST::FUNCTION: -SSL_set_msg_callback 29 4_0_0 EXIST::FUNCTION: -SSL_SRP_CTX_init 30 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_CTX_SRP_CTX_init 31 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_SRP_CTX_free 32 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_CTX_SRP_CTX_free 33 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_srp_server_param_with_username 34 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SRP_Calc_A_param 35 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_CTX_sessions 36 4_0_0 EXIST::FUNCTION: -SSL_CTX_sess_set_new_cb 37 4_0_0 EXIST::FUNCTION: -SSL_CTX_sess_get_new_cb 38 4_0_0 EXIST::FUNCTION: -SSL_CTX_sess_set_remove_cb 39 4_0_0 EXIST::FUNCTION: -SSL_CTX_sess_get_remove_cb 40 4_0_0 EXIST::FUNCTION: -SSL_CTX_sess_set_get_cb 41 4_0_0 EXIST::FUNCTION: -SSL_CTX_sess_get_get_cb 42 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_info_callback 43 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_info_callback 44 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_client_cert_cb 45 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_client_cert_cb 46 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_cookie_generate_cb 47 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_cookie_verify_cb 48 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_stateless_cookie_generate_cb 49 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_stateless_cookie_verify_cb 50 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_next_protos_advertised_cb 51 4_0_0 EXIST::FUNCTION:NEXTPROTONEG -SSL_CTX_set_next_proto_select_cb 52 4_0_0 EXIST::FUNCTION:NEXTPROTONEG -SSL_get0_next_proto_negotiated 53 4_0_0 EXIST::FUNCTION:NEXTPROTONEG -SSL_select_next_proto 54 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_alpn_protos 55 4_0_0 EXIST::FUNCTION: -SSL_set_alpn_protos 56 4_0_0 EXIST::FUNCTION: -SSL_CTX_get0_alpn_protos 57 4_0_0 EXIST::FUNCTION: -SSL_get0_alpn_protos 58 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_alpn_select_cb 59 4_0_0 EXIST::FUNCTION: -SSL_get0_alpn_selected 60 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_psk_client_callback 61 4_0_0 EXIST::FUNCTION:PSK -SSL_set_psk_client_callback 62 4_0_0 EXIST::FUNCTION:PSK -SSL_CTX_set_psk_server_callback 63 4_0_0 EXIST::FUNCTION:PSK -SSL_set_psk_server_callback 64 4_0_0 EXIST::FUNCTION:PSK -SSL_CTX_use_psk_identity_hint 65 4_0_0 EXIST::FUNCTION:PSK -SSL_use_psk_identity_hint 66 4_0_0 EXIST::FUNCTION:PSK -SSL_get_psk_identity_hint 67 4_0_0 EXIST::FUNCTION:PSK -SSL_get_psk_identity 68 4_0_0 EXIST::FUNCTION:PSK -SSL_set_psk_find_session_callback 69 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_psk_find_session_callback 70 4_0_0 EXIST::FUNCTION: -SSL_set_psk_use_session_callback 71 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_psk_use_session_callback 72 4_0_0 EXIST::FUNCTION: -SSL_CTX_has_client_custom_ext 73 4_0_0 EXIST::FUNCTION: -SSL_CTX_add_client_custom_ext 74 4_0_0 EXIST::FUNCTION: -SSL_CTX_add_server_custom_ext 75 4_0_0 EXIST::FUNCTION: -SSL_CTX_add_custom_ext 76 4_0_0 EXIST::FUNCTION: -SSL_extension_supported 77 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_keylog_callback 78 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_keylog_callback 79 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_max_early_data 80 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_max_early_data 81 4_0_0 EXIST::FUNCTION: -SSL_set_max_early_data 82 4_0_0 EXIST::FUNCTION: -SSL_get_max_early_data 83 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_recv_max_early_data 84 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_recv_max_early_data 85 4_0_0 EXIST::FUNCTION: -SSL_set_recv_max_early_data 86 4_0_0 EXIST::FUNCTION: -SSL_get_recv_max_early_data 87 4_0_0 EXIST::FUNCTION: -SSL_set_debug 88 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0 -SSL_in_init 89 4_0_0 EXIST::FUNCTION: -SSL_in_before 90 4_0_0 EXIST::FUNCTION: -SSL_is_init_finished 91 4_0_0 EXIST::FUNCTION: -SSL_get_finished 92 4_0_0 EXIST::FUNCTION: -SSL_get_peer_finished 93 4_0_0 EXIST::FUNCTION: -PEM_read_SSL_SESSION 94 4_0_0 EXIST::FUNCTION:STDIO -PEM_write_SSL_SESSION 95 4_0_0 EXIST::FUNCTION:STDIO -PEM_read_bio_SSL_SESSION 96 4_0_0 EXIST::FUNCTION: -PEM_write_bio_SSL_SESSION 97 4_0_0 EXIST::FUNCTION: -SSL_get0_group_name 98 4_0_0 EXIST::FUNCTION: -SSL_group_to_name 99 4_0_0 EXIST::FUNCTION: -SSL_set0_tmp_dh_pkey 100 4_0_0 EXIST::FUNCTION: -SSL_CTX_set0_tmp_dh_pkey 101 4_0_0 EXIST::FUNCTION: -BIO_f_ssl 102 4_0_0 EXIST::FUNCTION: -BIO_new_ssl 103 4_0_0 EXIST::FUNCTION: -BIO_new_ssl_connect 104 4_0_0 EXIST::FUNCTION: -BIO_new_buffer_ssl_connect 105 4_0_0 EXIST::FUNCTION: -BIO_ssl_copy_session_id 106 4_0_0 EXIST::FUNCTION: -BIO_ssl_shutdown 107 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_cipher_list 108 4_0_0 EXIST::FUNCTION: -SSL_CTX_new 109 4_0_0 EXIST::FUNCTION: -SSL_CTX_new_ex 110 4_0_0 EXIST::FUNCTION: -SSL_CTX_up_ref 111 4_0_0 EXIST::FUNCTION: -SSL_CTX_free 112 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_timeout 113 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_timeout 114 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_cert_store 115 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_cert_store 116 4_0_0 EXIST::FUNCTION: -SSL_CTX_set1_cert_store 117 4_0_0 EXIST::FUNCTION: -SSL_want 118 4_0_0 EXIST::FUNCTION: -SSL_clear 119 4_0_0 EXIST::FUNCTION: -SSL_CTX_flush_sessions 120 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_4 -SSL_CTX_flush_sessions_ex 121 4_0_0 EXIST::FUNCTION: -SSL_get_current_cipher 122 4_0_0 EXIST::FUNCTION: -SSL_get_pending_cipher 123 4_0_0 EXIST::FUNCTION: -SSL_CIPHER_get_bits 124 4_0_0 EXIST::FUNCTION: -SSL_CIPHER_get_version 125 4_0_0 EXIST::FUNCTION: -SSL_CIPHER_get_name 126 4_0_0 EXIST::FUNCTION: -SSL_CIPHER_standard_name 127 4_0_0 EXIST::FUNCTION: -OPENSSL_cipher_name 128 4_0_0 EXIST::FUNCTION: -SSL_CIPHER_get_id 129 4_0_0 EXIST::FUNCTION: -SSL_CIPHER_get_protocol_id 130 4_0_0 EXIST::FUNCTION: -SSL_CIPHER_get_kx_nid 131 4_0_0 EXIST::FUNCTION: -SSL_CIPHER_get_auth_nid 132 4_0_0 EXIST::FUNCTION: -SSL_CIPHER_get_handshake_digest 133 4_0_0 EXIST::FUNCTION: -SSL_CIPHER_is_aead 134 4_0_0 EXIST::FUNCTION: -SSL_get_fd 135 4_0_0 EXIST::FUNCTION: -SSL_get_rfd 136 4_0_0 EXIST::FUNCTION: -SSL_get_wfd 137 4_0_0 EXIST::FUNCTION: -SSL_get_cipher_list 138 4_0_0 EXIST::FUNCTION: -SSL_get_shared_ciphers 139 4_0_0 EXIST::FUNCTION: -SSL_get_read_ahead 140 4_0_0 EXIST::FUNCTION: -SSL_pending 141 4_0_0 EXIST::FUNCTION: -SSL_has_pending 142 4_0_0 EXIST::FUNCTION: -SSL_set_fd 143 4_0_0 EXIST::FUNCTION:SOCK -SSL_set_rfd 144 4_0_0 EXIST::FUNCTION:SOCK -SSL_set_wfd 145 4_0_0 EXIST::FUNCTION:SOCK -SSL_set0_rbio 146 4_0_0 EXIST::FUNCTION: -SSL_set0_wbio 147 4_0_0 EXIST::FUNCTION: -SSL_set_bio 148 4_0_0 EXIST::FUNCTION: -SSL_get_rbio 149 4_0_0 EXIST::FUNCTION: -SSL_get_wbio 150 4_0_0 EXIST::FUNCTION: -SSL_set_cipher_list 151 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_ciphersuites 152 4_0_0 EXIST::FUNCTION: -SSL_set_ciphersuites 153 4_0_0 EXIST::FUNCTION: -SSL_set_read_ahead 154 4_0_0 EXIST::FUNCTION: -SSL_get_verify_mode 155 4_0_0 EXIST::FUNCTION: -SSL_get_verify_depth 156 4_0_0 EXIST::FUNCTION: -SSL_get_verify_callback 157 4_0_0 EXIST::FUNCTION: -SSL_set_verify 158 4_0_0 EXIST::FUNCTION: -SSL_set_verify_depth 159 4_0_0 EXIST::FUNCTION: -SSL_set_cert_cb 160 4_0_0 EXIST::FUNCTION: -SSL_use_RSAPrivateKey 161 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SSL_use_RSAPrivateKey_ASN1 162 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SSL_use_PrivateKey 163 4_0_0 EXIST::FUNCTION: -SSL_use_PrivateKey_ASN1 164 4_0_0 EXIST::FUNCTION: -SSL_use_certificate 165 4_0_0 EXIST::FUNCTION: -SSL_use_certificate_ASN1 166 4_0_0 EXIST::FUNCTION: -SSL_use_cert_and_key 167 4_0_0 EXIST::FUNCTION: -SSL_CTX_use_serverinfo 168 4_0_0 EXIST::FUNCTION: -SSL_CTX_use_serverinfo_ex 169 4_0_0 EXIST::FUNCTION: -SSL_CTX_use_serverinfo_file 170 4_0_0 EXIST::FUNCTION: -SSL_use_RSAPrivateKey_file 171 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SSL_use_PrivateKey_file 172 4_0_0 EXIST::FUNCTION: -SSL_use_certificate_file 173 4_0_0 EXIST::FUNCTION: -SSL_CTX_use_RSAPrivateKey_file 174 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SSL_CTX_use_PrivateKey_file 175 4_0_0 EXIST::FUNCTION: -SSL_CTX_use_certificate_file 176 4_0_0 EXIST::FUNCTION: -SSL_CTX_use_certificate_chain_file 177 4_0_0 EXIST::FUNCTION: -SSL_use_certificate_chain_file 178 4_0_0 EXIST::FUNCTION: -SSL_load_client_CA_file 179 4_0_0 EXIST::FUNCTION: -SSL_load_client_CA_file_ex 180 4_0_0 EXIST::FUNCTION: -SSL_add_file_cert_subjects_to_stack 181 4_0_0 EXIST::FUNCTION: -SSL_add_dir_cert_subjects_to_stack 182 4_0_0 EXIST::FUNCTION: -SSL_add_store_cert_subjects_to_stack 183 4_0_0 EXIST::FUNCTION: -SSL_state_string 184 4_0_0 EXIST::FUNCTION: -SSL_rstate_string 185 4_0_0 EXIST::FUNCTION: -SSL_state_string_long 186 4_0_0 EXIST::FUNCTION: -SSL_rstate_string_long 187 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get_time 188 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_4 -SSL_SESSION_set_time 189 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_4 -SSL_SESSION_get_timeout 190 4_0_0 EXIST::FUNCTION: -SSL_SESSION_set_timeout 191 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get_protocol_version 192 4_0_0 EXIST::FUNCTION: -SSL_SESSION_set_protocol_version 193 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get_time_ex 194 4_0_0 EXIST::FUNCTION: -SSL_SESSION_set_time_ex 195 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get0_hostname 196 4_0_0 EXIST::FUNCTION: -SSL_SESSION_set1_hostname 197 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get0_alpn_selected 198 4_0_0 EXIST::FUNCTION: -SSL_SESSION_set1_alpn_selected 199 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get0_cipher 200 4_0_0 EXIST::FUNCTION: -SSL_SESSION_set_cipher 201 4_0_0 EXIST::FUNCTION: -SSL_SESSION_has_ticket 202 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get_ticket_lifetime_hint 203 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get0_ticket 204 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get_max_early_data 205 4_0_0 EXIST::FUNCTION: -SSL_SESSION_set_max_early_data 206 4_0_0 EXIST::FUNCTION: -SSL_copy_session_id 207 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get0_peer 208 4_0_0 EXIST::FUNCTION: -SSL_SESSION_set1_id_context 209 4_0_0 EXIST::FUNCTION: -SSL_SESSION_set1_id 210 4_0_0 EXIST::FUNCTION: -SSL_SESSION_is_resumable 211 4_0_0 EXIST::FUNCTION: -SSL_SESSION_new 212 4_0_0 EXIST::FUNCTION: -SSL_SESSION_dup 213 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get_id 214 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get0_id_context 215 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get_compress_id 216 4_0_0 EXIST::FUNCTION: -SSL_SESSION_print_fp 217 4_0_0 EXIST::FUNCTION:STDIO -SSL_SESSION_print 218 4_0_0 EXIST::FUNCTION: -SSL_SESSION_print_keylog 219 4_0_0 EXIST::FUNCTION: -SSL_SESSION_up_ref 220 4_0_0 EXIST::FUNCTION: -SSL_SESSION_free 221 4_0_0 EXIST::FUNCTION: -i2d_SSL_SESSION 222 4_0_0 EXIST::FUNCTION: -SSL_set_session 223 4_0_0 EXIST::FUNCTION: -SSL_CTX_add_session 224 4_0_0 EXIST::FUNCTION: -SSL_CTX_remove_session 225 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_generate_session_id 226 4_0_0 EXIST::FUNCTION: -SSL_set_generate_session_id 227 4_0_0 EXIST::FUNCTION: -SSL_has_matching_session_id 228 4_0_0 EXIST::FUNCTION: -d2i_SSL_SESSION 229 4_0_0 EXIST::FUNCTION: -d2i_SSL_SESSION_ex 230 4_0_0 EXIST::FUNCTION: -SSL_get0_peer_certificate 231 4_0_0 EXIST::FUNCTION: -SSL_get1_peer_certificate 232 4_0_0 EXIST::FUNCTION: -SSL_get_peer_cert_chain 233 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_verify_mode 234 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_verify_depth 235 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_verify_callback 236 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_verify 237 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_verify_depth 238 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_cert_verify_callback 239 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_cert_cb 240 4_0_0 EXIST::FUNCTION: -SSL_CTX_use_RSAPrivateKey 241 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SSL_CTX_use_RSAPrivateKey_ASN1 242 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -SSL_CTX_use_PrivateKey 243 4_0_0 EXIST::FUNCTION: -SSL_CTX_use_PrivateKey_ASN1 244 4_0_0 EXIST::FUNCTION: -SSL_CTX_use_certificate 245 4_0_0 EXIST::FUNCTION: -SSL_CTX_use_certificate_ASN1 246 4_0_0 EXIST::FUNCTION: -SSL_CTX_use_cert_and_key 247 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_default_passwd_cb 248 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_default_passwd_cb_userdata 249 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_default_passwd_cb 250 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_default_passwd_cb_userdata 251 4_0_0 EXIST::FUNCTION: -SSL_set_default_passwd_cb 252 4_0_0 EXIST::FUNCTION: -SSL_set_default_passwd_cb_userdata 253 4_0_0 EXIST::FUNCTION: -SSL_get_default_passwd_cb 254 4_0_0 EXIST::FUNCTION: -SSL_get_default_passwd_cb_userdata 255 4_0_0 EXIST::FUNCTION: -SSL_CTX_check_private_key 256 4_0_0 EXIST::FUNCTION: -SSL_check_private_key 257 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_session_id_context 258 4_0_0 EXIST::FUNCTION: -SSL_new 259 4_0_0 EXIST::FUNCTION: -SSL_up_ref 260 4_0_0 EXIST::FUNCTION: -SSL_is_dtls 261 4_0_0 EXIST::FUNCTION: -SSL_is_tls 262 4_0_0 EXIST::FUNCTION: -SSL_is_quic 263 4_0_0 EXIST::FUNCTION: -SSL_set_session_id_context 264 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_purpose 265 4_0_0 EXIST::FUNCTION: -SSL_set_purpose 266 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_trust 267 4_0_0 EXIST::FUNCTION: -SSL_set_trust 268 4_0_0 EXIST::FUNCTION: -SSL_set1_host 269 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_0 -SSL_add1_host 270 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_0 -SSL_set1_dnsname 271 4_0_0 EXIST::FUNCTION: -SSL_add1_dnsname 272 4_0_0 EXIST::FUNCTION: -SSL_set1_ipaddr 273 4_0_0 EXIST::FUNCTION: -SSL_add1_ipaddr 274 4_0_0 EXIST::FUNCTION: -SSL_get0_peername 275 4_0_0 EXIST::FUNCTION: -SSL_set_hostflags 276 4_0_0 EXIST::FUNCTION: -SSL_CTX_dane_enable 277 4_0_0 EXIST::FUNCTION: -SSL_CTX_dane_mtype_set 278 4_0_0 EXIST::FUNCTION: -SSL_dane_enable 279 4_0_0 EXIST::FUNCTION: -SSL_dane_tlsa_add 280 4_0_0 EXIST::FUNCTION: -SSL_get0_dane_authority 281 4_0_0 EXIST::FUNCTION: -SSL_get0_dane_tlsa 282 4_0_0 EXIST::FUNCTION: -SSL_get0_dane 283 4_0_0 EXIST::FUNCTION: -SSL_CTX_dane_set_flags 284 4_0_0 EXIST::FUNCTION: -SSL_CTX_dane_clear_flags 285 4_0_0 EXIST::FUNCTION: -SSL_dane_set_flags 286 4_0_0 EXIST::FUNCTION: -SSL_dane_clear_flags 287 4_0_0 EXIST::FUNCTION: -SSL_CTX_set1_param 288 4_0_0 EXIST::FUNCTION: -SSL_set1_param 289 4_0_0 EXIST::FUNCTION: -SSL_CTX_get0_param 290 4_0_0 EXIST::FUNCTION: -SSL_get0_param 291 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_srp_username 292 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_CTX_set_srp_password 293 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_CTX_set_srp_strength 294 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_CTX_set_srp_client_pwd_callback 295 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_CTX_set_srp_verify_param_callback 296 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_CTX_set_srp_username_callback 297 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_CTX_set_srp_cb_arg 298 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_set_srp_server_param 299 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_set_srp_server_param_pw 300 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_get_srp_g 301 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_get_srp_N 302 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_get_srp_username 303 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_get_srp_userinfo 304 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP -SSL_CTX_set_client_hello_cb 305 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_new_pending_conn_cb 306 4_0_0 EXIST::FUNCTION: -SSL_client_hello_isv2 307 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_0 -SSL_client_hello_get0_legacy_version 308 4_0_0 EXIST::FUNCTION: -SSL_client_hello_get0_random 309 4_0_0 EXIST::FUNCTION: -SSL_client_hello_get0_session_id 310 4_0_0 EXIST::FUNCTION: -SSL_client_hello_get0_ciphers 311 4_0_0 EXIST::FUNCTION: -SSL_client_hello_get0_compression_methods 312 4_0_0 EXIST::FUNCTION: -SSL_client_hello_get1_extensions_present 313 4_0_0 EXIST::FUNCTION: -SSL_client_hello_get_extension_order 314 4_0_0 EXIST::FUNCTION: -SSL_client_hello_get0_ext 315 4_0_0 EXIST::FUNCTION: -SSL_certs_clear 316 4_0_0 EXIST::FUNCTION: -SSL_free 317 4_0_0 EXIST::FUNCTION: -SSL_waiting_for_async 318 4_0_0 EXIST::FUNCTION: -SSL_get_all_async_fds 319 4_0_0 EXIST::FUNCTION: -SSL_get_changed_async_fds 320 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_async_callback 321 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_async_callback_arg 322 4_0_0 EXIST::FUNCTION: -SSL_set_async_callback 323 4_0_0 EXIST::FUNCTION: -SSL_set_async_callback_arg 324 4_0_0 EXIST::FUNCTION: -SSL_get_async_status 325 4_0_0 EXIST::FUNCTION: -SSL_accept 326 4_0_0 EXIST::FUNCTION: -SSL_stateless 327 4_0_0 EXIST::FUNCTION: -SSL_connect 328 4_0_0 EXIST::FUNCTION: -SSL_read 329 4_0_0 EXIST::FUNCTION: -SSL_read_ex 330 4_0_0 EXIST::FUNCTION: -SSL_read_early_data 331 4_0_0 EXIST::FUNCTION: -SSL_peek 332 4_0_0 EXIST::FUNCTION: -SSL_peek_ex 333 4_0_0 EXIST::FUNCTION: -SSL_sendfile 334 4_0_0 EXIST::FUNCTION: -SSL_write 335 4_0_0 EXIST::FUNCTION: -SSL_write_ex 336 4_0_0 EXIST::FUNCTION: -SSL_write_early_data 337 4_0_0 EXIST::FUNCTION: -SSL_ctrl 338 4_0_0 EXIST::FUNCTION: -SSL_callback_ctrl 339 4_0_0 EXIST::FUNCTION: -SSL_CTX_ctrl 340 4_0_0 EXIST::FUNCTION: -SSL_CTX_callback_ctrl 341 4_0_0 EXIST::FUNCTION: -SSL_write_ex2 342 4_0_0 EXIST::FUNCTION: -SSL_get_early_data_status 343 4_0_0 EXIST::FUNCTION: -SSL_get_error 344 4_0_0 EXIST::FUNCTION: -SSL_get_version 345 4_0_0 EXIST::FUNCTION: -SSL_get_handshake_rtt 346 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_ssl_version 347 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 -TLS_method 348 4_0_0 EXIST::FUNCTION: -TLS_server_method 349 4_0_0 EXIST::FUNCTION: -TLS_client_method 350 4_0_0 EXIST::FUNCTION: -DTLS_method 351 4_0_0 EXIST::FUNCTION: -DTLS_server_method 352 4_0_0 EXIST::FUNCTION: -DTLS_client_method 353 4_0_0 EXIST::FUNCTION: -DTLS_get_data_mtu 354 4_0_0 EXIST::FUNCTION: -SSL_get_ciphers 355 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_ciphers 356 4_0_0 EXIST::FUNCTION: -SSL_get_client_ciphers 357 4_0_0 EXIST::FUNCTION: -SSL_get1_supported_ciphers 358 4_0_0 EXIST::FUNCTION: -SSL_do_handshake 359 4_0_0 EXIST::FUNCTION: -SSL_key_update 360 4_0_0 EXIST::FUNCTION: -SSL_get_key_update_type 361 4_0_0 EXIST::FUNCTION: -SSL_renegotiate 362 4_0_0 EXIST::FUNCTION: -SSL_renegotiate_abbreviated 363 4_0_0 EXIST::FUNCTION: -SSL_renegotiate_pending 364 4_0_0 EXIST::FUNCTION: -SSL_new_session_ticket 365 4_0_0 EXIST::FUNCTION: -SSL_shutdown 366 4_0_0 EXIST::FUNCTION: -SSL_verify_client_post_handshake 367 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_post_handshake_auth 368 4_0_0 EXIST::FUNCTION: -SSL_set_post_handshake_auth 369 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_ssl_method 370 4_0_0 EXIST::FUNCTION: -SSL_get_ssl_method 371 4_0_0 EXIST::FUNCTION: -SSL_set_ssl_method 372 4_0_0 EXIST::FUNCTION: -SSL_alert_type_string_long 373 4_0_0 EXIST::FUNCTION: -SSL_alert_type_string 374 4_0_0 EXIST::FUNCTION: -SSL_alert_desc_string_long 375 4_0_0 EXIST::FUNCTION: -SSL_alert_desc_string 376 4_0_0 EXIST::FUNCTION: -SSL_set0_CA_list 377 4_0_0 EXIST::FUNCTION: -SSL_CTX_set0_CA_list 378 4_0_0 EXIST::FUNCTION: -SSL_get0_CA_list 379 4_0_0 EXIST::FUNCTION: -SSL_CTX_get0_CA_list 380 4_0_0 EXIST::FUNCTION: -SSL_add1_to_CA_list 381 4_0_0 EXIST::FUNCTION: -SSL_CTX_add1_to_CA_list 382 4_0_0 EXIST::FUNCTION: -SSL_get0_peer_CA_list 383 4_0_0 EXIST::FUNCTION: -SSL_set_client_CA_list 384 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_client_CA_list 385 4_0_0 EXIST::FUNCTION: -SSL_get_client_CA_list 386 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_client_CA_list 387 4_0_0 EXIST::FUNCTION: -SSL_add_client_CA 388 4_0_0 EXIST::FUNCTION: -SSL_CTX_add_client_CA 389 4_0_0 EXIST::FUNCTION: -SSL_set_connect_state 390 4_0_0 EXIST::FUNCTION: -SSL_set_accept_state 391 4_0_0 EXIST::FUNCTION: -SSL_get_default_timeout 392 4_0_0 EXIST::FUNCTION: -SSL_CIPHER_description 393 4_0_0 EXIST::FUNCTION: -SSL_dup_CA_list 394 4_0_0 EXIST::FUNCTION: -SSL_dup 395 4_0_0 EXIST::FUNCTION: -SSL_get_certificate 396 4_0_0 EXIST::FUNCTION: -SSL_get_privatekey 397 4_0_0 EXIST::FUNCTION: -SSL_CTX_get0_certificate 398 4_0_0 EXIST::FUNCTION: -SSL_CTX_get0_privatekey 399 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_quiet_shutdown 400 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_quiet_shutdown 401 4_0_0 EXIST::FUNCTION: -SSL_set_quiet_shutdown 402 4_0_0 EXIST::FUNCTION: -SSL_get_quiet_shutdown 403 4_0_0 EXIST::FUNCTION: -SSL_set_shutdown 404 4_0_0 EXIST::FUNCTION: -SSL_get_shutdown 405 4_0_0 EXIST::FUNCTION: -SSL_version 406 4_0_0 EXIST::FUNCTION: -SSL_client_version 407 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_default_verify_paths 408 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_default_verify_dir 409 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_default_verify_file 410 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_default_verify_store 411 4_0_0 EXIST::FUNCTION: -SSL_CTX_load_verify_file 412 4_0_0 EXIST::FUNCTION: -SSL_CTX_load_verify_dir 413 4_0_0 EXIST::FUNCTION: -SSL_CTX_load_verify_store 414 4_0_0 EXIST::FUNCTION: -SSL_CTX_load_verify_locations 415 4_0_0 EXIST::FUNCTION: -SSL_get_session 416 4_0_0 EXIST::FUNCTION: -SSL_get1_session 417 4_0_0 EXIST::FUNCTION: -SSL_get_SSL_CTX 418 4_0_0 EXIST::FUNCTION: -SSL_set_SSL_CTX 419 4_0_0 EXIST::FUNCTION: -SSL_set_info_callback 420 4_0_0 EXIST::FUNCTION: -SSL_get_info_callback 421 4_0_0 EXIST::FUNCTION: -SSL_get_state 422 4_0_0 EXIST::FUNCTION: -SSL_set_verify_result 423 4_0_0 EXIST::FUNCTION: -SSL_get_verify_result 424 4_0_0 EXIST::FUNCTION: -SSL_get0_verified_chain 425 4_0_0 EXIST::FUNCTION: -SSL_get_client_random 426 4_0_0 EXIST::FUNCTION: -SSL_get_server_random 427 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get_master_key 428 4_0_0 EXIST::FUNCTION: -SSL_SESSION_set1_master_key 429 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get_max_fragment_length 430 4_0_0 EXIST::FUNCTION: -SSL_set_ex_data 431 4_0_0 EXIST::FUNCTION: -SSL_get_ex_data 432 4_0_0 EXIST::FUNCTION: -SSL_SESSION_set_ex_data 433 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get_ex_data 434 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_ex_data 435 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_ex_data 436 4_0_0 EXIST::FUNCTION: -SSL_get_ex_data_X509_STORE_CTX_idx 437 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_default_read_buffer_len 438 4_0_0 EXIST::FUNCTION: -SSL_set_default_read_buffer_len 439 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_tmp_dh_callback 440 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -SSL_set_tmp_dh_callback 441 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH -SSL_get_current_compression 442 4_0_0 EXIST::FUNCTION: -SSL_get_current_expansion 443 4_0_0 EXIST::FUNCTION: -SSL_COMP_get_name 444 4_0_0 EXIST::FUNCTION: -SSL_COMP_get0_name 445 4_0_0 EXIST::FUNCTION: -SSL_COMP_get_id 446 4_0_0 EXIST::FUNCTION: -SSL_COMP_get_compression_methods 447 4_0_0 EXIST::FUNCTION: -SSL_COMP_set0_compression_methods 448 4_0_0 EXIST::FUNCTION: -SSL_COMP_add_compression_method 449 4_0_0 EXIST::FUNCTION: -SSL_CIPHER_find 450 4_0_0 EXIST::FUNCTION: -SSL_CIPHER_get_cipher_nid 451 4_0_0 EXIST::FUNCTION: -SSL_CIPHER_get_digest_nid 452 4_0_0 EXIST::FUNCTION: -SSL_bytes_to_cipher_list 453 4_0_0 EXIST::FUNCTION: -SSL_set_session_ticket_ext 454 4_0_0 EXIST::FUNCTION: -SSL_set_session_ticket_ext_cb 455 4_0_0 EXIST::FUNCTION: -SSL_set_session_secret_cb 456 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_not_resumable_session_callback 457 4_0_0 EXIST::FUNCTION: -SSL_set_not_resumable_session_callback 458 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_record_padding_callback 459 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_record_padding_callback_arg 460 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_record_padding_callback_arg 461 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_block_padding 462 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_block_padding_ex 463 4_0_0 EXIST::FUNCTION: -SSL_set_record_padding_callback 464 4_0_0 EXIST::FUNCTION: -SSL_set_record_padding_callback_arg 465 4_0_0 EXIST::FUNCTION: -SSL_get_record_padding_callback_arg 466 4_0_0 EXIST::FUNCTION: -SSL_set_block_padding 467 4_0_0 EXIST::FUNCTION: -SSL_set_block_padding_ex 468 4_0_0 EXIST::FUNCTION: -SSL_set_num_tickets 469 4_0_0 EXIST::FUNCTION: -SSL_get_num_tickets 470 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_num_tickets 471 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_num_tickets 472 4_0_0 EXIST::FUNCTION: -SSL_handle_events 473 4_0_0 EXIST::FUNCTION: -SSL_get_event_timeout 474 4_0_0 EXIST::FUNCTION: -SSL_get_peer_addr 475 4_0_0 EXIST::FUNCTION: -SSL_get_rpoll_descriptor 476 4_0_0 EXIST::FUNCTION: -SSL_get_wpoll_descriptor 477 4_0_0 EXIST::FUNCTION: -SSL_net_read_desired 478 4_0_0 EXIST::FUNCTION: -SSL_net_write_desired 479 4_0_0 EXIST::FUNCTION: -SSL_set_blocking_mode 480 4_0_0 EXIST::FUNCTION: -SSL_get_blocking_mode 481 4_0_0 EXIST::FUNCTION: -SSL_set1_initial_peer_addr 482 4_0_0 EXIST::FUNCTION: -SSL_get0_connection 483 4_0_0 EXIST::FUNCTION: -SSL_is_connection 484 4_0_0 EXIST::FUNCTION: -SSL_is_listener 485 4_0_0 EXIST::FUNCTION: -SSL_get0_listener 486 4_0_0 EXIST::FUNCTION: -SSL_new_listener 487 4_0_0 EXIST::FUNCTION: -SSL_new_listener_from 488 4_0_0 EXIST::FUNCTION: -SSL_new_from_listener 489 4_0_0 EXIST::FUNCTION: -SSL_accept_connection 490 4_0_0 EXIST::FUNCTION: -SSL_get_accept_connection_queue_len 491 4_0_0 EXIST::FUNCTION: -SSL_listen 492 4_0_0 EXIST::FUNCTION: -SSL_is_domain 493 4_0_0 EXIST::FUNCTION: -SSL_get0_domain 494 4_0_0 EXIST::FUNCTION: -SSL_new_domain 495 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_domain_flags 496 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_domain_flags 497 4_0_0 EXIST::FUNCTION: -SSL_get_domain_flags 498 4_0_0 EXIST::FUNCTION: -SSL_get_stream_type 499 4_0_0 EXIST::FUNCTION: -SSL_get_stream_id 500 4_0_0 EXIST::FUNCTION: -SSL_is_stream_local 501 4_0_0 EXIST::FUNCTION: -SSL_set_default_stream_mode 502 4_0_0 EXIST::FUNCTION: -SSL_new_stream 503 4_0_0 EXIST::FUNCTION: -SSL_set_incoming_stream_policy 504 4_0_0 EXIST::FUNCTION: -SSL_accept_stream 505 4_0_0 EXIST::FUNCTION: -SSL_get_accept_stream_queue_len 506 4_0_0 EXIST::FUNCTION: -SSL_inject_net_dgram 507 4_0_0 EXIST::FUNCTION:QUIC -SSL_shutdown_ex 508 4_0_0 EXIST::FUNCTION: -SSL_stream_conclude 509 4_0_0 EXIST::FUNCTION: -SSL_stream_reset 510 4_0_0 EXIST::FUNCTION: -SSL_get_stream_read_state 511 4_0_0 EXIST::FUNCTION: -SSL_get_stream_write_state 512 4_0_0 EXIST::FUNCTION: -SSL_get_stream_read_error_code 513 4_0_0 EXIST::FUNCTION: -SSL_get_stream_write_error_code 514 4_0_0 EXIST::FUNCTION: -SSL_get_conn_close_info 515 4_0_0 EXIST::FUNCTION: -SSL_get_value_uint 516 4_0_0 EXIST::FUNCTION: -SSL_set_value_uint 517 4_0_0 EXIST::FUNCTION: -SSL_poll 518 4_0_0 EXIST::FUNCTION: -SSL_session_reused 519 4_0_0 EXIST::FUNCTION: -SSL_is_server 520 4_0_0 EXIST::FUNCTION: -SSL_CONF_CTX_new 521 4_0_0 EXIST::FUNCTION: -SSL_CONF_CTX_finish 522 4_0_0 EXIST::FUNCTION: -SSL_CONF_CTX_free 523 4_0_0 EXIST::FUNCTION: -SSL_CONF_CTX_set_flags 524 4_0_0 EXIST::FUNCTION: -SSL_CONF_CTX_clear_flags 525 4_0_0 EXIST::FUNCTION: -SSL_CONF_CTX_set1_prefix 526 4_0_0 EXIST::FUNCTION: -SSL_CONF_CTX_set_ssl 527 4_0_0 EXIST::FUNCTION: -SSL_CONF_CTX_set_ssl_ctx 528 4_0_0 EXIST::FUNCTION: -SSL_CONF_cmd 529 4_0_0 EXIST::FUNCTION: -SSL_CONF_cmd_argv 530 4_0_0 EXIST::FUNCTION: -SSL_CONF_cmd_value_type 531 4_0_0 EXIST::FUNCTION: -SSL_add_ssl_module 532 4_0_0 EXIST::FUNCTION: -SSL_config 533 4_0_0 EXIST::FUNCTION: -SSL_CTX_config 534 4_0_0 EXIST::FUNCTION: -SSL_trace 535 4_0_0 EXIST::FUNCTION:SSL_TRACE -DTLSv1_listen 536 4_0_0 EXIST::FUNCTION:SOCK -SSL_set_ct_validation_callback 537 4_0_0 EXIST::FUNCTION:CT -SSL_CTX_set_ct_validation_callback 538 4_0_0 EXIST::FUNCTION:CT -SSL_enable_ct 539 4_0_0 EXIST::FUNCTION:CT -SSL_CTX_enable_ct 540 4_0_0 EXIST::FUNCTION:CT -SSL_ct_is_enabled 541 4_0_0 EXIST::FUNCTION:CT -SSL_CTX_ct_is_enabled 542 4_0_0 EXIST::FUNCTION:CT -SSL_get0_peer_scts 543 4_0_0 EXIST::FUNCTION:CT -SSL_CTX_set_default_ctlog_list_file 544 4_0_0 EXIST::FUNCTION:CT -SSL_CTX_set_ctlog_list_file 545 4_0_0 EXIST::FUNCTION:CT -SSL_CTX_set0_ctlog_store 546 4_0_0 EXIST::FUNCTION:CT -SSL_CTX_get0_ctlog_store 547 4_0_0 EXIST::FUNCTION:CT -SSL_set_security_level 548 4_0_0 EXIST::FUNCTION: -SSL_get_security_level 549 4_0_0 EXIST::FUNCTION: -SSL_set_security_callback 550 4_0_0 EXIST::FUNCTION: -SSL_get_security_callback 551 4_0_0 EXIST::FUNCTION: -SSL_set0_security_ex_data 552 4_0_0 EXIST::FUNCTION: -SSL_get0_security_ex_data 553 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_security_level 554 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_security_level 555 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_security_callback 556 4_0_0 EXIST::FUNCTION: -SSL_CTX_get_security_callback 557 4_0_0 EXIST::FUNCTION: -SSL_CTX_set0_security_ex_data 558 4_0_0 EXIST::FUNCTION: -SSL_CTX_get0_security_ex_data 559 4_0_0 EXIST::FUNCTION: -OPENSSL_init_ssl 560 4_0_0 EXIST::FUNCTION: -SSL_test_functions 561 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_4_1,UNIT_TEST -SSL_free_buffers 562 4_0_0 EXIST::FUNCTION: -SSL_alloc_buffers 563 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_session_ticket_cb 564 4_0_0 EXIST::FUNCTION: -SSL_SESSION_set1_ticket_appdata 565 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get0_ticket_appdata 566 4_0_0 EXIST::FUNCTION: -DTLS_set_timer_cb 567 4_0_0 EXIST::FUNCTION: -SSL_CTX_set_allow_early_data_cb 568 4_0_0 EXIST::FUNCTION: -SSL_set_allow_early_data_cb 569 4_0_0 EXIST::FUNCTION: -OSSL_default_cipher_list 570 4_0_0 EXIST::FUNCTION: -OSSL_default_ciphersuites 571 4_0_0 EXIST::FUNCTION: -SSL_CTX_compress_certs 572 4_0_0 EXIST::FUNCTION: -SSL_compress_certs 573 4_0_0 EXIST::FUNCTION: -SSL_CTX_set1_cert_comp_preference 574 4_0_0 EXIST::FUNCTION: -SSL_set1_cert_comp_preference 575 4_0_0 EXIST::FUNCTION: -SSL_CTX_set1_compressed_cert 576 4_0_0 EXIST::FUNCTION: -SSL_set1_compressed_cert 577 4_0_0 EXIST::FUNCTION: -SSL_CTX_get1_compressed_cert 578 4_0_0 EXIST::FUNCTION: -SSL_get1_compressed_cert 579 4_0_0 EXIST::FUNCTION: -SSL_add_expected_rpk 580 4_0_0 EXIST::FUNCTION: -SSL_get0_peer_rpk 581 4_0_0 EXIST::FUNCTION: -SSL_SESSION_get0_peer_rpk 582 4_0_0 EXIST::FUNCTION: -SSL_get_negotiated_client_cert_type 583 4_0_0 EXIST::FUNCTION: -SSL_get_negotiated_server_cert_type 584 4_0_0 EXIST::FUNCTION: -SSL_set1_client_cert_type 585 4_0_0 EXIST::FUNCTION: -SSL_set1_server_cert_type 586 4_0_0 EXIST::FUNCTION: -SSL_CTX_set1_client_cert_type 587 4_0_0 EXIST::FUNCTION: -SSL_CTX_set1_server_cert_type 588 4_0_0 EXIST::FUNCTION: -SSL_get0_client_cert_type 589 4_0_0 EXIST::FUNCTION: -SSL_get0_server_cert_type 590 4_0_0 EXIST::FUNCTION: -SSL_CTX_get0_client_cert_type 591 4_0_0 EXIST::FUNCTION: -SSL_CTX_get0_server_cert_type 592 4_0_0 EXIST::FUNCTION: -SSL_set_quic_tls_cbs 593 4_0_0 EXIST::FUNCTION: -SSL_set_quic_tls_transport_params 594 4_0_0 EXIST::FUNCTION: -SSL_set_quic_tls_early_data_enabled 595 4_0_0 EXIST::FUNCTION: -SSL_CTX_is_quic 596 4_0_0 EXIST::FUNCTION: -SSL_CTX_is_server 597 4_0_0 EXIST::FUNCTION: -OSSL_QUIC_method 598 4_0_0 EXIST::FUNCTION:QUIC -SSL_listen_ex 599 4_0_0 EXIST::FUNCTION: -OSSL_ECHSTORE_new 600 4_0_0 EXIST::FUNCTION:ECH -OSSL_ECHSTORE_free 601 4_0_0 EXIST::FUNCTION:ECH -OSSL_ECHSTORE_new_config 602 4_0_0 EXIST::FUNCTION:ECH -OSSL_ECHSTORE_write_pem 603 4_0_0 EXIST::FUNCTION:ECH -OSSL_ECHSTORE_read_echconfiglist 604 4_0_0 EXIST::FUNCTION:ECH -OSSL_ECHSTORE_get1_info 605 4_0_0 EXIST::FUNCTION:ECH -OSSL_ECHSTORE_downselect 606 4_0_0 EXIST::FUNCTION:ECH -OSSL_ECHSTORE_set1_key_and_read_pem 607 4_0_0 EXIST::FUNCTION:ECH -OSSL_ECHSTORE_read_pem 608 4_0_0 EXIST::FUNCTION:ECH -OSSL_ECHSTORE_num_keys 609 4_0_0 EXIST::FUNCTION:ECH -OSSL_ECHSTORE_flush_keys 610 4_0_0 EXIST::FUNCTION:ECH -SSL_CTX_set1_echstore 611 4_0_0 EXIST::FUNCTION:ECH -SSL_set1_echstore 612 4_0_0 EXIST::FUNCTION:ECH -SSL_CTX_get1_echstore 613 4_0_0 EXIST::FUNCTION:ECH -SSL_get1_echstore 614 4_0_0 EXIST::FUNCTION:ECH -SSL_ech_get1_status 615 4_0_0 EXIST::FUNCTION:ECH -SSL_ech_set_grease_type 616 4_0_0 EXIST::FUNCTION:ECH -SSL_ech_set_callback 617 4_0_0 EXIST::FUNCTION:ECH -SSL_CTX_ech_set_callback 618 4_0_0 EXIST::FUNCTION:ECH -OSSL_ECHSTORE_num_entries 619 4_0_0 EXIST::FUNCTION:ECH -SSL_ech_set1_server_names 620 4_0_0 EXIST::FUNCTION:ECH -SSL_ech_set1_outer_server_name 621 4_0_0 EXIST::FUNCTION:ECH -SSL_ech_set1_outer_alpn_protos 622 4_0_0 EXIST::FUNCTION:ECH -SSL_ech_set1_grease_suite 623 4_0_0 EXIST::FUNCTION:ECH -SSL_ech_get1_retry_config 624 4_0_0 EXIST::FUNCTION:ECH -SSL_CTX_ech_set1_outer_alpn_protos 625 4_0_0 EXIST::FUNCTION:ECH -SSL_set1_ech_config_list 626 4_0_0 EXIST::FUNCTION:ECH -SSL_get0_sigalg 627 4_0_0 EXIST::FUNCTION: -SSL_get0_shared_sigalg 628 4_0_0 EXIST::FUNCTION: +OSSL_QUIC_client_method ? 4_0_0 EXIST::FUNCTION:QUIC +OSSL_QUIC_client_thread_method ? 4_0_0 EXIST::FUNCTION:QUIC +OSSL_QUIC_server_method ? 4_0_0 EXIST::FUNCTION:QUIC +SSL_CTX_set_tlsext_use_srtp ? 4_0_0 EXIST::FUNCTION:SRTP +SSL_set_tlsext_use_srtp ? 4_0_0 EXIST::FUNCTION:SRTP +SSL_get_srtp_profiles ? 4_0_0 EXIST::FUNCTION:SRTP +SSL_get_selected_srtp_profile ? 4_0_0 EXIST::FUNCTION:SRTP +ERR_load_SSL_strings ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SSL_CTX_set_tlsext_max_fragment_length ? 4_0_0 EXIST::FUNCTION: +SSL_set_tlsext_max_fragment_length ? 4_0_0 EXIST::FUNCTION: +SSL_get_servername ? 4_0_0 EXIST::FUNCTION: +SSL_get_servername_type ? 4_0_0 EXIST::FUNCTION: +SSL_export_keying_material ? 4_0_0 EXIST::FUNCTION: +SSL_export_keying_material_early ? 4_0_0 EXIST::FUNCTION: +SSL_get_peer_signature_type_nid ? 4_0_0 EXIST::FUNCTION: +SSL_get_signature_type_nid ? 4_0_0 EXIST::FUNCTION: +SSL_get_sigalgs ? 4_0_0 EXIST::FUNCTION: +SSL_get1_builtin_sigalgs ? 4_0_0 EXIST::FUNCTION: +SSL_get_shared_sigalgs ? 4_0_0 EXIST::FUNCTION: +SSL_check_chain ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_tlsext_ticket_key_evp_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_options ? 4_0_0 EXIST::FUNCTION: +SSL_get_options ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_clear_options ? 4_0_0 EXIST::FUNCTION: +SSL_clear_options ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_options ? 4_0_0 EXIST::FUNCTION: +SSL_set_options ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_msg_callback ? 4_0_0 EXIST::FUNCTION: +SSL_set_msg_callback ? 4_0_0 EXIST::FUNCTION: +SSL_SRP_CTX_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_CTX_SRP_CTX_init ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_SRP_CTX_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_CTX_SRP_CTX_free ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_srp_server_param_with_username ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SRP_Calc_A_param ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_CTX_sessions ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_sess_set_new_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_sess_get_new_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_sess_set_remove_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_sess_get_remove_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_sess_set_get_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_sess_get_get_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_info_callback ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_info_callback ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_client_cert_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_client_cert_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_cookie_generate_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_cookie_verify_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_stateless_cookie_generate_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_stateless_cookie_verify_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_next_protos_advertised_cb ? 4_0_0 EXIST::FUNCTION:NEXTPROTONEG +SSL_CTX_set_next_proto_select_cb ? 4_0_0 EXIST::FUNCTION:NEXTPROTONEG +SSL_get0_next_proto_negotiated ? 4_0_0 EXIST::FUNCTION:NEXTPROTONEG +SSL_select_next_proto ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_alpn_protos ? 4_0_0 EXIST::FUNCTION: +SSL_set_alpn_protos ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_alpn_select_cb ? 4_0_0 EXIST::FUNCTION: +SSL_get0_alpn_selected ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_psk_client_callback ? 4_0_0 EXIST::FUNCTION:PSK +SSL_set_psk_client_callback ? 4_0_0 EXIST::FUNCTION:PSK +SSL_CTX_set_psk_server_callback ? 4_0_0 EXIST::FUNCTION:PSK +SSL_set_psk_server_callback ? 4_0_0 EXIST::FUNCTION:PSK +SSL_CTX_use_psk_identity_hint ? 4_0_0 EXIST::FUNCTION:PSK +SSL_use_psk_identity_hint ? 4_0_0 EXIST::FUNCTION:PSK +SSL_get_psk_identity_hint ? 4_0_0 EXIST::FUNCTION:PSK +SSL_get_psk_identity ? 4_0_0 EXIST::FUNCTION:PSK +SSL_set_psk_find_session_callback ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_psk_find_session_callback ? 4_0_0 EXIST::FUNCTION: +SSL_set_psk_use_session_callback ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_psk_use_session_callback ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_has_client_custom_ext ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_add_client_custom_ext ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_add_server_custom_ext ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_add_custom_ext ? 4_0_0 EXIST::FUNCTION: +SSL_extension_supported ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_keylog_callback ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_keylog_callback ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_max_early_data ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_max_early_data ? 4_0_0 EXIST::FUNCTION: +SSL_set_max_early_data ? 4_0_0 EXIST::FUNCTION: +SSL_get_max_early_data ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_recv_max_early_data ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_recv_max_early_data ? 4_0_0 EXIST::FUNCTION: +SSL_set_recv_max_early_data ? 4_0_0 EXIST::FUNCTION: +SSL_get_recv_max_early_data ? 4_0_0 EXIST::FUNCTION: +SSL_set_debug ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0 +SSL_in_init ? 4_0_0 EXIST::FUNCTION: +SSL_in_before ? 4_0_0 EXIST::FUNCTION: +SSL_is_init_finished ? 4_0_0 EXIST::FUNCTION: +SSL_get_finished ? 4_0_0 EXIST::FUNCTION: +SSL_get_peer_finished ? 4_0_0 EXIST::FUNCTION: +PEM_read_SSL_SESSION ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_write_SSL_SESSION ? 4_0_0 EXIST::FUNCTION:STDIO +PEM_read_bio_SSL_SESSION ? 4_0_0 EXIST::FUNCTION: +PEM_write_bio_SSL_SESSION ? 4_0_0 EXIST::FUNCTION: +SSL_get0_group_name ? 4_0_0 EXIST::FUNCTION: +SSL_group_to_name ? 4_0_0 EXIST::FUNCTION: +SSL_set0_tmp_dh_pkey ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set0_tmp_dh_pkey ? 4_0_0 EXIST::FUNCTION: +BIO_f_ssl ? 4_0_0 EXIST::FUNCTION: +BIO_new_ssl ? 4_0_0 EXIST::FUNCTION: +BIO_new_ssl_connect ? 4_0_0 EXIST::FUNCTION: +BIO_new_buffer_ssl_connect ? 4_0_0 EXIST::FUNCTION: +BIO_ssl_copy_session_id ? 4_0_0 EXIST::FUNCTION: +BIO_ssl_shutdown ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_cipher_list ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_new ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_new_ex ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_up_ref ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_free ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_timeout ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_timeout ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_cert_store ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_cert_store ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set1_cert_store ? 4_0_0 EXIST::FUNCTION: +SSL_want ? 4_0_0 EXIST::FUNCTION: +SSL_clear ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_flush_sessions ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_4 +SSL_CTX_flush_sessions_ex ? 4_0_0 EXIST::FUNCTION: +SSL_get_current_cipher ? 4_0_0 EXIST::FUNCTION: +SSL_get_pending_cipher ? 4_0_0 EXIST::FUNCTION: +SSL_CIPHER_get_bits ? 4_0_0 EXIST::FUNCTION: +SSL_CIPHER_get_version ? 4_0_0 EXIST::FUNCTION: +SSL_CIPHER_get_name ? 4_0_0 EXIST::FUNCTION: +SSL_CIPHER_standard_name ? 4_0_0 EXIST::FUNCTION: +OPENSSL_cipher_name ? 4_0_0 EXIST::FUNCTION: +SSL_CIPHER_get_id ? 4_0_0 EXIST::FUNCTION: +SSL_CIPHER_get_protocol_id ? 4_0_0 EXIST::FUNCTION: +SSL_CIPHER_get_kx_nid ? 4_0_0 EXIST::FUNCTION: +SSL_CIPHER_get_auth_nid ? 4_0_0 EXIST::FUNCTION: +SSL_CIPHER_get_handshake_digest ? 4_0_0 EXIST::FUNCTION: +SSL_CIPHER_is_aead ? 4_0_0 EXIST::FUNCTION: +SSL_get_fd ? 4_0_0 EXIST::FUNCTION: +SSL_get_rfd ? 4_0_0 EXIST::FUNCTION: +SSL_get_wfd ? 4_0_0 EXIST::FUNCTION: +SSL_get_cipher_list ? 4_0_0 EXIST::FUNCTION: +SSL_get_shared_ciphers ? 4_0_0 EXIST::FUNCTION: +SSL_get_read_ahead ? 4_0_0 EXIST::FUNCTION: +SSL_pending ? 4_0_0 EXIST::FUNCTION: +SSL_has_pending ? 4_0_0 EXIST::FUNCTION: +SSL_set_fd ? 4_0_0 EXIST::FUNCTION:SOCK +SSL_set_rfd ? 4_0_0 EXIST::FUNCTION:SOCK +SSL_set_wfd ? 4_0_0 EXIST::FUNCTION:SOCK +SSL_set0_rbio ? 4_0_0 EXIST::FUNCTION: +SSL_set0_wbio ? 4_0_0 EXIST::FUNCTION: +SSL_set_bio ? 4_0_0 EXIST::FUNCTION: +SSL_get_rbio ? 4_0_0 EXIST::FUNCTION: +SSL_get_wbio ? 4_0_0 EXIST::FUNCTION: +SSL_set_cipher_list ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_ciphersuites ? 4_0_0 EXIST::FUNCTION: +SSL_set_ciphersuites ? 4_0_0 EXIST::FUNCTION: +SSL_set_read_ahead ? 4_0_0 EXIST::FUNCTION: +SSL_get_verify_mode ? 4_0_0 EXIST::FUNCTION: +SSL_get_verify_depth ? 4_0_0 EXIST::FUNCTION: +SSL_get_verify_callback ? 4_0_0 EXIST::FUNCTION: +SSL_set_verify ? 4_0_0 EXIST::FUNCTION: +SSL_set_verify_depth ? 4_0_0 EXIST::FUNCTION: +SSL_set_cert_cb ? 4_0_0 EXIST::FUNCTION: +SSL_use_RSAPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SSL_use_RSAPrivateKey_ASN1 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SSL_use_PrivateKey ? 4_0_0 EXIST::FUNCTION: +SSL_use_PrivateKey_ASN1 ? 4_0_0 EXIST::FUNCTION: +SSL_use_certificate ? 4_0_0 EXIST::FUNCTION: +SSL_use_certificate_ASN1 ? 4_0_0 EXIST::FUNCTION: +SSL_use_cert_and_key ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_use_serverinfo ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_use_serverinfo_ex ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_use_serverinfo_file ? 4_0_0 EXIST::FUNCTION: +SSL_use_RSAPrivateKey_file ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SSL_use_PrivateKey_file ? 4_0_0 EXIST::FUNCTION: +SSL_use_certificate_file ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_use_RSAPrivateKey_file ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SSL_CTX_use_PrivateKey_file ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_use_certificate_file ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_use_certificate_chain_file ? 4_0_0 EXIST::FUNCTION: +SSL_use_certificate_chain_file ? 4_0_0 EXIST::FUNCTION: +SSL_load_client_CA_file ? 4_0_0 EXIST::FUNCTION: +SSL_load_client_CA_file_ex ? 4_0_0 EXIST::FUNCTION: +SSL_add_file_cert_subjects_to_stack ? 4_0_0 EXIST::FUNCTION: +SSL_add_dir_cert_subjects_to_stack ? 4_0_0 EXIST::FUNCTION: +SSL_add_store_cert_subjects_to_stack ? 4_0_0 EXIST::FUNCTION: +SSL_state_string ? 4_0_0 EXIST::FUNCTION: +SSL_rstate_string ? 4_0_0 EXIST::FUNCTION: +SSL_state_string_long ? 4_0_0 EXIST::FUNCTION: +SSL_rstate_string_long ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get_time ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_4 +SSL_SESSION_set_time ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_4 +SSL_SESSION_get_timeout ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_set_timeout ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get_protocol_version ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_set_protocol_version ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get_time_ex ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_set_time_ex ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get0_hostname ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_set1_hostname ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get0_alpn_selected ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_set1_alpn_selected ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get0_cipher ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_set_cipher ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_has_ticket ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get_ticket_lifetime_hint ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get0_ticket ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get_max_early_data ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_set_max_early_data ? 4_0_0 EXIST::FUNCTION: +SSL_copy_session_id ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get0_peer ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_set1_id_context ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_set1_id ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_is_resumable ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_new ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_dup ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get_id ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get0_id_context ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get_compress_id ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_print_fp ? 4_0_0 EXIST::FUNCTION:STDIO +SSL_SESSION_print ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_print_keylog ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_up_ref ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_free ? 4_0_0 EXIST::FUNCTION: +i2d_SSL_SESSION ? 4_0_0 EXIST::FUNCTION: +SSL_set_session ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_add_session ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_remove_session ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_generate_session_id ? 4_0_0 EXIST::FUNCTION: +SSL_set_generate_session_id ? 4_0_0 EXIST::FUNCTION: +SSL_has_matching_session_id ? 4_0_0 EXIST::FUNCTION: +d2i_SSL_SESSION ? 4_0_0 EXIST::FUNCTION: +d2i_SSL_SESSION_ex ? 4_0_0 EXIST::FUNCTION: +SSL_get0_peer_certificate ? 4_0_0 EXIST::FUNCTION: +SSL_get1_peer_certificate ? 4_0_0 EXIST::FUNCTION: +SSL_get_peer_cert_chain ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_verify_mode ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_verify_depth ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_verify_callback ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_verify ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_verify_depth ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_cert_verify_callback ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_cert_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_use_RSAPrivateKey ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SSL_CTX_use_RSAPrivateKey_ASN1 ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SSL_CTX_use_PrivateKey ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_use_PrivateKey_ASN1 ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_use_certificate ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_use_certificate_ASN1 ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_use_cert_and_key ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_default_passwd_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_default_passwd_cb_userdata ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_default_passwd_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_default_passwd_cb_userdata ? 4_0_0 EXIST::FUNCTION: +SSL_set_default_passwd_cb ? 4_0_0 EXIST::FUNCTION: +SSL_set_default_passwd_cb_userdata ? 4_0_0 EXIST::FUNCTION: +SSL_get_default_passwd_cb ? 4_0_0 EXIST::FUNCTION: +SSL_get_default_passwd_cb_userdata ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_check_private_key ? 4_0_0 EXIST::FUNCTION: +SSL_check_private_key ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_session_id_context ? 4_0_0 EXIST::FUNCTION: +SSL_new ? 4_0_0 EXIST::FUNCTION: +SSL_up_ref ? 4_0_0 EXIST::FUNCTION: +SSL_is_dtls ? 4_0_0 EXIST::FUNCTION: +SSL_is_tls ? 4_0_0 EXIST::FUNCTION: +SSL_is_quic ? 4_0_0 EXIST::FUNCTION: +SSL_set_session_id_context ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_purpose ? 4_0_0 EXIST::FUNCTION: +SSL_set_purpose ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_trust ? 4_0_0 EXIST::FUNCTION: +SSL_set_trust ? 4_0_0 EXIST::FUNCTION: +SSL_set1_host ? 4_0_0 EXIST::FUNCTION: +SSL_add1_host ? 4_0_0 EXIST::FUNCTION: +SSL_get0_peername ? 4_0_0 EXIST::FUNCTION: +SSL_set_hostflags ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_dane_enable ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_dane_mtype_set ? 4_0_0 EXIST::FUNCTION: +SSL_dane_enable ? 4_0_0 EXIST::FUNCTION: +SSL_dane_tlsa_add ? 4_0_0 EXIST::FUNCTION: +SSL_get0_dane_authority ? 4_0_0 EXIST::FUNCTION: +SSL_get0_dane_tlsa ? 4_0_0 EXIST::FUNCTION: +SSL_get0_dane ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_dane_set_flags ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_dane_clear_flags ? 4_0_0 EXIST::FUNCTION: +SSL_dane_set_flags ? 4_0_0 EXIST::FUNCTION: +SSL_dane_clear_flags ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set1_param ? 4_0_0 EXIST::FUNCTION: +SSL_set1_param ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get0_param ? 4_0_0 EXIST::FUNCTION: +SSL_get0_param ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_srp_username ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_CTX_set_srp_password ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_CTX_set_srp_strength ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_CTX_set_srp_client_pwd_callback ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_CTX_set_srp_verify_param_callback ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_CTX_set_srp_username_callback ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_CTX_set_srp_cb_arg ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_set_srp_server_param ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_set_srp_server_param_pw ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_get_srp_g ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_get_srp_N ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_get_srp_username ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_get_srp_userinfo ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,SRP +SSL_CTX_set_client_hello_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_new_pending_conn_cb ? 4_0_0 EXIST::FUNCTION: +SSL_client_hello_isv2 ? 4_0_0 EXIST::FUNCTION: +SSL_client_hello_get0_legacy_version ? 4_0_0 EXIST::FUNCTION: +SSL_client_hello_get0_random ? 4_0_0 EXIST::FUNCTION: +SSL_client_hello_get0_session_id ? 4_0_0 EXIST::FUNCTION: +SSL_client_hello_get0_ciphers ? 4_0_0 EXIST::FUNCTION: +SSL_client_hello_get0_compression_methods ? 4_0_0 EXIST::FUNCTION: +SSL_client_hello_get1_extensions_present ? 4_0_0 EXIST::FUNCTION: +SSL_client_hello_get_extension_order ? 4_0_0 EXIST::FUNCTION: +SSL_client_hello_get0_ext ? 4_0_0 EXIST::FUNCTION: +SSL_certs_clear ? 4_0_0 EXIST::FUNCTION: +SSL_free ? 4_0_0 EXIST::FUNCTION: +SSL_waiting_for_async ? 4_0_0 EXIST::FUNCTION: +SSL_get_all_async_fds ? 4_0_0 EXIST::FUNCTION: +SSL_get_changed_async_fds ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_async_callback ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_async_callback_arg ? 4_0_0 EXIST::FUNCTION: +SSL_set_async_callback ? 4_0_0 EXIST::FUNCTION: +SSL_set_async_callback_arg ? 4_0_0 EXIST::FUNCTION: +SSL_get_async_status ? 4_0_0 EXIST::FUNCTION: +SSL_accept ? 4_0_0 EXIST::FUNCTION: +SSL_stateless ? 4_0_0 EXIST::FUNCTION: +SSL_connect ? 4_0_0 EXIST::FUNCTION: +SSL_read ? 4_0_0 EXIST::FUNCTION: +SSL_read_ex ? 4_0_0 EXIST::FUNCTION: +SSL_read_early_data ? 4_0_0 EXIST::FUNCTION: +SSL_peek ? 4_0_0 EXIST::FUNCTION: +SSL_peek_ex ? 4_0_0 EXIST::FUNCTION: +SSL_sendfile ? 4_0_0 EXIST::FUNCTION: +SSL_write ? 4_0_0 EXIST::FUNCTION: +SSL_write_ex ? 4_0_0 EXIST::FUNCTION: +SSL_write_early_data ? 4_0_0 EXIST::FUNCTION: +SSL_ctrl ? 4_0_0 EXIST::FUNCTION: +SSL_callback_ctrl ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_ctrl ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_callback_ctrl ? 4_0_0 EXIST::FUNCTION: +SSL_write_ex2 ? 4_0_0 EXIST::FUNCTION: +SSL_get_early_data_status ? 4_0_0 EXIST::FUNCTION: +SSL_get_error ? 4_0_0 EXIST::FUNCTION: +SSL_get_version ? 4_0_0 EXIST::FUNCTION: +SSL_get_handshake_rtt ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_ssl_version ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0 +SSLv3_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,SSL3_METHOD +SSLv3_server_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,SSL3_METHOD +SSLv3_client_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,SSL3_METHOD +TLS_method ? 4_0_0 EXIST::FUNCTION: +TLS_server_method ? 4_0_0 EXIST::FUNCTION: +TLS_client_method ? 4_0_0 EXIST::FUNCTION: +TLSv1_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,TLS1_METHOD +TLSv1_server_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,TLS1_METHOD +TLSv1_client_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,TLS1_METHOD +TLSv1_1_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,TLS1_1_METHOD +TLSv1_1_server_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,TLS1_1_METHOD +TLSv1_1_client_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,TLS1_1_METHOD +TLSv1_2_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,TLS1_2_METHOD +TLSv1_2_server_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,TLS1_2_METHOD +TLSv1_2_client_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,TLS1_2_METHOD +DTLSv1_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,DTLS1_METHOD +DTLSv1_server_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,DTLS1_METHOD +DTLSv1_client_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,DTLS1_METHOD +DTLSv1_2_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,DTLS1_2_METHOD +DTLSv1_2_server_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,DTLS1_2_METHOD +DTLSv1_2_client_method ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_1_1_0,DTLS1_2_METHOD +DTLS_method ? 4_0_0 EXIST::FUNCTION: +DTLS_server_method ? 4_0_0 EXIST::FUNCTION: +DTLS_client_method ? 4_0_0 EXIST::FUNCTION: +DTLS_get_data_mtu ? 4_0_0 EXIST::FUNCTION: +SSL_get_ciphers ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_ciphers ? 4_0_0 EXIST::FUNCTION: +SSL_get_client_ciphers ? 4_0_0 EXIST::FUNCTION: +SSL_get1_supported_ciphers ? 4_0_0 EXIST::FUNCTION: +SSL_do_handshake ? 4_0_0 EXIST::FUNCTION: +SSL_key_update ? 4_0_0 EXIST::FUNCTION: +SSL_get_key_update_type ? 4_0_0 EXIST::FUNCTION: +SSL_renegotiate ? 4_0_0 EXIST::FUNCTION: +SSL_renegotiate_abbreviated ? 4_0_0 EXIST::FUNCTION: +SSL_renegotiate_pending ? 4_0_0 EXIST::FUNCTION: +SSL_new_session_ticket ? 4_0_0 EXIST::FUNCTION: +SSL_shutdown ? 4_0_0 EXIST::FUNCTION: +SSL_verify_client_post_handshake ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_post_handshake_auth ? 4_0_0 EXIST::FUNCTION: +SSL_set_post_handshake_auth ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_ssl_method ? 4_0_0 EXIST::FUNCTION: +SSL_get_ssl_method ? 4_0_0 EXIST::FUNCTION: +SSL_set_ssl_method ? 4_0_0 EXIST::FUNCTION: +SSL_alert_type_string_long ? 4_0_0 EXIST::FUNCTION: +SSL_alert_type_string ? 4_0_0 EXIST::FUNCTION: +SSL_alert_desc_string_long ? 4_0_0 EXIST::FUNCTION: +SSL_alert_desc_string ? 4_0_0 EXIST::FUNCTION: +SSL_set0_CA_list ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set0_CA_list ? 4_0_0 EXIST::FUNCTION: +SSL_get0_CA_list ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get0_CA_list ? 4_0_0 EXIST::FUNCTION: +SSL_add1_to_CA_list ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_add1_to_CA_list ? 4_0_0 EXIST::FUNCTION: +SSL_get0_peer_CA_list ? 4_0_0 EXIST::FUNCTION: +SSL_set_client_CA_list ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_client_CA_list ? 4_0_0 EXIST::FUNCTION: +SSL_get_client_CA_list ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_client_CA_list ? 4_0_0 EXIST::FUNCTION: +SSL_add_client_CA ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_add_client_CA ? 4_0_0 EXIST::FUNCTION: +SSL_set_connect_state ? 4_0_0 EXIST::FUNCTION: +SSL_set_accept_state ? 4_0_0 EXIST::FUNCTION: +SSL_get_default_timeout ? 4_0_0 EXIST::FUNCTION: +SSL_CIPHER_description ? 4_0_0 EXIST::FUNCTION: +SSL_dup_CA_list ? 4_0_0 EXIST::FUNCTION: +SSL_dup ? 4_0_0 EXIST::FUNCTION: +SSL_get_certificate ? 4_0_0 EXIST::FUNCTION: +SSL_get_privatekey ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get0_certificate ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get0_privatekey ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_quiet_shutdown ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_quiet_shutdown ? 4_0_0 EXIST::FUNCTION: +SSL_set_quiet_shutdown ? 4_0_0 EXIST::FUNCTION: +SSL_get_quiet_shutdown ? 4_0_0 EXIST::FUNCTION: +SSL_set_shutdown ? 4_0_0 EXIST::FUNCTION: +SSL_get_shutdown ? 4_0_0 EXIST::FUNCTION: +SSL_version ? 4_0_0 EXIST::FUNCTION: +SSL_client_version ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_default_verify_paths ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_default_verify_dir ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_default_verify_file ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_default_verify_store ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_load_verify_file ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_load_verify_dir ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_load_verify_store ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_load_verify_locations ? 4_0_0 EXIST::FUNCTION: +SSL_get_session ? 4_0_0 EXIST::FUNCTION: +SSL_get1_session ? 4_0_0 EXIST::FUNCTION: +SSL_get_SSL_CTX ? 4_0_0 EXIST::FUNCTION: +SSL_set_SSL_CTX ? 4_0_0 EXIST::FUNCTION: +SSL_set_info_callback ? 4_0_0 EXIST::FUNCTION: +SSL_get_info_callback ? 4_0_0 EXIST::FUNCTION: +SSL_get_state ? 4_0_0 EXIST::FUNCTION: +SSL_set_verify_result ? 4_0_0 EXIST::FUNCTION: +SSL_get_verify_result ? 4_0_0 EXIST::FUNCTION: +SSL_get0_verified_chain ? 4_0_0 EXIST::FUNCTION: +SSL_get_client_random ? 4_0_0 EXIST::FUNCTION: +SSL_get_server_random ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get_master_key ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_set1_master_key ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get_max_fragment_length ? 4_0_0 EXIST::FUNCTION: +SSL_set_ex_data ? 4_0_0 EXIST::FUNCTION: +SSL_get_ex_data ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_set_ex_data ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get_ex_data ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_ex_data ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_ex_data ? 4_0_0 EXIST::FUNCTION: +SSL_get_ex_data_X509_STORE_CTX_idx ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_default_read_buffer_len ? 4_0_0 EXIST::FUNCTION: +SSL_set_default_read_buffer_len ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_tmp_dh_callback ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +SSL_set_tmp_dh_callback ? 4_0_0 EXIST::FUNCTION:DEPRECATEDIN_3_0,DH +SSL_get_current_compression ? 4_0_0 EXIST::FUNCTION: +SSL_get_current_expansion ? 4_0_0 EXIST::FUNCTION: +SSL_COMP_get_name ? 4_0_0 EXIST::FUNCTION: +SSL_COMP_get0_name ? 4_0_0 EXIST::FUNCTION: +SSL_COMP_get_id ? 4_0_0 EXIST::FUNCTION: +SSL_COMP_get_compression_methods ? 4_0_0 EXIST::FUNCTION: +SSL_COMP_set0_compression_methods ? 4_0_0 EXIST::FUNCTION: +SSL_COMP_add_compression_method ? 4_0_0 EXIST::FUNCTION: +SSL_CIPHER_find ? 4_0_0 EXIST::FUNCTION: +SSL_CIPHER_get_cipher_nid ? 4_0_0 EXIST::FUNCTION: +SSL_CIPHER_get_digest_nid ? 4_0_0 EXIST::FUNCTION: +SSL_bytes_to_cipher_list ? 4_0_0 EXIST::FUNCTION: +SSL_set_session_ticket_ext ? 4_0_0 EXIST::FUNCTION: +SSL_set_session_ticket_ext_cb ? 4_0_0 EXIST::FUNCTION: +SSL_set_session_secret_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_not_resumable_session_callback ? 4_0_0 EXIST::FUNCTION: +SSL_set_not_resumable_session_callback ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_record_padding_callback ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_record_padding_callback_arg ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_record_padding_callback_arg ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_block_padding ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_block_padding_ex ? 4_0_0 EXIST::FUNCTION: +SSL_set_record_padding_callback ? 4_0_0 EXIST::FUNCTION: +SSL_set_record_padding_callback_arg ? 4_0_0 EXIST::FUNCTION: +SSL_get_record_padding_callback_arg ? 4_0_0 EXIST::FUNCTION: +SSL_set_block_padding ? 4_0_0 EXIST::FUNCTION: +SSL_set_block_padding_ex ? 4_0_0 EXIST::FUNCTION: +SSL_set_num_tickets ? 4_0_0 EXIST::FUNCTION: +SSL_get_num_tickets ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_num_tickets ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_num_tickets ? 4_0_0 EXIST::FUNCTION: +SSL_handle_events ? 4_0_0 EXIST::FUNCTION: +SSL_get_event_timeout ? 4_0_0 EXIST::FUNCTION: +SSL_get_peer_addr ? 4_0_0 EXIST::FUNCTION: +SSL_get_rpoll_descriptor ? 4_0_0 EXIST::FUNCTION: +SSL_get_wpoll_descriptor ? 4_0_0 EXIST::FUNCTION: +SSL_net_read_desired ? 4_0_0 EXIST::FUNCTION: +SSL_net_write_desired ? 4_0_0 EXIST::FUNCTION: +SSL_set_blocking_mode ? 4_0_0 EXIST::FUNCTION: +SSL_get_blocking_mode ? 4_0_0 EXIST::FUNCTION: +SSL_set1_initial_peer_addr ? 4_0_0 EXIST::FUNCTION: +SSL_get0_connection ? 4_0_0 EXIST::FUNCTION: +SSL_is_connection ? 4_0_0 EXIST::FUNCTION: +SSL_is_listener ? 4_0_0 EXIST::FUNCTION: +SSL_get0_listener ? 4_0_0 EXIST::FUNCTION: +SSL_new_listener ? 4_0_0 EXIST::FUNCTION: +SSL_new_listener_from ? 4_0_0 EXIST::FUNCTION: +SSL_new_from_listener ? 4_0_0 EXIST::FUNCTION: +SSL_accept_connection ? 4_0_0 EXIST::FUNCTION: +SSL_get_accept_connection_queue_len ? 4_0_0 EXIST::FUNCTION: +SSL_listen ? 4_0_0 EXIST::FUNCTION: +SSL_is_domain ? 4_0_0 EXIST::FUNCTION: +SSL_get0_domain ? 4_0_0 EXIST::FUNCTION: +SSL_new_domain ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_domain_flags ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_domain_flags ? 4_0_0 EXIST::FUNCTION: +SSL_get_domain_flags ? 4_0_0 EXIST::FUNCTION: +SSL_get_stream_type ? 4_0_0 EXIST::FUNCTION: +SSL_get_stream_id ? 4_0_0 EXIST::FUNCTION: +SSL_is_stream_local ? 4_0_0 EXIST::FUNCTION: +SSL_set_default_stream_mode ? 4_0_0 EXIST::FUNCTION: +SSL_new_stream ? 4_0_0 EXIST::FUNCTION: +SSL_set_incoming_stream_policy ? 4_0_0 EXIST::FUNCTION: +SSL_accept_stream ? 4_0_0 EXIST::FUNCTION: +SSL_get_accept_stream_queue_len ? 4_0_0 EXIST::FUNCTION: +SSL_inject_net_dgram ? 4_0_0 EXIST::FUNCTION:QUIC +SSL_shutdown_ex ? 4_0_0 EXIST::FUNCTION: +SSL_stream_conclude ? 4_0_0 EXIST::FUNCTION: +SSL_stream_reset ? 4_0_0 EXIST::FUNCTION: +SSL_get_stream_read_state ? 4_0_0 EXIST::FUNCTION: +SSL_get_stream_write_state ? 4_0_0 EXIST::FUNCTION: +SSL_get_stream_read_error_code ? 4_0_0 EXIST::FUNCTION: +SSL_get_stream_write_error_code ? 4_0_0 EXIST::FUNCTION: +SSL_get_conn_close_info ? 4_0_0 EXIST::FUNCTION: +SSL_get_value_uint ? 4_0_0 EXIST::FUNCTION: +SSL_set_value_uint ? 4_0_0 EXIST::FUNCTION: +SSL_poll ? 4_0_0 EXIST::FUNCTION: +SSL_session_reused ? 4_0_0 EXIST::FUNCTION: +SSL_is_server ? 4_0_0 EXIST::FUNCTION: +SSL_CONF_CTX_new ? 4_0_0 EXIST::FUNCTION: +SSL_CONF_CTX_finish ? 4_0_0 EXIST::FUNCTION: +SSL_CONF_CTX_free ? 4_0_0 EXIST::FUNCTION: +SSL_CONF_CTX_set_flags ? 4_0_0 EXIST::FUNCTION: +SSL_CONF_CTX_clear_flags ? 4_0_0 EXIST::FUNCTION: +SSL_CONF_CTX_set1_prefix ? 4_0_0 EXIST::FUNCTION: +SSL_CONF_CTX_set_ssl ? 4_0_0 EXIST::FUNCTION: +SSL_CONF_CTX_set_ssl_ctx ? 4_0_0 EXIST::FUNCTION: +SSL_CONF_cmd ? 4_0_0 EXIST::FUNCTION: +SSL_CONF_cmd_argv ? 4_0_0 EXIST::FUNCTION: +SSL_CONF_cmd_value_type ? 4_0_0 EXIST::FUNCTION: +SSL_add_ssl_module ? 4_0_0 EXIST::FUNCTION: +SSL_config ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_config ? 4_0_0 EXIST::FUNCTION: +SSL_trace ? 4_0_0 EXIST::FUNCTION:SSL_TRACE +DTLSv1_listen ? 4_0_0 EXIST::FUNCTION:SOCK +SSL_set_ct_validation_callback ? 4_0_0 EXIST::FUNCTION:CT +SSL_CTX_set_ct_validation_callback ? 4_0_0 EXIST::FUNCTION:CT +SSL_enable_ct ? 4_0_0 EXIST::FUNCTION:CT +SSL_CTX_enable_ct ? 4_0_0 EXIST::FUNCTION:CT +SSL_ct_is_enabled ? 4_0_0 EXIST::FUNCTION:CT +SSL_CTX_ct_is_enabled ? 4_0_0 EXIST::FUNCTION:CT +SSL_get0_peer_scts ? 4_0_0 EXIST::FUNCTION:CT +SSL_CTX_set_default_ctlog_list_file ? 4_0_0 EXIST::FUNCTION:CT +SSL_CTX_set_ctlog_list_file ? 4_0_0 EXIST::FUNCTION:CT +SSL_CTX_set0_ctlog_store ? 4_0_0 EXIST::FUNCTION:CT +SSL_CTX_get0_ctlog_store ? 4_0_0 EXIST::FUNCTION:CT +SSL_set_security_level ? 4_0_0 EXIST::FUNCTION: +SSL_get_security_level ? 4_0_0 EXIST::FUNCTION: +SSL_set_security_callback ? 4_0_0 EXIST::FUNCTION: +SSL_get_security_callback ? 4_0_0 EXIST::FUNCTION: +SSL_set0_security_ex_data ? 4_0_0 EXIST::FUNCTION: +SSL_get0_security_ex_data ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_security_level ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_security_level ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_security_callback ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get_security_callback ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set0_security_ex_data ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get0_security_ex_data ? 4_0_0 EXIST::FUNCTION: +OPENSSL_init_ssl ? 4_0_0 EXIST::FUNCTION: +SSL_test_functions ? 4_0_0 EXIST::FUNCTION:UNIT_TEST +SSL_free_buffers ? 4_0_0 EXIST::FUNCTION: +SSL_alloc_buffers ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_session_ticket_cb ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_set1_ticket_appdata ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get0_ticket_appdata ? 4_0_0 EXIST::FUNCTION: +DTLS_set_timer_cb ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set_allow_early_data_cb ? 4_0_0 EXIST::FUNCTION: +SSL_set_allow_early_data_cb ? 4_0_0 EXIST::FUNCTION: +OSSL_default_cipher_list ? 4_0_0 EXIST::FUNCTION: +OSSL_default_ciphersuites ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_compress_certs ? 4_0_0 EXIST::FUNCTION: +SSL_compress_certs ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set1_cert_comp_preference ? 4_0_0 EXIST::FUNCTION: +SSL_set1_cert_comp_preference ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set1_compressed_cert ? 4_0_0 EXIST::FUNCTION: +SSL_set1_compressed_cert ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get1_compressed_cert ? 4_0_0 EXIST::FUNCTION: +SSL_get1_compressed_cert ? 4_0_0 EXIST::FUNCTION: +SSL_add_expected_rpk ? 4_0_0 EXIST::FUNCTION: +SSL_get0_peer_rpk ? 4_0_0 EXIST::FUNCTION: +SSL_SESSION_get0_peer_rpk ? 4_0_0 EXIST::FUNCTION: +SSL_get_negotiated_client_cert_type ? 4_0_0 EXIST::FUNCTION: +SSL_get_negotiated_server_cert_type ? 4_0_0 EXIST::FUNCTION: +SSL_set1_client_cert_type ? 4_0_0 EXIST::FUNCTION: +SSL_set1_server_cert_type ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set1_client_cert_type ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_set1_server_cert_type ? 4_0_0 EXIST::FUNCTION: +SSL_get0_client_cert_type ? 4_0_0 EXIST::FUNCTION: +SSL_get0_server_cert_type ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get0_client_cert_type ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_get0_server_cert_type ? 4_0_0 EXIST::FUNCTION: +SSL_set_quic_tls_cbs ? 4_0_0 EXIST::FUNCTION: +SSL_set_quic_tls_transport_params ? 4_0_0 EXIST::FUNCTION: +SSL_set_quic_tls_early_data_enabled ? 4_0_0 EXIST::FUNCTION: +SSL_CTX_is_quic ? 4_0_0 EXIST::FUNCTION: +OSSL_QUIC_method ? 4_0_0 EXIST::FUNCTION:QUIC +SSL_listen_ex ? 4_0_0 EXIST::FUNCTION: diff --git a/util/missingcrypto.txt b/util/missingcrypto.txt index 5e8126d12c..873e7a7745 100644 --- a/util/missingcrypto.txt +++ b/util/missingcrypto.txt @@ -20,7 +20,16 @@ ASIdOrRange_it(3) ASIdentifierChoice_it(3) ASIdentifiers_it(3) ASN1_ANY_it(3) +ASN1_BIT_STRING_check(3) +ASN1_BIT_STRING_free(3) +ASN1_BIT_STRING_get_bit(3) ASN1_BIT_STRING_it(3) +ASN1_BIT_STRING_name_print(3) +ASN1_BIT_STRING_new(3) +ASN1_BIT_STRING_num_asc(3) +ASN1_BIT_STRING_set(3) +ASN1_BIT_STRING_set_asc(3) +ASN1_BIT_STRING_set_bit(3) ASN1_BMPSTRING_free(3) ASN1_BMPSTRING_it(3) ASN1_BMPSTRING_new(3) @@ -161,6 +170,7 @@ BIO_asn1_get_prefix(3) BIO_asn1_get_suffix(3) BIO_asn1_set_prefix(3) BIO_asn1_set_suffix(3) +BIO_clear_flags(3) BIO_copy_next_retry(3) BIO_dgram_is_sctp(3) BIO_dgram_non_fatal_error(3) @@ -177,6 +187,7 @@ BIO_dup_chain(3) BIO_f_asn1(3) BIO_f_linebuffer(3) BIO_f_nbio_test(3) +BIO_f_reliable(3) BIO_fd_non_fatal_error(3) BIO_fd_should_retry(3) BIO_get_accept_socket(3) @@ -189,10 +200,15 @@ BIO_method_name(3) BIO_new_NDEF(3) BIO_new_PKCS7(3) BIO_new_dgram_sctp(3) +BIO_nread(3) +BIO_nread0(3) BIO_number_read(3) BIO_number_written(3) +BIO_nwrite(3) +BIO_nwrite0(3) BIO_s_datagram_sctp(3) BIO_s_log(3) +BIO_set_flags(3) BIO_set_tcp_ndelay(3) BIO_sock_error(3) BIO_sock_info(3) @@ -201,6 +217,7 @@ BIO_sock_non_fatal_error(3) BIO_sock_should_retry(3) BIO_socket_ioctl(3) BIO_socket_nbio(3) +BIO_test_flags(3) BN_GF2m_add(3) BN_GF2m_arr2poly(3) BN_GF2m_mod(3) @@ -363,6 +380,7 @@ CRYPTO_gcm128_tag(3) CRYPTO_mem_debug_free(3) CRYPTO_mem_debug_malloc(3) CRYPTO_mem_debug_realloc(3) +CRYPTO_memdup(3) CRYPTO_nistcts128_decrypt(3) CRYPTO_nistcts128_decrypt_block(3) CRYPTO_nistcts128_encrypt(3) @@ -378,6 +396,7 @@ CRYPTO_ocb128_new(3) CRYPTO_ocb128_setiv(3) CRYPTO_ocb128_tag(3) CRYPTO_ofb128_encrypt(3) +CRYPTO_secure_actual_size(3) CRYPTO_xts128_encrypt(3) Camellia_cbc_encrypt(3) Camellia_cfb128_encrypt(3) @@ -398,6 +417,7 @@ DES_encrypt2(3) DES_encrypt3(3) DES_options(3) DH_KDF_X9_42(3) +DH_check_pub_key(3) DH_up_ref(3) DHparams_dup(3) DHparams_it(3) @@ -449,6 +469,8 @@ EC_KEY_new_method(3) EC_KEY_print(3) EC_KEY_print_fp(3) EC_KEY_set_default_method(3) +EC_curve_nid2nist(3) +EC_curve_nist2nid(3) EDIPARTYNAME_it(3) ENGINE_get_EC(3) ENGINE_get_default_EC(3) @@ -480,6 +502,7 @@ ENGINE_setup_bsd_cryptodev(3) ENGINE_unregister_EC(3) ENGINE_unregister_pkey_asn1_meths(3) ENGINE_unregister_pkey_meths(3) +ERR_get_state(3) ERR_load_ASN1_strings(3) ERR_load_ASYNC_strings(3) ERR_load_BIO_strings(3) @@ -570,6 +593,8 @@ LONG_it(3) MD2_options(3) MD4_Transform(3) MD5_Transform(3) +NAME_CONSTRAINTS_check(3) +NAME_CONSTRAINTS_check_CN(3) NAME_CONSTRAINTS_it(3) NAMING_AUTHORITY_it(3) NCONF_WIN32(3) @@ -763,6 +788,7 @@ PKCS7_ctrl(3) PKCS7_dataDecode(3) PKCS7_dataFinal(3) PKCS7_dataInit(3) +PKCS7_dataVerify(3) PKCS7_digest_from_attributes(3) PKCS7_final(3) PKCS7_get_attribute(3) @@ -1016,6 +1042,8 @@ X509V3_EXT_get(3) X509V3_EXT_get_nid(3) X509V3_EXT_nconf(3) X509V3_EXT_nconf_nid(3) +X509V3_EXT_print(3) +X509V3_EXT_print_fp(3) X509V3_EXT_val_prn(3) X509V3_NAME_from_section(3) X509V3_add_standard_extensions(3) @@ -1099,6 +1127,7 @@ X509_STORE_CTX_get_explicit_policy(3) X509_STORE_CTX_set0_dane(3) X509_STORE_CTX_set_depth(3) X509_STORE_CTX_set_flags(3) +X509_STORE_CTX_set_time(3) X509_STORE_get_verify(3) X509_TRUST_add(3) X509_TRUST_cleanup(3) @@ -1130,6 +1159,7 @@ X509_alias_set1(3) X509_aux_print(3) X509_certificate_type(3) X509_chain_check_suiteb(3) +X509_check_akid(3) X509_check_trust(3) X509_email_free(3) X509_find_by_issuer_and_serial(3) diff --git a/util/missingcrypto111.txt b/util/missingcrypto111.txt new file mode 100644 index 0000000000..f3402ada7e --- /dev/null +++ b/util/missingcrypto111.txt @@ -0,0 +1,1742 @@ +# A list of libcrypto functions that are known to be missing documentation as +# used by the find-doc-nits -v -o option. The list is as of commit 1708e3e85b +# (the release of 1.1.1). +ACCESS_DESCRIPTION_it(3) +ACCESS_DESCRIPTION_it(3) +ADMISSIONS_it(3) +ADMISSIONS_it(3) +ADMISSION_SYNTAX_it(3) +ADMISSION_SYNTAX_it(3) +AES_bi_ige_encrypt(3) +AES_cbc_encrypt(3) +AES_cfb128_encrypt(3) +AES_cfb1_encrypt(3) +AES_cfb8_encrypt(3) +AES_decrypt(3) +AES_ecb_encrypt(3) +AES_encrypt(3) +AES_ige_encrypt(3) +AES_ofb128_encrypt(3) +AES_options(3) +AES_set_decrypt_key(3) +AES_set_encrypt_key(3) +AES_unwrap_key(3) +AES_wrap_key(3) +ASIdOrRange_it(3) +ASIdOrRange_it(3) +ASIdentifierChoice_it(3) +ASIdentifierChoice_it(3) +ASIdentifiers_it(3) +ASIdentifiers_it(3) +ASN1_ANY_it(3) +ASN1_BIT_STRING_check(3) +ASN1_BIT_STRING_free(3) +ASN1_BIT_STRING_get_bit(3) +ASN1_BIT_STRING_it(3) +ASN1_BIT_STRING_name_print(3) +ASN1_BIT_STRING_new(3) +ASN1_BIT_STRING_num_asc(3) +ASN1_BIT_STRING_set(3) +ASN1_BIT_STRING_set_asc(3) +ASN1_BIT_STRING_set_bit(3) +ASN1_BMPSTRING_free(3) +ASN1_BMPSTRING_it(3) +ASN1_BMPSTRING_new(3) +ASN1_BOOLEAN_it(3) +ASN1_ENUMERATED_free(3) +ASN1_ENUMERATED_it(3) +ASN1_ENUMERATED_new(3) +ASN1_FBOOLEAN_it(3) +ASN1_GENERALIZEDTIME_free(3) +ASN1_GENERALIZEDTIME_it(3) +ASN1_GENERALIZEDTIME_new(3) +ASN1_GENERALSTRING_free(3) +ASN1_GENERALSTRING_it(3) +ASN1_GENERALSTRING_new(3) +ASN1_IA5STRING_free(3) +ASN1_IA5STRING_it(3) +ASN1_IA5STRING_new(3) +ASN1_INTEGER_cmp(3) +ASN1_INTEGER_dup(3) +ASN1_INTEGER_free(3) +ASN1_INTEGER_it(3) +ASN1_INTEGER_new(3) +ASN1_NULL_free(3) +ASN1_NULL_it(3) +ASN1_NULL_new(3) +ASN1_OBJECT_create(3) +ASN1_OBJECT_it(3) +ASN1_OCTET_STRING_NDEF_it(3) +ASN1_OCTET_STRING_cmp(3) +ASN1_OCTET_STRING_dup(3) +ASN1_OCTET_STRING_free(3) +ASN1_OCTET_STRING_it(3) +ASN1_OCTET_STRING_new(3) +ASN1_OCTET_STRING_set(3) +ASN1_PCTX_free(3) +ASN1_PCTX_get_cert_flags(3) +ASN1_PCTX_get_flags(3) +ASN1_PCTX_get_nm_flags(3) +ASN1_PCTX_get_oid_flags(3) +ASN1_PCTX_get_str_flags(3) +ASN1_PCTX_new(3) +ASN1_PCTX_set_cert_flags(3) +ASN1_PCTX_set_flags(3) +ASN1_PCTX_set_nm_flags(3) +ASN1_PCTX_set_oid_flags(3) +ASN1_PCTX_set_str_flags(3) +ASN1_PRINTABLESTRING_free(3) +ASN1_PRINTABLESTRING_it(3) +ASN1_PRINTABLESTRING_new(3) +ASN1_PRINTABLE_free(3) +ASN1_PRINTABLE_it(3) +ASN1_PRINTABLE_new(3) +ASN1_PRINTABLE_type(3) +ASN1_SCTX_free(3) +ASN1_SCTX_get_app_data(3) +ASN1_SCTX_get_flags(3) +ASN1_SCTX_get_item(3) +ASN1_SCTX_get_template(3) +ASN1_SCTX_new(3) +ASN1_SCTX_set_app_data(3) +ASN1_SEQUENCE_ANY_it(3) +ASN1_SEQUENCE_it(3) +ASN1_SET_ANY_it(3) +ASN1_STRING_clear_free(3) +ASN1_STRING_copy(3) +ASN1_STRING_get_default_mask(3) +ASN1_STRING_length_set(3) +ASN1_STRING_set0(3) +ASN1_STRING_set_by_NID(3) +ASN1_STRING_set_default_mask(3) +ASN1_STRING_set_default_mask_asc(3) +ASN1_T61STRING_free(3) +ASN1_T61STRING_it(3) +ASN1_T61STRING_new(3) +ASN1_TBOOLEAN_it(3) +ASN1_TIME_free(3) +ASN1_TIME_it(3) +ASN1_TIME_new(3) +ASN1_TYPE_free(3) +ASN1_TYPE_get_int_octetstring(3) +ASN1_TYPE_get_octetstring(3) +ASN1_TYPE_new(3) +ASN1_TYPE_set_int_octetstring(3) +ASN1_TYPE_set_octetstring(3) +ASN1_UNIVERSALSTRING_free(3) +ASN1_UNIVERSALSTRING_it(3) +ASN1_UNIVERSALSTRING_new(3) +ASN1_UNIVERSALSTRING_to_string(3) +ASN1_UTCTIME_free(3) +ASN1_UTCTIME_it(3) +ASN1_UTCTIME_new(3) +ASN1_UTF8STRING_free(3) +ASN1_UTF8STRING_it(3) +ASN1_UTF8STRING_new(3) +ASN1_VISIBLESTRING_free(3) +ASN1_VISIBLESTRING_it(3) +ASN1_VISIBLESTRING_new(3) +ASN1_add_stable_module(3) +ASN1_bn_print(3) +ASN1_buf_print(3) +ASN1_check_infinite_end(3) +ASN1_const_check_infinite_end(3) +ASN1_d2i_bio(3) +ASN1_d2i_fp(3) +ASN1_digest(3) +ASN1_dup(3) +ASN1_get_object(3) +ASN1_i2d_bio(3) +ASN1_i2d_fp(3) +ASN1_item_d2i(3) +ASN1_item_d2i_bio(3) +ASN1_item_d2i_fp(3) +ASN1_item_digest(3) +ASN1_item_dup(3) +ASN1_item_ex_d2i(3) +ASN1_item_ex_free(3) +ASN1_item_ex_i2d(3) +ASN1_item_ex_new(3) +ASN1_item_free(3) +ASN1_item_i2d(3) +ASN1_item_i2d_bio(3) +ASN1_item_i2d_fp(3) +ASN1_item_ndef_i2d(3) +ASN1_item_new(3) +ASN1_item_pack(3) +ASN1_item_print(3) +ASN1_item_sign(3) +ASN1_item_sign_ctx(3) +ASN1_item_unpack(3) +ASN1_item_verify(3) +ASN1_mbstring_copy(3) +ASN1_mbstring_ncopy(3) +ASN1_object_size(3) +ASN1_parse(3) +ASN1_parse_dump(3) +ASN1_put_eoc(3) +ASN1_put_object(3) +ASN1_sign(3) +ASN1_str2mask(3) +ASN1_tag2bit(3) +ASN1_verify(3) +ASRange_it(3) +AUTHORITY_INFO_ACCESS_it(3) +AUTHORITY_INFO_ACCESS_it(3) +AUTHORITY_KEYID_it(3) +AUTHORITY_KEYID_it(3) +BASIC_CONSTRAINTS_it(3) +BASIC_CONSTRAINTS_it(3) +BIGNUM_it(3) +BIGNUM_it(3) +BIO_accept(3) +BIO_asn1_get_prefix(3) +BIO_asn1_get_suffix(3) +BIO_asn1_set_prefix(3) +BIO_asn1_set_suffix(3) +BIO_clear_flags(3) +BIO_copy_next_retry(3) +BIO_dgram_is_sctp(3) +BIO_dgram_non_fatal_error(3) +BIO_dgram_sctp_msg_waiting(3) +BIO_dgram_sctp_notification_cb(3) +BIO_dgram_sctp_wait_for_dry(3) +BIO_dump(3) +BIO_dump_cb(3) +BIO_dump_fp(3) +BIO_dump_indent(3) +BIO_dump_indent_cb(3) +BIO_dump_indent_fp(3) +BIO_dup_chain(3) +BIO_f_asn1(3) +BIO_f_linebuffer(3) +BIO_f_nbio_test(3) +BIO_f_reliable(3) +BIO_f_zlib(3) +BIO_fd_non_fatal_error(3) +BIO_fd_should_retry(3) +BIO_get_accept_socket(3) +BIO_get_host_ip(3) +BIO_get_port(3) +BIO_gethostbyname(3) +BIO_hex_string(3) +BIO_indent(3) +BIO_method_name(3) +BIO_new_NDEF(3) +BIO_new_PKCS7(3) +BIO_new_dgram(3) +BIO_new_dgram_sctp(3) +BIO_nread(3) +BIO_nread0(3) +BIO_number_read(3) +BIO_number_written(3) +BIO_nwrite(3) +BIO_nwrite0(3) +BIO_s_datagram(3) +BIO_s_datagram_sctp(3) +BIO_s_log(3) +BIO_set_flags(3) +BIO_set_tcp_ndelay(3) +BIO_sock_error(3) +BIO_sock_info(3) +BIO_sock_init(3) +BIO_sock_non_fatal_error(3) +BIO_sock_should_retry(3) +BIO_socket_ioctl(3) +BIO_socket_nbio(3) +BIO_test_flags(3) +BN_GF2m_add(3) +BN_GF2m_arr2poly(3) +BN_GF2m_mod(3) +BN_GF2m_mod_arr(3) +BN_GF2m_mod_div(3) +BN_GF2m_mod_div_arr(3) +BN_GF2m_mod_exp(3) +BN_GF2m_mod_exp_arr(3) +BN_GF2m_mod_inv(3) +BN_GF2m_mod_inv_arr(3) +BN_GF2m_mod_mul(3) +BN_GF2m_mod_mul_arr(3) +BN_GF2m_mod_solve_quad(3) +BN_GF2m_mod_solve_quad_arr(3) +BN_GF2m_mod_sqr(3) +BN_GF2m_mod_sqr_arr(3) +BN_GF2m_mod_sqrt(3) +BN_GF2m_mod_sqrt_arr(3) +BN_GF2m_poly2arr(3) +BN_MONT_CTX_set_locked(3) +BN_X931_derive_prime_ex(3) +BN_X931_generate_Xpq(3) +BN_X931_generate_prime_ex(3) +BN_abs_is_word(3) +BN_asc2bn(3) +BN_bntest_rand(3) +BN_consttime_swap(3) +BN_generate_dsa_nonce(3) +BN_get_flags(3) +BN_get_params(3) +BN_is_negative(3) +BN_kronecker(3) +BN_mod_add_quick(3) +BN_mod_exp2_mont(3) +BN_mod_exp_mont(3) +BN_mod_exp_mont_consttime(3) +BN_mod_exp_mont_word(3) +BN_mod_exp_recp(3) +BN_mod_exp_simple(3) +BN_mod_lshift(3) +BN_mod_lshift1(3) +BN_mod_lshift1_quick(3) +BN_mod_lshift_quick(3) +BN_mod_sqrt(3) +BN_mod_sub_quick(3) +BN_nist_mod_192(3) +BN_nist_mod_224(3) +BN_nist_mod_256(3) +BN_nist_mod_384(3) +BN_nist_mod_521(3) +BN_nist_mod_func(3) +BN_options(3) +BN_reciprocal(3) +BN_set_flags(3) +BN_set_negative(3) +BN_set_params(3) +BN_uadd(3) +BN_usub(3) +BN_zero_ex(3) +CAST_cbc_encrypt(3) +CAST_cfb64_encrypt(3) +CAST_decrypt(3) +CAST_ecb_encrypt(3) +CAST_encrypt(3) +CAST_ofb64_encrypt(3) +CAST_set_key(3) +CBIGNUM_it(3) +CBIGNUM_it(3) +CERTIFICATEPOLICIES_it(3) +CERTIFICATEPOLICIES_it(3) +CMAC_CTX_cleanup(3) +CMAC_CTX_copy(3) +CMAC_CTX_free(3) +CMAC_CTX_get0_cipher_ctx(3) +CMAC_CTX_new(3) +CMAC_Final(3) +CMAC_Init(3) +CMAC_Update(3) +CMAC_resume(3) +CMS_ContentInfo_it(3) +CMS_ContentInfo_it(3) +CMS_EncryptedData_decrypt(3) +CMS_EncryptedData_encrypt(3) +CMS_EncryptedData_set1_key(3) +CMS_EnvelopedData_create(3) +CMS_ReceiptRequest_it(3) +CMS_ReceiptRequest_it(3) +CMS_RecipientEncryptedKey_cert_cmp(3) +CMS_RecipientEncryptedKey_get0_id(3) +CMS_RecipientInfo_get0_pkey_ctx(3) +CMS_RecipientInfo_kari_decrypt(3) +CMS_RecipientInfo_kari_get0_alg(3) +CMS_RecipientInfo_kari_get0_ctx(3) +CMS_RecipientInfo_kari_get0_orig_id(3) +CMS_RecipientInfo_kari_get0_reks(3) +CMS_RecipientInfo_kari_orig_id_cmp(3) +CMS_RecipientInfo_kari_set0_pkey(3) +CMS_RecipientInfo_ktri_get0_algs(3) +CMS_RecipientInfo_set0_password(3) +CMS_SharedInfo_encode(3) +CMS_SignedData_init(3) +CMS_SignerInfo_get0_algs(3) +CMS_SignerInfo_get0_md_ctx(3) +CMS_SignerInfo_get0_pkey_ctx(3) +CMS_SignerInfo_verify(3) +CMS_SignerInfo_verify_content(3) +CMS_add0_CertificateChoices(3) +CMS_add0_RevocationInfoChoice(3) +CMS_add0_recipient_password(3) +CMS_add_simple_smimecap(3) +CMS_add_smimecap(3) +CMS_add_standard_smimecap(3) +CMS_data(3) +CMS_dataFinal(3) +CMS_dataInit(3) +CMS_data_create(3) +CMS_decrypt_set1_key(3) +CMS_decrypt_set1_password(3) +CMS_decrypt_set1_pkey(3) +CMS_digest_create(3) +CMS_digest_verify(3) +CMS_is_detached(3) +CMS_set1_signers_certs(3) +CMS_set_detached(3) +CMS_signed_add1_attr(3) +CMS_signed_add1_attr_by_NID(3) +CMS_signed_add1_attr_by_OBJ(3) +CMS_signed_add1_attr_by_txt(3) +CMS_signed_delete_attr(3) +CMS_signed_get0_data_by_OBJ(3) +CMS_signed_get_attr(3) +CMS_signed_get_attr_by_NID(3) +CMS_signed_get_attr_by_OBJ(3) +CMS_signed_get_attr_count(3) +CMS_stream(3) +CMS_unsigned_add1_attr(3) +CMS_unsigned_add1_attr_by_NID(3) +CMS_unsigned_add1_attr_by_OBJ(3) +CMS_unsigned_add1_attr_by_txt(3) +CMS_unsigned_delete_attr(3) +CMS_unsigned_get0_data_by_OBJ(3) +CMS_unsigned_get_attr(3) +CMS_unsigned_get_attr_by_NID(3) +CMS_unsigned_get_attr_by_OBJ(3) +CMS_unsigned_get_attr_count(3) +COMP_CTX_free(3) +COMP_CTX_get_method(3) +COMP_CTX_get_type(3) +COMP_CTX_new(3) +COMP_compress_block(3) +COMP_expand_block(3) +COMP_get_name(3) +COMP_get_type(3) +COMP_zlib(3) +CONF_dump_bio(3) +CONF_dump_fp(3) +CONF_free(3) +CONF_get_number(3) +CONF_get_section(3) +CONF_get_string(3) +CONF_imodule_get_flags(3) +CONF_imodule_get_module(3) +CONF_imodule_get_name(3) +CONF_imodule_get_usr_data(3) +CONF_imodule_get_value(3) +CONF_imodule_set_flags(3) +CONF_imodule_set_usr_data(3) +CONF_load(3) +CONF_load_bio(3) +CONF_load_fp(3) +CONF_module_add(3) +CONF_module_get_usr_data(3) +CONF_module_set_usr_data(3) +CONF_parse_list(3) +CONF_set_default_method(3) +CONF_set_nconf(3) +CRL_DIST_POINTS_it(3) +CRL_DIST_POINTS_it(3) +CRYPTO_128_unwrap(3) +CRYPTO_128_unwrap_pad(3) +CRYPTO_128_wrap(3) +CRYPTO_128_wrap_pad(3) +CRYPTO_THREAD_cleanup_local(3) +CRYPTO_THREAD_compare_id(3) +CRYPTO_THREAD_get_current_id(3) +CRYPTO_THREAD_get_local(3) +CRYPTO_THREAD_init_local(3) +CRYPTO_THREAD_set_local(3) +CRYPTO_cbc128_decrypt(3) +CRYPTO_cbc128_encrypt(3) +CRYPTO_ccm128_aad(3) +CRYPTO_ccm128_decrypt(3) +CRYPTO_ccm128_decrypt_ccm64(3) +CRYPTO_ccm128_encrypt(3) +CRYPTO_ccm128_encrypt_ccm64(3) +CRYPTO_ccm128_init(3) +CRYPTO_ccm128_setiv(3) +CRYPTO_ccm128_tag(3) +CRYPTO_cfb128_1_encrypt(3) +CRYPTO_cfb128_8_encrypt(3) +CRYPTO_cfb128_encrypt(3) +CRYPTO_ctr128_encrypt(3) +CRYPTO_ctr128_encrypt_ctr32(3) +CRYPTO_cts128_decrypt(3) +CRYPTO_cts128_decrypt_block(3) +CRYPTO_cts128_encrypt(3) +CRYPTO_cts128_encrypt_block(3) +CRYPTO_dup_ex_data(3) +CRYPTO_gcm128_aad(3) +CRYPTO_gcm128_decrypt(3) +CRYPTO_gcm128_decrypt_ctr32(3) +CRYPTO_gcm128_encrypt(3) +CRYPTO_gcm128_encrypt_ctr32(3) +CRYPTO_gcm128_finish(3) +CRYPTO_gcm128_init(3) +CRYPTO_gcm128_new(3) +CRYPTO_gcm128_release(3) +CRYPTO_gcm128_setiv(3) +CRYPTO_gcm128_tag(3) +CRYPTO_mem_debug_free(3) +CRYPTO_mem_debug_malloc(3) +CRYPTO_mem_debug_realloc(3) +CRYPTO_memdup(3) +CRYPTO_nistcts128_decrypt(3) +CRYPTO_nistcts128_decrypt_block(3) +CRYPTO_nistcts128_encrypt(3) +CRYPTO_nistcts128_encrypt_block(3) +CRYPTO_ocb128_aad(3) +CRYPTO_ocb128_cleanup(3) +CRYPTO_ocb128_copy_ctx(3) +CRYPTO_ocb128_decrypt(3) +CRYPTO_ocb128_encrypt(3) +CRYPTO_ocb128_finish(3) +CRYPTO_ocb128_init(3) +CRYPTO_ocb128_new(3) +CRYPTO_ocb128_setiv(3) +CRYPTO_ocb128_tag(3) +CRYPTO_ofb128_encrypt(3) +CRYPTO_secure_actual_size(3) +CRYPTO_xts128_encrypt(3) +Camellia_cbc_encrypt(3) +Camellia_cfb128_encrypt(3) +Camellia_cfb1_encrypt(3) +Camellia_cfb8_encrypt(3) +Camellia_ctr128_encrypt(3) +Camellia_decrypt(3) +Camellia_ecb_encrypt(3) +Camellia_encrypt(3) +Camellia_ofb128_encrypt(3) +Camellia_set_key(3) +DES_cbc_encrypt(3) +DES_check_key_parity(3) +DES_decrypt3(3) +DES_ede3_cfb_encrypt(3) +DES_encrypt1(3) +DES_encrypt2(3) +DES_encrypt3(3) +DES_options(3) +DH_KDF_X9_42(3) +DH_check_pub_key(3) +DH_compute_key_padded(3) +DH_up_ref(3) +DHparams_dup(3) +DHparams_it(3) +DHparams_it(3) +DIRECTORYSTRING_it(3) +DIRECTORYSTRING_it(3) +DISPLAYTEXT_it(3) +DISPLAYTEXT_it(3) +DIST_POINT_NAME_it(3) +DIST_POINT_NAME_it(3) +DIST_POINT_it(3) +DIST_POINT_it(3) +DIST_POINT_set_dpname(3) +DSA_get_method(3) +DSA_up_ref(3) +DSO_METHOD_openssl(3) +DSO_bind_func(3) +DSO_convert_filename(3) +DSO_ctrl(3) +DSO_dsobyaddr(3) +DSO_flags(3) +DSO_free(3) +DSO_get_filename(3) +DSO_global_lookup(3) +DSO_load(3) +DSO_merge(3) +DSO_new(3) +DSO_pathbyaddr(3) +DSO_set_filename(3) +DSO_up_ref(3) +ECDH_KDF_X9_62(3) +ECDH_compute_key(3) +ECPARAMETERS_it(3) +ECPARAMETERS_it(3) +ECPKPARAMETERS_it(3) +ECPKPARAMETERS_it(3) +ECParameters_print(3) +ECParameters_print_fp(3) +EC_GROUP_get_mont_data(3) +EC_KEY_METHOD_free(3) +EC_KEY_METHOD_get_compute_key(3) +EC_KEY_METHOD_get_init(3) +EC_KEY_METHOD_get_keygen(3) +EC_KEY_METHOD_get_sign(3) +EC_KEY_METHOD_get_verify(3) +EC_KEY_METHOD_new(3) +EC_KEY_METHOD_set_compute_key(3) +EC_KEY_METHOD_set_init(3) +EC_KEY_METHOD_set_keygen(3) +EC_KEY_METHOD_set_sign(3) +EC_KEY_METHOD_set_verify(3) +EC_KEY_OpenSSL(3) +EC_KEY_can_sign(3) +EC_KEY_get_default_method(3) +EC_KEY_new_method(3) +EC_KEY_print(3) +EC_KEY_print_fp(3) +EC_KEY_set_default_method(3) +EC_curve_nid2nist(3) +EC_curve_nist2nid(3) +EDIPARTYNAME_it(3) +EDIPARTYNAME_it(3) +ENGINE_get_EC(3) +ENGINE_get_default_EC(3) +ENGINE_get_pkey_asn1_meth(3) +ENGINE_get_pkey_asn1_meth_engine(3) +ENGINE_get_pkey_asn1_meth_str(3) +ENGINE_get_pkey_asn1_meths(3) +ENGINE_get_pkey_meth(3) +ENGINE_get_pkey_meth_engine(3) +ENGINE_get_pkey_meths(3) +ENGINE_get_ssl_client_cert_function(3) +ENGINE_get_static_state(3) +ENGINE_load_ssl_client_cert(3) +ENGINE_pkey_asn1_find_str(3) +ENGINE_register_EC(3) +ENGINE_register_all_EC(3) +ENGINE_register_all_pkey_asn1_meths(3) +ENGINE_register_all_pkey_meths(3) +ENGINE_register_pkey_asn1_meths(3) +ENGINE_register_pkey_meths(3) +ENGINE_set_EC(3) +ENGINE_set_default_EC(3) +ENGINE_set_default_pkey_asn1_meths(3) +ENGINE_set_default_pkey_meths(3) +ENGINE_set_load_ssl_client_cert_function(3) +ENGINE_set_pkey_asn1_meths(3) +ENGINE_set_pkey_meths(3) +ENGINE_setup_bsd_cryptodev(3) +ENGINE_unregister_EC(3) +ENGINE_unregister_pkey_asn1_meths(3) +ENGINE_unregister_pkey_meths(3) +ERR_clear_last_mark(3) +ERR_get_state(3) +ERR_load_ASN1_strings(3) +ERR_load_ASYNC_strings(3) +ERR_load_BIO_strings(3) +ERR_load_BN_strings(3) +ERR_load_BUF_strings(3) +ERR_load_CMS_strings(3) +ERR_load_COMP_strings(3) +ERR_load_CONF_strings(3) +ERR_load_CRYPTO_strings(3) +ERR_load_CRYPTOlib_strings(3) +ERR_load_CT_strings(3) +ERR_load_DH_strings(3) +ERR_load_DSA_strings(3) +ERR_load_DSO_strings(3) +ERR_load_EC_strings(3) +ERR_load_ENGINE_strings(3) +ERR_load_ERR_strings(3) +ERR_load_EVP_strings(3) +ERR_load_KDF_strings(3) +ERR_load_OBJ_strings(3) +ERR_load_OCSP_strings(3) +ERR_load_OSSL_STORE_strings(3) +ERR_load_PEM_strings(3) +ERR_load_PKCS12_strings(3) +ERR_load_PKCS7_strings(3) +ERR_load_RAND_strings(3) +ERR_load_RSA_strings(3) +ERR_load_TS_strings(3) +ERR_load_UI_strings(3) +ERR_load_X509V3_strings(3) +ERR_load_X509_strings(3) +ERR_load_strings_const(3) +ERR_set_error_data(3) +ERR_unload_strings(3) +EVP_CIPHER_CTX_buf_noconst(3) +EVP_CIPHER_CTX_clear_flags(3) +EVP_CIPHER_CTX_copy(3) +EVP_CIPHER_CTX_encrypting(3) +EVP_CIPHER_CTX_iv(3) +EVP_CIPHER_CTX_iv_noconst(3) +EVP_CIPHER_CTX_num(3) +EVP_CIPHER_CTX_original_iv(3) +EVP_CIPHER_CTX_rand_key(3) +EVP_CIPHER_CTX_set_flags(3) +EVP_CIPHER_CTX_set_num(3) +EVP_CIPHER_CTX_test_flags(3) +EVP_CIPHER_do_all(3) +EVP_CIPHER_do_all_sorted(3) +EVP_CIPHER_get_asn1_iv(3) +EVP_CIPHER_impl_ctx_size(3) +EVP_CIPHER_set_asn1_iv(3) +EVP_Cipher(3) +EVP_Digest(3) +EVP_MD_CTX_pkey_ctx(3) +EVP_MD_CTX_set_update_fn(3) +EVP_MD_CTX_update_fn(3) +EVP_MD_do_all(3) +EVP_MD_do_all_sorted(3) +EVP_MD_flags(3) +EVP_PBE_CipherInit(3) +EVP_PBE_alg_add(3) +EVP_PBE_alg_add_type(3) +EVP_PBE_cleanup(3) +EVP_PBE_find(3) +EVP_PBE_get(3) +EVP_PBE_scrypt(3) +EVP_PKCS82PKEY(3) +EVP_PKEY2PKCS8(3) +EVP_PKEY_CTX_ctrl_uint64(3) +EVP_PKEY_CTX_get0_peerkey(3) +EVP_PKEY_CTX_get0_pkey(3) +EVP_PKEY_CTX_get_data(3) +EVP_PKEY_CTX_get_operation(3) +EVP_PKEY_CTX_hex2ctrl(3) +EVP_PKEY_CTX_md(3) +EVP_PKEY_CTX_set0_keygen_info(3) +EVP_PKEY_CTX_set_data(3) +EVP_PKEY_CTX_str2ctrl(3) +EVP_PKEY_add1_attr(3) +EVP_PKEY_add1_attr_by_NID(3) +EVP_PKEY_add1_attr_by_OBJ(3) +EVP_PKEY_add1_attr_by_txt(3) +EVP_PKEY_assign(3) +EVP_PKEY_bits(3) +EVP_PKEY_decrypt_old(3) +EVP_PKEY_delete_attr(3) +EVP_PKEY_encrypt_old(3) +EVP_PKEY_get0(3) +EVP_PKEY_get0_poly1305(3) +EVP_PKEY_get0_siphash(3) +EVP_PKEY_get_attr(3) +EVP_PKEY_get_attr_by_NID(3) +EVP_PKEY_get_attr_by_OBJ(3) +EVP_PKEY_get_attr_count(3) +EVP_PKEY_save_parameters(3) +EVP_PKEY_set_type(3) +EVP_PKEY_set_type_str(3) +EVP_add_alg_module(3) +EVP_add_cipher(3) +EVP_add_digest(3) +EVP_aes_128_cfb128(3) +EVP_aes_192_cfb128(3) +EVP_aes_256_cfb128(3) +EVP_aria_128_cfb128(3) +EVP_aria_192_cfb128(3) +EVP_aria_256_cfb128(3) +EVP_bf_cfb64(3) +EVP_camellia_128_cfb128(3) +EVP_camellia_192_cfb128(3) +EVP_camellia_256_cfb128(3) +EVP_cast5_cfb64(3) +EVP_des_cfb64(3) +EVP_des_ede3_cfb64(3) +EVP_des_ede3_ecb(3) +EVP_des_ede_cfb64(3) +EVP_des_ede_ecb(3) +EVP_get_pw_prompt(3) +EVP_idea_cfb64(3) +EVP_md5_sha1(3) +EVP_rc2_cfb64(3) +EVP_rc5_32_12_16_cfb64(3) +EVP_read_pw_string(3) +EVP_read_pw_string_min(3) +EVP_seed_cfb128(3) +EVP_set_pw_prompt(3) +EVP_sm4_cfb128(3) +EXTENDED_KEY_USAGE_it(3) +EXTENDED_KEY_USAGE_it(3) +FIPS_mode(3) +FIPS_mode_set(3) +GENERAL_NAMES_it(3) +GENERAL_NAMES_it(3) +GENERAL_NAME_cmp(3) +GENERAL_NAME_get0_otherName(3) +GENERAL_NAME_get0_value(3) +GENERAL_NAME_it(3) +GENERAL_NAME_it(3) +GENERAL_NAME_print(3) +GENERAL_NAME_set0_othername(3) +GENERAL_NAME_set0_value(3) +GENERAL_SUBTREE_it(3) +GENERAL_SUBTREE_it(3) +IDEA_cbc_encrypt(3) +IDEA_cfb64_encrypt(3) +IDEA_ecb_encrypt(3) +IDEA_encrypt(3) +IDEA_ofb64_encrypt(3) +IDEA_options(3) +IDEA_set_decrypt_key(3) +IDEA_set_encrypt_key(3) +INT32_it(3) +INT32_it(3) +INT64_it(3) +INT64_it(3) +IPAddressChoice_it(3) +IPAddressChoice_it(3) +IPAddressFamily_it(3) +IPAddressFamily_it(3) +IPAddressOrRange_it(3) +IPAddressOrRange_it(3) +IPAddressRange_it(3) +IPAddressRange_it(3) +ISSUING_DIST_POINT_it(3) +ISSUING_DIST_POINT_it(3) +LONG_it(3) +LONG_it(3) +MD2_options(3) +MD4_Transform(3) +MD5_Transform(3) +NAME_CONSTRAINTS_check(3) +NAME_CONSTRAINTS_check_CN(3) +NAME_CONSTRAINTS_it(3) +NAME_CONSTRAINTS_it(3) +NAMING_AUTHORITY_it(3) +NAMING_AUTHORITY_it(3) +NCONF_WIN32(3) +NCONF_default(3) +NCONF_dump_bio(3) +NCONF_dump_fp(3) +NCONF_free(3) +NCONF_free_data(3) +NCONF_get_number_e(3) +NCONF_get_section(3) +NCONF_get_string(3) +NCONF_load(3) +NCONF_load_bio(3) +NCONF_load_fp(3) +NCONF_new(3) +NETSCAPE_CERT_SEQUENCE_it(3) +NETSCAPE_CERT_SEQUENCE_it(3) +NETSCAPE_SPKAC_it(3) +NETSCAPE_SPKAC_it(3) +NETSCAPE_SPKI_b64_decode(3) +NETSCAPE_SPKI_b64_encode(3) +NETSCAPE_SPKI_get_pubkey(3) +NETSCAPE_SPKI_it(3) +NETSCAPE_SPKI_it(3) +NETSCAPE_SPKI_print(3) +NETSCAPE_SPKI_set_pubkey(3) +NETSCAPE_SPKI_sign(3) +NETSCAPE_SPKI_verify(3) +NOTICEREF_it(3) +NOTICEREF_it(3) +OBJ_NAME_add(3) +OBJ_NAME_cleanup(3) +OBJ_NAME_do_all(3) +OBJ_NAME_do_all_sorted(3) +OBJ_NAME_get(3) +OBJ_NAME_init(3) +OBJ_NAME_new_index(3) +OBJ_NAME_remove(3) +OBJ_add_object(3) +OBJ_add_sigid(3) +OBJ_bsearch_(3) +OBJ_bsearch_ex_(3) +OBJ_create_objects(3) +OBJ_find_sigid_algs(3) +OBJ_find_sigid_by_algs(3) +OBJ_new_nid(3) +OBJ_sigid_free(3) +OCSP_BASICRESP_add1_ext_i2d(3) +OCSP_BASICRESP_add_ext(3) +OCSP_BASICRESP_delete_ext(3) +OCSP_BASICRESP_get1_ext_d2i(3) +OCSP_BASICRESP_get_ext(3) +OCSP_BASICRESP_get_ext_by_NID(3) +OCSP_BASICRESP_get_ext_by_OBJ(3) +OCSP_BASICRESP_get_ext_by_critical(3) +OCSP_BASICRESP_get_ext_count(3) +OCSP_BASICRESP_it(3) +OCSP_BASICRESP_it(3) +OCSP_CERTID_it(3) +OCSP_CERTID_it(3) +OCSP_CERTSTATUS_it(3) +OCSP_CERTSTATUS_it(3) +OCSP_CRLID_it(3) +OCSP_CRLID_it(3) +OCSP_ONEREQ_add1_ext_i2d(3) +OCSP_ONEREQ_add_ext(3) +OCSP_ONEREQ_delete_ext(3) +OCSP_ONEREQ_get1_ext_d2i(3) +OCSP_ONEREQ_get_ext(3) +OCSP_ONEREQ_get_ext_by_NID(3) +OCSP_ONEREQ_get_ext_by_OBJ(3) +OCSP_ONEREQ_get_ext_by_critical(3) +OCSP_ONEREQ_get_ext_count(3) +OCSP_ONEREQ_it(3) +OCSP_ONEREQ_it(3) +OCSP_REQINFO_it(3) +OCSP_REQINFO_it(3) +OCSP_REQUEST_add1_ext_i2d(3) +OCSP_REQUEST_add_ext(3) +OCSP_REQUEST_delete_ext(3) +OCSP_REQUEST_get1_ext_d2i(3) +OCSP_REQUEST_get_ext(3) +OCSP_REQUEST_get_ext_by_NID(3) +OCSP_REQUEST_get_ext_by_OBJ(3) +OCSP_REQUEST_get_ext_by_critical(3) +OCSP_REQUEST_get_ext_count(3) +OCSP_REQUEST_it(3) +OCSP_REQUEST_it(3) +OCSP_REQUEST_print(3) +OCSP_REQ_CTX_get0_mem_bio(3) +OCSP_REQ_CTX_http(3) +OCSP_REQ_CTX_i2d(3) +OCSP_REQ_CTX_nbio(3) +OCSP_REQ_CTX_nbio_d2i(3) +OCSP_REQ_CTX_new(3) +OCSP_RESPBYTES_it(3) +OCSP_RESPBYTES_it(3) +OCSP_RESPDATA_it(3) +OCSP_RESPDATA_it(3) +OCSP_RESPID_it(3) +OCSP_RESPID_it(3) +OCSP_RESPONSE_it(3) +OCSP_RESPONSE_it(3) +OCSP_RESPONSE_print(3) +OCSP_REVOKEDINFO_it(3) +OCSP_REVOKEDINFO_it(3) +OCSP_SERVICELOC_it(3) +OCSP_SERVICELOC_it(3) +OCSP_SIGNATURE_it(3) +OCSP_SIGNATURE_it(3) +OCSP_SINGLERESP_add1_ext_i2d(3) +OCSP_SINGLERESP_add_ext(3) +OCSP_SINGLERESP_delete_ext(3) +OCSP_SINGLERESP_get0_id(3) +OCSP_SINGLERESP_get1_ext_d2i(3) +OCSP_SINGLERESP_get_ext(3) +OCSP_SINGLERESP_get_ext_by_NID(3) +OCSP_SINGLERESP_get_ext_by_OBJ(3) +OCSP_SINGLERESP_get_ext_by_critical(3) +OCSP_SINGLERESP_get_ext_count(3) +OCSP_SINGLERESP_it(3) +OCSP_SINGLERESP_it(3) +OCSP_accept_responses_new(3) +OCSP_archive_cutoff_new(3) +OCSP_basic_add1_cert(3) +OCSP_basic_add1_status(3) +OCSP_cert_status_str(3) +OCSP_crlID2_new(3) +OCSP_crlID_new(3) +OCSP_crl_reason_str(3) +OCSP_onereq_get0_id(3) +OCSP_parse_url(3) +OCSP_request_is_signed(3) +OCSP_request_set1_name(3) +OCSP_request_verify(3) +OCSP_response_status_str(3) +OCSP_url_svcloc_new(3) +OPENSSL_DIR_end(3) +OPENSSL_DIR_read(3) +OPENSSL_LH_delete(3) +OPENSSL_LH_doall(3) +OPENSSL_LH_doall_arg(3) +OPENSSL_LH_error(3) +OPENSSL_LH_free(3) +OPENSSL_LH_get_down_load(3) +OPENSSL_LH_insert(3) +OPENSSL_LH_new(3) +OPENSSL_LH_num_items(3) +OPENSSL_LH_retrieve(3) +OPENSSL_LH_set_down_load(3) +OPENSSL_LH_strhash(3) +OPENSSL_asc2uni(3) +OPENSSL_die(3) +OPENSSL_gmtime(3) +OPENSSL_gmtime_adj(3) +OPENSSL_gmtime_diff(3) +OPENSSL_init(3) +OPENSSL_isservice(3) +OPENSSL_issetugid(3) +OPENSSL_memcmp(3) +OPENSSL_sk_deep_copy(3) +OPENSSL_sk_delete(3) +OPENSSL_sk_delete_ptr(3) +OPENSSL_sk_dup(3) +OPENSSL_sk_find(3) +OPENSSL_sk_find_ex(3) +OPENSSL_sk_free(3) +OPENSSL_sk_insert(3) +OPENSSL_sk_is_sorted(3) +OPENSSL_sk_new(3) +OPENSSL_sk_new_null(3) +OPENSSL_sk_new_reserve(3) +OPENSSL_sk_num(3) +OPENSSL_sk_pop(3) +OPENSSL_sk_pop_free(3) +OPENSSL_sk_push(3) +OPENSSL_sk_reserve(3) +OPENSSL_sk_set(3) +OPENSSL_sk_set_cmp_func(3) +OPENSSL_sk_shift(3) +OPENSSL_sk_sort(3) +OPENSSL_sk_unshift(3) +OPENSSL_sk_value(3) +OPENSSL_sk_zero(3) +OPENSSL_strnlen(3) +OPENSSL_uni2asc(3) +OPENSSL_uni2utf8(3) +OPENSSL_utf82uni(3) +OSSL_STORE_do_all_loaders(3) +OSSL_STORE_vctrl(3) +OTHERNAME_cmp(3) +OTHERNAME_it(3) +OTHERNAME_it(3) +PBE2PARAM_it(3) +PBE2PARAM_it(3) +PBEPARAM_it(3) +PBEPARAM_it(3) +PBKDF2PARAM_it(3) +PBKDF2PARAM_it(3) +PEM_ASN1_read(3) +PEM_ASN1_read_bio(3) +PEM_ASN1_write(3) +PEM_ASN1_write_bio(3) +PEM_SignFinal(3) +PEM_SignInit(3) +PEM_SignUpdate(3) +PEM_X509_INFO_read(3) +PEM_X509_INFO_read_bio(3) +PEM_X509_INFO_write_bio(3) +PEM_def_callback(3) +PEM_dek_info(3) +PEM_proc_type(3) +PEM_read_bio_ECPrivateKey(3) +PEM_read_bio_Parameters(3) +PEM_write_bio_ASN1_stream(3) +PEM_write_bio_Parameters(3) +PKCS12_AUTHSAFES_it(3) +PKCS12_AUTHSAFES_it(3) +PKCS12_BAGS_it(3) +PKCS12_BAGS_it(3) +PKCS12_MAC_DATA_it(3) +PKCS12_MAC_DATA_it(3) +PKCS12_PBE_add(3) +PKCS12_PBE_keyivgen(3) +PKCS12_SAFEBAGS_it(3) +PKCS12_SAFEBAGS_it(3) +PKCS12_SAFEBAG_create0_p8inf(3) +PKCS12_SAFEBAG_create0_pkcs8(3) +PKCS12_SAFEBAG_create_cert(3) +PKCS12_SAFEBAG_create_crl(3) +PKCS12_SAFEBAG_create_pkcs8_encrypt(3) +PKCS12_SAFEBAG_get0_attr(3) +PKCS12_SAFEBAG_get0_attrs(3) +PKCS12_SAFEBAG_get0_p8inf(3) +PKCS12_SAFEBAG_get0_pkcs8(3) +PKCS12_SAFEBAG_get0_safes(3) +PKCS12_SAFEBAG_get0_type(3) +PKCS12_SAFEBAG_get1_cert(3) +PKCS12_SAFEBAG_get1_crl(3) +PKCS12_SAFEBAG_get_bag_nid(3) +PKCS12_SAFEBAG_get_nid(3) +PKCS12_SAFEBAG_it(3) +PKCS12_SAFEBAG_it(3) +PKCS12_add_CSPName_asc(3) +PKCS12_add_cert(3) +PKCS12_add_friendlyname_asc(3) +PKCS12_add_friendlyname_uni(3) +PKCS12_add_friendlyname_utf8(3) +PKCS12_add_key(3) +PKCS12_add_localkeyid(3) +PKCS12_add_safe(3) +PKCS12_add_safes(3) +PKCS12_decrypt_skey(3) +PKCS12_gen_mac(3) +PKCS12_get_attr(3) +PKCS12_get_attr_gen(3) +PKCS12_get_friendlyname(3) +PKCS12_init(3) +PKCS12_it(3) +PKCS12_it(3) +PKCS12_item_decrypt_d2i(3) +PKCS12_item_i2d_encrypt(3) +PKCS12_item_pack_safebag(3) +PKCS12_key_gen_asc(3) +PKCS12_key_gen_uni(3) +PKCS12_key_gen_utf8(3) +PKCS12_mac_present(3) +PKCS12_pack_authsafes(3) +PKCS12_pack_p7data(3) +PKCS12_pack_p7encdata(3) +PKCS12_pbe_crypt(3) +PKCS12_set_mac(3) +PKCS12_setup_mac(3) +PKCS12_unpack_authsafes(3) +PKCS12_unpack_p7data(3) +PKCS12_unpack_p7encdata(3) +PKCS12_verify_mac(3) +PKCS1_MGF1(3) +PKCS5_PBE_add(3) +PKCS5_PBE_keyivgen(3) +PKCS5_pbe2_set(3) +PKCS5_pbe2_set_iv(3) +PKCS5_pbe2_set_scrypt(3) +PKCS5_pbe_set(3) +PKCS5_pbe_set0_algor(3) +PKCS5_pbkdf2_set(3) +PKCS5_v2_PBE_keyivgen(3) +PKCS5_v2_scrypt_keyivgen(3) +PKCS7_ATTR_SIGN_it(3) +PKCS7_ATTR_SIGN_it(3) +PKCS7_ATTR_VERIFY_it(3) +PKCS7_ATTR_VERIFY_it(3) +PKCS7_DIGEST_it(3) +PKCS7_DIGEST_it(3) +PKCS7_ENCRYPT_it(3) +PKCS7_ENCRYPT_it(3) +PKCS7_ENC_CONTENT_it(3) +PKCS7_ENC_CONTENT_it(3) +PKCS7_ENVELOPE_it(3) +PKCS7_ENVELOPE_it(3) +PKCS7_ISSUER_AND_SERIAL_it(3) +PKCS7_ISSUER_AND_SERIAL_it(3) +PKCS7_RECIP_INFO_get0_alg(3) +PKCS7_RECIP_INFO_it(3) +PKCS7_RECIP_INFO_it(3) +PKCS7_RECIP_INFO_set(3) +PKCS7_SIGNED_it(3) +PKCS7_SIGNED_it(3) +PKCS7_SIGNER_INFO_get0_algs(3) +PKCS7_SIGNER_INFO_it(3) +PKCS7_SIGNER_INFO_it(3) +PKCS7_SIGNER_INFO_set(3) +PKCS7_SIGNER_INFO_sign(3) +PKCS7_SIGN_ENVELOPE_it(3) +PKCS7_SIGN_ENVELOPE_it(3) +PKCS7_add0_attrib_signing_time(3) +PKCS7_add1_attrib_digest(3) +PKCS7_add_attrib_content_type(3) +PKCS7_add_attrib_smimecap(3) +PKCS7_add_attribute(3) +PKCS7_add_certificate(3) +PKCS7_add_crl(3) +PKCS7_add_recipient(3) +PKCS7_add_recipient_info(3) +PKCS7_add_signature(3) +PKCS7_add_signed_attribute(3) +PKCS7_add_signer(3) +PKCS7_cert_from_signer_info(3) +PKCS7_content_new(3) +PKCS7_ctrl(3) +PKCS7_dataDecode(3) +PKCS7_dataFinal(3) +PKCS7_dataInit(3) +PKCS7_dataVerify(3) +PKCS7_digest_from_attributes(3) +PKCS7_final(3) +PKCS7_get_attribute(3) +PKCS7_get_issuer_and_serial(3) +PKCS7_get_signed_attribute(3) +PKCS7_get_signer_info(3) +PKCS7_get_smimecap(3) +PKCS7_it(3) +PKCS7_it(3) +PKCS7_set0_type_other(3) +PKCS7_set_attributes(3) +PKCS7_set_cipher(3) +PKCS7_set_content(3) +PKCS7_set_digest(3) +PKCS7_set_signed_attributes(3) +PKCS7_set_type(3) +PKCS7_signatureVerify(3) +PKCS7_simple_smimecap(3) +PKCS7_stream(3) +PKCS7_to_TS_TST_INFO(3) +PKCS8_PRIV_KEY_INFO_it(3) +PKCS8_PRIV_KEY_INFO_it(3) +PKCS8_add_keyusage(3) +PKCS8_decrypt(3) +PKCS8_encrypt(3) +PKCS8_get_attr(3) +PKCS8_pkey_add1_attr_by_NID(3) +PKCS8_pkey_get0(3) +PKCS8_pkey_get0_attrs(3) +PKCS8_pkey_set0(3) +PKCS8_set0_pbe(3) +PKEY_USAGE_PERIOD_it(3) +PKEY_USAGE_PERIOD_it(3) +POLICYINFO_it(3) +POLICYINFO_it(3) +POLICYQUALINFO_it(3) +POLICYQUALINFO_it(3) +POLICY_CONSTRAINTS_it(3) +POLICY_CONSTRAINTS_it(3) +POLICY_MAPPINGS_it(3) +POLICY_MAPPINGS_it(3) +POLICY_MAPPING_it(3) +POLICY_MAPPING_it(3) +PROFESSION_INFO_it(3) +PROFESSION_INFO_it(3) +PROXY_CERT_INFO_EXTENSION_it(3) +PROXY_CERT_INFO_EXTENSION_it(3) +PROXY_POLICY_it(3) +PROXY_POLICY_it(3) +RAND_set_rand_engine(3) +RC2_cbc_encrypt(3) +RC2_cfb64_encrypt(3) +RC2_decrypt(3) +RC2_ecb_encrypt(3) +RC2_encrypt(3) +RC2_ofb64_encrypt(3) +RC2_set_key(3) +RC4_options(3) +RC5_32_cbc_encrypt(3) +RC5_32_cfb64_encrypt(3) +RC5_32_decrypt(3) +RC5_32_ecb_encrypt(3) +RC5_32_encrypt(3) +RC5_32_ofb64_encrypt(3) +RC5_32_set_key(3) +RIPEMD160_Transform(3) +RSAPrivateKey_it(3) +RSAPrivateKey_it(3) +RSAPublicKey_it(3) +RSAPublicKey_it(3) +RSA_OAEP_PARAMS_it(3) +RSA_OAEP_PARAMS_it(3) +RSA_PSS_PARAMS_it(3) +RSA_PSS_PARAMS_it(3) +RSA_X931_derive_ex(3) +RSA_X931_generate_key_ex(3) +RSA_X931_hash_id(3) +RSA_null_method(3) +RSA_padding_add_PKCS1_OAEP_mgf1(3) +RSA_padding_add_PKCS1_PSS(3) +RSA_padding_add_PKCS1_PSS_mgf1(3) +RSA_padding_add_X931(3) +RSA_padding_check_PKCS1_OAEP_mgf1(3) +RSA_padding_check_X931(3) +RSA_pkey_ctx_ctrl(3) +RSA_setup_blinding(3) +RSA_up_ref(3) +RSA_verify_PKCS1_PSS(3) +RSA_verify_PKCS1_PSS_mgf1(3) +SCRYPT_PARAMS_it(3) +SCRYPT_PARAMS_it(3) +SEED_cbc_encrypt(3) +SEED_cfb128_encrypt(3) +SEED_decrypt(3) +SEED_ecb_encrypt(3) +SEED_encrypt(3) +SEED_ofb128_encrypt(3) +SEED_set_key(3) +SHA1_Transform(3) +SHA256_Transform(3) +SHA512_Transform(3) +SMIME_crlf_copy(3) +SMIME_read_ASN1(3) +SMIME_text(3) +SMIME_write_ASN1(3) +SRP_Calc_A(3) +SRP_Calc_B(3) +SRP_Calc_client_key(3) +SRP_Calc_server_key(3) +SRP_Calc_u(3) +SRP_Calc_x(3) +SRP_VBASE_free(3) +SRP_VBASE_get1_by_user(3) +SRP_VBASE_get_by_user(3) +SRP_VBASE_init(3) +SRP_VBASE_new(3) +SRP_Verify_A_mod_N(3) +SRP_Verify_B_mod_N(3) +SRP_check_known_gN_param(3) +SRP_create_verifier(3) +SRP_create_verifier_BN(3) +SRP_get_default_gN(3) +SRP_user_pwd_free(3) +SSL_CTX_set0_ctlog_store(3) +SXNETID_it(3) +SXNETID_it(3) +SXNET_add_id_INTEGER(3) +SXNET_add_id_asc(3) +SXNET_add_id_ulong(3) +SXNET_get_id_INTEGER(3) +SXNET_get_id_asc(3) +SXNET_get_id_ulong(3) +SXNET_it(3) +SXNET_it(3) +TS_ACCURACY_get_micros(3) +TS_ACCURACY_get_millis(3) +TS_ACCURACY_get_seconds(3) +TS_ACCURACY_set_micros(3) +TS_ACCURACY_set_millis(3) +TS_ACCURACY_set_seconds(3) +TS_ASN1_INTEGER_print_bio(3) +TS_CONF_get_tsa_section(3) +TS_CONF_load_cert(3) +TS_CONF_load_certs(3) +TS_CONF_load_key(3) +TS_CONF_set_accuracy(3) +TS_CONF_set_certs(3) +TS_CONF_set_clock_precision_digits(3) +TS_CONF_set_crypto_device(3) +TS_CONF_set_def_policy(3) +TS_CONF_set_default_engine(3) +TS_CONF_set_digests(3) +TS_CONF_set_ess_cert_id_chain(3) +TS_CONF_set_ess_cert_id_digest(3) +TS_CONF_set_ordering(3) +TS_CONF_set_policies(3) +TS_CONF_set_serial(3) +TS_CONF_set_signer_cert(3) +TS_CONF_set_signer_digest(3) +TS_CONF_set_signer_key(3) +TS_CONF_set_tsa_name(3) +TS_MSG_IMPRINT_get_algo(3) +TS_MSG_IMPRINT_get_msg(3) +TS_MSG_IMPRINT_print_bio(3) +TS_MSG_IMPRINT_set_algo(3) +TS_MSG_IMPRINT_set_msg(3) +TS_OBJ_print_bio(3) +TS_REQ_add_ext(3) +TS_REQ_delete_ext(3) +TS_REQ_ext_free(3) +TS_REQ_get_cert_req(3) +TS_REQ_get_ext(3) +TS_REQ_get_ext_by_NID(3) +TS_REQ_get_ext_by_OBJ(3) +TS_REQ_get_ext_by_critical(3) +TS_REQ_get_ext_count(3) +TS_REQ_get_ext_d2i(3) +TS_REQ_get_exts(3) +TS_REQ_get_msg_imprint(3) +TS_REQ_get_nonce(3) +TS_REQ_get_policy_id(3) +TS_REQ_get_version(3) +TS_REQ_print_bio(3) +TS_REQ_set_cert_req(3) +TS_REQ_set_msg_imprint(3) +TS_REQ_set_nonce(3) +TS_REQ_set_policy_id(3) +TS_REQ_set_version(3) +TS_REQ_to_TS_VERIFY_CTX(3) +TS_RESP_CTX_add_failure_info(3) +TS_RESP_CTX_add_flags(3) +TS_RESP_CTX_add_md(3) +TS_RESP_CTX_add_policy(3) +TS_RESP_CTX_free(3) +TS_RESP_CTX_get_request(3) +TS_RESP_CTX_get_tst_info(3) +TS_RESP_CTX_new(3) +TS_RESP_CTX_set_accuracy(3) +TS_RESP_CTX_set_certs(3) +TS_RESP_CTX_set_clock_precision_digits(3) +TS_RESP_CTX_set_def_policy(3) +TS_RESP_CTX_set_ess_cert_id_digest(3) +TS_RESP_CTX_set_extension_cb(3) +TS_RESP_CTX_set_serial_cb(3) +TS_RESP_CTX_set_signer_cert(3) +TS_RESP_CTX_set_signer_digest(3) +TS_RESP_CTX_set_signer_key(3) +TS_RESP_CTX_set_status_info(3) +TS_RESP_CTX_set_status_info_cond(3) +TS_RESP_CTX_set_time_cb(3) +TS_RESP_create_response(3) +TS_RESP_get_status_info(3) +TS_RESP_get_token(3) +TS_RESP_get_tst_info(3) +TS_RESP_print_bio(3) +TS_RESP_set_status_info(3) +TS_RESP_set_tst_info(3) +TS_RESP_verify_response(3) +TS_RESP_verify_signature(3) +TS_RESP_verify_token(3) +TS_STATUS_INFO_get0_failure_info(3) +TS_STATUS_INFO_get0_status(3) +TS_STATUS_INFO_get0_text(3) +TS_STATUS_INFO_print_bio(3) +TS_STATUS_INFO_set_status(3) +TS_TST_INFO_add_ext(3) +TS_TST_INFO_delete_ext(3) +TS_TST_INFO_ext_free(3) +TS_TST_INFO_get_accuracy(3) +TS_TST_INFO_get_ext(3) +TS_TST_INFO_get_ext_by_NID(3) +TS_TST_INFO_get_ext_by_OBJ(3) +TS_TST_INFO_get_ext_by_critical(3) +TS_TST_INFO_get_ext_count(3) +TS_TST_INFO_get_ext_d2i(3) +TS_TST_INFO_get_exts(3) +TS_TST_INFO_get_msg_imprint(3) +TS_TST_INFO_get_nonce(3) +TS_TST_INFO_get_ordering(3) +TS_TST_INFO_get_policy_id(3) +TS_TST_INFO_get_serial(3) +TS_TST_INFO_get_time(3) +TS_TST_INFO_get_tsa(3) +TS_TST_INFO_get_version(3) +TS_TST_INFO_print_bio(3) +TS_TST_INFO_set_accuracy(3) +TS_TST_INFO_set_msg_imprint(3) +TS_TST_INFO_set_nonce(3) +TS_TST_INFO_set_ordering(3) +TS_TST_INFO_set_policy_id(3) +TS_TST_INFO_set_serial(3) +TS_TST_INFO_set_time(3) +TS_TST_INFO_set_tsa(3) +TS_TST_INFO_set_version(3) +TS_VERIFY_CTS_set_certs(3) +TS_VERIFY_CTX_add_flags(3) +TS_VERIFY_CTX_cleanup(3) +TS_VERIFY_CTX_free(3) +TS_VERIFY_CTX_init(3) +TS_VERIFY_CTX_new(3) +TS_VERIFY_CTX_set_data(3) +TS_VERIFY_CTX_set_flags(3) +TS_VERIFY_CTX_set_imprint(3) +TS_VERIFY_CTX_set_store(3) +TS_X509_ALGOR_print_bio(3) +TS_ext_print_bio(3) +TXT_DB_create_index(3) +TXT_DB_free(3) +TXT_DB_get_by_index(3) +TXT_DB_insert(3) +TXT_DB_read(3) +TXT_DB_write(3) +UINT32_it(3) +UINT32_it(3) +UINT64_it(3) +UINT64_it(3) +USERNOTICE_it(3) +USERNOTICE_it(3) +UTF8_getc(3) +UTF8_putc(3) +WHIRLPOOL(3) +WHIRLPOOL_BitUpdate(3) +WHIRLPOOL_Final(3) +WHIRLPOOL_Init(3) +WHIRLPOOL_Update(3) +X509V3_EXT_CRL_add_conf(3) +X509V3_EXT_CRL_add_nconf(3) +X509V3_EXT_REQ_add_conf(3) +X509V3_EXT_REQ_add_nconf(3) +X509V3_EXT_add(3) +X509V3_EXT_add_alias(3) +X509V3_EXT_add_conf(3) +X509V3_EXT_add_list(3) +X509V3_EXT_add_nconf(3) +X509V3_EXT_add_nconf_sk(3) +X509V3_EXT_cleanup(3) +X509V3_EXT_conf(3) +X509V3_EXT_conf_nid(3) +X509V3_EXT_get(3) +X509V3_EXT_get_nid(3) +X509V3_EXT_nconf(3) +X509V3_EXT_nconf_nid(3) +X509V3_EXT_print(3) +X509V3_EXT_print_fp(3) +X509V3_EXT_val_prn(3) +X509V3_NAME_from_section(3) +X509V3_add_standard_extensions(3) +X509V3_add_value(3) +X509V3_add_value_bool(3) +X509V3_add_value_bool_nf(3) +X509V3_add_value_int(3) +X509V3_add_value_uchar(3) +X509V3_conf_free(3) +X509V3_extensions_print(3) +X509V3_get_section(3) +X509V3_get_string(3) +X509V3_get_value_bool(3) +X509V3_get_value_int(3) +X509V3_parse_list(3) +X509V3_section_free(3) +X509V3_set_conf_lhash(3) +X509V3_set_ctx(3) +X509V3_set_nconf(3) +X509V3_string_free(3) +X509_ALGORS_it(3) +X509_ALGORS_it(3) +X509_ALGOR_it(3) +X509_ALGOR_it(3) +X509_ATTRIBUTE_count(3) +X509_ATTRIBUTE_create(3) +X509_ATTRIBUTE_create_by_NID(3) +X509_ATTRIBUTE_create_by_OBJ(3) +X509_ATTRIBUTE_create_by_txt(3) +X509_ATTRIBUTE_get0_data(3) +X509_ATTRIBUTE_get0_object(3) +X509_ATTRIBUTE_get0_type(3) +X509_ATTRIBUTE_it(3) +X509_ATTRIBUTE_it(3) +X509_ATTRIBUTE_set1_data(3) +X509_ATTRIBUTE_set1_object(3) +X509_CERT_AUX_it(3) +X509_CERT_AUX_it(3) +X509_CINF_it(3) +X509_CINF_it(3) +X509_CRL_INFO_it(3) +X509_CRL_INFO_it(3) +X509_CRL_METHOD_free(3) +X509_CRL_METHOD_new(3) +X509_CRL_check_suiteb(3) +X509_CRL_cmp(3) +X509_CRL_diff(3) +X509_CRL_get_lastUpdate(3) +X509_CRL_get_meth_data(3) +X509_CRL_get_nextUpdate(3) +X509_CRL_http_nbio(3) +X509_CRL_it(3) +X509_CRL_it(3) +X509_CRL_match(3) +X509_CRL_print(3) +X509_CRL_print_ex(3) +X509_CRL_print_fp(3) +X509_CRL_set_default_method(3) +X509_CRL_set_meth_data(3) +X509_CRL_up_ref(3) +X509_EXTENSIONS_it(3) +X509_EXTENSIONS_it(3) +X509_EXTENSION_it(3) +X509_EXTENSION_it(3) +X509_INFO_free(3) +X509_INFO_new(3) +X509_LOOKUP_by_alias(3) +X509_LOOKUP_by_fingerprint(3) +X509_LOOKUP_by_issuer_serial(3) +X509_LOOKUP_by_subject(3) +X509_LOOKUP_ctrl(3) +X509_LOOKUP_free(3) +X509_LOOKUP_init(3) +X509_LOOKUP_new(3) +X509_LOOKUP_shutdown(3) +X509_NAME_ENTRY_it(3) +X509_NAME_ENTRY_it(3) +X509_NAME_ENTRY_set(3) +X509_NAME_cmp(3) +X509_NAME_hash(3) +X509_NAME_hash_old(3) +X509_NAME_it(3) +X509_NAME_it(3) +X509_NAME_set(3) +X509_OBJECT_free(3) +X509_OBJECT_get0_X509(3) +X509_OBJECT_get0_X509_CRL(3) +X509_OBJECT_get_type(3) +X509_OBJECT_idx_by_subject(3) +X509_OBJECT_new(3) +X509_OBJECT_retrieve_by_subject(3) +X509_OBJECT_retrieve_match(3) +X509_OBJECT_up_ref_count(3) +X509_PKEY_free(3) +X509_PKEY_new(3) +X509_POLICY_NODE_print(3) +X509_PUBKEY_it(3) +X509_PUBKEY_it(3) +X509_PURPOSE_add(3) +X509_PURPOSE_cleanup(3) +X509_PURPOSE_get0(3) +X509_PURPOSE_get0_name(3) +X509_PURPOSE_get0_sname(3) +X509_PURPOSE_get_by_id(3) +X509_PURPOSE_get_by_sname(3) +X509_PURPOSE_get_count(3) +X509_PURPOSE_get_id(3) +X509_PURPOSE_get_trust(3) +X509_PURPOSE_set(3) +X509_REQ_INFO_it(3) +X509_REQ_INFO_it(3) +X509_REQ_add1_attr(3) +X509_REQ_add1_attr_by_NID(3) +X509_REQ_add1_attr_by_OBJ(3) +X509_REQ_add1_attr_by_txt(3) +X509_REQ_add_extensions(3) +X509_REQ_add_extensions_nid(3) +X509_REQ_delete_attr(3) +X509_REQ_extension_nid(3) +X509_REQ_get1_email(3) +X509_REQ_get_attr(3) +X509_REQ_get_attr_by_NID(3) +X509_REQ_get_attr_by_OBJ(3) +X509_REQ_get_attr_count(3) +X509_REQ_get_extension_nids(3) +X509_REQ_get_extensions(3) +X509_REQ_it(3) +X509_REQ_it(3) +X509_REQ_print(3) +X509_REQ_print_ex(3) +X509_REQ_print_fp(3) +X509_REQ_set_extension_nids(3) +X509_REQ_to_X509(3) +X509_REVOKED_it(3) +X509_REVOKED_it(3) +X509_SIG_it(3) +X509_SIG_it(3) +X509_STORE_CTX_get0_current_crl(3) +X509_STORE_CTX_get0_current_issuer(3) +X509_STORE_CTX_get0_parent_ctx(3) +X509_STORE_CTX_get0_policy_tree(3) +X509_STORE_CTX_get0_store(3) +X509_STORE_CTX_get1_certs(3) +X509_STORE_CTX_get1_crls(3) +X509_STORE_CTX_get1_issuer(3) +X509_STORE_CTX_get_by_subject(3) +X509_STORE_CTX_get_explicit_policy(3) +X509_STORE_CTX_get_obj_by_subject(3) +X509_STORE_CTX_purpose_inherit(3) +X509_STORE_CTX_set0_dane(3) +X509_STORE_CTX_set_depth(3) +X509_STORE_CTX_set_flags(3) +X509_STORE_CTX_set_purpose(3) +X509_STORE_CTX_set_time(3) +X509_STORE_CTX_set_trust(3) +X509_STORE_add_lookup(3) +X509_STORE_get_verify(3) +X509_TRUST_add(3) +X509_TRUST_cleanup(3) +X509_TRUST_get0(3) +X509_TRUST_get0_name(3) +X509_TRUST_get_by_id(3) +X509_TRUST_get_count(3) +X509_TRUST_get_flags(3) +X509_TRUST_get_trust(3) +X509_TRUST_set(3) +X509_TRUST_set_default(3) +X509_VAL_it(3) +X509_VAL_it(3) +X509_VERIFY_PARAM_add0_table(3) +X509_VERIFY_PARAM_free(3) +X509_VERIFY_PARAM_get0(3) +X509_VERIFY_PARAM_get0_name(3) +X509_VERIFY_PARAM_get_count(3) +X509_VERIFY_PARAM_inherit(3) +X509_VERIFY_PARAM_lookup(3) +X509_VERIFY_PARAM_move_peername(3) +X509_VERIFY_PARAM_new(3) +X509_VERIFY_PARAM_set1(3) +X509_VERIFY_PARAM_set1_name(3) +X509_VERIFY_PARAM_table_cleanup(3) +X509_add1_reject_object(3) +X509_add1_trust_object(3) +X509_alias_get0(3) +X509_alias_set1(3) +X509_aux_print(3) +X509_certificate_type(3) +X509_chain_check_suiteb(3) +X509_check_akid(3) +X509_check_purpose(3) +X509_check_trust(3) +X509_cmp(3) +X509_email_free(3) +X509_find_by_issuer_and_serial(3) +X509_find_by_subject(3) +X509_get0_pubkey_bitstr(3) +X509_get0_reject_objects(3) +X509_get0_trust_objects(3) +X509_get1_email(3) +X509_get1_ocsp(3) +X509_get_default_cert_area(3) +X509_get_default_cert_dir(3) +X509_get_default_cert_dir_env(3) +X509_get_default_cert_file(3) +X509_get_default_cert_file_env(3) +X509_get_default_private_dir(3) +X509_get_pubkey_parameters(3) +X509_get_signature_type(3) +X509_gmtime_adj(3) +X509_http_nbio(3) +X509_issuer_and_serial_cmp(3) +X509_issuer_and_serial_hash(3) +X509_issuer_name_cmp(3) +X509_issuer_name_hash(3) +X509_issuer_name_hash_old(3) +X509_it(3) +X509_it(3) +X509_keyid_get0(3) +X509_keyid_set1(3) +X509_ocspid_print(3) +X509_policy_check(3) +X509_policy_level_get0_node(3) +X509_policy_level_node_count(3) +X509_policy_node_get0_parent(3) +X509_policy_node_get0_policy(3) +X509_policy_node_get0_qualifiers(3) +X509_policy_tree_free(3) +X509_policy_tree_get0_level(3) +X509_policy_tree_get0_policies(3) +X509_policy_tree_get0_user_policies(3) +X509_policy_tree_level_count(3) +X509_print(3) +X509_print_ex(3) +X509_print_ex_fp(3) +X509_print_fp(3) +X509_reject_clear(3) +X509_signature_dump(3) +X509_signature_print(3) +X509_subject_name_cmp(3) +X509_subject_name_hash(3) +X509_subject_name_hash_old(3) +X509_supported_extension(3) +X509_to_X509_REQ(3) +X509_trust_clear(3) +X509_trusted(3) +X509at_add1_attr(3) +X509at_add1_attr_by_NID(3) +X509at_add1_attr_by_OBJ(3) +X509at_add1_attr_by_txt(3) +X509at_delete_attr(3) +X509at_get0_data_by_OBJ(3) +X509at_get_attr(3) +X509at_get_attr_by_NID(3) +X509at_get_attr_by_OBJ(3) +X509at_get_attr_count(3) +X509v3_addr_add_inherit(3) +X509v3_addr_add_prefix(3) +X509v3_addr_add_range(3) +X509v3_addr_canonize(3) +X509v3_addr_get_afi(3) +X509v3_addr_get_range(3) +X509v3_addr_inherits(3) +X509v3_addr_is_canonical(3) +X509v3_addr_subset(3) +X509v3_addr_validate_path(3) +X509v3_addr_validate_resource_set(3) +X509v3_asid_add_id_or_range(3) +X509v3_asid_add_inherit(3) +X509v3_asid_canonize(3) +X509v3_asid_inherits(3) +X509v3_asid_is_canonical(3) +X509v3_asid_subset(3) +X509v3_asid_validate_path(3) +X509v3_asid_validate_resource_set(3) +ZINT32_it(3) +ZINT32_it(3) +ZINT64_it(3) +ZINT64_it(3) +ZLONG_it(3) +ZLONG_it(3) +ZUINT32_it(3) +ZUINT32_it(3) +ZUINT64_it(3) +ZUINT64_it(3) +_shadow_DES_check_key(3) +_shadow_DES_check_key(3) +a2d_ASN1_OBJECT(3) +a2i_ASN1_ENUMERATED(3) +a2i_ASN1_INTEGER(3) +a2i_ASN1_STRING(3) +a2i_GENERAL_NAME(3) +a2i_IPADDRESS(3) +a2i_IPADDRESS_NC(3) +b2i_PVK_bio(3) +b2i_PrivateKey(3) +b2i_PrivateKey_bio(3) +b2i_PublicKey(3) +b2i_PublicKey_bio(3) +conf_ssl_get(3) +conf_ssl_get_cmd(3) +conf_ssl_name_find(3) +err_free_strings_int(3) +i2a_ACCESS_DESCRIPTION(3) +i2a_ASN1_ENUMERATED(3) +i2a_ASN1_INTEGER(3) +i2a_ASN1_OBJECT(3) +i2a_ASN1_STRING(3) +i2b_PVK_bio(3) +i2b_PrivateKey_bio(3) +i2b_PublicKey_bio(3) +i2d_PrivateKey_bio(3) +i2d_PrivateKey_fp(3) +i2o_ECPublicKey(3) +i2s_ASN1_ENUMERATED(3) +i2s_ASN1_ENUMERATED_TABLE(3) +i2s_ASN1_IA5STRING(3) +i2s_ASN1_INTEGER(3) +i2s_ASN1_OCTET_STRING(3) +i2v_ASN1_BIT_STRING(3) +i2v_GENERAL_NAME(3) +i2v_GENERAL_NAMES(3) +o2i_ECPublicKey(3) +s2i_ASN1_IA5STRING(3) +s2i_ASN1_INTEGER(3) +s2i_ASN1_OCTET_STRING(3) +v2i_ASN1_BIT_STRING(3) +v2i_GENERAL_NAME(3) +v2i_GENERAL_NAMES(3) +v2i_GENERAL_NAME_ex(3) diff --git a/util/missingmacro.txt b/util/missingmacro.txt index 20e6077c6b..50b4b17b15 100644 --- a/util/missingmacro.txt +++ b/util/missingmacro.txt @@ -137,6 +137,7 @@ SSL_get0_certificate_types(3) SSL_CTX_set1_client_certificate_types(3) SSL_set1_client_certificate_types(3) SSL_get0_raw_cipherlist(3) +SSL_get0_ec_point_formats(3) SSL_CTX_need_tmp_RSA(3) SSL_CTX_set_tmp_rsa(3) SSL_need_tmp_RSA(3) diff --git a/util/missingmacro111.txt b/util/missingmacro111.txt new file mode 100644 index 0000000000..0b6a86e7e3 --- /dev/null +++ b/util/missingmacro111.txt @@ -0,0 +1,230 @@ +# A list of macros that are known to be missing documentation as used by the +# find-doc-nits -v -o option. The list is as of commit 1708e3e85b (the release +# of 1.1.1). +BIO_get_flags(3) +BIO_set_retry_special(3) +BIO_set_retry_read(3) +BIO_set_retry_write(3) +BIO_clear_retry_flags(3) +BIO_get_retry_flags(3) +BIO_CB_return(3) +BIO_cb_pre(3) +BIO_cb_post(3) +BIO_set_app_data(3) +BIO_get_app_data(3) +BIO_set_conn_mode(3) +BIO_dup_state(3) +BIO_buffer_get_num_lines(3) +BIO_buffer_peek(3) +BIO_ctrl_dgram_connect(3) +BIO_ctrl_set_connected(3) +BIO_dgram_recv_timedout(3) +BIO_dgram_send_timedout(3) +BIO_dgram_get_peer(3) +BIO_dgram_set_peer(3) +BIO_dgram_get_mtu_overhead(3) +BIO_sock_cleanup(3) +ossl_bio__attr__(3) +BN_prime_checks_for_size(3) +BN_GF2m_sub(3) +BN_GF2m_cmp(3) +BUF_strdup(3) +BUF_strndup(3) +BUF_memdup(3) +BUF_strlcpy(3) +BUF_strlcat(3) +BUF_strnlen(3) +COMP_zlib_cleanup(3) +NCONF_get_number(3) +OPENSSL_MALLOC_MAX_NELEMS(3) +CRYPTO_cleanup_all_ex_data(3) +CRYPTO_num_locks(3) +CRYPTO_set_locking_callback(3) +CRYPTO_get_locking_callback(3) +CRYPTO_set_add_lock_callback(3) +CRYPTO_get_add_lock_callback(3) +CRYPTO_THREADID_set_numeric(3) +CRYPTO_THREADID_set_pointer(3) +CRYPTO_THREADID_set_callback(3) +CRYPTO_THREADID_get_callback(3) +CRYPTO_THREADID_current(3) +CRYPTO_THREADID_cmp(3) +CRYPTO_THREADID_cpy(3) +CRYPTO_THREADID_hash(3) +CRYPTO_set_id_callback(3) +CRYPTO_get_id_callback(3) +CRYPTO_thread_id(3) +CRYPTO_set_dynlock_create_callback(3) +CRYPTO_set_dynlock_lock_callback(3) +CRYPTO_set_dynlock_destroy_callback(3) +CRYPTO_get_dynlock_create_callback(3) +CRYPTO_get_dynlock_lock_callback(3) +CRYPTO_get_dynlock_destroy_callback(3) +OpenSSLDie(3) +OPENSSL_assert(3) +EVP_PKEY_CTX_set_dh_paramgen_subprime_len(3) +EVP_PKEY_CTX_set_dh_paramgen_type(3) +EVP_PKEY_CTX_set_dh_rfc5114(3) +EVP_PKEY_CTX_set_dhx_rfc5114(3) +EVP_PKEY_CTX_set_dh_kdf_type(3) +EVP_PKEY_CTX_get_dh_kdf_type(3) +EVP_PKEY_CTX_set0_dh_kdf_oid(3) +EVP_PKEY_CTX_get0_dh_kdf_oid(3) +EVP_PKEY_CTX_set_dh_kdf_md(3) +EVP_PKEY_CTX_get_dh_kdf_md(3) +EVP_PKEY_CTX_set_dh_kdf_outlen(3) +EVP_PKEY_CTX_get_dh_kdf_outlen(3) +EVP_PKEY_CTX_set0_dh_kdf_ukm(3) +EVP_PKEY_CTX_get0_dh_kdf_ukm(3) +DSA_is_prime(3) +OPENSSL_GLOBAL_REF(3) +OPENSSL_GLOBAL_REF(3) +ECParameters_dup(3) +EVP_PKEY_CTX_set_ecdh_cofactor_mode(3) +EVP_PKEY_CTX_get_ecdh_cofactor_mode(3) +EVP_PKEY_CTX_set_ecdh_kdf_type(3) +EVP_PKEY_CTX_get_ecdh_kdf_type(3) +EVP_PKEY_CTX_set_ecdh_kdf_md(3) +EVP_PKEY_CTX_get_ecdh_kdf_md(3) +EVP_PKEY_CTX_set_ecdh_kdf_outlen(3) +EVP_PKEY_CTX_get_ecdh_kdf_outlen(3) +EVP_PKEY_CTX_set0_ecdh_kdf_ukm(3) +EVP_PKEY_CTX_get0_ecdh_kdf_ukm(3) +ENGINE_load_openssl(3) +ENGINE_load_dynamic(3) +ENGINE_load_padlock(3) +ENGINE_load_capi(3) +ENGINE_load_afalg(3) +ENGINE_load_cryptodev(3) +ENGINE_load_rdrand(3) +EVP_PKEY_assign_SIPHASH(3) +EVP_PKEY_assign_POLY1305(3) +EVP_MD_nid(3) +EVP_MD_name(3) +EVP_CIPHER_name(3) +EVP_ENCODE_LENGTH(3) +EVP_DECODE_LENGTH(3) +BIO_set_md_ctx(3) +EVP_add_cipher_alias(3) +EVP_add_digest_alias(3) +EVP_delete_cipher_alias(3) +EVP_delete_digest_alias(3) +EVP_MD_CTX_create(3) +EVP_MD_CTX_init(3) +EVP_MD_CTX_destroy(3) +EVP_CIPHER_CTX_init(3) +EVP_CIPHER_CTX_cleanup(3) +OPENSSL_add_all_algorithms_conf(3) +OPENSSL_add_all_algorithms_noconf(3) +LHASH_HASH_FN(3) +LHASH_COMP_FN(3) +LHASH_DOALL_ARG_FN(3) +LHASH_OF(3) +DEFINE_LHASH_OF(3) +int_implement_lhash_doall(3) +OBJ_create_and_add_object(3) +OBJ_bsearch(3) +OBJ_bsearch_ex(3) +PEM_read_bio_OCSP_REQUEST(3) +PEM_read_bio_OCSP_RESPONSE(3) +PEM_write_bio_OCSP_REQUEST(3) +PEM_write_bio_OCSP_RESPONSE(3) +ASN1_BIT_STRING_digest(3) +OCSP_CERTSTATUS_dup(3) +PKCS7_get_signed_attributes(3) +PKCS7_get_attributes(3) +PKCS7_type_is_signed(3) +PKCS7_type_is_encrypted(3) +PKCS7_type_is_enveloped(3) +PKCS7_type_is_signedAndEnveloped(3) +PKCS7_type_is_data(3) +PKCS7_type_is_digest(3) +PKCS7_set_detached(3) +PKCS7_get_detached(3) +PKCS7_is_detached(3) +EVP_PKEY_CTX_get_rsa_padding(3) +EVP_PKEY_CTX_get_rsa_pss_saltlen(3) +EVP_PKEY_CTX_set_rsa_keygen_primes(3) +EVP_PKEY_CTX_set_rsa_mgf1_md(3) +EVP_PKEY_CTX_set_rsa_oaep_md(3) +EVP_PKEY_CTX_get_rsa_mgf1_md(3) +EVP_PKEY_CTX_get_rsa_oaep_md(3) +EVP_PKEY_CTX_set0_rsa_oaep_label(3) +EVP_PKEY_CTX_get0_rsa_oaep_label(3) +RSA_set_app_data(3) +RSA_get_app_data(3) +STACK_OF(3) +SKM_DEFINE_STACK_OF(3) +U64(3) +U64(3) +U64(3) +SSL_set_mtu(3) +DTLS_set_link_mtu(3) +DTLS_get_link_min_mtu(3) +SSL_heartbeat(3) +SSL_CTX_set_cert_flags(3) +SSL_set_cert_flags(3) +SSL_CTX_clear_cert_flags(3) +SSL_clear_cert_flags(3) +SSL_set_app_data(3) +SSL_get_app_data(3) +SSL_SESSION_set_app_data(3) +SSL_SESSION_get_app_data(3) +SSL_CTX_get_app_data(3) +SSL_CTX_set_app_data(3) +SSLeay_add_ssl_algorithms(3) +DTLSv1_get_timeout(3) +DTLSv1_handle_timeout(3) +SSL_num_renegotiations(3) +SSL_clear_num_renegotiations(3) +SSL_total_renegotiations(3) +SSL_CTX_set_tmp_ecdh(3) +SSL_set_tmp_ecdh(3) +SSL_CTX_get_extra_chain_certs(3) +SSL_CTX_get_extra_chain_certs_only(3) +SSL_get0_certificate_types(3) +SSL_CTX_set1_client_certificate_types(3) +SSL_set1_client_certificate_types(3) +SSL_get0_raw_cipherlist(3) +SSL_get0_ec_point_formats(3) +SSL_CTX_need_tmp_RSA(3) +SSL_CTX_set_tmp_rsa(3) +SSL_need_tmp_RSA(3) +SSL_set_tmp_rsa(3) +SSL_CTX_set_ecdh_auto(3) +SSL_set_ecdh_auto(3) +SSL_CTX_set_tmp_rsa_callback(3) +SSL_set_tmp_rsa_callback(3) +SSL_get_ex_new_index(3) +SSL_SESSION_get_ex_new_index(3) +SSL_CTX_get_ex_new_index(3) +SSL_CTX_set_default_read_ahead(3) +SSL_cache_hit(3) +TLS1_get_version(3) +TLS1_get_client_version(3) +SSL_set_tlsext_debug_callback(3) +SSL_set_tlsext_debug_arg(3) +SSL_get_tlsext_status_exts(3) +SSL_set_tlsext_status_exts(3) +SSL_get_tlsext_status_ids(3) +SSL_set_tlsext_status_ids(3) +SSL_CTX_get_tlsext_ticket_keys(3) +SSL_CTX_set_tlsext_ticket_keys(3) +SSL_get_dtlsext_heartbeat_pending(3) +SSL_set_dtlsext_heartbeat_no_requests(3) +SSL_get_tlsext_heartbeat_pending(3) +SSL_set_tlsext_heartbeat_no_requests(3) +UI_set_app_data(3) +UI_get_app_data(3) +X509_extract_key(3) +X509_REQ_extract_key(3) +X509_name_cmp(3) +X509_STORE_CTX_set_app_data(3) +X509_STORE_CTX_get_app_data(3) +X509_LOOKUP_load_file(3) +X509_LOOKUP_add_dir(3) +X509V3_conf_err(3) +X509V3_set_ctx_test(3) +X509V3_set_ctx_nodb(3) +EXT_BITSTRING(3) +EXT_IA5STRING(3) diff --git a/util/missingssl.txt b/util/missingssl.txt index 0ab346fe57..8da9842a0b 100644 --- a/util/missingssl.txt +++ b/util/missingssl.txt @@ -25,5 +25,7 @@ SSL_get_peer_finished(3) SSL_set_SSL_CTX(3) SSL_set_debug(3) SSL_set_not_resumable_session_callback(3) +SSL_set_session_ticket_ext(3) +SSL_set_session_ticket_ext_cb(3) SSL_srp_server_param_with_username(3) SSL_test_functions(3) diff --git a/util/missingssl111.txt b/util/missingssl111.txt new file mode 100644 index 0000000000..da92e87737 --- /dev/null +++ b/util/missingssl111.txt @@ -0,0 +1,58 @@ +# A list of libssl functions that are known to be missing documentation as +# used by the find-doc-nits -v -o option. The list is as of commit 1708e3e85b +# (the release of 1.1.1). +ERR_load_SSL_strings(3) +SRP_Calc_A_param(3) +SSL_COMP_get_name(3) +SSL_COMP_set0_compression_methods(3) +SSL_CONF_CTX_finish(3) +SSL_CTX_SRP_CTX_free(3) +SSL_CTX_SRP_CTX_init(3) +SSL_CTX_get0_certificate(3) +SSL_CTX_get0_ctlog_store(3) +SSL_CTX_get0_privatekey(3) +SSL_CTX_get_ssl_method(3) +SSL_CTX_set0_ctlog_store(3) +SSL_CTX_set_client_cert_engine(3) +SSL_CTX_set_cookie_generate_cb(3) +SSL_CTX_set_cookie_verify_cb(3) +SSL_CTX_set_not_resumable_session_callback(3) +SSL_CTX_set_purpose(3) +SSL_CTX_set_srp_cb_arg(3) +SSL_CTX_set_srp_client_pwd_callback(3) +SSL_CTX_set_srp_password(3) +SSL_CTX_set_srp_strength(3) +SSL_CTX_set_srp_username(3) +SSL_CTX_set_srp_username_callback(3) +SSL_CTX_set_srp_verify_param_callback(3) +SSL_CTX_set_trust(3) +SSL_SRP_CTX_free(3) +SSL_SRP_CTX_init(3) +SSL_add_ssl_module(3) +SSL_certs_clear(3) +SSL_copy_session_id(3) +SSL_dup_CA_list(3) +SSL_get0_dane(3) +SSL_get_certificate(3) +SSL_get_current_compression(3) +SSL_get_current_expansion(3) +SSL_get_finished(3) +SSL_get_peer_finished(3) +SSL_get_privatekey(3) +SSL_get_srp_N(3) +SSL_get_srp_g(3) +SSL_get_srp_userinfo(3) +SSL_get_srp_username(3) +SSL_set_SSL_CTX(3) +SSL_set_debug(3) +SSL_set_not_resumable_session_callback(3) +SSL_set_purpose(3) +SSL_set_session_secret_cb(3) +SSL_set_session_ticket_ext(3) +SSL_set_session_ticket_ext_cb(3) +SSL_set_srp_server_param(3) +SSL_set_srp_server_param_pw(3) +SSL_set_trust(3) +SSL_srp_server_param_with_username(3) +SSL_test_functions(3) +SSL_trace(3) diff --git a/util/mkerr.pl b/util/mkerr.pl index e2479e727b..803a3efc83 100755 --- a/util/mkerr.pl +++ b/util/mkerr.pl @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 1999-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 1999-2024 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -339,21 +339,21 @@ foreach my $lib ( keys %errorfile ) { */ #ifndef $guard -#define $guard -#pragma once +# define $guard +# pragma once -#include -#include +# include +# include -#ifdef __cplusplus +# ifdef __cplusplus extern \"C\" { -#endif +# endif EOF $indent = ' '; if ($disablable) { print OUT <<"EOF"; -#ifndef OPENSSL_NO_${lib} +# ifndef OPENSSL_NO_${lib} EOF $indent = " "; @@ -380,7 +380,7 @@ EOF $rassigned{$lib} .= "$findcode:"; print STDERR "New Reason code $i\n" if $debug; } - printf OUT "#define $i $rcodes{$i}\n"; + printf OUT "#${indent}define $i%s $rcodes{$i}\n", " " x $z; } print OUT "\n"; } @@ -389,14 +389,14 @@ EOF # brace for 'extern "C" {'. while (length($indent) > 1) { $indent = substr $indent, 0, -1; - print OUT "#endif\n"; + print OUT "#${indent}endif\n"; } print OUT <<"EOF"; -#ifdef __cplusplus +# ifdef __cplusplus } -#endif +# endif #endif EOF close OUT; @@ -408,8 +408,8 @@ EOF my $extra_include = $internal ? ($lib ne 'SSL' - ? "#include \n" - : "#include \n") + ? "# include \n" + : "# include \n") : ''; my $hfile = $hpubinc{$lib}; my $guard = $hfile; @@ -430,43 +430,46 @@ EOF */ #ifndef $guard -#define $guard -#pragma once +# define $guard +# pragma once -#include -#include +# include +# include $extra_include + EOF $indent = ' '; if ( $internal ) { if ($disablable) { print OUT <<"EOF"; -#ifndef OPENSSL_NO_${lib} +# ifndef OPENSSL_NO_${lib} + EOF $indent .= ' '; } } else { print OUT <<"EOF"; -#define ${lib}err(f, r) ERR_${lib}_error(0, (r), OPENSSL_FILE, OPENSSL_LINE) -#define ERR_R_${lib}_LIB ERR_${lib}_lib() +# define ${lib}err(f, r) ERR_${lib}_error(0, (r), OPENSSL_FILE, OPENSSL_LINE) +# define ERR_R_${lib}_LIB ERR_${lib}_lib() + EOF if ( ! $static ) { print OUT <<"EOF"; -#ifdef __cplusplus +# ifdef __cplusplus extern \"C\" { -#endif +# endif int ERR_load_${lib}_strings(void); void ERR_unload_${lib}_strings(void); void ERR_${lib}_error(int function, int reason, const char *file, int line); -#ifdef __cplusplus +# ifdef __cplusplus } -#endif +# endif EOF } } - print OUT "/*\n * $lib reason codes.\n */\n"; + print OUT "\n/*\n * $lib reason codes.\n */\n"; foreach my $i ( @reasons ) { my $z = 48 - length($i); $z = 0 if $z < 0; @@ -481,13 +484,13 @@ EOF $rassigned{$lib} .= "$findcode:"; print STDERR "New Reason code $i\n" if $debug; } - printf OUT "#define $i $rcodes{$i}\n"; + printf OUT "#${indent}define $i%s $rcodes{$i}\n", " " x $z; } print OUT "\n"; while (length($indent) > 0) { $indent = substr $indent, 0, -1; - print OUT "#endif\n"; + print OUT "#${indent}endif\n"; } close OUT; } @@ -547,7 +550,7 @@ EOF } } print OUT <<"EOF"; -#ifndef OPENSSL_NO_ERR +#${indent}ifndef OPENSSL_NO_ERR static ${const}ERR_STRING_DATA ${lib}_str_reasons[] = { EOF @@ -565,26 +568,26 @@ EOF $strings{$i} = $rn; } my $lines; - $lines = " { ERR_PACK($pack_lib, 0, $i), \"$rn\" },"; - $lines = " { ERR_PACK($pack_lib, 0, $i),\n \"$rn\" }," - if length($lines) > 82; + $lines = " {ERR_PACK($pack_lib, 0, $i), \"$rn\"},"; + $lines = " {ERR_PACK($pack_lib, 0, $i),\n \"$rn\"}," + if length($lines) > 80; print OUT "$lines\n"; } print OUT <<"EOF"; - { 0, NULL } + {0, NULL} }; -#endif +#${indent}endif EOF if ( $internal ) { print OUT <<"EOF"; int ossl_err_load_${lib}_strings(void) { -#ifndef OPENSSL_NO_ERR +#${indent}ifndef OPENSSL_NO_ERR if (ERR_reason_error_string(${lib}_str_reasons[0].error) == NULL) ERR_load_strings_const(${lib}_str_reasons); -#endif +#${indent}endif return 1; } EOF @@ -639,7 +642,7 @@ EOF while (length($indent) > 1) { $indent = substr $indent, 0, -1; - print OUT "#endif\n"; + print OUT "#${indent}endif\n"; } if ($internal && $disablable) { print OUT <<"EOF"; diff --git a/util/mkinstallvars.pl b/util/mkinstallvars.pl index 09924901ce..10fd868b18 100644 --- a/util/mkinstallvars.pl +++ b/util/mkinstallvars.pl @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -19,8 +19,6 @@ use File::Spec; #use List::Util qw(pairs); sub _pairs (@); -my $debug = $ENV{OPENSSL_MKINSTALLVARS_DEBUG} || 0; - # These are expected to be set up as absolute directories my @absolutes = qw(PREFIX libdir); # These may be absolute directories, and if not, they are expected to be set up @@ -31,13 +29,13 @@ my @subdirs = _pairs (PREFIX => [ qw(BINDIR LIBDIR INCLUDEDIR APPLINKDIR) ], LIBDIR => [ qw(MODULESDIR PKGCONFIGDIR CMAKECONFIGDIR) ]); # For completeness, other expected variables -my @others = qw(COMMENT VERSION LDLIBS); +my @others = qw(VERSION LDLIBS); my %all = ( ); foreach (@absolutes) { $all{$_} = 1 } foreach (@subdirs) { foreach (@{$_->[1]}) { $all{$_} = 1 } } foreach (@others) { $all{$_} = 1 } -print STDERR "DEBUG: all keys: ", join(", ", sort keys %all), "\n" if $debug; +print STDERR "DEBUG: all keys: ", join(", ", sort keys %all), "\n"; my %keys = (); my %values = (); @@ -47,17 +45,6 @@ foreach (@ARGV) { push @{$values{$k}}, $v; } -# special case for LIBDIR vs libdir. -# For installations, They both get their value from ./Configure's --libdir or -# corresponding config target attribute, but LIBDIR only gets a value if the -# configuration is a relative path, while libdir always gets a value, so if -# the former doesn't have a value, we give it the latter's value, and rely -# on mechanisms further down to do the rest of the processing. -# If they're both empty, it's still fine. -print STDERR "DEBUG: LIBDIR = $values{LIBDIR}->[0], libdir = $values{libdir}->[0] => " if $debug; -$values{LIBDIR}->[0] = $values{libdir}->[0] unless $values{LIBDIR}->[0]; -print STDERR "LIBDIR = $values{LIBDIR}->[0]\n" if $debug; - # warn if there are missing values, and also if there are unexpected values foreach my $k (sort keys %all) { warn "No value given for $k\n" unless $keys{$k}; @@ -71,10 +58,10 @@ foreach my $k (sort keys %keys) { foreach my $k (@absolutes) { my $v = $values{$k} || [ '.' ]; die "Can't have more than one $k\n" if scalar @$v > 1; - print STDERR "DEBUG: $k = $v->[0] => " if $debug; + print STDERR "DEBUG: $k = $v->[0] => "; $v = [ map { File::Spec->rel2abs($_) } @$v ]; $values{$k} = $v; - print STDERR "$k = $v->[0]\n" if $debug; + print STDERR "$k = $v->[0]\n"; } # Absolute paths for the subdir variables are computed. This provides @@ -92,7 +79,7 @@ foreach my $pair (@subdirs) { $values{$k} = []; # We're rebuilding it print STDERR "DEBUG: $k = ", (scalar @$v2 > 1 ? "[ " . join(", ", @$v2) . " ]" : $v2->[0]), - " => " if $debug; + " => "; foreach my $v (@$v2) { if (File::Spec->file_name_is_absolute($v)) { push @{$values{$k}}, $v; @@ -111,7 +98,7 @@ foreach my $pair (@subdirs) { ? "[ " . join(", ", @$v) . " ]" : $v->[0]); } ($k, $kr)), - "\n" if $debug; + "\n"; } } @@ -137,10 +124,9 @@ foreach my $pair (@subdirs) { } print <<_____; - \$COMMENT \$VERSION \@LDLIBS + \$VERSION \@LDLIBS ); -our \$COMMENT = '$values{COMMENT}->[0]'; _____ foreach my $k (@absolutes) { diff --git a/util/mkwraps.pl b/util/mkwraps.pl deleted file mode 100755 index 91a44cbb3f..0000000000 --- a/util/mkwraps.pl +++ /dev/null @@ -1,592 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -use strict; -use warnings; - -use Getopt::Long; -use File::Spec::Functions qw(catdir catfile file_name_is_absolute rel2abs); -use File::Basename qw(dirname); - -my $build_info_file; -my $target; -my @extra_includes; -my $output_file; -my $mode = 'both'; -my $cc; -my $use_system = 1; -my $verbose = 0; -my $help = 0; - -GetOptions('build-info=s' => \$build_info_file, - 'target=s' => \$target, - 'include=s' => \@extra_includes, - 'output=s' => \$output_file, - 'mode=s' => \$mode, - 'cc=s' => \$cc, - 'system!' => \$use_system, - 'verbose' => \$verbose, - 'help' => \$help) - or die "Error in command line arguments\n"; - -$cc = $ENV{CC} || 'cc' unless defined $cc; - -sub help -{ - print STDERR <<"EOF"; -mkwraps.pl [options] - -Options: - - --build-info FILE build.info file containing a WRAP[] entry. - - --target NAME Test program name used as the WRAP[]/INCLUDE[] key. - - --include DIR Extra include directory to search. Cumulative. - - --output FILE Output file. Defaults to stdout. - - --mode MODE What to emit: 'wraps', 'expects' or 'both'. - Defaults to 'both'. - - --cc NAME C compiler used to discover the default system - include search paths. Defaults to \$CC or 'cc'. - - --no-system Do not fall back to the compiler's default system - include directories. By default, functions not - found in the project headers (typically libc/POSIX - functions) are looked up there. - - --verbose Print progress to stderr. - - --help Show this help text. - -For each function name listed in WRAP[], the script searches -the headers (*.h) under each directory in INCLUDE[], resolved -relative to the directory containing the build.info file, plus any -extra --include directories. The search recurses into subdirectories, -mirroring how the compiler resolves via -I flags. -The first header containing a matching declaration provides the -prototype. - -Functions not found in those directories (typically system functions -such as read() or socket()) are then looked up under the compiler's -default include search paths, as reported by the C compiler. System -prototypes are emitted with angle-bracket #include directives. Use ---no-system to disable this fallback. - -The output is meant as a stub for further editing. Custom logic -(out-parameters, variadic forwarding, side effects on globals) still -needs to be written manually, and the emitted #include directives may -need to be adjusted (e.g. to add internal headers for opaque types). -Long lines in the output are not wrapped. -EOF -} - -if ($help) { - &help(); - exit 0; -} - -unless (defined $build_info_file && defined $target) { - &help(); - exit 1; -} - -die "--mode must be 'wraps', 'expects' or 'both'\n" - unless $mode =~ /^(?:wraps|expects|both)$/; - -my @t = localtime(); -my $YEAR = $t[5] + 1900; - -# Parse the build.info file. We are only interested in two directives, -# WRAP[] and INCLUDE[], either of which may be split -# across several physical lines using the usual backslash continuation. - -my @wraps; -my @includes; - -open(IN, "<$build_info_file") || die "Can't open $build_info_file, $!,"; -my $content = do { local $/; }; -close IN; - -$content =~ s/\\\n\s*/ /g; - -foreach (split /\n/, $content) { - next if /^\s*#/ || /^\s*$/; - if (/^\s*WRAP\[\Q$target\E\]\s*=\s*(.+?)\s*$/) { - push @wraps, split(/\s+/, $1); - } elsif (/^\s*INCLUDE\[\Q$target\E\]\s*=\s*(.+?)\s*$/) { - push @includes, split(/\s+/, $1); - } -} - -die "No WRAP[$target] entry found in $build_info_file\n" unless @wraps; - -my $bi_dir = dirname($build_info_file); -my @search_dirs; -foreach my $inc (@includes, @extra_includes) { - push @search_dirs, - file_name_is_absolute($inc) ? $inc : rel2abs(catdir($bi_dir, $inc)); -} - -print STDERR "Wraps:\n ", join("\n ", @wraps), "\n" if $verbose; -print STDERR "Search dirs:\n ", join("\n ", @search_dirs), "\n" if $verbose; - -# Walk all search directories and get them in the order that level ones are -# first followed by subdirs so if there are nested includes, we get the -# shortest ones first searched. Each base is a [dir, is_system] pair and the -# is_system flag is carried onto every header found beneath it, so that system -# prototypes can later be emitted with angle-bracket includes. -sub find_headers -{ - my (@bases) = @_; - my @found; - my @queue = map { [$_->[0], '', $_->[1]] } @bases; - - while (@queue) { - my @next; - my @level_files; - foreach my $entry (@queue) { - my ($dir, $rel, $sys) = @$entry; - next unless -d $dir; - opendir(my $dh, $dir) or next; - foreach my $name (readdir $dh) { - next if $name =~ /^\./; - my $full = catfile($dir, $name); - my $newrel = $rel eq '' ? $name : "$rel/$name"; - if (-d $full) { - push @next, [$full, $newrel, $sys]; - } elsif (-f $full && $name =~ /\.h$/) { - push @level_files, [$full, $newrel, $sys]; - } - } - closedir $dh; - } - # Stable sort within a level for deterministic ordering. - push @found, sort { $a->[1] cmp $b->[1] } @level_files; - @queue = sort { $a->[1] cmp $b->[1] } @next; - } - return @found; -} - -# Ask the C compiler for its default "#include <...>" search paths. Returns -# the list of existing directories, in search order. Empty on failure. -sub system_include_dirs -{ - my ($compiler) = @_; - my $out = `$compiler -xc -E -v /dev/null 2>&1`; - return () unless defined $out - && $out =~ /search starts here:(.*?)End of search list\./s; - my @dirs; - foreach my $line (split /\n/, $1) { - $line =~ s/^\s+//; - $line =~ s/\s+$//; - # clang annotates framework directories; skip those. - next if $line eq '' || $line =~ /\(framework directory\)$/; - push @dirs, $line if -d $line; - } - return @dirs; -} - -# Project headers are searched first (with is_system = 0) so that a project -# declaration always wins over a colliding system one. The system headers are -# appended lazily, only if some function is not found in the project headers. -my @search_files = find_headers(map { [$_, 0] } @search_dirs); -my $system_loaded = 0; - -sub load_system_headers -{ - return if $system_loaded; - $system_loaded = 1; - return unless $use_system; - my @sys_dirs = system_include_dirs($cc); - unless (@sys_dirs) { - warn "WARNING: could not determine system include dirs from '$cc'\n"; - return; - } - print STDERR "System include dirs:\n ", join("\n ", @sys_dirs), "\n" - if $verbose; - push @search_files, find_headers(map { [$_, 1] } @sys_dirs); -} - -my %file_cache; - -sub strip_c_comments -{ - my $s = shift; - $s =~ s{/\*.*?\*/}{}sg; - $s =~ s{//[^\n]*}{}g; - return $s; -} - -# Drop attribute and qualifier macros that should not appear in the -# emitted return type. -sub strip_attribute_macros -{ - my $s = shift; - foreach my $kw (qw(__owur __pure __malloc__ ossl_inline static inline - extern OSSL_DEPRECATEDIN_0_9_8 - OSSL_DEPRECATEDIN_1_0_0 OSSL_DEPRECATEDIN_1_1_0 - OSSL_DEPRECATEDIN_3_0 OSSL_DEPRECATEDIN_3_1 - OSSL_DEPRECATEDIN_3_2 OSSL_DEPRECATEDIN_3_3 - OSSL_DEPRECATEDIN_3_4 OSSL_DEPRECATEDIN_3_5)) { - $s =~ s/\b\Q$kw\E\b//g; - } - $s =~ s/\b__attribute__\s*\(\([^)]*\)\)//g; - $s =~ s/\s+/ /g; - $s =~ s/^\s+|\s+$//g; - return $s; -} - -# Consume reserved-namespace decorations between a declaration's closing -# parenthesis and its semicolon, e.g. glibc's __THROW, __wur or -# __attr_access ((...)). Only __-prefixed tokens (with an optional balanced -# argument list) are eaten, so a genuine following declaration is left alone. -sub skip_trailing_attributes -{ - my $s = shift; - while (1) { - $s =~ s/^\s+//; - last unless $s =~ /^(__\w+)/; - $s = substr($s, length($1)); - $s =~ s/^\s+//; - if ($s =~ /^\(/) { - my $depth = 0; - my $i = 0; - while ($i < length($s)) { - my $c = substr($s, $i, 1); - $depth++ if $c eq '('; - $depth-- if $c eq ')'; - $i++; - last if $depth == 0; - } - return $s if $depth != 0; - $s = substr($s, $i); - } - } - return $s; -} - -sub find_function_decl -{ - my ($funcname) = @_; - - foreach my $entry (@search_files) { - my ($file, $relpath, $is_system) = @$entry; - unless (exists $file_cache{$file}) { - my $text = ''; - if (open(my $fh, '<', $file)) { - local $/; - $text = <$fh>; - close $fh; - } - $file_cache{$file} = strip_c_comments($text); - } - my $text = $file_cache{$file}; - - while ($text =~ /\b\Q$funcname\E\s*\(/g) { - my $name_start = $-[0]; - my $paren_start = pos($text); - - # Find matching closing paren, respecting nesting. - my $depth = 1; - my $cursor = $paren_start; - while ($cursor < length($text) && $depth > 0) { - my $c = substr($text, $cursor, 1); - $depth++ if $c eq '('; - $depth-- if $c eq ')'; - $cursor++; - } - next if $depth != 0; - my $params_str = - substr($text, $paren_start, $cursor - $paren_start - 1); - - # What follows must be ; for this to be a declaration, possibly - # after trailing attribute macros (__THROW, __wur, ...). - my $after = substr($text, $cursor); - $after = skip_trailing_attributes($after); - next unless $after =~ /^;/; - - # Anything since the previous statement terminator is the return - # type expression. - my $pre = substr($text, 0, $name_start); - $pre =~ s/\s+$//; - my $ret_start = 0; - $ret_start = $-[2] if $pre =~ /([;}\n])([^;}\n]*)$/s; - my $rettype = strip_attribute_macros(substr($pre, $ret_start)); - - # Normalise to forward slashes for use as an #include path. - my $include_path = $relpath; - $include_path =~ s|\\|/|g; - - return { name => $funcname, - rettype => $rettype, - params => $params_str, - file => $file, - include_path => $include_path, - system => $is_system }; - } - } - return undef; -} - -# Split a parameter list on top-level commas, respecting parentheses -sub split_params -{ - my $str = shift; - $str =~ s/^\s+|\s+$//g; - return () if $str eq '' || $str eq 'void'; - - my @parts; - my $current = ''; - my $depth = 0; - foreach my $c (split //, $str) { - if ($c eq '(') { - $depth++; - $current .= $c; - } elsif ($c eq ')') { - $depth--; - $current .= $c; - } elsif ($c eq ',' && $depth == 0) { - push @parts, $current; - $current = ''; - } else { - $current .= $c; - } - } - push @parts, $current if $current ne ''; - foreach my $p (@parts) { - $p =~ s/^\s+|\s+$//g; - } - return @parts; -} - -sub parse_param -{ - my $param = shift; - return { type => '', name => '', is_variadic => 1, is_ptr => 0 } - if $param eq '...'; - - # Drop the restrict qualifier; it plays no role in a mock signature. - $param =~ s/\b(?:__restrict(?:__)?|restrict)\b//g; - - # Reduce TYPE NAME[size] to TYPE * NAME for our purposes. - my $is_array = 0; - $is_array = 1 if $param =~ s/\[\s*[^\]]*\s*\]\s*$//; - - my ($type, $name); - if ($param =~ /^(.*?)([A-Za-z_]\w*)\s*$/) { - $type = $1; - $name = $2; - $type =~ s/\s+$//; - } else { - $type = $param; - $name = ''; - } - - # System headers name parameters in the reserved __ namespace; strip the - # leading underscores so the generated wrap uses ordinary local names. - $name =~ s/^_+//; - - return { type => $type, - name => $name, - is_ptr => (($type =~ /\*/) || $is_array) ? 1 : 0, - is_variadic => 0, - is_array => $is_array }; -} - -sub is_void_type -{ - my $t = shift; - $t =~ s/^\s+|\s+$//g; - $t =~ s/\s+/ /g; - return $t eq 'void'; -} - -sub is_ptr_type { return $_[0] =~ /\*/; } - -# Look up each WRAP entry's signature. Functions we cannot find are -# skipped with a warning rather than aborting. -my @signatures; -my @found_includes; -my %seen_include; -foreach my $func (@wraps) { - my $info = find_function_decl($func); - if (!defined $info && !$system_loaded) { - # Not in the project headers: pull in the system ones and retry. - load_system_headers(); - $info = find_function_decl($func); - } - unless (defined $info) { - warn "WARNING: $func: declaration not found in any include dir\n"; - next; - } - - my @params = map { parse_param($_) } split_params($info->{params}); - - my $idx = 0; - foreach my $p (@params) { - next if $p->{is_variadic}; - $p->{name} = "arg$idx" if $p->{name} eq ''; - $idx++; - } - - push @signatures, { name => $func, - rettype => $info->{rettype}, - params => \@params }; - - unless ($seen_include{$info->{include_path}}) { - $seen_include{$info->{include_path}} = 1; - push @found_includes, { path => $info->{include_path}, - system => $info->{system} }; - } - print STDERR " found $func in $info->{file}\n" if $verbose; -} - -die "No declarations found, nothing to emit\n" unless @signatures; - -my $out_fh; -if (defined $output_file) { - open($out_fh, '>', $output_file) or die "$output_file: $!\n"; -} else { - $out_fh = \*STDOUT; -} - -print $out_fh <<"EOF"; -/* - * Copyright $YEAR The OpenSSL Project Authors. All Rights Reserved. - * - * Licensed under the Apache License 2.0 (the "License"). You may not use - * this file except in compliance with the License. You can obtain a copy - * in the file LICENSE in the source distribution or at - * https://www.openssl.org/source/license.html - */ - -EOF - -print $out_fh "#include \n"; -print $out_fh "\n"; -if (@found_includes) { - my @angle; - my @local; - foreach my $inc (sort { $a->{path} cmp $b->{path} } @found_includes) { - if ($inc->{system} || $inc->{path} =~ m|^openssl/|) { - push @angle, $inc->{path}; - } else { - push @local, $inc->{path}; - } - } - foreach my $inc (@angle) { - print $out_fh "#include <$inc>\n"; - } - print $out_fh "\n" if @angle && @local; - foreach my $inc (@local) { - print $out_fh "#include \"$inc\"\n"; - } - print $out_fh "\n"; -} - -if ($mode eq 'wraps' || $mode eq 'both') { - print $out_fh "/* wraps */\n\n"; - foreach my $f (@signatures) { - print $out_fh format_signature($f->{rettype}, - "__wrap_$f->{name}", - $f->{params}), ";\n"; - } - print $out_fh "\n"; - - foreach my $f (@signatures) { - emit_wrap($out_fh, $f); - print $out_fh "\n"; - } -} - -if ($mode eq 'expects' || $mode eq 'both') { - print $out_fh "/* expectations */\n\n"; - foreach my $f (@signatures) { - emit_expect($out_fh, $f); - print $out_fh "\n"; - } -} - -close $out_fh if defined $output_file; - -exit 0; - -sub format_decl -{ - my ($type, $name) = @_; - return $type =~ /\*$/ ? "$type$name" : "$type $name"; -} - -sub format_param -{ - my $p = shift; - return '...' if $p->{is_variadic}; - return format_decl($p->{type}, $p->{name}); -} - -sub format_signature -{ - my ($rettype, $name, $params) = @_; - my $param_str = @$params - ? join(', ', map { format_param($_) } @$params) - : 'void'; - return format_decl($rettype, $name) . "($param_str)"; -} - -sub emit_wrap -{ - my ($fh, $f) = @_; - print $fh format_signature($f->{rettype}, "__wrap_$f->{name}", - $f->{params}), "\n{\n"; - print $fh " function_called();\n"; - foreach my $p (@{$f->{params}}) { - next if $p->{is_variadic}; - if ($p->{is_ptr}) { - print $fh " check_expected_ptr($p->{name});\n"; - } else { - print $fh " check_expected($p->{name});\n"; - } - } - if ( ! is_void_type($f->{rettype})) { - if (is_ptr_type($f->{rettype})) { - print $fh "\n return mock_ptr_type($f->{rettype});\n"; - } else { - print $fh "\n return mock_type($f->{rettype});\n"; - } - } - print $fh "}\n"; -} - -sub emit_expect -{ - my ($fh, $f) = @_; - my $name = $f->{name}; - my @params = @{$f->{params}}; - - my @sig_parts; - foreach my $p (@params) { - next if $p->{is_variadic}; - push @sig_parts, format_param($p); - } - - my $needs_rc = !is_void_type($f->{rettype}); - push @sig_parts, format_decl($f->{rettype}, 'rc') if $needs_rc; - - my $param_str = @sig_parts ? join(', ', @sig_parts) : 'void'; - print $fh "static void expect_$name($param_str)\n{\n"; - print $fh " expect_function_call(__wrap_$name);\n"; - foreach my $p (@params) { - next if $p->{is_variadic}; - print $fh " expect_value(__wrap_$name, $p->{name}, $p->{name});\n"; - } - print $fh " will_return(__wrap_$name, rc);\n" if $needs_rc; - print $fh "}\n"; -} diff --git a/util/other.syms b/util/other.syms index 114e25a348..80488efa10 100644 --- a/util/other.syms +++ b/util/other.syms @@ -160,7 +160,6 @@ custom_ext_parse_cb datatype pem_password_cb datatype ssl_ct_validation_cb datatype tls_session_secret_cb_fn datatype -tls_session_ticket_ext_cb_fn datatype ASYNC_stack_alloc_fn datatype ASYNC_stack_free_fn datatype PKCS12_create_cb datatype @@ -221,8 +220,6 @@ BIO_get_conn_port define BIO_get_conn_ip_family define BIO_get_conn_mode define BIO_get_fd define -BIO_get_flags define -BIO_get_retry_flags define BIO_get_fp define BIO_get_indent define BIO_get_info_callback define @@ -257,12 +254,6 @@ BIO_set_conn_port define BIO_set_conn_ip_family define BIO_set_conn_mode define BIO_set_fd define -BIO_set_flags define -BIO_set_retry_read define -BIO_set_retry_write define -BIO_set_retry_special define -BIO_clear_flags define -BIO_clear_retry_flags define BIO_set_fp define BIO_set_indent define BIO_set_info_callback define @@ -314,7 +305,6 @@ ERR_raise define ERR_raise_data define EVP_DigestSignUpdate define EVP_DigestVerifyUpdate define -EVP_KDF_CTX_kdf define EVP_MD_CTX_get_block_size define EVP_MD_CTX_get0_name define EVP_MD_CTX_get_size define @@ -416,7 +406,6 @@ EVP_RSA_gen define EVP_seed_cfb define EVP_sm4_cfb define EXT_UTF8STRING define -FIPS_mode define OBJ_cleanup define deprecated 1.1.0 OCSP_parse_url define OCSP_REQ_CTX datatype deprecated 3.0.0 @@ -647,7 +636,6 @@ SSL_clear_mode define SSL_disable_ct define SSL_get0_chain_certs define SSL_get0_iana_groups define -SSL_get0_ec_point_formats define SSL_get0_session define SSL_get0_chain_cert_store define SSL_get0_verify_cert_store define @@ -801,12 +789,6 @@ SSL_VALUE_CLASS_FEATURE_REQUEST define SSL_VALUE_CLASS_FEATURE_PEER_REQUEST define SSL_VALUE_CLASS_FEATURE_NEGOTIATED define SSL_VALUE_QUIC_IDLE_TIMEOUT define -SSL_VALUE_QUIC_UDP_PAYLOAD_SIZE_MAX define -SSL_VALUE_QUIC_WINDOWCON define -SSL_VALUE_QUIC_WINDOWBSTR define -SSL_VALUE_QUIC_WINDOWUSTR define -SSL_VALUE_QUIC_ACK_DELAY_EXPONENT define -SSL_VALUE_QUIC_ACK_DELAY_MAX define SSL_VALUE_QUIC_STREAM_BIDI_LOCAL_AVAIL define SSL_VALUE_QUIC_STREAM_BIDI_REMOTE_AVAIL define SSL_VALUE_QUIC_STREAM_UNI_LOCAL_AVAIL define @@ -900,5 +882,3 @@ OPENSSL_load_u64_be inline OPENSSL_load_u64_le inline OPENSSL_store_u64_be inline OPENSSL_store_u64_le inline -OSSL_BEGIN_ALLOW_DEPRECATED define -OSSL_END_ALLOW_DEPRECATED define diff --git a/util/perl/OpenSSL/ParseC.pm b/util/perl/OpenSSL/ParseC.pm index 6249704a23..837559e1d0 100644 --- a/util/perl/OpenSSL/ParseC.pm +++ b/util/perl/OpenSSL/ParseC.pm @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2018-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2018-2024 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -62,7 +62,7 @@ my @opensslcpphandlers = ( ################################################################## # OpenSSL CPP specials # - # These are used to convert certain pre-processor expressions into + # These are used to convert certain pre-precessor expressions into # others that @cpphandlers have a better chance to understand. # This changes any OPENSSL_NO_DEPRECATED_x_y[_z] check to a check of @@ -73,22 +73,6 @@ my @opensslcpphandlers = ( massager => sub { return (<<"EOF"); #if$1 OPENSSL_NO_DEPRECATEDIN_$2 -EOF - } - }, - # Do the same for modern CPP definition tests. - { regexp => qr/#if (\!defined).*OPENSSL_NO_DEPRECATED_(\d+_\d+(?:_\d+)?).*$/, - massager => sub { - return (<<"EOF"); -#ifndef OPENSSL_NO_DEPRECATEDIN_$2 -EOF - } - }, - # Do the same for modern CPP definition tests. - { regexp => qr/#if (defined).*OPENSSL_NO_DEPRECATED_(\d+_\d+(?:_\d+)?).*$/, - massager => sub { - return (<<"EOF"); -#ifdef OPENSSL_NO_DEPRECATEDIN_$2 EOF } } @@ -480,15 +464,6 @@ int i2d_$2(void); int $2_free(void); int $2_new(void); DECLARE_ASN1_ITEM($2) -EOF - }, - }, - { regexp => qr/DECLARE_ASN1_ENCODE_FUNCTIONS_name_attr<<<\((.*),\s*(.*)\)>>>/, - massager => sub { - return (<<"EOF"); -int d2i_$2(void); -int i2d_$2(void); -DECLARE_ASN1_ITEM($2) EOF }, }, diff --git a/util/perl/OpenSSL/Test.pm b/util/perl/OpenSSL/Test.pm index 570d3a8631..a0396499a7 100644 --- a/util/perl/OpenSSL/Test.pm +++ b/util/perl/OpenSSL/Test.pm @@ -1,4 +1,4 @@ -# Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -73,7 +73,6 @@ use Cwd qw/getcwd abs_path/; use OpenSSL::Util; my $level = 0; -my $idx = 0; # The name of the test. This is set by setup() and is used in the other # functions to verify that setup() has been used. @@ -329,16 +328,8 @@ sub app { return sub { my @cmdargs = ( @{$cmd} ); my @prog = __fixup_prg(__apps_file(shift @cmdargs, __exeext())); - if (defined $ENV{OSSL_USE_VALGRIND}) { - $idx=$idx+1; - my $resultdir = result_dir(); - my $srcdir = srctop_dir(); - return cmd([ "valgrind", "--leak-check=full", "--show-leak-kinds=all", "--gen-suppressions=all", "--suppressions=$srcdir/util/valgrind.suppression", "--log-file=$resultdir/valgrind.log.$idx.%p", "--suppressions=$srcdir/util/valgrind.suppression", @prog, @cmdargs ], - exe_shell => $ENV{EXE_SHELL}, %opts) -> (shift); - } else { - return cmd([ @prog, @cmdargs ], - exe_shell => $ENV{EXE_SHELL}, %opts) -> (shift); - } + return cmd([ @prog, @cmdargs ], + exe_shell => $ENV{EXE_SHELL}, %opts) -> (shift); } } @@ -359,29 +350,8 @@ sub test { return sub { my @cmdargs = ( @{$cmd} ); my @prog = __fixup_prg(__test_file(shift @cmdargs, __exeext())); - if (defined $ENV{OSSL_USE_VALGRIND}) { - $idx=$idx+1; - my $resultdir = result_dir(); - my $srcdir = srctop_dir(); - return cmd([ "valgrind", "--leak-check=full", "--show-leak-kinds=all", "--gen-suppressions=all", "--suppressions=$srcdir/util/valgrind.suppression", "--log-file=$resultdir/valgrind.log.$idx.%p", "--suppressions=$srcdir/util/valgrind.suppression", @prog, @cmdargs ], + return cmd([ @prog, @cmdargs ], exe_shell => $ENV{EXE_SHELL}, %opts) -> (shift); - } elsif (defined $ENV{OSSL_VALGRIND_CT}) { - # Constant-time validation mode: mark secret data as undefined and - # fail immediately if any branch or memory index depends on it. - # Unlike OSSL_USE_VALGRIND this writes to stdout (not a log file) - # and uses --error-exitcode so the test fails on any CT violation. - # Set OSSL_VALGRIND_CT=yes when building with enable-ct-validation. - return cmd([ "valgrind", - "--tool=memcheck", - "--track-origins=yes", - "--error-exitcode=1", - "--num-callers=20", - @prog, @cmdargs ], - exe_shell => $ENV{EXE_SHELL}, %opts) -> (shift); - } else { - return cmd([ @prog, @cmdargs ], - exe_shell => $ENV{EXE_SHELL}, %opts) -> (shift); - } } } @@ -448,14 +418,6 @@ If used, B must be a reference to a scalar variable. It will be assigned a boolean indicating if the command succeeded or not. This is particularly useful together with B. -=item B 0|1> - -If true, suppress the diagnostic line that C normally prints to STDERR -after the command completes (the C exitcode> line) when running -under a non-verbose test harness. Has no effect outside a harness or under -C. Useful for loops that invoke many commands where that -line would be noise. - =back Usually 1 indicates that the command was successful and 0 indicates failure. @@ -530,20 +492,19 @@ sub run { ${$opts{statusvar}} = $r; } - my $harness_quiet = $ENV{HARNESS_ACTIVE} && !$ENV{HARNESS_VERBOSE}; + # Restore STDOUT / STDERR on VMS if ($^O eq 'VMS') { - # Restore STDOUT / STDERR on VMS - if ($harness_quiet) { + if ($ENV{HARNESS_ACTIVE} && !$ENV{HARNESS_VERBOSE}) { close STDOUT; close STDERR; open STDOUT, '>&', $save_STDOUT or die "Can't restore STDOUT: $!"; open STDERR, '>&', $save_STDERR or die "Can't restore STDERR: $!"; } - print STDERR "$prefix$display_cmd => $e\n" unless $harness_quiet; - } else { print STDERR "$prefix$display_cmd => $e\n" - unless $opts{quiet} && $harness_quiet; + if !$ENV{HARNESS_ACTIVE} || $ENV{HARNESS_VERBOSE}; + } else { + print STDERR "$prefix$display_cmd => $e\n"; } # At this point, $? stops being interesting, and unfortunately, diff --git a/util/perl/OpenSSL/config.pm b/util/perl/OpenSSL/config.pm index e9dc9d3243..c4e556a5bd 100755 --- a/util/perl/OpenSSL/config.pm +++ b/util/perl/OpenSSL/config.pm @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 1998-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 1998-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -145,6 +145,9 @@ my $guess_patterns = [ } ], [ 'Paragon.*?:.*', 'i860-intel-osf1' ], + [ 'Rhapsody:.*', 'ppc-apple-rhapsody' ], + [ 'Darwin:8.*?:.*?:Power.*', 'ppc-apple-darwin8' ], + [ 'Darwin:.*?:.*?:Power.*', 'ppc-apple-darwin' ], [ 'Darwin:.*', '${MACHINE}-apple-darwin' ], [ 'SunOS:5\..*', '${MACHINE}-whatever-solaris2' ], [ 'SunOS:.*', '${MACHINE}-sun-sunos4' ], @@ -411,7 +414,7 @@ sub determine_compiler_settings { $CCVER = 0; my $v = `cl 2>&1`; - if ( $v =~ /Microsoft .* Version ([0-9\.]+) for (x86|x64|ARM)/ ) { + if ( $v =~ /Microsoft .* Version ([0-9\.]+) for (x86|x64|ARM|ia64)/ ) { $CCVER = $1; $CL_ARCH = $2; } @@ -488,6 +491,55 @@ EOF return { target => "irix-mips3" }; } ], + [ 'ppc-apple-rhapsody', { target => "rhapsody-ppc" } ], + [ 'ppc-apple-darwin8.*', + sub { + my $KERNEL_BITS = $ENV{KERNEL_BITS} // ''; + my $ISA64 = `sysctl -n hw.optional.64bitops 2>/dev/null`; + if ( $ISA64 == 1 && $KERNEL_BITS eq '' ) { + print < "darwin8-ppc64-cc" } + if $ISA64 == 1 && $KERNEL_BITS eq '64'; + return { target => "darwin8-ppc-cc" }; + } + ], + [ 'ppc-apple-darwin.*', + sub { + my $KERNEL_BITS = $ENV{KERNEL_BITS} // ''; + my $ISA64 = `sysctl -n hw.optional.64bitops 2>/dev/null`; + if ( $ISA64 == 1 && $KERNEL_BITS eq '' ) { + print < "darwin64-ppc" } + if $ISA64 == 1 && $KERNEL_BITS eq '64'; + return { target => "darwin-ppc" }; + } + ], + [ 'i.86-apple-darwin.*', + sub { + my $KERNEL_BITS = $ENV{KERNEL_BITS} // ''; + my $ISA64 = `sysctl -n hw.optional.x86_64 2>/dev/null`; + if ( $ISA64 == 1 && $KERNEL_BITS eq '' ) { + print < "darwin64-x86_64" } + if $ISA64 == 1 && $KERNEL_BITS eq '64'; + return { target => "darwin-i386" }; + } + ], [ 'x86_64-apple-darwin.*', sub { my $KERNEL_BITS = $ENV{KERNEL_BITS} // ''; @@ -499,6 +551,13 @@ EOF return { target => "darwin64-x86_64" }; } } + return { target => "darwin-i386" } if $KERNEL_BITS eq '32'; + + print < "darwin64-x86_64" }; } ], @@ -898,7 +957,7 @@ EOF ], # Windows values found by looking at Perl 5's win32/win32.c - [ '(amd64|x86|ARM)-.*?-Windows NT', + [ '(amd64|ia64|x86|ARM)-.*?-Windows NT', sub { # If we determined the arch by asking cl, take that value, # otherwise the SYSTEM we got from from POSIX::uname(). @@ -907,6 +966,7 @@ EOF if ($arch) { $config = { 'amd64' => { target => 'VC-WIN64A' }, + 'ia64' => { target => 'VC-WIN64I' }, 'x86' => { target => 'VC-WIN32' }, 'x64' => { target => 'VC-WIN64A' }, 'ARM' => { target => 'VC-WIN64-ARM' }, diff --git a/util/perl/OpenSSL/fipsparams.pm b/util/perl/OpenSSL/fipsparams.pm deleted file mode 100755 index 38ba27b5b1..0000000000 --- a/util/perl/OpenSSL/fipsparams.pm +++ /dev/null @@ -1,183 +0,0 @@ -#! /usr/bin/env perl -# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). You may not use -# this file except in compliance with the License. You can obtain a copy -# in the file LICENSE in the source distribution or at -# https://www.openssl.org/source/license.html - -package OpenSSL::fipsparams; - -use strict; -use warnings; -use Exporter; - -our @ISA = qw(Exporter); -our @EXPORT_OK = qw(produce_fips_params); - -sub produce_fips_params { - my @params = @_; - my $s; - open(local *STDOUT, '>', \$s); - - print "/* Machine generated by util/perl/OpenSSL/fipsparams.pm */\n"; - print "\n"; - - print "#ifdef FIPSPARAMS_AS_HEADER\n"; - print "enum fips_config_id {\n"; - my $first = " = 1"; - foreach my $p (@params) { - my $name = $p->[1]; - my $use = $p->[4]; - if ($use eq 'indicator') { - print " FIPS_CONFIG_$name$first,\n"; - $first = ""; - } - } - print "};\n"; - - print "#else /* FIPSPARAMS_AS_HEADER */\n"; - print "\n"; - print "typedef struct fips_params_st {\n"; - foreach my $p (@params) { - my $field = $p->[0]; - my $type = $p->[2]; - my $sep = $type =~ /\*$/ ? "" : " "; - printf " $type$sep$field;\n"; - } - print "} FIPS_PARAMS;\n"; - - print "\n"; - print "static void init_fips_params(FIPS_PARAMS *fp)\n"; - print "{\n"; - foreach my $p (@params) { - my $field = $p->[0]; - my $default = $p->[3]; - printf " fp->$field = $default;\n"; - } - print "}\n"; - - print "\n"; - print "/*\n"; - print " * Parameters to retrieve from the core provider\n"; - print " * NOTE: inside core_get_params() these will be loaded from config items\n"; - print " * stored inside prov->parameters\n"; - print " */\n"; - print "static int fips_get_params_from_core(\n"; - print " const OSSL_CORE_HANDLE *handle, FIPS_PARAMS *fp)\n"; - print "{\n"; - foreach my $p (@params) { - my $field = $p->[0]; - print " const char *$field = NULL;\n"; - } - print " OSSL_PARAM core_params[] = {\n"; - foreach my $p (@params) { - my $field = $p->[0]; - my $name = $p->[1]; - my $type = $p->[2]; - my $use = $p->[4]; - if ($use eq 'indicator') { - $name = "OSSL_PROV_PARAM_" . $name; - } - print " OSSL_PARAM_construct_utf8_ptr($name,\n"; - print " (char **)&$field, 0),\n"; - } - print " OSSL_PARAM_construct_end()\n"; - print " };\n"; - print " OSSL_PARAM *p = core_params;\n"; - print "\n"; - print " if (!c_get_params(handle, core_params)) {\n"; - print " return 0;\n"; - print " }\n"; - print "\n"; - print " for (;p->key != NULL; p++) {\n"; - print " if (OSSL_PARAM_modified(p)) {\n"; - foreach my $p (@params) { - my $field = $p->[0]; - my $name = $p->[1]; - my $type = $p->[2]; - my $use = $p->[4]; - if ($use eq 'indicator') { - $name = "OSSL_PROV_PARAM_" . $name; - } - print " if (strcmp($name, p->key) == 0) {\n"; - if ($type eq 'const char *') { - print " fp->$field = $field;\n"; - } elsif ($type eq 'unsigned char') { - print " if ($field != NULL\n"; - print " && strcmp($field, \"1\") == 0)\n"; - print " fp->$field = 1;\n"; - print " else if ($field != NULL\n"; - print " && strcmp($field, \"0\") == 0)\n"; - print " fp->$field = 0;\n"; - print " else\n"; - print " return 0;\n"; - } - print " }\n"; - } - print " }\n"; - print " }\n"; - print " return 1;\n"; - print "}\n"; - - print "\n"; - print "#define OSSL_FIPS_PARAMS_DEFN_TYPES \\\n"; - my $cnt = 0; - my $sep = ""; - foreach my $p (@params) { - my $use = $p->[4]; - if ($use eq 'indicator') { - my $name = "OSSL_PROV_PARAM_" . $p->[1]; - print "$sep OSSL_PARAM_DEFN($name, OSSL_PARAM_INTEGER, NULL, 0)"; - $sep = ", \\\n"; - } - } - print "\n"; - - print "\n"; - print "static int return_fips_params(OSSL_PARAM *params, FIPS_PARAMS *fp)\n"; - print "{\n"; - print " OSSL_PARAM *p = params;\n"; - print "\n"; - print " for (;p->key != NULL; p++) {\n"; - foreach my $p (@params) { - my $field = $p->[0]; - my $use = $p->[4]; - if ($use eq 'indicator') { - my $name = "OSSL_PROV_PARAM_" . $p->[1]; - print " if (strcmp($name, p->key) == 0)\n"; - print " if (!OSSL_PARAM_set_int(p, fp->$field))\n"; - print " return 0;\n"; - } - } - print " }\n"; - print " return 1;\n"; - print "}\n"; - - print "\n"; - print "struct fips_global_st;\n"; - print "static FIPS_PARAMS *get_fips_params(struct fips_global_st *fgbl);\n"; - print "int ossl_fips_config(OSSL_LIB_CTX *libctx, enum fips_config_id id)\n"; - print "{\n"; - print " struct fips_global_st *fgbl = ossl_lib_ctx_get_data(libctx, OSSL_LIB_CTX_FIPS_PROV_INDEX);\n"; - print " FIPS_PARAMS *params = get_fips_params(fgbl);\n"; - print " switch (id) {\n"; - foreach my $p (@params) { - my $field = $p->[0]; - my $use = $p->[4]; - if ($use eq 'indicator') { - my $id = "FIPS_CONFIG_" . $p->[1]; - print " case $id:\n"; - print " return params->$field;\n"; - } - } - print " default:\n"; - print " return -1;\n"; - print " }\n"; - print "}\n"; - - print "\n"; - print "#endif /* FIPSPARAMS_AS_HEADER */\n"; - - return $s; -} diff --git a/util/perl/OpenSSL/paramnames.pm b/util/perl/OpenSSL/paramnames.pm index 328189c7b3..24c339c944 100644 --- a/util/perl/OpenSSL/paramnames.pm +++ b/util/perl/OpenSSL/paramnames.pm @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2023-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -14,8 +14,7 @@ use warnings; require Exporter; our @ISA = qw(Exporter); our @EXPORT_OK = qw(generate_public_macros - produce_param_decoder - produce_param_decoder_with_count); + produce_param_decoder); my $case_sensitive = 1; my $need_break = 0; @@ -173,15 +172,6 @@ my %params = ( 'OSSL_DIGEST_PARAM_SIZE' => "size", # size_t 'OSSL_DIGEST_PARAM_XOF' => "xof", # int, 0 or 1 'OSSL_DIGEST_PARAM_ALGID_ABSENT' => "algid-absent", # int, 0 or 1 - 'OSSL_DIGEST_PARAM_FUNCTION_NAME' => "function-name", # utf8 string - 'OSSL_DIGEST_PARAM_CUSTOMIZATION' => "customization", # utf8 string - 'OSSL_DIGEST_PARAM_PROPERTIES' => '*OSSL_ALG_PARAM_PROPERTIES',# utf8 string - -# external mu digest parameters - 'OSSL_DIGEST_PARAM_MU_PUB_KEY' => "pub", # octet string - 'OSSL_DIGEST_PARAM_MU_CONTEXT_STRING' => "context-string", # octet string - 'OSSL_DIGEST_PARAM_MU_DIGEST' => '*OSSL_ALG_PARAM_DIGEST', # utf8 string - 'OSSL_DIGEST_PARAM_MU_PROPERTIES' => '*OSSL_ALG_PARAM_PROPERTIES', # utf8 string # MAC parameters 'OSSL_MAC_PARAM_KEY' => "key", # octet string @@ -226,10 +216,6 @@ my %params = ( 'OSSL_KDF_PARAM_PKCS5' => "pkcs5", # int 'OSSL_KDF_PARAM_UKM' => "ukm", # octet string 'OSSL_KDF_PARAM_CEK_ALG' => "cekalg", # utf8 string - 'OSSL_KDF_PARAM_IKEV2KDF_NI' => "ni", # octet string - 'OSSL_KDF_PARAM_IKEV2KDF_NR' => "nr", # octet string - 'OSSL_KDF_PARAM_IKEV2KDF_SPII' => "spii", # octet string - 'OSSL_KDF_PARAM_IKEV2KDF_SPIR' => "spir", # octet string 'OSSL_KDF_PARAM_SCRYPT_N' => "n", # uint64_t 'OSSL_KDF_PARAM_SCRYPT_R' => "r", # uint32_t 'OSSL_KDF_PARAM_SCRYPT_P' => "p", # uint32_t @@ -237,9 +223,6 @@ my %params = ( 'OSSL_KDF_PARAM_INFO' => "info", # octet string 'OSSL_KDF_PARAM_SEED' => "seed", # octet string 'OSSL_KDF_PARAM_SNMPKDF_EID' => "eid", # octet string - 'OSSL_KDF_PARAM_SRTPKDF_INDEX' => "index", # octet string - 'OSSL_KDF_PARAM_SRTPKDF_KDR' => "kdr", # uint32_t - 'OSSL_KDF_PARAM_SRTPKDF_LABEL' => "label", # uint32_t 'OSSL_KDF_PARAM_SSHKDF_XCGHASH' => "xcghash", # octet string 'OSSL_KDF_PARAM_SSHKDF_SESSION_ID' => "session_id", # octet string 'OSSL_KDF_PARAM_SSHKDF_TYPE' => "type", # int @@ -360,7 +343,6 @@ my %params = ( # Elliptic Curve Explicit Domain Parameters 'OSSL_PKEY_PARAM_EC_FIELD_TYPE' => "field-type", - 'OSSL_PKEY_PARAM_EC_FIELD_DEGREE' => "field-degree", 'OSSL_PKEY_PARAM_EC_P' => "p", 'OSSL_PKEY_PARAM_EC_A' => "a", 'OSSL_PKEY_PARAM_EC_B' => "b", @@ -517,7 +499,6 @@ my %params = ( 'OSSL_SIGNATURE_PARAM_MU' => "mu", # int 'OSSL_SIGNATURE_PARAM_TEST_ENTROPY' => "test-entropy", 'OSSL_SIGNATURE_PARAM_ADD_RANDOM' => "additional-random", - 'OSSL_SIGNATURE_PARAM_TLS_VERSION' => "tls-version", # Asym cipher parameters 'OSSL_ASYM_CIPHER_PARAM_DIGEST' => '*OSSL_PKEY_PARAM_DIGEST', @@ -696,7 +677,6 @@ sub generate_public_macros { } sub trie_matched { - my $with_count = shift; my $field = shift; my $num = shift; my $indent1 = shift; @@ -712,7 +692,6 @@ sub trie_matched { printf "%s \"param %%s present >%%d times\", s, $num);\n", $indent2; printf "%sreturn 0;\n", $indent2; printf "%s}\n", $indent1; - printf "%s++*count;\n", $indent1 if $with_count; printf "%sr->%s[r->num_%s++] = (OSSL_PARAM *)p;\n", $indent1, $field, $field; } else { printf "%sif (ossl_unlikely(r->%s != NULL)) {\n", $indent1, $field; @@ -720,13 +699,11 @@ sub trie_matched { printf "%s \"param %%s is repeated\", s);\n", $indent2; printf "%sreturn 0;\n", $indent2; printf "%s}\n", $indent1; - printf "%s++*count;\n", $indent1 if $with_count; printf "%sr->%s = (OSSL_PARAM *)p;\n", $indent1, $field; } } sub generate_decoder_from_trie { - my $with_count = shift; my $n = shift; my $trieref = shift; my $identmap = shift; @@ -753,7 +730,7 @@ sub generate_decoder_from_trie { } print ")) {\n"; printf "%s/* %s */\n", $indent1, $trieref->{'name'}; - trie_matched($with_count, $field, $num, $indent1, $indent2); + trie_matched($field, $num, $indent1, $indent2); printf "%s}\n", $indent0; # If this is at the top level and it's conditional, we have to @@ -775,7 +752,7 @@ sub generate_decoder_from_trie { printf "%sbreak;\n", $indent1; printf "%scase '\\0':\n", $indent0; output_ifdef($ifdefs->{$field}); - trie_matched($with_count, $field, $num, $indent1, $indent2); + trie_matched($field, $num, $indent1, $indent2); output_endifdef($ifdefs->{$field}); } else { printf "%sbreak;\n", $indent1; @@ -785,7 +762,7 @@ sub generate_decoder_from_trie { printf " case '%s':", uc $l if ($l =~ /[a-z]/); } print "\n"; - generate_decoder_from_trie($with_count, $n + 1, $trieref->{$l}, $identmap, $concat_num, $ifdefs); + generate_decoder_from_trie($n + 1, $trieref->{$l}, $identmap, $concat_num, $ifdefs); } } if ($need_break) { @@ -858,20 +835,15 @@ sub locate_long_endings { } sub output_param_decoder { - my ($with_count, $decoder_name_base, @params) = @_; + my $decoder_name_base = shift; + my @params = @_; my @keys = (); my %prms = (); my %concat_num = (); my %ifdefs = (); print "/* Machine generated by util/perl/OpenSSL/paramnames.pm */\n"; - # IWYU - print "#include \n"; - print "#include \n"; - print "#include \"internal/common.h\"\n"; - print "#include \"prov/proverr.h\"\n"; - print "\n"; - # Output gettable param array + # Output ettable param array printf "#ifndef %s_list\n", $decoder_name_base; printf "static const OSSL_PARAM %s_list[] = {\n", $decoder_name_base; for (my $i = 0; $i <= $#params; $i++) { @@ -945,15 +917,13 @@ sub output_param_decoder { printf "#ifndef %s_decoder\n", $decoder_name_base; printf "static int %s_decoder\n", $decoder_name_base; - printf " (const OSSL_PARAM *p, struct %s_st *r", $decoder_name_base; - printf "%s)\n", ($with_count ? ", int *count" : ""); + printf " (const OSSL_PARAM *p, struct %s_st *r)\n", $decoder_name_base; print "{\n"; print " const char *s;\n\n"; - print " *count = 0;\n" if $with_count; print " memset(r, 0, sizeof(*r));\n"; print " if (p != NULL)\n"; print " for (; (s = p->key) != NULL; p++)\n"; - generate_decoder_from_trie($with_count, 0, \%t, \%prms, \%concat_num, \%ifdefs); + generate_decoder_from_trie(0, \%t, \%prms, \%concat_num, \%ifdefs); print " return 1;\n"; print "}\n#endif\n"; print "/* End of machine generated */"; @@ -963,14 +933,6 @@ sub produce_param_decoder { my $s; open(local *STDOUT, '>', \$s); - output_param_decoder(0, @_); - return $s; -} - -sub produce_param_decoder_with_count { - my $s; - - open(local *STDOUT, '>', \$s); - output_param_decoder(1, @_); + output_param_decoder(@_); return $s; } diff --git a/util/perl/OpenSSL/stackhash.pm b/util/perl/OpenSSL/stackhash.pm index b3446f7747..f9f5e9ca82 100644 --- a/util/perl/OpenSSL/stackhash.pm +++ b/util/perl/OpenSSL/stackhash.pm @@ -1,5 +1,5 @@ #! /usr/bin/env perl -# Copyright 2020-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2020-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -28,30 +28,9 @@ sub generate_stack_macros_int { SKM_DEFINE_STACK_OF_INTERNAL(${nametype}, ${realtype}, ${plaintype}) #define sk_${nametype}_num(sk) OPENSSL_sk_num(ossl_check_const_${nametype}_sk_type(sk)) #define sk_${nametype}_value(sk, idx) ((${realtype} *)OPENSSL_sk_value(ossl_check_const_${nametype}_sk_type(sk), (idx))) -#define sk_${nametype}_new(cmp) \\ - ((STACK_OF(${nametype}) *)OPENSSL_sk_set_thunks( \\ - OPENSSL_sk_set_copy_thunks( \\ - OPENSSL_sk_set_cmp_thunks( \\ - OPENSSL_sk_new(ossl_check_${nametype}_compfunc_type(cmp)), \\ - sk_${nametype}_cmpfunc_thunk), \\ - sk_${nametype}_copyfunc_thunk), \\ - sk_${nametype}_freefunc_thunk)) -#define sk_${nametype}_new_null() \\ - ((STACK_OF(${nametype}) *)OPENSSL_sk_set_thunks( \\ - OPENSSL_sk_set_copy_thunks( \\ - OPENSSL_sk_set_cmp_thunks( \\ - OPENSSL_sk_new_null(), \\ - sk_${nametype}_cmpfunc_thunk), \\ - sk_${nametype}_copyfunc_thunk), \\ - sk_${nametype}_freefunc_thunk)) -#define sk_${nametype}_new_reserve(cmp, n) \\ - ((STACK_OF(${nametype}) *)OPENSSL_sk_set_thunks( \\ - OPENSSL_sk_set_copy_thunks( \\ - OPENSSL_sk_set_cmp_thunks( \\ - OPENSSL_sk_new_reserve(ossl_check_${nametype}_compfunc_type(cmp), (n)), \\ - sk_${nametype}_cmpfunc_thunk), \\ - sk_${nametype}_copyfunc_thunk), \\ - sk_${nametype}_freefunc_thunk)) +#define sk_${nametype}_new(cmp) ((STACK_OF(${nametype}) *)OPENSSL_sk_new(ossl_check_${nametype}_compfunc_type(cmp))) +#define sk_${nametype}_new_null() ((STACK_OF(${nametype}) *)OPENSSL_sk_new_null()) +#define sk_${nametype}_new_reserve(cmp, n) ((STACK_OF(${nametype}) *)OPENSSL_sk_new_reserve(ossl_check_${nametype}_compfunc_type(cmp), (n))) #define sk_${nametype}_reserve(sk, n) OPENSSL_sk_reserve(ossl_check_${nametype}_sk_type(sk), (n)) #define sk_${nametype}_free(sk) OPENSSL_sk_free(ossl_check_${nametype}_sk_type(sk)) #define sk_${nametype}_zero(sk) OPENSSL_sk_zero(ossl_check_${nametype}_sk_type(sk)) @@ -69,25 +48,8 @@ SKM_DEFINE_STACK_OF_INTERNAL(${nametype}, ${realtype}, ${plaintype}) #define sk_${nametype}_find_all(sk, ptr, pnum) OPENSSL_sk_find_all(ossl_check_${nametype}_sk_type(sk), ossl_check_${nametype}_type(ptr), pnum) #define sk_${nametype}_sort(sk) OPENSSL_sk_sort(ossl_check_${nametype}_sk_type(sk)) #define sk_${nametype}_is_sorted(sk) OPENSSL_sk_is_sorted(ossl_check_const_${nametype}_sk_type(sk)) -#define sk_${nametype}_dup(sk) \\ - ((STACK_OF(${nametype}) *)OPENSSL_sk_set_thunks( \\ - OPENSSL_sk_set_copy_thunks( \\ - OPENSSL_sk_set_cmp_thunks( \\ - OPENSSL_sk_dup(ossl_check_const_${nametype}_sk_type(sk)), \\ - sk_${nametype}_cmpfunc_thunk), \\ - sk_${nametype}_copyfunc_thunk), \\ - sk_${nametype}_freefunc_thunk)) -#define sk_${nametype}_deep_copy(sk, copyfunc, freefunc) \\ - ((STACK_OF(${nametype}) *)OPENSSL_sk_set_thunks( \\ - OPENSSL_sk_set_copy_thunks( \\ - OPENSSL_sk_set_cmp_thunks( \\ - OPENSSL_sk_deep_copy( \\ - ossl_check_const_${nametype}_sk_type(sk), \\ - ossl_check_${nametype}_copyfunc_type(copyfunc), \\ - ossl_check_${nametype}_freefunc_type(freefunc)), \\ - sk_${nametype}_cmpfunc_thunk), \\ - sk_${nametype}_copyfunc_thunk), \\ - sk_${nametype}_freefunc_thunk)) +#define sk_${nametype}_dup(sk) ((STACK_OF(${nametype}) *)OPENSSL_sk_dup(ossl_check_const_${nametype}_sk_type(sk))) +#define sk_${nametype}_deep_copy(sk, copyfunc, freefunc) ((STACK_OF(${nametype}) *)OPENSSL_sk_deep_copy(ossl_check_const_${nametype}_sk_type(sk), ossl_check_${nametype}_copyfunc_type(copyfunc), ossl_check_${nametype}_freefunc_type(freefunc))) #define sk_${nametype}_set_cmp_func(sk, cmp) ((sk_${nametype}_compfunc)OPENSSL_sk_set_cmp_func(ossl_check_${nametype}_sk_type(sk), ossl_check_${nametype}_compfunc_type(cmp))) END_MACROS diff --git a/util/perl/TLSProxy/Certificate.pm b/util/perl/TLSProxy/Certificate.pm index 6d4fe0f326..a0c01bd97e 100644 --- a/util/perl/TLSProxy/Certificate.pm +++ b/util/perl/TLSProxy/Certificate.pm @@ -1,4 +1,4 @@ -# Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -12,14 +12,6 @@ package TLSProxy::Certificate; use vars '@ISA'; push @ISA, 'TLSProxy::Message'; -use constant { - TLSEXT_cert_type_x509 => 0, - TLSEXT_cert_type_rpk => 2, -}; - -my $client_cert_type = TLSEXT_cert_type_x509; -my $server_cert_type = TLSEXT_cert_type_x509; - sub new { my $class = shift; @@ -48,7 +40,6 @@ sub new $self->{first_certificate} = ""; $self->{extension_data} = ""; $self->{remaining_certdata} = ""; - $self->{rpk} = ""; return $self; } @@ -57,9 +48,6 @@ sub parse { my $self = shift; - my $type = $self->server() ? - $self->server_type() : $self->client_type(); - if (TLSProxy::Proxy->is_tls13()) { my $context_len = unpack('C', $self->data); my $context = substr($self->data, 1, $context_len); @@ -109,26 +97,13 @@ sub parse $remdata = substr($remdata, $extensions_len); $self->context($context); + $self->first_certificate($certdata); $self->extension_data(\%extensions); - if ($type == TLSEXT_cert_type_x509) { - $self->first_certificate($certdata); - $self->remaining_certdata($remdata); - } elsif ($type == TLSEXT_cert_type_rpk) { - die "Post %s RPK content\n", $self->server() ? "server" : "client" - if ($remdata ne ""); - $self->rpk($certdata); - } else { - die "Unsupported %s certificate type: %d\n", - $self->server() ? "server" : "client", $type; - } + $self->remaining_certdata($remdata); print " Context:".$context."\n"; print " Certificate List Len:".$certlistlen."\n"; - if ($type == TLSEXT_cert_type_x509) { - print " Certificate Len:".$certlen."\n"; - } else { - print " RPK Len:".$certlen."\n"; - } + print " Certificate Len:".$certlen."\n"; print " Extensions Len:".$extensions_len."\n"; } else { my ($hicertlistlen, $certlistlen) = unpack('Cn', $self->data); @@ -139,33 +114,22 @@ sub parse die "Invalid Certificate List length" if length($remdata) != $certlistlen; - if ($type == TLSEXT_cert_type_x509) { - # X.509 Chain - my ($hicertlen, $certlen) = unpack('Cn', $remdata); - $certlen += ($hicertlen << 16); + my ($hicertlen, $certlen) = unpack('Cn', $remdata); + $certlen += ($hicertlen << 16); - die "Certificate too long" if ($certlen + 3) > $certlistlen; + die "Certificate too long" if ($certlen + 3) > $certlistlen; - $remdata = substr($remdata, 3); + $remdata = substr($remdata, 3); - my $certdata = substr($remdata, 0, $certlen); + my $certdata = substr($remdata, 0, $certlen); - $remdata = substr($remdata, $certlen); + $remdata = substr($remdata, $certlen); - $self->first_certificate($certdata); - $self->remaining_certdata($remdata); + $self->first_certificate($certdata); + $self->remaining_certdata($remdata); - print " Certificate List Len:".$certlistlen."\n"; - print " Certificate Len:".$certlen."\n"; - } elsif ($type == TLSEXT_cert_type_rpk) { - # RFC7250 RPK - $self->rpk($remdata); - - print " RPK LEN:".$certlistlen."\n"; - } else { - die "Unsupported %s certificate type: %d\n", - $self->server() ? "server" : "client", $type; - } + print " Certificate List Len:".$certlistlen."\n"; + print " Certificate Len:".$certlen."\n"; } } @@ -199,28 +163,16 @@ sub set_message_contents $data .= $self->remaining_certdata(); $self->data($data); } else { - my $type = $self->server() ? $self->server_type() : $self->client_type(); - if ($type == TLSEXT_cert_type_x509) { - # X.509 chain - my $certlen = length($self->first_certificate); - my $certlistlen = $certlen + length($self->remaining_certdata); - my $hi = $certlistlen >> 16; - $certlistlen = $certlistlen & 0xffff; - $data .= pack('Cn', $hi, $certlistlen); - $hi = $certlen >> 16; - $certlen = $certlen & 0xffff; - $data .= pack('Cn', $hi, $certlen); - $data .= $self->remaining_certdata(); - $self->data($data); - } elsif ($type == TLSEXT_cert_type_rpk) { - # RFC7250 RPK - my $len = length($self->rpk); - my $hi = $len >> 16; - $len = $len & 0xffff; - $data .= pack('Cn', $hi, $len); - $data .= $self->rpk(); - $self->data($data); - } + my $certlen = length($self->first_certificate); + my $certlistlen = $certlen + length($self->remaining_certdata); + my $hi = $certlistlen >> 16; + $certlistlen = $certlistlen & 0xffff; + $data .= pack('Cn', $hi, $certlistlen); + $hi = $certlen >> 16; + $certlen = $certlen & 0xffff; + $data .= pack('Cn', $hi, $certlen); + $data .= $self->remaining_certdata(); + $self->data($data); } } @@ -267,23 +219,4 @@ sub delete_extension my ($self, $ext_type) = @_; delete $self->{extension_data}{$ext_type}; } - -sub client_type { - shift; - $client_cert_type = shift if (@_); - return $client_cert_type; -} - -sub server_type { - shift; - $server_cert_type = shift if (@_); - return $server_cert_type; -} - -sub rpk { - my $self = shift; - $self->{rpk} = shift if (@_); - return $self->{rpk}; -} - 1; diff --git a/util/perl/TLSProxy/EncryptedExtensions.pm b/util/perl/TLSProxy/EncryptedExtensions.pm index 9eb73dd332..362e0c1082 100644 --- a/util/perl/TLSProxy/EncryptedExtensions.pm +++ b/util/perl/TLSProxy/EncryptedExtensions.pm @@ -1,4 +1,4 @@ -# Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -103,17 +103,6 @@ sub extension_data if (@_) { $self->{extension_data} = shift; } - my $exts = $self->{extension_data}; - if (defined($exts) && defined(my $data = $exts->{TLSProxy::Message::EXT_CLIENT_CERT_TYPE})) { - die "Invalid client certificate type extension\n" - if length($data) != 1; - TLSProxy::Certificate->client_type(unpack("C", $data)); - } - if (defined($exts) && defined(my $data = $exts->{TLSProxy::Message::EXT_SERVER_CERT_TYPE})) { - die "Invalid server certificate type extension\n" - if length($data) != 1; - TLSProxy::Certificate->server_type(unpack("C", $data)); - } return $self->{extension_data}; } sub set_extension diff --git a/util/perl/TLSProxy/Message.pm b/util/perl/TLSProxy/Message.pm index 8c4f9564fa..de923f0903 100644 --- a/util/perl/TLSProxy/Message.pm +++ b/util/perl/TLSProxy/Message.pm @@ -1,4 +1,4 @@ -# Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -45,14 +45,11 @@ use constant { AL_DESC_CLOSE_NOTIFY => 0, AL_DESC_UNEXPECTED_MESSAGE => 10, AL_DESC_BAD_RECORD_MAC => 20, - AL_DESC_BAD_CERTIFICATE => 42, AL_DESC_ILLEGAL_PARAMETER => 47, AL_DESC_DECODE_ERROR => 50, - AL_DESC_DECRYPT_ERROR => 51, AL_DESC_PROTOCOL_VERSION => 70, AL_DESC_NO_RENEGOTIATION => 100, - AL_DESC_MISSING_EXTENSION => 109, - AL_DESC_UNSUPPORTED_EXTENSION => 110 + AL_DESC_MISSING_EXTENSION => 109 }; my %message_type = ( @@ -102,8 +99,6 @@ use constant { EXT_RENEGOTIATE => 65281, EXT_NPN => 13172, EXT_CRYPTOPRO_BUG_EXTENSION => 0xfde8, - EXT_ECH => 0xfe0d, - EXT_ECH_OUTER => 0xfd00, EXT_UNKNOWN => 0xfffe, #Unknown extension that should appear last EXT_FORCE_LAST => 0xffff diff --git a/util/perl/TLSProxy/Proxy.pm b/util/perl/TLSProxy/Proxy.pm index a7fe48e9ce..aa6c9ff9a8 100644 --- a/util/perl/TLSProxy/Proxy.pm +++ b/util/perl/TLSProxy/Proxy.pm @@ -1,4 +1,4 @@ -# Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -82,9 +82,8 @@ sub new { my ($filter, $execute, $cert, - $debug, - $use_IPv6) = @_; - return init($class, $filter, $execute, $cert, $debug, 0, $use_IPv6); + $debug) = @_; + return init($class, $filter, $execute, $cert, $debug, 0); } sub new_dtls { @@ -92,9 +91,8 @@ sub new_dtls { my ($filter, $execute, $cert, - $debug, - $use_IPv6) = @_; - return init($class, $filter, $execute, $cert, $debug, 1, $use_IPv6); + $debug) = @_; + return init($class, $filter, $execute, $cert, $debug, 1); } sub init @@ -121,9 +119,7 @@ sub init $execute, $cert, $debug, - $isdtls, - $use_IPv6) = @_; - $use_IPv6 //= $have_IPv6; + $isdtls) = @_; my $test_client_port; @@ -132,12 +128,12 @@ sub init # this test to fail, so lets harden ourselves against that by doing # a test bind to the randomly selected port, and only continue once we # find a port that's available. - my $test_client_addr = $use_IPv6 ? "[::1]" : "127.0.0.1"; + my $test_client_addr = $have_IPv6 ? "[::1]" : "127.0.0.1"; my $found_port = 0; for (my $i = 0; $i <= 10; $i++) { $test_client_port = 49152 + int(rand(65535 - 49152)); my $test_sock; - if ($use_IPv6 == 0 || $useINET6 == 0) { + if ($useINET6 == 0) { if ($useSockInet == 0) { $test_sock = IO::Socket::IP->new(LocalPort => $test_client_port, LocalAddr => $test_client_addr); @@ -181,7 +177,6 @@ sub init server_port => 0, serverpid => 0, clientpid => 0, - clientexit => 0, execute => $execute, cert => $cert, debug => $debug, @@ -220,7 +215,6 @@ sub clearClient $self->{clientflags} = ""; $self->{sessionfile} = undef; $self->{clientpid} = 0; - $self->{clientexit} = 0; $is_tls13 = 0; $ciphersuite = undef; @@ -342,13 +336,8 @@ sub start #different one that doesn't get confused. ." -ext_cache" ." -accept $self->{server_addr}:0" + ." -cert ".$self->cert." -cert2 ".$self->cert ." -naccept ".$self->serverconnects; - if (defined $self->cert) { - $execcmd .= " -cert ".$self->cert." -cert2 ".$self->cert; - } else { - $execcmd .= " -nocert"; - } - if ($self->{isdtls}) { $execcmd .= " -dtls -max_protocol DTLSv1.2" # TLSProxy does not support message fragmentation. So @@ -380,7 +369,7 @@ sub start # Process the output from s_server until we find the ACCEPT line, which # tells us what the accepting address and port are. while (<>) { - print STDERR $_; + print; s/\R$//; # Better chomp next unless (/^ACCEPT\s.*:(\d+)$/); $self->{server_port} = $1; @@ -401,7 +390,7 @@ sub start my $error; $pid = undef; if (eval { require Win32::Process; 1; }) { - if (Win32::Process::Create(my $h, $^X, 'perl -ne "print STDERR $_"', 0, 0, ".")) { + if (Win32::Process::Create(my $h, $^X, "perl -ne print", 0, 0, ".")) { $pid = $h->GetProcessID(); $self->{proc_handle} = $h; # hold handle till next round [or exit] } else { @@ -409,7 +398,7 @@ sub start } } else { if (defined($pid = fork)) { - $pid or exec($^X, '-ne', 'print STDERR $_') or exit($!); + $pid or exec("$^X -ne print") or exit($!); } else { $error = $!; } @@ -606,7 +595,6 @@ sub clientstart $pid = $self->{clientpid}; print "Waiting for s_client process to close: $pid...\n"; waitpid($pid, 0); - $self->{clientexit} = $?; return $success; } @@ -744,11 +732,6 @@ sub clientpid my $self = shift; return $self->{clientpid}; } -sub clientexit -{ - my $self = shift; - return $self->{clientexit}; -} #Read/write accessors sub filter diff --git a/util/perl/TLSProxy/Record.pm b/util/perl/TLSProxy/Record.pm index b0560fa0e5..460991e8aa 100644 --- a/util/perl/TLSProxy/Record.pm +++ b/util/perl/TLSProxy/Record.pm @@ -121,6 +121,7 @@ sub get_records $epoch, $seq, $len, + 0, $len, # len_real $len, # decrypt_len $data, # data @@ -132,6 +133,7 @@ sub get_records $content_type, $version, $len, + 0, $len, # len_real $len, # decrypt_len $data, # data @@ -213,6 +215,7 @@ sub new_dtls $epoch, $seq, $len, + $sslv2, $len_real, $decrypt_len, $data, @@ -224,6 +227,7 @@ sub new_dtls $epoch, $seq, $len, + $sslv2, $len_real, $decrypt_len, $data, @@ -237,6 +241,7 @@ sub new $content_type, $version, $len, + $sslv2, $len_real, $decrypt_len, $data, @@ -249,6 +254,7 @@ sub new 0, #epoch 0, #seq $len, + $sslv2, $len_real, $decrypt_len, $data, @@ -265,6 +271,7 @@ sub init $epoch, $seq, $len, + $sslv2, $len_real, $decrypt_len, $data, @@ -278,6 +285,7 @@ sub init epoch => $epoch, seq => $seq, len => $len, + sslv2 => $sslv2, len_real => $len_real, decrypt_len => $decrypt_len, data => $data, @@ -380,23 +388,27 @@ sub reconstruct_record } $self->{sent} = 1; - if($self->{isdtls}) { - my $seqhi = ($self->seq >> 32) & 0xffff; - my $seqmi = ($self->seq >> 16) & 0xffff; - my $seqlo = ($self->seq >> 0) & 0xffff; - $data = pack('Cnnnnnn', $self->content_type, $self->version, - $self->epoch, $seqhi, $seqmi, $seqlo, $self->len); + if ($self->sslv2) { + $data = pack('n', $self->len | 0x8000); } else { - if (TLSProxy::Proxy->is_tls13() && $self->encrypted) { - $data = pack('Cnn', $self->outer_content_type, $self->version, - $self->len); + if($self->{isdtls}) { + my $seqhi = ($self->seq >> 32) & 0xffff; + my $seqmi = ($self->seq >> 16) & 0xffff; + my $seqlo = ($self->seq >> 0) & 0xffff; + $data = pack('Cnnnnnn', $self->content_type, $self->version, + $self->epoch, $seqhi, $seqmi, $seqlo, $self->len); + } else { + if (TLSProxy::Proxy->is_tls13() && $self->encrypted) { + $data = pack('Cnn', $self->outer_content_type, $self->version, + $self->len); + } + else { + $data = pack('Cnn', $self->content_type, $self->version, + $self->len); + } } - else { - $data = pack('Cnn', $self->content_type, $self->version, - $self->len); - } - } + } $data .= $self->data; return $data; @@ -408,6 +420,11 @@ sub flight my $self = shift; return $self->{flight}; } +sub sslv2 +{ + my $self = shift; + return $self->{sslv2}; +} sub len_real { my $self = shift; diff --git a/util/perl/TLSProxy/ServerHello.pm b/util/perl/TLSProxy/ServerHello.pm index 2d35105d75..a76ef571ef 100644 --- a/util/perl/TLSProxy/ServerHello.pm +++ b/util/perl/TLSProxy/ServerHello.pm @@ -1,4 +1,4 @@ -# Copyright 2016-2026 The OpenSSL Project Authors. All Rights Reserved. +# Copyright 2016-2025 The OpenSSL Project Authors. All Rights Reserved. # # Licensed under the Apache License 2.0 (the "License"). You may not use # this file except in compliance with the License. You can obtain a copy @@ -10,7 +10,6 @@ use strict; package TLSProxy::ServerHello; use TLSProxy::Record; -use TLSProxy::Certificate; use vars '@ISA'; push @ISA, 'TLSProxy::Message'; @@ -129,7 +128,6 @@ sub parse $self->extension_data(\%extensions); $self->process_data(); - $self->process_extensions(); print " Server Version:".$TLSProxy::Record::tls_version{$server_version}."\n"; @@ -147,28 +145,6 @@ sub process_data TLSProxy::Message->ciphersuite($self->ciphersuite); } -#Perform any actions necessary based on the extensions we've seen -sub process_extensions -{ - my $self = shift; - my %extensions = %{$self->extension_data}; - - #Clear any state from a previous run - TLSProxy::Certificate->client_type(TLSProxy::Certificate::TLSEXT_cert_type_x509); - TLSProxy::Certificate->server_type(TLSProxy::Certificate::TLSEXT_cert_type_x509); - - if (defined(my $data = $extensions{TLSProxy::Message::EXT_CLIENT_CERT_TYPE})) { - die "Invalid client certificate type extension\n" - if length($data) != 1; - TLSProxy::Certificate->client_type(unpack("C", $data)); - } - if (defined(my $data = $extensions{TLSProxy::Message::EXT_SERVER_CERT_TYPE})) { - die "Invalid server certificate type extension\n" - if length($data) != 1; - TLSProxy::Certificate->server_type(unpack("C", $data)); - } -} - #Reconstruct the on-the-wire message data following changes sub set_message_contents { diff --git a/util/platform_symbols/unix-symbols.txt b/util/platform_symbols/unix-symbols.txt index 62720f35fd..166bc5d8df 100644 --- a/util/platform_symbols/unix-symbols.txt +++ b/util/platform_symbols/unix-symbols.txt @@ -118,7 +118,6 @@ recvfrom recvmmsg secure_getenv select -send sendmmsg sendto setbuf diff --git a/util/platform_symbols/windows-symbols.txt b/util/platform_symbols/windows-symbols.txt index 7ae58a3f18..69fb23bfc1 100644 --- a/util/platform_symbols/windows-symbols.txt +++ b/util/platform_symbols/windows-symbols.txt @@ -1,176 +1,235 @@ -AcquireSRWLockExclusive -AcquireSRWLockShared -BCryptGenRandom -CertCloseStore +CryptGenRandom +RegisterEventSourceW +ReportEventW +CryptAcquireContextW +CryptReleaseContext +DeregisterEventSource CertFindCertificateInStore CertFreeCertificateContext CertOpenSystemStoreW -CloseHandle +CertCloseStore +GetUserObjectInformationW +GetProcessWindowStation +MessageBoxW +GetCurrentProcess +ReadConsoleW +ReadConsoleA +SetConsoleMode +GetConsoleMode +CreateSemaphoreA +GetExitCodeThread +WaitForSingleObject +ReleaseSemaphore +GetCurrentProcessId +TryEnterCriticalSection +LeaveCriticalSection +EnterCriticalSection +InitializeCriticalSection +SystemTimeToFileTime +GetSystemTime +TlsFree +TlsSetValue +TlsGetValue +GetSystemTimeAsFileTime +RtlCaptureContext +RtlLookupFunctionEntry +UnhandledExceptionFilter +SetUnhandledExceptionFilter +IsProcessorFeaturePresent +IsDebuggerPresent +GetStartupInfoW +QueryPerformanceCounter +InitializeSListHead +DeleteCriticalSection +TerminateProcess +TlsAlloc +GetCurrentThreadId +AcquireSRWLockShared +AcquireSRWLockExclusive +RtlVirtualUnwind ConvertFiberToThread ConvertThreadToFiberEx -CreateFiberEx -CreateSemaphoreA -CryptAcquireContextW -CryptGenRandom -CryptReleaseContext -DeleteCriticalSection +SwitchToFiber DeleteFiber -DeregisterEventSource -DisableThreadLibraryCalls -EnterCriticalSection +CreateFiberEx +GetSystemDirectoryA +FreeLibrary +GetProcAddress +LoadLibraryA +FormatMessageA +GetLastError +SetLastError +CloseHandle +LoadLibraryW +GetEnvironmentVariableW +GetStdHandle +GetFileType +WriteFile +GetModuleHandleW +MultiByteToWideChar +WideCharToMultiByte +GetACP +GetModuleHandleExW +GetSystemInfo +VirtualAlloc +VirtualProtect +VirtualFree +VirtualLock FindClose FindFirstFileW FindNextFileW -FormatMessageA -FreeLibrary -GetACP -GetConsoleMode -GetCurrentProcess -GetCurrentProcessId -GetCurrentThreadId -GetEnvironmentVariableW -GetExitCodeThread -GetFileType -GetLastError -GetModuleHandleExW -GetModuleHandleW -GetProcAddress -GetProcessWindowStation -GetStartupInfoW -GetStdHandle -GetSystemDirectoryA -GetSystemInfo -GetSystemTime -GetSystemTimeAsFileTime -GetUserObjectInformationW -InitializeCriticalSection -InitializeSListHead +Sleep InitializeSRWLock -IsDebuggerPresent -IsProcessorFeaturePresent -LeaveCriticalSection -LoadLibraryA -LoadLibraryW -MessageBoxW -MultiByteToWideChar -QueryPerformanceCounter -ReadConsoleA -ReadConsoleW -RegisterEventSourceW ReleaseSRWLockExclusive ReleaseSRWLockShared -ReleaseSemaphore -ReportEventW -RtlCaptureContext -RtlLookupFunctionEntry -RtlVirtualUnwind -SetConsoleMode -SetLastError -SetUnhandledExceptionFilter -Sleep -SwitchToFiber -SystemTimeToFileTime -TerminateProcess -TlsAlloc -TlsFree -TlsGetValue -TlsSetValue -TryEnterCriticalSection -UnhandledExceptionFilter -VirtualAlloc -VirtualFree -VirtualLock -VirtualProtect -WSAIoctl -WSASocketA -WaitForSingleObject -WideCharToMultiByte -WriteFile -__C_specific_handler -__acrt_iob_func __current_exception +__C_specific_handler +wcsstr __current_exception_context +strlen +strstr +strchr +memmove +strrchr +memcmp +memset +memcpy +memchr __std_type_info_destroy_list -__stdio_common_vfprintf -__stdio_common_vsnprintf_s __stdio_common_vsprintf -__stdio_common_vsprintf_s +__stdio_common_vfprintf __stdio_common_vsscanf -__stdio_common_vswprintf -__timezone -_beginthreadex -_cexit -_chmod -_configure_narrow_argv -_crt_at_quick_exit -_crt_atexit -_dclass -_endthreadex -_errno -_execute_onexit_table -_exit +ftell +fseek +fread _fileno -_fstat64i32 -_get_osfhandle +__stdio_common_vswprintf +_wfopen +fopen +setvbuf +fflush +ferror +feof +clearerr +setbuf +fclose +fputs +__acrt_iob_func +__stdio_common_vsprintf_s +fwrite +fgets +_setmode +strtoul +atoi +strtol +tolower +strspn +strcspn +strncpy +strpbrk +strncmp +strcmp +strcat_s +isspace +_strdup +isdigit +strncpy_s +strcpy_s _gmtime64_s +__timezone +_mktime64 +_time64 +qsort +malloc +realloc +calloc +free +terminate +signal _initialize_narrow_environment +_beginthreadex +_endthreadex +_register_onexit_function +strerror_s +_execute_onexit_table +raise +_crt_atexit +_exit +_crt_at_quick_exit +_errno +_cexit +_initterm_e +_configure_narrow_argv _initialize_onexit_table _initterm -_initterm_e -_mktime64 -_register_onexit_function _seh_filter_dll -_setmode +_chmod _stat64i32 -_strdup -_time64 -_wfopen -atoi -calloc -clearerr -fclose -feof -ferror -fflush -fgets -fopen -fputs -fread -free -fseek -ftell -fwrite +_fstat64i32 getenv -isdigit -isspace -malloc -memchr -memcmp +GetStartupInfoW +RtlLookupFunctionEntry +RtlVirtualUnwind +UnhandledExceptionFilter +GetSystemTime +SystemTimeToFileTime +CloseHandle +InitializeCriticalSection +EnterCriticalSection +LeaveCriticalSection +TryEnterCriticalSection +DeleteCriticalSection +ReleaseSemaphore +WaitForSingleObject +WSASocketA +GetCurrentThreadId +SetUnhandledExceptionFilter +GetExitCodeThread +CreateSemaphoreA +SetLastError +GetLastError +GetCurrentProcess +TerminateProcess +IsProcessorFeaturePresent +QueryPerformanceCounter +RtlCaptureContext +GetCurrentProcessId +GetSystemTimeAsFileTime +DisableThreadLibraryCalls +InitializeSListHead +IsDebuggerPresent +GetModuleHandleW memcpy -memmove memset -qsort -raise -realloc -setbuf -setvbuf -signal -strcat_s +__current_exception_context strchr -strcmp -strcpy_s -strcspn -strerror_s -strlen -strncmp -strncpy -strncpy_s -strpbrk -strrchr -strspn +memcmp +memchr strstr -strtol -strtoul +memmove +__std_type_info_destroy_list +__current_exception +__C_specific_handler +_errno +_endthreadex terminate -tolower -wcsstr +_initterm +_initterm_e +_seh_filter_dll +_configure_narrow_argv +_initialize_narrow_environment +_initialize_onexit_table +_register_onexit_function +_execute_onexit_table +_crt_atexit +_crt_at_quick_exit +_cexit +_beginthreadex +_time64 +strncmp +strcmp +qsort +_stat64i32 +atoi +__stdio_common_vsprintf +_dclass diff --git a/util/reformat-patches.sh b/util/reformat-patches.sh deleted file mode 100755 index 7f6a6be239..0000000000 --- a/util/reformat-patches.sh +++ /dev/null @@ -1,470 +0,0 @@ -#! /bin/sh -efu - -# Copyright 2025 The OpenSSL Project Authors. All Rights Reserved. -# -# Licensed under the Apache License 2.0 (the "License"). -# You may not use this file except in compliance with the License. -# You can obtain a copy in the file LICENSE in the source distribution -# or at https://www.openssl.org/source/license.html - -# The script takes starts with PATCH_BRANCH (or commit derived from TAG_PRE_FMT -# and openssl version derived from OPENSSL_BRANCH, if none provided), applies -# the list of patches provided in the command line, rebases the resulting -# branch to TAG_PRE_FMT-derived-tagged commit, then iterates over each -# of the branch commits and processes the files with extensions specified -# in FMT_EXTENSIONS (except for the ones in EXCLUDE_FILES) with CLANG_FMT_CMD, -# and committing the result on top of TAG_POST_FMT-derived-tagged commit. -# The result of successful processing is saved to OUT_DIR with -# git format-patch, and, if PATCH_BRANCH is a local branch name, it is reset -# to the resulting branch. - -: "${TAG_PRE_FMT=%s-PRE-CLANG-FORMAT-WEBKIT}" -: "${TAG_POST_FMT=%s-POST-CLANG-FORMAT-WEBKIT}" -: "${GIT_CMD=git}" -: "${GIT_REMOTE=origin}" -: "${CLANG_FMT_CMD=clang-format-21}" -: "${EXCLUDE_FILES=crypto/asn1/charmap.h crypto/bn/bn_prime.h crypto/conf/conf_def.h crypto/objects/obj_dat.h crypto/objects/obj_xref.h include/openssl/obj_mac.h}" -: "${FMT_EXTENSIONS=.c .h .c.in .h.in}" -: "${WORK_BRANCH_PRE=reformat-patches-pre}" -: "${WORK_BRANCH_POST=reformat-patches-post}" -: "${PROCESS_BRANCH_PRE=reformat-patches-process-pre}" - -: "${GIT_REPO_URL=https://github.com/openssl/openssl.git}" -: "${NO_CLEANUP=0}" -: "${GIT_REPO_DIR=}" -: "${OUT_DIR=out}" -: "${NO_FORMAT_PATCH=0}" -: "${OPENSSL_BRANCH=master}" -: "${PATCH_BRANCH=}" -: "${FORCE=0}" -: "${DO_REBASE_AFTER=0}" -: "${NO_RESET_ON_SUCCESS=0}" - -cleanup_done=1 -branches_created=0 - -prn() -{ - printf >&2 "%s\n" "$@" -} - -msg() -{ - printf >&2 "$0: %s\n" "$*" -} - -die() -{ - msg "$*" - exit 1 -} - -exit_handler() -{ - [ 0 = "${cleanup_done}" ] || return; - - if [ -n "${WORKTREE_DIR-}" ]; then - msg "The temporarily created worktree is located" \ - "at '${WORKTREE_DIR}', feel free to remove it (after" \ - "it is no longer needed) with" \ - "$GIT_CMD ${GIT_REPO_DIR:+-C ${GIT_REPO_DIR} }worktree remove" \ - "-f '${WORKTREE_DIR}' && rm -rf '${WORKTREE_DIR}'" - fi - - if [ 0 = "${PERMANENT_GIT_DIR:-}" -a -n "${GIT_REPO_DIR:-}" ]; then - msg "The temporarily created git repository directory is located" \ - "at '${GIT_REPO_DIR}', feel free to remove it after" \ - "it is no longer needed." - fi - - [ 0 = "${branches_created}" ] || - msg "The temporarily created working branches ('${WORK_BRANCH_PRE}'," \ - "'${WORK_BRANCH_POST}', and '${PROCESS_BRANCH_PRE}')" \ - "are not removed." - - cleanup_done=1 -} - -trap exit_handler 0 TERM INT QUIT - -# Check that the working branches are available for us to use -check_branch() -{ - branch_name=$(eval "printf '%s' \"\${$1}\"") - - if "$GIT_CMD" -C "${GIT_REPO_DIR}" show-ref --verify --quiet \ - "refs/heads/${branch_name}"; then - die "'${branch_name}' branch exists already in '${GIT_REPO_DIR}';" \ - "please specify -f option or a different working branch name" \ - "in $1 environment variable" - fi - - return 0 -} - -usage() -{ - prn "Usage: $0 [-g GIT_REPO_DIR] [-D] [-u GIT_REPO_URL] [-o OUT_DIR] [-O]" \ - " [-b OPENSSL_BRANCH] [-B PATCH_BRANCH] [-f] [-R] [-n] [-h]" \ - " [patch...]" -} - -help() -{ - prn "" \ - "Re-format OpenSSL patches using clang-format." \ - "" \ - "A script applies patches on top of a pre-reformat-tagged commit," \ - "processes them with clang-format, and re-generates them on top" \ - "of the corresponding post-reformat-tagged commit." \ - "" \ - "OPTIONS:" \ - " -g Path to a local openssl repository; if no local" \ - " directory is specified, the repository is checked out" \ - " from GIT_REPO_URL into a temporary directory" \ - " (Current: '${GIT_REPO_DIR}')." \ - " -D Do not remove the temporarily created repository" \ - " (Current: '${NO_CLEANUP}')." \ - " -u URL for cloning the openssl repository, if no git" \ - " repository directory was provided" \ - " (Current: '${GIT_REPO_URL}')." \ - " -o Output directory for patches (Current: '${OUT_DIR}')." \ - " -O Do not output the resulting patches with git format-patch" \ - " (Current: '${NO_FORMAT_PATCH}')." \ - " -b openssl branch to work on, should be 'master'" \ - " or 'openssl-X.Y' (Current: '${OPENSSL_BRANCH}')." \ - " -B If non-empty, the provided revision is used as a base" \ - " commit to work on: the provided patches are applied" \ - " on top of it (if any); if a local branch name" \ - " is provided, it will be reset to the resulting patch set" \ - " upon success, unless -n option is specified" \ - " (Current: '${PATCH_BRANCH}')." \ - " -f Allow overwriting working branches" \ - " (WORK_BRANCH_PRE='${WORK_BRANCH_PRE}'," \ - " WORK_BRANCH_POST='${WORK_BRANCH_POST}'," \ - " PROCESS_BRANCH_PRE='${PROCESS_BRANCH_PRE}') if they exist" \ - " already (Current: '${FORCE}')." \ - " -R Try to rebase the branch on top of OPENSSL_BRANCH" \ - " after the processing (Current: '${DO_REBASE_AFTER}')." \ - " -n Do not reset PATCH_BRANCH to the result of processing" \ - " on success (Current: '${NO_RESET_ON_SUCCESS}')." \ - " -h Show this help message and exit." \ - " patch Path to a patch file(s) to process, required" \ - " if no PATCH_BRANCH is specified. If PATCH_BRANCH" \ - " is provided, patches are applied on top of it, otherwise" \ - " applied on top of pre-reformat-tagged commit, that" \ - " is referenced by tag name constructed from TAG_PRE_FMT" \ - " and version derived from the openssl branch provided" \ - " in -b option/OPENSSL_BRANCH." \ - "" \ - "ENVIRONMENT:" \ - " TAG_PRE_FMT" \ - " Format of the pre-format tag, it is passed as a format" \ - " string to printf with openssl version (either '4.0'" \ - " for the master branch or the remainder after removal" \ - " of 'openssl-' prefix in the OPENSSL_BRANCH value)" \ - " as the only argument to yield the name of the git tag" \ - " that is considered the last commit before the reformatting" \ - " with clang-format took place (Current: '${TAG_PRE_FMT}')." \ - " TAG_POST_FMT" \ - " Format of the post-format tag, semantics is similar" \ - " to TAG_PRE_FMT, but with respect to the first commit" \ - " after the clang-format reformatting" \ - " (Current: '${TAG_POST_FMT}')." \ - " GIT_CMD" \ - " git command (Current: '${GIT_CMD}')." \ - " GIT_REMOTE" \ - " Remote to track (Current: '${GIT_REMOTE}')." \ - " CLANG_FMT_CMD" \ - " clang-format command (Current: '${CLANG_FMT_CMD}')." \ - " EXCLUDE_FILES" \ - " Space-separated list of files to exclude from clang-format" \ - " processing, as they are generated with make update" \ - " (Current: '${EXCLUDE_FILES}')." \ - " FMT_EXTENSIONS" \ - " List of extensions of files to process with clang-format" \ - " (Current: '${FMT_EXTENSIONS}')." \ - " WORK_BRANCH_PRE " \ - " Name of a temporary branch for pre-reformatted commits" \ - " (Current: '${WORK_BRANCH_PRE}')." \ - " WORK_BRANCH_POST " \ - " Name of a temporary branch for post-reformatted commits" \ - " (Current: '${WORK_BRANCH_POST}')." \ - " PROCESS_BRANCH_PRE " \ - " Name of a temporary branch for tracking reformatting" \ - " progress (it walks from TAG_PRE to WORK_BRANCH_PRE" \ - " during the course of processing)" \ - " (Current: '${PROCESS_BRANCH_PRE}')." \ - " GIT_REPO_URL" \ - " URL to openssl git repository, can be overridden" \ - " with -u option." \ - " GIT_REPO_DIR" \ - " openssl git repository dir, can be overridden" \ - " with -g option." \ - " NO_CLEANUP" \ - " If not set to 0, skip removal of work branches, worktree," \ - " and a temporarily created git repository after processing," \ - " can be overridden with -D option." \ - " OUT_DIR" \ - " Output directory for patches, can be overridden" \ - " with -o option." \ - " NO_FORMAT_PATCH" \ - " If set to 1, skip calling git format-patch on the resulting" \ - " branch in order to store the results on the OUT_DIR," \ - " can be overridden with -O option." \ - " OPENSSL_BRANCH" \ - " openssl branch to work on, can be overridden with -b option." \ - " PATCH_BRANCH" \ - " If non-empty, uses the branch as the base commit" \ - " for processing, can be overridden with -B option." \ - " FORCE" \ - " If not set to 1, script aborts if any of WORK_BRANCH_PRE," \ - " WORK_BRANCH_POST, or PROCESS_BRANCH_PRE branches exists" \ - " before the start of processing." \ - " DO_REBASE_AFTER" \ - " If set to 1, try to perform rebase on top of OPENSSL_BRANCH" \ - " after processing, can be overridden with -R option." \ - " NO_RESET_ON_SUCCESS" \ - " If not set to 0, do not reset PATH_BRANCH after a successful" \ - " processing, can be overridden with -n option." \ - "" \ - "EXAMPLES:" \ - " Updating a patch set against a stable branch that can be applied" \ - " on top of pre-reformat-tagged commit:" \ - "" \ - " $0 -b openssl-3.5 -o out_dir my_patches/*.patch" \ - "" \ - " It will create a temporary repository, perform the processing" \ - " there, and output the patches into the specified directory." \ - "" \ - "" \ - " Updating a branch in an existing repository and rebase" \ - " it on top of the current master:" \ - "" \ - " $0 -g openssl_repo -B my_branch -O -R" \ - "" \ - " It will process the patches, rebase them on top of the default" \ - " branch (master), and then reset the provided branch name" \ - " upon success." -} - -while getopts ":g:Du:o:Ob:B:fRnh" opt; do - case "${opt}" in - g) GIT_REPO_DIR="${OPTARG}" ;; - D) NO_CLEANUP=1 ;; - u) GIT_REPO_URL="${OPTARG}" ;; - o) OUT_DIR="${OPTARG}" ;; - O) NO_FORMAT_PATCH=1 ;; - b) OPENSSL_BRANCH="${OPTARG}" ;; - B) PATCH_BRANCH="${OPTARG}" ;; - f) FORCE=1 ;; - R) DO_REBASE_AFTER=1 ;; - n) NO_RESET_ON_SUCCESS=1 ;; - h) - usage - help - exit 0 - ;; - ?) - msg "Unknown option '-${OPTARG}', see $0 -h for more information." - usage - exit 1 - ;; - esac -done - -shift "$((OPTIND - 1))" - -[ 0 -eq "$#" -o "x--" != "x${1-}" ] || shift - -# Check that we have work to do -if [ -z "${PATCH_BRANCH}" -a 1 -gt "$#" ]; then - usage - die "PATCH_BRANCH is empty and no patches supplied on the command line, exiting" -fi - -if [ 1 != "${FORCE}" -a -n "${GIT_REPO_DIR}" ]; then - check_branch 'WORK_BRANCH_PRE' - check_branch 'WORK_BRANCH_POST' - check_branch 'PROCESS_BRANCH_PRE' -fi - -# Command-line checks are done -cleanup_done=0 - -# Getting the repo -PERMANENT_GIT_DIR=1 -if [ -z "${GIT_REPO_DIR}" ]; then - PERMANENT_GIT_DIR=0 - GIT_REPO_DIR=$(mktemp -d "$(pwd)/reformat-openssl-XXXXXX") - "$GIT_CMD" clone "${GIT_REPO_URL}" "${GIT_REPO_DIR}" -fi -if [ 0 != "${NO_CLEANUP}" ]; then - msg "Created a temporary directory for the repo: ${GIT_REPO_DIR}" -fi - -# Determine the tag name -if [ "master" = "${OPENSSL_BRANCH}" ]; then - TAG_PREFIX=4.0 -else - # Check that we can extract the tag prefix first - [ "x${OPENSSL_BRANCH#openssl-}" != "x${OPENSSL_BRANCH}" ] || - die "Can't parse branch name: '${OPENSSL_BRANCH}'," \ - "only 'master' and 'openssl-X.Y' are supported." - TAG_PREFIX="${OPENSSL_BRANCH#openssl-}" -fi -TAG_PRE=$(printf "${TAG_PRE_FMT}" "${TAG_PREFIX}") -TAG_POST=$(printf "${TAG_POST_FMT}" "${TAG_PREFIX}") - -# Checking that PATCH_BRANCH doesn't include TAG_POST already -if [ -n "${PATCH_BRANCH}" ]; then - if "$GIT_CMD" -C "${GIT_REPO_DIR}" merge-base --is-ancestor "${TAG_POST}" "$PATCH_BRANCH"; then - die "PATCH_BRANCH ('${PATCH_BRANCH}') already includes" \ - "post-reformat-tagged ('${TAG_POST}') commit, exiting." - fi -fi - - -# Create the worktree -WORKTREE_DIR=$(mktemp -d "$(pwd)/reformat-openssl-worktree-XXXXXX") -"$GIT_CMD" -C "$GIT_REPO_DIR" worktree add "${WORKTREE_DIR}" "${TAG_PRE}" - -# Get the branches set up -BASE_COMMIT="${PATCH_BRANCH}" -[ -n "$BASE_COMMIT" ] || BASE_COMMIT="${TAG_PRE}" -"$GIT_CMD" -C "$WORKTREE_DIR" branch -f "${WORK_BRANCH_POST}" "${TAG_POST}" -"$GIT_CMD" -C "$WORKTREE_DIR" branch -f "${WORK_BRANCH_PRE}" "${BASE_COMMIT}" -"$GIT_CMD" -C "$WORKTREE_DIR" branch -u "${GIT_REMOTE}/${OPENSSL_BRANCH}" "${WORK_BRANCH_PRE}" -branches_created=1 - -# Apply the patches -while [ 0 -lt "$#" ]; do - patch_path=$(realpath "$1") - "$GIT_CMD" -C "${WORKTREE_DIR}" am "${patch_path}" - shift -done - -# Working inside the worktree from now on -( -cd "${WORKTREE_DIR}" - -# Rebase the branch -"$GIT_CMD" checkout "${WORK_BRANCH_PRE}" -"$GIT_CMD" rebase "${TAG_PRE}" - -# Iterate over the commits and process each with clang-format -"$GIT_CMD" log --reverse --pretty="%H" "${TAG_PRE}..${WORK_BRANCH_PRE}" \ - | while read -r commit; do - "$GIT_CMD" branch -f "${PROCESS_BRANCH_PRE}" "$commit" - "$GIT_CMD" checkout "${PROCESS_BRANCH_PRE}" - msg "Processing $("$GIT_CMD" log --pretty=oneline HEAD^..HEAD)" - # Process only the touched files - "$GIT_CMD" show --pretty="" --name-status --no-renames "$commit" \ - | while read -r line; do - # Skip deletions - [ "x${line}" = "x${line#D}" ] || continue - - fname="${line#* }" - - do_process=0 - # Process only *.c *.h *.c.in *.h.in - for i in ${FMT_EXTENSIONS}; do - if [ "x${fname}" != "x${fname%${i}}" ]; then - do_process=1 - break - fi - done - - # Process the exclusion list - for i in ${EXCLUDE_FILES}; do - if [ "x${fname}" = "x${i}" ]; then - do_process=0 - break; - fi - done - - if [ 1 = "${do_process}" ]; then - msg " Formatting ${fname}" - "$CLANG_FMT_CMD" -i --style=file:.clang-format "$fname" - else - msg " Including ${fname} without processing" - fi - "$GIT_CMD" add "$fname" - done - - "$GIT_CMD" commit --amend --no-edit - "$GIT_CMD" checkout "${WORK_BRANCH_POST}" - - "$GIT_CMD" show --pretty="" --name-status --no-renames "${PROCESS_BRANCH_PRE}" \ - | while read -r line; do - fname="${line#* }" - - # Process deletions - if [ "x${line}" != "x${line#D}" ]; then - "$GIT_CMD" rm "$fname" - continue - fi - - "$GIT_CMD" reset "${PROCESS_BRANCH_PRE}" -- "$fname" - done - - "$GIT_CMD" commit -C "${commit}" - "$GIT_CMD" reset --hard - done - -# Rebase WORK_BRANCH_POST on top of OPENSSL_BRANCH -if [ 1 = "${DO_REBASE_AFTER}" ]; then - "$GIT_CMD" checkout "${WORK_BRANCH_POST}" - "$GIT_CMD" rebase "${OPENSSL_BRANCH}" -fi - -# Reset PATCH_BRANCH to WORK_BRANCH_POST if the former is a ref -if [ 0 = "${NO_RESET_ON_SUCCESS}" ]; then - if "$GIT_CMD" show-ref --verify --quiet "refs/heads/${PATCH_BRANCH}"; then - msg "Resetting branch '${PATCH_BRANCH}'" \ - "from $("$GIT_CMD" show-ref "refs/heads/${PATCH_BRANCH}")" \ - "to $("$GIT_CMD" show-ref refs/heads/"${WORK_BRANCH_POST}")" - "$GIT_CMD" branch -f "${PATCH_BRANCH}" "${WORK_BRANCH_POST}" - fi -fi -) # End of the subshell with pwd in the worktree - -# Output the patches -if [ 1 != "${NO_FORMAT_PATCH}" ]; then - mkdir -p "${OUT_DIR}" - OUT_DIR=$(realpath "${OUT_DIR}") - "$GIT_CMD" -C "${WORKTREE_DIR}" format-patch -o "${OUT_DIR}" \ - "${TAG_POST}..${WORK_BRANCH_POST}" - msg "The resulting patches are saved at '${OUT_DIR}'" -else - if [ 1 = "${PERMANENT_GIT_DIR}" -a 0 != "${NO_RESET_ON_SUCCESS}" ]; then - msg "The resulting patches are in the '${WORK_BRANCH_POST}' branch" - fi -fi - -# Cleanup -if [ 0 = "${NO_CLEANUP}" ]; then - if [ -n "${WORKTREE_DIR-}" ]; then - "$GIT_CMD" -C "${WORKTREE_DIR}" worktree remove -f "${WORKTREE_DIR}" - rm -rf "${WORKTREE_DIR}" || : - fi - - if [ 1 = "${PERMANENT_GIT_DIR}" ]; then - # Removing the working branches - "$GIT_CMD" -C "${GIT_REPO_DIR}" branch -D "${WORK_BRANCH_PRE}" || : - "$GIT_CMD" -C "${GIT_REPO_DIR}" branch -D "${PROCESS_BRANCH_PRE}" || : - - # Leaving WORK_BRANCH_POST if the branch has not been reset - # and the patches haven't been output - if [ 1 != "${NO_FORMAT_PATCH}" -o 0 = "${NO_RESET_ON_SUCCESS}" ]; then - "$GIT_CMD" -C "${GIT_REPO_DIR}" branch -D "${WORK_BRANCH_POST}" || : - fi - else - # Removing the temporarily created git repo - rm -rf "${GIT_REPO_DIR}" || : - fi -fi - -cleanup_done=1 - -exit 0 diff --git a/util/valgrind.suppression b/util/valgrind.suppression deleted file mode 100644 index e4f14372d4..0000000000 --- a/util/valgrind.suppression +++ /dev/null @@ -1,146 +0,0 @@ -{ - reachable_globals_in_libcrypto - Memcheck:Leak - match-leak-kinds: reachable - ... - obj:*/libcrypto.so.* -} -{ - reachable_globals_in_libssl - Memcheck:Leak - match-leak-kinds: reachable - ... - obj:*/libssl.so.* -} -{ - openssl_test_title_reachable - Memcheck:Leak - match-leak-kinds: reachable - ... - fun:set_test_title - ... -} - -{ - reachable_globals_in_openssl_static - Memcheck:Leak - match-leak-kinds: reachable - ... - fun:CRYPTO_*alloc - ... -} -{ - reachable_crypto_aligned_alloc - Memcheck:Leak - match-leak-kinds: reachable - ... - fun:CRYPTO_aligned_alloc - ... -} -{ - glibc_dl_open_reachable_issue - Memcheck:Leak - match-leak-kinds: reachable - ... - fun:_dl_map_new_object - ... -} -{ - glibc_dlopen_reachable_issue - Memcheck:Leak - match-leak-kinds: reachable - ... - fun:_dl_check_map_versions - ... -} -{ - glibc_dlopen_reachable_issue - Memcheck:Leak - match-leak-kinds: reachable - ... - fun:_dl_new_object - ... -} -{ - glibc_dlopen_reachable_issue - Memcheck:Leak - match-leak-kinds: reachable - ... - fun:dl_open_worker - ... -} -{ - valgrind_confusion_in_asm_code - Memcheck:Value8 - ... - fun:ossl_cipher_generic_stream_update - ... -} -{ - valgrind_confusion_in_asm_code - Memcheck:Cond - ... - fun:ossl_cipher_generic_stream_update - ... -} -{ - valgrind_confusion_in_asm_code - Memcheck:Cond - fun:EVP_DecryptUpdate - ... -} -{ - valgrind_confusion_in_asm_code - Memcheck:Cond - ... - fun:tls_get_more_records - ... -} -{ - valgrind_confusion_in_asm_code - Memcheck:Cond - fun:ssl3_read_bytes - ... -} -{ - valgrind_confusion_in_asm_code - Memcheck:Cond - fun:tls_release_record - ... -} -{ - valgrind_confusion_in_asm_code - Memcheck:Cond - fun:ssl_release_record - ... -} -{ - provider_activate_strdup - Memcheck:Leak - match-leak-kinds: reachable - fun:malloc - ... - fun:OSSL_provider_init - fun:provider_init - fun:provider_activate - ... -} -{ - false_positive_conditional_check - Memcheck:Cond - fun:bcmp - fun:test_mem_eq - ... -} -{ - false_positive_conditional_check - Memcheck:Cond - fun:ossl_gcm_stream_final - ... -} -{ - false_positive_conditional_check - Memcheck:Cond - fun:gcm_cipher_internal - ... -} diff --git a/util/wrap.pl.in b/util/wrap.pl.in index 4bb13189d3..221da07b94 100644 --- a/util/wrap.pl.in +++ b/util/wrap.pl.in @@ -78,7 +78,6 @@ if ($ARGV[0] eq '-jitter') { $std_openssl_conf_include = catdir($there, 'providers'); } -local $ENV{OPENSSL_RUNNING_UNIT_TESTS} = "yes"; local $ENV{OPENSSL_CONF_INCLUDE} = $std_openssl_conf_include if defined $std_openssl_conf_include